From a245360297f1bc4e9a6ddc9a65f9a8ae5d623a0e Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Mon, 7 Sep 2026 13:28:35 +0000 Subject: [PATCH 1/4] Merge pull request #506 from CyberDrain/dev Dev to release Synced from CyberDrain/CIPP@0e60de03aca689d7deff125dd9ba56246a4188de --- .../CopilotLimitedMode.json | 1 + .../QuarantineRequestAlert.json | 8 +- .../Defender Standards/SpamFilterPolicy.json | 20 + .../Entra (AAD) Standards/AdminSSPR.json | 4 + .../Entra (AAD) Standards/AppDeploy.json | 3 +- .../AuthMethodsPolicyMigration.json | 4 + .../AuthMethodsSettings.json | 5 + .../AuthenticationMethods.json | 212 +- .../BitLockerKeysForOwnedDevice.json | 4 + .../DisableAppCreation.json | 4 + .../Entra (AAD) Standards/DisableEmail.json | 4 + .../Entra (AAD) Standards/DisableGuests.json | 9 +- .../DisableQRCodePin.json | 4 + .../Entra (AAD) Standards/DisableSMS.json | 4 + .../DisableSecurityGroupUsers.json | 4 + .../DisableSelfServiceLicenses.json | 9 +- .../DisableTenantCreation.json | 4 + .../Entra (AAD) Standards/DisableVoice.json | 4 + .../Disablex509Certificate.json | 4 + .../Entra (AAD) Standards/EnableFIDO2.json | 4 + .../EnableHardwareOAuth.json | 4 + .../ExternalComplianceTrusted.json | 41 + .../Entra (AAD) Standards/GuestInvite.json | 4 + .../Entra (AAD) Standards/NudgeMFA.json | 4 + .../Entra (AAD) Standards/OauthConsent.json | 4 + .../OauthConsentLowSec.json | 4 + .../PWcompanionAppAllowedState.json | 4 + .../PWdisplayAppInformationRequiredState.json | 5 + .../SecurityDefaults.json | 2 +- .../Entra (AAD) Standards/SmartLockout.json | 24 +- .../Entra (AAD) Standards/TAP.json | 69 +- .../Entra (AAD) Standards/UndoOauth.json | 4 + .../allowOAuthTokens.json | 4 + .../Entra (AAD) Standards/allowOTPTokens.json | 5 +- .../intuneDeviceRegLocalAdmins.json | 1 + .../intuneRestrictUserDeviceJoin.json | 1 + .../intuneRestrictUserDeviceRegistration.json | 1 + .../Entra (AAD) Standards/laps.json | 1 + .../Exchange Standards/AutoArchive.json | 13 +- .../AutoArchiveMailbox.json | 1 + .../Exchange Standards/AutoExpandArchive.json | 1 + .../Exchange Standards/Bookings.json | 1 + .../CloudMessageRecall.json | 1 + .../Exchange Standards/DisableEWS.json | 1 + .../Exchange Standards/DlpViaDcsEnabled.json | 1 + .../Exchange Standards/EXODirectSend.json | 1 + .../Exchange Standards/EnableMailTips.json | 1 + .../EnableMailboxAuditing.json | 1 + .../Exchange Standards/FocusedInbox.json | 1 + .../Exchange Standards/MessageExpiration.json | 8 +- .../Exchange Standards/OMEBranding.json | 48 +- .../Exchange Standards/OutBoundSpamAlert.json | 17 +- .../Exchange Standards/SendFromAlias.json | 1 + .../Exchange Standards/ShortenMeetings.json | 1 + .../TeamsMeetingsByDefault.json | 1 + .../TwoClickEmailProtection.json | 1 + .../Exchange Standards/UserSubmissions.json | 21 +- .../DisableGuestDirectory.json | 4 + .../EnableCustomerLockbox.json | 1 + .../DefaultPlatformRestrictions.json | 126 +- .../IntuneAppTemplateDeploy.json | 5 +- .../intuneBrandingProfile.json | 60 +- .../Intune Standards/intuneDeviceReg.json | 1 + .../intuneDeviceRetirementDays.json | 14 +- .../Intune Standards/intuneRequireMFA.json | 1 + .../DefaultSharingLink.json | 4 + .../DeletedUserRentention.json | 1 + .../DisableAddShortcutsToOneDrive.json | 1 + .../SharePoint Standards/DisableReshare.json | 1 + .../DisableSharePointLegacyAuth.json | 1 + .../SharePoint Standards/SPAzureB2B.json | 1 + .../SharePoint Standards/SPDirectSharing.json | 4 + .../SPDisableCustomScripts.json | 1 + .../SPDisableLegacyWorkflows.json | 1 + .../SPDisableStoreAccess.json | 1 + .../SPDisallowInfectedFiles.json | 1 + .../SPEmailAttestation.json | 1 + .../SPExternalUserExpiration.json | 7 +- .../SharePoint Standards/SPFileRequests.json | 1 + .../SPGuestPeoplePicker.json | 42 + .../SPOVersionControl.json | 1 + .../SPSyncButtonState.json | 1 + .../SharePoint Standards/disableMacSync.json | 1 + .../sharingCapability.json | 1 + .../SharePoint Standards/unmanagedSync.json | 1 + .../TeamsGlobalMeetingPolicy.json | 36 +- Config/CIPPDBCacheTypes.json | 28 + Config/CountryList.json | 252 + Config/DocsPublishedPages.txt | 11 +- Config/FeatureFlags.json | 13 +- Config/LicensePricingDefaults.csv | 476 + Config/PermissionsTranslator.json | 21327 +++++++++++++--- Config/SAMManifest.json | 8 + .../ListOffboardingProgress.json | 3 + Config/openapi.json | 4871 +++- Config/standards.json | 409 +- .../Activity Triggers/BEC/Push-BECRun.ps1 | 36 +- .../Push-DomainAnalyserTenant.ps1 | 6 +- .../Push-GetCalendarPermissionsBatch.ps1 | 40 +- .../Push-DBCacheOneDriveLongPaths.ps1 | 225 + ...sh-DBCacheOneDriveRootPermissionsBatch.ps1 | 8 +- .../Push-CIPPDBCacheData.ps1 | 28 +- .../Push-CIPPOffboardingComplete.ps1 | 55 +- .../Push-CIPPOffboardingTask.ps1 | 14 +- .../Push-ExecJITAdminListAllTenants.ps1 | 5 +- .../Push-ExecMdoAlertsListAllTenants.ps1 | 4 +- .../Push-ExecOnboardTenantQueue.ps1 | 28 +- .../Push-ExecScheduledCommand.ps1 | 31 +- .../Push-GetMailboxRulesBatch.ps1 | 6 +- ...istConditionalAccessPoliciesAllTenants.ps1 | 8 +- .../Push-DBCacheStorageCleanupScanBatch.ps1 | 248 + .../Push-StoreStorageCleanupScan.ps1 | 89 + .../Alerts/Get-CIPPAlertApnCertExpiry.ps1 | 12 +- .../Alerts/Get-CIPPAlertAppSecretExpiry.ps1 | 2 + .../Alerts/Get-CIPPAlertArchiveQuota.ps1 | 111 + .../Alerts/Get-CIPPAlertDepTokenExpiry.ps1 | 14 +- ...t-CIPPAlertDeviceComplianceGracePeriod.ps1 | 55 + .../Alerts/Get-CIPPAlertExpiringLicenses.ps1 | 6 +- .../Get-CIPPAlertIntuneApprovalRequests.ps1 | 2 +- .../Alerts/Get-CIPPAlertMXRecordChanged.ps1 | 5 + .../Alerts/Get-CIPPAlertNewAppApproval.ps1 | 6 +- .../Alerts/Get-CIPPAlertOneDriveLongPaths.ps1 | 76 + ...-CIPPAlertPermanentActiveAdminAssigned.ps1 | 94 + ...Get-CIPPAlertQuarantineReleaseRequests.ps1 | 8 +- .../Public/Alerts/Get-CIPPAlertQuotaUsed.ps1 | 3 +- .../Get-CIPPAlertUnlicensedOneDriveData.ps1 | 13 +- .../Alerts/Get-CIPPAlertVppTokenExpiry.ps1 | 14 +- .../Public/Add-CIPPApplicationPermission.ps1 | 5 + Modules/CIPPCore/Public/Add-CIPPDbItem.ps1 | 6 +- .../Public/Add-CIPPDelegatedPermission.ps1 | 13 + .../Public/Add-CIPPGDAPRoleTemplate.ps1 | 69 +- .../CIPPCore/Public/Add-CIPPScheduledTask.ps1 | 35 +- .../Add-CIPPAsyncDeploymentStep.ps1 | 66 + .../Get-CIPPAsyncDeployment.ps1 | 3 + .../New-CIPPAsyncDeployment.ps1 | 41 +- .../Set-CIPPAsyncDeploymentStep.ps1 | 46 +- .../Authentication/Get-CIPPHttpFunctions.ps1 | 3 +- .../Authentication/Get-CippApiClient.ps1 | 7 +- .../Get-CippHttpPermissions.ps1 | 35 +- .../Authentication/Set-CIPPAccessRole.ps1 | 6 +- .../Public/Authentication/Test-CIPPAccess.ps1 | 96 +- .../Test-CippHttpPermissionUniverse.ps1 | 27 + .../Test-CippRoleTenantScope.ps1 | 132 + .../Get-CIPPBaselineAntiPhishPolicyState.ps1 | 7 +- ...CIPPBaselineAuthenticationMethodsState.ps1 | 9 +- ...selineDefaultPlatformRestrictionsState.ps1 | 22 + ...IPPBaselineDeployContactTemplatesState.ps1 | 8 +- .../Get-CIPPBaselineDisableGuestsState.ps1 | 27 +- ...-CIPPBaselineDisableSharedMailboxState.ps1 | 10 +- ...BaselineExternalComplianceTrustedState.ps1 | 26 + ...-CIPPBaselineFIDO2PasskeyProfilesState.ps1 | 3 + ...IPPBaselineMailboxRecipientLimitsState.ps1 | 3 +- ...t-CIPPBaselineMalwareFilterPolicyState.ps1 | 14 +- .../Get-CIPPBaselinePhishProtectionState.ps1 | 7 +- ...t-CIPPBaselineSPGuestPeoplePickerState.ps1 | 54 + ...IPPBaselineSendReceiveLimitTenantState.ps1 | 30 +- .../Get-CIPPBaselineSpamFilterPolicyState.ps1 | 13 + .../Get-CIPPBaselineUserSubmissionsState.ps1 | 8 +- .../Baselines/Get-CIPPBaselineWorkItems.ps1 | 133 +- .../Get-CIPPBaselinecalDefaultState.ps1 | 5 + .../Invoke-CIPPBaselineAppDeploy.ps1 | 26 +- ...-CIPPBaselineExternalComplianceTrusted.ps1 | 27 + ...nvoke-CIPPBaselineFIDO2PasskeyProfiles.ps1 | 3 + ...ke-CIPPBaselineIntuneAppTemplateDeploy.ps1 | 8 +- ...Invoke-CIPPBaselineSPGuestPeoplePicker.ps1 | 95 + .../Invoke-CIPPBaselineSPOVersionControl.ps1 | 21 +- .../Baselines/Invoke-CIPPBaselineStandard.ps1 | 18 + .../Invoke-CIPPBaselineUserSubmissions.ps1 | 4 +- Modules/CIPPCore/Public/Clear-CIPPDbCache.ps1 | 107 + .../Public/Clear-CIPPMobileDevice.ps1 | 42 + .../Public/ConvertTo-CIPPCountryCode.ps1 | 64 + .../ConvertTo-CIPPIntunePolicyListItem.ps1 | 11 +- ...nvertTo-CIPPSharePointSiteUsagePayload.ps1 | 61 + .../Public/ConvertTo-SPOAdminListInt64.ps1 | 31 + .../ConvertTo-SPOUsageRootWebTemplate.ps1 | 41 + .../Public/DeltaQueries/Get-DeltaQueryUrl.ps1 | 13 +- .../DeltaQueries/New-GraphDeltaQuery.ps1 | 6 + .../Start-UpdatePermissionsOrchestrator.ps1 | 11 +- .../Start-UserTasksOrchestrator.ps1 | 163 +- .../Timer Functions/Start-TableCleanup.ps1 | 12 + .../Start-UpdateTokensTimer.ps1 | 7 +- .../Timer Functions/Start-UserSyncTimer.ps1 | 61 +- .../Public/Functions/Format-CIPPCAPolicy.ps1 | 21 + .../Functions/Get-CIPPAppServiceSite.ps1 | 52 + .../Public/Functions/Get-CIPPHostname.ps1 | 17 +- .../Functions/Get-CIPPTenantAlignment.ps1 | 57 +- .../Public/Functions/Get-CIPPURLName.ps1 | 3 + .../Invoke-CIPPCustomDomainCertificate.ps1 | 131 + .../Test-CIPPCacheCapabilityError.ps1 | 51 + .../Public/Get-CIPPAuthentication.ps1 | 10 + Modules/CIPPCore/Public/Get-CIPPBackup.ps1 | 6 +- Modules/CIPPCore/Public/Get-CIPPCVEReport.ps1 | 26 +- .../CIPPCore/Public/Get-CIPPDbItemPage.ps1 | 61 + Modules/CIPPCore/Public/Get-CIPPDrift.ps1 | 90 +- .../Get-CIPPDriveItemCloudPathLength.ps1 | 62 + .../CIPPCore/Public/Get-CIPPEdgeAppBody.ps1 | 52 + .../Public/Get-CIPPGroupUsageReport.ps1 | 234 + .../CIPPCore/Public/Get-CIPPGroupsReport.ps1 | 94 +- .../Public/Get-CIPPGuestUsersReport.ps1 | 34 +- ...et-CIPPIntuneAppProtectionPolicyReport.ps1 | 29 +- .../Get-CIPPIntuneApplicationReport.ps1 | 8 +- .../Get-CIPPIntuneCompareExclusions.ps1 | 6 +- .../Get-CIPPIntuneCompliancePolicyReport.ps1 | 10 +- .../CIPPCore/Public/Get-CIPPIntunePolicy.ps1 | 37 + .../Get-CIPPIntuneReusableSettingsReport.ps1 | 6 +- .../Public/Get-CIPPIntuneScriptReport.ps1 | 10 +- .../Public/Get-CIPPJITAdminAllowedRoles.ps1 | 148 + .../CIPPCore/Public/Get-CIPPLAPSPassword.ps1 | 8 +- .../Public/Get-CIPPLastSignInDateTime.ps1 | 31 + .../Public/Get-CIPPLicenseOptimization.ps1 | 297 + .../Public/Get-CIPPLicenseOverview.ps1 | 4 +- .../CIPPCore/Public/Get-CIPPLicensePrice.ps1 | 131 + .../Public/Get-CIPPMFAStateReport.ps1 | 37 +- .../Public/Get-CIPPMailboxRulesReport.ps1 | 9 +- .../Public/Get-CIPPMailboxesReport.ps1 | 30 +- .../CIPPCore/Public/Get-CIPPOutOfOffice.ps1 | 7 +- .../Public/Get-CIPPPagedTableRows.ps1 | 115 + .../Public/Get-CIPPSPOAdminListData.ps1 | 23 +- Modules/CIPPCore/Public/Get-CIPPSPOSite.ps1 | 13 +- .../CIPPCore/Public/Get-CIPPSPOSiteBulk.ps1 | 138 + Modules/CIPPCore/Public/Get-CIPPSPOTenant.ps1 | 12 +- .../Public/Get-CIPPScheduledTaskNextRun.ps1 | 32 + .../Get-CIPPSharePointCopyJobProgress.ps1 | 256 + .../Get-CIPPSharePointCopyJobQueueLogs.ps1 | 88 + ...Get-CIPPSharePointLibraryCopyOperation.ps1 | 60 + ...Get-CIPPSharePointLibraryRootChildUris.ps1 | 80 + .../Get-CIPPSharePointSiteUsageReport.ps1 | 249 +- .../Get-CIPPSharePointSiteUsageRows.ps1 | 189 + .../Get-CIPPTenantAllowBlockListReport.ps1 | 8 +- Modules/CIPPCore/Public/Get-CippDbRole.ps1 | 32 +- .../Public/Get-CippTestDataFieldManifest.ps1 | 6 +- Modules/CIPPCore/Public/Get-DefenderCves.ps1 | 3 + .../CIPPCore/Public/Get-DefenderTvmRaw.ps1 | 3 +- .../GraphHelper/Get-ClassicAPIToken.ps1 | 11 +- .../Public/GraphHelper/Get-GraphToken.ps1 | 6 + .../Public/GraphHelper/Get-Tenants.ps1 | 35 +- .../New-CIPPCertificateAssertion.ps1 | 8 +- .../GraphHelper/New-CIPPMFAConnectorToken.ps1 | 132 + .../GraphHelper/New-GraphBulkRequest.ps1 | 52 +- .../Update-AppManagementPolicy.ps1 | 128 +- .../Public/GraphHelper/Write-LogMessage.ps1 | 8 +- .../GraphRequests/Get-GraphRequestList.ps1 | 92 +- .../Public/Invoke-CIPPCATemplateBatch.ps1 | 19 +- .../Public/Invoke-CIPPDBCacheCollection.ps1 | 29 +- .../Public/Invoke-CIPPOffboardingJob.ps1 | 123 +- .../Invoke-CIPPSharePointCreateCopyJobs.ps1 | 100 + .../CIPPCore/Public/New-CIPPAlertTemplate.ps1 | 34 +- Modules/CIPPCore/Public/New-CIPPCAPolicy.ps1 | 32 +- .../Public/New-CIPPGDAPRoleMapping.ps1 | 110 + .../Public/New-CIPPIntuneAppDeployment.ps1 | 26 +- .../Public/New-CIPPIntuneTemplate.ps1 | 23 + .../Public/New-CIPPSharePointLibrary.ps1 | 8 +- .../CIPPCore/Public/New-CIPPTemplateRun.ps1 | 42 +- Modules/CIPPCore/Public/New-CIPPUserTask.ps1 | 28 +- .../Public/New-CippStandardsDriftClone.ps1 | 7 +- .../PIM/Compare-CIPPPIMRoleSettings.ps1 | 152 + .../PIM/ConvertFrom-CIPPPIMPolicyRules.ps1 | 87 + .../PIM/ConvertTo-CIPPPIMPolicyRules.ps1 | 160 + .../PIM/ConvertTo-CIPPPIMRoleSettings.ps1 | 92 + .../Public/PIM/Get-CIPPPIMPolicySummary.ps1 | 81 + .../Public/PIM/Get-CIPPPIMRoleAssignments.ps1 | 301 + .../Public/PIM/Get-CIPPPIMRolePolicies.ps1 | 82 + .../PIM/Get-CIPPPrivilegedRoleTemplateIds.ps1 | 77 + .../PIM/Invoke-CIPPPIMAssignmentAction.ps1 | 306 + .../Public/PIM/New-CIPPPIMScheduleRequest.ps1 | 204 + .../PIM/Repair-CIPPPIMRoleSettingsFloor.ps1 | 118 + .../Public/PIM/Set-CIPPPIMRoleSettings.ps1 | 74 + .../PIM/Test-CIPPPIMRoleSettingsFloor.ps1 | 134 + Modules/CIPPCore/Public/Remove-CIPPDbItem.ps1 | 60 +- .../Public/Remove-CIPPMobileDevice.ps1 | 8 +- .../Public/Remove-CIPPSPOSiteUser.ps1 | 2 +- .../Public/Remove-CIPPUserTeamsPhoneDIDs.ps1 | 54 +- .../Public/Request-CIPPSPOPersonalSite.ps1 | 23 +- .../Resolve-CIPPIntuneTargetedMobileApps.ps1 | 105 + .../Resolve-CIPPSharePointLibraryRootUri.ps1 | 52 + .../Resolve-CIPPSharePointPermissionScope.ps1 | 21 +- .../Resolve-CIPPSharePointRestContext.ps1 | 49 + Modules/CIPPCore/Public/Send-CIPPAlert.ps1 | 33 +- .../Public/Send-CIPPCustomTestAlert.ps1 | 6 +- .../Public/Send-CIPPScheduledTaskAlert.ps1 | 74 +- .../Public/Set-CIPPAuthenticationPolicy.ps1 | 16 +- .../Public/Set-CIPPDefenderASRPolicy.ps1 | 4 +- .../Public/Set-CIPPDefenderAVPolicy.ps1 | 4 +- .../Set-CIPPDefenderCompliancePolicy.ps1 | 8 +- .../Public/Set-CIPPDefenderEDRPolicy.ps1 | 4 +- .../Set-CIPPDefenderExclusionPolicy.ps1 | 4 +- .../CIPPCore/Public/Set-CIPPFeatureFlag.ps1 | 11 +- .../CIPPCore/Public/Set-CIPPIntunePolicy.ps1 | 20 +- .../Public/Set-CIPPNotificationConfig.ps1 | 3 +- .../CIPPCore/Public/Set-CIPPPerUserMFA.ps1 | 2 +- .../Public/Set-CIPPRegistrationCampaign.ps1 | 12 +- .../Public/Set-CIPPSAMCertificate.ps1 | 3 +- Modules/CIPPCore/Public/Set-CIPPSPOSite.ps1 | 11 +- .../CIPPCore/Public/Set-CIPPSPOSiteBulk.ps1 | 128 + Modules/CIPPCore/Public/Set-CIPPSPOTenant.ps1 | 13 +- ...Set-CIPPSharePointLibraryCopyOperation.ps1 | 93 + .../Set-CIPPSharePointObjectPermission.ps1 | 8 +- .../Public/Set-CIPPStandardsCompareField.ps1 | 10 +- .../Public/Standards/Get-CIPPStandards.ps1 | 20 +- .../Get-CIPPStandardsTemplateScope.ps1 | 74 + .../Start-CIPPSharePointLibraryCopy.ps1 | 159 + .../Public/Test-CIPPGDAPGroupMappings.ps1 | 3 + .../Public/Test-CIPPOffboardingRequest.ps1 | 2 +- ...Test-CIPPSharePointLibraryCopyEligible.ps1 | 40 + .../Public/Tools/Import-CommunityTemplate.ps1 | 8 +- .../Push-ExecGenerateReportBuilderReport.ps1 | 29 +- ...Update-CIPPSharePointLibraryCopyStatus.ps1 | 178 + .../Webhooks/Invoke-CIPPWebhookProcessing.ps1 | 6 + .../Webhooks/Test-CIPPAuditLogRules.ps1 | 37 +- .../Set-CIPPDBCacheActiveUserDetail.ps1 | 38 + .../Set-CIPPDBCacheAppRoleAssignments.ps1 | 11 +- ...t-CIPPDBCacheAuthenticationFlowsPolicy.ps1 | 5 + ...CIPPDBCacheAuthenticationMethodsPolicy.ps1 | 5 + ...CIPPDBCacheAutopilotDeploymentProfiles.ps1 | 3 + .../Set-CIPPDBCacheB2BManagementPolicy.ps1 | 17 +- ...CIPPDBCacheComplianceRetentionPolicies.ps1 | 8 + ...et-CIPPDBCacheComplianceRetentionRules.ps1 | 8 + ...t-CIPPDBCacheConditionalAccessPolicies.ps1 | 7 + .../Set-CIPPDBCacheCopilotAdminSettings.ps1 | 18 +- .../Set-CIPPDBCacheCopilotPolicySettings.ps1 | 14 +- .../Set-CIPPDBCacheCsExternalAccessPolicy.ps1 | 5 + ...-CIPPDBCacheCsTeamsAppPermissionPolicy.ps1 | 5 + ...-CIPPDBCacheCsTeamsClientConfiguration.ps1 | 5 + .../Set-CIPPDBCacheCsTeamsMeetingPolicy.ps1 | 5 + ...PPDBCacheCsTeamsMessagingConfiguration.ps1 | 5 + .../Set-CIPPDBCacheCsTeamsMessagingPolicy.ps1 | 5 + ...DBCacheCsTenantFederationConfiguration.ps1 | 5 + .../DBCache/Set-CIPPDBCacheDefenderCVEs.ps1 | 107 +- ...PDBCacheDeviceEnrollmentConfigurations.ps1 | 3 + ...et-CIPPDBCacheDeviceRegistrationPolicy.ps1 | 5 + .../Set-CIPPDBCacheDlpCompliancePolicies.ps1 | 14 + .../Set-CIPPDBCacheExoAcceptedDomains.ps1 | 5 + .../Set-CIPPDBCacheExoAdminAuditLogConfig.ps1 | 5 + .../Set-CIPPDBCacheExoAntiPhishPolicies.ps1 | 10 + .../Set-CIPPDBCacheExoAtpPolicyForO365.ps1 | 15 +- .../Set-CIPPDBCacheExoDkimSigningConfig.ps1 | 5 + ...et-CIPPDBCacheExoDlpSensitiveInfoTypes.ps1 | 15 +- .../Set-CIPPDBCacheExoExternalInOutlook.ps1 | 5 + ...t-CIPPDBCacheExoGlobalQuarantinePolicy.ps1 | 5 + ...DBCacheExoHostedConnectionFilterPolicy.ps1 | 5 + ...IPPDBCacheExoHostedContentFilterPolicy.ps1 | 5 + ...-CIPPDBCacheExoHostedContentFilterRule.ps1 | 5 + ...CacheExoHostedOutboundSpamFilterPolicy.ps1 | 5 + .../Set-CIPPDBCacheExoInboundConnector.ps1 | 5 + .../DBCache/Set-CIPPDBCacheExoLabels.ps1 | 13 +- .../Set-CIPPDBCacheExoMailContacts.ps1 | 19 +- ...et-CIPPDBCacheExoMalwareFilterPolicies.ps1 | 10 + .../Set-CIPPDBCacheExoOMEConfiguration.ps1 | 5 + .../Set-CIPPDBCacheExoOrganizationConfig.ps1 | 5 + .../Set-CIPPDBCacheExoOutboundConnector.ps1 | 5 + ...Set-CIPPDBCacheExoPresetSecurityPolicy.ps1 | 8 + .../Set-CIPPDBCacheExoProtectionAlert.ps1 | 5 + .../Set-CIPPDBCacheExoQuarantinePolicy.ps1 | 10 + .../Set-CIPPDBCacheExoRemoteDomain.ps1 | 5 + ...Set-CIPPDBCacheExoRoleAssignmentPolicy.ps1 | 5 + ...t-CIPPDBCacheExoSafeAttachmentPolicies.ps1 | 24 +- .../Set-CIPPDBCacheExoSafeLinksPolicies.ps1 | 40 +- .../Set-CIPPDBCacheExoSharingPolicy.ps1 | 5 + ...et-CIPPDBCacheExoTeamsProtectionPolicy.ps1 | 5 + .../Set-CIPPDBCacheExoTransportConfig.ps1 | 5 + .../Set-CIPPDBCacheExoTransportRules.ps1 | 5 + .../DBCache/Set-CIPPDBCacheGroupUsage.ps1 | 51 + .../Public/DBCache/Set-CIPPDBCacheGroups.ps1 | 117 +- .../DBCache/Set-CIPPDBCacheHVEAccounts.ps1 | 6 +- ...CIPPDBCacheIntuneAppProtectionPolicies.ps1 | 5 + ...neAppleUserInitiatedEnrollmentProfiles.ps1 | 3 + .../Set-CIPPDBCacheIntuneApplications.ps1 | 5 + ...Set-CIPPDBCacheIntuneAssignmentFilters.ps1 | 3 + .../Set-CIPPDBCacheIntuneBrandingProfile.ps1 | 3 + ...et-CIPPDBCacheIntuneCompliancePolicies.ps1 | 4 + ...CIPPDBCacheIntuneConfigurationPolicies.ps1 | 3 + ...PPDBCacheIntuneDataProcessorOnboarding.ps1 | 3 + ...heIntuneDeviceEnrollmentConfigurations.ps1 | 3 + ...PDBCacheIntuneDeviceManagementSettings.ps1 | 3 + .../Set-CIPPDBCacheIntuneMobileApps.ps1 | 3 + .../Set-CIPPDBCacheIntuneReusableSettings.ps1 | 3 + .../DBCache/Set-CIPPDBCacheIntuneScripts.ps1 | 5 + ...tuneWindowsAutopilotDeploymentProfiles.ps1 | 3 + .../DBCache/Set-CIPPDBCacheMailboxes.ps1 | 15 +- ...t-CIPPDBCacheManagedDeviceCleanupRules.ps1 | 3 + ...PDBCacheMobileDeviceManagementPolicies.ps1 | 2 +- .../Set-CIPPDBCacheOAuth2PermissionGrants.ps1 | 5 + .../Set-CIPPDBCacheOneDriveLongPaths.ps1 | 155 + ...Set-CIPPDBCacheOneDriveRootPermissions.ps1 | 3 + .../DBCache/Set-CIPPDBCacheOneDriveUsage.ps1 | 6 +- .../Set-CIPPDBCacheOwaMailboxPolicy.ps1 | 5 + .../DBCache/Set-CIPPDBCachePIMSettings.ps1 | 14 + ...Set-CIPPDBCachePermissionGrantPolicies.ps1 | 3 +- .../Set-CIPPDBCacheReportSubmissionPolicy.ps1 | 5 + .../Set-CIPPDBCacheReportSubmissionRule.ps1 | 5 + .../DBCache/Set-CIPPDBCacheRiskDetections.ps1 | 3 + .../Set-CIPPDBCacheRiskyServicePrincipals.ps1 | 3 + .../DBCache/Set-CIPPDBCacheRiskyUsers.ps1 | 3 + .../DBCache/Set-CIPPDBCacheSPOSites.ps1 | 115 + .../DBCache/Set-CIPPDBCacheSPOTenant.ps1 | 9 +- .../Set-CIPPDBCacheSensitivityLabels.ps1 | 8 + .../Set-CIPPDBCacheSharePointPermissions.ps1 | 3 + .../Set-CIPPDBCacheSharePointSiteUsage.ps1 | 107 +- .../Set-CIPPDBCacheStorageCleanupScan.ps1 | 151 + .../Set-CIPPDBCacheTeamsResourceAccounts.ps1 | 3 + .../CIPP/Core/Invoke-ExecAzBobbyTables.ps1 | 15 +- .../CIPP/Core/Invoke-ExecCIPPDBCache.ps1 | 13 + .../CIPP/Core/Invoke-ExecCIPPDBCacheAdmin.ps1 | 149 + .../CIPP/Core/Invoke-ExecCippFunction.ps1 | 7 + .../CIPP/Core/Invoke-ExecCloneTemplate.ps1 | 10 +- .../Core/Invoke-ExecDiagnosticsPresets.ps1 | 13 +- .../CIPP/Core/Invoke-ExecEditTemplate.ps1 | 4 +- .../CIPP/Core/Invoke-ExecPartnerWebhook.ps1 | 3 + .../Core/Invoke-ExecServicePrincipals.ps1 | 15 +- .../CIPP/Core/Invoke-ListGraphRequest.ps1 | 34 + .../CIPP/Core/Invoke-ListLogs.ps1 | 404 +- .../CIPP/Core/Invoke-RemoveCippQueue.ps1 | 12 +- .../Invoke-ExecExtensionClearHIBPKey.ps1 | 11 +- .../Invoke-ExecExtensionMapping.ps1 | 14 +- .../Invoke-ExecExtensionNinjaOneQueue.ps1 | 30 +- .../Extensions/Invoke-ExecExtensionSync.ps1 | 3 + .../Invoke-ExecExtensionsConfig.ps1 | 9 +- .../Scheduler/Invoke-ListAsyncDeployment.ps1 | 33 + .../Invoke-ListFunctionParameters.ps1 | 4 +- .../Invoke-ListScheduledItemDetails.ps1 | 36 +- .../Scheduler/Invoke-ListScheduledItems.ps1 | 19 +- .../CIPP/Settings/Invoke-ExecAddTrustedIP.ps1 | 37 +- .../CIPP/Settings/Invoke-ExecApiClient.ps1 | 18 +- .../Settings/Invoke-ExecAppServiceDomains.ps1 | 289 +- .../CIPP/Settings/Invoke-ExecBackendURLs.ps1 | 14 +- .../Settings/Invoke-ExecCippReplacemap.ps1 | 11 +- .../CIPP/Settings/Invoke-ExecCustomData.ps1 | 81 +- .../CIPP/Settings/Invoke-ExecCustomRole.ps1 | 39 +- .../Invoke-ExecMaintenanceScripts.ps1 | 1 + .../Invoke-ExecNotificationConfig.ps1 | 8 + .../Settings/Invoke-ExecOffloadFunctions.ps1 | 15 +- .../CIPP/Settings/Invoke-ExecPartnerMode.ps1 | 8 +- .../Settings/Invoke-ExecPermissionRepair.ps1 | 9 +- .../Settings/Invoke-ExecRefreshMyAccess.ps1 | 1 + .../CIPP/Settings/Invoke-ExecRemoveTenant.ps1 | 12 +- .../Invoke-ExecRunTenantGroupRule.ps1 | 6 +- .../CIPP/Settings/Invoke-ExecSAMRoles.ps1 | 26 +- .../CIPP/Settings/Invoke-ExecTenantGroup.ps1 | 5 +- .../Settings/Invoke-ExecUserBookmarks.ps1 | 14 +- .../CIPP/Settings/Invoke-ExecUserSettings.ps1 | 12 +- .../CIPP/Settings/Invoke-ListCustomRole.ps1 | 15 + .../Settings/Invoke-ListExcludedLicenses.ps1 | 2 +- .../CIPP/Setup/Invoke-ExecCombinedSetup.ps1 | 37 + .../CIPP/Setup/Invoke-ExecCreateSAMApp.ps1 | 42 +- .../CIPP/Setup/Invoke-ExecSamSecretStatus.ps1 | 19 + .../CIPP/Setup/Invoke-ExecTokenExchange.ps1 | 67 +- .../Setup/Invoke-ExecUpdateRefreshToken.ps1 | 9 +- .../Contacts/Invoke-RemoveContact.ps1 | 2 +- .../Invoke-ExecMailboxMobileDevices.ps1 | 13 +- .../Invoke-ExecScheduleForwardingVacation.ps1 | 1 + .../Invoke-ExecScheduleMailboxVacation.ps1 | 1 + .../Invoke-ExecScheduleOOOVacation.ps1 | 1 + .../Administration/Invoke-ListMailboxes.ps1 | 43 +- .../Reports/Invoke-ListMailFlowReports.ps1 | 66 + .../Invoke-AddSpamFilterTemplate.ps1 | 4 +- .../Invoke-ListUserReportedMessage.ps1 | 85 + .../Invoke-ListUserReportedMessages.ps1 | 64 + .../Tools/Invoke-ExecHistoricalSearch.ps1 | 99 + .../Tools/Invoke-ExecMailboxRestore.ps1 | 9 +- .../Tools/Invoke-ListHistoricalSearches.ps1 | 49 + .../Tools/Invoke-ListMessageTrace.ps1 | 215 +- .../Invoke-AddConnectionFilterTemplate.ps1 | 4 +- .../Invoke-AddExConnectorTemplate.ps1 | 8 +- .../Transport/Invoke-AddTransportTemplate.ps1 | 8 +- .../Invoke-ListExConnectorTemplates.ps1 | 6 +- .../Transport/Invoke-RemoveExConnector.ps1 | 2 +- .../Applications/Invoke-AddAppTemplate.ps1 | 11 + .../Applications/Invoke-AddEdgeApp.ps1 | 50 + .../Invoke-ExecDeployAppTemplate.ps1 | 26 +- .../Endpoint/Applications/Invoke-ListApps.ps1 | 6 +- .../Invoke-AddAssignmentFilterTemplate.ps1 | 4 +- ...nvoke-AddIntuneReusableSettingTemplate.ps1 | 4 +- .../Endpoint/MEM/Invoke-AddIntuneTemplate.ps1 | 6 +- .../Endpoint/MEM/Invoke-EditIntuneScript.ps1 | 4 + .../MEM/Invoke-ExecCompareIntunePolicy.ps1 | 89 +- .../MEM/Invoke-ListAppProtectionPolicies.ps1 | 28 +- .../Invoke-ListAppleEnrollmentProfiles.ps1 | 38 +- .../MEM/Invoke-ListCompliancePolicies.ps1 | 8 +- .../Endpoint/MEM/Invoke-ListIntuneScript.ps1 | 6 +- .../MEM/Invoke-ListIntuneTemplates.ps1 | 36 +- .../Groups/Invoke-AddGroupTemplate.ps1 | 4 +- .../Groups/Invoke-EditGroup.ps1 | 2 + .../Groups/Invoke-ListGroups.ps1 | 58 +- .../Invoke-AddPIMRoleSettingsTemplate.ps1 | 140 + .../Roles/Invoke-ExecPIMRoleAssignment.ps1 | 112 + .../Invoke-ListPIMRoleSettingsTemplates.ps1 | 51 + .../Roles/Invoke-ListPIMRoles.ps1 | 115 + .../Roles/Invoke-ListRoleAssignments.ps1 | 76 + .../Invoke-RemovePIMRoleSettingsTemplate.ps1 | 48 + .../Users/Invoke-AddJITRoleTemplate.ps1 | 81 + .../Administration/Users/Invoke-AddUser.ps1 | 1 + .../Users/Invoke-AddUserBulk.ps1 | 1 + .../Users/Invoke-AddUserDefaults.ps1 | 2 + .../Users/Invoke-EditJITRoleTemplate.ps1 | 94 + .../Users/Invoke-ExecJITAdmin.ps1 | 24 + .../Users/Invoke-ExecOffboardUser.ps1 | 74 + .../Users/Invoke-ExecSendPush.ps1 | 170 +- .../Users/Invoke-ListGuestUsers.ps1 | 32 +- .../Users/Invoke-ListJITAdmin.ps1 | 47 +- .../Users/Invoke-ListJITAdminTemplates.ps1 | 6 +- .../Users/Invoke-ListJITAllowedRoles.ps1 | 24 + .../Users/Invoke-ListJITRoleTemplates.ps1 | 47 + .../Users/Invoke-ListNewUserDefaults.ps1 | 6 +- .../Users/Invoke-ListOffboardingProgress.ps1 | 33 + .../Users/Invoke-ListUserCounts.ps1 | 29 +- .../Users/Invoke-ListUserMailboxDetails.ps1 | 51 +- .../Administration/Users/Invoke-ListUsers.ps1 | 12 +- .../Users/Invoke-RemoveJITRoleTemplate.ps1 | 50 + .../Reports/Invoke-ListGroupUsage.ps1 | 29 + .../Reports/Invoke-ListInactiveAccounts.ps1 | 5 +- .../Identity/Reports/Invoke-ListMFAUsers.ps1 | 28 +- .../Invoke-AddDlpCompliancePolicyTemplate.ps1 | 4 +- ...e-AddRetentionCompliancePolicyTemplate.ps1 | 4 +- .../Invoke-ListRetentionCompliancePolicy.ps1 | 55 +- .../Invoke-AddSensitivityLabelTemplate.ps1 | 4 +- .../Incidents/Invoke-ExecMdoAlertsList.ps1 | 4 +- .../Invoke-AddSafeLinksPolicyTemplate.ps1 | 10 +- .../Invoke-ExecNewSafeLinksPolicy.ps1 | 10 + .../Invoke-ExecBulkRemoveSharingLinks.ps1 | 40 +- .../Invoke-ExecEmptySiteRecycleBin.ps1 | 134 + .../Invoke-ExecReactivateSite.ps1 | 81 + .../Invoke-ExecRestoreRecycleBinItems.ps1 | 8 +- .../Invoke-ExecSetSharePointMember.ps1 | 8 +- .../Invoke-ExecSharePointTemplate.ps1 | 12 +- .../Invoke-ExecSiteBrowserLibraryCopy.ps1 | 80 + .../Invoke-ExecSiteBrowserPermissions.ps1 | 8 +- .../Invoke-ListSharePointTemplates.ps1 | 6 +- .../Invoke-ListSharepointSettings.ps1 | 7 +- .../Invoke-ListSiteActivity.ps1 | 6 +- .../Invoke-ListSiteBrowser.ps1 | 67 +- .../Invoke-ListSiteBrowserLibraryCopy.ps1 | 37 + .../Invoke-ListSiteBrowserPermissions.ps1 | 21 +- .../Invoke-ListSiteMembers.ps1 | 8 +- .../Invoke-ListSitePermissions.ps1 | 8 +- .../Invoke-ListSiteRecycleBin.ps1 | 8 +- .../Invoke-ListSiteRecycleBinSummary.ps1 | 97 + .../Invoke-ListSiteRoleDefinitions.ps1 | 8 +- .../Invoke-ListSiteStorageComposition.ps1 | 93 + .../Teams-Sharepoint/Invoke-ListSites.ps1 | 127 +- .../Invoke-ListStorageCleanupScan.ps1 | 131 + .../Administration/Alerts/Invoke-AddAlert.ps1 | 21 +- .../Alerts/Invoke-AddScriptedAlert.ps1 | 76 +- ...oke-ExecScheduleAuditExclusionVacation.ps1 | 1 + .../Alerts/Invoke-ListAlertsQueue.ps1 | 40 +- .../Alerts/Invoke-PublicWebhooks.ps1 | 21 +- .../Alerts/Invoke-RemoveWebhookAlert.ps1 | 9 +- .../Invoke-ExecAddMultiTenantApp.ps1 | 18 +- .../Invoke-ExecAppApprovalTemplate.ps1 | 22 +- .../Invoke-ExecApplication.ps1 | 46 +- .../Tenant/Invoke-AddTenant.ps1 | 14 +- .../Tenant/Invoke-EditTenant.ps1 | 8 +- .../Tenant/Invoke-ExecAddSPN.ps1 | 1 + .../Tenant/Invoke-ExecOnboardTenant.ps1 | 27 +- .../Tenant/Invoke-ExecSendOrgMessage.ps1 | 13 +- .../Invoke-RemoveTenantCapabilitiesCache.ps1 | 4 +- .../Conditional/Invoke-AddCATemplate.ps1 | 4 +- .../Conditional/Invoke-ExecCAExclusion.ps1 | 5 +- .../Conditional/Invoke-ListCAtemplates.ps1 | 20 +- .../Invoke-ListConditionalAccessPolicies.ps1 | 45 +- .../Tenant/GDAP/Invoke-ExecAddGDAPRole.ps1 | 228 +- .../GDAP/Invoke-ExecGDAPAccessAssignment.ps1 | 3 + .../GDAP/Invoke-ExecGDAPInviteApproved.ps1 | 18 +- .../Invoke-ExecGDAPRepairRoleMappings.ps1 | 24 +- .../GDAP/Invoke-ExecGDAPRoleTemplate.ps1 | 64 +- .../Tenant/GDAP/Invoke-ListGDAPRoles.ps1 | 47 + .../Reports/Invoke-ExecLicensePricing.ps1 | 76 + .../Invoke-ListLicenseOptimization.ps1 | 57 + .../Reports/Invoke-ListLicensePricing.ps1 | 41 + .../Reports/Invoke-ListServiceHealth.ps1 | 6 +- .../Standards/Invoke-AddBPATemplate.ps1 | 4 +- .../Standards/Invoke-ExecDriftClone.ps1 | 22 +- .../Standards/Invoke-ExecStandardConvert.ps1 | 17 +- .../Standards/Invoke-ExecStandardsRun.ps1 | 7 +- .../Invoke-ExecUpdateBaselineDeviation.ps1 | 11 +- .../Invoke-ExecUpdateDriftDeviation.ps1 | 46 +- .../Standards/Invoke-ListStandardsCompare.ps1 | 30 +- .../Invoke-listStandardTemplates.ps1 | 11 +- .../Tenant/Tests/Invoke-AddTestReport.ps1 | 6 +- .../Tenant/Tests/Invoke-DeleteTestReport.ps1 | 6 +- .../Tenant/Tests/Invoke-ExecTestRefresh.ps1 | 5 +- .../Tenant/Tests/Invoke-ListTests.ps1 | 8 +- .../Tools/Invoke-ExecGraphExplorerPreset.ps1 | 9 + .../Tools/GitHub/Invoke-ExecCommunityRepo.ps1 | 11 + .../Tools/GitHub/Invoke-ExecGitHubAction.ps1 | 18 +- .../Invoke-ListCommunityRepoTemplates.ps1 | 3 +- .../GitHub/Invoke-ListCommunityRepos.ps1 | 10 +- .../Invoke-CIPPStandardAntiPhishPolicy.ps1 | 7 + .../Invoke-CIPPStandardAppDeploy.ps1 | 2 +- ...voke-CIPPStandardAuthenticationMethods.ps1 | 85 +- ...-CIPPStandardConditionalAccessTemplate.ps1 | 7 +- ...IPPStandardDefaultPlatformRestrictions.ps1 | 103 +- ...oke-CIPPStandardDeployContactTemplates.ps1 | 8 +- .../Invoke-CIPPStandardDisableGuests.ps1 | 87 +- ...nvoke-CIPPStandardDisableInactiveUsers.ps1 | 12 +- ...nvoke-CIPPStandardDisableSharedMailbox.ps1 | 38 +- ...voke-CIPPStandardEnableMailboxAuditing.ps1 | 84 +- ...-CIPPStandardExternalComplianceTrusted.ps1 | 97 + ...nvoke-CIPPStandardFIDO2PasskeyProfiles.ps1 | 10 + .../Invoke-CIPPStandardGroupTemplate.ps1 | 35 +- ...ke-CIPPStandardIntuneAppTemplateDeploy.ps1 | 22 +- .../Invoke-CIPPStandardIntuneTemplate.ps1 | 12 +- .../Standards/Invoke-CIPPStandardMDMScope.ps1 | 2 +- ...voke-CIPPStandardOneDriveLicensedQuota.ps1 | 17 +- .../Invoke-CIPPStandardOutBoundSpamAlert.ps1 | 56 +- .../Invoke-CIPPStandardPIMRoleSettings.ps1 | 197 + ...oke-CIPPStandardQuarantineRequestAlert.ps1 | 37 +- ...Invoke-CIPPStandardSPGuestPeoplePicker.ps1 | 136 + .../Invoke-CIPPStandardSPOVersionControl.ps1 | 60 +- .../Invoke-CIPPStandardSpamFilterPolicy.ps1 | 13 + ...e-CIPPStandardTeamsGlobalMeetingPolicy.ps1 | 29 +- .../Standards/Invoke-CIPPStandardTeamsZAP.ps1 | 15 + .../Invoke-CIPPStandardUserSubmissions.ps1 | 16 +- .../Invoke-CIPPStandardcalDefault.ps1 | 44 +- .../Helpers/ConvertTo-CippMarkdownCell.ps1 | 4 +- .../CIS/Identity/Invoke-CippTestCIS_2_1_1.ps1 | 9 +- .../Identity/Invoke-CippTestCIS_2_1_11.ps1 | 17 +- .../CIS/Identity/Invoke-CippTestCIS_2_1_3.ps1 | 15 +- .../CIS/Identity/Invoke-CippTestCIS_2_1_4.ps1 | 9 +- .../CIS/Identity/Invoke-CippTestCIS_2_1_5.ps1 | 9 +- .../CIS/Identity/Invoke-CippTestCIS_6_1_2.ps1 | 13 +- .../Identity/Invoke-CippTestCIS_7_2_11.ps1 | 14 +- .../CIS/Identity/Invoke-CippTestCIS_7_2_7.ps1 | 18 +- .../Invoke-CippTestGenericTest011.ps1 | 6 +- .../Identity/Invoke-CippTestZTNA21811.ps1 | 15 +- .../Register-CippExtensionScheduledTasks.ps1 | 12 + .../Public/Halo/Get-HaloPriority.ps1 | 19 +- .../Public/Halo/Get-HaloTicketTypeSlaId.ps1 | 53 + .../Public/Halo/New-HaloPSATicket.ps1 | 173 +- .../Public/New-CippExtAlert.ps1 | 64 +- .../NinjaOne/Invoke-NinjaOneTenantSync.ps1 | 31 +- .../Sherweb/Invoke-SherwebMigration.ps1 | 16 +- .../{1.1.8 => 1.1.10}/DNSHealth.psd1 | 14 +- .../{1.1.8 => 1.1.10}/DNSHealth.psm1 | 12 +- .../MailProviders/AppRiver.json | 0 .../MailProviders/BarracudaESS.json | 0 .../MailProviders/Google.json | 0 .../MailProviders/HornetSecurity.json | 0 .../MailProviders/Intermedia.json | 0 .../MailProviders/Microsoft365.json | 0 .../MailProviders/Mimecast.json | 2 +- .../MailProviders/MimecastOffshore.json | 10 + .../{1.1.8 => 1.1.10}/MailProviders/Null.json | 0 .../MailProviders/Proofpoint.json | 0 .../MailProviders/Reflexion.json | 0 .../MailProviders/Sophos.json | 3 +- .../MailProviders/SpamTitan.json | 0 .../MailProviders/SymantecCloud.json | 0 .../MailProviders/_template.json | 0 .../{1.1.8 => 1.1.10}/PSGetModuleInfo.xml | 92 +- Modules/DNSHealth/1.1.10/SevenTinyRsa.dll | Bin 0 -> 5120 bytes Shared/CIPPSharp/CIPPRestClient.cs | 178 +- Shared/CIPPSharp/bin/CIPPSharp.dll | Bin 64512 -> 71168 bytes ...ditionalAccessPoliciesAllTenants.Tests.ps1 | 67 + .../Get-CIPPAlertMXRecordChanged.Tests.ps1 | 87 + .../Get-CIPPAlertOneDriveLongPaths.Tests.ps1 | 73 + ...PPAlertQuarantineReleaseRequests.Tests.ps1 | 116 + Tests/Alerts/Get-CIPPAlertQuotaUsed.Tests.ps1 | 77 + .../Alerts/Invoke-AddScriptedAlert.Tests.ps1 | 125 + Tests/Alerts/Send-CIPPAlert.Psa.Tests.ps1 | 112 + ...cheduledTaskAlert.ResultEnvelope.Tests.ps1 | 162 + .../Send-CIPPScheduledTaskAlert.Tests.ps1 | 64 +- .../Baselines/BaselineDisableGuests.Tests.ps1 | 119 + .../Baselines/BaselineEntraHeavies.Tests.ps1 | 42 + .../Baselines/BaselineExchangeBatch.Tests.ps1 | 39 + .../BaselineOneOffStandards.Tests.ps1 | 26 +- .../BaselineSPGuestPeoplePicker.Tests.ps1 | 118 + .../BaselineSharePointBatch.Tests.ps1 | 19 +- Tests/DBCache/Clear-CIPPDbCache.Tests.ps1 | 208 + Tests/DBCache/OneDriveLongPaths.Tests.ps1 | 328 + ...Push-GetCalendarPermissionsBatch.Tests.ps1 | 134 + .../DBCache/Set-CIPPDBCache.Memory.Tests.ps1 | 175 +- ...et-CIPPDBCacheDefenderCVEs.Flush.Tests.ps1 | 3 +- .../Set-CIPPDBCacheDefenderCVEs.Tests.ps1 | 62 +- .../SharePointSharingLinks.Resume.Tests.ps1 | 10 +- .../Endpoint/Invoke-AddAppTemplate.Tests.ps1 | 171 + ...nvoke-AddPIMRoleSettingsTemplate.Tests.ps1 | 215 + Tests/Endpoint/Invoke-EditTenant.Tests.ps1 | 140 + .../Invoke-ExecAppServiceDomains.Tests.ps1 | 74 + .../Invoke-ExecCippReplacemap.Tests.ps1 | 1 + .../Invoke-ExecEmptySiteRecycleBin.Tests.ps1 | 148 + .../Invoke-ExecOffboardUser.Tests.ps1 | 118 +- .../Invoke-ExecPIMRoleAssignment.Tests.ps1 | 163 + .../Invoke-ExecRefreshMyAccess.Tests.ps1 | 4 + ...nvoke-ExecSiteBrowserLibraryCopy.Tests.ps1 | 105 + ...ke-ListConditionalAccessPolicies.Tests.ps1 | 154 + Tests/Endpoint/Invoke-ListGroups.Tests.ps1 | 133 + .../Endpoint/Invoke-ListGuestUsers.Tests.ps1 | 78 +- .../Invoke-ListLicenseOptimization.Tests.ps1 | 96 + Tests/Endpoint/Invoke-ListLogs.Tests.ps1 | 297 + Tests/Endpoint/Invoke-ListMailboxes.Tests.ps1 | 113 + .../Invoke-ListMessageTrace.Tests.ps1 | 146 + ...ListScheduledItems.TenantDomains.Tests.ps1 | 96 + ...New-CippExtAlert.TicketReference.Tests.ps1 | 193 + .../New-HaloPSATicket.Priority.Tests.ps1 | 159 + .../New-HaloPSATicket.TicketTarget.Tests.ps1 | 169 + ...-ClassicAPIToken.CertificateAuth.Tests.ps1 | 72 + .../Get-GraphToken.CertificateAuth.Tests.ps1 | 110 + .../Get-Tenants.RefreshLoop.Tests.ps1 | 225 + .../New-CIPPMFAConnectorToken.Tests.ps1 | 63 + .../New-GraphBulkRequest.Paging.Tests.ps1 | 115 + ...ManagementPolicy.CertificateOnly.Tests.ps1 | 91 + ...ppManagementPolicy.ExemptionBody.Tests.ps1 | 136 + Tests/Private/Add-CIPPDbItem.Tests.ps1 | 21 + Tests/Private/Format-CIPPCAPolicy.Tests.ps1 | 54 + Tests/Private/Get-CIPPCVEReport.Tests.ps1 | 63 +- Tests/Private/Get-CIPPDbItemPage.Tests.ps1 | 84 + ...Get-CIPPDriveItemCloudPathLength.Tests.ps1 | 36 + Tests/Private/Get-CIPPGroupsReport.Tests.ps1 | 99 + .../Get-CIPPLicenseOptimization.Tests.ps1 | 158 + Tests/Private/Get-CIPPLicensePrice.Tests.ps1 | 151 + .../Private/Get-CIPPPagedTableRows.Tests.ps1 | 200 + ...et-CIPPSharePointCopyJobProgress.Tests.ps1 | 205 + ...PPSharePointLibraryCopyOperation.Tests.ps1 | 117 + Tests/Private/Get-CippApiClient.Tests.ps1 | 102 + .../Private/Get-CippHttpPermissions.Tests.ps1 | 114 + Tests/Private/Get-DefenderCves.Tests.ps1 | 23 +- .../Get-GraphRequestList.Paging.Tests.ps1 | 219 + ...voke-CIPPCustomDomainCertificate.Tests.ps1 | 120 + ...ke-CIPPOffboardingJob.DeleteUser.Tests.ps1 | 77 + ...voke-CIPPOffboardingJob.Progress.Tests.ps1 | 128 + .../Invoke-CIPPPIMAssignmentAction.Tests.ps1 | 220 + ...oke-CIPPSharePointCreateCopyJobs.Tests.ps1 | 47 + .../New-CIPPPIMScheduleRequest.Tests.ps1 | 120 + Tests/Private/New-CIPPUserTask.Tests.ps1 | 33 + ...ffboardingComplete.PostExecution.Tests.ps1 | 115 + ...ush-CIPPOffboardingTask.Progress.Tests.ps1 | 96 + .../Remove-CIPPUserTeamsPhoneDIDs.Tests.ps1 | 90 + .../Repair-CIPPPIMRoleSettingsFloor.Tests.ps1 | 143 + ...esolve-CIPPSharePointRestContext.Tests.ps1 | 46 + .../Set-CIPPAsyncDeploymentStep.Tests.ps1 | 95 + .../Set-CIPPFeatureFlag.Force.Tests.ps1 | 44 + .../Private/Set-CIPPSAMCertificate.Tests.ps1 | 60 + Tests/Private/Start-UserSyncTimer.Tests.ps1 | 183 + ...Test-CIPPAccess.BlockedEndpoints.Tests.ps1 | 219 + .../Test-CIPPAccess.TenantGroupAuth.Tests.ps1 | 87 + .../Test-CIPPPIMRoleSettingsFloor.Tests.ps1 | 197 + ...IPPSharePointLibraryCopyEligible.Tests.ps1 | 26 + ...-CIPPSharePointLibraryCopyStatus.Tests.ps1 | 111 + .../ConvertTo-CippMarkdownCell.Tests.ps1 | 10 + Tests/Reports/Get-CIPPDrift.Tests.ps1 | 41 + .../Reports/Get-CIPPLicenseOverview.Tests.ps1 | 120 + ...CIPPScheduledTask.TenantCoercion.Tests.ps1 | 143 + ...IPPScheduledTask.TenantSelection.Tests.ps1 | 95 + .../Get-CIPPScheduledTaskNextRun.Tests.ps1 | 41 + ...cScheduledCommand.TenantCoercion.Tests.ps1 | 128 + ...pdateTokensTimer.CertificateAuth.Tests.ps1 | 69 + ...erTasksOrchestrator.TenantGroups.Tests.ps1 | 353 + ...tandardConditionalAccessTemplate.Tests.ps1 | 2 +- ...Invoke-CIPPStandardDisableGuests.Tests.ps1 | 230 + ...CIPPStandardDisableSharedMailbox.Tests.ps1 | 228 + ...tandardExternalComplianceTrusted.Tests.ps1 | 62 + ...CIPPStandardFIDO2PasskeyProfiles.Tests.ps1 | 162 + ...Invoke-CIPPStandardGroupTemplate.Tests.ps1 | 53 + ...IPPStandardOneDriveLicensedQuota.Tests.ps1 | 32 +- ...PPStandardQuarantineRequestAlert.Tests.ps1 | 178 + ...ke-CIPPStandardSPOVersionControl.Tests.ps1 | 149 + ...voke-CIPPStandardUserSubmissions.Tests.ps1 | 70 +- ...-CIPPStandardcalDefault.Coverage.Tests.ps1 | 125 + Tests/Static/PIMSecureDirection.Tests.ps1 | 80 + ...nvoke-ExecGDAPRepairRoleMappings.Tests.ps1 | 81 + .../Invoke-ListGDAPRoles.Validate.Tests.ps1 | 97 + .../Tenant/New-CIPPGDAPRoleMapping.Tests.ps1 | 119 + .../Webhooks/Test-CIPPAuditLogRules.Tests.ps1 | 22 +- version_latest.txt | 2 +- 764 files changed, 53153 insertions(+), 7819 deletions(-) create mode 100644 Config/BaselineStandards/Entra (AAD) Standards/ExternalComplianceTrusted.json create mode 100644 Config/BaselineStandards/SharePoint Standards/SPGuestPeoplePicker.json create mode 100644 Config/CountryList.json create mode 100644 Config/LicensePricingDefaults.csv create mode 100644 Config/openapi-overrides/ListOffboardingProgress.json create mode 100644 Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/OneDrive Long Paths/Push-DBCacheOneDriveLongPaths.ps1 create mode 100644 Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/SharePoint Storage Cleanup/Push-DBCacheStorageCleanupScanBatch.ps1 create mode 100644 Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/SharePoint Storage Cleanup/Push-StoreStorageCleanupScan.ps1 create mode 100644 Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertArchiveQuota.ps1 create mode 100644 Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertDeviceComplianceGracePeriod.ps1 create mode 100644 Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertOneDriveLongPaths.ps1 create mode 100644 Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertPermanentActiveAdminAssigned.ps1 create mode 100644 Modules/CIPPCore/Public/AsyncDeployment/Add-CIPPAsyncDeploymentStep.ps1 create mode 100644 Modules/CIPPCore/Public/Authentication/Test-CippHttpPermissionUniverse.ps1 create mode 100644 Modules/CIPPCore/Public/Authentication/Test-CippRoleTenantScope.ps1 create mode 100644 Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineExternalComplianceTrustedState.ps1 create mode 100644 Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineSPGuestPeoplePickerState.ps1 create mode 100644 Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineExternalComplianceTrusted.ps1 create mode 100644 Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineSPGuestPeoplePicker.ps1 create mode 100644 Modules/CIPPCore/Public/Clear-CIPPDbCache.ps1 create mode 100644 Modules/CIPPCore/Public/Clear-CIPPMobileDevice.ps1 create mode 100644 Modules/CIPPCore/Public/ConvertTo-CIPPCountryCode.ps1 create mode 100644 Modules/CIPPCore/Public/ConvertTo-CIPPSharePointSiteUsagePayload.ps1 create mode 100644 Modules/CIPPCore/Public/ConvertTo-SPOAdminListInt64.ps1 create mode 100644 Modules/CIPPCore/Public/ConvertTo-SPOUsageRootWebTemplate.ps1 create mode 100644 Modules/CIPPCore/Public/Functions/Get-CIPPAppServiceSite.ps1 create mode 100644 Modules/CIPPCore/Public/Functions/Invoke-CIPPCustomDomainCertificate.ps1 create mode 100644 Modules/CIPPCore/Public/Functions/Test-CIPPCacheCapabilityError.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPDbItemPage.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPDriveItemCloudPathLength.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPEdgeAppBody.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPGroupUsageReport.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPJITAdminAllowedRoles.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPLastSignInDateTime.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPLicenseOptimization.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPLicensePrice.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPPagedTableRows.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPSPOSiteBulk.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPScheduledTaskNextRun.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPSharePointCopyJobProgress.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPSharePointCopyJobQueueLogs.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPSharePointLibraryCopyOperation.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPSharePointLibraryRootChildUris.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPSharePointSiteUsageRows.ps1 create mode 100644 Modules/CIPPCore/Public/GraphHelper/New-CIPPMFAConnectorToken.ps1 create mode 100644 Modules/CIPPCore/Public/Invoke-CIPPSharePointCreateCopyJobs.ps1 create mode 100644 Modules/CIPPCore/Public/New-CIPPGDAPRoleMapping.ps1 create mode 100644 Modules/CIPPCore/Public/PIM/Compare-CIPPPIMRoleSettings.ps1 create mode 100644 Modules/CIPPCore/Public/PIM/ConvertFrom-CIPPPIMPolicyRules.ps1 create mode 100644 Modules/CIPPCore/Public/PIM/ConvertTo-CIPPPIMPolicyRules.ps1 create mode 100644 Modules/CIPPCore/Public/PIM/ConvertTo-CIPPPIMRoleSettings.ps1 create mode 100644 Modules/CIPPCore/Public/PIM/Get-CIPPPIMPolicySummary.ps1 create mode 100644 Modules/CIPPCore/Public/PIM/Get-CIPPPIMRoleAssignments.ps1 create mode 100644 Modules/CIPPCore/Public/PIM/Get-CIPPPIMRolePolicies.ps1 create mode 100644 Modules/CIPPCore/Public/PIM/Get-CIPPPrivilegedRoleTemplateIds.ps1 create mode 100644 Modules/CIPPCore/Public/PIM/Invoke-CIPPPIMAssignmentAction.ps1 create mode 100644 Modules/CIPPCore/Public/PIM/New-CIPPPIMScheduleRequest.ps1 create mode 100644 Modules/CIPPCore/Public/PIM/Repair-CIPPPIMRoleSettingsFloor.ps1 create mode 100644 Modules/CIPPCore/Public/PIM/Set-CIPPPIMRoleSettings.ps1 create mode 100644 Modules/CIPPCore/Public/PIM/Test-CIPPPIMRoleSettingsFloor.ps1 create mode 100644 Modules/CIPPCore/Public/Resolve-CIPPIntuneTargetedMobileApps.ps1 create mode 100644 Modules/CIPPCore/Public/Resolve-CIPPSharePointLibraryRootUri.ps1 create mode 100644 Modules/CIPPCore/Public/Resolve-CIPPSharePointRestContext.ps1 create mode 100644 Modules/CIPPCore/Public/Set-CIPPSPOSiteBulk.ps1 create mode 100644 Modules/CIPPCore/Public/Set-CIPPSharePointLibraryCopyOperation.ps1 create mode 100644 Modules/CIPPCore/Public/Standards/Get-CIPPStandardsTemplateScope.ps1 create mode 100644 Modules/CIPPCore/Public/Start-CIPPSharePointLibraryCopy.ps1 create mode 100644 Modules/CIPPCore/Public/Test-CIPPSharePointLibraryCopyEligible.ps1 create mode 100644 Modules/CIPPCore/Public/Update-CIPPSharePointLibraryCopyStatus.ps1 create mode 100644 Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheActiveUserDetail.ps1 create mode 100644 Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheGroupUsage.ps1 create mode 100644 Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOneDriveLongPaths.ps1 create mode 100644 Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSPOSites.ps1 create mode 100644 Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheStorageCleanupScan.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCIPPDBCacheAdmin.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListAsyncDeployment.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Reports/Invoke-ListMailFlowReports.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Spamfilter/Invoke-ListUserReportedMessage.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Spamfilter/Invoke-ListUserReportedMessages.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ExecHistoricalSearch.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ListHistoricalSearches.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-AddEdgeApp.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-AddPIMRoleSettingsTemplate.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ExecPIMRoleAssignment.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListPIMRoleSettingsTemplates.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListPIMRoles.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListRoleAssignments.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-RemovePIMRoleSettingsTemplate.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddJITRoleTemplate.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-EditJITRoleTemplate.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITAllowedRoles.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITRoleTemplates.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListOffboardingProgress.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-RemoveJITRoleTemplate.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListGroupUsage.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecEmptySiteRecycleBin.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecReactivateSite.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSiteBrowserLibraryCopy.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteBrowserLibraryCopy.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteRecycleBinSummary.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteStorageComposition.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListStorageCleanupScan.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ExecLicensePricing.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ListLicenseOptimization.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ListLicensePricing.ps1 create mode 100644 Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardExternalComplianceTrusted.ps1 create mode 100644 Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardPIMRoleSettings.ps1 create mode 100644 Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardSPGuestPeoplePicker.ps1 create mode 100644 Modules/CippExtensions/Public/Halo/Get-HaloTicketTypeSlaId.ps1 rename Modules/DNSHealth/{1.1.8 => 1.1.10}/DNSHealth.psd1 (89%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/DNSHealth.psm1 (99%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/AppRiver.json (100%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/BarracudaESS.json (100%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/Google.json (100%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/HornetSecurity.json (100%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/Intermedia.json (100%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/Microsoft365.json (100%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/Mimecast.json (84%) create mode 100644 Modules/DNSHealth/1.1.10/MailProviders/MimecastOffshore.json rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/Null.json (100%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/Proofpoint.json (100%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/Reflexion.json (100%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/Sophos.json (68%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/SpamTitan.json (100%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/SymantecCloud.json (100%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/MailProviders/_template.json (100%) rename Modules/DNSHealth/{1.1.8 => 1.1.10}/PSGetModuleInfo.xml (71%) create mode 100644 Modules/DNSHealth/1.1.10/SevenTinyRsa.dll create mode 100644 Tests/ActivityTriggers/Push-ListConditionalAccessPoliciesAllTenants.Tests.ps1 create mode 100644 Tests/Alerts/Get-CIPPAlertMXRecordChanged.Tests.ps1 create mode 100644 Tests/Alerts/Get-CIPPAlertOneDriveLongPaths.Tests.ps1 create mode 100644 Tests/Alerts/Get-CIPPAlertQuarantineReleaseRequests.Tests.ps1 create mode 100644 Tests/Alerts/Get-CIPPAlertQuotaUsed.Tests.ps1 create mode 100644 Tests/Alerts/Invoke-AddScriptedAlert.Tests.ps1 create mode 100644 Tests/Alerts/Send-CIPPAlert.Psa.Tests.ps1 create mode 100644 Tests/Alerts/Send-CIPPScheduledTaskAlert.ResultEnvelope.Tests.ps1 create mode 100644 Tests/Baselines/BaselineDisableGuests.Tests.ps1 create mode 100644 Tests/Baselines/BaselineSPGuestPeoplePicker.Tests.ps1 create mode 100644 Tests/DBCache/Clear-CIPPDbCache.Tests.ps1 create mode 100644 Tests/DBCache/OneDriveLongPaths.Tests.ps1 create mode 100644 Tests/DBCache/Push-GetCalendarPermissionsBatch.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-AddAppTemplate.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-AddPIMRoleSettingsTemplate.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-EditTenant.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-ExecAppServiceDomains.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-ExecEmptySiteRecycleBin.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-ExecPIMRoleAssignment.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-ExecSiteBrowserLibraryCopy.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-ListConditionalAccessPolicies.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-ListGroups.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-ListLicenseOptimization.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-ListLogs.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-ListMailboxes.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-ListMessageTrace.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-ListScheduledItems.TenantDomains.Tests.ps1 create mode 100644 Tests/Extensions/New-CippExtAlert.TicketReference.Tests.ps1 create mode 100644 Tests/Extensions/New-HaloPSATicket.Priority.Tests.ps1 create mode 100644 Tests/Extensions/New-HaloPSATicket.TicketTarget.Tests.ps1 create mode 100644 Tests/GraphHelper/Get-ClassicAPIToken.CertificateAuth.Tests.ps1 create mode 100644 Tests/GraphHelper/Get-GraphToken.CertificateAuth.Tests.ps1 create mode 100644 Tests/GraphHelper/Get-Tenants.RefreshLoop.Tests.ps1 create mode 100644 Tests/GraphHelper/New-CIPPMFAConnectorToken.Tests.ps1 create mode 100644 Tests/GraphHelper/New-GraphBulkRequest.Paging.Tests.ps1 create mode 100644 Tests/GraphHelper/Update-AppManagementPolicy.CertificateOnly.Tests.ps1 create mode 100644 Tests/GraphHelper/Update-AppManagementPolicy.ExemptionBody.Tests.ps1 create mode 100644 Tests/Private/Get-CIPPDbItemPage.Tests.ps1 create mode 100644 Tests/Private/Get-CIPPDriveItemCloudPathLength.Tests.ps1 create mode 100644 Tests/Private/Get-CIPPGroupsReport.Tests.ps1 create mode 100644 Tests/Private/Get-CIPPLicenseOptimization.Tests.ps1 create mode 100644 Tests/Private/Get-CIPPLicensePrice.Tests.ps1 create mode 100644 Tests/Private/Get-CIPPPagedTableRows.Tests.ps1 create mode 100644 Tests/Private/Get-CIPPSharePointCopyJobProgress.Tests.ps1 create mode 100644 Tests/Private/Get-CIPPSharePointLibraryCopyOperation.Tests.ps1 create mode 100644 Tests/Private/Get-CippApiClient.Tests.ps1 create mode 100644 Tests/Private/Get-CippHttpPermissions.Tests.ps1 create mode 100644 Tests/Private/Get-GraphRequestList.Paging.Tests.ps1 create mode 100644 Tests/Private/Invoke-CIPPCustomDomainCertificate.Tests.ps1 create mode 100644 Tests/Private/Invoke-CIPPOffboardingJob.DeleteUser.Tests.ps1 create mode 100644 Tests/Private/Invoke-CIPPOffboardingJob.Progress.Tests.ps1 create mode 100644 Tests/Private/Invoke-CIPPPIMAssignmentAction.Tests.ps1 create mode 100644 Tests/Private/Invoke-CIPPSharePointCreateCopyJobs.Tests.ps1 create mode 100644 Tests/Private/New-CIPPPIMScheduleRequest.Tests.ps1 create mode 100644 Tests/Private/Push-CIPPOffboardingComplete.PostExecution.Tests.ps1 create mode 100644 Tests/Private/Push-CIPPOffboardingTask.Progress.Tests.ps1 create mode 100644 Tests/Private/Remove-CIPPUserTeamsPhoneDIDs.Tests.ps1 create mode 100644 Tests/Private/Repair-CIPPPIMRoleSettingsFloor.Tests.ps1 create mode 100644 Tests/Private/Resolve-CIPPSharePointRestContext.Tests.ps1 create mode 100644 Tests/Private/Set-CIPPAsyncDeploymentStep.Tests.ps1 create mode 100644 Tests/Private/Set-CIPPFeatureFlag.Force.Tests.ps1 create mode 100644 Tests/Private/Set-CIPPSAMCertificate.Tests.ps1 create mode 100644 Tests/Private/Start-UserSyncTimer.Tests.ps1 create mode 100644 Tests/Private/Test-CIPPAccess.BlockedEndpoints.Tests.ps1 create mode 100644 Tests/Private/Test-CIPPAccess.TenantGroupAuth.Tests.ps1 create mode 100644 Tests/Private/Test-CIPPPIMRoleSettingsFloor.Tests.ps1 create mode 100644 Tests/Private/Test-CIPPSharePointLibraryCopyEligible.Tests.ps1 create mode 100644 Tests/Private/Update-CIPPSharePointLibraryCopyStatus.Tests.ps1 create mode 100644 Tests/Reports/Get-CIPPLicenseOverview.Tests.ps1 create mode 100644 Tests/Scheduler/Add-CIPPScheduledTask.TenantCoercion.Tests.ps1 create mode 100644 Tests/Scheduler/Add-CIPPScheduledTask.TenantSelection.Tests.ps1 create mode 100644 Tests/Scheduler/Get-CIPPScheduledTaskNextRun.Tests.ps1 create mode 100644 Tests/Scheduler/Push-ExecScheduledCommand.TenantCoercion.Tests.ps1 create mode 100644 Tests/Scheduler/Start-UpdateTokensTimer.CertificateAuth.Tests.ps1 create mode 100644 Tests/Scheduler/Start-UserTasksOrchestrator.TenantGroups.Tests.ps1 create mode 100644 Tests/Standards/Invoke-CIPPStandardDisableGuests.Tests.ps1 create mode 100644 Tests/Standards/Invoke-CIPPStandardDisableSharedMailbox.Tests.ps1 create mode 100644 Tests/Standards/Invoke-CIPPStandardExternalComplianceTrusted.Tests.ps1 create mode 100644 Tests/Standards/Invoke-CIPPStandardFIDO2PasskeyProfiles.Tests.ps1 create mode 100644 Tests/Standards/Invoke-CIPPStandardQuarantineRequestAlert.Tests.ps1 create mode 100644 Tests/Standards/Invoke-CIPPStandardSPOVersionControl.Tests.ps1 create mode 100644 Tests/Standards/Invoke-CIPPStandardcalDefault.Coverage.Tests.ps1 create mode 100644 Tests/Static/PIMSecureDirection.Tests.ps1 create mode 100644 Tests/Tenant/Invoke-ExecGDAPRepairRoleMappings.Tests.ps1 create mode 100644 Tests/Tenant/Invoke-ListGDAPRoles.Validate.Tests.ps1 create mode 100644 Tests/Tenant/New-CIPPGDAPRoleMapping.Tests.ps1 diff --git a/Config/BaselineStandards/Copilot (M365) Standards/CopilotLimitedMode.json b/Config/BaselineStandards/Copilot (M365) Standards/CopilotLimitedMode.json index 27d9612f1627d..9490913e86287 100644 --- a/Config/BaselineStandards/Copilot (M365) Standards/CopilotLimitedMode.json +++ b/Config/BaselineStandards/Copilot (M365) Standards/CopilotLimitedMode.json @@ -1,5 +1,6 @@ { "name": "CopilotLimitedMode", + "disabled": true, "label": "Set Copilot Limited Mode", "cat": "Copilot (M365) Standards", "tag": [], diff --git a/Config/BaselineStandards/Defender Standards/QuarantineRequestAlert.json b/Config/BaselineStandards/Defender Standards/QuarantineRequestAlert.json index fd5d6def28f81..21b64f8f51f0e 100644 --- a/Config/BaselineStandards/Defender Standards/QuarantineRequestAlert.json +++ b/Config/BaselineStandards/Defender Standards/QuarantineRequestAlert.json @@ -36,7 +36,13 @@ "type": "textField", "label": "E-mail to receive the alert", "helperText": "Ignored when the alert state is Removed.", - "required": true + "required": true, + "validators": { + "pattern": { + "value": "^[^\\s@]+@[^\\s@]+\\.[^\\s@]+$", + "message": "Must be a valid e-mail address" + } + } }, "AllowExtraAddresses": { "type": "switch", diff --git a/Config/BaselineStandards/Defender Standards/SpamFilterPolicy.json b/Config/BaselineStandards/Defender Standards/SpamFilterPolicy.json index bed69c21a2762..9d2abc8047589 100644 --- a/Config/BaselineStandards/Defender Standards/SpamFilterPolicy.json +++ b/Config/BaselineStandards/Defender Standards/SpamFilterPolicy.json @@ -302,6 +302,26 @@ "required": true, "default": 7 }, + "BulkMovesEnabled": { + "type": "select", + "multiple": false, + "label": "Bulk moves enabled (deliver bulk mail below the threshold to the Promotions folder - Preview)", + "options": [ + { + "label": "Do not configure", + "value": "" + }, + { + "label": "On", + "value": "On" + }, + { + "label": "Off", + "value": "Off" + } + ], + "default": "" + }, "IncreaseScoreWithImageLinks": { "type": "switch", "label": "Increase score with image links", diff --git a/Config/BaselineStandards/Entra (AAD) Standards/AdminSSPR.json b/Config/BaselineStandards/Entra (AAD) Standards/AdminSSPR.json index 66a49b9e5d8ec..6c30b0877796c 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/AdminSSPR.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/AdminSSPR.json @@ -36,6 +36,10 @@ "read": { "cacheType": "AuthorizationPolicy" }, + "writeTarget": "authorizationPolicy", + "writeTargetProperties": { + "allowedToUseSSPR": "%allowSSPR%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/AppDeploy.json b/Config/BaselineStandards/Entra (AAD) Standards/AppDeploy.json index 6ac7ece8dadd3..49246814cd69e 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/AppDeploy.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/AppDeploy.json @@ -46,7 +46,8 @@ "url": "/api/ListAppApprovalTemplates", "labelField": "TemplateName", "valueField": "TemplateId", - "queryKey": "StdAppApprovalTemplateList" + "queryKey": "StdAppApprovalTemplateList", + "templateView": { "title": "App Approval Template" } } }, "appids": { diff --git a/Config/BaselineStandards/Entra (AAD) Standards/AuthMethodsPolicyMigration.json b/Config/BaselineStandards/Entra (AAD) Standards/AuthMethodsPolicyMigration.json index 27c464b1a58f9..917b063093403 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/AuthMethodsPolicyMigration.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/AuthMethodsPolicyMigration.json @@ -44,6 +44,10 @@ "read": { "cacheType": "AuthenticationMethodsPolicy" }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "policyMigrationState": "%migrationState%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/AuthMethodsSettings.json b/Config/BaselineStandards/Entra (AAD) Standards/AuthMethodsSettings.json index 62bd935a822df..75acc7d80cd86 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/AuthMethodsSettings.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/AuthMethodsSettings.json @@ -81,6 +81,11 @@ "read": { "cacheType": "AuthenticationMethodsPolicy" }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "reportSuspiciousActivitySettings.state": "%reportSuspiciousActivity%", + "systemCredentialPreferences.state": "%systemCredential%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/AuthenticationMethods.json b/Config/BaselineStandards/Entra (AAD) Standards/AuthenticationMethods.json index 75563d8a71bc9..78b500a14c137 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/AuthenticationMethods.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/AuthenticationMethods.json @@ -24,9 +24,24 @@ "compare": "subset", "variables": { "MicrosoftAuthenticatorEnabled": { - "label": "Microsoft Authenticator: manage this method", + "creatable": false, + "options": [ + { + "value": true, + "label": "Enabled" + }, + { + "value": false, + "label": "Disabled" + }, + { + "value": "notConfigured", + "label": "Not Configured" + } + ], "omitWhenBlank": true, - "type": "switch" + "type": "autoComplete", + "label": "Microsoft Authenticator: state (Not Configured = leave as-is)" }, "MicrosoftAuthenticatorGroup": { "label": "Microsoft Authenticator: target group (blank = all users)", @@ -34,9 +49,24 @@ "type": "textField" }, "FIDO2Enabled": { - "label": "FIDO2 Security Keys: manage this method", + "creatable": false, + "options": [ + { + "value": true, + "label": "Enabled" + }, + { + "value": false, + "label": "Disabled" + }, + { + "value": "notConfigured", + "label": "Not Configured" + } + ], "omitWhenBlank": true, - "type": "switch" + "type": "autoComplete", + "label": "FIDO2 Security Keys: state (Not Configured = leave as-is)" }, "FIDO2Group": { "label": "FIDO2 Security Keys: target group (blank = all users)", @@ -44,9 +74,24 @@ "type": "textField" }, "TAPEnabled": { - "label": "Temporary Access Pass: manage this method", + "creatable": false, + "options": [ + { + "value": true, + "label": "Enabled" + }, + { + "value": false, + "label": "Disabled" + }, + { + "value": "notConfigured", + "label": "Not Configured" + } + ], "omitWhenBlank": true, - "type": "switch" + "type": "autoComplete", + "label": "Temporary Access Pass: state (Not Configured = leave as-is)" }, "TAPGroup": { "label": "Temporary Access Pass: target group (blank = all users)", @@ -54,9 +99,24 @@ "type": "textField" }, "SoftwareOathEnabled": { - "label": "Software OATH Tokens: manage this method", + "creatable": false, + "options": [ + { + "value": true, + "label": "Enabled" + }, + { + "value": false, + "label": "Disabled" + }, + { + "value": "notConfigured", + "label": "Not Configured" + } + ], "omitWhenBlank": true, - "type": "switch" + "type": "autoComplete", + "label": "Software OATH Tokens: state (Not Configured = leave as-is)" }, "SoftwareOathGroup": { "label": "Software OATH Tokens: target group (blank = all users)", @@ -64,9 +124,24 @@ "type": "textField" }, "HardwareOathEnabled": { - "label": "Hardware OATH Tokens: manage this method", + "creatable": false, + "options": [ + { + "value": true, + "label": "Enabled" + }, + { + "value": false, + "label": "Disabled" + }, + { + "value": "notConfigured", + "label": "Not Configured" + } + ], "omitWhenBlank": true, - "type": "switch" + "type": "autoComplete", + "label": "Hardware OATH Tokens: state (Not Configured = leave as-is)" }, "HardwareOathGroup": { "label": "Hardware OATH Tokens: target group (blank = all users)", @@ -74,9 +149,24 @@ "type": "textField" }, "SMSEnabled": { - "label": "SMS: manage this method", + "creatable": false, + "options": [ + { + "value": true, + "label": "Enabled" + }, + { + "value": false, + "label": "Disabled" + }, + { + "value": "notConfigured", + "label": "Not Configured" + } + ], "omitWhenBlank": true, - "type": "switch" + "type": "autoComplete", + "label": "SMS: state (Not Configured = leave as-is)" }, "SMSGroup": { "label": "SMS: target group (blank = all users)", @@ -84,9 +174,24 @@ "type": "textField" }, "VoiceEnabled": { - "label": "Voice Call: manage this method", + "creatable": false, + "options": [ + { + "value": true, + "label": "Enabled" + }, + { + "value": false, + "label": "Disabled" + }, + { + "value": "notConfigured", + "label": "Not Configured" + } + ], "omitWhenBlank": true, - "type": "switch" + "type": "autoComplete", + "label": "Voice Call: state (Not Configured = leave as-is)" }, "VoiceGroup": { "label": "Voice Call: target group (blank = all users)", @@ -94,9 +199,24 @@ "type": "textField" }, "EmailEnabled": { - "label": "Email OTP: manage this method", + "creatable": false, + "options": [ + { + "value": true, + "label": "Enabled" + }, + { + "value": false, + "label": "Disabled" + }, + { + "value": "notConfigured", + "label": "Not Configured" + } + ], "omitWhenBlank": true, - "type": "switch" + "type": "autoComplete", + "label": "Email OTP: state (Not Configured = leave as-is)" }, "EmailGroup": { "label": "Email OTP: target group (blank = all users)", @@ -104,9 +224,24 @@ "type": "textField" }, "x509CertificateEnabled": { - "label": "Certificate-Based Authentication: manage this method", + "creatable": false, + "options": [ + { + "value": true, + "label": "Enabled" + }, + { + "value": false, + "label": "Disabled" + }, + { + "value": "notConfigured", + "label": "Not Configured" + } + ], "omitWhenBlank": true, - "type": "switch" + "type": "autoComplete", + "label": "Certificate-Based Authentication: state (Not Configured = leave as-is)" }, "x509CertificateGroup": { "label": "Certificate-Based Authentication: target group (blank = all users)", @@ -114,9 +249,24 @@ "type": "textField" }, "QRCodePinEnabled": { - "label": "QR Code Pin: manage this method", + "creatable": false, + "options": [ + { + "value": true, + "label": "Enabled" + }, + { + "value": false, + "label": "Disabled" + }, + { + "value": "notConfigured", + "label": "Not Configured" + } + ], "omitWhenBlank": true, - "type": "switch" + "type": "autoComplete", + "label": "QR Code Pin: state (Not Configured = leave as-is)" }, "QRCodePinGroup": { "label": "QR Code Pin: target group (blank = all users)", @@ -268,6 +418,28 @@ "cacheType": "AuthenticationMethodsPolicy" }, "prepare": "Get-CIPPBaselineAuthenticationMethodsState", + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "Sms.state": "%SMSEnabled%", + "Voice.state": "%VoiceEnabled%", + "Email.state": "%EmailEnabled%", + "x509Certificate.state": "%x509CertificateEnabled%", + "HardwareOath.state": "%HardwareOathEnabled%", + "SoftwareOath.state": "%SoftwareOathEnabled%", + "QRCodePin.state": "%QRCodePinEnabled%", + "Fido2.state": "%FIDO2Enabled%", + "MicrosoftAuthenticator.state": "%MicrosoftAuthenticatorEnabled%", + "MicrosoftAuthenticator.isSoftwareOathEnabled": "%MicrosoftAuthenticatorSoftwareOath%", + "MicrosoftAuthenticator.featureSettings.displayAppInformationRequiredState.state": "%MicrosoftAuthenticatorDisplayAppInfo%", + "MicrosoftAuthenticator.featureSettings.displayLocationInformationRequiredState.state": "%MicrosoftAuthenticatorDisplayLocation%", + "MicrosoftAuthenticator.featureSettings.companionAppAllowedState.state": "%MicrosoftAuthenticatorCompanionApp%", + "TemporaryAccessPass.state": "%TAPEnabled%", + "TemporaryAccessPass.isUsableOnce": "%TAPUsableOnce%", + "TemporaryAccessPass.defaultLifetimeInMinutes": "%TAPDefaultLifetime%", + "TemporaryAccessPass.minimumLifetimeInMinutes": "%TAPMinLifetime%", + "TemporaryAccessPass.maximumLifetimeInMinutes": "%TAPMaxLifetime%", + "TemporaryAccessPass.defaultLength": "%TAPDefaultLength%" + }, "remediate": { "executor": "AuthenticationMethods" } diff --git a/Config/BaselineStandards/Entra (AAD) Standards/BitLockerKeysForOwnedDevice.json b/Config/BaselineStandards/Entra (AAD) Standards/BitLockerKeysForOwnedDevice.json index bafe1f818baa3..5a63f4856ff5d 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/BitLockerKeysForOwnedDevice.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/BitLockerKeysForOwnedDevice.json @@ -35,6 +35,10 @@ "cacheType": "AuthorizationPolicy", "object": "defaultUserRolePermissions" }, + "writeTarget": "authorizationPolicy", + "writeTargetProperties": { + "defaultUserRolePermissions.allowedToReadBitLockerKeysForOwnedDevice": "%allowed%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/DisableAppCreation.json b/Config/BaselineStandards/Entra (AAD) Standards/DisableAppCreation.json index 3383a5420aba3..00ababc9eadc2 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/DisableAppCreation.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/DisableAppCreation.json @@ -38,6 +38,10 @@ "cacheType": "AuthorizationPolicy", "object": "defaultUserRolePermissions" }, + "writeTarget": "authorizationPolicy", + "writeTargetProperties": { + "defaultUserRolePermissions.allowedToCreateApps": "%allowAppCreation%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/DisableEmail.json b/Config/BaselineStandards/Entra (AAD) Standards/DisableEmail.json index c8080154836cb..83b79a9e4df87 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/DisableEmail.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/DisableEmail.json @@ -57,6 +57,10 @@ } ] }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "Email.state": "%state%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/DisableGuests.json b/Config/BaselineStandards/Entra (AAD) Standards/DisableGuests.json index 2af5ca4a2f59a..8af928e5ab5f5 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/DisableGuests.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/DisableGuests.json @@ -6,9 +6,9 @@ "SMB1001 (2.8)" ], "impact": "Medium Impact", - "helpText": "Blocks login for guest users that have not logged in for a number of days. Guests still pending invitation acceptance are included. Accounts an administrator re-enabled in the last 7 days are left alone.", + "helpText": "Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone.", "executiveText": "Automatically disables external guest accounts that haven't been used for a number of days, reducing security risks from dormant accounts while maintaining access for active external collaborators. This helps maintain a clean user directory and reduces potential attack vectors.", - "docsDescription": "Blocks login for guest users that have not logged in for a number of days, and for guests that never accepted their invitation.", + "docsDescription": "Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled.", "impactColour": "warning", "addedDate": "2022-10-20", "powershellEquivalent": "Graph API", @@ -32,6 +32,11 @@ "label": "Days of inactivity", "required": true, "default": 90 + }, + "IncludeNeverSignedIn": { + "type": "switch", + "label": "Disable accounts that have not yet signed in", + "default": false } }, "expected": { diff --git a/Config/BaselineStandards/Entra (AAD) Standards/DisableQRCodePin.json b/Config/BaselineStandards/Entra (AAD) Standards/DisableQRCodePin.json index da6cb08e1d0be..e276c3e1bd36f 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/DisableQRCodePin.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/DisableQRCodePin.json @@ -45,6 +45,10 @@ } ] }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "QRCodePin.state": "%state%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/DisableSMS.json b/Config/BaselineStandards/Entra (AAD) Standards/DisableSMS.json index f1a59ff3e82ac..6aa5909df77a9 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/DisableSMS.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/DisableSMS.json @@ -62,6 +62,10 @@ } ] }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "Sms.state": "%state%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/DisableSecurityGroupUsers.json b/Config/BaselineStandards/Entra (AAD) Standards/DisableSecurityGroupUsers.json index cc62a43f463a3..091ef35387d30 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/DisableSecurityGroupUsers.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/DisableSecurityGroupUsers.json @@ -38,6 +38,10 @@ "cacheType": "AuthorizationPolicy", "object": "defaultUserRolePermissions" }, + "writeTarget": "authorizationPolicy", + "writeTargetProperties": { + "defaultUserRolePermissions.allowedToCreateSecurityGroups": "%allowSecurityGroupCreation%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/DisableSelfServiceLicenses.json b/Config/BaselineStandards/Entra (AAD) Standards/DisableSelfServiceLicenses.json index b381d021c282f..21f7901a1b460 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/DisableSelfServiceLicenses.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/DisableSelfServiceLicenses.json @@ -39,7 +39,14 @@ "cacheType": "SelfServicePurchaseProducts" }, "prepare": "Get-CIPPBaselineDisableSelfServiceLicensesState", + "writeTarget": "authorizationPolicy", + "writeTargetProperties": { + "allowedToSignUpEmailBasedSubscriptions": false + }, "remediate": { - "executor": "DisableSelfServiceLicenses" + "executor": "DisableSelfServiceLicenses", + "refreshCache": [ + "SelfServicePurchaseProducts" + ] } } diff --git a/Config/BaselineStandards/Entra (AAD) Standards/DisableTenantCreation.json b/Config/BaselineStandards/Entra (AAD) Standards/DisableTenantCreation.json index f41e4f23f4270..adfe50c5c4571 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/DisableTenantCreation.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/DisableTenantCreation.json @@ -42,6 +42,10 @@ "cacheType": "AuthorizationPolicy", "object": "defaultUserRolePermissions" }, + "writeTarget": "authorizationPolicy", + "writeTargetProperties": { + "defaultUserRolePermissions.allowedToCreateTenants": "%allowTenantCreation%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/DisableVoice.json b/Config/BaselineStandards/Entra (AAD) Standards/DisableVoice.json index 098d46ea40f4b..ab42302985c6c 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/DisableVoice.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/DisableVoice.json @@ -62,6 +62,10 @@ } ] }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "Voice.state": "%state%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/Disablex509Certificate.json b/Config/BaselineStandards/Entra (AAD) Standards/Disablex509Certificate.json index 17cb7f2875743..d65ce97280e09 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/Disablex509Certificate.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/Disablex509Certificate.json @@ -45,6 +45,10 @@ } ] }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "x509Certificate.state": "%state%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/EnableFIDO2.json b/Config/BaselineStandards/Entra (AAD) Standards/EnableFIDO2.json index b2fac9b15eb07..f0cabf36c182a 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/EnableFIDO2.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/EnableFIDO2.json @@ -54,6 +54,10 @@ } ] }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "Fido2.state": "enabled" + }, "remediate": { "executor": "EnableFIDO2" } diff --git a/Config/BaselineStandards/Entra (AAD) Standards/EnableHardwareOAuth.json b/Config/BaselineStandards/Entra (AAD) Standards/EnableHardwareOAuth.json index e5fae59d7f403..0ff0983a3d818 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/EnableHardwareOAuth.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/EnableHardwareOAuth.json @@ -54,6 +54,10 @@ } ] }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "HardwareOath.state": "%state%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/ExternalComplianceTrusted.json b/Config/BaselineStandards/Entra (AAD) Standards/ExternalComplianceTrusted.json new file mode 100644 index 0000000000000..41076b444cdb0 --- /dev/null +++ b/Config/BaselineStandards/Entra (AAD) Standards/ExternalComplianceTrusted.json @@ -0,0 +1,41 @@ +{ + "name": "ExternalComplianceTrusted", + "label": "Sets the Cross-tenant Access Setting to Trust External Compliant Devices", + "cat": "Entra (AAD) Standards", + "tag": [], + "impact": "Low Impact", + "helpText": "Sets the default state for whether device compliance performed in an external tenant is trusted for inbound B2B access.", + "executiveText": "Controls whether guests using compliant devices from their home organization can access this tenant without requiring device compliance to be evaluated again. Trusting external compliance reduces partner friction while preserving device-based access controls.", + "docsDescription": "Grades and sets inboundTrust.isCompliantDeviceAccepted on the default cross-tenant access policy. Remediation reads the live policy and rewrites the merged inboundTrust object, preserving the MFA and hybrid-join trust flags alongside it.", + "impactColour": "info", + "addedDate": "2026-08-25", + "powershellEquivalent": "Update-MgPolicyCrossTenantAccessPolicyDefault", + "recommendedBy": [], + "requiredCapabilities": [ + "AAD_PREMIUM", + "AAD_PREMIUM_P2" + ], + "disabledFeatures": { + "report": false, + "warn": false, + "remediate": false + }, + "secureScoreImpact": 0, + "compare": "subset", + "variables": { + "state": { + "type": "switch", + "label": "Trust compliant devices from external tenants", + "default": false, + "recommended": true + } + }, + "read": { + "cacheType": "CrossTenantAccessPolicy" + }, + "prepare": "Get-CIPPBaselineExternalComplianceTrustedState", + "remediate": { + "executor": "ExternalComplianceTrusted", + "trusted": "%state%" + } +} diff --git a/Config/BaselineStandards/Entra (AAD) Standards/GuestInvite.json b/Config/BaselineStandards/Entra (AAD) Standards/GuestInvite.json index 279c3913c88bc..2e5090ad29ce1 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/GuestInvite.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/GuestInvite.json @@ -57,6 +57,10 @@ "read": { "cacheType": "AuthorizationPolicy" }, + "writeTarget": "authorizationPolicy", + "writeTargetProperties": { + "allowInvitesFrom": "%allowInvitesFrom%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/NudgeMFA.json b/Config/BaselineStandards/Entra (AAD) Standards/NudgeMFA.json index aa69fd8b8dff2..0e34a0a586d84 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/NudgeMFA.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/NudgeMFA.json @@ -84,6 +84,10 @@ "cacheType": "AuthenticationMethodsPolicy" }, "prepare": "Get-CIPPBaselineNudgeMFAState", + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "registrationEnforcement.authenticationMethodsRegistrationCampaign.state": "%state%" + }, "remediate": { "executor": "NudgeMFA" } diff --git a/Config/BaselineStandards/Entra (AAD) Standards/OauthConsent.json b/Config/BaselineStandards/Entra (AAD) Standards/OauthConsent.json index 156277de11685..02c0984857455 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/OauthConsent.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/OauthConsent.json @@ -30,6 +30,10 @@ "cacheType": "AuthorizationPolicy" }, "prepare": "Get-CIPPBaselineOauthConsentState", + "writeTarget": "authorizationPolicy", + "writeTargetProperties": { + "permissionGrantPolicyIdsAssignedToDefaultUserRole": ["ManagePermissionGrantsForSelf.cipp-consent-policy"] + }, "remediate": { "executor": "OauthConsent" } diff --git a/Config/BaselineStandards/Entra (AAD) Standards/OauthConsentLowSec.json b/Config/BaselineStandards/Entra (AAD) Standards/OauthConsentLowSec.json index 3204b6e6988b1..0bdb8794c40ae 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/OauthConsentLowSec.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/OauthConsentLowSec.json @@ -25,6 +25,10 @@ "read": { "cacheType": "AuthorizationPolicy" }, + "writeTarget": "authorizationPolicy", + "writeTargetProperties": { + "permissionGrantPolicyIdsAssignedToDefaultUserRole": ["ManagePermissionGrantsForSelf.microsoft-user-default-low"] + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/PWcompanionAppAllowedState.json b/Config/BaselineStandards/Entra (AAD) Standards/PWcompanionAppAllowedState.json index d4f37adfc7dcb..554f2fa956320 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/PWcompanionAppAllowedState.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/PWcompanionAppAllowedState.json @@ -57,6 +57,10 @@ ], "object": "featureSettings.companionAppAllowedState" }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "MicrosoftAuthenticator.featureSettings.companionAppAllowedState.state": "%state%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/PWdisplayAppInformationRequiredState.json b/Config/BaselineStandards/Entra (AAD) Standards/PWdisplayAppInformationRequiredState.json index c29aaa70ad2dd..60772959f958a 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/PWdisplayAppInformationRequiredState.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/PWdisplayAppInformationRequiredState.json @@ -54,6 +54,11 @@ } ] }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "MicrosoftAuthenticator.state": "enabled", + "MicrosoftAuthenticator.featureSettings.displayAppInformationRequiredState.state": "enabled" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/SecurityDefaults.json b/Config/BaselineStandards/Entra (AAD) Standards/SecurityDefaults.json index 8cf4e43bb83db..52d2c159944df 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/SecurityDefaults.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/SecurityDefaults.json @@ -10,7 +10,7 @@ "BlockLegacyAuthentication" ], "impact": "High Impact", - "helpText": "Enables security defaults for the tenant, for newer tenants this is enabled by default. Do not enable this feature if you use Conditional Access.", + "helpText": "Enables security defaults for the tenant, for newer tenants this is enabled by default. Do not enable this feature if you use Conditional Access. Microsoft refuses to enable security defaults while any Conditional Access policy exists ('Conditional access policies are enabled. Please disable and try again.'), so remediation always fails on tenants that have CA policies.", "executiveText": "Activates Microsoft's baseline security configuration that requires multi-factor authentication and blocks legacy authentication methods. This provides essential security protection for organizations without complex conditional access policies, significantly improving security posture with minimal configuration.", "docsDescription": "Enables SD for the tenant, which disables all forms of basic authentication and enforces users to configure MFA. Users are only prompted for MFA when a logon is considered 'suspect' by Microsoft.", "impactColour": "danger", diff --git a/Config/BaselineStandards/Entra (AAD) Standards/SmartLockout.json b/Config/BaselineStandards/Entra (AAD) Standards/SmartLockout.json index d19cef09c82f5..28cf48cbb722e 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/SmartLockout.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/SmartLockout.json @@ -26,12 +26,32 @@ "LockoutDurationInSeconds": { "label": "Lockout Duration (seconds)", "type": "number", - "default": 60 + "default": 60, + "validators": { + "min": { + "value": 5, + "message": "Minimum value is 5" + }, + "max": { + "value": 18000, + "message": "Maximum value is 18000" + } + } }, "LockoutThreshold": { "label": "Lockout Threshold (failed attempts)", "type": "number", - "default": 10 + "default": 10, + "validators": { + "min": { + "value": 1, + "message": "Minimum value is 1" + }, + "max": { + "value": 50, + "message": "Maximum value is 50" + } + } }, "EnableBannedPasswordCheckOnPremises": { "label": "Enable On-Premises Password Protection", diff --git a/Config/BaselineStandards/Entra (AAD) Standards/TAP.json b/Config/BaselineStandards/Entra (AAD) Standards/TAP.json index 2178b0023bc7a..7538c35d42810 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/TAP.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/TAP.json @@ -33,25 +33,77 @@ "type": "number", "label": "Minimum Lifetime (minutes)", "default": 60, - "recommended": 60 + "recommended": 60, + "validators": { + "min": { + "value": 10, + "message": "Minimum value is 10" + }, + "max": { + "value": 43200, + "message": "Maximum value is 43200" + }, + "lessThanOrEqual": { + "field": "MaximumLifetime", + "message": "Minimum lifetime cannot exceed the maximum lifetime" + } + } }, "MaximumLifetime": { "type": "number", "label": "Maximum Lifetime (minutes)", "default": 480, - "recommended": 480 + "recommended": 480, + "validators": { + "min": { + "value": 10, + "message": "Minimum value is 10" + }, + "max": { + "value": 43200, + "message": "Maximum value is 43200" + } + } }, "DefaultLifetime": { "type": "number", "label": "Default Lifetime (minutes)", "default": 60, - "recommended": 60 + "recommended": 60, + "validators": { + "min": { + "value": 10, + "message": "Minimum value is 10" + }, + "max": { + "value": 43200, + "message": "Maximum value is 43200" + }, + "greaterThanOrEqual": { + "field": "MinimumLifetime", + "message": "Default lifetime must be at least the minimum lifetime" + }, + "lessThanOrEqual": { + "field": "MaximumLifetime", + "message": "Default lifetime cannot exceed the maximum lifetime" + } + } }, "TAPLength": { "type": "number", "label": "Length (characters)", "default": 8, - "recommended": 8 + "recommended": 8, + "validators": { + "min": { + "value": 8, + "message": "Minimum value is 8" + }, + "max": { + "value": 48, + "message": "Maximum value is 48" + } + } } }, "expected": { @@ -72,6 +124,15 @@ } ] }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "TemporaryAccessPass.state": "enabled", + "TemporaryAccessPass.isUsableOnce": "%isUsableOnce%", + "TemporaryAccessPass.minimumLifetimeInMinutes": "%MinimumLifetime%", + "TemporaryAccessPass.maximumLifetimeInMinutes": "%MaximumLifetime%", + "TemporaryAccessPass.defaultLifetimeInMinutes": "%DefaultLifetime%", + "TemporaryAccessPass.defaultLength": "%TAPLength%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/UndoOauth.json b/Config/BaselineStandards/Entra (AAD) Standards/UndoOauth.json index 1ccc22241a897..2eafed09695b6 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/UndoOauth.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/UndoOauth.json @@ -22,6 +22,10 @@ "read": { "cacheType": "AuthorizationPolicy" }, + "writeTarget": "authorizationPolicy", + "writeTargetProperties": { + "permissionGrantPolicyIdsAssignedToDefaultUserRole": ["ManagePermissionGrantsForSelf.microsoft-user-default-legacy"] + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/allowOAuthTokens.json b/Config/BaselineStandards/Entra (AAD) Standards/allowOAuthTokens.json index bf4af7a7f2419..4bebd678f9916 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/allowOAuthTokens.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/allowOAuthTokens.json @@ -52,6 +52,10 @@ } ] }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "SoftwareOath.state": "%state%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Entra (AAD) Standards/allowOTPTokens.json b/Config/BaselineStandards/Entra (AAD) Standards/allowOTPTokens.json index 5e4fbb2f59241..bb168a9fa3a5c 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/allowOTPTokens.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/allowOTPTokens.json @@ -40,6 +40,10 @@ } ] }, + "writeTarget": "authenticationMethodsPolicy", + "writeTargetProperties": { + "MicrosoftAuthenticator.isSoftwareOathEnabled": "%isSoftwareOathEnabled%" + }, "remediate": { "executor": "GraphRequest", "requests": [ @@ -48,7 +52,6 @@ "uri": "policies/authenticationMethodsPolicy/authenticationMethodConfigurations/microsoftAuthenticator", "body": { "@odata.type": "#microsoft.graph.microsoftAuthenticatorAuthenticationMethodConfiguration", - "state": "enabled", "isSoftwareOathEnabled": "%isSoftwareOathEnabled%" } } diff --git a/Config/BaselineStandards/Entra (AAD) Standards/intuneDeviceRegLocalAdmins.json b/Config/BaselineStandards/Entra (AAD) Standards/intuneDeviceRegLocalAdmins.json index 88fe41d2eb972..a4279d9f32836 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/intuneDeviceRegLocalAdmins.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/intuneDeviceRegLocalAdmins.json @@ -57,6 +57,7 @@ "cacheType": "DeviceRegistrationPolicy" }, "prepare": "Get-CIPPBaselineDeviceRegistrationPolicyState", + "writeTarget": "deviceRegistrationPolicy", "remediate": { "executor": "DeviceRegistrationPolicy", "set": { diff --git a/Config/BaselineStandards/Entra (AAD) Standards/intuneRestrictUserDeviceJoin.json b/Config/BaselineStandards/Entra (AAD) Standards/intuneRestrictUserDeviceJoin.json index 9543e96ee6f39..f0787627e51db 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/intuneRestrictUserDeviceJoin.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/intuneRestrictUserDeviceJoin.json @@ -48,6 +48,7 @@ "cacheType": "DeviceRegistrationPolicy" }, "prepare": "Get-CIPPBaselineDeviceRegistrationPolicyState", + "writeTarget": "deviceRegistrationPolicy", "remediate": { "executor": "DeviceRegistrationPolicy", "requireAdminConfigurable": "azureADJoin", diff --git a/Config/BaselineStandards/Entra (AAD) Standards/intuneRestrictUserDeviceRegistration.json b/Config/BaselineStandards/Entra (AAD) Standards/intuneRestrictUserDeviceRegistration.json index 2ac7f85115764..29fed26d2957d 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/intuneRestrictUserDeviceRegistration.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/intuneRestrictUserDeviceRegistration.json @@ -42,6 +42,7 @@ "cacheType": "DeviceRegistrationPolicy" }, "prepare": "Get-CIPPBaselineDeviceRegistrationPolicyState", + "writeTarget": "deviceRegistrationPolicy", "remediate": { "executor": "DeviceRegistrationPolicy", "requireAdminConfigurable": "azureADRegistration", diff --git a/Config/BaselineStandards/Entra (AAD) Standards/laps.json b/Config/BaselineStandards/Entra (AAD) Standards/laps.json index 75b3bfe4301ff..6168054d91281 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/laps.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/laps.json @@ -34,6 +34,7 @@ "cacheType": "DeviceRegistrationPolicy" }, "prepare": "Get-CIPPBaselineDeviceRegistrationPolicyState", + "writeTarget": "deviceRegistrationPolicy", "remediate": { "executor": "DeviceRegistrationPolicy", "set": { diff --git a/Config/BaselineStandards/Exchange Standards/AutoArchive.json b/Config/BaselineStandards/Exchange Standards/AutoArchive.json index e3a2121184fd5..367aa1ecfcfc1 100644 --- a/Config/BaselineStandards/Exchange Standards/AutoArchive.json +++ b/Config/BaselineStandards/Exchange Standards/AutoArchive.json @@ -24,7 +24,17 @@ "threshold": { "type": "number", "label": "Auto-Archiving Threshold Percentage (80-100, default 96, 100 disables)", - "default": 96 + "default": 96, + "validators": { + "min": { + "value": 80, + "message": "Exchange only accepts a threshold between 80 and 100" + }, + "max": { + "value": 100, + "message": "Exchange only accepts a threshold between 80 and 100" + } + } } }, "expected": { @@ -33,6 +43,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/AutoArchiveMailbox.json b/Config/BaselineStandards/Exchange Standards/AutoArchiveMailbox.json index 459024cf3bb57..1892e5c707bf6 100644 --- a/Config/BaselineStandards/Exchange Standards/AutoArchiveMailbox.json +++ b/Config/BaselineStandards/Exchange Standards/AutoArchiveMailbox.json @@ -33,6 +33,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/AutoExpandArchive.json b/Config/BaselineStandards/Exchange Standards/AutoExpandArchive.json index 4d108ab7dc817..a8286659465a5 100644 --- a/Config/BaselineStandards/Exchange Standards/AutoExpandArchive.json +++ b/Config/BaselineStandards/Exchange Standards/AutoExpandArchive.json @@ -27,6 +27,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/Bookings.json b/Config/BaselineStandards/Exchange Standards/Bookings.json index b5759e0204b77..59d75b09714a0 100644 --- a/Config/BaselineStandards/Exchange Standards/Bookings.json +++ b/Config/BaselineStandards/Exchange Standards/Bookings.json @@ -39,6 +39,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/CloudMessageRecall.json b/Config/BaselineStandards/Exchange Standards/CloudMessageRecall.json index 2e69e8dbbd654..7b8a404da0738 100644 --- a/Config/BaselineStandards/Exchange Standards/CloudMessageRecall.json +++ b/Config/BaselineStandards/Exchange Standards/CloudMessageRecall.json @@ -33,6 +33,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/DisableEWS.json b/Config/BaselineStandards/Exchange Standards/DisableEWS.json index c69f0bd601694..b87fdb66165de 100644 --- a/Config/BaselineStandards/Exchange Standards/DisableEWS.json +++ b/Config/BaselineStandards/Exchange Standards/DisableEWS.json @@ -36,6 +36,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/DlpViaDcsEnabled.json b/Config/BaselineStandards/Exchange Standards/DlpViaDcsEnabled.json index 3ded26f763ff7..632b19bce5b3c 100644 --- a/Config/BaselineStandards/Exchange Standards/DlpViaDcsEnabled.json +++ b/Config/BaselineStandards/Exchange Standards/DlpViaDcsEnabled.json @@ -33,6 +33,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/EXODirectSend.json b/Config/BaselineStandards/Exchange Standards/EXODirectSend.json index d11c51ef00c8e..ae57ac165de79 100644 --- a/Config/BaselineStandards/Exchange Standards/EXODirectSend.json +++ b/Config/BaselineStandards/Exchange Standards/EXODirectSend.json @@ -33,6 +33,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/EnableMailTips.json b/Config/BaselineStandards/Exchange Standards/EnableMailTips.json index a56f93b0d59fa..e74af61b85079 100644 --- a/Config/BaselineStandards/Exchange Standards/EnableMailTips.json +++ b/Config/BaselineStandards/Exchange Standards/EnableMailTips.json @@ -51,6 +51,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/EnableMailboxAuditing.json b/Config/BaselineStandards/Exchange Standards/EnableMailboxAuditing.json index 69c46dd49b9c0..4054c473cc5f3 100644 --- a/Config/BaselineStandards/Exchange Standards/EnableMailboxAuditing.json +++ b/Config/BaselineStandards/Exchange Standards/EnableMailboxAuditing.json @@ -51,6 +51,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/FocusedInbox.json b/Config/BaselineStandards/Exchange Standards/FocusedInbox.json index 2eee36981d703..b2d6b56527d1e 100644 --- a/Config/BaselineStandards/Exchange Standards/FocusedInbox.json +++ b/Config/BaselineStandards/Exchange Standards/FocusedInbox.json @@ -33,6 +33,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/MessageExpiration.json b/Config/BaselineStandards/Exchange Standards/MessageExpiration.json index d2593512570b8..568738b64e39f 100644 --- a/Config/BaselineStandards/Exchange Standards/MessageExpiration.json +++ b/Config/BaselineStandards/Exchange Standards/MessageExpiration.json @@ -25,7 +25,13 @@ "type": "textField", "label": "Message expiration timeout (hh:mm:ss)", "default": "12:00:00", - "recommended": "12:00:00" + "recommended": "12:00:00", + "validators": { + "pattern": { + "value": "^(1\\.00:00:00|(0\\.)?(1[2-9]|2[0-3]):[0-5][0-9]:[0-5][0-9])$", + "message": "Must be a timespan between 12:00:00 (12 hours) and 1.00:00:00 (24 hours)" + } + } } }, "expected": { diff --git a/Config/BaselineStandards/Exchange Standards/OMEBranding.json b/Config/BaselineStandards/Exchange Standards/OMEBranding.json index e7e564b77d032..ebc33062cc1ae 100644 --- a/Config/BaselineStandards/Exchange Standards/OMEBranding.json +++ b/Config/BaselineStandards/Exchange Standards/OMEBranding.json @@ -29,12 +29,24 @@ "BackgroundColor": { "type": "textField", "label": "Background Color (hex, e.g. #ffffff)", - "omitWhenBlank": true + "omitWhenBlank": true, + "validators": { + "pattern": { + "value": "^#[0-9A-Fa-f]{6}$", + "message": "Must be a hex color like #FFFFFF" + } + } }, "LogoUrl": { "type": "textField", "label": "Logo Image URL (max 40KB, 170x70px)", - "omitWhenBlank": true + "omitWhenBlank": true, + "validators": { + "pattern": { + "value": "^https?://.+$", + "message": "Must be a URL starting with http:// or https://" + } + } }, "IntroductionText": { "type": "textField", @@ -49,22 +61,46 @@ "EmailText": { "type": "textField", "label": "Email text below the button", - "omitWhenBlank": true + "omitWhenBlank": true, + "validators": { + "maxLength": { + "value": 1024, + "message": "Maximum length is 1024 characters" + } + } }, "PrivacyStatementUrl": { "type": "textField", "label": "Privacy Statement URL", - "omitWhenBlank": true + "omitWhenBlank": true, + "validators": { + "pattern": { + "value": "^https?://.+$", + "message": "Must be a URL starting with http:// or https://" + } + } }, "DisclaimerText": { "type": "textField", "label": "Disclaimer Statement", - "omitWhenBlank": true + "omitWhenBlank": true, + "validators": { + "maxLength": { + "value": 1024, + "message": "Maximum length is 1024 characters" + } + } }, "PortalText": { "type": "textField", "label": "Portal header text (max 128 chars)", - "omitWhenBlank": true + "omitWhenBlank": true, + "validators": { + "maxLength": { + "value": 128, + "message": "Maximum length is 128 characters" + } + } }, "OTPEnabled": { "type": "autoComplete", diff --git a/Config/BaselineStandards/Exchange Standards/OutBoundSpamAlert.json b/Config/BaselineStandards/Exchange Standards/OutBoundSpamAlert.json index 3cce7f7b8dc13..31ed550810b89 100644 --- a/Config/BaselineStandards/Exchange Standards/OutBoundSpamAlert.json +++ b/Config/BaselineStandards/Exchange Standards/OutBoundSpamAlert.json @@ -39,13 +39,24 @@ "type": "textField", "label": "Outbound spam contact", "required": true + }, + "BccSuspiciousOutboundMail": { + "type": "switch", + "label": "BCC suspicious outbound mail to a mailbox", + "omitWhenBlank": true + }, + "BccSuspiciousOutboundContact": { + "type": "textField", + "label": "BCC recipient for suspicious outbound mail", + "omitWhenBlank": true } }, "expected": { "NotifyOutboundSpam": "%NotifyOutboundSpam%", "NotifyOutboundSpamRecipients": [ "%OutboundSpamContact%" - ] + ], + "BccSuspiciousOutboundMail": "%BccSuspiciousOutboundMail%" }, "read": { "cacheType": "ExoHostedOutboundSpamFilterPolicy", @@ -64,7 +75,9 @@ "params": { "Identity": "Default", "NotifyOutboundSpam": "%NotifyOutboundSpam%", - "NotifyOutboundSpamRecipients": "%OutboundSpamContact%" + "NotifyOutboundSpamRecipients": "%OutboundSpamContact%", + "BccSuspiciousOutboundMail": "%BccSuspiciousOutboundMail%", + "BccSuspiciousOutboundAdditionalRecipients": "%BccSuspiciousOutboundContact%" } } ] diff --git a/Config/BaselineStandards/Exchange Standards/SendFromAlias.json b/Config/BaselineStandards/Exchange Standards/SendFromAlias.json index 574c809dd404f..287173bd632ab 100644 --- a/Config/BaselineStandards/Exchange Standards/SendFromAlias.json +++ b/Config/BaselineStandards/Exchange Standards/SendFromAlias.json @@ -36,6 +36,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/ShortenMeetings.json b/Config/BaselineStandards/Exchange Standards/ShortenMeetings.json index 9082a37500c34..eda397fe9c206 100644 --- a/Config/BaselineStandards/Exchange Standards/ShortenMeetings.json +++ b/Config/BaselineStandards/Exchange Standards/ShortenMeetings.json @@ -58,6 +58,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/TeamsMeetingsByDefault.json b/Config/BaselineStandards/Exchange Standards/TeamsMeetingsByDefault.json index 3153192383da8..94c1334099cd3 100644 --- a/Config/BaselineStandards/Exchange Standards/TeamsMeetingsByDefault.json +++ b/Config/BaselineStandards/Exchange Standards/TeamsMeetingsByDefault.json @@ -35,6 +35,7 @@ "OnlineMeetingsByDefaultEnabled": true } }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/TwoClickEmailProtection.json b/Config/BaselineStandards/Exchange Standards/TwoClickEmailProtection.json index 5d268d6dba918..beeaf7c8bde81 100644 --- a/Config/BaselineStandards/Exchange Standards/TwoClickEmailProtection.json +++ b/Config/BaselineStandards/Exchange Standards/TwoClickEmailProtection.json @@ -33,6 +33,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Exchange Standards/UserSubmissions.json b/Config/BaselineStandards/Exchange Standards/UserSubmissions.json index d4613f5223e4b..fe4a5ff14ccf7 100644 --- a/Config/BaselineStandards/Exchange Standards/UserSubmissions.json +++ b/Config/BaselineStandards/Exchange Standards/UserSubmissions.json @@ -4,9 +4,9 @@ "cat": "Exchange Standards", "tag": [], "impact": "Medium Impact", - "helpText": "Enables or disables the built-in Report button in Outlook, optionally routing reported messages to a custom mailbox as well as Microsoft.", + "helpText": "Enables or disables the built-in Report button in Outlook, optionally routing reported messages to a custom mailbox as well as, or instead of, Microsoft.", "executiveText": "Governs how employees report suspicious email: enabling the built-in report button routes phishing reports to Microsoft and optionally to the security team, turning users into a detection layer.", - "docsDescription": "Grades the report submission policy and rule against the chosen posture: enabled (reports to Microsoft), enabled with a custom address (all three report types route to it and the rule is enabled), or disabled. The configured address supports tenant %variable% replacement. Remediation creates or updates the default policy and rule, removing the rule when reporting is turned off.", + "docsDescription": "Grades the report submission policy and rule against the chosen posture: enabled (reports to Microsoft), enabled with a custom address (all three report types route to it and the rule is enabled), or disabled. When a custom address is set, the 'Send reported items to' setting controls whether reports also go to Microsoft or to the reporting mailbox only (for third-party phishing report services). The configured address supports tenant %variable% replacement. Remediation creates or updates the default policy and rule, removing the rule when reporting is turned off.", "impactColour": "warning", "addedDate": "2026-08-16", "powershellEquivalent": "New-ReportSubmissionPolicy or Set-ReportSubmissionPolicy", @@ -46,6 +46,23 @@ "omitWhenBlank": true, "type": "textField", "label": "Destination email address (optional)" + }, + "reportDestination": { + "omitWhenBlank": true, + "type": "autoComplete", + "required": false, + "creatable": false, + "options": [ + { + "label": "Microsoft and my reporting mailbox", + "value": "Both" + }, + { + "label": "My reporting mailbox only", + "value": "Mailbox" + } + ], + "label": "Send reported items to (when a destination email address is set)" } }, "read": { diff --git a/Config/BaselineStandards/Global Standards/DisableGuestDirectory.json b/Config/BaselineStandards/Global Standards/DisableGuestDirectory.json index f9230b63c68fe..bb3ee5b94a7af 100644 --- a/Config/BaselineStandards/Global Standards/DisableGuestDirectory.json +++ b/Config/BaselineStandards/Global Standards/DisableGuestDirectory.json @@ -61,6 +61,10 @@ "read": { "cacheType": "AuthorizationPolicy" }, + "writeTarget": "authorizationPolicy", + "writeTargetProperties": { + "guestUserRoleId": "%guestUserRoleId%" + }, "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/Global Standards/EnableCustomerLockbox.json b/Config/BaselineStandards/Global Standards/EnableCustomerLockbox.json index b63d5f7c3a0f2..6c2264882e82e 100644 --- a/Config/BaselineStandards/Global Standards/EnableCustomerLockbox.json +++ b/Config/BaselineStandards/Global Standards/EnableCustomerLockbox.json @@ -40,6 +40,7 @@ "read": { "cacheType": "ExoOrganizationConfig" }, + "writeTarget": "exoOrganizationConfig", "remediate": { "executor": "ExoRequest", "cmdlets": [ diff --git a/Config/BaselineStandards/Intune Standards/DefaultPlatformRestrictions.json b/Config/BaselineStandards/Intune Standards/DefaultPlatformRestrictions.json index fc6d8b5ac222a..7a8c90de67ac0 100644 --- a/Config/BaselineStandards/Intune Standards/DefaultPlatformRestrictions.json +++ b/Config/BaselineStandards/Intune Standards/DefaultPlatformRestrictions.json @@ -4,9 +4,9 @@ "cat": "Intune Standards", "tag": [], "impact": "High Impact", - "helpText": "Sets the default enrollment platform restrictions, controlling which device platforms may enroll and whether personally-owned devices of each platform are allowed.", - "executiveText": "Controls which kinds of device can enrol into management, and whether employees may enrol personal devices. This keeps unmanaged or unsupported platforms off corporate resources.", - "docsDescription": "Sets the default device enrollment platform restrictions for Android, Android for Work, iOS, macOS and Windows.", + "helpText": "Sets the default enrollment platform restrictions, controlling which device platforms may enroll, whether personally-owned devices of each platform are allowed, and the minimum/maximum OS version each platform may enroll with.", + "executiveText": "Controls which kinds of device can enrol into management, whether employees may enrol personal devices, and how up to date a device's operating system must be to enrol. This keeps unmanaged, unsupported or out-of-date platforms off corporate resources.", + "docsDescription": "Sets the default device enrollment platform restrictions for Android, Android for Work, iOS, macOS and Windows, including optional minimum and maximum OS version limits per platform.", "impactColour": "warning", "addedDate": "2024-07-15", "powershellEquivalent": "Graph API", @@ -31,6 +31,32 @@ "label": "Block personally owned Android (work profile)", "default": false }, + "osMinimumVersionAndroidForWork": { + "type": "textField", + "label": "Android (work profile) minimum OS version", + "helperText": "Example: 11.0. Leave blank to not enforce a minimum.", + "omitWhenBlank": true, + "default": "", + "validators": { + "pattern": { + "value": "^\\d+(\\.\\d+)*$", + "message": "Must be a version number using digits and dots, e.g. 11.0" + } + } + }, + "osMaximumVersionAndroidForWork": { + "type": "textField", + "label": "Android (work profile) maximum OS version", + "helperText": "Example: 14.0. Leave blank to not enforce a maximum.", + "omitWhenBlank": true, + "default": "", + "validators": { + "pattern": { + "value": "^\\d+(\\.\\d+)*$", + "message": "Must be a version number using digits and dots, e.g. 14.0" + } + } + }, "platformAndroidBlocked": { "type": "switch", "label": "Block Android (device administrator) platform", @@ -41,6 +67,32 @@ "label": "Block personally owned Android (device administrator)", "default": false }, + "osMinimumVersionAndroid": { + "type": "textField", + "label": "Android (device administrator) minimum OS version", + "helperText": "Example: 10.0. Leave blank to not enforce a minimum.", + "omitWhenBlank": true, + "default": "", + "validators": { + "pattern": { + "value": "^\\d+(\\.\\d+)*$", + "message": "Must be a version number using digits and dots, e.g. 10.0" + } + } + }, + "osMaximumVersionAndroid": { + "type": "textField", + "label": "Android (device administrator) maximum OS version", + "helperText": "Example: 13.0. Leave blank to not enforce a maximum.", + "omitWhenBlank": true, + "default": "", + "validators": { + "pattern": { + "value": "^\\d+(\\.\\d+)*$", + "message": "Must be a version number using digits and dots, e.g. 13.0" + } + } + }, "platformiOSBlocked": { "type": "switch", "label": "Block iOS platform", @@ -51,6 +103,32 @@ "label": "Block personally owned iOS", "default": false }, + "osMinimumVersioniOS": { + "type": "textField", + "label": "iOS/iPadOS minimum OS version", + "helperText": "Example: 16.1. Leave blank to not enforce a minimum.", + "omitWhenBlank": true, + "default": "", + "validators": { + "pattern": { + "value": "^\\d+(\\.\\d+)*$", + "message": "Must be a version number using digits and dots, e.g. 16.1" + } + } + }, + "osMaximumVersioniOS": { + "type": "textField", + "label": "iOS/iPadOS maximum OS version", + "helperText": "Example: 18.0. Leave blank to not enforce a maximum.", + "omitWhenBlank": true, + "default": "", + "validators": { + "pattern": { + "value": "^\\d+(\\.\\d+)*$", + "message": "Must be a version number using digits and dots, e.g. 18.0" + } + } + }, "platformMacOSBlocked": { "type": "switch", "label": "Block macOS platform", @@ -70,6 +148,32 @@ "type": "switch", "label": "Block personally owned Windows", "default": false + }, + "osMinimumVersionWindows": { + "type": "textField", + "label": "Windows minimum OS version", + "helperText": "Example: 10.0.19045.0. Leave blank to not enforce a minimum.", + "omitWhenBlank": true, + "default": "", + "validators": { + "pattern": { + "value": "^\\d+(\\.\\d+)*$", + "message": "Must be a version number using digits and dots, e.g. 10.0.19045.0" + } + } + }, + "osMaximumVersionWindows": { + "type": "textField", + "label": "Windows maximum OS version", + "helperText": "Example: 10.0.22631.0. Leave blank to not enforce a maximum.", + "omitWhenBlank": true, + "default": "", + "validators": { + "pattern": { + "value": "^\\d+(\\.\\d+)*$", + "message": "Must be a version number using digits and dots, e.g. 10.0.22631.0" + } + } } }, "read": { @@ -83,17 +187,23 @@ "androidForWorkRestriction": { "@odata.type": "microsoft.graph.deviceEnrollmentPlatformRestriction", "platformBlocked": "%platformAndroidForWorkBlocked%", - "personalDeviceEnrollmentBlocked": "%personalAndroidForWorkBlocked%" + "personalDeviceEnrollmentBlocked": "%personalAndroidForWorkBlocked%", + "osMinimumVersion": "%osMinimumVersionAndroidForWork%", + "osMaximumVersion": "%osMaximumVersionAndroidForWork%" }, "androidRestriction": { "@odata.type": "microsoft.graph.deviceEnrollmentPlatformRestriction", "platformBlocked": "%platformAndroidBlocked%", - "personalDeviceEnrollmentBlocked": "%personalAndroidBlocked%" + "personalDeviceEnrollmentBlocked": "%personalAndroidBlocked%", + "osMinimumVersion": "%osMinimumVersionAndroid%", + "osMaximumVersion": "%osMaximumVersionAndroid%" }, "iosRestriction": { "@odata.type": "microsoft.graph.deviceEnrollmentPlatformRestriction", "platformBlocked": "%platformiOSBlocked%", - "personalDeviceEnrollmentBlocked": "%personaliOSBlocked%" + "personalDeviceEnrollmentBlocked": "%personaliOSBlocked%", + "osMinimumVersion": "%osMinimumVersioniOS%", + "osMaximumVersion": "%osMaximumVersioniOS%" }, "macOSRestriction": { "@odata.type": "microsoft.graph.deviceEnrollmentPlatformRestriction", @@ -103,7 +213,9 @@ "windowsRestriction": { "@odata.type": "microsoft.graph.deviceEnrollmentPlatformRestriction", "platformBlocked": "%platformWindowsBlocked%", - "personalDeviceEnrollmentBlocked": "%personalWindowsBlocked%" + "personalDeviceEnrollmentBlocked": "%personalWindowsBlocked%", + "osMinimumVersion": "%osMinimumVersionWindows%", + "osMaximumVersion": "%osMaximumVersionWindows%" } } } diff --git a/Config/BaselineStandards/Intune Standards/IntuneAppTemplateDeploy.json b/Config/BaselineStandards/Intune Standards/IntuneAppTemplateDeploy.json index 69585a845b6fa..a80fc86166c9a 100644 --- a/Config/BaselineStandards/Intune Standards/IntuneAppTemplateDeploy.json +++ b/Config/BaselineStandards/Intune Standards/IntuneAppTemplateDeploy.json @@ -34,9 +34,10 @@ "required": true, "api": { "url": "/api/ListAppTemplates", - "labelField": "Displayname", + "labelField": "displayName", "valueField": "GUID", - "queryKey": "StdIntuneAppTemplateList" + "queryKey": "StdIntuneAppTemplateList", + "templateView": { "title": "Application Template" } } } }, diff --git a/Config/BaselineStandards/Intune Standards/intuneBrandingProfile.json b/Config/BaselineStandards/Intune Standards/intuneBrandingProfile.json index ebfe909156d3a..aba9ffc4a5e6c 100644 --- a/Config/BaselineStandards/Intune Standards/intuneBrandingProfile.json +++ b/Config/BaselineStandards/Intune Standards/intuneBrandingProfile.json @@ -25,7 +25,13 @@ "type": "textField", "label": "Organization name", "omitWhenBlank": true, - "default": "" + "default": "", + "validators": { + "maxLength": { + "value": 40, + "message": "Maximum length is 40 characters" + } + } }, "showLogo": { "type": "autoComplete", @@ -73,19 +79,41 @@ "type": "textField", "label": "Contact IT name", "omitWhenBlank": true, - "default": "" + "default": "", + "validators": { + "maxLength": { + "value": 40, + "message": "Maximum length is 40 characters" + } + } }, "contactITPhoneNumber": { "type": "textField", "label": "Contact IT phone number", "omitWhenBlank": true, - "default": "" + "default": "", + "validators": { + "pattern": { + "value": "^\\+?(?=(?:[^0-9]*[0-9]){3})[0-9 ()./-]{3,}$", + "message": "Must be a phone number, e.g. +31612345678" + } + } }, "contactITEmailAddress": { "type": "textField", "label": "Contact IT email address", "omitWhenBlank": true, - "default": "" + "default": "", + "validators": { + "pattern": { + "value": "^[^\\s@]+@[^\\s@]+\\.[^\\s@]+$", + "message": "Must be a valid e-mail address" + }, + "maxLength": { + "value": 40, + "message": "Maximum length is 40 characters" + } + } }, "contactITNotes": { "type": "textField", @@ -97,19 +125,37 @@ "type": "textField", "label": "Online support site name", "omitWhenBlank": true, - "default": "" + "default": "", + "validators": { + "maxLength": { + "value": 40, + "message": "Maximum length is 40 characters" + } + } }, "onlineSupportSiteUrl": { "type": "textField", "label": "Online support site URL", "omitWhenBlank": true, - "default": "" + "default": "", + "validators": { + "pattern": { + "value": "^https?://.+$", + "message": "Must be a URL starting with http:// or https://" + } + } }, "privacyUrl": { "type": "textField", "label": "Privacy statement URL", "omitWhenBlank": true, - "default": "" + "default": "", + "validators": { + "pattern": { + "value": "^https?://.+$", + "message": "Must be a URL starting with http:// or https://" + } + } } }, "expected": { diff --git a/Config/BaselineStandards/Intune Standards/intuneDeviceReg.json b/Config/BaselineStandards/Intune Standards/intuneDeviceReg.json index 63936bd5cd110..66cf606d304ec 100644 --- a/Config/BaselineStandards/Intune Standards/intuneDeviceReg.json +++ b/Config/BaselineStandards/Intune Standards/intuneDeviceReg.json @@ -44,6 +44,7 @@ "cacheType": "DeviceRegistrationPolicy" }, "prepare": "Get-CIPPBaselineDeviceRegistrationPolicyState", + "writeTarget": "deviceRegistrationPolicy", "remediate": { "executor": "DeviceRegistrationPolicy", "set": { diff --git a/Config/BaselineStandards/Intune Standards/intuneDeviceRetirementDays.json b/Config/BaselineStandards/Intune Standards/intuneDeviceRetirementDays.json index 07b08eb0c81b2..4d70a5e231e99 100644 --- a/Config/BaselineStandards/Intune Standards/intuneDeviceRetirementDays.json +++ b/Config/BaselineStandards/Intune Standards/intuneDeviceRetirementDays.json @@ -28,8 +28,18 @@ "variables": { "days": { "type": "number", - "label": "Maximum days of inactivity before retirement", - "required": true + "label": "Maximum days of inactivity before retirement (30-270)", + "required": true, + "validators": { + "min": { + "value": 30, + "message": "Intune only accepts a retirement window between 30 and 270 days" + }, + "max": { + "value": 270, + "message": "Intune only accepts a retirement window between 30 and 270 days" + } + } } }, "read": { diff --git a/Config/BaselineStandards/Intune Standards/intuneRequireMFA.json b/Config/BaselineStandards/Intune Standards/intuneRequireMFA.json index d507be5cc7fcd..6d9fd11bacf8f 100644 --- a/Config/BaselineStandards/Intune Standards/intuneRequireMFA.json +++ b/Config/BaselineStandards/Intune Standards/intuneRequireMFA.json @@ -27,6 +27,7 @@ "cacheType": "DeviceRegistrationPolicy" }, "prepare": "Get-CIPPBaselineDeviceRegistrationPolicyState", + "writeTarget": "deviceRegistrationPolicy", "remediate": { "executor": "DeviceRegistrationPolicy", "set": { diff --git a/Config/BaselineStandards/SharePoint Standards/DefaultSharingLink.json b/Config/BaselineStandards/SharePoint Standards/DefaultSharingLink.json index 80f3ca3421dd7..8e774517bb255 100644 --- a/Config/BaselineStandards/SharePoint Standards/DefaultSharingLink.json +++ b/Config/BaselineStandards/SharePoint Standards/DefaultSharingLink.json @@ -58,6 +58,10 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", + "writeTargetProperties": { + "DefaultSharingLinkType": "%SharingLinkType%" + }, "remediate": { "executor": "SPOTenant", "properties": { diff --git a/Config/BaselineStandards/SharePoint Standards/DeletedUserRentention.json b/Config/BaselineStandards/SharePoint Standards/DeletedUserRentention.json index 86635bc3e9337..a4b539b179bb8 100644 --- a/Config/BaselineStandards/SharePoint Standards/DeletedUserRentention.json +++ b/Config/BaselineStandards/SharePoint Standards/DeletedUserRentention.json @@ -89,6 +89,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/SharePoint Standards/DisableAddShortcutsToOneDrive.json b/Config/BaselineStandards/SharePoint Standards/DisableAddShortcutsToOneDrive.json index 76c29a6a249cb..1b0183f977e61 100644 --- a/Config/BaselineStandards/SharePoint Standards/DisableAddShortcutsToOneDrive.json +++ b/Config/BaselineStandards/SharePoint Standards/DisableAddShortcutsToOneDrive.json @@ -33,6 +33,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "SPOTenant", "properties": { diff --git a/Config/BaselineStandards/SharePoint Standards/DisableReshare.json b/Config/BaselineStandards/SharePoint Standards/DisableReshare.json index 0bbe40a78f6a6..f2f6fe4173a16 100644 --- a/Config/BaselineStandards/SharePoint Standards/DisableReshare.json +++ b/Config/BaselineStandards/SharePoint Standards/DisableReshare.json @@ -42,6 +42,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/SharePoint Standards/DisableSharePointLegacyAuth.json b/Config/BaselineStandards/SharePoint Standards/DisableSharePointLegacyAuth.json index b3355e0d72c0e..fb78322e38d13 100644 --- a/Config/BaselineStandards/SharePoint Standards/DisableSharePointLegacyAuth.json +++ b/Config/BaselineStandards/SharePoint Standards/DisableSharePointLegacyAuth.json @@ -49,6 +49,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/SharePoint Standards/SPAzureB2B.json b/Config/BaselineStandards/SharePoint Standards/SPAzureB2B.json index ef02a058885e7..dbc1d713a6f6f 100644 --- a/Config/BaselineStandards/SharePoint Standards/SPAzureB2B.json +++ b/Config/BaselineStandards/SharePoint Standards/SPAzureB2B.json @@ -34,6 +34,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "SPOTenant", "properties": { diff --git a/Config/BaselineStandards/SharePoint Standards/SPDirectSharing.json b/Config/BaselineStandards/SharePoint Standards/SPDirectSharing.json index 9af5d99d21722..c49f631f03920 100644 --- a/Config/BaselineStandards/SharePoint Standards/SPDirectSharing.json +++ b/Config/BaselineStandards/SharePoint Standards/SPDirectSharing.json @@ -31,6 +31,10 @@ "cacheType": "SPOTenant" }, "prepare": "Get-CIPPBaselineSPDirectSharingState", + "writeTarget": "spoTenant", + "writeTargetProperties": { + "DefaultSharingLinkType": "Direct" + }, "remediate": { "executor": "SPDirectSharing" } diff --git a/Config/BaselineStandards/SharePoint Standards/SPDisableCustomScripts.json b/Config/BaselineStandards/SharePoint Standards/SPDisableCustomScripts.json index e2de4c364f9c3..3e261534e39ff 100644 --- a/Config/BaselineStandards/SharePoint Standards/SPDisableCustomScripts.json +++ b/Config/BaselineStandards/SharePoint Standards/SPDisableCustomScripts.json @@ -30,6 +30,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "SPOTenant", "properties": { diff --git a/Config/BaselineStandards/SharePoint Standards/SPDisableLegacyWorkflows.json b/Config/BaselineStandards/SharePoint Standards/SPDisableLegacyWorkflows.json index 6b6b48e68d942..9dae8d7cf8529 100644 --- a/Config/BaselineStandards/SharePoint Standards/SPDisableLegacyWorkflows.json +++ b/Config/BaselineStandards/SharePoint Standards/SPDisableLegacyWorkflows.json @@ -29,6 +29,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "SPOTenant", "properties": { diff --git a/Config/BaselineStandards/SharePoint Standards/SPDisableStoreAccess.json b/Config/BaselineStandards/SharePoint Standards/SPDisableStoreAccess.json index fbdf3cf341344..5c19e0819ef55 100644 --- a/Config/BaselineStandards/SharePoint Standards/SPDisableStoreAccess.json +++ b/Config/BaselineStandards/SharePoint Standards/SPDisableStoreAccess.json @@ -30,6 +30,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "SPOTenant", "properties": { diff --git a/Config/BaselineStandards/SharePoint Standards/SPDisallowInfectedFiles.json b/Config/BaselineStandards/SharePoint Standards/SPDisallowInfectedFiles.json index 151a3f03f4dd6..b3f34888562bb 100644 --- a/Config/BaselineStandards/SharePoint Standards/SPDisallowInfectedFiles.json +++ b/Config/BaselineStandards/SharePoint Standards/SPDisallowInfectedFiles.json @@ -38,6 +38,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "SPOTenant", "properties": { diff --git a/Config/BaselineStandards/SharePoint Standards/SPEmailAttestation.json b/Config/BaselineStandards/SharePoint Standards/SPEmailAttestation.json index 2134d650b075e..bf768e2feb056 100644 --- a/Config/BaselineStandards/SharePoint Standards/SPEmailAttestation.json +++ b/Config/BaselineStandards/SharePoint Standards/SPEmailAttestation.json @@ -45,6 +45,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "SPOTenant", "properties": { diff --git a/Config/BaselineStandards/SharePoint Standards/SPExternalUserExpiration.json b/Config/BaselineStandards/SharePoint Standards/SPExternalUserExpiration.json index 4eb3ad407cb95..ab826a4f6a468 100644 --- a/Config/BaselineStandards/SharePoint Standards/SPExternalUserExpiration.json +++ b/Config/BaselineStandards/SharePoint Standards/SPExternalUserExpiration.json @@ -35,7 +35,11 @@ "days": { "type": "number", "label": "Days until expiration (Default 60)", - "default": 60 + "default": 60, + "validators": { + "min": { "value": 30, "message": "SharePoint accepts 30 to 730 days - lower values are silently ignored" }, + "max": { "value": 730, "message": "SharePoint accepts 30 to 730 days" } + } } }, "expected": { @@ -45,6 +49,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "SPOTenant", "properties": { diff --git a/Config/BaselineStandards/SharePoint Standards/SPFileRequests.json b/Config/BaselineStandards/SharePoint Standards/SPFileRequests.json index bb42f444ffcee..72558f5b514a5 100644 --- a/Config/BaselineStandards/SharePoint Standards/SPFileRequests.json +++ b/Config/BaselineStandards/SharePoint Standards/SPFileRequests.json @@ -56,6 +56,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "SPOTenant", "properties": { diff --git a/Config/BaselineStandards/SharePoint Standards/SPGuestPeoplePicker.json b/Config/BaselineStandards/SharePoint Standards/SPGuestPeoplePicker.json new file mode 100644 index 0000000000000..1990aeef1d931 --- /dev/null +++ b/Config/BaselineStandards/SharePoint Standards/SPGuestPeoplePicker.json @@ -0,0 +1,42 @@ +{ + "name": "SPGuestPeoplePicker", + "label": "Show guest users in the SharePoint People Picker", + "cat": "SharePoint Standards", + "tag": [], + "impact": "Low Impact", + "helpText": "Controls whether guest (external) users already in the tenant appear as suggestions in the SharePoint and OneDrive People Picker. Enforces the wanted state on BOTH the tenant default and every existing site collection - the two are set independently, so changing the tenant default does not update existing sites. Which sites differ is read from the daily SharePoint cache, and the write sweep runs at most once per 24h per tenant so it never re-runs against a stale cache.", + "executiveText": "Makes existing external collaborators discoverable (or hidden) when sharing SharePoint and OneDrive content, consistently across the whole tenant - the default for new sites and every existing site. This keeps the sharing experience predictable and prevents individual sites from drifting away from the agreed collaboration posture.", + "docsDescription": "Enforces ShowPeoplePickerSuggestionsForGuestUsers at both levels it is set independently: the tenant default and each site collection. Which sites differ is read from the SPOSites reporting cache (populated by the daily SharePoint cache run); the tenant default is read from the cached SharePoint tenant configuration. It reports the tenant default and every differing site as offenders and remediates the tenant default (Set-SPOTenant) and each offending site (Set-SPOSite), sweeping the sites concurrently. The sweep is guarded to once per 24h per tenant (shared with the classic standard) so it is not repeated before the next daily cache run reflects the change and the standard re-evaluates. Guests are not shown by default even when they exist in the tenant, and changing the tenant default does not retroactively change existing sites - which is why both are covered here.", + "impactColour": "info", + "addedDate": "2026-09-03", + "powershellEquivalent": "Set-SPOTenant / Set-SPOSite -ShowPeoplePickerSuggestionsForGuestUsers $true or $false", + "recommendedBy": ["CIPP"], + "requiredCapabilities": [ + "SHAREPOINTWAC", + "SHAREPOINTSTANDARD", + "SHAREPOINTENTERPRISE", + "SHAREPOINTENTERPRISE_EDU", + "ONEDRIVE_BASIC", + "ONEDRIVE_ENTERPRISE" + ], + "secureScoreImpact": 0, + "compare": "subset", + "variables": { + "showGuests": { + "type": "switch", + "label": "Show guests in the People Picker", + "default": true + } + }, + "expected": { + "offenders": [] + }, + "read": { + "cacheType": "SPOSites" + }, + "prepare": "Get-CIPPBaselineSPGuestPeoplePickerState", + "remediate": { + "executor": "SPGuestPeoplePicker", + "useCertificate": true + } +} diff --git a/Config/BaselineStandards/SharePoint Standards/SPOVersionControl.json b/Config/BaselineStandards/SharePoint Standards/SPOVersionControl.json index 69daff377ec48..74b86ec897293 100644 --- a/Config/BaselineStandards/SharePoint Standards/SPOVersionControl.json +++ b/Config/BaselineStandards/SharePoint Standards/SPOVersionControl.json @@ -52,6 +52,7 @@ "cacheType": "SPOTenant" }, "prepare": "Get-CIPPBaselineSPOVersionControlState", + "writeTarget": "spoTenant", "remediate": { "executor": "SPOVersionControl", "enableAutoTrim": "%EnableAutoTrim%", diff --git a/Config/BaselineStandards/SharePoint Standards/SPSyncButtonState.json b/Config/BaselineStandards/SharePoint Standards/SPSyncButtonState.json index 4aa047be72d00..3ee76016b1df4 100644 --- a/Config/BaselineStandards/SharePoint Standards/SPSyncButtonState.json +++ b/Config/BaselineStandards/SharePoint Standards/SPSyncButtonState.json @@ -33,6 +33,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "SPOTenant", "properties": { diff --git a/Config/BaselineStandards/SharePoint Standards/disableMacSync.json b/Config/BaselineStandards/SharePoint Standards/disableMacSync.json index 1ae3fc1112a72..ae9e7dbcc05f9 100644 --- a/Config/BaselineStandards/SharePoint Standards/disableMacSync.json +++ b/Config/BaselineStandards/SharePoint Standards/disableMacSync.json @@ -27,6 +27,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "GraphRequest", "requests": [ diff --git a/Config/BaselineStandards/SharePoint Standards/sharingCapability.json b/Config/BaselineStandards/SharePoint Standards/sharingCapability.json index 458fbf2a640f0..e1765c48fe43b 100644 --- a/Config/BaselineStandards/SharePoint Standards/sharingCapability.json +++ b/Config/BaselineStandards/SharePoint Standards/sharingCapability.json @@ -66,6 +66,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "SPOTenant", "properties": { diff --git a/Config/BaselineStandards/SharePoint Standards/unmanagedSync.json b/Config/BaselineStandards/SharePoint Standards/unmanagedSync.json index 50cb67bac1597..4913da87e045c 100644 --- a/Config/BaselineStandards/SharePoint Standards/unmanagedSync.json +++ b/Config/BaselineStandards/SharePoint Standards/unmanagedSync.json @@ -51,6 +51,7 @@ "read": { "cacheType": "SPOTenant" }, + "writeTarget": "spoTenant", "remediate": { "executor": "SPOTenant", "properties": { diff --git a/Config/BaselineStandards/Teams Standards/TeamsGlobalMeetingPolicy.json b/Config/BaselineStandards/Teams Standards/TeamsGlobalMeetingPolicy.json index 6de2a8d3b540f..abed7caa5e62e 100644 --- a/Config/BaselineStandards/Teams Standards/TeamsGlobalMeetingPolicy.json +++ b/Config/BaselineStandards/Teams Standards/TeamsGlobalMeetingPolicy.json @@ -84,6 +84,7 @@ "AutoAdmittedUsers": { "type": "autoComplete", "label": "Who can bypass the lobby?", + "helperText": "Teams couples this to the dial-in bypass switch: 'Everyone' requires that switch on, 'Only organizers and co-organizers' requires it off - other pairings are rejected with error 40013.", "omitWhenBlank": true, "options": [ { @@ -117,6 +118,7 @@ "AllowPSTNUsersToBypassLobby": { "type": "switch", "label": "Allow dial-in users to bypass lobby", + "helperText": "Must be on when 'Who can bypass the lobby?' is 'Everyone' and off when it is 'Only organizers and co-organizers' - Teams rejects any other combination.", "default": false, "recommended": false }, @@ -151,6 +153,32 @@ "label": "External participants can give or request control", "default": false, "recommended": false + }, + "AllowExternalNonTrustedMeetingChat": { + "type": "autoComplete", + "label": "External meeting chat", + "helperText": "CIS 8.5.8 recommends Off. Leave blank to keep the tenant's current value.", + "omitWhenBlank": true, + "options": [ + { "label": "Keep the tenant's current value", "value": "" }, + { "label": "Off (CIS recommended)", "value": false }, + { "label": "On", "value": true } + ], + "default": "", + "recommended": false + }, + "AllowCloudRecording": { + "type": "autoComplete", + "label": "Meeting cloud recording", + "helperText": "CIS 8.5.9 recommends Off. Leave blank to keep the tenant's current value.", + "omitWhenBlank": true, + "options": [ + { "label": "Keep the tenant's current value", "value": "" }, + { "label": "Off (CIS recommended)", "value": false }, + { "label": "On", "value": true } + ], + "default": "", + "recommended": false } }, "expected": { @@ -161,7 +189,9 @@ "MeetingChatEnabledType": "%MeetingChatEnabledType%", "DesignatedPresenterRoleMode": "%DesignatedPresenterRoleMode%", "AllowExternalParticipantGiveRequestControl": "%AllowExternalParticipantGiveRequestControl%", - "AllowParticipantGiveRequestControl": "%AllowParticipantGiveRequestControl%" + "AllowParticipantGiveRequestControl": "%AllowParticipantGiveRequestControl%", + "AllowExternalNonTrustedMeetingChat": "%AllowExternalNonTrustedMeetingChat%", + "AllowCloudRecording": "%AllowCloudRecording%" }, "read": { "cacheType": "CsTeamsMeetingPolicy" @@ -179,7 +209,9 @@ "MeetingChatEnabledType": "%MeetingChatEnabledType%", "DesignatedPresenterRoleMode": "%DesignatedPresenterRoleMode%", "AllowExternalParticipantGiveRequestControl": "%AllowExternalParticipantGiveRequestControl%", - "AllowParticipantGiveRequestControl": "%AllowParticipantGiveRequestControl%" + "AllowParticipantGiveRequestControl": "%AllowParticipantGiveRequestControl%", + "AllowExternalNonTrustedMeetingChat": "%AllowExternalNonTrustedMeetingChat%", + "AllowCloudRecording": "%AllowCloudRecording%" } } ] diff --git a/Config/CIPPDBCacheTypes.json b/Config/CIPPDBCacheTypes.json index 07903eacec24b..08da042719e89 100644 --- a/Config/CIPPDBCacheTypes.json +++ b/Config/CIPPDBCacheTypes.json @@ -276,6 +276,7 @@ }, { "type": "OneDriveSiteListing", + "collectedBy": "OneDriveUsage", "friendlyName": "OneDrive Site Listing", "description": "OneDrive personal site listing details used for usage reporting" }, @@ -284,8 +285,14 @@ "friendlyName": "OneDrive Usage", "description": "OneDrive usage statistics" }, + { + "type": "OneDriveLongPaths", + "friendlyName": "OneDrive Long Paths", + "description": "Per-user counts of OneDrive paths that may exceed Windows 260-character sync limits or the cloud 400-character ceiling (no file or folder names stored)" + }, { "type": "SharePointSiteListing", + "collectedBy": "SharePointSiteUsage", "friendlyName": "SharePoint Site Listing", "description": "SharePoint site listing details used for usage reporting" }, @@ -309,6 +316,11 @@ "friendlyName": "SharePoint Permissions", "description": "Site and document library permission assignments, including libraries that no longer inherit and grants to tenant-wide claims such as Everyone except external users" }, + { + "type": "StorageCleanupScan", + "friendlyName": "Storage Cleanup Scan", + "description": "Per-site library version estimates and recycle totals for the storage report cleanup signals. Report-private; not used by other CIPP features." + }, { "type": "OfficeActivations", "friendlyName": "Office Activations", @@ -419,6 +431,11 @@ "friendlyName": "SharePoint Admin Settings", "description": "SharePoint tenant admin settings including sharing capability, site creation, sync, timezone and excluded file extensions" }, + { + "type": "SPOSites", + "friendlyName": "SharePoint Site Settings", + "description": "Per-site SharePoint admin settings (site owner, sharing controls, lifecycle, version policy, People Picker, unmanaged-device access) for every site collection, keyed by site id" + }, { "type": "PeopleInsights", "friendlyName": "People Insights Settings", @@ -516,6 +533,7 @@ }, { "type": "IntuneMobileAppsAll", + "collectedBy": "IntuneApplications", "friendlyName": "All Intune Mobile Apps", "description": "Unfiltered mobile apps list (id, displayName, odata type) for presence checks" }, @@ -591,16 +609,19 @@ }, { "type": "ExoPhishSimOverridePolicy", + "collectedBy": "ExoPhishSimConfig", "friendlyName": "Phishing Simulation Override Policy", "description": "Third-party phishing simulation override policy" }, { "type": "ExoPhishSimOverrideRule", + "collectedBy": "ExoPhishSimConfig", "friendlyName": "Phishing Simulation Override Rule", "description": "Phishing simulation override rule with sender IP ranges and domains" }, { "type": "ExoPhishSimUrlAllowItems", + "collectedBy": "ExoPhishSimConfig", "friendlyName": "Phishing Simulation URL Allow Items", "description": "Advanced delivery URL allow entries for phishing simulations" }, @@ -626,6 +647,7 @@ }, { "type": "DlpComplianceRules", + "collectedBy": "DlpCompliancePolicies", "friendlyName": "DLP Compliance Rules", "description": "Data Loss Prevention compliance rules from the Purview compliance portal" }, @@ -636,6 +658,7 @@ }, { "type": "Fido2Configuration", + "collectedBy": "AuthenticationMethodsPolicy", "friendlyName": "FIDO2 Authentication Method Configuration", "description": "FIDO2 passkey authentication method configuration including passkey profiles" }, @@ -648,5 +671,10 @@ "type": "SelfServicePurchaseProducts", "friendlyName": "Self-Service Purchase Products", "description": "AllowSelfServicePurchase product policies and trial autoclaim policy" + }, + { + "type": "GroupUsage", + "friendlyName": "Group Usage Sources", + "description": "Refreshes every cache type that feeds the group usage report (groups, Conditional Access, Intune, roles, app assignments, licenses, transport rules); writes no rows of its own" } ] diff --git a/Config/CountryList.json b/Config/CountryList.json new file mode 100644 index 0000000000000..49ef2e53ea7d7 --- /dev/null +++ b/Config/CountryList.json @@ -0,0 +1,252 @@ +[ + { "Code": "AF", "Name": "Afghanistan" }, + { "Code": "AX", "Name": "\u00c5land Islands" }, + { "Code": "AL", "Name": "Albania" }, + { "Code": "DZ", "Name": "Algeria" }, + { "Code": "AS", "Name": "American Samoa" }, + { "Code": "AD", "Name": "Andorra" }, + { "Code": "AO", "Name": "Angola" }, + { "Code": "AI", "Name": "Anguilla" }, + { "Code": "AQ", "Name": "Antarctica" }, + { "Code": "AG", "Name": "Antigua and Barbuda" }, + { "Code": "AR", "Name": "Argentina" }, + { "Code": "AM", "Name": "Armenia" }, + { "Code": "AW", "Name": "Aruba" }, + { "Code": "AU", "Name": "Australia" }, + { "Code": "AT", "Name": "Austria" }, + { "Code": "AZ", "Name": "Azerbaijan" }, + { "Code": "BS", "Name": "Bahamas" }, + { "Code": "BH", "Name": "Bahrain" }, + { "Code": "BD", "Name": "Bangladesh" }, + { "Code": "BB", "Name": "Barbados" }, + { "Code": "BY", "Name": "Belarus" }, + { "Code": "BE", "Name": "Belgium" }, + { "Code": "BZ", "Name": "Belize" }, + { "Code": "BJ", "Name": "Benin" }, + { "Code": "BM", "Name": "Bermuda" }, + { "Code": "BT", "Name": "Bhutan" }, + { "Code": "BO", "Name": "Bolivia, Plurinational State of" }, + { "Code": "BQ", "Name": "Bonaire, Sint Eustatius and Saba" }, + { "Code": "BA", "Name": "Bosnia and Herzegovina" }, + { "Code": "BW", "Name": "Botswana" }, + { "Code": "BV", "Name": "Bouvet Island" }, + { "Code": "BR", "Name": "Brazil" }, + { "Code": "IO", "Name": "British Indian Ocean Territory" }, + { "Code": "BN", "Name": "Brunei Darussalam" }, + { "Code": "BG", "Name": "Bulgaria" }, + { "Code": "BF", "Name": "Burkina Faso" }, + { "Code": "BI", "Name": "Burundi" }, + { "Code": "KH", "Name": "Cambodia" }, + { "Code": "CM", "Name": "Cameroon" }, + { "Code": "CA", "Name": "Canada" }, + { "Code": "CV", "Name": "Cape Verde" }, + { "Code": "KY", "Name": "Cayman Islands" }, + { "Code": "CF", "Name": "Central African Republic" }, + { "Code": "TD", "Name": "Chad" }, + { "Code": "CL", "Name": "Chile" }, + { "Code": "CN", "Name": "China" }, + { "Code": "CX", "Name": "Christmas Island" }, + { "Code": "CC", "Name": "Cocos (Keeling) Islands" }, + { "Code": "CO", "Name": "Colombia" }, + { "Code": "KM", "Name": "Comoros" }, + { "Code": "CG", "Name": "Congo" }, + { "Code": "CD", "Name": "Congo, the Democratic Republic of the" }, + { "Code": "CK", "Name": "Cook Islands" }, + { "Code": "CR", "Name": "Costa Rica" }, + { "Code": "CI", "Name": "C\u00f4te d'Ivoire" }, + { "Code": "HR", "Name": "Croatia" }, + { "Code": "CU", "Name": "Cuba" }, + { "Code": "CW", "Name": "Cura\u00e7ao" }, + { "Code": "CY", "Name": "Cyprus" }, + { "Code": "CZ", "Name": "Czech Republic" }, + { "Code": "DK", "Name": "Denmark" }, + { "Code": "DJ", "Name": "Djibouti" }, + { "Code": "DM", "Name": "Dominica" }, + { "Code": "DO", "Name": "Dominican Republic" }, + { "Code": "EC", "Name": "Ecuador" }, + { "Code": "EG", "Name": "Egypt" }, + { "Code": "SV", "Name": "El Salvador" }, + { "Code": "GQ", "Name": "Equatorial Guinea" }, + { "Code": "ER", "Name": "Eritrea" }, + { "Code": "EE", "Name": "Estonia" }, + { "Code": "ET", "Name": "Ethiopia" }, + { "Code": "FK", "Name": "Falkland Islands (Malvinas)" }, + { "Code": "FO", "Name": "Faroe Islands" }, + { "Code": "FJ", "Name": "Fiji" }, + { "Code": "FI", "Name": "Finland" }, + { "Code": "FR", "Name": "France" }, + { "Code": "GF", "Name": "French Guiana" }, + { "Code": "PF", "Name": "French Polynesia" }, + { "Code": "TF", "Name": "French Southern Territories" }, + { "Code": "GA", "Name": "Gabon" }, + { "Code": "GM", "Name": "Gambia" }, + { "Code": "GE", "Name": "Georgia" }, + { "Code": "DE", "Name": "Germany" }, + { "Code": "GH", "Name": "Ghana" }, + { "Code": "GI", "Name": "Gibraltar" }, + { "Code": "GR", "Name": "Greece" }, + { "Code": "GL", "Name": "Greenland" }, + { "Code": "GD", "Name": "Grenada" }, + { "Code": "GP", "Name": "Guadeloupe" }, + { "Code": "GU", "Name": "Guam" }, + { "Code": "GT", "Name": "Guatemala" }, + { "Code": "GG", "Name": "Guernsey" }, + { "Code": "GN", "Name": "Guinea" }, + { "Code": "GW", "Name": "Guinea-Bissau" }, + { "Code": "GY", "Name": "Guyana" }, + { "Code": "HT", "Name": "Haiti" }, + { "Code": "HM", "Name": "Heard Island and McDonald Islands" }, + { "Code": "VA", "Name": "Holy See (Vatican City State)" }, + { "Code": "HN", "Name": "Honduras" }, + { "Code": "HK", "Name": "Hong Kong" }, + { "Code": "HU", "Name": "Hungary" }, + { "Code": "IS", "Name": "Iceland" }, + { "Code": "IN", "Name": "India" }, + { "Code": "ID", "Name": "Indonesia" }, + { "Code": "IR", "Name": "Iran, Islamic Republic of" }, + { "Code": "IQ", "Name": "Iraq" }, + { "Code": "IE", "Name": "Ireland" }, + { "Code": "IM", "Name": "Isle of Man" }, + { "Code": "IL", "Name": "Israel" }, + { "Code": "IT", "Name": "Italy" }, + { "Code": "JM", "Name": "Jamaica" }, + { "Code": "JP", "Name": "Japan" }, + { "Code": "JE", "Name": "Jersey" }, + { "Code": "JO", "Name": "Jordan" }, + { "Code": "KZ", "Name": "Kazakhstan" }, + { "Code": "KE", "Name": "Kenya" }, + { "Code": "KI", "Name": "Kiribati" }, + { "Code": "KP", "Name": "Korea, Democratic People's Republic of" }, + { "Code": "KR", "Name": "Korea, Republic of" }, + { "Code": "XK", "Name": "Kosovo" }, + { "Code": "KW", "Name": "Kuwait" }, + { "Code": "KG", "Name": "Kyrgyzstan" }, + { "Code": "LA", "Name": "Lao People's Democratic Republic" }, + { "Code": "LV", "Name": "Latvia" }, + { "Code": "LB", "Name": "Lebanon" }, + { "Code": "LS", "Name": "Lesotho" }, + { "Code": "LR", "Name": "Liberia" }, + { "Code": "LY", "Name": "Libya" }, + { "Code": "LI", "Name": "Liechtenstein" }, + { "Code": "LT", "Name": "Lithuania" }, + { "Code": "LU", "Name": "Luxembourg" }, + { "Code": "MO", "Name": "Macao" }, + { "Code": "MK", "Name": "Macedonia, the Former Yugoslav Republic of" }, + { "Code": "MG", "Name": "Madagascar" }, + { "Code": "MW", "Name": "Malawi" }, + { "Code": "MY", "Name": "Malaysia" }, + { "Code": "MV", "Name": "Maldives" }, + { "Code": "ML", "Name": "Mali" }, + { "Code": "MT", "Name": "Malta" }, + { "Code": "MH", "Name": "Marshall Islands" }, + { "Code": "MQ", "Name": "Martinique" }, + { "Code": "MR", "Name": "Mauritania" }, + { "Code": "MU", "Name": "Mauritius" }, + { "Code": "YT", "Name": "Mayotte" }, + { "Code": "MX", "Name": "Mexico" }, + { "Code": "FM", "Name": "Micronesia, Federated States of" }, + { "Code": "MD", "Name": "Moldova, Republic of" }, + { "Code": "MC", "Name": "Monaco" }, + { "Code": "MN", "Name": "Mongolia" }, + { "Code": "ME", "Name": "Montenegro" }, + { "Code": "MS", "Name": "Montserrat" }, + { "Code": "MA", "Name": "Morocco" }, + { "Code": "MZ", "Name": "Mozambique" }, + { "Code": "MM", "Name": "Myanmar" }, + { "Code": "NA", "Name": "Namibia" }, + { "Code": "NR", "Name": "Nauru" }, + { "Code": "NP", "Name": "Nepal" }, + { "Code": "NL", "Name": "Netherlands" }, + { "Code": "NC", "Name": "New Caledonia" }, + { "Code": "NZ", "Name": "New Zealand" }, + { "Code": "NI", "Name": "Nicaragua" }, + { "Code": "NE", "Name": "Niger" }, + { "Code": "NG", "Name": "Nigeria" }, + { "Code": "NU", "Name": "Niue" }, + { "Code": "NF", "Name": "Norfolk Island" }, + { "Code": "MP", "Name": "Northern Mariana Islands" }, + { "Code": "NO", "Name": "Norway" }, + { "Code": "OM", "Name": "Oman" }, + { "Code": "PK", "Name": "Pakistan" }, + { "Code": "PW", "Name": "Palau" }, + { "Code": "PS", "Name": "Palestine, State of" }, + { "Code": "PA", "Name": "Panama" }, + { "Code": "PG", "Name": "Papua New Guinea" }, + { "Code": "PY", "Name": "Paraguay" }, + { "Code": "PE", "Name": "Peru" }, + { "Code": "PH", "Name": "Philippines" }, + { "Code": "PN", "Name": "Pitcairn" }, + { "Code": "PL", "Name": "Poland" }, + { "Code": "PT", "Name": "Portugal" }, + { "Code": "PR", "Name": "Puerto Rico" }, + { "Code": "QA", "Name": "Qatar" }, + { "Code": "RE", "Name": "R\u00e9union" }, + { "Code": "RO", "Name": "Romania" }, + { "Code": "RU", "Name": "Russian Federation" }, + { "Code": "RW", "Name": "Rwanda" }, + { "Code": "BL", "Name": "Saint Barth\u00e9lemy" }, + { "Code": "SH", "Name": "Saint Helena, Ascension and Tristan da Cunha" }, + { "Code": "KN", "Name": "Saint Kitts and Nevis" }, + { "Code": "LC", "Name": "Saint Lucia" }, + { "Code": "MF", "Name": "Saint Martin (French part)" }, + { "Code": "PM", "Name": "Saint Pierre and Miquelon" }, + { "Code": "VC", "Name": "Saint Vincent and the Grenadines" }, + { "Code": "WS", "Name": "Samoa" }, + { "Code": "SM", "Name": "San Marino" }, + { "Code": "ST", "Name": "Sao Tome and Principe" }, + { "Code": "SA", "Name": "Saudi Arabia" }, + { "Code": "SN", "Name": "Senegal" }, + { "Code": "RS", "Name": "Serbia" }, + { "Code": "SC", "Name": "Seychelles" }, + { "Code": "SL", "Name": "Sierra Leone" }, + { "Code": "SG", "Name": "Singapore" }, + { "Code": "SX", "Name": "Sint Maarten (Dutch part)" }, + { "Code": "SK", "Name": "Slovakia" }, + { "Code": "SI", "Name": "Slovenia" }, + { "Code": "SB", "Name": "Solomon Islands" }, + { "Code": "SO", "Name": "Somalia" }, + { "Code": "ZA", "Name": "South Africa" }, + { "Code": "GS", "Name": "South Georgia and the South Sandwich Islands" }, + { "Code": "SS", "Name": "South Sudan" }, + { "Code": "ES", "Name": "Spain" }, + { "Code": "LK", "Name": "Sri Lanka" }, + { "Code": "SD", "Name": "Sudan" }, + { "Code": "SR", "Name": "Suriname" }, + { "Code": "SJ", "Name": "Svalbard and Jan Mayen" }, + { "Code": "SZ", "Name": "Swaziland" }, + { "Code": "SE", "Name": "Sweden" }, + { "Code": "CH", "Name": "Switzerland" }, + { "Code": "SY", "Name": "Syrian Arab Republic" }, + { "Code": "TW", "Name": "Taiwan, Province of China" }, + { "Code": "TJ", "Name": "Tajikistan" }, + { "Code": "TZ", "Name": "Tanzania, United Republic of" }, + { "Code": "TH", "Name": "Thailand" }, + { "Code": "TL", "Name": "Timor-Leste" }, + { "Code": "TG", "Name": "Togo" }, + { "Code": "TK", "Name": "Tokelau" }, + { "Code": "TO", "Name": "Tonga" }, + { "Code": "TT", "Name": "Trinidad and Tobago" }, + { "Code": "TN", "Name": "Tunisia" }, + { "Code": "TR", "Name": "Turkey" }, + { "Code": "TM", "Name": "Turkmenistan" }, + { "Code": "TC", "Name": "Turks and Caicos Islands" }, + { "Code": "TV", "Name": "Tuvalu" }, + { "Code": "UG", "Name": "Uganda" }, + { "Code": "UA", "Name": "Ukraine" }, + { "Code": "AE", "Name": "United Arab Emirates" }, + { "Code": "GB", "Name": "United Kingdom" }, + { "Code": "US", "Name": "United States" }, + { "Code": "UM", "Name": "United States Minor Outlying Islands" }, + { "Code": "UY", "Name": "Uruguay" }, + { "Code": "UZ", "Name": "Uzbekistan" }, + { "Code": "VU", "Name": "Vanuatu" }, + { "Code": "VE", "Name": "Venezuela, Bolivarian Republic of" }, + { "Code": "VN", "Name": "Viet Nam" }, + { "Code": "VG", "Name": "Virgin Islands, British" }, + { "Code": "VI", "Name": "Virgin Islands, U.S." }, + { "Code": "WF", "Name": "Wallis and Futuna" }, + { "Code": "EH", "Name": "Western Sahara" }, + { "Code": "YE", "Name": "Yemen" }, + { "Code": "ZM", "Name": "Zambia" }, + { "Code": "ZW", "Name": "Zimbabwe" } +] diff --git a/Config/DocsPublishedPages.txt b/Config/DocsPublishedPages.txt index b9d3e4eecdfd4..1e21236768e88 100644 --- a/Config/DocsPublishedPages.txt +++ b/Config/DocsPublishedPages.txt @@ -1,7 +1,7 @@ # Slugs published on docs.cipp.app, snapshotted from llms.txt. # Generated by build/tools/Update-DocsPublishedPages.ps1 - do not hand-edit. # Read by Get-CippDocsPublishedSet so the docs search index never emits a URL that 404s. -# 427 pages. +# 426 pages. api-documentation/endpoints api-documentation/setup-and-authentication demos/showcases @@ -238,12 +238,12 @@ user-documentation/identity/administration/groups/edit user-documentation/identity/administration/groups/group user-documentation/identity/administration/jit-admin user-documentation/identity/administration/jit-admin-templates -user-documentation/identity/administration/jit-admin-templates/add-jit-admin-template -user-documentation/identity/administration/jit-admin-templates/edit-jit-admin-template +user-documentation/identity/administration/jit-admin-templates/add +user-documentation/identity/administration/jit-admin-templates/edit user-documentation/identity/administration/jit-admin/add user-documentation/identity/administration/offboarding-wizard user-documentation/identity/administration/risky-users -user-documentation/identity/administration/roles +user-documentation/identity/administration/user-defaults user-documentation/identity/administration/users user-documentation/identity/administration/users/patch-wizard user-documentation/identity/administration/users/user @@ -374,8 +374,8 @@ user-documentation/tenant/gdap-management/relationships/relationship/mappings user-documentation/tenant/gdap-management/role-templates user-documentation/tenant/gdap-management/role-templates/add user-documentation/tenant/gdap-management/role-templates/edit +user-documentation/tenant/gdap-management/role-templates/mappings/add user-documentation/tenant/gdap-management/roles -user-documentation/tenant/gdap-management/roles/add user-documentation/tenant/manage user-documentation/tenant/manage/applied-standards user-documentation/tenant/manage/backup @@ -383,7 +383,6 @@ user-documentation/tenant/manage/drift user-documentation/tenant/manage/edit user-documentation/tenant/manage/history user-documentation/tenant/manage/policies-deployed -user-documentation/tenant/manage/user-defaults user-documentation/tenant/reports user-documentation/tenant/reports/application-consent user-documentation/tenant/reports/custom-test-report diff --git a/Config/FeatureFlags.json b/Config/FeatureFlags.json index b68f2c5e6f1d7..75a740f482d1d 100644 --- a/Config/FeatureFlags.json +++ b/Config/FeatureFlags.json @@ -91,7 +91,7 @@ { "Id": "Baselines", "Name": "Baselines", - "Description": "The drift-first baseline engine that replaces classic Standards and Drift. Enables the scheduled baseline run and the Baselines menu, hides the classic Standards and Drift pages, and skips the scheduled classic Standards and Drift runs - the two systems never run side by side.", + "Description": "This is pre-alpha do not enable in production. The drift-first baseline engine that replaces classic Standards and Drift. Enables the scheduled baseline run and the Baselines menu, hides the classic Standards and Drift pages, and skips the scheduled classic Standards and Drift runs - the two systems never run side by side.", "Enabled": false, "AllowUserToggle": true, "Timers": ["9f2c7b1e-4a6d-4c3f-8b9a-5e1d2f7c0a44"], @@ -104,5 +104,16 @@ "/tenant/manage/policies-deployed" ], "Hidden": false + }, + { + "Id": "CertificateAuthentication", + "Name": "Certificate Authentication", + "Description": "Authenticate CIPP's SAM application with the SAM certificate instead of the client secret for every Graph and Exchange Online call (app-only and delegated). Managed from the Setup Wizard - enable it for an existing install (the client secret is kept as a rollback) or provision a secret-less install from scratch.", + "Enabled": false, + "AllowUserToggle": false, + "Timers": [], + "Endpoints": [], + "Pages": [], + "Hidden": true } ] diff --git a/Config/LicensePricingDefaults.csv b/Config/LicensePricingDefaults.csv new file mode 100644 index 0000000000000..30a2ea1a7bcfc --- /dev/null +++ b/Config/LicensePricingDefaults.csv @@ -0,0 +1,476 @@ +skuId,skuPartNumber,Product_Display_Name,MonthlyPrice,Currency +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,18,AUD +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,68.9,BRL +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,16.3,CAD +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,9.8,CHF +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,77.9,DKK +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,10.4,EUR +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,9.3,GBP +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,1000,INR +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,1805,JPY +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,16300,KRW +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,122.4,NOK +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,19.5,NZD +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,115.1,SEK +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,385,TWD +efccb6f7-5641-4e0e-bd10-b4976e1bf68e,EMS,Enterprise Mobility + Security E3,12,USD +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,27,AUD +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,103.3,BRL +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,24.5,CAD +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,14.6,CHF +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,116.7,DKK +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,15.6,EUR +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,13.9,GBP +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,1500,INR +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,2704,JPY +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,24400,KRW +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,183.4,NOK +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,29.2,NZD +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,172.4,SEK +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,580,TWD +b05e124f-c7cc-45a0-a6aa-8cf78c946968,EMSPREMIUM,Enterprise Mobility + Security E5,18,USD +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),6,AUD +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),22.9,BRL +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),5.4,CAD +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),3.2,CHF +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),25.9,DKK +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),3.5,EUR +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),3.1,GBP +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),335,INR +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),599,JPY +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),5400,KRW +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),40.7,NOK +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),6.5,NZD +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),38.2,SEK +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),130,TWD +4b9405b0-7788-4568-add1-99614e613b69,EXCHANGESTANDARD,Exchange Online (Plan 1),4,USD +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),12,AUD +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),45.8,BRL +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),10.9,CAD +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),6.5,CHF +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),51.7,DKK +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),6.9,EUR +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),6.2,GBP +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),665,INR +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),1199,JPY +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),10800,KRW +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),81.3,NOK +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),12.9,NZD +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),76.5,SEK +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),255,TWD +19ec0d23-8335-4cbd-94ac-6050e30712fa,EXCHANGEENTERPRISE,Exchange Online (Plan 2),8,USD +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,15.8,AUD +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,57.3,BRL +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,14.2,CAD +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,10.1,CHF +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,81.9,DKK +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,11,EUR +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,9.8,GBP +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,830,INR +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,1499,JPY +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,13200,KRW +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,127.6,NOK +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,19.2,NZD +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,120,SEK +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,370,TWD +cdd28e44-67e3-425e-be4c-737fab2899d3,O365_BUSINESS,Microsoft 365 Apps for Business,10,USD +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,22.1,AUD +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,80.2,BRL +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,19.8,CAD +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,14.2,CHF +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,114.7,DKK +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,15.4,EUR +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,13.7,GBP +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,1165,INR +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,2098,JPY +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,18500,KRW +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,178.6,NOK +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,26.9,NZD +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,168,SEK +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,515,TWD +c2273bd0-dff7-4215-9ef5-2c7bcfb06425,OFFICESUBSCRIPTION,Microsoft 365 Apps for Enterprise,14,USD +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,10.5,AUD +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,33.4,BRL +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,9.5,CAD +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,5.67,CHF +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,45.27,DKK +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,6.07,EUR +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,5.4,GBP +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,170,INR +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,1049,JPY +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,9500,KRW +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,71.16,NOK +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,11.3,NZD +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,66.91,SEK +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,225,TWD +3b555118-da6a-4418-894f-7df1e2096870,O365_BUSINESS_ESSENTIALS,Microsoft 365 Business Basic,7,USD +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,32.9,AUD +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,126,BRL +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,29.8,CAD +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,17.82,CHF +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,142.27,DKK +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,19.06,EUR +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,16.9,GBP +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,1830,INR +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,3298,JPY +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,29700,KRW +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,223.63,NOK +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,35.6,NZD +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,210.29,SEK +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,705,TWD +cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46,SPB,Microsoft 365 Business Premium,22,USD +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,21,AUD +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,80.2,BRL +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,19,CAD +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,11.34,CHF +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,90.54,DKK +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,12.13,EUR +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,10.8,GBP +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,860,INR +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,2098,JPY +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,18900,KRW +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,142.31,NOK +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,22.6,NZD +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,133.82,SEK +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,450,TWD +f245ecc8-75af-4f8e-b61f-27d8114de5f3,O365_BUSINESS_PREMIUM,Microsoft 365 Business Standard,14,USD +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,58.4,AUD +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,223.3,BRL +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,52.9,CAD +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,35.32,CHF +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,281.97,DKK +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,37.78,EUR +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,33.5,GBP +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,3245,INR +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,5847,JPY +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,52700,KRW +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,442.03,NOK +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,63.1,NZD +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,416.77,SEK +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,1255,TWD +05e9a617-0261-4cee-bb44-138d3ef5d965,SPE_E3,Microsoft 365 E3,39,USD +dcf0408c-aaec-446c-afd4-43e3683943ea,Microsoft_365_E3_(no_Teams),Microsoft 365 E3 (no Teams),45.6,AUD +dcf0408c-aaec-446c-afd4-43e3683943ea,Microsoft_365_E3_(no_Teams),Microsoft 365 E3 (no Teams),174.3,BRL +dcf0408c-aaec-446c-afd4-43e3683943ea,Microsoft_365_E3_(no_Teams),Microsoft 365 E3 (no Teams),41.3,CAD +dcf0408c-aaec-446c-afd4-43e3683943ea,Microsoft_365_E3_(no_Teams),Microsoft 365 E3 (no Teams),27,GBP +dcf0408c-aaec-446c-afd4-43e3683943ea,Microsoft_365_E3_(no_Teams),Microsoft 365 E3 (no Teams),2535,INR +dcf0408c-aaec-446c-afd4-43e3683943ea,Microsoft_365_E3_(no_Teams),Microsoft 365 E3 (no Teams),4565,JPY +dcf0408c-aaec-446c-afd4-43e3683943ea,Microsoft_365_E3_(no_Teams),Microsoft 365 E3 (no Teams),41100,KRW +dcf0408c-aaec-446c-afd4-43e3683943ea,Microsoft_365_E3_(no_Teams),Microsoft 365 E3 (no Teams),49.3,NZD +dcf0408c-aaec-446c-afd4-43e3683943ea,Microsoft_365_E3_(no_Teams),Microsoft 365 E3 (no Teams),980,TWD +dcf0408c-aaec-446c-afd4-43e3683943ea,Microsoft_365_E3_(no_Teams),Microsoft 365 E3 (no Teams),30.45,USD +c2fe850d-fbbb-4858-b67d-bd0c6e746da3,O365_w/o Teams Bundle_M3,Microsoft 365 E3 EEA (no Teams),28.38,CHF +c2fe850d-fbbb-4858-b67d-bd0c6e746da3,O365_w/o Teams Bundle_M3,Microsoft 365 E3 EEA (no Teams),226.68,DKK +c2fe850d-fbbb-4858-b67d-bd0c6e746da3,O365_w/o Teams Bundle_M3,Microsoft 365 E3 EEA (no Teams),30.36,EUR +c2fe850d-fbbb-4858-b67d-bd0c6e746da3,O365_w/o Teams Bundle_M3,Microsoft 365 E3 EEA (no Teams),355.12,NOK +c2fe850d-fbbb-4858-b67d-bd0c6e746da3,O365_w/o Teams Bundle_M3,Microsoft 365 E3 EEA (no Teams),335.04,SEK +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,89.8,AUD +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,343.5,BRL +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,81.4,CAD +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,54.33,CHF +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,433.8,DKK +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,58.13,EUR +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,51.6,GBP +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,4990,INR +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,8995,JPY +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,81100,KRW +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,680.04,NOK +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,97.1,NZD +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,641.18,SEK +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,1930,TWD +06ebc4ee-1bb5-47dd-8120-11324bc54e06,SPE_E5,Microsoft 365 E5,60,USD +18a4bd3f-0b5b-4887-b04f-61dd0ee15f5e,Microsoft_365_E5_(no_Teams),Microsoft 365 E5 (no Teams),77,AUD +18a4bd3f-0b5b-4887-b04f-61dd0ee15f5e,Microsoft_365_E5_(no_Teams),Microsoft 365 E5 (no Teams),294.6,BRL +18a4bd3f-0b5b-4887-b04f-61dd0ee15f5e,Microsoft_365_E5_(no_Teams),Microsoft 365 E5 (no Teams),69.8,CAD +18a4bd3f-0b5b-4887-b04f-61dd0ee15f5e,Microsoft_365_E5_(no_Teams),Microsoft 365 E5 (no Teams),45,GBP +18a4bd3f-0b5b-4887-b04f-61dd0ee15f5e,Microsoft_365_E5_(no_Teams),Microsoft 365 E5 (no Teams),4280,INR +18a4bd3f-0b5b-4887-b04f-61dd0ee15f5e,Microsoft_365_E5_(no_Teams),Microsoft 365 E5 (no Teams),7713,JPY +18a4bd3f-0b5b-4887-b04f-61dd0ee15f5e,Microsoft_365_E5_(no_Teams),Microsoft 365 E5 (no Teams),69500,KRW +18a4bd3f-0b5b-4887-b04f-61dd0ee15f5e,Microsoft_365_E5_(no_Teams),Microsoft 365 E5 (no Teams),83.2,NZD +18a4bd3f-0b5b-4887-b04f-61dd0ee15f5e,Microsoft_365_E5_(no_Teams),Microsoft 365 E5 (no Teams),1655,TWD +18a4bd3f-0b5b-4887-b04f-61dd0ee15f5e,Microsoft_365_E5_(no_Teams),Microsoft 365 E5 (no Teams),51.45,USD +3271cf8e-2be5-4a09-a549-70fd05baaa17,O365_w/o_Teams_Bundle_M5,Microsoft 365 E5 EEA (no Teams),47.4,CHF +3271cf8e-2be5-4a09-a549-70fd05baaa17,O365_w/o_Teams_Bundle_M5,Microsoft 365 E5 EEA (no Teams),378.5,DKK +3271cf8e-2be5-4a09-a549-70fd05baaa17,O365_w/o_Teams_Bundle_M5,Microsoft 365 E5 EEA (no Teams),50.71,EUR +3271cf8e-2be5-4a09-a549-70fd05baaa17,O365_w/o_Teams_Bundle_M5,Microsoft 365 E5 EEA (no Teams),593.13,NOK +3271cf8e-2be5-4a09-a549-70fd05baaa17,O365_w/o_Teams_Bundle_M5,Microsoft 365 E5 EEA (no Teams),559.44,SEK +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,89.8,AUD +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,343.5,BRL +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,81.4,CAD +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,54.33,CHF +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,433.8,DKK +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,58.13,EUR +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,51.6,GBP +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,4990,INR +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,8995,JPY +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,81100,KRW +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,680.04,NOK +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,97.1,NZD +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,641.18,SEK +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,1930,TWD +cd2925a3-5076-4233-8931-638a8c94f773,SPE_E5_NOPSTNCONF,Microsoft 365 E5 without Audio Conferencing,60,USD +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,4.5,AUD +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,17.2,BRL +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,4.1,CAD +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,2.43,CHF +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,19.4,DKK +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,2.6,EUR +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,2.3,GBP +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,250,INR +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,449,JPY +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,4100,KRW +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,30.5,NOK +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,4.9,NZD +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,28.68,SEK +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,96.5,TWD +50f60901-3181-4b75-8a2c-4c8e4c1d5a72,M365_F1_COMM,Microsoft 365 F1,3,USD +0666269f-b167-4c5b-a76f-fc574f2b1118,Microsoft_365_F1_EEA_(no_Teams),Microsoft 365 F1 EEA (no Teams),2.02,CHF +0666269f-b167-4c5b-a76f-fc574f2b1118,Microsoft_365_F1_EEA_(no_Teams),Microsoft 365 F1 EEA (no Teams),16.16,DKK +0666269f-b167-4c5b-a76f-fc574f2b1118,Microsoft_365_F1_EEA_(no_Teams),Microsoft 365 F1 EEA (no Teams),2.16,EUR +0666269f-b167-4c5b-a76f-fc574f2b1118,Microsoft_365_F1_EEA_(no_Teams),Microsoft 365 F1 EEA (no Teams),25.41,NOK +0666269f-b167-4c5b-a76f-fc574f2b1118,Microsoft_365_F1_EEA_(no_Teams),Microsoft 365 F1 EEA (no Teams),23.89,SEK +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,15,AUD +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,57.3,BRL +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,13.6,CAD +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,8.1,CHF +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,64.67,DKK +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,8.66,EUR +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,7.7,GBP +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,830,INR +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,1499,JPY +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,13500,KRW +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,101.65,NOK +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,16.2,NZD +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,95.59,SEK +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,320,TWD +66b55226-6b4f-492c-910c-a3b7a3c9d993,SPE_F1,Microsoft 365 F3,10,USD +f7ee79a7-7aec-4ca4-9fb9-34d6b930ad87,Microsoft_365_F3_EEA_(no_Teams),Microsoft 365 F3 EEA (no Teams),7.23,CHF +f7ee79a7-7aec-4ca4-9fb9-34d6b930ad87,Microsoft_365_F3_EEA_(no_Teams),Microsoft 365 F3 EEA (no Teams),57.74,DKK +f7ee79a7-7aec-4ca4-9fb9-34d6b930ad87,Microsoft_365_F3_EEA_(no_Teams),Microsoft 365 F3 EEA (no Teams),7.73,EUR +f7ee79a7-7aec-4ca4-9fb9-34d6b930ad87,Microsoft_365_F3_EEA_(no_Teams),Microsoft 365 F3 EEA (no Teams),90.77,NOK +f7ee79a7-7aec-4ca4-9fb9-34d6b930ad87,Microsoft_365_F3_EEA_(no_Teams),Microsoft 365 F3 EEA (no Teams),85.35,SEK +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,44.9,AUD +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,171.8,BRL +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,40.7,CAD +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,24.3,CHF +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,194,DKK +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,26,EUR +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,23.1,GBP +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,2495,INR +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,4497,JPY +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,40500,KRW +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,305,NOK +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,48.5,NZD +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,286.8,SEK +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,965,TWD +639dec6b-bb19-468b-871c-c5c441c4b0cb,Microsoft_365_Copilot,Microsoft Copilot for Microsoft 365,30,USD +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,4.5,AUD +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,13.7,BRL +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,4.1,CAD +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,2.4,CHF +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,19.4,DKK +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,2.6,EUR +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,2.3,GBP +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,250,INR +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,449,JPY +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,4100,KRW +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,30.5,NOK +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,4.9,NZD +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,28.7,SEK +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,96.5,TWD +5e1e7702-a2b7-4360-8d07-2f515792896f,MDE_SMB,Microsoft Defender for Business,3,USD +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,10.5,AUD +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,40.1,BRL +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,9.5,CAD +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,5.7,CHF +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,45.3,DKK +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,6.1,EUR +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,5.4,GBP +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,580,INR +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,1049,JPY +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,9500,KRW +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,71.2,NOK +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,11.3,NZD +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,66.9,SEK +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,225,TWD +cf6b0d46-4093-4546-a0ab-0b1546dcc10e,Microsoft_Entra_ID_Governance,Microsoft Entra ID Governance,7,USD +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,10.5,AUD +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,40.1,BRL +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,9.5,CAD +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,5.7,CHF +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,45.3,DKK +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,6.1,EUR +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,5.4,GBP +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,580,INR +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,1049,JPY +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,9500,KRW +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,71.2,NOK +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,11.3,NZD +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,66.9,SEK +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,225,TWD +078d2b04-f1bd-4111-bbd4-b4b1b354cef4,AAD_PREMIUM,Microsoft Entra ID P1,7,USD +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,15,AUD +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,57.3,BRL +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,13.6,CAD +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,8.1,CHF +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,64.7,DKK +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,8.7,EUR +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,7.7,GBP +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,830,INR +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,1499,JPY +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,13500,KRW +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,101.7,NOK +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,16.2,NZD +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,95.6,SEK +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,320,TWD +84a661c4-e949-4bd2-a560-ed7766fcaf2b,AAD_PREMIUM_P2,Microsoft Entra ID P2,10,USD +7e31c0d9-9551-471d-836f-32ee72be4a01,Microsoft_Teams_Enterprise_New,Microsoft Teams Enterprise,12.8,AUD +7e31c0d9-9551-471d-836f-32ee72be4a01,Microsoft_Teams_Enterprise_New,Microsoft Teams Enterprise,49,BRL +7e31c0d9-9551-471d-836f-32ee72be4a01,Microsoft_Teams_Enterprise_New,Microsoft Teams Enterprise,11.6,CAD +7e31c0d9-9551-471d-836f-32ee72be4a01,Microsoft_Teams_Enterprise_New,Microsoft Teams Enterprise,6.6,GBP +7e31c0d9-9551-471d-836f-32ee72be4a01,Microsoft_Teams_Enterprise_New,Microsoft Teams Enterprise,710,INR +7e31c0d9-9551-471d-836f-32ee72be4a01,Microsoft_Teams_Enterprise_New,Microsoft Teams Enterprise,1281,JPY +7e31c0d9-9551-471d-836f-32ee72be4a01,Microsoft_Teams_Enterprise_New,Microsoft Teams Enterprise,11600,KRW +7e31c0d9-9551-471d-836f-32ee72be4a01,Microsoft_Teams_Enterprise_New,Microsoft Teams Enterprise,13.8,NZD +7e31c0d9-9551-471d-836f-32ee72be4a01,Microsoft_Teams_Enterprise_New,Microsoft Teams Enterprise,275,TWD +7e31c0d9-9551-471d-836f-32ee72be4a01,Microsoft_Teams_Enterprise_New,Microsoft Teams Enterprise,8.55,USD +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,6,AUD +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,22.9,BRL +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,5.4,CAD +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,3.2,CHF +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,25.9,DKK +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,3.5,EUR +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,3.1,GBP +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,115,INR +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,599,JPY +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,5400,KRW +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,40.7,NOK +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,6.5,NZD +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,38.2,SEK +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,130,TWD +fde42873-30b6-436b-b361-21af5a6b84ae,Teams_Ess,Microsoft Teams Essentials,4,USD +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,15,AUD +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,57.3,BRL +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,13.6,CAD +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,8.1,CHF +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,64.7,DKK +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,8.7,EUR +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,7.7,GBP +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,830,INR +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,1499,JPY +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,13500,KRW +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,101.7,NOK +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,16.2,NZD +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,95.6,SEK +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,320,TWD +e43b5b99-8dfb-405f-9987-dc307f34bcbd,MCOEV,Microsoft Teams Phone Standard,10,USD +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,59.9,AUD +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,229,BRL +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,54.3,CAD +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,32.4,CHF +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,258.7,DKK +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,34.7,EUR +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,30.8,GBP +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,5997,JPY +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,54100,KRW +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,406.6,NOK +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,64.7,NZD +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,382.3,SEK +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,1285,TWD +4cde982a-ede4-4409-9ae6-b003453c8ea6,Microsoft_Teams_Rooms_Pro,Microsoft Teams Rooms Pro,40,USD +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,15,AUD +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,57.3,BRL +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,13.6,CAD +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,8.1,CHF +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,64.67,DKK +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,8.66,EUR +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,7.7,GBP +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,830,INR +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,1499,JPY +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,13500,KRW +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,101.65,NOK +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,16.2,NZD +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,95.59,SEK +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,320,TWD +18181a46-0d4e-45cd-891e-60aabd171b4e,STANDARDPACK,Office 365 E1,10,USD +f8ced641-8e17-4dc5-b014-f5a2d53f6ac8,Office_365_E1_(no_Teams),Office 365 E1 (no Teams),10.2,AUD +f8ced641-8e17-4dc5-b014-f5a2d53f6ac8,Office_365_E1_(no_Teams),Office 365 E1 (no Teams),38.9,BRL +f8ced641-8e17-4dc5-b014-f5a2d53f6ac8,Office_365_E1_(no_Teams),Office 365 E1 (no Teams),9.2,CAD +f8ced641-8e17-4dc5-b014-f5a2d53f6ac8,Office_365_E1_(no_Teams),Office 365 E1 (no Teams),5.2,GBP +f8ced641-8e17-4dc5-b014-f5a2d53f6ac8,Office_365_E1_(no_Teams),Office 365 E1 (no Teams),565,INR +f8ced641-8e17-4dc5-b014-f5a2d53f6ac8,Office_365_E1_(no_Teams),Office 365 E1 (no Teams),1017,JPY +f8ced641-8e17-4dc5-b014-f5a2d53f6ac8,Office_365_E1_(no_Teams),Office 365 E1 (no Teams),9200,KRW +f8ced641-8e17-4dc5-b014-f5a2d53f6ac8,Office_365_E1_(no_Teams),Office 365 E1 (no Teams),11,NZD +f8ced641-8e17-4dc5-b014-f5a2d53f6ac8,Office_365_E1_(no_Teams),Office 365 E1 (no Teams),220,TWD +f8ced641-8e17-4dc5-b014-f5a2d53f6ac8,Office_365_E1_(no_Teams),Office 365 E1 (no Teams),6.79,USD +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,38.9,AUD +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,148.9,BRL +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,35.3,CAD +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,24.56,CHF +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,195.65,DKK +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,26.27,EUR +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,23.3,GBP +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,2165,INR +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,3898,JPY +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,35100,KRW +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,305.29,NOK +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,44.4,NZD +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,289.81,SEK +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,905,TWD +6fd2c87f-b296-42f0-b197-1e91e994b900,ENTERPRISEPACK,Office 365 E3,26,USD +46c3a859-c90d-40b3-9551-6178a48d5c18,Office_365_E3_(no_Teams),Office 365 E3 (no Teams),26.1,AUD +46c3a859-c90d-40b3-9551-6178a48d5c18,Office_365_E3_(no_Teams),Office 365 E3 (no Teams),99.9,BRL +46c3a859-c90d-40b3-9551-6178a48d5c18,Office_365_E3_(no_Teams),Office 365 E3 (no Teams),23.7,CAD +46c3a859-c90d-40b3-9551-6178a48d5c18,Office_365_E3_(no_Teams),Office 365 E3 (no Teams),16.7,GBP +46c3a859-c90d-40b3-9551-6178a48d5c18,Office_365_E3_(no_Teams),Office 365 E3 (no Teams),1450,INR +46c3a859-c90d-40b3-9551-6178a48d5c18,Office_365_E3_(no_Teams),Office 365 E3 (no Teams),2616,JPY +46c3a859-c90d-40b3-9551-6178a48d5c18,Office_365_E3_(no_Teams),Office 365 E3 (no Teams),23600,KRW +46c3a859-c90d-40b3-9551-6178a48d5c18,Office_365_E3_(no_Teams),Office 365 E3 (no Teams),30.6,NZD +46c3a859-c90d-40b3-9551-6178a48d5c18,Office_365_E3_(no_Teams),Office 365 E3 (no Teams),635,TWD +46c3a859-c90d-40b3-9551-6178a48d5c18,Office_365_E3_(no_Teams),Office 365 E3 (no Teams),17.45,USD +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,61.4,AUD +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,234.8,BRL +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,55.6,CAD +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,38.72,CHF +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,308.53,DKK +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,41.42,EUR +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,36.8,GBP +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,3410,INR +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,6146,JPY +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,55400,KRW +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,481.41,NOK +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,70.1,NZD +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,457,SEK +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,1425,TWD +c7df2760-2c81-4ef7-b578-5b5392b571df,ENTERPRISEPREMIUM,Office 365 E5,41,USD +4b585984-651b-448a-9e53-3b10f069cf7f,DESKLESSPACK,Office 365 F3,4.00,USD +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,35.9,AUD +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,137.4,BRL +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,32.6,CAD +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,19.4,CHF +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,155.2,DKK +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,20.8,EUR +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,18.5,GBP +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,1995,INR +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,3598,JPY +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,32400,KRW +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,244,NOK +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,38.8,NZD +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,229.4,SEK +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,770,TWD +c1d032e0-5619-4761-9b5c-75b6831e1711,PBI_PREMIUM_PER_USER,Power BI Premium Per User,24,USD +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,21,AUD +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,80.2,BRL +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,19,CAD +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,11.3,CHF +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,90.5,DKK +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,12.1,EUR +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,10.8,GBP +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,1165,INR +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,2098,JPY +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,18900,KRW +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,142.3,NOK +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,22.6,NZD +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,133.8,SEK +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,450,TWD +f8a1db68-be16-40ed-86d5-cb42ce701560,POWER_BI_PRO,Power BI Pro,14,USD diff --git a/Config/PermissionsTranslator.json b/Config/PermissionsTranslator.json index 30c15bbb5bdad..5e6ce04fe8aaf 100644 --- a/Config/PermissionsTranslator.json +++ b/Config/PermissionsTranslator.json @@ -1,5425 +1,18594 @@ [ { - "description": "Allows the app to read email metadata and security detection details for all emails in your organization, without a signed-in user.", - "displayName": "Read metadata and detection details for all emails in your organization", - "id": "b48f7ac2-044d-4281-b02f-75db744d6f5f", - "origin": "Application", - "value": "SecurityAnalyzedMessage.Read.All" + "description": "This allows users to manage ADO Pools. ", + "displayName": "Manage AzDevops Pools", + "id": "99c58aeb-f6a2-4999-b722-b052dc773c26", + "origin": "Delegated (1ES Resource Management PPE)", + "value": "manage_ado_pools" }, { - "description": "Allows the app to read email metadata and security detection details, and execute remediation actions like deleting an email, for all emails in your organization, without a signed-in user.", - "displayName": "Read metadata, detection details, and execute remediation actions on all emails in your organization", - "id": "04c55753-2244-4c25-87fc-704ab82a4f69", - "origin": "Application", - "value": "SecurityAnalyzedMessage.ReadWrite.All" + "description": "Allows the app to read and write your organization's SPIFFE trust domains and child resources on behalf of the user.", + "displayName": "Read and write SPIFFE trust domains and child resources", + "id": "8ba47079-8c47-4bfe-b2ce-13f28ef37247", + "origin": "Delegated (Microsoft Graph)", + "value": "SpiffeTrustDomain.ReadWrite.All" }, { - "description": "Allows the app to impersonate the signed-in user to access the Partner Center API.", - "displayName": "Partner Center as User", - "id": "1cebfa2a-fb4d-419e-b5f9-839b4383e05a", - "origin": "Delegated (Microsoft Partner Center)", - "value": "user_impersonation" + "description": "Allows the app to modify the Viva Engage storyline and read all storyline properties on behalf of the signed-in user.", + "displayName": "Read and write all Viva Engage storylines", + "id": "fd1d61cb-4e4b-4d15-a6d2-161348681d84", + "origin": "Delegated (Microsoft Graph)", + "value": "Storyline.ReadWrite.All" }, { - "description": "Allows Exchange Management as app", - "displayName": "Manage Exchange As Application ", - "id": "dc50a0fb-09a3-484d-be87-e023b12c6440", - "origin": "Application (Office 365 Exchange Online)", - "value": "Exchange.ManageAsApp" + "description": "Allows the app to read and write all the subject name registration properties on behalf of the signed-in user.", + "displayName": "Read and write a subject name registration.", + "id": "fb0d7592-1943-4141-a7bc-b7ae45b84ecf", + "origin": "Delegated (Microsoft Graph)", + "value": "SubjectNameRegistration.ReadWrite" }, { - "description": "Allows the app to read a basic set of profile properties of other users in your organization without a signed-in user. Includes display name, first and last name, email address, open extensions, and photo.", - "displayName": "Read all users' basic profiles", - "id": "97235f07-e226-4f63-ace3-39588e11d3a1", - "origin": "Application", - "value": "User.ReadBasic.All" + "description": "Allows the app to read subject rights requests on behalf of the signed-in user", + "displayName": "Read subject rights requests", + "id": "9c3af74c-fd0f-4db4-b17a-71939e2a9d77", + "origin": "Delegated (Microsoft Graph)", + "value": "SubjectRightsRequest.Read.All" }, { - "description": "Allows the app to read all\u00a0class assignments without grades for all users without a signed-in user.", - "displayName": "Read all class assignments without grades", - "id": "6e0a958b-b7fc-4348-b7c4-a6ab9fd3dd0e", - "origin": "Application", - "value": "EduAssignments.ReadBasic.All" + "description": "Allows the app to read and write subject rights requests on behalf of the signed-in user", + "displayName": "Read and write subject rights requests", + "id": "2b8fcc74-bce1-4ae3-a0e8-60c53739299d", + "origin": "Delegated (Microsoft Graph)", + "value": "SubjectRightsRequest.ReadWrite.All" }, { - "description": "Allows the app to create, read, update and delete all\u00a0class assignments without grades for all users without a signed-in user.", - "displayName": "Create, read, update and delete all\u00a0class assignments without grades", - "id": "f431cc63-a2de-48c4-8054-a34bc093af84", - "origin": "Application", - "value": "EduAssignments.ReadWriteBasic.All" + "description": "Allows the app to read all webhook subscriptions on behalf of the signed-in user.", + "displayName": "Read all webhook subscriptions ", + "id": "5f88184c-80bb-4d52-9ff2-757288b2e9b7", + "origin": "Delegated (Microsoft Graph)", + "value": "Subscription.Read.All" }, { - "description": "Allows the app to read all\u00a0class assignments with grades for all users without a signed-in user.", - "displayName": "Read all class assignments with grades", - "id": "4c37e1b6-35a1-43bf-926a-6f30f2cdf585", - "origin": "Application", - "value": "EduAssignments.Read.All" + "description": "Allows the app to read Azure AD synchronization information, on behalf of the signed-in user.", + "displayName": "Read all Azure AD synchronization data", + "id": "7aa02aeb-824f-4fbe-a3f7-611f751f5b55", + "origin": "Delegated (Microsoft Graph)", + "value": "Synchronization.Read.All" }, { - "description": "Allows the app to create, read, update and delete all\u00a0class assignments with grades for all users without a signed-in user.", - "displayName": "Create, read, update and delete all\u00a0class assignments with grades", - "id": "0d22204b-6cad-4dd0-8362-3e3f2ae699d9", - "origin": "Application", - "value": "EduAssignments.ReadWrite.All" + "description": "Allows the app to configure the Azure AD synchronization service, on behalf of the signed-in user.", + "displayName": "Read and write all Azure AD synchronization data", + "id": "7bb27fa3-ea8f-4d67-a916-87715b6188bd", + "origin": "Delegated (Microsoft Graph)", + "value": "Synchronization.ReadWrite.All" }, { - "description": "Allows\u00a0the\u00a0app\u00a0to\u00a0read\u00a0subject\u00a0rights requests\u00a0without a\u00a0signed-in\u00a0user.", - "displayName": "Read\u00a0all subject\u00a0rights requests", - "id": "ee1460f0-368b-4153-870a-4e1ca7e72c42", - "origin": "Application", - "value": "SubjectRightsRequest.Read.All" + "description": "Allows the app to upload bulk user data to the identity synchronization service, on behalf of the signed-in user.", + "displayName": "Upload user data to the identity synchronization service", + "id": "1a2e7420-4e92-4d2b-94cb-fb2952e9ddf7", + "origin": "Delegated (Microsoft Graph)", + "value": "SynchronizationData-User.Upload" }, { - "description": "Allows\u00a0the\u00a0app\u00a0to\u00a0read\u00a0and\u00a0write subject\u00a0rights requests\u00a0without a signed in user.", - "displayName": "Read\u00a0and\u00a0write\u00a0all subject\u00a0rights requests", - "id": "8387eaa4-1a3c-41f5-b261-f888138e6041", - "origin": "Application", - "value": "SubjectRightsRequest.ReadWrite.All" + "description": "Allows the app to read the signed-in user’s tasks and task lists, including any shared with the user. Doesn't include permission to create, delete, or update anything.", + "displayName": "Read user's tasks and task lists", + "id": "f45671fb-e0fe-4b4b-be20-3d3ce43f1bcb", + "origin": "Delegated (Microsoft Graph)", + "value": "Tasks.Read" }, { - "description": "Allows the app to read attack simulation and training data for an organization without a signed-in user.", - "displayName": "Read attack simulation data of an organization", - "id": "93283d0a-6322-4fa8-966b-8c121624760d", - "origin": "Application", - "value": "AttackSimulation.Read.All" + "description": "Allows the app to read tasks a user has permissions to access, including their own and shared tasks.", + "displayName": "Read user and shared tasks", + "id": "88d21fd4-8e5a-4c32-b5e2-4a1c95f34f72", + "origin": "Delegated (Microsoft Graph)", + "value": "Tasks.Read.Shared" }, { - "description": "Allows custom authentication extensions associated with the app to receive HTTP requests triggered by an authentication event. The request can include information about a user, client and resource service principals, and other information about the authentication.", - "displayName": "Receive custom authentication extension HTTP requests", - "id": "214e810f-fda8-4fd7-a475-29461495eb00", - "origin": "Application", - "value": "CustomAuthenticationExtension.Receive.Payload" + "description": "Allows the app to create, read, update, and delete the signed-in user's tasks and task lists, including any shared with the user.", + "displayName": "Create, read, update, and delete user’s tasks and task lists", + "id": "2219042f-cab5-40cc-b0d2-16b1540b4c5f", + "origin": "Delegated (Microsoft Graph)", + "value": "Tasks.ReadWrite" }, { - "description": "Allows the app to read and write your organization's directory access review default policy without a signed-in user.", - "displayName": "Read and write your organization's directory access review default policy", - "id": "77c863fd-06c0-47ce-a7eb-49773e89d319", - "origin": "Application", - "value": "Policy.ReadWrite.AccessReview" + "description": "Allows the app to create, read, update, and delete tasks a user has permissions to, including their own and shared tasks.", + "displayName": "Read and write user and shared tasks", + "id": "c5ddf11b-c114-4886-8558-8a4e557cd52b", + "origin": "Delegated (Microsoft Graph)", + "value": "Tasks.ReadWrite.Shared" }, { - "description": "Allows the app to create groups, read all group properties and memberships, update group properties and memberships, and delete groups. Also allows the app to read and write conversations. All of these operations can be performed by the app without a signed-in user.", - "displayName": "Read and write all groups", - "id": "62a82d76-70ea-41e2-9197-370581804d09", - "origin": "Application", - "value": "Group.ReadWrite.All" + "description": "Allows the app to create teams on behalf of the signed-in user.", + "displayName": "Create teams", + "id": "7825d5d6-6049-4ce7-bdf6-3b8d53f4bcd0", + "origin": "Delegated (Microsoft Graph)", + "value": "Team.Create" }, { - "description": "Allows the app to read group properties and memberships, and read\u00a0conversations for all groups, without a signed-in user.", - "displayName": "Read all groups", - "id": "5b567255-7703-4780-807c-7be8301ae99b", - "origin": "Application", - "value": "Group.Read.All" + "description": "Read the names and descriptions of teams, on behalf of the signed-in user.", + "displayName": "Read the names and descriptions of teams", + "id": "485be79e-c497-4b35-9400-0e3fa7f2a5d4", + "origin": "Delegated (Microsoft Graph)", + "value": "Team.ReadBasic.All" }, { - "description": "Allows the app to read your organization's threat submissions and threat submission policies without a signed-in user. Also allows the app to create new threat submissions without a signed-in user.", - "displayName": "Read and write all of the organization's threat submissions", - "id": "d72bdbf4-a59b-405c-8b04-5995895819ac", - "origin": "Application", - "value": "ThreatSubmission.ReadWrite.All" + "description": "Read the members of teams, on behalf of the signed-in user.", + "displayName": "Read the members of teams", + "id": "2497278c-d82d-46a2-b1ce-39d4cdde5570", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamMember.Read.All" }, { - "description": "Allows an app to read Bookings appointments, businesses, customers, services, and staff without a signed-in user. ", - "displayName": "Read all Bookings related resources.", - "id": "6e98f277-b046-4193-a4f2-6bf6a78cd491", - "origin": "Application", - "value": "Bookings.Read.All" + "description": "Add and remove members from teams, on behalf of the signed-in user. Also allows changing a member's role, for example from owner to non-owner.", + "displayName": "Add and remove members from teams", + "id": "4a06efd2-f825-4e34-813e-82a57b03d1ee", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamMember.ReadWrite.All" }, { - "description": "Allows an app to read and write Bookings appointments and customers, and additionally allows reading businesses, services, and staff without a signed-in user. ", - "displayName": "Read and write all Bookings related resources.", - "id": "9769393e-5a9f-4302-9e3d-7e018ecb64a7", - "origin": "Application", - "value": "BookingsAppointment.ReadWrite.All" + "description": "Allows the app to read your organization's SPIFFE trust domains and child resources on behalf of the user.", + "displayName": "Read SPIFFE trust domains and child resources", + "id": "9b4aa4b1-aaf3-41b7-b743-698b27e77ff6", + "origin": "Delegated (Microsoft Graph)", + "value": "SpiffeTrustDomain.Read.All" }, { - "description": "Allows the application to read any data from Records Management, such as configuration, labels, and policies without the signed in user.", - "displayName": "Read Records Management configuration,\u00a0labels and policies", - "id": "ac3a2b8e-03a3-4da9-9ce0-cbe28bf1accd", - "origin": "Application", - "value": "RecordsManagement.Read.All" + "description": "Add and remove members from all teams, on behalf of the signed-in user. Does not allow adding or removing a member with the owner role. Additionally, does not allow the app to elevate an existing member to the owner role.", + "displayName": "Add and remove members with non-owner role for all teams", + "id": "2104a4db-3a2f-4ea0-9dba-143d457dc666", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamMember.ReadWriteNonOwnerRole.All" }, { - "description": "Allow the application to create, update and delete any data from Records Management, such as configuration, labels, and policies without the signed in user.", - "displayName": "Read and write Records Management configuration, labels and policies", - "id": "eb158f57-df43-4751-8b21-b8932adb3d34", - "origin": "Application", - "value": "RecordsManagement.ReadWrite.All" + "description": "Allows the app to be able to send emails from the user’s mailbox using the SMTP AUTH client submission protocol.", + "displayName": "Send emails from mailboxes using SMTP AUTH.", + "id": "258f6531-6087-4cc4-bb90-092c5fb3ed3f", + "origin": "Delegated (Microsoft Graph)", + "value": "SMTP.Send" }, { - "description": "Allows the app to read details of delegated admin relationships with customers like access details (that includes roles) and the duration as well as specific role assignments to security groups without a signed-in user.", - "displayName": "Read Delegated Admin relationships with customers", - "id": "f6e9e124-4586-492f-adc0-c6f96e4823fd", - "origin": "Application", - "value": "DelegatedAdminRelationship.Read.All" + "description": "Allows the application to edit or delete documents and list items in all site collections on behalf of the signed-in user.", + "displayName": "Edit or delete items in all site collections", + "id": "89fe6a52-be36-487e-b7d8-d061c450a026", + "origin": "Delegated (Microsoft Graph)", + "value": "Sites.ReadWrite.All" }, { - "description": "Allows the app to manage (create-update-terminate) Delegated Admin relationships with customers and role assignments to security groups for active Delegated Admin relationships without a signed-in user.", - "displayName": "Manage Delegated Admin relationships with customers", - "id": "cc13eba4-8cd8-44c6-b4d4-f93237adce58", - "origin": "Application", - "value": "DelegatedAdminRelationship.ReadWrite.All" + "description": "Allows the app to read your tenant's service health information on behalf of the signed-in user. Health information may include service issues or service health overviews.", + "displayName": "Read service health", + "id": "55896846-df78-47a7-aa94-8d3d4442ca7f", + "origin": "Delegated (Microsoft Graph)", + "value": "ServiceHealth.Read.All" }, { - "description": "Allows the app to read and manage the Cloud PC role-based access control (RBAC) settings, without a signed-in user. This includes reading and managing Cloud PC role definitions and memberships.", - "displayName": "Read and write all Cloud PC RBAC settings", - "id": "274d0592-d1b6-44bd-af1d-26d259bcb43a", - "origin": "Application", - "value": "RoleManagement.ReadWrite.CloudPC" + "description": "Allows the app to read your tenant's service announcement messages on behalf of the signed-in user. Messages may include information about new or changed features.", + "displayName": "Read service announcement messages", + "id": "eda39fa6-f8cf-4c3c-a909-432c683e4c9b", + "origin": "Delegated (Microsoft Graph)", + "value": "ServiceMessage.Read.All" }, { - "description": "Allows the app to read the Cloud PC role-based access control (RBAC) settings, without a signed-in user.", - "displayName": "Read Cloud PC RBAC settings", - "id": "031a549a-bb80-49b6-8032-2068448c6a3c", - "origin": "Application", - "value": "RoleManagement.Read.CloudPC" + "description": "Allows the app to update service announcement messages' user status on behalf of the signed-in user. The message status can be marked as read, archive, or favorite.", + "displayName": "Update user status on service announcement messages", + "id": "636e1b0b-1cc2-4b1c-9aa9-4eeed9b9761b", + "origin": "Delegated (Microsoft Graph)", + "value": "ServiceMessageViewpoint.Write" }, { - "description": "Allows the app to read custom security attribute assignments for all principals in the tenant without a signed in user.", - "displayName": "Read custom security attribute assignments", - "id": "3b37c5a4-1226-493d-bec3-5d6c6b866f3f", - "origin": "Application", - "value": "CustomSecAttributeAssignment.Read.All" + "description": "Allows the app to read service principal endpoints", + "displayName": "Read service principal endpoints", + "id": "9f9ce928-e038-4e3b-8faf-7b59049a8ddc", + "origin": "Delegated (Microsoft Graph)", + "value": "ServicePrincipalEndpoint.Read.All" }, { - "description": "Allows the app to read custom security attribute definitions for the tenant without a signed in user.", - "displayName": "Read custom security attribute definitions", - "id": "b185aa14-d8d2-42c1-a685-0f5596613624", - "origin": "Application", - "value": "CustomSecAttributeDefinition.Read.All" + "description": "Allows the app to update service principal endpoints", + "displayName": "Read and update service principal endpoints", + "id": "7297d82c-9546-4aed-91df-3d4f0a9b3ff0", + "origin": "Delegated (Microsoft Graph)", + "value": "ServicePrincipalEndpoint.ReadWrite.All" }, { - "description": "Allows the app to read all external connections without a signed-in user.", - "displayName": "Read all external connections", - "id": "1914711b-a1cb-4793-b019-c2ce0ed21b8c", - "origin": "Application", - "value": "ExternalConnection.Read.All" + "description": "Allows the app to read, write and manage your tenant's SharePoint Cross-Tenant migration settings and tasks, on behalf of the signed-in user.", + "displayName": "Read, write and manage SharePoint Cross-Tenant migration settings and tasks", + "id": "c608c170-08b5-466b-a8fe-0b4074b01613", + "origin": "Delegated (Microsoft Graph)", + "value": "SharePointCrossTenantMigration.Manage.All" }, { - "description": "Allows the app to read and write all external connections without a signed-in user.", - "displayName": "Read and write all external connections", - "id": "34c37bc0-2b40-4d5e-85e1-2365cd256d79", - "origin": "Application", - "value": "ExternalConnection.ReadWrite.All" + "description": "Allows the app to read your tenant's SharePoint Cross-Tenant migration settings and tasks, on behalf of the signed-in user.", + "displayName": "Read SharePoint Cross-Tenant migration settings and tasks", + "id": "00dcb678-f9af-4e73-acb1-4f1657364629", + "origin": "Delegated (Microsoft Graph)", + "value": "SharePointCrossTenantMigration.Read.All" }, { - "description": "Allows the app to read all external items without a signed-in user.", - "displayName": "Read all external items", - "id": "7a7cffad-37d2-4f48-afa4-c6ab129adcc2", - "origin": "Application", - "value": "ExternalItem.Read.All" + "description": "Allows the application to read the tenant-level settings in SharePoint and OneDrive on behalf of the signed-in user.", + "displayName": "Read SharePoint and OneDrive tenant settings", + "id": "2ef70e10-5bfd-4ede-a5f6-67720500b258", + "origin": "Delegated (Microsoft Graph)", + "value": "SharePointTenantSettings.Read.All" }, { - "description": "Allows the app to read and write your organization's cross tenant access policies without a signed-in user.", - "displayName": "Read and write your organization's cross tenant access policies", - "id": "338163d7-f101-4c92-94ba-ca46fe52447c", - "origin": "Application", - "value": "Policy.ReadWrite.CrossTenantAccess" + "description": "Allows the application to read and change the tenant-level settings of SharePoint and OneDrive on behalf of the signed-in user.", + "displayName": "Read and change SharePoint and OneDrive tenant settings", + "id": "aa07f155-3612-49b8-a147-6c590df35536", + "origin": "Delegated (Microsoft Graph)", + "value": "SharePointTenantSettings.ReadWrite.All" }, { - "description": "Allows the app to read and write custom security attribute definitions for the tenant without a signed in user.", - "displayName": "Read and write custom security attribute definitions", - "id": "12338004-21f4-4896-bf5e-b75dfaf1016d", - "origin": "Application", - "value": "CustomSecAttributeDefinition.ReadWrite.All" + "description": "Allows the app to read all the short notes a sign-in user has access to.", + "displayName": "Read short notes of the signed-in user", + "id": "50f66e47-eb56-45b7-aaa2-75057d9afe08", + "origin": "Delegated (Microsoft Graph)", + "value": "ShortNotes.Read" }, { - "description": "Allows the app to read and write custom security attribute assignments for all principals in the tenant without a signed in user.", - "displayName": "Read and write custom security attribute assignments", - "id": "de89b5e4-5b8f-48eb-8925-29c2b33bd8bd", - "origin": "Application", - "value": "CustomSecAttributeAssignment.ReadWrite.All" + "description": "Allows the app to read, create, edit, and delete short notes of a signed-in user.", + "displayName": "Read, create, edit, and delete short notes of the signed-in user", + "id": "328438b7-4c01-4c07-a840-e625a749bb89", + "origin": "Delegated (Microsoft Graph)", + "value": "ShortNotes.ReadWrite" }, { - "description": "Allows the app to read and write to all security incidents, without a signed-in user.", - "displayName": "Read and write to all security incidents", - "id": "34bf0e97-1971-4929-b999-9e2442d941d7", - "origin": "Application", - "value": "SecurityIncident.ReadWrite.All" + "description": "Allows the app to read your organization's sign-in identifiers, on behalf of the signed-in user.", + "displayName": "Read SignInIdentifiers", + "id": "458e1edc-1e75-438c-8c7b-c32115c9d373", + "origin": "Delegated (Microsoft Graph)", + "value": "SignInIdentifier.Read.All" }, { - "description": "Allows the app to read all security incidents, without a signed-in user.", - "displayName": "Read all security incidents", - "id": "45cc0394-e837-488b-a098-1918f48d186c", - "origin": "Application", - "value": "SecurityIncident.Read.All" + "description": "Allows the app to read and write your organization's sign-in identifiers, on behalf of the signed-in user.", + "displayName": "Read and write all sign-in identifiers", + "id": "b4673c3c-7b5a-4012-9826-7c7e3c8db6af", + "origin": "Delegated (Microsoft Graph)", + "value": "SignInIdentifier.ReadWrite.All" }, { - "description": "Allows the app to read and write to all security alerts, without a signed-in user.", - "displayName": "Read and write to all security alerts", - "id": "ed4fca05-be46-441f-9803-1873825f8fdb", - "origin": "Application", - "value": "SecurityAlert.ReadWrite.All" + "description": "Allow the application to create site collections on behalf of the signed in user. Upon creation the application will be granted Sites.Selected(delegated) + FullControl to the newly created site.", + "displayName": "Create Site Collections, on behalf of the signed-in user", + "id": "0e2e68e1-3f32-4e10-9281-f749e097fcbe", + "origin": "Delegated (Microsoft Graph)", + "value": "Sites.Create.All" }, { - "description": "Allows the app to read all security alerts, without a signed-in user.", - "displayName": "Read all security alerts", - "id": "472e4a4d-bb4a-4026-98d1-0b0d74cb74a5", - "origin": "Application", - "value": "SecurityAlert.Read.All" + "description": "Allows the application to have full control of all site collections on behalf of the signed-in user.", + "displayName": "Have full control of all site collections", + "id": "5a54b8b3-347c-476d-8f8e-42d5c7424d29", + "origin": "Delegated (Microsoft Graph)", + "value": "Sites.FullControl.All" + }, + { + "description": "Allows the application to create or delete document libraries and lists in all site collections on behalf of the signed-in user.", + "displayName": "Create, edit, and delete items and lists in all site collections", + "id": "65e50fdc-43b7-4915-933e-e8138f11f40a", + "origin": "Delegated (Microsoft Graph)", + "value": "Sites.Manage.All" + }, + { + "description": "Allows the application to read documents and list items in all site collections on behalf of the signed-in user", + "displayName": "Read items in all site collections", + "id": "205e70e5-aba6-4c52-a976-6d2d46c48043", + "origin": "Delegated (Microsoft Graph)", + "value": "Sites.Read.All" + }, + { + "description": "Allow the application to access a subset of site collections on behalf of the signed-in user. The specific site collections and the permissions granted will be configured in SharePoint Online.", + "displayName": "Access selected Sites, on behalf of the signed-in user", + "id": "f89c84ef-20d0-4b54-87e9-02e856d66d53", + "origin": "Delegated (Microsoft Graph)", + "value": "Sites.Selected" + }, + { + "description": "Allows the app to read all Teams service activity, on behalf of the signed-in user.", + "displayName": "Read all Teams service activity", + "id": "404d76f0-e10e-460a-92be-ef19600c54d1", + "origin": "Delegated (Microsoft Graph)", + "value": "ServiceActivity-Teams.Read.All" + }, + { + "description": "Allows the app to read the signed-in user's teamwork activity feed.", + "displayName": "Read user's teamwork activity feed", + "id": "0e755559-83fb-4b44-91d0-4cc721b9323e", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsActivity.Read" + }, + { + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in chats the signed-in user can access. Gives the ability to manage permission grants for accessing those specific chats' data.", + "displayName": "Manage installation and permission grants of selected Teams apps in chats", + "id": "d1ba22c6-3f02-4c91-addb-bc3399bcca88", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ManageSelectedForChat" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself to teams the signed-in user can access.", + "displayName": "Allow the app to manage itself in teams", + "id": "0f4595f7-64b1-4e13-81bc-11a249df07a9", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteSelfForTeam" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for the signed-in user.", + "displayName": "Allow the Teams app to manage itself for a user", + "id": "207e0cb1-3ce7-4922-b991-5a760c346ebc", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteSelfForUser" + }, + { + "description": "Read all teams' settings, on behalf of the signed-in user.", + "displayName": "Read teams' settings", + "id": "48638b3c-ad68-4383-8ac4-e6880ee6ca57", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamSettings.Read.All" + }, + { + "description": "Read and change all teams' settings, on behalf of the signed-in user.", + "displayName": "Read and change teams' settings", + "id": "39d65650-9d3e-4223-80db-a335590d027e", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamSettings.ReadWrite.All" + }, + { + "description": "Allow the app to read or write/update the policy assignment and unassigment for Teams users for all policy type categories.", + "displayName": "Read and Write Teams policy user assignment and unassigment for all policy types.", + "id": "6997c35c-a586-440c-8a0b-4ffe5d118dc0", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsPolicyUserAssign.ReadWrite.All" + }, + { + "description": "Allows the app to read your tenant's resource accounts on behalf of the signed-in admin user.", + "displayName": "Read Teams resource accounts", + "id": "ea2cbd09-253c-4f69-a0e6-07383c5f07cc", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsResourceAccount.Read.All" + }, + { + "description": "Allows the app to create tabs in any team in Microsoft Teams, on behalf of the signed-in user. This does not grant the ability to read, modify or delete tabs after they are created, or give access to the content inside the tabs.", + "displayName": "Create tabs in Microsoft Teams.", + "id": "a9ff19c2-f369-4a95-9a25-ba9d460efc8e", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsTab.Create" + }, + { + "description": "Read the names and settings of tabs inside any team in Microsoft Teams, on behalf of the signed-in user. This does not give access to the content inside the tabs.", + "displayName": "Read tabs in Microsoft Teams.", + "id": "59dacb05-e88d-4c13-a684-59f1afc8cc98", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsTab.Read.All" + }, + { + "description": "Read and write tabs in any team in Microsoft Teams, on behalf of the signed-in user. This does not give access to the content inside the tabs.", + "displayName": "Read and write tabs in Microsoft Teams.", + "id": "b98bfd41-87c6-45cc-b104-e2de4f0dafb9", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsTab.ReadWrite.All" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs in chats the signed-in user can access.", + "displayName": "Allow the Teams app to manage all tabs in chats", + "id": "ee928332-e9c2-4747-b4a0-f8c164b68de6", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsTab.ReadWriteForChat" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs to teams the signed-in user can access.", + "displayName": "Allow the Teams app to manage all tabs in teams", + "id": "c975dd04-a06e-4fbb-9704-62daad77bb49", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsTab.ReadWriteForTeam" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs for the signed-in user.", + "displayName": "Allow the Teams app to manage all tabs for a user", + "id": "c37c9b61-7762-4bff-a156-afc0005847a0", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsTab.ReadWriteForUser" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs in chats the signed-in user can access.", + "displayName": "Allow the Teams app to manage only its own tabs in chats", + "id": "0c219d04-3abf-47f7-912d-5cca239e90e6", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsTab.ReadWriteSelfForChat" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs to teams the signed-in user can access.", + "displayName": "Allow the Teams app to manage only its own tabs in teams", + "id": "f266662f-120a-4314-b26a-99b08617c7ef", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsTab.ReadWriteSelfForTeam" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for the signed-in user.", + "displayName": "Allow the Teams app to manage only its own tabs for a user", + "id": "395dfec1-a0b9-465f-a783-8250a430cb8c", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsTab.ReadWriteSelfForUser" + }, + { + "description": "Allows the app to read your tenant's acquired telephone number details on behalf of the signed-in admin user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", + "displayName": "Read Tenant-Acquired Telephone Number Details", + "id": "1bc6eab1-058d-4557-b011-d4c41cec88b7", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsTelephoneNumber.Read.All" + }, + { + "description": "Allows the app to read and modify your tenant's acquired telephone number details on behalf of the signed-in admin user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", + "displayName": "Read and Modify Tenant-Acquired Telephone Number Details", + "id": "424b07a8-1209-4d17-9fe4-9018a93a1024", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsTelephoneNumber.ReadWrite.All" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in chats the signed-in user can access.", + "displayName": "Allow the Teams app to manage itself in chats", + "id": "0ce33576-30e8-43b7-99e5-62f8569a4002", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteSelfForChat" + }, + { + "description": "Allows the app to create new notifications in users' teamwork activity feeds on behalf of the signed in user. These notifications may not be discoverable or be held or governed by compliance policies.", + "displayName": "Send a teamwork activity as the user", + "id": "7ab1d787-bae7-4d5d-8db6-37ea32df9186", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsActivity.Send" + }, + { + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps installed for the signed in user. Does not give the ability to read application-specific settings.", + "displayName": "Manage selected Teams apps installed for a user", + "id": "ea819e27-c92a-4118-b83b-4540b125d744", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteSelectedForUser" + }, + { + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in chats the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Manage selected Teams apps installed in chats", + "id": "690aa3b6-4b71-41c2-a990-77a8c4768d2b", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteSelectedForChat" + }, + { + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in teams the signed-in user can access. Gives the ability to manage permission grants for accessing those specific teams' data.", + "displayName": "Manage installation and permission grants of selected Teams apps in teams", + "id": "c67b2d7e-6b80-4218-938a-05e73058e42d", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ManageSelectedForTeam" + }, + { + "description": "Allows the app to read, install, upgrade, and uninstall seleected Teams apps in user accounts, on behalf of the signed-in user. Gives the ability to manage permission grants for accessing those specific users' data.", + "displayName": "Manage installation and permission grants of selected Teams apps in users' personal scope", + "id": "830c2bd9-c335-4caf-bf83-c07fa8a23ef1", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ManageSelectedForUser" + }, + { + "description": "Allows the app to read the Teams apps that are installed in chats the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Read installed Teams apps in chats", + "id": "bf3fbf03-f35f-4e93-963e-47e4d874c37a", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadForChat" + }, + { + "description": "Allows the app to read the Teams apps that are installed in teams the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Read installed Teams apps in teams", + "id": "5248dcb1-f83b-4ec3-9f4d-a4428a961a72", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadForTeam" + }, + { + "description": "Allows the app to read the Teams apps that are installed for the signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Read user's installed Teams apps", + "id": "c395395c-ff9a-4dba-bc1f-8372ba9dca84", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadForUser" + }, + { + "description": "Allows the app to read the selected Teams apps that are installed in chats the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Read selected installed Teams apps in chats", + "id": "0f3420c2-c6ec-46de-ab72-fd51267087d5", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadSelectedForChat" + }, + { + "description": "Allows the app to read the selected Teams apps that are installed in teams the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Read selected installed Teams apps in teams", + "id": "b55df1c0-db20-435b-aef2-afe6ed487e16", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadSelectedForTeam" + }, + { + "description": "Allows the app to read the selected Teams apps that are installed for the signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Read user's selected installed Teams apps", + "id": "fe2e4e1d-101f-4fb2-9cb1-9d6659db45d4", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadSelectedForUser" + }, + { + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in chats the signed-in user can access. Gives the ability to manage permission grants for accessing those specific chats' data.", + "displayName": "Manage installed Teams apps in chats", + "id": "e1408a66-8f82-451b-a2f3-3c3e38f7413f", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentForChat" + }, + { + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in teams the signed-in user can access. Gives the ability to manage permission grants for accessing those specific teams' data.", + "displayName": "Manage installed Teams apps in teams", + "id": "946349d5-2a9d-4535-abc0-7beeacaedd1d", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentForTeam" + }, + { + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in user accounts, on behalf of the signed-in user. Gives the ability to manage permission grants for accessing those specific users' data.", + "displayName": "Manage installation and permission grants of Teams apps in users' personal scope", + "id": "2da62c49-dfbd-40df-ba16-fef3529d391c", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentForUser" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in chats the signed-in user can access, and manage its permission grants for accessing those specific chats' data.", + "displayName": "Allow the Teams app to manage itself and its permission grants in chats", + "id": "a0e0e18b-8fb2-458f-8130-da2d7cab9c75", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForChat" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in teams the signed-in user can access, and manage its permission grants for accessing those specific teams' data.", + "displayName": "Allow the Teams app to manage itself and its permission grants in teams", + "id": "4a6bbf29-a0e1-4a4d-a7d1-cef17f772975", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForTeam" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in user accounts, and manage its permission grants for accessing those specific users' data, on behalf of the signed-in user.", + "displayName": "Allow the Teams app to manage itself and its permission grants in user accounts", + "id": "7a349935-c54d-44ab-ab66-1b460d315be7", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForUser" + }, + { + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in chats the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Manage installed Teams apps in chats", + "id": "aa85bf13-d771-4d5d-a9e6-bca04ce44edf", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteForChat" + }, + { + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in teams the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Manage installed Teams apps in teams", + "id": "2e25a044-2580-450d-8859-42eeb6e996c0", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteForTeam" + }, + { + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps installed for the signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Manage user's installed Teams apps", + "id": "093f8818-d05f-49b8-95bc-9d2a73e9a43c", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteForUser" + }, + { + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in teams the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Manage selected Teams apps installed in teams", + "id": "9131c833-9a49-4c54-b38f-615ecfc4fc69", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteSelectedForTeam" + }, + { + "description": "Allows the app to read all One Drive service activity, on behalf of the signed-in user.", + "displayName": "Read all One Drive service activity", + "id": "347e3c16-30f3-4ac7-9b52-fc3c053de9c9", + "origin": "Delegated (Microsoft Graph)", + "value": "ServiceActivity-OneDrive.Read.All" + }, + { + "description": "Allows the app to read all Microsoft 365 Web service activity, on behalf of the signed-in user.", + "displayName": "Read all Microsoft 365 Web service activity", + "id": "d74c75b1-d5a9-479d-902d-92f8f99182c1", + "origin": "Delegated (Microsoft Graph)", + "value": "ServiceActivity-Microsoft365Web.Read.All" + }, + { + "description": "Allows the app to read all Exchange service activity, on behalf of the signed-in user.", + "displayName": "Read all Exchange service activity", + "id": "1fe7aa48-9373-4a47-8df3-168335e0f4c9", + "origin": "Delegated (Microsoft Graph)", + "value": "ServiceActivity-Exchange.Read.All" + }, + { + "description": "Allows the app to read your organization's risk prevention providers, on behalf of the signed-in user.", + "displayName": "Read all identity risk prevention providers", + "id": "e197c06f-ae7b-4398-b0a2-89f76ebca159", + "origin": "Delegated (Microsoft Graph)", + "value": "RiskPreventionProviders.Read.All" + }, + { + "description": "Allows the app to read and write your organization's risk prevention providers, on behalf of the signed-in user.", + "displayName": "Read and write all identity risk prevention providers", + "id": "2a7babba-9623-4109-bc9c-79728cf3bb4f", + "origin": "Delegated (Microsoft Graph)", + "value": "RiskPreventionProviders.ReadWrite.All" + }, + { + "description": "Allows the app to read the active role-based access control (RBAC) assignments for your company's directory, on behalf of the signed-in user. This includes reading directory role templates, and directory roles.", + "displayName": "Read all active role assignments for your company's directory", + "id": "344a729c-0285-42c6-9014-f12b9b8d6129", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleAssignmentSchedule.Read.Directory" + }, + { + "description": "Allows the app to read and manage the active role-based access control (RBAC) assignments for your company's directory, on behalf of the signed-in user. This includes managing active directory role membership, and reading directory role templates, directory roles and active memberships.", + "displayName": "Read, update, and delete all active role assignments for your company's directory", + "id": "8c026be3-8e26-4774-9372-8d5d6f21daff", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleAssignmentSchedule.ReadWrite.Directory" + }, + { + "description": "Allows the app to delete the active role-based access control (RBAC) assignments for your company's directory, on behalf of the signed-in user.", + "displayName": "Delete all active role assignments for your company's directory", + "id": "f71cd05c-3fdb-4568-aef2-e1cf62ee20d4", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleAssignmentSchedule.Remove.Directory" + }, + { + "description": "Allows the app to read the eligible role-based access control (RBAC) assignments for your company's directory, on behalf of the signed-in user. This includes reading directory role templates, and directory roles.", + "displayName": "Read all eligible role assignments for your company's directory", + "id": "eb0788c2-6d4e-4658-8c9e-c0fb8053f03d", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleEligibilitySchedule.Read.Directory" + }, + { + "description": "Allows the app to read and manage the eligible role-based access control (RBAC) assignments for your company's directory, on behalf of the signed-in user. This includes managing eligible directory role membership, and reading directory role templates, directory roles and eligible memberships.", + "displayName": "Read, update, and delete all eligible role assignments for your company's directory", + "id": "62ade113-f8e0-4bf9-a6ba-5acb31db32fd", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleEligibilitySchedule.ReadWrite.Directory" + }, + { + "description": "Allows the app to delete the eligible role-based access control (RBAC) assignments for your company's directory, on behalf of the signed-in user.", + "displayName": "Delete all eligible role assignments for your company's directory", + "id": "58ac4fa2-b484-4d6e-ba97-beee2a574220", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleEligibilitySchedule.Remove.Directory" + }, + { + "description": "Allows the app to read the role-based access control (RBAC) settings for all RBAC providers, on behalf of the signed-in user. This includes reading role definitions and role assignments.", + "displayName": "Read role management data for all RBAC providers", + "id": "48fec646-b2ba-4019-8681-8eb31435aded", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagement.Read.All" + }, + { + "description": "Allows the app to read the Cloud PC role-based access control (RBAC) settings, on behalf of the signed-in user. This includes reading Cloud PC role definitions and role assignments.", + "displayName": "Read Cloud PC RBAC settings", + "id": "9619b88a-8a25-48a7-9571-d23be0337a79", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagement.Read.CloudPC" + }, + { + "description": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes reading M365 Defender role definitions and role assignments.", + "displayName": "Read M365 Defender RBAC configuration", + "id": "dd689728-6eb8-4deb-bd38-2924a935f3de", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagement.Read.Defender" + }, + { + "description": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes reading directory role templates, directory roles and memberships.", + "displayName": "Read directory RBAC settings", + "id": "741c54c3-0c1e-44a1-818b-3f97ab4e8c83", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagement.Read.Directory" + }, + { + "description": "Allows the app to read the role-based access control (RBAC) settings for your organization's Exchange Online service, on behalf of the signed-in user. This includes reading Exchange management role definitions, role groups, role group membership, role assignments, management scopes, and role assignment policies.", + "displayName": "Read Exchange Online RBAC configuration", + "id": "3bc15058-7858-4141-b24f-ae43b4e80b52", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagement.Read.Exchange" + }, + { + "description": "Allows the app to read and manage the Cloud PC role-based access control (RBAC) settings, on behalf of the signed-in user. This includes reading and managing Cloud PC role definitions and role assignments.", + "displayName": "Read and write Cloud PC RBAC settings", + "id": "501d06f8-07b8-4f18-b5c6-c191a4af7a82", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagement.ReadWrite.CloudPC" + }, + { + "description": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes reading M365 Defender role definitions and role assignments.", + "displayName": "Read M365 Defender RBAC configuration", + "id": "d8914f8f-9f64-4bd1-b4d3-f5a701ed8457", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagement.ReadWrite.Defender" + }, + { + "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes instantiating directory roles and managing directory role membership, and reading directory role templates, directory roles and memberships.", + "displayName": "Read and write directory RBAC settings", + "id": "d01b97e9-cbc0-49fe-810a-750afd5527a3", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagement.ReadWrite.Directory" + }, + { + "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your organization's Exchange Online service, on behalf of the signed-in user. This includes reading, creating, updating, and deleting Exchange management role definitions, role groups, role group membership, role assignments, management scopes, and role assignment policies.", + "displayName": "Read and write Exchange Online RBAC configuration", + "id": "c1499fe0-52b1-4b22-bed2-7a244e0e879f", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagement.ReadWrite.Exchange" + }, + { + "description": "Allows the app to read the resource specific permissions granted on a user account, on behalf of the signed-in user.", + "displayName": "Read resource specific permissions granted on a user account", + "id": "f1d91a8f-88e7-4774-8401-b668d5bca0c5", + "origin": "Delegated (Microsoft Graph)", + "value": "ResourceSpecificPermissionGrant.ReadForUser" + }, + { + "description": "Allows the app to read the role-based access control (RBAC) alerts for your company's directory, on behalf of the signed-in user. This includes reading alert statuses, alert definitions, alert configurations and incidents that lead to an alert.", + "displayName": "Read all alert data for your company's directory", + "id": "cce71173-f76d-446e-97ff-efb2d82e11b1", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagementAlert.Read.Directory" + }, + { + "description": "Allows the app to read the resource specific permissions granted on the team, on behalf of the signed-in user.", + "displayName": "Read resource specific permissions granted on a team", + "id": "eafad40c-bf7a-415a-b7f8-acdf5706b58f", + "origin": "Delegated (Microsoft Graph)", + "value": "ResourceSpecificPermissionGrant.ReadForTeam" + }, + { + "description": "Allows the app to read and update admin report settings, such as whether to display concealed information in reports, on behalf of the signed-in user.", + "displayName": "Read and write admin report settings", + "id": "b955410e-7715-4a88-a940-dfd551018df3", + "origin": "Delegated (Microsoft Graph)", + "value": "ReportSettings.ReadWrite.All" + }, + { + "description": "Allows the app to read programs and program controls that the signed-in user has access to in the organization.", + "displayName": "Read all programs that user can access", + "id": "c492a2e1-2f8f-4caa-b076-99bbf6e40fe4", + "origin": "Delegated (Microsoft Graph)", + "value": "ProgramControl.Read.All" + }, + { + "description": "Allows the app to read, update, delete and perform actions on programs and program controls that the signed-in user has access to in the organization.", + "displayName": "Manage all programs that user can access", + "id": "50fd364f-9d93-4ae1-b170-300e87cccf84", + "origin": "Delegated (Microsoft Graph)", + "value": "ProgramControl.ReadWrite.All" + }, + { + "description": "Allows the app to identify Purview data protection, compliance and governance policy scopes defined for all users across tenant.", + "displayName": "Compute Purview policies at tenant scope", + "id": "98f5a27a-539a-48bc-a597-f78e9e1e76bf", + "origin": "Delegated (Microsoft Graph)", + "value": "ProtectionScopes.Compute.All" + }, + { + "description": "Allows the app to identify Purview data protection, compliance and governance policy scopes defined for an individual user.", + "displayName": "Compute Purview policies for an individual user", + "id": "4fc04d16-a9fc-4c5e-8da4-79b6c33638a4", + "origin": "Delegated (Microsoft Graph)", + "value": "ProtectionScopes.Compute.User" + }, + { + "description": "Allows the app to read and query your provisioning log activities, on behalf of the signed-in user.", + "displayName": "Read provisioning log data", + "id": "95aec97b-cf27-4a8d-a67d-42f60b5b38ef", + "origin": "Delegated (Microsoft Graph)", + "value": "ProvisioningLog.Read.All" + }, + { + "description": "Allows the application to read certificate-based authentication configuration such as all public key infrastructures (PKI) and certificate authorities (CA) configured for the organization, on behalf of the signed-in user.", + "displayName": "Read certificate based authentication configurations", + "id": "04a4b2a2-3f26-4fc8-87ee-9c46e68db175", + "origin": "Delegated (Microsoft Graph)", + "value": "PublicKeyInfrastructure.Read.All" + }, + { + "description": "Allows the application to read and write certificate-based authentication configuration such as all public key infrastructures (PKI) and certificate authorities (CA) configured for the organization, on behalf of the signed-in user.", + "displayName": "Read and write certificate based authentication configurations", + "id": "3591b7f3-dba8-4bad-b667-7a64bd4f2b83", + "origin": "Delegated (Microsoft Graph)", + "value": "PublicKeyInfrastructure.ReadWrite.All" + }, + { + "description": "Allows the application to create, read, update and delete pull-print printers and manage member printers on behalf of the signed-in user.", + "displayName": "Create, read, update and delete pull-print printers and manage member printers", + "id": "ef6b83cd-f762-47ff-97d7-6f6f2d0486ea", + "origin": "Delegated (Microsoft Graph)", + "value": "PullPrintPrinter.FullControl.All" + }, + { + "description": "Allows the application to read pull-print printers on behalf of the signed-in user. ", + "displayName": "Read pull-print printers", + "id": "deac7994-79bc-44c9-8828-01c1a9a96618", + "origin": "Delegated (Microsoft Graph)", + "value": "PullPrintPrinter.Read.All" + }, + { + "description": "Allows the application to read and update pull-print printers on behalf of the signed-in user. Does not allow creating or deleting pull-print printers or managing member printers.", + "displayName": "Read and update pull-print printers", + "id": "c628c397-5d7f-4c93-ae0f-4680282fd6d5", + "origin": "Delegated (Microsoft Graph)", + "value": "PullPrintPrinter.ReadWrite.All" + }, + { + "description": "Allows an app to read all question and answer sets that the signed-in user can access.", + "displayName": "Read all Questions and Answers that the user can access.", + "id": "f73fa04f-b9a5-4df9-8843-993ce928925e", + "origin": "Delegated (Microsoft Graph)", + "value": "QnA.Read.All" + }, + { + "description": "Allows the app to get direct access to real-time enriched data in a meeting, on behalf of the signed-in user.", + "displayName": "Access real-time enriched data in a meeting", + "id": "db5d5bae-0c9e-444e-9390-8a5fea98c253", + "origin": "Delegated (Microsoft Graph)", + "value": "RealTimeActivityFeed.Read.All" + }, + { + "description": "Allows the application to read any data from Records Management, such as configuration, labels, and policies on behalf of the signed-in user.", + "displayName": "Read Records Management configuration, labels, and policies", + "id": "07f995eb-fc67-4522-ad66-2b8ca8ea3efd", + "origin": "Delegated (Microsoft Graph)", + "value": "RecordsManagement.Read.All" + }, + { + "description": "Allow the application to create, update and delete any data from Records Management, such as configuration, labels, and policies on behalf of the signed-in user.", + "displayName": "Read and write Records Management configuration, labels, and policies", + "id": "f2833d75-a4e6-40ab-86d4-6dfe73c97605", + "origin": "Delegated (Microsoft Graph)", + "value": "RecordsManagement.ReadWrite.All" + }, + { + "description": "Allows the app to read available properties of remoteTenantGroups, on behalf of the signed-in user.", + "displayName": "Read RemoteTenantGroups information", + "id": "d207fff0-6e36-4360-a23b-495e23b60385", + "origin": "Delegated (Microsoft Graph)", + "value": "RemoteTenantGroups.Read.All" + }, + { + "description": "Allows an app to read all service usage reports on behalf of the signed-in user. Services that provide usage reports include Office 365 and Azure Active Directory.", + "displayName": "Read all usage reports", + "id": "02e97553-ed7b-43d0-ab3c-f8bace0d040c", + "origin": "Delegated (Microsoft Graph)", + "value": "Reports.Read.All" + }, + { + "description": "Allows the app to read admin report settings, such as whether to display concealed information in reports, on behalf of the signed-in user", + "displayName": "Read admin report settings", + "id": "84fac5f4-33a9-4100-aa38-a20c6d29e5e7", + "origin": "Delegated (Microsoft Graph)", + "value": "ReportSettings.Read.All" + }, + { + "description": "Allows the app to read the resource specific permissions granted on the chat, on behalf of the signed-in user.", + "displayName": "Read resource specific permissions granted on a chat", + "id": "cb530fca-534b-4e72-aa74-bca7e8bbd06f", + "origin": "Delegated (Microsoft Graph)", + "value": "ResourceSpecificPermissionGrant.ReadForChat" + }, + { + "description": "Allows the app to read and manage the role-based access control (RBAC) alerts for your company's directory, on behalf of the signed-in user. This includes managing alert settings, initiating alert scans, dismissing alerts, remediating alert incidents, and reading alert statuses, alert definitions, alert configurations and incidents that lead to an alert.", + "displayName": "Read all alert data, configure alerts, and take actions on all alerts for your company's directory", + "id": "435644c6-a5b1-40bf-8f52-fe8e5b53e19c", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagementAlert.ReadWrite.Directory" + }, + { + "description": "Allows the app to read policies in Privileged Identity Management for Groups, on behalf of the signed-in user.", + "displayName": "Read all policies in PIM for Groups", + "id": "7e26fdff-9cb1-4e56-bede-211fe0e420e8", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagementPolicy.Read.AzureADGroup" + }, + { + "description": "Allows the app to read policies for privileged role-based access control (RBAC) assignments of your company's directory, on behalf of the signed-in user.", + "displayName": "Read all policies for privileged role assignments of your company's directory", + "id": "3de2cdbe-0ff5-47d5-bdee-7f45b4749ead", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagementPolicy.Read.Directory" + }, + { + "description": "Allows the app to read the sensors window auditing configuration of the signed in user", + "displayName": "Read sensors window auditing configuration", + "id": "8ff90903-1ecb-4f3a-b8b2-42120374ecd6", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIdentitiesAutoConfig.Read.All" + }, + { + "description": "Allows the app to read and write the sensors window auditing configuration of the signed in user", + "displayName": "Read and write sensors window auditing configuration", + "id": "b810fdb4-8733-43bd-9b37-fddb7215c69f", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIdentitiesAutoConfig.ReadWrite.All" + }, + { + "description": "Allows the app to read all the identity security health issues of signed user", + "displayName": "Read identity security health issues", + "id": "a0d0da43-a6df-4416-b63d-99c79991aae8", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIdentitiesHealth.Read.All" + }, + { + "description": "Allows the app to read and write identity security health issues on behalf of the signed-in user.", + "displayName": "Read and write identity security health issues", + "id": "53e51eec-2d9b-4990-97f3-c9aa5d5652c3", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIdentitiesHealth.ReadWrite.All" + }, + { + "description": "Allows the app to read all the identity security sensor migration information of signed user", + "displayName": "Read identity security sensor migration", + "id": "63595162-fcc0-4127-8b1e-bfe90b23a10e", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIdentitiesMigration.Read.All" + }, + { + "description": "Allows the app to read and write identity security sensor migration on behalf of the signed-in user.", + "displayName": "Read and write identity security sensor migration", + "id": "741a6ef0-37e6-4b0a-9178-133d94fbc46e", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIdentitiesMigration.ReadWrite.All" + }, + { + "description": "Allows the app to read all the identity security sensors of signed user", + "displayName": "Read identity security sensors", + "id": "2c221239-7c5c-4b30-9355-d84663bfcd96", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIdentitiesSensors.Read.All" + }, + { + "description": "Allows the app to read and write identity security sensors on behalf of the signed-in user.", + "displayName": "Read and write identity security sensors", + "id": "087c3ad9-c2ca-4b82-9885-d5e25ce9e183", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIdentitiesSensors.ReadWrite.All" + }, + { + "description": "Allows the app to read all the identity security available user actions of signed user", + "displayName": "Read identity security available user actions", + "id": "c7d0a939-da1c-4aca-80fa-d0a6cd924801", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIdentitiesUserActions.Read.All" + }, + { + "description": "Allows the app to read and write identity security available user actions on behalf of the signed-in user.", + "displayName": "Read and perform identity security available user actions", + "id": "bf230e97-1957-4df6-b3f6-57f9029eacdf", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIdentitiesUserActions.ReadWrite.All" + }, + { + "description": "Allows the app to read security incidents, on behalf of the signed-in user.", + "displayName": "Read incidents", + "id": "b9abcc4f-94fc-4457-9141-d20ce80ec952", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIncident.Read.All" + }, + { + "description": "Allows the app to read and write security incidents, on behalf of the signed-in user.", + "displayName": "Read and write to incidents", + "id": "128ca929-1a19-45e6-a3b8-435ec44a36ba", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIncident.ReadWrite.All" + }, + { + "description": "Allow the app to determine if there is any sensitivity label to be applied automatically to the content or recommended to the user for manual application, on behalf of the signed-in user.", + "displayName": "Evaluate sensitivity labels", + "id": "a4633e44-d355-4474-99df-8c2de6b0e39e", + "origin": "Delegated (Microsoft Graph)", + "value": "SensitivityLabel.Evaluate" + }, + { + "description": "Allows the app to evaluate all sensitivity label.", + "displayName": "Evaluate labels tenant scope.", + "id": "a42e3c42-b31e-4919-b699-696dca5dc9e7", + "origin": "Delegated (Microsoft Graph)", + "value": "SensitivityLabel.Evaluate.All" + }, + { + "description": "Allows the app to get sensitivity labels.", + "displayName": "Get labels user scope.", + "id": "1aeb73ce-68d7-49b7-913a-eedc80844551", + "origin": "Delegated (Microsoft Graph)", + "value": "SensitivityLabel.Read" + }, + { + "description": "Allows the app to get sensitivity labels.", + "displayName": "Get labels app scope.", + "id": "8b377c27-ea19-4863-a948-8a8588c8f2c3", + "origin": "Delegated (Microsoft Graph)", + "value": "SensitivityLabels.Read.All" + }, + { + "description": "Allows the app to export all Sentiment Survey, on behalf of the signed-in user.", + "displayName": "Export all Sentiment Survey", + "id": "df9fd94d-51ff-443d-8f31-ae4dc1b5b8d8", + "origin": "Delegated (Microsoft Graph)", + "value": "SentimentSurvey.Export.All" + }, + { + "description": "Allows the app to read and write identity security available actions on behalf of the signed-in identity.", + "displayName": "Read and perform identity security available actions", + "id": "818229ce-20e4-47bd-92f4-bc94dbb37a56", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIdentitiesActions.ReadWrite.All" + }, + { + "description": "Allows the app to read all the identity security available identity accounts", + "displayName": "Read identity security available identity accounts", + "id": "3e9ed69a-a48e-473c-8b97-413016703a37", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIdentitiesAccount.Read.All" + }, + { + "description": "Allows the app to read your organization’s security events on behalf of the signed-in user. Also allows the app to update editable properties in security events on behalf of the signed-in user.", + "displayName": "Read and update your organization’s security events", + "id": "6aedf524-7e1c-45a7-bd76-ded8cab8d0fc", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityEvents.ReadWrite.All" + }, + { + "description": "Allows the app to read your organization’s security events on behalf of the signed-in user.", + "displayName": "Read your organization’s security events", + "id": "64733abd-851e-478a-bffb-e47a14b18235", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityEvents.Read.All" + }, + { + "description": "Allows the app to read policies in Privileged Identity Management for App Roles, on behalf of the signed-in user.", + "displayName": "Read all policies in PIM for App Roles", + "id": "8b3ffd3b-178e-4aae-be39-ba87585eddb2", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagementPolicy.Read.EntraAppRole" + }, + { + "description": "Allows the app to read, update, and delete policies in Privileged Identity Management for Groups, on behalf of the signed-in user.", + "displayName": "Read, update, and delete all policies in PIM for Groups", + "id": "0da165c7-3f15-4236-b733-c0b0f6abe41d", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagementPolicy.ReadWrite.AzureADGroup" + }, + { + "description": "Allows the app to read, update, and delete policies for privileged role-based access control (RBAC) assignments of your company's directory, on behalf of the signed-in user.", + "displayName": "Read, update, and delete all policies for privileged role assignments of your company's directory", + "id": "1ff1be21-34eb-448c-9ac9-ce1f506b2a68", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagementPolicy.ReadWrite.Directory" + }, + { + "description": "Allows the app to manage policies in Privileged Identity Management for App Roles, on behalf of the signed-in user.", + "displayName": "Manage all policies in PIM for App Roles", + "id": "652ec839-e4ac-4eb5-b545-ecc90eeceb2d", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagementPolicy.ReadWrite.EntraAppRole" + }, + { + "description": "Allows the app to read schedule, schedule groups, shifts and associated entities in the Teams or Shifts application on behalf of the signed-in user.", + "displayName": "Read user schedule items", + "id": "fccf6dd8-5706-49fa-811f-69e2e1b585d0", + "origin": "Delegated (Microsoft Graph)", + "value": "Schedule.Read.All" + }, + { + "description": "Allows the app to manage schedule, schedule groups, shifts and associated entities in the Teams or Shifts application on behalf of the signed-in user.", + "displayName": "Read and write user schedule items", + "id": "63f27281-c9d9-4f29-94dd-6942f7f1feb0", + "origin": "Delegated (Microsoft Graph)", + "value": "Schedule.ReadWrite.All" + }, + { + "description": "Allows the app to read/write schedule permissions for a specific role in Shifts application on behalf of the signed-in user.", + "displayName": "Read/Write schedule permissions for a role.", + "id": "07919803-6073-4cd8-bc55-28077db0ee10", + "origin": "Delegated (Microsoft Graph)", + "value": "SchedulePermissions.ReadWrite.All" + }, + { + "description": "Allows the app to read search configuration, on behalf of the signed-in user.", + "displayName": "Read your organization's search configuration", + "id": "7d307522-aa38-4cd0-bd60-90c6f0ac50bd", + "origin": "Delegated (Microsoft Graph)", + "value": "SearchConfiguration.Read.All" + }, + { + "description": "Allows the app to read your tenant's user configurations on behalf of the signed-in admin user. User configuration may include attributes related to user, such as telephone number, assigned policies, etc.", + "displayName": "Read Teams user configurations", + "id": "5c469ce4-dab5-4afd-b9de-14f1ba4004a7", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsUserConfiguration.Read.All" + }, + { + "description": "Allows the app to read and write search configuration, on behalf of the signed-in user.", + "displayName": "Read and write your organization's search configuration", + "id": "b1a7d408-cab0-47d2-a2a5-a74a3733600d", + "origin": "Delegated (Microsoft Graph)", + "value": "SearchConfiguration.ReadWrite.All" + }, + { + "description": "Allows the app to read or update security actions, on behalf of the signed-in user.", + "displayName": "Read and update your organization's security actions", + "id": "dc38509c-b87d-4da0-bd92-6bec988bac4a", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityActions.ReadWrite.All" + }, + { + "description": "Allows the app to create security alerts, on behalf of the signed-in user.", + "displayName": "Create security alerts", + "id": "7417b8c6-a088-4c4c-99c7-bca9ab3eb9ba", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityAlert.Create.All" + }, + { + "description": "Allows the app to read all security alerts, on behalf of the signed-in user.", + "displayName": "Read all security alerts", + "id": "bc257fb8-46b4-4b15-8713-01e91bfbe4ea", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityAlert.Read.All" + }, + { + "description": "Allows the app to read and write to all security alerts, on behalf of the signed-in user.", + "displayName": "Read and write to all security alerts", + "id": "471f2a7f-2a42-4d45-a2bf-594d0838070d", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityAlert.ReadWrite.All" + }, + { + "description": "Read email metadata and security detection details on behalf of the signed in user.", + "displayName": "Read metadata and detection details for emails in your organization", + "id": "53e6783e-b127-4a35-ab3a-6a52d80a9077", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityAnalyzedMessage.Read.All" + }, + { + "description": "Read email metadata, security detection details, and execute remediation actions like deleting an email, on behalf of the signed in user.", + "displayName": "Read metadata, detection details, and execute remediation actions on emails in your organization", + "id": "48eb8c83-6e58-46e7-a6d3-8805822f5940", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityAnalyzedMessage.ReadWrite.All" + }, + { + "description": "Allows the app to read all Security Copilot signed-in user's resources on behalf of the signed-in user", + "displayName": "Read all Security Copilot resources for the signed-in user", + "id": "84499c31-ac2e-44d3-a0cf-a6c386d4dfe8", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityCopilotWorkspaces.Read.All" + }, + { + "description": "Allows the app to read and write Security Copilot resources owned by the signed-in user on their behalf.", + "displayName": "Read and write individually owned Security Copilot resources of the signed-in user", + "id": "206291b0-2167-47a7-a640-6cdc1df710ba", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityCopilotWorkspaces.ReadWrite.All" + }, + { + "description": "Allows the app to read security actions, on behalf of the signed-in user.", + "displayName": "Read your organization's security actions", + "id": "1638cddf-07a4-4de2-8645-69c96cacad73", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityActions.Read.All" + }, + { + "description": "Allows the app to read the available Teams templates, on behalf of the signed-in user.", + "displayName": "Read available Teams templates", + "id": "cd87405c-5792-4f15-92f7-debc0db6d1d6", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamTemplates.Read" + }, + { + "description": "Allows the app to read the teamwork settings of the organization, on behalf of the signed-in user.", + "displayName": "Read organizational teamwork settings", + "id": "594f4bb6-c083-4cf9-8aa8-213823bdf351", + "origin": "Delegated (Microsoft Graph)", + "value": "Teamwork.Read.All" + }, + { + "description": "Allows the app to read the Teams app settings on behalf of the signed-in user.", + "displayName": "Read Teams app settings", + "id": "44e060c4-bbdc-4256-a0b9-dcc0396db368", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkAppSettings.Read.All" + }, + { + "description": "Allows the app to read and write Windows Hello authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' Windows Hello methods.", + "id": "13eae17d-aaa4-47b8-aaee-0eb33c6e2450", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-WindowsHello.ReadWrite.All" + }, + { + "description": "Allows the app to read cloud clipboard data on behalf of the signed-in user.", + "displayName": "Read cloud clipboard items", + "id": "61e8a09a-087f-4e36-8c8c-1c77c5228017", + "origin": "Delegated (Microsoft Graph)", + "value": "UserCloudClipboard.Read" + }, + { + "description": "Allow the app to convert an external user to an internal member user, on behalf of signed-in user.", + "displayName": "Convert an external user to internal memeber user", + "id": "550e695c-7511-40f4-ac79-e8fb9c82552d", + "origin": "Delegated (Microsoft Graph)", + "value": "User-ConvertToInternal.ReadWrite.All" + }, + { + "description": "Allows the app to read the lifecycle information like employeeLeaveDateTime of users in your organization, on behalf of the signed-in user.", + "displayName": "Read all users' lifecycle information", + "id": "ed8d2a04-0374-41f1-aefe-da8ac87ccc87", + "origin": "Delegated (Microsoft Graph)", + "value": "User-LifeCycleInfo.Read.All" + }, + { + "description": "Allows the app to read and write the lifecycle information like employeeLeaveDateTime of users in your organization, on behalf of the signed-in user.", + "displayName": "Read and write all users' lifecycle information", + "id": "7ee7473e-bd4b-4c9f-987c-bd58481f5fa2", + "origin": "Delegated (Microsoft Graph)", + "value": "User-LifeCycleInfo.ReadWrite.All" + }, + { + "description": "Allows the app to read and write secondary mail addresses for all users, on behalf of the signed-in user.", + "displayName": "Read and write secondary mail addresses for users", + "id": "6166886a-9576-433b-8544-658177bdef1d", + "origin": "Delegated (Microsoft Graph)", + "value": "User-Mail.ReadWrite.All" + }, + { + "description": "Allows the app to send, read, update and delete user’s notifications.", + "displayName": "Deliver and manage user's notifications", + "id": "26e2f3e8-b2a1-47fc-9620-89bb5b042024", + "origin": "Delegated (Microsoft Graph)", + "value": "UserNotification.ReadWrite.CreatedByApp" + }, + { + "description": "Allows the app to read and update the on-premises sync behavior of users on behalf of the signed-in user.", + "displayName": "Read and update the on-premises sync behavior of users", + "id": "7ff9afdd-0cdb-439d-a61c-fea3e9339e89", + "origin": "Delegated (Microsoft Graph)", + "value": "User-OnPremisesSyncBehavior.ReadWrite.All" + }, + { + "description": "Allows the app to read and write password profiles and reset passwords for all users, on behalf of the signed-in user.", + "displayName": "Read and write password profiles and reset user passwords", + "id": "56760768-b641-451f-8906-e1b8ab31bca7", + "origin": "Delegated (Microsoft Graph)", + "value": "User-PasswordProfile.ReadWrite.All" + }, + { + "description": "Allows the app to read and write the mobile phone and business phones for all users, on behalf of the signed-in user.", + "displayName": "Read and write user mobile phone and business phones", + "id": "e29d5979-5b06-4a7f-ae24-6a9348d2e1ff", + "origin": "Delegated (Microsoft Graph)", + "value": "User-Phone.ReadWrite.All" + }, + { + "description": "Allows the app to read the teamwork settings of the signed-in user.", + "displayName": "Read user teamwork settings", + "id": "834bcc1c-762f-41b0-bb91-1cdc323ee4bf", + "origin": "Delegated (Microsoft Graph)", + "value": "UserTeamwork.Read" + }, + { + "description": "Allows the app to report the signed-in user's app activity information to Microsoft Timeline.", + "displayName": "Write app activity to users' timeline", + "id": "367492fc-594d-4972-a9b5-0d58c622c91c", + "origin": "Delegated (Microsoft Graph)", + "value": "UserTimelineActivity.Write.CreatedByApp" + }, + { + "description": "Allows the app to read a user's windows settings which are stored in cloud and their values on behalf of the signed-in user.", + "displayName": "Read windows settings for all devices", + "id": "77e07bab-1b34-40a5-bb6c-4b197b3f6027", + "origin": "Delegated (Microsoft Graph)", + "value": "UserWindowsSettings.Read.All" + }, + { + "description": "Allows the app to read and write a user's windows settings which are stored in cloud and their values on behalf of the signed-in user.", + "displayName": "Read and write windows settings for all devices", + "id": "dcb1026d-b7e1-4d31-9f61-6724d5140bf9", + "origin": "Delegated (Microsoft Graph)", + "value": "UserWindowsSettings.ReadWrite.All" + }, + { + "description": "This role can read Verified Id profiles in a tenant.", + "displayName": "Read Verified Id profiles", + "id": "604b2056-41ed-4c56-aad5-1241d4ef7333", + "origin": "Delegated (Microsoft Graph)", + "value": "VerifiedId-Profile.Read.All" + }, + { + "description": "This role can read and write Verified Id profiles in a tenant.", + "displayName": "Read and write Verified Id profiles", + "id": "e4a9cb5e-4767-48f8-9029-decf26a54456", + "origin": "Delegated (Microsoft Graph)", + "value": "VerifiedId-Profile.ReadWrite.All" + }, + { + "description": "Allows an application to read virtual appointments for the signed-in user. Only an organizer or participant user can read their virtual appointments. ", + "displayName": "Read a user's virtual appointments", + "id": "27470298-d3b8-4b9c-aad4-6334312a3eac", + "origin": "Delegated (Microsoft Graph)", + "value": "VirtualAppointment.Read" + }, + { + "description": "Allows the app to read and write the signed-in user's Windows Hello authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's Windows Hello authentication methods", + "id": "f11e1db9-d419-4a24-b677-792723ffd727", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-WindowsHello.ReadWrite" + }, + { + "description": "Allows an application to read and write virtual appointments for the signed-in user. Only an organizer or participant user can read and write their virtual appointments. ", + "displayName": "Read and write a user's virtual appointments ", + "id": "2ccc2926-a528-4b17-b8bb-860eed29d64c", + "origin": "Delegated (Microsoft Graph)", + "value": "VirtualAppointment.ReadWrite" + }, + { + "description": "Allows the app to read Windows Hello authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' Windows Hello methods", + "id": "ff37d46d-b88a-4e0c-85ee-7e26c37b18eb", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-WindowsHello.Read.All" + }, + { + "description": "Allows the app to read and write Temporary Access Pass authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' Temporary Access Pass methods.", + "id": "05de4a66-e51a-4312-842a-30c8094698d2", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-TAP.ReadWrite.All" + }, + { + "description": "Allows the app to read the signed-in user's platform credential authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's platform credential authentication methods", + "id": "9c694582-e8f2-40e2-8353-fb43e2e0f12a", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-PlatformCred.Read" + }, + { + "description": "Allows the app to read platform credentials methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' platform credentials methods", + "id": "5936156c-f89b-4850-997d-026c4e6ce529", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-PlatformCred.Read.All" + }, + { + "description": "Allows the app to read and write the signed-in user's platform credential authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's platform credential authentication methods", + "id": "70327f81-b953-43c9-92d3-131c74e4beb8", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-PlatformCred.ReadWrite" + }, + { + "description": "Allows the app to read and write platform credentials methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' platform credentials methods.", + "id": "cb11bf8c-dde1-4504-b6a5-31e1562b0749", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-PlatformCred.ReadWrite.All" + }, + { + "description": "Allows the app to read the signed-in user's QR authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's QR authentication methods", + "id": "d6893c31-9187-405c-8dfc-f700c8fc161a", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-QR.Read" + }, + { + "description": "Allows the app to read QR authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' QR methods", + "id": "e4900dfb-ad17-410d-8ddb-7aebd8a6af1a", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-QR.Read.All" + }, + { + "description": "Allows the app to read and write the signed-in user's QR authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's QR authentication methods", + "id": "651210da-18ce-4e42-b7db-302ff88e9326", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-QR.ReadWrite" + }, + { + "description": "Allows the app to read and write QR authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' QR methods.", + "id": "db39086a-da7d-4cbd-9ac0-6816f9a80c95", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-QR.ReadWrite.All" + }, + { + "description": "Allows the app to read the keys associated with the user representing a resource account.", + "displayName": "Read the keys associated with the user representing a resource account.", + "id": "c86e40fc-66fd-4d68-802e-b90e3038f5e8", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-ResourceKey.Read.All" + }, + { + "description": "Allows the app to read and delete the keys associated with the user representing a resource account.", + "displayName": "Read and delete the keys associated with the user representing a resource account.", + "id": "e71dec0d-02b4-429d-a49a-030950d45faa", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-ResourceKey.ReadWrite.All" + }, + { + "description": "Allows the app to read the signed-in user's SoftwareOATH authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's SoftwareOATH authentication methods", + "id": "247f2733-6e3d-46ff-a904-f5fd58eb0d97", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-SoftwareOATH.Read" + }, + { + "description": "Allows the app to read SoftwareOATH authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' SoftwareOATH methods", + "id": "3e366fa0-3097-4eb6-8294-3028f77eea6f", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-SoftwareOATH.Read.All" + }, + { + "description": "Allows the app to read and write the signed-in user's SoftwareOATH authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's SoftwareOATH authentication methods", + "id": "16721eb3-4493-4ae1-9542-264d9ffe3ce9", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-SoftwareOATH.ReadWrite" + }, + { + "description": "Allows the app to read and write SoftwareOATH authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' SoftwareOATH methods.", + "id": "5b34c8b5-2396-4b35-b284-83fb6a3e73ce", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-SoftwareOATH.ReadWrite.All" + }, + { + "description": "Allows the app to read the signed-in user's Temporary Access Pass authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's Temporary Access Pass authentication methods", + "id": "84ded88f-26ba-49d6-b776-efec398de692", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-TAP.Read" + }, + { + "description": "Allows the app to read Temporary Access Pass authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' Temporary Access Pass methods", + "id": "6976c635-c9c2-41e6-a21d-e6913a155273", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-TAP.Read.All" + }, + { + "description": "Allows the app to read and write the signed-in user's Temporary Access Pass authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's Temporary Access Pass authentication methods", + "id": "2424436d-902f-4651-a1c7-b3b93147c960", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-TAP.ReadWrite" + }, + { + "description": "Allows the app to read the signed-in user's Windows Hello authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's Windows Hello methods", + "id": "efe2b5aa-3a8e-486c-b0be-cc4d185c1b40", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-WindowsHello.Read" + }, + { + "description": "Allows an application to send notifications for virtual appointments for the signed-in user.", + "displayName": "Send notification regarding virtual appointments for the signed-in user", + "id": "20d02fff-a0ef-49e7-a46e-019d4a6523b7", + "origin": "Delegated (Microsoft Graph)", + "value": "VirtualAppointmentNotification.Send" + }, + { + "description": "Allows the app to read virtual events created by you", + "displayName": "Read your virtual events", + "id": "6b616635-ae58-433a-a918-8c45e4f304dc", + "origin": "Delegated (Microsoft Graph)", + "value": "VirtualEvent.Read" + }, + { + "description": "Allows the app to read and write virtual events for you", + "displayName": "Read and write your virtual events", + "id": "d38d189c-e29b-4344-8b3b-829bfa81380b", + "origin": "Delegated (Microsoft Graph)", + "value": "VirtualEvent.ReadWrite" + }, + { + "description": "Allow the telecom expense management app to send and receive device telecom and Wi-Fi data usage information, including phone number, with Intune to help analyze and manage data usage costs of corporate-owned devices.", + "displayName": "Send and receive device telecom and Wi-Fi data usage information with Microsoft Intune", + "id": "7828b294-fdcc-4ed6-a45a-854364afb21d", + "origin": "Application (Microsoft Intune API)", + "value": "send_data_usage" + }, + { + "description": "Send device attributes to Microsoft Intune.  \r\n", + "displayName": "Send device attributes to Microsoft Intune", + "id": "7b3c62c0-bbe4-4ceb-971b-ecc50a191b3e", + "origin": "Application (Microsoft Intune API)", + "value": "update_device_attributes" + }, + { + "description": "Allow this app to send device risk and threat information to Intune to help determine device compliance with corporate security policy.", + "displayName": "Send device threat information to Microsoft Intune", + "id": "a5438881-186a-48f0-bc41-a93ae8a195fe", + "origin": "Application (Microsoft Intune API)", + "value": "update_device_health" + }, + { + "description": "Grants access to the Intune data warehouse API", + "displayName": "Get data warehouse information from Microsoft Intune", + "id": "d603c21a-d512-4b5a-b552-c233ebbeaf2e", + "origin": "Delegated (Microsoft Intune API)", + "value": "get_data_warehouse" + }, + { + "description": "Allow users to report info on their Apple Device.", + "displayName": "AppleDeviceInfo.ReadWrite", + "id": "830bc8bc-f872-4624-8386-0013e444366d", + "origin": "Delegated (Microsoft Intune Enrollment)", + "value": "AppleDeviceInfo.ReadWrite" + }, + { + "description": "Allows users to search for their custom branding information.", + "displayName": "branding.search", + "id": "17c38fce-d62f-4e61-85d1-d60852e316a2", + "origin": "Delegated (Microsoft Intune IW Service)", + "value": "branding.search" + }, + { + "description": "Allows user to read their targeted AAD Enterprise apps", + "displayName": "Read AAD Enterprise Apps", + "id": "e3fb1dc8-dea4-41fc-bfbe-1148f98e8821", + "origin": "Delegated (Microsoft Intune IW Service)", + "value": "IntuneAADEnterpriseApps.Read" + }, + { + "description": "Allows the app to read read user's OS Recovery Profiles.", + "displayName": "Read user's OS Recovery Profiles", + "id": "65f5fc61-37d4-4b5c-b092-d51e627c11a4", + "origin": "Delegated (Microsoft Intune IW Service)", + "value": "UserOSRecoveryProfiles.Read" + }, + { + "description": "Microsoft Invoicing for Office 365", + "displayName": "Access according to the application's permissions in Microsoft Invoicing", + "id": "d3010f21-1088-4717-b6b6-60f186f268f6", + "origin": "Application (Microsoft Invoicing)", + "value": "app_access" + }, + { + "description": "Microsoft Invoicing for Office 365", + "displayName": "Access as the signed-in user", + "id": "d079d0df-9773-4880-8129-d0f087474a78", + "origin": "Delegated (Microsoft Invoicing)", + "value": "user_impersonation" + }, + { + "description": "create app", + "displayName": "Application Readwrite", + "id": "51f99752-487f-4501-af40-90beb78bdaa2", + "origin": "Delegated (Microsoft IoT Central)", + "value": "Application.ReadWrite.All" + }, + { + "description": "Allows the application full access to the REST APIs provided by IoT Central on behalf of the signed-in user", + "displayName": "Access IoT Central REST APIs as Signed In User", + "id": "73792908-5709-46da-9a68-098589599db6", + "origin": "Delegated (Microsoft IoT Central)", + "value": "user_impersonation" + }, + { + "description": "Sign in to Remote Rendering service", + "displayName": "arrtest.signin", + "id": "49b8cb69-fa3b-4f0c-a198-62506e47dba1", + "origin": "Application (Microsoft Mixed Reality)", + "value": "arrtest.signin" + }, + { + "description": "Sign In to Mixed Reality Services", + "displayName": "Signin", + "id": "b24fe742-e2a6-4995-adbf-aba1516932c5", + "origin": "Application (Microsoft Mixed Reality)", + "value": "mixedreality.signin" + }, + { + "description": "Sign in to synthetics service", + "displayName": "syntest.signin", + "id": "9f56f4b8-4de2-4e83-a632-45d1e4b47400", + "origin": "Delegated (Microsoft Mixed Reality)", + "value": "syntest.signin" + }, + { + "description": "Send SCEP challenges to Intune for certificate request validation. ", + "displayName": "SCEP challenge validation", + "id": "39d724e8-6a34-4930-9a36-364082c35716", + "origin": "Application (Microsoft Intune API)", + "value": "scep_challenge_provider" + }, + { + "description": "Read PFX certificate requests and send certificates to Microsoft Intune.", + "displayName": "PFX certificate management", + "id": "907d16c7-7591-49a4-b523-6fd42e5f2c7e", + "origin": "Application (Microsoft Intune API)", + "value": "pfx_cert_provider" + }, + { + "description": "Allows the app to send partner compliance policies and its Azure AD Group assignment to Microsoft Intune without a signed-in user.", + "displayName": "Manage partner compliance policies with Microsoft Intune.", + "id": "3857e233-c379-404e-85e9-bdbf3a62b28f", + "origin": "Application (Microsoft Intune API)", + "value": "manage_partner_compliance_policy" + }, + { + "description": "Allow this app to receive information about devices (such as compliance and enrollment state) that are managed by Intune.", + "displayName": "Get device state and compliance information from Microsoft Intune", + "id": "7ec88bad-30c7-4928-a005-4455362cfd98", + "origin": "Application (Microsoft Intune API)", + "value": "get_device_compliance" + }, + { + "description": "Allows the app to read all Windows update deployment settings for the organization on behalf of the signed-in user.", + "displayName": "Read all Windows update deployment settings", + "id": "e09fef2d-bf5e-4439-affa-7c48d23bb1c2", + "origin": "Delegated (Microsoft Graph)", + "value": "WindowsUpdates.Read.All" + }, + { + "description": "Allows the app to read and write all Windows update deployment settings for the organization on behalf of the signed-in user.", + "displayName": "Read and write all Windows update deployment settings", + "id": "11776c0c-6138-4db3-a668-ee621bea2555", + "origin": "Delegated (Microsoft Graph)", + "value": "WindowsUpdates.ReadWrite.All" + }, + { + "description": "Allows the app to read workforce integrations, to synchronize data from Microsoft Teams Shifts, on behalf of the signed-in user.", + "displayName": "Read workforce integrations", + "id": "f1ccd5a7-6383-466a-8db8-1a656f7d06fa", + "origin": "Delegated (Microsoft Graph)", + "value": "WorkforceIntegration.Read.All" + }, + { + "description": "Allows the app to manage workforce integrations, to synchronize data from Microsoft Teams Shifts, on behalf of the signed-in user.", + "displayName": "Read and write workforce integrations", + "id": "08c4b377-0d23-4a8b-be2a-23c1c1d88545", + "origin": "Delegated (Microsoft Graph)", + "value": "WorkforceIntegration.ReadWrite.All" + }, + { + "description": "Allows the current signed-in user to read Content Domain information.", + "displayName": "ContentDomain.Read.All", + "id": "bbee328f-fe32-4251-a58c-9b16f9bf50c8", + "origin": "Application (Microsoft Graph Connectors Core)", + "value": "ContentDomain.Read.All" + }, + { + "description": "Allows the current signed in user to update the Content Domain information", + "displayName": "ContentDomain.ReadWrite", + "id": "6662245d-d5f3-42cb-b401-b08c2f424d5f", + "origin": "Application (Microsoft Graph Connectors Core)", + "value": "ContentDomain.ReadWrite" + }, + { + "description": "Read and Write permission of Content Domain Items into all content domain shards. ", + "displayName": "ContentDomainItem.ReadWrite.All", + "id": "175d9ac0-118e-4725-b5a1-be1e16948cf6", + "origin": "Application (Microsoft Graph Connectors Core)", + "value": "ContentDomainItem.ReadWrite.All" + }, + { + "description": "Read and Write permission of Content Domain Items into the content domain shard owned by the application. ", + "displayName": "ContentDomainItem.ReadWrite.OwnedBy", + "id": "83447e6a-d68b-4373-bd75-efab237f20ba", + "origin": "Application (Microsoft Graph Connectors Core)", + "value": "ContentDomainItem.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read and write Phone methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' phone methods.", + "id": "48c99302-9a24-4f27-a8a7-acef4debba14", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Phone.ReadWrite.All" + }, + { + "description": "Read all published labels and label policies for an organization.", + "displayName": "InformationProtectionPolicy.Read.All", + "id": "dfa45ec9-c9fd-4944-93c8-d07af06cfa40", + "origin": "Application (Microsoft Information Protection API)", + "value": "InformationProtectionPolicy.Read.All" + }, + { + "description": "Read user labels and label policies.", + "displayName": "InformationProtectionPolicy.Read", + "id": "e79e5e22-ae68-4744-b17f-95a009916d6e", + "origin": "Delegated (Microsoft Information Protection API)", + "value": "InformationProtectionPolicy.Read" + }, + { + "description": "Read all published labels and label policies for an organization on your behalf.", + "displayName": "InformationProtectionPolicy.Read.All", + "id": "bf59e00b-be0a-4c3d-bf14-ce55d7146a41", + "origin": "Delegated (Microsoft Information Protection API)", + "value": "InformationProtectionPolicy.Read.All" + }, + { + "description": "c", + "displayName": "Read all unified policies of the tenant.", + "id": "8b2071cd-015a-4025-8052-1c0dba2d3f64", + "origin": "Application (Microsoft Information Protection Sync Service)", + "value": "UnifiedPolicy.Tenant.Read" + }, + { + "description": "Read all unified policies a user has access to.", + "displayName": "Read all unified policies a user has access to.", + "id": "34f7024b-1bed-402f-9664-f5316a1e1b4a", + "origin": "Delegated (Microsoft Information Protection Sync Service)", + "value": "UnifiedPolicy.User.Read" + }, + { + "description": "Allows Intune Admins to enroll a Microsoft Tunnel Gateway Agent", + "displayName": "MicrosoftTunnelGatewayEnrollment", + "id": "e323f13a-1fcc-49cc-883f-c6da13ae0542", + "origin": "Delegated (Microsoft Intune)", + "value": "MicrosoftTunnelGatewayEnrollment" + }, + { + "description": "Allows user to view their BitLocker recovery keys", + "displayName": "Read BitLocker recovery keys", + "id": "ecff1a9d-e6bb-4e01-9136-c8825bbfceb3", + "origin": "Delegated (Microsoft Intune AAD BitLocker Recovery Key Integration)", + "value": "IntuneAADBitLockerRecoveryKey.Read" + }, + { + "description": "Grants access to the Intune data warehouse API", + "displayName": "Get data warehouse information from Microsoft Intune", + "id": "3d9dc976-32fb-45a8-90bd-c9f8a850d098", + "origin": "Application (Microsoft Intune API)", + "value": "get_data_warehouse" + }, + { + "description": "Allows the app to read and write all profile photos of users and groups, on behalf of the signed-in user.", + "displayName": "Read and write profile photo of a user or group", + "id": "f5b24df7-511e-48bb-ae88-643f023b55e1", + "origin": "Delegated (Microsoft Graph)", + "value": "ProfilePhoto.ReadWrite.All" + }, + { + "description": "Allows the app to read and write the signed-in user's phone authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's phone authentication methods", + "id": "6c4aad61-f76b-46ad-a22c-57d4d3d962af", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Phone.ReadWrite" + }, + { + "description": "Allows the app to read the signed-in user's phone authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's phone authentication methods", + "id": "43dab3b9-e8b4-424d-8e13-6a2ad2a625fa", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Phone.Read" + }, + { + "description": "Allows the application to read Tenant Governance settings on behalf of the signed-in user.", + "displayName": "Read Tenant Governance settings", + "id": "4ad3e05f-2467-49d9-baa2-8e4de7bcee9b", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-Setting.Read.All" + }, + { + "description": "Allows the application to read Tenant Governance settings and update them on behalf of the signed-in user.", + "displayName": "Read and write Tenant Governance settings", + "id": "135f3533-12fc-4608-97ac-5c5cea64baf0", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-Setting.ReadWrite.All" + }, + { + "description": "Allows the app to read the term store data that the signed-in user has access to. This includes all sets, groups and terms in the term store.", + "displayName": "Read term store data", + "id": "297f747b-0005-475b-8fef-c890f5152b38", + "origin": "Delegated (Microsoft Graph)", + "value": "TermStore.Read.All" + }, + { + "description": "Allows the app to read or modify data that the signed-in user has access to. This includes all sets, groups and terms in the term store.", + "displayName": "Read and write term store data", + "id": "6c37c71d-f50f-4bff-8fd3-8a41da390140", + "origin": "Delegated (Microsoft Graph)", + "value": "TermStore.ReadWrite.All" + }, + { + "description": "Allows an app to read your organization's threat assessment requests on behalf of the signed-in user. Also allows the app to create new requests to assess threats received by your organization on behalf of the signed-in user.", + "displayName": "Read and write threat assessment requests", + "id": "cac97e40-6730-457d-ad8d-4852fddab7ad", + "origin": "Delegated (Microsoft Graph)", + "value": "ThreatAssessment.ReadWrite.All" + }, + { + "description": "Allows the app to run hunting queries, on behalf of the signed-in user.", + "displayName": "Run hunting queries", + "id": "b152eca8-ea73-4a48-8c98-1a6742673d99", + "origin": "Delegated (Microsoft Graph)", + "value": "ThreatHunting.Read.All" + }, + { + "description": "Allows the app to read all the indicators for your organization, on behalf of the signed-in user.", + "displayName": "Read all threat indicators", + "id": "9cc427b4-2004-41c5-aa22-757b755e9796", + "origin": "Delegated (Microsoft Graph)", + "value": "ThreatIndicators.Read.All" + }, + { + "description": "Allows the app to create threat indicators, and fully manage those threat indicators (read, update and delete), on behalf of the signed-in user. It cannot update any threat indicators it does not own.", + "displayName": "Manage threat indicators this app creates or owns", + "id": "91e7d36d-022a-490f-a748-f8e011357b42", + "origin": "Delegated (Microsoft Graph)", + "value": "ThreatIndicators.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read threat intelligence information, such as indicators, observations, and articles, on behalf of the signed-in user.", + "displayName": "Read all threat intelligence information", + "id": "f266d9c0-ccb9-4fb8-a228-01ac0d8d6627", + "origin": "Delegated (Microsoft Graph)", + "value": "ThreatIntelligence.Read.All" + }, + { + "description": "Allows the app to read the threat submissions and threat submission policies owned by the signed-in user.", + "displayName": "Read threat submissions", + "id": "fd5353c6-26dd-449f-a565-c4e16b9fce78", + "origin": "Delegated (Microsoft Graph)", + "value": "ThreatSubmission.Read" + }, + { + "description": "Allows the app to read your organization's threat submissions and threat submission policies on behalf of the signed-in user.", + "displayName": "Read all threat submissions", + "id": "7083913a-4966-44b6-9886-c5822a5fd910", + "origin": "Delegated (Microsoft Graph)", + "value": "ThreatSubmission.Read.All" + }, + { + "description": "Allows the app to read the threat submissions and threat submission policies owned by the signed-in user. Also allows the app to create new threat submissions on behalf of the signed-in user.", + "displayName": "Read and write threat submissions", + "id": "68a3156e-46c9-443c-b85c-921397f082b5", + "origin": "Delegated (Microsoft Graph)", + "value": "ThreatSubmission.ReadWrite" + }, + { + "description": "Allows the app to read your organization's threat submissions and threat submission policies on behalf of the signed-in user. Also allows the app to create new threat submissions on behalf of the signed-in user.", + "displayName": "Read and write all threat submissions", + "id": "8458e264-4eb9-4922-abe9-768d58f13c7f", + "origin": "Delegated (Microsoft Graph)", + "value": "ThreatSubmission.ReadWrite.All" + }, + { + "description": "Allows the app to read your organization's threat submission policies on behalf of the signed-in user. Also allows the app to create new threat submission policies on behalf of the signed-in user.", + "displayName": "Read and write all threat submission policies", + "id": "059e5840-5353-4c68-b1da-666a033fc5e8", + "origin": "Delegated (Microsoft Graph)", + "value": "ThreatSubmissionPolicy.ReadWrite.All" + }, + { + "description": "Allows the app to read topics data on behalf of the signed-in user.", + "displayName": "Read topic items", + "id": "79c4c76f-409a-4f98-884d-e2c09291ec26", + "origin": "Delegated (Microsoft Graph)", + "value": "Topic.Read.All" + }, + { + "description": "Allows the app to read trust framework key set properties on behalf of the signed-in user.", + "displayName": "Read trust framework key sets", + "id": "7ad34336-f5b1-44ce-8682-31d7dfcd9ab9", + "origin": "Delegated (Microsoft Graph)", + "value": "TrustFrameworkKeySet.Read.All" + }, + { + "description": "Allows the app to read and write trust framework key set properties on behalf of the signed-in user.", + "displayName": "Read and write trust framework key sets", + "id": "39244520-1e7d-4b4a-aee0-57c65826e427", + "origin": "Delegated (Microsoft Graph)", + "value": "TrustFrameworkKeySet.ReadWrite.All" + }, + { + "description": "Allows the application to list, read, create, and update Tenant Governance requests on behalf of the signed-in user.", + "displayName": "Read and write Tenant Governance requests", + "id": "3c7a434e-4e5d-413f-be82-b77ea4ba5a4d", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-Request.ReadWrite.All" + }, + { + "description": "Allows the app to read basic unified group properties, memberships and owners of the group the signed-in guest is a member of.", + "displayName": "Read unified group memberships as guest", + "id": "73e75199-7c3e-41bb-9357-167164dbb415", + "origin": "Delegated (Microsoft Graph)", + "value": "UnifiedGroupMember.Read.AsGuest" + }, + { + "description": "Allows the application to list and read all Tenant Governance requests on behalf of the signed-in user.", + "displayName": "Read Tenant Governance requests", + "id": "a924b9f1-7af0-4982-aecf-b6e0e10b2830", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-Request.Read.All" + }, + { + "description": "Allows the application to list and read all Tenant Governance relationships on behalf of the signed-in user.", + "displayName": "Read Tenant Governance relationships", + "id": "0b1c2458-4845-477b-a704-3cce8b06bf28", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-Relationship.Read.All" + }, + { + "description": "Allows the app to read and write the Teams app settings on behalf of the signed-in user.", + "displayName": "Read and write Teams app settings", + "id": "87c556f0-2bd9-4eed-bd74-5dd8af6eaf7e", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkAppSettings.ReadWrite.All" + }, + { + "description": "Create custom emoji on behalf of the signed-in user.", + "displayName": "Create custom emoji", + "id": "72464cd4-58fd-4116-8a9e-b74757574757", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkCustomEmoji.Create" + }, + { + "description": "Read custom emoji on behalf of the signed-in user.", + "displayName": "Read custom emoji", + "id": "89b231b1-414e-4dd4-bb87-d59906da4e05", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkCustomEmoji.Read" + }, + { + "description": "Allow the app to read the management data for Teams devices on behalf of the signed-in user.", + "displayName": "Read Teams devices", + "id": "b659488b-9d28-4208-b2be-1c6652b3c970", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkDevice.Read.All" + }, + { + "description": "Allow the app to read and write the management data for Teams devices on behalf of the signed-in user.", + "displayName": "Read and write Teams devices", + "id": "ddd97ecb-5c31-43db-a235-0ee20e635c40", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkDevice.ReadWrite.All" + }, + { + "description": "Allows the app to read the signed-in user's sections (folders) for organizing chats and channels in Teams.", + "displayName": "Read your sections", + "id": "87a3258d-8c34-49e2-ab91-9b8bdbd79177", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkSection.Read" + }, + { + "description": "Allows the app to read and write the signed-in user's sections (folders) for organizing chats and channels in Teams.", + "displayName": "Read and write your sections", + "id": "70dbe5e8-39b9-40f3-8c65-3ec7b00ad804", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkSection.ReadWrite" + }, + { + "description": "Allows the app to read tags in Teams, on behalf of the signed-in user.", + "displayName": "Read tags in Teams", + "id": "57587d0b-8399-45be-b207-8050cec54575", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkTag.Read" + }, + { + "description": "Allows the app to read and write tags in Teams, on behalf of the signed-in user.", + "displayName": "Read and write tags in Teams", + "id": "539dabd7-b5b6-4117-b164-d60cd15a8671", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkTag.ReadWrite" + }, + { + "description": "Allows the user to update group chat or channel targeted messages in Microsoft Teams.", + "displayName": "Update targeted messages belonging to the user", + "id": "162354de-2885-4e5a-94fb-2f03019a65a8", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkTargetedMessage.ReadWrite" + }, + { + "description": "Allows the app to read all of the possible Teams interactions between the signed-in user and other users", + "displayName": "Read all of the possible Teams interactions between the user and other users", + "id": "b4d26916-07e0-4daf-9096-9f6d9174aa96", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkUserInteraction.Read.All" + }, + { + "description": "Allows the application to list and read all Tenant Governance invitations on behalf of the signed-in user.", + "displayName": "Read Tenant Governance invitations", + "id": "fda068e8-0524-485e-8d7f-b5bc29b0dae9", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-Invitation.Read.All" + }, + { + "description": "Allows the application to list, read, create, and delete Tenant Governance invitations on behalf of the signed-in user.", + "displayName": "Read and write Tenant Governance invitations", + "id": "42b91635-3803-4af2-a2d5-e91127f9c488", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-Invitation.ReadWrite.All" + }, + { + "description": "Allows the application to list and read all Tenant Governance policy templates on behalf of the signed-in user.", + "displayName": "Read Tenant Governance policy templates", + "id": "ad222a15-813d-46b8-8f8d-1976a69a74f3", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-PolicyTemplate.Read.All" + }, + { + "description": "Allows the application to list, read, create, update, and delete Tenant Governance policy templates on behalf of the signed-in user.", + "displayName": "Read and write Tenant Governance policy templates", + "id": "7cd0bd21-45fe-4c8e-a549-3c95bd27d185", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-PolicyTemplate.ReadWrite.All" + }, + { + "description": "Allows the application to list and read related tenants information on behalf of the signed-in user.", + "displayName": "Read related tenants", + "id": "9caaca93-f090-4b9a-b4bb-17de251354d4", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-RelatedTenant.Read.All" + }, + { + "description": "Allows the application to list, read, and refresh related tenants information on behalf of the signed-in user.", + "displayName": "Read and write related tenants", + "id": "e61db2de-de55-461e-942d-52a028ed1076", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-RelatedTenant.ReadWrite.All" + }, + { + "description": "Allows the application to list, read, and update Tenant Governance relationships on behalf of the signed-in user.", + "displayName": "Read and write Tenant Governance relationships", + "id": "3fbcd6a3-a9a5-4d69-8a78-acc7d7195180", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-Relationship.ReadWrite.All" + }, + { + "description": "Allows the app to create users, on behalf of the signed-in user.", + "displayName": "Create users", + "id": "d8ce6a2a-46ff-438e-96bc-020f23870a55", + "origin": "Delegated (Microsoft Graph)", + "value": "User.Create" + }, + { + "description": "Allows the app to delete and restore all users, on behalf of the signed-in user.", + "displayName": "Delete and restore users", + "id": "4bb440cd-2cf2-4f90-8004-aa2acd2537c5", + "origin": "Delegated (Microsoft Graph)", + "value": "User.DeleteRestore.All" + }, + { + "description": "Allows the app to enable and disable users' accounts, on behalf of the signed-in user.", + "displayName": "Enable and disable user accounts", + "id": "f92e74e7-2563-467f-9dd0-902688cb5863", + "origin": "Delegated (Microsoft Graph)", + "value": "User.EnableDisableAccount.All" + }, + { + "description": "Allows the app to read and write external authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' external methods.", + "id": "9d91805d-0f53-43e3-a0f3-303ad4f3056f", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-External.ReadWrite.All" + }, + { + "description": "Allows the app to read the signed-in user's HardwareOATH authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's HardwareOATH authentication methods", + "id": "ccd2eb40-8874-44e6-8f96-335908b3cfdb", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-HardwareOATH.Read" + }, + { + "description": "Allows the app to read HardwareOATH authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' HardwareOATH authentication methods", + "id": "acd68c26-c283-4bf4-8b5c-200fc179bdd5", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-HardwareOATH.Read.All" + }, + { + "description": "Allows the app to read and write the signed-in user's HardwareOATH authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's HardwareOATH authentication methods", + "id": "147ca97b-6686-4849-b37e-09d9b5ad45fc", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-HardwareOATH.ReadWrite" + }, + { + "description": "Allows the app to read and write HardwareOATH authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' HardwareOATH methods.", + "id": "480643f2-a162-43c5-a670-dc1494fc911b", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-HardwareOATH.ReadWrite.All" + }, + { + "description": "Allows the app to read the signed-in user's Microsoft Authenticator authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's Microsoft Authenticator authentication methods", + "id": "f14a567b-3280-4124-95a0-eca86006967e", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-MicrosoftAuthApp.Read" + }, + { + "description": "Allows the app to read Microsoft authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' Microsoft authentication methods", + "id": "7b627679-e2fd-4bfd-990e-989e2914d4e6", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-MicrosoftAuthApp.Read.All" + }, + { + "description": "Allows the app to read and write the signed-in user's Microsoft Authenticator authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's Microsoft Authenticator authentication methods", + "id": "9f7dfa0c-eb40-42be-8d45-8af4a9219c6f", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-MicrosoftAuthApp.ReadWrite" + }, + { + "description": "Allows the app to read and write Microsoft Authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' Microsoft Authentication methods.", + "id": "1b7322b2-5cb3-4f13-928f-d7ca97c5fba9", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-MicrosoftAuthApp.ReadWrite.All" + }, + { + "description": "Allows the app to read the signed-in user's passkey authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's passkey authentication methods", + "id": "828fcbda-0d26-431d-8bfb-83f217224621", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Passkey.Read" + }, + { + "description": "Allows the app to read passkey authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' passkey authentication methods", + "id": "14195339-1fe4-48a7-a0d3-a39eb9fd8958", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Passkey.Read.All" + }, + { + "description": "Allows the app to read and write the signed-in user's passkey authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's passkey authentication methods", + "id": "b2de7db9-10f7-4800-b04c-b5b91e4891d6", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Passkey.ReadWrite" + }, + { + "description": "Allows the app to read and write passkey authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' passkey methods.", + "id": "64930478-d0ea-4671-ad72-fe0d9821df09", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Passkey.ReadWrite.All" + }, + { + "description": "Allows the app to read the signed-in user's password authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's password authentication methods", + "id": "7f0f82c3-de19-4ddc-810d-a2206d7637fd", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Password.Read" + }, + { + "description": "Allows the app to read password authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' password authentication methods", + "id": "4f69a4e2-2aa0-43a7-ad6b-98b4cda1f23f", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Password.Read.All" + }, + { + "description": "Allows the app to read and write the signed-in user's password authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's password authentication methods", + "id": "60cce20d-d41e-4594-b391-84bbf8cc31f3", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Password.ReadWrite" + }, + { + "description": "Allows the app to read and write password authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' password methods.", + "id": "7f5b683d-df96-4690-a88d-6e336ed6dc7c", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Password.ReadWrite.All" + }, + { + "description": "Allows the app to read and write the signed-in user's external authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's external authentication methods", + "id": "28c2e8f9-828a-4691-a090-f2f0b7fc07b3", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-External.ReadWrite" + }, + { + "description": "Allows the app to read external authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' external authentication methods", + "id": "cbca9646-4c34-4cea-8e54-9a7088018820", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-External.Read.All" + }, + { + "description": "Allows the app to read the signed-in user's external authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's external authentication methods", + "id": "d1739827-146b-4f7f-b52c-1c509253aa57", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-External.Read" + }, + { + "description": "Allows the app to read and write email methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' email methods.", + "id": "074f680f-c89e-45be-880e-5d0642860a1c", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Email.ReadWrite.All" + }, + { + "description": "Allows the app to export data (e.g. customer content or system-generated logs), associated with any user in your company, when the app is used by a privileged user (e.g. a Company Administrator).", + "displayName": "Export user's data", + "id": "405a51b5-8d8d-430b-9842-8be4b0e9f324", + "origin": "Delegated (Microsoft Graph)", + "value": "User.Export.All" + }, + { + "description": "Allows the app to invite guest users to the organization, on behalf of the signed-in user.", + "displayName": "Invite guest users to the organization", + "id": "63dd7cd9-b489-4adf-a28c-ac38b9a0f962", + "origin": "Delegated (Microsoft Graph)", + "value": "User.Invite.All" + }, + { + "description": "Allows the app to read, update and delete identities that are associated with a user's account that the signed-in user has access to. This controls the identities users can sign-in with.", + "displayName": "Manage user identities", + "id": "637d7bec-b31e-4deb-acc9-24275642a2c9", + "origin": "Delegated (Microsoft Graph)", + "value": "User.ManageIdentities.All" + }, + { + "description": "Allows users to sign-in to the app, and allows the app to read the profile of signed-in users. It also allows the app to read basic company information of signed-in users.", + "displayName": "Sign in and read user profile", + "id": "e1fe6dd8-ba31-4d61-89e7-88639da4683d", + "origin": "Delegated (Microsoft Graph)", + "value": "User.Read" + }, + { + "description": "Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user.", + "displayName": "Read all users' full profiles", + "id": "a154be20-db9c-4678-8ab7-66f6cc099a59", + "origin": "Delegated (Microsoft Graph)", + "value": "User.Read.All" + }, + { + "description": "Allows the app to read a basic set of profile properties of other users in your organization on behalf of the signed-in user. This includes display name, first and last name, email address and photo.", + "displayName": "Read all users' basic profiles", + "id": "b340eb25-3456-403f-be2f-af7a0d370277", + "origin": "Delegated (Microsoft Graph)", + "value": "User.ReadBasic.All" + }, + { + "description": "Allows the app to read and update users, on behalf of the signed-in user.", + "displayName": "Read and update users", + "id": "f8b099f1-a6ce-4e00-8fff-5f783ff4faeb", + "origin": "Delegated (Microsoft Graph)", + "value": "User.ReadUpdate.All" + }, + { + "description": "Allows the app to read your profile. It also allows the app to update your profile information on your behalf.", + "displayName": "Read and write access to user profile", + "id": "b4e74841-8e56-480b-be8b-910348b18b4c", + "origin": "Delegated (Microsoft Graph)", + "value": "User.ReadWrite" + }, + { + "description": "Allows the app to read phone authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' phone authentication methods", + "id": "20cf4ae1-09b9-4d29-a6f8-43e1820ce60c", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Phone.Read.All" + }, + { + "description": "Allows the app to read and write the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user.", + "displayName": "Read and write all users' full profiles", + "id": "204e0828-b5ca-4ad8-b9f3-f32a958e7cc4", + "origin": "Delegated (Microsoft Graph)", + "value": "User.ReadWrite.All" + }, + { + "description": "Allows the app to read and report the signed-in user's activity in the app.", + "displayName": "Read and write app activity to users' activity feed", + "id": "47607519-5fb1-47d9-99c7-da4b48f369b1", + "origin": "Delegated (Microsoft Graph)", + "value": "UserActivity.ReadWrite.CreatedByApp" + }, + { + "description": "Allows the app to read the signed-in user's authentication methods, including phone numbers and Authenticator app settings. This does not allow the app to see secret information like the signed-in user's passwords, or to sign-in or otherwise use the signed-in user's authentication methods.", + "displayName": "Read user authentication methods.", + "id": "1f6b61c5-2f65-4135-9c9f-31c0f8d32b52", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthenticationMethod.Read" + }, + { + "description": "Allows the app to read authentication methods of all users in your organization that the signed-in user has access to. Authentication methods include things like a user’s phone numbers and Authenticator app settings. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' authentication methods", + "id": "aec28ec7-4d02-4e8c-b864-50163aea77eb", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthenticationMethod.Read.All" + }, + { + "description": "Allows the app to read and write the signed-in user's authentication methods, including phone numbers and Authenticator app settings. This does not allow the app to see secret information like the signed-in user's passwords, or to sign-in or otherwise use the signed-in user's authentication methods. ", + "displayName": "Read and write user authentication methods", + "id": "48971fc1-70d7-4245-af77-0beb29b53ee2", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthenticationMethod.ReadWrite" + }, + { + "description": " Allows the app to read and write authentication methods of all users in your organization that the signed-in user has access to. Authentication methods include things like a user's phone numbers and Authenticator app settings. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' authentication methods", + "id": "b7887744-6746-4312-813d-72daeaee7e2d", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthenticationMethod.ReadWrite.All" + }, + { + "description": "Allows the app to read the signed-in user's email authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's email authentication methods", + "id": "12b23cea-90c1-4873-9094-f45c5f290f86", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Email.Read" + }, + { + "description": "Allows the app to read email methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' email methods", + "id": "76caaf3a-ebdb-40a3-9299-4196e636f290", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Email.Read.All" + }, + { + "description": "Allows the app to read and write the signed-in user's email authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's email authentication methods", + "id": "696aa421-62dc-4c99-be16-015b23444089", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Email.ReadWrite" + }, + { + "description": "Allow the app to revoke all sign in sessions for a user, on behalf of a signed-in user.", + "displayName": "Revoke all sign in sessions for a user", + "id": "fc30e98b-8810-4501-81f5-c20a3196387b", + "origin": "Delegated (Microsoft Graph)", + "value": "User.RevokeSessions.All" + }, + { + "description": "Allows the app to read all profile photos of users and groups, on behalf of the signed-in user.", + "displayName": "Read profile photo of a user or group", + "id": "469cd065-729e-4dee-b1fa-d92e0fab6310", + "origin": "Delegated (Microsoft Graph)", + "value": "ProfilePhoto.Read.All" + }, + { + "description": "Allows the app to see your users' basic profile (e.g., name, picture, user name, email address)", + "displayName": "View users' basic profile", + "id": "14dad69e-099b-42c9-810b-d002981feec1", + "origin": "Delegated (Microsoft Graph)", + "value": "profile" + }, + { + "description": "Allows the app to delete time-based eligibility schedules for access to Azure AD groups, on behalf of the signed-in user.", + "displayName": "Delete eligibility schedules for access to Azure AD groups", + "id": "c5ea9ab4-9b41-4c09-a400-53e652fb5096", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedEligibilitySchedule.Remove.AzureADGroup" + }, + { + "description": "Allows the application to manage selected file storage container type registrations on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", + "displayName": "Access selected file storage container type registrations.", + "id": "d1e4f63a-1569-475c-b9b2-bdc140405e38", + "origin": "Delegated (Microsoft Graph)", + "value": "FileStorageContainerTypeReg.Selected" + }, + { + "description": "Allows the app to read and write financials data on behalf of the signed-in user.", + "displayName": "Read and write financials data", + "id": "f534bf13-55d4-45a9-8f3c-c92fe64d6131", + "origin": "Delegated (Microsoft Graph)", + "value": "Financials.ReadWrite.All" + }, + { + "description": "Allows the app to read all goals and export jobs that the signed-in user can access.", + "displayName": "Read all goals and export jobs that a user can access", + "id": "092211d9-ca1a-427b-813e-b79c7653fe71", + "origin": "Delegated (Microsoft Graph)", + "value": "Goals-Export.Read.All" + }, + { + "description": "Allows the app to read goals, create and read export jobs that the signed-in user can access.", + "displayName": "Have full access to all goals and export jobs a user can access", + "id": "2edeb9fd-4228-480c-a26d-2ed52011cf3d", + "origin": "Delegated (Microsoft Graph)", + "value": "Goals-Export.ReadWrite.All" + }, + { + "description": "Allows the app to list groups, and to read their basic properties and manage the MIP label for all label enabled groups on behalf of the signed-in user. ", + "displayName": "Manage the Microsoft Information Protection (MIP) label for M365 and security groups.", + "id": "36263ed6-285e-4f84-b25a-62ec2ba17d29", + "origin": "Delegated (Microsoft Graph)", + "value": "Group.ManageProtection.All" + }, + { + "description": "Allows the app to list groups, and to read their properties and all group memberships on behalf of the signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups the signed-in user can access.", + "displayName": "Read all groups", + "id": "5f8c59db-677d-491f-a6b8-5f174b11ec1d", + "origin": "Delegated (Microsoft Graph)", + "value": "Group.Read.All" + }, + { + "description": "Allows the app to create groups and read all group properties and memberships on behalf of the signed-in user. Additionally allows group owners to manage their groups and allows group members to update group content.", + "displayName": "Read and write all groups", + "id": "4e46008b-f24c-477d-8fff-7bb4ec7aafe0", + "origin": "Delegated (Microsoft Graph)", + "value": "Group.ReadWrite.All" + }, + { + "description": "Allows the app to read group conversations that the signed-in user has access to.", + "displayName": "Read group conversations", + "id": "c92fbbc2-50e0-4842-93ef-385c3293ea3d", + "origin": "Delegated (Microsoft Graph)", + "value": "Group-Conversation.Read.All" + }, + { + "description": "Allows the app to read and write group conversations that the signed-in user has access to.", + "displayName": "Read and write group conversations", + "id": "302bcbb5-855a-4e49-ae20-94a331b0281e", + "origin": "Delegated (Microsoft Graph)", + "value": "Group-Conversation.ReadWrite.All" + }, + { + "description": "Allows the app to list groups, read basic group properties and read membership of all groups the signed-in user has access to.", + "displayName": "Read group memberships", + "id": "bc024368-1153-4739-b217-4326f2e966d0", + "origin": "Delegated (Microsoft Graph)", + "value": "GroupMember.Read.All" + }, + { + "description": "Allows the app to list groups, read basic properties, read and update the membership of the groups the signed-in user has access to. Group properties and owners cannot be updated and groups cannot be deleted.", + "displayName": "Read and write group memberships", + "id": "f81125ac-d3b7-4573-a3b2-7099cc39df9e", + "origin": "Delegated (Microsoft Graph)", + "value": "GroupMember.ReadWrite.All" + }, + { + "description": "Allows the app to read and write groups' disableNesting property on behalf of the signed-in user.", + "displayName": "Read and write groups' disableNesting property", + "id": "afc507db-8793-4d2f-999d-6e34cff02b7c", + "origin": "Delegated (Microsoft Graph)", + "value": "Group-NestingSupport.ReadWrite.All" + }, + { + "description": "Allows the app to read and update the on-premises sync behavior of groups on behalf of the signed-in user.", + "displayName": "Read and update the on-premises sync behavior of groups", + "id": "37e00479-5776-4659-aecf-4841ec5d590a", + "origin": "Delegated (Microsoft Graph)", + "value": "Group-OnPremisesSyncBehavior.ReadWrite.All" + }, + { + "description": "Allows the app to read a list of tenant-level or group-specific group settings objects, on behalf of the signed-in user.", + "displayName": "Read all group settings that user can access", + "id": "2eb2bc92-94ef-4c6b-b4ab-2a09bc975e0e", + "origin": "Delegated (Microsoft Graph)", + "value": "GroupSettings.Read.All" + }, + { + "description": "Allows the app to create, read, update, and delete on the list of tenant-level or group-specific group settings objects that you have access to in the organization, on behalf of the signed-in user.", + "displayName": "Read and write all group settings that user can access", + "id": "c1691a6d-99e2-4cfa-b4b5-9e4d67dc0f36", + "origin": "Delegated (Microsoft Graph)", + "value": "GroupSettings.ReadWrite.All" + }, + { + "description": "Allows the app to read all Cross-Tenant Identity Synchronization properties on Groups, on behalf of the signed-in user.", + "displayName": "Read all Group Cross-Tenant Identity Synchronization properties", + "id": "f7c0661b-4247-48ac-a371-05ff047614c6", + "origin": "Delegated (Microsoft Graph)", + "value": "Group-XTenantIdentitySync.Read.All" + }, + { + "description": "Allows the app to read all scenario health monitoring alerts", + "displayName": "Read all scenario health monitoring alerts", + "id": "74b4ff32-4917-4536-a66d-38a4861e6220", + "origin": "Delegated (Microsoft Graph)", + "value": "HealthMonitoringAlert.Read.All" + }, + { + "description": "Allows the application to manage file storage container type registrations on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", + "displayName": "Manage file storage container type registrations on behalf of the signed in user", + "id": "c319a7df-930e-44c0-a43b-7e5e9c7f4f24", + "origin": "Delegated (Microsoft Graph)", + "value": "FileStorageContainerTypeReg.Manage.All" + }, + { + "description": "Allows the app to read and write all scenario monitoring alerts, on behalf of the signed-in user.", + "displayName": "Read and write all scenario monitoring alerts", + "id": "b7c60f27-2195-4d5f-96a7-6b98bdfd9664", + "origin": "Delegated (Microsoft Graph)", + "value": "HealthMonitoringAlert.ReadWrite.All" + }, + { + "description": "Allows the application to manage file storage container types on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", + "displayName": "Manage file storage container types on behalf of the signed in user", + "id": "8e6ec84c-5fcd-4cc7-ac8a-2296efc0ed9b", + "origin": "Delegated (Microsoft Graph)", + "value": "FileStorageContainerType.Manage.All" + }, + { + "description": "Allows the application to utilize the file storage container administration capabilities on behalf of an administrator user.", + "displayName": "Manage all file storage containers", + "id": "527b6d64-cdf5-4b8b-b336-4aa0b8ca2ce5", + "origin": "Delegated (Microsoft Graph)", + "value": "FileStorageContainer.Manage.All" + }, + { + "description": "Allows the app to read all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", + "displayName": "Read all external connections", + "id": "a38267a5-26b6-4d76-9493-935b7599116b", + "origin": "Delegated (Microsoft Graph)", + "value": "ExternalConnection.Read.All" + }, + { + "description": "Allows the app to read and write all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", + "displayName": "Read and write all external connections", + "id": "bbbbd9b3-3566-4931-ac37-2b2180d9e334", + "origin": "Delegated (Microsoft Graph)", + "value": "ExternalConnection.ReadWrite.All" + }, + { + "description": "Allows the app to read and write settings of external connections on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read and write settings of connections that it is authorized to.", + "displayName": "Read and write external connections", + "id": "4082ad95-c812-4f02-be92-780c4c4f1830", + "origin": "Delegated (Microsoft Graph)", + "value": "ExternalConnection.ReadWrite.OwnedBy" + }, + { + "description": "Allow the app to read external datasets and content, on behalf of the signed-in user.", + "displayName": "Read items in external datasets", + "id": "922f9392-b1b7-483c-a4be-0089be7704fb", + "origin": "Delegated (Microsoft Graph)", + "value": "ExternalItem.Read.All" + }, + { + "description": "Allows the app to read and write all external items on behalf of a signed-in user. The signed-in user must be an administrator.", + "displayName": "Read and write all external items", + "id": "b02c54f8-eb48-4c50-a9f0-a149e5a2012f", + "origin": "Delegated (Microsoft Graph)", + "value": "ExternalItem.ReadWrite.All" + }, + { + "description": "Allows the app to read and write external items on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read external items of the connection that it is authorized to.", + "displayName": "Read and write external items", + "id": "4367b9d7-cee7-4995-853c-a0bdfe95c1f9", + "origin": "Delegated (Microsoft Graph)", + "value": "ExternalItem.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read available properties of external user profiles, on behalf of the signed-in user.", + "displayName": "Read external user profiles", + "id": "47167bec-55a7-4caf-9ecc-8d4566e3cfb1", + "origin": "Delegated (Microsoft Graph)", + "value": "ExternalUserProfile.Read.All" + }, + { + "description": "Allows the app to read and write available properties of external user profiles, on behalf of the signed-in user.", + "displayName": "Read and write external user profiles", + "id": "c6068dc7-a791-46a4-a811-b8228e6649ab", + "origin": "Delegated (Microsoft Graph)", + "value": "ExternalUserProfile.ReadWrite.All" + }, + { + "description": "Allows the app to read your family information, members and their basic profile.", + "displayName": "Read your family info", + "id": "3a1e4806-a744-4c70-80fc-223bf8582c46", + "origin": "Delegated (Microsoft Graph)", + "value": "Family.Read" + }, + { + "description": "Allows the app to read the signed-in user's files.", + "displayName": "Read user files", + "id": "10465720-29dd-4523-a11a-6a75c743c9d9", + "origin": "Delegated (Microsoft Graph)", + "value": "Files.Read" + }, + { + "description": "Allows the app to read all files the signed-in user can access.", + "displayName": "Read all files that user can access", + "id": "df85f4d6-205c-4ac5-a5ea-6bf408dba283", + "origin": "Delegated (Microsoft Graph)", + "value": "Files.Read.All" + }, + { + "description": "(Preview) Allows the app to read files that the user selects. The app has access for several hours after the user selects a file.", + "displayName": "Read files that the user selects (preview)", + "id": "5447fe39-cb82-4c1a-b977-520e67e724eb", + "origin": "Delegated (Microsoft Graph)", + "value": "Files.Read.Selected" + }, + { + "description": "Allows the app to read, create, update and delete the signed-in user's files.", + "displayName": "Have full access to user files", + "id": "5c28f0bf-8a70-41f1-8ab2-9032436ddb65", + "origin": "Delegated (Microsoft Graph)", + "value": "Files.ReadWrite" + }, + { + "description": "Allows the app to read, create, update and delete all files the signed-in user can access.", + "displayName": "Have full access to all files user can access", + "id": "863451e7-0667-486c-a5d6-d135439485f0", + "origin": "Delegated (Microsoft Graph)", + "value": "Files.ReadWrite.All" + }, + { + "description": "(Preview) Allows the app to read, create, update and delete files in the application's folder.", + "displayName": "Have full access to the application's folder (preview)", + "id": "8019c312-3263-48e6-825e-2b833497195b", + "origin": "Delegated (Microsoft Graph)", + "value": "Files.ReadWrite.AppFolder" + }, + { + "description": "(Preview) Allows the app to read and write files that the user selects. The app has access for several hours after the user selects a file.", + "displayName": "Read and write files that the user selects (preview)", + "id": "17dde5bd-8c17-420f-a486-969730c1b827", + "origin": "Delegated (Microsoft Graph)", + "value": "Files.ReadWrite.Selected" + }, + { + "description": "Allow the application to access files explicitly permissioned to the application on behalf of the signed in user. The specific files and the permissions granted will be configured in SharePoint Online or OneDrive.", + "displayName": "Access selected Files, on behalf of the signed-in user", + "id": "ef2779dc-ef1b-4211-8310-8a0ac2450081", + "origin": "Delegated (Microsoft Graph)", + "value": "Files.SelectedOperations.Selected" + }, + { + "description": "Allows the application to utilize the file storage container platform to manage containers on behalf of the signed in user. The specific file storage containers and the permissions granted to them will be configured in Microsoft 365 by the developer of each container type.", + "displayName": "Access selected file storage containers", + "id": "085ca537-6565-41c2-aca7-db852babc212", + "origin": "Delegated (Microsoft Graph)", + "value": "FileStorageContainer.Selected" + }, + { + "description": "Allows the app to read all scenario health monitoring alert configurations", + "displayName": "Read all scenario health monitoring alert configurations", + "id": "fb873030-8626-47e6-96ff-8a5bff3b725f", + "origin": "Delegated (Microsoft Graph)", + "value": "HealthMonitoringAlertConfig.Read.All" + }, + { + "description": "Allows the app to read and write all scenario monitoring alert configurations, on behalf of the signed-in user.", + "displayName": "Read and write all scenario monitoring alert configurations.", + "id": "b3e5ebc6-1c23-4337-8286-3f27165addb4", + "origin": "Delegated (Microsoft Graph)", + "value": "HealthMonitoringAlertConfig.ReadWrite.All" + }, + { + "description": "Allows the app to read identity notification settings, email templates, and prerequisites on behalf of the signed-in user.", + "displayName": "Read identity notification settings and templates", + "id": "59cd3e28-aa9c-4f72-a734-1b592eb06853", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityNotifications.Read.All" + }, + { + "description": "Allows the app to read reference definitions on behalf of the signed-in user.", + "displayName": "View reference definitions", + "id": "a3f96ffe-cb84-40a8-ac85-582d7ef97c2a", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-ReferenceDefinition.Read.All" + }, + { + "description": "Allows the app to read and write reference definitions on behalf of the signed-in user.", + "displayName": "Manage reference definitions", + "id": "a757d430-be6d-430f-af57-28aabe79d247", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-ReferenceDefinition.ReadWrite.All" + }, + { + "description": "Allows the app to read current and previous IndustryData runs on behalf of the signed-in user.", + "displayName": "View current and previous runs", + "id": "92685235-50c4-4702-b2c8-36043db6fa79", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-Run.Read.All" + }, + { + "description": "Allows the app to view and start IndustryData runs on behalf of the signed-in user.", + "displayName": "View and start runs", + "id": "f03a6d0e-0989-460f-80b2-e57c8561763e", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-Run.Start" + }, + { + "description": "Allows the app to read source system definitions on behalf of the signed-in user.", + "displayName": "View source system definitions", + "id": "49b7016c-89ae-41e7-bd6f-b7170c5490bf", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-SourceSystem.Read.All" + }, + { + "description": "Allows the app to read and write source system definitions on behalf of the signed-in user.", + "displayName": "Manage source system definitions", + "id": "9599f005-05d6-4ea7-b1b1-4929768af5d0", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-SourceSystem.ReadWrite.All" + }, + { + "description": "Allows the app to read time period definitions on behalf of the signed-in user.", + "displayName": "Read time period definitions", + "id": "c9d51f28-8ccd-42b2-a836-fd8fe9ebf2ae", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-TimePeriod.Read.All" + }, + { + "description": "Allows the app to read and write time period definitions on behalf of the signed-in user.", + "displayName": "Manage time period definitions", + "id": "b6d56528-3032-4f9d-830f-5a24a25e6661", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-TimePeriod.ReadWrite.All" + }, + { + "description": "Allows the app to read the configurations applicable to the signed-in user for protecting organizational data, on behalf of the signed-in user.", + "displayName": "Read configurations for protecting organizational data applicable to the user", + "id": "12f4bffb-b598-413c-984b-db99728f8b54", + "origin": "Delegated (Microsoft Graph)", + "value": "InformationProtectionConfig.Read" + }, + { + "description": "Allows an app to read information protection sensitivity labels and label policy settings, on behalf of the signed-in user.", + "displayName": "Read user sensitivity labels and label policies.", + "id": "4ad84827-5578-4e18-ad7a-86530b12f884", + "origin": "Delegated (Microsoft Graph)", + "value": "InformationProtectionPolicy.Read" + }, + { + "description": "Allows an app to read user metrics insights, such as daily and monthly active users, on behalf of the signed-in user.", + "displayName": "Read user metrics insights", + "id": "7d249730-51a3-4180-8ec1-214f144f1bff", + "origin": "Delegated (Microsoft Graph)", + "value": "Insights-UserMetric.Read.All" + }, + { + "description": "Allows the app to read data for the learner's assignments in the organization's directory, on behalf of the signed-in user.", + "displayName": "Read user's assignments", + "id": "ac08cdae-e845-41db-adf9-5899a0ec9ef6", + "origin": "Delegated (Microsoft Graph)", + "value": "LearningAssignedCourse.Read" + }, + { + "description": "Allows the app to read learning content in the organization's directory, on behalf of the signed-in user.", + "displayName": "Read learning content", + "id": "ea4c1fd9-6a9f-4432-8e5d-86e06cc0da77", + "origin": "Delegated (Microsoft Graph)", + "value": "LearningContent.Read.All" + }, + { + "description": "Allows the app to manage learning content in the organization's directory, on behalf of the signed-in user.", + "displayName": "Manage learning content", + "id": "53cec1c4-a65f-4981-9dc1-ad75dbf1c077", + "origin": "Delegated (Microsoft Graph)", + "value": "LearningContent.ReadWrite.All" + }, + { + "description": "Allows the app to read data for the learning provider in the organization's directory, on behalf of the signed-in user.", + "displayName": "Read learning provider", + "id": "dd8ce36f-9245-45ea-a99e-8ac398c22861", + "origin": "Delegated (Microsoft Graph)", + "value": "LearningProvider.Read" + }, + { + "description": "Allows the app to create, update, read, and delete data for the learning provider in the organization's directory, on behalf of the signed-in user.", + "displayName": "Manage learning provider", + "id": "40c2eb57-abaf-49f5-9331-e90fd01f7130", + "origin": "Delegated (Microsoft Graph)", + "value": "LearningProvider.ReadWrite" + }, + { + "description": "Allows the app to read data for the learner's self-initiated courses in the organization's directory, on behalf of the signed-in user.", + "displayName": "Read user's self-initiated courses", + "id": "f6403ef7-4a96-47be-a190-69ba274c3f11", + "origin": "Delegated (Microsoft Graph)", + "value": "LearningSelfInitiatedCourse.Read" + }, + { + "description": "Allows the app to read and write outbound data flows on behalf of the signed-in user.", + "displayName": "Manage outbound flow definitions", + "id": "aeb68e0b-e562-4a1f-b6dd-3484ad0cbb4b", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-OutboundFlow.ReadWrite.All" + }, + { + "description": "Allows the app to read outbound data flows on behalf of the signed-in user.", + "displayName": "View outbound flow definitions", + "id": "4741a003-8952-4be4-9217-33a0ac327122", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-OutboundFlow.Read.All" + }, + { + "description": "Allows the app to read and write inbound data flows on behalf of the signed-in user.", + "displayName": "Manage inbound flow definitions", + "id": "97044676-2cec-40ee-bd70-38df444c9e70", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-InboundFlow.ReadWrite.All" + }, + { + "description": "Allows the app to read inbound data flows on behalf of the signed-in user.", + "displayName": "View inbound flow definitions", + "id": "cb0774da-a605-42af-959c-32f438fb38f4", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-InboundFlow.Read.All" + }, + { + "description": "Allows the app to read and write identity notification settings, customize email templates, and send test emails on behalf of the signed-in user.", + "displayName": "Read and write identity notification settings and templates", + "id": "c9c9fdea-4ecc-4d82-a2ea-3feff3489275", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityNotifications.ReadWrite.All" + }, + { + "description": "Allows the app to read your organization’s identity (authentication) providers’ properties on behalf of the user.", + "displayName": "Read identity providers", + "id": "43781733-b5a7-4d1b-98f4-e8edff23e1a9", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityProvider.Read.All" + }, + { + "description": "Allows the app to read and write your organization’s identity (authentication) providers’ properties on behalf of the user.", + "displayName": "Read and write identity providers", + "id": "f13ce604-1677-429f-90bd-8a10b9f01325", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityProvider.ReadWrite.All" + }, + { + "description": "Allows the app to read identity risk event information for all users in your organization on behalf of the signed-in user.", + "displayName": "Read identity risk event information", + "id": "8f6a01e7-0391-4ee5-aa22-a3af122cef27", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityRiskEvent.Read.All" + }, + { + "description": "Allows the app to read and update identity risk event information for all users in your organization on behalf of the signed-in user. Update operations include confirming risk event detections. ", + "displayName": "Read and write risk event information", + "id": "9e4862a5-b68f-479e-848a-4e07e25c9916", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityRiskEvent.ReadWrite.All" + }, + { + "description": "Allows the app to read risky agents information in your organization, on behalf of the signed-in user.", + "displayName": "Read risky agents information", + "id": "3215c57f-3faa-4295-95c2-6f14a5bc6124", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityRiskyAgent.Read.All" + }, + { + "description": "Allows the app to read and update identity risky agents information for all agents in your organization on behalf of the signed-in user. Update operations include dismissing risky agents.", + "displayName": "Read and write risky agents information", + "id": "d343bdeb-db6a-4e06-97da-9dafc2d61c60", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityRiskyAgent.ReadWrite.All" + }, + { + "description": "Allows the app to read all identity risky service principal information for your organization, on behalf of the signed-in user.", + "displayName": "Read all identity risky service principal information", + "id": "ea5c4ab0-5a73-4f35-8272-5d5337884e5d", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityRiskyServicePrincipal.Read.All" + }, + { + "description": "Allows the app to search the email message trace on behalf of the signed-in user.", + "displayName": "Search the email message trace", + "id": "b2e7d27e-14e7-41ad-bb15-a88ceb9c3e90", + "origin": "Delegated (Microsoft Graph)", + "value": "ExchangeMessageTrace.Read.All" + }, + { + "description": "Allows the app to read and update identity risky service principal information for all service principals in your organization, on behalf of the signed-in user. Update operations include dismissing risky service principals.", + "displayName": "Read and write all identity risky service principal information", + "id": "bb6f654c-d7fd-4ae3-85c3-fc380934f515", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityRiskyServicePrincipal.ReadWrite.All" + }, + { + "description": "Allows the app to read and update identity risky user information for all users in your organization on behalf of the signed-in user. Update operations include dismissing risky users.", + "displayName": "Read and write risky user information", + "id": "e0a7cdbb-08b0-4697-8264-0069786e9674", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityRiskyUser.ReadWrite.All" + }, + { + "description": "Allows the app to read your organization's user flows, on behalf of the signed-in user.", + "displayName": "Read all identity user flows", + "id": "2903d63d-4611-4d43-99ce-a33f3f52e343", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityUserFlow.Read.All" + }, + { + "description": "Allows the app to read or write your organization's user flows, on behalf of the signed-in user.", + "displayName": "Read and write all identity user flows", + "id": "281892cc-4dbf-4e3a-b6cc-b21029bb4e82", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityUserFlow.ReadWrite.All" + }, + { + "description": "Allows the app to have the same access to mailboxes as the signed-in user via IMAP protocol.", + "displayName": "Read and write access to mailboxes via IMAP.", + "id": "652390e4-393a-48de-9484-05f9b1212954", + "origin": "Delegated (Microsoft Graph)", + "value": "IMAP.AccessAsUser.All" + }, + { + "description": "Allows the app to read basic Industry Data service and resource information on behalf of the signed-in user.", + "displayName": "Read basic Industry Data service and resource definitions", + "id": "60382b96-1f5e-46ea-a544-0407e489e588", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData.ReadBasic.All" + }, + { + "description": "Allows the app to read data connectors on behalf of the signed-in user.", + "displayName": "View data connector definitions", + "id": "d19c0de5-7ecb-4aba-b090-da35ebcd5425", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-DataConnector.Read.All" + }, + { + "description": "Allows the app to read and write data connectors on behalf of the signed-in user.", + "displayName": "Manage data connector definitions", + "id": "5ce933ac-3997-4280-aed0-cc072e5c062a", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-DataConnector.ReadWrite.All" + }, + { + "description": "Allows the app to upload data files to a data connector on behalf of the signed-in user.", + "displayName": "Upload files to a data connector", + "id": "fc47391d-ab2c-410f-9059-5600f7af660d", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-DataConnector.Upload" + }, + { + "description": "Allows the app to read identity risky user information for all users in your organization on behalf of the signed-in user.", + "displayName": "Read identity risky user information", + "id": "d04bb851-cb7c-4146-97c7-ca3e71baf56c", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityRiskyUser.Read.All" + }, + { + "description": "Allows an app to read license assignments for users and groups, on behalf of the signed-in user.", + "displayName": "Read all license assignments.", + "id": "f395577a-0960-456b-979f-7228de0c5996", + "origin": "Delegated (Microsoft Graph)", + "value": "LicenseAssignment.Read.All" + }, + { + "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange Web Services.", + "displayName": "Access mailboxes as the signed-in user via Exchange Web Services", + "id": "9769c687-087d-48ac-9cb3-c37dde652038", + "origin": "Delegated (Microsoft Graph)", + "value": "EWS.AccessAsUser.All" + }, + { + "description": "Allows the app to read your organization's authentication event listeners on behalf of the signed-in user.", + "displayName": "Read your organization's authentication event listeners", + "id": "f7dd3bed-5eec-48da-bc73-1c0ef50bc9a1", + "origin": "Delegated (Microsoft Graph)", + "value": "EventListener.Read.All" + }, + { + "description": "Allows the app to read a user's list of devices on behalf of the signed-in user.", + "displayName": "Read user devices", + "id": "11d4cd79-5ba5-460f-803f-e22c8ab85ccd", + "origin": "Delegated (Microsoft Graph)", + "value": "Device.Read" + }, + { + "description": "Allows the app to read your organization's devices' configuration information on behalf of the signed-in user.", + "displayName": "Read all devices", + "id": "951183d1-1a61-466f-a6d1-1fde911bfd95", + "origin": "Delegated (Microsoft Graph)", + "value": "Device.Read.All" + }, + { + "description": "Allows the app to read device local credential properties including passwords, on behalf of the signed-in user.", + "displayName": "Read device local credential passwords", + "id": "280b3b69-0437-44b1-bc20-3b2fca1ee3e9", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceLocalCredential.Read.All" + }, + { + "description": "Allows the app to read device local credential properties excluding passwords, on behalf of the signed-in user.", + "displayName": "Read device local credential properties", + "id": "9917900e-410b-4d15-846e-42a357488545", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceLocalCredential.ReadBasic.All" + }, + { + "description": "Allows the app to read the properties, group assignments and status of apps, app configurations and app protection policies managed by Microsoft Intune.", + "displayName": "Read Microsoft Intune apps", + "id": "4edf5f54-4666-44af-9de9-0144fb4b6e8c", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementApps.Read.All" + }, + { + "description": "Allows the app to read and write the properties, group assignments and status of apps, app configurations and app protection policies managed by Microsoft Intune.", + "displayName": "Read and write Microsoft Intune apps", + "id": "7b3f05d5-f68c-4b8d-8c59-a2ecd12f24af", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementApps.ReadWrite.All" + }, + { + "description": "Allows the app to read certification authority information on behalf of the signed-in user.", + "displayName": "Read Microsoft Cloud PKI objects", + "id": "ac5c8443-d999-471f-9247-ce92cf5c5560", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementCloudCA.Read.All" + }, + { + "description": "Allows the app to read and write certification authority information on behalf of the signed-in user.", + "displayName": "Read and write Microsoft Cloud PKI objects", + "id": "93028c58-65aa-48db-a706-1fe4ada325ec", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementCloudCA.ReadWrite.All" + }, + { + "description": "Allows the app to read properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups.", + "displayName": "Read Microsoft Intune Device Configuration and Policies", + "id": "f1493658-876a-4c87-8fa7-edb559b3476a", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementConfiguration.Read.All" + }, + { + "description": "Allows the app to read and write properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups.", + "displayName": "Read and write Microsoft Intune Device Configuration and Policies", + "id": "0883f392-0a7a-443d-8c76-16a6d39c7b63", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementConfiguration.ReadWrite.All" + }, + { + "description": "Allows the app to read properties of Microsoft Intune-managed deployment plans and their ring configurations.", + "displayName": "Read Microsoft Intune Deployment Plans", + "id": "700bfe0b-b3bd-4fa4-bec2-6849edd7fb7b", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementDeploymentPlans.Read.All" + }, + { + "description": "Allows the app to read and write properties of Microsoft Intune-managed deployment plans and their ring configurations.", + "displayName": "Read and write Microsoft Intune Deployment Plans", + "id": "9d95843d-67b9-48b2-8e20-e42372db8549", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementDeploymentPlans.ReadWrite.All" + }, + { + "description": "Allows the app to perform remote high impact actions such as wiping the device or resetting the passcode on devices managed by Microsoft Intune.", + "displayName": "Perform user-impacting remote actions on Microsoft Intune devices", + "id": "3404d2bf-2b13-457e-a330-c24615765193", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementManagedDevices.PrivilegedOperations.All" + }, + { + "description": "Allows the app to read the properties of devices managed by Microsoft Intune.", + "displayName": "Read Microsoft Intune devices", + "id": "314874da-47d6-4978-88dc-cf0d37f0bb82", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementManagedDevices.Read.All" + }, + { + "description": "Allows the app to read and write the properties of devices managed by Microsoft Intune. Does not allow high impact operations such as remote wipe and password reset on the device’s owner.", + "displayName": "Read and write Microsoft Intune devices", + "id": "44642bfe-8385-4adc-8fc6-fe3cb2c375c3", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementManagedDevices.ReadWrite.All" + }, + { + "description": "Allows the app to read the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings.", + "displayName": "Read Microsoft Intune RBAC settings", + "id": "49f0cc30-024c-4dfd-ab3e-82e137ee5431", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementRBAC.Read.All" + }, + { + "description": "Allows the app to read and write the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings.", + "displayName": "Read and write Microsoft Intune RBAC settings", + "id": "0c5e8a55-87a6-4556-93ab-adc52c4d862d", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementRBAC.ReadWrite.All" + }, + { + "description": "Allows the app to create device objects based on device templates owned by the signed-in user, on behalf of the signed in user.", + "displayName": "Create devices based on owned device templates", + "id": "edc92e89-a987-48a9-911a-a7b1967dd7b1", + "origin": "Delegated (Microsoft Graph)", + "value": "Device.CreateFromOwnedTemplate" + }, + { + "description": "Allows the app to read Microsoft Intune device compliance scripts, device management scripts, device shell scripts, device custom attribute shell scripts and device health scripts on behalf of the signed in user.", + "displayName": "Read Microsoft Intune Scripts", + "id": "d32381d8-ee89-4220-9c83-b672aa68d404", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementScripts.Read.All" + }, + { + "description": "Allows the app to launch another app or communicate with another app on a user's device on behalf of the signed-in user.", + "displayName": "Communicate with user devices", + "id": "bac3b9c2-b516-4ef4-bd3b-c2ef73d8d804", + "origin": "Delegated (Microsoft Graph)", + "value": "Device.Command" + }, + { + "description": "Allows the app to read delegated permission grants, on behalf of the signed in user.", + "displayName": "Read delegated permission grants", + "id": "a197cdc4-a8e8-4d49-9d35-4ca7c83887b4", + "origin": "Delegated (Microsoft Graph)", + "value": "DelegatedPermissionGrant.Read.All" + }, + { + "description": "Allows the application to list and query user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export and remove external user data (e.g. customer content or system-generated logs), associated with the current tenant on behalf of the signed-in user.", + "displayName": "Read shared cross-tenant user profile and export or delete data", + "id": "eed0129d-dc60-4f30-8641-daf337a39ffd", + "origin": "Delegated (Microsoft Graph)", + "value": "CrossTenantUserProfileSharing.ReadWrite" + }, + { + "description": "Allows the application to list and query any shared user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export and remove external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant on behalf of the signed-in user.", + "displayName": "Read all shared cross-tenant user profiles and export or delete their data", + "id": "64dfa325-cbf8-48e3-938d-51224a0cac01", + "origin": "Delegated (Microsoft Graph)", + "value": "CrossTenantUserProfileSharing.ReadWrite.All" + }, + { + "description": "Allows the app to read your organization's custom authentication extensions on behalf of the signed-in user.", + "displayName": "Read your organization's custom authentication extensions", + "id": "b2052569-c98c-4f36-a5fb-43e5c111e6d0", + "origin": "Delegated (Microsoft Graph)", + "value": "CustomAuthenticationExtension.Read.All" + }, + { + "description": "Allows the app to read or write your organization's custom authentication extensions on behalf of the signed-in user.", + "displayName": "Read and write your organization's custom authentication extensions", + "id": "8dfcf82f-15d0-43b3-bc78-a958a13a5792", + "origin": "Delegated (Microsoft Graph)", + "value": "CustomAuthenticationExtension.ReadWrite.All" + }, + { + "description": "Allows the app to read custom detection rules on behalf of the signed-in user.", + "displayName": "Read custom detection rules", + "id": "b13ff42e-f321-4d7d-a462-141c46a1b832", + "origin": "Delegated (Microsoft Graph)", + "value": "CustomDetection.Read.All" + }, + { + "description": "Allows the app to read and write custom detection rules on behalf of the signed-in user.", + "displayName": "Read and write custom detection rules", + "id": "c34088fb-0649-4714-af0b-bcbfec155897", + "origin": "Delegated (Microsoft Graph)", + "value": "CustomDetection.ReadWrite.All" + }, + { + "description": "Allows the app to read custom security attribute assignments for all principals in the tenant on behalf of a signed in user.", + "displayName": "Read custom security attribute assignments", + "id": "b46ffa80-fe3d-4822-9a1a-c200932d54d0", + "origin": "Delegated (Microsoft Graph)", + "value": "CustomSecAttributeAssignment.Read.All" + }, + { + "description": "Allows the app to read and write custom security attribute assignments for all principals in the tenant on behalf of a signed in user.", + "displayName": "Read and write custom security attribute assignments", + "id": "ca46335e-8453-47cd-a001-8459884efeae", + "origin": "Delegated (Microsoft Graph)", + "value": "CustomSecAttributeAssignment.ReadWrite.All" + }, + { + "description": "Allows the app to read audit logs for events that contain information about custom security attributes, on behalf of the signed-in user.", + "displayName": "Read custom security attribute audit logs", + "id": "1fcdeaab-b519-44dd-bffc-ed1fd15a24e0", + "origin": "Delegated (Microsoft Graph)", + "value": "CustomSecAttributeAuditLogs.Read.All" + }, + { + "description": "Allows the app to read custom security attribute definitions for the tenant on behalf of a signed in user.", + "displayName": "Read custom security attribute definitions", + "id": "ce026878-a0ff-4745-a728-d4fedd086c07", + "origin": "Delegated (Microsoft Graph)", + "value": "CustomSecAttributeDefinition.Read.All" + }, + { + "description": "Allows the app to read and write custom security attribute definitions for the tenant on behalf of a signed in user.", + "displayName": "Read and write custom security attribute definitions", + "id": "8b0160d4-5743-482b-bb27-efc0a485ca4a", + "origin": "Delegated (Microsoft Graph)", + "value": "CustomSecAttributeDefinition.ReadWrite.All" + }, + { + "description": "Allows the app to read the provisioning configuration of all active custom security attributes on behalf of a signed in user.", + "displayName": "Read the provisioning configuration of all active custom security attributes", + "id": "9ddd870d-077c-49e7-b3e3-6b3012a8a880", + "origin": "Delegated (Microsoft Graph)", + "value": "CustomSecAttributeProvisioning.Read.All" + }, + { + "description": "Allows the app to read and edit the provisioning configuration of all active custom security attributes on behalf of a signed in user.", + "displayName": "Read and edit the provisioning configuration of all active custom security attributes", + "id": "1140d9e4-6776-433e-a9e4-b9831adbb2e0", + "origin": "Delegated (Microsoft Graph)", + "value": "CustomSecAttributeProvisioning.ReadWrite.All" + }, + { + "description": "Read custom tags data on behalf of the signed-in user", + "displayName": "Read all custom tags data", + "id": "de6ea87d-10bd-467c-8682-d525a0c61b89", + "origin": "Delegated (Microsoft Graph)", + "value": "CustomTags.Read.All" + }, + { + "description": "Read and write custom tags data on behalf of the signed-in user", + "displayName": "Read and write custom tags data", + "id": "2f1bbe0a-f34b-4efb-9edb-8db8dcb50eca", + "origin": "Delegated (Microsoft Graph)", + "value": "CustomTags.ReadWrite.All" + }, + { + "description": "Allows the app to read details of delegated admin relationships with customers like access details (that includes roles) and the duration as well as specific role assignments to security groups on behalf of the signed-in user.", + "displayName": "Read Delegated Admin relationships with customers", + "id": "0c0064ea-477b-4130-82a5-4c2cc4ff68aa", + "origin": "Delegated (Microsoft Graph)", + "value": "DelegatedAdminRelationship.Read.All" + }, + { + "description": "Allows the app to manage (create-update-terminate) Delegated Admin relationships with customers as well as role assignments to security groups for active Delegated Admin relationships on behalf of the signed-in user.", + "displayName": "Manage Delegated Admin relationships with customers", + "id": "885f682f-a990-4bad-a642-36736a74b0c7", + "origin": "Delegated (Microsoft Graph)", + "value": "DelegatedAdminRelationship.ReadWrite.All" + }, + { + "description": "Allows the app to manage permission grants for delegated permissions exposed by any API (including Microsoft Graph), on behalf of the signed in user.", + "displayName": "Manage all delegated permission grants", + "id": "41ce6ca6-6826-4807-84f1-1c82854f7ee5", + "origin": "Delegated (Microsoft Graph)", + "value": "DelegatedPermissionGrant.ReadWrite.All" + }, + { + "description": "Allows the app to read and write Microsoft Intune device compliance scripts, device management scripts, device shell scripts, device custom attribute shell scripts and device health scripts on behalf of the signed in user.", + "displayName": "Read and write Microsoft Intune Scripts", + "id": "8b9d79d0-ad75-4566-8619-f7500ecfcebe", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementScripts.ReadWrite.All" + }, + { + "description": "Allows the app to read Microsoft Intune service properties including device enrollment and third party service connection configuration.", + "displayName": "Read Microsoft Intune configuration", + "id": "8696daa5-bce5-4b2e-83f9-51b6defc4e1e", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementServiceConfig.Read.All" + }, + { + "description": "Allows the app to read and write Microsoft Intune service properties including device enrollment and third party service connection configuration.", + "displayName": "Read and write Microsoft Intune configuration", + "id": "662ed50a-ac44-4eef-ad86-62eed9be2a29", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementServiceConfig.ReadWrite.All" + }, + { + "description": "Allows the app to read and write user's modules and resources on behalf of the signed-in user.", + "displayName": "Read and write the user's class modules and resources", + "id": "4793c53b-df34-44fd-8d26-d15c517732f5", + "origin": "Delegated (Microsoft Graph)", + "value": "EduCurricula.ReadWrite" + }, + { + "description": "Allows the app to read the structure of schools and classes in an organization's roster and education-specific information about users to be read on behalf of the user.", + "displayName": "Read users' view of the roster", + "id": "a4389601-22d9-4096-ac18-36a927199112", + "origin": "Delegated (Microsoft Graph)", + "value": "EduRoster.Read" + }, + { + "description": "Allows the app to read a limited subset of the properties from the structure of schools and classes in an organization's roster and a limited subset of properties about users to be read on behalf of the user. Includes name, status, education role, email address and photo.", + "displayName": "Read a limited subset of users' view of the roster", + "id": "5d186531-d1bf-4f07-8cea-7c42119e1bd9", + "origin": "Delegated (Microsoft Graph)", + "value": "EduRoster.ReadBasic" + }, + { + "description": "Allows the app to read and write the structure of schools and classes in an organization's roster and education-specific information about users to be read and written on behalf of the user.", + "displayName": "Read and write users' view of the roster", + "id": "359e19a6-e3fa-4d7f-bcab-d28ec592b51e", + "origin": "Delegated (Microsoft Graph)", + "value": "EduRoster.ReadWrite" + }, + { + "description": "Allows the app to read your users' primary email address", + "displayName": "View users' email address", + "id": "64a6cdd6-aab1-4aaf-94b8-3cc8405e90d0", + "origin": "Delegated (Microsoft Graph)", + "value": "email" + }, + { + "description": "Allows the app to read Viva Engage conversations, and to read their properties on behalf of the signed-in user.", + "displayName": "Read all Viva Engage conversations", + "id": "c55541d9-2cdd-4fad-8ead-0c08fae5b0c8", + "origin": "Delegated (Microsoft Graph)", + "value": "EngagementConversation.Read.All" + }, + { + "description": "Allows the app to create Viva Engage conversations and read all conversation properties on behalf of the signed-in user.", + "displayName": "Read and write all Viva Engage conversations", + "id": "ebbfd079-1634-4640-8618-68b19ebbed1d", + "origin": "Delegated (Microsoft Graph)", + "value": "EngagementConversation.ReadWrite.All" + }, + { + "description": "Allows the app to read Viva Engage Teams QA conversations, and to read their properties on behalf of the signed-in user.", + "displayName": "Read all Viva Engage Teams QA conversations", + "id": "58c5819e-29bd-4400-ad52-82cd82a63fbd", + "origin": "Delegated (Microsoft Graph)", + "value": "EngagementMeetingConversation.Read.All" + }, + { + "description": "Allows the app to list a user's Viva Engage roles, on behalf of the signed-in user.", + "displayName": "Read a user's Viva Engage roles ", + "id": "9f1da0fc-345c-4dfb-bab5-5215a073a417", + "origin": "Delegated (Microsoft Graph)", + "value": "EngagementRole.Read" + }, + { + "description": "Allows the app to list all Viva Engage roles and role memberships on behalf of the signed-in user.", + "displayName": "Read all Viva Engage roles and role memberships", + "id": "3cad91a5-8413-4c4a-acfe-dfeb83d1366d", + "origin": "Delegated (Microsoft Graph)", + "value": "EngagementRole.Read.All" + }, + { + "description": "Allows the app to assign Viva Engage role to a user, and remove a Viva Engage role from a user behalf of the signed-in user.", + "displayName": "Modify Viva Engage role membership", + "id": "4905982d-6459-4ccd-949c-949fefc0a8f2", + "origin": "Delegated (Microsoft Graph)", + "value": "EngagementRole.ReadWrite.All" + }, + { + "description": "Allows the app to read access packages and related entitlement management resources on behalf of the signed-in user.", + "displayName": "Read all entitlement management resources", + "id": "5449aa12-1393-4ea2-a7c7-d0e06c1a56b2", + "origin": "Delegated (Microsoft Graph)", + "value": "EntitlementManagement.Read.All" + }, + { + "description": "Allows the app to request access to and management of access packages and related entitlement management resources on behalf of the signed-in user.", + "displayName": "Read and write entitlement management resources", + "id": "ae7a573d-81d7-432b-ad44-4ed5c9d89038", + "origin": "Delegated (Microsoft Graph)", + "value": "EntitlementManagement.ReadWrite.All" + }, + { + "description": "Allows the app to manage self-service entitlement management resources on behalf of the signed-in user. This includes operations such as requesting access and approving access of others.", + "displayName": "Read and write entitlement management resources related to self-service operations", + "id": "e9fdcbbb-8807-410f-b9ec-8d5468c7c2ac", + "origin": "Delegated (Microsoft Graph)", + "value": "EntitlementMgmt-SubjectAccess.ReadWrite" + }, + { + "description": "Allows the app to list the all the snapshots, jobs and enumerate the changes of a specific preview job, on behalf of the signed-in user.", + "displayName": "Read Preview jobs and snapshots", + "id": "a6ea9dd7-4dd9-4484-a80a-ac9ad981dcf1", + "origin": "Delegated (Microsoft Graph)", + "value": "EntraBackup.Read.All" + }, + { + "description": "Allows the app to list the all the snapshots, create a preview job and enumerate the changes of a specific preview job, on behalf of the signed-in user.", + "displayName": "Create a preview job, read preview job and snapshots", + "id": "cef123a8-c18c-4eba-852e-d90cfbf67c91", + "origin": "Delegated (Microsoft Graph)", + "value": "EntraBackup.ReadWrite.Preview" + }, + { + "description": "Allows the app to list the all the snapshots, create a recovery job and enumerate the changes of a specific recovery job, on behalf of the signed-in user.", + "displayName": "Create preview and recovery job, read recovery job and snapshots", + "id": "8269c6ff-41d7-4172-a783-b2ce38322e42", + "origin": "Delegated (Microsoft Graph)", + "value": "EntraBackup.ReadWrite.Recovery" + }, + { + "description": "Allows the app to read the user's modules and resources on behalf of the signed-in user.", + "displayName": "Read the user's class modules and resources", + "id": "484859e8-b9e2-4e92-b910-84db35dadd29", + "origin": "Delegated (Microsoft Graph)", + "value": "EduCurricula.Read" + }, + { + "description": "Allows the app to read and write assignments without grades on behalf of the user.", + "displayName": "Read and write users' class assignments without grades", + "id": "2ef770a1-622a-47c4-93ee-28d6adbed3a0", + "origin": "Delegated (Microsoft Graph)", + "value": "EduAssignments.ReadWriteBasic" + }, + { + "description": "Allows the app to read and write assignments and their grades on behalf of the user.", + "displayName": "Read and write users' class assignments and their grades", + "id": "2f233e90-164b-4501-8bce-31af2559a2d3", + "origin": "Delegated (Microsoft Graph)", + "value": "EduAssignments.ReadWrite" + }, + { + "description": "Allows the app to read assignments without grades on behalf of the user.", + "displayName": "Read users' class assignments without grades", + "id": "c0b0103b-c053-4b2e-9973-9f3a544ec9b8", + "origin": "Delegated (Microsoft Graph)", + "value": "EduAssignments.ReadBasic" + }, + { + "description": "Allows the app to create device templates on behalf of the signed in user. The user is marked as owners of the created device template. As a member of owners, the user will be allowed to manage devices created from the template.", + "displayName": "Create device templates", + "id": "0b1717ff-3e42-4a73-8c29-e6b2e1093960", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceTemplate.Create" + }, + { + "description": "Allows the app to read all device templates, on behalf of the signed in user.", + "displayName": "Read all device templates", + "id": "2bcae0b0-aa93-48e4-a9e4-855482dffdcd", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceTemplate.Read.All" + }, + { + "description": "Allows the app to create, read, update and delete the device template, on behalf of the signed in user. It also allows the app to add or remove owners on any device template.", + "displayName": "Read and write all device templates", + "id": "2d372e98-f1ae-406c-a157-2ea83f6f5e4a", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceTemplate.ReadWrite.All" + }, + { + "description": "Allows the app to have the same access to information in the directory as the signed-in user.", + "displayName": "Access directory as the signed in user", + "id": "0e263e50-5827-48a4-b97c-d940288653c7", + "origin": "Delegated (Microsoft Graph)", + "value": "Directory.AccessAsUser.All" + }, + { + "description": "Allows the app to read data in your organization's directory, such as users, groups and apps.", + "displayName": "Read directory data", + "id": "06da0dbc-49e2-44d2-8312-53f166ab848a", + "origin": "Delegated (Microsoft Graph)", + "value": "Directory.Read.All" + }, + { + "description": "Allows the app to read and write data in your organization's directory, such as users, and groups. It does not allow the app to delete users or groups, or reset user passwords.", + "displayName": "Read and write directory data", + "id": "c5366453-9fb0-48a5-a156-24f0c49a4b84", + "origin": "Delegated (Microsoft Graph)", + "value": "Directory.ReadWrite.All" + }, + { + "description": "Allows the app to read Azure AD recommendations, on behalf of the signed-in user.", + "displayName": "Read Azure AD recommendations", + "id": "34d3bd24-f6a6-468c-b67c-0c365c1d6410", + "origin": "Delegated (Microsoft Graph)", + "value": "DirectoryRecommendations.Read.All" + }, + { + "description": "Allows the app to read and update Azure AD recommendations, on behalf of the signed-in user.", + "displayName": "Read and update Azure AD recommendations", + "id": "f37235e8-90a0-4189-93e2-e55b53867ccd", + "origin": "Delegated (Microsoft Graph)", + "value": "DirectoryRecommendations.ReadWrite.All" + }, + { + "description": "Allows the app to read or write your organization's authentication event listeners on behalf of the signed-in user.", + "displayName": "Read and write your organization's authentication event listeners", + "id": "d11625a6-fe21-4fc6-8d3d-063eba5525ad", + "origin": "Delegated (Microsoft Graph)", + "value": "EventListener.ReadWrite.All" + }, + { + "description": "Allows the app to read all domain properties on behalf of the signed-in user.", + "displayName": "Read domains.", + "id": "2f9ee017-59c1-4f1d-9472-bd5529a7b311", + "origin": "Delegated (Microsoft Graph)", + "value": "Domain.Read.All" + }, + { + "description": "Allows the app to read internal federation configuration for a domain.", + "displayName": "Read internal federation configuration for a domain.", + "id": "33203a2a-a761-40f0-8a7c-a7e74a9f8ac6", + "origin": "Delegated (Microsoft Graph)", + "value": "Domain-InternalFederation.Read.All" + }, + { + "description": "Allows the app to create, read, update and delete internal federation configuration for a domain.", + "displayName": "Create, read, update and delete internal federation configuration for a domain.", + "id": "857bd3ea-490e-4284-88a7-a7de1893b6ee", + "origin": "Delegated (Microsoft Graph)", + "value": "Domain-InternalFederation.ReadWrite.All" + }, + { + "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange ActiveSync.", + "displayName": "Access mailboxes via Exchange ActiveSync", + "id": "ff91d191-45a0-43fd-b837-bd682c4a0b0f", + "origin": "Delegated (Microsoft Graph)", + "value": "EAS.AccessAsUser.All" + }, + { + "description": "Allows the app to read eDiscovery objects such as cases, custodians, review sets and other related objects on behalf of the signed-in user.", + "displayName": "Read all eDiscovery objects", + "id": "99201db3-7652-4d5a-809a-bdb94f85fe3c", + "origin": "Delegated (Microsoft Graph)", + "value": "eDiscovery.Read.All" + }, + { + "description": "Allows the app to read and write eDiscovery objects such as cases, custodians, review sets and other related objects on behalf of the signed-in user.", + "displayName": "Read and write all eDiscovery objects", + "id": "acb8f680-0834-4146-b69e-4ab1b39745ad", + "origin": "Delegated (Microsoft Graph)", + "value": "eDiscovery.ReadWrite.All" + }, + { + "description": "Read the state and settings of all Microsoft education apps on behalf of the user.", + "displayName": "Read education app settings", + "id": "8523895c-6081-45bf-8a5d-f062a2f12c9f", + "origin": "Delegated (Microsoft Graph)", + "value": "EduAdministration.Read" + }, + { + "description": "Manage the state and settings of all Microsoft education apps on behalf of the user.", + "displayName": "Manage education app settings", + "id": "63589852-04e3-46b4-bae9-15d5b1050748", + "origin": "Delegated (Microsoft Graph)", + "value": "EduAdministration.ReadWrite" + }, + { + "description": "Allows the app to read assignments and their grades on behalf of the user.", + "displayName": "Read users' class assignments and their grades", + "id": "091460c9-9c4a-49b2-81ef-1f3d852acce2", + "origin": "Delegated (Microsoft Graph)", + "value": "EduAssignments.Read" + }, + { + "description": "Allows the app to read and write all domain properties on behalf of the signed-in user. Also allows the app to add, verify and remove domains.", + "displayName": "Read and write domains", + "id": "0b5d694c-a244-4bde-86e6-eb5cd07730fe", + "origin": "Delegated (Microsoft Graph)", + "value": "Domain.ReadWrite.All" + }, + { + "description": "Allows the Application to read and write the user's data pertaining to itself in the Intune Mobile Application Management service", + "displayName": "Read and Write the User's App Management data", + "id": "3c7192af-9629-4473-9276-d35e4e4b36c5", + "origin": "Delegated (Microsoft Mobile Application Management)", + "value": "DeviceManagementManagedApps.ReadWrite" + }, + { + "description": "Allows an app to manage license assignments for users and groups, on behalf of the signed-in user.", + "displayName": "Manage all license assignments", + "id": "f55016cc-149c-447e-8f21-7cf3ec1d6350", + "origin": "Delegated (Microsoft Graph)", + "value": "LicenseAssignment.ReadWrite.All" + }, + { + "description": "Allows the app to read, create, update and delete identity lifecycle policies for agent identities that the signed-in user has access to in the organization.", + "displayName": "Read and write identity lifecycle policies for agent identities", + "id": "f2292ca5-46fc-4195-9b4d-16491bf9bf7f", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecyclePolicies-AgentId.ReadWrite.All" + }, + { + "description": "Allows the app to read and write the authentication flow policies, on behalf of the signed-in user.", + "displayName": "Read and write authentication flow policies", + "id": "edb72de9-4252-4d03-a925-451deef99db7", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.AuthenticationFlows" + }, + { + "description": "Allows the app to read and write the authentication method policies, on behalf of the signed-in user. ", + "displayName": "Read and write authentication method policies", + "id": "7e823077-d88e-468f-a337-e18f1f0e6c7c", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.AuthenticationMethod" + }, + { + "description": "Allows the app to read and write your organization's authorization policy on behalf of the signed-in user. For example, authorization policies can control some of the permissions that the out-of-the-box user role has by default.", + "displayName": "Read and write your organization's authorization policy", + "id": "edd3c878-b384-41fd-95ad-e7407dd775be", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.Authorization" + }, + { + "description": "Allows the app to read and write your organization's B2BManagement policies on behalf of the signed-in user.", + "displayName": "Read and write your organization's B2BManagement policies", + "id": "723c4a0c-85b0-4a02-bb2a-c9eb07959de9", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.B2BManagementPolicy" + }, + { + "description": "Allows the app to read and write your organization's conditional access policies on behalf of the signed-in user.", + "displayName": "Read and write your organization's conditional access policies", + "id": "ad902697-1014-4ef5-81ef-2b4301988e8c", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.ConditionalAccess" + }, + { + "description": "Allows the app to read and write your organization's consent requests policy on behalf of the signed-in user.", + "displayName": "Read and write consent request policy", + "id": "4d135e65-66b8-41a8-9f8b-081452c91774", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.ConsentRequest" + }, + { + "description": "Allows the app to read and write your organization's cross-tenant access policies and configuration for automatic user consent settings to suppress consent prompts for users of the other tenant on behalf of the signed-in user.", + "displayName": "Read and write your organization's cross tenant access policies", + "id": "014b43d0-6ed4-4fc6-84dc-4b6f7bae7d85", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.CrossTenantAccess" + }, + { + "description": "Allows the app to read and write your organization's M365 cross tenant access capabilities on behalf of the signed-in user.", + "displayName": "Read and write your organization's M365 cross tenant access capabilities", + "id": "9ef7463f-1d39-406f-89ea-3483a4645e1c", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.CrossTenantCapability" + }, + { + "description": "Allows the app to read and write your organization's device configuration policies on behalf of the signed-in user. For example, device registration policy can limit initial provisioning controls using quota restrictions, additional authentication and authorization checks.", + "displayName": "Read and write your organization's device configuration policies", + "id": "40b534c3-9552-4550-901b-23879c90bcf9", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.DeviceConfiguration" + }, + { + "description": "Allows the application to read and update the organization's external identities policy on behalf of the signed-in user. For example, external identities policy controls if users invited to access resources in your organization via B2B collaboration or B2B direct connect are allowed to self-service leave.", + "displayName": "Read and write your organization's external identities policy", + "id": "b5219784-1215-45b5-b3f1-88fe1081f9c0", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.ExternalIdentities" + }, + { + "description": "Allows the app to read and write your organization's feature rollout policies on behalf of the signed-in user. Includes abilities to assign and remove users and groups to rollout of a specific feature.", + "displayName": "Read and write your organization's feature rollout policies", + "id": "92a38652-f13b-4875-bc77-6e1dbb63e1b2", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.FeatureRollout" + }, + { + "description": "Allows the application to read and update the organization's federated token validation policy on behalf of the signed-in user.", + "displayName": "Read and write your organization's federated token validation policy", + "id": "be1be369-4540-4ac9-8928-79de99f70d8f", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.FedTokenValidation" + }, + { + "description": "Allows the app to read and write your organization’s identity protection policy on behalf of the signed-in user.", + "displayName": "Read and write your organization’s identity protection policy ", + "id": "7256e131-3efb-4323-9854-cf41c6021770", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.IdentityProtection" + }, + { + "description": "Allows the app to read and write your organization's mobility management policies on behalf of the signed-in user. For example, a mobility management policy can set the enrollment scope for a given mobility management application.", + "displayName": "Read and write your organization's mobility management policies", + "id": "a8ead177-1889-4546-9387-f25e658e2a79", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.MobilityManagement" + }, + { + "description": "Allows the app to manage policies related to consent and permission grants for applications, on behalf of the signed-in user.", + "displayName": "Manage consent and permission grant policies", + "id": "2672f8bb-fd5e-42e0-85e1-ec764dd2614e", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.PermissionGrant" + }, + { + "description": "Allows the application to read and update the organization's recovery policy on behalf of the signed-in user.", + "displayName": "Read and write your organization's recovery policy", + "id": "1e7a2f4c-e602-4b1b-9547-304dd65c4cc2", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.Recovery" + }, + { + "description": "Allows the app to read and write your organization's security defaults policy on behalf of the signed-in user.", + "displayName": "Read and write your organization's security defaults policy", + "id": "0b2a744c-2abf-4f1e-ad7e-17a087e2be99", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.SecurityDefaults" + }, + { + "description": "Allows the app to read and write your organization's application configuration policies on behalf of the signed-in user. This includes policies such as activityBasedTimeoutPolicy, claimsMappingPolicy, homeRealmDiscoveryPolicy, tokenIssuancePolicy and tokenLifetimePolicy.", + "displayName": "Read and write your organization's application configuration policies", + "id": "b27add92-efb2-4f16-84f5-8108ba77985c", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.ApplicationConfiguration" + }, + { + "description": "Allows the app to read and write your organization's trust framework policies on behalf of the signed-in user.", + "displayName": "Read and write your organization's trust framework policies", + "id": "cefba324-1a70-4a6e-9c1d-fd670b7ae392", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.TrustFramework" + }, + { + "description": "Allows the app to read and write your organization's directory access review default policy on behalf of the signed-in user.", + "displayName": "Read and write your organization's directory access review default policy", + "id": "4f5bc9c8-ea54-4772-973a-9ca119cb0409", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.AccessReview" + }, + { + "description": "Allows the app to read policies related to consent and permission grants for applications, on behalf of the signed-in user.", + "displayName": "Read consent and permission grant policies", + "id": "414de6ea-2d92-462f-b120-6e2a809a6d01", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.PermissionGrant" + }, + { + "description": "Allows the app to read available properties of pending external user profiles, on behalf of the signed-in user.", + "displayName": "Read pending external user profiles", + "id": "d88fd3fb-53d3-4c1c-8c39-787fcac2ed7a", + "origin": "Delegated (Microsoft Graph)", + "value": "PendingExternalUserProfile.Read.All" + }, + { + "description": "Allows the app to read and write available properties of pending external user profiles, on behalf of the signed-in user.", + "displayName": "Read and write pending external user profiles", + "id": "93a1fb28-c908-4826-904e-0c74ad352b73", + "origin": "Delegated (Microsoft Graph)", + "value": "PendingExternalUserProfile.ReadWrite.All" + }, + { + "description": "Allows the app to read a ranked list of relevant people of the signed-in user. The list includes local contacts, contacts from social networking, your organization's directory, and people from recent communications (such as email and Skype).", + "displayName": "Read users' relevant people lists", + "id": "ba47897c-39ec-4d83-8086-ee8256fa737d", + "origin": "Delegated (Microsoft Graph)", + "value": "People.Read" + }, + { + "description": "Allows the app to read a scored list of relevant people of the signed-in user or other users in the signed-in user's organization. The list can include local contacts, contacts from social networking, your organization's directory, and people from recent communications (such as email and Skype).", + "displayName": "Read all users' relevant people lists", + "id": "b89f9189-71a5-4e70-b041-9887f0bc7e4a", + "origin": "Delegated (Microsoft Graph)", + "value": "People.Read.All" + }, + { + "description": "Allows the application to read tenant-wide people settings on behalf of the signed-in user.", + "displayName": "Read tenant-wide people settings", + "id": "ec762c5f-388b-4b16-8693-ac1efbc611bc", + "origin": "Delegated (Microsoft Graph)", + "value": "PeopleSettings.Read.All" + }, + { + "description": "Allows the application to read and write tenant-wide people settings on behalf of the signed-in user.", + "displayName": "Read and write tenant-wide people settings", + "id": "e67e6727-c080-415e-b521-e3f35d5248e9", + "origin": "Delegated (Microsoft Graph)", + "value": "PeopleSettings.ReadWrite.All" + }, + { + "description": "Allows the app to read your company's places (conference rooms and room lists) for calendar events and other applications, on behalf of the signed-in user.", + "displayName": "Read all company places", + "id": "cb8f45a0-5c2e-4ea1-b803-84b870a7d7ec", + "origin": "Delegated (Microsoft Graph)", + "value": "Place.Read.All" + }, + { + "description": "Allows the app to manage organization places (conference rooms and room lists) for calendar events and other applications, on behalf of the signed-in user.", + "displayName": "Read and write organization places", + "id": "4c06a06a-098a-4063-868e-5dfee3827264", + "origin": "Delegated (Microsoft Graph)", + "value": "Place.ReadWrite.All" + }, + { + "description": "Allows the app to read all workplace devices, on behalf of the signed-in user.", + "displayName": "Read all workplace devices", + "id": "4c7f93d2-6b0b-4e05-91aa-87842f0a2142", + "origin": "Delegated (Microsoft Graph)", + "value": "PlaceDevice.Read.All" + }, + { + "description": "Allows the app to read and write all workplace devices, on behalf of the signed-in user.", + "displayName": "Read and write all workplace devices", + "id": "eafd6a71-e95a-4f8a-bb6e-fb84ab7fbd9e", + "origin": "Delegated (Microsoft Graph)", + "value": "PlaceDevice.ReadWrite.All" + }, + { + "description": "Allows the app to read your organization's policies on behalf of the signed-in user.", + "displayName": "Read your organization's policies", + "id": "572fea84-0151-49b2-9301-11cb16974376", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.All" + }, + { + "description": "Allows the app to read the authentication method policies, on behalf of the signed-in user. ", + "displayName": "Read authentication method policies", + "id": "a6ff13ac-1851-4993-8ca9-a671d70de2d5", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.AuthenticationMethod" + }, + { + "description": "Allows the app to read your organization's B2BManagement policies on behalf of the signed-in user.", + "displayName": "Read your organization's B2BManagement policies", + "id": "4b293250-121d-4cb4-acc7-5280438c18a6", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.B2BManagementPolicy" + }, + { + "description": "Allows the app to read your organization's conditional access policies on behalf of the signed-in user.", + "displayName": "Read your organization's conditional access policies", + "id": "633e0fce-8c58-4cfb-9495-12bbd5a24f7c", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.ConditionalAccess" + }, + { + "description": "Allows the app to read your organization's cross tenant access policies on behalf of the signed-in user.", + "displayName": "Read your organization's cross tenant access policies", + "id": "b337372a-8b4d-428d-9cd8-3d7363865736", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.CrossTenantAccess" + }, + { + "description": "Allows the app to read your organization's device configuration policies on behalf of the signed-in user. For example, device registration policy can limit initial provisioning controls using quota restrictions, additional authentication and authorization checks.", + "displayName": "Read your organization's device configuration policies", + "id": "3616a4b0-6746-49c4-a678-4c237599074d", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.DeviceConfiguration" + }, + { + "description": "Allows the app to read your organization’s identity protection policy on behalf of the signed-in user.", + "displayName": "Read your organization’s identity protection policy", + "id": "d146432f-b803-4ed4-8d42-ba74193a6ede", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.IdentityProtection" + }, + { + "description": "Allows the application to read the organization's recovery policy on behalf of the signed-in user.", + "displayName": "Read your organization's recovery policy", + "id": "61faa1e9-0931-4f9a-94ba-bc2e3505c685", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.Recovery" + }, + { + "description": "Allows the app to have the same access to mailboxes as the signed-in user via POP protocol.", + "displayName": "Read and write access to mailboxes via POP.", + "id": "d7b7f2d9-0f45-4ea1-9d42-e50810c06991", + "origin": "Delegated (Microsoft Graph)", + "value": "POP.AccessAsUser.All" + }, + { + "description": "Allows the app to read preauthorization grants for service principals on behalf of the signed-in user.", + "displayName": "Read all preauthorization grants", + "id": "9c98cbde-410c-4719-9058-166504f17863", + "origin": "Delegated (Microsoft Graph)", + "value": "PreAuthorizationGrant.Read.All" + }, + { + "description": "Allows the app to read presence information on behalf of the signed-in user. Presence information includes activity, availability, status note, calendar out-of-office message, timezone and location.", + "displayName": "Read user's presence information", + "id": "76bc735e-aecd-4a1d-8b4c-2b915deabb79", + "origin": "Delegated (Microsoft Graph)", + "value": "Presence.Read" + }, + { + "description": "Allows the app to read time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD built-in and custom administrative roles, on behalf of the signed-in user.", + "displayName": "Read privileged access to Azure AD", + "id": "b3a539c9-59cb-4ad5-825a-041ddbdc2bdb", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedAccess.Read.AzureAD" + }, + { + "description": "Allows the app to read time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups, on behalf of the signed-in user.", + "displayName": "Read privileged access to Azure AD groups", + "id": "d329c81c-20ad-4772-abf9-3f6fdb7e5988", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedAccess.Read.AzureADGroup" + }, + { + "description": "Allows the app to read time-based assignment and just-in-time elevation of Azure resources (like your subscriptions, resource groups, storage, compute) on behalf of the signed-in user.", + "displayName": "Read privileged access to Azure resources", + "id": "1d89d70c-dcac-4248-b214-903c457af83a", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedAccess.Read.AzureResources" + }, + { + "description": "Allows the app to request and manage just in time elevation (including scheduled elevation) of users to Azure AD built-in administrative roles, on behalf of signed-in users.", + "displayName": "Read and write privileged access to Azure AD", + "id": "3c3c74f5-cdaa-4a97-b7e0-4e788bfcfb37", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedAccess.ReadWrite.AzureAD" + }, + { + "description": "Allows the app to request and manage time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups, on behalf of the signed-in user.", + "displayName": "Read and write privileged access to Azure AD groups", + "id": "32531c59-1f32-461f-b8df-6f8a3b89f73b", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedAccess.ReadWrite.AzureADGroup" + }, + { + "description": "Allows the app to request and manage time-based assignment and just-in-time elevation of user privileges to manage Azure resources (like subscriptions, resource groups, storage, compute) on behalf of the signed-in users.", + "displayName": "Read and write privileged access to Azure resources", + "id": "a84a9652-ffd3-496e-a991-22ba5529156a", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedAccess.ReadWrite.AzureResources" + }, + { + "description": "Allows the app to read Privileged Access (PIM) custom extensions for your organization, without a signed-in user.", + "displayName": "Read Privileged Access (PIM) custom extensions", + "id": "bc04fe80-7e6a-4154-8b8f-d1e3465613bf", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedAccess-CustomExt.Read.All" + }, + { + "description": "Allows the app to read and write Privileged Access (PIM) custom extensions for your organization, without a signed-in user.", + "displayName": "Read and write Privileged Access (PIM) custom extensions", + "id": "157efa76-20fd-4db4-876e-90c049322467", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedAccess-CustomExt.ReadWrite.All" + }, + { + "description": "Allows the app to read time-based assignment schedules for access to Azure AD groups, on behalf of the signed-in user.", + "displayName": "Read assignment schedules for access to Azure AD groups", + "id": "02a32cc4-7ab5-4b58-879a-0586e0f7c495", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedAssignmentSchedule.Read.AzureADGroup" + }, + { + "description": "Allows the app to read time-based assignment schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", + "displayName": "Read assignment schedules for app permission grants and app role assignments", + "id": "d5767d44-e1c1-4fc7-8fb1-7daa58df022a", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedAssignmentSchedule.Read.EntraAppRole" + }, + { + "description": "Allows the app to read, create, and delete time-based assignment schedules for access to Azure AD groups, on behalf of the signed-in user.", + "displayName": "Read, create, and delete assignment schedules for access to Azure AD groups", + "id": "06dbc45d-6708-4ef0-a797-f797ee68bf4b", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedAssignmentSchedule.ReadWrite.AzureADGroup" + }, + { + "description": "Allows the app to read, create, and delete time-based assignment schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", + "displayName": "Read, create, and delete assignment schedules for app permission grants and app role assignments", + "id": "e07122a7-d275-4a27-a2f5-eb62349edae0", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedAssignmentSchedule.ReadWrite.EntraAppRole" + }, + { + "description": "Allows the app to delete time-based assignment schedules for access to Azure AD groups, on behalf of the signed-in user.", + "displayName": "Delete assignment schedules for access to Azure AD groups", + "id": "ca5fe595-68ff-4dfd-907d-4509501a0e49", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedAssignmentSchedule.Remove.AzureADGroup" + }, + { + "description": "Allows the app to read time-based eligibility schedules for access to Azure AD groups, on behalf of the signed-in user.", + "displayName": "Read eligibility schedules for access to Azure AD groups", + "id": "8f44f93d-ecef-46ae-a9bf-338508d44d6b", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedEligibilitySchedule.Read.AzureADGroup" + }, + { + "description": "Allows the app to read time-based eligibility schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", + "displayName": "Read eligibility schedules for app permission grants and app role assignments", + "id": "9b9eb231-5483-4f3c-89e9-9d5048dafe9d", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedEligibilitySchedule.Read.EntraAppRole" + }, + { + "description": "Allows the app to read, create, and delete time-based eligibility schedules for access to Azure AD groups, on behalf of the signed-in user.", + "displayName": "Read, create, and delete eligibility schedules for access to Azure AD groups", + "id": "ba974594-d163-484e-ba39-c330d5897667", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedEligibilitySchedule.ReadWrite.AzureADGroup" + }, + { + "description": "Allows the app to read, create, and delete time-based eligibility schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", + "displayName": "Read, create, and delete eligibility schedules for app permission grants and app role assignments", + "id": "f7ff1cb0-e255-4bb3-b24a-6708c60c5418", + "origin": "Delegated (Microsoft Graph)", + "value": "PrivilegedEligibilitySchedule.ReadWrite.EntraAppRole" + }, + { + "description": "Allows the application to read and write tenant-wide print settings on behalf of the signed-in user.", + "displayName": "Read and write tenant-wide print settings", + "id": "9ccc526a-c51c-4e5c-a1fd-74726ef50b8f", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintSettings.ReadWrite.All" + }, + { + "description": "Allows the application to read tenant-wide print settings on behalf of the signed-in user.", + "displayName": "Read tenant-wide print settings", + "id": "490f32fd-d90f-4dd7-a601-ff6cdc1a3f6c", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintSettings.Read.All" + }, + { + "description": "Allows the application to read and update the metadata of print jobs on behalf of the signed-in user. Does not allow access to print job document content.", + "displayName": "Read and write basic information of print jobs", + "id": "3a0db2f6-0d2a-4c19-971b-49109b19ad3d", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintJob.ReadWriteBasic.All" + }, + { + "description": "Allows the application to read and update the metadata of print jobs that the signed-in user created. Does not allow access to print job document content.", + "displayName": "Read and write basic information of user's print jobs", + "id": "6f2d22f2-1cb6-412c-a17c-3336817eaa82", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintJob.ReadWriteBasic" + }, + { + "description": "Allows the app to read presence information of all users in the directory on behalf of the signed-in user. Presence information includes activity, availability, status note, calendar out-of-office message, timezone and location.", + "displayName": "Read presence information of all users in your organization", + "id": "9c7a330d-35b3-4aa1-963d-cb2b9f927841", + "origin": "Delegated (Microsoft Graph)", + "value": "Presence.Read.All" + }, + { + "description": "Allows the app to read the presence information and write activity and availability on behalf of the signed-in user. Presence information includes activity, availability, status note, calendar out-of-office message, timezone and location.", + "displayName": "Read and write a user's presence information", + "id": "8d3c54a7-cf58-4773-bf81-c0cd6ad522bb", + "origin": "Delegated (Microsoft Graph)", + "value": "Presence.ReadWrite" + }, + { + "description": "Allows the application to read print connectors on behalf of the signed-in user.", + "displayName": "Read print connectors", + "id": "d69c2d6d-4f72-4f99-a6b9-663e32f8cf68", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintConnector.Read.All" + }, + { + "description": "Allows the application to read and write print connectors on behalf of the signed-in user.", + "displayName": "Read and write print connectors", + "id": "79ef9967-7d59-4213-9c64-4b10687637d8", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintConnector.ReadWrite.All" + }, + { + "description": "Allows the application to create (register) printers on behalf of the signed-in user. ", + "displayName": "Register printers ", + "id": "90c30bed-6fd1-4279-bf39-714069619721", + "origin": "Delegated (Microsoft Graph)", + "value": "Printer.Create" + }, + { + "description": "Allows the application to create (register), read, update, and delete (unregister) printers on behalf of the signed-in user. ", + "displayName": "Register, read, update, and unregister printers", + "id": "93dae4bd-43a1-4a23-9a1a-92957e1d9121", + "origin": "Delegated (Microsoft Graph)", + "value": "Printer.FullControl.All" + }, + { + "description": "Allows the application to read printers on behalf of the signed-in user. ", + "displayName": "Read printers", + "id": "3a736c8a-018e-460a-b60c-863b2683e8bf", + "origin": "Delegated (Microsoft Graph)", + "value": "Printer.Read.All" + }, + { + "description": "Allows the application to read and update printers on behalf of the signed-in user. Does not allow creating (registering) or deleting (unregistering) printers.", + "displayName": "Read and update printers", + "id": "89f66824-725f-4b8f-928e-e1c5258dc565", + "origin": "Delegated (Microsoft Graph)", + "value": "Printer.ReadWrite.All" + }, + { + "description": "Allows the app to read security alerts and update status of alerts of customer with CSP relationship on behalf of the partner signed-in user.", + "displayName": "Read security alerts and update status of security alerts of customer with CSP relationship", + "id": "0cd2c1f6-94a1-4075-ab8c-0b1aff2e1ad5", + "origin": "Delegated (Microsoft Graph)", + "value": "PartnerSecurity.ReadWrite.All" + }, + { + "description": "Allows the application to read printer shares on behalf of the signed-in user. ", + "displayName": "Read printer shares", + "id": "ed11134d-2f3f-440d-a2e1-411efada2502", + "origin": "Delegated (Microsoft Graph)", + "value": "PrinterShare.Read.All" + }, + { + "description": "Allows the application to read and update printer shares on behalf of the signed-in user. ", + "displayName": "Read and write printer shares", + "id": "06ceea37-85e2-40d7-bec3-91337a46038f", + "origin": "Delegated (Microsoft Graph)", + "value": "PrinterShare.ReadWrite.All" + }, + { + "description": "Allows the application to create print jobs on behalf of the signed-in user and upload document content to print jobs that the signed-in user created.", + "displayName": "Create print jobs", + "id": "21f0d9c0-9f13-48b3-94e0-b6b231c7d320", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintJob.Create" + }, + { + "description": "Allows the application to read the metadata and document content of print jobs that the signed-in user created.", + "displayName": "Read user's print jobs", + "id": "248f5528-65c0-4c88-8326-876c7236df5e", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintJob.Read" + }, + { + "description": "Allows the application to read the metadata and document content of print jobs on behalf of the signed-in user. ", + "displayName": "Read print jobs", + "id": "afdd6933-a0d8-40f7-bd1a-b5d778e8624b", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintJob.Read.All" + }, + { + "description": "Allows the application to read the metadata of print jobs that the signed-in user created. Does not allow access to print job document content.", + "displayName": "Read basic information of user's print jobs", + "id": "6a71a747-280f-4670-9ca0-a9cbf882b274", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintJob.ReadBasic" + }, + { + "description": "Allows the application to read the metadata of print jobs on behalf of the signed-in user. Does not allow access to print job document content.", + "displayName": "Read basic information of print jobs", + "id": "04ce8d60-72ce-4867-85cf-6d82f36922f3", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintJob.ReadBasic.All" + }, + { + "description": "Allows the application to read and update the metadata and document content of print jobs that the signed-in user created.", + "displayName": "Read and write user's print jobs", + "id": "b81dd597-8abb-4b3f-a07a-820b0316ed04", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintJob.ReadWrite" + }, + { + "description": "Allows the application to read and update the metadata and document content of print jobs on behalf of the signed-in user. ", + "displayName": "Read and write print jobs", + "id": "036b9544-e8c5-46ef-900a-0646cc42b271", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintJob.ReadWrite.All" + }, + { + "description": "Allows the application to read basic information about printer shares on behalf of the signed-in user. Does not allow reading access control information.", + "displayName": "Read basic information about printer shares", + "id": "5fa075e9-b951-4165-947b-c63396ff0a37", + "origin": "Delegated (Microsoft Graph)", + "value": "PrinterShare.ReadBasic.All" + }, + { + "description": "Allows the app to read identity lifecycle policies for agent identities that the signed-in user has access to in the organization.", + "displayName": "Read identity lifecycle policies for agent identities", + "id": "65857db0-62ac-4279-aa73-c2b5dab186f5", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecyclePolicies-AgentId.Read.All" + }, + { + "description": "Allows the app to read security alerts of customer with CSP relationship on behalf of the partner signed-in user.", + "displayName": "Read security alerts of customer with CSP relationship", + "id": "5567b981-0bf1-4796-9038-0648b46e116d", + "origin": "Delegated (Microsoft Graph)", + "value": "PartnerSecurity.Read.All" + }, + { + "description": "Allows the app to read and write organization-wide Microsoft To Do settings on behalf of the signed-in user.", + "displayName": "Read and write organization-wide Microsoft To Do settings", + "id": "087502c2-5263-433e-abe3-8f77231a0627", + "origin": "Delegated (Microsoft Graph)", + "value": "OrgSettings-Todo.ReadWrite.All" + }, + { + "description": "Allows the app to create, read, update, and delete email, including contents of non-draft emails in user mailboxes, on behalf of the signed-in user. Does not include permission to send mail.", + "displayName": "Read and write the user's mail, including modifying existing non-draft mails", + "id": "f3af82f6-18e0-4a41-8dc8-a03c11854a8d", + "origin": "Delegated (Microsoft Graph)", + "value": "Mail-Advanced.ReadWrite" + }, + { + "description": "Allows the app to create, read, update, and delete mail including contents of non-draft emails for all mails a user has permission to access, on behalf of the signed-in user. This includes their own and shared mail. Does not include permission to send mail.", + "displayName": "Read and write all mail the user can access, including modifying existing non-draft mails", + "id": "bebf0bb6-2ff3-4295-a17d-f3561da294fb", + "origin": "Delegated (Microsoft Graph)", + "value": "Mail-Advanced.ReadWrite.Shared" + }, + { + "description": "Allows the app to read user's UserConfiguration objects, on behalf of the the signed-in user.", + "displayName": "Read user's UserConfiguration objects", + "id": "dce2e6fc-0f4b-40da-94e2-14b4477f3d92", + "origin": "Delegated (Microsoft Graph)", + "value": "MailboxConfigItem.Read" + }, + { + "description": "Allows the app to create, read, update and delete user's UserConfiguration objects, on behalf of the the signed-in user.", + "displayName": "Read and write user's UserConfiguration objects", + "id": "7d461784-7715-4b09-9f90-91a6d8722652", + "origin": "Delegated (Microsoft Graph)", + "value": "MailboxConfigItem.ReadWrite" + }, + { + "description": "Allows the app to read the user's mailbox folders, on behalf of the signed-in user.", + "displayName": "Read a user's mailbox folders", + "id": "52dc2051-4958-4636-8f2a-281d39c6981c", + "origin": "Delegated (Microsoft Graph)", + "value": "MailboxFolder.Read" + }, + { + "description": "Allows the app to read and write the user's mailbox folders, on behalf of the signed-in user.", + "displayName": "Read and write a user's mailbox folders", + "id": "077fde41-7e0b-4c5b-bcd1-e9d743a30c80", + "origin": "Delegated (Microsoft Graph)", + "value": "MailboxFolder.ReadWrite" + }, + { + "description": "Allows the app to export the user's mailbox items, on behalf of the the signed-in user.", + "displayName": "Export a user's mailbox items", + "id": "58d3e7fa-3ce9-4a0c-9baa-0971f64709d9", + "origin": "Delegated (Microsoft Graph)", + "value": "MailboxItem.Export" + }, + { + "description": "Allows the app to export and import the user's mailbox items, on behalf of the the signed-in user.", + "displayName": "Export and import a user's mailbox items", + "id": "df96e8a0-f4e1-4ecf-8d83-a429f822cbd6", + "origin": "Delegated (Microsoft Graph)", + "value": "MailboxItem.ImportExport" + }, + { + "description": "Allows the app to read the user's mailbox items, on behalf of the signed-in user.", + "displayName": "Read a user's mailbox items", + "id": "82305458-296d-4edd-8b0b-74dd74c34526", + "origin": "Delegated (Microsoft Graph)", + "value": "MailboxItem.Read" + }, + { + "description": "Allows the app to read, write, and delete the user's mailbox items, on behalf of the signed-in user.", + "displayName": "Read and write your mailbox items", + "id": "ec1ade38-5268-4bc8-87fa-b230e42f7a88", + "origin": "Delegated (Microsoft Graph)", + "value": "MailboxItem.ReadWrite" + }, + { + "description": "Allows the app to the read user's mailbox settings. Does not include permission to send mail.", + "displayName": "Read user mailbox settings", + "id": "87f447af-9fa4-4c32-9dfa-4a57a73d18ce", + "origin": "Delegated (Microsoft Graph)", + "value": "MailboxSettings.Read" + }, + { + "description": "Allows the app to create, read, update, and delete user's mailbox settings. Does not include permission to send mail.", + "displayName": "Read and write user mailbox settings", + "id": "818c620a-27a9-40bd-a6a5-d96f7d610b4b", + "origin": "Delegated (Microsoft Graph)", + "value": "MailboxSettings.ReadWrite" + }, + { + "description": "Allows the app to read mail tips on behalf of the signed-in user for mailboxes they have access to. Mail tips include automatic replies, mailbox status, custom tips, and delivery information.", + "displayName": "Read mail tips for mailboxes you can access", + "id": "4776cae1-54bd-4dfd-823c-e5861ed49a98", + "origin": "Delegated (Microsoft Graph)", + "value": "MailTips.ReadBasic.Shared" + }, + { + "description": "Allows the app to read all managed tenant information on behalf of the signed-in user.", + "displayName": "Read all managed tenant information", + "id": "dc34164e-6c4a-41a0-be89-3ae2fbad7cd3", + "origin": "Delegated (Microsoft Graph)", + "value": "ManagedTenants.Read.All" + }, + { + "description": "Allows the app to read and write all managed tenant information on behalf of the signed-in user.", + "displayName": "Read and write all managed tenant information", + "id": "b31fa710-c9b3-4d9e-8f5e-8036eecddab9", + "origin": "Delegated (Microsoft Graph)", + "value": "ManagedTenants.ReadWrite.All" + }, + { + "description": "Allows the app to read the memberships of hidden groups and administrative units on behalf of the signed-in user, for those hidden groups and administrative units that the signed-in user has access to.", + "displayName": "Read hidden memberships", + "id": "f6a3db3e-f7e8-4ed2-a414-557c8c9830be", + "origin": "Delegated (Microsoft Graph)", + "value": "Member.Read.Hidden" + }, + { + "description": "Allows the app to read multi-tenant organization details and tenants on behalf of the signed-in user.", + "displayName": "Read multi-tenant organization details and tenants", + "id": "526aa72a-5878-49fe-bf4e-357973af9b06", + "origin": "Delegated (Microsoft Graph)", + "value": "MultiTenantOrganization.Read.All" + }, + { + "description": "Allows the app to send mail as the signed-in user, including sending on-behalf of others.", + "displayName": "Send mail on behalf of others", + "id": "a367ab51-6b49-43bf-a716-a1fb06d2a174", + "origin": "Delegated (Microsoft Graph)", + "value": "Mail.Send.Shared" + }, + { + "description": "Allows the app to read multi-tenant organization basic details and active tenants on behalf of the signed-in user.", + "displayName": "Read multi-tenant organization basic details and active tenants", + "id": "225db56b-15b2-4daa-acb3-0eec2bbe4849", + "origin": "Delegated (Microsoft Graph)", + "value": "MultiTenantOrganization.ReadBasic.All" + }, + { + "description": "Allows the app to send mail as users in the organization.", + "displayName": "Send mail as a user ", + "id": "e383f46e-2787-4529-855e-0e479a3ffac0", + "origin": "Delegated (Microsoft Graph)", + "value": "Mail.Send" + }, + { + "description": "Allows the app to create, read, update, and delete email in user mailboxes. Does not include permission to send mail.", + "displayName": "Read and write access to user mail ", + "id": "024d486e-b451-40bb-833d-3e66d98c5c73", + "origin": "Delegated (Microsoft Graph)", + "value": "Mail.ReadWrite" + }, + { + "description": "Allows the app to read identity lifecycle policies for external guests on behalf of the signed-in user.", + "displayName": "Read identity lifecycle policies for external guests", + "id": "1bbb7916-b98a-449f-8ee4-c68bfcba5724", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecyclePolicies-Guests.Read.All" + }, + { + "description": "Allows the app to create, update, and delete identity lifecycle policies for external guests on behalf of the signed-in user.", + "displayName": "Read and write identity lifecycle policies for external guests", + "id": "d9ec82ed-63db-4905-b1b3-859b74d2bbf5", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecyclePolicies-Guests.ReadWrite.All" + }, + { + "description": "Allows the app to list and read all workflows, tasks and related lifecycle workflows resources on behalf of the signed-in user.", + "displayName": "Read all lifecycle workflows resources", + "id": "9bcb9916-765a-42af-bf77-02282e26b01a", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecycleWorkflows.Read.All" + }, + { + "description": "Allows the app to create, update, list, read and delete all workflows, tasks and related lifecycle workflows resources on behalf of the signed-in user.", + "displayName": "Read and write all lifecycle workflows resources", + "id": "84b9d731-7db8-4454-8c90-fd9e95350179", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecycleWorkflows.ReadWrite.All" + }, + { + "description": "Allows the app to read all Lifecycle workflows custom task extensions on behalf of a signed-in user.", + "displayName": "Read all Lifecycle workflows custom task extensions", + "id": "2973a298-1d69-4f87-8d30-7025f0ec19d7", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecycleWorkflows-CustomExt.Read.All" + }, + { + "description": "Allows the app to create, update, list, read and delete all Lifecycle workflows custom task extensions on behalf of a signed-in user.", + "displayName": "Read and write all Lifecycle workflows custom task extensions", + "id": "ef6bafb1-3019-4a22-a332-103aff92225f", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecycleWorkflows-CustomExt.ReadWrite.All" + }, + { + "description": "Allows the app to read all Lifecycle workflows reports on behalf of a signed-in user.", + "displayName": "Read all Lifecycle workflows reports", + "id": "4d3d7f81-163f-426a-8432-5638d2e82083", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecycleWorkflows-Reports.Read.All" + }, + { + "description": "Allows the app to run workflows on-demand on behalf of a signed-in user.", + "displayName": "Run workflows on-demand in Lifecycle workflows", + "id": "df1c25b3-072c-45cd-8403-c63441e4cca1", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecycleWorkflows-Workflow.Activate" + }, + { + "description": "Allows the app to list and read all workflows and tasks on behalf of a signed-in user.", + "displayName": "Read all workflows in Lifecycle workflows", + "id": "7fabe5bd-2e47-4e61-b924-327117024e18", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecycleWorkflows-Workflow.Read.All" + }, + { + "description": "Allows the app to list all workflows on behalf of a signed-in user.", + "displayName": "List all workflows in Lifecycle workflows", + "id": "789c445d-433c-4575-a1fc-367a58a1bd4a", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecycleWorkflows-Workflow.ReadBasic.All" + }, + { + "description": "Allows the app to create, update, list, read and delete all workflows and tasks in lifecycle workflows on behalf of a signed-in user.", + "displayName": "Read and write all workflows in Lifecycle workflows", + "id": "29e49f0c-a053-4cc5-a4b1-7da0c8c1e643", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecycleWorkflows-Workflow.ReadWrite.All" + }, + { + "description": "Allow the application to access a subset of listitems on behalf of the signed in user. The specific listitems and the permissions granted will be configured in SharePoint Online.", + "displayName": "Access selected ListItems, on behalf of the signed-in user", + "id": "d6d361b3-211a-4191-9fa7-15f72de4aac4", + "origin": "Delegated (Microsoft Graph)", + "value": "ListItems.SelectedOperations.Selected" + }, + { + "description": "Allow the application to access a subset of lists on behalf of the signed in user. The specific lists and the permissions granted will be configured in SharePoint Online.", + "displayName": "Access selected Lists, on behalf of the signed-in user", + "id": "033b51ee-d6fa-4add-b627-ee680c7212b5", + "origin": "Delegated (Microsoft Graph)", + "value": "Lists.SelectedOperations.Selected" + }, + { + "description": "Allows the app to read the signed-in user's mailbox.", + "displayName": "Read user mail ", + "id": "570282fd-fa5c-430d-a7fd-fc8dc98a9dca", + "origin": "Delegated (Microsoft Graph)", + "value": "Mail.Read" + }, + { + "description": "Allows the app to read mail a user can access, including their own and shared mail.", + "displayName": "Read user and shared mail", + "id": "7b9103a5-4610-446b-9670-80643382c1fa", + "origin": "Delegated (Microsoft Graph)", + "value": "Mail.Read.Shared" + }, + { + "description": "Allows the app to read email in the signed-in user's mailbox except body, previewBody, attachments and any extended properties.", + "displayName": "Read user basic mail", + "id": "a4b8392a-d8d1-4954-a029-8e668a39a170", + "origin": "Delegated (Microsoft Graph)", + "value": "Mail.ReadBasic" + }, + { + "description": "Allows the app to read mail the signed-in user can access, including their own and shared mail, except for body, bodyPreview, uniqueBody, attachments, extensions, and any extended properties.", + "displayName": "Read user and shared basic mail", + "id": "b11fa0e7-fdb7-4dc9-b1f1-59facd463480", + "origin": "Delegated (Microsoft Graph)", + "value": "Mail.ReadBasic.Shared" + }, + { + "description": "Allows the app to create, read, update, and delete mail a user has permission to access, including their own and shared mail. Does not include permission to send mail.", + "displayName": "Read and write user and shared mail", + "id": "5df07973-7d5d-46ed-9847-1271055cbd51", + "origin": "Delegated (Microsoft Graph)", + "value": "Mail.ReadWrite.Shared" + }, + { + "description": "Allows the app to read and write multi-tenant organization details and tenants on behalf of the signed-in user.", + "displayName": "Read and write multi-tenant organization details and tenants", + "id": "77af1528-84f3-4023-8d90-d219cd433108", + "origin": "Delegated (Microsoft Graph)", + "value": "MultiTenantOrganization.ReadWrite.All" + }, + { + "description": "Allows the app to read configuration used for OAuth 2.0 mutual-TLS client authentication, on behalf of the signed-in user. This includes reading trusted certificate authorities.", + "displayName": "Read all configurations used for mutual-TLS client authentication.", + "id": "51ae584e-e736-4718-897b-10af70f8e3cc", + "origin": "Delegated (Microsoft Graph)", + "value": "MutualTlsOauthConfiguration.Read.All" + }, + { + "description": "Allows the app to read and update configuration used for OAuth 2.0 mutual-TLS client authentication, on behalf of the signed-in user. This includes adding and updating trusted certificate authorities.", + "displayName": "Read and write all configurations used for mutual-TLS client authentication.", + "id": "a51115bc-f64f-498f-bcee-00dcd28f4a03", + "origin": "Delegated (Microsoft Graph)", + "value": "MutualTlsOauthConfiguration.ReadWrite.All" + }, + { + "description": "Allows the app to read and write all on-premises directory synchronization information for the organization, on behalf of the signed-in user.", + "displayName": "Read and write all on-premises directory synchronization information", + "id": "c2d95988-7604-4ba1-aaed-38a5f82a51c7", + "origin": "Delegated (Microsoft Graph)", + "value": "OnPremDirectorySynchronization.ReadWrite.All" + }, + { + "description": "Allows the app to manage hybrid identity service configuration by creating, viewing, updating and deleting on-premises published resources, on-premises agents and agent groups, on behalf of the signed-in user.", + "displayName": "Manage on-premises published resources", + "id": "8c4d5184-71c2-4bf8-bb9d-bc3378c9ad42", + "origin": "Delegated (Microsoft Graph)", + "value": "OnPremisesPublishingProfiles.ReadWrite.All" + }, + { + "description": "Allows users to sign in to the app with their work or school accounts and allows the app to see basic user profile information.", + "displayName": "Sign users in", + "id": "37f7f235-527c-4136-accd-4a02d197296e", + "origin": "Delegated (Microsoft Graph)", + "value": "openid" + }, + { + "description": "Allows the app to read the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed skus and tenant branding information.", + "displayName": "Read organization information", + "id": "4908d5b9-3fb2-4b1e-9336-1888b7937185", + "origin": "Delegated (Microsoft Graph)", + "value": "Organization.Read.All" + }, + { + "description": "Allows the app to read and write the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed skus and tenant branding information.", + "displayName": "Read and write organization information", + "id": "46ca0847-7e6b-426e-9775-ea810a948356", + "origin": "Delegated (Microsoft Graph)", + "value": "Organization.ReadWrite.All" + }, + { + "description": "Allows the app to read the organizational branding information, on behalf of the signed-in user.", + "displayName": "Read organizational branding information", + "id": "9082f138-6f02-4f3a-9f4d-5f3c2ce5c688", + "origin": "Delegated (Microsoft Graph)", + "value": "OrganizationalBranding.Read.All" + }, + { + "description": "Allows the app to read and write the organizational branding information, on behalf of the signed-in user.", + "displayName": "Read and write organizational branding information", + "id": "15ce63de-b141-4c9a-a9a5-241bf27c6aaf", + "origin": "Delegated (Microsoft Graph)", + "value": "OrganizationalBranding.ReadWrite.All" + }, + { + "description": "Allows the app to read all organizational contacts on behalf of the signed-in user. These contacts are managed by the organization and are different from a user's personal contacts.", + "displayName": "Read organizational contacts", + "id": "08432d1b-5911-483c-86df-7980af5cdee0", + "origin": "Delegated (Microsoft Graph)", + "value": "OrgContact.Read.All" + }, + { + "description": "Allows the app to read organization-wide apps and services settings on behalf of the signed-in user.", + "displayName": "Read organization-wide apps and services settings", + "id": "1e9b7a7e-4d64-44ff-acf5-2e9651c1519f", + "origin": "Delegated (Microsoft Graph)", + "value": "OrgSettings-AppsAndServices.Read.All" + }, + { + "description": "Allows the app to read and write organization-wide apps and services settings on behalf of the signed-in user.", + "displayName": "Read and write organization-wide apps and services settings", + "id": "c167b0e7-47c0-48e8-9eee-9892f58018fa", + "origin": "Delegated (Microsoft Graph)", + "value": "OrgSettings-AppsAndServices.ReadWrite.All" + }, + { + "description": "Allows the app to read organization-wide Dynamics customer voice settings on behalf of the signed-in user.", + "displayName": "Read organization-wide Dynamics customer voice settings", + "id": "9862d930-5aec-4a98-8d4f-7277a8db9bcb", + "origin": "Delegated (Microsoft Graph)", + "value": "OrgSettings-DynamicsVoice.Read.All" + }, + { + "description": "Allows the app to read and write organization-wide Dynamics customer voice settings on behalf of the signed-in user.", + "displayName": "Read and write organization-wide Dynamics customer voice settings", + "id": "4cea26fb-6967-4234-82c4-c044414743f8", + "origin": "Delegated (Microsoft Graph)", + "value": "OrgSettings-DynamicsVoice.ReadWrite.All" + }, + { + "description": "Allows the app to read organization-wide Microsoft Forms settings on behalf of the signed-in user.", + "displayName": "Read organization-wide Microsoft Forms settings", + "id": "210051a0-1ffc-435c-ae76-02d226d05752", + "origin": "Delegated (Microsoft Graph)", + "value": "OrgSettings-Forms.Read.All" + }, + { + "description": "Allows the app to read and write organization-wide Microsoft Forms settings on behalf of the signed-in user.", + "displayName": "Read and write organization-wide Microsoft Forms settings", + "id": "346c19ff-3fb2-4e81-87a0-bac9e33990c1", + "origin": "Delegated (Microsoft Graph)", + "value": "OrgSettings-Forms.ReadWrite.All" + }, + { + "description": "Allows the app to read organization-wide Microsoft 365 apps installation settings on behalf of the signed-in user.", + "displayName": "Read organization-wide Microsoft 365 apps installation settings", + "id": "8cbdb9f6-9c2e-451a-814d-ec606e5d0212", + "origin": "Delegated (Microsoft Graph)", + "value": "OrgSettings-Microsoft365Install.Read.All" + }, + { + "description": "Allows the app to read and write organization-wide Microsoft 365 apps installation settings on behalf of the signed-in user.", + "displayName": "Read and write organization-wide Microsoft 365 apps installation settings", + "id": "1ff35e91-19eb-42d8-aa2d-cc9891127ae5", + "origin": "Delegated (Microsoft Graph)", + "value": "OrgSettings-Microsoft365Install.ReadWrite.All" + }, + { + "description": "Allows the app to read organization-wide Microsoft To Do settings on behalf of the signed-in user.", + "displayName": "Read organization-wide Microsoft To Do settings", + "id": "7ff96f41-f022-45ba-acd8-ef3f03063d6b", + "origin": "Delegated (Microsoft Graph)", + "value": "OrgSettings-Todo.Read.All" + }, + { + "description": "Allows the app to read all on-premises directory synchronization information for the organization, on behalf of the signed-in user.", + "displayName": "Read all on-premises directory synchronization information", + "id": "f6609722-4100-44eb-b747-e6ca0536989d", + "origin": "Delegated (Microsoft Graph)", + "value": "OnPremDirectorySynchronization.Read.All" + }, + { + "description": "Allows the app to read all transcripts of online meetings, on behalf of the signed-in user.", + "displayName": "Read all transcripts of online meetings.", + "id": "30b87d18-ebb1-45db-97f8-82ccb1f0190c", + "origin": "Delegated (Microsoft Graph)", + "value": "OnlineMeetingTranscript.Read.All" + }, + { + "description": "Allows the app to read and create online meetings on behalf of the signed-in user.", + "displayName": "Read and create user's online meetings", + "id": "a65f2972-a4f8-4f5e-afd7-69ccb046d5dc", + "origin": "Delegated (Microsoft Graph)", + "value": "OnlineMeetings.ReadWrite" + }, + { + "description": "Allows the app to read online meeting details on behalf of the signed-in user.", + "displayName": "Read user's online meetings", + "id": "9be106e1-f4e3-4df5-bdff-e4bc531cbe43", + "origin": "Delegated (Microsoft Graph)", + "value": "OnlineMeetings.Read" + }, + { + "description": "Allows the app to read all network access information on behalf of the signed-in user.", + "displayName": "Read all network access information", + "id": "2f7013e0-ab4e-447f-a5e1-5d419950692d", + "origin": "Delegated (Microsoft Graph)", + "value": "NetworkAccess.Read.All" + }, + { + "description": "Allows the app to read and write all network access information and configuration settings on behalf of the signed-in user.", + "displayName": "Read and write all network access information", + "id": "ae2df9c5-f18d-4ec4-a51b-bdeb807f177b", + "origin": "Delegated (Microsoft Graph)", + "value": "NetworkAccess.ReadWrite.All" + }, + { + "description": "Allows the app to read your organization's branches for network access on behalf of the signed-in user.", + "displayName": "Read properties of branches for network access", + "id": "4051c7fc-b429-4804-8d80-8f1f8c24a6f7", + "origin": "Delegated (Microsoft Graph)", + "value": "NetworkAccessBranch.Read.All" + }, + { + "description": "Allows the app to read and write your organization's branches for network access on behalf of the signed-in user.", + "displayName": "Read and write properties of branches for network access", + "id": "b8a36cc2-b810-461a-baa4-a7281e50bd5c", + "origin": "Delegated (Microsoft Graph)", + "value": "NetworkAccessBranch.ReadWrite.All" + }, + { + "description": "Allows the app to read your organization's security and routing network access policies on behalf of the signed-in user.", + "displayName": "Read security and routing policies for network access", + "id": "ba22922b-752c-446f-89d7-a2d92398fceb", + "origin": "Delegated (Microsoft Graph)", + "value": "NetworkAccessPolicy.Read.All" + }, + { + "description": "Allows the app to read and write your organization's security and routing network access policies on behalf of the signed-in user.", + "displayName": "Read and write security and routing policies for network access", + "id": "b1fbad0f-ef6e-42ed-8676-bca7fa3e7291", + "origin": "Delegated (Microsoft Graph)", + "value": "NetworkAccessPolicy.ReadWrite.All" + }, + { + "description": "Allows the app to read all network access reports on behalf of the signed-in user.", + "displayName": "Read all network access reports", + "id": "b0c61509-cfc3-42bd-9bd4-66d81785fee4", + "origin": "Delegated (Microsoft Graph)", + "value": "NetworkAccess-Reports.Read.All" + }, + { + "description": "Allows the app to read the titles of OneNote notebooks and sections and to create new pages, notebooks, and sections on behalf of the signed-in user.", + "displayName": "Create user OneNote notebooks", + "id": "9d822255-d64d-4b7a-afdb-833b9a97ed02", + "origin": "Delegated (Microsoft Graph)", + "value": "Notes.Create" + }, + { + "description": "Allows the app to read all of billing data from Microsoft for your company's tenant, on behalf of the signed-in user. This includes reading billed and unbilled Usage and Invoice reconciliation data.", + "displayName": "Read all billing data for your company's tenant", + "id": "8804798e-5934-4e30-8ce3-ef88257cecd4", + "origin": "Delegated (Microsoft Graph)", + "value": "PartnerBilling.Read.All" + }, + { + "description": "Allows the app to read OneNote notebooks on behalf of the signed-in user.", + "displayName": "Read user OneNote notebooks", + "id": "371361e4-b9e2-4a3f-8315-2a301a3b0a3d", + "origin": "Delegated (Microsoft Graph)", + "value": "Notes.Read" + }, + { + "description": "Allows the app to read, share, and modify OneNote notebooks on behalf of the signed-in user.", + "displayName": "Read and write user OneNote notebooks", + "id": "615e26af-c38a-4150-ae3e-c3b0d4cb1d6a", + "origin": "Delegated (Microsoft Graph)", + "value": "Notes.ReadWrite" + }, + { + "description": "Allows the app to read, share, and modify OneNote notebooks that the signed-in user has access to in the organization.", + "displayName": "Read and write all OneNote notebooks that user can access", + "id": "64ac0503-b4fa-45d9-b544-71a463f05da0", + "origin": "Delegated (Microsoft Graph)", + "value": "Notes.ReadWrite.All" + }, + { + "description": "This is deprecated! Do not use! This permission no longer has any effect. You can safely consent to it. No additional privileges will be granted to the app.", + "displayName": "Limited notebook access (deprecated)", + "id": "ed68249d-017c-4df5-9113-e684c7f8760b", + "origin": "Delegated (Microsoft Graph)", + "value": "Notes.ReadWrite.CreatedByApp" + }, + { + "description": "Allows the app to deliver its notifications on behalf of signed-in users. Also allows the app to read, update, and delete the user's notification items for this app.", + "displayName": "Deliver and manage user notifications for this app", + "id": "89497502-6e42-46a2-8cb2-427fd3df970a", + "origin": "Delegated (Microsoft Graph)", + "value": "Notifications.ReadWrite.CreatedByApp" + }, + { + "description": "Allows the app to see and update the data you gave it access to, even when users are not currently using the app. This does not give the app any additional permissions.", + "displayName": "Maintain access to data you have given it access to", + "id": "7427e0e9-2fba-42fe-b0c0-848c9e6a8182", + "origin": "Delegated (Microsoft Graph)", + "value": "offline_access" + }, + { + "description": "Allows the app to read all AI Insights for online meetings, on behalf of the signed-in user.", + "displayName": "Read all AI Insights for online meetings.", + "id": "166741d6-eeb8-46fe-91f4-817d2af7bc88", + "origin": "Delegated (Microsoft Graph)", + "value": "OnlineMeetingAiInsight.Read.All" + }, + { + "description": "Allows the app to read online meeting artifacts on behalf of the signed-in user.", + "displayName": "Read user's online meeting artifacts", + "id": "110e5abb-a10c-4b59-8b55-9b4daa4ef743", + "origin": "Delegated (Microsoft Graph)", + "value": "OnlineMeetingArtifact.Read.All" + }, + { + "description": "Allows the app to read all recordings of online meetings, on behalf of the signed-in user.", + "displayName": "Read all recordings of online meetings.", + "id": "190c2bb6-1fdd-4fec-9aa2-7d571b5e1fe3", + "origin": "Delegated (Microsoft Graph)", + "value": "OnlineMeetingRecording.Read.All" + }, + { + "description": "Allows the app to read OneNote notebooks that the signed-in user has access to in the organization.", + "displayName": "Read all OneNote notebooks that user can access", + "id": "dfabfca6-ee36-4db2-8208-7a28381419b3", + "origin": "Delegated (Microsoft Graph)", + "value": "Notes.Read.All" + }, + { + "description": "Allows the app to uninstall Microsoft Entra Connect Sync Agent and offboard SSPR for the tenant", + "displayName": "Read, write and manage Microsoft Entra Connect Sync Agent", + "id": "69201c67-737b-4a20-8f16-e0c8c64e0b0e", + "origin": "Application (Microsoft password reset service)", + "value": "PasswordWriteback.OffboardClient.All" + }, + { + "description": "Allows the app to refresh and recreate on-premises configuration for Microsoft self-service password reset.", + "displayName": "Read, write and manage self-service password reset writeback configuration", + "id": "fc7e8088-95b5-453e-8bef-b17ecfec5ba3", + "origin": "Application (Microsoft password reset service)", + "value": "PasswordWriteback.RefreshClient.All" + }, + { + "description": "Allows the app to register a newer version of on-premises Microsoft Entra Connect Sync Agent.", + "displayName": "Read, write and manage Microsoft Entra Connect Sync Agent", + "id": "e006e431-a65b-4f3e-8808-77d29d4c5f1a", + "origin": "Application (Microsoft password reset service)", + "value": "PasswordWriteback.RegisterClientVersion.All" + }, + { + "description": " ", + "displayName": "PaginatedReport.Execute (retired)", + "id": "4aaafe5b-1b27-4403-88f2-e3ebbb8bccc5", + "origin": "Delegated (Power BI Service)", + "value": "PaginatedReport.Execute.All" + }, + { + "description": "Allows reading paginated reports on the user’s behalf.", + "displayName": "Read paginated reports", + "id": "e93694df-fa72-4011-aad8-f3648588c762", + "origin": "Delegated (Power BI Service)", + "value": "PaginatedReport.Read.All" + }, + { + "description": "Allows modifying paginated reports on the user’s behalf.", + "displayName": "Read and write paginated reports", + "id": "a405c0f7-5d2f-4e19-8db7-7323bae0b3c3", + "origin": "Delegated (Power BI Service)", + "value": "PaginatedReport.ReadWrite.All" + }, + { + "description": " ", + "displayName": "PaginatedReport.Reshare (retired)", + "id": "b510092a-d399-45f3-b1d5-4e2d34c87997", + "origin": "Delegated (Power BI Service)", + "value": "PaginatedReport.Reshare.All" + }, + { + "description": "The app can deploy content in all pipelines and pipeline stages in deployment pipelines, which the signed in user has access to.", + "displayName": "Deploy in all pipelines", + "id": "652d7d02-6ff0-4cf7-9516-cf77d33a3ae4", + "origin": "Delegated (Power BI Service)", + "value": "Pipeline.Deploy" + }, + { + "description": "The app can view all deployment pipelines that the signed in user has access to.", + "displayName": "View all pipelines", + "id": "dbe6434c-63f0-42bb-be8e-122ec1bad4d2", + "origin": "Delegated (Power BI Service)", + "value": "Pipeline.Read.All" + }, + { + "description": "The app can view and edit all deployment pipelines that the signed in user has access to.", + "displayName": "Read and write all pipelines", + "id": "199f155b-cccd-4be4-bbe6-ca9a867b24b4", + "origin": "Delegated (Power BI Service)", + "value": "Pipeline.ReadWrite.All" + }, + { + "description": "Allows the app to read basic properties of Entra ID identities in your organization that are known to Microsoft Fabric, on behalf of the signed-in user. This includes display names and email addresses of users, service principals and security groups.", + "displayName": "Read Entra ID identities basic properties", + "id": "8eb59948-47ce-4224-8cb1-f2a1ddb35822", + "origin": "Delegated (Power BI Service)", + "value": "PrincipalDetails.ReadBasic.All" + }, + { + "description": " ", + "displayName": "Reflex.Execute (retired)", + "id": "784ff746-e33b-4449-ba4e-081158296c6c", + "origin": "Delegated (Power BI Service)", + "value": "Reflex.Execute.All" + }, + { + "description": "Allows reading Reflexes on the user’s behalf.", + "displayName": "Read Reflexes", + "id": "781c41ac-e316-4a17-b470-cafd75f5c010", + "origin": "Delegated (Power BI Service)", + "value": "Reflex.Read.All" + }, + { + "description": "Allows modifying Reflexes on the user’s behalf.", + "displayName": "Read and write Reflexes", + "id": "99cac2a4-5c59-45dc-83bd-5303fda5d49d", + "origin": "Delegated (Power BI Service)", + "value": "Reflex.ReadWrite.All" + }, + { + "description": " ", + "displayName": "Reflex.Reshare (retired)", + "id": "004969fb-6ad0-4ca6-aa15-246f2bc7ba3c", + "origin": "Delegated (Power BI Service)", + "value": "Reflex.Reshare.All" + }, + { + "description": " ", + "displayName": "Report.Execute (retired)", + "id": "b0a64161-0e6a-4f7c-aa14-a1f9413136f3", + "origin": "Delegated (Power BI Service)", + "value": "Report.Execute.All" + }, + { + "description": "Allows reading reports on the user’s behalf.", + "displayName": "Read reports", + "id": "4ae1bf56-f562-4747-b7bc-2fa0874ed46f", + "origin": "Delegated (Power BI Service)", + "value": "Report.Read.All" + }, + { + "description": "Allows modifying reports on the user’s behalf.", + "displayName": "Read and write reports", + "id": "7504609f-c495-4c64-8542-686125a5a36f", + "origin": "Delegated (Power BI Service)", + "value": "Report.ReadWrite.All" + }, + { + "description": " ", + "displayName": "Report.Reshare (retired)", + "id": "54f4913d-63d6-4256-a270-f16a6222e625", + "origin": "Delegated (Power BI Service)", + "value": "Report.Reshare.All" + }, + { + "description": " ", + "displayName": "RetailDataManager.Execute (retired)", + "id": "5793b2af-bc3b-4f1d-bbb1-9a3e359dd8e1", + "origin": "Delegated (Power BI Service)", + "value": "RetailDataManager.Execute.All" + }, + { + "description": " ", + "displayName": "OrgApp.Reshare (retired)", + "id": "02d9fa8b-e936-407b-a8f2-9b8fa5bda3bc", + "origin": "Delegated (Power BI Service)", + "value": "OrgApp.Reshare.All" + }, + { + "description": "Allows reading retail data manager items on the user’s behalf.", + "displayName": "Read retail data manager items", + "id": "1ddcbaa9-c4cf-4684-9048-e04a12739a8c", + "origin": "Delegated (Power BI Service)", + "value": "RetailDataManager.Read.All" + }, + { + "description": "Allows modifying org apps on the user’s behalf.", + "displayName": "Read and write org apps", + "id": "38536678-0d9f-4f82-88e5-a13a78d1d209", + "origin": "Delegated (Power BI Service)", + "value": "OrgApp.ReadWrite.All" + }, + { + "description": "Allows the app to make API calls that read and write OneLake metadata, on your behalf.", + "displayName": "Make API calls that read and write OneLake metadata", + "id": "ada1b44b-4474-40ed-b32c-e3543dccec0e", + "origin": "Delegated (Power BI Service)", + "value": "OneLake.ReadWrite.All" + }, + { + "description": "Allows executing ML experiments on the user’s behalf.", + "displayName": "Execute ML experiments", + "id": "3101f5b2-b314-4bbd-a1f6-8a05f94f33ea", + "origin": "Delegated (Power BI Service)", + "value": "MLExperiment.Execute.All" + }, + { + "description": "Allows reading ML experiments on the user’s behalf.", + "displayName": "Read ML experiments", + "id": "179809f0-8b05-4f65-bdd0-920fb4945c33", + "origin": "Delegated (Power BI Service)", + "value": "MLExperiment.Read.All" + }, + { + "description": "Allows modifying ML experiments on the user’s behalf.", + "displayName": "Read and write ML experiments", + "id": "e4f65fe4-b466-4254-89ea-2fcdc8d8ac49", + "origin": "Delegated (Power BI Service)", + "value": "MLExperiment.ReadWrite.All" + }, + { + "description": " ", + "displayName": "MLExperiment.Reshare (retired)", + "id": "27296d33-1a83-44d6-9665-63f4902781f9", + "origin": "Delegated (Power BI Service)", + "value": "MLExperiment.Reshare.All" + }, + { + "description": "Allows executing ML models on the user’s behalf.", + "displayName": "Execute ML models", + "id": "6b03f425-0a8e-4c54-ba35-df73806f1396", + "origin": "Delegated (Power BI Service)", + "value": "MLModel.Execute.All" + }, + { + "description": "Allows reading ML models on the user’s behalf.", + "displayName": "Read ML models", + "id": "5d9a285a-0847-4aa7-a9db-4991dedc2b53", + "origin": "Delegated (Power BI Service)", + "value": "MLModel.Read.All" + }, + { + "description": "Allows modifying ML models on the user’s behalf.", + "displayName": "Read and write ML models", + "id": "2cb667b2-c449-4f2d-a1ad-e0ffa27b5d75", + "origin": "Delegated (Power BI Service)", + "value": "MLModel.ReadWrite.All" + }, + { + "description": "Allows resharing ML models on the user’s behalf.", + "displayName": "Reshare ML models", + "id": "5a93e9d0-4312-4fad-bbb5-44c74a75083a", + "origin": "Delegated (Power BI Service)", + "value": "MLModel.Reshare.All" + }, + { + "description": " ", + "displayName": "MountedDataFactory.Execute (retired)", + "id": "aeae5f51-8e10-4970-97f6-8bc2664df3a1", + "origin": "Delegated (Power BI Service)", + "value": "MountedDataFactory.Execute.All" + }, + { + "description": "Allows reading Azure Data Factories on the user’s behalf.", + "displayName": "Read Azure Data Factories", + "id": "7aaf3c81-a937-4309-a1bc-812e1102a837", + "origin": "Delegated (Power BI Service)", + "value": "MountedDataFactory.Read.All" + }, + { + "description": "Allows modifying Azure Data Factories on the user’s behalf.", + "displayName": "Read and write Azure Data Factories", + "id": "63ec6016-8d37-4b46-bee2-39ad0ded84d6", + "origin": "Delegated (Power BI Service)", + "value": "MountedDataFactory.ReadWrite.All" + }, + { + "description": " ", + "displayName": "MountedDataFactory.Reshare (retired)", + "id": "da46e639-2366-4e0a-a190-3fb3aac31e45", + "origin": "Delegated (Power BI Service)", + "value": "MountedDataFactory.Reshare.All" + }, + { + "description": "Allows executing notebooks on the user’s behalf.", + "displayName": "Execute notebooks", + "id": "3e801746-e22a-4fcb-a3f5-315ace8e165a", + "origin": "Delegated (Power BI Service)", + "value": "Notebook.Execute.All" + }, + { + "description": "Allows reading notebooks on the user’s behalf.", + "displayName": "Read notebooks", + "id": "0a25ca24-b130-4a32-affd-29d640b63f14", + "origin": "Delegated (Power BI Service)", + "value": "Notebook.Read.All" + }, + { + "description": "Allows modifying notebooks on the user’s behalf.", + "displayName": "Read and write notebooks", + "id": "b02aa3b5-6fb3-48b8-803a-57bdef45d20c", + "origin": "Delegated (Power BI Service)", + "value": "Notebook.ReadWrite.All" + }, + { + "description": " ", + "displayName": "Notebook.Reshare (retired)", + "id": "9ff20ed3-e70b-486e-9686-006be349a5d6", + "origin": "Delegated (Power BI Service)", + "value": "Notebook.Reshare.All" + }, + { + "description": "Allows the app to make API calls that read OneLake metadata on your behalf.", + "displayName": "Make API calls that read OneLake metadata", + "id": "547211ef-7223-404f-8519-fee52fda6402", + "origin": "Delegated (Power BI Service)", + "value": "OneLake.Read.All" + }, + { + "description": "Allows reading org apps on the user’s behalf.", + "displayName": "Read org apps", + "id": "d27d5544-b17d-471f-9a02-ef09d6720508", + "origin": "Delegated (Power BI Service)", + "value": "OrgApp.Read.All" + }, + { + "description": "Allows modifying retail data manager items on the user’s behalf.", + "displayName": "Read and write retail data manager items", + "id": "e87305de-874c-4fb9-a7c1-fff664dc5d6e", + "origin": "Delegated (Power BI Service)", + "value": "RetailDataManager.ReadWrite.All" + }, + { + "description": " ", + "displayName": "RetailDataManager.Reshare (retired)", + "id": "d95f0afe-0ace-431b-9741-b29d7a02e19b", + "origin": "Delegated (Power BI Service)", + "value": "RetailDataManager.Reshare.All" + }, + { + "description": " ", + "displayName": "Scorecard.Execute (retired)", + "id": "dc75a12a-fef2-436d-8311-fed5b7e3a9d0", + "origin": "Delegated (Power BI Service)", + "value": "Scorecard.Execute.All" + }, + { + "description": "The app can view and edit all storage accounts registered with Power BI that the signed in user is an admin of.", + "displayName": "Read and write all storage accounts", + "id": "27789c5b-aca8-4cb6-94b8-bcc8964dd8ad", + "origin": "Delegated (Power BI Service)", + "value": "StorageAccount.ReadWrite.All" + }, + { + "description": "The app can view all content in the tenant if the signed in user is in the Global administrator or Power BI service administrator role.", + "displayName": "View all content in tenant", + "id": "01944dba-21df-426f-bb8c-796488be96ad", + "origin": "Delegated (Power BI Service)", + "value": "Tenant.Read.All" + }, + { + "description": "The app can create, edit, view, and delete all content in the tenant if the signed in user is in the Global administrator or Power BI service administrator role.", + "displayName": "Read and write all content in tenant", + "id": "d594897b-76e7-4b2b-984b-b4adff35e109", + "origin": "Delegated (Power BI Service)", + "value": "Tenant.ReadWrite.All" + }, + { + "description": "Allows executing user data function items on the user’s behalf.", + "displayName": "Execute user data function items", + "id": "2a34e79d-bc8c-40b7-8053-22549c4f8a8d", + "origin": "Delegated (Power BI Service)", + "value": "UserDataFunction.Execute.All" + }, + { + "description": "Allows reading user data function items on the user’s behalf.", + "displayName": "Read user data function items", + "id": "64f9ad72-16e9-49c9-b691-1cb7545560c3", + "origin": "Delegated (Power BI Service)", + "value": "UserDataFunction.Read.All" + }, + { + "description": "Allows modifying user data function items on the user’s behalf.", + "displayName": "Read and write user data function items", + "id": "9a69fd02-6f0f-4945-bd56-33a4a01f887d", + "origin": "Delegated (Power BI Service)", + "value": "UserDataFunction.ReadWrite.All" + }, + { + "description": "The app can view and edit any user settings and the user-specific state associated with content the signed in user has access to.", + "displayName": "Read and write user settings and state", + "id": "b43e1ada-25ee-416f-bd5c-512976ddc74b", + "origin": "Delegated (Power BI Service)", + "value": "UserState.ReadWrite.All" + }, + { + "description": "Allows executing variable libraries on the user’s behalf.", + "displayName": "Execute variable libraries", + "id": "2c1729df-8c12-449b-ae71-2e4acea26919", + "origin": "Delegated (Power BI Service)", + "value": "VariableLibrary.Execute.All" + }, + { + "description": "Allows reading variable libraries on the user’s behalf.", + "displayName": "Read variable libraries", + "id": "ea662897-fca3-4698-84f4-6acc2fb3a7ea", + "origin": "Delegated (Power BI Service)", + "value": "VariableLibrary.Read.All" + }, + { + "description": "Allows modifying variable libraries on the user’s behalf.", + "displayName": "Read and write variable libraries", + "id": "43e2cb94-fe45-449d-aa4d-b1f473b98c53", + "origin": "Delegated (Power BI Service)", + "value": "VariableLibrary.ReadWrite.All" + }, + { + "description": " ", + "displayName": "VariableLibrary.Reshare (retired)", + "id": "79649b78-0856-46fa-902e-b634299dbc3c", + "origin": "Delegated (Power BI Service)", + "value": "VariableLibrary.Reshare.All" + }, + { + "description": "Allows executing warehouses on the user’s behalf.", + "displayName": "Execute warehouses", + "id": "d17eaf78-91ce-4314-9101-868b933996fb", + "origin": "Delegated (Power BI Service)", + "value": "Warehouse.Execute.All" + }, + { + "description": "Allows the app to create and manage external data shares for all warehouses, on behalf of the signed-in user.", + "displayName": "Allows the app to create and manage external data shares for all warehouses", + "id": "b102c99e-b723-4ac3-beb8-8813448ccfa7", + "origin": "Delegated (Power BI Service)", + "value": "Warehouse.ExternalDataShare.All" + }, + { + "description": "Allows reading warehouses on the user’s behalf.", + "displayName": "Read warehouses", + "id": "6f4dd5b6-1369-4aef-a71b-8a734a9e0a20", + "origin": "Delegated (Power BI Service)", + "value": "Warehouse.Read.All" + }, + { + "description": "Allows modifying warehouses on the user’s behalf.", + "displayName": "Read and write warehouses", + "id": "35735863-502b-4a11-8f65-b0bbe7ec8e95", + "origin": "Delegated (Power BI Service)", + "value": "Warehouse.ReadWrite.All" + }, + { + "description": " ", + "displayName": "Warehouse.Reshare (retired)", + "id": "d7629fc2-75c0-412f-9c11-052513f055ae", + "origin": "Delegated (Power BI Service)", + "value": "Warehouse.Reshare.All" + }, + { + "description": "Allows the app to make API calls that require restore permissions on all Warehouses, on behalf of the signed-in user.", + "displayName": "Make API calls that require restore permissions on all Warehouses", + "id": "7da32ee4-ec68-43a4-b13a-b5385ad9770e", + "origin": "Delegated (Power BI Service)", + "value": "Warehouse.Restore.All" + }, + { + "description": "The app can view all storage accounts registered with Power BI that the signed in user is an admin of.", + "displayName": "View all storage accounts", + "id": "e677843f-76d8-44d3-bcdb-ec40dea919e7", + "origin": "Delegated (Power BI Service)", + "value": "StorageAccount.Read.All" + }, + { + "description": " ", + "displayName": "SQLEndpoint.Reshare (retired)", + "id": "15a808d7-2065-4357-8b76-47f701df3575", + "origin": "Delegated (Power BI Service)", + "value": "SQLEndpoint.Reshare.All" + }, + { + "description": "Allows modifying SQL endpoints on the user’s behalf.", + "displayName": "Read and write SQL endpoints", + "id": "e5c15c39-f5e8-45b2-b858-edba09abc583", + "origin": "Delegated (Power BI Service)", + "value": "SQLEndpoint.ReadWrite.All" + }, + { + "description": "Allows reading SQL endpoints on the user’s behalf.", + "displayName": "Read SQL endpoints", + "id": "dbc7f8f6-3822-41e6-aebd-5a79e2ddc72a", + "origin": "Delegated (Power BI Service)", + "value": "SQLEndpoint.Read.All" + }, + { + "description": "Allows the app to make API calls that require read permissions on all scorecards, on behalf of the signed-in user.", + "displayName": "Make API calls that require read permissions on all scorecards", + "id": "a74298d9-12f6-45f5-808d-7907af21179c", + "origin": "Delegated (Power BI Service)", + "value": "Scorecard.Read.All" + }, + { + "description": " ", + "displayName": "Scorecard.ReadWrite (retired)", + "id": "b13a1be2-e407-47b5-8429-12f4ad4f9fcd", + "origin": "Delegated (Power BI Service)", + "value": "Scorecard.ReadWrite.All" + }, + { + "description": " ", + "displayName": "Scorecard.Reshare (retired)", + "id": "62816fca-afaa-44af-abd6-9e8f604d8dbb", + "origin": "Delegated (Power BI Service)", + "value": "Scorecard.Reshare.All" + }, + { + "description": " ", + "displayName": "SemanticModel.Execute (retired)", + "id": "42b94671-298c-48a0-a55d-077e48186883", + "origin": "Delegated (Power BI Service)", + "value": "SemanticModel.Execute.All" + }, + { + "description": "Allows the app to create and manage external data shares for all semantic models, on behalf of the signed-in user.", + "displayName": "Allows the app to create and manage external data shares for all semantic models", + "id": "5cf1e703-06da-4688-8f2a-29e77c25489a", + "origin": "Delegated (Power BI Service)", + "value": "SemanticModel.ExternalDataShare.All" + }, + { + "description": "Allows reading semantic models on the user’s behalf.", + "displayName": "Read semantic models", + "id": "d2090f0b-c876-45ea-b6fa-785e7ef84788", + "origin": "Delegated (Power BI Service)", + "value": "SemanticModel.Read.All" + }, + { + "description": "Allows modifying semantic models on the user’s behalf.", + "displayName": "Read and write semantic models", + "id": "9e7c970c-1dc5-482d-b2a1-2a4fed211921", + "origin": "Delegated (Power BI Service)", + "value": "SemanticModel.ReadWrite.All" + }, + { + "description": " ", + "displayName": "SemanticModel.Reshare (retired)", + "id": "868c9b47-9e35-4c69-bac3-042213ef72a3", + "origin": "Delegated (Power BI Service)", + "value": "SemanticModel.Reshare.All" + }, + { + "description": " ", + "displayName": "MirroredDatabase.Reshare (retired)", + "id": "c18991d0-0a42-4567-983a-1993bc79f327", + "origin": "Delegated (Power BI Service)", + "value": "MirroredDatabase.Reshare.All" + }, + { + "description": "Allows executing spark job definitions on the user’s behalf.", + "displayName": "Execute spark job definitions", + "id": "3492d2fc-251d-4a2b-8be4-97f06fd6d0d4", + "origin": "Delegated (Power BI Service)", + "value": "SparkJobDefinition.Execute.All" + }, + { + "description": "Allows modifying spark job definitions on the user’s behalf.", + "displayName": "Read and write spark job definitions", + "id": "ec20a3e3-8c0b-4d75-8d1b-a9ffdbbe2519", + "origin": "Delegated (Power BI Service)", + "value": "SparkJobDefinition.ReadWrite.All" + }, + { + "description": " ", + "displayName": "SparkJobDefinition.Reshare (retired)", + "id": "49dd4a50-f26f-4cc8-b895-227eb620861d", + "origin": "Delegated (Power BI Service)", + "value": "SparkJobDefinition.Reshare.All" + }, + { + "description": " ", + "displayName": "SQLDatabase.Execute (retired)", + "id": "f87561dd-6f31-48ab-bcca-d3cec4564562", + "origin": "Delegated (Power BI Service)", + "value": "SQLDatabase.Execute.All" + }, + { + "description": "Allows the app to create and manage external data shares for all SQL Databases, on behalf of the signed-in user.", + "displayName": "Allows the app to create and manage external data shares for all SQL Databases", + "id": "e90f72dc-f418-4844-82db-ea22d405cfc1", + "origin": "Delegated (Power BI Service)", + "value": "SQLDatabase.ExternalDataShare.All" + }, + { + "description": "Allows reading SQL databases on the user’s behalf.", + "displayName": "Read SQL databases", + "id": "1cc6e528-a407-4de1-883e-e36b91e09379", + "origin": "Delegated (Power BI Service)", + "value": "SQLDatabase.Read.All" + }, + { + "description": "Allows modifying SQL databases on the user’s behalf.", + "displayName": "Read and write SQL databases", + "id": "e4a4166c-b39f-4956-96ee-52ae6f1242e8", + "origin": "Delegated (Power BI Service)", + "value": "SQLDatabase.ReadWrite.All" + }, + { + "description": " ", + "displayName": "SQLDatabase.Reshare (retired)", + "id": "7cbb226f-a463-4f7e-b085-d11f68dac9ee", + "origin": "Delegated (Power BI Service)", + "value": "SQLDatabase.Reshare.All" + }, + { + "description": " ", + "displayName": "SQLEndpoint.Execute (retired)", + "id": "aa70d616-e57e-4a5a-84cd-07de4250dd2e", + "origin": "Delegated (Power BI Service)", + "value": "SQLEndpoint.Execute.All" + }, + { + "description": "Allows reading spark job definitions on the user’s behalf.", + "displayName": "Read spark job definitions", + "id": "beaf3087-05af-4060-a0a5-29779c902004", + "origin": "Delegated (Power BI Service)", + "value": "SparkJobDefinition.Read.All" + }, + { + "description": " ", + "displayName": "WarehouseSnapshot.Execute (retired)", + "id": "f132046a-f99f-4e2f-af2c-bcc6690050a5", + "origin": "Delegated (Power BI Service)", + "value": "WarehouseSnapshot.Execute.All" + }, + { + "description": "Allows modifying mirrored databases on the user’s behalf.", + "displayName": "Read and write mirrored databases", + "id": "2eb0ab4e-195e-45ec-9eb3-3b9842bea4f4", + "origin": "Delegated (Power BI Service)", + "value": "MirroredDatabase.ReadWrite.All" + }, + { + "description": "Allows the app to create and manage external data shares for all mirrored Databases, on behalf of the signed-in user.", + "displayName": "Allows the app to create and manage external data shares for all mirrored Databases", + "id": "eb433b13-ec6d-487b-8411-b5fadda75072", + "origin": "Delegated (Power BI Service)", + "value": "MirroredDatabase.ExternalDataShare.All" + }, + { + "description": "Allows modifying eventhouses on the user’s behalf.", + "displayName": "Read and write eventhouses", + "id": "b13393d0-9253-4ca8-be5a-be145f337ea3", + "origin": "Delegated (Power BI Service)", + "value": "Eventhouse.ReadWrite.All" + }, + { + "description": " ", + "displayName": "Eventhouse.Reshare (retired)", + "id": "1318ed2f-75ad-4748-b33a-d49044214bdb", + "origin": "Delegated (Power BI Service)", + "value": "Eventhouse.Reshare.All" + }, + { + "description": " ", + "displayName": "Eventstream.Execute (retired)", + "id": "110e2f5f-6226-4c3f-8d02-4b30b33e5fd1", + "origin": "Delegated (Power BI Service)", + "value": "Eventstream.Execute.All" + }, + { + "description": "Allows reading eventstreams on the user’s behalf.", + "displayName": "Read eventstreams", + "id": "5ce2a0b7-2512-440d-bf05-d5db590cc4c7", + "origin": "Delegated (Power BI Service)", + "value": "Eventstream.Read.All" + }, + { + "description": "Allows modifying eventstreams on the user’s behalf.", + "displayName": "Read and write eventstreams", + "id": "bd305576-f504-4e9a-81d4-d16c7eb5334b", + "origin": "Delegated (Power BI Service)", + "value": "Eventstream.ReadWrite.All" + }, + { + "description": " ", + "displayName": "Eventstream.Reshare (retired)", + "id": "ff4d87c4-a161-49a8-a886-fe14bf6a2203", + "origin": "Delegated (Power BI Service)", + "value": "Eventstream.Reshare.All" + }, + { + "description": "Allows the app to accept the external data share invitation on behalf of the signed-in user.", + "displayName": "Allows the app to accept the external data share invitation", + "id": "f4e8a89a-fa13-4aac-abd3-925cfe74dc66", + "origin": "Delegated (Power BI Service)", + "value": "ExternalDataShare.Accept.All" + }, + { + "description": "Allows retrieving item definitions, user identifiers, and other restricted metadata required for embedding Fabric items on the user’s behalf. To embed, the app must also be granted the appropriate contextual scope(s), such as Item.Read.All, Notebook.Read.All, or Workspace.Read.All.", + "displayName": "Embed Fabric items, retrieve user identifiers and restricted metadata", + "id": "04994edc-428b-482b-af95-ee1575dde39b", + "origin": "Delegated (Power BI Service)", + "value": "Fabric.Embed" + }, + { + "description": "Allows the app to extend Fabric with new item types and have restricted access to Fabric items, user identifiers and other metadata, on behalf of the signed-in user. Protecting exports with sensitivity labels, enforcement of regional boundaries and some other Fabric capabilities are not available to partner items.", + "displayName": "Extend Fabric with new item types", + "id": "7ba630b9-8110-4e27-8d17-81e5f2218787", + "origin": "Delegated (Power BI Service)", + "value": "Fabric.Extend" + }, + { + "description": "Allow partner Fabric items managed by this app to run in iframes with the relaxed sandbox enabling additional operations.", + "displayName": "Run partner Fabric items in iframes with relaxed sandbox protection.", + "id": "0a7d02f8-6c5f-4f1f-91e0-0650efd2436b", + "origin": "Delegated (Power BI Service)", + "value": "Fabric.Extend.IframeSandbox" + }, + { + "description": "The app can view all gateways that the signed in user is an admin of.", + "displayName": "View all gateways", + "id": "d2e42f6b-2baf-4ff4-83ef-51e66321516e", + "origin": "Delegated (Power BI Service)", + "value": "Gateway.Read.All" + }, + { + "description": "The app can view and edit all gateways that the signed in user is an admin of.", + "displayName": "Read and write all gateways", + "id": "ddb3ca45-a192-477d-acb2-46bf9dc586de", + "origin": "Delegated (Power BI Service)", + "value": "Gateway.ReadWrite.All" + }, + { + "description": "Allows executing graph instances on the user’s behalf.", + "displayName": "Execute graph instances", + "id": "d7fd01f6-c485-406a-ad50-27ea1c711589", + "origin": "Delegated (Power BI Service)", + "value": "GraphInstance.Execute.All" + }, + { + "description": "Allows reading graph instances on the user’s behalf.", + "displayName": "Read graph instances", + "id": "dc55c1dd-468c-4d7f-877a-9414f4c79c61", + "origin": "Delegated (Power BI Service)", + "value": "GraphInstance.Read.All" + }, + { + "description": "Allows modifying graph instances on the user’s behalf.", + "displayName": "Read and write graph instances", + "id": "6523f613-2a20-4d18-8b05-4d1bce5b7b07", + "origin": "Delegated (Power BI Service)", + "value": "GraphInstance.ReadWrite.All" + }, + { + "description": " ", + "displayName": "GraphInstance.Reshare (retired)", + "id": "ce5cc3da-13ac-4c07-9b8d-f5c5811d91d0", + "origin": "Delegated (Power BI Service)", + "value": "GraphInstance.Reshare.All" + }, + { + "description": "Allows the app to make API calls that executes requests on all API for GraphQL items, on behalf of the signed-in user.", + "displayName": "Make API calls that executes requests on all API for GraphQL items", + "id": "fc011432-d782-46d3-8143-f0328911e0a3", + "origin": "Delegated (Power BI Service)", + "value": "GraphQL.Execute.All" + }, + { + "description": "Allows reading eventhouses on the user’s behalf.", + "displayName": "Read eventhouses", + "id": "cd1718e4-3e09-4381-a6e1-183e245f8613", + "origin": "Delegated (Power BI Service)", + "value": "Eventhouse.Read.All" + }, + { + "description": "Allows executing GraphQLApis on the user’s behalf.", + "displayName": "Execute GraphQLApis", + "id": "cece14a0-0fa7-4de3-b458-69bd0cfea634", + "origin": "Delegated (Power BI Service)", + "value": "GraphQLApi.Execute.All" + }, + { + "description": " ", + "displayName": "Eventhouse.Execute (retired)", + "id": "0a5f551e-003b-482b-b5fb-7124a9510ba1", + "origin": "Delegated (Power BI Service)", + "value": "Eventhouse.Execute.All" + }, + { + "description": "Allows modifying environment items on the user’s behalf.", + "displayName": "Read and write environment items", + "id": "995d4201-6a2d-45c6-bad2-9f2aba89298d", + "origin": "Delegated (Power BI Service)", + "value": "Environment.ReadWrite.All" + }, + { + "description": "Allows executing dataflows on the user’s behalf.", + "displayName": "Execute dataflows", + "id": "529939f7-18e3-4be4-ba92-b01894a4fadf", + "origin": "Delegated (Power BI Service)", + "value": "Dataflow.Execute.All" + }, + { + "description": "Allows reading dataflows on the user’s behalf.", + "displayName": "Read dataflows", + "id": "f9759906-80a4-4f4a-b010-24b832bc6a30", + "origin": "Delegated (Power BI Service)", + "value": "Dataflow.Read.All" + }, + { + "description": "Allows modifying dataflows on the user’s behalf.", + "displayName": "Read and write dataflows", + "id": "ddd37690-e119-40c5-a821-3746ea6125c4", + "origin": "Delegated (Power BI Service)", + "value": "Dataflow.ReadWrite.All" + }, + { + "description": " ", + "displayName": "Dataflow.Reshare (retired)", + "id": "ad056abd-4839-4bb1-ba68-ffcf8194a869", + "origin": "Delegated (Power BI Service)", + "value": "Dataflow.Reshare.All" + }, + { + "description": " ", + "displayName": "Datamart.Execute (retired)", + "id": "17cddc84-5ff7-4b6a-a017-632384c5e063", + "origin": "Delegated (Power BI Service)", + "value": "Datamart.Execute.All" + }, + { + "description": "Allows reading datamarts on the user’s behalf.", + "displayName": "Read datamarts", + "id": "91f75836-b68c-4fff-84db-4372412a2c82", + "origin": "Delegated (Power BI Service)", + "value": "Datamart.Read.All" + }, + { + "description": "Allows modifying datamarts on the user’s behalf.", + "displayName": "Read and write datamarts", + "id": "6098cd04-d625-4e1c-91d6-f7888f645256", + "origin": "Delegated (Power BI Service)", + "value": "Datamart.ReadWrite.All" + }, + { + "description": " ", + "displayName": "Datamart.Reshare (retired)", + "id": "44abf802-73c1-42f4-a26f-915b4c27fa8f", + "origin": "Delegated (Power BI Service)", + "value": "Datamart.Reshare.All" + }, + { + "description": "Allows the app to make API calls that require execute permissions on all data pipelines, on behalf of the signed-in user.", + "displayName": "Make API calls that require execute permissions all data pipelines", + "id": "7e010a28-f5fa-4e63-b03d-2dc25cba9d2e", + "origin": "Delegated (Power BI Service)", + "value": "DataPipeline.Execute.All" + }, + { + "description": "Allows the app to make API calls that require read permissions on all data pipelines, on behalf of the signed-in user.", + "displayName": "Make API calls that require read permissions on all data pipelines", + "id": "a61cf2d1-8b81-4518-b2bb-a24e0831c17a", + "origin": "Delegated (Power BI Service)", + "value": "DataPipeline.Read.All" + }, + { + "description": "Allows the app to make API calls that require read and write permissions on all data pipelines, on behalf of the signed-in user.", + "displayName": "Make API calls that require read and write permissions on all data pipelines", + "id": "e0c0aef0-3eab-49ca-9662-50cc7bd13bfb", + "origin": "Delegated (Power BI Service)", + "value": "DataPipeline.ReadWrite.All" + }, + { + "description": " ", + "displayName": "DataPipeline.Reshare (retired)", + "id": "9afd59c7-4e4d-4a5d-b2aa-2777debb5cd9", + "origin": "Delegated (Power BI Service)", + "value": "DataPipeline.Reshare.All" + }, + { + "description": "The app can view all datasets for the signed in user and any datasets that the user has access to.", + "displayName": "View all datasets", + "id": "7f33e027-4039-419b-938e-2f8ca153e68e", + "origin": "Delegated (Power BI Service)", + "value": "Dataset.Read.All" + }, + { + "description": "The app can view and write to all datasets for the signed in user and any datasets that the user has access to.", + "displayName": "Read and write all datasets", + "id": "322b68b2-0804-416e-86a5-d772c567b6e6", + "origin": "Delegated (Power BI Service)", + "value": "Dataset.ReadWrite.All" + }, + { + "description": "Allows the app to make API calls to register and manage 3rd party Service Fabric workloads, on your behalf.", + "displayName": "Create and Manage Developer Experience functionality", + "id": "b23bb8c4-af74-49b0-91dd-79ffb83cddb9", + "origin": "Delegated (Power BI Service)", + "value": "DevX.ReadWrite.All" + }, + { + "description": " ", + "displayName": "Environment.Execute (retired)", + "id": "7a638d43-6e2d-4bf0-bffd-477785a2c721", + "origin": "Delegated (Power BI Service)", + "value": "Environment.Execute.All" + }, + { + "description": "Allows reading environment items on the user’s behalf.", + "displayName": "Read environment items", + "id": "80a4f621-10a7-45e5-a961-79e9b81831d0", + "origin": "Delegated (Power BI Service)", + "value": "Environment.Read.All" + }, + { + "description": " ", + "displayName": "Environment.Reshare (retired)", + "id": "72e814f5-a6b9-4316-b2ca-d07f426c178c", + "origin": "Delegated (Power BI Service)", + "value": "Environment.Reshare.All" + }, + { + "description": "Allows reading GraphQLApis on the user’s behalf.", + "displayName": "Read GraphQLApis", + "id": "deae611f-920b-422f-805e-f635080c4cfb", + "origin": "Delegated (Power BI Service)", + "value": "GraphQLApi.Read.All" + }, + { + "description": "Allows modifying GraphQLApis on the user’s behalf.", + "displayName": "Read and write GraphQLApis", + "id": "73d01b13-cb5e-466e-8752-a50feccb317e", + "origin": "Delegated (Power BI Service)", + "value": "GraphQLApi.ReadWrite.All" + }, + { + "description": " ", + "displayName": "GraphQLApi.Reshare (retired)", + "id": "88cf9f59-aa53-4386-ae14-3c8263713766", + "origin": "Delegated (Power BI Service)", + "value": "GraphQLApi.Reshare.All" + }, + { + "description": "Allows reading KQL querysets on the user’s behalf.", + "displayName": "Read KQL querysets", + "id": "8826b95a-bc76-4025-97f1-8c89c3d5f210", + "origin": "Delegated (Power BI Service)", + "value": "KQLQueryset.Read.All" + }, + { + "description": "Allows modifying KQL querysets on the user’s behalf.", + "displayName": "Read and write KQL querysets", + "id": "88ba374a-d581-4944-b7c7-1181754eba74", + "origin": "Delegated (Power BI Service)", + "value": "KQLQueryset.ReadWrite.All" + }, + { + "description": " ", + "displayName": "KQLQueryset.Reshare (retired)", + "id": "2d3aa07c-d364-4ce0-acbc-b7e151ee161d", + "origin": "Delegated (Power BI Service)", + "value": "KQLQueryset.Reshare.All" + }, + { + "description": "Allows executing lakehouses on the user’s behalf.", + "displayName": "Execute lakehouses", + "id": "565b3968-767c-4100-8771-a827146f38ce", + "origin": "Delegated (Power BI Service)", + "value": "Lakehouse.Execute.All" + }, + { + "description": "Allows the app to create and manage external data shares for all lakehouses, on behalf of the signed-in user.", + "displayName": "Allows the app to create and manage external data shares for all lakehouses", + "id": "1d1f591a-f469-48d6-8995-a532552ae72c", + "origin": "Delegated (Power BI Service)", + "value": "Lakehouse.ExternalDataShare.All" + }, + { + "description": "Allows reading lakehouses on the user’s behalf.", + "displayName": "Read lakehouses", + "id": "13060bfd-9305-4ec6-8388-8916580f4fa9", + "origin": "Delegated (Power BI Service)", + "value": "Lakehouse.Read.All" + }, + { + "description": "Allows modifying lakehouses on the user’s behalf.", + "displayName": "Read and write lakehouses", + "id": "eee83281-2212-467d-b9e3-2aadfb170f33", + "origin": "Delegated (Power BI Service)", + "value": "Lakehouse.ReadWrite.All" + }, + { + "description": " ", + "displayName": "Lakehouse.Reshare (retired)", + "id": "881e9f00-4e9c-4798-bc50-832fea2cdbe6", + "origin": "Delegated (Power BI Service)", + "value": "Lakehouse.Reshare.All" + }, + { + "description": " ", + "displayName": "MetricSet.Execute (retired)", + "id": "c79ca1a6-cca1-4ef3-98e3-6abf01eb242f", + "origin": "Delegated (Power BI Service)", + "value": "MetricSet.Execute.All" + }, + { + "description": "Allows reading metric sets on the user’s behalf.", + "displayName": "Read metric sets", + "id": "f4611230-1dcf-4466-92d9-59a35c81737a", + "origin": "Delegated (Power BI Service)", + "value": "MetricSet.Read.All" + }, + { + "description": "Allows modifying metric sets on the user’s behalf.", + "displayName": "Read and write metric sets", + "id": "68386d9d-5570-4b99-9211-ab8abd584145", + "origin": "Delegated (Power BI Service)", + "value": "MetricSet.ReadWrite.All" + }, + { + "description": " ", + "displayName": "MetricSet.Reshare (retired)", + "id": "f2fe8057-777e-4536-a069-90f4a2f922bf", + "origin": "Delegated (Power BI Service)", + "value": "MetricSet.Reshare.All" + }, + { + "description": "Allows executing mirrored azure databricks catalogs on the user’s behalf.", + "displayName": "Execute mirrored azure databricks catalogs", + "id": "e618543a-fb4e-4e95-a8f0-7af6549af7a9", + "origin": "Delegated (Power BI Service)", + "value": "MirroredAzureDatabricksCatalog.Execute.All" + }, + { + "description": "Allows reading mirrored azure databricks catalogs on the user’s behalf.", + "displayName": "Read mirrored azure databricks catalogs", + "id": "0107b32c-22a6-4354-ad71-828b6d03598a", + "origin": "Delegated (Power BI Service)", + "value": "MirroredAzureDatabricksCatalog.Read.All" + }, + { + "description": "Allows modifying mirrored azure databricks catalogs on the user’s behalf.", + "displayName": "Read and write mirrored azure databricks catalogs", + "id": "c5431154-27d8-4db7-96d0-8a201ad5d027", + "origin": "Delegated (Power BI Service)", + "value": "MirroredAzureDatabricksCatalog.ReadWrite.All" + }, + { + "description": " ", + "displayName": "MirroredAzureDatabricksCatalog.Reshare (retired)", + "id": "ee9fd26c-e612-44ef-8985-a0c7a1b06ab1", + "origin": "Delegated (Power BI Service)", + "value": "MirroredAzureDatabricksCatalog.Reshare.All" + }, + { + "description": " ", + "displayName": "MirroredDatabase.Execute (retired)", + "id": "67d4aa3f-531f-4db2-a382-7db42788fd35", + "origin": "Delegated (Power BI Service)", + "value": "MirroredDatabase.Execute.All" + }, + { + "description": " ", + "displayName": "KQLQueryset.Execute (retired)", + "id": "b84b0d8d-9870-4b2b-92d2-9bfa7f940db3", + "origin": "Delegated (Power BI Service)", + "value": "KQLQueryset.Execute.All" + }, + { + "description": " ", + "displayName": "KQLDataConnection.Reshare (retired)", + "id": "8191607d-cbe5-49c6-b480-1aae71f3dce6", + "origin": "Delegated (Power BI Service)", + "value": "KQLDataConnection.Reshare.All" + }, + { + "description": "Allows the app to make API calls that require read and write permissions on all KQL data connections, on behalf of the signed-in user.", + "displayName": "Make API calls that require read and write permissions on and write all KQL data connections", + "id": "753e9303-2fd9-496e-aa7c-cf84a133f42a", + "origin": "Delegated (Power BI Service)", + "value": "KQLDataConnection.ReadWrite.All" + }, + { + "description": "Allows the app to make API calls that require read permissions on all KQL data connections, on behalf of the signed-in user.", + "displayName": "Make API calls that require read permissions on all KQL data connections", + "id": "59b5791b-482f-4b95-8498-fe078f6bd6fa", + "origin": "Delegated (Power BI Service)", + "value": "KQLDataConnection.Read.All" + }, + { + "description": "Allows the app to make API calls that require audit permissions on all items, on behalf of the signed-in user.", + "displayName": "Make API calls that require audit permissions on all items", + "id": "6213ab68-aad6-4ec9-836a-306b14f6fee6", + "origin": "Delegated (Power BI Service)", + "value": "Item.Audit.All" + }, + { + "description": "Allows the app to make API calls that require execute permissions on all Fabric items, on behalf of the signed-in user.", + "displayName": "Make API calls that require execute permissions on all Fabric items", + "id": "caf40b1a-f10e-4da1-86e4-5fda17eb2b07", + "origin": "Delegated (Power BI Service)", + "value": "Item.Execute.All" + }, + { + "description": "Allows the app to create and manage external data shares for all Fabric items, on behalf of the signed-in user.", + "displayName": "Allows the app to create and manage external data shares for all Fabric items", + "id": "bae3e5e0-a78a-4b0f-b3a0-0dc52f365b9d", + "origin": "Delegated (Power BI Service)", + "value": "Item.ExternalDataShare.All" + }, + { + "description": "Allows the app to make API calls that require read permissions on all Fabric items, on behalf of the signed-in user.", + "displayName": "Make API calls that require read permissions on all Fabric items", + "id": "d2bc95fc-440e-4b0e-bafd-97182de7aef5", + "origin": "Delegated (Power BI Service)", + "value": "Item.Read.All" + }, + { + "description": "Allows the app to make API calls that require read and write permissions on all Fabric items, on behalf of the signed-in user.", + "displayName": "Make API calls that require read and write permissions on all Fabric items", + "id": "7a27a256-301d-4359-b77b-c2b759d2e362", + "origin": "Delegated (Power BI Service)", + "value": "Item.ReadWrite.All" + }, + { + "description": "Allows the app to make API calls that require reshare permissions on all Fabric items, on behalf of the signed-in user.", + "displayName": "Make API calls that require reshare permissions on all Fabric items", + "id": "02e8d710-956c-4760-b996-2e83935c2cf5", + "origin": "Delegated (Power BI Service)", + "value": "Item.Reshare.All" + }, + { + "description": "Allows the app to make API calls that can read the item metadata of all Fabric items, on behalf of the signed-in user.", + "displayName": "Make API calls that can read item metadata for all Fabric items", + "id": "94a31d2b-0d95-46b5-9dcd-1bf123c80327", + "origin": "Delegated (Power BI Service)", + "value": "ItemMetadata.Read.All" + }, + { + "description": "Allows the app to make API calls that can read and write the item metadata of all Fabric items, on behalf of the signed-in user.", + "displayName": "Make API calls that can read and write item metadata for all Fabric items", + "id": "c289c338-860d-4abf-8312-2455f47f8f33", + "origin": "Delegated (Power BI Service)", + "value": "ItemMetadata.ReadWrite.All" + }, + { + "description": "Allows reading mirrored databases on the user’s behalf.", + "displayName": "Read mirrored databases", + "id": "10051e25-9077-418c-a076-32a2d35132a2", + "origin": "Delegated (Power BI Service)", + "value": "MirroredDatabase.Read.All" + }, + { + "description": " ", + "displayName": "KQLDashboard.Execute (retired)", + "id": "6132db85-22d5-486c-b094-56eb8f746628", + "origin": "Delegated (Power BI Service)", + "value": "KQLDashboard.Execute.All" + }, + { + "description": "Allows modifying KQL dashboards on the user’s behalf.", + "displayName": "Read and write KQL dashboards", + "id": "3a857d04-01aa-421a-aa42-e40b4264b6f7", + "origin": "Delegated (Power BI Service)", + "value": "KQLDashboard.ReadWrite.All" + }, + { + "description": " ", + "displayName": "KQLDashboard.Reshare (retired)", + "id": "ed4d5569-4170-4f10-b174-16f9d1b31cec", + "origin": "Delegated (Power BI Service)", + "value": "KQLDashboard.Reshare.All" + }, + { + "description": "Allows executing KQL databases on the user’s behalf.", + "displayName": "Execute KQL databases", + "id": "21b4da43-510a-43ac-afd4-580e1e2c09c8", + "origin": "Delegated (Power BI Service)", + "value": "KQLDatabase.Execute.All" + }, + { + "description": "Allows the app to create and manage external data shares for all KQL databases, on behalf of the signed-in user.", + "displayName": "Allows the app to create and manage external data shares for all KQL databases", + "id": "3a1af33d-ccfa-4264-998b-348c8c299db1", + "origin": "Delegated (Power BI Service)", + "value": "KQLDatabase.ExternalDataShare.All" + }, + { + "description": "Allows reading KQL databases on the user’s behalf.", + "displayName": "Read KQL databases", + "id": "24367f1a-a6d6-410d-b438-378ed19cb875", + "origin": "Delegated (Power BI Service)", + "value": "KQLDatabase.Read.All" + }, + { + "description": "Allows modifying KQL databases on the user’s behalf.", + "displayName": "Read and write KQL databases", + "id": "726667b1-01a6-4be4-b04c-e95eae4023a8", + "origin": "Delegated (Power BI Service)", + "value": "KQLDatabase.ReadWrite.All" + }, + { + "description": " ", + "displayName": "KQLDatabase.Reshare (retired)", + "id": "83a35b59-6a34-40f4-ac4e-5bf5a6ff9a5d", + "origin": "Delegated (Power BI Service)", + "value": "KQLDatabase.Reshare.All" + }, + { + "description": " ", + "displayName": "KQLDataConnection.Execute (retired)", + "id": "6872ffe8-d8d4-46f9-9a32-5537dad08dd2", + "origin": "Delegated (Power BI Service)", + "value": "KQLDataConnection.Execute.All" + }, + { + "description": "Allows reading KQL dashboards on the user’s behalf.", + "displayName": "Read KQL dashboards", + "id": "f19ea7d7-2f31-4c6d-9845-d5480c5d1798", + "origin": "Delegated (Power BI Service)", + "value": "KQLDashboard.Read.All" + }, + { + "description": "Allows reading Databricks workspaces catalog metadata on the user’s behalf.", + "displayName": "Read Databricks workspaces catalog metadata.", + "id": "6cadaf62-a218-4d72-a641-0f85c813ece3", + "origin": "Delegated (Power BI Service)", + "value": "DatabricksCatalog.Read.All" + }, + { + "description": "Allows reading warehouse snapshots on the user’s behalf.", + "displayName": "Read warehouse snapshots", + "id": "fe27a477-ed49-4762-9157-5a22eec929a7", + "origin": "Delegated (Power BI Service)", + "value": "WarehouseSnapshot.Read.All" + }, + { + "description": " ", + "displayName": "WarehouseSnapshot.Reshare (retired)", + "id": "7e23ffe1-cea7-435d-94ce-4a7b4e8b38a0", + "origin": "Delegated (Power BI Service)", + "value": "WarehouseSnapshot.Reshare.All" + }, + { + "description": "Allows the app to read any alert", + "displayName": "Read all alerts", + "id": "71fe6b80-7034-4028-9ed8-0f316df9c3ff", + "origin": "Application (WindowsDefenderATP)", + "value": "Alert.Read.All" + }, + { + "description": "Allows the app to create or update any alert", + "displayName": "Read and write all alerts", + "id": "0f7000ec-157b-497f-b70e-ef0b0584f140", + "origin": "Application (WindowsDefenderATP)", + "value": "Alert.ReadWrite.All" + }, + { + "description": "Allows the app to create events in the machine timeline", + "displayName": "Write timeline events", + "id": "84ddd701-5fac-4c30-b0ad-aa73a67bea1a", + "origin": "Application (WindowsDefenderATP)", + "value": "Event.Write" + }, + { + "description": "Allows the app to read all file profiles", + "displayName": "Read file profiles", + "id": "8788f1a9-beca-4e26-ba58-10513f3b896f", + "origin": "Application (WindowsDefenderATP)", + "value": "File.Read.All" + }, + { + "description": "Allows the app to read and modify integration settings between itself and the service", + "displayName": "Read and Write Integration settings", + "id": "7c6f6912-60e9-4fcd-bb2a-c25bc35e8c59", + "origin": "Application (WindowsDefenderATP)", + "value": "IntegrationConfiguration.ReadWrite" + }, + { + "description": "Allows the app to read all IP address profiles", + "displayName": "Read IP address profiles", + "id": "47bf842d-354b-49ef-b741-3a6dd815bc13", + "origin": "Application (WindowsDefenderATP)", + "value": "Ip.Read.All" + }, + { + "description": "Allows the app to manage live response library files", + "displayName": "Manage live response library files", + "id": "41d209c7-2511-4fc9-b899-8008a3976f09", + "origin": "Application (WindowsDefenderATP)", + "value": "Library.Manage" + }, + { + "description": "Allows the app to collect forensics from a machine", + "displayName": "Collect forensics", + "id": "15405ab2-2103-4a3c-ad80-e829841cedcc", + "origin": "Application (WindowsDefenderATP)", + "value": "Machine.CollectForensics" + }, + { + "description": "Allows the app to isolate a machine", + "displayName": "Isolate machine", + "id": "7e4e1300-e1b9-4102-88ba-f0cb6e6d5974", + "origin": "Application (WindowsDefenderATP)", + "value": "Machine.Isolate" + }, + { + "description": "Allows the app to run a live response on a specific machine", + "displayName": "Run live response on a specific machine", + "id": "1629b959-c0af-42a1-92f0-f6162060bdf1", + "origin": "Application (WindowsDefenderATP)", + "value": "Machine.LiveResponse" + }, + { + "description": "Allows the app to offboard a machine from the service", + "displayName": "Offboard machine", + "id": "594435bf-36dd-4548-83bd-1bdafe157d7a", + "origin": "Application (WindowsDefenderATP)", + "value": "Machine.Offboard" + }, + { + "description": "Allows the app to read all machine profiles, including the commands that were sent to each machine", + "displayName": "Read all machine profiles", + "id": "ea8291d3-4b9a-44b5-bc3a-6cea3026dc79", + "origin": "Application (WindowsDefenderATP)", + "value": "Machine.Read.All" + }, + { + "description": "Allows the app to create machine records and to read or update any machine record", + "displayName": "Read and write all machine information", + "id": "aa027352-232b-4ed4-b963-a705fc4d6d2c", + "origin": "Application (WindowsDefenderATP)", + "value": "Machine.ReadWrite.All" + }, + { + "description": "Allows the app to restrict code execution on a machine according to policy", + "displayName": "Restrict code execution", + "id": "96b6b35d-074d-4e2d-b167-8d68d9269648", + "origin": "Application (WindowsDefenderATP)", + "value": "Machine.RestrictExecution" + }, + { + "description": "Allows the app to scan a machine", + "displayName": "Scan machine", + "id": "a86d9824-b2b6-45f8-b042-16bc4922ed4e", + "origin": "Application (WindowsDefenderATP)", + "value": "Machine.Scan" + }, + { + "description": "Allows the app to stop a file running on a machine and to quarantine that file", + "displayName": "Stop and quarantine file", + "id": "96e72b5e-7e68-4171-aad1-3937599e4751", + "origin": "Application (WindowsDefenderATP)", + "value": "Machine.StopAndQuarantine" + }, + { + "description": "Users assign to this role will be able to access the Windows Defender ATP portal, view all the data but will not be able to perform any action", + "displayName": "Security Operations - Read Only", + "id": "f820e656-f1d1-4cb8-a566-31d18eeecb40", + "origin": "Application (WindowsDefenderATP)", + "value": "readonly" + }, + { + "description": "Allows the app to run advanced queries", + "displayName": "Run advanced queries", + "id": "93489bf5-0fbc-4f2d-b901-33f2fe08ff05", + "origin": "Application (WindowsDefenderATP)", + "value": "AdvancedQuery.Read.All" + }, + { + "description": "Allows the app to read all remediation tasks", + "displayName": "Read all remediation tasks", + "id": "6a33eedf-ba73-4e5a-821b-f057ef63853a", + "origin": "Application (WindowsDefenderATP)", + "value": "RemediationTasks.Read.All" + }, + { + "description": "Allow the application to access Windows Virtual Desktop on your behalf.", + "displayName": "Access Windows Virtual Desktop", + "id": "1ea0ab9c-b888-476f-aca9-0fc9a53b483a", + "origin": "Delegated (Windows Virtual Desktop)", + "value": "User.Access" + }, + { + "description": "Allow the application to access Windows Store for Business on behalf of the signed-in user.", + "displayName": "Access Windows Store for Business", + "id": "56cee9a4-2b49-4d48-a5c1-b26a2e48aada", + "origin": "Delegated (Windows Store for Business)", + "value": "user_impersonation" + }, + { + "description": "Allows the app to read and write data in your company or school directory, such as users, and groups. Does not allow user or group deletion.", + "displayName": "Read and write directory data", + "id": "78c8a3c8-a07e-4b9e-af1b-b5ccab50a175", + "origin": "Delegated (Windows Azure Active Directory)", + "value": "Directory.ReadWrite.All" + }, + { + "description": "Allows the app to read basic group properties and memberships on behalf of the signed-in user.", + "displayName": "Read all groups", + "id": "6234d376-f627-4f0f-90e0-dff25c5211a3", + "origin": "Delegated (Windows Azure Active Directory)", + "value": "Group.Read.All" + }, + { + "description": "Allows the app to create groups on behalf of the signed-in user and read all group properties and memberships. Additionally, this allows the app to update group properties and memberships for the groups the signed-in user owns.", + "displayName": "Read and write all groups", + "id": "970d6fa6-214a-4a9b-8513-08fad511e2fd", + "origin": "Delegated (Windows Azure Active Directory)", + "value": "Group.ReadWrite.All" + }, + { + "description": "Allows the app to read the memberships of hidden groups and administrative units on behalf of the signed-in user, for those hidden groups and administrative units that the signed-in user has access to.", + "displayName": "Read hidden memberships", + "id": "2d05a661-f651-4d57-a595-489c91eda336", + "origin": "Delegated (Windows Azure Active Directory)", + "value": "Member.Read.Hidden" + }, + { + "description": "Allows the app to read your organization's policies on behalf of the signed-in user.", + "displayName": "Read your organization's policies", + "id": "80e5b1bf-3ad0-4365-943a-0ec983009b67", + "origin": "Delegated (Windows Azure Active Directory)", + "value": "Policy.Read.All" + }, + { + "description": "Allows users to sign in to the app, and allows the app to read the profile of signed-in users. It also allow the app to read basic company information of signed-in users.", + "displayName": "Sign in and read user profile", + "id": "311a71cc-e848-46a1-bdf8-97ff7156d8e6", + "origin": "Delegated (Windows Azure Active Directory)", + "value": "User.Read" + }, + { + "description": "Allows the app to read the full set of profile properties of all users in your company or school, on behalf of the signed-in user. Additionally, this allows the app to read the profiles of the signed-in user's reports and manager.", + "displayName": "Read all users' full profiles", + "id": "c582532d-9d9e-43bd-a97c-2667a28ce295", + "origin": "Delegated (Windows Azure Active Directory)", + "value": "User.Read.All" + }, + { + "description": "Allows the app to read a basic set of profile properties of all users in your company or school on behalf of the signed-in user. Includes display name, first and last name, photo, and email address. Additionally, this allows the app to read basic info about the signed-in user's reports and manager.", + "displayName": "Read all users' basic profiles", + "id": "cba73afc-7f69-4d86-8450-4978e04ecd1a", + "origin": "Delegated (Windows Azure Active Directory)", + "value": "User.ReadBasic.All" + }, + { + "description": "Allows the application to access Azure Resource Manager acting as users in the organization.", + "displayName": "Access Azure Resource Manager as organization users", + "id": "41094075-9dad-400e-a0bd-54e686782033", + "origin": "Delegated (Windows Azure Service Management API)", + "value": "user_impersonation" + }, + { + "description": "Allow the application to sign in to Windows on behalf of the signed-in user", + "displayName": "Sign in to Windows", + "id": "d0ee7be9-09ed-4def-83f2-6e72005521f7", + "origin": "Delegated (Windows Cloud Login)", + "value": "user_impersonation" + }, + { + "description": "Can buy products for inventory, assign and reclaim licenses.", + "displayName": "Basic purchaser", + "id": "cf498509-9a5c-4d83-aa26-2b70fcbd0e1c", + "origin": "Application (Windows Store for Business)", + "value": "basicpurchaser" + }, + { + "description": "Can only access the things made available to them by their organization.", + "displayName": "Basic user", + "id": "16beb6e1-c277-4b64-97fa-5c90295a5c84", + "origin": "Application (Windows Store for Business)", + "value": "basicuser" + }, + { + "description": "Has all the permissions of Purchaser. Can also grant access, set permission levels, and change all settings and configurations.", + "displayName": "Administrator", + "id": "f75b6470-490d-4b7b-a084-15d2f79fcd26", + "origin": "Application (Windows Store for Business)", + "value": "bspadmin" + }, + { + "description": "A configured management tool can distribute app licenses that have been acquired in the Windows Store for Business Portal to users and devices within an organization.", + "displayName": "Management Tool", + "id": "e4c00fbe-aea4-4c3b-b803-335d512be9d6", + "origin": "Application (Windows Store for Business)", + "value": "bspmdm" + }, + { + "description": "Can buy products for inventory, assign and reclaim licenses.", + "displayName": "Purchaser", + "id": "20220577-b1fd-4061-bfed-05a068857ffc", + "origin": "Application (Windows Store for Business)", + "value": "bsppurchaser" + }, + { + "description": "Has access to the device guard signing page, can sign policies and catalogs.", + "displayName": "Device Guard signer", + "id": "4c7bcbe9-70eb-42d2-a8b1-a66d985811c3", + "origin": "Application (Windows Store for Business)", + "value": "deviceguardsigner" + }, + { + "description": "Allows user to view purchased products and subscriptions", + "displayName": "Assets.Read", + "id": "30000000-aaaa-bbbb-cccc-100000000002", + "origin": "Delegated (Windows Store for Business)", + "value": "Assets.Read" + }, + { + "description": "Creators can create Windows Virtual Desktop Tenants", + "displayName": "Tenant.Create", + "id": "299dad25-58e3-473d-9733-171fb3034713", + "origin": "Application (Windows Virtual Desktop)", + "value": "Tenant.Create" + }, + { + "description": "Allows the app to read any Threat and Vulnerability Management score", + "displayName": "Read Threat and Vulnerability Management score", + "id": "02b005dd-f804-43b4-8fc7-078460413f74", + "origin": "Application (WindowsDefenderATP)", + "value": "Score.Read.All" + }, + { + "description": "Users assign to this role will be able to access the Windows Defender ATP portal, view all the data and be able to perform actions such as change alerts status, apply suppression rules etc.", + "displayName": "Security Operations - Read & Write", + "id": "2261fd4a-5f23-4b74-9e4d-f4ac92dc86a2", + "origin": "Application (WindowsDefenderATP)", + "value": "secop" + }, + { + "description": "Allows the app to read all security baselines assessment information", + "displayName": "Read all security baselines assessment information", + "id": "e870c0c1-c1a2-41ca-948e-a33912d2d3f0", + "origin": "Application (WindowsDefenderATP)", + "value": "SecurityBaselinesAssessment.Read.All" + }, + { + "description": "Allows the app to create machine records and to read or update any machine record that the signed-in user can create, read or update.", + "displayName": "Read and write machine information", + "id": "f6846c57-9e3c-4a65-81aa-2f5e09ff4f0b", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Machine.ReadWrite" + }, + { + "description": "Allows the app to restrict code execution on a machine according to policy on behalf of the signed-in user", + "displayName": "Restrict code execution", + "id": "abddfa88-80bb-4aef-81ff-18cbf29363a9", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Machine.RestrictExecution" + }, + { + "description": "Allows the app to scan a machine on behalf of the signed-in user", + "displayName": "Scan machine", + "id": "b4618115-647e-42a5-bd0d-0ea9878fb376", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Machine.Scan" + }, + { + "description": "Allows the app to restrict code execution on a machine according to policy on behalf of the signed-in user", + "displayName": "Stop and quarantine file", + "id": "69e036b7-3f10-4d4c-a85e-82295629eca8", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Machine.StopAndQuarantine" + }, + { + "description": "Allows the app to read remediation tasks that the signed in user can", + "displayName": "Read remediation tasks", + "id": "19956c04-168f-4f44-b471-48c8f50dc0c8", + "origin": "Delegated (WindowsDefenderATP)", + "value": "RemediationTasks.Read" + }, + { + "description": "Allows the app to read Threat and Vulnerability Management score on behalf of the signed-in user", + "displayName": "Read Threat and Vulnerability Management score", + "id": "df4ed126-3a4c-460a-b0fc-67aea84fc332", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Score.Read" + }, + { + "description": "Allows the app to read security baselines assessment information", + "displayName": "Read security baselines assessment information", + "id": "d42e2aa1-a664-43a9-b7c6-2766d44a6687", + "origin": "Delegated (WindowsDefenderATP)", + "value": "SecurityBaselinesAssessment.Read" + }, + { + "description": "Allows the app to read security configurations that the signed in user can access", + "displayName": "Read security configurations", + "id": "4ac83e46-552f-4948-91c2-f7eaff971018", + "origin": "Delegated (WindowsDefenderATP)", + "value": "SecurityConfiguration.Read" + }, + { + "description": "Allows the app to read and write security configurations that the signed in user can manage", + "displayName": "Read and write security configurations", + "id": "bfc81a3a-4f6d-4bfe-b945-d7fe6747d2a0", + "origin": "Delegated (WindowsDefenderATP)", + "value": "SecurityConfiguration.ReadWrite" + }, + { + "description": "Allows the app to read Threat and Vulnerability Management security recommendations on behalf of the signed-in user", + "displayName": "Read Threat and Vulnerability Management security recommendations", + "id": "1ab96238-1253-4059-a32f-4087f20ed65d", + "origin": "Delegated (WindowsDefenderATP)", + "value": "SecurityRecommendation.Read" + }, + { + "description": "Allows the app to read Threat and Vulnerability Management software information on behalf of the signed-in user", + "displayName": "Read Threat and Vulnerability Management software information", + "id": "5f216ada-3f51-4a22-ace5-06b198328476", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Software.Read" + }, + { + "description": "Allows the app to create IOCs and to read or update IOCs it created, on behalf of the signed-in user", + "displayName": "Read and write IOCs", + "id": "650ff1f9-dd5f-48ee-8c58-7beef332c818", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Ti.ReadWrite" + }, + { + "description": "Allows the app to read all URL profiles on behalf of the signed-in user", + "displayName": "Read URL profiles", + "id": "42b4777c-6196-49ad-9cfc-207e73f2eb61", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Url.Read.All" + }, + { + "description": "Allows the app to read all user profiles on behalf of the signed-in user", + "displayName": "Read user profiles", + "id": "ffd6563e-842b-4cfc-b349-06006e0473a3", + "origin": "Delegated (WindowsDefenderATP)", + "value": "User.Read.All" + }, + { + "description": "Allows the app to read Threat and Vulnerability Management vulnerability information on behalf of the signed-in user", + "displayName": "Read Threat and Vulnerability Management vulnerability information", + "id": "63a677ce-818c-4409-9d12-5c6d2e2a6bfe", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Vulnerability.Read" + }, + { + "description": "Allows the app to impersonate the signed-in user to access the Partner Center API.", + "displayName": "Partner Center as User", + "id": "1cebfa2a-fb4d-419e-b5f9-839b4383e05a", + "origin": "Delegated (Microsoft Partner Center)", + "value": "user_impersonation" + }, + { + "description": "Allows the app to manage restricted resources based on the other permissions granted to the app, without a signed-in user.", + "displayName": "Manage restricted resources in the directory", + "id": "f20584af-9290-4153-9280-ff8bb2c0ea7f", + "origin": "Application", + "value": "Directory.Write.Restricted" + }, + { + "description": "Allows the app to read machine profiles (including the commands that were sent to each machine), that the signed in user can access", + "displayName": "Read machine information", + "id": "fbd3d33a-b1f5-4573-906c-51b39682fbcf", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Machine.Read" + }, + { + "description": "Allows the app to offboard a machine from the service on behalf of the signed-in user", + "displayName": "Offboard machine", + "id": "29d1c73a-07f6-495f-b62b-1554a954d0a3", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Machine.Offboard" + }, + { + "description": "Allows the app to run live response on a specific machine according to policy on behalf of the signed-in user", + "displayName": "Run live response on a specific machine", + "id": "25fb0c21-5877-492a-8d0c-e7893a9585cc", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Machine.LiveResponse" + }, + { + "description": "Allows the app to isolate a machine on behalf of the signed-in user", + "displayName": "Isolate machine", + "id": "479231ef-3b86-4933-ae6b-1fa84bba9e31", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Machine.Isolate" + }, + { + "description": "Allows the app to read all security configurations", + "displayName": "Read all security configurations", + "id": "227f2ea0-c2c2-4428-b7af-9ff40f1a720e", + "origin": "Application (WindowsDefenderATP)", + "value": "SecurityConfiguration.Read.All" + }, + { + "description": "Allows the app to read and write all security configurations", + "displayName": "Read and write all security configurations", + "id": "e5e05709-32a3-4c85-89c8-67596eb94f24", + "origin": "Application (WindowsDefenderATP)", + "value": "SecurityConfiguration.ReadWrite.All" + }, + { + "description": "Allows the app to read any Threat and Vulnerability Management security recommendation", + "displayName": "Read Threat and Vulnerability Management security recommendations", + "id": "6443965c-7dd2-4cfd-b38f-bb7772bee163", + "origin": "Application (WindowsDefenderATP)", + "value": "SecurityRecommendation.Read.All" + }, + { + "description": "Allows the app to read any Threat and Vulnerability Management software information", + "displayName": "Read Threat and Vulnerability Management software information", + "id": "37f71c98-d198-41ae-964d-2c49aab74926", + "origin": "Application (WindowsDefenderATP)", + "value": "Software.Read.All" + }, + { + "description": "Allows the app to read all IOCs", + "displayName": "Read all IOCs", + "id": "528ca142-c849-4a5b-935e-10b8b9c38a84", + "origin": "Application (WindowsDefenderATP)", + "value": "Ti.Read.All" + }, + { + "description": "Allows the app to create IOCs and to read or update IOCs it created", + "displayName": "Read and write IOCs belonging to the app", + "id": "a8bc2240-f96a-46a1-bad5-6a960b7327a1", + "origin": "Application (WindowsDefenderATP)", + "value": "Ti.ReadWrite" + }, + { + "description": "Allows the app to manage all IOCs of the tenant", + "displayName": "Read and write all IOCs", + "id": "fc511a58-3adf-4d71-af24-00f13e35e479", + "origin": "Application (WindowsDefenderATP)", + "value": "Ti.ReadWrite.All" + }, + { + "description": "Allows the app to read all URL profiles", + "displayName": "Read URL profiles", + "id": "721af526-ffa8-42d7-9b84-1a56244dd99d", + "origin": "Application (WindowsDefenderATP)", + "value": "Url.Read.All" + }, + { + "description": "Allows the app to read data in your company or school directory, such as users, groups, and apps.", + "displayName": "Read directory data", + "id": "5778995a-e1bf-45b8-affa-663a9f3f4d04", + "origin": "Delegated (Windows Azure Active Directory)", + "value": "Directory.Read.All" + }, + { + "description": "Allows the app to read all user profiles", + "displayName": "Read user profiles", + "id": "a833834a-4cf1-4732-8acf-bbcfa13fb610", + "origin": "Application (WindowsDefenderATP)", + "value": "User.Read.All" + }, + { + "description": "Allows the app to run advanced queries, that the signed-in user can execute.", + "displayName": "Run advanced queries", + "id": "1fb6e712-1bd9-4184-b1c0-5e71e759196b", + "origin": "Delegated (WindowsDefenderATP)", + "value": "AdvancedQuery.Read" + }, + { + "description": "Allows the app to read any alert that the signed in user can access", + "displayName": "Read alerts", + "id": "b2069dc0-9fe9-4e6d-9aca-ccf3dd503819", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Alert.Read" + }, + { + "description": "Allows the app to create or update any alert that the signed in user can create or update", + "displayName": "Read and write alerts", + "id": "cbc3b413-21e6-416d-95a4-af87687efbd0", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Alert.ReadWrite" + }, + { + "description": "Allows the app to read all file profiles on", + "displayName": "Read file profiles", + "id": "8fce64a0-67c8-4e39-8f47-cac9ff7e13bb", + "origin": "Delegated (WindowsDefenderATP)", + "value": "File.Read.All" + }, + { + "description": "Allows the app to read all IP address profiles on behalf of the signed-in user", + "displayName": "Read IP address profiles", + "id": "b65a97e8-c8e8-4908-b19a-f654615de1a9", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Ip.Read.All" + }, + { + "description": "Allows the app to manage live response library files on behalf of the signed-in user", + "displayName": "Manage live response library files", + "id": "5998a3da-2c9b-4bf3-99bd-44c9fe337ad2", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Library.Manage" + }, + { + "description": "Allows the app to collect forensics data from a machine on behalf of the signed-in user", + "displayName": "Collect forensics", + "id": "5eb7b9dc-cbce-4c7e-9d73-5be248260ae6", + "origin": "Delegated (WindowsDefenderATP)", + "value": "Machine.CollectForensics" + }, + { + "description": "Allows the app to read any Threat and Vulnerability Management vulnerability information", + "displayName": "Read Threat and Vulnerability Management vulnerability information", + "id": "41269fc5-d04d-4bfd-bce7-43a51cea049a", + "origin": "Application (WindowsDefenderATP)", + "value": "Vulnerability.Read.All" + }, + { + "description": "Allows modifying warehouse snapshots on the user’s behalf.", + "displayName": "Read and write warehouse snapshots", + "id": "00a826b4-8fc8-4273-b68f-5947f7d13795", + "origin": "Delegated (Power BI Service)", + "value": "WarehouseSnapshot.ReadWrite.All" + }, + { + "description": "Allows the app to have the same access to information in the directory as the signed-in user.", + "displayName": "Access the directory as the signed-in user", + "id": "a42657d6-7f20-40e3-b6f0-cee03008a62a", + "origin": "Delegated (Windows Azure Active Directory)", + "value": "Directory.AccessAsUser.All" + }, + { + "description": "Allows the app to read the memberships of hidden groups and administrative units without a signed-in user.", + "displayName": "Read all hidden memberships", + "id": "9728c0c4-a06b-4e0e-8d1b-3d694e8ec207", + "origin": "Application (Windows Azure Active Directory)", + "value": "Member.Read.Hidden" + }, + { + "description": "Allows the app to read M365 assets insights.", + "displayName": "Read M365 insights for Purview", + "id": "5a55b1b6-8996-4250-abc2-74ec0107ab20", + "origin": "Application (Purview Ecosystem)", + "value": "PurviewData.Read.All" + }, + { + "description": "Allows the user to call UploadActivity API.", + "displayName": "Purview UploadActivity API", + "id": "9d4a6836-0ce9-4bcd-9559-0399e6da09b9", + "origin": "Delegated (Purview Ecosystem)", + "value": "Purview.Activities.Upload.All" + }, + { + "description": "Allows content processing on behalf of user", + "displayName": "Purview ProcessContent API", + "id": "13f23ab3-b1fa-41f6-af62-b1afc79de846", + "origin": "Delegated (Purview Ecosystem)", + "value": "Purview.Content.Process.All" + }, + { + "description": "Allows an application to call ProcessContent API on behalf of a user", + "displayName": "Purview ProcessContent API", + "id": "5087908c-b26e-4cd3-afe9-12489ad60deb", + "origin": "Delegated (Purview Ecosystem)", + "value": "Purview.ProcessContent.All" + }, + { + "description": "Allows access to ProcessConversationMessages API.", + "displayName": "Purview ProcessConversationMessages API", + "id": "d4ed36df-1979-4939-aeec-4db91905c84d", + "origin": "Delegated (Purview Ecosystem)", + "value": "Purview.ProcessConversationMessages.All" + }, + { + "description": "Allows access to protection scopes on behalf of user", + "displayName": "Purview ProtectionScopes API", + "id": "2ecf07b4-8c46-4b2b-acd0-6635c0171fc0", + "origin": "Delegated (Purview Ecosystem)", + "value": "Purview.ProtectionScopes.Read.All" + }, + { + "description": "Allows access to Purview SensitivityLabels APIs", + "displayName": "Sensitivity Labels for Purview", + "id": "06e3dab0-0fcd-4186-a17c-8d7b7c66258e", + "origin": "Delegated (Purview Ecosystem)", + "value": "Purview.SensitivityLabels.All" + }, + { + "description": "Allows access to Purview File SensitivityLabels APIs", + "displayName": "File Sensitivity Labels for Purview", + "id": "6718b42b-dbde-438d-a9c2-c598144664ed", + "origin": "Delegated (Purview Ecosystem)", + "value": "Purview.SensitivityLabels.File" + }, + { + "description": "Allows access to Purview Read SensitivityLabels APIs", + "displayName": "Read Sensitivity Labels for Purview", + "id": "f6b3cb3b-702a-4280-bf39-558b85cbfca3", + "origin": "Delegated (Purview Ecosystem)", + "value": "Purview.SensitivityLabels.Read" + }, + { + "description": "This allows applications to call Quota Service APIs", + "displayName": "Call all Quota Service APIs", + "id": "b77e1667-c4c2-4be1-ab53-cc94767800ad", + "origin": "Application (Quota Core Service PROD)", + "value": "Qs.Api.All" + }, + { + "description": "Allows the application to access Sherlock Conversations API acting as users in the organization.", + "displayName": "Access Sherlock Conversations API as organization users", + "id": "1a8d204a-10fb-4da1-a303-17497f914fbc", + "origin": "Delegated (Sherlock)", + "value": "Conversations.Access" + }, + { + "description": "Allows apps to call ModernPostPurchaseProvisioning API", + "displayName": "ModernPostPurchaseProvisioning.Execute", + "id": "8339ddc4-fc04-4ad0-b7d5-b7d83667da93", + "origin": "Application (Signup)", + "value": "ModernPostPurchaseProvisioning.Execute" + }, + { + "description": "Allows the apps to create tenant, save tenant profile and add company tags", + "displayName": "Tenant.Create", + "id": "fca3dabc-fd9a-4d63-bc1f-196bfa2df787", + "origin": "Application (Signup)", + "value": "Tenant.Create" + }, + { + "description": "Allows the app to assign license for a product", + "displayName": "License.Assign", + "id": "8a82ad6b-9201-4f8e-a324-b97e0fcd3e46", + "origin": "Delegated (Signup)", + "value": "License.Assign" + }, + { + "description": "Allows the caller to perform low friction trial for the given user.", + "displayName": "LowFriction.ReadWrite", + "id": "0ec94f6b-7dfb-43d3-a076-648593587760", + "origin": "Delegated (Signup)", + "value": "LowFriction.ReadWrite" + }, + { + "description": "Allows the app to send distributed emails to impacted users post system outage", + "displayName": "Soar.SendEmail", + "id": "83e1ccc9-47d7-4632-8fbd-1a4392c87254", + "origin": "Delegated (Signup)", + "value": "Soar.SendEmail" + }, + { + "description": "Allows the app to add managed subscriptions to a tenant", + "displayName": "Add subscriptions", + "id": "dc13fe4e-f936-494b-8b88-09d4e9a5cde0", + "origin": "Delegated (Signup)", + "value": "Subscription.Add" + }, + { + "description": "Allows full access to UploadActivity API", + "displayName": "Upload Activity for Purview", + "id": "5c672fc5-9428-4b19-96d7-4fd10240c2c6", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.UploadActivity.All" + }, + { + "description": "Allows the caller to perform product signup eligibility check for the given user", + "displayName": "Users.Signup.Product", + "id": "62c3283a-e0b2-4608-85d5-013e99604063", + "origin": "Delegated (Signup)", + "value": "Users.Signup.Product" + }, + { + "description": "Allows the app access to Purview Read SensitivityLabels APIs", + "displayName": "Read Sensitivity Labels for Purview", + "id": "cba40051-8d05-45da-aa85-f6321b023c16", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.SensitivityLabels.Read" + }, + { + "description": "Allows the app access to Purview SensitivityLabels APIs", + "displayName": "Sensitivity Labels for Purview", + "id": "c79a7e98-4663-4e08-aaf4-cc6dfc36a524", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.SensitivityLabels.All" + }, + { + "description": "Allows the app to make API calls that commit workspace content and setting to remote git repository, on behalf of the signed-in user.", + "displayName": "Make API calls that commit workspace content and setting to remote git repository.", + "id": "a55d4405-a37a-4d41-ad6e-745665a3bbcb", + "origin": "Delegated (Power BI Service)", + "value": "Workspace.GitCommit.All" + }, + { + "description": "Allows the app to make API calls that update workspace content and setting from remote git repository, on behalf of the signed-in user.", + "displayName": "Make API calls that update workspace content and setting from remote git repository.", + "id": "5809ab1d-9154-49e7-a105-d82760eac8cf", + "origin": "Delegated (Power BI Service)", + "value": "Workspace.GitUpdate.All" + }, + { + "description": "The app can view all workspaces that the signed in user has access to.", + "displayName": "View all workspaces", + "id": "b2f1b2fa-f35c-407c-979c-a858a808ba85", + "origin": "Delegated (Power BI Service)", + "value": "Workspace.Read.All" + }, + { + "description": "The app can view and edit all workspaces that the signed in user has access to.", + "displayName": "Read and write all workspaces", + "id": "445002fb-a6f2-4dc1-a81e-4254a111cd29", + "origin": "Delegated (Power BI Service)", + "value": "Workspace.ReadWrite.All" + }, + { + "description": "Allow the app to access resources on behalf of the signed-in user.", + "displayName": "Access system data", + "id": "b9fa208e-7a07-49d9-9fe6-9ed353eec6c1", + "origin": "Delegated (Prod Messaging Catalog First Party App)", + "value": "access_as_user" + }, + { + "description": "Allows the app to call UploadActivity API.", + "displayName": "Call the UploadActivity API", + "id": "db90b932-4ee2-4549-8970-1932ef440310", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.Activities.Upload.All" + }, + { + "description": "Allows the app to request batch activities upload", + "displayName": "Call the BatchUploadActivity API", + "id": "13a61426-7aef-4d3e-aaaf-0c95062048ba", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.Activities.UploadBatch.All" + }, + { + "description": "Allows the app create access to data assets and metadata.", + "displayName": "Create Assets for Purview", + "id": "faadf052-bcc5-4045-9df6-11a3e217fb8e", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.Assets.Create" + }, + { + "description": "Allows the app delete access to data assets and metadata.", + "displayName": "Delete Assets for Purview", + "id": "f6893e92-b5aa-4634-870a-e2bc4d2d7fad", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.Assets.Delete" + }, + { + "description": "Allows the app read access to data assets and metadata.", + "displayName": "Read Assets for Purview", + "id": "04cd5d64-65c5-4dc5-9582-89bac29ed189", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.Assets.Read" + }, + { + "description": "Allows the app update access to data assets and metadata.", + "displayName": "Update Assets for Purview", + "id": "db52b997-83d6-4090-aea1-60858744d271", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.Assets.Update" + }, + { + "description": "Allows the app upsert access to data assets and metadata.", + "displayName": "Upsert Assets for Purview", + "id": "45b1a781-b80c-4a21-895c-5a6afb57efbf", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.Assets.Upsert" + }, + { + "description": "Allows the app to call the ProcessContent API", + "displayName": "Call the ProcessContent API", + "id": "fd2b47b4-2d6e-4abe-bd96-57cd37b899a5", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.Content.Process.All" + }, + { + "description": "Allows the app to request batch content processing", + "displayName": "Call the ProcessContentBatch API", + "id": "d0ccca8f-3f3b-44b4-914d-ce2e6a0d7edc", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.Content.ProcessBatch.All" + }, + { + "description": "Allows full access to ProcessContent API", + "displayName": "Process Content for Purview", + "id": "c4d09b20-ef57-4e63-9fd1-0392d5ce853d", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.ProcessContent.All" + }, + { + "description": "Allows full access to ProcessConversationMessages API", + "displayName": "Process Conversation Messages for Purview", + "id": "a4543e1f-6e5d-4ec9-a54a-f3b8c156163f", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.ProcessConversationMessages.All" + }, + { + "description": "Allows the app to read protection scopes", + "displayName": "Read Purview protection scopes", + "id": "7e2fc5f2-d647-4926-89f6-f13ad2950560", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.ProtectionScopes.Read.All" + }, + { + "description": "Allows the app access to Purview File SensitivityLabels APIs", + "displayName": "File Sensitivity Labels for Purview", + "id": "a817e1ed-b6e2-4214-a252-ab12ec7dad09", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.SensitivityLabels.File" + }, + { + "description": "Allows the app create an on-demand Skype meeting and join guest users into Skype for Business services", + "displayName": "Guest user join services (preview)", + "id": "b783bde8-ffc2-4f0c-96ce-6e2900b7aa4e", + "origin": "Application (Skype for Business Online)", + "value": "Anonymous" + }, + { + "description": "Allows the app to send and receive audio and video; and manage audio/video service scenarios", + "displayName": "Send/Receive Audio and Video (preview)", + "id": "05a4e3e8-cfa6-4934-bb91-b6fc4ce6f340", + "origin": "Application (Skype for Business Online)", + "value": "Conversations.AudioVideo" + }, + { + "description": "Allows the app to send and receive instant messages; and manage instant messaging service scenarios", + "displayName": "Send/Receive Instant Messages (preview)", + "id": "f7a521bb-ae17-42df-8096-97ebcc8b4edb", + "origin": "Application (Skype for Business Online)", + "value": "Conversations.Chat" + }, + { + "description": "Gives full access to the API", + "displayName": "full_access", + "id": "f4922361-5b56-4b3b-808f-a25115425e16", + "origin": "Delegated (Verifiable Credentials Service Admin)", + "value": "full_access" + }, + { + "description": "This allows the application to create Verifiable Credential issuance and presentation requests", + "displayName": "VerifiableCredential.Create.All", + "id": "949ebb93-18f8-41b4-b677-c2bfea940027", + "origin": "Application (Verifiable Credentials Service Request)", + "value": "VerifiableCredential.Create.All" + }, + { + "description": "This allows the application to create Verifiable Credential issuance requests", + "displayName": "VerifiableCredential.Create.IssueRequest", + "id": "0165bd66-5f36-41ef-abde-4e8fc0c91294", + "origin": "Application (Verifiable Credentials Service Request)", + "value": "VerifiableCredential.Create.IssueRequest" + }, + { + "description": "This allows the application to create Verifiable Credential presentation requests", + "displayName": "VerifiableCredential.Create.PresentRequest", + "id": "410607a4-22de-48a8-b35d-ad33c0c2e1bf", + "origin": "Application (Verifiable Credentials Service Request)", + "value": "VerifiableCredential.Create.PresentRequest" + }, + { + "description": "Allows user to create Verifiable Credential issuance requests.", + "displayName": "User Issuance", + "id": "b5aaa6fb-8c09-4929-877c-9147695b78b8", + "origin": "Delegated (Verifiable Credentials Service Request)", + "value": "VerifiableCredential.Create.IssueRequest.User" + }, + { + "description": "Allows the application to read and check MyAccount Verified ID eligibility on behalf of the signed-in user.", + "displayName": "Read MyAccount Verified ID eligibility", + "id": "438013ce-a6ed-4686-9a80-778b7d82e8ce", + "origin": "Delegated (Verifiable Credentials Service Request)", + "value": "VerifiedId.MyAccountEligibility.Read" + }, + { + "description": "Allows the partner app to read and write the properties of Cloud PCs, without a signed-in user.", + "displayName": "Partner read and write cloud pc", + "id": "c107831b-9c28-4609-b219-a7b3fc5cc190", + "origin": "Application (Windows 365)", + "value": "CloudPC.PartnerReadWrite.All" + }, + { + "description": "For IW service test", + "displayName": "EndUser.Access", + "id": "5184a2ce-115e-4318-9526-df3e39c2e839", + "origin": "Application (Windows 365)", + "value": "EndUser.Access" + }, + { + "description": "Allows the app to read applications and service principals without a signed-in user", + "displayName": "Read all applications", + "id": "3afa6a7d-9b1a-42eb-948e-1650a849e176", + "origin": "Application (Windows Azure Active Directory)", + "value": "Application.Read.All" + }, + { + "description": "Allows the app to create, read, update and delete applications and service principals without a signed-in user. Does not allow management of consent grants.", + "displayName": "Read and write all applications", + "id": "1cda74f2-2616-4834-b122-5cb1b07f8a59", + "origin": "Application (Windows Azure Active Directory)", + "value": "Application.ReadWrite.All" + }, + { + "description": "Allows the app to create other applications, and fully manage those applications (read, update, update application secrets and delete), without a signed-in user. It cannot update any apps that it is not an owner of.", + "displayName": "Manage apps that this app creates or owns", + "id": "824c81eb-e3f8-4ee6-8f6d-de7f50d565b7", + "origin": "Application (Windows Azure Active Directory)", + "value": "Application.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read and write all device properties without a signed in user. Does not allow device creation, device deletion or update of device alternative security identifiers.", + "displayName": "Read and write devices", + "id": "1138cb37-bd11-4084-a2b7-9f71582aeddb", + "origin": "Application (Windows Azure Active Directory)", + "value": "Device.ReadWrite.All" + }, + { + "description": "Allows the app to read and write all domain properties without a signed in user. Also allows the app to add, verify and remove domains.", + "displayName": "Read and write domains", + "id": "abefe9df-d5a9-41c6-a60b-27b38eac3efb", + "origin": "Application (Windows Azure Active Directory)", + "value": "Domain.ReadWrite.All" + }, + { + "description": "This allows  the application to search authorities and contracts in the VerifiedID network", + "displayName": "VerifiableCredential.Network.Read", + "id": "63f52f43-0b98-429c-b291-b2dba4a64504", + "origin": "Application (Verifiable Credentials Service Admin)", + "value": "VerifiableCredential.Network.Read" + }, + { + "description": "This allows the application to search credentials via Admin API", + "displayName": "VerifiableCredential.Credential.Search", + "id": "933a4159-27ca-4486-b1be-dce09da38475", + "origin": "Application (Verifiable Credentials Service Admin)", + "value": "VerifiableCredential.Credential.Search" + }, + { + "description": "This allows  the application to revoke credentials via Admin API", + "displayName": "VerifiableCredential.Credential.Revoke", + "id": "c7656015-9c77-47f7-ae83-110ad70f1edc", + "origin": "Application (Verifiable Credentials Service Admin)", + "value": "VerifiableCredential.Credential.Revoke" + }, + { + "description": "This allows the application to perform operations on contracts via Admin API", + "displayName": "VerifiableCredential.Contract.ReadWrite", + "id": "077813bc-e516-4576-bafd-07bead19c0dc", + "origin": "Application (Verifiable Credentials Service Admin)", + "value": "VerifiableCredential.Contract.ReadWrite" + }, + { + "description": "Allows the app to send and receive voice calls; and manage PSTN service scenarios", + "displayName": "Send/Receive PSTN (preview)", + "id": "30a91c70-863f-4a08-b01c-6c1d78685414", + "origin": "Application (Skype for Business Online)", + "value": "Conversations.PSTN" + }, + { + "description": "Allows the app to join and manage Skype meetings", + "displayName": "Join and Manage Skype Meetings (preview)", + "id": "e821ef97-a9f6-4c9e-bb6a-29fa0d8f6101", + "origin": "Application (Skype for Business Online)", + "value": "Meetings.JoinManage" + }, + { + "description": "Allows the app to create on-demand Skype meetings (short term expiry)", + "displayName": "Create on-demand Skype meetings (preview)", + "id": "189125ec-ea35-4135-b00a-e51472464beb", + "origin": "Application (Skype for Business Online)", + "value": "Meetings.ScheduleOnDemand" + }, + { + "description": "Allows the app to read and write Skype user contacts and groups\r\n", + "displayName": "Read/write Skype user contacts and groups", + "id": "5bdeff8b-73d9-4b8a-9e9b-d44c6105f9b4", + "origin": "Delegated (Skype for Business Online)", + "value": "Contacts.ReadWrite" + }, + { + "description": "Allows the app to initiate instant messages, audio, video, and desktop sharing conversations; and join meetings on-behalf of the signed-in user\r\n", + "displayName": "Initiate conversations and join meetings", + "id": "44e84b5a-52a3-4b41-975c-6c960414004a", + "origin": "Delegated (Skype for Business Online)", + "value": "Conversations.Initiate" + }, + { + "description": "Allows the app to receive instant messages, audio, video, and desktop sharing invitations on-behalf of the signed-in user\r\n", + "displayName": "Receive conversation invites (preview)", + "id": "4d48dea7-b534-4bca-9d76-5f8a7a8edae8", + "origin": "Delegated (Skype for Business Online)", + "value": "Conversations.Receive" + }, + { + "description": "Allows the app to create Skype meetings on-behalf of the signed-in user\r\n", + "displayName": "Create Skype Meetings", + "id": "d0c8f2ea-8f80-4289-8e78-4bc821cde1bc", + "origin": "Delegated (Skype for Business Online)", + "value": "Meetings.ReadWrite" + }, + { + "description": "Allows the app to read and update presence, photo, location, note, call forwarding settings of the signed-in user\r\n", + "displayName": "Read/write Skype user information (preview)", + "id": "208afe8f-9dfa-4f72-a755-6b810d61f42f", + "origin": "Delegated (Skype for Business Online)", + "value": "User.ReadWrite" + }, + { + "description": "Allows the app to read all your organization's policies without a signed-in user. ", + "displayName": "Read your organization's policies", + "id": "6c2d1b1d-a490-4178-ba6b-7efceda9129b", + "origin": "Application (Windows Azure Active Directory)", + "value": "Policy.Read.All" + }, + { + "description": "Allows the app to access the SQL Adx Proxy on behalf of the signed-in user.", + "displayName": "Access Sql Adx Proxy as user", + "id": "78ec75b3-3d15-4adb-bdc7-a8ab1f81e402", + "origin": "Delegated (SQL ADX Proxy)", + "value": "access_as_user" + }, + { + "description": "Allows reading basic user details", + "displayName": "user.read", + "id": "42ac4dc0-0862-4f71-89ed-85c8dca034a4", + "origin": "Delegated (Targeted Messaging Service)", + "value": "user.read" + }, + { + "description": "Allows access to the Azure API Center Data API service on behalf of the signed-in user", + "displayName": "Access Azure API Center Data API", + "id": "48f5e34f-bdfb-42e4-8da9-6519222a42ba", + "origin": "Delegated (TEST-Azure API Center)", + "value": "user_impersonation" + }, + { + "description": "Allows the app to call the Sentinel Platform service APIs on behalf of a user.", + "displayName": "Sentinel Platform Delegated API Access", + "id": "991a963a-4203-4dbc-acf2-254a258f76f2", + "origin": "Delegated (TEST-SecurityPlatform)", + "value": "SentinelPlatform.DelegatedAccess" + }, + { + "description": "Enables the application to perform trusted issuance of verifiable credentials.", + "displayName": "VerifiedCredentials.TrustedIssuance", + "id": "b4ebfa8b-750f-4993-8cf7-6a48fb98f13e", + "origin": "Application (Verifiable Credentials Service)", + "value": "VerifiedCredentials.TrustedIssuance" + }, + { + "description": "Allows the user to present access token during issuance", + "displayName": "Issuance.default", + "id": "1498e9cd-61d0-4068-b918-627d7ead8386", + "origin": "Delegated (Verifiable Credentials Service)", + "value": "issuance.default" + }, + { + "description": "This allows the application to perform read operations on authorities via Admin API", + "displayName": "VerifiableCredential.Authority.Read", + "id": "65499f04-0d5f-42ef-927e-6b4673fae3df", + "origin": "Application (Verifiable Credentials Service Admin)", + "value": "VerifiableCredential.Authority.Read" + }, + { + "description": "This allows the application to perform operations on authorities via Admin API", + "displayName": "VerifiableCredential.Authority.ReadWrite", + "id": "4ceb7a90-1485-40b1-accf-83a647694c0f", + "origin": "Application (Verifiable Credentials Service Admin)", + "value": "VerifiableCredential.Authority.ReadWrite" + }, + { + "description": "This allows the application to perform read operations on contracts via Admin API", + "displayName": "VerifiableCredential.Contract.Read", + "id": "24811a58-8ce0-4f09-a081-9ed0441ad3f2", + "origin": "Application (Verifiable Credentials Service Admin)", + "value": "VerifiableCredential.Contract.Read" + }, + { + "description": "PhysicalRP.ReadWrite", + "displayName": "PhysicalRP.ReadWrite", + "id": "da98d496-63c4-4eb4-b55c-19b2c584fca3", + "origin": "Delegated (StoreWebServices)", + "value": "PhysicalRP.ReadWrite" + }, + { + "description": "Allows the application to list and query any shared user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant on behalf of the signed-in user.", + "displayName": "Read all shared cross-tenant user profiles and export their data", + "id": "759dcd16-3c90-463c-937e-abf89f991c18", + "origin": "Delegated (Microsoft Graph)", + "value": "CrossTenantUserProfileSharing.Read.All" + }, + { + "description": " ", + "displayName": "DataAgent.Reshare (retired)", + "id": "82b1d51c-42df-4ba9-9aee-bbba1e3f2ab7", + "origin": "Delegated (Power BI Service)", + "value": "DataAgent.Reshare.All" + }, + { + "description": "Allows reading data agents on the user’s behalf.", + "displayName": "Read data agents", + "id": "40fa91d5-73ef-412c-a8c8-c8658670d0eb", + "origin": "Delegated (Power BI Service)", + "value": "DataAgent.Read.All" + }, + { + "description": "Allows the app to have send access to all mailboxes", + "displayName": "Application access for sending emails via SMTP AUTH", + "id": "7146a1f0-8703-45b3-9eae-527a64c00995", + "origin": "Application (Office 365 Exchange Online)", + "value": "SMTP.SendAsApp" + }, + { + "description": "Allows the app to read user tasks in all mailboxes without a signed-in user.", + "displayName": "Read user tasks in all mailboxes", + "id": "c1b0de0a-1de9-455d-919f-eca451053141", + "origin": "Application (Office 365 Exchange Online)", + "value": "Tasks.Read" + }, + { + "description": "Allows the app to create, read, update, and delete tasks in all mailboxes without a signed-in user.", + "displayName": "Read and write tasks in all mailboxes", + "id": "2c6a42ca-0d4d-49ad-bc0e-21222c449a65", + "origin": "Application (Office 365 Exchange Online)", + "value": "Tasks.ReadWrite" + }, + { + "description": "Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user.", + "displayName": "Read all users' full profiles", + "id": "bf24470f-10c1-436d-8d53-7b997eb473be", + "origin": "Application (Office 365 Exchange Online)", + "value": "User.Read.All" + }, + { + "description": "Allows the app to read a basic set of profile properties of other users in your organization on behalf of the signed-in user. This includes display name, first and last name, email address and photo.", + "displayName": "Read all users' basic profiles", + "id": "77e65b5a-ceae-48b3-9490-50a86a038a48", + "origin": "Application (Office 365 Exchange Online)", + "value": "User.ReadBasic.All" + }, + { + "description": "Allows the app to read events in user calendars.", + "displayName": "Read user calendars", + "id": "5b9be81f-2977-4d27-8faf-bb43af8fc705", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Calendars.Read" + }, + { + "description": "Allows the app to read events in all calendars that the user can access, including delegate and shared calendars.", + "displayName": "Read user and shared calendars ", + "id": "da710fc9-1e83-407b-8c5c-09d225031769", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Calendars.Read.All" + }, + { + "description": "Allows the app to read events in all calendars that the user can access, including delegate and shared calendars.", + "displayName": "Read user and shared calendars ", + "id": "c21d8660-9de1-4404-85b6-59695921bd8d", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Calendars.Read.Shared" + }, + { + "description": "Allows the app to create, read, update, and delete events in user calendars.", + "displayName": "Read and write user calendars", + "id": "765f423e-b55d-412e-97e3-13a800c3a537", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Calendars.ReadWrite" + }, + { + "description": "Allows the app to create, read, update and delete events in all calendars in the organization user has permissions to access. This includes delegate and shared calendars.", + "displayName": "Read and write user and shared calendars ", + "id": "bbd1ca91-75e0-4814-ad94-9c5dbbae3415", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Calendars.ReadWrite.All" + }, + { + "description": "Allows the app to create, read, update and delete events in all calendars in the organization user has permissions to access. This includes delegate and shared calendars.", + "displayName": "Read and write user and shared calendars", + "id": "4585ecca-5b47-432f-ac70-e1391e4951ed", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Calendars.ReadWrite.Shared" + }, + { + "description": "Allows the app to read user contacts.", + "displayName": "Read user contacts", + "id": "181aac24-028a-486e-a649-b3742c74ec71", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Contacts.Read" + }, + { + "description": "Allows the app to read contacts a user has permissions to access, including their own and shared contacts.", + "displayName": "Read user and shared contacts ", + "id": "d660a04c-7b62-4b4c-bea3-89226df00142", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Contacts.Read.All" + }, + { + "description": "Allows the app to read contacts a user has permissions to access, including their own and shared contacts.", + "displayName": "Read user and shared contacts ", + "id": "d6aa6fa9-3360-416a-b8db-021249d58e86", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Contacts.Read.Shared" + }, + { + "description": "Allows the app to create, read, update, and delete user contacts.", + "displayName": "Read and write user contacts", + "id": "32253599-e142-4cf0-810d-4827eedd1cfa", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Contacts.ReadWrite" + }, + { + "description": "Allows the app to create, read, update, and delete contacts a user has permissions to, including their own and shared contacts.", + "displayName": "Read and write user and shared contacts ", + "id": "44882612-f346-430a-b938-4f00ee1c77a7", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Contacts.ReadWrite.All" + }, + { + "description": "Allows the app to create, read, update, and delete contacts a user has permissions to, including their own and shared contacts.", + "displayName": "Read and write user and shared contacts ", + "id": "c54cba4f-60fe-4332-b0de-b5990fd1999e", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Contacts.ReadWrite.Shared" + }, + { + "description": "Download all reports via the Office 365 reporting web service", + "displayName": "ReportingWebService.Read.All", + "id": "b4d5a5c7-c085-487f-b922-ef0d6ebde6b1", + "origin": "Application (Office 365 Exchange Online)", + "value": "ReportingWebService.Read.All" + }, + { + "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange ActiveSync.", + "displayName": "Access mailboxes via Exchange ActiveSync", + "id": "266d2589-20b5-4f91-9a03-89247d1be8da", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "EAS.AccessAsUser.All" + }, + { + "description": "Allow application to access user’s mailbox via POP protocol", + "displayName": "POP.AccessAsApp", + "id": "cb842b43-da6e-4506-86fe-bb12199c656d", + "origin": "Application (Office 365 Exchange Online)", + "value": "POP.AccessAsApp" + }, + { + "description": "Allows the application to read and write tenant-wide people settings without a signed-in user.", + "displayName": "Read and write all tenant-wide people settings", + "id": "98ed40ef-611a-4479-bd35-eaa7863e946a", + "origin": "Application (Office 365 Exchange Online)", + "value": "PeopleSettings.ReadWrite.All" + }, + { + "description": "Allows the app to create, read, update, and delete events of all calendars without a signed-in user.", + "displayName": "Read and write calendars in all mailboxes", + "id": "ef54d2bf-783f-4e0f-bca1-3210c0444d99", + "origin": "Application (Office 365 Exchange Online)", + "value": "Calendars.ReadWrite.All" + }, + { + "description": "Allows the app to read all contacts in all mailboxes without a signed-in user.", + "displayName": "Read contacts in all mailboxes", + "id": "089fe4d0-434a-44c5-8827-41ba8a0b17f5", + "origin": "Application (Office 365 Exchange Online)", + "value": "Contacts.Read" + }, + { + "description": "Allows the app to create, read, update, and delete all contacts in all mailboxes without a signed-in user.", + "displayName": "Read and write contacts in all mailboxes", + "id": "6918b873-d17a-4dc1-b314-35f528134491", + "origin": "Application (Office 365 Exchange Online)", + "value": "Contacts.ReadWrite" + }, + { + "description": "Allows the app to manage a limited set of Exchange Online configuration objects without user interaction, for specific scenarios supported by the adminapi/v2.0 endpoint. To enable management actions an admin must also assign the appropriate Exchange RBAC roles directly to the app. This permission replaces the previous Exchange.ManageAsAppV2 permission.", + "displayName": "Manage Exchange Online Admin API as App", + "id": "95930782-af91-4e2e-89b7-e34ce33a0450", + "origin": "Application (Office 365 Exchange Online)", + "value": "Exchange.AdminAPI.ManageAsApp" + }, + { + "description": "Allows the app to manage the organization's Exchange environment without any user interaction. This includes mailboxes, groups, and other configuration objects. To enable management actions, an admin must assign the appropriate roles directly to the app.", + "displayName": "Manage Exchange As Application", + "id": "dc50a0fb-09a3-484d-be87-e023b12c6440", + "origin": "Application (Office 365 Exchange Online)", + "value": "Exchange.ManageAsApp" + }, + { + "description": "Allows the app to manage a limited set of Exchange Online configuration objects without user interaction, for specific scenarios supported by the adminapi/v2.0 endpoint. To enable management actions an admin must also assign the appropriate Exchange RBAC roles directly to the app.", + "displayName": "Manage Exchange as application v2", + "id": "ea3d980d-ebc7-4be4-8298-a167e5b8797c", + "origin": "Application (Office 365 Exchange Online)", + "value": "Exchange.ManageAsAppV2" + }, + { + "description": "Allows the app to have full access via Exchange Web Services to all mailboxes without a signed-in user.", + "displayName": "Use Exchange Web Services with full access to all mailboxes", + "id": "dc890d15-9560-4a4c-9b7f-a736ec74ec40", + "origin": "Application (Office 365 Exchange Online)", + "value": "full_access_as_app" + }, + { + "description": "Allow application to access user’s mailbox via IMAP protocol", + "displayName": "IMAP.AccessAsApp", + "id": "5e5addcd-3e8d-4e90-baf5-964efab2b20a", + "origin": "Application (Office 365 Exchange Online)", + "value": "IMAP.AccessAsApp" + }, + { + "description": "Allows the app to read mail in all mailboxes without a signed-in user.", + "displayName": "Read mail in all mailboxes", + "id": "810c84a8-4a9e-49e6-bf7d-12d183f40d01", + "origin": "Application (Office 365 Exchange Online)", + "value": "Mail.Read" + }, + { + "description": "Allows the app to create, read, update, and delete mail in all mailboxes without a signed-in user. Does not include permission to send mail.", + "displayName": "Read and write mail in all mailboxes", + "id": "e2a3a72e-5f79-4c64-b1b1-878b674786c9", + "origin": "Application (Office 365 Exchange Online)", + "value": "Mail.ReadWrite" + }, + { + "description": "Allows the app to send mail as any user without a signed-in user.", + "displayName": "Send mail as any user", + "id": "b633e1c5-b582-4048-a93e-9f11b44c7e96", + "origin": "Application (Office 365 Exchange Online)", + "value": "Mail.Send" + }, + { + "description": "Application permission grants permission to move mailboxes between Office365 organizations", + "displayName": "Move mailboxes between organizations", + "id": "f7264778-fba9-422d-8e9e-2675a2c4b513", + "origin": "Application (Office 365 Exchange Online)", + "value": "Mailbox.Migration" + }, + { + "description": "Allows the app to read user's mailbox settings without a signed-in user. Does not include permission to send mail.", + "displayName": "Read all user mailbox settings", + "id": "d45fa9f8-36e5-4cd2-b601-b063c7cf9ac2", + "origin": "Application (Office 365 Exchange Online)", + "value": "MailboxSettings.Read" + }, + { + "description": "Allows the app to create, read, update, and delete user's mailbox settings without a signed-in user. Does not include permission to send mail.", + "displayName": "Read and write all user mailbox settings", + "id": "f9156939-25cd-4ba8-abfe-7fabcf003749", + "origin": "Application (Office 365 Exchange Online)", + "value": "MailboxSettings.ReadWrite" + }, + { + "description": "Allows the app to read the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed SKUs and tenant branding information.", + "displayName": "Organization.Read.All", + "id": "15f260d6-f874-4366-8672-6b3658c5a09b", + "origin": "Application (Office 365 Exchange Online)", + "value": "Organization.Read.All" + }, + { + "description": "Allows the app to read and write the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed SKUs and tenant branding information.", + "displayName": "Organization.ReadWrite.All", + "id": "c976971c-a54d-4835-a240-2479e3dac74a", + "origin": "Application (Office 365 Exchange Online)", + "value": "Organization.ReadWrite.All" + }, + { + "description": "Allows the application to read tenant-wide people settings without a signed-in user.", + "displayName": "Read all tenant-wide people settings", + "id": "789ef6b5-4ecc-4f61-b6b3-66ef3109173c", + "origin": "Application (Office 365 Exchange Online)", + "value": "PeopleSettings.Read.All" + }, + { + "description": "Allows the app to read company places (conference rooms and room lists) for calendar events and other applications, without a signed-in user.", + "displayName": "Read all company places", + "id": "4830e04b-48ac-4de5-bbd9-8aceb58e506b", + "origin": "Application (Office 365 Exchange Online)", + "value": "Place.Read.All" + }, + { + "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange Web Services.", + "displayName": "Access mailboxes as the signed-in user via Exchange Web Services", + "id": "3b5f3d61-589b-4a3c-a359-5dd4b5ee5bd5", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "EWS.AccessAsUser.All" + }, + { + "description": "Allows the app to manage a limited set of Exchange Online configuration objects via the adminapi/v2.0 endpoint. This permission is intended for specific scenarios and requires appropriate Exchange RBAC role assignments. This permission replaces the previous Exchange.ManageV2 permission.", + "displayName": "Manage Exchange Online Admin API", + "id": "9f021f4d-e924-4317-bf46-8db5e8340c6c", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Exchange.AdminAPI.Manage" + }, + { + "description": "Allows the app to manage the organization's Exchange environment, such as mailboxes, groups, and other configuration objects. To enable management actions, an admin must assign the appropriate roles to the app user.", + "displayName": "Manage Exchange configuration", + "id": "ab4f2b77-0b06-4fc1-a9de-02113fc2ab7c", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Exchange.Manage" + }, + { + "description": "Allows the app to read and write the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed SKUs and tenant branding information.", + "displayName": "Organization.ReadWrite.All", + "id": "17f07f5d-fb80-4278-ba37-70ae04d476a3", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Organization.ReadWrite.All" + }, + { + "description": "Allows the app to read a ranked list of relevant people of the signed-in user. The list includes local contacts, contacts from social networking, your organization's directory, and people from recent communications (such as email and Skype).", + "displayName": "Read users' relevant people lists (preview)", + "id": "9478ac54-3753-4543-b95a-4fad24978902", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "People.Read" + }, + { + "description": "Allows the app to create, read and write to the ranked list of relevant people of the signed-in user. The list includes local contacts, contacts from social networking, your organization's directory, and people from recent communications (such as email and Skype).", + "displayName": "Read and write users' relevant people lists (preview)", + "id": "a88daf86-d44d-4077-8258-54131dd44e5d", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "People.ReadWrite" + }, + { + "description": "Allows the application to read tenant-wide people settings on behalf of the signed-in user.", + "displayName": "Read tenant-wide people settings", + "id": "e1eeeffa-b5a5-4b80-ae8f-ccb93d4b75eb", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "PeopleSettings.Read.All" + }, + { + "description": "Allows the application to read and write tenant-wide people settings on behalf of the signed-in user.", + "displayName": "Read and write tenant-wide people settings", + "id": "5430838e-68e7-4b12-b353-06478ace39c3", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "PeopleSettings.ReadWrite.All" + }, + { + "description": "Allows the app to read your company's places (conference rooms and room lists) for calendar events and other applications, on behalf of the signed-in user.", + "displayName": "Read all company places", + "id": "43ed0a33-2264-4716-b3bd-c5d8e248eebf", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Place.Read.All" + }, + { + "description": "Allows the app to have the same access to mailboxes as the signed-in user via POP protocol.", + "displayName": "Read and write access to your mail via POP", + "id": "fb698133-92fa-453e-a9ed-688e10f2e5ac", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "POP.AccessAsUser.All" + }, + { + "description": "Download reports via the Office 365 reporting web service", + "displayName": "ReportingWebService.Read", + "id": "bbbcc29c-7bd7-48f0-8c8b-ef5f9865b626", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "ReportingWebService.Read" + }, + { + "description": "Allows the app to be able to send emails from the user’s mailbox using the SMTP AUTH client submission protocol.", + "displayName": "Access to sending emails from your mailbox using SMTP AUTH", + "id": "76faac2a-0f20-42f1-928a-50de5b9dbe52", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "SMTP.Send" + }, + { + "description": "Allows the app to read user tasks", + "displayName": "Read user tasks", + "id": "8af8046f-5694-470f-91e4-d47ad05eda18", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Tasks.Read" + }, + { + "description": "Allows the app to read all tasks a user has access to", + "displayName": "Read all tasks a user has access to", + "id": "3d5e9942-27d3-4e96-80b1-696c7a3369c1", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Tasks.Read.Shared" + }, + { + "description": "Allows the app to create, read, update and delete user tasks ", + "displayName": "Create, read, update and delete user tasks ", + "id": "6b49b74d-642f-4417-a6b4-820576845707", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Tasks.ReadWrite" + }, + { + "description": "Allows the app to create, read, update and delete all tasks a user has access to", + "displayName": "Create, read, update and delete all tasks a user has access to", + "id": "2915e980-bca5-4194-9a3f-71c4ccdbd77b", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Tasks.ReadWrite.Shared" + }, + { + "description": "Allows the app to read a set of the current user's profile properties in your company or school. Includes display name, photo, and email address.", + "displayName": "Read user profiles", + "id": "6223a6d3-53ef-4f8f-982a-895b39483c61", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "User.Read" + }, + { + "description": "Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user.", + "displayName": "Read all users' full profiles", + "id": "eb665d05-7f76-4d1b-b176-1cfc814e668d", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "User.Read.All" + }, + { + "description": "Allows the app to read a basic set of profile properties of other users in your organization on behalf of the signed-in user. This includes display name, first and last name, email address and photo.", + "displayName": "Read all users' basic profiles", + "id": "9b005f11-86f0-45f7-8c27-4fff5d849916", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "User.ReadBasic.All" + }, + { + "description": "Allows the app to read a basic set of profile properties of users in your company or school on behalf of the signed-in user. Includes display name, photo, and email address.", + "displayName": "Read all users' basic profiles", + "id": "6222dbab-a24c-4210-9d91-2f47cf565614", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "User.ReadBasic.All" + }, + { + "description": "Allows the app to read the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed SKUs and tenant branding information.", + "displayName": "Organization.Read.All", + "id": "1d490c92-d2ca-4a30-b52e-6edf5f279f4d", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Organization.Read.All" + }, + { + "description": "This allows application to host MyDay Owa powered experience for shared mailbox and calendar", + "displayName": "OPX.MyDay.Shared", + "id": "405782ba-4062-4ea3-bd33-f7c731841e3b", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "OPX.MyDay.Shared" + }, + { + "description": "This allows application to host MyDay Owa powered experience for both user and shared mailbox and calendar", + "displayName": "OPX.MyDay.All", + "id": "d056cee4-aed2-4aa4-b2a9-292fe18b06d2", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "OPX.MyDay.All" + }, + { + "description": "This allows the application to host MyDay Owa powered experience", + "displayName": "OPX.MyDay", + "id": "8cac6046-ce43-4348-855c-efd9d956b7bf", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "OPX.MyDay" + }, + { + "description": "Allows the app to manage a limited set of Exchange Online configuration objects via the adminapi/v2.0 endpoint. This permission is intended for specific scenarios and requires appropriate Exchange RBAC role assignments.", + "displayName": "Manage Exchange configuration v2", + "id": "44d6b5f2-d42b-4fa7-b999-1c5fcab98e4d", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Exchange.ManageV2" + }, + { + "description": "Allows the app to read group properties on behalf of the signed-in user, and read group calendar and conversations on public groups and groups the signed in user is a member of.", + "displayName": "Read all groups (preview)", + "id": "b5c79e22-9bf2-42d7-b60d-1b95c11ebc66", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Group.Read.All" + }, + { + "description": "Allows the app to read group properties. Additionally allows the app to update group properties for groups the signed-in user owns. Also allows the app to read and write group calendar and conversations on public groups and groups the signed-in user is a member of.", + "displayName": "Read and write all groups (preview)", + "id": "27235839-268c-4d68-a668-351401ff623a", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Group.ReadWrite.All" + }, + { + "description": "Allows the app to have the same access to mailboxes as the signed-in user via IMAP protocol.", + "displayName": "Read and write access to your mail via IMAP", + "id": "195adc35-e27b-454b-a7ed-1ecdffa1c09f", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "IMAP.AccessAsUser.All" + }, + { + "description": "Allows the app to read email in user mailboxes.", + "displayName": "Read user mail", + "id": "185758ba-798d-4b72-9e54-429a413a2510", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Mail.Read" + }, + { + "description": "Allows the app to read mail a user can access, including their own and shared mail.", + "displayName": "Read user and shared mail ", + "id": "ad13ac2e-ad46-4dc0-b7da-249c94395a6d", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Mail.Read.All" + }, + { + "description": "Allows the app to read mail a user can access, including their own and shared mail.", + "displayName": "Read user and shared mail ", + "id": "1d894596-c906-42b1-8422-9360440c1c0c", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Mail.Read.Shared" + }, + { + "description": "Allows the app to read the signed-in user's mailbox except body, previewBody, attachments and any extended properties.", + "displayName": "Read user basic mail", + "id": "dab085de-3e14-432f-a47f-84b6457059c4", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Mail.ReadBasic" + }, + { + "description": "Allows the app to read events of all R without a signed-in user", + "displayName": "Read calendars in all mailboxes", + "id": "2dfdc6dc-2fa7-4a2c-a922-dbd4f85d17be", + "origin": "Application (Office 365 Exchange Online)", + "value": "Calendars.Read.All" + }, + { + "description": "Allows the app to create, read, update, and delete email in user mailboxes. Does not include permission to send mail.", + "displayName": "Read and write user mail", + "id": "75767999-c7a8-481e-a6b4-19458e0b30a5", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Mail.ReadWrite" + }, + { + "description": "Allows the app to create, read, update, and delete mail a user has permission to access, including their own and shared mail. Does not include permission to send mail.", + "displayName": "Read and write user and shared mail ", + "id": "b09ec548-3f99-4d0a-859c-c9b7ff53b7a9", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Mail.ReadWrite.Shared" + }, + { + "description": "Allows the app to send mail as users in the organization.", + "displayName": "Send mail as a user", + "id": "5eb43c10-865a-4259-960a-83946678f8dd", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Mail.Send" + }, + { + "description": "Allows the app to send mail as the signed-in user, including sending on-behalf of others.", + "displayName": "Send mail on behalf of others", + "id": "e843bc88-e493-446d-a73c-0ded7ff1913f", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Mail.Send.All" + }, + { + "description": "Allows the app to send mail as the signed-in user, including sending on-behalf of others.", + "displayName": "Send mail on behalf of others", + "id": "16572339-6149-452b-b084-280b01354687", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Mail.Send.Shared" + }, + { + "description": "Allows the app to read user's mailbox settings. Does not include permission to send mail.", + "displayName": "Read user mailbox settings ", + "id": "d36ad51d-15a2-458d-9b3a-16dbe4c51c30", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "MailboxSettings.Read" + }, + { + "description": "Allows the app to create, read, update, and delete user's mailbox settings. Does not include permission to send mail.", + "displayName": "Read and write user mailbox settings", + "id": "2e83d72d-8895-4b66-9eea-abb43449ab8b", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "MailboxSettings.ReadWrite" + }, + { + "description": "Allows the app to read user notes", + "displayName": "Read user notes", + "id": "505d82a7-24f3-4632-bffc-4d21625b31de", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Notes.Read" + }, + { + "description": "Allows the app to create, read, update and delete user notes", + "displayName": "Create, read, update and delete user notes", + "id": "1b69a6c3-108d-42d0-a3ec-fafcd610e80b", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Notes.ReadWrite" + }, + { + "description": "Allows the app to create, read, update, and delete mail a user has permission to access, including their own and shared mail. Does not include permission to send mail.", + "displayName": "Read and write user and shared mail ", + "id": "140e747e-90d3-4de0-8618-85a0cc7a1129", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Mail.ReadWrite.All" + }, + { + "description": "Allows the app to create, read, and write a set of the current user's profile properties in your company or school. Includes display name, photo, and email address.", + "displayName": "Read and write user profiles", + "id": "f9408c03-bd3d-48c4-8bee-17a72d20bd9c", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "User.ReadWrite" + }, + { + "description": "Allows the app to read events of all calendars without a signed-in user.", + "displayName": "Read calendars in all mailboxes", + "id": "798ee544-9d2d-430c-a058-570e29e34338", + "origin": "Application (Office 365 Exchange Online)", + "value": "Calendars.Read" + }, + { + "description": "A placeholder scope for preauth", + "displayName": "PreAuthPlaceholder", + "id": "25b4ea33-257e-47f5-b778-8df9c7e10548", + "origin": "Delegated (o365.servicecommunications.microsoft.com)", + "value": "PreAuthPlaceholder" + }, + { + "description": "Allows the application to call Purview APIs without a signed-in user", + "displayName": "Purview Application API Access", + "id": "8d48872e-7710-4001-bfd0-7dac15c28f69", + "origin": "Application (Microsoft Project Babylon)", + "value": "Purview.ApplicationAccess" + }, + { + "description": "Allows the application to call Purview APIs on behalf of a user", + "displayName": "Purview Delegated API Access", + "id": "817468d0-81dd-4cb5-94ac-07ca133fbbf6", + "origin": "Delegated (Microsoft Project Babylon)", + "value": "Purview.DelegatedAccess" + }, + { + "description": "Allow the application to sign in to Windows on behalf of the signed-in user", + "displayName": "Sign in to Windows", + "id": "dc5f2fe2-469e-48e9-87e5-6e48938b8789", + "origin": "Delegated (Microsoft Remote Desktop)", + "value": "user_impersonation" + }, + { + "description": "Allows the application to get or read all service configuration and log data", + "displayName": "Read all service configuration and log data for the Azure Information Protection service.", + "id": "e23bd57d-bfd5-4906-867f-89fb5ed8cd43", + "origin": "Application (Microsoft Rights Management Services)", + "value": "Application.Read.All" + }, + { + "description": "c", + "displayName": "Read protected content on behalf of a user", + "id": "7f740376-647b-4ad7-9ff7-292af252707a", + "origin": "Application (Microsoft Rights Management Services)", + "value": "Content.DelegatedReader" + }, + { + "description": "c", + "displayName": "Create protected content on behalf of a user", + "id": "d13f921c-7f21-4c08-bade-db9d048bd0da", + "origin": "Application (Microsoft Rights Management Services)", + "value": "Content.DelegatedWriter" + }, + { + "description": "c", + "displayName": "Read all protected content for this tenant", + "id": "7347eb49-7a1a-43c5-8eac-a5cd1d1c7cf0", + "origin": "Application (Microsoft Rights Management Services)", + "value": "Content.SuperUser" + }, + { + "description": "c", + "displayName": "Create protected content", + "id": "006e763d-a822-41fc-8df5-8d3d7fe20022", + "origin": "Application (Microsoft Rights Management Services)", + "value": "Content.Writer" + }, + { + "description": "Allow the application to use Azure Rights Management", + "displayName": "Create and access protected content for users", + "id": "c9c9a04d-3b66-4ca8-a00c-fca953e2afd3", + "origin": "Delegated (Microsoft Rights Management Services)", + "value": "user_impersonation" + }, + { + "description": "Allow the app to access Log Analytics on behalf of the signed-in user.", + "displayName": "Situational Awareness User Impersonation", + "id": "be810c4b-8598-4528-a3e3-1736473d6bf8", + "origin": "Delegated (Microsoft Sentinel Situational Awareness Workspace Access)", + "value": "UserImpersonation" + }, + { + "description": "Allows applications to read and write CPMC vocabularies for various tenants", + "displayName": "CustomerManagement.ReadWrite.CPMC", + "id": "6dc96d9f-75cd-4c03-a450-6bf81a89ad9e", + "origin": "Application (Microsoft Service Trust)", + "value": "CustomerManagement.ReadWrite.CPMC" + }, + { + "description": "Allows applications to read and write MMD vocabularies for various tenants", + "displayName": "CustomerManagement.ReadWrite.MMD", + "id": "1994c32e-87b9-46f9-a8b8-7daf25cd5a95", + "origin": "Application (Microsoft Service Trust)", + "value": "CustomerManagement.ReadWrite.MMD" + }, + { + "description": "Our app will be a one stop shop for current and prospective customers who need Security, Privacy, and Compliance information around Microsoft Cloud (Azure, Dynamics CRM Online and Office 365). It should be open any tenant who has AAD record – trial tenants as well as paid tenant across Microsoft Cloud. ", + "displayName": "Microsoft Service Trust", + "id": "50bf3dfa-9431-427d-823a-f146d9350034", + "origin": "Application (Microsoft Service Trust)", + "value": "TBD" + }, + { + "description": "Allows users to read and write Compliance Manager data.", + "displayName": "Read and write all Compliance Manager data", + "id": "05d808b8-d17a-47c9-ae7f-e20768cbad5d", + "origin": "Delegated (Microsoft Service Trust)", + "value": "ComplianceManager.ReadWrite.All" + }, + { + "description": "Allows users to read documents.", + "displayName": "Read all documents", + "id": "e808ab43-7555-447f-8b87-1d6a5c5038ef", + "origin": "Delegated (Microsoft Service Trust)", + "value": "Documents.Read.All" + }, + { + "description": "Our app will be a one stop shop for current and prospective customers who need Security, Privacy, and Compliance information around Microsoft Cloud (Azure, Dynamics CRM Online and Office 365). It should be open any tenant who has AAD record – trial tenants as well as paid tenant across Microsoft Cloud.", + "displayName": "Microsoft Service Trust", + "id": "b55dae21-0932-4324-a1cd-45a046d7a6e1", + "origin": "Delegated (Microsoft Service Trust)", + "value": "Trust.Content.All" + }, + { + "description": "Allows a client to access Premonition API on users behalf", + "displayName": "Access Premonition API", + "id": "33ee90e9-11ee-4949-81e2-b93e26b390d6", + "origin": "Delegated (Microsoft Premonition)", + "value": "All" + }, + { + "description": "Allows the app to run advanced hunting queries", + "displayName": "Run advanced hunting queries", + "id": "7734e8e5-8dde-42fc-b5ae-6eafea078693", + "origin": "Application (Microsoft Threat Protection)", + "value": "AdvancedHunting.Read.All" + }, + { + "description": "Allows for all operations of library resources", + "displayName": "Librarian", + "id": "59699edb-24d7-488d-a355-2b0e39dce24c", + "origin": "Application (Microsoft Premonition)", + "value": "Library.ReadWrite" + }, + { + "description": "Allows control plane operations of VNETs owned by the user", + "displayName": "VNET.ReadWrite", + "id": "9d4d9b26-9ecf-4796-ab43-702f556bc88c", + "origin": "Delegated (Microsoft Power Platform Service - PROD)", + "value": "VNET.ReadWrite" + }, + { + "description": "Directory.AccessAsUser.All", + "displayName": "Directory.AccessAsUser.All", + "id": "7757dd34-1b17-4123-afba-9bdbeeb48d1a", + "origin": "Delegated (Microsoft password reset service)", + "value": "Directory.AccessAsUser.All" + }, + { + "description": "Allow access the Office People API", + "displayName": "Access the Office People API", + "id": "de374d49-137d-465b-b4bb-ef2cec26583f", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "Calendar.Read" + }, + { + "description": "Allow access to chat messages via this API.", + "displayName": "Read chat messages (delegated)", + "id": "594a414c-f70a-4504-b1f6-f1b5a4c95b2f", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "Chat.Read" + }, + { + "description": "Allow access to read and send chat messages via this API.", + "displayName": "Read and write chat messages (delegated)", + "id": "20abcb3c-0462-42ce-9fa0-d1c97a22f4e5", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "Chat.ReadWrite" + }, + { + "description": "Allow access the Office People API", + "displayName": "Access the Office People API", + "id": "1c95d935-5ae8-4181-944c-746c8b105528", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "Files.Read" + }, + { + "description": "Allow access the Office People API", + "displayName": "Access the Office People API", + "id": "9beac4c9-e7ab-4507-9600-1f78e7d6097e", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "Files.ReadWrite" + }, + { + "description": "Allow access the Office People API", + "displayName": "Access the Office People API", + "id": "36e9a6a1-4901-4ea6-bf22-12fa030a7dda", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "Group.ReadWrite" + }, + { + "description": "Allow access the Office People API", + "displayName": "Access the Office People API", + "id": "de67d5fd-90b8-49f3-9ed1-d8010f5455a4", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "Insight.Read" + }, + { + "description": "Allow access the Office People API", + "displayName": "Access the Office People API", + "id": "b4ed7afe-ffaf-4a1c-ade1-91d29981e3bb", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "LLM.Read" + }, + { + "description": "Allow access the Office People API", + "displayName": "Access the Office People API", + "id": "75763f24-4303-4c58-a8b1-8e03ead9d770", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "Mail.Read" + }, + { + "description": "Allow access the Office People API", + "displayName": "Access the Office People API", + "id": "2e87e453-2fc7-45ee-947f-bf81dc7f0926", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "OnlineMeetings.Read" + }, + { + "description": "Allow access the Office People API", + "displayName": "Access the Office People API", + "id": "a248f402-c66c-43c5-87b7-f1bcb63d5541", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "Organization.Read" + }, + { + "description": "Allow client apps to read policy data via Loki.", + "displayName": "Loki Policy.Read", + "id": "1d28bd1f-7c1b-4e6b-bc5b-abc07323e7f2", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "Policy.Read" + }, + { + "description": "Allow access the Office People API", + "displayName": "Access the Office People API", + "id": "62e3da56-9c9b-4e31-a9bb-967b9a2b361f", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "User.Read" + }, + { + "description": "Access the Office People API", + "displayName": "Access to log on", + "id": "07c496ee-38d1-46df-b73d-45e1ff46d11e", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "User.Read.All" + }, + { + "description": "Allow access the Office People API", + "displayName": "Access the Office People API", + "id": "9eb61caf-4504-44c6-9d98-48e6a1ab8639", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "User.ReadWrite" + }, + { + "description": "Allows data plane access to all VNETs on the system", + "displayName": "VNET.Read.All", + "id": "e2159836-d709-4343-a518-8bb0e5744afa", + "origin": "Application (Microsoft Power Platform Service - PROD)", + "value": "VNET.Read.All" + }, + { + "description": "Allows reading library resources", + "displayName": "Visitor", + "id": "91fb9a45-6b1c-4d38-b915-4f1987a64c1c", + "origin": "Application (Microsoft Premonition)", + "value": "Library.Read" + }, + { + "description": "Allows the app to create or update any custom detection rule", + "displayName": "Read and write all custom detection rules", + "id": "a7deff90-e2f5-4e4e-83a3-2c74e7002e28", + "origin": "Application (Microsoft Threat Protection)", + "value": "CustomDetections.ReadWrite.All" + }, + { + "description": "Allows the app to read any incident", + "displayName": "Read all incidents", + "id": "a9790345-4595-42e4-971a-ccdc79f19b7c", + "origin": "Application (Microsoft Threat Protection)", + "value": "Incident.Read.All" + }, + { + "description": "Allows the app to create or update any incident", + "displayName": "Read and write all incidents", + "id": "8d90f441-09cf-4fdc-ab45-e874fa3a28e8", + "origin": "Application (Microsoft Threat Protection)", + "value": "Incident.ReadWrite.All" + }, + { + "description": "Allows the app to read and write MCP tools on behalf of the user.", + "displayName": "Read and write MCP tools", + "id": "e6b51422-0b88-40ba-8639-b7b0451665cb", + "origin": "Delegated (Microsoft_Azure_Support)", + "value": "Mcp.Tools.ReadWrite" + }, + { + "description": "Allows the app to perform support operations on behalf of the user", + "displayName": "Perform support operations for the user", + "id": "5f4c8442-eba3-4814-adca-42c6bb62590c", + "origin": "Delegated (Microsoft_Azure_Support)", + "value": "SupportAndTroubleshootOperations.All" + }, + { + "description": "Azure Storage Express service for customers to transfer large amount of data to their storage accounts using storage devices", + "displayName": "Azure Storage Express", + "id": "d6f965c1-8fd3-4bfd-b912-705922a79272", + "origin": "Application (MicrosoftStorageExpressPodAADApp)", + "value": "user_impersonation" + }, + { + "description": "Business Admins who can use application", + "displayName": "MDLAdminCenterRole.Admin", + "id": "ea358ccf-c4a8-48ac-8b94-2558ae2f7a5c", + "origin": "Application (MileIQ Admin Center)", + "value": "mdladmincenterrole.admin" + }, + { + "description": "This allows users to sign in to Spatial Maps", + "displayName": "mixedreality.signin", + "id": "326ee642-50a8-4c21-ba85-68887a9e84f3", + "origin": "Delegated (MRMaps PPE)", + "value": "mixedreality.signin" + }, + { + "description": "This allows users to sign in to Spatial Maps", + "displayName": "mixedreality.signin", + "id": "b0c501aa-3640-456a-961e-7c302c78bc91", + "origin": "Delegated (MRMapsProd)", + "value": "mixedreality.signin" + }, + { + "description": "Allows the app to read Defender RBAC and URBAC roles for a given identity.", + "displayName": "Read all Defender RBAC and URBAC roles and permissions", + "id": "1e95888a-4dde-464e-85df-8e8e7895a6f0", + "origin": "Application (MTP Unified RBAC)", + "value": "Defender.RBAC.Read.All" + }, + { + "description": "Role to use instead of user impersonation pre auth.", + "displayName": "user impersonation pre auth", + "id": "c40e2389-78db-4e82-8eca-d0b898970f73", + "origin": "Application (MTP Unified RBAC)", + "value": "UserImpersonation" + }, + { + "description": "This allows users to read workspaces", + "displayName": "workspace.read", + "id": "f05e1490-846d-4ed2-abcf-869977a8a09f", + "origin": "Delegated (My Apps)", + "value": "workspace.read" + }, + { + "description": "This allows users to modify workspaces", + "displayName": "workspace.write", + "id": "c1b318ae-a684-4c27-ab24-81350fb6a401", + "origin": "Delegated (My Apps)", + "value": "workspace.write" + }, + { + "description": "c", + "displayName": "AzureEventGridSecureWebhook", + "id": "c141600b-52f9-46b0-a3ad-5f3eb4890cc1", + "origin": "Application (Networking-MNC)", + "value": "AzureEventGridSecureWebhook" + }, + { + "description": "Allows apps to start and get status of transitions.", + "displayName": "Transitions.ReadWrite", + "id": "226ed26c-f1f6-46f4-8892-54c1d9569817", + "origin": "Application (O365 Demeter)", + "value": "Transitions.ReadWrite" + }, + { + "description": "Allows the pidl test application to access commerce api", + "displayName": "pidlsdktest.read", + "id": "ed05fd6e-dbd5-4815-b368-18c07b9acc1e", + "origin": "Delegated (O365 Demeter)", + "value": "pidlsdktest.read" + }, + { + "description": "This allows users to read proposals", + "displayName": "proposal.read", + "id": "59c7e161-b483-4c17-91db-1c8b632c90b1", + "origin": "Delegated (O365 Demeter)", + "value": "proposal.read" + }, + { + "description": "Allows callers to read subscriptions", + "displayName": "subscriptions.read", + "id": "b24afad3-a979-4f67-8e97-6da6301b3c2e", + "origin": "Delegated (O365 Demeter)", + "value": "subscriptions.read" + }, + { + "description": "This allows teams users to access HAPI", + "displayName": "teams", + "id": "e734da10-5e7c-48a0-a906-1a0d8b751264", + "origin": "Delegated (O365 Demeter)", + "value": "teams" + }, + { + "description": "Allow the application full access to the Azure Key Vault service on behalf of the signed-in user", + "displayName": "Have full access to Azure Service Bus service", + "id": "40e16207-c5fd-4916-8ca4-64565f2367ca", + "origin": "Delegated (Microsoft.ServiceBus)", + "value": "user_impersonation" + }, + { + "description": "Read Write Access To MDLRest APIs", + "displayName": "MDLRest.ReadWrite", + "id": "bd79113c-40b8-4608-8c47-994bf0c2853d", + "origin": "Delegated (Microsoft.MileIQ.RESTService)", + "value": "MDLRest.ReadWrite" + }, + { + "description": "Read Access To MDLRest APIs", + "displayName": "MDLRest.Read", + "id": "9b5904c8-49e7-4d21-81c0-118a2a9c7d81", + "origin": "Delegated (Microsoft.MileIQ.RESTService)", + "value": "MDLRest.Read" + }, + { + "description": "Allows the app to run advanced hunting queries, that the signed-in user can execute.", + "displayName": "Run advanced hunting queries", + "id": "15f11de4-5113-4268-a2d1-0bad43d781f9", + "origin": "Delegated (Microsoft Threat Protection)", + "value": "AdvancedHunting.Read" + }, + { + "description": "Allows the app to create or update any custom detection rule that the signed in user can", + "displayName": "Read and write custom detection rules", + "id": "ddbb8d0c-c86b-4ece-bcb7-0f031a9cf103", + "origin": "Delegated (Microsoft Threat Protection)", + "value": "CustomDetections.ReadWrite" + }, + { + "description": "Allows the app to read any incident that the signed in user can access", + "displayName": "Read incidents", + "id": "12c153a4-4204-4224-aa3c-4626e2f47c2b", + "origin": "Delegated (Microsoft Threat Protection)", + "value": "Incident.Read" + }, + { + "description": "Allows the app to create, read or update any incident that the signed in user can create, read or update", + "displayName": "Read and write incidents", + "id": "2af415cc-88cf-4146-a0c8-444c3a80d5db", + "origin": "Delegated (Microsoft Threat Protection)", + "value": "Incident.ReadWrite" + }, + { + "description": "Allow access to all serivce capabilities", + "displayName": "All", + "id": "9bd5ab7f-4031-4045-ace9-6bebbad202f6", + "origin": "Delegated (Microsoft Visual Studio Services API)", + "value": "all" + }, + { + "description": "Allow the application to delete feature flags on behalf of the signed-in user.", + "displayName": "Delete Feature Flags", + "id": "954b4156-78fb-4d19-94b0-41dc7b763e68", + "origin": "Delegated (Microsoft.Azconfig)", + "value": "FeatureFlag.Delete" + }, + { + "description": "Allow the application to read feature flags on behalf of the signed-in user.", + "displayName": "Read Feature Flags", + "id": "dd4449fe-4788-4656-b3f2-4f066e14478a", + "origin": "Delegated (Microsoft.Azconfig)", + "value": "FeatureFlag.Read" + }, + { + "description": "Allow the application to write feature flags on behalf of the signed-in user.", + "displayName": "Write Feature Flags", + "id": "f3cb665c-6320-4ae2-996d-b58707ade4c3", + "origin": "Delegated (Microsoft.Azconfig)", + "value": "FeatureFlag.Write" + }, + { + "description": "Allow the application full access to the OCM service on behalf of the signed-in user", + "displayName": "Have full access to the OCM Service ", + "id": "9454efbe-3f0a-4074-9ec5-a25adefb6f87", + "origin": "Delegated (O365SBRM Service)", + "value": "user_impersonation" + }, + { + "description": "Allow the application to delete key-values on behalf of the signed-in user.", + "displayName": "Delete Key-Values", + "id": "08eeff12-9b4a-4273-b3d9-ff8a13c32645", + "origin": "Delegated (Microsoft.Azconfig)", + "value": "KeyValue.Delete" + }, + { + "description": "Allow the application to write key-values on behalf of the signed-in user.", + "displayName": "Write Key-Values", + "id": "77967a14-4f88-4960-84da-e8f71f761ac2", + "origin": "Delegated (Microsoft.Azconfig)", + "value": "KeyValue.Write" + }, + { + "description": "Allow the application to perform snapshot actions, such as archive, on behalf of the signed-in user.", + "displayName": "Perform Snapshot Actions", + "id": "28bb462a-d940-4cbe-afeb-281756df9af8", + "origin": "Delegated (Microsoft.Azconfig)", + "value": "Snapshot.Action" + }, + { + "description": "Allow the application to read snapshots on behalf of the signed-in user.", + "displayName": "Read Snapshots", + "id": "5970d132-a862-421f-9352-8ed18f833d78", + "origin": "Delegated (Microsoft.Azconfig)", + "value": "Snapshot.Read" + }, + { + "description": "Allow the application to write snapshots on behalf of the signed-in user.", + "displayName": "Write Snapshots", + "id": "ea601552-5fd3-4792-9dfc-e85be5a6827c", + "origin": "Delegated (Microsoft.Azconfig)", + "value": "Snapshot.Write" + }, + { + "description": "To allow application to send notifications to Azure AD provisioning service", + "displayName": "Notifications.Write", + "id": "0d7005c0-855a-485a-9d5b-5676f80a4a04", + "origin": "Delegated (Microsoft.Azure.SyncFabric)", + "value": "Notifications.Write" + }, + { + "description": "Allow the application full access to the Azure Event Hubs service on behalf of the signed-in user", + "displayName": "Have full access to the Azure Event Hub service", + "id": "7d388411-3845-4cfc-aa69-33192f4b9735", + "origin": "Delegated (Microsoft.EventHubs)", + "value": "user_impersonation" + }, + { + "description": "MileIQ.All", + "displayName": "MileIQ.All", + "id": "d26f02bb-ae28-4375-9184-101879252b0f", + "origin": "Delegated (Microsoft.MileIQ.Dashboard)", + "value": "MileIQ.All" + }, + { + "description": "Allow the application to read key-values on behalf of the signed-in user.", + "displayName": "Read Key-Values", + "id": "8d17f7f7-030c-4b57-8129-cfb5a16433cd", + "origin": "Delegated (Microsoft.Azconfig)", + "value": "KeyValue.Read" + }, + { + "description": "Allows modifying data agents on the user’s behalf.", + "displayName": "Read and write data agents", + "id": "c23fda5c-561f-4890-ad72-5f57bb7496fd", + "origin": "Delegated (Power BI Service)", + "value": "DataAgent.ReadWrite.All" + }, + { + "description": "c", + "displayName": "activitydata.tenant.read", + "id": "ba4ca83c-e834-4e66-bfe1-df738f63b557", + "origin": "Application (Office 365 Information Protection)", + "value": "activitydata.tenant.read" + }, + { + "description": "This allows the app to read AirAdminAction alerts", + "displayName": "AirAdminAction.tenant.read", + "id": "cc02f7ae-3d9b-42c9-bc91-3424d92c5547", + "origin": "Application (Office 365 Information Protection)", + "value": "AirAdminAction.tenant.read" + }, + { + "description": "Allows the app to read the current user's enterprise resources.", + "displayName": "Read user project enterprise resources", + "id": "b8341dab-4143-49da-8eb9-3d8c073f9e77", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "EnterpriseResource.Read" + }, + { + "description": "Allows the app to read, create, update, and delete the current user’s enterprise resources.", + "displayName": "Read and write user project enterprise resources", + "id": "2511a087-5795-4cae-9123-d5b7d6ec4844", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "EnterpriseResource.Write" + }, + { + "description": "Allows the app to read migration data using the SharePoint admin site, on behalf of the signed-in user.", + "displayName": "Can view migration data from the admin site", + "id": "f569098d-1005-4cc6-a812-3bdccdcfbb98", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "Migration.Read.All" + }, + { + "description": "Allows the app to read and write migration data using the SharePoint admin site, on behalf of the signed-in user.", + "displayName": "Can view and edit migration data from the admin site", + "id": "1a50df37-8278-4139-9af3-3b60d57dd007", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "Migration.ReadWrite.All" + }, + { + "description": "Allows the app to read the current user's files.", + "displayName": "Read user files", + "id": "dd2c8d78-58e1-46d7-82dd-34d411282686", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "MyFiles.Read" + }, + { + "description": "Allows the app to read, create, update, and delete the current user's files.", + "displayName": "Read and write user files", + "id": "2cfdc887-d7b4-4798-9b33-3d98d6b95dd2", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "MyFiles.Write" + }, + { + "description": "Allows the app to read the current user's projects.", + "displayName": "Read user projects", + "id": "2beb830c-70d1-4f5b-a983-79cbdb0c6c6a", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "Project.Read" + }, + { + "description": "Allows the app to read, create, update, and delete the current users’ projects.", + "displayName": "Read and write user projects", + "id": "d75a7b17-f04e-40d9-8e35-79b949bdb891", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "Project.Write" + }, + { + "description": "Allows the app to have full control of all ProjectWebApp site collections the signed-in user.", + "displayName": "Have full control of all ProjectWebApp site collections", + "id": "e7e732bd-932b-45c4-8ce5-40d60a7daad9", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "ProjectWebApp.FullControl" + }, + { + "description": "Allows the app to read all OData reporting data from all ProjectWebApp site collections for the signed-in user.", + "displayName": "Read ProjectWebApp OData reporting data", + "id": "a4c14cd7-8bd6-4337-8e87-78623dfc023b", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "ProjectWebAppReporting.Read" + }, + { + "description": "Read, write and manage Cross-Tenant migration settings and tasks, on behalf of the signed-in user", + "displayName": "Read, write and manage Cross-Tenant migration settings and tasks", + "id": "5b625b3d-65b6-4fb0-85d9-8a5aa26bdf36", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "SharePointCrossTenantMigration.Manage.All" + }, + { + "description": "Read Cross-Tenant migration settings and tasks, on behalf of the signed-in user", + "displayName": "Read Cross-Tenant migration settings and tasks", + "id": "8d11884e-6820-4673-a5d6-64d2a68b311e", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "SharePointCrossTenantMigration.Read.All" + }, + { + "description": "Allows the application to read the tenant-level settings in SharePoint and OneDrive on behalf of the signed-in user.", + "displayName": "Read SharePoint and OneDrive tenant settings", + "id": "a9b72c67-36e4-4bef-b91f-dff5801f2270", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "SharePointTenantSettings.Read.All" + }, + { + "description": "Allows the application to read and change the tenant-level settings of SharePoint and OneDrive on behalf of the signed-in user.", + "displayName": "Read and change SharePoint and OneDrive tenant settings", + "id": "aef0f52b-5892-4590-ae2c-d3f7928bd577", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "SharePointTenantSettings.ReadWrite.All" + }, + { + "description": "Allows the app to run search queries and to read basic site info on behalf of the current signed-in user. Search results are based on the user's permissions instead of the app's permissions.", + "displayName": "Run search queries as a user", + "id": "1002502a-9a71-4426-8551-69ab83452fab", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "Sites.Search.All" + }, + { + "description": "Allows the app to access a subset of site collections with a signed-in user. The specific site collections and the permissions granted will be configured in SharePoint Online.", + "displayName": "Access selected site collections", + "id": "9ac4404a-0323-446d-b334-b4ae4d18b38a", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "Sites.Selected" + }, + { + "description": "Allows the app to read site collection metadata using the SharePoint admin site, on behalf of the signed-in user.", + "displayName": "Can view site collection metadata from the admin site", + "id": "ee5c91f0-be0b-463e-85c9-57f0514c3d29", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "SitesMetadataAdmin.Read.All" + }, + { + "description": "Allows the app to create, read, update, and delete documents and list items in all site collections on behalf of the signed-in user.", + "displayName": "Read and write items in all site collections", + "id": "640ddd16-e5b7-4d71-9690-3f4022699ee7", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "AllSites.Write" + }, + { + "description": "Allows the app to read and write site collection metadata using the SharePoint admin site, on behalf of the signed-in user.", + "displayName": "Can view and edit site collection metadata from the admin site", + "id": "9aaa3660-6678-4cb8-b4b5-be92b6f4fbf0", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "SitesMetadataAdmin.ReadWrite.All" + }, + { + "description": "Allows the app to read documents and list items in all site collections on behalf of the signed-in user.", + "displayName": "Read items in all site collections", + "id": "4e0d77b0-96ba-4398-af14-3baa780278f4", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "AllSites.Read" + }, + { + "description": "Allows the app to have full control of all site collections on behalf of the signed-in user.", + "displayName": "Have full control of all site collections", + "id": "56680e0d-d2a3-4ae1-80d8-3c4f2100e3d0", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "AllSites.FullControl" + }, + { + "description": "Read, write and manage Cross-Tenant migration settings and tasks, without a signed-in user", + "displayName": "Read, write and manage Cross-Tenant migration settings and tasks", + "id": "806d1b36-e37b-4f02-9c9e-a1269982b2aa", + "origin": "Application (Office 365 SharePoint Online)", + "value": "SharePointCrossTenantMigration.Manage.All" + }, + { + "description": "Read Cross-Tenant migration settings and tasks, without a signed-in user", + "displayName": "Read Cross-Tenant migration settings and tasks", + "id": "8cfb5122-1118-41e2-b9f2-8ab21a06c030", + "origin": "Application (Office 365 SharePoint Online)", + "value": "SharePointCrossTenantMigration.Read.All" + }, + { + "description": "Allows the application to read the tenant-level settings of SharePoint and OneDrive, without a signed-in user.", + "displayName": "Read SharePoint and OneDrive tenant settings", + "id": "e370eb8e-f9cc-499d-90cc-7da62103e4f3", + "origin": "Application (Office 365 SharePoint Online)", + "value": "SharePointTenantSettings.Read.All" + }, + { + "description": "Allows the application to read and change the tenant-level settings of SharePoint and OneDrive, without a signed-in user.", + "displayName": "Read and change SharePoint and OneDrive tenant settings", + "id": "85bd96b3-dd7e-44d4-94f4-47fbb58e5718", + "origin": "Application (Office 365 SharePoint Online)", + "value": "SharePointTenantSettings.ReadWrite.All" + }, + { + "description": "Allows the app to have full control of all site collections without a signed in user.", + "displayName": "Have full control of all site collections", + "id": "678536fe-1083-478a-9c59-b99265e6b0d3", + "origin": "Application (Office 365 SharePoint Online)", + "value": "Sites.FullControl.All" + }, + { + "description": "Allows the app to read, create, update, and delete document libraries and lists in all site collections without a signed in user.", + "displayName": "Read and write items and lists in all site collections", + "id": "9bff6588-13f2-4c48-bbf2-ddab62256b36", + "origin": "Application (Office 365 SharePoint Online)", + "value": "Sites.Manage.All" + }, + { + "description": "Allows the app to read documents and list items in all site collections without a signed in user.", + "displayName": "Read items in all site collections", + "id": "d13f72ca-a275-4b96-b789-48ebcc4da984", + "origin": "Application (Office 365 SharePoint Online)", + "value": "Sites.Read.All" + }, + { + "description": "Allows the app to create, read, update, and delete documents and list items in all site collections without a signed in user.", + "displayName": "Read and write items in all site collections", + "id": "fbcd29d2-fcca-4405-aded-518d457caae4", + "origin": "Application (Office 365 SharePoint Online)", + "value": "Sites.ReadWrite.All" + }, + { + "description": "Allow the application to access a subset of site collections without a signed in user. The specific site collections and the permissions granted will be configured in SharePoint Online.", + "displayName": "Access selected site collections", + "id": "20d37865-089c-4dee-8c41-6967602d4ac8", + "origin": "Application (Office 365 SharePoint Online)", + "value": "Sites.Selected" + }, + { + "description": "Allows the app to read site collection metadata without a signed-in user.", + "displayName": "Read access to site collection metadata on the SharePoint admin site", + "id": "1ee80186-f376-4677-b0be-fbad73a4a9ea", + "origin": "Application (Office 365 SharePoint Online)", + "value": "SitesMetadataAdmin.Read.All" + }, + { + "description": "Allows the app to read and write site collection metadata without a signed-in user.", + "displayName": "Read and write access to site collection metadata on the SharePoint admin site", + "id": "6d004c19-cc42-41ea-8888-cce2fc5bd2c5", + "origin": "Application (Office 365 SharePoint Online)", + "value": "SitesMetadataAdmin.ReadWrite.All" + }, + { + "description": "Allows the app to read tenant reports via the SharePoint admin site without a signed-in user.", + "displayName": "Read access to tenant report data on the SharePoint admin site", + "id": "3cc23ca2-bb9d-42cd-9802-f792b98bac3b", + "origin": "Application (Office 365 SharePoint Online)", + "value": "TenantReports.Read.All" + }, + { + "description": "Allows the app to read and write tenant reports via the SharePoint admin site without a signed-in user.", + "displayName": "Read and write access to tenant report data on the SharePoint admin site", + "id": "e512dd2e-d13a-4816-9202-d3ef0357c7b1", + "origin": "Application (Office 365 SharePoint Online)", + "value": "TenantReports.ReadWrite.All" + }, + { + "description": "Allows the app to read enterprise managed metadata and to read basic site info without a signed in user.", + "displayName": "Read managed metadata", + "id": "2a8d57a5-4090-4a41-bf1c-3c621d2ccad3", + "origin": "Application (Office 365 SharePoint Online)", + "value": "TermStore.Read.All" + }, + { + "description": "Allows the app to write enterprise managed metadata and to read basic site info without a signed in user.", + "displayName": "Read and write managed metadata", + "id": "c8e3537c-ec53-43b9-bed3-b2bd3617ae97", + "origin": "Application (Office 365 SharePoint Online)", + "value": "TermStore.ReadWrite.All" + }, + { + "description": "Allows the app to read user profiles without a signed in user.", + "displayName": "Read user profiles", + "id": "df021288-bdef-4463-88db-98f22de89214", + "origin": "Application (Office 365 SharePoint Online)", + "value": "User.Read.All" + }, + { + "description": "Allows the app to read and update user profiles and to read basic site info without a signed in user.", + "displayName": "Read and write user profiles", + "id": "741f803b-c850-494e-b5df-cde7c675a1ca", + "origin": "Application (Office 365 SharePoint Online)", + "value": "User.ReadWrite.All" + }, + { + "description": "Allows the app to read, create, update, and delete document libraries and lists in all site collections on behalf of the signed-in user.", + "displayName": "Read and write items and lists in all site collections", + "id": "b3f70a70-8a4b-4f95-9573-d71c496a53f4", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "AllSites.Manage" + }, + { + "description": "Allows the app to submit project task status updates the signed-in user.", + "displayName": "Submit project task status updates", + "id": "c4258712-0efb-41f1-b6bc-be58e4e32f3f", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "TaskStatus.Submit" + }, + { + "description": "Allows the app to read tenant reports via the SharePoint admin site, on behalf of the signed-in user.", + "displayName": "Can view tenant reports from the admin site", + "id": "97533022-c395-42ce-bcf7-7d554ac912fc", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "TenantReports.Read.All" + }, + { + "description": "Allows the app to read and write tenant reports via the SharePoint admin site, on behalf of the signed-in user.", + "displayName": "Can view and edit tenant reports from the admin site", + "id": "fb471c34-3a48-412f-969b-e2b9bc071042", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "TenantReports.ReadWrite.All" + }, + { + "description": "Allow the application full access to the Azure Key Vault service on behalf of the signed-in user.", + "displayName": "Have full access to the Azure Key Vault service", + "id": "2049d009-d5d1-4947-85ab-8b727def2427", + "origin": "Delegated (Power BI Service)", + "value": "Code.AccessAzureKeyvault.All" + }, + { + "description": "Allows the app to make API calls to access all Fabric resources, on behalf of signed-in user.", + "displayName": "Allow API calls to access all Fabric resources on behalf of signed-in user", + "id": "a66db2ff-fea7-40f3-8b63-2a35d6c5f753", + "origin": "Delegated (Power BI Service)", + "value": "Code.AccessFabric.All" + }, + { + "description": "This is for Azure SQL database and data warehouse access", + "displayName": "Access Azure SQL database and data warehouse", + "id": "a1999a26-9603-41b3-abf3-45698c57f620", + "origin": "Delegated (Power BI Service)", + "value": "Code.AccessSQL.All" + }, + { + "description": "Allow the application to access Azure Storage on behalf of the signed-in user.", + "displayName": "Access Azure Storage", + "id": "3f981b02-4cb2-4226-b4d2-c378f291573c", + "origin": "Delegated (Power BI Service)", + "value": "Code.AccessStorage.All" + }, + { + "description": "Allows the app to make API calls that require read permissions on all Fabric connections, on behalf of the signed-in user.", + "displayName": "Make API calls that require read permissions on all Fabric connections", + "id": "9ff18859-b8d5-4a89-9912-448b84dfb097", + "origin": "Delegated (Power BI Service)", + "value": "Connection.Read.All" + }, + { + "description": "Allows the app to make API calls that require read and write permissions on all Fabric connections, on behalf of the signed-in user.", + "displayName": "Make API calls that require read and write permissions on all Fabric connections", + "id": "3be8fe94-2189-4d8b-89c6-dd35c5cea6ef", + "origin": "Delegated (Power BI Service)", + "value": "Connection.ReadWrite.All" + }, + { + "description": " ", + "displayName": "Connection.Reshare (retired)", + "id": "346e63ff-7cb8-4d86-9f6b-c9212f86a719", + "origin": "Delegated (Power BI Service)", + "value": "Connection.Reshare.All" + }, + { + "description": "App can automatically create content and datasets for a user.", + "displayName": "Create content", + "id": "f3076109-ca66-412a-be10-d4ee1be95d47", + "origin": "Delegated (Power BI Service)", + "value": "Content.Create" + }, + { + "description": "Allows executing copy jobs on the user’s behalf.", + "displayName": "Execute copy jobs", + "id": "5de94f0e-625f-423b-a7e3-aa181fa938c7", + "origin": "Delegated (Power BI Service)", + "value": "CopyJob.Execute.All" + }, + { + "description": "Allows reading copy jobs on the user’s behalf.", + "displayName": "Read copy jobs", + "id": "fa6c6162-62d9-4f38-b83e-52a4a0382d00", + "origin": "Delegated (Power BI Service)", + "value": "CopyJob.Read.All" + }, + { + "description": "Allows modifying copy jobs on the user’s behalf.", + "displayName": "Read and write copy jobs", + "id": "615e36fa-c072-424a-a1f6-c098849fade9", + "origin": "Delegated (Power BI Service)", + "value": "CopyJob.ReadWrite.All" + }, + { + "description": " ", + "displayName": "CopyJob.Reshare (retired)", + "id": "840d81d1-e227-45e2-982c-e76ce6908b43", + "origin": "Delegated (Power BI Service)", + "value": "CopyJob.Reshare.All" + }, + { + "description": " ", + "displayName": "Dashboard.Execute (retired)", + "id": "bcd38192-b0a2-4c40-bc0e-5728ec6ee69d", + "origin": "Delegated (Power BI Service)", + "value": "Dashboard.Execute.All" + }, + { + "description": "Allows reading dashboards on the user’s behalf.", + "displayName": "Read dashboards", + "id": "2448370f-f988-42cd-909c-6528efd67c1a", + "origin": "Delegated (Power BI Service)", + "value": "Dashboard.Read.All" + }, + { + "description": "Allows modifying dashboards on the user’s behalf.", + "displayName": "Read and write dashboards", + "id": "b271f05e-8329-4b97-baa4-91cf15b99cf1", + "origin": "Delegated (Power BI Service)", + "value": "Dashboard.ReadWrite.All" + }, + { + "description": " ", + "displayName": "Dashboard.Reshare (retired)", + "id": "c67b16d3-b5b8-4c87-8ca0-a8e00c6d6ff3", + "origin": "Delegated (Power BI Service)", + "value": "Dashboard.Reshare.All" + }, + { + "description": "Allows executing data agents on the user’s behalf.", + "displayName": "Execute data agents", + "id": "c6756612-6853-4145-a661-90c1d045b2dc", + "origin": "Delegated (Power BI Service)", + "value": "DataAgent.Execute.All" + }, + { + "description": "Allow the application full access to the Azure Data Lake service on behalf of the signed-in user.", + "displayName": "Have full access to the Azure Data Lake service", + "id": "c655ab60-056e-4dd8-8cd0-6b5398bf6002", + "origin": "Delegated (Power BI Service)", + "value": "Code.AccessAzureDataLake.All" + }, + { + "description": "Allow the application to access Azure Data Explorer on behalf of the signed-in user.", + "displayName": "Access Azure Data Explorer", + "id": "eaf7943f-ddfe-4442-96af-9419cf9522f3", + "origin": "Delegated (Power BI Service)", + "value": "Code.AccessAzureDataExplorer.All" + }, + { + "description": "Allows reading Iceberg and Delta table catalog metadata from the external provider on the users behalf.", + "displayName": "Read Iceberg and Delta table catalog metadata from the provider", + "id": "debb9ba3-fb14-491a-884c-b4406ac079f5", + "origin": "Delegated (Power BI Service)", + "value": "CatalogMirroring.Read.All" + }, + { + "description": "Allows reading catalog on the user’s behalf.", + "displayName": "Read catalog", + "id": "c595891f-110c-4524-abce-fa7b97bc7c65", + "origin": "Delegated (Power BI Service)", + "value": "Catalog.Read.All" + }, + { + "description": "Allows the app to read managed metadata and to read basic site info on behalf of the signed-in user.", + "displayName": "Read managed metadata", + "id": "a468ea40-458c-4cc2-80c4-51781af71e41", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "TermStore.Read.All" + }, + { + "description": "Allows the app to read, create, update, and delete managed metadata and to read basic site info on behalf of the signed-in user.", + "displayName": "Read and write managed metadata", + "id": "59a198b5-0420-45a8-ae59-6da1cb640505", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "TermStore.ReadWrite.All" + }, + { + "description": "Allows the app to read user profiles and to read basic site info on behalf of the signed-in user.", + "displayName": "Read user profiles", + "id": "0cea5a30-f6f8-42b5-87a0-84cc26822e02", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "User.Read.All" + }, + { + "description": "Allows the app to read and update user profiles and to read basic site info on behalf of the signed-in user.", + "displayName": "Read and write user profiles", + "id": "82866913-39a9-4be7-8091-f4fa781088ae", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "User.ReadWrite.All" + }, + { + "description": "Allow app to read properties of jobs submitted to eDiscovery.", + "displayName": "eDiscovery.Jobs.Read", + "id": "0f062bc7-6f95-469a-810f-d846e6cbba44", + "origin": "Application (Office365 Zoom)", + "value": "eDiscovery.Jobs.Read" + }, + { + "description": "Allow app to submit jobs to eDiscovery.", + "displayName": "eDiscovery.Jobs.Write", + "id": "5faac7a2-ab08-4049-aece-ab2b4de5f59e", + "origin": "Application (Office365 Zoom)", + "value": "eDiscovery.Jobs.Write" + }, + { + "description": "Allow app to access compliance connector", + "displayName": "Connector.Read", + "id": "06d98eed-6e1d-47d1-af81-f69ca60a0e97", + "origin": "Delegated (Office365 Zoom)", + "value": "Connector.Read" + }, + { + "description": "Allow app to download the ediscovery exported data", + "displayName": "eDiscovery.Export.Download", + "id": "df0d2e21-1705-4006-b158-1114609fdfbd", + "origin": "Delegated (Office365 Zoom)", + "value": "eDiscovery.Export.Download" + }, + { + "description": "Allow the application to provision OneDrive for Business drives for users in the tenant, without a signed-in user.", + "displayName": "Provision OneDrive for Business drives without a signed-in user.", + "id": "7689db6e-2939-41b4-98b7-13c05a52bcd6", + "origin": "Application (Office 365 SharePoint Online)", + "value": "OneDrive.Provision.All" + }, + { + "description": "Legacy scope used by Office Client", + "displayName": "user_impersonation", + "id": "4003e653-ac3b-43c3-af2c-a49553838842", + "origin": "Delegated (OfficeClientService)", + "value": "user_impersonation" + }, + { + "description": "Allows the app to read a set of the current user’s profile properties in your company or school. Includes display name, photo, and email address.", + "displayName": "Read user profiles", + "id": "6b0a3177-0946-453c-95bf-1d7b1886f0e4", + "origin": "Delegated (OneProfile Service)", + "value": "User.Read" + }, + { + "description": "Allow full access to the Microsoft Authorization Service on behalf of the signed-in user", + "displayName": "Have full access to the Microsoft Authorization Service", + "id": "e1e4ebc7-1bb4-4ccc-8394-895d471ba1a7", + "origin": "Delegated (Policy Administration Service)", + "value": "user_impersonation" + }, + { + "description": "The app can view all content in the tenant without a signed in user.", + "displayName": "View all content in tenant", + "id": "654b31ae-d941-4e22-8798-7add8fdf049f", + "origin": "Application (Power BI Service)", + "value": "Tenant.Read.All" + }, + { + "description": "The app can create, edit, view, and delete all content in the tenant without a signed in user.", + "displayName": "Read and write all content in tenant", + "id": "28379fa9-8596-4fd9-869e-cb60a93b5d84", + "origin": "Application (Power BI Service)", + "value": "Tenant.ReadWrite.All" + }, + { + "description": "The app can view all Power BI apps the signed in user has access to.", + "displayName": "View all Power BI apps", + "id": "8b01a991-5a5a-47f8-91a2-84d6bfd72c02", + "origin": "Delegated (Power BI Service)", + "value": "App.Read.All" + }, + { + "description": "The app can view all Power BI Premium and Power BI Embedded capacities that the signed in user has access to.", + "displayName": "View all capacities", + "id": "76e2ebd5-0dfb-4a5b-93c7-ed89e0362834", + "origin": "Delegated (Power BI Service)", + "value": "Capacity.Read.All" + }, + { + "description": "The app can view and edit all Power BI Premium and Power BI Embedded capacities that the signed in user has access to.", + "displayName": "Read and write all capacities", + "id": "4eabc3d1-b762-40ff-9da5-0e18fdf11230", + "origin": "Delegated (Power BI Service)", + "value": "Capacity.ReadWrite.All" + }, + { + "description": "c", + "displayName": "AggConsumptionBillingReport.Read.All", + "id": "f9d2daf6-8028-48d1-b4c1-b963f7ae7a73", + "origin": "Application (Office 365 Information Protection)", + "value": "AggConsumptionBillingReport.Read.All" + }, + { + "description": "Allows the app to read and write migration data via the SharePoint admin site without a signed-in user.", + "displayName": "Read and write access to migration data on the SharePoint admin site", + "id": "dfe5a59c-77fe-436b-9a47-375a284cf302", + "origin": "Application (Office 365 SharePoint Online)", + "value": "Migration.ReadWrite.All" + }, + { + "description": "Allows the app to search across sharepoint content. This is used for 3S unfurl route.", + "displayName": "Search across the users office content", + "id": "2aec0168-f9e2-4ce1-bb0f-1145f35f5a60", + "origin": "Delegated (Office 365 Search Service)", + "value": "SubstrateSearchServiceFiles.ReadAll" + }, + { + "description": "This allows apps to read the MtpAction", + "displayName": "MtpAction.tenant.read", + "id": "86e9643d-f798-40d2-98bb-293a7daaa2d7", + "origin": "Application (Office 365 Information Protection)", + "value": "MtpAction.tenant.read" + }, + { + "description": "This allows apps to write the MtpAction", + "displayName": "MtpAction.tenant.write", + "id": "e6e79fef-f4ee-4f93-aec3-3f0001087066", + "origin": "Application (Office 365 Information Protection)", + "value": "MtpAction.tenant.write" + }, + { + "description": "c", + "displayName": "MtpMailboxRuleAction.tenant.read", + "id": "ca69fdfa-5ba6-4c33-9eac-013653c2c3af", + "origin": "Application (Office 365 Information Protection)", + "value": "MtpMailboxRuleAction.tenant.read" + }, + { + "description": "c", + "displayName": "MtpMailboxRuleAction.tenant.write", + "id": "5f124282-d2c3-47dd-87ff-106ba9aa079b", + "origin": "Application (Office 365 Information Protection)", + "value": "MtpMailboxRuleAction.tenant.write" + }, + { + "description": "Allow o365 applications to read MTP Status", + "displayName": "mtpstatus.tenant.read", + "id": "74450f94-a5b1-4243-a991-9a688375883f", + "origin": "Application (Office 365 Information Protection)", + "value": "mtpstatus.tenant.read" + }, + { + "description": "c", + "displayName": "OcrBillingConfiguration-Internal.Write.All", + "id": "a585dd3a-70b6-4ff4-a1b9-093b4214e7e4", + "origin": "Application (Office 365 Information Protection)", + "value": "OcrBillingConfiguration-Internal.Write.All" + }, + { + "description": "This allows apps to read the OneCyberRelocationData", + "displayName": "OneCyberRelocationData.tenant.read", + "id": "9b31c028-bb6a-4d1a-8295-4514d184c061", + "origin": "Application (Office 365 Information Protection)", + "value": "OneCyberRelocationData.tenant.read" + }, + { + "description": "This allows apps to write the OneCyberRelocationData", + "displayName": "OneCyberRelocationData.tenant.write", + "id": "03f3ead7-60e6-4522-847b-8a67bb9c50df", + "origin": "Application (Office 365 Information Protection)", + "value": "OneCyberRelocationData.tenant.write" + }, + { + "description": "c", + "displayName": "PolicyStatusSummary-Internal.Write.All", + "id": "6c68db0a-4608-48d3-b0bf-4d0917b88bef", + "origin": "Application (Office 365 Information Protection)", + "value": "PolicyStatusSummary-Internal.Write.All" + }, + { + "description": "c", + "displayName": "Purview.DataAccess.All", + "id": "67a4e76f-5125-4b64-bcd6-b42a60d47dbe", + "origin": "Application (Office 365 Information Protection)", + "value": "Purview.DataAccess.All" + }, + { + "description": "c", + "displayName": "QuarantinedMessage.Read.All", + "id": "3e4e080e-55db-4fa9-8d68-0d9199d4c792", + "origin": "Application (Office 365 Information Protection)", + "value": "QuarantinedMessage.Read.All" + }, + { + "description": "c", + "displayName": "Recipient.tenant.read", + "id": "81eac90b-5b5b-422f-8d2a-9bc2055c5453", + "origin": "Application (Office 365 Information Protection)", + "value": "Recipient.tenant.read" + }, + { + "description": "c", + "displayName": "Recipient.tenant.write", + "id": "7b67f132-5c43-45cb-8cc3-e78fd80d0776", + "origin": "Application (Office 365 Information Protection)", + "value": "Recipient.tenant.write" + }, + { + "description": "c", + "displayName": "RecipientBatch.tenant.write", + "id": "39de55cd-e81d-4d2a-880d-3872c4fb992d", + "origin": "Application (Office 365 Information Protection)", + "value": "RecipientBatch.tenant.write" + }, + { + "description": "this allows to read reducedrecipient", + "displayName": "reducedrecipient.read.all", + "id": "24c052b7-e297-4369-b344-e4b62baa3fca", + "origin": "Application (Office 365 Information Protection)", + "value": "reducedrecipient.read.all" + }, + { + "description": "c", + "displayName": "Relocation.ReadWrite.All", + "id": "092afc53-fa1b-44c3-9fdf-46fcd25a5d99", + "origin": "Application (Office 365 Information Protection)", + "value": "Relocation.ReadWrite.All" + }, + { + "description": "c", + "displayName": "RemediationEmailResult.Read.All", + "id": "cae0e51f-af85-4f35-870d-9f024147648d", + "origin": "Application (Office 365 Information Protection)", + "value": "RemediationEmailResult.Read.All" + }, + { + "description": "c", + "displayName": "MessageTraceDetail.tenant.read", + "id": "85e837d7-9e4b-4bb2-9535-08bb51aa974a", + "origin": "Application (Office 365 Information Protection)", + "value": "MessageTraceDetail.tenant.read" + }, + { + "description": "c", + "displayName": "RemediationEmailResult.ReadWrite.All", + "id": "dac43cb8-9b13-43b1-bc17-e7eb8fe26717", + "origin": "Application (Office 365 Information Protection)", + "value": "RemediationEmailResult.ReadWrite.All" + }, + { + "description": "c", + "displayName": "MessageTrace.Read.All", + "id": "06ab0d31-7112-476e-a479-66394bec63d6", + "origin": "Application (Office 365 Information Protection)", + "value": "MessageTrace.Read.All" + }, + { + "description": "c", + "displayName": "M365ContentExplorer.Read.All", + "id": "26872368-3756-4995-a1d0-73cfa9d8f83a", + "origin": "Application (Office 365 Information Protection)", + "value": "M365ContentExplorer.Read.All" + }, + { + "description": "This allows apps to write the AirAdminAction alerts", + "displayName": "AirAdminAction.tenant.write", + "id": "43f2aa58-36d7-421e-8628-fbe9b129bf76", + "origin": "Application (Office 365 Information Protection)", + "value": "AirAdminAction.tenant.write" + }, + { + "description": "c", + "displayName": "Alert.Read.All", + "id": "43e3dfa5-222e-4a48-8253-d36086c5558c", + "origin": "Application (Office 365 Information Protection)", + "value": "Alert.Read.All" + }, + { + "description": "This allows to read tenant Office 365 alerts.", + "displayName": "alert.tenant.read", + "id": "d91202fb-0f5f-4245-8148-dfe12af913e6", + "origin": "Application (Office 365 Information Protection)", + "value": "alert.tenant.read" + }, + { + "description": "This allows to change any Office 365 alerts belong to the tenant.", + "displayName": "alert.tenant.write", + "id": "723c28f9-60b9-4cd4-8b04-6d344a3c4d84", + "origin": "Application (Office 365 Information Protection)", + "value": "alert.tenant.write" + }, + { + "description": "c", + "displayName": "AttackSimulationData.tenant.read", + "id": "06c43929-37aa-4707-ae05-68d6d967953e", + "origin": "Application (Office 365 Information Protection)", + "value": "AttackSimulationData.tenant.read" + }, + { + "description": "c", + "displayName": "AuditProvisioningData.Tenant.Read", + "id": "9760b448-d4d4-478b-bebc-0ebe62c935c9", + "origin": "Application (Office 365 Information Protection)", + "value": "AuditProvisioningData.Tenant.Read" + }, + { + "description": "c", + "displayName": "AzureActivityData.Read.All", + "id": "926c05c5-5941-491b-973a-509c2a4a2542", + "origin": "Application (Office 365 Information Protection)", + "value": "AzureActivityData.Read.All" + }, + { + "description": "c", + "displayName": "compliancestatus.tenant.read", + "id": "59c90462-e42e-4698-8a51-196ebd407166", + "origin": "Application (Office 365 Information Protection)", + "value": "compliancestatus.tenant.read" + }, + { + "description": "c", + "displayName": "CustomTag.Tenant.Read", + "id": "e0ba9b2a-a247-4d95-bca6-43211b61057f", + "origin": "Application (Office 365 Information Protection)", + "value": "CustomTag.Tenant.Read" + }, + { + "description": "c", + "displayName": "CustomTag.Tenant.Write", + "id": "92b5621e-0e43-46c9-b830-bc26b325a150", + "origin": "Application (Office 365 Information Protection)", + "value": "CustomTag.Tenant.Write" + }, + { + "description": "c", + "displayName": "DataInsightsSubscription.tenant.read", + "id": "bfeb98e9-5067-42b0-a7df-9022b927a10e", + "origin": "Application (Office 365 Information Protection)", + "value": "DataInsightsSubscription.tenant.read" + }, + { + "description": "c", + "displayName": "DataInsightsSubscription.tenant.write", + "id": "182f95e9-8c6f-4c32-8de2-e1abc1fe6ea4", + "origin": "Application (Office 365 Information Protection)", + "value": "DataInsightsSubscription.tenant.write" + }, + { + "description": "c", + "displayName": "DataInsightsUsersData.tenant.read", + "id": "0eabd45c-e771-460d-a601-2d534e78a1be", + "origin": "Application (Office 365 Information Protection)", + "value": "DataInsightsUsersData.tenant.read" + }, + { + "description": "c", + "displayName": "DynamicRiskPreventionTag.Tenant.Read", + "id": "f63db487-96bf-49af-8a79-faa86287aee6", + "origin": "Application (Office 365 Information Protection)", + "value": "DynamicRiskPreventionTag.Tenant.Read" + }, + { + "description": "c", + "displayName": "DynamicRiskPreventionTag.Tenant.Write", + "id": "15188c9e-7879-4e83-9d63-c728da8feb0d", + "origin": "Application (Office 365 Information Protection)", + "value": "DynamicRiskPreventionTag.Tenant.Write" + }, + { + "description": "c", + "displayName": "EopDataInsights.AccessAsApp", + "id": "cfbd1345-3cf0-408c-8c99-1491bde7ce52", + "origin": "Application (Office 365 Information Protection)", + "value": "EopDataInsights.AccessAsApp" + }, + { + "description": "c", + "displayName": "InsiderRiskData.Read.All", + "id": "57fee0bb-e97d-4e5c-a663-2b0c7ce0db37", + "origin": "Application (Office 365 Information Protection)", + "value": "InsiderRiskData.Read.All" + }, + { + "description": "This scope allows Apps to read tenant's MessageEventSummary data", + "displayName": "messageeventsummary.tenant.read", + "id": "51aa070e-cc8b-45a9-8530-3fc96b0aa701", + "origin": "Application (Office 365 Information Protection)", + "value": "messageeventsummary.tenant.read" + }, + { + "description": "This allows to change RoleGroupMember to the tenant", + "displayName": "RoleGroupMember.tenant.write", + "id": "abe60d99-0a67-4250-afc0-290614d84b41", + "origin": "Application (Office 365 Information Protection)", + "value": "RoleGroupMember.tenant.write" + }, + { + "description": "c", + "displayName": "TenantLicenseStatus.Read.All", + "id": "27787a44-0423-4f0d-a417-1276c93397fb", + "origin": "Application (Office 365 Information Protection)", + "value": "TenantLicenseStatus.Read.All" + }, + { + "description": "c", + "displayName": "ThreatSubmission.ReadWrite.All", + "id": "944c8d5a-fdcd-4aac-af4d-3366942700d5", + "origin": "Application (Office 365 Information Protection)", + "value": "ThreatSubmission.ReadWrite.All" + }, + { + "description": "Allows the application to read service health information for your organization.", + "displayName": "Read activity reports for your organization", + "id": "825c9d21-ba03-4e97-8007-83f020ff8c0f", + "origin": "Application (Office 365 Management APIs)", + "value": "Deprecated_ActivityReports.Read" + }, + { + "description": "Allows the application to read threat intelligence data for your organization", + "displayName": "Read threat intelligence data for your organization", + "id": "69784729-33e3-471d-b130-744ce05343e5", + "origin": "Application (Office 365 Management APIs)", + "value": "Deprecated_ThreatIntelligence.Read" + }, + { + "description": "Allows the application to read service health information for your organization.", + "displayName": "Read service health information for your organization", + "id": "e2cea78f-e743-4d8f-a16a-75b629a038ae", + "origin": "Application (Office 365 Management APIs)", + "value": "ServiceHealth.Read" + }, + { + "description": "Allows the application to read threat intelligence data for your organization", + "displayName": "Read threat intelligence data for your organization", + "id": "17f1c501-83cd-414c-9064-cd10f7aef836", + "origin": "Application (Office 365 Management APIs)", + "value": "ThreatIntelligence.Read" + }, + { + "description": "Allows the application to read activity data for your organization.", + "displayName": "Read activity data for your organization", + "id": "594c1fb6-4f81-4475-ae41-0c394909246c", + "origin": "Delegated (Office 365 Management APIs)", + "value": "ActivityFeed.Read" + }, + { + "description": "Allows the application to read DLP policy events, including detected sensitive data, for your organization.", + "displayName": "Read DLP policy events including detected sensitive data", + "id": "4807a72c-ad38-4250-94c9-4eabfe26cd55", + "origin": "Delegated (Office 365 Management APIs)", + "value": "ActivityFeed.ReadDlp" + }, + { + "description": "Allows the application to read service health information for your organization.", + "displayName": "Read activity reports for your organization", + "id": "b3b78c39-cb1d-4d17-820a-25d9196a800e", + "origin": "Delegated (Office 365 Management APIs)", + "value": "ActivityReports.Read" + }, + { + "description": "Allows the application to read all the AppCatalog", + "displayName": "Read App Catalog", + "id": "bb050071-0147-4956-8cf1-9168939c0a79", + "origin": "Application (Office 365 Search Service)", + "value": "AppCatalog.Read.All" + }, + { + "description": "Allows the app to read the signed-in files of the user and files shared with the user.", + "displayName": "Read user files and files shared with user", + "id": "749d9cae-ceda-4718-bd22-1ae6830cbee6", + "origin": "Delegated (Office 365 Search Service)", + "value": "Files.Read" + }, + { + "description": "Allows the app to read email in user mailboxes.", + "displayName": "Read user mail", + "id": "fdf2c210-c550-4378-b72d-0d94197f7bd3", + "origin": "Delegated (Office 365 Search Service)", + "value": "Mail.Read" + }, + { + "description": "Allows the app to read a ranked list of relevant people of the signed-in user. The list includes local contacts, contacts from social networking, your organization's directory, and people from recent communications (such as email and Skype)", + "displayName": "Read users' relevant people lists", + "id": "36073ebf-e0ad-4838-b99a-8f63f2b60db1", + "origin": "Delegated (Office 365 Search Service)", + "value": "People.Read" + }, + { + "description": "Allows the app to list QnA and to read their properties on behalf of the signed-in user. ", + "displayName": "Read all QnA", + "id": "537ceb4f-32cd-4b8e-bab3-8303e950ccf0", + "origin": "Delegated (Office 365 Search Service)", + "value": "QnA.Read.All" + }, + { + "description": "Allows the app to search across the users office content. This content includes relevant people, documents, emails and skype messages.", + "displayName": "Search across the office content of the user", + "id": "2aec0168-f9e2-4ce1-bb0f-1145f35f5a64", + "origin": "Delegated (Office 365 Search Service)", + "value": "SubstrateSearch-Internal.ReadWrite" + }, + { + "description": "c", + "displayName": "TiRemediation.Read.All", + "id": "5c6799ba-41c0-49cc-9f2d-7486a52d52a0", + "origin": "Application (Office 365 Information Protection)", + "value": "TiRemediation.Read.All" + }, + { + "description": "c", + "displayName": "TiRemediation.ReadWrite.All", + "id": "38b568f3-92e4-4c17-92b7-a49c28904247", + "origin": "Application (Office 365 Information Protection)", + "value": "TiRemediation.ReadWrite.All" + }, + { + "description": "c", + "displayName": "UsersAggregateByAttackSimulation.tenant.read", + "id": "e0ff780c-d4f4-4ef4-b0ad-b19863ca72a2", + "origin": "Application (Office 365 Information Protection)", + "value": "UsersAggregateByAttackSimulation.tenant.read" + }, + { + "description": "This allows user to read Office 365 alerts.", + "displayName": "alert.read", + "id": "6b300195-82d7-4a39-a7bc-0510371998cc", + "origin": "Delegated (Office 365 Information Protection)", + "value": "alert.read" + }, + { + "description": "This allows user to change Office 365 alerts.", + "displayName": "alert.write", + "id": "bcc2bc0d-d08c-412a-b24d-f6f78d714bdc", + "origin": "Delegated (Office 365 Information Protection)", + "value": "alert.write" + }, + { + "description": "AtpStandardPolicy.Tenant.Read", + "displayName": "AtpStandardPolicy.Tenant.Read", + "id": "b87cb2cc-0570-4e76-9606-3528d5fb44e7", + "origin": "Delegated (Office 365 Information Protection)", + "value": "AtpStandardPolicy.Tenant.Read" + }, + { + "description": "Allows the app to read migration data via the SharePoint admin site without a signed-in user.", + "displayName": "Read access to migration data on the SharePoint admin site", + "id": "b7155856-e8b7-4ba1-bf43-8c9912353676", + "origin": "Application (Office 365 SharePoint Online)", + "value": "Migration.Read.All" + }, + { + "description": "AtpStandardPolicy.Tenant.Write", + "displayName": "AtpStandardPolicy.Tenant.Write", + "id": "9945d5be-d9cb-45d0-b347-3f827c0d374d", + "origin": "Delegated (Office 365 Information Protection)", + "value": "AtpStandardPolicy.Tenant.Write" + }, + { + "description": "This allows user to read M365ContentExplorer", + "displayName": "M365ContentExplorer.Read.All", + "id": "b80e6cec-e423-411f-8c98-7fe5a25ca7cf", + "origin": "Delegated (Office 365 Information Protection)", + "value": "M365ContentExplorer.Read.All" + }, + { + "description": "This allows user to read MtpRoleInfo", + "displayName": "mtproleinfo.read", + "id": "6f44fc23-ea08-4666-8329-85597e11bdcd", + "origin": "Delegated (Office 365 Information Protection)", + "value": "mtproleinfo.read" + }, + { + "description": "Purview.DataAccess.All", + "displayName": "Purview.DataAccess.All", + "id": "739f66f6-655e-48e4-b5bd-2bbeb6077954", + "origin": "Delegated (Office 365 Information Protection)", + "value": "Purview.DataAccess.All" + }, + { + "description": "This Allows User to read the Rbac Roles", + "displayName": "RbacAccessCheck.read", + "id": "384a8502-84c5-41d9-a875-7834b77c8005", + "origin": "Delegated (Office 365 Information Protection)", + "value": "RbacAccessCheck.read" + }, + { + "description": "RbacTenantStatus.Read", + "displayName": "RbacTenantStatus.Read", + "id": "edfd2d1c-b4b5-4b83-b5e8-c38594e49c26", + "origin": "Delegated (Office 365 Information Protection)", + "value": "RbacTenantStatus.Read" + }, + { + "description": "RbacTenantStatus.Write", + "displayName": "RbacTenantStatus.Write", + "id": "4e26c42d-fab0-4daa-9ea6-d860a28aa7d0", + "origin": "Delegated (Office 365 Information Protection)", + "value": "RbacTenantStatus.Write" + }, + { + "description": "LabelAnalyticsActivityData.Read.All", + "displayName": "LabelAnalyticsActivityData.Read.All", + "id": "2da9421b-01d5-43ec-9c8e-b1bfa4a8b2bb", + "origin": "Delegated (Office 365 Information Protection)", + "value": "LabelAnalyticsActivityData.Read.All" + }, + { + "description": "Allows the application to list and query user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export external user data (e.g. customer content or system-generated logs), associated with the current tenant on behalf of the signed-in user.", + "displayName": "Read shared cross-tenant user profile and export data", + "id": "cb1ba48f-d22b-4325-a07f-74135a62ee41", + "origin": "Delegated (Microsoft Graph)", + "value": "CrossTenantUserProfileSharing.Read" + }, + { + "description": "Allows the application to obtain basic tenant information about another target tenant within the Azure AD ecosystem on behalf of the signed-in user.", + "displayName": "Read cross-tenant basic information", + "id": "81594d25-e88e-49cf-ac8c-fecbff49f994", + "origin": "Delegated (Microsoft Graph)", + "value": "CrossTenantInformation.ReadBasic.All" + }, + { + "description": "Allows the app to read and write organization-wide copilot limited mode setting on behalf of the signed-in user.", + "displayName": "Read and write organization-wide copilot limited mode setting", + "id": "4704e5b2-0ada-4aa0-b18c-00ad7525bc06", + "origin": "Delegated (Microsoft Graph)", + "value": "CopilotSettings-LimitedMode.ReadWrite" + }, + { + "description": "Manage all settings", + "displayName": "settings.manage", + "id": "cb792285-1541-416c-a581-d8ede4ebc219", + "origin": "Application (Microsoft Cloud App Security)", + "value": "settings.manage" + }, + { + "description": "View all settings", + "displayName": "settings.read", + "id": "8e41f311-31d5-43aa-bb79-8fd4e14a8745", + "origin": "Application (Microsoft Cloud App Security)", + "value": "settings.read" + }, + { + "description": "Manage discovery alerts, reports, apps, and other related information", + "displayName": "discovery.manage", + "id": "f6e78c1a-b9c7-42d3-b067-220689a7a2e9", + "origin": "Delegated (Microsoft Cloud App Security)", + "value": "discovery.manage" + }, + { + "description": "View discovery alerts, reports, apps, and other related information", + "displayName": "discovery.read", + "id": "e9aa7b67-ea0d-435b-ab36-592cd9b23d61", + "origin": "Delegated (Microsoft Cloud App Security)", + "value": "discovery.read" + }, + { + "description": "Manage alerts, activities, policies, and other investigation-related information", + "displayName": "investigation.manage", + "id": "a832eaa3-0cfc-4a2b-9af1-27c5b092dd40", + "origin": "Delegated (Microsoft Cloud App Security)", + "value": "investigation.manage" + }, + { + "description": "View alerts, activities and policies", + "displayName": "investigation.read", + "id": "83bc8d83-2679-44ef-b813-d5f556fc4474", + "origin": "Delegated (Microsoft Cloud App Security)", + "value": "investigation.read" + }, + { + "description": "Allows the application to access the Cognitive Services API acting as users in the organization.", + "displayName": "Access Cognitive Services API as organization users.", + "id": "5f1e8914-a52b-429f-9324-91b92b81adaf", + "origin": "Delegated (Microsoft Cognitive Services)", + "value": "user_impersonation" + }, + { + "description": "Allow third-party application access to the Microsoft Customer Insights Service API.", + "displayName": "Have third-party access to Microsoft Customer Insights Service API", + "id": "056209dc-5c35-434b-9569-0c77d4aa6047", + "origin": "Application (Microsoft Customer Insights)", + "value": "CustomerInsights.Api.All" + }, + { + "description": "Allows App to Read from Azure Data Lake", + "displayName": "Read from Azure Data Lake", + "id": "ede937ec-309f-443a-bc4d-34c78296e4fd", + "origin": "Delegated (Microsoft Customer Insights)", + "value": "ADLS.Read" + }, + { + "description": "Allow the application access to the Microsoft Customer Insights Service API on behalf of the signed-in user.", + "displayName": "Have access to Microsoft Customer Insights Service API", + "id": "2e3c0709-0f8e-46b4-a196-ee6a15d858cd", + "origin": "Delegated (Microsoft Customer Insights)", + "value": "user_impersonation" + }, + { + "description": "Role to use instead of user impersonation pre auth.", + "displayName": "user impersonation pre auth", + "id": "6e61bc2a-6212-4824-b2fc-17261f45f642", + "origin": "Application (Microsoft Defender Hunting)", + "value": "UserImpersonation" + }, + { + "description": "Allows the app to see your list of devices as well as devices shared in your family.", + "displayName": "See your list of devices", + "id": "79a8f059-5727-4e7d-986a-d509f1799603", + "origin": "Delegated (Microsoft Device Directory Service)", + "value": "dds.read" + }, + { + "description": "Allows the app to be added to your list of devices and apps.", + "displayName": "Be added to your list of devices and apps", + "id": "b2c5a8a4-d75c-4c8d-ab0e-325d6d89c9e1", + "origin": "Delegated (Microsoft Device Directory Service)", + "value": "dds.register" + }, + { + "description": "Scope to allow FirstParty APPS to make PolicySync calls", + "displayName": "EopPolicySync.AccessAsApp", + "id": "c79b0778-99a8-4d45-9063-3f160ec2776d", + "origin": "Application (Microsoft Exchange Online Protection)", + "value": "EopPolicySync.AccessAsApp" + }, + { + "description": "c", + "displayName": "Exchange.ManageAsApp", + "id": "455e5cd2-84e8-4751-8344-5672145dfa17", + "origin": "Application (Microsoft Exchange Online Protection)", + "value": "Exchange.ManageAsApp" + }, + { + "description": "c", + "displayName": "ThreatSubmission.ReadWrite.All", + "id": "8f819283-077c-4c68-aa24-0ad706da26e0", + "origin": "Application (Microsoft Exchange Online Protection)", + "value": "ThreatSubmission.ReadWrite.All" + }, + { + "description": "Used to get token for agent to get network scan tasks", + "displayName": "NetworkScanAgent.Operate", + "id": "2adb0da9-d999-4186-85a4-0b66bbd9a535", + "origin": "Application (MDATPNetworkScanAgent)", + "value": "NetworkScanAgent.Operate" + }, + { + "description": "This allows users to install a new MDATP network scan agent", + "displayName": "NetworkScanAgent.Manage", + "id": "c65f274d-9690-45ee-a2ec-09e1e1f81bcd", + "origin": "Delegated (MDATPNetworkScanAgent)", + "value": "NetworkScanAgent.Manage" + }, + { + "description": "c", + "displayName": "Medeina.App", + "id": "85e2c024-8528-488c-a14e-42b99dfb2635", + "origin": "Application (Medeina Service)", + "value": "Medeina.App" + }, + { + "description": "Allows users to access the Medeina APIs", + "displayName": "Medeina.Access", + "id": "91918404-f9e2-41da-9065-5b776af95942", + "origin": "Delegated (Medeina Service)", + "value": "Medeina.Access" + }, + { + "description": "Medeina.Temp", + "displayName": "Medeina.Temp", + "id": "d8ea63e6-7c3c-4788-82e8-ba4ed13b95a3", + "origin": "Delegated (Medeina Service)", + "value": "Medeina.Temp" + }, + { + "description": "Allows users to access the Medeina APIs", + "displayName": "Mediena.Access", + "id": "fa228bfa-2a9b-48e9-9145-9ac39ac9b6f8", + "origin": "Delegated (Medeina Service Dev)", + "value": "Medeina.Access" + }, + { + "description": "Allow the application to access all the APIs registered with App Service", + "displayName": "Access APIs registered with App Service", + "id": "e0ea806b-d128-49dc-ac08-2bf18f7874d8", + "origin": "Delegated (Microsoft Azure App Service)", + "value": "user_impersonation" + }, + { + "description": "Allow the application to access the Azure Batch Service API on behalf of the signed-in user.", + "displayName": "Access Azure Batch Service", + "id": "635ced16-958c-4230-8508-ac2c509d94c6", + "origin": "Delegated (Microsoft Azure Batch)", + "value": "user_impersonation" + }, + { + "description": "Allows the application to access Azure Growth Signup APIs acting as signed-in users", + "displayName": "Azure Growth Signup", + "id": "df5e5f31-cc73-4a31-9291-89348976337e", + "origin": "Delegated (Microsoft Azure Signup Portal)", + "value": "azuregrowth.api.signup" + }, + { + "description": "Allows synchronizing billing information, such as the number of physical processor cores, between the Azure Stack HCI cluster and the cloud.", + "displayName": "Sync billing information", + "id": "7c2ddece-a157-4a29-a61a-1f8116e7cc57", + "origin": "Application (Microsoft Azure Stack HCI Service)", + "value": "AzureStackHCI.Billing.Sync" + }, + { + "description": "Allows synchronizing census metadata, such as hardware vendor and software version, between the Azure Stack HCI cluster and the cloud.", + "displayName": "Sync census metadata", + "id": "b582234c-0282-4247-9d0a-730c45218605", + "origin": "Application (Microsoft Azure Stack HCI Service)", + "value": "AzureStackHCI.Census.Sync" + }, + { + "description": "Allows read only access to cluster level properties, between the Azure Stack HCI cluster and the cloud", + "displayName": "Read only access to cluster level properties", + "id": "2344a320-6a09-4530-bed7-c90485b5e5e2", + "origin": "Application (Microsoft Azure Stack HCI Service)", + "value": "AzureStackHCI.Cluster.Read" + }, + { + "description": "Allows read and write access to cluster level actions, between the Azure Stack HCI cluster and the cloud", + "displayName": "Read and write access to cluster level actions", + "id": "493bd689-9082-40db-a506-11f40b68128f", + "origin": "Application (Microsoft Azure Stack HCI Service)", + "value": "AzureStackHCI.Cluster.ReadWrite" + }, + { + "description": "Allows read only access to cluster node level properties, between the Azure Stack HCI cluster node and the cloud", + "displayName": "Read only access to cluster node level properties", + "id": "8fa5445e-80fb-4c71-a3b1-9a16a81a1966", + "origin": "Application (Microsoft Azure Stack HCI Service)", + "value": "AzureStackHCI.ClusterNode.Read" + }, + { + "description": "Allows read and write access to cluster node level actions, between the Azure Stack HCI cluster node and the cloud", + "displayName": "Read and write access to cluster node level actions", + "id": "bbe8afc9-f3ba-4955-bb5f-1cfb6960b242", + "origin": "Application (Microsoft Azure Stack HCI Service)", + "value": "AzureStackHCI.ClusterNode.ReadWrite" + }, + { + "description": "Stream Analytics access to Power BI", + "displayName": "Stream Analytics access to Power BI", + "id": "27fa5b85-cf15-41f1-a29d-2e44dde75208", + "origin": "Delegated (Microsoft Azure Stream Analytics)", + "value": "user_impersonation" + }, + { + "description": "This scope allows working with Microsoft Project Arcadia Workspaces' Artifacts API.", + "displayName": "workspaceartifacts.management", + "id": "f99087ab-db8f-46be-8ff0-613ef11c6ed8", + "origin": "Delegated (Microsoft Azure Synapse Gateway)", + "value": "workspaceartifacts.management" + }, + { + "description": "Allows the app to read access reviews, reviewers, decisions and settings in the organization, without a signed-in user.", + "displayName": "Read all access reviews", + "id": "d07a8cc0-3d51-4b77-b3b0-32704d1f69fa", + "origin": "Application (Microsoft Graph)", + "value": "AccessReview.Read.All" + }, + { + "description": "Allows the app to read, update, delete and perform actions on access reviews, reviewers, decisions and settings in the organization, without a signed-in user.", + "displayName": "Manage all access reviews", + "id": "ef5f7d5c-338f-44b0-86c3-351f46c8bb5f", + "origin": "Application (Microsoft Graph)", + "value": "AccessReview.ReadWrite.All" + }, + { + "description": "Allows the app to read, update, delete and perform actions on access reviews, reviewers, decisions and settings in the organization for group and app memberships, without a signed-in user.", + "displayName": "Manage access reviews for group and app memberships", + "id": "18228521-a591-40f1-b215-5fad4488c117", + "origin": "Application (Microsoft Graph)", + "value": "AccessReview.ReadWrite.Membership" + }, + { + "description": "Allows deleting or restoring agent identity blueprints without a signed-in user.", + "displayName": "Delete and restore agent identity blueprints.", + "id": "3f80b699-6405-4e36-a4df-4f19950ff91e", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentityBlueprint.DeleteRestore.All" + }, + { + "description": "Allows the client to read all agent identity blueprints without a signed-in user.", + "displayName": "Read all agent identity blueprints", + "id": "7547a7d1-36fa-4479-9c31-559a600eaa4f", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentityBlueprint.Read.All" + }, + { + "description": "Allows the client to read, update, create, and delete agent identity blueprints without a signed-in user.", + "displayName": "Read and write all agent identity blueprints.", + "id": "7fddd33b-d884-4ec0-8696-72cff90ff825", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentityBlueprint.ReadWrite.All" + }, + { + "description": "Allows updating agent identity blueprint authorization and authentication properties without a signed-in user.", + "displayName": "Update agent identity blueprint authorization and authentication properties", + "id": "19202363-278e-49c2-bf00-391e2ba00881", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentityBlueprint.UpdateAuthProperties.All" + }, + { + "description": "Allows updating agent identity blueprint branding without a signed-in user.", + "displayName": "Update agent identity blueprint branding", + "id": "76232daa-a1e4-4544-b664-495a006513bf", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentityBlueprint.UpdateBranding.All" + }, + { + "description": "Allows creating new agent identity blueprint principals without a signed-in user.", + "displayName": "Create agent identity blueprint principals.", + "id": "8959696d-d07e-4916-9b1e-3ba9ce459161", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentityBlueprintPrincipal.Create" + }, + { + "description": "Allows deleting or restoring agent identity blueprint principals without a signed-in user.", + "displayName": "Delete and restore agent identity blueprint principals.", + "id": "f86a2dd8-9298-4675-bd78-f5a3572da2d7", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentityBlueprintPrincipal.DeleteRestore.All" + }, + { + "description": "Allows enabling or disabling agent identity blueprint principals without a signed-in user.", + "displayName": "Enable or disable agent identity blueprint principals.", + "id": "a0bdd23d-8b19-4682-b428-574d96527c6f", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentityBlueprintPrincipal.EnableDisable.All" + }, + { + "description": "Allows reading agent identity blueprint principals without a signed-in user.", + "displayName": "Read agent identity blueprint principals.", + "id": "9361dea9-4524-493d-941d-f1b65aaf6c7c", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentityBlueprintPrincipal.Read.All" + }, + { + "description": "Allows the app to read, update, create, and delete agent identity blueprint principals without a signed-in user.", + "displayName": "Read and write all agent identity blueprint principals.", + "id": "3bc933bc-8b4d-4cb6-ac49-b73774299250", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentityBlueprintPrincipal.ReadWrite.All" + }, + { + "description": "Allows the app to create agent users, read and update agent ID user profiles and read basic company properties, delete and restore agent users without a signed in user.", + "displayName": "Read and write all agent ID users' full profiles", + "id": "b782c9ad-6f2b-4894-a21b-72bf22417f0a", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdUser.ReadWrite.All" + }, + { + "description": "Allows the app to create agent users, read and update agent ID user profiles, delete and restore agent users under an agent blueprint, and read basic company properties without a signed-in user.", + "displayName": "Read and write full profiles of agent ID users under an agent blueprint", + "id": "4aa6e624-eee0-40ab-bdd8-f9639038a614", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdUser.ReadWrite.IdentityParentedBy" + }, + { + "description": "Allows the app to read all agent instances and their related collections in your organization's Agent Registry without a signed-in user.", + "displayName": "Read all agent instances in Agent Registry", + "id": "799a4732-85b8-4c67-b048-75f0e88a232b", + "origin": "Application (Microsoft Graph)", + "value": "AgentInstance.Read.All" + }, + { + "description": "Allows the app to create, read, update, and delete all agent instances in your organization's Agent Registry without a signed-in user.", + "displayName": "Read and write all agent instances in Agent Registry", + "id": "07abdd95-78dc-4353-bd32-09f880ea43d0", + "origin": "Application (Microsoft Graph)", + "value": "AgentInstance.ReadWrite.All" + }, + { + "description": "Allows the app to create, read, update, and delete agent instances that designate the calling app as their manager in your organization's Agent Registry without a signed-in user.", + "displayName": "Read and write managed-by agent instances in Agent Registry", + "id": "782ab1bf-24f1-4c27-8bbc-2006d42792a6", + "origin": "Application (Microsoft Graph)", + "value": "AgentInstance.ReadWrite.ManagedBy" + }, + { + "description": "Allows the app to read agent registration information without a signed-in user.", + "displayName": "Read all agent registrations", + "id": "d3acceb6-4673-47c0-aeac-582f2c7cf72c", + "origin": "Application (Microsoft Graph)", + "value": "AgentRegistration.Read.All" + }, + { + "description": "Allows the app to read and write agent registration information without a signed-in user.", + "displayName": "Read and write all agent registrations", + "id": "39fb8c64-7bd3-4107-8515-14d6e55ddda4", + "origin": "Application (Microsoft Graph)", + "value": "AgentRegistration.ReadWrite.All" + }, + { + "description": "Allows creating new agent identity blueprints without a signed-in user.", + "displayName": "Create agent identity blueprints.", + "id": "ea4b2453-ad2d-4d94-9155-10d5d9493ce9", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentityBlueprint.Create" + }, + { + "description": "Allows updating agent identity blueprint credentials without a signed-in user.", + "displayName": "Update agent identity blueprint credentials", + "id": "0510736e-bdfb-4b37-9a1f-89b4a074763a", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentityBlueprint.AddRemoveCreds.All" + }, + { + "description": "Allows the client to read, update, create, and delete agent identities without a signed-in user.", + "displayName": "Read and write all agent identities", + "id": "dcf7150a-88d4-4fe6-9be1-c2744c455397", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentity.ReadWrite.All" + }, + { + "description": "Allows the app to read all agent identities without a signed-in user.", + "displayName": "Read all agent identities", + "id": "b2b8f011-2898-4234-9092-5059f6c1ebfa", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentity.Read.All" + }, + { + "description": "Allows an app to read all acronyms without a signed-in user.", + "displayName": "Read all acronyms", + "id": "8c0aed2c-0c61-433d-b63c-6370ddc73248", + "origin": "Application (Microsoft Graph)", + "value": "Acronym.Read.All" + }, + { + "description": "Allows the app to read administrative units and administrative unit membership without a signed-in user.", + "displayName": "Read all administrative units", + "id": "134fd756-38ce-4afd-ba33-e9623dbe66c2", + "origin": "Application (Microsoft Graph)", + "value": "AdministrativeUnit.Read.All" + }, + { + "description": "Allows the app to create, read, update, and delete administrative units and manage administrative unit membership without a signed-in user.", + "displayName": "Read and write all administrative units", + "id": "5eb59dd3-1da2-4329-8733-9dabdc435916", + "origin": "Application (Microsoft Graph)", + "value": "AdministrativeUnit.ReadWrite.All" + }, + { + "description": "Allows the app to read all agent cards and their skills in your organization's Agent Registry without a signed-in user.", + "displayName": "Read all agent cards in Agent Registry", + "id": "aec9e0a0-6f46-4150-a9f7-05e9e3e87399", + "origin": "Application (Microsoft Graph)", + "value": "AgentCard.Read.All" + }, + { + "description": "Allows the app to create, read, update, and delete all agent cards and manage their skills in your organization's Agent Registry without a signed-in user.", + "displayName": "Read and write all agent cards in Agent Registry", + "id": "ef566853-42d6-45a5-bed9-5ccb82c98b4f", + "origin": "Application (Microsoft Graph)", + "value": "AgentCard.ReadWrite.All" + }, + { + "description": "Allows the app to read and update agent cards that designate the calling app as their manager and manage their skills in your organization's Agent Registry without a signed-in user.", + "displayName": "Read and write managed-by agent cards in Agent Registry", + "id": "9c4a07db-e0c1-4fb0-8e85-dfd8ae3b8201", + "origin": "Application (Microsoft Graph)", + "value": "AgentCard.ReadWrite.ManagedBy" + }, + { + "description": "Allows the app to read all agent card manifests in your organization's Agent Registry without a signed-in user.", + "displayName": "Read all agent card manifests in Agent Registry", + "id": "3ee18438-e6e5-4858-8f1c-d7b723b45213", + "origin": "Application (Microsoft Graph)", + "value": "AgentCardManifest.Read.All" + }, + { + "description": "Allows the app to read and write to all agent card manifests in your organization's Agent Registry without a signed-in user.", + "displayName": "Read and write all agent card manifests in Agent Registry", + "id": "228b1a03-f7ca-4348-b50d-e8a547ab61af", + "origin": "Application (Microsoft Graph)", + "value": "AgentCardManifest.ReadWrite.All" + }, + { + "description": "Allows an application to read or write Customer Key Encryption Tenant Data", + "displayName": "Read or Write Customer Key Encryption Tenant Data", + "id": "e85fa438-368f-4c1d-909a-5760a4e045ae", + "origin": "Delegated (M365DataAtRestEncryption)", + "value": "CustomerKeyTenant-Internal.ReadWrite.All" + }, + { + "description": "Allows the app to read and write agent card manifests that name it as manager in your organization's Agent Registry without a signed-in user.", + "displayName": "Read and write managed-by agent card manifests in Agent Registry", + "id": "77f6034c-52f5-4526-9fa1-d55a67e72cc4", + "origin": "Application (Microsoft Graph)", + "value": "AgentCardManifest.ReadWrite.ManagedBy" + }, + { + "description": "Allows the app to create, read, update, and delete all collections and manage their membership in your organization's Agent Registry without a signed-in user.", + "displayName": "Read and write all collections in Agent Registry, except quarantined and global", + "id": "feb31d7d-a227-4487-898c-e014840d07b3", + "origin": "Application (Microsoft Graph)", + "value": "AgentCollection.ReadWrite.All" + }, + { + "description": "Allows the app to create, read, update, and delete collections that designate the calling app as their manager and manage their membership in your organization's Agent Registry without a signed-in user.", + "displayName": "Read and write managed-by collections in Agent Registry", + "id": "2e0fb698-9996-479f-926b-ce63f4397829", + "origin": "Application (Microsoft Graph)", + "value": "AgentCollection.ReadWrite.ManagedBy" + }, + { + "description": "Allows the app to read the communication configuration of agent blueprints without a signed-in user.", + "displayName": "Read all agent communication configurations", + "id": "eccf3f2d-f81a-4718-95d7-ef4a0c42ac43", + "origin": "Application (Microsoft Graph)", + "value": "AgentCommunicationConfiguration.Read.All" + }, + { + "description": "Allows the app to read and update the communication configuration of agent blueprints without a signed-in user.", + "displayName": "Read and write all agent communication configurations", + "id": "9c72696d-c77b-4d8d-b59e-dfca4792c9ec", + "origin": "Application (Microsoft Graph)", + "value": "AgentCommunicationConfiguration.ReadWrite.All" + }, + { + "description": "Allows the client to create agent identities without a signed-in user, even if the client is not the parent agent identity blueprint.", + "displayName": "Create agent identities without an agent blueprint parent", + "id": "ad25cc1d-84d8-47df-a08e-b34c2e800819", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentity.Create.All" + }, + { + "description": "Allows the app to create agent identities as the parent agent identity blueprint and fully manage them, including reading, updating, and deleting, without a signed-in user.", + "displayName": "Create and manage agent identities as the parent agent identity blueprint", + "id": "4c390976-b2b7-42e0-9187-c6be3bead001", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentity.CreateAsManager" + }, + { + "description": "Allows the client to delete and restore agent identities without a signed-in user.", + "displayName": "Delete and restore agent identities", + "id": "5b016f9b-18eb-41d4-869a-66931914d1c8", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentity.DeleteRestore.All" + }, + { + "description": "Allows the client to enable or disable agent identities without a signed-in user.", + "displayName": "Enable or disable agent identities", + "id": "69ee0943-4fa4-4ec8-8e52-d12e4ea661a3", + "origin": "Application (Microsoft Graph)", + "value": "AgentIdentity.EnableDisable.All" + }, + { + "description": "Allows the app to read all collections and their membership in your organization's Agent Registry without a signed-in user.", + "displayName": "Read all collections in Agent Registry, except quarantined and global", + "id": "e65ee1da-d1d5-467b-bdd0-3e9bb94e6e0c", + "origin": "Application (Microsoft Graph)", + "value": "AgentCollection.Read.All" + }, + { + "description": "Allows the app to read terms of use agreements, without a signed in user.", + "displayName": "Read all terms of use agreements", + "id": "2f3e6f8c-093b-4c57-a58b-ba5ce494a169", + "origin": "Application (Microsoft Graph)", + "value": "Agreement.Read.All" + }, + { + "description": "Allows an application to read or write Microsoft Managed Key Data", + "displayName": "Read or Write Microsoft Managed Key Data", + "id": "ac23b270-1dc3-4ee4-bd56-d7eb945c2332", + "origin": "Application (M365DataAtRestEncryption)", + "value": "MicrosoftManagedKey-Internal.ReadWrite.All" + }, + { + "description": "Allows an application to delete Customer Key Encryption Tenant data", + "displayName": "Delete Customer Key Encryption Tenant Data", + "id": "ef16fcfc-1309-42bc-9c0c-7eb48a9d5f02", + "origin": "Application (M365DataAtRestEncryption)", + "value": "CustomerKeyTenant-Internal.Delete.All" + }, + { + "description": "Allows the uesr to Read and Write Asset Resource, on behalf of the signed-in user.", + "displayName": "Read and Write Asset Resource", + "id": "3e2a4aea-4efd-4851-9af9-de64ccbb354f", + "origin": "Delegated (EASM API)", + "value": "AssetResource.ReadWrite.All" + }, + { + "description": "Allows the user to read DiscoveryGroup, on behalf of the signed-in user.", + "displayName": "Read DiscoveryGroup information", + "id": "034f2362-c46e-4e6b-9905-c23d1b928bce", + "origin": "Delegated (EASM API)", + "value": "DiscoveryGroup.Read.All" + }, + { + "description": "Allows the uesr to Read and Write DiscoveryGroup, on behalf of the signed-in user.", + "displayName": "Read and Write DiscoveryGroup", + "id": "ff3b7cad-a709-4b6f-9304-862191f23ff6", + "origin": "Delegated (EASM API)", + "value": "DiscoveryGroup.ReadWrite.All" + }, + { + "description": "Allows the user to read Discovery Run, on behalf of the signed-in user.", + "displayName": "Read Discovery Run information", + "id": "255d9bfb-b946-4910-a246-17382a9f5759", + "origin": "Delegated (EASM API)", + "value": "DiscoveryRun.Read.All" + }, + { + "description": "Allows the uesr to Read and Write Discovery Run, on behalf of the signed-in user.", + "displayName": "Read and Write Discovery Run", + "id": "1bd45aed-5a43-435e-a2ab-719d6d88f94f", + "origin": "Delegated (EASM API)", + "value": "DiscoveryRun.ReadWrite.All" + }, + { + "description": "Allows the user to read Discovery Templates information, such as workspace, on behalf of the signed-in user.", + "displayName": "Read all Discovery Templates information", + "id": "e63fca22-b70f-468d-8ac6-22be260f12c4", + "origin": "Delegated (EASM API)", + "value": "DiscoveryTemplate.Read.All" + }, + { + "description": "Allows the user to read Filter, on behalf of the signed-in user.", + "displayName": "Read Filter information", + "id": "a24df28a-cd42-4d3c-b5f2-ed5be3dea64c", + "origin": "Delegated (EASM API)", + "value": "Filter.Read.All" + }, + { + "description": "Allows the uesr to Read and Write Filter, on behalf of the signed-in user.", + "displayName": "Read and Write Filter", + "id": "21813d7d-e1db-4a36-827d-5416f07e39ca", + "origin": "Delegated (EASM API)", + "value": "Filter.ReadWrite.All" + }, + { + "description": "Allows the user to read Tag, on behalf of the signed-in user.", + "displayName": "Read Tag information", + "id": "5fa521bf-ccf9-4e9e-9155-63c00c6ace83", + "origin": "Delegated (EASM API)", + "value": "Tag.Read.All" + }, + { + "description": "Allows the uesr to Read and Write Tag, on behalf of the signed-in user.", + "displayName": "Read and Write Tag", + "id": "18688279-8144-4ff4-953a-5174888c57a5", + "origin": "Delegated (EASM API)", + "value": "Tag.ReadWrite.All" + }, + { + "description": "Allows the user to read Task, on behalf of the signed-in user.", + "displayName": "Read Task information", + "id": "1d6a2ebe-7d16-455f-b698-e91b02f66a3b", + "origin": "Delegated (EASM API)", + "value": "Task.Read.All" + }, + { + "description": "Allows the uesr to Read and Write Task, on behalf of the signed-in user.", + "displayName": "Read and Write Task", + "id": "8d25b6b1-b5ca-416d-be6a-900b51f31e18", + "origin": "Delegated (EASM API)", + "value": "Task.ReadWrite.All" + }, + { + "description": "Allows the user to read Workspace, on behalf of the signed-in user.", + "displayName": "Read Workspace information", + "id": "42f3ea82-12d0-4de1-9d0f-463211dcaae6", + "origin": "Delegated (EASM API)", + "value": "Workspace.Read.All" + }, + { + "description": "Allows the uesr to Read and Write Workspace, on behalf of the signed-in user.", + "displayName": "Read and Write Workspace", + "id": "0081ccf6-a13e-4372-ad55-df45ffb7dea5", + "origin": "Delegated (EASM API)", + "value": "Workspace.ReadWrite.All" + }, + { + "description": "Contributors have the ability to make all requests supported by the API, for any subscription", + "displayName": "EdgeZoneRpApi.Contributor", + "id": "453ddc3f-d897-4299-9ca1-6401b3313412", + "origin": "Application (Edge Zone RP API - Prod)", + "value": "EdgeZoneRpApi.Contributor" + }, + { + "description": "Allow the application to access Azure Event Grid on behalf of the signed-in user.", + "displayName": "Access Azure Event Grid", + "id": "d5f985b8-5529-49be-926a-58f4a026c488", + "origin": "Delegated (EventGrid Data API)", + "value": "user_impersonation" + }, + { + "description": "Allows the app to create resources on behalf of eligible users when policy and RBAC permit.", + "displayName": "Act On Behalf Of - Create All", + "id": "b1a7c8e2-1234-4cde-9876-abcdef123456", + "origin": "Application (Fidalgo Dataplane Public)", + "value": "actonbehalfof.create.all" + }, + { + "description": "Allows the user to read Asset Resource, including asset resource, asset audit trails, asset summary and asset snapshot, on behalf of the signed-in user.", + "displayName": "Read Asset Resource information", + "id": "2288f070-b471-48c3-b16b-113c05a3cfbb", + "origin": "Delegated (EASM API)", + "value": "AssetResource.Read.All" + }, + { + "description": "Allows users to access Fidalgo resources.", + "displayName": "access_as_user", + "id": "983c9dc3-3bcf-4538-9937-bab8b1a31d86", + "origin": "Delegated (Fidalgo Dataplane Public)", + "value": "access_as_user" + }, + { + "description": "Dynamics 365 is a business management solution that’s connecting people and processes like never before. From day one, it makes ordering, selling, invoicing, and reporting easier and faster.", + "displayName": "Access as the signed-in user", + "id": "bce0976a-cb0b-473b-8800-84eda9f8e447", + "origin": "Delegated (Dynamics 365 Business Central)", + "value": "user_impersonation" + }, + { + "description": "Grants full access to the Business Central automation APIs. These APIs provide the capability to automate company setup.", + "displayName": "Full access to automation", + "id": "d365bc00-a990-0000-00bc-160000000001", + "origin": "Application (Dynamics 365 Business Central)", + "value": "Automation.ReadWrite.All" + }, + { + "description": "Allows calling debugging APIs", + "displayName": "UserScope-PPE.Debug.All", + "id": "f6c5fb21-2e2e-42f4-a961-ffb661669441", + "origin": "Application (DirectoryLookupService)", + "value": "UserScope-PPE.Debug.All" + }, + { + "description": "This allows app to run ppe tenant userscope in DLS", + "displayName": "UserScope-PPE.ReadWrite.All", + "id": "60f89623-e4c0-4fbd-84c6-a7f1e4108959", + "origin": "Application (DirectoryLookupService)", + "value": "UserScope-PPE.ReadWrite.All" + }, + { + "description": "This allows app to access test tenant data", + "displayName": "Users-Dev.Read.All", + "id": "0f998d84-9f24-404e-ac95-4de6e66be0c3", + "origin": "Application (DirectoryLookupService)", + "value": "Users-Dev.Read.All" + }, + { + "description": "This allows app to access PPE tenant data", + "displayName": "Users-PPE.Read.All", + "id": "15139b67-d076-43b0-bcae-d959c69a8458", + "origin": "Application (DirectoryLookupService)", + "value": "Users-PPE.Read.All" + }, + { + "description": "Allows the application to access the Microsoft.Discovery data-plane services as a user in the organization", + "displayName": "Access Microsoft.Discovery service as a user", + "id": "89262da0-2b68-4c38-a6eb-79d067511de8", + "origin": "Delegated (Discovery data-plane service App)", + "value": "access_as_user" + }, + { + "description": "access dnc as application", + "displayName": "Dnc.Application.All", + "id": "d220ea05-1e7a-47bd-a414-7215922c7cab", + "origin": "Application (DNC)", + "value": "Dnc.Application.All" + }, + { + "description": "access dnc as user", + "displayName": "Dnc.User.All", + "id": "f474b40e-b24b-4cbb-b2bb-aedcae68541d", + "origin": "Delegated (DNC)", + "value": "Dnc.User.All" + }, + { + "description": "Allow the application to access Domain Controller Services on behalf of the signed-in user.", + "displayName": "Access Domain Controller Services", + "id": "dcf6ff68-86c0-44e6-83f2-502f9fdd4b26", + "origin": "Delegated (Domain Controller Services)", + "value": "user_impersonation" + }, + { + "description": "Get orchestration and activity work-items, and post results", + "displayName": "Execute", + "id": "2fd36249-0769-40b9-bf88-00cb556e2594", + "origin": "Delegated (DTS-Authentication)", + "value": "Execute" + }, + { + "description": "Manage orchestrations", + "displayName": "Manage", + "id": "5b8637fc-0900-41a9-94f7-a06f7b393c54", + "origin": "Delegated (DTS-Authentication)", + "value": "Manage" + }, + { + "description": "Allow raising events to orchestrations", + "displayName": "Raise Events", + "id": "c24049f6-d976-4a21-9cae-3b1dbeaf7548", + "origin": "Delegated (DTS-Authentication)", + "value": "RaiseEvents" + }, + { + "description": "Get or list orchestrations, including data payloads", + "displayName": "Read All", + "id": "770cc82b-17ad-4de5-b79d-6ea1a7d2b7f2", + "origin": "Delegated (DTS-Authentication)", + "value": "Read.All" + }, + { + "description": "Get or lists orchestration metadata, but does not allow returning data payloads", + "displayName": "Read Metadata", + "id": "bc864a93-0398-42d0-824a-e48e25b6340d", + "origin": "Delegated (DTS-Authentication)", + "value": "Read.Metadata" + }, + { + "description": "Allow clients to read topic suggestions and update their status", + "displayName": "TopicSuggestion-Internal.ReadWrite", + "id": "e6d57537-d278-4cb8-9f1d-19e173bcf4eb", + "origin": "Delegated (DWEngineV2)", + "value": "TopicSuggestion-Internal.ReadWrite" + }, + { + "description": "Grants full access to the Business Central Admin Center API. This API provides capability to execute administrative tasks for a Business Central tenant.", + "displayName": "Full access to Admin Center API", + "id": "a20fe46f-4f63-4666-8e0e-9b882d90b837", + "origin": "Application (Dynamics 365 Business Central)", + "value": "AdminCenter.ReadWrite.All" + }, + { + "description": "Grants full access to the Business Central web services APIs. These APIs provide the capability to call web services APIs and modify Business Central data.\t", + "displayName": "Full access to web services API", + "id": "a42b0b75-311e-488d-b67e-8fe84f924341", + "origin": "Application (Dynamics 365 Business Central)", + "value": "API.ReadWrite.All" + }, + { + "description": "Dynamics 365 is a business management solution that’s connecting people and processes like never before. From day one, it makes ordering, selling, invoicing, and reporting easier and faster.", + "displayName": "Access according to the application's permissions in Dynamics 365 Business Central", + "id": "3983b928-ed40-4111-bbad-e7910cf234bd", + "origin": "Application (Dynamics 365 Business Central)", + "value": "app_access" + }, + { + "description": "Dynamics 365 is a business management solution that’s connecting people and processes like never before. From day one, it makes ordering, selling, invoicing, and reporting easier and faster.", + "displayName": "Access Dynamics 365 Business Central as the signed-in user", + "id": "2fb13c28-9d89-417f-9af2-ec3065bc16e6", + "origin": "Delegated (Dynamics 365 Business Central)", + "value": "Financials.ReadWrite.All" + }, + { + "description": "Allow the application to access Fiji Storage on behalf of the signed-in user.", + "displayName": "Access Fiji Storage", + "id": "4e5661b3-5a0d-47fc-b7a6-e5b659cfea8b", + "origin": "Delegated (Fiji Storage)", + "value": "user_impersonation" + }, + { + "description": "Allow applications to access Genome RP API on behalf of the signed-in user", + "displayName": "Access Genome RP API as the signed-in user", + "id": "6fc8a23e-a3f1-4b36-9b21-8df0b525bd83", + "origin": "Delegated (Genome RP API)", + "value": "access_as_user" + }, + { + "description": "Allows the app to read all external connections without a signed-in user.", + "displayName": "ExternalConnection.Read.All", + "id": "1ef94f6e-ade0-4b79-9f7f-a72563e3ad60", + "origin": "Application (Graph Connector Service)", + "value": "ExternalConnection.Read.All" + }, + { + "description": "Allow Healthcare Agent Service APIs to process the data sent to it.", + "displayName": "Healthcare Agent Service APIs Process", + "id": "28e41776-5350-4c1e-9ee4-689de5cb6d85", + "origin": "Delegated (Health Safeguards REST API)", + "value": "HealthcareAgentServiceApis.Process" + }, + { + "description": "Invoke Diagnostics", + "displayName": "Invoke Diagnostics", + "id": "8040cfef-0635-4aa6-b099-9f40d6866bbb", + "origin": "Delegated (IAM Supportability)", + "value": "invoke" + }, + { + "description": "Allow the application to access Dynamics 365 Recommendations on behalf of the signed-in user.", + "displayName": "Dynamics 365 Recommendations", + "id": "47e2b85b-5704-487f-be47-74aa52bbe838", + "origin": "Delegated (Intelligent Recommendations Service)", + "value": "user_impersonation" + }, + { + "description": "Allow the application to access Azure Data Explorer on behalf of the signed-in user.", + "displayName": "Access Azure Data Explorer", + "id": "00d678f0-da44-4b12-a6d6-c98bcfd1c5fe", + "origin": "Delegated (KustoService)", + "value": "user_impersonation" + }, + { + "description": "Allow this application to access Log Analytics data on", + "displayName": "Read Log Analytics data", + "id": "e8f6e161-84d0-4cd7-9441-2d46ec9ec3d5", + "origin": "Application (Log Analytics API)", + "value": "Data.Read" + }, + { + "description": "Allow this application to access Log Analytics data on behalf of the user", + "displayName": "Read Log Analytics data as user", + "id": "e8dac03d-d467-4a7e-9293-9cca7df08b31", + "origin": "Delegated (Log Analytics API)", + "value": "Data.Read" + }, + { + "description": "Grants access to execute diagnostics", + "displayName": "Diagnostic.Execute.All", + "id": "2417f470-7490-419f-820a-144a3ba39e79", + "origin": "Delegated (M365 Pillar Diagnostics Service)", + "value": "Diagnostic.Execute.All" + }, + { + "description": "Scope used by TAC", + "displayName": "M365AdminPortal.Centro.Read", + "id": "46d318a0-1196-4991-a1cc-5de005ce9c0a", + "origin": "Delegated (M365 Pillar Diagnostics Service)", + "value": "M365AdminPortal.Centro.Read" + }, + { + "description": "Scope used by EAC", + "displayName": "M365AdminPortal.Settings.Read", + "id": "89100101-60c5-46a6-8c41-85bde6f3a2f0", + "origin": "Delegated (M365 Pillar Diagnostics Service)", + "value": "M365AdminPortal.Settings.Read" + }, + { + "description": "Scope used by SAC", + "displayName": "User.Read", + "id": "f4dd0a95-1d33-479d-90f7-7ef86537471e", + "origin": "Delegated (M365 Pillar Diagnostics Service)", + "value": "User.Read" + }, + { + "description": "Scope used by MAC and Security center", + "displayName": "user_impersonation", + "id": "75a4e338-37d0-450b-928f-b9e546c8a03a", + "origin": "Delegated (M365 Pillar Diagnostics Service)", + "value": "user_impersonation" + }, + { + "description": "This scope allows the holder to invoke customer onboarding scenarios", + "displayName": "CustomerKeyOnboarding-Internal.ReadWrite.All", + "id": "837e1541-7f8b-4fcf-a215-12fe252cd3e2", + "origin": "Application (M365DataAtRestEncryption)", + "value": "CustomerKeyOnboarding-Internal.ReadWrite.All" + }, + { + "description": "Allows application to Wrap or Unwrap data using CustomerKey Encryption Policy", + "displayName": "Wrap or Unwrap data using CustomerKey Encryption Policy", + "id": "42e29572-777c-48b4-bdaf-c63df6da65d3", + "origin": "Application (M365DataAtRestEncryption)", + "value": "CustomerKeyPolicy.WrapUnwrap" + }, + { + "description": "Allows application to Wrap or Unwrap data using CustomerKey Encryption Policy.", + "displayName": "Wrap or Unwrap data using CustomerKey Encryption Policy", + "id": "f8a2c9d1-31d8-4a2e-900a-4105aaf50280", + "origin": "Application (M365DataAtRestEncryption)", + "value": "CustomerKeyPolicy-Internal.WrapUnwrap.All" + }, + { + "description": "Allows an application to Read or Write resource application registration data for their application", + "displayName": "Read or Write resource application registration data for their application", + "id": "6bbe32a7-dfd3-4ab5-877a-62b4caa98d4d", + "origin": "Application (M365DataAtRestEncryption)", + "value": "CustomerKeyRegistration.ReadWrite.All" + }, + { + "description": "Allows an application to Read or Write resource application registration data for any application", + "displayName": "Read or Write resource application registration data for any application", + "id": "d747c012-3ada-46fa-9807-9c2534d06a14", + "origin": "Application (M365DataAtRestEncryption)", + "value": "CustomerKeyRegistration-Internal.ReadWrite.All" + }, + { + "description": "Allows an application to read Customer Key Encryption Tenant Data", + "displayName": "Read Customer Key Encryption Tenant Data", + "id": "54f050d4-7d90-4abe-97bd-15325467480e", + "origin": "Application (M365DataAtRestEncryption)", + "value": "CustomerKeyTenant.Read.All" + }, + { + "description": "Access the Azure Health Bot", + "displayName": "AzureHealthBot.PortalAccess", + "id": "4d148aae-170b-417a-9d06-6978383e329a", + "origin": "Delegated (Health Bot Portal V4)", + "value": "AzureHealthBot.PortalAccess" + }, + { + "description": "Allow the app to read webhook connection details, on behalf of the signed-in user.", + "displayName": "Read webhook connection details", + "id": "a3028c9a-803b-47f3-be20-0f9a6c25a813", + "origin": "Delegated (Graph Connector Service)", + "value": "WebhookData.Read.All" + }, + { + "description": "Allows the app to read and write external items on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read external items of the connection that it is authorized to.", + "displayName": "ExternalItem.ReadWrite.OwnedBy", + "id": "13d477ed-f4cf-4cc0-9678-80517234742e", + "origin": "Delegated (Graph Connector Service)", + "value": "ExternalItem.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read and write all external items on behalf of a signed-in user. The signed-in user must be an administrator.", + "displayName": "ExternalItem.ReadWrite.All", + "id": "565c16dd-b86f-4528-9d73-af8687391f02", + "origin": "Delegated (Graph Connector Service)", + "value": "ExternalItem.ReadWrite.All" + }, + { + "description": "Allows the app to read external connections without a signed-in user. The app can only read external connections that it is authorized to. ", + "displayName": "ExternalConnection.Read.OwnedBy", + "id": "6ed7b42a-d211-4a23-9d86-4ad9bb3cd8c9", + "origin": "Application (Graph Connector Service)", + "value": "ExternalConnection.Read.OwnedBy" + }, + { + "description": "Allows the app to read and write all external connections without a signed-in user.", + "displayName": "ExternalConnection.ReadWrite.All", + "id": "296c3066-18b3-4977-9e2b-9d2ca1fda62c", + "origin": "Application (Graph Connector Service)", + "value": "ExternalConnection.ReadWrite.All" + }, + { + "description": "Allows the app to read and write external connections without a signed-in user. The app can only read and write external connections that it is authorized to, or it can create new external connections. ", + "displayName": "ExternalConnection.ReadWrite.OwnedBy", + "id": "f4601885-7fd6-4ade-9175-09e03e5bc85c", + "origin": "Application (Graph Connector Service)", + "value": "ExternalConnection.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read settings of external connections without a signed-in user. The app can only read settings of connections that it is authorized to. ", + "displayName": "ExternalConnectionSetting.Read.OwnedBy", + "id": "e5f41e81-b3e3-4345-8fc2-33254784c76b", + "origin": "Application (Graph Connector Service)", + "value": "ExternalConnectionSetting.Read.OwnedBy" + }, + { + "description": "Allows the app to read and write settings of external connections without a signed-in user. The app can only read settings of connections that it is authorized to. ", + "displayName": "ExternalConnectionSetting.ReadWrite.OwnedBy", + "id": "a82b69a1-5441-4adf-b26d-0fe741adab90", + "origin": "Application (Graph Connector Service)", + "value": "ExternalConnectionSetting.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read all external items without a signed-in user.", + "displayName": "ExternalItem.Read.All", + "id": "89e9f68a-2eb2-49a3-94fe-0fd4b162663b", + "origin": "Application (Graph Connector Service)", + "value": "ExternalItem.Read.All" + }, + { + "description": "Allows the app to read external items without a signed-in user. The app can only read items of the connection that it is authorized to.", + "displayName": "ExternalItem.Read.OwnedBy", + "id": "2d39c17b-ba50-4d0b-9b85-6bc10574bcdb", + "origin": "Application (Graph Connector Service)", + "value": "ExternalItem.Read.OwnedBy" + }, + { + "description": "Allows the app to read and write all external items without a signed-in user.", + "displayName": "ExternalItem.ReadWrite.All", + "id": "38c3d6ee-69ee-422f-b954-e17819665354", + "origin": "Application (Graph Connector Service)", + "value": "ExternalItem.ReadWrite.All" + }, + { + "description": "Allows the app to read and write external items without a signed-in user. The app can only read external items of the connection that it is authorized to.", + "displayName": "ExternalItem.ReadWrite.OwnedBy", + "id": "c01869db-7dda-4be3-a224-eea18a6e6beb", + "origin": "Application (Graph Connector Service)", + "value": "ExternalItem.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", + "displayName": "ExternalConnection.Read.All", + "id": "feac6de7-1991-4608-8905-0bed2fd3f86f", + "origin": "Delegated (Graph Connector Service)", + "value": "ExternalConnection.Read.All" + }, + { + "description": "Allows the app to read external connections on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read external connections that it is authorized to. ", + "displayName": "ExternalConnection.Read.OwnedBy", + "id": "039455a3-0a80-4713-841a-f87a5d43bee9", + "origin": "Delegated (Graph Connector Service)", + "value": "ExternalConnection.Read.OwnedBy" + }, + { + "description": "Allows the app to read and write all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", + "displayName": "ExternalConnection.ReadWrite.All", + "id": "d44774bd-e26c-43b1-996d-51bb90a9078e", + "origin": "Delegated (Graph Connector Service)", + "value": "ExternalConnection.ReadWrite.All" + }, + { + "description": "Allows the app to read and write external connections on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read and write external connections that it is authorized to, or it can create new external connections. ", + "displayName": "ExternalConnection.ReadWrite.OwnedBy", + "id": "238a47c3-0105-47ae-804f-44a011bcd9d7", + "origin": "Delegated (Graph Connector Service)", + "value": "ExternalConnection.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read settings of external connections on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read settings of connections that it is authorized to. ", + "displayName": "ExternalConnectionSetting.Read.OwnedBy", + "id": "874ea7d3-6542-4c86-9dea-1a9165a302e8", + "origin": "Delegated (Graph Connector Service)", + "value": "ExternalConnectionSetting.Read.OwnedBy" + }, + { + "description": "Allows the app to read and write settings of external connections on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read settings of connections that it is authorized to.", + "displayName": "ExternalConnectionSetting.ReadWrite.OwnedBy", + "id": "1d1ee9dd-444c-4646-a36a-db2a1feee3a1", + "origin": "Delegated (Graph Connector Service)", + "value": "ExternalConnectionSetting.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read external items on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read items of the connection that it is authorized to.", + "displayName": "ExternalItem.Read.OwnedBy", + "id": "7dd8483d-ffd6-4c0c-a2be-88d3aea446d8", + "origin": "Delegated (Graph Connector Service)", + "value": "ExternalItem.Read.OwnedBy" + }, + { + "description": "Allows the app to read all webhook connection details without a signed-in user.", + "displayName": "WebhookData.Read.All", + "id": "875b7cce-8b8e-4f69-8744-0d0d285c25f3", + "origin": "Application (Graph Connector Service)", + "value": "WebhookData.Read.All" + }, + { + "description": "This allows app to run test tenant userscope in DLS", + "displayName": "UserScope-Dev.ReadWrite.All", + "id": "dc532015-4941-4351-b852-8781cf87c6e5", + "origin": "Application (DirectoryLookupService)", + "value": "UserScope-Dev.ReadWrite.All" + }, + { + "description": "Allows the app to read and write terms of use agreements, without a signed in user.", + "displayName": "Read and write all terms of use agreements", + "id": "c9090d00-6101-42f0-a729-c41074260d47", + "origin": "Application (Microsoft Graph)", + "value": "Agreement.ReadWrite.All" + }, + { + "description": "Allows the app to read all AI enterprise interactions.", + "displayName": "Read all AI enterprise interactions.", + "id": "839c90ab-5771-41ee-aef8-a562e8487c1e", + "origin": "Application (Microsoft Graph)", + "value": "AiEnterpriseInteraction.Read.All" + }, + { + "description": "Allows the app to process and evaluate content for data security, governance and compliance outcomes at tenant scope.", + "displayName": "Process content for data security, governance and compliance", + "id": "5ad511bf-571c-4ef6-8c3c-85b94b85df98", + "origin": "Application (Microsoft Graph)", + "value": "Content.Process.All" + }, + { + "description": "Allows the app to process and evaluate content for data security, governance and compliance outcomes for a user.", + "displayName": "Process content for data security, governance and compliance", + "id": "24ceb246-ad29-4680-90b4-3e91ffad15eb", + "origin": "Application (Microsoft Graph)", + "value": "Content.Process.User" + }, + { + "description": "c", + "displayName": "Read contents activity audit log from the audit store.", + "id": "368425e7-6954-4f5a-9d92-90b75bd580c9", + "origin": "Application (Microsoft Graph)", + "value": "ContentActivity.Read" + }, + { + "description": "Allows the application to upload bulk contents activity audit logs to the audit store.", + "displayName": "Upload content activity audit logs to the audit store.", + "id": "2932e07a-3c29-44e4-bb36-6d0fc176387f", + "origin": "Application (Microsoft Graph)", + "value": "ContentActivity.Write" + }, + { + "description": "Allows the app to read available properties on contracts, without a signed-in user.", + "displayName": "Read contracts", + "id": "f9af4646-98b0-4e9d-a53e-40d4f6452fc4", + "origin": "Application (Microsoft Graph)", + "value": "Contracts.Read.All" + }, + { + "description": "Allows the app to read packages information without a signed-in user.", + "displayName": "Read all packages information", + "id": "72f0655d-6228-4ddc-8e1b-164973b9213b", + "origin": "Application (Microsoft Graph)", + "value": "CopilotPackages.Read.All" + }, + { + "description": "Allows the app to read and update packages information without a signed-in user.", + "displayName": "Read and update all packages information", + "id": "ed31732f-9495-47ed-ba3b-4ed0948c1c64", + "origin": "Application (Microsoft Graph)", + "value": "CopilotPackages.ReadWrite.All" + }, + { + "description": "Allows the app to read Copilot policy settings for the organization, without a signed-in user.", + "displayName": "Read Copilot policy settings", + "id": "556d5e2e-1081-4452-8147-26c3a1b06f58", + "origin": "Application (Microsoft Graph)", + "value": "CopilotPolicySettings.Read" + }, + { + "description": "Allows the app to read and write Copilot policy settings for the organization, without a signed-in user.", + "displayName": "Read and write Copilot policy settings", + "id": "cc147c17-b8e8-4d3f-9f94-aa9e279a079a", + "origin": "Application (Microsoft Graph)", + "value": "CopilotPolicySettings.ReadWrite" + }, + { + "description": "Allows the application to obtain basic tenant information about another target tenant within the Azure AD ecosystem without a signed-in user.", + "displayName": "Read cross-tenant basic information", + "id": "cac88765-0581-4025-9725-5ebc13f729ee", + "origin": "Application (Microsoft Graph)", + "value": "CrossTenantInformation.ReadBasic.All" + }, + { + "description": "Allows the application to list and query any shared user profile information associated with the current tenant without a signed-in user. It also permits the application to export external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant without a signed-in user.", + "displayName": "Read all shared cross-tenant user profiles and export their data", + "id": "8b919d44-6192-4f3d-8a3b-f86f8069ae3c", + "origin": "Application (Microsoft Graph)", + "value": "CrossTenantUserProfileSharing.Read.All" + }, + { + "description": "Allows the application to list and query any shared user profile information associated with the current tenant without a signed-in user. It also permits the application to export and remove external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant without a signed-in user.", + "displayName": "Read all shared cross-tenant user profiles and export or delete their data", + "id": "306785c5-c09b-4ba0-a4ee-023f3da165cb", + "origin": "Application (Microsoft Graph)", + "value": "CrossTenantUserProfileSharing.ReadWrite.All" + }, + { + "description": "Allows the app to read your organization's custom authentication extensions without a signed-in user.", + "displayName": "Read all custom authentication extensions", + "id": "88bb2658-5d9e-454f-aacd-a3933e079526", + "origin": "Application (Microsoft Graph)", + "value": "CustomAuthenticationExtension.Read.All" + }, + { + "description": "Allows the app to read or write your organization's custom authentication extensions without a signed-in user.", + "displayName": "Read and write all custom authentication extensions", + "id": "c2667967-7050-4e7e-b059-4cbbb3811d03", + "origin": "Application (Microsoft Graph)", + "value": "CustomAuthenticationExtension.ReadWrite.All" + }, + { + "description": "Allows custom authentication extensions associated with the app to receive HTTP requests triggered by an authentication event. The request can include information about a user, client and resource service principals, and other information about the authentication.", + "displayName": "Receive custom authentication extension HTTP requests", + "id": "214e810f-fda8-4fd7-a475-29461495eb00", + "origin": "Application (Microsoft Graph)", + "value": "CustomAuthenticationExtension.Receive.Payload" + }, + { + "description": "Allows the app to read custom detection rules without a signed-in user.", + "displayName": "Read all custom detection rules", + "id": "673a007a-9e0f-4c97-b066-3c0164486909", + "origin": "Application (Microsoft Graph)", + "value": "CustomDetection.Read.All" + }, + { + "description": "Allows the app to read and write custom detection rules without a signed-in user.", + "displayName": "Read and write all custom detection rules", + "id": "e0fd9c8d-a12e-4cc9-9827-20c8c3cd6fb8", + "origin": "Application (Microsoft Graph)", + "value": "CustomDetection.ReadWrite.All" + }, + { + "description": "Allows the app to update the on-premises sync behavior of all contacts in all mailboxes without a signed-in user.", + "displayName": "Read and update the on-premises sync behavior of contacts", + "id": "c8948c23-e66b-42db-83fd-770b71ab78d2", + "origin": "Application (Microsoft Graph)", + "value": "Contacts-OnPremisesSyncBehavior.ReadWrite.All" + }, + { + "description": "Allows the app to read custom security attribute assignments for all principals in the tenant without a signed in user.", + "displayName": "Read custom security attribute assignments", + "id": "3b37c5a4-1226-493d-bec3-5d6c6b866f3f", + "origin": "Application (Microsoft Graph)", + "value": "CustomSecAttributeAssignment.Read.All" + }, + { + "description": "Allows the app to read app consent requests and approvals, and deny or approve those requests without a signed-in user.", + "displayName": "Read and write all consent requests", + "id": "9f1b81a7-0223-4428-bfa4-0bcb5535f27d", + "origin": "Application (Microsoft Graph)", + "value": "ConsentRequest.ReadWrite.All" + }, + { + "description": "Allows the app to read names and members of all one-to-one and group chats in Microsoft Teams where the associated Teams application is installed, without a signed-in user.", + "displayName": "Read names and members of all chat threads where the associated Teams application is installed.", + "id": "818ba5bd-5b3e-4fe0-bbe6-aa4686669073", + "origin": "Application (Microsoft Graph)", + "value": "Chat.ReadBasic.WhereInstalled" + }, + { + "description": "Allows an app to read and write all chat messages in Microsoft Teams, without a signed-in user.", + "displayName": "Read and write all chat messages", + "id": "294ce7c9-31ba-490a-ad7d-97a7d075e4ed", + "origin": "Application (Microsoft Graph)", + "value": "Chat.ReadWrite.All" + }, + { + "description": "Allows the app to read and write all chat messages in Microsoft Teams for chats where the associated Teams application is installed, without a signed-in user.", + "displayName": "Read and write all chat messages for chats where the associated Teams application is installed.", + "id": "ad73ce80-f3cd-40ce-b325-df12c33df713", + "origin": "Application (Microsoft Graph)", + "value": "Chat.ReadWrite.WhereInstalled" + }, + { + "description": "Allows the app to update Microsoft Teams 1-to-1 or group chat messages by patching a set of Data Loss Prevention (DLP) policy violation properties to handle the output of DLP processing.", + "displayName": "Flag chat messages for violating policy", + "id": "7e847308-e030-4183-9899-5235d7270f58", + "origin": "Application (Microsoft Graph)", + "value": "Chat.UpdatePolicyViolation.All" + }, + { + "description": "Read the members of all chats, without a signed-in user.", + "displayName": "Read the members of all chats", + "id": "a3410be2-8e48-4f32-8454-c29a7465209d", + "origin": "Application (Microsoft Graph)", + "value": "ChatMember.Read.All" + }, + { + "description": "Allows the app to read the members of all chats where the associated Teams application is installed, without a signed-in user.", + "displayName": "Read the members of all chats where the associated Teams application is installed.", + "id": "93e7c9e4-54c5-4a41-b796-f2a5adaacda7", + "origin": "Application (Microsoft Graph)", + "value": "ChatMember.Read.WhereInstalled" + }, + { + "description": "Add and remove members from all chats, without a signed-in user.", + "displayName": "Add and remove members from all chats", + "id": "57257249-34ce-4810-a8a2-a03adf0c5693", + "origin": "Application (Microsoft Graph)", + "value": "ChatMember.ReadWrite.All" + }, + { + "description": "Allows the app to add and remove members from all chats where the associated Teams application is installed, without a signed-in user.", + "displayName": "Add and remove members from all chats where the associated Teams application is installed.", + "id": "e32c2cd9-0124-4e44-88fc-772cd98afbdb", + "origin": "Application (Microsoft Graph)", + "value": "ChatMember.ReadWrite.WhereInstalled" + }, + { + "description": "Allows the app to read all one-to-one and group chats messages in Microsoft Teams, without a signed-in user.", + "displayName": "Read all chat messages", + "id": "b9bb2381-47a4-46cd-aafb-00cb12f68504", + "origin": "Application (Microsoft Graph)", + "value": "ChatMessage.Read.All" + }, + { + "description": "Allows the app to read all details of discovered cloud apps in the organization, without a signed-in user.", + "displayName": "Read all discovered cloud applications data", + "id": "64a59178-dad3-4673-89db-84fdcd622fec", + "origin": "Application (Microsoft Graph)", + "value": "CloudApp-Discovery.Read.All" + }, + { + "description": "Allows the app to read the properties of Cloud PCs, without a signed-in user.", + "displayName": "Read Cloud PCs", + "id": "a9e09520-8ed4-4cde-838e-4fdea192c227", + "origin": "Application (Microsoft Graph)", + "value": "CloudPC.Read.All" + }, + { + "description": "Allows the app to read and write the properties of Cloud PCs, without a signed-in user.", + "displayName": "Read and write Cloud PCs", + "id": "3b4349e1-8cf5-45a3-95b7-69d1751d3e6a", + "origin": "Application (Microsoft Graph)", + "value": "CloudPC.ReadWrite.All" + }, + { + "description": "Allows the app to list Viva Engage communities, and to read their properties without a signed-in user.", + "displayName": "Read all Viva Engage communities", + "id": "407f0cce-3212-441f-9f55-3bc91342cf86", + "origin": "Application (Microsoft Graph)", + "value": "Community.Read.All" + }, + { + "description": "Allows the app to create Viva Engage communities, read all community properties, update community properties, and delete communities without a signed-in user.", + "displayName": "Read and write all Viva Engage communities", + "id": "35d59e32-eab5-4553-9345-abb62b4c703c", + "origin": "Application (Microsoft Graph)", + "value": "Community.ReadWrite.All" + }, + { + "description": "Allows the app to read all Configuration Monitoring entities, without a signed-in user.", + "displayName": "Read all Configuration Monitoring entities", + "id": "aca929ec-9830-44dc-bda1-85cf938aaa95", + "origin": "Application (Microsoft Graph)", + "value": "ConfigurationMonitoring.Read.All" + }, + { + "description": "Allows the app to read and write all Configuration Monitoring entities, without a signed-in user.", + "displayName": "Read and write all Configuration Monitoring entities", + "id": "cfa85bfb-2ee8-4e13-8e7f-489e57a015a1", + "origin": "Application (Microsoft Graph)", + "value": "ConfigurationMonitoring.ReadWrite.All" + }, + { + "description": "Allows the app to read consent requests and approvals without a signed-in user.", + "displayName": "Read all consent requests", + "id": "1260ad83-98fb-4785-abbb-d6cc1806fd41", + "origin": "Application (Microsoft Graph)", + "value": "ConsentRequest.Read.All" + }, + { + "description": "Allows the app to read and write custom security attribute assignments for all principals in the tenant without a signed in user.", + "displayName": "Read and write custom security attribute assignments", + "id": "de89b5e4-5b8f-48eb-8925-29c2b33bd8bd", + "origin": "Application (Microsoft Graph)", + "value": "CustomSecAttributeAssignment.ReadWrite.All" + }, + { + "description": "Allows the app to read all audit logs for events that contain information about custom security attributes, without a signed-in user.", + "displayName": "Read all custom security attribute audit logs", + "id": "2a4f026d-e829-4e84-bdbf-d981a2703059", + "origin": "Application (Microsoft Graph)", + "value": "CustomSecAttributeAuditLogs.Read.All" + }, + { + "description": "Allows the app to read custom security attribute definitions for the tenant without a signed in user.", + "displayName": "Read custom security attribute definitions", + "id": "b185aa14-d8d2-42c1-a685-0f5596613624", + "origin": "Application (Microsoft Graph)", + "value": "CustomSecAttributeDefinition.Read.All" + }, + { + "description": "Allows the app to read the properties of devices managed by Microsoft Intune, without a signed-in user.", + "displayName": "Read Microsoft Intune devices", + "id": "2f51be20-0bb4-4fed-bf7b-db946066c75e", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementManagedDevices.Read.All" + }, + { + "description": "Allows the app to read and write the properties of devices managed by Microsoft Intune, without a signed-in user. Does not allow high impact operations such as remote wipe and password reset on the device’s owner", + "displayName": "Read and write Microsoft Intune devices", + "id": "243333ab-4d21-40cb-a475-36241daa0842", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementManagedDevices.ReadWrite.All" + }, + { + "description": "Allows the app to read the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings, without a signed-in user.", + "displayName": "Read Microsoft Intune RBAC settings", + "id": "58ca0d9a-1575-47e1-a3cb-007ef2e4583b", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementRBAC.Read.All" + }, + { + "description": "Allows the app to read and write the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings, without a signed-in user.", + "displayName": "Read and write Microsoft Intune RBAC settings", + "id": "e330c4f0-4170-414e-a55a-2f022ec2b57b", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementRBAC.ReadWrite.All" + }, + { + "description": "Allows the app to read Microsoft Intune device compliance scripts, device management scripts, device shell scripts, device custom attribute shell scripts and device health scripts, without a signed-in user.", + "displayName": "Read Microsoft Intune Scripts", + "id": "c7a5be92-2b3d-4540-8a67-c96dcaae8b43", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementScripts.Read.All" + }, + { + "description": "Allows the app to read and write Microsoft Intune device compliance scripts, device management scripts, device shell scripts, device custom attribute shell scripts and device health scripts, without a signed-in user.", + "displayName": "Read and write Microsoft Intune Scripts", + "id": "9255e99d-faf5-445e-bbf7-cb71482737c4", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementScripts.ReadWrite.All" + }, + { + "description": "Allows the app to read Microsoft Intune service properties including device enrollment and third party service connection configuration, without a signed-in user.", + "displayName": "Read Microsoft Intune configuration", + "id": "06a5fe6d-c49d-46a7-b082-56b1b14103c7", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementServiceConfig.Read.All" + }, + { + "description": "Allows the app to read and write Microsoft Intune service properties including device enrollment and third party service connection configuration, without a signed-in user.", + "displayName": "Read and write Microsoft Intune configuration", + "id": "5ac13192-7ace-4fcf-b828-1a26f28068ee", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementServiceConfig.ReadWrite.All" + }, + { + "description": "Allows the app to create device templates. The app is marked as owner of the created device template. As a member of owners, the app will be allowed to manage devices created from the template.", + "displayName": "Create device template", + "id": "abf6441f-0772-4932-96e7-0191478dd73a", + "origin": "Application (Microsoft Graph)", + "value": "DeviceTemplate.Create" + }, + { + "description": "Allows the app to read all device templates, without a signed-in user.", + "displayName": "Read all device templates", + "id": "dd9febb5-0c6d-419f-b256-3afe12c6adeb", + "origin": "Application (Microsoft Graph)", + "value": "DeviceTemplate.Read.All" + }, + { + "description": "Allows the app to create, read, update and delete any device template, without a signed-in user. It also allows the app to add or remove owners on any device template.", + "displayName": "Read and write all device templates", + "id": "9fadb66e-6421-4744-aede-4ab6fb98a884", + "origin": "Application (Microsoft Graph)", + "value": "DeviceTemplate.ReadWrite.All" + }, + { + "description": "Allows the app to read data in your organization's directory, such as users, groups and apps, without a signed-in user.", + "displayName": "Read directory data", + "id": "7ab1d382-f21e-4acd-a863-ba3e13f7da61", + "origin": "Application (Microsoft Graph)", + "value": "Directory.Read.All" + }, + { + "description": "Allows the app to read and write data in your organization's directory, such as users, and groups, without a signed-in user. Does not allow user or group deletion.", + "displayName": "Read and write directory data", + "id": "19dbc75e-c2e2-444c-a770-ec69d8559fc7", + "origin": "Application (Microsoft Graph)", + "value": "Directory.ReadWrite.All" + }, + { + "description": "Allows the app to read all Azure AD recommendations, without a signed-in user.", + "displayName": "Read all Azure AD recommendations", + "id": "ae73097b-cb2a-4447-b064-5d80f6093921", + "origin": "Application (Microsoft Graph)", + "value": "DirectoryRecommendations.Read.All" + }, + { + "description": "Allows the app to read and update all Azure AD recommendations, without a signed-in user.", + "displayName": "Read and update all Azure AD recommendations", + "id": "0e9eea12-4f01-45f6-9b8d-3ea4c8144158", + "origin": "Application (Microsoft Graph)", + "value": "DirectoryRecommendations.ReadWrite.All" + }, + { + "description": "Allows the app to read all domain properties without a signed-in user.", + "displayName": "Read domains", + "id": "dbb9058a-0e50-45d7-ae91-66909b5d4664", + "origin": "Application (Microsoft Graph)", + "value": "Domain.Read.All" + }, + { + "description": "Allows the app to read and write all domain properties without a signed in user. Also allows the app to add, verify and remove domains.", + "displayName": "Read and write domains", + "id": "7e05723c-0bb0-42da-be95-ae9f08a6e53c", + "origin": "Application (Microsoft Graph)", + "value": "Domain.ReadWrite.All" + }, + { + "description": "Allows the app to perform remote high impact actions such as wiping the device or resetting the passcode on devices managed by Microsoft Intune, without a signed-in user.", + "displayName": "Perform user-impacting remote actions on Microsoft Intune devices", + "id": "5b07b0dd-2377-4e44-a38d-703f09a0dc3c", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementManagedDevices.PrivilegedOperations.All" + }, + { + "description": "Allows the app to read and write properties of Microsoft Intune-managed deployment plans and their ring configurations, without a signed-in user.", + "displayName": "Read and write Microsoft Intune Deployment Plans", + "id": "68356fd1-028d-4ce3-b724-241dec11127a", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementDeploymentPlans.ReadWrite.All" + }, + { + "description": "Allows the app to read properties of Microsoft Intune-managed deployment plans and their ring configurations, without a signed-in user.", + "displayName": "Read Microsoft Intune Deployment Plans", + "id": "c5825671-0390-4bf2-b99b-80496fd4b673", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementDeploymentPlans.Read.All" + }, + { + "description": "Allows the app to read and write properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups, without a signed-in user.", + "displayName": "Read and write Microsoft Intune device configuration and policies", + "id": "9241abd9-d0e6-425a-bd4f-47ba86e767a4", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementConfiguration.ReadWrite.All" + }, + { + "description": "Allows the app to read and write custom security attribute definitions for the tenant without a signed in user.", + "displayName": "Read and write custom security attribute definitions", + "id": "12338004-21f4-4896-bf5e-b75dfaf1016d", + "origin": "Application (Microsoft Graph)", + "value": "CustomSecAttributeDefinition.ReadWrite.All" + }, + { + "description": "Allows the app to read the provisioning configuration of all active custom security attributes without a signed-in user.", + "displayName": "Read the provisioning configuration of all active custom security attributes", + "id": "9fd1f8bf-a443-4df6-bc2a-5d00c5ec7828", + "origin": "Application (Microsoft Graph)", + "value": "CustomSecAttributeProvisioning.Read.All" + }, + { + "description": "Allows the app to read and edit the provisioning configuration of all active custom security attributes without a signed-in user.", + "displayName": "Read and edit the provisioning configuration of all active custom security attributes", + "id": "1db69e9c-8d0a-498d-a5df-11fd0b68ceab", + "origin": "Application (Microsoft Graph)", + "value": "CustomSecAttributeProvisioning.ReadWrite.All" + }, + { + "description": "Read custom tags data, without a signed-in user", + "displayName": "Read all custom tags data", + "id": "ab8a5872-7c88-47a6-8141-7becce939190", + "origin": "Application (Microsoft Graph)", + "value": "CustomTags.Read.All" + }, + { + "description": "Read and write custom tags data, without a signed-in user", + "displayName": "Read and write custom tags data", + "id": "2f503208-e509-4e39-974c-8cc16e5785c9", + "origin": "Application (Microsoft Graph)", + "value": "CustomTags.ReadWrite.All" + }, + { + "description": "Allows the app to read details of delegated admin relationships with customers like access details (that includes roles) and the duration as well as specific role assignments to security groups without a signed-in user.", + "displayName": "Read Delegated Admin relationships with customers", + "id": "f6e9e124-4586-492f-adc0-c6f96e4823fd", + "origin": "Application (Microsoft Graph)", + "value": "DelegatedAdminRelationship.Read.All" + }, + { + "description": "Allows the app to manage (create-update-terminate) Delegated Admin relationships with customers and role assignments to security groups for active Delegated Admin relationships without a signed-in user.", + "displayName": "Manage Delegated Admin relationships with customers", + "id": "cc13eba4-8cd8-44c6-b4d4-f93237adce58", + "origin": "Application (Microsoft Graph)", + "value": "DelegatedAdminRelationship.ReadWrite.All" + }, + { + "description": "Allows the app to read all delegated permission grants, without a signed-in user.", + "displayName": "Read all delegated permission grants", + "id": "81b4724a-58aa-41c1-8a55-84ef97466587", + "origin": "Application (Microsoft Graph)", + "value": "DelegatedPermissionGrant.Read.All" + }, + { + "description": "Read names and members of all one-to-one and group chats in Microsoft Teams, without a signed-in user.", + "displayName": "Read names and members of all chat threads", + "id": "b2e060da-3baf-4687-9611-f4ebc0f0cbde", + "origin": "Application (Microsoft Graph)", + "value": "Chat.ReadBasic.All" + }, + { + "description": "Allows the app to manage permission grants for delegated permissions exposed by any API (including Microsoft Graph), without a signed-in user.", + "displayName": "Manage all delegated permission grants", + "id": "8e8e4742-1d95-4f68-9d56-6ee75648c72a", + "origin": "Application (Microsoft Graph)", + "value": "DelegatedPermissionGrant.ReadWrite.All" + }, + { + "description": "Allows the app to read device local credential properties including passwords, without a signed-in user.", + "displayName": "Read device local credential passwords", + "id": "884b599e-4d48-43a5-ba94-15c414d00588", + "origin": "Application (Microsoft Graph)", + "value": "DeviceLocalCredential.Read.All" + }, + { + "description": "Allows the app to read device local credential properties excluding passwords, without a signed-in user.", + "displayName": "Read device local credential properties", + "id": "db51be59-e728-414b-b800-e0f010df1a79", + "origin": "Application (Microsoft Graph)", + "value": "DeviceLocalCredential.ReadBasic.All" + }, + { + "description": "Allows the app to read the properties, group assignments and status of apps, app configurations and app protection policies managed by Microsoft Intune, without a signed-in user.", + "displayName": "Read Microsoft Intune apps", + "id": "7a6ee1e7-141e-4cec-ae74-d9db155731ff", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementApps.Read.All" + }, + { + "description": "Allows the app to read and write the properties, group assignments and status of apps, app configurations and app protection policies managed by Microsoft Intune, without a signed-in user.", + "displayName": "Read and write Microsoft Intune apps", + "id": "78145de6-330d-4800-a6ce-494ff2d33d07", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementApps.ReadWrite.All" + }, + { + "description": "Allows the app to read certification authority information without a signed-in user.", + "displayName": "Read Microsoft Cloud PKI objects", + "id": "315b6e8c-d92a-4691-919d-00ce76d1344a", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementCloudCA.Read.All" + }, + { + "description": "Allows the app to read and write certification authority information without a signed-in user.", + "displayName": "Read and write Microsoft Cloud PKI objects", + "id": "f15eb2ba-ef8a-4f70-991d-da5d045154e2", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementCloudCA.ReadWrite.All" + }, + { + "description": "Allows the app to read properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups, without a signed-in user.", + "displayName": "Read Microsoft Intune device configuration and policies", + "id": "dc377aa6-52d8-4e23-b271-2a7ae04cedf3", + "origin": "Application (Microsoft Graph)", + "value": "DeviceManagementConfiguration.Read.All" + }, + { + "description": "Allows the app to read your organization's devices' configuration information without a signed-in user.", + "displayName": "Read all devices", + "id": "7438b122-aefc-4978-80ed-43db9fcc7715", + "origin": "Application (Microsoft Graph)", + "value": "Device.Read.All" + }, + { + "description": "Allows the app to read terms of use acceptance statuses, without a signed in user.", + "displayName": "Read all terms of use acceptance statuses", + "id": "d8e4ec18-f6c0-4620-8122-c8b1f2bf400e", + "origin": "Application (Microsoft Graph)", + "value": "AgreementAcceptance.Read.All" + }, + { + "description": "Allows the app to read all one-to-one or group chat messages in Microsoft Teams for chats where the associated Teams application is installed, without a signed-in user.", + "displayName": "Read all chat messages for chats where the associated Teams application is installed.", + "id": "1c1b4c8e-3cc7-4c58-8470-9b92c9d5848b", + "origin": "Application (Microsoft Graph)", + "value": "Chat.Read.WhereInstalled" + }, + { + "description": "Allows the app to delete and recover deleted chats, without a signed-in user.", + "displayName": "Delete and recover deleted chats", + "id": "9c7abde0-eacd-4319-bf9e-35994b1a1717", + "origin": "Application (Microsoft Graph)", + "value": "Chat.ManageDeletion.All" + }, + { + "description": "Allows the app to read and query audit logs from Exchange workload, without a signed-in user", + "displayName": "Read audit logs data from Exchange workload", + "id": "6b0d2622-d34e-4470-935b-b96550e5ca8d", + "origin": "Application (Microsoft Graph)", + "value": "AuditLogsQuery-Exchange.Read.All" + }, + { + "description": "Allows the app to read and query audit logs from OneDrive workload, without a signed-in user", + "displayName": "Read audit logs data from OneDrive workload", + "id": "8a169a81-841c-45fd-ad43-96aede8801a0", + "origin": "Application (Microsoft Graph)", + "value": "AuditLogsQuery-OneDrive.Read.All" + }, + { + "description": "Allows the app to read and query audit logs from SharePoint workload, without a signed-in user", + "displayName": "Read audit logs data from SharePoint workload", + "id": "91c64a47-a524-4fce-9bf3-3d569a344ecf", + "origin": "Application (Microsoft Graph)", + "value": "AuditLogsQuery-SharePoint.Read.All" + }, + { + "description": "Allows the app to read the authentication context information in your organization without a signed-in user.", + "displayName": "Read all authentication context information", + "id": "381f742f-e1f8-4309-b4ab-e3d91ae4c5c1", + "origin": "Application (Microsoft Graph)", + "value": "AuthenticationContext.Read.All" + }, + { + "description": "Allows the app to read and update the authentication context information in your organization without a signed-in user.", + "displayName": "Read and write all authentication context information", + "id": "a88eef72-fed0-4bf7-a2a9-f19df33f8b83", + "origin": "Application (Microsoft Graph)", + "value": "AuthenticationContext.ReadWrite.All" + }, + { + "description": "Allows the app to read all backup configurations, and lists of Microsoft 365 service resources to be backed-up, without a signed-in user.", + "displayName": "Read all backup configuration policies", + "id": "5fbb5982-3230-4882-93c0-2167523ce0c2", + "origin": "Application (Microsoft Graph)", + "value": "BackupRestore-Configuration.Read.All" + }, + { + "description": "Allows the app to read and update the backup configuration, and list of Microsoft 365 service resources to be backed-up, without a signed-in user.", + "displayName": "Read and edit all backup configuration policies", + "id": "18133149-5489-40ac-80f0-4b6fa85f6cdc", + "origin": "Application (Microsoft Graph)", + "value": "BackupRestore-Configuration.ReadWrite.All" + }, + { + "description": "Allows the app to read the status of M365 backup service (enable/disable), without signed in user", + "displayName": "Read the status of the M365 backup service", + "id": "6fe20a79-0e15-45a1-b019-834c125993a0", + "origin": "Application (Microsoft Graph)", + "value": "BackupRestore-Control.Read.All" + }, + { + "description": "Allows the app to update or read the status of M365 backup service (enable/disable), without signed in user", + "displayName": "Update or read the status of the M365 backup service", + "id": "fb240865-88f8-4a1d-923f-98dbc7920860", + "origin": "Application (Microsoft Graph)", + "value": "BackupRestore-Control.ReadWrite.All" + }, + { + "description": "Allows the app to monitor all backup and restore jobs, view quota usage and billing details, without a signed-in user.", + "displayName": "Read all monitoring, quota and billing information for the tenant", + "id": "ecae8511-f2d7-4be4-bdbf-91f244d45986", + "origin": "Application (Microsoft Graph)", + "value": "BackupRestore-Monitor.Read.All" + }, + { + "description": "Allows the app to read all restore sessions, without a signed-in user.", + "displayName": "Read all restore sessions", + "id": "87853aa5-0372-4710-b34b-cef27bb7156e", + "origin": "Application (Microsoft Graph)", + "value": "BackupRestore-Restore.Read.All" + }, + { + "description": "Allows the app to search all backup snapshots for Microsoft 365 resources, and restore Microsoft 365 resources from a backed-up snapshot, without a signed-in user.", + "displayName": "Read restore all sessions and start restore sessions from backups", + "id": "bebd0841-a3d8-4313-a51d-731112c8ee41", + "origin": "Application (Microsoft Graph)", + "value": "BackupRestore-Restore.ReadWrite.All" + }, + { + "description": "Allows the app to search all backup snapshots for Microsoft 365 resources, without a signed-in user.", + "displayName": "Search for metadata properties in all backup snapshots", + "id": "f6135c51-c766-4be1-9638-ed90c2ed2443", + "origin": "Application (Microsoft Graph)", + "value": "BackupRestore-Search.Read.All" + }, + { + "description": "Allows the app to read and write the billing configuration on all applications without a signed-in user.", + "displayName": "Read and write application billing configuration", + "id": "9e8be751-7eee-4c09-bcfd-d64f6b087fd8", + "origin": "Application (Microsoft Graph)", + "value": "BillingConfiguration.ReadWrite.All" + }, + { + "description": "Allows an app to read BitLocker keys for all devices, without a signed-in user. Allows read of the recovery key.", + "displayName": "Read all BitLocker keys", + "id": "57f1cf28-c0c4-4ec3-9a30-19a2eaaf2f6e", + "origin": "Application (Microsoft Graph)", + "value": "BitlockerKey.Read.All" + }, + { + "description": "Allows an app to read basic BitLocker key properties for all devices, without a signed-in user. Does not allow read of the recovery key.", + "displayName": "Read all BitLocker keys basic information", + "id": "f690d423-6b29-4d04-98c6-694c42282419", + "origin": "Application (Microsoft Graph)", + "value": "BitlockerKey.ReadBasic.All" + }, + { + "description": "Allows an app to read, write and manage bookings appointments, businesses, customers, services, and staff on behalf of the signed-in user.", + "displayName": "Manage bookings information", + "id": "6b22000a-1228-42ec-88db-b8c00399aecb", + "origin": "Application (Microsoft Graph)", + "value": "Bookings.Manage.All" + }, + { + "description": "Allows the app to read and query audit logs from Entra (Azure AD) workload, without a signed-in user", + "displayName": "Read audit logs data from Entra (Azure AD) workload", + "id": "7276d950-48fc-4269-8348-f22f2bb296d0", + "origin": "Application (Microsoft Graph)", + "value": "AuditLogsQuery-Entra.Read.All" + }, + { + "description": "Allows an app to read Bookings appointments, businesses, customers, services, and staff without a signed-in user. ", + "displayName": "Read all Bookings related resources.", + "id": "6e98f277-b046-4193-a4f2-6bf6a78cd491", + "origin": "Application (Microsoft Graph)", + "value": "Bookings.Read.All" + }, + { + "description": "Allows the app to read and query audit logs from Endpoint Data Loss Prevention workload, without a signed-in user", + "displayName": "Read audit logs data from Endpoint Data Loss Prevention workload", + "id": "0bc85aed-7b0b-437a-bac8-3b29a1b84c99", + "origin": "Application (Microsoft Graph)", + "value": "AuditLogsQuery-Endpoint.Read.All" + }, + { + "description": "Allows the app to read and query audit logs from all services.", + "displayName": "Read audit logs data from all services", + "id": "5e1e9171-754d-478c-812c-f1755a9a4c2d", + "origin": "Application (Microsoft Graph)", + "value": "AuditLogsQuery.Read.All" + }, + { + "description": "Allows the app to read the API connectors used in user authentication flows, without a signed-in user.", + "displayName": "Read API connectors for authentication flows", + "id": "b86848a7-d5b1-41eb-a9b4-54a4e6306e97", + "origin": "Application (Microsoft Graph)", + "value": "APIConnectors.Read.All" + }, + { + "description": "Allows the app to read, create and manage the API connectors used in user authentication flows, without a signed-in user.", + "displayName": "Read and write API connectors for authentication flows", + "id": "1dfe531a-24a6-4f1b-80f4-7a0dc5a0a171", + "origin": "Application (Microsoft Graph)", + "value": "APIConnectors.ReadWrite.All" + }, + { + "description": "Allows the app to read apps in the app catalogs without a signed-in user.", + "displayName": "Read all app catalogs", + "id": "e12dae10-5a57-4817-b79d-dfbec5348930", + "origin": "Application (Microsoft Graph)", + "value": "AppCatalog.Read.All" + }, + { + "description": "Allows the app to create, read, update, and delete apps in the app catalogs without a signed-in user.", + "displayName": "Read and write to all app catalogs", + "id": "dc149144-f292-421e-b185-5953f2e98d7f", + "origin": "Application (Microsoft Graph)", + "value": "AppCatalog.ReadWrite.All" + }, + { + "description": "Allows the app to read all applications and service principals without a signed-in user.", + "displayName": "Read all applications", + "id": "9a5d68dd-52b0-4cc2-bd40-abcf44ac3a30", + "origin": "Application (Microsoft Graph)", + "value": "Application.Read.All" + }, + { + "description": "Allows the app to read and update all apps in your organization, without a signed-in user.", + "displayName": "Read and update all apps", + "id": "fc023787-fd04-4e44-9bc7-d454f00c0f0a", + "origin": "Application (Microsoft Graph)", + "value": "Application.ReadUpdate.All" + }, + { + "description": "Allows the app to create, read, update and delete applications and service principals without a signed-in user. Allows management of app role assignments, except those exposed by Microsoft Graph. Does not allow management of delegated permission grants.", + "displayName": "Read and write all applications", + "id": "1bfefb4e-e0b5-418b-a88f-73c46d2cc8e9", + "origin": "Application (Microsoft Graph)", + "value": "Application.ReadWrite.All" + }, + { + "description": "Allows the app to create other applications, and fully manage those applications (read, update, update application secrets and delete), without a signed-in user. It cannot update any apps that it is not an owner of.", + "displayName": "Manage apps that this app creates or owns", + "id": "18a4783c-866b-4cc7-a460-3d5e5662c884", + "origin": "Application (Microsoft Graph)", + "value": "Application.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read and write the remote desktop security configuration for all apps in your organization, without a signed-in user.", + "displayName": "Read and write the remote desktop security configuration for all apps", + "id": "3be0012a-cc4e-426b-895b-f9c836bf6381", + "origin": "Application (Microsoft Graph)", + "value": "Application-RemoteDesktopConfig.ReadWrite.All" + }, + { + "description": "Allows the app to manage permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, without a signed-in user.", + "displayName": "Manage app permission grants and app role assignments", + "id": "06b708a9-e830-4db3-a914-8e69da51d44f", + "origin": "Application (Microsoft Graph)", + "value": "AppRoleAssignment.ReadWrite.All" + }, + { + "description": "Allows the app to read all approvals and approval item subscriptions, without a signed-in user.", + "displayName": "Read all approvals", + "id": "9f265de7-8d5e-4e9a-a805-5e8bbc49656f", + "origin": "Application (Microsoft Graph)", + "value": "ApprovalSolution.Read.All" + }, + { + "description": "Allows the app to read all approvals and create, update, or remove approval item subscriptions, without a signed-in user.", + "displayName": "Read all approvals and manage approval subscriptions", + "id": "45583558-1113-4d06-8969-e79a28edc9ad", + "origin": "Application (Microsoft Graph)", + "value": "ApprovalSolution.ReadWrite.All" + }, + { + "description": "Allows the app to read attack simulation and training data for an organization without a signed-in user.", + "displayName": "Read attack simulation data of an organization", + "id": "93283d0a-6322-4fa8-966b-8c121624760d", + "origin": "Application (Microsoft Graph)", + "value": "AttackSimulation.Read.All" + }, + { + "description": "Allows the app to read, create, and update attack simulation and training data for an organization without a signed-in user.", + "displayName": "Read, create, and update all attack simulation data of an organization", + "id": "e125258e-8c8a-42a8-8f55-ab502afa52f3", + "origin": "Application (Microsoft Graph)", + "value": "AttackSimulation.ReadWrite.All" + }, + { + "description": "c", + "displayName": "Read activity audit log from the audit store.", + "id": "99bc85fb-e857-4220-9f8c-3a1c83148d2e", + "origin": "Application (Microsoft Graph)", + "value": "AuditActivity.Read" + }, + { + "description": "Allows the application to upload bulk activity audit logs to the audit store.", + "displayName": "Upload activity audit logs to the audit store.", + "id": "f6318678-2713-4bb6-b123-233e7336c1bd", + "origin": "Application (Microsoft Graph)", + "value": "AuditActivity.Write" + }, + { + "description": "Allows the app to read and query your audit log activities, without a signed-in user.", + "displayName": "Read all audit log data", + "id": "b0afded3-3588-46d8-8b3d-9842eff778da", + "origin": "Application (Microsoft Graph)", + "value": "AuditLog.Read.All" + }, + { + "description": "Allows the app to read and query audit logs from Dynamics CRM workload, without a signed-in user", + "displayName": "Read audit logs data from Dynamics CRM workload", + "id": "20e6f8e4-ffac-4cf7-82f7-70ddb7564318", + "origin": "Application (Microsoft Graph)", + "value": "AuditLogsQuery-CRM.Read.All" + }, + { + "description": "Allows an app to read and write bookings appointments, businesses, customers, services, and staff on behalf of the signed-in user. Does not allow create, delete and publish of booking businesses.", + "displayName": "Read and write bookings information", + "id": "0c4b2d20-7919-468d-8668-c54b09d4dee8", + "origin": "Application (Microsoft Graph)", + "value": "Bookings.ReadWrite.All" + }, + { + "description": "Allows an app to read and write Bookings appointments and customers, and additionally allows reading businesses, services, and staff without a signed-in user.", + "displayName": "Read and write all Bookings related resources.", + "id": "9769393e-5a9f-4302-9e3d-7e018ecb64a7", + "origin": "Application (Microsoft Graph)", + "value": "BookingsAppointment.ReadWrite.All" + }, + { + "description": "Allows an app to read all bookmarks without a signed-in user.", + "displayName": "Read all bookmarks", + "id": "be95e614-8ef3-49eb-8464-1c9503433b86", + "origin": "Application (Microsoft Graph)", + "value": "Bookmark.Read.All" + }, + { + "description": "Allows the app to join group calls and scheduled meetings in your organization, without a signed-in user. The app will be joined with the privileges of a directory user to meetings in your organization.", + "displayName": "Join group calls and meetings as an app", + "id": "f6b49018-60ab-4f81-83bd-22caeabfed2d", + "origin": "Application (Microsoft Graph)", + "value": "Calls.JoinGroupCall.All" + }, + { + "description": "Allows the app to anonymously join group calls and scheduled meetings in your organization, without a signed-in user. The app will be joined as a guest to meetings in your organization.", + "displayName": "Join group calls and meetings as a guest", + "id": "fd7ccf6b-3d28-418b-9701-cd10f5cd2fd4", + "origin": "Application (Microsoft Graph)", + "value": "Calls.JoinGroupCallAsGuest.All" + }, + { + "description": "Allows the app to report synthetic media detections for participants in calls, without a signed-in user.", + "displayName": "Report synthetic media detections in calls", + "id": "050b0d28-840a-4ff6-bdf9-cc6221acbc1f", + "origin": "Application (Microsoft Graph)", + "value": "Calls.ReportSyntheticMedia.All" + }, + { + "description": "Allows the app to read call transcripts for all calls without a signed-in user.", + "displayName": "Read all call transcripts", + "id": "4cd61b6d-8692-40bf-9d90-7f38db5e5fce", + "origin": "Application (Microsoft Graph)", + "value": "CallTranscripts.Read.All" + }, + { + "description": "Allows the app to read all cases, relations, tasks, attachments and activities, without a signed-in user.", + "displayName": "Read all cases, relations, tasks, attachments and activities", + "id": "b328f35f-712c-40d6-b6b4-95449d77b352", + "origin": "Application (Microsoft Graph)", + "value": "CaseManagement.Read.All" + }, + { + "description": "Allows the app to read and write to all cases, relations, tasks, attachments and activities, without a signed-in user.", + "displayName": "Read and write to all cases, relations, tasks, attachments and activities", + "id": "57ac77a0-bb98-4ba8-bf9a-7af06dcdcc1f", + "origin": "Application (Microsoft Graph)", + "value": "CaseManagement.ReadWrite.All" + }, + { + "description": "Allows to read all Change Management items.", + "displayName": "Read Change Management items", + "id": "418dae40-2b65-4819-900c-519a04e4d278", + "origin": "Application (Microsoft Graph)", + "value": "ChangeManagement.Read.All" + }, + { + "description": "Create channels in any team, without a signed-in user.", + "displayName": "Create channels", + "id": "f3a65bd4-b703-46df-8f7e-0174fea562aa", + "origin": "Application (Microsoft Graph)", + "value": "Channel.Create" + }, + { + "description": "Delete channels in any team, without a signed-in user.", + "displayName": "Delete channels", + "id": "6a118a39-1227-45d4-af0c-ea7b40d210bc", + "origin": "Application (Microsoft Graph)", + "value": "Channel.Delete.All" + }, + { + "description": "Read all channel names and channel descriptions, without a signed-in user.", + "displayName": "Read the names and descriptions of all channels", + "id": "59a6b24b-4225-4393-8165-ebaec5f55d7a", + "origin": "Application (Microsoft Graph)", + "value": "Channel.ReadBasic.All" + }, + { + "description": "Read the members of all channels, without a signed-in user.", + "displayName": "Read the members of all channels", + "id": "3b55498e-47ec-484f-8136-9013221c06a9", + "origin": "Application (Microsoft Graph)", + "value": "ChannelMember.Read.All" + }, + { + "description": "Add and remove members from all channels, without a signed-in user. Also allows changing a member's role, for example from owner to non-owner.", + "displayName": "Add and remove members from all channels", + "id": "35930dcf-aceb-4bd1-b99a-8ffed403c974", + "origin": "Application (Microsoft Graph)", + "value": "ChannelMember.ReadWrite.All" + }, + { + "description": "Allows the app to read all channel messages in Microsoft Teams", + "displayName": "Read all channel messages", + "id": "7b2449af-6ccd-4f4d-9f78-e550c193f0d1", + "origin": "Application (Microsoft Graph)", + "value": "ChannelMessage.Read.All" + }, + { + "description": "Allows the app to update Microsoft Teams channel messages by patching a set of Data Loss Prevention (DLP) policy violation properties to handle the output of DLP processing.", + "displayName": "Flag channel messages for violating policy", + "id": "4d02b0cc-d90b-441f-8d82-4fb55c34d6bb", + "origin": "Application (Microsoft Graph)", + "value": "ChannelMessage.UpdatePolicyViolation.All" + }, + { + "description": "Read all channel names, channel descriptions, and channel settings, without a signed-in user.", + "displayName": "Read the names, descriptions, and settings of all channels", + "id": "c97b873f-f59f-49aa-8a0e-52b32d762124", + "origin": "Application (Microsoft Graph)", + "value": "ChannelSettings.Read.All" + }, + { + "description": "Read and write the names, descriptions, and settings of all channels, without a signed-in user.", + "displayName": "Read and write the names, descriptions, and settings of all channels", + "id": "243cded2-bd16-4fd6-a953-ff8177894c3d", + "origin": "Application (Microsoft Graph)", + "value": "ChannelSettings.ReadWrite.All" + }, + { + "description": "Allows the app to create chats without a signed-in user. ", + "displayName": "Create chats", + "id": "d9c48af6-9ad9-47ad-82c3-63757137b9af", + "origin": "Application (Microsoft Graph)", + "value": "Chat.Create" + }, + { + "description": "Allows the app to place outbound calls to multiple users and add participants to meetings in your organization, without a signed-in user.", + "displayName": "Initiate outgoing group calls from the app", + "id": "4c277553-8a09-487b-8023-29ee378d8324", + "origin": "Application (Microsoft Graph)", + "value": "Calls.InitiateGroupCall.All" + }, + { + "description": "Allows the app to place outbound calls to a single user and transfer calls to users in your organization’s directory, without a signed-in user.", + "displayName": "Initiate outgoing 1 to 1 calls from the app", + "id": "284383ee-7f6e-4e40-a2a8-e85dcb029101", + "origin": "Application (Microsoft Graph)", + "value": "Calls.Initiate.All" + }, + { + "description": "Allows the app to get direct access to media streams in a call, without a signed-in user.", + "displayName": "Access media streams in a call as an app", + "id": "a7a681dc-756e-4909-b988-f160edc6655f", + "origin": "Application (Microsoft Graph)", + "value": "Calls.AccessMedia.All" + }, + { + "description": "Allows the app to read call records for all calls and online meetings without a signed-in user.", + "displayName": "Read all call records", + "id": "45bbb07e-7321-4fd7-a8f6-3ff27e6a81c8", + "origin": "Application (Microsoft Graph)", + "value": "CallRecords.Read.All" + }, + { + "description": "Allows an app to read all browser site lists configured for your organization, without a signed-in user.", + "displayName": "Read all browser site lists for your organization", + "id": "c5ee1f21-fc7f-4937-9af0-c91648ff9597", + "origin": "Application (Microsoft Graph)", + "value": "BrowserSiteLists.Read.All" + }, + { + "description": "Allows an app to read and write all browser site lists configured for your organization, without a signed-in user.", + "displayName": "Read and write all browser site lists for your organization", + "id": "8349ca94-3061-44d5-9bfb-33774ea5e4f9", + "origin": "Application (Microsoft Graph)", + "value": "BrowserSiteLists.ReadWrite.All" + }, + { + "description": "Allows the app to read the configurations of business scenarios it owns, without a signed-in user.", + "displayName": "Read all business scenario configurations this app creates or owns", + "id": "acc0fc4d-2cd6-4194-8700-1768d8423d86", + "origin": "Application (Microsoft Graph)", + "value": "BusinessScenarioConfig.Read.OwnedBy" + }, + { + "description": "Allows the app to create new business scenarios and fully manage the configurations of scenarios it owns, without a signed-in user.", + "displayName": "Read and write all business scenario configurations this app creates or owns", + "id": "bbea195a-4c47-4a4f-bff2-cba399e11698", + "origin": "Application (Microsoft Graph)", + "value": "BusinessScenarioConfig.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read the data associated with the business scenarios it owns, without a signed-in user.", + "displayName": "Read data for all business scenarios this app creates or owns", + "id": "6c0257fd-cffe-415b-8239-2d0d70fdaa9c", + "origin": "Application (Microsoft Graph)", + "value": "BusinessScenarioData.Read.OwnedBy" + }, + { + "description": "Allows the app to fully manage the data associated with the business scenarios it owns, without a signed-in user.", + "displayName": "Read and write data for all business scenarios this app creates or owns", + "id": "f2d21f22-5d80-499e-91cc-0a8a4ce16f54", + "origin": "Application (Microsoft Graph)", + "value": "BusinessScenarioData.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read work hours and locations settings, recurrences, and occurrences for all users in the organization, without a signed-in user.", + "displayName": "Read all users' work hours and locations", + "id": "470229df-a15a-4b08-9d95-8c534862b362", + "origin": "Application (Microsoft Graph)", + "value": "Calendars.Read.All" + }, + { + "description": "Allows the app to read all 1-to-1 or group chat messages in Microsoft Teams.", + "displayName": "Read all chat messages", + "id": "6b7d71aa-70aa-4810-a8d9-5d9fb2830017", + "origin": "Application (Microsoft Graph)", + "value": "Chat.Read.All" + }, + { + "description": "Allows the app to read events of all calendars, except for properties such as body, attachments, and extensions, without a signed-in user.", + "displayName": "Read basic details of calendars in all mailboxes ", + "id": "8ba4a692-bc31-4128-9094-475872af8a53", + "origin": "Application (Microsoft Graph)", + "value": "Calendars.ReadBasic.All" + }, + { + "description": "Allows the app to read, create, update, and delete work hours and locations settings, recurrences, and occurrences for all users in the organization, without a signed-in user.", + "displayName": "Read and write all users' work hours and locations", + "id": "d91697b0-a708-4c11-a712-8fb2dc081aa2", + "origin": "Application (Microsoft Graph)", + "value": "Calendars.ReadWrite.All" + }, + { + "description": "Allows the app to read all AI Insights for all calls, without a signed-in user.", + "displayName": "Read all AI Insights for calls.", + "id": "792b782b-7822-4b92-8103-77e44f2f706c", + "origin": "Application (Microsoft Graph)", + "value": "CallAiInsights.Read.All" + }, + { + "description": "Allows the app to read delegation settings of you", + "displayName": "Read delegation settings", + "id": "5aa33e77-b893-495e-bdc5-4bf6f27d42a0", + "origin": "Application (Microsoft Graph)", + "value": "CallDelegation.Read.All" + }, + { + "description": "Allows the app to read and write delegation settings of you", + "displayName": "Read and write delegation settings", + "id": "8d06abce-e69b-4122-ba60-4f901bb1db2f", + "origin": "Application (Microsoft Graph)", + "value": "CallDelegation.ReadWrite.All" + }, + { + "description": "Allows the app to read call event information for all users in your organization, without a signed-in user.", + "displayName": "Read all call events", + "id": "1abb026f-7572-49f6-9ddd-ad61cbba181e", + "origin": "Application (Microsoft Graph)", + "value": "CallEvents.Read.All" + }, + { + "description": "Allows the app to read emergency call event information for all users in your organization without a signed-in user.", + "displayName": "Read all emergency call events", + "id": "f0a35f91-2aa6-4a99-9d5a-5b6bcb66204e", + "origin": "Application (Microsoft Graph)", + "value": "CallEvents-Emergency.Read.All" + }, + { + "description": "Allows the app to read call recordings for all calls without a signed-in user.", + "displayName": "Read all call recordings", + "id": "ce8fb1f1-5e1f-44a0-b102-4ec28454d0dc", + "origin": "Application (Microsoft Graph)", + "value": "CallRecordings.Read.All" + }, + { + "description": "Allows the app to read all PSTN and direct routing call log data without a signed-in user.", + "displayName": "Read PSTN and direct routing call log data", + "id": "a2611786-80b3-417e-adaa-707d4261a5f0", + "origin": "Application (Microsoft Graph)", + "value": "CallRecord-PstnCalls.Read.All" + }, + { + "description": "Allows the app to read internal federation configuration for a domain.", + "displayName": "Read internal federation configuration for a domain.", + "id": "c0e5a7b0-e8b7-40a7-b8e0-8249e6ea81d5", + "origin": "Application (Microsoft Graph)", + "value": "Domain-InternalFederation.Read.All" + }, + { + "description": "Allows calling debugging APIs", + "displayName": "UserScope-Dev.Debug.All", + "id": "d3aaaaff-f3e8-4b2f-8285-12478a43eb7d", + "origin": "Application (DirectoryLookupService)", + "value": "UserScope-Dev.Debug.All" + }, + { + "description": "Allows calling debugging APIs", + "displayName": "UserScope.Debug.All", + "id": "9c87ec21-0463-42cf-a35b-1b1e81ac135f", + "origin": "Application (DirectoryLookupService)", + "value": "UserScope.Debug.All" + }, + { + "description": "Grants the ability to read, write, and manage symbols.", + "displayName": "Symbols (read, write and manage)", + "id": "6314624e-fd22-4945-a279-2bab145fe26e", + "origin": "Delegated (Azure DevOps)", + "value": "vso.symbols_manage" + }, + { + "description": "Grants the ability to read and write symbols.", + "displayName": "Symbols (read and write)", + "id": "61b345ff-217b-4c81-9648-88991cf1c1ee", + "origin": "Delegated (Azure DevOps)", + "value": "vso.symbols_write" + }, + { + "description": "Grants the ability to read, create and manage taskgroups.", + "displayName": "Task Groups (read, create and manage)", + "id": "7a350bc8-d2d9-4842-9c59-a815a1923097", + "origin": "Delegated (Azure DevOps)", + "value": "vso.taskgroups_manage" + }, + { + "description": "Grants the ability to read task groups.", + "displayName": "Task Groups (read)", + "id": "8f5046df-6ee0-497b-b5b2-5e125f882eae", + "origin": "Delegated (Azure DevOps)", + "value": "vso.taskgroups_read" + }, + { + "description": "Grants the ability to read and create task groups.", + "displayName": "Task Groups (read, create)", + "id": "8be3739c-dabb-4cf4-a05d-207a5220e4f0", + "origin": "Delegated (Azure DevOps)", + "value": "vso.taskgroups_write" + }, + { + "description": "Grants the ability to read test plans, cases, results and other test management related artifacts.", + "displayName": "Test management (read)", + "id": "c0efe20b-0db1-4aec-9cb5-cdc097b2e773", + "origin": "Delegated (Azure DevOps)", + "value": "vso.test" + }, + { + "description": "Grants the ability to read, create, and update test plans, cases, results and other test management related artifacts.", + "displayName": "Test management (read and write)", + "id": "0a731f7b-93ec-4267-aa35-47b4b9fcdf08", + "origin": "Delegated (Azure DevOps)", + "value": "vso.test_write" + }, + { + "description": "Grants the ability to manage (view and revoke) existing tokens to organization administrators", + "displayName": "Token Administration", + "id": "859fb1f9-e5ab-4e67-88f8-a971d3e4707a", + "origin": "Delegated (Azure DevOps)", + "value": "vso.tokenadministration" + }, + { + "description": "Grants the ability to manage delegated authorization tokens to users", + "displayName": "Delegated Authorization Tokens", + "id": "ea83b09f-09d2-4ee5-bb93-d346c57debdb", + "origin": "Delegated (Azure DevOps)", + "value": "vso.tokens" + }, + { + "description": "Grants the ability to read, create and manage variable groups.", + "displayName": "Variable Groups (read, create and manage)", + "id": "e20dcb7e-deff-4025-805a-853e74ff44c1", + "origin": "Delegated (Azure DevOps)", + "value": "vso.variablegroups_manage" + }, + { + "description": "Grants the ability to read variable groups.", + "displayName": "Variable Groups (read)", + "id": "469808c3-0aad-4ce3-854e-0080dfc973d9", + "origin": "Delegated (Azure DevOps)", + "value": "vso.variablegroups_read" + }, + { + "description": "Grants the ability to read and create variable groups.", + "displayName": "Variable Groups (read, create)", + "id": "c4679fff-04f1-4e29-88b4-4ae78bf4ee27", + "origin": "Delegated (Azure DevOps)", + "value": "vso.variablegroups_write" + }, + { + "description": "\tGrants the ability to read wikis, wiki pages and wiki attachments. Also grants the ability to search wiki pages.", + "displayName": "Wiki (read)", + "id": "7ad94a7f-9169-422b-a66b-1c74dea4c016", + "origin": "Delegated (Azure DevOps)", + "value": "vso.wiki" + }, + { + "description": "Grants the ability to read, create and updates wikis, wiki pages and wiki attachments.", + "displayName": "Wiki (read and write)", + "id": "b5ffdb18-5c2f-420d-a35a-8ffe20092235", + "origin": "Delegated (Azure DevOps)", + "value": "vso.wiki_write" + }, + { + "description": "Grants the ability to read work items, queries, boards, area and iterations paths, and other work item tracking related metadata. Also grants the ability to execute queries, search work items and to receive notifications about work item events via service hooks.", + "displayName": "Work items (read)", + "id": "3214d9aa-5551-4ef3-a866-22914177e2a4", + "origin": "Delegated (Azure DevOps)", + "value": "vso.work" + }, + { + "description": "Grants full access to work items, queries, backlogs, plans, and work item tracking metadata. Also provides the ability to receive notifications about work item events via service hooks.", + "displayName": "Work items (full)", + "id": "3e49c96c-b24e-493b-a225-497a7b3805ab", + "origin": "Delegated (Azure DevOps)", + "value": "vso.work_full" + }, + { + "description": "Grants the ability to read, create, and update work items and queries, update board metadata, read area and iterations paths other work item tracking related metadata, execute queries, and to receive notifications about work item events via service hooks.", + "displayName": "Work items (read and write)", + "id": "dfc8977a-1f87-4e99-95cb-4bd25e4f546d", + "origin": "Delegated (Azure DevOps)", + "value": "vso.work_write" + }, + { + "description": "Grants the ability to read symbols.", + "displayName": "Symbols (read)", + "id": "c424c3d9-15df-4837-9fa3-b9ed83b3687a", + "origin": "Delegated (Azure DevOps)", + "value": "vso.symbols" + }, + { + "description": "Read/Write access for all objects in the space topology", + "displayName": "Read/Write Access", + "id": "4589bd03-58cb-4e6c-b17f-b580e39652f8", + "origin": "Delegated (Azure Digital Twins)", + "value": "Read.Write" + }, + { + "description": "Grants the ability to read and query service endpoints.", + "displayName": "Service Endpoints (read and query)", + "id": "81928d24-d278-4dc9-baf9-6756e5ea62e2", + "origin": "Delegated (Azure DevOps)", + "value": "vso.serviceendpoint_query" + }, + { + "description": "Grants the ability to read service endpoints.", + "displayName": "Service Endpoints (read)", + "id": "503568bd-aea0-4478-a536-a8325f5f0830", + "origin": "Delegated (Azure DevOps)", + "value": "vso.serviceendpoint" + }, + { + "description": "Grants the ability to create and read feeds and packages.", + "displayName": "Packaging (read and write)", + "id": "fb6a8425-8933-4b7f-9c4a-154568e06e5c", + "origin": "Delegated (Azure DevOps)", + "value": "vso.packaging_write" + }, + { + "description": "Grants the ability to read Pats for a user", + "displayName": "Pats (read)", + "id": "de2740de-3092-4b70-afcd-df4a8a4ecacf", + "origin": "Delegated (Azure DevOps)", + "value": "vso.pats" + }, + { + "description": "Grants the ability to read and manage Pats for a user", + "displayName": "Pats (read and manage)", + "id": "15b69eb5-89f0-4f4d-8d0d-219397dab9c4", + "origin": "Delegated (Azure DevOps)", + "value": "vso.pats_manage" + }, + { + "description": "Grants the ability to manage a protected resource or a pipeline's request to use a protected resource, agent pool, environment, queue, repository, secure files, service connection, and variable group", + "displayName": "Pipeline Resources (use and manage)", + "id": "8deb8858-ff9b-4c4e-b702-5a6abbb28db0", + "origin": "Delegated (Azure DevOps)", + "value": "vso.pipelineresources_manage" + }, + { + "description": "Grants the ability to approve a pipeline's request to use a protected resource, agent pool, environment, queue, repository, secure files, service connection, and variable group", + "displayName": "Pipeline Resources (use)", + "id": "7c6f675c-fff5-4f8a-adf1-1a3d6f3fafdc", + "origin": "Delegated (Azure DevOps)", + "value": "vso.pipelineresources_use" + }, + { + "description": "Grants the ability to read your profile, accounts, collections, projects, teams, and other top-level organizational artifacts.", + "displayName": "User profile (read)", + "id": "4ee63f9b-9e65-476c-a487-9fea1e00c7ef", + "origin": "Delegated (Azure DevOps)", + "value": "vso.profile" + }, + { + "description": "Grants the ability to write to your profile.", + "displayName": "User profile (write)", + "id": "cf053792-b7ad-46ba-aecb-a8e9b706587e", + "origin": "Delegated (Azure DevOps)", + "value": "vso.profile_write" + }, + { + "description": "Grants the ability to read projects and teams.", + "displayName": "Project and team (read)", + "id": "7b1a2725-1134-40f5-a891-d20bbb122919", + "origin": "Delegated (Azure DevOps)", + "value": "vso.project" + }, + { + "description": "Grants the ability to create, read, update, and delete projects and teams.", + "displayName": "Project and team (read, write and manage)", + "id": "0bf9fd64-9272-43aa-8459-00e29f78e146", + "origin": "Delegated (Azure DevOps)", + "value": "vso.project_manage" + }, + { + "description": "Grants the ability to read and update projects and teams.", + "displayName": "Project and team (read and write)", + "id": "e8a8f033-da2f-4059-ba3e-63a8f69b8842", + "origin": "Delegated (Azure DevOps)", + "value": "vso.project_write" + }, + { + "description": "Grants the ability to read release artifacts, including releases, release definitions and release environment.", + "displayName": "Release (read)", + "id": "a6abae6c-fe64-4795-aea0-ccf174ec25cf", + "origin": "Delegated (Azure DevOps)", + "value": "vso.release" + }, + { + "description": "Grants the ability to read and update release artifacts, including releases, release definitions and release environment, and the ability to queue a new release.", + "displayName": "Release (read, write and execute)", + "id": "1decc0a5-a110-4bb7-86e5-0b0ecf40c010", + "origin": "Delegated (Azure DevOps)", + "value": "vso.release_execute" + }, + { + "description": "Grants the ability to read, update, and delete release artifacts, including releases, release definitions and release environment, and the ability to queue and approve a new release.", + "displayName": "Release (read, write, execute and manage)", + "id": "36d3e2c4-2a6b-4dd0-aa72-058aaedf09d4", + "origin": "Delegated (Azure DevOps)", + "value": "vso.release_manage" + }, + { + "description": "Grants the ability to read, create, and manage secure files.", + "displayName": "Secure Files (read, create, and manage)", + "id": "2b7fbe3e-6b64-4f44-a125-fb407930daaf", + "origin": "Delegated (Azure DevOps)", + "value": "vso.securefiles_manage" + }, + { + "description": "Grants the ability to read secure files.", + "displayName": "Secure Files (read)", + "id": "a07b91f9-72ea-4d16-a874-018f0350e3c1", + "origin": "Delegated (Azure DevOps)", + "value": "vso.securefiles_read" + }, + { + "description": "Grants the ability to read and create secure files.", + "displayName": "Secure Files (read, create)", + "id": "6c67f103-736c-44a0-9c09-6e72547c7d99", + "origin": "Delegated (Azure DevOps)", + "value": "vso.securefiles_write" + }, + { + "description": "Grants the ability to read, write, and manage security permissions.", + "displayName": "Security (manage)", + "id": "59ead6af-1488-485a-bd24-059f30ad33f2", + "origin": "Delegated (Azure DevOps)", + "value": "vso.security_manage" + }, + { + "description": "Grants the ability to read, query, and manage service endpoints.", + "displayName": "Service Endpoints (read, query and manage)", + "id": "6f9f984c-a956-40b7-a6ac-4f7e3f091f96", + "origin": "Delegated (Azure DevOps)", + "value": "vso.serviceendpoint_manage" + }, + { + "description": "Read, write access for all objects in the space topology", + "displayName": "Read, write Access", + "id": "6f0a461a-c02f-4f98-994a-b116efecc7b2", + "origin": "Delegated (Azure Digital Twins Authorization PDP)", + "value": "Read.Write" + }, + { + "description": "Allows the user to access consumption APIs on Microsoft Enterprise Graph", + "displayName": "Read Microsoft Enterprise Graph data as an organization user (preview)", + "id": "df43b147-a9af-4e9b-92f9-c366aa5c2c5c", + "origin": "Delegated (Azure Enterprise Knowledge Graph RP)", + "value": "Knowledge.Read" + }, + { + "description": "Role representing Azure ExP backend services.", + "displayName": "Azure ExP Backend Service", + "id": "ddae8266-1a14-470c-92bd-5901e981053f", + "origin": "Application (Azure ExP)", + "value": "az-exp-backend" + }, + { + "description": "Allows user to read DocumentReference resources in a patient's compartment.", + "displayName": "patient.DocumentReference.read", + "id": "e2a5290a-59c6-4847-af7f-c5b16c692f24", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.DocumentReference.read" + }, + { + "description": "Allows user to read Encounter resources in a patient's compartment.", + "displayName": "patient.Encounter.read", + "id": "9e7cdd6e-af8a-4e6d-9170-4274b35864bc", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.Encounter.read" + }, + { + "description": "Allows user to read Goal resources in a patient's compartment.", + "displayName": "patient.Goal.read", + "id": "e6e32ed0-c9a2-4f1b-adb5-e3d59e47bb54", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.Goal.read" + }, + { + "description": "Allows user to read Immunization resources in a patient's compartment.", + "displayName": "patient.Immunization.read", + "id": "f6c2728b-b49d-4d10-bb69-7798f1603807", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.Immunization.read" + }, + { + "description": "Allows a user to read Location resources in a patient's compartment.", + "displayName": "patient.Location.read", + "id": "6fbb6a2c-cd2f-486c-a421-b188f2184df8", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.Location.read" + }, + { + "description": "Allows user to read Medication resources in a patient's compartment.", + "displayName": "patient.Medication.read", + "id": "058fa58e-ac09-4308-970e-2f2da3bf49b4", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.Medication.read" + }, + { + "description": "Allows user to read MedicationRequest resources in a patient's compartment.", + "displayName": "patient.MedicationRequest.read", + "id": "16352d13-6c69-4eee-adbb-f7420b3f252b", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.MedicationRequest.read" + }, + { + "description": "Allows user to read Observation resources in a patient's compartment.", + "displayName": "patient.Observation.read", + "id": "890da85b-b5ad-4981-8966-4b80fd75a5b8", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.Observation.read" + }, + { + "description": "Allows user to read Organization resources in a patient's compartment.", + "displayName": "patient.Organization.read", + "id": "81882045-ad54-4a5f-926c-a2a09d7dd2b5", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.Organization.read" + }, + { + "description": "Allows user to read Patient resources in a patient's compartment.", + "displayName": "patient.Patient.read", + "id": "d23f0b68-a2f5-4647-987b-b58fdd86b49d", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.Patient.read" + }, + { + "description": "Allows user to read Practitioner resources in a patient's compartment.", + "displayName": "patient.Practitioner.read", + "id": "ad27d725-86ff-4bc9-86fb-afdb2f007089", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.Practitioner.read" + }, + { + "description": "Allows user to read PractitionerRole resources in a patient's compartment.", + "displayName": "patient.PractitionerRole.read", + "id": "1d6a9f65-62f4-42b0-93d7-fc3437112f46", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.PractitionerRole.read" + }, + { + "description": "Allows user to read Procedure resources in a patient's compartment.", + "displayName": "patient.Procedure.read", + "id": "be1c7593-9057-4947-a456-424dde696627", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.Procedure.read" + }, + { + "description": "Allows user to read Provenance resources in a patient's compartment.", + "displayName": "patient.Provenance.read", + "id": "d56c68f3-ec5f-4e12-82cc-afa8921337f0", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.Provenance.read" + }, + { + "description": "Allows a user to read all resources in their compartment.", + "displayName": "user.all.read", + "id": "5a03b38d-4081-4265-9558-aab5f2a18b8b", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.all.read" + }, + { + "description": "Allows user to read AllergyIntolerance resources in their own compartment.", + "displayName": "user.AllergyIntolerance.read", + "id": "263687ba-ab05-41b1-98ad-f057c7365c91", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.AllergyIntolerance.read" + }, + { + "description": "Allows user to read CarePlan resources in their own compartment.", + "displayName": "user.CarePlan.read", + "id": "c2c62692-9cd2-4612-9f15-cf5641284e41", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.CarePlan.read" + }, + { + "description": "Allows user to read DiagnosticReport resources in a patient's compartment.", + "displayName": "patient.DiagnosticReport.read", + "id": "ef9475b2-f7da-4a86-b385-9fffe030c310", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.DiagnosticReport.read" + }, + { + "description": "Allows user to read Device resources in a patient's compartment.", + "displayName": "patient.Device.read", + "id": "f7b318b5-9bf5-46d0-8701-845c568925d9", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.Device.read" + }, + { + "description": "Allows user to read Condition resources in a patient's compartment.", + "displayName": "patient.Condition.read", + "id": "60fd617d-0d96-4c44-9cf3-ee91c0c45161", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.Condition.read" + }, + { + "description": "Allows user to read CareTeam resources in a patient's compartment.", + "displayName": "patient.CareTeam.read", + "id": "4860ad86-f40e-4e2b-8661-ba03ee154b19", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.CareTeam.read" + }, + { + "description": "Role representing Azure ExP frontend services.", + "displayName": "Azure ExP Frontend", + "id": "7f9e080a-e4af-4ac9-bc98-8b8cf39c0e40", + "origin": "Application (Azure ExP)", + "value": "az-exp-frontend" + }, + { + "description": "Role representing Azure ExP Reader Security Group.", + "displayName": "Azure ExP Reader", + "id": "6e32d6dd-89e3-4a14-b3c5-578b15e08d70", + "origin": "Application (Azure ExP)", + "value": "Experimentation.Reader" + }, + { + "description": "Allow the application to access Azure Experimentation Platform (ExP) dataplane APIs on behalf of the signed in user.", + "displayName": "Access Azure ExP", + "id": "a8a27510-3bf9-4a9d-a5be-5340c8a026e5", + "origin": "Delegated (Azure ExP)", + "value": "user_impersonation" + }, + { + "description": "c", + "displayName": "Access Kafka rest proxy apis in HDInsight", + "id": "bcc42819-54c2-4d19-a7c5-de8402bf34e3", + "origin": "Application (Azure HDInsight Cluster API)", + "value": "Kafka.ReadWrite" + }, + { + "description": "Allows callers to access all apis", + "displayName": "Cluster API Access", + "id": "8f89faa0-ffef-4007-974d-4989b39ad77d", + "origin": "Delegated (Azure HDInsight Cluster API)", + "value": "Cluster.ReadWrite" + }, + { + "description": "Grants permission for refresh tokens to be used to obtain a new access token even after the user is no longer online.", + "displayName": "offline_access", + "id": "7f08bce5-b21b-4518-b783-c69c9c0cd658", + "origin": "Application (Azure Healthcare APIs)", + "value": "offline_access" + }, + { + "description": "Read and write all resources in the system.", + "displayName": "system.all.all", + "id": "bea2566c-7172-42d0-a06a-0e2e2b58f084", + "origin": "Application (Azure Healthcare APIs)", + "value": "system.all.all" + }, + { + "description": "Grants the ability to create, read, update, and delete feeds and packages.", + "displayName": "Packaging (read, write, and manage)", + "id": "1c2a30a3-4b4c-42b1-bb10-6f24faf344d7", + "origin": "Delegated (Azure DevOps)", + "value": "vso.packaging_manage" + }, + { + "description": "Allows a user to read all resources in the system.", + "displayName": "system.all.read", + "id": "a44c4c64-cdb5-48fc-adbd-070df4852b2c", + "origin": "Application (Azure Healthcare APIs)", + "value": "system.all.read" + }, + { + "description": "Grants permission to obtain launch context.", + "displayName": "launch", + "id": "fa5f9b76-5f20-4466-8b3d-6718de9744e2", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "launch" + }, + { + "description": "Asks for a patient to be selected at launch time.", + "displayName": "launch.patient", + "id": "f6c8eb20-e799-4de7-a7ce-74ca0c7270e1", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "launch.patient" + }, + { + "description": "Grants permission for a refresh token to be used to obtain a new access token as long as the user is still online.", + "displayName": "online_access", + "id": "8f4fe9ac-b7f2-43ca-a0ef-070f4a8ae5dc", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "online_access" + }, + { + "description": "Grants permission to retrieve information about the current logged-in user.", + "displayName": "openid", + "id": "0ea38e69-761b-46c7-ac06-9cd17d518949", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "openid" + }, + { + "description": "Allows user to read all resources in a patient's compartment.", + "displayName": "patient.all.read", + "id": "c71e9482-f052-461b-80e1-7cfeba7b2b12", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.all.read" + }, + { + "description": "Allows user to read AllergyIntolerance resources in a patient's compartment.", + "displayName": "patient.AllergyIntolerance.read", + "id": "fa23e5cb-b06f-4d07-bcf8-f5ce114dd847", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.AllergyIntolerance.read" + }, + { + "description": "Allows user to read CarePlan resources in a patient's compartment.", + "displayName": "patient.CarePlan.read", + "id": "4fcc09b8-fd6b-430f-9b2b-7bbd2c2b7e8f", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.CarePlan.read" + }, + { + "description": "Grants permission to read information about the current logged-in user.", + "displayName": "fhirUser", + "id": "a86144c7-3e19-4b56-9675-15803eb1e617", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "fhirUser" + }, + { + "description": "Allows user to read CareTeam resources in their own compartment.", + "displayName": "user.CareTeam.read", + "id": "3cb5f829-1e8d-4224-9e87-678b02c8f9b1", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.CareTeam.read" + }, + { + "description": "Grants the ability to read feeds and packages.", + "displayName": "Packaging (read)", + "id": "fcc79b02-ad6b-4ac7-af05-70cb9e349708", + "origin": "Delegated (Azure DevOps)", + "value": "vso.packaging" + }, + { + "description": "Provides read, write, and management access to subscriptions and read access to event metadata, including filterable field values.", + "displayName": "Notifications (manage)", + "id": "90f74b44-f4ec-4f41-9003-cb9cb64cdd32", + "origin": "Delegated (Azure DevOps)", + "value": "vso.notification_manage" + }, + { + "description": "The app can view and write to all models for the signed in user and models that the user has access to.", + "displayName": "Read and Write all Models", + "id": "59ef67ea-d35f-4c6d-b1ce-95468f134ccb", + "origin": "Delegated (Azure Analysis Services)", + "value": "Model.ReadWrite.All" + }, + { + "description": "Allows access to the Azure API Center Data API service on behalf of the signed-in user.", + "displayName": "Access Azure API Center Data API", + "id": "8351d75c-0972-4fe9-b20b-d91b74614489", + "origin": "Delegated (Azure API Center)", + "value": "Data.Read.All" + }, + { + "description": "Allows access to the Azure API Center Data API service on behalf of the signed-in user", + "displayName": "Access Azure API Center Data API", + "id": "44327351-3395-414e-882e-7aa4a9c3b25d", + "origin": "Delegated (Azure API Center)", + "value": "user_impersonation" + }, + { + "description": "Allows application to read and write DICOM resources.", + "displayName": "Read and write DICOM", + "id": "e69ab058-b8ae-4c0f-b687-5d97888ddccb", + "origin": "Delegated (Azure API for DICOM)", + "value": "Dicom.ReadWrite" + }, + { + "description": "Have full access to the Azure API Connection service.", + "displayName": "Access Azure API Connections runtime service API", + "id": "6c3012bf-22c1-4bb5-959b-dff738314144", + "origin": "Delegated (Azure API Hub)", + "value": "Runtime.All" + }, + { + "description": "Access Azure Cognitive Search", + "displayName": "user_impersonation ", + "id": "a4165a31-5d9e-4120-bd1e-9d88c66fd3b8", + "origin": "Delegated (Azure Cognitive Search)", + "value": "user_impersonation" + }, + { + "description": "c", + "displayName": "CST SP", + "id": "801546d2-55cc-4ff4-b66d-134b1208deb5", + "origin": "Application (Azure Commercial Services Tool - CST)", + "value": "samples.read" + }, + { + "description": "Azure Container Registry Resource Provider", + "displayName": "Azure Container Registry RP", + "id": "a25ca244-bc95-4be7-bd58-ca9325bd24b2", + "origin": "Application (Azure Container Registry)", + "value": "AzureContainerRegistryRP" + }, + { + "description": "Allows the application to access Azure Container Registry acting as users in the organization.", + "displayName": "Access Azure Container Registry as organization users", + "id": "cdcfcdaf-ae2f-408c-9585-bb5b86000ba4", + "origin": "Delegated (Azure Container Registry Application)", + "value": "user_impersonation" + }, + { + "description": "Allows the client application to create and execute sessions that user has access to", + "displayName": "Sessions.ReadWrite.All", + "id": "2843164f-ca31-473a-9198-ceaeb95e59b1", + "origin": "Delegated (Azure ContainerApps Sessions)", + "value": "Sessions.ReadWrite.All" + }, + { + "description": "Allow the application to access Azure Cosmos DB on behalf of the signed-in user.", + "displayName": "Access Azure Cosmos DB", + "id": "8741c20d-e8c0-41ff-8adf-b7b9ba168197", + "origin": "Delegated (Azure Cosmos DB)", + "value": "user_impersonation" + }, + { + "description": "Access CPG Prod services from the application", + "displayName": "Azure CPG Prod", + "id": "45b2dd25-66bb-4e03-8945-c0781f29fc85", + "origin": "Application (Azure CosmosDB for PostgreSQL AAD Authentication)", + "value": "app_impersonation" + }, + { + "description": "Access CPG Prod Service as a user", + "displayName": "Access CPG Prod Services", + "id": "546e6d41-31bd-4cc1-976a-2be4eb91f35e", + "origin": "Delegated (Azure CosmosDB for PostgreSQL AAD Authentication)", + "value": "user_impersonation" + }, + { + "description": "Access CPG Prod services from the application", + "displayName": "Azure CPG Prod", + "id": "bb7fb9ee-c8d2-4c3b-853e-af20f589cb42", + "origin": "Application (Azure CosmosDB for PostgreSQL Microsoft EntraId)", + "value": "app_impersonation" + }, + { + "description": "Access CosmosDB for PostgreSQL as a user", + "displayName": "Access CosmosDB for PostgreSQL", + "id": "51a464c6-5185-43ba-b6fc-cb173be5e291", + "origin": "Delegated (Azure CosmosDB for PostgreSQL Microsoft EntraId)", + "value": "user_impersonation" + }, + { + "description": "Allow the application full access to the Azure Data Lake service on behalf of the signed-in user", + "displayName": "Have full access to the Azure Data Lake service", + "id": "9f15d22d-3cdf-430f-ba48-f75401c0408e", + "origin": "Delegated (Azure Data Lake)", + "value": "user_impersonation" + }, + { + "description": "Allows the app to send which accounts are managed by the PAM solution for all AD and Entra identities for MDI customers.", + "displayName": "Send which accounts are managed by the PAM solution", + "id": "9bba0ae2-fc9b-4c22-b607-b6afdf6601cb", + "origin": "Delegated (Azure Advanced Threat Protection)", + "value": "Identity.PrivilegeAccountTagging" + }, + { + "description": "Allows an application to call ADME apis without a signed in user.", + "displayName": "ADME Application API access", + "id": "c0795231-e282-4abc-8822-576cbaea5bfb", + "origin": "Application (Azure Data Manager for Energy)", + "value": "ADME.ApplicationAccess" + }, + { + "description": "Allows the app to get a list of actions required on AD and Entra identities and update on the status of said actions for MDI customers.", + "displayName": "get a list of actions and update on the status of said actions", + "id": "1f479d02-0183-4852-8264-464546fd8f52", + "origin": "Delegated (Azure Advanced Threat Protection)", + "value": "Identity.PrivilegeAccountActions" + }, + { + "description": "Allows the app to get a list of actions required on AD and Entra identities and update on the status of said actions for MDI customers.", + "displayName": "get a list of actions and update on the status of said actions", + "id": "c613cf81-75fb-4201-a32b-7a58d1fe4dff", + "origin": "Application (Azure Advanced Threat Protection)", + "value": "Identity.PrivilegeAccountActions" + }, + { + "description": "Access to IoT DPS", + "displayName": "Access to IoT DPS", + "id": "02ce5515-6df6-47e3-b3a5-96dd4fc74f64", + "origin": "Delegated (Access IoT Hub Device Provisioning Service)", + "value": "user_impersonation" + }, + { + "description": "Allows user to generate a sas token.", + "displayName": "Generate SAS Token.", + "id": "7a4930f3-f625-4ed4-a257-5cdb1401acb9", + "origin": "Delegated (AIO-Diagnostics-Admin-Service-App)", + "value": "Tokens.Get" + }, + { + "description": "Allows users to sign-in to the app, and allows the app to read the profile of signed-in users. It also allows the app to read basic company information of signed-in users.", + "displayName": "Sign in and read user profile", + "id": "111a3bb6-1bbf-4127-a604-3b1b58acc41b", + "origin": "Delegated (AIO-Diagnostics-Admin-Service-App)", + "value": "user_impersonation" + }, + { + "description": "this allows user to read app usage in the organization. Requires admin consent", + "displayName": "usage.read.all", + "id": "c9742cae-d7c1-4b54-a641-5f676846a768", + "origin": "Delegated (App Protection)", + "value": "usage.read.all" + }, + { + "description": "Allow this application to access Application Insights data", + "displayName": "Read Application Insights Data", + "id": "3c63f9fe-1706-42a7-9f53-25b47753d668", + "origin": "Application (Application Insights API)", + "value": "Data.Read" + }, + { + "description": "Allow this application to access Application Insights data on behalf of the user", + "displayName": "Read Application Insights Data as user", + "id": "c6d30a22-009b-43ce-a9e9-3ca625e7a3d4", + "origin": "Delegated (Application Insights API)", + "value": "Data.Read" + }, + { + "description": "Default permission to access Attestation service", + "displayName": "user_impersonation", + "id": "aabdcc35-2d84-4cae-b8f0-23d8272e3fec", + "origin": "Application (Attestation Service)", + "value": "user_impersonation" + }, + { + "description": "Allow the application to access Azure Autonomous Development Platform on behalf of the signed-in user.", + "displayName": "Access Azure Autonomous Development Platform", + "id": "bd7d1ce5-f0a9-4489-a4df-3e41e7b963e2", + "origin": "Delegated (Autonomous Development Platform)", + "value": "user_impersonation" + }, + { + "description": "Allows a service or application to register Global Secure Access Private Network Connectors.", + "displayName": "Register connectors", + "id": "46314cfe-5021-44c3-a00c-e5e4fdc9b5ac", + "origin": "Application (Azure AD Application Proxy)", + "value": "Connector.Register" + }, + { + "description": "Allows an application to read access recommendation insights", + "displayName": "Read access recommendation insights", + "id": "179ad82c-ddf7-4180-9ecc-af2608f2ae6d", + "origin": "Application (Azure AD Identity Governance Insights)", + "value": "Insights.Read.AccessRecommendation" + }, + { + "description": "Allows an application to read all insights", + "displayName": "Read all insights", + "id": "50974fa0-9c21-4479-a75c-a901ccdb4b5c", + "origin": "Application (Azure AD Identity Governance Insights)", + "value": "Insights.Read.All" + }, + { + "description": "Allows an application to read sign-in insights", + "displayName": "Read sign-in insights", + "id": "c05406e2-24d5-4c73-8c33-dde21e8501e6", + "origin": "Application (Azure AD Identity Governance Insights)", + "value": "Insights.Read.SignIn" + }, + { + "description": "Allows an application to read subscriptions", + "displayName": "Read subscriptions", + "id": "2e03c640-95b1-462d-b0cc-811335e6c60b", + "origin": "Application (Azure AD Identity Governance Insights)", + "value": "Subscriptions.Read" + }, + { + "description": "Allows an application to create other subscriptions and fully manage those subscriptions. It cannot update any subscriptions that it is not an owner of.", + "displayName": "Read and write subscriptions", + "id": "0be7af70-7a46-4866-8e53-d01ebd5c57a1", + "origin": "Application (Azure AD Identity Governance Insights)", + "value": "Subscriptions.ReadWrite" + }, + { + "description": "AD Notification Teams consent", + "displayName": "AD Notification Teams consent", + "id": "0c80a1ae-d4a4-4dfc-acde-ec00fbf86fe8", + "origin": "Delegated (Azure AD Notification)", + "value": "access-as-user" + }, + { + "description": "Allows a user to manage an application's notifications and templates..", + "displayName": "Application.ReadWrite", + "id": "0a8cab7d-5369-41c7-ae0f-dc63a8f0465a", + "origin": "Delegated (Azure AD Notification)", + "value": "Application.ReadWrite" + }, + { + "description": "Allows the app to send which accounts are managed by the PAM solution for all AD and Entra identities for MDI customers.", + "displayName": "Send which accounts are managed by the PAM solution", + "id": "850e8a94-5d16-40ff-9167-cfda8c7f9ea8", + "origin": "Application (Azure Advanced Threat Protection)", + "value": "Identity.PrivilegeAccountTagging" + }, + { + "description": "Allow the app to access resources on behalf of the signed-in user.", + "displayName": "Access ADME", + "id": "b51d4d2d-b434-4627-8f1d-6684a79793e7", + "origin": "Delegated (Azure Data Manager for Energy)", + "value": "user_impersonation" + }, + { + "description": "Allow the application to access Azure Device Update on behalf of the signed-in user.", + "displayName": "Access Azure Device Update", + "id": "884024e2-2000-4ca9-aaad-4436358e330c", + "origin": "Delegated (Azure Device Update)", + "value": "user_impersonation" + }, + { + "description": "Grants the ability to read your load test runs, test results, and APM artifacts.", + "displayName": "Load test (read)", + "id": "e000c422-1bec-45ec-9d30-083f21df9d04", + "origin": "Application (Azure DevOps)", + "value": "vso.loadtest" + }, + { + "description": "Grants the ability to read installed extensions.", + "displayName": "Extensions (read)", + "id": "8fd343dd-9d94-4128-b3a3-f0ba1b869463", + "origin": "Delegated (Azure DevOps)", + "value": "vso.extension" + }, + { + "description": "Grants the ability to read data (settings and documents) stored by installed extensions.", + "displayName": "Extension data (read)", + "id": "9a68ae69-5073-4b4d-bb8a-d9f5acc6f008", + "origin": "Delegated (Azure DevOps)", + "value": "vso.extension.data" + }, + { + "description": "Grants the ability to read and write data (settings and documents) stored by installed extensions.", + "displayName": "Extension data (read and write)", + "id": "c144cb3f-c759-4b9f-991d-37b7b8877072", + "origin": "Delegated (Azure DevOps)", + "value": "vso.extension.data_write" + }, + { + "description": "Grants the ability to install, uninstall, and perform other administrative actions on installed extensions.", + "displayName": "Extensions (read and manage)", + "id": "657d7b2a-c30e-48d1-8041-f563ec1c94fa", + "origin": "Delegated (Azure DevOps)", + "value": "vso.extension_manage" + }, + { + "description": "Grants read access to public and private items and publishers.", + "displayName": "Marketplace", + "id": "c2353c51-3f94-413b-b7b1-083b387258c0", + "origin": "Delegated (Azure DevOps)", + "value": "vso.gallery" + }, + { + "description": "Grants read access and the ability to acquire items.", + "displayName": "Marketplace (acquire)", + "id": "87cbee9a-42a4-4213-963a-189cb029f8fa", + "origin": "Delegated (Azure DevOps)", + "value": "vso.gallery_acquire" + }, + { + "description": "Grants read access and the ability to publish and manage items and publishers.", + "displayName": "Marketplace (manage)", + "id": "05ac28f3-1561-4528-8579-c379a0f02805", + "origin": "Delegated (Azure DevOps)", + "value": "vso.gallery_manage" + }, + { + "description": "Grants read access and the ability to upload, update, and share items.", + "displayName": "Marketplace (publish)", + "id": "ac7ed1fb-75be-4f8c-adf3-4d19a5cead08", + "origin": "Delegated (Azure DevOps)", + "value": "vso.gallery_publish" + }, + { + "description": "Grants the ability to read user, group, scope, and group membership information.", + "displayName": "Graph (read)", + "id": "75a97209-eb46-4571-9d6b-777ae5fcb245", + "origin": "Delegated (Azure DevOps)", + "value": "vso.graph" + }, + { + "description": "Grants the ability to read user, group, scope and group membership information, and to add users, groups, and manage group memberships.", + "displayName": "Graph (manage)", + "id": "e5125ad5-f716-4bc5-8688-14499b80567e", + "origin": "Delegated (Azure DevOps)", + "value": "vso.graph_manage" + }, + { + "description": "Grants the ability to read identities and groups.", + "displayName": "Identity (read)", + "id": "e1bca0e2-994e-4688-b5f6-665b49ee1787", + "origin": "Delegated (Azure DevOps)", + "value": "vso.identity" + }, + { + "description": "Grants the ability to read, write, and manage identities and groups.", + "displayName": "Identity (manage)", + "id": "8b01a8c5-f24c-4740-8104-d74337d52c0f", + "origin": "Delegated (Azure DevOps)", + "value": "vso.identity_manage" + }, + { + "description": "Provides ability to manage deployment group and agent pools.", + "displayName": "Deployment group (read, manage)", + "id": "98b7775c-bc8f-4a14-8ca3-d83bfff24d81", + "origin": "Delegated (Azure DevOps)", + "value": "vso.machinegroup_manage" + }, + { + "description": "Grants the ability to read users, their licenses as well as projects and extensions they can access.", + "displayName": "MemberEntitlement Management (read)", + "id": "eafb48a2-84ed-4179-802a-5d6f1fe452f6", + "origin": "Delegated (Azure DevOps)", + "value": "vso.memberentitlementmanagement" + }, + { + "description": "Grants the ability to manage users, their licenses as well as projects and extensions they can access.", + "displayName": "MemberEntitlement Management (write)", + "id": "7f232b5a-2cf4-410c-833e-7fcb6175eb94", + "origin": "Delegated (Azure DevOps)", + "value": "vso.memberentitlementmanagement_write" + }, + { + "description": "Provides read access to subscriptions and event metadata, including filterable field values.", + "displayName": "Notifications (read)", + "id": "e7fce5bb-fd6c-4f04-9a7d-bc4d67ea64fc", + "origin": "Delegated (Azure DevOps)", + "value": "vso.notification" + }, + { + "description": "Provides access to notification-related diagnostic logs and provides the ability to enable diagnostics for individual subscriptions.", + "displayName": "Notifications (diagnostics)", + "id": "0284cfbf-b7a6-4576-b9f4-cade73cfc16f", + "origin": "Delegated (Azure DevOps)", + "value": "vso.notification_diagnostics" + }, + { + "description": "Provides ability to manage environment", + "displayName": "Environment (read, manage)", + "id": "8f4f9d85-c065-4d6c-8535-99d2998c84bd", + "origin": "Delegated (Azure DevOps)", + "value": "vso.environment_manage" + }, + { + "description": "Provides read only access to licensing entitlements endpoint to get account entitlements.", + "displayName": "Entitlements (Read)", + "id": "c3cbdc26-4b85-4be1-bfb4-af3a552fb28c", + "origin": "Delegated (Azure DevOps)", + "value": "vso.entitlements" + }, + { + "description": "Grants the ability to manage team dashboard information.", + "displayName": "Team dashboards (manage)", + "id": "885358bd-5763-4432-a781-5f2c78eb29e2", + "origin": "Delegated (Azure DevOps)", + "value": "vso.dashboards_manage" + }, + { + "description": "Grants the ability to read team dashboard information.", + "displayName": "Team dashboards (read)", + "id": "e9e366b1-b116-44b7-bd65-575d6bc13fc8", + "origin": "Delegated (Azure DevOps)", + "value": "vso.dashboards" + }, + { + "description": "Grants the ability to create and update load test runs, and read metadata including test results and APM artifacts.", + "displayName": "Load test (read and write)", + "id": "28d646b8-7efa-4ff7-9e39-dfb3a53b7fa6", + "origin": "Application (Azure DevOps)", + "value": "vso.loadtest_write" + }, + { + "description": "Allow the application full access to the REST APIs provided by Visual Studio Team Services on behalf of the signed-in user", + "displayName": "Have full access to Visual Studio Team Services REST APIs", + "id": "ee69721e-6c3a-468f-a9ec-302d16a4c599", + "origin": "Delegated (Azure DevOps)", + "value": "user_impersonation" + }, + { + "description": "Grants the ability to read alerts, result instances, analysis result instances", + "displayName": "AdvancedSecurity (read)", + "id": "78fa0d77-2f93-4844-b309-d46fe87fdc1c", + "origin": "Delegated (Azure DevOps)", + "value": "vso.advsec" + }, + { + "description": "Grants the ability to access sarif upload information, delete analysis, and update alerts", + "displayName": "AdvancedSecurity (read, write, and manage)", + "id": "5a20e9fd-a07c-4c6e-9595-7b78bebaf75d", + "origin": "Delegated (Azure DevOps)", + "value": "vso.advsec_manage" + }, + { + "description": "Grants the ability to upload analyses in sarif", + "displayName": "AdvancedSecurity (read and write)", + "id": "be203134-c456-436a-9be1-c6bd8a5046a4", + "origin": "Delegated (Azure DevOps)", + "value": "vso.advsec_write" + }, + { + "description": "Grants the ability to view tasks, pools, queues, agents, and currently running or recently completed jobs for agents.", + "displayName": "Agent Pools (read)", + "id": "ff83db68-cb4a-4cff-9bfe-285ed2bb9e45", + "origin": "Delegated (Azure DevOps)", + "value": "vso.agentpools" + }, + { + "description": "Grants the ability to manage pools, queues, and agents.", + "displayName": "Agent Pools (read, manage)", + "id": "09370e63-5e5c-4c44-b89a-6368427605d4", + "origin": "Delegated (Azure DevOps)", + "value": "vso.agentpools_manage" + }, + { + "description": "Grants the ability to query analytics.", + "displayName": "Analytics (read)", + "id": "fcd8f1a4-ac62-487a-b198-13632f189646", + "origin": "Delegated (Azure DevOps)", + "value": "vso.analytics" + }, + { + "description": "Provides read and write access to subscriptions and read access to event metadata, including filterable field values.", + "displayName": "Notifications (write)", + "id": "10e32108-6193-4cd9-b405-ab95c87509b0", + "origin": "Delegated (Azure DevOps)", + "value": "vso.notification_write" + }, + { + "description": "Grants the ability to read the auditing log and audit streams to users", + "displayName": "Audit Read Log", + "id": "47446fe8-9e9f-4bb2-bc8b-81a861caeddb", + "origin": "Delegated (Azure DevOps)", + "value": "vso.auditlog" + }, + { + "description": "Grants the ability to access build artifacts, including build results, definitions, and requests, and the ability to receive notifications about build events via service hooks.", + "displayName": "Build (read)", + "id": "0d85fdcb-8267-4af0-857e-7f76b110fbdc", + "origin": "Delegated (Azure DevOps)", + "value": "vso.build" + }, + { + "description": "Grants the ability to access build artifacts, including build results, definitions, and requests, and the ability to queue a build, update build properties, and the ability to receive notifications about build events via service hooks.", + "displayName": "Build (read and execute)", + "id": "b64406bf-2a08-4182-b51e-f51dd0f6d5a3", + "origin": "Delegated (Azure DevOps)", + "value": "vso.build_execute" + }, + { + "description": "Grants the ability to read source code and metadata about commits, changesets, branches, and other version control artifacts. Also grants the ability to search code and get notified about version control events via service hooks.", + "displayName": "Code (read)", + "id": "b325850d-aa53-41ed-b77a-c5036b2f39fa", + "origin": "Delegated (Azure DevOps)", + "value": "vso.code" + }, + { + "description": "Grants full access to source code, metadata about commits, changesets, branches, and other version control artifacts. Also grants the ability to create and manage code repositories, create and manage pull requests and code reviews, and to receive notifications about version control events via service hooks. Also includes limited support for Client OM APIs.", + "displayName": "Code (full)", + "id": "9aae797f-f2fc-47b9-bae7-1db49fdd874b", + "origin": "Delegated (Azure DevOps)", + "value": "vso.code_full" + }, + { + "description": "Grants the ability to read, update, and delete source code, access metadata about commits, changesets, branches, and other version control artifacts. Also grants the ability to create and manage code repositories, create and manage pull requests and code reviews, and to receive notifications about version control events via service hooks.", + "displayName": "Code (read, write, and manage)", + "id": "5f1d8cdf-acb3-47db-b79d-e0c6f18e262d", + "origin": "Delegated (Azure DevOps)", + "value": "vso.code_manage" + }, + { + "description": "Grants the ability to read and write commit and pull request status.", + "displayName": "Code (status)", + "id": "7082e756-8e76-4ebc-a2b0-353809a642c2", + "origin": "Delegated (Azure DevOps)", + "value": "vso.code_status" + }, + { + "description": "Grants the ability to read, update, and delete source code, access metadata about commits, changesets, branches, and other version control artifacts. Also grants the ability to create and manage pull requests and code reviews and to receive notifications about version control events via service hooks.", + "displayName": "Code (read and write)", + "id": "028ffaf1-6f06-490a-979e-38011f92fb7c", + "origin": "Delegated (Azure DevOps)", + "value": "vso.code_write" + }, + { + "description": "Grants the ability to access endpoints needed from an onprem connected server", + "displayName": "Connected Server", + "id": "c994c1ad-fd6d-42ae-9af7-20d4820fe36c", + "origin": "Delegated (Azure DevOps)", + "value": "vso.connected_server" + }, + { + "description": "Grants the ability to manage auditing streams to users", + "displayName": "Audit Streams (manage)", + "id": "ba2781d8-d6df-4b58-ac73-d80e7cdd25cd", + "origin": "Delegated (Azure DevOps)", + "value": "vso.auditstreams_manage" + }, + { + "description": "This allows app to run prod tenant userscope in DLS", + "displayName": "UserScope.ReadWrite.All", + "id": "6f6965e3-3c5a-47e2-81a6-9c40ddacc7f6", + "origin": "Application (DirectoryLookupService)", + "value": "UserScope.ReadWrite.All" + }, + { + "description": "Allows user to read Condition resources in their own compartment.", + "displayName": "user.Condition.read", + "id": "dd554abf-e473-4190-8382-9b096fe49efa", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Condition.read" + }, + { + "description": "Allows user to read DiagnosticReport resources in their own compartment.", + "displayName": "user.DiagnosticReport.read", + "id": "588567a0-59db-4598-8bd7-0cbea9ff1811", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.DiagnosticReport.read" + }, + { + "description": "c", + "displayName": "Skype Bot Reviewer", + "id": "ae068e81-caaf-43a2-8081-717c1fb700d0", + "origin": "Application (Bot Framework Dev Portal)", + "value": "SkypeReviewer" + }, + { + "description": "Read-only access to Bcos resources", + "displayName": "Bcos.ReadOnly", + "id": "c6a7f3e3-dea5-4df4-a094-59ceca797083", + "origin": "Application (Branch Connect Web Service)", + "value": "Bcos.ReadOnly" + }, + { + "description": "Read-write access to Bcos resources", + "displayName": "Bcos.ReadWrite", + "id": "aa6b9a9f-c72d-4834-a656-bb689b56844b", + "origin": "Application (Branch Connect Web Service)", + "value": "Bcos.ReadWrite" + }, + { + "description": "Read access to Branch Connect resources", + "displayName": "crosstenant.access", + "id": "231695ae-e8c8-44aa-a5ea-e976ffb46667", + "origin": "Application (Branch Connect Web Service)", + "value": "crosstenant.access" + }, + { + "description": "General access to Branch Connect tenanted resources", + "displayName": "intratenant.access", + "id": "fa7e7dba-1436-4a97-8144-94896b64b1bb", + "origin": "Application (Branch Connect Web Service)", + "value": "intratenant.access" + }, + { + "description": "ISV parter access to opt in or opt out Path Feedback", + "displayName": "Bcos.IsvPartner", + "id": "33cd71af-81fb-4558-b105-eb7a5f4c3191", + "origin": "Delegated (Branch Connect Web Service)", + "value": "Bcos.IsvPartner" + }, + { + "description": "Allows application to invite users to tenant", + "displayName": "Invite users to tenant", + "id": "7431916a-fe67-40b3-b273-602ffe516093", + "origin": "Application (CABProvisioning)", + "value": "user.invite.all" + }, + { + "description": "Allows the calling app to invoke Commerce Pricing APIs as the signed-in user.", + "displayName": "Access Commerce Pricing APIs on behalf of the signed-in user", + "id": "a7558686-77a5-4d0c-8563-d803e81c784c", + "origin": "Delegated (CCM_Pricing_PROD)", + "value": "CommercePricingAPIs.Access" + }, + { + "description": "Allows the app to read and deploy composite solutions, on your behalf", + "displayName": "Read and write composite solutions", + "id": "35bae7a0-c6c0-4835-b671-89f0f1736121", + "origin": "Delegated (CompositeSolutions-Canary)", + "value": "Deployment.ReadWrite" + }, + { + "description": "This allows applications to call CRS APIs.", + "displayName": "Call all CRS APIs", + "id": "f155dcbc-e393-438b-b343-92699349582d", + "origin": "Application (Compute Recommendation Service)", + "value": "Crs.Api.All" + }, + { + "description": "Allows to call service API to query account onboarding data", + "displayName": "Read account onboarding data", + "id": "c8750fbf-30e2-40ed-8519-e2876cbeccb9", + "origin": "Application (Configuration Manager Microservice)", + "value": "Account.Read.All" + }, + { + "description": "Allows to call service API to query or modify account onboarding data", + "displayName": "Read or write account onboarding data", + "id": "76e55082-bbde-4602-b506-bba9c6368668", + "origin": "Application (Configuration Manager Microservice)", + "value": "Account.ReadWrite.All" + }, + { + "description": "Allows user to perform administrative actions", + "displayName": "Admin User", + "id": "c22b119a-bb68-45ab-8a0a-ef26bc7a66e7", + "origin": "Application (Configuration Manager Microservice)", + "value": "AdminUser.ReadWrite" + }, + { + "description": "Allows to call service API to query boundary data", + "displayName": "Read boundary data", + "id": "b026af69-9eae-4bb3-9351-304d4987e170", + "origin": "Application (Configuration Manager Microservice)", + "value": "Boundary.Read.All" + }, + { + "description": "Allows services to call APIs that return SCCM collection membership data", + "displayName": "Read CM Collection Data", + "id": "1ce9e34f-35e8-4af8-b172-09e4dd00453d", + "origin": "Application (Configuration Manager Microservice)", + "value": "CmCollectionData.read" + }, + { + "description": "Allows services to write collection membership data to storage in the Configuration Manager microservice", + "displayName": "Write CM Collection Data", + "id": "a7a0e953-7ed2-423c-849f-9d78b5e44612", + "origin": "Application (Configuration Manager Microservice)", + "value": "CmCollectionData.write" + }, + { + "description": "c", + "displayName": "RBAC Test Role Prod", + "id": "b6c09b98-4044-4869-976f-625da4f561c3", + "origin": "Application (Bot Framework Dev Portal)", + "value": "RBACTestRoleProd" + }, + { + "description": "Allows to call service API to query collection data", + "displayName": "Read collection data", + "id": "66a874a2-b739-43fa-8e1a-176cd8290cf5", + "origin": "Application (Configuration Manager Microservice)", + "value": "Collection.Read.All" + }, + { + "description": "Support engineers for prod devportal", + "displayName": "Prod Devportal Support", + "id": "b1de6b77-7554-4b4d-9db5-dc90af4bbe89", + "origin": "Application (Bot Framework Dev Portal)", + "value": "ProdSupport" + }, + { + "description": "Users of scratch / ppe devportal", + "displayName": "Internal Devportal User", + "id": "0e91f604-29c5-475d-9463-5494ee9b147e", + "origin": "Application (Bot Framework Dev Portal)", + "value": "IntUser" + }, + { + "description": "Allows the app to search all calendars and to read their properties on behalf of the signed-in user. ", + "displayName": "Read all calendars", + "id": "73c5d1d0-1ba7-4978-ad4c-32f0a8a1a9ed", + "origin": "Delegated (Bing)", + "value": "Calendar.Read.All" + }, + { + "description": "Allows the app to search all calendars and to read their properties for default on behalf of the signed-in user. ", + "displayName": "Read all calendars for default", + "id": "46089125-31ba-451a-96a1-278c9490b608", + "origin": "Delegated (Bing)", + "value": "Calendars.Read" + }, + { + "description": "Allows the app to read Copilot product eligibility information, on behalf of the signed-in user.", + "displayName": "Read user Copilot product eligibility information", + "id": "9cc9bf6f-c54f-4db7-801a-a3c0a4f7ea7c", + "origin": "Delegated (Bing)", + "value": "CopilotEligibility.Read" + }, + { + "description": "Allows the app to read Copilot product configuration information, on behalf of the signed-in user.", + "displayName": "Read user Copilot product configuration information", + "id": "cdedc077-0f6e-4cf8-ab81-44ba9d14983c", + "origin": "Delegated (Bing)", + "value": "CopilotSettings.ReadWrite" + }, + { + "description": "Allows the app to read all files the signed-in user can access.", + "displayName": "Read all files that user can access", + "id": "79bb59ea-208c-4cff-881e-098caabe543a", + "origin": "Delegated (Bing)", + "value": "Files.Read.All" + }, + { + "description": "Allows the app to list floor plans and to read their properties on behalf of the signed-in user. ", + "displayName": "Read all floor plans", + "id": "ff60b1a1-5694-4b26-9c81-a5f4fabf51f5", + "origin": "Delegated (Bing)", + "value": "FloorPlan.Read.All" + }, + { + "description": "Allows the app to list groups, and to read their properties and all group memberships on behalf of the signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups the signed-in user can access.", + "displayName": "Read all groups", + "id": "fe6d53fc-0936-42ba-8388-d39c6855c3f2", + "origin": "Delegated (Bing)", + "value": "Group.Read.All" + }, + { + "description": "Allows the app to read news feeds and to read their properties on behalf of the signed-in user. ", + "displayName": "Read news feed", + "id": "c11daebe-235e-4429-ab4c-43569661ff2a", + "origin": "Delegated (Bing)", + "value": "NewsFeed.Read" + }, + { + "description": "Allows the app to list QnA and to read their properties on behalf of the signed-in user. ", + "displayName": "Read all QnA", + "id": "bfc6f88b-6314-451d-ac7c-501307ad192a", + "origin": "Delegated (Bing)", + "value": "QnA.Read.All" + }, + { + "description": "Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user.", + "displayName": "Read all users' full profiles", + "id": "9ee66b54-9cf0-41b8-87da-d62f8c21222b", + "origin": "Delegated (Bing)", + "value": "User.Read.All" + }, + { + "description": "Allows the app to fetch web grounded data for Copilot", + "displayName": "Access web grounding", + "id": "516d1055-ed6f-4e63-922d-eb17aef59604", + "origin": "Delegated (Bing)", + "value": "Web.Read" + }, + { + "description": "c", + "displayName": "Bing Bot Reviewer", + "id": "c9774c15-ca59-44c2-8934-14892b976eeb", + "origin": "Application (Bot Framework Dev Portal)", + "value": "BingReviewer" + }, + { + "description": "operator who can manage how user access DiretlineSpeech channel", + "displayName": "DirectlineSpeech Channel Operator", + "id": "8445d019-58a2-4852-8169-28bb272b72da", + "origin": "Application (Bot Framework Dev Portal)", + "value": "channelOperator_DirectlineSpeech" + }, + { + "description": "users with this role are automatically placed on the cortana1PSkills flight", + "displayName": "cortana 1P skills", + "id": "7ee5d4d7-5187-475f-bf60-e29825067173", + "origin": "Application (Bot Framework Dev Portal)", + "value": "flight_cortana1PSkills" + }, + { + "description": "users with this role are automatically placed in the cortanaPreview flight", + "displayName": "cortana preview flight role", + "id": "c97c1572-9874-40a8-905a-9e00c9fb7e19", + "origin": "Application (Bot Framework Dev Portal)", + "value": "flight_cortanaPreview" + }, + { + "description": "Admins for scratch / ppe devportal ", + "displayName": "Internal Devportal Admin", + "id": "d5936425-7cdb-467d-990c-de5b9dfecc93", + "origin": "Application (Bot Framework Dev Portal)", + "value": "IntAdmin" + }, + { + "description": "Support engineers for scratch / ppe devportal", + "displayName": "Internal Devportal Support", + "id": "3c23c4fc-15c2-43ff-b26c-ea2fb7f2cac7", + "origin": "Application (Bot Framework Dev Portal)", + "value": "IntSupport" + }, + { + "description": "Admins for prod devportal", + "displayName": "Prod Devportal Admin", + "id": "9160be5e-b0e2-4961-9419-21dc535897ca", + "origin": "Application (Bot Framework Dev Portal)", + "value": "ProdAdmin" + }, + { + "description": "Allows to call service API to query device data", + "displayName": "Read device data", + "id": "15fdfc00-27d5-4f79-8a38-8efe91e3c1cc", + "origin": "Application (Configuration Manager Microservice)", + "value": "Device.Read.All" + }, + { + "description": "Allows to call service API to query or modify device data", + "displayName": "Read or write device data", + "id": "4b03fb80-ef9e-4391-86c9-152c41bf0693", + "origin": "Application (Configuration Manager Microservice)", + "value": "Device.ReadWrite.All" + }, + { + "description": "Allows to call service API to query inventory class", + "displayName": "Read inventory class", + "id": "d430b935-3087-4654-8d58-25faba0dabb5", + "origin": "Application (Configuration Manager Microservice)", + "value": "InventoryClass.Read.All" + }, + { + "description": "Permission to create seeding offer", + "displayName": "CREATE/START Seeding offer for a tenant", + "id": "072da657-3fd6-47c8-914c-384bed197d2a", + "origin": "Application (Consumption Billing)", + "value": "Purview.Offer.Seeding.Create" + }, + { + "description": "Read Permission for seeding offers", + "displayName": "READ Seeding offers for a tenant", + "id": "f3f3f5b3-6e2e-4f6b-8f3c-6e2e2b1e4f4a", + "origin": "Application (Consumption Billing)", + "value": "Purview.Offer.Seeding.Read" + }, + { + "description": "Allows the app to create, read, update and delete applications and service principals on behalf of the signed-in user. Does not allow management of consent grants.", + "displayName": "Read and write all applications (preview)", + "id": "16ad0ec2-1d62-4034-9a8e-88b445cc30ec", + "origin": "Delegated (Consumption Billing)", + "value": "Application.ReadWrite.All" + }, + { + "description": "Permissions for an internal Cortana application to read and write all Cortana user data", + "displayName": "BingCortana-Internal.ReadWrite", + "id": "f78726f6-cf77-45f6-ae8b-87d4b8bd7a2c", + "origin": "Application (Cortana at Work Bing Services)", + "value": "BingCortana-Internal.ReadWrite" + }, + { + "description": "Permissions for an internal Cortana application to read and write all Cortana user data", + "displayName": "BingCortana-Internal.ReadWrite", + "id": "ab725b17-4fd4-46ee-a0bf-102895a209e3", + "origin": "Application (Cortana at Work Service)", + "value": "BingCortana-Internal.ReadWrite" + }, + { + "description": "Permission for internal Cortana applications", + "displayName": "BingCortana-Internal.ReadWrite", + "id": "c9265686-1717-4d25-a640-1f46263a162c", + "origin": "Application (Cortana Runtime Service)", + "value": "BingCortana-Internal.ReadWrite" + }, + { + "description": "Scope for Semantic Machines context access", + "displayName": "SemanticMachineContext.ReadWrite", + "id": "47d1397b-a828-452a-9b8d-2796c4e65f4e", + "origin": "Application (Cortana Runtime Service)", + "value": "SemanticMachineContext.ReadWrite" + }, + { + "description": "allows access to read DeploymentTask and UpdatePolicy", + "displayName": "DeploymentTask.Read", + "id": "a0f3e90e-0c99-4c7d-bfaf-69531a09579c", + "origin": "Application (DeploymentScheduler)", + "value": "deploymenttask.read" + }, + { + "description": "allows access to read or write deployment task and update policies", + "displayName": "DeploymentTask.ReadWrite", + "id": "64b22404-2ac7-4ca5-a15d-607e62d2694b", + "origin": "Application (DeploymentScheduler)", + "value": "deploymenttask.readwrite" + }, + { + "description": "Allow the application permissions to delete any device registered to the signed-in user", + "displayName": "User can delete devices that belong to them", + "id": "086327cd-9afe-4777-8341-b136a1866bb3", + "origin": "Delegated (Device Registration Service)", + "value": "self_service_device_delete" + }, + { + "description": "Allow the application to read profiler traces, insights, and diagnostic data on behalf of the signed-in user", + "displayName": "Read Diagnostic Services data", + "id": "ada81ce7-1959-4df2-81a5-cd710022e0c5", + "origin": "Delegated (Diagnostic Services Data Access)", + "value": "DataAccess.Read" + }, + { + "description": "Allow the application to read and modify profiler settings, trigger profiling sessions, upload symbols, and manage diagnostic data on behalf of the signed-in user", + "displayName": "Read and write Diagnostic Services data", + "id": "ce194c4c-ad00-4826-8328-102bb21ec298", + "origin": "Delegated (Diagnostic Services Data Access)", + "value": "DataAccess.ReadWrite" + }, + { + "description": "Allow the application to access Diagnostic Services on behalf of the signed-in user", + "displayName": "Access Diagnostic Services", + "id": "384a9d29-7ed2-4fc4-b781-1aa48cb2b883", + "origin": "Delegated (Diagnostic Services Data Access)", + "value": "user_impersonation" + }, + { + "description": "This allows app to access prod user profile", + "displayName": "Users.Read.All", + "id": "b0dc367b-7342-44c8-9816-d5f9ade99d5d", + "origin": "Application (DirectoryLookupService)", + "value": "Users.Read.All" + }, + { + "description": "Permission to update seeding offer consumption", + "displayName": "Update consumption against a feature as part of seeding offers", + "id": "b1e2f3d4-5c6b-7a8d-9e0f-1a2b3c4d5e6f", + "origin": "Application (Consumption Billing)", + "value": "Purview.Offer.Seeding.ConsumedUnits.Write" + }, + { + "description": "Read Permission for free trials", + "displayName": "READ Free Trials for a tenant", + "id": "7677749a-98a0-4fb4-ab2b-a0c1f445b393", + "origin": "Application (Consumption Billing)", + "value": "Purview.Offer.FreeTrial.Read" + }, + { + "description": "Permission to create/start free trials", + "displayName": "CREATE/START Free Trials for a tenant", + "id": "6061d6f3-95e7-4aef-b53f-81967905b679", + "origin": "Application (Consumption Billing)", + "value": "Purview.Offer.FreeTrial.Create" + }, + { + "description": "Permission to update free trials consumption", + "displayName": "Update consumption against a feature as part of free trials", + "id": "30d79437-9413-4983-80b2-b9c64df69cde", + "origin": "Application (Consumption Billing)", + "value": "Purview.Offer.FreeTrial.ConsumedUnits.Write" + }, + { + "description": "Allows to call service API to query notification and notification result", + "displayName": "Read notification or notification result", + "id": "20bd8bbf-3063-4a8f-ae4f-f2f5e5bda666", + "origin": "Application (Configuration Manager Microservice)", + "value": "Notification.Read.All" + }, + { + "description": "Allows to call service API to query or modify notification and notification result", + "displayName": "Read or write notification and notification result", + "id": "0db7d603-2368-4c9a-8f47-adc9ac73e5e1", + "origin": "Application (Configuration Manager Microservice)", + "value": "Notification.ReadWrite.All" + }, + { + "description": "Allows the app to list buildings and to read their properties on behalf of the signed-in user. ", + "displayName": "Read all buildings", + "id": "b74d6cc7-732d-424d-9f47-b08e1404f765", + "origin": "Delegated (Bing)", + "value": "Building.Read.All" + }, + { + "description": "Allows the app to create and manage connector configurations. The app would use the connector configuration to send actionable messages to your inbox or a group of your choice.", + "displayName": "Read and write connector configurations", + "id": "ba9c6a98-63fd-487c-b835-c1f895764e25", + "origin": "Delegated (Connectors)", + "value": "webhook.readwrite.all" + }, + { + "description": "Authorized to call the Consumption Billing reporting API for a single tenant id", + "displayName": "GET Consumption Bill Report for a tenant", + "id": "866040a7-8984-4760-8e56-363aefb78d69", + "origin": "Application (Consumption Billing)", + "value": "CBS.Reporting.Read" + }, + { + "description": "Authorized to call the Consumption Billing reporting API for a single tenant id", + "displayName": "GET Consumption Bill Report for any tenant", + "id": "387f12b7-02f9-4763-ae1d-1686945340fc", + "origin": "Application (Consumption Billing)", + "value": "CBS.Reporting.Read.Any" + }, + { + "description": "Authorized to call the GLSaccount for a single tenant id", + "displayName": "GLS Read Permissions", + "id": "4fbf572c-d471-4816-a804-873ab98e6356", + "origin": "Application (Consumption Billing)", + "value": "Gls.Tenant.Forest.Read" + }, + { + "description": "Authorized to call the GLSaccount for any tenant id", + "displayName": "GLS Read Permissions", + "id": "0954fe74-24eb-11f0-b752-325096b39f47", + "origin": "Application (Consumption Billing)", + "value": "Gls.Tenant.Forest.Read.Any" + }, + { + "description": "Authorized to call the Consumption Billing Post API for a single tenant id to enable/disable billing consent at feature level", + "displayName": "POST API to update the billing consent", + "id": "389f13b7-02f9-4763-ae1d-1686945340fc", + "origin": "Application (Consumption Billing)", + "value": "Purview.Account.Feature.State.Write" + }, + { + "description": "Authorized to call the purview account for a single tenant id", + "displayName": "GET Purview Account for a tenant", + "id": "228c9ab9-eb11-4548-a16a-7efb4ed58162", + "origin": "Application (Consumption Billing)", + "value": "Purview.Account.Read" + }, + { + "description": "Authorized to call the purview account for any tenant id", + "displayName": "GET Purview Account for any tenant", + "id": "693c4235-83dd-4f0c-baca-a30c2826c9a8", + "origin": "Application (Consumption Billing)", + "value": "Purview.Account.Read.Any" + }, + { + "description": "Access Connections Service Api", + "displayName": "Access Connections Service Api", + "id": "04d2d44f-432b-4f9b-be28-cb651a028099", + "origin": "Delegated (ConnectionsService)", + "value": "user_impersonation" + }, + { + "description": "Allows user to read Device resources in their own compartment.", + "displayName": "user.Device.read", + "id": "a246e7b9-d55c-43a2-9b5a-b3341bc1a57d", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Device.read" + }, + { + "description": "Allows the app to list bookmarks and to read their properties on behalf of the signed-in user. ", + "displayName": "Read all bookmarks", + "id": "e017a1f7-f5a6-4dc5-a7b6-4342362e299b", + "origin": "Delegated (Bing)", + "value": "Bookmark.Read.All" + }, + { + "description": "Allows members of a special preview group to use experimental features of Bing", + "displayName": "Preview User", + "id": "cfc0dc64-9211-4513-9d32-c387680182cf", + "origin": "Application (Bing)", + "value": "bawuser" + }, + { + "description": "Allow the application full access to the Azure Key Vault service on behalf of the signed-in user", + "displayName": "Have full access to the Azure Key Vault service", + "id": "f53da476-18e3-4152-8e01-aec403e6edc0", + "origin": "Delegated (Azure Key Vault)", + "value": "user_impersonation" + }, + { + "description": "this allows to read user profile", + "displayName": "user.read", + "id": "34a47c2f-cd0d-47b4-a93c-2c41130c671c", + "origin": "Delegated (Azure Kubernetes Service AAD Server)", + "value": "user.read" + }, + { + "description": "Consent for Azure Machine Learning Service", + "displayName": "user_impersonation", + "id": "1a7925b5-f871-417a-9b8b-303f9f29fa10", + "origin": "Delegated (Azure Machine Learning Services)", + "value": "user_impersonation" + }, + { + "description": "Allow the application to access Azure Maps on behalf of the signed-in user.", + "displayName": "Access Azure Maps", + "id": "1c3162b4-de12-4eb3-b521-088e4e2d6915", + "origin": "Delegated (Azure Maps)", + "value": "user_impersonation" + }, + { + "description": "Azure media service API allows creating, modifying, viewing & deleting of media assets", + "displayName": "Access azure media service as signed-in user", + "id": "59f34ebf-a919-4365-9cc3-00193275099c", + "origin": "Delegated (Azure Media Services)", + "value": "access_media_service" + }, + { + "description": "Allows the app to read and write MCP tools on behalf of the user.", + "displayName": "Read and write MCP tools", + "id": "66cf23b6-becd-4117-8b55-28aba2d06b9b", + "origin": "Delegated (Azure Migrate AI Assistant)", + "value": "Mcp.Tools.ReadWrite" + }, + { + "description": "This scope allows Azure Monitor Agents to access Azure Monitor backends on behalf of the Client Device.", + "displayName": "Read Data Collection Rules", + "id": "8a4fc8e7-d346-4d67-a1d3-e83b55cf3659", + "origin": "Delegated (Azure Monitor Control Service)", + "value": "AMA.Ingest" + }, + { + "description": "Allows the app to access GeoCatalogs on behalf of the signed-in user.", + "displayName": "Access GeoCatalogs", + "id": "870e9a7e-1d10-42b2-85dc-2cd2b2cd656b", + "origin": "Delegated (Azure Orbital Planetary Computer)", + "value": "user_impersonation" + }, + { + "description": "Access OSSRDBMS services from the application", + "displayName": "OSSRDBMS Azure", + "id": "017211c5-049f-46b5-a0f0-bcc46299e550", + "origin": "Application (Azure OSSRDBMS Database)", + "value": "app_impersonation" + }, + { + "description": "Access OSSRDBMS services as a user", + "displayName": "Access OSSRDBMS services", + "id": "cef99a3a-4cd3-4408-8143-4375d1e38a17", + "origin": "Delegated (Azure OSSRDBMS Database)", + "value": "user_impersonation" + }, + { + "description": "Allow the application full read and write access to the PKI service", + "displayName": "Have full read and write access to the PKI service", + "id": "65b05492-d252-4876-b9fb-0a848447f31a", + "origin": "Delegated (Azure PKI)", + "value": "Pki.ReadWrite.All" + }, + { + "description": "Azure Event Grid Role", + "displayName": "AzureEventGridSecureWebhookSubscriber", + "id": "83262d98-99cb-496d-8da9-e0ceed85d0ed", + "origin": "Application (Azure Resources Topology)", + "value": "AzureEventGridSecureWebhookSubscriber" + }, + { + "description": "Allows users to deploy Azure resources to one or more regions in a orchestrated manner using an ARM based declarative model.", + "displayName": "Azure Service Deploy", + "id": "bc5c4337-74a0-4a05-864d-576511d9621f", + "origin": "Delegated (Azure Service Deploy)", + "value": "Rollouts.ReadWrite.User" + }, + { + "description": "Allows the application to access Azure SignalR Service on behalf of the signed-in user.", + "displayName": "Access Azure SignalR Service", + "id": "d210251d-4053-4044-ba08-3cb30c4cfcdc", + "origin": "Delegated (Azure SignalR Service Resource Provider)", + "value": "user_impersonation" + }, + { + "description": "Allows the app to create and get a new InvitationId for tenant and billing account creation.", + "displayName": "CreateInvitation20230101", + "id": "b39d576f-c5a3-4820-b851-00060443f895", + "origin": "Application (Azure Signup Api)", + "value": "CreateInvitation20230101" + }, + { + "description": "Allow user to add charity qualification.", + "displayName": "Qualification_Charity", + "id": "0fab173d-4ed1-478b-976a-8c8ee219758b", + "origin": "Application (Azure Signup Api)", + "value": "Qualification_Charity" + }, + { + "description": "Allow user to add commercial qualification.", + "displayName": "Qualification_Commercial", + "id": "f04d1efa-b98b-4a56-ad63-a259c4859fdd", + "origin": "Application (Azure Signup Api)", + "value": "Qualification_Commercial" + }, + { + "description": "Allow the application to access Inference Service on behalf of the signed-in user.", + "displayName": "Access Inference Service", + "id": "a1e1f816-e7ca-4a34-900a-f863a751e400", + "origin": "Delegated (Azure Inference Service)", + "value": "Azure.Inference.User" + }, + { + "description": "Allow user to add dod qualification.", + "displayName": "Qualification_DOD", + "id": "d0175eef-86a5-4f91-ba11-e69a87656565", + "origin": "Application (Azure Signup Api)", + "value": "Qualification_DOD" + }, + { + "description": "Have the permissions to read models, deployments and environments.", + "displayName": "Inference ML reader", + "id": "55d7b9ab-4730-4d3e-9e2c-0130c1e764aa", + "origin": "Application (Azure Inference Service)", + "value": "Azure.Inference.MLReader" + }, + { + "description": "Have the permissions to execute inference calls.", + "displayName": "Inference executor", + "id": "92ad2108-b071-46c2-8ac0-1dcf9a2c4fd6", + "origin": "Application (Azure Inference Service)", + "value": "Azure.Inference.Executor" + }, + { + "description": "Allows user to read DocumentReference resources in their own compartment.", + "displayName": "user.DocumentReference.read", + "id": "23b15307-5f89-4954-b86c-00e2c4279a8f", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.DocumentReference.read" + }, + { + "description": "Allows user to read Encounter resources in their own compartment.", + "displayName": "user.Encounter.read", + "id": "0e5be5d5-7b95-4583-aa3c-2de990f139c9", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Encounter.read" + }, + { + "description": "Allows user to read Goal resources in their own compartment.", + "displayName": "user.Goal.read", + "id": "81d580ea-26f6-4822-9d91-31fb29019023", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Goal.read" + }, + { + "description": "Allows user to read Immunization resources in their compartment.", + "displayName": "user.Immunization.read", + "id": "97d73b5a-b052-4953-a6da-3e3f159a2f85", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Immunization.read" + }, + { + "description": "Allows user to read Location resources in their own compartment.", + "displayName": "user.Location.read", + "id": "cf8b4a64-fb79-401f-94a4-28d9d7cd6a8d", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Location.read" + }, + { + "description": "Allows user to read Medication resources in their own compartment.", + "displayName": "user.Medication.read", + "id": "e5a7cdb9-3edb-4b0a-a43d-40a377726680", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Medication.read" + }, + { + "description": "Allows user to read MedicationRequest resources in their own compartment.", + "displayName": "user.MedicationRequest.read", + "id": "c1519c05-9e3c-4656-844a-c83845bbaa9a", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.MedicationRequest.read" + }, + { + "description": "Allows user to read Observation resources in their own compartment.", + "displayName": "user.Observation.read", + "id": "556e34b1-56e8-4c27-b6be-679d856c0efa", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Observation.read" + }, + { + "description": "Allows user to read Organization resources in their own compartment.", + "displayName": "user.Organization.read", + "id": "e75606ef-f141-4339-a248-f4c9b07886b2", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Organization.read" + }, + { + "description": "Allows user to read Patient resources in their own compartment.", + "displayName": "user.Patient.read", + "id": "56998e01-1f00-4832-a130-c358e252acf2", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Patient.read" + }, + { + "description": "Allows user to read Practitioner resources in their own compartment.", + "displayName": "user.Practitioner.read", + "id": "079186df-3044-4484-a785-d9750101f8f3", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Practitioner.read" + }, + { + "description": "Allows user to read PractitionerRole resources in their own compartment.", + "displayName": "user.PractitionerRole.read", + "id": "ae77fe95-13db-47f8-968c-5eee9d973273", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.PractitionerRole.read" + }, + { + "description": "Allows user to read Procedure resources in their own compartment.", + "displayName": "user.Procedure.read", + "id": "81d46baa-aaff-454b-9a35-b6fdaa0eb2d9", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Procedure.read" + }, + { + "description": "Allows user to read Provenance resources in their own compartment.", + "displayName": "user.Provenance.read", + "id": "8d821765-6bbb-4f52-8b7f-0dfe9ce5cb1e", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Provenance.read" + }, + { + "description": "Allow the application to access Azure Healthcare APIs on behalf of the signed-in user.", + "displayName": "Access Azure Healthcare APIs", + "id": "db75143a-8f20-4238-9450-8b73ef4992f4", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user_impersonation" + }, + { + "description": "Azure Import Export service for massive data transferring by shipping disks", + "displayName": "Azure Import Export", + "id": "26d59185-6d22-461c-98e2-2cd4bcc6911b", + "origin": "Application (Azure Import Export)", + "value": "user_impersonation" + }, + { + "description": "Have the permissions to run administrative operations in the App Service layer", + "displayName": "Inference administrator", + "id": "ae7e897c-6c70-4824-ba03-bfcc9ad84c64", + "origin": "Application (Azure Inference Service)", + "value": "Azure.Inference.Admin" + }, + { + "description": "Have the permissions to create and modify models, deployments and environments; update traffic of deployments and perform; and scale up deployments.", + "displayName": "Inference ML administrator", + "id": "90d1b19a-1849-4c47-9d91-ed1842c92f52", + "origin": "Application (Azure Inference Service)", + "value": "Azure.Inference.MLAdministrator" + }, + { + "description": "Allow user to add gcc high qualification.", + "displayName": "Qualification_GCCHigh", + "id": "ab0c514c-6a2b-4a77-81bc-74019dff79d3", + "origin": "Application (Azure Signup Api)", + "value": "Qualification_GCCHigh" + }, + { + "description": "Allow user to add government qualification.", + "displayName": "Qualification_Government", + "id": "3e74b245-2d1f-4ffb-a5e8-9a05aceca540", + "origin": "Application (Azure Signup Api)", + "value": "Qualification_Government" + }, + { + "description": "Provides delegated role to the caller.", + "displayName": "SignupPlatformDelegatedRole", + "id": "8de2faed-dae7-4e94-8d5d-a49be218c680", + "origin": "Application (Azure Signup Api)", + "value": "SignupPlatformDelegatedRole" + }, + { + "description": "Allows the app to make API calls that require read and write permissions on ContextualSupport Service, on behalf of the signed-in user.", + "displayName": "Make API calls that require read and write permissions on ContextualSupport Service", + "id": "c21cb1c4-59a0-4474-939f-6e57bf66bfde", + "origin": "Delegated (Azure-WaaS-ContextualSupport-Service)", + "value": "ContextualSupport.ReadWrite.All" + }, + { + "description": "Address Customer Master Reader", + "displayName": "AddressCustomerMasterReader", + "id": "1cbc9fa5-af3f-44ad-9455-35ef4dd212aa", + "origin": "Application (Billing)", + "value": "AddressCustomerMasterReader" + }, + { + "description": "Billing Period Reader", + "displayName": "BillingPeriodReader", + "id": "8e62a787-fdef-400f-86a5-c8ba447b1e3a", + "origin": "Application (Billing)", + "value": "BillingPeriodReader" + }, + { + "description": "Customer Offboarding Manager", + "displayName": "CustomerOffboardingManager", + "id": "3c3a3b03-4791-4e89-8753-fa338df5564d", + "origin": "Application (Billing)", + "value": "CustomerOffboardingManager" + }, + { + "description": "Customer Reader", + "displayName": "CustomerReader", + "id": "a589c920-4000-431e-8a26-3c849e60d9e8", + "origin": "Application (Billing)", + "value": "CustomerReader" + }, + { + "description": "Full Trust Billing Subscription Refund Manager", + "displayName": "FullTrustBillingSubscriptionRefundManager", + "id": "501b1467-43a9-475e-9fbb-5e840ff5b597", + "origin": "Application (Billing)", + "value": "FullTrustBillingSubscriptionRefundManager" + }, + { + "description": "FullTrust EA Partner Organizations Reader", + "displayName": "FullTrustEAPartnerOrganizationsReader", + "id": "1224c7b4-5fd0-40e8-a122-2fb278e6d012", + "origin": "Application (Billing)", + "value": "FullTrustEAPartnerOrganizationsReader" + }, + { + "description": "Full Trust Internal Billing Account Reader", + "displayName": "FullTrustInternalBillingAccountReader", + "id": "42f62651-2fce-49b0-8b8a-b2c36bdb2c28", + "origin": "Application (Billing)", + "value": "FullTrustInternalBillingAccountReader" + }, + { + "description": "Full Trust Project Reader", + "displayName": "FullTrustProjectReader", + "id": "a010eb98-c8e4-40c5-afc7-87df9f063e89", + "origin": "Application (Billing)", + "value": "FullTrustProjectReader" + }, + { + "description": "Indirect Reseller Offboarding Manager", + "displayName": "IndirectResellerOffboardingManager", + "id": "ddbd0f71-1ff8-4335-a4b5-420bab16e11e", + "origin": "Application (Billing)", + "value": "IndirectResellerOffboardingManager" + }, + { + "description": "Manger of legacy APIs", + "displayName": "LegacyManager", + "id": "b0096bea-94b4-42b2-990c-6eedd19f4f4a", + "origin": "Application (Billing)", + "value": "LegacyManager" + }, + { + "description": "Partner Details Manager", + "displayName": "PartnerDetailsManager", + "id": "66b0d3be-66cc-465d-852a-87d76566ce29", + "origin": "Application (Billing)", + "value": "PartnerDetailsManager" + }, + { + "description": "Partner Offboarding Manager", + "displayName": "PartnerOffboardingManager", + "id": "54bff1ce-0f2d-4eb3-a2f0-49d67447a80e", + "origin": "Application (Billing)", + "value": "PartnerOffboardingManager" + }, + { + "description": "Project Reader", + "displayName": "ProjectReader", + "id": "88c2cc2d-c66c-4343-83ae-31fd6fd413b6", + "origin": "Application (Billing)", + "value": "ProjectReader" + }, + { + "description": "Refresh Manager", + "displayName": "RefreshManager", + "id": "73ba0d8a-0f84-44f8-9857-fb364934f4db", + "origin": "Application (Billing)", + "value": "RefreshManager" + }, + { + "description": "Rem Policy Manager", + "displayName": "RemPolicyManager", + "id": "03830c81-7471-499e-a514-e86f71829003", + "origin": "Application (Billing)", + "value": "RemPolicyManager" + }, + { + "description": "Subscription Migrator", + "displayName": "SubscriptionMigrator", + "id": "9edf2859-df6b-4ef5-ab1b-fd2837e2f7f7", + "origin": "Application (Billing)", + "value": "SubscriptionMigrator" + }, + { + "description": "Allow the app to submit and retrieve jobs.", + "displayName": "Jobs.ReadWrite", + "id": "52109446-c0d3-4e4f-9e8a-35bbee6b8b7d", + "origin": "Delegated (AzureQuantum)", + "value": "Jobs.ReadWrite" + }, + { + "description": "allows the user to have full access to Azure Databricks", + "displayName": "user_impersonation", + "id": "739272be-e143-11e8-9f32-f2801f1b9fd1", + "origin": "Delegated (AzureDatabricks)", + "value": "user_impersonation" + }, + { + "description": "Allows a user to invoke any write (POST, PUT) operation across the provisioning API.", + "displayName": "ProvisioningAPI.WriteUser", + "id": "c175fb63-786b-45cc-b884-9372c7f12120", + "origin": "Application (AzureCommunicationsGateway)", + "value": "ProvisioningAPI.WriteUser" + }, + { + "description": "Allows an application to invoke any write (POST, PUT) operation across the provisioning API.", + "displayName": "ProvisioningAPI.Write", + "id": "31e9e2c5-f52d-4a97-9962-5c4fc2d1bcc1", + "origin": "Application (AzureCommunicationsGateway)", + "value": "ProvisioningAPI.Write" + }, + { + "description": "Allows partners to add tags with charity namespace.", + "displayName": "Tag_charity", + "id": "eb6f173a-fd78-41c4-9208-e2df4e4e0475", + "origin": "Application (Azure Signup Api)", + "value": "Tag_charity" + }, + { + "description": "Allows partners to add tags with ea namespace.", + "displayName": "Tag_ea", + "id": "d59f33c1-1406-4028-a0f7-8f00ae1dbf10", + "origin": "Application (Azure Signup Api)", + "value": "Tag_ea" + }, + { + "description": "Allows partners to add tags with edu namespace.", + "displayName": "Tag_edu", + "id": "be01a05d-841f-49e7-9fd9-06ddc2bd6e28", + "origin": "Application (Azure Signup Api)", + "value": "Tag_edu" + }, + { + "description": "Allows partners to add tags with gov namespace.", + "displayName": "Tag_gov", + "id": "537eda31-79dd-4d7a-882a-00651883dcec", + "origin": "Application (Azure Signup Api)", + "value": "Tag_gov" + }, + { + "description": "Allows partners to add tags with servicescope namespace.", + "displayName": "Tag_servicescope", + "id": "b9a6ff0b-f721-41df-915d-a0094656547b", + "origin": "Application (Azure Signup Api)", + "value": "Tag_servicescope" + }, + { + "description": "Allows the app to update the billing stage.", + "displayName": "UpdateBillingStage", + "id": "5653af47-c35e-4df8-b835-bd1b642b6931", + "origin": "Application (Azure Signup Api)", + "value": "UpdateBillingStage" + }, + { + "description": "Allows the app to create a billing account with UsExempt taxid.", + "displayName": "UsExemptTaxId", + "id": "06aac3fb-02c4-49ef-9f4d-c55455eab2e3", + "origin": "Application (Azure Signup Api)", + "value": "UsExemptTaxId" + }, + { + "description": "Access Azure SQL DB and Data Warehouse from the application", + "displayName": "Access Azure SQL DB and Data Warehouse", + "id": "efe4d732-bfbb-4617-8a77-349a9d67c720", + "origin": "Application (Azure SQL Database)", + "value": "app_impersonation" + }, + { + "description": "Allows the app to list Acronym and to read their properties on behalf of the signed-in user. ", + "displayName": "Read all Acronyms", + "id": "92bacdd9-8c69-46f7-a004-387210ecd2eb", + "origin": "Delegated (Bing)", + "value": "Acronym.Read.All" + }, + { + "description": "Access Azure SQL DB and Data Warehouse", + "displayName": "Access Azure SQL DB and Data Warehouse", + "id": "c39ef2d1-04ce-46dc-8b5f-e9a5c60f0fc9", + "origin": "Delegated (Azure SQL Database)", + "value": "user_impersonation" + }, + { + "description": "Allow the application to access Azure Storage on behalf of the signed-in user.", + "displayName": "Access Azure Storage", + "id": "03e0da56-190b-40ad-a80c-ea378c433f7f", + "origin": "Delegated (Azure Storage)", + "value": "user_impersonation" + }, + { + "description": "Allow the application full access to the Azure Time Series Insights service on behalf of the signed-in user.", + "displayName": "Access Azure Time Series Insights service", + "id": "a3a77dfe-67a4-4373-b02a-dfe8485e2248", + "origin": "Delegated (Azure Time Series Insights)", + "value": "user_impersonation" + }, + { + "description": "Allows an application to invoke any operation across the provisioning API.", + "displayName": "ProvisioningAPI.Admin", + "id": "de5aee63-7b89-495b-879a-0c5d6462594d", + "origin": "Application (AzureCommunicationsGateway)", + "value": "ProvisioningAPI.Admin" + }, + { + "description": "Allows a user to invoke any operation across the provisioning API.", + "displayName": "ProvisioningAPI.AdminUser", + "id": "0bafd649-9eef-438f-ad0c-05606fedf8b0", + "origin": "Application (AzureCommunicationsGateway)", + "value": "ProvisioningAPI.AdminUser" + }, + { + "description": "Allows an application to invoke any delete (DELETE) operation across the provisioning API.", + "displayName": "ProvisioningAPI.Delete", + "id": "1a692cf6-98d5-41e5-a04b-9f774d805956", + "origin": "Application (AzureCommunicationsGateway)", + "value": "ProvisioningAPI.Delete" + }, + { + "description": "Allows a user to invoke any delete (DELETE) operation across the provisioning API.", + "displayName": "ProvisioningAPI.DeleteUser", + "id": "6c693d49-fa6e-44ed-a113-c12ce08e2bf3", + "origin": "Application (AzureCommunicationsGateway)", + "value": "ProvisioningAPI.DeleteUser" + }, + { + "description": "Allows an application to invoke any read (GET) operation across the provisioning API.", + "displayName": "ProvisioningAPI.Read", + "id": "ace5c110-8cd1-464a-9058-393fe5cde5ff", + "origin": "Application (AzureCommunicationsGateway)", + "value": "ProvisioningAPI.Read" + }, + { + "description": "Allows a user to invoke any read (GET) operation across the provisioning API.", + "displayName": "ProvisioningAPI.ReadUser", + "id": "a5550f6e-7cd5-4f65-9916-fd0326cde7e9", + "origin": "Application (AzureCommunicationsGateway)", + "value": "ProvisioningAPI.ReadUser" + }, + { + "description": "Allows the application to create conversation threads and reply on existing threads for the SRE agents that user has access to", + "displayName": "Create conversation threads with SRE agents and reply on existing conversation threads", + "id": "c41153e1-cb8a-4a26-ac7e-e6457e0716cf", + "origin": "Delegated (Azure SRE Agent)", + "value": "Threads.ReadWrite.All" + }, + { + "description": "Allows the app to manage restricted resources based on the other permissions granted to the app, on behalf of the signed-in user.", + "displayName": "Manage restricted resources in the directory", + "id": "cba5390f-ed6a-4b7f-b657-0efc2210ed20", + "origin": "Delegated", + "value": "Directory.Write.Restricted" + }, + { + "description": "Allows the app to create, read, update and delete internal federation configuration for a domain.", + "displayName": "Create, read, update and delete internal federation configuration for a domain.", + "id": "64d40371-8d58-4270-bc8a-b4a66de36b9a", + "origin": "Application (Microsoft Graph)", + "value": "Domain-InternalFederation.ReadWrite.All" }, { "description": "Allows the app to read and write eDiscovery objects such as cases, custodians, review sets and other related objects without a signed-in user.", "displayName": "Read and write all eDiscovery objects", "id": "b2620db1-3bf7-4c5b-9cb9-576d29eac736", - "origin": "Application", + "origin": "Application (Microsoft Graph)", "value": "eDiscovery.ReadWrite.All" }, { - "description": "Allows the app to read eDiscovery objects such as cases, custodians, review sets and other related objects without a signed-in user.", - "displayName": "Read all eDiscovery objects", - "id": "50180013-6191-4d1e-a373-e590ff4e66af", - "origin": "Application", - "value": "eDiscovery.Read.All" + "description": "Allows the app to read a basic set of profile properties of other users in your organization without a signed-in user. Includes display name, first and last name, email address, open extensions, and photo.", + "displayName": "Read all users' basic profiles", + "id": "97235f07-e226-4f63-ace3-39588e11d3a1", + "origin": "Application (Microsoft Graph)", + "value": "User.ReadBasic.All" + }, + { + "description": "Allows the app to read and update users, without a signed-in user.", + "displayName": "Read and update users", + "id": "5639c449-cfd9-4088-bc48-3e16da108bf8", + "origin": "Application (Microsoft Graph)", + "value": "User.ReadUpdate.All" + }, + { + "description": "Allows the app to read and update external cloud user profiles without a signed in user.", + "displayName": "Read and write profiles of users that originate from an external cloud.", + "id": "5652f862-b626-407b-a3e6-248aeb95763c", + "origin": "Application (Microsoft Graph)", + "value": "User.ReadWrite.CrossCloud" + }, + { + "description": "Allow the app to revoke all sign in sessions for a user, without a signed-in user.", + "displayName": "Revoke all sign in sessions for a user", + "id": "77f3a031-c388-4f99-b373-dc68676a979e", + "origin": "Application (Microsoft Graph)", + "value": "User.RevokeSessions.All" + }, + { + "description": "Allows the app to delete authentication methods of all users in your organization, without a signed-in user. Authentication methods include things like a user's phone numbers and Authenticator app settings. This does not allow the app to read, create, or modify authentication methods.", + "displayName": "Delete all users' authentication methods", + "id": "712f5e0d-bc8d-4ae5-8242-cfb9a4921ed3", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthenticationMethod.Delete.All" + }, + { + "description": "Allows the app to read authentication methods of all users in your organization, without a signed-in user. Authentication methods include things like a user’s phone numbers and Authenticator app settings. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' authentication methods", + "id": "38d9df27-64da-44fd-b7c5-a6fbac20248f", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthenticationMethod.Read.All" + }, + { + "description": "Allows the application to read and write authentication methods of all users in your organization, without a signed-in user. Authentication methods include things like a user's phone numbers and Authenticator app settings. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods", + "displayName": "Read and write all users' authentication methods ", + "id": "50483e42-d915-4231-9639-7fdb7fd190e5", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthenticationMethod.ReadWrite.All" + }, + { + "description": "Allows the application to delete email methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify email methods.", + "displayName": "Delete all users' email methods", + "id": "f0e9adfd-ed6b-45f5-b969-324a75286a39", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-Email.Delete.All" + }, + { + "description": "Allows the app to read email methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' email methods", + "id": "a1e58be0-1095-422b-b067-73434bd7d40f", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-Email.Read.All" + }, + { + "description": "Allows the application to read and write email methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' email methods", + "id": "e8ecb853-1435-4a49-95ba-ec5b31b11672", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-Email.ReadWrite.All" + }, + { + "description": "Allows the application to delete external authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify external authentication methods.", + "displayName": "Delete all users' external authentication methods", + "id": "7fa6d39e-1e4e-44be-bf9c-e8260b12e1f5", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-External.Delete.All" + }, + { + "description": "Allows the app to read external authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' external authentication methods", + "id": "d2c4289f-9f95-40da-ad43-eeb1506f0db7", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-External.Read.All" + }, + { + "description": "Allows the application to read and write external authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' external authentication methods", + "id": "c7a22c2e-5b01-4129-8159-6c8be2c78f16", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-External.ReadWrite.All" + }, + { + "description": "Allows the application to delete HardwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify HardwareOATH authentication methods.", + "displayName": "Delete all users' HardwareOATH authentication methods", + "id": "9d8eb432-7ea3-491a-9ed7-e6361b308f08", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-HardwareOATH.Delete.All" + }, + { + "description": "Allows the app to read HardwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' HardwareOATH authentication methods", + "id": "7b544555-7811-49ff-8223-a56be870e33a", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-HardwareOATH.Read.All" + }, + { + "description": "Allows the application to read and write HardwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' HardwareOATH authentication methods", + "id": "7e9ebcc1-90aa-4471-8051-e68d6b4e9c89", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-HardwareOATH.ReadWrite.All" + }, + { + "description": "Allows the application to delete Microsoft Authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify Microsoft Authentication methods.", + "displayName": "Delete all users' Microsoft Authentication methods", + "id": "ae494ca6-9612-417a-972a-ef52efaf2de3", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-MicrosoftAuthApp.Delete.All" + }, + { + "description": "Allows the app to read, update and delete identities that are associated with a user's account, without a signed in user. This controls the identities users can sign-in with.", + "displayName": "Manage all users' identities", + "id": "c529cfca-c91b-489c-af2b-d92990b66ce6", + "origin": "Application (Microsoft Graph)", + "value": "User.ManageIdentities.All" + }, + { + "description": "Allows the application to list and read all Tenant Governance requests without a signed-in user.", + "displayName": "Read Tenant Governance requests", + "id": "294294d5-2b81-4cf1-837c-28fc22bc3290", + "origin": "Application (Microsoft Graph)", + "value": "TenantGovernance-Request.Read.All" + }, + { + "description": "Allows the application to read Tenant Governance settings without a signed-in user.", + "displayName": "Read Tenant Governance settings", + "id": "e2d1cac5-0317-4ae3-aca9-59737eb75317", + "origin": "Application (Microsoft Graph)", + "value": "TenantGovernance-Setting.Read.All" + }, + { + "description": "Allows the app to read all term store data, without a signed-in user. This includes all sets, groups and terms in the term store.", + "displayName": "Read all term store data", + "id": "ea047cc2-df29-4f3e-83a3-205de61501ca", + "origin": "Application (Microsoft Graph)", + "value": "TermStore.Read.All" + }, + { + "description": "Allows the app to read, edit or write all term store data, without a signed-in user. This includes all sets, groups and terms in the term store.", + "displayName": "Read and write all term store data", + "id": "f12eb8d6-28e3-46e6-b2c0-b7e4dc69fc95", + "origin": "Application (Microsoft Graph)", + "value": "TermStore.ReadWrite.All" + }, + { + "description": "Allows an app to read your organization's threat assessment requests, without a signed-in user.", + "displayName": "Read threat assessment requests", + "id": "f8f035bb-2cce-47fb-8bf5-7baf3ecbee48", + "origin": "Application (Microsoft Graph)", + "value": "ThreatAssessment.Read.All" }, { "description": "Allows the app to run hunting queries, without a signed-in user.", "displayName": "Run hunting queries", "id": "dd98c7f5-2d42-42d3-a0e4-633161547251", - "origin": "Application", + "origin": "Application (Microsoft Graph)", "value": "ThreatHunting.Read.All" }, { - "description": "Allow the app to read the management data for Teams devices, without a signed-in user.", - "displayName": "Read Teams devices", - "id": "0591bafd-7c1c-4c30-a2a5-2b9aacb1dfe8", - "origin": "Application", - "value": "TeamworkDevice.Read.All" + "description": "Allows the app to read all the indicators for your organization, without a signed-in user.", + "displayName": "Read all threat indicators", + "id": "197ee4e9-b993-4066-898f-d6aecc55125b", + "origin": "Application (Microsoft Graph)", + "value": "ThreatIndicators.Read.All" }, { - "description": "Allow the app to read and write the management data for Teams devices, without a signed-in user.", - "displayName": "Read and write Teams devices", - "id": "79c02f5b-bd4f-4713-bc2c-a8a4a66e127b", - "origin": "Application", - "value": "TeamworkDevice.ReadWrite.All" + "description": "Allows the app to create threat indicators, and fully manage those threat indicators (read, update and delete), without a signed-in user. It cannot update any threat indicators it does not own.", + "displayName": "Manage threat indicators this app creates or owns", + "id": "21792b6c-c986-4ffc-85de-df9da54b52fa", + "origin": "Application (Microsoft Graph)", + "value": "ThreatIndicators.ReadWrite.OwnedBy" }, { - "description": "Allows the app to read and update identity risky service principal for your organization, without a signed-in user.", - "displayName": "Read and write all identity risky service principal information", - "id": "cb8d6980-6bcb-4507-afec-ed6de3a2d798", - "origin": "Application", - "value": "IdentityRiskyServicePrincipal.ReadWrite.All" + "description": "Allows the app to read threat intelligence information, such as indicators, observations, and and articles, without a signed in user.", + "displayName": "Read all Threat Intelligence Information", + "id": "e0b77adb-e790-44a3-b0a0-257d06303687", + "origin": "Application (Microsoft Graph)", + "value": "ThreatIntelligence.Read.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for any user, without a signed-in user.", - "displayName": "Allow the Teams app to manage only its own tabs for all users", - "id": "3c42dec6-49e8-4a0a-b469-36cff0d9da93", - "origin": "Application", - "value": "TeamsTab.ReadWriteSelfForUser.All" + "description": "Allows the app to read your organization's threat submissions and to view threat submission policies without a signed-in user.", + "displayName": "Read all of the organization's threat submissions", + "id": "86632667-cd15-4845-ad89-48a88e8412e1", + "origin": "Application (Microsoft Graph)", + "value": "ThreatSubmission.Read.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs in any team, without a signed-in user.", - "displayName": "Allow the Teams app to manage only its own tabs for all teams", - "id": "91c32b81-0ef0-453f-a5c7-4ce2e562f449", - "origin": "Application", - "value": "TeamsTab.ReadWriteSelfForTeam.All" + "description": "Allows the app to read your organization's threat submissions and threat submission policies without a signed-in user. Also allows the app to create new threat submissions without a signed-in user.", + "displayName": "Read and write all of the organization's threat submissions", + "id": "d72bdbf4-a59b-405c-8b04-5995895819ac", + "origin": "Application (Microsoft Graph)", + "value": "ThreatSubmission.ReadWrite.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for any chat, without a signed-in user.", - "displayName": "Allow the Teams app to manage only its own tabs for all chats", - "id": "9f62e4a2-a2d6-4350-b28b-d244728c4f86", - "origin": "Application", - "value": "TeamsTab.ReadWriteSelfForChat.All" + "description": "Allows the app to read your organization's threat submission policies without a signed-in user. Also allows the app to create new threat submission policies without a signed-in user.", + "displayName": "Read and write all of the organization's threat submission policies", + "id": "926a6798-b100-4a20-a22f-a4918f13951d", + "origin": "Application (Microsoft Graph)", + "value": "ThreatSubmissionPolicy.ReadWrite.All" + }, + { + "description": "Allows the app to read trust framework key set properties without a signed-in user.", + "displayName": "Read trust framework key sets", + "id": "fff194f1-7dce-4428-8301-1badb5518201", + "origin": "Application (Microsoft Graph)", + "value": "TrustFrameworkKeySet.Read.All" + }, + { + "description": "Allows the app to read and write trust framework key set properties without a signed-in user.", + "displayName": "Read and write trust framework key sets", + "id": "4a771c9a-1cf2-4609-b88e-3d3e02d539cd", + "origin": "Application (Microsoft Graph)", + "value": "TrustFrameworkKeySet.ReadWrite.All" + }, + { + "description": "Allows the app to create users, without a signed-in user.", + "displayName": "Create users", + "id": "4240f680-4f73-4082-a766-aa916a2dc9b3", + "origin": "Application (Microsoft Graph)", + "value": "User.Create" + }, + { + "description": "Allows the app to delete and restore all users, without a signed-in user.", + "displayName": "Delete and restore all users", + "id": "eccc023d-eccf-4e7b-9683-8813ab36cecc", + "origin": "Application (Microsoft Graph)", + "value": "User.DeleteRestore.All" + }, + { + "description": "Allows the app to enable and disable users' accounts, without a signed-in user.", + "displayName": "Enable and disable user accounts", + "id": "3011c876-62b7-4ada-afa2-506cbbecc68c", + "origin": "Application (Microsoft Graph)", + "value": "User.EnableDisableAccount.All" + }, + { + "description": "Allows the app to invite guest users to the organization, without a signed-in user.", + "displayName": "Invite guest users to the organization", + "id": "09850681-111b-4a89-9bed-3f2cae46d706", + "origin": "Application (Microsoft Graph)", + "value": "User.Invite.All" + }, + { + "description": "Allows the app to read Microsoft authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' Microsoft authentication methods", + "id": "a9c5f16e-e5ca-4e33-89ad-903fcfc01c23", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-MicrosoftAuthApp.Read.All" + }, + { + "description": "Allows the application to read and write Microsoft Authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' Microsoft Authentication methods", + "id": "c833c349-a1ab-4b6d-94a2-fa9a8674420c", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-MicrosoftAuthApp.ReadWrite.All" + }, + { + "description": "Allows the application to delete passkey authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify passkey authentication methods.", + "displayName": "Delete all users' passkey authentication methods", + "id": "9563fbd0-03a7-466e-8042-63d668b7d1a3", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-Passkey.Delete.All" + }, + { + "description": "Allows the application to delete Windows Hello authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify Windows Hello authentication methods.", + "displayName": "Delete all users' Windows Hello authentication methods", + "id": "f3197110-aa7f-4acd-a0fd-71981ad68d42", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-WindowsHello.Delete.All" + }, + { + "description": "Allows the app to read Windows Hello authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' Windows Hello methods", + "id": "9b8dd4c7-8cca-4ef5-a34a-9c2c75fcc934", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-WindowsHello.Read.All" }, { - "description": "Allows the app to read all risky service principal information for your organization, without a signed-in user.", - "displayName": "Read all identity risky service principal information", - "id": "607c7344-0eed-41e5-823a-9695ebe1b7b0", - "origin": "Application", - "value": "IdentityRiskyServicePrincipal.Read.All" + "description": "Allows the application to read and write Windows Hello authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' Windows Hello authentication methods", + "id": "f14eee8a-713e-45aa-8223-2ab74632db1a", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-WindowsHello.ReadWrite.All" }, { - "description": "Allows the app to read and write search configurations, without a signed-in user.", - "displayName": "Read and write your organization's search configuration", - "id": "0e778b85-fefa-466d-9eec-750569d92122", - "origin": "Application", - "value": "SearchConfiguration.ReadWrite.All" + "description": "Allow the app to convert an external user to an internal member user, without a signed-in user.", + "displayName": "Convert an external user to internal member user", + "id": "9d952b72-f741-4b40-9185-8c53076c2339", + "origin": "Application (Microsoft Graph)", + "value": "User-ConvertToInternal.ReadWrite.All" }, { - "description": "Allows the app to read search configurations, without a signed-in user.", - "displayName": "Read your organization's search configuration", - "id": "ada977a5-b8b1-493b-9a91-66c206d76ecf", - "origin": "Application", - "value": "SearchConfiguration.Read.All" + "description": "Allows the app to read the lifecycle information like employeeLeaveDateTime of users in your organization, without a signed-in user.", + "displayName": "Read all users' lifecycle information", + "id": "8556a004-db57-4d7a-8b82-97a13428e96f", + "origin": "Application (Microsoft Graph)", + "value": "User-LifeCycleInfo.Read.All" }, { - "description": "Allows the app to read online meeting artifacts in your organization, without a signed-in user.", - "displayName": "Read online meeting artifacts", - "id": "df01ed3b-eb61-4eca-9965-6b3d789751b2", - "origin": "Application", - "value": "OnlineMeetingArtifact.Read.All" + "description": "Allows the app to read and write the lifecycle information like employeeLeaveDateTime of users in your organization, without a signed-in user.", + "displayName": "Read and write all users' lifecycle information", + "id": "925f1248-0f97-47b9-8ec8-538c54e01325", + "origin": "Application (Microsoft Graph)", + "value": "User-LifeCycleInfo.ReadWrite.All" }, { - "description": "Allows the app to create, read, update, and delete apps in the app catalogs without a signed-in user.", - "displayName": "Read and write to all app catalogs", - "id": "dc149144-f292-421e-b185-5953f2e98d7f", - "origin": "Application", - "value": "AppCatalog.ReadWrite.All" + "description": "Allows the app to read and write secondary mail addresses for all users, without a signed-in user.", + "displayName": "Read and write all secondary mail addresses for users", + "id": "280d0935-0796-47d1-8d26-273470a3f17a", + "origin": "Application (Microsoft Graph)", + "value": "User-Mail.ReadWrite.All" }, { - "description": "Allows the app to read apps in the app catalogs without a signed-in user.", - "displayName": "Read all app catalogs", - "id": "e12dae10-5a57-4817-b79d-dfbec5348930", - "origin": "Application", - "value": "AppCatalog.Read.All" + "description": "Allows the app to send, read, update and delete user’s notifications, without a signed-in user.", + "displayName": "Deliver and manage all user's notifications", + "id": "4e774092-a092-48d1-90bd-baad67c7eb47", + "origin": "Application (Microsoft Graph)", + "value": "UserNotification.ReadWrite.CreatedByApp" }, { - "description": "Allows the app to manage workforce integrations to synchronize data from Microsoft Teams Shifts, without a signed-in user.", - "displayName": "Read and write workforce integrations", - "id": "202bf709-e8e6-478e-bcfd-5d63c50b68e3", - "origin": "Application", - "value": "WorkforceIntegration.ReadWrite.All" + "description": "Allows the app to update the on-premises sync behavior of all users without a signed-in user.", + "displayName": "Read and update the on-premises sync behavior of users", + "id": "a94a502d-0281-4d15-8cd2-682ac9362c4c", + "origin": "Application (Microsoft Graph)", + "value": "User-OnPremisesSyncBehavior.ReadWrite.All" }, { - "description": "Allows the app to read all presence information and write activity and availability of all users in the directory without a signed-in user. Presence information includes activity, availability, status note, calendar out-of-office message, time zone and location.", - "displayName": "Read and write presence information for all users", - "id": "83cded22-8297-4ff6-a7fa-e97e9545a259", - "origin": "Application", - "value": "Presence.ReadWrite.All" + "description": "Allows the app to read and write password profiles and reset passwords for all users, without a signed-in user.", + "displayName": "Read and write all password profiles and reset user passwords", + "id": "cc117bb9-00cf-4eb8-b580-ea2a878fe8f7", + "origin": "Application (Microsoft Graph)", + "value": "User-PasswordProfile.ReadWrite.All" }, { - "description": "Allows the app to read and write tags in Teams without a signed-in user.", - "displayName": "Read and write tags in Teams", - "id": "a3371ca5-911d-46d6-901c-42c8c7a937d8", - "origin": "Application", - "value": "TeamworkTag.ReadWrite.All" + "description": "Allows the app to read and write the mobile phone and business phones for all users, without a signed-in user.", + "displayName": "Read and write all user mobile phone and business phones", + "id": "86ceff06-c822-49ff-989a-d912845ffe69", + "origin": "Application (Microsoft Graph)", + "value": "User-Phone.ReadWrite.All" }, { - "description": "Allows the app to read\u00a0tags in Teams\u00a0without a signed-in user.", - "displayName": "Read tags in Teams", - "id": "b74fd6c4-4bde-488e-9695-eeb100e4907f", - "origin": "Application", - "value": "TeamworkTag.Read.All" + "description": "Allows the app to read all users' shift schedule preferences without a signed-in user.", + "displayName": "Read all user shift preferences", + "id": "de023814-96df-4f53-9376-1e2891ef5a18", + "origin": "Application (Microsoft Graph)", + "value": "UserShiftPreferences.Read.All" }, { - "description": "Allows the app to read and write all Windows update deployment settings for the organization without a signed-in user.", - "displayName": "Read and write all Windows update deployment settings", - "id": "7dd1be58-6e76-4401-bf8d-31d1e8180d5b", - "origin": "Application", - "value": "WindowsUpdates.ReadWrite.All" + "description": "Allows the app to manage all users' shift schedule preferences without a signed-in user.", + "displayName": "Read and write all user shift preferences", + "id": "d1eec298-80f3-49b0-9efb-d90e224798ac", + "origin": "Application (Microsoft Graph)", + "value": "UserShiftPreferences.ReadWrite.All" }, { - "description": "Allows the app to read and write external connections without a signed-in user. The app can only read and write external connections that it is authorized to, or it can create new external connections. ", - "displayName": "Read and write external connections", - "id": "f431331c-49a6-499f-be1c-62af19c34a9d", - "origin": "Application", - "value": "ExternalConnection.ReadWrite.OwnedBy" + "description": "Allows the app to read all user teamwork settings without a signed-in user.", + "displayName": "Read all user teamwork settings", + "id": "fbcd7ef1-df0d-4e05-bb28-93424a89c6df", + "origin": "Application (Microsoft Graph)", + "value": "UserTeamwork.Read.All" }, { - "description": "Allows the app to read and write external items without a signed-in user. The app can only read external items of the connection that it is authorized to.", - "displayName": "Read and write external items", - "id": "8116ae0f-55c2-452d-9944-d18420f5b2c8", - "origin": "Application", - "value": "ExternalItem.ReadWrite.OwnedBy" + "description": "This role can read Verified Id profiles in a tenant.", + "displayName": "Read Verified Id profiles", + "id": "e227c591-dd64-4a8a-a033-816167f7c938", + "origin": "Application (Microsoft Graph)", + "value": "VerifiedId-Profile.Read.All" }, { - "description": "Allow the application to access a subset of site collections without a signed in user.\u00a0\u00a0The specific site collections and the permissions granted will be configured in SharePoint Online.", - "displayName": "Access selected site collections", - "id": "883ea226-0bf2-4a8f-9f9d-92c9162a727d", - "origin": "Application", - "value": "Sites.Selected" + "description": "Allows the application to read virtual appointments for all users, without a signed-in user. The app must also be authorized to access an individual user’s data by the online meetings application access policy.", + "displayName": "Read all virtual appointments for users, as authorized by online meetings application access policy", + "id": "d4f67ec2-59b5-4bdc-b4af-d78f6f9c1954", + "origin": "Application (Microsoft Graph)", + "value": "VirtualAppointment.Read.All" }, { - "description": "Allows the app to read documents and list items in all site collections without a signed in user.", - "displayName": "Read items in all site collections ", - "id": "332a536c-c7ef-4017-ab91-336970924f0d", - "origin": "Application", - "value": "Sites.Read.All" + "description": "Allows the application to read and write virtual appointments for all users, without a signed-in user. The app must also be authorized to access an individual user’s data by the online meetings application access policy.", + "displayName": "Read-write all virtual appointments for users, as authorized by online meetings app access policy", + "id": "bf46a256-f47d-448f-ab78-f226fff08d40", + "origin": "Application (Microsoft Graph)", + "value": "VirtualAppointment.ReadWrite.All" }, { - "description": "Allows the app to create, read, update, and delete documents and list items in all site collections without a signed in user.", - "displayName": "Read and write items in all site collections", - "id": "9492366f-7969-46a4-8d15-ed1a20078fff", - "origin": "Application", - "value": "Sites.ReadWrite.All" + "description": "Allows the application to read and write Temporary Access Pass authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' Temporary Access Pass methods", + "id": "627169a8-8c15-451c-861a-5b80e383de5c", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-TAP.ReadWrite.All" }, { - "description": "Allows the app to read and write the properties of Cloud PCs, without a signed-in user.", - "displayName": "Read and write Cloud PCs", - "id": "3b4349e1-8cf5-45a3-95b7-69d1751d3e6a", - "origin": "Application", - "value": "CloudPC.ReadWrite.All" + "description": "Allows the app to read Temporary Access Pass authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' Temporary Access Pass methods", + "id": "bf82209c-b22b-4747-ac88-a68be99032cf", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-TAP.Read.All" }, { - "description": "Allows the app to read the properties of Cloud PCs, without a signed-in user.", - "displayName": "Read Cloud PCs", - "id": "a9e09520-8ed4-4cde-838e-4fdea192c227", - "origin": "Application", - "value": "CloudPC.Read.All" + "description": "Allows the application to delete Temporary Access Pass authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify Temporary Access Pass authentication methods.", + "displayName": "Delete all users' Temporary Access Pass authentication methods", + "id": "4f872e9d-d232-4ecd-ab9c-337cbdb184e5", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-TAP.Delete.All" }, { - "description": "Allows the app to update service principal endpoints", - "displayName": "Read and update service principal endpoints", - "id": "89c8469c-83ad-45f7-8ff2-6e3d4285709e", - "origin": "Application", - "value": "ServicePrincipalEndpoint.ReadWrite.All" + "description": "Allows the application to read and write SoftwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' SoftwareOATH methods", + "id": "787442d4-3c6e-4e99-aa95-8ccca20a48ff", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-SoftwareOATH.ReadWrite.All" }, { - "description": "Allows the app to read service principal endpoints", - "displayName": "Read service principal endpoints", - "id": "5256681e-b7f6-40c0-8447-2d9db68797a0", - "origin": "Application", - "value": "ServicePrincipalEndpoint.Read.All" + "description": "Allows the app to read passkey authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' passkey authentication methods", + "id": "72e00c1d-3e3d-43bb-a0b9-c435611bb1d2", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-Passkey.Read.All" }, { - "description": "Allows the app to create new notifications in users' teamwork activity feeds without a signed in user. These notifications may not be discoverable or be held or governed by compliance policies.", - "displayName": "Send a teamwork activity to any user", - "id": "a267235f-af13-44dc-8385-c1dc93023186", - "origin": "Application", - "value": "TeamsActivity.Send" + "description": "Allows the application to read and write passkey authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods", + "displayName": "Read and write all users' passkey authentication methods", + "id": "0400e371-7db1-4338-a269-96069eb65227", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-Passkey.ReadWrite.All" }, { - "description": "Allows the app to read terms of use acceptance statuses, without a signed in user.", - "displayName": "Read all terms of use acceptance statuses", - "id": "d8e4ec18-f6c0-4620-8122-c8b1f2bf400e", - "origin": "Application", - "value": "AgreementAcceptance.Read.All" + "description": "Allows the app to read password authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' password authentication methods", + "id": "8d2c17ff-b93d-40d5-9def-d843680509cb", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-Password.Read.All" }, { - "description": "Allows the app to read and write terms of use agreements, without a signed in user.", - "displayName": "Read and write all terms of use agreements", - "id": "c9090d00-6101-42f0-a729-c41074260d47", - "origin": "Application", - "value": "Agreement.ReadWrite.All" + "description": "Allows the application to read and write password authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' password authentication methods", + "id": "f6d38dfd-ec08-4995-8f07-23e929df0936", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-Password.ReadWrite.All" }, { - "description": "Allows the app to read terms of use agreements, without a signed in user.", - "displayName": "Read all terms of use agreements", - "id": "2f3e6f8c-093b-4c57-a58b-ba5ce494a169", - "origin": "Application", - "value": "Agreement.Read.All" + "description": "Allows the application to delete phone methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify phone methods.", + "displayName": "Delete all users' phone methods", + "id": "59f17651-8b6c-494e-a269-4ac582fbbca0", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-Phone.Delete.All" }, { - "description": "Allows the app to read app consent requests and approvals, and deny or approve those requests without a signed-in user.", - "displayName": "Read and write all consent requests", - "id": "9f1b81a7-0223-4428-bfa4-0bcb5535f27d", - "origin": "Application", - "value": "ConsentRequest.ReadWrite.All" + "description": "Allows the app to read phone authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' phone authentication methods", + "id": "f529a223-ea70-43ec-b268-5012de2fbaa2", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-Phone.Read.All" }, { - "description": "Allows the app to read and write your organization's consent requests policy without a signed-in user.", - "displayName": "Read and write your organization's consent request policy", - "id": "999f8c63-0a38-4f1b-91fd-ed1947bdd1a9", - "origin": "Application", - "value": "Policy.ReadWrite.ConsentRequest" + "description": "Allows the application to read and write phone methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' phone methods", + "id": "6e85d483-7092-4375-babe-0a94a8213a58", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-Phone.ReadWrite.All" }, { - "description": "Allows the app to read consent requests and approvals without a signed-in user.", - "displayName": "Read all consent requests", - "id": "1260ad83-98fb-4785-abbb-d6cc1806fd41", - "origin": "Application", - "value": "ConsentRequest.Read.All" + "description": "Allows the application to delete platform credentials methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify platform credentials methods.", + "displayName": "Delete all users' platform credentials methods", + "id": "bd760918-651f-4e67-b66f-8f614384dec2", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-PlatformCred.Delete.All" }, { - "description": "Allows the app to read basic mail properties in all mailboxes without a signed-in user. Includes all properties except body, previewBody, attachments and any extended properties.", - "displayName": "Read basic mail in all mailboxes", - "id": "693c5e45-0940-467d-9b8a-1022fb9d42ef", - "origin": "Application", - "value": "Mail.ReadBasic.All" + "description": "Allows the application to list and read all Tenant Governance relationships without a signed-in user.", + "displayName": "Read Tenant Governance relationships", + "id": "41c250d0-8793-44e1-a130-5fdbd5bccd0a", + "origin": "Application (Microsoft Graph)", + "value": "TenantGovernance-Relationship.Read.All" }, { - "description": "Allows the app to read basic mail properties in all mailboxes without a signed-in user. Includes all properties except body, previewBody, attachments and any extended properties.", - "displayName": "Read basic mail in all mailboxes", - "id": "6be147d2-ea4f-4b5a-a3fa-3eab6f3c140a", - "origin": "Application", - "value": "Mail.ReadBasic" + "description": "Allows the app to read platform credentials methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' platform credentials methods", + "id": "07c0b1e4-15bd-442f-834b-30f8291388d1", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-PlatformCred.Read.All" }, { - "description": "Allows the app to read and write feature rollout policies without a signed-in user. Includes abilities to assign and remove users and groups to rollout of a specific feature.", - "displayName": "Read and write feature rollout policies", - "id": "2044e4f1-e56c-435b-925c-44cd8f6ba89a", - "origin": "Application", - "value": "Policy.ReadWrite.FeatureRollout" + "description": "Allows the application to delete QR authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify QR authentication methods.", + "displayName": "Delete all users' QR authentication methods", + "id": "e1c34213-26ac-400b-9548-a749f1b1a4e0", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-QR.Delete.All" }, { - "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your company's directory, without a signed-in user. This includes instantiating directory roles and managing directory role membership, and reading directory role templates, directory roles and memberships.", - "displayName": "Read and write all directory RBAC settings", - "id": "9e3f62cf-ca93-4989-b6ce-bf83c28f9fe8", - "origin": "Application", - "value": "RoleManagement.ReadWrite.Directory" + "description": "Allows the app to read QR authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' QR methods", + "id": "9a45bc50-cddd-4ebe-bd9c-4f2eacf646ae", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-QR.Read.All" }, { - "description": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, without a signed-in user. This includes reading directory role templates, directory roles and memberships.", - "displayName": "Read all directory RBAC settings", - "id": "483bed4a-2ad3-4361-a73b-c83ccdbdc53c", - "origin": "Application", - "value": "RoleManagement.Read.Directory" + "description": "Allows the application to read and write QR authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' QR methods", + "id": "4869299f-18c3-40c8-98f2-222657e67db1", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-QR.ReadWrite.All" }, { - "description": "Allows the app to read and write the organization and related resources, without a signed-in user.\u00a0Related resources include things like subscribed skus and tenant branding information.", - "displayName": "Read and write organization information", - "id": "292d869f-3427-49a8-9dab-8c70152b74e9", - "origin": "Application", - "value": "Organization.ReadWrite.All" + "description": "Allows the application to delete resource key authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify resource key authentication methods.", + "displayName": "Delete all users' resource key authentication methods", + "id": "a71aecaf-82f1-47c5-ad0a-5e63503b928f", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-ResourceKey.Delete.All" }, { - "description": "Allows the app to read the organization and related resources, without a signed-in user.\u00a0Related resources include things like subscribed skus and tenant branding information.", - "displayName": "Read organization information", - "id": "498476ce-e0fe-48b0-b801-37ba7e2685c6", - "origin": "Application", - "value": "Organization.Read.All" + "description": "Allows the app to read the keys associated with the user representing a resource account.", + "displayName": "Read and write all users' external authentication methods", + "id": "94ed018c-a499-47e0-beef-803b93873ece", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-ResourceKey.Read.All" }, { - "description": "Allows the app to read company places (conference rooms and room lists) for calendar events and other applications, without a signed-in user.", - "displayName": "Read all company places", - "id": "913b9306-0ce1-42b8-9137-6a7df690a760", - "origin": "Application", - "value": "Place.Read.All" + "description": "Allows the app to read and delete the keys associated with the user representing a resource account.", + "displayName": "Read and delete all users' external authentication methods", + "id": "1bf7461f-222a-4525-9760-f7739228d0f4", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-ResourceKey.ReadWrite.All" }, { - "description": "Allows the app to read the memberships of hidden groups and administrative units without a signed-in user.", - "displayName": "Read all hidden memberships", - "id": "658aa5d8-239f-45c4-aa12-864f4fc7e490", - "origin": "Application", - "value": "Member.Read.Hidden" + "description": "Allows the application to delete SoftwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify SoftwareOATH authentication methods.", + "displayName": "Delete all users' SoftwareOATH authentication methods", + "id": "e5676e10-1a16-452b-ad10-71f54b755852", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-SoftwareOATH.Delete.All" }, { - "description": "Allow the app to read or write items in all external datasets that the app is authorized to access", - "displayName": "Read and write items in external datasets", - "id": "38c3d6ee-69ee-422f-b954-e17819665354", - "origin": "Application", - "value": "ExternalItem.ReadWrite.All" + "description": "Allows the app to read SoftwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' SoftwareOATH methods", + "id": "a6b423df-a0c8-411d-a809-a4a5985d2939", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-SoftwareOATH.Read.All" }, { - "description": "Allows the app to read, update, delete and perform actions on access reviews, reviewers, decisions and settings in the organization for group and app memberships, without a signed-in user.", - "displayName": "Manage access reviews for group and app memberships", - "id": "18228521-a591-40f1-b215-5fad4488c117", - "origin": "Application", - "value": "AccessReview.ReadWrite.Membership" + "description": "Allows the application to read and write platform credentials methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' platform credentials methods", + "id": "1a87acf4-a9ca-4576-a974-452ea265d5f6", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-PlatformCred.ReadWrite.All" }, { - "description": "Allows the app to read properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups, without a signed-in user.", - "displayName": "Read Microsoft Intune device configuration and policies", - "id": "dc377aa6-52d8-4e23-b271-2a7ae04cedf3", - "origin": "Application", - "value": "DeviceManagementConfiguration.Read.All" + "description": "Allows the application to send notification regarding virtual appointments as any user, without a signed-in user. The app must also be authorized to access an individual user's data by the online meetings application access policy.", + "displayName": "Send notification regarding virtual appointments as any user", + "id": "97e45b36-1250-48e4-bd70-2df6dab7e94a", + "origin": "Application (Microsoft Graph)", + "value": "VirtualAppointmentNotification.Send" }, { - "description": "Allows the app to read the properties, group assignments and status of apps, app configurations and app protection policies managed by Microsoft Intune, without a signed-in user.", - "displayName": "Read Microsoft Intune apps", - "id": "7a6ee1e7-141e-4cec-ae74-d9db155731ff", - "origin": "Application", - "value": "DeviceManagementApps.Read.All" + "description": "Allows the application to list and read related tenants information without a signed-in user.", + "displayName": "Read related tenants", + "id": "7ced9a83-8e7c-46df-b3e0-6b45a6ecedcd", + "origin": "Application (Microsoft Graph)", + "value": "TenantGovernance-RelatedTenant.Read.All" }, { - "description": "Allows the app to read the properties of devices managed by Microsoft Intune, without a signed-in user.", - "displayName": "Read Microsoft Intune devices", - "id": "2f51be20-0bb4-4fed-bf7b-db946066c75e", - "origin": "Application", - "value": "DeviceManagementManagedDevices.Read.All" + "description": "Allows the application to list and read all Tenant Governance invitations without a signed-in user.", + "displayName": "Read Tenant Governance invitations", + "id": "3f4f98e9-6faf-4e5f-814b-ed2ed8a4ec9e", + "origin": "Application (Microsoft Graph)", + "value": "TenantGovernance-Invitation.Read.All" }, { - "description": "Allows the app to read the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings, without a signed-in user.", - "displayName": "Read Microsoft Intune RBAC settings", - "id": "58ca0d9a-1575-47e1-a3cb-007ef2e4583b", - "origin": "Application", - "value": "DeviceManagementRBAC.Read.All" + "description": "Read the members of all teams, without a signed-in user.", + "displayName": "Read the members of all teams", + "id": "660b7406-55f1-41ca-a0ed-0b035e182f3e", + "origin": "Application (Microsoft Graph)", + "value": "TeamMember.Read.All" }, { - "description": "Allows the app to read Microsoft Intune service properties including device enrollment and third party service connection configuration, without a signed-in user.", - "displayName": "Read Microsoft Intune configuration", - "id": "06a5fe6d-c49d-46a7-b082-56b1b14103c7", - "origin": "Application", - "value": "DeviceManagementServiceConfig.Read.All" + "description": "Add and remove members from all teams, without a signed-in user. Also allows changing a team member's role, for example from owner to non-owner.", + "displayName": "Add and remove members from all teams", + "id": "0121dc95-1b9f-4aed-8bac-58c5ac466691", + "origin": "Application (Microsoft Graph)", + "value": "TeamMember.ReadWrite.All" }, { - "description": "Allows the app to create, view, update and delete on-premises published resources, on-premises agents and agent groups, as part of a hybrid identity configuration, without a signed in user.", - "displayName": "Manage on-premises published resources", - "id": "0b57845e-aa49-4e6f-8109-ce654fffa618", - "origin": "Application", - "value": "OnPremisesPublishingProfiles.ReadWrite.All" + "description": "Add and remove members from all teams, without a signed-in user. Does not allow adding or removing a member with the owner role. Additionally, does not allow the app to elevate an existing member to the owner role.", + "displayName": "Add and remove members with non-owner role for all teams", + "id": "4437522e-9a86-4a41-a7da-e380edd4a97d", + "origin": "Application (Microsoft Graph)", + "value": "TeamMember.ReadWriteNonOwnerRole.All" + }, + { + "description": "Allows the app to read all users' teamwork activity feed, without a signed-in user.", + "displayName": "Read all users' teamwork activity feed", + "id": "70dec828-f620-4914-aa83-a29117306807", + "origin": "Application (Microsoft Graph)", + "value": "TeamsActivity.Read.All" + }, + { + "description": "Allows the app to create new notifications in users' teamwork activity feeds without a signed in user. These notifications may not be discoverable or be held or governed by compliance policies.", + "displayName": "Send a teamwork activity to any user", + "id": "a267235f-af13-44dc-8385-c1dc93023186", + "origin": "Application (Microsoft Graph)", + "value": "TeamsActivity.Send" }, { - "description": "Allows the app to read and write trust framework key set properties without a signed-in user.", - "displayName": "Read and write trust framework key sets", - "id": "4a771c9a-1cf2-4609-b88e-3d3e02d539cd", - "origin": "Application", - "value": "TrustFrameworkKeySet.ReadWrite.All" + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in any chat, without a signed-in user. Gives the ability to manage permission grants for accessing those specific chats' data.", + "displayName": "Manage installation and permission grants of selected Teams apps in all chats", + "id": "22b74aab-d9e4-46f7-9424-f24b42307227", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ManageSelectedForChat.All" }, { - "description": "Allows the app to read trust framework key set properties without a signed-in user.", - "displayName": "Read trust framework key sets", - "id": "fff194f1-7dce-4428-8301-1badb5518201", - "origin": "Application", - "value": "TrustFrameworkKeySet.Read.All" + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in any team, without a signed-in user. Gives the ability to manage permission grants for accessing those specific teams' data.", + "displayName": "Manage installation and permission grants of selected Teams apps in all teams", + "id": "b448d252-1f26-4227-b6ff-21ab510975a2", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ManageSelectedForTeam.All" }, { - "description": "Allows the app to read and write your organization's trust framework policies without a signed in user.", - "displayName": "Read and write your organization's trust framework policies", - "id": "79a677f7-b79d-40d0-a36a-3e6f8688dd7a", - "origin": "Application", - "value": "Policy.ReadWrite.TrustFramework" + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in any user account, without a signed-in user. Gives the ability to manage permission grants for accessing those specific users' data.", + "displayName": "Manage installation and permission grants of selected Teams apps for all user accounts", + "id": "e97a9235-5b3c-43c4-b37d-6786a173fae4", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ManageSelectedForUser.All" }, { - "description": "Allows the app to read all your organization's policies without a signed in user.", - "displayName": "Read your organization's policies", - "id": "246dd0d5-5bd0-4def-940b-0421030a5b68", - "origin": "Application", - "value": "Policy.Read.All" + "description": "Allows the app to read the Teams apps that are installed in any scope, without a signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Read installed Teams apps for all installation scopes", + "id": "0fdf35a5-82f8-41ff-9ded-0b761cc73512", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.Read.All" }, { - "description": "Allows the app to read and write your organization\u2019s identity (authentication) providers\u2019 properties without a signed in user.", - "displayName": "Read and write identity providers", - "id": "90db2b9a-d928-4d33-a4dd-8442ae3d41e4", - "origin": "Application", - "value": "IdentityProvider.ReadWrite.All" + "description": "Allows the app to read the Teams apps that are installed in any chat, without a signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Read installed Teams apps for all chats", + "id": "cc7e7635-2586-41d6-adaa-a8d3bcad5ee5", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadForChat.All" }, { - "description": "Allows the app to read your organization\u2019s identity (authentication) providers\u2019 properties without a signed in user.", - "displayName": "Read identity providers", - "id": "e321f0bb-e7f7-481e-bb28-e3b0b32d4bd0", - "origin": "Application", - "value": "IdentityProvider.Read.All" + "description": "Allows the app to read the Teams apps that are installed in any team, without a signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Read installed Teams apps for all teams", + "id": "1f615aea-6bf9-4b05-84bd-46388e138537", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadForTeam.All" }, { - "description": "Allows the app to create, read, update, and delete administrative units and manage administrative unit membership without a signed-in user.", - "displayName": "Read and write all administrative units", - "id": "5eb59dd3-1da2-4329-8733-9dabdc435916", - "origin": "Application", - "value": "AdministrativeUnit.ReadWrite.All" + "description": "Allows the app to read the Teams apps that are installed for any user, without a signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Read installed Teams apps for all users", + "id": "9ce09611-f4f7-4abd-a629-a05450422a97", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadForUser.All" }, { - "description": "Allows the app to read administrative units and administrative unit membership without a signed-in user.", - "displayName": "Read all administrative units", - "id": "134fd756-38ce-4afd-ba33-e9623dbe66c2", - "origin": "Application", - "value": "AdministrativeUnit.Read.All" + "description": "Allows the app to read the selected Teams apps that are installed in any chat, without a signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Read selected installed Teams apps in all chats", + "id": "53d40ddb-9b27-4c97-b800-985be6041990", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadSelectedForChat.All" }, { - "description": "Allows an app to read published sensitivity labels and label policy settings for the entire organization or a specific user, without a signed in user.", - "displayName": "Read all published labels and label policies for an organization.", - "id": "19da66cb-0fb0-4390-b071-ebc76a349482", - "origin": "Application", - "value": "InformationProtectionPolicy.Read.All" + "description": "Allows the app to read the selected Teams apps that are installed in any team, without a signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Read selected installed Teams apps in all teams", + "id": "93c6a289-70fd-489e-a053-6cf8f7d772f6", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadSelectedForTeam.All" }, { - "description": "Allows the app to read all the OneNote notebooks in your organization, without a signed-in user.", - "displayName": "Read all OneNote notebooks", - "id": "3aeca27b-ee3a-4c2b-8ded-80376e2134a4", - "origin": "Application", - "value": "Notes.Read.All" + "description": "Allows an app to read, install, upgrade, and uninstall selected apps to any user, without a signed-in user.", + "displayName": "Read selected installed Teams apps for all users", + "id": "44fb0e7c-1f9a-47f1-bb9e-7f92d48ed288", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadSelectedForUser.All" }, { - "description": "Allows the app to invite guest users to the organization, without a signed-in user.", - "displayName": "Invite guest users to the organization", - "id": "09850681-111b-4a89-9bed-3f2cae46d706", - "origin": "Application", - "value": "User.Invite.All" + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any chat, without a signed-in user. Gives the ability to manage permission grants for accessing those specific chats' data.", + "displayName": "Manage installation and permission grants of Teams apps for all chats", + "id": "6e74eff9-4a21-45d6-bc03-3a20f61f8281", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentForChat.All" }, { - "description": "Allows the app to read, create, update and delete all files in all site collections without a signed in user. ", - "displayName": "Read and write files in all site collections", - "id": "75359482-378d-4052-8f01-80520e7db3cd", - "origin": "Application", - "value": "Files.ReadWrite.All" + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any team, without a signed-in user. Gives the ability to manage permission grants for accessing those specific teams' data.", + "displayName": "Manage installation and permission grants of Teams apps for all teams", + "id": "b0c13be0-8e20-4bc5-8c55-963c23a39ce9", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentForTeam.All" }, { - "description": "Allows the app to create threat indicators, and fully manage those threat indicators (read, update and delete), without a signed-in user. \u00a0It cannot update any threat indicators it does not own.", - "displayName": "Manage threat indicators this app creates or owns", - "id": "21792b6c-c986-4ffc-85de-df9da54b52fa", - "origin": "Application", - "value": "ThreatIndicators.ReadWrite.OwnedBy" + "description": "Get a list of all teams, without a signed-in user.", + "displayName": "Get a list of all teams", + "id": "2280dda6-0bfd-44ee-a2f4-cb867cfc4c1e", + "origin": "Application (Microsoft Graph)", + "value": "Team.ReadBasic.All" }, { - "description": "Allows the app to read or update security actions, without a signed-in user.", - "displayName": "Read and update your organization's security actions", - "id": "f2bf083f-0179-402a-bedb-b2784de8a49b", - "origin": "Application", - "value": "SecurityActions.ReadWrite.All" + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any user account, without a signed-in user. Gives the ability to manage permission grants for accessing those specific users' data.", + "displayName": "Manage installation and permission grants of Teams apps in a user account", + "id": "32ca478f-f89e-41d0-aaf8-101deb7da510", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentForUser.All" }, { - "description": "Allows the app to read security actions, without a signed-in user.", - "displayName": "Read your organization's security actions", - "id": "5e0edab9-c148-49d0-b423-ac253e121825", - "origin": "Application", - "value": "SecurityActions.Read.All" + "description": "Allows the app to create teams without a signed-in user. ", + "displayName": "Create teams", + "id": "23fc2474-f741-46ce-8465-674744c5c361", + "origin": "Application (Microsoft Graph)", + "value": "Team.Create" }, { - "description": "Allows the app to read your organization\u2019s security events without a signed-in user. Also allows the app to update editable properties in security events.", - "displayName": "Read and update your organization\u2019s security events", - "id": "d903a879-88e0-4c09-b0c9-82f6a1333f84", - "origin": "Application", - "value": "SecurityEvents.ReadWrite.All" + "description": "Allows the app to read all users’ tasks and task lists in your organization, without a signed-in user.", + "displayName": "Read all users’ tasks and tasklist", + "id": "f10e1f91-74ed-437f-a6fd-d6ae88e26c1f", + "origin": "Application (Microsoft Graph)", + "value": "Tasks.Read.All" }, { - "description": "Allows the app to read your organization\u2019s security events without a signed-in user.", - "displayName": "Read your organization\u2019s security events", - "id": "bf394140-e372-4bf9-a898-299cfc7564e5", - "origin": "Application", - "value": "SecurityEvents.Read.All" + "description": "Allows the app to read and write your organization's sign-in identifiers, without a signed-in user.", + "displayName": "Read and write all sign-in identifiers", + "id": "7fc588a2-ea2d-4d1f-bcf7-33c324b149b8", + "origin": "Application (Microsoft Graph)", + "value": "SignInIdentifier.ReadWrite.All" }, { - "description": "Allows an app to read and write all chat messages in Microsoft Teams, without a signed-in user.", - "displayName": "Read and write all chat messages", - "id": "294ce7c9-31ba-490a-ad7d-97a7d075e4ed", - "origin": "Application", - "value": "Chat.ReadWrite.All" + "description": "Allow the application to archive/reactivate site collections without a signed in user.", + "displayName": "Archive/reactivate Site Collections without a signed in user.", + "id": "e3530185-4080-478c-a4ab-39322704df58", + "origin": "Application (Microsoft Graph)", + "value": "Sites.Archive.All" }, { - "description": "Allows the app to read and update identity risk detection information for your organization without a signed-in user. Update operations include confirming risk event detections.\u00a0", - "displayName": "Read and write all risk detection information", - "id": "db06fb33-1953-4b7b-a2ac-f1e2c854f7ae", - "origin": "Application", - "value": "IdentityRiskEvent.ReadWrite.All" + "description": "Allow the application to create site collections without a signed in user. Upon creation the application will be granted Sites.Selected(application) + FullControl to the newly created site.", + "displayName": "Create Site Collections without a signed in user.", + "id": "80819dd8-2b3b-4551-a1ad-2700fc44f533", + "origin": "Application (Microsoft Graph)", + "value": "Sites.Create.All" }, { - "description": "Allows the app to read and update identity risky user information for your organization without a signed-in user. \u00a0Update operations include dismissing risky users.", - "displayName": "Read and write all risky user information", - "id": "656f6061-f9fe-4807-9708-6a2e0934df76", - "origin": "Application", - "value": "IdentityRiskyUser.ReadWrite.All" + "description": "Allows the app to have full control of all site collections without a signed in user.", + "displayName": "Have full control of all site collections", + "id": "a82116e5-55eb-4c41-a434-62fe8a61c773", + "origin": "Application (Microsoft Graph)", + "value": "Sites.FullControl.All" }, { - "description": "Allows the app to read all files in all site collections without a signed in user.", - "displayName": "Read files in all site collections", - "id": "01d4889c-1287-42c6-ac1f-5d1e02578ef6", - "origin": "Application", - "value": "Files.Read.All" + "description": "Allows the app to create or delete document libraries and lists in all site collections without a signed in user.", + "displayName": "Create, edit, and delete items and lists in all site collections", + "id": "0c0bf378-bf22-4481-8f81-9e89a9b4960a", + "origin": "Application (Microsoft Graph)", + "value": "Sites.Manage.All" }, { - "description": "Allows the app to read the identity risk event information for your organization without a signed in user.", - "displayName": "Read all identity risk event information", - "id": "6e472fd1-ad78-48da-a0f0-97ab2c6b769e", - "origin": "Application", - "value": "IdentityRiskEvent.Read.All" + "description": "Allows the app to read documents and list items in all site collections without a signed in user.", + "displayName": "Read items in all site collections ", + "id": "332a536c-c7ef-4017-ab91-336970924f0d", + "origin": "Application (Microsoft Graph)", + "value": "Sites.Read.All" }, { - "description": "Allows the app to read a limited subset of properties from both the structure of schools and classes in the organization's roster and education-specific information about all users. Includes name, status, role, email address and photo.", - "displayName": "Read a limited subset of the organization's roster", - "id": "0d412a8c-a06c-439f-b3ec-8abcf54d2f96", - "origin": "Application", - "value": "EduRoster.ReadBasic.All" + "description": "Allows the app to create, read, update, and delete documents and list items in all site collections without a signed in user.", + "displayName": "Read and write items in all site collections", + "id": "9492366f-7969-46a4-8d15-ed1a20078fff", + "origin": "Application (Microsoft Graph)", + "value": "Sites.ReadWrite.All" }, { - "description": "Allows the app to read the structure of schools and classes in the organization's roster and education-specific information about all users to be read.", - "displayName": "Read the organization's roster", - "id": "e0ac9e1b-cb65-4fc5-87c5-1a8bc181f648", - "origin": "Application", - "value": "EduRoster.Read.All" + "description": "Allow the application to access a subset of site collections without a signed in user. The specific site collections and the permissions granted will be configured in SharePoint Online.", + "displayName": "Access selected site collections", + "id": "883ea226-0bf2-4a8f-9f9d-92c9162a727d", + "origin": "Application (Microsoft Graph)", + "value": "Sites.Selected" }, { - "description": "Allows the app to read and write the structure of schools and classes in the organization's roster and education-specific information about all users to be read and written.", - "displayName": "Read and write the organization's roster", - "id": "d1808e82-ce13-47af-ae0d-f9b254e6d58a", - "origin": "Application", - "value": "EduRoster.ReadWrite.All" + "description": "Allows the app to read your organization's SPIFFE trust domains and child resources without a signed in user.", + "displayName": "Read SPIFFE trust domains and child resources", + "id": "dcdfc277-41fd-4d68-ad0c-c3057235bd8e", + "origin": "Application (Microsoft Graph)", + "value": "SpiffeTrustDomain.Read.All" }, { - "description": "Read the state and settings of all Microsoft education apps.", - "displayName": "Read Education app settings", - "id": "7c9db06a-ec2d-4e7b-a592-5a1e30992566", - "origin": "Application", - "value": "EduAdministration.Read.All" + "description": "Allows the app to read and write your organization's SPIFFE trust domains and child resources without a signed in user.", + "displayName": "Read and write SPIFFE trust domains and child resources", + "id": "17b78cfd-eeff-447d-8bab-2795af00055a", + "origin": "Application (Microsoft Graph)", + "value": "SpiffeTrustDomain.ReadWrite.All" }, { - "description": "Manage the state and settings of all Microsoft education apps.", - "displayName": "Manage education app settings", - "id": "9bc431c3-b8bc-4a8d-a219-40f10f92eff6", - "origin": "Application", - "value": "EduAdministration.ReadWrite.All" + "description": "Allows the app to modify Viva Engage storylines, read all storylines properties, update storyline properties, and delete storyline properties without a signed-in user.", + "displayName": "Read and write all Viva Engage storylines", + "id": "6eff534b-699e-44d9-af61-a4182f0ec37e", + "origin": "Application (Microsoft Graph)", + "value": "Storyline.ReadWrite.All" }, { - "description": "Allows the app to read the identity risky user information for your organization without a signed in user.", - "displayName": "Read all identity risky user information", - "id": "dc5007c0-2d7d-4c42-879c-2dab87571379", - "origin": "Application", - "value": "IdentityRiskyUser.Read.All" + "description": "Allows the app to read subject rights requests without a signed-in user.", + "displayName": "Read all subject rights requests", + "id": "ee1460f0-368b-4153-870a-4e1ca7e72c42", + "origin": "Application (Microsoft Graph)", + "value": "SubjectRightsRequest.Read.All" }, { - "description": "Allows the app to read and update user profiles without a signed in user.", - "displayName": "Read and write all users' full profiles", - "id": "741f803b-c850-494e-b5df-cde7c675a1ca", - "origin": "Application", - "value": "User.ReadWrite.All" + "description": "Allows the app to read and write subject rights requests without a signed in user.", + "displayName": "Read and write all subject rights requests", + "id": "8387eaa4-1a3c-41f5-b261-f888138e6041", + "origin": "Application (Microsoft Graph)", + "value": "SubjectRightsRequest.ReadWrite.All" }, { - "description": "Allows the app to read user profiles without a signed in user.", - "displayName": "Read all users' full profiles", - "id": "df021288-bdef-4463-88db-98f22de89214", - "origin": "Application", - "value": "User.Read.All" + "description": "Allows the application to read Azure AD synchronization information, without a signed-in user.", + "displayName": "Read all Azure AD synchronization data.", + "id": "5ba43d2f-fa88-4db2-bd1c-a67c5f0fb1ce", + "origin": "Application (Microsoft Graph)", + "value": "Synchronization.Read.All" }, { - "description": "Allows the app to read and query your audit log activities, without a signed-in user.", - "displayName": "Read all audit log data", - "id": "b0afded3-3588-46d8-8b3d-9842eff778da", - "origin": "Application", - "value": "AuditLog.Read.All" + "description": "Allows the application to configure the Azure AD synchronization service, without a signed-in user.", + "displayName": "Read and write all Azure AD synchronization data.", + "id": "9b50c33d-700f-43b1-b2eb-87e89b703581", + "origin": "Application (Microsoft Graph)", + "value": "Synchronization.ReadWrite.All" }, { - "description": "Allows the app to create other applications, and fully manage those applications (read, update, update application secrets and delete), without a signed-in user. \u00a0It cannot update any apps that it is not an owner of.", - "displayName": "Manage apps that this app creates or owns", - "id": "18a4783c-866b-4cc7-a460-3d5e5662c884", - "origin": "Application", - "value": "Application.ReadWrite.OwnedBy" + "description": "Allows the application to upload bulk user data to the identity synchronization service, without a signed-in user.", + "displayName": "Upload user data to the identity synchronization service", + "id": "db31e92a-b9ea-4d87-bf6a-75a37a9ca35a", + "origin": "Application (Microsoft Graph)", + "value": "SynchronizationData-User.Upload" }, { - "description": "Allows the app to export data (e.g. customer content or system-generated logs), associated with any user in your company, when the app is used by a privileged user (e.g. a Company Administrator).", - "displayName": "Export user's data", - "id": "405a51b5-8d8d-430b-9842-8be4b0e9f324", - "origin": "Application", - "value": "User.Export.All" + "description": "Allows the application to upload bulk user data to the identity synchronization service for apps that this application creates or owns, without a signed-in user.", + "displayName": "Upload user data to the identity sync service for apps that this application creates or owns", + "id": "25c32ff3-849a-494b-b94f-20a8ac4e6774", + "origin": "Application (Microsoft Graph)", + "value": "SynchronizationData-User.Upload.OwnedBy" }, { - "description": "Allows the app to read, update, delete and perform actions on programs and program controls in the organization, without a signed-in user.", - "displayName": "Manage all programs", - "id": "60a901ed-09f7-4aa5-a16e-7dd3d6f9de36", - "origin": "Application", - "value": "ProgramControl.ReadWrite.All" + "description": "Allows the app to create, read, update and delete all users’ tasks and task lists in your organization, without a signed-in user", + "displayName": "Read and write all users’ tasks and tasklists", + "id": "44e666d1-d276-445b-a5fc-8815eeb81d55", + "origin": "Application (Microsoft Graph)", + "value": "Tasks.ReadWrite.All" }, { - "description": "Allows the app to read programs and program controls in the organization, without a signed-in user.", - "displayName": "Read all programs", - "id": "eedb7fdd-7539-4345-a38b-4839e4a84cbd", - "origin": "Application", - "value": "ProgramControl.Read.All" + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any chat, without a signed-in user, and manage its permission grants for accessing those specific chats' data.", + "displayName": "Allow the Teams app to manage itself and its permission grants for all chats", + "id": "ba1ba90b-2d8f-487e-9f16-80728d85bb5c", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForChat.All" }, { - "description": "Allows the app to read, update, delete and perform actions on access reviews, reviewers, decisions and settings in the organization, without a signed-in user.", - "displayName": "Manage all access reviews", - "id": "ef5f7d5c-338f-44b0-86c3-351f46c8bb5f", - "origin": "Application", - "value": "AccessReview.ReadWrite.All" + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any team, without a signed-in user, and manage its permission grants for accessing those specific teams' data.", + "displayName": "Allow the Teams app to manage itself and its permission grants for all teams", + "id": "1e4be56c-312e-42b8-a2c9-009600d732c0", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForTeam.All" }, { - "description": "Allows the app to read access reviews, reviewers, decisions and settings in the organization, without a signed-in user.", - "displayName": "Read all access reviews", - "id": "d07a8cc0-3d51-4b77-b3b0-32704d1f69fa", - "origin": "Application", - "value": "AccessReview.Read.All" + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any user account, without a signed-in user, and manage its permission grants for accessing those specific users' data.", + "displayName": "Allow the Teams app to manage itself and its permission grants in all user accounts", + "id": "a87076cf-6abd-4e56-8559-4dbdf41bef96", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForUser.All" }, { - "description": "Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Office 365 and Azure Active Directory.", - "displayName": "Read all usage reports", - "id": "230c1aed-a721-4c5d-9cb4-a90514e508ef", - "origin": "Application", - "value": "Reports.Read.All" + "description": "Allows the app to read your tenant's acquired telephone number details, without a signed-in user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", + "displayName": "Read Tenant-Acquired Telephone Number Details", + "id": "39b17d18-680c-41f4-b9c2-5f30629e7cb6", + "origin": "Application (Microsoft Graph)", + "value": "TeamsTelephoneNumber.Read.All" }, { - "description": "Allows the app to read any user's scored list of relevant people, without a signed-in user. The list can include local contacts, contacts from social networking, your organization's directory, and people from recent communications (such as email and Skype).", - "displayName": "Read all users' relevant people lists", - "id": "b528084d-ad10-4598-8b93-929746b4d7d6", - "origin": "Application", - "value": "People.Read.All" + "description": "Allows the app to read your tenant's acquired telephone number details, without a signed-in user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", + "displayName": "Read and Modify Tenant-Acquired Telephone Number Details", + "id": "0a42382f-155c-4eb1-9bdc-21548ccaa387", + "origin": "Application (Microsoft Graph)", + "value": "TeamsTelephoneNumber.ReadWrite.All" }, { - "description": "Allows the app to update Microsoft Teams 1-to-1 or group chat messages by patching a set of Data Loss Prevention (DLP) policy violation properties to handle the output of DLP processing.", - "displayName": "Flag chat messages for violating policy", - "id": "7e847308-e030-4183-9899-5235d7270f58", - "origin": "Application", - "value": "Chat.UpdatePolicyViolation.All" + "description": "Allows the app to read your tenant's user configurations, without a signed-in user. User configuration may include attributes related to user, such as telephone number, assigned policies, etc.", + "displayName": "Read Teams user configurations", + "id": "a91eadaf-2c3c-4362-908b-fb172d208fc6", + "origin": "Application (Microsoft Graph)", + "value": "TeamsUserConfiguration.Read.All" }, { - "description": "Allows the app to read all 1-to-1 or group chat messages in Microsoft Teams.", - "displayName": "Read all chat messages", - "id": "6b7d71aa-70aa-4810-a8d9-5d9fb2830017", - "origin": "Application", - "value": "Chat.Read.All" + "description": "Allows the app to read all available Teams Templates, without a signed-user.", + "displayName": "Read all available Teams Templates", + "id": "6323133e-1f6e-46d4-9372-ac33a0870636", + "origin": "Application (Microsoft Graph)", + "value": "TeamTemplates.Read.All" }, { - "description": "Allows the app to read all channel messages in Microsoft Teams", - "displayName": "Read all channel messages", - "id": "7b2449af-6ccd-4f4d-9f78-e550c193f0d1", - "origin": "Application", - "value": "ChannelMessage.Read.All" + "description": "Allows the app to create chat and channel messages, without a signed in user. The app specifies which user appears as the sender, and can backdate the message to appear as if it was sent long ago. The messages can be sent to any chat or channel in the organization.", + "displayName": "Create chat and channel messages with anyone's identity and with any timestamp", + "id": "dfb0dd15-61de-45b2-be36-d6a69fba3c79", + "origin": "Application (Microsoft Graph)", + "value": "Teamwork.Migrate.All" + }, + { + "description": "Allows the app to read all teamwork settings of the organization without a signed-in user.", + "displayName": "Read organizational teamwork settings", + "id": "75bcfbce-a647-4fba-ad51-b63d73b210f4", + "origin": "Application (Microsoft Graph)", + "value": "Teamwork.Read.All" }, { - "description": "Allows the app to update Microsoft Teams channel messages by patching a set of Data Loss Prevention (DLP) policy violation properties to handle the output of DLP processing.", - "displayName": "Flag channel messages for violating policy", - "id": "4d02b0cc-d90b-441f-8d82-4fb55c34d6bb", - "origin": "Application", - "value": "ChannelMessage.UpdatePolicyViolation.All" + "description": "Allows the app to read the Teams app settings without a signed-in user.", + "displayName": "Read Teams app settings", + "id": "475ebe88-f071-4bd7-af2b-642952bd4986", + "origin": "Application (Microsoft Graph)", + "value": "TeamworkAppSettings.Read.All" }, { - "description": "Allows the app to create, read, update and delete applications and service principals without a signed-in user. Does not allow management of consent grants.", - "displayName": "Read and write all applications", - "id": "1bfefb4e-e0b5-418b-a88f-73c46d2cc8e9", - "origin": "Application", - "value": "Application.ReadWrite.All" + "description": "Allows the app to read and write the Teams app settings without a signed-in user.", + "displayName": "Read and write Teams app settings", + "id": "ab5b445e-8f10-45f4-9c79-dd3f8062cc4e", + "origin": "Application (Microsoft Graph)", + "value": "TeamworkAppSettings.ReadWrite.All" }, { - "description": "Allows the app to create, read, update, and delete user's mailbox settings without a signed-in user. Does not include permission to send mail.", - "displayName": "Read and write all user mailbox settings", - "id": "6931bccd-447a-43d1-b442-00a195474933", - "origin": "Application", - "value": "MailboxSettings.ReadWrite" + "description": "Create custom emoji without a signed-in user.", + "displayName": "Create custom emoji", + "id": "85643b08-0e25-4d99-9d68-04ba0fef9740", + "origin": "Application (Microsoft Graph)", + "value": "TeamworkCustomEmoji.Create.All" }, { - "description": "Allows the app to read and write all domain properties without a signed in user. \u00a0Also allows the app to add, \u00a0verify and remove domains.", - "displayName": "Read and write domains", - "id": "7e05723c-0bb0-42da-be95-ae9f08a6e53c", - "origin": "Application", - "value": "Domain.ReadWrite.All" + "description": "Read custom emoji without a signed-in user.", + "displayName": "Read custom emoji", + "id": "1efa3d37-1703-4685-9a59-baf6296fb956", + "origin": "Application (Microsoft Graph)", + "value": "TeamworkCustomEmoji.Read.All" }, { - "description": "Allows the app to read user's mailbox settings without a signed-in user. Does not include permission to send mail.", - "displayName": "Read all user mailbox settings", - "id": "40f97065-369a-49f4-947c-6a255697ae91", - "origin": "Application", - "value": "MailboxSettings.Read" + "description": "Allow the app to read the management data for Teams devices, without a signed-in user.", + "displayName": "Read Teams devices", + "id": "0591bafd-7c1c-4c30-a2a5-2b9aacb1dfe8", + "origin": "Application (Microsoft Graph)", + "value": "TeamworkDevice.Read.All" }, { - "description": "Allows the app to read mail in all mailboxes without a signed-in user.", - "displayName": "Read mail in all mailboxes", - "id": "810c84a8-4a9e-49e6-bf7d-12d183f40d01", - "origin": "Application", - "value": "Mail.Read" + "description": "Allow the app to read and write the management data for Teams devices, without a signed-in user.", + "displayName": "Read and write Teams devices", + "id": "79c02f5b-bd4f-4713-bc2c-a8a4a66e127b", + "origin": "Application (Microsoft Graph)", + "value": "TeamworkDevice.ReadWrite.All" }, { - "description": "Allows the app to create, read, update, and delete mail in all mailboxes without a signed-in user. Does not include permission to send mail.", - "displayName": "Read and write mail in all mailboxes", - "id": "e2a3a72e-5f79-4c64-b1b1-878b674786c9", - "origin": "Application", - "value": "Mail.ReadWrite" + "description": "Allows the app to read all users' sections (folders) for organizing chats and channels in Teams, without a signed-in user.", + "displayName": "Read all users' sections", + "id": "e9e1b87a-726e-4628-8fab-d1fc58d4d9ad", + "origin": "Application (Microsoft Graph)", + "value": "TeamworkSection.Read.All" }, { - "description": "Allows the app to send mail as any user without a signed-in user.", - "displayName": "Send mail as any user", - "id": "b633e1c5-b582-4048-a93e-9f11b44c7e96", - "origin": "Application", - "value": "Mail.Send" + "description": "Allows the app to read and write all users' sections (folders) for organizing chats and channels in Teams, without a signed-in user.", + "displayName": "Read and write all users' sections", + "id": "fd99f9da-42d6-4d00-8a41-4161bea42309", + "origin": "Application (Microsoft Graph)", + "value": "TeamworkSection.ReadWrite.All" }, { - "description": "Allows the app to read all contacts in all mailboxes without a signed-in user.", - "displayName": "Read contacts in all mailboxes", - "id": "089fe4d0-434a-44c5-8827-41ba8a0b17f5", - "origin": "Application", - "value": "Contacts.Read" + "description": "Allows the app to read tags in Teams without a signed-in user.", + "displayName": "Read tags in Teams", + "id": "b74fd6c4-4bde-488e-9695-eeb100e4907f", + "origin": "Application (Microsoft Graph)", + "value": "TeamworkTag.Read.All" }, { - "description": "Allows the app to create, read, update, and delete all contacts in all mailboxes without a signed-in user.", - "displayName": "Read and write contacts in all mailboxes", - "id": "6918b873-d17a-4dc1-b314-35f528134491", - "origin": "Application", - "value": "Contacts.ReadWrite" + "description": "Allows the app to read and write tags in Teams without a signed-in user.", + "displayName": "Read and write tags in Teams", + "id": "a3371ca5-911d-46d6-901c-42c8c7a937d8", + "origin": "Application (Microsoft Graph)", + "value": "TeamworkTag.ReadWrite.All" }, { - "description": "Allows the app to read data in your organization's directory, such as users, groups and apps, without a signed-in user.", - "displayName": "Read directory data", - "id": "7ab1d382-f21e-4acd-a863-ba3e13f7da61", - "origin": "Application", - "value": "Directory.Read.All" + "description": "Allows the app to read all group chat or channel targeted messages in Microsoft Teams.", + "displayName": "Read all targeted messages of group chat or channel", + "id": "b0cfd829-be18-4b31-bb0e-ec1df8197ba3", + "origin": "Application (Microsoft Graph)", + "value": "TeamworkTargetedMessage.Read.All" }, { - "description": "Allows the app to read and write data in your organization's directory, such as users, and groups, without a signed-in user. Does not allow user or group deletion.", - "displayName": "Read and write directory data", - "id": "19dbc75e-c2e2-444c-a770-ec69d8559fc7", - "origin": "Application", - "value": "Directory.ReadWrite.All" + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for any user, without a signed-in user.", + "displayName": "Allow the Teams app to manage only its own tabs for all users", + "id": "3c42dec6-49e8-4a0a-b469-36cff0d9da93", + "origin": "Application (Microsoft Graph)", + "value": "TeamsTab.ReadWriteSelfForUser.All" }, { - "description": "Allows the app to read and write all device properties without a signed in user. Does not allow device creation, device deletion or update of device alternative security identifiers.", - "displayName": "Read and write devices", - "id": "1138cb37-bd11-4084-a2b7-9f71582aeddb", - "origin": "Application", - "value": "Device.ReadWrite.All" + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs in any team, without a signed-in user.", + "displayName": "Allow the Teams app to manage only its own tabs for all teams", + "id": "91c32b81-0ef0-453f-a5c7-4ce2e562f449", + "origin": "Application (Microsoft Graph)", + "value": "TeamsTab.ReadWriteSelfForTeam.All" }, { - "description": "Allows the app to read events of all calendars without a signed-in user.", - "displayName": "Read calendars in all mailboxes", - "id": "798ee544-9d2d-430c-a058-570e29e34338", - "origin": "Application", - "value": "Calendars.Read" + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for any chat, without a signed-in user.", + "displayName": "Allow the Teams app to manage only its own tabs for all chats", + "id": "9f62e4a2-a2d6-4350-b28b-d244728c4f86", + "origin": "Application (Microsoft Graph)", + "value": "TeamsTab.ReadWriteSelfForChat.All" }, { - "description": "Allows the app to create, read, update, and delete events of all calendars without a signed-in user.", - "displayName": "Read and write calendars in all mailboxes", - "id": "ef54d2bf-783f-4e0f-bca1-3210c0444d99", - "origin": "Application (Office 365 Exchange Online)", - "value": "Calendars.ReadWrite.All" + "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs for any user, without a signed-in user.", + "displayName": "Allow the app to manage all tabs for all users", + "id": "425b4b59-d5af-45c8-832f-bb0b7402348a", + "origin": "Application (Microsoft Graph)", + "value": "TeamsTab.ReadWriteForUser.All" }, { - "description": "Allows the app to create, read, update, and delete user's mailbox settings without a signed-in user. Does not include permission to send mail.", - "displayName": "Read and write all user mailbox settings", - "id": "f9156939-25cd-4ba8-abfe-7fabcf003749", - "origin": "Application (Office 365 Exchange Online)", - "value": "MailboxSettings.ReadWrite" + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any chat, without a signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Manage Teams apps for all chats", + "id": "9e19bae1-2623-4c4f-ab6e-2664615ff9a0", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteForChat.All" }, { - "description": "Allows the app to read your organization's user flows, without a signed-in user.", - "displayName": "Read all identity user flows", - "id": "1b0c317f-dd31-4305-9932-259a8b6e8099", - "origin": "Application", - "value": "IdentityUserFlow.Read.All" + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any team, without a signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Manage Teams apps for all teams", + "id": "5dad17ba-f6cc-4954-a5a2-a0dcc95154f0", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteForTeam.All" }, { - "description": "Allows the app to read or write your organization's user flows, without a signed-in user.", - "displayName": "Read and write all identity user flows", - "id": "65319a09-a2be-469d-8782-f6b07debf789", - "origin": "Application", - "value": "IdentityUserFlow.ReadWrite.All" + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps for any user, without a signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Manage Teams apps for all users", + "id": "74ef0291-ca83-4d02-8c7e-d2391e6a444f", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteForUser.All" }, { - "description": "Allows the app to read and create online meetings as an application in your organization.", - "displayName": "Read and create online meetings", - "id": "b8bb2037-6e08-44ac-a4ea-4674e010e2a4", - "origin": "Application", - "value": "OnlineMeetings.ReadWrite.All" + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in any chat, without a signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Manage selected installed Teams apps in all chats", + "id": "25bbeaad-04be-4207-83ed-a263aae76ddf", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteSelectedForChat.All" }, { - "description": "Allows the app to read online meeting details in your organization, without a signed-in user.", - "displayName": "Read online meeting details", - "id": "c1684f21-1984-47fa-9d61-2dc8c296bb70", - "origin": "Application", - "value": "OnlineMeetings.Read.All" + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in any team, without a signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Manage selected installed Teams apps in all teams", + "id": "7b5823ae-d0f2-424d-b90c-d843ffada7d9", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteSelectedForTeam.All" }, { - "description": "Allows the app to get direct access to media streams in a call, without a signed-in user.", - "displayName": "Access media streams in a call as an app", - "id": "a7a681dc-756e-4909-b988-f160edc6655f", - "origin": "Application", - "value": "Calls.AccessMedia.All" + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps for any user, without a signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Manage selected Teams apps installed for all users", + "id": "650a76ec-4118-4b25-9d3a-1f98048a5ee0", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteSelectedForUser.All" }, { - "description": "Allows the app to anonymously join group calls and scheduled meetings in your organization, without a signed-in user. \u00a0The app will be joined as a guest to meetings in your organization.", - "displayName": "Join group calls and meetings as a guest", - "id": "fd7ccf6b-3d28-418b-9701-cd10f5cd2fd4", - "origin": "Application", - "value": "Calls.JoinGroupCallAsGuest.All" + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any chat, without a signed-in user.", + "displayName": "Allow the Teams app to manage itself for all chats", + "id": "73a45059-f39c-4baf-9182-4954ac0e55cf", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteSelfForChat.All" }, { - "description": "Allows the app to join group calls and scheduled meetings in your organization, without a signed-in user. \u00a0The app will be joined with the privileges of a directory user to meetings in your organization.", - "displayName": "Join group calls and meetings as an app", - "id": "f6b49018-60ab-4f81-83bd-22caeabfed2d", - "origin": "Application", - "value": "Calls.JoinGroupCall.All" + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in any team, without a signed-in user.", + "displayName": "Allow the Teams app to manage itself for all teams", + "id": "9f67436c-5415-4e7f-8ac1-3014a7132630", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteSelfForTeam.All" }, { - "description": "Allows the app to place outbound calls to multiple users and add participants to meetings in your organization, without a signed-in user.", - "displayName": "Initiate outgoing group calls from the app", - "id": "4c277553-8a09-487b-8023-29ee378d8324", - "origin": "Application", - "value": "Calls.InitiateGroupCall.All" + "description": "Allows the application to list and read all Tenant Governance policy templates without a signed-in user.", + "displayName": "Read Tenant Governance policy templates", + "id": "eb9465d8-e7c0-4301-8e51-927f34ee3134", + "origin": "Application (Microsoft Graph)", + "value": "TenantGovernance-PolicyTemplate.Read.All" }, { - "description": "Allows the app to place outbound calls to a single user and transfer calls to users in your organization\u2019s directory, without a signed-in user.", - "displayName": "Initiate outgoing 1 to 1 calls from the app", - "id": "284383ee-7f6e-4e40-a2a8-e85dcb029101", - "origin": "Application", - "value": "Calls.Initiate.All" + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself to any user, without a signed-in user.", + "displayName": "Allow the app to manage itself for all users", + "id": "908de74d-f8b2-4d6b-a9ed-2a17b3b78179", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteSelfForUser.All" }, { - "description": "Allows the app to read all organizational contacts without a signed-in user. These contacts are managed by the organization and are different from a user's personal contacts.", - "displayName": "Read organizational contacts", - "id": "e1a88a34-94c4-4418-be12-c87b00e26bea", - "origin": "Application", - "value": "OrgContact.Read.All" + "description": "Read and change all teams' settings, without a signed-in user.", + "displayName": "Read and change all teams' settings", + "id": "bdd80a03-d9bc-451d-b7c4-ce7c63fe3c8f", + "origin": "Application (Microsoft Graph)", + "value": "TeamSettings.ReadWrite.All" }, { - "description": "Allows the app to read and write the properties, group assignments and status of apps, app configurations and app protection policies managed by Microsoft Intune, without a signed-in user.", - "displayName": "Read and write Microsoft Intune apps", - "id": "78145de6-330d-4800-a6ce-494ff2d33d07", - "origin": "Application", - "value": "DeviceManagementApps.ReadWrite.All" + "description": "Allow the app to read or write/update the policy assignment and unassigment for Teams users for all policy type categories.", + "displayName": "Read and Write Teams policy user assignment and unassigment for all policy types.", + "id": "1801e8f4-cf09-4c4e-a1b5-036dfcca6c90", + "origin": "Application (Microsoft Graph)", + "value": "TeamsPolicyUserAssign.ReadWrite.All" }, { - "description": "Allows the app to read and write properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups, without a signed-in user.", - "displayName": "Read and write Microsoft Intune device configuration and policies", - "id": "9241abd9-d0e6-425a-bd4f-47ba86e767a4", - "origin": "Application", - "value": "DeviceManagementConfiguration.ReadWrite.All" + "description": "Allows the app to read your tenant's resource accounts without a signed-in user.", + "displayName": "Read Teams resource accounts", + "id": "b55aa226-33a1-4396-bcf4-edce5e7a31c1", + "origin": "Application (Microsoft Graph)", + "value": "TeamsResourceAccount.Read.All" }, { - "description": "Allows the app to perform remote high impact actions such as wiping the device or resetting the passcode on devices managed by Microsoft Intune, without a signed-in user.", - "displayName": "Perform user-impacting remote actions on Microsoft Intune devices", - "id": "5b07b0dd-2377-4e44-a38d-703f09a0dc3c", - "origin": "Application", - "value": "DeviceManagementManagedDevices.PrivilegedOperations.All" + "description": "Allows the app to create tabs in any team in Microsoft Teams, without a signed-in user. This does not grant the ability to read, modify or delete tabs after they are created, or give access to the content inside the tabs.", + "displayName": "Create tabs in Microsoft Teams.", + "id": "49981c42-fd7b-4530-be03-e77b21aed25e", + "origin": "Application (Microsoft Graph)", + "value": "TeamsTab.Create" }, { - "description": "Allows the app to read and write the properties of devices managed by Microsoft Intune, without a signed-in user. Does not allow high impact operations such as remote wipe and password reset on the device\u2019s owner", - "displayName": "Read and write Microsoft Intune devices", - "id": "243333ab-4d21-40cb-a475-36241daa0842", - "origin": "Application", - "value": "DeviceManagementManagedDevices.ReadWrite.All" + "description": "Read the names and settings of tabs inside any team in Microsoft Teams, without a signed-in user. This does not give access to the content inside the tabs.", + "displayName": "Read tabs in Microsoft Teams.", + "id": "46890524-499a-4bb2-ad64-1476b4f3e1cf", + "origin": "Application (Microsoft Graph)", + "value": "TeamsTab.Read.All" }, { - "description": "Allows the app to read and write the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings, without a signed-in user.", - "displayName": "Read and write Microsoft Intune RBAC settings", - "id": "e330c4f0-4170-414e-a55a-2f022ec2b57b", - "origin": "Application", - "value": "DeviceManagementRBAC.ReadWrite.All" + "description": "Read and write tabs in any team in Microsoft Teams, without a signed-in user. This does not give access to the content inside the tabs.", + "displayName": "Read and write tabs in Microsoft Teams.", + "id": "a96d855f-016b-47d7-b51c-1218a98d791c", + "origin": "Application (Microsoft Graph)", + "value": "TeamsTab.ReadWrite.All" }, { - "description": "Allows the app to read and write Microsoft Intune service properties including device enrollment and third party service connection configuration, without a signed-in user.", - "displayName": "Read and write Microsoft Intune configuration", - "id": "5ac13192-7ace-4fcf-b828-1a26f28068ee", - "origin": "Application", - "value": "DeviceManagementServiceConfig.ReadWrite.All" + "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs for any chat, without a signed-in user.", + "displayName": "Allow the Teams app to manage all tabs for all chats", + "id": "fd9ce730-a250-40dc-bd44-8dc8d20f39ea", + "origin": "Application (Microsoft Graph)", + "value": "TeamsTab.ReadWriteForChat.All" }, { - "description": "Allows the app to manage permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, without a signed-in user.", - "displayName": "Manage app permission grants and app role assignments", - "id": "06b708a9-e830-4db3-a914-8e69da51d44f", - "origin": "Application", - "value": "AppRoleAssignment.ReadWrite.All" + "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs in any team, without a signed-in user.", + "displayName": "Allow the Teams app to manage all tabs for all teams", + "id": "6163d4f4-fbf8-43da-a7b4-060fe85ed148", + "origin": "Application (Microsoft Graph)", + "value": "TeamsTab.ReadWriteForTeam.All" }, { - "description": "Allows the app to manage permission grants for delegated permissions exposed by any API (including Microsoft Graph), without a signed-in user.", - "displayName": "Manage all delegated permission grants", - "id": "8e8e4742-1d95-4f68-9d56-6ee75648c72a", - "origin": "Application", - "value": "DelegatedPermissionGrant.ReadWrite.All" + "description": "Read all team's settings, without a signed-in user.", + "displayName": "Read all teams' settings", + "id": "242607bd-1d2c-432c-82eb-bdb27baa23ab", + "origin": "Application (Microsoft Graph)", + "value": "TeamSettings.Read.All" }, { - "description": "Allows the app to read all users' teamwork activity feed, without a signed-in user.", - "displayName": "Read all users' teamwork activity feed", - "id": "70dec828-f620-4914-aa83-a29117306807", - "origin": "Application", - "value": "TeamsActivity.Read.All" + "description": "Allows the app to read your organization's sign-in identifiers, without a signed-in user.", + "displayName": "Read all sign-in identifiers", + "id": "28e1fe78-598f-4df4-b55e-18bf34218925", + "origin": "Application (Microsoft Graph)", + "value": "SignInIdentifier.Read.All" }, { - "description": "Allows the app to read time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD built-in and custom administrative roles in your organization, without a signed-in user.", - "displayName": "Read privileged access to Azure AD roles", - "id": "4cdc2547-9148-4295-8d11-be0db1391d6b", - "origin": "Application", - "value": "PrivilegedAccess.Read.AzureAD" + "description": "Allows the app to read all virtual events without a signed-in user.", + "displayName": "Read all users' virtual events", + "id": "1dccb351-c4e4-4e09-a8d1-7a9ecbf027cc", + "origin": "Application (Microsoft Graph)", + "value": "VirtualEvent.Read.All" }, { - "description": "Allows the app to read time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups in your organization, without a signed-in user.", - "displayName": "Read privileged access to Azure AD groups", - "id": "01e37dc9-c035-40bd-b438-b2879c4870a6", - "origin": "Application", - "value": "PrivilegedAccess.Read.AzureADGroup" + "description": "Allows the app to read all Windows update deployment settings for the organization without a signed-in user.", + "displayName": "Read all Windows update deployment settings", + "id": "50a8bf5f-b06a-4ac7-881f-3ca0c4be7550", + "origin": "Application (Microsoft Graph)", + "value": "WindowsUpdates.Read.All" }, { - "description": "Allows the app to read time-based assignment and just-in-time elevation of user privileges to audit Azure resources in your organization, without a signed-in user.", - "displayName": "Read privileged access to Azure resources", - "id": "5df6fe86-1be0-44eb-b916-7bd443a71236", - "origin": "Application", - "value": "PrivilegedAccess.Read.AzureResources" + "description": "Allows the app to create, read, update, and delete events in user calendars.", + "displayName": "Have full access to user calendars ", + "id": "1ec239c2-d7c9-4623-a91a-a9775856bb36", + "origin": "Delegated (Microsoft Graph)", + "value": "Calendars.ReadWrite" }, { - "description": "Allows the app to request and manage time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD built-in and custom administrative roles in your organization, without a signed-in user.", - "displayName": "Read and write privileged access to Azure AD roles", - "id": "854d9ab1-6657-4ec8-be45-823027bcd009", - "origin": "Application", - "value": "PrivilegedAccess.ReadWrite.AzureAD" + "description": "Allows the app to create, read, update and delete events in all calendars in the organization user has permissions to access. This includes delegate and shared calendars.", + "displayName": "Read and write user and shared calendars", + "id": "12466101-c9b8-439a-8589-dd09ee67e8e9", + "origin": "Delegated (Microsoft Graph)", + "value": "Calendars.ReadWrite.Shared" }, { - "description": "Allows the app to request and manage time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups in your organization, without a signed-in user.", - "displayName": "Read and write privileged access to Azure AD groups", - "id": "2f6817f8-7b12-4f0f-bc18-eeaf60705a9e", - "origin": "Application", - "value": "PrivilegedAccess.ReadWrite.AzureADGroup" + "description": "Allows the app to read all AI Insights for calls, on behalf of the signed-in user.", + "displayName": "Read all AI Insights for calls. ", + "id": "e24bdaf9-83f8-468b-a144-c681ccb6caf4", + "origin": "Delegated (Microsoft Graph)", + "value": "CallAiInsights.Read.All" }, { - "description": "Allows the app to request and manage time-based assignment and just-in-time elevation of Azure resources (like your subscriptions, resource groups, storage, compute) in your organization, without a signed-in user.", - "displayName": "Read and write privileged access to Azure resources", - "id": "6f9d5abc-2db6-400b-a267-7de22a40fb87", - "origin": "Application", - "value": "PrivilegedAccess.ReadWrite.AzureResources" + "description": "Allows the app to read delegation settings of you", + "displayName": "Read delegation settings", + "id": "305b375b-00fe-48bf-81bc-e8d78954c1b6", + "origin": "Delegated (Microsoft Graph)", + "value": "CallDelegation.Read" }, { - "description": "Allows the app to read all the indicators for your organization, without a signed-in user.", - "displayName": "Read all threat indicators", - "id": "197ee4e9-b993-4066-898f-d6aecc55125b", - "origin": "Application", - "value": "ThreatIndicators.Read.All" + "description": "Allows the app to read and write delegation settings of you", + "displayName": "Read and write delegation settings", + "id": "599abf67-f72b-4b5f-98a3-cb38fe646118", + "origin": "Delegated (Microsoft Graph)", + "value": "CallDelegation.ReadWrite" }, { - "description": "Allows the app to send, read, update and delete user\u2019s notifications, without a signed-in user.", - "displayName": "Deliver and manage all user's notifications", - "id": "4e774092-a092-48d1-90bd-baad67c7eb47", - "origin": "Application", - "value": "UserNotification.ReadWrite.CreatedByApp" + "description": "Allows the app to read call event information for an organization for the signed-in user.", + "displayName": "Read call event data", + "id": "43431c03-960e-400f-87c6-8f910321dca3", + "origin": "Delegated (Microsoft Graph)", + "value": "CallEvents.Read" }, { - "description": "Allows the app to read all applications and service principals without a signed-in user.", - "displayName": "Read all applications", - "id": "9a5d68dd-52b0-4cc2-bd40-abcf44ac3a30", - "origin": "Application", - "value": "Application.Read.All" + "description": "Allows the app to read all recordings of calls, on behalf of the signed-in user.", + "displayName": "Read all recordings of calls. ", + "id": "63d31bd6-bcf5-40ca-8283-ba4130a66405", + "origin": "Delegated (Microsoft Graph)", + "value": "CallRecordings.Read.All" }, { - "description": "Allows the app to read memberships and basic group properties for all groups without a signed-in user.", - "displayName": "Read all group memberships", - "id": "98830695-27a2-44f7-8c18-0c3ebc9698f6", - "origin": "Application", - "value": "GroupMember.Read.All" + "description": "Allows the app to read all transcripts of calls, on behalf of the signed-in user.", + "displayName": "Read all transcripts of calls. ", + "id": "fbace248-5d8e-441c-85ca-cc19221a69a2", + "origin": "Delegated (Microsoft Graph)", + "value": "CallTranscripts.Read.All" }, { - "description": "Allows the app to list groups, read basic properties, read and update the membership of the groups this app has access to without a signed-in user. Group properties and owners cannot be updated and groups cannot be deleted.", - "displayName": "Read and write all group memberships", - "id": "dbaae8cf-10b5-4b86-a4a1-f871c94c6695", - "origin": "Application", - "value": "GroupMember.ReadWrite.All" + "description": "Allows the app to read all cases, relations, tasks, attachments and activities, on behalf of the signed-in user.", + "displayName": "Read all cases, relations, tasks, attachments and activities", + "id": "7bdc421c-99cd-4b67-a749-aa8e92775f7e", + "origin": "Delegated (Microsoft Graph)", + "value": "CaseManagement.Read.All" }, { - "description": "Allows the app to create groups without a signed-in user.", - "displayName": "Create groups", - "id": "bf7b1a76-6e77-406b-b258-bf5c7720e98f", - "origin": "Application", - "value": "Group.Create" + "description": "Allows the app to read and write to all cases, relations, tasks, attachments and activities, on behalf of the signed-in user.", + "displayName": "Read and write to all cases, relations, tasks, attachments and activities", + "id": "363a0763-d7eb-40bc-9457-6be55acd81e2", + "origin": "Delegated (Microsoft Graph)", + "value": "CaseManagement.ReadWrite.All" }, { - "description": "Allows an app to read your organization's threat assessment requests, without a signed-in user.", - "displayName": "Read threat assessment requests", - "id": "f8f035bb-2cce-47fb-8bf5-7baf3ecbee48", - "origin": "Application", - "value": "ThreatAssessment.Read.All" + "description": "Allows to read all Change Management items.", + "displayName": "Read Change Management items", + "id": "4628dff5-c33e-4fde-b17a-b64e7acb1bed", + "origin": "Delegated (Microsoft Graph)", + "value": "ChangeManagement.Read.All" }, { - "description": "Allows the app to read all schedules, schedule groups, shifts and associated entities in the Teams or Shifts application without a signed-in user.", - "displayName": "Read all schedule items", - "id": "7b2ebf90-d836-437f-b90d-7b62722c4456", - "origin": "Application", - "value": "Schedule.Read.All" + "description": "Create channels in any team, on behalf of the signed-in user.", + "displayName": "Create channels", + "id": "101147cf-4178-4455-9d58-02b5c164e759", + "origin": "Delegated (Microsoft Graph)", + "value": "Channel.Create" }, { - "description": "Allows the app to manage all schedules, schedule groups, shifts and associated entities in the Teams or Shifts application without a signed-in user.", - "displayName": "Read and write all schedule items", - "id": "b7760610-0545-4e8a-9ec3-cce9e63db01c", - "origin": "Application", - "value": "Schedule.ReadWrite.All" + "description": "Delete channels in any team, on behalf of the signed-in user.", + "displayName": "Delete channels", + "id": "cc83893a-e232-4723-b5af-bd0b01bcfe65", + "origin": "Delegated (Microsoft Graph)", + "value": "Channel.Delete.All" }, { - "description": "Allows the app to read call records for all calls and online meetings without a signed-in user.", - "displayName": "Read all call records", - "id": "45bbb07e-7321-4fd7-a8f6-3ff27e6a81c8", - "origin": "Application", - "value": "CallRecords.Read.All" + "description": "Read channel names and channel descriptions, on behalf of the signed-in user.", + "displayName": "Read the names and descriptions of channels", + "id": "9d8982ae-4365-4f57-95e9-d6032a4c0b87", + "origin": "Delegated (Microsoft Graph)", + "value": "Channel.ReadBasic.All" }, { - "description": "Allows the app to read and write your organization's conditional access policies, without a signed-in user.", - "displayName": "Read and write your organization's conditional access policies", - "id": "01c0a623-fc9b-48e9-b794-0756f8e8f067", - "origin": "Application", - "value": "Policy.ReadWrite.ConditionalAccess" + "description": "Read the members of channels, on behalf of the signed-in user.", + "displayName": "Read the members of channels", + "id": "2eadaff8-0bce-4198-a6b9-2cfc35a30075", + "origin": "Delegated (Microsoft Graph)", + "value": "ChannelMember.Read.All" }, { - "description": "Allows the application to read and write authentication methods of all users in your organization, without a signed-in user. Authentication methods include things like a user\u2019s phone numbers and Authenticator app settings. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods", - "displayName": "Read and write all users' authentication methods ", - "id": "50483e42-d915-4231-9639-7fdb7fd190e5", - "origin": "Application", - "value": "UserAuthenticationMethod.ReadWrite.All" + "description": "Add and remove members from channels, on behalf of the signed-in user. Also allows changing a member's role, for example from owner to non-owner.", + "displayName": "Add and remove members from channels", + "id": "0c3e411a-ce45-4cd1-8f30-f99a3efa7b11", + "origin": "Delegated (Microsoft Graph)", + "value": "ChannelMember.ReadWrite.All" }, { - "description": " Allows the app to read authentication methods of all users in your organization, without a signed-in user. Authentication methods include things like a user\u2019s phone numbers and Authenticator app settings. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": " Read all users' authentication methods", - "id": "38d9df27-64da-44fd-b7c5-a6fbac20248f", - "origin": "Application", - "value": "UserAuthenticationMethod.Read.All" + "description": "Allows an app to edit channel messages in Microsoft Teams, on behalf of the signed-in user.", + "displayName": "Edit user's channel messages", + "id": "2b61aa8a-6d36-4b2f-ac7b-f29867937c53", + "origin": "Delegated (Microsoft Graph)", + "value": "ChannelMessage.Edit" }, { - "description": "Allows the app to create tabs in any team in Microsoft Teams, without a signed-in user. This does not grant the ability to read, modify or delete tabs after they are created, or give access to the content inside the tabs.", - "displayName": "Create tabs in Microsoft Teams.", - "id": "49981c42-fd7b-4530-be03-e77b21aed25e", - "origin": "Application", - "value": "TeamsTab.Create" + "description": "Allows the app to read events in user calendars, except for properties such as body, attachments, and extensions.", + "displayName": "Read basic details of user calendars", + "id": "662d75ba-a364-42ad-adee-f5f880ea4878", + "origin": "Delegated (Microsoft Graph)", + "value": "Calendars.ReadBasic" }, { - "description": "Read the names and settings of tabs inside any team in Microsoft Teams, without a signed-in user. This does not give access to the content inside the tabs. ", - "displayName": "Read tabs in Microsoft Teams.", - "id": "46890524-499a-4bb2-ad64-1476b4f3e1cf", - "origin": "Application", - "value": "TeamsTab.Read.All" + "description": "Allows an app to read a channel's messages in Microsoft Teams, on behalf of the signed-in user.", + "displayName": "Read user channel messages", + "id": "767156cb-16ae-4d10-8f8b-41b657c8c8c8", + "origin": "Delegated (Microsoft Graph)", + "value": "ChannelMessage.Read.All" }, { - "description": "Read and write tabs in any team in Microsoft Teams, without a signed-in user. This does not give access to the content inside the tabs.", - "displayName": "Read and write tabs in Microsoft Teams.", - "id": "a96d855f-016b-47d7-b51c-1218a98d791c", - "origin": "Application", - "value": "TeamsTab.ReadWrite.All" + "description": "Allows the app to read events in all calendars that the user can access, including delegate and shared calendars.", + "displayName": "Read user and shared calendars", + "id": "2b9c4092-424d-4249-948d-b43879977640", + "origin": "Delegated (Microsoft Graph)", + "value": "Calendars.Read.Shared" }, { - "description": "Allows the app to read all domain properties without a signed-in user.", - "displayName": "Read domains", - "id": "dbb9058a-0e50-45d7-ae91-66909b5d4664", - "origin": "Application", - "value": "Domain.Read.All" + "description": "Allows the app to fully manage all data associated with the business scenarios it owns. Data access and changes will be attributed to the signed-in user.", + "displayName": "Read and write all data for business scenarios this app creates or owns", + "id": "19932d57-2952-4c60-8634-3655c79fc527", + "origin": "Delegated (Microsoft Graph)", + "value": "BusinessScenarioData.ReadWrite.OwnedBy" }, { - "description": "Allows the app to read and write your organization's application configuration policies, without a signed-in user. This includes policies such as activityBasedTimeoutPolicy, claimsMappingPolicy, homeRealmDiscoveryPolicy, tokenIssuancePolicy and tokenLifetimePolicy.", - "displayName": "Read and write your organization's application configuration policies", - "id": "be74164b-cff1-491c-8741-e671cb536e13", - "origin": "Application", - "value": "Policy.ReadWrite.ApplicationConfiguration" + "description": "Allows the app to search the backup snapshots for Microsoft 365 resources, and restore Microsoft 365 resources from a backed-up snapshot, on behalf of the signed in user.", + "displayName": "Read restore sessions and start restore sessions from backups", + "id": "9f89e109-94b9-4c9b-b4fc-98cdaa54f574", + "origin": "Delegated (Microsoft Graph)", + "value": "BackupRestore-Restore.ReadWrite.All" }, { - "description": "Allows the app to read your organization's devices' configuration information without a signed-in user.", - "displayName": "Read all devices", - "id": "7438b122-aefc-4978-80ed-43db9fcc7715", - "origin": "Application", - "value": "Device.Read.All" + "description": "Allows the app to search the backup snapshots for Microsoft 365 resources, on behalf of the signed in user.", + "displayName": "Search for metadata properties in backup snapshots", + "id": "2b24830f-f435-446f-ab5a-b1e70d9a2eb5", + "origin": "Delegated (Microsoft Graph)", + "value": "BackupRestore-Search.Read.All" }, { - "description": "Allows the app to read, update and delete identities that are associated with a user's account, without a signed in user. This controls the identities users can sign-in with.", - "displayName": "Manage all users' identities", - "id": "c529cfca-c91b-489c-af2b-d92990b66ce6", - "origin": "Application", - "value": "User.ManageIdentities.All" + "description": "Allows the app to read and write the billing configuration on all applications on behalf of the signed-in user.", + "displayName": "Read and write application billing configuration", + "id": "2bf6d319-dfca-4c22-9879-f88dcfaee6be", + "origin": "Delegated (Microsoft Graph)", + "value": "BillingConfiguration.ReadWrite.All" }, { - "description": "Allows the app to read all users' shift schedule preferences without a signed-in user.", - "displayName": "Read all user shift preferences", - "id": "de023814-96df-4f53-9376-1e2891ef5a18", - "origin": "Application", - "value": "UserShiftPreferences.Read.All" + "description": "Allows the app to read BitLocker keys on behalf of the signed-in user, for their owned devices. Allows read of the recovery key.", + "displayName": "Read BitLocker keys", + "id": "b27a61ec-b99c-4d6a-b126-c4375d08ae30", + "origin": "Delegated (Microsoft Graph)", + "value": "BitlockerKey.Read.All" }, { - "description": "Allows the app to manage all users' shift schedule preferences without a signed-in user.", - "displayName": "Read and write all user shift preferences", - "id": "d1eec298-80f3-49b0-9efb-d90e224798ac", - "origin": "Application", - "value": "UserShiftPreferences.ReadWrite.All" + "description": "Allows the app to read basic BitLocker key properties on behalf of the signed-in user, for their owned devices. Does not allow read of the recovery key itself.", + "displayName": "Read BitLocker keys basic information", + "id": "5a107bfc-4f00-4e1a-b67e-66451267bc68", + "origin": "Delegated (Microsoft Graph)", + "value": "BitlockerKey.ReadBasic.All" }, { - "description": "Allows the app to read all the OneNote notebooks in your organization, without a signed-in user.", - "displayName": "Read and write all OneNote notebooks", - "id": "0c458cef-11f3-48c2-a568-c66751c238c0", - "origin": "Application", - "value": "Notes.ReadWrite.All" + "description": "Allows an app to read, write and manage bookings appointments, businesses, customers, services, and staff on behalf of the signed-in user.", + "displayName": "Manage bookings information", + "id": "7f36b48e-542f-4d3b-9bcb-8406f0ab9fdb", + "origin": "Delegated (Microsoft Graph)", + "value": "Bookings.Manage.All" }, { - "description": "Allows the app to have full control of all site collections without a signed in user.", - "displayName": "Have full control of all site collections", - "id": "a82116e5-55eb-4c41-a434-62fe8a61c773", - "origin": "Application", - "value": "Sites.FullControl.All" + "description": "Allows an app to read bookings appointments, businesses, customers, services, and staff on behalf of the signed-in user.", + "displayName": "Read bookings information", + "id": "33b1df99-4b29-4548-9339-7a7b83eaeebc", + "origin": "Delegated (Microsoft Graph)", + "value": "Bookings.Read.All" }, { - "description": "Allows the app to create or delete document libraries and lists in all site collections without a signed in user.", - "displayName": "Create, edit, and delete items and lists in all site collections", - "id": "0c0bf378-bf22-4481-8f81-9e89a9b4960a", - "origin": "Application", - "value": "Sites.Manage.All" + "description": "Allows an app to read and write bookings appointments, businesses, customers, services, and staff on behalf of the signed-in user. Does not allow create, delete and publish of booking businesses.", + "displayName": "Read and write bookings information", + "id": "948eb538-f19d-4ec5-9ccc-f059e1ea4c72", + "origin": "Delegated (Microsoft Graph)", + "value": "Bookings.ReadWrite.All" }, { - "description": "Allows the app to read access packages and related entitlement management resources without a signed-in user.", - "displayName": "Read all entitlement management resources", - "id": "c74fd47d-ed3c-45c3-9a9e-b8676de685d2", - "origin": "Application", - "value": "EntitlementManagement.Read.All" + "description": "Allows an app to read and write bookings appointments and customers, and additionally allows read businesses information, services, and staff on behalf of the signed-in user.", + "displayName": "Read and write booking appointments", + "id": "02a5a114-36a6-46ff-a102-954d89d9ab02", + "origin": "Delegated (Microsoft Graph)", + "value": "BookingsAppointment.ReadWrite.All" }, { - "description": "Allows the app to read and write access packages and related entitlement management resources without a signed-in user.", - "displayName": "Read and write all entitlement management resources", - "id": "9acd699f-1e81-4958-b001-93b1d2506e19", - "origin": "Application", - "value": "EntitlementManagement.ReadWrite.All" + "description": "Allows an app to read all bookmarks that the signed-in user can access.", + "displayName": "Read all bookmarks that the user can access", + "id": "98b17b35-f3b1-4849-a85f-9f13733002f0", + "origin": "Delegated (Microsoft Graph)", + "value": "Bookmark.Read.All" }, { - "description": "Create channels in any team, without a signed-in user.", - "displayName": "Create channels", - "id": "f3a65bd4-b703-46df-8f7e-0174fea562aa", - "origin": "Application", - "value": "Channel.Create" + "description": "Allows an app to read the browser site lists configured for your organization, on behalf of the signed-in user.", + "displayName": "Read browser site lists for your organization", + "id": "fb9be2b7-a7fc-4182-aec1-eda4597c43d5", + "origin": "Delegated (Microsoft Graph)", + "value": "BrowserSiteLists.Read.All" }, { - "description": "Delete channels in any team, without a signed-in user.", - "displayName": "Delete channels", - "id": "6a118a39-1227-45d4-af0c-ea7b40d210bc", - "origin": "Application", - "value": "Channel.Delete.All" + "description": "Allows an app to read and write the browser site lists configured for your organization, on behalf of the signed-in user.", + "displayName": "Read and write browser site lists for your organization", + "id": "83b34c85-95bf-497b-a04e-b58eca9d49d0", + "origin": "Delegated (Microsoft Graph)", + "value": "BrowserSiteLists.ReadWrite.All" }, - { - "description": "Read all channel names, channel descriptions, and channel settings, without a signed-in user.", - "displayName": "Read the names, descriptions, and settings of all channels", - "id": "c97b873f-f59f-49aa-8a0e-52b32d762124", - "origin": "Application", - "value": "ChannelSettings.Read.All" + { + "description": "Allows the app to read the configurations of your organization's business scenarios, on behalf of the signed-in user.", + "displayName": "Read business scenario configurations", + "id": "d16480b2-e469-4118-846b-d3d177327bee", + "origin": "Delegated (Microsoft Graph)", + "value": "BusinessScenarioConfig.Read.All" }, { - "description": "Read and write the names, descriptions, and settings of all channels, without a signed-in user.", - "displayName": "Read and write the names, descriptions, and settings of all channels", - "id": "243cded2-bd16-4fd6-a953-ff8177894c3d", - "origin": "Application", - "value": "ChannelSettings.ReadWrite.All" + "description": "Allows the app to read the configurations of business scenarios it owns, on behalf of the signed-in user.", + "displayName": "Read business scenario configurations this app creates or owns", + "id": "c47e7b6e-d6f1-4be9-9ffd-1e00f3e32892", + "origin": "Delegated (Microsoft Graph)", + "value": "BusinessScenarioConfig.Read.OwnedBy" }, { - "description": "Get a list of all teams, without a signed-in user.", - "displayName": "Get a list of all teams", - "id": "2280dda6-0bfd-44ee-a2f4-cb867cfc4c1e", - "origin": "Application", - "value": "Team.ReadBasic.All" + "description": "Allows the app to read and write the configurations of your organization's business scenarios, on behalf of the signed-in user.", + "displayName": "Read and write business scenario configurations", + "id": "755e785b-b658-446f-bb22-5a46abd029ea", + "origin": "Delegated (Microsoft Graph)", + "value": "BusinessScenarioConfig.ReadWrite.All" }, { - "description": "Read all channel names and channel descriptions, without a signed-in user.", - "displayName": "Read the names and descriptions of all channels", - "id": "59a6b24b-4225-4393-8165-ebaec5f55d7a", - "origin": "Application", - "value": "Channel.ReadBasic.All" + "description": "Allows the app to create new business scenarios and fully manage the configurations of scenarios it owns, on behalf of the signed-in user.", + "displayName": "Read and write business scenario configurations this app creates or owns", + "id": "b3b7fcff-b4d4-4230-bf6f-90bd91285395", + "origin": "Delegated (Microsoft Graph)", + "value": "BusinessScenarioConfig.ReadWrite.OwnedBy" }, { - "description": "Read and change all teams' settings, without a signed-in user.", - "displayName": "Read and change all teams' settings", - "id": "bdd80a03-d9bc-451d-b7c4-ce7c63fe3c8f", - "origin": "Application", - "value": "TeamSettings.ReadWrite.All" + "description": "Allows the app to read all data associated with the business scenarios it owns. Data access will be attributed to the signed-in user.", + "displayName": "Read all data for business scenarios this app creates or owns", + "id": "25b265c4-5d34-4e44-952d-b567f6d3b96d", + "origin": "Delegated (Microsoft Graph)", + "value": "BusinessScenarioData.Read.OwnedBy" }, { - "description": "Read all team's settings, without a signed-in user.", - "displayName": "Read all teams' settings", - "id": "242607bd-1d2c-432c-82eb-bdb27baa23ab", - "origin": "Application", - "value": "TeamSettings.Read.All" + "description": "Allows the app to read events in user calendars.", + "displayName": "Read user calendars ", + "id": "465a38f9-76ea-45b9-9f34-9e8b0d4b0b42", + "origin": "Delegated (Microsoft Graph)", + "value": "Calendars.Read" }, { - "description": "Read the members of all teams, without a signed-in user.", - "displayName": "Read the members of all teams", - "id": "660b7406-55f1-41ca-a0ed-0b035e182f3e", - "origin": "Application", - "value": "TeamMember.Read.All" + "description": "Allows the app to read and write channel messages, on behalf of the signed-in user. This doesn't allow the app to edit the policyViolation of a channel message.", + "displayName": "Read and write user channel messages", + "id": "5922d31f-46c8-4404-9eaf-2117e390a8a4", + "origin": "Delegated (Microsoft Graph)", + "value": "ChannelMessage.ReadWrite" }, { - "description": "Add and remove members from all teams, without a signed-in user. Also allows changing a team member's role, for example from owner to non-owner.", - "displayName": "Add and remove members from all teams", - "id": "0121dc95-1b9f-4aed-8bac-58c5ac466691", - "origin": "Application", - "value": "TeamMember.ReadWrite.All" + "description": "Allows an app to send channel messages in Microsoft Teams, on behalf of the signed-in user.", + "displayName": "Send channel messages", + "id": "ebf0f66e-9fb1-49e4-a278-222f76911cf4", + "origin": "Delegated (Microsoft Graph)", + "value": "ChannelMessage.Send" }, { - "description": "Read the members of all channels, without a signed-in user.", - "displayName": "Read the members of all channels", - "id": "3b55498e-47ec-484f-8136-9013221c06a9", - "origin": "Application", - "value": "ChannelMember.Read.All" + "description": "Read all channel names, channel descriptions, and channel settings, on behalf of the signed-in user.", + "displayName": "Read the names, descriptions, and settings of channels", + "id": "233e0cf1-dd62-48bc-b65b-b38fe87fcf8e", + "origin": "Delegated (Microsoft Graph)", + "value": "ChannelSettings.Read.All" }, { - "description": "Add and remove members from all channels, without a signed-in user. Also allows changing a member's role, for example from owner to non-owner.", - "displayName": "Add and remove members from all channels", - "id": "35930dcf-aceb-4bd1-b99a-8ffed403c974", - "origin": "Application", - "value": "ChannelMember.ReadWrite.All" + "description": "Allows the app to read app consent requests and approvals, and deny or approve those requests on behalf of the signed-in user.", + "displayName": "Read and write consent requests", + "id": "497d9dfa-3bd1-481a-baab-90895e54568c", + "origin": "Delegated (Microsoft Graph)", + "value": "ConsentRequest.ReadWrite.All" }, { - "description": "Allows the app to read and write all authentication flow policies for the tenant, without a signed-in user.", - "displayName": "Read and write authentication flow policies", - "id": "25f85f3c-f66c-4205-8cd5-de92dd7f0cec", - "origin": "Application", - "value": "Policy.ReadWrite.AuthenticationFlows" + "description": "Allows the app to read user contacts. ", + "displayName": "Read user contacts ", + "id": "ff74d97f-43af-4b68-9f2a-b77ee6968c5d", + "origin": "Delegated (Microsoft Graph)", + "value": "Contacts.Read" }, { - "description": "Allows the app to read and write all authentication method policies for the tenant, without a signed-in user.\u00a0", - "displayName": "Read and write all authentication method policies\u00a0", - "id": "29c18626-4985-4dcd-85c0-193eef327366", - "origin": "Application", - "value": "Policy.ReadWrite.AuthenticationMethod" + "description": "Allows the app to read contacts a user has permissions to access, including their own and shared contacts.", + "displayName": "Read user and shared contacts", + "id": "242b9d9e-ed24-4d09-9a52-f43769beb9d4", + "origin": "Delegated (Microsoft Graph)", + "value": "Contacts.Read.Shared" }, { - "description": "Allows the app to read and write your organization's authorization policy without a signed in user. For example, authorization policies can control some of the permissions that the out-of-the-box user role has by default.", - "displayName": "Read and write your organization's authorization policy", - "id": "fb221be6-99f2-473f-bd32-01c6a0e9ca3b", - "origin": "Application", - "value": "Policy.ReadWrite.Authorization" + "description": "Allows the app to create, read, update, and delete user contacts.", + "displayName": "Have full access to user contacts ", + "id": "d56682ec-c09e-4743-aaf4-1a3aac4caa21", + "origin": "Delegated (Microsoft Graph)", + "value": "Contacts.ReadWrite" }, { - "description": "Read names and members of all one-to-one and group chats in Microsoft Teams, without a signed-in user.", - "displayName": "Read names and members of all chat threads", - "id": "b2e060da-3baf-4687-9611-f4ebc0f0cbde", - "origin": "Application", - "value": "Chat.ReadBasic.All" + "description": "Allows the app to create, read, update, and delete contacts a user has permissions to, including their own and shared contacts.", + "displayName": "Read and write user and shared contacts", + "id": "afb6c84b-06be-49af-80bb-8f3f77004eab", + "origin": "Delegated (Microsoft Graph)", + "value": "Contacts.ReadWrite.Shared" }, { - "description": "Allows the app to read policies related to consent and permission grants for applications, without a signed-in user.", - "displayName": "Read consent and permission grant policies", - "id": "9e640839-a198-48fb-8b9a-013fd6f6cbcd", - "origin": "Application", - "value": "Policy.Read.PermissionGrant" + "description": "Allows the app to read and update the on-premises sync behavior of contacts a user has permissions to, including their own and shared contacts.", + "displayName": "Read and update the on-premises sync behavior of contacts", + "id": "1e4c6c41-0803-4f52-85ef-0a5d63ad8670", + "origin": "Delegated (Microsoft Graph)", + "value": "Contacts-OnPremisesSyncBehavior.ReadWrite.All" }, { - "description": "Allows the app to manage policies related to consent and permission grants for applications, without a signed-in user.", - "displayName": "Manage consent and permission grant policies", - "id": "a402ca1c-2696-4531-972d-6e5ee4aa11ea", - "origin": "Application", - "value": "Policy.ReadWrite.PermissionGrant" + "description": "Allows the app to process and evaluate content for data security, governance and compliance outcomes at tenant scope.", + "displayName": "Process content for data security, governance and compliance", + "id": "7e2467d1-f874-46bb-828e-24cb06b29d3f", + "origin": "Delegated (Microsoft Graph)", + "value": "Content.Process.All" }, { - "description": "Allows the application to read printers without a signed-in user.\u00a0", - "displayName": "Read printers", - "id": "9709bb33-4549-49d4-8ed9-a8f65e45bb0f", - "origin": "Application", - "value": "Printer.Read.All" + "description": "Allows the app to process and evaluate content for data security, governance and compliance outcomes for a user.", + "displayName": "Process content for data security, governance and compliance", + "id": "1d787a13-f750-4ad6-875a-fcbd2725596b", + "origin": "Delegated (Microsoft Graph)", + "value": "Content.Process.User" }, { - "description": "Allows the application to read and update printers without a signed-in user. Does not allow creating (registering) or deleting (unregistering) printers.", - "displayName": "Read and update printers", - "id": "f5b3f73d-6247-44df-a74c-866173fddab0", - "origin": "Application", - "value": "Printer.ReadWrite.All" + "description": "Read contents activity audit log from the audit store.", + "displayName": "Read contents activity audit log from the audit store.", + "id": "62c55b2f-a2b1-4312-8385-be57afd901b4", + "origin": "Delegated (Microsoft Graph)", + "value": "ContentActivity.Read" }, { - "description": "Allows the application to perform advanced operations like redirecting a print job to another printer without a signed-in user. Also allows the application to read and update the metadata of print jobs.", - "displayName": "Perform advanced operations on print jobs", - "id": "58a52f47-9e36-4b17-9ebe-ce4ef7f3e6c8", - "origin": "Application", - "value": "PrintJob.Manage.All" + "description": "Allows the application to upload bulk contents activity audit logs to the audit store.", + "displayName": "Upload contents activity audit logs to the audit store.", + "id": "948caae6-152a-48cd-a746-4844af30e8e9", + "origin": "Delegated (Microsoft Graph)", + "value": "ContentActivity.Write" }, { - "description": "Allows the application to read the metadata and document content of print jobs without a signed-in user.\u00a0", - "displayName": "Read print jobs", - "id": "ac6f956c-edea-44e4-bd06-64b1b4b9aec9", - "origin": "Application", - "value": "PrintJob.Read.All" + "description": "Allows the app to read available properties of contracts, on behalf of the signed-in user.", + "displayName": "Read contracts", + "id": "9df4d5b0-7921-4437-9ea8-adf0c9e276dc", + "origin": "Delegated (Microsoft Graph)", + "value": "Contracts.Read.All" }, { - "description": "Allows the application to read the metadata of print jobs without a signed-in user.\u00a0Does not allow access to print job document content.", - "displayName": "Read basic information for print jobs", - "id": "fbf67eee-e074-4ef7-b965-ab5ce1c1f689", - "origin": "Application", - "value": "PrintJob.ReadBasic.All" + "description": "Allows the app to delete Microsoft 365 Copilot conversations on behalf of the signed-in user.", + "displayName": "Delete Microsoft 365 Copilot conversations", + "id": "ed510a02-ac32-45f9-93e6-04864f7f7e47", + "origin": "Delegated (Microsoft Graph)", + "value": "CopilotConversation.Delete" }, { - "description": "Allows the application to read and update the metadata and document content of print jobs without a signed-in user.", - "displayName": "Read and write print jobs", - "id": "5114b07b-2898-4de7-a541-53b0004e2e13", - "origin": "Application", - "value": "PrintJob.ReadWrite.All" + "description": "Allows the user to read the packages information", + "displayName": "Read all packages information", + "id": "a2dcfcb9-cbe8-4d42-812d-952e55cf7f3f", + "origin": "Delegated (Microsoft Graph)", + "value": "CopilotPackages.Read.All" }, { - "description": "Allows the application to read and update the metadata of print jobs without a signed-in user.\u00a0Does not allow access to print job document content.", - "displayName": "Read and write basic information for print jobs", - "id": "57878358-37f4-4d3a-8c20-4816e0d457b1", - "origin": "Application", - "value": "PrintJob.ReadWriteBasic.All" + "description": "Allows the user to read and update the packages information", + "displayName": "Read and update all packages information", + "id": "e9c5fd18-ac15-43dd-9f5c-6f9611dd5604", + "origin": "Delegated (Microsoft Graph)", + "value": "CopilotPackages.ReadWrite.All" }, { - "description": "Allows the application to read and update print task definitions without a signed-in user.\u00a0", - "displayName": "Read, write and update print task definitions", - "id": "456b71a7-0ee0-4588-9842-c123fcc8f664", - "origin": "Application", - "value": "PrintTaskDefinition.ReadWrite.All" + "description": "Allows the app to read Copilot policy settings for the organization, on behalf of the signed-in user.", + "displayName": "Read Copilot policy settings", + "id": "b7281c63-cd4d-40c3-b721-73aa8ee7c3a8", + "origin": "Delegated (Microsoft Graph)", + "value": "CopilotPolicySettings.Read" }, { - "description": "Allows the app to create chat and channel messages, without a signed in user. The app specifies which user appears as the sender, and can backdate the message to appear as if it was sent long ago. The messages can be sent to any chat or channel in the organization.", - "displayName": "Create chat and channel messages with anyone's identity and with any timestamp", - "id": "dfb0dd15-61de-45b2-be36-d6a69fba3c79", - "origin": "Application", - "value": "Teamwork.Migrate.All" + "description": "Allows the app to read and write Copilot policy settings for the organization, on behalf of the signed-in user.", + "displayName": "Read and write Copilot policy settings", + "id": "e2edbde8-4448-4e49-8ebb-d53ba72df0f3", + "origin": "Delegated (Microsoft Graph)", + "value": "CopilotPolicySettings.ReadWrite" }, { - "description": "Allows the app to read the Teams apps that are installed in any chat, without a signed-in user. Does not give the ability to read application-specific settings.", - "displayName": "Read installed Teams apps for all chats", - "id": "cc7e7635-2586-41d6-adaa-a8d3bcad5ee5", - "origin": "Application", - "value": "TeamsAppInstallation.ReadForChat.All" + "description": "Allows the app to read organization-wide copilot limited mode setting on behalf of the signed-in user.", + "displayName": "Read organization-wide copilot limited mode setting", + "id": "aeb2982d-632d-4155-b533-18756ab6fdd8", + "origin": "Delegated (Microsoft Graph)", + "value": "CopilotSettings-LimitedMode.Read" }, { - "description": "Allows the app to read the Teams apps that are installed in any team, without a signed-in user. Does not give the ability to read application-specific settings.", - "displayName": "Read installed Teams apps for all teams", - "id": "1f615aea-6bf9-4b05-84bd-46388e138537", - "origin": "Application", - "value": "TeamsAppInstallation.ReadForTeam.All" + "description": "Allows the app to read and approve consent requests on behalf of the signed in user.", + "displayName": "Read and approve consent requests", + "id": "e694a3a1-7878-46d8-8c29-3d195f6589f4", + "origin": "Delegated (Microsoft Graph)", + "value": "ConsentRequest.ReadApprove.All" }, { - "description": "Allows the app to read the Teams apps that are installed for any user, without a signed-in user. Does not give the ability to read application-specific settings.", - "displayName": "Read installed Teams apps for all users", - "id": "9ce09611-f4f7-4abd-a629-a05450422a97", - "origin": "Application", - "value": "TeamsAppInstallation.ReadForUser.All" + "description": "Allows the app to read consent requests and approvals on behalf of the signed-in user.", + "displayName": "Read consent requests", + "id": "f3bfad56-966e-4590-a536-82ecf548ac1e", + "origin": "Delegated (Microsoft Graph)", + "value": "ConsentRequest.Read.All" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any chat, without a signed-in user. Does not give the ability to read application-specific settings.", - "displayName": "Manage Teams apps for all chats", - "id": "9e19bae1-2623-4c4f-ab6e-2664615ff9a0", - "origin": "Application", - "value": "TeamsAppInstallation.ReadWriteForChat.All" + "description": "Allows the app to read consent requests and approvals created by the signed-in user, on behalf of the signed-in user.", + "displayName": "Read consent requests created by the user", + "id": "5942b2f6-5a7b-40af-aa37-4b6ea5447506", + "origin": "Delegated (Microsoft Graph)", + "value": "ConsentRequest.Read" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any team, without a signed-in user. Does not give the ability to read application-specific settings.", - "displayName": "Manage Teams apps for all teams", - "id": "5dad17ba-f6cc-4954-a5a2-a0dcc95154f0", - "origin": "Application", - "value": "TeamsAppInstallation.ReadWriteForTeam.All" + "description": "Allows the app to read create consent requests on behalf of the signed-in user.", + "displayName": "Create consent requests", + "id": "f2143d35-9b4b-480d-951c-d083e69eeb2c", + "origin": "Delegated (Microsoft Graph)", + "value": "ConsentRequest.Create" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps for any user, without a signed-in user. Does not give the ability to read application-specific settings.", - "displayName": "Manage Teams apps for all users", - "id": "74ef0291-ca83-4d02-8c7e-d2391e6a444f", - "origin": "Application", - "value": "TeamsAppInstallation.ReadWriteForUser.All" + "description": "Read and write the names, descriptions, and settings of all channels, on behalf of the signed-in user.", + "displayName": "Read and write the names, descriptions, and settings of channels", + "id": "d649fb7c-72b4-4eec-b2b4-b15acf79e378", + "origin": "Delegated (Microsoft Graph)", + "value": "ChannelSettings.ReadWrite.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any chat, without a signed-in user.", - "displayName": "Allow the Teams app to manage itself for all chats", - "id": "73a45059-f39c-4baf-9182-4954ac0e55cf", - "origin": "Application", - "value": "TeamsAppInstallation.ReadWriteSelfForChat.All" + "description": "Allows the app to create chats on behalf of the signed-in user.", + "displayName": "Create chats", + "id": "38826093-1258-4dea-98f0-00003be2b8d0", + "origin": "Delegated (Microsoft Graph)", + "value": "Chat.Create" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in any team, without a signed-in user.", - "displayName": "Allow the Teams app to manage itself for all teams", - "id": "9f67436c-5415-4e7f-8ac1-3014a7132630", - "origin": "Application", - "value": "TeamsAppInstallation.ReadWriteSelfForTeam.All" + "description": "Allows the app to delete and recover deleted chats, on behalf of the signed-in user.", + "displayName": "Delete and recover deleted chats", + "id": "bb64e6fc-6b6d-4752-aea0-dd922dbba588", + "origin": "Delegated (Microsoft Graph)", + "value": "Chat.ManageDeletion.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself to any user, without a signed-in user.", - "displayName": "Allow the app to manage itself for all users", - "id": "908de74d-f8b2-4d6b-a9ed-2a17b3b78179", - "origin": "Application", - "value": "TeamsAppInstallation.ReadWriteSelfForUser.All" + "description": "Allows an app to read 1 on 1 or group chats threads, on behalf of the signed-in user.", + "displayName": "Read user chat messages", + "id": "f501c180-9344-439a-bca0-6cbf209fd270", + "origin": "Delegated (Microsoft Graph)", + "value": "Chat.Read" }, { - "description": "Allows the app to create teams without a signed-in user.\u00a0", - "displayName": "Create teams", - "id": "23fc2474-f741-46ce-8465-674744c5c361", - "origin": "Application", - "value": "Team.Create" + "description": "Allows an app to read the members and descriptions of one-to-one and group chat threads, on behalf of the signed-in user.", + "displayName": "Read names and members of user chat threads", + "id": "9547fcb5-d03f-419d-9948-5928bbf71b0f", + "origin": "Delegated (Microsoft Graph)", + "value": "Chat.ReadBasic" }, { - "description": "Add and remove members from all teams, without a signed-in user. Does not allow adding or removing a member with the owner role. Additionally, does not allow the app to elevate an existing member to the owner role.", - "displayName": "Add and remove members with non-owner role for all teams", - "id": "4437522e-9a86-4a41-a7da-e380edd4a97d", - "origin": "Application", - "value": "TeamMember.ReadWriteNonOwnerRole.All" + "description": "Allows an app to read and write 1 on 1 or group chats threads, on behalf of the signed-in user.", + "displayName": "Read and write user chat messages", + "id": "9ff7295e-131b-4d94-90e1-69fde507ac11", + "origin": "Delegated (Microsoft Graph)", + "value": "Chat.ReadWrite" }, { - "description": "Allows the app to read all term store data, without a signed-in user. This includes all sets, groups and terms in the term store.", - "displayName": "Read all term store data", - "id": "ea047cc2-df29-4f3e-83a3-205de61501ca", - "origin": "Application", - "value": "TermStore.Read.All" + "description": "Allows an app to read and write all one-to-one and group chats in Microsoft Teams, without a signed-in user. Does not allow sending messages.", + "displayName": "Read and write all chat messages", + "id": "7e9a077b-3711-42b9-b7cb-5fa5f3f7fea7", + "origin": "Delegated (Microsoft Graph)", + "value": "Chat.ReadWrite.All" }, { - "description": "Allows the app to read, edit or write all term store data, without a signed-in user. This includes all sets, groups and terms in the term store.", - "displayName": "Read and write all term store data", - "id": "f12eb8d6-28e3-46e6-b2c0-b7e4dc69fc95", - "origin": "Application", - "value": "TermStore.ReadWrite.All" + "description": "Read the members of chats, on behalf of the signed-in user.", + "displayName": "Read the members of chats", + "id": "c5a9e2b1-faf6-41d4-8875-d381aa549b24", + "origin": "Delegated (Microsoft Graph)", + "value": "ChatMember.Read" }, { - "description": "Allows the app to read your tenant's service health information, without a signed-in user. Health information may include service issues or service health overviews.", - "displayName": "Read service health", - "id": "79c261e0-fe76-4144-aad5-bdc68fbe4037", - "origin": "Application", - "value": "ServiceHealth.Read.All" + "description": "Allows the app to read restore sessions, on behalf of the signed in user.", + "displayName": "Read restore sessions", + "id": "94b36f78-434f-4904-8c08-421d9a9c1dc2", + "origin": "Delegated (Microsoft Graph)", + "value": "BackupRestore-Restore.Read.All" + }, + { + "description": "Add and remove members from chats, on behalf of the signed-in user.", + "displayName": "Add and remove members from chats", + "id": "dea13482-7ea6-488f-8b98-eb5bbecf033d", + "origin": "Delegated (Microsoft Graph)", + "value": "ChatMember.ReadWrite" }, { - "description": "Allows the app to read your tenant's service announcement messages, without a signed-in user. Messages may include information about new or changed features.", - "displayName": "Read service messages", - "id": "1b620472-6534-4fe6-9df2-4680e8aa28ec", - "origin": "Application", - "value": "ServiceMessage.Read.All" + "description": "Allows an app to send one-to-one and group chat messages in Microsoft Teams, on behalf of the signed-in user.", + "displayName": "Send user chat messages", + "id": "116b7235-7cc6-461e-b163-8e55691d839e", + "origin": "Delegated (Microsoft Graph)", + "value": "ChatMessage.Send" }, { - "description": "Allows the app to read all the short notes without a signed-in user.", - "displayName": "Read all users' short notes", - "id": "0c7d31ec-31ca-4f58-b6ec-9950b6b0de69", - "origin": "Application", - "value": "ShortNotes.Read.All" + "description": "Allows the app to read details of discovered cloud apps in the organization, on behalf of the signed in user.", + "displayName": "Read discovered cloud applications data", + "id": "ad46d60e-1027-4b75-af88-7c14ccf43a19", + "origin": "Delegated (Microsoft Graph)", + "value": "CloudApp-Discovery.Read.All" }, { - "description": "Allows the app to read, create, edit, and delete all the short notes without a signed-in user.", - "displayName": "Read, create, edit, and delete all users' short notes", - "id": "842c284c-763d-4a97-838d-79787d129bab", - "origin": "Application", - "value": "ShortNotes.ReadWrite.All" + "description": "Allows the app to read the properties of Cloud PCs on behalf of the signed-in user.", + "displayName": "Read Cloud PCs", + "id": "5252ec4e-fd40-4d92-8c68-89dd1d3c6110", + "origin": "Delegated (Microsoft Graph)", + "value": "CloudPC.Read.All" }, { - "description": "Allows the app to read your organization's conditional access policies, without a signed-in user.", - "displayName": "Read your organization's conditional access policies", - "id": "37730810-e9ba-4e46-b07e-8ca78d182097", - "origin": "Application", - "value": "Policy.Read.ConditionalAccess" + "description": "Allows the app to read and write the properties of Cloud PCs on behalf of the signed-in user.", + "displayName": "Read and write Cloud PCs", + "id": "9d77138f-f0e2-47ba-ab33-cd246c8b79d1", + "origin": "Delegated (Microsoft Graph)", + "value": "CloudPC.ReadWrite.All" }, { - "description": "Allows the app to read role-based access control (RBAC) settings for all RBAC providers without a signed-in user. This includes reading role definitions and role assignments.", - "displayName": "Read role management data for all RBAC providers", - "id": "c7fbd983-d9aa-4fa7-84b8-17382c103bc4", - "origin": "Application", - "value": "RoleManagement.Read.All" + "description": "Allows the app to list Viva Engage communities, and to read their properties on behalf of the signed-in user.", + "displayName": "Read all Viva Engage communities", + "id": "12ae2e92-14b5-47b2-babb-4e890bbedc0a", + "origin": "Delegated (Microsoft Graph)", + "value": "Community.Read.All" }, { - "description": "Allows the app to read all PSTN and direct routing call log data without a signed-in user.", - "displayName": "Read PSTN and direct routing call log data", - "id": "a2611786-80b3-417e-adaa-707d4261a5f0", - "origin": "Application", - "value": "CallRecord-PstnCalls.Read.All" + "description": "Allows the app to create Viva Engage communities and read all community properties on behalf of the signed-in user.", + "displayName": "Read and write all Viva Engage communities", + "id": "9e69467d-e0e2-402b-a926-3d796990197f", + "origin": "Delegated (Microsoft Graph)", + "value": "Community.ReadWrite.All" }, { - "description": "Allows the app to read all one-to-one and group chats messages in Microsoft Teams, without a signed-in user.", - "displayName": "Read all chat messages", - "id": "b9bb2381-47a4-46cd-aafb-00cb12f68504", - "origin": "Application", - "value": "ChatMessage.Read.All" + "description": "Allows the app to read all Configuration Monitoring entities on behalf of the signed-in user.", + "displayName": "Read all Configuration Monitoring entities", + "id": "c645bb69-adc4-4242-b620-02e635f03bf6", + "origin": "Delegated (Microsoft Graph)", + "value": "ConfigurationMonitoring.Read.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs for any chat, without a signed-in user.", - "displayName": "Allow the Teams app to manage all tabs for all chats", - "id": "fd9ce730-a250-40dc-bd44-8dc8d20f39ea", - "origin": "Application", - "value": "TeamsTab.ReadWriteForChat.All" + "description": "Allows the app to read and write all Configuration Monitoring entities on behalf of the signed-in user.", + "displayName": "Read and write all Configuration Monitoring entities", + "id": "54505ce9-e719-41f7-a7cc-dbe114e1d811", + "origin": "Delegated (Microsoft Graph)", + "value": "ConfigurationMonitoring.ReadWrite.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs in any team, without a signed-in user.", - "displayName": "Allow the Teams app to manage all tabs for all teams", - "id": "6163d4f4-fbf8-43da-a7b4-060fe85ed148", - "origin": "Application", - "value": "TeamsTab.ReadWriteForTeam.All" + "description": "Allows an app to read one-to-one and group chat messages, on behalf of the signed-in user.", + "displayName": "Read user chat messages", + "id": "cdcdac3a-fd45-410d-83ef-554db620e5c7", + "origin": "Delegated (Microsoft Graph)", + "value": "ChatMessage.Read" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs for any user, without a signed-in user.", - "displayName": "Allow the app to manage all tabs for all users", - "id": "425b4b59-d5af-45c8-832f-bb0b7402348a", - "origin": "Application", - "value": "TeamsTab.ReadWriteForUser.All" + "description": "Allows the app to read and write anonymous users' virtual event registrations, without a signed-in user", + "displayName": "Read and write anonymous users' virtual event registrations", + "id": "23211fc1-f9d1-4e8e-8e9e-08a5d0a109bb", + "origin": "Application (Microsoft Graph)", + "value": "VirtualEventRegistration-Anon.ReadWrite.All" }, { - "description": "Allows the app to read the API connectors used in user authentication flows, without a signed-in user.", - "displayName": "Read API connectors for authentication flows", - "id": "b86848a7-d5b1-41eb-a9b4-54a4e6306e97", - "origin": "Application", - "value": "APIConnectors.Read.All" + "description": "Allows the app to monitor backup and restore jobs, view quota usage and billing details, on behalf of the signed in user.", + "displayName": "Read monitoring, quota and billing information for the tenant", + "id": "b4e98de1-4600-4e90-b5e1-7c1dfef04e5c", + "origin": "Delegated (Microsoft Graph)", + "value": "BackupRestore-Monitor.Read.All" }, { - "description": "Allows the app to read, create and manage the API connectors used in user authentication flows, without a signed-in user.", - "displayName": "Read and write API connectors for authentication flows", - "id": "1dfe531a-24a6-4f1b-80f4-7a0dc5a0a171", - "origin": "Application", - "value": "APIConnectors.ReadWrite.All" + "description": "Allows the app to read the status of M365 backup service (enable/disable), on behalf of the signed in user.", + "displayName": "Read the status of the M365 backup service", + "id": "af598c63-4292-4437-b925-e996354d3854", + "origin": "Delegated (Microsoft Graph)", + "value": "BackupRestore-Control.Read.All" }, { - "description": "Read the members of all chats, without a signed-in user.", - "displayName": "Read the members of all chats", - "id": "a3410be2-8e48-4f32-8454-c29a7465209d", - "origin": "Application", - "value": "ChatMember.Read.All" + "description": "Allows the client to create agent identities on behalf of the signed-in user, even if the client is not the parent agent identity blueprint.", + "displayName": "Create agent identities without an agent blueprint parent", + "id": "e75eeac6-d759-4ba3-ae5c-773a27efafba", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentity.Create.All" }, { - "description": "Add and remove members from all chats, without a signed-in user.", - "displayName": "Add and remove members from all chats", - "id": "57257249-34ce-4810-a8a2-a03adf0c5693", - "origin": "Application", - "value": "ChatMember.ReadWrite.All" + "description": "Allows the client to delete and restore agent identities on behalf of the signed-in user.", + "displayName": "Delete and restore agent identities", + "id": "c8ee41e5-35e7-4fe9-8ecb-93493adcac5b", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentity.DeleteRestore.All" }, { - "description": "Allows the app to create chats without a signed-in user.\u00a0", - "displayName": "Create chats", - "id": "d9c48af6-9ad9-47ad-82c3-63757137b9af", - "origin": "Application", - "value": "Chat.Create" + "description": "Allows the client to enable or disable agent identities on behalf of the signed-in user.", + "displayName": "Enable or disable agent identities", + "id": "a501206a-e364-4a3f-be6e-765806d0e323", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentity.EnableDisable.All" }, { - "description": "Allows the application to read tenant-wide print settings without a signed-in user.", - "displayName": "Read tenant-wide print settings", - "id": "b5991872-94cf-4652-9765-29535087c6d8", - "origin": "Application", - "value": "PrintSettings.Read.All" + "description": "Allows the client to read all agent identities on behalf of the signed-in user.", + "displayName": "Read all agent identities", + "id": "5e850691-d86a-4b24-bfa6-8a52fb37a0c1", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentity.Read.All" }, { - "description": "Allows an app to read and write all browser site lists configured for your organization, without a signed-in user.", - "displayName": "Read and write all browser site lists for your organization", - "id": "8349ca94-3061-44d5-9bfb-33774ea5e4f9", - "origin": "Application", - "value": "BrowserSiteLists.ReadWrite.All" + "description": "Allows the client to read, update, create, and delete agent identities on behalf of the signed-in user.", + "displayName": "Read and write all agent identities", + "id": "4a4facd5-0ee1-49b7-a5b2-fdcc2491685e", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentity.ReadWrite.All" }, { - "description": "Allows the application to read and change the tenant-level settings of SharePoint and OneDrive, without a signed-in user.", - "displayName": "Read and change SharePoint and OneDrive tenant settings", - "id": "19b94e34-907c-4f43-bde9-38b1909ed408", - "origin": "Application", - "value": "SharePointTenantSettings.ReadWrite.All" + "description": "Allows updating agent identity blueprint credentials on behalf of the signed-in user.", + "displayName": "Update agent identity blueprint credentials", + "id": "75b5feb2-bfe7-423f-907d-cc505186f246", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentityBlueprint.AddRemoveCreds.All" }, { - "description": "Allows the app to read your organization's authentication event listeners without a signed-in user.", - "displayName": "Read all authentication event listeners", - "id": "b7f6385c-6ce6-4639-a480-e23c42ed9784", - "origin": "Application", - "value": "EventListener.Read.All" + "description": "Allows creating new agent identity blueprints on behalf of the signed-in user.", + "displayName": "Create agent identity blueprints.", + "id": "8fc15edd-ba24-494e-9bf6-d38e1b7ba8fd", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentityBlueprint.Create" }, { - "description": "Allows the app to read or write your organization's authentication event listeners without a signed-in user.", - "displayName": "Read and write all authentication event listeners", - "id": "0edf5e9e-4ce8-468a-8432-d08631d18c43", - "origin": "Application", - "value": "EventListener.ReadWrite.All" + "description": "Allows deleting or restoring agent identity blueprints on behalf of the signed-in user.", + "displayName": "Delete and restore agent identity blueprints.", + "id": "f12ba1f6-afb7-4685-9a30-21e8c3f551d8", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentityBlueprint.DeleteRestore.All" }, { - "description": "Allows the app to read your organization's custom authentication extensions without a signed-in user.", - "displayName": "Read all custom authentication extensions", - "id": "88bb2658-5d9e-454f-aacd-a3933e079526", - "origin": "Application", - "value": "CustomAuthenticationExtension.Read.All" + "description": "Allows the client to read all agent identity blueprints on behalf of the signed-in user.", + "displayName": "Read all agent identity blueprints", + "id": "26512dc8-1364-4e9f-867c-6d8b22a9e162", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentityBlueprint.Read.All" }, { - "description": "Allows the app to read all users\u2019 tasks and task lists in your organization, without a signed-in user.", - "displayName": "Read all users\u2019 tasks and tasklist", - "id": "f10e1f91-74ed-437f-a6fd-d6ae88e26c1f", - "origin": "Application", - "value": "Tasks.Read.All" + "description": "Allows the client to read, update, create, and delete agent identity blueprints on behalf of the signed-in user.", + "displayName": "Read and write all agent identity blueprints.", + "id": "4fd490fc-1467-48eb-8a4c-421597ab0402", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentityBlueprint.ReadWrite.All" }, { - "description": "Allows the app to create, update, list, read and delete all workflows, tasks and related lifecycle workflows resources without a signed-in user.", - "displayName": "Read and write all lifecycle workflows resources", - "id": "5c505cf4-8424-4b8e-aa14-ee06e3bb23e3", - "origin": "Application", - "value": "LifecycleWorkflows.ReadWrite.All" + "description": "Allows updating agent identity blueprint authorization and authentication properties on behalf of the signed-in user.", + "displayName": "Update agent identity blueprint authorization and authentication properties", + "id": "6f677aa9-25af-49a5-8a1d-628dc7f0d009", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentityBlueprint.UpdateAuthProperties.All" }, { - "description": "Allows an app to read all bookmarks without a signed-in user.", - "displayName": "Read all bookmarks", - "id": "be95e614-8ef3-49eb-8464-1c9503433b86", - "origin": "Application", - "value": "Bookmark.Read.All" + "description": "Allows updating agent identity blueprint branding on behalf of the signed-in user.", + "displayName": "Update agent identity blueprint branding", + "id": "60960e31-67cb-4d25-9d36-4922109923a2", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentityBlueprint.UpdateBranding.All" }, { - "description": "Allows the application to obtain basic tenant information about another target tenant within the Azure AD ecosystem without a signed-in user.", - "displayName": "Read cross-tenant basic information", - "id": "cac88765-0581-4025-9725-5ebc13f729ee", - "origin": "Application", - "value": "CrossTenantInformation.ReadBasic.All" + "description": "Allows creating new agent identity blueprint principals on behalf of the signed-in user.", + "displayName": "Create agent identity blueprint principals.", + "id": "00dcd896-6b23-42ce-b5de-c58493c05e22", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentityBlueprintPrincipal.Create" }, { - "description": "Allows the application to list and query any shared user profile information associated with the current tenant without a signed-in user.\u00a0 It also permits the application to export and remove external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant without a signed-in user.", - "displayName": "Read all shared cross-tenant user profiles and export or delete their data", - "id": "306785c5-c09b-4ba0-a4ee-023f3da165cb", - "origin": "Application", - "value": "CrossTenantUserProfileSharing.ReadWrite.All" + "description": "Allows deleting or restoring agent identity blueprint principals on behalf of the signed-in user.", + "displayName": "Delete and restore agent identity blueprint principals.", + "id": "2c70023e-a482-4af2-9ff1-51ded53e6bad", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentityBlueprintPrincipal.DeleteRestore.All" }, { - "description": "Allows the app to read all learning content in the organization's directory, without a signed-in user.", - "displayName": "Read all learning content", - "id": "8740813e-d8aa-4204-860e-2a0f8f84dbc8", - "origin": "Application", - "value": "LearningContent.Read.All" + "description": "Allows enabling or disabling agent identity blueprint principals on behalf of the signed-in user.", + "displayName": "Enable or disable agent identity blueprint principals.", + "id": "e7475e0a-9f02-43e2-a250-5c2ea74ccd0e", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentityBlueprintPrincipal.EnableDisable.All" }, { - "description": "Allows the app to read and update the authentication context information in your organization without a signed-in user.", - "displayName": "Read and write all authentication context information", - "id": "a88eef72-fed0-4bf7-a2a9-f19df33f8b83", - "origin": "Application", - "value": "AuthenticationContext.ReadWrite.All" + "description": "Allows reading agent identity blueprint principals on behalf of the signed-in user.", + "displayName": "Read agent identity blueprint principals.", + "id": "88c856a2-de61-4632-b2d4-ac503cbc8dd2", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentityBlueprintPrincipal.Read.All" }, { - "description": "Allows the app to read all admin report settings, such as whether to display concealed information in reports, without a signed-in user.", - "displayName": "Read all admin report settings", - "id": "ee353f83-55ef-4b78-82da-555bfa2b4b95", - "origin": "Application", - "value": "ReportSettings.Read.All" + "description": "Allows the app to read, update, create, and delete agent identity blueprint principals on behalf of the signed-in user.", + "displayName": "Read and write all agent identity blueprint principals.", + "id": "bf2cad6a-9082-438a-9a63-95fa2687af65", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentityBlueprintPrincipal.ReadWrite.All" }, { - "description": "Allows the app to read the members of all chats where the associated Teams application is installed, without a signed-in user.", - "displayName": "Read the members of all chats where the associated Teams application is installed.", - "id": "93e7c9e4-54c5-4a41-b796-f2a5adaacda7", - "origin": "Application", - "value": "ChatMember.Read.WhereInstalled" + "description": "Allows the app to read and update the communication configuration of agent blueprints on behalf of the signed-in user.", + "displayName": "Read and write agent communication configuration", + "id": "15e0db35-0641-4175-b014-c2cb39286338", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCommunicationConfiguration.ReadWrite" }, { - "description": "Allows the app to add and remove members from all chats where the associated Teams application is installed, without a signed-in user.", - "displayName": "Add and remove members from all chats where the associated Teams application is installed.", - "id": "e32c2cd9-0124-4e44-88fc-772cd98afbdb", - "origin": "Application", - "value": "ChatMember.ReadWrite.WhereInstalled" + "description": "Allows the app to create agent users, read and write the full set of profile properties, reports, and managers of agent ID users, delete and restore agent users in your organization, and read basic company properties, on behalf of the signed-in user.", + "displayName": "Read and write all agent ID users' full profiles", + "id": "ad57fb88-4658-4fd6-ab7d-e43184b08e4e", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdUser.ReadWrite.All" }, { - "description": "Allows the app to read your organization's threat submissions and to view threat submission policies without a signed-in user.", - "displayName": "Read all of the organization's threat submissions", - "id": "86632667-cd15-4845-ad89-48a88e8412e1", - "origin": "Application", - "value": "ThreatSubmission.Read.All" + "description": "Allows the app to read the communication configuration of agent blueprints on behalf of the signed-in user.", + "displayName": "Read agent communication configuration", + "id": "57ff8075-2fb3-4879-8693-5d51ee8d5e9e", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCommunicationConfiguration.Read" }, { - "description": "Allows an app to sign digests for data without a signed-in user.", - "displayName": "Sign digests for data", - "id": "cbe6c7e4-09aa-4b8d-b3c3-2dbb59af4b54", - "origin": "Application", - "value": "InformationProtectionContent.Sign.All" + "description": "Allows the app to read and update global collection and manage its membership in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read and write global collection in Agent Registry", + "id": "c001dd65-8a6b-4349-ab0c-4e8a410d28d2", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCollection.ReadWrite.Global" }, { - "description": "Allows the app to read your organization's threat submission policies without a signed-in user. Also allows the app to create new threat submission polices without a signed-in user.", - "displayName": "Read and write all of the organization's threat submission policies", - "id": "926a6798-b100-4a20-a22f-a4918f13951d", - "origin": "Application", - "value": "ThreatSubmissionPolicy.ReadWrite.All" + "description": "Allows the app to read and write all Windows update deployment settings for the organization without a signed-in user.", + "displayName": "Read and write all Windows update deployment settings", + "id": "7dd1be58-6e76-4401-bf8d-31d1e8180d5b", + "origin": "Application (Microsoft Graph)", + "value": "WindowsUpdates.ReadWrite.All" }, { - "description": "Allows the app to read all one-to-one or group chat messages in Microsoft Teams for chats where the associated Teams application is installed, without a signed-in user.", - "displayName": "Read all chat messages for chats where the associated Teams application is installed.", - "id": "1c1b4c8e-3cc7-4c58-8470-9b92c9d5848b", - "origin": "Application", - "value": "Chat.Read.WhereInstalled" + "description": "Allows the app to read workforce integrations without a signed-in user.", + "displayName": "Read workforce integrations", + "id": "f10b94b9-37d1-4c88-8b7e-bf75a1152d39", + "origin": "Application (Microsoft Graph)", + "value": "WorkforceIntegration.Read.All" }, { - "description": "Allows the app to read and write all chat messages in Microsoft Teams for chats where the associated Teams application is installed, without a signed-in user.", - "displayName": "Read and write all chat messages for chats where the associated Teams application is installed.", - "id": "ad73ce80-f3cd-40ce-b325-df12c33df713", - "origin": "Application", - "value": "Chat.ReadWrite.WhereInstalled" + "description": "Allows the app to manage workforce integrations to synchronize data from Microsoft Teams Shifts, without a signed-in user.", + "displayName": "Read and write workforce integrations", + "id": "202bf709-e8e6-478e-bcfd-5d63c50b68e3", + "origin": "Application (Microsoft Graph)", + "value": "WorkforceIntegration.ReadWrite.All" }, { - "description": "Allows the app to read and update all Azure AD recommendations, without a signed-in user. ", - "displayName": "Read and update all Azure AD recommendations", - "id": "0e9eea12-4f01-45f6-9b8d-3ea4c8144158", - "origin": "Application", - "value": "DirectoryRecommendations.ReadWrite.All" + "description": "Allows the app to read access reviews, reviewers, decisions and settings that the signed-in user has access to in the organization.", + "displayName": "Read all access reviews that user can access", + "id": "ebfcd32b-babb-40f4-a14b-42706e83bd28", + "origin": "Delegated (Microsoft Graph)", + "value": "AccessReview.Read.All" }, { - "description": "Allows the app to read all recordings of all online meetings, without a signed-in user.", - "displayName": "Read all recordings of online meetings.", - "id": "a4a08342-c95d-476b-b943-97e100569c8d", - "origin": "Application", - "value": "OnlineMeetingRecording.Read.All" + "description": "Allows the app to read, update, delete and perform actions on access reviews, reviewers, decisions and settings that the signed-in user has access to in the organization.", + "displayName": "Manage all access reviews that user can access", + "id": "e4aa47b9-9a69-4109-82ed-36ec70d85ff1", + "origin": "Delegated (Microsoft Graph)", + "value": "AccessReview.ReadWrite.All" }, { - "description": "Allows an app to manage license assignments for users and groups, without a signed-in user.", - "displayName": "Manage all license assignments", - "id": "5facf0c1-8979-4e95-abcf-ff3d079771c0", - "origin": "Application", - "value": "LicenseAssignment.ReadWrite.All" + "description": "Allows the app to read, update, delete and perform actions on access reviews, reviewers, decisions and settings for group and app memberships that the signed-in user has access to in the organization.", + "displayName": "Manage access reviews for group and app memberships", + "id": "5af8c3f5-baca-439a-97b0-ea58a435e269", + "origin": "Delegated (Microsoft Graph)", + "value": "AccessReview.ReadWrite.Membership" }, { - "description": "Allows the app to read and write the Teams app settings without a signed-in user.", - "displayName": "Read and write Teams app settings", - "id": "ab5b445e-8f10-45f4-9c79-dd3f8062cc4e", - "origin": "Application", - "value": "TeamworkAppSettings.ReadWrite.All" + "description": "Allows an app to read all acronyms that the signed-in user can access.", + "displayName": "Read all acronyms that the user can access", + "id": "9084c10f-a2d6-4713-8732-348def50fe02", + "origin": "Delegated (Microsoft Graph)", + "value": "Acronym.Read.All" }, { - "description": "Allows the app to read and write the lifecycle information like employeeLeaveDateTime of users in your organization, without a signed-in user.", - "displayName": "Read and write all users' lifecycle information", - "id": "925f1248-0f97-47b9-8ec8-538c54e01325", - "origin": "Application", - "value": "User-LifeCycleInfo.ReadWrite.All" + "description": "Allows the app to read administrative units and administrative unit membership on behalf of the signed-in user.", + "displayName": "Read administrative units", + "id": "3361d15d-be43-4de6-b441-3c746d05163d", + "origin": "Delegated (Microsoft Graph)", + "value": "AdministrativeUnit.Read.All" }, { - "description": "Allows the app to read all Azure AD recommendations, without a signed-in user. ", - "displayName": "Read all Azure AD recommendations", - "id": "ae73097b-cb2a-4447-b064-5d80f6093921", - "origin": "Application", - "value": "DirectoryRecommendations.Read.All" + "description": "Allows the app to create, read, update, and delete administrative units and manage administrative unit membership on behalf of the signed-in user.", + "displayName": "Read and write administrative units", + "id": "7b8a2d34-6b3f-4542-a343-54651608ad81", + "origin": "Delegated (Microsoft Graph)", + "value": "AdministrativeUnit.ReadWrite.All" + }, + { + "description": "Allows the app to read agent cards and their skills in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read agent cards in Agent Registry", + "id": "73ea6732-992c-4292-98f7-9feff18d3ade", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCard.Read.All" }, { - "description": "Allows the application to list and query any shared user profile information associated with the current tenant without a signed-in user.\u00a0 It also permits the application to export external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant without a signed-in user.", - "displayName": "Read all shared cross-tenant user profiles and export their data", - "id": "8b919d44-6192-4f3d-8a3b-f86f8069ae3c", - "origin": "Application", - "value": "CrossTenantUserProfileSharing.Read.All" + "description": "Allows the app to create, read, update, and delete agent cards and manage their skills in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read and write agent cards in Agent Registry", + "id": "b0f726a8-0fa2-4ce2-937b-fd17a446261f", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCard.ReadWrite.All" }, { - "description": "Allows the app to manage restricted resources based on the other permissions granted to the app, without a signed-in user.", - "displayName": "Manage restricted resources in the directory", - "id": "f20584af-9290-4153-9280-ff8bb2c0ea7f", - "origin": "Application", - "value": "Directory.Write.Restricted" + "description": "Allows the app to read agent card manifests in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read all agent card manifests in Agent Registry", + "id": "ada96a26-9579-4c29-a578-c3482a765716", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCardManifest.Read.All" }, { - "description": "Allows the app to read all transcripts of all online meetings, without a signed-in user.", - "displayName": "Read all transcripts of online meetings.", - "id": "a4a80d8d-d283-4bd8-8504-555ec3870630", - "origin": "Application", - "value": "OnlineMeetingTranscript.Read.All" + "description": "Allows the app to read and write agent card manifests in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read and write agent card manifests in Agent Registry", + "id": "80151b1a-1c31-4846-ae0d-c79939ee13d1", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCardManifest.ReadWrite.All" }, { - "description": "Allows\u00a0the\u00a0app\u00a0to\u00a0manage all learning\u00a0content\u00a0in\u00a0the\u00a0organization's\u00a0directory, without a signed-in user.", - "displayName": "Manage all\u00a0learning\u00a0content", - "id": "444d6fcb-b738-41e5-b103-ac4f2a2628a3", - "origin": "Application", - "value": "LearningContent.ReadWrite.All" + "description": "Allows the app to read collections and their membership in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read all collections in Agent Registry, except quarantined and global", + "id": "fa50be38-fdff-469c-96dc-ef5fce3c64bf", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCollection.Read.All" }, { - "description": "Allows the application to read the tenant-level settings of SharePoint and OneDrive, without a signed-in user.", - "displayName": "Read SharePoint and OneDrive tenant settings", - "id": "83d4163d-a2d8-4d3b-9695-4ae3ca98f888", - "origin": "Application", - "value": "SharePointTenantSettings.Read.All" + "description": "Allows the app to read global collection and its membership in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read global collection in Agent Registry", + "id": "b14924c8-87f1-438a-81f2-dc370ba2f45d", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCollection.Read.Global" }, { - "description": "Allows the app to read or write your organization's custom authentication extensions without a signed-in user.", - "displayName": "Read and write all custom authentication extensions", - "id": "c2667967-7050-4e7e-b059-4cbbb3811d03", - "origin": "Application", - "value": "CustomAuthenticationExtension.ReadWrite.All" + "description": "Allows the app to read quarantined collection and its membership in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read quarantined collection in Agent Registry", + "id": "43acfda3-daf3-4aa4-955d-b051d0024e82", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCollection.Read.Quarantined" }, { - "description": "Allows the app to read names and members of all one-to-one and group chats in Microsoft Teams where the associated Teams application is installed, without a signed-in user.", - "displayName": "Read names and members of all chat threads where the associated Teams application is installed.", - "id": "818ba5bd-5b3e-4fe0-bbe6-aa4686669073", - "origin": "Application", - "value": "Chat.ReadBasic.WhereInstalled" + "description": "Allows the app to create, read, update, and delete collections and manage their membership in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read and write collections in Agent Registry, except quarantined and global", + "id": "6d8a7002-a05e-4b95-a768-0e6f0badc6c8", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCollection.ReadWrite.All" }, { - "description": "Allows the app to list and read all workflows, tasks and related lifecycle workflows resources without a signed-in user.", - "displayName": "Read all lifecycle workflows resources", - "id": "7c67316a-232a-4b84-be22-cea2c0906404", - "origin": "Application", - "value": "LifecycleWorkflows.Read.All" + "description": "Allows the app to read and update quarantined collection and manage its membership in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read and write quarantined collection in Agent Registry", + "id": "ae331cc9-9f51-484b-a90b-124f2e4a6398", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCollection.ReadWrite.Quarantined" }, { - "description": "Allows the app to create protected content without a signed-in user. ", - "displayName": "Create protected content", - "id": "287bd98c-e865-4e8c-bade-1a85523195b9", - "origin": "Application", - "value": "InformationProtectionContent.Write.All" + "description": "Allows the app to create agent users, read and write the full set of profile properties, reports, and managers of agent ID users in your organization, delete and restore agent users under an agent blueprint, and read basic company properties, on behalf of the signed-in user.", + "displayName": "Read and write full profiles of agent ID users under an agent blueprint", + "id": "52a417d9-0b3c-4466-9a3b-66960de73d74", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdUser.ReadWrite.IdentityParentedBy" }, { - "description": "Allows the app to create, read, update and delete all users\u2019 tasks and task lists in your organization, without a signed-in user", - "displayName": "Read and write all users\u2019 tasks and tasklists", - "id": "44e666d1-d276-445b-a5fc-8815eeb81d55", - "origin": "Application", - "value": "Tasks.ReadWrite.All" + "description": "Allows the app to read agent instances and their related collections in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read all agent instances in Agent Registry", + "id": "4c3c738a-2df0-4877-bf4a-f796950ff34c", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentInstance.Read.All" }, { - "description": "Allows the app to read the Teams app settings without a signed-in user.", - "displayName": "Read Teams app settings", - "id": "475ebe88-f071-4bd7-af2b-642952bd4986", - "origin": "Application", - "value": "TeamworkAppSettings.Read.All" + "description": "Allows the app to create, read, update, and delete agent instances in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read and write agent instances in Agent Registry", + "id": "fc79e324-da24-497a-b5ec-e7de08320375", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentInstance.ReadWrite.All" }, { - "description": "Allows the app to read the authentication context information in your organization without a signed-in user.", - "displayName": "Read all authentication context information", - "id": "381f742f-e1f8-4309-b4ab-e3d91ae4c5c1", - "origin": "Application", - "value": "AuthenticationContext.Read.All" + "description": "Allows the app to read and respond to approvals on behalf of the signed-in user.", + "displayName": "Read and respond to approvals assigned to the current user", + "id": "89d944f2-2011-44ad-830c-aa9bf5ef2319", + "origin": "Delegated (Microsoft Graph)", + "value": "ApprovalSolutionResponse.ReadWrite" }, { - "description": "Allows the app to read and update all admin report settings, such as whether to display concealed information in reports, without a signed-in user.", - "displayName": "Read and write all admin report settings", - "id": "2a60023f-3219-47ad-baa4-40e17cd02a1d", - "origin": "Application", - "value": "ReportSettings.ReadWrite.All" + "description": "Allows the app to read attack simulation and training data for an organization for the signed-in user.", + "displayName": "Read attack simulation data of an organization", + "id": "104a7a4b-ca76-4677-b7e7-2f4bc482f381", + "origin": "Delegated (Microsoft Graph)", + "value": "AttackSimulation.Read.All" }, { - "description": "Allows an app to read all browser site lists configured for your organization, without a signed-in user.", - "displayName": "Read all browser site lists for your organization", - "id": "c5ee1f21-fc7f-4937-9af0-c91648ff9597", - "origin": "Application", - "value": "BrowserSiteLists.Read.All" + "description": "Allows the app to read, create, and update attack simulation and training data for an organization for the signed-in user.", + "displayName": "Read, create, and update attack simulation data of an organization", + "id": "27608d7c-2c66-4cad-a657-951d575f5a60", + "origin": "Delegated (Microsoft Graph)", + "value": "AttackSimulation.ReadWrite.All" }, { - "description": "Allows the app to read the lifecycle information like employeeLeaveDateTime of users in your organization, without a signed-in user.", - "displayName": "Read all users' lifecycle information", - "id": "8556a004-db57-4d7a-8b82-97a13428e96f", - "origin": "Application", - "value": "User-LifeCycleInfo.Read.All" + "description": "Read activity audit log from the audit store.", + "displayName": "Read activity audit log from the audit store.", + "id": "16786f81-40d2-4116-bb26-d1a753bf0b20", + "origin": "Delegated (Microsoft Graph)", + "value": "AuditActivity.Read" }, { - "description": "Allows an app to read all acronyms without a signed-in user.", - "displayName": "Read all acronyms", - "id": "8c0aed2c-0c61-433d-b63c-6370ddc73248", - "origin": "Application", - "value": "Acronym.Read.All" + "description": "Allows the application to upload bulk activity audit logs to the audit store.", + "displayName": "Upload activity audit logs to the audit store.", + "id": "a78fd341-0672-4792-a8ae-a5925b2546eb", + "origin": "Delegated (Microsoft Graph)", + "value": "AuditActivity.Write" }, { - "description": "Allows the app to see your users' basic profile (e.g., name, picture, user name, email address)", - "displayName": "View users' basic profile", - "id": "14dad69e-099b-42c9-810b-d002981feec1", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to see your basic profile (e.g., name, picture, user name, email address)", - "userConsentDisplayName": "View your basic profile", - "value": "profile" + "description": "Allows the app to read and query your audit log activities, on behalf of the signed-in user.", + "displayName": "Read audit log data", + "id": "e4c9e354-4dc5-45b8-9e7c-e1393b0b1a20", + "origin": "Delegated (Microsoft Graph)", + "value": "AuditLog.Read.All" }, { - "description": "Allows the app to read attack simulation and training data for an organization for the signed-in user.", - "displayName": "Read attack simulation data of an organization", - "id": "104a7a4b-ca76-4677-b7e7-2f4bc482f381", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read attack simulation and training data for an organization on your behalf.", - "userConsentDisplayName": "Read attack simulation data of an organization", - "value": "AttackSimulation.Read.All" + "description": "Allows the app to read and query audit logs from all services, on behalf of a signed-in user", + "displayName": "Read audit logs data from all services", + "id": "1d9e7ac3-0eca-442c-82f9-e92625af6e6d", + "origin": "Delegated (Microsoft Graph)", + "value": "AuditLogsQuery.Read.All" }, { - "description": "Allows the app to read and write your organization's directory access review default policy on behalf of the signed-in user.", - "displayName": "Read and write your organization's directory access review default policy", - "id": "4f5bc9c8-ea54-4772-973a-9ca119cb0409", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write your organization's directory access review default policy on your behalf.", - "userConsentDisplayName": "Read and write your organization's directory access review default policy", - "value": "Policy.ReadWrite.AccessReview" + "description": "Allows the app to read and query audit logs from Dynamics CRM workload, on behalf of the signed-in user.", + "displayName": "Read audit logs data from Dynamics CRM workload", + "id": "ba78b16f-1e01-41b6-89ca-73e0a32b304c", + "origin": "Delegated (Microsoft Graph)", + "value": "AuditLogsQuery-CRM.Read.All" }, { - "description": "Allows the app to read your organization's threat submissions and threat submission policies on behalf of the signed-in user. Also allows the app to create new threat submissions on behalf of the signed-in user.", - "displayName": "Read and write all threat submissions", - "id": "8458e264-4eb9-4922-abe9-768d58f13c7f", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your organization's threat submissions and threat submission policies on your behalf. Also allows the app to create new threat submissions on your behalf.", - "userConsentDisplayName": "Read and write all threat submissions", - "value": "ThreatSubmission.ReadWrite.All" + "description": "Allows the app to read and query audit logs from Endpoint Data Loss Prevention workload, on behalf of the signed-in user.", + "displayName": "Read audit logs data from Endpoint Data Loss Prevention workload", + "id": "ee3409fe-617f-43cf-bd1e-fc8b38049e69", + "origin": "Delegated (Microsoft Graph)", + "value": "AuditLogsQuery-Endpoint.Read.All" }, { - "description": "Allows the application to read any data from Records Management, such as configuration, labels, and policies on behalf of the signed-in user.", - "displayName": "Read Records Management configuration,\u00a0labels, and policies", - "id": "07f995eb-fc67-4522-ad66-2b8ca8ea3efd", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read any data from Records Management, such as configuration, labels and policies on your behalf.", - "userConsentDisplayName": "Read Records Management configuration,\u00a0labels, and policies", - "value": "RecordsManagement.Read.All" + "description": "Allows the app to read and query audit logs from Entra (Azure AD) workload, on behalf of the signed-in user.", + "displayName": "Read audit logs data from Entra (Azure AD) workload", + "id": "5ff2f415-e0f1-4d11-bfd0-6d87c0f667fd", + "origin": "Delegated (Microsoft Graph)", + "value": "AuditLogsQuery-Entra.Read.All" }, { - "description": "Allow the application to create, update and delete any data from Records Management, such as configuration, labels, and policies on behalf of the signed-in user.", - "displayName": "Read and write Records Management configuration, labels, and policies", - "id": "f2833d75-a4e6-40ab-86d4-6dfe73c97605", - "Origin": "Delegated", - "userConsentDescription": "Allow the application to create, update and delete any data from Records Management, such as configuration, labels, and policies on your behalf.", - "userConsentDisplayName": "Read and write Records Management configuration, labels, and policies", - "value": "RecordsManagement.ReadWrite.All" + "description": "Allows the app to read and query audit logs from Exchange workload, on behalf of a signed-in user.", + "displayName": "Read audit logs data from Exchange workload", + "id": "6c8c71d2-c7e1-45b0-ac6d-1d2724fba6ae", + "origin": "Delegated (Microsoft Graph)", + "value": "AuditLogsQuery-Exchange.Read.All" }, { - "description": "Allows the app to read details of delegated admin relationships with customers like access details (that includes roles) and the duration as well as specific role assignments to security groups on behalf of the signed-in user.", - "displayName": "Read Delegated Admin relationships with customers", - "id": "0c0064ea-477b-4130-82a5-4c2cc4ff68aa", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read details of Delegated Admin relationships with customers like access details (that includes roles) and the duration as well as specific role assignments to security groups on your behalf.", - "userConsentDisplayName": "Read Delegated Admin relationships with customers", - "value": "DelegatedAdminRelationship.Read.All" + "description": "Allows the app to read and query audit logs from OneDrive workload, on behalf of a signed-in user.", + "displayName": "Read audit logs data from OneDrive workload", + "id": "4a72c235-a50d-4870-b598-fd88fd1fa074", + "origin": "Delegated (Microsoft Graph)", + "value": "AuditLogsQuery-OneDrive.Read.All" }, { - "description": "Allows the app to manage (create-update-terminate) Delegated Admin relationships with customers as well as role assignments to security groups for active Delegated Admin relationships on behalf of the signed-in user.", - "displayName": "Manage Delegated Admin relationships with customers", - "id": "885f682f-a990-4bad-a642-36736a74b0c7", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to manage (create-update-terminate) Delegated Admin relationships with customers and role assignments to security groups for active Delegated Admin relationships on your behalf.", - "userConsentDisplayName": "Manage Delegated Admin relationships with customers", - "value": "DelegatedAdminRelationship.ReadWrite.All" + "description": "Allows the app to read and query audit logs from SharePoint workload, on behalf of a signed-in user.", + "displayName": "Read audit logs data from SharePoint workload", + "id": "30630b65-ed12-4a81-9130-e3a964109fae", + "origin": "Delegated (Microsoft Graph)", + "value": "AuditLogsQuery-SharePoint.Read.All" }, { - "description": "Allows the app to read and write all managed tenant information on behalf of the signed-in user.", - "displayName": "Read and write all managed tenant information", - "id": "b31fa710-c9b3-4d9e-8f5e-8036eecddab9", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write all managed tenant information on your behalf.", - "userConsentDisplayName": "Read and write all managed tenant information", - "value": "ManagedTenants.ReadWrite.All" + "description": "Allows the app to read all authentication context information in your organization on behalf of the signed-in user.", + "displayName": "Read all authentication context information", + "id": "57b030f1-8c35-469c-b0d9-e4a077debe70", + "origin": "Delegated (Microsoft Graph)", + "value": "AuthenticationContext.Read.All" }, { - "description": "Allows the app to read all managed tenant information on behalf of the signed-in user.", - "displayName": "Read all managed tenant information", - "id": "dc34164e-6c4a-41a0-be89-3ae2fbad7cd3", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all managed tenant information on your behalf.", - "userConsentDisplayName": "Read all managed tenant information", - "value": "ManagedTenants.Read.All" + "description": "Allows the app to read and update all authentication context information in your organization on behalf of the signed-in user.", + "displayName": "Read and write all authentication context information", + "id": "ba6d575a-1344-4516-b777-1404f5593057", + "origin": "Delegated (Microsoft Graph)", + "value": "AuthenticationContext.ReadWrite.All" }, { - "description": "Allows the app to read and manage the Cloud PC role-based access control (RBAC) settings, on behalf of the signed-in user. This includes reading and managing Cloud PC role definitions and role assignments.", - "displayName": "Read and write Cloud PC RBAC settings", - "id": "501d06f8-07b8-4f18-b5c6-c191a4af7a82", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and manage the Cloud PC role-based access control (RBAC) settings, on your behalf. This includes reading and managing Cloud PC role definitions and memberships.", - "userConsentDisplayName": "Read and write Cloud PC RBAC settings", - "value": "RoleManagement.ReadWrite.CloudPC" + "description": "Allows the app to read the backup configuration, and list of Microsoft 365 service resources to be backed-up, on behalf of the signed in user.", + "displayName": "Read backup configuration policies", + "id": "444ed4b6-0554-4dc6-8e9c-3f9a34ee3ff6", + "origin": "Delegated (Microsoft Graph)", + "value": "BackupRestore-Configuration.Read.All" }, { - "description": "Allows the app to read the Cloud PC role-based access control (RBAC) settings, on behalf of the signed-in user.\u00a0 This includes reading Cloud PC role definitions and role assignments.", - "displayName": "Read Cloud PC RBAC settings", - "id": "9619b88a-8a25-48a7-9571-d23be0337a79", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the Cloud PC role-based access control (RBAC) settings, on your behalf.\u00a0 This includes reading Cloud PC role definitions and role assignments.", - "userConsentDisplayName": "Read Cloud PC RBAC settings", - "value": "RoleManagement.Read.CloudPC" + "description": "Allows the app to read and update the backup configuration, and list of Microsoft 365 service resources to be backed-up, on behalf of the signed in user.", + "displayName": "Read and edit backup configuration policies", + "id": "a0244d16-171c-4496-8ffb-7b9b6954d339", + "origin": "Delegated (Microsoft Graph)", + "value": "BackupRestore-Configuration.ReadWrite.All" }, { - "description": "Allows the app to read and write settings of external connections on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read and write settings of connections that it is authorized to.", - "displayName": "Read and write external connections", - "id": "4082ad95-c812-4f02-be92-780c4c4f1830", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write external connections on your behalf. The signed-in user must be an administrator. The app can only read and write external connections that it is authorized to, or it can create new external connections. ", - "userConsentDisplayName": "Read and write external connections", - "value": "ExternalConnection.ReadWrite.OwnedBy" + "description": "Allows the app to provision, read, create, and respond to approvals on behalf of the signed-in user.", + "displayName": "Read, create, and respond to approvals", + "id": "6768d3af-4562-48ff-82d2-c5e19eb21b9c", + "origin": "Delegated (Microsoft Graph)", + "value": "ApprovalSolution.ReadWrite" }, { - "description": "Allows the app to read all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", - "displayName": "Read all external connections", - "id": "a38267a5-26b6-4d76-9493-935b7599116b", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all external connections on your behalf. The signed-in user must be an administrator.", - "userConsentDisplayName": "Read all external connections", - "value": "ExternalConnection.Read.All" + "description": "Allows the app to read approvals on behalf of the signed-in user.", + "displayName": "Read approvals", + "id": "b0df437d-d341-4df0-aa3e-89ca81a1207f", + "origin": "Delegated (Microsoft Graph)", + "value": "ApprovalSolution.Read" }, { - "description": "Allows the app to read and write all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", - "displayName": "Read and write all external connections", - "id": "bbbbd9b3-3566-4931-ac37-2b2180d9e334", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write all external connections on your behalf. The signed-in user must be an administrator.", - "userConsentDisplayName": "Read and write all external connections", - "value": "ExternalConnection.ReadWrite.All" + "description": "Allows the app to manage permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", + "displayName": "Manage app permission grants and app role assignments", + "id": "84bccea3-f856-4a8a-967b-dbe0a3d53a64", + "origin": "Delegated (Microsoft Graph)", + "value": "AppRoleAssignment.ReadWrite.All" }, { - "description": "Allows the app to read and write external items on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read external items of the connection that it is authorized to.", - "displayName": "Read and write external items", - "id": "4367b9d7-cee7-4995-853c-a0bdfe95c1f9", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write external items on your behalf. The signed-in user must be an administrator. The app can only read external items of the connection that it is authorized to.", - "userConsentDisplayName": "Read and write external items", - "value": "ExternalItem.ReadWrite.OwnedBy" + "description": "Allows the app to read and write other apps' remote desktop security configuration, on behalf of the signed-in user.", + "displayName": "Read and write the remote desktop security configuration for apps", + "id": "ffa91d43-2ad8-45cc-b592-09caddeb24bb", + "origin": "Delegated (Microsoft Graph)", + "value": "Application-RemoteDesktopConfig.ReadWrite.All" }, { - "description": "Allows the app to read and write all external items on behalf of a signed-in user. The signed-in user must be an administrator.", - "displayName": "Read and write all external items", - "id": "b02c54f8-eb48-4c50-a9f0-a149e5a2012f", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write all external items on your behalf. The signed-in user must be an administrator.", - "userConsentDisplayName": "Read and write all external items", - "value": "ExternalItem.ReadWrite.All" + "description": "Allows the user to read all agent registration information", + "displayName": "Read all agent registrations", + "id": "ef96ce0b-b2ea-4ae4-a783-108212d8ecee", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentRegistration.Read.All" }, { - "description": "Allows the app to read custom security attribute assignments for all principals in the tenant on behalf of a signed in user.", - "displayName": "Read custom security attribute assignments", - "id": "b46ffa80-fe3d-4822-9a1a-c200932d54d0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read custom security attribute assignments for all principals in the tenant on your behalf.", - "userConsentDisplayName": "Read custom security attribute assignments", - "value": "CustomSecAttributeAssignment.Read.All" + "description": "Allows the user to read and write all agent registration information", + "displayName": "Read and write all agent registrations", + "id": "20f263bf-7d50-4e66-912c-16b4b4194fd4", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentRegistration.ReadWrite.All" }, { - "description": "Allows the app to read custom security attribute definitions for the tenant on behalf of a signed in user.", - "displayName": "Read custom security attribute definitions", - "id": "ce026878-a0ff-4745-a728-d4fedd086c07", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read custom security attribute definitions for the tenant on your behalf.", - "userConsentDisplayName": "Read custom security attribute definitions", - "value": "CustomSecAttributeDefinition.Read.All" + "description": "Allows the app to read terms of use agreements on behalf of the signed-in user.", + "displayName": "Read all terms of use agreements", + "id": "af2819c9-df71-4dd3-ade7-4d7c9dc653b7", + "origin": "Delegated (Microsoft Graph)", + "value": "Agreement.Read.All" }, { - "description": "Allows the app to read and write your organization's cross tenant access policies on behalf of the signed-in user.", - "displayName": "Read and write your organization's cross tenant access policies", - "id": "014b43d0-6ed4-4fc6-84dc-4b6f7bae7d85", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write your organization's cross tenant access policies on your behalf.", - "userConsentDisplayName": "Read and write your organization's cross tenant access policies", - "value": "Policy.ReadWrite.CrossTenantAccess" + "description": "Allows the app to read and write terms of use agreements on behalf of the signed-in user.", + "displayName": "Read and write all terms of use agreements", + "id": "ef4b5d93-3104-4664-9053-a5c49ab44218", + "origin": "Delegated (Microsoft Graph)", + "value": "Agreement.ReadWrite.All" }, { - "description": "Allows the app to read and write tags in Teams, on behalf of the signed-in user.", - "displayName": "Read and write tags in Teams", - "id": "539dabd7-b5b6-4117-b164-d60cd15a8671", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write tags in Teams, on your behalf.", - "userConsentDisplayName": "Read and write tags in Teams", - "value": "TeamworkTag.ReadWrite" + "description": "Allows the app to read terms of use acceptance statuses on behalf of the signed-in user.", + "displayName": "Read user terms of use acceptance statuses", + "id": "0b7643bb-5336-476f-80b5-18fbfbc91806", + "origin": "Delegated (Microsoft Graph)", + "value": "AgreementAcceptance.Read" }, { - "description": "Allows the app to read tags in Teams, on behalf of the signed-in user.", - "displayName": "Read tags in Teams", - "id": "57587d0b-8399-45be-b207-8050cec54575", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read tags in Teams, on your behalf.", - "userConsentDisplayName": "Read tags in Teams", - "value": "TeamworkTag.Read" + "description": "Allows the app to read terms of use acceptance statuses on behalf of the signed-in user.", + "displayName": "Read terms of use acceptance statuses that user can access", + "id": "a66a5341-e66e-4897-9d52-c2df58c2bfb9", + "origin": "Delegated (Microsoft Graph)", + "value": "AgreementAcceptance.Read.All" }, { - "description": "Allows the app to read and write security incidents, on behalf of the signed-in user.", - "displayName": "Read and write to incidents", - "id": "128ca929-1a19-45e6-a3b8-435ec44a36ba", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write to all security incidents that you have access to.", - "userConsentDisplayName": "Read and write to security incidents", - "value": "SecurityIncident.ReadWrite.All" + "description": "Allows the app to read user AI enterprise interactions, on behalf of the signed-in user.", + "displayName": "Read user AI enterprise interactions.", + "id": "859cceb9-2ec2-4e48-bcd7-b8490b5248a5", + "origin": "Delegated (Microsoft Graph)", + "value": "AiEnterpriseInteraction.Read" }, { - "description": "Allows the app to read security incidents, on behalf of the signed-in user.", - "displayName": "Read incidents", - "id": "b9abcc4f-94fc-4457-9141-d20ce80ec952", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all security incidents that you have access to.", - "userConsentDisplayName": "Read security incidents", - "value": "SecurityIncident.Read.All" + "description": "Allows the app to read the signed-in user's activity statistics, such as how much time the user has spent on emails, in meetings, or in chat sessions.", + "displayName": "Read user activity statistics", + "id": "e03cf23f-8056-446a-8994-7d93dfc8b50e", + "origin": "Delegated (Microsoft Graph)", + "value": "Analytics.Read" }, { - "description": "Allows the app to read and write to all security alerts, on behalf of the signed-in user.", - "displayName": "Read and write to all security alerts", - "id": "471f2a7f-2a42-4d45-a2bf-594d0838070d", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write all alerts that you have access to.", - "userConsentDisplayName": "Read and write all alerts", - "value": "SecurityAlert.ReadWrite.All" + "description": "Allows the app to update or read the status of M365 backup service (enable/disable), on behalf of the signed in user.", + "displayName": "Update or read the status of the M365 backup service", + "id": "96d46335-d92d-41b8-bc9f-273a692381ea", + "origin": "Delegated (Microsoft Graph)", + "value": "BackupRestore-Control.ReadWrite.All" }, { - "description": "Allows the app to read all security alerts, on behalf of the signed-in user.", - "displayName": "Read all security alerts", - "id": "bc257fb8-46b4-4b15-8713-01e91bfbe4ea", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all security alerts that you have access to.", - "userConsentDisplayName": "Read all alerts", - "value": "SecurityAlert.Read.All" + "description": "Allows the app to read the API connectors used in user authentication flows, on behalf of the signed-in user.", + "displayName": "Read API connectors for authentication flows", + "id": "1b6ff35f-31df-4332-8571-d31ea5a4893f", + "origin": "Delegated (Microsoft Graph)", + "value": "APIConnectors.Read.All" }, { - "description": "Allows the app to update service announcement messages' user status on behalf of the signed-in user. The message status can be marked as read, archive, or favorite.", - "displayName": "Update user status on service announcement messages", - "id": "636e1b0b-1cc2-4b1c-9aa9-4eeed9b9761b", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to update service announcement messages' status on your behalf. Your status for messages can be marked as read, archive, or favorite.", - "userConsentDisplayName": "Update your user status on service announcement messages", - "value": "ServiceMessageViewpoint.Write" + "description": "Allows the app to read the apps in the app catalogs.", + "displayName": "Read all app catalogs", + "id": "88e58d74-d3df-44f3-ad47-e89edf4472e4", + "origin": "Delegated (Microsoft Graph)", + "value": "AppCatalog.Read.All" }, { - "description": "Allows the app to run hunting queries, on behalf of the signed-in user.", - "displayName": "Run hunting queries", - "id": "b152eca8-ea73-4a48-8c98-1a6742673d99", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to run hunting queries that you can execute.", - "userConsentDisplayName": "Run hunting queries", - "value": "ThreatHunting.Read.All" + "description": "Allows the app to create, read, update, and delete apps in the app catalogs.", + "displayName": "Read and write to all app catalogs", + "id": "1ca167d5-1655-44a1-8adf-1414072e1ef9", + "origin": "Delegated (Microsoft Graph)", + "value": "AppCatalog.ReadWrite.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself to teams the signed-in user can access.", - "displayName": "Allow the app to manage itself in teams", - "id": "0f4595f7-64b1-4e13-81bc-11a249df07a9", - "Origin": "Delegated", - "userConsentDescription": "Allows a Teams app to read, install, upgrade, and uninstall itself to teams you can access.", - "userConsentDisplayName": "Allow the Teams app to manage itself in teams", - "value": "TeamsAppInstallation.ReadWriteSelfForTeam" + "description": "Allows the app to submit application packages to the catalog and cancel submissions that are pending review on behalf of the signed-in user.", + "displayName": "Submit application packages to the catalog and cancel pending submissions", + "id": "3db89e36-7fa6-4012-b281-85f3d9d9fd2e", + "origin": "Delegated (Microsoft Graph)", + "value": "AppCatalog.Submit" }, { - "description": "Allow the app to read the management data for Teams devices on behalf of the signed-in user.", - "displayName": "Read Teams devices", - "id": "b659488b-9d28-4208-b2be-1c6652b3c970", - "Origin": "Delegated", - "userConsentDescription": "Allow the app to read the management data for Teams devices on your behalf.", - "userConsentDisplayName": "Read Teams devices", - "value": "TeamworkDevice.Read.All" + "description": "Allows the app to read the trusted certificate authority configuration which can be used to restrict application certificates based on their issuing authority, on behalf of the signed-in user.", + "displayName": "Read the trusted certificate authority configuration for applications", + "id": "af281d3a-030d-4122-886e-146fb30a0413", + "origin": "Delegated (Microsoft Graph)", + "value": "AppCertTrustConfiguration.Read.All" }, { - "description": "Allow the app to read and write the management data for Teams devices on behalf of the signed-in user.", - "displayName": "Read and write Teams devices", - "id": "ddd97ecb-5c31-43db-a235-0ee20e635c40", - "Origin": "Delegated", - "userConsentDescription": "Allow the app to read and write the management data for Teams devices on your behalf.", - "userConsentDisplayName": "Read and write Teams devices", - "value": "TeamworkDevice.ReadWrite.All" + "description": "Allows the app to create, read, update and delete the trusted certificate authority configuration which can be used to restrict application certificates based on their issuing authority, on behalf of the signed-in user.", + "displayName": "Read and write the trusted certificate authority configuration for applications", + "id": "4bae2ed4-473e-4841-a493-9829cfd51d48", + "origin": "Delegated (Microsoft Graph)", + "value": "AppCertTrustConfiguration.ReadWrite.All" }, { - "description": "Allows the app to read all identity risky service principal information for your organization, on behalf of the signed-in user.", - "displayName": "Read all identity risky service principal information", - "id": "ea5c4ab0-5a73-4f35-8272-5d5337884e5d", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all identity risky service principal information for your organization, on your behalf.", - "userConsentDisplayName": "Read all identity risky service principal information", - "value": "IdentityRiskyServicePrincipal.Read.All" + "description": "Allows the app to read applications and service principals on behalf of the signed-in user.", + "displayName": "Read applications", + "id": "c79f8feb-a9db-4090-85f9-90d820caa0eb", + "origin": "Delegated (Microsoft Graph)", + "value": "Application.Read.All" }, { - "description": "Allows the app to read and update identity risky service principal information for all service principals in your organization, on behalf of the signed-in user. Update operations include dismissing risky service principals.", - "displayName": "Read and write all identity risky service principal information", - "id": "bb6f654c-d7fd-4ae3-85c3-fc380934f515", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and update identity risky service principal information for all service principals in your organization, on your behalf. Update operations include dismissing risky service principals.", - "userConsentDisplayName": "Read and write all identity risky service principal information", - "value": "IdentityRiskyServicePrincipal.ReadWrite.All" + "description": "Allows the app to read and update all apps in your organization, on behalf of the signed-in user.", + "displayName": "Read and update all apps", + "id": "0586a906-4d89-4de8-b3c8-1aacdcc0c679", + "origin": "Delegated (Microsoft Graph)", + "value": "Application.ReadUpdate.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs to teams the signed-in user can access.", - "displayName": "Allow the Teams app to manage only its own tabs in teams", - "id": "f266662f-120a-4314-b26a-99b08617c7ef", - "Origin": "Delegated", - "userConsentDescription": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs to teams you can access.", - "userConsentDisplayName": "Allow the Teams app to manage only its own tabs in teams", - "value": "TeamsTab.ReadWriteSelfForTeam" + "description": "Allows the app to create, read, update and delete applications and service principals on behalf of the signed-in user. Allows management of app role assignments, except those exposed by Microsoft Graph. Does not allow management of delegated permission grants.", + "displayName": "Read and write applications", + "id": "bdfbf15f-ee85-4955-8675-146e8e5296b5", + "origin": "Delegated (Microsoft Graph)", + "value": "Application.ReadWrite.All" }, { - "description": "Allows the app to read the presence information and write activity and availability on behalf of the signed-in user. Presence information includes activity, availability, status note, calendar out-of-office message, timezone and location.", - "displayName": "Read and write a user's presence information", - "id": "8d3c54a7-cf58-4773-bf81-c0cd6ad522bb", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the presence information and write activity and availability on your behalf. Presence information includes activity, availability, status note, calendar out-of-office message, timezone and location.", - "userConsentDisplayName": "Read and write your presence information", - "value": "Presence.ReadWrite" + "description": "Allows the app to read, create and manage the API connectors used in user authentication flows, on behalf of the signed-in user.", + "displayName": "Read and write API connectors for authentication flows", + "id": "c67b52c5-7c69-48b6-9d48-7b3af3ded914", + "origin": "Delegated (Microsoft Graph)", + "value": "APIConnectors.ReadWrite.All" }, { - "description": "Allows the app to read subject rights requests on behalf of the signed-in user", - "displayName": "Read subject rights requests", - "id": "9c3af74c-fd0f-4db4-b17a-71939e2a9d77", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read subject rights requests on your behalf.", - "userConsentDisplayName": "Read data subject requests", - "value": "SubjectRightsRequest.Read.All" + "description": "Allows the app to read eDiscovery objects such as cases, custodians, review sets and other related objects without a signed-in user.", + "displayName": "Read all eDiscovery objects", + "id": "50180013-6191-4d1e-a373-e590ff4e66af", + "origin": "Application (Microsoft Graph)", + "value": "eDiscovery.Read.All" }, { - "description": "Allows the app to read and write subject rights requests on behalf of the signed-in user", - "displayName": "Read and write subject rights requests", - "id": "2b8fcc74-bce1-4ae3-a0e8-60c53739299d", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write subject rights requests on your behalf.", - "userConsentDisplayName": "Read and write data subject requests", - "value": "SubjectRightsRequest.ReadWrite.All" + "description": "Allows the app to read, create, edit, and delete all the short notes without a signed-in user.", + "displayName": "Read, create, edit, and delete all users' short notes", + "id": "842c284c-763d-4a97-838d-79787d129bab", + "origin": "Application (Microsoft Graph)", + "value": "ShortNotes.ReadWrite.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for the signed-in user.", - "displayName": "Allow the Teams app to manage only its own tabs for a user", - "id": "395dfec1-a0b9-465f-a783-8250a430cb8c", - "Origin": "Delegated", - "userConsentDescription": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for you.", - "userConsentDisplayName": "Allow the Teams app to manage only its own tabs for you", - "value": "TeamsTab.ReadWriteSelfForUser" + "description": "Allows the application to read and change the tenant-level settings of SharePoint and OneDrive, without a signed-in user.", + "displayName": "Read and change SharePoint and OneDrive tenant settings", + "id": "19b94e34-907c-4f43-bde9-38b1909ed408", + "origin": "Application (Microsoft Graph)", + "value": "SharePointTenantSettings.ReadWrite.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs in chats the signed-in user can access.", - "displayName": "Allow the Teams app to manage only its own tabs in chats", - "id": "0c219d04-3abf-47f7-912d-5cca239e90e6", - "Origin": "Delegated", - "userConsentDescription": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs in chats you can access.", - "userConsentDisplayName": "Allow the Teams app to manage only its own tabs in chats", - "value": "TeamsTab.ReadWriteSelfForChat" + "description": "Allows the app to list and read all workflows, tasks and related lifecycle workflows resources without a signed-in user.", + "displayName": "Read all lifecycle workflows resources", + "id": "7c67316a-232a-4b84-be22-cea2c0906404", + "origin": "Application (Microsoft Graph)", + "value": "LifecycleWorkflows.Read.All" }, { - "description": "Allows the app to read and write search configuration, on behalf of the signed-in user.", - "displayName": "Read and write your organization's search configuration", - "id": "b1a7d408-cab0-47d2-a2a5-a74a3733600d", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write search configuration, on your behalf.", - "userConsentDisplayName": "Read and write your organization's search configuration", - "value": "SearchConfiguration.ReadWrite.All" + "description": "Allows the app to create, update, list, read and delete all workflows, tasks and related lifecycle workflows resources without a signed-in user.", + "displayName": "Read and write all lifecycle workflows resources", + "id": "5c505cf4-8424-4b8e-aa14-ee06e3bb23e3", + "origin": "Application (Microsoft Graph)", + "value": "LifecycleWorkflows.ReadWrite.All" }, { - "description": "Allows the app to read search configuration, on behalf of the signed-in user.", - "displayName": "Read your organization's search configuration", - "id": "7d307522-aa38-4cd0-bd60-90c6f0ac50bd", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read search configuration, on your behalf.", - "userConsentDisplayName": "Read your organization's search configuration", - "value": "SearchConfiguration.Read.All" + "description": "Allows the app to read all Lifecycle workflows custom task extensions without a signed-in user.", + "displayName": "Read all Lifecycle workflows custom task extensionss", + "id": "2cb19e7d-9012-40bf-9a22-69fc776af8b0", + "origin": "Application (Microsoft Graph)", + "value": "LifecycleWorkflows-CustomExt.Read.All" }, { - "description": "Allows the app to read online meeting artifacts on behalf of the signed-in user.", - "displayName": "Read user's online meeting artifacts", - "id": "110e5abb-a10c-4b59-8b55-9b4daa4ef743", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read online meeting artifacts on your behalf.", - "userConsentDisplayName": "Read user's online meeting artifacts", - "value": "OnlineMeetingArtifact.Read.All" + "description": "Allows the app to create, update, list, read and delete all Lifecycle workflows custom task extensions without a signed-in user.", + "displayName": "Read and write all Lifecycle workflows custom task extensions", + "id": "3351c766-bacc-4d93-94fa-f2c8b1986ee7", + "origin": "Application (Microsoft Graph)", + "value": "LifecycleWorkflows-CustomExt.ReadWrite.All" }, { - "description": "Allows the app to read and manage the active role-based access control (RBAC) assignments for your company's directory, on behalf of the signed-in user. This includes managing active directory role membership, and reading directory role templates, directory roles and active memberships.", - "displayName": "Read, update, and delete all active role assignments for your company's directory", - "id": "8c026be3-8e26-4774-9372-8d5d6f21daff", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and manage the active role-based access control (RBAC) assignments for your company's directory, on your behalf. This includes managing active directory role membership, and reading directory role templates, directory roles and active memberships.", - "userConsentDisplayName": "Read, update, and delete all active role assignments for your company's directory", - "value": "RoleAssignmentSchedule.ReadWrite.Directory" + "description": "Allows the app to read all Lifecycle workflows reports without a signed-in user.", + "displayName": "Read all Lifecycle workflows reports", + "id": "fe615156-48b5-4c83-b613-e6e31a43c446", + "origin": "Application (Microsoft Graph)", + "value": "LifecycleWorkflows-Reports.Read.All" }, { - "description": "Allows the app to read and manage the eligible role-based access control (RBAC) assignments for your company's directory, on behalf of the signed-in user. This includes managing eligible directory role membership, and reading directory role templates, directory roles and eligible memberships.", - "displayName": "Read, update, and delete all eligible role assignments for your company's directory", - "id": "62ade113-f8e0-4bf9-a6ba-5acb31db32fd", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and manage the eligible role-based access control (RBAC) assignments for your company's directory, on your behalf. This includes managing eligible directory role membership, and reading directory role templates, directory roles and eligible memberships.", - "userConsentDisplayName": "Read, update, and delete all eligible role assignments for your company's directory", - "value": "RoleEligibilitySchedule.ReadWrite.Directory" + "description": "Allows the app run workflows on-demand without a signed-in user.", + "displayName": "Run workflows on-demand in Lifecycle workflows", + "id": "3a87a643-13d2-47aa-8d6a-b0a8377cb03b", + "origin": "Application (Microsoft Graph)", + "value": "LifecycleWorkflows-Workflow.Activate" }, { - "description": "Allows the app to read, update, and delete policies for privileged role-based access control (RBAC) assignments of your company's directory, on behalf of the signed-in user.", - "displayName": "Read, update, and delete all policies for privileged role assignments of your company's directory", - "id": "1ff1be21-34eb-448c-9ac9-ce1f506b2a68", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update, and delete policies for privileged role-based access control (RBAC) assignments of your company's directory, on your behalf.", - "userConsentDisplayName": "Read, update, and delete all policies for privileged role assignments of your company's directory", - "value": "RoleManagementPolicy.ReadWrite.Directory" + "description": "Allows the app to list and read all workflows and tasks without a signed-in user.", + "displayName": "Read all workflows in Lifecycle workflows", + "id": "03b0ad3e-fc2b-4ef1-b0ff-252e865cb608", + "origin": "Application (Microsoft Graph)", + "value": "LifecycleWorkflows-Workflow.Read.All" }, { - "description": "Allows the app to read the active role-based access control (RBAC) assignments for your company's directory, on behalf of the signed-in user. This includes reading directory role templates, and directory roles.", - "displayName": "Read all active role assignments for your company's directory", - "id": "344a729c-0285-42c6-9014-f12b9b8d6129", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the active role-based access control (RBAC) assignments for your company's directory, on your behalf. This includes reading directory role templates, and directory roles.", - "userConsentDisplayName": "Read all active role assignments for your company's directory", - "value": "RoleAssignmentSchedule.Read.Directory" + "description": "Allows the app to list all workflows without a signed-in user.", + "displayName": "List all workflows in Lifecycle workflows", + "id": "021ea6db-c06b-45c6-8c9c-c1cd9a37a483", + "origin": "Application (Microsoft Graph)", + "value": "LifecycleWorkflows-Workflow.ReadBasic.All" }, { - "description": "Allows the app to read the eligible role-based access control (RBAC) assignments for your company's directory, on behalf of the signed-in user. This includes reading directory role templates, and directory roles.", - "displayName": "Read all eligible role assignments for your company's directory", - "id": "eb0788c2-6d4e-4658-8c9e-c0fb8053f03d", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the eligible role-based access control (RBAC) assignments for your company's directory, on your behalf. This includes reading directory role templates, and directory roles.", - "userConsentDisplayName": "Read all eligible role assignments for your company's directory", - "value": "RoleEligibilitySchedule.Read.Directory" + "description": "Allows the app to create, update, list, read and delete all workflows and tasks in lifecycle workflows without a signed-in user.", + "displayName": "Read and write all workflows in Lifecycle workflows", + "id": "94c88098-1d9d-4c42-a356-4d5a95312554", + "origin": "Application (Microsoft Graph)", + "value": "LifecycleWorkflows-Workflow.ReadWrite.All" }, { - "description": "Allows the app to read policies for privileged role-based access control (RBAC) assignments of your company's directory, on behalf of the signed-in user.", - "displayName": "Read all policies for privileged role assignments of your company's directory", - "id": "3de2cdbe-0ff5-47d5-bdee-7f45b4749ead", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read policies for privileged role-based access control (RBAC) assignments of your company's directory, on your behalf.", - "userConsentDisplayName": "Read all policies for privileged role assignments of your company's directory", - "value": "RoleManagementPolicy.Read.Directory" + "description": "Allow the application to access a subset of listitems without a signed in user. The specific listitems and the permissions granted will be configured in SharePoint Online.", + "displayName": "Access selected ListItems without a signed in user.", + "id": "de4e4161-a10a-4dfd-809c-e328d89aefeb", + "origin": "Application (Microsoft Graph)", + "value": "ListItems.SelectedOperations.Selected" }, { - "description": "Allows the app to read and write all Windows update deployment settings for the organization on behalf of the signed-in user.", - "displayName": "Read and write all Windows update deployment settings", - "id": "11776c0c-6138-4db3-a668-ee621bea2555", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write all Windows update deployment settings for the organization on your behalf.", - "userConsentDisplayName": "Read and write all Windows update deployment settings", - "value": "WindowsUpdates.ReadWrite.All" + "description": "Allow the application to access a subset of lists without a signed in user. The specific lists and the permissions granted will be configured in SharePoint Online.", + "displayName": "Access selected Lists without a signed in user.", + "id": "23c5a9bd-d900-4ecf-be26-a0689755d9e5", + "origin": "Application (Microsoft Graph)", + "value": "Lists.SelectedOperations.Selected" }, { - "description": "Allows the app to read and write your organization's mobility management policies on behalf of the signed-in user. For example, a mobility management policy can set the enrollment scope for a given mobility management application.", - "displayName": "Read and write your organization's mobility management policies", - "id": "a8ead177-1889-4546-9387-f25e658e2a79", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write your organization's mobility management policies on your behalf. For example, a mobility management policy can set the enrollment scope for a given mobility management application.", - "userConsentDisplayName": "Read and write your organization's mobility management policies", - "value": "Policy.ReadWrite.MobilityManagement" + "description": "Allows the app to read basic mail properties in all mailboxes without a signed-in user. Includes all properties except body, previewBody, attachments and any extended properties.", + "displayName": "Read basic mail in all mailboxes", + "id": "6be147d2-ea4f-4b5a-a3fa-3eab6f3c140a", + "origin": "Application (Microsoft Graph)", + "value": "Mail.ReadBasic" }, { - "description": "Allows the app to read basic unified group properties, memberships and owners of the group the signed-in guest is a member of.", - "displayName": "Read unified group memberships as guest", - "id": "73e75199-7c3e-41bb-9357-167164dbb415", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read basic unified group properties, memberships and owners of the group you are a member of.", - "userConsentDisplayName": "Read unified group memberships as guest", - "value": "UnifiedGroupMember.Read.AsGuest" + "description": "Allows the app to read basic mail properties in all mailboxes without a signed-in user. Includes all properties except body, previewBody, attachments and any extended properties.", + "displayName": "Read basic mail in all mailboxes", + "id": "693c5e45-0940-467d-9b8a-1022fb9d42ef", + "origin": "Application (Microsoft Graph)", + "value": "Mail.ReadBasic.All" }, { - "description": "Allows the app to update service principal endpoints", - "displayName": "Read and update service principal endpoints", - "id": "7297d82c-9546-4aed-91df-3d4f0a9b3ff0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to update service principal endpoints", - "userConsentDisplayName": "Read and update service principal endpoints", - "value": "ServicePrincipalEndpoint.ReadWrite.All" + "description": "Allows the app to create, read, update, and delete all email, including contents of non-draft emails in user mailboxes, without a signed-in user. Does not include permission to send mail.", + "displayName": "Read and write mail in all mailboxes, including modifying existing non-draft mails", + "id": "e118f1da-5c1c-46cf-bff6-8858d786f46f", + "origin": "Application (Microsoft Graph)", + "value": "Mail-Advanced.ReadWrite.All" }, { - "description": "Allows the app to read service principal endpoints", - "displayName": "Read service principal endpoints", - "id": "9f9ce928-e038-4e3b-8faf-7b59049a8ddc", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read service principal endpoints", - "userConsentDisplayName": "Read service principal endpoints", - "value": "ServicePrincipalEndpoint.Read.All" + "description": "Allows the app to read, create, update and delete identity lifecycle policies for agent identities in the organization, without a signed-in user.", + "displayName": "Read and write identity lifecycle policies for agent identities", + "id": "00d1c504-8dc7-461b-8a0b-dc15c8f1bd5a", + "origin": "Application (Microsoft Graph)", + "value": "LifecyclePolicies-AgentId.ReadWrite.All" }, { - "description": "Allows the app to create new notifications in users' teamwork activity feeds on behalf of the signed in user. These notifications may not be discoverable or be held or governed by compliance policies.", - "displayName": "Send a teamwork activity as the user", - "id": "7ab1d787-bae7-4d5d-8db6-37ea32df9186", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to create new activities in your teamwork activity feed, and send new activities to other users' activity feed, on your behalf.", - "userConsentDisplayName": "Send a teamwork activity", - "value": "TeamsActivity.Send" + "description": "Allows the app to read all users' UserConfiguration objects.", + "displayName": "Read all users' UserConfiguration objects", + "id": "27d9d776-f4d2-426d-80ad-5f22f2b01b0a", + "origin": "Application (Microsoft Graph)", + "value": "MailboxConfigItem.Read" }, { - "description": "Allows the app to read and write eDiscovery objects such as cases, custodians, review sets and other related objects on behalf of the signed-in user.", - "displayName": "Read and write all eDiscovery objects", - "id": "acb8f680-0834-4146-b69e-4ab1b39745ad", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write eDiscovery objects such as cases, custodians, review sets and other related objects on your behalf.", - "userConsentDisplayName": "Read and write all eDiscovery objects", - "value": "eDiscovery.ReadWrite.All" + "description": "Allows the app to read identity lifecycle policies for agent identities in the organization, without a signed-in user.", + "displayName": "Read identity lifecycle policies for agent identities", + "id": "6343d63f-034f-45b5-832d-9f9d7632e182", + "origin": "Application (Microsoft Graph)", + "value": "LifecyclePolicies-AgentId.Read.All" }, { - "description": "Allows the app to read eDiscovery objects such as cases, custodians, review sets and other related objects on behalf of the signed-in user.", - "displayName": "Read all eDiscovery objects", - "id": "99201db3-7652-4d5a-809a-bdb94f85fe3c", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read eDiscovery objects such as cases, custodians, review sets and other related objects on your behalf.", - "userConsentDisplayName": "Read all eDiscovery objects", - "value": "eDiscovery.Read.All" + "description": "Allows an app to read license assignments for users and groups, without a signed-in user.", + "displayName": "Read all license assignments.", + "id": "e2f98668-2877-4f38-a2f4-8202e0717aa1", + "origin": "Application (Microsoft Graph)", + "value": "LicenseAssignment.Read.All" }, { - "description": "Allows the app to read and write custom security attribute assignments for all principals in the tenant on behalf of a signed in user.", - "displayName": "Read and write custom security attribute assignments", - "id": "ca46335e-8453-47cd-a001-8459884efeae", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write custom security attribute assignments for all principals in the tenant on your behalf.", - "userConsentDisplayName": "Read and write custom security attribute assignments", - "value": "CustomSecAttributeAssignment.ReadWrite.All" + "description": "Allows the app to read current and previous IndustryData runs without a signed-in user.", + "displayName": "View current and previous runs", + "id": "f6f5d10b-3024-4d1d-b674-aae4df4a1a73", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-Run.Read.All" }, { - "description": "Allows the app to read and write custom security attribute definitions for the tenant on behalf of a signed in user.", - "displayName": "Read and write custom security attribute definitions", - "id": "8b0160d4-5743-482b-bb27-efc0a485ca4a", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write custom security attribute definitions for the tenant on your behalf.", - "userConsentDisplayName": "Read and write custom security attribute definitions", - "value": "CustomSecAttributeDefinition.ReadWrite.All" + "description": "Allows the app to view and start IndustryData runs without a signed-in user.", + "displayName": "View and start runs", + "id": "7e429772-5b5e-47c0-8fd6-7279294c8033", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-Run.Start" }, { - "description": "Allows the app to read email in the signed-in user's mailbox except body, previewBody, attachments and any extended properties.", - "displayName": "Read user basic mail", - "id": "a4b8392a-d8d1-4954-a029-8e668a39a170", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read email in the signed-in user's mailbox except body, previewBody, attachments and any extended properties.", - "userConsentDisplayName": "Read user basic mail", - "value": "Mail.ReadBasic" + "description": "Allows the app to read source system definitions without a signed-in user.", + "displayName": "View source system definitions", + "id": "bc167a60-39fe-4865-8b44-78400fc6ed03", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-SourceSystem.Read.All" }, { - "description": "Allows the app to read and write your organization's feature rollout policies on behalf of the signed-in user. Includes abilities to assign and remove users and groups to rollout of a specific feature.", - "displayName": "Read and write your organization's feature rollout policies", - "id": "92a38652-f13b-4875-bc77-6e1dbb63e1b2", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write your organization's feature rollout policies on your behalf. Includes abilities to assign and remove users and groups to rollout of a specific feature.", - "userConsentDisplayName": "Read and write your organization's feature rollout policies", - "value": "Policy.ReadWrite.FeatureRollout" + "description": "Allows the app to read and write source system definitions without a signed-in user.", + "displayName": "Manage source system definitions", + "id": "7d866958-e06e-4dd6-91c6-a086b3f5cfeb", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-SourceSystem.ReadWrite.All" }, { - "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes instantiating directory roles and managing directory role membership, and reading directory role templates, directory roles and memberships.", - "displayName": "Read and write directory RBAC settings", - "id": "d01b97e9-cbc0-49fe-810a-750afd5527a3", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and manage the role-based access control (RBAC) settings for your company's directory, on your behalf. This includes instantiating directory roles and managing directory role membership, and reading directory role templates, directory roles and memberships.", - "userConsentDisplayName": "Read and write directory RBAC settings", - "value": "RoleManagement.ReadWrite.Directory" + "description": "Allows the app to read time period definitions without a signed-in user.", + "displayName": "Read time period definitions", + "id": "7c55c952-b095-4c23-a522-022bce4cc1e3", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-TimePeriod.Read.All" }, { - "description": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes reading directory role templates, directory roles and memberships.", - "displayName": "Read directory RBAC settings", - "id": "741c54c3-0c1e-44a1-818b-3f97ab4e8c83", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, on your behalf. This includes reading directory role templates, directory roles and memberships.", - "userConsentDisplayName": "Read directory RBAC settings", - "value": "RoleManagement.Read.Directory" + "description": "Allows the app to read and write time period definitions without a signed-in user.", + "displayName": "Manage time period definitions", + "id": "7afa7744-a782-4a32-b8c2-e3db637e8de7", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-TimePeriod.ReadWrite.All" }, { - "description": "Allows the app to read and write the organization and related resources, on behalf of the signed-in user.\u00a0Related resources include things like subscribed skus and tenant branding information.", - "displayName": "Read and write organization information", - "id": "46ca0847-7e6b-426e-9775-ea810a948356", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write the organization and related resources, on your behalf.\u00a0Related resources include things like subscribed skus and tenant branding information.", - "userConsentDisplayName": "Read and write organization information", - "value": "Organization.ReadWrite.All" + "description": "Allows the app to read all configurations applicable to users for protecting organizational data, without a signed-in user.", + "displayName": "Read all configurations for protecting organizational data applicable to users", + "id": "14f49b9f-4bf2-4d24-b80e-b27ec58409bd", + "origin": "Application (Microsoft Graph)", + "value": "InformationProtectionConfig.Read.All" }, { - "description": "Allows the app to read the organization and related resources, on behalf of the signed-in user.\u00a0Related resources include things like subscribed skus and tenant branding information.", - "displayName": "Read organization information", - "id": "4908d5b9-3fb2-4b1e-9336-1888b7937185", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the organization and related resources, on your behalf.\u00a0Related resources include things like subscribed skus and tenant branding information.", - "userConsentDisplayName": "Read organization information", - "value": "Organization.Read.All" + "description": "Allows an app to sign digests for data without a signed-in user.", + "displayName": "Sign digests for data", + "id": "cbe6c7e4-09aa-4b8d-b3c3-2dbb59af4b54", + "origin": "Application (Microsoft Graph)", + "value": "InformationProtectionContent.Sign.All" }, { - "description": "Allows the app to read your company's places (conference rooms and room lists) for calendar events and other applications, on behalf of the signed-in user.", - "displayName": "Read all company places", - "id": "cb8f45a0-5c2e-4ea1-b803-84b870a7d7ec", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your company's places (conference rooms and room lists) for calendar events and other applications, on your behalf.", - "userConsentDisplayName": "Read all company places", - "value": "Place.Read.All" + "description": "Allows the app to create protected content without a signed-in user.", + "displayName": "Create protected content", + "id": "287bd98c-e865-4e8c-bade-1a85523195b9", + "origin": "Application (Microsoft Graph)", + "value": "InformationProtectionContent.Write.All" }, { - "description": "Allows the app to manage workforce integrations, to synchronize data from Microsoft Teams Shifts, on behalf of the signed-in user.", - "displayName": "Read and write workforce integrations", - "id": "08c4b377-0d23-4a8b-be2a-23c1c1d88545", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to manage workforce integrations, to synchronize data from Microsoft Teams Shifts, on your behalf.", - "userConsentDisplayName": "Read and write workforce integrations", - "value": "WorkforceIntegration.ReadWrite.All" + "description": "Allows an app to read published sensitivity labels and label policy settings for the entire organization or a specific user, without a signed in user.", + "displayName": "Read all published labels and label policies for an organization.", + "id": "19da66cb-0fb0-4390-b071-ebc76a349482", + "origin": "Application (Microsoft Graph)", + "value": "InformationProtectionPolicy.Read.All" }, { - "description": "Allows the app to read workforce integrations, to synchronize data from Microsoft Teams Shifts, on behalf of the signed-in user.", - "displayName": "Read workforce integrations", - "id": "f1ccd5a7-6383-466a-8db8-1a656f7d06fa", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read workforce integrations, to synchronize data from Microsoft Teams Shifts, on your behalf.", - "userConsentDisplayName": "Read workforce integrations", - "value": "WorkforceIntegration.Read.All" + "description": "Allows an app to read all user metrics insights, such as daily and monthly active users, without a signed-in user.", + "displayName": "Read all user metrics insights", + "id": "34cbd96c-d824-4755-90d3-1008ef47efc1", + "origin": "Application (Microsoft Graph)", + "value": "Insights-UserMetric.Read.All" }, { - "description": "Allows the app to read, update, delete and perform actions on access reviews, reviewers, decisions and settings for group and app memberships that the signed-in user has access to in the organization.", - "displayName": "Manage access reviews for group and app memberships", - "id": "5af8c3f5-baca-439a-97b0-ea58a435e269", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update and perform action on access reviews, reviewers, decisions and settings that you have access to.", - "userConsentDisplayName": "Manage access reviews for group and app memberships", - "value": "AccessReview.ReadWrite.Membership" + "description": "Allows the app to read data for all assignments in the organization's directory, without a signed-in user.", + "displayName": "Read all assignments", + "id": "535e6066-2894-49ef-ab33-e2c6d064bb81", + "origin": "Application (Microsoft Graph)", + "value": "LearningAssignedCourse.Read.All" }, { - "description": "Allows the app to manage hybrid identity service configuration by creating, viewing, updating and deleting on-premises published resources, on-premises agents and agent groups, on behalf of the signed-in user.", - "displayName": "Manage on-premises published resources", - "id": "8c4d5184-71c2-4bf8-bb9d-bc3378c9ad42", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to manage hybrid identity service configuration by creating, viewing, updating and deleting on-premises published resources, on-premises agents and agent groups, on your behalf.", - "userConsentDisplayName": "Manage on-premises published resources", - "value": "OnPremisesPublishingProfiles.ReadWrite.All" + "description": "Allows the app to create, update, read and delete all assignments in the organization's directory, without a signed-in user.", + "displayName": "Read and write all assignments", + "id": "236c1cbd-1187-427f-b0f5-b1852454973b", + "origin": "Application (Microsoft Graph)", + "value": "LearningAssignedCourse.ReadWrite.All" }, { - "description": "Allows an app to read information protection sensitivity labels and label policy settings, on behalf of the signed-in user.", - "displayName": "Read user sensitivity labels and label policies.", - "id": "4ad84827-5578-4e18-ad7a-86530b12f884", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to read information protection sensitivity labels and label policy settings, on behalf of the signed-in user.", - "userConsentDisplayName": "Read user sensitivity labels and label policies.", - "value": "InformationProtectionPolicy.Read" + "description": "Allows the app to read all learning content in the organization's directory, without a signed-in user.", + "displayName": "Read all learning content", + "id": "8740813e-d8aa-4204-860e-2a0f8f84dbc8", + "origin": "Application (Microsoft Graph)", + "value": "LearningContent.Read.All" }, { - "description": "Allows the app to read administrative units and administrative unit membership on behalf of the signed-in user.", - "displayName": "Read administrative units", - "id": "3361d15d-be43-4de6-b441-3c746d05163d", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read administrative units and administrative unit membership on your behalf.", - "userConsentDisplayName": "Read administrative units", - "value": "AdministrativeUnit.Read.All" + "description": "Allows the app to manage all learning content in the organization's directory, without a signed-in user.", + "displayName": "Manage all learning content", + "id": "444d6fcb-b738-41e5-b103-ac4f2a2628a3", + "origin": "Application (Microsoft Graph)", + "value": "LearningContent.ReadWrite.All" }, { - "description": "Allows the app to create, read, update, and delete administrative units and manage administrative unit membership on behalf of the signed-in user.", - "displayName": "Read and write administrative units", - "id": "7b8a2d34-6b3f-4542-a343-54651608ad81", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to create, read, update, and delete administrative units and manage administrative unit membership on your behalf.", - "userConsentDisplayName": "Read and write administrative units", - "value": "AdministrativeUnit.ReadWrite.All" + "description": "Allows the app to read data for all self-initiated courses in the organization's directory, without a signed-in user.", + "displayName": "Read all self-initiated courses", + "id": "467524fc-ed22-4356-a910-af61191e3503", + "origin": "Application (Microsoft Graph)", + "value": "LearningSelfInitiatedCourse.Read.All" }, { - "description": "Allows the app to read your family information, members and their basic profile.", - "displayName": "Read your family info", - "id": "3a1e4806-a744-4c70-80fc-223bf8582c46", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your family information, members and their basic profile.", - "userConsentDisplayName": "Read your family info", - "value": "Family.Read" + "description": "Allows the app to create, update, read and delete all self-initiated courses in the organization's directory, without a signed-in user.", + "displayName": "Read and write all self-initiated courses", + "id": "7654ed61-8965-4025-846a-0856ec02b5b0", + "origin": "Application (Microsoft Graph)", + "value": "LearningSelfInitiatedCourse.ReadWrite.All" }, { - "description": "Allows the app to create threat indicators, and fully manage those threat indicators (read, update and delete), on behalf of the signed-in user. \u00a0It cannot update any threat indicators it does not own.", - "displayName": "Manage threat indicators this app creates or owns", - "id": "91e7d36d-022a-490f-a748-f8e011357b42", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to create threat indicators, and fully manage those threat indicators (read, update and delete), on your behalf. \u00a0It cannot update any threat indicators that it is not an owner of.", - "userConsentDisplayName": "Manage threat indicators this app creates or owns", - "value": "ThreatIndicators.ReadWrite.OwnedBy" + "description": "Allows an app to manage license assignments for users and groups, without a signed-in user.", + "displayName": "Manage all license assignments", + "id": "5facf0c1-8979-4e95-abcf-ff3d079771c0", + "origin": "Application (Microsoft Graph)", + "value": "LicenseAssignment.ReadWrite.All" }, { - "description": "Allows the app to read or update security actions, on behalf of the signed-in user.", - "displayName": "Read and update your organization's security actions", - "id": "dc38509c-b87d-4da0-bd92-6bec988bac4a", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and update security actions, on your behalf.", - "userConsentDisplayName": "Read and update your organization's security actions", - "value": "SecurityActions.ReadWrite.All" + "description": "Allows the app to create, read, update and delete all users' UserConfiguration objects.", + "displayName": "Read and write all users' UserConfiguration objects", + "id": "aa6d92d4-b25a-4640-aefe-3e3231e5e736", + "origin": "Application (Microsoft Graph)", + "value": "MailboxConfigItem.ReadWrite" }, { - "description": "Allows the app to read security actions, on behalf of the signed-in user.", - "displayName": "Read your organization's security actions", - "id": "1638cddf-07a4-4de2-8645-69c96cacad73", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read security actions, on your behalf.", - "userConsentDisplayName": "Read your organization's security actions", - "value": "SecurityActions.Read.All" + "description": "Allows the app to read all the users' mailbox folders, without signed-in user.", + "displayName": "Read all the users' mailbox folders", + "id": "99280d24-a782-4793-93cc-0888549957f6", + "origin": "Application (Microsoft Graph)", + "value": "MailboxFolder.Read.All" }, { - "description": "Allows an app to read 1 on 1 or group chats threads, on behalf of the signed-in user.", - "displayName": "Read user chat messages", - "id": "f501c180-9344-439a-bca0-6cbf209fd270", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to read your 1 on 1 or group chat messages in Microsoft Teams, on your behalf.", - "userConsentDisplayName": "Read your chat messages", - "value": "Chat.Read" + "description": "Allows the app to read and write all the users' mailbox folders, without signed-in user.", + "displayName": "Read and write all the users' mailbox folders", + "id": "fef87b92-8391-4589-9da7-eb93dab7dc8a", + "origin": "Application (Microsoft Graph)", + "value": "MailboxFolder.ReadWrite.All" }, { - "description": "Allows an app to read and write 1 on 1 or group chats threads, on behalf of the signed-in user.", - "displayName": "Read and write user chat messages", - "id": "9ff7295e-131b-4d94-90e1-69fde507ac11", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to read and write your 1 on 1 or group chat messages in Microsoft Teams, on your behalf.", - "userConsentDisplayName": "Read and write your chat messages", - "value": "Chat.ReadWrite" + "description": "Allows the app to read all AI Insights for all online meetings, without a signed-in user.", + "displayName": "Read all AI Insights for online meetings.", + "id": "c0cf7895-985f-42d4-a693-b618f36674ad", + "origin": "Application (Microsoft Graph)", + "value": "OnlineMeetingAiInsight.Read.All" }, { - "description": "Allows the app to read and write your organization's trust framework policies on behalf of the signed-in user.", - "displayName": "Read and write your organization's trust framework policies", - "id": "cefba324-1a70-4a6e-9c1d-fd670b7ae392", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write your organization's trust framework policies on your behalf.", - "userConsentDisplayName": "Read and write trust framework policies", - "value": "Policy.ReadWrite.TrustFramework" + "description": "Allows the teams-app to read all aiInsights for online meetings where the Teams-app is installed, without a signed-in user.", + "displayName": "Read all AI Insights for online meetings where the Teams application is installed.", + "id": "01892c31-3b66-4bcf-b5f5-bf0a03d5ed9f", + "origin": "Application (Microsoft Graph)", + "value": "OnlineMeetingAiInsight.Read.Chat" }, { - "description": "Allows the app to read trust framework key set properties on behalf of the signed-in user.", - "displayName": "Read trust framework key sets", - "id": "7ad34336-f5b1-44ce-8682-31d7dfcd9ab9", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read trust framework key sets, on your behalf.", - "userConsentDisplayName": "Read trust framework key sets", - "value": "TrustFrameworkKeySet.Read.All" + "description": "Allows the app to read online meeting artifacts in your organization, without a signed-in user.", + "displayName": "Read online meeting artifacts", + "id": "df01ed3b-eb61-4eca-9965-6b3d789751b2", + "origin": "Application (Microsoft Graph)", + "value": "OnlineMeetingArtifact.Read.All" }, - { - "description": "Allows the app to read and write trust framework key set properties on behalf of the signed-in user.", - "displayName": "Read and write trust framework key sets", - "id": "39244520-1e7d-4b4a-aee0-57c65826e427", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read or write trust framework key sets, on your behalf.", - "userConsentDisplayName": "Read and write trust framework key sets", - "value": "TrustFrameworkKeySet.ReadWrite.All" + { + "description": "Allows the app to read all recordings of all online meetings, without a signed-in user.", + "displayName": "Read all recordings of online meetings.", + "id": "a4a08342-c95d-476b-b943-97e100569c8d", + "origin": "Application (Microsoft Graph)", + "value": "OnlineMeetingRecording.Read.All" }, { - "description": "Allows the app to read and update identity risk event information for all users in your organization on behalf of the signed-in user.\u00a0Update operations include confirming risk event detections.\u00a0", - "displayName": "Read and write risk event information", - "id": "9e4862a5-b68f-479e-848a-4e07e25c9916", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and update identity risk event information for all users in your organization on your behalf.\u00a0Update operations include confirming risk event detections.\u00a0", - "userConsentDisplayName": "Read and write risk event information", - "value": "IdentityRiskEvent.ReadWrite.All" + "description": "Allows the app to read online meeting details in your organization, without a signed-in user.", + "displayName": "Read online meeting details", + "id": "c1684f21-1984-47fa-9d61-2dc8c296bb70", + "origin": "Application (Microsoft Graph)", + "value": "OnlineMeetings.Read.All" }, { - "description": "Allows the app to read and update identity risky user information for all users in your organization on behalf of the signed-in user.\u00a0Update operations include dismissing risky users.", - "displayName": "Read and write risky user information", - "id": "e0a7cdbb-08b0-4697-8264-0069786e9674", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and update identity risky user information for all users in your organization on your behalf.\u00a0Update operations include dismissing risky users.", - "userConsentDisplayName": "Read and write identity risky user information", - "value": "IdentityRiskyUser.ReadWrite.All" + "description": "Allows the app to read and create online meetings as an application in your organization.", + "displayName": "Read and create online meetings", + "id": "b8bb2037-6e08-44ac-a4ea-4674e010e2a4", + "origin": "Application (Microsoft Graph)", + "value": "OnlineMeetings.ReadWrite.All" }, { - "description": "Allows the app to read the signed-in user's mailbox.", - "displayName": "Read user mail ", - "id": "570282fd-fa5c-430d-a7fd-fc8dc98a9dca", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read email in your mailbox. ", - "userConsentDisplayName": "Read your mail ", - "value": "Mail.Read" + "description": "Allows the app to read all transcripts of all online meetings, without a signed-in user.", + "displayName": "Read all transcripts of online meetings.", + "id": "a4a80d8d-d283-4bd8-8504-555ec3870630", + "origin": "Application (Microsoft Graph)", + "value": "OnlineMeetingTranscript.Read.All" }, { - "description": "Allows the app to read identity risky user information for all users in your organization on behalf of the signed-in user.", - "displayName": "Read identity risky user information", - "id": "d04bb851-cb7c-4146-97c7-ca3e71baf56c", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read identity risky user information for all users in your organization on behalf of the signed-in user.", - "userConsentDisplayName": "Read identity risky user information", - "value": "IdentityRiskyUser.Read.All" + "description": "Allows the app to read all on-premises directory synchronization information for the organization, without a signed-in user.", + "displayName": "Read all on-premises directory synchronization information", + "id": "bb70e231-92dc-4729-aff5-697b3f04be95", + "origin": "Application (Microsoft Graph)", + "value": "OnPremDirectorySynchronization.Read.All" }, { - "description": "Allows the app to read the signed-in user's activity statistics, such as how much time the user has spent on emails, in meetings, or in chat sessions.", - "displayName": "Read user activity statistics", - "id": "e03cf23f-8056-446a-8994-7d93dfc8b50e", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your activity statistics, such as how much time you've spent on emails, in meetings, or in chat sessions.", - "userConsentDisplayName": "Read your activity statistics", - "value": "Analytics.Read" + "description": "Allows the app to read and write all on-premises directory synchronization information for the organization, without a signed-in user.", + "displayName": "Read and write all on-premises directory synchronization information", + "id": "c22a92cc-79bf-4bb1-8b6c-e0a05d3d80ce", + "origin": "Application (Microsoft Graph)", + "value": "OnPremDirectorySynchronization.ReadWrite.All" }, { - "description": "Allows the app to see and update the data you gave it access to, even when users are not currently using the app. This does not give the app any additional permissions.", - "displayName": "Maintain access to data you have given it access to", - "id": "7427e0e9-2fba-42fe-b0c0-848c9e6a8182", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to see and update the data you gave it access to, even when you are not currently using the app. This does not give the app any additional permissions.", - "userConsentDisplayName": "Maintain access to data you have given it access to", - "value": "offline_access" + "description": "Allows the app to create, view, update and delete on-premises published resources, on-premises agents and agent groups, as part of a hybrid identity configuration, without a signed in user.", + "displayName": "Manage on-premises published resources", + "id": "0b57845e-aa49-4e6f-8109-ce654fffa618", + "origin": "Application (Microsoft Graph)", + "value": "OnPremisesPublishingProfiles.ReadWrite.All" }, { - "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange Web Services.", - "displayName": "Access mailboxes as the signed-in user via Exchange Web Services", - "id": "9769c687-087d-48ac-9cb3-c37dde652038", - "Origin": "Delegated", - "userConsentDescription": "Allows the app full access to your mailboxes on your behalf.", - "userConsentDisplayName": "Access your mailboxes", - "value": "EWS.AccessAsUser.All" + "description": "Allows the app to read the organization and related resources, without a signed-in user. Related resources include things like subscribed skus and tenant branding information.", + "displayName": "Read organization information", + "id": "498476ce-e0fe-48b0-b801-37ba7e2685c6", + "origin": "Application (Microsoft Graph)", + "value": "Organization.Read.All" }, { - "description": "Allows the app to export data (e.g. customer content or system-generated logs), associated with any user in your company, when the app is used by a privileged user (e.g. a Company Administrator).", - "displayName": "Export user's data", - "id": "405a51b5-8d8d-430b-9842-8be4b0e9f324", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to export data (e.g. customer content or system-generated logs), associated with any user in your company, when the app is used by a privileged user (e.g. a Company Administrator).", - "userConsentDisplayName": "Export user's data", - "value": "User.Export.All" + "description": "Allows the app to read and write the organization and related resources, without a signed-in user. Related resources include things like subscribed skus and tenant branding information.", + "displayName": "Read and write organization information", + "id": "292d869f-3427-49a8-9dab-8c70152b74e9", + "origin": "Application (Microsoft Graph)", + "value": "Organization.ReadWrite.All" }, { - "description": "Allows the app to deliver its notifications on behalf of signed-in users. Also allows the app to read, update, and delete the user's notification items for this app.", - "displayName": "Deliver and manage user notifications for this app", - "id": "89497502-6e42-46a2-8cb2-427fd3df970a", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to deliver its notifications, on your behalf. Also allows the app to read, update, and delete your notification items for this app.", - "userConsentDisplayName": "Deliver and manage your notifications for this app", - "value": "Notifications.ReadWrite.CreatedByApp" + "description": "Allows the app to read the organizational branding information, without a signed-in user.", + "displayName": "Read organizational branding information", + "id": "eb76ac34-0d62-4454-b97c-185e4250dc20", + "origin": "Application (Microsoft Graph)", + "value": "OrganizationalBranding.Read.All" }, { - "description": "Allows the app to read and write your organization's conditional access policies on behalf of the signed-in user.", - "displayName": "Read and write your organization's conditional access policies", - "id": "ad902697-1014-4ef5-81ef-2b4301988e8c", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write your organization's conditional access policies on your behalf.", - "userConsentDisplayName": "Read and write your organization's conditional access policies", - "value": "Policy.ReadWrite.ConditionalAccess" + "description": "Allows the app to read and write the organizational branding information, without a signed-in user.", + "displayName": "Read and write organizational branding information", + "id": "d2ebfbc1-a5f8-424b-83a6-56ab5927a73c", + "origin": "Application (Microsoft Graph)", + "value": "OrganizationalBranding.ReadWrite.All" }, { - "description": "Allows the app to read your organization's policies on behalf of the signed-in user.", - "displayName": "Read your organization's policies", - "id": "572fea84-0151-49b2-9301-11cb16974376", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your organization's policies on your behalf.", - "userConsentDisplayName": "Read your organization's policies", - "value": "Policy.Read.All" + "description": "Allows the app to read all organizational contacts without a signed-in user. These contacts are managed by the organization and are different from a user's personal contacts.", + "displayName": "Read organizational contacts", + "id": "e1a88a34-94c4-4418-be12-c87b00e26bea", + "origin": "Application (Microsoft Graph)", + "value": "OrgContact.Read.All" }, { - "description": "Allows the app to read access reviews, reviewers, decisions and settings that the signed-in user has access to in the organization.", - "displayName": "Read all access reviews that user can access", - "id": "ebfcd32b-babb-40f4-a14b-42706e83bd28", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read information on access reviews, reviewers, decisions and settings that you have access to.", - "userConsentDisplayName": "Read access reviews that you can access", - "value": "AccessReview.Read.All" + "description": "Allows the app to read organization-wide apps and services settings, without a signed-in user.", + "displayName": "Read organization-wide apps and services settings", + "id": "56c84fa9-ea1f-4a15-90f2-90ef41ece2c9", + "origin": "Application (Microsoft Graph)", + "value": "OrgSettings-AppsAndServices.Read.All" }, { - "description": "Allows the app to read, update, delete and perform actions on access reviews, reviewers, decisions and settings that the signed-in user has access to in the organization.", - "displayName": "Manage all access reviews that user can access", - "id": "e4aa47b9-9a69-4109-82ed-36ec70d85ff1", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update and perform action on access reviews, reviewers, decisions and settings that you have access to.", - "userConsentDisplayName": "Manage access reviews that you can access", - "value": "AccessReview.ReadWrite.All" + "description": "Allows the app to read and write organization-wide apps and services settings, without a signed-in user.", + "displayName": "Read and write organization-wide apps and services settings", + "id": "4a8e4191-c1c8-45f8-b801-f9a1a5ee6ad3", + "origin": "Application (Microsoft Graph)", + "value": "OrgSettings-AppsAndServices.ReadWrite.All" }, { - "description": "Allows the app to read programs and program controls that the signed-in user has access to in the organization.", - "displayName": "Read all programs that user can access", - "id": "c492a2e1-2f8f-4caa-b076-99bbf6e40fe4", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read information on programs and program controls that you have access to.", - "userConsentDisplayName": "Read programs that you can access", - "value": "ProgramControl.Read.All" + "description": "Allows the app to read all the OneNote notebooks in your organization, without a signed-in user.", + "displayName": "Read and write all OneNote notebooks", + "id": "0c458cef-11f3-48c2-a568-c66751c238c0", + "origin": "Application (Microsoft Graph)", + "value": "Notes.ReadWrite.All" }, { - "description": "Allows the app to read, update, delete and perform actions on programs and program controls that the signed-in user has access to in the organization.", - "displayName": "Manage all programs that user can access", - "id": "50fd364f-9d93-4ae1-b170-300e87cccf84", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update and perform action on programs and program controls that you have access to.", - "userConsentDisplayName": "Manage programs that you can access", - "value": "ProgramControl.ReadWrite.All" + "description": "Allows the app to read all the OneNote notebooks in your organization, without a signed-in user.", + "displayName": "Read all OneNote notebooks", + "id": "3aeca27b-ee3a-4c2b-8ded-80376e2134a4", + "origin": "Application (Microsoft Graph)", + "value": "Notes.Read.All" }, { - "description": "Allows the app to create, read, update, and delete apps in the app catalogs.", - "displayName": "Read and write to all app catalogs", - "id": "1ca167d5-1655-44a1-8adf-1414072e1ef9", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to create, read, update, and delete apps in the app catalogs.", - "userConsentDisplayName": "Read and write to all app catalogs", - "value": "AppCatalog.ReadWrite.All" + "description": "Allows the app to read all network access reports without a signed-in user.", + "displayName": "Read all network access reports", + "id": "40049381-3cc1-42af-94ec-5ce755db4b0d", + "origin": "Application (Microsoft Graph)", + "value": "NetworkAccess-Reports.Read.All" }, { - "description": "Allows the app to request and manage just in time elevation (including scheduled elevation) of users to Azure AD built-in administrative roles, on behalf of signed-in users.", - "displayName": "Read and write privileged access to Azure AD", - "id": "3c3c74f5-cdaa-4a97-b7e0-4e788bfcfb37", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to request and manage just in time elevation (including scheduled elevation) of users to Azure AD built-in administrative roles, on your behalf.", - "userConsentDisplayName": "Read and write privileged access to Azure AD", - "value": "PrivilegedAccess.ReadWrite.AzureAD" + "description": "Allows the app to read and write your organization's network access policies, without a signed-in user.", + "displayName": "Read and write all security and routing policies for network access", + "id": "f0c341be-8348-4989-8e43-660324294538", + "origin": "Application (Microsoft Graph)", + "value": "NetworkAccessPolicy.ReadWrite.All" }, { - "description": "Allows the app to read terms of use agreements on behalf of the signed-in user.", - "displayName": "Read all terms of use agreements", - "id": "af2819c9-df71-4dd3-ade7-4d7c9dc653b7", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read terms of use agreements on your behalf.", - "userConsentDisplayName": "Read all terms of use agreements", - "value": "Agreement.Read.All" + "description": "Allows the app to export all the users' mailbox items, without signed-in user.", + "displayName": "Export all the users' mailbox items", + "id": "937550e9-33a3-494b-88ae-d9cd394b1fbb", + "origin": "Application (Microsoft Graph)", + "value": "MailboxItem.Export.All" }, { - "description": "Allows the app to read and write terms of use agreements on behalf of the signed-in user.", - "displayName": "Read and write all terms of use agreements", - "id": "ef4b5d93-3104-4664-9053-a5c49ab44218", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write terms of use agreements on your behalf.", - "userConsentDisplayName": "Read and write all terms of use agreements", - "value": "Agreement.ReadWrite.All" + "description": "Allows the app to export and import all the users' mailbox items, without signed-in user.", + "displayName": "Export and import all the users' mailbox items", + "id": "76577085-e73d-4f1d-b26a-85fb33892327", + "origin": "Application (Microsoft Graph)", + "value": "MailboxItem.ImportExport.All" }, { - "description": "Allows the app to read terms of use acceptance statuses on behalf of the signed-in user.", - "displayName": "Read user terms of use acceptance statuses", - "id": "0b7643bb-5336-476f-80b5-18fbfbc91806", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your terms of use acceptance statuses.", - "userConsentDisplayName": "Read your terms of use acceptance statuses", - "value": "AgreementAcceptance.Read" + "description": "Allows the app to read all the users' mailbox items, without signed-in user.", + "displayName": "Read all the users' mailbox items", + "id": "7d9f353d-a7bd-4fbb-822a-26d5dd39a3ce", + "origin": "Application (Microsoft Graph)", + "value": "MailboxItem.Read.All" }, { - "description": "Allows the app to read terms of use acceptance statuses on behalf of the signed-in user.", - "displayName": "Read terms of use acceptance statuses that user can access", - "id": "a66a5341-e66e-4897-9d52-c2df58c2bfb9", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read terms of use acceptance statuses on your behalf.", - "userConsentDisplayName": "Read all terms of use acceptance statuses", - "value": "AgreementAcceptance.Read.All" + "description": "Allows the app to read, write, and delete all users' mailbox items, without a signed-in user.", + "displayName": "Read and write all users' mailbox items", + "id": "1583d471-fede-4e7c-b062-57e9d60cfb49", + "origin": "Application (Microsoft Graph)", + "value": "MailboxItem.ReadWrite.All" }, { - "description": "Read activity data for your organization", - "displayName": "Allows the application to read activity data for your organization.", - "id": "594c1fb6-4f81-4475-ae41-0c394909246c", - "Origin": "Delegated (Office 365 Management)", - "userConsentDescription": "Read activity data for your organization", - "userConsentDisplayName": "Allows the application to read activity data for your organization.", - "value": "ActivityFeed.Read" + "description": "Allows the app to read user's mailbox settings without a signed-in user. Does not include permission to send mail.", + "displayName": "Read all user mailbox settings", + "id": "40f97065-369a-49f4-947c-6a255697ae91", + "origin": "Application (Microsoft Graph)", + "value": "MailboxSettings.Read" }, { - "description": "Allows the app to read and query your audit log activities, on behalf of the signed-in user.", - "displayName": "Read audit log data", - "id": "e4c9e354-4dc5-45b8-9e7c-e1393b0b1a20", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and query your audit log activities, on your behalf.", - "userConsentDisplayName": "Read audit log data", - "value": "AuditLog.Read.All" + "description": "Allows the app to create, read, update, and delete user's mailbox settings without a signed-in user. Does not include permission to send mail.", + "displayName": "Read and write all user mailbox settings", + "id": "6931bccd-447a-43d1-b442-00a195474933", + "origin": "Application (Microsoft Graph)", + "value": "MailboxSettings.ReadWrite" }, { - "description": "Allows the app to read and report the signed-in user's activity in the app.", - "displayName": "Read and write app activity to users' activity feed", - "id": "47607519-5fb1-47d9-99c7-da4b48f369b1", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and report your activity in the app.", - "userConsentDisplayName": "Read and write app activity to your activity feed", - "value": "UserActivity.ReadWrite.CreatedByApp" + "description": "Allows the app to read mail tips for all users in the organization without a signed-in user. Mail tips include automatic replies, mailbox status, custom tips, and delivery information.", + "displayName": "Read mail tips for all users", + "id": "a2c9652d-4d7f-4e4e-9d75-ac32fdc6f413", + "origin": "Application (Microsoft Graph)", + "value": "MailTips.ReadBasic.All" }, { - "description": "Allows the app to read properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups.", - "displayName": "Read Microsoft Intune Device Configuration and Policies", - "id": "f1493658-876a-4c87-8fa7-edb559b3476a", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups.", - "userConsentDisplayName": "Read Microsoft Intune Device Configuration and Policies", - "value": "DeviceManagementConfiguration.Read.All" + "description": "Allows the app to read the memberships of hidden groups and administrative units without a signed-in user.", + "displayName": "Read all hidden memberships", + "id": "658aa5d8-239f-45c4-aa12-864f4fc7e490", + "origin": "Application (Microsoft Graph)", + "value": "Member.Read.Hidden" }, { - "description": "Allows the app to read and write properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups.", - "displayName": "Read and write Microsoft Intune Device Configuration and Policies", - "id": "0883f392-0a7a-443d-8c76-16a6d39c7b63", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups.", - "userConsentDisplayName": "Read and write Microsoft Intune Device Configuration and Policies", - "value": "DeviceManagementConfiguration.ReadWrite.All" + "description": "Allows the app to read and write reference definitions without a signed-in user.", + "displayName": "Manage reference definitions", + "id": "bda16293-63d3-45b7-b16b-833841d27d56", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-ReferenceDefinition.ReadWrite.All" }, { - "description": "Allows the app to read the properties, group assignments and status of apps, app configurations and app protection policies managed by Microsoft Intune.", - "displayName": "Read Microsoft Intune apps", - "id": "4edf5f54-4666-44af-9de9-0144fb4b6e8c", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the properties, group assignments and status of apps, app configurations and app protection policies managed by Microsoft Intune.", - "userConsentDisplayName": "Read Microsoft Intune apps", - "value": "DeviceManagementApps.Read.All" + "description": "Allows the app to read all multi-tenant organization details and tenants, without a signed-in user.", + "displayName": "Read all multi-tenant organization details and tenants", + "id": "4f994bc0-31bb-44bb-b480-7a7c1be8c02e", + "origin": "Application (Microsoft Graph)", + "value": "MultiTenantOrganization.Read.All" }, { - "description": "Allows the app to read and write the properties, group assignments and status of apps, app configurations and app protection policies managed by Microsoft Intune.", - "displayName": "Read and write Microsoft Intune apps", - "id": "7b3f05d5-f68c-4b8d-8c59-a2ecd12f24af", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write the properties, group assignments and status of apps, app configurations and app protection policies managed by Microsoft Intune.", - "userConsentDisplayName": "Read and write Microsoft Intune apps", - "value": "DeviceManagementApps.ReadWrite.All" + "description": "Allows the app to read and write all multi-tenant organization details and tenants, without a signed-in user.", + "displayName": "Read and write all multi-tenant organization details and tenants", + "id": "920def01-ca61-4d2d-b3df-105b46046a70", + "origin": "Application (Microsoft Graph)", + "value": "MultiTenantOrganization.ReadWrite.All" }, { - "description": "Allows the app to read the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings.", - "displayName": "Read Microsoft Intune RBAC settings", - "id": "49f0cc30-024c-4dfd-ab3e-82e137ee5431", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings.", - "userConsentDisplayName": "Read Microsoft Intune RBAC settings", - "value": "DeviceManagementRBAC.Read.All" + "description": "Allows the app to read configuration used for OAuth 2.0 mutual-TLS client authentication, without a signed-in user. This includes reading trusted certificate authorities.", + "displayName": "Read all configurations used for mutual-TLS client authentication.", + "id": "6daaff82-2880-496d-9d80-57e8e31195e2", + "origin": "Application (Microsoft Graph)", + "value": "MutualTlsOauthConfiguration.Read.All" }, { - "description": "Allows the app to read and write the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings.", - "displayName": "Read and write Microsoft Intune RBAC settings", - "id": "0c5e8a55-87a6-4556-93ab-adc52c4d862d", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings.", - "userConsentDisplayName": "Read and write Microsoft Intune RBAC settings", - "value": "DeviceManagementRBAC.ReadWrite.All" + "description": "Allows the app to read and update configuration used for OAuth 2.0 mutual-TLS client authentication, without a signed-in user. This includes reading and updating trusted certificate authorities.", + "displayName": "Read and write all configurations used for mutual-TLS client authentication.", + "id": "78bbf8cf-07d8-45ba-b0eb-1a7b48efbcf1", + "origin": "Application (Microsoft Graph)", + "value": "MutualTlsOauthConfiguration.ReadWrite.All" }, { - "description": "Allows the app to read the properties of devices managed by Microsoft Intune.", - "displayName": "Read Microsoft Intune devices", - "id": "314874da-47d6-4978-88dc-cf0d37f0bb82", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the properties of devices managed by Microsoft Intune.", - "userConsentDisplayName": "Read devices Microsoft Intune devices", - "value": "DeviceManagementManagedDevices.Read.All" + "description": "Allows the app to read all network access information and configuration settings without a signed-in user.", + "displayName": "Read all network access information", + "id": "e30060de-caa5-4331-99d3-6ac6c966a9a4", + "origin": "Application (Microsoft Graph)", + "value": "NetworkAccess.Read.All" }, { - "description": "Allows the app to read and write the properties of devices managed by Microsoft Intune. Does not allow high impact operations such as remote wipe and password reset on the device\u2019s owner.", - "displayName": "Read and write Microsoft Intune devices", - "id": "44642bfe-8385-4adc-8fc6-fe3cb2c375c3", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write the properties of devices managed by Microsoft Intune. Does not allow high impact operations such as remote wipe and password reset on the device\u2019s owner.", - "userConsentDisplayName": "Read and write Microsoft Intune devices", - "value": "DeviceManagementManagedDevices.ReadWrite.All" + "description": "Allows the app to read and write all network access information and configuration settings without a signed-in user.", + "displayName": "Read and write all network access information", + "id": "b10642fc-a6cf-4c46-87f9-e1f96c2a18aa", + "origin": "Application (Microsoft Graph)", + "value": "NetworkAccess.ReadWrite.All" }, { - "description": "Allows the app to perform remote high impact actions such as wiping the device or resetting the passcode on devices managed by Microsoft Intune.", - "displayName": "Perform user-impacting remote actions on Microsoft Intune devices", - "id": "3404d2bf-2b13-457e-a330-c24615765193", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to perform remote high impact actions such as wiping the device or resetting the passcode on devices managed by Microsoft Intune.", - "userConsentDisplayName": "Perform user-impacting remote actions on Microsoft Intune devices", - "value": "DeviceManagementManagedDevices.PrivilegedOperations.All" + "description": "Allows the app to read your organization's network access branches, without a signed-in user.", + "displayName": "Read properties of all branches for network access", + "id": "39ae4a24-1ef0-49e8-9d63-2a66f5c39edd", + "origin": "Application (Microsoft Graph)", + "value": "NetworkAccessBranch.Read.All" }, { - "description": "Allows the app to read and write Microsoft Intune service properties including device enrollment and third party service connection configuration.", - "displayName": "Read and write Microsoft Intune configuration", - "id": "662ed50a-ac44-4eef-ad86-62eed9be2a29", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write Microsoft Intune service properties including device enrollment and third party service connection configuration.", - "userConsentDisplayName": "Read and write Microsoft Intune configuration", - "value": "DeviceManagementServiceConfig.ReadWrite.All" + "description": "Allows the app to read and write your organization's network access branches, without a signed-in user.", + "displayName": "Read and write properties of all branches for network access", + "id": "8137102d-ec16-4191-aaf8-7aeda8026183", + "origin": "Application (Microsoft Graph)", + "value": "NetworkAccessBranch.ReadWrite.All" }, { - "description": "Allows the app to read Microsoft Intune service properties including device enrollment and third party service connection configuration.", - "displayName": "Read Microsoft Intune configuration", - "id": "8696daa5-bce5-4b2e-83f9-51b6defc4e1e", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read Microsoft Intune service properties including device enrollment and third party service connection configuration.", - "userConsentDisplayName": "Read Microsoft Intune configuration", - "value": "DeviceManagementServiceConfig.Read.All" + "description": "Allows the app to read your organization's network access policies, without a signed-in user.", + "displayName": "Read all security and routing policies for network access", + "id": "8a3d36bf-cb46-4bcc-bec9-8d92829dab84", + "origin": "Application (Microsoft Graph)", + "value": "NetworkAccessPolicy.Read.All" }, { - "description": "Allows the app to read your organization\u2019s security events on behalf of the signed-in user.", - "displayName": "Read your organization\u2019s security events", - "id": "64733abd-851e-478a-bffb-e47a14b18235", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your organization\u2019s security events on your behalf.", - "userConsentDisplayName": "Read your organization\u2019s security events", - "value": "SecurityEvents.Read.All" + "description": "Allows the app to read multi-tenant organization basic details and active tenants, without a signed-in user.", + "displayName": "Read multi-tenant organization basic details and active tenants", + "id": "f9c2b2a7-3895-4b2e-80f6-c924b456e50b", + "origin": "Application (Microsoft Graph)", + "value": "MultiTenantOrganization.ReadBasic.All" }, { - "description": "Allows the app to read your organization\u2019s security events on behalf of the signed-in user. Also allows the app to update editable properties in security events on behalf of the signed-in user.", - "displayName": "Read and update your organization\u2019s security events", - "id": "6aedf524-7e1c-45a7-bd76-ded8cab8d0fc", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your organization\u2019s security events on your behalf. Also allows you to update editable properties in security events.", - "userConsentDisplayName": "Read and update your organization\u2019s security events", - "value": "SecurityEvents.ReadWrite.All" + "description": "Allows the app to read organization-wide Dynamics customer voice settings, without a signed-in user.", + "displayName": "Read organization-wide Dynamics customer voice settings", + "id": "c18ae2dc-d9f3-4495-a93f-18980a0e159f", + "origin": "Application (Microsoft Graph)", + "value": "OrgSettings-DynamicsVoice.Read.All" }, { - "description": "Allows the app to read a scored list of relevant people of the signed-in user or other users in the signed-in user's organization. The list can include local contacts, contacts from social networking, your organization's directory, and people from recent communications (such as email and Skype).", - "displayName": "Read all users' relevant people lists", - "id": "b89f9189-71a5-4e70-b041-9887f0bc7e4a", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read a list of people in the order that is most relevant to you. Allows the app to read a list of people in the order that is most relevant to another user in your organization. These can include local contacts, contacts from social networking, people listed in your organization\u2019s directory, and people from recent communications.", - "userConsentDisplayName": "Read all users\u2019 relevant people lists", - "value": "People.Read.All" + "description": "Allows the app to read reference definitions without a signed-in user.", + "displayName": "View reference definitions", + "id": "6ee891c3-74a4-4148-8463-0c834375dfaf", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-ReferenceDefinition.Read.All" }, { - "description": "Manage the state and settings of all Microsoft education apps on behalf of the user.", - "displayName": "Manage education app settings", - "id": "63589852-04e3-46b4-bae9-15d5b1050748", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to manage the state and settings of all Microsoft education apps on your behalf.", - "userConsentDisplayName": "Manage your education app settings", - "value": "EduAdministration.ReadWrite" + "description": "Allows the app to read outbound data flows without a signed-in user.", + "displayName": "View outbound flow definitions", + "id": "61d0354c-5d88-483c-b974-a37ec3395a2c", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-OutboundFlow.Read.All" }, { - "description": "Read the state and settings of all Microsoft education apps on behalf of the user.", - "displayName": "Read education app settings", - "id": "8523895c-6081-45bf-8a5d-f062a2f12c9f", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to view the state and settings of all Microsoft education apps on your behalf.", - "userConsentDisplayName": "View your education app settings", - "value": "EduAdministration.Read" + "description": "Allows the app to assign Viva Engage role to a user, and remove a Viva Engage role from a user without a signed-in user.", + "displayName": "Modify Viva Engage role membership", + "id": "3ede5358-7366-4da8-a2f7-472bf9c7cc34", + "origin": "Application (Microsoft Graph)", + "value": "EngagementRole.ReadWrite.All" }, { - "description": "Allows the app to read and write assignments and their grades on behalf of the user.", - "displayName": "Read and write users' class assignments and their grades", - "id": "2f233e90-164b-4501-8bce-31af2559a2d3", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to view and modify your assignments on your behalf including \u00a0grades.", - "userConsentDisplayName": "View and modify your assignments and grades", - "value": "EduAssignments.ReadWrite" + "description": "Allows the app to read access packages and related entitlement management resources without a signed-in user.", + "displayName": "Read all entitlement management resources", + "id": "c74fd47d-ed3c-45c3-9a9e-b8676de685d2", + "origin": "Application (Microsoft Graph)", + "value": "EntitlementManagement.Read.All" }, { - "description": "Allows the app to read assignments and their grades on behalf of the user.", - "displayName": "Read users' class assignments and their grades", - "id": "091460c9-9c4a-49b2-81ef-1f3d852acce2", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to view your assignments on your behalf including grades.", - "userConsentDisplayName": "View your assignments and grades", - "value": "EduAssignments.Read" + "description": "Allows the app to read and write access packages and related entitlement management resources without a signed-in user.", + "displayName": "Read and write all entitlement management resources", + "id": "9acd699f-1e81-4958-b001-93b1d2506e19", + "origin": "Application (Microsoft Graph)", + "value": "EntitlementManagement.ReadWrite.All" }, { - "description": "Allows the app to read and write assignments without grades on behalf of the user.", - "displayName": "Read and write users' class assignments without grades", - "id": "2ef770a1-622a-47c4-93ee-28d6adbed3a0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to view and modify your assignments on your behalf without seeing grades.", - "userConsentDisplayName": "View and modify your assignments without grades", - "value": "EduAssignments.ReadWriteBasic" + "description": "Allows the app to list the all the snapshots, jobs and enumerate the changes of a specific preview job, on behalf of the signed-in user.", + "displayName": "Read Preview jobs and snapshots", + "id": "56eda3c5-3834-4815-bd41-6f8fa1295247", + "origin": "Application (Microsoft Graph)", + "value": "EntraBackup.Read.All" }, { - "description": "Allows the app to read assignments without grades on behalf of the user.", - "displayName": "Read users' class assignments without grades", - "id": "c0b0103b-c053-4b2e-9973-9f3a544ec9b8", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to view your assignments on your behalf without seeing grades.", - "userConsentDisplayName": "View your assignments without grades", - "value": "EduAssignments.ReadBasic" + "description": "Allows the app to read your organization's authentication event listeners without a signed-in user.", + "displayName": "Read all authentication event listeners", + "id": "b7f6385c-6ce6-4639-a480-e23c42ed9784", + "origin": "Application (Microsoft Graph)", + "value": "EventListener.Read.All" }, { - "description": "Allows the app to read and write the structure of schools and classes in an organization's roster and education-specific information about users to be read and written on behalf of the user.", - "displayName": "Read and write users' view of the roster", - "id": "359e19a6-e3fa-4d7f-bcab-d28ec592b51e", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to view and modify information about schools and classes in your organization and education-related information about you and other users on your behalf.", - "userConsentDisplayName": "View and modify your school, class and user information", - "value": "EduRoster.ReadWrite" + "description": "Allows the app to read or write your organization's authentication event listeners without a signed-in user.", + "displayName": "Read and write all authentication event listeners", + "id": "0edf5e9e-4ce8-468a-8432-d08631d18c43", + "origin": "Application (Microsoft Graph)", + "value": "EventListener.ReadWrite.All" }, { - "description": "Allows the app to read the structure of schools and classes in an organization's roster and education-specific information about users to be read on behalf of the user.", - "displayName": "Read users' view of the roster", - "id": "a4389601-22d9-4096-ac18-36a927199112", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to view information about schools and classes in your organization and education-related information about you and other users on your behalf.", - "userConsentDisplayName": "View your school, class and user information", - "value": "EduRoster.Read" + "description": "Allows the app to search the email message trace, without a signed-in user.", + "displayName": "Search the email message trace", + "id": "89b20d8a-76e2-4057-867b-9961f800b9a4", + "origin": "Application (Microsoft Graph)", + "value": "ExchangeMessageTrace.Read.All" }, { - "description": "Allows the app to read a limited subset of the properties from the structure of schools and classes in an organization's roster and a limited subset of properties about users to be read on behalf of the user.\u00a0Includes name, status, education role, email address and photo.", - "displayName": "Read a limited subset of users' view of the roster", - "id": "5d186531-d1bf-4f07-8cea-7c42119e1bd9", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to view minimal \u00a0information about both schools and classes in your organization and education-related information about you and other users on your behalf.", - "userConsentDisplayName": "View a limited subset of your school, class and user information", - "value": "EduRoster.ReadBasic" + "description": "Allows the app to read all external connections without a signed-in user.", + "displayName": "Read all external connections", + "id": "1914711b-a1cb-4793-b019-c2ce0ed21b8c", + "origin": "Application (Microsoft Graph)", + "value": "ExternalConnection.Read.All" }, { - "description": "Allows the app to report the signed-in user's app activity information to Microsoft Timeline.", - "displayName": "Write app activity to users' timeline", - "id": "367492fc-594d-4972-a9b5-0d58c622c91c", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to report your app activity information to Microsoft Timeline.", - "userConsentDisplayName": "Write app activity to your timeline", - "value": "UserTimelineActivity.Write.CreatedByApp" + "description": "Allows the app to read and write all external connections without a signed-in user.", + "displayName": "Read and write all external connections", + "id": "34c37bc0-2b40-4d5e-85e1-2365cd256d79", + "origin": "Application (Microsoft Graph)", + "value": "ExternalConnection.ReadWrite.All" }, { - "description": "Allows the app to create, read, update, and delete user's mailbox settings. Does not include permission to send mail.", - "displayName": "Read and write user mailbox settings", - "id": "818c620a-27a9-40bd-a6a5-d96f7d610b4b", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update, create, and delete your mailbox settings.", - "userConsentDisplayName": "Read and write to your mailbox settings", - "value": "MailboxSettings.ReadWrite" + "description": "Allows the app to read and write external connections without a signed-in user. The app can only read and write external connections that it is authorized to, or it can create new external connections.", + "displayName": "Read and write external connections", + "id": "f431331c-49a6-499f-be1c-62af19c34a9d", + "origin": "Application (Microsoft Graph)", + "value": "ExternalConnection.ReadWrite.OwnedBy" }, { - "description": "Allows the app to launch another app or communicate with another app on a user's device on behalf of the signed-in user.", - "displayName": "Communicate with user devices", - "id": "bac3b9c2-b516-4ef4-bd3b-c2ef73d8d804", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to launch another app or communicate with another app on a device that you own.", - "userConsentDisplayName": "Communicate with your other devices", - "value": "Device.Command" + "description": "Allows the app to read all external items without a signed-in user.", + "displayName": "Read all external items", + "id": "7a7cffad-37d2-4f48-afa4-c6ab129adcc2", + "origin": "Application (Microsoft Graph)", + "value": "ExternalItem.Read.All" }, { - "description": "Allows the app to read a user's list of devices on behalf of the signed-in user.", - "displayName": "Read user devices", - "id": "11d4cd79-5ba5-460f-803f-e22c8ab85ccd", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to see your list of devices.", - "userConsentDisplayName": "View your list of devices", - "value": "Device.Read" + "description": "Allows the app to read and write external items without a signed-in user. The app can only read external items of the connection that it is authorized to.", + "displayName": "Read and write external items", + "id": "8116ae0f-55c2-452d-9944-d18420f5b2c8", + "origin": "Application (Microsoft Graph)", + "value": "ExternalItem.ReadWrite.OwnedBy" }, { - "description": "Allows the app to read, share, and modify OneNote notebooks that the signed-in user has access to in the organization.", - "displayName": "Read and write all OneNote notebooks that user can access", - "id": "64ac0503-b4fa-45d9-b544-71a463f05da0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, share, and modify all the OneNote notebooks that you have access to.", - "userConsentDisplayName": "Read and write all OneNote notebooks that you can access", - "value": "Notes.ReadWrite.All" + "description": "Allows the app to read available properties of external user profiles, without a signed-in user.", + "displayName": "Read all external user profiles", + "id": "1987d7a0-d602-4262-ab90-cfdd43b37545", + "origin": "Application (Microsoft Graph)", + "value": "ExternalUserProfile.Read.All" }, { - "description": "Allows the app to read OneNote notebooks that the signed-in user has access to in the organization.", - "displayName": "Read all OneNote notebooks that user can access", - "id": "dfabfca6-ee36-4db2-8208-7a28381419b3", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all the OneNote notebooks that you have access to.", - "userConsentDisplayName": "Read all OneNote notebooks that you can access", - "value": "Notes.Read.All" + "description": "Allows the app to read and write available properties of external user profiles, without a signed-in user.", + "displayName": "Read and write all external user profiles", + "id": "761327c9-d819-4c08-9a5f-874cd2826608", + "origin": "Application (Microsoft Graph)", + "value": "ExternalUserProfile.ReadWrite.All" }, { - "description": "Allows the app to read, share, and modify OneNote notebooks on behalf of the signed-in user.", - "displayName": "Read and write user OneNote notebooks", - "id": "615e26af-c38a-4150-ae3e-c3b0d4cb1d6a", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, share, and modify OneNote notebooks on your behalf.", - "userConsentDisplayName": "Read and write your OneNote notebooks", - "value": "Notes.ReadWrite" + "description": "Allows the app to ingest SharePoint and OneDrive content to make it available in the search index, without a signed-in user.", + "displayName": "Ingest SharePoint and OneDrive content to make it available in the search index", + "id": "65891b00-2fd9-4e33-be27-04a53132e3df", + "origin": "Application (Microsoft Graph)", + "value": "FileIngestion.Ingest" }, { - "description": "Allows the app to read OneNote notebooks on behalf of the signed-in user.", - "displayName": "Read user OneNote notebooks", - "id": "371361e4-b9e2-4a3f-8315-2a301a3b0a3d", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read OneNote notebooks on your behalf.", - "userConsentDisplayName": "Read your OneNote notebooks", - "value": "Notes.Read" + "description": "Allows the app to manage onboarding for a Hybrid Cloud tenant, without a signed-in user.", + "displayName": "Manage onboarding for a Hybrid Cloud tenant", + "id": "766c601b-c009-4438-8290-c8b05fa00c4b", + "origin": "Application (Microsoft Graph)", + "value": "FileIngestionHybridOnboarding.Manage" }, { - "description": "This is deprecated! Do not use! This permission no longer has any effect. You can safely consent to it. No additional privileges will be granted to the app.", - "displayName": "Limited notebook access (deprecated)", - "id": "ed68249d-017c-4df5-9113-e684c7f8760b", - "Origin": "Delegated", - "userConsentDescription": "This permission no longer has any effect. You can safely consent to it. No additional privileges will be granted to the app.", - "userConsentDisplayName": "Limited access to your OneNote notebooks for this app (preview)", - "value": "Notes.ReadWrite.CreatedByApp" + "description": "Allows the app to list all Viva Engage roles and role memberships without a signed-in user.", + "displayName": "Read all Viva Engage roles and role memberships", + "id": "30614864-4114-45ef-bdd9-0dd7894a1cc4", + "origin": "Application (Microsoft Graph)", + "value": "EngagementRole.Read.All" }, { - "description": "Allows the app to read the titles of OneNote notebooks and sections and to create new pages, notebooks, and sections on behalf of the signed-in user.", - "displayName": "Create user OneNote notebooks", - "id": "9d822255-d64d-4b7a-afdb-833b9a97ed02", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to view the titles of your OneNote notebooks and sections and to create new pages, notebooks, and sections on your behalf.", - "userConsentDisplayName": "Create your OneNote notebooks", - "value": "Notes.Create" + "description": "Allows the app to read all files in all site collections without a signed in user.", + "displayName": "Read files in all site collections", + "id": "01d4889c-1287-42c6-ac1f-5d1e02578ef6", + "origin": "Application (Microsoft Graph)", + "value": "Files.Read.All" }, { - "description": "Allows the app to invite guest users to the organization, on behalf of the signed-in user.", - "displayName": "Invite guest users to the organization", - "id": "63dd7cd9-b489-4adf-a28c-ac38b9a0f962", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to invite guest users to the organization, on your behalf.", - "userConsentDisplayName": "Invite guest users to the organization", - "value": "User.Invite.All" + "description": "Allows the app to list Viva Engage Teams QA conversations, and to read their properties without a signed-in user.", + "displayName": "Read all Viva Engage Teams QA conversations", + "id": "d746beae-b46e-446e-924a-5b805a5c4467", + "origin": "Application (Microsoft Graph)", + "value": "EngagementMeetingConversation.Read.All" }, { - "description": "Allows the app to the read user's mailbox settings. Does not include permission to send mail.", - "displayName": "Read user mailbox settings", - "id": "87f447af-9fa4-4c32-9dfa-4a57a73d18ce", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your mailbox settings.", - "userConsentDisplayName": "Read your mailbox settings", - "value": "MailboxSettings.Read" + "description": "Allows the app to create Viva Engage conversations, read all conversation properties, update conversation properties, and delete conversations without a signed-in user.", + "displayName": "Read and write all Viva Engage conversations", + "id": "bfbd4840-fba0-43a7-93a9-465b687e47d0", + "origin": "Application (Microsoft Graph)", + "value": "EngagementConversation.ReadWrite.All" }, { - "description": "(Preview) Allows the app to read files that the user selects. The app has access for several hours after the user selects a file.", - "displayName": "Read files that the user selects (preview)", - "id": "5447fe39-cb82-4c1a-b977-520e67e724eb", - "Origin": "Delegated", - "userConsentDescription": "(Preview) Allows the app to read files that you select. After you select a file, the app has access to the file for several hours.", - "userConsentDisplayName": "Read selected files", - "value": "Files.Read.Selected" + "description": "Read the state and settings of all Microsoft education apps.", + "displayName": "Read Education app settings", + "id": "7c9db06a-ec2d-4e7b-a592-5a1e30992566", + "origin": "Application (Microsoft Graph)", + "value": "EduAdministration.Read.All" }, { - "description": "(Preview) Allows the app to read and write files that the user selects. The app has access for several hours after the user selects a file.", - "displayName": "Read and write files that the user selects (preview)", - "id": "17dde5bd-8c17-420f-a486-969730c1b827", - "Origin": "Delegated", - "userConsentDescription": "(Preview) Allows the app to read and write files that you select. After you select a file, the app has access to the file for several hours.", - "userConsentDisplayName": "Read and write selected files", - "value": "Files.ReadWrite.Selected" + "description": "Manage the state and settings of all Microsoft education apps.", + "displayName": "Manage education app settings", + "id": "9bc431c3-b8bc-4a8d-a219-40f10f92eff6", + "origin": "Application (Microsoft Graph)", + "value": "EduAdministration.ReadWrite.All" }, { - "description": "(Preview) Allows the app to read, create, update and delete files in the application's folder.", - "displayName": "Have full access to the application's folder (preview)", - "id": "8019c312-3263-48e6-825e-2b833497195b", - "Origin": "Delegated", - "userConsentDescription": "(Preview) Allows the app to read, create, update and delete files in the application's folder.", - "userConsentDisplayName": "Have full access to the application's folder", - "value": "Files.ReadWrite.AppFolder" + "description": "Allows the app to read all class assignments with grades for all users without a signed-in user.", + "displayName": "Read all class assignments with grades", + "id": "4c37e1b6-35a1-43bf-926a-6f30f2cdf585", + "origin": "Application (Microsoft Graph)", + "value": "EduAssignments.Read.All" }, { - "description": "Allows an app to read all service usage reports on behalf of the signed-in user. Services that provide usage reports include Office 365 and Azure Active Directory.", - "displayName": "Read all usage reports", - "id": "02e97553-ed7b-43d0-ab3c-f8bace0d040c", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to read all service usage reports on your behalf. Services that provide usage reports include Office 365 and Azure Active Directory.", - "userConsentDisplayName": "Read all usage reports", - "value": "Reports.Read.All" + "description": "Allows the app to read all class assignments without grades for all users without a signed-in user.", + "displayName": "Read all class assignments without grades", + "id": "6e0a958b-b7fc-4348-b7c4-a6ab9fd3dd0e", + "origin": "Application (Microsoft Graph)", + "value": "EduAssignments.ReadBasic.All" }, { - "description": "Allows the application to edit or delete documents and list items in all site collections on behalf of the signed-in user.", - "displayName": "Edit or delete items in all site collections", - "id": "89fe6a52-be36-487e-b7d8-d061c450a026", - "Origin": "Delegated", - "userConsentDescription": "Allow the application to edit or delete documents and list items in all site collections on your behalf.", - "userConsentDisplayName": "Edit or delete items in all site collections", - "value": "Sites.ReadWrite.All" + "description": "Allows the app to create, read, update and delete all class assignments with grades for all users without a signed-in user.", + "displayName": "Create, read, update and delete all class assignments with grades", + "id": "0d22204b-6cad-4dd0-8362-3e3f2ae699d9", + "origin": "Application (Microsoft Graph)", + "value": "EduAssignments.ReadWrite.All" }, { - "description": "Allows the app to create, read, update, and delete tasks a user has permissions to, including their own and shared tasks.", - "displayName": "Read and write user and shared tasks", - "id": "c5ddf11b-c114-4886-8558-8a4e557cd52b", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update, create, and delete tasks you have permissions to access, including your own and shared tasks.", - "userConsentDisplayName": "Read and write to your and shared tasks", - "value": "Tasks.ReadWrite.Shared" + "description": "Allows the app to create, read, update and delete all class assignments without grades for all users without a signed-in user.", + "displayName": "Create, read, update and delete all class assignments without grades", + "id": "f431cc63-a2de-48c4-8054-a34bc093af84", + "origin": "Application (Microsoft Graph)", + "value": "EduAssignments.ReadWriteBasic.All" }, { - "description": "Allows the app to read tasks a user has permissions to access, including their own and shared tasks.", - "displayName": "Read user and shared tasks", - "id": "88d21fd4-8e5a-4c32-b5e2-4a1c95f34f72", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read tasks you have permissions to access, including your own and shared tasks.", - "userConsentDisplayName": "Read your and shared tasks", - "value": "Tasks.Read.Shared" + "description": "Allows the app to read all modules and resources, without a signed-in user.", + "displayName": "Read all class modules and resources", + "id": "6cdb464c-3a03-40f8-900b-4cb7ea1da9c0", + "origin": "Application (Microsoft Graph)", + "value": "EduCurricula.Read.All" }, { - "description": "Allows the app to create, read, update, and delete contacts a user has permissions to, including their own and shared contacts.", - "displayName": "Read and write user and shared contacts", - "id": "afb6c84b-06be-49af-80bb-8f3f77004eab", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update, create, and delete contacts you have permissions to access, including your own and shared contacts.", - "userConsentDisplayName": "Read and write to your and shared contacts", - "value": "Contacts.ReadWrite.Shared" + "description": "Allows the app to read and write all modules and resources, without a signed-in user.", + "displayName": "Read and write all class modules and resources", + "id": "6a0c2318-d59d-4c7d-bf2e-5f3902dc2593", + "origin": "Application (Microsoft Graph)", + "value": "EduCurricula.ReadWrite.All" }, { - "description": "Allows the app to read contacts a user has permissions to access, including their own and shared contacts.", - "displayName": "Read user and shared contacts", - "id": "242b9d9e-ed24-4d09-9a52-f43769beb9d4", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read contacts you have permissions to access, including your own and shared contacts.", - "userConsentDisplayName": "Read your and shared contacts", - "value": "Contacts.Read.Shared" + "description": "Allows the app to read all tenant users reading assignments submissions data without a signed-in user.", + "displayName": "Read all tenant reading assignments submissions data", + "id": "ad248c30-1919-40c8-b3d2-304481894e88", + "origin": "Application (Microsoft Graph)", + "value": "EduReports-Reading.Read.All" }, { - "description": "Allows the app to create, read, update and delete events in all calendars in the organization user has permissions to access. This includes delegate and shared calendars.", - "displayName": "Read and write user and shared calendars", - "id": "12466101-c9b8-439a-8589-dd09ee67e8e9", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update, create and delete events in all calendars in your organization you have permissions to access. This includes delegate and shared calendars.", - "userConsentDisplayName": "Read and write to your and shared calendars", - "value": "Calendars.ReadWrite.Shared" + "description": "Allows the app to read all tenant users reading assignments submissions data (excludes student-identifying information) without a signed-in user.", + "displayName": "Read all tenant reading assignments submissions data", + "id": "040330d7-be7e-4130-b349-a6eb3a56e2f8", + "origin": "Application (Microsoft Graph)", + "value": "EduReports-Reading.ReadAnonymous.All" }, { - "description": "Allows the app to read events in all calendars that the user can access, including delegate and shared calendars.", - "displayName": "Read user and shared calendars", - "id": "2b9c4092-424d-4249-948d-b43879977640", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read events in all calendars that you can access, including delegate and shared calendars.\u00a0", - "userConsentDisplayName": "Read calendars\u00a0you can access", - "value": "Calendars.Read.Shared" + "description": "Allows the app to read all tenant users reflect check-ins submissions data without a signed-in user.", + "displayName": "Read all tenant reflect check-ins submissions data", + "id": "c5debf73-bdc8-473d-bf07-f4074ad05f71", + "origin": "Application (Microsoft Graph)", + "value": "EduReports-Reflect.Read.All" }, { - "description": "Allows the app to send mail as the signed-in user, including sending on-behalf of others.", - "displayName": "Send mail on behalf of others", - "id": "a367ab51-6b49-43bf-a716-a1fb06d2a174", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to send mail as you or on-behalf of someone else.", - "userConsentDisplayName": "Send mail on behalf of others or yourself", - "value": "Mail.Send.Shared" + "description": "Allows the app to read all tenant users reflect check-ins submissions data (excludes responder-identifying information) without a signed-in user.", + "displayName": "Read all tenant reflect check-ins submissions data", + "id": "f5d05dba-7ef0-46fc-b62c-a7282555f428", + "origin": "Application (Microsoft Graph)", + "value": "EduReports-Reflect.ReadAnonymous.All" }, { - "description": "Allows the app to create, read, update, and delete mail a user has permission to access, including their own and shared mail. Does not include permission to send mail.", - "displayName": "Read and write user and shared mail", - "id": "5df07973-7d5d-46ed-9847-1271055cbd51", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update, create, and delete mail you have permission to access, including your own and shared mail. Does not allow the app to send mail on your behalf.", - "userConsentDisplayName": "Read and write mail\u00a0you can access", - "value": "Mail.ReadWrite.Shared" + "description": "Allows the app to read the structure of schools and classes in the organization's roster and education-specific information about all users to be read.", + "displayName": "Read the organization's roster", + "id": "e0ac9e1b-cb65-4fc5-87c5-1a8bc181f648", + "origin": "Application (Microsoft Graph)", + "value": "EduRoster.Read.All" }, { - "description": "Allows the app to read mail a user can access, including their own and shared mail.", - "displayName": "Read user and shared mail", - "id": "7b9103a5-4610-446b-9670-80643382c1fa", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read mail you can access, including shared mail.", - "userConsentDisplayName": "Read mail you can access", - "value": "Mail.Read.Shared" + "description": "Allows the app to read a limited subset of properties from both the structure of schools and classes in the organization's roster and education-specific information about all users. Includes name, status, role, email address and photo.", + "displayName": "Read a limited subset of the organization's roster", + "id": "0d412a8c-a06c-439f-b3ec-8abcf54d2f96", + "origin": "Application (Microsoft Graph)", + "value": "EduRoster.ReadBasic.All" }, { - "description": "Allows users to sign-in to the app, and allows the app to read the profile of signed-in users. It also allows the app to read basic company information of signed-in users.", - "displayName": "Sign in and read user profile", - "id": "e1fe6dd8-ba31-4d61-89e7-88639da4683d", - "Origin": "Delegated", - "userConsentDescription": "Allows you to sign in to the app with your organizational account and let the app read your profile. It also allows the app to read basic company information.", - "userConsentDisplayName": "Sign you in and read your profile", - "value": "User.Read" + "description": "Allows the app to read and write the structure of schools and classes in the organization's roster and education-specific information about all users to be read and written.", + "displayName": "Read and write the organization's roster", + "id": "d1808e82-ce13-47af-ae0d-f9b254e6d58a", + "origin": "Application (Microsoft Graph)", + "value": "EduRoster.ReadWrite.All" }, { - "description": "Allows the app to read your profile. It also allows the app to update your profile information on your behalf.", - "displayName": "Read and write access to user profile", - "id": "b4e74841-8e56-480b-be8b-910348b18b4c", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your profile, and discover your group membership, reports and manager. It also allows the app to update your profile information on your behalf.", - "userConsentDisplayName": "Read and update your profile", - "value": "User.ReadWrite" + "description": "Allows the app to create Viva Engage conversations without a signed-in user.", + "displayName": "Read and write all Viva Engage conversations", + "id": "e1d2136d-eaaf-427a-a7db-f97dbe847c27", + "origin": "Application (Microsoft Graph)", + "value": "EngagementConversation.Migration.All" }, { - "description": "Allows the app to read a basic set of profile properties of other users in your organization on behalf of the signed-in user. This includes display name, first and last name, email address and photo.", - "displayName": "Read all users' basic profiles", - "id": "b340eb25-3456-403f-be2f-af7a0d370277", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read a basic set of profile properties of other users in your organization on your behalf. Includes display name, first and last name, email address and photo.", - "userConsentDisplayName": "Read all users' basic profiles", - "value": "User.ReadBasic.All" + "description": "Allows the app to list Viva Engage conversations, and to read their properties without a signed-in user.", + "displayName": "Read all Viva Engage conversations", + "id": "2c495153-cd0e-41b4-9980-3bcecf1ca22f", + "origin": "Application (Microsoft Graph)", + "value": "EngagementConversation.Read.All" }, { - "description": "Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user.", - "displayName": "Read all users' full profiles", - "id": "a154be20-db9c-4678-8ab7-66f6cc099a59", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on your behalf.", - "userConsentDisplayName": "Read all users' full profiles", - "value": "User.Read.All" + "description": "Allows the app to export Viva Engage data for compliance, GDPR, and admin scenarios without a signed-in user.", + "displayName": "Export Viva Engage data", + "id": "eda8c187-a7d5-42cb-b2e1-c9142f63899f", + "origin": "Application (Microsoft Graph)", + "value": "EngagementExport.Read.All" }, { - "description": "Allows the app to read and write the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user.", - "displayName": "Read and write all users' full profiles", - "id": "204e0828-b5ca-4ad8-b9f3-f32a958e7cc4", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write the full set of profile properties, reports, and managers of other users in your organization, on your behalf.", - "userConsentDisplayName": "Read and write all users' full profiles", - "value": "User.ReadWrite.All" + "description": "Allows the app to read, create, update and delete all files in all site collections without a signed in user.", + "displayName": "Read and write files in all site collections", + "id": "75359482-378d-4052-8f01-80520e7db3cd", + "origin": "Application (Microsoft Graph)", + "value": "Files.ReadWrite.All" }, { - "description": "Allows the app to list groups, and to read their properties and all group memberships on behalf of the signed-in user. Also allows the app to read calendar, conversations, files, and other group content for all groups the signed-in user can access. ", - "displayName": "Read all groups", - "id": "5f8c59db-677d-491f-a6b8-5f174b11ec1d", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to list groups, and to read their properties and all group memberships on your behalf. Also allows the app to read calendar, conversations, files, and other group content for all groups you can access. ", - "userConsentDisplayName": "Read all groups", - "value": "Group.Read.All" + "description": "Allows the app to read, create, update and delete files in the application's folder without a signed in user.", + "displayName": "Have full access to the application's folder without a signed in user.", + "id": "b47b160b-1054-4efd-9ca0-e2f614696086", + "origin": "Application (Microsoft Graph)", + "value": "Files.ReadWrite.AppFolder" }, { - "description": "Allows the app to create groups and read all group properties and memberships on behalf of the signed-in user. Additionally allows group owners to manage their groups and allows group members to update group content.", - "displayName": "Read and write all groups", - "id": "4e46008b-f24c-477d-8fff-7bb4ec7aafe0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to create groups and read all group properties and memberships on your behalf. Additionally allows the app to manage your groups and to update group content for groups you are a member of.", - "userConsentDisplayName": "Read and write all groups", - "value": "Group.ReadWrite.All" + "description": "Allow the application to access a subset of files without a signed in user. The specific files and the permissions granted will be configured in SharePoint Online or OneDrive.", + "displayName": "Access selected Files without a signed in user.", + "id": "bd61925e-3bf4-4d62-bc0b-06b06c96d95c", + "origin": "Application (Microsoft Graph)", + "value": "Files.SelectedOperations.Selected" }, { - "description": "Allows the app to read data in your organization's directory, such as users, groups and apps.", - "displayName": "Read directory data", - "id": "06da0dbc-49e2-44d2-8312-53f166ab848a", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read data in your organization's directory.", - "userConsentDisplayName": "Read directory data", - "value": "Directory.Read.All" + "description": "Allows the app to read and write your organization’s identity (authentication) providers’ properties without a signed in user.", + "displayName": "Read and write identity providers", + "id": "90db2b9a-d928-4d33-a4dd-8442ae3d41e4", + "origin": "Application (Microsoft Graph)", + "value": "IdentityProvider.ReadWrite.All" }, { - "description": "Allows the app to read and write data in your organization's directory, such as users, and groups. It does not allow the app to delete users or groups, or reset user passwords.", - "displayName": "Read and write directory data", - "id": "c5366453-9fb0-48a5-a156-24f0c49a4b84", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write data in your organization's directory, such as other users, groups. It does not allow the app to delete users or groups, or reset user passwords.", - "userConsentDisplayName": "Read and write directory data", - "value": "Directory.ReadWrite.All" + "description": "Allows the app to read the identity risk event information for your organization without a signed in user.", + "displayName": "Read all identity risk event information", + "id": "6e472fd1-ad78-48da-a0f0-97ab2c6b769e", + "origin": "Application (Microsoft Graph)", + "value": "IdentityRiskEvent.Read.All" }, { - "description": "Allows the app to have the same access to information in the directory as the signed-in user.", - "displayName": "Access directory as the signed in user", - "id": "0e263e50-5827-48a4-b97c-d940288653c7", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to have the same access to information in your work or school directory as you do.", - "userConsentDisplayName": "Access the directory as you", - "value": "Directory.AccessAsUser.All" + "description": "Allows the app to read and update identity risk detection information for your organization without a signed-in user. Update operations include confirming risk event detections. ", + "displayName": "Read and write all risk detection information", + "id": "db06fb33-1953-4b7b-a2ac-f1e2c854f7ae", + "origin": "Application (Microsoft Graph)", + "value": "IdentityRiskEvent.ReadWrite.All" }, { - "description": "Allows the app to create, read, update, and delete email in user mailboxes. Does not include permission to send mail. ", - "displayName": "Read and write access to user mail ", - "id": "024d486e-b451-40bb-833d-3e66d98c5c73", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update, create and delete email in your mailbox. Does not include permission to send mail. ", - "userConsentDisplayName": "Read and write access to your mail ", - "value": "Mail.ReadWrite" + "description": "Allows the app to read the risky agents information in your organization without a signed-in user.", + "displayName": "Read all risky agents information", + "id": "4aadfb66-d49a-414a-a883-d8c240b6fa33", + "origin": "Application (Microsoft Graph)", + "value": "IdentityRiskyAgent.Read.All" }, { - "description": "Allows the app to send mail as users in the organization. ", - "displayName": "Send mail as a user ", - "id": "e383f46e-2787-4529-855e-0e479a3ffac0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to send mail as you. ", - "userConsentDisplayName": "Send mail as you ", - "value": "Mail.Send" + "description": "Allows the app to read and update risky agents information in your organization without a signed-in user.", + "displayName": "Read and write risky agents information", + "id": "dca4e4fd-a7cf-4e6f-86d1-d1ec094d766e", + "origin": "Application (Microsoft Graph)", + "value": "IdentityRiskyAgent.ReadWrite.All" }, { - "description": "Allows the app to read events in user calendars . ", - "displayName": "Read user calendars ", - "id": "465a38f9-76ea-45b9-9f34-9e8b0d4b0b42", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read events in your calendars. ", - "userConsentDisplayName": "Read your calendars ", - "value": "Calendars.Read" + "description": "Allows the app to read all risky service principal information for your organization, without a signed-in user.", + "displayName": "Read all identity risky service principal information", + "id": "607c7344-0eed-41e5-823a-9695ebe1b7b0", + "origin": "Application (Microsoft Graph)", + "value": "IdentityRiskyServicePrincipal.Read.All" }, { - "description": "Allows the app to create, read, update, and delete events in user calendars. ", - "displayName": "Have full access to user calendars ", - "id": "1ec239c2-d7c9-4623-a91a-a9775856bb36", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update, create and delete events in your calendars. ", - "userConsentDisplayName": "Have full access to your calendars ", - "value": "Calendars.ReadWrite" + "description": "Allows the app to read and update identity risky service principal for your organization, without a signed-in user.", + "displayName": "Read and write all identity risky service principal information", + "id": "cb8d6980-6bcb-4507-afec-ed6de3a2d798", + "origin": "Application (Microsoft Graph)", + "value": "IdentityRiskyServicePrincipal.ReadWrite.All" }, { - "description": "Allows the app to read user contacts. ", - "displayName": "Read user contacts ", - "id": "ff74d97f-43af-4b68-9f2a-b77ee6968c5d", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read contacts in your contact folders. ", - "userConsentDisplayName": "Read your contacts ", - "value": "Contacts.Read" + "description": "Allows the app to read the identity risky user information for your organization without a signed in user.", + "displayName": "Read all identity risky user information", + "id": "dc5007c0-2d7d-4c42-879c-2dab87571379", + "origin": "Application (Microsoft Graph)", + "value": "IdentityRiskyUser.Read.All" }, { - "description": "Allows the app to create, read, update, and delete user contacts. ", - "displayName": "Have full access to user contacts ", - "id": "d56682ec-c09e-4743-aaf4-1a3aac4caa21", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update, create and delete contacts in your contact folders. ", - "userConsentDisplayName": "Have full access of your contacts ", - "value": "Contacts.ReadWrite" + "description": "Allows the app to read and update identity risky user information for your organization without a signed-in user. Update operations include dismissing risky users.", + "displayName": "Read and write all risky user information", + "id": "656f6061-f9fe-4807-9708-6a2e0934df76", + "origin": "Application (Microsoft Graph)", + "value": "IdentityRiskyUser.ReadWrite.All" }, { - "description": "Allows the app to read the signed-in user's files.", - "displayName": "Read user files", - "id": "10465720-29dd-4523-a11a-6a75c743c9d9", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your files.", - "userConsentDisplayName": "Read your files", - "value": "Files.Read" + "description": "Allows the app to read your organization's user flows, without a signed-in user.", + "displayName": "Read all identity user flows", + "id": "1b0c317f-dd31-4305-9932-259a8b6e8099", + "origin": "Application (Microsoft Graph)", + "value": "IdentityUserFlow.Read.All" }, { - "description": "Allows the app to read, create, update and delete the signed-in user's files.", - "displayName": "Have full access to user files", - "id": "5c28f0bf-8a70-41f1-8ab2-9032436ddb65", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, create, update, and delete your files.", - "userConsentDisplayName": "Have full access to your files", - "value": "Files.ReadWrite" + "description": "Allows the app to read or write your organization's user flows, without a signed-in user.", + "displayName": "Read and write all identity user flows", + "id": "65319a09-a2be-469d-8782-f6b07debf789", + "origin": "Application (Microsoft Graph)", + "value": "IdentityUserFlow.ReadWrite.All" }, { - "description": "Allows the app to read all files the signed-in user can access.", - "displayName": "Read all files that user can access", - "id": "df85f4d6-205c-4ac5-a5ea-6bf408dba283", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all files you can access.", - "userConsentDisplayName": "Read all files that you have access to", - "value": "Files.Read.All" + "description": "Allows the app to read basic service and resource information without a signed-in user.", + "displayName": "View basic service and resource information", + "id": "4f5ac95f-62fd-472c-b60f-125d24ca0bc5", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData.ReadBasic.All" + }, + { + "description": "Allows the app to read data connectors without a signed-in user.", + "displayName": "View data connector definitions", + "id": "7ab52c2f-a2ee-4d98-9ebc-725e3934aae2", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-DataConnector.Read.All" }, { - "description": "Allows the app to read, create, update and delete all files the signed-in user can access.", - "displayName": "Have full access to all files user can access", - "id": "863451e7-0667-486c-a5d6-d135439485f0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, create, update and delete all files that you can access.", - "userConsentDisplayName": "Have full access to all files you have access to", - "value": "Files.ReadWrite.All" + "description": "Allows the app to read and write data connectors without a signed-in user.", + "displayName": "Manage data connector definitions", + "id": "eda0971c-482e-4345-b28f-69c309cb8a34", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-DataConnector.ReadWrite.All" }, { - "description": "Allows the application to read documents and list items in all site collections on behalf of the signed-in user", - "displayName": "Read items in all site collections", - "id": "205e70e5-aba6-4c52-a976-6d2d46c48043", - "Origin": "Delegated", - "userConsentDescription": "Allow the application to read documents and list items in all site collections on your behalf", - "userConsentDisplayName": "Read items in all site collections", - "value": "Sites.Read.All" + "description": "Allows the app to upload data files to a data connector without a signed-in user.", + "displayName": "Upload files to a data connector", + "id": "9334c44b-a7c6-4350-8036-6bf8e02b4c1f", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-DataConnector.Upload" }, { - "description": "Allows users to sign in to the app with their work or school accounts and allows the app to see basic user profile information.", - "displayName": "Sign users in", - "id": "37f7f235-527c-4136-accd-4a02d197296e", - "Origin": "Delegated", - "userConsentDescription": "Allows you to sign in to the app with your work or school account and allows the app to read your basic profile information.", - "userConsentDisplayName": "Sign in as you", - "value": "openid" + "description": "Allows the app to read inbound data flows without a signed-in user.", + "displayName": "View inbound flow definitions", + "id": "305f6ba2-049a-4b1b-88bb-fe7e08758a00", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-InboundFlow.Read.All" }, { - "description": "Allows the app to read your users' primary email address", - "displayName": "View users' email address", - "id": "64a6cdd6-aab1-4aaf-94b8-3cc8405e90d0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your primary email address", - "userConsentDisplayName": "View your email address", - "value": "email" + "description": "Allows the app to read and write inbound data flows without a signed-in user.", + "displayName": "Manage inbound flow definitions", + "id": "e688c61f-d4c6-4d64-a197-3bcf6ba1d6ad", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-InboundFlow.ReadWrite.All" }, { - "description": "Allows the app to read identity risk event information for all users in your organization on behalf of the signed-in user. ", - "displayName": "Read identity risk event information", - "id": "8f6a01e7-0391-4ee5-aa22-a3af122cef27", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read identity risk event information for all users in your organization on behalf of the signed-in user. ", - "userConsentDisplayName": "Read identity risk event information", - "value": "IdentityRiskEvent.Read.All" + "description": "Allows the app to read your organization’s identity (authentication) providers’ properties without a signed in user.", + "displayName": "Read identity providers", + "id": "e321f0bb-e7f7-481e-bb28-e3b0b32d4bd0", + "origin": "Application (Microsoft Graph)", + "value": "IdentityProvider.Read.All" }, { - "description": "Allows the app to read the memberships of hidden groups and administrative units on behalf of the signed-in user, for those hidden groups and administrative units that the signed-in user has access to.", - "displayName": "Read hidden memberships", - "id": "f6a3db3e-f7e8-4ed2-a414-557c8c9830be", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the memberships of hidden groups or administrative units on your behalf, for those hidden groups or adminstrative units that you have access to.", - "userConsentDisplayName": "Read your hidden memberships", - "value": "Member.Read.Hidden" + "description": "Allows the app to read and write identity notification settings, customize email templates, and send test emails without a signed-in user.", + "displayName": "Read and write all identity notification settings and templates", + "id": "d9fe7b9f-cb27-4289-9cb4-54debd9d3c25", + "origin": "Application (Microsoft Graph)", + "value": "IdentityNotifications.ReadWrite.All" }, { - "description": "Allows the app to read a ranked list of relevant people of the signed-in user. The list includes local contacts, contacts from social networking, your organization's directory, and people from recent communications (such as email and Skype).", - "displayName": "Read users' relevant people lists", - "id": "ba47897c-39ec-4d83-8086-ee8256fa737d", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read a list of people in the order that's most relevant to you. This includes your local contacts, your contacts from social networking, people listed in your organization's directory, and people from recent communications.", - "userConsentDisplayName": "Read your relevant people list", - "value": "People.Read" + "description": "Allows the app to read identity notification settings, email templates, and prerequisites without a signed-in user.", + "displayName": "Read all identity notification settings and templates", + "id": "52ced3dd-dbb6-41a0-9ce5-61a056be97b8", + "origin": "Application (Microsoft Graph)", + "value": "IdentityNotifications.Read.All" }, { - "description": "Allows the application to create or delete document libraries and lists in all site collections on behalf of the signed-in user.", - "displayName": "Create, edit, and delete items and lists in all site collections", - "id": "65e50fdc-43b7-4915-933e-e8138f11f40a", - "Origin": "Delegated", - "userConsentDescription": "Allow the application to create or delete document libraries and lists in all site collections on your behalf.", - "userConsentDisplayName": "Create, edit, and delete items and lists in all your site collections", - "value": "Sites.Manage.All" + "description": "Allows the app to read and write all scenario monitoring alerts, without a signed-in user.", + "displayName": "Read and write all scenario monitoring alerts", + "id": "432e76f0-8af6-4315-a853-66ab9538f480", + "origin": "Application (Microsoft Graph)", + "value": "HealthMonitoringAlertConfig.ReadWrite.All" }, { - "description": "Allows the application to have full control of all site collections on behalf of the signed-in user.", - "displayName": "Have full control of all site collections", - "id": "5a54b8b3-347c-476d-8f8e-42d5c7424d29", - "Origin": "Delegated", - "userConsentDescription": "Allow the application to have full control of all site collections on your behalf.", - "userConsentDisplayName": "Have full control of all your site collections", - "value": "Sites.FullControl.All" + "description": "Allows the application to utilize the file storage container platform to manage containers, without a signed-in user. The specific file storage containers and the permissions granted to them will be configured in Microsoft 365 by the developer of each container type.", + "displayName": "Access selected file storage containers", + "id": "40dc41bc-0f7e-42ff-89bd-d9516947e474", + "origin": "Application (Microsoft Graph)", + "value": "FileStorageContainer.Selected" }, { - "description": "Allows the app to read and write your organization\u2019s identity (authentication) providers\u2019 properties on behalf of the user.", - "displayName": "Read and write identity providers", - "id": "f13ce604-1677-429f-90bd-8a10b9f01325", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write your organization\u2019s identity (authentication) providers\u2019 properties on your behalf.", - "userConsentDisplayName": "Read and write identity providers", - "value": "IdentityProvider.ReadWrite.All" + "description": "Allows the application to manage file storage container type registrations without a signed-in user.", + "displayName": "Access selected file storage container type registrations", + "id": "2dcc6599-bd30-442b-8f11-90f88ad441dc", + "origin": "Application (Microsoft Graph)", + "value": "FileStorageContainerTypeReg.Selected" }, { - "description": "Allows the app to read your organization\u2019s identity (authentication) providers\u2019 properties on behalf of the user.", - "displayName": "Read identity providers", - "id": "43781733-b5a7-4d1b-98f4-e8edff23e1a9", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your organization\u2019s identity (authentication) providers\u2019 properties on your behalf.", - "userConsentDisplayName": "Read identity providers", - "value": "IdentityProvider.Read.All" + "description": "Allows the app to create groups without a signed-in user.", + "displayName": "Create groups", + "id": "bf7b1a76-6e77-406b-b258-bf5c7720e98f", + "origin": "Application (Microsoft Graph)", + "value": "Group.Create" }, { - "description": "Allows an app to read bookings appointments, businesses, customers, services, and staff on behalf of the signed-in user.", - "displayName": "Read bookings information", - "id": "33b1df99-4b29-4548-9339-7a7b83eaeebc", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to read bookings appointments, businesses, customers, services, and staff on your behalf.", - "userConsentDisplayName": "Read bookings information", - "value": "Bookings.Read.All" + "description": "Allows the app to list groups, and to read their basic properties and manage the MIP label for all label enabled groups without a signed-in user.", + "displayName": "Manage the Microsoft Information Protection (MIP) label for M365 and security groups.", + "id": "60f8cea0-2476-45c9-ab18-70e79e60ad14", + "origin": "Application (Microsoft Graph)", + "value": "Group.ManageProtection.All" }, { - "description": "Allows an app to read and write bookings appointments and customers, and additionally allows read businesses information, services, and staff on behalf of the signed-in user.", - "displayName": "Read and write booking appointments", - "id": "02a5a114-36a6-46ff-a102-954d89d9ab02", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to read and write bookings appointments and customers, and additionally allows read businesses information, services, and staff on your behalf.", - "userConsentDisplayName": "Read and write booking appointments", - "value": "BookingsAppointment.ReadWrite.All" + "description": "Allows the app to read group properties and memberships, and read conversations for all groups, without a signed-in user.", + "displayName": "Read all groups", + "id": "5b567255-7703-4780-807c-7be8301ae99b", + "origin": "Application (Microsoft Graph)", + "value": "Group.Read.All" }, { - "description": "Allows an app to read and write bookings appointments, businesses, customers, services, and staff on behalf of the signed-in user. Does not allow create, delete and publish of booking businesses.", - "displayName": "Read and write bookings information", - "id": "948eb538-f19d-4ec5-9ccc-f059e1ea4c72", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to read and write Bookings appointments, businesses, customers, services, and staff on your behalf. Does not allow create, delete and publish of booking businesses.", - "userConsentDisplayName": "Read and write bookings information", - "value": "Bookings.ReadWrite.All" + "description": "Allows the app to create groups, read all group properties and memberships, update group properties and memberships, and delete groups. Also allows the app to read and write conversations. All of these operations can be performed by the app without a signed-in user.", + "displayName": "Read and write all groups", + "id": "62a82d76-70ea-41e2-9197-370581804d09", + "origin": "Application (Microsoft Graph)", + "value": "Group.ReadWrite.All" }, { - "description": "Allows an app to read, write and manage bookings appointments, businesses, customers, services, and staff on behalf of the signed-in user.", - "displayName": "Manage bookings information", - "id": "7f36b48e-542f-4d3b-9bcb-8406f0ab9fdb", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to read, write and manage bookings appointments, businesses, customers, services, and staff on your behalf.", - "userConsentDisplayName": "Manage bookings information", - "value": "Bookings.Manage.All" + "description": "Allows the app to read conversations of the groups this app has access to without a signed-in user.", + "displayName": "Read all group conversations", + "id": "4f0a8235-6f6f-4ec7-9500-34b452a4a0c3", + "origin": "Application (Microsoft Graph)", + "value": "Group-Conversation.Read.All" }, { - "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange ActiveSync.", - "displayName": "Access mailboxes via Exchange ActiveSync", - "id": "ff91d191-45a0-43fd-b837-bd682c4a0b0f", - "Origin": "Delegated", - "userConsentDescription": "Allows the app full access to your mailboxes on your behalf.", - "userConsentDisplayName": "Access your mailboxes", - "value": "EAS.AccessAsUser.All" + "description": "Allows the app to read and write conversations of the groups this app has access to without a signed-in user.", + "displayName": "Read and write all group conversations", + "id": "6679c91b-820a-4900-ab47-e97b197a89c4", + "origin": "Application (Microsoft Graph)", + "value": "Group-Conversation.ReadWrite.All" }, { - "description": "Allows the app to read and write financials data on behalf of the signed-in user.", - "displayName": "Read and write financials data", - "id": "f534bf13-55d4-45a9-8f3c-c92fe64d6131", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write financials data on your behalf.", - "userConsentDisplayName": "Read and write financials data", - "value": "Financials.ReadWrite.All" + "description": "Allows the app to read and write outbound data flows without a signed-in user.", + "displayName": "Manage outbound flow definitions", + "id": "24a65b4a-e501-47e2-8849-d679517887f0", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-OutboundFlow.ReadWrite.All" }, { - "description": "Allows the app to read your organization's user flows, on behalf of the signed-in user.", - "displayName": "Read all identity user flows", - "id": "2903d63d-4611-4d43-99ce-a33f3f52e343", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your organization's user flows, on your behalf.", - "userConsentDisplayName": "Read all identity user flows", - "value": "IdentityUserFlow.Read.All" + "description": "Allows the app to read memberships and basic group properties for all groups without a signed-in user.", + "displayName": "Read all group memberships", + "id": "98830695-27a2-44f7-8c18-0c3ebc9698f6", + "origin": "Application (Microsoft Graph)", + "value": "GroupMember.Read.All" }, { - "description": "Allows the app to read or write your organization's user flows, on behalf of the signed-in user.", - "displayName": "Read and write all identity user flows", - "id": "281892cc-4dbf-4e3a-b6cc-b21029bb4e82", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read or write your organization's user flows, on your behalf.", - "userConsentDisplayName": "Read and write all identity user flows", - "value": "IdentityUserFlow.ReadWrite.All" + "description": "Allows the app to read and write groups' disableNesting property without a signed-in user.", + "displayName": "Read and write groups' disableNesting property", + "id": "2d53948b-d2c5-4008-9c4e-6361bf192555", + "origin": "Application (Microsoft Graph)", + "value": "Group-NestingSupport.ReadWrite.All" }, { - "description": "Allows the app to read all organizational contacts on behalf of the signed-in user. \u00a0These contacts are managed by the organization and are different from a user's personal contacts.", - "displayName": "Read organizational contacts", - "id": "08432d1b-5911-483c-86df-7980af5cdee0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all organizational contacts on your behalf.\u00a0 These contacts are managed by the organization and are different from your personal contacts.", - "userConsentDisplayName": "Read organizational contacts", - "value": "OrgContact.Read.All" + "description": "Allows the app to update the on-premises sync behavior of all groups without a signed-in user.", + "displayName": "Read and update the on-premises sync behavior of groups", + "id": "2d9bd318-b883-40be-9df7-63ec4fcdc424", + "origin": "Application (Microsoft Graph)", + "value": "Group-OnPremisesSyncBehavior.ReadWrite.All" }, { - "description": "Allows the app to manage permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", - "displayName": "Manage app permission grants and app role assignments", - "id": "84bccea3-f856-4a8a-967b-dbe0a3d53a64", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to manage permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on your behalf.", - "userConsentDisplayName": "Manage app permission grants and app role assignments", - "value": "AppRoleAssignment.ReadWrite.All" + "description": "Allows the app to read a list of tenant-level or group-specific group settings objects, without a signed-in user.", + "displayName": "Read all group settings", + "id": "f3c4f514-c65a-43f5-bfce-1735872258dd", + "origin": "Application (Microsoft Graph)", + "value": "GroupSettings.Read.All" }, { - "description": "Allows the app to manage permission grants for delegated permissions exposed by any API (including Microsoft Graph), on behalf of the signed in user.", - "displayName": "Manage all delegated permission grants", - "id": "41ce6ca6-6826-4807-84f1-1c82854f7ee5", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to manage permission grants for delegated permissions exposed by any API (including Microsoft Graph), on your behalf. ", - "userConsentDisplayName": "Manage all delegated permission grants", - "value": "DelegatedPermissionGrant.ReadWrite.All" + "description": "Allows the app to create, read, update, and delete on the list of tenant-level or group-specific group settings objects, without a signed-in user.", + "displayName": "Read and write all group settings", + "id": "546168c3-1183-4281-9491-fafb24dea37e", + "origin": "Application (Microsoft Graph)", + "value": "GroupSettings.ReadWrite.All" }, { - "description": "Allows the app to read online meeting details on behalf of the signed-in user.", - "displayName": "Read user's online meetings", - "id": "9be106e1-f4e3-4df5-bdff-e4bc531cbe43", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read online meeting details on your behalf.", - "userConsentDisplayName": "Read your online meetings", - "value": "OnlineMeetings.Read" + "description": "Allows the app to read all Cross-Tenant Identity Synchronization properties on Groups, without a signed-in user.", + "displayName": "Read all Group Cross-Tenant Identity Synchronization properties", + "id": "35b96aac-d839-4362-abd4-7381f2b27ccd", + "origin": "Application (Microsoft Graph)", + "value": "Group-XTenantIdentitySync.Read.All" }, { - "description": "Allows the app to read and create online meetings on behalf of the signed-in user.", - "displayName": "Read and create user's online meetings", - "id": "a65f2972-a4f8-4f5e-afd7-69ccb046d5dc", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and create online meetings on your behalf.", - "userConsentDisplayName": "Read and create your online meetings", - "value": "OnlineMeetings.ReadWrite" + "description": "Allows the app to read all scenario health monitoring alerts, without a signed-in user.", + "displayName": "Read all scenario health monitoring alert", + "id": "5183ed5d-b7f8-4e9a-915e-dafb46b9cb62", + "origin": "Application (Microsoft Graph)", + "value": "HealthMonitoringAlert.Read.All" }, { - "description": "Allows the app to read the signed-in user's teamwork activity feed.", - "displayName": "Read user's teamwork activity feed", - "id": "0e755559-83fb-4b44-91d0-4cc721b9323e", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your teamwork activity feed.", - "userConsentDisplayName": "Read your teamwork activity feed", - "value": "TeamsActivity.Read" + "description": "Allows the app to read and write all scenario monitoring alerts, without a signed-in user.", + "displayName": "Read and write all scenario monitoring alerts", + "id": "ac29eb50-f2f9-4518-a117-4bef18e84c7d", + "origin": "Application (Microsoft Graph)", + "value": "HealthMonitoringAlert.ReadWrite.All" }, { - "description": "Allows the app to request and manage time-based assignment and just-in-time elevation of user privileges to manage Azure resources (like subscriptions, resource groups, storage, compute) on behalf of the signed-in users.", - "displayName": "Read and write privileged access to Azure resources", - "id": "a84a9652-ffd3-496e-a991-22ba5529156a", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to request and manage time-based assignment and just-in-time elevation of user privileges to manage \u00a0your Azure resources (like your subscriptions, resource groups, storage, compute) on your behalf.", - "userConsentDisplayName": "Read and write privileged access to Azure resources", - "value": "PrivilegedAccess.ReadWrite.AzureResources" + "description": "Allows the app to read all scenario health monitoring alert configurations, without a signed-in user.", + "displayName": "Read all scenario health monitoring alert configurations", + "id": "bb424d73-e898-4c97-9d42-688c32810003", + "origin": "Application (Microsoft Graph)", + "value": "HealthMonitoringAlertConfig.Read.All" }, { - "description": "Allows the app to read time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD built-in and custom administrative roles, on behalf of the signed-in user.", - "displayName": "Read privileged access to Azure AD", - "id": "b3a539c9-59cb-4ad5-825a-041ddbdc2bdb", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD built-in and custom administrative roles, on your behalf.", - "userConsentDisplayName": "Read privileged access to Azure AD", - "value": "PrivilegedAccess.Read.AzureAD" + "description": "Allows the app to list groups, read basic properties, read and update the membership of the groups this app has access to without a signed-in user. Group properties and owners cannot be updated and groups cannot be deleted.", + "displayName": "Read and write all group memberships", + "id": "dbaae8cf-10b5-4b86-a4a1-f871c94c6695", + "origin": "Application (Microsoft Graph)", + "value": "GroupMember.ReadWrite.All" }, { - "description": "Allows the app to read time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups, on behalf of the signed-in user.", - "displayName": "Read privileged access to Azure AD groups", - "id": "d329c81c-20ad-4772-abf9-3f6fdb7e5988", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups, on your behalf.", - "userConsentDisplayName": "Read privileged access to Azure AD groups", - "value": "PrivilegedAccess.Read.AzureADGroup" + "description": "Allows the app to read all the short notes without a signed-in user.", + "displayName": "Read all users' short notes", + "id": "0c7d31ec-31ca-4f58-b6ec-9950b6b0de69", + "origin": "Application (Microsoft Graph)", + "value": "ShortNotes.Read.All" }, { - "description": "Allows the app to read time-based assignment and just-in-time elevation of Azure resources (like your subscriptions, resource groups, storage, compute) on behalf of the signed-in user.", - "displayName": "Read privileged access to Azure resources", - "id": "1d89d70c-dcac-4248-b214-903c457af83a", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read time-based assignment and just-in-time elevation of Azure resources (like your subscriptions, resource groups, storage, compute) on your behalf.", - "userConsentDisplayName": "Read privileged access to your Azure resources", - "value": "PrivilegedAccess.Read.AzureResources" + "description": "Allows the app to read and write organization-wide Dynamics customer voice settings, without a signed-in user.", + "displayName": "Read and write organization-wide Dynamics customer voice settings", + "id": "c3f1cc32-8bbd-4ab6-bd33-f270e0d9e041", + "origin": "Application (Microsoft Graph)", + "value": "OrgSettings-DynamicsVoice.ReadWrite.All" }, { - "description": "Allows the app to request and manage time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups, on behalf of the signed-in user.", - "displayName": "Read and write privileged access to Azure AD groups", - "id": "32531c59-1f32-461f-b8df-6f8a3b89f73b", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to request and manage time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups, on your behalf.", - "userConsentDisplayName": "Read and write privileged access to Azure AD groups", - "value": "PrivilegedAccess.ReadWrite.AzureADGroup" + "description": "Allows the app to read and write organization-wide Microsoft Forms settings, without a signed-in user.", + "displayName": "Read and write organization-wide Microsoft Forms settings", + "id": "2cb92fee-97a3-4034-8702-24a6f5d0d1e9", + "origin": "Application (Microsoft Graph)", + "value": "OrgSettings-Forms.ReadWrite.All" }, { - "description": "Allows the app to read all the indicators for your organization, on behalf of the signed-in user.", - "displayName": "Read all threat indicators", - "id": "9cc427b4-2004-41c5-aa22-757b755e9796", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all the indicators for your organization, on your behalf.", - "userConsentDisplayName": "Read all threat indicators", - "value": "ThreatIndicators.Read.All" + "description": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, without a signed-in user.", + "displayName": "Read M365 Defender RBAC configuration", + "id": "4d6e30d1-e64e-4ae7-bf9d-c706cc928cef", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagement.Read.Defender" }, { - "description": "Allow the app to read external datasets and content, on behalf of the signed-in user.", - "displayName": "Read items in external datasets", - "id": "922f9392-b1b7-483c-a4be-0089be7704fb", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read external datasets and content that you have access to.", - "userConsentDisplayName": "Read items in external datasets", - "value": "ExternalItem.Read.All" + "description": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, without a signed-in user. This includes reading directory role templates, directory roles and memberships.", + "displayName": "Read all directory RBAC settings", + "id": "483bed4a-2ad3-4361-a73b-c83ccdbdc53c", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagement.Read.Directory" }, { - "description": "Allows an app to edit channel messages in Microsoft Teams, on behalf of the signed-in user.", - "displayName": "Edit user's channel messages", - "id": "2b61aa8a-6d36-4b2f-ac7b-f29867937c53", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to edit channel messages in Microsoft Teams, on your behalf.", - "userConsentDisplayName": "Edit your channel messages", - "value": "ChannelMessage.Edit" + "description": "Allows the app to read the role-based access control (RBAC) configuration for your organization's Exchange Online service, without a signed-in user. This includes reading Exchange management role definitions, role groups, role group membership, role assignments, management scopes, and role assignment policies.", + "displayName": "Read Exchange Online RBAC configuration", + "id": "c769435f-f061-4d0b-8ff1-3d39870e5f85", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagement.Read.Exchange" }, { - "description": "Allows an app to send channel messages in Microsoft Teams, on behalf of the signed-in user.", - "displayName": "Send channel messages", - "id": "ebf0f66e-9fb1-49e4-a278-222f76911cf4", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to send channel messages in Microsoft Teams, on your behalf.", - "userConsentDisplayName": "Send channel messages", - "value": "ChannelMessage.Send" + "description": "Allows the app to read and manage the Cloud PC role-based access control (RBAC) settings, without a signed-in user. This includes reading and managing Cloud PC role definitions and memberships.", + "displayName": "Read and write all Cloud PC RBAC settings", + "id": "274d0592-d1b6-44bd-af1d-26d259bcb43a", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagement.ReadWrite.CloudPC" }, { - "description": "Allows the app to manage organization places (conference rooms and room lists) for calendar events and other applications, on behalf of the signed-in user.", - "displayName": "Read and write organization places", - "id": "4c06a06a-098a-4063-868e-5dfee3827264", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to manage organization places (conference rooms and room lists) for calendar events and other applications, on your behalf.", - "userConsentDisplayName": "Read and write organization places", - "value": "Place.ReadWrite.All" + "description": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, without a signed-in user.", + "displayName": "Read M365 Defender RBAC configuration", + "id": "8b7e8c0a-7e9d-4049-97ec-04b5e1bcaf05", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagement.ReadWrite.Defender" }, { - "description": "Allows the app to request access to and management of access packages and related entitlement management resources on behalf of the signed-in user.", - "displayName": "Read and write entitlement management resources", - "id": "ae7a573d-81d7-432b-ad44-4ed5c9d89038", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to request access to and management of access packages and related entitlement management resources that you have access to.", - "userConsentDisplayName": "Read and write entitlement management resources", - "value": "EntitlementManagement.ReadWrite.All" + "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your company's directory, without a signed-in user. This includes instantiating directory roles and managing directory role membership, and reading directory role templates, directory roles and memberships.", + "displayName": "Read and write all directory RBAC settings", + "id": "9e3f62cf-ca93-4989-b6ce-bf83c28f9fe8", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagement.ReadWrite.Directory" }, { - "description": "Allows the app to send, read, update and delete user\u2019s notifications.", - "displayName": "Deliver and manage user's notifications", - "id": "26e2f3e8-b2a1-47fc-9620-89bb5b042024", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to send, read, update and delete your app-specific notifications.", - "userConsentDisplayName": "Deliver and manage your notifications", - "value": "UserNotification.ReadWrite.CreatedByApp" + "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your organization's Exchange Online service, without a signed-in user. This includes reading, creating, updating, and deleting Exchange management role definitions, role groups, role group membership, role assignments, management scopes, and role assignment policies.", + "displayName": "Read and write Exchange Online RBAC configuration", + "id": "025d3225-3f02-4882-b4c0-cd5b541a4e80", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagement.ReadWrite.Exchange" }, { - "description": "Allows the app to read applications and service principals on behalf of the signed-in user.", - "displayName": "Read applications", - "id": "c79f8feb-a9db-4090-85f9-90d820caa0eb", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read applications and service principals on your behalf.", - "userConsentDisplayName": "Read applications", - "value": "Application.Read.All" + "description": "Allows the app to read all role-based access control (RBAC) alerts for your company's directory, without a signed-in user. This includes reading alert statuses, alert definitions, alert configurations and incidents that lead to an alert.", + "displayName": "Read all alert data for your company's directory", + "id": "ef31918f-2d50-4755-8943-b8638c0a077e", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagementAlert.Read.Directory" }, { - "description": "Allows the app to create, read, update and delete applications and service principals on behalf of the signed-in user. Does not allow management of consent grants.", - "displayName": "Read and write all applications", - "id": "bdfbf15f-ee85-4955-8675-146e8e5296b5", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to create, read, update and delete applications and service principals on your behalf. Does not allow management of consent grants.", - "userConsentDisplayName": "Read and write applications", - "value": "Application.ReadWrite.All" + "description": "Allows the app to read and manage all role-based access control (RBAC) alerts for your company's directory, without a signed-in user. This includes managing alert settings, initiating alert scans, dismissing alerts, remediating alert incidents, and reading alert statuses, alert definitions, alert configurations and incidents that lead to an alert.", + "displayName": "Read all alert data, configure alerts, and take actions on all alerts for your company's directory", + "id": "11059518-d6a6-4851-98ed-509268489c4a", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagementAlert.ReadWrite.Directory" }, { - "description": "Allows the app to read BitLocker keys on behalf of the signed-in user, for their owned devices. Allows read of the recovery key.", - "displayName": "Read BitLocker keys", - "id": "b27a61ec-b99c-4d6a-b126-c4375d08ae30", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read BitLocker keys for your owned devices. Allows read of the recovery key.", - "userConsentDisplayName": "Read your BitLocker keys", - "value": "BitlockerKey.Read.All" + "description": "Allows the app to read policies in Privileged Identity Management for Groups, without a signed-in user.", + "displayName": "Read all policies in PIM for Groups", + "id": "69e67828-780e-47fd-b28c-7b27d14864e6", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagementPolicy.Read.AzureADGroup" }, { - "description": "Allows the app to read basic BitLocker key properties on behalf of the signed-in user, for their owned devices. Does not allow read of the recovery key itself.", - "displayName": "Read BitLocker keys basic information", - "id": "5a107bfc-4f00-4e1a-b67e-66451267bc68", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read basic BitLocker key properties for your owned devices. Does not allow read of the recovery key itself.", - "userConsentDisplayName": "Read your BitLocker keys basic information", - "value": "BitlockerKey.ReadBasic.All" + "description": "Allows the app to read policies for privileged role-based access control (RBAC) assignments of your company's directory, without a signed-in user.", + "displayName": "Read all policies for privileged role assignments of your company's directory", + "id": "fdc4c997-9942-4479-bfcb-75a36d1138df", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagementPolicy.Read.Directory" }, { - "description": "Allows the app to list groups, read basic group properties and read membership of all groups the signed-in user has access to.", - "displayName": "Read group memberships", - "id": "bc024368-1153-4739-b217-4326f2e966d0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to list groups, read basic group properties and read membership of all your groups.", - "userConsentDisplayName": "Read group memberships", - "value": "GroupMember.Read.All" + "description": "Allows the app to read policies in Privileged Identity Management for App Roles, without a signed-in user.", + "displayName": "Read all policies in PIM for App Roles", + "id": "3d201a4e-90f1-420d-bd4f-3beec28a46b9", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagementPolicy.Read.EntraAppRole" }, { - "description": "Allows the app to list groups, read basic properties, read and update the membership of the groups the signed-in user has access to. Group properties and owners cannot be updated and groups cannot be deleted.", - "displayName": "Read and write group memberships", - "id": "f81125ac-d3b7-4573-a3b2-7099cc39df9e", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to list groups, read basic properties, read and update the membership of your groups. Group properties and owners cannot be updated and groups cannot be deleted.", - "userConsentDisplayName": "Read and write group memberships", - "value": "GroupMember.ReadWrite.All" + "description": "Allows the app to read, update, and delete policies in Privileged Identity Management for Groups, without a signed-in user.", + "displayName": "Read, update, and delete all policies in PIM for Groups", + "id": "b38dcc4d-a239-4ed6-aa84-6c65b284f97c", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagementPolicy.ReadWrite.AzureADGroup" }, { - "description": "Allows an app to read your organization's threat assessment requests on behalf of the signed-in user. Also allows the app to create new requests to assess threats received by your organization on behalf of the signed-in user.", - "displayName": "Read and write threat assessment requests", - "id": "cac97e40-6730-457d-ad8d-4852fddab7ad", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to read your organization's threat assessment requests on your behalf. Also allows the app to create new requests to assess threats received by your organization on your behalf.", - "userConsentDisplayName": "Read and write threat assessment requests", - "value": "ThreatAssessment.ReadWrite.All" + "description": "Allows the app to read, update, and delete policies for privileged role-based access control (RBAC) assignments of your company's directory, without a signed-in user.", + "displayName": "Read, update, and delete all policies for privileged role assignments of your company's directory", + "id": "31e08e0a-d3f7-4ca2-ac39-7343fb83e8ad", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagementPolicy.ReadWrite.Directory" }, { - "description": "Allows the app to read schedule, schedule groups, shifts and associated entities in the Teams or Shifts application on behalf of the signed-in user.", - "displayName": "Read user schedule items", - "id": "fccf6dd8-5706-49fa-811f-69e2e1b585d0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read schedule, schedule groups, shifts and associated entities in the Teams or Shifts application on your behalf.", - "userConsentDisplayName": "Read your schedule items", - "value": "Schedule.Read.All" + "description": "Allows the app to manage policies in Privileged Identity Management for App Roles, without a signed-in user.", + "displayName": "Manage all policies in PIM for App Roles", + "id": "ec563bdb-80dc-47c0-81d3-bff47cc6ac06", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagementPolicy.ReadWrite.EntraAppRole" }, { - "description": "Allows the app to manage schedule, schedule groups, shifts and associated entities in the Teams or Shifts application on behalf of the signed-in user.", - "displayName": "Read and write user schedule items", - "id": "63f27281-c9d9-4f29-94dd-6942f7f1feb0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to manage schedule, schedule groups, shifts and associated entities in the Teams or Shifts application on your behalf.", - "userConsentDisplayName": "Read and write your schedule items", - "value": "Schedule.ReadWrite.All" + "description": "Allows the app to read all schedules, schedule groups, shifts and associated entities in the Teams or Shifts application without a signed-in user.", + "displayName": "Read all schedule items", + "id": "7b2ebf90-d836-437f-b90d-7b62722c4456", + "origin": "Application (Microsoft Graph)", + "value": "Schedule.Read.All" }, { - "description": " Allows the app to read and write authentication methods of all users in your organization that the signed-in user has access to. Authentication methods include things like a user\u2019s phone numbers and Authenticator app settings. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' authentication methods.", - "id": "b7887744-6746-4312-813d-72daeaee7e2d", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write authentication methods of all users you have access to in your organization. Authentication methods include things like a user\u2019s phone numbers and Authenticator app settings. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "userConsentDisplayName": "Read and write all users' authentication methods", - "value": "UserAuthenticationMethod.ReadWrite.All" + "description": "Allows the app to manage all schedules, schedule groups, shifts and associated entities in the Teams or Shifts application without a signed-in user.", + "displayName": "Read and write all schedule items", + "id": "b7760610-0545-4e8a-9ec3-cce9e63db01c", + "origin": "Application (Microsoft Graph)", + "value": "Schedule.ReadWrite.All" }, { - "description": "Allows the app to read and write the signed-in user's authentication methods, including phone numbers and Authenticator app settings. This does not allow the app to see secret information like the signed-in user's passwords, or to sign-in or otherwise use the signed-in user's authentication methods. ", - "displayName": "Read and write user authentication methods", - "id": "48971fc1-70d7-4245-af77-0beb29b53ee2", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write your authentication methods, including phone numbers and Authenticator app settings.This does not allow the app to see secret information like your passwords, or to sign-in or otherwise use your authentication methods.", - "userConsentDisplayName": "Read and write your authentication methods", - "value": "UserAuthenticationMethod.ReadWrite" + "description": "Allows the app to read the Cloud PC role-based access control (RBAC) settings, without a signed-in user.", + "displayName": "Read Cloud PC RBAC settings", + "id": "031a549a-bb80-49b6-8032-2068448c6a3c", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagement.Read.CloudPC" }, { - "description": "Allows the app to read authentication methods of all users in your organization that the signed-in user has access to. Authentication methods include things like a user\u2019s phone numbers and Authenticator app settings. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' authentication methods", - "id": "aec28ec7-4d02-4e8c-b864-50163aea77eb", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read authentication methods of all users you have access to in your organization. Authentication methods include things like a user\u2019s phone numbers and Authenticator app settings. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "userConsentDisplayName": "Read all users' authentication methods", - "value": "UserAuthenticationMethod.Read.All" + "description": "Allows the app to read/write schedule permissions for a specific role in Shifts application without a signed-in user.", + "displayName": "Read/Write schedule permissions for a role", + "id": "7239b71d-b402-4150-b13d-78ecfe8df441", + "origin": "Application (Microsoft Graph)", + "value": "SchedulePermissions.ReadWrite.All" }, { - "description": "Allows the app to read the signed-in user's authentication methods, including phone numbers and Authenticator app settings. This does not allow the app to see secret information like the signed-in user's passwords, or to sign-in or otherwise use the signed-in user's authentication methods.", - "displayName": "Read user authentication methods.", - "id": "1f6b61c5-2f65-4135-9c9f-31c0f8d32b52", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your authentication methods, including phone numbers and Authenticator app settings. This does not allow the app to see secret information like your passwords, or to sign-in or otherwise use your authentication methods.", - "userConsentDisplayName": "Read your authentication methods.", - "value": "UserAuthenticationMethod.Read" + "description": "Allows the app to read role-based access control (RBAC) settings for all RBAC providers without a signed-in user. This includes reading role definitions and role assignments.", + "displayName": "Read role management data for all RBAC providers", + "id": "c7fbd983-d9aa-4fa7-84b8-17382c103bc4", + "origin": "Application (Microsoft Graph)", + "value": "RoleManagement.Read.All" }, { - "description": "Allows the app to create tabs in any team in Microsoft Teams, on behalf of the signed-in user. This does not grant the ability to read, modify or delete tabs after they are created, or give access to the content inside the tabs.", - "displayName": "Create tabs in Microsoft Teams.", - "id": "a9ff19c2-f369-4a95-9a25-ba9d460efc8e", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to create tabs in any team in Microsoft Teams, on your behalf. This does not grant the ability to read, modify or delete tabs after they are created, or give access to the content inside the tabs.", - "userConsentDisplayName": "Create tabs in Microsoft Teams.", - "value": "TeamsTab.Create" + "description": "Allows the app to read and manage the eligible role-based access control (RBAC) assignments and schedules for your company's directory, without a signed-in user. This includes managing eligible directory role membership, and reading directory role templates, directory roles and eligible memberships.", + "displayName": "Read, update, and delete all eligible role assignments and schedules for your company's directory", + "id": "fee28b28-e1f3-4841-818e-2704dc62245f", + "origin": "Application (Microsoft Graph)", + "value": "RoleEligibilitySchedule.ReadWrite.Directory" }, { - "description": "Read the names and settings of tabs inside any team in Microsoft Teams, on behalf of the signed-in user. This does not give access to the content inside the tabs.", - "displayName": "Read tabs in Microsoft Teams.", - "id": "59dacb05-e88d-4c13-a684-59f1afc8cc98", - "Origin": "Delegated", - "userConsentDescription": "Read the names and settings of tabs inside any team in Microsoft Teams, on your behalf. This does not give access to the content inside the tabs.", - "userConsentDisplayName": "Read tabs in Microsoft Teams.", - "value": "TeamsTab.Read.All" + "description": "Allows an app to read all question and answers, without a signed-in user.", + "displayName": "Read all Question and Answers ", + "id": "ee49e170-1dd1-4030-b44c-61ad6e98f743", + "origin": "Application (Microsoft Graph)", + "value": "QnA.Read.All" }, { - "description": "Read and write tabs in any team in Microsoft Teams, on behalf of the signed-in user. This does not give access to the content inside the tabs.", - "displayName": "Read and write tabs in Microsoft Teams.", - "id": "b98bfd41-87c6-45cc-b104-e2de4f0dafb9", - "Origin": "Delegated", - "userConsentDescription": "Read and write tabs in any team in Microsoft Teams, on your behalf. This does not give access to the content inside the tabs.", - "userConsentDisplayName": "Read and write tabs in Microsoft Teams.", - "value": "TeamsTab.ReadWrite.All" + "description": "Allows the app to get direct access to real-time enriched data in a meeting, without a signed-in user.", + "displayName": "Access real-time enriched data in a meeting as an app", + "id": "abafe00f-ea87-4c63-b8a8-0e7bb0a88144", + "origin": "Application (Microsoft Graph)", + "value": "RealTimeActivityFeed.Read.All" }, { - "description": "Allows the app to have the same access to mailboxes as the signed-in user via IMAP protocol.", - "displayName": "Read and write access to mailboxes via IMAP.", - "id": "652390e4-393a-48de-9484-05f9b1212954", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update, create and delete email in your mailbox. Does not include permission to send mail.", - "userConsentDisplayName": "Read and write access to your mail.", - "value": "IMAP.AccessAsUser.All" + "description": "Allows the application to read any data from Records Management, such as configuration, labels, and policies without the signed in user.", + "displayName": "Read Records Management configuration, labels and policies", + "id": "ac3a2b8e-03a3-4da9-9ce0-cbe28bf1accd", + "origin": "Application (Microsoft Graph)", + "value": "RecordsManagement.Read.All" }, { - "description": "Allows the app to have the same access to mailboxes as the signed-in user via POP protocol.", - "displayName": "Read and write access to mailboxes via POP.", - "id": "d7b7f2d9-0f45-4ea1-9d42-e50810c06991", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update, create and delete email in your mailbox. Does not include permission to send mail.", - "userConsentDisplayName": "Read and write access to your mail.", - "value": "POP.AccessAsUser.All" + "description": "Allow the application to create, update and delete any data from Records Management, such as configuration, labels, and policies without the signed in user.", + "displayName": "Read and write Records Management configuration, labels and policies", + "id": "eb158f57-df43-4751-8b21-b8932adb3d34", + "origin": "Application (Microsoft Graph)", + "value": "RecordsManagement.ReadWrite.All" }, { - "description": "Allows the app to be able to send emails from the user\u2019s mailbox using the SMTP AUTH client submission protocol.", - "displayName": "Send emails from mailboxes using SMTP AUTH.", - "id": "258f6531-6087-4cc4-bb90-092c5fb3ed3f", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to send emails on your behalf from your mailbox.", - "userConsentDisplayName": "Access to sending emails from your mailbox.", - "value": "SMTP.Send" + "description": "Allows the app to read available properties on remoteTenantGroups, without a signed-in user.", + "displayName": "Read RemoteTenantGroups information", + "id": "faa08cc0-0dcd-4ea9-9f9c-8b16f842b36e", + "origin": "Application (Microsoft Graph)", + "value": "RemoteTenantGroups.Read.All" }, { - "description": "Allows the app to read all domain properties on behalf of the signed-in user.", - "displayName": "Read domains.", - "id": "2f9ee017-59c1-4f1d-9472-bd5529a7b311", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all domain properties on your behalf.", - "userConsentDisplayName": "Read domains.", - "value": "Domain.Read.All" + "description": "Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Office 365 and Azure Active Directory.", + "displayName": "Read all usage reports", + "id": "230c1aed-a721-4c5d-9cb4-a90514e508ef", + "origin": "Application (Microsoft Graph)", + "value": "Reports.Read.All" }, { - "description": "Allows the app to read and write all domain properties on behalf of the signed-in user. Also allows the app to add, verify and remove domains.", - "displayName": "Read and write domains", - "id": "0b5d694c-a244-4bde-86e6-eb5cd07730fe", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write all domain properties on your behalf. Also allows the app to add, verify and remove domains.", - "userConsentDisplayName": "Read and write domains", - "value": "Domain.ReadWrite.All" + "description": "Allows the app to read all admin report settings, such as whether to display concealed information in reports, without a signed-in user.", + "displayName": "Read all admin report settings", + "id": "ee353f83-55ef-4b78-82da-555bfa2b4b95", + "origin": "Application (Microsoft Graph)", + "value": "ReportSettings.Read.All" }, { - "description": "Allows the app to read and write your organization's application configuration policies on behalf of the signed-in user. This includes policies such as activityBasedTimeoutPolicy, claimsMappingPolicy, homeRealmDiscoveryPolicy, tokenIssuancePolicy and tokenLifetimePolicy.", - "displayName": "Read and write your organization's application configuration policies", - "id": "b27add92-efb2-4f16-84f5-8108ba77985c", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write your organization's application configuration policies on your behalf. This includes policies such as activityBasedTimeoutPolicy, claimsMappingPolicy, homeRealmDiscoveryPolicy, tokenIssuancePolicy and tokenLifetimePolicy.", - "userConsentDisplayName": "Read and write your organization's application configuration policies", - "value": "Policy.ReadWrite.ApplicationConfiguration" + "description": "Allows the app to read and update all admin report settings, such as whether to display concealed information in reports, without a signed-in user.", + "displayName": "Read and write all admin report settings", + "id": "2a60023f-3219-47ad-baa4-40e17cd02a1d", + "origin": "Application (Microsoft Graph)", + "value": "ReportSettings.ReadWrite.All" }, { - "description": "Allows the app to read your organization's devices' configuration information on behalf of the signed-in user.", - "displayName": "Read all devices", - "id": "951183d1-1a61-466f-a6d1-1fde911bfd95", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read devices' configuration information on your behalf.", - "userConsentDisplayName": "Read all devices", - "value": "Device.Read.All" + "description": "Allows the app to read the resource specific permissions granted on the chat without a signed-in user.", + "displayName": "Read resource specific permissions granted on a chat", + "id": "2ff643d8-43e4-4a9b-88c1-86cb4a4b4c2f", + "origin": "Application (Microsoft Graph)", + "value": "ResourceSpecificPermissionGrant.ReadForChat.All" }, { - "description": "Allows the app to read, update and delete identities that are associated with a user's account that the signed-in user has access to. This controls the identities users can sign-in with.", - "displayName": "Manage user identities", - "id": "637d7bec-b31e-4deb-acc9-24275642a2c9", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, update and delete identities that are associated with a user's account that you have access to. This controls the identities users can sign-in with.", - "userConsentDisplayName": "Manage user identities", - "value": "User.ManageIdentities.All" + "description": "Allows the app to read the resource specific permissions granted on the team without a signed-in user.", + "displayName": "Read resource specific permissions granted on a team", + "id": "ad4600ae-d900-42cb-a9a2-2415d05593d0", + "origin": "Application (Microsoft Graph)", + "value": "ResourceSpecificPermissionGrant.ReadForTeam.All" }, { - "description": "Allows the app to read access packages and related entitlement management resources on behalf of the signed-in user.", - "displayName": "Read all entitlement management resources", - "id": "5449aa12-1393-4ea2-a7c7-d0e06c1a56b2", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read access packages and related entitlement management resources that you have access to.", - "userConsentDisplayName": "Read all entitlement management resources", - "value": "EntitlementManagement.Read.All" + "description": "Allows the app to read all resource specific permissions granted on user accounts, without a signed-in user.", + "displayName": "Read all resource specific permissions granted on user accounts", + "id": "acfca4d5-f49f-40ed-9648-84068b474c73", + "origin": "Application (Microsoft Graph)", + "value": "ResourceSpecificPermissionGrant.ReadForUser.All" }, { - "description": "Create channels in any team, on behalf of the signed-in user.", - "displayName": "Create channels", - "id": "101147cf-4178-4455-9d58-02b5c164e759", - "Origin": "Delegated", - "userConsentDescription": "Create channels in any team, on your behalf.", - "userConsentDisplayName": "Create channels", - "value": "Channel.Create" + "description": "Allows the app to read your organization's risk prevention providers, without a signed-in user.", + "displayName": "Read all identity risk prevention providers", + "id": "2a6baefd-edea-4ff6-b24e-bebcaa27a50d", + "origin": "Application (Microsoft Graph)", + "value": "RiskPreventionProviders.Read.All" }, { - "description": "Delete channels in any team, on behalf of the signed-in user.", - "displayName": "Delete channels", - "id": "cc83893a-e232-4723-b5af-bd0b01bcfe65", - "Origin": "Delegated", - "userConsentDescription": "Delete channels in any team, on your behalf.", - "userConsentDisplayName": "Delete channels", - "value": "Channel.Delete.All" + "description": "Allows the app to read and write your organization's risk prevention providers, without a signed-in user.", + "displayName": "Read and write all identity risk prevention providers", + "id": "7fc7225d-eb37-4c39-90f3-a33a57cf1081", + "origin": "Application (Microsoft Graph)", + "value": "RiskPreventionProviders.ReadWrite.All" }, { - "description": "Read all channel names, channel descriptions, and channel settings, on behalf of the signed-in user.", - "displayName": "Read the names, descriptions, and settings of channels", - "id": "233e0cf1-dd62-48bc-b65b-b38fe87fcf8e", - "Origin": "Delegated", - "userConsentDescription": "Read all channel names, channel descriptions, and channel settings, on your behalf.", - "userConsentDisplayName": "Read the names, descriptions, and settings of channels", - "value": "ChannelSettings.Read.All" + "description": "Allows the app to read the active role-based access control (RBAC) assignments and schedules for your company's directory, without a signed-in user. This includes reading directory role templates, and directory roles.", + "displayName": "Read all active role assignments and role schedules for your company's directory", + "id": "d5fe8ce8-684c-4c83-a52c-46e882ce4be1", + "origin": "Application (Microsoft Graph)", + "value": "RoleAssignmentSchedule.Read.Directory" }, { - "description": "Read and write the names, descriptions, and settings of all channels, on behalf of the signed-in user.", - "displayName": "Read and write the names, descriptions, and settings of channels", - "id": "d649fb7c-72b4-4eec-b2b4-b15acf79e378", - "Origin": "Delegated", - "userConsentDescription": "Read and write the names, descriptions, and settings of all channels, on your behalf.", - "userConsentDisplayName": "Read and write the names, descriptions, and settings of channels", - "value": "ChannelSettings.ReadWrite.All" + "description": "Allows the app to read, update, and delete policies for privileged role-based access control (RBAC) assignments of your company's directory, without a signed-in user.", + "displayName": "Read, update, and delete all policies for privileged role assignments of your company's directory", + "id": "dd199f4a-f148-40a4-a2ec-f0069cc799ec", + "origin": "Application (Microsoft Graph)", + "value": "RoleAssignmentSchedule.ReadWrite.Directory" }, { - "description": "Allows the app to read all webhook subscriptions on behalf of the signed-in user.", - "displayName": "Read all webhook subscriptions ", - "id": "5f88184c-80bb-4d52-9ff2-757288b2e9b7", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all webhook subscriptions on your behalf.", - "userConsentDisplayName": "Read all webhook subscriptions ", - "value": "Subscription.Read.All" + "description": "Delete all active privileged role-based access control (RBAC) assignments of your company's directory, without a signed-in user.", + "displayName": "Delete all active role assignments of your company's directory", + "id": "d3495511-98b7-4df3-b317-4e35c19f6129", + "origin": "Application (Microsoft Graph)", + "value": "RoleAssignmentSchedule.Remove.Directory" }, { - "description": "Read the names and descriptions of teams, on behalf of the signed-in user.", - "displayName": "Read the names and descriptions of teams", - "id": "485be79e-c497-4b35-9400-0e3fa7f2a5d4", - "Origin": "Delegated", - "userConsentDescription": "Read the names and descriptions of teams, on your behalf.", - "userConsentDisplayName": "Read the names and descriptions of teams", - "value": "Team.ReadBasic.All" + "description": "Allows the app to read the eligible role-based access control (RBAC) assignments and schedules for your company's directory, without a signed-in user. This includes reading directory role templates, and directory roles.", + "displayName": "Read all eligible role assignments and role schedules for your company's directory", + "id": "ff278e11-4a33-4d0c-83d2-d01dc58929a5", + "origin": "Application (Microsoft Graph)", + "value": "RoleEligibilitySchedule.Read.Directory" }, { - "description": "Read channel names and channel descriptions, on behalf of the signed-in user.", - "displayName": "Read the names and descriptions of channels", - "id": "9d8982ae-4365-4f57-95e9-d6032a4c0b87", - "Origin": "Delegated", - "userConsentDescription": "Read channel names and channel descriptions, on your behalf.", - "userConsentDisplayName": "Read the names and descriptions of channels", - "value": "Channel.ReadBasic.All" + "description": "Delete all eligible privileged role-based access control (RBAC) assignments of your company's directory, without a signed-in user.", + "displayName": "Delete all eligible role assignments of your company's directory", + "id": "79c7e69c-0d9f-4eff-97a8-49170a5a08ba", + "origin": "Application (Microsoft Graph)", + "value": "RoleEligibilitySchedule.Remove.Directory" }, { - "description": "Read all teams' settings, on behalf of the signed-in user.", - "displayName": "Read teams' settings", - "id": "48638b3c-ad68-4383-8ac4-e6880ee6ca57", - "Origin": "Delegated", - "userConsentDescription": "Read all teams' settings, on your behalf.", - "userConsentDisplayName": "Read teams' settings", - "value": "TeamSettings.Read.All" + "description": "Allows the app to trigger the working time policies and read the working time status for other users in your organization, without a signed-in user.", + "displayName": "Trigger working time policies and read the working time status", + "id": "0b21c159-dbf4-4dbb-a6f6-490e412c716e", + "origin": "Application (Microsoft Graph)", + "value": "Schedule-WorkingTime.ReadWrite.All" }, { - "description": "Read and change all teams' settings, on behalf of the signed-in user.", - "displayName": "Read and change teams' settings", - "id": "39d65650-9d3e-4223-80db-a335590d027e", - "Origin": "Delegated", - "userConsentDescription": "Read and change all teams' settings, on your behalf.", - "userConsentDisplayName": "Read and change teams' settings", - "value": "TeamSettings.ReadWrite.All" + "description": "Allows the app to read search configurations, without a signed-in user.", + "displayName": "Read your organization's search configuration", + "id": "ada977a5-b8b1-493b-9a91-66c206d76ecf", + "origin": "Application (Microsoft Graph)", + "value": "SearchConfiguration.Read.All" }, { - "description": "Read the members of teams, on behalf of the signed-in user.", - "displayName": "Read the members of teams", - "id": "2497278c-d82d-46a2-b1ce-39d4cdde5570", - "Origin": "Delegated", - "userConsentDescription": "Read the members of teams, on your behalf.", - "userConsentDisplayName": "Read the members of teams", - "value": "TeamMember.Read.All" + "description": "Allows the app to read and write search configurations, without a signed-in user.", + "displayName": "Read and write your organization's search configuration", + "id": "0e778b85-fefa-466d-9eec-750569d92122", + "origin": "Application (Microsoft Graph)", + "value": "SearchConfiguration.ReadWrite.All" }, { - "description": "Add and remove members from teams, on behalf of the signed-in user. Also allows changing a member's role, for example from owner to non-owner.", - "displayName": "Add and remove members from teams", - "id": "4a06efd2-f825-4e34-813e-82a57b03d1ee", - "Origin": "Delegated", - "userConsentDescription": "Add and remove members from teams, on your behalf. Also allows changing a member's role, for example from owner to non-owner.", - "userConsentDisplayName": "Add and remove members from teams and channels", - "value": "TeamMember.ReadWrite.All" + "description": "Allows the app to read and write to all security incidents, without a signed-in user.", + "displayName": "Read and write to all security incidents", + "id": "34bf0e97-1971-4929-b999-9e2442d941d7", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIncident.ReadWrite.All" }, { - "description": "Allows the app to read consent requests and approvals on behalf of the signed-in user.", - "displayName": "Read consent requests", - "id": "f3bfad56-966e-4590-a536-82ecf548ac1e", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read consent requests and approvals, on your behalf.", - "userConsentDisplayName": "Read consent requests", - "value": "ConsentRequest.Read.All" + "description": "Allow the app to determine if there is any sensitivity label to be applied automatically to the content or recommended to the user for manual application, without a signed-in user.", + "displayName": "Evaluate sensitivity labels", + "id": "57f0b71b-a759-45a0-9a0f-cc099fbd9a44", + "origin": "Application (Microsoft Graph)", + "value": "SensitivityLabel.Evaluate" }, { - "description": "Allows the app to read app consent requests and approvals, and deny or approve those requests on behalf of the signed-in user.", - "displayName": "Read and write consent requests", - "id": "497d9dfa-3bd1-481a-baab-90895e54568c", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read app consent requests for your approval, and deny or approve those request on your behalf.", - "userConsentDisplayName": "Read and write consent requests", - "value": "ConsentRequest.ReadWrite.All" + "description": "Allows the app to evaluate all sensitivity label.", + "displayName": "Evaluate labels tenant scope.", + "id": "986fa56a-6680-4aac-af09-4d1765376739", + "origin": "Application (Microsoft Graph)", + "value": "SensitivityLabel.Evaluate.All" }, { - "description": "Allows the app to read and write your organization's consent requests policy on behalf of the signed-in user.", - "displayName": "Read and write consent request policy", - "id": "4d135e65-66b8-41a8-9f8b-081452c91774", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write your organization's consent request policy on your behalf.", - "userConsentDisplayName": "Read and write consent request policy", - "value": "Policy.ReadWrite.ConsentRequest" + "description": "Allows the app to get sensitivity labels.", + "displayName": "Get labels application scope.", + "id": "3b8e7aad-f6e3-4299-83f8-6fc6a5777f0b", + "origin": "Application (Microsoft Graph)", + "value": "SensitivityLabel.Read" }, { - "description": "Allows the app to read presence information on behalf of the signed-in user. Presence information includes activity, availability, status note, calendar out-of-office message, timezone and location.", - "displayName": "Read user's presence information", - "id": "76bc735e-aecd-4a1d-8b4c-2b915deabb79", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your presence information on your behalf. Presence information includes activity, availability, status note, calendar out-of-office message, timezone and location.", - "userConsentDisplayName": "Read your presence information", - "value": "Presence.Read" + "description": "Allows the app to get sensitivity labels.", + "displayName": "Get labels tenant scope.", + "id": "e46a01e9-b2cf-4d89-8424-bcdc6dd445ab", + "origin": "Application (Microsoft Graph)", + "value": "SensitivityLabels.Read.All" }, { - "description": "Allows the app to read presence information of all users in the directory on behalf of the signed-in user. Presence information includes activity, availability, status note, calendar out-of-office message, timezone and location.", - "displayName": "Read presence information of all users in your organization", - "id": "9c7a330d-35b3-4aa1-963d-cb2b9f927841", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read presence information of all users in the directory on your behalf. Presence information includes activity, availability, status note, calendar out-of-office message, timezone and location.", - "userConsentDisplayName": "Read presence information of all users in your organization", - "value": "Presence.Read.All" + "description": "Allows the app to read all Sentiment Survey, without a signed-in user. ", + "displayName": "Export all Sentiment Survey", + "id": "84fa35c1-f997-4c1c-894c-bb52108cfbbf", + "origin": "Application (Microsoft Graph)", + "value": "SentimentSurvey.Export.All" }, { - "description": "Read the members of channels, on behalf of the signed-in user.", - "displayName": "Read the members of channels", - "id": "2eadaff8-0bce-4198-a6b9-2cfc35a30075", - "Origin": "Delegated", - "userConsentDescription": "Read the members of channels, on your behalf.", - "userConsentDisplayName": "Read the members of teams and channels", - "value": "ChannelMember.Read.All" + "description": "Allows the app to read all Exchange service activity, without a signed-in user.", + "displayName": "Read all Exchange service activity", + "id": "2b655018-450a-4845-81e7-d603b1ebffdb", + "origin": "Application (Microsoft Graph)", + "value": "ServiceActivity-Exchange.Read.All" }, { - "description": "Add and remove members from channels, on behalf of the signed-in user. Also allows changing a member's role, for example from owner to non-owner.", - "displayName": "Add and remove members from channels", - "id": "0c3e411a-ce45-4cd1-8f30-f99a3efa7b11", - "Origin": "Delegated", - "userConsentDescription": "Add and remove members from channels, on your behalf. Also allows changing a member's role, for example from owner to non-owner.", - "userConsentDisplayName": "Add and remove members from teams and channels", - "value": "ChannelMember.ReadWrite.All" + "description": "Allows the app to read all Microsoft 365 Web service activity, without a signed-in user.", + "displayName": "Read all Microsoft 365 Web service activity", + "id": "c766cb16-acc4-4663-ba09-6eedef5876c5", + "origin": "Application (Microsoft Graph)", + "value": "ServiceActivity-Microsoft365Web.Read.All" }, { - "description": "Allows the app to read and write the authentication flow policies, on behalf of the signed-in user. ", - "displayName": "Read and write authentication flow policies", - "id": "edb72de9-4252-4d03-a925-451deef99db7", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write the authentication flow policies for your tenant, on your behalf.", - "userConsentDisplayName": "Read and write your authentication flow policies", - "value": "Policy.ReadWrite.AuthenticationFlows" + "description": "Allows the app to read all One Drive service activity, without a signed-in user.", + "displayName": "Read all One Drive service activity", + "id": "57b4f899-b8c5-47c7-bdd3-c410c55602b7", + "origin": "Application (Microsoft Graph)", + "value": "ServiceActivity-OneDrive.Read.All" }, { - "description": "Allows an app to read a channel's messages in Microsoft Teams, on behalf of the signed-in user.", - "displayName": "Read user channel messages", - "id": "767156cb-16ae-4d10-8f8b-41b657c8c8c8", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read a channel's messages in Microsoft Teams, on your behalf.", - "userConsentDisplayName": "Read your channel messages", - "value": "ChannelMessage.Read.All" + "description": "Allows the app to read all Teams service activity, without a signed-in user.", + "displayName": "Read all Teams service activity", + "id": "4dfee10b-fa4a-41b5-b34d-ccf54cc0c394", + "origin": "Application (Microsoft Graph)", + "value": "ServiceActivity-Teams.Read.All" }, { - "description": "Allows the app to read the apps in the app catalogs.", - "displayName": "Read all app catalogs", - "id": "88e58d74-d3df-44f3-ad47-e89edf4472e4", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read apps in the app catalogs.", - "userConsentDisplayName": "Read all app catalogs", - "value": "AppCatalog.Read.All" + "description": "Allows the app to read your tenant's service health information, without a signed-in user. Health information may include service issues or service health overviews.", + "displayName": "Read service health", + "id": "79c261e0-fe76-4144-aad5-bdc68fbe4037", + "origin": "Application (Microsoft Graph)", + "value": "ServiceHealth.Read.All" }, { - "description": "Allows the app to read and write the authentication method policies, on behalf of the signed-in user.\u00a0", - "displayName": "Read and write authentication method policies", - "id": "7e823077-d88e-468f-a337-e18f1f0e6c7c", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write the authentication method policies for your tenant, on your behalf.", - "userConsentDisplayName": "Read and write your authentication method policies ", - "value": "Policy.ReadWrite.AuthenticationMethod" + "description": "Allows the app to read your tenant's service announcement messages, without a signed-in user. Messages may include information about new or changed features.", + "displayName": "Read service messages", + "id": "1b620472-6534-4fe6-9df2-4680e8aa28ec", + "origin": "Application (Microsoft Graph)", + "value": "ServiceMessage.Read.All" }, { - "description": "Allows the app to read and write your organization's authorization policy on behalf of the signed-in user. For example, authorization policies can control some of the permissions that the out-of-the-box user role has by default.", - "displayName": "Read and write your organization's authorization policy", - "id": "edd3c878-b384-41fd-95ad-e7407dd775be", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write your organization's authorization policy on your behalf. For example, authorization policies can control some of the permissions that the out-of-the-box user role has by default.", - "userConsentDisplayName": "Read and write your organization's authorization policy", - "value": "Policy.ReadWrite.Authorization" + "description": "Allows the app to read service principal endpoints", + "displayName": "Read service principal endpoints", + "id": "5256681e-b7f6-40c0-8447-2d9db68797a0", + "origin": "Application (Microsoft Graph)", + "value": "ServicePrincipalEndpoint.Read.All" }, { - "description": "Allows the app to read policies related to consent and permission grants for applications, on behalf of the signed-in user.", - "displayName": "Read consent and permission grant policies", - "id": "414de6ea-2d92-462f-b120-6e2a809a6d01", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read policies related to consent and permission grants for applications, on your behalf.", - "userConsentDisplayName": "Read consent and permission grant policies", - "value": "Policy.Read.PermissionGrant" + "description": "Allows the app to update service principal endpoints", + "displayName": "Read and update service principal endpoints", + "id": "89c8469c-83ad-45f7-8ff2-6e3d4285709e", + "origin": "Application (Microsoft Graph)", + "value": "ServicePrincipalEndpoint.ReadWrite.All" }, { - "description": "Allows the app to manage policies related to consent and permission grants for applications, on behalf of the signed-in user.", - "displayName": "Manage consent and permission grant policies", - "id": "2672f8bb-fd5e-42e0-85e1-ec764dd2614e", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to manage policies related to consent and permission grants for applications, on behalf of the signed-in user.", - "userConsentDisplayName": "Manage consent and permission grant policies", - "value": "Policy.ReadWrite.PermissionGrant" + "description": "Allows the app to read, write and manage your tenant's SharePoint Cross-Tenant migration settings and tasks, without a signed-in user.", + "displayName": "Read, write and manage SharePoint Cross-Tenant migration settings and tasks", + "id": "a0521574-fcd8-4742-b29c-f796df57ea70", + "origin": "Application (Microsoft Graph)", + "value": "SharePointCrossTenantMigration.Manage.All" }, { - "description": "Allows the application to create (register) printers on behalf of the signed-in user.\u00a0", - "displayName": "Register printers\u202f\u00a0", - "id": "90c30bed-6fd1-4279-bf39-714069619721", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to create (register) printers on your behalf.\u00a0", - "userConsentDisplayName": "Register printers\u202f\u00a0", - "value": "Printer.Create" + "description": "Allows the app to read your tenant's SharePoint Cross-Tenant migration settings and tasks, without a signed-in user.", + "displayName": "Read SharePoint Cross-Tenant migration settings and tasks", + "id": "f5fa52a5-b9ab-4dc3-885e-9e5b4a67068e", + "origin": "Application (Microsoft Graph)", + "value": "SharePointCrossTenantMigration.Read.All" }, { - "description": "Allows the application to create (register), read, update, and delete (unregister) printers on behalf of the signed-in user.\u00a0", - "displayName": "Register, read, update, and unregister printers", - "id": "93dae4bd-43a1-4a23-9a1a-92957e1d9121", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to create (register), read, update, and delete (unregister) printers on your behalf.\u00a0\u00a0", - "userConsentDisplayName": "Register, read, update, and unregister printers", - "value": "Printer.FullControl.All" + "description": "Allows the application to read the tenant-level settings of SharePoint and OneDrive, without a signed-in user.", + "displayName": "Read SharePoint and OneDrive tenant settings", + "id": "83d4163d-a2d8-4d3b-9695-4ae3ca98f888", + "origin": "Application (Microsoft Graph)", + "value": "SharePointTenantSettings.Read.All" }, { - "description": "Allows the application to read printers on behalf of the signed-in user.\u00a0", - "displayName": "Read printers", - "id": "3a736c8a-018e-460a-b60c-863b2683e8bf", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read printers on your behalf.\u00a0", - "userConsentDisplayName": "Read printers", - "value": "Printer.Read.All" + "description": "Allows the app to read all security incidents, without a signed-in user.", + "displayName": "Read all security incidents", + "id": "45cc0394-e837-488b-a098-1918f48d186c", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIncident.Read.All" }, { - "description": "Allows the application to read and update printers on behalf of the signed-in user.\u00a0Does not allow creating (registering) or deleting (unregistering) printers.", - "displayName": "Read and update printers", - "id": "89f66824-725f-4b8f-928e-e1c5258dc565", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read and update printers on your behalf.\u00a0Does not allow creating (registering) or deleting (unregistering) printers.", - "userConsentDisplayName": "Read and update printers", - "value": "Printer.ReadWrite.All" + "description": "Allows the app to read and write identity security available user actions without a signed-in user.", + "displayName": "Read and perform all identity security available user actions", + "id": "b4146a3a-dd4f-4af4-8d91-7cc0eef3d041", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIdentitiesUserActions.ReadWrite.All" }, { - "description": "Allows the application to read printer shares on behalf of the signed-in user.\u00a0", - "displayName": "Read printer shares", - "id": "ed11134d-2f3f-440d-a2e1-411efada2502", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read printer shares on your behalf.\u00a0", - "userConsentDisplayName": "Read printer shares", - "value": "PrinterShare.Read.All" + "description": "Allows the app to read all the identity security available user actions without a signed-in user.", + "displayName": "Read all identity security available user actions", + "id": "3e5d0bee-973f-4736-a123-4e1ab146f3a8", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIdentitiesUserActions.Read.All" }, { - "description": "Allows the application to read and update printer shares on behalf of the signed-in user.\u00a0", - "displayName": "Read and write printer shares", - "id": "06ceea37-85e2-40d7-bec3-91337a46038f", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read and update printer shares on your behalf.\u00a0", - "userConsentDisplayName": "Read and update printer shares", - "value": "PrinterShare.ReadWrite.All" + "description": "Allows the app to read and write identity security sensors without a signed-in user.", + "displayName": "Read and write all identity security sensors", + "id": "d4dcee6d-0774-412a-b06c-aeabbd99e816", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIdentitiesSensors.ReadWrite.All" }, { - "description": "Allows the application to read the metadata and document content of print jobs that the signed-in user created.", - "displayName": "Read user's print jobs", - "id": "248f5528-65c0-4c88-8326-876c7236df5e", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read the metadata and document content of print jobs that you created.", - "userConsentDisplayName": "Read your print jobs", - "value": "PrintJob.Read" + "description": "Allows the app to read security actions, without a signed-in user.", + "displayName": "Read your organization's security actions", + "id": "5e0edab9-c148-49d0-b423-ac253e121825", + "origin": "Application (Microsoft Graph)", + "value": "SecurityActions.Read.All" }, { - "description": "Allows the application to read the metadata and document content of print jobs on behalf of the signed-in user.\u00a0", - "displayName": "Read print jobs", - "id": "afdd6933-a0d8-40f7-bd1a-b5d778e8624b", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read the metadata and document content of print jobs on your behalf.\u00a0", - "userConsentDisplayName": "Read print jobs", - "value": "PrintJob.Read.All" + "description": "Allows the app to read or update security actions, without a signed-in user.", + "displayName": "Read and update your organization's security actions", + "id": "f2bf083f-0179-402a-bedb-b2784de8a49b", + "origin": "Application (Microsoft Graph)", + "value": "SecurityActions.ReadWrite.All" }, { - "description": "Allows the application to read the metadata of print jobs that the signed-in user created. Does not allow access to print job document content.", - "displayName": "Read basic information of user's print jobs", - "id": "6a71a747-280f-4670-9ca0-a9cbf882b274", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read the metadata of print jobs that you created. Does not allow access to print job document content.", - "userConsentDisplayName": "Read basic information of your print jobs", - "value": "PrintJob.ReadBasic" + "description": "Allows the app to create security alerts, without a signed-in user.", + "displayName": "Create security alerts", + "id": "06870c4c-7370-4a2a-ad10-239a337af816", + "origin": "Application (Microsoft Graph)", + "value": "SecurityAlert.Create.All" }, { - "description": "Allows the application to read the metadata of print jobs on behalf of the signed-in user.\u00a0Does not allow access to print job document content.", - "displayName": "Read basic information of print jobs", - "id": "04ce8d60-72ce-4867-85cf-6d82f36922f3", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read the metadata of print jobs on your behalf.\u00a0Does not allow access to print job document content.", - "userConsentDisplayName": "Read basic information of print jobs", - "value": "PrintJob.ReadBasic.All" + "description": "Allows the app to read all security alerts, without a signed-in user.", + "displayName": "Read all security alerts", + "id": "472e4a4d-bb4a-4026-98d1-0b0d74cb74a5", + "origin": "Application (Microsoft Graph)", + "value": "SecurityAlert.Read.All" }, { - "description": "Allows the application to read and update the metadata and document content of print jobs that the signed-in user created.", - "displayName": "Read and write user's print jobs", - "id": "b81dd597-8abb-4b3f-a07a-820b0316ed04", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read and update the metadata and document content of print jobs that you created.", - "userConsentDisplayName": "Read and update your print jobs", - "value": "PrintJob.ReadWrite" + "description": "Allows the app to read and write to all security alerts, without a signed-in user.", + "displayName": "Read and write to all security alerts", + "id": "ed4fca05-be46-441f-9803-1873825f8fdb", + "origin": "Application (Microsoft Graph)", + "value": "SecurityAlert.ReadWrite.All" }, { - "description": "Allows the application to read and update the metadata and document content of print jobs on behalf of the signed-in user.\u00a0", - "displayName": "Read and write print jobs", - "id": "036b9544-e8c5-46ef-900a-0646cc42b271", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read and update the metadata and document content of print jobs on your behalf.\u00a0", - "userConsentDisplayName": "Read and update print jobs", - "value": "PrintJob.ReadWrite.All" + "description": "Read email metadata and security detection details, without a signed-in user. ", + "displayName": "Read metadata and detection details for all emails in your organization", + "id": "b48f7ac2-044d-4281-b02f-75db744d6f5f", + "origin": "Application (Microsoft Graph)", + "value": "SecurityAnalyzedMessage.Read.All" }, { - "description": "Allows the application to read and update the metadata of print jobs that the signed-in user created. Does not allow access to print job document content.", - "displayName": "Read and write basic information of user's print jobs", - "id": "6f2d22f2-1cb6-412c-a17c-3336817eaa82", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read and update the metadata of print jobs that you created. Does not allow access to print job document content.", - "userConsentDisplayName": "Read and write basic information of your print jobs", - "value": "PrintJob.ReadWriteBasic" + "description": "Read email metadata and security detection details, and execute remediation actions like deleting an email, without a signed-in user.", + "displayName": "Read metadata, detection details, and execute remediation actions on all emails in your organization", + "id": "04c55753-2244-4c25-87fc-704ab82a4f69", + "origin": "Application (Microsoft Graph)", + "value": "SecurityAnalyzedMessage.ReadWrite.All" }, { - "description": "Allows the application to read and update the metadata of print jobs on behalf of the signed-in user.\u00a0Does not allow access to print job document content.", - "displayName": "Read and write basic information of print jobs", - "id": "3a0db2f6-0d2a-4c19-971b-49109b19ad3d", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read and update the metadata of print jobs on your behalf.\u00a0Does not allow access to print job document content.", - "userConsentDisplayName": "Read and write basic information of print jobs", - "value": "PrintJob.ReadWriteBasic.All" + "description": "Allows the app to read your organization’s security events without a signed-in user.", + "displayName": "Read your organization’s security events", + "id": "bf394140-e372-4bf9-a898-299cfc7564e5", + "origin": "Application (Microsoft Graph)", + "value": "SecurityEvents.Read.All" }, { - "description": "Allows the app to read and write your organization's device configuration policies on behalf of the signed-in user. For example, device registration policy can limit initial provisioning controls using quota restrictions, additional authentication and authorization checks.", - "displayName": "Read and write your organization's device configuration policies", - "id": "40b534c3-9552-4550-901b-23879c90bcf9", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write your organization's device configuration policies on your behalf. For example, device registration policy can limit initial provisioning controls using quota restrictions, additional authentication and authorization checks.", - "userConsentDisplayName": "Read and write your organization's device configuration policies", - "value": "Policy.ReadWrite.DeviceConfiguration" + "description": "Allows the application to read pull-print printers without a signed-in user. ", + "displayName": "Read pull-print printers", + "id": "f369d3b8-fe98-4772-85e1-b23e7cf41982", + "origin": "Application (Microsoft Graph)", + "value": "PullPrintPrinter.Read.All" }, { - "description": "Allows the app to submit application packages to the catalog and cancel submissions that are pending review on behalf of the signed-in user.", - "displayName": "Submit application packages to the catalog and cancel pending submissions", - "id": "3db89e36-7fa6-4012-b281-85f3d9d9fd2e", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to submit application packages to the catalog and cancel submissions that are pending review on your behalf.", - "userConsentDisplayName": "Submit application packages to your organization's catalog and cancel pending submissions", - "value": "AppCatalog.Submit" + "description": "Allows the app to read your organization’s security events without a signed-in user. Also allows the app to update editable properties in security events.", + "displayName": "Read and update your organization’s security events", + "id": "d903a879-88e0-4c09-b0c9-82f6a1333f84", + "origin": "Application (Microsoft Graph)", + "value": "SecurityEvents.ReadWrite.All" }, { - "description": "Allows the app to read the Teams apps that are installed in chats the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Read installed Teams apps in chats", - "id": "bf3fbf03-f35f-4e93-963e-47e4d874c37a", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the Teams apps that are installed in chats that you can access. Does not give the ability to read application-specific settings.", - "userConsentDisplayName": "Read installed Teams apps in chats", - "value": "TeamsAppInstallation.ReadForChat" + "description": "Allows the app to read and write identity security available actions without a signed-in user.", + "displayName": "Read and perform all identity security available actions", + "id": "af2bf46f-7bf1-4be3-8bad-e17e279e8462", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIdentitiesActions.ReadWrite.All" }, { - "description": "Allows the app to read the Teams apps that are installed in teams the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Read installed Teams apps in teams", - "id": "5248dcb1-f83b-4ec3-9f4d-a4428a961a72", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the Teams apps that are installed in teams that you can access. Does not give the ability to read application-specific settings.", - "userConsentDisplayName": "Read installed Teams apps in teams", - "value": "TeamsAppInstallation.ReadForTeam" + "description": "Allows the app to read sensors window auditing configuration without a signed-in user", + "displayName": "Read sensors window auditing configuration", + "id": "58971758-9844-4fe4-9fba-7e4ce7a659bf", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIdentitiesAutoConfig.Read.All" }, { - "description": "Allows the app to read the Teams apps that are installed for the signed-in user. Does not give the ability to read application-specific settings.", - "displayName": "Read user's installed Teams apps", - "id": "c395395c-ff9a-4dba-bc1f-8372ba9dca84", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the Teams apps that are installed for you. Does not give the ability to read application-specific settings.", - "userConsentDisplayName": "Read your installed Teams apps", - "value": "TeamsAppInstallation.ReadForUser" + "description": "Allows the app to read and write sensors window auditing configuration without a signed-in user", + "displayName": "Read and write sensors window auditing configuration", + "id": "4f1f0deb-08d1-4ffb-8cca-21dfc362b7c0", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIdentitiesAutoConfig.ReadWrite.All" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in teams the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Manage installed Teams apps in teams", - "id": "2e25a044-2580-450d-8859-42eeb6e996c0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, install, upgrade, and uninstall Teams apps in teams you can access. Does not give the ability to read application-specific settings.", - "userConsentDisplayName": "Manage installed Teams apps in teams", - "value": "TeamsAppInstallation.ReadWriteForTeam" + "description": "Allows the app to read all the identity security health issues without a signed-in user.", + "displayName": "Read all identity security health issues", + "id": "f8dcd971-5d83-4e1e-aa95-ef44611ad351", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIdentitiesHealth.Read.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in chats the signed-in user can access.", - "displayName": "Allow the Teams app to manage itself in chats", - "id": "0ce33576-30e8-43b7-99e5-62f8569a4002", - "Origin": "Delegated", - "userConsentDescription": "Allows a Teams app to read, install, upgrade, and uninstall itself in chats you can access.", - "userConsentDisplayName": "Allow the Teams app to manage itself in chats", - "value": "TeamsAppInstallation.ReadWriteSelfForChat" + "description": "Allows the app to read and write identity security health issues without a signed-in user.", + "displayName": "Read and write all identity security health issues", + "id": "ab03ddd5-7ae4-4f2e-8af8-86654f7e0a27", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIdentitiesHealth.ReadWrite.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for the signed-in user.", - "displayName": "Allow the Teams app to manage itself for a user", - "id": "207e0cb1-3ce7-4922-b991-5a760c346ebc", - "Origin": "Delegated", - "userConsentDescription": "Allows a Teams app to read, install, upgrade, and uninstall itself for you.", - "userConsentDisplayName": "Allow the Teams app to manage itself for you", - "value": "TeamsAppInstallation.ReadWriteSelfForUser" + "description": "Allows the app to read all the identity security sensor migration information without a signed-in user.", + "displayName": "Read all identity security sensor migration", + "id": "b018cc1c-c680-4e91-bb6e-462ee243fdb5", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIdentitiesMigration.Read.All" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps installed for the signed-in user. Does not give the ability to read application-specific settings.", - "displayName": "Manage user's installed Teams apps", - "id": "093f8818-d05f-49b8-95bc-9d2a73e9a43c", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, install, upgrade, and uninstall Teams apps installed for you. Does not give the ability to read application-specific settings.", - "userConsentDisplayName": "Manage your installed Teams apps", - "value": "TeamsAppInstallation.ReadWriteForUser" + "description": "Allows the app to read and write identity security sensor migration without a signed-in user.", + "displayName": "Read and write all identity security sensor migration", + "id": "afd28a5a-707f-4edf-85c2-c446291e63da", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIdentitiesMigration.ReadWrite.All" }, { - "description": "Allows the app to create teams on behalf of the signed-in user.", - "displayName": "Create teams", - "id": "7825d5d6-6049-4ce7-bdf6-3b8d53f4bcd0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to create teams on your behalf.\u00a0", - "userConsentDisplayName": "Create teams", - "value": "Team.Create" + "description": "Allows the app to read all the identity security sensors without a signed-in user.", + "displayName": "Read all identity security sensors", + "id": "5f0ffea2-f474-4cf2-9834-61cda2bcea5c", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIdentitiesSensors.Read.All" }, { - "description": "Add and remove members from all teams, on behalf of the signed-in user. Does not allow adding or removing a member with the owner role. Additionally, does not allow the app to elevate an existing member to the owner role.", - "displayName": "Add and remove members with non-owner role for all teams", - "id": "2104a4db-3a2f-4ea0-9dba-143d457dc666", - "Origin": "Delegated", - "userConsentDescription": "Add and remove members from all teams, on your behalf. Does not allow adding or removing a member with the owner role. Additionally, does not allow the app to elevate an existing member to the owner role.", - "userConsentDisplayName": "Add and remove members with non-owner role for all teams", - "value": "TeamMember.ReadWriteNonOwnerRole.All" + "description": "Allows the app to read all the identity security available identity accounts without a signed-in user.", + "displayName": "Read all identity security available identity accounts", + "id": "c5bc96f5-b4a1-4cfc-8189-d5f0d772278f", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIdentitiesAccount.Read.All" }, { - "description": "Allows the app to read the term store data that the signed-in user has access to. This includes all sets, groups and terms in the term store.", - "displayName": "Read term store data", - "id": "297f747b-0005-475b-8fef-c890f5152b38", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the term store data that you have access to. This includes all sets, groups and terms in the term store.", - "userConsentDisplayName": "Read term store data", - "value": "TermStore.Read.All" + "description": "Allows the app to read organization-wide Microsoft Forms settings, without a signed-in user.", + "displayName": "Read organization-wide Microsoft Forms settings", + "id": "434d7c66-07c6-4b1f-ab21-417cf2cdaaca", + "origin": "Application (Microsoft Graph)", + "value": "OrgSettings-Forms.Read.All" }, { - "description": "Allows the app to read or modify data that the signed-in user has access to.\u00a0This includes all sets, groups and terms in the term store.", - "displayName": "Read and write term store data", - "id": "6c37c71d-f50f-4bff-8fd3-8a41da390140", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read or modify data that you have access to. This includes all sets, groups and terms in the term store.", - "userConsentDisplayName": "Read and write term store data", - "value": "TermStore.ReadWrite.All" + "description": "Allows the application to read and write certificate-based authentication configuration such as all public key infrastructures (PKI) and certificate authorities (CA) configured for the organization, without a signed-in user.", + "displayName": "Read and write all certificate based authentication configurations", + "id": "a2b63618-5350-462d-b1b3-ba6eb3684e26", + "origin": "Application (Microsoft Graph)", + "value": "PublicKeyInfrastructure.ReadWrite.All" }, { - "description": "Allows the app to read your tenant's service announcement messages on behalf of the signed-in user. Messages may include information about new or changed features.", - "displayName": "Read service announcement messages", - "id": "eda39fa6-f8cf-4c3c-a909-432c683e4c9b", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your tenant's service announcement messages on your behalf. Messages may include information about new or changed features.", - "userConsentDisplayName": "Read service messages", - "value": "ServiceMessage.Read.All" + "description": "Allows the app to read and query your provisioning log activities, without a signed-in user.", + "displayName": "Read all provisioning log data", + "id": "091937d3-3e38-47a1-8649-b2f99d3035f1", + "origin": "Application (Microsoft Graph)", + "value": "ProvisioningLog.Read.All" }, { - "description": "Allows the app to read your tenant's service health information on behalf of the signed-in user. Health information may include service issues or service health overviews.", - "displayName": "Read service health", - "id": "55896846-df78-47a7-aa94-8d3d4442ca7f", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your tenant's service health information on your behalf.Health information may include service issues or service health overviews.", - "userConsentDisplayName": "Read service health", - "value": "ServiceHealth.Read.All" + "description": "Allows the app to read your organization's cross tenant access policies without a signed-in user.", + "displayName": "Read your organization's cross tenant access policies", + "id": "8fc84b9a-5c21-479b-ba9d-02d252d062aa", + "origin": "Application (Microsoft Graph)", + "value": "Policy.Read.CrossTenantAccess" }, { - "description": "Allows the app to read all the short notes a sign-in user has access to.", - "displayName": "Read short notes of the signed-in user", - "id": "50f66e47-eb56-45b7-aaa2-75057d9afe08", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your short notes.", - "userConsentDisplayName": "Read your short notes", - "value": "ShortNotes.Read" + "description": "Allows the application to read your organization's device configuration policies without a signed-in user. For example, device registration policy can limit initial provisioning controls using quota restrictions, additional authentication and authorization checks.", + "displayName": "Read your organization's device configuration policies", + "id": "bdba4817-6ba1-4a7c-8a01-be9bc7c242dd", + "origin": "Application (Microsoft Graph)", + "value": "Policy.Read.DeviceConfiguration" }, { - "description": "Allows the app to read, create, edit, and delete short notes of a signed-in user.", - "displayName": "Read, create, edit, and delete short notes of the signed-in user", - "id": "328438b7-4c01-4c07-a840-e625a749bb89", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, create, edit, and delete your short notes.", - "userConsentDisplayName": "Read, create, edit, and delete your short notes", - "value": "ShortNotes.ReadWrite" + "description": "Allows the app to read your organization’s identity protection policy without a signed-in user.", + "displayName": "Read your organization’s identity protection policy", + "id": "b21b72f6-4e6a-4533-9112-47eea9f97b28", + "origin": "Application (Microsoft Graph)", + "value": "Policy.Read.IdentityProtection" }, { - "description": "Allows the app to read your organization's conditional access policies on behalf of the signed-in user.", - "displayName": "Read your organization's conditional access policies", - "id": "633e0fce-8c58-4cfb-9495-12bbd5a24f7c", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your organization's conditional access policies on your behalf.", - "userConsentDisplayName": "Read your organization's conditional access policies", - "value": "Policy.Read.ConditionalAccess" + "description": "Allows the app to read policies related to consent and permission grants for applications, without a signed-in user.", + "displayName": "Read consent and permission grant policies", + "id": "9e640839-a198-48fb-8b9a-013fd6f6cbcd", + "origin": "Application (Microsoft Graph)", + "value": "Policy.Read.PermissionGrant" }, { - "description": "Allows the app to read the role-based access control (RBAC) settings for all RBAC providers, on behalf of the signed-in user. This includes reading role definitions and role assignments.", - "displayName": "Read role management data for all RBAC providers", - "id": "48fec646-b2ba-4019-8681-8eb31435aded", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the role-based access control (RBAC) settings for all RBAC providers, on your behalf. This includes reading role definitions and role assignments.", - "userConsentDisplayName": "Read role management data for all RBAC providers", - "value": "RoleManagement.Read.All" + "description": "Allows the application to read and update the organization's recovery policy without a signed-in user.", + "displayName": "Read your organization's recovery policy", + "id": "447f996a-7c58-4ce7-9a9e-da80381a45ab", + "origin": "Application (Microsoft Graph)", + "value": "Policy.Read.Recovery" }, { - "description": "Allows an app to send one-to-one and group chat messages in Microsoft Teams, on behalf of the signed-in user.", - "displayName": "Send user chat messages", - "id": "116b7235-7cc6-461e-b163-8e55691d839e", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to send one-to-one and group chat messages in Microsoft Teams, on your behalf.", - "userConsentDisplayName": "Send chat messages", - "value": "ChatMessage.Send" + "description": "Allows the app to read and write your organization's directory access review default policy without a signed-in user.", + "displayName": "Read and write your organization's directory access review default policy", + "id": "77c863fd-06c0-47ce-a7eb-49773e89d319", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.AccessReview" }, { - "description": "Allows an app to read the members and descriptions of one-to-one and group chat threads, on behalf of the signed-in user.", - "displayName": "Read names and members of user chat threads", - "id": "9547fcb5-d03f-419d-9948-5928bbf71b0f", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to read the members and descriptions of one-to-one and group chat threads, on your behalf.", - "userConsentDisplayName": "Read names and members of your chat threads", - "value": "Chat.ReadBasic" + "description": "Allows the app to read and write your organization's application configuration policies, without a signed-in user. This includes policies such as activityBasedTimeoutPolicy, claimsMappingPolicy, homeRealmDiscoveryPolicy, tokenIssuancePolicy and tokenLifetimePolicy.", + "displayName": "Read and write your organization's application configuration policies", + "id": "be74164b-cff1-491c-8741-e671cb536e13", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.ApplicationConfiguration" }, { - "description": "Allows the app to read and write the properties of Cloud PCs on behalf of the signed-in user.", - "displayName": "Read and write Cloud PCs", - "id": "9d77138f-f0e2-47ba-ab33-cd246c8b79d1", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write the properties of Cloud PCs, on your behalf.", - "userConsentDisplayName": "Read and write Cloud PCs", - "value": "CloudPC.ReadWrite.All" + "description": "Allows the app to read and write all authentication flow policies for the tenant, without a signed-in user.", + "displayName": "Read and write authentication flow policies", + "id": "25f85f3c-f66c-4205-8cd5-de92dd7f0cec", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.AuthenticationFlows" }, { - "description": "Allows the app to read the properties of Cloud PCs on behalf of the signed-in user.", - "displayName": "Read Cloud PCs", - "id": "5252ec4e-fd40-4d92-8c68-89dd1d3c6110", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the properties of Cloud PCs, on your behalf.", - "userConsentDisplayName": "Read Cloud PCs", - "value": "CloudPC.Read.All" + "description": "Allows the app to read and write all authentication method policies for the tenant, without a signed-in user. ", + "displayName": "Read and write all authentication method policies ", + "id": "29c18626-4985-4dcd-85c0-193eef327366", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.AuthenticationMethod" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in chats the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Manage installed Teams apps in chats", - "id": "aa85bf13-d771-4d5d-a9e6-bca04ce44edf", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, install, upgrade, and uninstall Teams apps in chats you can access. Does not give the ability to read application-specific settings.", - "userConsentDisplayName": "Manage installed Teams apps in chats", - "value": "TeamsAppInstallation.ReadWriteForChat" + "description": "Allows the app to read and write your organization's authorization policy without a signed in user. For example, authorization policies can control some of the permissions that the out-of-the-box user role has by default.", + "displayName": "Read and write your organization's authorization policy", + "id": "fb221be6-99f2-473f-bd32-01c6a0e9ca3b", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.Authorization" }, { - "description": "Allows the app to create, read, update, and delete the signed-in user's tasks and task lists, including any shared with the user.", - "displayName": "Create, read, update, and delete user\u2019s tasks and task lists", - "id": "2219042f-cab5-40cc-b0d2-16b1540b4c5f", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to create, read, update, and delete your tasks and task lists, including any shared with you.", - "userConsentDisplayName": "Create, read, update, and delete your tasks and task lists", - "value": "Tasks.ReadWrite" + "description": "Allows the app to read and write all your organization's B2BManagement policies without a signed in user.", + "displayName": "Read and write your organization's B2BManagement policies", + "id": "886bd2d9-5b8b-4b49-adea-ca75fb50d9ef", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.B2BManagementPolicy" }, { - "description": "Allows the app to read the signed-in user\u2019s tasks and task lists, including any shared with the user. Doesn't include permission to create, delete, or update anything.", - "displayName": "Read user's tasks and task lists", - "id": "f45671fb-e0fe-4b4b-be20-3d3ce43f1bcb", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your tasks and task lists, including any shared with you. Doesn't include permission to create, delete, or update anything.", - "userConsentDisplayName": "Read your tasks and task lists", - "value": "Tasks.Read" + "description": "Allows the app to read and write your organization's conditional access policies, without a signed-in user.", + "displayName": "Read and write your organization's conditional access policies", + "id": "01c0a623-fc9b-48e9-b794-0756f8e8f067", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.ConditionalAccess" }, { - "description": "Allows an app to read one-to-one and group chat messages, on behalf of the signed-in user.", - "displayName": "Read user chat messages", - "id": "cdcdac3a-fd45-410d-83ef-554db620e5c7", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to read one-to-one or group chat messages in Microsoft Teams, on your behalf.", - "userConsentDisplayName": "Read user chat messages", - "value": "ChatMessage.Read" + "description": "Allows the app to read and write your organization's consent requests policy without a signed-in user.", + "displayName": "Read and write your organization's consent request policy", + "id": "999f8c63-0a38-4f1b-91fd-ed1947bdd1a9", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.ConsentRequest" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs in chats the signed-in user can access.", - "displayName": "Allow the Teams app to manage all tabs in chats", - "id": "ee928332-e9c2-4747-b4a0-f8c164b68de6", - "Origin": "Delegated", - "userConsentDescription": "Allows a Teams app to read, install, upgrade, and uninstall all tabs in chats you can access.", - "userConsentDisplayName": "Allow the Teams app to manage all tabs in chats", - "value": "TeamsTab.ReadWriteForChat" + "description": "Allows the app to read and write your organization's cross-tenant access policies and configuration for automatic user consent settings to suppress consent prompts for users of the other tenant on behalf of the signed-in user.", + "displayName": "Read and write your organization's cross tenant access policies", + "id": "338163d7-f101-4c92-94ba-ca46fe52447c", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.CrossTenantAccess" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs to teams the signed-in user can access.", - "displayName": "Allow the Teams app to manage all tabs in teams", - "id": "c975dd04-a06e-4fbb-9704-62daad77bb49", - "Origin": "Delegated", - "userConsentDescription": "Allows a Teams app to read, install, upgrade, and uninstall all tabs to teams you can access.", - "userConsentDisplayName": "Allow the app to manage all tabs in teams", - "value": "TeamsTab.ReadWriteForTeam" + "description": "Allows the app to read and write your organization's M365 cross tenant access capabilities without a signed-in user.", + "displayName": "Read and write your organization's M365 cross tenant access capabilities", + "id": "a6325ae7-2b73-4dbd-abed-fbeacfbf8696", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.CrossTenantCapability" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs for the signed-in user.", - "displayName": "Allow the Teams app to manage all tabs for a user", - "id": "c37c9b61-7762-4bff-a156-afc0005847a0", - "Origin": "Delegated", - "userConsentDescription": "Allows a Teams app to read, install, upgrade, and uninstall all tabs for you.", - "userConsentDisplayName": "Allow the Teams app to manage all tabs for you", - "value": "TeamsTab.ReadWriteForUser" + "description": "Allows the application to read and write your organization's device configuration policies without a signed-in user. For example, device registration policy can limit initial provisioning controls using quota restrictions, additional authentication and authorization checks.", + "displayName": "Read and write your organization's device configuration policies", + "id": "230fb2d5-aa21-49c1-bfa7-ae1be179d867", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.DeviceConfiguration" }, { - "description": "Allows the app to read the API connectors used in user authentication flows, on behalf of the signed-in user.", - "displayName": "Read API connectors for authentication flows", - "id": "1b6ff35f-31df-4332-8571-d31ea5a4893f", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the API connectors used in user authentication flows, on your behalf.", - "userConsentDisplayName": "Read API connectors for authentication flows", - "value": "APIConnectors.Read.All" + "description": "Allows the application to read and update the organization's external identities policy without a signed-in user. For example, external identities policy controls if users invited to access resources in your organization via B2B collaboration or B2B direct connect are allowed to self-service leave.", + "displayName": "Read and write your organization's external identities policy", + "id": "03cc4f92-788e-4ede-b93f-199424d144a5", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.ExternalIdentities" }, { - "description": "Allows the app to read, create and manage the API connectors used in user authentication flows, on behalf of the signed-in user.", - "displayName": "Read and write API connectors for authentication flows", - "id": "c67b52c5-7c69-48b6-9d48-7b3af3ded914", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read, create and manage the API connectors used in user authentication flows, on your behalf.", - "userConsentDisplayName": "Read and write API connectors for authentication flows", - "value": "APIConnectors.ReadWrite.All" + "description": "Allows the app to read your organization's conditional access policies, without a signed-in user.", + "displayName": "Read your organization's conditional access policies", + "id": "37730810-e9ba-4e46-b07e-8ca78d182097", + "origin": "Application (Microsoft Graph)", + "value": "Policy.Read.ConditionalAccess" }, { - "description": "Read the members of chats, on behalf of the signed-in user.", - "displayName": "Read the members of chats", - "id": "c5a9e2b1-faf6-41d4-8875-d381aa549b24", - "Origin": "Delegated", - "userConsentDescription": "Read the members of chats, on your behalf.", - "userConsentDisplayName": "Read the members of chats", - "value": "ChatMember.Read" + "description": "Allows the app to read and write feature rollout policies without a signed-in user. Includes abilities to assign and remove users and groups to rollout of a specific feature.", + "displayName": "Read and write feature rollout policies", + "id": "2044e4f1-e56c-435b-925c-44cd8f6ba89a", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.FeatureRollout" }, { - "description": "Add and remove members from chats, on behalf of the signed-in user.", - "displayName": "Add and remove members from chats", - "id": "dea13482-7ea6-488f-8b98-eb5bbecf033d", - "Origin": "Delegated", - "userConsentDescription": "Add and remove members from chats, on your behalf.", - "userConsentDisplayName": "Add and remove members from chats", - "value": "ChatMember.ReadWrite" + "description": "Allows the app to read all your organization's B2BManagement policies without a signed in user.", + "displayName": "Read your organization's B2BManagement policies", + "id": "227900ff-df89-40f8-90e2-8157cf6995d5", + "origin": "Application (Microsoft Graph)", + "value": "Policy.Read.B2BManagementPolicy" }, { - "description": "Allows the app to create chats on behalf of the signed-in user.", - "displayName": "Create chats", - "id": "38826093-1258-4dea-98f0-00003be2b8d0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to create chats on your behalf.\u00a0", - "userConsentDisplayName": "Create chats", - "value": "Chat.Create" + "description": "Allows the app to read all your organization's policies without a signed in user.", + "displayName": "Read your organization's policies", + "id": "246dd0d5-5bd0-4def-940b-0421030a5b68", + "origin": "Application (Microsoft Graph)", + "value": "Policy.Read.All" }, { - "description": "Allows the application to read and write tenant-wide print settings on behalf of the signed-in user.", - "displayName": "Read and write tenant-wide print settings", - "id": "9ccc526a-c51c-4e5c-a1fd-74726ef50b8f", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read and write tenant-wide print settings on your behalf.", - "userConsentDisplayName": "Read and write tenant-wide print settings", - "value": "PrintSettings.ReadWrite.All" + "description": "Allows the app to read organization-wide Microsoft 365 apps installation settings, without a signed-in user.", + "displayName": "Read organization-wide Microsoft 365 apps installation settings", + "id": "6cdf1fb1-b46f-424f-9493-07247caa22e2", + "origin": "Application (Microsoft Graph)", + "value": "OrgSettings-Microsoft365Install.Read.All" }, { - "description": "Allows the application to read tenant-wide print settings on behalf of the signed-in user.", - "displayName": "Read tenant-wide print settings", - "id": "490f32fd-d90f-4dd7-a601-ff6cdc1a3f6c", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read tenant-wide print settings on your behalf.", - "userConsentDisplayName": "Read tenant-wide print settings", - "value": "PrintSettings.Read.All" + "description": "Allows the app to read and write organization-wide Microsoft 365 apps installation settings, without a signed-in user.", + "displayName": "Read and write organization-wide Microsoft 365 apps installation settings", + "id": "83f7232f-763c-47b2-a097-e35d2cbe1da5", + "origin": "Application (Microsoft Graph)", + "value": "OrgSettings-Microsoft365Install.ReadWrite.All" }, { - "description": "Allows the application to read and write print connectors on behalf of the signed-in user. ", - "displayName": "Read and write print connectors", - "id": "79ef9967-7d59-4213-9c64-4b10687637d8", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read and write print connectors on your behalf.", - "userConsentDisplayName": "Read and write print connectors", - "value": "PrintConnector.ReadWrite.All" + "description": "Allows the app to read organization-wide Microsoft To Do settings, without a signed-in user.", + "displayName": "Read organization-wide Microsoft To Do settings", + "id": "e4d9cd09-d858-4363-9410-abb96737f0cf", + "origin": "Application (Microsoft Graph)", + "value": "OrgSettings-Todo.Read.All" }, { - "description": "Allows the application to read print connectors on behalf of the signed-in user.", - "displayName": "Read print connectors", - "id": "d69c2d6d-4f72-4f99-a6b9-663e32f8cf68", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read print connectors on your behalf.", - "userConsentDisplayName": "Read print connectors", - "value": "PrintConnector.Read.All" + "description": "Allows the app to read and write organization-wide Microsoft To Do settings, without a signed-in user.", + "displayName": "Read and write organization-wide Microsoft To Do settings", + "id": "5febc9da-e0d0-4576-bd13-ae70b2179a39", + "origin": "Application (Microsoft Graph)", + "value": "OrgSettings-Todo.ReadWrite.All" }, { - "description": "Allows the application to read basic information about printer shares on behalf of the signed-in user. Does not allow reading access control information.", - "displayName": "Read basic information about printer shares", - "id": "5fa075e9-b951-4165-947b-c63396ff0a37", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read basic information about printer shares on your behalf.", - "userConsentDisplayName": "Read basic information about printer shares", - "value": "PrinterShare.ReadBasic.All" + "description": "Allows the app to read all of billing data from Microsoft for your company's tenant, without a signed-in user. This includes reading billed and unbilled azure usage and invoice reconciliation data.", + "displayName": "Read all billing data for your company's tenant", + "id": "7c3e1994-38ff-4412-a99b-9369f6bb7706", + "origin": "Application (Microsoft Graph)", + "value": "PartnerBilling.Read.All" }, { - "description": "Allows the application to create print jobs on behalf of the signed-in user and upload document content to print jobs that the signed-in user created.", - "displayName": "Create print jobs", - "id": "21f0d9c0-9f13-48b3-94e0-b6b231c7d320", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to create print jobs on your behalf and upload document content to print jobs that you created.", - "userConsentDisplayName": "Create your print jobs", - "value": "PrintJob.Create" + "description": "Allows the app to read security alerts of customer with CSP relationship, without a signed-in user.", + "displayName": "Read security alerts of customer with CSP relationship", + "id": "21ffa320-2e7f-47d3-a466-7ff04d2dd68d", + "origin": "Application (Microsoft Graph)", + "value": "PartnerSecurity.Read.All" }, { - "description": "Allows the app to read Azure AD recommendations, on behalf of the signed-in user.", - "displayName": "Read Azure AD recommendations", - "id": "34d3bd24-f6a6-468c-b67c-0c365c1d6410", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read Azure AD recommendations, on your behalf.", - "userConsentDisplayName": "Read Azure AD recommendations", - "value": "DirectoryRecommendations.Read.All" + "description": "Allows the app to read security alerts and update status of alerts of customer with CSP relationship, without a signed-in user.", + "displayName": "Read security alerts and update status of security alerts of customer with CSP relationship", + "id": "04a2c935-5b4b-474a-be42-11f53111f271", + "origin": "Application (Microsoft Graph)", + "value": "PartnerSecurity.ReadWrite.All" }, { - "description": "Allows the application to list and query user profile information associated with the current tenant on behalf of the signed-in user.\u00a0 It also permits the application to export and remove external user data (e.g. customer content or system-generated logs), associated with the current tenant on behalf of the signed-in user.", - "displayName": "Read shared cross-tenant user profile and export or delete data", - "id": "eed0129d-dc60-4f30-8641-daf337a39ffd", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to list and query shared user profile information associated with the current tenant on your behalf.\u00a0 It also permits the application to export and remove your external user data (e.g. customer content or system-generated logs), associated with the current tenant on your behalf.", - "userConsentDisplayName": "Read shared cross-tenant user profile and export or delete data", - "value": "CrossTenantUserProfileSharing.ReadWrite" + "description": "Allows the app to read available properties of pending external user profiles, without a signed-in user.", + "displayName": "Read all pending external user profiles", + "id": "bdfb26d9-bb36-49be-9b4c-b8cbf4b05808", + "origin": "Application (Microsoft Graph)", + "value": "PendingExternalUserProfile.Read.All" }, { - "description": "Allows the app to manage restricted resources based on the other permissions granted to the app, on behalf of the signed-in user.", - "displayName": "Manage restricted resources in the directory", - "id": "cba5390f-ed6a-4b7f-b657-0efc2210ed20", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to manage restricted resources based on the other permissions granted to the app, on your behalf.", - "userConsentDisplayName": "Manage restricted resources in the directory", - "value": "Directory.Write.Restricted" + "description": "Allows the app to read and write available properties of pending external user profiles, without a signed-in user.", + "displayName": "Read and write all pending external user profiles", + "id": "8363c2b8-6ff7-420b-9966-c5884c2d48bc", + "origin": "Application (Microsoft Graph)", + "value": "PendingExternalUserProfile.ReadWrite.All" }, { - "description": "Allows the app to read your organization's threat submission policies on behalf of the signed-in user. Also allows the app to create new threat submission policies on behalf of the signed-in user.", - "displayName": "Read and write all threat submission policies", - "id": "059e5840-5353-4c68-b1da-666a033fc5e8", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your organization's threat submission policies on your behalf. Also allows the app to create new threat submission policies on your behalf.", - "userConsentDisplayName": "Read and write all threat submission policies", - "value": "ThreatSubmissionPolicy.ReadWrite.All" + "description": "Allows the app to read any user's scored list of relevant people, without a signed-in user. The list can include local contacts, contacts from social networking, your organization's directory, and people from recent communications (such as email and Skype).", + "displayName": "Read all users' relevant people lists", + "id": "b528084d-ad10-4598-8b93-929746b4d7d6", + "origin": "Application (Microsoft Graph)", + "value": "People.Read.All" }, { - "description": "Allows an app to read the browser site lists configured for your organization, on behalf of the signed-in user.", - "displayName": "Read browser site lists for your organization", - "id": "fb9be2b7-a7fc-4182-aec1-eda4597c43d5", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to read the browser site lists configured for your organization, on your behalf.", - "userConsentDisplayName": "Read browser site lists for your organization", - "value": "BrowserSiteLists.Read.All" + "description": "Allows the application to read tenant-wide people settings without a signed-in user.", + "displayName": "Read all tenant-wide people settings", + "id": "ef02f2e7-e22d-4c77-8614-8f765683b86e", + "origin": "Application (Microsoft Graph)", + "value": "PeopleSettings.Read.All" }, { - "description": "Allows the application to list and query any shared user profile information associated with the current tenant on behalf of the signed-in user.\u00a0 It also permits the application to export and remove external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant on behalf of the signed-in user.", - "displayName": "Read all shared cross-tenant user profiles and export or delete their data", - "id": "64dfa325-cbf8-48e3-938d-51224a0cac01", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to list and query any shared user profile information associated with the current tenant on your behalf.\u00a0 It also permits the application to export and remove external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant on your behalf.", - "userConsentDisplayName": "Read any shared cross-tenant user profiles and export or delete data", - "value": "CrossTenantUserProfileSharing.ReadWrite.All" + "description": "Allows the application to read and write tenant-wide people settings without a signed-in user.", + "displayName": "Read and write all tenant-wide people settings", + "id": "b6890674-9dd5-4e42-bb15-5af07f541ae1", + "origin": "Application (Microsoft Graph)", + "value": "PeopleSettings.ReadWrite.All" }, { - "description": "Allows the app to read the threat submissions and threat submission policies owned by the signed-in user.", - "displayName": "Read threat submissions", - "id": "fd5353c6-26dd-449f-a565-c4e16b9fce78", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the threat submissions and threat submission policies that you own on your behalf.", - "userConsentDisplayName": "Read threat submissions", - "value": "ThreatSubmission.Read" + "description": "Allows the app to read company places (conference rooms and room lists) for calendar events and other applications, without a signed-in user.", + "displayName": "Read all company places", + "id": "913b9306-0ce1-42b8-9137-6a7df690a760", + "origin": "Application (Microsoft Graph)", + "value": "Place.Read.All" }, { - "description": "Allows the app to read the threat submissions and threat submission policies owned by the signed-in user. Also allows the app to create new threat submissions on behalf of the signed-in user.", - "displayName": "Read and write threat submissions", - "id": "68a3156e-46c9-443c-b85c-921397f082b5", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the threat submissions and threat submission policies that you own. Also allows the app to create new threat submissions on your behalf.", - "userConsentDisplayName": "Read and write threat submissions", - "value": "ThreatSubmission.ReadWrite" + "description": "Allows the app to manage organization places (conference rooms and room lists) for calendar events and other applications, on behalf of the signed-in user.", + "displayName": "Read and write organization places", + "id": "f1f5e9aa-ad18-4b97-883e-6aa7e95b7a5f", + "origin": "Application (Microsoft Graph)", + "value": "Place.ReadWrite.All" }, { - "description": "Allows the app to read all recordings of online meetings, on behalf of the signed-in user.", - "displayName": "Read all recordings of online meetings.", - "id": "190c2bb6-1fdd-4fec-9aa2-7d571b5e1fe3", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all recordings of online meetings, on your behalf.\u00a0", - "userConsentDisplayName": "Read all recordings of online meetings.\u00a0", - "value": "OnlineMeetingRecording.Read.All" + "description": "Allows the app to read all workplace devices, without a signed-in user.", + "displayName": "Read all workplace devices", + "id": "8b724a84-ceac-4fd9-897e-e31ba8f2d7a3", + "origin": "Application (Microsoft Graph)", + "value": "PlaceDevice.Read.All" }, { - "description": "Allows the application to obtain basic tenant information about another target tenant within the Azure AD ecosystem on behalf of the signed-in user.", - "displayName": "Read cross-tenant basic information", - "id": "81594d25-e88e-49cf-ac8c-fecbff49f994", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to obtain basic tenant information about another target tenant within the Azure AD ecosystem on your behalf.", - "userConsentDisplayName": "Read cross-tenant basic information", - "value": "CrossTenantInformation.ReadBasic.All" + "description": "Allows the app to read and write all workplace devices, without a signed-in user.", + "displayName": "Read and write all workplace devices", + "id": "2d510721-5c4e-43cd-bfdb-ac0f8819fb92", + "origin": "Application (Microsoft Graph)", + "value": "PlaceDevice.ReadWrite.All" }, { - "description": "Allows the app to read your organization's authentication event listeners on behalf of the signed-in user.", - "displayName": "Read your organization's authentication event listeners", - "id": "f7dd3bed-5eec-48da-bc73-1c0ef50bc9a1", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your organization's authentication event listeners on your behalf.", - "userConsentDisplayName": "Read your organization's authentication event listeners", - "value": "EventListener.Read.All" + "description": "Allows the app to read and write telemetry for all workplace devices, without a signed-in user.", + "displayName": "Read and write telemetry for all workplace devices.", + "id": "27fc435f-44e2-4b30-bf3c-e0ce74aed618", + "origin": "Application (Microsoft Graph)", + "value": "PlaceDeviceTelemetry.ReadWrite.All" }, { - "description": "Allows the app to read the Teams app settings on behalf of the signed-in user.", - "displayName": "Read Teams app settings", - "id": "44e060c4-bbdc-4256-a0b9-dcc0396db368", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the Teams app settings on your behalf.", - "userConsentDisplayName": "Read Teams app settings", - "value": "TeamworkAppSettings.Read.All" + "description": "Allows the app to read all authentication method policies for the tenant, without a signed-in user. ", + "displayName": "Read authentication method policies", + "id": "8e3bc81b-d2f3-4b7b-838c-32c88218d2f0", + "origin": "Application (Microsoft Graph)", + "value": "Policy.Read.AuthenticationMethod" }, { - "description": "Allows\u00a0the\u00a0app\u00a0to\u00a0manage learning\u00a0content\u00a0in\u00a0the\u00a0organization's\u00a0directory, on behalf of the signed-in user.", - "displayName": "Manage\u00a0learning\u00a0content", - "id": "53cec1c4-a65f-4981-9dc1-ad75dbf1c077", - "Origin": "Delegated", - "userConsentDescription": "Allows\u00a0the\u00a0app\u00a0to\u00a0manage learning\u00a0content\u00a0in\u00a0the\u00a0organization's\u00a0directory, on your behalf.", - "userConsentDisplayName": "Manage learning content", - "value": "LearningContent.ReadWrite.All" + "description": "Allows the application to read and update the organization's federated token validation policy without a signed-in user.", + "displayName": "Read and write your organization's federated token validation policy", + "id": "90bbca0b-227c-4cdc-8083-1c6cfb95bac6", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.FedTokenValidation" }, { - "description": "Allows the app to create, update, read, and delete data for the learning provider in the organization's directory, on behalf of the signed-in user.", - "displayName": "Manage\u00a0learning\u00a0provider", - "id": "40c2eb57-abaf-49f5-9331-e90fd01f7130", - "Origin": "Delegated", - "userConsentDescription": "Allows\u00a0the\u00a0app\u00a0to\u00a0create, update, read, and delete\u00a0data\u00a0for\u00a0the learning\u00a0provider\u00a0in\u00a0the organization's\u00a0directory, on your behalf.", - "userConsentDisplayName": "Manage learning provider", - "value": "LearningProvider.ReadWrite" + "description": "Allows the app to read and write your organization’s identity protection policy without a signed-in user.", + "displayName": "Read and write your organization’s identity protection policy ", + "id": "2dcf8603-09eb-4078-b1ec-d30a1a76b873", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.IdentityProtection" }, { - "description": "Allows the app to read the lifecycle information like employeeLeaveDateTime of users in your organization, on behalf of the signed-in user.", - "displayName": "Read all users' lifecycle information", - "id": "ed8d2a04-0374-41f1-aefe-da8ac87ccc87", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read the lifecycle information like employeeLeaveDateTime of users in your organization, on behalf of the signed-in user.", - "userConsentDisplayName": "Read all users' lifecycle information", - "value": "User-LifeCycleInfo.Read.All" + "description": "Allows the app to manage policies related to consent and permission grants for applications, without a signed-in user.", + "displayName": "Manage consent and permission grant policies", + "id": "a402ca1c-2696-4531-972d-6e5ee4aa11ea", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.PermissionGrant" }, { - "description": "Allows an app to read and write the browser site lists configured for your organization, on behalf of the signed-in user.", - "displayName": "Read and write browser site lists for your organization", - "id": "83b34c85-95bf-497b-a04e-b58eca9d49d0", - "Origin": "Delegated", - "userConsentDescription": "Allows an app to read and write the browser site lists configured for your organization, on your behalf.", - "userConsentDisplayName": "Read and write browser site lists for your organization", - "value": "BrowserSiteLists.ReadWrite.All" + "description": "Allows the app to read and write Privileged Access (PIM) custom extensions for your organization, without a signed-in user.", + "displayName": "Read and write Privileged Access (PIM) custom extensions", + "id": "124325f3-0c46-4c57-a050-d6d1a82510f6", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedAccess-CustomExt.ReadWrite.All" }, { - "description": "Allows the application to list and query user profile information associated with the current tenant on behalf of the signed-in user.\u00a0 It also permits the application to export external user data (e.g. customer content or system-generated logs), associated with the current tenant on behalf of the signed-in user.", - "displayName": "Read shared cross-tenant user profile and export data", - "id": "cb1ba48f-d22b-4325-a07f-74135a62ee41", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to list and query shared user profile information associated with the current tenant on your behalf.\u00a0 It also permits the application to export your external user data (e.g. customer content or system-generated logs), associated with the current tenant on your behalf.", - "userConsentDisplayName": "Read shared cross-tenant user profile and export data", - "value": "CrossTenantUserProfileSharing.Read" + "description": "Allows the app to read time-based assignment schedules for access to Azure AD groups, without a signed-in user.", + "displayName": "Read assignment schedules for access to Azure AD groups", + "id": "cd4161cb-f098-48f8-a884-1eda9a42434c", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedAssignmentSchedule.Read.AzureADGroup" }, { - "description": "Allows the app to read admin report settings, such as whether to display concealed information in reports, on behalf of the signed-in user", - "displayName": "Read admin report settings", - "id": "84fac5f4-33a9-4100-aa38-a20c6d29e5e7", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read admin report settings, such as whether to display concealed information in reports, on your behalf.", - "userConsentDisplayName": "Read admin report settings", - "value": "ReportSettings.Read.All" + "description": "Allows the app to read time-based assignment schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, without a signed-in user.", + "displayName": "Read assignment schedules for app permission grants and app role assignments", + "id": "3a728f2e-df1d-4294-9899-86f601fae70a", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedAssignmentSchedule.Read.EntraAppRole" }, { - "description": "Allows the app to read and write the lifecycle information like employeeLeaveDateTime of users in your organization, on behalf of the signed-in user.", - "displayName": "Read and write all users' lifecycle information", - "id": "7ee7473e-bd4b-4c9f-987c-bd58481f5fa2", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write the lifecycle information like employeeLeaveDateTime of users in your organization, on behalf of the signed-in user.", - "userConsentDisplayName": "Read and write all users' lifecycle information", - "value": "User-LifeCycleInfo.ReadWrite.All" + "description": "Allows the app to read, create, and delete time-based assignment schedules for access to Azure AD groups, without a signed-in user.", + "displayName": "Read, create, and delete assignment schedules for access to Azure AD groups", + "id": "41202f2c-f7ab-45be-b001-85c9728b9d69", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedAssignmentSchedule.ReadWrite.AzureADGroup" }, { - "description": "Allows the app to read and update Azure AD recommendations, on behalf of the signed-in user. ", - "displayName": "Read and update Azure AD recommendations", - "id": "f37235e8-90a0-4189-93e2-e55b53867ccd", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and update Azure AD recommendations, on your behalf.", - "userConsentDisplayName": "Read and update Azure AD recommendations", - "value": "DirectoryRecommendations.ReadWrite.All" + "description": "Allows the app to read, create, and delete time-based assignment schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, without a signed-in user.", + "displayName": "Read, create, and delete assignment schedules for app permission grants and app role assignments", + "id": "81adad77-a25a-489d-ac43-321115620139", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedAssignmentSchedule.ReadWrite.EntraAppRole" }, { - "description": "Allows the app to read your organization's threat submissions and threat submission policies on behalf of the signed-in user.", - "displayName": "Read all threat submissions", - "id": "7083913a-4966-44b6-9886-c5822a5fd910", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your organization's threat submissions and threat submission policies on your behalf.", - "userConsentDisplayName": "Read all threat submissions", - "value": "ThreatSubmission.Read.All" + "description": "Delete time-based assignment schedules for access to Azure AD groups, without a signed-in user.", + "displayName": "Delete assignment schedules for access to Azure AD groups", + "id": "55d1104b-3821-413d-b3ca-e2393d333cd3", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedAssignmentSchedule.Remove.AzureADGroup" }, { - "description": "Allows the app to read learning content in the organization's directory, on behalf of the signed-in user.", - "displayName": "Read learning content", - "id": "ea4c1fd9-6a9f-4432-8e5d-86e06cc0da77", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read learning content in the organization's directory, on your behalf.", - "userConsentDisplayName": "Read learning content", - "value": "LearningContent.Read.All" + "description": "Allows the app to read time-based eligibility schedules for access to Azure AD groups, without a signed-in user.", + "displayName": "Read eligibility schedules for access to Azure AD groups", + "id": "edb419d6-7edc-42a3-9345-509bfdf5d87c", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedEligibilitySchedule.Read.AzureADGroup" }, { - "description": "Allows the app to read data for the learning provider in the organization's directory, on behalf of the signed-in user.", - "displayName": "Read learning provider", - "id": "dd8ce36f-9245-45ea-a99e-8ac398c22861", - "Origin": "Delegated", - "userConsentDescription": "Allows\u00a0the\u00a0app\u00a0to\u00a0read\u00a0data\u00a0for\u00a0the learning\u00a0provider\u00a0in\u00a0the organization's\u00a0directory, on your behalf.", - "userConsentDisplayName": "Read learning provider", - "value": "LearningProvider.Read" + "description": "Allows the app to read time-based eligibility schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, without a signed-in user.", + "displayName": "Read eligibility schedules for app permission grants and app role assignments", + "id": "d2ab45a0-ed46-4f7f-806a-0f1146144d5a", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedEligibilitySchedule.Read.EntraAppRole" }, { - "description": "Allows the app to create, update, list, read and delete all workflows, tasks and related lifecycle workflows resources on behalf of the signed-in user.", - "displayName": "Read and write all lifecycle workflows resources", - "id": "84b9d731-7db8-4454-8c90-fd9e95350179", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to create, update, list, read and delete all workflows, tasks and related lifecycle workflows resources on your behalf.", - "userConsentDisplayName": "Read and write all lifecycle workflows resources", - "value": "LifecycleWorkflows.ReadWrite.All" + "description": "Allows the app to read, create, and delete time-based eligibility schedules for access to Azure AD groups, without a signed-in user.", + "displayName": "Read, create, and delete eligibility schedules for access to Azure AD groups", + "id": "618b6020-bca8-4de6-99f6-ef445fa4d857", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedEligibilitySchedule.ReadWrite.AzureADGroup" }, { - "description": "Allows an app to read all bookmarks that the signed-in user can access.", - "displayName": "Read all bookmarks that the user can access", - "id": "98b17b35-f3b1-4849-a85f-9f13733002f0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all bookmarks you can access.", - "userConsentDisplayName": "Read all bookmarks that you have access to", - "value": "Bookmark.Read.All" + "description": "Allows the app to read, create, and delete time-based eligibility schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, without a signed-in user.", + "displayName": "Read, create, and delete eligibility schedules for app permission grants and app role assignments", + "id": "7f4c39f1-1aa7-44b7-ab05-38df2609c37a", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedEligibilitySchedule.ReadWrite.EntraAppRole" }, { - "description": "Allows the application to read and change the tenant-level settings of SharePoint and OneDrive on behalf of the signed-in user.", - "displayName": "Read and change SharePoint and OneDrive tenant settings", - "id": "aa07f155-3612-49b8-a147-6c590df35536", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read and change the tenant-level settings of SharePoint and OneDrive on your behalf.", - "userConsentDisplayName": "Read and change SharePoint and OneDrive tenant settings", - "value": "SharePointTenantSettings.ReadWrite.All" + "description": "Delete time-based eligibility schedules for access to Azure AD groups, without a signed-in user.", + "displayName": "Delete eligibility schedules for access to Azure AD groups", + "id": "55745561-7572-4314-a737-a2c2a1b0dd2e", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedEligibilitySchedule.Remove.AzureADGroup" }, { - "description": "Allows the app to read or write your organization's authentication event listeners on behalf of the signed-in user.", - "displayName": "Read and write your organization's authentication event listeners", - "id": "d11625a6-fe21-4fc6-8d3d-063eba5525ad", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read or write your organization's authentication event listeners on your behalf.", - "userConsentDisplayName": "Read and write your organization's authentication event listeners", - "value": "EventListener.ReadWrite.All" + "description": "Allows the app to read all profile photos of users and groups, without a signed-in user", + "displayName": "Read profile photo of a user or group", + "id": "e24d31aa-e1ab-4c80-85fe-23018690335d", + "origin": "Application (Microsoft Graph)", + "value": "ProfilePhoto.Read.All" }, { - "description": "Allows the app to read and write the Teams app settings on behalf of the signed-in user.", - "displayName": "Read and write Teams app settings", - "id": "87c556f0-2bd9-4eed-bd74-5dd8af6eaf7e", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write the Teams app settings on your behalf.", - "userConsentDisplayName": "Read and write Teams app settings", - "value": "TeamworkAppSettings.ReadWrite.All" + "description": "Allows the app to read and write all profile photos of users and groups, without a signed-in user", + "displayName": "Read and write profile photo of a user or group", + "id": "27baa7f6-5dfb-4ba8-b1d3-1e812c143013", + "origin": "Application (Microsoft Graph)", + "value": "ProfilePhoto.ReadWrite.All" }, { - "description": "Allows the app to read all authentication context information in your organization on behalf of the signed-in user.", - "displayName": "Read all authentication context information", - "id": "57b030f1-8c35-469c-b0d9-e4a077debe70", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all authentication context information in your organization on your behalf.", - "userConsentDisplayName": "Read all authentication context information", - "value": "AuthenticationContext.Read.All" + "description": "Allows the app to read programs and program controls in the organization, without a signed-in user.", + "displayName": "Read all programs", + "id": "eedb7fdd-7539-4345-a38b-4839e4a84cbd", + "origin": "Application (Microsoft Graph)", + "value": "ProgramControl.Read.All" }, { - "description": "Allows the app to read and update all authentication context information in your organization on behalf of the signed-in user.", - "displayName": "Read and write all authentication context information", - "id": "ba6d575a-1344-4516-b777-1404f5593057", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and update all authentication context information in your organization on your behalf.", - "userConsentDisplayName": "Read and write all authentication context information", - "value": "AuthenticationContext.ReadWrite.All" + "description": "Allows the app to read, update, delete and perform actions on programs and program controls in the organization, without a signed-in user.", + "displayName": "Manage all programs", + "id": "60a901ed-09f7-4aa5-a16e-7dd3d6f9de36", + "origin": "Application (Microsoft Graph)", + "value": "ProgramControl.ReadWrite.All" }, { - "description": "Allows the app to read and update admin report settings, such as whether to display concealed information in reports, on behalf of the signed-in user.", - "displayName": "Read and write admin report settings", - "id": "b955410e-7715-4a88-a940-dfd551018df3", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and update admin report settings, such as whether to display concealed information in reports, on your behalf.", - "userConsentDisplayName": "Read and write admin report settings", - "value": "ReportSettings.ReadWrite.All" + "description": "Allows the app to identify Purview data protection, compliance and governance policy scopes defined for all users across tenant.", + "displayName": "Compute Purview policies at tenant scope", + "id": "e5a76501-dbb0-492c-ab55-5d09e8837263", + "origin": "Application (Microsoft Graph)", + "value": "ProtectionScopes.Compute.All" }, { - "description": "Allows the app to list and read all workflows, tasks and related lifecycle workflows resources on behalf of the signed-in user.", - "displayName": "Read all lifecycle workflows resources", - "id": "9bcb9916-765a-42af-bf77-02282e26b01a", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to list and read all workflows, tasks and related lifecycle workflows resources on your behalf.", - "userConsentDisplayName": "Read all lifecycle workflows resources", - "value": "LifecycleWorkflows.Read.All" + "description": "Allows the app to identify Purview data protection, compliance and governance policy scopes defined for an individual user.", + "displayName": "Compute Purview policies for an individual user", + "id": "fe696d63-5e1f-4515-8232-cccc316903c6", + "origin": "Application (Microsoft Graph)", + "value": "ProtectionScopes.Compute.User" }, { - "description": "Allows the application to list and query any shared user profile information associated with the current tenant on behalf of the signed-in user.\u00a0 It also permits the application to export external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant on behalf of the signed-in user.", - "displayName": "Read all shared cross-tenant user profiles and export their data", - "id": "759dcd16-3c90-463c-937e-abf89f991c18", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to list and query any shared user profile information associated with the current tenant on your behalf.\u00a0 It also permits the application to export external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant on your behalf.", - "userConsentDisplayName": "Read any shared cross-tenant user profiles and export data", - "value": "CrossTenantUserProfileSharing.Read.All" + "description": "Allows the app to read Privileged Access (PIM) custom extensions for your organization, without a signed-in user.", + "displayName": "Read Privileged Access (PIM) custom extensions", + "id": "e7ebe2d9-6e26-487a-8286-191d623a6904", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedAccess-CustomExt.Read.All" }, { - "description": "Allows the application to read the tenant-level settings in SharePoint and OneDrive on behalf of the signed-in user.", - "displayName": "Read SharePoint and OneDrive tenant settings", - "id": "2ef70e10-5bfd-4ede-a5f6-67720500b258", - "Origin": "Delegated", - "userConsentDescription": "Allows the application to read the tenant-level settings in SharePoint and OneDrive on your behalf.", - "userConsentDisplayName": "Read SharePoint and OneDrive tenant settings", - "value": "SharePointTenantSettings.Read.All" + "description": "Allows the app to request and manage time-based assignment and just-in-time elevation of Azure resources (like your subscriptions, resource groups, storage, compute) in your organization, without a signed-in user.", + "displayName": "Read and write privileged access to Azure resources", + "id": "6f9d5abc-2db6-400b-a267-7de22a40fb87", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedAccess.ReadWrite.AzureResources" }, { - "description": "Allows the app to read or write your organization's custom authentication extensions on behalf of the signed-in user.", - "displayName": "Read and write your organization's custom authentication extensions", - "id": "8dfcf82f-15d0-43b3-bc78-a958a13a5792", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read or write your organization's custom authentication extensions on your behalf.", - "userConsentDisplayName": "Read and write your organization's custom authentication extensions", - "value": "CustomAuthenticationExtension.ReadWrite.All" + "description": "Allows the app to request and manage time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups in your organization, without a signed-in user.", + "displayName": "Read and write privileged access to Azure AD groups", + "id": "2f6817f8-7b12-4f0f-bc18-eeaf60705a9e", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedAccess.ReadWrite.AzureADGroup" }, { - "description": "Allows an app to manage license assignments for users and groups, on behalf of the signed-in user.", - "displayName": "Manage all license assignments", - "id": "f55016cc-149c-447e-8f21-7cf3ec1d6350", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to manage all license assignments, on your behalf.", - "userConsentDisplayName": "Manage all license assignments", - "value": "LicenseAssignment.ReadWrite.All" + "description": "Allows the app to request and manage time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD built-in and custom administrative roles in your organization, without a signed-in user.", + "displayName": "Read and write privileged access to Azure AD roles", + "id": "854d9ab1-6657-4ec8-be45-823027bcd009", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedAccess.ReadWrite.AzureAD" }, { - "description": "Allows an app to read all acronyms that the signed-in user can access.", - "displayName": "Read all acronyms that the user can access", - "id": "9084c10f-a2d6-4713-8732-348def50fe02", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all acronyms you can access.", - "userConsentDisplayName": "Read all acronyms that you have access to", - "value": "Acronym.Read.All" + "description": "Allows the application to read and update the organization's recovery policy without a signed-in user.", + "displayName": "Read and write your organization's recovery policy", + "id": "795fc94d-3deb-4632-b1eb-e6d1a5f44918", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.Recovery" }, { - "description": "Allows the app to read your organization's custom authentication extensions on behalf of the signed-in user.", - "displayName": "Read your oganization's custom authentication extensions", - "id": "b2052569-c98c-4f36-a5fb-43e5c111e6d0", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your organization's custom authentication extensions on your behalf.", - "userConsentDisplayName": "Read your organization's custom authentication extensions", - "value": "CustomAuthenticationExtension.Read.All" + "description": "Allows the app to read and write your organization's security defaults policy, without a signed-in user.", + "displayName": "Read and write your organization's security defaults policy", + "id": "1c6e93a6-28e2-4cbb-9f64-1a46a821124d", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.SecurityDefaults" }, { - "description": "Allows the app to read all transcripts of online meetings, on behalf of the signed-in user.", - "displayName": "Read all transcripts of online meetings. ", - "id": "30b87d18-ebb1-45db-97f8-82ccb1f0190c", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read all transcripts of online meetings, on your behalf.", - "userConsentDisplayName": "Read all transcripts of online meetings.", - "value": "OnlineMeetingTranscript.Read.All" + "description": "Allows the app to read and write your organization's trust framework policies without a signed in user.", + "displayName": "Read and write your organization's trust framework policies", + "id": "79a677f7-b79d-40d0-a36a-3e6f8688dd7a", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.TrustFramework" }, { - "description": "Allows the app to read and write channel messages, on behalf of the signed-in user. This doesn't allow the app to edit the policyViolation of a channel message.", - "displayName": "Read and write user channel messages", - "id": "5922d31f-46c8-4404-9eaf-2117e390a8a4", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write channel messages, on your behalf. This doesn't allow the app to edit the policyViolation of a channel message.", - "userConsentDisplayName": "Read and write user channel messages", - "value": "ChannelMessage.ReadWrite" + "description": "Allows the app to read preauthorization grants for service principals without a signed-in user.", + "displayName": "Read all preauthorization grants", + "id": "66ae8ecc-328f-47f6-97ca-4d9e952df081", + "origin": "Application (Microsoft Graph)", + "value": "PreAuthorizationGrant.Read.All" }, { - "description": "Read Threat and Vulnerability Management vulnerability information", - "displayName": "Allows the app to read any Threat and Vulnerability Management vulnerability information", - "id": "63a677ce-818c-4409-9d12-5c6d2e2a6bfe", - "Origin": "Application (WindowsDefenderATP)", - "userConsentDescription": "Allows the app to read any Threat and Vulnerability Management vulnerability information", - "userConsentDisplayName": "Allows the app to read any Threat and Vulnerability Management vulnerability information", - "value": "Vulnerability.Read.All" + "description": "Allows the app to read presence information of all users in the directory without a signed-in user. Presence information includes activity, availability, status note, calendar out-of-office message, timezone and location.", + "displayName": "Read presence information for all users", + "id": "a70e0c2d-e793-494c-94c4-118fa0a67f42", + "origin": "Application (Microsoft Graph)", + "value": "Presence.Read.All" }, { - "description": "Allows the app to read Threat and Vulnerability Management vulnerability information on behalf of the signed-in user", - "displayName": "Read Threat and Vulnerability Management vulnerability information", - "id": "41269fc5-d04d-4bfd-bce7-43a51cea049a", - "Origin": "Delegated (WindowsDefenderATP)", - "userConsentDescription": "Allows the app to read Threat and Vulnerability Management vulnerability information on behalf of the signed-in user", - "userConsentDisplayName": "Read Threat and Vulnerability Management vulnerability information", - "value": "Vulnerability.Read" + "description": "Allows the app to read all presence information and write activity and availability of all users in the directory without a signed-in user. Presence information includes activity, availability, status note, calendar out-of-office message, time zone and location.", + "displayName": "Read and write presence information for all users", + "id": "83cded22-8297-4ff6-a7fa-e97e9545a259", + "origin": "Application (Microsoft Graph)", + "value": "Presence.ReadWrite.All" }, { - "description": "Allows the app to manage Exchange Online", - "displayName": "Manage Exchange online", - "id": "ab4f2b77-0b06-4fc1-a9de-02113fc2ab7c", - "Origin": "Delegated (Office 365 Exchange Online)", - "userConsentDescription": "Allows the app to read Threat and Vulnerability Management vulnerability information on behalf of the signed-in user", - "userConsentDisplayName": "Read Threat and Vulnerability Management vulnerability information", - "value": "Exchange.Manage" + "description": "Allows the application to read printers without a signed-in user. ", + "displayName": "Read printers", + "id": "9709bb33-4549-49d4-8ed9-a8f65e45bb0f", + "origin": "Application (Microsoft Graph)", + "value": "Printer.Read.All" }, { - "description": "Allows the app to create, read, update and delete events in all calendars in the organization user has permissions to access. This includes delegate and shared calendars", - "displayName": "Read and write user and shared calendars", - "id": "bbd1ca91-75e0-4814-ad94-9c5dbbae3415", - "Origin": "Delegated (Office 365 Exchange Online)", - "userConsentDescription": "Allows the app to read, update, create and delete events in all calendars in your organization you have permissions to access. This includes delegate and shared calendars", - "userConsentDisplayName": "Read and write to your and shared calendars", - "value": "Calendars.ReadWrite.All" + "description": "Allows the application to read and update printers without a signed-in user. Does not allow creating (registering) or deleting (unregistering) printers.", + "displayName": "Read and update printers", + "id": "f5b3f73d-6247-44df-a74c-866173fddab0", + "origin": "Application (Microsoft Graph)", + "value": "Printer.ReadWrite.All" }, { - "description": "Allows the app to create, read, update, and delete user's mailbox settings. Does not include permission to send mail.", - "displayName": "Read and write user mailbox settings", - "id": "2e83d72d-8895-4b66-9eea-abb43449ab8b", - "Origin": "Delegated (Office 365 Exchange Online)", - "userConsentDescription": "Allows the app to read, update, create, and delete your mailbox settings.", - "userConsentDisplayName": "Read and write to your mailbox settings", - "value": "MailboxSettings.ReadWrite" + "description": "Allows the application to read certificate-based authentication configuration such as all public key infrastructures (PKI) and certificate authorities (CA) configured for the organization, without a signed-in user.", + "displayName": "Read all certificate based authentication configurations", + "id": "214fda0c-514a-4650-b037-b562b1a66124", + "origin": "Application (Microsoft Graph)", + "value": "PublicKeyInfrastructure.Read.All" }, { - "description": "Allows the app to have full control of all site collections on behalf of the signed-in user.", - "displayName": "Manage SharePoint Online", - "id": "56680e0d-d2a3-4ae1-80d8-3c4f2100e3d0", - "Origin": "Delegated (Office 365 SharePoint Online)", - "userConsentDescription": "Have full control of all site collections", - "userConsentDisplayName": "Allows the app to have full control of all site collections on your behalf.", - "value": "AllSites.FullControl" + "description": "Allows the application to perform advanced operations like redirecting a print job to another printer without a signed-in user. Also allows the application to read and update the metadata of print jobs.", + "displayName": "Perform advanced operations on print jobs", + "id": "58a52f47-9e36-4b17-9ebe-ce4ef7f3e6c8", + "origin": "Application (Microsoft Graph)", + "value": "PrintJob.Manage.All" }, { - "description": "Allows to read the LAPS passwords.", - "displayName": "Manage LAPS passwords", - "id": "280b3b69-0437-44b1-bc20-3b2fca1ee3e9", - "Origin": "Delegated", - "userConsentDescription": "Allows to read the LAPS passwords.", - "userConsentDisplayName": "Manage LAPS passwords", - "value": "DeviceLocalCredential.Read.All" + "description": "Allows the application to read the metadata of print jobs without a signed-in user. Does not allow access to print job document content.", + "displayName": "Read basic information for print jobs", + "id": "fbf67eee-e074-4ef7-b965-ab5ce1c1f689", + "origin": "Application (Microsoft Graph)", + "value": "PrintJob.ReadBasic.All" }, { - "description": "Access Microsoft Teams and Skype for Business data as the signed in user", - "displayName": "Access Microsoft Teams and Skype for Business data based on the user's role membership", - "id": "e60370c1-e451-437e-aa6e-d76df38e5f15", - "Origin": "Delegated (Skype and Teams Tenant Admin API)", - "userConsentDescription": "Access Microsoft Teams and Skype for Business data as the signed in user", - "userConsentDisplayName": "Access Microsoft Teams and Skype for Business data based on the user's role membership", - "value": "user_impersonation" + "description": "Allows the application to read and update the metadata and document content of print jobs without a signed-in user.", + "displayName": "Read and write print jobs", + "id": "5114b07b-2898-4de7-a541-53b0004e2e13", + "origin": "Application (Microsoft Graph)", + "value": "PrintJob.ReadWrite.All" }, { - "description": "Read and write all on-premises directory synchronization information", - "displayName": "Read and write all on-premises directory synchronization information", - "id": "c2d95988-7604-4ba1-aaed-38a5f82a51c7", - "Origin": "Delegated", - "userConsentDescription": "Access Microsoft Teams and Skype for Business data as the signed in user", - "userConsentDisplayName": "Access Microsoft Teams and Skype for Business data based on the user's role membership", - "value": "OnPremDirectorySynchronization.ReadWrite.All" + "description": "Allows the application to read and update the metadata of print jobs without a signed-in user. Does not allow access to print job document content.", + "displayName": "Read and write basic information for print jobs", + "id": "57878358-37f4-4d3a-8c20-4816e0d457b1", + "origin": "Application (Microsoft Graph)", + "value": "PrintJob.ReadWriteBasic.All" }, { - "description": "Read and Modify Tenant-Acquired Telephone Number Details", - "displayName": "Read and Modify Tenant-Acquired Telephone Number Details", - "id": "424b07a8-1209-4d17-9fe4-9018a93a1024", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and modify your tenant's acquired telephone number details on behalf of the signed-in admin user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", - "userConsentDisplayName": "Allows the app to read and modify your tenant's acquired telephone number details on behalf of the signed-in admin user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", - "value": "TeamsTelephoneNumber.ReadWrite.All" + "description": "Allows the application to read tenant-wide print settings without a signed-in user.", + "displayName": "Read tenant-wide print settings", + "id": "b5991872-94cf-4652-9765-29535087c6d8", + "origin": "Application (Microsoft Graph)", + "value": "PrintSettings.Read.All" }, { - "description": "Read Teams user configurations", - "displayName": "Read Teams user configurations", - "id": "5c469ce4-dab5-4afd-b9de-14f1ba4004a7", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read your tenant's user configurations on behalf of the signed-in admin user. User configuration may include attributes related to user, such as telephone number, assigned policies, etc.", - "userConsentDisplayName": "Read Teams user configurations", - "value": "TeamsUserConfiguration.Read.All" + "description": "Allows the application to read and update print task definitions without a signed-in user. ", + "displayName": "Read, write and update print task definitions", + "id": "456b71a7-0ee0-4588-9842-c123fcc8f664", + "origin": "Application (Microsoft Graph)", + "value": "PrintTaskDefinition.ReadWrite.All" }, { - "description": "Read and Modify Tenant-Acquired Telephone Number Details", - "displayName": "Read and Modify Tenant-Acquired Telephone Number Details", - "id": "0a42382f-155c-4eb1-9bdc-21548ccaa387", - "Origin": "Application", - "userConsentDescription": "Allows the app to read your tenant's acquired telephone number details, without a signed-in user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", - "userConsentDisplayName": "Allows the app to read your tenant's acquired telephone number details, without a signed-in user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", - "value": "TeamsTelephoneNumber.ReadWrite.All" + "description": "Allows the app to read time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD built-in and custom administrative roles in your organization, without a signed-in user.", + "displayName": "Read privileged access to Azure AD roles", + "id": "4cdc2547-9148-4295-8d11-be0db1391d6b", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedAccess.Read.AzureAD" }, { - "description": "Read Teams user configurations", - "displayName": "Read Teams user configurations", - "id": "a91eadaf-2c3c-4362-908b-fb172d208fc6", - "Origin": "Application", - "userConsentDescription": "Allows the app to read your tenant's user configurations, without a signed-in user. User configuration may include attributes related to user, such as telephone number, assigned policies, etc.", - "userConsentDisplayName": "Read Teams user configurations", - "value": "TeamsUserConfiguration.Read.All" + "description": "Allows the app to read time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups in your organization, without a signed-in user.", + "displayName": "Read privileged access to Azure AD groups", + "id": "01e37dc9-c035-40bd-b438-b2879c4870a6", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedAccess.Read.AzureADGroup" }, { - "description": "Allows the app to read and write Copilot policy settings for the organization, on behalf of the signed-in user.", - "displayName": "Read and write Copilot policy settings", - "id": "e2edbde8-4448-4e49-8ebb-d53ba72df0f3", - "Origin": "Delegated", - "userConsentDescription": "Allows the app to read and write Copilot policy settings for the organization, on your behalf.", - "userConsentDisplayName": "Read and write Copilot policy settings", - "value": "CopilotPolicySettings.ReadWrite" + "description": "Allows the app to read time-based assignment and just-in-time elevation of user privileges to audit Azure resources in your organization, without a signed-in user.", + "displayName": "Read privileged access to Azure resources", + "id": "5df6fe86-1be0-44eb-b916-7bd443a71236", + "origin": "Application (Microsoft Graph)", + "value": "PrivilegedAccess.Read.AzureResources" }, { - "description": "Allows the app to read and write Copilot policy settings for the organization, without a signed-in user.", - "displayName": "Read and write Copilot policy settings", - "id": "cc147c17-b8e8-4d3f-9f94-aa9e279a079a", - "Origin": "Application", - "userConsentDescription": "Allows the app to read and write Copilot policy settings for the organization, without a signed-in user.", - "userConsentDisplayName": "Read and write Copilot policy settings", - "value": "CopilotPolicySettings.ReadWrite" + "description": "Allows the application to read the metadata and document content of print jobs without a signed-in user. ", + "displayName": "Read print jobs", + "id": "ac6f956c-edea-44e4-bd06-64b1b4b9aec9", + "origin": "Application (Microsoft Graph)", + "value": "PrintJob.Read.All" + }, + { + "description": "Access Microsoft Teams and Skype for Business data as the signed in user", + "displayName": "Access Microsoft Teams and Skype for Business data based on the user's role membership", + "id": "e60370c1-e451-437e-aa6e-d76df38e5f15", + "origin": "Delegated (Skype and Teams Tenant Admin API)", + "value": "user_impersonation" } ] diff --git a/Config/SAMManifest.json b/Config/SAMManifest.json index e9d5640e8f554..b4ddb1320508b 100644 --- a/Config/SAMManifest.json +++ b/Config/SAMManifest.json @@ -23,6 +23,10 @@ { "resourceAppId": "00000003-0000-0000-c000-000000000000", "resourceAccess": [ + { + "id": "89b20d8a-76e2-4057-867b-9961f800b9a4", + "type": "Role" + }, { "id": "ed31732f-9495-47ed-ba3b-4ed0948c1c64", "type": "Role" @@ -707,6 +711,10 @@ { "id": "678536fe-1083-478a-9c59-b99265e6b0d3", "type": "Role" + }, + { + "id": "741f803b-c850-494e-b5df-cde7c675a1ca", + "type": "Role" } ] }, diff --git a/Config/openapi-overrides/ListOffboardingProgress.json b/Config/openapi-overrides/ListOffboardingProgress.json new file mode 100644 index 0000000000000..83b9d293f2071 --- /dev/null +++ b/Config/openapi-overrides/ListOffboardingProgress.json @@ -0,0 +1,3 @@ +{ + "method": "get" +} diff --git a/Config/openapi.json b/Config/openapi.json index 34c1d1df1d008..4bc57c7d41509 100644 --- a/Config/openapi.json +++ b/Config/openapi.json @@ -279,6 +279,14 @@ "logbook": { "$ref": "#/components/schemas/LabelValue" }, + "PsaTicketPriority": { + "allOf": [ + { + "$ref": "#/components/schemas/LabelValue" + } + ], + "description": "The audit form posts the raw form values, so an autocomplete selection arrives as a {label, value} object - unwrap it to the bare Halo priority id before storing." + }, "RowKey": { "type": "string" }, @@ -2178,6 +2186,87 @@ "x-cipp-role": "Tenant.Administration.ReadWrite" } }, + "/api/AddEdgeApp": { + "post": { + "summary": "AddEdgeApp", + "operationId": "AddEdgeApp", + "tags": [ + "Endpoint > Applications" + ], + "requestBody": { + "required": false, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "AssignTo": { + "type": "string" + }, + "CustomGroup": { + "type": "string" + }, + "displayLanguageLocale": { + "$ref": "#/components/schemas/LabelValue" + }, + "edgeChannel": { + "$ref": "#/components/schemas/LabelValue" + }, + "excludeGroup": { + "type": "string" + }, + "IntuneBody": { + "type": "string" + }, + "selectedTenants": { + "type": "array", + "items": { + "type": "object", + "properties": { + "customerId": { + "type": "string" + } + } + } + } + }, + "additionalProperties": true, + "x-cipp-passthrough": true, + "description": "This endpoint forwards the request body onward rather than reading a fixed set of fields. The properties listed here are the ones it is known to read; others may be accepted." + } + } + } + }, + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Endpoint.Application.ReadWrite", + "x-cipp-any-tenant": true, + "x-cipp-reads-via": [ + "Get-CIPPEdgeAppBody" + ] + } + }, "/api/AddEditTransportRule": { "post": { "summary": "AddEditTransportRule", @@ -3344,7 +3433,7 @@ "Email-Exchange > Transport" ], "requestBody": { - "required": false, + "required": true, "content": { "application/json": { "schema": { @@ -3354,9 +3443,13 @@ "type": "string" }, "name": { - "type": "string" + "type": "string", + "description": "Posted from the row action; without a name the template lists blank." } }, + "required": [ + "name" + ], "additionalProperties": true, "x-cipp-passthrough": true, "description": "This endpoint forwards the request body onward rather than reading a fixed set of fields. The properties listed here are the ones it is known to read; others may be accepted." @@ -4387,6 +4480,64 @@ "x-cipp-role": "Identity.Role.ReadWrite" } }, + "/api/AddJITRoleTemplate": { + "post": { + "summary": "AddJITRoleTemplate", + "operationId": "AddJITRoleTemplate", + "tags": [ + "Identity > Administration > Users" + ], + "description": "Creates a JIT Role Template - a named allow-list of directory roles that can be assigned to a\nCIPP custom role to restrict which roles that role's members may grant via JIT Admin.", + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "roles": { + "type": "string" + }, + "templateName": { + "type": "string" + } + }, + "required": [ + "templateName" + ] + } + } + } + }, + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Identity.Role.ReadWrite" + } + }, "/api/AddMSPApp": { "post": { "summary": "AddMSPApp", @@ -4690,82 +4841,64 @@ ] } }, - "/api/AddPolicy": { + "/api/AddPIMRoleSettingsTemplate": { "post": { - "summary": "AddPolicy", - "operationId": "AddPolicy", + "summary": "Create or update a PIM role settings template.", + "operationId": "AddPIMRoleSettingsTemplate", "tags": [ - "Endpoint > MEM" + "Identity > Administration > Roles" ], + "description": "Saves a Privileged Identity Management role settings template. The settings are validated against CIPP's secure floor (activation must expire within 24 hours and require MFA or an authentication context plus a justification; eligibilities and active assignments must expire within a year; active assignments must require a justification). A template below the floor is rejected with the list of problems rather than silently adjusted. Pass GUID to update an existing template. Pass captureRoleId with a tenantFilter to build the settings from that role's current PIM policy in the tenant instead of supplying them: values below the secure floor are raised to the closest value the floor allows and every raise is reported in the results.", "requestBody": { - "required": true, + "required": false, "content": { "application/json": { "schema": { "type": "object", "properties": { - "assignmentFilter": { - "type": "string" - }, - "AssignmentFilterName": { - "type": "string" - }, - "AssignmentFilterType": { - "type": "string" - }, - "AssignTo": { - "type": "string" - }, - "customGroup": { - "type": "string" - }, - "Description": { - "type": "string" + "captureRoleId": { + "allOf": [ + { + "$ref": "#/components/schemas/LabelValue" + } + ], + "description": "Capture mode: build the settings from a role's current PIM policy in a tenant." }, - "displayName": { + "captureRoleName": { "type": "string" }, - "excludeGroup": { - "type": "string" - }, - "RAWJson": { + "description": { "type": "string" }, - "replacemap": { - "type": "string" + "GUID": { + "type": "string", + "description": "Existing template GUID when editing." }, - "ReusableSettings": { + "roles": { "type": "array", "items": { - "type": "string" - } - }, - "TemplateGuid": { - "type": "string", - "description": "The deploy drawer and wizard send the chosen row's GUID as TemplateList.value, not as TemplateID. Template display names are not unique - re-imports create same-named twins - so resolving by display name below can land on a different row than the one the user picked. The selected RowKey must win whenever the request carries one. String rather than Guid: built-in templates are stored with their filename as RowKey." - }, - "TemplateID": { - "type": "string", - "description": "The deploy drawer and wizard send the chosen row's GUID as TemplateList.value, not as TemplateID. Template display names are not unique - re-imports create same-named twins - so resolving by display name below can land on a different row than the one the user picked. The selected RowKey must win whenever the request carries one. String rather than Guid: built-in templates are stored with their filename as RowKey." + "$ref": "#/components/schemas/LabelValue" + }, + "description": "Roles (label/value pairs of role template ids) when roleScope is Custom." }, - "TemplateList": { + "roleScope": { "allOf": [ { "$ref": "#/components/schemas/LabelValue" } ], - "description": "The deploy drawer and wizard send the chosen row's GUID as TemplateList.value, not as TemplateID. Template display names are not unique - re-imports create same-named twins - so resolving by display name below can land on a different row than the one the user picked. The selected RowKey must win whenever the request carries one. String rather than Guid: built-in templates are stored with their filename as RowKey." + "description": "PrivilegedRoles | AllRoles | Custom" }, - "TemplateType": { + "settings": { + "type": "string" + }, + "templateName": { "type": "string" }, "tenantFilter": { "$ref": "#/components/schemas/LabelValue" } - }, - "required": [ - "tenantFilter" - ] + } } } } @@ -4781,6 +4914,9 @@ } } }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, "401": { "description": "Unauthorized - invalid or missing bearer token" }, @@ -4793,51 +4929,158 @@ "bearerAuth": [] } ], - "x-cipp-role": "Endpoint.MEM.ReadWrite" + "x-cipp-role": "Identity.Role.ReadWrite", + "x-cipp-any-tenant": true } }, - "/api/AddQuarantinePolicy": { + "/api/AddPolicy": { "post": { - "summary": "AddQuarantinePolicy", - "operationId": "AddQuarantinePolicy", + "summary": "AddPolicy", + "operationId": "AddPolicy", "tags": [ - "Email-Exchange > Spamfilter" + "Endpoint > MEM" ], "requestBody": { - "required": false, + "required": true, "content": { "application/json": { "schema": { "type": "object", "properties": { - "AllowSender": { + "assignmentFilter": { "type": "string" }, - "BlockSender": { + "AssignmentFilterName": { "type": "string" }, - "Delete": { + "AssignmentFilterType": { "type": "string" }, - "IncludeMessagesFromBlockedSenderAddress": { + "AssignTo": { "type": "string" }, - "Name": { + "customGroup": { "type": "string" }, - "Preview": { + "Description": { "type": "string" }, - "QuarantineNotification": { + "displayName": { "type": "string" }, - "ReleaseActionPreference": { - "$ref": "#/components/schemas/LabelValue" + "excludeGroup": { + "type": "string" }, - "selectedTenants": { + "RAWJson": { + "type": "string" + }, + "replacemap": { + "type": "string" + }, + "ReusableSettings": { + "type": "array", + "items": { + "type": "string" + } + }, + "TemplateGuid": { + "type": "string", + "description": "The deploy drawer and wizard send the chosen row's GUID as TemplateList.value, not as TemplateID. Template display names are not unique - re-imports create same-named twins - so resolving by display name below can land on a different row than the one the user picked. The selected RowKey must win whenever the request carries one. String rather than Guid: built-in templates are stored with their filename as RowKey." + }, + "TemplateID": { + "type": "string", + "description": "The deploy drawer and wizard send the chosen row's GUID as TemplateList.value, not as TemplateID. Template display names are not unique - re-imports create same-named twins - so resolving by display name below can land on a different row than the one the user picked. The selected RowKey must win whenever the request carries one. String rather than Guid: built-in templates are stored with their filename as RowKey." + }, + "TemplateList": { + "allOf": [ + { + "$ref": "#/components/schemas/LabelValue" + } + ], + "description": "The deploy drawer and wizard send the chosen row's GUID as TemplateList.value, not as TemplateID. Template display names are not unique - re-imports create same-named twins - so resolving by display name below can land on a different row than the one the user picked. The selected RowKey must win whenever the request carries one. String rather than Guid: built-in templates are stored with their filename as RowKey." + }, + "TemplateType": { "type": "string" + }, + "tenantFilter": { + "$ref": "#/components/schemas/LabelValue" } - } + }, + "required": [ + "tenantFilter" + ] + } + } + } + }, + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Endpoint.MEM.ReadWrite" + } + }, + "/api/AddQuarantinePolicy": { + "post": { + "summary": "AddQuarantinePolicy", + "operationId": "AddQuarantinePolicy", + "tags": [ + "Email-Exchange > Spamfilter" + ], + "requestBody": { + "required": false, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "AllowSender": { + "type": "string" + }, + "BlockSender": { + "type": "string" + }, + "Delete": { + "type": "string" + }, + "IncludeMessagesFromBlockedSenderAddress": { + "type": "string" + }, + "Name": { + "type": "string" + }, + "Preview": { + "type": "string" + }, + "QuarantineNotification": { + "type": "string" + }, + "ReleaseActionPreference": { + "$ref": "#/components/schemas/LabelValue" + }, + "selectedTenants": { + "type": "string" + } + } } } } @@ -5223,21 +5466,21 @@ }, "Name": { "type": "string", - "description": "Validate required fields" + "description": "Validate required fields. The \"create template from policy\" row action posts the policy row, which carries Name/PolicyName but no TemplateName." }, "PolicyName": { - "type": "string" + "type": "string", + "description": "Set name and comments - prioritize template-specific fields, falling back to the policy name so a template made from a policy is not listed with a blank name." }, "TemplateDescription": { "type": "string" }, "TemplateName": { "type": "string", - "description": "Set name and comments - prioritize template-specific fields" + "description": "Validate required fields. The \"create template from policy\" row action posts the policy row, which carries Name/PolicyName but no TemplateName." } }, "required": [ - "Name", "PolicyName" ] } @@ -5362,6 +5605,7 @@ "tags": [ "Tenant > Administration > Alerts" ], + "description": "Creates or updates a scripted CIPP alert, stored as a hidden scheduled task.\n\nA selection of two or more tenants or groups is stored verbatim and expanded on every run,\nso tenant group membership is always current.", "requestBody": { "required": true, "content": { @@ -5370,16 +5614,15 @@ "type": "object", "properties": { "excludedTenants": { - "type": "string" - }, - "RowKey": { - "type": "string" + "type": "string", + "description": "Tenants or tenant groups to skip even when they fall within the selection above. Optional." }, "tenantFilter": { "type": "array", "items": { "type": "string" - } + }, + "description": "The tenants, tenant groups or *All Tenants the alert applies to. At least one is required." } }, "required": [ @@ -6822,11 +7065,13 @@ "schema": { "type": "object", "properties": { - "name": { - "type": "string" + "Name": { + "type": "string", + "description": "Posted from the row action; without a name the template lists blank and deploys with no parameters." }, "PowerShellCommand": { - "type": "string" + "type": "string", + "description": "Posted from the row action; without a name the template lists blank and deploys with no parameters." } }, "additionalProperties": true, @@ -6944,6 +7189,9 @@ "password": { "type": "string" }, + "perUserMfa": { + "type": "boolean" + }, "postalCode": { "type": "string" }, @@ -6964,6 +7212,9 @@ "PrimDomain": { "$ref": "#/components/schemas/LabelValue" }, + "PsaTicketId": { + "type": "string" + }, "reference": { "type": "string" }, @@ -7250,6 +7501,9 @@ "password": { "type": "string" }, + "perUserMfa": { + "type": "string" + }, "postalCode": { "type": "string" }, @@ -9122,6 +9376,68 @@ "x-cipp-role": "Identity.Role.ReadWrite" } }, + "/api/EditJITRoleTemplate": { + "post": { + "summary": "EditJITRoleTemplate", + "operationId": "EditJITRoleTemplate", + "tags": [ + "Identity > Administration > Users" + ], + "description": "Updates an existing JIT Role Template.", + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "GUID": { + "type": "string" + }, + "roles": { + "type": "string" + }, + "templateName": { + "type": "string" + } + }, + "required": [ + "GUID", + "templateName" + ] + } + } + } + }, + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Identity.Role.ReadWrite" + } + }, "/api/EditMalwareFilter": { "post": { "summary": "EditMalwareFilter", @@ -11399,9 +11715,23 @@ "GroupId": { "type": "string" }, + "Results": { + "type": "string" + }, "roleDefinitionId": { "type": "string" }, + "RoleMappings": { + "type": "array", + "items": { + "type": "object", + "properties": { + "roleDefinitionId": { + "type": "string" + } + } + } + }, "RoleName": { "type": "string" } @@ -11409,7 +11739,8 @@ } }, "templateId": { - "type": "string" + "type": "string", + "description": "Add-CIPPGDAPRoleTemplate already writes customer-visible logs for the template path" } } } @@ -11681,7 +12012,11 @@ } ], "x-cipp-role": "Tenant.Relationship.ReadWrite", - "x-cipp-any-tenant": true + "x-cipp-any-tenant": true, + "x-cipp-reads-via": [ + "Add-CIPPGDAPRoleTemplate", + "New-CIPPGDAPRoleMapping" + ] } }, "/api/ExecAddMultiTenantApp": { @@ -12016,6 +12351,9 @@ }, "403": { "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" } }, "security": [ @@ -13179,7 +13517,7 @@ "tags": [ "CIPP > Settings" ], - "description": "Drives the super-admin \"Custom Domains\" page. All actions operate on the App Service that\nhosts this CIPP instance (Microsoft.Web/sites/$env:WEBSITE_SITE_NAME) using the managed\nidentity via New-CIPPAzRestRequest — the same resource and auth path the Container\nManagement page uses.\n\nActions (passed as Query.Action or Body.Action):\n List - Site metadata (default hostname, inbound IP) plus every hostname\n binding and any App Service Managed Certificate that matches.\n CheckDns - Live DoH lookup of the alias record a custom domain needs. CIPP no\n longer uses domain-verification TXT records, so a leftover\n asuid. record is detected and flagged for removal rather than\n requested. Powers wizard step 1 + resume.\n AddBinding - Create the hostname binding (wizard step 2). Azure re-validates ownership.\n AddCertificate - Create an App Service Managed Certificate and enable the SNI SSL binding\n (wizard step 3). Safe to re-run — reuses an existing cert if present.\n Remove - Delete a custom hostname binding (and its managed cert, best effort).\n\nEvery action is independently re-runnable so the wizard can resume a half-finished domain or\nretry a failed step without redoing the ones that already succeeded.", + "description": "Drives the super-admin \"Custom Domains\" page. All actions operate on the App Service that\nhosts this CIPP instance (Microsoft.Web/sites/$env:WEBSITE_SITE_NAME) using the managed\nidentity via New-CIPPAzRestRequest — the same resource and auth path the Container\nManagement page uses.\n\nActions (passed as Query.Action or Body.Action):\n List - Site metadata (default hostname, inbound IP) plus every hostname\n binding, any App Service Managed Certificate that matches, and the\n state of a certificate job still running in the background.\n CheckDns - Live DoH lookup of the alias record a custom domain needs. CIPP no\n longer uses domain-verification TXT records, so a leftover\n asuid. record is detected and flagged for removal rather than\n requested. Powers wizard step 1 + resume.\n AddBinding - Create the hostname binding (wizard step 2). Azure validates ownership\n through the alias record.\n AddCertificate - Issue an App Service Managed Certificate and enable the SNI SSL binding\n (wizard step 3) via Invoke-CIPPCustomDomainCertificate. Issuance that\n outlives the request carries on as a hidden scheduled task that retries\n every 15 minutes, a few times, then stops.\n Remove - Delete a custom hostname binding (and its managed cert, best effort).\n\nEvery action is independently re-runnable so the wizard can resume a half-finished domain or\nretry a failed step without redoing the ones that already succeeded.", "requestBody": { "required": true, "content": { @@ -13190,6 +13528,10 @@ "Action": { "type": "string" }, + "DnsRecordType": { + "type": "string", + "description": "Which alias record Azure should validate against: the one CheckDns saw resolve (A or CNAME), else the recommended type for this hostname shape." + }, "Hostname": { "type": "string" } @@ -14192,7 +14534,7 @@ "tags": [ "CIPP > Settings" ], - "description": "Returns Azure portal deep links for the CIPP deployment's own infrastructure (resource group, key vault, function app, static web app) plus its subscription, SKU, hosting mode and timezone.", + "description": "Returns Azure portal deep links for the CIPP deployment's own infrastructure (resource group, key vault, the function app or web app, its App Service plan, static web app) plus its subscription, SKU and timezone. Whether the instance is CyberDrain-hosted or CIPP-NG comes from /api/me.", "responses": { "200": { "description": "Success", @@ -15866,6 +16208,70 @@ "x-cipp-role": "CIPP.Core.ReadWrite" } }, + "/api/ExecCIPPDBCacheAdmin": { + "post": { + "summary": "SuperAdmin browse / remove / empty for CIPPDB (CippReportingDB) cache collections.", + "operationId": "ExecCIPPDBCacheAdmin", + "tags": [ + "CIPP > Core" + ], + "description": "Typed alternative to Table Maintenance for the reporting cache. List returns decoded\ncache objects stamped with CIPPPartitionKey / CIPPRowKey / CIPPETag so the UI can\ndelete by storage key. Empty clears an entire type for a tenant (or AllTenants).", + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "Action": { + "type": "string" + }, + "Rows": { + "type": "string" + }, + "TenantFilter": { + "type": "string" + }, + "Type": { + "type": "string" + } + }, + "required": [ + "TenantFilter" + ] + } + } + } + }, + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "CIPP.SuperAdmin.ReadWrite" + } + }, "/api/ExecCippFunction": { "post": { "summary": "Execute a CIPPCore function", @@ -16405,6 +16811,10 @@ "baselineOption": { "type": "string" }, + "certificateAuth": { + "type": "boolean", + "description": "Certificate-auth toggle for an existing install: enabling keeps the client secret as a rollback and switches SAM tokens to the certificate. Idempotent with a certificate-only First Setup." + }, "email": { "type": "string" }, @@ -16464,11 +16874,16 @@ "x-cipp-field-source": "backend" }, "RowKey": { + "type": "string", "x-cipp-field-source": "storage" }, "SASUrl": { "x-cipp-field-source": "storage" }, + "SecretValue": { + "type": "string", + "x-cipp-field-source": "storage" + }, "severity": { "x-cipp-field-source": "backend" }, @@ -16621,50 +17036,50 @@ "type": "string" }, "standardsTemplateId": { - "type": "string", - "description": "Without this the comparison would report the policy as missing while remediation would happily overwrite an existing, similarly named one. Mirrors the candidate selection Set-CIPPIntunePolicy performs at deployment time." - }, - "templateGuid": { "type": "string", "description": "tenantFilter is optional here - supplying it resolves the template the way the standard would for that tenant instead of comparing the stored template verbatim." }, - "tenantFilter": { - "type": "string", - "description": "tenantFilter is optional here - supplying it resolves the template the way the standard would for that tenant instead of comparing the stored template verbatim." - }, - "type": { - "type": "string", - "x-cipp-observed-values": [ - "communityRepo", - "template", - "tenantPolicy", - "tenantPolicyByTemplate" - ] - }, - "urlName": { - "type": "string" - } - } - }, - "sourceB": { - "type": "object", - "properties": { - "branch": { - "type": "string" - }, - "fullName": { - "type": "string" - }, - "path": { - "type": "string" - }, - "policyId": { - "type": "string" - }, - "standardsTemplateId": { - "type": "string", - "description": "Without this the comparison would report the policy as missing while remediation would happily overwrite an existing, similarly named one. Mirrors the candidate selection Set-CIPPIntunePolicy performs at deployment time." - }, + "templateGuid": { + "type": "string", + "description": "tenantFilter is optional here - supplying it resolves the template the way the standard would for that tenant instead of comparing the stored template verbatim." + }, + "tenantFilter": { + "type": "string", + "description": "tenantFilter is optional here - supplying it resolves the template the way the standard would for that tenant instead of comparing the stored template verbatim." + }, + "type": { + "type": "string", + "x-cipp-observed-values": [ + "communityRepo", + "template", + "tenantPolicy", + "tenantPolicyByTemplate" + ] + }, + "urlName": { + "type": "string" + } + } + }, + "sourceB": { + "type": "object", + "properties": { + "branch": { + "type": "string" + }, + "fullName": { + "type": "string" + }, + "path": { + "type": "string" + }, + "policyId": { + "type": "string" + }, + "standardsTemplateId": { + "type": "string", + "description": "tenantFilter is optional here - supplying it resolves the template the way the standard would for that tenant instead of comparing the stored template verbatim." + }, "templateGuid": { "type": "string", "description": "tenantFilter is optional here - supplying it resolves the template the way the standard would for that tenant instead of comparing the stored template verbatim." @@ -17474,6 +17889,10 @@ "access_token": { "type": "string", "description": "Find Existing app registration" + }, + "certificateOnly": { + "type": "boolean", + "description": "A certificate-only setup provisions no client secret. Determined up front so every app management policy call in this flow leaves the password-addition block in force." } } } @@ -17915,6 +18334,9 @@ "Action": { "type": "string" }, + "AllowedRolesTemplate": { + "type": "string" + }, "AllowedTenants": { "type": "string" }, @@ -20087,6 +20509,69 @@ "x-cipp-role": "Exchange.Mailbox.ReadWrite" } }, + "/api/ExecEmptySiteRecycleBin": { + "post": { + "summary": "ExecEmptySiteRecycleBin", + "operationId": "ExecEmptySiteRecycleBin", + "tags": [ + "Teams-Sharepoint" + ], + "description": "Permanently empty a site recycle bin (first stage, second stage, or both).\nItem ids are used only server-side; the response never includes file names.", + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "SiteUrl": { + "type": "string" + }, + "Stage": { + "type": "string" + }, + "tenantFilter": { + "type": "string" + } + }, + "required": [ + "SiteUrl", + "tenantFilter" + ] + } + } + } + }, + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "object", + "description": "Not described statically: this endpoint returns the upstream response as-is, so its fields are determined by the upstream API rather than by CIPP. Call the endpoint to see the actual shape, or add a response schema in backend/Config/openapi-overrides." + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Sharepoint.SiteRecycleBin.ReadWrite" + } + }, "/api/ExecEnableArchive": { "post": { "summary": "ExecEnableArchive", @@ -20721,7 +21206,7 @@ { "name": "TicketType", "in": "query", - "description": "Outcomes and priorities are scoped to a ticket type. The settings page sends the ticket type currently selected in the form so the lists follow the dropdown; without it both fall back to whatever ticket type was last saved.", + "description": "Outcomes and priorities are scoped to a ticket type. The settings page sends the ticket type currently selected in the form so the lists follow the dropdown; without it both fall back to whatever ticket type was last saved. @() on each: PowerShell unrolls single-element output, so a ticket type with one outcome (or a lookup that answers with a single explanatory row) would otherwise serialise as a bare object and break callers that expect a list.", "required": false, "schema": { "type": "string" @@ -20891,6 +21376,9 @@ ] } }, + { + "$ref": "#/components/parameters/tenantFilter" + }, { "name": "TenantID", "in": "query", @@ -21561,6 +22049,9 @@ }, "403": { "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" } }, "security": [ @@ -21737,9 +22228,15 @@ "schema": { "type": "object", "properties": { + "CustomSuffix": { + "type": "string" + }, "GroupId": { "type": "string" }, + "NewRoles": { + "type": "string" + }, "OriginalTemplateId": { "type": "string", "description": "Use OriginalTemplateId if provided (for rename), otherwise use TemplateId" @@ -21749,6 +22246,12 @@ "items": { "type": "object", "properties": { + "GroupId": { + "type": "array", + "items": { + "type": "string" + } + }, "roleDefinitionId": { "type": "string" } @@ -21757,7 +22260,7 @@ }, "TemplateId": { "type": "string", - "description": "Use OriginalTemplateId if provided (for rename), otherwise use TemplateId" + "description": "Template-first save: creates any group mappings the editor asked for, then writes the full mapping set to the template in one shot." } } } @@ -21774,7 +22277,8 @@ "enum": [ "Add", "Delete", - "Edit" + "Edit", + "Save" ] } }, @@ -21800,12 +22304,18 @@ "type": "string", "x-cipp-field-source": "storage" }, + "GroupMappings": { + "x-cipp-field-source": "frontend" + }, "PartitionKey": { "x-cipp-field-source": "storage" }, "RoleMappings": { "type": "string", - "x-cipp-field-source": "storage,backend,frontend" + "x-cipp-field-source": "storage,backend" + }, + "Roles": { + "x-cipp-field-source": "frontend" }, "RowKey": { "x-cipp-field-source": "storage" @@ -22995,6 +23505,96 @@ "x-cipp-role": "Exchange.Mailbox.ReadWrite" } }, + "/api/ExecHistoricalSearch": { + "post": { + "summary": "ExecHistoricalSearch", + "operationId": "ExecHistoricalSearch", + "tags": [ + "Email-Exchange > Tools" + ], + "description": "Starts or cancels an Exchange Online historical search. Historical searches cover up to 90 days,\ndeliver results as CSV (max 100,000 rows) and are limited to 250 submissions per day per tenant.", + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "Action": { + "type": "string" + }, + "deliveryStatus": { + "$ref": "#/components/schemas/LabelValue" + }, + "direction": { + "$ref": "#/components/schemas/LabelValue" + }, + "jobId": { + "type": "string" + }, + "messageId": { + "type": "string" + }, + "notifyAddress": { + "type": "string" + }, + "originalClientIP": { + "type": "string" + }, + "recipientAddress": { + "type": "string" + }, + "reportTitle": { + "type": "string" + }, + "reportType": { + "$ref": "#/components/schemas/LabelValue" + }, + "senderAddress": { + "type": "string" + }, + "tenantFilter": { + "type": "string" + } + }, + "required": [ + "jobId", + "tenantFilter" + ] + } + } + } + }, + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "object", + "description": "Not described statically: this endpoint returns the upstream response as-is, so its fields are determined by the upstream API rather than by CIPP. Call the endpoint to see the actual shape, or add a response schema in backend/Config/openapi-overrides." + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Exchange.Mailbox.ReadWrite" + } + }, "/api/ExecHVEUser": { "post": { "summary": "ExecHVEUser", @@ -23367,7 +23967,11 @@ "type": "object", "properties": { "AdminRoles": { - "$ref": "#/components/schemas/LabelValue" + "type": "array", + "items": { + "$ref": "#/components/schemas/LabelValue" + }, + "description": "Enforce the caller's allowed JIT roles (from the JIT Role Template on their custom role). Get-CIPPJITAdminAllowedRoles is authoritative and fails closed for restricted callers, so we trust its result rather than swallowing errors here." }, "Domain": { "$ref": "#/components/schemas/LabelValue" @@ -23626,29 +24230,51 @@ "x-cipp-any-tenant": true } }, - "/api/ExecLicenseSearch": { + "/api/ExecLicensePricing": { "post": { - "summary": "ExecLicenseSearch", - "operationId": "ExecLicenseSearch", + "summary": "ExecLicensePricing", + "operationId": "ExecLicensePricing", "tags": [ - "CIPP > Core" + "Tenant > Reports" ], - "description": "Finds which tenants hold the given licence SKUs, searching the cached licence overview rather than querying each tenant live. Takes an array of skuIds in the body.", + "description": "Manage MSP-global license price overrides used by the license optimization report.\nSetPrice upserts a per-SKU monthly price; RemovePrice deletes an override so the SKU falls\nback to the shipped MSRP estimate.", "requestBody": { - "required": false, + "required": true, "content": { "application/json": { "schema": { "type": "object", "properties": { - "skuIds": { - "type": "array", - "items": { - "type": "string" - }, - "description": "Get skuIds from POST body" + "Action": { + "type": "string", + "enum": [ + "RemovePrice", + "SetPrice" + ], + "description": "SetPrice or RemovePrice" + }, + "Currency": { + "type": "string", + "description": "Overrides are currency-scoped: one row per (skuId, currency), so an AUD override and a USD override for the same SKU coexist. RowKey = \"{skuId}-{currency}\"." + }, + "MonthlyPrice": { + "type": "number", + "description": "Monthly price per seat, in the given currency" + }, + "Product_Display_Name": { + "type": "string" + }, + "skuId": { + "type": "string", + "description": "The SKU GUID (skuId) the price applies to" + }, + "skuPartNumber": { + "type": "string" } - } + }, + "required": [ + "Action" + ] } } } @@ -23660,7 +24286,102 @@ "application/json": { "schema": { "type": "object", - "description": "Not described statically: this endpoint returns the upstream response as-is, so its fields are determined by the upstream API rather than by CIPP. Call the endpoint to see the actual shape, or add a response schema in backend/Config/openapi-overrides." + "description": "Derived from the fields written into the storage table it reads. Fields taken from the storage writers may be omitted by this endpoint, and the response may carry computed fields not listed here.", + "properties": { + "Currency": { + "x-cipp-field-source": "storage" + }, + "ETag": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "MonthlyPrice": { + "type": "number", + "x-cipp-field-source": "storage" + }, + "PartitionKey": { + "x-cipp-field-source": "storage" + }, + "Product_Display_Name": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "RowKey": { + "x-cipp-field-source": "storage" + }, + "skuId": { + "x-cipp-field-source": "storage" + }, + "skuPartNumber": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "Timestamp": { + "type": "string", + "x-cipp-field-source": "storage" + } + } + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Tenant.Directory.ReadWrite", + "x-cipp-any-tenant": true + } + }, + "/api/ExecLicenseSearch": { + "post": { + "summary": "ExecLicenseSearch", + "operationId": "ExecLicenseSearch", + "tags": [ + "CIPP > Core" + ], + "description": "Finds which tenants hold the given licence SKUs, searching the cached licence overview rather than querying each tenant live. Takes an array of skuIds in the body.", + "requestBody": { + "required": false, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "skuIds": { + "type": "array", + "items": { + "type": "string" + }, + "description": "Get skuIds from POST body" + } + } + } + } + } + }, + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "object", + "description": "Not described statically: this endpoint returns the upstream response as-is, so its fields are determined by the upstream API rather than by CIPP. Call the endpoint to see the actual shape, or add a response schema in backend/Config/openapi-overrides." } } } @@ -23870,6 +24591,7 @@ "x-cipp-field-source": "graph-entity" }, "RowKey": { + "type": "string", "x-cipp-field-source": "storage" }, "samlMetadataUrl": { @@ -23879,6 +24601,10 @@ "SASUrl": { "x-cipp-field-source": "storage" }, + "SecretValue": { + "type": "string", + "x-cipp-field-source": "storage" + }, "serviceManagementReference": { "type": "string", "x-cipp-field-source": "graph-entity" @@ -24182,12 +24908,35 @@ "Email-Exchange > Administration" ], "requestBody": { - "required": false, + "required": true, "content": { "application/json": { "schema": { "type": "object", - "properties": {} + "properties": { + "Delete": { + "type": "string" + }, + "deviceid": { + "type": "string" + }, + "guid": { + "type": "string" + }, + "Quarantine": { + "type": "string" + }, + "tenantFilter": { + "type": "string" + }, + "Userid": { + "type": "string", + "description": "Interact with query parameters or the body of the request. This is a state-changing action, so the frontend dispatches it as a POST; keep the query fallback for backwards compatibility." + } + }, + "required": [ + "tenantFilter" + ] } } } @@ -24231,6 +24980,7 @@ { "name": "Userid", "in": "query", + "description": "Interact with query parameters or the body of the request. This is a state-changing action, so the frontend dispatches it as a POST; keep the query fallback for backwards compatibility.", "required": false, "schema": { "type": "string" @@ -25103,7 +25853,7 @@ "tags": [ "Security > Incidents" ], - "description": "Lists Microsoft Defender for Office 365 alerts for a tenant, filtered to that service source. tenantFilter=AllTenants reads the cached alert table rather than querying each tenant live.", + "description": "Lists Microsoft Defender for Office 365 and Defender for Endpoint alerts for a tenant, filtered to those service sources. tenantFilter=AllTenants reads the cached alert table rather than querying each tenant live.", "parameters": [ { "$ref": "#/components/parameters/tenantFilter" @@ -25264,7 +26014,7 @@ }, "serviceSource": { "type": "object", - "x-cipp-field-source": "graph-entity" + "x-cipp-field-source": "graph-entity,frontend" }, "severity": { "type": "object", @@ -27014,6 +27764,9 @@ } } }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, "401": { "description": "Unauthorized - invalid or missing bearer token" }, @@ -27223,6 +27976,7 @@ "tags": [ "Identity > Administration > Users" ], + "description": "Runs the offboarding wizard: one scheduled offboarding job per user, immediately or at the\nscheduled time, reporting live progress under one job id. Action=Rerun queues an existing\noffboarding task again; Action=RerunStep queues one step of it, reported to the same progress row.", "requestBody": { "required": true, "content": { @@ -27230,6 +27984,9 @@ "schema": { "type": "object", "properties": { + "Action": { + "type": "string" + }, "forward": { "$ref": "#/components/schemas/LabelValue" }, @@ -27250,6 +28007,9 @@ } } }, + "PsaTicketId": { + "type": "string" + }, "reference": { "type": "string" }, @@ -27266,6 +28026,18 @@ }, "description": "Scheduled: when enabled, date must be a valid Unix timestamp" }, + "StepIndex": { + "type": "integer", + "description": "Zero-based index of the step, as listed in the progress row, to run again" + }, + "StepTitle": { + "type": "string", + "description": "Title of that step, used to name the re-run task" + }, + "TaskId": { + "type": "string", + "description": "RowKey of the offboarding task to run again" + }, "tenantFilter": { "allOf": [ { @@ -27291,19 +28063,23 @@ } } }, + "parameters": [ + { + "name": "Action", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + } + ], "responses": { "200": { "description": "Success", "content": { "application/json": { "schema": { - "type": "object", - "description": "Derived from the fields the endpoint selects onto each record. The response may carry more; these are the ones known to exist.", - "properties": { - "Results": { - "x-cipp-field-source": "backend" - } - } + "$ref": "#/components/schemas/StandardResults" } } } @@ -27424,7 +28200,7 @@ "type": "boolean" }, "standardsExcludeAllTenants": { - "type": "string" + "type": "boolean" } } } @@ -27470,6 +28246,9 @@ "type": "string", "x-cipp-field-source": "storage,backend" }, + "StandardsExcludeAllTenants": { + "x-cipp-field-source": "storage,backend" + }, "Status": { "x-cipp-field-source": "storage,backend" }, @@ -27715,7 +28494,8 @@ "type": "object", "properties": { "enabled": { - "type": "boolean" + "type": "boolean", + "description": "Subscription create/update is logged by New-CIPPGraphSubscription; log the onboarding config write here." }, "EventType": { "$ref": "#/components/schemas/LabelValue" @@ -28230,6 +29010,129 @@ "x-cipp-role": "Identity.User.ReadWrite" } }, + "/api/ExecPIMRoleAssignment": { + "post": { + "summary": "Change a directory role assignment through PIM in the secure direction only.", + "operationId": "ExecPIMRoleAssignment", + "tags": [ + "Identity > Administration > Roles" + ], + "description": "Converts a permanent assignment to eligible, grants a time-bound active assignment, extends or renews a time-bound assignment or eligibility, or removes an assignment. Every request must carry an expiration (a duration or an end date); permanent / no-expiration assignments are refused, as are changes to group-inherited rows, the CIPP-SAM application and the last active Global Administrator. Requires Entra ID P2.", + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "Action": { + "allOf": [ + { + "$ref": "#/components/schemas/LabelValue" + } + ], + "description": "ConvertToEligible | GrantActive | Extend | Renew | Remove" + }, + "AssignmentType": { + "allOf": [ + { + "$ref": "#/components/schemas/LabelValue" + } + ], + "description": "The row's current assignment type: Permanent | Active | ActivatedFromEligible | Eligible" + }, + "DirectoryScopeId": { + "allOf": [ + { + "$ref": "#/components/schemas/LabelValue" + } + ], + "description": "'/' for the whole directory or '/administrativeUnits/{id}'." + }, + "Duration": { + "allOf": [ + { + "$ref": "#/components/schemas/LabelValue" + } + ], + "description": "ISO 8601 lifetime such as PT4H or P1Y. Use either Duration or EndDateTime, not both." + }, + "EndDateTime": { + "allOf": [ + { + "$ref": "#/components/schemas/LabelValue" + } + ], + "description": "Absolute end (unix seconds or ISO 8601). Use either Duration or EndDateTime, not both." + }, + "Justification": { + "type": "string", + "description": "Reason recorded on the PIM request and in the CIPP logbook." + }, + "PrincipalId": { + "allOf": [ + { + "$ref": "#/components/schemas/LabelValue" + } + ], + "description": "Object id of the user, group or service principal." + }, + "RoleDefinitionId": { + "allOf": [ + { + "$ref": "#/components/schemas/LabelValue" + } + ], + "description": "Role template id (roleDefinitionId as PIM reports it)." + }, + "tenantFilter": { + "$ref": "#/components/schemas/LabelValue" + }, + "TimeZone": { + "allOf": [ + { + "$ref": "#/components/schemas/LabelValue" + } + ], + "description": "IANA time zone of the browser (e.g. Australia/Perth); only used to word the end time in the result." + } + }, + "required": [ + "tenantFilter" + ] + } + } + } + }, + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Identity.Role.ReadWrite" + } + }, "/api/ExecQuarantineManagement": { "post": { "summary": "ExecQuarantineManagement", @@ -28308,6 +29211,75 @@ "x-cipp-role": "Exchange.SpamFilter.ReadWrite" } }, + "/api/ExecReactivateSite": { + "post": { + "summary": "Reactivate an archived SharePoint or OneDrive site.", + "operationId": "ExecReactivateSite", + "tags": [ + "Teams-Sharepoint" + ], + "description": "Reactivates (unarchives) a Microsoft 365 Archive site through the Graph beta\nsite: unarchive endpoint (POST /beta/sites/{site-id}/unarchive). Primarily used to\nreactivate archived OneDrive accounts before granting permissions to them.\nReactivation is asynchronous (can take up to 24 hours) and, for fully-archived\naccounts, may incur Microsoft 365 Archive charges and require Unlicensed OneDrive\nbilling to be enabled on the tenant.", + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "SiteId": { + "type": "string", + "description": "Site-collection GUID (the row's siteId / sharepointIds.siteId). Used to build the Graph composite site id without touching the locked, archived site." + }, + "SiteUrl": { + "type": "string", + "description": "Full web URL of the archived site / OneDrive (the row's webUrl)." + }, + "tenantFilter": { + "type": "string", + "description": "Tenant the archived site belongs to." + }, + "WebId": { + "type": "string", + "description": "Web GUID (the row's webId / sharepointIds.webId)." + } + }, + "required": [ + "SiteUrl", + "tenantFilter" + ] + } + } + } + }, + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Sharepoint.Site.ReadWrite" + } + }, "/api/ExecRefreshMyAccess": { "get": { "summary": "Re-check the caller's Entra group membership and refresh their CIPP roles", @@ -31403,7 +32375,7 @@ "tags": [ "Identity > Administration > Users" ], - "description": "Sends a test MFA push notification to a user's authenticator app and reports whether it was approved. Used to confirm a user's MFA registration works. This causes a real prompt on the user's device.", + "description": "Sends a test MFA push notification to a user's authenticator app and reports whether it was approved, or - when an OTP code is supplied - verifies that typed code without sending a push. Used to confirm a user's MFA registration works. The push path causes a real prompt on the user's device.", "requestBody": { "required": true, "content": { @@ -31411,6 +32383,10 @@ "schema": { "type": "object", "properties": { + "OTP": { + "type": "string", + "description": "When an OTP code is supplied we verify that code instead of sending a push notification." + }, "TenantFilter": { "type": "string" }, @@ -31432,10 +32408,366 @@ "application/json": { "schema": { "type": "object", - "description": "Derived from the fields the endpoint selects onto each record. The response may carry more; these are the ones known to exist.", + "description": "Derived from the Microsoft Graph entity it queries, and the fields the endpoint selects onto each record. This endpoint returns the Graph response as-is without selecting fields, so these are the properties the entity CAN carry (x-cipp-field-source: graph-entity) rather than a proven projection - Graph returns a default subset unless asked otherwise.", "properties": { + "aboutMe": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "accountEnabled": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "ageGroup": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "assignedLicenses": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "assignedPlans": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "authorizationInfo": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "birthday": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "businessPhones": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "city": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "cloudLicensing": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "cloudRealtimeCommunicationInfo": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "companyName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "consentProvidedForMinor": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "country": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "createdDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "creationType": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "customSecurityAttributes": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "deletedDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "department": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "deviceEnrollmentLimit": { + "type": "integer", + "x-cipp-field-source": "graph-entity" + }, + "deviceKeys": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "displayName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "employeeHireDate": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "employeeId": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "employeeLeaveDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "employeeOrgData": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "employeeType": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "externalUserState": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "externalUserStateChangeDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "faxNumber": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "givenName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "hireDate": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "id": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "identities": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "identityGovernance": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "identityParentId": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "imAddresses": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "infoCatalogs": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "interests": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "isLicenseReconciliationNeeded": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "isManagementRestricted": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "isResourceAccount": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "jobTitle": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "lastPasswordChangeDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "legalAgeGroupClassification": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "licenseAssignmentStates": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "mail": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "mailboxSettings": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "mailNickname": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "mobilePhone": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "mySite": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "officeLocation": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesDistinguishedName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesDomainName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesExtensionAttributes": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesImmutableId": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesLastSyncDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesProvisioningErrors": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesSamAccountName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesSecurityIdentifier": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesSipInfo": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesSyncEnabled": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesUserPrincipalName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "otherMails": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "passwordPolicies": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "passwordProfile": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "pastProjects": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "postalCode": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "preferredDataLocation": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "preferredLanguage": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "preferredName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "print": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "provisionedPlans": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "proxyAddresses": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "refreshTokensValidFromDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "responsibilities": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, "Results": { "x-cipp-field-source": "backend" + }, + "schools": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "securityIdentifier": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "serviceProvisioningErrors": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "showInAddressList": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "signInActivity": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "signInSessionsValidFromDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "skills": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "state": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "streetAddress": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "surname": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "usageLocation": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "userPrincipalName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "userType": { + "type": "string", + "x-cipp-field-source": "graph-entity" } } } @@ -34044,6 +35376,108 @@ "x-cipp-role": "Sharepoint.Site.ReadWrite" } }, + "/api/ExecSiteBrowserLibraryCopy": { + "post": { + "summary": "ExecSiteBrowserLibraryCopy", + "operationId": "ExecSiteBrowserLibraryCopy", + "tags": [ + "Teams-Sharepoint" + ], + "description": "Starts or preflights a SharePoint document library content copy (CreateCopyJobs + MoveButKeepSource).\nActions: PreflightLibraryCopy, StartLibraryCopy.", + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "Action": { + "type": "string" + }, + "DestLibraryName": { + "type": "string" + }, + "DestListId": { + "type": "string" + }, + "DestSiteId": { + "type": "string" + }, + "DestSiteName": { + "type": "string" + }, + "DestSiteUrl": { + "type": "string" + }, + "NameConflictBehavior": { + "type": "string" + }, + "SourceLibraryName": { + "type": "string" + }, + "SourceListId": { + "type": "string" + }, + "SourceSiteId": { + "type": "string" + }, + "SourceSiteName": { + "type": "string" + }, + "SourceSiteUrl": { + "type": "string" + }, + "tenantFilter": { + "type": "string" + } + }, + "required": [ + "Action", + "tenantFilter" + ] + } + } + } + }, + "parameters": [ + { + "name": "Action", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Sharepoint.Site.ReadWrite" + } + }, "/api/ExecSiteBrowserPermissions": { "post": { "summary": "ExecSiteBrowserPermissions", @@ -35378,11 +36812,16 @@ "x-cipp-field-source": "storage" }, "RowKey": { + "type": "string", "x-cipp-field-source": "storage" }, "SASUrl": { "x-cipp-field-source": "storage" }, + "SecretValue": { + "type": "string", + "x-cipp-field-source": "storage" + }, "TenantId": { "x-cipp-field-source": "storage" }, @@ -35661,6 +37100,7 @@ }, "status": { "type": "string", + "description": "The status is written at the end of this block, after the action it implies succeeds.", "x-cipp-observed-values": [ "deniedDelete", "DeniedRemediate" @@ -35805,11 +37245,16 @@ "x-cipp-field-source": "backend" }, "RowKey": { + "type": "string", "x-cipp-field-source": "storage" }, "SASUrl": { "x-cipp-field-source": "storage" }, + "SecretValue": { + "type": "string", + "x-cipp-field-source": "storage" + }, "TenantId": { "x-cipp-field-source": "storage" }, @@ -35973,7 +37418,8 @@ "bearerAuth": [] } ], - "x-cipp-role": "CIPP.Core.ReadWrite" + "x-cipp-role": "CIPP.Core.ReadWrite", + "x-cipp-any-tenant": true } }, "/api/ExecUserSettings": { @@ -38287,6 +39733,59 @@ "x-cipp-any-tenant": true } }, + "/api/ListAsyncDeployment": { + "get": { + "summary": "Get the live progress of a background job", + "operationId": "ListAsyncDeployment", + "tags": [ + "CIPP > Scheduler" + ], + "description": "Returns the status rows of a background job that reports progress while it runs, such as a\nuser offboarding started from the wizard: one row per target (the user) with its overall\nstatus and the status and message of every step.", + "parameters": [ + { + "name": "DeploymentId", + "in": "query", + "description": "The job id handed back when the work was queued (e.g. DeploymentId from ExecOffboardUser)", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Not described statically: this endpoint returns the upstream response as-is, so its fields are determined by the upstream API rather than by CIPP. Call the endpoint to see the actual shape, or add a response schema in backend/Config/openapi-overrides." + } + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "CIPP.Scheduler.Read", + "x-cipp-any-tenant": true + } + }, "/api/ListAuditLogCoverage": { "get": { "summary": "ListAuditLogCoverage", @@ -39821,7 +41320,7 @@ "label": { "x-cipp-field-source": "backend" }, - "package": { + "Package": { "x-cipp-field-source": "storage,frontend" }, "PartitionKey": { @@ -39837,8 +41336,8 @@ "SHA": { "x-cipp-field-source": "storage" }, - "source": { - "x-cipp-field-source": "storage" + "Source": { + "x-cipp-field-source": "storage,frontend" }, "templateCount": { "x-cipp-field-source": "backend" @@ -40512,8 +42011,34 @@ "tags": [ "Tenant > Conditional" ], - "description": "Lists Conditional Access policies for a tenant with resolved display names for users, groups, applications, and locations.", + "description": "Lists Conditional Access policies for a tenant with resolved display names for users, groups, applications, and locations. When manualPagination is set on an AllTenants read, one page is returned per request with a continuation token in Metadata.nextLink.", "parameters": [ + { + "name": "manualPagination", + "in": "query", + "description": "Return one page per request with a continuation token in Metadata.nextLink; AllTenants reads only.", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "nextLink", + "in": "query", + "description": "Continuation token from the previous page's Metadata.nextLink; opaque to callers.", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "PageSize", + "in": "query", + "required": false, + "schema": { + "type": "integer" + } + }, { "$ref": "#/components/parameters/tenantFilter" } @@ -44563,7 +46088,7 @@ "x-cipp-field-source": "storage" }, "ExecutedTime": { - "x-cipp-field-source": "frontend" + "x-cipp-field-source": "storage,frontend" }, "Hidden": { "type": "boolean", @@ -44585,6 +46110,14 @@ "type": "string", "x-cipp-field-source": "storage" }, + "PsaTicketId": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "PsaTicketPriority": { + "type": "string", + "x-cipp-field-source": "storage" + }, "PsaTicketStrategy": { "type": "string", "x-cipp-field-source": "storage" @@ -45344,7 +46877,18 @@ "tags": [ "Tenant > GDAP" ], - "description": "Lists the configured GDAP role-to-security-group mappings used for delegated admin access.", + "description": "Lists the configured GDAP role-to-security-group mappings used for delegated admin access.\nPass ?validate=true to annotate each mapping with the state of its partner tenant group.", + "parameters": [ + { + "name": "validate", + "in": "query", + "description": "Opt-in only: other consumers of this endpoint depend on the unannotated shape.", + "required": false, + "schema": { + "type": "boolean" + } + } + ], "responses": { "200": { "description": "Success", @@ -45366,6 +46910,12 @@ "GroupName": { "x-cipp-field-source": "storage,backend,frontend" }, + "GroupStatus": { + "x-cipp-field-source": "backend,frontend" + }, + "GroupStatusMessage": { + "x-cipp-field-source": "backend" + }, "PartitionKey": { "x-cipp-field-source": "storage" }, @@ -45387,6 +46937,9 @@ "Timestamp": { "type": "string", "x-cipp-field-source": "storage" + }, + "UsedInTemplates": { + "x-cipp-field-source": "frontend" } } } @@ -46080,6 +47633,15 @@ "type": "string" } }, + { + "name": "maxPageBytes", + "in": "query", + "description": "Paged AllTenants cache reads only: target page size in bytes of raw JSON, clamped between 262144 and 8388608 (default 4000000). Pages always hold at least one whole tenant.", + "required": false, + "schema": { + "type": "integer" + } + }, { "name": "nextLink", "in": "query", @@ -46270,7 +47832,7 @@ "tags": [ "Identity > Administration > Groups" ], - "description": "Lists Entra ID groups for a tenant, including group members and owners. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants.", + "description": "Lists Entra ID groups for a tenant, including group members and owners. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants. When manualPagination is also set on a cached read, one page is returned per request as { Results, Metadata } with a continuation token in Metadata.nextLink.", "parameters": [ { "name": "expandMembers", @@ -46307,6 +47869,15 @@ "type": "string" } }, + { + "name": "manualPagination", + "in": "query", + "description": "Return one page per request as { Results, Metadata } with a continuation token in Metadata.nextLink; cached reads only.", + "required": false, + "schema": { + "type": "string" + } + }, { "name": "members", "in": "query", @@ -46316,6 +47887,15 @@ "type": "boolean" } }, + { + "name": "nextLink", + "in": "query", + "description": "Continuation token from the previous page's Metadata.nextLink; opaque to callers. Stream the cached blobs as raw JSON so member arrays are never re-parsed here.", + "required": false, + "schema": { + "type": "string" + } + }, { "name": "owners", "in": "query", @@ -46325,6 +47905,14 @@ "type": "boolean" } }, + { + "name": "PageSize", + "in": "query", + "required": false, + "schema": { + "type": "integer" + } + }, { "$ref": "#/components/parameters/tenantFilter" }, @@ -46419,9 +48007,6 @@ "members": { "x-cipp-field-source": "backend" }, - "membersCsv": { - "x-cipp-field-source": "backend" - }, "membershipRule": { "type": "string", "x-cipp-field-source": "graph" @@ -46441,9 +48026,6 @@ "owners": { "x-cipp-field-source": "backend" }, - "ownersCsv": { - "x-cipp-field-source": "backend" - }, "primDomain": { "x-cipp-field-source": "backend" }, @@ -46681,6 +48263,78 @@ "x-cipp-any-tenant": true } }, + "/api/ListGroupUsage": { + "get": { + "summary": "ListGroupUsage", + "operationId": "ListGroupUsage", + "tags": [ + "Identity > Reports" + ], + "description": "Compiles where each Entra group is used (Conditional Access, Intune assignments, group-based\nlicensing, Teams, nested groups, Entra roles, enterprise applications, Exchange transport\nrules) from the CIPP reporting database cache. Always served from cache — no live Graph calls.", + "parameters": [ + { + "$ref": "#/components/parameters/tenantFilter" + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the columns the CIPP UI renders. The response may carry more; these are the ones known to exist.", + "properties": { + "displayName": { + "x-cipp-field-source": "frontend" + }, + "groupType": { + "x-cipp-field-source": "frontend" + }, + "isUsed": { + "x-cipp-field-source": "frontend" + }, + "mail": { + "x-cipp-field-source": "frontend" + }, + "Tenant": { + "x-cipp-field-source": "frontend" + }, + "usageCount": { + "x-cipp-field-source": "frontend" + }, + "usedIn": { + "x-cipp-field-source": "frontend" + }, + "usedLocations": { + "x-cipp-field-source": "frontend" + } + } + } + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Identity.Group.Read" + } + }, "/api/ListGuestUsers": { "get": { "summary": "List guest users with lifecycle status", @@ -46688,8 +48342,34 @@ "tags": [ "Identity > Administration > Users" ], - "description": "Lists all guest accounts in a tenant with a computed lifecycle status (Active, Pending Acceptance, Stale, Never Signed In or Disabled) based on the invitation state and sign-in activity. Supports UseReportDB=true to serve cached data from the reporting database; AllTenants always uses the cache.", + "description": "Lists all guest accounts in a tenant with a computed lifecycle status (Active, Pending Acceptance, Stale, Never Signed In or Disabled) based on the invitation state and sign-in activity. Supports UseReportDB=true to serve cached data from the reporting database; AllTenants always uses the cache. When manualPagination is set on a cached read, one page is returned per request as { Results, Metadata } with a continuation token in Metadata.nextLink.", "parameters": [ + { + "name": "manualPagination", + "in": "query", + "description": "Return one page per request as { Results, Metadata } with a continuation token in Metadata.nextLink; cached reads only.", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "nextLink", + "in": "query", + "description": "Continuation token from the previous page's Metadata.nextLink; opaque to callers.", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "PageSize", + "in": "query", + "required": false, + "schema": { + "type": "integer" + } + }, { "name": "staleDays", "in": "query", @@ -46864,6 +48544,86 @@ "x-cipp-role": "CIPP.Extension.Read" } }, + "/api/ListHistoricalSearches": { + "get": { + "summary": "ListHistoricalSearches", + "operationId": "ListHistoricalSearches", + "tags": [ + "Email-Exchange > Tools" + ], + "description": "Lists Exchange Online historical searches (async message trace/report jobs) submitted in the last 10 days.", + "parameters": [ + { + "name": "jobId", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + }, + { + "$ref": "#/components/parameters/tenantFilter" + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the columns the CIPP UI renders. The response may carry more; these are the ones known to exist.", + "properties": { + "EndDate": { + "x-cipp-field-source": "frontend" + }, + "JobProgress": { + "x-cipp-field-source": "frontend" + }, + "ReportTitle": { + "x-cipp-field-source": "frontend" + }, + "ReportType": { + "x-cipp-field-source": "frontend" + }, + "Rows": { + "x-cipp-field-source": "frontend" + }, + "StartDate": { + "x-cipp-field-source": "frontend" + }, + "Status": { + "x-cipp-field-source": "frontend" + }, + "SubmitDate": { + "x-cipp-field-source": "frontend" + } + } + } + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Exchange.Mailbox.Read" + } + }, "/api/ListHVEAccounts": { "get": { "summary": "ListHVEAccounts", @@ -47017,6 +48777,9 @@ "type": "object", "description": "Derived from the columns the CIPP UI renders. The response may carry more; these are the ones known to exist.", "properties": { + "accountEnabled": { + "x-cipp-field-source": "frontend" + }, "daysSinceLastSignIn": { "x-cipp-field-source": "frontend" }, @@ -47623,8 +49386,8 @@ "SHA": { "x-cipp-field-source": "storage" }, - "source": { - "x-cipp-field-source": "storage,backend" + "Source": { + "x-cipp-field-source": "storage,backend,frontend" }, "templateCount": { "x-cipp-field-source": "backend" @@ -47959,14 +49722,14 @@ "x-cipp-any-tenant": true } }, - "/api/ListKnownIPDb": { + "/api/ListJITAllowedRoles": { "get": { - "summary": "ListKnownIPDb", - "operationId": "ListKnownIPDb", + "summary": "ListJITAllowedRoles", + "operationId": "ListJITAllowedRoles", "tags": [ - "CIPP > Core" + "Identity > Administration > Users" ], - "description": "Lists known IP address entries from the CIPP IP database, optionally filtered by tenant.", + "description": "Returns the directory roles the calling user is permitted to assign via JIT Admin, based on the\nJIT Role Template(s) attached to their CIPP custom role(s). When the caller is unrestricted the\nfull role catalog is available (Restricted = false).", "responses": { "200": { "description": "Success", @@ -47994,29 +49757,27 @@ "bearerAuth": [] } ], - "x-cipp-role": "CIPP.Core.Read", + "x-cipp-role": "Identity.Role.Read", "x-cipp-any-tenant": true } }, - "/api/ListLicenses": { + "/api/ListJITRoleTemplates": { "get": { - "summary": "ListLicenses", - "operationId": "ListLicenses", + "summary": "ListJITRoleTemplates", + "operationId": "ListJITRoleTemplates", "tags": [ - "Tenant > Reports" + "Identity > Administration > Users" ], - "description": "Lists Microsoft 365 license SKUs and their assigned/available counts for a tenant. For AllTenants queries, consider using ListDBCache for better performance.", + "description": "Lists JIT Role Templates - named allow-lists of directory roles used to restrict which roles a\nCIPP custom role may assign via JIT Admin.", "parameters": [ { - "name": "IncludeExcluded", + "name": "GUID", "in": "query", + "description": "If a specific GUID is requested, filter to that template", "required": false, "schema": { - "type": "boolean" + "type": "string" } - }, - { - "$ref": "#/components/parameters/tenantFilter" } ], "responses": { @@ -48028,28 +49789,55 @@ "type": "array", "items": { "type": "object", - "description": "Derived from the fields written into the storage table it reads, and the fields the endpoint selects onto each record. Fields taken from the storage writers may be omitted by this endpoint, and the response may carry computed fields not listed here.", + "description": "Derived from the fields written into the storage table it reads, and the columns the CIPP UI renders. Fields taken from the storage writers may be omitted by this endpoint, and the response may carry computed fields not listed here.", "properties": { + "createdBy": { + "x-cipp-field-source": "frontend" + }, + "createdDate": { + "x-cipp-field-source": "frontend" + }, "ETag": { "type": "string", "x-cipp-field-source": "storage" }, - "License": { - "type": "string", - "x-cipp-field-source": "storage,backend" + "GUID": { + "x-cipp-field-source": "storage" + }, + "JSON": { + "x-cipp-field-source": "storage" + }, + "Package": { + "x-cipp-field-source": "storage" }, "PartitionKey": { "x-cipp-field-source": "storage" }, + "Permissions": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "roles": { + "x-cipp-field-source": "frontend" + }, "RowKey": { "x-cipp-field-source": "storage" }, - "Tenant": { - "x-cipp-field-source": "backend" + "SHA": { + "x-cipp-field-source": "storage" + }, + "Source": { + "x-cipp-field-source": "storage" + }, + "templateName": { + "x-cipp-field-source": "storage,frontend" }, "Timestamp": { "type": "string", "x-cipp-field-source": "storage" + }, + "UpdatedBy": { + "x-cipp-field-source": "storage" } } } @@ -48069,28 +49857,84 @@ "bearerAuth": [] } ], - "x-cipp-role": "Tenant.Directory.Read" + "x-cipp-role": "Identity.Role.Read", + "x-cipp-any-tenant": true } }, - "/api/ListLicensesReport": { + "/api/ListKnownIPDb": { "get": { - "summary": "ListLicensesReport", - "operationId": "ListLicensesReport", + "summary": "ListKnownIPDb", + "operationId": "ListKnownIPDb", + "tags": [ + "CIPP > Core" + ], + "description": "Lists known IP address entries from the CIPP IP database, optionally filtered by tenant.", + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Not described statically: this endpoint returns the upstream response as-is, so its fields are determined by the upstream API rather than by CIPP. Call the endpoint to see the actual shape, or add a response schema in backend/Config/openapi-overrides." + } + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "CIPP.Core.Read", + "x-cipp-any-tenant": true + } + }, + "/api/ListLicenseOptimization": { + "get": { + "summary": "ListLicenseOptimization", + "operationId": "ListLicenseOptimization", "tags": [ "Tenant > Reports" ], - "description": "Lists a detailed license overview across all tenants or a single tenant, including SKU breakdowns, costs, and availability.", + "description": "License cost-optimization report for a tenant: a monetary summary plus reclaim\nopportunities across five waste tiers (unassigned seats, disabled and inactive licensed\naccounts, mailbox-only downgrade candidates, and redundant overlapping SKUs). Computed from\nthe reporting-DB cache. For tenantFilter=AllTenants it returns a per-tenant summary money\nmap (ranked by reclaimable spend) instead of the full opportunity detail.", "parameters": [ { - "name": "QueueId", + "name": "currency", "in": "query", + "description": "Currency the money figures are resolved in (ISO code); defaults to USD", "required": false, "schema": { "type": "string" } }, { - "$ref": "#/components/parameters/tenantFilter" + "name": "inactiveDays", + "in": "query", + "description": "Sign-in age in days past which an enabled licensed user counts as inactive (default 90)", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "tenantFilter", + "in": "query", + "description": "The tenant to report on, or AllTenants for the cross-tenant summary money map", + "required": true, + "schema": { + "type": "string" + } } ], "responses": { @@ -48102,52 +49946,251 @@ "type": "array", "items": { "type": "object", - "description": "Derived from the fields written into the storage table it reads, and the fields the endpoint selects onto each record, and the columns the CIPP UI renders. Fields taken from the storage writers may be omitted by this endpoint, and the response may carry computed fields not listed here.", + "description": "Not described statically: this endpoint returns the upstream response as-is, so its fields are determined by the upstream API rather than by CIPP. Call the endpoint to see the actual shape, or add a response schema in backend/Config/openapi-overrides." + } + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Tenant.Directory.Read", + "x-cipp-any-tenant": true + } + }, + "/api/ListLicensePricing": { + "get": { + "summary": "ListLicensePricing", + "operationId": "ListLicensePricing", + "tags": [ + "Tenant > Reports" + ], + "description": "Lists the resolved monthly price for every known license SKU: MSP price overrides merged\nover the shipped MSRP estimates. Consumed by the license optimization report and its\nprice-management UI. Each row carries a Source of Override, Estimate, or Unknown.\n\nPrices are resolved in the requested currency (?currency=, default USD). The response also\ncarries the list of currencies present in the price data so the UI can offer a selector.", + "parameters": [ + { + "name": "currency", + "in": "query", + "description": "Currency to resolve prices in (ISO code); defaults to USD", + "required": false, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the columns the CIPP UI renders. The response may carry more; these are the ones known to exist.", "properties": { - "AssignedGroups": { + "Currency": { "x-cipp-field-source": "frontend" }, - "AssignedUsers": { + "MonthlyPrice": { "x-cipp-field-source": "frontend" }, - "CountAvailable": { + "Product_Display_Name": { "x-cipp-field-source": "frontend" }, - "CountUsed": { + "skuId": { + "x-cipp-field-source": "frontend" + }, + "skuPartNumber": { "x-cipp-field-source": "frontend" }, + "Source": { + "x-cipp-field-source": "frontend" + } + } + } + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Tenant.Directory.Read", + "x-cipp-any-tenant": true + } + }, + "/api/ListLicenses": { + "get": { + "summary": "ListLicenses", + "operationId": "ListLicenses", + "tags": [ + "Tenant > Reports" + ], + "description": "Lists Microsoft 365 license SKUs and their assigned/available counts for a tenant. For AllTenants queries, consider using ListDBCache for better performance.", + "parameters": [ + { + "name": "IncludeExcluded", + "in": "query", + "required": false, + "schema": { + "type": "boolean" + } + }, + { + "$ref": "#/components/parameters/tenantFilter" + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the fields written into the storage table it reads, and the fields the endpoint selects onto each record. Fields taken from the storage writers may be omitted by this endpoint, and the response may carry computed fields not listed here.", + "properties": { "ETag": { "type": "string", "x-cipp-field-source": "storage" }, "License": { "type": "string", - "x-cipp-field-source": "storage,frontend" - }, - "Metadata": { - "x-cipp-field-source": "backend" + "x-cipp-field-source": "storage,backend" }, "PartitionKey": { "x-cipp-field-source": "storage" }, - "Results": { - "x-cipp-field-source": "backend" - }, "RowKey": { "x-cipp-field-source": "storage" }, "Tenant": { - "x-cipp-field-source": "frontend" - }, - "TermInfo": { - "x-cipp-field-source": "frontend" + "x-cipp-field-source": "backend" }, "Timestamp": { "type": "string", "x-cipp-field-source": "storage" - }, - "TotalLicenses": { - "x-cipp-field-source": "frontend" + } + } + } + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Tenant.Directory.Read" + } + }, + "/api/ListLicensesReport": { + "get": { + "summary": "ListLicensesReport", + "operationId": "ListLicensesReport", + "tags": [ + "Tenant > Reports" + ], + "description": "Lists a detailed license overview across all tenants or a single tenant, including SKU breakdowns, costs, and availability.", + "parameters": [ + { + "name": "QueueId", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + }, + { + "$ref": "#/components/parameters/tenantFilter" + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the fields written into the storage table it reads, and the fields the endpoint selects onto each record, and the columns the CIPP UI renders. Fields taken from the storage writers may be omitted by this endpoint, and the response may carry computed fields not listed here.", + "properties": { + "AssignedGroups": { + "x-cipp-field-source": "frontend" + }, + "AssignedUsers": { + "x-cipp-field-source": "frontend" + }, + "CountAvailable": { + "x-cipp-field-source": "frontend" + }, + "CountUsed": { + "x-cipp-field-source": "frontend" + }, + "ETag": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "License": { + "type": "string", + "x-cipp-field-source": "storage,frontend" + }, + "Metadata": { + "x-cipp-field-source": "backend" + }, + "PartitionKey": { + "x-cipp-field-source": "storage" + }, + "Results": { + "x-cipp-field-source": "backend" + }, + "RowKey": { + "x-cipp-field-source": "storage" + }, + "Tenant": { + "x-cipp-field-source": "frontend" + }, + "TermInfo": { + "x-cipp-field-source": "frontend" + }, + "Timestamp": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "TotalLicenses": { + "x-cipp-field-source": "frontend" } } } @@ -48177,7 +50220,7 @@ "tags": [ "CIPP > Core" ], - "description": "Lists CIPP platform audit logs with filtering by severity, date range, tenant, and user. Supports listing available log categories.", + "description": "Lists CIPP platform audit logs with filtering by severity, date range, tenant, and user. Supports listing available log categories, fetching a single entry, and server-side pagination via manualPagination/nextLink.", "parameters": [ { "name": "API", @@ -48203,6 +50246,15 @@ "type": "string" } }, + { + "name": "Days", + "in": "query", + "description": "Days=N widens a filtered query to the last N calendar days (in the instance timezone), so the scoped drawers still show a run that finished last night. Ignored when dates are given.", + "required": false, + "schema": { + "type": "integer" + } + }, { "name": "EndDate", "in": "query", @@ -48214,6 +50266,7 @@ { "name": "Filter", "in": "query", + "description": "When true, the Severity/User/Tenant/API/StartDate/EndDate query filters are applied; otherwise the current day is returned unfiltered.", "required": false, "schema": { "type": "boolean" @@ -48230,11 +50283,39 @@ { "name": "logentryid", "in": "query", + "description": "Return single log entry by RowKey. RowKeys are either legacy GUIDs or the inverted-ticks format Write-LogMessage writes; both use only hex digits and hyphens.", "required": false, "schema": { "type": "string" } }, + { + "name": "manualPagination", + "in": "query", + "description": "Return one page per request plus a continuation token in Metadata.nextLink, which the frontend passes back as nextLink to fetch the next page. Pages walk the requested date range newest-day-first and, within a day, in RowKey order (newest-first for entries written with the inverted-ticks RowKey scheme).", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "nextLink", + "in": "query", + "description": "Continuation token from the previous page's Metadata.nextLink; opaque to callers.", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "PageSize", + "in": "query", + "description": "Rows to return per page, clamped between 50 and 1000. Defaults to 400.", + "required": false, + "schema": { + "type": "integer" + } + }, { "name": "ScheduledTaskId", "in": "query", @@ -48480,8 +50561,43 @@ "tags": [ "Email-Exchange > Administration" ], - "description": "Lists Exchange Online mailboxes for a tenant. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants.", + "description": "Lists Exchange Online mailboxes for a tenant. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants. When manualPagination is also set, one page is returned per request as { Results, Metadata } with a continuation token in Metadata.nextLink.", "parameters": [ + { + "name": "manualPagination", + "in": "query", + "description": "Return one page per request as { Results, Metadata } with a continuation token in Metadata.nextLink; cached reads only.", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "Minimal", + "in": "query", + "description": "Picker mode: address autocompletes only need the address + name, so skip the heavy field set, the per-mailbox computed properties, and the extra Get-OrganizationConfig call.", + "required": false, + "schema": { + "type": "boolean" + } + }, + { + "name": "nextLink", + "in": "query", + "description": "Continuation token from the previous page's Metadata.nextLink; opaque to callers.", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "PageSize", + "in": "query", + "required": false, + "schema": { + "type": "integer" + } + }, { "$ref": "#/components/parameters/tenantFilter" }, @@ -49059,6 +51175,100 @@ "x-cipp-role": "Exchange.Mailbox.Read" } }, + "/api/ListMailFlowReports": { + "get": { + "summary": "ListMailFlowReports", + "operationId": "ListMailFlowReports", + "tags": [ + "Email-Exchange > Reports" + ], + "description": "Returns Exchange Online mail flow reports: disposition counts by day (Get-MailFlowStatusReport)\nand top sender/recipient summaries (Get-MailTrafficSummaryReport). Both support up to 90 days.", + "parameters": [ + { + "name": "category", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "days", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "reportType", + "in": "query", + "required": false, + "schema": { + "type": "string", + "enum": [ + "MailFlowStatus", + "TrafficSummary" + ] + } + }, + { + "$ref": "#/components/parameters/tenantFilter" + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the fields the endpoint selects onto each record. The response may carry more; these are the ones known to exist.", + "properties": { + "Count": { + "x-cipp-field-source": "backend" + }, + "Date": { + "x-cipp-field-source": "backend" + }, + "Direction": { + "x-cipp-field-source": "backend" + }, + "EventType": { + "x-cipp-field-source": "backend" + }, + "Extra": { + "x-cipp-field-source": "backend" + }, + "Name": { + "x-cipp-field-source": "backend" + } + } + } + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Exchange.Mailbox.Read" + } + }, "/api/ListMailQuarantine": { "get": { "summary": "ListMailQuarantine", @@ -49606,7 +51816,7 @@ "tags": [ "Email-Exchange > Tools" ], - "description": "Traces email message delivery in Exchange Online, searchable by message ID, sender, recipient, and date range.", + "description": "Traces email delivery in Exchange Online via the Graph message trace API\n(/beta/admin/exchange/tracing/messageTraces), searchable by sender, recipient, subject,\nstatus, IP, message ID and date range. Graph works over GDAP/app-only where the legacy\nreporting endpoints do not. Requires the \"Transport Data Platform\" service principal\n(8bd644d1-64a1-4d4b-ae52-2e0cbf64e373) in the tenant; it is provisioned on demand. Until\nthat SP activates (which can take hours), or where the Graph permission is not yet\nconsented, the request falls back to Get-MessageTraceV2 so results are returned immediately.", "requestBody": { "required": true, "content": { @@ -49615,7 +51825,8 @@ "type": "object", "properties": { "days": { - "type": "string" + "type": "number", + "description": "Parse the shared search inputs." }, "endDate": { "type": "integer" @@ -49626,19 +51837,28 @@ "ID": { "type": "string" }, - "MessageId": { + "messageId": { + "type": "string" + }, + "messageTraceId": { "type": "string" }, "recipient": { "$ref": "#/components/schemas/LabelValue" }, "sender": { - "$ref": "#/components/schemas/LabelValue" + "type": "string" }, "startDate": { "type": "integer" }, "status": { + "type": "string" + }, + "subject": { + "type": "string" + }, + "subjectFilterType": { "$ref": "#/components/schemas/LabelValue" }, "tenantFilter": { @@ -49667,43 +51887,25 @@ "type": "array", "items": { "type": "object", - "description": "Derived from the fields the endpoint selects onto each record, and the columns the CIPP UI renders. The response may carry more; these are the ones known to exist.", + "description": "Derived from the columns the CIPP UI renders. The response may carry more; these are the ones known to exist.", "properties": { - "Action": { - "x-cipp-field-source": "backend" - }, - "Date": { - "x-cipp-field-source": "backend" - }, - "Detail": { - "x-cipp-field-source": "backend" - }, - "Event": { - "x-cipp-field-source": "backend" - }, - "FromIP": { - "x-cipp-field-source": "backend" - }, - "MessageTraceId": { - "x-cipp-field-source": "backend" - }, "Received": { - "x-cipp-field-source": "backend,frontend" + "x-cipp-field-source": "frontend" }, "RecipientAddress": { - "x-cipp-field-source": "backend,frontend" + "x-cipp-field-source": "frontend" }, "SenderAddress": { - "x-cipp-field-source": "backend,frontend" + "x-cipp-field-source": "frontend" + }, + "Size": { + "x-cipp-field-source": "frontend" }, "Status": { - "x-cipp-field-source": "backend,frontend" + "x-cipp-field-source": "frontend" }, "Subject": { - "x-cipp-field-source": "backend,frontend" - }, - "ToIP": { - "x-cipp-field-source": "backend" + "x-cipp-field-source": "frontend" } } } @@ -49736,8 +51938,34 @@ "tags": [ "Identity > Reports" ], - "description": "Lists users and their MFA registration status for a tenant. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants.", + "description": "Lists users and their MFA registration status for a tenant. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants. When manualPagination is also set, one page is returned per request as { Results, Metadata } with a continuation token in Metadata.nextLink.", "parameters": [ + { + "name": "manualPagination", + "in": "query", + "description": "Return one page per request as { Results, Metadata } with a continuation token in Metadata.nextLink; cached reads only.", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "nextLink", + "in": "query", + "description": "Continuation token from the previous page's Metadata.nextLink; opaque to callers.", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "PageSize", + "in": "query", + "required": false, + "schema": { + "type": "integer" + } + }, { "$ref": "#/components/parameters/tenantFilter" }, @@ -50073,6 +52301,15 @@ "PartitionKey": { "x-cipp-field-source": "storage" }, + "PsaTicketId": { + "x-cipp-field-source": "storage" + }, + "PsaTicketPriority": { + "x-cipp-field-source": "storage" + }, + "Reference": { + "x-cipp-field-source": "storage" + }, "RowKey": { "x-cipp-field-source": "storage" }, @@ -50340,6 +52577,59 @@ "x-cipp-role": "Identity.AuditLog.Read" } }, + "/api/ListOffboardingProgress": { + "get": { + "summary": "Get the live progress of an offboarding job", + "operationId": "ListOffboardingProgress", + "tags": [ + "Identity > Administration > Users" + ], + "description": "Returns the progress rows of an offboarding job started from the wizard: one row per user with\nits overall status and the status and message of every step. Same rows as ListAsyncDeployment.\nThis is a read-only GET, so it carries a read role; an offboarding operator (who holds the\nbroader user write role) can still follow and re-run their jobs.", + "parameters": [ + { + "name": "DeploymentId", + "in": "query", + "description": "The DeploymentId handed back by ExecOffboardUser, also stored on each offboarding task", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Not described statically: this endpoint returns the upstream response as-is, so its fields are determined by the upstream API rather than by CIPP. Call the endpoint to see the actual shape, or add a response schema in backend/Config/openapi-overrides." + } + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Identity.User.Read", + "x-cipp-any-tenant": true + } + }, "/api/ListOffboardTenants": { "post": { "summary": "ListOffboardTenants", @@ -50802,93 +53092,35 @@ "x-cipp-role": "Identity.User.Read" } }, - "/api/ListPotentialApps": { - "post": { - "summary": "ListPotentialApps", - "operationId": "ListPotentialApps", - "tags": [ - "Endpoint > Applications" - ], - "description": "Searches application repositories (WinGet, Chocolatey) for available applications matching a search string.", - "requestBody": { - "required": false, - "content": { - "application/json": { - "schema": { - "type": "object", - "properties": { - "SearchString": { - "type": "string" - }, - "type": { - "type": "string", - "x-cipp-observed-values": [ - "Choco", - "WinGet" - ] - } - } - } - } - } - }, - "responses": { - "200": { - "description": "Success", - "content": { - "application/json": { - "schema": { - "type": "array", - "items": { - "type": "object", - "description": "Derived from the fields the endpoint selects onto each record. The response may carry more; these are the ones known to exist.", - "properties": { - "applicationName": { - "x-cipp-field-source": "backend" - }, - "packagename": { - "x-cipp-field-source": "backend" - } - } - } - } - } - } - }, - "401": { - "description": "Unauthorized - invalid or missing bearer token" - }, - "403": { - "description": "Forbidden - caller lacks the required RBAC role" - } - }, - "security": [ - { - "bearerAuth": [] - } - ], - "x-cipp-role": "Endpoint.Application.Read" - } - }, - "/api/ListQuarantinePolicy": { + "/api/ListPIMRoles": { "get": { - "summary": "ListQuarantinePolicy", - "operationId": "ListQuarantinePolicy", + "summary": "List Entra directory roles grouped with their PIM assignment breakdown.", + "operationId": "ListPIMRoles", "tags": [ - "Email-Exchange > Spamfilter" + "Identity > Administration > Roles" ], - "description": "Lists quarantine policies configured in Exchange Online Protection, controlling end-user access to quarantined messages.", + "description": "Returns one row per role (per tenant when AllTenants is selected) with the role's definition details, how many principals hold it permanently, eligibly or with a time-bound active assignment, the role's PIM policy summary, a slim Members list and the full assignment rows for drill-in. Roles nobody holds are included for a single tenant so the result is also the role catalogue. Powers the Roles & PIM page; ListRoles keeps its original per-definition shape and ListRoleAssignments stays one flat row per assignment.", "parameters": [ { - "$ref": "#/components/parameters/tenantFilter" + "name": "principalId", + "in": "query", + "description": "Restrict to the roles one principal (object id) holds.", + "required": false, + "schema": { + "type": "string" + } }, { - "name": "Type", + "name": "roleTemplateId", "in": "query", + "description": "Restrict to one role template id, e.g. from an alert link.", "required": false, "schema": { "type": "string" } + }, + { + "$ref": "#/components/parameters/tenantFilter" } ], "responses": { @@ -50900,131 +53132,427 @@ "type": "array", "items": { "type": "object", - "description": "Derived from the fields the endpoint selects onto each record, and the columns the CIPP UI renders. The response may carry more; these are the ones known to exist.", + "description": "Derived from the columns the CIPP UI renders. The response may carry more; these are the ones known to exist.", "properties": { - "AllowSender": { + "ActiveCount": { "x-cipp-field-source": "frontend" }, - "BlockSender": { + "AssignmentType": { "x-cipp-field-source": "frontend" }, - "Builtin": { - "x-cipp-field-source": "backend" - }, - "Delete": { + "EligibleCount": { "x-cipp-field-source": "frontend" }, - "IncludeMessagesFromBlockedSenderAddress": { + "EndDateTime": { "x-cipp-field-source": "frontend" }, - "Name": { + "IsPrivilegedRole": { "x-cipp-field-source": "frontend" }, - "Preview": { + "Members": { "x-cipp-field-source": "frontend" }, - "QuarantineNotification": { - "x-cipp-field-source": "backend,frontend" - }, - "ReleaseActionPreference": { - "x-cipp-field-source": "backend,frontend" - }, - "WhenChanged": { + "MemberType": { "x-cipp-field-source": "frontend" }, - "WhenCreated": { - "x-cipp-field-source": "frontend" - } - } - } - } - } - } - }, - "401": { - "description": "Unauthorized - invalid or missing bearer token" - }, - "403": { - "description": "Forbidden - caller lacks the required RBAC role" - } - }, - "security": [ - { - "bearerAuth": [] - } - ], - "x-cipp-role": "Exchange.SpamFilter.Read" - } - }, - "/api/ListReportBuilderTemplates": { - "get": { - "summary": "ListReportBuilderTemplates", - "operationId": "ListReportBuilderTemplates", - "tags": [ - "Tools > Report-Builder" - ], - "description": "Lists saved Report Builder templates that define custom report configurations with data blocks and formatting.", - "responses": { - "200": { - "description": "Success", - "content": { - "application/json": { - "schema": { - "type": "array", - "items": { - "type": "object", - "description": "Derived from the fields written into the storage table it reads, and the columns the CIPP UI renders. Fields taken from the storage writers may be omitted by this endpoint, and the response may carry computed fields not listed here.", - "properties": { - "CustomCount": { + "PermanentCount": { "x-cipp-field-source": "frontend" }, - "ETag": { - "type": "string", - "x-cipp-field-source": "storage" - }, - "GUID": { - "x-cipp-field-source": "storage" - }, - "JSON": { - "x-cipp-field-source": "storage" - }, - "Name": { + "PolicySummary": { "x-cipp-field-source": "frontend" }, - "Package": { - "x-cipp-field-source": "storage" - }, - "PartitionKey": { - "x-cipp-field-source": "storage" - }, - "Permissions": { - "type": "string", - "x-cipp-field-source": "storage" - }, - "RowKey": { - "x-cipp-field-source": "storage" - }, - "Sections": { + "PrincipalDisplayName": { "x-cipp-field-source": "frontend" }, - "SHA": { - "x-cipp-field-source": "storage" - }, - "Source": { - "x-cipp-field-source": "storage" + "PrincipalType": { + "x-cipp-field-source": "frontend" }, - "TemplateName": { - "x-cipp-field-source": "storage" + "PrincipalUserPrincipalName": { + "x-cipp-field-source": "frontend" }, - "TestCount": { + "RoleDisplayName": { "x-cipp-field-source": "frontend" }, - "Timestamp": { - "type": "string", - "x-cipp-field-source": "storage" + "Scope": { + "x-cipp-field-source": "frontend" }, - "UpdatedBy": { - "x-cipp-field-source": "storage" + "Tenant": { + "x-cipp-field-source": "frontend" + } + } + } + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Identity.Role.Read" + } + }, + "/api/ListPIMRoleSettingsTemplates": { + "get": { + "summary": "List PIM role settings templates.", + "operationId": "ListPIMRoleSettingsTemplates", + "tags": [ + "Identity > Administration > Roles" + ], + "description": "Lists saved Privileged Identity Management role settings templates. A template names a set of roles and the activation, eligibility, assignment, approval and notification rules to enforce on them; the PIMRoleSettings standard deploys a template to tenants.", + "parameters": [ + { + "name": "GUID", + "in": "query", + "description": "Return only the template with this GUID.", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "id", + "in": "query", + "description": "Return only the template with this GUID.", + "required": false, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the fields written into the storage table it reads, and the columns the CIPP UI renders. Fields taken from the storage writers may be omitted by this endpoint, and the response may carry computed fields not listed here.", + "properties": { + "ETag": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "GUID": { + "x-cipp-field-source": "storage" + }, + "JSON": { + "x-cipp-field-source": "storage" + }, + "meetsSecureFloor": { + "x-cipp-field-source": "frontend" + }, + "Package": { + "x-cipp-field-source": "storage" + }, + "PartitionKey": { + "x-cipp-field-source": "storage" + }, + "Permissions": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "roleCount": { + "x-cipp-field-source": "frontend" + }, + "roleScope": { + "x-cipp-field-source": "frontend" + }, + "RowKey": { + "x-cipp-field-source": "storage" + }, + "settings.activationMaxDuration": { + "x-cipp-field-source": "frontend" + }, + "settings.activationRequires": { + "x-cipp-field-source": "frontend" + }, + "settings.activationRequiresApproval": { + "x-cipp-field-source": "frontend" + }, + "settings.activeAssignmentMaxDuration": { + "x-cipp-field-source": "frontend" + }, + "settings.eligibilityMaxDuration": { + "x-cipp-field-source": "frontend" + }, + "SHA": { + "x-cipp-field-source": "storage" + }, + "Source": { + "x-cipp-field-source": "storage" + }, + "templateName": { + "x-cipp-field-source": "storage,frontend" + }, + "Timestamp": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "UpdatedBy": { + "x-cipp-field-source": "storage,frontend" + }, + "updatedDate": { + "x-cipp-field-source": "frontend" + } + } + } + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Identity.Role.Read", + "x-cipp-any-tenant": true + } + }, + "/api/ListPotentialApps": { + "post": { + "summary": "ListPotentialApps", + "operationId": "ListPotentialApps", + "tags": [ + "Endpoint > Applications" + ], + "description": "Searches application repositories (WinGet, Chocolatey) for available applications matching a search string.", + "requestBody": { + "required": false, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "SearchString": { + "type": "string" + }, + "type": { + "type": "string", + "x-cipp-observed-values": [ + "Choco", + "WinGet" + ] + } + } + } + } + } + }, + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the fields the endpoint selects onto each record. The response may carry more; these are the ones known to exist.", + "properties": { + "applicationName": { + "x-cipp-field-source": "backend" + }, + "packagename": { + "x-cipp-field-source": "backend" + } + } + } + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Endpoint.Application.Read" + } + }, + "/api/ListQuarantinePolicy": { + "get": { + "summary": "ListQuarantinePolicy", + "operationId": "ListQuarantinePolicy", + "tags": [ + "Email-Exchange > Spamfilter" + ], + "description": "Lists quarantine policies configured in Exchange Online Protection, controlling end-user access to quarantined messages.", + "parameters": [ + { + "$ref": "#/components/parameters/tenantFilter" + }, + { + "name": "Type", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the fields the endpoint selects onto each record, and the columns the CIPP UI renders. The response may carry more; these are the ones known to exist.", + "properties": { + "AllowSender": { + "x-cipp-field-source": "frontend" + }, + "BlockSender": { + "x-cipp-field-source": "frontend" + }, + "Builtin": { + "x-cipp-field-source": "backend" + }, + "Delete": { + "x-cipp-field-source": "frontend" + }, + "IncludeMessagesFromBlockedSenderAddress": { + "x-cipp-field-source": "frontend" + }, + "Name": { + "x-cipp-field-source": "frontend" + }, + "Preview": { + "x-cipp-field-source": "frontend" + }, + "QuarantineNotification": { + "x-cipp-field-source": "backend,frontend" + }, + "ReleaseActionPreference": { + "x-cipp-field-source": "backend,frontend" + }, + "WhenChanged": { + "x-cipp-field-source": "frontend" + }, + "WhenCreated": { + "x-cipp-field-source": "frontend" + } + } + } + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Exchange.SpamFilter.Read" + } + }, + "/api/ListReportBuilderTemplates": { + "get": { + "summary": "ListReportBuilderTemplates", + "operationId": "ListReportBuilderTemplates", + "tags": [ + "Tools > Report-Builder" + ], + "description": "Lists saved Report Builder templates that define custom report configurations with data blocks and formatting.", + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the fields written into the storage table it reads, and the columns the CIPP UI renders. Fields taken from the storage writers may be omitted by this endpoint, and the response may carry computed fields not listed here.", + "properties": { + "CustomCount": { + "x-cipp-field-source": "frontend" + }, + "ETag": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "GUID": { + "x-cipp-field-source": "storage" + }, + "JSON": { + "x-cipp-field-source": "storage" + }, + "Name": { + "x-cipp-field-source": "frontend" + }, + "Package": { + "x-cipp-field-source": "storage" + }, + "PartitionKey": { + "x-cipp-field-source": "storage" + }, + "Permissions": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "RowKey": { + "x-cipp-field-source": "storage" + }, + "Sections": { + "x-cipp-field-source": "frontend" + }, + "SHA": { + "x-cipp-field-source": "storage" + }, + "Source": { + "x-cipp-field-source": "storage" + }, + "TemplateName": { + "x-cipp-field-source": "storage" + }, + "TestCount": { + "x-cipp-field-source": "frontend" + }, + "Timestamp": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "UpdatedBy": { + "x-cipp-field-source": "storage" } } } @@ -51197,16 +53725,19 @@ "RestrictiveRetention": { "x-cipp-field-source": "frontend" }, - "RuleCount": { + "RetentionAction": { "x-cipp-field-source": "backend,frontend" }, - "WhenChangedUTC": { - "x-cipp-field-source": "frontend" + "RetentionDuration": { + "x-cipp-field-source": "backend,frontend" }, - "WhenCreatedUTC": { - "x-cipp-field-source": "frontend" + "RuleCount": { + "x-cipp-field-source": "backend,frontend" }, - "Workload": { + "ScopedLocations": { + "x-cipp-field-source": "backend,frontend" + }, + "WhenChangedUTC": { "x-cipp-field-source": "frontend" } } @@ -51332,6 +53863,88 @@ "x-cipp-any-tenant": true } }, + "/api/ListRoleAssignments": { + "get": { + "summary": "List Entra directory role assignments with their PIM assignment type.", + "operationId": "ListRoleAssignments", + "tags": [ + "Identity > Administration > Roles" + ], + "description": "Returns one row per principal, role and scope showing whether the assignment is Permanent (active with no end date), Active (time-bound), ActivatedFromEligible or Eligible, whether it is held directly or through a role-assignable group, the scope (directory or administrative unit), the principal type, the role's description and built-in flag, and the role's PIM policy summary. For a single tenant roles that nobody holds are included as Unassigned rows so the result is also the role catalogue. A single tenant is read live from Graph (Entra ID P2 tenants via PIM, others via unified RBAC where every assignment is permanent); AllTenants is served from the reporting cache.", + "parameters": [ + { + "name": "includeUnassigned", + "in": "query", + "description": "Single tenant: also list roles that nobody holds (AssignmentType 'Unassigned'), so the result is the full role catalogue. Default true; set to false for assignments only.", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "permanentOnly", + "in": "query", + "description": "Only return permanent (active, no end date) assignments.", + "required": false, + "schema": { + "type": "boolean" + } + }, + { + "name": "principalId", + "in": "query", + "description": "Restrict to one principal (object id), e.g. for the user view page.", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "roleTemplateId", + "in": "query", + "description": "Restrict to one role template id.", + "required": false, + "schema": { + "type": "string" + } + }, + { + "$ref": "#/components/parameters/tenantFilter" + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Not described statically: this endpoint returns the upstream response as-is, so its fields are determined by the upstream API rather than by CIPP. Call the endpoint to see the actual shape, or add a response schema in backend/Config/openapi-overrides." + } + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Identity.Role.Read" + } + }, "/api/ListRoles": { "get": { "summary": "ListRoles", @@ -52264,6 +54877,9 @@ "type": "string", "x-cipp-field-source": "storage" }, + "ExecutedTime": { + "x-cipp-field-source": "storage" + }, "Hidden": { "type": "boolean", "x-cipp-field-source": "storage" @@ -52287,6 +54903,14 @@ "type": "string", "x-cipp-field-source": "storage" }, + "PsaTicketId": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "PsaTicketPriority": { + "type": "string", + "x-cipp-field-source": "storage" + }, "PsaTicketStrategy": { "type": "string", "x-cipp-field-source": "storage" @@ -54619,6 +57243,56 @@ "x-cipp-role": "Sharepoint.Site.Read" } }, + "/api/ListSiteBrowserLibraryCopy": { + "get": { + "summary": "ListSiteBrowserLibraryCopy", + "operationId": "ListSiteBrowserLibraryCopy", + "tags": [ + "Teams-Sharepoint" + ], + "description": "Returns sanitized aggregate status for a SharePoint library copy operation (OperationId).", + "parameters": [ + { + "name": "OperationId", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + }, + { + "$ref": "#/components/parameters/tenantFilter" + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Sharepoint.Site.Read" + } + }, "/api/ListSiteBrowserPermissions": { "get": { "summary": "ListSiteBrowserPermissions", @@ -54964,6 +57638,64 @@ "x-cipp-role": "Sharepoint.SiteRecycleBin.Read" } }, + "/api/ListSiteRecycleBinSummary": { + "get": { + "summary": "ListSiteRecycleBinSummary", + "operationId": "ListSiteRecycleBinSummary", + "tags": [ + "Teams-Sharepoint" + ], + "description": "Aggregate recycle bin sizes for a site (counts + bytes by stage). Never returns\nitem titles, leaf names, or paths — storage-report privacy ceiling.", + "parameters": [ + { + "name": "MaxItems", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "SiteUrl", + "in": "query", + "required": true, + "schema": { + "type": "string" + } + }, + { + "$ref": "#/components/parameters/tenantFilter" + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Sharepoint.SiteRecycleBin.Read" + } + }, "/api/ListSiteRoleDefinitions": { "get": { "summary": "ListSiteRoleDefinitions", @@ -55029,7 +57761,7 @@ "tags": [ "Teams-Sharepoint" ], - "description": "Lists SharePoint sites or OneDrive usage for a tenant. Requires a Type parameter (SharePointSiteUsage or OneDriveUsageAccount). Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants.", + "description": "Lists SharePoint sites or OneDrive usage for a tenant. Requires a Type parameter (SharePointSiteUsage or OneDriveUsageAccount). SharePoint live data uses SPO admin RLD plus Graph enrichment; OneDrive live data uses Graph usage reports. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants.", "parameters": [ { "$ref": "#/components/parameters/tenantFilter" @@ -55146,6 +57878,56 @@ "x-cipp-role": "Sharepoint.Site.Read" } }, + "/api/ListSiteStorageComposition": { + "get": { + "summary": "ListSiteStorageComposition", + "operationId": "ListSiteStorageComposition", + "tags": [ + "Teams-Sharepoint" + ], + "description": "Site-level storage composition at library ceiling: tip / previous-version estimate /\nrecycle estimate from root web StorageMetrics + site StorageUsed. No file names.", + "parameters": [ + { + "name": "SiteUrl", + "in": "query", + "required": true, + "schema": { + "type": "string" + } + }, + { + "$ref": "#/components/parameters/tenantFilter" + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Sharepoint.Site.Read" + } + }, "/api/ListSiteUserAccess": { "get": { "summary": "ListSiteUserAccess", @@ -55868,7 +58650,7 @@ "SHA": { "x-cipp-field-source": "storage" }, - "source": { + "Source": { "x-cipp-field-source": "storage" }, "standards": { @@ -55918,6 +58700,78 @@ "x-cipp-any-tenant": true } }, + "/api/ListStorageCleanupScan": { + "get": { + "summary": "ListStorageCleanupScan", + "operationId": "ListStorageCleanupScan", + "tags": [ + "Teams-Sharepoint" + ], + "description": "Reads the hold-only StorageCleanupScan CIPPDB cache and rebuilds the scans map expected by\nthe storage report cleanup opportunity helpers. No live enumeration — refresh via\nExecCIPPDBCache Name=StorageCleanupScan. Report-private; not used by other List APIs.", + "parameters": [ + { + "$ref": "#/components/parameters/tenantFilter" + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the fields the endpoint selects onto each record. The response may carry more; these are the ones known to exist.", + "properties": { + "cleanupSynced": { + "x-cipp-field-source": "backend" + }, + "lastDataRefresh": { + "x-cipp-field-source": "backend" + }, + "librariesScanned": { + "x-cipp-field-source": "backend" + }, + "scans": { + "x-cipp-field-source": "backend" + }, + "sitesScanned": { + "x-cipp-field-source": "backend" + }, + "sitesSkipped": { + "x-cipp-field-source": "backend" + }, + "sitesWithRecycle": { + "x-cipp-field-source": "backend" + }, + "summary": { + "x-cipp-field-source": "backend" + } + } + } + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Sharepoint.Site.Read" + } + }, "/api/ListTeams": { "get": { "summary": "ListTeams", @@ -57303,6 +60157,9 @@ "type": "string", "x-cipp-field-source": "storage" }, + "StandardsExcludeAllTenants": { + "x-cipp-field-source": "storage" + }, "Status": { "x-cipp-field-source": "storage,frontend" }, @@ -58226,7 +61083,7 @@ "type": "array", "items": { "type": "object", - "description": "Derived from the fields the endpoint selects onto each record. The response may carry more; these are the ones known to exist.", + "description": "Derived from the fields written into the storage table it reads, and the fields the endpoint selects onto each record. Fields taken from the storage writers may be omitted by this endpoint, and the response may carry computed fields not listed here.", "properties": { "AdditionalEmailAddresses": { "x-cipp-field-source": "backend" @@ -58237,12 +61094,19 @@ "ComplianceTagHoldApplied": { "x-cipp-field-source": "backend" }, + "Data": { + "type": "string", + "x-cipp-field-source": "storage" + }, "DeliverToMailboxAndForward": { "x-cipp-field-source": "backend" }, "displayName": { "x-cipp-field-source": "backend" }, + "ETag": { + "x-cipp-field-source": "storage" + }, "ExchangeGuid": { "x-cipp-field-source": "backend" }, @@ -58285,6 +61149,9 @@ "MessageCopyForSentAsEnabled": { "x-cipp-field-source": "backend" }, + "PartitionKey": { + "x-cipp-field-source": "storage" + }, "primarySmtpAddress": { "x-cipp-field-source": "backend" }, @@ -58297,6 +61164,16 @@ "RetentionHoldEnabled": { "x-cipp-field-source": "backend" }, + "RowKey": { + "x-cipp-field-source": "storage" + }, + "Timestamp": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "Type": { + "x-cipp-field-source": "storage" + }, "UPN": { "x-cipp-field-source": "backend" }, @@ -58444,25 +61321,25 @@ "x-cipp-any-tenant": true } }, - "/api/ListUsers": { + "/api/ListUserReportedMessage": { "get": { - "summary": "ListUsers", - "operationId": "ListUsers", + "summary": "ListUserReportedMessage", + "operationId": "ListUserReportedMessage", "tags": [ - "Identity > Administration > Users" + "Email-Exchange > Spamfilter" ], - "description": "Lists Entra ID users for a tenant with license and sign-in details, or retrieves a specific user by ID. For AllTenants or cached data, consider using ListDBCache with type=Users for significantly better performance.", + "description": "Retrieves the raw EML content of a user reported message by its Internet Message ID. Tries the quarantine store first (Export-QuarantineMessage), then falls back to reading the message from the recipient's or reporter's mailbox via Graph.", "parameters": [ { - "name": "graphFilter", + "name": "InternetMessageId", "in": "query", - "required": false, + "required": true, "schema": { "type": "string" } }, { - "name": "IncludeLogonDetails", + "name": "RecipientEmail", "in": "query", "required": false, "schema": { @@ -58470,15 +61347,15 @@ } }, { - "$ref": "#/components/parameters/tenantFilter" - }, - { - "name": "UserID", + "name": "ReporterEmail", "in": "query", "required": false, "schema": { "type": "string" } + }, + { + "$ref": "#/components/parameters/tenantFilter" } ], "responses": { @@ -58490,7 +61367,546 @@ "type": "array", "items": { "type": "object", - "description": "Derived from the Microsoft Graph entity it queries, and the fields the endpoint selects onto each record. This endpoint returns the Graph response as-is without selecting fields, so these are the properties the entity CAN carry (x-cipp-field-source: graph-entity) rather than a proven projection - Graph returns a default subset unless asked otherwise.", + "description": "Derived from the Microsoft Graph entity it queries. This endpoint returns the Graph response as-is without selecting fields, so these are the properties the entity CAN carry (x-cipp-field-source: graph-entity) rather than a proven projection - Graph returns a default subset unless asked otherwise.", + "properties": { + "aboutMe": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "accountEnabled": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "ageGroup": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "assignedLicenses": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "assignedPlans": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "authorizationInfo": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "birthday": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "businessPhones": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "city": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "companyName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "consentProvidedForMinor": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "country": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "createdDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "creationType": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "customSecurityAttributes": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "deletedDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "department": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "deviceEnrollmentLimit": { + "type": "integer", + "x-cipp-field-source": "graph-entity" + }, + "displayName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "employeeHireDate": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "employeeId": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "employeeLeaveDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "employeeOrgData": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "employeeType": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "externalUserState": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "externalUserStateChangeDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "faxNumber": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "givenName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "hireDate": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "id": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "identities": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "identityParentId": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "imAddresses": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "interests": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "isManagementRestricted": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "isResourceAccount": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "jobTitle": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "lastPasswordChangeDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "legalAgeGroupClassification": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "licenseAssignmentStates": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "mail": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "mailboxSettings": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "mailNickname": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "mobilePhone": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "mySite": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "officeLocation": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesDistinguishedName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesDomainName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesExtensionAttributes": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesImmutableId": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesLastSyncDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesProvisioningErrors": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesSamAccountName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesSecurityIdentifier": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesSyncEnabled": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesUserPrincipalName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "otherMails": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "passwordPolicies": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "passwordProfile": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "pastProjects": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "postalCode": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "preferredDataLocation": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "preferredLanguage": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "preferredName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "print": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "provisionedPlans": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "proxyAddresses": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "responsibilities": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "schools": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "securityIdentifier": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "serviceProvisioningErrors": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "showInAddressList": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "signInActivity": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "signInSessionsValidFromDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "skills": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "state": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "streetAddress": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "surname": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "usageLocation": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "userPrincipalName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "userType": { + "type": "string", + "x-cipp-field-source": "graph-entity" + } + } + } + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Exchange.SpamFilter.Read" + } + }, + "/api/ListUserReportedMessages": { + "get": { + "summary": "ListUserReportedMessages", + "operationId": "ListUserReportedMessages", + "tags": [ + "Email-Exchange > Spamfilter" + ], + "description": "Lists user reported email threat submissions (Defender Submissions with source 'user') for a tenant.", + "parameters": [ + { + "$ref": "#/components/parameters/tenantFilter" + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the Microsoft Graph entity it queries, and the fields the endpoint selects onto each record, and the columns the CIPP UI renders. This endpoint returns the Graph response as-is without selecting fields, so these are the properties the entity CAN carry (x-cipp-field-source: graph-entity) rather than a proven projection - Graph returns a default subset unless asked otherwise.", + "properties": { + "adminReview": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "attackSimulationInfo": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "Category": { + "type": "object", + "x-cipp-field-source": "graph-entity,frontend" + }, + "clientSource": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "contentType": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "createdBy": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "createdDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "id": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "internetMessageId": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "Metadata": { + "x-cipp-field-source": "backend" + }, + "originalCategory": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "receivedDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "RecipientEmail": { + "x-cipp-field-source": "frontend" + }, + "recipientEmailAddress": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "ReportedBy": { + "x-cipp-field-source": "frontend" + }, + "ReportedDateTime": { + "x-cipp-field-source": "frontend" + }, + "result": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "ResultCategory": { + "x-cipp-field-source": "frontend" + }, + "Results": { + "x-cipp-field-source": "backend" + }, + "Sender": { + "type": "string", + "x-cipp-field-source": "graph-entity,frontend" + }, + "senderIP": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "source": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "Status": { + "type": "object", + "x-cipp-field-source": "graph-entity,frontend" + }, + "Subject": { + "type": "string", + "x-cipp-field-source": "graph-entity,frontend" + }, + "Tenant": { + "x-cipp-field-source": "frontend" + }, + "tenantAllowOrBlockListAction": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "tenantId": { + "type": "string", + "x-cipp-field-source": "graph-entity" + } + } + } + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Exchange.SpamFilter.Read" + } + }, + "/api/ListUsers": { + "get": { + "summary": "ListUsers", + "operationId": "ListUsers", + "tags": [ + "Identity > Administration > Users" + ], + "description": "Lists Entra ID users for a tenant with license and sign-in details, or retrieves a specific user by ID. For AllTenants or cached data, consider using ListDBCache with type=Users for significantly better performance.", + "parameters": [ + { + "name": "graphFilter", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "IncludeLogonDetails", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + }, + { + "$ref": "#/components/parameters/tenantFilter" + }, + { + "name": "UserID", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the Microsoft Graph entity it queries, and the fields the endpoint selects onto each record. This endpoint returns the Graph response as-is without selecting fields, so these are the properties the entity CAN carry (x-cipp-field-source: graph-entity) rather than a proven projection - Graph returns a default subset unless asked otherwise.", "properties": { "aboutMe": { "type": "string", @@ -59468,6 +62884,15 @@ "PartitionKey": { "x-cipp-field-source": "storage" }, + "PsaTicketId": { + "x-cipp-field-source": "storage" + }, + "PsaTicketPriority": { + "x-cipp-field-source": "storage" + }, + "Reference": { + "x-cipp-field-source": "storage" + }, "RowKey": { "x-cipp-field-source": "storage" }, @@ -61426,41 +64851,312 @@ "bearerAuth": [] } ], - "x-cipp-role": "Exchange.Connector.ReadWrite" + "x-cipp-role": "Exchange.Connector.ReadWrite" + } + }, + "/api/RemoveExConnectorTemplate": { + "post": { + "summary": "RemoveExConnectorTemplate", + "operationId": "RemoveExConnectorTemplate", + "tags": [ + "Email-Exchange > Transport" + ], + "requestBody": { + "required": false, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "ID": { + "type": "string" + } + } + } + } + } + }, + "parameters": [ + { + "name": "ID", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Exchange.Connector.ReadWrite", + "x-cipp-any-tenant": true + } + }, + "/api/RemoveGroupTemplate": { + "post": { + "summary": "RemoveGroupTemplate", + "operationId": "RemoveGroupTemplate", + "tags": [ + "Identity > Administration > Groups" + ], + "requestBody": { + "required": false, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "ID": { + "type": "string" + } + } + } + } + } + }, + "parameters": [ + { + "name": "ID", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Identity.Group.ReadWrite", + "x-cipp-any-tenant": true + } + }, + "/api/RemoveIntuneReusableSetting": { + "post": { + "summary": "RemoveIntuneReusableSetting", + "operationId": "RemoveIntuneReusableSetting", + "tags": [ + "Endpoint > MEM" + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "DisplayName": { + "type": "string" + }, + "ID": { + "type": "string" + }, + "tenantFilter": { + "type": "string" + } + }, + "required": [ + "ID", + "tenantFilter" + ] + } + } + } + }, + "parameters": [ + { + "name": "DisplayName", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "ID", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + }, + { + "$ref": "#/components/parameters/tenantFilter" + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Endpoint.MEM.ReadWrite" + } + }, + "/api/RemoveIntuneReusableSettingTemplate": { + "post": { + "summary": "RemoveIntuneReusableSettingTemplate", + "operationId": "RemoveIntuneReusableSettingTemplate", + "tags": [ + "Endpoint > MEM" + ], + "requestBody": { + "required": false, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "ID": { + "type": "string" + } + } + } + } + } + }, + "parameters": [ + { + "name": "ID", + "in": "query", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Endpoint.MEM.ReadWrite", + "x-cipp-any-tenant": true } }, - "/api/RemoveExConnectorTemplate": { + "/api/RemoveIntuneScript": { "post": { - "summary": "RemoveExConnectorTemplate", - "operationId": "RemoveExConnectorTemplate", + "summary": "RemoveIntuneScript", + "operationId": "RemoveIntuneScript", "tags": [ - "Email-Exchange > Transport" + "Endpoint > MEM" ], "requestBody": { - "required": false, + "required": true, "content": { "application/json": { "schema": { "type": "object", "properties": { + "DisplayName": { + "type": "string" + }, "ID": { "type": "string" + }, + "ScriptType": { + "type": "string", + "enum": [ + "Linux", + "MacOS", + "Remediation", + "Windows" + ] + }, + "TenantFilter": { + "type": "string", + "description": "Interact with query parameters or the body of the request." } - } + }, + "required": [ + "TenantFilter" + ] } } } }, - "parameters": [ - { - "name": "ID", - "in": "query", - "required": false, - "schema": { - "type": "string" - } - } - ], "responses": { "200": { "description": "Success", @@ -61477,9 +65173,6 @@ }, "403": { "description": "Forbidden - caller lacks the required RBAC role" - }, - "500": { - "description": "Internal server error" } }, "security": [ @@ -61487,16 +65180,15 @@ "bearerAuth": [] } ], - "x-cipp-role": "Exchange.Connector.ReadWrite", - "x-cipp-any-tenant": true + "x-cipp-role": "Endpoint.MEM.ReadWrite" } }, - "/api/RemoveGroupTemplate": { + "/api/RemoveIntuneTemplate": { "post": { - "summary": "RemoveGroupTemplate", - "operationId": "RemoveGroupTemplate", + "summary": "RemoveIntuneTemplate", + "operationId": "RemoveIntuneTemplate", "tags": [ - "Identity > Administration > Groups" + "Endpoint > MEM" ], "requestBody": { "required": false, @@ -61549,95 +65241,15 @@ "bearerAuth": [] } ], - "x-cipp-role": "Identity.Group.ReadWrite", - "x-cipp-any-tenant": true - } - }, - "/api/RemoveIntuneReusableSetting": { - "post": { - "summary": "RemoveIntuneReusableSetting", - "operationId": "RemoveIntuneReusableSetting", - "tags": [ - "Endpoint > MEM" - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "type": "object", - "properties": { - "DisplayName": { - "type": "string" - }, - "ID": { - "type": "string" - }, - "tenantFilter": { - "type": "string" - } - }, - "required": [ - "ID", - "tenantFilter" - ] - } - } - } - }, - "parameters": [ - { - "name": "DisplayName", - "in": "query", - "required": false, - "schema": { - "type": "string" - } - }, - { - "name": "ID", - "in": "query", - "required": false, - "schema": { - "type": "string" - } - }, - { - "$ref": "#/components/parameters/tenantFilter" - } - ], - "responses": { - "200": { - "description": "Success", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/StandardResults" - } - } - } - }, - "401": { - "description": "Unauthorized - invalid or missing bearer token" - }, - "403": { - "description": "Forbidden - caller lacks the required RBAC role" - } - }, - "security": [ - { - "bearerAuth": [] - } - ], "x-cipp-role": "Endpoint.MEM.ReadWrite" } }, - "/api/RemoveIntuneReusableSettingTemplate": { + "/api/RemoveJITAdminTemplate": { "post": { - "summary": "RemoveIntuneReusableSettingTemplate", - "operationId": "RemoveIntuneReusableSettingTemplate", + "summary": "RemoveJITAdminTemplate", + "operationId": "RemoveJITAdminTemplate", "tags": [ - "Endpoint > MEM" + "Identity > Administration > Users" ], "requestBody": { "required": false, @@ -61680,74 +65292,12 @@ }, "403": { "description": "Forbidden - caller lacks the required RBAC role" - } - }, - "security": [ - { - "bearerAuth": [] - } - ], - "x-cipp-role": "Endpoint.MEM.ReadWrite", - "x-cipp-any-tenant": true - } - }, - "/api/RemoveIntuneScript": { - "post": { - "summary": "RemoveIntuneScript", - "operationId": "RemoveIntuneScript", - "tags": [ - "Endpoint > MEM" - ], - "requestBody": { - "required": true, - "content": { - "application/json": { - "schema": { - "type": "object", - "properties": { - "DisplayName": { - "type": "string" - }, - "ID": { - "type": "string" - }, - "ScriptType": { - "type": "string", - "enum": [ - "Linux", - "MacOS", - "Remediation", - "Windows" - ] - }, - "TenantFilter": { - "type": "string", - "description": "Interact with query parameters or the body of the request." - } - }, - "required": [ - "TenantFilter" - ] - } - } - } - }, - "responses": { - "200": { - "description": "Success", - "content": { - "application/json": { - "schema": { - "$ref": "#/components/schemas/StandardResults" - } - } - } }, - "401": { - "description": "Unauthorized - invalid or missing bearer token" + "404": { + "description": "Not found" }, - "403": { - "description": "Forbidden - caller lacks the required RBAC role" + "500": { + "description": "Internal server error" } }, "security": [ @@ -61755,16 +65305,17 @@ "bearerAuth": [] } ], - "x-cipp-role": "Endpoint.MEM.ReadWrite" + "x-cipp-role": "Identity.Role.ReadWrite" } }, - "/api/RemoveIntuneTemplate": { + "/api/RemoveJITRoleTemplate": { "post": { - "summary": "RemoveIntuneTemplate", - "operationId": "RemoveIntuneTemplate", + "summary": "RemoveJITRoleTemplate", + "operationId": "RemoveJITRoleTemplate", "tags": [ - "Endpoint > MEM" + "Identity > Administration > Users" ], + "description": "Deletes a JIT Role Template.", "requestBody": { "required": false, "content": { @@ -61784,7 +65335,7 @@ { "name": "ID", "in": "query", - "required": false, + "required": true, "schema": { "type": "string" } @@ -61807,6 +65358,9 @@ "403": { "description": "Forbidden - caller lacks the required RBAC role" }, + "404": { + "description": "Not found" + }, "500": { "description": "Internal server error" } @@ -61816,16 +65370,17 @@ "bearerAuth": [] } ], - "x-cipp-role": "Endpoint.MEM.ReadWrite" + "x-cipp-role": "Identity.Role.ReadWrite" } }, - "/api/RemoveJITAdminTemplate": { + "/api/RemovePIMRoleSettingsTemplate": { "post": { - "summary": "RemoveJITAdminTemplate", - "operationId": "RemoveJITAdminTemplate", + "summary": "Delete a PIM role settings template.", + "operationId": "RemovePIMRoleSettingsTemplate", "tags": [ - "Identity > Administration > Users" + "Identity > Administration > Roles" ], + "description": "Deletes a saved Privileged Identity Management role settings template by GUID. Tenants already configured from the template keep their settings.", "requestBody": { "required": false, "content": { @@ -61833,8 +65388,13 @@ "schema": { "type": "object", "properties": { + "GUID": { + "type": "string", + "description": "GUID of the template to delete." + }, "ID": { - "type": "string" + "type": "string", + "description": "GUID of the template to delete." } } } @@ -61845,7 +65405,8 @@ { "name": "ID", "in": "query", - "required": true, + "description": "GUID of the template to delete.", + "required": false, "schema": { "type": "string" } @@ -61880,7 +65441,8 @@ "bearerAuth": [] } ], - "x-cipp-role": "Identity.Role.ReadWrite" + "x-cipp-role": "Identity.Role.ReadWrite", + "x-cipp-any-tenant": true } }, "/api/RemovePolicy": { @@ -63044,12 +66606,20 @@ "Tenant > Administration > Tenant" ], "requestBody": { - "required": false, + "required": true, "content": { "application/json": { "schema": { "type": "object", - "properties": {} + "properties": { + "defaultDomainName": { + "type": "string", + "description": "Get the tenant identifier from the request body (POST) or query (legacy GET)." + } + }, + "required": [ + "defaultDomainName" + ] } } } @@ -63058,8 +66628,8 @@ { "name": "defaultDomainName", "in": "query", - "description": "Get the tenant identifier from query parameters", - "required": true, + "description": "Get the tenant identifier from the request body (POST) or query (legacy GET).", + "required": false, "schema": { "type": "string" } @@ -63527,6 +67097,15 @@ "PartitionKey": { "x-cipp-field-source": "storage" }, + "PsaTicketId": { + "x-cipp-field-source": "storage" + }, + "PsaTicketPriority": { + "x-cipp-field-source": "storage" + }, + "Reference": { + "x-cipp-field-source": "storage" + }, "Results": { "x-cipp-field-source": "backend" }, diff --git a/Config/standards.json b/Config/standards.json index 57c45550d2fb6..5e79d23e0fcca 100644 --- a/Config/standards.json +++ b/Config/standards.json @@ -582,15 +582,23 @@ "name": "standards.AuthenticationMethods", "cat": "Entra (AAD) Standards", "tag": [], - "helpText": "Configures all authentication methods for the tenant including Microsoft Authenticator, FIDO2, SMS, Voice, Email OTP, Temporary Access Pass, Software OATH, Hardware OATH, Certificate-based, and QR Code Pin. Enable or disable each method and optionally target specific groups.", - "docsDescription": "Unified standard to configure all authentication method policies in a single place. Each method can be independently enabled or disabled, targeted to all users or specific groups using group name wildcards, and configured with method-specific settings such as TAP lifetime, QR code pin length, and Authenticator software OTP.", + "helpText": "Configures all authentication methods for the tenant including Microsoft Authenticator, FIDO2, SMS, Voice, Email OTP, Temporary Access Pass, Software OATH, Hardware OATH, Certificate-based, and QR Code Pin. Set each method to Enabled, Disabled or Not Configured and optionally target specific groups. Methods set to Not Configured (or left blank) keep the tenant's current setting.", + "docsDescription": "Unified standard to configure all authentication method policies in a single place. Each method can be independently set to Enabled, Disabled or Not Configured (leaving the tenant's current configuration untouched), targeted to all users or specific groups using group name wildcards, and configured with method-specific settings such as TAP lifetime, QR code pin length, and Authenticator software OTP.", "executiveText": "Provides centralized control over all tenant authentication methods from a single standard. Administrators can enable phishing-resistant methods like FIDO2 and Microsoft Authenticator while disabling less secure options like SMS and Voice. Each method supports group-level targeting using wildcard group names, allowing staged rollouts and granular control.", "addedComponent": [ { - "type": "switch", + "type": "autoComplete", + "multiple": false, + "creatable": false, + "required": false, "name": "standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled", "label": "Microsoft Authenticator", - "defaultValue": false + "helperText": "Not Configured or blank leaves the tenant's current setting untouched.", + "options": [ + { "label": "Enabled", "value": true }, + { "label": "Disabled", "value": false }, + { "label": "Not Configured", "value": "notConfigured" } + ] }, { "type": "textField", @@ -599,7 +607,7 @@ "required": false, "condition": { "field": "standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, @@ -610,7 +618,7 @@ "defaultValue": false, "condition": { "field": "standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, @@ -627,7 +635,7 @@ ], "condition": { "field": "standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, @@ -644,7 +652,7 @@ ], "condition": { "field": "standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, @@ -661,7 +669,7 @@ ], "condition": { "field": "standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, @@ -678,15 +686,23 @@ ], "condition": { "field": "standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, { - "type": "switch", + "type": "autoComplete", + "multiple": false, + "creatable": false, + "required": false, "name": "standards.AuthenticationMethods.FIDO2Enabled", "label": "FIDO2 Security Keys", - "defaultValue": false + "helperText": "Not Configured or blank leaves the tenant's current setting untouched.", + "options": [ + { "label": "Enabled", "value": true }, + { "label": "Disabled", "value": false }, + { "label": "Not Configured", "value": "notConfigured" } + ] }, { "type": "textField", @@ -695,15 +711,23 @@ "required": false, "condition": { "field": "standards.AuthenticationMethods.FIDO2Enabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, { - "type": "switch", + "type": "autoComplete", + "multiple": false, + "creatable": false, + "required": false, "name": "standards.AuthenticationMethods.TAPEnabled", "label": "Temporary Access Pass", - "defaultValue": false + "helperText": "Not Configured or blank leaves the tenant's current setting untouched.", + "options": [ + { "label": "Enabled", "value": true }, + { "label": "Disabled", "value": false }, + { "label": "Not Configured", "value": "notConfigured" } + ] }, { "type": "textField", @@ -712,7 +736,7 @@ "required": false, "condition": { "field": "standards.AuthenticationMethods.TAPEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, @@ -728,7 +752,7 @@ ], "condition": { "field": "standards.AuthenticationMethods.TAPEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, @@ -739,7 +763,7 @@ "defaultValue": 60, "condition": { "field": "standards.AuthenticationMethods.TAPEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, @@ -750,7 +774,7 @@ "defaultValue": 60, "condition": { "field": "standards.AuthenticationMethods.TAPEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, @@ -761,7 +785,7 @@ "defaultValue": 480, "condition": { "field": "standards.AuthenticationMethods.TAPEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, @@ -772,15 +796,23 @@ "defaultValue": 8, "condition": { "field": "standards.AuthenticationMethods.TAPEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, { - "type": "switch", + "type": "autoComplete", + "multiple": false, + "creatable": false, + "required": false, "name": "standards.AuthenticationMethods.SoftwareOathEnabled", "label": "Third-Party Software OATH Tokens", - "defaultValue": false + "helperText": "Not Configured or blank leaves the tenant's current setting untouched.", + "options": [ + { "label": "Enabled", "value": true }, + { "label": "Disabled", "value": false }, + { "label": "Not Configured", "value": "notConfigured" } + ] }, { "type": "textField", @@ -789,15 +821,23 @@ "required": false, "condition": { "field": "standards.AuthenticationMethods.SoftwareOathEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, { - "type": "switch", + "type": "autoComplete", + "multiple": false, + "creatable": false, + "required": false, "name": "standards.AuthenticationMethods.HardwareOathEnabled", "label": "Hardware OATH Tokens", - "defaultValue": false + "helperText": "Not Configured or blank leaves the tenant's current setting untouched.", + "options": [ + { "label": "Enabled", "value": true }, + { "label": "Disabled", "value": false }, + { "label": "Not Configured", "value": "notConfigured" } + ] }, { "type": "textField", @@ -806,15 +846,23 @@ "required": false, "condition": { "field": "standards.AuthenticationMethods.HardwareOathEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, { - "type": "switch", + "type": "autoComplete", + "multiple": false, + "creatable": false, + "required": false, "name": "standards.AuthenticationMethods.SMSEnabled", "label": "SMS", - "defaultValue": false + "helperText": "Not Configured or blank leaves the tenant's current setting untouched.", + "options": [ + { "label": "Enabled", "value": true }, + { "label": "Disabled", "value": false }, + { "label": "Not Configured", "value": "notConfigured" } + ] }, { "type": "textField", @@ -823,15 +871,23 @@ "required": false, "condition": { "field": "standards.AuthenticationMethods.SMSEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, { - "type": "switch", + "type": "autoComplete", + "multiple": false, + "creatable": false, + "required": false, "name": "standards.AuthenticationMethods.VoiceEnabled", "label": "Voice Call", - "defaultValue": false + "helperText": "Not Configured or blank leaves the tenant's current setting untouched.", + "options": [ + { "label": "Enabled", "value": true }, + { "label": "Disabled", "value": false }, + { "label": "Not Configured", "value": "notConfigured" } + ] }, { "type": "textField", @@ -840,15 +896,23 @@ "required": false, "condition": { "field": "standards.AuthenticationMethods.VoiceEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, { - "type": "switch", + "type": "autoComplete", + "multiple": false, + "creatable": false, + "required": false, "name": "standards.AuthenticationMethods.EmailEnabled", "label": "Email OTP", - "defaultValue": false + "helperText": "Not Configured or blank leaves the tenant's current setting untouched.", + "options": [ + { "label": "Enabled", "value": true }, + { "label": "Disabled", "value": false }, + { "label": "Not Configured", "value": "notConfigured" } + ] }, { "type": "textField", @@ -857,15 +921,23 @@ "required": false, "condition": { "field": "standards.AuthenticationMethods.EmailEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, { - "type": "switch", + "type": "autoComplete", + "multiple": false, + "creatable": false, + "required": false, "name": "standards.AuthenticationMethods.x509CertificateEnabled", "label": "Certificate-Based Authentication", - "defaultValue": false + "helperText": "Not Configured or blank leaves the tenant's current setting untouched.", + "options": [ + { "label": "Enabled", "value": true }, + { "label": "Disabled", "value": false }, + { "label": "Not Configured", "value": "notConfigured" } + ] }, { "type": "textField", @@ -874,15 +946,23 @@ "required": false, "condition": { "field": "standards.AuthenticationMethods.x509CertificateEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, { - "type": "switch", + "type": "autoComplete", + "multiple": false, + "creatable": false, + "required": false, "name": "standards.AuthenticationMethods.QRCodePinEnabled", "label": "QR Code Pin", - "defaultValue": false + "helperText": "Not Configured or blank leaves the tenant's current setting untouched.", + "options": [ + { "label": "Enabled", "value": true }, + { "label": "Disabled", "value": false }, + { "label": "Not Configured", "value": "notConfigured" } + ] }, { "type": "textField", @@ -891,7 +971,7 @@ "required": false, "condition": { "field": "standards.AuthenticationMethods.QRCodePinEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, @@ -902,7 +982,7 @@ "defaultValue": 365, "condition": { "field": "standards.AuthenticationMethods.QRCodePinEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } }, @@ -913,7 +993,7 @@ "defaultValue": 8, "condition": { "field": "standards.AuthenticationMethods.QRCodePinEnabled", - "compareType": "is", + "compareType": "valueEq", "compareValue": true } } @@ -999,7 +1079,8 @@ "labelField": "TemplateName", "valueField": "TemplateId", "queryKey": "StdAppApprovalTemplateList", - "addedField": { "AppId": "AppId" } + "addedField": { "AppId": "AppId" }, + "templateView": { "title": "App Approval Template" } }, "condition": { "field": "standards.AppDeploy.mode", @@ -1353,6 +1434,32 @@ "powershellEquivalent": "Update-MgBetaPolicyCrossTenantAccessPolicyDefault", "recommendedBy": [] }, + { + "name": "standards.ExternalComplianceTrusted", + "cat": "Entra (AAD) Standards", + "tag": [], + "helpText": "Sets the state of the Cross-tenant access setting to trust external compliant devices. This allows guest users to use a compliant device from their home tenant to access your tenant.", + "executiveText": "Allows external partners and vendors to use compliant devices from their own organization when accessing company resources, streamlining collaboration while maintaining security standards. This reduces friction for external users while ensuring their devices still meet compliance requirements.", + "addedComponent": [ + { + "type": "autoComplete", + "multiple": false, + "creatable": false, + "label": "Select value", + "name": "standards.ExternalComplianceTrusted.state", + "options": [ + { "label": "Enabled", "value": "true" }, + { "label": "Disabled", "value": "false" } + ] + } + ], + "label": "Sets the Cross-tenant access setting to trust external compliant devices", + "impact": "Low Impact", + "impactColour": "info", + "addedDate": "2026-08-25", + "powershellEquivalent": "Update-MgBetaPolicyCrossTenantAccessPolicyDefault", + "recommendedBy": [] + }, { "name": "standards.DisableTenantCreation", "cat": "Entra (AAD) Standards", @@ -1661,7 +1768,7 @@ "cat": "Entra (AAD) Standards", "tag": ["SMB1001 (2.8)"], "appliesToTest": ["SMB1001_2_8", "ZTNA21858"], - "helpText": "Blocks login for guest users that have not logged in for a number of days", + "helpText": "Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone.", "executiveText": "Automatically disables external guest accounts that haven't been used for a number of days, reducing security risks from dormant accounts while maintaining access for active external collaborators. This helps maintain a clean user directory and reduces potential attack vectors.", "addedComponent": [ { @@ -1670,6 +1777,12 @@ "required": true, "defaultValue": 90, "label": "Days of inactivity" + }, + { + "type": "switch", + "name": "standards.DisableGuests.IncludeNeverSignedIn", + "label": "Disable accounts that have not yet signed in", + "defaultValue": false } ], "label": "Disable Guest accounts that have not logged on for a number of days", @@ -2128,6 +2241,16 @@ "type": "textField", "name": "standards.OutBoundSpamAlert.OutboundSpamContact", "label": "Outbound spam contact" + }, + { + "type": "switch", + "name": "standards.OutBoundSpamAlert.BccSuspiciousOutboundMail", + "label": "BCC suspicious outbound mail to a mailbox" + }, + { + "type": "textField", + "name": "standards.OutBoundSpamAlert.BccSuspiciousOutboundContact", + "label": "BCC recipient for suspicious outbound mail" } ], "label": "Set Outbound Spam Alert e-mail", @@ -3322,7 +3445,7 @@ "tag": ["CIS M365 7.0.0 (8.6.1)"], "appliesToTest": ["CIS_8_6_1"], "helpText": "Set the state of the spam submission button in Outlook", - "docsDescription": "Set the state of the built-in Report button in Outlook. This gives the users the ability to report emails as spam or phish.", + "docsDescription": "Set the state of the built-in Report button in Outlook. This gives the users the ability to report emails as spam or phish. When a destination email address is set, the 'Send reported items to' setting controls whether reported messages go to Microsoft and the reporting mailbox, or to the reporting mailbox only (for third-party phishing report services).", "executiveText": "Enables employees to easily report suspicious emails directly from Outlook, helping improve the organization's spam and phishing detection systems. This crowdsourced approach to security allows users to contribute to threat detection while providing valuable feedback to enhance email security filters.", "addedComponent": [ { @@ -3340,6 +3463,16 @@ "name": "standards.UserSubmissions.email", "required": false, "label": "Destination email address" + }, + { + "type": "autoComplete", + "multiple": false, + "label": "Send reported items to (when a destination email address is set)", + "name": "standards.UserSubmissions.reportDestination", + "options": [ + { "label": "Microsoft and my reporting mailbox", "value": "Both" }, + { "label": "My reporting mailbox only", "value": "Mailbox" } + ] } ], "label": "Set the state of the built-in Report button in Outlook", @@ -4309,6 +4442,18 @@ } ] }, + { + "type": "autoComplete", + "required": false, + "multiple": false, + "creatable": false, + "label": "Bulk moves enabled (deliver bulk mail below the threshold to the Promotions folder - Preview)", + "name": "standards.SpamFilterPolicy.BulkMovesEnabled", + "options": [ + { "label": "On", "value": "On" }, + { "label": "Off", "value": "Off" } + ] + }, { "type": "autoComplete", "required": true, @@ -4779,7 +4924,7 @@ "cat": "Intune Standards", "tag": ["CIS M365 7.0.0 (4.2)", "CISA (MS.AAD.19.1v1)"], "appliesToTest": ["CIS_4_2"], - "helpText": "Sets the default platform restrictions for enrolling devices into Intune. Note: Do not block personally owned if platform is blocked.", + "helpText": "Sets the default platform restrictions for enrolling devices into Intune, including optional minimum and maximum OS version limits per platform (Android Enterprise, Android, iOS/iPadOS and Windows). Note: Do not block personally owned if platform is blocked.", "executiveText": "Controls which types of devices (iOS, Android, Windows, macOS) and ownership models (corporate vs. personal) can be enrolled in the company's device management system. This helps maintain security standards while supporting necessary business device types and usage scenarios.", "addedComponent": [ { @@ -4794,6 +4939,20 @@ "label": "Block personally owned Android Enterprise (work profile)", "default": false }, + { + "type": "textField", + "name": "standards.DefaultPlatformRestrictions.osMinimumVersionAndroidForWork", + "label": "Android Enterprise (work profile) minimum OS version", + "helperText": "Example: 11.0. Leave blank to not enforce a minimum.", + "required": false + }, + { + "type": "textField", + "name": "standards.DefaultPlatformRestrictions.osMaximumVersionAndroidForWork", + "label": "Android Enterprise (work profile) maximum OS version", + "helperText": "Example: 14.0. Leave blank to not enforce a maximum.", + "required": false + }, { "type": "switch", "name": "standards.DefaultPlatformRestrictions.platformAndroidBlocked", @@ -4806,6 +4965,20 @@ "label": "Block personally owned Android", "default": false }, + { + "type": "textField", + "name": "standards.DefaultPlatformRestrictions.osMinimumVersionAndroid", + "label": "Android minimum OS version", + "helperText": "Example: 10.0. Leave blank to not enforce a minimum.", + "required": false + }, + { + "type": "textField", + "name": "standards.DefaultPlatformRestrictions.osMaximumVersionAndroid", + "label": "Android maximum OS version", + "helperText": "Example: 13.0. Leave blank to not enforce a maximum.", + "required": false + }, { "type": "switch", "name": "standards.DefaultPlatformRestrictions.platformiOSBlocked", @@ -4818,6 +4991,20 @@ "label": "Block personally owned iOS", "default": false }, + { + "type": "textField", + "name": "standards.DefaultPlatformRestrictions.osMinimumVersioniOS", + "label": "iOS/iPadOS minimum OS version", + "helperText": "Example: 16.1. Leave blank to not enforce a minimum.", + "required": false + }, + { + "type": "textField", + "name": "standards.DefaultPlatformRestrictions.osMaximumVersioniOS", + "label": "iOS/iPadOS maximum OS version", + "helperText": "Example: 18.0. Leave blank to not enforce a maximum.", + "required": false + }, { "type": "switch", "name": "standards.DefaultPlatformRestrictions.platformMacOSBlocked", @@ -4841,6 +5028,20 @@ "name": "standards.DefaultPlatformRestrictions.personalWindowsBlocked", "label": "Block personally owned Windows", "default": false + }, + { + "type": "textField", + "name": "standards.DefaultPlatformRestrictions.osMinimumVersionWindows", + "label": "Windows minimum OS version", + "helperText": "Example: 10.0.19045.0. Leave blank to not enforce a minimum.", + "required": false + }, + { + "type": "textField", + "name": "standards.DefaultPlatformRestrictions.osMaximumVersionWindows", + "label": "Windows maximum OS version", + "helperText": "Example: 10.0.22631.0. Leave blank to not enforce a maximum.", + "required": false } ], "label": "Device enrollment restrictions", @@ -5261,6 +5462,40 @@ "ONEDRIVE_ENTERPRISE" ] }, + { + "name": "standards.SPGuestPeoplePicker", + "cat": "SharePoint Standards", + "tag": [], + "helpText": "Controls whether guest (external) users already in the tenant appear as suggestions in the SharePoint and OneDrive People Picker. Enforces the wanted state on BOTH the tenant default and every existing site collection - they are set independently, so changing the tenant default does not update existing sites. The per-site picture is read from the SharePoint reporting cache (refreshed daily), so a large tenant is never enumerated live during a run; a 24h rerun guard stops the write sweep from repeating before that cache refreshes and re-evaluates the result.", + "executiveText": "Makes existing external collaborators discoverable (or hidden) when sharing SharePoint and OneDrive content, consistently across the tenant default and every existing site. This keeps the sharing experience predictable and prevents individual sites from drifting away from the agreed collaboration posture.", + "addedComponent": [ + { + "type": "autoComplete", + "multiple": false, + "creatable": false, + "label": "Guest People Picker suggestions", + "name": "standards.SPGuestPeoplePicker.state", + "options": [ + { "label": "Show guests in the People Picker", "value": "true" }, + { "label": "Hide guests in the People Picker", "value": "false" } + ] + } + ], + "label": "Show guest users in the SharePoint People Picker", + "impact": "Low Impact", + "impactColour": "info", + "addedDate": "2026-09-03", + "powershellEquivalent": "Set-SPOTenant / Set-SPOSite -ShowPeoplePickerSuggestionsForGuestUsers $true or $false", + "recommendedBy": ["CIPP"], + "requiredCapabilities": [ + "SHAREPOINTWAC", + "SHAREPOINTSTANDARD", + "SHAREPOINTENTERPRISE", + "SHAREPOINTENTERPRISE_EDU", + "ONEDRIVE_BASIC", + "ONEDRIVE_ENTERPRISE" + ] + }, { "name": "standards.SPAzureB2B", "cat": "SharePoint Standards", @@ -5801,7 +6036,7 @@ "CIS_8_5_8", "CIS_8_5_9" ], - "helpText": "Defines the CIS recommended global meeting policy for Teams. This includes AllowAnonymousUsersToJoinMeeting, AllowAnonymousUsersToStartMeeting, AutoAdmittedUsers, AllowPSTNUsersToBypassLobby, MeetingChatEnabledType, DesignatedPresenterRoleMode, AllowExternalParticipantGiveRequestControl, AllowParticipantGiveRequestControl", + "helpText": "Defines the CIS recommended global meeting policy for Teams. This includes AllowAnonymousUsersToJoinMeeting, AllowAnonymousUsersToStartMeeting, AutoAdmittedUsers, AllowPSTNUsersToBypassLobby, MeetingChatEnabledType, DesignatedPresenterRoleMode, AllowExternalParticipantGiveRequestControl, AllowParticipantGiveRequestControl, AllowExternalNonTrustedMeetingChat, AllowCloudRecording", "executiveText": "Establishes security-focused default settings for Teams meetings, controlling who can join meetings, present content, and participate in chats. These policies balance collaboration needs with security requirements, ensuring meetings remain productive while protecting against unauthorized access and disruption.", "addedComponent": [ { @@ -5876,13 +6111,39 @@ "type": "switch", "name": "standards.TeamsGlobalMeetingPolicy.AllowExternalParticipantGiveRequestControl", "label": "External participants can give or request control" + }, + { + "type": "autoComplete", + "required": false, + "multiple": false, + "creatable": false, + "name": "standards.TeamsGlobalMeetingPolicy.AllowExternalNonTrustedMeetingChat", + "label": "External meeting chat", + "helperText": "CIS 8.5.8 recommends Off. Leave blank to keep the tenant's current value.", + "options": [ + { "label": "Off (CIS recommended)", "value": false }, + { "label": "On", "value": true } + ] + }, + { + "type": "autoComplete", + "required": false, + "multiple": false, + "creatable": false, + "name": "standards.TeamsGlobalMeetingPolicy.AllowCloudRecording", + "label": "Meeting cloud recording", + "helperText": "CIS 8.5.9 recommends Off. Leave blank to keep the tenant's current value.", + "options": [ + { "label": "Off (CIS recommended)", "value": false }, + { "label": "On", "value": true } + ] } ], "label": "Define Global Meeting Policy for Teams", "impact": "Low Impact", "impactColour": "info", "addedDate": "2024-11-12", - "powershellEquivalent": "Set-CsTeamsMeetingPolicy -AllowAnonymousUsersToJoinMeeting $false -AllowAnonymousUsersToStartMeeting $false -AutoAdmittedUsers $AutoAdmittedUsers -AllowPSTNUsersToBypassLobby $false -MeetingChatEnabledType EnabledExceptAnonymous -DesignatedPresenterRoleMode $DesignatedPresenterRoleMode -AllowExternalParticipantGiveRequestControl $false -AllowParticipantGiveRequestControl $false", + "powershellEquivalent": "Set-CsTeamsMeetingPolicy -AllowAnonymousUsersToJoinMeeting $false -AllowAnonymousUsersToStartMeeting $false -AutoAdmittedUsers $AutoAdmittedUsers -AllowPSTNUsersToBypassLobby $false -MeetingChatEnabledType EnabledExceptAnonymous -DesignatedPresenterRoleMode $DesignatedPresenterRoleMode -AllowExternalParticipantGiveRequestControl $false -AllowParticipantGiveRequestControl $false -AllowExternalNonTrustedMeetingChat $false -AllowCloudRecording $false", "recommendedBy": ["CIS"], "requiredCapabilities": ["MCOSTANDARD", "MCOEV", "MCOIMP", "TEAMS1", "Teams_Room_Standard"] }, @@ -8092,7 +8353,8 @@ "url": "/api/ListAppTemplates", "labelField": "displayName", "valueField": "GUID", - "queryKey": "StdIntuneAppTemplateList" + "queryKey": "StdIntuneAppTemplateList", + "templateView": { "title": "Application Template" } } } ], @@ -8493,5 +8755,50 @@ "warn": false, "remediate": false } + }, + { + "name": "standards.PIMRoleSettings", + "label": "PIM Role Settings Template", + "cat": "Templates", + "multiple": true, + "disabledFeatures": { + "report": false, + "warn": false, + "remediate": false + }, + "impact": "High Impact", + "impactColour": "danger", + "addedDate": "2026-08-23", + "tag": [], + "helpText": "Deploys a Privileged Identity Management role settings template to the tenant: activation limits, MFA or authentication context, justification, approval, eligibility and active-assignment expiry and notification rules for the roles the template covers. Templates cannot weaken settings below CIPP's secure floor.", + "docsDescription": "Deploys a Privileged Identity Management role settings template to the tenant. The template defines, for a set of roles, the maximum activation duration, whether activation requires MFA or an authentication context, justification, ticket and approval requirements, the maximum lifetime of eligible and active assignments, and additional notification recipients. Templates are validated against CIPP's secure floor (activation within 24 hours with MFA or an authentication context and a justification; eligible and active assignments must expire within a year; active assignments require a justification) and are refused, not adjusted, when they fall below it. Requires Entra ID P2.", + "executiveText": "Enforces consistent Privileged Identity Management settings so that administrator roles can only be used for a limited time, after strong authentication and with a recorded reason. This keeps standing administrative access to a minimum and makes every use of privilege visible and accountable.", + "addedComponent": [ + { + "type": "autoComplete", + "name": "TemplateList", + "multiple": false, + "required": true, + "creatable": false, + "label": "Select PIM Role Settings Template", + "api": { + "url": "/api/ListPIMRoleSettingsTemplates", + "labelField": "templateName", + "valueField": "GUID", + "queryKey": "ListPIMRoleSettingsTemplates", + "showRefresh": true, + "templateView": { + "title": "PIM Role Settings Template" + } + } + } + ], + "powershellEquivalent": "Update-MgBetaPolicyRoleManagementPolicyRule", + "recommendedBy": [ + "CIPP" + ], + "requiredCapabilities": [ + "AAD_PREMIUM_P2" + ] } ] diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/BEC/Push-BECRun.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/BEC/Push-BECRun.ps1 index d4f9a8b2f814c..2fda2e5351d42 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/BEC/Push-BECRun.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/BEC/Push-BECRun.ps1 @@ -456,7 +456,25 @@ if (-not $IntuneResponse) { $IntuneDevicesError = 'Intune device query did not return a response' } elseif ([int]$IntuneResponse.status -ge 400) { - $IntuneDevicesError = $IntuneResponse.body.error.message + # Graph proxies this call to Intune's DeviceFE service, which returns its own JSON + # error blob as the Graph error message. Unwrap it so the report shows a readable + # sentence instead of raw JSON, keeping the Activity ID for Microsoft support cases. + $RawIntuneError = $IntuneResponse.body.error.message + $IntuneDevicesError = $RawIntuneError + if ($RawIntuneError -match '^\s*\{') { + try { + $ParsedIntuneError = $RawIntuneError | ConvertFrom-Json -ErrorAction Stop + if (-not [string]::IsNullOrWhiteSpace($ParsedIntuneError.Message)) { + $IntuneDevicesError = $ParsedIntuneError.Message + } + } catch { + # Not valid JSON after all - keep the raw message + } + } + if ($IntuneDevicesError -like 'An error has occurred*') { + $ActivityId = [regex]::Match($IntuneDevicesError, 'Activity ID: ([0-9a-fA-F-]{36})').Groups[1].Value + $IntuneDevicesError = "Intune returned an unexpected error (HTTP $($IntuneResponse.status)). This is a failure inside the Intune service itself - usually transient, or the tenant does not have Intune provisioned. Rerun the check to retry.$(if ($ActivityId) { " Microsoft support reference (Activity ID): $ActivityId" })" + } if ([string]::IsNullOrWhiteSpace($IntuneDevicesError)) { $IntuneDevicesError = "Intune device query failed with status $($IntuneResponse.status)" } @@ -518,15 +536,19 @@ foreach ($Row in (@($RuleChangesLog) + @($SafelistChanges) + @($SharingChanges))) { $Geo = & $GetGeo $Row.ClientIP - $Row | Add-Member -NotePropertyName 'Country' -NotePropertyValue $Geo.CountryOrRegion -Force - $Row | Add-Member -NotePropertyName 'City' -NotePropertyValue $Geo.City -Force - $Row | Add-Member -NotePropertyName 'ForeignLocation' -NotePropertyValue (& $TestForeign $Geo.CountryOrRegion) -Force + $Row | Add-Member -NotePropertyMembers ([ordered]@{ + Country = $Geo.CountryOrRegion + City = $Geo.City + ForeignLocation = (& $TestForeign $Geo.CountryOrRegion) + }) -Force } foreach ($Row in @($SentMessages)) { $Geo = & $GetGeo $Row.FromIP - $Row | Add-Member -NotePropertyName 'Country' -NotePropertyValue $Geo.CountryOrRegion -Force - $Row | Add-Member -NotePropertyName 'City' -NotePropertyValue $Geo.City -Force - $Row | Add-Member -NotePropertyName 'ForeignLocation' -NotePropertyValue (& $TestForeign $Geo.CountryOrRegion) -Force + $Row | Add-Member -NotePropertyMembers ([ordered]@{ + Country = $Geo.CountryOrRegion + City = $Geo.City + ForeignLocation = (& $TestForeign $Geo.CountryOrRegion) + }) -Force } foreach ($Row in @($SuspectUserSignIns)) { $Row | Add-Member -NotePropertyName 'ForeignLocation' -NotePropertyValue (& $TestForeign $Row.Country) -Force diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Domain Analyser/Push-DomainAnalyserTenant.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Domain Analyser/Push-DomainAnalyserTenant.ps1 index 24d9c31535dfb..20bba052712a5 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Domain Analyser/Push-DomainAnalyserTenant.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Domain Analyser/Push-DomainAnalyserTenant.ps1 @@ -109,8 +109,10 @@ function Push-DomainAnalyserTenant { $Domain.MailProviders = $OldDomain.MailProviders } # Fix tenant info in the event of a default domain name change in a tenant - $Domain | Add-Member -MemberType NoteProperty -Name 'TenantId' -Value $TenantDomain.Tenant -Force - $Domain | Add-Member -MemberType NoteProperty -Name 'TenantGUID' -Value $TenantDomain.TenantGUID -Force + $Domain | Add-Member -NotePropertyMembers ([ordered]@{ + TenantId = $TenantDomain.Tenant + TenantGUID = $TenantDomain.TenantGUID + }) -Force } # Return domain object to list $TenantDomainObjects.Add($Domain) diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Mailbox Permissions/Push-GetCalendarPermissionsBatch.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Mailbox Permissions/Push-GetCalendarPermissionsBatch.ps1 index 66424361f4b18..d95878b545a93 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Mailbox Permissions/Push-GetCalendarPermissionsBatch.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Mailbox Permissions/Push-GetCalendarPermissionsBatch.ps1 @@ -29,6 +29,10 @@ function Push-GetCalendarPermissionsBatch { try { $CacheEntries = Get-CIPPAzDataTableEntity @FolderCacheTable -Filter "PartitionKey eq '$TenantFilter'" foreach ($Entry in $CacheEntries) { + # Entries predating the FolderType fix can name a subfolder instead of the root, + # and the name alone cannot say which. Anything unstamped is a miss: Phase 1 + # rediscovers it and overwrites the row, so a poisoned cache self-heals. + if ($Entry.FolderType -ne 'Calendar') { continue } $CachedFolders[$Entry.RowKey] = $Entry.FolderName } Write-Information "CAL Cached Folders count is $($CachedFolders.Count)" @@ -70,23 +74,37 @@ function Push-GetCalendarPermissionsBatch { } Write-Information "Phase 1: Bulk Get-MailboxFolderStatistics for $($CacheMissMailboxes.Count) mailboxes" - $FolderStatsResults = New-ExoBulkRequest -tenantid $TenantFilter -cmdletArray @($FolderStatsRequests) - + $FolderStatsResults = New-ExoBulkRequest -tenantid $TenantFilter -cmdletArray @($FolderStatsRequests) -Select 'Name,FolderType' + + # One call returns EVERY calendar folder flattened under one OperationGuid, so + # last-wins cached whatever the mailbox listed last - 'United States holidays' for + # over half a tenant, after which Phase 2 queried that folder and got nothing. + # FolderType stays English in any mailbox language, same reason + # Invoke-ListCalendarPermissions uses it. No fallback on purpose: a guess here + # poisons a cache that never expires. foreach ($Result in $FolderStatsResults) { if ($Result.error) { Write-Information "Failed to get folder stats for $($Result.OperationGuid): $($Result.error)" continue } $MailboxUPN = $Result.OperationGuid - $FolderName = $Result.name - if ($MailboxUPN -and $FolderName) { - $FolderNameMap[$MailboxUPN] = $FolderName - $NewCacheEntries.Add(@{ - PartitionKey = $TenantFilter - RowKey = $MailboxUPN - FolderName = $FolderName - }) - } + if (-not $MailboxUPN -or -not $Result.Name -or $Result.FolderType -ne 'Calendar') { continue } + if ($FolderNameMap.ContainsKey($MailboxUPN)) { continue } + + $FolderNameMap[$MailboxUPN] = $Result.Name + $NewCacheEntries.Add(@{ + PartitionKey = $TenantFilter + RowKey = $MailboxUPN + FolderName = $Result.Name + FolderType = 'Calendar' + }) + } + + # Loud on purpose: if the API stops returning FolderType, every mailbox fails the + # filter above and the whole type silently collects nothing. + $NoRootCalendar = $CacheMissMailboxes.Count - $NewCacheEntries.Count + if ($NoRootCalendar -gt 0) { + Write-Information "No root calendar folder (FolderType 'Calendar') found for $NoRootCalendar of $($CacheMissMailboxes.Count) cache-miss mailboxes" } # Persist newly discovered folder names to cache diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/OneDrive Long Paths/Push-DBCacheOneDriveLongPaths.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/OneDrive Long Paths/Push-DBCacheOneDriveLongPaths.ps1 new file mode 100644 index 0000000000000..0c5ab5b01badc --- /dev/null +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/OneDrive Long Paths/Push-DBCacheOneDriveLongPaths.ps1 @@ -0,0 +1,225 @@ +function Push-DBCacheOneDriveLongPaths { + <# + .SYNOPSIS + Full-recount OneDrive path-length counts for one personal site (resumable). + + .DESCRIPTION + Walks the site default drive via Graph root/delta (no item webUrl). Measures decoded + cloud path length and inferred Windows sync full-path length in memory, increments + counts, discards path strings. Writes one anonymized OneDriveLongPaths row: + ownerPrincipalName, countOver260, countOver400. + + Checkpoints CurrentUri + running counts for timebox/throttle requeue. Does not use + deltaLink incremental count math — each run recounts from scratch (resume continues + the same full walk). + + .FUNCTIONALITY + Entrypoint + #> + [CmdletBinding()] + param($Item) + + $TenantFilter = [string]$Item.TenantFilter + $SiteId = [string]$Item.SiteId + $OwnerPrincipalName = [string]($Item.OwnerPrincipalName ?? '') + $ScanId = [string]$Item.ScanId + $RequeueCount = [int]($Item.RequeueCount ?? 0) + + $CacheType = 'OneDriveLongPaths' + $StateTable = Get-CippTable -tablename 'CippOneDriveLongPathsState' + $SafeTenant = ConvertTo-CIPPODataFilterValue -Value $TenantFilter -Type String + + # Superseded scan — overlapping ExecCIPPDBCache runs must not write. + $CurrentScan = Get-CIPPAzDataTableEntity @StateTable -Filter "PartitionKey eq '$SafeTenant' and RowKey eq 'scan'" + if (-not $CurrentScan -or [string]$CurrentScan.ScanId -ne $ScanId) { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "OneDrive long-paths: skipping superseded scan $ScanId" -sev Debug + return @() + } + + $SiteKeySegment = ($SiteId -replace '[/\\#?]', '_') -replace '[\u0000-\u001F\u007F-\u009F]', '' + $CheckpointRowKey = "chk-$SiteKeySegment" + + $TimeboxSeconds = 540 + if ($env:CIPPNG -eq 'true') { $TimeboxSeconds = 1100 } + if ($null -ne $env:CIPP_ONEDRIVE_LONGPATHS_TIMEBOX_SECONDS -and "$($env:CIPP_ONEDRIVE_LONGPATHS_TIMEBOX_SECONDS)" -ne '') { + $Parsed = 0 + if ([int]::TryParse("$($env:CIPP_ONEDRIVE_LONGPATHS_TIMEBOX_SECONDS)", [ref]$Parsed) -and $Parsed -ge 0) { + $TimeboxSeconds = $Parsed + } + } + + # Fixed length (C:\Users\ + \OneDrive - {org}\) computed once per tenant at fan-out; add UPN local-part after owner is known. + $FixedLength = [int]($Item.InferredLocalRootFixedLength ?? 0) + if ($FixedLength -le 0) { + $OrgDisplayName = [string]($Item.OrgDisplayName ?? 'Organization') + if ([string]::IsNullOrWhiteSpace($OrgDisplayName)) { $OrgDisplayName = 'Organization' } + $FixedLength = ('C:\Users\').Length + ("\OneDrive - $OrgDisplayName\").Length + } + $Stopwatch = [System.Diagnostics.Stopwatch]::StartNew() + + function Get-LongPathsCheckpoint { + $Row = Get-CIPPAzDataTableEntity @StateTable -Filter "PartitionKey eq '$SafeTenant' and RowKey eq '$CheckpointRowKey'" + if (-not $Row -or [string]$Row.ScanId -ne $ScanId) { return $null } + try { ($Row.StateJson | ConvertFrom-Json -ErrorAction Stop) } catch { $null } + } + + function Save-LongPathsCheckpoint { + param($State) + Add-CIPPAzDataTableEntity @StateTable -Entity @{ + PartitionKey = $TenantFilter + RowKey = $CheckpointRowKey + ScanId = $ScanId + StateJson = [string]($State | ConvertTo-Json -Depth 5 -Compress) + } -Force + } + + function Remove-LongPathsCheckpoint { + $Row = Get-CIPPAzDataTableEntity @StateTable -Filter "PartitionKey eq '$SafeTenant' and RowKey eq '$CheckpointRowKey'" + if ($Row) { Remove-CIPPAzDataTableEntity @StateTable -Entity $Row -Force } + } + + function Invoke-LongPathsRequeue { + param([int]$NextRequeueCount = $RequeueCount) + $ResumeItem = [PSCustomObject]@{} + foreach ($Property in $Item.PSObject.Properties) { + $ResumeItem | Add-Member -NotePropertyName $Property.Name -NotePropertyValue $Property.Value -Force + } + $ResumeItem | Add-Member -NotePropertyName 'RequeueCount' -NotePropertyValue $NextRequeueCount -Force + $null = Start-CIPPOrchestrator -InputObject ([PSCustomObject]@{ + Batch = @($ResumeItem) + OrchestratorName = "OneDriveLongPathsResume_$($TenantFilter)_$([guid]::NewGuid().ToString('N').Substring(0, 8))" + SkipLog = $true + }) + } + + function Invoke-LongPathsTimeboxRequeue { + param($State) + if ($Stopwatch.Elapsed.TotalSeconds -lt $TimeboxSeconds) { return $false } + Save-LongPathsCheckpoint -State $State + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "OneDrive long-paths: timebox reached for $OwnerPrincipalName; requeueing" -sev Debug + Invoke-LongPathsRequeue + return $true + } + + function Invoke-LongPathsThrottleRequeue { + param([string]$ErrorMessage, $State) + if ($ErrorMessage -notmatch 'throttl|too many requests|429') { return $false } + if ($RequeueCount -ge 6) { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "OneDrive long-paths: still throttled after $RequeueCount resumes for $OwnerPrincipalName; giving up this scan" -sev Warning + return $false + } + Save-LongPathsCheckpoint -State $State + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "OneDrive long-paths: throttled for $OwnerPrincipalName; requeueing (attempt $($RequeueCount + 1))" -sev Info + Invoke-LongPathsRequeue -NextRequeueCount ($RequeueCount + 1) + return $true + } + + try { + $Drive = $null + try { + $Drive = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/sites/$SiteId/drive?`$select=id,name,driveType,owner" -tenantid $TenantFilter -asapp $true + } catch { + if ($_.Exception.Message -match 'Access to this site has been blocked') { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'OneDrive long-paths: skipping locked OneDrive site' -sev Info + return @() + } + throw + } + + if (-not $Drive.id) { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'OneDrive long-paths: no default drive for site' -sev Debug + return @() + } + + if ([string]::IsNullOrWhiteSpace($OwnerPrincipalName)) { + $OwnerPrincipalName = [string]($Drive.owner.user.email ?? $Drive.owner.user.userPrincipalName ?? '') + } + if ([string]::IsNullOrWhiteSpace($OwnerPrincipalName)) { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'OneDrive long-paths: skipping site with unresolved owner UPN' -sev Debug + return @() + } + + $LocalPart = $OwnerPrincipalName + $At = $OwnerPrincipalName.IndexOf('@') + if ($At -gt 0) { $LocalPart = $OwnerPrincipalName.Substring(0, $At) } + $LocalRootLength = $FixedLength + $LocalPart.Length + + $DeltaSelect = 'id,name,parentReference,folder,file,deleted' + $FullDeltaUri = "https://graph.microsoft.com/beta/drives/$($Drive.id)/root/delta?`$select=$DeltaSelect&`$top=999" + + $CountOver260 = 0 + $CountOver400 = 0 + $Uri = $FullDeltaUri + + $Checkpoint = Get-LongPathsCheckpoint + if ($Checkpoint -and $Checkpoint.CurrentUri) { + $Uri = [string]$Checkpoint.CurrentUri + $CountOver260 = [int]($Checkpoint.CountOver260 ?? 0) + $CountOver400 = [int]($Checkpoint.CountOver400 ?? 0) + } + + while ($Uri) { + try { + $Page = New-GraphGetRequest -uri $Uri -tenantid $TenantFilter -asapp $true -noPagination $true -SkipValueExtraction + } catch { + $ErrorMessage = $_.Exception.Message + $State = @{ + CurrentUri = $Uri + CountOver260 = $CountOver260 + CountOver400 = $CountOver400 + } + if (Invoke-LongPathsThrottleRequeue -ErrorMessage $ErrorMessage -State $State) { return @() } + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "OneDrive long-paths: delta failed for ${OwnerPrincipalName}: $ErrorMessage" -sev Warning + return @() + } + + $Values = @($Page.value) + foreach ($PageItem in $Values) { + if ($PageItem.deleted) { continue } + if (-not $PageItem.file -and -not $PageItem.folder) { continue } + + $CloudLength = Get-CIPPDriveItemCloudPathLength -ParentPath ([string]$PageItem.parentReference.path) -Name ([string]$PageItem.name) + if ($CloudLength -le 0) { continue } + + if ($CloudLength -gt 400) { $CountOver400++ } + $InferredLocal = $LocalRootLength + $CloudLength + if ($InferredLocal -gt 260) { $CountOver260++ } + } + + $Next = $Page.'@odata.nextLink' + $DeltaDone = $Page.'@odata.deltaLink' + if ($Next) { + $Uri = [string]$Next + } elseif ($DeltaDone) { + # Full recount complete — do not store deltaLink for incremental counts. + $Uri = $null + } else { + $Uri = $null + } + + if ($Uri) { + $State = @{ + CurrentUri = $Uri + CountOver260 = $CountOver260 + CountOver400 = $CountOver400 + } + Save-LongPathsCheckpoint -State $State + if (Invoke-LongPathsTimeboxRequeue -State $State) { return @() } + } + } + + $Row = [PSCustomObject]@{ + id = $OwnerPrincipalName + ownerPrincipalName = $OwnerPrincipalName + countOver260 = [int]$CountOver260 + countOver400 = [int]$CountOver400 + } + Add-CIPPDbItem -TenantFilter $TenantFilter -Type $CacheType -Data @($Row) -Append -RunId $ScanId + Remove-LongPathsCheckpoint + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "OneDrive long-paths: cached counts for $OwnerPrincipalName (260=$CountOver260, 400=$CountOver400)" -sev Debug + return @() + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "OneDrive long-paths: site task failed: $($_.Exception.Message)" -sev Error -LogData (Get-CippException -Exception $_) + return @() + } +} diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/OneDrive Root Permissions/Push-DBCacheOneDriveRootPermissionsBatch.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/OneDrive Root Permissions/Push-DBCacheOneDriveRootPermissionsBatch.ps1 index 47e9f69b92c17..bbdf94bafe8a9 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/OneDrive Root Permissions/Push-DBCacheOneDriveRootPermissionsBatch.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/OneDrive Root Permissions/Push-DBCacheOneDriveRootPermissionsBatch.ps1 @@ -362,10 +362,10 @@ function Push-DBCacheOneDriveRootPermissionsBatch { $AssociatedGroupTitles = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) try { - $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter - $Scope = "$($SharePointInfo.SharePointUrl)/.default" - $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $Scope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri $AssociatedEndpoints = [ordered]@{ 'Owners' = 'associatedownergroup' diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPDBCacheData.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPDBCacheData.ps1 index a0bb9f7693082..188eecb36f3ae 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPDBCacheData.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPDBCacheData.ps1 @@ -67,10 +67,18 @@ function Push-CIPPDBCacheData { $DefenderCapable = $false try { - $DefenderCapable = Test-CIPPStandardLicense -StandardName Compliance'DefenderLicenseCheck' -TenantFilter $TenantFilter -RequiredCapabilities @('MDE_SMB', 'WIN_DEF_ATP', 'DEFENDER_ENDPOINT_P1') -SkipLog + $DefenderCapable = Test-CIPPStandardLicense -StandardName 'DefenderLicenseCheck' -TenantFilter $TenantFilter -RequiredCapabilities @('MDE_SMB', 'WIN_DEF_ATP', 'DEFENDER_ENDPOINT_P1') -SkipLog } catch { $ErrorMessage = Get-CippException -Exception $_ - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Compliance license check failed: $($_.Exception.Message)" -sev Warning -LogData $ErrorMessage + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Defender license check failed: $($_.Exception.Message)" -sev Warning -LogData $ErrorMessage + } + + $MdoCapable = $false + try { + $MdoCapable = Test-CIPPStandardLicense -StandardName 'DefenderForOffice365LicenseCheck' -TenantFilter $TenantFilter -Preset DefenderForOffice365 -SkipLog + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Defender for Office 365 license check failed: $($_.Exception.Message)" -sev Warning -LogData $ErrorMessage } $SharePointCapable = $false @@ -89,7 +97,7 @@ function Push-CIPPDBCacheData { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Teams license check failed: $($_.Exception.Message)" -sev Warning -LogData $ErrorMessage } - Write-Information "License capabilities for $TenantFilter - Intune: $IntuneCapable, CA: $ConditionalAccessCapable, P2: $AzureADPremiumP2Capable, Exchange: $ExchangeCapable, Compliance: $ComplianceCapable, SharePoint: $SharePointCapable, Teams: $TeamsCapable" + Write-Information "License capabilities for $TenantFilter - Intune: $IntuneCapable, CA: $ConditionalAccessCapable, P2: $AzureADPremiumP2Capable, Exchange: $ExchangeCapable, Compliance: $ComplianceCapable, SharePoint: $SharePointCapable, Teams: $TeamsCapable, MDO: $MdoCapable" # Build grouped collection tasks — one activity per license category instead of one per cache type $Tasks = [System.Collections.Generic.List[object]]::new() @@ -211,6 +219,18 @@ function Push-CIPPDBCacheData { Write-Host "Skipping Defender data collection for $TenantFilter - no required license" } + if ($MdoCapable) { + $Tasks.Add(@{ + FunctionName = 'ExecCIPPDBCache' + CollectionType = 'DefenderForOffice365' + TenantFilter = $TenantFilter + QueueId = $QueueId + QueueName = "DB Cache DefenderForOffice365 - $TenantFilter" + }) + } else { + Write-Host "Skipping Defender for Office 365 data collection for $TenantFilter - no required license" + } + if ($SharePointCapable) { $Tasks.Add(@{ FunctionName = 'ExecCIPPDBCache' @@ -219,7 +239,7 @@ function Push-CIPPDBCacheData { QueueId = $QueueId QueueName = "DB Cache SharePoint - $TenantFilter" }) - # SharePointSharingLinks runs adhoc since it can take a long time to enumerate all sharing links for large tenants + # SharePointSharingLinks and OneDriveLongPaths run adhoc — full drive walks are too slow for nightly } else { Write-Host "Skipping SharePoint data collection for $TenantFilter - no required license" } diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPOffboardingComplete.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPOffboardingComplete.ps1 index c848c0b147238..9ce7262e3494a 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPOffboardingComplete.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPOffboardingComplete.ps1 @@ -105,17 +105,68 @@ function Push-CIPPOffboardingComplete { Write-LogMessage -API 'Offboarding' -tenant $TenantFilter -message "Offboarding completed successfully for $Username" -sev Info -headers $Headers - # Send post-execution alerts if configured + # Send post-execution alerts if configured, and keep each delivery outcome with the task and + # on the progress row, so a failed webhook, email or PSA note is as visible as a failed step. if ($TaskInfo.PostExecution -and $ProcessedResults) { - Send-CIPPScheduledTaskAlert -Results $ProcessedResults -TaskInfo $TaskInfo -TenantFilter $TenantFilter -TaskType 'User Offboarding' + $DeploymentId = $Item.Parameters.DeploymentId + # The notification steps have been on the row since the job started; show them running + # while the deliveries are made, then fill each one in by title. + $NotifyIndexes = @{} + if ($DeploymentId) { + $Row = Get-CIPPAsyncDeployment -JobId $DeploymentId | Where-Object { $_.Name -eq $Username } + $RowSteps = @($Row.Steps) + for ($i = 0; $i -lt $RowSteps.Count; $i++) { + if ($RowSteps[$i].Kind -eq 'notify') { + $NotifyIndexes[[string]$RowSteps[$i].Title] = $i + Set-CIPPAsyncDeploymentStep -JobId $DeploymentId -Name $Username -StepIndex $i -StepStatus 'running' -Message 'Sending' + } + } + } + + $PostExecutionResults = @(Send-CIPPScheduledTaskAlert -Results $ProcessedResults -TaskInfo $TaskInfo -TenantFilter $TenantFilter -TaskType 'User Offboarding') + $null = Update-AzDataTableEntity -Force @Table -Entity @{ + PartitionKey = $TaskInfo.PartitionKey + RowKey = $TaskInfo.RowKey + PostExecutionResults = [string](ConvertTo-Json -Compress -Depth 5 -InputObject $PostExecutionResults) + } + + if ($DeploymentId) { + # One step per channel; the PSA channel can make several deliveries (per-user tickets). + $Covered = @{} + foreach ($Group in ($PostExecutionResults | Group-Object -Property Channel)) { + $Title = "Notify via $($Group.Name)" + $Message = @($Group.Group | ForEach-Object { [string]$_.Result }) -join "`n" + # Skipped = asked for and not delivered, so it fails the step. + $NotifyStatus = if (@($Group.Group | Where-Object { [string]$_.Result -match '^(Error|Could not|Failed|Skipped)' }).Count -gt 0) { 'failed' } else { 'succeeded' } + if ($NotifyIndexes.ContainsKey($Title)) { + $Covered[$Title] = $true + Set-CIPPAsyncDeploymentStep -JobId $DeploymentId -Name $Username -StepIndex $NotifyIndexes[$Title] -StepStatus $NotifyStatus -Message $Message + } else { + Add-CIPPAsyncDeploymentStep -JobId $DeploymentId -Name $Username -Title $Title -StepStatus $NotifyStatus -Message $Message -Kind 'notify' + } + } + # A channel that produced no delivery at all (the sender gave up before reaching it) + foreach ($Title in @($NotifyIndexes.Keys | Where-Object { -not $Covered.ContainsKey($_) })) { + Set-CIPPAsyncDeploymentStep -JobId $DeploymentId -Name $Username -StepIndex $NotifyIndexes[$Title] -StepStatus 'failed' -Message 'No delivery was attempted' + } + } } } + if ($Item.Parameters.DeploymentId) { + # Close the live-progress row: failed when any step failed, otherwise succeeded. + $Row = Get-CIPPAsyncDeployment -JobId $Item.Parameters.DeploymentId | Where-Object { $_.Name -eq $Username } + $FinalStatus = if (@($Row.Steps | Where-Object { $_.Status -eq 'failed' }).Count -gt 0) { 'failed' } else { 'succeeded' } + Set-CIPPAsyncDeploymentStatus -JobId $Item.Parameters.DeploymentId -Name $Username -Status $FinalStatus -Logs $StoredResults + } Write-LogMessage -API 'Offboarding' -tenant $TenantFilter -message "Offboarding completed for $Username" -sev Info -headers $Headers return "Offboarding completed for $Username" } catch { $ErrorMsg = "Failed to complete offboarding for $Username : $($_.Exception.Message)" Write-LogMessage -API 'Offboarding' -tenant $TenantFilter -message $ErrorMsg -sev Error -headers $Headers -LogData (Get-CippException -Exception $_) + if ($Item.Parameters.DeploymentId) { + Set-CIPPAsyncDeploymentStatus -JobId $Item.Parameters.DeploymentId -Name $Username -Status 'failed' -Logs $ErrorMsg + } throw $ErrorMsg } } diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPOffboardingTask.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPOffboardingTask.ps1 index eacb976bf70ed..9b92fc0fd3df1 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPOffboardingTask.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPOffboardingTask.ps1 @@ -4,7 +4,8 @@ function Push-CIPPOffboardingTask { Generic wrapper to execute individual offboarding task cmdlets .DESCRIPTION - Executes the specified cmdlet with the provided parameters as part of user offboarding + Executes the specified cmdlet with the provided parameters as part of user offboarding and, + when the job tracks live progress, reports the outcome to the step it was stamped with .FUNCTIONALITY Entrypoint @@ -14,9 +15,12 @@ function Push-CIPPOffboardingTask { $Cmdlet = $Item.Cmdlet $Parameters = $Item.Parameters | ConvertTo-Json -Depth 5 | ConvertFrom-Json -AsHashtable + # Live progress (optional): the job stamps each task with the status row and step it reports to + $Step = if ($Item.DeploymentId) { @{ JobId = $Item.DeploymentId; Name = $Item.DeploymentName; StepIndex = [int]$Item.StepIndex } } try { Write-Information "Executing offboarding cmdlet: $Cmdlet" + if ($Step) { Set-CIPPAsyncDeploymentStep @Step -StepStatus 'running' -Message 'In progress' } # Check if cmdlet exists $CmdletInfo = Get-Command -Name $Cmdlet -Module CIPPCore -ErrorAction SilentlyContinue @@ -28,11 +32,19 @@ function Push-CIPPOffboardingTask { $Result = & $Cmdlet @Parameters Write-Information "Completed $Cmdlet successfully" + if ($Step) { + # Most cmdlets report per-item problems as returned 'Error: ...' lines rather than throwing + # (group removal, for one), so a returned error line counts as a failed step. + $Lines = @($Result | ForEach-Object { [string]($_.resultText ?? $_) }) + $StepStatus = if (@($Lines | Where-Object { $_ -match '^\s*(Error|Failed)\b' }).Count -gt 0) { 'failed' } else { 'succeeded' } + Set-CIPPAsyncDeploymentStep @Step -StepStatus $StepStatus -Message ($Lines -join "`n") + } return $Result } catch { $ErrorMsg = "Failed to execute $Cmdlet : $($_.Exception.Message)" Write-Information $ErrorMsg + if ($Step) { Set-CIPPAsyncDeploymentStep @Step -StepStatus 'failed' -Message $ErrorMsg } return $ErrorMsg } } diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecJITAdminListAllTenants.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecJITAdminListAllTenants.ps1 index 2a4ec142805dc..79ffdb7bd551c 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecJITAdminListAllTenants.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecJITAdminListAllTenants.ps1 @@ -31,7 +31,7 @@ function Push-ExecJITAdminListAllTenants { $BulkRequests.Add(@{ id = $User.id method = 'GET' - url = "users/$($User.id)/memberOf/microsoft.graph.directoryRole/?`$select=id,displayName" + url = "users/$($User.id)/memberOf/microsoft.graph.directoryRole/?`$select=id,displayName,roleTemplateId" }) } # Ensure $BulkRequests is not empty or null before making the bulk request @@ -45,7 +45,7 @@ function Push-ExecJITAdminListAllTenants { if ($RoleResults) { $userRoleResult = $RoleResults | Where-Object -Property id -EQ $currentUser.id if ($userRoleResult -and $userRoleResult.body -and $userRoleResult.body.value) { - $MemberOf = $userRoleResult.body.value | Select-Object displayName, id + $MemberOf = $userRoleResult.body.value | Select-Object displayName, id, roleTemplateId } } @@ -61,6 +61,7 @@ function Push-ExecJITAdminListAllTenants { jitAdminEnabled = $jitAdminEnabled jitAdminExpiration = $jitAdminExpiration memberOf = ($MemberOf | ConvertTo-Json -Depth 5 -Compress) + roleTemplateIds = @($MemberOf.roleTemplateId | Where-Object { $_ }) } } diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecMdoAlertsListAllTenants.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecMdoAlertsListAllTenants.ps1 index 15cab5352f97a..7485073537ca7 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecMdoAlertsListAllTenants.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecMdoAlertsListAllTenants.ps1 @@ -10,8 +10,8 @@ function Push-ExecMdoAlertsListAllTenants { $Table = Get-CIPPTable -TableName 'cachealertsandincidents' try { - # Get MDO alerts using the specific endpoint and filter - $Alerts = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/security/alerts_v2?`$filter=serviceSource eq 'microsoftDefenderForOffice365'" -tenantid $domainName + # Get MDO and MDE alerts using the specific endpoint and filter + $Alerts = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/security/alerts_v2?`$filter=serviceSource eq 'microsoftDefenderForOffice365' or serviceSource eq 'microsoftDefenderForEndpoint'" -tenantid $domainName foreach ($Alert in $Alerts) { $GUID = (New-Guid).Guid diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecOnboardTenantQueue.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecOnboardTenantQueue.ps1 index 8b4dddb20c1ee..b1f17b64e77a5 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecOnboardTenantQueue.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecOnboardTenantQueue.ps1 @@ -13,6 +13,20 @@ function Push-ExecOnboardTenantQueue { $OnboardTable = Get-CIPPTable -TableName 'TenantOnboarding' $TenantOnboarding = Get-CIPPAzDataTableEntity @OnboardTable -Filter "RowKey eq '$Id'" + # Prefer Item flag; fall back to persisted onboarding row (poll/retry may omit it from Item) + $StandardsExcludeAllTenants = if ($Item.StandardsExcludeAllTenants -eq $true) { + $true + } else { + [bool]$TenantOnboarding.StandardsExcludeAllTenants + } + if ($StandardsExcludeAllTenants -eq $true) { + if ($TenantOnboarding.PSObject.Properties.Name -notcontains 'StandardsExcludeAllTenants') { + $TenantOnboarding | Add-Member -NotePropertyName 'StandardsExcludeAllTenants' -NotePropertyValue $true -Force + } else { + $TenantOnboarding.StandardsExcludeAllTenants = $true + } + } + $Logs.Add([PSCustomObject]@{ Date = (Get-Date).ToUniversalTime(); Log = "Starting onboarding for relationship $Id" }) $OnboardingSteps = $TenantOnboarding.OnboardingSteps | ConvertFrom-Json $OnboardingSteps.Step1.Status = 'running' @@ -358,7 +372,7 @@ function Push-ExecOnboardTenantQueue { AutoMapRoles = $Item.AutoMapRoles IgnoreMissingRoles = $Item.IgnoreMissingRoles AddMissingGroups = $Item.AddMissingGroups - StandardsExcludeAllTenants = $Item.StandardsExcludeAllTenants + StandardsExcludeAllTenants = $StandardsExcludeAllTenants } } $RetryTask = [PSCustomObject]@{ @@ -487,7 +501,7 @@ function Push-ExecOnboardTenantQueue { } if ($OnboardingSteps.Step4.Status -eq 'succeeded') { - if ($Item.StandardsExcludeAllTenants -eq $true) { + if ($StandardsExcludeAllTenants -eq $true) { $GroupTable = Get-CIPPTable -tablename 'TenantGroups' $MembersTable = Get-CIPPTable -tablename 'TenantGroupMembers' $ExclusionGroupName = 'Excluded onboarded tenants' @@ -542,14 +556,10 @@ function Push-ExecOnboardTenantQueue { } $NewExcludedTenants.Add($GroupExclusionObj) $object.excludedTenants = $NewExcludedTenants - $JSON = ConvertTo-Json -InputObject $object -Compress -Depth 10 + # Depth 100 like every other writer; write back the row read so its other columns survive. + $AllTenantsTemplate.JSON = ConvertTo-Json -InputObject $object -Compress -Depth 100 $TemplatesTable.Force = $true - Add-CIPPAzDataTableEntity @TemplatesTable -Entity @{ - JSON = "$JSON" - RowKey = $AllTenantsTemplate.RowKey - GUID = $AllTenantsTemplate.GUID - PartitionKey = 'StandardsTemplateV2' - } + Add-CIPPAzDataTableEntity @TemplatesTable -Entity $AllTenantsTemplate } } diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecScheduledCommand.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecScheduledCommand.ps1 index 9862a22073f6c..76642ac56c520 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecScheduledCommand.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecScheduledCommand.ps1 @@ -227,6 +227,24 @@ function Push-ExecScheduledCommand { Write-Information "Failed to remove parameters: $($_.Exception.Message)" } + # Stored parameters are user input: the command's tenant parameter is forced to the authorized + # task tenant so a stored value can never target another tenant. When a command declares more + # than one tenant-identifying name, only the most specific one is injected and the others are + # dropped so the command resolves them itself. + $DeclaredTenantParams = [array](@('TenantFilter', 'Tenant', 'TenantId') | Where-Object { $Function.Parameters.ContainsKey($_) }) + foreach ($TenantParamName in $DeclaredTenantParams) { + $StoredTenantValue = $commandParameters[$TenantParamName] + $StoredTenantString = [string]($StoredTenantValue.value ?? $StoredTenantValue) + if (![string]::IsNullOrWhiteSpace($StoredTenantString) -and $StoredTenantString -ne [string]$Tenant) { + Write-LogMessage -API 'Scheduler_UserTasks' -tenant $Tenant -tenantid $TenantInfo.customerId -message "Task $($task.Name): stored parameter -$TenantParamName value '$StoredTenantString' does not match the authorized tenant '$Tenant' and was overridden." -sev Error + } + if ($TenantParamName -eq $DeclaredTenantParams[0]) { + $commandParameters[$TenantParamName] = $Tenant + } else { + $commandParameters.Remove($TenantParamName) + } + } + if ($IsTriggerTask -eq $true -and $Trigger.ExecutePerResource -ne $true) { # iterate through paramters looking for %variables% and replace them with matched data from the delta query # examples would be %id% to be the id of the result @@ -404,7 +422,18 @@ function Push-ExecScheduledCommand { if ($TaskAttachments) { $AlertParams.Attachments = $TaskAttachments } - Send-CIPPScheduledTaskAlert @AlertParams + $PostExecutionResults = @(Send-CIPPScheduledTaskAlert @AlertParams) + # Keep the delivery outcomes with the task, so a failed webhook, email or PSA note shows on the task page. + try { + $TaskTable = Get-CippTable -tablename 'ScheduledTasks' + $null = Update-AzDataTableEntity -Force @TaskTable -Entity @{ + PartitionKey = $task.PartitionKey + RowKey = $task.RowKey + PostExecutionResults = [string](ConvertTo-Json -Compress -Depth 5 -InputObject $PostExecutionResults) + } + } catch { + Write-Information "Could not store the post-execution results: $($_.Exception.Message)" + } } try { diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-GetMailboxRulesBatch.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-GetMailboxRulesBatch.ps1 index 8ba597b4e1dbd..cac14c52d3e19 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-GetMailboxRulesBatch.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-GetMailboxRulesBatch.ps1 @@ -38,8 +38,10 @@ function Push-GetMailboxRulesBatch { # Add metadata and return for aggregation if (($Rules | Measure-Object).Count -gt 0) { $RulesWithMetadata = foreach ($Rule in $Rules) { - $Rule | Add-Member -NotePropertyName 'Tenant' -NotePropertyValue $TenantFilter -Force - $Rule | Add-Member -NotePropertyName 'UserPrincipalName' -NotePropertyValue $Rule.OperationGuid -Force + $Rule | Add-Member -NotePropertyMembers ([ordered]@{ + Tenant = $TenantFilter + UserPrincipalName = $Rule.OperationGuid + }) -Force $Rule } return , $RulesWithMetadata diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ListConditionalAccessPoliciesAllTenants.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ListConditionalAccessPoliciesAllTenants.ps1 index 6654ae719c800..daf01e43ec2fb 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ListConditionalAccessPoliciesAllTenants.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ListConditionalAccessPoliciesAllTenants.ps1 @@ -103,7 +103,8 @@ $AllServicePrincipals = ($BulkResults | Where-Object { $_.id -eq 'servicePrincipals' }).body.value foreach ($cap in $ConditionalAccessPolicyOutput) { - $GUID = (New-Guid).Guid + # Deterministic key so overlapping fan-outs upsert instead of appending duplicates. + $RowKey = ('{0}-{1}' -f $domainName, $cap.id) -replace '[\\/#?]', '_' -replace '[\x00-\x1F\x7F]', '' $PolicyData = @{ id = $cap.id displayName = $cap.displayName @@ -136,7 +137,7 @@ $Entity = @{ Policy = [string]($PolicyData | ConvertTo-Json -Depth 10 -Compress) - RowKey = [string]$GUID + RowKey = [string]$RowKey PartitionKey = 'CAPolicy' Tenant = [string]$domainName } @@ -144,7 +145,6 @@ } } catch { - $GUID = (New-Guid).Guid $ErrorPolicy = ConvertTo-Json -InputObject @{ Tenant = $domainName displayName = "Could not connect to Tenant: $($_.Exception.Message)" @@ -156,7 +156,7 @@ } -Compress $Entity = @{ Policy = [string]$ErrorPolicy - RowKey = [string]$GUID + RowKey = [string]('{0}-Error' -f $domainName) -replace '[\\/#?]', '_' PartitionKey = 'CAPolicy' Tenant = [string]$domainName } diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/SharePoint Storage Cleanup/Push-DBCacheStorageCleanupScanBatch.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/SharePoint Storage Cleanup/Push-DBCacheStorageCleanupScanBatch.ps1 new file mode 100644 index 0000000000000..89cc02c93d7a7 --- /dev/null +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/SharePoint Storage Cleanup/Push-DBCacheStorageCleanupScanBatch.ps1 @@ -0,0 +1,248 @@ +function Push-DBCacheStorageCleanupScanBatch { + <# + .SYNOPSIS + Collects library version estimates and recycle-bin totals for a batch of SharePoint sites. + + .DESCRIPTION + Processes up to 20 site seeds per activity. Each site is wrapped in its own try/catch so a + batch of N sites always returns exactly N site results - Push-StoreStorageCleanupScan + relies on that to verify completeness before it replaces the cache. + + Per site (mirrors ListSiteBrowser library drill-in + ListSiteRecycleBinSummary): + - Graph lists for documentLibrary / webPageLibrary + - SPO StorageMetrics for versionEstimateBytes + - Aggregate recycle bin sizes (no item titles or paths) + + Two row types are emitted, discriminated by rowType: + - Site one per scanned site (Full or Skipped); carries recycle aggregates + - Library one per visible document/page library when collection succeeded + + collectionStatus: + - Full libraries were collected; recycle fields may still be null if recycle failed + - Skipped site-level collection failed; no Library rows + + .FUNCTIONALITY + Entrypoint + #> + [CmdletBinding()] + param($Item) + + $TenantFilter = $Item.TenantFilter + $BatchNumber = $Item.BatchNumber + $SiteSeeds = @($Item.Sites) + + function New-CleanupSiteRow { + param( + $SiteSeed, + [string]$Status, + [string]$ErrorMessage, + [int]$LibrariesScanned, + [string]$CollectedAt, + $Recycle + ) + [PSCustomObject]@{ + rowType = 'Site' + id = "$($SiteSeed.id)_site" + siteId = $SiteSeed.id + displayName = $SiteSeed.displayName + siteUrl = $SiteSeed.webUrl + collectionStatus = $Status + collectionError = $ErrorMessage + librariesScanned = $LibrariesScanned + recycleTotalBytes = $Recycle.totalBytes + recycleItemCount = $Recycle.itemCount + recycleFirstStageBytes = $Recycle.firstStageBytes + recycleFirstStageCount = $Recycle.firstStageCount + recycleSecondStageBytes = $Recycle.secondStageBytes + recycleSecondStageCount = $Recycle.secondStageCount + recycleCapped = $Recycle.capped + recycleScannedItems = $Recycle.scannedItems + collectedAt = $CollectedAt + } + } + + function Get-CIPPRecycleBinSummary { + param( + [string]$TenantFilter, + [string]$SiteUrl, + [string]$Scope, + $JsonAccept, + [int]$MaxItems = 5000 + ) + $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $FirstCount = [int64]0 + $FirstBytes = [int64]0 + $SecondCount = [int64]0 + $SecondBytes = [int64]0 + $Seen = 0 + $Capped = $false + $NextUri = "$BaseUri/site/RecycleBin?`$select=Id,Size,ItemState&`$top=500&`$orderby=DeletedDate desc" + + while ($NextUri) { + $Page = New-GraphGetRequest -uri $NextUri -tenantid $TenantFilter -scope $Scope -extraHeaders $JsonAccept -UseCertificate -AsApp $true -noPagination $true -SkipValueExtraction + $Items = @() + $NextLink = $null + if ($null -ne $Page.value) { + $Items = @($Page.value) + $NextLink = $Page.'@odata.nextLink' + } elseif ($Page -is [System.Array]) { + $Items = @($Page) + } elseif ($Page.PSObject.Properties.Name -contains 'Id') { + $Items = @($Page) + } + + foreach ($BinItem in $Items) { + if ($Seen -ge $MaxItems) { + $Capped = $true + break + } + $Seen++ + $Size = 0 + try { $Size = [int64][double]$BinItem.Size } catch { $Size = 0 } + $State = 0 + try { $State = [int]$BinItem.ItemState } catch { $State = 0 } + if ($State -eq 2) { + $SecondCount++ + $SecondBytes += $Size + } else { + $FirstCount++ + $FirstBytes += $Size + } + } + + if ($Capped -or [string]::IsNullOrWhiteSpace($NextLink)) { break } + $NextUri = $NextLink + } + + return [PSCustomObject]@{ + siteUrl = $SiteUrl.TrimEnd('/') + itemCount = $FirstCount + $SecondCount + totalBytes = $FirstBytes + $SecondBytes + firstStageCount = $FirstCount + firstStageBytes = $FirstBytes + secondStageCount = $SecondCount + secondStageBytes = $SecondBytes + capped = $Capped + scannedItems = $Seen + } + } + + $SiteResults = [System.Collections.Generic.List[object]]::new() + + try { + Write-Information "Processing StorageCleanupScan batch $BatchNumber for tenant $TenantFilter with $($SiteSeeds.Count) sites" + + $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter + $SpoScope = "$($SharePointInfo.SharePointUrl)/.default" + $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } + + foreach ($SiteSeed in $SiteSeeds) { + $CollectedAt = (Get-Date).ToUniversalTime().ToString('o') + $LibraryRows = [System.Collections.Generic.List[object]]::new() + try { + $SiteId = $SiteSeed.id + $SiteUrl = $SiteSeed.webUrl + if ([string]::IsNullOrWhiteSpace($SiteUrl)) { + throw 'Site webUrl is required' + } + + $SiteSegment = $SiteId + if ([string]::IsNullOrWhiteSpace($SiteSegment)) { + $ParsedUrl = [System.Uri]$SiteUrl + $SiteSegment = if ($ParsedUrl.AbsolutePath -in @('', '/')) { + $ParsedUrl.Host + } else { + "$($ParsedUrl.Host):$($ParsedUrl.AbsolutePath):" + } + } + + $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $Lists = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/sites/$SiteSegment/lists?`$select=id,displayName,name,webUrl,list,createdDateTime" -tenantid $TenantFilter -asapp $true + $Libraries = @($Lists | Where-Object { $_.list.hidden -ne $true -and $_.list.template -in @('documentLibrary', 'webPageLibrary') }) + + foreach ($List in $Libraries) { + $StorageUsed = $null + $FileCount = $null + $FileStreamSize = $null + $MetadataSize = $null + $VersionEstimate = $null + try { + $Metrics = New-GraphGetRequest -uri "$BaseUri/web/lists(guid'$($List.id)')/RootFolder?`$select=StorageMetrics&`$expand=StorageMetrics" -tenantid $TenantFilter -scope $SpoScope -extraHeaders $JsonAccept -UseCertificate -AsApp $true + $TotalSize = ConvertTo-SPOAdminListInt64 -Raw $Metrics.StorageMetrics.TotalSize + $FileStreamSize = ConvertTo-SPOAdminListInt64 -Raw $Metrics.StorageMetrics.TotalFileStreamSize + $MetadataSize = ConvertTo-SPOAdminListInt64 -Raw $Metrics.StorageMetrics.MetadataSize + $FileCount = ConvertTo-SPOAdminListInt64 -Raw $Metrics.StorageMetrics.TotalFileCount + $StorageUsed = $TotalSize + if ($null -ne $TotalSize) { + $Tip = if ($null -ne $FileStreamSize) { $FileStreamSize } else { [int64]0 } + $Meta = if ($null -ne $MetadataSize) { $MetadataSize } else { [int64]0 } + $VersionEstimate = [Math]::Max([int64]0, $TotalSize - $Tip - $Meta) + } + } catch { + $StorageUsed = $null + $FileCount = $null + $FileStreamSize = $null + $MetadataSize = $null + $VersionEstimate = $null + } + + $LibraryRows.Add([PSCustomObject]@{ + rowType = 'Library' + id = "$($SiteId)_$($List.id)" + siteId = $SiteId + siteUrl = $SiteUrl + libraryId = $List.id + libraryName = $List.name + libraryDisplayName = $List.displayName + storageUsedInBytes = $StorageUsed + versionEstimateBytes = $VersionEstimate + fileStreamSizeInBytes = $FileStreamSize + metadataSizeInBytes = $MetadataSize + fileCount = $FileCount + template = $List.list.template + webUrl = $List.webUrl + collectedAt = $CollectedAt + }) + } + + $Recycle = $null + try { + $Recycle = Get-CIPPRecycleBinSummary -TenantFilter $TenantFilter -SiteUrl $SiteUrl -Scope $SpoScope -JsonAccept $JsonAccept + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "StorageCleanupScan: recycle summary failed for '$SiteUrl': $($_.Exception.Message)" -sev Warning + $Recycle = $null + } + + $SiteResults.Add([PSCustomObject]@{ + SiteId = $SiteId + CollectionStatus = 'Full' + SiteRow = (New-CleanupSiteRow -SiteSeed $SiteSeed -Status 'Full' -ErrorMessage $null -LibrariesScanned $LibraryRows.Count -CollectedAt $CollectedAt -Recycle $Recycle) + Rows = @($LibraryRows) + }) + + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "StorageCleanupScan: collection failed for '$($SiteSeed.webUrl)': $($_.Exception.Message)" -sev Warning + $SiteResults.Add([PSCustomObject]@{ + SiteId = $SiteSeed.id + CollectionStatus = 'Skipped' + SiteRow = (New-CleanupSiteRow -SiteSeed $SiteSeed -Status 'Skipped' -ErrorMessage $_.Exception.Message -LibrariesScanned 0 -CollectedAt $CollectedAt -Recycle $null) + Rows = @() + }) + } + } + + if ($SiteResults.Count -ne $SiteSeeds.Count) { + throw "Batch $BatchNumber invariant violated: expected $($SiteSeeds.Count) site results, got $($SiteResults.Count)" + } + + return [PSCustomObject]@{ + BatchNumber = $BatchNumber + Sites = @($SiteResults) + } + + } catch { + $ErrorMsg = "Failed StorageCleanupScan batch $BatchNumber for tenant $TenantFilter : $($_.Exception.Message)" + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message $ErrorMsg -sev Error -LogData (Get-CippException -Exception $_) + throw + } +} diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/SharePoint Storage Cleanup/Push-StoreStorageCleanupScan.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/SharePoint Storage Cleanup/Push-StoreStorageCleanupScan.ps1 new file mode 100644 index 0000000000000..167e2df42b355 --- /dev/null +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/SharePoint Storage Cleanup/Push-StoreStorageCleanupScan.ps1 @@ -0,0 +1,89 @@ +function Push-StoreStorageCleanupScan { + <# + .SYNOPSIS + Post-execution function that aggregates per-batch storage cleanup rows and writes the cache. + + .DESCRIPTION + Collects the Sites arrays returned by every Push-DBCacheStorageCleanupScanBatch activity, + flattens their Site and Library rows into a single row set, and writes StorageCleanupScan + once via Add-CIPPDbItem. + + Completeness guard: if the number of site results does not match ExpectedSiteCount the + function throws without writing. The cache is written in replace mode, so writing a partial + set would silently discard every site the failed batches were responsible for. + + Merge-on-Skip: when a site returns Skipped, its Library rows are restored from the existing + cache (matched on siteId) so a transient SPO failure does not erase cleanup signals that + were collected successfully on an earlier run. + + .FUNCTIONALITY + Entrypoint + #> + [CmdletBinding()] + param($Item) + + $TenantFilter = $Item.Parameters.TenantFilter + $ExpectedSiteCount = [int]$Item.Parameters.ExpectedSiteCount + + try { + $SiteResults = [System.Collections.Generic.List[object]]::new() + foreach ($BatchResult in @($Item.Results)) { + foreach ($SiteResult in @($BatchResult.Sites)) { + if ($SiteResult) { $SiteResults.Add($SiteResult) } + } + } + + $ActualCount = $SiteResults.Count + if ($ActualCount -ne $ExpectedSiteCount) { + throw "StorageCleanupScan completeness check failed for $TenantFilter : expected $ExpectedSiteCount site results, got $ActualCount" + } + + $SkippedResults = @($SiteResults | Where-Object { $_.CollectionStatus -eq 'Skipped' }) + $MergedCount = 0 + $PriorRowsBySiteId = @{} + if ($SkippedResults.Count -gt 0) { + foreach ($Existing in @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'StorageCleanupScan')) { + if ($Existing.rowType -ne 'Library') { continue } + $Key = [string]$Existing.siteId + if (-not $Key) { continue } + if (-not $PriorRowsBySiteId.ContainsKey($Key)) { + $PriorRowsBySiteId[$Key] = [System.Collections.Generic.List[object]]::new() + } + $PriorRowsBySiteId[$Key].Add($Existing) + } + } + + $AllRows = [System.Collections.Generic.List[object]]::new() + foreach ($SiteResult in $SiteResults) { + if ($SiteResult.SiteRow) { $AllRows.Add($SiteResult.SiteRow) } + + if ($SiteResult.CollectionStatus -eq 'Skipped') { + $Key = [string]$SiteResult.SiteId + if ($Key -and $PriorRowsBySiteId.ContainsKey($Key)) { + foreach ($Row in $PriorRowsBySiteId[$Key]) { $AllRows.Add($Row) } + $MergedCount++ + } + continue + } + + foreach ($Row in @($SiteResult.Rows)) { + if ($Row) { $AllRows.Add($Row) } + } + } + + if ($SkippedResults.Count -gt 0) { + $RemainingSkipped = $SkippedResults.Count - $MergedCount + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "StorageCleanupScan: $($SkippedResults.Count) of $ActualCount sites returned Skipped from collection; restored $MergedCount from prior cache; $RemainingSkipped have no library rows" -sev Warning + } + + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'StorageCleanupScan' -Data @($AllRows) -AddCount + + $LibraryCount = @($AllRows | Where-Object { $_.rowType -eq 'Library' }).Count + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $LibraryCount StorageCleanupScan libraries across $ActualCount sites ($MergedCount merge-on-Skip) from $(@($Item.Results).Count) batches" -sev Info + return + + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Failed to store StorageCleanupScan: $($_.Exception.Message)" -sev Error -LogData (Get-CippException -Exception $_) + throw + } +} diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertApnCertExpiry.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertApnCertExpiry.ps1 index 0b288e964f31d..dfc1459d293c8 100644 --- a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertApnCertExpiry.ps1 +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertApnCertExpiry.ps1 @@ -12,8 +12,18 @@ function Get-CIPPAlertApnCertExpiry { ) try { + $expiryDays = 30 + if ($InputValue -is [hashtable] -or $InputValue -is [pscustomobject]) { + if ($null -ne $InputValue.DaysUntilExpiry -and $InputValue.DaysUntilExpiry -ne '') { + $parsedDays = 0 + if ([int]::TryParse($InputValue.DaysUntilExpiry.ToString(), [ref]$parsedDays) -and $parsedDays -gt 0) { + $expiryDays = $parsedDays + } + } + } + $Apn = New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/deviceManagement/applePushNotificationCertificate' -tenantid $TenantFilter - $AlertData = if ($Apn.expirationDateTime -lt (Get-Date).AddDays(30) -and $Apn.expirationDateTime -gt (Get-Date).AddDays(-7)) { + $AlertData = if ($Apn.expirationDateTime -lt (Get-Date).AddDays($expiryDays) -and $Apn.expirationDateTime -gt (Get-Date).AddDays(-7)) { $Apn | Select-Object -Property appleIdentifier, expirationDateTime } if ($AlertData) { diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertAppSecretExpiry.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertAppSecretExpiry.ps1 index 20041ca7845c1..7e741af1e5d2b 100644 --- a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertAppSecretExpiry.ps1 +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertAppSecretExpiry.ps1 @@ -15,6 +15,8 @@ function Get-CIPPAlertAppSecretExpiry { Write-Host "Checking app expire for $($TenantFilter)" $appList = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/applications?`$select=appId,displayName,passwordCredentials" -tenantid $TenantFilter } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API 'Alerts' -tenant $TenantFilter -message "Application secret expiry alert: unable to list applications: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage return } diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertArchiveQuota.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertArchiveQuota.ps1 new file mode 100644 index 0000000000000..8c9499d49a53f --- /dev/null +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertArchiveQuota.ps1 @@ -0,0 +1,111 @@ +function Get-CIPPAlertArchiveQuota { + <# + .FUNCTIONALITY + Entrypoint + #> + [CmdletBinding()] + param ( + [Parameter(Mandatory = $false)] + [Alias('input')] + $InputValue, + [Parameter(Mandatory)] + $TenantFilter + ) + + $Threshold = if ($InputValue.ArchiveQuotaThreshold) { [int]$InputValue.ArchiveQuotaThreshold } else { 90 } + $ExcludedRaw = Get-CIPPTextReplacement -TenantFilter $TenantFilter -Text ([string]$InputValue.ArchiveQuotaExcludedMailboxes) + $Excluded = @($ExcludedRaw -split ',' | ForEach-Object { $_.Trim().ToLower() } | Where-Object { $_ }) + + # Prefer the reporting DB: Set-CIPPDBCacheMailboxes already stores archive size and quota (both in + # bytes) per mailbox, so a warm cache answers this without any Exchange Online call. The archive + # figures change slowly and this alert runs weekly, so day-old cache data is well within tolerance. + # Fall back to live Exchange only when the tenant has no cached mailbox data (or a cache written + # before ArchiveQuota was added), so the alert never silently no-ops. + $ArchiveUsage = $null + try { + $Cached = @(Get-CIPPMailboxesReport -TenantFilter $TenantFilter -ErrorAction Stop) + } catch { + $Cached = @() + } + $CacheHasQuota = $Cached.Count -gt 0 -and ($Cached[0].PSObject.Properties.Name -contains 'ArchiveQuota') + + if ($CacheHasQuota) { + $ArchiveUsage = foreach ($Mailbox in $Cached) { + if ($Mailbox.ArchiveEnabled -ne $true -or -not $Mailbox.UPN) { continue } + [PSCustomObject]@{ + UPN = $Mailbox.UPN + RecipientType = $Mailbox.recipientTypeDetails + UsedBytes = [int64]($Mailbox.ArchiveSize ?? 0) + QuotaBytes = [int64]($Mailbox.ArchiveQuota ?? 0) + } + } + } else { + try { + # -Archive limits the result to mailboxes that actually have an online archive, and the + # quota fields ride along so only the per-mailbox usage needs a second lookup. + $ArchiveMailboxes = @(New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-Mailbox' -cmdParams @{ Archive = $true } -Select 'UserPrincipalName,RecipientTypeDetails,ArchiveQuota,ArchiveGuid' -useSystemMailbox $true | Where-Object { $_.UserPrincipalName }) + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API 'Alerts' -tenant $TenantFilter -message "Archive quota Alert: Unable to get archive mailboxes: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + return + } + if ($ArchiveMailboxes.Count -eq 0) { return } + + # Archive size only comes from Get-MailboxStatistics. Batch it with an operation guid per + # mailbox so each result maps back to its mailbox, the same pattern the reporting-DB cache uses. + $MailboxByRequestId = @{} + $StatsRequests = @(foreach ($Mailbox in $ArchiveMailboxes) { + $OperationGuid = [Guid]::NewGuid().ToString() + $MailboxByRequestId[$OperationGuid] = $Mailbox + @{ + CmdletInput = @{ + CmdletName = 'Get-MailboxStatistics' + Parameters = @{ Identity = $Mailbox.UserPrincipalName; Archive = $true } + } + OperationGuid = $OperationGuid + } + }) + + try { + $StatsResults = New-ExoBulkRequest -tenantid $TenantFilter -cmdletArray $StatsRequests -useSystemMailbox $true + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API 'Alerts' -tenant $TenantFilter -message "Archive quota Alert: Unable to get archive statistics: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + return + } + + $ArchiveUsage = foreach ($Stat in @($StatsResults)) { + if (-not $Stat.OperationGuid -or -not $MailboxByRequestId.ContainsKey($Stat.OperationGuid) -or $Stat.error) { continue } + $Mailbox = $MailboxByRequestId[$Stat.OperationGuid] + [PSCustomObject]@{ + UPN = $Mailbox.UserPrincipalName + RecipientType = $Mailbox.RecipientTypeDetails + UsedBytes = Get-ExoOnlineStringBytes -SizeString ([string]$Stat.TotalItemSize) + QuotaBytes = Get-ExoOnlineStringBytes -SizeString ([string]$Mailbox.ArchiveQuota) + } + } + } + + $OverQuota = foreach ($Item in @($ArchiveUsage)) { + if (-not $Item.UPN) { continue } + if ($Excluded -contains $Item.UPN.ToLower()) { continue } + # An archive with no quota reports 0 bytes here (e.g. 'Unlimited'); skip rather than divide by zero. + if ($Item.QuotaBytes -le 0) { continue } + $UsagePercent = [math]::Round(($Item.UsedBytes / $Item.QuotaBytes) * 100) + if ($UsagePercent -ge $Threshold) { + [PSCustomObject]@{ + Message = "$($Item.UPN): Online archive is more than $($Threshold)% full. Archive is $UsagePercent% full" + Owner = $Item.UPN + RecipientType = $Item.RecipientType + UsagePercent = $UsagePercent + ArchiveUsedBytes = $Item.UsedBytes + ArchiveQuotaBytes = $Item.QuotaBytes + Tenant = $TenantFilter + } + } + } + + if ($OverQuota) { + Write-AlertTrace -cmdletName $MyInvocation.MyCommand -tenantFilter $TenantFilter -data $OverQuota + } +} diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertDepTokenExpiry.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertDepTokenExpiry.ps1 index 63436166abda8..10320d3bf030c 100644 --- a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertDepTokenExpiry.ps1 +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertDepTokenExpiry.ps1 @@ -13,10 +13,20 @@ function Get-CIPPAlertDepTokenExpiry { try { try { + $expiryDays = 30 + if ($InputValue -is [hashtable] -or $InputValue -is [pscustomobject]) { + if ($null -ne $InputValue.DaysUntilExpiry -and $InputValue.DaysUntilExpiry -ne '') { + $parsedDays = 0 + if ([int]::TryParse($InputValue.DaysUntilExpiry.ToString(), [ref]$parsedDays) -and $parsedDays -gt 0) { + $expiryDays = $parsedDays + } + } + } + $DepTokens = New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/deviceManagement/depOnboardingSettings' -tenantid $TenantFilter $AlertData = foreach ($Dep in $DepTokens) { - if ($Dep.tokenExpirationDateTime -lt (Get-Date).AddDays(30) -and $Dep.tokenExpirationDateTime -gt (Get-Date).AddDays(-7)) { - $Message = 'Apple Device Enrollment Program token expiring on {0}' -f $Dep.tokenExpirationDateTime + if ($Dep.tokenExpirationDateTime -lt (Get-Date).AddDays($expiryDays) -and $Dep.tokenExpirationDateTime -gt (Get-Date).AddDays(-7)) { + $Message = 'Apple Device Enrollment Program token expiring on {0}' -f ([datetime]$Dep.tokenExpirationDateTime).ToString('yyyy-MM-dd') $Dep | Select-Object -Property tokenName, @{Name = 'Message'; Expression = { $Message } } } } diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertDeviceComplianceGracePeriod.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertDeviceComplianceGracePeriod.ps1 new file mode 100644 index 0000000000000..02acf09a1fd12 --- /dev/null +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertDeviceComplianceGracePeriod.ps1 @@ -0,0 +1,55 @@ +function Get-CIPPAlertDeviceComplianceGracePeriod { + <# + .FUNCTIONALITY + Entrypoint + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $false)] + [Alias('input')] + $InputValue, + $TenantFilter + ) + try { + $ExpiresWithinDays = 0 + if ($null -ne $InputValue.ExpiresWithinDays -and $InputValue.ExpiresWithinDays -ne '') { + $parsedDays = 0 + if ([int]::TryParse($InputValue.ExpiresWithinDays.ToString(), [ref]$parsedDays) -and $parsedDays -gt 0) { + $ExpiresWithinDays = $parsedDays + } + } + + $GraphRequest = New-GraphGETRequest -uri "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices?`$filter=complianceState eq 'inGracePeriod'&`$select=id,deviceName,userPrincipalName,operatingSystem,managedDeviceOwnerType,complianceState,complianceGracePeriodExpirationDateTime,lastSyncDateTime&`$top=999" -tenantid $TenantFilter + $AlertData = foreach ($Device in $GraphRequest) { + $Expiration = $Device.complianceGracePeriodExpirationDateTime + $DaysRemaining = if ($Expiration) { [Math]::Ceiling(([DateTime]$Expiration - (Get-Date).ToUniversalTime()).TotalDays) } else { $null } + if ($ExpiresWithinDays -gt 0 -and $null -ne $DaysRemaining -and $DaysRemaining -gt $ExpiresWithinDays) { continue } + + $Message = if ($null -ne $DaysRemaining) { + 'Device {0} is in the compliance grace period and will be marked noncompliant on {1} ({2} days remaining)' -f $Device.deviceName, ([datetime]$Expiration).ToString('yyyy-MM-dd'), $DaysRemaining + } else { + 'Device {0} is in the compliance grace period' -f $Device.deviceName + } + + [PSCustomObject]@{ + DeviceName = $Device.deviceName + Id = $Device.id + UserPrincipalName = $Device.userPrincipalName + OperatingSystem = $Device.operatingSystem + OwnerType = $Device.managedDeviceOwnerType + GracePeriodExpiration = $Expiration + DaysRemaining = $DaysRemaining + LastSync = $Device.lastSyncDateTime + Message = $Message + Tenant = $TenantFilter + } + } + + if ($AlertData) { + Write-AlertTrace -cmdletName $MyInvocation.MyCommand -tenantFilter $TenantFilter -data $AlertData + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API 'Alerts' -tenant $TenantFilter -message "Could not get compliance grace period state for $($TenantFilter): $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + } +} diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertExpiringLicenses.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertExpiringLicenses.ps1 index 15fcfdf3009b2..200adf97719ba 100644 --- a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertExpiringLicenses.ps1 +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertExpiringLicenses.ps1 @@ -16,10 +16,12 @@ function Get-CIPPAlertExpiringLicenses { # Support both old format (direct value) and new format (object with properties) if ($InputValue -is [hashtable] -or $InputValue -is [PSCustomObject]) { $DaysThreshold = if ($InputValue.ExpiringLicensesDays) { [int]$InputValue.ExpiringLicensesDays } else { 30 } + $MinDaysThreshold = if ($InputValue.ExpiringLicensesMinDays) { [int]$InputValue.ExpiringLicensesMinDays } else { 0 } $UnassignedOnly = if ($null -ne $InputValue.ExpiringLicensesUnassignedOnly) { [bool]$InputValue.ExpiringLicensesUnassignedOnly } else { $false } } else { # Backward compatibility: if InputValue is a simple value, treat it as days threshold $DaysThreshold = if ($InputValue) { [int]$InputValue } else { 30 } + $MinDaysThreshold = 0 $UnassignedOnly = $false } @@ -39,7 +41,9 @@ function Get-CIPPAlertExpiringLicenses { foreach ($Term in $TermData) { $DaysUntilRenew = [int]$Term.DaysUntilRenew - if ($DaysUntilRenew -lt $DaysThreshold -and $DaysUntilRenew -gt 0) { + # Graph does not expose the actual commitment term (P1M/P1Y), so the minimum + # threshold is the only reliable way to skip monthly auto-renewing subscriptions + if ($DaysUntilRenew -lt $DaysThreshold -and $DaysUntilRenew -gt 0 -and $DaysUntilRenew -ge $MinDaysThreshold) { $Message = if ($UnassignedOnly) { "$($_.License) has $UnassignedCount unassigned license(s) expiring in $DaysUntilRenew days. The estimated term is $($Term.Term)" diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertIntuneApprovalRequests.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertIntuneApprovalRequests.ps1 index 9978c2fb377a9..4c2fe0844787a 100644 --- a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertIntuneApprovalRequests.ps1 +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertIntuneApprovalRequests.ps1 @@ -24,7 +24,7 @@ function Get-CIPPAlertIntuneApprovalRequests { # left null even for requests raised through Graph, so there is no 'who' to report. $Operation = ($ApprovalRequest.payloadOperation ?? 'change').ToLower() $Target = $ApprovalRequest.payloadName ?? (@($ApprovalRequest.requiredOperationApprovalPolicyTypes) -join ', ') - $Message = 'Intune {0} of "{1}" is waiting for multi-admin approval and expires {2}' -f $Operation, $Target, $ApprovalRequest.expirationDateTime + $Message = 'Intune {0} of "{1}" is waiting for multi-admin approval and expires {2}' -f $Operation, $Target, ([datetime]$ApprovalRequest.expirationDateTime).ToString('yyyy-MM-dd') $ApprovalRequest | Select-Object -Property id, status, requestDateTime, expirationDateTime, requestJustification, @{Name = 'operation'; Expression = { $ApprovalRequest.payloadOperation } }, diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertMXRecordChanged.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertMXRecordChanged.ps1 index 80a676b5ff37e..056928e9c2afa 100644 --- a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertMXRecordChanged.ps1 +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertMXRecordChanged.ps1 @@ -23,6 +23,11 @@ function Get-CIPPAlertMXRecordChanged { $ChangedDomains = foreach ($Domain in $DomainData) { try { $PreviousDomain = $PreviousResults | Where-Object { $_.Domain -eq $Domain.Domain } + if (-not $PreviousDomain) { + Write-Information "Initializing MX record baseline for domain $($Domain.Domain): $($Domain.ActualMXRecords.Hostname -join ', ')" + continue + } + $PreviousRecords = if ($PreviousDomain.ActualMXRecords) { @($PreviousDomain.ActualMXRecords -split ',' | Sort-Object) } else { @() } $CurrentRecords = if ($Domain.ActualMXRecords.Hostname) { @($Domain.ActualMXRecords.Hostname | Sort-Object) } else { @() } diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertNewAppApproval.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertNewAppApproval.ps1 index ac6aa1bef28e5..b8e0252a39396 100644 --- a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertNewAppApproval.ps1 +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertNewAppApproval.ps1 @@ -24,7 +24,11 @@ function Get-CIPPAlertNewAppApproval { $userConsentRequests = New-GraphGetRequest -Uri "https://graph.microsoft.com/v1.0/identityGovernance/appConsent/appConsentRequests/$($App.id)/userConsentRequests" -tenantid $TenantFilter $userConsentRequests | ForEach-Object { - if ($_.status -eq 'Expired') { + # Only alert on pending (InProgress) requests. The top-level appConsentRequests + # filter matches an app when ANY of its userConsentRequests is InProgress, but + # this per-app list returns ALL of them - including Completed, Denied and Expired + # - so without this guard already-resolved requests were being alerted on. + if ($_.status -ne 'InProgress') { return } $consentUrl = if ($App.consentType -eq 'Static') { diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertOneDriveLongPaths.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertOneDriveLongPaths.ps1 new file mode 100644 index 0000000000000..de865c1a9015f --- /dev/null +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertOneDriveLongPaths.ps1 @@ -0,0 +1,76 @@ +function Get-CIPPAlertOneDriveLongPaths { + <# + .FUNCTIONALITY + Entrypoint + .SYNOPSIS + Alert on OneDrive accounts with over-long path counts from the Report DB cache. + + .DESCRIPTION + Reads OneDriveLongPaths cache only (no live crawl). Requires a prior + ExecCIPPDBCache?Name=OneDriveLongPaths run. Alert text includes owner UPN and + counts only — never file or folder names. + #> + [CmdletBinding()] + param ( + [Parameter(Mandatory = $false)] + [Alias('input')] + $InputValue, + $TenantFilter + ) + + $HasSharePoint = Test-CIPPStandardLicense -StandardName 'OneDriveLongPaths' -TenantFilter $TenantFilter -Preset SharePoint + if (-not $HasSharePoint) { + return + } + + try { + $MinCount = 1 + if ($InputValue -is [hashtable] -or $InputValue -is [PSCustomObject]) { + $Raw = $InputValue.OneDriveLongPaths ?? $InputValue.MinCount ?? $InputValue + if ($null -ne $Raw -and "$Raw" -ne '') { + $Parsed = 0 + if ([int]::TryParse("$Raw", [ref]$Parsed) -and $Parsed -gt 0) { + $MinCount = $Parsed + } + } + } elseif ($null -ne $InputValue -and "$InputValue" -ne '') { + $Parsed = 0 + if ([int]::TryParse("$InputValue", [ref]$Parsed) -and $Parsed -gt 0) { + $MinCount = $Parsed + } + } + + $Rows = @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'OneDriveLongPaths') + if (-not $Rows) { + return + } + + $AlertData = foreach ($Row in $Rows) { + $Upn = [string]($Row.ownerPrincipalName ?? $Row.id) + if ([string]::IsNullOrWhiteSpace($Upn)) { continue } + + $Count260 = 0 + $Count400 = 0 + if ($null -ne $Row.countOver260) { [void][int]::TryParse("$($Row.countOver260)", [ref]$Count260) } + if ($null -ne $Row.countOver400) { [void][int]::TryParse("$($Row.countOver400)", [ref]$Count400) } + + if ($Count260 -lt $MinCount) { continue } + + [PSCustomObject]@{ + Message = "${Upn}: $Count260 OneDrive paths may exceed Windows 260-character path limit when synced ($Count400 over cloud 400 limit)." + Id = $Upn + ownerPrincipalName = $Upn + countOver260 = $Count260 + countOver400 = $Count400 + Tenant = $TenantFilter + } + } + + if ($AlertData) { + Write-AlertTrace -cmdletName $MyInvocation.MyCommand -tenantFilter $TenantFilter -data $AlertData + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-AlertMessage -message "OneDrive long paths alert failed: $($ErrorMessage.NormalizedError)" -tenant $TenantFilter -LogData $ErrorMessage + } +} diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertPermanentActiveAdminAssigned.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertPermanentActiveAdminAssigned.ps1 new file mode 100644 index 0000000000000..6cad3c9cdaa81 --- /dev/null +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertPermanentActiveAdminAssigned.ps1 @@ -0,0 +1,94 @@ +function Get-CIPPAlertPermanentActiveAdminAssigned { + <# + .FUNCTIONALITY + Entrypoint + .SYNOPSIS + Alerts when a principal gains a permanent (no end date) active admin role assignment. + .DESCRIPTION + Compares the tenant's current permanent active role assignments with the set seen on the + previous run (DeltaCompare table) and alerts on new ones that are not in the approved + allow list. Entra ID P2 tenants are read through PIM (roleAssignmentScheduleInstances, so + time-bound and activated assignments are excluded); other tenants through unified RBAC, + where every assignment is permanent. + + Inputs: ApprovedAdmins - comma separated UPN prefixes, UPNs or display names that may hold + permanent assignments (break-glass accounts); PrivilegedRolesOnly - limit to CIPP's + privileged role list (default on). + #> + [CmdletBinding()] + param ( + [Parameter(Mandatory = $false)] + [Alias('input')] + $InputValue, + $TenantFilter + ) + try { + $Approved = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + $PrivilegedRolesOnly = $true + $ApprovedRaw = $null + if ($InputValue -is [System.Collections.IDictionary] -or $InputValue -is [pscustomobject]) { + $ApprovedRaw = $InputValue.ApprovedAdmins + if ($null -ne $InputValue.PrivilegedRolesOnly) { $PrivilegedRolesOnly = [bool]($InputValue.PrivilegedRolesOnly -eq $true -or "$($InputValue.PrivilegedRolesOnly)" -eq 'true') } + } elseif ($null -ne $InputValue) { + $ApprovedRaw = $InputValue + } + foreach ($Entry in @("$ApprovedRaw" -split '[,;]' | ForEach-Object { $_.Trim() } | Where-Object { $_ })) { $null = $Approved.Add($Entry) } + + $Rows = @(Get-CIPPPIMRoleAssignments -TenantFilter $TenantFilter | Where-Object { $_.AssignmentType -eq 'Permanent' -and $_.MemberType -ne 'Group' }) + if ($PrivilegedRolesOnly) { + $Rows = @($Rows | Where-Object { $_.IsPrivilegedRole }) + } + + $Current = @($Rows | ForEach-Object { + [PSCustomObject]@{ + Key = "$($_.PrincipalId)|$($_.RoleDefinitionId)|$($_.DirectoryScopeId)" + PrincipalId = $_.PrincipalId + DisplayName = $_.PrincipalDisplayName + UserPrincipalName = $_.PrincipalUserPrincipalName + PrincipalType = $_.PrincipalType + Role = $_.RoleDisplayName + Scope = $_.Scope + } + }) + + $DeltaTable = Get-CIPPTable -Table DeltaCompare + $Filter = "PartitionKey eq 'PermanentAdminDelta' and RowKey eq '{0}'" -f $TenantFilter + $Previous = (Get-CIPPAzDataTableEntity @DeltaTable -Filter $Filter).delta | ConvertFrom-Json -ErrorAction SilentlyContinue + $PreviousKeys = [System.Collections.Generic.HashSet[string]]::new([string[]]@($Previous.Key | Where-Object { $_ }), [System.StringComparer]::OrdinalIgnoreCase) + + Add-CIPPAzDataTableEntity @DeltaTable -Entity @{ + PartitionKey = 'PermanentAdminDelta' + RowKey = [string]$TenantFilter + delta = "$(ConvertTo-Json -InputObject @($Current) -Depth 5 -Compress)" + } -Force + + # First run only seeds the baseline; alerting on everything that already existed would be noise. + if ($null -eq $Previous) { return } + + $AlertData = foreach ($Item in $Current) { + if ($PreviousKeys.Contains($Item.Key)) { continue } + $Candidates = @($Item.PrincipalId, $Item.DisplayName, $Item.UserPrincipalName) + if ($Item.UserPrincipalName) { $Candidates += ($Item.UserPrincipalName -split '@')[0] } + $IsApproved = $false + foreach ($Candidate in $Candidates) { if ($Candidate -and $Approved.Contains("$Candidate")) { $IsApproved = $true; break } } + if ($IsApproved) { continue } + $Label = @($Item.UserPrincipalName, $Item.DisplayName, $Item.PrincipalId) | Where-Object { -not [string]::IsNullOrWhiteSpace($_) } | Select-Object -First 1 + [PSCustomObject]@{ + Message = "$Label was given a permanent (no end date) active assignment to the $($Item.Role) role." + UserPrincipalName = $Item.UserPrincipalName + DisplayName = $Item.DisplayName + PrincipalType = $Item.PrincipalType + Role = $Item.Role + Scope = $Item.Scope + Tenant = $TenantFilter + } + } + + if ($AlertData) { + Write-AlertTrace -cmdletName $MyInvocation.MyCommand -tenantFilter $TenantFilter -data $AlertData + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API 'Alerts' -tenant $TenantFilter -message "Could not check permanent admin assignments for $($TenantFilter): $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + } +} diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertQuarantineReleaseRequests.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertQuarantineReleaseRequests.ps1 index e53db602ca355..b9607981ecdcd 100644 --- a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertQuarantineReleaseRequests.ps1 +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertQuarantineReleaseRequests.ps1 @@ -18,11 +18,15 @@ } try { + # The received-date window has to be wide enough to catch a release request raised some time after + # the message was quarantined. The old 6-hour window missed most of them; a one-day window suits an + # hourly-scheduled alert. (The Quarantine page applies no received-date filter, which is why the + # request is visible there while no webhook or email is ever sent.) $cmdParams = @{ PageSize = 1000 ReleaseStatus = 'Requested' - StartReceivedDate = (Get-Date).AddHours(-6) - EndReceivedDate = (Get-Date).AddHours(0) + StartReceivedDate = (Get-Date).AddDays(-1) + EndReceivedDate = (Get-Date) } $RequestedReleases = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-QuarantineMessage' -cmdParams $cmdParams -ErrorAction Stop | Select-Object -ExcludeProperty *data.type* | Sort-Object -Property ReceivedTime diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertQuotaUsed.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertQuotaUsed.ps1 index 3d803dafa0d99..91691e65b6c6c 100644 --- a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertQuotaUsed.ps1 +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertQuotaUsed.ps1 @@ -26,7 +26,8 @@ function Get-CIPPAlertQuotaUsed { } $OverQuota = $AlertData | ForEach-Object { - if (!$_.StorageUsedInBytes -or !$_.prohibitSendReceiveQuotaInBytes) { return } + if (!$_.storageUsedInBytes -or !$_.prohibitSendReceiveQuotaInBytes) { return } + if ("$($_.isDeleted)" -eq 'True') { return } if ($Excluded -contains $_.userPrincipalName.ToLower()) { return } # Report returns 'User'/'Shared' or 'UserMailbox'/'SharedMailbox' depending on tenant; normalize before matching if ($MailboxTypes.Count -gt 0 -and ($_.recipientType -replace 'Mailbox$') -notin $MailboxTypes) { return } diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertUnlicensedOneDriveData.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertUnlicensedOneDriveData.ps1 index aee0951583e30..751440ba7682f 100644 --- a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertUnlicensedOneDriveData.ps1 +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertUnlicensedOneDriveData.ps1 @@ -128,17 +128,8 @@ function Get-CIPPAlertUnlicensedOneDriveData { } $StorageUsedGB = $null - $StorageBytes = 0.0 - $ParsedStorage = $false - if ($Row.PSObject.Properties.Name -contains 'StorageUsed.') { - $ParsedStorage = [double]::TryParse("$($Row.'StorageUsed.')", [ref]$StorageBytes) - } - if (-not $ParsedStorage -and $Row.StorageUsed) { - $UsedRaw = "$($Row.StorageUsed)" -replace '[^\d.]', '' - $ParsedStorage = [double]::TryParse($UsedRaw, [ref]$StorageBytes) - } - if ($ParsedStorage) { - $StorageUsedGB = [math]::Round($StorageBytes / 1GB, 2) + if ($null -ne $Row.StorageUsed) { + $StorageUsedGB = [math]::Round([double]$Row.StorageUsed / 1GB, 2) } $Title = [string]$Row.Title diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertVppTokenExpiry.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertVppTokenExpiry.ps1 index 775fa7cec263d..c2d228ad4b8bf 100644 --- a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertVppTokenExpiry.ps1 +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertVppTokenExpiry.ps1 @@ -12,13 +12,23 @@ function Get-CIPPAlertVppTokenExpiry { ) try { try { + $expiryDays = 30 + if ($InputValue -is [hashtable] -or $InputValue -is [pscustomobject]) { + if ($null -ne $InputValue.DaysUntilExpiry -and $InputValue.DaysUntilExpiry -ne '') { + $parsedDays = 0 + if ([int]::TryParse($InputValue.DaysUntilExpiry.ToString(), [ref]$parsedDays) -and $parsedDays -gt 0) { + $expiryDays = $parsedDays + } + } + } + $VppTokens = New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/deviceAppManagement/vppTokens' -tenantid $TenantFilter $AlertData = foreach ($Vpp in $VppTokens) { if ($Vpp.state -ne 'valid') { $Message = 'Apple Volume Purchase Program Token is not valid, new token required' $Vpp | Select-Object -Property organizationName, appleId, vppTokenAccountType, @{Name = 'Message'; Expression = { $Message } }, @{Name = 'Tenant'; Expression = { $TenantFilter } } - } elseif ($Vpp.expirationDateTime -lt (Get-Date).AddDays(30).ToUniversalTime() -and $Vpp.expirationDateTime -gt (Get-Date).AddDays(-7).ToUniversalTime()) { - $Message = 'Apple Volume Purchase Program token expiring on {0}' -f $Vpp.expirationDateTime + } elseif ($Vpp.expirationDateTime -lt (Get-Date).AddDays($expiryDays).ToUniversalTime() -and $Vpp.expirationDateTime -gt (Get-Date).AddDays(-7).ToUniversalTime()) { + $Message = 'Apple Volume Purchase Program token expiring on {0}' -f ([datetime]$Vpp.expirationDateTime).ToString('yyyy-MM-dd') $Vpp | Select-Object -Property organizationName, appleId, vppTokenAccountType, @{Name = 'Message'; Expression = { $Message } }, @{Name = 'Tenant'; Expression = { $TenantFilter } } } } diff --git a/Modules/CIPPCore/Public/Add-CIPPApplicationPermission.ps1 b/Modules/CIPPCore/Public/Add-CIPPApplicationPermission.ps1 index 263a2a0fbfcd9..f8a0b90f97c8d 100644 --- a/Modules/CIPPCore/Public/Add-CIPPApplicationPermission.ps1 +++ b/Modules/CIPPCore/Public/Add-CIPPApplicationPermission.ps1 @@ -165,6 +165,11 @@ function Add-CIPPApplicationPermission { # App-only scopes changed; a cached client_credentials token still carries the old # roles, so drop it rather than wait out its TTL. $null = Clear-CippTokenCache -TenantFilter $TenantFilter + Write-LogMessage -API 'Add-CIPPApplicationPermission' -tenant $TenantFilter -message "Added $counter application permission(s) to $($ourSVCPrincipal.displayName)" -Sev 'Info' + } + $Failures = @($Results | Where-Object { $_ -match '^Failed to' }) + if ($Failures.Count -gt 0) { + Write-LogMessage -API 'Add-CIPPApplicationPermission' -tenant $TenantFilter -message "Failed during application permission update for $($ourSVCPrincipal.displayName): $($Failures.Count) error(s)" -Sev 'Warning' -LogData @{ Failures = $Failures } } "Added $counter Application permissions to $($ourSVCPrincipal.displayName)" return $Results diff --git a/Modules/CIPPCore/Public/Add-CIPPDbItem.ps1 b/Modules/CIPPCore/Public/Add-CIPPDbItem.ps1 index 963619ad3bbe0..597a479adb257 100644 --- a/Modules/CIPPCore/Public/Add-CIPPDbItem.ps1 +++ b/Modules/CIPPCore/Public/Add-CIPPDbItem.ps1 @@ -130,7 +130,11 @@ function Add-CIPPDbItem { $Filter += " and Timestamp lt datetime'{0}'" -f $RunStartUtc.UtcDateTime.ToString('yyyy-MM-ddTHH:mm:ss.fffffffZ') } - $Existing = Get-CIPPAzDataTableEntity @Table -Filter $Filter -Property PartitionKey, RowKey, ETag, OriginalEntityId, RunId + # Project all row-level split markers (OriginalEntityId, PartIndex, PartCount) so split + # entities reassemble; a subset makes the module drop them. Reassembly is what keeps this + # sound - each logical row carries its RunId. Raw rows (no markers) would be wrong: part + # rows lack RunId and would look like foreign-run orphans. + $Existing = Get-CIPPAzDataTableEntity @Table -Filter $Filter -Property PartitionKey, RowKey, ETag, OriginalEntityId, RunId, PartIndex, PartCount if ($Existing) { $Orphans = foreach ($Row in @($Existing)) { if ($Row.RowKey -eq "$Type-Count") { continue } diff --git a/Modules/CIPPCore/Public/Add-CIPPDelegatedPermission.ps1 b/Modules/CIPPCore/Public/Add-CIPPDelegatedPermission.ps1 index 8543acab6b84d..9f5fbf9459e1e 100644 --- a/Modules/CIPPCore/Public/Add-CIPPDelegatedPermission.ps1 +++ b/Modules/CIPPCore/Public/Add-CIPPDelegatedPermission.ps1 @@ -82,6 +82,7 @@ function Add-CIPPDelegatedPermission { } $CurrentDelegatedScopes = New-GraphGETRequest -uri "https://graph.microsoft.com/beta/servicePrincipals/$($ourSVCPrincipal.id)/oauth2PermissionGrants" -skipTokenCache $true -tenantid $TenantFilter -NoAuthCheck $true + $ChangedResources = [System.Collections.Generic.List[string]]::new() foreach ($App in $RequiredResourceAccess) { if (!$App) { @@ -134,6 +135,7 @@ function Add-CIPPDelegatedPermission { } | ConvertTo-Json -Compress $CreateRequest = New-GraphPOSTRequest -uri 'https://graph.microsoft.com/v1.0/oauth2PermissionGrants' -tenantid $TenantFilter -body $Createbody -type POST -NoAuthCheck $true $Results.add("Successfully added permissions for $($svcPrincipalId.displayName)") + $ChangedResources.Add("$($svcPrincipalId.displayName) (added)") } catch { $Results.add("Failed to add permissions for $($svcPrincipalId.displayName): $(Get-NormalizedError -message $_.Exception.Message)") continue @@ -180,9 +182,20 @@ function Add-CIPPDelegatedPermission { # Added permissions $Added = ($Compare | Where-Object { $_.SideIndicator -eq '=>' }).InputObject -join ' ' $Removed = ($Compare | Where-Object { $_.SideIndicator -eq '<=' }).InputObject -join ' ' + $AddedCount = @(($Compare | Where-Object { $_.SideIndicator -eq '=>' })).Count + $RemovedCount = @(($Compare | Where-Object { $_.SideIndicator -eq '<=' })).Count $Results.add("Successfully updated permissions for $($svcPrincipalId.displayName). $(if ($Added) { "Added: $Added"}) $(if ($Removed) { "Removed: $Removed"})") + $ChangedResources.Add("$($svcPrincipalId.displayName) (updated: +$AddedCount/-$RemovedCount)") } } + if ($ChangedResources.Count -gt 0) { + Write-LogMessage -API 'Add-CIPPDelegatedPermission' -tenant $TenantFilter -message "Updated delegated permissions for $($ourSVCPrincipal.displayName): $($ChangedResources -join '; ')" -Sev 'Info' + } + $Failures = @($Results | Where-Object { $_ -match '^Failed to' }) + if ($Failures.Count -gt 0) { + Write-LogMessage -API 'Add-CIPPDelegatedPermission' -tenant $TenantFilter -message "Failed during delegated permission update for $($ourSVCPrincipal.displayName): $($Failures.Count) error(s)" -Sev 'Warning' -LogData @{ Failures = $Failures } + } + return $Results } diff --git a/Modules/CIPPCore/Public/Add-CIPPGDAPRoleTemplate.ps1 b/Modules/CIPPCore/Public/Add-CIPPGDAPRoleTemplate.ps1 index 4c01b85cb78c8..c8b9cad39c180 100644 --- a/Modules/CIPPCore/Public/Add-CIPPGDAPRoleTemplate.ps1 +++ b/Modules/CIPPCore/Public/Add-CIPPGDAPRoleTemplate.ps1 @@ -10,38 +10,53 @@ function Add-CIPPGDAPRoleTemplate { param( $TemplateId, $RoleMappings, - [switch]$Overwrite + [switch]$Overwrite, + $Headers, + $APIName = 'AddGDAPRoleTemplate' ) - $Table = Get-CIPPTable -TableName 'GDAPRoleTemplates' - $Templates = Get-CIPPAzDataTableEntity @Table - if ($Templates.RowKey -contains $TemplateId -and !$Overwrite.IsPresent) { - $ExistingTemplate = $Templates | Where-Object -Property RowKey -EQ $RowKey - try { - $ExistingRoleMappings = $ExistingTemplate.RoleMappings | ConvertFrom-Json - } catch { - $ExistingRoleMappings = @() - } - $NewRoleMappings = [System.Collections.Generic.List[object]]@() + try { + $Table = Get-CIPPTable -TableName 'GDAPRoleTemplates' + $Templates = Get-CIPPAzDataTableEntity @Table + if ($Templates.RowKey -contains $TemplateId -and !$Overwrite.IsPresent) { + $ExistingTemplate = $Templates | Where-Object -Property RowKey -EQ $TemplateId + try { + $ExistingRoleMappings = $ExistingTemplate.RoleMappings | ConvertFrom-Json + } catch { + $ExistingRoleMappings = @() + } + $NewRoleMappings = [System.Collections.Generic.List[object]]@() - $ExistingRoleMappings | ForEach-Object { - $NewRoleMappings.Add($_) - } - # Merge the new role mappings with the existing role mappings, exclude ones that have a duplicate roleDefinitionId - $RoleMappings | ForEach-Object { - if ($_.roleDefinitionId -notin $ExistingRoleMappings.roleDefinitionId) { + $ExistingRoleMappings | ForEach-Object { $NewRoleMappings.Add($_) } + # Merge the new role mappings with the existing role mappings, exclude ones that have a duplicate roleDefinitionId + $RoleMappings | ForEach-Object { + if ($_.roleDefinitionId -notin $ExistingRoleMappings.roleDefinitionId) { + $NewRoleMappings.Add($_) + } + } + $NewRoleMappings = @($NewRoleMappings | Sort-Object -Property GroupName) | ConvertTo-Json -Compress + $ExistingTemplate.RoleMappings = [string]$NewRoleMappings + $Template = $ExistingTemplate + Add-CIPPAzDataTableEntity @Table -Entity $Template -Force + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Updated GDAP role template '$TemplateId'" -Sev 'Info' + } else { + $Template = [PSCustomObject]@{ + PartitionKey = 'RoleTemplate' + RowKey = $TemplateId + RoleMappings = [string](@($RoleMappings | Sort-Object -Property GroupName) | ConvertTo-Json -Compress) + } + Add-CIPPAzDataTableEntity @Table -Entity $Template -Force + if ($Overwrite.IsPresent) { + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Overwrote GDAP role template '$TemplateId'" -Sev 'Info' + } else { + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Created GDAP role template '$TemplateId'" -Sev 'Info' + } } - $NewRoleMappings = @($NewRoleMappings | Sort-Object -Property GroupName) | ConvertTo-Json -Compress - $ExistingTemplate.RoleMappings = [string]$NewRoleMappings - $Template = $ExistingTemplate - } else { - $Template = [PSCustomObject]@{ - PartitionKey = 'RoleTemplate' - RowKey = $TemplateId - RoleMappings = [string](@($RoleMappings | Sort-Object -Property GroupName) | ConvertTo-Json -Compress) - } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Failed to save GDAP role template '$TemplateId': $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage + throw } - Add-CIPPAzDataTableEntity @Table -Entity $Template -Force } diff --git a/Modules/CIPPCore/Public/Add-CIPPScheduledTask.ps1 b/Modules/CIPPCore/Public/Add-CIPPScheduledTask.ps1 index 1eaaa5f840663..f94ec6b7675e7 100644 --- a/Modules/CIPPCore/Public/Add-CIPPScheduledTask.ps1 +++ b/Modules/CIPPCore/Public/Add-CIPPScheduledTask.ps1 @@ -38,7 +38,8 @@ function Add-CIPPScheduledTask { $ExistingTask.TaskState = 'Planned' Add-CIPPAzDataTableEntity @Table -Entity $ExistingTask -Force Write-LogMessage -headers $Headers -API 'RunNow' -message "Task $($ExistingTask.Name) scheduled to run now" -Sev 'Info' -Tenant $ExistingTask.Tenant - Add-CippQueueMessage -Cmdlet 'Start-UserTasksOrchestrator' -Parameters @{ + # Add-CippQueueMessage returns $true; without discarding it the caller's Results array shows a bare 'true' + $null = Add-CippQueueMessage -Cmdlet 'Start-UserTasksOrchestrator' -Parameters @{ TaskId = $RowKey } return "Task $($ExistingTask.Name) scheduled to run now" @@ -58,7 +59,7 @@ function Add-CIPPScheduledTask { $Filter = "PartitionKey eq 'ScheduledTask' and Name eq '$($Task.Name)' and TaskState ne 'Completed' and TaskState ne 'Failed'" $ExistingTask = (Get-CIPPAzDataTableEntity @Table -Filter $Filter) if ($ExistingTask) { - return "Task with name $($Task.Name) already exists" + return "Error - A scheduled task named '$($Task.Name)' already exists and was not created again." } } @@ -147,7 +148,6 @@ function Add-CIPPScheduledTask { $Parameters.Headers = $Headers | Select-Object -Property 'x-forwarded-for', 'x-ms-client-principal', 'x-ms-client-principal-idp', 'x-ms-client-principal-name' } - $Parameters = ($Parameters | ConvertTo-Json -Depth 10 -Compress) $AdditionalProperties = [System.Collections.Hashtable]@{} foreach ($Prop in $task.AdditionalProperties) { if ($null -eq $Prop.Value -or $Prop.Value -eq '' -or ($Prop.Value | Measure-Object).Count -eq 0) { @@ -156,7 +156,6 @@ function Add-CIPPScheduledTask { $AdditionalProperties[$Prop.Key] = $Prop.Value } $AdditionalProperties = ([PSCustomObject]$AdditionalProperties | ConvertTo-Json -Compress) - if ($Parameters -eq 'null') { $Parameters = '' } $Recurrence = if ([string]::IsNullOrEmpty($task.Recurrence.value)) { @@ -223,6 +222,22 @@ function Add-CIPPScheduledTask { } } + # Stored parameters are user input: strip any tenant-identifying parameter so the + # authorized task tenant is injected at execution instead of a stored value, and log + # when the stored value pointed somewhere other than the picked tenant. + foreach ($TenantParamName in @('TenantFilter', 'Tenant', 'TenantId')) { + if (-not $Parameters.ContainsKey($TenantParamName)) { continue } + $StoredTenantValue = $Parameters[$TenantParamName] + $StoredTenantString = [string]($StoredTenantValue.value ?? $StoredTenantValue) + if (![string]::IsNullOrWhiteSpace($StoredTenantString) -and $StoredTenantString -ne [string]$tenantFilter) { + Write-LogMessage -headers $Headers -API 'ScheduledTask' -message "Task $($task.Name): parameter -$TenantParamName value '$StoredTenantString' does not match the selected tenant '$tenantFilter' and was removed; the task runs against the selected tenant." -Sev 'Error' -Tenant $tenantFilter + } + $Parameters.Remove($TenantParamName) + } + + $Parameters = ($Parameters | ConvertTo-Json -Depth 10 -Compress) + if ($Parameters -eq 'null') { $Parameters = '' } + $entity = @{ PartitionKey = [string]'ScheduledTask' TaskState = [string]'Planned' @@ -243,6 +258,8 @@ function Add-CIPPScheduledTask { AlertComment = [string]$task.AlertComment CustomSubject = [string]$task.CustomSubject PsaTicketStrategy = [string]($task.PsaTicketStrategy.value ?? $task.PsaTicketStrategy) + PsaTicketPriority = [string]($task.PsaTicketPriority.value ?? $task.PsaTicketPriority) + PsaTicketId = [string]($task.PsaTicketId.value ?? $task.PsaTicketId) } @@ -278,6 +295,13 @@ function Add-CIPPScheduledTask { } } + # Stored verbatim so the orchestrator expands groups at run time. The version marker tells + # it excludedTenants holds only the operator's picks, not a snapshot of unselected tenants. + if ($task.Tenants) { + $entity['Tenants'] = $task.Tenants -is [string] ? [string]$task.Tenants : [string]($task.Tenants | ConvertTo-Json -Compress -Depth 10) + $entity['TenantSelectionVersion'] = 2 + } + if ($task.Trigger) { $entity.Trigger = [string]($task.Trigger | ConvertTo-Json -Compress) $TriggerType = $task.Trigger.Type.value ?? $task.Trigger.Type @@ -346,7 +370,8 @@ function Add-CIPPScheduledTask { } if ($RunNow.IsPresent) { - Add-CippQueueMessage -Cmdlet 'Start-UserTasksOrchestrator' -Parameters @{ + # Add-CippQueueMessage returns $true; without discarding it the caller's Results array shows a bare 'true' + $null = Add-CippQueueMessage -Cmdlet 'Start-UserTasksOrchestrator' -Parameters @{ TaskId = $RowKey } return "Task $($entity.Name) scheduled to run now" diff --git a/Modules/CIPPCore/Public/AsyncDeployment/Add-CIPPAsyncDeploymentStep.ps1 b/Modules/CIPPCore/Public/AsyncDeployment/Add-CIPPAsyncDeploymentStep.ps1 new file mode 100644 index 0000000000000..08ff6f00ff9ea --- /dev/null +++ b/Modules/CIPPCore/Public/AsyncDeployment/Add-CIPPAsyncDeploymentStep.ps1 @@ -0,0 +1,66 @@ +function Add-CIPPAsyncDeploymentStep { + <# + .SYNOPSIS + Append a step to an async deployment row + + .DESCRIPTION + Adds a step, with its final status, to the end of a CacheAsyncDeployments row created by + New-CIPPAsyncDeployment. Used for work that only exists once the job has finished, such as the + post-execution notifications of an offboarding. Meant to be called after the parallel step + workers are done; failures to persist are swallowed so reporting never breaks the job. + + .PARAMETER JobId + The deployment job id + + .PARAMETER Name + The row name (the user for offboarding, the tenant for tenant-keyed jobs) + + .PARAMETER Title + Step title shown to the user + + .PARAMETER StepStatus + pending, running, succeeded or failed + + .PARAMETER Message + Progress message shown under the step title + + .PARAMETER Kind + What kind of step this is, e.g. 'notify'. The UI offers a step re-run only for plain task steps. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$JobId, + + [Parameter(Mandatory = $true)] + [string]$Name, + + [Parameter(Mandatory = $true)] + [string]$Title, + + [ValidateSet('pending', 'running', 'succeeded', 'failed')] + [string]$StepStatus = 'succeeded', + + [string]$Message = '', + + [string]$Kind = '' + ) + + try { + if ($Message.Length -gt 2000) { $Message = $Message.Substring(0, 2000) + '...' } + $Table = Get-CIPPTable -TableName 'CacheAsyncDeployments' + $SafeJobId = $JobId -replace "'", "''" + $SafeName = $Name -replace "'", "''" + $Row = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq '$SafeJobId' and RowKey eq '$SafeName'" + if (-not $Row) { return } + + $Steps = @( + @($Row.Steps | ConvertFrom-Json) + [pscustomobject]@{ Title = $Title; Status = $StepStatus; Message = $Message; Kind = $Kind } + ) + $Row.Steps = [string](ConvertTo-Json -InputObject @($Steps) -Compress -Depth 5) + Update-CIPPAzDataTableEntity @Table -Entity $Row -Force + } catch { + Write-Verbose "Failed to append async deployment step: $($_.Exception.Message)" + } +} diff --git a/Modules/CIPPCore/Public/AsyncDeployment/Get-CIPPAsyncDeployment.ps1 b/Modules/CIPPCore/Public/AsyncDeployment/Get-CIPPAsyncDeployment.ps1 index d91caacbe8a52..4162a966d2d4e 100644 --- a/Modules/CIPPCore/Public/AsyncDeployment/Get-CIPPAsyncDeployment.ps1 +++ b/Modules/CIPPCore/Public/AsyncDeployment/Get-CIPPAsyncDeployment.ps1 @@ -26,6 +26,9 @@ function Get-CIPPAsyncDeployment { Name = $_.RowKey Source = $_.Source Status = $_.Status + TaskId = $_.TaskId + # Offboarding rows are users, so the tenant rides alongside; tenant-keyed jobs leave it empty + TenantFilter = $_.TenantFilter Steps = @($_.Steps | ConvertFrom-Json) Logs = $_.Logs } diff --git a/Modules/CIPPCore/Public/AsyncDeployment/New-CIPPAsyncDeployment.ps1 b/Modules/CIPPCore/Public/AsyncDeployment/New-CIPPAsyncDeployment.ps1 index 68eb4eb19bfe1..e59d666c5614b 100644 --- a/Modules/CIPPCore/Public/AsyncDeployment/New-CIPPAsyncDeployment.ps1 +++ b/Modules/CIPPCore/Public/AsyncDeployment/New-CIPPAsyncDeployment.ps1 @@ -17,10 +17,21 @@ function New-CIPPAsyncDeployment { One row is created per name — typically the target tenants. .PARAMETER StepTitles - Ordered step titles shown to the user (e.g. one per site template) + Ordered steps shown to the user (e.g. one per site template): a title string, or an object with + Title plus an optional Kind (e.g. 'notify', which the UI does not offer for step re-run) and an + initial Message. Optional, so a row can be created as soon as work is queued and given its steps + later by calling this again with the same JobId and Name. .PARAMETER Source Which feature created this job (e.g. SharePointTemplate) + + .PARAMETER TenantFilter + The tenant the rows belong to, when the names are not tenants themselves (offboarding rows are + users). Stored on the row so restricted callers only see rows for tenants in their scope. + + .PARAMETER TaskId + The ScheduledTasks RowKey behind the row(s), when the work runs as a scheduled task. Stored on + the row so the UI can offer a re-run through the scheduler. #> [CmdletBinding()] param( @@ -29,19 +40,31 @@ function New-CIPPAsyncDeployment { [Parameter(Mandatory = $true)] [string[]]$Names, - [Parameter(Mandatory = $true)] - [string[]]$StepTitles, + [object[]]$StepTitles = @(), + + [string]$Source = 'CIPP', + + [string]$TaskId, - [string]$Source = 'CIPP' + [string]$TenantFilter ) $Table = Get-CIPPTable -TableName 'CacheAsyncDeployments' $InitialSteps = [string](ConvertTo-Json -Compress -Depth 5 -InputObject @( $StepTitles | ForEach-Object { - @{ - Title = [string]$_ - Status = 'pending' - Message = 'Waiting for deployment to start' + if ($_ -is [string]) { + @{ + Title = [string]$_ + Status = 'pending' + Message = 'Waiting to start' + } + } else { + @{ + Title = [string]$_.Title + Status = 'pending' + Message = [string]($_.Message ?? 'Waiting to start') + Kind = [string]$_.Kind + } } } )) @@ -53,6 +76,8 @@ function New-CIPPAsyncDeployment { Source = [string]$Source Status = 'queued' Steps = $InitialSteps + TaskId = [string]$TaskId + TenantFilter = [string]$TenantFilter Logs = '' } -Force } diff --git a/Modules/CIPPCore/Public/AsyncDeployment/Set-CIPPAsyncDeploymentStep.ps1 b/Modules/CIPPCore/Public/AsyncDeployment/Set-CIPPAsyncDeploymentStep.ps1 index 84943120f71c4..b95305fac8ea5 100644 --- a/Modules/CIPPCore/Public/AsyncDeployment/Set-CIPPAsyncDeploymentStep.ps1 +++ b/Modules/CIPPCore/Public/AsyncDeployment/Set-CIPPAsyncDeploymentStep.ps1 @@ -5,8 +5,9 @@ function Set-CIPPAsyncDeploymentStep { .DESCRIPTION Sets the status and message of a single step on a CacheAsyncDeployments row created by - New-CIPPAsyncDeployment. Safe to call from queue workers; failures to persist are - swallowed so status reporting never breaks the actual deployment. + New-CIPPAsyncDeployment. Safe to call from queue workers, including several at once for + different steps of the same row; failures to persist are swallowed so status reporting + never breaks the actual work. .PARAMETER JobId The deployment job id @@ -41,20 +42,31 @@ function Set-CIPPAsyncDeploymentStep { [string]$Message = '' ) - try { - $Table = Get-CIPPTable -TableName 'CacheAsyncDeployments' - $SafeJobId = $JobId -replace "'", "''" - $SafeName = $Name -replace "'", "''" - $Row = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq '$SafeJobId' and RowKey eq '$SafeName'" - if (-not $Row) { return } - - $Steps = @($Row.Steps | ConvertFrom-Json) - if ($StepIndex -lt 0 -or $StepIndex -ge $Steps.Count) { return } - $Steps[$StepIndex].Status = $StepStatus - $Steps[$StepIndex].Message = $Message - $Row.Steps = [string](ConvertTo-Json -InputObject @($Steps) -Compress -Depth 5) - Add-CIPPAzDataTableEntity @Table -Entity $Row -Force - } catch { - Write-Verbose "Failed to update async deployment step: $($_.Exception.Message)" + # Keep the row well inside the 64 KB property limit: a cmdlet that lists hundreds of groups + # would otherwise make the whole write fail and freeze the progress view. + if ($Message.Length -gt 2000) { $Message = $Message.Substring(0, 2000) + '...' } + + # All steps of a row live in one JSON property, and steps can run on different workers at the + # same time. The write is ETag-checked (no -Force) so a step finishing between our read and + # write is not overwritten; a rejected write re-reads the row and tries again. + for ($Attempt = 1; $Attempt -le 5; $Attempt++) { + try { + $Table = Get-CIPPTable -TableName 'CacheAsyncDeployments' + $SafeJobId = $JobId -replace "'", "''" + $SafeName = $Name -replace "'", "''" + $Row = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq '$SafeJobId' and RowKey eq '$SafeName'" + if (-not $Row) { return } + + $Steps = @($Row.Steps | ConvertFrom-Json) + if ($StepIndex -lt 0 -or $StepIndex -ge $Steps.Count) { return } + $Steps[$StepIndex].Status = $StepStatus + $Steps[$StepIndex].Message = $Message + $Row.Steps = [string](ConvertTo-Json -InputObject @($Steps) -Compress -Depth 5) + Update-CIPPAzDataTableEntity @Table -Entity $Row + return + } catch { + Write-Verbose "Failed to update async deployment step (attempt $Attempt): $($_.Exception.Message)" + Start-Sleep -Milliseconds (Get-Random -Minimum 50 -Maximum 250) + } } } diff --git a/Modules/CIPPCore/Public/Authentication/Get-CIPPHttpFunctions.ps1 b/Modules/CIPPCore/Public/Authentication/Get-CIPPHttpFunctions.ps1 index 6074f4c09bd01..e68eeb19fee48 100644 --- a/Modules/CIPPCore/Public/Authentication/Get-CIPPHttpFunctions.ps1 +++ b/Modules/CIPPCore/Public/Authentication/Get-CIPPHttpFunctions.ps1 @@ -68,6 +68,7 @@ function Get-CIPPHttpFunctions { } $Results } catch { - "Function Error $($_.Exception.Message): $($_.InvocationInfo.PositionMessage)" + # A failed enumeration must fail, or the caller caches the error text as the universe. + throw "Failed to enumerate HTTP function permissions: $($_.Exception.Message) $($_.InvocationInfo.PositionMessage)" } } diff --git a/Modules/CIPPCore/Public/Authentication/Get-CippApiClient.ps1 b/Modules/CIPPCore/Public/Authentication/Get-CippApiClient.ps1 index 0bdd119a85753..ca0d3399e4723 100644 --- a/Modules/CIPPCore/Public/Authentication/Get-CippApiClient.ps1 +++ b/Modules/CIPPCore/Public/Authentication/Get-CippApiClient.ps1 @@ -29,8 +29,11 @@ function Get-CippApiClient { if ($Client.IPRange) { try { $IPRange = @($Client.IPRange | ConvertFrom-Json -ErrorAction Stop) - if (($IPRange | Measure-Object).Count -eq 0) { @('Any') } - $Client.IPRange = $IPRange + if (($IPRange | Measure-Object).Count -eq 0) { + $Client.IPRange = @('Any') + } else { + $Client.IPRange = $IPRange + } } catch { $Client.IPRange = @('Any') } diff --git a/Modules/CIPPCore/Public/Authentication/Get-CippHttpPermissions.ps1 b/Modules/CIPPCore/Public/Authentication/Get-CippHttpPermissions.ps1 index 599ce78189de4..6b5f573d5aa42 100644 --- a/Modules/CIPPCore/Public/Authentication/Get-CippHttpPermissions.ps1 +++ b/Modules/CIPPCore/Public/Authentication/Get-CippHttpPermissions.ps1 @@ -31,20 +31,35 @@ function Get-CippHttpPermissions { $AllPermissionCacheTable = Get-CIPPTable -tablename 'cachehttppermissions' $AllPermissionsRow = Get-CIPPAzDataTableEntity @AllPermissionCacheTable -Filter "PartitionKey eq 'HttpFunctions' and RowKey eq 'HttpFunctions' and Version eq '$($Version)'" - if (-not $AllPermissionsRow.Permissions) { - $AllPermissions = Get-CIPPHttpFunctions -ByRole | Select-Object -ExpandProperty Permission - $Entity = @{ - PartitionKey = 'HttpFunctions' - RowKey = 'HttpFunctions' - Version = [string]$Version - Permissions = [string]($AllPermissions | ConvertTo-Json -Compress) - } - Add-CIPPAzDataTableEntity @AllPermissionCacheTable -Entity $Entity -Force + # A universe written by an out-of-memory worker is short or garbage and was never recomputed; validate on read and write. + $Cached = if ($AllPermissionsRow.Permissions) { + try { @($AllPermissionsRow.Permissions | ConvertFrom-Json -ErrorAction Stop) } catch { @() } + } else { @() } + + if (Test-CippHttpPermissionUniverse -Permissions $Cached) { + $AllPermissions = $Cached } else { - $AllPermissions = $AllPermissionsRow.Permissions | ConvertFrom-Json + if ($AllPermissionsRow.Permissions) { + Write-Warning "The cached HTTP permission universe for version $Version is not usable ($($Cached.Count) entries); recomputing it." + } + $AllPermissions = @(Get-CIPPHttpFunctions -ByRole | Select-Object -ExpandProperty Permission) + if (Test-CippHttpPermissionUniverse -Permissions $AllPermissions) { + $Entity = @{ + PartitionKey = 'HttpFunctions' + RowKey = 'HttpFunctions' + Version = [string]$Version + Permissions = [string]($AllPermissions | ConvertTo-Json -Compress) + } + Add-CIPPAzDataTableEntity @AllPermissionCacheTable -Entity $Entity -Force + } else { + # Serve it uncached so the next request retries. + Write-Warning "HTTP permission enumeration returned $($AllPermissions.Count) entries, which is not a complete universe; not caching it." + return @($AllPermissions) + } } $script:CippHttpPermissions = @($AllPermissions) $script:CippHttpPermissionsVersion = $Version return $script:CippHttpPermissions } + diff --git a/Modules/CIPPCore/Public/Authentication/Set-CIPPAccessRole.ps1 b/Modules/CIPPCore/Public/Authentication/Set-CIPPAccessRole.ps1 index 623a318b472c8..2d539283a7c67 100644 --- a/Modules/CIPPCore/Public/Authentication/Set-CIPPAccessRole.ps1 +++ b/Modules/CIPPCore/Public/Authentication/Set-CIPPAccessRole.ps1 @@ -22,7 +22,9 @@ function Set-CIPPAccessRole { [Parameter(Mandatory = $true)] [string]$Role, [Parameter(Mandatory = $true)] - $Group + $Group, + $Headers, + $APIName = 'Set-CIPPAccessRole' ) $BlacklistedRoles = @('authenticated', 'anonymous') @@ -56,5 +58,7 @@ function Set-CIPPAccessRole { Clear-CippAccessUserCache try { Start-UserSyncTimer } catch {} try { [Craft.Services.AuthBridge]::InvalidateUsers() } catch {} + + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Mapped Entra group '$($Group.displayName)' to CIPP access role '$Role'" -Sev 'Info' } } diff --git a/Modules/CIPPCore/Public/Authentication/Test-CIPPAccess.ps1 b/Modules/CIPPCore/Public/Authentication/Test-CIPPAccess.ps1 index 890251be393d2..876542e4f229c 100644 --- a/Modules/CIPPCore/Public/Authentication/Test-CIPPAccess.ps1 +++ b/Modules/CIPPCore/Public/Authentication/Test-CIPPAccess.ps1 @@ -272,6 +272,13 @@ function Test-CIPPAccess { if ($env:cipp_hosted_failed_payments) { $MeResponse['hostedFailedPayments'] = $true } + # CyberDrain-hosted instance (CIPP_HOSTED is set by the hosted deployment templates). + # Lets the frontend point at the management portal for anything the instance's own + # identity cannot do, such as custom domains on the shared App Service plan. + $MeResponse['hosted'] = $env:CIPP_HOSTED -eq 'true' + # CIPP-NG (container web app on an App Service plan) versus a legacy function app plus + # static web app - the backend page shows different resources for each. + $MeResponse['ng'] = $env:CIPPNG -eq 'true' $CanManageAppSettings = $Permissions -contains 'CIPP.AppSettings.ReadWrite' $HasAnyPermission = ($Permissions | Measure-Object).Count -gt 0 @@ -469,78 +476,49 @@ function Test-CIPPAccess { if ($PermissionsFound) { # Tenant list and group list requests have already returned above, from the # cached scope rules. Everything from here is the per-endpoint access decision. + # Resolve the target from the request only. Do not fall back to $env:TenantID — + # that is the partner/home tenant, not a customer. Missing/unmapped filters are + # unresolved: Test-CippRoleTenantScope returns $true (block fail-closed / allow quirk). + $TenantFilter = $Request.Query.tenantFilter ?? $Request.Body.tenantFilter.value ?? $Request.Body.tenantFilter ?? $Request.Query.tenantId ?? $Request.Body.tenantId.value ?? $Request.Body.tenantId $TenantAllowed = $false $APIAllowed = $false $swPermissionEval = [System.Diagnostics.Stopwatch]::StartNew() + + # Block pass: deny wins, but only when the blocking role also grants the + # permission and its tenant scope covers the target. Test-CippRoleTenantScope + # returns $true for missing/unmapped tenants — here that means fail closed (apply block). foreach ($Role in $PermissionSet) { + $RoleGrantsPermission = $false foreach ($Perm in $Role.Permissions) { if ($Perm -match $APIRole) { - if ($Role.BlockedEndpoints -contains $Request.Params.CIPPEndpoint) { - throw "Access to this CIPP API endpoint is not allowed, the custom role '$($Role.Role)' has blocked this endpoint: $($Request.Params.CIPPEndpoint)" - } - $APIAllowed = $true + $RoleGrantsPermission = $true break } } + if (-not $RoleGrantsPermission) { continue } + if ($Role.BlockedEndpoints -notcontains $Request.Params.CIPPEndpoint) { continue } - if ($APIAllowed) { - $TenantFilter = $Request.Query.tenantFilter ?? $Request.Body.tenantFilter.value ?? $Request.Body.tenantFilter ?? $Request.Query.tenantId ?? $Request.Body.tenantId.value ?? $Request.Body.tenantId ?? $env:TenantID - # Check tenant level access - if (($Role.BlockedTenants | Measure-Object).Count -eq 0 -and $Role.AllowedTenants -contains 'AllTenants') { - $TenantAllowed = $true - } elseif ($TenantFilter -eq 'AllTenants' -and $ApiRole -match 'Write$') { - $TenantAllowed = $false - } elseif ($TenantFilter -eq 'AllTenants' -and $ApiRole -match 'Read$') { - $TenantAllowed = $true - } else { - $Tenant = ($Tenants | Where-Object { $TenantFilter -eq $_.customerId -or $TenantFilter -eq $_.defaultDomainName }).customerId - - # Expand allowed tenant groups to individual tenant IDs - $ExpandedAllowedTenants = foreach ($AllowedItem in $Role.AllowedTenants) { - if ($AllowedItem -is [PSCustomObject] -and $AllowedItem.type -eq 'Group') { - try { - $GroupMembers = Expand-CIPPTenantGroups -TenantFilter @($AllowedItem) - $GroupMembers | ForEach-Object { $_.addedFields.customerId } - } catch { - Write-Warning "Failed to expand allowed tenant group '$($AllowedItem.label)': $($_.Exception.Message)" - @() - } - } else { - $AllowedItem - } - } - - # Expand blocked tenant groups to individual tenant IDs - $ExpandedBlockedTenants = foreach ($BlockedItem in $Role.BlockedTenants) { - if ($BlockedItem -is [PSCustomObject] -and $BlockedItem.type -eq 'Group') { - try { - $GroupMembers = Expand-CIPPTenantGroups -TenantFilter @($BlockedItem) - $GroupMembers | ForEach-Object { $_.addedFields.customerId } - } catch { - Write-Warning "Failed to expand blocked tenant group '$($BlockedItem.label)': $($_.Exception.Message)" - @() - } - } else { - $BlockedItem - } - } - - if ($ExpandedAllowedTenants -contains 'AllTenants') { - $AllowedTenants = $Tenants.customerId - } else { - $AllowedTenants = $ExpandedAllowedTenants - } + $BlockInScope = Test-CippRoleTenantScope -Role $Role -TenantFilter $TenantFilter -Tenants $Tenants -Request $Request -ApiRole $APIRole + if ($BlockInScope) { + throw "Access to this CIPP API endpoint is not allowed, the custom role '$($Role.Role)' has blocked this endpoint: $($Request.Params.CIPPEndpoint)" + } + } - if ($Tenant) { - $TenantAllowed = $AllowedTenants -contains $Tenant -and $ExpandedBlockedTenants -notcontains $Tenant - if (!$TenantAllowed) { continue } - break - } else { - $TenantAllowed = $true - break - } + # Allow pass: sticky $APIAllowed preserved (permission from one role + tenant + # from another can still succeed). BlockedEndpoints already handled above. + foreach ($Role in $PermissionSet) { + foreach ($Perm in $Role.Permissions) { + if ($Perm -match $APIRole) { + $APIAllowed = $true + break } } + + if ($APIAllowed) { + $TenantAllowed = Test-CippRoleTenantScope -Role $Role -TenantFilter $TenantFilter -Tenants $Tenants -Request $Request -ApiRole $APIRole + if (!$TenantAllowed) { continue } + break + } } $swPermissionEval.Stop() $AccessTimings['EvaluatePermissions'] = $swPermissionEval.Elapsed.TotalMilliseconds diff --git a/Modules/CIPPCore/Public/Authentication/Test-CippHttpPermissionUniverse.ps1 b/Modules/CIPPCore/Public/Authentication/Test-CippHttpPermissionUniverse.ps1 new file mode 100644 index 0000000000000..ec3d122c618cc --- /dev/null +++ b/Modules/CIPPCore/Public/Authentication/Test-CippHttpPermissionUniverse.ps1 @@ -0,0 +1,27 @@ +function Test-CippHttpPermissionUniverse { + <# + .SYNOPSIS + Decides whether a list of permission names can be the full HTTP permission universe. + .DESCRIPTION + The universe is every distinct .ROLE across the HTTP entrypoints - well over a hundred + names shaped Area.Object.Read/ReadWrite, always including the core read permission the + dashboard needs. A list that is short, contains non-permission text, or lacks the core + permission came from a failed or truncated enumeration. + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [AllowNull()] + [AllowEmptyCollection()] + [object[]]$Permissions + ) + + $Names = @($Permissions | ForEach-Object { [string]$_ } | Where-Object { -not [string]::IsNullOrWhiteSpace($_) }) + if ($Names.Count -lt 50) { return $false } + if ($Names -notcontains 'CIPP.Core.Read') { return $false } + foreach ($Name in $Names) { + if ($Name -ne 'None' -and $Name -notmatch '^[A-Za-z0-9]+\.[A-Za-z0-9]+\.[A-Za-z]+$') { return $false } + } + return $true +} diff --git a/Modules/CIPPCore/Public/Authentication/Test-CippRoleTenantScope.ps1 b/Modules/CIPPCore/Public/Authentication/Test-CippRoleTenantScope.ps1 new file mode 100644 index 0000000000000..c72d3abe1ca41 --- /dev/null +++ b/Modules/CIPPCore/Public/Authentication/Test-CippRoleTenantScope.ps1 @@ -0,0 +1,132 @@ +function Test-CippRoleTenantScope { + <# + .SYNOPSIS + Whether a custom role's tenant scope covers the request's target tenant (or group). + + .DESCRIPTION + Extracted from the per-endpoint allow path in Test-CIPPAccess. Same rules: + AllTenants with no blocked list, AllTenants Write/Read request special-cases, + group-shaped body authorized by group identity (no member expand), then + allowed-minus-blocked after expanding tenant groups. + + Unknown / missing / unmapped tenant filters return $true. Callers interpret that + differently: the allow path treats it as allow (legacy quirk); the + BlockedEndpoints pass treats it as in-scope so the deny still applies + (fail closed). Do not fall back to $env:TenantID — that is the partner + home tenant, not a customer. Do not "align" those call sites without an + explicit decision. + + .PARAMETER Role + Role permission object from Get-CIPPRolePermissions (AllowedTenants, BlockedTenants, ...). + + .PARAMETER TenantFilter + Resolved tenant filter string (customerId, domain, AllTenants, or group value when body is Group-shaped). + + .PARAMETER Tenants + Tenant list from Get-Tenants -IncludeErrors (used to resolve filter and expand AllTenants). + + .PARAMETER Request + HTTP request; Body.tenantFilter.type -eq 'Group' selects group-identity authorization. + + .PARAMETER ApiRole + Endpoint permission string; used for AllTenants Write$ / Read$ branches. + + .OUTPUTS + [bool] $true if the role's scope covers the target. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + [OutputType([bool])] + param( + [Parameter(Mandatory = $true)] + $Role, + + [Parameter(Mandatory = $true)] + [AllowEmptyString()] + [AllowNull()] + $TenantFilter, + + [Parameter(Mandatory = $true)] + [AllowEmptyCollection()] + [AllowNull()] + $Tenants, + + [Parameter(Mandatory = $true)] + $Request, + + [Parameter(Mandatory = $true)] + [string]$ApiRole + ) + + $Tenants = @($Tenants) + + if (($Role.BlockedTenants | Measure-Object).Count -eq 0 -and $Role.AllowedTenants -contains 'AllTenants') { + return $true + } + + if ($TenantFilter -eq 'AllTenants' -and $ApiRole -match 'Write$') { + return $false + } + + if ($TenantFilter -eq 'AllTenants' -and $ApiRole -match 'Read$') { + return $true + } + + # A requested tenant GROUP arrives as a complex body object + # {type:'Group', value:}. Authorize it by group identity against the + # role's granted groups - never by expanding members - so it can't fall + # through to the unknown-tenant allow below. Query-string filters are plain + # strings and cannot carry a group, so only the body object is a group request. + if ($Request.Body.tenantFilter.type -eq 'Group') { + $RequestedGroup = $Request.Body.tenantFilter.value + $AllowedGroupIds = @(foreach ($AllowedItem in $Role.AllowedTenants) { + if ($AllowedItem -is [PSCustomObject] -and $AllowedItem.type -eq 'Group') { $AllowedItem.value } + }) + return ($AllowedGroupIds -contains $RequestedGroup) + } + + $Tenant = ($Tenants | Where-Object { $TenantFilter -eq $_.customerId -or $TenantFilter -eq $_.defaultDomainName }).customerId + + $ExpandedAllowedTenants = foreach ($AllowedItem in $Role.AllowedTenants) { + if ($AllowedItem -is [PSCustomObject] -and $AllowedItem.type -eq 'Group') { + try { + $GroupMembers = Expand-CIPPTenantGroups -TenantFilter @($AllowedItem) + $GroupMembers | ForEach-Object { $_.addedFields.customerId } + } catch { + Write-Warning "Failed to expand allowed tenant group '$($AllowedItem.label)': $($_.Exception.Message)" + @() + } + } else { + $AllowedItem + } + } + + $ExpandedBlockedTenants = foreach ($BlockedItem in $Role.BlockedTenants) { + if ($BlockedItem -is [PSCustomObject] -and $BlockedItem.type -eq 'Group') { + try { + $GroupMembers = Expand-CIPPTenantGroups -TenantFilter @($BlockedItem) + $GroupMembers | ForEach-Object { $_.addedFields.customerId } + } catch { + Write-Warning "Failed to expand blocked tenant group '$($BlockedItem.label)': $($_.Exception.Message)" + @() + } + } else { + $BlockedItem + } + } + + if ($ExpandedAllowedTenants -contains 'AllTenants') { + $AllowedTenants = $Tenants.customerId + } else { + $AllowedTenants = $ExpandedAllowedTenants + } + + if ($Tenant) { + return ($AllowedTenants -contains $Tenant -and $ExpandedBlockedTenants -notcontains $Tenant) + } + + # Unmapped tenant filter: true for both call sites (allow quirk / block fail-closed). + return $true +} diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineAntiPhishPolicyState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineAntiPhishPolicyState.ps1 index af3c853f8d341..f18a8b63ad75e 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineAntiPhishPolicyState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineAntiPhishPolicyState.ps1 @@ -43,6 +43,11 @@ function Get-CIPPBaselineAntiPhishPolicyState { $Rule = @($Rules | Where-Object { "$($_.Name)" -eq $RuleName }) | Select-Object -First 1 $V = $Item.Variables + # Get-AntiPhishPolicy only populates Enabled for the built-in default policy; on a custom policy + # the active state lives on the rule's State (see Invoke-ListAntiPhishingFilters). Fall back to + # the policy value so the built-in default policy stays correct. + $PolicyEnabled = if ($null -ne $Rule.State) { $Rule.State -eq 'Enabled' } else { [bool]$Policy.Enabled } + # The eight properties every tenant has. $Expected = [PSCustomObject]@{ name = $PolicyName @@ -56,7 +61,7 @@ function Get-CIPPBaselineAntiPhishPolicyState { } $Current = [PSCustomObject]@{ name = "$($Policy.Name)" - enabled = [bool]$Policy.Enabled + enabled = $PolicyEnabled enableSpoofIntelligence = [bool]$Policy.EnableSpoofIntelligence enableFirstContactSafetyTips = [bool]$Policy.EnableFirstContactSafetyTips enableUnauthenticatedSender = [bool]$Policy.EnableUnauthenticatedSender diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineAuthenticationMethodsState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineAuthenticationMethodsState.ps1 index ffa1e606bccf2..892e5f334da42 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineAuthenticationMethodsState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineAuthenticationMethodsState.ps1 @@ -46,11 +46,16 @@ function Get-CIPPBaselineAuthenticationMethodsState { ) $Configured = @(foreach ($Method in $AuthMethods) { + # Formerly a switch (raw boolean), now a three-state autoComplete whose option + # wrapper the pipeline already unwrapped to $true/$false/'notConfigured'. Legacy + # booleans and the new values both land here; 'notConfigured' skips the method + # exactly like an absent variable - the tenant's current setting is never graded. $Enabled = $V."$($Method.Key)Enabled" - if ($null -eq $Enabled -or "$Enabled" -eq '') { continue } + $Enabled = $Enabled.value ?? $Enabled + if ($null -eq $Enabled -or "$Enabled" -eq '' -or "$Enabled" -eq 'notConfigured') { continue } [PSCustomObject]@{ Id = $Method.Id; RemediationId = $Method.RemediationId; Key = $Method.Key; Label = $Method.Label - Enabled = [bool]($Enabled -eq $true -or "$Enabled" -eq 'True') + Enabled = [bool]($Enabled -eq $true -or "$Enabled" -eq 'True' -or "$Enabled" -eq 'enabled') GroupName = "$($V."$($Method.Key)Group")" ExcludeGroupName = "$($V."$($Method.Key)ExcludeGroup")" } diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDefaultPlatformRestrictionsState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDefaultPlatformRestrictionsState.ps1 index d6f3d9d9d22df..c4c4e993705de 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDefaultPlatformRestrictionsState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDefaultPlatformRestrictionsState.ps1 @@ -48,6 +48,28 @@ function Get-CIPPBaselineDefaultPlatformRestrictionsState { $Expected | Add-Member -NotePropertyName $Entry.e -NotePropertyValue ([bool]($V.($Entry.e) -eq $true)) $Current | Add-Member -NotePropertyName $Entry.e -NotePropertyValue ([bool]$Config.($Entry.c).($Entry.p)) } + + # Minimum/maximum OS version per platform. macOS is intentionally absent - the Intune + # enrollment restriction for macOS carries no version limit. Each is graded ONLY when the + # operator supplied it (like WHfB's newer fields): a blank field means 'no opinion', so it + # stays out of the compare here and omitWhenBlank prunes it from the remediation body. + # osMinimumVersion/osMaximumVersion are free-form strings on Graph, compared as strings. + $VersionMap = @( + @{ e = 'osMinimumVersionAndroidForWork'; c = 'androidForWorkRestriction'; p = 'osMinimumVersion' } + @{ e = 'osMaximumVersionAndroidForWork'; c = 'androidForWorkRestriction'; p = 'osMaximumVersion' } + @{ e = 'osMinimumVersionAndroid'; c = 'androidRestriction'; p = 'osMinimumVersion' } + @{ e = 'osMaximumVersionAndroid'; c = 'androidRestriction'; p = 'osMaximumVersion' } + @{ e = 'osMinimumVersioniOS'; c = 'iosRestriction'; p = 'osMinimumVersion' } + @{ e = 'osMaximumVersioniOS'; c = 'iosRestriction'; p = 'osMaximumVersion' } + @{ e = 'osMinimumVersionWindows'; c = 'windowsRestriction'; p = 'osMinimumVersion' } + @{ e = 'osMaximumVersionWindows'; c = 'windowsRestriction'; p = 'osMaximumVersion' } + ) + foreach ($Entry in $VersionMap) { + if ([string]::IsNullOrWhiteSpace("$($V.($Entry.e))")) { continue } + $Expected | Add-Member -NotePropertyName $Entry.e -NotePropertyValue "$($V.($Entry.e))" + $Current | Add-Member -NotePropertyName $Entry.e -NotePropertyValue "$($Config.($Entry.c).($Entry.p))" + } + $Current | Add-Member -NotePropertyName 'configurationId' -NotePropertyValue "$($Config.id)" @{ Expected = $Expected; Current = $Current } diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDeployContactTemplatesState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDeployContactTemplatesState.ps1 index 923f73a95440b..bf66ff8d66e5a 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDeployContactTemplatesState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDeployContactTemplatesState.ps1 @@ -82,7 +82,7 @@ function Get-CIPPBaselineDeployContactTemplatesState { @{ Template = 'jobTitle'; Current = "$($Existing.Title)" } @{ Template = 'city'; Current = "$($Existing.City)" } @{ Template = 'postalCode'; Current = "$($Existing.PostalCode)" } - @{ Template = 'country'; Current = "$($Existing.CountryOrRegion)" } + @{ Template = 'country'; Current = "$($Existing.CountryOrRegion)"; IsCountry = $true } @{ Template = 'mobilePhone'; Current = "$($Existing.MobilePhone)" } ) $Differences = [System.Collections.Generic.List[string]]::new() @@ -93,7 +93,11 @@ function Get-CIPPBaselineDeployContactTemplatesState { continue } if ([string]::IsNullOrWhiteSpace("$TemplateValue")) { continue } - $Mismatch = if ($Field.IsEmail) { + # country: template stores an ISO code ('US'), Exchange returns the full name + # ('United States'); normalise both to a code before comparing. + $Mismatch = if ($Field.IsCountry) { + [string]::IsNullOrWhiteSpace($Field.Current) -or (ConvertTo-CIPPCountryCode "$TemplateValue") -ne (ConvertTo-CIPPCountryCode $Field.Current) + } elseif ($Field.IsEmail) { [string]::IsNullOrWhiteSpace($Field.Current) -or -not "$TemplateValue".Equals($Field.Current, [System.StringComparison]::OrdinalIgnoreCase) } else { [string]::IsNullOrWhiteSpace($Field.Current) -or "$TemplateValue" -ne $Field.Current diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableGuestsState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableGuestsState.ps1 index a014a5bfc03f6..2408a4bc0cc53 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableGuestsState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableGuestsState.ps1 @@ -1,16 +1,17 @@ function Get-CIPPBaselineDisableGuestsState { <# .SYNOPSIS - Prepare hook for DisableGuests: enabled guests that are stale or never accepted their - invitation. + Prepare hook for DisableGuests: enabled guests with no sign-in attempt inside the window. .DESCRIPTION - Read live rather than from the Guests cache: that collector expands sponsors but - selects neither signInActivity nor externalUserState, and both decide the verdict here. - Extending it would let this move to cache like the other user sweeps. + Read live rather than from the Guests cache: that collector expands sponsors but does not + select signInActivity, which decides the verdict here. Extending it would let this move to + cache like the other user sweeps. - A guest counts when it has not signed in within the window, OR when it is still - PendingAcceptance - an invitation nobody ever took up is exactly the account this is - meant to close. Accounts an admin re-enabled in the last 7 days are left alone. + A guest counts when the newest of its interactive, non-interactive and successful sign-in + timestamps is older than the window - the same view the Entra portal and the inactive-guest + alert give. Guests with no sign-in on record (typically invitations nobody redeemed) only + count when IncludeNeverSignedIn is on; it is off by default and off when the template + predates it. Accounts an admin re-enabled in the last 7 days are left alone. .FUNCTIONALITY Internal #> @@ -21,17 +22,15 @@ function Get-CIPPBaselineDisableGuestsState { ) $CheckDays = if ([string]::IsNullOrWhiteSpace("$($Item.Variables.days)")) { 90 } else { [int]$Item.Variables.days } + $IncludeNeverSignedIn = $Item.Variables.IncludeNeverSignedIn -eq $true $Cutoff = (Get-Date).AddDays(-$CheckDays).ToUniversalTime() $Lookup = $Cutoff.ToString('o') - $Guests = @(New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users?`$filter=createdDateTime le $Lookup and userType eq 'Guest' and accountEnabled eq true&`$select=id,userPrincipalName,signInActivity,mail,userType,accountEnabled,createdDateTime,externalUserState" -scope 'https://graph.microsoft.com/.default' -tenantid $TenantFilter) + $Guests = @(New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users?`$filter=createdDateTime le $Lookup and userType eq 'Guest' and accountEnabled eq true&`$select=id,userPrincipalName,signInActivity,mail,userType,accountEnabled,createdDateTime" -scope 'https://graph.microsoft.com/.default' -tenantid $TenantFilter) $Stale = @($Guests | Where-Object { - if ($_.signInActivity -and $_.signInActivity.lastSuccessfulSignInDateTime) { - ([datetime]$_.signInActivity.lastSuccessfulSignInDateTime).ToUniversalTime() -le $Cutoff - } else { - $_.externalUserState -eq 'PendingAcceptance' - } + $LastSignIn = Get-CIPPLastSignInDateTime -SignInActivity $_.signInActivity + if ($LastSignIn) { $LastSignIn -le $Cutoff } else { $IncludeNeverSignedIn } }) if ($Stale.Count -gt 0) { diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableSharedMailboxState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableSharedMailboxState.ps1 index 0dfea4da2f76f..f47f7f3c69485 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableSharedMailboxState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableSharedMailboxState.ps1 @@ -8,12 +8,12 @@ function Get-CIPPBaselineDisableSharedMailboxState { standard read the adminapi Mailbox endpoint live; the cache carries recipientTypeDetails and ExternalDirectoryObjectId, so no live call is needed. - NOTE - a deliberate behaviour change. The classic filter read + NOTE - the classic filter read RecipientTypeDetails -eq 'SharedMailbox' -or RecipientTypeDetails -eq 'SchedulingMailbox' -and UserPrincipalName -in $UserList - and -and binds tighter than -or, so the enabled/cloud-only test only ever applied to - SchedulingMailbox. Every shared mailbox was swept regardless, including ones whose - account was already disabled or directory-synced. The join here applies to both types, - which is what the standard's own description says it does. + which looks like it only joins SchedulingMailbox against the user list, but does not: + PowerShell gives -and and -or the same precedence and associates them left to right, so + it means '(shared or scheduling) and still enabled'. Same set as the join here; the only + real difference is that this one keys on ExternalDirectoryObjectId instead of the UPN. .FUNCTIONALITY Internal #> diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineExternalComplianceTrustedState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineExternalComplianceTrustedState.ps1 new file mode 100644 index 0000000000000..a9e1642109b08 --- /dev/null +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineExternalComplianceTrustedState.ps1 @@ -0,0 +1,26 @@ +function Get-CIPPBaselineExternalComplianceTrustedState { + <# + .SYNOPSIS + Prepare hook for ExternalComplianceTrusted: does the tenant trust device compliance from external tenants. + .DESCRIPTION + One graded boolean, read from the default cross-tenant access policy's inboundTrust. + A hook rather than a declarative expected because the operator's switch has to grade + in BOTH directions - trusting external device compliance and deliberately not trusting it + are both valid postures. + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + $Item, + $TenantFilter + ) + + $Policy = @(Get-CIPPBaselineCacheRows -TenantFilter $TenantFilter -Type 'CrossTenantAccessPolicy') | Select-Object -First 1 + if (-not $Policy) { return @{ Current = $null } } + + @{ + Expected = [PSCustomObject]@{ isCompliantDeviceAccepted = [bool]($Item.Variables.state -eq $true) } + Current = [PSCustomObject]@{ isCompliantDeviceAccepted = [bool]$Policy.inboundTrust.isCompliantDeviceAccepted } + } +} diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineFIDO2PasskeyProfilesState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineFIDO2PasskeyProfilesState.ps1 index 042dc95eb3ce9..e75cdd1f5757a 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineFIDO2PasskeyProfilesState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineFIDO2PasskeyProfilesState.ps1 @@ -31,6 +31,9 @@ function Get-CIPPBaselineFIDO2PasskeyProfilesState { $EnforcementType = "$($V.EnforcementType.value ?? $V.EnforcementType)" if ([string]::IsNullOrWhiteSpace($EnforcementType)) { $EnforcementType = 'allow' } $AAGUIDs = @("$($V.AAGUIDs)" -split ',' | ForEach-Object { $_.Trim() } | Where-Object { $_ } | Sort-Object) + # Supplying AAGUIDs implies enforcement - the list only takes effect while isEnforced = $true, so + # the expected state must enforce whenever AAGUIDs are present to match what the executor writes. + if ($AAGUIDs.Count -gt 0) { $EnforceRestrictions = $true } if ($EnforceRestrictions -and $AAGUIDs.Count -eq 0) { return @{ Current = $null } } $DefaultProfile = @($Config.passkeyProfiles) | Where-Object { "$($_.id)" -eq "$($Config.defaultPasskeyProfile)" } | Select-Object -First 1 diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineMailboxRecipientLimitsState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineMailboxRecipientLimitsState.ps1 index 042cc16981df8..079acaee98db4 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineMailboxRecipientLimitsState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineMailboxRecipientLimitsState.ps1 @@ -44,7 +44,8 @@ function Get-CIPPBaselineMailboxRecipientLimitsState { if ($UPN -like 'DiscoverySearchMailbox*' -or $UPN -like 'SystemMailbox*') { continue } $Plan = $PlanCap["$($Mailbox.MailboxPlanId)"] - $Cap = if ($Plan) { [int]"$($Plan.MaxRecipientsPerMessage)" } else { 0 } + # A plan without a stored limit (null on some tenants) means no cap - [int]'' throws. + $Cap = if ($Plan -and "$($Plan.MaxRecipientsPerMessage)" -match '^\d+$') { [int]"$($Plan.MaxRecipientsPerMessage)" } else { 0 } if ($Plan -and $Cap -gt 0 -and $Limit -gt $Cap) { $PlanIssues.Add("$UPN (plan $($Plan.DisplayName) caps at $Cap)") continue diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineMalwareFilterPolicyState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineMalwareFilterPolicyState.ps1 index e633388a38f17..948e76deaf86a 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineMalwareFilterPolicyState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineMalwareFilterPolicyState.ps1 @@ -10,7 +10,9 @@ function Get-CIPPBaselineMalwareFilterPolicyState { FileTypes is the 55-entry default list plus whatever the operator adds as a comma-separated string, compared as a set - the classic used Compare-Object, which is - order-insensitive, so both sides are sorted here. + order-insensitive, case-insensitive AND collapses duplicates, so both sides are + lowercased and unique-sorted here (tenants exist whose policy stores the list doubled, + and Exchange keeps whatever casing it was last sent). The two admin-notification addresses are graded only when supplied, matching the classic '($null -eq $Settings.X) -or ...' tests. @@ -45,8 +47,8 @@ function Get-CIPPBaselineMalwareFilterPolicyState { $Rule = @($Rules | Where-Object { "$($_.Name)" -eq $RuleName }) | Select-Object -First 1 $DefaultFileTypes = @('ace', 'ani', 'apk', 'app', 'appx', 'arj', 'bat', 'cab', 'cmd', 'com', 'deb', 'dex', 'dll', 'docm', 'elf', 'exe', 'hta', 'img', 'iso', 'jar', 'jnlp', 'kext', 'lha', 'lib', 'library', 'lnk', 'lzh', 'macho', 'msc', 'msi', 'msix', 'msp', 'mst', 'pif', 'ppa', 'ppam', 'reg', 'rev', 'scf', 'scr', 'sct', 'sys', 'uif', 'vb', 'vbe', 'vbs', 'vxd', 'wsc', 'wsf', 'wsh', 'xll', 'xz', 'z') - $Optional = @("$($Item.Variables.OptionalFileTypes)" -split ',' | ForEach-Object { $_.Trim() } | Where-Object { $_ }) - $ExpectedFileTypes = @(($DefaultFileTypes + $Optional) | Sort-Object) + $Optional = @("$($Item.Variables.OptionalFileTypes)" -split ',' | ForEach-Object { $_.Trim().ToLowerInvariant() } | Where-Object { $_ }) + $ExpectedFileTypes = @(($DefaultFileTypes + $Optional) | Sort-Object -Unique) $Expected = [PSCustomObject]@{ name = $PolicyName @@ -68,7 +70,7 @@ function Get-CIPPBaselineMalwareFilterPolicyState { name = "$($Policy.Name)" enableFileFilter = [bool]$Policy.EnableFileFilter fileTypeAction = "$($Policy.FileTypeAction)" - fileTypes = @(@($Policy.FileTypes) | Where-Object { $_ } | Sort-Object) + fileTypes = @(@($Policy.FileTypes) | Where-Object { $_ } | ForEach-Object { "$_".ToLowerInvariant() } | Sort-Object -Unique) zapEnabled = [bool]$Policy.ZapEnabled quarantineTag = "$($Policy.QuarantineTag)" enableInternalSenderAdminNotifications = [bool]$Policy.EnableInternalSenderAdminNotifications @@ -88,6 +90,10 @@ function Get-CIPPBaselineMalwareFilterPolicyState { } } + # The executor merges these over the spec's static policyParams. FileTypes is graded + # above, so it must also be written: a policy created or left without the list would + # otherwise drift on fileTypes forever with nothing ever sending them. + $Current | Add-Member -NotePropertyName 'extraPolicyParams' -NotePropertyValue ([PSCustomObject]@{ FileTypes = @($ExpectedFileTypes) }) $Current | Add-Member -NotePropertyName 'policyName' -NotePropertyValue $PolicyName $Current | Add-Member -NotePropertyName 'ruleName' -NotePropertyValue $RuleName $Current | Add-Member -NotePropertyName 'policyExists' -NotePropertyValue ([bool]$Policy) diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselinePhishProtectionState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselinePhishProtectionState.ps1 index 2081cb12fcce4..8ba46ddc3ed51 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselinePhishProtectionState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselinePhishProtectionState.ps1 @@ -34,9 +34,14 @@ function Get-CIPPBaselinePhishProtectionState { background-image: url(https://clone.cipp.app/api/PublicPhishingCheck?Tenantid=$($TenantFilter)&URL=https://$($CIPPUrl)); } "@ + # The here-string inherits the source file's line endings, but the branding CSS round-trips + # through Graph as LF. Normalise both sides so a CRLF checkout (or CSS stored with different + # endings) still grades a re-read as a match rather than a silent drift. + $CSS = $CSS -replace "`r`n", "`n" + $NormalizedBody = "$CurrentBody" -replace "`r`n", "`n" $Current = [PSCustomObject]@{ - phishingCSSEnabled = [bool]("$CurrentBody" -like "*$CSS*") + phishingCSSEnabled = [bool]($NormalizedBody -like "*$CSS*") } # Carried for the executor. $Current | Add-Member -NotePropertyName 'currentBody' -NotePropertyValue "$CurrentBody" diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineSPGuestPeoplePickerState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineSPGuestPeoplePickerState.ps1 new file mode 100644 index 0000000000000..e7cebdb9accf1 --- /dev/null +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineSPGuestPeoplePickerState.ps1 @@ -0,0 +1,54 @@ +function Get-CIPPBaselineSPGuestPeoplePickerState { + <# + .SYNOPSIS + Prepare hook for SPGuestPeoplePicker: the tenant default and every cached site collection whose + People Picker guest visibility differs from the wanted state. + .DESCRIPTION + Decides offenders from cache, not the live enumeration. Which sites differ comes from the + SPOSites reporting cache (refreshed by the daily SharePoint CIPPDB run); the tenant default is + read through Get-CIPPSPOTenant's own 1h cache (which works app-only with the certificate even + where the delegated SPOTenant reporting collector cannot). Reading cache keeps a large tenant + from being enumerated live on every run and lets the baseline engine's optimistic post-write + model verify on the next daily cache read. + + Detection always runs (the read is cheap and idempotent against the daily cache); the 24h + rerun guard lives in the executor so it throttles only the write sweep, never drift reporting. + + Returns the offenders/targets pair the sweep model expects: offenders are display strings + graded against [] ('Tenant default' plus offending site URLs); targets carry the Scope and the + value to write. Current is $null (No Data) only when the tenant configuration cannot be read. + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + $Item, + $TenantFilter + ) + + $Wanted = ($Item.Variables.showGuests -eq $true) -or ("$($Item.Variables.showGuests)" -eq 'true') + + try { + $Tenant = Get-CIPPSPOTenant -TenantFilter $TenantFilter -UseCertificate | Select-Object -First 1 + } catch { + return @{ Current = $null; NoDataReason = "Could not read the SharePoint tenant configuration: $($_.Exception.Message)" } + } + if (-not $Tenant) { return @{ Current = $null; NoDataReason = 'Could not read the SharePoint tenant configuration.' } } + + $Sites = @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'SPOSites' | Where-Object { $_ -and $_.Url }) + + $Offenders = [System.Collections.Generic.List[string]]::new() + $Targets = [System.Collections.Generic.List[object]]::new() + + if ([bool]$Tenant.ShowPeoplePickerSuggestionsForGuestUsers -ne $Wanted) { + $Offenders.Add('Tenant default') + $Targets.Add([PSCustomObject]@{ Scope = 'tenant'; SiteUrl = $null; Wanted = $Wanted }) + } + + foreach ($Site in ($Sites | Where-Object { [bool]$_.ShowPeoplePickerSuggestionsForGuestUsers -ne $Wanted } | Sort-Object Url)) { + $Offenders.Add("$($Site.Url)") + $Targets.Add([PSCustomObject]@{ Scope = 'site'; SiteUrl = "$($Site.Url)"; Wanted = $Wanted }) + } + + @{ Current = [PSCustomObject]@{ offenders = @($Offenders); targets = @($Targets) } } +} diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineSendReceiveLimitTenantState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineSendReceiveLimitTenantState.ps1 index 9bde6b58400ff..ecca826004fbd 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineSendReceiveLimitTenantState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineSendReceiveLimitTenantState.ps1 @@ -3,11 +3,12 @@ function Get-CIPPBaselineSendReceiveLimitTenantState { .SYNOPSIS Prepare hook for SendReceiveLimitTenant: mailbox plan send/receive limits. .DESCRIPTION - Grades which mailbox PLANS are off the configured limits - Exchange reports sizes as - display strings ('35 MB (36,700,160 bytes)'), so the byte count is parsed out the - way the classic parsed it, and 'Unlimited' always counts as an offender. New - mailboxes inherit their plan, which is why the plan is the graded object rather than - any mailbox. + Grades which mailbox PLANS are off the configured limits. The DBCache collector + normalizes MaxSendSize/MaxReceiveSize to whole MB ($null = Unlimited), so the compare + is MB against MB; rows written before that normalization still carry Exchange's + display strings ('35 MB (36,700,160 bytes)') and are parsed down to MB the same way. + 'Unlimited' always counts as an offender. New mailboxes inherit their plan, which is + why the plan is the graded object rather than any mailbox. .FUNCTIONALITY Internal #> @@ -25,18 +26,25 @@ function Get-CIPPBaselineSendReceiveLimitTenantState { $SendLimit = [int]"$($Item.Variables.SendLimit)" $ReceiveLimit = [int]"$($Item.Variables.ReceiveLimit)" if ($SendLimit -lt 1 -or $SendLimit -gt 150 -or $ReceiveLimit -lt 1 -or $ReceiveLimit -gt 150) { return @{ Current = $null } } - $MaxSendBytes = [int64]$SendLimit * 1MB - $MaxReceiveBytes = [int64]$ReceiveLimit * 1MB + + # The collector stores whole MB ($null = Unlimited); pre-normalization rows still hold + # display strings with a byte suffix, which reduce to the same MB value. + $ConvertSizeToMB = { + param($Value) + if ([string]::IsNullOrWhiteSpace("$Value") -or "$Value" -match 'Unlimited') { return $null } + if ("$Value" -match '\(([\d,]+)') { return [int][math]::Round([int64]($Matches[1] -replace ',', '') / 1MB) } + try { return [int]$Value } catch { return $null } + } $Offenders = [System.Collections.Generic.List[object]]::new() foreach ($Plan in $Plans) { - if ("$($Plan.MaxSendSize)" -match 'Unlimited' -or "$($Plan.MaxReceiveSize)" -match 'Unlimited') { + $PlanSend = & $ConvertSizeToMB $Plan.MaxSendSize + $PlanReceive = & $ConvertSizeToMB $Plan.MaxReceiveSize + if ($null -eq $PlanSend -or $null -eq $PlanReceive) { $Offenders.Add($Plan) continue } - $PlanSend = [int64]("$($Plan.MaxSendSize)" -replace '.*\(([\d,]+).*', '$1' -replace ',', '') - $PlanReceive = [int64]("$($Plan.MaxReceiveSize)" -replace '.*\(([\d,]+).*', '$1' -replace ',', '') - if ($PlanSend -ne $MaxSendBytes -or $PlanReceive -ne $MaxReceiveBytes) { $Offenders.Add($Plan) } + if ($PlanSend -ne $SendLimit -or $PlanReceive -ne $ReceiveLimit) { $Offenders.Add($Plan) } } $Current = [PSCustomObject]@{ plansOffLimits = @($Offenders | ForEach-Object { "$($_.DisplayName)" } | Sort-Object) } diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineSpamFilterPolicyState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineSpamFilterPolicyState.ps1 index dcf830c6698d7..15a092b4de3a4 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineSpamFilterPolicyState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineSpamFilterPolicyState.ps1 @@ -140,6 +140,16 @@ function Get-CIPPBaselineSpamFilterPolicyState { $Current | Add-Member -NotePropertyName 'regionBlockList' -NotePropertyValue @(@($Policy.RegionBlockList) | Where-Object { $_ } | ForEach-Object { "$_".ToUpper() } | Sort-Object) } + # BulkMovesEnabled (bulk mail to the Promotions folder) is in Preview and not available in + # every organization, so it is only graded - and written, via extraPolicyParams below - when + # explicitly configured On or Off. 'Do not configure' never sends the parameter to a tenant + # that may reject it. + $BulkMovesEnabled = "$($V.BulkMovesEnabled.value ?? $V.BulkMovesEnabled)" + if ($BulkMovesEnabled -in @('On', 'Off')) { + $Expected | Add-Member -NotePropertyName 'bulkMovesEnabled' -NotePropertyValue $BulkMovesEnabled + $Current | Add-Member -NotePropertyName 'bulkMovesEnabled' -NotePropertyValue "$($Policy.BulkMovesEnabled)" + } + # The built-in Default policy cannot carry a rule. if (-not $IsDefaultPolicy) { $Expected | Add-Member -NotePropertyName 'rule' -NotePropertyValue ([PSCustomObject]@{ @@ -189,6 +199,9 @@ function Get-CIPPBaselineSpamFilterPolicyState { } else { $ExtraPolicyParams['EnableRegionBlockList'] = $false } + if ($BulkMovesEnabled -in @('On', 'Off')) { + $ExtraPolicyParams['BulkMovesEnabled'] = $BulkMovesEnabled + } $Current | Add-Member -NotePropertyName 'extraPolicyParams' -NotePropertyValue ([PSCustomObject]$ExtraPolicyParams) @{ Expected = $Expected; Current = $Current } diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineUserSubmissionsState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineUserSubmissionsState.ps1 index edb4e1ea2b776..0a3b60789ef50 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineUserSubmissionsState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineUserSubmissionsState.ps1 @@ -36,8 +36,13 @@ function Get-CIPPBaselineUserSubmissionsState { if ($Email -notmatch '@') { return @{ Current = $null } } } + # 'Send reported items to' only applies when an address is configured; blank or missing + # keeps the original posture (Microsoft as well as the reporting mailbox). + $Destination = "$($Item.Variables.reportDestination.value ?? $Item.Variables.reportDestination)" + $ReportToMicrosoft = [string]::IsNullOrWhiteSpace($Email) -or $Destination -ne 'Mailbox' + if ($State -eq 'enable' -and -not [string]::IsNullOrWhiteSpace($Email)) { - $Expected = [PSCustomObject]@{ reportToMicrosoft = $true; customAddressCorrect = $true; ruleCorrect = $true } + $Expected = [PSCustomObject]@{ reportToMicrosoft = $ReportToMicrosoft; customAddressCorrect = $true; ruleCorrect = $true } $Current = [PSCustomObject]@{ reportToMicrosoft = [bool]$Policy.EnableReportToMicrosoft customAddressCorrect = [bool]($Policy.ReportJunkToCustomizedAddress -eq $true -and @($Policy.ReportJunkAddresses) -eq $Email -and @@ -69,6 +74,7 @@ function Get-CIPPBaselineUserSubmissionsState { $Current | Add-Member -NotePropertyName 'ruleExists' -NotePropertyValue ([bool]$Rule) $Current | Add-Member -NotePropertyName 'ruleEnabled' -NotePropertyValue ([bool]($Rule -and "$($Rule.State)" -eq 'Enabled')) $Current | Add-Member -NotePropertyName 'resolvedEmail' -NotePropertyValue $Email + $Current | Add-Member -NotePropertyName 'reportDestination' -NotePropertyValue $Destination @{ Expected = $Expected; Current = $Current } } diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineWorkItems.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineWorkItems.ps1 index 1dda1b5b15935..9d96137d4aec3 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineWorkItems.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineWorkItems.ps1 @@ -17,6 +17,14 @@ function Get-CIPPBaselineWorkItems { instance key, except for definitions declaring instanceIdentity (e.g. the CA template id): there the SELECTED TEMPLATE is the identity, so the same template applied twice at one level collides while different templates coexist. + - DIFFERENT standards writing the SAME tenant object (definition writeTarget) with + remediation on and opposing desired values are the same class of conflict, caught + per tenant after resolution: each definition's writeTargetProperties render to + its claims on the shared object, and overlapping claims with different values + mark every involved item Conflicted - proven live: the umbrella + AuthenticationMethods rewrote per-method states, and the OauthConsent trio are + mutually opposing consent policies. Compare-only items never conflict here - + detection reads don't fight. - Excluded tenants get nothing from that baseline. Each item carries the configured variable values, action posture, inheritance tiers for the UI, and the baseline's alert destinations. @@ -263,10 +271,13 @@ function Get-CIPPBaselineWorkItems { $Effective[$Key] = @{ Rank = 3; Candidates = $OverrideCandidates } } + # Collected instead of streamed: the write-target conflict pass below needs the whole + # tenant's resolved set in hand before anything is emitted. + $ResolvedItems = [System.Collections.Generic.List[object]]::new() foreach ($Entry in $Effective.Values) { $Candidates = @($Entry.Candidates | Sort-Object -Property UpdatedAt -Descending) if ($Candidates.Count -le 1) { - $Candidates[0].Item + $ResolvedItems.Add($Candidates[0].Item) continue } # Same rank, same identity, different settings: even the expected value is @@ -295,9 +306,123 @@ function Get-CIPPBaselineWorkItems { $ConflictItem.Tiers = @($ConflictTiers) # Attribute the row to every colliding baseline, not just its own source. $ConflictItem.SourceTemplate = ($ConflictNames -join ', ') - $ConflictItem | Add-Member -NotePropertyName Conflicted -NotePropertyValue $true -Force - $ConflictItem | Add-Member -NotePropertyName ConflictWith -NotePropertyValue $ConflictNames -Force - $ConflictItem + $ConflictItem | Add-Member -NotePropertyMembers ([ordered]@{ + Conflicted = $true + ConflictWith = $ConflictNames + }) -Force + $ResolvedItems.Add($ConflictItem) } } + + # ---- write-target coordination ----------------------------------------------------- + # Definitions naming a shared tenant object (writeTarget) stamp it onto their items so + # the orchestrator can serialize same-object writes; parallel activities racing one + # object were last-writer-wins on live tenants (a Graph 409 in the worst case). + foreach ($ResolvedItem in $ResolvedItems) { + $ResolvedItem | Add-Member -NotePropertyName WriteTarget -NotePropertyValue "$($DefinitionsByName[$ResolvedItem.BaseName].writeTarget)" -Force + } + + # Claim values are canonicalized before compare because the families mix vocabularies + # for the same write: the umbrella stores a method's desired state as $true/$false + # where the per-method standards store 'enabled'/'disabled' - both mean the same PATCH. + # Blank, 'notConfigured' and unresolved %tokens% are 'no opinion' and never conflict. + $CanonicalClaimValue = { + param($Value) + if ($null -eq $Value) { return $null } + $Value = $Value.value ?? $Value + if ($Value -is [array]) { + $Parts = @($Value | ForEach-Object { & $CanonicalClaimValue $_ } | Where-Object { $null -ne $_ } | Sort-Object) + if ($Parts.Count -eq 0) { return $null } + return ('[{0}]' -f ($Parts -join ',')) + } + if ($Value -is [bool]) { return $(if ($Value) { 'enabled' } else { 'disabled' }) } + $Text = "$Value".Trim() + if ($Text -eq '' -or $Text -eq 'notConfigured' -or $Text -match '^%[A-Za-z0-9_]+%$') { return $null } + if ($Text -match '^(?i)true$') { return 'enabled' } + if ($Text -match '^(?i)false$') { return 'disabled' } + if ($Text -match '^-?\d+(\.\d+)?$') { return "$([double]$Text)" } + $Text.ToLowerInvariant() + } + + # Renders a definition's writeTargetProperties with the item's variables into + # path -> canonical value. Defaults apply exactly as the engine applies them at run + # time (locked always, blank takes default/recommended) - without this a blank + # DisableSMS state would claim nothing while the run enforces 'disabled'. + $RenderWriteClaims = { + param($Definition, $Variables) + if ($null -eq $Definition.writeTargetProperties) { return $null } + $Values = @{} + foreach ($ConfiguredVariable in (($Variables ?? [PSCustomObject]@{}).PSObject.Properties)) { + # The UI's pickers save option WRAPPERS ({label, value}); claims need the value. + $Values[$ConfiguredVariable.Name] = if ($ConfiguredVariable.Value -is [array]) { + @($ConfiguredVariable.Value | ForEach-Object { $_.value ?? $_ }) + } else { + $ConfiguredVariable.Value.value ?? $ConfiguredVariable.Value + } + } + foreach ($Declared in (($Definition.variables ?? [PSCustomObject]@{}).PSObject.Properties)) { + $Fallback = $Declared.Value.default ?? $Declared.Value.recommended + if ($null -eq $Fallback) { continue } + $IsBlank = [string]::IsNullOrEmpty("$($Values[$Declared.Name])") + if ($Declared.Value.locked -eq $true -or ($IsBlank -and $Declared.Value.omitWhenBlank -ne $true)) { + $Values[$Declared.Name] = $Fallback + } + } + $Claims = @{} + foreach ($ClaimProperty in $Definition.writeTargetProperties.PSObject.Properties) { + $ClaimValue = $ClaimProperty.Value + if ($ClaimValue -is [string] -and $ClaimValue -match '^%([A-Za-z0-9_]+)%$') { + $ClaimValue = $Values[$Matches[1]] + } + $Canonical = & $CanonicalClaimValue $ClaimValue + # Hashtable keys compare case-insensitively, which absorbs the id-casing drift + # between definitions ('SoftwareOath' filter vs 'softwareOath' Graph id). + if ($null -ne $Canonical) { $Claims[$ClaimProperty.Name] = $Canonical } + } + $Claims + } + + # Two REMEDIATING standards claiming the same property of one shared object with + # different values can only scramble the tenant (each write undoes the other), so the + # whole set parks at Conflict through the same Conflicted plumbing as the + # same-standard collision above. Items already Conflicted never write and are skipped. + foreach ($TargetGroup in ($ResolvedItems | Where-Object { $_.WriteTarget } | Group-Object -Property { '{0}|{1}' -f $_.TenantFilter, $_.WriteTarget })) { + $Claimants = @($TargetGroup.Group | Where-Object { $_.RemediateEnabled -and $_.Conflicted -ne $true }) + if ($Claimants.Count -lt 2) { continue } + # Index-aligned with $Claimants; a List keeps $null entries (definition without + # writeTargetProperties) in place where a pipeline would drop them. + $ClaimMaps = [System.Collections.Generic.List[object]]::new() + foreach ($Claimant in $Claimants) { + $ClaimMaps.Add((& $RenderWriteClaims $DefinitionsByName[$Claimant.BaseName] $Claimant.Variables)) + } + # claimant index -> its opponents; every pairwise opposition marks BOTH sides. + $Opponents = @{} + for ($First = 0; $First -lt $Claimants.Count - 1; $First++) { + for ($Second = $First + 1; $Second -lt $Claimants.Count; $Second++) { + $MapA = $ClaimMaps[$First] + $MapB = $ClaimMaps[$Second] + if (-not $MapA -or -not $MapB) { continue } + $Opposed = @($MapA.Keys | Where-Object { $MapB.ContainsKey($_) -and $MapA[$_] -ne $MapB[$_] }) + if ($Opposed.Count -eq 0) { continue } + foreach ($Pair in @(@($First, $Second), @($Second, $First))) { + $Theirs = $Claimants[$Pair[1]] + if (-not $Opponents.ContainsKey($Pair[0])) { $Opponents[$Pair[0]] = [System.Collections.Generic.List[string]]::new() } + $Opponents[$Pair[0]].Add(('{0} ({1})' -f $Theirs.Standard, $Theirs.TemplateName)) + } + } + } + if ($Opponents.Count -eq 0) { continue } + $GroupAlert = @($Opponents.Keys | Where-Object { $Claimants[$_].AlertEnabled }).Count -gt 0 + foreach ($Index in $Opponents.Keys) { + $Member = $Claimants[$Index] + $Member.RemediateEnabled = $false + $Member.AlertEnabled = $GroupAlert + $Member | Add-Member -NotePropertyMembers ([ordered]@{ + Conflicted = $true + ConflictWith = @($Opponents[$Index] | Select-Object -Unique) + }) -Force + } + } + + foreach ($ResolvedItem in $ResolvedItems) { $ResolvedItem } } diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselinecalDefaultState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselinecalDefaultState.ps1 index 59a2456e6d8b3..eeac363d8bd1d 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselinecalDefaultState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselinecalDefaultState.ps1 @@ -13,6 +13,11 @@ function Get-CIPPBaselinecalDefaultState { Only the 'Default' principal is graded; named delegates are somebody's deliberate grant and are none of this standard's business. AccessRights arrives as an array on some rows and a string on others, so it is joined before comparing. + + Coverage is deliberately NOT graded here. 'offenders' is the only channel the compare + keeps, and an entry there leaves 'targets' empty - ExoBulkSweep then returns at its + `if ($Attempted -eq 0)` guard, before refreshCache, while the engine records Remediated. + Invoke-CIPPStandardcalDefault carries the coverage check instead. .FUNCTIONALITY Internal #> diff --git a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineAppDeploy.ps1 b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineAppDeploy.ps1 index 58a1d2ab441b7..b3b3f80b24df0 100644 --- a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineAppDeploy.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineAppDeploy.ps1 @@ -19,21 +19,37 @@ function Invoke-CIPPBaselineAppDeploy { $Current ) - $ServicePrincipals = @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'ServicePrincipals') + try { + $ServicePrincipals = @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'ServicePrincipals') + } catch { + # Without this, a storage hiccup here surfaces as a bare transport error with no hint + # of what AppDeploy was doing. + throw "AppDeploy: reading the ServicePrincipals cache for $TenantFilter failed: $($_.Exception.Message)" + } $Mode = [string]($Remediate.mode.value ?? $Remediate.mode ?? 'copy') if ($Mode -eq 'copy') { - foreach ($App in @("$($Remediate.appids)" -split ',')) { - $App = $App.Trim() - if (-not $App) { continue } + $AppIds = @("$($Remediate.appids)" -split ',' | ForEach-Object { "$_".Trim() } | Where-Object { $_ }) + $FailedApps = [System.Collections.Generic.List[string]]::new() + $LastError = $null + foreach ($App in $AppIds) { $Application = $ServicePrincipals | Where-Object -Property appId -EQ $App try { New-CIPPApplicationCopy -App $App -Tenant $TenantFilter Write-LogMessage -API 'Baselines' -tenant $TenantFilter -message "Added application $($Application.displayName) ($App) and updated its permissions." -Sev 'Info' } catch { - Write-LogMessage -API 'Baselines' -tenant $TenantFilter -message "Failed to add app $($Application.displayName) ($App): $($_.Exception.Message)" -Sev 'Error' + $FailedApps.Add($App) + $LastError = "$($_.Exception.Message)" + # The log write itself can fail on the same storage hiccup that broke the + # deploy; the end-of-loop throw still names the app either way. + try { Write-LogMessage -API 'Baselines' -tenant $TenantFilter -message "Failed to add app $($Application.displayName) ($App): $($_.Exception.Message)" -Sev 'Error' } catch { $null = $_ } } } + # Partial failure keeps the classic's log-and-continue; when nothing deployed at all, + # surface WHICH app id(s) failed instead of grading the run remediated. + if ($AppIds.Count -gt 0 -and $FailedApps.Count -eq $AppIds.Count) { + throw "AppDeploy: deploying application id(s) $($FailedApps -join ', ') failed. Last error: $LastError" + } return } diff --git a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineExternalComplianceTrusted.ps1 b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineExternalComplianceTrusted.ps1 new file mode 100644 index 0000000000000..905acb3dedbf9 --- /dev/null +++ b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineExternalComplianceTrusted.ps1 @@ -0,0 +1,27 @@ +function Invoke-CIPPBaselineExternalComplianceTrusted { + <# + .SYNOPSIS + ExternalComplianceTrusted executor: sets inbound device compliance trust on the default + cross-tenant access policy. + .DESCRIPTION + Reads the policy LIVE and patches the merged inboundTrust object, never the single + flag: Graph replaces the whole complex value on PATCH, so a bare + isCompliantDeviceAccepted body would silently reset the MFA and hybrid-join trust flags. + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + $Remediate, + $TenantFilter, + $Current + ) + + $Policy = New-GraphGetRequest -uri 'https://graph.microsoft.com/v1.0/policies/crossTenantAccessPolicy/default?$select=inboundTrust' -tenantid $TenantFilter + if (-not $Policy.inboundTrust) { throw 'Could not read the default cross-tenant access policy - refusing a blind write.' } + + $Policy.inboundTrust.isCompliantDeviceAccepted = [bool]($Remediate.trusted -eq $true -or "$($Remediate.trusted)" -eq 'True') + $Body = ConvertTo-Json -Compress -Depth 10 -InputObject ([PSCustomObject]@{ inboundTrust = $Policy.inboundTrust }) + $null = New-GraphPostRequest -tenantid $TenantFilter -uri 'https://graph.microsoft.com/v1.0/policies/crossTenantAccessPolicy/default' -type PATCH -body $Body + Write-LogMessage -API 'Baselines' -tenant $TenantFilter -message "Set external device compliance trust to $($Policy.inboundTrust.isCompliantDeviceAccepted)." -Sev 'Info' +} diff --git a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineFIDO2PasskeyProfiles.ps1 b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineFIDO2PasskeyProfiles.ps1 index 5cc412d74194c..d2c563000832b 100644 --- a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineFIDO2PasskeyProfiles.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineFIDO2PasskeyProfiles.ps1 @@ -26,6 +26,9 @@ function Invoke-CIPPBaselineFIDO2PasskeyProfiles { $EnforcementType = "$($Remediate.enforcementType)" if ([string]::IsNullOrWhiteSpace($EnforcementType)) { $EnforcementType = 'allow' } $AAGUIDs = @("$($Remediate.aaGuids)" -split ',' | ForEach-Object { $_.Trim() } | Where-Object { $_ }) + # A profile's AAGUID list only takes effect while key restrictions are enforced; sent with + # isEnforced = $false the list is stored but never applied. Supplying AAGUIDs implies enforcement. + if ($AAGUIDs.Count -gt 0) { $Enforce = $true } $UpdatedProfiles = @(@($Current.allProfiles) | ForEach-Object { if ("$($_.id)" -eq $DefaultId) { diff --git a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineIntuneAppTemplateDeploy.ps1 b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineIntuneAppTemplateDeploy.ps1 index d9010d1dfc136..edb9593ac058c 100644 --- a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineIntuneAppTemplateDeploy.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineIntuneAppTemplateDeploy.ps1 @@ -33,10 +33,12 @@ function Invoke-CIPPBaselineIntuneAppTemplateDeploy { default { "$($App.AppType)" } } $DeployConfig = $App.Config | ConvertTo-Json -Depth 100 | ConvertFrom-Json -Depth 100 - $DeployConfig | Add-Member -NotePropertyName 'type' -NotePropertyValue $QueueType -Force - $DeployConfig | Add-Member -NotePropertyName 'Applicationname' -NotePropertyValue "$($App.AppName)" -Force $AppAssignTo = if ("$($DeployConfig.AssignTo)" -eq 'customGroup') { $DeployConfig.CustomGroup } else { $DeployConfig.AssignTo } - $DeployConfig | Add-Member -NotePropertyName 'assignTo' -NotePropertyValue $AppAssignTo -Force + $DeployConfig | Add-Member -NotePropertyMembers ([ordered]@{ + type = $QueueType + Applicationname = "$($App.AppName)" + assignTo = $AppAssignTo + }) -Force $null = New-CIPPIntuneAppDeployment -AppConfig $DeployConfig -TenantFilter $TenantFilter -APIName 'Baselines' Write-LogMessage -API 'Baselines' -tenant $TenantFilter -message "Queued the Intune app '$($App.AppName)' ($($App.AppType)) from template '$($App.TemplateName)'." -Sev 'Info' diff --git a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineSPGuestPeoplePicker.ps1 b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineSPGuestPeoplePicker.ps1 new file mode 100644 index 0000000000000..83b7ce806223b --- /dev/null +++ b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineSPGuestPeoplePicker.ps1 @@ -0,0 +1,95 @@ +function Invoke-CIPPBaselineSPGuestPeoplePicker { + <# + .SYNOPSIS + SPGuestPeoplePicker executor: applies People Picker guest visibility to the tenant default + and each offending site collection, once per 24h per tenant. + .DESCRIPTION + Each target from the prepare hook carries a Scope ('tenant' or 'site') and the value in + 'Wanted'. Tenant targets write through Set-CIPPSPOTenant, site targets through the concurrent + Set-CIPPSPOSiteBulk fan-out. It does NOT re-read after writing: the eventually-consistent site + enumeration lags a just-applied write, and the baseline engine already verifies optimistically + on the next daily cache read. + + A 24h rerun guard (Test-CIPPRerun, shared with the classic standard via the 'SPGuestPeoplePicker' + key) gates the write sweep: the prepare's offender set is derived from the SPOSites cache, which + only refreshes daily, so without the guard a sub-daily baseline schedule would re-issue the same + writes against a stale picture and throttle SharePoint. Detection and drift reporting are not + gated - only the sweep. + + Partial failure does NOT throw - sites that wrote stay written, failures are logged, and once + the cache reflects the successes the next run's prepare re-derives only the still-drifted set. + A run where every write failed throws (a permission/endpoint problem, not drift). + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + $Remediate, + $TenantFilter, + $Current + ) + + $Targets = @($Current.targets | Where-Object { $_ }) + if ($Targets.Count -eq 0) { return } + + # Once-per-24h per tenant. Test-CIPPRerun records the run as it allows it, and the classic standard + # shares this key, so whichever system sweeps first blocks the other until the next daily cache run + # reflects the change. Only reached when there is drift to write (the engine calls the executor only + # for a non-compliant, remediate-enabled item), so detection/alerting are never gated by it. + if (Test-CIPPRerun -Tenant $TenantFilter -API 'SPGuestPeoplePicker' -Interval 86400) { + Write-LogMessage -API 'Baselines' -tenant $TenantFilter -message 'SPGuestPeoplePicker: write sweep already ran within the last 24h - skipping it until the next daily cache run re-evaluates the result.' -Sev 'Info' + return + } + + $AuthSplat = @{} + if ($Remediate.useCertificate) { $AuthSplat['UseCertificate'] = $true } + $Property = 'ShowPeoplePickerSuggestionsForGuestUsers' + + $Attempted = 0 + $Failed = 0 + $FailureDetail = [System.Collections.Generic.List[string]]::new() + + # Tenant default (at most one target): a fresh Get-CIPPSPOTenant supplies the write handle, then + # one Set-CIPPSPOTenant. No re-read - the next daily cache run confirms it. + foreach ($Target in @($Targets | Where-Object { $_.Scope -eq 'tenant' })) { + $Attempted++ + try { + $SPOTenant = Get-CIPPSPOTenant -TenantFilter $TenantFilter @AuthSplat | Select-Object -First 1 + if (-not $SPOTenant) { throw "Could not resolve the SharePoint tenant object for $TenantFilter." } + $null = $SPOTenant | Set-CIPPSPOTenant -Properties @{ $Property = [bool]$Target.Wanted } @AuthSplat + } catch { + $Failed++ + $FailureDetail.Add("Tenant default -> $($_.Exception.Message)") + } + } + + # Existing sites: one concurrent bulk write. Per-site success/failure comes straight from the bulk + # result (CSOM reports per-site errors in the response body); no separate verification read. + $SiteTargets = @($Targets | Where-Object { $_.Scope -eq 'site' -and $_.SiteUrl }) + if ($SiteTargets.Count -gt 0) { + $BulkSites = @($SiteTargets | ForEach-Object { @{ SiteUrl = $_.SiteUrl; Properties = @{ $Property = [bool]$_.Wanted } } }) + try { + $Results = @(Set-CIPPSPOSiteBulk -TenantFilter $TenantFilter -Sites $BulkSites @AuthSplat) + $ResultByUrl = @{} + foreach ($Result in $Results) { $ResultByUrl["$($Result.SiteUrl)"] = $Result } + foreach ($SiteTarget in $SiteTargets) { + $Attempted++ + $Result = $ResultByUrl["$($SiteTarget.SiteUrl)"] + if (-not $Result -or -not $Result.Success) { + $Failed++ + $FailureDetail.Add("$($SiteTarget.SiteUrl) -> $(if ($Result.Error) { $Result.Error } else { 'no result returned' })") + } + } + } catch { + foreach ($SiteTarget in $SiteTargets) { $Attempted++; $Failed++ } + $FailureDetail.Add("Site batch -> $($_.Exception.Message)") + } + } + + if ($FailureDetail.Count -gt 0) { + Write-LogMessage -API 'Baselines' -tenant $TenantFilter -message "Guest People Picker: $Failed of $Attempted writes failed. $($FailureDetail -join ' | ')" -Sev 'Warning' + } + if ($Attempted -gt 0 -and $Failed -eq $Attempted) { + throw "SPGuestPeoplePicker: all $Attempted writes failed. $($FailureDetail | Select-Object -First 1)" + } +} diff --git a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineSPOVersionControl.ps1 b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineSPOVersionControl.ps1 index ebdc7dbd658c2..c4af3384b22ad 100644 --- a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineSPOVersionControl.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineSPOVersionControl.ps1 @@ -24,7 +24,8 @@ function Invoke-CIPPBaselineSPOVersionControl { $ExpireDays = [int]"$($Remediate.expireVersionsAfterDays ?? 0)" if (-not $AutoTrim -and $ExpireDays -ne 0 -and ($ExpireDays -lt 30 -or $ExpireDays -gt 36500)) { return } - $State = Get-CIPPSPOTenant -TenantFilter $TenantFilter | Select-Object -Property _ObjectIdentity_, TenantFilter + # SharePoint app-only requires the SAM certificate; delegated is not available on every tenant. + $State = Get-CIPPSPOTenant -TenantFilter $TenantFilter -UseCertificate | Select-Object -Property _ObjectIdentity_, TenantFilter if (-not $State) { throw 'Could not read the SPO tenant configuration - refusing a blind write.' } $MethodParams = if ($AutoTrim) { @@ -32,7 +33,7 @@ function Invoke-CIPPBaselineSPOVersionControl { } else { @(@{ Type = 'Boolean'; Value = $false }, @{ Type = 'Int32'; Value = $MajorLimit }, @{ Type = 'Int32'; Value = $ExpireDays }) } - $State | Set-CIPPSPOTenant -MethodName 'SetFileVersionPolicy' -MethodParameters $MethodParams + $State | Set-CIPPSPOTenant -MethodName 'SetFileVersionPolicy' -MethodParameters $MethodParams -UseCertificate Write-LogMessage -API 'Baselines' -tenant $TenantFilter -message "Set the file version policy (autoTrim=$AutoTrim$(if (-not $AutoTrim) { ", limit=$MajorLimit, expire=${ExpireDays}d" }))." -Sev 'Info' if ($Remediate.applyToExistingSites -eq $true -or "$($Remediate.applyToExistingSites)" -eq 'True') { @@ -47,15 +48,13 @@ function Invoke-CIPPBaselineSPOVersionControl { $SiteProperties.MajorVersionLimit = $MajorLimit $SiteProperties.ExpireVersionsAfterDays = $ExpireDays } - $Failures = 0 - foreach ($Site in $Sites) { - try { - Set-CIPPSPOSite -TenantFilter $TenantFilter -SiteUrl $Site.webUrl -Properties $SiteProperties - } catch { - $Failures++ - Write-Information "Baselines: version policy on $($Site.webUrl) continued past: $($_.Exception.Message)" - } + # One concurrent batch (Set-CIPPSPOSiteBulk fans out in .NET) instead of ~2s per site. + $BulkSites = @($Sites | ForEach-Object { @{ SiteUrl = $_.webUrl; Properties = $SiteProperties } }) + $BulkResults = @(Set-CIPPSPOSiteBulk -TenantFilter $TenantFilter -Sites $BulkSites -UseCertificate) + $Failures = @($BulkResults | Where-Object { -not $_.Success }) + foreach ($FailedSite in $Failures) { + Write-Information "Baselines: version policy on $($FailedSite.SiteUrl) continued past: $($FailedSite.Error)" } - Write-LogMessage -API 'Baselines' -tenant $TenantFilter -message "Applied the version policy to $(@($Sites).Count - $Failures) of $(@($Sites).Count) existing site(s)." -Sev 'Info' + Write-LogMessage -API 'Baselines' -tenant $TenantFilter -message "Applied the version policy to $(@($Sites).Count - $Failures.Count) of $(@($Sites).Count) existing site(s)." -Sev 'Info' } } diff --git a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineStandard.ps1 b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineStandard.ps1 index 1b6123c0a2b93..800f3419e9214 100644 --- a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineStandard.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineStandard.ps1 @@ -108,6 +108,24 @@ function Invoke-CIPPBaselineStandard { if ($Definition.package) { throw "Package standard $($Item.BaseName) must be expanded by the resolver and never executes directly." } $Label = $Definition.label ?? $Item.Standard + # A disabled definition is not ready for use: the catalog hides it, and anything + # still configured from before skips here - never compared, never written - with + # the reason visible instead of a silent absence. + if ($Definition.disabled -eq $true) { + if ($GradeOnly) { return $null } + Write-LogMessage -API 'Baselines' -tenant $TenantFilter -message "`"$Label`" is disabled (not ready for use) - skipped without comparing or changing anything. - Run $RunId" -Sev 'Info' + $Disabled = [PSCustomObject]@{ + Item = $Item; Mode = $Mode; TriggeredBy = $TriggeredBy + ExpectedValue = $null; CurrentValue = $null; Compliant = $false + PendingVerification = $false; LicenseAvailable = $true + Status = 'No Data'; Remediated = $false; Outcome = 'Skipped-Disabled' + Diff = $null; RowDiff = @(); Manual = $null; Inheritance = @($Item.Tiers) + AlertEvent = $null; CacheType = $null + } + Set-CIPPBaselineResult -Result $Disabled -Prior $null -RunId $RunId -Detail 'This standard is disabled - it is not ready for use and was skipped.' + return $Disabled + } + # Definition-aware variable pass: declared defaults apply at RUN time, not just as # editor seeds. A blank variable would otherwise splice its raw '%token%' into the # expected value and grade as permanent fake drift ('%enabled%' vs true). Rules: diff --git a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineUserSubmissions.ps1 b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineUserSubmissions.ps1 index f4eeb03e810bb..6ac12bd73e678 100644 --- a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineUserSubmissions.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineUserSubmissions.ps1 @@ -23,8 +23,10 @@ function Invoke-CIPPBaselineUserSubmissions { $Email = "$($Current.resolvedEmail)" if ($State -eq 'enable' -and -not [string]::IsNullOrWhiteSpace($Email)) { + # 'Mailbox' routes reports to the reporting mailbox only (third-party phishing + # services); anything else keeps the original Microsoft-as-well posture. $PolicyParams = @{ - EnableReportToMicrosoft = $true + EnableReportToMicrosoft = "$($Current.reportDestination)" -ne 'Mailbox' ReportJunkToCustomizedAddress = $true; ReportJunkAddresses = $Email ReportNotJunkToCustomizedAddress = $true; ReportNotJunkAddresses = $Email ReportPhishToCustomizedAddress = $true; ReportPhishAddresses = $Email diff --git a/Modules/CIPPCore/Public/Clear-CIPPDbCache.ps1 b/Modules/CIPPCore/Public/Clear-CIPPDbCache.ps1 new file mode 100644 index 0000000000000..3071bf503c023 --- /dev/null +++ b/Modules/CIPPCore/Public/Clear-CIPPDbCache.ps1 @@ -0,0 +1,107 @@ +function Clear-CIPPDbCache { + <# + .SYNOPSIS + Remove every CippReportingDB row for a cache type and reset the Count row to 0. + + .DESCRIPTION + SuperAdmin empty path. + + Rows are read and deleted physically rather than as reassembled large entities, so any + part rows a split entity left behind go with it. + + The delete is re-read afterwards and a row that survived is an error. Table deletes + report success for a row the service says does not exist - the SDK returns 404 as a + response rather than throwing, and AzBobbyTables' large-entity remove swallows it in + its per-row fallback - so an empty that only trusted the delete call could report + clearing rows it never touched. + + .PARAMETER TenantFilter + Tenant domain, GUID, or AllTenants. + + .PARAMETER Type + Cache collection name (e.g. Users, Groups, Mailboxes). + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [Parameter(Mandatory = $true)] + [string]$Type + ) + + try { + $Table = Get-CippTable -tablename 'CippReportingDB' + $IsAllTenants = $TenantFilter -eq 'AllTenants' -or $TenantFilter -eq 'allTenants' + $TypeName = [string]$Type + $CountRowKey = "$TypeName-Count" + + if ($IsAllTenants) { + $Filter = "RowKey ge '$TypeName-' and RowKey lt '${TypeName}0'" + $ResultTenant = 'AllTenants' + $DbTenant = $null + } else { + $Tenant = Get-Tenants -TenantFilter $TenantFilter + if (-not $Tenant) { + throw "Tenant '$TenantFilter' not found" + } + $DbTenant = [string]$Tenant.defaultDomainName + if ([string]::IsNullOrWhiteSpace($DbTenant)) { + throw "Tenant '$TenantFilter' has no defaultDomainName" + } + $ResultTenant = $DbTenant + $Filter = "PartitionKey eq '$DbTenant' and RowKey ge '$TypeName-' and RowKey lt '${TypeName}0'" + } + + $Rows = @(Get-AzDataTableEntity @Table -Filter $Filter -Property PartitionKey, RowKey -ErrorAction Stop) + + $TouchedPartitions = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + $Entities = [System.Collections.Generic.List[object]]::new() + foreach ($Row in $Rows) { + $Pk = [string]$Row.PartitionKey + $Rk = [string]$Row.RowKey + if ([string]::IsNullOrWhiteSpace($Pk) -or [string]::IsNullOrWhiteSpace($Rk)) { continue } + [void]$TouchedPartitions.Add($Pk) + if ($Rk -eq $CountRowKey) { continue } + $Entities.Add([pscustomobject]@{ PartitionKey = $Pk; RowKey = $Rk }) + } + + $RemovedCount = 0 + if ($Entities.Count -gt 0) { + # One call: the module splits the entities into transactions per partition key and + # per the service's 100-operation limit, so an AllTenants clear needs no grouping here. + Remove-AzDataTableEntity @Table -Entity $Entities.ToArray() -Force -ErrorAction Stop + $RemovedCount = $Entities.Count + } + + if (-not $IsAllTenants) { + [void]$TouchedPartitions.Add($DbTenant) + } + + foreach ($Partition in $TouchedPartitions) { + $null = Add-CIPPAzDataTableEntity @Table -Entity @{ + PartitionKey = $Partition + RowKey = $CountRowKey + DataCount = 0 + Type = $TypeName + } -Force + } + + $StillThere = @(Get-AzDataTableEntity @Table -Filter $Filter -Property PartitionKey, RowKey -ErrorAction Stop | + Where-Object { [string]$_.RowKey -ne $CountRowKey }) + if ($StillThere.Count -gt 0) { + $Sample = ($StillThere | Select-Object -First 3 | ForEach-Object { "$($_.PartitionKey)/$($_.RowKey)" }) -join ', ' + throw "Deleted $RemovedCount $TypeName row(s) for $TenantFilter but $($StillThere.Count) still exist (e.g. $Sample)" + } + + Write-LogMessage -API 'CIPPDbItem' -tenant $TenantFilter -message "Cleared $RemovedCount $TypeName cache row(s) for $TenantFilter" -sev Warning + return [PSCustomObject]@{ + RemovedCount = $RemovedCount + Tenant = $ResultTenant + Type = $TypeName + } + } catch { + Write-LogMessage -API 'CIPPDbItem' -tenant $TenantFilter -message "Failed to clear $Type cache: $($_.Exception.Message)" -sev Error -LogData (Get-CippException -Exception $_) + throw + } +} diff --git a/Modules/CIPPCore/Public/Clear-CIPPMobileDevice.ps1 b/Modules/CIPPCore/Public/Clear-CIPPMobileDevice.ps1 new file mode 100644 index 0000000000000..9e9da733c2d4d --- /dev/null +++ b/Modules/CIPPCore/Public/Clear-CIPPMobileDevice.ps1 @@ -0,0 +1,42 @@ +function Clear-CIPPMobileDevice { + [CmdletBinding()] + param( + $UserId, + $TenantFilter, + $Username, + $APIName = 'Wipe Mobile', + $Headers + ) + + try { + $WipedDevices = [System.Collections.Generic.List[string]]::new() + $ErrorDevices = [System.Collections.Generic.List[string]]::new() + # AccountOnly wipes the Exchange account data from the device, never the full device. + # Requires EAS v16.1+; older clients fail the call rather than falling back to a device wipe. + $null = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-MobileDevice' -Anchor $Username -cmdParams @{mailbox = $Username } | ForEach-Object { + try { + $MobileDevice = $_ + # FriendlyName is usually empty; fall back like the ActiveSync device list. + $DeviceName = @($MobileDevice.FriendlyName, $MobileDevice.DeviceModel, $MobileDevice.DeviceOS, $MobileDevice.DeviceId) | + Where-Object { -not [string]::IsNullOrWhiteSpace($_) } | Select-Object -First 1 + if (-not $DeviceName) { $DeviceName = 'Unknown device' } + $null = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Clear-MobileDevice' -Anchor $Username -cmdParams @{Identity = $MobileDevice.Identity; AccountOnly = $true } + $WipedDevices.Add([string]$DeviceName) + } catch { + $ErrorDevices.Add([string]$DeviceName) + } + } + if ($ErrorDevices.Count -eq 0) { + $Message = "Successfully issued an account-only wipe for $($WipedDevices.Count) mobile devices for $($Username): $($WipedDevices -join '; '). The wipe is performed when the device next connects to Exchange." + } else { + $Message = "Failed to wipe all mobile devices for $($Username). Successfully issued an account-only wipe for $($WipedDevices.Count) mobile devices: $($WipedDevices -join '; '). Failed to wipe $($ErrorDevices.Count) mobile devices: $($ErrorDevices -join '; ')" + Write-LogMessage -headers $Headers -API $APIName -message $Message -Sev 'Error' -tenant $TenantFilter + } + return $Message + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Message = "Failed to wipe mobile devices for $($Username). Error: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -message $Message -Sev 'Error' -tenant $TenantFilter -LogData $ErrorMessage + throw $Message + } +} diff --git a/Modules/CIPPCore/Public/ConvertTo-CIPPCountryCode.ps1 b/Modules/CIPPCore/Public/ConvertTo-CIPPCountryCode.ps1 new file mode 100644 index 0000000000000..4f655459fa59b --- /dev/null +++ b/Modules/CIPPCore/Public/ConvertTo-CIPPCountryCode.ps1 @@ -0,0 +1,64 @@ +function ConvertTo-CIPPCountryCode { + <# + .SYNOPSIS + Normalises a country value (ISO 3166-1 alpha-2 code or country name) to its code. + + .DESCRIPTION + Contact templates store the country as a two-letter ISO code - the value field of the + frontend country picker - but Exchange's Get-Contact returns CountryOrRegion as the full + country name (e.g. 'United States'). Comparing the two directly always reports a + difference, so callers normalise both sides through this helper before comparing. + + Resolution is done against Config\CountryList.json - the same list the frontend picker is + built from (frontend\src\data\countryList.json) - so the code<->name mapping matches what + produced the stored value. Matching is case-insensitive and accepts either a code or a + name. Anything that cannot be resolved (unknown value, unreadable list) is returned + trimmed and upper-cased so a raw comparison still works and no country is silently + dropped; null/empty input returns $null. + + Keep Config\CountryList.json in sync with frontend\src\data\countryList.json. + + .PARAMETER Country + A country code ('US') or name ('United States'). Accepts pipeline input. + + .EXAMPLE + ConvertTo-CIPPCountryCode 'US' # US + + .EXAMPLE + ConvertTo-CIPPCountryCode 'United States' # US + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + [OutputType([string])] + param( + [Parameter(Position = 0, ValueFromPipeline = $true)] + [AllowNull()] + [AllowEmptyString()] + $Country + ) + + process { + $Value = "$Country".Trim() + if ([string]::IsNullOrWhiteSpace($Value)) { return $null } + + if (-not $script:CIPPCountryList) { + try { + $ListPath = Join-Path $env:CIPPRootPath 'Config\CountryList.json' + $script:CIPPCountryList = [System.IO.File]::ReadAllText($ListPath) | ConvertFrom-Json + } catch { + Write-Warning "[CountryCode] Could not load CountryList.json: $($_.Exception.Message)" + return $Value.ToUpperInvariant() + } + } + + # -eq on strings is case-insensitive, so 'us'/'US' and 'united states'/'United States' both hit. + $Match = $script:CIPPCountryList | Where-Object { + $_.Code -eq $Value -or $_.Name -eq $Value + } | Select-Object -First 1 + + if ($Match) { return [string]$Match.Code } + return $Value.ToUpperInvariant() + } +} diff --git a/Modules/CIPPCore/Public/ConvertTo-CIPPIntunePolicyListItem.ps1 b/Modules/CIPPCore/Public/ConvertTo-CIPPIntunePolicyListItem.ps1 index b11330739f093..f20b43481a7c0 100644 --- a/Modules/CIPPCore/Public/ConvertTo-CIPPIntunePolicyListItem.ps1 +++ b/Modules/CIPPCore/Public/ConvertTo-CIPPIntunePolicyListItem.ps1 @@ -42,6 +42,8 @@ function ConvertTo-CIPPIntunePolicyListItem { '*windowsUpdateForBusinessConfiguration*' { 'Update Configuration' } '*windowsHealthMonitoringConfiguration*' { 'Health Monitoring' } '*microsoft.graph.macOSGeneralDeviceConfiguration*' { 'MacOS Configuration' } + '*microsoft.graph.macOSSoftwareUpdateConfiguration*' { 'macOS Update Configuration' } + '*microsoft.graph.windows10GeneralConfiguration*' { 'Windows Configuration' } '*microsoft.graph.macOSEndpointProtectionConfiguration*' { 'MacOS Endpoint Protection' } '*microsoft.graph.androidWorkProfileGeneralDeviceConfiguration*' { 'Android Configuration' } '*windowsFeatureUpdateProfiles*' { 'Feature Update' } @@ -67,7 +69,14 @@ function ConvertTo-CIPPIntunePolicyListItem { } elseif (-not [string]::IsNullOrWhiteSpace($DefaultPolicyTypeName)) { $PolicyTypeName = $DefaultPolicyTypeName } else { - $PolicyTypeName = $AssignmentContext + # Unmapped family: name it from the @odata type in the assignment context so the + # column never surfaces a raw Graph URL. + $OdataType = [regex]::Match([string]$AssignmentContext, 'microsoft\.graph\.([A-Za-z0-9]+)').Groups[1].Value + if ($OdataType) { + $PolicyTypeName = (($OdataType -creplace '([a-z\d])([A-Z])', '$1 $2') -creplace '([A-Z]+)([A-Z][a-z])', '$1 $2') + } else { + $PolicyTypeName = $AssignmentContext + } } } diff --git a/Modules/CIPPCore/Public/ConvertTo-CIPPSharePointSiteUsagePayload.ps1 b/Modules/CIPPCore/Public/ConvertTo-CIPPSharePointSiteUsagePayload.ps1 new file mode 100644 index 0000000000000..e4dd75e2d73fc --- /dev/null +++ b/Modules/CIPPCore/Public/ConvertTo-CIPPSharePointSiteUsagePayload.ps1 @@ -0,0 +1,61 @@ +function ConvertTo-CIPPSharePointSiteUsagePayload { + <# + .SYNOPSIS + Maps a SharePoint site listing row and usage row to the Invoke-ListSites payload shape. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + $Site, + + $SiteUsage, + + [string]$Tenant, + + $CacheTimestamp + ) + + $StorageUsedInGigabytes = if ($SiteUsage -and $null -ne $SiteUsage.storageUsedInBytes) { + [math]::Round([double]$SiteUsage.storageUsedInBytes / 1GB, 2) + } else { $null } + + $StorageAllocatedInGigabytes = if ($SiteUsage -and $null -ne $SiteUsage.storageAllocatedInBytes) { + [math]::Round([double]$SiteUsage.storageAllocatedInBytes / 1GB, 2) + } else { $null } + + $ArchiveGb = if ($null -ne $Site.archivedFileDiskUsedBytes) { + [math]::Round([double]$Site.archivedFileDiskUsedBytes / 1GB, 2) + } else { $null } + + $ReportItem = [PSCustomObject]@{ + siteId = $Site.sharepointIds.siteId + webId = $Site.sharepointIds.webId + createdDateTime = $Site.createdDateTime + displayName = $Site.displayName + webUrl = $Site.webUrl + ownerDisplayName = if ($SiteUsage) { $SiteUsage.ownerDisplayName } else { $null } + ownerPrincipalName = if ($SiteUsage) { $SiteUsage.ownerPrincipalName } else { $null } + lastActivityDate = if ($SiteUsage) { $SiteUsage.lastActivityDate } else { $null } + fileCount = if ($SiteUsage) { $SiteUsage.fileCount } else { $null } + storageUsedInGigabytes = $StorageUsedInGigabytes + storageAllocatedInGigabytes = $StorageAllocatedInGigabytes + storageUsedInBytes = if ($SiteUsage) { $SiteUsage.storageUsedInBytes } else { $null } + storageAllocatedInBytes = if ($SiteUsage) { $SiteUsage.storageAllocatedInBytes } else { $null } + rootWebTemplate = if ($SiteUsage) { $SiteUsage.rootWebTemplate } else { $null } + reportRefreshDate = if ($SiteUsage) { $SiteUsage.reportRefreshDate } else { $null } + archivedFileDiskUsedBytes = $Site.archivedFileDiskUsedBytes + archivedFileDiskUsedGigabytes = $ArchiveGb + allowFileArchive = $Site.allowFileArchive + AutoMapUrl = $Site.AutoMapUrl + } + + if ($Tenant) { + $ReportItem | Add-Member -NotePropertyName 'Tenant' -NotePropertyValue $Tenant -Force + } + + if ($CacheTimestamp) { + $ReportItem | Add-Member -NotePropertyName 'CacheTimestamp' -NotePropertyValue $CacheTimestamp -Force + } + + return $ReportItem +} diff --git a/Modules/CIPPCore/Public/ConvertTo-SPOAdminListInt64.ps1 b/Modules/CIPPCore/Public/ConvertTo-SPOAdminListInt64.ps1 new file mode 100644 index 0000000000000..831f2cba81d49 --- /dev/null +++ b/Modules/CIPPCore/Public/ConvertTo-SPOAdminListInt64.ps1 @@ -0,0 +1,31 @@ +function ConvertTo-SPOAdminListInt64 { + <# + .SYNOPSIS + Parse RenderAdminListData numeric fields (comma-separated strings) to int64. + + .DESCRIPTION + SPO.Tenant/RenderAdminListData returns counts and byte sizes as strings like + "1,073,741,824". Returns $null for empty or unparseable values. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [AllowNull()] + $Raw + ) + + if ($null -eq $Raw -or $Raw -eq '') { return $null } + if ($Raw -is [int64]) { return $Raw } + if ($Raw -is [int] -or $Raw -is [long]) { return [int64]$Raw } + + $Clean = ([string]$Raw).Replace(',', '').Trim() + if ($Clean -eq '') { return $null } + + $Parsed = [int64]0 + if ([int64]::TryParse($Clean, [ref]$Parsed)) { + return $Parsed + } + return $null +} diff --git a/Modules/CIPPCore/Public/ConvertTo-SPOUsageRootWebTemplate.ps1 b/Modules/CIPPCore/Public/ConvertTo-SPOUsageRootWebTemplate.ps1 new file mode 100644 index 0000000000000..1cf81c1a9e0da --- /dev/null +++ b/Modules/CIPPCore/Public/ConvertTo-SPOUsageRootWebTemplate.ps1 @@ -0,0 +1,41 @@ +function ConvertTo-SPOUsageRootWebTemplate { + <# + .SYNOPSIS + Map SPO admin TemplateName to Graph getSharePointSiteUsageDetail rootWebTemplate values. + + .DESCRIPTION + RenderAdminListData returns template codes like GROUP#0 and STS#3. Cached SharePoint + usage consumers (sharing report, SharePoint Sites actions) expect the friendly values + from the Graph usage report, e.g. Group and Team Channel. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [AllowNull()] + [string]$TemplateName + ) + + if ([string]::IsNullOrWhiteSpace($TemplateName)) { return $null } + + $Trimmed = $TemplateName.Trim() + if ($Trimmed -notmatch '#') { return $Trimmed } + + $Base = ($Trimmed -split '#', 2)[0].Trim() + + switch -Regex ($Base) { + '^(?i)GROUP$' { return 'Group' } + '^(?i)TEAMCHANNEL$' { return 'Team Channel' } + '^(?i)STS$' { return 'STS' } + '^(?i)SITEPAGEPUBLISHING$' { return 'Site Page Publishing' } + '^(?i)APPCATALOG$' { return 'App Catalog Site' } + '^(?i)REDIRECTSITE$' { return 'Redirect Site' } + '^(?i)TENANTADMIN$' { return 'Tenant Admin Site' } + '^(?i)SPSMSITEHOST$' { return 'My Site Host' } + '^(?i)SRCHCEN$' { return 'Basic Search Center' } + '^(?i)EDISC$' { return 'Compliance Policy Center' } + '^(?i)POINTPUBLISHINGTOPIC$' { return 'SharePoint Online Tenant Fundamental Site' } + default { return $Base } + } +} diff --git a/Modules/CIPPCore/Public/DeltaQueries/Get-DeltaQueryUrl.ps1 b/Modules/CIPPCore/Public/DeltaQueries/Get-DeltaQueryUrl.ps1 index c2ad699215d15..87af12a39482b 100644 --- a/Modules/CIPPCore/Public/DeltaQueries/Get-DeltaQueryUrl.ps1 +++ b/Modules/CIPPCore/Public/DeltaQueries/Get-DeltaQueryUrl.ps1 @@ -22,21 +22,26 @@ function Get-DeltaQueryUrl { $Table = Get-CIPPTable -TableName 'DeltaQueries' $DeltaQueryEntity = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq '$PartitionKey' and RowKey eq '$TenantFilter'" - if ($DeltaQueryEntity) { + # A row whose DeltaUrl is blank is as unusable as a missing row: an earlier delta query that + # ended without a deltaLink persisted an empty value, and handing that to New-GraphDeltaQuery + # fails parameter binding ("Cannot bind argument to parameter 'DeltaUrl' because it is an + # empty string") on every scheduled evaluation until the row is rebuilt. + if ($DeltaQueryEntity -and -not [string]::IsNullOrWhiteSpace($DeltaQueryEntity.DeltaUrl)) { return $DeltaQueryEntity.DeltaUrl } + $MissingReason = if ($DeltaQueryEntity) { 'has no delta link' } else { 'is missing' } $TaskTable = Get-CIPPTable -TableName 'ScheduledTasks' $Task = Get-CIPPAzDataTableEntity @TaskTable -Filter "PartitionKey eq 'ScheduledTask' and RowKey eq '$PartitionKey'" if (!$Task.Trigger) { - throw "Delta Query not found for Tenant '$TenantFilter' and PartitionKey '$PartitionKey', and no scheduled task with a trigger exists to rebuild it from." + throw "Delta Query for Tenant '$TenantFilter' and PartitionKey '$PartitionKey' $MissingReason, and no scheduled task with a trigger exists to rebuild it from." } - Write-Warning "Delta Query missing for Tenant '$TenantFilter' and PartitionKey '$PartitionKey'. Rebuilding it from task '$($Task.Name)'." + Write-Warning "Delta Query for Tenant '$TenantFilter' and PartitionKey '$PartitionKey' $MissingReason. Rebuilding it from task '$($Task.Name)'." $Rebuilt = New-CIPPTaskDeltaQuery -Trigger $Task.Trigger -TenantFilter $TenantFilter -PartitionKey $PartitionKey $DeltaUrl = $Rebuilt.'@odata.deltaLink' if (!$DeltaUrl) { - throw "Delta Query not found for Tenant '$TenantFilter' and PartitionKey '$PartitionKey' and could not be rebuilt." + throw "Delta Query for Tenant '$TenantFilter' and PartitionKey '$PartitionKey' $MissingReason and could not be rebuilt." } Write-LogMessage -API 'Scheduler_UserTasks' -tenant $TenantFilter -message "Rebuilt the missing delta query for task '$($Task.Name)'. Changes from before the rebuild were not captured and will not trigger this task." -sev Warning diff --git a/Modules/CIPPCore/Public/DeltaQueries/New-GraphDeltaQuery.ps1 b/Modules/CIPPCore/Public/DeltaQueries/New-GraphDeltaQuery.ps1 index 22891bf8d6a75..586612d2985d1 100644 --- a/Modules/CIPPCore/Public/DeltaQueries/New-GraphDeltaQuery.ps1 +++ b/Modules/CIPPCore/Public/DeltaQueries/New-GraphDeltaQuery.ps1 @@ -160,6 +160,12 @@ function New-GraphDeltaQuery { if ($DeltaError) { throw "Delta Query failed for tenant '$TenantFilter'." } + # Never persist a row without a delta link. A blank DeltaUrl is not "start over", it is a + # row that every later evaluation reads and then fails to bind, so the trigger silently + # stops working until someone rebuilds it. + if ([string]::IsNullOrWhiteSpace($deltaLink)) { + throw "Graph returned no deltaLink for the '$($DeltaQuery.Resource ?? $Resource)' delta query on tenant '$TenantFilter'. The delta query row was not updated." + } $DeltaQuery.RowKey = $TenantFilter $DeltaQuery.DeltaUrl = $deltaLink diff --git a/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-UpdatePermissionsOrchestrator.ps1 b/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-UpdatePermissionsOrchestrator.ps1 index ea206ff721cf5..ead5e05b3da2a 100644 --- a/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-UpdatePermissionsOrchestrator.ps1 +++ b/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-UpdatePermissionsOrchestrator.ps1 @@ -63,9 +63,16 @@ function Start-UpdatePermissionsOrchestrator { OrchestratorName = 'UpdatePermissionsOrchestrator' Batch = @($TenantBatch) } - Start-CIPPOrchestrator -InputObject $InputObject + $InstanceId = Start-CIPPOrchestrator -InputObject $InputObject + Write-LogMessage -API 'CPVRefresh' -tenant 'Global' -message "Started CPV permissions refresh for $TenantCount tenant(s). QueueId=$($Queue.RowKey)" -Sev 'Info' + return $InstanceId } else { Write-Information 'No tenants require permissions update' + Write-LogMessage -API 'CPVRefresh' -tenant 'Global' -message 'CPV permissions refresh triggered; no tenants required an update' -Sev 'Info' + return $null } - } catch {} + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API 'CPVRefresh' -tenant 'Global' -message "Failed to start CPV permissions refresh: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage + } } diff --git a/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-UserTasksOrchestrator.ps1 b/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-UserTasksOrchestrator.ps1 index 131cf714d7cbb..069473961ed66 100644 --- a/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-UserTasksOrchestrator.ps1 +++ b/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-UserTasksOrchestrator.ps1 @@ -106,7 +106,11 @@ function Start-UserTasksOrchestrator { throw "Command '$($task.Command)' not found and no module could be resolved from the command name for scheduled task '$($task.Name)'." } } - $HasTenantFilter = $CommandInfo.Parameters.ContainsKey('TenantFilter') + # The task's authorized tenant is injected into the most specific tenant-identifying + # parameter the command declares - stored parameter values must never select the tenant. + $TenantParamNames = [array](@('TenantFilter', 'Tenant', 'TenantId') | Where-Object { $CommandInfo.Parameters.ContainsKey($_) }) + $HasTenantFilter = $TenantParamNames.Count -gt 0 + $PrimaryTenantParam = $TenantParamNames.Count -gt 0 ? $TenantParamNames[0] : $null $ScheduledCommand = [pscustomobject]@{ Command = $task.Command @@ -115,20 +119,79 @@ function Start-UserTasksOrchestrator { FunctionName = 'ExecScheduledCommand' } - if ($task.Tenant -eq 'AllTenants') { - $ExcludedTenants = @($task.excludedTenants -split ',' | Where-Object { $_ }) - if ($task.excludedTenantGroups) { - # Expand excluded tenant groups at runtime so membership changes are honored - $ExcludedGroups = $task.excludedTenantGroups | ConvertFrom-Json -ErrorAction SilentlyContinue - if ($ExcludedGroups) { - $ExcludedTenants = @($ExcludedTenants + (Expand-CIPPTenantGroups -TenantFilter $ExcludedGroups).value | Where-Object { $_ }) + # Scope is resolved on every run so group membership stays current, as + # Test-CIPPAuditLogRules does for audit alerts. The stored selection is only trusted + # on a row the execution gates also read as multi-tenant, otherwise the fan-out here + # and Push-ExecScheduledCommand would disagree about the task's shape. + $UsesStoredSelection = $task.Tenants -and $task.Tenant -eq 'AllTenants' + if ($task.Tenants -and -not $UsesStoredSelection) { + Write-Information "Task $($task.Name): ignoring the stored selection, Tenant is '$($task.Tenant)' rather than AllTenants" + } + $Selection = if ($UsesStoredSelection) { + @($task.Tenants | ConvertFrom-Json -ErrorAction SilentlyContinue) + } elseif ($task.TenantGroup) { + @($task.TenantGroup | ConvertFrom-Json -ErrorAction SilentlyContinue) + } + + $TargetTenants = $null + $ResolvedScope = $false + if ($Selection) { + try { + $Expanded = Expand-CIPPTenantGroups -TenantFilter $Selection + } catch { + # Must not fall through to the single-tenant path below: Tenant is the + # AllTenants sentinel for a multi-entry selection. Fail the task instead. + throw "Failed to expand tenant selection for task $($task.Name): $($_.Exception.Message)" + } + # Non-group entries pass through unexpanded, so the sentinel survives. + $TargetTenants = if ($Expanded.value -contains 'AllTenants') { + $TenantList + } else { + @($TenantList | Where-Object { $_.defaultDomainName -in $Expanded.value }) + } + $ResolvedScope = $true + } elseif ($task.Tenant -eq 'AllTenants') { + # An explicit *All Tenants pick, with no selection stored alongside it + $TargetTenants = $TenantList + $ResolvedScope = $true + } + + # Rows predating runtime expansion merged a snapshot of every unselected tenant into + # excludedTenants, indistinguishable from the operator's own picks, so it is ignored + # for those. A selection carrying the AllTenants sentinel never had a snapshot + # written, so its exclusions are the operator's and are kept. excludedTenantGroups + # was never part of the snapshot either and always applies. + $IsLegacySnapshot = $UsesStoredSelection -and -not $task.TenantSelectionVersion -and ($Selection.value -notcontains 'AllTenants') + $ExcludedTenants = [System.Collections.Generic.List[string]]::new() + if ($task.excludedTenants) { + $StoredExclusions = @($task.excludedTenants -split ',' | Where-Object { $_ }) + if ($IsLegacySnapshot) { + # Only report a snapshot that would actually have dropped a tenant in scope + # now, or every run of every legacy row logs the same no-op indefinitely. + $Reinstated = @($StoredExclusions | Where-Object { $_ -in $TargetTenants.defaultDomainName }) + if ($Reinstated.Count -gt 0) { + Write-LogMessage -API 'Scheduler_UserTasks' -tenant $tenant -message "Task $($task.Name): ignored $($Reinstated.Count) stale snapshot exclusions, tenant group membership is now resolved at runtime" -Sev 'Info' } + } else { + $ExcludedTenants.AddRange([string[]]$StoredExclusions) + } + } + if ($task.excludedTenantGroups) { + $ExcludedGroups = $task.excludedTenantGroups | ConvertFrom-Json -ErrorAction SilentlyContinue + if ($ExcludedGroups) { + $ExcludedTenants.AddRange([string[]]@((Expand-CIPPTenantGroups -TenantFilter $ExcludedGroups).value | Where-Object { $_ })) } - Write-Host "Excluded Tenants from this task: $ExcludedTenants" - $AllTenantCommands = foreach ($Tenant in $TenantList | Where-Object { $_.defaultDomainName -notin $ExcludedTenants }) { + } + + if ($ResolvedScope) { + Write-Information "Task $($task.Name): $(@($TargetTenants).Count) tenants in scope, $($ExcludedTenants.Count) excluded" + $FanOutCommands = foreach ($Tenant in $TargetTenants | Where-Object { $_.defaultDomainName -notin $ExcludedTenants }) { $NewParams = $task.Parameters.Clone() if ($HasTenantFilter) { + # TenantFilter always carries the execution tenant context; it is stripped + # before splatting if the command does not declare it $NewParams.TenantFilter = $Tenant.defaultDomainName + $NewParams.$PrimaryTenantParam = $Tenant.defaultDomainName } # Clone TaskInfo to prevent shared object references $TaskInfoClone = $task.PSObject.Copy() @@ -139,75 +202,49 @@ function Start-UserTasksOrchestrator { FunctionName = 'ExecScheduledCommand' } } - $Batch.AddRange(@($AllTenantCommands)) - } elseif ($task.TenantGroup) { - # Handle tenant groups - expand group to individual tenants - try { - $TenantGroupObject = $task.TenantGroup | ConvertFrom-Json - Write-Host "Expanding tenant group: $($TenantGroupObject.label) with ID: $($TenantGroupObject.value)" - - # Create a tenant filter object for expansion - $TenantFilterForExpansion = @([PSCustomObject]@{ - type = 'Group' - value = $TenantGroupObject.value - label = $TenantGroupObject.label - }) - - # Expand the tenant group to individual tenants - $ExpandedTenants = Expand-CIPPTenantGroups -TenantFilter $TenantFilterForExpansion - - $ExcludedTenants = @($task.excludedTenants -split ',' | Where-Object { $_ }) - if ($task.excludedTenantGroups) { - # Expand excluded tenant groups at runtime so membership changes are honored - $ExcludedGroups = $task.excludedTenantGroups | ConvertFrom-Json -ErrorAction SilentlyContinue - if ($ExcludedGroups) { - $ExcludedTenants = @($ExcludedTenants + (Expand-CIPPTenantGroups -TenantFilter $ExcludedGroups).value | Where-Object { $_ }) - } - } - Write-Host "Excluded Tenants from this task: $ExcludedTenants" - - $GroupTenantCommands = foreach ($ExpandedTenant in $ExpandedTenants | Where-Object { $_.value -notin $ExcludedTenants }) { - $NewParams = $task.Parameters.Clone() - if ($HasTenantFilter) { - $NewParams.TenantFilter = $ExpandedTenant.value - } - # Clone TaskInfo to prevent shared object references - $TaskInfoClone = $task.PSObject.Copy() - [pscustomobject]@{ - Command = $task.Command - Parameters = $NewParams - TaskInfo = $TaskInfoClone - FunctionName = 'ExecScheduledCommand' - } - } - $Batch.AddRange(@($GroupTenantCommands)) - } catch { - Write-Host "Error expanding tenant group: $($_.Exception.Message)" - Write-LogMessage -API 'Scheduler_UserTasks' -tenant $tenant -message "Failed to expand tenant group for task $($task.Name): $($_.Exception.Message)" -sev Error - - # Fall back to treating as single tenant - if ($HasTenantFilter) { - $ScheduledCommand.Parameters['TenantFilter'] = $task.Tenant + if (@($FanOutCommands).Count -gt 0) { + $Batch.AddRange(@($FanOutCommands)) + } else { + # Every selected group resolved empty, or was deleted. Close the run out here: + # the row is already Pending, and with no batch item no orchestrator or post + # execution runs, so it would be reclaimed as stale every hour and a recurring + # task would never advance its schedule. + $NextRun = Get-CIPPScheduledTaskNextRun -Recurrence $task.Recurrence -ScheduledTime $task.ScheduledTime + $EmptyScopeEntity = @{ + PartitionKey = $task.PartitionKey + RowKey = $task.RowKey + Results = 'No tenants in scope for this task.' + ExecutedTime = "$currentUnixTime" + TaskState = $NextRun -gt 0 ? 'Planned' : 'Completed' } - $Batch.Add($ScheduledCommand) + if ($NextRun -gt 0) { $EmptyScopeEntity.ScheduledTime = "$NextRun" } + $null = Update-AzDataTableEntity -Force @Table -Entity $EmptyScopeEntity + Write-LogMessage -API 'Scheduler_UserTasks' -tenant $tenant -message "Task $($task.Name): no tenants in scope, nothing to run" -Sev 'Info' } } else { - # Handle single tenant + # Single tenant if ($HasTenantFilter) { $ScheduledCommand.Parameters['TenantFilter'] = $task.Tenant + $ScheduledCommand.Parameters[$PrimaryTenantParam] = $task.Tenant } $Batch.Add($ScheduledCommand) } } catch { $errorMessage = $_.Exception.Message - $null = Update-AzDataTableEntity -Force @Table -Entity @{ + # Failed is terminal - the pickup filter only reads Planned and Failed - Planned - so + # a recurring task parked there never runs again. A transient failure here (a tenant + # or group table read, say) must not permanently stop it. + $NextRun = Get-CIPPScheduledTaskNextRun -Recurrence $task.Recurrence -ScheduledTime $task.ScheduledTime + $FailureEntity = @{ PartitionKey = $task.PartitionKey RowKey = $task.RowKey Results = "$errorMessage" ExecutedTime = "$currentUnixTime" - TaskState = 'Failed' + TaskState = $NextRun -gt 0 ? 'Failed - Planned' : 'Failed' } + if ($NextRun -gt 0) { $FailureEntity.ScheduledTime = "$NextRun" } + $null = Update-AzDataTableEntity -Force @Table -Entity $FailureEntity Write-LogMessage -API 'Scheduler_UserTasks' -tenant $tenant -message "Failed to execute task $($task.Name): $errorMessage" -sev Error } } diff --git a/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-TableCleanup.ps1 b/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-TableCleanup.ps1 index ef2c70496461b..a91a6dc0a1464 100644 --- a/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-TableCleanup.ps1 +++ b/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-TableCleanup.ps1 @@ -128,6 +128,18 @@ function Start-TableCleanup { Property = @('PartitionKey', 'RowKey', 'ETag') } } + @{ + # Live-progress rows of background jobs (SharePoint template deploys, user offboarding). + # They matter while the job runs; a month covers looking back at a task page afterwards. + FunctionName = 'TableCleanupTask' + Type = 'CleanupRule' + TableName = 'CacheAsyncDeployments' + DataTableProps = @{ + Filter = "Timestamp lt datetime'$((Get-Date).AddDays(-30).ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:ssZ'))'" + First = 10000 + Property = @('PartitionKey', 'RowKey', 'ETag') + } + } @{ FunctionName = 'TableCleanupTask' Type = 'DeleteTable' diff --git a/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-UpdateTokensTimer.ps1 b/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-UpdateTokensTimer.ps1 index 77a45fc69813e..4d0ddc5b22927 100644 --- a/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-UpdateTokensTimer.ps1 +++ b/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-UpdateTokensTimer.ps1 @@ -52,7 +52,12 @@ function Start-UpdateTokensTimer { Write-Information ($_.InvocationInfo.PositionMessage) } - if ($LastPasswordCredential.endDateTime -lt (Get-Date).AddDays(30).ToUniversalTime()) { + if ($env:CertificateAuthMode) { + # Certificate-exclusive mode: CIPP authenticates with the SAM certificate, so never + # generate a client secret. Doing so would fail on tenants blocking password addition, + # or silently re-create a secret on a secret-less install. The certificate is renewed below. + Write-Information "Certificate authentication is enabled for $AppId; skipping client secret generation." + } elseif ($LastPasswordCredential.endDateTime -lt (Get-Date).AddDays(30).ToUniversalTime()) { Write-Information "Application secret for $AppId is expiring soon. Generating a new application secret." $AppSecret = New-GraphPostRequest -uri "https://graph.microsoft.com/v1.0/applications/$($AppRegistration.id)/addPassword" -Body '{"passwordCredential":{"displayName":"UpdateTokens"}}' -NoAuthCheck $true -AsApp $true -ErrorAction Stop Write-Information "New application secret generated for $AppId. Expiration date: $($AppSecret.endDateTime)." diff --git a/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-UserSyncTimer.ps1 b/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-UserSyncTimer.ps1 index 8060d563651be..dabf3a7ee0f1d 100644 --- a/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-UserSyncTimer.ps1 +++ b/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-UserSyncTimer.ps1 @@ -24,20 +24,46 @@ function Start-UserSyncTimer { $AccessGroupsTable = Get-CippTable -TableName AccessRoleGroups $AccessGroups = @(Get-CIPPAzDataTableEntity @AccessGroupsTable -Filter "PartitionKey eq 'AccessRoleGroups'") - # Get the group IDs we care about - $RoleGroupIds = @($AccessGroups | ForEach-Object { $_.GroupId } | Where-Object { $_ }) + # Load the roles that actually exist on this instance. A mapping whose role was never + # migrated across (or was later deleted) leaves an orphaned auto-role that the access + # check cannot resolve - which locks the user out of everything, base role included. + # Skipping those mappings here lets the sync self-heal: because each user's auto-roles + # are recomputed from scratch every run, the stale role is dropped from every affected + # user on the next pass instead of being re-stamped forever. This mirrors the same + # existence guard the live path already applies in Test-CIPPAccessUserRole. + # $CustomRoleNames stays $null when the lookup fails so a transient storage error + # degrades to "prune nothing" rather than stripping every custom role from every user. + $BaseRoles = @('superadmin', 'admin', 'editor', 'readonly') + $CustomRoleNames = $null + try { + $CustomRolesTable = Get-CippTable -TableName CustomRoles + $CustomRoleNames = @(Get-CIPPAzDataTableEntity @CustomRolesTable -Filter "PartitionKey eq 'CustomRoles'" | ForEach-Object { $_.RowKey }) + } catch { + Write-LogMessage -API $ApiName -tenant 'none' -message "User sync could not load custom roles; skipping stale-role pruning this run: $($_.Exception.Message)" -sev Warning + } - # Build a lookup: GroupId -> Role names (a group can map to multiple roles) + # Build a lookup: GroupId -> Role names (a group can map to multiple roles), keeping only + # roles that still exist. Orphaned role names are collected so the run that prunes them + # can say which ones, without re-logging on every steady-state pass afterwards. $GroupToRoles = @{} + $SkippedRoles = [System.Collections.Generic.List[string]]::new() foreach ($Mapping in $AccessGroups) { - if ($Mapping.GroupId) { - if (-not $GroupToRoles.ContainsKey($Mapping.GroupId)) { - $GroupToRoles[$Mapping.GroupId] = [System.Collections.Generic.List[string]]::new() - } - $GroupToRoles[$Mapping.GroupId].Add($Mapping.RowKey) + if (-not $Mapping.GroupId) { continue } + # $null CustomRoleNames means the lookup failed above - treat every role as valid. + $RoleExists = ($BaseRoles -contains $Mapping.RowKey) -or ($null -eq $CustomRoleNames) -or ($CustomRoleNames -contains $Mapping.RowKey) + if (-not $RoleExists) { + if ($SkippedRoles -notcontains $Mapping.RowKey) { $SkippedRoles.Add($Mapping.RowKey) } + continue } + if (-not $GroupToRoles.ContainsKey($Mapping.GroupId)) { + $GroupToRoles[$Mapping.GroupId] = [System.Collections.Generic.List[string]]::new() + } + $GroupToRoles[$Mapping.GroupId].Add($Mapping.RowKey) } + # Only fetch members of groups that still map to at least one real role + $RoleGroupIds = @($GroupToRoles.Keys) + # Fetch members of each role group from the partner tenant # Use transitiveMembers to catch nested group memberships $UserRoleMap = @{} # UPN -> HashSet of auto roles @@ -52,6 +78,19 @@ function Start-UserSyncTimer { foreach ($Member in $UserMembers) { $Upn = $Member.userPrincipalName if ([string]::IsNullOrWhiteSpace($Upn)) { continue } + + if ($Upn -match '#EXT#') { + if (-not [string]::IsNullOrWhiteSpace($Member.mail)) { + $Upn = $Member.mail + } else { + $Upn = ($Upn -replace '#EXT#@.+$', '') -replace '_([^_]+)$', '@$1' + } + } + + if ($Upn -match '[#/\\?]') { + Write-LogMessage -API $ApiName -tenant 'none' -message "User sync skipped '$($Member.userPrincipalName)': could not derive a Table Storage-safe key." -sev Warning + continue + } $Upn = $Upn.Trim().ToLower() if (-not $UserRoleMap.ContainsKey($Upn)) { @@ -223,7 +262,11 @@ function Start-UserSyncTimer { # Only log when something actually changed — no noise on steady-state runs. if ($ChangedCount -gt 0 -or $RemoveCount -gt 0) { - Write-LogMessage -API $ApiName -tenant 'none' -message "User sync completed: $ChangedCount users added/updated, $RemoveCount duplicate/stale rows removed." -sev Info + $Message = "User sync completed: $ChangedCount users added/updated, $RemoveCount duplicate/stale rows removed." + if ($SkippedRoles.Count -gt 0) { + $Message += " Pruned auto-role(s) with no matching definition on this instance: $($SkippedRoles -join ', ')." + } + Write-LogMessage -API $ApiName -tenant 'none' -message $Message -sev Info } } catch { diff --git a/Modules/CIPPCore/Public/Functions/Format-CIPPCAPolicy.ps1 b/Modules/CIPPCore/Public/Functions/Format-CIPPCAPolicy.ps1 index f97189819906f..236dde50cd5eb 100644 --- a/Modules/CIPPCore/Public/Functions/Format-CIPPCAPolicy.ps1 +++ b/Modules/CIPPCore/Public/Functions/Format-CIPPCAPolicy.ps1 @@ -24,6 +24,12 @@ function Format-CIPPCAPolicy { than being removed - null is accepted on a create and still clears on an update. Empty assignment arrays are deliberately KEPT: an explicit "includeGroups": [] is the only thing that strips a group off a policy that already has one. + + 3. sessionControls.signInFrequency - value is Int32 in Graph but has been saved as a + string by older editors, so a numeric string is cast. When frequencyInterval is + everyTime, value/type are forced explicitly null (added if absent) since Graph + requires both null there and a PATCH merge would otherwise let a stale value/type + survive from the tenant's existing policy. .PARAMETER Policy The parsed CA policy object. Mutated in place. .FUNCTIONALITY @@ -136,4 +142,19 @@ function Format-CIPPCAPolicy { $Policy.sessionControls = $null } } + + # signInFrequency.value is Int32 in Graph, but editors have saved it as a string - cast it. + # When frequencyInterval is everyTime, Graph requires value/type to be null rather than + # merely absent, and this is a PATCH merge, so a stale value/type from the tenant's existing + # policy would otherwise survive. + $SignInFrequency = $Policy.sessionControls.signInFrequency + if ($null -ne $SignInFrequency -and $SignInFrequency -is [PSCustomObject]) { + if ($SignInFrequency.PSObject.Properties.Name -contains 'value' -and $SignInFrequency.value -is [string] -and $SignInFrequency.value -match '^\d+$') { + $SignInFrequency.value = [int]$SignInFrequency.value + } + if ($SignInFrequency.frequencyInterval -eq 'everyTime') { + $SignInFrequency | Add-Member -NotePropertyName 'value' -NotePropertyValue $null -Force + $SignInFrequency | Add-Member -NotePropertyName 'type' -NotePropertyValue $null -Force + } + } } diff --git a/Modules/CIPPCore/Public/Functions/Get-CIPPAppServiceSite.ps1 b/Modules/CIPPCore/Public/Functions/Get-CIPPAppServiceSite.ps1 new file mode 100644 index 0000000000000..b729fc979f265 --- /dev/null +++ b/Modules/CIPPCore/Public/Functions/Get-CIPPAppServiceSite.ps1 @@ -0,0 +1,52 @@ +function Get-CIPPAppServiceSite { + <# + .SYNOPSIS + Resolves the App Service hosting this CIPP instance and the certificates its plan can bind. + .DESCRIPTION + One ARM read of the site (Microsoft.Web/sites/$env:WEBSITE_SITE_NAME, via the managed + identity) plus one of the certificates in the plan's resource group. A certificate binds + from the App Service PLAN's webspace, not the site's, so when the plan lives in another + resource group (a shared plan) certificates are created and looked up there. On a dedicated + plan both resource groups are the same. + + The certificate list is best effort: an identity without rights on the plan's resource + group gets an empty list, and the caller's create/bind then fails with the real 403. + .FUNCTIONALITY + Internal + .EXAMPLE + $AppService = Get-CIPPAppServiceSite + $AppService.Site.properties.hostNames + #> + [CmdletBinding()] + param( + [string]$ApiVersion = '2024-11-01' + ) + + $SiteName = $env:WEBSITE_SITE_NAME + $ResourceGroup = Get-CIPPFunctionAppResourceGroup -SiteName $SiteName + $SubscriptionId = Get-CIPPAzFunctionAppSubId + $ArmBase = "https://management.azure.com/subscriptions/$SubscriptionId/resourceGroups/$ResourceGroup/providers/Microsoft.Web/sites/$SiteName" + $Site = New-CIPPAzRestRequest -Uri "$ArmBase`?api-version=$ApiVersion" -Method GET -ErrorAction Stop + + $PlanId = [string]$Site.properties.serverFarmId + $CertResourceGroup = if ($PlanId -match '(?i)/resourceGroups/([^/]+)/') { $Matches[1] } else { $ResourceGroup } + $CertBase = "https://management.azure.com/subscriptions/$SubscriptionId/resourceGroups/$CertResourceGroup/providers/Microsoft.Web/certificates" + $Certificates = try { + @((New-CIPPAzRestRequest -Uri "$CertBase`?api-version=$ApiVersion" -Method GET -ErrorAction Stop).value) + } catch { + Write-Information "Could not list certificates in resource group '$CertResourceGroup': $($_.Exception.Message)" + @() + } + + [pscustomobject]@{ + SubscriptionId = $SubscriptionId + SiteName = $SiteName + ResourceGroup = $ResourceGroup + CertResourceGroup = $CertResourceGroup + ArmBase = $ArmBase + CertBase = $CertBase + ApiVersion = $ApiVersion + Site = $Site + Certificates = $Certificates + } +} diff --git a/Modules/CIPPCore/Public/Functions/Get-CIPPHostname.ps1 b/Modules/CIPPCore/Public/Functions/Get-CIPPHostname.ps1 index 02abf305acb1b..8309d2236028d 100644 --- a/Modules/CIPPCore/Public/Functions/Get-CIPPHostname.ps1 +++ b/Modules/CIPPCore/Public/Functions/Get-CIPPHostname.ps1 @@ -15,7 +15,10 @@ function Get-CIPPHostname { Resolve from the custom domain bound to the App Service ahead of the inbound request. Use it for anything that outlives the request - webhook registrations, stored URLs - so an admin who happens to browse in on the *.azurewebsites.net hostname does not pin - background work to it. + background work to it. Only a custom domain takes precedence: when none is bound to the + App Service the inbound request still decides, so a Static Web App deployment (custom + domain on the SWA, API as a linked backend) keeps generating links on the domain the + user is actually on rather than the platform hostname. .FUNCTIONALITY Internal .EXAMPLE @@ -30,17 +33,21 @@ function Get-CIPPHostname { $Hostname = $null - # Only an authoritative ARM answer wins here. When the lookup fails we fall through to the - # request host rather than guessing: demoting a working custom domain to the platform hostname - # on a transient 403 would silently rewrite every link CIPP sends out. + # Only an authoritative ARM answer that found a custom domain wins here. When the lookup fails + # we fall through to the request host rather than guessing: demoting a working custom domain to + # the platform hostname on a transient 403 would silently rewrite every link CIPP sends out. + # The same applies when ARM answers but no custom domain is bound: behind a Static Web App the + # custom domain lives on the SWA, so the function app's own hostname is never user-facing. if ($PreferCustomDomain.IsPresent) { try { $SiteState = Get-CIPPSiteHostname -IncludeStatus -NoFallback - if ($SiteState.Discovered -and ![string]::IsNullOrWhiteSpace($SiteState.PreferredHostname)) { + if ($SiteState.Discovered -and $SiteState.CustomHostnames.Count -gt 0 -and ![string]::IsNullOrWhiteSpace($SiteState.PreferredHostname)) { $Hostname = $SiteState.PreferredHostname if ($SiteState.CustomHostnames.Count -gt 1) { Write-Information "Get-CIPPHostname: $($SiteState.CustomHostnames.Count) custom domains bound ($($SiteState.CustomHostnames -join ', ')) - using the first, '$Hostname'" } + } elseif ($SiteState.Discovered) { + Write-Information 'Get-CIPPHostname: no custom domain is bound to this App Service - falling back to the request host' } else { Write-Information "Get-CIPPHostname: custom domain lookup was not authoritative, falling back to the request host: $($SiteState.Error)" } diff --git a/Modules/CIPPCore/Public/Functions/Get-CIPPTenantAlignment.ps1 b/Modules/CIPPCore/Public/Functions/Get-CIPPTenantAlignment.ps1 index 240e77e0aec6d..49ce40b910c84 100644 --- a/Modules/CIPPCore/Public/Functions/Get-CIPPTenantAlignment.ps1 +++ b/Modules/CIPPCore/Public/Functions/Get-CIPPTenantAlignment.ps1 @@ -90,6 +90,33 @@ function Get-CIPPTenantAlignment { $CATemplatesByPackage[$t.Package].Add($t) } } + # Every id a standards template can legitimately reference for each template type: the + # RowKey, the GUID column (the picker surfaces that one) and the bare guid of a built-in + # '..json' row. A reference that matches none of these points at a template that + # was deleted, and its standard can never get a report row - it would sit at NOT FOUND + # forever with nothing naming the culprit. + function Get-TemplateIdSet { + param($Rows) + $Set = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + foreach ($Row in @($Rows)) { + if ($Row.RowKey) { + [void]$Set.Add([string]$Row.RowKey) + if ($Row.RowKey -match '^([0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12})\.') { [void]$Set.Add($Matches[1]) } + } + if ($Row.GUID) { [void]$Set.Add([string]$Row.GUID) } + } + return , $Set + } + $KnownIntuneTemplateIds = Get-TemplateIdSet -Rows $TagTemplates + $KnownCATemplateIds = Get-TemplateIdSet -Rows $CATagTemplates + $KnownReusableTemplateIds = Get-TemplateIdSet -Rows (Get-CIPPAzDataTableEntity @TemplateTable -Filter "PartitionKey eq 'IntuneReusableSettingTemplate'") + function Get-MissingTemplateMessage { + param([string]$Kind, $Reference, [System.Collections.Generic.HashSet[string]]$KnownIds) + $Id = [string]$Reference.value + if ([string]::IsNullOrWhiteSpace($Id) -or $KnownIds.Contains($Id)) { return $null } + $Name = if ($Reference.label) { "'$($Reference.label)' " } else { '' } + return "$Kind template $Name($Id) no longer exists in the template library. Remove it from this standards template or select the template again." + } # Build tenant standards data structure $tenantData = @{} foreach ($Standard in $Standards) { @@ -218,6 +245,7 @@ function Get-CIPPTenantAlignment { [PSCustomObject]@{ StandardId = $IntuneStandardId ReportingEnabled = $IntuneReportingEnabled + MissingTemplate = Get-MissingTemplateMessage -Kind 'Intune' -Reference $IntuneTemplate.TemplateList -KnownIds $KnownIntuneTemplateIds } } @@ -252,6 +280,7 @@ function Get-CIPPTenantAlignment { [PSCustomObject]@{ StandardId = $CAStandardId ReportingEnabled = $CAReportingEnabled + MissingTemplate = Get-MissingTemplateMessage -Kind 'Conditional Access' -Reference $CATemplate.TemplateList -KnownIds $KnownCATemplateIds } } @@ -280,11 +309,14 @@ function Get-CIPPTenantAlignment { foreach ($RSTemplate in @($StandardConfig)) { $RSActions = if ($RSTemplate.action) { $RSTemplate.action } else { @() } $RSReportingEnabled = ($RSActions | Where-Object { $_.value -and ($_.value.ToLower() -eq 'report' -or $_.value.ToLower() -eq 'remediate') }).Count -gt 0 - foreach ($RSTemplateId in @($RSTemplate.TemplateList.value)) { + foreach ($RSReference in @($RSTemplate.TemplateList)) { + $RSTemplateId = if ($RSReference.value) { [string]$RSReference.value } else { [string]$RSReference } if ($RSTemplateId) { + $RSLookup = if ($RSReference.value) { $RSReference } else { [PSCustomObject]@{ value = $RSTemplateId; label = $null } } [PSCustomObject]@{ StandardId = "standards.ReusableSettingsTemplate.$RSTemplateId" ReportingEnabled = $RSReportingEnabled + MissingTemplate = Get-MissingTemplateMessage -Kind 'Reusable settings' -Reference $RSLookup -KnownIds $KnownReusableTemplateIds } } } @@ -312,6 +344,12 @@ function Get-CIPPTenantAlignment { } if (-not $StandardsData) { continue } + $MissingTemplateMessages = @{} + foreach ($Entry in @($StandardsData)) { + if ($Entry.PSObject.Properties['MissingTemplate'] -and $Entry.MissingTemplate -and $Entry.StandardId) { + $MissingTemplateMessages[[string]$Entry.StandardId] = [string]$Entry.MissingTemplate + } + } $AllStandards = @($StandardsData.StandardId | Where-Object { $_ }) if ($AllStandards.Count -eq 0) { continue } $AllStandardsArray = $AllStandards @@ -374,6 +412,23 @@ function Get-CIPPTenantAlignment { $IsReportingDisabled = $ReportingDisabledSet.Contains($StandardKey) # Use cached tenant data + # A standard pointing at a deleted template never gets a report row. Say so, + # naming the template, instead of reporting NOT FOUND until the end of time. + if ($MissingTemplateMessages.ContainsKey($StandardKey)) { + $ComparisonResults.Add([PSCustomObject]@{ + StandardName = $StandardKey + Compliant = $false + StandardValue = $MissingTemplateMessages[$StandardKey] + ComplianceStatus = if ($IsReportingDisabled) { 'Reporting Disabled' } else { 'Non-Compliant' } + ReportingDisabled = $IsReportingDisabled + LicenseAvailable = $null + CurrentValue = $MissingTemplateMessages[$StandardKey] + ExpectedValue = $null + TemplateMissing = $true + }) + continue + } + $HasStandard = $StandardKey -and $CurrentTenantStandards.ContainsKey($StandardKey) if ($HasStandard) { diff --git a/Modules/CIPPCore/Public/Functions/Get-CIPPURLName.ps1 b/Modules/CIPPCore/Public/Functions/Get-CIPPURLName.ps1 index cefb64d2a6c18..b90f8aaaf4518 100644 --- a/Modules/CIPPCore/Public/Functions/Get-CIPPURLName.ps1 +++ b/Modules/CIPPCore/Public/Functions/Get-CIPPURLName.ps1 @@ -139,6 +139,9 @@ function Get-CIPPURLName { '*officeSuiteApp' { 'deviceAppManagement/mobileApps' } + '*microsoftEdgeApp' { + 'deviceAppManagement/mobileApps' + } # Named Locations '*namedLocation' { diff --git a/Modules/CIPPCore/Public/Functions/Invoke-CIPPCustomDomainCertificate.ps1 b/Modules/CIPPCore/Public/Functions/Invoke-CIPPCustomDomainCertificate.ps1 new file mode 100644 index 0000000000000..4beed42040499 --- /dev/null +++ b/Modules/CIPPCore/Public/Functions/Invoke-CIPPCustomDomainCertificate.ps1 @@ -0,0 +1,131 @@ +function Invoke-CIPPCustomDomainCertificate { + <# + .SYNOPSIS + Issues an App Service Managed Certificate for a bound custom domain and enables its SNI binding. + .DESCRIPTION + Managed certificate issuance is asynchronous and regularly outlives a single request, so this + runs once inline from the Custom Domains wizard and then, while the certificate is still + pending or the attempt failed, reschedules itself as a hidden one-off task 15 minutes out. + It stops on success, when the hostname is no longer bound (the domain was removed in the + meantime), and after MaxAttempts - it never reschedules past that. + + Every run is idempotent: an existing certificate for the hostname is reused rather than + re-created, and a certificate whose issuance is already in flight (ARM answers 409) is + polled for instead of failing. + .PARAMETER Hostname + The custom domain. Its hostname binding must already exist on the App Service. + .PARAMETER Attempt + Current attempt number. Managed by the reschedule - callers should leave it at the default. + .PARAMETER MaxAttempts + Total attempts before giving up. Defaults to 4: the inline run plus three retries. + .FUNCTIONALITY + Internal + .EXAMPLE + Invoke-CIPPCustomDomainCertificate -Hostname 'portal.contoso.com' + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [ValidatePattern('^[a-z0-9][a-z0-9.-]*\.[a-z]{2,}$')] + [string]$Hostname, + + [int]$Attempt = 1, + + [int]$MaxAttempts = 4 + ) + + $AppService = Get-CIPPAppServiceSite + $Api = $AppService.ApiVersion + + if ($AppService.Site.properties.hostNames -notcontains $Hostname) { + $Message = "No hostname binding exists for '$Hostname' - the domain was removed or never added. Nothing to do." + Write-LogMessage -API 'CustomDomains' -message $Message -sev Warn + return $Message + } + + $SslState = ($AppService.Site.properties.hostNameSslStates | Where-Object { $_.name -eq $Hostname } | Select-Object -First 1).sslState + if ($SslState -in @('SniEnabled', 'IpBasedEnabled')) { + $Message = "'$Hostname' is already secured ($SslState)." + Write-LogMessage -API 'CustomDomains' -message $Message -sev Info + return $Message + } + + $Outcome = $null + try { + # Reuse whatever certificate already covers this hostname, whatever it is named: Azure keys + # uniqueness on canonicalName per plan, so a second PUT for the same hostname is rejected. + $Cert = $AppService.Certificates | Where-Object { $_.properties.canonicalName -eq $Hostname } | Select-Object -First 1 + if (-not $Cert) { + # Same name the Azure portal uses, so a portal-created certificate is the same resource. + $CertUri = "$($AppService.CertBase)/$Hostname-$($AppService.SiteName)?api-version=$Api" + $CertBody = @{ + location = $AppService.Site.location + properties = @{ + canonicalName = $Hostname + serverFarmId = $AppService.Site.properties.serverFarmId + } + } + try { + $Cert = New-CIPPAzRestRequest -Uri $CertUri -Method PUT -Body $CertBody -ErrorAction Stop + } catch { + # An issuance already in flight holds the hostname's slot before the resource exists, + # so the list above finds nothing and the PUT answers 409. Poll for it instead. + if ($_.Exception.Message -notmatch 'Conflict|duplicate') { throw } + Write-Information "Certificate creation for $Hostname returned 409 - an issuance is already pending, polling for it instead" + } + } + + # Brief poll (6 x 10 s): issuance usually takes a minute or two; anything longer is what + # the retry is for. + $Thumbprint = $Cert.properties.thumbprint + for ($Poll = 0; -not $Thumbprint -and $Poll -lt 6; $Poll++) { + Start-Sleep -Seconds 10 + $Issued = try { + (New-CIPPAzRestRequest -Uri "$($AppService.CertBase)?api-version=$Api" -Method GET -ErrorAction Stop).value | + Where-Object { $_.properties.canonicalName -eq $Hostname } | Select-Object -First 1 + } catch { $null } + $Thumbprint = $Issued.properties.thumbprint + } + + if ($Thumbprint) { + $BindBody = @{ properties = @{ sslState = 'SniEnabled'; thumbprint = $Thumbprint; toUpdate = $true } } + $null = New-CIPPAzRestRequest -Uri "$($AppService.ArmBase)/hostNameBindings/$Hostname`?api-version=$Api" -Method PUT -Body $BindBody -ErrorAction Stop + $Message = "Managed certificate issued and SNI SSL enabled for '$Hostname'. The domain is now secured." + Write-LogMessage -API 'CustomDomains' -message $Message -sev Info + return $Message + } + $Outcome = "The managed certificate for '$Hostname' is still being issued" + } catch { + $Outcome = "Certificate provisioning for '$Hostname' failed: $((Get-CippException -Exception $_).NormalizedError)" + } + + if ($Attempt -ge $MaxAttempts) { + $Message = "$Outcome. Giving up after $MaxAttempts attempts - check that the domain's DNS record points directly at this App Service (not through a proxy or CDN), then run 'Provision certificate' on the domain again." + Write-LogMessage -API 'CustomDomains' -message $Message -sev Error + return $Message + } + + $ScheduleResult = Add-CIPPScheduledTask -Hidden $true -Task ([pscustomobject]@{ + TenantFilter = $env:TenantID + Name = "Custom domain certificate: $Hostname" + Command = @{ value = 'Invoke-CIPPCustomDomainCertificate' } + Parameters = [pscustomobject]@{ + Hostname = $Hostname + Attempt = $Attempt + 1 + MaxAttempts = $MaxAttempts + } + ScheduledTime = [int64](([datetime]::UtcNow.AddMinutes(15)) - (Get-Date '1/1/1970')).TotalSeconds + Recurrence = '0' + PostExecution = @{} + Reference = "CustomDomainCert-$Hostname" + }) + if ("$ScheduleResult" -match '^Error') { + $Message = "$Outcome, and the retry could not be scheduled: $ScheduleResult" + Write-LogMessage -API 'CustomDomains' -message $Message -sev Error + return $Message + } + + $Message = "$Outcome (attempt $Attempt of $MaxAttempts). CIPP will try again in 15 minutes." + Write-LogMessage -API 'CustomDomains' -message $Message -sev Info + return $Message +} diff --git a/Modules/CIPPCore/Public/Functions/Test-CIPPCacheCapabilityError.ps1 b/Modules/CIPPCore/Public/Functions/Test-CIPPCacheCapabilityError.ps1 new file mode 100644 index 0000000000000..df81af8a4e87c --- /dev/null +++ b/Modules/CIPPCore/Public/Functions/Test-CIPPCacheCapabilityError.ps1 @@ -0,0 +1,51 @@ +function Test-CIPPCacheCapabilityError { + <# + .SYNOPSIS + Returns $true when a cache-collection exception reflects a benign tenant condition + rather than a real fault. + + .DESCRIPTION + License gating (Push-CIPPDBCacheData) skips whole collection groups a tenant is not + licensed for, but it cannot detect a service that is licensed yet not provisioned - for + example a Business Premium tenant that holds a Defender for Business (MDE_SMB) plan but + has never onboarded a device to Defender for Endpoint. Those endpoints answer with + 'No active license found' and similar, which is an expected state rather than an error + worth surfacing to an MSP. + + Collectors pass their caught exception message here to decide log severity: a match is + logged at Debug and treated as a clean skip; anything else stays an Error. + + .PARAMETER Message + The exception message to classify. + + .FUNCTIONALITY + Internal + + .EXAMPLE + $Sev = if (Test-CIPPCacheCapabilityError -Message $_.Exception.Message) { 'Debug' } else { 'Error' } + #> + [OutputType([bool])] + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [AllowEmptyString()] + [string]$Message + ) + + if ([string]::IsNullOrWhiteSpace($Message)) { return $false } + + # High-confidence 'tenant lacks or has not provisioned this capability' signals. Kept + # deliberately specific so a genuine failure is never silently downgraded to Debug. + $BenignPatterns = @( + 'No active license found' + 'not licensed' + 'does not have a valid' + '(is )?not onboarded' + 'license.{0,20}(is )?(required|not found|missing)' + ) + + foreach ($Pattern in $BenignPatterns) { + if ($Message -match $Pattern) { return $true } + } + return $false +} diff --git a/Modules/CIPPCore/Public/Get-CIPPAuthentication.ps1 b/Modules/CIPPCore/Public/Get-CIPPAuthentication.ps1 index 699531c9b0754..04c1ada114d5c 100644 --- a/Modules/CIPPCore/Public/Get-CIPPAuthentication.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPAuthentication.ps1 @@ -108,6 +108,16 @@ function Get-CIPPAuthentication { Write-LogMessage -message 'Could not preload or provision the SAM certificate. It will be retried by the weekly token update.' -Sev 'Warning' -API 'CIPP Authentication' -LogData (Get-CippException -Exception $_) } + # Mirror the CertificateAuthentication flag to an env var so the hot token path (Get-GraphToken) + # reads it without a table hit. The flag is the single source of truth; set when enabled, + # cleared when not - consumers do a plain truthiness check (same pattern as SetFromProfile). + try { + $CertFlag = Get-CIPPFeatureFlag -Id 'CertificateAuthentication' + $env:CertificateAuthMode = if ($CertFlag.Enabled -eq $true) { $true } else { $null } + } catch { + Write-Information "Could not resolve certificate auth mode: $($_.Exception.Message)" + } + Write-LogMessage -message 'Reloaded authentication data from KeyVault' -Sev 'debug' -API 'CIPP Authentication' return $true diff --git a/Modules/CIPPCore/Public/Get-CIPPBackup.ps1 b/Modules/CIPPCore/Public/Get-CIPPBackup.ps1 index fbfe7dc676577..13a45d81c9db9 100644 --- a/Modules/CIPPCore/Public/Get-CIPPBackup.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPBackup.ps1 @@ -88,8 +88,10 @@ function Get-CIPPBackup { } } } - $item | Add-Member -NotePropertyName 'BackupIsBlobLink' -NotePropertyValue $isBlobLink -Force - $item | Add-Member -NotePropertyName 'BlobResourcePath' -NotePropertyValue $blobPath -Force + $item | Add-Member -NotePropertyMembers ([ordered]@{ + BackupIsBlobLink = $isBlobLink + BlobResourcePath = $blobPath + }) -Force } } return $Info diff --git a/Modules/CIPPCore/Public/Get-CIPPCVEReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPCVEReport.ps1 index f995a1f470134..dd77ec9051353 100644 --- a/Modules/CIPPCore/Public/Get-CIPPCVEReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPCVEReport.ps1 @@ -68,8 +68,6 @@ function Get-CIPPCVEReport { TotalDeviceCount = 0 AffectedTenantsList = [System.Collections.Generic.List[object]]::new() AffectedDevicesList = [System.Collections.Generic.List[object]]::new() - DiskPathList = [System.Collections.Generic.List[object]]::new() - RegistryPathList = [System.Collections.Generic.List[object]]::new() ExceptionMatchCount = 0 TotalTenantGroupCount = 0 ExceptionSources = [System.Collections.Generic.HashSet[string]]::new() @@ -81,22 +79,14 @@ function Get-CIPPCVEReport { [void]$CveGroup.AffectedTenantsList.Add(@{ customerId = $Item.customerId }) - # Unpack the device JSON details from the row + # Trust the unique-device count the collector wrote rather than recounting unpacked + # rows; for AllTenants this sums each tenant's contribution to the same CVE. + $CveGroup.TotalDeviceCount += [int]$Item.deviceCount + + # Unpack the minimal per-device detail ({deviceId, deviceName}) from the row. if ($Item.deviceDetailsJson) { - $Devices = ConvertFrom-Json $Item.deviceDetailsJson | Sort-Object -Property deviceName -Unique - foreach ($Dev in $Devices) { - [void]$CveGroup.AffectedDevicesList.Add(@{ deviceName = $Dev.deviceName }) - if ($Dev.registryPaths) { - [void]$CveGroup.RegistryPathList.Add(@{ deviceName = $Dev.deviceName - registryPaths = $Dev.registryPaths - }) - } - if ($Dev.diskPaths) { - [void]$CveGroup.DiskPathList.Add(@{ deviceName = $Dev.deviceName - diskPaths = $Dev.diskPaths - }) - } - $CveGroup.TotalDeviceCount ++ + foreach ($Dev in @(ConvertFrom-Json $Item.deviceDetailsJson)) { + [void]$CveGroup.AffectedDevicesList.Add(@{ deviceId = $Dev.deviceId; deviceName = $Dev.deviceName }) } } } @@ -172,8 +162,6 @@ function Get-CIPPCVEReport { softwareVersion = $Target.softwareVersion deviceCount = $Target.TotalDeviceCount tenantCount = $Target.TotalTenantGroupCount - registryPaths = $Target.RegistryPathList - diskPaths = $Target.DiskPathList exceptionStatus = $ExceptionStatus hasException = $HasException affectedTenants = $Target.AffectedTenantsList diff --git a/Modules/CIPPCore/Public/Get-CIPPDbItemPage.ps1 b/Modules/CIPPCore/Public/Get-CIPPDbItemPage.ps1 new file mode 100644 index 0000000000000..3bfedaaa1ae6e --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPDbItemPage.ps1 @@ -0,0 +1,61 @@ +function Get-CIPPDbItemPage { + <# + .FUNCTIONALITY + Internal + .SYNOPSIS + Reads one page of items of a type from the CIPP Reporting database. + .DESCRIPTION + Continuation-token pager over CippReportingDB (PartitionKey = tenant, RowKey = '-'). + AllTenants walks every managed tenant that has a '-Count' row; a single tenant walks + its own partition. Returns raw entities minus the count markers; callers parse Data and + read the tenant from PartitionKey. A null NextToken means the walk is complete. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + [Parameter(Mandatory = $true)] + [string]$Type, + [ValidateRange(1, 10000)] + [int]$PageSize = 5000, + [string]$ContinuationToken + ) + + # Enforce tenant lock when running inside custom script execution (parity with Get-CIPPDbItem) + if ($script:CIPPLockedTenant) { + $TenantFilter = $script:CIPPLockedTenant + } + + $Table = Get-CippTable -tablename 'CippReportingDB' + + if ($TenantFilter -eq 'AllTenants') { + $CountRows = Get-CIPPDbItem -TenantFilter 'allTenants' -Type $Type -CountsOnly + $TenantList = Get-Tenants -IncludeErrors + $Known = [System.Collections.Generic.HashSet[string]]::new([StringComparer]::OrdinalIgnoreCase) + foreach ($Domain in $TenantList.defaultDomainName) { + if ($Domain) { $null = $Known.Add([string]$Domain) } + } + # Ordinal ascending, to match the walker's range-scan order. + $Unique = [System.Collections.Generic.HashSet[string]]::new([StringComparer]::Ordinal) + foreach ($Partition in $CountRows.PartitionKey) { + if ($Partition -and $Known.Contains([string]$Partition)) { $null = $Unique.Add([string]$Partition) } + } + $Partitions = [string[]]@($Unique) + [System.Array]::Sort($Partitions, [System.Collections.IComparer][StringComparer]::Ordinal) + } else { + $Tenant = Get-Tenants -TenantFilter $TenantFilter + if (-not $Tenant) { + throw "Tenant '$TenantFilter' not found" + } + $Partitions = @($Tenant.defaultDomainName) + } + + $Page = Get-CIPPPagedTableRows -Table $Table -PartitionKeys $Partitions -RowKeyGe "$Type-" -RowKeyLt "$Type." -PageSize $PageSize -ContinuationToken $ContinuationToken + # Drop the count marker, which sorts inside the range. + $Items = @($Page.Rows | Where-Object { $_.RowKey -ne "$Type-Count" }) + + return [PSCustomObject]@{ + Items = $Items + NextToken = $Page.NextToken + } +} diff --git a/Modules/CIPPCore/Public/Get-CIPPDrift.ps1 b/Modules/CIPPCore/Public/Get-CIPPDrift.ps1 index 88a23d6a5b914..0bf9ae6653b16 100644 --- a/Modules/CIPPCore/Public/Get-CIPPDrift.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPDrift.ps1 @@ -29,6 +29,26 @@ function Get-CIPPDrift { [switch]$AllTenants ) + # The label a standards template stores for a template reference, for the template types whose + # standard key ends in the referenced template id. Used when the template row itself is gone. + function Get-DriftTemplateLabel { + param($StandardName, $StandardSettings) + if (-not $StandardSettings) { return $null } + $Match = [regex]::Match([string]$StandardName, '^standards\.(IntuneTemplate|ConditionalAccessTemplate|ReusableSettingsTemplate)\.(.+)$') + if (-not $Match.Success) { return $null } + $Kind = $Match.Groups[1].Value + $Id = $Match.Groups[2].Value + foreach ($Entry in @($StandardSettings.$Kind)) { + foreach ($Item in @($Entry.TemplateList)) { + $Value = if ($Item.value) { [string]$Item.value } else { [string]$Item } + if ($Value -and ($Value -eq $Id -or $Value -like "$Id*" -or $Id -like "$Value*")) { + if ($Item.label) { return [string]$Item.label } + } + } + } + return $null + } + $IntuneCapable = Test-CIPPStandardLicense -StandardName 'IntuneTemplate_general' -TenantFilter $TenantFilter -Preset Intune $ConditionalAccessCapable = Test-CIPPStandardLicense -StandardName 'ConditionalAccessTemplate_general' -TenantFilter $TenantFilter -Preset Entra $IntuneTable = Get-CippTable -tablename 'templates' @@ -51,10 +71,12 @@ function Get-CIPPDrift { try { $JSONData = $RawTemplate.JSON | ConvertFrom-Json -Depth 100 -ErrorAction SilentlyContinue $data = $JSONData.RAWJson | ConvertFrom-Json -Depth 100 -ErrorAction SilentlyContinue - $data | Add-Member -NotePropertyName 'displayName' -NotePropertyValue $JSONData.Displayname -Force - $data | Add-Member -NotePropertyName 'description' -NotePropertyValue $JSONData.Description -Force - $data | Add-Member -NotePropertyName 'Type' -NotePropertyValue $JSONData.Type -Force - $data | Add-Member -NotePropertyName 'GUID' -NotePropertyValue $RawTemplate.RowKey -Force + $data | Add-Member -NotePropertyMembers ([ordered]@{ + displayName = $JSONData.Displayname + description = $JSONData.Description + Type = $JSONData.Type + GUID = $RawTemplate.RowKey + }) -Force $IntuneTemplatesByGuid[$RawTemplate.RowKey] = $data # Built-in templates are seeded with RowKey = '.IntuneTemplate.json'; also index # by the bare guid so display-name lookups that extract the guid from a standard key hit @@ -123,13 +145,27 @@ function Get-CIPPDrift { $DriftTable = Get-CippTable -tablename 'tenantDrift' $DriftFilter = "PartitionKey eq '$TenantFilter'" $ExistingDriftStates = @{} + # Set only once every decided status has been read. Without them every deviation looks + # New, and writing or pruning on that view would replace accepted / customer-specific + # decisions with New - so both steps below are skipped when the read did not complete. + $DriftStatesLoaded = $false + $DriftEntities = @() try { - $DriftEntities = Get-CIPPAzDataTableEntity @DriftTable -Filter $DriftFilter + $DriftEntities = @(Get-CIPPAzDataTableEntity @DriftTable -Filter $DriftFilter) foreach ($Entity in $DriftEntities) { - $ExistingDriftStates[$Entity.StandardName] = $Entity + $EntityKey = [string]$Entity.StandardName + if ([string]::IsNullOrWhiteSpace($EntityKey)) { + # A row without a name cannot be matched to a deviation. Skipping it is the only + # option that keeps the rest of the table usable - a null hashtable key throws + # and would abandon every row after it. + Write-Warning "Drift state row '$($Entity.RowKey)' for tenant '$TenantFilter' has no StandardName and was ignored." + continue + } + $ExistingDriftStates[$EntityKey] = $Entity } + $DriftStatesLoaded = $true } catch { - Write-Warning "Failed to get existing drift states: $($_.Exception.Message)" + Write-Warning "Failed to get existing drift states for '$TenantFilter': $($_.Exception.Message). Drift decisions will not be written or pruned this run." } $Results = [System.Collections.Generic.List[object]]::new() @@ -197,6 +233,17 @@ function Get-CIPPDrift { $displayName = "Quarantine Policy: $(-join $Chars)" } } + # When the template row is gone (or its GUID column drifted from the RowKey) the + # lookups above find nothing. Fall back to the label the standards template still + # carries, so the deviation names the template to fix instead of showing a bare id. + if (-not $displayName) { + $FallbackLabel = Get-DriftTemplateLabel -StandardName $ComparisonItem.StandardName -StandardSettings $Alignment.standardSettings + if ($FallbackLabel) { $displayName = $FallbackLabel } + } + if ($ComparisonItem.PSObject.Properties['TemplateMissing'] -and $ComparisonItem.TemplateMissing) { + $displayName = "Missing template - $($displayName ?? $ComparisonItem.StandardName)" + $standardDescription = [string]$ComparisonItem.StandardValue + } $reason = if ($ExistingDriftStates.ContainsKey($ComparisonItem.StandardName)) { $ExistingDriftStates[$ComparisonItem.StandardName].Reason } $User = if ($ExistingDriftStates.ContainsKey($ComparisonItem.StandardName)) { $ExistingDriftStates[$ComparisonItem.StandardName].User } $IsLicenseMissing = $ComparisonItem.ComplianceStatus -eq 'License Missing' @@ -292,8 +339,14 @@ function Get-CIPPDrift { # Graph $batch returns 200 even when individual sub-requests fail (e.g. 429 # throttling on one endpoint), silently dropping that policy type from the # collection - which must not count as evidence the policies are gone, or their - # drift rows get pruned and decided statuses reset to New. - $IntunePoliciesCollected = @($IntuneGraphRequest | Where-Object { $_.status -and [int]$_.status -ge 400 }).Count -eq 0 + # drift rows get pruned and decided statuses reset to New. The same applies when + # a collection paged and a later page failed: New-GraphBulkRequest flags that on + # the item as PagingIncomplete while the status stays 200. + $IncompleteIntune = @($IntuneGraphRequest | Where-Object { ($_.status -and [int]$_.status -ge 400) -or $_.PagingIncomplete }) + $IntunePoliciesCollected = $IncompleteIntune.Count -eq 0 + if (-not $IntunePoliciesCollected) { + Write-Warning "Intune policy inventory for '$TenantFilter' is incomplete this run ($(($IncompleteIntune | ForEach-Object { "$($_.id): $($_.PagingError ?? $_.status)" }) -join '; ')). Policy drift rows will not be pruned." + } } catch { Write-Warning "Failed to get Intune policies: $($_.Exception.Message)" } @@ -310,9 +363,13 @@ function Get-CIPPDrift { ) $CAGraphRequest = New-GraphBulkRequest -Requests $CARequests -tenantid $TenantFilter -asapp $true $TenantCAPolicies = ($CAGraphRequest | Where-Object { $_.id -eq 'policies' }).body.value - # Same per-item check as the Intune collection: a throttled $batch item returns - # inside a 200 response and must not arm the prune. - $CAPoliciesCollected = @($CAGraphRequest | Where-Object { $_.status -and [int]$_.status -ge 400 }).Count -eq 0 + # Same per-item check as the Intune collection: a throttled $batch item or a + # failed continuation page returns inside a 200 response and must not arm the prune. + $IncompleteCA = @($CAGraphRequest | Where-Object { ($_.status -and [int]$_.status -ge 400) -or $_.PagingIncomplete }) + $CAPoliciesCollected = $IncompleteCA.Count -eq 0 + if (-not $CAPoliciesCollected) { + Write-Warning "Conditional Access policy inventory for '$TenantFilter' is incomplete this run ($(($IncompleteCA | ForEach-Object { "$($_.id): $($_.PagingError ?? $_.status)" }) -join '; ')). Policy drift rows will not be pruned." + } } catch { Write-Warning "Failed to get Conditional Access policies: $($_.Exception.Message)" $TenantCAPolicies = @() @@ -517,12 +574,14 @@ function Get-CIPPDrift { }) } } - if ($NewDriftEntities.Count -gt 0) { + if ($NewDriftEntities.Count -gt 0 -and $DriftStatesLoaded) { try { Add-CIPPAzDataTableEntity @DriftTable -Entity $NewDriftEntities -Force } catch { Write-Warning "Failed to persist new drift deviations: $($_.Exception.Message)" } + } elseif ($NewDriftEntities.Count -gt 0) { + Write-Warning "Skipped writing $($NewDriftEntities.Count) drift deviation rows for '$TenantFilter' because the existing drift states could not be read." } # License-missing standards are excluded from the deviation buckets so the counts match @@ -572,8 +631,9 @@ function Get-CIPPDrift { # are invisible to the score once their key leaves ComparisonDetails, so only undecided rows # ('New' or missing Status) are pruned there: Accepted/Denied*/CustomerSpecific decisions must # survive transient key-enumeration drops (package/tag membership changes, template - # re-saves). A template-scoped run cannot see every valid key, so it never prunes. - if (-not $TemplateId) { + # re-saves). A template-scoped run cannot see every valid key, so it never prunes, and + # neither does a run whose read of the existing states did not complete. + if (-not $TemplateId -and $DriftStatesLoaded) { $StaleDriftEntities = foreach ($Entity in $DriftEntities) { $EntityName = [string]$Entity.StandardName if ([string]::IsNullOrWhiteSpace($EntityName) -or $ValidDriftKeys.Contains($EntityName)) { continue } diff --git a/Modules/CIPPCore/Public/Get-CIPPDriveItemCloudPathLength.ps1 b/Modules/CIPPCore/Public/Get-CIPPDriveItemCloudPathLength.ps1 new file mode 100644 index 0000000000000..583e9f5337321 --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPDriveItemCloudPathLength.ps1 @@ -0,0 +1,62 @@ +function Get-CIPPDriveItemCloudPathLength { + <# + .SYNOPSIS + Returns the decoded library-relative path length for a Graph drive item. + + .DESCRIPTION + Builds path from parentReference.path + name. Strips the Graph "/.../root:" prefix, + URL-decodes, and returns character length only — never the path string to callers + that might persist it. Used for OneDrive long-path counting. + + .PARAMETER ParentPath + driveItem.parentReference.path (e.g. /drives/{id}/root:/Folder/Sub) + + .PARAMETER Name + driveItem.name + + .OUTPUTS + System.Int32 + #> + [CmdletBinding()] + [OutputType([int])] + param( + [Parameter(Mandatory = $false)] + [AllowEmptyString()] + [AllowNull()] + [string]$ParentPath, + + [Parameter(Mandatory = $false)] + [AllowEmptyString()] + [AllowNull()] + [string]$Name + ) + + if ([string]::IsNullOrWhiteSpace($Name)) { + return 0 + } + + $Relative = '' + if (-not [string]::IsNullOrWhiteSpace($ParentPath)) { + $Marker = 'root:' + $Idx = $ParentPath.IndexOf($Marker, [System.StringComparison]::OrdinalIgnoreCase) + if ($Idx -ge 0) { + $Relative = $ParentPath.Substring($Idx + $Marker.Length) + } + } + + if ([string]::IsNullOrWhiteSpace($Relative) -or $Relative -eq '/') { + $Combined = $Name + } else { + $Combined = $Relative.TrimEnd('/') + '/' + $Name + } + + $Combined = $Combined.TrimStart('/') + + try { + $Decoded = [uri]::UnescapeDataString($Combined) + } catch { + $Decoded = $Combined + } + + return $Decoded.Length +} diff --git a/Modules/CIPPCore/Public/Get-CIPPEdgeAppBody.ps1 b/Modules/CIPPCore/Public/Get-CIPPEdgeAppBody.ps1 new file mode 100644 index 0000000000000..8c2c8d6bd8d5d --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPEdgeAppBody.ps1 @@ -0,0 +1,52 @@ +function Get-CIPPEdgeAppBody { + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + $Config + ) + + if ($Config.IntuneBody) { + $IntuneBody = $Config.IntuneBody + if ($IntuneBody -is [string]) { + $IntuneBody = $IntuneBody | ConvertFrom-Json -Depth 100 + } else { + $IntuneBody = $IntuneBody | ConvertTo-Json -Depth 100 | ConvertFrom-Json -Depth 100 + } + + $ReadOnlyProps = @( + 'id', 'createdDateTime', 'lastModifiedDateTime', 'uploadState', 'publishingState', + 'isAssigned', 'roleScopeTagIds', 'dependentAppCount', 'supersedingAppCount', + 'supersededAppCount', 'committedContentVersion', 'fileName', 'size', + 'assignments@odata.context', 'assignments', 'AppAssignment', 'AppExclude' + ) + foreach ($Prop in $ReadOnlyProps) { + if ($IntuneBody.PSObject.Properties[$Prop]) { + $IntuneBody.PSObject.Properties.Remove($Prop) + } + } + return $IntuneBody + } + + $Channel = if ($Config.edgeChannel.value) { $Config.edgeChannel.value } else { $Config.edgeChannel } + if (-not $Channel) { $Channel = 'stable' } + + $Body = [PSCustomObject]@{ + '@odata.type' = '#microsoft.graph.windowsMicrosoftEdgeApp' + 'displayName' = 'Microsoft Edge for Windows 10 and later' + 'description' = 'Microsoft Edge for Windows 10 and later' + 'publisher' = 'Microsoft' + 'isFeatured' = $false + 'informationUrl' = 'https://www.microsoft.com/edge' + 'privacyInformationUrl' = 'https://privacy.microsoft.com/en-us/privacystatement' + 'owner' = 'Microsoft' + 'notes' = '' + 'channel' = $Channel + } + + $Locale = if ($Config.displayLanguageLocale.value) { $Config.displayLanguageLocale.value } else { $Config.displayLanguageLocale } + if ($Locale) { + $Body | Add-Member -NotePropertyName 'displayLanguageLocale' -NotePropertyValue $Locale + } + + return $Body +} diff --git a/Modules/CIPPCore/Public/Get-CIPPGroupUsageReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPGroupUsageReport.ps1 new file mode 100644 index 0000000000000..f948ac7b8f5d9 --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPGroupUsageReport.ps1 @@ -0,0 +1,234 @@ +function Get-CIPPGroupUsageReport { + <# + .SYNOPSIS + Compiles where each Entra group is used across the tenant from the CIPP Reporting database + + .DESCRIPTION + Reads the cached Groups, Conditional Access, Intune, role, application, license and + Exchange datasets from CippReportingDB and builds one row per group listing every + location that references it. No live Graph calls are made. + + .PARAMETER TenantFilter + The tenant to generate the report for, or 'AllTenants' for all tenants + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter + ) + + if ($TenantFilter -eq 'AllTenants') { + $AnyItems = Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'Groups' + $Tenants = @($AnyItems | Where-Object { $_.RowKey -notlike '*-Count' } | Select-Object -ExpandProperty PartitionKey -Unique) + $TenantList = Get-Tenants -IncludeErrors + $Tenants = $Tenants | Where-Object { $TenantList.defaultDomainName -contains $_ } + + $AllResults = [System.Collections.Generic.List[PSCustomObject]]::new() + foreach ($Tenant in $Tenants) { + try { + $TenantResults = Get-CIPPGroupUsageReport -TenantFilter $Tenant + foreach ($Result in $TenantResults) { + $Result | Add-Member -NotePropertyName 'Tenant' -NotePropertyValue $Tenant -Force + $AllResults.Add($Result) + } + } catch { + Write-LogMessage -API 'GroupUsageReport' -tenant $Tenant -message "Failed to get group usage report: $($_.Exception.Message)" -sev Warning + } + } + return $AllResults + } + + $GroupItems = Get-CIPPDbItem -TenantFilter $TenantFilter -Type 'Groups' | Where-Object { $_.RowKey -notlike '*-Count' } + if (-not $GroupItems) { + throw "No groups data found in reporting database for $TenantFilter. Sync the report data first." + } + $CacheTimestamp = ($GroupItems | Where-Object { $_.Timestamp } | Sort-Object Timestamp -Descending | Select-Object -First 1).Timestamp + + $Groups = [System.Collections.Generic.List[PSCustomObject]]::new() + foreach ($Item in $GroupItems) { + try { + $Groups.Add(($Item.Data | ConvertFrom-Json -Depth 20 -ErrorAction Stop)) + } catch { + Write-LogMessage -API 'GroupUsageReport' -tenant $TenantFilter -message "Failed to parse group item: $($_.Exception.Message)" -sev Warning + } + } + + # Index groups by id and by mail (transport rules reference groups by SMTP address) + $GroupIndex = @{} + $MailIndex = @{} + foreach ($Group in $Groups) { + if (-not $Group.id) { continue } + $GroupIndex[[string]$Group.id] = $Group + if (-not [string]::IsNullOrWhiteSpace($Group.mail)) { + $MailIndex[([string]$Group.mail).ToLowerInvariant()] = [string]$Group.id + } + } + + $UsageByGroup = @{} + $SeenUsageKeys = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + $AddUsage = { + param($GroupId, $Category, $Location, $Name, $Id) + $GroupKey = [string]$GroupId + if ([string]::IsNullOrWhiteSpace($GroupKey) -or -not $GroupIndex.ContainsKey($GroupKey)) { return } + $DedupeKey = '{0}|{1}|{2}' -f $GroupKey, $Location, [string]$Id + if (-not $SeenUsageKeys.Add($DedupeKey)) { return } + if (-not $UsageByGroup.ContainsKey($GroupKey)) { + $UsageByGroup[$GroupKey] = [System.Collections.Generic.List[PSCustomObject]]::new() + } + $UsageByGroup[$GroupKey].Add([PSCustomObject]@{ + Category = $Category + Location = $Location + Name = [string]$Name + Id = [string]$Id + }) + } + + $ReadCache = { + param($Type) + try { @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type $Type -ErrorAction Stop) } catch { @() } + } + + # Conditional Access — raw policies carry group GUIDs in the user conditions + foreach ($Policy in (& $ReadCache 'ConditionalAccessPolicies')) { + foreach ($GroupId in @($Policy.conditions.users.includeGroups)) { + & $AddUsage $GroupId 'Conditional Access' 'Conditional Access' $Policy.displayName $Policy.id + } + foreach ($GroupId in @($Policy.conditions.users.excludeGroups)) { + & $AddUsage $GroupId 'Conditional Access' 'Conditional Access (Excluded)' $Policy.displayName $Policy.id + } + } + + # Intune — every cached family stores its Graph assignments verbatim + $IntuneCacheTypes = [ordered]@{ + IntuneDeviceConfigurations = 'Intune Configuration Profile' + IntuneConfigurationPolicies = 'Intune Settings Catalog Policy' + IntuneDeviceCompliancePolicies = 'Intune Compliance Policy' + IntuneGroupPolicyConfigurations = 'Intune Administrative Template' + IntuneMobileAppConfigurations = 'Intune App Configuration Policy' + IntuneWindowsDriverUpdateProfiles = 'Intune Driver Update Profile' + IntuneWindowsFeatureUpdateProfiles = 'Intune Feature Update Profile' + IntuneWindowsQualityUpdatePolicies = 'Intune Quality Update Policy' + IntuneWindowsQualityUpdateProfiles = 'Intune Quality Update Profile' + IntuneHardwareConfigurations = 'Intune Hardware Configuration' + IntuneIntents = 'Intune Endpoint Security Policy' + IntuneAppProtectionPolicies = 'Intune App Protection Policy' + IntuneAppProtectionManagedAppPolicies = 'Intune App Protection Policy' + IntuneApplications = 'Intune Application' + IntuneWindowsScripts = 'Intune Platform Script' + IntuneMacOSScripts = 'Intune Platform Script' + IntuneLinuxScripts = 'Intune Platform Script' + IntuneRemediationScripts = 'Intune Remediation Script' + IntuneWindowsAutopilotDeploymentProfiles = 'Autopilot Deployment Profile' + IntuneDeviceEnrollmentConfigurations = 'Intune Enrollment Configuration' + } + foreach ($CacheType in $IntuneCacheTypes.Keys) { + foreach ($Policy in (& $ReadCache $CacheType)) { + $PolicyName = $Policy.displayName ?? $Policy.name + foreach ($Assignment in @($Policy.assignments)) { + $GroupId = [string]$Assignment.target.groupId + if ([string]::IsNullOrWhiteSpace($GroupId)) { continue } + $Label = $IntuneCacheTypes[$CacheType] + if ($Assignment.target.'@odata.type' -eq '#microsoft.graph.exclusionGroupAssignmentTarget') { + $Label = "$Label (Excluded)" + } + & $AddUsage $GroupId 'Intune' $Label $PolicyName $Policy.id + } + } + } + + # Group-based licensing, Teams, and nested group membership — all from the Groups cache itself + $SkuNames = @{} + foreach ($Sku in (& $ReadCache 'LicenseOverview')) { + if (-not [string]::IsNullOrWhiteSpace($Sku.skuId)) { + $SkuNames[([string]$Sku.skuId).ToLowerInvariant()] = $Sku.License + } + } + foreach ($Group in $Groups) { + foreach ($License in @($Group.assignedLicenses)) { + if ([string]::IsNullOrWhiteSpace($License.skuId)) { continue } + $LicenseName = $SkuNames[([string]$License.skuId).ToLowerInvariant()] ?? [string]$License.skuId + & $AddUsage $Group.id 'Licensing' 'Group-Based Licensing' $LicenseName $License.skuId + } + if ($Group.teamsEnabled -eq $true) { + & $AddUsage $Group.id 'Teams' 'Microsoft Teams' $Group.displayName $Group.id + } + foreach ($Member in @($Group.members)) { + if ($Member.'@odata.type' -eq '#microsoft.graph.group' -and $Member.id) { + & $AddUsage $Member.id 'Group Nesting' 'Member of Group' $Group.displayName $Group.id + } + } + } + + # Entra directory roles + PIM assignments/eligibilities + $RoleNamesByTemplate = @{} + foreach ($Role in (& $ReadCache 'Roles')) { + if ($Role.roleTemplateId) { $RoleNamesByTemplate[[string]$Role.roleTemplateId] = $Role.displayName } + foreach ($Member in @($Role.members)) { + if ($Member.id -and $GroupIndex.ContainsKey([string]$Member.id)) { + & $AddUsage $Member.id 'Entra Roles' 'Entra Role' $Role.displayName $Role.id + } + } + } + $PimSources = @( + [PSCustomObject]@{ Type = 'RoleAssignmentScheduleInstances'; Location = 'PIM Role Assignment' } + [PSCustomObject]@{ Type = 'RoleEligibilitySchedules'; Location = 'PIM Role Eligibility' } + ) + foreach ($Source in $PimSources) { + foreach ($Schedule in (& $ReadCache $Source.Type)) { + $PrincipalId = [string]$Schedule.principalId + if (-not $GroupIndex.ContainsKey($PrincipalId)) { continue } + $RoleName = $RoleNamesByTemplate[[string]$Schedule.roleDefinitionId] ?? [string]$Schedule.roleDefinitionId + & $AddUsage $PrincipalId 'Entra Roles' $Source.Location $RoleName $Schedule.roleDefinitionId + } + } + + # Enterprise application assignments granted to groups + foreach ($Assignment in (& $ReadCache 'AppRoleAssignments')) { + if ([string]$Assignment.principalType -ne 'Group') { continue } + $AppName = $Assignment.resourceDisplayName ?? $Assignment.servicePrincipalDisplayName + & $AddUsage $Assignment.principalId 'Enterprise Applications' 'Enterprise Application' $AppName $Assignment.resourceId + } + + # Exchange transport rules reference groups by SMTP address + foreach ($Rule in (& $ReadCache 'ExoTransportRules')) { + $RuleName = $Rule.Name ?? $Rule.Identity + $RuleId = $Rule.Guid ?? $Rule.Identity + foreach ($Property in @('SentToMemberOf', 'FromMemberOf', 'ExceptIfSentToMemberOf', 'ExceptIfFromMemberOf')) { + foreach ($Address in @($Rule.$Property)) { + if ([string]::IsNullOrWhiteSpace($Address)) { continue } + $GroupId = $MailIndex[([string]$Address).ToLowerInvariant()] + if ($GroupId) { + & $AddUsage $GroupId 'Exchange' 'Exchange Transport Rule' $RuleName $RuleId + } + } + } + } + + $Results = [System.Collections.Generic.List[PSCustomObject]]::new() + foreach ($Group in $Groups) { + if (-not $Group.id) { continue } + $GroupKey = [string]$Group.id + $UsedIn = [System.Collections.Generic.List[string]]::new() + $Categories = [System.Collections.Generic.SortedSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + if ($UsageByGroup.ContainsKey($GroupKey)) { + foreach ($Usage in ($UsageByGroup[$GroupKey] | Sort-Object -Property Location, Name)) { + $UsedIn.Add(('{0} - {1} ({2})' -f $Usage.Location, $Usage.Name, $Usage.Id)) + [void]$Categories.Add($Usage.Category) + } + } + $Results.Add([PSCustomObject]@{ + id = $GroupKey + displayName = $Group.displayName + groupType = $Group.groupType + mail = $Group.mail + dynamicGroup = [bool]$Group.dynamicGroupBool + usedLocations = @($Categories) + usedIn = @($UsedIn) + usageCount = $UsedIn.Count + isUsed = ($UsedIn.Count -gt 0) + CacheTimestamp = $CacheTimestamp + }) + } + + return ($Results | Sort-Object displayName) +} diff --git a/Modules/CIPPCore/Public/Get-CIPPGroupsReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPGroupsReport.ps1 index d553268202555..5c6c046f39e2f 100644 --- a/Modules/CIPPCore/Public/Get-CIPPGroupsReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPGroupsReport.ps1 @@ -5,13 +5,93 @@ function Get-CIPPGroupsReport { .PARAMETER TenantFilter The tenant to generate the report for, or 'AllTenants' for all tenants + + .PARAMETER PageSize + When set, returns one page of at most this many rows as @{ Items; NextToken }, in table walk order. + + .PARAMETER ContinuationToken + NextToken from the previous page. Only meaningful together with PageSize. #> [CmdletBinding()] param( [Parameter(Mandatory = $true)] - [string]$TenantFilter + [string]$TenantFilter, + [int]$PageSize, + [string]$ContinuationToken, + # Return one page as { CippPagedJson; NextToken }: the stored blobs stitched into a + # JSON array verbatim, with per-row CacheTimestamp/Tenant spliced in. No member array + # is ever deserialized on the read path. + [switch]$AsRawJson ) + if ($PageSize -gt 0) { + $Page = Get-CIPPDbItemPage -TenantFilter $TenantFilter -Type 'Groups' -PageSize $PageSize -ContinuationToken $ContinuationToken + if ($TenantFilter -ne 'AllTenants' -and -not $ContinuationToken -and @($Page.Items).Count -eq 0 -and -not $Page.NextToken) { + throw "No groups data found in reporting database for $TenantFilter. Sync the report data first." + } + + if ($AsRawJson) { + $IsAllTenants = $TenantFilter -eq 'AllTenants' + $Builder = [System.Text.StringBuilder]::new() + $null = $Builder.Append('[') + $First = $true + foreach ($Item in $Page.Items) { + $Blob = [string]$Item.Data + if ([string]::IsNullOrWhiteSpace($Blob)) { continue } + $Blob = $Blob.Trim() + if ($Blob[0] -ne '{') { continue } + if (-not $First) { $null = $Builder.Append(',') } + $First = $false + # Emit the blob verbatim, then splice the two row-level fields onto its closing + # brace. membersCsv/ownersCsv already live in the blob (written at cache time). + $null = $Builder.Append($Blob, 0, $Blob.Length - 1) + $null = $Builder.Append(',"CacheTimestamp":').Append((ConvertTo-Json -InputObject $Item.Timestamp -Compress)) + if ($IsAllTenants) { + $null = $Builder.Append(',"Tenant":').Append((ConvertTo-Json -InputObject ([string]$Item.PartitionKey) -Compress)) + } + $null = $Builder.Append('}') + } + $null = $Builder.Append(']') + return [PSCustomObject]@{ + CippPagedJson = $Builder.ToString() + NextToken = $Page.NextToken + } + } + + $Results = [System.Collections.Generic.List[PSCustomObject]]::new() + foreach ($Item in $Page.Items) { + try { + $Group = $Item.Data | ConvertFrom-Json -Depth 10 -ErrorAction Stop + # Collect every note property once, then attach in a single Add-Member call. + $NewProps = [ordered]@{} + if ($Group.members -and -not $Group.membersCsv) { + $NewProps['membersCsv'] = $Group.members.userPrincipalName -join ',' + } + if ($Group.owners -and -not $Group.ownersCsv) { + $NewProps['ownersCsv'] = $Group.owners.userPrincipalName -join ',' + } + if ($null -eq $Group.hasOwner) { + # Use the freshly computed ownersCsv if we just built one, else the stored value. + $OwnersCsv = if ($NewProps.Contains('ownersCsv')) { $NewProps['ownersCsv'] } else { $Group.ownersCsv } + $NewProps['hasOwner'] = -not [string]::IsNullOrEmpty($OwnersCsv) + } + # Per-item timestamp: a page may span tenants. + $NewProps['CacheTimestamp'] = $Item.Timestamp + if ($TenantFilter -eq 'AllTenants') { + $NewProps['Tenant'] = $Item.PartitionKey + } + $Group | Add-Member -NotePropertyMembers $NewProps -Force + $Results.Add($Group) + } catch { + Write-LogMessage -API 'GroupsReport' -tenant $Item.PartitionKey -message "Failed to parse group item: $($_.Exception.Message)" -sev Warning + } + } + return [PSCustomObject]@{ + Items = $Results + NextToken = $Page.NextToken + } + } + if ($TenantFilter -eq 'AllTenants') { $AnyItems = Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'Groups' $Tenants = @($AnyItems | Where-Object { $_.RowKey -notlike '*-Count' } | Select-Object -ExpandProperty PartitionKey -Unique) @@ -44,13 +124,19 @@ function Get-CIPPGroupsReport { foreach ($Item in $Items) { try { $Group = $Item.Data | ConvertFrom-Json -Depth 10 -ErrorAction Stop + # Collect every note property once, then attach in a single Add-Member call. + $NewProps = [ordered]@{} if ($Group.members -and -not $Group.membersCsv) { - $Group | Add-Member -NotePropertyName 'membersCsv' -NotePropertyValue ($Group.members.userPrincipalName -join ',') -Force + $NewProps['membersCsv'] = $Group.members.userPrincipalName -join ',' } if ($Group.owners -and -not $Group.ownersCsv) { - $Group | Add-Member -NotePropertyName 'ownersCsv' -NotePropertyValue ($Group.owners.userPrincipalName -join ',') -Force + $NewProps['ownersCsv'] = $Group.owners.userPrincipalName -join ',' } - $Group | Add-Member -NotePropertyName 'CacheTimestamp' -NotePropertyValue $CacheTimestamp -Force + # Use the freshly computed ownersCsv if we just built one, else the stored value. + $OwnersCsv = if ($NewProps.Contains('ownersCsv')) { $NewProps['ownersCsv'] } else { $Group.ownersCsv } + $NewProps['hasOwner'] = -not [string]::IsNullOrEmpty($OwnersCsv) + $NewProps['CacheTimestamp'] = $CacheTimestamp + $Group | Add-Member -NotePropertyMembers $NewProps -Force $Results.Add($Group) } catch { Write-LogMessage -API 'GroupsReport' -tenant $TenantFilter -message "Failed to parse group item: $($_.Exception.Message)" -sev Warning diff --git a/Modules/CIPPCore/Public/Get-CIPPGuestUsersReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPGuestUsersReport.ps1 index bab411a0b6a6b..b764bc7afb4a3 100644 --- a/Modules/CIPPCore/Public/Get-CIPPGuestUsersReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPGuestUsersReport.ps1 @@ -10,13 +10,45 @@ function Get-CIPPGuestUsersReport { .PARAMETER TenantFilter The tenant to read cached guest users for, or 'AllTenants' for all tenants + + .PARAMETER PageSize + When set, returns one page of at most this many rows as @{ Items; NextToken }, in table walk order. .PARAMETER ContinuationToken + NextToken from the previous page. Only meaningful together with PageSize. #> [CmdletBinding()] param( [Parameter(Mandatory = $true)] - [string]$TenantFilter + [string]$TenantFilter, + [int]$PageSize, + [string]$ContinuationToken ) + if ($PageSize -gt 0) { + $Page = Get-CIPPDbItemPage -TenantFilter $TenantFilter -Type 'Guests' -PageSize $PageSize -ContinuationToken $ContinuationToken + if ($TenantFilter -ne 'AllTenants' -and -not $ContinuationToken -and @($Page.Items).Count -eq 0 -and -not $Page.NextToken) { + throw "No guest user data found in reporting database for $TenantFilter. Sync the report data first." + } + $Results = [System.Collections.Generic.List[PSCustomObject]]::new() + foreach ($Item in $Page.Items) { + try { + $Guest = $Item.Data | ConvertFrom-Json -Depth 10 -ErrorAction Stop + # Per-item timestamp: a page may span tenants. + $GuestProps = [ordered]@{ CacheTimestamp = $Item.Timestamp } + if ($TenantFilter -eq 'AllTenants') { + $GuestProps['Tenant'] = $Item.PartitionKey + } + $Guest | Add-Member -NotePropertyMembers $GuestProps -Force + $Results.Add($Guest) + } catch { + Write-LogMessage -API 'GuestUsersReport' -tenant $Item.PartitionKey -message "Failed to parse guest user item: $($_.Exception.Message)" -sev Warning + } + } + return [PSCustomObject]@{ + Items = $Results + NextToken = $Page.NextToken + } + } + if ($TenantFilter -eq 'AllTenants') { $AnyItems = Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'Guests' $Tenants = @($AnyItems | Where-Object { $_.RowKey -notlike '*-Count' } | Select-Object -ExpandProperty PartitionKey -Unique) diff --git a/Modules/CIPPCore/Public/Get-CIPPIntuneAppProtectionPolicyReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPIntuneAppProtectionPolicyReport.ps1 index 46483af66431f..7c6840a265b67 100644 --- a/Modules/CIPPCore/Public/Get-CIPPIntuneAppProtectionPolicyReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPIntuneAppProtectionPolicyReport.ps1 @@ -91,11 +91,13 @@ function Get-CIPPIntuneAppProtectionPolicyReport { } } - $Policy | Add-Member -NotePropertyName 'PolicyTypeName' -NotePropertyValue $policyType -Force - $Policy | Add-Member -NotePropertyName 'PolicySource' -NotePropertyValue 'AppProtection' -Force - $Policy | Add-Member -NotePropertyName 'PolicyAssignment' -NotePropertyValue ($PolicyAssignment -join ', ') -Force - $Policy | Add-Member -NotePropertyName 'PolicyExclude' -NotePropertyValue ($PolicyExclude -join ', ') -Force - $Policy | Add-Member -NotePropertyName 'CacheTimestamp' -NotePropertyValue $CacheTimestamp -Force + $Policy | Add-Member -NotePropertyMembers ([ordered]@{ + PolicyTypeName = $policyType + PolicySource = 'AppProtection' + PolicyAssignment = ($PolicyAssignment -join ', ') + PolicyExclude = ($PolicyExclude -join ', ') + CacheTimestamp = $CacheTimestamp + }) -Force $Results.Add($Policy) } @@ -130,15 +132,18 @@ function Get-CIPPIntuneAppProtectionPolicyReport { } } - $Config | Add-Member -NotePropertyName 'PolicyTypeName' -NotePropertyValue $policyType -Force - $Config | Add-Member -NotePropertyName 'URLName' -NotePropertyValue 'mobileAppConfigurations' -Force - $Config | Add-Member -NotePropertyName 'PolicySource' -NotePropertyValue 'AppConfiguration' -Force - $Config | Add-Member -NotePropertyName 'PolicyAssignment' -NotePropertyValue ($PolicyAssignment -join ', ') -Force - $Config | Add-Member -NotePropertyName 'PolicyExclude' -NotePropertyValue ($PolicyExclude -join ', ') -Force + $ConfigProps = [ordered]@{ + PolicyTypeName = $policyType + URLName = 'mobileAppConfigurations' + PolicySource = 'AppConfiguration' + PolicyAssignment = ($PolicyAssignment -join ', ') + PolicyExclude = ($PolicyExclude -join ', ') + } if (-not $Config.PSObject.Properties['isAssigned']) { - $Config | Add-Member -NotePropertyName 'isAssigned' -NotePropertyValue $false -Force + $ConfigProps['isAssigned'] = $false } - $Config | Add-Member -NotePropertyName 'CacheTimestamp' -NotePropertyValue $CacheTimestamp -Force + $ConfigProps['CacheTimestamp'] = $CacheTimestamp + $Config | Add-Member -NotePropertyMembers $ConfigProps -Force $Results.Add($Config) } diff --git a/Modules/CIPPCore/Public/Get-CIPPIntuneApplicationReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPIntuneApplicationReport.ps1 index d6f53a245e65e..84f281656b4eb 100644 --- a/Modules/CIPPCore/Public/Get-CIPPIntuneApplicationReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPIntuneApplicationReport.ps1 @@ -71,9 +71,11 @@ function Get-CIPPIntuneApplicationReport { } } - $App | Add-Member -NotePropertyName 'AppAssignment' -NotePropertyValue ($AppAssignment -join ', ') -Force - $App | Add-Member -NotePropertyName 'AppExclude' -NotePropertyValue ($AppExclude -join ', ') -Force - $App | Add-Member -NotePropertyName 'CacheTimestamp' -NotePropertyValue $CacheTimestamp -Force + $App | Add-Member -NotePropertyMembers ([ordered]@{ + AppAssignment = ($AppAssignment -join ', ') + AppExclude = ($AppExclude -join ', ') + CacheTimestamp = $CacheTimestamp + }) -Force $Results.Add($App) } diff --git a/Modules/CIPPCore/Public/Get-CIPPIntuneCompareExclusions.ps1 b/Modules/CIPPCore/Public/Get-CIPPIntuneCompareExclusions.ps1 index f1a30d479507f..81fa4355a4bd3 100644 --- a/Modules/CIPPCore/Public/Get-CIPPIntuneCompareExclusions.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPIntuneCompareExclusions.ps1 @@ -45,7 +45,11 @@ function Get-CIPPIntuneCompareExclusions { 'templateId', 'source', 'package', - 'assignments' + 'assignments', + # App configuration policies name their apps by mobileApp id, which differs per tenant by + # construction; the app identity captured next to it is deployment metadata, not policy. + 'targetedMobileApps', + 'targetedMobileAppsDetails' ) if ($AppProtection) { $Exclusions = $Exclusions + @('apps', 'deployedAppCount', 'isAssigned') diff --git a/Modules/CIPPCore/Public/Get-CIPPIntuneCompliancePolicyReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPIntuneCompliancePolicyReport.ps1 index 70c70cbd75bff..31d16fb27d413 100644 --- a/Modules/CIPPCore/Public/Get-CIPPIntuneCompliancePolicyReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPIntuneCompliancePolicyReport.ps1 @@ -81,10 +81,12 @@ function Get-CIPPIntuneCompliancePolicyReport { } } - $Policy | Add-Member -NotePropertyName 'PolicyTypeName' -NotePropertyValue $policyType -Force - $Policy | Add-Member -NotePropertyName 'PolicyAssignment' -NotePropertyValue ($PolicyAssignment -join ', ') -Force - $Policy | Add-Member -NotePropertyName 'PolicyExclude' -NotePropertyValue ($PolicyExclude -join ', ') -Force - $Policy | Add-Member -NotePropertyName 'CacheTimestamp' -NotePropertyValue $CacheTimestamp -Force + $Policy | Add-Member -NotePropertyMembers ([ordered]@{ + PolicyTypeName = $policyType + PolicyAssignment = ($PolicyAssignment -join ', ') + PolicyExclude = ($PolicyExclude -join ', ') + CacheTimestamp = $CacheTimestamp + }) -Force $Results.Add($Policy) } diff --git a/Modules/CIPPCore/Public/Get-CIPPIntunePolicy.ps1 b/Modules/CIPPCore/Public/Get-CIPPIntunePolicy.ps1 index 039ec90c3353e..565771296eb04 100644 --- a/Modules/CIPPCore/Public/Get-CIPPIntunePolicy.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPIntunePolicy.ps1 @@ -242,6 +242,43 @@ function Get-CIPPIntunePolicy { return $policies } } + 'AppConfiguration' { + # Managed-device app configuration policies. Without this case the IntuneTemplate + # standard could never find a deployed app configuration and reported it missing on + # every run while remediation kept patching the policy that was already there. + $PlatformType = 'deviceAppManagement' + $TemplateTypeURL = 'mobileAppConfigurations' + $ExcludedProperties = @('id', 'createdDateTime', 'lastModifiedDateTime', 'version', '@odata.context') + + if ($DisplayName) { + $policies = New-GraphGETRequest -uri "https://graph.microsoft.com/beta/$PlatformType/$TemplateTypeURL" -tenantid $tenantFilter + $policy = $policies | Where-Object -Property displayName -EQ $DisplayName | Sort-Object -Property lastModifiedDateTime -Descending | Select-Object -First 1 + if ($policy) { + $policyDetails = New-GraphGETRequest -uri "https://graph.microsoft.com/beta/$PlatformType/$TemplateTypeURL('$($policy.id)')" -tenantid $tenantFilter + $policyDetails = $policyDetails | Select-Object * -ExcludeProperty $ExcludedProperties + $policyJson = ConvertTo-Json -InputObject $policyDetails -Depth 100 -Compress + $policy | Add-Member -MemberType NoteProperty -Name 'cippconfiguration' -Value $policyJson -Force + } + return $policy + } elseif ($PolicyId) { + $policy = New-GraphGETRequest -uri "https://graph.microsoft.com/beta/$PlatformType/$TemplateTypeURL('$PolicyId')" -tenantid $tenantFilter + if ($policy) { + $policyDetails = $policy | Select-Object * -ExcludeProperty $ExcludedProperties + $policyJson = ConvertTo-Json -InputObject $policyDetails -Depth 100 -Compress + $policy | Add-Member -MemberType NoteProperty -Name 'cippconfiguration' -Value $policyJson -Force + } + return $policy + } else { + $policies = New-GraphGETRequest -uri "https://graph.microsoft.com/beta/$PlatformType/$TemplateTypeURL" -tenantid $tenantFilter + foreach ($policy in $policies) { + $policyDetails = New-GraphGETRequest -uri "https://graph.microsoft.com/beta/$PlatformType/$TemplateTypeURL('$($policy.id)')" -tenantid $tenantFilter + $policyDetails = $policyDetails | Select-Object * -ExcludeProperty $ExcludedProperties + $policyJson = ConvertTo-Json -InputObject $policyDetails -Depth 100 -Compress + $policy | Add-Member -MemberType NoteProperty -Name 'cippconfiguration' -Value $policyJson -Force + } + return $policies + } + } 'Device' { $PlatformType = 'deviceManagement' $TemplateTypeURL = 'deviceConfigurations' diff --git a/Modules/CIPPCore/Public/Get-CIPPIntuneReusableSettingsReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPIntuneReusableSettingsReport.ps1 index 61b64e3d257f4..6fa4bbaac5198 100644 --- a/Modules/CIPPCore/Public/Get-CIPPIntuneReusableSettingsReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPIntuneReusableSettingsReport.ps1 @@ -46,8 +46,10 @@ function Get-CIPPIntuneReusableSettingsReport { $rawJson = $null } - $Setting | Add-Member -NotePropertyName 'RawJSON' -NotePropertyValue $rawJson -Force - $Setting | Add-Member -NotePropertyName 'CacheTimestamp' -NotePropertyValue $CacheTimestamp -Force + $Setting | Add-Member -NotePropertyMembers ([ordered]@{ + RawJSON = $rawJson + CacheTimestamp = $CacheTimestamp + }) -Force $Results.Add($Setting) } diff --git a/Modules/CIPPCore/Public/Get-CIPPIntuneScriptReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPIntuneScriptReport.ps1 index 9a57ab372595c..dadd504daa89d 100644 --- a/Modules/CIPPCore/Public/Get-CIPPIntuneScriptReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPIntuneScriptReport.ps1 @@ -93,10 +93,12 @@ function Get-CIPPIntuneScriptReport { } } - $script | Add-Member -NotePropertyName 'ScriptAssignment' -NotePropertyValue ($ScriptAssignment -join ', ') -Force - $script | Add-Member -NotePropertyName 'ScriptExclude' -NotePropertyValue ($ScriptExclude -join ', ') -Force - $script | Add-Member -MemberType NoteProperty -Name scriptType -Value $scriptId -Force - $script | Add-Member -NotePropertyName 'CacheTimestamp' -NotePropertyValue $CacheTimestamp -Force + $script | Add-Member -NotePropertyMembers ([ordered]@{ + ScriptAssignment = ($ScriptAssignment -join ', ') + ScriptExclude = ($ScriptExclude -join ', ') + scriptType = $scriptId + CacheTimestamp = $CacheTimestamp + }) -Force $Results.Add($script) } } diff --git a/Modules/CIPPCore/Public/Get-CIPPJITAdminAllowedRoles.ps1 b/Modules/CIPPCore/Public/Get-CIPPJITAdminAllowedRoles.ps1 new file mode 100644 index 0000000000000..8f646b2b91ac7 --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPJITAdminAllowedRoles.ps1 @@ -0,0 +1,148 @@ +function Get-CIPPJITAdminAllowedRoles { + <# + .SYNOPSIS + Resolve which directory roles the calling user is permitted to assign via JIT Admin. + + .DESCRIPTION + JIT Role Templates are named allow-lists of Entra directory roles that can be attached to a + CIPP custom role (via the AllowedRolesTemplate property on the CustomRoles row). This function + resolves the calling user's roles and returns the effective allow-list. + + Restrictive semantics, matching how CIPP combines multiple custom roles everywhere else + ("assigning multiple custom roles is restrictive and not additive"): + - Base roles (superadmin/admin/editor/readonly) do not carry templates. admin/superadmin are + unaffected by custom roles and are always unrestricted. + - A custom role with NO template contributes "all roles" (the universal set), so it never + loosens the result - but on its own it does not restrict. + - If the caller holds AT LEAST ONE templated custom role they are restricted, and the allow-list + is the INTERSECTION of the templated roles' sets. An untemplated custom role therefore cannot + be used to bypass a template held alongside it. + - If NO custom role carries a template, the caller is unrestricted, so deployments with no + templates assigned anywhere are undisturbed. + + Fails closed for restricted callers: a template (or role row) that cannot be read contributes an + empty set to the intersection rather than opening access, so a lookup failure cannot escalate. + + .PARAMETER Headers + The request headers (containing x-ms-client-principal) used to resolve the caller. + + .OUTPUTS + PSCustomObject with: + Restricted [bool] - $true when the allow-list should be enforced. + AllowedRoleIds [string[]] - directory role template IDs the caller may assign (only meaningful when Restricted). + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + $Headers + ) + + $Unrestricted = [PSCustomObject]@{ Restricted = $false; AllowedRoleIds = @() } + + # Resolve the calling user's roles, including Entra group-based roles (mirrors Invoke-ExecRestoreBackup) + try { + $CallingUser = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($Headers.'x-ms-client-principal')) | ConvertFrom-Json + } catch { + # Without a resolvable principal we cannot determine a custom role, so nothing is restricted. + return $Unrestricted + } + + if (($CallingUser.userRoles | Measure-Object).Count -eq 2 -and $CallingUser.userRoles -contains 'authenticated' -and $CallingUser.userRoles -contains 'anonymous') { + $CallingUser = Test-CIPPAccessUserRole -User $CallingUser + } + + # admin/superadmin are unaffected by custom roles (CIPP convention) -> never restricted. + if ($CallingUser.userRoles -contains 'admin' -or $CallingUser.userRoles -contains 'superadmin') { + return $Unrestricted + } + + $DefaultRoles = @('superadmin', 'admin', 'editor', 'readonly', 'anonymous', 'authenticated') + $CustomRoleNames = @($CallingUser.userRoles | Where-Object { $DefaultRoles -notcontains $_ }) + + # No custom role -> unrestricted (base roles have no template concept). + if ($CustomRoleNames.Count -eq 0) { + return $Unrestricted + } + + $Table = Get-CIPPTable -tablename 'CustomRoles' + $TemplateTable = Get-CIPPTable -tablename 'templates' + + # Each templated custom role contributes one set of allowed role IDs. Untemplated custom roles + # contribute nothing (they represent the universal set and never tighten the intersection). + $TemplatedSets = [System.Collections.Generic.List[object]]::new() + + foreach ($RoleName in $CustomRoleNames) { + try { + $SafeRole = ConvertTo-CIPPODataFilterValue -Value ($RoleName.ToLower()) -Type String + $RoleRow = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'CustomRoles' and RowKey eq '$SafeRole'" + } catch { + Write-Warning "JIT allowed-roles: failed to read custom role '$RoleName': $($_.Exception.Message)" + # Cannot confirm whether this role is templated -> fail closed: contribute an empty set. + $TemplatedSets.Add([string[]]@()) + continue + } + + # A role with no template assigned represents the universal set - skip it (it never restricts). + if (-not $RoleRow -or [string]::IsNullOrWhiteSpace($RoleRow.AllowedRolesTemplate)) { + continue + } + + try { + $TemplateRef = $RoleRow.AllowedRolesTemplate | ConvertFrom-Json -ErrorAction Stop + } catch { + $TemplateRef = $RoleRow.AllowedRolesTemplate + } + $TemplateGuid = if ($TemplateRef -is [string]) { $TemplateRef } else { $TemplateRef.value ?? $TemplateRef.GUID } + + # A blank template reference is equivalent to no template -> universal set, skip it. + if ([string]::IsNullOrWhiteSpace($TemplateGuid)) { + continue + } + + try { + $SafeGuid = ConvertTo-CIPPODataFilterValue -Value $TemplateGuid -Type Guid + $TemplateRow = Get-CIPPAzDataTableEntity @TemplateTable -Filter "PartitionKey eq 'JITRoleTemplate' and RowKey eq '$SafeGuid'" + } catch { + Write-Warning "JIT allowed-roles: failed to read JIT Role Template '$TemplateGuid': $($_.Exception.Message)" + $TemplateRow = $null + } + + # A templated role whose template cannot be resolved contributes an empty set (fail closed). + if (-not $TemplateRow) { + $TemplatedSets.Add([string[]]@()) + continue + } + + try { + $TemplateData = $TemplateRow.JSON | ConvertFrom-Json -Depth 10 -ErrorAction Stop + } catch { + $TemplatedSets.Add([string[]]@()) + continue + } + $Ids = foreach ($Role in @($TemplateData.roles)) { + $Id = if ($Role -is [string]) { $Role } else { $Role.value ?? $Role.ObjectId } + if (-not [string]::IsNullOrWhiteSpace($Id)) { [string]$Id } + } + $TemplatedSets.Add([string[]]@($Ids)) + } + + # No templated custom role -> nothing restricts the caller. + if ($TemplatedSets.Count -eq 0) { + return $Unrestricted + } + + # Restricted: the allow-list is the intersection of every templated role's set (most restrictive wins). + $Intersection = $null + foreach ($Set in $TemplatedSets) { + if ($null -eq $Intersection) { + $Intersection = [System.Collections.Generic.HashSet[string]]::new([string[]]@($Set)) + } else { + $Intersection.IntersectWith([string[]]@($Set)) + } + } + + return [PSCustomObject]@{ + Restricted = $true + AllowedRoleIds = @($Intersection) + } +} diff --git a/Modules/CIPPCore/Public/Get-CIPPLAPSPassword.ps1 b/Modules/CIPPCore/Public/Get-CIPPLAPSPassword.ps1 index b0cd9c6534a06..f54212d7e6699 100644 --- a/Modules/CIPPCore/Public/Get-CIPPLAPSPassword.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPLAPSPassword.ps1 @@ -18,7 +18,13 @@ function Get-CIPPLapsPassword { state = 'success' } } - if ($GraphRequest) { return $GraphRequest } else { return "No LAPS password found for $device" } + if ($GraphRequest) { + Write-LogMessage -headers $Headers -API $APIName -message "Retrieved LAPS password for $device" -Sev 'Info' -tenant $TenantFilter + return $GraphRequest + } else { + Write-LogMessage -headers $Headers -API $APIName -message "No LAPS password found for $device" -Sev 'Info' -tenant $TenantFilter + return "No LAPS password found for $device" + } } catch { $ErrorMessage = Get-CippException -Exception $_ Write-LogMessage -headers $Headers -API $APIName -message "Could not retrieve LAPS password for $($device). Error: $($ErrorMessage.NormalizedError)" -Sev 'Error' -tenant $TenantFilter -LogData $ErrorMessage diff --git a/Modules/CIPPCore/Public/Get-CIPPLastSignInDateTime.ps1 b/Modules/CIPPCore/Public/Get-CIPPLastSignInDateTime.ps1 new file mode 100644 index 0000000000000..8518f3503f5ca --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPLastSignInDateTime.ps1 @@ -0,0 +1,31 @@ +function Get-CIPPLastSignInDateTime { + <# + .SYNOPSIS + Returns the most recent sign-in timestamp from a Graph signInActivity object, in UTC. + .DESCRIPTION + Takes the newest of lastSignInDateTime (interactive), lastNonInteractiveSignInDateTime and + lastSuccessfulSignInDateTime. The first two record the last sign-in attempt whether it + succeeded or not, which is the view the Entra portal and the inactive-user alerts give; + the third can run ahead of both, so leaving it out would report a recently active user + as stale. Returns $null when the user has no sign-in activity on record. + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param($SignInActivity) + + if (-not $SignInActivity) { return $null } + + $Latest = $null + foreach ($Property in 'lastSignInDateTime', 'lastNonInteractiveSignInDateTime', 'lastSuccessfulSignInDateTime') { + $Value = $SignInActivity.$Property + if ([string]::IsNullOrWhiteSpace("$Value")) { continue } + try { + $Candidate = ([datetime]$Value).ToUniversalTime() + } catch { + continue + } + if ($null -eq $Latest -or $Candidate -gt $Latest) { $Latest = $Candidate } + } + return $Latest +} diff --git a/Modules/CIPPCore/Public/Get-CIPPLicenseOptimization.ps1 b/Modules/CIPPCore/Public/Get-CIPPLicenseOptimization.ps1 new file mode 100644 index 0000000000000..752cdb30cc384 --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPLicenseOptimization.ps1 @@ -0,0 +1,297 @@ +function Get-CIPPLicenseOptimization { + <# + .SYNOPSIS + Compute license waste and reclaimable spend for a tenant. + + .DESCRIPTION + Joins the cached license overview, users, and active-user-detail datasets with the resolved + price map (Get-CIPPLicensePrice) to produce a per-tenant optimization report: a monetary + summary plus a list of reclaim opportunities across five tiers: + + 1. UnassignedSeats - owned seats no one holds (CountAvailable > 0) + 2. DisabledAccount - a license assigned to a disabled account + 3. Inactive - a license on an enabled account with no sign-in in -InactiveDays + 4. Downgrade - a mailbox-only user on a premium SKU (review candidate) + 5. Overlap - a SKU whose service plans are fully covered by another SKU the user holds + + All inputs default to the reporting-DB cache but can be injected for testing or a live run. + + .PARAMETER TenantFilter + The tenant (domain or GUID) to report on. + + .PARAMETER Licenses + Optional. LicenseOverview records. Defaults to the cached 'LicenseOverview' type. + + .PARAMETER Users + Optional. User records. Defaults to the cached 'Users' type. + + .PARAMETER ActivityDetail + Optional. getOffice365ActiveUserDetail rows. Defaults to the cached 'ActiveUserDetail' type. + + .PARAMETER InactiveDays + Sign-in age (days) past which an enabled licensed user counts as inactive. Default 90. + + .PARAMETER Currency + ISO currency code the money figures are resolved in (passed to Get-CIPPLicensePrice). + Default USD. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + $Licenses, + $Users, + $ActivityDetail, + [int]$InactiveDays = 90, + [string]$Currency = 'USD' + ) + + if (-not $PSBoundParameters.ContainsKey('Licenses')) { $Licenses = @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'LicenseOverview') } + if (-not $PSBoundParameters.ContainsKey('Users')) { $Users = @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'Users') } + if (-not $PSBoundParameters.ContainsKey('ActivityDetail')) { $ActivityDetail = @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'ActiveUserDetail') } + + $Licenses = @($Licenses) + $Users = @($Users) + $ActivityDetail = @($ActivityDetail) + + # --- price map (lowercased skuId -> price object) --- + $PriceBySku = @{} + foreach ($Price in @(Get-CIPPLicensePrice -Currency $Currency)) { + if ($Price.skuId) { $PriceBySku[([string]$Price.skuId).ToLowerInvariant()] = $Price } + } + $PriceOf = { + param($Sku) + $Key = ([string]$Sku).ToLowerInvariant() + if ($PriceBySku.ContainsKey($Key) -and $null -ne $PriceBySku[$Key].MonthlyPrice) { return [double]$PriceBySku[$Key].MonthlyPrice } + return $null + } + + # --- SKU lookup from the license overview: pretty name, service-plan set, seat counts --- + $SkuInfo = @{} + foreach ($Lic in $Licenses) { + if (-not $Lic.skuId) { continue } + $Key = ([string]$Lic.skuId).ToLowerInvariant() + $PlanIds = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + foreach ($Plan in @($Lic.ServicePlans)) { + if ($Plan.servicePlanId) { $null = $PlanIds.Add([string]$Plan.servicePlanId) } + } + $Total = [int]($Lic.TotalLicenses -as [int]) + $Used = [int]($Lic.CountUsed -as [int]) + $SkuInfo[$Key] = [pscustomobject]@{ + skuId = $Key + License = if ($Lic.License) { [string]$Lic.License } else { $Key } + PlanIds = $PlanIds + Total = $Total + Used = $Used + Available = $Total - $Used + } + } + $NameOf = { + param($Sku) + $Key = ([string]$Sku).ToLowerInvariant() + if ($SkuInfo.ContainsKey($Key)) { return $SkuInfo[$Key].License } + if ($PriceBySku.ContainsKey($Key) -and $PriceBySku[$Key].Product_Display_Name) { return [string]$PriceBySku[$Key].Product_Display_Name } + return $Key + } + + # --- activity map (lowercased UPN -> row); detect anonymized reports --- + $ActivityByUpn = @{} + foreach ($Row in $ActivityDetail) { + if ($Row.userPrincipalName) { $ActivityByUpn[([string]$Row.userPrincipalName).ToLowerInvariant()] = $Row } + } + $Cutoff = (Get-Date).AddDays(-$InactiveDays) + $ActiveIn = { + param($Row, $DateProp) + $Value = $Row.$DateProp + if ([string]::IsNullOrWhiteSpace([string]$Value)) { return $false } + $Parsed = [datetime]::MinValue + if ([datetime]::TryParse([string]$Value, [ref]$Parsed)) { return $Parsed -ge $Cutoff } + return $false + } + + # Real (non-service, non-guest) users only for per-user tiers + $RealUsers = @($Users | Where-Object { + $_.assignedLicenses -and @($_.assignedLicenses).Count -gt 0 -and + $_.userType -ne 'Guest' -and $_.isResourceAccount -ne $true + }) + + # Anonymized when activity exists but almost none of its UPNs match real users + $AnonymizedReports = $false + if ($ActivityByUpn.Count -gt 0 -and $RealUsers.Count -gt 0) { + $MatchCount = @($RealUsers | Where-Object { $ActivityByUpn.ContainsKey(([string]$_.userPrincipalName).ToLowerInvariant()) }).Count + if (($MatchCount / [double]$RealUsers.Count) -lt 0.1) { $AnonymizedReports = $true } + } + + $Opportunities = [System.Collections.Generic.List[object]]::new() + $NewOpportunity = { + param($Tier, $Finding, $Sku, $Seats, $MonthlySaving, $Action, $Users, $PriceKnown) + $Monthly = [math]::Round(([double]$MonthlySaving), 2) + $Opportunities.Add([pscustomobject]@{ + Tier = $Tier + FindingLabel = $Finding + License = & $NameOf $Sku + skuId = ([string]$Sku).ToLowerInvariant() + Seats = [int]$Seats + UnitCost = & $PriceOf $Sku + MonthlySaving = $Monthly + SuggestedAction = $Action + Users = @($Users) + PriceKnown = [bool]$PriceKnown + }) + } + + # --- Tier 1: unassigned (empty) seats --- + foreach ($Sku in $SkuInfo.Values) { + if ($Sku.Available -le 0) { continue } + $UnitPrice = & $PriceOf $Sku.skuId + & $NewOpportunity 'UnassignedSeats' 'Unassigned' $Sku.skuId $Sku.Available (($UnitPrice ?? 0) * $Sku.Available) 'Reduce seat count' @() ($null -ne $UnitPrice) + } + + # --- Tiers 2 & 3: disabled / inactive assigned seats (grouped by SKU) --- + $DisabledBySku = @{} + $InactiveBySku = @{} + foreach ($User in $RealUsers) { + $Upn = [string]$User.userPrincipalName + $Disabled = $User.accountEnabled -eq $false + + # Most-recent sign-in (interactive or non-interactive) + $LastSignIn = $null + foreach ($Prop in @('lastSignInDateTime', 'lastNonInteractiveSignInDateTime')) { + $Value = $User.signInActivity.$Prop + if (-not [string]::IsNullOrWhiteSpace([string]$Value)) { + $Parsed = [datetime]::MinValue + if ([datetime]::TryParse([string]$Value, [ref]$Parsed)) { + if ($null -eq $LastSignIn -or $Parsed -gt $LastSignIn) { $LastSignIn = $Parsed } + } + } + } + # Enabled + has a sign-in on record + that sign-in is stale. Never-signed-in enabled + # accounts are skipped by default to avoid flagging provisioning/service identities. + $Inactive = (-not $Disabled) -and ($null -ne $LastSignIn) -and ($LastSignIn -lt $Cutoff) + + if (-not $Disabled -and -not $Inactive) { continue } + $Bucket = if ($Disabled) { $DisabledBySku } else { $InactiveBySku } + foreach ($Assigned in @($User.assignedLicenses)) { + if (-not $Assigned.skuId) { continue } + $Key = ([string]$Assigned.skuId).ToLowerInvariant() + if (-not $Bucket.ContainsKey($Key)) { $Bucket[$Key] = [System.Collections.Generic.List[string]]::new() } + $Bucket[$Key].Add($Upn) + } + } + foreach ($Key in $DisabledBySku.Keys) { + $Upns = $DisabledBySku[$Key] + $UnitPrice = & $PriceOf $Key + & $NewOpportunity 'DisabledAccount' 'Disabled user' $Key $Upns.Count (($UnitPrice ?? 0) * $Upns.Count) 'Remove license' $Upns ($null -ne $UnitPrice) + } + foreach ($Key in $InactiveBySku.Keys) { + $Upns = $InactiveBySku[$Key] + $UnitPrice = & $PriceOf $Key + & $NewOpportunity 'Inactive' ("Inactive {0}d+" -f $InactiveDays) $Key $Upns.Count (($UnitPrice ?? 0) * $Upns.Count) 'Review / remove' $Upns ($null -ne $UnitPrice) + } + + # --- Tier 4: mailbox-only users on a premium suite SKU (flag for REVIEW, not a downgrade) --- + # A user who only uses email yet holds a full suite may be over-licensed - but a licensed + # (shared) mailbox is sometimes deliberate (large archive, litigation/in-place hold, >50 GB, an + # auto-mapped resource). So we make no assumption about downgrading and claim no saving; we + # surface the seats for the MSP to review and decide. + $ReviewSuiteSkus = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + foreach ($Guid in @( + '6fd2c87f-b296-42f0-b197-1e91e994b900', # Office 365 E3 + 'c7df2760-2c81-4ef7-b578-5b5392b571df', # Office 365 E5 + '05e9a617-0261-4cee-bb44-138d3ef5d965', # Microsoft 365 E3 + '06ebc4ee-1bb5-47dd-8120-11324bc54e06', # Microsoft 365 E5 + 'f245ecc8-75af-4f8e-b61f-27d8114de5f3', # Microsoft 365 Business Standard + 'cbdc14ab-d96c-4c30-b9f4-6ada7cdc1d46' # Microsoft 365 Business Premium + )) { $null = $ReviewSuiteSkus.Add($Guid) } + + $ReviewBySku = @{} + foreach ($User in $RealUsers) { + if ($User.accountEnabled -eq $false) { continue } + $Activity = $ActivityByUpn[([string]$User.userPrincipalName).ToLowerInvariant()] + if (-not $Activity) { continue } + $UsedExchange = & $ActiveIn $Activity 'exchangeLastActivityDate' + $UsedCollab = (& $ActiveIn $Activity 'oneDriveLastActivityDate') -or + (& $ActiveIn $Activity 'sharePointLastActivityDate') -or + (& $ActiveIn $Activity 'teamsLastActivityDate') -or + (& $ActiveIn $Activity 'yammerLastActivityDate') + if (-not $UsedExchange -or $UsedCollab) { continue } + foreach ($Assigned in @($User.assignedLicenses)) { + $Key = ([string]$Assigned.skuId).ToLowerInvariant() + if (-not $ReviewSuiteSkus.Contains($Key)) { continue } + if (-not $ReviewBySku.ContainsKey($Key)) { $ReviewBySku[$Key] = [System.Collections.Generic.List[string]]::new() } + $ReviewBySku[$Key].Add([string]$User.userPrincipalName) + } + } + foreach ($Key in $ReviewBySku.Keys) { + $Upns = $ReviewBySku[$Key] + # Review only - no assumed downgrade target, so no monetary saving is claimed. PriceKnown + # still reflects whether the SKU itself is priced (so the UI's set-price action only targets + # genuinely unpriced SKUs, not these). + $UnitPrice = & $PriceOf $Key + & $NewOpportunity 'Downgrade' 'Mailbox-only' $Key $Upns.Count 0 'Review: only using email' $Upns ($null -ne $UnitPrice) + } + + # --- Tier 5: redundant SKU whose service plans are fully covered by another SKU the user holds --- + $OverlapBySku = @{} + foreach ($User in $RealUsers) { + $Held = @(@($User.assignedLicenses).skuId | Where-Object { $_ } | ForEach-Object { ([string]$_).ToLowerInvariant() } | Select-Object -Unique) + if ($Held.Count -lt 2) { continue } + foreach ($A in $Held) { + if (-not $SkuInfo.ContainsKey($A) -or $SkuInfo[$A].PlanIds.Count -eq 0) { continue } + foreach ($B in $Held) { + if ($A -eq $B -or -not $SkuInfo.ContainsKey($B)) { continue } + # A is redundant if every plan in A is also in B (A is a subset of B) and B is larger + if ($SkuInfo[$B].PlanIds.Count -gt $SkuInfo[$A].PlanIds.Count -and $SkuInfo[$B].PlanIds.IsSupersetOf($SkuInfo[$A].PlanIds)) { + if (-not $OverlapBySku.ContainsKey($A)) { $OverlapBySku[$A] = [System.Collections.Generic.List[string]]::new() } + $OverlapBySku[$A].Add([string]$User.userPrincipalName) + break + } + } + } + } + foreach ($Key in $OverlapBySku.Keys) { + $Upns = @($OverlapBySku[$Key] | Select-Object -Unique) + $UnitPrice = & $PriceOf $Key + & $NewOpportunity 'Overlap' 'Redundant' $Key $Upns.Count (($UnitPrice ?? 0) * $Upns.Count) 'Remove redundant license' $Upns ($null -ne $UnitPrice) + } + + # --- summary --- (money resolved in the requested $Currency) + $MonthlySpend = 0.0 + $PricedSeats = 0 + $TotalAssignedSeats = 0 + foreach ($Sku in $SkuInfo.Values) { + $TotalAssignedSeats += $Sku.Used + $UnitPrice = & $PriceOf $Sku.skuId + if ($null -ne $UnitPrice) { + $MonthlySpend += $UnitPrice * $Sku.Used + $PricedSeats += $Sku.Used + } + } + $ReclaimableMonthly = 0.0 + foreach ($Opp in $Opportunities) { $ReclaimableMonthly += $Opp.MonthlySaving } + $ReclaimableSeats = 0 + foreach ($Opp in $Opportunities) { + if ($Opp.Tier -in @('UnassignedSeats', 'DisabledAccount', 'Inactive')) { $ReclaimableSeats += $Opp.Seats } + } + + $Summary = [pscustomobject]@{ + Tenant = $TenantFilter + Currency = $Currency + MonthlySpend = [math]::Round($MonthlySpend, 2) + ReclaimableMonthly = [math]::Round($ReclaimableMonthly, 2) + ReclaimableSeats = $ReclaimableSeats + AssignedSeats = $TotalAssignedSeats + PriceCoverage = if ($TotalAssignedSeats -gt 0) { [math]::Round($PricedSeats / [double]$TotalAssignedSeats, 3) } else { 0 } + OpportunityCount = $Opportunities.Count + AnonymizedReports = $AnonymizedReports + DataAvailable = ($Licenses.Count -gt 0) + } + + return [pscustomobject]@{ + Summary = $Summary + Opportunities = @($Opportunities | Sort-Object -Property MonthlySaving -Descending) + } +} diff --git a/Modules/CIPPCore/Public/Get-CIPPLicenseOverview.ps1 b/Modules/CIPPCore/Public/Get-CIPPLicenseOverview.ps1 index 7e7c32e5285eb..f583824cd2f4d 100644 --- a/Modules/CIPPCore/Public/Get-CIPPLicenseOverview.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPLicenseOverview.ps1 @@ -73,7 +73,7 @@ function Get-CIPPLicenseOverview { $null -eq $_.ExcludedEverywhere -or $_.ExcludedEverywhere -eq $true } | ForEach-Object { $_.GUID }) } - $DropdownVisibleGuids = @($ExcludedSkuList | Where-Object { $_.ShowInLicenseDropdown -eq $true } | ForEach-Object { $_.GUID }) + $HiddenFromDropdownGuids = @($ExcludedSkuList | Where-Object { $_.ShowInLicenseDropdown -eq $false } | ForEach-Object { $_.GUID }) $AllLicensedUsers = @(($Results | Where-Object { $_.id -eq 'licensedUsers' }).body.value) | Sort-Object -Property displayName $UsersBySku = @{} @@ -123,7 +123,7 @@ function Get-CIPPLicenseOverview { $skuId = $singleReq.Licenses foreach ($sku in $skuId) { if ($sku.skuId -in $EffectiveExcludedGuids) { - if (!$IncludeExcluded -or $sku.skuId -notin $DropdownVisibleGuids) { continue } + if (!$IncludeExcluded -or $sku.skuId -in $HiddenFromDropdownGuids) { continue } } $PrettyNameAdmin = $AdminPortalLicenses | Where-Object { $_.aadSkuId -eq $sku.skuId } | Select-Object -ExpandProperty displayName -First 1 $PrettyNameCSV = ($ConvertTable | Where-Object { $_.guid -eq $sku.skuid }).'Product_Display_Name' | Select-Object -Last 1 diff --git a/Modules/CIPPCore/Public/Get-CIPPLicensePrice.ps1 b/Modules/CIPPCore/Public/Get-CIPPLicensePrice.ps1 new file mode 100644 index 0000000000000..8994e35166dac --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPLicensePrice.ps1 @@ -0,0 +1,131 @@ +function Get-CIPPLicensePrice { + <# + .SYNOPSIS + Resolve the monthly price for one or all license SKUs, in a given currency. + + .DESCRIPTION + Merges the shipped MSRP estimate list (Config\LicensePricingDefaults.csv) with the + MSP-maintained override table (LicensePricing). An override always wins over the estimate. + Both are multi-currency: each SKU can have a row per ISO currency. Prices are MSP-global + (not per-tenant). + + Returns one price object per SKU for the requested -Currency, with a Source of: + - 'Override' : an explicit price the MSP entered for this currency + - 'Estimate' : the shipped public MSRP fallback for this currency (subject to drift) + - 'Unknown' : the SKU has no price in the requested currency (MonthlyPrice is $null) + + There is no cross-currency conversion: asking for AUD returns only AUD prices. A single + -SkuId lookup with no price in the requested currency is reported 'Unknown' (null price); the + full list (the price matrix) omits such SKUs entirely rather than showing empty rows. + + .PARAMETER SkuId + Optional. Return the single resolved price object for this SKU GUID. Omit to return every + known SKU (overrides merged over estimates) for the requested currency. + + .PARAMETER Currency + ISO currency code to resolve prices in. Defaults to USD. + + .PARAMETER ListCurrencies + Return the sorted list of currency codes present in the estimates + overrides instead of + prices. Used to populate the currency selector. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [string]$SkuId, + [string]$Currency = 'USD', + [switch]$ListCurrencies + ) + + # currency (lower) -> @{ skuId (lower) -> price object } + $Estimate = @{} + $Override = @{} + # skuId (lower) -> metadata shared across currencies (name / part number) + $SkuMeta = @{} + $CurrencySet = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + + # Shipped MSRP estimates (public list prices, subject to drift - labelled Estimate) + try { + $CsvPath = Join-Path $env:CIPPRootPath 'Config\LicensePricingDefaults.csv' + if (Test-Path $CsvPath) { + foreach ($Row in (Import-Csv -Path $CsvPath)) { + $Key = ([string]$Row.skuId).ToLowerInvariant() + if ([string]::IsNullOrWhiteSpace($Key)) { continue } + $Cur = if ($Row.Currency) { [string]$Row.Currency } else { 'USD' } + $null = $CurrencySet.Add($Cur) + $CurKey = $Cur.ToLowerInvariant() + if (-not $Estimate.ContainsKey($CurKey)) { $Estimate[$CurKey] = @{} } + $Estimate[$CurKey][$Key] = [pscustomobject]@{ + skuId = $Key + skuPartNumber = [string]$Row.skuPartNumber + Product_Display_Name = [string]$Row.Product_Display_Name + MonthlyPrice = [double]$Row.MonthlyPrice + Currency = $Cur + Source = 'Estimate' + } + if (-not $SkuMeta.ContainsKey($Key)) { + $SkuMeta[$Key] = [pscustomobject]@{ skuPartNumber = [string]$Row.skuPartNumber; Product_Display_Name = [string]$Row.Product_Display_Name } + } + } + } + } catch { + Write-Information "Get-CIPPLicensePrice: failed to read defaults CSV: $($_.Exception.Message)" + } + + # MSP overrides (win over estimates, per currency) + try { + $Table = Get-CIPPTable -TableName 'LicensePricing' + foreach ($Row in (Get-CIPPAzDataTableEntity @Table)) { + $Key = if ($Row.skuId) { ([string]$Row.skuId).ToLowerInvariant() } else { (([string]$Row.RowKey) -split '-')[0].ToLowerInvariant() } + if ([string]::IsNullOrWhiteSpace($Key)) { continue } + $Cur = if ($Row.Currency) { [string]$Row.Currency } else { 'USD' } + $null = $CurrencySet.Add($Cur) + $CurKey = $Cur.ToLowerInvariant() + if (-not $Override.ContainsKey($CurKey)) { $Override[$CurKey] = @{} } + $Override[$CurKey][$Key] = [pscustomobject]@{ + skuId = $Key + skuPartNumber = [string]$Row.skuPartNumber + Product_Display_Name = [string]$Row.Product_Display_Name + MonthlyPrice = [double]$Row.MonthlyPrice + Currency = $Cur + Source = 'Override' + } + if (-not $SkuMeta.ContainsKey($Key)) { + $SkuMeta[$Key] = [pscustomobject]@{ skuPartNumber = [string]$Row.skuPartNumber; Product_Display_Name = [string]$Row.Product_Display_Name } + } + } + } catch { + Write-Information "Get-CIPPLicensePrice: failed to read override table: $($_.Exception.Message)" + } + + if ($ListCurrencies) { + return @($CurrencySet | Sort-Object) + } + + $WantCur = $Currency.ToLowerInvariant() + $ResolveOne = { + param($Sku) + if ($Override.ContainsKey($WantCur) -and $Override[$WantCur].ContainsKey($Sku)) { return $Override[$WantCur][$Sku] } + if ($Estimate.ContainsKey($WantCur) -and $Estimate[$WantCur].ContainsKey($Sku)) { return $Estimate[$WantCur][$Sku] } + $Meta = $SkuMeta[$Sku] + return [pscustomobject]@{ + skuId = $Sku + skuPartNumber = if ($Meta) { $Meta.skuPartNumber } else { $null } + Product_Display_Name = if ($Meta) { $Meta.Product_Display_Name } else { $null } + MonthlyPrice = $null + Currency = $Currency + Source = 'Unknown' + } + } + + if ($SkuId) { + return & $ResolveOne ([string]$SkuId).ToLowerInvariant() + } + + # The full list is the price matrix: only SKUs that actually carry a price in this currency + # (a SKU priced in USD but not the requested currency is omitted, not shown as 'Unknown'). + $Result = foreach ($Sku in $SkuMeta.Keys) { & $ResolveOne $Sku } + return @($Result | Where-Object { $null -ne $_.MonthlyPrice } | Sort-Object -Property Product_Display_Name) +} diff --git a/Modules/CIPPCore/Public/Get-CIPPMFAStateReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPMFAStateReport.ps1 index 41f2bc9c41e79..a34d6c2ef50e3 100644 --- a/Modules/CIPPCore/Public/Get-CIPPMFAStateReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPMFAStateReport.ps1 @@ -26,6 +26,10 @@ function Get-CIPPMFAStateReport { .PARAMETER TenantFilter The tenant to generate the report for + .PARAMETER PageSize + When set, returns one page of at most this many rows as @{ Items; NextToken }, in table walk order. .PARAMETER ContinuationToken + NextToken from the previous page. Only meaningful together with PageSize. + .EXAMPLE Get-CIPPMFAStateReport -TenantFilter 'contoso.onmicrosoft.com' Gets MFA state for all users in the tenant @@ -33,10 +37,41 @@ function Get-CIPPMFAStateReport { [CmdletBinding()] param( [Parameter(Mandatory = $true)] - [string]$TenantFilter + [string]$TenantFilter, + [int]$PageSize, + [string]$ContinuationToken ) try { + if ($PageSize -gt 0) { + $Page = Get-CIPPDbItemPage -TenantFilter $TenantFilter -Type 'MFAState' -PageSize $PageSize -ContinuationToken $ContinuationToken + if ($TenantFilter -ne 'AllTenants' -and -not $ContinuationToken -and @($Page.Items).Count -eq 0 -and -not $Page.NextToken) { + throw 'No MFA state data found in reporting database. Sync the report data first.' + } + # Same memory discipline as the unpaged path below: hashtables, no Add-Member. + $Results = [System.Collections.Generic.List[object]]::new() + foreach ($Item in $Page.Items) { + $MFAUser = $Item.Data | ConvertFrom-Json -AsHashtable + + # Legacy rows stored these as embedded JSON strings rather than as objects. + if ($MFAUser['CAPolicies'] -is [string]) { + $MFAUser['CAPolicies'] = try { $MFAUser['CAPolicies'] | ConvertFrom-Json -AsHashtable } catch { $MFAUser['CAPolicies'] } + } + if ($MFAUser['MFAMethods'] -is [string]) { + $MFAUser['MFAMethods'] = try { $MFAUser['MFAMethods'] | ConvertFrom-Json -AsHashtable } catch { $MFAUser['MFAMethods'] } + } + + $MFAUser['CacheTimestamp'] = $Item.Timestamp + # Tenant is already stored on every row by Get-CIPPMFAState; only fill it + # in for older rows that predate that. + if (-not $MFAUser['Tenant']) { $MFAUser['Tenant'] = $Item.PartitionKey } + $Results.Add($MFAUser) + } + return [PSCustomObject]@{ + Items = $Results + NextToken = $Page.NextToken + } + } # Handle AllTenants if ($TenantFilter -eq 'AllTenants') { diff --git a/Modules/CIPPCore/Public/Get-CIPPMailboxRulesReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPMailboxRulesReport.ps1 index 641e979654528..9d664f3c0c9e7 100644 --- a/Modules/CIPPCore/Public/Get-CIPPMailboxRulesReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPMailboxRulesReport.ps1 @@ -62,13 +62,12 @@ function Get-CIPPMailboxRulesReport { foreach ($Item in $RulesItems | Where-Object { $_.RowKey -ne 'MailboxRules-Count' }) { $Rule = $Item.Data | ConvertFrom-Json - # Add cache timestamp to the rule - $Rule | Add-Member -NotePropertyName 'CacheTimestamp' -NotePropertyValue $CacheTimestamp -Force -ErrorAction SilentlyContinue - - # Ensure Tenant property is set + # Add cache timestamp to the rule; ensure Tenant property is set + $RuleProps = [ordered]@{ CacheTimestamp = $CacheTimestamp } if (-not $Rule.Tenant) { - $Rule | Add-Member -NotePropertyName 'Tenant' -NotePropertyValue $TenantFilter -Force -ErrorAction SilentlyContinue + $RuleProps['Tenant'] = $TenantFilter } + $Rule | Add-Member -NotePropertyMembers $RuleProps -Force -ErrorAction SilentlyContinue $AllRules.Add($Rule) } diff --git a/Modules/CIPPCore/Public/Get-CIPPMailboxesReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPMailboxesReport.ps1 index 7e87d65243f99..a852987913ef8 100644 --- a/Modules/CIPPCore/Public/Get-CIPPMailboxesReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPMailboxesReport.ps1 @@ -9,6 +9,10 @@ function Get-CIPPMailboxesReport { .PARAMETER TenantFilter The tenant to generate the report for + .PARAMETER PageSize + When set, returns one page of at most this many rows as @{ Items; NextToken }, in table walk order. .PARAMETER ContinuationToken + NextToken from the previous page. Only meaningful together with PageSize. + .EXAMPLE Get-CIPPMailboxesReport -TenantFilter 'contoso.onmicrosoft.com' Gets all mailboxes for the tenant from the report database @@ -16,10 +20,34 @@ function Get-CIPPMailboxesReport { [CmdletBinding()] param( [Parameter(Mandatory = $true)] - [string]$TenantFilter + [string]$TenantFilter, + [int]$PageSize, + [string]$ContinuationToken ) try { + if ($PageSize -gt 0) { + $Page = Get-CIPPDbItemPage -TenantFilter $TenantFilter -Type 'Mailboxes' -PageSize $PageSize -ContinuationToken $ContinuationToken + if ($TenantFilter -ne 'AllTenants' -and -not $ContinuationToken -and @($Page.Items).Count -eq 0 -and -not $Page.NextToken) { + throw 'No mailbox data found in reporting database. Sync the report data first.' + } + $Results = [System.Collections.Generic.List[PSCustomObject]]::new() + foreach ($Item in $Page.Items) { + $Mailbox = $Item.Data | ConvertFrom-Json + # Per-item timestamp: a page may span tenants. + $MailboxProps = [ordered]@{ CacheTimestamp = $Item.Timestamp } + if ($TenantFilter -eq 'AllTenants') { + $MailboxProps['Tenant'] = $Item.PartitionKey + } + $Mailbox | Add-Member -NotePropertyMembers $MailboxProps -Force + $Results.Add($Mailbox) + } + return [PSCustomObject]@{ + Items = $Results + NextToken = $Page.NextToken + } + } + # Handle AllTenants if ($TenantFilter -eq 'AllTenants') { # Get all tenants that have mailbox data diff --git a/Modules/CIPPCore/Public/Get-CIPPOutOfOffice.ps1 b/Modules/CIPPCore/Public/Get-CIPPOutOfOffice.ps1 index fd80a389be8f8..163a2577ee1cb 100644 --- a/Modules/CIPPCore/Public/Get-CIPPOutOfOffice.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPOutOfOffice.ps1 @@ -11,8 +11,11 @@ function Get-CIPPOutOfOffice { $OutOfOffice = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-MailboxAutoReplyConfiguration' -cmdParams @{Identity = $UserID } -Anchor $UserID $Results = @{ AutoReplyState = $OutOfOffice.AutoReplyState - StartTime = $OutOfOffice.StartTime ? $OutOfOffice.StartTime.ToString('yyyy-MM-dd HH:mm') : $null - EndTime = $OutOfOffice.EndTime ? $OutOfOffice.EndTime.ToString('yyyy-MM-dd HH:mm') : $null + # Emit UTC with an explicit 'Z' marker. Get-MailboxAutoReplyConfiguration returns these + # as server-local DateTimes; without the marker the browser reparses the wall-clock in its + # own timezone, shifting a reopened schedule by the UTC offset (and drifting on re-save). + StartTime = $OutOfOffice.StartTime ? $OutOfOffice.StartTime.ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:ssZ') : $null + EndTime = $OutOfOffice.EndTime ? $OutOfOffice.EndTime.ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:ssZ') : $null InternalMessage = $OutOfOffice.InternalMessage ExternalMessage = $OutOfOffice.ExternalMessage CreateOOFEvent = $OutOfOffice.CreateOOFEvent diff --git a/Modules/CIPPCore/Public/Get-CIPPPagedTableRows.ps1 b/Modules/CIPPCore/Public/Get-CIPPPagedTableRows.ps1 new file mode 100644 index 0000000000000..fba60f3e68a5d --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPPagedTableRows.ps1 @@ -0,0 +1,115 @@ +function Get-CIPPPagedTableRows { + <# + .FUNCTIONALITY + Internal + .SYNOPSIS + Reads one page of rows from an Azure Table by scanning an ordinal range of partitions. + .DESCRIPTION + Continuation-token pager over an ordinal (PartitionKey, RowKey) range: one range query + per chunk, so page cost tracks rows returned, not partition count. Rows from partitions + outside $PartitionKeys are dropped but still advance the cursor. A null NextToken means + the walk is complete. + + Invariants: $PartitionKeys must be ordinal ascending; resume uses RowKey gt '~' + ('~' sorts after every key character and the '-partN' rows, but an id that prefix-extends + another id could be skipped at a boundary - GUID ids cannot); -First counts physical + rows, so only an empty chunk proves the range drained, and the module completes any + split entity cut at the boundary (RecoverMissingPartRows) so pages hold whole entities. + .PARAMETER Table + Table splat from Get-CIPPTable. + .PARAMETER PartitionKeys + Partition keys to serve, ordinal ascending; the caller owns membership filtering. + .PARAMETER RowKeyGe + Optional inclusive RowKey lower bound (e.g. 'Guests-'). + .PARAMETER RowKeyLt + Optional exclusive RowKey upper bound (e.g. 'Guests.'). + .PARAMETER ExtraFilterClauses + Optional OData clauses ANDed onto every query; values must already be escaped. + .PARAMETER PageSize + Target kept rows per page (also the physical-row chunk size per query). + .PARAMETER MaxQueries + Safety bound on round trips per call; normally one or two are needed. + .PARAMETER ContinuationToken + NextToken from the previous call. Opaque to callers. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [hashtable]$Table, + [Parameter(Mandatory = $true)] + [AllowEmptyCollection()] + [string[]]$PartitionKeys, + [string]$RowKeyGe, + [string]$RowKeyLt, + [string[]]$ExtraFilterClauses = @(), + [ValidateRange(1, 10000)] + [int]$PageSize = 5000, + [ValidateRange(1, 100)] + [int]$MaxQueries = 10, + [string]$ContinuationToken + ) + + $Rows = [System.Collections.Generic.List[object]]::new() + if ($PartitionKeys.Count -eq 0) { + return [PSCustomObject]@{ Rows = $Rows; NextToken = $null } + } + + $Known = [System.Collections.Generic.HashSet[string]]::new([StringComparer]::Ordinal) + foreach ($Pk in $PartitionKeys) { $null = $Known.Add($Pk) } + + $CursorPk = $null + $CursorRk = $null + if ($ContinuationToken) { + $TokenParts = $ContinuationToken.Split('|', 2) + $CursorPk = [System.Uri]::UnescapeDataString($TokenParts[0]) + if ($TokenParts.Count -eq 2 -and $TokenParts[1]) { + $CursorRk = [System.Uri]::UnescapeDataString($TokenParts[1]) + } + } + + $Queries = 0 + $Exhausted = $false + while (-not $Exhausted -and $Queries -lt $MaxQueries -and $Rows.Count -lt $PageSize) { + $Clauses = [System.Collections.Generic.List[string]]::new() + $Clauses.Add("PartitionKey ge '{0}'" -f (ConvertTo-CIPPODataFilterValue -Value $PartitionKeys[0] -Type String)) + $Clauses.Add("PartitionKey le '{0}'" -f (ConvertTo-CIPPODataFilterValue -Value $PartitionKeys[-1] -Type String)) + if ($RowKeyGe) { + $Clauses.Add("RowKey ge '{0}'" -f (ConvertTo-CIPPODataFilterValue -Value $RowKeyGe -Type String)) + } + if ($RowKeyLt) { + $Clauses.Add("RowKey lt '{0}'" -f (ConvertTo-CIPPODataFilterValue -Value $RowKeyLt -Type String)) + } + if ($CursorPk) { + $SafePk = ConvertTo-CIPPODataFilterValue -Value $CursorPk -Type String + if ($CursorRk) { + $SafeRk = ConvertTo-CIPPODataFilterValue -Value $CursorRk -Type String + $Clauses.Add("((PartitionKey gt '$SafePk') or (PartitionKey eq '$SafePk' and RowKey gt '$SafeRk~'))") + } else { + # A token naming a partition but no row resumes from that partition's start. + $Clauses.Add("PartitionKey ge '$SafePk'") + } + } + foreach ($Clause in $ExtraFilterClauses) { $Clauses.Add($Clause) } + + $Chunk = @(Get-CIPPAzDataTableEntity @Table -Filter ($Clauses -join ' and ') -First $PageSize) + $Queries++ + if ($Chunk.Count -eq 0) { + $Exhausted = $true + break + } + foreach ($Row in $Chunk) { + if ($Known.Contains([string]$Row.PartitionKey)) { $Rows.Add($Row) } + } + $CursorPk = [string]$Chunk[-1].PartitionKey + $CursorRk = [string]$Chunk[-1].RowKey + } + + $NextToken = if (-not $Exhausted) { + '{0}|{1}' -f [System.Uri]::EscapeDataString($CursorPk), $(if ($CursorRk) { [System.Uri]::EscapeDataString($CursorRk) } else { '' }) + } else { $null } + + return [PSCustomObject]@{ + Rows = $Rows + NextToken = $NextToken + } +} diff --git a/Modules/CIPPCore/Public/Get-CIPPSPOAdminListData.ps1 b/Modules/CIPPCore/Public/Get-CIPPSPOAdminListData.ps1 index 97e35811bb89f..91f16d0da35b4 100644 --- a/Modules/CIPPCore/Public/Get-CIPPSPOAdminListData.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPSPOAdminListData.ps1 @@ -9,7 +9,8 @@ function Get-CIPPSPOAdminListData { Returns flat admin list Row objects (all pages). Does not join Graph or map browser DTOs. Dotted numeric props (e.g. StorageUsed.) are an RLD quirk; -NormalizeRows copies them to - undotted names when present. + undotted names when present, coerces StorageUsed / NumOfFiles / StorageQuota to int64, and + adds StorageQuotaBytes (admin quota is MB unless already byte-sized). .PARAMETER TenantFilter Tenant to query. @@ -35,7 +36,8 @@ function Get-CIPPSPOAdminListData { Abort if paging exceeds this many pages. .PARAMETER NormalizeRows - Copy StorageUsed. / NumOfFiles. / etc. onto undotted property names. + Copy StorageUsed. / NumOfFiles. / etc. onto undotted property names, parse numerics, and + derive StorageQuotaBytes. .FUNCTIONALITY Internal @@ -179,6 +181,23 @@ function Get-CIPPSPOAdminListData { } } } + foreach ($Field in @('StorageUsed', 'NumOfFiles', 'StorageQuota')) { + if ($Row.PSObject.Properties.Name -contains $Field) { + $Coerced = ConvertTo-SPOAdminListInt64 -Raw $Row.$Field + if ($null -ne $Coerced) { + $Row | Add-Member -NotePropertyName $Field -NotePropertyValue $Coerced -Force + } elseif ($Row.$Field -is [string] -and -not [string]::IsNullOrWhiteSpace($Row.$Field)) { + $Row | Add-Member -NotePropertyName $Field -NotePropertyValue $null -Force + } + } + } + if ($Row.PSObject.Properties.Name -contains 'StorageQuota') { + $QuotaMb = $Row.StorageQuota + if ($null -ne $QuotaMb -and $QuotaMb -gt 0) { + $QuotaBytes = if ($QuotaMb -lt 1TB) { [int64]($QuotaMb * 1MB) } else { $QuotaMb } + $Row | Add-Member -NotePropertyName 'StorageQuotaBytes' -NotePropertyValue $QuotaBytes -Force + } + } } [void]$AllRows.Add($Row) } diff --git a/Modules/CIPPCore/Public/Get-CIPPSPOSite.ps1 b/Modules/CIPPCore/Public/Get-CIPPSPOSite.ps1 index 8f35bca98ef3a..16057d7829f8b 100644 --- a/Modules/CIPPCore/Public/Get-CIPPSPOSite.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPSPOSite.ps1 @@ -28,19 +28,26 @@ function Get-CIPPSPOSite { param( [Parameter(Mandatory = $true)] [string]$TenantFilter, - [string]$SiteUrl + [string]$SiteUrl, + # SharePoint app-only auth requires a certificate (secret app-only is rejected by SPO). When + # set, authenticate app-only with the SAM certificate instead of the delegated context. + [switch]$UseCertificate ) $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter $AdminUrl = $SharePointInfo.AdminUrl + # Threaded onto every SPO admin call below; empty = unchanged delegated behaviour. + $AuthSplat = @{} + if ($UseCertificate) { $AuthSplat['AsApp'] = $true; $AuthSplat['UseCertificate'] = $true } + if ($SiteUrl) { # Single-site fast path: Tenant Constructor -> GetSitePropertiesByUrl -> Query all properties $XML = @" $([System.Security.SecurityElement]::Escape($SiteUrl))true "@ $AdditionalHeaders = @{ 'Accept' = 'application/json;odata=verbose' } - $Results = New-GraphPostRequest -scope "$AdminUrl/.default" -tenantid $TenantFilter -Uri "$AdminUrl/_vti_bin/client.svc/ProcessQuery" -Type POST -Body $XML -ContentType 'text/xml' -AddedHeaders $AdditionalHeaders + $Results = New-GraphPostRequest -scope "$AdminUrl/.default" -tenantid $TenantFilter -Uri "$AdminUrl/_vti_bin/client.svc/ProcessQuery" -Type POST -Body $XML -ContentType 'text/xml' -AddedHeaders $AdditionalHeaders @AuthSplat $Site = $Results | Where-Object { $_._ObjectType_ -match 'SiteProperties' } | Select-Object -First 1 if (-not $Site) { throw "Could not retrieve site properties for $SiteUrl" @@ -66,7 +73,7 @@ function Get-CIPPSPOSite { "@ } - $Results = New-GraphPostRequest -scope "$AdminUrl/.default" -tenantid $TenantFilter -Uri "$AdminUrl/_vti_bin/client.svc/ProcessQuery" -Type POST -Body $XML -ContentType 'text/xml' -AddedHeaders $AdditionalHeaders + $Results = New-GraphPostRequest -scope "$AdminUrl/.default" -tenantid $TenantFilter -Uri "$AdminUrl/_vti_bin/client.svc/ProcessQuery" -Type POST -Body $XML -ContentType 'text/xml' -AddedHeaders $AdditionalHeaders @AuthSplat # The response contains multiple objects; find the one with _Child_Items_ (site list) and NextStartIndexFromSharePoint $SiteCollection = $Results | Where-Object { $_._Child_Items_ } diff --git a/Modules/CIPPCore/Public/Get-CIPPSPOSiteBulk.ps1 b/Modules/CIPPCore/Public/Get-CIPPSPOSiteBulk.ps1 new file mode 100644 index 0000000000000..22bc5f518c6a5 --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPSPOSiteBulk.ps1 @@ -0,0 +1,138 @@ +function Get-CIPPSPOSiteBulk { + <# + .SYNOPSIS + Read individual SharePoint site properties for many sites (authoritative), batched and concurrent + + .DESCRIPTION + Concurrent counterpart to Get-CIPPSPOSite -SiteUrl. Fires single-site GetSitePropertiesByUrl CSOM + reads through CIPP.CIPPRestClient.SendConcurrent. Unlike the tenant-wide enumeration + (GetSitePropertiesFromSharePoint), the single-site read is AUTHORITATIVE and immediate, and it is + the ONLY source for ~19 per-site properties the enumeration returns as defaults (site owner, + per-site sharing controls, ShowPeoplePickerSuggestionsForGuestUsers, ...). + + Reads are grouped: each request carries -BatchSize GetSitePropertiesByUrl reads in one ProcessQuery + (fewer round-trips), and up to -MaxConcurrency requests run at once. SharePoint SERIALIZES the reads + inside a request and rejects large ones ("The request uses too many resources"), so batches stay + small; concurrency - not batch size - is what parallelises the work. The SPO admin token is + acquired once and reused across every request. + + Returns one object per input URL: @{ SiteUrl; Site; Success; Error }, where Site is the parsed + SiteProperties object (or $null on failure). A batch that fails marks every URL in it failed, so the + caller can fall back per site. + + .PARAMETER TenantFilter + Tenant to read from + + .PARAMETER SiteUrls + Array of full site URLs to read. + + .PARAMETER MaxConcurrency + Upper bound on in-flight requests (default 4). The SPO connection pool caps it to 5 regardless. + + .PARAMETER BatchSize + Site reads packed into a single ProcessQuery (default 5). Kept small - SharePoint rejects large + batched CSOM requests ("too many resources"); ~8 is the practical ceiling with SelectAllProperties. + + .PARAMETER UseCertificate + Authenticate app-only with the SAM certificate (SharePoint app-only requires it). + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + [Parameter(Mandatory = $true)] + [string[]]$SiteUrls, + [int]$MaxConcurrency = 4, + [int]$MaxRetries = 3, + [int]$BatchSize = 5, + [switch]$UseCertificate + ) + + $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter + $AdminUrl = $SharePointInfo.AdminUrl + $RequestUri = "$AdminUrl/_vti_bin/client.svc/ProcessQuery" + + $TokenSplat = @{ tenantid = $TenantFilter; scope = "$AdminUrl/.default" } + if ($UseCertificate) { $TokenSplat['AsApp'] = $true; $TokenSplat['UseCertificate'] = $true } + $Authorization = (Get-GraphToken @TokenSplat).Authorization + + if ($BatchSize -lt 1) { $BatchSize = 1 } + $CleanUrls = @($SiteUrls | Where-Object { -not [string]::IsNullOrWhiteSpace($_) }) + if ($CleanUrls.Count -eq 0) { return @() } + + $Requests = [System.Collections.Generic.List[CIPP.CIPPConcurrentRequest]]::new() + $BatchUrls = [System.Collections.Generic.List[object]]::new() + + for ($Start = 0; $Start -lt $CleanUrls.Count; $Start += $BatchSize) { + $End = [Math]::Min($Start + $BatchSize - 1, $CleanUrls.Count - 1) + $Chunk = @($CleanUrls[$Start..$End]) + + $Actions = [System.Text.StringBuilder]::new() + $Paths = [System.Text.StringBuilder]::new() + $Index = 0 + foreach ($Url in $Chunk) { + $MethodId = 1000 + $Index; $PathId = 4000 + $Index; $QueryId = 7000 + $Index + [void]$Actions.Append("") + [void]$Paths.Append("$([System.Security.SecurityElement]::Escape($Url))true") + $Index++ + } + $XML = "$($Actions.ToString())$($Paths.ToString())" + + $Request = [CIPP.CIPPConcurrentRequest]::new() + $Request.Uri = $RequestUri + $Request.Method = 'POST' + $Request.Body = $XML + $Request.ContentType = 'text/xml' + $Headers = [System.Collections.Generic.Dictionary[string, string]]::new() + $Headers['Authorization'] = $Authorization + $Headers['Accept'] = 'application/json;odata=verbose' + $Request.Headers = $Headers + + $Requests.Add($Request) + $BatchUrls.Add($Chunk) + } + + $Results = [CIPP.CIPPRestClient]::SendConcurrent($Requests, $MaxConcurrency, $MaxRetries) + + @(foreach ($Result in $Results) { + $Chunk = $BatchUrls[$Result.Index] + $BatchError = $null + $Parsed = $null + if ($Result.Error) { + $BatchError = $Result.Error + } elseif ($Result.StatusCode -ne 200) { + $BatchError = "HTTP $($Result.StatusCode)" + } else { + try { + $Parsed = $Result.Result.Content | ConvertFrom-Json + # One action's error aborts the whole ProcessQuery, so a batch-level ErrorInfo fails + # every URL in the chunk - the caller falls back per site. + $CsomError = ($Parsed | Where-Object { $_.ErrorInfo } | Select-Object -First 1).ErrorInfo.ErrorMessage + if ($CsomError) { $BatchError = $CsomError } + } catch { + $BatchError = "Could not parse CSOM response: $($_.Exception.Message)" + } + } + + if ($BatchError) { + foreach ($Url in $Chunk) { + [PSCustomObject]@{ SiteUrl = $Url; Site = $null; Success = $false; Error = $BatchError } + } + } else { + # Match each returned SiteProperties to its input URL (order is not guaranteed, and a + # deleted/erroring site in the middle would leave a gap) rather than trusting position. + $SitesInBatch = @($Parsed | Where-Object { $_._ObjectType_ -match 'SiteProperties' -and $_.Url }) + foreach ($Url in $Chunk) { + $Site = $SitesInBatch | Where-Object { "$($_.Url)".TrimEnd('/') -ieq "$Url".TrimEnd('/') } | Select-Object -First 1 + if ($Site) { + [PSCustomObject]@{ SiteUrl = $Url; Site = $Site; Success = $true; Error = $null } + } else { + [PSCustomObject]@{ SiteUrl = $Url; Site = $null; Success = $false; Error = 'No SiteProperties returned' } + } + } + } + }) +} diff --git a/Modules/CIPPCore/Public/Get-CIPPSPOTenant.ps1 b/Modules/CIPPCore/Public/Get-CIPPSPOTenant.ps1 index 60e31c9f0245a..cc245c53a2586 100644 --- a/Modules/CIPPCore/Public/Get-CIPPSPOTenant.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPSPOTenant.ps1 @@ -7,9 +7,17 @@ function Get-CIPPSPOTenant { # Only meaningful alongside SharepointPrefix. Sovereign clouds are not on sharepoint.com # (see Get-SharePointAdminLink), so a prefix on its own cannot build the admin URL. [string]$SharepointDomain = 'sharepoint.com', - [switch]$SkipCache + [switch]$SkipCache, + # SharePoint app-only auth requires a certificate (secret app-only is rejected by SPO with + # 'Unsupported app only token'). When set, authenticate app-only with the SAM certificate + # instead of the default delegated (refresh-token) context. + [switch]$UseCertificate ) + # Threaded onto every SPO admin call below; empty = unchanged delegated behaviour. + $AuthSplat = @{} + if ($UseCertificate) { $AuthSplat['AsApp'] = $true; $AuthSplat['UseCertificate'] = $true } + if (!$SharepointPrefix) { # get sharepoint admin site $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter @@ -47,7 +55,7 @@ function Get-CIPPSPOTenant { # $AdminUrl, not $SharePointInfo.AdminUrl - the latter is empty when a prefix was supplied. try { - $Results = New-GraphPostRequest -scope "$($AdminUrl)/.default" -tenantid $TenantFilter -Uri "$($AdminUrl)/_vti_bin/client.svc/ProcessQuery" -Type POST -Body $XML -ContentType 'text/xml' -AddedHeaders $AdditionalHeaders + $Results = New-GraphPostRequest -scope "$($AdminUrl)/.default" -tenantid $TenantFilter -Uri "$($AdminUrl)/_vti_bin/client.svc/ProcessQuery" -Type POST -Body $XML -ContentType 'text/xml' -AddedHeaders $AdditionalHeaders @AuthSplat } catch { # The admin endpoint answers a bare 401 when the CIPP service principal holds no SharePoint # app-only consent in the tenant - the token is issued fine, SharePoint just refuses it. That diff --git a/Modules/CIPPCore/Public/Get-CIPPScheduledTaskNextRun.ps1 b/Modules/CIPPCore/Public/Get-CIPPScheduledTaskNextRun.ps1 new file mode 100644 index 0000000000000..48fe2e0c48255 --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPScheduledTaskNextRun.ps1 @@ -0,0 +1,32 @@ +function Get-CIPPScheduledTaskNextRun { + <# + .SYNOPSIS + Next run time for a scheduled task, in unix seconds, or 0 when it does not repeat. + .DESCRIPTION + Recurrence is stored as 30m, 1h, 1d and so on; a bare number is a day count, the shape older + tasks carry. A run further back than one interval is treated as starting now, so a task that + was disabled or stuck does not replay a backlog of missed runs. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)][AllowNull()]$Recurrence, + [Parameter(Mandatory = $true)][AllowNull()]$ScheduledTime + ) + + $Value = [string]$Recurrence + if ($Value -match '^\d+$') { $Value = '{0}d' -f $Value } + + $SecondsToAdd = switch -Regex ($Value) { + '(\d+)m$' { [int64]$Matches[1] * 60 } + '(\d+)h$' { [int64]$Matches[1] * 3600 } + '(\d+)d$' { [int64]$Matches[1] * 86400 } + default { 0 } + } + if ($SecondsToAdd -le 0) { return 0 } + + $Now = [int64](([datetime]::UtcNow) - (Get-Date '1/1/1970')).TotalSeconds + $Last = [int64]($ScheduledTime ?? 0) + if ($Last -lt ($Now - $SecondsToAdd)) { $Last = $Now } + + return $Last + $SecondsToAdd +} diff --git a/Modules/CIPPCore/Public/Get-CIPPSharePointCopyJobProgress.ps1 b/Modules/CIPPCore/Public/Get-CIPPSharePointCopyJobProgress.ps1 new file mode 100644 index 0000000000000..57730d8a36283 --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPSharePointCopyJobProgress.ps1 @@ -0,0 +1,256 @@ +function Get-CIPPSharePointCopyJobProgress { + <# + .SYNOPSIS + Polls GetCopyJobProgress for one handle and returns sanitized aggregate metrics. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [Parameter(Mandatory = $true)] + [string]$SourceSiteUrl, + + [Parameter(Mandatory = $true)] + [object]$CopyJobInfo + ) + + $SanitizeCopyLogMessage = { + param([object]$Entry, [ValidateSet('Error', 'Warning')][string]$Kind) + + $Message = [string]($Entry.Message ?? $Entry.message ?? $Entry.ErrorMessage ?? '') + $ErrorType = [string]($Entry.ErrorType ?? $Entry.errorType ?? '') + $ErrorCode = [string]($Entry.ErrorCode ?? $Entry.errorCode ?? '') + $ObjectType = [string]($Entry.ObjectType ?? $Entry.objectType ?? '') + + if ($ErrorType -match '\.') { $ErrorType = ($ErrorType -split '\.')[-1] } + if ([string]::IsNullOrWhiteSpace($Message) -and ($ErrorType -or $ErrorCode)) { + $Message = if ($ErrorCode) { "$ErrorType ($ErrorCode)".Trim(' ()') } else { $ErrorType } + } + if ($ObjectType -and $Message) { $Message = "${ObjectType}: $Message" } + + $Fallback = if ($Kind -eq 'Error') { 'SharePoint reported a copy error.' } else { 'SharePoint reported a copy warning.' } + if ([string]::IsNullOrWhiteSpace($Message)) { return $Fallback } + + $Sanitized = $Message + $Sanitized = [regex]::Replace($Sanitized, 'https?://[^\s''"]+', '[url redacted]', 'IgnoreCase') + $Sanitized = [regex]::Replace($Sanitized, '\\[^\s''"]+', '[path redacted]', 'IgnoreCase') + $Sanitized = [regex]::Replace($Sanitized, '/(?:sites|teams)/[^\s''"]+', '[path redacted]', 'IgnoreCase') + $Sanitized = [regex]::Replace( + $Sanitized, + '[^\s\\/''"]+\.(docx?|xlsx?|pptx?|pdf|txt|csv|png|jpe?g|gif|zip|msg|one|aspx|html?|xml|json|mp4|mov|avi|wmv|rtf|md|svg|webp|heic|tif|tiff|7z|rar|tar|gz|ppt|xls|doc)\b', + '[file]', + 'IgnoreCase' + ) + $Sanitized = ($Sanitized -replace '\s{2,}', ' ').Trim() + if ([string]::IsNullOrWhiteSpace($Sanitized)) { return $Fallback } + return $Sanitized + } + + $MeasureCopyJobLogs = { + param([array]$RawLogs = @()) + + $ObjectsProcessed = 0 + $TotalExpected = $null + $FilesCreated = 0 + $BytesProcessed = 0 + $TotalErrors = 0 + $TotalWarnings = 0 + $ErrorMessages = [System.Collections.Generic.List[string]]::new() + $WarningMessages = [System.Collections.Generic.List[string]]::new() + $SeenErrors = [System.Collections.Generic.HashSet[string]]::new([StringComparer]::OrdinalIgnoreCase) + $SeenWarnings = [System.Collections.Generic.HashSet[string]]::new([StringComparer]::OrdinalIgnoreCase) + + foreach ($LogLine in @($RawLogs)) { + $Entry = $LogLine + if ($LogLine -is [string]) { + try { $Entry = $LogLine | ConvertFrom-Json } catch { continue } + } + if (-not $Entry) { continue } + + $EventName = [string]($Entry.Event ?? $Entry.event ?? $Entry.EventType ?? '') + $HasErrorDetails = -not [string]::IsNullOrWhiteSpace([string]($Entry.ErrorCode ?? $Entry.errorCode ?? '')) ` + -or -not [string]::IsNullOrWhiteSpace([string]($Entry.ErrorType ?? $Entry.errorType ?? '')) + + switch -Regex ($EventName) { + 'JobError|Error' { + $TotalErrors++ + $SanitizedMessage = & $SanitizeCopyLogMessage -Entry $Entry -Kind Error + if ($SeenErrors.Add($SanitizedMessage) -and $ErrorMessages.Count -lt 25) { + [void]$ErrorMessages.Add($SanitizedMessage) + } + } + 'JobWarning|Warning' { + $TotalWarnings++ + $SanitizedMessage = & $SanitizeCopyLogMessage -Entry $Entry -Kind Warning + if ($SeenWarnings.Add($SanitizedMessage) -and $WarningMessages.Count -lt 25) { + [void]$WarningMessages.Add($SanitizedMessage) + } + } + 'JobProgress|JobEnd|JobStart|JobQueued|JobFinishedObjectInfo' { + if ($null -ne $Entry.ObjectsProcessed) { $ObjectsProcessed = [int64]$Entry.ObjectsProcessed } + if ($null -ne $Entry.TotalExpectedSPObjects) { $TotalExpected = [int64]$Entry.TotalExpectedSPObjects } + if ($null -ne $Entry.FilesCreated) { $FilesCreated = [int64]$Entry.FilesCreated } + if ($null -ne $Entry.BytesProcessed) { $BytesProcessed = [int64]$Entry.BytesProcessed } + if ($null -ne $Entry.TotalErrors) { $TotalErrors = [int64]$Entry.TotalErrors } + if ($null -ne $Entry.TotalWarnings) { $TotalWarnings = [int64]$Entry.TotalWarnings } + } + default { + if ($HasErrorDetails) { + $TotalErrors++ + $SanitizedMessage = & $SanitizeCopyLogMessage -Entry $Entry -Kind Error + if ($SeenErrors.Add($SanitizedMessage) -and $ErrorMessages.Count -lt 25) { + [void]$ErrorMessages.Add($SanitizedMessage) + } + } + } + } + } + + if ($TotalErrors -gt 0 -and $ErrorMessages.Count -eq 0) { + foreach ($LogLine in @($RawLogs)) { + $Entry = $LogLine + if ($LogLine -is [string]) { + try { $Entry = $LogLine | ConvertFrom-Json } catch { continue } + } + if (-not $Entry) { continue } + if ([string]::IsNullOrWhiteSpace([string]($Entry.Message ?? $Entry.message ?? ''))) { continue } + $SanitizedMessage = & $SanitizeCopyLogMessage -Entry $Entry -Kind Error + if ($SeenErrors.Add($SanitizedMessage) -and $ErrorMessages.Count -lt 25) { + [void]$ErrorMessages.Add($SanitizedMessage) + } + } + } + + [PSCustomObject]@{ + ObjectsProcessed = $ObjectsProcessed + TotalExpectedObjects = $TotalExpected + FilesCreated = $FilesCreated + BytesProcessed = $BytesProcessed + TotalErrors = $TotalErrors + TotalWarnings = $TotalWarnings + ErrorMessages = @($ErrorMessages) + WarningMessages = @($WarningMessages) + } + } + + # Accept normalized handles, or legacy OData collection wrappers still in the table. + $Handle = $CopyJobInfo + if (-not ($Handle.JobId ?? $Handle.jobId) -and $null -ne $Handle.results) { + $Handle = @($Handle.results) | Select-Object -First 1 + } + + $JobId = [string]($Handle.JobId ?? $Handle.jobId ?? $Handle.JobID ?? '') + $JobQueueUri = $Handle.JobQueueUri ?? $Handle.jobQueueUri + if ($JobQueueUri -is [PSCustomObject]) { + $JobQueueUri = [string]($JobQueueUri.Url ?? $JobQueueUri.AbsoluteUri ?? $JobQueueUri) + } + $JobQueueUri = [string]$JobQueueUri + $EncryptionKey = $Handle.EncryptionKey ?? $Handle.encryptionKey + if ($EncryptionKey -is [PSCustomObject]) { + $EncryptionKey = $EncryptionKey.'#text' ?? $EncryptionKey.Value ?? $EncryptionKey.bytes + } + + if ([string]::IsNullOrWhiteSpace($JobId) -or [string]::IsNullOrWhiteSpace($JobQueueUri)) { + throw 'Copy job handle is missing JobId or JobQueueUri.' + } + + $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter + $Scope = "$($SharePointInfo.SharePointUrl)/.default" + $Uri = "$($SourceSiteUrl.TrimEnd('/'))/_api/site/GetCopyJobProgress" + $Body = ConvertTo-Json -InputObject @{ + copyJobInfo = @{ + __metadata = @{ type = 'SP.CopyMigrationInfo' } + JobQueueUri = $JobQueueUri + JobId = $JobId + EncryptionKey = $EncryptionKey + } + } -Depth 5 -Compress + + $RawLogs = @() + $JobState = $null + $RestError = $null + + try { + $Response = New-GraphPOSTRequest -uri $Uri -tenantid $TenantFilter -scope $Scope -type POST -body $Body ` + -AddedHeaders @{ Accept = 'application/json;odata=verbose' } ` + -contentType 'application/json;odata=verbose' -UseCertificate -AsApp $true + + if ($Response -is [string]) { + $Response = $Response | ConvertFrom-Json + } + + $Progress = if ($Response.d.GetCopyJobProgress) { + $P = $Response.d.GetCopyJobProgress + if ($P -is [string]) { $P | ConvertFrom-Json } else { $P } + } elseif ($Response.d) { + $Response.d + } else { + $Response + } + + $JobState = $Progress.JobState ?? $Progress.jobState + $LogsProperty = $Progress.Logs ?? $Progress.logs + if ($null -eq $LogsProperty) { + $RawLogs = @() + } elseif ($LogsProperty.PSObject.Properties['results']) { + $RawLogs = @($LogsProperty.results) + } elseif ($LogsProperty -is [System.Collections.IEnumerable] -and $LogsProperty -isnot [string]) { + $RawLogs = @($LogsProperty) + } else { + $RawLogs = @($LogsProperty) + } + } catch { + $RestError = $_.Exception.Message + Write-Information "GetCopyJobProgress REST failed: $RestError" + } + + $Metrics = & $MeasureCopyJobLogs -RawLogs $RawLogs + + if ($EncryptionKey -and ($RestError -or $Metrics.ErrorMessages.Count -eq 0 -or $RawLogs.Count -eq 0)) { + try { + $QueueLogs = Get-CIPPSharePointCopyJobQueueLogs -JobQueueUri $JobQueueUri -EncryptionKey $EncryptionKey + if ($QueueLogs.Count -gt 0) { + $Metrics = & $MeasureCopyJobLogs -RawLogs (@($RawLogs) + @($QueueLogs)) + } + } catch { + Write-Verbose "SharePoint copy queue log read failed: $($_.Exception.Message)" + } + } + + if ($RestError -and $RawLogs.Count -eq 0 -and $Metrics.TotalErrors -eq 0 -and $Metrics.ErrorMessages.Count -eq 0) { + $Detail = [regex]::Replace([string]$RestError, 'https?://[^\s''"]+', '[url redacted]', 'IgnoreCase') + $Detail = ($Detail -replace '\s{2,}', ' ').Trim() + if ($Detail.Length -gt 240) { $Detail = $Detail.Substring(0, 240).Trim() + '…' } + throw "Failed to retrieve copy job progress from SharePoint: $Detail" + } + + $StateInt = if ($null -ne $JobState) { [int]$JobState } else { -1 } + $IsComplete = $StateInt -eq 0 + if (-not $IsComplete -and $StateInt -lt 0 -and ( + $Metrics.TotalErrors -gt 0 -or $Metrics.TotalExpectedObjects -gt 0 -or $Metrics.ObjectsProcessed -gt 0 + )) { + $IsComplete = $true + } + + $Status = switch ($true) { + { $IsComplete -and $Metrics.TotalErrors -gt 0 } { 'CompletedWithErrors' } + { $IsComplete } { 'Complete' } + { $StateInt -eq 2 } { 'Queued' } + default { 'Processing' } + } + + [PSCustomObject]@{ + Status = $Status + JobState = $StateInt + IsComplete = $IsComplete + ObjectsProcessed = $Metrics.ObjectsProcessed + TotalExpectedObjects = $Metrics.TotalExpectedObjects + FilesCreated = $Metrics.FilesCreated + BytesProcessed = $Metrics.BytesProcessed + TotalErrors = $Metrics.TotalErrors + TotalWarnings = $Metrics.TotalWarnings + ErrorMessages = @($Metrics.ErrorMessages) + WarningMessages = @($Metrics.WarningMessages) + } +} diff --git a/Modules/CIPPCore/Public/Get-CIPPSharePointCopyJobQueueLogs.ps1 b/Modules/CIPPCore/Public/Get-CIPPSharePointCopyJobQueueLogs.ps1 new file mode 100644 index 0000000000000..1460e7c88995e --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPSharePointCopyJobQueueLogs.ps1 @@ -0,0 +1,88 @@ +function Get-CIPPSharePointCopyJobQueueLogs { + <# + .SYNOPSIS + Peeks encrypted SharePoint copy job log messages from the job Azure Storage queue. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$JobQueueUri, + + [Parameter(Mandatory = $true)] + $EncryptionKey, + + [int]$MaxMessages = 100 + ) + + if ([string]::IsNullOrWhiteSpace($JobQueueUri)) { + return @() + } + + $KeyBytes = if ($EncryptionKey -is [byte[]]) { + $EncryptionKey + } else { + $KeyText = [string]$EncryptionKey + if ([string]::IsNullOrWhiteSpace($KeyText)) { throw 'EncryptionKey is empty.' } + try { + [Convert]::FromBase64String($KeyText) + } catch { + [System.Text.Encoding]::UTF8.GetBytes($KeyText) + } + } + + $Logs = [System.Collections.Generic.List[object]]::new() + $Separator = if ($JobQueueUri -match '\?') { '&' } else { '?' } + $Remaining = $MaxMessages + $Page = 0 + + while ($Remaining -gt 0 -and $Page -lt 8) { + $BatchSize = [Math]::Min(32, $Remaining) + $Uri = "$JobQueueUri${Separator}peekonly=true&numofmessages=$BatchSize&format=json" + $Response = Invoke-RestMethod -Uri $Uri -Method Get -ErrorAction Stop + + $Messages = @() + if ($null -ne $Response.QueueMessages) { + $Messages = @($Response.QueueMessages) + } elseif ($null -ne $Response.QueueMessage) { + $Messages = @($Response.QueueMessage) + } + + if ($Messages.Count -eq 0) { break } + + foreach ($Message in $Messages) { + $BodyText = [string]($Message.MessageText ?? $Message.messageText ?? '') + if ([string]::IsNullOrWhiteSpace($BodyText)) { continue } + + try { + $EnvelopeJson = [System.Text.Encoding]::UTF8.GetString([Convert]::FromBase64String($BodyText)) + $Envelope = $EnvelopeJson | ConvertFrom-Json + if (-not $Envelope.IV -or -not $Envelope.Content) { continue } + + $Aes = [System.Security.Cryptography.Aes]::Create() + try { + $Aes.Mode = [System.Security.Cryptography.CipherMode]::CBC + $Aes.Padding = [System.Security.Cryptography.PaddingMode]::PKCS7 + $Aes.Key = $KeyBytes + $Aes.IV = [Convert]::FromBase64String([string]$Envelope.IV) + $Decryptor = $Aes.CreateDecryptor() + $Cipher = [Convert]::FromBase64String([string]$Envelope.Content) + $PlainBytes = $Decryptor.TransformFinalBlock($Cipher, 0, $Cipher.Length) + $PlainJson = [System.Text.Encoding]::UTF8.GetString($PlainBytes) + } finally { + $Aes.Dispose() + } + + if ([string]::IsNullOrWhiteSpace($PlainJson)) { continue } + [void]$Logs.Add(($PlainJson | ConvertFrom-Json)) + } catch { + continue + } + } + + $Remaining -= $Messages.Count + $Page++ + if ($Messages.Count -lt $BatchSize) { break } + } + + return @($Logs) +} diff --git a/Modules/CIPPCore/Public/Get-CIPPSharePointLibraryCopyOperation.ps1 b/Modules/CIPPCore/Public/Get-CIPPSharePointLibraryCopyOperation.ps1 new file mode 100644 index 0000000000000..862453ff6ed70 --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPSharePointLibraryCopyOperation.ps1 @@ -0,0 +1,60 @@ +function Get-CIPPSharePointLibraryCopyOperation { + <# + .SYNOPSIS + Loads a SharePointLibraryCopy operation row and reassembles chunked CopyJobInfo handles. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [Parameter(Mandatory = $true)] + [string]$OperationId + ) + + $Table = Get-CIPPTable -TableName 'SharePointLibraryCopy' + $SafeTenant = $TenantFilter -replace "'", "''" + $SafeOp = $OperationId -replace "'", "''" + $Primary = @(Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq '$SafeTenant' and RowKey eq '$SafeOp'") | Select-Object -First 1 + if (-not $Primary) { + return $null + } + + $ChunkRows = @(Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq '$SafeTenant' and startswith(RowKey, '$SafeOp`_')") | + Sort-Object RowKey + + $HandlesParts = [System.Collections.Generic.List[string]]::new() + if ($Primary.CopyJobInfos) { [void]$HandlesParts.Add([string]$Primary.CopyJobInfos) } + foreach ($Chunk in $ChunkRows) { + if ($Chunk.CopyJobInfos) { [void]$HandlesParts.Add([string]$Chunk.CopyJobInfos) } + } + + $HandlesJson = -join $HandlesParts + $CopyJobInfos = @() + if (-not [string]::IsNullOrWhiteSpace($HandlesJson)) { + $CopyJobInfos = @($HandlesJson | ConvertFrom-Json) + } + + $HandleStates = @() + if ($Primary.HandleStates) { + $HandleStates = @($Primary.HandleStates | ConvertFrom-Json) + } + + [PSCustomObject]@{ + PartitionKey = $Primary.PartitionKey + RowKey = $Primary.RowKey + OperationId = $OperationId + SourceSiteUrl = $Primary.SourceSiteUrl + SourceSiteName = $Primary.SourceSiteName + SourceLibraryName = $Primary.SourceLibraryName + DestSiteName = $Primary.DestSiteName + DestLibraryName = $Primary.DestLibraryName + StartedBy = $Primary.StartedBy + Status = $Primary.Status + JobHandleCount = [int]$Primary.JobHandleCount + Expiry = $Primary.Expiry + CopyJobInfos = @($CopyJobInfos) + HandleStates = @($HandleStates) + SanitizedSnapshot = if ($Primary.SanitizedSnapshot) { $Primary.SanitizedSnapshot | ConvertFrom-Json } else { $null } + } +} diff --git a/Modules/CIPPCore/Public/Get-CIPPSharePointLibraryRootChildUris.ps1 b/Modules/CIPPCore/Public/Get-CIPPSharePointLibraryRootChildUris.ps1 new file mode 100644 index 0000000000000..e337dcc2d3aa9 --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPSharePointLibraryRootChildUris.ps1 @@ -0,0 +1,80 @@ +function Get-CIPPSharePointLibraryRootChildUris { + <# + .SYNOPSIS + Enumerates eligible immediate children of a document library root for CreateCopyJobs. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [Parameter(Mandatory = $true)] + [string]$ListId, + + [string]$SiteUrl, + [string]$SiteId + ) + + if ([string]::IsNullOrWhiteSpace($SiteId)) { + if ([string]::IsNullOrWhiteSpace($SiteUrl)) { + throw 'SiteUrl or SiteId is required.' + } + $ParsedUrl = [System.Uri]$SiteUrl + $SiteSegment = if ($ParsedUrl.AbsolutePath -in @('', '/')) { + $ParsedUrl.Host + } else { + "$($ParsedUrl.Host):$($ParsedUrl.AbsolutePath):" + } + $SiteMeta = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/sites/$SiteSegment`?`$select=id" -tenantid $TenantFilter -asapp $true + $SiteId = $SiteMeta.id + } + + $Uris = [System.Collections.Generic.List[string]]::new() + $GraphUri = "https://graph.microsoft.com/v1.0/sites/$SiteId/lists/$ListId/drive/root/children?`$select=name,webUrl,folder,file&`$top=999" + + try { + $Children = @(New-GraphGetRequest -uri $GraphUri -tenantid $TenantFilter -asapp $true) + foreach ($Child in $Children) { + $Name = [string]$Child.name + if ([string]::IsNullOrWhiteSpace($Name) -or $Name -eq 'Forms' -or $Name.StartsWith('_') -or $Name -match '\.(aspx|dotx)$') { + continue + } + if ([string]::IsNullOrWhiteSpace($Child.webUrl)) { continue } + if (-not ($Child.folder -or $Child.file)) { continue } + $Uris.Add([string]$Child.webUrl) + } + } catch { + $RootInfo = Resolve-CIPPSharePointLibraryRootUri -TenantFilter $TenantFilter -ListId $ListId -SiteUrl $SiteUrl -SiteId $SiteId + $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter + $Scope = "$($SharePointInfo.SharePointUrl)/.default" + $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } + $BaseUri = "$($RootInfo.SiteUrl)/_api" + $SafeListId = $ListId -replace "'", "''" + $EscapedDir = $RootInfo.ServerRelativeUrl -replace "'", "''" + $NextLink = "$BaseUri/web/lists(guid'$SafeListId')/items?`$filter=FileDirRef eq '$EscapedDir'&`$select=FileRef,FileLeafRef,FSObjType&`$top=5000" + + do { + $Page = New-GraphGetRequest -uri $NextLink -tenantid $TenantFilter -scope $Scope -extraHeaders $JsonAccept -UseCertificate -AsApp $true -noPagination + $Items = @($Page.value) + if ($Items.Count -eq 0 -and $Page.FileRef) { $Items = @($Page) } + + foreach ($Item in $Items) { + $Leaf = [string]$Item.FileLeafRef + if ([string]::IsNullOrWhiteSpace($Leaf) -or $Leaf -eq 'Forms' -or $Leaf.StartsWith('_') -or $Leaf -match '\.(aspx|dotx)$') { + continue + } + $FileRef = $Item.FileRef + if ([string]::IsNullOrWhiteSpace($FileRef)) { continue } + $Origin = ([System.Uri]$RootInfo.SiteUrl).GetLeftPart([System.UriPartial]::Authority) + $Uris.Add("$Origin$FileRef") + } + + $NextLink = $Page.'@odata.nextLink' + } while (-not [string]::IsNullOrWhiteSpace($NextLink)) + } + + [PSCustomObject]@{ + ChildUris = @($Uris) + EligibleRootCount = $Uris.Count + } +} diff --git a/Modules/CIPPCore/Public/Get-CIPPSharePointSiteUsageReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPSharePointSiteUsageReport.ps1 index f5b2def74674a..6556c06095c27 100644 --- a/Modules/CIPPCore/Public/Get-CIPPSharePointSiteUsageReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPSharePointSiteUsageReport.ps1 @@ -1,155 +1,94 @@ -function Get-CIPPSharePointSiteUsageReport { - <# - .SYNOPSIS - Generates a SharePoint site usage report from the CIPP Reporting database - - .DESCRIPTION - Retrieves cached SharePoint site listing and usage data and combines them to match - the payload shape of Invoke-ListSites for Type=SharePointSiteUsage. - - .PARAMETER TenantFilter - The tenant to generate the report for - #> - [CmdletBinding()] - param( - [Parameter(Mandatory = $true)] - [string]$TenantFilter - ) - - try { - if ($TenantFilter -eq 'AllTenants') { - # Bulk-fetch all site listings and usage data in 2 queries instead of per-tenant - $AllSiteItems = @(Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'SharePointSiteListing' | Where-Object { $_.RowKey -ne 'SharePointSiteListing-Count' }) - $AllUsageItems = @(Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'SharePointSiteUsage' | Where-Object { $_.RowKey -ne 'SharePointSiteUsage-Count' }) - - $TenantList = Get-Tenants -IncludeErrors - $ValidTenants = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) - foreach ($T in $TenantList) { [void]$ValidTenants.Add($T.defaultDomainName) } - - # Build usage lookup keyed by siteId across all tenants - $UsageBySiteId = [System.Collections.Generic.Dictionary[string, object]]::new([System.StringComparer]::OrdinalIgnoreCase) - foreach ($UsageItem in $AllUsageItems) { - $UsageRow = $UsageItem.Data | ConvertFrom-Json -Depth 10 - if (-not [string]::IsNullOrWhiteSpace($UsageRow.siteId)) { - $UsageBySiteId[[string]$UsageRow.siteId] = $UsageRow - } - } - - $AllResults = [System.Collections.Generic.List[PSCustomObject]]::new() - foreach ($SiteItem in $AllSiteItems) { - $Tenant = $SiteItem.PartitionKey - if (-not $ValidTenants.Contains($Tenant)) { continue } - - $Site = $SiteItem.Data | ConvertFrom-Json -Depth 10 - if ($Site.isPersonalSite -eq $true) { continue } - - $SiteUsage = $null - [void]$UsageBySiteId.TryGetValue([string]$Site.sharepointIds.siteId, [ref]$SiteUsage) - - # A site with no usage row has UNKNOWN storage, not zero storage. Coercing the - # null to 0 made those sites render an authoritative-looking '0' that is - # indistinguishable from a genuinely empty site, so leave them null and let the - # table show them as having no data. - $StorageUsedInGigabytes = if ($null -ne $SiteUsage.storageUsedInBytes) { [math]::round([double]$SiteUsage.storageUsedInBytes / 1GB, 2) } else { $null } - $StorageAllocatedInGigabytes = if ($null -ne $SiteUsage.storageAllocatedInBytes) { [math]::round([double]$SiteUsage.storageAllocatedInBytes / 1GB, 2) } else { $null } - - $AllResults.Add([PSCustomObject]@{ - Tenant = $Tenant - siteId = $Site.sharepointIds.siteId - webId = $Site.sharepointIds.webId - createdDateTime = $Site.createdDateTime - displayName = $Site.displayName - webUrl = $Site.webUrl - ownerDisplayName = $SiteUsage.ownerDisplayName - ownerPrincipalName = $SiteUsage.ownerPrincipalName - lastActivityDate = $SiteUsage.lastActivityDate - fileCount = $SiteUsage.fileCount - storageUsedInGigabytes = $StorageUsedInGigabytes - storageAllocatedInGigabytes = $StorageAllocatedInGigabytes - storageUsedInBytes = $SiteUsage.storageUsedInBytes - storageAllocatedInBytes = $SiteUsage.storageAllocatedInBytes - rootWebTemplate = $SiteUsage.rootWebTemplate - reportRefreshDate = $SiteUsage.reportRefreshDate - AutoMapUrl = $Site.AutoMapUrl - }) - } - return $AllResults - } - - $SiteItems = @(Get-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSiteListing' | Where-Object { $_.RowKey -ne 'SharePointSiteListing-Count' }) - if (-not $SiteItems) { - throw 'No SharePoint site listing data found in reporting database. Sync SharePointSiteUsage cache first.' - } - - # No usage rows is a valid cached result, not a missing cache: getSharePointSiteUsageDetail - # returns an empty set for tenants Microsoft has no usage report for yet. The site listing - # is the backbone of this payload and the usage merge below is a left join, so an empty - # usage set yields the same rows-with-null-usage the live path returns. Throwing here made - # the single-tenant cached view fail on tenants the live view and the AllTenants branch of - # this same function both render fine. - $UsageItems = @(Get-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSiteUsage' | Where-Object { $_.RowKey -ne 'SharePointSiteUsage-Count' }) - - $LatestSiteTimestamp = ($SiteItems | Where-Object { $_.Timestamp } | Sort-Object Timestamp -Descending | Select-Object -First 1).Timestamp - $LatestUsageTimestamp = ($UsageItems | Where-Object { $_.Timestamp } | Sort-Object Timestamp -Descending | Select-Object -First 1).Timestamp - $CacheTimestamp = if ($LatestSiteTimestamp -and $LatestUsageTimestamp) { - if ($LatestSiteTimestamp -gt $LatestUsageTimestamp) { $LatestSiteTimestamp } else { $LatestUsageTimestamp } - } else { - $LatestSiteTimestamp ?? $LatestUsageTimestamp - } - - $UsageBySiteId = [System.Collections.Generic.Dictionary[string, object]]::new([System.StringComparer]::OrdinalIgnoreCase) - foreach ($UsageItem in $UsageItems) { - $UsageRow = $UsageItem.Data | ConvertFrom-Json -Depth 10 - if (-not [string]::IsNullOrWhiteSpace($UsageRow.siteId)) { - $UsageBySiteId[[string]$UsageRow.siteId] = $UsageRow - } - } - - $Report = [System.Collections.Generic.List[PSCustomObject]]::new() - foreach ($SiteItem in $SiteItems) { - $Site = $SiteItem.Data | ConvertFrom-Json -Depth 10 - if ($Site.isPersonalSite -eq $true) { - continue - } - - $SiteUsage = $null - [void]$UsageBySiteId.TryGetValue([string]$Site.sharepointIds.siteId, [ref]$SiteUsage) - - # Unknown storage stays null rather than becoming a misleading 0 - see the - # AllTenants branch above. - $StorageUsedInGigabytes = if ($null -ne $SiteUsage.storageUsedInBytes) { [math]::round([double]$SiteUsage.storageUsedInBytes / 1GB, 2) } else { $null } - $StorageAllocatedInGigabytes = if ($null -ne $SiteUsage.storageAllocatedInBytes) { [math]::round([double]$SiteUsage.storageAllocatedInBytes / 1GB, 2) } else { $null } - - $ReportItem = [PSCustomObject]@{ - siteId = $Site.sharepointIds.siteId - webId = $Site.sharepointIds.webId - createdDateTime = $Site.createdDateTime - displayName = $Site.displayName - webUrl = $Site.webUrl - ownerDisplayName = $SiteUsage.ownerDisplayName - ownerPrincipalName = $SiteUsage.ownerPrincipalName - lastActivityDate = $SiteUsage.lastActivityDate - fileCount = $SiteUsage.fileCount - storageUsedInGigabytes = $StorageUsedInGigabytes - storageAllocatedInGigabytes = $StorageAllocatedInGigabytes - storageUsedInBytes = $SiteUsage.storageUsedInBytes - storageAllocatedInBytes = $SiteUsage.storageAllocatedInBytes - rootWebTemplate = $SiteUsage.rootWebTemplate - reportRefreshDate = $SiteUsage.reportRefreshDate - AutoMapUrl = $Site.AutoMapUrl - } - - if ($CacheTimestamp) { - $ReportItem | Add-Member -NotePropertyName 'CacheTimestamp' -NotePropertyValue $CacheTimestamp -Force - } - - $Report.Add($ReportItem) - } - - return $Report | Sort-Object -Property displayName - - } catch { - Write-LogMessage -API 'SharePointSiteUsageReport' -tenant $TenantFilter -message "Failed to generate SharePoint site usage report: $($_.Exception.Message)" -sev Error -LogData (Get-CippException -Exception $_) - throw - } -} \ No newline at end of file +function Get-CIPPSharePointSiteUsageReport { + <# + .SYNOPSIS + Generates a SharePoint site usage report from the CIPP Reporting database + + .DESCRIPTION + Retrieves cached SharePoint site listing and usage data and combines them to match + the payload shape of Invoke-ListSites for Type=SharePointSiteUsage. + + .PARAMETER TenantFilter + The tenant to generate the report for + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter + ) + + try { + if ($TenantFilter -eq 'AllTenants') { + $AllSiteItems = @(Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'SharePointSiteListing' | Where-Object { $_.RowKey -ne 'SharePointSiteListing-Count' }) + $AllUsageItems = @(Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'SharePointSiteUsage' | Where-Object { $_.RowKey -ne 'SharePointSiteUsage-Count' }) + + $TenantList = Get-Tenants -IncludeErrors + $ValidTenants = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + foreach ($T in $TenantList) { [void]$ValidTenants.Add($T.defaultDomainName) } + + $UsageBySiteId = [System.Collections.Generic.Dictionary[string, object]]::new([System.StringComparer]::OrdinalIgnoreCase) + foreach ($UsageItem in $AllUsageItems) { + $UsageRow = $UsageItem.Data | ConvertFrom-Json -Depth 10 + if (-not [string]::IsNullOrWhiteSpace($UsageRow.siteId)) { + $UsageBySiteId[[string]$UsageRow.siteId.Trim('{}')] = $UsageRow + } + } + + $AllResults = [System.Collections.Generic.List[PSCustomObject]]::new() + foreach ($SiteItem in $AllSiteItems) { + $Tenant = $SiteItem.PartitionKey + if (-not $ValidTenants.Contains($Tenant)) { continue } + + $Site = $SiteItem.Data | ConvertFrom-Json -Depth 10 + if ($Site.isPersonalSite -eq $true) { continue } + + $SiteUsage = $null + [void]$UsageBySiteId.TryGetValue([string]$Site.sharepointIds.siteId.Trim('{}'), [ref]$SiteUsage) + + $AllResults.Add((ConvertTo-CIPPSharePointSiteUsagePayload -Site $Site -SiteUsage $SiteUsage -Tenant $Tenant)) + } + return $AllResults + } + + $SiteItems = @(Get-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSiteListing' | Where-Object { $_.RowKey -ne 'SharePointSiteListing-Count' }) + if (-not $SiteItems) { + throw 'No SharePoint site listing data found in reporting database. Sync SharePointSiteUsage cache first.' + } + + $UsageItems = @(Get-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSiteUsage' | Where-Object { $_.RowKey -ne 'SharePointSiteUsage-Count' }) + + $LatestSiteTimestamp = ($SiteItems | Where-Object { $_.Timestamp } | Sort-Object Timestamp -Descending | Select-Object -First 1).Timestamp + $LatestUsageTimestamp = ($UsageItems | Where-Object { $_.Timestamp } | Sort-Object Timestamp -Descending | Select-Object -First 1).Timestamp + $CacheTimestamp = if ($LatestSiteTimestamp -and $LatestUsageTimestamp) { + if ($LatestSiteTimestamp -gt $LatestUsageTimestamp) { $LatestSiteTimestamp } else { $LatestUsageTimestamp } + } else { + $LatestSiteTimestamp ?? $LatestUsageTimestamp + } + + $UsageBySiteId = [System.Collections.Generic.Dictionary[string, object]]::new([System.StringComparer]::OrdinalIgnoreCase) + foreach ($UsageItem in $UsageItems) { + $UsageRow = $UsageItem.Data | ConvertFrom-Json -Depth 10 + if (-not [string]::IsNullOrWhiteSpace($UsageRow.siteId)) { + $UsageBySiteId[[string]$UsageRow.siteId.Trim('{}')] = $UsageRow + } + } + + $Report = [System.Collections.Generic.List[PSCustomObject]]::new() + foreach ($SiteItem in $SiteItems) { + $Site = $SiteItem.Data | ConvertFrom-Json -Depth 10 + if ($Site.isPersonalSite -eq $true) { + continue + } + + $SiteUsage = $null + [void]$UsageBySiteId.TryGetValue([string]$Site.sharepointIds.siteId.Trim('{}'), [ref]$SiteUsage) + + $Report.Add((ConvertTo-CIPPSharePointSiteUsagePayload -Site $Site -SiteUsage $SiteUsage -CacheTimestamp $CacheTimestamp)) + } + + return $Report | Sort-Object -Property displayName + + } catch { + Write-LogMessage -API 'SharePointSiteUsageReport' -tenant $TenantFilter -message "Failed to generate SharePoint site usage report: $($_.Exception.Message)" -sev Error -LogData (Get-CippException -Exception $_) + throw + } +} diff --git a/Modules/CIPPCore/Public/Get-CIPPSharePointSiteUsageRows.ps1 b/Modules/CIPPCore/Public/Get-CIPPSharePointSiteUsageRows.ps1 new file mode 100644 index 0000000000000..7a8e7fcb6ed9f --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPSharePointSiteUsageRows.ps1 @@ -0,0 +1,189 @@ +function Get-CIPPSharePointSiteUsageRows { + <# + .SYNOPSIS + Builds SharePoint site listing and usage rows from SPO admin RLD plus Graph enrichment. + + .DESCRIPTION + Active sites and usage metrics come from SPO admin RenderAdminListData. Graph getAllSites + supplies webId and composite ids; an optional Get-CIPPSPOSite pass adds file-level archive + fields; a Graph lists bulk pass fills AutoMapUrl. Used by the site usage cache collector + and the live Invoke-ListSites SharePoint path. + + .PARAMETER TenantFilter + Tenant to query. + + .PARAMETER IncludeArchive + When set, merges ArchivedFileDiskUsed and AllowFileArchive from Get-CIPPSPOSite. + + .PARAMETER LogApi + API name passed to Write-LogMessage for warnings and errors. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [switch]$IncludeArchive, + + [string]$LogApi = 'SharePointSiteUsage' + ) + + $Tenant = Get-Tenants -TenantFilter $TenantFilter + $TenantId = $Tenant.customerId + $ReportRefreshDate = (Get-Date).ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:ssZ') + + $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter + $AdminRows = @(Get-CIPPSPOAdminListData -TenantFilter $TenantFilter -AdminUrl $SharePointInfo.AdminUrl -Type SharePoint) + + $GraphBulk = New-GraphBulkRequest -tenantid $TenantFilter -Requests @( + @{ + id = 'listAllSites' + method = 'GET' + url = "sites/getAllSites?`$filter=isPersonalSite eq false&`$select=id,createdDateTime,description,name,displayName,isPersonalSite,lastModifiedDateTime,webUrl,siteCollection,sharepointIds&`$top=999" + } + ) -asapp $true + $SitesResponse = @($GraphBulk | Where-Object { $_.id -eq 'listAllSites' }) | Select-Object -First 1 + if ($null -eq $SitesResponse) { + throw 'getAllSites response missing from Graph bulk batch' + } + if ($SitesResponse.status -and $SitesResponse.status -ne 200) { + throw ($SitesResponse.body.error.message ?? "getAllSites failed with status $($SitesResponse.status)") + } + + $GraphBySiteId = [System.Collections.Generic.Dictionary[string, object]]::new([System.StringComparer]::OrdinalIgnoreCase) + $GraphByWebUrl = [System.Collections.Generic.Dictionary[string, object]]::new([System.StringComparer]::OrdinalIgnoreCase) + foreach ($GraphSite in @($SitesResponse.body.value)) { + if ($null -eq $GraphSite) { continue } + $Guid = [string]$GraphSite.sharepointIds.siteId + if (-not [string]::IsNullOrWhiteSpace($Guid)) { + $GraphBySiteId[$Guid.Trim('{}').ToLowerInvariant()] = $GraphSite + } + if (-not [string]::IsNullOrWhiteSpace($GraphSite.webUrl)) { + $GraphByWebUrl[$GraphSite.webUrl.TrimEnd('/').ToLowerInvariant()] = $GraphSite + } + } + + $ArchiveByUrl = [System.Collections.Generic.Dictionary[string, object]]::new([System.StringComparer]::OrdinalIgnoreCase) + if ($IncludeArchive) { + try { + foreach ($SpoSite in @(Get-CIPPSPOSite -TenantFilter $TenantFilter)) { + if ([string]::IsNullOrWhiteSpace($SpoSite.Url)) { continue } + $ArchiveByUrl[$SpoSite.Url.TrimEnd('/').ToLowerInvariant()] = @{ + archivedFileDiskUsedBytes = $SpoSite.ArchivedFileDiskUsed + allowFileArchive = $SpoSite.AllowFileArchive + } + } + } catch { + if ($_.Exception.Data['SPOAccessDenied']) { + Write-LogMessage -API $LogApi -tenant $TenantFilter -message $_.Exception.Message -sev Warning + } else { + Write-LogMessage -API $LogApi -tenant $TenantFilter -message "SharePoint file archive enrichment skipped: $($_.Exception.Message)" -sev Warning -LogData (Get-CippException -Exception $_) + } + } + } + + $SiteListing = [System.Collections.Generic.List[object]]::new() + $UsageRows = [System.Collections.Generic.List[object]]::new() + + foreach ($Row in $AdminRows) { + if ($null -eq $Row) { continue } + + $RowUrl = [string]$Row.SiteUrl + $RowTitle = [string]$Row.Title + $RowSiteId = ([string]$Row.SiteId).Trim('{}') + if ([string]::IsNullOrWhiteSpace($RowSiteId) -and [string]::IsNullOrWhiteSpace($RowUrl)) { continue } + + $GraphSite = $null + if (-not [string]::IsNullOrWhiteSpace($RowSiteId)) { + $GraphSite = $GraphBySiteId[$RowSiteId.ToLowerInvariant()] + } + if (-not $GraphSite -and $RowUrl) { + $GraphSite = $GraphByWebUrl[$RowUrl.TrimEnd('/').ToLowerInvariant()] + } + + $SiteGuid = if ($GraphSite -and $GraphSite.sharepointIds.siteId) { [string]$GraphSite.sharepointIds.siteId } else { $RowSiteId } + $SiteGuid = $SiteGuid.Trim('{}') + if ([string]::IsNullOrWhiteSpace($SiteGuid)) { continue } + + $OwnerEmail = [string]$Row.SiteOwnerEmail + $OwnerName = [string]$Row.SiteOwnerName + if ([string]::IsNullOrWhiteSpace($OwnerName)) { $OwnerName = $OwnerEmail } + + $ListingItem = [PSCustomObject]@{ + id = $(if ($GraphSite -and $GraphSite.id) { $GraphSite.id } else { $SiteGuid }) + sharepointIds = [PSCustomObject]@{ + siteId = $SiteGuid + webId = $(if ($GraphSite -and $GraphSite.sharepointIds.webId) { $GraphSite.sharepointIds.webId } else { $null }) + } + createdDateTime = $(if ($Row.TimeCreated) { $Row.TimeCreated } elseif ($GraphSite) { $GraphSite.createdDateTime } else { $null }) + displayName = $(if ($RowTitle) { $RowTitle } elseif ($GraphSite) { $GraphSite.displayName } else { $SiteGuid }) + webUrl = $(if ($RowUrl) { $RowUrl } elseif ($GraphSite) { $GraphSite.webUrl } else { $null }) + isPersonalSite = $false + AutoMapUrl = '' + } + + if ($IncludeArchive -and -not [string]::IsNullOrWhiteSpace($ListingItem.webUrl)) { + $ArchiveFields = $null + if ($ArchiveByUrl.TryGetValue($ListingItem.webUrl.TrimEnd('/').ToLowerInvariant(), [ref]$ArchiveFields)) { + $ListingItem | Add-Member -NotePropertyMembers ([ordered]@{ + archivedFileDiskUsedBytes = $ArchiveFields.archivedFileDiskUsedBytes + allowFileArchive = $ArchiveFields.allowFileArchive + }) -Force + } + } + + [void]$SiteListing.Add($ListingItem) + + $UsageRows.Add([PSCustomObject]@{ + id = $SiteGuid + siteId = $SiteGuid + ownerDisplayName = $OwnerName + ownerPrincipalName = $OwnerEmail + lastActivityDate = $Row.LastActivityOn + fileCount = $Row.NumOfFiles + storageUsedInBytes = $Row.StorageUsed + storageAllocatedInBytes = $Row.StorageQuotaBytes + rootWebTemplate = ConvertTo-SPOUsageRootWebTemplate -TemplateName ([string]$Row.TemplateName) + reportRefreshDate = $ReportRefreshDate + }) + } + + $RequestId = 0 + $ListRequests = foreach ($Site in $SiteListing) { + if (-not $Site.sharepointIds.siteId) { continue } + @{ + id = $RequestId++ + method = 'GET' + url = "sites/$($Site.sharepointIds.siteId)/lists?`$select=id,name,list,parentReference" + } + } + + $ListIdBySiteKey = @{} + if (@($ListRequests).Count -gt 0) { + try { + $LibraryLists = (New-GraphBulkRequest -tenantid $TenantFilter -scope 'https://graph.microsoft.com/.default' -Requests @($ListRequests) -asapp $true).body.value + foreach ($List in @($LibraryLists)) { + if ($List.list.template -ne 'DocumentLibrary') { continue } + $ParentSiteId = $List.parentReference.siteId + if (-not $ParentSiteId) { continue } + foreach ($Key in ([string]$ParentSiteId -split ',')) { + if ($Key -and -not $ListIdBySiteKey.ContainsKey($Key)) { $ListIdBySiteKey[$Key] = $List.id } + } + } + $LibraryLists = $null + } catch { + Write-LogMessage -Message "Error getting auto map urls for SharePoint site usage: $($_.Exception.Message)" -Sev 'Error' -tenant $TenantFilter -API $LogApi -LogData (Get-CippException -Exception $_) + } + } + + foreach ($Site in $SiteListing) { + $SiteKey = [string]$Site.sharepointIds.siteId + $ListId = if ($SiteKey) { $ListIdBySiteKey[$SiteKey] } else { $null } + $Site.AutoMapUrl = "tenantId=$($TenantId)&webId={$($Site.sharepointIds.webId)}&siteid={$($Site.sharepointIds.siteId)}&webUrl=$($Site.webUrl)&listId={$ListId}" + } + + return [PSCustomObject]@{ + SiteListing = $SiteListing + UsageRows = $UsageRows + } +} diff --git a/Modules/CIPPCore/Public/Get-CIPPTenantAllowBlockListReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPTenantAllowBlockListReport.ps1 index a7e0e98096f77..8f61799da526c 100644 --- a/Modules/CIPPCore/Public/Get-CIPPTenantAllowBlockListReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPTenantAllowBlockListReport.ps1 @@ -43,9 +43,11 @@ function Get-CIPPTenantAllowBlockListReport { $Entries = [System.Collections.Generic.List[PSCustomObject]]::new() foreach ($Row in $Rows) { $Entry = $Row.Data | ConvertFrom-Json - $Entry | Add-Member -NotePropertyName 'Tenant' -NotePropertyValue $Row.PartitionKey -Force - # Per row rather than per report: each tenant is cached on its own schedule. - $Entry | Add-Member -NotePropertyName 'CacheTimestamp' -NotePropertyValue $Row.Timestamp -Force + $Entry | Add-Member -NotePropertyMembers ([ordered]@{ + Tenant = $Row.PartitionKey + # Per row rather than per report: each tenant is cached on its own schedule. + CacheTimestamp = $Row.Timestamp + }) -Force $Entries.Add($Entry) } diff --git a/Modules/CIPPCore/Public/Get-CippDbRole.ps1 b/Modules/CIPPCore/Public/Get-CippDbRole.ps1 index 5c38f0eb63a43..a416f9cff937a 100644 --- a/Modules/CIPPCore/Public/Get-CippDbRole.ps1 +++ b/Modules/CIPPCore/Public/Get-CippDbRole.ps1 @@ -13,39 +13,15 @@ function Get-CippDbRole { $Roles = Get-CIPPTestData -TenantFilter $TenantFilter -Type 'Roles' + # The id lists live in Get-CIPPPrivilegedRoleTemplateIds so every "privileged roles" scope in + # CIPP (tests, PIM pages, standards, alerts) means the same roles. if ($IncludePrivilegedRoles) { - $PrivilegedRoleTemplateIds = @( - '62e90394-69f5-4237-9190-012177145e10', - '194ae4cb-b126-40b2-bd5b-6091b380977d', - '9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3', - 'e8611ab8-c189-46e8-94e1-60213ab1f814', - '29232cdf-9323-42fd-ade2-1d097af3e4de', - 'b1be1c3e-b65d-4f19-8427-f6fa0d97feb9', - 'f28a1f50-f6e7-4571-818b-6a12f2af6b6c', - 'fe930be7-5e62-47db-91af-98c3a49a38b1', - '729827e3-9c14-49f7-bb1b-9608f156bbb8', - '966707d0-3269-4727-9be2-8c3a10f19b9d', - 'b0f54661-2d74-4c50-afa3-1ec803f12efe', - '7be44c8a-adaf-4e2a-84d6-ab2649e08a13', - '158c047a-c907-4556-b7ef-446551a6b5f7', - 'c4e39bd9-1100-46d3-8c65-fb160da0071f', - '9f06204d-73c1-4d4c-880a-6edb90606fd8', - '17315797-102d-40b4-93e0-432062caca18', - '4a5d8f65-41da-4de4-8968-e035b65339cf', - '75941009-915a-4869-abe7-691bff18279e' - ) + $PrivilegedRoleTemplateIds = Get-CIPPPrivilegedRoleTemplateIds -Set Privileged $Roles = $Roles | Where-Object { $PrivilegedRoleTemplateIds -contains $_.RoletemplateId } } if ($CisaHighlyPrivilegedRoles) { - $CisaRoleTemplateIds = @( - '62e90394-69f5-4237-9190-012177145e10', - '9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3', - '29232cdf-9323-42fd-ade2-1d097af3e4de', - '729827e3-9c14-49f7-bb1b-9608f156bbb8', - '966707d0-3269-4727-9be2-8c3a10f19b9d', - 'b0f54661-2d74-4c50-afa3-1ec803f12efe' - ) + $CisaRoleTemplateIds = Get-CIPPPrivilegedRoleTemplateIds -Set CisaHighlyPrivileged $Roles = $Roles | Where-Object { $CisaRoleTemplateIds -contains $_.RoletemplateId } } diff --git a/Modules/CIPPCore/Public/Get-CippTestDataFieldManifest.ps1 b/Modules/CIPPCore/Public/Get-CippTestDataFieldManifest.ps1 index b0598ac101d4d..76b010f8bb364 100644 --- a/Modules/CIPPCore/Public/Get-CippTestDataFieldManifest.ps1 +++ b/Modules/CIPPCore/Public/Get-CippTestDataFieldManifest.ps1 @@ -129,7 +129,7 @@ function Get-CippTestDataFieldManifest { 'IntuneDeviceConfigurations' = @('@odata.type', 'displayName', 'assignments', 'qualityUpdatesDeferralPeriodInDays', 'fileVaultEnabled', 'wiFiSecurityType') 'IntuneDeviceEnrollmentConfigurations' = @('@odata.type', 'displayName', 'priority', 'deviceEnrollmentConfigurationType', 'assignments', 'androidForWorkRestriction', 'androidRestriction', 'iosRestriction', 'macOSRestriction', 'windowsRestriction') 'LicenseOverview' = @('License', 'TotalLicenses', 'CountUsed', 'ServicePlans', 'AssignedUsers', 'TermInfo') - 'Mailboxes' = @('UPN', 'UserPrincipalName', 'displayName', 'recipientTypeDetails', 'ExternalDirectoryObjectId', 'AuditEnabled', 'AuditOwner', 'AuditBypassEnabled', 'WhenSoftDeleted', 'LitigationHoldEnabled', 'LicensedForLitigationHold', 'ComplianceTagHoldApplied', 'RetentionPolicy', 'InPlaceHolds') + 'Mailboxes' = @('UPN', 'UserPrincipalName', 'displayName', 'recipientTypeDetails', 'ExternalDirectoryObjectId', 'AuditEnabled', 'AuditOwner', 'AuditDelegate', 'AuditAdmin', 'DefaultAuditSet', 'AuditBypassEnabled', 'WhenSoftDeleted', 'LitigationHoldEnabled', 'LicensedForLitigationHold', 'ComplianceTagHoldApplied', 'RetentionPolicy', 'InPlaceHolds') 'ManagedDevices' = @('deviceName', 'lastSyncDateTime', 'operatingSystem', 'osVersion') 'MDEOnboarding' = @('partnerState') 'MFAState' = @('UPN', 'userPrincipalName', 'DisplayName', 'AccountEnabled', 'UserType', 'IsAdmin', 'isLicensed', 'PerUser', 'PerUserMFAState', 'CoveredByCA', 'CoveredBySD', 'MFARegistration', 'MFACapable', 'MFAMethods') @@ -144,8 +144,8 @@ function Get-CippTestDataFieldManifest { # 'principal' is NOT read by any test file — Get-CippDbRoleMembers reads # $member.principal.displayName/.userPrincipalName. Omitting it would silently blank # every role member across the CIS/E8/ZTNA privileged-access tests. - 'RoleAssignmentScheduleInstances' = @('roleDefinitionId', 'assignmentType', 'memberType', 'endDateTime', 'principalId', 'principal') - 'RoleEligibilitySchedules' = @('roleDefinitionId', 'principalId', 'principal', 'scheduleInfo') + 'RoleAssignmentScheduleInstances' = @('id', 'roleDefinitionId', 'assignmentType', 'memberType', 'startDateTime', 'endDateTime', 'principalId', 'principal', 'directoryScopeId', 'roleAssignmentOriginId', 'roleAssignmentScheduleId') + 'RoleEligibilitySchedules' = @('id', 'roleDefinitionId', 'principalId', 'principal', 'scheduleInfo', 'directoryScopeId', 'memberType', 'status') # policyId, not id: this type is sourced from roleManagementPolicyAssignments (only the # assignment carries roleDefinitionId) and the policy is flattened up one level. 'RoleManagementPolicies' = @('policyId', 'scopeId', 'scopeType', 'roleDefinitionId', 'rules', 'effectiveRules') diff --git a/Modules/CIPPCore/Public/Get-DefenderCves.ps1 b/Modules/CIPPCore/Public/Get-DefenderCves.ps1 index 50b42f0e0960e..c97cad5bffea8 100644 --- a/Modules/CIPPCore/Public/Get-DefenderCves.ps1 +++ b/Modules/CIPPCore/Public/Get-DefenderCves.ps1 @@ -45,6 +45,9 @@ function get-DefenderCVEs { try { $CveId = $Vuln.cveId + # Skip TVM software-inventory rows with no CVE before the hashtable lookup; + # ContainsKey($null) throws and was logged per-record as an 'Allover Build' error. + if ([string]::IsNullOrWhiteSpace($CveId)) { $SkippedCount++; return } if (-not $CveAggregator.ContainsKey($CveId)) { # Establish global CVE & software properties for this specific tenant diff --git a/Modules/CIPPCore/Public/Get-DefenderTvmRaw.ps1 b/Modules/CIPPCore/Public/Get-DefenderTvmRaw.ps1 index 01ae9151fb0f6..c09e88666c22a 100644 --- a/Modules/CIPPCore/Public/Get-DefenderTvmRaw.ps1 +++ b/Modules/CIPPCore/Public/Get-DefenderTvmRaw.ps1 @@ -79,7 +79,8 @@ function Get-DefenderTvmRaw { return $all } catch { - Write-LogMessage -API 'DefenderTVM' -tenant $TenantId -message "Error on page $page`: $($_.Exception.Message)" -Sev 'Error' + $Sev = if (Test-CIPPCacheCapabilityError -Message $_.Exception.Message) { 'Debug' } else { 'Error' } + Write-LogMessage -API 'DefenderTVM' -tenant $TenantId -message "Error on page $page`: $($_.Exception.Message)" -Sev $Sev throw } } diff --git a/Modules/CIPPCore/Public/GraphHelper/Get-ClassicAPIToken.ps1 b/Modules/CIPPCore/Public/GraphHelper/Get-ClassicAPIToken.ps1 index 5c9954f8401c6..f3375364c5b46 100644 --- a/Modules/CIPPCore/Public/GraphHelper/Get-ClassicAPIToken.ps1 +++ b/Modules/CIPPCore/Public/GraphHelper/Get-ClassicAPIToken.ps1 @@ -12,11 +12,20 @@ function Get-ClassicAPIToken($tenantID, $Resource) { $uri = "https://login.microsoftonline.com/$($TenantID)/oauth2/token" $Body = @{ client_id = $env:ApplicationID - client_secret = $env:ApplicationSecret resource = $Resource refresh_token = $env:RefreshToken grant_type = 'refresh_token' } + # Certificate-exclusive auth: sign an assertion instead of sending the client secret. The + # audience must be the classic v1 token endpoint this request targets. + if ($env:CertificateAuthMode) { + $SAMCert = Get-CIPPSAMCertificate -ErrorAction Stop + if (-not $SAMCert) { throw 'Certificate authentication is enabled but no SAM certificate is available.' } + $Body.client_assertion_type = 'urn:ietf:params:oauth:client-assertion-type:jwt-bearer' + $Body.client_assertion = New-CIPPCertificateAssertion -TenantId $TenantID -AppId $env:ApplicationID -Certificate $SAMCert.Certificate -Audience $uri + } else { + $Body.client_secret = $env:ApplicationSecret + } try { if (!$script:classictoken) { $script:classictoken = [HashTable]::Synchronized(@{}) } $script:classictoken.$TokenKey = Invoke-CIPPRestMethod -Uri $uri -Body $body -ContentType 'application/x-www-form-urlencoded' -ErrorAction SilentlyContinue -Method post diff --git a/Modules/CIPPCore/Public/GraphHelper/Get-GraphToken.ps1 b/Modules/CIPPCore/Public/GraphHelper/Get-GraphToken.ps1 index fa9b948eebf34..3e549741a2ab5 100644 --- a/Modules/CIPPCore/Public/GraphHelper/Get-GraphToken.ps1 +++ b/Modules/CIPPCore/Public/GraphHelper/Get-GraphToken.ps1 @@ -18,6 +18,12 @@ function Get-GraphToken { if (!$scope) { $scope = 'https://graph.microsoft.com/.default' } if (!$tenantid) { $tenantid = $env:TenantID } + # Certificate-exclusive auth: force the SAM certificate for CIPP's own SAM app tokens (app-only and + # delegated). Scoped to the SAM app - explicit $AppID/$AppSecret callers use their own credentials. + if ($env:CertificateAuthMode -and -not $AppID -and -not $AppSecret) { + $UseCertificate = $true + } + $UseSharedTokenCache = ($SkipCache -ne $true) -and ($null -ne ('CIPP.CIPPTokenCache' -as [type])) # ── Fast path: check shared .NET token cache before any table lookups ── diff --git a/Modules/CIPPCore/Public/GraphHelper/Get-Tenants.ps1 b/Modules/CIPPCore/Public/GraphHelper/Get-Tenants.ps1 index 4c15c67838398..8c8680f7d43be 100644 --- a/Modules/CIPPCore/Public/GraphHelper/Get-Tenants.ps1 +++ b/Modules/CIPPCore/Public/GraphHelper/Get-Tenants.ps1 @@ -43,7 +43,8 @@ function Get-Tenants { $IncludedTenantFilter = [scriptblock]::Create("`$_.customerId -eq '$SafeTenantFilter'") $RelationshipFilter = " and customer/tenantId eq '$SafeTenantFilter'" } else { - $Filter = "{0} and defaultDomainName eq '{1}' or initialDomainName eq '{1}'" -f $Filter, $SafeTenantFilter + # parens: OData 'and' binds tighter than 'or', which would leave the initialDomainName clause unscoped + $Filter = "{0} and (defaultDomainName eq '{1}' or initialDomainName eq '{1}')" -f $Filter, $SafeTenantFilter $IncludedTenantFilter = [scriptblock]::Create("`$_.defaultDomainName -eq '$SafeTenantFilter' -or `$_.initialDomainName -eq '$SafeTenantFilter'") $RelationshipFilter = '' } @@ -94,6 +95,13 @@ function Get-Tenants { if (!$env:RefreshToken) { throw 'RefreshToken not set. Cannot get tenant list.' } + # GDAP relationship objects carry customerId, not domains, so a domain-scoped refresh must key + # on the customerId of the row already read above - otherwise it matches zero relationships. + $ResolvedCustomerId = ($IncludedTenantsCache | Select-Object -First 1).customerId + if ($TenantFilter -and -not $RelationshipFilter -and $ResolvedCustomerId) { + $RelationshipFilter = " and customer/tenantId eq '$ResolvedCustomerId'" + $IncludedTenantFilter = [scriptblock]::Create("`$_.customerId -eq '$ResolvedCustomerId'") + } #get the full list of tenants $GDAPRelationships = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/tenantRelationships/delegatedAdminRelationships?`$filter=status eq 'active'$RelationshipFilter&`$select=customer,autoExtendDuration,endDateTime" -NoAuthCheck:$true # Filter out MLT relationships locally @@ -118,6 +126,12 @@ function Get-Tenants { # Write-Host "Processing $($_.Name), $($_.displayName) to add to tenant list." $ExistingTenantInfo = Get-CIPPAzDataTableEntity @TenantsTable -Filter "PartitionKey eq 'Tenants' and RowKey eq '$($_.Name)'" + # Reset per tenant so a fallback on one tenant does not leak RequiresRefresh onto the next. + $RequiresRefresh = $false + + # Resolved before the cache-hit check below, which compares against its displayName. + $LatestRelationship = $_.Group | Sort-Object -Property relationshipEnd | Select-Object -Last 1 + $Alias = (Get-AzDataTableEntity @PropertiesTable -Filter "PartitionKey eq '$($_.Name)' and RowKey eq 'Alias'").Value if ($Alias) { @@ -131,7 +145,14 @@ function Get-Tenants { Add-CIPPAzDataTableEntity @TenantsTable -Entity $ExistingTenantInfo -Force | Out-Null } - if ($ExistingTenantInfo -and $ExistingTenantInfo.RequiresRefresh -eq $false -and ($ExistingTenantInfo.displayName -eq $LatestRelationship.displayName -or $ExistingTenantInfo.displayName -eq $Alias)) { + # Re-read domains for a row last derived over 7 days ago even when it looks healthy: a custom + # domain can be made default in M365 after onboarding with nothing here to signal it, and the + # cache-hit branch below never re-reads domains. LastRefresh is stamped only on a real fetch. + # (Table returns a DateTimeOffset; [datetime] cannot cast it. Null/garbage throws -> stale.) + try { $DomainsStale = ([DateTimeOffset]$ExistingTenantInfo.LastRefresh) -lt [DateTimeOffset]::UtcNow.AddDays(-7) } catch { $DomainsStale = $true } + + # A refresh scoped to one tenant is an explicit "re-read this one now" - never shortcut it. + if ($ExistingTenantInfo -and $ExistingTenantInfo.RequiresRefresh -eq $false -and -not $DomainsStale -and -not ($TriggerRefresh.IsPresent -and $TenantFilter) -and ($ExistingTenantInfo.displayName -eq $LatestRelationship.displayName -or $ExistingTenantInfo.displayName -eq $Alias)) { Write-Host 'Existing tenant found. We already have it cached, skipping.' $DisplayNameUpdated = $false @@ -157,7 +178,6 @@ function Get-Tenants { $ExistingTenantInfo return } - $LatestRelationship = $_.Group | Sort-Object -Property relationshipEnd | Select-Object -Last 1 $AutoExtend = ($_.Group | Where-Object { $_.autoExtend -eq $true } | Measure-Object).Count -gt 0 if (!$SkipDomains.IsPresent) { try { @@ -172,14 +192,17 @@ function Get-Tenants { Write-Host "Domain variable is $Domain" $Domain = (New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/tenantRelationships/findTenantInformationByTenantId(tenantId='$($LatestRelationship.customerId)')" -NoAuthCheck:$true ).defaultDomainName Write-Host "Alternative method worked, got domain $Domain." - $RequiresRefresh = $true } catch { $ErrorMessage = Get-CippException -Exception $_ Write-LogMessage -API 'Get-Tenants' -message "Tried adding $($LatestRelationship.customerId) to tenant list but failed to get domains - $($_.Exception.Message)" -Sev 'Critical' -LogData $ErrorMessage $Domain = 'Invalid' } finally { - $defaultDomainName = $Domain - $initialDomainName = $Domain + # Main read failed, so this value is provisional - always flag for retry. The fallback returns + # the initial (.onmicrosoft.com) domain for many tenants: keep a good cached custom default over it. + $RequiresRefresh = $true + $KeepCached = $ExistingTenantInfo.defaultDomainName -and $ExistingTenantInfo.defaultDomainName -notlike '*.onmicrosoft.com' + $defaultDomainName = if ($KeepCached) { $ExistingTenantInfo.defaultDomainName } else { $Domain } + $initialDomainName = if ($KeepCached) { $ExistingTenantInfo.initialDomainName } else { $Domain } } } Write-Host 'finished getting domain' diff --git a/Modules/CIPPCore/Public/GraphHelper/New-CIPPCertificateAssertion.ps1 b/Modules/CIPPCore/Public/GraphHelper/New-CIPPCertificateAssertion.ps1 index bda4ea3aa77e6..5769dc6627820 100644 --- a/Modules/CIPPCore/Public/GraphHelper/New-CIPPCertificateAssertion.ps1 +++ b/Modules/CIPPCore/Public/GraphHelper/New-CIPPCertificateAssertion.ps1 @@ -21,7 +21,11 @@ function New-CIPPCertificateAssertion { [string]$AppId, [Parameter(Mandatory = $true)] - [System.Security.Cryptography.X509Certificates.X509Certificate2]$Certificate + [System.Security.Cryptography.X509Certificates.X509Certificate2]$Certificate, + + # Token endpoint the assertion is presented to (the aud claim). Defaults to the v2 endpoint; + # the classic v1 endpoint (/oauth2/token) must be passed explicitly so the STS accepts it. + [string]$Audience = "https://login.microsoftonline.com/$TenantId/oauth2/v2.0/token" ) # get sha256 hash of certificate for the x5t#S256 header @@ -52,7 +56,7 @@ function New-CIPPCertificateAssertion { iss = $AppId # What endpoint is allowed to use this JWT - aud = "https://login.microsoftonline.com/$TenantId/oauth2/v2.0/token" + aud = $Audience # JWT ID: random guid jti = [guid]::NewGuid() diff --git a/Modules/CIPPCore/Public/GraphHelper/New-CIPPMFAConnectorToken.ps1 b/Modules/CIPPCore/Public/GraphHelper/New-CIPPMFAConnectorToken.ps1 new file mode 100644 index 0000000000000..994d7acb1e45b --- /dev/null +++ b/Modules/CIPPCore/Public/GraphHelper/New-CIPPMFAConnectorToken.ps1 @@ -0,0 +1,132 @@ +function New-CIPPMFAConnectorToken { + <# + .SYNOPSIS + Returns an access token for the Azure MFA StrongAuthenticationService connector. + + .DESCRIPTION + The connector token is minted from a client secret on the tenant's "Azure Multi-Factor Auth Client" + service principal. Provisioning that secret is expensive (it may adjust the tenant's app management + policy and add a credential), so a long-lived secret is cached per tenant - in Key Vault in + production, in the DevSecrets table in local development - and reused. A cached secret is only + reprovisioned when it is missing or the token exchange fails (e.g. it has expired). The provisioned + secret is capped at 180 days; refresh happens automatically on the next call after it lapses. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + [Diagnostics.CodeAnalysis.SuppressMessageAttribute('PSAvoidUsingConvertToSecureStringWithPlainText', '', Justification = 'The connector secret must be written to Key Vault as a SecureString and is encrypted at rest.')] + param( + [Parameter(Mandatory = $true)] + $TenantFilter, + $Headers, + [switch]$ForceProvision + ) + + $MFAAppID = '981f26a1-7f43-403b-a875-f8b09b8cd720' + $ConnectorResource = 'https://adnotifications.windowsazure.com/StrongAuthenticationService.svc/Connector' + $TokenUri = "https://login.microsoftonline.com/$TenantFilter/oauth2/token" + + # Stable, Key-Vault-safe secret name keyed on the tenant GUID (domains contain dots, which KV rejects). + $GuidPattern = '^[0-9a-f]{8}-([0-9a-f]{4}-){3}[0-9a-f]{12}$' + $TenantId = if ($TenantFilter -match $GuidPattern) { $TenantFilter } else { (Get-Tenants -TenantFilter $TenantFilter).customerId } + if (-not $TenantId) { $TenantId = $TenantFilter } + $SecretName = "NPS-$TenantId" + $IsDevMode = $env:AzureWebJobsStorage -eq 'UseDevelopmentStorage=true' -or $env:NonLocalHostAzurite -eq 'true' + + # --- dev-aware cached-secret storage ----------------------------------------------------------- + function Get-StoredSecret { + if ($IsDevMode) { + $Table = Get-CIPPTable -tablename 'DevSecrets' + $Row = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'NPSSecret' and RowKey eq '$TenantId'" + return $Row.SecretValue + } + return Get-CippKeyVaultSecret -Name $SecretName -AsPlainText -ErrorAction SilentlyContinue + } + function Set-StoredSecret { + param($Value) + if ($IsDevMode) { + $Table = Get-CIPPTable -tablename 'DevSecrets' + $Entity = @{ PartitionKey = 'NPSSecret'; RowKey = [string]$TenantId; SecretValue = [string]$Value } + Add-CIPPAzDataTableEntity @Table -Entity $Entity -Force + } else { + $null = Set-CippKeyVaultSecret -Name $SecretName -SecretValue (ConvertTo-SecureString -String $Value -AsPlainText -Force) + } + } + + # Keep retrying the token exchange while Microsoft finishes provisioning a freshly added secret. + function Get-ConnectorToken { + param($Secret, [int]$MaxAttempts = 1) + $ClientBody = @{ + resource = $ConnectorResource + client_id = $MFAAppID + client_secret = $Secret + grant_type = 'client_credentials' + scope = 'openid' + } + for ($Attempt = 1; $Attempt -le $MaxAttempts; $Attempt++) { + try { + return (Invoke-RestMethod -Method Post -Uri $TokenUri -Body $ClientBody -ErrorAction Stop).access_token + } catch { + if ($Attempt -ge $MaxAttempts) { throw } + Start-Sleep 1 + } + } + } + + # 1. Reuse the cached secret when present (single token attempt - it is already active). + if (-not $ForceProvision) { + $CachedSecret = Get-StoredSecret + if ($CachedSecret) { + try { + return [pscustomobject]@{ AccessToken = (Get-ConnectorToken -Secret $CachedSecret) } + } catch { + # Cached secret is expired or revoked - fall through and reprovision. + Write-Information "Cached MFA connector secret for $TenantId failed token exchange; reprovisioning." + } + } + } + + # 2. Provision a fresh long-lived secret on the MFA client service principal. + $SPResult = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/servicePrincipals?`$top=999&`$select=id,appId" -tenantid $TenantFilter -AsApp $true + $SPID = ($SPResult | Where-Object { $_.appId -eq $MFAAppID }).id + if (!$SPID) { + $SPBody = [pscustomobject]@{ appId = $MFAAppID } | ConvertTo-Json -Depth 5 + $SPID = (New-GraphPostRequest -uri 'https://graph.microsoft.com/v1.0/servicePrincipals' -tenantid $TenantFilter -type POST -body $SPBody -AsApp $true).id + } + + try { + $PolicyUpdate = Update-AppManagementPolicy -TenantFilter $TenantFilter -ApplicationId $MFAAppID -ServicePrincipal + Write-Information $PolicyUpdate.PolicyAction + } catch { + Write-Information "Failed to update app management policy: $($_.Exception.Message)" + } + + $PassReqBody = @{ + 'passwordCredential' = @{ + 'displayName' = 'CIPP MFA Connector' + 'endDateTime' = $((Get-Date).AddDays(180)) + 'startDateTime' = $((Get-Date).AddMinutes(-5)) + } + } | ConvertTo-Json -Depth 5 + + $NewSecret = $null + $AddSecretError = $null + for ($Attempt = 1; $Attempt -le 5; $Attempt++) { + try { + $NewSecret = (New-GraphPostRequest -uri "https://graph.microsoft.com/v1.0/servicePrincipals/$SPID/addPassword" -tenantid $TenantFilter -type POST -body $PassReqBody -AsApp $true).secretText + break + } catch { + $AddSecretError = $_.Exception.Message + if ($Attempt -lt 5) { Start-Sleep -Seconds 4 } + } + } + if (-not $NewSecret) { + throw "Failed to add a credential to the MFA service principal. The tenant's app management policy may be blocking credential creation for this app. Error: $AddSecretError" + } + + $AccessToken = Get-ConnectorToken -Secret $NewSecret -MaxAttempts 20 + Set-StoredSecret -Value $NewSecret + + return [pscustomobject]@{ AccessToken = $AccessToken } +} diff --git a/Modules/CIPPCore/Public/GraphHelper/New-GraphBulkRequest.ps1 b/Modules/CIPPCore/Public/GraphHelper/New-GraphBulkRequest.ps1 index c191724346e55..d89b5e8734202 100644 --- a/Modules/CIPPCore/Public/GraphHelper/New-GraphBulkRequest.ps1 +++ b/Modules/CIPPCore/Public/GraphHelper/New-GraphBulkRequest.ps1 @@ -68,6 +68,7 @@ function New-GraphBulkRequest { id = $MoreData.id url = $InitialNextUrl }) + $RetriedPages = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) while ($NextLinkQueue.Count -gt 0) { # Drain up to 20 nextLinks into a batch @@ -88,7 +89,36 @@ function New-GraphBulkRequest { $NextReturn = Invoke-CIPPRestMethod -Uri $URL -Method POST -Headers $headers -ContentType 'application/json; charset=utf-8' -Body $NextReqBody } + # A continuation page that fails (throttled, timed out, or missing from the batch + # reply) used to be dropped silently: the parent item kept status 200 with only + # its first page, so callers took a partial list for the complete one. The drift + # engine then pruned the decisions for every policy that sat on a later page and + # re-created them as New on the next run. Retry the page once, then mark the + # parent so callers can tell the collection is incomplete. + $AnsweredIds = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) foreach ($NextResponse in $NextReturn.responses) { + $null = $AnsweredIds.Add([string]$NextResponse.id) + $PageStatus = $NextResponse.status -as [int] + if ($PageStatus -ge 400) { + $PageRequest = $NextBatchRequests | Where-Object { $_.id -eq $NextResponse.id } | Select-Object -First 1 + $RetryKey = "$($NextResponse.id)|$($PageRequest.url)" + if ($PageRequest -and $RetriedPages.Add($RetryKey)) { + $RetryAfter = [Math]::Min([Math]::Max(($NextResponse.headers.'Retry-After' -as [int]), 0), 30) + if ($RetryAfter -gt 0) { Start-Sleep -Seconds $RetryAfter } + $NextLinkQueue.Enqueue([PSCustomObject]@{ + id = $PageRequest.id + url = $PageRequest.url + }) + continue + } + $PageError = "continuation page returned $PageStatus$(if ($NextResponse.body.error.message) { ": $($NextResponse.body.error.message)" })" + Write-Warning "Graph bulk request for '$($NextResponse.id)' ($tenantid): $PageError. The result is incomplete." + $MoreData | Add-Member -NotePropertyMembers ([ordered]@{ + PagingIncomplete = $true + PagingError = $PageError + }) -Force + continue + } if ($NextResponse.body.value) { $NewValues = [System.Collections.Generic.List[PSCustomObject]]$MoreData.body.value foreach ($val in $NextResponse.body.value) { $NewValues.Add($val) } @@ -102,23 +132,37 @@ function New-GraphBulkRequest { }) } } + foreach ($Unanswered in ($NextBatchRequests | Where-Object { -not $AnsweredIds.Contains([string]$_.id) })) { + Write-Warning "Graph bulk request for '$($Unanswered.id)' ($tenantid): no reply for continuation page '$($Unanswered.url)'. The result is incomplete." + $MoreData | Add-Member -NotePropertyMembers ([ordered]@{ + PagingIncomplete = $true + PagingError = 'continuation page missing from the batch reply' + }) -Force + } } } } catch { Write-Host 'updating graph table because something failed.' + $ErrorRecord = $_ # $_ is the parse error inside the nested catch # Try to parse ErrorDetails.Message as JSON - if ($_.ErrorDetails.Message) { + $ErrorBody = [string]$ErrorRecord.ErrorDetails.Message + if ($ErrorBody) { try { - $ErrorJson = $_.ErrorDetails.Message | ConvertFrom-Json -ErrorAction Stop + $ErrorJson = $ErrorBody | ConvertFrom-Json -ErrorAction Stop $Message = $ErrorJson.error.message } catch { - $Message = $_.ErrorDetails.Message + $Message = $ErrorBody } } if ([string]::IsNullOrEmpty($Message)) { - $Message = $_.Exception.Message + $Message = $ErrorRecord.Exception.Message + } + + # An IIS error page ('Request Too Long') is HTML, not a Graph error; keep its text only. + if ($Message -match '(?i)]+>', ' ' -replace '\s+', ' ').Trim() } if ($Message -ne 'Request not applicable to target tenant.') { diff --git a/Modules/CIPPCore/Public/GraphHelper/Update-AppManagementPolicy.ps1 b/Modules/CIPPCore/Public/GraphHelper/Update-AppManagementPolicy.ps1 index 566f250f36c9f..553f77e88ef63 100644 --- a/Modules/CIPPCore/Public/GraphHelper/Update-AppManagementPolicy.ps1 +++ b/Modules/CIPPCore/Public/GraphHelper/Update-AppManagementPolicy.ps1 @@ -16,9 +16,18 @@ function Update-AppManagementPolicy { param( $TenantFilter = $env:TenantID, $ApplicationId = $env:ApplicationID, - $headers + $headers, + # Skip the password-addition exemption (leave secrets blocked, exempt only the SAM certificate). + # Defaults on only for the SAM app in certificate mode; other apps still get the password exemption. + [bool]$CertificateOnly = ([bool]$env:CertificateAuthMode -and ($ApplicationId -eq $env:ApplicationID)), + # Target a service principal instead of an application registration. First-party apps (e.g. the + # Azure MFA client) exist only as a service principal in the tenant, so the exemption must be + # resolved and assigned via servicePrincipals rather than applications. + [switch]$ServicePrincipal ) + $TargetResource = if ($ServicePrincipal) { 'servicePrincipals' } else { 'applications' } + try { # Create bulk request to fetch both policies at once $Requests = @( @@ -35,7 +44,7 @@ function Update-AppManagementPolicy { @{ id = 'appRegistration' method = 'GET' - url = "applications(appId='$ApplicationId')?`$select=id,appId,displayName" + url = "$TargetResource(appId='$ApplicationId')?`$select=id,appId,displayName" } ) @@ -134,9 +143,11 @@ function Update-AppManagementPolicy { $DefaultPolicyBlocksKeyCredentials = $DefaultKeyRestrictions.Count -gt 0 } - # If default policy blocks credentials and CIPP app doesn't have an exemption, create/update policy + # Create/update an exemption when the default policy blocks credentials. In certificate mode a + # password block is left in force, so only a key-credential block requires an exemption. $PolicyAction = $null - if (($DefaultPolicyBlocksCredentials -or $DefaultPolicyBlocksKeyCredentials) -and $CIPPApp) { + $RequiresExemption = $DefaultPolicyBlocksKeyCredentials -or (-not $CertificateOnly -and $DefaultPolicyBlocksCredentials) + if ($RequiresExemption -and $CIPPApp) { # Check if a CIPP-SAM Exemption Policy already exists $ExistingExemptionPolicy = $AppPolicies | Where-Object { $_.displayName -eq 'CIPP Exemption Policy' } | Select-Object -First 1 @@ -144,8 +155,10 @@ function Update-AppManagementPolicy { $CIPPHasExemption = $false if ($CIPPAppPolicyId) { $CIPPPolicy = $AppPolicies | Where-Object { $_.id -eq $CIPPAppPolicyId } - # Check if the policy explicitly allows credentials (no enabled passwordAddition/symmetricKeyAddition restriction) - if ($CIPPPolicy.restrictions.passwordCredentials) { + # In certificate mode the password block is intentional, so only the key exemption matters. + if ($CertificateOnly) { + $CIPPHasExemption = $true + } elseif ($CIPPPolicy.restrictions.passwordCredentials) { $CIPPHasExemption = -not ($CIPPPolicy.restrictions.passwordCredentials | Where-Object { $_.restrictionType -in @('passwordAddition', 'symmetricKeyAddition') -and $_.state -eq 'enabled' }) } else { # No password restrictions means it allows credentials @@ -164,37 +177,54 @@ function Update-AppManagementPolicy { if (-not $CIPPHasExemption) { # Need to create or update a policy for CIPP try { - # Define policy structure with disabled restrictions + # Only exempt the restriction types the default policy actually enforces, so the + # exemption body never carries a restriction Graph would reject as unneeded or malformed. + $Restrictions = @{} + + # Password restrictions are disabled only for secret installs; certificate mode leaves + # them blocked so secrets stay disallowed. + if (-not $CertificateOnly -and $DefaultPolicyBlocksCredentials) { + $Restrictions.passwordCredentials = @( + @{ + restrictionType = 'passwordAddition' + state = 'disabled' + restrictForAppsCreatedAfterDateTime = '0001-01-01T00:00:00Z' + } + @{ + restrictionType = 'symmetricKeyAddition' + state = 'disabled' + restrictForAppsCreatedAfterDateTime = '0001-01-01T00:00:00Z' + } + ) + } + + # Key restrictions are disabled so the SAM certificate can register. asymmetricKeyLifetime + # is a lifetime-type restriction; Graph rejects the whole policy body unless it carries a + # valid maxLifetime duration, even when the restriction is disabled. Echo the tenant + # default's value when present, otherwise fall back to a conservative duration. + if ($DefaultPolicyBlocksKeyCredentials) { + $AsymmetricKeyMaxLifetime = ($DefaultKeyRestrictions | Where-Object { $_.restrictionType -eq 'asymmetricKeyLifetime' } | Select-Object -First 1).maxLifetime + if (-not $AsymmetricKeyMaxLifetime) { $AsymmetricKeyMaxLifetime = 'P730D' } + + $Restrictions.keyCredentials = @( + @{ + restrictionType = 'asymmetricKeyLifetime' + state = 'disabled' + restrictForAppsCreatedAfterDateTime = '0001-01-01T00:00:00Z' + maxLifetime = $AsymmetricKeyMaxLifetime + } + @{ + restrictionType = 'trustedCertificateAuthority' + state = 'disabled' + restrictForAppsCreatedAfterDateTime = '0001-01-01T00:00:00Z' + } + ) + } $PolicyBody = @{ displayName = 'CIPP Exemption Policy' - description = 'Allows CIPP app to manage credentials' + description = if ($CertificateOnly) { 'Allows CIPP app to register certificates (password addition intentionally left blocked)' } else { 'Allows CIPP app to manage credentials' } isEnabled = $true - restrictions = @{ - passwordCredentials = @( - @{ - restrictionType = 'passwordAddition' - state = 'disabled' - restrictForAppsCreatedAfterDateTime = '0001-01-01T00:00:00Z' - } - @{ - restrictionType = 'symmetricKeyAddition' - state = 'disabled' - restrictForAppsCreatedAfterDateTime = '0001-01-01T00:00:00Z' - } - ) - keyCredentials = @( - @{ - restrictionType = 'asymmetricKeyLifetime' - state = 'disabled' - restrictForAppsCreatedAfterDateTime = '0001-01-01T00:00:00Z' - } - @{ - restrictionType = 'trustedCertificateAuthority' - state = 'disabled' - restrictForAppsCreatedAfterDateTime = '0001-01-01T00:00:00Z' - } - ) - } + restrictions = $Restrictions } if ($CIPPAppPolicyId) { @@ -206,12 +236,21 @@ function Update-AppManagementPolicy { $null = New-GraphPostRequest -uri "https://graph.microsoft.com/v1.0/policies/appManagementPolicies/$($ExistingExemptionPolicy.id)" -type PATCH -body ($PolicyBody | ConvertTo-Json -Depth 10) -asapp $true -NoAuthCheck $true -tenantid $TenantFilter -headers $headers if ($CIPPApp.id) { - # Assign existing policy to CIPP-SAM application + # Assign existing policy to the target app registration or service principal $AssignBody = @{ '@odata.id' = "https://graph.microsoft.com/beta/policies/appManagementPolicies/$($ExistingExemptionPolicy.id)" } - $null = New-GraphPostRequest -uri "https://graph.microsoft.com/beta/applications/$($CIPPApp.id)/appManagementPolicies/`$ref" -type POST -body ($AssignBody | ConvertTo-Json) -asapp $true -NoAuthCheck $true -tenantid $TenantFilter -headers $headers - $PolicyAction = "Updated and assigned existing policy $($ExistingExemptionPolicy.id) to CIPP-SAM" + try { + $null = New-GraphPostRequest -uri "https://graph.microsoft.com/beta/$TargetResource/$($CIPPApp.id)/appManagementPolicies/`$ref" -type POST -body ($AssignBody | ConvertTo-Json) -asapp $true -NoAuthCheck $true -tenantid $TenantFilter -headers $headers + $PolicyAction = "Updated and assigned existing policy $($ExistingExemptionPolicy.id) to CIPP-SAM" + } catch { + # A duplicate reference means the policy is already assigned - that is the desired end state, not a failure. + if ($_.Exception.Message -match 'already exist') { + $PolicyAction = "Existing policy $($ExistingExemptionPolicy.id) already assigned to CIPP-SAM" + } else { + throw + } + } $CIPPAppPolicyId = $ExistingExemptionPolicy.id $CIPPAppTargeted = $true } else { @@ -222,12 +261,21 @@ function Update-AppManagementPolicy { $CreatedPolicy = New-GraphPostRequest -uri 'https://graph.microsoft.com/v1.0/policies/appManagementPolicies' -type POST -body ($PolicyBody | ConvertTo-Json -Depth 10) -asapp $true -NoAuthCheck $true -tenantid $TenantFilter -headers $headers if ($CIPPApp.id) { - # Assign policy to CIPP-SAM application using beta endpoint + # Assign policy to the target app registration or service principal using beta endpoint $AssignBody = @{ '@odata.id' = "https://graph.microsoft.com/beta/policies/appManagementPolicies/$($CreatedPolicy.id)" } - $null = New-GraphPostRequest -uri "https://graph.microsoft.com/beta/applications/$($CIPPApp.id)/appManagementPolicies/`$ref" -type POST -body ($AssignBody | ConvertTo-Json) -asapp $true -NoAuthCheck $true -tenantid $TenantFilter -headers $headers - $PolicyAction = "Created new policy $($CreatedPolicy.id) and assigned to CIPP-SAM" + try { + $null = New-GraphPostRequest -uri "https://graph.microsoft.com/beta/$TargetResource/$($CIPPApp.id)/appManagementPolicies/`$ref" -type POST -body ($AssignBody | ConvertTo-Json) -asapp $true -NoAuthCheck $true -tenantid $TenantFilter -headers $headers + $PolicyAction = "Created new policy $($CreatedPolicy.id) and assigned to CIPP-SAM" + } catch { + # A duplicate reference means the policy is already assigned - that is the desired end state, not a failure. + if ($_.Exception.Message -match 'already exist') { + $PolicyAction = "Created new policy $($CreatedPolicy.id); already assigned to CIPP-SAM" + } else { + throw + } + } $CIPPAppPolicyId = $CreatedPolicy.id $CIPPAppTargeted = $true } else { diff --git a/Modules/CIPPCore/Public/GraphHelper/Write-LogMessage.ps1 b/Modules/CIPPCore/Public/GraphHelper/Write-LogMessage.ps1 index 741dd44d48c7b..975238e16573c 100644 --- a/Modules/CIPPCore/Public/GraphHelper/Write-LogMessage.ps1 +++ b/Modules/CIPPCore/Public/GraphHelper/Write-LogMessage.ps1 @@ -47,6 +47,12 @@ function Write-LogMessage { $TzId = if ($env:CIPP_TIMEZONE) { $env:CIPP_TIMEZONE } else { 'UTC' } $LocalNow = [TimeZoneInfo]::ConvertTimeBySystemTimeZoneId([DateTime]::UtcNow, $TzId) $PartitionKey = $LocalNow.ToString('yyyyMMdd') + # Inverted-ticks RowKey: the table service returns rows in ascending RowKey order, so + # (MaxValue - now) makes a partition read newest-first without scanning it whole. The + # suffix keeps concurrent writers from colliding; Invoke-ListLogs derives the day + # partition back out of the tick prefix. Rows written before this scheme have GUID + # RowKeys and simply sort in arbitrary order within their (historical) partitions. + $RowKey = '{0:D19}-{1}' -f ([DateTime]::MaxValue.Ticks - [DateTime]::UtcNow.Ticks), [guid]::NewGuid().ToString('N').Substring(0, 12) $TableRow = @{ 'Tenant' = [string]$tenant 'API' = [string]$API @@ -55,7 +61,7 @@ function Write-LogMessage { 'Severity' = [string]$sev 'sentAsAlert' = $false 'PartitionKey' = [string]$PartitionKey - 'RowKey' = [string]([guid]::NewGuid()).ToString() + 'RowKey' = [string]$RowKey 'FunctionNode' = [string]$env:WEBSITE_SITE_NAME 'LogData' = [string]$LogData } diff --git a/Modules/CIPPCore/Public/GraphRequests/Get-GraphRequestList.ps1 b/Modules/CIPPCore/Public/GraphRequests/Get-GraphRequestList.ps1 index 1e27e7b39b312..22a56bae7464b 100644 --- a/Modules/CIPPCore/Public/GraphRequests/Get-GraphRequestList.ps1 +++ b/Modules/CIPPCore/Public/GraphRequests/Get-GraphRequestList.ps1 @@ -81,10 +81,12 @@ function Get-GraphRequestList { [boolean]$AsApp = $false, [string]$Caller = 'Get-GraphRequestList', [switch]$UseBatchExpand, - [switch]$RawJsonArray + [switch]$RawJsonArray, + [int]$MaxPageBytes ) $SingleTenantThreshold = 8000 + $PagedAllTenants = $false Write-Information "Tenant: $TenantFilter" $TableName = ('cache{0}' -f ($Endpoint -replace '[^A-Za-z0-9]'))[0..62] -join '' $Endpoint = $Endpoint -replace '^/', '' @@ -210,7 +212,28 @@ function Get-GraphRequestList { $Filter = "PartitionKey eq '{0}' and (RowKey eq '{1}' or OriginalEntityId eq '{1}') and Timestamp ge datetime'{2}'" -f $PartitionKey, $TenantFilter, $Timestamp } $Tenants = Get-Tenants -IncludeErrors - $Rows = Get-CIPPAzDataTableEntity @Table -Filter $Filter | Where-Object { $_.OriginalEntityId -in $Tenants.defaultDomainName -or $_.RowKey -in $Tenants.defaultDomainName } + # Paged AllTenants serve: key scan here, bounded blob fetches in the serve branch. + $PagedAllTenants = $TenantFilter -eq 'AllTenants' -and $ManualPagination.IsPresent -and $RawJsonArray.IsPresent + if ($PagedAllTenants) { + # Keys only, and none of the split-entity markers: projecting a subset of them + # (e.g. OriginalEntityId alone) makes reassembly fail and drops split tenants. + $KeyRows = Get-CIPPAzDataTableEntity @Table -Filter $Filter -Property PartitionKey, RowKey + # Physical rows per tenant ('-part' rows fold into their head); sizes the spans below. + $PagedTenantRowCounts = [System.Collections.Generic.Dictionary[string, int]]::new([StringComparer]::Ordinal) + foreach ($KeyRow in @($KeyRows)) { + $TenantKey = [string]$KeyRow.RowKey -replace '-part\d+$', '' + if ($TenantKey) { + $PagedTenantRowCounts[$TenantKey] = 1 + $(if ($PagedTenantRowCounts.ContainsKey($TenantKey)) { $PagedTenantRowCounts[$TenantKey] } else { 0 }) + } + } + # Ordinal, to match the resume comparison below (a culture sort re-served tenants). + $PagedTenantPlan = [string[]]@($PagedTenantRowCounts.Keys | Where-Object { $_ -in $Tenants.defaultDomainName }) + [System.Array]::Sort($PagedTenantPlan, [System.Collections.IComparer][StringComparer]::Ordinal) + # $Rows gates queue-vs-serve below; an empty plan queues like an empty fetch. + $Rows = $PagedTenantPlan + } else { + $Rows = Get-CIPPAzDataTableEntity @Table -Filter $Filter | Where-Object { $_.OriginalEntityId -in $Tenants.defaultDomainName -or $_.RowKey -in $Tenants.defaultDomainName } + } $Type = 'Cache' Write-Information "Table: $TableName | PK: $PartitionKey | Cached: $(($Rows | Measure-Object).Count) rows (Type: $($Type))" $QueueReference = '{0}-{1}' -f $TenantFilter, $PartitionKey @@ -436,6 +459,71 @@ function Get-GraphRequestList { } } else { if ($RawJsonArray.IsPresent) { + if ($PagedAllTenants) { + # One page of whole tenant blobs, ended by the byte budget alone (never a tenant + # count); tenants are fetched in RowKey-range spans so split blobs reassemble. + $MaxPageChars = if ($MaxPageBytes -gt 0) { [Math]::Min([Math]::Max($MaxPageBytes, 262144), 8388608) } else { 4000000 } + # Rows are <= ~1MB each, so a row cap bounds a span's worst-case fetch. + $SpanRowCap = 40 + $StartAfter = if ($nextLink) { $nextLink } else { $null } + + $Remaining = [System.Collections.Generic.List[string]]::new() + foreach ($TenantKey in $PagedTenantPlan) { + if (-not $StartAfter -or [string]::CompareOrdinal($TenantKey, $StartAfter) -gt 0) { $Remaining.Add($TenantKey) } + } + + $JsonParts = [System.Collections.Generic.List[string]]::new() + $Chars = 0 + $Queries = 0 + $LastEmitted = $null + $BudgetReached = $false + $Index = 0 + while ($Index -lt $Remaining.Count -and -not $BudgetReached) { + # Build the next span: consecutive plan tenants until the row cap fills. + $SpanStart = $Index + $SpanRows = 0 + $SpanSet = [System.Collections.Generic.HashSet[string]]::new([StringComparer]::Ordinal) + while ($Index -lt $Remaining.Count) { + $Candidate = $Remaining[$Index] + $CandidateRows = $PagedTenantRowCounts[$Candidate] + if ($SpanSet.Count -gt 0 -and ($SpanRows + $CandidateRows) -gt $SpanRowCap) { break } + $null = $SpanSet.Add($Candidate) + $SpanRows += $CandidateRows + $Index++ + } + $SpanFirst = ConvertTo-CIPPODataFilterValue -Value $Remaining[$SpanStart] -Type String + $SpanLast = ConvertTo-CIPPODataFilterValue -Value $Remaining[$Index - 1] -Type String + # le '~' keeps the last tenant's '-partN' rows in range; non-member rows + # the range also catches are dropped below. + $SpanFilter = "PartitionKey eq '{0}' and RowKey ge '{1}' and RowKey le '{2}~' and Timestamp ge datetime'{3}'" -f $PartitionKey, $SpanFirst, $SpanLast, $Timestamp + # Budget is enforced per whole tenant; the rest of a span past it is discarded + # and re-fetched by the next page. + foreach ($Row in @(Get-CIPPAzDataTableEntity @Table -Filter $SpanFilter)) { + if (-not $SpanSet.Contains([string]$Row.RowKey)) { continue } + if ($BudgetReached) { break } + $LastEmitted = [string]$Row.RowKey + if ($Row.Data) { + $d = $Row.Data.Trim() + if ($d.Length -gt 2 -and $d[0] -eq '[' -and $d[-1] -eq ']') { + $JsonParts.Add($d.Substring(1, $d.Length - 2)) + $Chars += $d.Length + } elseif ($d.Length -gt 0 -and $d -ne '[]') { + $JsonParts.Add($d) + $Chars += $d.Length + } + } + if ($Chars -ge $MaxPageChars) { $BudgetReached = $true } + } + $Queries++ + } + # A drained plan is complete even if the last tenant landed on the budget. + $MoreRemain = $BudgetReached -and $null -ne $LastEmitted -and [string]::CompareOrdinal($LastEmitted, $Remaining[$Remaining.Count - 1]) -lt 0 + Write-Information "Paged AllTenants cache serve: $Queries spans, $Chars chars, last: $LastEmitted, more: $MoreRemain" + return [PSCustomObject]@{ + CippPagedJson = '[' + ($JsonParts -join ',') + ']' + CippNextLink = if ($MoreRemain) { $LastEmitted } else { $null } + } + } # Fast path: concatenate raw JSON strings without deserialization. This is much faster and uses less memory when no post-processing is needed, especially for large datasets. $JsonParts = [System.Collections.Generic.List[string]]::new() foreach ($Row in $Rows) { diff --git a/Modules/CIPPCore/Public/Invoke-CIPPCATemplateBatch.ps1 b/Modules/CIPPCore/Public/Invoke-CIPPCATemplateBatch.ps1 index b5f031869ddcb..43a144947b838 100644 --- a/Modules/CIPPCore/Public/Invoke-CIPPCATemplateBatch.ps1 +++ b/Modules/CIPPCore/Public/Invoke-CIPPCATemplateBatch.ps1 @@ -48,7 +48,9 @@ function Invoke-CIPPCATemplateBatch { $TestResult = Test-CIPPStandardLicense -StandardName 'ConditionalAccessTemplate_general' -TenantFilter $Tenant -Preset Entra if ($TestResult -eq $false) { foreach ($t in $Templates) { - Set-CIPPStandardsCompareField -FieldName "standards.ConditionalAccessTemplate.$($t.Settings.TemplateList.value)" -FieldValue 'This tenant does not have the required license for this standard.' -Tenant $Tenant + # LicenseAvailable is what the standards page keys off to show the licensing message; + # without it a bare string value renders as "data has not yet been collected". + Set-CIPPStandardsCompareField -FieldName "standards.ConditionalAccessTemplate.$($t.Settings.TemplateList.value)" -FieldValue 'This tenant does not have the required license for this standard.' -LicenseAvailable $false -Tenant $Tenant } return } @@ -92,16 +94,23 @@ function Invoke-CIPPCATemplateBatch { # Load each template's JSON once $CATemplates = foreach ($t in $Templates) { $TemplateValue = $t.Settings.TemplateList.value - $Filter = "PartitionKey eq 'CATemplate' and RowKey eq '$TemplateValue'" - $JSON = (Get-CippAzDataTableEntity @Table -Filter $Filter).JSON + # The template picker surfaces the GUID column while the engine keys on RowKey. CIPP writes + # both to the same value, but templates re-synced by older releases can differ - accept + # either so a template that is sitting in the table is not reported as missing. + $SafeTemplateValue = ConvertTo-CIPPODataFilterValue -Value $TemplateValue -Type String + $Filter = "PartitionKey eq 'CATemplate' and (RowKey eq '$SafeTemplateValue' or GUID eq '$SafeTemplateValue')" + $JSON = (Get-CippAzDataTableEntity @Table -Filter $Filter | Select-Object -First 1).JSON # Resolve custom variables once at load: the compare helper, the dependency # reconciliation objects and the deploy RawJSON must all see the same resolved # values, or the DependencyMap ends up keyed by raw %tokens% that the (resolved) # policies can never look up. if ($JSON) { $JSON = Get-CIPPTextReplacement -TenantFilter $Tenant -Text $JSON -EscapeForJson } if (-not $JSON) { - Write-LogMessage -API 'Standards' -tenant $Tenant -message "Conditional Access template '$($t.Settings.TemplateList.label)' ($TemplateValue) could not be loaded from the template store - skipping." -Sev 'Error' - Set-CIPPStandardsCompareField -FieldName "standards.ConditionalAccessTemplate.$TemplateValue" -FieldValue "Template '$($t.Settings.TemplateList.label)' could not be loaded from the template store." -Tenant $Tenant + $MissingText = "Template '$($t.Settings.TemplateList.label)' ($TemplateValue) no longer exists in the template library. Remove it from the standards template or select the template again." + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Conditional Access template '$($t.Settings.TemplateList.label)' ($TemplateValue) could not be loaded from the template store - skipping. $MissingText" -Sev 'Error' + # Carry the reason into the report so the standards page shows it instead of "data has + # not yet been collected". + Set-CIPPStandardsCompareField -FieldName "standards.ConditionalAccessTemplate.$TemplateValue" -CurrentValue @{ Differences = $MissingText } -ExpectedValue @{ Differences = @() } -Tenant $Tenant continue } [pscustomobject]@{ diff --git a/Modules/CIPPCore/Public/Invoke-CIPPDBCacheCollection.ps1 b/Modules/CIPPCore/Public/Invoke-CIPPDBCacheCollection.ps1 index 3c761f84c784d..a81a95e7c0fb2 100644 --- a/Modules/CIPPCore/Public/Invoke-CIPPDBCacheCollection.ps1 +++ b/Modules/CIPPCore/Public/Invoke-CIPPDBCacheCollection.ps1 @@ -9,13 +9,14 @@ function Invoke-CIPPDBCacheCollection { compared to individual per-type activities, eliminating replay overhead. Collection types map to license categories: - - Graph: Core tenant data (no special license needed) - - ExchangeConfig: Exchange Online policy/config data - - ExchangeData: Mailboxes, CAS mailboxes, usage reports - - ConditionalAccess: CA policies and registration details - - IdentityProtection: Risky users/SPs, risk detections, PIM - - Intune: Managed devices, policies, app protection - - Defender: Defender Vulnerabilities + - Graph: Core tenant data (no special license needed) + - ExchangeConfig: Exchange Online policy/config data + - ExchangeData: Mailboxes, CAS mailboxes, usage reports + - ConditionalAccess: CA policies and registration details + - IdentityProtection: Risky users/SPs, risk detections, PIM + - Intune: Managed devices, policies, app protection + - DefenderForOffice365: Safe Links/Attachments, ATP, Teams protection (MDO P1/P2) + - Defender: Defender for Endpoint vulnerabilities (TVM/CVE) .PARAMETER CollectionType The group of cache functions to execute @@ -32,7 +33,7 @@ function Invoke-CIPPDBCacheCollection { [CmdletBinding()] param( [Parameter(Mandatory = $true)] - [ValidateSet('Graph', 'ExchangeConfig', 'ExchangeData', 'ConditionalAccess', 'IdentityProtection', 'Intune', 'Compliance', 'CopilotUsage', 'SharePoint', 'Teams', 'Defender')] + [ValidateSet('Graph', 'ExchangeConfig', 'ExchangeData', 'ConditionalAccess', 'IdentityProtection', 'Intune', 'Compliance', 'CopilotUsage', 'SharePoint', 'Teams', 'DefenderForOffice365', 'Defender')] [string]$CollectionType, [Parameter(Mandatory = $true)] @@ -69,6 +70,7 @@ function Invoke-CIPPDBCacheCollection { 'OAuth2PermissionGrants' 'AppRoleAssignments' 'LicenseOverview' + 'ActiveUserDetail' 'BitlockerKeys' 'AdminReportSettings' 'PeopleInsights' @@ -88,15 +90,12 @@ function Invoke-CIPPDBCacheCollection { ExchangeConfig = @( 'ExoAntiPhishPolicies' 'ExoMalwareFilterPolicies' - 'ExoSafeLinksPolicies' - 'ExoSafeAttachmentPolicies' 'ExoTransportRules' 'ExoDkimSigningConfig' 'ExoOrganizationConfig' 'ExoAcceptedDomains' 'ExoHostedContentFilterPolicy' 'ExoHostedOutboundSpamFilterPolicy' - 'ExoAtpPolicyForO365' 'ExoQuarantinePolicy' 'ExoRemoteDomain' 'ExoSharingPolicy' @@ -111,7 +110,6 @@ function Invoke-CIPPDBCacheCollection { 'ExoTransportConfig' 'ExoHostedConnectionFilterPolicy' 'ExoExternalInOutlook' - 'ExoTeamsProtectionPolicy' 'ExoOutboundConnector' 'ExoRoleAssignmentPolicy' 'ExoHostedContentFilterRule' @@ -181,6 +179,7 @@ function Invoke-CIPPDBCacheCollection { ) SharePoint = @( 'SPOTenant' + 'SPOSites' 'SPOTenantSyncClientRestriction' 'SharePointAdminSettings' 'SharePointSiteUsage' @@ -203,6 +202,12 @@ function Invoke-CIPPDBCacheCollection { Defender = @( 'DefenderCVEs' ) + DefenderForOffice365 = @( + 'ExoSafeLinksPolicies' + 'ExoSafeAttachmentPolicies' + 'ExoAtpPolicyForO365' + 'ExoTeamsProtectionPolicy' + ) } $CacheTypes = $Collections[$CollectionType] diff --git a/Modules/CIPPCore/Public/Invoke-CIPPOffboardingJob.ps1 b/Modules/CIPPCore/Public/Invoke-CIPPOffboardingJob.ps1 index 3174219365396..0c5025cd28673 100644 --- a/Modules/CIPPCore/Public/Invoke-CIPPOffboardingJob.ps1 +++ b/Modules/CIPPCore/Public/Invoke-CIPPOffboardingJob.ps1 @@ -7,7 +7,11 @@ function Invoke-CIPPOffboardingJob { $Options, $APIName = 'Offboard user', $Headers, - $TaskInfo + $TaskInfo, + # Live-progress job created by the caller; when set, the user's status row is kept up to date + [string]$DeploymentId, + # Zero-based indices of the steps to run again (a step re-run); empty runs every selected task + [int[]]$StepIndexes = @() ) try { @@ -31,9 +35,30 @@ function Invoke-CIPPOffboardingJob { # Build dynamic batch of offboarding tasks based on selected options $Batch = [System.Collections.Generic.List[object]]::new() - # Build list of tasks in execution order with their cmdlets + # When the user is being deleted, only user removal and OneDrive access grants remain valid; every other task is skipped regardless of its flag + $DeleteUserSelected = $Options.DeleteUser -eq $true + $AllowedCmdletsWhenDeletingUser = @('Remove-CIPPUser', 'Set-CIPPSharePointPerms') + $SkippedForDeleteUser = [System.Collections.Generic.List[string]]::new() + + # Build list of tasks in execution order with their cmdlets. + # The account-only wipe must run before session revocation, sign-in disable and device removal: + # the wipe is delivered on the device's next Exchange connection, so the account must still be + # able to authenticate and the ActiveSync partnership must still exist when it is issued. $TaskOrder = @( @{ + Title = 'Wipe mobile devices (account data only)' + Condition = { $Options.WipeMobile -eq $true } + Cmdlet = 'Clear-CIPPMobileDevice' + Parameters = @{ + userid = $UserID + username = $Username + tenantFilter = $TenantFilter + APIName = $APIName + Headers = $Headers + } + } + @{ + Title = 'Revoke all sessions' Condition = { $Options.RevokeSessions -eq $true } Cmdlet = 'Revoke-CIPPSessions' Parameters = @{ @@ -45,6 +70,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Reset password' Condition = { $Options.ResetPass -eq $true } Cmdlet = 'Set-CIPPResetPassword' Parameters = @{ @@ -56,6 +82,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Disable sign in' Condition = { $Options.DisableSignIn -eq $true } Cmdlet = 'Set-CIPPSignInState' Parameters = @{ @@ -67,6 +94,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Hide from Global Address List' Condition = { $Options.HideFromGAL -eq $true } Cmdlet = 'Set-CIPPHideFromGAL' Parameters = @{ @@ -78,6 +106,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Remove from all groups' Condition = { $Options.RemoveGroups -eq $true } Cmdlet = 'Remove-CIPPGroups' Parameters = @{ @@ -89,6 +118,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Remove all rules' Condition = { $Options.RemoveRules -eq $true } Cmdlet = 'Remove-CIPPMailboxRule' Parameters = @{ @@ -101,6 +131,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Remove all mobile devices' Condition = { $Options.RemoveMobile -eq $true } Cmdlet = 'Remove-CIPPMobileDevice' Parameters = @{ @@ -112,6 +143,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Cancel all calendar invites' Condition = { $Options.removeCalendarInvites -eq $true } Cmdlet = 'Remove-CIPPCalendarInvites' Parameters = @{ @@ -123,6 +155,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Set Out of Office message' Condition = { -not [string]::IsNullOrEmpty($OooMessage) } Cmdlet = 'Set-CIPPOutOfOffice' Parameters = @{ @@ -136,6 +169,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Forward email' Condition = { ![string]::IsNullOrEmpty($Options.forward) } Cmdlet = 'Set-CIPPForwarding' Parameters = @{ @@ -149,6 +183,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Disable email forwarding' Condition = { $Options.disableForwarding -eq $true } Cmdlet = 'Set-CIPPForwarding' Parameters = @{ @@ -161,6 +196,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Grant OneDrive full access' Condition = { $Options.OnedriveAccess.Count -gt 0 } Cmdlet = 'Set-CIPPSharePointPerms' Parameters = @{ @@ -172,6 +208,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Disable OneDrive sharing links' Condition = { $Options.DisableOneDriveSharing -eq $true } Cmdlet = 'Set-CIPPOneDriveSharing' Parameters = @{ @@ -183,6 +220,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Grant full access (no automap)' Condition = { $Options.AccessNoAutomap.Count -gt 0 } Cmdlet = 'Set-CIPPMailboxAccess' Parameters = @{ @@ -196,6 +234,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Grant full access (automap)' Condition = { $Options.AccessAutomap.Count -gt 0 } Cmdlet = 'Set-CIPPMailboxAccess' Parameters = @{ @@ -209,6 +248,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Grant Send As access' Condition = { $Options.AccessSendAs.Count -gt 0 } Cmdlet = 'Set-CIPPMailboxAccess' Parameters = @{ @@ -221,6 +261,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Grant Send on Behalf access' Condition = { $Options.AccessSendOnBehalf.Count -gt 0 } Cmdlet = 'Set-CIPPMailboxAccess' Parameters = @{ @@ -233,6 +274,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Remove user''s mailbox permissions' Condition = { $Options.removePermissions -eq $true } Cmdlet = 'Remove-CIPPMailboxPermissions' Parameters = @{ @@ -244,6 +286,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Remove user''s calendar permissions' Condition = { $Options.removeCalendarPermissions -eq $true } Cmdlet = 'Remove-CIPPCalendarPermissions' Parameters = @{ @@ -255,6 +298,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Convert to shared mailbox' Condition = { $Options.ConvertToShared -eq $true } Cmdlet = 'Set-CIPPMailboxType' Parameters = @{ @@ -267,6 +311,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Remove all MFA devices' Condition = { $Options.RemoveMFADevices -eq $true } Cmdlet = 'Remove-CIPPUserMFA' Parameters = @{ @@ -277,6 +322,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Remove Teams Phone DID' Condition = { $Options.RemoveTeamsPhoneDID -eq $true } Cmdlet = 'Remove-CIPPUserTeamsPhoneDIDs' Parameters = @{ @@ -288,6 +334,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Remove licenses' Condition = { $Options.RemoveLicenses -eq $true } Cmdlet = 'Remove-CIPPLicense' Parameters = @{ @@ -300,6 +347,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Clear Immutable ID' Condition = { $Options.ClearImmutableId -eq $true } Cmdlet = 'Clear-CIPPImmutableID' Parameters = @{ @@ -312,6 +360,7 @@ function Invoke-CIPPOffboardingJob { } } @{ + Title = 'Delete user' Condition = { $Options.DeleteUser -eq $true } Cmdlet = 'Remove-CIPPUser' Parameters = @{ @@ -326,13 +375,27 @@ function Invoke-CIPPOffboardingJob { # Build batch from selected tasks foreach ($Task in $TaskOrder) { - if (& $Task.Condition) { - $Batch.Add(@{ - FunctionName = 'CIPPOffboardingTask' - Cmdlet = $Task.Cmdlet - Parameters = $Task.Parameters - }) + if (-not (& $Task.Condition)) { + continue } + + if ($DeleteUserSelected -and $Task.Cmdlet -notin $AllowedCmdletsWhenDeletingUser) { + $SkippedForDeleteUser.Add($Task.Cmdlet) + continue + } + + $Batch.Add(@{ + FunctionName = 'CIPPOffboardingTask' + Cmdlet = $Task.Cmdlet + Title = $Task.Title + Parameters = $Task.Parameters + }) + } + + if ($SkippedForDeleteUser.Count -gt 0) { + $SkippedMessage = "Delete user selected for $Username. Skipped tasks: $($SkippedForDeleteUser -join ', ')" + Write-Information $SkippedMessage + Write-LogMessage -API $APIName -tenant $TenantFilter -message $SkippedMessage -sev Info } if ($Batch.Count -eq 0) { @@ -343,6 +406,46 @@ function Invoke-CIPPOffboardingJob { Write-Information "Built batch of $($Batch.Count) offboarding tasks for $Username" + # Live progress: the wizard pre-created a queued row per user under this job id. Replace it with + # the real step list and stamp every task with its step, so the workers (which run in parallel) + # each report to their own step. + if ($DeploymentId) { + if ($StepIndexes.Count -gt 0) { + # Re-running selected steps: keep the row and reset only those steps. + foreach ($Index in $StepIndexes) { + Set-CIPPAsyncDeploymentStep -JobId $DeploymentId -Name $Username -StepIndex $Index -StepStatus 'pending' -Message 'Waiting to start' + } + } else { + # Notification channels configured on the task are steps from the start, so the row does + # not look finished while the deliveries are still being made. + $NotifySteps = @( + foreach ($Channel in @(([string]$TaskInfo.PostExecution -split ',') | ForEach-Object { $_.Trim() } | Where-Object { $_ })) { + @{ Title = "Notify via $Channel"; Kind = 'notify'; Message = 'Sent once every action has finished' } + } + ) + try { + $null = New-CIPPAsyncDeployment -JobId $DeploymentId -Names @($Username) -StepTitles (@($Batch | ForEach-Object { $_.Title }) + $NotifySteps) -Source 'Offboarding' -TaskId $TaskInfo.RowKey -TenantFilter $TenantFilter + } catch { + # Progress is a nice-to-have: a storage hiccup here must not fail the offboarding itself. + Write-LogMessage -API $APIName -tenant $TenantFilter -message "Could not write the progress row for $Username : $($_.Exception.Message)" -sev Warn + } + } + for ($i = 0; $i -lt $Batch.Count; $i++) { + $Batch[$i].DeploymentId = $DeploymentId + $Batch[$i].DeploymentName = $Username + $Batch[$i].StepIndex = $i + } + Set-CIPPAsyncDeploymentStatus -JobId $DeploymentId -Name $Username -Status 'running' + } + + if ($StepIndexes.Count -gt 0) { + # Step re-run: the full list above keeps the indices stable; only the requested steps run. + $Batch = [System.Collections.Generic.List[object]]@($StepIndexes | Where-Object { $_ -ge 0 -and $_ -lt $Batch.Count } | ForEach-Object { $Batch[$_] }) + if ($Batch.Count -eq 0) { + throw "None of the requested steps ($($StepIndexes -join ', ')) exist for $Username" + } + } + # Start orchestration $InputObject = [PSCustomObject]@{ OrchestratorName = "OffboardingUser_$($Username)_$TenantFilter" @@ -359,6 +462,7 @@ function Invoke-CIPPOffboardingJob { TenantFilter = $TenantFilter Username = $Username Headers = $Headers + DeploymentId = $DeploymentId } } @@ -371,6 +475,9 @@ function Invoke-CIPPOffboardingJob { } catch { $ErrorMessage = Get-CippException -Exception $_ Write-LogMessage -API 'Offboarding' -tenant $TenantFilter -message "Failed to start offboarding job for $Username : $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + if ($DeploymentId) { + Set-CIPPAsyncDeploymentStatus -JobId $DeploymentId -Name $Username -Status 'failed' -Logs $ErrorMessage.NormalizedError + } throw $ErrorMessage } } diff --git a/Modules/CIPPCore/Public/Invoke-CIPPSharePointCreateCopyJobs.ps1 b/Modules/CIPPCore/Public/Invoke-CIPPSharePointCreateCopyJobs.ps1 new file mode 100644 index 0000000000000..240aba1fa9cc4 --- /dev/null +++ b/Modules/CIPPCore/Public/Invoke-CIPPSharePointCreateCopyJobs.ps1 @@ -0,0 +1,100 @@ +function Invoke-CIPPSharePointCreateCopyJobs { + <# + .SYNOPSIS + Submits a CreateCopyJobs request on the source SharePoint site. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [Parameter(Mandatory = $true)] + [string]$SourceSiteUrl, + + [Parameter(Mandatory = $true)] + [string[]]$ExportObjectUris, + + [Parameter(Mandatory = $true)] + [string]$DestinationUri, + + [int]$NameConflictBehavior = 1, + [bool]$SameWebCopyMoveOptimization = $false + ) + + $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter + $Scope = "$($SharePointInfo.SharePointUrl)/.default" + + $Body = ConvertTo-Json -InputObject @{ + exportObjectUris = @($ExportObjectUris) + destinationUri = $DestinationUri + options = @{ + IsMoveMode = $false + MoveButKeepSource = $true + IgnoreVersionHistory = $false + AllowSchemaMismatch = $true + AllowSmallerVersionLimitOnDestination = $true + NameConflictBehavior = $NameConflictBehavior + BypassSharedLock = $true + SameWebCopyMoveOptimization = $SameWebCopyMoveOptimization + ExcludeChildren = $false + } + } -Depth 6 -Compress + + $Uri = "$($SourceSiteUrl.TrimEnd('/'))/_api/site/CreateCopyJobs" + $Response = New-GraphPOSTRequest -uri $Uri -tenantid $TenantFilter -scope $Scope -type POST -body $Body ` + -AddedHeaders @{ Accept = 'application/json;odata=verbose' } ` + -contentType 'application/json;odata=verbose' -UseCertificate -AsApp $true + + if ($Response -is [string]) { + $Response = $Response | ConvertFrom-Json + } + + $Jobs = @() + if ($Response.d -and $Response.d.CreateCopyJobs) { + $CreateCopyJobs = $Response.d.CreateCopyJobs + $Jobs = if ($null -ne $CreateCopyJobs.results) { @($CreateCopyJobs.results) } else { @($CreateCopyJobs) } + } elseif ($Response.value) { + $Jobs = @($Response.value) + } elseif ($Response -is [System.Array]) { + $Jobs = @($Response) + } elseif ($Response.d -and ($Response.d.JobId -or $Response.d.jobId)) { + $Jobs = @($Response.d) + } elseif ($Response.JobId -or $Response.jobId) { + $Jobs = @($Response) + } + + if ($Jobs.Count -eq 0) { + throw 'SharePoint CreateCopyJobs returned no job handles.' + } + + # Normalize to the three fields GetCopyJobProgress needs (strip SourceListItemUniqueIds / OData wrappers). + return @($Jobs | ForEach-Object { + $Candidate = $_ + if ($null -ne $_.results) { + $Nested = @($_.results) + if ($Nested.Count -eq 1 -and ($Nested[0].JobId -or $Nested[0].jobId)) { + $Candidate = $Nested[0] + } + } + + $JobId = [string]($Candidate.JobId ?? $Candidate.jobId ?? $Candidate.JobID ?? '') + $JobQueueUri = $Candidate.JobQueueUri ?? $Candidate.jobQueueUri + if ($JobQueueUri -is [PSCustomObject]) { + $JobQueueUri = [string]($JobQueueUri.Url ?? $JobQueueUri.AbsoluteUri ?? $JobQueueUri) + } + $EncryptionKey = $Candidate.EncryptionKey ?? $Candidate.encryptionKey + if ($EncryptionKey -is [PSCustomObject]) { + $EncryptionKey = $EncryptionKey.'#text' ?? $EncryptionKey.Value ?? $EncryptionKey.bytes + } + + if ([string]::IsNullOrWhiteSpace($JobId) -or [string]::IsNullOrWhiteSpace([string]$JobQueueUri)) { + throw 'SharePoint CreateCopyJobs returned a handle without JobId or JobQueueUri.' + } + + [PSCustomObject]@{ + JobId = $JobId + JobQueueUri = [string]$JobQueueUri + EncryptionKey = $EncryptionKey + } + }) +} diff --git a/Modules/CIPPCore/Public/New-CIPPAlertTemplate.ps1 b/Modules/CIPPCore/Public/New-CIPPAlertTemplate.ps1 index 5e2dfee582c63..116d4764adf9e 100644 --- a/Modules/CIPPCore/Public/New-CIPPAlertTemplate.ps1 +++ b/Modules/CIPPCore/Public/New-CIPPAlertTemplate.ps1 @@ -287,7 +287,7 @@ function New-CIPPAlertTemplate { $Table = ($data | ConvertTo-Html -Fragment -As List | Out-String).Replace('', '
') if ($Appname) { $AppName = $AppName.'Application Name' } else { $appName = $data.ApplicationId } $Title = "$($Tenant) - a user has logged on from a location you've set up to receive alerts for." - $IntroText = "$($data.UserId) ($($data.Userkey)) has logged on from IP $($data.ClientIP) to the application $($Appname). According to our database this is located in $($LocationInfo.Country) - $($LocationInfo.City).

You have set up alerts to be notified when this happens. See the table below for more info.$Table" + $IntroText = "$($data.UserId) ($($data.Userkey)) has logged on from IP $($data.ClientIP) to the application $($Appname). According to our database this is located in $($LocationInfo.CountryOrRegion) - $($LocationInfo.City).

You have set up alerts to be notified when this happens. See the table below for more info.$Table" if ($ActionResults) { $IntroText = $IntroText + "

Based on the rule, the following actions have been taken: $($ActionResults -join '
' )

" } if ($LocationInfo) { $LocationTable = ($LocationInfo | ConvertTo-Html -Fragment -As List | Out-String).Replace('
', '
') @@ -325,23 +325,23 @@ function New-CIPPAlertTemplate { # $Data is a single object for audit logs but an array of rows for logbook alerts, # so only resolve when every row agrees - a multi-user alert has no one username. $ResolvedSubject = [regex]::Replace($CustomSubject, '%(\w+)%', { - param($Match) - $PropertyName = switch ($Match.Groups[1].Value) { - 'username' { 'UserId' } - 'tenant' { return $Tenant } - default { $Match.Groups[1].Value } - } - $Values = foreach ($Row in @($Data)) { - if ($null -eq $Row) { continue } - if ($Row -is [System.Collections.IDictionary]) { - $Row[$PropertyName] - } else { - ($Row.PSObject.Properties | Where-Object { $_.Name -ieq $PropertyName } | Select-Object -First 1).Value + param($Match) + $PropertyName = switch ($Match.Groups[1].Value) { + 'username' { 'UserId' } + 'tenant' { return $Tenant } + default { $Match.Groups[1].Value } } - } - $Distinct = @($Values | Where-Object { ![string]::IsNullOrWhiteSpace("$_") } | ForEach-Object { "$_" } | Select-Object -Unique) - if ($Distinct.Count -eq 1) { $Distinct[0] } else { $Match.Value } - }) + $Values = foreach ($Row in @($Data)) { + if ($null -eq $Row) { continue } + if ($Row -is [System.Collections.IDictionary]) { + $Row[$PropertyName] + } else { + ($Row.PSObject.Properties | Where-Object { $_.Name -ieq $PropertyName } | Select-Object -First 1).Value + } + } + $Distinct = @($Values | Where-Object { ![string]::IsNullOrWhiteSpace("$_") } | ForEach-Object { "$_" } | Select-Object -Unique) + if ($Distinct.Count -eq 1) { $Distinct[0] } else { $Match.Value } + }) $Title = '{0} - {1}' -f $Tenant, $ResolvedSubject } diff --git a/Modules/CIPPCore/Public/New-CIPPCAPolicy.ps1 b/Modules/CIPPCore/Public/New-CIPPCAPolicy.ps1 index 74e613aa5f633..5f757c129ec61 100644 --- a/Modules/CIPPCore/Public/New-CIPPCAPolicy.ps1 +++ b/Modules/CIPPCore/Public/New-CIPPCAPolicy.ps1 @@ -45,11 +45,19 @@ function New-CIPPCAPolicy { } } elseif ($CreateGroups) { Write-Warning "Creating group $_ as it does not exist in the tenant" - if ($GroupTemplates.displayName -eq $_) { + # A template store with duplicate display names returns every match here. Passing that + # array to New-CIPPGroup makes the Graph create body's displayName an array, so the + # create fails ("Unexpected token: StartArray. Path 'resourcePayload.displayName'") and + # leaves an empty group id, which Graph then rejects with the opaque + # "1054: Invalid group value: ." on the whole policy. Select a single template. + $MatchingTemplates = @($GroupTemplates | Where-Object -Property displayName -EQ $_) + if ($MatchingTemplates.Count -gt 0) { + if ($MatchingTemplates.Count -gt 1) { + Write-Warning "Multiple group templates found with display name '$_'. Using the first match." + $null = Write-LogMessage -Headers $Headers -API $APIName -message "Multiple group templates found with display name '$_'. Using the first match; remove the duplicate group template." -Sev 'Warning' + } Write-Information "Creating group from template for $_" - $GroupTemplate = $GroupTemplates | Where-Object -Property displayName -EQ $_ - $NewGroup = New-CIPPGroup -GroupObject $GroupTemplate -TenantFilter $TenantFilter -APIName $APIName - $GroupIds.Add($NewGroup.GroupId) + $NewGroup = New-CIPPGroup -GroupObject ($MatchingTemplates | Select-Object -First 1) -TenantFilter $TenantFilter -APIName $APIName } else { Write-Information "No template found, creating security group for $_" $username = $_ -replace '[^a-zA-Z0-9]', '' @@ -63,8 +71,14 @@ function New-CIPPCAPolicy { securityEnabled = $true } $NewGroup = New-CIPPGroup -GroupObject $GroupObject -TenantFilter $TenantFilter -APIName $APIName - $GroupIds.Add($NewGroup.GroupId) } + # Fail closed: never add an empty id. A dropped exclusion silently widens the policy + # (e.g. break-glass accounts no longer excluded), and Graph rejects the empty value + # anyway. Surface why the create failed instead of the opaque 1054 group error. + if (-not $NewGroup.Success -or [string]::IsNullOrWhiteSpace($NewGroup.GroupId)) { + throw "Failed to create group '$_' in tenant $TenantFilter$(if ($NewGroup.Error) { ": $($NewGroup.Error)" }). Resolve the group manually or remove the duplicate group template, then redeploy." + } + $GroupIds.Add($NewGroup.GroupId) } else { Write-Warning "Group $_ not found in the tenant and CreateGroups is disabled" throw "Group '$_' not found in tenant $TenantFilter. Enable 'Create groups if they do not exist' or create the group manually before deploying this policy." @@ -488,8 +502,14 @@ function New-CIPPCAPolicy { } } switch ($ReplacePattern) { - 'none' { + { $_ -in 'none', 'leave' } { + # The deploy drawer sends 'leave'; treat it like 'none'. Write-Information 'Replacement pattern for inclusions and exclusions is none' + # Graph wants ids; a name-based template fails with an opaque 1054, so say why here. + $NamedGroups = @(@($JSONobj.conditions.users.includeGroups) + @($JSONobj.conditions.users.excludeGroups) | Where-Object { -not [string]::IsNullOrWhiteSpace($_) -and -not (Test-IsGuid -String $_) }) + if ($NamedGroups.Count -gt 0) { + throw "Policy '$($JSONobj.displayName)' references groups by name ($($NamedGroups -join ', ')). Deploy it with 'Replace by display name' so the names are resolved to group ids, or store object ids in the template." + } break } 'AllUsers' { diff --git a/Modules/CIPPCore/Public/New-CIPPGDAPRoleMapping.ps1 b/Modules/CIPPCore/Public/New-CIPPGDAPRoleMapping.ps1 new file mode 100644 index 0000000000000..d8548e830f7da --- /dev/null +++ b/Modules/CIPPCore/Public/New-CIPPGDAPRoleMapping.ps1 @@ -0,0 +1,110 @@ +function New-CIPPGDAPRoleMapping { + <# + .SYNOPSIS + Creates or reuses the partner tenant security groups backing a set of GDAP roles + + .DESCRIPTION + For each role a group named 'M365 GDAP ' (optionally suffixed) is reused when it + already exists in the partner tenant, otherwise created. The resulting mappings are upserted + into the GDAPRoles table and returned for template writes. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + $Roles, + [string]$CustomSuffix + ) + + $Table = Get-CIPPTable -TableName 'GDAPRoles' + + $Results = [System.Collections.Generic.List[string]]::new() + $Requests = [System.Collections.Generic.List[object]]::new() + $ExistingGroups = New-GraphGetRequest -NoAuthCheck $True -uri 'https://graph.microsoft.com/beta/groups' -tenantid $env:TenantID -AsApp $true + + $ExistingRoleMappings = foreach ($Role in $Roles) { + $RoleName = $Role.label ?? $Role.Name + $Value = $Role.value ?? $Role.ObjectId + + if ($CustomSuffix) { + $GroupName = "M365 GDAP $($RoleName) - $CustomSuffix" + $MailNickname = "M365GDAP$(($RoleName).replace(' ',''))$($CustomSuffix.replace(' ',''))" + } else { + $GroupName = "M365 GDAP $($RoleName)" + $MailNickname = "M365GDAP$(($RoleName).replace(' ',''))" + } + + if ($GroupName -in $ExistingGroups.displayName) { + @{ + PartitionKey = 'Roles' + RowKey = ($ExistingGroups | Where-Object -Property displayName -EQ $GroupName | Select-Object -First 1).id + RoleName = $RoleName + GroupName = $GroupName + GroupId = ($ExistingGroups | Where-Object -Property displayName -EQ $GroupName | Select-Object -First 1).id + roleDefinitionId = $Value + } + $Results.Add("$GroupName already exists") + } else { + $Requests.Add(@{ + id = $Value + url = '/groups' + method = 'POST' + headers = @{ + 'Content-Type' = 'application/json' + } + body = @{ + displayName = $GroupName + description = "This group is used to manage M365 partner tenants at the $($RoleName) level." + securityEnabled = $true + mailEnabled = $false + mailNickname = $MailNickname + } + }) + } + } + + if ($ExistingRoleMappings) { + Add-CIPPAzDataTableEntity @Table -Entity $ExistingRoleMappings -Force + } + + if ($Requests) { + $ReturnedData = New-GraphBulkRequest -Requests $Requests -tenantid $env:TenantID -NoAuthCheck $True -asapp $true + $NewRoleMappings = foreach ($Return in $ReturnedData) { + if ($Return.body.error) { + $Results.Add("Could not create GDAP group: $($Return.body.error.message)") + } else { + $GroupName = $Return.body.displayName + @{ + PartitionKey = 'Roles' + RowKey = $Return.body.id + RoleName = $Return.body.displayName -replace '^M365 GDAP ', '' -replace " - $CustomSuffix$", '' + GroupName = $Return.body.displayName + GroupId = $Return.body.id + roleDefinitionId = $Return.id + } + $Results.Add("Created $($GroupName)") + } + } + Write-Information ($NewRoleMappings | ConvertTo-Json -Depth 10 -Compress) + if ($NewRoleMappings) { + Add-CIPPAzDataTableEntity @Table -Entity $NewRoleMappings -Force + } + } + + $RoleMappings = [System.Collections.Generic.List[object]]::new() + foreach ($Mapping in @($ExistingRoleMappings) + @($NewRoleMappings)) { + if (!$Mapping) { continue } + $RoleMappings.Add([PSCustomObject]@{ + RoleName = $Mapping.RoleName + GroupName = $Mapping.GroupName + GroupId = $Mapping.GroupId + roleDefinitionId = $Mapping.roleDefinitionId + }) + } + + return [PSCustomObject]@{ + RoleMappings = $RoleMappings + Results = $Results + } +} diff --git a/Modules/CIPPCore/Public/New-CIPPIntuneAppDeployment.ps1 b/Modules/CIPPCore/Public/New-CIPPIntuneAppDeployment.ps1 index b9accba7a50e3..0ce44860f248d 100644 --- a/Modules/CIPPCore/Public/New-CIPPIntuneAppDeployment.ps1 +++ b/Modules/CIPPCore/Public/New-CIPPIntuneAppDeployment.ps1 @@ -25,6 +25,11 @@ function New-CIPPIntuneAppDeployment { $ExcludeGroup = $AppConfig.excludeGroup $AppType = if ($AppConfig.type) { $AppConfig.type } else { 'Choco' } + # Older templates may hold a Graph-read body (has an id); only Office/Edge can deploy from one. + if ($IntuneBody.id -and $AppType -notin @('OfficeApp', 'EdgeApp')) { + throw "'$($AppConfig.Applicationname)' was templated from an existing Intune application with uploaded installer content. CIPP cannot deploy uploaded installer content; only script or package based applications can be templated. Rebuild this template entry as a Store, Chocolatey, Office, Edge, MSP or Custom Application." + } + # Build IntuneBody from raw config if not pre-built (template/standard path) if (-not $IntuneBody -and $AppType -eq 'WinGet') { $PackageId = $AppConfig.packagename ?? $AppConfig.PackageName @@ -116,13 +121,12 @@ function New-CIPPIntuneAppDeployment { $BaseUri = 'https://graph.microsoft.com/beta/deviceAppManagement/mobileApps' - # Check if app already exists (any type with matching display name). Office is a singleton per - # tenant and Graph names it 'Microsoft 365 Apps for Windows 10 and later' regardless of what the - # template calls it, so match that one on type instead or it is redeployed on every run. - $ApplicationList = if ($AppType -eq 'OfficeApp') { - New-GraphGetRequest -Uri $BaseUri -tenantid $TenantFilter | Where-Object { $_.'@odata.type' -eq '#microsoft.graph.officeSuiteApp' } - } else { - New-GraphGetRequest -Uri $BaseUri -tenantid $TenantFilter | Where-Object { $_.DisplayName -eq $AppConfig.Applicationname } + # Check if app already exists (any type with matching display name). Office and Edge are + # singletons per tenant whose Graph display name may differ from the template, so match on type. + $ApplicationList = switch ($AppType) { + 'OfficeApp' { New-GraphGetRequest -Uri $BaseUri -tenantid $TenantFilter | Where-Object { $_.'@odata.type' -eq '#microsoft.graph.officeSuiteApp' } } + 'EdgeApp' { New-GraphGetRequest -Uri $BaseUri -tenantid $TenantFilter | Where-Object { $_.'@odata.type' -eq '#microsoft.graph.windowsMicrosoftEdgeApp' } } + default { New-GraphGetRequest -Uri $BaseUri -tenantid $TenantFilter | Where-Object { $_.DisplayName -eq $AppConfig.Applicationname } } } if ($ApplicationList.displayname.count -ge 1) { Write-LogMessage -API $APIName -tenant $TenantFilter -message "$($AppConfig.Applicationname) exists. Skipping this application" -Sev 'Info' @@ -209,6 +213,13 @@ function New-CIPPIntuneAppDeployment { } $NewApp = New-GraphPostRequest -Uri $BaseUri -tenantid $TenantFilter -Body (ConvertTo-Json -InputObject $ObjBody -Depth 10) -Type POST } + 'EdgeApp' { + $ObjBody = Get-CIPPEdgeAppBody -Config $AppConfig + if (-not $ObjBody) { + throw "No Edge configuration could be built from the supplied settings for '$($AppConfig.Applicationname)'." + } + $NewApp = New-GraphPostRequest -Uri $BaseUri -tenantid $TenantFilter -Body (ConvertTo-Json -InputObject $ObjBody -Depth 10) -Type POST + } default { throw "Unsupported app type: $AppType" } @@ -224,6 +235,7 @@ function New-CIPPIntuneAppDeployment { 'WinGet' { 'WinGet' } 'WinGetNew' { 'WinGet' } 'OfficeApp' { $null } + 'EdgeApp' { $null } default { 'Win32Lob' } } Start-Sleep -Milliseconds 200 diff --git a/Modules/CIPPCore/Public/New-CIPPIntuneTemplate.ps1 b/Modules/CIPPCore/Public/New-CIPPIntuneTemplate.ps1 index db4dc19e6e7aa..c38d5d39f0540 100644 --- a/Modules/CIPPCore/Public/New-CIPPIntuneTemplate.ps1 +++ b/Modules/CIPPCore/Public/New-CIPPIntuneTemplate.ps1 @@ -61,6 +61,29 @@ function New-CIPPIntuneTemplate { 'mobileAppConfigurations' { $Type = 'AppConfiguration' $Template = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/deviceAppManagement/$($urlname)('$($ID)')" -tenantid $TenantFilter + # targetedMobileApps are mobileApp ids, which only mean something in the tenant the + # policy was captured from - deploying them elsewhere fails with an unknown app. Record + # each app's identity (bundle / package id, name, type) so deployment can find the same + # app in the target tenant. See Resolve-CIPPIntuneTargetedMobileApps. + $TargetedAppDetails = foreach ($AppId in @($Template.targetedMobileApps | Where-Object { $_ })) { + try { + $App = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/deviceAppManagement/mobileApps/$AppId" -tenantid $TenantFilter + [PSCustomObject]@{ + id = $App.id + displayName = $App.displayName + '@odata.type' = $App.'@odata.type' + bundleId = $App.bundleId + packageId = $App.packageId + packageIdentifier = $App.packageIdentifier + appStoreUrl = $App.appStoreUrl + } + } catch { + Write-Warning "Could not read targeted app $AppId for app configuration '$($Template.displayName)': $($_.Exception.Message)" + } + } + if ($TargetedAppDetails) { + $Template | Add-Member -NotePropertyName 'targetedMobileAppsDetails' -NotePropertyValue @($TargetedAppDetails) -Force + } $DisplayName = $Template.displayName $TemplateJson = ConvertTo-Json -InputObject $Template -Depth 100 -Compress } diff --git a/Modules/CIPPCore/Public/New-CIPPSharePointLibrary.ps1 b/Modules/CIPPCore/Public/New-CIPPSharePointLibrary.ps1 index f58c9520102a6..98911e5e6d0b2 100644 --- a/Modules/CIPPCore/Public/New-CIPPSharePointLibrary.ps1 +++ b/Modules/CIPPCore/Public/New-CIPPSharePointLibrary.ps1 @@ -37,10 +37,10 @@ function New-CIPPSharePointLibrary { $Headers ) - $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter - $Scope = "$($SharePointInfo.SharePointUrl)/.default" - $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $Scope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri # Idempotency: return the existing library when one with this title is already present. $EscapedTitle = $LibraryName -replace "'", "''" diff --git a/Modules/CIPPCore/Public/New-CIPPTemplateRun.ps1 b/Modules/CIPPCore/Public/New-CIPPTemplateRun.ps1 index dc7ab7c8899c1..08fcdec56df1e 100644 --- a/Modules/CIPPCore/Public/New-CIPPTemplateRun.ps1 +++ b/Modules/CIPPCore/Public/New-CIPPTemplateRun.ps1 @@ -5,14 +5,28 @@ function New-CIPPTemplateRun { $TenantFilter ) $Table = Get-CippTable -tablename 'templates' + + # Templates created from a tenant are keyed by that tenant in their Source column and matched + # on it to update-in-place. The tenant can be addressed by any of its names (default domain, + # initial onmicrosoft domain, tenant id), and a second sync task created under a different name + # used to see none of the existing templates and create a full duplicate set on every run. + # Match on every name the tenant is known by and write the canonical one. + $TenantInfo = Get-Tenants -IncludeErrors -TenantFilter $TenantFilter | Select-Object -First 1 + $SourceAliases = @(@($TenantFilter, $TenantInfo.defaultDomainName, $TenantInfo.initialDomainName, $TenantInfo.customerId) | Where-Object { -not [string]::IsNullOrWhiteSpace($_) } | Select-Object -Unique) + $SourceName = if ($TenantInfo.defaultDomainName) { [string]$TenantInfo.defaultDomainName } else { [string]$TenantFilter } + $ExistingTemplates = (Get-CIPPAzDataTableEntity @Table) | ForEach-Object { try { $data = $_.JSON | ConvertFrom-Json -ErrorAction SilentlyContinue -Depth 100 - $data | Add-Member -NotePropertyName 'GUID' -NotePropertyValue $_.RowKey -Force -ErrorAction Stop - $data | Add-Member -NotePropertyName 'PartitionKey' -NotePropertyValue $_.PartitionKey -Force -ErrorAction Stop - $data | Add-Member -NotePropertyName 'SHA' -NotePropertyValue $_.SHA -Force -ErrorAction SilentlyContinue - $data | Add-Member -NotePropertyName 'Package' -NotePropertyValue $_.Package -Force -ErrorAction SilentlyContinue - $data | Add-Member -NotePropertyName 'Source' -NotePropertyValue $_.Source -Force -ErrorAction SilentlyContinue + $data | Add-Member -NotePropertyMembers ([ordered]@{ + GUID = $_.RowKey + PartitionKey = $_.PartitionKey + }) -Force -ErrorAction Stop + $data | Add-Member -NotePropertyMembers ([ordered]@{ + SHA = $_.SHA + Package = $_.Package + Source = $_.Source + }) -Force -ErrorAction SilentlyContinue $data } catch { return @@ -117,7 +131,7 @@ function New-CIPPTemplateRun { foreach ($policy in $policies) { try { $Hash = Get-StringHash -String ($policy | ConvertTo-Json -Depth 100 -Compress) - $ExistingPolicy = $ExistingTemplates | Where-Object { $_.PartitionKey -eq 'CATemplate' -and $_.displayName -eq $policy.displayName -and $_.Source -eq $TenantFilter } | Select-Object -First 1 + $ExistingPolicy = $ExistingTemplates | Where-Object { $_.PartitionKey -eq 'CATemplate' -and $_.displayName -eq $policy.displayName -and $_.Source -in $SourceAliases } | Select-Object -First 1 if ($ExistingPolicy -and $ExistingPolicy.SHA -eq $Hash) { "CA Policy $($policy.displayName) found, SHA matches, skipping template creation" continue @@ -127,10 +141,12 @@ function New-CIPPTemplateRun { if ($ExistingPolicy -and $ExistingPolicy.PartitionKey -eq 'CATemplate') { "CA Policy $($policy.displayName) found, updating template" + # Full replace: carry Package across like the Intune branches do. Add-CIPPAzDataTableEntity @Table -Entity @{ JSON = "$Template" RowKey = $ExistingPolicy.GUID PartitionKey = 'CATemplate' + Package = $ExistingPolicy.Package GUID = $ExistingPolicy.GUID SHA = $Hash Source = $ExistingPolicy.Source @@ -144,7 +160,7 @@ function New-CIPPTemplateRun { PartitionKey = 'CATemplate' GUID = "$GUID" SHA = $Hash - Source = $TenantFilter + Source = $SourceName } } @@ -188,7 +204,7 @@ function New-CIPPTemplateRun { $Hash = Get-StringHash -String ($Policy | ConvertTo-Json -Depth 100 -Compress) $DisplayName = $Policy.displayName ?? $Policy.name - $ExistingPolicy = $ExistingTemplates | Where-Object { $_.PartitionKey -eq 'IntuneTemplate' -and $_.displayName -eq $DisplayName -and $_.Source -eq $TenantFilter } | Select-Object -First 1 + $ExistingPolicy = $ExistingTemplates | Where-Object { $_.PartitionKey -eq 'IntuneTemplate' -and $_.displayName -eq $DisplayName -and $_.Source -in $SourceAliases } | Select-Object -First 1 Write-Information "Processing Intune Configuration Policy $($DisplayName) - $($ExistingPolicy ? 'Existing template found' : 'No existing template found')" @@ -234,7 +250,7 @@ function New-CIPPTemplateRun { PartitionKey = 'IntuneTemplate' GUID = "$GUID" SHA = $Hash - Source = $TenantFilter + Source = $SourceName } -Force } } catch { @@ -253,7 +269,7 @@ function New-CIPPTemplateRun { foreach ($Policy in $Policies) { try { $Hash = Get-StringHash -String (ConvertTo-Json -Depth 100 -Compress -InputObject $Policy) - $ExistingPolicy = $ExistingTemplates | Where-Object { $_.PartitionKey -eq 'IntuneTemplate' -and $Policy.displayName -eq $_.DisplayName -and $_.Source -eq $TenantFilter } | Select-Object -First 1 + $ExistingPolicy = $ExistingTemplates | Where-Object { $_.PartitionKey -eq 'IntuneTemplate' -and $Policy.displayName -eq $_.DisplayName -and $_.Source -in $SourceAliases } | Select-Object -First 1 if ($ExistingPolicy -and $ExistingPolicy.SHA -eq $Hash) { "Intune Compliance Policy $($Policy.displayName) found, SHA matches, skipping template creation" continue @@ -296,7 +312,7 @@ function New-CIPPTemplateRun { PartitionKey = 'IntuneTemplate' SHA = $Hash GUID = "$GUID" - Source = $TenantFilter + Source = $SourceName } -Force } } catch { @@ -312,7 +328,7 @@ function New-CIPPTemplateRun { foreach ($Policy in $Policies) { try { $Hash = Get-StringHash -String (ConvertTo-Json -Depth 100 -Compress -InputObject $Policy) - $ExistingPolicy = $ExistingTemplates | Where-Object { $_.PartitionKey -eq 'IntuneTemplate' -and $Policy.displayName -eq $_.DisplayName -and $_.Source -eq $TenantFilter } | Select-Object -First 1 + $ExistingPolicy = $ExistingTemplates | Where-Object { $_.PartitionKey -eq 'IntuneTemplate' -and $Policy.displayName -eq $_.DisplayName -and $_.Source -in $SourceAliases } | Select-Object -First 1 if ($ExistingPolicy -and $ExistingPolicy.SHA -eq $Hash) { "Intune Protection Policy $($Policy.displayName) found, SHA matches, skipping template creation" continue @@ -355,7 +371,7 @@ function New-CIPPTemplateRun { PartitionKey = 'IntuneTemplate' SHA = $Hash GUID = "$GUID" - Source = $TenantFilter + Source = $SourceName } -Force } } catch { diff --git a/Modules/CIPPCore/Public/New-CIPPUserTask.ps1 b/Modules/CIPPCore/Public/New-CIPPUserTask.ps1 index a793bb717dde4..b47c28f8111b6 100644 --- a/Modules/CIPPCore/Public/New-CIPPUserTask.ps1 +++ b/Modules/CIPPCore/Public/New-CIPPUserTask.ps1 @@ -164,13 +164,23 @@ function New-CIPPUserTask { # task per level. They are separate Exchange operations anyway. $MailboxPermissions = @(@($UserObj.sharedMailboxPermission) | ForEach-Object { if ($_.value) { $_.value } else { $_ } } | Where-Object { $_ }) if (-not $MailboxPermissions) { $MailboxPermissions = @('FullAccess') } + # FullAccessNoAutoMap is Full Access granted with automapping off. A grant carries one + # automapping flag, so when both variants are selected the explicit no-automapping wins. + if ($MailboxPermissions -contains 'FullAccessNoAutoMap') { + $MailboxPermissions = @($MailboxPermissions | Where-Object { $_ -ne 'FullAccess' }) + } foreach ($Mailbox in @($UserObj.sharedMailboxes)) { $MailboxId = if ($Mailbox.value) { $Mailbox.value } else { $Mailbox } $MailboxLabel = if ($Mailbox.label) { $Mailbox.label } else { $MailboxId } foreach ($MailboxPermission in $MailboxPermissions) { + $PermissionLevel = if ($MailboxPermission -eq 'FullAccessNoAutoMap') { 'FullAccess' } else { $MailboxPermission } + $AutoMap = $MailboxPermission -ne 'FullAccessNoAutoMap' # AutoMap only applies to FullAccess, and is what makes Outlook mount the mailbox # on its own, so no invitation is needed on this side of the feature. - $AutoMapNote = if ($MailboxPermission -eq 'FullAccess') { ' Outlook adds the mailbox automatically.' } else { '' } + $AutoMapNote = if ($PermissionLevel -ne 'FullAccess') { '' } + elseif ($AutoMap) { ' Outlook adds the mailbox automatically.' } + else { ' Automapping is off, so the user adds the mailbox to Outlook themselves.' } + $PermissionDisplay = if ($AutoMap) { $PermissionLevel } else { 'FullAccess (no automapping)' } $SharedAccessGrants.Add([PSCustomObject]@{ Identity = $MailboxId Kind = 'mailbox' @@ -181,12 +191,12 @@ function New-CIPPUserTask { TenantFilter = $UserObj.tenantFilter UserId = $MailboxId AccessUser = $CreationResults.Username - PermissionLevel = $MailboxPermission + PermissionLevel = $PermissionLevel Action = 'Add' - AutoMap = $true + AutoMap = $AutoMap APIName = 'Shared Mailbox Onboarding' } - Success = "Scheduled $MailboxPermission on the shared mailbox $MailboxLabel in 15 minutes.$AutoMapNote" + Success = "Scheduled $PermissionDisplay on the shared mailbox $MailboxLabel in 15 minutes.$AutoMapNote" }) } } @@ -230,6 +240,16 @@ function New-CIPPUserTask { $Results.Add($SponsorResults.Result) } + try { + if ($UserObj.perUserMfa -eq $true) { + $MfaResult = Set-CIPPPerUserMFA -TenantFilter $UserObj.tenantFilter -userId $CreationResults.Username -State 'enforced' -Headers $Headers -APIName $APIName + $Results.Add($MfaResult) + } + } catch { + Write-LogMessage -headers $Headers -API $APIName -tenant $($UserObj.tenantFilter) -message "Failed to set per-user MFA. Error:$($_.Exception.Message)" -Sev 'Error' + $Results.Add("Failed to set per-user MFA: $($_.Exception.Message)") + } + return @{ Results = $Results Username = $CreationResults.Username diff --git a/Modules/CIPPCore/Public/New-CippStandardsDriftClone.ps1 b/Modules/CIPPCore/Public/New-CippStandardsDriftClone.ps1 index f66d3af836e4a..9854c36ffb699 100644 --- a/Modules/CIPPCore/Public/New-CippStandardsDriftClone.ps1 +++ b/Modules/CIPPCore/Public/New-CippStandardsDriftClone.ps1 @@ -2,8 +2,7 @@ function New-CippStandardsDriftClone { [CmdletBinding()] param ( [Parameter(Mandatory)][string]$TemplateId, - [Parameter(Mandatory)][switch]$UpgradeToDrift, - $Headers + [Parameter(Mandatory)][switch]$UpgradeToDrift ) $Table = Get-CippTable -tablename 'templates' @@ -32,8 +31,8 @@ function New-CippStandardsDriftClone { $Entity.JSON = "$(ConvertTo-Json -InputObject $data -Compress -Depth 100)" $Entity.RowKey = "$($data.GUID)" $Entity.GUID = $data.GUID - $update = Add-CIPPAzDataTableEntity @Table -Entity $Entity -Force - return 'Clone Completed successfully' + $null = Add-CIPPAzDataTableEntity @Table -Entity $Entity -Force + return "Created drift template '$($data.templateName)' ($($data.GUID)) from $TemplateId" } catch { return "Failed to Clone template to Drift Template: $_" } diff --git a/Modules/CIPPCore/Public/PIM/Compare-CIPPPIMRoleSettings.ps1 b/Modules/CIPPCore/Public/PIM/Compare-CIPPPIMRoleSettings.ps1 new file mode 100644 index 0000000000000..2b062bca635e4 --- /dev/null +++ b/Modules/CIPPCore/Public/PIM/Compare-CIPPPIMRoleSettings.ps1 @@ -0,0 +1,152 @@ +function Compare-CIPPPIMRoleSettings { + <# + .SYNOPSIS + Lists the differences between desired PIM policy rules and a role's current rules. + + .DESCRIPTION + Property-level comparison per managed rule so the PIMRoleSettings standard can report + drift precisely and remediate only the rules that differ. Durations compare as timespans + (PT480M equals PT8H); enabled-rule and recipient lists compare as sets. + + .PARAMETER DesiredRules + Output of ConvertTo-CIPPPIMPolicyRules. + + .PARAMETER CurrentRules + The role's current rules. + + .PARAMETER RoleName + Display name used in the output rows. + + .OUTPUTS + PSCustomObject rows: Role, Rule, Property, Expected, Current. Empty when compliant. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [AllowEmptyCollection()] + [array]$DesiredRules, + + [Parameter(Mandatory = $true)] + [AllowNull()] + [AllowEmptyCollection()] + $CurrentRules, + + [string]$RoleName = '' + ) + + $ById = @{} + foreach ($Rule in @($CurrentRules)) { + if ($Rule.id) { $ById[$Rule.id] = $Rule } + } + + $Differences = [System.Collections.Generic.List[object]]::new() + $RoleLabel = $RoleName + + function Add-Difference { + param([string]$Rule, [string]$Property, $Expected, $Current) + $Differences.Add([PSCustomObject]@{ + Role = $RoleLabel + Rule = $Rule + Property = $Property + Expected = $Expected + Current = $Current + }) + } + + function Test-SameDuration { + param([string]$Expected, [string]$Current) + if ([string]::IsNullOrWhiteSpace($Expected) -or [string]::IsNullOrWhiteSpace($Current)) { return ($Expected -eq $Current) } + try { + return ([System.Xml.XmlConvert]::ToTimeSpan($Expected) -eq [System.Xml.XmlConvert]::ToTimeSpan($Current)) + } catch { + return ($Expected -eq $Current) + } + } + + function Test-SameSet { + param($Expected, $Current) + $ExpectedSet = @($Expected | ForEach-Object { "$_".ToLowerInvariant() } | Where-Object { $_ } | Sort-Object -Unique) + $CurrentSet = @($Current | ForEach-Object { "$_".ToLowerInvariant() } | Where-Object { $_ } | Sort-Object -Unique) + if ($ExpectedSet.Count -ne $CurrentSet.Count) { return $false } + for ($i = 0; $i -lt $ExpectedSet.Count; $i++) { + if ($ExpectedSet[$i] -ne $CurrentSet[$i]) { return $false } + } + return $true + } + + function Get-ApproverKeys { + param($Setting) + $Keys = @() + if ($Setting -and $Setting.approvalStages) { + foreach ($Stage in @($Setting.approvalStages)) { + foreach ($Approver in @($Stage.primaryApprovers)) { + # Property access works for both the hashtables we build and Graph's objects. + $Keys += ($Approver.groupId ?? $Approver.userId) + } + } + } + return @($Keys | Where-Object { $_ }) + } + + foreach ($Desired in $DesiredRules) { + $Id = $Desired['id'] + $Current = $ById[$Id] + if (-not $Current) { + Add-Difference -Rule $Id -Property 'rule' -Expected 'present' -Current 'missing' + continue + } + + switch -Wildcard ($Desired['@odata.type']) { + '*ExpirationRule' { + if ([bool]$Current.isExpirationRequired -ne [bool]$Desired['isExpirationRequired']) { + Add-Difference -Rule $Id -Property 'isExpirationRequired' -Expected $Desired['isExpirationRequired'] -Current $Current.isExpirationRequired + } + if ($Desired['isExpirationRequired'] -and -not (Test-SameDuration -Expected $Desired['maximumDuration'] -Current $Current.maximumDuration)) { + Add-Difference -Rule $Id -Property 'maximumDuration' -Expected $Desired['maximumDuration'] -Current $Current.maximumDuration + } + } + '*EnablementRule' { + if (-not (Test-SameSet -Expected $Desired['enabledRules'] -Current $Current.enabledRules)) { + Add-Difference -Rule $Id -Property 'enabledRules' -Expected (@($Desired['enabledRules']) -join ', ') -Current (@($Current.enabledRules) -join ', ') + } + } + '*AuthenticationContextRule' { + if ([bool]$Current.isEnabled -ne [bool]$Desired['isEnabled']) { + Add-Difference -Rule $Id -Property 'isEnabled' -Expected $Desired['isEnabled'] -Current $Current.isEnabled + } + if ($Desired['isEnabled'] -and "$($Current.claimValue)" -ne "$($Desired['claimValue'])") { + Add-Difference -Rule $Id -Property 'claimValue' -Expected $Desired['claimValue'] -Current $Current.claimValue + } + } + '*ApprovalRule' { + $ExpectedRequired = [bool]$Desired['setting']['isApprovalRequired'] + $CurrentRequired = [bool]($Current.setting -and $Current.setting.isApprovalRequired -eq $true) + if ($ExpectedRequired -ne $CurrentRequired) { + Add-Difference -Rule $Id -Property 'setting.isApprovalRequired' -Expected $ExpectedRequired -Current $CurrentRequired + } elseif ($ExpectedRequired) { + $ExpectedApprovers = Get-ApproverKeys -Setting $Desired['setting'] + $CurrentApprovers = Get-ApproverKeys -Setting $Current.setting + if (-not (Test-SameSet -Expected $ExpectedApprovers -Current $CurrentApprovers)) { + Add-Difference -Rule $Id -Property 'setting.approvalStages.primaryApprovers' -Expected ($ExpectedApprovers -join ', ') -Current ($CurrentApprovers -join ', ') + } + } + } + '*NotificationRule' { + if ("$($Current.notificationLevel)" -ne "$($Desired['notificationLevel'])") { + Add-Difference -Rule $Id -Property 'notificationLevel' -Expected $Desired['notificationLevel'] -Current $Current.notificationLevel + } + if ([bool]$Current.isDefaultRecipientsEnabled -ne [bool]$Desired['isDefaultRecipientsEnabled']) { + Add-Difference -Rule $Id -Property 'isDefaultRecipientsEnabled' -Expected $Desired['isDefaultRecipientsEnabled'] -Current $Current.isDefaultRecipientsEnabled + } + if (-not (Test-SameSet -Expected $Desired['notificationRecipients'] -Current $Current.notificationRecipients)) { + Add-Difference -Rule $Id -Property 'notificationRecipients' -Expected (@($Desired['notificationRecipients']) -join ', ') -Current (@($Current.notificationRecipients) -join ', ') + } + } + } + } + + return @($Differences) +} diff --git a/Modules/CIPPCore/Public/PIM/ConvertFrom-CIPPPIMPolicyRules.ps1 b/Modules/CIPPCore/Public/PIM/ConvertFrom-CIPPPIMPolicyRules.ps1 new file mode 100644 index 0000000000000..054711b26e782 --- /dev/null +++ b/Modules/CIPPCore/Public/PIM/ConvertFrom-CIPPPIMPolicyRules.ps1 @@ -0,0 +1,87 @@ +function ConvertFrom-CIPPPIMPolicyRules { + <# + .SYNOPSIS + Reads a tenant's PIM role management policy rules into the canonical settings shape. + + .DESCRIPTION + Inverse of ConvertTo-CIPPPIMPolicyRules. Lets a live policy be graded against the secure + floor (Test-CIPPPIMRoleSettingsFloor) and summarised (Get-CIPPPIMPolicySummary) with the + same code that handles templates. + + A $null duration means the rule does not require expiration, i.e. permanent + assignments/eligibilities are allowed by that policy. + + .PARAMETER Rules + The policy's rules (unifiedRoleManagementPolicyRule collection), from + policies/roleManagementPolicies/{id}/rules or the RoleManagementPolicies cache. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [AllowNull()] + [AllowEmptyCollection()] + $Rules + ) + + $ById = @{} + foreach ($Rule in @($Rules)) { + if ($Rule.id) { $ById[$Rule.id] = $Rule } + } + + function Get-ExpirationDuration { + param([string]$RuleId) + $Rule = $ById[$RuleId] + if (-not $Rule) { return $null } + if ($Rule.isExpirationRequired -ne $true) { return $null } + return $Rule.maximumDuration + } + + function Get-EnabledRules { + param([string]$RuleId) + $Rule = $ById[$RuleId] + if (-not $Rule) { return @() } + return @($Rule.enabledRules) + } + + $ActivationEnablement = Get-EnabledRules 'Enablement_EndUser_Assignment' + $AuthContext = $ById['AuthenticationContext_EndUser_Assignment'] + $Approval = $ById['Approval_EndUser_Assignment'] + $AdminEnablement = Get-EnabledRules 'Enablement_Admin_Assignment' + $Notification = $ById['Notification_Admin_EndUser_Assignment'] + + $ActivationRequires = if ($AuthContext -and $AuthContext.isEnabled -eq $true) { + 'AuthenticationContext' + } elseif ($ActivationEnablement -contains 'MultiFactorAuthentication') { + 'MFA' + } else { + 'None' + } + + $Approvers = @() + if ($Approval -and $Approval.setting -and $Approval.setting.approvalStages) { + foreach ($Stage in @($Approval.setting.approvalStages)) { + foreach ($Approver in @($Stage.primaryApprovers)) { + $Approvers += ($Approver.description ?? $Approver.groupId ?? $Approver.userId) + } + } + } + + [PSCustomObject]@{ + activationMaxDuration = Get-ExpirationDuration 'Expiration_EndUser_Assignment' + activationRequires = $ActivationRequires + authenticationContextClaimValue = if ($AuthContext) { $AuthContext.claimValue } else { '' } + activationRequiresJustification = ($ActivationEnablement -contains 'Justification') + activationRequiresTicket = ($ActivationEnablement -contains 'Ticketing') + activationRequiresApproval = [bool]($Approval -and $Approval.setting -and $Approval.setting.isApprovalRequired -eq $true) + approvers = ($Approvers | Where-Object { $_ }) -join ', ' + eligibilityMaxDuration = Get-ExpirationDuration 'Expiration_Admin_Eligibility' + activeAssignmentMaxDuration = Get-ExpirationDuration 'Expiration_Admin_Assignment' + activeAssignmentRequiresMfa = ($AdminEnablement -contains 'MultiFactorAuthentication') + activeAssignmentRequiresJustification = ($AdminEnablement -contains 'Justification') + notificationRecipients = if ($Notification) { @($Notification.notificationRecipients) -join ', ' } else { '' } + notificationLevel = if ($Notification) { $Notification.notificationLevel } else { 'All' } + } +} diff --git a/Modules/CIPPCore/Public/PIM/ConvertTo-CIPPPIMPolicyRules.ps1 b/Modules/CIPPCore/Public/PIM/ConvertTo-CIPPPIMPolicyRules.ps1 new file mode 100644 index 0000000000000..ed1c5d827a025 --- /dev/null +++ b/Modules/CIPPCore/Public/PIM/ConvertTo-CIPPPIMPolicyRules.ps1 @@ -0,0 +1,160 @@ +function ConvertTo-CIPPPIMPolicyRules { + <# + .SYNOPSIS + Turns canonical PIM role settings into the policy rule objects Graph expects. + + .DESCRIPTION + Produces only the rules CIPP manages, each carrying '@odata.type', 'id' and the 'target' + copied from the tenant's current rule (Graph requires the target on PATCH). Rules CIPP does + not manage (requestor/approver notifications, ticketing for admin assignment, ...) are left + untouched in the tenant. + + Callers validate the settings against the floor BEFORE calling this; it does not re-check. + + .PARAMETER Settings + Canonical settings (ConvertTo-CIPPPIMRoleSettings). + + .PARAMETER CurrentRules + The role's current rules, used for the 'target' and to keep unmanaged approval-stage + details when approval is switched off. + + .PARAMETER ResolvedApprovers + Approver objects already resolved in the tenant: + @{ '@odata.type' = '#microsoft.graph.groupMembers'; groupId = '...'; description = 'Name' } or + @{ '@odata.type' = '#microsoft.graph.singleUser'; userId = '...'; description = 'upn' }. + Required when activationRequiresApproval is true. + + .OUTPUTS + Ordered hashtables, one per managed rule. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + $Settings, + + [Parameter(Mandatory = $true)] + [AllowNull()] + [AllowEmptyCollection()] + $CurrentRules, + + [array]$ResolvedApprovers = @() + ) + + $ById = @{} + foreach ($Rule in @($CurrentRules)) { + if ($Rule.id) { $ById[$Rule.id] = $Rule } + } + + function Get-Target { + param([string]$RuleId) + $Rule = $ById[$RuleId] + if ($Rule -and $Rule.target) { return $Rule.target } + return $null + } + + function ConvertTo-Rule { + param([string]$Id, [string]$Type, [System.Collections.IDictionary]$Properties) + $Rule = [ordered]@{ + '@odata.type' = $Type + id = $Id + } + $Target = Get-Target $Id + if ($Target) { $Rule.target = $Target } + foreach ($Key in $Properties.Keys) { $Rule[$Key] = $Properties[$Key] } + return $Rule + } + + $ExpirationType = '#microsoft.graph.unifiedRoleManagementPolicyExpirationRule' + $EnablementType = '#microsoft.graph.unifiedRoleManagementPolicyEnablementRule' + $AuthContextType = '#microsoft.graph.unifiedRoleManagementPolicyAuthenticationContextRule' + $ApprovalType = '#microsoft.graph.unifiedRoleManagementPolicyApprovalRule' + $NotificationType = '#microsoft.graph.unifiedRoleManagementPolicyNotificationRule' + + $Desired = [System.Collections.Generic.List[object]]::new() + + # Activation (end user) + $Desired.Add((ConvertTo-Rule -Id 'Expiration_EndUser_Assignment' -Type $ExpirationType -Properties ([ordered]@{ + isExpirationRequired = $true + maximumDuration = $Settings.activationMaxDuration + }))) + + $ActivationEnabled = [System.Collections.Generic.List[string]]::new() + if ("$($Settings.activationRequires)" -eq 'MFA') { $ActivationEnabled.Add('MultiFactorAuthentication') } + if ($Settings.activationRequiresJustification) { $ActivationEnabled.Add('Justification') } + if ($Settings.activationRequiresTicket) { $ActivationEnabled.Add('Ticketing') } + $Desired.Add((ConvertTo-Rule -Id 'Enablement_EndUser_Assignment' -Type $EnablementType -Properties ([ordered]@{ + enabledRules = @($ActivationEnabled) + }))) + + $UseAuthContext = ("$($Settings.activationRequires)" -eq 'AuthenticationContext') + $AuthContextProps = [ordered]@{ isEnabled = $UseAuthContext } + if ($UseAuthContext) { $AuthContextProps.claimValue = $Settings.authenticationContextClaimValue } + $Desired.Add((ConvertTo-Rule -Id 'AuthenticationContext_EndUser_Assignment' -Type $AuthContextType -Properties $AuthContextProps)) + + $CurrentApproval = $ById['Approval_EndUser_Assignment'] + if ($Settings.activationRequiresApproval) { + $Desired.Add((ConvertTo-Rule -Id 'Approval_EndUser_Assignment' -Type $ApprovalType -Properties ([ordered]@{ + setting = [ordered]@{ + isApprovalRequired = $true + isApprovalRequiredForExtension = $false + isRequestorJustificationRequired = $true + approvalMode = 'SingleStage' + approvalStages = @( + [ordered]@{ + approvalStageTimeOutInDays = 1 + isApproverJustificationRequired = $true + escalationTimeInMinutes = 0 + primaryApprovers = @($ResolvedApprovers) + isEscalationEnabled = $false + escalationApprovers = @() + } + ) + } + }))) + } else { + # Keep the tenant's stage configuration; only flip the requirement off. + $Setting = [ordered]@{ isApprovalRequired = $false } + if ($CurrentApproval -and $CurrentApproval.setting) { + foreach ($Property in $CurrentApproval.setting.PSObject.Properties) { + if ($Property.Name -ne 'isApprovalRequired') { $Setting[$Property.Name] = $Property.Value } + } + } + $Desired.Add((ConvertTo-Rule -Id 'Approval_EndUser_Assignment' -Type $ApprovalType -Properties ([ordered]@{ setting = $Setting }))) + } + + # Admin eligibility / assignment + $Desired.Add((ConvertTo-Rule -Id 'Expiration_Admin_Eligibility' -Type $ExpirationType -Properties ([ordered]@{ + isExpirationRequired = $true + maximumDuration = $Settings.eligibilityMaxDuration + }))) + $Desired.Add((ConvertTo-Rule -Id 'Expiration_Admin_Assignment' -Type $ExpirationType -Properties ([ordered]@{ + isExpirationRequired = $true + maximumDuration = $Settings.activeAssignmentMaxDuration + }))) + + $AdminEnabled = [System.Collections.Generic.List[string]]::new() + if ($Settings.activeAssignmentRequiresMfa) { $AdminEnabled.Add('MultiFactorAuthentication') } + if ($Settings.activeAssignmentRequiresJustification) { $AdminEnabled.Add('Justification') } + $Desired.Add((ConvertTo-Rule -Id 'Enablement_Admin_Assignment' -Type $EnablementType -Properties ([ordered]@{ + enabledRules = @($AdminEnabled) + }))) + + # Notifications to additional admins - only managed when the template names recipients. + $Recipients = @("$($Settings.notificationRecipients)" -split '[,;]' | ForEach-Object { $_.Trim() } | Where-Object { $_ }) + if ($Recipients.Count -gt 0) { + foreach ($NotificationId in @('Notification_Admin_Admin_Eligibility', 'Notification_Admin_Admin_Assignment', 'Notification_Admin_EndUser_Assignment')) { + $Desired.Add((ConvertTo-Rule -Id $NotificationId -Type $NotificationType -Properties ([ordered]@{ + notificationType = 'Email' + recipientType = 'Admin' + notificationLevel = $Settings.notificationLevel + isDefaultRecipientsEnabled = $true + notificationRecipients = @($Recipients) + }))) + } + } + + return @($Desired) +} diff --git a/Modules/CIPPCore/Public/PIM/ConvertTo-CIPPPIMRoleSettings.ps1 b/Modules/CIPPCore/Public/PIM/ConvertTo-CIPPPIMRoleSettings.ps1 new file mode 100644 index 0000000000000..951b7909d77de --- /dev/null +++ b/Modules/CIPPCore/Public/PIM/ConvertTo-CIPPPIMRoleSettings.ps1 @@ -0,0 +1,92 @@ +function ConvertTo-CIPPPIMRoleSettings { + <# + .SYNOPSIS + Normalises PIM role settings from a request body or stored template into the canonical shape. + + .DESCRIPTION + The template editor posts autoComplete fields as { label, value } objects and switches as + booleans (or 'true'/'false' strings after a JSON round trip). Everything that consumes a + template - the floor check, the rule converter, the standard - works on this one flat + shape with ISO 8601 durations and real booleans, so the unwrapping lives here once. + + Unknown properties are dropped; missing ones take the secure defaults so an older + template keeps validating after new settings are introduced. + + .PARAMETER InputObject + A hashtable or PSCustomObject with any subset of the settings properties. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [AllowNull()] + $InputObject + ) + + function Get-Scalar { + param($Value) + if ($null -eq $Value) { return $null } + if ($Value -is [string] -or $Value -is [bool] -or $Value -is [System.ValueType]) { return $Value } + if ($Value -is [System.Collections.IDictionary]) { + if ($Value.Contains('value')) { return $Value['value'] } + return $null + } + if ($Value.PSObject.Properties['value']) { return $Value.value } + return "$Value" + } + + function Get-Bool { + param($Value, [bool]$Default) + $Scalar = Get-Scalar $Value + if ($null -eq $Scalar -or "$Scalar" -eq '') { return $Default } + if ($Scalar -is [bool]) { return $Scalar } + return ("$Scalar" -match '^(true|1|yes)$') + } + + function Get-Text { + param($Value, [string]$Default = '') + $Scalar = Get-Scalar $Value + if ($null -eq $Scalar) { return $Default } + $Text = "$Scalar".Trim() + if ($Text -eq '') { return $Default } + return $Text + } + + function Get-Prop { + param($Object, [string]$Name) + if ($null -eq $Object) { return $null } + if ($Object -is [System.Collections.IDictionary]) { return $Object[$Name] } + return $Object.$Name + } + + # A multi-select of recipients/approvers may arrive as an array of strings or label/value objects. + function Get-List { + param($Value) + if ($null -eq $Value) { return '' } + if ($Value -is [string]) { return $Value.Trim() } + if ($Value -is [System.Collections.IEnumerable]) { + return (@($Value | ForEach-Object { Get-Text $_ } | Where-Object { $_ }) -join ', ') + } + return (Get-Text $Value) + } + + $Source = $InputObject + + [PSCustomObject]@{ + activationMaxDuration = Get-Text (Get-Prop $Source 'activationMaxDuration') 'PT8H' + activationRequires = Get-Text (Get-Prop $Source 'activationRequires') 'MFA' + authenticationContextClaimValue = Get-Text (Get-Prop $Source 'authenticationContextClaimValue') + activationRequiresJustification = Get-Bool (Get-Prop $Source 'activationRequiresJustification') $true + activationRequiresTicket = Get-Bool (Get-Prop $Source 'activationRequiresTicket') $false + activationRequiresApproval = Get-Bool (Get-Prop $Source 'activationRequiresApproval') $false + approvers = Get-List (Get-Prop $Source 'approvers') + eligibilityMaxDuration = Get-Text (Get-Prop $Source 'eligibilityMaxDuration') 'P365D' + activeAssignmentMaxDuration = Get-Text (Get-Prop $Source 'activeAssignmentMaxDuration') 'P180D' + activeAssignmentRequiresMfa = Get-Bool (Get-Prop $Source 'activeAssignmentRequiresMfa') $true + activeAssignmentRequiresJustification = Get-Bool (Get-Prop $Source 'activeAssignmentRequiresJustification') $true + notificationRecipients = Get-List (Get-Prop $Source 'notificationRecipients') + notificationLevel = Get-Text (Get-Prop $Source 'notificationLevel') 'All' + } +} diff --git a/Modules/CIPPCore/Public/PIM/Get-CIPPPIMPolicySummary.ps1 b/Modules/CIPPCore/Public/PIM/Get-CIPPPIMPolicySummary.ps1 new file mode 100644 index 0000000000000..266bb48b974ff --- /dev/null +++ b/Modules/CIPPCore/Public/PIM/Get-CIPPPIMPolicySummary.ps1 @@ -0,0 +1,81 @@ +function Get-CIPPPIMPolicySummary { + <# + .SYNOPSIS + Summarises PIM role settings for display and grades them against the secure floor. + + .PARAMETER Settings + Canonical settings (ConvertTo-CIPPPIMRoleSettings or ConvertFrom-CIPPPIMPolicyRules output). + + .OUTPUTS + PSCustomObject with SummaryText (e.g. "Activation <= 8h | MFA | Justification | Eligibility <= 1y + | Active <= 6mo"), the individual flags, BelowFloor and FloorIssues. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [AllowNull()] + $Settings + ) + + function ConvertTo-FriendlyDuration { + param([string]$Iso) + if ([string]::IsNullOrWhiteSpace($Iso)) { return $null } + try { $Span = [System.Xml.XmlConvert]::ToTimeSpan($Iso) } catch { return $Iso } + if ($Span.TotalDays -ge 365 -and ($Span.TotalDays % 365) -eq 0) { return "$([int]($Span.TotalDays / 365))y" } + if ($Span.TotalDays -ge 30 -and ($Span.TotalDays % 30) -eq 0) { return "$([int]($Span.TotalDays / 30))mo" } + if ($Span.TotalDays -ge 1 -and $Span.TotalDays -eq [math]::Floor($Span.TotalDays)) { return "$([int]$Span.TotalDays)d" } + if ($Span.TotalHours -ge 1 -and $Span.TotalHours -eq [math]::Floor($Span.TotalHours)) { return "$([int]$Span.TotalHours)h" } + return "$([int]$Span.TotalMinutes)m" + } + + if ($null -eq $Settings) { + return [PSCustomObject]@{ + SummaryText = 'No PIM policy' + MaxActivation = $null + RequiresMfa = $false + RequiresAuthenticationContext = $false + RequiresJustification = $false + RequiresTicket = $false + RequiresApproval = $false + EligibilityExpirationRequired = $false + ActiveAssignmentExpirationRequired = $false + BelowFloor = $true + FloorIssues = @('No PIM policy found for this role.') + } + } + + $Parts = [System.Collections.Generic.List[string]]::new() + $Activation = ConvertTo-FriendlyDuration $Settings.activationMaxDuration + $Parts.Add($(if ($Activation) { "Activation <= $Activation" } else { 'Activation unlimited' })) + switch ("$($Settings.activationRequires)") { + 'MFA' { $Parts.Add('MFA') } + 'AuthenticationContext' { $Parts.Add("Auth context $($Settings.authenticationContextClaimValue)") } + default { $Parts.Add('No MFA') } + } + $Parts.Add($(if ($Settings.activationRequiresJustification) { 'Justification' } else { 'No justification' })) + if ($Settings.activationRequiresTicket) { $Parts.Add('Ticket') } + if ($Settings.activationRequiresApproval) { $Parts.Add('Approval') } + $Eligibility = ConvertTo-FriendlyDuration $Settings.eligibilityMaxDuration + $Parts.Add($(if ($Eligibility) { "Eligibility <= $Eligibility" } else { 'Permanent eligibility allowed' })) + $Active = ConvertTo-FriendlyDuration $Settings.activeAssignmentMaxDuration + $Parts.Add($(if ($Active) { "Active <= $Active" } else { 'Permanent active allowed' })) + + $Floor = Test-CIPPPIMRoleSettingsFloor -Settings $Settings + + [PSCustomObject]@{ + SummaryText = ($Parts -join ' | ') + MaxActivation = $Settings.activationMaxDuration + RequiresMfa = ("$($Settings.activationRequires)" -eq 'MFA') + RequiresAuthenticationContext = ("$($Settings.activationRequires)" -eq 'AuthenticationContext') + RequiresJustification = [bool]$Settings.activationRequiresJustification + RequiresTicket = [bool]$Settings.activationRequiresTicket + RequiresApproval = [bool]$Settings.activationRequiresApproval + EligibilityExpirationRequired = -not [string]::IsNullOrWhiteSpace($Settings.eligibilityMaxDuration) + ActiveAssignmentExpirationRequired = -not [string]::IsNullOrWhiteSpace($Settings.activeAssignmentMaxDuration) + BelowFloor = -not $Floor.Valid + FloorIssues = @($Floor.Errors) + } +} diff --git a/Modules/CIPPCore/Public/PIM/Get-CIPPPIMRoleAssignments.ps1 b/Modules/CIPPCore/Public/PIM/Get-CIPPPIMRoleAssignments.ps1 new file mode 100644 index 0000000000000..aa2c4de378ff1 --- /dev/null +++ b/Modules/CIPPCore/Public/PIM/Get-CIPPPIMRoleAssignments.ps1 @@ -0,0 +1,301 @@ +function Get-CIPPPIMRoleAssignments { + <# + .SYNOPSIS + Lists a tenant's directory role assignments with their PIM assignment type. + + .DESCRIPTION + One row per principal x role x scope x assignment kind, merged from: + - roleAssignmentScheduleInstances (v1.0, $expand=principal): every ACTIVE assignment, + including ones made outside PIM (those show as assignmentType 'Assigned', memberType + 'Direct', endDateTime null). 'Activated' = activated from an eligibility. + - roleEligibilitySchedules (v1.0, $expand=principal): ELIGIBLE assignments. + Both need -AsApp: RoleManagement.*.Directory is an application permission. + + Tenants without Entra ID P2 have no PIM API; there the unified roleManagement/directory/ + roleAssignments list is used and every row is Permanent/Direct (PIMCapable = $false). + + AssignmentType values: + Permanent active, no end date (what the PermanentActiveAdminAssigned alert watches) + Active active, time-bound (endDateTime set) + ActivatedFromEligible active because the principal activated an eligibility + Eligible eligible; EligibilityPermanent tells whether the eligibility itself expires + + MemberType 'Group' rows are inherited through a role-assignable group: the principal shown + is the member, and the assignment to act on belongs to the group. + + .PARAMETER PrincipalId + Restrict to one principal (pushed into the Graph filter - cheap for the user page). + + .PARAMETER RoleDefinitionId + Restrict to one role template id. + + .PARAMETER FromCache + Read the CIPPDB cache (RoleAssignmentScheduleInstances / RoleEligibilitySchedules, falling + back to the directoryRoles 'Roles' cache for tenants without PIM rows). Used for AllTenants. + + .PARAMETER IncludePolicy + Attach the role's PIM policy summary (PolicySummary, PolicyBelowFloor) to every row. + + .PARAMETER IncludeUnassignedRoles + Live reads only: also return one row per role definition that has no assignment at all + (AssignmentType 'Unassigned', no principal), so the result doubles as the role catalogue. + Ignored when -PrincipalId is given. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [string]$PrincipalId, + + [string]$RoleDefinitionId, + + [switch]$FromCache, + + [switch]$IncludePolicy, + + [switch]$IncludeUnassignedRoles + ) + + $PrivilegedCatalog = Get-CIPPPrivilegedRoleTemplateIds -WithNames + $PrivilegedIds = [System.Collections.Generic.HashSet[string]]::new([string[]]@($PrivilegedCatalog.Id), [System.StringComparer]::OrdinalIgnoreCase) + $RoleNames = @{} + # Description / built-in flag per role id, filled from the definitions (live) or the Roles cache. + $RoleInfo = @{} + foreach ($Entry in $PrivilegedCatalog) { $RoleNames[$Entry.Id] = $Entry.DisplayName } + + function ConvertTo-PrincipalType { + param([string]$ODataType) + switch -Wildcard ($ODataType) { + '*user' { 'User' } + '*group' { 'Group' } + '*servicePrincipal' { 'ServicePrincipal' } + default { 'Unknown' } + } + } + + function ConvertTo-DateTime { + param($Value) + if ($null -eq $Value -or "$Value" -eq '') { return $null } + if ($Value -is [datetime]) { return $Value.ToUniversalTime() } + try { return ([datetime]$Value).ToUniversalTime() } catch { return $null } + } + + $Rows = [System.Collections.Generic.List[object]]::new() + $ScopeIds = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + + function ConvertTo-Row { + param( + $Principal, [string]$PrincipalObjectId, [string]$RoleId, [string]$AssignmentType, [string]$MemberType, + [string]$ScopeId, $Start, $End, [string]$Source, [string]$ScheduleId, [string]$RoleAssignmentId, + [bool]$PIMCapable, [bool]$EligibilityPermanent = $false + ) + if ([string]::IsNullOrWhiteSpace($ScopeId)) { $ScopeId = '/' } + $null = $ScopeIds.Add($ScopeId) + $Type = ConvertTo-PrincipalType ($Principal.'@odata.type') + [PSCustomObject]@{ + Tenant = $TenantFilter + Id = "$PrincipalObjectId|$RoleId|$ScopeId|$AssignmentType" + PrincipalId = $PrincipalObjectId + PrincipalDisplayName = $Principal.displayName + PrincipalUserPrincipalName = $Principal.userPrincipalName + PrincipalType = $Type + PrincipalAppId = $Principal.appId + RoleDefinitionId = $RoleId + RoleDisplayName = $RoleNames[$RoleId] ?? $RoleId + RoleDescription = $null + RoleIsBuiltIn = $null + IsPrivilegedRole = $PrivilegedIds.Contains($RoleId) + AssignmentType = $AssignmentType + IsAssigned = ($AssignmentType -ne 'Unassigned') + IsPermanent = ($AssignmentType -eq 'Permanent') + EligibilityPermanent = $EligibilityPermanent + MemberType = $MemberType + DirectoryScopeId = $ScopeId + Scope = if ($ScopeId -eq '/') { 'Directory' } else { $ScopeId } + StartDateTime = ConvertTo-DateTime $Start + EndDateTime = ConvertTo-DateTime $End + Source = $Source + ScheduleId = $ScheduleId + RoleAssignmentId = $RoleAssignmentId + PIMCapable = $PIMCapable + PolicySummary = $null + PolicyBelowFloor = $null + } + } + + function Add-InstanceRows { + param($Instances, [bool]$PIMCapable = $true) + foreach ($Instance in @($Instances)) { + if (-not $Instance.principalId -or -not $Instance.roleDefinitionId) { continue } + $End = ConvertTo-DateTime $Instance.endDateTime + $Type = if ($Instance.assignmentType -eq 'Activated') { + 'ActivatedFromEligible' + } elseif ($null -eq $End) { + 'Permanent' + } else { + 'Active' + } + $Source = if ($Type -eq 'Permanent' -and $Instance.memberType -ne 'Group') { 'Direct' } else { 'PIM' } + $Principal = $Instance.principal ?? [PSCustomObject]@{ displayName = $null; userPrincipalName = $null; '@odata.type' = $null; appId = $null } + $Rows.Add((ConvertTo-Row -Principal $Principal -PrincipalObjectId $Instance.principalId -RoleId $Instance.roleDefinitionId -AssignmentType $Type -MemberType ($Instance.memberType ?? 'Direct') -ScopeId $Instance.directoryScopeId -Start $Instance.startDateTime -End $Instance.endDateTime -Source $Source -ScheduleId $Instance.roleAssignmentScheduleId -RoleAssignmentId $Instance.roleAssignmentOriginId -PIMCapable $PIMCapable)) + } + } + + function Add-EligibilityRows { + param($Schedules) + foreach ($Schedule in @($Schedules)) { + if (-not $Schedule.principalId -or -not $Schedule.roleDefinitionId) { continue } + if ($Schedule.status -and $Schedule.status -notin @('Provisioned', 'PendingProvisioning', 'ScheduleCreated')) { continue } + $Principal = $Schedule.principal ?? [PSCustomObject]@{ displayName = $null; userPrincipalName = $null; '@odata.type' = $null; appId = $null } + $Expiration = $Schedule.scheduleInfo.expiration + $EligibilityPermanent = ($null -eq $Expiration -or $Expiration.type -eq 'noExpiration') + $Rows.Add((ConvertTo-Row -Principal $Principal -PrincipalObjectId $Schedule.principalId -RoleId $Schedule.roleDefinitionId -AssignmentType 'Eligible' -MemberType ($Schedule.memberType ?? 'Direct') -ScopeId $Schedule.directoryScopeId -Start $Schedule.scheduleInfo.startDateTime -End $Expiration.endDateTime -Source 'PIM' -ScheduleId $Schedule.id -RoleAssignmentId $null -PIMCapable $true -EligibilityPermanent $EligibilityPermanent)) + } + } + + if ($FromCache.IsPresent) { + $Instances = @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'RoleAssignmentScheduleInstances') + $Eligibilities = @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'RoleEligibilitySchedules') + $CachedRoles = @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'Roles') + foreach ($Role in $CachedRoles) { + if ($Role.roleTemplateId -and $Role.displayName) { $RoleNames[$Role.roleTemplateId] = $Role.displayName } + if ($Role.roleTemplateId) { $RoleInfo[$Role.roleTemplateId] = @{ Description = $Role.description; IsBuiltIn = $null } } + } + + if ($Instances.Count -gt 0 -or $Eligibilities.Count -gt 0) { + Add-InstanceRows -Instances $Instances -PIMCapable $true + Add-EligibilityRows -Schedules $Eligibilities + } else { + # No PIM data cached (non-P2 tenant or PIM never onboarded): directoryRoles members are + # all permanent, direct assignments. + foreach ($Role in $CachedRoles) { + foreach ($Member in @($Role.members)) { + if (-not $Member.id) { continue } + $Rows.Add((ConvertTo-Row -Principal $Member -PrincipalObjectId $Member.id -RoleId ($Role.roleTemplateId ?? $Role.id) -AssignmentType 'Permanent' -MemberType 'Direct' -ScopeId '/' -Start $null -End $null -Source 'Direct' -ScheduleId $null -RoleAssignmentId $null -PIMCapable $false)) + } + } + } + } else { + $PIMCapable = [bool](Test-CIPPStandardLicense -StandardName 'PIMRoleAssignments' -TenantFilter $TenantFilter -Preset EntraP2 -SkipLog) + + # Role names come from the tenant's definitions (custom roles included); PIM's + # roleDefinitionId equals the template id for built-in roles and the definition id otherwise. + # beta: isPrivileged is not on the v1.0 unifiedRoleDefinition and a $select of it fails the + # whole request, which left every row showing the template GUID. + $Definitions = @() + try { + $Definitions = @(New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/roleManagement/directory/roleDefinitions?$select=id,templateId,displayName,description,isBuiltIn,isPrivileged' -tenantid $TenantFilter) + foreach ($Definition in @($Definitions)) { + $Info = @{ Description = $Definition.description; IsBuiltIn = [bool]$Definition.isBuiltIn } + if ($Definition.id) { $RoleNames[$Definition.id] = $Definition.displayName; $RoleInfo[$Definition.id] = $Info } + if ($Definition.templateId) { $RoleNames[$Definition.templateId] = $Definition.displayName; $RoleInfo[$Definition.templateId] = $Info } + if ($Definition.isPrivileged -eq $true) { + $null = $PrivilegedIds.Add($Definition.id) + if ($Definition.templateId) { $null = $PrivilegedIds.Add($Definition.templateId) } + } + } + } catch { + Write-Information "Could not list role definitions for $TenantFilter`: $($_.Exception.Message)" + } + + $Filters = [System.Collections.Generic.List[string]]::new() + if ($PrincipalId) { $Filters.Add("principalId eq '$PrincipalId'") } + if ($RoleDefinitionId) { $Filters.Add("roleDefinitionId eq '$RoleDefinitionId'") } + $FilterClause = if ($Filters.Count -gt 0) { "&`$filter=$($Filters -join ' and ')" } else { '' } + + if ($PIMCapable) { + $Instances = @(New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/roleManagement/directory/roleAssignmentScheduleInstances?`$expand=principal$FilterClause" -tenantid $TenantFilter -AsApp $true) + Add-InstanceRows -Instances $Instances -PIMCapable $true + $Eligibilities = @(New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/roleManagement/directory/roleEligibilitySchedules?`$expand=principal$FilterClause" -tenantid $TenantFilter -AsApp $true) + Add-EligibilityRows -Schedules $Eligibilities + } else { + $Assignments = @(New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/roleManagement/directory/roleAssignments?`$select=id,principalId,roleDefinitionId,directoryScopeId&`$top=999$FilterClause" -tenantid $TenantFilter) + # Resolve principals in bulk; getByIds returns in milliseconds where $expand costs seconds. + $Principals = @{} + $PrincipalIds = @($Assignments.principalId | Where-Object { $_ } | Sort-Object -Unique) + for ($i = 0; $i -lt $PrincipalIds.Count; $i += 1000) { + $Body = ConvertTo-Json -InputObject @{ ids = @($PrincipalIds[$i..([Math]::Min($i + 999, $PrincipalIds.Count - 1))]) } -Compress + $Resolved = New-GraphPOSTRequest -tenantid $TenantFilter -uri 'https://graph.microsoft.com/v1.0/directoryObjects/getByIds?$select=id,displayName,userPrincipalName,appId' -body $Body + foreach ($Principal in @($Resolved.value)) { $Principals[$Principal.id] = $Principal } + } + foreach ($Assignment in $Assignments) { + if (-not $Assignment.principalId) { continue } + $Principal = $Principals[$Assignment.principalId] ?? [PSCustomObject]@{ displayName = $null; userPrincipalName = $null; '@odata.type' = $null; appId = $null } + $Rows.Add((ConvertTo-Row -Principal $Principal -PrincipalObjectId $Assignment.principalId -RoleId $Assignment.roleDefinitionId -AssignmentType 'Permanent' -MemberType 'Direct' -ScopeId $Assignment.directoryScopeId -Start $null -End $null -Source 'Direct' -ScheduleId $null -RoleAssignmentId $Assignment.id -PIMCapable $false)) + } + } + + # The role catalogue: one row per definition nobody holds, so the PIM page can list every + # role the way the old Roles page did. Skipped for a single-principal read. + if ($IncludeUnassignedRoles.IsPresent -and -not $PrincipalId) { + $AssignedRoleIds = [System.Collections.Generic.HashSet[string]]::new([string[]]@($Rows.RoleDefinitionId | Where-Object { $_ }), [System.StringComparer]::OrdinalIgnoreCase) + foreach ($Definition in $Definitions) { + $RoleId = $Definition.templateId ?? $Definition.id + if (-not $RoleId) { continue } + if ($RoleDefinitionId -and $RoleId -ne $RoleDefinitionId -and $Definition.id -ne $RoleDefinitionId) { continue } + if ($AssignedRoleIds.Contains($RoleId) -or ($Definition.id -and $AssignedRoleIds.Contains($Definition.id))) { continue } + $NoPrincipal = [PSCustomObject]@{ displayName = $null; userPrincipalName = $null; '@odata.type' = $null; appId = $null } + $Row = ConvertTo-Row -Principal $NoPrincipal -PrincipalObjectId '' -RoleId $RoleId -AssignmentType 'Unassigned' -MemberType '' -ScopeId '/' -Start $null -End $null -Source '' -ScheduleId $null -RoleAssignmentId $null -PIMCapable $PIMCapable + $Row.PrincipalId = $null + $Row.PrincipalType = 'None' + $Rows.Add($Row) + } + } + + # Administrative-unit scopes: show the unit's name instead of its id. + $UnitIds = @($ScopeIds | Where-Object { $_ -match '^/administrativeUnits/' } | ForEach-Object { $_ -replace '^/administrativeUnits/', '' }) + if ($UnitIds.Count -gt 0) { + try { + $UnitRequests = @(foreach ($UnitId in $UnitIds) { + @{ id = $UnitId; method = 'GET'; url = "/directory/administrativeUnits/$UnitId`?`$select=id,displayName" } + }) + $UnitResults = New-GraphBulkRequest -tenantid $TenantFilter -Requests $UnitRequests -Version 'v1.0' + $UnitNames = @{} + foreach ($Result in @($UnitResults)) { + if ($Result.body.displayName) { $UnitNames["/administrativeUnits/$($Result.id)"] = "AU: $($Result.body.displayName)" } + } + foreach ($Row in $Rows) { + if ($UnitNames.ContainsKey($Row.DirectoryScopeId)) { $Row.Scope = $UnitNames[$Row.DirectoryScopeId] } + } + } catch { + Write-Information "Could not resolve administrative unit names for $TenantFilter`: $($_.Exception.Message)" + } + } + } + + # Names for rows whose role was not resolvable earlier (cache path, roles never activated). + foreach ($Row in $Rows) { + if ($Row.RoleDisplayName -eq $Row.RoleDefinitionId -and $RoleNames.ContainsKey($Row.RoleDefinitionId)) { + $Row.RoleDisplayName = $RoleNames[$Row.RoleDefinitionId] + } + if (-not $Row.IsPrivilegedRole -and $PrivilegedIds.Contains($Row.RoleDefinitionId)) { $Row.IsPrivilegedRole = $true } + $Info = $RoleInfo[$Row.RoleDefinitionId] + if ($Info) { + $Row.RoleDescription = $Info.Description + $Row.RoleIsBuiltIn = $Info.IsBuiltIn + } + } + + if ($IncludePolicy.IsPresent -and $Rows.Count -gt 0) { + try { + $Policies = @(Get-CIPPPIMRolePolicies -TenantFilter $TenantFilter -FromCache:$FromCache) + $PolicyByRole = @{} + foreach ($Policy in $Policies) { $PolicyByRole[$Policy.RoleDefinitionId] = $Policy } + foreach ($Row in $Rows) { + $Policy = $PolicyByRole[$Row.RoleDefinitionId] + if ($Policy) { + $Row.PolicySummary = $Policy.Summary.SummaryText + $Row.PolicyBelowFloor = $Policy.Summary.BelowFloor + } + } + } catch { + Write-Information "Could not load PIM policies for $TenantFilter`: $($_.Exception.Message)" + } + } + + return @($Rows) +} diff --git a/Modules/CIPPCore/Public/PIM/Get-CIPPPIMRolePolicies.ps1 b/Modules/CIPPCore/Public/PIM/Get-CIPPPIMRolePolicies.ps1 new file mode 100644 index 0000000000000..59377c7f476c1 --- /dev/null +++ b/Modules/CIPPCore/Public/PIM/Get-CIPPPIMRolePolicies.ps1 @@ -0,0 +1,82 @@ +function Get-CIPPPIMRolePolicies { + <# + .SYNOPSIS + Returns the PIM role management policy for each directory role, with canonical settings + and a display summary. + + .DESCRIPTION + Reads policies/roleManagementPolicyAssignments (the assignment is the only record that + carries roleDefinitionId - see Set-CIPPDBCacheRoleManagementPolicies) with the policy and + its rules expanded. -AsApp is required: RoleManagement.*.Directory is an application + permission. A tenant that has never onboarded PIM answers "MissingProvider"; that is tenant + state and yields an empty result rather than an error. + + .PARAMETER RoleDefinitionId + Optional role template ids to restrict the query to (pushed into the Graph filter). + + .PARAMETER FromCache + Read the RoleManagementPolicies cache instead of Graph. + + .OUTPUTS + PSCustomObject per role: RoleDefinitionId, PolicyId, Rules, Settings, Summary. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [string[]]$RoleDefinitionId, + + [switch]$FromCache + ) + + $Records = @() + if ($FromCache.IsPresent) { + $Records = @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'RoleManagementPolicies' | ForEach-Object { + [PSCustomObject]@{ + roleDefinitionId = $_.roleDefinitionId + policyId = $_.policyId + rules = @($_.rules) + } + }) + } else { + $Filter = "scopeId eq '/' and scopeType eq 'DirectoryRole'" + if ($RoleDefinitionId -and $RoleDefinitionId.Count -eq 1) { + $Filter = "$Filter and roleDefinitionId eq '$($RoleDefinitionId[0])'" + } + $Uri = "https://graph.microsoft.com/beta/policies/roleManagementPolicyAssignments?`$filter=$Filter&`$expand=policy(`$expand=rules)" + try { + $Records = @(New-GraphGetRequest -uri $Uri -tenantid $TenantFilter -AsApp $true | ForEach-Object { + [PSCustomObject]@{ + roleDefinitionId = $_.roleDefinitionId + policyId = $_.policyId + rules = @($_.policy.rules) + } + }) + } catch { + if ($_.Exception.Message -match 'MissingProvider|provider is missing') { + Write-Information "PIM is not onboarded in $TenantFilter (MissingProvider); no role management policies." + return @() + } + throw + } + } + + if ($RoleDefinitionId) { + $Records = @($Records | Where-Object { $RoleDefinitionId -contains $_.roleDefinitionId }) + } + + foreach ($Record in $Records) { + $Settings = ConvertFrom-CIPPPIMPolicyRules -Rules $Record.rules + [PSCustomObject]@{ + RoleDefinitionId = $Record.roleDefinitionId + PolicyId = $Record.policyId + Rules = @($Record.rules) + Settings = $Settings + Summary = Get-CIPPPIMPolicySummary -Settings $Settings + } + } +} diff --git a/Modules/CIPPCore/Public/PIM/Get-CIPPPrivilegedRoleTemplateIds.ps1 b/Modules/CIPPCore/Public/PIM/Get-CIPPPrivilegedRoleTemplateIds.ps1 new file mode 100644 index 0000000000000..cd745f8540df5 --- /dev/null +++ b/Modules/CIPPCore/Public/PIM/Get-CIPPPrivilegedRoleTemplateIds.ps1 @@ -0,0 +1,77 @@ +function Get-CIPPPrivilegedRoleTemplateIds { + <# + .SYNOPSIS + Returns the Entra role TEMPLATE ids that CIPP treats as privileged. + + .DESCRIPTION + Single source for every "privileged roles" scope in CIPP: Get-CippDbRole, the PIM role + assignment surfaces, the PIM role settings templates and the PermanentActiveAdminAssigned + alert all use this list so that the phrase means the same roles everywhere. + + Template ids are what PIM's roleDefinitionId carries for built-in roles, so these compare + directly against roleAssignmentScheduleInstances / roleEligibilitySchedules records. + + .PARAMETER Set + Privileged - CIPP's privileged set (18 roles). Default. + CisaHighlyPrivileged - the six roles CISA SCuBA calls highly privileged. + GlobalAdministrator - only Global Administrator. + + .PARAMETER WithNames + Return objects with Id and DisplayName instead of bare ids, for callers that need a + name fallback when the tenant's role definitions are not at hand (cached AllTenants views). + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [ValidateSet('Privileged', 'CisaHighlyPrivileged', 'GlobalAdministrator')] + [string]$Set = 'Privileged', + + [switch]$WithNames + ) + + $Catalog = [ordered]@{ + '62e90394-69f5-4237-9190-012177145e10' = 'Global Administrator' + '194ae4cb-b126-40b2-bd5b-6091b380977d' = 'Security Administrator' + '9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3' = 'Application Administrator' + 'e8611ab8-c189-46e8-94e1-60213ab1f814' = 'Privileged Role Administrator' + '29232cdf-9323-42fd-ade2-1d097af3e4de' = 'Exchange Administrator' + 'b1be1c3e-b65d-4f19-8427-f6fa0d97feb9' = 'Conditional Access Administrator' + 'f28a1f50-f6e7-4571-818b-6a12f2af6b6c' = 'SharePoint Administrator' + 'fe930be7-5e62-47db-91af-98c3a49a38b1' = 'User Administrator' + '729827e3-9c14-49f7-bb1b-9608f156bbb8' = 'Helpdesk Administrator' + '966707d0-3269-4727-9be2-8c3a10f19b9d' = 'Password Administrator' + 'b0f54661-2d74-4c50-afa3-1ec803f12efe' = 'Billing Administrator' + '7be44c8a-adaf-4e2a-84d6-ab2649e08a13' = 'Privileged Authentication Administrator' + '158c047a-c907-4556-b7ef-446551a6b5f7' = 'Cloud Application Administrator' + 'c4e39bd9-1100-46d3-8c65-fb160da0071f' = 'Authentication Administrator' + '9f06204d-73c1-4d4c-880a-6edb90606fd8' = 'Azure AD Joined Device Local Administrator' + '17315797-102d-40b4-93e0-432062caca18' = 'Compliance Administrator' + '4a5d8f65-41da-4de4-8968-e035b65339cf' = 'Reports Reader' + '75941009-915a-4869-abe7-691bff18279e' = 'Skype for Business Administrator' + } + + $Ids = switch ($Set) { + 'GlobalAdministrator' { @('62e90394-69f5-4237-9190-012177145e10') } + 'CisaHighlyPrivileged' { + @( + '62e90394-69f5-4237-9190-012177145e10', + '9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3', + '29232cdf-9323-42fd-ade2-1d097af3e4de', + '729827e3-9c14-49f7-bb1b-9608f156bbb8', + '966707d0-3269-4727-9be2-8c3a10f19b9d', + 'b0f54661-2d74-4c50-afa3-1ec803f12efe' + ) + } + default { @($Catalog.Keys) } + } + + if ($WithNames.IsPresent) { + return @(foreach ($Id in $Ids) { + [PSCustomObject]@{ Id = $Id; DisplayName = $Catalog[$Id] } + }) + } + + return @($Ids) +} diff --git a/Modules/CIPPCore/Public/PIM/Invoke-CIPPPIMAssignmentAction.ps1 b/Modules/CIPPCore/Public/PIM/Invoke-CIPPPIMAssignmentAction.ps1 new file mode 100644 index 0000000000000..5d2e66cdc4c91 --- /dev/null +++ b/Modules/CIPPCore/Public/PIM/Invoke-CIPPPIMAssignmentAction.ps1 @@ -0,0 +1,306 @@ +function Invoke-CIPPPIMAssignmentAction { + <# + .SYNOPSIS + Performs a secure-direction change to a directory role assignment through PIM. + + .DESCRIPTION + The single write path for role assignments in CIPP's PIM surfaces, used by the + ExecPIMRoleAssignment endpoint (and any future standard or automation that changes assignments). + + Actions: + ConvertToEligible permanent/time-bound active -> eligible. Creates the eligibility, READS + IT BACK to confirm it exists, and only then removes the active + assignment. A principal never loses access without gaining eligibility. + GrantActive eligible (or nothing) -> time-bound active assignment (the JIT equivalent; + Entra removes it at the end date). + Extend / Renew push out the end of a time-bound active assignment or an eligibility. + Remove remove an eligibility or an active assignment. + + What it refuses, regardless of caller: + - anything without an expiration (New-CIPPPIMScheduleRequest throws); + - a lifetime above the tightest cap: the role's PIM policy maximum, the JIT admin + MaxDuration setting (GrantActive/Extend/Renew of actives) and CIPP's P365D ceiling; + - rows inherited through a group (MemberType 'Group') - the group's assignment is the + real one; + - the CIPP-SAM service principal's own assignments; + - removing or converting the LAST active Global Administrator; + - converting a service principal (PIM eligibility is users and groups only). + + Every change is logged with the assignment type before and after. + + .PARAMETER AssignmentType + The row's current type (Permanent | Active | ActivatedFromEligible | Eligible). Decides + whether Extend/Renew/Remove target the eligibility or the assignment schedule. + + .PARAMETER Duration + ISO 8601 lifetime for the new/extended schedule. Mutually exclusive with -EndDateTime. + + .OUTPUTS + PSCustomObject: resultText, state, Before, After, EndDateTime. + + .FUNCTIONALITY + Internal + #> + [CmdletBinding(SupportsShouldProcess = $true)] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [Parameter(Mandatory = $true)] + [ValidateSet('ConvertToEligible', 'GrantActive', 'Extend', 'Renew', 'Remove')] + [string]$Action, + + [Parameter(Mandatory = $true)] + [string]$PrincipalId, + + [Parameter(Mandatory = $true)] + [string]$RoleDefinitionId, + + [string]$DirectoryScopeId = '/', + + [ValidateSet('', 'Permanent', 'Active', 'ActivatedFromEligible', 'Eligible')] + [string]$AssignmentType = '', + + [string]$Duration, + + [datetime]$EndDateTime, + + [string]$Justification, + + # IANA time zone of the caller (the browser sends it) used only to word end times in the + # result text; UTC when absent or unknown. Never changes what is written to Graph. + [string]$TimeZone, + + $Headers, + + [string]$APIName = 'PIMRoleAssignment' + ) + + $GlobalAdminTemplateId = '62e90394-69f5-4237-9190-012177145e10' + # End times are stored in UTC; word them in the caller's zone so "until 08:06" reads as the + # time the operator will see on their clock. Falls back to UTC (labelled) for an unknown zone. + $Zone = $null + if (-not [string]::IsNullOrWhiteSpace($TimeZone)) { + try { $Zone = [System.TimeZoneInfo]::FindSystemTimeZoneById($TimeZone) } catch { $Zone = $null } + } + $FormatEnd = { + param($Value) + if ($null -eq $Value -or "$Value" -eq '') { return '' } + $Utc = if ($Value -is [datetime]) { + if ($Value.Kind -eq 'Local') { $Value.ToUniversalTime() } else { [datetime]::SpecifyKind($Value, 'Utc') } + } else { ([datetime]$Value).ToUniversalTime() } + if ($Zone) { "$([System.TimeZoneInfo]::ConvertTimeFromUtc($Utc, $Zone).ToString('yyyy-MM-dd HH:mm')) ($TimeZone)" } else { "$($Utc.ToString('yyyy-MM-dd HH:mm')) UTC" } + } + if ([string]::IsNullOrWhiteSpace($DirectoryScopeId)) { $DirectoryScopeId = '/' } + if ([string]::IsNullOrWhiteSpace($Justification)) { $Justification = 'Changed via CIPP' } + + $PIMCapable = [bool](Test-CIPPStandardLicense -StandardName 'PIMRoleAssignment' -TenantFilter $TenantFilter -Preset EntraP2 -SkipLog) + if (-not $PIMCapable) { + throw "Tenant $TenantFilter is not licensed for Entra ID P2 / Privileged Identity Management, so PIM assignment changes are not available. Assignments can still be removed from the PIM page." + } + + # Current state for this principal (cheap: filtered at Graph) and the role's policy caps. + $PrincipalRows = @(Get-CIPPPIMRoleAssignments -TenantFilter $TenantFilter -PrincipalId $PrincipalId) + $RoleRows = @($PrincipalRows | Where-Object { $_.RoleDefinitionId -eq $RoleDefinitionId -and $_.DirectoryScopeId -eq $DirectoryScopeId }) + $RoleName = ($RoleRows | Select-Object -First 1).RoleDisplayName ?? $RoleDefinitionId + $PrincipalName = ($PrincipalRows | Where-Object { $_.PrincipalUserPrincipalName -or $_.PrincipalDisplayName } | Select-Object -First 1) + # Groups and service principals have no UPN (and the value may be '' rather than $null). + $PrincipalLabel = @($PrincipalName.PrincipalUserPrincipalName, $PrincipalName.PrincipalDisplayName, $PrincipalId) | Where-Object { -not [string]::IsNullOrWhiteSpace($_) } | Select-Object -First 1 + $PrincipalType = ($PrincipalRows | Select-Object -First 1).PrincipalType + $PrincipalAppId = ($PrincipalRows | Select-Object -First 1).PrincipalAppId + + $ActiveRow = $RoleRows | Where-Object { $_.AssignmentType -in @('Permanent', 'Active', 'ActivatedFromEligible') } | Select-Object -First 1 + $EligibleRow = $RoleRows | Where-Object { $_.AssignmentType -eq 'Eligible' } | Select-Object -First 1 + $TargetRow = switch ($AssignmentType) { + 'Eligible' { $EligibleRow } + '' { $ActiveRow ?? $EligibleRow } + default { $ActiveRow } + } + + if ($TargetRow -and $TargetRow.MemberType -eq 'Group') { + throw "$PrincipalLabel holds $RoleName through a role-assignable group. Change the group's assignment instead of the member's." + } + if ($PrincipalAppId -and $env:ApplicationID -and $PrincipalAppId -eq $env:ApplicationID) { + throw "Refusing to change the CIPP-SAM application's own role assignment for $RoleName." + } + + $Before = if ($TargetRow) { + "$($TargetRow.AssignmentType)$(if ($TargetRow.EndDateTime) { " until $(& $FormatEnd $TargetRow.EndDateTime)" })" + } else { + 'None' + } + + function Get-MinimumDuration { + param([string[]]$Candidates) + $Best = $null + $BestSpan = $null + foreach ($Candidate in @($Candidates | Where-Object { -not [string]::IsNullOrWhiteSpace($_) })) { + try { $Span = [System.Xml.XmlConvert]::ToTimeSpan($Candidate) } catch { continue } + if ($null -eq $BestSpan -or $Span -lt $BestSpan) { $Best = $Candidate; $BestSpan = $Span } + } + return $Best + } + + $Policy = $null + try { + $Policy = Get-CIPPPIMRolePolicies -TenantFilter $TenantFilter -RoleDefinitionId $RoleDefinitionId | Select-Object -First 1 + } catch { + Write-Information "Could not read the PIM policy for $RoleName in $TenantFilter`: $($_.Exception.Message)" + } + + $JitMaxDuration = $null + try { + $ConfigTable = Get-CIPPTable -TableName Config + $JITAdminConfig = Get-CIPPAzDataTableEntity @ConfigTable -Filter "PartitionKey eq 'JITAdminSettings' and RowKey eq 'JITAdminSettings'" + if ($JITAdminConfig -and -not [string]::IsNullOrWhiteSpace($JITAdminConfig.MaxDuration)) { $JitMaxDuration = $JITAdminConfig.MaxDuration } + } catch { + Write-Information "Could not read the JIT admin maximum duration: $($_.Exception.Message)" + } + + $EligibilityCap = Get-MinimumDuration @('P365D', $Policy.Settings.eligibilityMaxDuration) + $AssignmentCap = Get-MinimumDuration @('P365D', $Policy.Settings.activeAssignmentMaxDuration, $JitMaxDuration) + + function Test-LastGlobalAdmin { + if ($RoleDefinitionId -ne $GlobalAdminTemplateId) { return } + $OtherActive = @(Get-CIPPPIMRoleAssignments -TenantFilter $TenantFilter -RoleDefinitionId $GlobalAdminTemplateId | Where-Object { + $_.AssignmentType -in @('Permanent', 'Active', 'ActivatedFromEligible') -and $_.PrincipalId -ne $PrincipalId + }) + if ($OtherActive.Count -eq 0) { + throw "Refusing: $PrincipalLabel is the last active Global Administrator in $TenantFilter. Assign another active Global Administrator first." + } + } + + function Send-ScheduleRequest { + param($Request) + $Json = ConvertTo-Json -InputObject $Request.Body -Depth 10 -Compress + return New-GraphPOSTRequest -uri $Request.Uri -body $Json -tenantid $TenantFilter -AsApp $true + } + + function Invoke-ActiveAssignmentRemoval { + # adminRemove covers PIM-created and legacy direct assignments alike; the unified RBAC + # delete is only a fallback for the rare record PIM does not recognise. + $Request = New-CIPPPIMScheduleRequest -Kind Assignment -Action adminRemove -PrincipalId $PrincipalId -RoleDefinitionId $RoleDefinitionId -DirectoryScopeId $DirectoryScopeId -Justification $Justification + try { + $null = Send-ScheduleRequest -Request $Request + } catch { + # Entra refuses to retire an active assignment younger than five minutes + # ("The Active duration is too short. Minimum Required is 5 minutes"). + if ($_.Exception.Message -match 'duration is too short') { + throw "Entra requires an active assignment to exist for at least 5 minutes before it can be removed; $PrincipalLabel's $RoleName assignment was created too recently. Try again in a few minutes." + } + if ($_.Exception.Message -notmatch 'RoleAssignmentDoesNotExist|does not exist|NotFound|not found') { throw } + $Existing = @(New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/roleManagement/directory/roleAssignments?`$filter=principalId eq '$PrincipalId' and roleDefinitionId eq '$RoleDefinitionId'" -tenantid $TenantFilter | Where-Object { ($_.directoryScopeId ?? '/') -eq $DirectoryScopeId }) + if ($Existing.Count -eq 0) { throw } + foreach ($Assignment in $Existing) { + $null = New-GraphPOSTRequest -type DELETE -uri "https://graph.microsoft.com/v1.0/roleManagement/directory/roleAssignments/$($Assignment.id)" -tenantid $TenantFilter + } + } + # Graph accepts the removal (status Revoked) and retires the instance a few seconds later; + # wait for that so the reported state - and the table refresh behind it - is the real one. + for ($Attempt = 0; $Attempt -lt 8; $Attempt++) { + $Remaining = @(New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/roleManagement/directory/roleAssignmentScheduleInstances?`$filter=principalId eq '$PrincipalId' and roleDefinitionId eq '$RoleDefinitionId'" -tenantid $TenantFilter -AsApp $true | Where-Object { ($_.directoryScopeId ?? '/') -eq $DirectoryScopeId }) + if ($Remaining.Count -eq 0) { return $true } + Start-Sleep -Seconds 3 + } + return $false + } + + $DurationParams = @{} + if (-not [string]::IsNullOrWhiteSpace($Duration)) { $DurationParams.Duration = $Duration } + if ($PSBoundParameters.ContainsKey('EndDateTime') -and $null -ne $EndDateTime) { $DurationParams.EndDateTime = $EndDateTime } + + if (-not $PSCmdlet.ShouldProcess("$PrincipalLabel / $RoleName in $TenantFilter", $Action)) { return } + + $After = $Before + $ResultEnd = $null + switch ($Action) { + 'ConvertToEligible' { + if (-not $ActiveRow) { throw "$PrincipalLabel has no active $RoleName assignment to convert." } + if ($PrincipalType -eq 'ServicePrincipal') { throw "$PrincipalLabel is a service principal; PIM eligibility is only supported for users and groups. Remove the assignment instead if it is not needed." } + Test-LastGlobalAdmin + + if ($DurationParams.Count -eq 0) { $DurationParams.Duration = $EligibilityCap } + if (-not $EligibleRow) { + $Request = New-CIPPPIMScheduleRequest -Kind Eligibility -Action adminAssign -PrincipalId $PrincipalId -RoleDefinitionId $RoleDefinitionId -DirectoryScopeId $DirectoryScopeId -Justification $Justification -MaxDuration $EligibilityCap @DurationParams + try { + $null = Send-ScheduleRequest -Request $Request + } catch { + if ($_.Exception.Message -notmatch 'RoleAssignmentExists|already exists') { throw } + } + $ResultEnd = $Request.EndDateTime + } else { + $ResultEnd = $EligibleRow.EndDateTime + } + + # Verify the eligibility is really there before taking the active assignment away. + $Confirmed = $null + for ($Attempt = 0; $Attempt -lt 6 -and -not $Confirmed; $Attempt++) { + if ($Attempt -gt 0) { Start-Sleep -Seconds 2 } + $Confirmed = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/roleManagement/directory/roleEligibilitySchedules?`$filter=principalId eq '$PrincipalId' and roleDefinitionId eq '$RoleDefinitionId'" -tenantid $TenantFilter -AsApp $true | Where-Object { ($_.directoryScopeId ?? '/') -eq $DirectoryScopeId } | Select-Object -First 1 + } + if (-not $Confirmed) { + throw "The eligibility for $PrincipalLabel on $RoleName could not be confirmed; the active assignment was left in place." + } + + $RemovalSeen = Invoke-ActiveAssignmentRemoval + $After = "Eligible$(if ($ResultEnd) { " until $(& $FormatEnd $ResultEnd)" })" + $ResultText = "Converted $PrincipalLabel on $RoleName from $Before to $After.$(if (-not $RemovalSeen) { ' The removal of the active assignment was accepted by Entra and is still propagating; refresh in a minute.' })" + } + 'GrantActive' { + if ($DurationParams.Count -eq 0) { throw 'GrantActive needs a Duration or EndDateTime.' } + if ($ActiveRow -and $ActiveRow.AssignmentType -eq 'Permanent') { throw "$PrincipalLabel already holds $RoleName permanently; convert it to eligible instead." } + $Request = New-CIPPPIMScheduleRequest -Kind Assignment -Action adminAssign -PrincipalId $PrincipalId -RoleDefinitionId $RoleDefinitionId -DirectoryScopeId $DirectoryScopeId -Justification $Justification -MaxDuration $AssignmentCap @DurationParams + $null = Send-ScheduleRequest -Request $Request + $ResultEnd = $Request.EndDateTime + $After = "Active until $(& $FormatEnd $ResultEnd)" + $ResultText = "Granted $PrincipalLabel a time-bound active $RoleName assignment until $(& $FormatEnd $ResultEnd)." + } + { $_ -in @('Extend', 'Renew') } { + if (-not $TargetRow) { throw "$PrincipalLabel has no $RoleName assignment to $($Action.ToLower())." } + if ($TargetRow.AssignmentType -eq 'Permanent') { throw "A permanent assignment cannot be extended; convert it to eligible instead." } + if ($DurationParams.Count -eq 0) { throw "$Action needs a Duration or EndDateTime." } + $Kind = if ($TargetRow.AssignmentType -eq 'Eligible') { 'Eligibility' } else { 'Assignment' } + $Cap = if ($Kind -eq 'Eligibility') { $EligibilityCap } else { $AssignmentCap } + $GraphAction = if ($Action -eq 'Extend') { 'adminExtend' } else { 'adminRenew' } + $Request = New-CIPPPIMScheduleRequest -Kind $Kind -Action $GraphAction -PrincipalId $PrincipalId -RoleDefinitionId $RoleDefinitionId -DirectoryScopeId $DirectoryScopeId -Justification $Justification -MaxDuration $Cap @DurationParams + $null = Send-ScheduleRequest -Request $Request + $ResultEnd = $Request.EndDateTime + $After = "$($TargetRow.AssignmentType) until $(& $FormatEnd $ResultEnd)" + $ResultText = "$($Action)ed $PrincipalLabel's $($TargetRow.AssignmentType.ToLower()) $RoleName assignment until $(& $FormatEnd $ResultEnd)." + } + 'Remove' { + if (-not $TargetRow) { throw "$PrincipalLabel has no $RoleName assignment to remove." } + $RemovalSeen = $true + if ($TargetRow.AssignmentType -eq 'Eligible') { + $Request = New-CIPPPIMScheduleRequest -Kind Eligibility -Action adminRemove -PrincipalId $PrincipalId -RoleDefinitionId $RoleDefinitionId -DirectoryScopeId $DirectoryScopeId -Justification $Justification + $null = Send-ScheduleRequest -Request $Request + } else { + Test-LastGlobalAdmin + $RemovalSeen = Invoke-ActiveAssignmentRemoval + } + $After = 'None' + $ResultText = "Removed $PrincipalLabel's $($TargetRow.AssignmentType.ToLower()) $RoleName assignment.$(if (-not $RemovalSeen) { ' Entra accepted the removal and is still propagating it; refresh in a minute.' })" + } + } + + $LogData = @{ + Action = $Action + PrincipalId = $PrincipalId + Principal = $PrincipalLabel + RoleDefinitionId = $RoleDefinitionId + Role = $RoleName + DirectoryScopeId = $DirectoryScopeId + Before = $Before + After = $After + Justification = $Justification + } + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "$ResultText (before: $Before, after: $After)" -Sev 'Info' -LogData $LogData + + return [PSCustomObject]@{ + resultText = $ResultText + state = 'success' + Before = $Before + After = $After + EndDateTime = $ResultEnd + } +} diff --git a/Modules/CIPPCore/Public/PIM/New-CIPPPIMScheduleRequest.ps1 b/Modules/CIPPCore/Public/PIM/New-CIPPPIMScheduleRequest.ps1 new file mode 100644 index 0000000000000..97d507b38fc55 --- /dev/null +++ b/Modules/CIPPCore/Public/PIM/New-CIPPPIMScheduleRequest.ps1 @@ -0,0 +1,204 @@ +function New-CIPPPIMScheduleRequest { + <# + .SYNOPSIS + Builds the body for a PIM role eligibility / role assignment schedule request. + + .DESCRIPTION + The ONLY place in CIPP that constructs roleEligibilityScheduleRequests and + roleAssignmentScheduleRequests bodies. It exists so that the security rule "CIPP can never + create a permanent (no-expiration) assignment or eligibility" is enforced in one function + that every caller - endpoints, standards, scheduled tasks - has to go through. + + Every request that creates, updates, extends or renews a schedule MUST carry an expiration, + expressed either as an ISO 8601 duration (-Duration) or an absolute end (-EndDateTime). + There is deliberately no parameter that produces scheduleInfo.expiration.type + 'noExpiration'; asking for it by any spelling throws. adminRemove is the one action that + needs no schedule. + + -MaxDuration caps the effective lifetime. Callers pass the tightest applicable limit + (role policy maximum, JIT maximum duration setting, the PIM ceiling) and the builder refuses + anything longer rather than clamping it, so the user sees why a request was rejected. + + .PARAMETER Kind + Eligibility -> roleEligibilityScheduleRequests; Assignment -> roleAssignmentScheduleRequests. + + .PARAMETER Action + adminAssign | adminUpdate | adminExtend | adminRenew | adminRemove. Self-service actions + (selfActivate, selfDeactivate, ...) are not offered: they can only be performed by the + principal, so CIPP uses time-bound active assignments instead. + + .PARAMETER Duration + ISO 8601 duration, e.g. PT8H, P1D, P6M, P1Y. Mutually exclusive with -EndDateTime. + + .PARAMETER EndDateTime + Absolute end. Must be in the future. Mutually exclusive with -Duration. + + .PARAMETER StartDateTime + Optional start; defaults to now (UTC). + + .PARAMETER MaxDuration + ISO 8601 duration cap. The effective lifetime (Duration, or EndDateTime - start) may not + exceed it. + + .OUTPUTS + PSCustomObject: Uri (v1.0 Graph endpoint), Body (ordered hashtable ready for ConvertTo-Json), + Kind, Action, ExpirationType, StartDateTime, EndDateTime (UTC, $null for adminRemove). + + .EXAMPLE + $Req = New-CIPPPIMScheduleRequest -Kind Assignment -Action adminAssign -PrincipalId $Id -RoleDefinitionId $Role -Duration 'PT4H' -Justification 'Ticket 1234' -MaxDuration 'PT8H' + New-GraphPOSTRequest -uri $Req.Uri -body ($Req.Body | ConvertTo-Json -Depth 10) -tenantid $Tenant -AsApp $true + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [ValidateSet('Eligibility', 'Assignment')] + [string]$Kind, + + [Parameter(Mandatory = $true)] + [ValidateSet('adminAssign', 'adminUpdate', 'adminExtend', 'adminRenew', 'adminRemove')] + [string]$Action, + + [Parameter(Mandatory = $true)] + [ValidateNotNullOrEmpty()] + [string]$PrincipalId, + + [Parameter(Mandatory = $true)] + [ValidateNotNullOrEmpty()] + [string]$RoleDefinitionId, + + [string]$DirectoryScopeId = '/', + + [string]$Justification, + + [string]$Duration, + + [datetime]$EndDateTime, + + [datetime]$StartDateTime, + + [string]$MaxDuration, + + [string]$TicketNumber, + + [string]$TicketSystem + ) + + $Uri = if ($Kind -eq 'Eligibility') { + 'https://graph.microsoft.com/v1.0/roleManagement/directory/roleEligibilityScheduleRequests' + } else { + 'https://graph.microsoft.com/v1.0/roleManagement/directory/roleAssignmentScheduleRequests' + } + + if ([string]::IsNullOrWhiteSpace($DirectoryScopeId)) { $DirectoryScopeId = '/' } + + $Body = [ordered]@{ + action = $Action + principalId = $PrincipalId + roleDefinitionId = $RoleDefinitionId + directoryScopeId = $DirectoryScopeId + } + if (-not [string]::IsNullOrWhiteSpace($Justification)) { + $Body.justification = $Justification + } + if (-not [string]::IsNullOrWhiteSpace($TicketNumber)) { + $Body.ticketInfo = @{ ticketNumber = $TicketNumber; ticketSystem = $TicketSystem } + } + + if ($Action -eq 'adminRemove') { + return [PSCustomObject]@{ + Uri = $Uri + Body = $Body + Kind = $Kind + Action = $Action + ExpirationType = $null + StartDateTime = $null + EndDateTime = $null + } + } + + # Everything below creates or changes a schedule, so it has to end. + $PermanentPattern = '^\s*(noExpiration|permanent|never|none|unlimited)\s*$' + if ($Duration -match $PermanentPattern) { + throw "Refusing to build a $Kind $Action request: '$Duration' asks for a permanent (no-expiration) schedule, which CIPP never creates. Supply an ISO 8601 duration such as PT8H or P1Y." + } + + $HasDuration = -not [string]::IsNullOrWhiteSpace($Duration) + $HasEnd = $PSBoundParameters.ContainsKey('EndDateTime') -and $null -ne $EndDateTime + if (-not $HasDuration -and -not $HasEnd) { + throw "Refusing to build a $Kind $Action request without an expiration: CIPP never creates permanent (no-expiration) role schedules. Supply -Duration (ISO 8601) or -EndDateTime." + } + if ($HasDuration -and $HasEnd) { + throw 'Specify either -Duration or -EndDateTime, not both.' + } + + $NowUtc = [datetime]::UtcNow + $Start = if ($PSBoundParameters.ContainsKey('StartDateTime') -and $null -ne $StartDateTime) { + $StartDateTime.ToUniversalTime() + } else { + $NowUtc + } + + if ($HasDuration) { + try { + $DurationSpan = [System.Xml.XmlConvert]::ToTimeSpan($Duration) + } catch { + throw "'$Duration' is not a valid ISO 8601 duration (expected a value such as PT8H, P1D, P6M or P1Y)." + } + if ($DurationSpan -le [timespan]::Zero) { + throw "Duration '$Duration' must be greater than zero." + } + $EffectiveSpan = $DurationSpan + $ComputedEnd = $Start.Add($DurationSpan) + $Expiration = [ordered]@{ + type = 'afterDuration' + duration = $Duration + } + $ExpirationType = 'afterDuration' + } else { + $EndUtc = $EndDateTime.ToUniversalTime() + if ($EndUtc -le $NowUtc) { + throw "EndDateTime $($EndUtc.ToString('o')) is not in the future." + } + if ($EndUtc -le $Start) { + throw "EndDateTime $($EndUtc.ToString('o')) is not after the start $($Start.ToString('o'))." + } + $EffectiveSpan = $EndUtc - $Start + $ComputedEnd = $EndUtc + $Expiration = [ordered]@{ + type = 'afterDateTime' + endDateTime = $EndUtc.ToString('yyyy-MM-ddTHH:mm:ssZ') + } + $ExpirationType = 'afterDateTime' + } + + if (-not [string]::IsNullOrWhiteSpace($MaxDuration)) { + try { + $MaxSpan = [System.Xml.XmlConvert]::ToTimeSpan($MaxDuration) + } catch { + throw "MaxDuration '$MaxDuration' is not a valid ISO 8601 duration." + } + if ($EffectiveSpan -gt $MaxSpan) { + $Requested = [math]::Round($EffectiveSpan.TotalHours, 2) + $Allowed = [math]::Round($MaxSpan.TotalHours, 2) + throw "Requested $Kind lifetime ($Requested hours) exceeds the maximum allowed ($MaxDuration = $Allowed hours). Shorten the request; CIPP does not extend limits." + } + } + + $Body.scheduleInfo = [ordered]@{ + startDateTime = $Start.ToString('yyyy-MM-ddTHH:mm:ssZ') + expiration = $Expiration + } + + return [PSCustomObject]@{ + Uri = $Uri + Body = $Body + Kind = $Kind + Action = $Action + ExpirationType = $ExpirationType + StartDateTime = $Start + EndDateTime = $ComputedEnd + } +} diff --git a/Modules/CIPPCore/Public/PIM/Repair-CIPPPIMRoleSettingsFloor.ps1 b/Modules/CIPPCore/Public/PIM/Repair-CIPPPIMRoleSettingsFloor.ps1 new file mode 100644 index 0000000000000..6af085a2205ce --- /dev/null +++ b/Modules/CIPPCore/Public/PIM/Repair-CIPPPIMRoleSettingsFloor.ps1 @@ -0,0 +1,118 @@ +function Repair-CIPPPIMRoleSettingsFloor { + <# + .SYNOPSIS + Raises captured PIM role settings to CIPP's secure floor, reporting every change. + + .DESCRIPTION + Used when a template is created from a role's current settings in a tenant + (ConvertFrom-CIPPPIMPolicyRules output). A tenant's live policy may sit below the secure + floor - permanent eligibility or active assignments, activation without MFA - and a + template must never store that, so each offending value is replaced with the closest value + the floor allows and the change is returned as an adjustment for the caller to surface. + Settings already at or above the floor pass through untouched, so capturing a compliant + role is an exact copy. + + This is the one deliberate exception to "reject, never adjust": templates typed in by an + administrator are still rejected outright (Test-CIPPPIMRoleSettingsFloor); only a capture + of what a tenant already has is raised, because the tenant's own values are the input and + refusing them would make capture useless on any tenant still on Entra's defaults. + + .PARAMETER Settings + The canonical settings object, as returned by ConvertFrom-CIPPPIMPolicyRules. + + .OUTPUTS + PSCustomObject: Settings (the repaired copy), Adjustments (string[] describing each raise). + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + $Settings + ) + + $Adjustments = [System.Collections.Generic.List[string]]::new() + + function Repair-Duration { + param([string]$Value, [string]$Max, [string]$Describe) + if ([string]::IsNullOrWhiteSpace($Value)) { + $Adjustments.Add("$Describe did not require an expiration (permanent allowed); set to $Max.") + return $Max + } + $Span = try { [System.Xml.XmlConvert]::ToTimeSpan($Value) } catch { $null } + if ($null -eq $Span -or $Span -le [timespan]::Zero) { + $Adjustments.Add("$Describe had an unusable duration '$Value'; set to $Max.") + return $Max + } + if ($Span -gt [System.Xml.XmlConvert]::ToTimeSpan($Max)) { + $Adjustments.Add("$Describe allowed '$Value', above the floor maximum; lowered to $Max.") + return $Max + } + return $Value + } + + $ActivationRequires = "$($Settings.activationRequires)" + $ClaimValue = "$($Settings.authenticationContextClaimValue)" + if ($ActivationRequires -eq 'AuthenticationContext' -and $ClaimValue -notmatch '^c\d{1,2}$') { + $Adjustments.Add("Activation used an authentication context without a usable claim value ('$ClaimValue'); switched to requiring MFA.") + $ActivationRequires = 'MFA' + $ClaimValue = '' + } elseif ($ActivationRequires -notin @('MFA', 'AuthenticationContext')) { + $Adjustments.Add('Activation did not require MFA or an authentication context; set to require MFA.') + $ActivationRequires = 'MFA' + $ClaimValue = '' + } + + $ActivationJustification = $Settings.activationRequiresJustification -eq $true + if (-not $ActivationJustification) { + $Adjustments.Add('Activation did not require a justification; enabled it.') + $ActivationJustification = $true + } + + $RequiresApproval = $Settings.activationRequiresApproval -eq $true + $Approvers = "$($Settings.approvers)" + if ($RequiresApproval -and [string]::IsNullOrWhiteSpace($Approvers)) { + $Adjustments.Add('Activation required approval but no approver could be captured; approval disabled.') + $RequiresApproval = $false + } + + $ActiveJustification = $Settings.activeAssignmentRequiresJustification -eq $true + if (-not $ActiveJustification) { + $Adjustments.Add('Creating an active assignment did not require a justification; enabled it.') + $ActiveJustification = $true + } + + $Recipients = @("$($Settings.notificationRecipients)" -split '[,;]' | ForEach-Object { $_.Trim() } | Where-Object { $_ }) + $ValidRecipients = @($Recipients | Where-Object { $_ -match '^[^@\s]+@[^@\s]+\.[^@\s]+$' }) + if ($ValidRecipients.Count -lt $Recipients.Count) { + $Dropped = @($Recipients | Where-Object { $_ -notin $ValidRecipients }) + $Adjustments.Add("Dropped notification recipient(s) that are not e-mail addresses: $($Dropped -join ', ').") + } + $NotificationLevel = "$($Settings.notificationLevel)" + if ($ValidRecipients.Count -gt 0 -and $NotificationLevel -notin @('All', 'Critical')) { + $Adjustments.Add("Notification level '$NotificationLevel' is not valid; set to 'All'.") + $NotificationLevel = 'All' + } + + $Repaired = [PSCustomObject]@{ + activationMaxDuration = Repair-Duration -Value $Settings.activationMaxDuration -Max 'PT24H' -Describe 'Role activation' + activationRequires = $ActivationRequires + authenticationContextClaimValue = $ClaimValue + activationRequiresJustification = $ActivationJustification + activationRequiresTicket = $Settings.activationRequiresTicket -eq $true + activationRequiresApproval = $RequiresApproval + approvers = if ($RequiresApproval) { $Approvers } else { '' } + eligibilityMaxDuration = Repair-Duration -Value $Settings.eligibilityMaxDuration -Max 'P365D' -Describe 'Eligible assignments' + activeAssignmentMaxDuration = Repair-Duration -Value $Settings.activeAssignmentMaxDuration -Max 'P365D' -Describe 'Active assignments' + activeAssignmentRequiresMfa = $Settings.activeAssignmentRequiresMfa -eq $true + activeAssignmentRequiresJustification = $ActiveJustification + notificationRecipients = ($ValidRecipients -join ', ') + notificationLevel = if ([string]::IsNullOrWhiteSpace($NotificationLevel)) { 'All' } else { $NotificationLevel } + } + + return [PSCustomObject]@{ + Settings = $Repaired + Adjustments = @($Adjustments) + } +} diff --git a/Modules/CIPPCore/Public/PIM/Set-CIPPPIMRoleSettings.ps1 b/Modules/CIPPCore/Public/PIM/Set-CIPPPIMRoleSettings.ps1 new file mode 100644 index 0000000000000..214fa45159630 --- /dev/null +++ b/Modules/CIPPCore/Public/PIM/Set-CIPPPIMRoleSettings.ps1 @@ -0,0 +1,74 @@ +function Set-CIPPPIMRoleSettings { + <# + .SYNOPSIS + Applies desired PIM policy rules to a role's management policy, one PATCH per differing rule. + + .DESCRIPTION + Compares first (Compare-CIPPPIMRoleSettings) and only writes the rules that differ, so a + compliant tenant sees no writes and the logbook records exactly what changed. Callers must + have validated the desired settings against the secure floor; this function does not + weaken or strengthen anything on its own. + + .PARAMETER PolicyId + The unifiedRoleManagementPolicy id (from policies/roleManagementPolicyAssignments.policyId). + + .FUNCTIONALITY + Internal + #> + [CmdletBinding(SupportsShouldProcess = $true)] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [Parameter(Mandatory = $true)] + [string]$PolicyId, + + [Parameter(Mandatory = $true)] + [AllowEmptyCollection()] + [array]$DesiredRules, + + [Parameter(Mandatory = $true)] + [AllowNull()] + [AllowEmptyCollection()] + $CurrentRules, + + [string]$RoleName = '', + + $Headers, + + [string]$APIName = 'Standards' + ) + + $Differences = Compare-CIPPPIMRoleSettings -DesiredRules $DesiredRules -CurrentRules $CurrentRules -RoleName $RoleName + $Results = [System.Collections.Generic.List[object]]::new() + + if ($Differences.Count -eq 0) { + return @($Results) + } + + $RuleIds = @($Differences.Rule | Sort-Object -Unique) + foreach ($RuleId in $RuleIds) { + $Rule = $DesiredRules | Where-Object { $_['id'] -eq $RuleId } | Select-Object -First 1 + if (-not $Rule) { continue } + + $Changed = @($Differences | Where-Object { $_.Rule -eq $RuleId } | ForEach-Object { "$($_.Property): $($_.Current) -> $($_.Expected)" }) -join '; ' + $Uri = "https://graph.microsoft.com/beta/policies/roleManagementPolicies/$PolicyId/rules/$RuleId" + $Body = ConvertTo-Json -InputObject $Rule -Depth 20 -Compress + + if (-not $PSCmdlet.ShouldProcess("$RoleName ($PolicyId) rule $RuleId", 'PATCH')) { continue } + + try { + $null = New-GraphPOSTRequest -type PATCH -uri $Uri -body $Body -tenantid $TenantFilter -AsApp $true + $Message = "Updated PIM role setting $RuleId for $RoleName`: $Changed" + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Message -Sev 'Info' -LogData @{ Role = $RoleName; PolicyId = $PolicyId; Rule = $RuleId; Changes = $Changed } + $Results.Add([PSCustomObject]@{ Rule = $RuleId; Success = $true; Message = $Message }) + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Message = "Failed to update PIM role setting $RuleId for $RoleName`: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Message -Sev 'Error' -LogData $ErrorMessage + $Results.Add([PSCustomObject]@{ Rule = $RuleId; Success = $false; Message = $Message }) + } + } + + return @($Results) +} diff --git a/Modules/CIPPCore/Public/PIM/Test-CIPPPIMRoleSettingsFloor.ps1 b/Modules/CIPPCore/Public/PIM/Test-CIPPPIMRoleSettingsFloor.ps1 new file mode 100644 index 0000000000000..edb9b7252c12e --- /dev/null +++ b/Modules/CIPPCore/Public/PIM/Test-CIPPPIMRoleSettingsFloor.ps1 @@ -0,0 +1,134 @@ +function Test-CIPPPIMRoleSettingsFloor { + <# + .SYNOPSIS + Validates PIM role settings against CIPP's secure floor. + + .DESCRIPTION + Pure validation shared by the PIM role-settings template endpoints (a template below the + floor is rejected, not clamped), the PIMRoleSettings standard (a stored template is + re-checked at run time so a hand-edited table row cannot weaken a tenant) and the policy + summary shown on the Roles pages (a tenant's live policy is graded against the same floor). + + The floor: + - activation (Expiration_EndUser_Assignment) must expire; maximum PT24H. Above PT8H is + allowed but reported as a warning so the override is visible in the logbook. + - activation must require MFA, or an authentication context (the two are mutually + exclusive in Entra, so one of them is enough). + - activation must require a justification. + - eligibility (Expiration_Admin_Eligibility) must expire; maximum P365D. + - active assignments (Expiration_Admin_Assignment) must expire; maximum P365D. This is what + stops permanent active assignments being created in the portal as well as in CIPP. + - active assignments must require a justification. + - approval is optional, but when required at least one approver must be named. + - notification recipients, when given, must be e-mail addresses with a valid level. + + .PARAMETER Settings + The canonical settings object (see ConvertTo-CIPPPIMRoleSettings). A $null duration means + "no expiration" and fails the floor. + + .OUTPUTS + PSCustomObject: Valid (bool), Errors (string[]), Warnings (string[]). + + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [AllowNull()] + $Settings + ) + + $Errors = [System.Collections.Generic.List[string]]::new() + $Warnings = [System.Collections.Generic.List[string]]::new() + + if ($null -eq $Settings) { + $Errors.Add('No settings supplied.') + return [PSCustomObject]@{ Valid = $false; Errors = @($Errors); Warnings = @($Warnings) } + } + + function Test-FloorBool { + param($Value) + if ($Value -is [bool]) { return $Value } + if ($null -eq $Value) { return $false } + return ("$Value" -match '^(true|1|yes)$') + } + + function Get-FloorSpan { + param([string]$Value, [string]$Name, [string]$Max, [string]$Describe) + if ([string]::IsNullOrWhiteSpace($Value)) { + $Errors.Add("$Describe must expire ($Name is empty - a permanent/no-expiration setting is below the secure floor).") + return $null + } + try { + $Span = [System.Xml.XmlConvert]::ToTimeSpan($Value) + } catch { + $Errors.Add("$Describe`: '$Value' is not a valid ISO 8601 duration ($Name).") + return $null + } + if ($Span -le [timespan]::Zero) { + $Errors.Add("$Describe`: '$Value' must be greater than zero ($Name).") + return $null + } + $MaxSpan = [System.Xml.XmlConvert]::ToTimeSpan($Max) + if ($Span -gt $MaxSpan) { + $Errors.Add("$Describe`: '$Value' exceeds the maximum of $Max ($Name).") + return $null + } + return $Span + } + + # Activation (end-user assignment) + $ActivationSpan = Get-FloorSpan -Value $Settings.activationMaxDuration -Name 'activationMaxDuration' -Max 'PT24H' -Describe 'Role activation' + if ($ActivationSpan -and $ActivationSpan -gt [System.Xml.XmlConvert]::ToTimeSpan('PT8H')) { + $Warnings.Add("Role activation maximum '$($Settings.activationMaxDuration)' exceeds the recommended PT8H.") + } + + $Requires = "$($Settings.activationRequires)" + switch ($Requires) { + 'MFA' { } + 'AuthenticationContext' { + if ("$($Settings.authenticationContextClaimValue)" -notmatch '^c\d{1,2}$') { + $Errors.Add("Activation with an authentication context needs a claim value such as 'c1' (authenticationContextClaimValue).") + } + } + default { + $Errors.Add("Role activation must require MFA or an authentication context (activationRequires is '$Requires').") + } + } + + if (-not (Test-FloorBool $Settings.activationRequiresJustification)) { + $Errors.Add('Role activation must require a justification (activationRequiresJustification).') + } + + if ((Test-FloorBool $Settings.activationRequiresApproval) -and [string]::IsNullOrWhiteSpace("$($Settings.approvers)")) { + $Errors.Add('Approval is required but no approvers are named (approvers).') + } + + # Admin eligibility / assignment + $null = Get-FloorSpan -Value $Settings.eligibilityMaxDuration -Name 'eligibilityMaxDuration' -Max 'P365D' -Describe 'Eligible assignments' + $null = Get-FloorSpan -Value $Settings.activeAssignmentMaxDuration -Name 'activeAssignmentMaxDuration' -Max 'P365D' -Describe 'Active assignments' + + if (-not (Test-FloorBool $Settings.activeAssignmentRequiresJustification)) { + $Errors.Add('Creating an active assignment must require a justification (activeAssignmentRequiresJustification).') + } + + # Notifications + $Recipients = @("$($Settings.notificationRecipients)" -split '[,;]' | ForEach-Object { $_.Trim() } | Where-Object { $_ }) + if ($Recipients.Count -gt 0) { + foreach ($Recipient in $Recipients) { + if ($Recipient -notmatch '^[^@\s]+@[^@\s]+\.[^@\s]+$') { + $Errors.Add("'$Recipient' is not a valid notification e-mail address (notificationRecipients).") + } + } + if ("$($Settings.notificationLevel)" -notin @('All', 'Critical')) { + $Errors.Add("notificationLevel must be 'All' or 'Critical' when recipients are set (found '$($Settings.notificationLevel)').") + } + } + + return [PSCustomObject]@{ + Valid = ($Errors.Count -eq 0) + Errors = @($Errors) + Warnings = @($Warnings) + } +} diff --git a/Modules/CIPPCore/Public/Remove-CIPPDbItem.ps1 b/Modules/CIPPCore/Public/Remove-CIPPDbItem.ps1 index 056edfc4a5aac..4386ac7a30b50 100644 --- a/Modules/CIPPCore/Public/Remove-CIPPDbItem.ps1 +++ b/Modules/CIPPCore/Public/Remove-CIPPDbItem.ps1 @@ -4,7 +4,9 @@ function Remove-CIPPDbItem { Remove an item from the CIPP Reporting database .DESCRIPTION - Removes a specific item from the CippReportingDB table using partition key (tenant) and row key (item ID) + Removes a specific item from the CippReportingDB table using partition key (tenant) + and either Type+ItemId or an explicit RowKey. Decrements the matching {Type}-Count + row when a data row (not the Count row itself) is removed. .PARAMETER TenantFilter The tenant domain or GUID (partition key) @@ -15,10 +17,19 @@ function Remove-CIPPDbItem { .PARAMETER ItemId The item ID or identifier to remove (used in row key) + .PARAMETER RowKey + Explicit table RowKey (preferred when the caller already has storage keys) + + .PARAMETER ETag + Optional ETag when deleting by RowKey + .EXAMPLE Remove-CIPPDbItem -TenantFilter 'contoso.onmicrosoft.com' -Type 'MailboxRules' -ItemId 'rule-id-123' + + .EXAMPLE + Remove-CIPPDbItem -TenantFilter 'contoso.onmicrosoft.com' -Type 'Users' -RowKey 'Users-abc-123' #> - [CmdletBinding()] + [CmdletBinding(DefaultParameterSetName = 'ByItemId')] param( [Parameter(Mandatory = $true)] [string]$TenantFilter, @@ -26,27 +37,52 @@ function Remove-CIPPDbItem { [Parameter(Mandatory = $true)] [string]$Type, - [Parameter(Mandatory = $true)] - [string]$ItemId + [Parameter(Mandatory = $true, ParameterSetName = 'ByItemId')] + [string]$ItemId, + + [Parameter(Mandatory = $true, ParameterSetName = 'ByRowKey')] + [string]$RowKey, + + [Parameter(ParameterSetName = 'ByRowKey')] + [string]$ETag ) try { $Table = Get-CippTable -tablename 'CippReportingDB' - # Sanitize the ItemId for RowKey (same as in Add-CIPPDbItem) - $SanitizedId = $ItemId -replace '[/\\#?]', '_' -replace '[\u0000-\u001F\u007F-\u009F]', '' - $RowKey = "$Type-$SanitizedId" + if ($TenantFilter -match '^[0-9a-f]{8}-([0-9a-f]{4}-){3}[0-9a-f]{12}$') { + $TenantLookup = Get-Tenants -TenantFilter $TenantFilter + if ($TenantLookup) { + $TenantFilter = $TenantLookup.defaultDomainName + } + } + + if ($PSCmdlet.ParameterSetName -eq 'ByItemId') { + # Sanitize the ItemId for RowKey (same as in Add-CIPPDbItem) + $SanitizedId = $ItemId -replace '[/\\#?]', '_' -replace '[\u0000-\u001F\u007F-\u009F]', '' + $RowKey = "$Type-$SanitizedId" + } else { + $ExpectedPrefix = "$Type-" + if (-not $RowKey.StartsWith($ExpectedPrefix, [System.StringComparison]::OrdinalIgnoreCase)) { + throw "RowKey '$RowKey' does not match type '$Type'" + } + } - # Try to get the entity $Filter = "PartitionKey eq '$TenantFilter' and RowKey eq '$RowKey'" $Entity = Get-CIPPAzDataTableEntity @Table -Filter $Filter if ($Entity) { - # Remove the entity + if ($ETag) { + $Entity | Add-Member -MemberType NoteProperty -Name 'ETag' -Value $ETag -Force + } Remove-CIPPAzDataTableEntity @Table -Entity $Entity -Force - Write-LogMessage -API 'CIPPDbItem' -tenant $TenantFilter -message "Removed $Type item with ID: $ItemId" -sev Debug + Write-LogMessage -API 'CIPPDbItem' -tenant $TenantFilter -message "Removed $Type row: $RowKey" -sev Debug + + # Do not decrement when removing the Count row itself + if ($RowKey -eq "$Type-Count") { + return + } - # Always decrement count try { $CountRowKey = "$Type-Count" $CountFilter = "PartitionKey eq '$TenantFilter' and RowKey eq '$CountRowKey'" @@ -66,7 +102,7 @@ function Remove-CIPPDbItem { Write-LogMessage -API 'CIPPDbItem' -tenant $TenantFilter -message "Failed to decrement count for $Type : $($_.Exception.Message)" -sev Warning } } else { - Write-LogMessage -API 'CIPPDbItem' -tenant $TenantFilter -message "Item not found for removal: $Type with ID $ItemId" -sev Debug + Write-LogMessage -API 'CIPPDbItem' -tenant $TenantFilter -message "Item not found for removal: $Type row $RowKey" -sev Debug } } catch { diff --git a/Modules/CIPPCore/Public/Remove-CIPPMobileDevice.ps1 b/Modules/CIPPCore/Public/Remove-CIPPMobileDevice.ps1 index e436fce09d5c6..3663920260845 100644 --- a/Modules/CIPPCore/Public/Remove-CIPPMobileDevice.ps1 +++ b/Modules/CIPPCore/Public/Remove-CIPPMobileDevice.ps1 @@ -14,10 +14,14 @@ function Remove-CIPPMobileDevice { $null = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-MobileDevice' -Anchor $Username -cmdParams @{mailbox = $Username } | ForEach-Object { try { $MobileDevice = $_ + # FriendlyName is usually empty; fall back like the ActiveSync device list. + $DeviceName = @($MobileDevice.FriendlyName, $MobileDevice.DeviceModel, $MobileDevice.DeviceOS, $MobileDevice.DeviceId) | + Where-Object { -not [string]::IsNullOrWhiteSpace($_) } | Select-Object -First 1 + if (-not $DeviceName) { $DeviceName = 'Unknown device' } $null = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Remove-MobileDevice' -Anchor $Username -cmdParams @{Identity = $MobileDevice.Identity } - $RemovedDevices.Add("$($MobileDevice.FriendlyName)") + $RemovedDevices.Add([string]$DeviceName) } catch { - $ErrorDevices.Add("$($MobileDevice.FriendlyName)") + $ErrorDevices.Add([string]$DeviceName) } } if ($ErrorDevices.Count -eq 0) { diff --git a/Modules/CIPPCore/Public/Remove-CIPPSPOSiteUser.ps1 b/Modules/CIPPCore/Public/Remove-CIPPSPOSiteUser.ps1 index f62defdce7a55..7ddeb0b1ff9ef 100644 --- a/Modules/CIPPCore/Public/Remove-CIPPSPOSiteUser.ps1 +++ b/Modules/CIPPCore/Public/Remove-CIPPSPOSiteUser.ps1 @@ -44,7 +44,7 @@ function Remove-CIPPSPOSiteUser { foreach ($SiteUrl in $SiteUrls) { if (-not $PSCmdlet.ShouldProcess($SiteUrl, "Remove $LoginName")) { continue } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $BaseUri = (Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl -SharePointInfo $SharePointInfo).BaseUri try { try { $EnsureBody = ConvertTo-Json -Compress -InputObject @{ logonName = $LoginName } diff --git a/Modules/CIPPCore/Public/Remove-CIPPUserTeamsPhoneDIDs.ps1 b/Modules/CIPPCore/Public/Remove-CIPPUserTeamsPhoneDIDs.ps1 index 420e41e86ea63..fc7f7db2f8c6c 100644 --- a/Modules/CIPPCore/Public/Remove-CIPPUserTeamsPhoneDIDs.ps1 +++ b/Modules/CIPPCore/Public/Remove-CIPPUserTeamsPhoneDIDs.ps1 @@ -13,6 +13,8 @@ function Remove-CIPPUserTeamsPhoneDIDs { $TenantFilter ) + $BaseUri = 'https://graph.microsoft.com/v1.0/admin/teams/telephoneNumberManagement/numberAssignments' + try { # Set Username to UserID if not provided @@ -25,61 +27,41 @@ function Remove-CIPPUserTeamsPhoneDIDs { $SuccessCount = 0 $ErrorCount = 0 - # Get all tenant DIDs - $TeamsPhoneDIDs = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/admin/teams/telephoneNumberManagement/numberAssignments" -tenant $TenantFilter + $TeamsPhoneDIDs = New-GraphGetRequest -uri $BaseUri -tenantid $TenantFilter if (-not $TeamsPhoneDIDs -or $TeamsPhoneDIDs.Count -eq 0) { - $Result = "No Teams Phone DIDs found in tenant" + $Result = 'No Teams Phone DIDs found in tenant' $Results.Add($Result) return $Results.ToArray() } # Filter DIDs assigned to the specific user - $UserDIDs = $TeamsPhoneDIDs | Where-Object { $_.assignmentTargetId -eq $UserID -and $_.assignmentStatus -ne 'unassigned' } + $UserDIDs = @($TeamsPhoneDIDs | Where-Object { $_.assignmentTargetId -eq $UserID -and $_.assignmentStatus -ne 'unassigned' }) - if (-not $UserDIDs -or $UserDIDs.Count -eq 0) { + if ($UserDIDs.Count -eq 0) { $Result = "No Teams Phone DIDs found assigned to user: '$Username' - '$UserID'" $Results.Add($Result) return $Results.ToArray() } - # Prepare bulk requests for all DIDs - $RemoveRequests = foreach ($DID in $UserDIDs) { - @{ - id = $DID.telephoneNumber - method = 'POST' - url = "admin/teams/telephoneNumberManagement/numberAssignments/unassignNumber" - headers = @{ - 'Content-Type' = 'application/json' - } - body = @{ - telephoneNumber = $DID.telephoneNumber - numberType = $DID.numberType + # One POST per number: $batch fails with an IIS 'Request Too Long' page. + foreach ($DID in $UserDIDs) { + $PhoneNumber = $DID.telephoneNumber + try { + $Body = @{ + telephoneNumber = $PhoneNumber + numberType = Get-CippTeamsNumberType -NumberType $DID.numberType } - } - } + $null = New-GraphPOSTRequest -uri "$BaseUri/unassignNumber" -tenantid $TenantFilter -body ($Body | ConvertTo-Json -Compress) -type POST - # Execute bulk request - $RemoveResults = New-GraphBulkRequest -tenantid $TenantFilter -requests @($RemoveRequests) - - # Process results - $RemoveResults | ForEach-Object { - $PhoneNumber = $_.id - - if ($_.status -in (202, 204)) { $SuccessResult = "Successfully removed Teams Phone DID: '$PhoneNumber' from: '$Username' - '$UserID'" Write-LogMessage -headers $Headers -API $APIName -message $SuccessResult -Sev 'Info' -tenant $TenantFilter $Results.Add($SuccessResult) $SuccessCount++ - } else { - $ErrorMessage = if ($_.body.error.message) { - $_.body.error.message - } else { - "HTTP Status: $($_.status)" - } - - $ErrorResult = "Failed to remove Teams Phone DID: '$PhoneNumber' from: '$Username' - '$UserID'. Error: $ErrorMessage" - Write-LogMessage -headers $Headers -API $APIName -message $ErrorResult -Sev 'Error' -tenant $TenantFilter + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $ErrorResult = "Failed to remove Teams Phone DID: '$PhoneNumber' from: '$Username' - '$UserID'. Error: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -message $ErrorResult -Sev 'Error' -tenant $TenantFilter -LogData $ErrorMessage $Results.Add($ErrorResult) $ErrorCount++ } diff --git a/Modules/CIPPCore/Public/Request-CIPPSPOPersonalSite.ps1 b/Modules/CIPPCore/Public/Request-CIPPSPOPersonalSite.ps1 index 46afa2f3d3333..13816a670d220 100644 --- a/Modules/CIPPCore/Public/Request-CIPPSPOPersonalSite.ps1 +++ b/Modules/CIPPCore/Public/Request-CIPPSPOPersonalSite.ps1 @@ -39,13 +39,30 @@ function Request-CIPPSPOPersonalSite { $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter try { - $Request = New-GraphPostRequest -scope "$($SharePointInfo.AdminUrl)/.default" -tenantid $TenantFilter -Uri "$($SharePointInfo.AdminUrl)/_vti_bin/client.svc/ProcessQuery" -Type POST -Body $XML -ContentType 'text/xml' - if (!$Request.IsComplete) { throw } + # OneDrive pre-provisioning (ProfileLoader.RequestPersonalSites) is a User Profile Service + # operation, so it must run app-only with the SAM certificate: a GDAP delegated token has no + # licensed user object in the customer tenant and SharePoint refuses it with a bare 401. App-only + # here needs the SharePoint 'User.ReadWrite.All' application permission (declared in + # SAMManifest.json, applied on CPV consent) on top of Sites.FullControl.All. + $Request = New-GraphPostRequest -scope "$($SharePointInfo.AdminUrl)/.default" -tenantid $TenantFilter -Uri "$($SharePointInfo.AdminUrl)/_vti_bin/client.svc/ProcessQuery" -Type POST -Body $XML -ContentType 'text/xml' -AsApp $true -UseCertificate + + # ProcessQuery answers HTTP 200 even when the request was refused - the reason rides in the CSOM + # ErrorInfo node (e.g. an "access to profile information" denial when the permission above is not + # yet consented). Surface it so a refusal is not reported back as success. + $CsomError = ($Request | Where-Object { $_.ErrorInfo } | Select-Object -First 1).ErrorInfo.ErrorMessage + if ($CsomError) { throw $CsomError } + if (!$Request.IsComplete) { throw 'SharePoint did not confirm the personal site request.' } Write-LogMessage -headers $Headers -API $APIName -message "Requested personal site for $($UserEmails -join ', ')" -Sev 'Info' -tenant $TenantFilter return "Successfully requested personal site for $($UserEmails -join ', ')" } catch { $ErrorMessage = Get-CippException -Exception $_ - $Result = "Failed to request personal site for $($UserEmails -join ', '). Error: $($ErrorMessage.NormalizedError)" + $Detail = $ErrorMessage.NormalizedError + # A "profile information" denial means the SAM app has not been granted the SharePoint + # User.ReadWrite.All application permission in this tenant yet - refreshing CPV consent fixes it. + if ($Detail -match 'profile information') { + $Detail = "$Detail - CIPP is missing the SharePoint 'User.ReadWrite.All' application permission in $TenantFilter. Refresh the tenant's CPV permissions and try again." + } + $Result = "Failed to request personal site for $($UserEmails -join ', '). Error: $Detail" Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' -tenant $TenantFilter -LogData $ErrorMessage throw $Result } diff --git a/Modules/CIPPCore/Public/Resolve-CIPPIntuneTargetedMobileApps.ps1 b/Modules/CIPPCore/Public/Resolve-CIPPIntuneTargetedMobileApps.ps1 new file mode 100644 index 0000000000000..bae616ac6ac35 --- /dev/null +++ b/Modules/CIPPCore/Public/Resolve-CIPPIntuneTargetedMobileApps.ps1 @@ -0,0 +1,105 @@ +function Resolve-CIPPIntuneTargetedMobileApps { + <# + .SYNOPSIS + Resolves an app configuration template's targeted apps to the target tenant's mobile app ids. + .DESCRIPTION + A managed-device app configuration policy (deviceAppManagement/mobileAppConfigurations) names + the apps it applies to by mobileApp id, and those ids exist only in the tenant the policy was + captured from. Deploying the template's ids into another tenant fails with an unknown app. + + New-CIPPIntuneTemplate records each targeted app's identity alongside the ids + (targetedMobileAppsDetails: bundle id, package id, display name, type). This function turns + that into the matching app ids in the tenant being deployed to: bundle id or package id first, + then display name plus app type. Any app that cannot be found is reported by name rather than + silently dropped, because a configuration policy that targets nothing is not the policy that + was asked for. + + Templates captured before the identity was recorded carry only ids. Those are kept when the + target tenant has an app with that id (the same tenant, or a re-deploy), and rejected with an + explanation otherwise. + .PARAMETER PolicyFile + The template payload, parsed from the template's RAWJson. + .PARAMETER TenantFilter + The tenant the policy is being deployed to. + .OUTPUTS + The resolved mobileApp ids for the target tenant. + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + $PolicyFile, + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + $Headers, + $APIName = 'Resolve-CIPPIntuneTargetedMobileApps' + ) + + $TemplateAppIds = @($PolicyFile.targetedMobileApps | Where-Object { $_ }) + $Details = @($PolicyFile.targetedMobileAppsDetails | Where-Object { $_ }) + + if ($TemplateAppIds.Count -eq 0 -and $Details.Count -eq 0) { + return @() + } + + $TenantApps = @(New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/deviceAppManagement/mobileApps?$top=999' -tenantid $TenantFilter) + $TenantAppIds = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + foreach ($App in $TenantApps) { if ($App.id) { [void]$TenantAppIds.Add([string]$App.id) } } + + $Resolved = [System.Collections.Generic.List[string]]::new() + $Unresolved = [System.Collections.Generic.List[string]]::new() + + if ($Details.Count -gt 0) { + foreach ($Detail in $Details) { + # Same id present in the target tenant: the template came from this tenant. + if ($Detail.id -and $TenantAppIds.Contains([string]$Detail.id)) { + if (-not $Resolved.Contains([string]$Detail.id)) { $Resolved.Add([string]$Detail.id) } + continue + } + + $Match = $null + foreach ($IdentityProperty in 'bundleId', 'packageId', 'packageIdentifier') { + $Identity = [string]$Detail.$IdentityProperty + if ([string]::IsNullOrWhiteSpace($Identity)) { continue } + $Match = $TenantApps | Where-Object { [string]$_.$IdentityProperty -eq $Identity } | Select-Object -First 1 + if ($Match) { break } + } + if (-not $Match -and $Detail.displayName) { + # Name plus type: a store app and a line-of-business app can share a name and + # cannot substitute for one another in a configuration policy. + $Match = $TenantApps | Where-Object { + $_.displayName -eq $Detail.displayName -and (-not $Detail.'@odata.type' -or $_.'@odata.type' -eq $Detail.'@odata.type') + } | Select-Object -First 1 + } + + if ($Match.id) { + if (-not $Resolved.Contains([string]$Match.id)) { $Resolved.Add([string]$Match.id) } + } else { + $Identifier = $Detail.bundleId ?? $Detail.packageId ?? $Detail.packageIdentifier ?? $Detail.id + $Unresolved.Add("'$($Detail.displayName ?? 'unknown app')' ($Identifier)") + } + } + } else { + foreach ($AppId in $TemplateAppIds) { + if ($TenantAppIds.Contains([string]$AppId)) { + if (-not $Resolved.Contains([string]$AppId)) { $Resolved.Add([string]$AppId) } + } else { + $Unresolved.Add("app id $AppId") + } + } + if ($Unresolved.Count -gt 0) { + $Message = "App configuration '$($PolicyFile.displayName)' targets apps that do not exist in $TenantFilter ($($Unresolved -join ', ')). This template was captured before CIPP recorded which apps those ids belong to, so they cannot be matched to this tenant's apps. Re-create the template from the source tenant and deploy it again." + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Message -Sev Error + throw $Message + } + } + + if ($Unresolved.Count -gt 0) { + $Message = "App configuration '$($PolicyFile.displayName)' targets apps that are not present in $TenantFilter : $($Unresolved -join ', '). Add these apps to Intune in this tenant, then deploy the template again." + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Message -Sev Error + throw $Message + } + + return @($Resolved) +} diff --git a/Modules/CIPPCore/Public/Resolve-CIPPSharePointLibraryRootUri.ps1 b/Modules/CIPPCore/Public/Resolve-CIPPSharePointLibraryRootUri.ps1 new file mode 100644 index 0000000000000..b77073fd614a8 --- /dev/null +++ b/Modules/CIPPCore/Public/Resolve-CIPPSharePointLibraryRootUri.ps1 @@ -0,0 +1,52 @@ +function Resolve-CIPPSharePointLibraryRootUri { + <# + .SYNOPSIS + Resolves a document library list GUID to its absolute root folder URI via SPO REST. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [Parameter(Mandatory = $true)] + [string]$ListId, + + [string]$SiteUrl, + [string]$SiteId + ) + + if ([string]::IsNullOrWhiteSpace($SiteUrl)) { + if ([string]::IsNullOrWhiteSpace($SiteId)) { + throw 'SiteUrl or SiteId is required.' + } + $SiteMeta = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/sites/$SiteId`?`$select=webUrl" -tenantid $TenantFilter -asapp $true + if ([string]::IsNullOrWhiteSpace($SiteMeta.webUrl)) { + throw "Could not resolve webUrl for site id $SiteId." + } + $SiteUrl = $SiteMeta.webUrl + } + + $SiteUrl = $SiteUrl.TrimEnd('/') + $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter + $Scope = "$($SharePointInfo.SharePointUrl)/.default" + $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } + $BaseUri = "$SiteUrl/_api" + $SafeListId = $ListId -replace "'", "''" + + $List = New-GraphGetRequest -uri "$BaseUri/web/lists(guid'$SafeListId')?`$select=RootFolder/ServerRelativeUrl&`$expand=RootFolder" ` + -tenantid $TenantFilter -scope $Scope -extraHeaders $JsonAccept -UseCertificate -AsApp $true + + $ServerRelativeUrl = $List.RootFolder.ServerRelativeUrl + if ([string]::IsNullOrWhiteSpace($ServerRelativeUrl)) { + throw 'Could not resolve library root folder ServerRelativeUrl.' + } + + $Origin = ([System.Uri]$SiteUrl).GetLeftPart([System.UriPartial]::Authority) + $AbsoluteUri = "$Origin$ServerRelativeUrl" + + [PSCustomObject]@{ + SiteUrl = $SiteUrl + LibraryRootUri = $AbsoluteUri + ServerRelativeUrl = $ServerRelativeUrl + } +} diff --git a/Modules/CIPPCore/Public/Resolve-CIPPSharePointPermissionScope.ps1 b/Modules/CIPPCore/Public/Resolve-CIPPSharePointPermissionScope.ps1 index d0d00d140e68e..63135102c8eee 100644 --- a/Modules/CIPPCore/Public/Resolve-CIPPSharePointPermissionScope.ps1 +++ b/Modules/CIPPCore/Public/Resolve-CIPPSharePointPermissionScope.ps1 @@ -39,10 +39,10 @@ function Resolve-CIPPSharePointPermissionScope { [switch]$EnsureUniqueRoleAssignments ) - $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter - $Scope = "$($SharePointInfo.SharePointUrl)/.default" - $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $Scope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri $IsLibrary = -not [string]::IsNullOrWhiteSpace($ListId) $ScopeUri = if ($IsLibrary) { "$BaseUri/web/lists(guid'$ListId')" } else { "$BaseUri/web" } @@ -50,7 +50,18 @@ function Resolve-CIPPSharePointPermissionScope { $BrokeInheritance = $false if ($IsLibrary) { $ListInfo = New-GraphGetRequest -uri "$ScopeUri`?`$select=HasUniqueRoleAssignments,Title" -tenantid $TenantFilter -scope $Scope -extraHeaders $JsonAccept -UseCertificate -AsApp $true - $HasUnique = [bool]$ListInfo.HasUniqueRoleAssignments + # [bool]$null is $false in PowerShell, which falsely reports inheriting libraries when + # HasUniqueRoleAssignments is not projected. Probe the scalar property in that case. + $HasUniqueRaw = $ListInfo.HasUniqueRoleAssignments + if ($null -eq $HasUniqueRaw) { + try { + $Probe = New-GraphGetRequest -uri "$ScopeUri/HasUniqueRoleAssignments" -tenantid $TenantFilter -scope $Scope -extraHeaders $JsonAccept -UseCertificate -AsApp $true + $HasUniqueRaw = if ($null -ne $Probe.PSObject.Properties['value']) { $Probe.value } else { $Probe } + } catch { + $HasUniqueRaw = $null + } + } + $HasUnique = $HasUniqueRaw -eq $true -or "$HasUniqueRaw" -eq 'true' $TargetLabel = if ($ListInfo.Title) { "library '$($ListInfo.Title)'" } else { "library $ListId" } if (-not $HasUnique -and $EnsureUniqueRoleAssignments.IsPresent) { diff --git a/Modules/CIPPCore/Public/Resolve-CIPPSharePointRestContext.ps1 b/Modules/CIPPCore/Public/Resolve-CIPPSharePointRestContext.ps1 new file mode 100644 index 0000000000000..b297dc54cfef7 --- /dev/null +++ b/Modules/CIPPCore/Public/Resolve-CIPPSharePointRestContext.ps1 @@ -0,0 +1,49 @@ +function Resolve-CIPPSharePointRestContext { + <# + .SYNOPSIS + Resolve the SharePoint REST context for a site-scoped API call + + .DESCRIPTION + Builds the certificate-authenticated SharePoint REST plumbing shared by site-scoped + endpoints: the token scope, odata headers, normalized site URL and the /_api base URI. + Pass -SharePointInfo when resolving several sites in one operation to avoid repeated + admin-link lookups. + + .PARAMETER TenantFilter + The tenant the site belongs to + + .PARAMETER SiteUrl + The full URL of the site + + .PARAMETER SharePointInfo + Optional output from Get-SharePointAdminLink to reuse across multiple sites + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [Parameter(Mandatory = $true)] + [string]$SiteUrl, + + [object]$SharePointInfo + ) + + if (-not $SharePointInfo) { + $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter + } + + $NormalizedSiteUrl = $SiteUrl.TrimEnd('/') + $Scope = "$($SharePointInfo.SharePointUrl)/.default" + $Headers = @{ Accept = 'application/json;odata=nometadata' } + $BaseUri = "$NormalizedSiteUrl/_api" + + return [PSCustomObject]@{ + SharePointInfo = $SharePointInfo + SiteUrl = $NormalizedSiteUrl + Scope = $Scope + Headers = $Headers + BaseUri = $BaseUri + WebUri = "$BaseUri/web" + } +} diff --git a/Modules/CIPPCore/Public/Send-CIPPAlert.ps1 b/Modules/CIPPCore/Public/Send-CIPPAlert.ps1 index 52cefebb84d97..961cd378c84cf 100644 --- a/Modules/CIPPCore/Public/Send-CIPPAlert.ps1 +++ b/Modules/CIPPCore/Public/Send-CIPPAlert.ps1 @@ -17,6 +17,9 @@ function Send-CIPPAlert { $RowKey = [string][guid]::NewGuid(), $Attachments, $AffectedUser, + $PsaTicketPriority, + $PSAReference, + $PSATicketId, [switch]$UseStandardizedSchema ) Write-Information 'Shipping Alert' @@ -343,8 +346,10 @@ function Send-CIPPAlert { if ($Type -eq 'psa') { Write-Information 'Trying to send to PSA' if (-not $config.sendtoIntegration) { + # The extension test button bypasses this gate, so log the skip where the operator looks. Write-Information 'PSA delivery skipped: sendtoIntegration is disabled in CippNotifications config. Enable it under Settings -> Notifications to route alerts to your PSA.' - return + Write-LogMessage -API 'Webhook Alerts' -tenant $TenantFilter -message "PSA delivery skipped for '$Title': 'Send to integration' is off under Settings > Notifications, so no PSA ticket was raised." -sev Warning + return 'Skipped: PSA delivery is disabled in the notification settings' } if ($PSCmdlet.ShouldProcess('PSA', 'Sending alert')) { try { @@ -358,20 +363,40 @@ function Send-CIPPAlert { AlertText = "$HTMLContent" AlertTitle = "$PsaTitle" } + if ($PSAReference) { + # Passed through verbatim - what a reference means is the PSA extension's call. + $Alert.Reference = $PSAReference + Write-Information "PSA alert reference: $PSAReference" + } + if ($PSATicketId) { + $Alert.PsaTicketId = $PSATicketId + Write-Information "PSA alert target ticket: $PSATicketId" + } if ($AffectedUser) { $Alert.AffectedUser = $AffectedUser $UserLabel = if ($AffectedUser.UPN) { $AffectedUser.UPN } elseif ($AffectedUser.AzureOID) { "OID:$($AffectedUser.AzureOID)" } else { 'unknown' } Write-Information "PSA alert AffectedUser: $UserLabel" } - $PsaResult = New-CippExtAlert -Alert $Alert - if ($PsaResult) { - Write-Information "PSA result: $PsaResult" + if ($PsaTicketPriority) { + $Alert.PsaTicketPriority = $PsaTicketPriority + Write-Information "PSA alert priority override: $PsaTicketPriority" + } + # Extensions report failure in their return value, one line per extension. + $PsaOutput = @(New-CippExtAlert -Alert $Alert) + $PsaResult = ($PsaOutput -join ' ').Trim() + $Failure = (@($PsaOutput | Where-Object { "$_" -match '^(Failed|Error)' }) -join ' ').Trim() + if ($Failure) { + Write-LogMessage -API 'Webhook Alerts' -tenant $TenantFilter -message "PSA delivery failed for '$Title': $Failure" -sev Error + return "Error: $Failure" } Write-LogMessage -API 'Webhook Alerts' -tenant $TenantFilter -message "Sent PSA alert $title" -sev info + # Same shape as the email and webhook branches; the text carries the ticket id. + return "Sent PSA alert: $title$(if ($PsaResult) { " - $PsaResult" })" } catch { $ErrorMessage = Get-CippException -Exception $_ Write-Information "Could not send alerts to ticketing system: $($ErrorMessage.NormalizedError)" Write-LogMessage -API 'Webhook Alerts' -tenant $TenantFilter -message "Could not send alerts to ticketing system: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + return "Error: Could not send alerts to ticketing system: $($ErrorMessage.NormalizedError)" } } } diff --git a/Modules/CIPPCore/Public/Send-CIPPCustomTestAlert.ps1 b/Modules/CIPPCore/Public/Send-CIPPCustomTestAlert.ps1 index 172fc50111403..07ef814787cb9 100644 --- a/Modules/CIPPCore/Public/Send-CIPPCustomTestAlert.ps1 +++ b/Modules/CIPPCore/Public/Send-CIPPCustomTestAlert.ps1 @@ -59,8 +59,10 @@ function Send-CIPPCustomTestAlert { # Email — Send-CIPPAlert no-ops if no notification email is configured. $null = Send-CIPPAlert -Type 'email' -Title $Title -HTMLContent $Template.htmlcontent -TenantFilter $TenantFilter -APIName 'CustomTests' - # PSA — Send-CIPPAlert no-ops unless config.sendtoIntegration is set. - $null = Send-CIPPAlert -Type 'psa' -Title $Title -HTMLContent $Template.htmlcontent -TenantFilter $TenantFilter -APIName 'CustomTests' + # Gate here so Send-CIPPAlert's skip warning only fires for deliveries someone asked for. + if ($Config.sendtoIntegration) { + $null = Send-CIPPAlert -Type 'psa' -Title $Title -HTMLContent $Template.htmlcontent -TenantFilter $TenantFilter -APIName 'CustomTests' + } # Webhook — hand-built payload, Send-CIPPAlert no-ops if no webhook is configured. $WebhookData = [PSCustomObject]@{ diff --git a/Modules/CIPPCore/Public/Send-CIPPScheduledTaskAlert.ps1 b/Modules/CIPPCore/Public/Send-CIPPScheduledTaskAlert.ps1 index 029e99ce54c0f..a5c29324aa3b5 100644 --- a/Modules/CIPPCore/Public/Send-CIPPScheduledTaskAlert.ps1 +++ b/Modules/CIPPCore/Public/Send-CIPPScheduledTaskAlert.ps1 @@ -126,6 +126,9 @@ function Send-CIPPScheduledTaskAlert { } } + # One outcome per delivery attempt (Channel, Result), returned so the caller can keep it with the task. + $Outcomes = [System.Collections.Generic.List[object]]::new() + try { Write-Information "Sending post-execution alerts for task $($TaskInfo.Name)" @@ -149,13 +152,45 @@ function Send-CIPPScheduledTaskAlert { $EncodedTaskName = [System.Web.HttpUtility]::HtmlEncode($TaskInfo.Name) $EncodedTenantName = [System.Web.HttpUtility]::HtmlEncode($TenantFilter) $AlertHeader = "

$EncodedTaskName

Tenant: $EncodedTenantName

" - $FinalResults = if ($Results -is [array] -and $Results[0] -is [string]) { + # Commands that also serve an HTTP caller return a single row carrying the result lines plus + # the extras that caller needs - New-CIPPUserTask hands back Results alongside Username, + # Password, CopyFrom and the whole Graph user object. Rendered as one row that becomes a + # column per key, so the readable lines end up squeezed beside a flattened Graph object. + # Split it instead: the result lines become the table, the rest follows underneath. Nothing + # is dropped, and $Results itself is untouched so the webhook payload and the stored task + # results keep the exact shape they have always had. + $EnvelopeRow = $null + if (@($Results).Count -eq 1) { + $SingleRow = @($Results)[0] + if ($null -ne $SingleRow -and $SingleRow -isnot [string]) { + $RowProps = @($SingleRow.PSObject.Properties) + if ($RowProps.Count -gt 1 -and $RowProps.Name -contains 'Results') { $EnvelopeRow = $SingleRow } + } + } + + $FinalResults = if ($EnvelopeRow) { + @($EnvelopeRow.Results) | ConvertTo-Html -Fragment -Property @{ l = 'Results'; e = { $_ } } + } elseif ($Results -is [array] -and $Results[0] -is [string]) { $Results | ConvertTo-Html -Fragment -Property @{ l = 'Text'; e = { $_ } } } else { $Results | ForEach-Object { ConvertTo-AlertDisplayRow -Row $_ } | ConvertTo-Html -Fragment } $HTML = $FinalResults -replace '\[\[BR\]\]', '
' -replace '
', "$AlertHeader $TableDesign
" | Out-String + # Everything the envelope carried besides the result lines, as field/value rows below the + # table rather than as extra columns beside it. + if ($EnvelopeRow) { + $ExtraRows = foreach ($Prop in $EnvelopeRow.PSObject.Properties) { + if ($Prop.Name -eq 'Results') { continue } + [pscustomobject]@{ Field = $Prop.Name; Value = (Format-AlertCellValue -Value $Prop.Value -Depth 1) } + } + if ($ExtraRows) { + $ExtraHtml = @($ExtraRows) | ConvertTo-Html -Fragment + $ExtraHtml = $ExtraHtml -replace '\[\[BR\]\]', '
' -replace '
', '
' | Out-String + $HTML += "

Additional detail

$ExtraHtml" + } + } + # For alert tasks, add per-row snooze links. The resolved URL is kept in scope so the # per-user PSA split below can build the same block from each user's own rows. $SnoozeCIPPURL = $null @@ -215,6 +250,19 @@ function Send-CIPPScheduledTaskAlert { '*psa*' { $PsaSplitSent = $false $TaskAffectedUser = $null + # Per-task PSA ticket priority (configured on the alert) overrides the global + # HaloPSA.DefaultPriority. Empty on tasks saved before this field existed, in which + # case New-HaloPSATicket falls back to the integration default. Read here rather + # than inside the try so the consolidated fallback path below can use it even when + # the affected-user resolution throws. + $TaskPsaPriority = $TaskInfo.PsaTicketPriority + # A task can name the ticket the work came from, either explicitly (PsaTicketId, set + # from the ticket box on the wizards) or inside its free-text reference. Both travel + # with the alert so a PSA that recognises them can add the result to that ticket + # rather than opening a new one; the extension decides which wins. Every PSA call + # below carries them, so a split task's per-user notes land on the same ticket. + $PsaReference = $TaskInfo.Reference + $PsaTicketId = $TaskInfo.PsaTicketId try { $ExtConfigTable = Get-CIPPTable -TableName Extensionsconfig $ExtConfig = (Get-CIPPAzDataTableEntity @ExtConfigTable).config | ConvertFrom-Json -ErrorAction SilentlyContinue @@ -302,9 +350,10 @@ function Send-CIPPScheduledTaskAlert { if ([string]::IsNullOrWhiteSpace($GroupKey)) { # Rows without a usable user identifier - fall back to the # task-level affected user if one was resolved. - $GroupParams = @{ Type = 'psa'; Title = $title; HTMLContent = $GroupHTML; TenantFilter = $TenantFilter } + $GroupParams = @{ Type = 'psa'; Title = $title; HTMLContent = $GroupHTML; TenantFilter = $TenantFilter; PSAReference = $PsaReference; PSATicketId = $PsaTicketId } if ($TaskAffectedUser) { $GroupParams.AffectedUser = $TaskAffectedUser } - Send-CIPPAlert @GroupParams + if ($TaskPsaPriority) { $GroupParams.PsaTicketPriority = $TaskPsaPriority } + $Outcomes.Add([pscustomobject]@{ Channel = 'PSA'; Result = [string]((Send-CIPPAlert @GroupParams) -join ' ') }) } else { $GroupDisplayName = if ($DisplayField) { $Group.Group[0].$DisplayField } else { $null } $UserLabel = if ($GroupDisplayName) { "$GroupDisplayName ($GroupKey)" } else { $GroupKey } @@ -313,7 +362,9 @@ function Send-CIPPScheduledTaskAlert { UPN = $GroupKey DisplayName = $GroupDisplayName } - Send-CIPPAlert -Type 'psa' -Title $UserTitle -HTMLContent $GroupHTML -TenantFilter $TenantFilter -AffectedUser $AffectedUser + $UserParams = @{ Type = 'psa'; Title = $UserTitle; HTMLContent = $GroupHTML; TenantFilter = $TenantFilter; AffectedUser = $AffectedUser; PSAReference = $PsaReference; PSATicketId = $PsaTicketId } + if ($TaskPsaPriority) { $UserParams.PsaTicketPriority = $TaskPsaPriority } + $Outcomes.Add([pscustomobject]@{ Channel = 'PSA'; Result = [string]((Send-CIPPAlert @UserParams) -join ' ') }) } } $PsaSplitSent = $true @@ -325,12 +376,17 @@ function Send-CIPPScheduledTaskAlert { } if (-not $PsaSplitSent) { - $PsaParams = @{ Type = 'psa'; Title = $title; HTMLContent = (ConvertTo-PSAHtml -Html $HTML); TenantFilter = $TenantFilter } + $PsaParams = @{ Type = 'psa'; Title = $title; HTMLContent = (ConvertTo-PSAHtml -Html $HTML); TenantFilter = $TenantFilter; PSAReference = $PsaReference; PSATicketId = $PsaTicketId } if ($TaskAffectedUser) { $PsaParams.AffectedUser = $TaskAffectedUser } - Send-CIPPAlert @PsaParams + if ($TaskPsaPriority) { $PsaParams.PsaTicketPriority = $TaskPsaPriority } + $Outcomes.Add([pscustomobject]@{ Channel = 'PSA'; Result = [string]((Send-CIPPAlert @PsaParams) -join ' ') }) } } '*email*' { + # Deliberately untouched by PsaTicketId: that field drives the PSA note only. What a + # mail-ingesting PSA threads on is whatever the operator put in Reference, which is + # already carried into the title above - stamping a ticket token onto every subject + # would push CIPP's own convention onto recipients who never asked for it. $EmailParams = @{ Type = 'email' Title = $title @@ -340,7 +396,7 @@ function Send-CIPPScheduledTaskAlert { if ($TaskAttachments) { $EmailParams.Attachments = $TaskAttachments } - Send-CIPPAlert @EmailParams + $Outcomes.Add([pscustomobject]@{ Channel = 'Email'; Result = [string]((Send-CIPPAlert @EmailParams) -join ' ') }) } '*webhook*' { # Build per-item snooze metadata for alert tasks @@ -398,7 +454,7 @@ function Send-CIPPScheduledTaskAlert { if ($SnoozeInfo) { $obj | Add-Member -NotePropertyName 'Snooze' -NotePropertyValue $SnoozeInfo } $obj } - Send-CIPPAlert -Type 'webhook' -Title $title -TenantFilter $TenantFilter -JSONContent $($Webhook | ConvertTo-Json -Depth 20) -APIName 'Scheduled Task Alerts' -SchemaSource $TaskType -InvokingCommand $TaskInfo.Command -UseStandardizedSchema:$UseStandardizedSchema + $Outcomes.Add([pscustomobject]@{ Channel = 'Webhook'; Result = [string]((Send-CIPPAlert -Type 'webhook' -Title $title -TenantFilter $TenantFilter -JSONContent $($Webhook | ConvertTo-Json -Depth 20) -APIName 'Scheduled Task Alerts' -SchemaSource $TaskType -InvokingCommand $TaskInfo.Command -UseStandardizedSchema:$UseStandardizedSchema) -join ' ') }) } } @@ -407,5 +463,7 @@ function Send-CIPPScheduledTaskAlert { } catch { Write-Warning "Failed to send scheduled task alerts: $($_.Exception.Message)" Write-LogMessage -API 'Scheduler_Alerts' -tenant $TenantFilter -message "Failed to send alerts for task $($TaskInfo.Name): $($_.Exception.Message)" -sev Error + $Outcomes.Add([pscustomobject]@{ Channel = 'All'; Result = "Error: $($_.Exception.Message)" }) } + return @($Outcomes) } diff --git a/Modules/CIPPCore/Public/Set-CIPPAuthenticationPolicy.ps1 b/Modules/CIPPCore/Public/Set-CIPPAuthenticationPolicy.ps1 index 7eb6edbd418db..c6229afc715f4 100644 --- a/Modules/CIPPCore/Public/Set-CIPPAuthenticationPolicy.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPAuthenticationPolicy.ps1 @@ -1,7 +1,9 @@ function Set-CIPPAuthenticationPolicy { [CmdletBinding(SupportsShouldProcess = $true)] param( - [Parameter(Mandatory = $true)]$Tenant, + # TenantFilter (not Tenant) so the scheduler treats this as the protected tenant scope; + # the alias keeps existing -Tenant callers working + [Parameter(Mandatory = $true)][Alias('Tenant')]$TenantFilter, [Parameter(Mandatory = $true)][ValidateSet('FIDO2', 'MicrosoftAuthenticator', 'SMS', 'TemporaryAccessPass', 'HardwareOATH', 'softwareOath', 'Voice', 'Email', 'x509Certificate', 'QRCodePin')]$AuthenticationMethodId, [Parameter(Mandatory = $true)][bool]$Enabled, # true = enabled or false = disabled $MicrosoftAuthenticatorSoftwareOathEnabled, @@ -30,11 +32,11 @@ function Set-CIPPAuthenticationPolicy { $State = if ($Enabled) { 'enabled' } else { 'disabled' } # Get current state of the called authentication method and Set state of authentication method to input state try { - $CurrentInfo = New-GraphGetRequest -Uri "https://graph.microsoft.com/beta/policies/authenticationmethodspolicy/authenticationMethodConfigurations/$AuthenticationMethodId" -tenantid $Tenant -AsApp $True + $CurrentInfo = New-GraphGetRequest -Uri "https://graph.microsoft.com/beta/policies/authenticationmethodspolicy/authenticationMethodConfigurations/$AuthenticationMethodId" -tenantid $TenantFilter -AsApp $True $CurrentInfo.state = $State } catch { $ErrorMessage = Get-CippException -Exception $_ - Write-LogMessage -headers $Headers -API $APIName -tenant $Tenant -message "Could not get CurrentInfo for $AuthenticationMethodId. Error:$($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Could not get CurrentInfo for $AuthenticationMethodId. Error:$($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage # Throw rather than return: callers treat any returned string as a successful write, so returning # here made a failed read look like a completed remediation in both the audit log and the API response. throw "Could not get CurrentInfo for $AuthenticationMethodId. Error:$($ErrorMessage.NormalizedError)" @@ -180,7 +182,7 @@ function Set-CIPPAuthenticationPolicy { } } default { - Write-LogMessage -headers $Headers -API $APIName -tenant $Tenant -message "Somehow you hit the default case with an input of $AuthenticationMethodId . You probably made a typo in the input for AuthenticationMethodId. It`'s case sensitive." -sev Error + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Somehow you hit the default case with an input of $AuthenticationMethodId . You probably made a typo in the input for AuthenticationMethodId. It`'s case sensitive." -sev Error throw "Somehow you hit the default case with an input of $AuthenticationMethodId . You probably made a typo in the input for AuthenticationMethodId. It`'s case sensitive." } } @@ -202,14 +204,14 @@ function Set-CIPPAuthenticationPolicy { try { if ($PSCmdlet.ShouldProcess($AuthenticationMethodId, "Set state to $State $OptionalLogMessage")) { # Convert body to JSON and send request - $null = New-GraphPostRequest -tenantid $Tenant -Uri "https://graph.microsoft.com/beta/policies/authenticationmethodspolicy/authenticationMethodConfigurations/$AuthenticationMethodId" -Type PATCH -Body (ConvertTo-Json -InputObject $CurrentInfo -Compress -Depth 10) -ContentType 'application/json' -AsApp $True - Write-LogMessage -headers $Headers -API $APIName -tenant $Tenant -message "Set $AuthenticationMethodId state to $State $OptionalLogMessage" -sev Info + $null = New-GraphPostRequest -tenantid $TenantFilter -Uri "https://graph.microsoft.com/beta/policies/authenticationmethodspolicy/authenticationMethodConfigurations/$AuthenticationMethodId" -Type PATCH -Body (ConvertTo-Json -InputObject $CurrentInfo -Compress -Depth 10) -ContentType 'application/json' -AsApp $True + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Set $AuthenticationMethodId state to $State $OptionalLogMessage" -sev Info } return "Set $AuthenticationMethodId state to $State $OptionalLogMessage" } catch { $ErrorMessage = Get-CippException -Exception $_ - Write-LogMessage -headers $Headers -API $APIName -tenant $Tenant -message "Failed to $State $AuthenticationMethodId Support: $ErrorMessage" -sev Error -LogData $ErrorMessage + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Failed to $State $AuthenticationMethodId Support: $ErrorMessage" -sev Error -LogData $ErrorMessage throw "Failed to $State $AuthenticationMethodId Support. Error: $($ErrorMessage.NormalizedError)" } } diff --git a/Modules/CIPPCore/Public/Set-CIPPDefenderASRPolicy.ps1 b/Modules/CIPPCore/Public/Set-CIPPDefenderASRPolicy.ps1 index 0163793499830..5a67256124a57 100644 --- a/Modules/CIPPCore/Public/Set-CIPPDefenderASRPolicy.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPDefenderASRPolicy.ps1 @@ -87,7 +87,9 @@ function Set-CIPPDefenderASRPolicy { $null = New-GraphPOSTRequest -uri "https://graph.microsoft.com/beta/deviceManagement/configurationPolicies('$($ASRRequest.id)')/assign" -tenantid $TenantFilter -type POST -body $AssignBody Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Assigned policy $($DisplayName) to $($ASR.AssignTo)" -Sev 'Info' } - "$($TenantFilter): Successfully added ASR Settings" + $Result = "$($TenantFilter): Successfully added ASR Settings" + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -Sev 'Info' + $Result } } } diff --git a/Modules/CIPPCore/Public/Set-CIPPDefenderAVPolicy.ps1 b/Modules/CIPPCore/Public/Set-CIPPDefenderAVPolicy.ps1 index df3b6b816440c..780c90a057398 100644 --- a/Modules/CIPPCore/Public/Set-CIPPDefenderAVPolicy.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPDefenderAVPolicy.ps1 @@ -182,6 +182,8 @@ function Set-CIPPDefenderAVPolicy { $null = New-GraphPOSTRequest -uri "https://graph.microsoft.com/beta/deviceManagement/configurationPolicies('$($PolicyRequest.id)')/assign" -tenantid $TenantFilter -type POST -body $AssignBody Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Assigned AV policy to $($PolicySettings.AssignTo)" -Sev 'Info' } - "$($TenantFilter): Successfully set Default AV Policy settings" + $Result = "$($TenantFilter): Successfully set Default AV Policy settings" + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -Sev 'Info' + $Result } } diff --git a/Modules/CIPPCore/Public/Set-CIPPDefenderCompliancePolicy.ps1 b/Modules/CIPPCore/Public/Set-CIPPDefenderCompliancePolicy.ps1 index 5384b63995be1..e01634a87ea1c 100644 --- a/Modules/CIPPCore/Public/Set-CIPPDefenderCompliancePolicy.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPDefenderCompliancePolicy.ps1 @@ -64,9 +64,13 @@ function Set-CIPPDefenderCompliancePolicy { "Defender Intune Configuration already correct and active for $($TenantFilter). Skipping" } elseif ($ConnectorExists) { $null = New-GraphPOSTRequest -uri $ConnectorUri -tenantid $TenantFilter -type PATCH -body $SettingsObj -AsApp $true - "$($TenantFilter): Successfully updated Defender Compliance and Reporting settings." + $Result = "$($TenantFilter): Successfully updated Defender Compliance and Reporting settings." + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -Sev 'Info' + $Result } else { $null = New-GraphPOSTRequest -uri 'https://graph.microsoft.com/beta/deviceManagement/mobileThreatDefenseConnectors/' -tenantid $TenantFilter -type POST -body $SettingsObj -AsApp $true - "$($TenantFilter): Successfully created Defender Compliance and Reporting settings." + $Result = "$($TenantFilter): Successfully created Defender Compliance and Reporting settings." + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -Sev 'Info' + $Result } } diff --git a/Modules/CIPPCore/Public/Set-CIPPDefenderEDRPolicy.ps1 b/Modules/CIPPCore/Public/Set-CIPPDefenderEDRPolicy.ps1 index 511afe6f4ae0d..81296de2ba95f 100644 --- a/Modules/CIPPCore/Public/Set-CIPPDefenderEDRPolicy.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPDefenderEDRPolicy.ps1 @@ -80,7 +80,9 @@ function Set-CIPPDefenderEDRPolicy { $null = New-GraphPOSTRequest -uri "https://graph.microsoft.com/beta/deviceManagement/configurationPolicies('$($EDRRequest.id)')/assign" -tenantid $TenantFilter -type POST -body $AssignBody Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Assigned EDR policy $($DisplayName) to $($EDR.AssignTo)" -Sev 'Info' } - "$($TenantFilter): Successfully added EDR Settings" + $Result = "$($TenantFilter): Successfully added EDR Settings" + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -Sev 'Info' + $Result } } } diff --git a/Modules/CIPPCore/Public/Set-CIPPDefenderExclusionPolicy.ps1 b/Modules/CIPPCore/Public/Set-CIPPDefenderExclusionPolicy.ps1 index b602784d34d07..09f99e9f150cc 100644 --- a/Modules/CIPPCore/Public/Set-CIPPDefenderExclusionPolicy.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPDefenderExclusionPolicy.ps1 @@ -90,7 +90,9 @@ function Set-CIPPDefenderExclusionPolicy { $null = New-GraphPOSTRequest -uri "https://graph.microsoft.com/beta/deviceManagement/configurationPolicies('$($ExclusionRequest.id)')/assign" -tenantid $TenantFilter -type POST -body $AssignBody Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Assigned Exclusion policy to $($ExclusionAssignTo)" -Sev 'Info' } - "$($TenantFilter): Successfully set Default AV Exclusion Policy settings" + $Result = "$($TenantFilter): Successfully set Default AV Exclusion Policy settings" + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -Sev 'Info' + $Result } } } diff --git a/Modules/CIPPCore/Public/Set-CIPPFeatureFlag.ps1 b/Modules/CIPPCore/Public/Set-CIPPFeatureFlag.ps1 index 61a480b828c2a..f6bf1aafccce7 100644 --- a/Modules/CIPPCore/Public/Set-CIPPFeatureFlag.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPFeatureFlag.ps1 @@ -8,6 +8,9 @@ function Set-CIPPFeatureFlag { The ID of the feature flag to update .PARAMETER Enabled The new enabled state for the feature flag (true/false) + .PARAMETER Force + Set the flag even when AllowUserToggle is false. For system-driven flags that are + managed by a specific flow (e.g. the Setup Wizard) rather than the user settings page. .FUNCTIONALITY Internal #> @@ -17,7 +20,9 @@ function Set-CIPPFeatureFlag { [string]$Id, [Parameter(Mandatory = $true)] - [bool]$Enabled + [bool]$Enabled, + + [switch]$Force ) try { @@ -32,8 +37,8 @@ function Set-CIPPFeatureFlag { return $false } - # Check if user toggle is allowed - if (-not $FeatureFlag.AllowUserToggle) { + # -Force bypasses the user-toggle guard for system-managed flags (e.g. set by the Setup Wizard). + if (-not $FeatureFlag.AllowUserToggle -and -not $Force) { Write-Warning "Feature flag '$Id' does not allow user toggling" return $false } diff --git a/Modules/CIPPCore/Public/Set-CIPPIntunePolicy.ps1 b/Modules/CIPPCore/Public/Set-CIPPIntunePolicy.ps1 index e368fe27802b1..22b7abd94fd20 100644 --- a/Modules/CIPPCore/Public/Set-CIPPIntunePolicy.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPIntunePolicy.ps1 @@ -79,14 +79,20 @@ function Set-CIPPIntunePolicy { if ($FuzzyResult.MatchType -eq 'fuzzy') { Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Fuzzy matched policy '$($FuzzyResult.OriginalName)' for template '$DisplayName' (distance=$($FuzzyResult.Distance))" -Sev Info } - $PolicyFile = $PolicyFile | Select-Object * -ExcludeProperty id, createdDateTime, lastModifiedDateTime, version, '@odata.context', targetedMobileApps + $PolicyFile = $PolicyFile | Select-Object * -ExcludeProperty id, createdDateTime, lastModifiedDateTime, version, '@odata.context', targetedMobileApps, targetedMobileAppsDetails $RawJSON = ConvertTo-Json -InputObject $PolicyFile -Depth 20 -Compress $CreateRequest = New-GraphPOSTRequest -uri "https://graph.microsoft.com/beta/$PlatformType/$TemplateTypeURL/$($ExistingID.Id)" -tenantid $TenantFilter -type PATCH -body $RawJSON -AddedHeaders $ApprovalHeaders Write-LogMessage -headers $Headers -API $APIName -tenant $($TenantFilter) -message "Updated policy $($DisplayName) to template defaults" -Sev Info $CreateRequest = $FuzzyResult.Policy } else { $PostType = 'added' - $PolicyFile = $PolicyFile | Select-Object * -ExcludeProperty id, createdDateTime, lastModifiedDateTime, version, '@odata.context' + # The template's targetedMobileApps are ids from the tenant it was captured in. + # Resolve them to this tenant's apps (or fail with the app named) before creating. + $ResolvedApps = @(Resolve-CIPPIntuneTargetedMobileApps -PolicyFile $PolicyFile -TenantFilter $TenantFilter -Headers $Headers -APIName $APIName) + $PolicyFile = $PolicyFile | Select-Object * -ExcludeProperty id, createdDateTime, lastModifiedDateTime, version, '@odata.context', targetedMobileAppsDetails + if ($ResolvedApps.Count -gt 0 -or $PolicyFile.PSObject.Properties['targetedMobileApps']) { + $PolicyFile | Add-Member -NotePropertyName 'targetedMobileApps' -NotePropertyValue @($ResolvedApps) -Force + } $RawJSON = ConvertTo-Json -InputObject $PolicyFile -Depth 20 -Compress $CreateRequest = New-GraphPOSTRequest -uri "https://graph.microsoft.com/beta/$PlatformType/$TemplateTypeURL" -tenantid $TenantFilter -type POST -body $RawJSON -AddedHeaders $ApprovalHeaders Write-LogMessage -headers $Headers -API $APIName -tenant $($TenantFilter) -message "Added policy $($DisplayName) via template" -Sev Info @@ -103,7 +109,15 @@ function Set-CIPPIntunePolicy { $ComplianceODataType = ($RawJSON | ConvertFrom-Json).'@odata.type' $FuzzyResult = Find-CIPPFuzzyPolicyMatch -DisplayName $DisplayName -ExistingPolicies $CheckExististing -MaxDistance $LevenshteinDistance -ODataType $ComplianceODataType if ($FuzzyResult) { - $RawJSON = ConvertTo-Json -InputObject ($PolicyFile | Select-Object * -ExcludeProperty 'scheduledActionsForRule') -Depth 20 -Compress + $EditPolicy = $PolicyFile | Select-Object * -ExcludeProperty 'scheduledActionsForRule' + # deviceCompliancePolicies is a polymorphic collection with an abstract base type. A PATCH + # carrying derived-type properties (osMinimumVersion, workProfile*, ...) with no @odata.type + # fails Graph model validation. Templates imported or captured without it (RAWJson has no + # @odata.type) hit this, so borrow the concrete type from the matched policy. + if (-not $EditPolicy.'@odata.type' -and $FuzzyResult.Policy.'@odata.type') { + $null = $EditPolicy | Add-Member -MemberType NoteProperty -Name '@odata.type' -Value $FuzzyResult.Policy.'@odata.type' -Force + } + $RawJSON = ConvertTo-Json -InputObject $EditPolicy -Depth 20 -Compress $PostType = 'edited' $ExistingID = $FuzzyResult.Policy if ($FuzzyResult.MatchType -eq 'fuzzy') { diff --git a/Modules/CIPPCore/Public/Set-CIPPNotificationConfig.ps1 b/Modules/CIPPCore/Public/Set-CIPPNotificationConfig.ps1 index 2d28de0649392..b43366c6fd633 100644 --- a/Modules/CIPPCore/Public/Set-CIPPNotificationConfig.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPNotificationConfig.ps1 @@ -16,8 +16,7 @@ function Set-CIPPNotificationConfig { $logsToInclude, $sendtoIntegration, $sev, - [boolean]$UseStandardizedSchema, - $APIName = 'Set Notification Config' + [boolean]$UseStandardizedSchema ) try { diff --git a/Modules/CIPPCore/Public/Set-CIPPPerUserMFA.ps1 b/Modules/CIPPCore/Public/Set-CIPPPerUserMFA.ps1 index e06a75b7b070c..7f1822dcdd765 100644 --- a/Modules/CIPPCore/Public/Set-CIPPPerUserMFA.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPPerUserMFA.ps1 @@ -36,7 +36,7 @@ function Set-CIPPPerUserMFA { try { $int = 0 $Body = @{ - perUserMFAstate = $State + perUserMfaState = $State } $Requests = foreach ($id in $userId) { @{ diff --git a/Modules/CIPPCore/Public/Set-CIPPRegistrationCampaign.ps1 b/Modules/CIPPCore/Public/Set-CIPPRegistrationCampaign.ps1 index 52b7e0e29544f..31397a57cc3ac 100644 --- a/Modules/CIPPCore/Public/Set-CIPPRegistrationCampaign.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPRegistrationCampaign.ps1 @@ -16,7 +16,7 @@ function Set-CIPPRegistrationCampaign { #> [CmdletBinding(SupportsShouldProcess = $true)] param( - [Parameter(Mandatory = $true)]$Tenant, + [Parameter(Mandatory = $true)][Alias('Tenant')]$TenantFilter, $State, $TargetedAuthenticationMethod, $SnoozeDurationInDays, @@ -28,11 +28,11 @@ function Set-CIPPRegistrationCampaign { ) try { - $CurrentPolicy = New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/policies/authenticationMethodsPolicy' -tenantid $Tenant + $CurrentPolicy = New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/policies/authenticationMethodsPolicy' -tenantid $TenantFilter $CurrentCampaign = $CurrentPolicy.registrationEnforcement.authenticationMethodsRegistrationCampaign } catch { $ErrorMessage = Get-CippException -Exception $_ - Write-LogMessage -headers $Headers -API $APIName -tenant $Tenant -message "Could not get the current registration campaign. Error: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Could not get the current registration campaign. Error: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage throw "Could not get the current registration campaign. Error: $($ErrorMessage.NormalizedError)" } @@ -81,13 +81,13 @@ function Set-CIPPRegistrationCampaign { try { $Result = "Set the registration campaign state to $DesiredState targeting $DesiredMethod with a snooze duration of $DesiredSnooze day(s), $($DesiredIncludeTargets.Count) include target(s) and $($DesiredExcludeTargets.Count) exclude target(s)" if ($PSCmdlet.ShouldProcess('Registration campaign', "Set state to $DesiredState")) { - $null = New-GraphPostRequest -tenantid $Tenant -Uri 'https://graph.microsoft.com/beta/policies/authenticationMethodsPolicy' -Type PATCH -Body $Body -ContentType 'application/json' -AsApp $false - Write-LogMessage -headers $Headers -API $APIName -tenant $Tenant -message $Result -sev Info + $null = New-GraphPostRequest -tenantid $TenantFilter -Uri 'https://graph.microsoft.com/beta/policies/authenticationMethodsPolicy' -Type PATCH -Body $Body -ContentType 'application/json' -AsApp $false + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -sev Info } return $Result } catch { $ErrorMessage = Get-CippException -Exception $_ - Write-LogMessage -headers $Headers -API $APIName -tenant $Tenant -message "Failed to update the registration campaign. Error: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Failed to update the registration campaign. Error: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage throw "Failed to update the registration campaign. Error: $($ErrorMessage.NormalizedError)" } } diff --git a/Modules/CIPPCore/Public/Set-CIPPSAMCertificate.ps1 b/Modules/CIPPCore/Public/Set-CIPPSAMCertificate.ps1 index 1fc745e0ca115..9ecf1fba6edf8 100644 --- a/Modules/CIPPCore/Public/Set-CIPPSAMCertificate.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPSAMCertificate.ps1 @@ -40,8 +40,9 @@ function Set-CIPPSAMCertificate { if ($env:AzureWebJobsStorage -eq 'UseDevelopmentStorage=true' -or $env:NonLocalHostAzurite -eq 'true') { $Table = Get-CIPPTable -tablename 'DevSecrets' $Secret = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'Secret' and RowKey eq 'Secret'" + # A certificate-only First Setup registers the certificate before the Secret row exists; create it. if (!$Secret) { - throw 'DevSecrets table row not found. Cannot store SAM certificate in dev mode.' + $Secret = [PSCustomObject]@{ PartitionKey = 'Secret'; RowKey = 'Secret' } } $Secret | Add-Member -MemberType NoteProperty -Name $Name -Value $PfxBase64 -Force Add-AzDataTableEntity @Table -Entity $Secret -Force diff --git a/Modules/CIPPCore/Public/Set-CIPPSPOSite.ps1 b/Modules/CIPPCore/Public/Set-CIPPSPOSite.ps1 index df35ab4fd187e..aef08ce135a80 100644 --- a/Modules/CIPPCore/Public/Set-CIPPSPOSite.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPSPOSite.ps1 @@ -37,12 +37,19 @@ function Set-CIPPSPOSite { [Parameter(Mandatory = $true)] [string]$SiteUrl, [Parameter(Mandatory = $true)] - [hashtable]$Properties + [hashtable]$Properties, + # SharePoint app-only auth requires a certificate (secret app-only is rejected by SPO). When + # set, authenticate app-only with the SAM certificate instead of the delegated context. + [switch]$UseCertificate ) $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter $AdminUrl = $SharePointInfo.AdminUrl + # Threaded onto the ProcessQuery call below; empty = unchanged delegated behaviour. + $AuthSplat = @{} + if ($UseCertificate) { $AuthSplat['AsApp'] = $true; $AuthSplat['UseCertificate'] = $true } + $AllowedTypes = @('Boolean', 'String', 'Int32', 'Int64') # Properties that are CSOM enums; their (numeric) value must be sent as Type="Enum". $EnumProperties = @('SharingCapability', 'DefaultSharingLinkType', 'DefaultLinkPermission', 'SharingDomainRestrictionMode', 'ConditionalAccessPolicy') @@ -75,6 +82,6 @@ function Set-CIPPSPOSite { } if ($PSCmdlet.ShouldProcess($SiteUrl, 'Set Site Properties')) { - New-GraphPostRequest -scope "$AdminUrl/.default" -tenantid $TenantFilter -Uri "$AdminUrl/_vti_bin/client.svc/ProcessQuery" -Type POST -Body $XML -ContentType 'text/xml' -AddedHeaders $AdditionalHeaders + New-GraphPostRequest -scope "$AdminUrl/.default" -tenantid $TenantFilter -Uri "$AdminUrl/_vti_bin/client.svc/ProcessQuery" -Type POST -Body $XML -ContentType 'text/xml' -AddedHeaders $AdditionalHeaders @AuthSplat } } diff --git a/Modules/CIPPCore/Public/Set-CIPPSPOSiteBulk.ps1 b/Modules/CIPPCore/Public/Set-CIPPSPOSiteBulk.ps1 new file mode 100644 index 0000000000000..9544835df633c --- /dev/null +++ b/Modules/CIPPCore/Public/Set-CIPPSPOSiteBulk.ps1 @@ -0,0 +1,128 @@ +function Set-CIPPSPOSiteBulk { + <# + .SYNOPSIS + Set properties on many SharePoint sites concurrently via CSOM + + .DESCRIPTION + Batched counterpart to Set-CIPPSPOSite. SharePoint executes each site's Update serially inside a + single ProcessQuery (and caps a few per request), so batching into one request gives no speedup; + the win is CONCURRENCY. This builds one per-site ProcessQuery (identical shape to Set-CIPPSPOSite) + and hands them all to CIPP.CIPPRestClient.SendConcurrent, which fans them out asynchronously in + .NET (bounded by MaxConcurrency and the SPO admin host's connection-pool cap) with Retry-After / + backoff on 429. The SPO admin token is acquired once and reused across every request. + + Returns one object per site: @{ SiteUrl; Success; Error }. A single site's failure never aborts + the batch. + + .PARAMETER TenantFilter + Tenant to apply settings to + + .PARAMETER Sites + Array of per-site specs, each @{ SiteUrl = ''; Properties = @{ = ; ... } }. + Supported value types match Set-CIPPSPOSite: Boolean, String, Int32, Int64, and the CSOM enum + properties (SharingCapability, DefaultSharingLinkType, DefaultLinkPermission, + SharingDomainRestrictionMode, ConditionalAccessPolicy). + + .PARAMETER MaxConcurrency + Upper bound on in-flight requests (default 5, matching the SPO connection-pool cap in CIPPSharp). + Measured on a 526-site tenant, 5 in flight throttled far less than 8-10 - SharePoint's CSOM-admin + throttle is a sustained-rate limit, so a lower ceiling keeps the sweep under it. + + .PARAMETER UseCertificate + Authenticate app-only with the SAM certificate (SharePoint app-only requires it). + + .FUNCTIONALITY + Internal + #> + [CmdletBinding(SupportsShouldProcess = $true)] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + [Parameter(Mandatory = $true)] + [array]$Sites, + [int]$MaxConcurrency = 5, + [int]$MaxRetries = 3, + [switch]$UseCertificate + ) + + $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter + $AdminUrl = $SharePointInfo.AdminUrl + $RequestUri = "$AdminUrl/_vti_bin/client.svc/ProcessQuery" + + # Acquire the SPO admin token ONCE and reuse it across every concurrent request. + $TokenSplat = @{ tenantid = $TenantFilter; scope = "$AdminUrl/.default" } + if ($UseCertificate) { $TokenSplat['AsApp'] = $true; $TokenSplat['UseCertificate'] = $true } + $Authorization = (Get-GraphToken @TokenSplat).Authorization + + $AllowedTypes = @('Boolean', 'String', 'Int32', 'Int64') + $EnumProperties = @('SharingCapability', 'DefaultSharingLinkType', 'DefaultLinkPermission', 'SharingDomainRestrictionMode', 'ConditionalAccessPolicy') + + $Requests = [System.Collections.Generic.List[CIPP.CIPPConcurrentRequest]]::new() + $RequestSites = [System.Collections.Generic.List[object]]::new() + + foreach ($Site in $Sites) { + if ([string]::IsNullOrWhiteSpace($Site.SiteUrl) -or -not $Site.Properties) { continue } + + $SetProperty = [System.Collections.Generic.List[string]]::new() + $x = 106 + foreach ($Property in $Site.Properties.Keys) { + $Value = $Site.Properties[$Property] + $PropertyType = $Value.GetType().Name + if ($Property -in $EnumProperties) { + $SetProperty.Add("$([int]$Value)") + $x++ + } elseif ($PropertyType -in $AllowedTypes) { + $PropertyToSet = if ($PropertyType -eq 'Boolean') { $Value.ToString().ToLower() } else { [System.Security.SecurityElement]::Escape([string]$Value) } + $SetProperty.Add("$PropertyToSet") + $x++ + } + } + if ($SetProperty.Count -eq 0) { continue } + + $XML = @" +$($SetProperty -join '')$([System.Security.SecurityElement]::Escape($Site.SiteUrl))false +"@ + + $Request = [CIPP.CIPPConcurrentRequest]::new() + $Request.Uri = $RequestUri + $Request.Method = 'POST' + $Request.Body = $XML + $Request.ContentType = 'text/xml' + $Headers = [System.Collections.Generic.Dictionary[string, string]]::new() + $Headers['Authorization'] = $Authorization + $Headers['Accept'] = 'application/json;odata=verbose' + $Request.Headers = $Headers + + $Requests.Add($Request) + $RequestSites.Add($Site) + } + + if ($Requests.Count -eq 0) { return @() } + + if (-not $PSCmdlet.ShouldProcess("$($Requests.Count) sites", 'Set Site Properties (bulk)')) { return @() } + + $Results = [CIPP.CIPPRestClient]::SendConcurrent($Requests, $MaxConcurrency, $MaxRetries) + + @(foreach ($Result in $Results) { + $Site = $RequestSites[$Result.Index] + $ErrorMessage = $null + if ($Result.Error) { + $ErrorMessage = $Result.Error + } elseif ($Result.StatusCode -ne 200) { + $ErrorMessage = "HTTP $($Result.StatusCode): $($Result.Result.Content)" + } else { + # CSOM returns 200 even for per-site failures; the error is in the body's ErrorInfo. + try { + $CsomError = ($Result.Result.Content | ConvertFrom-Json | Where-Object { $_.ErrorInfo } | Select-Object -First 1).ErrorInfo.ErrorMessage + if ($CsomError) { $ErrorMessage = $CsomError } + } catch { + $ErrorMessage = "Could not parse CSOM response: $($_.Exception.Message)" + } + } + [PSCustomObject]@{ + SiteUrl = $Site.SiteUrl + Success = [string]::IsNullOrEmpty($ErrorMessage) + Error = $ErrorMessage + } + }) +} diff --git a/Modules/CIPPCore/Public/Set-CIPPSPOTenant.ps1 b/Modules/CIPPCore/Public/Set-CIPPSPOTenant.ps1 index fe1188e1ca7cf..94ae84b874593 100644 --- a/Modules/CIPPCore/Public/Set-CIPPSPOTenant.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPSPOTenant.ps1 @@ -68,10 +68,19 @@ function Set-CIPPSPOTenant { [string]$SharepointPrefix, [Parameter(ValueFromPipelineByPropertyName = $true, ParameterSetName = 'Properties')] [Parameter(ValueFromPipelineByPropertyName = $true, ParameterSetName = 'Method')] - [string]$SharepointDomain + [string]$SharepointDomain, + # SharePoint app-only auth requires a certificate (secret app-only is rejected by SPO). When + # set, authenticate app-only with the SAM certificate instead of the delegated context. + [Parameter(ParameterSetName = 'Properties')] + [Parameter(ParameterSetName = 'Method')] + [switch]$UseCertificate ) process { + # Threaded onto the ProcessQuery call below; empty = unchanged delegated behaviour. + $AuthSplat = @{} + if ($UseCertificate) { $AuthSplat['AsApp'] = $true; $AuthSplat['UseCertificate'] = $true } + if (!$SharepointPrefix) { # get sharepoint admin site $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter @@ -135,7 +144,7 @@ function Set-CIPPSPOTenant { } if ($PSCmdlet.ShouldProcess($Description, 'Set Tenant Properties')) { - New-GraphPostRequest -scope "$AdminURL/.default" -tenantid $TenantFilter -Uri "$AdminURL/_vti_bin/client.svc/ProcessQuery" -Type POST -Body $XML -ContentType 'text/xml' -AddedHeaders $AdditionalHeaders + New-GraphPostRequest -scope "$AdminURL/.default" -tenantid $TenantFilter -Uri "$AdminURL/_vti_bin/client.svc/ProcessQuery" -Type POST -Body $XML -ContentType 'text/xml' -AddedHeaders $AdditionalHeaders @AuthSplat # Invalidate cached tenant data so subsequent reads reflect the change $Table = Get-CIPPTable -tablename 'cachespotenant' diff --git a/Modules/CIPPCore/Public/Set-CIPPSharePointLibraryCopyOperation.ps1 b/Modules/CIPPCore/Public/Set-CIPPSharePointLibraryCopyOperation.ps1 new file mode 100644 index 0000000000000..19316eab085ed --- /dev/null +++ b/Modules/CIPPCore/Public/Set-CIPPSharePointLibraryCopyOperation.ps1 @@ -0,0 +1,93 @@ +function Set-CIPPSharePointLibraryCopyOperation { + <# + .SYNOPSIS + Persists a SharePointLibraryCopy operation, splitting large handle payloads across rows. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [Parameter(Mandatory = $true)] + [string]$OperationId, + + [Parameter(Mandatory = $true)] + [hashtable]$Entity + ) + + $Table = Get-CIPPTable -TableName 'SharePointLibraryCopy' + + $SafeTenant = $TenantFilter -replace "'", "''" + $SafeOp = $OperationId -replace "'", "''" + $PrimaryExisting = @(Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq '$SafeTenant' and RowKey eq '$SafeOp'") | Select-Object -First 1 + + # Status-only updates must not rewrite CopyJobInfos (avoids delete/recreate races). + $PreserveHandles = -not $Entity.ContainsKey('CopyJobInfos') + if ($PreserveHandles -and $PrimaryExisting) { + $MergeEntity = [ordered]@{ + PartitionKey = $TenantFilter + RowKey = $OperationId + } + foreach ($Key in $Entity.Keys) { + $MergeEntity[$Key] = $Entity[$Key] + } + Add-CIPPAzDataTableEntity @Table -Entity ([hashtable]$MergeEntity) -OperationType UpsertMerge + return + } + + $ChunkRows = @(Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq '$SafeTenant' and startswith(RowKey, '$SafeOp`_')") + $Existing = @($PrimaryExisting) + @($ChunkRows) | Where-Object { $_ } + + foreach ($Row in $Existing) { + Remove-CIPPAzDataTableEntity @Table -Entity $Row -Force -ErrorAction SilentlyContinue + } + + $Table.Force = $true + + $CopyJobInfos = $null + if ($Entity.ContainsKey('CopyJobInfos')) { + $CopyJobInfos = $Entity.CopyJobInfos + $Entity.Remove('CopyJobInfos') | Out-Null + } + + $BaseEntity = [ordered]@{ + PartitionKey = $TenantFilter + } + + foreach ($Key in $Entity.Keys) { + $BaseEntity[$Key] = $Entity[$Key] + } + + if ($null -ne $CopyJobInfos) { + $HandlesJson = ConvertTo-Json -InputObject @($CopyJobInfos) -Depth 8 -Compress + $MaxChunk = 60000 + if ($HandlesJson.Length -le $MaxChunk) { + $BaseEntity.CopyJobInfos = $HandlesJson + $BaseEntity.RowKey = $OperationId + Add-CIPPAzDataTableEntity @Table -Entity ([hashtable]$BaseEntity) + } else { + $ChunkIndex = 0 + for ($i = 0; $i -lt $HandlesJson.Length; $i += $MaxChunk) { + $Len = [Math]::Min($MaxChunk, $HandlesJson.Length - $i) + $Slice = $HandlesJson.Substring($i, $Len) + if ($ChunkIndex -eq 0) { + $PrimaryEntity = [hashtable]$BaseEntity.Clone() + $PrimaryEntity.CopyJobInfos = $Slice + $PrimaryEntity.RowKey = $OperationId + if (-not $PrimaryEntity.Status) { $PrimaryEntity.Status = 'Queued' } + Add-CIPPAzDataTableEntity @Table -Entity $PrimaryEntity + } else { + Add-CIPPAzDataTableEntity @Table -Entity @{ + PartitionKey = $TenantFilter + RowKey = "${OperationId}_$ChunkIndex" + CopyJobInfos = $Slice + } + } + $ChunkIndex++ + } + } + } else { + $BaseEntity.RowKey = $OperationId + Add-CIPPAzDataTableEntity @Table -Entity ([hashtable]$BaseEntity) + } +} diff --git a/Modules/CIPPCore/Public/Set-CIPPSharePointObjectPermission.ps1 b/Modules/CIPPCore/Public/Set-CIPPSharePointObjectPermission.ps1 index 213e6ac713ea4..e4ff59066cf7b 100644 --- a/Modules/CIPPCore/Public/Set-CIPPSharePointObjectPermission.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPSharePointObjectPermission.ps1 @@ -112,10 +112,10 @@ function Set-CIPPSharePointObjectPermission { throw "None of the groups ($($GroupNames -join ', ')) could be found in $TenantFilter by display name." } - $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter - $Scope = "$($SharePointInfo.SharePointUrl)/.default" - $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $Scope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri $TargetLabel = if ($ListId) { "library $ListId" } else { 'site root' } if (-not $PSCmdlet.ShouldProcess($SiteUrl, "Grant $PermissionLevel on $TargetLabel")) { return } diff --git a/Modules/CIPPCore/Public/Set-CIPPStandardsCompareField.ps1 b/Modules/CIPPCore/Public/Set-CIPPStandardsCompareField.ps1 index 2aff76ce9ac19..ca1d31525a234 100644 --- a/Modules/CIPPCore/Public/Set-CIPPStandardsCompareField.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPStandardsCompareField.ps1 @@ -123,10 +123,12 @@ function Set-CIPPStandardsCompareField { if ($ExistingHash.ContainsKey($Field.FieldName)) { $Entity = $ExistingHash[$Field.FieldName] $Entity.Value = $NormalizedValue - $Entity | Add-Member -NotePropertyName TemplateId -NotePropertyValue ([string]$script:CippStandardInfoStorage.Value.StandardTemplateId) -Force - $Entity | Add-Member -NotePropertyName LicenseAvailable -NotePropertyValue ([bool]$Field.LicenseAvailable) -Force - $Entity | Add-Member -NotePropertyName CurrentValue -NotePropertyValue ([string]$Field.CurrentValue) -Force - $Entity | Add-Member -NotePropertyName ExpectedValue -NotePropertyValue ([string]$Field.ExpectedValue) -Force + $Entity | Add-Member -NotePropertyMembers ([ordered]@{ + TemplateId = ([string]$script:CippStandardInfoStorage.Value.StandardTemplateId) + LicenseAvailable = ([bool]$Field.LicenseAvailable) + CurrentValue = ([string]$Field.CurrentValue) + ExpectedValue = ([string]$Field.ExpectedValue) + }) -Force } else { $Entity = [PSCustomObject]@{ PartitionKey = [string]$TenantName.defaultDomainName diff --git a/Modules/CIPPCore/Public/Standards/Get-CIPPStandards.ps1 b/Modules/CIPPCore/Public/Standards/Get-CIPPStandards.ps1 index 1cdafbdaff969..1a08d78164a8b 100644 --- a/Modules/CIPPCore/Public/Standards/Get-CIPPStandards.ps1 +++ b/Modules/CIPPCore/Public/Standards/Get-CIPPStandards.ps1 @@ -73,11 +73,13 @@ function Get-CIPPStandards { $TemplateLabel = if ($TemplateJSON.displayName) { $TemplateJSON.displayName } else { "$($TemplateItem.RowKey)" } $NewItem = $Item.PSObject.Copy() $NewItem.PSObject.Properties.Remove('TemplateList-Tags') - $NewItem | Add-Member -NotePropertyName TemplateList -NotePropertyValue ([pscustomobject]@{ - label = $TemplateLabel - value = "$($TemplateItem.RowKey)" + $NewItem | Add-Member -NotePropertyMembers ([ordered]@{ + TemplateList = ([pscustomobject]@{ + label = $TemplateLabel + value = "$($TemplateItem.RowKey)" + }) + TemplateId = $Template.GUID }) -Force - $NewItem | Add-Member -NotePropertyName TemplateId -NotePropertyValue $Template.GUID -Force $NewItem } } else { @@ -105,11 +107,13 @@ function Get-CIPPStandards { $TemplateLabel = if ($TemplateJSON.displayName) { $TemplateJSON.displayName } else { "$($TemplateItem.RowKey)" } $NewItem = $StandardValue.PSObject.Copy() $NewItem.PSObject.Properties.Remove('TemplateList-Tags') - $NewItem | Add-Member -NotePropertyName TemplateList -NotePropertyValue ([pscustomobject]@{ - label = $TemplateLabel - value = "$($TemplateItem.RowKey)" + $NewItem | Add-Member -NotePropertyMembers ([ordered]@{ + TemplateList = ([pscustomobject]@{ + label = $TemplateLabel + value = "$($TemplateItem.RowKey)" + }) + TemplateId = $Template.GUID }) -Force - $NewItem | Add-Member -NotePropertyName TemplateId -NotePropertyValue $Template.GUID -Force $NewItem } $ExpandedStandards[$StandardName] = $NewArray diff --git a/Modules/CIPPCore/Public/Standards/Get-CIPPStandardsTemplateScope.ps1 b/Modules/CIPPCore/Public/Standards/Get-CIPPStandardsTemplateScope.ps1 new file mode 100644 index 0000000000000..6a56bd9118966 --- /dev/null +++ b/Modules/CIPPCore/Public/Standards/Get-CIPPStandardsTemplateScope.ps1 @@ -0,0 +1,74 @@ +function Get-CIPPStandardsTemplateScope { + <# + .SYNOPSIS + Resolves what a standards template covers, straight from its stored definition. + .DESCRIPTION + Get-CIPPStandards only emits the template that won the three-tier merge for each standard, so a + report row written by a tenant-specific template still belongs to an AllTenants template that + carries the same standard. This reads the selected template's own definition and returns the + standard keys, Intune/CA template ids (package members included), quarantine policy names and + reusable settings template ids it references, in the shapes the CippStandardsReports RowKeys use. + .PARAMETER TemplateId + RowKey of the StandardsTemplateV2 row. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TemplateId + ) + + $Scope = [PSCustomObject]@{ + StandardKeys = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + TemplateGuids = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + QuarantineNames = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + } + + $TemplatesTable = Get-CIPPTable -TableName 'templates' + $SafeTemplateId = ConvertTo-CIPPODataFilterValue -Value $TemplateId -Type String + $SelectedTemplate = Get-CIPPAzDataTableEntity @TemplatesTable -Filter "PartitionKey eq 'StandardsTemplateV2' and RowKey eq '$SafeTemplateId'" + $SelectedStandards = try { ($SelectedTemplate.JSON | ConvertFrom-Json -Depth 100 -ErrorAction Stop).standards } catch { $null } + if ($null -eq $SelectedStandards) { return $Scope } + + $PackageRows = @{} + foreach ($Property in @($SelectedStandards.PSObject.Properties)) { + $StandardName = $Property.Name + $Config = $Property.Value + switch ($StandardName) { + { $_ -in @('IntuneTemplate', 'ConditionalAccessTemplate') } { + $Partition = if ($_ -eq 'IntuneTemplate') { 'IntuneTemplate' } else { 'CATemplate' } + foreach ($Item in @($Config)) { + if ($Item.TemplateList.value) { $null = $Scope.TemplateGuids.Add([string]$Item.TemplateList.value) } + foreach ($Tag in @($Item.'TemplateList-Tags')) { + $TagValue = if ($Tag.value) { [string]$Tag.value } else { [string]$Tag } + if (-not $TagValue) { continue } + if (-not $PackageRows.ContainsKey($Partition)) { + $PackageRows[$Partition] = @(Get-CIPPAzDataTableEntity @TemplatesTable -Filter "PartitionKey eq '$Partition'" | Where-Object { $_.Package }) + } + foreach ($Row in ($PackageRows[$Partition] | Where-Object { $_.Package -eq $TagValue })) { + $null = $Scope.TemplateGuids.Add([string]$Row.RowKey) + } + } + } + } + 'QuarantineTemplate' { + foreach ($Item in @($Config)) { + $DisplayName = $Item.displayName.value ?? $Item.displayName + if ($DisplayName) { $null = $Scope.QuarantineNames.Add([string]$DisplayName) } + } + } + 'ReusableSettingsTemplate' { + foreach ($Item in @($Config)) { + foreach ($Ref in @($Item.TemplateList)) { + $Id = if ($Ref.value) { [string]$Ref.value } else { [string]$Ref } + if ($Id) { $null = $Scope.StandardKeys.Add("standards.ReusableSettingsTemplate.$Id") } + } + } + } + default { + $null = $Scope.StandardKeys.Add("standards.$StandardName") + } + } + } + + return $Scope +} diff --git a/Modules/CIPPCore/Public/Start-CIPPSharePointLibraryCopy.ps1 b/Modules/CIPPCore/Public/Start-CIPPSharePointLibraryCopy.ps1 new file mode 100644 index 0000000000000..e1518bd51de92 --- /dev/null +++ b/Modules/CIPPCore/Public/Start-CIPPSharePointLibraryCopy.ps1 @@ -0,0 +1,159 @@ +function Start-CIPPSharePointLibraryCopy { + <# + .SYNOPSIS + Preflights or starts a SharePoint library-to-library copy operation. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [ValidateSet('PreflightLibraryCopy', 'StartLibraryCopy')] + [string]$Mode, + + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [Parameter(Mandatory = $true)] + [string]$SourceSiteId, + + [string]$SourceSiteUrl, + [Parameter(Mandatory = $true)] + [string]$SourceListId, + [string]$SourceSiteName, + [string]$SourceLibraryName, + + [Parameter(Mandatory = $true)] + [string]$DestSiteId, + + [string]$DestSiteUrl, + [Parameter(Mandatory = $true)] + [string]$DestListId, + [string]$DestSiteName, + [string]$DestLibraryName, + + [int]$NameConflictBehavior = 1, + [string]$StartedBy, + $Headers, + $APIName = 'SharePoint Library Copy' + ) + + $ResolveLibraryMeta = { + param([string]$SiteId, [string]$SiteUrl, [string]$ListId) + if ([string]::IsNullOrWhiteSpace($SiteId)) { + if ([string]::IsNullOrWhiteSpace($SiteUrl)) { + throw 'SourceSiteId or SourceSiteUrl is required.' + } + $ParsedUrl = [System.Uri]$SiteUrl + $SiteSegment = if ($ParsedUrl.AbsolutePath -in @('', '/')) { + $ParsedUrl.Host + } else { + "$($ParsedUrl.Host):$($ParsedUrl.AbsolutePath):" + } + $SiteMeta = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/sites/$SiteSegment`?`$select=id,webUrl,displayName" -tenantid $TenantFilter -asapp $true + $SiteId = $SiteMeta.id + $SiteUrl = $SiteMeta.webUrl + } else { + $SiteMeta = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/sites/$SiteId`?`$select=id,webUrl,displayName" -tenantid $TenantFilter -asapp $true + if (-not $SiteUrl) { $SiteUrl = $SiteMeta.webUrl } + } + $List = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/sites/$SiteId/lists/$ListId`?`$select=id,displayName,name,list" -tenantid $TenantFilter -asapp $true + [PSCustomObject]@{ + SiteId = $SiteId + SiteUrl = $SiteUrl + SiteDisplayName = $SiteMeta.displayName + ListId = $List.id + Title = $List.displayName + Name = $List.name + Template = $List.list.template + } + } + + $SourceMeta = & $ResolveLibraryMeta -SiteId $SourceSiteId -SiteUrl $SourceSiteUrl -ListId $SourceListId + $DestMeta = & $ResolveLibraryMeta -SiteId $DestSiteId -SiteUrl $DestSiteUrl -ListId $DestListId + + foreach ($Meta in @($SourceMeta, $DestMeta)) { + $Eligible = Test-CIPPSharePointLibraryCopyEligible -Template $Meta.Template -Title $Meta.Title -Name $Meta.Name + if (-not $Eligible.Eligible) { + throw $Eligible.Reason + } + } + + if ($SourceMeta.SiteId -eq $DestMeta.SiteId -and $SourceMeta.ListId -eq $DestMeta.ListId) { + throw 'Source and destination library must be different.' + } + + $Enumerate = Get-CIPPSharePointLibraryRootChildUris -TenantFilter $TenantFilter -SiteId $SourceMeta.SiteId ` + -SiteUrl $SourceMeta.SiteUrl -ListId $SourceMeta.ListId + + $Count = $Enumerate.EligibleRootCount + if ($Count -eq 0) { + throw 'Source library has no eligible content to copy.' + } + if ($Count -gt 1000) { + throw "Source library has $Count eligible root items (limit 1,000). Group files into folders and try again." + } + + $WarnLevel = 'none' + if ($Count -gt 200) { $WarnLevel = 'strong' } + elseif ($Count -gt 50) { $WarnLevel = 'soft' } + + if ($Mode -eq 'PreflightLibraryCopy') { + return [PSCustomObject]@{ + EligibleRootCount = $Count + WarnLevel = $WarnLevel + Message = "Estimated SharePoint jobs: $Count." + } + } + + $SourceRoot = Resolve-CIPPSharePointLibraryRootUri -TenantFilter $TenantFilter -SiteUrl $SourceMeta.SiteUrl ` + -SiteId $SourceMeta.SiteId -ListId $SourceMeta.ListId + $DestRoot = Resolve-CIPPSharePointLibraryRootUri -TenantFilter $TenantFilter -SiteUrl $DestMeta.SiteUrl ` + -SiteId $DestMeta.SiteId -ListId $DestMeta.ListId + + $SameWeb = $SourceMeta.SiteId -eq $DestMeta.SiteId + $CopyJobs = Invoke-CIPPSharePointCreateCopyJobs -TenantFilter $TenantFilter -SourceSiteUrl $SourceRoot.SiteUrl ` + -ExportObjectUris $Enumerate.ChildUris -DestinationUri $DestRoot.LibraryRootUri ` + -NameConflictBehavior $NameConflictBehavior -SameWebCopyMoveOptimization $SameWeb + + $OperationId = (New-Guid).Guid + $Expiry = ([DateTime]::UtcNow.AddDays(7)).ToString('o') + $SrcSiteName = if ($SourceSiteName) { $SourceSiteName } else { $SourceMeta.SiteDisplayName ?? 'Source site' } + $SrcLibName = if ($SourceLibraryName) { $SourceLibraryName } else { $SourceMeta.Title } + $DstSiteName = if ($DestSiteName) { $DestSiteName } else { $DestMeta.SiteDisplayName ?? 'Destination site' } + $DstLibName = if ($DestLibraryName) { $DestLibraryName } else { $DestMeta.Title } + + $HandleStates = @($CopyJobs | ForEach-Object { + [PSCustomObject]@{ Status = 'Queued'; IsComplete = $false } + }) + + Set-CIPPSharePointLibraryCopyOperation -TenantFilter $TenantFilter -OperationId $OperationId -Entity @{ + SourceSiteUrl = $SourceRoot.SiteUrl + SourceSiteName = $SrcSiteName + SourceLibraryName = $SrcLibName + DestSiteName = $DstSiteName + DestLibraryName = $DstLibName + StartedBy = $StartedBy + Status = 'Processing' + JobHandleCount = $CopyJobs.Count + Expiry = $Expiry + CopyJobInfos = @($CopyJobs) + HandleStates = (ConvertTo-Json -InputObject @($HandleStates) -Compress -Depth 4) + SanitizedSnapshot = (ConvertTo-Json -InputObject @{ + OperationId = $OperationId + Status = 'Processing' + JobsComplete = 0 + JobsTotal = $CopyJobs.Count + TotalErrors = 0 + TotalWarnings = 0 + Message = 'Copy queued.' + } -Compress) + } + + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter ` + -message "Started library copy $OperationId ($SrcLibName -> $DstLibName, $($CopyJobs.Count) jobs)" -sev Info + + [PSCustomObject]@{ + OperationId = $OperationId + JobHandleCount = $CopyJobs.Count + Message = 'Library copy started.' + } +} diff --git a/Modules/CIPPCore/Public/Test-CIPPGDAPGroupMappings.ps1 b/Modules/CIPPCore/Public/Test-CIPPGDAPGroupMappings.ps1 index e3f7b357491e6..d1c1d1b684b12 100644 --- a/Modules/CIPPCore/Public/Test-CIPPGDAPGroupMappings.ps1 +++ b/Modules/CIPPCore/Public/Test-CIPPGDAPGroupMappings.ps1 @@ -186,6 +186,7 @@ function Test-CIPPGDAPGroupMappings { roleDefinitionId = [string]$Mapping.roleDefinitionId } -Force } + Write-LogMessage -headers $Headers -API $APIName -message "Wrote back $($Corrections.Count) corrected GDAP group mapping(s) to GDAPRoles" -Sev 'Info' } catch { $ErrorMessage = Get-CippException -Exception $_ Write-LogMessage -headers $Headers -API $APIName -message "Failed to write corrected GDAP group mappings to GDAPRoles: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage @@ -197,6 +198,7 @@ function Test-CIPPGDAPGroupMappings { if ($TemplateId) { try { Add-CIPPGDAPRoleTemplate -TemplateId $TemplateId -RoleMappings ($Mappings | Select-Object -Property RoleName, GroupName, GroupId, roleDefinitionId) -Overwrite + Write-LogMessage -headers $Headers -API $APIName -message "Wrote corrected GDAP group mappings to template '$TemplateId'" -Sev 'Info' } catch { $ErrorMessage = Get-CippException -Exception $_ Write-LogMessage -headers $Headers -API $APIName -message "Failed to write corrected GDAP group mappings to template '$TemplateId': $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage @@ -209,6 +211,7 @@ function Test-CIPPGDAPGroupMappings { if ($Invite) { $Invite.RoleMappings = [string](@($Mappings | Select-Object -Property RoleName, GroupName, GroupId, roleDefinitionId) | ConvertTo-Json -Depth 10 -Compress) Add-CIPPAzDataTableEntity @InviteTable -Entity $Invite -Force + Write-LogMessage -headers $Headers -API $APIName -message "Wrote corrected GDAP group mappings to invite '$InviteRowKey'" -Sev 'Info' } } catch { $ErrorMessage = Get-CippException -Exception $_ diff --git a/Modules/CIPPCore/Public/Test-CIPPOffboardingRequest.ps1 b/Modules/CIPPCore/Public/Test-CIPPOffboardingRequest.ps1 index 0f9b81fa6b275..2fbdf33b1acc5 100644 --- a/Modules/CIPPCore/Public/Test-CIPPOffboardingRequest.ps1 +++ b/Modules/CIPPCore/Public/Test-CIPPOffboardingRequest.ps1 @@ -67,7 +67,7 @@ function Test-CIPPOffboardingRequest { # Keep this list in sync with the conditions in Invoke-CIPPOffboardingJob. $BooleanActions = @( 'ConvertToShared', 'HideFromGAL', 'removeCalendarInvites', 'removePermissions', 'removeCalendarPermissions', - 'RemoveRules', 'RemoveMobile', 'RemoveGroups', 'RemoveLicenses', 'RevokeSessions', 'DisableSignIn', + 'RemoveRules', 'RemoveMobile', 'WipeMobile', 'RemoveGroups', 'RemoveLicenses', 'RevokeSessions', 'DisableSignIn', 'ClearImmutableId', 'ResetPass', 'RemoveMFADevices', 'RemoveTeamsPhoneDID', 'DeleteUser', 'DisableOneDriveSharing', 'disableForwarding' ) diff --git a/Modules/CIPPCore/Public/Test-CIPPSharePointLibraryCopyEligible.ps1 b/Modules/CIPPCore/Public/Test-CIPPSharePointLibraryCopyEligible.ps1 new file mode 100644 index 0000000000000..75a8100e9d4c4 --- /dev/null +++ b/Modules/CIPPCore/Public/Test-CIPPSharePointLibraryCopyEligible.ps1 @@ -0,0 +1,40 @@ +function Test-CIPPSharePointLibraryCopyEligible { + <# + .SYNOPSIS + Returns whether a document library is eligible as source or destination for library copy. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$Template, + + [string]$Title, + [string]$Name + ) + + if ($Template -ne 'documentLibrary') { + return [PSCustomObject]@{ Eligible = $false; Reason = 'Not a document library.' } + } + + $TitleNorm = ([string]$Title).Trim() + $NameNorm = ([string]$Name).Trim() + + $DeniedTitles = @( + 'Form Templates' + 'Style Library' + 'Preservation Hold Library' + 'Site Assets' + 'Site Pages' + ) + foreach ($Denied in $DeniedTitles) { + if ($TitleNorm -eq $Denied) { + return [PSCustomObject]@{ Eligible = $false; Reason = "System library '$Denied' is not eligible." } + } + } + + if ($NameNorm -eq 'SiteAssets') { + return [PSCustomObject]@{ Eligible = $false; Reason = 'Site Assets library is not eligible.' } + } + + return [PSCustomObject]@{ Eligible = $true; Reason = $null } +} diff --git a/Modules/CIPPCore/Public/Tools/Import-CommunityTemplate.ps1 b/Modules/CIPPCore/Public/Tools/Import-CommunityTemplate.ps1 index 0170cdd70aa66..9a76171a1ae7e 100644 --- a/Modules/CIPPCore/Public/Tools/Import-CommunityTemplate.ps1 +++ b/Modules/CIPPCore/Public/Tools/Import-CommunityTemplate.ps1 @@ -150,6 +150,8 @@ function Import-CommunityTemplate { RowKey = if ($Duplicate) { $Duplicate.RowKey } else { $id } Source = $Source } + # Full replace: keep the CIPP-assigned Package. + if ($Duplicate -and $Duplicate.Package) { $entity.Package = $Duplicate.Package } Add-CIPPAzDataTableEntity @Table -Entity $entity -Force break } @@ -222,6 +224,8 @@ function Import-CommunityTemplate { RowKey = if ($Duplicate) { $Duplicate.RowKey } else { $id } Source = $Source } + # Full replace: keep the CIPP-assigned Package. + if ($Duplicate -and $Duplicate.Package) { $entity.Package = $Duplicate.Package } Write-Information "Final entity: $($entity | ConvertTo-Json -Depth 10)" Add-CIPPAzDataTableEntity @Table -Entity $entity -Force @@ -312,10 +316,6 @@ function Import-CommunityTemplate { Source = $Source } - if ($Existing -and $Existing.Package) { - $entity.Package = $Existing.Package - } - if ($Duplicate -and $Duplicate.Package) { $entity.Package = $Duplicate.Package } diff --git a/Modules/CIPPCore/Public/Tools/Push-ExecGenerateReportBuilderReport.ps1 b/Modules/CIPPCore/Public/Tools/Push-ExecGenerateReportBuilderReport.ps1 index ee55408feb75d..6235acfa63c4a 100644 --- a/Modules/CIPPCore/Public/Tools/Push-ExecGenerateReportBuilderReport.ps1 +++ b/Modules/CIPPCore/Public/Tools/Push-ExecGenerateReportBuilderReport.ps1 @@ -42,16 +42,23 @@ function Push-ExecGenerateReportBuilderReport { $ParsedBlocks = @($Blocks) } } elseif ($TemplateGUID) { + # A schedule that references a template by GUID follows the template: blocks, page + # setup and name are read fresh on every run, so edits made to the template after the + # schedule was created are picked up without recreating the schedule. $TemplateTable = Get-CippTable -tablename 'templates' $Template = Get-CIPPAzDataTableEntity @TemplateTable -Filter "PartitionKey eq 'ReportBuilderTemplate' and RowKey eq '$($TemplateGUID)'" - if ($Template -and $Template.JSON) { - $TemplateData = ConvertFrom-Json -InputObject $Template.JSON - $ParsedBlocks = @($TemplateData.Blocks) - # A schedule created before page setup existed passes no Settings, so fall back to - # whatever the template itself was saved with. - if (-not $ParsedSettings -and $TemplateData.Settings) { - $ParsedSettings = $TemplateData.Settings - } + if (-not $Template -or -not $Template.JSON) { + throw "Report template $TemplateGUID was not found. It may have been deleted; recreate the schedule from a saved template." + } + $TemplateData = ConvertFrom-Json -InputObject $Template.JSON + $ParsedBlocks = @($TemplateData.Blocks) + if ($TemplateData.Name) { + $TemplateName = $TemplateData.Name + } + # A schedule created before page setup existed passes no Settings, so fall back to + # whatever the template itself was saved with. + if (-not $ParsedSettings -and $TemplateData.Settings) { + $ParsedSettings = $TemplateData.Settings } } @@ -166,8 +173,10 @@ function Push-ExecGenerateReportBuilderReport { (@($HeaderLine, $SeparatorLine) + $DataLines) -join "`n" } } - $Block | Add-Member -NotePropertyName 'content' -NotePropertyValue $BlockContent -Force - $Block | Add-Member -NotePropertyName 'static' -NotePropertyValue $true -Force + $Block | Add-Member -NotePropertyMembers ([ordered]@{ + content = $BlockContent + static = $true + }) -Force } else { $Block | Add-Member -NotePropertyName 'content' -NotePropertyValue 'No data available for this data source.' -Force } diff --git a/Modules/CIPPCore/Public/Update-CIPPSharePointLibraryCopyStatus.ps1 b/Modules/CIPPCore/Public/Update-CIPPSharePointLibraryCopyStatus.ps1 new file mode 100644 index 0000000000000..cf9e9b93a1645 --- /dev/null +++ b/Modules/CIPPCore/Public/Update-CIPPSharePointLibraryCopyStatus.ps1 @@ -0,0 +1,178 @@ +function Update-CIPPSharePointLibraryCopyStatus { + <# + .SYNOPSIS + Polls unfinished copy job handles and returns a sanitized operation-level status snapshot. + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [Parameter(Mandatory = $true)] + [string]$OperationId + ) + + $CollectIssueMessages = { + param([array]$HandleStates, [ValidateSet('Error', 'Warning')][string]$Kind) + + $Property = if ($Kind -eq 'Error') { 'ErrorMessages' } else { 'WarningMessages' } + $Seen = [System.Collections.Generic.HashSet[string]]::new([StringComparer]::OrdinalIgnoreCase) + $Results = [System.Collections.Generic.List[object]]::new() + + foreach ($State in @($HandleStates)) { + if ($null -eq $State) { continue } + foreach ($Message in @($State.$Property)) { + if ([string]::IsNullOrWhiteSpace($Message)) { continue } + $Text = [string]$Message + if ($Seen.Add($Text)) { + [void]$Results.Add([PSCustomObject]@{ Severity = $Kind; Message = $Text }) + } + } + } + + return @($Results) + } + + $Operation = Get-CIPPSharePointLibraryCopyOperation -TenantFilter $TenantFilter -OperationId $OperationId + if (-not $Operation) { + throw 'Library copy operation not found.' + } + + if ($Operation.Status -in @('Completed', 'CompletedWithErrors', 'Failed') -and $Operation.SanitizedSnapshot) { + $Snapshot = $Operation.SanitizedSnapshot + $Snapshot | Add-Member -NotePropertyName Errors -NotePropertyValue ( + & $CollectIssueMessages -HandleStates $Operation.HandleStates -Kind Error + ) -Force + $Snapshot | Add-Member -NotePropertyName Warnings -NotePropertyValue ( + & $CollectIssueMessages -HandleStates $Operation.HandleStates -Kind Warning + ) -Force + return $Snapshot + } + + $JobsTotal = [Math]::Max([int]$Operation.JobHandleCount, @($Operation.CopyJobInfos).Count) + $HandleStates = @($Operation.HandleStates) + if ($HandleStates.Count -lt $JobsTotal) { + $HandleStates = @(1..$JobsTotal | ForEach-Object { + [PSCustomObject]@{ Status = 'Queued'; IsComplete = $false } + }) + } + + for ($Index = 0; $Index -lt $JobsTotal; $Index++) { + $State = $HandleStates[$Index] + if ($State.IsComplete) { continue } + + try { + $Progress = Get-CIPPSharePointCopyJobProgress -TenantFilter $TenantFilter ` + -SourceSiteUrl $Operation.SourceSiteUrl -CopyJobInfo $Operation.CopyJobInfos[$Index] + $HandleStates[$Index] = [PSCustomObject]@{ + Status = $Progress.Status + IsComplete = $Progress.IsComplete + ObjectsProcessed = $Progress.ObjectsProcessed + TotalExpectedObjects = $Progress.TotalExpectedObjects + FilesCreated = $Progress.FilesCreated + BytesProcessed = $Progress.BytesProcessed + TotalErrors = $Progress.TotalErrors + TotalWarnings = $Progress.TotalWarnings + ErrorMessages = @($Progress.ErrorMessages) + WarningMessages = @($Progress.WarningMessages) + } + } catch { + $Detail = [string]$_.Exception.Message + if ([string]::IsNullOrWhiteSpace($Detail)) { + $Detail = 'Failed to retrieve copy job progress from SharePoint.' + } else { + $Detail = [regex]::Replace($Detail, 'https?://[^\s''"]+', '[url redacted]', 'IgnoreCase') + $Detail = ($Detail -replace '\s{2,}', ' ').Trim() + if ($Detail.Length -gt 280) { + $Detail = $Detail.Substring(0, 280).Trim() + '…' + } + } + $HandleStates[$Index] = [PSCustomObject]@{ + Status = 'Failed' + IsComplete = $true + TotalErrors = 1 + ErrorMessages = @($Detail) + } + } + } + + $JobsComplete = @($HandleStates | Where-Object { $_.IsComplete }).Count + $ObjectsProcessed = ($HandleStates | ForEach-Object { [int64]($_.ObjectsProcessed ?? 0) } | Measure-Object -Sum).Sum + $TotalExpected = ($HandleStates | ForEach-Object { $_.TotalExpectedObjects } | Where-Object { $null -ne $_ } | Measure-Object -Sum).Sum + $FilesCreated = ($HandleStates | ForEach-Object { [int64]($_.FilesCreated ?? 0) } | Measure-Object -Sum).Sum + $BytesProcessed = ($HandleStates | ForEach-Object { [int64]($_.BytesProcessed ?? 0) } | Measure-Object -Sum).Sum + $TotalErrors = ($HandleStates | ForEach-Object { [int64]($_.TotalErrors ?? 0) } | Measure-Object -Sum).Sum + $TotalWarnings = ($HandleStates | ForEach-Object { [int64]($_.TotalWarnings ?? 0) } | Measure-Object -Sum).Sum + + $ProgressPercent = $null + if ($TotalExpected -gt 0) { + $ProgressPercent = [Math]::Round(100.0 * $ObjectsProcessed / $TotalExpected, 1) + } elseif ($JobsTotal -gt 0) { + $ProgressPercent = [Math]::Round(100.0 * $JobsComplete / $JobsTotal, 1) + } + + $AnyFailed = @($HandleStates | Where-Object { $_.Status -eq 'Failed' }).Count -gt 0 + $AllComplete = $JobsComplete -ge $JobsTotal + + $Status = if ($AllComplete -and $TotalErrors -gt 0) { 'CompletedWithErrors' } + elseif ($AllComplete -and -not $AnyFailed) { 'Completed' } + elseif ($AnyFailed -and $AllComplete) { 'CompletedWithErrors' } + elseif ($AnyFailed) { 'Failed' } + else { 'Processing' } + + $Message = switch ($Status) { + 'Completed' { 'Library copy completed.' } + 'CompletedWithErrors' { 'Library copy completed with errors.' } + 'Failed' { 'One or more copy jobs failed.' } + default { 'Copy in progress.' } + } + + $Errors = @(& $CollectIssueMessages -HandleStates $HandleStates -Kind Error) + $Warnings = @(& $CollectIssueMessages -HandleStates $HandleStates -Kind Warning) + if ($TotalErrors -gt 0 -and $Errors.Count -eq 0) { + $Errors = @([PSCustomObject]@{ + Severity = 'Error' + Message = 'SharePoint reported copy errors, but CIPP could not read detailed messages from the job log or queue.' + }) + } + + $Snapshot = [PSCustomObject]@{ + OperationId = $OperationId + Status = $Status + JobsComplete = $JobsComplete + JobsTotal = $JobsTotal + ObjectsProcessed = $ObjectsProcessed + TotalExpectedObjects = if ($TotalExpected -gt 0) { $TotalExpected } else { $null } + ProgressPercent = $ProgressPercent + FilesCreated = $FilesCreated + BytesProcessed = $BytesProcessed + TotalErrors = $TotalErrors + TotalWarnings = $TotalWarnings + Errors = $Errors + Warnings = $Warnings + LastUpdatedUtc = ([DateTime]::UtcNow).ToString('o') + Message = $Message + SourceSiteName = $Operation.SourceSiteName + SourceLibraryName = $Operation.SourceLibraryName + DestSiteName = $Operation.DestSiteName + DestLibraryName = $Operation.DestLibraryName + } + + $Expiry = if ($AllComplete) { ([DateTime]::UtcNow.AddHours(48)).ToString('o') } else { $Operation.Expiry } + + Set-CIPPSharePointLibraryCopyOperation -TenantFilter $TenantFilter -OperationId $OperationId -Entity @{ + SourceSiteUrl = $Operation.SourceSiteUrl + SourceSiteName = $Operation.SourceSiteName + SourceLibraryName = $Operation.SourceLibraryName + DestSiteName = $Operation.DestSiteName + DestLibraryName = $Operation.DestLibraryName + StartedBy = $Operation.StartedBy + Status = $Status + JobHandleCount = $JobsTotal + Expiry = $Expiry + HandleStates = (ConvertTo-Json -InputObject @($HandleStates) -Compress -Depth 6) + SanitizedSnapshot = (ConvertTo-Json -InputObject $Snapshot -Compress -Depth 6) + } + + return $Snapshot +} diff --git a/Modules/CIPPCore/Public/Webhooks/Invoke-CIPPWebhookProcessing.ps1 b/Modules/CIPPCore/Public/Webhooks/Invoke-CIPPWebhookProcessing.ps1 index aaefa7f488a42..f5067a0a840be 100644 --- a/Modules/CIPPCore/Public/Webhooks/Invoke-CIPPWebhookProcessing.ps1 +++ b/Modules/CIPPCore/Public/Webhooks/Invoke-CIPPWebhookProcessing.ps1 @@ -221,6 +221,12 @@ function Invoke-CippWebhookProcessing { if ($AffectedUser) { $CIPPAlert.AffectedUser = $AffectedUser } + # Per-alert priority rides on the record rather than a function parameter, the same + # way CustomSubject does above - this function has a second caller + # (Push-PublicWebhookProcess) that has no alert config to pass. + if ($Data.CIPPPsaTicketPriority) { + $CIPPAlert.PsaTicketPriority = $Data.CIPPPsaTicketPriority + } Send-CIPPAlert @CIPPAlert } 'generateWebhook' { diff --git a/Modules/CIPPCore/Public/Webhooks/Test-CIPPAuditLogRules.ps1 b/Modules/CIPPCore/Public/Webhooks/Test-CIPPAuditLogRules.ps1 index 935ff56ac883a..e9bf9d96dd71a 100644 --- a/Modules/CIPPCore/Public/Webhooks/Test-CIPPAuditLogRules.ps1 +++ b/Modules/CIPPCore/Public/Webhooks/Test-CIPPAuditLogRules.ps1 @@ -244,13 +244,14 @@ function Test-CIPPAuditLogRules { $ExcludedTenants = @(Expand-CIPPTenantGroups -TenantFilter $ExcludedTenants) } [pscustomobject]@{ - Tenants = $Tenants - Excluded = $ExcludedTenants - Conditions = $ConfigEntry.Conditions - Actions = $ConfigEntry.Actions - LogType = $ConfigEntry.Type - AlertComment = $ConfigEntry.AlertComment - CustomSubject = $ConfigEntry.CustomSubject + Tenants = $Tenants + Excluded = $ExcludedTenants + Conditions = $ConfigEntry.Conditions + Actions = $ConfigEntry.Actions + LogType = $ConfigEntry.Type + AlertComment = $ConfigEntry.AlertComment + CustomSubject = $ConfigEntry.CustomSubject + PsaTicketPriority = $ConfigEntry.PsaTicketPriority } } }) @@ -839,13 +840,14 @@ function Test-CIPPAuditLogRules { } [PSCustomObject]@{ - conditions = $conditions - expectedAction = $actions - CIPPClause = $CIPPClause - AlertComment = $Config.AlertComment - CustomSubject = $Config.CustomSubject - HasGeoCondition = $HasGeoCondition - ExcludedUserKeys = $LocationExcludedUserKeys + conditions = $conditions + expectedAction = $actions + CIPPClause = $CIPPClause + AlertComment = $Config.AlertComment + CustomSubject = $Config.CustomSubject + PsaTicketPriority = $Config.PsaTicketPriority + HasGeoCondition = $HasGeoCondition + ExcludedUserKeys = $LocationExcludedUserKeys } } } catch { @@ -904,8 +906,11 @@ function Test-CIPPAuditLogRules { $ReturnedData = foreach ($item in $ReturnedData) { $item.CIPPAction = $clause.expectedAction $item.CIPPClause = $clause.CIPPClause -join ' and ' - $item | Add-Member -NotePropertyName 'CIPPAlertComment' -NotePropertyValue $clause.AlertComment -Force -ErrorAction SilentlyContinue - $item | Add-Member -NotePropertyName 'CIPPCustomSubject' -NotePropertyValue $clause.CustomSubject -Force -ErrorAction SilentlyContinue + $item | Add-Member -NotePropertyMembers ([ordered]@{ + CIPPAlertComment = $clause.AlertComment + CIPPCustomSubject = $clause.CustomSubject + CIPPPsaTicketPriority = $clause.PsaTicketPriority + }) -Force -ErrorAction SilentlyContinue $MatchedRules.Add($clause.CIPPClause -join ' and ') $item } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheActiveUserDetail.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheActiveUserDetail.ps1 new file mode 100644 index 0000000000000..2050891087c92 --- /dev/null +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheActiveUserDetail.ps1 @@ -0,0 +1,38 @@ +function Set-CIPPDBCacheActiveUserDetail { + <# + .SYNOPSIS + Caches the Microsoft 365 active-user detail report for a tenant + + .DESCRIPTION + Stores getOffice365ActiveUserDetail(period='D90') - one row per user carrying per-service + last-activity dates (Exchange, OneDrive, SharePoint, Teams, Yammer) and the products + assigned. Rows are keyed by userPrincipalName so they join to the cached Users dataset. + + Note: when the tenant conceals usage-report names, userPrincipalName is anonymized and the + rows cannot be joined to users. The license optimization report detects this and points to + the Anonymous Reports Disable standard. + + .PARAMETER TenantFilter + The tenant to cache active-user detail for + + .PARAMETER QueueId + The queue ID to update with total tasks (optional) + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + [string]$QueueId + ) + + try { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Caching active user detail' -sev Debug + + New-GraphGetRequest -uri "https://graph.microsoft.com/beta/reports/getOffice365ActiveUserDetail(period='D90')?`$format=application%2fjson" -tenantid $TenantFilter -Stream | + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ActiveUserDetail' -AddCount + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached active user detail successfully' -sev Debug + + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Failed to cache active user detail: $($_.Exception.Message)" -sev Error + } +} diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAppRoleAssignments.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAppRoleAssignments.ps1 index 6db0d82a87690..870f6caf8874e 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAppRoleAssignments.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAppRoleAssignments.ps1 @@ -29,8 +29,10 @@ function Set-CIPPDBCacheAppRoleAssignments { $AppRoleAssignments = $SP.appRoleAssignments foreach ($Assignment in $AppRoleAssignments) { # Enrich with service principal info - $Assignment | Add-Member -NotePropertyName 'servicePrincipalDisplayName' -NotePropertyValue $SP.displayName -Force - $Assignment | Add-Member -NotePropertyName 'servicePrincipalAppId' -NotePropertyValue $SP.appId -Force + $Assignment | Add-Member -NotePropertyMembers ([ordered]@{ + servicePrincipalDisplayName = $SP.displayName + servicePrincipalAppId = $SP.appId + }) -Force $AllAppRoleAssignments.Add($Assignment) } } catch { @@ -41,6 +43,11 @@ function Set-CIPPDBCacheAppRoleAssignments { if ($AllAppRoleAssignments.Count -gt 0) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'AppRoleAssignments' -Data $AllAppRoleAssignments -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($AllAppRoleAssignments.Count) app role assignments" -sev Debug + } else { + # The service principal read succeeded and no assignments exist: write the authoritative + # empty set so the Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'AppRoleAssignments' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 app role assignments (none found)' -sev Debug } $AllAppRoleAssignments = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAuthenticationFlowsPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAuthenticationFlowsPolicy.ps1 index d25be4186873d..476fb63b4c91b 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAuthenticationFlowsPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAuthenticationFlowsPolicy.ps1 @@ -24,6 +24,11 @@ function Set-CIPPDBCacheAuthenticationFlowsPolicy { if ($AuthFlowPolicy) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'AuthenticationFlowsPolicy' -Data @($AuthFlowPolicy) -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached authentication flows policy successfully' -sev Debug + } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'AuthenticationFlowsPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 authentication flows policies (none found)' -sev Debug } } catch { diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAuthenticationMethodsPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAuthenticationMethodsPolicy.ps1 index 3f26788dbc30a..f718d3991229c 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAuthenticationMethodsPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAuthenticationMethodsPolicy.ps1 @@ -34,6 +34,11 @@ function Set-CIPPDBCacheAuthenticationMethodsPolicy { if ($Fido2Configuration) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'Fido2Configuration' -Data @($Fido2Configuration) -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached FIDO2 authentication method configuration successfully' -sev Debug + } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'Fido2Configuration' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 FIDO2 authentication method configurations (none found)' -sev Debug } $Fido2Configuration = $null } catch { diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAutopilotDeploymentProfiles.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAutopilotDeploymentProfiles.ps1 index 2dec2aee679a5..36c9266bf29ba 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAutopilotDeploymentProfiles.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheAutopilotDeploymentProfiles.ps1 @@ -20,6 +20,9 @@ function Set-CIPPDBCacheAutopilotDeploymentProfiles { $TestResult = Test-CIPPStandardLicense -StandardName 'AutopilotDeploymentProfilesCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping Autopilot deployment profiles cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'AutopilotDeploymentProfiles' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheB2BManagementPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheB2BManagementPolicy.ps1 index 36255c5e966de..710768604455d 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheB2BManagementPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheB2BManagementPolicy.ps1 @@ -34,10 +34,12 @@ function Set-CIPPDBCacheB2BManagementPolicy { $DomainPolicy = $ParsedDefinition.B2BManagementPolicy.InvitationsAllowedAndBlockedDomainsPolicy $AllowedDomains = @($DomainPolicy.AllowedDomains) $BlockedDomains = @($DomainPolicy.BlockedDomains) - $Policy | Add-Member -NotePropertyName 'parsedDefinition' -NotePropertyValue $ParsedDefinition -Force - $Policy | Add-Member -NotePropertyName 'allowedDomains' -NotePropertyValue $AllowedDomains -Force - $Policy | Add-Member -NotePropertyName 'blockedDomains' -NotePropertyValue $BlockedDomains -Force - $Policy | Add-Member -NotePropertyName 'hasRestrictions' -NotePropertyValue (($AllowedDomains.Count -gt 0) -or ($BlockedDomains.Count -gt 0)) -Force + $Policy | Add-Member -NotePropertyMembers ([ordered]@{ + parsedDefinition = $ParsedDefinition + allowedDomains = $AllowedDomains + blockedDomains = $BlockedDomains + hasRestrictions = (($AllowedDomains.Count -gt 0) -or ($BlockedDomains.Count -gt 0)) + }) -Force $Policy } @@ -45,7 +47,12 @@ function Set-CIPPDBCacheB2BManagementPolicy { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'B2BManagementPolicy' -Data @($B2BManagementPolicy) -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached B2B management policy successfully' -sev Debug } else { - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'No B2B management policy found' -sev Debug + # The read succeeded and the tenant genuinely has no legacy B2B policy: write the + # authoritative empty set so the Count marker records a completed collection and + # stale rows are cleared, instead of leaving the type indistinguishable from + # "collector never ran". + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'B2BManagementPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'No B2B management policy found - cached authoritative empty set' -sev Debug } } catch { diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheComplianceRetentionPolicies.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheComplianceRetentionPolicies.ps1 index a51e14ccc9bb2..0870d2840796a 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheComplianceRetentionPolicies.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheComplianceRetentionPolicies.ps1 @@ -26,6 +26,9 @@ function Set-CIPPDBCacheComplianceRetentionPolicies { if ($LicenseCheck -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have a Purview/AIP license, skipping retention compliance policies' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ComplianceRetentionPolicies' -Data @() -AddCount -ClearOnEmpty return } @@ -37,6 +40,11 @@ function Set-CIPPDBCacheComplianceRetentionPolicies { if ($Policies) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ComplianceRetentionPolicies' -Data @($Policies) -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $(@($Policies).Count) retention compliance policies" -sev Debug + } else { + # The read succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ComplianceRetentionPolicies' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 retention compliance policies (none found)' -sev Debug } } catch { diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheComplianceRetentionRules.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheComplianceRetentionRules.ps1 index 712ad8a419b30..2261ecbdbfcc6 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheComplianceRetentionRules.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheComplianceRetentionRules.ps1 @@ -26,6 +26,9 @@ function Set-CIPPDBCacheComplianceRetentionRules { if ($LicenseCheck -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have a Purview/AIP license, skipping retention compliance rules' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ComplianceRetentionRules' -Data @() -AddCount -ClearOnEmpty return } @@ -37,6 +40,11 @@ function Set-CIPPDBCacheComplianceRetentionRules { if ($Rules) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ComplianceRetentionRules' -Data @($Rules) -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $(@($Rules).Count) retention compliance rules" -sev Debug + } else { + # The read succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ComplianceRetentionRules' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 retention compliance rules (none found)' -sev Debug } } catch { diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheConditionalAccessPolicies.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheConditionalAccessPolicies.ps1 index b1c9b2bfb455d..9acf4ac8e8cf8 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheConditionalAccessPolicies.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheConditionalAccessPolicies.ps1 @@ -21,6 +21,13 @@ function Set-CIPPDBCacheConditionalAccessPolicies { if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Azure AD Premium license, skipping CA' -sev Debug + # A license skip is still a completed collection: record authoritative empty sets for + # the CA types this collector writes so collect-on-miss does not re-run it forever. + # SecurityDefaults is deliberately NOT emptied here - it applies exactly to tenants + # without Entra Premium and its ungated collector keeps that cache populated. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ConditionalAccessPolicies' -Data @() -AddCount -ClearOnEmpty + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'NamedLocations' -Data @() -AddCount -ClearOnEmpty + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'AuthenticationStrengths' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCopilotAdminSettings.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCopilotAdminSettings.ps1 index ae45e1b064372..be2452b193074 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCopilotAdminSettings.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCopilotAdminSettings.ps1 @@ -21,12 +21,22 @@ function Set-CIPPDBCacheCopilotAdminSettings { # The Copilot admin settings API currently requires delegated auth (no -AsApp) $LimitedMode = New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/copilot/admin/settings/limitedMode' -tenantid $TenantFilter - Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CopilotAdminSettings' -Data @($LimitedMode) -AddCount - $LimitedMode = $null - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Copilot admin settings successfully' -sev Debug + # Only write when the fetch actually returned the settings object. limitedMode always + # exists on a tenant that answers this endpoint, so an empty result means the request + # failed without throwing - writing it anyway would reset the Count marker (and rotate + # out the previous good row) on a transient Graph error. + if ($LimitedMode) { + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CopilotAdminSettings' -Data @($LimitedMode) -AddCount + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Copilot admin settings successfully' -sev Debug + } else { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Copilot admin settings fetch returned no data - leaving the existing cache untouched' -sev Warning + } + $LimitedMode = $null } catch { - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Failed to cache Copilot admin settings: $($_.Exception.Message)" -sev Error + # A transient Graph error must not touch the cache: the last good settings row stays in + # place and the next successful run replaces it. + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Failed to cache Copilot admin settings: $($_.Exception.Message)" -sev Debug } } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCopilotPolicySettings.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCopilotPolicySettings.ps1 index 0bdfae63d3772..a8a7b0f042586 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCopilotPolicySettings.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCopilotPolicySettings.ps1 @@ -39,6 +39,7 @@ function Set-CIPPDBCacheCopilotPolicySettings { # -SkipValueExtraction returns the entity intact. $Values = [ordered]@{} $PolicyIds = [ordered]@{} + $SucceededSettings = 0 foreach ($Key in $SettingMap.Keys) { try { $Current = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/copilot/admin/policySettings/$($SettingMap[$Key])" -tenantid $TenantFilter -SkipValueExtraction @@ -46,12 +47,23 @@ function Set-CIPPDBCacheCopilotPolicySettings { # never turns "0" into a number and stops matching the configured value. $Values[$Key] = if ($null -eq $Current.value) { $null } else { [string]$Current.value } $PolicyIds[$Key] = $Current.policyId + $SucceededSettings++ } catch { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Failed to get Copilot policy setting '$($SettingMap[$Key])': $($_.Exception.Message)" -sev Warning $Values[$Key] = $null $PolicyIds[$Key] = $null } } + + # When EVERY per-setting fetch failed this was a tenant-wide failure (auth, throttling, + # a transient Graph error), not five genuine null values: writing the all-null row would + # replace the previous good row via orphan cleanup. Leave the existing cache untouched + # and let the next successful run refresh it. + if ($SucceededSettings -eq 0) { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'All Copilot policy setting fetches failed - leaving the existing cache untouched' -sev Warning + return + } + $Values['policyIds'] = [PSCustomObject]$PolicyIds Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CopilotPolicySettings' -Data @([PSCustomObject]$Values) -AddCount @@ -61,6 +73,6 @@ function Set-CIPPDBCacheCopilotPolicySettings { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Copilot policy settings successfully' -sev Debug } catch { - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Failed to cache Copilot policy settings: $($_.Exception.Message)" -sev Error + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Failed to cache Copilot policy settings: $($_.Exception.Message)" -sev Debug } } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsExternalAccessPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsExternalAccessPolicy.ps1 index baf9ca9be9e2c..501d0eca33ed4 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsExternalAccessPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsExternalAccessPolicy.ps1 @@ -30,6 +30,11 @@ function Set-CIPPDBCacheCsExternalAccessPolicy { $Data = @($ExternalAccess) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsExternalAccessPolicy' -Data $Data -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Teams External Access Policy' -sev Debug + } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsExternalAccessPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Teams External Access Policies (none found)' -sev Debug } $ExternalAccess = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsAppPermissionPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsAppPermissionPolicy.ps1 index a7e3eda73371a..fd62167d29046 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsAppPermissionPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsAppPermissionPolicy.ps1 @@ -30,6 +30,11 @@ function Set-CIPPDBCacheCsTeamsAppPermissionPolicy { $Data = @($AppPermissionPolicies) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsTeamsAppPermissionPolicy' -Data $Data -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($Data.Count) Teams App Permission Policies" -sev Debug + } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsTeamsAppPermissionPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Teams App Permission Policies (none found)' -sev Debug } $AppPermissionPolicies = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsClientConfiguration.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsClientConfiguration.ps1 index 8e5ef591c4a23..21e59b1ce827b 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsClientConfiguration.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsClientConfiguration.ps1 @@ -31,6 +31,11 @@ function Set-CIPPDBCacheCsTeamsClientConfiguration { $Data = @($ClientConfig) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsTeamsClientConfiguration' -Data $Data -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Teams Client Configuration' -sev Debug + } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsTeamsClientConfiguration' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Teams Client Configurations (none found)' -sev Debug } $ClientConfig = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsMeetingPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsMeetingPolicy.ps1 index 33bdc29669c56..b045dd64f9caa 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsMeetingPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsMeetingPolicy.ps1 @@ -30,6 +30,11 @@ function Set-CIPPDBCacheCsTeamsMeetingPolicy { $Data = @($MeetingPolicy) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsTeamsMeetingPolicy' -Data $Data -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Teams Meeting Policy' -sev Debug + } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsTeamsMeetingPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Teams Meeting Policies (none found)' -sev Debug } $MeetingPolicy = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsMessagingConfiguration.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsMessagingConfiguration.ps1 index bff91cce2f2f6..886848e9d297e 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsMessagingConfiguration.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsMessagingConfiguration.ps1 @@ -31,6 +31,11 @@ function Set-CIPPDBCacheCsTeamsMessagingConfiguration { $Data = @($MessagingConfig) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsTeamsMessagingConfiguration' -Data $Data -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Teams Messaging Configuration' -sev Debug + } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsTeamsMessagingConfiguration' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Teams Messaging Configurations (none found)' -sev Debug } $MessagingConfig = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsMessagingPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsMessagingPolicy.ps1 index a843c6cfa7b52..860b056b5d2fa 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsMessagingPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTeamsMessagingPolicy.ps1 @@ -31,6 +31,11 @@ function Set-CIPPDBCacheCsTeamsMessagingPolicy { $Data = @($MessagingPolicy) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsTeamsMessagingPolicy' -Data $Data -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Teams Messaging Policy' -sev Debug + } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsTeamsMessagingPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Teams Messaging Policies (none found)' -sev Debug } $MessagingPolicy = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTenantFederationConfiguration.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTenantFederationConfiguration.ps1 index a27c559fcaf88..5afb630bdc417 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTenantFederationConfiguration.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheCsTenantFederationConfiguration.ps1 @@ -31,6 +31,11 @@ function Set-CIPPDBCacheCsTenantFederationConfiguration { $Data = @($Federation) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsTenantFederationConfiguration' -Data $Data -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Teams Tenant Federation Configuration' -sev Debug + } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'CsTenantFederationConfiguration' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Teams Tenant Federation Configurations (none found)' -sev Debug } $Federation = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDefenderCVEs.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDefenderCVEs.ps1 index 5434c6c6a2f8b..9a2a1bc8e99b7 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDefenderCVEs.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDefenderCVEs.ps1 @@ -44,22 +44,29 @@ function Set-CIPPDBCacheDefenderCVEs { try { $CveId = $Vuln.cveId + # TVM also returns software-inventory rows with no CVE. Skip them before the + # hashtable lookup: ContainsKey($null) throws, which was caught per-record and + # logged as an 'Allover Build' error for every such row. + if ([string]::IsNullOrWhiteSpace($CveId)) { $SkippedCount++; return } if (-not $CveAggregator.ContainsKey($CveId)) { # Establish global CVE & software properties for this specific tenant $CveAggregator[$CveId] = @{ - cveId = $CveId - customerId = $TenantFilter - softwareVendor = $Vuln.softwareVendor ?? '' - softwareName = $Vuln.softwareName ?? '' - vulnerabilitySeverityLevel = $Vuln.vulnerabilitySeverityLevel ?? '' - recommendedSecurityUpdate = $Vuln.recommendedSecurityUpdate ?? '' - recommendedSecurityUpdateUrl = $Vuln.recommendedSecurityUpdateUrl ?? '' - exploitabilityLevel = $Vuln.exploitabilityLevel ?? '' + cveId = $CveId + customerId = $TenantFilter + softwareVendor = $Vuln.softwareVendor ?? '' + softwareName = $Vuln.softwareName ?? '' + softwareVersion = $Vuln.softwareVersion ?? '' + vulnerabilitySeverityLevel = $Vuln.vulnerabilitySeverityLevel ?? '' + exploitabilityLevel = $Vuln.exploitabilityLevel ?? '' # Device metadata as the JSON text it will be stored as, not as objects. - DeviceJson = [System.Text.StringBuilder]::new() - DeviceCount = 0 + DeviceJson = [System.Text.StringBuilder]::new() + DeviceCount = 0 + # Dedupe devices by id so DeviceCount is a unique-device count and the + # stored list carries each affected device once, however many software + # packages reported the same CVE on it. + SeenDevices = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) } } @@ -78,23 +85,28 @@ function Set-CIPPDBCacheDefenderCVEs { # second copy that used to exist at emit time, where a CVE's whole device List and # the JSON produced from it were both live at once. # - # ConvertTo-Json builds the fragment rather than string interpolation, so escaping - # of device names and registry paths stays correct. - $Fragment = @{ - deviceId = ($Vuln.deviceId -join ',') ?? '' - deviceName = ($Vuln.deviceName -join ',') ?? '' - osVersion = $Vuln.osVersion ?? '' - softwareVersion = ($Vuln.softwareVersion -join ',') ?? '' - diskPaths = if ($Vuln.diskPaths) { $Vuln.diskPaths -join ';' } else { '' } - registryPaths = if ($Vuln.registryPaths) { $Vuln.registryPaths -join ';' } else { '' } - } | ConvertTo-Json -Compress - - # Appended only after the fragment is fully built, so a record that fails - # mid-extraction cannot leave a partial payload attached to the wrong CVE. + # Minimal per-device payload: only the id and name are consumed downstream. + $DeviceId = ($Vuln.deviceId -join ',') ?? '' + $DeviceName = ($Vuln.deviceName -join ',') ?? '' + + # Dedupe on the device id (falling back to the name) so one device that reports + # the same CVE across several software packages is stored and counted once. + $DeviceKey = if ($DeviceId) { $DeviceId } else { $DeviceName } $Bucket = $CveAggregator[$CveId] - if ($Bucket.DeviceCount -gt 0) { [void]$Bucket.DeviceJson.Append(',') } - [void]$Bucket.DeviceJson.Append($Fragment) - $Bucket.DeviceCount++ + if ($DeviceKey -and $Bucket.SeenDevices.Add($DeviceKey)) { + # ConvertTo-Json builds the fragment rather than string interpolation, so + # escaping of device names stays correct. + $Fragment = @{ + deviceId = $DeviceId + deviceName = $DeviceName + } | ConvertTo-Json -Compress + + # Appended only after the fragment is fully built, so a record that fails + # mid-extraction cannot leave a partial payload attached to the wrong CVE. + if ($Bucket.DeviceCount -gt 0) { [void]$Bucket.DeviceJson.Append(',') } + [void]$Bucket.DeviceJson.Append($Fragment) + $Bucket.DeviceCount++ + } } catch { $SkippedCount++ $ErrorMessage = Get-CippException -Exception $_ @@ -155,24 +167,27 @@ function Set-CIPPDBCacheDefenderCVEs { } @{ - PartitionKey = $CveKey - RowKey = $TenantFilter # RowKey becomes just the Tenant, ensuring 1 row per CVE per Tenant - customerId = $TenantFilter - cveId = $CveKey - softwareVendor = $CveData.softwareVendor - softwareName = $CveData.softwareName - vulnerabilitySeverityLevel = $CveData.vulnerabilitySeverityLevel - recommendedSecurityUpdate = $CveData.recommendedSecurityUpdate - recommendedSecurityUpdateUrl = $CveData.recommendedSecurityUpdateUrl - exploitabilityLevel = $CveData.exploitabilityLevel - - # Meta aggregation counts - deviceCount = $CveData.DeviceCount - - # All individual device variations compressed safely inside a single field - deviceDetailsJson = $CompactDeviceJson - - lastUpdated = $LastUpdated + PartitionKey = $CveKey + RowKey = $TenantFilter # blob field only; the table RowKey is derived from 'id' below + # Stable table RowKey: Add-CIPPDbItem derives "$Type-$id", so this makes + # writes idempotent (DefenderCVEs-) instead of a random GUID per + # run - which also stopped every run rewriting the whole tenant's rows. + id = $CveKey + customerId = $TenantFilter + cveId = $CveKey + softwareVendor = $CveData.softwareVendor + softwareName = $CveData.softwareName + softwareVersion = $CveData.softwareVersion + vulnerabilitySeverityLevel = $CveData.vulnerabilitySeverityLevel + exploitabilityLevel = $CveData.exploitabilityLevel + + # Unique affected-device count for this CVE in this tenant. + deviceCount = $CveData.DeviceCount + + # Minimal per-device detail ({deviceId, deviceName}) as one JSON string. + deviceDetailsJson = $CompactDeviceJson + + lastUpdated = $LastUpdated } # The row is built; drop the bucket so its device list is collectable @@ -187,6 +202,10 @@ function Set-CIPPDBCacheDefenderCVEs { } catch { $ErrorMessage = Get-CippException -Exception $_ + if (Test-CIPPCacheCapabilityError -Message $_.Exception.Message) { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Skipping Defender CVE cache - tenant not onboarded to Defender for Endpoint: $($ErrorMessage.NormalizedError)" -sev 'Debug' -LogData $ErrorMessage + return + } Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "CVE Cache Refresh failed: $($ErrorMessage.NormalizedError)" -sev 'Error' -LogData $ErrorMessage throw } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDeviceEnrollmentConfigurations.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDeviceEnrollmentConfigurations.ps1 index fb23fea07a7c2..ffd4054738b88 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDeviceEnrollmentConfigurations.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDeviceEnrollmentConfigurations.ps1 @@ -26,6 +26,9 @@ function Set-CIPPDBCacheDeviceEnrollmentConfigurations { $TestResult = Test-CIPPStandardLicense -StandardName 'DeviceEnrollmentConfigurationsCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping device enrollment configurations cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'DeviceEnrollmentConfigurations' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDeviceRegistrationPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDeviceRegistrationPolicy.ps1 index 876244bae3dc9..24224b44a6312 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDeviceRegistrationPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDeviceRegistrationPolicy.ps1 @@ -24,6 +24,11 @@ function Set-CIPPDBCacheDeviceRegistrationPolicy { if ($DeviceRegistrationPolicy) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'DeviceRegistrationPolicy' -Data @($DeviceRegistrationPolicy) -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached device registration policy successfully' -sev Debug + } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'DeviceRegistrationPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 device registration policies (none found)' -sev Debug } } catch { diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDlpCompliancePolicies.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDlpCompliancePolicies.ps1 index 2186b844e1953..8fe8a6fd58f3a 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDlpCompliancePolicies.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDlpCompliancePolicies.ps1 @@ -27,6 +27,10 @@ function Set-CIPPDBCacheDlpCompliancePolicies { if ($LicenseCheck -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have a Purview/AIP license, skipping DLP compliance policies' -sev Debug + # A license skip is still a completed collection: record authoritative empty sets for + # both types this collector writes so collect-on-miss does not re-run it forever. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'DlpCompliancePolicies' -Data @() -AddCount -ClearOnEmpty + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'DlpComplianceRules' -Data @() -AddCount -ClearOnEmpty return } @@ -40,6 +44,11 @@ function Set-CIPPDBCacheDlpCompliancePolicies { if ($Policies) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'DlpCompliancePolicies' -Data @($Policies) -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $(@($Policies).Count) DLP compliance policies" -sev Debug + } else { + # The read succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'DlpCompliancePolicies' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 DLP compliance policies (none found)' -sev Debug } # Full rule objects: the compare needs the Rule allowlist fields (AdvancedRule, conditions, @@ -49,6 +58,11 @@ function Set-CIPPDBCacheDlpCompliancePolicies { if ($Rules) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'DlpComplianceRules' -Data @($Rules) -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $(@($Rules).Count) DLP compliance rules" -sev Debug + } else { + # The read succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'DlpComplianceRules' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 DLP compliance rules (none found)' -sev Debug } } catch { diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAcceptedDomains.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAcceptedDomains.ps1 index be47cf4c37141..3965d7e22abf9 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAcceptedDomains.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAcceptedDomains.ps1 @@ -24,6 +24,11 @@ function Set-CIPPDBCacheExoAcceptedDomains { if ($AcceptedDomains) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoAcceptedDomains' -Data $AcceptedDomains -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($AcceptedDomains.Count) Accepted Domains" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoAcceptedDomains' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Accepted Domains (none found)' -sev Debug } $AcceptedDomains = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAdminAuditLogConfig.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAdminAuditLogConfig.ps1 index d51a81c26ba25..88f08cdf12185 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAdminAuditLogConfig.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAdminAuditLogConfig.ps1 @@ -26,6 +26,11 @@ function Set-CIPPDBCacheExoAdminAuditLogConfig { $AuditConfigArray = @($AuditConfig) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoAdminAuditLogConfig' -Data $AuditConfigArray -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Exchange Admin Audit Log configuration' -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoAdminAuditLogConfig' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Admin Audit Log configurations (none found)' -sev Debug } $AuditConfig = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAntiPhishPolicies.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAntiPhishPolicies.ps1 index 2e7fa2dbee1bc..8d7d1de93c095 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAntiPhishPolicies.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAntiPhishPolicies.ps1 @@ -24,6 +24,11 @@ function Set-CIPPDBCacheExoAntiPhishPolicies { if ($AntiPhishPolicies) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoAntiPhishPolicies' -Data $AntiPhishPolicies -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($AntiPhishPolicies.Count) Anti-Phishing policies" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoAntiPhishPolicies' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Anti-Phishing policies (none found)' -sev Debug } $AntiPhishPolicies = $null @@ -32,6 +37,11 @@ function Set-CIPPDBCacheExoAntiPhishPolicies { if ($AntiPhishRules) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoAntiPhishRules' -Data $AntiPhishRules -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($AntiPhishRules.Count) Anti-Phishing rules" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoAntiPhishRules' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Anti-Phishing rules (none found)' -sev Debug } $AntiPhishRules = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAtpPolicyForO365.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAtpPolicyForO365.ps1 index b93320868475e..dd39419d63db9 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAtpPolicyForO365.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoAtpPolicyForO365.ps1 @@ -19,14 +19,19 @@ function Set-CIPPDBCacheExoAtpPolicyForO365 { try { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Caching Exchange ATP policies for Office 365' -sev Debug - $AtpPolicies = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-AtpPolicyForO365' - if ($AtpPolicies) { - Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoAtpPolicyForO365' -Data $AtpPolicies -AddCount - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($AtpPolicies.Count) ATP policies for Office 365" -sev Debug - } + # Write unconditionally with -ClearOnEmpty so a successful but empty result records an + # authoritative Count=0 marker. That marker is what lets the CIS test tell "collected, no + # policy" (a real Failed) apart from "never collected" (a Skip) instead of both surfacing + # as "cache not found". + $AtpPolicies = @(New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-AtpPolicyForO365') + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoAtpPolicyForO365' -Data $AtpPolicies -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($AtpPolicies.Count) ATP policies for Office 365" -sev Debug $AtpPolicies = $null } catch { + # Rethrow so the collection runner records a real failure, instead of the producer silently + # reporting success with an empty cache (which surfaced to tests as "cache not found"). Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Failed to cache ATP policy data: $($_.Exception.Message)" -sev Error + throw } } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoDkimSigningConfig.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoDkimSigningConfig.ps1 index a0e3b6b2350a8..358a4d48e9664 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoDkimSigningConfig.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoDkimSigningConfig.ps1 @@ -24,6 +24,11 @@ function Set-CIPPDBCacheExoDkimSigningConfig { if ($DkimConfig) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoDkimSigningConfig' -Data $DkimConfig -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($DkimConfig.Count) DKIM configurations" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoDkimSigningConfig' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 DKIM configurations (none found)' -sev Debug } $DkimConfig = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoDlpSensitiveInfoTypes.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoDlpSensitiveInfoTypes.ps1 index dd640f3440725..98eb5647704f5 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoDlpSensitiveInfoTypes.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoDlpSensitiveInfoTypes.ps1 @@ -7,7 +7,8 @@ function Set-CIPPDBCacheExoDlpSensitiveInfoTypes { Calls Get-DlpSensitiveInformationTypeRulePackage against the Security & Compliance endpoint and writes the raw rule packages (including the ClassificationRuleCollectionXml the SIT drift comparer parses via ConvertTo-CIPPSitComparable) into the CIPP database under Type - 'ExoDlpSensitiveInfoTypes'. + 'ExoDlpSensitiveInfoTypes'. Only custom/tenant-authored rule packages are cached; the + Microsoft built-in catalog is huge, identical across every tenant, and never read from this cache. .PARAMETER TenantFilter The tenant to cache SIT rule packages for @@ -27,6 +28,9 @@ function Set-CIPPDBCacheExoDlpSensitiveInfoTypes { if ($LicenseCheck -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have a Purview/AIP license, skipping sensitive information type rule packages' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoDlpSensitiveInfoTypes' -Data @() -AddCount -ClearOnEmpty return } @@ -34,10 +38,19 @@ function Set-CIPPDBCacheExoDlpSensitiveInfoTypes { $Tenant = Get-Tenants -TenantFilter $TenantFilter | Select-Object -First 1 $RulePackages = New-ExoRequest -TenantId $Tenant.customerId -cmdlet 'Get-DlpSensitiveInformationTypeRulePackage' -Compliance | Select-Object * -ExcludeProperty '*odata*', '*data.type*' + # Drop Microsoft's built-in catalog packages, keeping only custom/tenant-authored ones. Fail-open: + # a package with no Publisher is kept rather than risk losing a real custom pack. + $RulePackages = @($RulePackages | Where-Object { $_.Publisher -notlike 'Microsoft*' }) if ($RulePackages) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoDlpSensitiveInfoTypes' -Data @($RulePackages) -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $(@($RulePackages).Count) sensitive information type rule packages" -sev Debug + } else { + # The read succeeded and no custom rule packages exist (the common case): write the + # authoritative empty set so the Count marker records a completed collection and stale + # rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoDlpSensitiveInfoTypes' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 sensitive information type rule packages (no custom packages found)' -sev Debug } } catch { diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoExternalInOutlook.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoExternalInOutlook.ps1 index 14236ee775a4f..bc5313e9e0c7a 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoExternalInOutlook.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoExternalInOutlook.ps1 @@ -28,6 +28,11 @@ function Set-CIPPDBCacheExoExternalInOutlook { $ExternalInOutlookArray = @($ExternalInOutlook) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoExternalInOutlook' -Data $ExternalInOutlookArray -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Exchange ExternalInOutlook configuration' -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoExternalInOutlook' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 ExternalInOutlook configurations (none found)' -sev Debug } $ExternalInOutlook = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoGlobalQuarantinePolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoGlobalQuarantinePolicy.ps1 index 67617a57577c0..9f67f0e148e19 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoGlobalQuarantinePolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoGlobalQuarantinePolicy.ps1 @@ -26,6 +26,11 @@ function Set-CIPPDBCacheExoGlobalQuarantinePolicy { $GlobalQuarantinePolicyArray = @($GlobalQuarantinePolicy) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoGlobalQuarantinePolicy' -Data $GlobalQuarantinePolicyArray -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Exchange global quarantine policy' -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoGlobalQuarantinePolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 global quarantine policies (none found)' -sev Debug } $GlobalQuarantinePolicy = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedConnectionFilterPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedConnectionFilterPolicy.ps1 index ec9531d11227e..799381f45edc6 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedConnectionFilterPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedConnectionFilterPolicy.ps1 @@ -23,6 +23,11 @@ function Set-CIPPDBCacheExoHostedConnectionFilterPolicy { if ($ConnectionFilterPolicies) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoHostedConnectionFilterPolicy' -Data $ConnectionFilterPolicies -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($ConnectionFilterPolicies.Count) hosted connection filter policies" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoHostedConnectionFilterPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 hosted connection filter policies (none found)' -sev Debug } $ConnectionFilterPolicies = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedContentFilterPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedContentFilterPolicy.ps1 index 958648690c0e1..19087288cbe32 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedContentFilterPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedContentFilterPolicy.ps1 @@ -22,6 +22,11 @@ function Set-CIPPDBCacheExoHostedContentFilterPolicy { if ($HostedContentFilterPolicies) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoHostedContentFilterPolicy' -Data $HostedContentFilterPolicies -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($HostedContentFilterPolicies.Count) Hosted Content Filter policies" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoHostedContentFilterPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Hosted Content Filter policies (none found)' -sev Debug } $HostedContentFilterPolicies = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedContentFilterRule.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedContentFilterRule.ps1 index a0834481eeea7..c93d433d0ef9e 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedContentFilterRule.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedContentFilterRule.ps1 @@ -23,6 +23,11 @@ function Set-CIPPDBCacheExoHostedContentFilterRule { if ($HostedContentFilterRules) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoHostedContentFilterRule' -Data $HostedContentFilterRules -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($HostedContentFilterRules.Count) hosted content filter rules" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoHostedContentFilterRule' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 hosted content filter rules (none found)' -sev Debug } $HostedContentFilterRules = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedOutboundSpamFilterPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedOutboundSpamFilterPolicy.ps1 index 2a53545a2405c..d3fae972d9f84 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedOutboundSpamFilterPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoHostedOutboundSpamFilterPolicy.ps1 @@ -23,6 +23,11 @@ function Set-CIPPDBCacheExoHostedOutboundSpamFilterPolicy { if ($HostedOutboundSpamFilterPolicies) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoHostedOutboundSpamFilterPolicy' -Data $HostedOutboundSpamFilterPolicies -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($HostedOutboundSpamFilterPolicies.Count) Hosted Outbound Spam Filter policies" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoHostedOutboundSpamFilterPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Hosted Outbound Spam Filter policies (none found)' -sev Debug } $HostedOutboundSpamFilterPolicies = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoInboundConnector.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoInboundConnector.ps1 index e4ba018b2bfe2..180edeb121504 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoInboundConnector.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoInboundConnector.ps1 @@ -23,6 +23,11 @@ function Set-CIPPDBCacheExoInboundConnector { if ($InboundConnectors) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoInboundConnector' -Data $InboundConnectors -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($InboundConnectors.Count) inbound connectors" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoInboundConnector' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 inbound connectors (none found)' -sev Debug } $InboundConnectors = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoLabels.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoLabels.ps1 index 93a551ae3fe96..6c647bbe827f2 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoLabels.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoLabels.ps1 @@ -26,7 +26,13 @@ function Set-CIPPDBCacheExoLabels { $LicenseCheck = Test-CIPPStandardLicense -StandardName 'ExoLabelsCache' -TenantFilter $TenantFilter -Preset Compliance -SkipLog if ($LicenseCheck -eq $false) { - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have a Purview/AIP license, skipping compliance labels' -sev Debug + # Warning, not Debug: Test-CIPPStandardLicense also returns $false when the capability + # lookup itself errors, so a wrong gate on a tenant that DOES have Purview must be + # visible in the logs rather than silently parking the standard at No Data. + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Purview/AIP capability check returned '$LicenseCheck' (requires one of RMS_S_PREMIUM, RMS_S_PREMIUM2, MIP_S_CLP1, MIP_S_CLP2) - skipping compliance labels and recording an authoritative empty set" -sev Warning + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoLabels' -Data @() -AddCount -ClearOnEmpty return } @@ -38,6 +44,11 @@ function Set-CIPPDBCacheExoLabels { if ($Labels) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoLabels' -Data @($Labels) -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $(@($Labels).Count) compliance labels" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoLabels' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 compliance labels (none found)' -sev Debug } } catch { diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoMailContacts.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoMailContacts.ps1 index 424f41cf9d54a..feb04b572f59b 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoMailContacts.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoMailContacts.ps1 @@ -8,7 +8,7 @@ function Set-CIPPDBCacheExoMailContacts { baselines. Get-MailContact carries the mail-specific properties (ExternalEmailAddress, MailTip, HiddenFromAddressListsEnabled) while the extended directory properties (FirstName, Company, City, Phone, etc.) only exist on Get-Contact, so both are fetched - in one bulk request and merged per contact. + (each $select-projected to only the stored fields) and merged per contact. ExternalEmailAddress is normalized: the 'SMTP:'/'smtp:' prefix is stripped and the value lowercased, because Exchange re-cases the domain part when it creates a contact @@ -31,17 +31,11 @@ function Set-CIPPDBCacheExoMailContacts { try { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Caching Mail Contacts' -sev Debug - $BulkRequests = @( - @{ CmdletInput = @{ CmdletName = 'Get-MailContact'; Parameters = @{ ResultSize = 'Unlimited' } } } - @{ CmdletInput = @{ CmdletName = 'Get-Contact'; Parameters = @{ ResultSize = 'Unlimited' } } } - ) - $BulkResults = New-ExoBulkRequest -tenantid $TenantFilter -cmdletArray $BulkRequests -useSystemMailbox $true -ReturnWithCommand $true - - # Build lookups from Get-Contact results: primary key ExternalDirectoryObjectId, - # fallback Identity for contacts without a directory object id. + $MailContactResults = @(New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-MailContact' -cmdParams @{ ResultSize = 'Unlimited' } -Select 'Identity,Guid,ExternalDirectoryObjectId,DisplayName,ExternalEmailAddress,MailTip,HiddenFromAddressListsEnabled') + $ContactResults = @(New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-Contact' -cmdParams @{ ResultSize = 'Unlimited' } -Select 'Identity,FirstName,LastName,Company,StateOrProvince,StreetAddress,Phone,WebPage,Title,City,PostalCode,CountryOrRegion,MobilePhone') $ContactByDirectoryId = @{} $ContactByIdentity = @{} - foreach ($Contact in @($BulkResults.'Get-Contact')) { + foreach ($Contact in $ContactResults) { if ($Contact.ExternalDirectoryObjectId) { $ContactByDirectoryId[[string]$Contact.ExternalDirectoryObjectId] = $Contact } @@ -51,7 +45,7 @@ function Set-CIPPDBCacheExoMailContacts { } $MailContacts = [System.Collections.Generic.List[PSObject]]::new() - foreach ($MailContact in @($BulkResults.'Get-MailContact')) { + foreach ($MailContact in $MailContactResults) { $MatchedContact = $null if ($MailContact.ExternalDirectoryObjectId -and $ContactByDirectoryId.ContainsKey([string]$MailContact.ExternalDirectoryObjectId)) { $MatchedContact = $ContactByDirectoryId[[string]$MailContact.ExternalDirectoryObjectId] @@ -85,7 +79,8 @@ function Set-CIPPDBCacheExoMailContacts { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoMailContacts' -Data @($MailContacts) -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($MailContacts.Count) Mail Contacts" -sev Debug - $BulkResults = $null + $MailContactResults = $null + $ContactResults = $null $ContactByDirectoryId = $null $ContactByIdentity = $null $MailContacts = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoMalwareFilterPolicies.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoMalwareFilterPolicies.ps1 index 7d71ab954e5e0..9c7430564252e 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoMalwareFilterPolicies.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoMalwareFilterPolicies.ps1 @@ -24,6 +24,11 @@ function Set-CIPPDBCacheExoMalwareFilterPolicies { if ($MalwarePolicies) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoMalwareFilterPolicies' -Data $MalwarePolicies -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($MalwarePolicies.Count) Malware Filter policies" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoMalwareFilterPolicies' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Malware Filter policies (none found)' -sev Debug } $MalwarePolicies = $null @@ -32,6 +37,11 @@ function Set-CIPPDBCacheExoMalwareFilterPolicies { if ($MalwareRules) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoMalwareFilterRules' -Data $MalwareRules -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($MalwareRules.Count) Malware Filter rules" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoMalwareFilterRules' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Malware Filter rules (none found)' -sev Debug } $MalwareRules = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoOMEConfiguration.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoOMEConfiguration.ps1 index 0d5524c56d747..c9a64520e64b5 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoOMEConfiguration.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoOMEConfiguration.ps1 @@ -24,6 +24,11 @@ function Set-CIPPDBCacheExoOMEConfiguration { $OMEConfigurationArray = @($OMEConfigurations) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoOMEConfiguration' -Data $OMEConfigurationArray -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($OMEConfigurationArray.Count) OME configurations" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoOMEConfiguration' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 OME configurations (none found)' -sev Debug } $OMEConfigurations = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoOrganizationConfig.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoOrganizationConfig.ps1 index c07c203edaef9..036d049a4c457 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoOrganizationConfig.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoOrganizationConfig.ps1 @@ -26,6 +26,11 @@ function Set-CIPPDBCacheExoOrganizationConfig { $OrgConfigArray = @($OrgConfig) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoOrganizationConfig' -Data $OrgConfigArray -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Exchange Organization configuration' -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoOrganizationConfig' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Organization configurations (none found)' -sev Debug } $OrgConfig = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoOutboundConnector.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoOutboundConnector.ps1 index 0253c3d512a5f..7f8dce099e6ba 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoOutboundConnector.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoOutboundConnector.ps1 @@ -23,6 +23,11 @@ function Set-CIPPDBCacheExoOutboundConnector { if ($OutboundConnectors) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoOutboundConnector' -Data $OutboundConnectors -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($OutboundConnectors.Count) outbound connectors" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoOutboundConnector' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 outbound connectors (none found)' -sev Debug } $OutboundConnectors = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoPresetSecurityPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoPresetSecurityPolicy.ps1 index 7930ec943f18e..71ec4f87d7c64 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoPresetSecurityPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoPresetSecurityPolicy.ps1 @@ -22,6 +22,9 @@ function Set-CIPPDBCacheExoPresetSecurityPolicy { $MDOTestResult = Test-CIPPStandardLicense -StandardName 'ExoPresetSecurityPolicy' -TenantFilter $TenantFilter -Preset DefenderForOffice365 -SkipLog if ($MDOTestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Skipping Preset Security Policy cache: tenant lacks Microsoft Defender for Office 365' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoPresetSecurityPolicy' -Data @() -AddCount -ClearOnEmpty return } @@ -40,6 +43,11 @@ function Set-CIPPDBCacheExoPresetSecurityPolicy { if ($AllRules.Count -gt 0) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoPresetSecurityPolicy' -Data $AllRules -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($AllRules.Count) Preset Security Policy rules" -sev Debug + } else { + # Both cmdlets succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoPresetSecurityPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Preset Security Policy rules (none found)' -sev Debug } $EOPRules = $null $ATPRules = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoProtectionAlert.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoProtectionAlert.ps1 index f0cb8cfcf8fc7..fc9d8f736bcfe 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoProtectionAlert.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoProtectionAlert.ps1 @@ -27,6 +27,11 @@ function Set-CIPPDBCacheExoProtectionAlert { if ($ProtectionAlerts) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoProtectionAlert' -Data $ProtectionAlerts -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($ProtectionAlerts.Count) protection alerts" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoProtectionAlert' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 protection alerts (none found)' -sev Debug } $ProtectionAlerts = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoQuarantinePolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoQuarantinePolicy.ps1 index 63cb47149ae29..b648c5315bb22 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoQuarantinePolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoQuarantinePolicy.ps1 @@ -23,6 +23,11 @@ function Set-CIPPDBCacheExoQuarantinePolicy { if ($QuarantinePolicies) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoQuarantinePolicy' -Data $QuarantinePolicies -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($QuarantinePolicies.Count) Quarantine policies" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoQuarantinePolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Quarantine policies (none found)' -sev Debug } $QuarantinePolicies = $null @@ -37,6 +42,11 @@ function Set-CIPPDBCacheExoQuarantinePolicy { if ($GlobalQuarantinePolicy) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoGlobalQuarantinePolicy' -Data $GlobalQuarantinePolicy -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Global Quarantine policy' -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoGlobalQuarantinePolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Global Quarantine policies (none found)' -sev Debug } $GlobalQuarantinePolicy = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoRemoteDomain.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoRemoteDomain.ps1 index dd9fb277b99ab..b1935ff7a19a1 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoRemoteDomain.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoRemoteDomain.ps1 @@ -23,6 +23,11 @@ function Set-CIPPDBCacheExoRemoteDomain { if ($RemoteDomains) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoRemoteDomain' -Data $RemoteDomains -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($RemoteDomains.Count) Remote Domains" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoRemoteDomain' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Remote Domains (none found)' -sev Debug } $RemoteDomains = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoRoleAssignmentPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoRoleAssignmentPolicy.ps1 index 93b57c264e616..271668d0a8ad7 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoRoleAssignmentPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoRoleAssignmentPolicy.ps1 @@ -23,6 +23,11 @@ function Set-CIPPDBCacheExoRoleAssignmentPolicy { if ($RoleAssignmentPolicies) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoRoleAssignmentPolicy' -Data $RoleAssignmentPolicies -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($RoleAssignmentPolicies.Count) role assignment policies" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoRoleAssignmentPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 role assignment policies (none found)' -sev Debug } $RoleAssignmentPolicies = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoSafeAttachmentPolicies.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoSafeAttachmentPolicies.ps1 index 07867a4caff3a..8b318dd4687b6 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoSafeAttachmentPolicies.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoSafeAttachmentPolicies.ps1 @@ -19,23 +19,25 @@ function Set-CIPPDBCacheExoSafeAttachmentPolicies { try { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Caching Exchange Safe Attachment policies and rules' -sev Debug - # Get Safe Attachment policies - $SafeAttachmentPolicies = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-SafeAttachmentPolicy' - if ($SafeAttachmentPolicies) { - Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoSafeAttachmentPolicies' -Data $SafeAttachmentPolicies -AddCount - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($SafeAttachmentPolicies.Count) Safe Attachment policies" -sev Debug - } + # Write unconditionally with -ClearOnEmpty so a successful but empty result records an + # authoritative Count=0 marker. That marker is what lets the CIS tests tell "collected, no + # policies" (a real Failed) apart from "never collected" (a Skip) instead of both surfacing + # as "cache not found". + $SafeAttachmentPolicies = @(New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-SafeAttachmentPolicy') + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoSafeAttachmentPolicies' -Data $SafeAttachmentPolicies -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($SafeAttachmentPolicies.Count) Safe Attachment policies" -sev Debug $SafeAttachmentPolicies = $null # Get Safe Attachment rules - $SafeAttachmentRules = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-SafeAttachmentRule' - if ($SafeAttachmentRules) { - Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoSafeAttachmentRules' -Data $SafeAttachmentRules -AddCount - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($SafeAttachmentRules.Count) Safe Attachment rules" -sev Debug - } + $SafeAttachmentRules = @(New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-SafeAttachmentRule') + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoSafeAttachmentRules' -Data $SafeAttachmentRules -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($SafeAttachmentRules.Count) Safe Attachment rules" -sev Debug $SafeAttachmentRules = $null } catch { + # Rethrow so the collection runner records a real failure, instead of the producer silently + # reporting success with an empty cache (which surfaced to tests as "cache not found"). Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Failed to cache Safe Attachment data: $($_.Exception.Message)" -sev Error + throw } } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoSafeLinksPolicies.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoSafeLinksPolicies.ps1 index 65403b1872684..897e15f5c9451 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoSafeLinksPolicies.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoSafeLinksPolicies.ps1 @@ -16,26 +16,44 @@ function Set-CIPPDBCacheExoSafeLinksPolicies { [string]$QueueId ) + # Safe Links is a Defender for Office 365 feature. On tenants without it Exchange rejects + # Get-SafeLinksPolicy, which surfaced as an Error log for every unlicensed tenant on every + # collection. Skip those tenants and leave the cache untouched, so the tests report the + # collection as not run (Skipped) rather than as a failure. + try { + $Capabilities = Get-CIPPTenantCapabilities -TenantFilter $TenantFilter + $MDOCapabilities = @('ATP_ENTERPRISE', 'ATP_ENTERPRISE_GOV', 'THREAT_INTELLIGENCE', 'THREAT_INTELLIGENCE_GOV') + $HasMDO = @($MDOCapabilities | Where-Object { $Capabilities.$_ -eq $true }).Count -gt 0 + if (-not $HasMDO) { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Skipping the Safe Links cache: this tenant is not licensed for Defender for Office 365' -sev Info + return + } + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Could not determine Defender for Office 365 licensing, attempting the Safe Links cache anyway: $($_.Exception.Message)" -sev Debug + } + try { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Caching Exchange Safe Links policies and rules' -sev Debug - # Get Safe Links policies - $SafeLinksPolicies = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-SafeLinksPolicy' - if ($SafeLinksPolicies) { - Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoSafeLinksPolicies' -Data $SafeLinksPolicies -AddCount - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($SafeLinksPolicies.Count) Safe Links policies" -sev Debug - } + # Write unconditionally with -ClearOnEmpty so a successful but empty result records an + # authoritative Count=0 marker. That marker is what lets the CIS tests tell "collected, no + # policies" (a real Failed) apart from "never collected" (a Skip) instead of both surfacing + # as "cache not found". + $SafeLinksPolicies = @(New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-SafeLinksPolicy') + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoSafeLinksPolicies' -Data $SafeLinksPolicies -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($SafeLinksPolicies.Count) Safe Links policies" -sev Debug $SafeLinksPolicies = $null # Get Safe Links rules - $SafeLinksRules = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-SafeLinksRule' - if ($SafeLinksRules) { - Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoSafeLinksRules' -Data $SafeLinksRules -AddCount - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($SafeLinksRules.Count) Safe Links rules" -sev Debug - } + $SafeLinksRules = @(New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-SafeLinksRule') + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoSafeLinksRules' -Data $SafeLinksRules -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($SafeLinksRules.Count) Safe Links rules" -sev Debug $SafeLinksRules = $null } catch { + # Rethrow so the collection runner records a real failure, instead of the producer silently + # reporting success with an empty cache (which surfaced to tests as "cache not found"). Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Failed to cache Safe Links data: $($_.Exception.Message)" -sev Error + throw } } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoSharingPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoSharingPolicy.ps1 index 368c1dca953ca..cda29daeeadc1 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoSharingPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoSharingPolicy.ps1 @@ -24,6 +24,11 @@ function Set-CIPPDBCacheExoSharingPolicy { if ($SharingPolicies) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoSharingPolicy' -Data $SharingPolicies -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($SharingPolicies.Count) Sharing Policies" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoSharingPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Sharing Policies (none found)' -sev Debug } $SharingPolicies = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoTeamsProtectionPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoTeamsProtectionPolicy.ps1 index 1b32996aa916c..b64142e6f03d4 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoTeamsProtectionPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoTeamsProtectionPolicy.ps1 @@ -24,6 +24,11 @@ function Set-CIPPDBCacheExoTeamsProtectionPolicy { $TeamsProtectionPolicyArray = @($TeamsProtectionPolicies) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoTeamsProtectionPolicy' -Data $TeamsProtectionPolicyArray -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($TeamsProtectionPolicyArray.Count) Teams protection policies" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoTeamsProtectionPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Teams protection policies (none found)' -sev Debug } $TeamsProtectionPolicies = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoTransportConfig.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoTransportConfig.ps1 index f606c288f0203..dfcf10af829f3 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoTransportConfig.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoTransportConfig.ps1 @@ -26,6 +26,11 @@ function Set-CIPPDBCacheExoTransportConfig { $TransportConfigArray = @($TransportConfig) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoTransportConfig' -Data $TransportConfigArray -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Exchange Transport configuration' -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoTransportConfig' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Transport configurations (none found)' -sev Debug } $TransportConfig = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoTransportRules.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoTransportRules.ps1 index a557947d4ce0d..836fffcad4323 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoTransportRules.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheExoTransportRules.ps1 @@ -24,6 +24,11 @@ function Set-CIPPDBCacheExoTransportRules { if ($TransportRules) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoTransportRules' -Data $TransportRules -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($TransportRules.Count) Transport Rules" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ExoTransportRules' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Transport Rules (none found)' -sev Debug } $TransportRules = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheGroupUsage.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheGroupUsage.ps1 new file mode 100644 index 0000000000000..8e16932a26590 --- /dev/null +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheGroupUsage.ps1 @@ -0,0 +1,51 @@ +function Set-CIPPDBCacheGroupUsage { + <# + .SYNOPSIS + Refreshes every reporting DB cache that feeds the group usage report + + .DESCRIPTION + The group usage report is compiled at read time from existing cache types, so this + collector writes no rows of its own — it runs the source collectors sequentially so + a single on-demand sync refreshes all of them. + + .PARAMETER TenantFilter + The tenant to refresh the source caches for + + .PARAMETER QueueId + The queue ID to update with total tasks (optional) + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + [string]$QueueId + ) + + $SourceTypes = @( + 'Groups' + 'ConditionalAccessPolicies' + 'IntunePolicies' + 'IntuneApplications' + 'IntuneAppProtectionPolicies' + 'IntuneScripts' + 'AutopilotDeploymentProfiles' + 'DeviceEnrollmentConfigurations' + 'Roles' + 'RoleAssignmentScheduleInstances' + 'RoleEligibilitySchedules' + 'AppRoleAssignments' + 'LicenseOverview' + 'ExoTransportRules' + ) + + foreach ($SourceType in $SourceTypes) { + $FunctionName = "Set-CIPPDBCache$SourceType" + try { + $Params = @{ TenantFilter = $TenantFilter } + if ($QueueId) { $Params.QueueId = $QueueId } + & $FunctionName @Params + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Group usage sync: failed to refresh $SourceType : $($_.Exception.Message)" -sev Warning + } + } +} diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheGroups.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheGroups.ps1 index b02fcc0d54fc5..857c167953ba0 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheGroups.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheGroups.ps1 @@ -19,49 +19,50 @@ function Set-CIPPDBCacheGroups { try { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Caching groups' -sev Debug + $MemberBatchSize = 50 $GroupSelect = 'id,createdDateTime,displayName,description,mail,mailEnabled,mailNickname,resourceProvisioningOptions,securityEnabled,visibility,organizationId,onPremisesSamAccountName,membershipRule,groupTypes,onPremisesSyncEnabled,assignedLicenses,licenseProcessingState' - $Groups = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/groups?`$top=999&`$select=$GroupSelect&`$expand=owners(`$select=id,displayName,userPrincipalName)" -tenantid $TenantFilter - - # Build bulk request for group members - $MemberRequests = $Groups | ForEach-Object { - if ($_.id) { - [PSCustomObject]@{ - id = $_.id - method = 'GET' - url = "/groups/$($_.id)/members?`$top=999&`$select=id,displayName,userPrincipalName" + $GroupUri = "https://graph.microsoft.com/beta/groups?`$top=999&`$select=$GroupSelect&`$expand=owners(`$select=id,displayName,userPrincipalName)" + + # Stream groups in batches of $MemberBatchSize so peak memory is one batch of rows + # plus their member lists, not the whole tenant. The writer is opened before the + # pipeline on purpose: GetSteppablePipeline() captures whichever scope is live, so + # opening it inside ForEach-Object captures the Graph call's scope, which is gone + # by End() - the end block then fails with "is not recognized". + $CachedCount = 0 + $PendingBatch = [System.Collections.Generic.List[object]]::new() + $Writer = { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'Groups' -AddCount }.GetSteppablePipeline() + $Writer.Begin($true) + + function Write-GroupBatch { + param( + [System.Collections.Generic.List[object]]$Batch, + $PipelineWriter, + [ref]$Count + ) + + if ($Batch.Count -eq 0) { return } + + $MemberRequests = $Batch | ForEach-Object { + if ($_.id -and $_.groupTypes -notcontains 'DynamicMembership') { + [PSCustomObject]@{ + id = $_.id + method = 'GET' + url = "/groups/$($_.id)/members?`$top=999&`$select=id,displayName,userPrincipalName" + } } } - } - # Index the member responses by group id. The previous per-group - # 'Where-Object { $_.id -eq $Group.id }' rescanned the whole response array for every - # group, which is O(groups x groups) - 100M comparisons on a 10k-group tenant. - $MembersByGroupId = @{} - # Tracks which shape the rows take: groups fetched with a member lookup carry a - # 'members' property (null when the lookup returned nothing for that group), groups - # fetched without one omit the property entirely. Keyed off whether the lookup ran, - # not off whether it returned anything, so an empty response still yields the - # members-shaped row the previous implementation produced. - $HasMembers = [bool]$MemberRequests - if ($HasMembers) { - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Fetching group members' -sev Debug - $MemberResults = New-GraphBulkRequest -Requests @($MemberRequests) -tenantid $TenantFilter - foreach ($Result in $MemberResults) { - if ($Result.id) { $MembersByGroupId[$Result.id] = $Result.body.value } + $MembersByGroupId = @{} + if ($MemberRequests) { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Fetching group members for batch of $($Batch.Count)" -sev Debug + $MemberResults = New-GraphBulkRequest -Requests @($MemberRequests) -tenantid $TenantFilter + foreach ($Result in $MemberResults) { + if ($Result.id) { $MembersByGroupId[$Result.id] = $Result.body.value } + } + $MemberResults = $null } - $MemberResults = $null - } - $MemberRequests = $null - - # Project and emit one group at a time: Add-CIPPDbItem batches internally, so peak - # retention is a batch of rows rather than every group (with its whole member list) - # plus a second materialised array. Each group's members are dropped from the index - # once written, so membership becomes collectable as the run progresses. - # Properties are applied in a single Add-Member call - adding them one at a time - # rebuilds the object's property bag on every call. The [ordered] dictionary keeps - # the emitted JSON property order identical to the previous sequential adds. - & { - foreach ($Group in $Groups) { + + foreach ($Group in $Batch) { $groupType = if ($Group.groupTypes -contains 'Unified') { 'Microsoft 365' } elseif ($Group.mailEnabled -and $Group.securityEnabled) { 'Mail-Enabled Security' } elseif (-not $Group.mailEnabled -and $Group.securityEnabled) { 'Security' } @@ -74,10 +75,19 @@ function Set-CIPPDBCacheGroups { else { 'unknown' } $NoteProperties = [ordered]@{} - if ($HasMembers) { + if ($Group.id -and $Group.groupTypes -notcontains 'DynamicMembership') { $NoteProperties['members'] = $MembersByGroupId[$Group.id] - $MembersByGroupId.Remove($Group.id) + # Precompute the UPN CSV so the paged list read can stream the stored blob + # verbatim instead of parsing every member array (heavy on 50k-member groups). + $NoteProperties['membersCsv'] = ($MembersByGroupId[$Group.id].userPrincipalName -join ',') } + if ($Group.owners) { + $NoteProperties['ownersCsv'] = ($Group.owners.userPrincipalName -join ',') + } + # Set unconditionally (unlike ownersCsv above) so a genuinely owner-less group + # still gets an explicit false baked into the blob - the AsRawJson paged read + # streams this stored blob verbatim and never recomputes it. + $NoteProperties['hasOwner'] = [bool]($Group.owners -and $Group.owners.Count -gt 0) $NoteProperties['primDomain'] = ($Group.mail -split '@' | Select-Object -Last 1) $NoteProperties['teamsEnabled'] = ($Group.resourceProvisioningOptions -contains 'Team') $NoteProperties['dynamicGroupBool'] = ($Group.groupTypes -contains 'DynamicMembership') @@ -85,14 +95,31 @@ function Set-CIPPDBCacheGroups { $NoteProperties['calculatedGroupType'] = $calculatedGroupType $Group | Add-Member -NotePropertyMembers $NoteProperties -Force - $Group + $Count.Value++ + $PipelineWriter.Process($Group) + } + + $Batch.Clear() + $MembersByGroupId = $null + } + + try { + New-GraphGetRequest -uri $GroupUri -tenantid $TenantFilter -Stream | ForEach-Object { + $PendingBatch.Add($_) + if ($PendingBatch.Count -ge $MemberBatchSize) { + Write-GroupBatch -Batch $PendingBatch -PipelineWriter $Writer -Count ([ref]$CachedCount) + } } - } | Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'Groups' -AddCount - $Groups = $null - $MembersByGroupId = $null + Write-GroupBatch -Batch $PendingBatch -PipelineWriter $Writer -Count ([ref]$CachedCount) - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached groups with members and owners successfully' -sev Debug + if ($CachedCount -gt 0) { + $Writer.End() + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $CachedCount groups with members and owners successfully" -sev Debug + } + } finally { + $Writer.Dispose() + } } catch { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter ` diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheHVEAccounts.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheHVEAccounts.ps1 index 8f84024e824c3..2ca38e78dc00b 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheHVEAccounts.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheHVEAccounts.ps1 @@ -41,7 +41,7 @@ function Set-CIPPDBCacheHVEAccounts { $BulkResults = New-ExoBulkRequest -tenantid $TenantFilter -cmdletArray @($BulkCmdlets) for ($i = 0; $i -lt $HVEAccounts.Count; $i++) { $Result = $BulkResults[$i] - if ($Result.body -and -not $Result.body.error -and $Result.body.value) { + if ($Result.body -and -not $Result.body.error -and $Result.body.value -and $HVEAccounts[$i].PrimarySmtpAddress) { $PolicyData = $Result.body.value $BillingPolicyMap[$HVEAccounts[$i].PrimarySmtpAddress] = @{ BillingPolicyId = $PolicyData.BillingPolicyId @@ -55,7 +55,9 @@ function Set-CIPPDBCacheHVEAccounts { } foreach ($HVE in $HVEAccounts) { - $Policy = $BillingPolicyMap[$HVE.PrimarySmtpAddress] + # PrimarySmtpAddress can be null for a partially-provisioned HVE account - same + # null-key-indexing hazard as the Mailboxes cache (see Set-CIPPDBCacheMailboxes.ps1). + $Policy = if ($HVE.PrimarySmtpAddress) { $BillingPolicyMap[$HVE.PrimarySmtpAddress] } else { $null } $Transformed.Add(($HVE | Select-Object ` @{ Name = 'displayName'; Expression = { $_.DisplayName } }, diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneAppProtectionPolicies.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneAppProtectionPolicies.ps1 index 6f77c3330d162..e8678f7b7e60f 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneAppProtectionPolicies.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneAppProtectionPolicies.ps1 @@ -10,6 +10,11 @@ function Set-CIPPDBCacheIntuneAppProtectionPolicies { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneAppProtectionPoliciesCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping app protection policies cache' -sev Debug + # A license skip is still a completed collection: record authoritative empty sets for + # every type this collector writes so collect-on-miss does not re-run it forever. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneAppProtectionPolicyGroups' -Data @() -AddCount -ClearOnEmpty + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneAppProtectionManagedAppPolicies' -Data @() -AddCount -ClearOnEmpty + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneAppProtectionMobileAppConfigurations' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneAppleUserInitiatedEnrollmentProfiles.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneAppleUserInitiatedEnrollmentProfiles.ps1 index 5b7f149e15b3a..e07e42cee41d2 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneAppleUserInitiatedEnrollmentProfiles.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneAppleUserInitiatedEnrollmentProfiles.ps1 @@ -24,6 +24,9 @@ function Set-CIPPDBCacheIntuneAppleUserInitiatedEnrollmentProfiles { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneAppleEnrollmentProfilesCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping Apple enrollment type profiles cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneAppleUserInitiatedEnrollmentProfiles' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneApplications.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneApplications.ps1 index 4218dfdc137ea..880b1007c6140 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneApplications.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneApplications.ps1 @@ -10,6 +10,11 @@ function Set-CIPPDBCacheIntuneApplications { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneApplicationsCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping applications cache' -sev Debug + # A license skip is still a completed collection: record authoritative empty sets for + # every type this collector writes so collect-on-miss does not re-run it forever. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneApplicationGroups' -Data @() -AddCount -ClearOnEmpty + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneApplications' -Data @() -AddCount -ClearOnEmpty + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneMobileAppsAll' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneAssignmentFilters.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneAssignmentFilters.ps1 index e6037b1f10611..2528eee0c1d50 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneAssignmentFilters.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneAssignmentFilters.ps1 @@ -10,6 +10,9 @@ function Set-CIPPDBCacheIntuneAssignmentFilters { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneAssignmentFiltersCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping assignment filters cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneAssignmentFilters' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneBrandingProfile.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneBrandingProfile.ps1 index 60c054954e2bd..30137eeeb6781 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneBrandingProfile.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneBrandingProfile.ps1 @@ -20,6 +20,9 @@ function Set-CIPPDBCacheIntuneBrandingProfile { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneBrandingProfileCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping Intune branding profile cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneBrandingProfile' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneCompliancePolicies.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneCompliancePolicies.ps1 index 06f43b240a03e..6e3f43915218d 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneCompliancePolicies.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneCompliancePolicies.ps1 @@ -10,6 +10,10 @@ function Set-CIPPDBCacheIntuneCompliancePolicies { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneCompliancePoliciesCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping compliance policies cache' -sev Debug + # A license skip is still a completed collection: record authoritative empty sets for + # both types this collector writes so collect-on-miss does not re-run it forever. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneCompliancePolicyGroups' -Data @() -AddCount -ClearOnEmpty + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneDeviceCompliancePolicies' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneConfigurationPolicies.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneConfigurationPolicies.ps1 index 36ba1b935a8c8..c8e858b7a57af 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneConfigurationPolicies.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneConfigurationPolicies.ps1 @@ -24,6 +24,9 @@ function Set-CIPPDBCacheIntuneConfigurationPolicies { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneConfigurationPoliciesCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping configuration policies cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneConfigurationPolicies' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneDataProcessorOnboarding.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneDataProcessorOnboarding.ps1 index 904e274db725d..cd0cc55cb8212 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneDataProcessorOnboarding.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneDataProcessorOnboarding.ps1 @@ -25,6 +25,9 @@ function Set-CIPPDBCacheIntuneDataProcessorOnboarding { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneDataProcessorOnboardingCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping data processor onboarding cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneDataProcessorOnboarding' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneDeviceEnrollmentConfigurations.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneDeviceEnrollmentConfigurations.ps1 index a7416e164a3dd..0e9e540eb4ade 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneDeviceEnrollmentConfigurations.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneDeviceEnrollmentConfigurations.ps1 @@ -26,6 +26,9 @@ function Set-CIPPDBCacheIntuneDeviceEnrollmentConfigurations { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneDeviceEnrollmentConfigurationsCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping Intune device enrollment configurations cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneDeviceEnrollmentConfigurations' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneDeviceManagementSettings.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneDeviceManagementSettings.ps1 index e55bad9d2f381..ff3254c2c8312 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneDeviceManagementSettings.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneDeviceManagementSettings.ps1 @@ -25,6 +25,9 @@ function Set-CIPPDBCacheIntuneDeviceManagementSettings { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneDeviceManagementSettingsCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping Intune device management settings cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneDeviceManagementSettings' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneMobileApps.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneMobileApps.ps1 index 70593f46d0327..50465f7f3e6d7 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneMobileApps.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneMobileApps.ps1 @@ -25,6 +25,9 @@ function Set-CIPPDBCacheIntuneMobileApps { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneMobileAppsCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping mobile apps cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneMobileApps' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneReusableSettings.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneReusableSettings.ps1 index 437bcd6607db4..065e579e936eb 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneReusableSettings.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneReusableSettings.ps1 @@ -10,6 +10,9 @@ function Set-CIPPDBCacheIntuneReusableSettings { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneReusableSettingsCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping reusable settings cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneReusableSettings' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneScripts.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneScripts.ps1 index 1052c9505b9d5..9f5746b472894 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneScripts.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneScripts.ps1 @@ -10,6 +10,11 @@ function Set-CIPPDBCacheIntuneScripts { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneScriptsCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping scripts cache' -sev Debug + # A license skip is still a completed collection: record authoritative empty sets for + # every type this collector writes so collect-on-miss does not re-run it forever. + foreach ($SkippedType in @('IntuneScriptGroups', 'IntuneWindowsScripts', 'IntuneMacOSScripts', 'IntuneRemediationScripts', 'IntuneLinuxScripts')) { + Add-CIPPDbItem -TenantFilter $TenantFilter -Type $SkippedType -Data @() -AddCount -ClearOnEmpty + } return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneWindowsAutopilotDeploymentProfiles.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneWindowsAutopilotDeploymentProfiles.ps1 index 03f966b3571ce..86f2997b4f506 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneWindowsAutopilotDeploymentProfiles.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheIntuneWindowsAutopilotDeploymentProfiles.ps1 @@ -23,6 +23,9 @@ function Set-CIPPDBCacheIntuneWindowsAutopilotDeploymentProfiles { $TestResult = Test-CIPPStandardLicense -StandardName 'IntuneAutopilotProfilesCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping Autopilot profiles cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'IntuneWindowsAutopilotDeploymentProfiles' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheMailboxes.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheMailboxes.ps1 index 74f56ffc3e599..09346031d3420 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheMailboxes.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheMailboxes.ps1 @@ -27,7 +27,7 @@ function Set-CIPPDBCacheMailboxes { # Get mailboxes and user details in a single bulk request $ZeroArchiveGuid = '00000000-0000-0000-0000-000000000000' - $Select = 'id,ExchangeGuid,ArchiveGuid,UserPrincipalName,DisplayName,PrimarySMTPAddress,RecipientType,RecipientTypeDetails,EmailAddresses,WhenSoftDeleted,IsInactiveMailbox,ForwardingSmtpAddress,DeliverToMailboxAndForward,ForwardingAddress,HiddenFromAddressListsEnabled,ExternalDirectoryObjectId,MessageCopyForSendOnBehalfEnabled,MessageCopyForSentAsEnabled,GrantSendOnBehalfTo,PersistedCapabilities,LitigationHoldEnabled,LitigationHoldDate,LitigationHoldDuration,ComplianceTagHoldApplied,RetentionHoldEnabled,InPlaceHolds,RetentionPolicy,RemotePowerShellEnabled,Guid,Identity,AutoExpandingArchiveEnabled,IsExchangeCloudManaged,IsDirSynced,MailboxPlan,MailboxPlanId,RecipientLimits,AccountDisabled' + $Select = 'id,ExchangeGuid,ArchiveGuid,UserPrincipalName,DisplayName,PrimarySMTPAddress,RecipientType,RecipientTypeDetails,EmailAddresses,WhenSoftDeleted,IsInactiveMailbox,ForwardingSmtpAddress,DeliverToMailboxAndForward,ForwardingAddress,HiddenFromAddressListsEnabled,ExternalDirectoryObjectId,MessageCopyForSendOnBehalfEnabled,MessageCopyForSentAsEnabled,GrantSendOnBehalfTo,PersistedCapabilities,LitigationHoldEnabled,LitigationHoldDate,LitigationHoldDuration,ComplianceTagHoldApplied,RetentionHoldEnabled,InPlaceHolds,RetentionPolicy,RemotePowerShellEnabled,Guid,Identity,AutoExpandingArchiveEnabled,ArchiveQuota,IsExchangeCloudManaged,IsDirSynced,MailboxPlan,MailboxPlanId,RecipientLimits,AccountDisabled,AuditEnabled,AuditOwner,AuditDelegate,AuditAdmin,DefaultAuditSet' $BulkRequests = @( @{ CmdletInput = @{ CmdletName = 'Get-Mailbox'; Parameters = @{} } } @{ CmdletInput = @{ CmdletName = 'Get-User'; Parameters = @{} } } @@ -54,13 +54,19 @@ function Set-CIPPDBCacheMailboxes { # Transform Get-Mailbox results and merge Get-User properties $Mailboxes = [System.Collections.Generic.List[PSObject]]::new() foreach ($Mailbox in @($BulkResults.'Get-Mailbox')) { - $MatchedUser = $UserLookup[$Mailbox.ExternalDirectoryObjectId] + # ExternalDirectoryObjectId can be null for a mailbox that has no linked Entra ID + # directory object (the $UserLookup population above already guards against this on + # the write side - see the -and check a few lines up). Indexing a hashtable with a + # null key throws "Index operation failed; the array index evaluated to null." and + # aborts the whole cache run for the tenant, so the read side needs the same guard. + $MatchedUser = if ($Mailbox.ExternalDirectoryObjectId) { $UserLookup[$Mailbox.ExternalDirectoryObjectId] } else { $null } $AutoExpandingArchiveState = Get-CIPPAutoExpandingArchiveState -MailboxAutoExpandingArchiveEnabled $Mailbox.AutoExpandingArchiveEnabled -OrgAutoExpandingArchiveEnabled $OrgAutoExpandingArchiveEnabled $Mailboxes.Add(($Mailbox | Select-Object id, ExchangeGuid, ArchiveGuid, WhenSoftDeleted, @{ Name = 'UPN'; Expression = { $_.'UserPrincipalName' } }, @{ Name = 'displayName'; Expression = { $_.'DisplayName' } }, @{ Name = 'primarySmtpAddress'; Expression = { $_.'PrimarySMTPAddress' } }, @{ Name = 'ArchiveEnabled'; Expression = { $_.ArchiveGuid -and $_.ArchiveGuid.ToString() -ne $ZeroArchiveGuid } }, + @{ Name = 'ArchiveQuota'; Expression = { try { Get-ExoOnlineStringBytes -SizeString ([string]$_.ArchiveQuota) } catch { 0 } } }, @{ Name = 'AutoExpandingArchive'; Expression = { $AutoExpandingArchiveState.AutoExpandingArchive } }, @{ Name = 'AutoExpandingArchiveScope'; Expression = { $AutoExpandingArchiveState.AutoExpandingArchiveScope } }, @{ Name = 'ArchiveSize'; Expression = { 0 } }, @@ -94,6 +100,11 @@ function Set-CIPPDBCacheMailboxes { PersistedCapabilities, RecipientLimits, AccountDisabled, + AuditEnabled, + AuditOwner, + AuditDelegate, + AuditAdmin, + DefaultAuditSet, @{ Name = 'RemotePowerShellEnabled'; Expression = { $MatchedUser.RemotePowerShellEnabled } }, @{ Name = 'Guid'; Expression = { $MatchedUser.Guid } }, @{ Name = 'Identity'; Expression = { $MatchedUser.Identity } })) diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheManagedDeviceCleanupRules.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheManagedDeviceCleanupRules.ps1 index 225a36899f5bb..7d85f2412df93 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheManagedDeviceCleanupRules.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheManagedDeviceCleanupRules.ps1 @@ -24,6 +24,9 @@ function Set-CIPPDBCacheManagedDeviceCleanupRules { $TestResult = Test-CIPPStandardLicense -StandardName 'ManagedDeviceCleanupRulesCache' -TenantFilter $TenantFilter -Preset Intune -SkipLog if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Intune license, skipping managed device cleanup rules cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ManagedDeviceCleanupRules' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheMobileDeviceManagementPolicies.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheMobileDeviceManagementPolicies.ps1 index 969f496cb5089..4d741e4a98092 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheMobileDeviceManagementPolicies.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheMobileDeviceManagementPolicies.ps1 @@ -26,7 +26,7 @@ function Set-CIPPDBCacheMobileDeviceManagementPolicies { # Full entity (no $select) so isMdmEnrollmentDuringRegistrationDisabled, appliesTo and the # termsOfUseUrl/discoveryUrl/complianceUrl properties are all included, plus included groups - $MDMPolicy = New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/policies/mobileDeviceManagementPolicies/0000000a-0000-0000-c000-000000000000?$expand=includedGroups($select=displayName)' -tenantid $TenantFilter + $MDMPolicy = New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/policies/mobileDeviceManagementPolicies/0000000a-0000-0000-c000-000000000000?$expand=includedGroups($select=id,displayName)' -tenantid $TenantFilter Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'MobileDeviceManagementPolicies' -Data @($MDMPolicy) -AddCount $MDMPolicy = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOAuth2PermissionGrants.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOAuth2PermissionGrants.ps1 index 404d7c7189ad7..2ab748e665707 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOAuth2PermissionGrants.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOAuth2PermissionGrants.ps1 @@ -24,6 +24,11 @@ function Set-CIPPDBCacheOAuth2PermissionGrants { if ($OAuth2PermissionGrants) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'OAuth2PermissionGrants' -Data $OAuth2PermissionGrants -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($OAuth2PermissionGrants.Count) OAuth2 permission grants" -sev Debug + } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'OAuth2PermissionGrants' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 OAuth2 permission grants (none found)' -sev Debug } $OAuth2PermissionGrants = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOneDriveLongPaths.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOneDriveLongPaths.ps1 new file mode 100644 index 0000000000000..6578cf1fed0b5 --- /dev/null +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOneDriveLongPaths.ps1 @@ -0,0 +1,155 @@ +function Set-CIPPDBCacheOneDriveLongPaths { + <# + .SYNOPSIS + Fans out OneDrive long-path recount, one resumable activity per personal site. + + .DESCRIPTION + Adhoc-only (not part of nightly SharePoint collection). Enumerates personal sites, resolves + owner UPN from OneDriveUsage cache (merging a live usage report for gaps), and starts + per-site activities that full-recount path-length counts without storing paths or names. + + Clears the previous OneDriveLongPaths cache at fan-out start so departed users cannot + leave stale alert counts. Mid-scan the cache may be partial until activities finish. + + Trigger: /api/ExecCIPPDBCache?Name=OneDriveLongPaths&TenantFilter=... + Alert Get-CIPPAlertOneDriveLongPaths reads the resulting cache — run this collection first. + + .PARAMETER TenantFilter + The tenant to scan + + .PARAMETER QueueId + Optional queue ID for progress tracking + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + [string]$QueueId + ) + + try { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Starting OneDrive long-path collection (per-site fan-out)' -sev Debug + + $OrgDisplayName = 'Organization' + try { + $Org = New-GraphGetRequest -uri 'https://graph.microsoft.com/v1.0/organization?$select=displayName' -tenantid $TenantFilter -asapp $true + $OrgRow = @($Org)[0] + if ($OrgRow.displayName) { $OrgDisplayName = [string]$OrgRow.displayName } + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "OneDrive long-paths: could not read organization displayName; using default: $($_.Exception.Message)" -sev Warning + } + # Default sync root: C:\Users\{upnLocal}\OneDrive - {org}\ — org segment once per tenant; UPN local-part added per site. + $InferredLocalRootFixedLength = ('C:\Users\').Length + ("\OneDrive - $OrgDisplayName\").Length + + $RawSites = @(New-GraphGetRequest -uri "https://graph.microsoft.com/beta/sites/getAllSites?`$filter=isPersonalSite eq true&`$select=id,webUrl,displayName,sharepointIds&`$top=999" -tenantid $TenantFilter -asapp $true) + $SeenSiteIds = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + $Sites = foreach ($Site in $RawSites) { + $GraphSiteId = [string]$Site.id + if ([string]::IsNullOrWhiteSpace($GraphSiteId)) { continue } + if (-not $SeenSiteIds.Add($GraphSiteId)) { continue } + $Site + } + $Sites = @($Sites) + + # siteId -> ownerPrincipalName (usage report siteId is the SPO GUID) + $UpnBySiteId = [System.Collections.Generic.Dictionary[string, string]]::new([System.StringComparer]::OrdinalIgnoreCase) + try { + $UsageItems = @(Get-CIPPDbItem -TenantFilter $TenantFilter -Type 'OneDriveUsage' | Where-Object { $_.RowKey -ne 'OneDriveUsage-Count' }) + foreach ($UsageItem in $UsageItems) { + $UsageRow = $null + try { $UsageRow = $UsageItem.Data | ConvertFrom-Json -Depth 5 } catch { continue } + if ($UsageRow.siteId -and $UsageRow.ownerPrincipalName) { + $UpnBySiteId[[string]$UsageRow.siteId] = [string]$UsageRow.ownerPrincipalName + } + } + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "OneDrive long-paths: OneDriveUsage cache read failed: $($_.Exception.Message)" -sev Debug + } + + $NeedsLiveUsage = ($UpnBySiteId.Count -eq 0) + if (-not $NeedsLiveUsage) { + foreach ($Site in $Sites) { + $SpoSiteId = [string]($Site.sharepointIds.siteId ?? '') + if ($SpoSiteId -and -not $UpnBySiteId.ContainsKey($SpoSiteId)) { + $NeedsLiveUsage = $true + break + } + } + } + + if ($NeedsLiveUsage) { + try { + $Usage = @(New-GraphGetRequest -uri "https://graph.microsoft.com/beta/reports/getOneDriveUsageAccountDetail(period='D7')?`$format=application/json&`$top=999" -tenantid $TenantFilter -asapp $true) + foreach ($UsageRow in $Usage) { + if ($UsageRow.siteId -and $UsageRow.ownerPrincipalName) { + $UpnBySiteId[[string]$UsageRow.siteId] = [string]$UsageRow.ownerPrincipalName + } + } + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "OneDrive long-paths: live usage report failed: $($_.Exception.Message)" -sev Warning + } + } + + if ($Sites.Count -eq 0) { + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'OneDriveLongPaths' -Data @() -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'OneDrive long-paths: no personal sites; wrote empty cache' -sev Debug + return + } + + $ScanId = [guid]::NewGuid().ToString() + $StateTable = Get-CippTable -tablename 'CippOneDriveLongPathsState' + Add-CIPPAzDataTableEntity @StateTable -Entity @{ + PartitionKey = $TenantFilter + RowKey = 'scan' + ScanId = $ScanId + StartedUtc = [string]([DateTimeOffset]::UtcNow.ToString('o')) + } -Force + + # Drop prior scan results so departed users cannot leave false alert counts. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'OneDriveLongPaths' -Data @() -ClearOnEmpty + + $Batch = [System.Collections.Generic.List[object]]::new() + foreach ($Site in $Sites) { + $SpoSiteId = [string]($Site.sharepointIds.siteId ?? '') + $GraphSiteId = [string]$Site.id + $Upn = $null + if ($SpoSiteId -and $UpnBySiteId.ContainsKey($SpoSiteId)) { + $Upn = $UpnBySiteId[$SpoSiteId] + } elseif ($GraphSiteId -and $UpnBySiteId.ContainsKey($GraphSiteId)) { + $Upn = $UpnBySiteId[$GraphSiteId] + } + + $QueueLabel = if ($Upn) { $Upn } else { $GraphSiteId } + $Batch.Add([PSCustomObject]@{ + FunctionName = 'DBCacheOneDriveLongPaths' + TenantFilter = $TenantFilter + SiteId = $GraphSiteId + SpoSiteId = $SpoSiteId + OwnerPrincipalName = $Upn + OrgDisplayName = $OrgDisplayName + InferredLocalRootFixedLength = $InferredLocalRootFixedLength + ScanId = $ScanId + QueueId = $QueueId + QueueName = "OneDrive Long Paths - $QueueLabel" + }) + } + + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "OneDrive long-paths: dispatching $($Batch.Count) sites, scan $ScanId" -sev Debug + + if ($QueueId) { + try { + Update-CippQueueEntry -RowKey $QueueId -TotalTasks $Batch.Count -IncrementTotalTasks + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "OneDrive long-paths: could not update queue ${QueueId}: $($_.Exception.Message)" -sev Warning + } + } + + $null = Start-CIPPOrchestrator -InputObject ([PSCustomObject]@{ + Batch = @($Batch) + OrchestratorName = "OneDriveLongPaths_$TenantFilter" + SkipLog = $true + }) + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Failed to start OneDrive long-path collection: $($_.Exception.Message)" -sev Error -LogData (Get-CippException -Exception $_) + } +} diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOneDriveRootPermissions.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOneDriveRootPermissions.ps1 index 6d8aefb5ffbc9..2f3fd77516440 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOneDriveRootPermissions.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOneDriveRootPermissions.ps1 @@ -53,6 +53,9 @@ function Set-CIPPDBCacheOneDriveRootPermissions { $LicenseCheck = Test-CIPPStandardLicense -StandardName 'OneDriveRootPermissionsCache' -TenantFilter $TenantFilter -Preset SharePoint -SkipLog if ($LicenseCheck -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have SharePoint/OneDrive license, skipping OneDrive root permissions cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'OneDriveRootPermissions' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOneDriveUsage.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOneDriveUsage.ps1 index d0f3cc2c58f1a..3110c08c12124 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOneDriveUsage.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOneDriveUsage.ps1 @@ -49,8 +49,10 @@ function Set-CIPPDBCacheOneDriveUsage { foreach ($UsageRow in $OneDriveUsage) { if ($null -eq $UsageRow) { continue } - $UsageRow | Add-Member -NotePropertyName 'id' -NotePropertyValue $UsageRow.siteId -Force - $UsageRow | Add-Member -NotePropertyName 'userPrincipalName' -NotePropertyValue $UsageRow.ownerPrincipalName -Force + $UsageRow | Add-Member -NotePropertyMembers ([ordered]@{ + id = $UsageRow.siteId + userPrincipalName = $UsageRow.ownerPrincipalName + }) -Force } $OneDriveListing = [System.Collections.Generic.List[object]]::new() diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOwaMailboxPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOwaMailboxPolicy.ps1 index b29ad6bfa0e9b..9a74445d198e6 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOwaMailboxPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOwaMailboxPolicy.ps1 @@ -30,6 +30,11 @@ function Set-CIPPDBCacheOwaMailboxPolicy { if ($OwaMailboxPolicies) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'OwaMailboxPolicy' -Data $OwaMailboxPolicies -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($OwaMailboxPolicies.Count) OWA Mailbox Policies" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'OwaMailboxPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 OWA Mailbox Policies (none found)' -sev Debug } $OwaMailboxPolicies = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCachePIMSettings.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCachePIMSettings.ps1 index 01057595b165f..74895f9de85ac 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCachePIMSettings.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCachePIMSettings.ps1 @@ -21,6 +21,10 @@ function Set-CIPPDBCachePIMSettings { if ($TestResult -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have Azure AD Premium P2 license, skipping PIM' -sev Debug + # A license skip is still a completed collection: record authoritative empty sets for + # both types this collector writes so collect-on-miss does not re-run it forever. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'PIMRoleSettings' -Data @() -AddCount -ClearOnEmpty + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'PIMAssignments' -Data @() -AddCount -ClearOnEmpty return } @@ -32,6 +36,11 @@ function Set-CIPPDBCachePIMSettings { if ($PIMRoleSettings) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'PIMRoleSettings' -Data $PIMRoleSettings -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($PIMRoleSettings.Count) PIM role settings" -sev Debug + } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'PIMRoleSettings' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 PIM role settings (none found)' -sev Debug } $PIMRoleSettings = $null } catch { @@ -44,6 +53,11 @@ function Set-CIPPDBCachePIMSettings { if ($PIMAssignments) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'PIMAssignments' -Data $PIMAssignments -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($PIMAssignments.Count) PIM assignments" -sev Debug + } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'PIMAssignments' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 PIM assignments (none found)' -sev Debug } $PIMAssignments = $null } catch { diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCachePermissionGrantPolicies.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCachePermissionGrantPolicies.ps1 index aa88aae3855d9..6b58076d61268 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCachePermissionGrantPolicies.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCachePermissionGrantPolicies.ps1 @@ -19,7 +19,8 @@ function Set-CIPPDBCachePermissionGrantPolicies { try { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Caching permission grant policies' -sev Debug - $PermissionGrantPolicies = @(New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/policies/permissionGrantPolicies?$expand=includes' -tenantid $TenantFilter) + # includes/excludes are auto-expanded on GET; $expand is rejected by Graph + $PermissionGrantPolicies = @(New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/policies/permissionGrantPolicies' -tenantid $TenantFilter) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'PermissionGrantPolicies' -Data @($PermissionGrantPolicies) -AddCount $PermissionGrantPolicies = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheReportSubmissionPolicy.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheReportSubmissionPolicy.ps1 index fb0e24beae0cc..4ebf1d77220d2 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheReportSubmissionPolicy.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheReportSubmissionPolicy.ps1 @@ -30,6 +30,11 @@ function Set-CIPPDBCacheReportSubmissionPolicy { $Data = @($ReportSubmissionPolicies) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ReportSubmissionPolicy' -Data $Data -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($Data.Count) Report Submission Policies" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ReportSubmissionPolicy' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 Report Submission Policies (none found)' -sev Debug } $ReportSubmissionPolicies = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheReportSubmissionRule.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheReportSubmissionRule.ps1 index 5a4ae9e018643..df15e3e7ae78b 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheReportSubmissionRule.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheReportSubmissionRule.ps1 @@ -24,6 +24,11 @@ function Set-CIPPDBCacheReportSubmissionRule { $ReportSubmissionRuleArray = @($ReportSubmissionRules) Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ReportSubmissionRule' -Data $ReportSubmissionRuleArray -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($ReportSubmissionRuleArray.Count) report submission rules" -sev Debug + } else { + # The cmdlet succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'ReportSubmissionRule' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 report submission rules (none found)' -sev Debug } $ReportSubmissionRules = $null diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheRiskDetections.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheRiskDetections.ps1 index a2590aa4d2f91..6066afb22a0f8 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheRiskDetections.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheRiskDetections.ps1 @@ -26,6 +26,9 @@ function Set-CIPPDBCacheRiskDetections { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'RiskDetections' -Data $RiskDetections -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($RiskDetections.Count) risk detections successfully" -sev Debug } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'RiskDetections' -Data @() -AddCount -ClearOnEmpty Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'No risk detections found or Identity Protection not available' -sev Debug } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheRiskyServicePrincipals.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheRiskyServicePrincipals.ps1 index 921208f6fff3e..36349c3a7e7ee 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheRiskyServicePrincipals.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheRiskyServicePrincipals.ps1 @@ -26,6 +26,9 @@ function Set-CIPPDBCacheRiskyServicePrincipals { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'RiskyServicePrincipals' -Data $RiskyServicePrincipals -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($RiskyServicePrincipals.Count) risky service principals successfully" -sev Debug } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'RiskyServicePrincipals' -Data @() -AddCount -ClearOnEmpty Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'No risky service principals found or Workload Identity Protection not available' -sev Debug } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheRiskyUsers.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheRiskyUsers.ps1 index 7e47e3b66ba5d..acd135036d559 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheRiskyUsers.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheRiskyUsers.ps1 @@ -26,6 +26,9 @@ function Set-CIPPDBCacheRiskyUsers { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'RiskyUsers' -Data $RiskyUsers -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($RiskyUsers.Count) risky users successfully" -sev Debug } else { + # The request succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'RiskyUsers' -Data @() -AddCount -ClearOnEmpty Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'No risky users found or Identity Protection not available' -sev Debug } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSPOSites.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSPOSites.ps1 new file mode 100644 index 0000000000000..65b297e64a02c --- /dev/null +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSPOSites.ps1 @@ -0,0 +1,115 @@ +function Set-CIPPDBCacheSPOSites { + <# + .SYNOPSIS + Caches per-site SharePoint Online admin settings for every site collection + + .DESCRIPTION + Generic per-site SharePoint cache (Type 'SPOSites'): one row per site collection with the + admin-manageable settings (site owner, sharing controls, lifecycle, version policy, People + Picker, unmanaged-device access), keyed by site id. Any site-level standard or report can read + it. The tenant-wide enumeration (Get-CIPPSPOSite) supplies the site list and the fields it is + accurate for; the ~19 fields it only returns as defaults (owner, per-site sharing, People + Picker, ...) are filled from an authoritative per-site read (Get-CIPPSPOSiteBulk, batched and + concurrency-capped). SharePoint app-only requires the certificate (delegated is not available on + every tenant), so both reads use -UseCertificate. + + .PARAMETER TenantFilter + The tenant to cache SharePoint site settings for + + .PARAMETER QueueId + The queue ID to update with total tasks (optional) + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + [string]$QueueId + ) + + try { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Caching SharePoint site settings' -sev Debug + + # The tenant-wide enumeration is fast but returns DEFAULT/empty values for ~19 per-site fields + # (site owner, per-site sharing controls, ShowPeoplePickerSuggestionsForGuestUsers, ...) - only + # the per-site GetSitePropertiesByUrl returns them (confirmed on a live tenant, and confirmed no + # Graph/enumeration variant supplies them). So the enumeration gives us the URL list + the fields + # it IS accurate for, and one authoritative per-site read - batched and concurrency-capped to stay + # under SharePoint's CSOM throttle - fills in the rest. A per-site read failure falls back to the + # enumeration value for that site. + $Sites = @(Get-CIPPSPOSite -TenantFilter $TenantFilter -UseCertificate | Where-Object { $_ -and $_.Url }) + + $AuthByUrl = @{} + if ($Sites.Count -gt 0) { + try { + foreach ($Result in @(Get-CIPPSPOSiteBulk -TenantFilter $TenantFilter -SiteUrls @($Sites.Url) -MaxConcurrency 4 -BatchSize 5 -UseCertificate)) { + if ($Result.Success -and $Result.Site) { $AuthByUrl["$($Result.SiteUrl)"] = $Result.Site } + } + $Missing = $Sites.Count - $AuthByUrl.Count + if ($Missing -gt 0) { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "SPOSites: $Missing of $($Sites.Count) sites fell back to enumeration values (authoritative per-site read did not return them)" -sev Debug + } + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "SPOSites: authoritative per-site read failed; falling back to the enumeration values for this run: $($_.Exception.Message)" -sev Warning + } + } + + # Fields the enumeration only returns as defaults - take the authoritative per-site value, and + # fall back to the (less accurate) enumeration value when the per-site read did not return. + $AuthoritativeFields = @( + 'ShowPeoplePickerSuggestionsForGuestUsers', 'OwnerName', 'OwnerEmail', 'OwnerLoginName', + 'GroupOwnerLoginName', 'IsGroupOwnerSiteAdmin', 'AllowEditing', 'AllowFileArchive', + 'DefaultShareLinkScope', 'DefaultMainLinkScope', 'DisableCompanyWideSharingLinks', + 'LoopDefaultSharingLinkScope', 'LoopDefaultSharingLinkRole', 'BlockDownloadLinksFileType', + 'LimitedAccessFileType', 'RequestFilesLinkEnabled', 'RequestFilesLinkExpirationInDays', + 'SharingLockDownEnabled', 'SharingLockDownCanBeCleared', 'ReadOnlyForUnmanagedDevices', + 'RestrictedAccessControl', 'DisableAppViews', 'DisableFlows', 'SandboxedCodeActivationCapability', + 'IsHubSite', 'IsTeamsConnected', 'IsTeamsChannelConnected', 'WebsCount', 'Status' + ) + + $Rows = @(foreach ($Site in $Sites) { + $Auth = $AuthByUrl["$($Site.Url)"] + $Source = if ($Auth) { $Auth } else { $Site } + # Accurate from the enumeration (kept as-is to preserve id/format stability). Enum values + # stay numeric as CSOM returns them. + $Row = [ordered]@{ + id = "$($Site.SiteId)" + Url = $Site.Url + Title = $Site.Title + Template = $Site.Template + GroupId = "$($Site.GroupId)" + SharingCapability = $Site.SharingCapability + DefaultSharingLinkType = $Site.DefaultSharingLinkType + DefaultLinkPermission = $Site.DefaultLinkPermission + SharingDomainRestrictionMode = $Site.SharingDomainRestrictionMode + SharingAllowedDomainList = $Site.SharingAllowedDomainList + SharingBlockedDomainList = $Site.SharingBlockedDomainList + OverrideTenantAnonymousLinkExpirationPolicy = $Site.OverrideTenantAnonymousLinkExpirationPolicy + AnonymousLinkExpirationInDays = $Site.AnonymousLinkExpirationInDays + LockState = $Site.LockState + StorageMaximumLevel = $Site.StorageMaximumLevel + StorageWarningLevel = $Site.StorageWarningLevel + StorageUsage = $Site.StorageUsage + InheritVersionPolicyFromTenant = $Site.InheritVersionPolicyFromTenant + EnableAutoExpirationVersionTrim = $Site.EnableAutoExpirationVersionTrim + MajorVersionLimit = $Site.MajorVersionLimit + ExpireVersionsAfterDays = $Site.ExpireVersionsAfterDays + ConditionalAccessPolicy = $Site.ConditionalAccessPolicy + } + foreach ($Field in $AuthoritativeFields) { $Row[$Field] = $Source.$Field } + [PSCustomObject]$Row + }) + + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'SPOSites' -Data $Rows -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($Rows.Count) SharePoint site settings" -sev Debug + + } catch { + # A tenant with no SharePoint app-only consent answers 401 every run until that changes; + # record it and move on rather than failing the whole collection for it. + if ($_.Exception.Data['SPOAccessDenied'] -or $_.Exception.Message -match '\b401\b|unauthorized') { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Skipped SharePoint site cache: $($_.Exception.Message)" -sev Warning + return + } + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Failed to cache SharePoint site settings: $($_.Exception.Message)" -sev Error + throw + } +} diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSPOTenant.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSPOTenant.ps1 index b3c720bcfe7e1..0b7acb8191d7a 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSPOTenant.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSPOTenant.ps1 @@ -20,13 +20,18 @@ function Set-CIPPDBCacheSPOTenant { param( [Parameter(Mandatory = $true)] [string]$TenantFilter, - [string]$QueueId + [string]$QueueId, + # SharePoint app-only requires the SAM certificate. Opt-in per caller (e.g. a baseline's + # read.collectorArgs) so this shared collector's default (delegated) is unchanged. + [switch]$UseCertificate ) try { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Caching SharePoint Online tenant configuration' -sev Debug - $SPOTenant = Get-CIPPSPOTenant -TenantFilter $TenantFilter -SkipCache + $AuthSplat = @{} + if ($UseCertificate) { $AuthSplat['UseCertificate'] = $true } + $SPOTenant = Get-CIPPSPOTenant -TenantFilter $TenantFilter -SkipCache @AuthSplat # An empty response is a failure too: this collection only runs for SharePoint-licensed # tenants, so there is always a configuration object to return. Falling through quietly diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSensitivityLabels.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSensitivityLabels.ps1 index 307bc5e879139..6891d3c87c0c6 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSensitivityLabels.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSensitivityLabels.ps1 @@ -21,6 +21,9 @@ function Set-CIPPDBCacheSensitivityLabels { if ($LicenseCheck -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have a Purview/AIP license, skipping sensitivity labels' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'SensitivityLabels' -Data @() -AddCount -ClearOnEmpty return } @@ -31,6 +34,11 @@ function Set-CIPPDBCacheSensitivityLabels { if ($Labels) { Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'SensitivityLabels' -Data $Labels -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($Labels.Count) sensitivity labels" -sev Debug + } else { + # The read succeeded with nothing returned: write the authoritative empty set so the + # Count marker records a completed collection and stale rows are cleared. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'SensitivityLabels' -Data @() -AddCount -ClearOnEmpty + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached 0 sensitivity labels (none found)' -sev Debug } } catch { diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSharePointPermissions.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSharePointPermissions.ps1 index 28d80fe2f4286..85f50a6609b7e 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSharePointPermissions.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSharePointPermissions.ps1 @@ -37,6 +37,9 @@ function Set-CIPPDBCacheSharePointPermissions { $LicenseCheck = Test-CIPPStandardLicense -StandardName 'SharePointPermissionsCache' -TenantFilter $TenantFilter -Preset SharePoint -SkipLog if ($LicenseCheck -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have a SharePoint license, skipping SharePoint permissions cache' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointPermissions' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSharePointSiteUsage.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSharePointSiteUsage.ps1 index f29626c038f22..6ca73597ac6c5 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSharePointSiteUsage.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSharePointSiteUsage.ps1 @@ -3,6 +3,12 @@ function Set-CIPPDBCacheSharePointSiteUsage { .SYNOPSIS Caches SharePoint site listing and site usage details for a tenant + .DESCRIPTION + Active sites + usage from SPO admin RenderAdminListData (same source as the site browser), + Graph getAllSites for Graph ids / sharepointIds, Get-CIPPSPOSite for file-level archive + metrics, and a Graph lists bulk pass for AutoMapUrl. Writes the same SharePointSiteListing + and SharePointSiteUsage property shapes consumed by Get-CIPPSharePointSiteUsageReport. + .PARAMETER TenantFilter The tenant to cache SharePoint site usage for @@ -19,105 +25,10 @@ function Set-CIPPDBCacheSharePointSiteUsage { try { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Caching SharePoint site listing and usage' -sev Debug - $Tenant = Get-Tenants -TenantFilter $TenantFilter - $TenantId = $Tenant.customerId - - $BulkRequests = @( - @{ - id = 'listAllSites' - method = 'GET' - url = "sites/getAllSites?`$filter=isPersonalSite eq false&`$select=id,createdDateTime,description,name,displayName,isPersonalSite,lastModifiedDateTime,webUrl,siteCollection,sharepointIds&`$top=999" - } - @{ - id = 'usage' - method = 'GET' - url = "reports/getSharePointSiteUsageDetail(period='D7')?`$format=application/json&`$top=999" - } - ) - - $Result = New-GraphBulkRequest -tenantid $TenantFilter -Requests @($BulkRequests) -asapp $true - $Sites = @(($Result | Where-Object { $_.id -eq 'listAllSites' }).body.value) - $UsageResponse = $Result | Where-Object { $_.id -eq 'usage' } - if ($UsageResponse.status -and $UsageResponse.status -ne 200) { - throw ($UsageResponse.body.error.message ?? "Usage report request failed with status $($UsageResponse.status)") - } - $UsageBody = $UsageResponse.body - if ($UsageBody -is [string]) { - $UsageJson = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($UsageBody)) - $UsageRows = @(($UsageJson | ConvertFrom-Json).value) - } else { - $UsageRows = @($UsageBody.value) - } - - # Ensure a stable row key for usage rows. - foreach ($UsageRow in $UsageRows) { - if ($null -eq $UsageRow) { continue } - $UsageRow | Add-Member -NotePropertyName 'id' -NotePropertyValue $UsageRow.siteId -Force - } - - $SiteListing = [System.Collections.Generic.List[object]]::new() - foreach ($Site in $Sites) { - $SiteListing.Add([PSCustomObject]@{ - id = $Site.id - sharepointIds = $Site.sharepointIds - createdDateTime = $Site.createdDateTime - displayName = $Site.displayName - webUrl = $Site.webUrl - isPersonalSite = $Site.isPersonalSite - AutoMapUrl = '' - }) - } - - $RequestId = 0 - $ListRequests = foreach ($Site in $SiteListing) { - @{ - id = $RequestId++ - method = 'GET' - url = "sites/$($Site.sharepointIds.siteId)/lists?`$select=id,name,list,parentReference" - } - } - - # Reduce the library responses to one list id per site key as they are read, rather than - # holding every document library object for the whole tenant. The previous version kept - # them all and rescanned the array for each site, which is O(sites x libraries). - # parentReference.siteId is a composite ('hostname,siteCollectionId,webId'), so each - # comma-separated component is indexed - that is what the old '-like "*$siteId*"' test - # matched, since a site GUID can only occur as a whole component. First writer wins, - # matching the previous 'Select-Object -First 1'. - $ListIdBySiteKey = @{} - # A site with no sharepointIds.siteId produced the wildcard pattern '**' in the old - # filter, which matches every library, so the first one won. Kept so those rows are - # unchanged. - $FirstLibraryListId = $null - if ($ListRequests.Count -gt 0) { - try { - $LibraryLists = (New-GraphBulkRequest -tenantid $TenantFilter -scope 'https://graph.microsoft.com/.default' -Requests @($ListRequests) -asapp $true).body.value - foreach ($List in $LibraryLists) { - if ($List.list.template -ne 'DocumentLibrary') { continue } - if ($null -eq $FirstLibraryListId) { $FirstLibraryListId = $List.id } - $ParentSiteId = $List.parentReference.siteId - if (-not $ParentSiteId) { continue } - foreach ($Key in ([string]$ParentSiteId -split ',')) { - if ($Key -and -not $ListIdBySiteKey.ContainsKey($Key)) { $ListIdBySiteKey[$Key] = $List.id } - } - } - $LibraryLists = $null - } catch { - Write-LogMessage -Message "Error getting auto map urls for SharePoint cache: $($_.Exception.Message)" -Sev 'Error' -tenant $TenantFilter -API 'CIPPDBCache' -LogData (Get-CippException -Exception $_) - } - } - $ListRequests = $null - - foreach ($Site in $SiteListing) { - $SiteKey = [string]$Site.sharepointIds.siteId - $ListId = if ($SiteKey) { $ListIdBySiteKey[$SiteKey] } else { $FirstLibraryListId } - $Site.AutoMapUrl = "tenantId=$($TenantId)&webId={$($Site.sharepointIds.webId)}&siteid={$($Site.sharepointIds.siteId)}&webUrl=$($Site.webUrl)&listId={$($ListId)}" - } - $ListIdBySiteKey = $null - - Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSiteListing' -Data @($SiteListing) -AddCount + $Built = Get-CIPPSharePointSiteUsageRows -TenantFilter $TenantFilter -IncludeArchive -LogApi 'CIPPDBCache' - Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSiteUsage' -Data @($UsageRows) -AddCount + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSiteListing' -Data @($Built.SiteListing) -AddCount + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSiteUsage' -Data @($Built.UsageRows) -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached SharePoint site listing and usage successfully' -sev Debug diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheStorageCleanupScan.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheStorageCleanupScan.ps1 new file mode 100644 index 0000000000000..7a3eef812a1bb --- /dev/null +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheStorageCleanupScan.ps1 @@ -0,0 +1,151 @@ +function Set-CIPPDBCacheStorageCleanupScan { + <# + .SYNOPSIS + Fans out SharePoint storage cleanup signal collection, batched by site. + + .DESCRIPTION + Enumerates every non-personal, non-system SharePoint site and starts a child orchestration + with one activity per batch of 20 sites (Push-DBCacheStorageCleanupScanBatch). A single + PostExecution (Push-StoreStorageCleanupScan) aggregates every batch and writes the + StorageCleanupScan cache once. + + Hold-only / report-private: only the storage report reads this cache. It is not part of + nightly CIPPDB collection and is not consumed by ListSites or other List APIs. + + Per site the batch collects library StorageMetrics (versionEstimateBytes) and an aggregate + recycle-bin summary (sizes only — no item titles or paths). + + .PARAMETER TenantFilter + The tenant to cache storage cleanup signals for + + .PARAMETER QueueId + Optional queue ID for progress tracking + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + [string]$QueueId + ) + + $BatchSize = 20 + $SitesToLeaveOut = @( + 'search' + 'contentTypeHub' + 'appcatalog' + 'portals/hub' + 'portals/community' + ) + + function Test-CIPPStorageCleanupLeaveOut { + param( + [string]$Name, + [string]$WebUrl, + [string[]]$LeaveOut + ) + $SitePath = $null + $SitePathLeaf = $null + if (-not [string]::IsNullOrWhiteSpace($WebUrl)) { + try { + $SitePath = ([System.Uri]$WebUrl).AbsolutePath.Trim('/') + if (-not [string]::IsNullOrWhiteSpace($SitePath)) { + $SitePathLeaf = $SitePath.Split('/')[-1] + } + } catch { + $SitePath = $null + $SitePathLeaf = $null + } + } + foreach ($LeaveOutName in $LeaveOut) { + if ( + ([string]::Equals($Name, $LeaveOutName, [System.StringComparison]::OrdinalIgnoreCase)) -or + ([string]::Equals($SitePath, $LeaveOutName, [System.StringComparison]::OrdinalIgnoreCase)) -or + ([string]::Equals($SitePathLeaf, $LeaveOutName, [System.StringComparison]::OrdinalIgnoreCase)) + ) { + return $true + } + } + return $false + } + + try { + $LicenseCheck = Test-CIPPStandardLicense -StandardName 'StorageCleanupScanCache' -TenantFilter $TenantFilter -Preset SharePoint -SkipLog + if ($LicenseCheck -eq $false) { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have a SharePoint license, skipping StorageCleanupScan cache' -sev Debug + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'StorageCleanupScan' -Data @() -AddCount -ClearOnEmpty + return + } + + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Starting StorageCleanupScan collection' -sev Debug + + $RawSites = @(New-GraphGetRequest -uri "https://graph.microsoft.com/beta/sites/getAllSites?`$select=id,displayName,name,webUrl,isPersonalSite&`$top=999" -tenantid $TenantFilter -asapp $true) + + $SiteById = @{} + foreach ($Site in $RawSites) { + if (-not $Site.id -or $Site.isPersonalSite) { continue } + if (Test-CIPPStorageCleanupLeaveOut -Name $Site.name -WebUrl $Site.webUrl -LeaveOut $SitesToLeaveOut) { continue } + $SiteById[$Site.id] = $Site + } + $Sites = @($SiteById.Values) + $ExpectedSiteCount = $Sites.Count + + if ($ExpectedSiteCount -eq 0) { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'No SharePoint sites found; writing empty StorageCleanupScan cache' -sev Debug + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'StorageCleanupScan' -Data @() -AddCount + return + } + + $Batches = [System.Collections.Generic.List[object]]::new() + $TotalBatches = [Math]::Ceiling($Sites.Count / $BatchSize) + for ($i = 0; $i -lt $Sites.Count; $i += $BatchSize) { + $BatchSites = $Sites[$i..[Math]::Min($i + $BatchSize - 1, $Sites.Count - 1)] + $BatchNumber = [Math]::Floor($i / $BatchSize) + 1 + $SiteSeeds = foreach ($Site in $BatchSites) { + [PSCustomObject]@{ + id = $Site.id + webUrl = $Site.webUrl + displayName = $Site.displayName ?? $Site.name + } + } + $BatchItem = [PSCustomObject]@{ + FunctionName = 'DBCacheStorageCleanupScanBatch' + TenantFilter = $TenantFilter + QueueName = "Storage Cleanup Scan Batch $BatchNumber/$TotalBatches - $TenantFilter" + BatchNumber = $BatchNumber + TotalBatches = $TotalBatches + Sites = @($SiteSeeds) + } + if ($QueueId) { + $BatchItem | Add-Member -NotePropertyName 'QueueId' -NotePropertyValue $QueueId -Force + } + [void]$Batches.Add($BatchItem) + } + + if ($QueueId -and $Batches.Count -gt 0) { + try { + Update-CippQueueEntry -RowKey $QueueId -TotalTasks $Batches.Count -IncrementTotalTasks + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Could not update queue $QueueId with StorageCleanupScan batch tasks: $($_.Exception.Message)" -sev Warning + } + } + + $InputObject = [PSCustomObject]@{ + Batch = @($Batches) + OrchestratorName = "StorageCleanupScan_$TenantFilter" + SkipLog = $true + PostExecution = @{ + FunctionName = 'StoreStorageCleanupScan' + Parameters = @{ + TenantFilter = $TenantFilter + ExpectedSiteCount = $ExpectedSiteCount + } + } + } + + $null = Start-CIPPOrchestrator -InputObject $InputObject + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Started StorageCleanupScan collection across $ExpectedSiteCount sites in $($Batches.Count) batches" -sev Debug + + } catch { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Failed to start StorageCleanupScan collection: $($_.Exception.Message)" -sev Error -LogData (Get-CippException -Exception $_) + } +} diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheTeamsResourceAccounts.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheTeamsResourceAccounts.ps1 index 6ae50e8ecfea3..021a0d1c81148 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheTeamsResourceAccounts.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheTeamsResourceAccounts.ps1 @@ -27,6 +27,9 @@ function Set-CIPPDBCacheTeamsResourceAccounts { if ($LicenseCheck -eq $false) { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Tenant does not have a Teams license, skipping Teams resource accounts' -sev Debug + # A license skip is still a completed collection: record the authoritative empty set + # so collect-on-miss does not re-run this collector forever on unlicensed tenants. + Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'TeamsResourceAccounts' -Data @() -AddCount -ClearOnEmpty return } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecAzBobbyTables.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecAzBobbyTables.ps1 index 4c7e5a7a4a7bf..287a6ef9714a0 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecAzBobbyTables.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecAzBobbyTables.ps1 @@ -12,6 +12,9 @@ function Invoke-ExecAzBobbyTables { #> [CmdletBinding()] param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers $AllowList = @( 'Add-AzDataTableEntity' 'Add-CIPPAzDataTableEntity' @@ -26,17 +29,20 @@ function Invoke-ExecAzBobbyTables { ) $Function = $Request.Body.FunctionName + $TableName = $Request.Body.TableName $Params = if ($Request.Body.Parameters) { $Request.Body.Parameters | ConvertTo-Json -Compress -ErrorAction Stop | ConvertFrom-Json -AsHashtable } else { @{} } + $ParamKeys = if ($Params.Keys) { @($Params.Keys) -join ', ' } else { 'none' } + $TableNote = if ($TableName) { " on table '$TableName'" } else { '' } if ($Function -in $AllowList) { if ($Function -eq 'Get-AzDataTable') { $Context = New-AzDataTableContext -ConnectionString $env:AzureWebJobsStorage } else { - $Context = New-AzDataTableContext -ConnectionString $env:AzureWebJobsStorage -TableName $Request.Body.TableName + $Context = New-AzDataTableContext -ConnectionString $env:AzureWebJobsStorage -TableName $TableName } try { $Results = & $Function -Context $Context @Params @@ -46,19 +52,22 @@ function Invoke-ExecAzBobbyTables { # Drop it from the Get-CIPPTable cache so it gets recreated on next use. The table # name comes from the request, so clear everything when it was not supplied. if ($Function -eq 'Remove-AzDataTable') { - if ($Request.Body.TableName) { - Unregister-CIPPTable -TableName $Request.Body.TableName + if ($TableName) { + Unregister-CIPPTable -TableName $TableName } else { Unregister-CIPPTable -All } } + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "SuperAdmin AzBobbyTables ran '$Function'$TableNote (param keys: $ParamKeys)" -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $Results = $_.Exception.Message + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "SuperAdmin AzBobbyTables '$Function' failed: $Results" -Sev 'Error' -LogData (Get-CippException -Exception $_) $StatusCode = [HttpStatusCode]::InternalServerError } } else { $Results = "Function $Function not found or not allowed" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "SuperAdmin AzBobbyTables blocked: $Results" -Sev 'Error' $StatusCode = [HttpStatusCode]::NotFound } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCIPPDBCache.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCIPPDBCache.ps1 index 0a4d9b5e1fe2b..bc8cb47b20358 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCIPPDBCache.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCIPPDBCache.ps1 @@ -29,6 +29,19 @@ function Invoke-ExecCIPPDBCache { throw 'TenantFilter parameter is required' } + # A derived cache type has no collector of its own — it is produced as a side-effect of + # another collector (e.g. SharePointSiteListing by Set-CIPPDBCacheSharePointSiteUsage). The + # registry's 'collectedBy' names that producing collector, so a run of the derived type runs + # it and populates the derived data. + $CacheTypesPath = Join-Path $env:CIPPRootPath 'Config/CIPPDBCacheTypes.json' + if (Test-Path $CacheTypesPath) { + $CollectedBy = ((Get-Content $CacheTypesPath -Raw | ConvertFrom-Json) | Where-Object { $_.type -eq $Name }).collectedBy + if ($CollectedBy) { + Write-Information "ExecCIPPDBCache: '$Name' is a derived cache type; running its producing collector '$CollectedBy'" + $Name = "$CollectedBy" + } + } + # Validate the function exists — on HttpOnly workers CIPPDB module isn't loaded, # so import it temporarily for validation (the actual execution runs on activity workers) $FunctionName = "Set-CIPPDBCache$Name" diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCIPPDBCacheAdmin.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCIPPDBCacheAdmin.ps1 new file mode 100644 index 0000000000000..691764831cfb4 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCIPPDBCacheAdmin.ps1 @@ -0,0 +1,149 @@ +function Invoke-ExecCIPPDBCacheAdmin { + <# + .SYNOPSIS + SuperAdmin browse / remove / empty for CIPPDB (CippReportingDB) cache collections. + + .DESCRIPTION + Typed alternative to Table Maintenance for the reporting cache. List returns decoded + cache objects stamped with CIPPPartitionKey / CIPPRowKey / CIPPETag so the UI can + delete by storage key. Empty clears an entire type for a tenant (or AllTenants). + + .FUNCTIONALITY + Entrypoint + .ROLE + CIPP.SuperAdmin.ReadWrite + #> + [CmdletBinding()] + param ( + $Request, + $TriggerMetadata + ) + + $APIName = $TriggerMetadata.FunctionName + $Body = $Request.Body + $Action = [string]$Body.Action + $TenantFilter = [string]$Body.TenantFilter + $Type = [string]$Body.Type + + if ([string]::IsNullOrWhiteSpace($Action)) { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @{ Results = 'Error: Action is required (List, Remove, Empty)' } + }) + } + + try { + switch ($Action) { + 'List' { + if ([string]::IsNullOrWhiteSpace($TenantFilter) -or [string]::IsNullOrWhiteSpace($Type)) { + throw 'List requires TenantFilter and Type' + } + + $IsAllTenants = $TenantFilter -eq 'AllTenants' + $DbTenant = if ($IsAllTenants) { 'allTenants' } else { $TenantFilter } + $Rows = @(Get-CIPPDbItem -TenantFilter $DbTenant -Type $Type) + $CountRowKey = "$Type-Count" + + $Results = foreach ($Row in $Rows) { + if ($Row.RowKey -eq $CountRowKey) { continue } + if ([string]::IsNullOrWhiteSpace($Row.Data)) { continue } + + try { + $Parsed = [CIPP.CippJson]::ConvertFromJson($Row.Data, $null) + } catch { + Write-Information "Skipping unparseable CippReportingDB row for '$($Row.PartitionKey)'/'$Type': $($_.Exception.Message)" + continue + } + + foreach ($Record in @($Parsed)) { + if ($Record -isnot [System.Management.Automation.PSObject] -and $Record -isnot [PSCustomObject]) { + $Record = [PSCustomObject]@{ Value = $Record } + } + $RecordProps = [ordered]@{ + CIPPPartitionKey = $Row.PartitionKey + CIPPRowKey = $Row.RowKey + CIPPETag = $Row.ETag + } + if ($IsAllTenants) { + $RecordProps['Tenant'] = $Row.PartitionKey + } + $Record | Add-Member -NotePropertyMembers $RecordProps -Force + $Record + } + } + + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = @{ Results = @($Results) } + }) + } + + 'Remove' { + if ([string]::IsNullOrWhiteSpace($Type)) { + throw 'Remove requires Type' + } + + $Rows = @($Body.Rows) + if ($Rows.Count -eq 0) { + throw 'Remove requires Rows with CIPPPartitionKey/CIPPRowKey (or PartitionKey/RowKey)' + } + + # Deduplicate by partition+row so array-unrolled List rows sharing one entity delete once + $Seen = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + $Removed = 0 + foreach ($Row in $Rows) { + $PartitionKey = [string]($Row.CIPPPartitionKey ?? $Row.PartitionKey ?? $TenantFilter) + $RowKey = [string]($Row.CIPPRowKey ?? $Row.RowKey) + $ETag = [string]($Row.CIPPETag ?? $Row.ETag) + if ([string]::IsNullOrWhiteSpace($PartitionKey) -or [string]::IsNullOrWhiteSpace($RowKey)) { + continue + } + $DedupKey = "$PartitionKey|$RowKey" + if (-not $Seen.Add($DedupKey)) { continue } + + $RemoveParams = @{ + TenantFilter = $PartitionKey + Type = $Type + RowKey = $RowKey + } + if ($ETag) { $RemoveParams.ETag = $ETag } + Remove-CIPPDbItem @RemoveParams + $Removed++ + } + + Write-LogMessage -API $APIName -tenant $TenantFilter -message "Removed $Removed $Type cache row(s)" -sev Warning + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = @{ Results = "Removed $Removed $Type cache row(s)" } + }) + } + + 'Empty' { + if ([string]::IsNullOrWhiteSpace($TenantFilter) -or [string]::IsNullOrWhiteSpace($Type)) { + throw 'Empty requires TenantFilter and Type' + } + + $ClearResult = Clear-CIPPDbCache -TenantFilter $TenantFilter -Type $Type + Write-LogMessage -API $APIName -tenant $TenantFilter -message "Emptied $Type cache for $($ClearResult.Tenant): $($ClearResult.RemovedCount) row(s)" -sev Warning + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = @{ + Results = "Emptied $Type cache for $($ClearResult.Tenant): $($ClearResult.RemovedCount) row(s) removed" + Details = $ClearResult + } + }) + } + + default { + throw "Unknown Action '$Action'. Use List, Remove, or Empty." + } + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API $APIName -tenant $TenantFilter -message "CIPPDB cache admin failed: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @{ Results = $ErrorMessage.NormalizedError } + }) + } +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCippFunction.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCippFunction.ps1 index 867ce9a67cb0d..4ec20a3a4521f 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCippFunction.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCippFunction.ps1 @@ -11,6 +11,9 @@ function Invoke-ExecCippFunction { #> [CmdletBinding()] param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers $BlockList = @( 'Get-GraphToken' 'Get-GraphTokenFromCert' @@ -28,6 +31,7 @@ function Invoke-ExecCippFunction { } else { @{} } + $ParamKeys = if ($Params.Keys) { @($Params.Keys) -join ', ' } else { 'none' } if (Get-Command -Module CIPPCore -Name $Function -and $BlockList -notcontains $Function) { try { @@ -35,13 +39,16 @@ function Invoke-ExecCippFunction { if (!$Results) { $Results = "Function $Function executed successfully" } + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "SuperAdmin CippFunction ran '$Function' (param keys: $ParamKeys)" -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $Results = $_.Exception.Message + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "SuperAdmin CippFunction '$Function' failed: $Results" -Sev 'Error' -LogData (Get-CippException -Exception $_) $StatusCode = [HttpStatusCode]::InternalServerError } } else { $Results = "Function $Function not found or not allowed" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "SuperAdmin CippFunction blocked: $Results" -Sev 'Error' $StatusCode = [HttpStatusCode]::NotFound } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCloneTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCloneTemplate.ps1 index 03489fb5602fe..6706fbeba1f4d 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCloneTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecCloneTemplate.ps1 @@ -10,6 +10,9 @@ function Invoke-ExecCloneTemplate { $TriggerMetadata ) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $GUID = $Request.Query.GUID ?? $Request.Body.GUID $Type = $Request.Query.Type ?? $Request.Body.Type @@ -31,6 +34,8 @@ function Invoke-ExecCloneTemplate { } try { Add-CIPPAzDataTableEntity @Table -Entity $Template + $Result = "Template cloned successfully (Type=$Type, NewGuid=$NewGuid)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $body = @{ Results = @{ state = 'success' @@ -38,11 +43,14 @@ function Invoke-ExecCloneTemplate { } } } catch { + $ErrorMessage = Get-CIPPException -Exception $_ + $Result = "Failed to clone template (Type=$Type, GUID=$GUID): $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' -LogData $ErrorMessage $body = @{ Results = @{ state = 'error' resultText = 'Failed to clone template' - details = Get-CIPPException -Exception $_ + details = $ErrorMessage } } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecDiagnosticsPresets.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecDiagnosticsPresets.ps1 index b7503b35dd12b..8241a2765d4e8 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecDiagnosticsPresets.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecDiagnosticsPresets.ps1 @@ -11,6 +11,9 @@ function Invoke-ExecDiagnosticsPresets { $TriggerMetadata ) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + try { $Table = Get-CIPPTable -TableName 'DiagnosticsPresets' $Action = $Request.Body.action @@ -31,6 +34,9 @@ function Invoke-ExecDiagnosticsPresets { RowKey = $GUID } + $Result = "Diagnostics preset deleted successfully (GUID=$GUID)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' + return [HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK Body = @{ @@ -68,6 +74,9 @@ function Invoke-ExecDiagnosticsPresets { Add-CIPPAzDataTableEntity @Table -Entity $Entity -Force + $Result = "Diagnostics preset saved successfully (Name=$Name, GUID=$GUID)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' + return [HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK Body = @{ @@ -79,10 +88,12 @@ function Invoke-ExecDiagnosticsPresets { } } } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Failed to manage diagnostics preset: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage return [HttpResponseContext]@{ StatusCode = [HttpStatusCode]::InternalServerError Body = @{ - Error = "Failed to manage diagnostics preset: $($_.Exception.Message)" + Error = "Failed to manage diagnostics preset: $($ErrorMessage.NormalizedError)" } } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecEditTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecEditTemplate.ps1 index 4a3076e6aef86..8b89cc8960380 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecEditTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecEditTemplate.ps1 @@ -88,12 +88,12 @@ function Invoke-ExecEditTemplate { SHA = '' } Add-CIPPAzDataTableEntity @Table -Entity $Entity -OperationType 'UpsertMerge' - Write-LogMessage -headers $Request.Headers -API $APINAME -message "Edited template $($Request.Body.name) with GUID $GUID" -Sev 'Debug' + Write-LogMessage -headers $Request.Headers -API $APINAME -tenant 'Global' -message "Edited template $($Request.Body.name) with GUID $GUID" -Sev 'Info' } $body = [pscustomobject]@{ 'Results' = 'Successfully saved the template' } } catch { - Write-LogMessage -headers $Request.Headers -API $APINAME -message "Failed to edit template: $($_.Exception.Message)" -Sev 'Error' + Write-LogMessage -headers $Request.Headers -API $APINAME -tenant 'Global' -message "Failed to edit template: $($_.Exception.Message)" -Sev 'Error' $body = [pscustomobject]@{'Results' = "Editing template failed: $($_.Exception.Message)" } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecPartnerWebhook.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecPartnerWebhook.ps1 index 82a6bc823ad30..ba953bef9c01a 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecPartnerWebhook.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecPartnerWebhook.ps1 @@ -82,6 +82,8 @@ function Invoke-ExecPartnerWebhook { StandardsExcludeAllTenants = $Request.Body.standardsExcludeAllTenants } Add-CIPPAzDataTableEntity @ConfigTable -Entity $PartnerWebhookOnboarding -Force | Out-Null + # Subscription create/update is logged by New-CIPPGraphSubscription; log the onboarding config write here. + Write-LogMessage -headers $Request.Headers -API ($Request.Params.CIPPEndpoint) -tenant 'Global' -message "Partner webhook onboarding config saved (Enabled=$([bool]$Request.Body.enabled))" -Sev 'Info' } 'SendTest' { $Results = New-GraphPOSTRequest -uri 'https://api.partnercenter.microsoft.com/webhooks/v1/registration/validationEvents' -tenantid $env:TenantID -NoAuthCheck $true -scope 'https://api.partnercenter.microsoft.com/.default' @@ -106,3 +108,4 @@ function Invoke-ExecPartnerWebhook { Body = $Body } } + diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecServicePrincipals.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecServicePrincipals.ps1 index 1c3fd744bf4c9..0e2a9a82225cc 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecServicePrincipals.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ExecServicePrincipals.ps1 @@ -7,6 +7,8 @@ function Invoke-ExecServicePrincipals { #> [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers $TenantFilter = $env:TenantID $Success = $true @@ -30,6 +32,7 @@ function Invoke-ExecServicePrincipals { if ($BlockList -contains $Request.Query.AppId) { $Results = 'Service Principal creation is blocked for this AppId' $Success = $false + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Results -Sev 'Error' } else { $Body = @{ 'appId' = $Request.Query.AppId @@ -37,14 +40,18 @@ function Invoke-ExecServicePrincipals { try { $ServicePrincipal = New-GraphPostRequest -Uri 'https://graph.microsoft.com/beta/servicePrincipals' -tenantid $TenantFilter -type POST -body $Body -NoAuthCheck $true $Results = "Created service principal for $($ServicePrincipal.displayName) ($($ServicePrincipal.appId))" + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Results -Sev 'Info' } catch { - $Results = "Unable to create service principal: $($_.Exception.Message)" + $ErrorMessage = Get-CippException -Exception $_ + $Results = "Unable to create service principal: $($ErrorMessage.NormalizedError)" $Success = $false + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Results -Sev 'Error' -LogData $ErrorMessage } } } else { $Results = 'Invalid AppId' $Success = $false + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Results -Sev 'Error' } } default { @@ -66,8 +73,12 @@ function Invoke-ExecServicePrincipals { } } } catch { - $Results = $_.Exception.Message + $ErrorMessage = Get-CippException -Exception $_ + $Results = $ErrorMessage.NormalizedError $Success = $false + if ($Action -eq 'Create') { + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Failed to create service principal: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage + } } $Metadata = @{ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ListGraphRequest.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ListGraphRequest.ps1 index d67a467f99665..b9e71e5062c74 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ListGraphRequest.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ListGraphRequest.ps1 @@ -99,6 +99,13 @@ function Invoke-ListGraphRequest { $GraphRequestParams.ManualPagination = [System.Convert]::ToBoolean($Request.Query.manualPagination) } + # $top is Graph's page size, so $top=1 with pagination fetches the entire collection one + # record per round trip. A caller asking for 1 wants one record; only an explicit + # NoPagination/manualPagination overrides this. + if ($Parameters.'$top' -eq '1' -and $null -eq $Request.Query.NoPagination -and $null -eq $Request.Query.manualPagination) { + $GraphRequestParams.NoPagination = $true + } + # Continue a manualPagination walk: pass back the @odata.nextLink returned with the # previous page. Endpoint is still required, and the other query options are already # encoded in the link. @@ -106,6 +113,12 @@ function Invoke-ListGraphRequest { $GraphRequestParams.nextLink = $Request.Query.nextLink } + # Paged AllTenants cache reads only: target page size in bytes of raw JSON, clamped + # between 262144 and 8388608 (default 4000000). Pages always hold at least one whole tenant. + if ($Request.Query.maxPageBytes -as [int]) { + $GraphRequestParams.MaxPageBytes = [int]$Request.Query.maxPageBytes + } + # Return just the number of matching records instead of the records themselves. The # cheapest way to size a collection before deciding whether to fetch it. if ($Request.Query.CountOnly) { @@ -158,6 +171,27 @@ function Invoke-ListGraphRequest { $Metadata.GraphHeaders = $script:LastGraphResponseHeaders } + # Paged AllTenants cache serve: one page of tenant blobs plus Metadata.nextLink. + if ($UseRawJson -and $Results -isnot [string] -and $Results.PSObject.Properties.Name -contains 'CippPagedJson') { + if ($Request.Headers.'x-ms-coldstart' -eq 1) { + $Metadata.ColdStart = $true + } + if ($Results.CippNextLink) { + $Metadata.nextLink = $Results.CippNextLink + } else { + # Do not echo the incoming token back on the final page. + $Metadata.Remove('nextLink') + } + $MetadataJson = ConvertTo-Json -InputObject $Metadata -Depth 5 -Compress + $GraphRequestData = '{"Results":' + $Results.CippPagedJson + ',"Metadata":' + $MetadataJson + '}' + + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + ContentType = 'application/json' + Body = $GraphRequestData + }) + } + # RawJsonArray returns a JSON string directly — skip object-level processing if ($UseRawJson -and $Results -is [string] -and $Results.StartsWith('[')) { if ($Request.Headers.'x-ms-coldstart' -eq 1) { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ListLogs.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ListLogs.ps1 index 204640c5f11b1..9a9df64ef972a 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ListLogs.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-ListLogs.ps1 @@ -5,64 +5,91 @@ function Invoke-ListLogs { .ROLE CIPP.Core.Read .DESCRIPTION - Lists CIPP platform audit logs with filtering by severity, date range, tenant, and user. Supports listing available log categories. + Lists CIPP platform audit logs with filtering by severity, date range, tenant, and user. Supports listing available log categories, fetching a single entry, and server-side pagination via manualPagination/nextLink. #> [CmdletBinding()] param($Request, $TriggerMetadata) $Table = Get-CIPPTable $TzId = if ($env:CIPP_TIMEZONE) { $env:CIPP_TIMEZONE } else { 'UTC' } + $LocalNow = [TimeZoneInfo]::ConvertTimeBySystemTimeZoneId([DateTime]::UtcNow, $TzId) - $TemplatesTable = Get-CIPPTable -tablename 'templates' - $Templates = Get-CIPPAzDataTableEntity @TemplatesTable + function Get-LogStandardInfo { + param($Row, $Templates) + if (-not $Row.StandardTemplateId) { return @{} } + $Standard = ($Templates | Where-Object { $_.RowKey -eq $Row.StandardTemplateId }).JSON | ConvertFrom-Json - $ReturnedLog = if ($Request.Query.ListLogs) { - Get-AzDataTableEntity @Table -Property PartitionKey | Sort-Object -Unique PartitionKey | Select-Object PartitionKey | ForEach-Object { + $StandardInfo = @{ + Template = $Standard.templateName + Standard = $Row.Standard + } + + if ($Row.IntuneTemplateId) { + $IntuneTemplate = ($Templates | Where-Object { $_.RowKey -eq $Row.IntuneTemplateId }).JSON | ConvertFrom-Json + $StandardInfo.IntunePolicy = $IntuneTemplate.displayName + } + if ($Row.ConditionalAccessTemplateId) { + $ConditionalAccessTemplate = ($Templates | Where-Object { $_.RowKey -eq $Row.ConditionalAccessTemplateId }).JSON | ConvertFrom-Json + $StandardInfo.ConditionalAccessPolicy = $ConditionalAccessTemplate.displayName + } + return $StandardInfo + } + + if ($Request.Query.ListLogs) { + $ReturnedLog = Get-CIPPAzDataTableEntity @Table -Property PartitionKey | Sort-Object -Unique PartitionKey | Select-Object PartitionKey | ForEach-Object { @{ value = $_.PartitionKey label = $_.PartitionKey } } - } elseif ($Request.Query.logentryid) { - # Return single log entry by RowKey - $LocalNow = [TimeZoneInfo]::ConvertTimeBySystemTimeZoneId([DateTime]::UtcNow, $TzId) - $DateFilter = ConvertTo-CIPPODataFilterValue -Value ($Request.Query.DateFilter ?? $LocalNow.ToString('yyyyMMdd')) -Type Date - $SafeLogEntryId = ConvertTo-CIPPODataFilterValue -Value $Request.Query.logentryid -Type Guid - $Filter = "RowKey eq '{0}' and PartitionKey eq '{1}'" -f $SafeLogEntryId, $DateFilter + return [HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = @($ReturnedLog) + } + } + + if ($Request.Query.logentryid) { + # Return single log entry by RowKey. RowKeys are either legacy GUIDs or the + # inverted-ticks format Write-LogMessage writes; both use only hex digits and hyphens. + $LogEntryId = [string]$Request.Query.logentryid + if ($LogEntryId -notmatch '^[0-9a-fA-F-]{1,64}$') { + throw "Invalid log entry id format: '$LogEntryId'" + } + $DateFilter = if ($Request.Query.DateFilter) { + ConvertTo-CIPPODataFilterValue -Value $Request.Query.DateFilter -Type Date + } elseif ($LogEntryId -match '^(?\d{19})-') { + # New-format RowKeys embed the write time, so links without a dateFilter (e.g. from + # the API logs drawer) resolve regardless of which day the entry was written. + try { + $Ticks = [DateTime]::MaxValue.Ticks - [long]$Matches.Inverted + [TimeZoneInfo]::ConvertTimeBySystemTimeZoneId([DateTime]::new($Ticks, [DateTimeKind]::Utc), $TzId).ToString('yyyyMMdd') + } catch { + $LocalNow.ToString('yyyyMMdd') + } + } else { + $LocalNow.ToString('yyyyMMdd') + } + $Filter = "RowKey eq '{0}' and PartitionKey eq '{1}'" -f $LogEntryId, $DateFilter $AllowedTenants = Test-CIPPAccess -Request $Request -TenantList - Write-Host "Getting single log entry for RowKey: $($Request.Query.logentryid)" + Write-Host "Getting single log entry for RowKey: $LogEntryId" - $Row = Get-AzDataTableEntity @Table -Filter $Filter + $Row = Get-CIPPAzDataTableEntity @Table -Filter $Filter - if ($Row) { + $ReturnedLog = if ($Row) { if ($AllowedTenants -notcontains 'AllTenants') { $TenantList = Get-Tenants -IncludeErrors | Where-Object { $_.customerId -in $AllowedTenants } } if ($AllowedTenants -contains 'AllTenants' -or ($AllowedTenants -notcontains 'AllTenants' -and ($TenantList.defaultDomainName -contains $Row.Tenant -or $Row.Tenant -eq 'CIPP' -or $TenantList.customerId -contains $Row.TenantId -or $TenantList.initialDomainName -contains $Row.Tenant)) ) { - if ($Row.StandardTemplateId) { - $Standard = ($Templates | Where-Object { $_.RowKey -eq $Row.StandardTemplateId }).JSON | ConvertFrom-Json - - $StandardInfo = @{ - Template = $Standard.templateName - Standard = $Row.Standard - } - - if ($Row.IntuneTemplateId) { - $IntuneTemplate = ($Templates | Where-Object { $_.RowKey -eq $Row.IntuneTemplateId }).JSON | ConvertFrom-Json - $StandardInfo.IntunePolicy = $IntuneTemplate.displayName - } - if ($Row.ConditionalAccessTemplateId) { - $ConditionalAccessTemplate = ($Templates | Where-Object { $_.RowKey -eq $Row.ConditionalAccessTemplateId }).JSON | ConvertFrom-Json - $StandardInfo.ConditionalAccessPolicy = $ConditionalAccessTemplate.displayName - } - - } else { - $StandardInfo = @{} - } - + $StandardInfo = if ($Row.StandardTemplateId) { + $TemplatesTable = Get-CIPPTable -tablename 'templates' + $Templates = Get-CIPPAzDataTableEntity @TemplatesTable + Get-LogStandardInfo -Row $Row -Templates $Templates + } else { @{} } $LogData = if ($Row.LogData -and (Test-Json -Json $Row.LogData -ErrorAction SilentlyContinue)) { $Row.LogData | ConvertFrom-Json } else { $Row.LogData } + # Same record shape as the list paths below, except the log entry page reads + # the template info as 'Standard' rather than 'StandardInfo'. [PSCustomObject]@{ DateTime = $Row.Timestamp Tenant = $Row.Tenant @@ -84,118 +111,235 @@ function Invoke-ListLogs { } } } - } else { - if ($request.Query.Filter -eq $true) { - $LogLevel = if ($Request.Query.Severity) { ($Request.query.Severity).split(',') } else { 'Info', 'Warn', 'Warning', 'Error', 'Critical', 'Alert' } - $PartitionKey = $Request.Query.DateFilter - $username = $Request.Query.User ?? '*' - $TenantFilter = $Request.Query.Tenant - $ApiFilter = $Request.Query.API - $StandardFilter = $Request.Query.StandardTemplateId - $ScheduledTaskFilter = $Request.Query.ScheduledTaskId - $BaselineRunFilter = $Request.Query.BaselineRunId - - $StartDate = if ($Request.Query.StartDate ?? $Request.Query.DateFilter) { ConvertTo-CIPPODataFilterValue -Value ($Request.Query.StartDate ?? $Request.Query.DateFilter) -Type Date } else { $null } - $EndDate = if ($Request.Query.EndDate ?? $Request.Query.DateFilter) { ConvertTo-CIPPODataFilterValue -Value ($Request.Query.EndDate ?? $Request.Query.DateFilter) -Type Date } else { $null } - - if ($StartDate -and $EndDate) { - $Filter = "PartitionKey ge '$StartDate' and PartitionKey le '$EndDate'" - } elseif ($StartDate) { - $Filter = "PartitionKey eq '{0}'" -f $StartDate - } else { - $Filter = "PartitionKey eq '{0}'" -f [TimeZoneInfo]::ConvertTimeBySystemTimeZoneId([DateTime]::UtcNow, $TzId).ToString('yyyyMMdd') - } - } else { - $LogLevel = 'Info', 'Warn', 'Warning', 'Error', 'Critical', 'Alert' - $PartitionKey = [TimeZoneInfo]::ConvertTimeBySystemTimeZoneId([DateTime]::UtcNow, $TzId).ToString('yyyyMMdd') - $username = '*' - $TenantFilter = $null - $ApiFilter = $null - $StandardFilter = $null - $ScheduledTaskFilter = $null - $BaselineRunFilter = $null - $Filter = "PartitionKey eq '{0}'" -f $PartitionKey + return [HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = @($ReturnedLog) } + } - # Severity stays client-side: Azurite/Azure Table OData has been unreliable - # on long OR chains. Per-partition row counts are small enough that this is fine. - if ($StandardFilter) { - $SafeStd = ConvertTo-CIPPODataFilterValue -Value $StandardFilter -Type Guid - $Filter = "$Filter and StandardTemplateId eq '$SafeStd'" + # When true, the Severity/User/Tenant/API/StartDate/EndDate query filters are applied; otherwise the current day is returned unfiltered. + if ($Request.Query.Filter -eq $true) { + $LogLevel = if ($Request.Query.Severity) { ($Request.Query.Severity).split(',') } else { 'Info', 'Warn', 'Warning', 'Error', 'Critical', 'Alert' } + $Username = $Request.Query.User ?? '*' + $TenantFilter = $Request.Query.Tenant + $ApiFilter = $Request.Query.API + $StandardFilter = $Request.Query.StandardTemplateId + $ScheduledTaskFilter = $Request.Query.ScheduledTaskId + $BaselineRunFilter = $Request.Query.BaselineRunId + $StartDateRaw = $Request.Query.StartDate ?? $Request.Query.DateFilter + $EndDateRaw = $Request.Query.EndDate ?? $Request.Query.DateFilter + } else { + $LogLevel = 'Info', 'Warn', 'Warning', 'Error', 'Critical', 'Alert' + $Username = '*' + $TenantFilter = $null + $ApiFilter = $null + $StandardFilter = $null + $ScheduledTaskFilter = $null + $BaselineRunFilter = $null + $StartDateRaw = $null + $EndDateRaw = $null + } + + $StartDate = if ($StartDateRaw) { ConvertTo-CIPPODataFilterValue -Value $StartDateRaw -Type Date } else { $null } + $EndDate = if ($EndDateRaw) { ConvertTo-CIPPODataFilterValue -Value $EndDateRaw -Type Date } else { $null } + + # Days=N widens a filtered query to the last N calendar days (in the instance timezone), + # so the scoped drawers still show a run that finished last night. Ignored when dates are given. + $Days = if ($Request.Query.Filter -eq $true) { $Request.Query.Days -as [int] } else { 0 } + if (-not $StartDate -and -not $EndDate -and $Days -gt 0) { + $StartDate = $LocalNow.Date.AddDays(-([Math]::Min($Days, 90) - 1)).ToString('yyyyMMdd') + $EndDate = $LocalNow.ToString('yyyyMMdd') + } + + # Severity stays client-side: Azurite/Azure Table OData has been unreliable + # on long OR chains. Per-partition row counts are small enough that this is fine. + $ServerSideFilter = [System.Collections.Generic.List[string]]::new() + if ($StandardFilter) { + $SafeStd = ConvertTo-CIPPODataFilterValue -Value $StandardFilter -Type Guid + $ServerSideFilter.Add("StandardTemplateId eq '$SafeStd'") + } + if ($ScheduledTaskFilter) { + $SafeSched = ConvertTo-CIPPODataFilterValue -Value $ScheduledTaskFilter -Type Guid + $ServerSideFilter.Add("ScheduledTaskId eq '$SafeSched'") + } + if ($BaselineRunFilter) { + $SafeRun = ConvertTo-CIPPODataFilterValue -Value $BaselineRunFilter -Type Guid + $ServerSideFilter.Add("BaselineRunId eq '$SafeRun'") + } + + $AllowedTenants = Test-CIPPAccess -Request $Request -TenantList + if ($AllowedTenants -notcontains 'AllTenants') { + $TenantList = Get-Tenants -IncludeErrors | Where-Object { $_.customerId -in $AllowedTenants } + } + + # Templates are only needed to resolve StandardInfo names, and only the scheduled-task + # view renders those - skip the extra table read everywhere else. + $Templates = if ($ScheduledTaskFilter) { + $TemplatesTable = Get-CIPPTable -tablename 'templates' + Get-CIPPAzDataTableEntity @TemplatesTable + } else { $null } + + # The row-level filters that cannot (or should not) go into the table query. + $RowFilter = { + param($Row) + $Row.Severity -in $LogLevel -and + ($Username -eq '*' -or $Row.Username -like $Username) -and + ([string]::IsNullOrEmpty($TenantFilter) -or $TenantFilter -eq 'AllTenants' -or $Row.Tenant -like "*$TenantFilter*" -or $Row.TenantID -eq $TenantFilter) -and + ([string]::IsNullOrEmpty($ApiFilter) -or $Row.API -match "$ApiFilter") -and + ($AllowedTenants -contains 'AllTenants' -or $TenantList.defaultDomainName -contains $Row.Tenant -or $Row.Tenant -eq 'CIPP' -or $TenantList.customerId -contains $Row.TenantId) + } + + # Return one page per request plus a continuation token in Metadata.nextLink, which the + # frontend passes back as nextLink to fetch the next page. Pages walk the requested date + # range newest-day-first and, within a day, in RowKey order (newest-first for entries + # written with the inverted-ticks RowKey scheme). + if ($Request.Query.manualPagination -and [System.Convert]::ToBoolean($Request.Query.manualPagination)) { + $PageSize = 400 + # Rows to return per page, clamped between 50 and 1000. Defaults to 400. + if ($Request.Query.PageSize -as [int]) { + $PageSize = [Math]::Min([Math]::Max([int]$Request.Query.PageSize, 50), 1000) } - if ($ScheduledTaskFilter) { - $SafeSched = ConvertTo-CIPPODataFilterValue -Value $ScheduledTaskFilter -Type Guid - $Filter = "$Filter and ScheduledTaskId eq '$SafeSched'" + # Bound the table round trips a single request can make, so a filter that matches + # nothing across many partitions returns a short (possibly empty) page with a + # nextLink instead of scanning until the gateway times out. + $MaxQueries = 10 + + $ParseDay = { + param($Value) + # ConvertTo-CIPPODataFilterValue has already validated the shape; normalize + # yyyy-MM-dd / ISO datetime forms down to a date. + [datetime]::ParseExact(($Value -replace '-', '').Substring(0, 8), 'yyyyMMdd', [cultureinfo]::InvariantCulture) } - if ($BaselineRunFilter) { - $SafeRun = ConvertTo-CIPPODataFilterValue -Value $BaselineRunFilter -Type Guid - $Filter = "$Filter and BaselineRunId eq '$SafeRun'" + $EndDay = if ($EndDate) { & $ParseDay $EndDate } elseif ($StartDate) { & $ParseDay $StartDate } else { $LocalNow.Date } + $StartDay = if ($StartDate) { & $ParseDay $StartDate } else { $EndDay } + if (($EndDay - $StartDay).TotalDays -gt 366) { $StartDay = $EndDay.AddDays(-366) } + + $CursorDay = $EndDay + $LastRowKey = $null + # Continuation token from the previous page's Metadata.nextLink; opaque to callers. + if ($Request.Query.nextLink) { + $TokenParts = ([string]$Request.Query.nextLink).Split('|', 2) + $CursorDay = [datetime]::ParseExact($TokenParts[0], 'yyyyMMdd', [cultureinfo]::InvariantCulture) + if ($CursorDay -gt $EndDay) { $CursorDay = $EndDay } + if ($TokenParts.Count -eq 2 -and $TokenParts[1]) { + $LastRowKey = $TokenParts[1] + } } - $AllowedTenants = Test-CIPPAccess -Request $Request -TenantList - Write-Host "Getting logs for filter: $Filter, LogLevel: $LogLevel, Username: $username" - - if ($AllowedTenants -notcontains 'AllTenants') { - $TenantList = Get-Tenants -IncludeErrors | Where-Object { $_.customerId -in $AllowedTenants } - } - - $ReturnedLog = Get-AzDataTableEntity @Table -Filter $Filter | Where-Object { - $_.Severity -in $LogLevel -and - ($username -eq '*' -or $_.Username -like $username) -and - ([string]::IsNullOrEmpty($TenantFilter) -or $TenantFilter -eq 'AllTenants' -or $_.Tenant -like "*$TenantFilter*" -or $_.TenantID -eq $TenantFilter) -and - ([string]::IsNullOrEmpty($ApiFilter) -or $_.API -match "$ApiFilter") -and - ($AllowedTenants -contains 'AllTenants' -or $TenantList.defaultDomainName -contains $_.Tenant -or $_.Tenant -eq 'CIPP' -or $TenantList.customerId -contains $_.TenantId) - } | ForEach-Object { - $Row = $_ - if ($ScheduledTaskFilter -and $Row.StandardTemplateId) { - $Standard = ($Templates | Where-Object { $_.RowKey -eq $Row.StandardTemplateId }).JSON | ConvertFrom-Json - - $StandardInfo = @{ - Template = $Standard.templateName - Standard = $Row.Standard - } + $Rows = [System.Collections.Generic.List[object]]::new() + $Queries = 0 + $Exhausted = $CursorDay -lt $StartDay + while (-not $Exhausted -and $Queries -lt $MaxQueries -and $Rows.Count -lt $PageSize) { + $Filter = "PartitionKey eq '{0}'" -f $CursorDay.ToString('yyyyMMdd') + if ($LastRowKey) { + $SafeRowKey = ConvertTo-CIPPODataFilterValue -Value $LastRowKey -Type String + # '~' sorts after every character valid in these RowKeys, so this resumes + # strictly after the last returned entity including any of its '-partN' + # split-entity continuation rows. + $Filter = "$Filter and RowKey gt '$SafeRowKey~'" + } + foreach ($Clause in $ServerSideFilter) { $Filter = "$Filter and $Clause" } - if ($Row.IntuneTemplateId) { - $IntuneTemplate = ($Templates | Where-Object { $_.RowKey -eq $Row.IntuneTemplateId }).JSON | ConvertFrom-Json - $StandardInfo.IntunePolicy = $IntuneTemplate.displayName - } - if ($Row.ConditionalAccessTemplateId) { - $ConditionalAccessTemplate = ($Templates | Where-Object { $_.RowKey -eq $Row.ConditionalAccessTemplateId }).JSON | ConvertFrom-Json - $StandardInfo.ConditionalAccessPolicy = $ConditionalAccessTemplate.displayName + $Chunk = @(Get-CIPPAzDataTableEntity @Table -Filter $Filter -First $PageSize) + $Queries++ + if ($Chunk.Count -gt 0) { + $LastRowKey = $Chunk[-1].RowKey + foreach ($Row in $Chunk) { + if (& $RowFilter $Row) { + $StandardInfo = if ($ScheduledTaskFilter) { Get-LogStandardInfo -Row $Row -Templates $Templates } else { @{} } + $LogData = if ($Row.LogData -and (Test-Json -Json $Row.LogData -ErrorAction SilentlyContinue)) { + $Row.LogData | ConvertFrom-Json + } else { $Row.LogData } + # Keep this record shape identical to the legacy list path below - the + # frontend treats paged and unpaged rows interchangeably. + $Rows.Add([PSCustomObject]@{ + DateTime = $Row.Timestamp + Tenant = $Row.Tenant + API = $Row.API + Message = $Row.Message + User = $Row.Username + Severity = $Row.Severity + LogData = $LogData + TenantID = if ($null -ne $Row.TenantID) { + $Row.TenantID + } else { + 'None' + } + AppId = $Row.AppId + IP = $Row.IP + RowKey = $Row.RowKey + StandardInfo = $StandardInfo + DateFilter = $Row.PartitionKey + }) + } } } else { - $StandardInfo = @{} + # -First counts physical rows before split-entity reassembly, so a short + # chunk does not prove the partition is drained; only an empty one does. + $CursorDay = $CursorDay.AddDays(-1) + $LastRowKey = $null + if ($CursorDay -lt $StartDay) { $Exhausted = $true } } + } - $LogData = if ($Row.LogData -and (Test-Json -Json $Row.LogData -ErrorAction SilentlyContinue)) { - $Row.LogData | ConvertFrom-Json - } else { $Row.LogData } - [PSCustomObject]@{ - DateTime = $Row.Timestamp - Tenant = $Row.Tenant - API = $Row.API - Message = $Row.Message - User = $Row.Username - Severity = $Row.Severity - LogData = $LogData - TenantID = if ($null -ne $Row.TenantID) { - $Row.TenantID - } else { - 'None' - } - AppId = $Row.AppId - IP = $Row.IP - RowKey = $Row.RowKey - StandardInfo = $StandardInfo - DateFilter = $Row.PartitionKey + $Metadata = @{} + if (-not $Exhausted) { + $Metadata.nextLink = '{0}|{1}' -f $CursorDay.ToString('yyyyMMdd'), $LastRowKey + } + return [HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = [PSCustomObject]@{ + # Walk order is already newest-first for inverted-ticks RowKeys, and more + # truthful than re-sorting on the table Timestamp, which jitters at ms + # granularity for near-simultaneous writes. Rows from pre-scheme GUID-keyed + # partitions arrive unordered; the logs table sorts by DateTime client-side. + Results = @($Rows) + Metadata = $Metadata } } - $ReturnedLog + } + + # Legacy unpaginated path: fetch the whole requested range in one go and return a bare + # array. Kept for callers that do not speak the Results/Metadata pagination contract. + if ($StartDate -and $EndDate) { + $Filter = "PartitionKey ge '$StartDate' and PartitionKey le '$EndDate'" + } elseif ($StartDate) { + $Filter = "PartitionKey eq '{0}'" -f $StartDate + } else { + $Filter = "PartitionKey eq '{0}'" -f $LocalNow.ToString('yyyyMMdd') + } + foreach ($Clause in $ServerSideFilter) { $Filter = "$Filter and $Clause" } + Write-Host "Getting logs for filter: $Filter, LogLevel: $LogLevel, Username: $Username" + + $ReturnedLog = Get-CIPPAzDataTableEntity @Table -Filter $Filter | Where-Object { & $RowFilter $_ } | ForEach-Object { + $Row = $_ + $StandardInfo = if ($ScheduledTaskFilter) { Get-LogStandardInfo -Row $Row -Templates $Templates } else { @{} } + $LogData = if ($Row.LogData -and (Test-Json -Json $Row.LogData -ErrorAction SilentlyContinue)) { + $Row.LogData | ConvertFrom-Json + } else { $Row.LogData } + [PSCustomObject]@{ + DateTime = $Row.Timestamp + Tenant = $Row.Tenant + API = $Row.API + Message = $Row.Message + User = $Row.Username + Severity = $Row.Severity + LogData = $LogData + TenantID = if ($null -ne $Row.TenantID) { + $Row.TenantID + } else { + 'None' + } + AppId = $Row.AppId + IP = $Row.IP + RowKey = $Row.RowKey + StandardInfo = $StandardInfo + DateFilter = $Row.PartitionKey + } } return [HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK Body = @($ReturnedLog | Sort-Object -Property DateTime -Descending) } - } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-RemoveCippQueue.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-RemoveCippQueue.ps1 index 6b664705e8fb3..77b78d5ca6189 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-RemoveCippQueue.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Core/Invoke-RemoveCippQueue.ps1 @@ -8,7 +8,17 @@ function Invoke-RemoveCippQueue { [CmdletBinding()] param($Request, $TriggerMetadata) - $Results = Clear-CIPPQueueData -Request $Request -TriggerMetadata $TriggerMetadata + $APIName = $Request.Params.CIPPEndpoint ?? 'RemoveCippQueue' + $Headers = $Request.Headers + + try { + $Results = Clear-CIPPQueueData -Request $Request -TriggerMetadata $TriggerMetadata + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message 'History cleared' -Sev 'Info' + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Failed to clear queue history: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage + $Results = @{Results = @("Failed to clear queue history: $($ErrorMessage.NormalizedError)") } + } return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionClearHIBPKey.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionClearHIBPKey.ps1 index c7a6f656047dd..5bde54b7b03ae 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionClearHIBPKey.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionClearHIBPKey.ps1 @@ -8,11 +8,18 @@ function Invoke-ExecExtensionClearHIBPKey { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint ?? 'ExtensionClearHIBPKey' + $Headers = $Request.Headers + $Results = try { Remove-ExtensionAPIKey -Extension 'HIBP' | Out-Null - 'Successfully cleared the HIBP API key.' + $Result = 'Successfully cleared the HIBP API key.' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Cleared API key for extension 'HIBP'" -Sev 'Info' + $Result } catch { - "Failed to clear the HIBP API key" + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Failed to clear API key for extension 'HIBP': $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage + 'Failed to clear the HIBP API key' } return ([HttpResponseContext]@{ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionMapping.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionMapping.ps1 index 5179bfdc3d0ee..65929d8da7930 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionMapping.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionMapping.ps1 @@ -38,10 +38,13 @@ Function Invoke-ExecExtensionMapping { # Outcomes and priorities are scoped to a ticket type. The settings page sends the # ticket type currently selected in the form so the lists follow the dropdown; without # it both fall back to whatever ticket type was last saved. + # @() on each: PowerShell unrolls single-element output, so a ticket type with one outcome + # (or a lookup that answers with a single explanatory row) would otherwise serialise as a + # bare object and break callers that expect a list. $SelectedTicketType = $Request.Query.TicketType - $TicketTypes = Get-HaloTicketType - $Outcomes = Get-HaloTicketOutcome -TicketType $SelectedTicketType - $Priorities = Get-HaloPriority -TicketType $SelectedTicketType + $TicketTypes = @(Get-HaloTicketType) + $Outcomes = @(Get-HaloTicketOutcome -TicketType $SelectedTicketType) + $Priorities = @(Get-HaloPriority -TicketType $SelectedTicketType) $Result = @{ 'TicketTypes' = $TicketTypes 'Outcomes' = $Outcomes @@ -110,7 +113,7 @@ Function Invoke-ExecExtensionMapping { catch { $ErrorMessage = Get-CippException -Exception $_ $Result = "Mapping API failed. $($ErrorMessage.NormalizedError)" - Write-LogMessage -API $APIName -headers $Headers -message $Result -Sev 'Error' -LogData $ErrorMessage + Write-LogMessage -API $APIName -tenant 'Global' -headers $Headers -message $Result -Sev 'Error' -LogData $ErrorMessage $StatusCode = [HttpStatusCode]::InternalServerError } @@ -130,6 +133,7 @@ Function Invoke-ExecExtensionMapping { $InstanceId = Start-CIPPOrchestrator -InputObject $InputObject Write-Host "Started permissions orchestration with ID = '$InstanceId'" $Result = 'AutoMapping Request has been queued. Exact name matches will appear first and matches on device names and serials will take longer. Please check the CIPP Logbook and refresh the page once complete.' + Write-LogMessage -API $APIName -tenant 'Global' -headers $Headers -message $Result -Sev 'Info' } 'HaloPSA' { $Result = Invoke-HaloAutoMap -CIPPMapping $Table @@ -141,7 +145,7 @@ Function Invoke-ExecExtensionMapping { catch { $ErrorMessage = Get-CippException -Exception $_ $Result = "Mapping API failed. $($ErrorMessage.NormalizedError)" - Write-LogMessage -API $APIName -headers $Headers -message $Result -Sev 'Error' -LogData $ErrorMessage + Write-LogMessage -API $APIName -tenant 'Global' -headers $Headers -message $Result -Sev 'Error' -LogData $ErrorMessage $StatusCode = [HttpStatusCode]::InternalServerError } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionNinjaOneQueue.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionNinjaOneQueue.ps1 index b9b5724e33104..102f767ce1fe4 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionNinjaOneQueue.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionNinjaOneQueue.ps1 @@ -7,10 +7,32 @@ function Invoke-ExecExtensionNinjaOneQueue { #> [CmdletBinding()] param($Request, $TriggerMetadata) - switch ($QueueItem.NinjaAction) { - 'StartAutoMapping' { Invoke-NinjaOneOrgMapping } - 'AutoMapTenant' { Invoke-NinjaOneOrgMappingTenant -QueueItem $QueueItem } - 'SyncTenant' { Invoke-NinjaOneTenantSync -QueueItem $QueueItem } + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $NinjaAction = $QueueItem.NinjaAction + + try { + switch ($NinjaAction) { + 'StartAutoMapping' { + Invoke-NinjaOneOrgMapping + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message 'NinjaOne StartAutoMapping completed' -Sev 'Info' + } + 'AutoMapTenant' { + Invoke-NinjaOneOrgMappingTenant -QueueItem $QueueItem + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message 'NinjaOne AutoMapTenant completed' -Sev 'Info' + } + 'SyncTenant' { + Invoke-NinjaOneTenantSync -QueueItem $QueueItem + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message 'NinjaOne SyncTenant completed' -Sev 'Info' + } + default { + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Unknown NinjaOne action: $NinjaAction" -Sev 'Error' + } + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "NinjaOne action '$NinjaAction' failed: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage } $Body = [PSCustomObject]@{ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionSync.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionSync.ps1 index 797bf04ec555b..86456117cb391 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionSync.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionSync.ps1 @@ -55,6 +55,9 @@ Function Invoke-ExecExtensionSync { #Write-Host ($InputObject | ConvertTo-Json) $InstanceId = Start-CIPPOrchestrator -InputObject $InputObject + $SyncTenantFilter = if ($Request.Query.TenantFilter) { $Request.Query.TenantFilter } else { $Tenant.RowKey } + Write-LogMessage -API 'NinjaOneSync' -tenant $SyncTenantFilter -message "On-demand NinjaOne Synchronization queued for $($Tenant.IntegrationName)" -Sev 'Info' -Headers $Request.Headers + $Results = [pscustomobject]@{'Results' = "NinjaOne Synchronization Queued for $($Tenant.IntegrationName)" } } else { $Results = [pscustomobject]@{'Results' = 'Tenant was not found.' } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionsConfig.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionsConfig.ps1 index 79529e5b52916..e6f0a94bcaa26 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionsConfig.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Extensions/Invoke-ExecExtensionsConfig.ps1 @@ -7,6 +7,7 @@ function Invoke-ExecExtensionsConfig { #> [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint $Headers = $Request.Headers @@ -74,9 +75,13 @@ function Invoke-ExecExtensionsConfig { Add-AzDataTableEntity @ConfigTable -Entity $AddObject -Force Register-CIPPExtensionScheduledTasks - "Successfully saved the extension configuration. $AddedText" + $Result = "Successfully saved the extension configuration. $AddedText" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result.Trim() -Sev 'Info' + $Result } catch { - "Failed to save the extensions configuration: $($_.Exception.message) Linenumber: $($_.InvocationInfo.ScriptLineNumber)" + $Result = "Failed to save the extensions configuration: $($_.Exception.message) Linenumber: $($_.InvocationInfo.ScriptLineNumber)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' + $Result } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListAsyncDeployment.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListAsyncDeployment.ps1 new file mode 100644 index 0000000000000..6f582d8f133d7 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListAsyncDeployment.ps1 @@ -0,0 +1,33 @@ +function Invoke-ListAsyncDeployment { + <# + .FUNCTIONALITY + Entrypoint,AnyTenant + .ROLE + CIPP.Scheduler.Read + .SYNOPSIS + Get the live progress of a background job + .DESCRIPTION + Returns the status rows of a background job that reports progress while it runs, such as a + user offboarding started from the wizard: one row per target (the user) with its overall + status and the status and message of every step. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + # The job id handed back when the work was queued (e.g. DeploymentId from ExecOffboardUser) + $DeploymentId = $Request.Query.DeploymentId ?? $Request.Body.DeploymentId + if (-not $DeploymentId) { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @{ Results = 'DeploymentId is required' } + }) + } + + # Rows name their tenant (TenantFilter, or Name for tenant-keyed jobs such as SharePoint template + # deployments); a tenant-restricted caller only gets rows in scope. + $Rows = @(Get-CIPPAsyncDeployment -JobId $DeploymentId | Select-CippAllowedTenantData -TenantProperty @('TenantFilter', 'Name')) + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = ConvertTo-Json -Depth 10 -InputObject $Rows + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListFunctionParameters.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListFunctionParameters.ps1 index 8016cae01fd7e..250ef5046d78f 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListFunctionParameters.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListFunctionParameters.ps1 @@ -20,7 +20,9 @@ function Invoke-ListFunctionParameters { $CommandQuery.Name = $Function } $IgnoreList = 'entryPoint', 'internal' - $CommonParameters = @('Verbose', 'Debug', 'ErrorAction', 'WarningAction', 'InformationAction', 'ErrorVariable', 'WarningVariable', 'InformationVariable', 'OutVariable', 'OutBuffer', 'PipelineVariable', 'TenantFilter', 'APIName', 'Headers', 'ProgressAction', 'WhatIf', 'Confirm', 'Headers', 'NoAuthCheck') + # Tenant/TenantId are hidden alongside TenantFilter: the scheduler injects the authorized task + # tenant into whichever of these the command declares, so they are never user-editable. + $CommonParameters = @('Verbose', 'Debug', 'ErrorAction', 'WarningAction', 'InformationAction', 'ErrorVariable', 'WarningVariable', 'InformationVariable', 'OutVariable', 'OutBuffer', 'PipelineVariable', 'TenantFilter', 'Tenant', 'TenantId', 'APIName', 'Headers', 'ProgressAction', 'WhatIf', 'Confirm', 'Headers', 'NoAuthCheck') $TemporaryBlacklist = 'Get-CIPPAuthentication', 'Invoke-CippWebhookProcessing', 'Invoke-ListFunctionParameters', 'New-CIPPAPIConfig', 'New-CIPPGraphSubscription' if (-not $global:CIPPFunctionParameters) { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListScheduledItemDetails.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListScheduledItemDetails.ps1 index 88ee45df5ba2b..ca8374da80043 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListScheduledItemDetails.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListScheduledItemDetails.ps1 @@ -27,7 +27,8 @@ function Invoke-ListScheduledItemDetails { # Retrieve the task information $TaskTable = Get-CIPPTable -TableName 'ScheduledTasks' - $Task = Get-CIPPAzDataTableEntity @TaskTable -Filter "RowKey eq '$SafeRowKey' and PartitionKey eq 'ScheduledTask'" | Select-Object RowKey, Name, TaskState, Command, Parameters, Recurrence, ExecutedTime, ScheduledTime, PostExecution, Tenant, TenantGroup, Hidden, Results, Timestamp, Trigger + $Task = Get-CIPPAzDataTableEntity @TaskTable -Filter "RowKey eq '$SafeRowKey' and PartitionKey eq 'ScheduledTask'" | Select-Object RowKey, Name, TaskState, Command, Parameters, Recurrence, ExecutedTime, ScheduledTime, PostExecution, PostExecutionResults, Tenant, TenantGroup, Tenants, TenantSelectionVersion, excludedTenants, excludedTenantGroups, Hidden, Results, Timestamp, Trigger + if (-not $Task) { return ([HttpResponseContext]@{ @@ -72,7 +73,21 @@ function Invoke-ListScheduledItemDetails { } catch {} # Handle tenant group display information (similar to Invoke-ListScheduledItems) - if ($Task.TenantGroup) { + if ($Task.Tenants) { + # Tenant stays 'AllTenants' for the execution gates, so report the real scope from Tenants. + try { + $TenantsParsed = $Task.Tenants | ConvertFrom-Json -Depth 10 -ErrorAction Stop + $Task.Tenant = @($TenantsParsed | ForEach-Object { + [PSCustomObject]@{ + label = $_.label ?? $_.value + value = $_.value + type = $_.type ?? 'Tenant' + } + }) + } catch { + Write-Warning "Failed to parse tenant selection for task $($Task.RowKey): $($_.Exception.Message)" + } + } elseif ($Task.TenantGroup) { try { $TenantGroupObject = $Task.TenantGroup | ConvertFrom-Json -ErrorAction SilentlyContinue if ($TenantGroupObject) { @@ -112,6 +127,15 @@ function Invoke-ListScheduledItemDetails { } } + # Delivery outcomes of the post-execution notifications (one per channel attempt), stored as JSON + if ($Task.PostExecutionResults) { + try { + $Task.PostExecutionResults = @($Task.PostExecutionResults | ConvertFrom-Json -ErrorAction Stop) + } catch { + $Task.PostExecutionResults = @() + } + } + # Get the results if available $ResultsTable = Get-CIPPTable -TableName 'ScheduledTaskResults' $ResultsFilter = "PartitionKey eq '$SafeRowKey'" @@ -198,9 +222,11 @@ function Invoke-ListScheduledItemDetails { $TenantId = $Result.RowKey $TenantInfo = Get-Tenants -TenantFilter $TenantId -ErrorAction SilentlyContinue if ($TenantInfo) { - $Result | Add-Member -NotePropertyName TenantName -NotePropertyValue $TenantInfo.displayName -Force - $Result | Add-Member -NotePropertyName TenantDefaultDomain -NotePropertyValue $TenantInfo.defaultDomainName -Force - $Result | Add-Member -NotePropertyName TenantId -NotePropertyValue $TenantInfo.customerId -Force + $Result | Add-Member -NotePropertyMembers ([ordered]@{ + TenantName = $TenantInfo.displayName + TenantDefaultDomain = $TenantInfo.defaultDomainName + TenantId = $TenantInfo.customerId + }) -Force } } } catch { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListScheduledItems.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListScheduledItems.ps1 index 4729b984d1cfc..4044caf468d1d 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListScheduledItems.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Scheduler/Invoke-ListScheduledItems.ps1 @@ -45,10 +45,11 @@ function Invoke-ListScheduledItems { } if ($TenantFilter -and $TenantFilter -ne 'AllTenants') { - # Tasks are stored against either the customerId or the default domain name depending on - # what created them, so resolve the tenant up front and let storage match either. + # Tasks are stored against whichever tenant identifier the caller supplied - customerId, + # default domain, or the initial .onmicrosoft.com domain - so resolve the tenant up front + # and let storage match any of them. (Get-Tenants itself accepts all three as -TenantFilter.) $TenantObject = Get-Tenants -TenantFilter $TenantFilter | Select-Object -First 1 - $TenantIdentifiers = @($TenantObject.defaultDomainName, $TenantObject.customerId) | Where-Object { $_ } | Select-Object -Unique + $TenantIdentifiers = @($TenantObject.defaultDomainName, $TenantObject.initialDomainName, $TenantObject.customerId) | Where-Object { $_ } | Select-Object -Unique if (-not $TenantIdentifiers) { # Tenant could not be resolved (deleted, excluded, or not visible to the caller). # Fall back to the raw value so we filter on something rather than on nothing. @@ -76,9 +77,9 @@ function Invoke-ListScheduledItems { $AllowedTenants = Test-CIPPAccess -Request $Request -TenantList $TenantLookup = @{} - foreach ($Tenant in (Get-Tenants -IncludeErrors | Select-Object customerId, defaultDomainName)) { + foreach ($Tenant in (Get-Tenants -IncludeErrors | Select-Object customerId, defaultDomainName, initialDomainName)) { if ($Tenant.customerId) { - $TenantLookup[[string]$Tenant.customerId] = $Tenant.defaultDomainName + $TenantLookup[[string]$Tenant.customerId] = $Tenant } } @@ -87,7 +88,11 @@ function Invoke-ListScheduledItems { foreach ($AllowedTenant in $AllowedTenants) { $null = $AllowedTenantIdentifiers.Add([string]$AllowedTenant) if ($TenantLookup.ContainsKey([string]$AllowedTenant)) { - $null = $AllowedTenantIdentifiers.Add($TenantLookup[[string]$AllowedTenant]) + # A task keyed on any of the tenant's identifiers must pass the access check, not just + # the default domain - otherwise a scoped user cannot see their own initial-domain tasks. + foreach ($Domain in @($TenantLookup[[string]$AllowedTenant].defaultDomainName, $TenantLookup[[string]$AllowedTenant].initialDomainName)) { + if ($Domain) { $null = $AllowedTenantIdentifiers.Add([string]$Domain) } + } } } $Tasks = $Tasks | Where-Object { $AllowedTenantIdentifiers.Contains([string]$_.Tenant) } @@ -147,7 +152,7 @@ function Invoke-ListScheduledItems { } else { $TenantValue = [string]$Task.Tenant if ($TenantLookup.ContainsKey($TenantValue)) { - $TenantValue = $TenantLookup[$TenantValue] + $TenantValue = $TenantLookup[$TenantValue].defaultDomainName } $Task.Tenant = [PSCustomObject]@{ label = $TenantValue diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecAddTrustedIP.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecAddTrustedIP.ps1 index 3aef21a287281..9a1fd93fc25a5 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecAddTrustedIP.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecAddTrustedIP.ps1 @@ -8,6 +8,9 @@ function Invoke-ExecAddTrustedIP { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $tenantfilter = $Request.Query.tenantfilter if (-not $tenantfilter) { return ([HttpResponseContext]@{ @@ -25,16 +28,28 @@ function Invoke-ExecAddTrustedIP { }) } - $Table = Get-CippTable -tablename 'trustedIps' - foreach ($IP in $Request.body.IP) { - Add-CIPPAzDataTableEntity @Table -Entity @{ - PartitionKey = $tenantDomain - RowKey = $IP - state = $Request.Body.State - } -Force + try { + $Table = Get-CippTable -tablename 'trustedIps' + foreach ($IP in $Request.body.IP) { + Add-CIPPAzDataTableEntity @Table -Entity @{ + PartitionKey = $tenantDomain + RowKey = $IP + state = $Request.Body.State + } -Force + } + $Result = "Added $($Request.Body.IP) to database with state $($Request.Body.State) for $($tenantDomain)" + Write-LogMessage -headers $Headers -API $APIName -tenant $tenantDomain -message $Result -Sev 'Info' + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = @{ results = $Result } + }) + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to add trusted IP(s) for $($tenantDomain): $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -tenant $tenantDomain -message $Result -Sev 'Error' -LogData $ErrorMessage + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::InternalServerError + Body = @{ results = $Result } + }) } - return ([HttpResponseContext]@{ - StatusCode = [HttpStatusCode]::OK - Body = @{ results = "Added $($Request.Body.IP) to database with state $($Request.Body.State) for $($tenantDomain)" } - }) } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecApiClient.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecApiClient.ps1 index 415e40089b889..4a346e1389765 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecApiClient.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecApiClient.ps1 @@ -221,13 +221,21 @@ function Invoke-ExecApiClient { Set-CippApiAuth -RGName $RGName -FunctionAppName $FunctionAppName -TenantId $TenantId -ClientIds $ClientIds -McpClientIds $McpClientIds if ($McpClientIds.Count -gt 0 -and $env:WEBSITE_HOSTNAME) { + # Advertise the OIDC scopes alongside the resource scope so discovery-based MCP + # clients (Copilot Studio, ChatGPT) request a refresh token. offline_access is + # what makes Entra issue one; without it the client re-consents every ~hour. + # Claude appends offline_access itself, but stricter clients only request what the + # metadata advertises, so it has to be in the protected-resource document and the + # EasyAuth challenge scope too - not just the authorization-server document. + $McpScope = "https://$($env:WEBSITE_HOSTNAME)/user_impersonation" + $McpScopesSupported = @('openid', 'profile', 'offline_access', $McpScope) + $McpDefaultScopeString = 'openid profile offline_access {0}' -f $McpScope if ($env:CIPPNG) { $TenantedLogin = "https://login.microsoftonline.com/$($env:TenantID)" - $McpScope = "https://$($env:WEBSITE_HOSTNAME)/user_impersonation" $PrmDocument = [ordered]@{ resource = '{origin}/api/ExecMcp' authorization_servers = @('{origin}') - scopes_supported = @($McpScope) + scopes_supported = $McpScopesSupported bearer_methods_supported = @('header') } | ConvertTo-Json -Compress $AsDocument = [ordered]@{ @@ -241,11 +249,11 @@ function Invoke-ExecApiClient { grant_types_supported = @('authorization_code', 'refresh_token') code_challenge_methods_supported = @('S256') token_endpoint_auth_methods_supported = @('none', 'client_secret_post', 'client_secret_basic') - scopes_supported = @('openid', 'profile', 'offline_access', $McpScope) + scopes_supported = $McpScopesSupported } | ConvertTo-Json -Compress - $null = Update-CIPPAzFunctionAppSetting -Name $FunctionAppName -ResourceGroupName $RGName -AppSetting @{ 'CRAFT_PRM' = "$PrmDocument"; 'CRAFT_PRM_AS' = "$AsDocument"; 'WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES' = $McpScope } + $null = Update-CIPPAzFunctionAppSetting -Name $FunctionAppName -ResourceGroupName $RGName -AppSetting @{ 'CRAFT_PRM' = "$PrmDocument"; 'CRAFT_PRM_AS' = "$AsDocument"; 'WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES' = $McpDefaultScopeString } } else { - $null = Update-CIPPAzFunctionAppSetting -Name $FunctionAppName -ResourceGroupName $RGName -AppSetting @{ 'WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES' = "https://$($env:WEBSITE_HOSTNAME)/user_impersonation" } + $null = Update-CIPPAzFunctionAppSetting -Name $FunctionAppName -ResourceGroupName $RGName -AppSetting @{ 'WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES' = $McpDefaultScopeString } } } else { $null = Update-CIPPAzFunctionAppSetting -Name $FunctionAppName -ResourceGroupName $RGName -AppSetting @{} -RemoveKeys @('WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES', 'CRAFT_PRM', 'CRAFT_PRM_AS') diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecAppServiceDomains.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecAppServiceDomains.ps1 index effbebdbe4a6a..b815a2b6b6331 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecAppServiceDomains.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecAppServiceDomains.ps1 @@ -14,14 +14,18 @@ function Invoke-ExecAppServiceDomains { Actions (passed as Query.Action or Body.Action): List - Site metadata (default hostname, inbound IP) plus every hostname - binding and any App Service Managed Certificate that matches. + binding, any App Service Managed Certificate that matches, and the + state of a certificate job still running in the background. CheckDns - Live DoH lookup of the alias record a custom domain needs. CIPP no longer uses domain-verification TXT records, so a leftover asuid. record is detected and flagged for removal rather than requested. Powers wizard step 1 + resume. - AddBinding - Create the hostname binding (wizard step 2). Azure re-validates ownership. - AddCertificate - Create an App Service Managed Certificate and enable the SNI SSL binding - (wizard step 3). Safe to re-run — reuses an existing cert if present. + AddBinding - Create the hostname binding (wizard step 2). Azure validates ownership + through the alias record. + AddCertificate - Issue an App Service Managed Certificate and enable the SNI SSL binding + (wizard step 3) via Invoke-CIPPCustomDomainCertificate. Issuance that + outlives the request carries on as a hidden scheduled task that retries + every 15 minutes, a few times, then stops. Remove - Delete a custom hostname binding (and its managed cert, best effort). Every action is independently re-runnable so the wizard can resume a half-finished domain or @@ -33,24 +37,15 @@ function Invoke-ExecAppServiceDomains { $APIName = $Request.Params.CIPPEndpoint $Headers = $Request.Headers $Action = $Request.Query.Action ?? $Request.Body.Action - $ApiVersion = '2024-11-01' - - # Resolve the ARM coordinates of the App Service running this instance. Mirrors the resolution - # the Container Management endpoint uses (platform env + managed identity token), so a missing - # resource group fails loudly rather than guessing. - function Get-AppServiceSiteInfo { - $SiteName = $env:WEBSITE_SITE_NAME - $RGName = Get-CIPPFunctionAppResourceGroup -SiteName $SiteName - return @{ - Subscription = Get-CIPPAzFunctionAppSubId - SiteName = $SiteName - RGName = $RGName - } - } - function Get-SiteArmBase { - param($Site) - return "https://management.azure.com/subscriptions/$($Site.Subscription)/resourceGroups/$($Site.RGName)/providers/Microsoft.Web/sites/$($Site.SiteName)" + # Trim/lowercase the requested hostname and reject anything that is not a DNS name - it goes + # into ARM URIs and table filters verbatim. + function Get-CleanHostname { + param([string]$Value) + $Clean = ([string]$Value).Trim().ToLower() + if ([string]::IsNullOrWhiteSpace($Clean)) { throw 'Hostname is required' } + if ($Clean -notmatch '^(\*\.)?([a-z0-9]([a-z0-9-]*[a-z0-9])?\.)+[a-z]{2,}$') { throw "'$Clean' is not a valid hostname" } + return $Clean } # Work out which DNS record a given custom hostname needs. Azure accepts either a CNAME (to the @@ -68,7 +63,7 @@ function Invoke-ExecAppServiceDomains { $Labels = $BaseHost.Split('.') # 2-label names (contoso.com) are treated as apex → A record. Everything else is a subdomain # → CNAME. This is a heuristic (multi-part TLDs like co.uk can't be detected without a public - # suffix list); the UI lets the operator pick the other record type, and Azure accepts either. + # suffix list); CheckDns reports which record actually resolved and AddBinding honours that. $IsApex = -not $IsWildcard -and $Labels.Count -le 2 return [pscustomobject]@{ @@ -101,73 +96,77 @@ function Invoke-ExecAppServiceDomains { try { switch ($Action) { 'List' { - $Site = Get-AppServiceSiteInfo - $ArmBase = Get-SiteArmBase -Site $Site - - $SiteObj = New-CIPPAzRestRequest -Uri "$($ArmBase)?api-version=$ApiVersion" -Method GET - $DefaultHostName = $SiteObj.properties.defaultHostName - $InboundIp = $SiteObj.properties.inboundIpAddress - - $BindingResponse = New-CIPPAzRestRequest -Uri "$($ArmBase)/hostNameBindings?api-version=$ApiVersion" -Method GET - - # Pull managed certs in the RG once so we can attach expiry/thumbprint per domain. - $Certs = @() - try { - $CertResponse = New-CIPPAzRestRequest -Uri "https://management.azure.com/subscriptions/$($Site.Subscription)/resourceGroups/$($Site.RGName)/providers/Microsoft.Web/certificates?api-version=$ApiVersion" -Method GET - $Certs = @($CertResponse.value) - } catch { - Write-Information "Could not list certificates: $($_.Exception.Message)" - } + $AppService = Get-CIPPAppServiceSite + $Api = $AppService.ApiVersion + $BindingResponse = New-CIPPAzRestRequest -Uri "$($AppService.ArmBase)/hostNameBindings?api-version=$Api" -Method GET -ErrorAction Stop + $TaskTable = Get-CIPPTable -TableName 'ScheduledTasks' $Domains = foreach ($Binding in $BindingResponse.value) { - $HostName = $Binding.name # ARM returns bindings named "/"; keep just the hostname. - if ($HostName -match '/') { $HostName = ($HostName -split '/')[-1] } + $HostName = ($Binding.name -split '/')[-1] $IsDefault = $HostName -like '*.azurewebsites.net' - $Cert = $Certs | Where-Object { $_.properties.canonicalName -eq $HostName } | Select-Object -First 1 + $Secured = $Binding.properties.sslState -in @('SniEnabled', 'IpBasedEnabled') + $Cert = $AppService.Certificates | Where-Object { $_.properties.canonicalName -eq $HostName } | Select-Object -First 1 + + # A certificate still being issued in the background is a chain of hidden retry + # tasks: the planned one says which attempt is next, the last finished one why. + $Active = $null + $Finished = $null + if (-not $IsDefault -and -not $Secured) { + $Jobs = @(Get-CIPPAzDataTableEntity @TaskTable -Filter "PartitionKey eq 'ScheduledTask' and Reference eq 'CustomDomainCert-$HostName'") + $Active = $Jobs | Where-Object { $_.TaskState -in @('Planned', 'Pending', 'Running') } | Select-Object -First 1 + $Finished = $Jobs | Where-Object { $_.TaskState -in @('Completed', 'Failed') } | Sort-Object -Property Timestamp -Descending | Select-Object -First 1 + } + $JobParams = try { ($Active ?? $Finished).Parameters | ConvertFrom-Json } catch { $null } + $LastResult = try { ($Finished.Results | ConvertFrom-Json).Results } catch { [string]$Finished.Results } [pscustomobject]@{ - Hostname = $HostName - IsDefault = $IsDefault - HostNameType = $Binding.properties.hostNameType - SslState = $Binding.properties.sslState ?? 'Disabled' - Thumbprint = $Binding.properties.thumbprint - DnsRecordType = $Binding.properties.customHostNameDnsRecordType - Secured = ($Binding.properties.sslState -in @('SniEnabled', 'IpBasedEnabled')) - CertName = $Cert.name - CertThumbprint = $Cert.properties.thumbprint - CertExpiration = $Cert.properties.expirationDate - CertIssuer = $Cert.properties.issuer + Hostname = $HostName + IsDefault = $IsDefault + HostNameType = $Binding.properties.hostNameType + SslState = $Binding.properties.sslState ?? 'Disabled' + Thumbprint = $Binding.properties.thumbprint + DnsRecordType = $Binding.properties.customHostNameDnsRecordType + Secured = $Secured + CertName = $Cert.name + CertThumbprint = $Cert.properties.thumbprint + CertExpiration = $Cert.properties.expirationDate + CertIssuer = $Cert.properties.issuer + CertJobActive = [bool]$Active + CertJobAttempt = $JobParams ? [int]$JobParams.Attempt : $null + CertJobMaxAttempts = $JobParams ? [int]$JobParams.MaxAttempts : $null + CertJobNextRun = $Active ? [DateTimeOffset]::FromUnixTimeSeconds([int64]$Active.ScheduledTime).UtcDateTime.ToString('o') : $null + CertJobResult = $LastResult } } $Body = @{ Results = @{ - SiteName = $Site.SiteName - ResourceGroup = $Site.RGName - DefaultHostName = $DefaultHostName - InboundIpAddress = $InboundIp - Domains = @($Domains | Sort-Object -Property IsDefault, Hostname) + SiteName = $AppService.SiteName + ResourceGroup = $AppService.ResourceGroup + DefaultHostName = $AppService.Site.properties.defaultHostName + InboundIpAddress = $AppService.Site.properties.inboundIpAddress + # The App Service's own Custom domains blade - the fallback the wizard offers when Azure rejects a binding. + AzurePortalDomainsUrl = "https://portal.azure.com/#@/resource/subscriptions/$($AppService.SubscriptionId)/resourceGroups/$($AppService.ResourceGroup)/providers/Microsoft.Web/sites/$($AppService.SiteName)/customDomains" + Domains = @($Domains | Sort-Object -Property IsDefault, Hostname) } } } 'CheckDns' { $HostName = $Request.Body.Hostname ?? $Request.Query.Hostname - if (-not [string]::IsNullOrWhiteSpace($HostName)) { $HostName = ([string]$HostName).Trim().ToLower() } if ([string]::IsNullOrWhiteSpace($HostName)) { throw 'Hostname is required' } + $HostName = Get-CleanHostname $HostName # DoH resolver lives in the DNSHealth module; import + initialize it the same way the # domain health endpoint does before resolving. Import-Module DNSHealth -ErrorAction SilentlyContinue Set-DnsResolver -Resolver 'Google' -ErrorAction SilentlyContinue - $Site = Get-AppServiceSiteInfo - $ArmBase = Get-SiteArmBase -Site $Site - $SiteObj = New-CIPPAzRestRequest -Uri "$($ArmBase)?api-version=$ApiVersion" -Method GET + $AppService = Get-CIPPAppServiceSite $Plan = Get-DomainRecordPlan -Hostname $HostName ` - -DefaultHostName $SiteObj.properties.defaultHostName ` - -InboundIp $SiteObj.properties.inboundIpAddress + -DefaultHostName $AppService.Site.properties.defaultHostName ` + -InboundIp $AppService.Site.properties.inboundIpAddress # CIPP no longer asks for a domain-verification TXT record at asuid., but an # old one left behind by a previous setup is actively harmful: Azure hard-fails the @@ -180,6 +179,7 @@ function Invoke-ExecAppServiceDomains { # Wildcards can't be resolved directly, so they pass this check unconditionally — # Azure validates the wildcard alias when the binding is created. $AliasVerified = $false + $AliasType = $null $AliasDetail = $null if ($Plan.IsWildcard) { $AliasVerified = $true @@ -191,9 +191,11 @@ function Invoke-ExecAppServiceDomains { $AMatch = $AValues | Where-Object { $_ -eq $Plan.ARecordTarget } if ($CnameMatch) { $AliasVerified = $true + $AliasType = 'CNAME' $AliasDetail = "CNAME -> $($Plan.CnameTarget)" } elseif ($AMatch) { $AliasVerified = $true + $AliasType = 'A' $AliasDetail = "A -> $($Plan.ARecordTarget)" } else { $Found = @($CnameValues + $AValues) -join ', ' @@ -201,10 +203,6 @@ function Invoke-ExecAppServiceDomains { } } - # The alias is the only record the wizard gates on now — Azure makes the final - # ownership call when the binding is created. - $CanProceed = [bool]$AliasVerified - $Records = @( [pscustomobject]@{ Purpose = 'Alias' @@ -223,7 +221,8 @@ function Invoke-ExecAppServiceDomains { LegacyAsuid = $LegacyAsuid LegacyAsuidHost = $Plan.LegacyAsuidHost AliasVerified = $AliasVerified - CanProceed = $CanProceed + AliasType = $AliasType + CanProceed = [bool]$AliasVerified AliasDetail = $AliasDetail Records = @($Records) } @@ -232,143 +231,85 @@ function Invoke-ExecAppServiceDomains { 'AddBinding' { $HostName = $Request.Body.Hostname ?? $Request.Query.Hostname - if (-not [string]::IsNullOrWhiteSpace($HostName)) { $HostName = ([string]$HostName).Trim().ToLower() } if ([string]::IsNullOrWhiteSpace($HostName)) { throw 'Hostname is required' } + $HostName = Get-CleanHostname $HostName if ($HostName -like '*.azurewebsites.net') { throw 'The default *.azurewebsites.net hostname is managed by Azure and cannot be added.' } - $Site = Get-AppServiceSiteInfo - $ArmBase = Get-SiteArmBase -Site $Site - - # Azure enforces domain-ownership validation during this PUT, using the alias - # record. A leftover asuid TXT record from an older setup hard-fails validation - # when its value doesn't match this App Service — even if the alias is correct — - # so append removal guidance to that error. - $BindingUri = "$($ArmBase)/hostNameBindings/$HostName`?api-version=$ApiVersion" - $BindingBody = @{ - properties = @{ - siteName = $Site.SiteName - hostNameType = 'Verified' - } + $AppService = Get-CIPPAppServiceSite + $Plan = Get-DomainRecordPlan -Hostname $HostName ` + -DefaultHostName $AppService.Site.properties.defaultHostName ` + -InboundIp $AppService.Site.properties.inboundIpAddress + + # Which alias record Azure should validate against: the one CheckDns saw resolve (A or CNAME), else the recommended type for this hostname shape. + $DnsRecordType = switch ([string]$Request.Body.DnsRecordType) { + 'A' { 'A' } + 'CNAME' { 'CName' } + default { $Plan.IsApex ? 'A' : 'CName' } } + + # Azure validates ownership during this PUT through the alias record - but only when + # customHostNameDnsRecordType says which one to check. Without it ARM skips the + # CNAME/A check and demands an asuid TXT record instead, so a correct CNAME still + # fails with "A TXT record pointing from asuid. ... was not found". + $BindingUri = "$($AppService.ArmBase)/hostNameBindings/$HostName`?api-version=$($AppService.ApiVersion)" + $BindingBody = @{ properties = @{ customHostNameDnsRecordType = $DnsRecordType } } try { - New-CIPPAzRestRequest -Uri $BindingUri -Method PUT -Body $BindingBody -ContentType 'application/json' | Out-Null + $null = New-CIPPAzRestRequest -Uri $BindingUri -Method PUT -Body $BindingBody -ErrorAction Stop } catch { + # A leftover asuid TXT record from an older setup hard-fails validation when its + # value doesn't match this App Service — even if the alias is correct. $BindingError = $_.Exception.Message if ($BindingError -match 'TXT record|asuid|CanonicalName') { - $AsuidHint = $HostName.StartsWith('*.') ? "asuid.$($HostName.Substring(2))" : "asuid.$HostName" - throw "$BindingError — If a TXT record named '$AsuidHint' exists from a previous setup, remove it: CIPP no longer uses domain-verification TXT records, and a leftover one blocks validation even when the CNAME/A alias is correct." + throw "$BindingError — If a TXT record named '$($Plan.LegacyAsuidHost)' exists from a previous setup, remove it: CIPP no longer uses domain-verification TXT records, and a leftover one blocks validation even when the CNAME/A alias is correct." } throw } - Write-LogMessage -API $APIName -headers $Headers -message "Added custom domain binding '$HostName' to $($Site.SiteName)" -sev Info + Write-LogMessage -API $APIName -headers $Headers -message "Added custom domain binding '$HostName' ($DnsRecordType) to $($AppService.SiteName)" -sev Info $Body = @{ Results = "Custom domain '$HostName' bound to the App Service. You can now enable a managed certificate." } } 'AddCertificate' { $HostName = $Request.Body.Hostname ?? $Request.Query.Hostname - if (-not [string]::IsNullOrWhiteSpace($HostName)) { $HostName = ([string]$HostName).Trim().ToLower() } if ([string]::IsNullOrWhiteSpace($HostName)) { throw 'Hostname is required' } + $HostName = Get-CleanHostname $HostName if ($HostName -like '*.azurewebsites.net') { throw 'The default hostname is already secured by Azure.' } if ($HostName.StartsWith('*.')) { throw 'App Service Managed Certificates do not support wildcard domains. Upload your own certificate in the Azure Portal instead.' } - $Site = Get-AppServiceSiteInfo - $ArmBase = Get-SiteArmBase -Site $Site - - $SiteObj = New-CIPPAzRestRequest -Uri "$($ArmBase)?api-version=$ApiVersion" -Method GET - $Location = $SiteObj.location - $ServerFarmId = $SiteObj.properties.serverFarmId + # First attempt runs inline; a certificate that is not issued by the time it returns + # is followed up by hidden scheduled retries (see Invoke-CIPPCustomDomainCertificate). + $Message = Invoke-CIPPCustomDomainCertificate -Hostname $HostName + $AppService = Get-CIPPAppServiceSite + $SslState = ($AppService.Site.properties.hostNameSslStates | Where-Object { $_.name -eq $HostName } | Select-Object -First 1).sslState - # The binding must already exist — the managed cert is validated against it. - $Bindings = New-CIPPAzRestRequest -Uri "$($ArmBase)/hostNameBindings?api-version=$ApiVersion" -Method GET - $ExistingBinding = $Bindings.value | Where-Object { (($_.name -split '/')[-1]) -eq $HostName } | Select-Object -First 1 - if (-not $ExistingBinding) { - throw "No hostname binding exists for '$HostName'. Create the domain binding first." - } - - # Reuse a managed cert for this hostname if one is already issued, otherwise create it. - $CertName = "$($HostName -replace '[^a-zA-Z0-9-]', '-')-$($Site.SiteName)" - $CertUri = "https://management.azure.com/subscriptions/$($Site.Subscription)/resourceGroups/$($Site.RGName)/providers/Microsoft.Web/certificates/$CertName`?api-version=$ApiVersion" - - $Thumbprint = $null - try { - $ExistingCert = New-CIPPAzRestRequest -Uri $CertUri -Method GET - $Thumbprint = $ExistingCert.properties.thumbprint - } catch { - Write-Information "No existing certificate '$CertName', creating a new managed certificate." - } - - if (-not $Thumbprint) { - $CertBody = @{ - location = $Location - properties = @{ - serverFarmId = $ServerFarmId - canonicalName = $HostName - domainValidationMethod = 'cname-delegation' - } - } - # Managed-cert issuance validates the domain during the PUT. If the alias is proxied - # (e.g. Cloudflare orange-cloud) validation can fail — the operator should turn the - # proxy off until the cert is issued, then re-enable it. - $NewCert = New-CIPPAzRestRequest -Uri $CertUri -Method PUT -Body $CertBody -ContentType 'application/json' - $Thumbprint = $NewCert.properties.thumbprint - - # Occasionally the thumbprint isn't populated on the create response; poll briefly. - $Attempt = 0 - while (-not $Thumbprint -and $Attempt -lt 6) { - Start-Sleep -Seconds 5 - $Attempt++ - try { - $PolledCert = New-CIPPAzRestRequest -Uri $CertUri -Method GET - $Thumbprint = $PolledCert.properties.thumbprint - } catch { - Write-Information "Polling certificate '$CertName' (attempt $Attempt): $($_.Exception.Message)" - } - } - } - - if (-not $Thumbprint) { - throw "The managed certificate for '$HostName' was created but is still provisioning. Re-run this step in a minute to finish the SNI binding." - } - - # Enable the SNI SSL binding by merging sslState + thumbprint into the existing binding. - $BindingUri = "$($ArmBase)/hostNameBindings/$HostName`?api-version=$ApiVersion" - $BindingBody = @{ - properties = @{ - siteName = $Site.SiteName - hostNameType = 'Verified' - sslState = 'SniEnabled' - thumbprint = $Thumbprint - } + Write-LogMessage -API $APIName -headers $Headers -message $Message -sev Info + $Body = @{ + Results = $Message + Secured = $SslState -in @('SniEnabled', 'IpBasedEnabled') } - New-CIPPAzRestRequest -Uri $BindingUri -Method PUT -Body $BindingBody -ContentType 'application/json' | Out-Null - - Write-LogMessage -API $APIName -headers $Headers -message "Provisioned managed certificate and SNI binding for '$HostName'" -sev Info - $Body = @{ Results = "Managed certificate issued and SNI SSL enabled for '$HostName'. The domain is now secured." } } 'Remove' { $HostName = $Request.Body.Hostname ?? $Request.Query.Hostname - if (-not [string]::IsNullOrWhiteSpace($HostName)) { $HostName = ([string]$HostName).Trim().ToLower() } if ([string]::IsNullOrWhiteSpace($HostName)) { throw 'Hostname is required' } + $HostName = Get-CleanHostname $HostName if ($HostName -like '*.azurewebsites.net') { throw 'The default *.azurewebsites.net hostname cannot be removed.' } - $Site = Get-AppServiceSiteInfo - $ArmBase = Get-SiteArmBase -Site $Site - - $BindingUri = "$($ArmBase)/hostNameBindings/$HostName`?api-version=$ApiVersion" - New-CIPPAzRestRequest -Uri $BindingUri -Method DELETE | Out-Null - - # Best effort: drop the managed cert we created for this hostname so it doesn't linger. - $CertName = "$($HostName -replace '[^a-zA-Z0-9-]', '-')-$($Site.SiteName)" - $CertUri = "https://management.azure.com/subscriptions/$($Site.Subscription)/resourceGroups/$($Site.RGName)/providers/Microsoft.Web/certificates/$CertName`?api-version=$ApiVersion" - try { - New-CIPPAzRestRequest -Uri $CertUri -Method DELETE | Out-Null - } catch { - Write-Information "Could not remove certificate '$CertName' (may not exist): $($_.Exception.Message)" + $AppService = Get-CIPPAppServiceSite + $Api = $AppService.ApiVersion + $null = New-CIPPAzRestRequest -Uri "$($AppService.ArmBase)/hostNameBindings/$HostName`?api-version=$Api" -Method DELETE -ErrorAction Stop + + # Best effort: drop the managed certificate(s) for this hostname so they don't linger and + # keep holding the one-certificate-per-hostname slot on the plan. + foreach ($Cert in @($AppService.Certificates | Where-Object { $_.properties.canonicalName -eq $HostName })) { + try { + $null = New-CIPPAzRestRequest -Uri "https://management.azure.com$($Cert.id)?api-version=$Api" -Method DELETE -ErrorAction Stop + } catch { + Write-Information "Could not remove certificate '$($Cert.name)': $($_.Exception.Message)" + } } - Write-LogMessage -API $APIName -headers $Headers -message "Removed custom domain '$HostName' from $($Site.SiteName)" -sev Info + Write-LogMessage -API $APIName -headers $Headers -message "Removed custom domain '$HostName' from $($AppService.SiteName)" -sev Info $Body = @{ Results = "Custom domain '$HostName' removed from the App Service." } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecBackendURLs.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecBackendURLs.ps1 index d154b1c3f6e98..fbfead871ce0b 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecBackendURLs.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecBackendURLs.ps1 @@ -5,7 +5,7 @@ function Invoke-ExecBackendURLs { .ROLE CIPP.AppSettings.Read .DESCRIPTION - Returns Azure portal deep links for the CIPP deployment's own infrastructure (resource group, key vault, function app, static web app) plus its subscription, SKU, hosting mode and timezone. + Returns Azure portal deep links for the CIPP deployment's own infrastructure (resource group, key vault, the function app or web app, its App Service plan, static web app) plus its subscription, SKU and timezone. Whether the instance is CyberDrain-hosted or CIPP-NG comes from /api/me. #> [CmdletBinding()] param($Request, $TriggerMetadata) @@ -22,7 +22,18 @@ function Invoke-ExecBackendURLs { $RGName = $null } + # The plan's name is only known to ARM. Best effort: local dev and an identity without rights + # on the site leave the link empty. + $AppServicePlan = $null + try { + $PlanId = [string](Get-CIPPAppServiceSite).Site.properties.serverFarmId + if ($PlanId) { $AppServicePlan = "https://portal.azure.com/#@/resource$PlanId/overview" } + } catch { + Write-Information "Could not resolve the App Service plan: $($_.Exception.Message)" + } + $results = @{ + AppServicePlan = $AppServicePlan ResourceGroup = "https://portal.azure.com/#@/resource/subscriptions/$Subscription/resourceGroups/$RGName/overview" KeyVault = "https://portal.azure.com/#@/resource/subscriptions/$Subscription/resourceGroups/$RGName/providers/Microsoft.KeyVault/vaults/$($env:WEBSITE_SITE_NAME)/secrets" FunctionApp = "https://portal.azure.com/#@/resource/subscriptions/$Subscription/resourceGroups/$RGName/providers/Microsoft.Web/sites/$($env:WEBSITE_SITE_NAME)/appServices" @@ -34,7 +45,6 @@ function Invoke-ExecBackendURLs { RGName = $RGName FunctionName = $env:WEBSITE_SITE_NAME SWAName = $SWAName - Hosted = $env:CIPP_HOSTED -eq 'true' ?? $false OS = $IsLinux ? 'Linux' : 'Windows' SKU = $env:WEBSITE_SKU } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecCippReplacemap.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecCippReplacemap.ps1 index d22ee5b46585e..2b1d5ca9d7fc0 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecCippReplacemap.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecCippReplacemap.ps1 @@ -8,6 +8,9 @@ function Invoke-ExecCippReplacemap { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $Table = Get-CippTable -tablename 'CippReplacemap' $Action = $Request.Query.Action ?? $Request.Body.Action $TenantId = $Request.Query.tenantId ?? $Request.Body.tenantId @@ -201,7 +204,9 @@ function Invoke-ExecCippReplacemap { } Add-CIPPAzDataTableEntity @Table -Entity $VariableEntity -Force - $Body = @{ Results = "Variable '$VariableName' saved successfully" } + $Result = "Variable '$VariableName' saved successfully" + Write-LogMessage -headers $Headers -API $APIName -tenant $customerId -message $Result -Sev 'Info' + $Body = @{ Results = $Result } } 'Delete' { $VariableName = $Request.Body.RowKey @@ -209,7 +214,9 @@ function Invoke-ExecCippReplacemap { $VariableEntity = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq '$customerId' and RowKey eq '$VariableName'" if ($VariableEntity) { Remove-CIPPAzDataTableEntity @Table -Entity $VariableEntity -Force - $Body = @{ Results = "Variable '$VariableName' deleted successfully" } + $Result = "Variable '$VariableName' deleted successfully" + Write-LogMessage -headers $Headers -API $APIName -tenant $customerId -message $Result -Sev 'Info' + $Body = @{ Results = $Result } } else { $Body = @{ Results = "Variable '$VariableName' not found" } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecCustomData.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecCustomData.ps1 index 0a7b3a16623ac..2dd4c7371af5b 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecCustomData.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecCustomData.ps1 @@ -8,6 +8,9 @@ function Invoke-ExecCustomData { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $Action = $Request.Query.Action ?? $Request.Body.Action $CustomDataTable = Get-CippTable -TableName 'CustomData' $CustomDataMappingsTable = Get-CippTable -TableName 'CustomDataMappings' @@ -63,18 +66,22 @@ function Invoke-ExecCustomData { Add-CIPPAzDataTableEntity @CustomDataTable -Entity $Entity -Force $SchemaExtensions = Get-CIPPSchemaExtensions | Where-Object { $_.id -eq $SchemaExtension.id } + $Result = "Schema extension '$($SchemaExtension.id)' added successfully." + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $Body = @{ Results = @{ state = 'success' - resultText = "Schema extension '$($SchemaExtension.id)' added successfully." + resultText = $Result } } } catch { + $Result = "Failed to add schema extension: $($_.Exception.Message)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' $Body = @{ Results = @( @{ state = 'error' - resultText = "Failed to add schema extension: $($_.Exception.Message)" + resultText = $Result } ) } @@ -109,18 +116,22 @@ function Invoke-ExecCustomData { # Delete the schema extension entity Remove-CIPPAzDataTableEntity @CustomDataTable -Entity $SchemaEntity + $Result = "Schema extension '$SchemaId' deleted successfully." + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $Body = @{ Results = @{ state = 'success' - resultText = "Schema extension '$SchemaId' deleted successfully." + resultText = $Result } } } catch { + $Result = "Failed to delete schema extension: $($_.Exception.Message)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' $Body = @{ Results = @( @{ state = 'error' - resultText = "Failed to delete schema extension: $($_.Exception.Message)" + resultText = $Result } ) } @@ -173,18 +184,22 @@ function Invoke-ExecCustomData { Add-CIPPAzDataTableEntity @CustomDataTable -Entity $SchemaEntity -Force try { $null = Get-CIPPSchemaExtensions } catch {} + $Result = "Property '$($NewProperty.name)' added to schema extension '$SchemaId' successfully." + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $Body = @{ Results = @{ state = 'success' - resultText = "Property '$($NewProperty.name)' added to schema extension '$SchemaId' successfully." + resultText = $Result } } } catch { + $Result = "Failed to add property to schema extension: $($_.Exception.Message)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' $Body = @{ Results = @( @{ state = 'error' - resultText = "Failed to add property to schema extension: $($_.Exception.Message)" + resultText = $Result } ) } @@ -223,18 +238,22 @@ function Invoke-ExecCustomData { Add-CIPPAzDataTableEntity @CustomDataTable -Entity $SchemaEntity -Force $null = Get-CIPPSchemaExtensions + $Result = "Schema extension '$SchemaId' status changed to '$NewStatus' successfully." + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $Body = @{ Results = @{ state = 'success' - resultText = "Schema extension '$SchemaId' status changed to '$NewStatus' successfully." + resultText = $Result } } } catch { + $Result = "Failed to change schema extension status: $($_.Exception.Message)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' $Body = @{ Results = @( @{ state = 'error' - resultText = "Failed to change schema extension status: $($_.Exception.Message)" + resultText = $Result } ) } @@ -295,14 +314,6 @@ function Invoke-ExecCustomData { $Response = New-GraphPOSTRequest -Uri $Uri -Body $BodyContent -AsApp $true -NoAuthCheck $true -tenantid $env:TenantID - $Body = @{ - Results = @{ - state = 'success' - resultText = "Directory extension '$ExtensionName' added successfully." - extension = $Response - } - } - # store the extension in the custom data table $Entity = @{ PartitionKey = 'DirectoryExtension' @@ -310,12 +321,24 @@ function Invoke-ExecCustomData { JSON = [string](ConvertTo-Json $Response -Compress -Depth 5) } Add-CIPPAzDataTableEntity @CustomDataTable -Entity $Entity -Force + + $Result = "Directory extension '$ExtensionName' added successfully." + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' + $Body = @{ + Results = @{ + state = 'success' + resultText = $Result + extension = $Response + } + } } catch { + $Result = "Failed to add directory extension: $($_.Exception.Message)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' $Body = @{ Results = @( @{ state = 'error' - resultText = "Failed to add directory extension: $($_.Exception.Message)" + resultText = $Result } ) } @@ -344,18 +367,22 @@ function Invoke-ExecCustomData { Write-Warning "Failed to delete directory extension from custom data table: $($_.Exception.Message)" } + $Result = "Directory extension '$ExtensionName' deleted successfully." + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $Body = @{ Results = @{ state = 'success' - resultText = "Directory extension '$ExtensionName' deleted successfully." + resultText = $Result } } } catch { + $Result = "Failed to delete directory extension: $($_.Exception.Message)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' $Body = @{ Results = @( @{ state = 'error' - resultText = "Failed to delete directory extension: $($_.Exception.Message)" + resultText = $Result } ) } @@ -428,18 +455,22 @@ function Invoke-ExecCustomData { Add-CIPPAzDataTableEntity @CustomDataMappingsTable -Entity $Entity -Force Register-CIPPExtensionScheduledTasks + $Result = 'Mapping saved successfully.' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $Body = @{ Results = @{ state = 'success' - resultText = 'Mapping saved successfully.' + resultText = $Result } } } catch { + $Result = "Failed to add mapping: $($_.Exception.Message)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' $Body = @{ Results = @( @{ state = 'error' - resultText = "Failed to add mapping: $($_.Exception.Message)" + resultText = $Result } ) } @@ -461,18 +492,22 @@ function Invoke-ExecCustomData { # Delete the mapping entity Remove-CIPPAzDataTableEntity @CustomDataMappingsTable -Entity $MappingEntity Register-CIPPExtensionScheduledTasks + $Result = 'Mapping deleted successfully.' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $Body = @{ Results = @{ state = 'success' - resultText = 'Mapping deleted successfully.' + resultText = $Result } } } catch { + $Result = "Failed to delete mapping: $($_.Exception.Message)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' $Body = @{ Results = @( @{ state = 'error' - resultText = "Failed to delete mapping: $($_.Exception.Message)" + resultText = $Result } ) } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecCustomRole.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecCustomRole.ps1 index 1594453d77e7d..9f7e017f44c01 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecCustomRole.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecCustomRole.ps1 @@ -83,13 +83,14 @@ function Invoke-ExecCustomRole { $PermissionRules = ConvertTo-CippPermissionRules -Permissions $Request.Body.Permissions } $Role = @{ - 'PartitionKey' = 'CustomRoles' - 'RowKey' = "$($Request.Body.RoleName.ToLower())" - 'Permissions' = "$($Request.Body.Permissions | ConvertTo-Json -Compress)" - 'PermissionRules' = "$($PermissionRules | ConvertTo-Json -Compress -Depth 5)" - 'AllowedTenants' = "$($Request.Body.AllowedTenants | ConvertTo-Json -Compress)" - 'BlockedTenants' = "$($Request.Body.BlockedTenants | ConvertTo-Json -Compress)" - 'BlockedEndpoints' = "$($Request.Body.BlockedEndpoints | ConvertTo-Json -Compress)" + 'PartitionKey' = 'CustomRoles' + 'RowKey' = "$($Request.Body.RoleName.ToLower())" + 'Permissions' = "$($Request.Body.Permissions | ConvertTo-Json -Compress)" + 'PermissionRules' = "$($PermissionRules | ConvertTo-Json -Compress -Depth 5)" + 'AllowedTenants' = "$($Request.Body.AllowedTenants | ConvertTo-Json -Compress)" + 'BlockedTenants' = "$($Request.Body.BlockedTenants | ConvertTo-Json -Compress)" + 'BlockedEndpoints' = "$($Request.Body.BlockedEndpoints | ConvertTo-Json -Compress)" + 'AllowedRolesTemplate' = "$($Request.Body.AllowedRolesTemplate | ConvertTo-Json -Compress)" } Add-CIPPAzDataTableEntity @Table -Entity $Role -Force | Out-Null $Results.Add("Custom role $($Request.Body.RoleName) saved") @@ -166,13 +167,14 @@ function Invoke-ExecCustomRole { } $NewRole = @{ - 'PartitionKey' = 'CustomRoles' - 'RowKey' = "$($Request.Body.NewRoleName.ToLower())" - 'Permissions' = $ExistingRole.Permissions - 'PermissionRules' = "$($ExistingRole.PermissionRules)" - 'AllowedTenants' = $ExistingRole.AllowedTenants - 'BlockedTenants' = $ExistingRole.BlockedTenants - 'BlockedEndpoints' = $ExistingRole.BlockedEndpoints + 'PartitionKey' = 'CustomRoles' + 'RowKey' = "$($Request.Body.NewRoleName.ToLower())" + 'Permissions' = $ExistingRole.Permissions + 'PermissionRules' = "$($ExistingRole.PermissionRules)" + 'AllowedTenants' = $ExistingRole.AllowedTenants + 'BlockedTenants' = $ExistingRole.BlockedTenants + 'BlockedEndpoints' = $ExistingRole.BlockedEndpoints + 'AllowedRolesTemplate' = $ExistingRole.AllowedRolesTemplate } Add-CIPPAzDataTableEntity @Table -Entity $NewRole -Force | Out-Null # Clone IP ranges if they exist @@ -290,6 +292,15 @@ function Invoke-ExecCustomRole { } else { $Role | Add-Member -NotePropertyName BlockedEndpoints -NotePropertyValue @() -Force } + if ($Role.AllowedRolesTemplate) { + try { + $Role.AllowedRolesTemplate = $Role.AllowedRolesTemplate | ConvertFrom-Json + } catch { + $Role.AllowedRolesTemplate = $null + } + } else { + $Role | Add-Member -NotePropertyName AllowedRolesTemplate -NotePropertyValue $null -Force + } $EntraRoleGroup = $EntraRoleGroups | Where-Object -Property RowKey -EQ $Role.RowKey if ($EntraRoleGroup) { $EntraGroup = $EntraRoleGroups | Where-Object -Property RowKey -EQ $Role.RowKey | Select-Object @{Name = 'label'; Expression = { $_.GroupName } }, @{Name = 'value'; Expression = { $_.GroupId } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecMaintenanceScripts.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecMaintenanceScripts.ps1 index 7438b6e88dc71..f99bcdb2b8b7e 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecMaintenanceScripts.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecMaintenanceScripts.ps1 @@ -60,6 +60,7 @@ Function Invoke-ExecMaintenanceScripts { } Add-CIPPAzDataTableEntity @Table -Entity $MaintenanceScriptRow -Force + Write-LogMessage -headers $Request.Headers -API $APIName -tenant 'Global' -message "Created one-time maintenance script link for $Filename" -Sev 'Info' $Body = @{ Link = "/api/PublicScripts?guid=$LinkGuid" } } else { $Body = @{ ScriptContent = $ScriptContent } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecNotificationConfig.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecNotificationConfig.ps1 index 46e3341eb2c6a..b5a724756827c 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecNotificationConfig.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecNotificationConfig.ps1 @@ -7,6 +7,9 @@ Function Invoke-ExecNotificationConfig { #> [CmdletBinding()] param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers $sev = ([pscustomobject]$Request.body.Severity).value -join (',') $config = @{ email = $Request.body.email @@ -25,6 +28,11 @@ Function Invoke-ExecNotificationConfig { sev = $sev } $Results = Set-cippNotificationConfig @Config + if ($Results -like 'Failed*') { + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Results -Sev 'Error' + } else { + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Results -Sev 'Info' + } $body = [pscustomobject]@{'Results' = $Results } return ([HttpResponseContext]@{ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecOffloadFunctions.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecOffloadFunctions.ps1 index a2081374dffc9..c74df0f48c892 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecOffloadFunctions.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecOffloadFunctions.ps1 @@ -9,6 +9,9 @@ function Invoke-ExecOffloadFunctions { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $Table = Get-CippTable -tablename 'Config' if ($Request.Query.Action -eq 'ListCurrent') { @@ -16,6 +19,9 @@ function Invoke-ExecOffloadFunctions { $VersionTable = Get-CippTable -tablename 'Version' $Version = Get-CIPPAzDataTableEntity @VersionTable -Filter "RowKey ne 'Version'" $MainVersion = $Version | Where-Object { $_.RowKey -eq $env:WEBSITE_SITE_NAME } + # The main app's row is keyed by WEBSITE_SITE_NAME, which the container runtime does not + # set, so fall back to the running build rather than comparing against an empty string. + $MainVersionString = if ($MainVersion.Version) { $MainVersion.Version } elseif ($env:APP_VERSION) { $env:APP_VERSION } else { $null } $OffloadVersions = $Version | Where-Object { Test-CippOffloadFunctionApp -SiteName $_.RowKey } $Alerts = [System.Collections.Generic.List[string]]::new() @@ -29,9 +35,12 @@ function Invoke-ExecOffloadFunctions { foreach ($Offload in $OffloadVersions) { $FunctionName = $Offload.RowKey - if ([semver]$Offload.Version -ne [semver]$MainVersion.Version) { + if (-not $MainVersionString) { + $CanEnable = $false + $Alerts.Add("The version of $FunctionName ($($Offload.Version)) could not be checked because the current version is unknown.") + } elseif ([semver]$Offload.Version -ne [semver]$MainVersionString) { $CanEnable = $false - $Alerts.Add("The version of $FunctionName ($($Offload.Version)) does not match the current version of $($MainVersion.Version).") + $Alerts.Add("The version of $FunctionName ($($Offload.Version)) does not match the current version of $MainVersionString.") } } @@ -75,9 +84,11 @@ function Invoke-ExecOffloadFunctions { } else { $Results = 'Disabled Offload Functions' } + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Results -Sev 'Info' return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK Body = @{ results = $Results } }) } } + diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecPartnerMode.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecPartnerMode.ps1 index a7b6783ad57dc..02cb0e9d7b351 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecPartnerMode.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecPartnerMode.ps1 @@ -8,6 +8,8 @@ function Invoke-ExecPartnerMode { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers $Table = Get-CippTable -tablename 'tenantMode' if ($request.body.TenantMode) { @@ -39,12 +41,15 @@ function Invoke-ExecPartnerMode { Start-CIPPOrchestrator -InputObject $InputObject } + $Result = "Set Tenant mode to $($Request.body.TenantMode)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' + return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK Body = @{ results = @( @{ - resultText = "Set Tenant mode to $($Request.body.TenantMode)" + resultText = $Result state = 'success' } ) @@ -72,3 +77,4 @@ function Invoke-ExecPartnerMode { } } + diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecPermissionRepair.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecPermissionRepair.ps1 index 513e0bd5aca07..d6933a8a82fbc 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecPermissionRepair.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecPermissionRepair.ps1 @@ -12,11 +12,18 @@ function Invoke-ExecPermissionRepair { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint ?? 'PermissionRepair' + $Headers = $Request.Headers + try { $User = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($Request.Headers.'x-ms-client-principal')) | ConvertFrom-Json - $Result = Update-CippSamPermissions -UpdatedBy ($User.UserDetails ?? 'CIPP-API') + $UpdatedBy = $User.UserDetails ?? 'CIPP-API' + $Result = Update-CippSamPermissions -UpdatedBy $UpdatedBy + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "CIPP-SAM permissions reconciled by ${UpdatedBy}: applied table now contains the CIPP manifest permissions plus any additional permissions." -Sev 'Info' $Body = @{'Results' = $Result } } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Failed to reconcile permissions: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage $Body = @{ 'Results' = "$($_.Exception.Message) - at line $($_.InvocationInfo.ScriptLineNumber)" } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecRefreshMyAccess.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecRefreshMyAccess.ps1 index e9105d3f72a83..50af017976148 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecRefreshMyAccess.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecRefreshMyAccess.ps1 @@ -59,6 +59,7 @@ function Invoke-ExecRefreshMyAccess { $SecondsSince = ((Get-Date).ToUniversalTime() - $CooldownMarker.Timestamp.UtcDateTime).TotalSeconds if ($SecondsSince -lt $CooldownSeconds) { $WaitSeconds = [math]::Ceiling($CooldownSeconds - $SecondsSince) + Write-LogMessage -API 'RefreshMyAccess' -headers $Request.Headers -message "$Upn hit the access-refresh cooldown; returned 429 asking them to retry in $WaitSeconds seconds." -sev Info return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::TooManyRequests Body = @{ Results = "Your access was refreshed less than $CooldownSeconds seconds ago. Try again in $WaitSeconds seconds." } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecRemoveTenant.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecRemoveTenant.ps1 index c0d710475bc79..fedd9526fd5f4 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecRemoveTenant.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecRemoveTenant.ps1 @@ -8,6 +8,9 @@ function Invoke-ExecRemoveTenant { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + if ($Request.Body.TenantID -notmatch '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$') { $Body = @{Results = "Tenant ID $($Request.Body.TenantID) is not a valid GUID." } $StatusCode = [HttpStatusCode]::BadRequest @@ -17,10 +20,15 @@ function Invoke-ExecRemoveTenant { if ($Tenant) { try { Remove-CIPPAzDataTableEntity -Force @Table -Entity $Tenant - $Body = @{Results = "$($Tenant.displayName) ($($Tenant.customerId)) deleted from CIPP. Note: This does not remove the GDAP relationship, see the Tenant Offboarding wizard to perform that action." } + $Result = "$($Tenant.displayName) ($($Tenant.customerId)) deleted from CIPP. Note: This does not remove the GDAP relationship, see the Tenant Offboarding wizard to perform that action." + Write-LogMessage -headers $Headers -API $APIName -tenant $Tenant.customerId -message $Result -Sev 'Info' + $Body = @{Results = $Result } $StatusCode = [HttpStatusCode]::OK } catch { - $Body = @{Results = "Failed to delete $($Tenant.displayName) ($($Tenant.customerId)) from CIPP. Error: $($_.Exception.Message)" } + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to delete $($Tenant.displayName) ($($Tenant.customerId)) from CIPP. Error: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -tenant $Tenant.customerId -message $Result -Sev 'Error' -LogData $ErrorMessage + $Body = @{Results = $Result } $StatusCode = [HttpStatusCode]::InternalServerError } } else { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecRunTenantGroupRule.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecRunTenantGroupRule.ps1 index 4ce8658e9fc2a..f159af6c8014b 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecRunTenantGroupRule.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecRunTenantGroupRule.ps1 @@ -31,7 +31,9 @@ function Invoke-ExecRunTenantGroupRule { $null = Start-TenantDynamicGroupOrchestrator -GroupId $GroupId - $Body = @{ Results = "Dynamic rules executed successfully for group '$($Group.Name)'. Processing will continue in the background. Check the logbook for details." } + $Result = "Dynamic rules executed successfully for group '$($Group.Name)'. Processing will continue in the background. Check the logbook for details." + Write-LogMessage -API 'TenantGroups' -tenant 'Global' -headers $Request.Headers -message $Result -Sev 'Info' + $Body = @{ Results = $Result } return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK @@ -39,7 +41,7 @@ function Invoke-ExecRunTenantGroupRule { }) } catch { $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message - Write-LogMessage -API 'TenantGroups' -message "Failed to execute tenant group rules: $ErrorMessage" -sev Error + Write-LogMessage -API 'TenantGroups' -tenant 'Global' -message "Failed to execute tenant group rules: $ErrorMessage" -sev Error $Body = @{ Results = "Failed to execute dynamic rules: $ErrorMessage" } return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::InternalServerError diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecSAMRoles.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecSAMRoles.ps1 index 9c5ad86db193a..f7f8af3500ac0 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecSAMRoles.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecSAMRoles.ps1 @@ -8,17 +8,29 @@ function Invoke-ExecSAMRoles { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $SAMRolesTable = Get-CIPPTable -tablename 'SAMRoles' switch ($Request.Query.Action) { 'Update' { - $Entity = [pscustomobject]@{ - PartitionKey = 'SAMRoles' - RowKey = 'SAMRoles' - Roles = [string](ConvertTo-Json -Depth 5 -Compress -InputObject $Request.Body.Roles) - Tenants = [string](ConvertTo-Json -Depth 5 -Compress -InputObject $Request.Body.Tenants) + try { + $Entity = [pscustomobject]@{ + PartitionKey = 'SAMRoles' + RowKey = 'SAMRoles' + Roles = [string](ConvertTo-Json -Depth 5 -Compress -InputObject $Request.Body.Roles) + Tenants = [string](ConvertTo-Json -Depth 5 -Compress -InputObject $Request.Body.Tenants) + } + $null = Add-CIPPAzDataTableEntity @SAMRolesTable -Entity $Entity -Force + $Result = 'Successfully updated SAM roles' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' + $Body = [pscustomobject]@{'Results' = $Result } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to update SAM roles: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' -LogData $ErrorMessage + $Body = [pscustomobject]@{'Results' = $Result } } - $null = Add-CIPPAzDataTableEntity @SAMRolesTable -Entity $Entity -Force - $Body = [pscustomobject]@{'Results' = 'Successfully updated SAM roles' } } default { $SAMRoles = Get-CIPPAzDataTableEntity @SAMRolesTable diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecTenantGroup.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecTenantGroup.ps1 index b4387430ff53e..6938be3bb72a2 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecTenantGroup.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecTenantGroup.ps1 @@ -144,6 +144,7 @@ function Invoke-ExecTenantGroup { }) } + Write-LogMessage -API 'TenantGroups' -tenant 'Global' -headers $Request.Headers -message "Group '$groupName' saved successfully" -Sev 'Info' $Body = @{ Results = $Results } } 'Delete' { @@ -151,7 +152,9 @@ function Invoke-ExecTenantGroup { $GroupEntity = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'TenantGroup' and RowKey eq '$groupId'" if ($GroupEntity) { Remove-CIPPAzDataTableEntity @Table -Entity $GroupEntity -Force - $Body = @{ Results = "Group '$($GroupEntity.Name)' deleted successfully" } + $Result = "Group '$($GroupEntity.Name)' deleted successfully" + Write-LogMessage -API 'TenantGroups' -tenant 'Global' -headers $Request.Headers -message $Result -Sev 'Info' + $Body = @{ Results = $Result } } else { $Body = @{ Results = "Group '$groupId' not found" } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecUserBookmarks.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecUserBookmarks.ps1 index 1b6ca6abc3302..8d83ec8001e13 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecUserBookmarks.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecUserBookmarks.ps1 @@ -1,11 +1,15 @@ function Invoke-ExecUserBookmarks { <# .FUNCTIONALITY - Entrypoint + Entrypoint,AnyTenant .ROLE CIPP.Core.ReadWrite #> param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + try { $Bookmarks = $Request.Body.currentSettings.bookmarks if ($null -eq $Bookmarks) { @@ -24,10 +28,14 @@ function Invoke-ExecUserBookmarks { PartitionKey = 'UserBookmarks' } $StatusCode = [HttpStatusCode]::OK - $Results = [pscustomobject]@{'Results' = 'Successfully added user bookmarks' } + $Result = 'Successfully added user bookmarks' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' + $Results = [pscustomobject]@{'Results' = $Result } } catch { $ErrorMsg = Get-NormalizedError -message $($_.Exception.Message) - $Results = "Function Error: $ErrorMsg" + $Result = "Function Error: $ErrorMsg" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' + $Results = $Result $StatusCode = [HttpStatusCode]::BadRequest } return [HttpResponseContext]@{ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecUserSettings.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecUserSettings.ps1 index 3bea3e902cda0..b665b8ea004b2 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecUserSettings.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecUserSettings.ps1 @@ -6,6 +6,10 @@ function Invoke-ExecUserSettings { CIPP.Core.ReadWrite #> param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + try { $object = $Request.Body.currentSettings | Select-Object * -ExcludeProperty CurrentTenant, pageSizes, sidebarShow, sidebarUnfoldable, _persist | ConvertTo-Json -Compress -Depth 10 $User = $Request.Body.user @@ -17,10 +21,14 @@ function Invoke-ExecUserSettings { PartitionKey = 'UserSettings' } $StatusCode = [HttpStatusCode]::OK - $Results = [pscustomobject]@{'Results' = 'Successfully added user settings' } + $Result = 'Successfully added user settings' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' + $Results = [pscustomobject]@{'Results' = $Result } } catch { $ErrorMsg = Get-NormalizedError -message $($_.Exception.Message) - $Results = "Function Error: $ErrorMsg" + $Result = "Function Error: $ErrorMsg" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' + $Results = $Result $StatusCode = [HttpStatusCode]::BadRequest } return [HttpResponseContext]@{ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListCustomRole.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListCustomRole.ps1 index e231cdcd085db..7c1be797a8032 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListCustomRole.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListCustomRole.ps1 @@ -139,6 +139,21 @@ function Invoke-ListCustomRole { $Role | Add-Member -NotePropertyName EntraGroup -NotePropertyValue $EntraGroup.GroupName -Force $Role | Add-Member -NotePropertyName EntraGroupId -NotePropertyValue $EntraGroup.GroupId -Force } + + # Custom roles keep their IP allow-list in AccessIPRanges (same as the built-in roles + # above); surface it here so this read-only list carries it too. + $IPRangeEntity = $AccessIPRanges | Where-Object -Property RowKey -EQ $Role.RowKey + if ($IPRangeEntity) { + try { + $IPRanges = @($IPRangeEntity.IPRanges | ConvertFrom-Json) + } catch { + $IPRanges = @() + } + } else { + $IPRanges = @() + } + $Role | Add-Member -NotePropertyName IPRange -NotePropertyValue $IPRanges -Force + $RoleList.Add($Role) } $Body = @($RoleList) diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListExcludedLicenses.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListExcludedLicenses.ps1 index 49c19af758381..e69bb30a84736 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListExcludedLicenses.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListExcludedLicenses.ps1 @@ -30,7 +30,7 @@ function Invoke-ListExcludedLicenses { $_ | Add-Member -NotePropertyName 'ExcludedEverywhere' -NotePropertyValue $true -Force } if ($null -eq $_.ShowInLicenseDropdown) { - $_ | Add-Member -NotePropertyName 'ShowInLicenseDropdown' -NotePropertyValue $false -Force + $_ | Add-Member -NotePropertyName 'ShowInLicenseDropdown' -NotePropertyValue $true -Force } $ExclusionType = if ($_.ExcludedEverywhere -eq $true) { 'Excluded Everywhere' } else { 'Excluded from Alerts Only' } $_ | Add-Member -NotePropertyName 'ExclusionType' -NotePropertyValue $ExclusionType -Force diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecCombinedSetup.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecCombinedSetup.ps1 index a6e6622499adc..2ae54831342f8 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecCombinedSetup.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecCombinedSetup.ps1 @@ -11,6 +11,38 @@ function Invoke-ExecCombinedSetup { #Make arraylist of Results $Results = [System.Collections.ArrayList]::new() try { + # Certificate-auth toggle for an existing install: enabling keeps the client secret as a rollback + # and switches SAM tokens to the certificate. Idempotent with a certificate-only First Setup. + if ($null -ne $Request.Body.certificateAuth) { + # Ensure credentials are loaded so the secret-usability check below is accurate on a cold + # runspace (otherwise a legitimate secret-based install could be wrongly refused a disable). + $null = Get-CIPPAuthentication + if ($Request.Body.certificateAuth -eq $true) { + try { + # Make sure the certificate exists and is registered on the app before switching to it. + $null = Update-CIPPSAMCertificate -ErrorAction Stop + $Cert = Get-CIPPSAMCertificate -SkipCache -ErrorAction Stop + if (-not $Cert) { throw 'No SAM certificate is available to authenticate with.' } + $null = Set-CIPPFeatureFlag -Id 'CertificateAuthentication' -Enabled $true -Force + $env:CertificateAuthMode = $true + $Results.add('Enabled certificate authentication. CIPP now authenticates with the SAM certificate instead of the client secret. The client secret is kept as a rollback - disable this option to switch back.') + } catch { + $Results.add("Could not enable certificate authentication: $($_.Exception.Message). The existing authentication method is unchanged.") + } + } else { + # Refuse to disable with no usable secret to fall back to - that would break auth. + $SecretPlaceholderPattern = '^(LongApplicationId|AppSecret|RefreshToken|tenantId)$' + $SecretUsable = $env:ApplicationSecret -and $env:ApplicationSecret -notmatch $SecretPlaceholderPattern + if (-not $SecretUsable) { + $Results.add('Certificate authentication cannot be disabled: this install has no client secret to fall back to.') + } else { + $null = Set-CIPPFeatureFlag -Id 'CertificateAuthentication' -Enabled $false -Force + $env:CertificateAuthMode = $null + $Results.add('Disabled certificate authentication. CIPP will use the client secret again.') + } + } + } + if ($request.body.selectedBaselines -and $request.body.baselineOption -eq 'downloadBaselines') { #do a single download of the selected baselines. foreach ($template in $request.body.selectedBaselines) { @@ -54,6 +86,11 @@ function Invoke-ExecCombinedSetup { $notificationConfig = $request.body | Select-Object email, webhook, onepertenant, logsToInclude, sendtoIntegration, sev | ConvertTo-Json | ConvertFrom-Json -AsHashtable $notificationResults = Set-CIPPNotificationConfig @notificationConfig $Results.add($notificationResults) + if ($notificationResults -like 'Failed*') { + Write-LogMessage -headers $Request.Headers -API ($Request.Params.CIPPEndpoint ?? 'CombinedSetup') -tenant 'Global' -message $notificationResults -Sev 'Error' + } else { + Write-LogMessage -headers $Request.Headers -API ($Request.Params.CIPPEndpoint ?? 'CombinedSetup') -tenant 'Global' -message $notificationResults -Sev 'Info' + } } if ($Request.Body.selectedOption -eq 'Manual') { $KV = Get-CippKeyVaultName diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecCreateSAMApp.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecCreateSAMApp.ps1 index e215ea1794b07..bce1a1c0c93a2 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecCreateSAMApp.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecCreateSAMApp.ps1 @@ -9,11 +9,16 @@ function Invoke-ExecCreateSAMApp { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers $KV = Get-CippKeyVaultName try { $Token = $Request.body if ($Token) { + # A certificate-only setup provisions no client secret. Determined up front so every app + # management policy call in this flow leaves the password-addition block in force. + $CertificateOnly = $Request.body.certificateOnly -eq $true $URL = $Request.headers.origin ?? $Request.headers.referer?.TrimEnd('/') $RedirectUri = "$URL/authredirect" $AuthCallbackUri = "$URL/.auth/callback" @@ -71,14 +76,31 @@ function Invoke-ExecCreateSAMApp { try { - $AppPolicyStatus = Update-AppManagementPolicy -Headers @{ authorization = "Bearer $($Token.access_token)" } -ApplicationId $appId.appId + $AppPolicyStatus = Update-AppManagementPolicy -Headers @{ authorization = "Bearer $($Token.access_token)" } -ApplicationId $appId.appId -CertificateOnly $CertificateOnly Write-Information $AppPolicyStatus.PolicyAction } catch { Write-Warning "Error updating app management policy $($_.Exception.Message)." Write-Information ($_.InvocationInfo.PositionMessage) } - $AppPassword = (Invoke-RestMethod "https://graph.microsoft.com/v1.0/applications/$($AppId.id)/addPassword" -Headers @{ authorization = "Bearer $($Token.access_token)" } -Method POST -Body '{"passwordCredential":{"displayName":"CIPPInstall"}}' -ContentType 'application/json').secretText + # A certificate-only setup provisions no client secret - the SAM certificate is the sole + # credential. Register it now (before the token step, which will authenticate with it) and + # turn on the feature flag so the reload below resolves certificate mode. + if ($CertificateOnly) { + try { + # Enable certificate mode BEFORE provisioning so the app management policy exemption + # leaves the password-addition block in force (no client secret is ever added). + $null = Set-CIPPFeatureFlag -Id 'CertificateAuthentication' -Enabled $true -Force + $env:CertificateAuthMode = $true + $CertResult = Update-CIPPSAMCertificate -ApplicationId $AppId.appId -Headers @{ authorization = "Bearer $($Token.access_token)" } -ErrorAction Stop + Write-Information "Registered SAM certificate for certificate-only setup. Thumbprint: $($CertResult.Thumbprint), storage mode: $($CertResult.StorageMode)" + } catch { + throw "Certificate-only setup was selected but the SAM certificate could not be registered on the application. Setup cannot continue without a credential. $($_.Exception.Message)" + } + $AppPassword = $null + } else { + $AppPassword = (Invoke-RestMethod "https://graph.microsoft.com/v1.0/applications/$($AppId.id)/addPassword" -Headers @{ authorization = "Bearer $($Token.access_token)" } -Method POST -Body '{"passwordCredential":{"displayName":"CIPPInstall"}}' -ContentType 'application/json').secretText + } if ($env:AzureWebJobsStorage -eq 'UseDevelopmentStorage=true' -or $env:NonLocalHostAzurite -eq 'true') { $DevSecretsTable = Get-CIPPTable -tablename 'DevSecrets' @@ -88,12 +110,17 @@ function Invoke-ExecCreateSAMApp { $Secret | Add-Member -MemberType NoteProperty -Name 'RowKey' -Value 'Secret' -Force $Secret | Add-Member -MemberType NoteProperty -Name 'tenantid' -Value $TenantId -Force $Secret | Add-Member -MemberType NoteProperty -Name 'applicationid' -Value $AppId.appId -Force - $Secret | Add-Member -MemberType NoteProperty -Name 'applicationsecret' -Value $AppPassword -Force + # Blank the stored secret in certificate-only mode so CIPP falls through to the certificate + $Secret | Add-Member -MemberType NoteProperty -Name 'applicationsecret' -Value ($AppPassword ?? '') -Force Add-CIPPAzDataTableEntity @DevSecretsTable -Entity $Secret -Force } else { Set-CippKeyVaultSecret -VaultName $kv -Name 'tenantid' -SecretValue (ConvertTo-SecureString -String $TenantId -AsPlainText -Force) Set-CippKeyVaultSecret -VaultName $kv -Name 'applicationid' -SecretValue (ConvertTo-SecureString -String $Appid.appId -AsPlainText -Force) - Set-CippKeyVaultSecret -VaultName $kv -Name 'applicationsecret' -SecretValue (ConvertTo-SecureString -String $AppPassword -AsPlainText -Force) + # Certificate-only setups create no secret; leave the placeholder in place so it reads + # back as unusable and CIPP authenticates with the certificate instead. + if ($AppPassword) { + Set-CippKeyVaultSecret -VaultName $kv -Name 'applicationsecret' -SecretValue (ConvertTo-SecureString -String $AppPassword -AsPlainText -Force) + } } # Populate this process straight from the values we just created. The wizard # moves to the next step immediately and every reader treats $env:ApplicationID @@ -134,7 +161,7 @@ function Invoke-ExecCreateSAMApp { } } if (-not $SecretsReadable) { - Write-LogMessage -message "Created the application registration but could not read the application id back from storage after $ReadAttempts attempts. This instance holds the new credentials, but other instances may still serve the previous values until the write propagates." -Sev 'Warning' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Created the application registration but could not read the application id back from storage after $ReadAttempts attempts. This instance holds the new credentials, but other instances may still serve the previous values until the write propagates." -Sev 'Warning' } $ConfigTable = Get-CippTable -tablename 'Config' @@ -172,7 +199,9 @@ function Invoke-ExecCreateSAMApp { Write-Warning "Failed to create SAM certificate during setup, the weekly token update will create it: $($_.Exception.Message)" } - $Results = @{'message' = "Successfully $state the application registration. The application ID is $($AppId.appid). You may continue to the next step."; severity = 'success' } + $CredentialNote = if ($CertificateOnly) { ' This is a certificate-only setup - no client secret was created, and CIPP will authenticate with the SAM certificate.' } else { '' } + $Results = @{'message' = "Successfully $state the application registration. The application ID is $($AppId.appid).$CredentialNote You may continue to the next step."; severity = 'success' } + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Successfully $state CIPP-SAM application registration AppId=$($AppId.appId) (certificate-only=$CertificateOnly)" -Sev 'Info' } } catch { @@ -184,6 +213,7 @@ function Invoke-ExecCreateSAMApp { } else { $_.Exception.Message } + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Failed to create or update CIPP-SAM application registration: $ErrorDetail" -Sev 'Error' $Results = [pscustomobject]@{'Results' = "Failed. $($_.InvocationInfo.ScriptLineNumber): $ErrorDetail"; severity = 'failed' } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecSamSecretStatus.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecSamSecretStatus.ps1 index 06cdc3c424844..982d802e5072a 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecSamSecretStatus.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecSamSecretStatus.ps1 @@ -18,6 +18,25 @@ function Invoke-ExecSamSecretStatus { try { $null = Get-CIPPAuthentication + # Certificate mode has no client secret to wait on - report ready once the SAM certificate + # exists, so the sign-in step isn't gated on a secret that will never be created. + if ($env:CertificateAuthMode) { + $Cert = Get-CIPPSAMCertificate -SkipCache -ErrorAction SilentlyContinue + if ($Cert) { + $Results = @{ ready = $true; reason = 'certificate' } + } else { + $Results = @{ + ready = $false + reason = 'certificatePending' + message = 'Preparing the SAM certificate. This unlocks automatically once the certificate is registered on the application.' + } + } + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = $Results + }) + } + # Same placeholder set the deployment template seeds and Get-CIPPAuthentication skips. $PlaceholderPattern = '^(LongApplicationId|AppSecret|RefreshToken|tenantId)$' $Configured = $env:ApplicationID -and $env:ApplicationID -notmatch $PlaceholderPattern -and diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecTokenExchange.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecTokenExchange.ps1 index dcf2154812270..0d986f51f3f49 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecTokenExchange.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecTokenExchange.ps1 @@ -38,46 +38,71 @@ function Invoke-ExecTokenExchange { Write-LogMessage -API $APIName -message "Making token request to $TokenUrl" -Sev 'Info' - # Make sure we get the latest authentication + # Make sure we get the latest authentication (also refreshes $env:CertificateAuthMode) $auth = Get-CIPPAuthentication - # Check if environment variable is already set and not the placeholder value + # Convert the token request to form data first, so the chosen credential - client secret + # or certificate assertion - can be layered on top. + $FormData = @{} + foreach ($key in $TokenRequest.PSObject.Properties.Name) { + $FormData[$key] = $TokenRequest.$key + } + + # Resolve the client secret, tolerating its absence. A secret-less certificate-only setup + # never has one, and certificate mode does not use it even when it exists. + $ClientSecret = $null if ($auth -and $env:ApplicationSecret -and $env:ApplicationSecret -ne 'AppSecret') { $ClientSecret = $env:ApplicationSecret - Write-LogMessage -API $APIName -message 'Using client secret from environment variable' -Sev 'Debug' } elseif ($env:AzureWebJobsStorage -eq 'UseDevelopmentStorage=true' -or $env:NonLocalHostAzurite -eq 'true') { $DevSecretsTable = Get-CIPPTable -tablename 'DevSecrets' $Secret = Get-CIPPAzDataTableEntity @DevSecretsTable -Filter "PartitionKey eq 'Secret' and RowKey eq 'Secret'" $ClientSecret = $Secret.applicationsecret - Write-LogMessage -API $APIName -message 'Retrieved client secret from development secrets' -Sev 'Debug' } else { try { $ClientSecret = (Get-CippKeyVaultSecret -VaultName $kv -Name 'applicationsecret' -AsPlainText) - Write-LogMessage -API $APIName -message 'Retrieved client secret from key vault' -Sev 'Debug' } catch { - Write-LogMessage -API $APIName -message "Failed to retrieve client secret: $($_.Exception.Message)" -Sev 'Error' - throw "Failed to retrieve client secret: $($_.Exception.Message)" + Write-LogMessage -API $APIName -message "Could not retrieve client secret (expected for a certificate-only setup): $($_.Exception.Message)" -Sev 'Debug' } } + $SecretUsable = $ClientSecret -and $ClientSecret -ne 'AppSecret' - # Check if client secret is still the default placeholder value from ARM template - if (!$ClientSecret -or $ClientSecret -eq 'AppSecret') { - Write-LogMessage -API $APIName -message 'Client secret is not configured' -Sev 'Error' - throw 'Application secret has not been configured. Please complete the setup process first.' - } + # Use a signed certificate assertion instead of the client secret when certificate mode is + # on, or when there is no usable secret at all (a secret-less setup - the only way to auth). + $UseCertAssertion = [bool]$env:CertificateAuthMode -or -not $SecretUsable - # Convert token request to form data and add client secret - $FormData = @{} - foreach ($key in $TokenRequest.PSObject.Properties.Name) { - $FormData[$key] = $TokenRequest.$key - } - - # Add client_secret to the form data if not already present - if (!$FormData.ContainsKey('client_secret')) { + if ($UseCertAssertion) { + $AppId = $FormData['client_id'] + if (!$AppId) { throw 'Token request is missing client_id; cannot build a certificate assertion.' } + $SAMCert = Get-CIPPSAMCertificate -SkipCache + if (-not $SAMCert) { + throw 'Certificate authentication is required but no SAM certificate is available. Complete the application step first, then retry.' + } + # Assertion audience = the tenant the sign-in targets ($env:TenantID). The body's tenantId is + # actually the app id, so it is not a valid audience; fall back to the multi-tenant authority. + $GuidPattern = '^[0-9a-f]{8}-([0-9a-f]{4}-){3}[0-9a-f]{12}$' + $AssertionTenant = if ($env:TenantID -match $GuidPattern) { $env:TenantID } else { 'organizations' } + $FormData.Remove('client_secret') + $FormData['client_assertion_type'] = 'urn:ietf:params:oauth:client-assertion-type:jwt-bearer' + Write-LogMessage -API $APIName -message 'Using the SAM certificate assertion for the token exchange' -Sev 'Debug' + } elseif (!$FormData.ContainsKey('client_secret')) { $FormData['client_secret'] = $ClientSecret } - $Results = Invoke-RestMethod -Uri $TokenUrl -Method Post -Body $FormData -ContentType 'application/x-www-form-urlencoded' -ErrorAction Stop -SkipHttpErrorCheck + # AADSTS700027 fires transiently while a freshly registered certificate propagates - retry + # briefly, regenerating the assertion each attempt so it never expires mid-retry. + $MaxAttempts = if ($UseCertAssertion) { 3 } else { 1 } + for ($Attempt = 1; $Attempt -le $MaxAttempts; $Attempt++) { + if ($UseCertAssertion) { + $FormData['client_assertion'] = New-CIPPCertificateAssertion -TenantId $AssertionTenant -AppId $AppId -Certificate $SAMCert.Certificate + } + $Results = Invoke-RestMethod -Uri $TokenUrl -Method Post -Body $FormData -ContentType 'application/x-www-form-urlencoded' -ErrorAction Stop -SkipHttpErrorCheck + if ($UseCertAssertion -and $Attempt -lt $MaxAttempts -and $Results.error_description -match 'AADSTS700027') { + Write-LogMessage -API $APIName -message "Certificate not yet recognized by the token service (attempt $Attempt of $MaxAttempts). Retrying." -Sev 'Warning' + Start-Sleep -Seconds 10 + continue + } + break + } } catch { $ErrorMessage = $_.Exception $Results = @{ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecUpdateRefreshToken.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecUpdateRefreshToken.ps1 index 321388cd22332..0e6fe7123457e 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecUpdateRefreshToken.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecUpdateRefreshToken.ps1 @@ -9,6 +9,8 @@ function Invoke-ExecUpdateRefreshToken { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers $KV = Get-CippKeyVaultName try { @@ -72,8 +74,10 @@ function Invoke-ExecUpdateRefreshToken { } else { $TenantName = $request.body.tenantId } + $Result = "Successfully updated the credentials for $($TenantName). You may continue to the next step, or add additional tenants if required." + Write-LogMessage -headers $Headers -API $APIName -tenant $Request.body.tenantId -message $Result -Sev 'Info' $Results = @{ - 'resultText' = "Successfully updated the credentials for $($TenantName). You may continue to the next step, or add additional tenants if required." + 'resultText' = $Result 'state' = 'success' } @@ -82,6 +86,9 @@ function Invoke-ExecUpdateRefreshToken { Body = $Results }) } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to update refresh token credentials. $($_.InvocationInfo.ScriptLineNumber): $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -tenant $Request.body.tenantId -message $Result -Sev 'Error' -LogData $ErrorMessage $Results = [pscustomobject]@{ 'Results' = @{ resultText = "Failed. $($_.InvocationInfo.ScriptLineNumber): $($_.Exception.message)" diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Contacts/Invoke-RemoveContact.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Contacts/Invoke-RemoveContact.ps1 index 9407a92f8fc9c..89ea2f79e8fc2 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Contacts/Invoke-RemoveContact.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Contacts/Invoke-RemoveContact.ps1 @@ -21,7 +21,7 @@ Function Invoke-RemoveContact { Identity = $GUID } $null = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Remove-MailContact' -cmdParams $Params -UseSystemMailbox $true - Write-LogMessage -Headers $Request.Headers -API $APIName -tenant $TenantFilter -message "Deleted contact $GUID" -sev Debug + Write-LogMessage -Headers $Request.Headers -API $APIName -tenant $TenantFilter -message "Deleted contact $GUID" -sev 'Info' $Result = "Deleted $Mail" $StatusCode = [HttpStatusCode]::OK } catch { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecMailboxMobileDevices.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecMailboxMobileDevices.ps1 index 559b47142f3ba..50c153b02f6dc 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecMailboxMobileDevices.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecMailboxMobileDevices.ps1 @@ -9,12 +9,19 @@ Function Invoke-ExecMailboxMobileDevices { param($Request, $TriggerMetadata) $APIName = $Request.Params.CIPPEndpoint - # Interact with query parameters or the body of the request. + # Interact with query parameters or the body of the request. This is a state-changing action, + # so the frontend dispatches it as a POST; keep the query fallback for backwards compatibility. + $UserId = $Request.Body.Userid ?? $Request.Query.Userid + $Guid = $Request.Body.guid ?? $Request.Query.guid + $DeviceId = $Request.Body.deviceid ?? $Request.Query.deviceid + $Quarantine = $Request.Body.Quarantine ?? $Request.Query.Quarantine + $Delete = $Request.Body.Delete ?? $Request.Query.Delete + $TenantFilter = $Request.Body.tenantFilter ?? $Request.Query.tenantFilter Try { - $MobileResults = Set-CIPPMobileDevice -UserId $request.query.Userid -Guid $request.query.guid -DeviceId $request.query.deviceid -Quarantine $request.query.Quarantine -tenantFilter $request.query.tenantfilter -APIName $APINAME -Delete $Request.query.Delete -Headers $Request.Headers + $MobileResults = Set-CIPPMobileDevice -UserId $UserId -Guid $Guid -DeviceId $DeviceId -Quarantine $Quarantine -tenantFilter $TenantFilter -APIName $APINAME -Delete $Delete -Headers $Request.Headers $Results = [pscustomobject]@{'Results' = $MobileResults } } catch { - $Results = [pscustomobject]@{'Results' = "Failed $($request.query.Userid): $($_.Exception.Message)" } + $Results = [pscustomobject]@{'Results' = "Failed $($UserId): $($_.Exception.Message)" } } return ([HttpResponseContext]@{ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecScheduleForwardingVacation.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecScheduleForwardingVacation.ps1 index f6475705c88d2..a7252770b63bf 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecScheduleForwardingVacation.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecScheduleForwardingVacation.ps1 @@ -84,6 +84,7 @@ function Invoke-ExecScheduleForwardingVacation { }) -hidden $false $Result = "Successfully scheduled forwarding vacation mode for $UserDisplay." + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecScheduleMailboxVacation.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecScheduleMailboxVacation.ps1 index 04eac0b8393ea..8a8a9c4c3e7f2 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecScheduleMailboxVacation.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecScheduleMailboxVacation.ps1 @@ -124,6 +124,7 @@ function Invoke-ExecScheduleMailboxVacation { Add-CIPPScheduledTask -Task $RemoveTaskBody -hidden $false $Result = "Successfully scheduled mailbox vacation mode for $DelegateDisplay -> $OwnerDisplay." + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecScheduleOOOVacation.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecScheduleOOOVacation.ps1 index 79fcbea7d9208..693ed5b50adbe 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecScheduleOOOVacation.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ExecScheduleOOOVacation.ps1 @@ -86,6 +86,7 @@ function Invoke-ExecScheduleOOOVacation { }) -hidden $false $Result = "Successfully scheduled OOO vacation mode for $UserDisplay." + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ListMailboxes.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ListMailboxes.ps1 index 500bdf5ff006c..56202680ad0ee 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ListMailboxes.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ListMailboxes.ps1 @@ -5,7 +5,7 @@ function Invoke-ListMailboxes { .ROLE Exchange.Mailbox.Read .DESCRIPTION - Lists Exchange Online mailboxes for a tenant. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants. + Lists Exchange Online mailboxes for a tenant. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants. When manualPagination is also set, one page is returned per request as { Results, Metadata } with a continuation token in Metadata.nextLink. #> [CmdletBinding()] param($Request, $TriggerMetadata) @@ -13,10 +13,30 @@ function Invoke-ListMailboxes { $TenantFilter = $Request.Query.tenantFilter # Serve from the reporting database cache instead of live Graph. Much faster, especially for AllTenants. $UseReportDB = $Request.Query.UseReportDB -eq $true + # Return one page per request as { Results, Metadata } with a continuation token in Metadata.nextLink; cached reads only. + $ManualPagination = $Request.Query.manualPagination -and [System.Convert]::ToBoolean($Request.Query.manualPagination) try { # If UseReportDB is specified, retrieve from report database if ($UseReportDB) { try { + if ($ManualPagination) { + # Rows per page, clamped between 250 and 10000. Defaults to 5000. + $PageSize = 5000 + if ($Request.Query.PageSize -as [int]) { + $PageSize = [Math]::Min([Math]::Max([int]$Request.Query.PageSize, 250), 10000) + } + # Continuation token from the previous page's Metadata.nextLink; opaque to callers. + $Page = Get-CIPPMailboxesReport -TenantFilter $TenantFilter -PageSize $PageSize -ContinuationToken $Request.Query.nextLink -ErrorAction Stop + $Metadata = @{} + if ($Page.NextToken) { $Metadata.nextLink = $Page.NextToken } + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = [PSCustomObject]@{ + Results = @($Page.Items) + Metadata = $Metadata + } + }) + } $GraphRequest = Get-CIPPMailboxesReport -TenantFilter $TenantFilter -ErrorAction Stop $StatusCode = [HttpStatusCode]::OK } catch { @@ -33,7 +53,14 @@ function Invoke-ListMailboxes { # Original live EXO logic $ZeroArchiveGuid = '00000000-0000-0000-0000-000000000000' - $Select = 'id,ExchangeGuid,ArchiveGuid,UserPrincipalName,DisplayName,PrimarySMTPAddress,RecipientType,RecipientTypeDetails,EmailAddresses,WhenSoftDeleted,IsInactiveMailbox,ForwardingSmtpAddress,DeliverToMailboxAndForward,ForwardingAddress,HiddenFromAddressListsEnabled,ExternalDirectoryObjectId,IsDirSynced,MessageCopyForSendOnBehalfEnabled,MessageCopyForSentAsEnabled,PersistedCapabilities,LitigationHoldEnabled,LitigationHoldDate,LitigationHoldDuration,ComplianceTagHoldApplied,RetentionHoldEnabled,InPlaceHolds,RetentionPolicy,AutoExpandingArchiveEnabled' + # Picker mode: address autocompletes only need the address + name, so skip the heavy field + # set, the per-mailbox computed properties, and the extra Get-OrganizationConfig call. + $Minimal = $Request.Query.Minimal -eq $true + if ($Minimal) { + $Select = 'id,UserPrincipalName,DisplayName,PrimarySMTPAddress' + } else { + $Select = 'id,ExchangeGuid,ArchiveGuid,UserPrincipalName,DisplayName,PrimarySMTPAddress,RecipientType,RecipientTypeDetails,EmailAddresses,WhenSoftDeleted,IsInactiveMailbox,ForwardingSmtpAddress,DeliverToMailboxAndForward,ForwardingAddress,HiddenFromAddressListsEnabled,ExternalDirectoryObjectId,IsDirSynced,MessageCopyForSendOnBehalfEnabled,MessageCopyForSentAsEnabled,PersistedCapabilities,LitigationHoldEnabled,LitigationHoldDate,LitigationHoldDuration,ComplianceTagHoldApplied,RetentionHoldEnabled,InPlaceHolds,RetentionPolicy,AutoExpandingArchiveEnabled' + } $ExoRequest = @{ tenantid = $TenantFilter cmdlet = 'Get-Mailbox' @@ -73,6 +100,18 @@ function Invoke-ListMailboxes { } } + if ($Minimal) { + $GraphRequest = @(New-ExoRequest @ExoRequest) | Select-Object Id, + @{ Name = 'UPN'; Expression = { $_.'UserPrincipalName' } }, + @{ Name = 'displayName'; Expression = { $_.'DisplayName' } }, + @{ Name = 'primarySmtpAddress'; Expression = { $_.'PrimarySMTPAddress' } } + + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = @($GraphRequest) + }) + } + $OrgAutoExpandingArchiveEnabled = (New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-OrganizationConfig' -Select 'AutoExpandingArchiveEnabled').AutoExpandingArchiveEnabled $GraphRequest = foreach ($Mailbox in @(New-ExoRequest @ExoRequest)) { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Reports/Invoke-ListMailFlowReports.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Reports/Invoke-ListMailFlowReports.ps1 new file mode 100644 index 0000000000000..e1769d38d4424 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Reports/Invoke-ListMailFlowReports.ps1 @@ -0,0 +1,66 @@ +function Invoke-ListMailFlowReports { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Exchange.Mailbox.Read + .DESCRIPTION + Returns Exchange Online mail flow reports: disposition counts by day (Get-MailFlowStatusReport) + and top sender/recipient summaries (Get-MailTrafficSummaryReport). Both support up to 90 days. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + try { + $TenantFilter = $Request.Query.tenantFilter + $ReportType = $Request.Query.reportType ?? 'MailFlowStatus' + $Days = [Math]::Min([Math]::Max([int]($Request.Query.days ?? 14), 1), 90) + $StartDate = (Get-Date).AddDays(-$Days).ToUniversalTime().ToString('s') + $EndDate = (Get-Date).ToUniversalTime().ToString('s') + + $Report = switch ($ReportType) { + 'MailFlowStatus' { + $CmdParams = @{ StartDate = $StartDate; EndDate = $EndDate } + New-ExoRequest -TenantId $TenantFilter -Cmdlet 'Get-MailFlowStatusReport' -CmdParams $CmdParams | + Select-Object @{ Name = 'Date'; Expression = { ([DateTime]$_.Date).ToString('yyyy-MM-dd') } }, Direction, EventType, @{ Name = 'Count'; Expression = { $_.MessageCount } } + } + 'TrafficSummary' { + $Category = $Request.Query.category ?? 'TopMailSender' + $CmdParams = @{ Category = $Category; StartDate = $StartDate; EndDate = $EndDate } + # C1/C2/C3 are generic columns whose meaning depends on the category; for the Top* categories + # C1 is the address/name and C2 the message count. + New-ExoRequest -TenantId $TenantFilter -Cmdlet 'Get-MailTrafficSummaryReport' -CmdParams $CmdParams | + Select-Object @{ Name = 'Name'; Expression = { $_.C1 } }, @{ Name = 'Count'; Expression = { $_.C2 } }, @{ Name = 'Extra'; Expression = { $_.C3 } } + } + default { + throw "Unknown report type '$ReportType'. Supported: MailFlowStatus, TrafficSummary." + } + } + + $StatusCode = [HttpStatusCode]::OK + $Body = @{ + Results = @($Report) + Metadata = @{ + ReportType = $ReportType + StartDate = $StartDate + EndDate = $EndDate + } + } + } catch { + $ErrorMessage = Get-NormalizedError -message $_.Exception.Message + Write-LogMessage -headers $Headers -API $APIName -tenant $($TenantFilter) -message "Failed to retrieve mail flow report. Error: $ErrorMessage" -Sev 'Error' + $StatusCode = [HttpStatusCode]::InternalServerError + $Body = @{ + Results = @() + Metadata = @{ Error = "Failed to retrieve mail flow report: $ErrorMessage" } + } + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = $Body + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Spamfilter/Invoke-AddSpamFilterTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Spamfilter/Invoke-AddSpamFilterTemplate.ps1 index d371af5d956fa..8069797a7b5c2 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Spamfilter/Invoke-AddSpamFilterTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Spamfilter/Invoke-AddSpamFilterTemplate.ps1 @@ -32,12 +32,12 @@ Function Invoke-AddSpamFilterTemplate { PartitionKey = 'SpamfilterTemplate' } $Result = "Successfully created Spam Filter Template: $($Request.Body.name) with GUID $GUID" - Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Debug' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ $Result = "Failed to create Spam Filter Template: $($ErrorMessage.NormalizedError)" - Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' -LogData $ErrorMessage + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' -LogData $ErrorMessage $StatusCode = [HttpStatusCode]::InternalServerError } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Spamfilter/Invoke-ListUserReportedMessage.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Spamfilter/Invoke-ListUserReportedMessage.ps1 new file mode 100644 index 0000000000000..8db86ac0c7c00 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Spamfilter/Invoke-ListUserReportedMessage.ps1 @@ -0,0 +1,85 @@ +function Invoke-ListUserReportedMessage { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Exchange.SpamFilter.Read + .DESCRIPTION + Retrieves the raw EML content of a user reported message by its Internet Message ID. Tries the quarantine store first (Export-QuarantineMessage), then falls back to reading the message from the recipient's or reporter's mailbox via Graph. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $TenantFilter = $Request.Query.tenantFilter + $InternetMessageId = $Request.Query.InternetMessageId + $Mailboxes = @($Request.Query.RecipientEmail, $Request.Query.ReporterEmail) | Where-Object { -not [string]::IsNullOrWhiteSpace($_) } | Select-Object -Unique + + try { + if ([string]::IsNullOrWhiteSpace($InternetMessageId)) { throw 'This submission has no Internet Message ID, so the message content cannot be retrieved.' } + + $EmlBase64 = $null + $Source = $null + $Errors = [System.Collections.Generic.List[string]]::new() + + # A reported message that was (or later got) quarantined can always be exported from quarantine + try { + $Quarantined = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-QuarantineMessage' -cmdParams @{ MessageId = $InternetMessageId } | Select-Object -First 1 + if ($Quarantined.Identity) { + $Export = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Export-QuarantineMessage' -cmdParams @{ Identity = $Quarantined.Identity } + if (-not [string]::IsNullOrEmpty($Export.Eml)) { + $EmlBase64 = $Export.Eml + $Source = 'Quarantine' + } + } + } catch { + $Errors.Add("Quarantine lookup: $(Get-NormalizedError -Message $_.Exception.Message)") + } + + # Otherwise the copy in the mailbox (Deleted Items included) is the only source left + if (-not $EmlBase64) { + $SafeMessageId = ConvertTo-CIPPODataFilterValue -Value $InternetMessageId -Type String + $Filter = [System.Uri]::EscapeDataString("internetMessageId eq '$SafeMessageId'") + foreach ($Mailbox in $Mailboxes) { + try { + $SafeMailbox = [System.Uri]::EscapeDataString($Mailbox) + $Message = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/users/$SafeMailbox/messages?`$filter=$Filter&`$select=id&`$top=5" -tenantid $TenantFilter | Select-Object -First 1 + if ($Message.id) { + $Mime = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/users/$SafeMailbox/messages/$($Message.id)/`$value" -tenantid $TenantFilter -ReturnRawResponse + if ($Mime.StatusCode -eq 200 -and -not [string]::IsNullOrEmpty($Mime.Content)) { + $EmlBase64 = [System.Convert]::ToBase64String([System.Text.Encoding]::UTF8.GetBytes([string]$Mime.Content)) + $Source = 'Mailbox' + break + } + } + } catch { + $Errors.Add("Mailbox $($Mailbox): $(Get-NormalizedError -Message $_.Exception.Message)") + } + } + } + + if (-not $EmlBase64) { + $Detail = if ($Errors.Count -gt 0) { " ($($Errors -join ' | '))" } else { '' } + throw "The reported message could not be retrieved: it is not in quarantine and could not be read from the mailbox. Mailbox retrieval requires the Mail.Read Graph permission on the CIPP-SAM application.$Detail" + } + + $EmlContent = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($EmlBase64)) + $Header = ($EmlContent -split "\r?\n\r?\n", 2)[0] + $Body = @{ + 'InternetMessageId' = $InternetMessageId + 'Message' = $EmlContent + 'EmlBase64' = $EmlBase64 + 'Header' = $Header + 'Source' = $Source + } + $StatusCode = [HttpStatusCode]::OK + } catch { + $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message + $StatusCode = [HttpStatusCode]::Forbidden + $Body = $ErrorMessage + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = $Body + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Spamfilter/Invoke-ListUserReportedMessages.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Spamfilter/Invoke-ListUserReportedMessages.ps1 new file mode 100644 index 0000000000000..448cabeaebe87 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Spamfilter/Invoke-ListUserReportedMessages.ps1 @@ -0,0 +1,64 @@ +function Invoke-ListUserReportedMessages { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Exchange.SpamFilter.Read + .DESCRIPTION + Lists user reported email threat submissions (Defender Submissions with source 'user') for a tenant. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $TenantFilter = $Request.Query.tenantFilter + + try { + if ($TenantFilter -eq 'AllTenants') { + $GraphRequest = @() + $Metadata = [PSCustomObject]@{ + QueueMessage = 'User reported messages are loaded per tenant. Select a tenant to view its reported messages.' + } + } else { + $Submissions = New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/security/threatSubmission/emailThreats' -tenantid $TenantFilter -AsApp $true + $Results = [System.Collections.Generic.List[object]]::new() + foreach ($Submission in $Submissions) { + # Admin submissions share the same Graph collection; this page only covers user reports + if ($Submission.source -ne 'user') { continue } + $Results.Add([PSCustomObject]@{ + ReportedDateTime = $Submission.createdDateTime + ReceivedDateTime = $Submission.receivedDateTime + Subject = $Submission.subject ?? $Submission.emailSubject + Sender = $Submission.sender + SenderIP = $Submission.senderIP + RecipientEmail = $Submission.recipientEmailAddress + ReportedBy = $Submission.createdBy.user.displayName + ReporterEmail = $Submission.createdBy.user.email + Category = $Submission.category + OriginalCategory = $Submission.originalCategory + Status = $Submission.status + ResultCategory = $Submission.result.category + ResultDetail = $Submission.result.detail + AdminReviewResult = $Submission.adminReview.reviewResult + InternetMessageId = $Submission.internetMessageId + Id = $Submission.id + Tenant = $TenantFilter + }) + } + $GraphRequest = $Results | Sort-Object -Property ReportedDateTime -Descending + } + $Body = [PSCustomObject]@{ + Results = @($GraphRequest) + Metadata = $Metadata + } + $StatusCode = [HttpStatusCode]::OK + } catch { + $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message + $StatusCode = [HttpStatusCode]::Forbidden + $Body = $ErrorMessage + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = $Body + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ExecHistoricalSearch.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ExecHistoricalSearch.ps1 new file mode 100644 index 0000000000000..5bf9b6c789f6f --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ExecHistoricalSearch.ps1 @@ -0,0 +1,99 @@ +function Invoke-ExecHistoricalSearch { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Exchange.Mailbox.ReadWrite + .DESCRIPTION + Starts or cancels an Exchange Online historical search. Historical searches cover up to 90 days, + deliver results as CSV (max 100,000 rows) and are limited to 250 submissions per day per tenant. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + try { + $TenantFilter = $Request.Body.tenantFilter + $Action = $Request.Body.Action ?? 'Start' + + if ($Action -eq 'Stop') { + $JobId = $Request.Body.jobId + if ([string]::IsNullOrEmpty($JobId)) { + throw 'jobId is required to cancel a historical search.' + } + $null = New-ExoRequest -TenantId $TenantFilter -Cmdlet 'Stop-HistoricalSearch' -CmdParams @{ JobId = $JobId } + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Cancelled historical search $JobId" -Sev 'Info' + $Result = "Cancelled historical search $JobId. Cancelled searches still count toward the daily quota." + } else { + $CmdParams = @{ + ReportTitle = $Request.Body.reportTitle + ReportType = $Request.Body.reportType.value ?? $Request.Body.reportType + } + if ([string]::IsNullOrEmpty($CmdParams.ReportTitle)) { + throw 'A report title is required.' + } + if ([string]::IsNullOrEmpty($CmdParams.ReportType)) { + throw 'A report type is required.' + } + + foreach ($DateField in @('startDate', 'endDate')) { + $Value = $Request.Body.$DateField + if ([string]::IsNullOrEmpty($Value)) { + throw 'A start and end date are required.' + } + $Parsed = $Value -match '^\d+$' ? [DateTimeOffset]::FromUnixTimeSeconds([int64]$Value).UtcDateTime : ([DateTime]$Value).ToUniversalTime() + $CmdParams[($DateField.Substring(0, 1).ToUpper() + $DateField.Substring(1))] = $Parsed.ToString('s') + } + + $Senders = @($Request.Body.senderAddress).value ?? @($Request.Body.senderAddress) | Where-Object { -not [string]::IsNullOrEmpty($_) } + if ($Senders) { + $CmdParams.SenderAddress = @($Senders) + } + $Recipients = @($Request.Body.recipientAddress).value ?? @($Request.Body.recipientAddress) | Where-Object { -not [string]::IsNullOrEmpty($_) } + if ($Recipients) { + $CmdParams.RecipientAddress = @($Recipients) + } + if (![string]::IsNullOrEmpty($Request.Body.messageId)) { + $CmdParams.MessageID = @($Request.Body.messageId -split '[,;]' | ForEach-Object { $_.Trim() } | Where-Object { $_ }) + } + if (!$CmdParams.SenderAddress -and !$CmdParams.RecipientAddress -and !$CmdParams.MessageID) { + throw 'At least one sender address, recipient address or message ID filter is required.' + } + + $Direction = $Request.Body.direction.value ?? $Request.Body.direction + if (![string]::IsNullOrEmpty($Direction) -and $Direction -ne 'All') { + $CmdParams.Direction = $Direction + } + $DeliveryStatus = $Request.Body.deliveryStatus.value ?? $Request.Body.deliveryStatus + if (![string]::IsNullOrEmpty($DeliveryStatus)) { + $CmdParams.DeliveryStatus = $DeliveryStatus + } + if (![string]::IsNullOrEmpty($Request.Body.originalClientIP)) { + $CmdParams.OriginalClientIP = $Request.Body.originalClientIP + } + $NotifyAddresses = @($Request.Body.notifyAddress).value ?? @($Request.Body.notifyAddress) | Where-Object { -not [string]::IsNullOrEmpty($_) } + if ($NotifyAddresses) { + $CmdParams.NotifyAddress = @($NotifyAddresses) + } + + $Job = New-ExoRequest -TenantId $TenantFilter -Cmdlet 'Start-HistoricalSearch' -CmdParams $CmdParams + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Started historical search '$($CmdParams.ReportTitle)' ($($CmdParams.ReportType))" -Sev 'Info' + $Result = "Started historical search '$($CmdParams.ReportTitle)'. Job ID: $($Job.JobId)" + } + + $StatusCode = [HttpStatusCode]::OK + $Body = @{ Results = @($Result) } + } catch { + $ErrorMessage = Get-NormalizedError -message $_.Exception.Message + Write-LogMessage -headers $Headers -API $APIName -tenant $($TenantFilter) -message "Historical search action failed. Error: $ErrorMessage" -Sev 'Error' + $StatusCode = [HttpStatusCode]::InternalServerError + $Body = @{ Results = @("Historical search action failed: $ErrorMessage") } + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = $Body + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ExecMailboxRestore.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ExecMailboxRestore.ps1 index eebb3e554d11f..52aa78859ec24 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ExecMailboxRestore.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ExecMailboxRestore.ps1 @@ -6,6 +6,8 @@ function Invoke-ExecMailboxRestore { Exchange.Mailbox.ReadWrite #> Param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers try { $Action = $Request.Query.Action ?? $Request.Body.Action $Identity = $Request.Query.Identity ?? $Request.Body.Identity @@ -106,6 +108,7 @@ function Invoke-ExecMailboxRestore { } $GraphRequest = New-ExoRequest @ExoRequest + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $SuccessMessage -Sev 'Info' $Body = @{ RestoreRequest = $GraphRequest @@ -113,11 +116,13 @@ function Invoke-ExecMailboxRestore { } $StatusCode = [HttpStatusCode]::OK } catch { - $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to $($Action ?? 'create') mailbox restore request: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -Sev 'Error' -LogData $ErrorMessage $StatusCode = [HttpStatusCode]::OK $Body = @{ RestoreRequest = $null - Results = @($ErrorMessage) + Results = @($ErrorMessage.NormalizedError) colour = 'danger' } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ListHistoricalSearches.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ListHistoricalSearches.ps1 new file mode 100644 index 0000000000000..c0b12a60a1741 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ListHistoricalSearches.ps1 @@ -0,0 +1,49 @@ +function Invoke-ListHistoricalSearches { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Exchange.Mailbox.Read + .DESCRIPTION + Lists Exchange Online historical searches (async message trace/report jobs) submitted in the last 10 days. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + try { + $TenantFilter = $Request.Query.tenantFilter + $CmdParams = @{} + if (![string]::IsNullOrEmpty($Request.Query.jobId)) { + $CmdParams.JobId = $Request.Query.jobId + } + + # FileUrl is the legacy admin.protection.outlook.com download endpoint. It is not GDAP-aware + # (401s for delegated partners by every path, including the modern EAC), so the CSV is only + # retrievable by a customer-native admin login, or delivered to a customer NotifyAddress. + $Searches = New-ExoRequest -TenantId $TenantFilter -Cmdlet 'Get-HistoricalSearch' -CmdParams $CmdParams | + Sort-Object -Property SubmitDate -Descending | + Select-Object JobId, ReportTitle, ReportType, Status, JobProgress, Rows, FileRows, ErrorDescription, FileUrl, + @{ Name = 'SubmitDate'; Expression = { $_.SubmitDate ? ([DateTime]$_.SubmitDate).ToString('u') : $null } }, + @{ Name = 'CompletionDate'; Expression = { $_.CompletionDate ? ([DateTime]$_.CompletionDate).ToString('u') : $null } }, + @{ Name = 'StartDate'; Expression = { $_.StartDate ? ([DateTime]$_.StartDate).ToString('u') : $null } }, + @{ Name = 'EndDate'; Expression = { $_.EndDate ? ([DateTime]$_.EndDate).ToString('u') : $null } }, + @{ Name = 'SenderAddress'; Expression = { @($_.SenderAddress) -join ', ' } }, + @{ Name = 'RecipientAddress'; Expression = { @($_.RecipientAddress) -join ', ' } } + + $StatusCode = [HttpStatusCode]::OK + $Body = @($Searches) + } catch { + $ErrorMessage = Get-NormalizedError -message $_.Exception.Message + Write-LogMessage -headers $Headers -API $APIName -tenant $($TenantFilter) -message "Failed to list historical searches. Error: $ErrorMessage" -Sev 'Error' + $StatusCode = [HttpStatusCode]::InternalServerError + $Body = @{ Results = @("Failed to list historical searches: $ErrorMessage") } + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = $Body + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ListMessageTrace.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ListMessageTrace.ps1 index 17976e179d6de..b8fde5f6afce9 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ListMessageTrace.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ListMessageTrace.ps1 @@ -5,82 +5,203 @@ function Invoke-ListMessageTrace { .ROLE Exchange.Mailbox.Read .DESCRIPTION - Traces email message delivery in Exchange Online, searchable by message ID, sender, recipient, and date range. + Traces email delivery in Exchange Online via the Graph message trace API + (/beta/admin/exchange/tracing/messageTraces), searchable by sender, recipient, subject, + status, IP, message ID and date range. Graph works over GDAP/app-only where the legacy + reporting endpoints do not. Requires the "Transport Data Platform" service principal + (8bd644d1-64a1-4d4b-ae52-2e0cbf64e373) in the tenant; it is provisioned on demand. Until + that SP activates (which can take hours), or where the Graph permission is not yet + consented, the request falls back to Get-MessageTraceV2 so results are returned immediately. #> [CmdletBinding()] param($Request, $TriggerMetadata) $APIName = $Request.Params.CIPPEndpoint $Headers = $Request.Headers + $TransportAppId = '8bd644d1-64a1-4d4b-ae52-2e0cbf64e373' + $GraphBase = 'https://graph.microsoft.com/beta/admin/exchange/tracing/messageTraces' + $State = @{ Fallback = $false } - try { - $TenantFilter = $Request.Body.tenantFilter + # Escape a value for an OData string literal (single quotes are doubled). + function ConvertTo-ODataLiteral { param([string]$Value) return ($Value -replace "'", "''") } - if ($Request.Body.MessageId) { - $SearchParams = @{ 'MessageId' = $Request.Body.messageId } - } else { - $SearchParams = @{} - if ($Request.Body.days) { - $Days = $Request.Body.days - $SearchParams.StartDate = (Get-Date).AddDays(-$Days).ToUniversalTime().ToString('s') - $SearchParams.EndDate = (Get-Date).ToUniversalTime().ToString('s') - } else { - if ($Request.Body.startDate) { - if ($Request.Body.startDate -match '^\d+$') { - $SearchParams.StartDate = [DateTimeOffset]::FromUnixTimeSeconds([int64]$Request.Body.startDate).UtcDateTime.ToString('s') - } else { - $SearchParams.StartDate = [DateTime]::ParseExact($Request.Body.startDate, 'yyyy-MM-ddTHH:mm:ssZ', $null).ToUniversalTime().ToString('s') + # Runs the Graph scriptblock; on a missing service principal or a consent/permission error it + # provisions the SP (best effort) and runs the Get-MessageTraceV2 scriptblock instead, so the + # first call in a tenant still returns data while Graph activates. + $RunWithFallback = { + param($GraphBlock, $V2Block) + try { + return (& $GraphBlock) + } catch { + $Message = $_.Exception.Message + $SpMissing = $Message -match $TransportAppId -or $Message -match 'service principal' + $Consent = $Message -match 'Authorization_RequestDenied' -or $Message -match 'insufficient' -or $Message -match 'consent' -or $Message -match 'Forbidden' -or $Message -match 'AADSTS' + if ($SpMissing -or $Consent) { + # Provision the SP only when it is genuinely absent. Once created it can still take + # hours to activate, during which Graph keeps reporting it missing - checking first + # avoids re-issuing (and log-spamming) a create that would fail as 'already in use'. + if ($SpMissing) { + $SpPresent = $false + try { + $SpPresent = [bool](New-GraphGetRequest -Uri "https://graph.microsoft.com/beta/servicePrincipals(appId='$TransportAppId')" -tenantid $TenantFilter -NoAuthCheck $true).id + } catch { + $SpPresent = $false } - } - if ($Request.Body.endDate) { - if ($Request.Body.endDate -match '^\d+$') { - $SearchParams.EndDate = [DateTimeOffset]::FromUnixTimeSeconds([int64]$Request.Body.endDate).UtcDateTime.ToString('s') - } else { - $SearchParams.EndDate = [DateTime]::ParseExact($Request.Body.endDate, 'yyyy-MM-ddTHH:mm:ssZ', $null).ToUniversalTime().ToString('s') + if (-not $SpPresent) { + try { + $null = New-GraphPostRequest -Uri 'https://graph.microsoft.com/beta/servicePrincipals' -tenantid $TenantFilter -type POST -body (@{ appId = $TransportAppId } | ConvertTo-Json -Compress) -NoAuthCheck $true + } catch { + # Lost a race with a concurrent provision - the V2 fallback covers this request. + } } } + $State.Fallback = $true + return (& $V2Block) } + throw + } + } - if ($Request.Body.status) { - $SearchParams.Add('Status', $Request.Body.status.value) + try { + $TenantFilter = $Request.Body.tenantFilter + $Recipient = $Request.Body.recipient.value ?? $Request.Body.recipient + + if ($Request.Body.traceDetail) { + $DetailUri = "$GraphBase/$($Request.Body.ID)/getDetailsByRecipient(recipientAddress='$(ConvertTo-ODataLiteral $Recipient)')" + $GraphDetail = { + New-GraphGetRequest -uri $DetailUri -tenantid $TenantFilter -AsApp $true | + Select-Object @{ Name = 'Date'; Expression = { $_.dateTime ? ([DateTime]$_.dateTime).ToString('u') : $null } }, + @{ Name = 'Event'; Expression = { $_.event } }, + @{ Name = 'Action'; Expression = { $_.action } }, + @{ Name = 'Detail'; Expression = { $_.description } } } - if (![string]::IsNullOrEmpty($Request.Body.fromIP)) { - $SearchParams.Add('FromIP', $Request.Body.fromIP) + $V2Detail = { + New-ExoRequest -TenantId $TenantFilter -Cmdlet 'Get-MessageTraceDetailV2' -CmdParams @{ MessageTraceId = $Request.Body.ID; RecipientAddress = $Recipient } | + Select-Object @{ Name = 'Date'; Expression = { $_.Date.ToString('u') } }, Event, Action, Detail + } + $Detail = @(& $RunWithFallback $GraphDetail $V2Detail) + $Body = @{ Results = @($Detail); Metadata = @{ TraceDetail = $true; Source = $State.Fallback ? 'Get-MessageTraceV2' : 'Graph' } } + return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK; Body = $Body }) + } + + # Parse the shared search inputs. + if ($Request.Body.days) { + # Single UtcNow capture keeps the window exactly N days, not N days plus call latency. + $End = [DateTime]::UtcNow + $Start = $End.AddDays(-[double]$Request.Body.days) + } elseif ($Request.Body.startDate -or $Request.Body.endDate) { + $Start = $Request.Body.startDate ? ($Request.Body.startDate -match '^\d+$' ? [DateTimeOffset]::FromUnixTimeSeconds([int64]$Request.Body.startDate).UtcDateTime : [DateTime]::Parse($Request.Body.startDate, [cultureinfo]::InvariantCulture, 'AdjustToUniversal')) : $null + $End = $Request.Body.endDate ? ($Request.Body.endDate -match '^\d+$' ? [DateTimeOffset]::FromUnixTimeSeconds([int64]$Request.Body.endDate).UtcDateTime : [DateTime]::Parse($Request.Body.endDate, [cultureinfo]::InvariantCulture, 'AdjustToUniversal')) : $null + } + if ($Start -and $End) { + if (($End - $Start).TotalDays -gt 10) { + throw 'Message trace queries are limited to a 10 day window. Narrow the date range, or use a historical search for longer periods.' } - if (![string]::IsNullOrEmpty($Request.Body.toIP)) { - $SearchParams.Add('ToIP', $Request.Body.toIP) + if (([DateTime]::UtcNow - $Start).TotalDays -gt 90) { + throw 'Message trace data is only available for the last 90 days.' } } - if ($Request.Body.recipient) { - $SearchParams.Add('RecipientAddress', $($Request.Body.recipient.value ?? $Request.Body.recipient)) + $MessageId = $Request.Body.messageId ?? $Request.Body.MessageId + $MessageTraceId = $Request.Body.messageTraceId + # No explicit window plus a message id: sweep backwards in 10-day pages (Graph's window + # cap) instead of relying on Graph's silent ~48h default, which misses older messages. + $Sweep = (-not $Start -and -not $End) -and (![string]::IsNullOrEmpty($MessageId) -or ![string]::IsNullOrEmpty($MessageTraceId)) + $Senders = @(@($Request.Body.sender).value ?? @($Request.Body.sender) | Where-Object { -not [string]::IsNullOrEmpty($_) }) + $Recipients = @(@($Request.Body.recipient).value ?? @($Request.Body.recipient) | Where-Object { -not [string]::IsNullOrEmpty($_) }) + $Statuses = @(@($Request.Body.status).value ?? @($Request.Body.status) | Where-Object { -not [string]::IsNullOrEmpty($_) }) + $ToIP = $Request.Body.toIP + $FromIP = $Request.Body.fromIP + $Subject = $Request.Body.subject + $SubjectType = ($Request.Body.subjectFilterType.value ?? $Request.Body.subjectFilterType ?? 'StartsWith') + + # Graph search: build the $filter clause. + $Filters = [System.Collections.Generic.List[string]]::new() + if ($Start -and $End) { + $Filters.Add("receivedDateTime ge $($Start.ToString('yyyy-MM-ddTHH:mm:ssZ')) and receivedDateTime le $($End.ToString('yyyy-MM-ddTHH:mm:ssZ'))") } - if ($Request.Body.sender) { - $SearchParams.Add('SenderAddress', $($Request.Body.sender.value ?? $Request.Body.sender)) + if (![string]::IsNullOrEmpty($MessageId)) { $Filters.Add("messageId eq '$(ConvertTo-ODataLiteral $MessageId)'") } + if (![string]::IsNullOrEmpty($MessageTraceId)) { $Filters.Add("id eq '$(ConvertTo-ODataLiteral $MessageTraceId)'") } + if ($Senders) { $Filters.Add('(' + (($Senders | ForEach-Object { "senderAddress eq '$(ConvertTo-ODataLiteral $_)'" }) -join ' or ') + ')') } + if ($Recipients) { $Filters.Add('(' + (($Recipients | ForEach-Object { "recipientAddress eq '$(ConvertTo-ODataLiteral $_)'" }) -join ' or ') + ')') } + if ($Statuses) { + # Graph status enum is camelCase (delivered, filteredAsSpam, ...); the UI sends PascalCase. + $Filters.Add('(' + (($Statuses | ForEach-Object { "status eq '$($_.Substring(0, 1).ToLower() + $_.Substring(1))'" }) -join ' or ') + ')') } + if (![string]::IsNullOrEmpty($ToIP)) { $Filters.Add("toIP eq '$(ConvertTo-ODataLiteral $ToIP)'") } + # Note: Graph cannot filter on fromIP (returned but not queryable); the V2 fallback can. + if (![string]::IsNullOrEmpty($Subject)) { + $Func = switch ($SubjectType) { 'Contains' { 'contains' } 'EndsWith' { 'endswith' } default { 'startswith' } } + $Filters.Add("$Func(subject, '$(ConvertTo-ODataLiteral $Subject)')") + } + $Uri = $GraphBase + '?$top=5000' + if ($Filters.Count -gt 0) { $Uri += "&`$filter=$([uri]::EscapeDataString($Filters -join ' and '))" } - $Trace = if ($Request.Body.traceDetail) { - $CmdParams = @{ - MessageTraceId = $Request.Body.ID - RecipientAddress = $Request.Body.recipient + $GraphSearch = { + New-GraphGetRequest -uri $Uri -tenantid $TenantFilter -AsApp $true | + Select-Object @{ Name = 'MessageTraceId'; Expression = { $_.id } }, + @{ Name = 'MessageId'; Expression = { $_.messageId } }, + @{ Name = 'Status'; Expression = { $_.status ? ($_.status.Substring(0, 1).ToUpper() + $_.status.Substring(1)) : $null } }, + @{ Name = 'Subject'; Expression = { $_.subject } }, + @{ Name = 'RecipientAddress'; Expression = { $_.recipientAddress } }, + @{ Name = 'SenderAddress'; Expression = { $_.senderAddress } }, + @{ Name = 'Received'; Expression = { $_.receivedDateTime ? ([DateTime]$_.receivedDateTime).ToString('u') : $null } }, + @{ Name = 'Size'; Expression = { $_.size } }, + @{ Name = 'FromIP'; Expression = { $_.fromIP } }, + @{ Name = 'ToIP'; Expression = { $_.toIP } } + } + $V2Search = { + $CmdParams = @{ ResultSize = 5000 } + if ($Start -and $End) { $CmdParams.StartDate = $Start.ToString('s'); $CmdParams.EndDate = $End.ToString('s') } + if (![string]::IsNullOrEmpty($MessageId)) { $CmdParams.MessageId = @($MessageId) } + if (![string]::IsNullOrEmpty($MessageTraceId)) { $CmdParams.MessageTraceId = $MessageTraceId } + if ($Senders) { $CmdParams.SenderAddress = @($Senders) } + if ($Recipients) { $CmdParams.RecipientAddress = @($Recipients) } + if ($Statuses) { $CmdParams.Status = @($Statuses) } + if (![string]::IsNullOrEmpty($ToIP)) { $CmdParams.ToIP = $ToIP } + if (![string]::IsNullOrEmpty($FromIP)) { $CmdParams.FromIP = $FromIP } + if (![string]::IsNullOrEmpty($Subject)) { $CmdParams.Subject = $Subject; $CmdParams.SubjectFilterType = $SubjectType } + New-ExoRequest -TenantId $TenantFilter -Cmdlet 'Get-MessageTraceV2' -CmdParams $CmdParams | + Select-Object MessageTraceId, MessageId, Status, Subject, RecipientAddress, SenderAddress, + @{ Name = 'Received'; Expression = { $_.Received.ToString('u') } }, Size, FromIP, ToIP + } + + if ($Sweep) { + # 9 pages of 10 days covers the 90 day lookback limit. + $Trace = @() + for ($Window = 0; $Window -lt 9; $Window++) { + $End = [DateTime]::UtcNow.AddDays(-10 * $Window) + $Start = $End.AddDays(-10) + $WindowFilters = [System.Collections.Generic.List[string]]::new($Filters) + $WindowFilters.Insert(0, "receivedDateTime ge $($Start.ToString('yyyy-MM-ddTHH:mm:ssZ')) and receivedDateTime le $($End.ToString('yyyy-MM-ddTHH:mm:ssZ'))") + $Uri = $GraphBase + '?$top=5000' + if ($WindowFilters.Count -gt 0) { $Uri += "&`$filter=$([uri]::EscapeDataString($WindowFilters -join ' and '))" } + $Trace = @(& $RunWithFallback $GraphSearch $V2Search) + if (@($Trace).Count -gt 0) { break } } - New-ExoRequest -TenantId $TenantFilter -Cmdlet 'Get-MessageTraceDetailV2' -CmdParams $CmdParams | Select-Object @{ Name = 'Date'; Expression = { $_.Date.ToString('u') } }, Event, Action, Detail } else { - Write-Information ($SearchParams | ConvertTo-Json) - - New-ExoRequest -TenantId $TenantFilter -Cmdlet 'Get-MessageTraceV2' -CmdParams $SearchParams | Select-Object MessageTraceId, Status, Subject, RecipientAddress, SenderAddress, @{ Name = 'Received'; Expression = { $_.Received.ToString('u') } }, FromIP, ToIP - Write-LogMessage -headers $Headers -API $APIName -tenant $($TenantFilter) -message 'Executed message trace' -Sev 'Info' + $Trace = @(& $RunWithFallback $GraphSearch $V2Search) + } + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message 'Executed message trace' -Sev 'Info' + $Metadata = @{ Returned = @($Trace).Count; Source = $State.Fallback ? 'Get-MessageTraceV2' : 'Graph' } + if ($State.Fallback) { + $Metadata.Note = 'Served via Get-MessageTraceV2 while the Graph message trace service principal activates for this tenant (this can take a few hours on first use).' } + $Body = @{ Results = @($Trace); Metadata = $Metadata } + $StatusCode = [HttpStatusCode]::OK } catch { - Write-LogMessage -headers $Headers -API $APIName -tenant $($TenantFilter) -message "Failed executing Message Trace. Error: $($_.Exception.Message)" -Sev 'Error' - $Trace = @{Status = "Failed to retrieve message trace $($_.Exception.Message)" } + $ErrorMessage = Get-NormalizedError -message $_.Exception.Message + Write-LogMessage -headers $Headers -API $APIName -tenant $($TenantFilter) -message "Failed executing Message Trace. Error: $ErrorMessage" -Sev 'Error' + $Body = @{ + Results = @() + Metadata = @{ Error = "Failed to retrieve message trace: $ErrorMessage" } + } $StatusCode = [HttpStatusCode]::InternalServerError } return ([HttpResponseContext]@{ - StatusCode = ($StatusCode ?? [HttpStatusCode]::OK) - Body = @($Trace) + StatusCode = $StatusCode + Body = $Body }) - } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-AddConnectionFilterTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-AddConnectionFilterTemplate.ps1 index 7b7709391e2e4..729e7e9f6da4c 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-AddConnectionFilterTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-AddConnectionFilterTemplate.ps1 @@ -35,12 +35,12 @@ function Invoke-AddConnectionFilterTemplate { PartitionKey = 'ConnectionfilterTemplate' } $Result = "Successfully created Connection Filter Template: $($Request.Body.name) with GUID $GUID" - Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Debug' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ $Result = "Failed to create Connection Filter Template: $($ErrorMessage.NormalizedError)" - Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' -LogData $ErrorMessage + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' -LogData $ErrorMessage $StatusCode = [HttpStatusCode]::InternalServerError } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-AddExConnectorTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-AddExConnectorTemplate.ps1 index 1b5b965a5f84d..67c3d5e582b5d 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-AddExConnectorTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-AddExConnectorTemplate.ps1 @@ -16,6 +16,10 @@ Function Invoke-AddExConnectorTemplate { try { $GUID = (New-Guid).GUID + # Posted from the row action; without a name the template lists blank. + if ([string]::IsNullOrWhiteSpace($Request.Body.name)) { + throw 'Connector template name is required but was not provided' + } $Select = if ($Request.Body.cippconnectortype -eq 'outbound') { @( 'name', 'AllAcceptedDomains', 'CloudServicesMailEnabled', 'Comment', 'Confirm', 'ConnectorSource', 'ConnectorType', 'Enabled', 'IsTransportRuleScoped', 'RecipientDomains', 'RouteAllMessagesViaOnPremises', 'SmartHosts', 'TestMode', 'TlsDomain', 'TlsSettings', 'UseMXRecord' @@ -40,12 +44,12 @@ Function Invoke-AddExConnectorTemplate { PartitionKey = 'ExConnectorTemplate' } $Result = "Successfully created Connector Template: $($Request.Body.name) with GUID $GUID" - Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Debug' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ $Result = "Failed to create Connector Template: $($ErrorMessage.NormalizedError)" - Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' $StatusCode = [HttpStatusCode]::InternalServerError } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-AddTransportTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-AddTransportTemplate.ps1 index bbf830c0a691f..df00724a6385d 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-AddTransportTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-AddTransportTemplate.ps1 @@ -15,6 +15,10 @@ Function Invoke-AddTransportTemplate { try { $GUID = (New-Guid).GUID + # Posted from the row action; without a name the template lists blank and deploys with no parameters. + if (-not $Request.Body.PowerShellCommand -and [string]::IsNullOrWhiteSpace($Request.Body.Name)) { + throw 'Transport rule template name is required but was not provided' + } $JSON = if ($request.body.PowerShellCommand) { Write-Host 'PowerShellCommand' $request.body.PowerShellCommand | ConvertFrom-Json @@ -33,12 +37,12 @@ Function Invoke-AddTransportTemplate { RowKey = "$GUID" PartitionKey = 'TransportTemplate' } - Write-LogMessage -Headers $Headers -API $APINAME -message "Created Transport Rule Template $($Request.body.name) with GUID $GUID" -Sev Debug + Write-LogMessage -Headers $Headers -API $APINAME -tenant 'Global' -message "Created Transport Rule Template $($Request.body.name) with GUID $GUID" -Sev 'Info' $body = [pscustomobject]@{'Results' = "Created Transport Rule Template $($Request.body.name) with GUID $GUID" } $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ - Write-LogMessage -Headers $Headers -API $APINAME -message "Failed to create Transport Rule Template: $($ErrorMessage.NormalizedError)" -Sev Error -LogData $ErrorMessage + Write-LogMessage -Headers $Headers -API $APINAME -tenant 'Global' -message "Failed to create Transport Rule Template: $($ErrorMessage.NormalizedError)" -Sev Error -LogData $ErrorMessage $body = [pscustomobject]@{'Results' = "Failed to create Transport Rule Template: $($ErrorMessage.NormalizedError)" } $StatusCode = [HttpStatusCode]::Forbidden } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-ListExConnectorTemplates.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-ListExConnectorTemplates.ps1 index c94ad02a045a7..b992745bebb5a 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-ListExConnectorTemplates.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-ListExConnectorTemplates.ps1 @@ -26,8 +26,10 @@ function Invoke-ListExConnectorTemplates { $GUID = $_.RowKey $Direction = $_.direction $data = $_.JSON | ConvertFrom-Json - $data | Add-Member -NotePropertyName 'GUID' -NotePropertyValue $GUID -Force - $data | Add-Member -NotePropertyName 'cippconnectortype' -NotePropertyValue $Direction -Force + $data | Add-Member -NotePropertyMembers ([ordered]@{ + GUID = $GUID + cippconnectortype = $Direction + }) -Force $data } | Sort-Object -Property displayName } else { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-RemoveExConnector.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-RemoveExConnector.ps1 index 61bb16ae5c3c9..3c04f8c45c4f0 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-RemoveExConnector.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Transport/Invoke-RemoveExConnector.ps1 @@ -20,7 +20,7 @@ Function Invoke-RemoveExConnector { $null = New-ExoRequest -tenantid $TenantFilter -cmdlet "Remove-$($Type)Connector" -cmdParams $params -useSystemMailbox $true $Result = "Deleted Connector: $($Guid)" - Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Deleted connector $($Guid)" -sev Debug + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Deleted connector $($Guid)" -sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-AddAppTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-AddAppTemplate.ps1 index 6dcf3031d2c26..896a34b4516f2 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-AddAppTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-AddAppTemplate.ps1 @@ -23,6 +23,17 @@ function Invoke-AddAppTemplate { $AppsList = [System.Collections.Generic.List[hashtable]]::new() foreach ($App in @($RawApps)) { $ConfigValue = if ($App.config -is [string]) { $App.config } else { $App.config | ConvertTo-Json -Depth 15 -Compress } + + # An IntuneBody with an id was read off Graph. Only Office/Edge can rebuild from one; + # CIPP cannot re-upload a customer's .intunewin, so the template could never deploy. + $AppType = [string]$App.appType + $ParsedConfig = $null + try { $ParsedConfig = $ConfigValue | ConvertFrom-Json -Depth 100 -ErrorAction Stop } catch { $ParsedConfig = $null } + if ($ParsedConfig.IntuneBody.id -and $AppType -notin @('officeApp', 'edgeApp')) { + $AppName = if ($App.appName) { [string]$App.appName } else { [string]$ParsedConfig.ApplicationName } + throw "'$AppName' is an existing Intune application with uploaded installer content. CIPP application templates are rebuilt from a package or script at deployment, so only Store, Chocolatey, Office, Edge, MSP and Custom (script) applications can be templated." + } + $AppsList.Add(@{ appType = [string]$App.appType appName = [string]$App.appName diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-AddEdgeApp.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-AddEdgeApp.ps1 new file mode 100644 index 0000000000000..da7116e13f553 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-AddEdgeApp.ps1 @@ -0,0 +1,50 @@ +function Invoke-AddEdgeApp { + <# + .FUNCTIONALITY + Entrypoint,AnyTenant + .ROLE + Endpoint.Application.ReadWrite + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + $AllowedTenants = Test-CIPPAccess -Request $Request -TenantList + $Tenants = ($Request.Body.selectedTenants | Where-Object { $AllowedTenants -contains $_.customerId -or $AllowedTenants -contains 'AllTenants' }).defaultDomainName + $Headers = $Request.Headers + $APIName = $Request.Params.CIPPEndpoint + if ('AllTenants' -in $Tenants) { $Tenants = (Get-Tenants).defaultDomainName } + $AssignTo = $Request.Body.AssignTo -eq 'customGroup' ? $Request.Body.CustomGroup : $Request.Body.AssignTo + $ExcludeGroup = $Request.Body.excludeGroup + + $Results = foreach ($Tenant in $Tenants) { + try { + $ExistingEdge = New-GraphGetRequest -Uri 'https://graph.microsoft.com/beta/deviceAppManagement/mobileApps' -tenantid $Tenant | Where-Object { $_.'@odata.type' -eq '#microsoft.graph.windowsMicrosoftEdgeApp' } + if (!$ExistingEdge) { + $ObjBody = Get-CIPPEdgeAppBody -Config $Request.Body + if (-not $ObjBody) { + throw 'No Edge configuration could be built from the supplied settings.' + } + Write-Host ($ObjBody | ConvertTo-Json -Compress) + $EdgeAppID = New-GraphPostRequest -Uri 'https://graph.microsoft.com/beta/deviceAppManagement/mobileApps' -tenantid $Tenant -Body (ConvertTo-Json -InputObject $ObjBody -Depth 10) -Type POST + } else { + "Edge deployment already exists for $($Tenant)" + continue + } + Write-LogMessage -headers $Headers -API $APIName -tenant $($Tenant) -message "Added Edge app to $($Tenant)" -Sev 'Info' + if ($AssignTo -and $AssignTo -ne 'On') { + Set-CIPPAssignedApplication -ApplicationId $EdgeAppID.id -TenantFilter $Tenant -Intent 'Required' -GroupName $AssignTo -ExcludeGroup $ExcludeGroup -APIName $APIName -Headers $Headers + Write-LogMessage -headers $Headers -API $APIName -tenant $($Tenant) -message "Assigned Edge to $AssignTo" -Sev 'Info' + } + "Successfully added Edge App for $($Tenant)" + } catch { + $ErrorMessage = Get-CippException -Exception $_ + "Failed to add Edge App for $($Tenant): $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -tenant $($Tenant) -message "Failed to add Edge App. Error: $($ErrorMessage.NormalizedError)" -Sev 'Error' -Logdata $ErrorMessage + continue + } + } + + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = @{'Results' = $Results } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-ExecDeployAppTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-ExecDeployAppTemplate.ps1 index f8d6a9a07c8f5..75aa395bc5146 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-ExecDeployAppTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-ExecDeployAppTemplate.ps1 @@ -57,15 +57,17 @@ function Invoke-ExecDeployAppTemplate { $AppType = "$($App.appType ?? $App.AppType)" $RequestBody = $Config | ConvertTo-Json -Depth 100 | ConvertFrom-Json -Depth 100 - $RequestBody | Add-Member -NotePropertyName 'selectedTenants' -NotePropertyValue $SelectedTenants -Force - $RequestBody | Add-Member -NotePropertyName 'tenantFilter' -NotePropertyValue 'allTenants' -Force - + $RequestProps = [ordered]@{ + selectedTenants = $SelectedTenants + tenantFilter = 'allTenants' + } if ($OverrideAssignTo) { - $RequestBody | Add-Member -NotePropertyName 'AssignTo' -NotePropertyValue $OverrideAssignTo -Force + $RequestProps['AssignTo'] = $OverrideAssignTo if ($OverrideAssignTo -eq 'customGroup' -and $OverrideCustomGroup) { - $RequestBody | Add-Member -NotePropertyName 'CustomGroup' -NotePropertyValue $OverrideCustomGroup -Force + $RequestProps['CustomGroup'] = $OverrideCustomGroup } } + $RequestBody | Add-Member -NotePropertyMembers $RequestProps -Force $MockRequest = [PSCustomObject]@{ Body = $RequestBody @@ -80,16 +82,28 @@ function Invoke-ExecDeployAppTemplate { 'officeApp' { Invoke-AddOfficeApp -Request $MockRequest -TriggerMetadata $null } 'win32ScriptApp' { Invoke-AddWin32ScriptApp -Request $MockRequest -TriggerMetadata $null } 'mspApp' { Invoke-AddMSPApp -Request $MockRequest -TriggerMetadata $null } + 'edgeApp' { Invoke-AddEdgeApp -Request $MockRequest -TriggerMetadata $null } default { throw "Unknown app type: $AppType" } } - if ($HandlerResult.Body.Results) { + $DeployedResult = if ($HandlerResult.Body.Results) { $HandlerResult.Body.Results } elseif ($HandlerResult.Body) { $HandlerResult.Body } else { "Queued '$($App.appName)'" } + + # Handlers signal rejection by status code, not by throwing. + $HandlerStatus = [int]$HandlerResult.StatusCode + if ($HandlerStatus -ge 200 -and $HandlerStatus -lt 300) { + Write-LogMessage -headers $Headers -API $APIName -message "Deployed app '$($App.appName)' ($AppType) from template $TemplateId" -Sev 'Info' + $DeployedResult + } else { + $FailureText = "Failed to deploy app '$($App.appName)' ($AppType) from template $($TemplateId): $($DeployedResult -join '; ')" + Write-LogMessage -headers $Headers -API $APIName -message $FailureText -Sev 'Error' + $FailureText + } } catch { $ErrorMessage = Get-CippException -Exception $_ "Failed '$($App.appName)': $($ErrorMessage.NormalizedError)" diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-ListApps.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-ListApps.ps1 index 3e0d0795b3b06..258e9f032fb02 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-ListApps.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-ListApps.ps1 @@ -74,8 +74,10 @@ function Invoke-ListApps { } } - $App | Add-Member -NotePropertyName 'AppAssignment' -NotePropertyValue ($AppAssignment -join ', ') -Force - $App | Add-Member -NotePropertyName 'AppExclude' -NotePropertyValue ($AppExclude -join ', ') -Force + $App | Add-Member -NotePropertyMembers ([ordered]@{ + AppAssignment = ($AppAssignment -join ', ') + AppExclude = ($AppExclude -join ', ') + }) -Force $App } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddAssignmentFilterTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddAssignmentFilterTemplate.ps1 index 1c1acccfdad2d..d43f3555a4e28 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddAssignmentFilterTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddAssignmentFilterTemplate.ps1 @@ -47,11 +47,11 @@ function Invoke-AddAssignmentFilterTemplate { RowKey = "$GUID" PartitionKey = 'AssignmentFilterTemplate' } - Write-LogMessage -headers $Request.Headers -API $APINAME -message "Created Assignment Filter template named $displayName with GUID $GUID" -Sev 'Debug' + Write-LogMessage -headers $Request.Headers -API $APINAME -tenant 'Global' -message "Created Assignment Filter template named $displayName with GUID $GUID" -Sev 'Info' $body = [pscustomobject]@{'Results' = 'Successfully added template' } } catch { - Write-LogMessage -headers $Request.Headers -API $APINAME -message "Assignment Filter Template Creation failed: $($_.Exception.Message)" -Sev 'Error' + Write-LogMessage -headers $Request.Headers -API $APINAME -tenant 'Global' -message "Assignment Filter Template Creation failed: $($_.Exception.Message)" -Sev 'Error' $body = [pscustomobject]@{'Results' = "Assignment Filter Template Creation failed: $($_.Exception.Message)" } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddIntuneReusableSettingTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddIntuneReusableSettingTemplate.ps1 index c5d96910299a3..c72b161450f3b 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddIntuneReusableSettingTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddIntuneReusableSettingTemplate.ps1 @@ -75,12 +75,12 @@ function Invoke-AddIntuneReusableSettingTemplate { RawJSON = "$sanitizedJson" # ensure string serialization for table storage } - Write-LogMessage -headers $Headers -API $APINAME -message "Created Intune reusable setting template named $displayName with GUID $GUID" -Sev 'Debug' + Write-LogMessage -headers $Headers -API $APINAME -tenant 'Global' -message "Created Intune reusable setting template named $displayName with GUID $GUID" -Sev 'Info' $body = [pscustomobject]@{ Results = 'Successfully added reusable setting template' } $StatusCode = [System.Net.HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ - Write-LogMessage -headers $Headers -API $APINAME -message "Reusable Settings Template creation failed: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage + Write-LogMessage -headers $Headers -API $APINAME -tenant 'Global' -message "Reusable Settings Template creation failed: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage $body = [pscustomobject]@{ Results = "Reusable Settings Template creation failed: $($ErrorMessage.NormalizedError)" } $StatusCode = [System.Net.HttpStatusCode]::InternalServerError } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddIntuneTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddIntuneTemplate.ps1 index 10380b5e2ad53..d0f3cb10012bf 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddIntuneTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddIntuneTemplate.ps1 @@ -35,7 +35,7 @@ function Invoke-AddIntuneTemplate { PartitionKey = 'IntuneTemplate' GUID = "$GUID" } - Write-LogMessage -headers $Headers -API $APIName -message "Created intune policy template named $($Request.Body.displayName) with GUID $GUID" -Sev 'Debug' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Created intune policy template named $($Request.Body.displayName) with GUID $GUID" -Sev 'Info' $Result = 'Successfully added template' $StatusCode = [HttpStatusCode]::OK @@ -73,7 +73,7 @@ function Invoke-AddIntuneTemplate { RowKey = "$GUID" PartitionKey = 'IntuneTemplate' } - Write-LogMessage -headers $Headers -API $APIName -message "Created intune policy template $($Request.Body.displayName) with GUID $GUID using an original policy from a tenant" -Sev 'Debug' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Created intune policy template $($Request.Body.displayName) with GUID $GUID using an original policy from a tenant" -Sev 'Info' $Result = 'Successfully added template' $StatusCode = [HttpStatusCode]::OK @@ -82,7 +82,7 @@ function Invoke-AddIntuneTemplate { $StatusCode = [HttpStatusCode]::InternalServerError $ErrorMessage = Get-CippException -Exception $_ $Result = "Intune Template Deployment failed: $($ErrorMessage.NormalizedMessage)" - Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' -LogData $ErrorMessage + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' -LogData $ErrorMessage } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-EditIntuneScript.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-EditIntuneScript.ps1 index 1674a0f7cd6d7..7c56fa60fdd1d 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-EditIntuneScript.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-EditIntuneScript.ps1 @@ -107,6 +107,8 @@ function Invoke-EditIntuneScript { try { $patchResult = New-GraphPOSTRequest @parms -type 'PATCH' + $Result = "Updated Intune $scriptType script $($Request.Body.ScriptId)" + Write-LogMessage -Headers $Headers -API $APIName -tenant $Request.Body.TenantFilter -message $Result -Sev 'Info' $body = [pscustomobject]@{'Results' = $patchResult } return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK @@ -114,6 +116,8 @@ function Invoke-EditIntuneScript { }) } catch { $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to update Intune $scriptType script $($Request.Body.ScriptId): $($ErrorMessage.NormalizedError)" + Write-LogMessage -Headers $Headers -API $APIName -tenant $Request.Body.TenantFilter -message $Result -Sev 'Error' -LogData $ErrorMessage return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::BadRequest Body = "Failed to update script: $($ErrorMessage.NormalizedError)" diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ExecCompareIntunePolicy.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ExecCompareIntunePolicy.ps1 index 22dd50c3f0525..b735e80f3fde0 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ExecCompareIntunePolicy.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ExecCompareIntunePolicy.ps1 @@ -56,6 +56,9 @@ function Invoke-ExecCompareIntunePolicy { [string]$TemplateGuid, [string]$TenantFilter, [string]$Label, + # The standards template the caller is looking at, used only to name a template + # that no longer exists by the label the standard still carries for it. + [string]$StandardsTemplateId, # Set when the caller only needs the template's identity and type in order to find # the tenant's own copy. Skips the reusable settings sync, which writes to the # tenant and is the other source's job to run. @@ -63,10 +66,18 @@ function Invoke-ExecCompareIntunePolicy { ) $Table = Get-CippTable -tablename 'templates' - $TemplateEntity = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'IntuneTemplate' and RowKey eq '$TemplateGuid'" + # The picker surfaces the GUID column while the engine keys on RowKey. CIPP writes both + # to the same value, but a template re-synced by an older release can carry a JSON GUID + # that differs from its RowKey - accept either rather than calling a present template missing. + $SafeGuid = ConvertTo-CIPPODataFilterValue -Value $TemplateGuid -Type String + $TemplateEntity = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'IntuneTemplate' and (RowKey eq '$SafeGuid' or GUID eq '$SafeGuid')" | Select-Object -First 1 if (-not $TemplateEntity) { - throw "$Label : Template with GUID '$TemplateGuid' not found" + # A bare id sends people searching the template table for a row that is gone. Name + # it by the label the standards template still holds, and say where to fix it. + $StandardEntry = Get-StandardEntry -StandardsTemplateId $StandardsTemplateId -TemplateGuid $TemplateGuid + $KnownAs = if ($StandardEntry.TemplateList.label) { "'$($StandardEntry.TemplateList.label)' " } else { '' } + throw "$Label : Intune template $KnownAs($TemplateGuid) no longer exists in the template library. Remove it from the standards or drift template, or select the template again." } $JSONData = $TemplateEntity.JSON | ConvertFrom-Json -Depth 100 @@ -122,30 +133,41 @@ function Invoke-ExecCompareIntunePolicy { # A standard can be configured to replace a similarly named policy on deployment rather than # create a new one. That setting lives on the standards template, keyed by the Intune # template GUID, and is stored as a string by the settings form. - function Get-StandardFuzzyDistance { + # The IntuneTemplate entry of a standards template for one Intune template GUID - the + # settings (fuzzy distance, assignment target, verifyAssignments) the standard runs with. + function Get-StandardEntry { param( [string]$StandardsTemplateId, [string]$TemplateGuid ) - if (-not $StandardsTemplateId) { return 0 } + if (-not $StandardsTemplateId -or -not $TemplateGuid) { return $null } try { $Table = Get-CippTable -tablename 'templates' - $Entity = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'StandardsTemplateV2' and RowKey eq '$StandardsTemplateId'" - if (-not $Entity) { return 0 } + $SafeId = ConvertTo-CIPPODataFilterValue -Value $StandardsTemplateId -Type String + $Entity = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'StandardsTemplateV2' and RowKey eq '$SafeId'" + if (-not $Entity) { return $null } $Standards = ($Entity.JSON | ConvertFrom-Json -Depth 100).standards.IntuneTemplate - $Match = @($Standards) | Where-Object { $_.TemplateList.value -eq $TemplateGuid } | Select-Object -First 1 - - if ([string]::IsNullOrWhiteSpace($Match.levenshteinDistance)) { return 0 } - return [int]$Match.levenshteinDistance + return @($Standards) | Where-Object { $_.TemplateList.value -eq $TemplateGuid } | Select-Object -First 1 } catch { - Write-Warning "Could not read the fuzzy match distance from standards template '$StandardsTemplateId': $($_.Exception.Message)" - return 0 + Write-Warning "Could not read standards template '$StandardsTemplateId': $($_.Exception.Message)" + return $null } } + function Get-StandardFuzzyDistance { + param( + [string]$StandardsTemplateId, + [string]$TemplateGuid + ) + + $Match = Get-StandardEntry -StandardsTemplateId $StandardsTemplateId -TemplateGuid $TemplateGuid + if ([string]::IsNullOrWhiteSpace($Match.levenshteinDistance)) { return 0 } + return [int]$Match.levenshteinDistance + } + # Resolve a source descriptor to its policy object and metadata function Resolve-PolicySource { param( @@ -161,7 +183,7 @@ function Invoke-ExecCompareIntunePolicy { # tenantFilter is optional here - supplying it resolves the template the way the # standard would for that tenant instead of comparing the stored template verbatim. - $Template = Get-ComparisonTemplate -TemplateGuid $Source.templateGuid -TenantFilter $Source.tenantFilter -Label $Label + $Template = Get-ComparisonTemplate -TemplateGuid $Source.templateGuid -TenantFilter $Source.tenantFilter -Label $Label -StandardsTemplateId $Source.standardsTemplateId $LabelSuffix = if ($Source.tenantFilter) { "Template, resolved for $($Source.tenantFilter)" } else { 'Template' } return @{ @@ -182,7 +204,7 @@ function Invoke-ExecCompareIntunePolicy { # Resolved for the tenant, because the name a policy is deployed under can depend on # tenant variables in the payload. The reusable settings sync is skipped - it writes # to the tenant, and the baseline source already runs it. - $Template = Get-ComparisonTemplate -TemplateGuid $Source.templateGuid -TenantFilter $Source.tenantFilter -SkipReusableSync -Label $Label + $Template = Get-ComparisonTemplate -TemplateGuid $Source.templateGuid -TenantFilter $Source.tenantFilter -SkipReusableSync -Label $Label -StandardsTemplateId $Source.standardsTemplateId if (-not $Template.TemplateType) { throw "$Label : Template '$($Template.DisplayName)' has no policy type and none could be inferred. Re-import the template to fix this." @@ -243,13 +265,37 @@ function Invoke-ExecCompareIntunePolicy { $PolicyObj = $Policy.cippconfiguration | ConvertFrom-Json -Depth 100 + # The settings diff ignores assignments. When the standard verifies them, run the + # same comparison the standard runs, so this dialog cannot say "matches" while the + # drift report for the same policy says the assignments differ. + $AssignmentComparison = $null + $StandardEntry = Get-StandardEntry -StandardsTemplateId $Source.standardsTemplateId -TemplateGuid $Source.templateGuid + if ($StandardEntry.verifyAssignments -eq $true) { + try { + $ExistingAssignments = Get-CIPPIntunePolicyAssignments -PolicyId $Policy.id -TemplateType $Template.TemplateType -TenantFilter $Source.tenantFilter -ExistingPolicy $Policy + $AssignmentDetail = Compare-CIPPIntuneAssignments -ExistingAssignments $ExistingAssignments -ExpectedAssignTo $StandardEntry.AssignTo -ExpectedCustomGroup $StandardEntry.customGroup -ExpectedExcludeGroup $StandardEntry.excludeGroup -ExpectedAssignmentFilter $StandardEntry.assignmentFilter -ExpectedAssignmentFilterType ($StandardEntry.assignmentFilterType ?? 'include') -PolicyType $Template.TemplateType -TenantFilter $Source.tenantFilter + $AssignmentComparison = @{ + matched = if ($AssignmentDetail.Unknown) { $null } else { [bool]$AssignmentDetail.Matched } + unknown = [bool]$AssignmentDetail.Unknown + reasons = @($AssignmentDetail.Reasons) + } + } catch { + $AssignmentComparison = @{ + matched = $null + unknown = $true + reasons = @("Assignments could not be read: $($_.Exception.Message)") + } + } + } + return @{ - Object = $PolicyObj - TemplateType = $Template.TemplateType - Label = "$MatchedName ($($Source.tenantFilter))" - RawData = $PolicyObj - MatchType = $MatchType - MatchedName = $MatchedName + Object = $PolicyObj + TemplateType = $Template.TemplateType + Label = "$MatchedName ($($Source.tenantFilter))" + RawData = $PolicyObj + MatchType = $MatchType + MatchedName = $MatchedName + AssignmentComparison = $AssignmentComparison } } elseif ($Source.type -eq 'tenantPolicy') { @@ -389,6 +435,9 @@ function Invoke-ExecCompareIntunePolicy { # the result should be read - the caller says so rather than implying a name match. matchType = $ResolvedB.MatchType ?? $ResolvedA.MatchType matchedName = $ResolvedB.MatchedName ?? $ResolvedA.MatchedName + # Present only when the standard verifies assignments; null otherwise so the dialog + # says nothing about a dimension that was not compared. + assignmentComparison = $ResolvedB.AssignmentComparison ?? $ResolvedA.AssignmentComparison } Write-LogMessage -headers $Headers -API $APIName -message "Compared Intune policies: $($ResolvedA.Label) vs $($ResolvedB.Label) - $($ComparisonResults.Count) differences found" -Sev 'Info' diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListAppProtectionPolicies.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListAppProtectionPolicies.ps1 index 5e8cfd8286caa..b19899d6291f4 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListAppProtectionPolicies.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListAppProtectionPolicies.ps1 @@ -126,11 +126,13 @@ function Invoke-ListAppProtectionPolicies { } } - $Policy | Add-Member -NotePropertyName 'PolicyTypeName' -NotePropertyValue $policyType -Force - # $Policy | Add-Member -NotePropertyName 'URLName' -NotePropertyValue 'managedAppPolicies' -Force - $Policy | Add-Member -NotePropertyName 'PolicySource' -NotePropertyValue 'AppProtection' -Force - $Policy | Add-Member -NotePropertyName 'PolicyAssignment' -NotePropertyValue ($PolicyAssignment -join ', ') -Force - $Policy | Add-Member -NotePropertyName 'PolicyExclude' -NotePropertyValue ($PolicyExclude -join ', ') -Force + # URLName is intentionally not set here (already carried from the per-type bulk fetch). + $Policy | Add-Member -NotePropertyMembers ([ordered]@{ + PolicyTypeName = $policyType + PolicySource = 'AppProtection' + PolicyAssignment = ($PolicyAssignment -join ', ') + PolicyExclude = ($PolicyExclude -join ', ') + }) -Force $GraphRequest.Add($Policy) } } @@ -167,16 +169,18 @@ function Invoke-ListAppProtectionPolicies { } } - $Config | Add-Member -NotePropertyName 'PolicyTypeName' -NotePropertyValue $policyType -Force - $Config | Add-Member -NotePropertyName 'URLName' -NotePropertyValue 'mobileAppConfigurations' -Force - $Config | Add-Member -NotePropertyName 'PolicySource' -NotePropertyValue 'AppConfiguration' -Force - $Config | Add-Member -NotePropertyName 'PolicyAssignment' -NotePropertyValue ($PolicyAssignment -join ', ') -Force - $Config | Add-Member -NotePropertyName 'PolicyExclude' -NotePropertyValue ($PolicyExclude -join ', ') -Force - + $ConfigProps = [ordered]@{ + PolicyTypeName = $policyType + URLName = 'mobileAppConfigurations' + PolicySource = 'AppConfiguration' + PolicyAssignment = ($PolicyAssignment -join ', ') + PolicyExclude = ($PolicyExclude -join ', ') + } # Ensure isAssigned property exists for consistency if (-not $Config.PSObject.Properties['isAssigned']) { - $Config | Add-Member -NotePropertyName 'isAssigned' -NotePropertyValue $false -Force + $ConfigProps['isAssigned'] = $false } + $Config | Add-Member -NotePropertyMembers $ConfigProps -Force $GraphRequest.Add($Config) } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListAppleEnrollmentProfiles.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListAppleEnrollmentProfiles.ps1 index 66f111b067af1..e910537a93287 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListAppleEnrollmentProfiles.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListAppleEnrollmentProfiles.ps1 @@ -18,16 +18,18 @@ function Invoke-ListAppleEnrollmentProfiles { $DepOnboardingSettings = @(New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/deviceManagement/depOnboardingSettings' -tenantid $TenantFilter) $Tokens = foreach ($DepSetting in $DepOnboardingSettings) { $Token = $DepSetting | Select-Object * - $Token | Add-Member -NotePropertyName 'daysUntilExpiration' -NotePropertyValue $( - if ($Token.tokenExpirationDateTime) { - [math]::Floor(([datetime]$Token.tokenExpirationDateTime - [datetime]::UtcNow).TotalDays) - } else { - $null - } - ) -Force - $Token | Add-Member -NotePropertyName 'isExpired' -NotePropertyValue $( - if ($Token.tokenExpirationDateTime) { ([datetime]$Token.tokenExpirationDateTime) -lt [datetime]::UtcNow } else { $false } - ) -Force + $Token | Add-Member -NotePropertyMembers ([ordered]@{ + daysUntilExpiration = $( + if ($Token.tokenExpirationDateTime) { + [math]::Floor(([datetime]$Token.tokenExpirationDateTime - [datetime]::UtcNow).TotalDays) + } else { + $null + } + ) + isExpired = $( + if ($Token.tokenExpirationDateTime) { ([datetime]$Token.tokenExpirationDateTime) -lt [datetime]::UtcNow } else { $false } + ) + }) -Force $Token } @@ -47,13 +49,15 @@ function Invoke-ListAppleEnrollmentProfiles { } $ProfileObject = $EnrollmentProfile | Select-Object * - $ProfileObject | Add-Member -NotePropertyName 'platform' -NotePropertyValue $Platform -Force - $ProfileObject | Add-Member -NotePropertyName 'profileType' -NotePropertyValue 'apple' -Force - $ProfileObject | Add-Member -NotePropertyName 'tokenId' -NotePropertyValue $DepSetting.id -Force - $ProfileObject | Add-Member -NotePropertyName 'tokenName' -NotePropertyValue $DepSetting.tokenName -Force - $ProfileObject | Add-Member -NotePropertyName 'appleIdentifier' -NotePropertyValue $DepSetting.appleIdentifier -Force - $ProfileObject | Add-Member -NotePropertyName 'tokenExpirationDateTime' -NotePropertyValue $DepSetting.tokenExpirationDateTime -Force - $ProfileObject | Add-Member -NotePropertyName 'tokenType' -NotePropertyValue $DepSetting.tokenType -Force + $ProfileObject | Add-Member -NotePropertyMembers ([ordered]@{ + platform = $Platform + profileType = 'apple' + tokenId = $DepSetting.id + tokenName = $DepSetting.tokenName + appleIdentifier = $DepSetting.appleIdentifier + tokenExpirationDateTime = $DepSetting.tokenExpirationDateTime + tokenType = $DepSetting.tokenType + }) -Force $ProfileObject } } catch { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListCompliancePolicies.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListCompliancePolicies.ps1 index 528cddb548eae..bb69466248b14 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListCompliancePolicies.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListCompliancePolicies.ps1 @@ -91,9 +91,11 @@ function Invoke-ListCompliancePolicies { } } - $Policy | Add-Member -NotePropertyName 'PolicyTypeName' -NotePropertyValue $policyType -Force - $Policy | Add-Member -NotePropertyName 'PolicyAssignment' -NotePropertyValue ($PolicyAssignment -join ', ') -Force - $Policy | Add-Member -NotePropertyName 'PolicyExclude' -NotePropertyValue ($PolicyExclude -join ', ') -Force + $Policy | Add-Member -NotePropertyMembers ([ordered]@{ + PolicyTypeName = $policyType + PolicyAssignment = ($PolicyAssignment -join ', ') + PolicyExclude = ($PolicyExclude -join ', ') + }) -Force $GraphRequest.Add($Policy) } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListIntuneScript.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListIntuneScript.ps1 index 7c98ea1e65879..3933ac1d599f4 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListIntuneScript.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListIntuneScript.ps1 @@ -114,8 +114,10 @@ function Invoke-ListIntuneScript { } } - $script | Add-Member -NotePropertyName 'ScriptAssignment' -NotePropertyValue ($ScriptAssignment -join ', ') -Force - $script | Add-Member -NotePropertyName 'ScriptExclude' -NotePropertyValue ($ScriptExclude -join ', ') -Force + $script | Add-Member -NotePropertyMembers ([ordered]@{ + ScriptAssignment = ($ScriptAssignment -join ', ') + ScriptExclude = ($ScriptExclude -join ', ') + }) -Force } $scripts | Add-Member -MemberType NoteProperty -Name scriptType -Value $scriptId diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListIntuneTemplates.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListIntuneTemplates.ps1 index f7cc6f7a511dc..d6d1ace41a9b0 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListIntuneTemplates.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListIntuneTemplates.ps1 @@ -38,14 +38,16 @@ function Invoke-ListIntuneTemplates { $JSONData = $Row.JSON | ConvertFrom-Json -Depth 100 -ErrorAction SilentlyContinue $data = $JSONData.RAWJson | ConvertFrom-Json -Depth 100 -ErrorAction SilentlyContinue if ($null -eq $data) { throw 'RAWJson is empty or not valid JSON' } - $data | Add-Member -NotePropertyName 'displayName' -NotePropertyValue $JSONData.Displayname -Force - $data | Add-Member -NotePropertyName 'description' -NotePropertyValue $JSONData.Description -Force - $data | Add-Member -NotePropertyName 'Type' -NotePropertyValue $JSONData.Type -Force - $data | Add-Member -NotePropertyName 'GUID' -NotePropertyValue $Row.RowKey -Force - $data | Add-Member -NotePropertyName 'package' -NotePropertyValue $Row.Package -Force - $data | Add-Member -NotePropertyName 'isSynced' -NotePropertyValue (![string]::IsNullOrEmpty($Row.SHA)) -Force - $data | Add-Member -NotePropertyName 'source' -NotePropertyValue $Row.Source -Force - $data | Add-Member -NotePropertyName 'reusableSettings' -NotePropertyValue $JSONData.ReusableSettings -Force + $data | Add-Member -NotePropertyMembers ([ordered]@{ + displayName = $JSONData.Displayname + description = $JSONData.Description + Type = $JSONData.Type + GUID = $Row.RowKey + package = $Row.Package + isSynced = (![string]::IsNullOrEmpty($Row.SHA)) + source = $Row.Source + reusableSettings = $JSONData.ReusableSettings + }) -Force $data } catch { # A row that fails to parse used to be dropped from this list entirely, so a corrupt @@ -137,14 +139,16 @@ function Invoke-ListIntuneTemplates { try { $JSONData = $_.JSON | ConvertFrom-Json -Depth 100 -ErrorAction SilentlyContinue $data = $JSONData.RAWJson | ConvertFrom-Json -Depth 100 -ErrorAction SilentlyContinue - $data | Add-Member -NotePropertyName 'displayName' -NotePropertyValue $JSONData.Displayname -Force - $data | Add-Member -NotePropertyName 'description' -NotePropertyValue $JSONData.Description -Force - $data | Add-Member -NotePropertyName 'Type' -NotePropertyValue $JSONData.Type -Force - $data | Add-Member -NotePropertyName 'GUID' -NotePropertyValue $_.RowKey -Force - $data | Add-Member -NotePropertyName 'package' -NotePropertyValue $_.Package -Force - $data | Add-Member -NotePropertyName 'source' -NotePropertyValue $_.Source -Force - $data | Add-Member -NotePropertyName 'isSynced' -NotePropertyValue (![string]::IsNullOrEmpty($_.SHA)) -Force - $data | Add-Member -NotePropertyName 'reusableSettings' -NotePropertyValue $JSONData.ReusableSettings -Force + $data | Add-Member -NotePropertyMembers ([ordered]@{ + displayName = $JSONData.Displayname + description = $JSONData.Description + Type = $JSONData.Type + GUID = $_.RowKey + package = $_.Package + source = $_.Source + isSynced = (![string]::IsNullOrEmpty($_.SHA)) + reusableSettings = $JSONData.ReusableSettings + }) -Force $data } catch { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Groups/Invoke-AddGroupTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Groups/Invoke-AddGroupTemplate.ps1 index d5c985745043f..5654cfaa16cb5 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Groups/Invoke-AddGroupTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Groups/Invoke-AddGroupTemplate.ps1 @@ -64,11 +64,11 @@ function Invoke-AddGroupTemplate { RowKey = "$GUID" PartitionKey = 'GroupTemplate' } - Write-LogMessage -headers $Request.Headers -API $APINAME -message "Created Group template named $displayName with GUID $GUID" -Sev 'Debug' + Write-LogMessage -headers $Request.Headers -API $APINAME -tenant 'Global' -message "Created Group template named $displayName with GUID $GUID" -Sev 'Info' $body = [pscustomobject]@{'Results' = 'Successfully added template' } } catch { - Write-LogMessage -headers $Request.Headers -API $APINAME -message "Group Template Creation failed: $($_.Exception.Message)" -Sev 'Error' + Write-LogMessage -headers $Request.Headers -API $APINAME -tenant 'Global' -message "Group Template Creation failed: $($_.Exception.Message)" -Sev 'Error' $body = [pscustomobject]@{'Results' = "Group Template Creation failed: $($_.Exception.Message)" } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Groups/Invoke-EditGroup.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Groups/Invoke-EditGroup.ps1 index e7042c65e82b2..eaf9675db2db6 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Groups/Invoke-EditGroup.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Groups/Invoke-EditGroup.ps1 @@ -509,10 +509,12 @@ function Invoke-EditGroup { $null = New-GraphPOSTRequest -uri "https://graph.microsoft.com/beta/groups/$($GroupID)" -type PATCH -tenantid $TenantId -body (@{'visibility' = $VisibilityValue } | ConvertTo-Json) $Results.Add("Set group visibility to $VisibilityValue for $($GroupName).") + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantId -message "Set group visibility to $VisibilityValue for $($GroupName)." -Sev 'Info' } catch { $ErrorMessage = Get-CippException -Exception $_ Write-Warning "Error in visibility: $($ErrorMessage.NormalizedError) - $($_.InvocationInfo.ScriptLineNumber)" $Results.Add("Failed to set group visibility for $($GroupName): $($ErrorMessage.NormalizedError)") + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantId -message "Failed to set group visibility for $($GroupName). Error:$($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Groups/Invoke-ListGroups.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Groups/Invoke-ListGroups.ps1 index 2a9c3d5f99e4e..e396293a497d1 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Groups/Invoke-ListGroups.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Groups/Invoke-ListGroups.ps1 @@ -5,7 +5,7 @@ function Invoke-ListGroups { .ROLE Identity.Group.Read .DESCRIPTION - Lists Entra ID groups for a tenant, including group members and owners. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants. + Lists Entra ID groups for a tenant, including group members and owners. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants. When manualPagination is also set on a cached read, one page is returned per request as { Results, Metadata } with a continuation token in Metadata.nextLink. #> [CmdletBinding()] param($Request, $TriggerMetadata) @@ -24,6 +24,8 @@ function Invoke-ListGroups { $ExpandOwners = $Request.Query.expandOwners -eq $true # Serve from the reporting database cache instead of live Graph. Much faster, especially for AllTenants. $UseReportDB = $Request.Query.UseReportDB -eq $true + # Return one page per request as { Results, Metadata } with a continuation token in Metadata.nextLink; cached reads only. + $ManualPagination = $Request.Query.manualPagination -and [System.Convert]::ToBoolean($Request.Query.manualPagination) # members/owners read groups//..., so without a groupID the URL collapses to # groups//members and the failure surfaces as an opaque parameter binding error. @@ -37,6 +39,25 @@ function Invoke-ListGroups { # Cache path: list view only — skip when fetching a specific group's details if ((-not $GroupID) -and (-not $Members) -and (-not $Owners) -and ($TenantFilter -eq 'AllTenants' -or $UseReportDB)) { try { + if ($ManualPagination) { + # Rows per page, clamped between 100 and 5000. Defaults to 750: group rows + # carry full member arrays and run far heavier than other report types. + $PageSize = 750 + if ($Request.Query.PageSize -as [int]) { + $PageSize = [Math]::Min([Math]::Max([int]$Request.Query.PageSize, 100), 5000) + } + # Continuation token from the previous page's Metadata.nextLink; opaque to callers. + # Stream the cached blobs as raw JSON so member arrays are never re-parsed here. + $Page = Get-CIPPGroupsReport -TenantFilter $TenantFilter -PageSize $PageSize -ContinuationToken $Request.Query.nextLink -AsRawJson -ErrorAction Stop + $Metadata = @{} + if ($Page.NextToken) { $Metadata.nextLink = $Page.NextToken } + $MetadataJson = ConvertTo-Json -InputObject $Metadata -Depth 5 -Compress + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + ContentType = 'application/json' + Body = '{"Results":' + $Page.CippPagedJson + ',"Metadata":' + $MetadataJson + '}' + }) + } $GraphRequest = Get-CIPPGroupsReport -TenantFilter $TenantFilter -ErrorAction Stop $StatusCode = [HttpStatusCode]::OK } catch { @@ -148,26 +169,41 @@ function Invoke-ListGroups { # add a bulk sub-request above, so this branch always means "every group in the # tenant". The URL previously interpolated $GroupID and $Members, both necessarily # empty here, which produced 'groups//' and only worked because Graph tolerated it. - $GraphRequest = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/groups?`$top=999&select=$SelectString" -tenantid $TenantFilter | Select-Object *, @{ Name = 'primDomain'; Expression = { $_.mail -split '@' | Select-Object -Last 1 } }, - @{Name = 'membersCsv'; Expression = { $_.members.userPrincipalName -join ',' } }, - @{Name = 'ownersCsv'; Expression = { $_.owners.userPrincipalName -join ',' } }, - @{Name = 'teamsEnabled'; Expression = { if ($_.resourceProvisioningOptions -like '*Team*') { $true }else { $false } } }, - @{Name = 'groupType'; Expression = { + # membersCsv/ownersCsv are computed from the expanded navigation property, so emit + # them only when that expand was requested - otherwise they ride along always-empty + # and surface as permanently blank columns in the UI and exports. + $GroupProperties = [System.Collections.Generic.List[object]]::new() + $GroupProperties.Add('*') + $GroupProperties.Add(@{ Name = 'primDomain'; Expression = { $_.mail -split '@' | Select-Object -Last 1 } }) + if ($ExpandMembers) { + $GroupProperties.Add(@{Name = 'membersCsv'; Expression = { $_.members.userPrincipalName -join ',' } }) + } + if ($ExpandOwners -and -not $ExpandMembers) { + # hasOwner only - ownersCsv is deliberately not emitted here. Populating it would + # make subTableShowsCachedColumn() (frontend) swap the interactive "View owners" + # button (Add/Remove Owner actions) for a read-only CSV column tenant-wide, since + # that check only looks at whether the field is populated, not which caller asked + # for it. + $GroupProperties.Add(@{Name = 'hasOwner'; Expression = { $_.owners.Count -gt 0 } }) + } + $GroupProperties.Add(@{Name = 'teamsEnabled'; Expression = { if ($_.resourceProvisioningOptions -like '*Team*') { $true }else { $false } } }) + $GroupProperties.Add(@{Name = 'groupType'; Expression = { if ($_.groupTypes -contains 'Unified') { 'Microsoft 365' } elseif ($_.mailEnabled -and $_.securityEnabled) { 'Mail-Enabled Security' } elseif (-not $_.mailEnabled -and $_.securityEnabled) { 'Security' } elseif (([string]::isNullOrEmpty($_.groupTypes)) -and ($_.mailEnabled) -and (-not $_.securityEnabled)) { 'Distribution List' } } - }, - @{Name = 'calculatedGroupType'; Expression = { + }) + $GroupProperties.Add(@{Name = 'calculatedGroupType'; Expression = { if ($_.groupTypes -contains 'Unified') { 'm365' } elseif ($_.mailEnabled -and $_.securityEnabled) { 'security' } elseif (-not $_.mailEnabled -and $_.securityEnabled) { 'generic' } elseif (([string]::isNullOrEmpty($_.groupTypes)) -and ($_.mailEnabled) -and (-not $_.securityEnabled)) { 'distributionList' } } - }, - @{Name = 'dynamicGroupBool'; Expression = { if ($_.groupTypes -contains 'DynamicMembership') { $true } else { $false } } }, - @{Name = 'SID'; Expression = { Convert-AzureAdObjectIdToSid -ObjectID $_.id } } + }) + $GroupProperties.Add(@{Name = 'dynamicGroupBool'; Expression = { if ($_.groupTypes -contains 'DynamicMembership') { $true } else { $false } } }) + $GroupProperties.Add(@{Name = 'SID'; Expression = { Convert-AzureAdObjectIdToSid -ObjectID $_.id } }) + $GraphRequest = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/groups?`$top=999&select=$SelectString" -tenantid $TenantFilter | Select-Object -Property $GroupProperties $GraphRequest = @($GraphRequest | Sort-Object displayName) } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-AddPIMRoleSettingsTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-AddPIMRoleSettingsTemplate.ps1 new file mode 100644 index 0000000000000..0d44e886b48b3 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-AddPIMRoleSettingsTemplate.ps1 @@ -0,0 +1,140 @@ +function Invoke-AddPIMRoleSettingsTemplate { + <# + .FUNCTIONALITY + Entrypoint,AnyTenant + .ROLE + Identity.Role.ReadWrite + .SYNOPSIS + Create or update a PIM role settings template. + .DESCRIPTION + Saves a Privileged Identity Management role settings template. The settings are validated against CIPP's secure floor (activation must expire within 24 hours and require MFA or an authentication context plus a justification; eligibilities and active assignments must expire within a year; active assignments must require a justification). A template below the floor is rejected with the list of problems rather than silently adjusted. Pass GUID to update an existing template. Pass captureRoleId with a tenantFilter to build the settings from that role's current PIM policy in the tenant instead of supplying them: values below the secure floor are raised to the closest value the floor allows and every raise is reported in the results. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + try { + # Existing template GUID when editing. + $GUID = $Request.Body.GUID + $TemplateName = "$($Request.Body.templateName)".Trim() + $Description = "$($Request.Body.description)".Trim() + # PrivilegedRoles | AllRoles | Custom + $RoleScope = $Request.Body.roleScope.value ?? $Request.Body.roleScope + # Roles (label/value pairs of role template ids) when roleScope is Custom. + $Roles = @($Request.Body.roles | ForEach-Object { + if ($null -eq $_) { return } + $Value = $_.value ?? $_ + $Label = $_.label ?? $_.value ?? $_ + if ([string]::IsNullOrWhiteSpace("$Value")) { return } + @{ label = "$Label"; value = "$Value" } + }) + + if ([string]::IsNullOrWhiteSpace($TemplateName)) { throw 'templateName is required' } + + # Capture mode: build the settings from a role's current PIM policy in a tenant. + $CaptureRoleId = $Request.Body.captureRoleId.value ?? $Request.Body.captureRoleId + $Adjustments = @() + if (-not [string]::IsNullOrWhiteSpace("$CaptureRoleId")) { + $CaptureTenant = $Request.Body.tenantFilter.value ?? $Request.Body.tenantFilter + if ([string]::IsNullOrWhiteSpace("$CaptureTenant") -or "$CaptureTenant" -eq 'AllTenants') { throw 'A single tenantFilter is required when capturing settings from a role.' } + $Policy = @(Get-CIPPPIMRolePolicies -TenantFilter $CaptureTenant) | Where-Object { $_.RoleDefinitionId -eq $CaptureRoleId } | Select-Object -First 1 + if (-not $Policy) { throw "No PIM role management policy was found for role $CaptureRoleId in $CaptureTenant. Privileged Identity Management may not be onboarded there yet." } + $Captured = ConvertFrom-CIPPPIMPolicyRules -Rules $Policy.Rules + # A tenant's live policy may sit below the floor (Entra's defaults do); a template must + # never store that, so offending values are raised and each raise is reported. + $Repair = Repair-CIPPPIMRoleSettingsFloor -Settings $Captured + $SettingsInput = $Repair.Settings + $Adjustments = @($Repair.Adjustments) + + $CaptureRoleName = "$($Request.Body.captureRoleName)".Trim() + if ([string]::IsNullOrWhiteSpace($CaptureRoleName)) { $CaptureRoleName = "$CaptureRoleId" } + if ([string]::IsNullOrWhiteSpace($RoleScope)) { + $RoleScope = 'Custom' + $Roles = @(@{ label = $CaptureRoleName; value = "$CaptureRoleId" }) + } + if ([string]::IsNullOrWhiteSpace($Description)) { $Description = "Captured from the $CaptureRoleName role in $CaptureTenant." } + } else { + $SettingsInput = $Request.Body.settings + } + + if ([string]::IsNullOrWhiteSpace($RoleScope)) { $RoleScope = 'PrivilegedRoles' } + if ($RoleScope -notin @('PrivilegedRoles', 'AllRoles', 'Custom')) { throw "roleScope '$RoleScope' is not valid. Use PrivilegedRoles, AllRoles or Custom." } + if ($RoleScope -eq 'Custom' -and $Roles.Count -eq 0) { throw 'Select at least one role when roleScope is Custom.' } + + # Role activation, eligibility, assignment, approval and notification settings. + $Settings = ConvertTo-CIPPPIMRoleSettings -InputObject $SettingsInput + $Floor = Test-CIPPPIMRoleSettingsFloor -Settings $Settings + if (-not $Floor.Valid) { + $Message = "PIM role settings template '$TemplateName' was not saved because it is below the secure floor: $($Floor.Errors -join ' ')" + Write-LogMessage -headers $Headers -API $APIName -message $Message -Sev 'Error' + return [HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @{ Results = @($Message) + @($Floor.Errors | ForEach-Object { @{ resultText = $_; state = 'error' } }) } + } + } + + $UserDetails = try { + ([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($Headers.'x-ms-client-principal')) | ConvertFrom-Json).userDetails + } catch { 'Unknown' } + $Now = (Get-Date).ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:ssZ') + + $Table = Get-CippTable -tablename 'templates' + $Existing = $null + if (-not [string]::IsNullOrWhiteSpace($GUID)) { + $SafeGUID = ConvertTo-CIPPODataFilterValue -Value $GUID -Type String + $Existing = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'PIMRoleSettingsTemplate' and RowKey eq '$SafeGUID'" + if (-not $Existing) { throw "PIM role settings template $GUID was not found" } + } else { + $GUID = (New-Guid).Guid + } + + $ExistingData = if ($Existing) { $Existing.JSON | ConvertFrom-Json -Depth 100 } else { $null } + $TemplateObject = [ordered]@{ + templateName = $TemplateName + description = $Description + roleScope = $RoleScope + roles = @($Roles) + settings = $Settings + createdBy = $ExistingData.createdBy ?? $UserDetails + createdDate = $ExistingData.createdDate ?? $Now + updatedBy = $UserDetails + updatedDate = $Now + GUID = $GUID + } + + $JSON = ConvertTo-Json -InputObject $TemplateObject -Depth 20 -Compress + $Table.Force = $true + Add-CIPPAzDataTableEntity @Table -Entity @{ + JSON = "$JSON" + RowKey = "$GUID" + PartitionKey = 'PIMRoleSettingsTemplate' + GUID = "$GUID" + } + + $Verb = if ($Existing) { 'Updated' } else { 'Created' } + $Result = "$Verb PIM role settings template '$TemplateName' with GUID $GUID" + Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Info' + foreach ($Adjustment in $Adjustments) { + # Captured value was below the secure floor; the raise must be visible in the logbook. + Write-LogMessage -headers $Headers -API $APIName -message "PIM role settings template '$TemplateName': raised to the secure floor - $Adjustment" -Sev 'Warning' + } + foreach ($Warning in $Floor.Warnings) { + # Above the recommended value but inside the hard cap: allowed, and visible in the logbook. + Write-LogMessage -headers $Headers -API $APIName -message "PIM role settings template '$TemplateName': $Warning" -Sev 'Warning' + } + $Results = @($Result) + @($Adjustments | ForEach-Object { @{ resultText = "Raised to the secure floor: $_"; state = 'warning' } }) + @($Floor.Warnings | ForEach-Object { @{ resultText = $_; state = 'warning' } }) + $StatusCode = [HttpStatusCode]::OK + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Results = @("Failed to save PIM role settings template: $($ErrorMessage.NormalizedError)") + Write-LogMessage -headers $Headers -API $APIName -message $Results[0] -Sev 'Error' -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::BadRequest + } + + return [HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{ Results = @($Results) } + } +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ExecPIMRoleAssignment.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ExecPIMRoleAssignment.ps1 new file mode 100644 index 0000000000000..a8caa6f58322e --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ExecPIMRoleAssignment.ps1 @@ -0,0 +1,112 @@ +function Invoke-ExecPIMRoleAssignment { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Identity.Role.ReadWrite + .SYNOPSIS + Change a directory role assignment through PIM in the secure direction only. + .DESCRIPTION + Converts a permanent assignment to eligible, grants a time-bound active assignment, extends or renews a time-bound assignment or eligibility, or removes an assignment. Every request must carry an expiration (a duration or an end date); permanent / no-expiration assignments are refused, as are changes to group-inherited rows, the CIPP-SAM application and the last active Global Administrator. Requires Entra ID P2. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $TenantFilter = $Request.Body.tenantFilter.value ?? $Request.Body.tenantFilter + # ConvertToEligible | GrantActive | Extend | Renew | Remove + $Action = $Request.Body.Action.value ?? $Request.Body.Action + # Object id of the user, group or service principal. + $PrincipalId = $Request.Body.PrincipalId.value ?? $Request.Body.PrincipalId + # Role template id (roleDefinitionId as PIM reports it). + $RoleDefinitionId = $Request.Body.RoleDefinitionId.value ?? $Request.Body.RoleDefinitionId + # '/' for the whole directory or '/administrativeUnits/{id}'. + $DirectoryScopeId = $Request.Body.DirectoryScopeId.value ?? $Request.Body.DirectoryScopeId + # The row's current assignment type: Permanent | Active | ActivatedFromEligible | Eligible + $AssignmentType = $Request.Body.AssignmentType.value ?? $Request.Body.AssignmentType + # ISO 8601 lifetime such as PT4H or P1Y. Use either Duration or EndDateTime, not both. + $Duration = $Request.Body.Duration.value ?? $Request.Body.Duration + # The dialog's "Custom end date" option carries no lifetime of its own; EndDateTime does. + if ("$Duration" -eq 'custom') { $Duration = $null } + # Absolute end (unix seconds or ISO 8601). Use either Duration or EndDateTime, not both. + $EndDateTimeRaw = $Request.Body.EndDateTime.value ?? $Request.Body.EndDateTime + # IANA time zone of the browser (e.g. Australia/Perth); only used to word the end time in the result. + $TimeZone = [string]($Request.Body.TimeZone.value ?? $Request.Body.TimeZone) + # Reason recorded on the PIM request and in the CIPP logbook. + $Justification = $Request.Body.Justification + + $Fail = { + param([string]$Message, [HttpStatusCode]$Status = [HttpStatusCode]::BadRequest) + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Message -Sev 'Error' + return [HttpResponseContext]@{ + StatusCode = $Status + Body = @{ Results = @(@{ resultText = $Message; state = 'error' }) } + } + } + + if ([string]::IsNullOrWhiteSpace($TenantFilter) -or [string]::IsNullOrWhiteSpace($Action) -or [string]::IsNullOrWhiteSpace($PrincipalId) -or [string]::IsNullOrWhiteSpace($RoleDefinitionId)) { + return (& $Fail 'tenantFilter, Action, PrincipalId and RoleDefinitionId are required.') + } + if ($Action -notin @('ConvertToEligible', 'GrantActive', 'Extend', 'Renew', 'Remove')) { + return (& $Fail "Action '$Action' is not supported. Use ConvertToEligible, GrantActive, Extend, Renew or Remove.") + } + if ([string]::IsNullOrWhiteSpace($Justification)) { + return (& $Fail 'A justification is required.') + } + if ("$Duration" -match '^\s*(noExpiration|permanent|never|none|unlimited)\s*$' -or "$EndDateTimeRaw" -match '^\s*(noExpiration|permanent|never|none|unlimited)\s*$') { + return (& $Fail 'Permanent (no-expiration) assignments cannot be created through CIPP. Supply a duration or an end date.') + } + + $EndDateTime = $null + if (-not [string]::IsNullOrWhiteSpace("$EndDateTimeRaw")) { + try { + $EndDateTime = if ("$EndDateTimeRaw" -match '^\d{9,11}$') { + ([System.DateTimeOffset]::FromUnixTimeSeconds([int64]$EndDateTimeRaw)).UtcDateTime + } else { + ([datetime]$EndDateTimeRaw).ToUniversalTime() + } + } catch { + return (& $Fail "EndDateTime '$EndDateTimeRaw' is not a valid date.") + } + } + + if ($Action -ne 'Remove' -and $Action -ne 'ConvertToEligible' -and [string]::IsNullOrWhiteSpace($Duration) -and $null -eq $EndDateTime) { + return (& $Fail "$Action requires a Duration or an EndDateTime; CIPP never creates permanent assignments.") + } + if (-not [string]::IsNullOrWhiteSpace($Duration) -and $null -ne $EndDateTime) { + return (& $Fail 'Supply either Duration or EndDateTime, not both.') + } + + $Params = @{ + TenantFilter = $TenantFilter + Action = $Action + PrincipalId = $PrincipalId + RoleDefinitionId = $RoleDefinitionId + DirectoryScopeId = if ([string]::IsNullOrWhiteSpace($DirectoryScopeId)) { '/' } else { $DirectoryScopeId } + Justification = $Justification + Headers = $Headers + APIName = $APIName + } + if ($AssignmentType -in @('Permanent', 'Active', 'ActivatedFromEligible', 'Eligible')) { $Params.AssignmentType = $AssignmentType } + if (-not [string]::IsNullOrWhiteSpace($Duration)) { $Params.Duration = $Duration } + if ($null -ne $EndDateTime) { $Params.EndDateTime = $EndDateTime } + if (-not [string]::IsNullOrWhiteSpace($TimeZone)) { $Params.TimeZone = $TimeZone } + + try { + $Result = Invoke-CIPPPIMAssignmentAction @Params + $StatusCode = [HttpStatusCode]::OK + $Results = @(@{ resultText = $Result.resultText; state = 'success' }) + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Message = "PIM $Action failed for $PrincipalId on $RoleDefinitionId`: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Message -Sev 'Error' -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::BadRequest + $Results = @(@{ resultText = $Message; state = 'error' }) + } + + return [HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{ Results = @($Results) } + } +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListPIMRoleSettingsTemplates.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListPIMRoleSettingsTemplates.ps1 new file mode 100644 index 0000000000000..c8d2bade4282d --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListPIMRoleSettingsTemplates.ps1 @@ -0,0 +1,51 @@ +function Invoke-ListPIMRoleSettingsTemplates { + <# + .FUNCTIONALITY + Entrypoint,AnyTenant + .ROLE + Identity.Role.Read + .SYNOPSIS + List PIM role settings templates. + .DESCRIPTION + Lists saved Privileged Identity Management role settings templates. A template names a set of roles and the activation, eligibility, assignment, approval and notification rules to enforce on them; the PIMRoleSettings standard deploys a template to tenants. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + # Return only the template with this GUID. + $GUID = $Request.Query.GUID ?? $Request.Query.id + + $Table = Get-CippTable -tablename 'templates' + $Filter = "PartitionKey eq 'PIMRoleSettingsTemplate'" + if (-not [string]::IsNullOrWhiteSpace($GUID)) { + $SafeGUID = ConvertTo-CIPPODataFilterValue -Value $GUID -Type String + $Filter = "$Filter and RowKey eq '$SafeGUID'" + } + + $Templates = @(Get-CIPPAzDataTableEntity @Table -Filter $Filter | ForEach-Object { + $Row = $_ + try { + $Data = $Row.JSON | ConvertFrom-Json -Depth 100 -ErrorAction Stop + # Grade the stored settings so the list shows a template that has drifted below + # the floor (e.g. edited in the table) before it is deployed. + $Floor = Test-CIPPPIMRoleSettingsFloor -Settings (ConvertTo-CIPPPIMRoleSettings -InputObject $Data.settings) + $Data | Add-Member -NotePropertyMembers ([ordered]@{ + GUID = $Row.GUID + RowKey = $Row.RowKey + meetsSecureFloor = $Floor.Valid + floorIssues = @($Floor.Errors) + roleCount = (@($Data.roles).Count) + }) -Force + $Data + } catch { + Write-LogMessage -headers $Headers -API $APIName -message "Failed to read PIM role settings template $($Row.RowKey): $($_.Exception.Message)" -sev 'Warning' + } + } | Sort-Object -Property templateName) + + return [HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = @($Templates) + } +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListPIMRoles.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListPIMRoles.ps1 new file mode 100644 index 0000000000000..42303dfda204a --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListPIMRoles.ps1 @@ -0,0 +1,115 @@ +function Invoke-ListPIMRoles { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Identity.Role.Read + .SYNOPSIS + List Entra directory roles grouped with their PIM assignment breakdown. + .DESCRIPTION + Returns one row per role (per tenant when AllTenants is selected) with the role's definition details, how many principals hold it permanently, eligibly or with a time-bound active assignment, the role's PIM policy summary, a slim Members list and the full assignment rows for drill-in. Roles nobody holds are included for a single tenant so the result is also the role catalogue. Powers the Roles & PIM page; ListRoles keeps its original per-definition shape and ListRoleAssignments stays one flat row per assignment. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $TenantFilter = $Request.Query.tenantFilter + # Restrict to one role template id, e.g. from an alert link. + $RoleTemplateId = $Request.Query.roleTemplateId + # Restrict to the roles one principal (object id) holds. + $PrincipalId = $Request.Query.principalId + + try { + if ($TenantFilter -eq 'AllTenants') { + $Counts = @( + Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'RoleAssignmentScheduleInstances' -CountsOnly + Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'Roles' -CountsOnly + ) | Where-Object { $_ } + $RefreshedAt = @{} + foreach ($Count in $Counts) { + $Existing = $RefreshedAt[$Count.PartitionKey] + if (-not $Existing -or $Count.Timestamp -gt $Existing) { $RefreshedAt[$Count.PartitionKey] = $Count.Timestamp } + } + $TenantList = Get-Tenants -IncludeErrors + $Tenants = @($RefreshedAt.Keys | Where-Object { $TenantList.defaultDomainName -contains $_ }) + + $Rows = [System.Collections.Generic.List[object]]::new() + foreach ($Tenant in $Tenants) { + try { + foreach ($Row in Get-CIPPPIMRoleAssignments -TenantFilter $Tenant -FromCache -IncludePolicy) { + $Row | Add-Member -NotePropertyName 'LastRefreshed' -NotePropertyValue $RefreshedAt[$Tenant] -Force + $Rows.Add($Row) + } + } catch { + Write-LogMessage -API $APIName -tenant $Tenant -message "Failed to read cached role assignments: $($_.Exception.Message)" -sev Warning + } + } + $Rows = @($Rows) + } else { + # A single-principal read drops the catalogue rows: the caller wants the roles the + # principal holds, not every role it does not. + $Params = @{ TenantFilter = $TenantFilter; IncludePolicy = $true; IncludeUnassignedRoles = [string]::IsNullOrWhiteSpace($PrincipalId) } + if (-not [string]::IsNullOrWhiteSpace($PrincipalId)) { $Params.PrincipalId = $PrincipalId } + if (-not [string]::IsNullOrWhiteSpace($RoleTemplateId)) { $Params.RoleDefinitionId = $RoleTemplateId } + $Rows = @(Get-CIPPPIMRoleAssignments @Params) + } + + if (-not [string]::IsNullOrWhiteSpace($PrincipalId)) { $Rows = @($Rows | Where-Object { $_.PrincipalId -eq $PrincipalId }) } + if (-not [string]::IsNullOrWhiteSpace($RoleTemplateId)) { $Rows = @($Rows | Where-Object { $_.RoleDefinitionId -eq $RoleTemplateId }) } + + $Grouped = @( + foreach ($Group in ($Rows | Group-Object -Property Tenant, RoleDefinitionId)) { + $GroupRows = @($Group.Group) + $Meta = $GroupRows[0] + # Catalogue rows (AssignmentType 'Unassigned') carry the role but no principal. + $Assignments = @($GroupRows | Where-Object { $_.PrincipalId }) + $PermanentCount = @($Assignments | Where-Object { $_.AssignmentType -eq 'Permanent' }).Count + $EligibleCount = @($Assignments | Where-Object { $_.AssignmentType -eq 'Eligible' }).Count + $ActiveCount = @($Assignments | Where-Object { $_.AssignmentType -in @('Active', 'ActivatedFromEligible') }).Count + [PSCustomObject]@{ + Tenant = $Meta.Tenant + RoleDefinitionId = $Meta.RoleDefinitionId + RoleDisplayName = $Meta.RoleDisplayName + RoleDescription = $Meta.RoleDescription + RoleIsBuiltIn = $Meta.RoleIsBuiltIn + IsPrivilegedRole = $Meta.IsPrivilegedRole + PIMCapable = $Meta.PIMCapable + PolicySummary = $Meta.PolicySummary + PolicyBelowFloor = $Meta.PolicyBelowFloor + MemberCount = $Assignments.Count + PermanentCount = $PermanentCount + EligibleCount = $EligibleCount + ActiveCount = $ActiveCount + IsAssigned = ($Assignments.Count -gt 0) + HasPermanentMembers = ($PermanentCount -gt 0) + # camelCase like the original ListRoles members, so the Members cell formatter + # and its CSV/PDF export read them. + Members = @($Assignments | ForEach-Object { + [PSCustomObject]@{ + displayName = $_.PrincipalDisplayName + userPrincipalName = $_.PrincipalUserPrincipalName + principalType = $_.PrincipalType + assignmentType = $_.AssignmentType + endDateTime = $_.EndDateTime + } + }) + Assignments = @($Assignments) + LastRefreshed = $Meta.LastRefreshed + } + } + ) + $Results = @($Grouped | Sort-Object -Property Tenant, RoleDisplayName) + + $StatusCode = [HttpStatusCode]::OK + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API $APIName -tenant $TenantFilter -message "Failed to list roles with PIM data: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + $Results = "Failed to list roles with PIM data for $TenantFilter. $($ErrorMessage.NormalizedError)" + $StatusCode = [HttpStatusCode]::BadRequest + } + + return [HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @($Results) + } +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListRoleAssignments.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListRoleAssignments.ps1 new file mode 100644 index 0000000000000..4220c47580e6f --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListRoleAssignments.ps1 @@ -0,0 +1,76 @@ +function Invoke-ListRoleAssignments { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Identity.Role.Read + .SYNOPSIS + List Entra directory role assignments with their PIM assignment type. + .DESCRIPTION + Returns one row per principal, role and scope showing whether the assignment is Permanent (active with no end date), Active (time-bound), ActivatedFromEligible or Eligible, whether it is held directly or through a role-assignable group, the scope (directory or administrative unit), the principal type, the role's description and built-in flag, and the role's PIM policy summary. For a single tenant roles that nobody holds are included as Unassigned rows so the result is also the role catalogue. A single tenant is read live from Graph (Entra ID P2 tenants via PIM, others via unified RBAC where every assignment is permanent); AllTenants is served from the reporting cache. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $TenantFilter = $Request.Query.tenantFilter + # Restrict to one principal (object id), e.g. for the user view page. + $PrincipalId = $Request.Query.principalId + # Restrict to one role template id. + $RoleTemplateId = $Request.Query.roleTemplateId + # Only return permanent (active, no end date) assignments. + $PermanentOnly = [bool]($Request.Query.permanentOnly -eq $true -or "$($Request.Query.permanentOnly)" -eq 'true') + # Single tenant: also list roles that nobody holds (AssignmentType 'Unassigned'), so the result is the full role catalogue. Default true; set to false for assignments only. + $IncludeUnassigned = -not ("$($Request.Query.includeUnassigned)" -eq 'false') + + try { + if ($TenantFilter -eq 'AllTenants') { + $Counts = @( + Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'RoleAssignmentScheduleInstances' -CountsOnly + Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'Roles' -CountsOnly + ) | Where-Object { $_ } + $RefreshedAt = @{} + foreach ($Count in $Counts) { + $Existing = $RefreshedAt[$Count.PartitionKey] + if (-not $Existing -or $Count.Timestamp -gt $Existing) { $RefreshedAt[$Count.PartitionKey] = $Count.Timestamp } + } + $TenantList = Get-Tenants -IncludeErrors + $Tenants = @($RefreshedAt.Keys | Where-Object { $TenantList.defaultDomainName -contains $_ }) + + $Results = [System.Collections.Generic.List[object]]::new() + foreach ($Tenant in $Tenants) { + try { + $Rows = Get-CIPPPIMRoleAssignments -TenantFilter $Tenant -FromCache -IncludePolicy + foreach ($Row in $Rows) { + $Row | Add-Member -NotePropertyName 'LastRefreshed' -NotePropertyValue $RefreshedAt[$Tenant] -Force + $Results.Add($Row) + } + } catch { + Write-LogMessage -API $APIName -tenant $Tenant -message "Failed to read cached role assignments: $($_.Exception.Message)" -sev Warning + } + } + $Results = @($Results) + } else { + $Params = @{ TenantFilter = $TenantFilter; IncludePolicy = $true; IncludeUnassignedRoles = ($IncludeUnassigned -and -not $PermanentOnly) } + if (-not [string]::IsNullOrWhiteSpace($PrincipalId)) { $Params.PrincipalId = $PrincipalId } + if (-not [string]::IsNullOrWhiteSpace($RoleTemplateId)) { $Params.RoleDefinitionId = $RoleTemplateId } + $Results = @(Get-CIPPPIMRoleAssignments @Params) + } + + if (-not [string]::IsNullOrWhiteSpace($PrincipalId)) { $Results = @($Results | Where-Object { $_.PrincipalId -eq $PrincipalId }) } + if (-not [string]::IsNullOrWhiteSpace($RoleTemplateId)) { $Results = @($Results | Where-Object { $_.RoleDefinitionId -eq $RoleTemplateId }) } + if ($PermanentOnly) { $Results = @($Results | Where-Object { $_.AssignmentType -eq 'Permanent' }) } + + $StatusCode = [HttpStatusCode]::OK + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API $APIName -tenant $TenantFilter -message "Failed to list role assignments: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + $Results = "Failed to list role assignments for $TenantFilter. $($ErrorMessage.NormalizedError)" + $StatusCode = [HttpStatusCode]::BadRequest + } + + return [HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @($Results) + } +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-RemovePIMRoleSettingsTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-RemovePIMRoleSettingsTemplate.ps1 new file mode 100644 index 0000000000000..dcb5985269453 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-RemovePIMRoleSettingsTemplate.ps1 @@ -0,0 +1,48 @@ +function Invoke-RemovePIMRoleSettingsTemplate { + <# + .FUNCTIONALITY + Entrypoint,AnyTenant + .ROLE + Identity.Role.ReadWrite + .SYNOPSIS + Delete a PIM role settings template. + .DESCRIPTION + Deletes a saved Privileged Identity Management role settings template by GUID. Tenants already configured from the template keep their settings. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + try { + # GUID of the template to delete. + $ID = $Request.Query.ID ?? $Request.Body.ID ?? $Request.Body.GUID + if ([string]::IsNullOrWhiteSpace($ID)) { throw 'ID is required' } + + $Table = Get-CippTable -tablename 'templates' + $SafeID = ConvertTo-CIPPODataFilterValue -Value $ID -Type String + $Template = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'PIMRoleSettingsTemplate' and RowKey eq '$SafeID'" + + if ($Template) { + Remove-CIPPAzDataTableEntity @Table -Entity $Template + $Result = "Successfully deleted PIM role settings template with ID: $ID" + Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Info' + $StatusCode = [HttpStatusCode]::OK + } else { + $Result = "PIM role settings template with ID $ID not found" + Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Warning' + $StatusCode = [HttpStatusCode]::NotFound + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to delete PIM role settings template: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::InternalServerError + } + + return [HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{ Results = "$Result" } + } +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddJITRoleTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddJITRoleTemplate.ps1 new file mode 100644 index 0000000000000..1d5a2567ae39f --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddJITRoleTemplate.ps1 @@ -0,0 +1,81 @@ +function Invoke-AddJITRoleTemplate { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Identity.Role.ReadWrite + .DESCRIPTION + Creates a JIT Role Template - a named allow-list of directory roles that can be assigned to a + CIPP custom role to restrict which roles that role's members may grant via JIT Admin. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + try { + $TemplateName = $Request.Body.templateName + + if ([string]::IsNullOrWhiteSpace($TemplateName)) { + throw 'templateName is required' + } + if (-not $Request.Body.roles -or @($Request.Body.roles).Count -eq 0) { + throw 'At least one role is required' + } + + Write-LogMessage -headers $Headers -API $APIName -message "Creating JIT Role template '$TemplateName'" -Sev 'Info' + + # Get user info for audit + $UserDetails = ([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($Headers.'x-ms-client-principal')) | ConvertFrom-Json).userDetails + + # Check if template name already exists + $Table = Get-CippTable -tablename 'templates' + $ExistingTemplates = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'JITRoleTemplate'" + $ExistingNames = $ExistingTemplates | ForEach-Object { + try { + $data = $_.JSON | ConvertFrom-Json -Depth 100 -ErrorAction Stop + if ($data.templateName -eq $TemplateName) { + $data + } + } catch {} + } + + if ($ExistingNames) { + throw "A JIT Role Template with name '$TemplateName' already exists" + } + + $TemplateObject = @{ + templateName = $TemplateName + roles = $Request.Body.roles + createdBy = $UserDetails + createdDate = (Get-Date).ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:ssZ') + } + + $GUID = (New-Guid).GUID + $JSON = ConvertTo-Json -InputObject $TemplateObject -Depth 100 -Compress + + $Table.Force = $true + Add-CIPPAzDataTableEntity @Table -Entity @{ + JSON = "$JSON" + RowKey = "$GUID" + PartitionKey = 'JITRoleTemplate' + GUID = "$GUID" + } + + $Result = "Created JIT Role Template '$($TemplateName)' with GUID $GUID" + Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Info' + $StatusCode = [HttpStatusCode]::OK + + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to create JIT Role Template: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::InternalServerError + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{'Results' = "$Result" } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUser.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUser.ps1 index 0bea284e0079d..5f36856d9bce8 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUser.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUser.ps1 @@ -39,6 +39,7 @@ function Invoke-AddUser { Parameters = [pscustomobject]@{ UserObj = $UserObj } ScheduledTime = $UserObj.Scheduled.date Reference = $UserObj.reference ?? $null + PsaTicketId = $UserObj.PsaTicketId ?? $null PostExecution = @{ Webhook = [bool]$Request.Body.PostExecution.Webhook Email = [bool]$Request.Body.PostExecution.Email diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUserBulk.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUserBulk.ps1 index 5e0cdf6c0f263..67ddccdaddea4 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUserBulk.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUserBulk.ps1 @@ -128,6 +128,7 @@ function Invoke-AddUserBulk { $LicenseSkus = $AssignedLicenses.value ?? $AssignedLicenses | Where-Object { $_ -match $GuidPattern } Set-CIPPUserLicense -UserId $BulkResult.id -AddLicenses $LicenseSkus -TenantFilter $TenantFilter -APIName $APIName -Headers $Headers } + Write-LogMessage -headers $Request.Headers -API $APIName -tenant $TenantFilter -message $Message.resultText -Sev 'Info' $Results.Add(@{ resultText = $Message.resultText state = 'success' diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUserDefaults.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUserDefaults.ps1 index 675322f302019..c9b58c10e6788 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUserDefaults.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUserDefaults.ps1 @@ -51,6 +51,7 @@ function Invoke-AddUserDefaults { $Autopassword = $Request.Body.Autopassword $Password = $Request.Body.password $MustChangePass = $Request.Body.MustChangePass + $PerUserMfa = [System.Convert]::ToBoolean($Request.Body.perUserMfa) $UsageLocation = if ($Request.Body.usageLocation -is [string]) { $Request.Body.usageLocation @@ -119,6 +120,7 @@ function Invoke-AddUserDefaults { Autopassword = $Autopassword password = $Password MustChangePass = $MustChangePass + perUserMfa = $PerUserMfa usageLocation = $UsageLocation licenses = $Licenses removeLicenses = $RemoveLicenses diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-EditJITRoleTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-EditJITRoleTemplate.ps1 new file mode 100644 index 0000000000000..b216337efc998 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-EditJITRoleTemplate.ps1 @@ -0,0 +1,94 @@ +function Invoke-EditJITRoleTemplate { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Identity.Role.ReadWrite + .DESCRIPTION + Updates an existing JIT Role Template. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + try { + $GUID = $Request.Body.GUID + $TemplateName = $Request.Body.templateName + + if ([string]::IsNullOrWhiteSpace($GUID)) { + throw 'GUID is required' + } + if ([string]::IsNullOrWhiteSpace($TemplateName)) { + throw 'templateName is required' + } + if (-not $Request.Body.roles -or @($Request.Body.roles).Count -eq 0) { + throw 'At least one role is required' + } + + Write-LogMessage -headers $Headers -API $APIName -message "Editing JIT Role template '$GUID'" -Sev 'Info' + + $UserDetails = ([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($Headers.'x-ms-client-principal')) | ConvertFrom-Json).userDetails + + $Table = Get-CippTable -tablename 'templates' + $SafeGUID = ConvertTo-CIPPODataFilterValue -Value $GUID -Type Guid + $Filter = "PartitionKey eq 'JITRoleTemplate' and RowKey eq '$SafeGUID'" + $ExistingTemplate = Get-CIPPAzDataTableEntity @Table -Filter $Filter + + if (!$ExistingTemplate) { + throw "JIT Role Template with GUID '$GUID' not found" + } + + $ExistingData = $ExistingTemplate.JSON | ConvertFrom-Json -Depth 100 + + # Check if template name is unique (excluding current template) + $AllTemplates = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'JITRoleTemplate'" + $DuplicateName = $AllTemplates | Where-Object { $_.RowKey -ne $GUID } | ForEach-Object { + try { + $data = $_.JSON | ConvertFrom-Json -Depth 100 -ErrorAction Stop + if ($data.templateName -eq $TemplateName) { + $data + } + } catch {} + } + + if ($DuplicateName) { + throw "A JIT Role Template with name '$TemplateName' already exists" + } + + $TemplateObject = @{ + templateName = $TemplateName + roles = $Request.Body.roles + createdBy = $ExistingData.createdBy + createdDate = $ExistingData.createdDate + modifiedBy = $UserDetails + modifiedDate = (Get-Date).ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:ssZ') + } + + $JSON = ConvertTo-Json -InputObject $TemplateObject -Depth 100 -Compress + + $Table.Force = $true + Add-CIPPAzDataTableEntity @Table -Entity @{ + JSON = "$JSON" + RowKey = "$GUID" + PartitionKey = 'JITRoleTemplate' + GUID = "$GUID" + } + + $Result = "Updated JIT Role Template '$($TemplateName)' (GUID: $GUID)" + Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Info' + $StatusCode = [HttpStatusCode]::OK + + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to update JIT Role Template: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::InternalServerError + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{'Results' = "$Result" } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecJITAdmin.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecJITAdmin.ps1 index 9233c506da6a9..f63405c35d442 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecJITAdmin.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecJITAdmin.ps1 @@ -53,6 +53,27 @@ function Invoke-ExecJITAdmin { # Continue execution if we can't check the setting } + # Enforce the caller's allowed JIT roles (from the JIT Role Template on their custom role). + # Get-CIPPJITAdminAllowedRoles is authoritative and fails closed for restricted callers, so we + # trust its result rather than swallowing errors here. + $RequestedRoles = @($Request.Body.AdminRoles.value | Where-Object { $_ }) + if ($RequestedRoles.Count -gt 0) { + $AllowedRoles = Get-CIPPJITAdminAllowedRoles -Headers $Headers + if ($AllowedRoles.Restricted) { + $ForbiddenRoles = @($RequestedRoles | Where-Object { $AllowedRoles.AllowedRoleIds -notcontains $_ }) + if ($ForbiddenRoles.Count -gt 0) { + $ForbiddenLabels = @($Request.Body.AdminRoles | Where-Object { $ForbiddenRoles -contains $_.value } | ForEach-Object { $_.label ?? $_.value }) + if ($ForbiddenLabels.Count -eq 0) { $ForbiddenLabels = $ForbiddenRoles } + $ErrorMessage = "You are not permitted to assign the following role(s): $($ForbiddenLabels -join ', ')" + Write-LogMessage -headers $Headers -API $APIName -message $ErrorMessage -Sev 'Error' + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @{'Results' = @($ErrorMessage) } + }) + } + } + } + if ($Request.Body.userAction -eq 'create') { $Domain = $Request.Body.Domain.value ? $Request.Body.Domain.value : $Request.Body.Domain $Username = "$($Request.Body.Username)@$($Domain)" @@ -186,6 +207,7 @@ function Invoke-ExecJITAdmin { $PasswordLink = New-PwPushLink -Payload $TempPass $Password = $PasswordLink ? $PasswordLink : $TempPass + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Created Temporary Access Pass for $Username (lifetime: $PasswordExpiration minutes)" -Sev 'Info' $Results.Add(@{ resultText = "Temporary Access Pass: $Password" copyField = $Password @@ -247,6 +269,7 @@ function Invoke-ExecJITAdmin { if ($Request.Body.userAction -ne 'create') { Set-CIPPUserJITAdminProperties -TenantFilter $TenantFilter -UserId $Request.Body.existingUser.value -Expiration $Expiration -StartDate $Start -Reason $Request.Body.Reason -CreatedBy (([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($Headers.'x-ms-client-principal')) | ConvertFrom-Json).userDetails) } + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Scheduled JIT Admin enable task for $Username" -Sev 'Info' $Results.Add("Scheduling JIT Admin enable task for $Username") } else { try { @@ -286,6 +309,7 @@ function Invoke-ExecJITAdmin { ScheduledTime = $Request.Body.EndDate } $null = Add-CIPPScheduledTask -Task $DisableTaskBody -hidden $false + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message "Scheduled JIT Admin $($Request.Body.ExpireAction.value) task for $Username" -Sev 'Info' $Results.Add("Scheduling JIT Admin $($Request.Body.ExpireAction.value) task for $Username") return ([HttpResponseContext]@{ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecOffboardUser.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecOffboardUser.ps1 index 068c95ec1c3b9..b58b806278e9c 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecOffboardUser.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecOffboardUser.ps1 @@ -4,10 +4,68 @@ function Invoke-ExecOffboardUser { Entrypoint .ROLE Identity.User.ReadWrite + .DESCRIPTION + Runs the offboarding wizard: one scheduled offboarding job per user, immediately or at the + scheduled time, reporting live progress under one job id. Action=Rerun queues an existing + offboarding task again; Action=RerunStep queues one step of it, reported to the same progress row. #> [CmdletBinding()] param($Request, $TriggerMetadata) + $Action = $Request.Query.Action ?? $Request.Body.Action + if ($Action -in @('Rerun', 'RerunStep')) { + try { + # RowKey of the offboarding task to run again + $TaskId = [string]$Request.Body.TaskId + if (-not $TaskId) { throw 'TaskId is required' } + $TenantFilter = [string]($Request.Body.tenantFilter.value ?? $Request.Body.tenantFilter) + $Table = Get-CIPPTable -TableName 'ScheduledTasks' + $SafeTaskId = $TaskId -replace "'", "''" + $Task = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'ScheduledTask' and RowKey eq '$SafeTaskId'" + # Access to tenantFilter was checked on the way in; the task must belong to that tenant. + if (-not $Task -or $Task.Command -ne 'Invoke-CIPPOffboardingJob' -or [string]$Task.Tenant -ne $TenantFilter) { + throw 'No offboarding task with that id exists in this tenant' + } + + if ($Action -eq 'Rerun') { + $Result = Add-CIPPScheduledTask -RunNow -RowKey $TaskId -Headers $Request.Headers + } else { + # Zero-based index of the step, as listed in the progress row, to run again + $StepIndex = $Request.Body.StepIndex -as [int] + if ($null -eq $StepIndex) { throw 'StepIndex is required' } + # Title of that step, used to name the re-run task + $StepTitle = [string]$Request.Body.StepTitle + $Parameters = $Task.Parameters | ConvertFrom-Json + # A step re-run is its own scheduled task (so it has results and logs of its own) that + # reports to the original job's progress row. + $taskObject = [PSCustomObject]@{ + TenantFilter = $TenantFilter + Name = "Offboarding: $($Parameters.Username) - re-run $(if ($StepTitle) { $StepTitle } else { "step $StepIndex" })" + Command = @{ value = 'Invoke-CIPPOffboardingJob' } + Parameters = [pscustomobject]@{ + Username = $Parameters.Username + APIName = 'Scheduled Offboarding' + options = $Parameters.options + RunScheduled = $true + DeploymentId = $Parameters.DeploymentId + StepIndexes = @($StepIndex) + } + Reference = $Task.Reference + } + $Result = Add-CIPPScheduledTask -Task $taskObject -hidden $false -RunNow -Headers $Request.Headers + } + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = @{ Results = $Result } + }) + } catch { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @{ Results = "Failed to queue the re-run: $($_.Exception.Message)" } + }) + } + } + $Validation = Test-CIPPOffboardingRequest -Body $Request.Body if (-not $Validation.IsValid) { return ([HttpResponseContext]@{ @@ -20,6 +78,16 @@ function Invoke-ExecOffboardUser { $TenantFilter = $Validation.TenantFilter $OffboardingOptions = $Request.Body | Select-Object * -ExcludeProperty user, tenantFilter, Scheduled + # One live-progress job per wizard run with a queued row per user: the wizard polls it when + # running now, and the task page shows it for any job. Progress is a nice-to-have, so failing to + # create the rows must not stop the offboarding itself. + $DeploymentId = $null + try { + $DeploymentId = New-CIPPAsyncDeployment -Names $AllUsers -Source 'Offboarding' -TenantFilter $TenantFilter + } catch { + Write-LogMessage -headers $Request.Headers -API $Request.Params.CIPPEndpoint -tenant $TenantFilter -message "Could not create the offboarding progress rows: $($_.Exception.Message)" -sev Warn + } + $StatusCode = [HttpStatusCode]::OK $Results = foreach ($username in $AllUsers) { try { @@ -35,6 +103,7 @@ function Invoke-ExecOffboardUser { APIName = 'Scheduled Offboarding' options = $OffboardingOptions RunScheduled = $true + DeploymentId = $DeploymentId } PostExecution = @{ Webhook = [bool]$Request.Body.PostExecution.webhook @@ -42,6 +111,7 @@ function Invoke-ExecOffboardUser { PSA = [bool]$Request.Body.PostExecution.psa } Reference = $Request.Body.reference + PsaTicketId = $Request.Body.PsaTicketId } $Params = @{ Task = $taskObject @@ -60,6 +130,10 @@ function Invoke-ExecOffboardUser { } } $body = [pscustomobject]@{'Results' = @($Results) } + if ($DeploymentId -and -not $Request.Body.Scheduled.enabled) { + # Only a run-now job is worth polling straight away; a scheduled one is watched from its task page. + $body | Add-Member -NotePropertyName DeploymentId -NotePropertyValue $DeploymentId + } return ([HttpResponseContext]@{ StatusCode = $StatusCode Body = $Body diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecSendPush.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecSendPush.ps1 index 8df1305cb4734..5fc330a57ad3d 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecSendPush.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecSendPush.ps1 @@ -5,7 +5,7 @@ function Invoke-ExecSendPush { .ROLE Identity.User.Read .DESCRIPTION - Sends a test MFA push notification to a user's authenticator app and reports whether it was approved. Used to confirm a user's MFA registration works. This causes a real prompt on the user's device. + Sends a test MFA push notification to a user's authenticator app and reports whether it was approved, or - when an OTP code is supplied - verifies that typed code without sending a push. Used to confirm a user's MFA registration works. The push path causes a real prompt on the user's device. #> [CmdletBinding()] param($Request, $TriggerMetadata) @@ -13,117 +13,113 @@ function Invoke-ExecSendPush { $APIName = $Request.Params.CIPPEndpoint $TenantFilter = $Request.body.TenantFilter $UserEmail = $Request.body.UserEmail - $MFAAppID = '981f26a1-7f43-403b-a875-f8b09b8cd720' + # When an OTP code is supplied we verify that code instead of sending a push notification. + $OTP = $Request.body.OTP + $VerifyOtp = -not [string]::IsNullOrWhiteSpace($OTP) - # Function to keep trying to get the access token while we wait for MS to actually set the temp password - function Get-ClientAccess { - param( - $uri, - $body, - $count = 1 - ) - try { - $ClientToken = Invoke-RestMethod -Method post -Uri $uri -Body $body -ea stop - } catch { - if ($count -lt 20) { - - $count++ - Start-Sleep 1 - $ClientToken = Get-ClientAccess -uri $uri -body $body -count $count - } else { - throw "Could not get Client Token: $_" - } - } - return $ClientToken - } - - - # Get all service principals - $SPResult = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/servicePrincipals?`$top=999&`$select=id,appId" -tenantid $TenantFilter -AsApp $true - - # Check if we have one for the MFA App - $SPID = ($SPResult | Where-Object { $_.appId -eq $MFAAppID }).id - - # Create a service principal if needed - if (!$SPID) { - - $SPBody = [pscustomobject]@{ - appId = $MFAAppID - } | ConvertTo-Json -Depth 5 - $SPID = (New-GraphPostRequest -uri 'https://graph.microsoft.com/v1.0/servicePrincipals' -tenantid $TenantFilter -type POST -body $SPBody -AsApp $true).id - } + # Defaults so every path returns a well-formed state, even when an early step fails. + $State = 'error' + $Body = 'An unknown error occurred while processing the MFA request.' + $obj = $null + $ResultValue = $null + # Mint a connector token (this provisions a temporary secret on the MFA client service principal). try { - $PolicyUpdate = Update-AppManagementPolicy -TenantFilter $TenantFilter -ApplicationId $MFAAppID - Write-Information $PolicyUpdate.PolicyAction + $Connector = New-CIPPMFAConnectorToken -TenantFilter $TenantFilter -Headers $Request.Headers } catch { - Write-Information "Failed to update app management policy: $($_.Exception.Message)" + $Body = $_.Exception.Message + Write-LogMessage -headers $Request.Headers -API $APINAME -message "Failed MFA request for $UserEmail - $Body" -Sev 'Error' + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = [pscustomobject]@{'Results' = @{ resultText = $Body; state = 'error' } } + }) } - $PassReqBody = @{ - 'passwordCredential' = @{ - 'displayName' = 'MFA Temporary Password' - 'endDateTime' = $((Get-Date).AddMinutes(5)) - 'startDateTime' = $((Get-Date).AddMinutes(-5)) - } - } | ConvertTo-Json -Depth 5 + $ClientHeaders = @{ 'Authorization' = "Bearer $($Connector.AccessToken)" } - $TempPass = (New-GraphPostRequest -uri "https://graph.microsoft.com/v1.0/servicePrincipals/$SPID/addPassword" -tenantid $TenantFilter -type POST -body $PassReqBody -AsApp $true).secretText + # Policy: a typed code is only accepted when the user has no Microsoft Authenticator registered. When the + # Authenticator is present the stronger interactive push is required, so a TOTP code is refused. + $HasAuthenticator = $false + if ($VerifyOtp) { + $UserMethods = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users/$UserEmail/authentication/methods" -tenantid $TenantFilter + $HasAuthenticator = @($UserMethods).'@odata.type' -contains '#microsoft.graph.microsoftAuthenticatorAuthenticationMethod' + } - # Give it a chance to apply - #Start-Sleep 5 + if ($VerifyOtp -and $HasAuthenticator) { + $Body = 'This user has Microsoft Authenticator registered, so a push notification is required instead of a typed code.' + $State = 'error' + } elseif ($VerifyOtp) { + # OTP verification is a two-call handshake against the modernized StrongAuthenticationService host + # (the adnotifications host only supports push): Begin with SyncCall=false so no push is sent, then + # End with the typed code in AdditionalAuthData, keyed to the returned SessionId. + $StrongAuthUri = 'https://strongauthenticationservice.auth.microsoft.com/StrongAuthenticationService.svc/Connector' + $ContextId = (New-Guid).Guid + $BeginXML = @" + +1.0 +$UserEmail +en-usOverrideVoiceOtpfalse$ContextId +falsetrueradiusUNKNOWN: +"@ + $BeginResp = Invoke-RestMethod -Uri "$StrongAuthUri/BeginTwoWayAuthentication" -Method POST -Headers $ClientHeaders -Body $BeginXML -ContentType 'application/xml' + $SessionId = $BeginResp.BeginTwoWayAuthenticationResponse.SessionId - # Generate the XML for the push request - $XML = @" + if ($SessionId) { + $EndXML = @" + +1.0 +$SessionId +$OTP + +"@ + $obj = Invoke-RestMethod -Uri "$StrongAuthUri/EndTwoWayAuthentication" -Method POST -Headers $ClientHeaders -Body $EndXML -ContentType 'application/xml' + $ResultValue = $obj.EndTwoWayAuthenticationResponse.Result.Value + + if ($obj.EndTwoWayAuthenticationResponse.AuthenticationResult -eq $true -and $ResultValue -eq 'Success') { + $Body = 'The MFA code was verified successfully.' + $State = 'success' + } elseif ($ResultValue -eq 'OathCodeIncorrect') { + $Body = 'The MFA code was incorrect. Please check the code and try again.' + $State = 'error' + } else { + $Body = "MFA code verification failed: $ResultValue" + $State = 'error' + } + } else { + $Body = 'Could not start an MFA verification session. Does the user have an authenticator (OTP) method registered?' + $State = 'error' + } + } else { + # Push notification: SyncCall=true blocks until the user approves or denies on their device. + # AuthenticationMethodId forces the Authenticator push so it prompts even when the user's default + # method is something else (e.g. an OATH code); otherwise the connector targets the default and + # returns immediately without a prompt. + $ContextId = (New-Guid).Guid + $XML = @" 1.0 $UserEmail -en-usOverrideVoiceOtpfalse69ff05bf-eb61-47f7-a70e-e7d77b6d47d0 +en-usPhoneAppNotificationOverrideVoiceOtpfalse$ContextId truetrueradiusUNKNOWN: "@ - - # Request to get client token - $body = @{ - 'resource' = 'https://adnotifications.windowsazure.com/StrongAuthenticationService.svc/Connector' - 'client_id' = $MFAAppID - 'client_secret' = $TempPass - 'grant_type' = 'client_credentials' - 'scope' = 'openid' - } - - # Attempt to get a token using the temp password - $ClientUri = "https://login.microsoftonline.com/$TenantFilter/oauth2/token" - try { - $ClientToken = Get-ClientAccess -Uri $ClientUri -Body $body - } catch { - $Body = 'Failed to create temporary token for MFA Application. Error: ' + $_.Exception.Message - } - - # If we got a token send a push - if ($ClientToken) { - - $ClientHeaders = @{ 'Authorization' = "Bearer $($ClientToken.access_token)" } - $obj = Invoke-RestMethod -Uri 'https://adnotifications.windowsazure.com/StrongAuthenticationService.svc/Connector//BeginTwoWayAuthentication' -Method POST -Headers $ClientHeaders -Body $XML -ContentType 'application/xml' + $ResultValue = $obj.BeginTwoWayAuthenticationResponse.result.value - if ($obj.BeginTwoWayAuthenticationResponse.result) { - $Body = "Received an MFA confirmation: $($obj.BeginTwoWayAuthenticationResponse.result.value | Out-String)" + if ($obj.BeginTwoWayAuthenticationResponse.AuthenticationResult -eq $true) { + $Body = "Received an MFA confirmation: $($ResultValue | Out-String)" $State = 'success' - } - if ($obj.BeginTwoWayAuthenticationResponse.AuthenticationResult -ne $true) { - $Body = "Authentication Failed! Does the user have Push/Phone call MFA configured? ErrorCode: $($obj.BeginTwoWayAuthenticationResponse.result.value | Out-String)" + } else { + $Body = "Authentication Failed! Does the user have Push/Phone call MFA configured? ErrorCode: $($ResultValue | Out-String)" $State = 'error' } - } $Results = [pscustomobject]@{'Results' = @{ resultText = $Body; state = $State } } - Write-LogMessage -headers $Request.Headers -API $APINAME -message "Sent push request to $UserEmail - Result: $($obj.BeginTwoWayAuthenticationResponse.result.value | Out-String)" -Sev 'Info' + $LogAction = if ($VerifyOtp) { 'Verified MFA code' } else { 'Sent push request' } + Write-LogMessage -headers $Request.Headers -API $APINAME -message "$LogAction for $UserEmail - Result: $($ResultValue | Out-String)" -Sev 'Info' return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK Body = $Results }) - - } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListGuestUsers.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListGuestUsers.ps1 index 0255de67a6cdf..981052311f28f 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListGuestUsers.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListGuestUsers.ps1 @@ -7,7 +7,7 @@ function Invoke-ListGuestUsers { .SYNOPSIS List guest users with lifecycle status .DESCRIPTION - Lists all guest accounts in a tenant with a computed lifecycle status (Active, Pending Acceptance, Stale, Never Signed In or Disabled) based on the invitation state and sign-in activity. Supports UseReportDB=true to serve cached data from the reporting database; AllTenants always uses the cache. + Lists all guest accounts in a tenant with a computed lifecycle status (Active, Pending Acceptance, Stale, Never Signed In or Disabled) based on the invitation state and sign-in activity. Supports UseReportDB=true to serve cached data from the reporting database; AllTenants always uses the cache. When manualPagination is set on a cached read, one page is returned per request as { Results, Metadata } with a continuation token in Metadata.nextLink. #> [CmdletBinding()] param($Request, $TriggerMetadata) @@ -21,13 +21,28 @@ function Invoke-ListGuestUsers { $StaleDays = $Request.Query.staleDays ? [int]$Request.Query.staleDays : 90 # Serve from the reporting database cache instead of live Graph. AllTenants always uses the cache. $UseReportDB = $Request.Query.UseReportDB -eq $true + # Return one page per request as { Results, Metadata } with a continuation token in Metadata.nextLink; cached reads only. + $ManualPagination = $Request.Query.manualPagination -and [System.Convert]::ToBoolean($Request.Query.manualPagination) + $NextToken = $null try { if ($TenantFilter -eq 'AllTenants' -or $UseReportDB) { # Cached rows carry a per-row signInLogsCapable stamp written by the cache job, # so sign-in availability is judged per row below. $SignInLogsCapable = $null - $GuestUsers = Get-CIPPGuestUsersReport -TenantFilter $TenantFilter + if ($ManualPagination) { + # Rows per page, clamped between 250 and 10000. Defaults to 5000. + $PageSize = 5000 + if ($Request.Query.PageSize -as [int]) { + $PageSize = [Math]::Min([Math]::Max([int]$Request.Query.PageSize, 250), 10000) + } + # Continuation token from the previous page's Metadata.nextLink; opaque to callers. + $Page = Get-CIPPGuestUsersReport -TenantFilter $TenantFilter -PageSize $PageSize -ContinuationToken $Request.Query.nextLink + $GuestUsers = $Page.Items + $NextToken = $Page.NextToken + } else { + $GuestUsers = Get-CIPPGuestUsersReport -TenantFilter $TenantFilter + } } else { # signInActivity can only be requested on tenants with an Entra ID P1 license - Graph # rejects the whole query on unlicensed tenants, so fall back to listing without @@ -113,6 +128,19 @@ function Invoke-ListGuestUsers { $GraphRequest = @{ Error = $ErrorMessage.NormalizedError } } + # Paged cached reads return { Results, Metadata }; everything else keeps the legacy bare array. + if ($ManualPagination -and ($TenantFilter -eq 'AllTenants' -or $UseReportDB) -and $StatusCode -eq [System.Net.HttpStatusCode]::OK) { + $Metadata = @{} + if ($NextToken) { $Metadata.nextLink = $NextToken } + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = [PSCustomObject]@{ + Results = @($GraphRequest) + Metadata = $Metadata + } + }) + } + return ([HttpResponseContext]@{ StatusCode = $StatusCode Body = @($GraphRequest) diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITAdmin.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITAdmin.ps1 index 3c5a66238d963..06830b6c183c9 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITAdmin.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITAdmin.ps1 @@ -15,6 +15,18 @@ $Schema = Get-CIPPSchemaExtensions | Where-Object { $_.id -match '_cippUser' } | Select-Object -First 1 $TenantFilter = $Request.Query.TenantFilter + # Resolve which directory roles the caller may see. When restricted, a JIT admin is only shown if + # every directory role it currently holds is within the caller's allow-list (strict subset). JIT + # admins with no resolvable roles (e.g. scheduled-but-not-yet-active, or stale cache) are shown. + $AllowedRoles = Get-CIPPJITAdminAllowedRoles -Headers $Request.Headers + $FilterJITAdmin = { + param($RoleTemplateIds) + if (-not $AllowedRoles.Restricted) { return $true } + $Ids = @($RoleTemplateIds | Where-Object { $_ }) + if ($Ids.Count -eq 0) { return $true } + return @($Ids | Where-Object { $AllowedRoles.AllowedRoleIds -notcontains $_ }).Count -eq 0 + } + if ($TenantFilter -ne 'AllTenants') { # Single tenant logic $BulkRequests = [System.Collections.Generic.List[object]]::new() @@ -29,27 +41,37 @@ $BulkRequests.Clear() foreach ($User in $Users) { + # memberOf (groups + roles) for display $BulkRequests.Add(@{ id = $User.id method = 'GET' url = "users/$($User.id)/memberOf?`$select=id,displayName" }) + # directory roles with roleTemplateId, used for allow-list filtering + $BulkRequests.Add(@{ + id = "role_$($User.id)" + method = 'GET' + url = "users/$($User.id)/memberOf/microsoft.graph.directoryRole?`$select=id,displayName,roleTemplateId" + }) } $RoleResults = New-GraphBulkRequest -tenantid $TenantFilter -Requests @($BulkRequests) # Write-Information ($RoleResults | ConvertTo-Json -Depth 10 ) $Results = $Users | ForEach-Object { $MemberOf = ($RoleResults | Where-Object -Property id -EQ $_.id).body.value | Select-Object displayName, id - [PSCustomObject]@{ - id = $_.id - displayName = $_.displayName - userPrincipalName = $_.userPrincipalName - accountEnabled = $_.accountEnabled - jitAdminEnabled = $_.($Schema.id).jitAdminEnabled - jitAdminExpiration = $_.($Schema.id).jitAdminExpiration - jitAdminStartDate = $_.($Schema.id).jitAdminStartDate - jitAdminReason = $_.($Schema.id).jitAdminReason - jitAdminCreatedBy = $_.($Schema.id).jitAdminCreatedBy - memberOf = $MemberOf + $DirectoryRoles = ($RoleResults | Where-Object -Property id -EQ "role_$($_.id)").body.value | Select-Object displayName, id, roleTemplateId + if ((& $FilterJITAdmin ($DirectoryRoles.roleTemplateId))) { + [PSCustomObject]@{ + id = $_.id + displayName = $_.displayName + userPrincipalName = $_.userPrincipalName + accountEnabled = $_.accountEnabled + jitAdminEnabled = $_.($Schema.id).jitAdminEnabled + jitAdminExpiration = $_.($Schema.id).jitAdminExpiration + jitAdminStartDate = $_.($Schema.id).jitAdminStartDate + jitAdminReason = $_.($Schema.id).jitAdminReason + jitAdminCreatedBy = $_.($Schema.id).jitAdminCreatedBy + memberOf = $MemberOf + } } } @@ -102,6 +124,9 @@ Write-Information "Found $($Rows.Count) rows in the cache" foreach ($row in ($Rows | Select-CippAllowedTenantData -TenantProperty 'Tenant')) { $UserObject = $row.JITAdminUser | ConvertFrom-Json + if (-not (& $FilterJITAdmin ($UserObject.roleTemplateIds))) { + continue + } $Results.Add( [PSCustomObject]@{ Tenant = $row.Tenant diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITAdminTemplates.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITAdminTemplates.ps1 index 2f3dabfc8b674..22791252d721a 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITAdminTemplates.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITAdminTemplates.ps1 @@ -32,8 +32,10 @@ function Invoke-ListJITAdminTemplates { try { $row = $_ $data = $row.JSON | ConvertFrom-Json -Depth 100 -ErrorAction Stop - $data | Add-Member -NotePropertyName 'GUID' -NotePropertyValue $row.GUID -Force - $data | Add-Member -NotePropertyName 'RowKey' -NotePropertyValue $row.RowKey -Force + $data | Add-Member -NotePropertyMembers ([ordered]@{ + GUID = $row.GUID + RowKey = $row.RowKey + }) -Force $data } catch { Write-LogMessage -headers $Headers -API $APIName -message "Failed to process JIT Admin template: $($row.RowKey) - $($_.Exception.Message)" -sev 'Warning' diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITAllowedRoles.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITAllowedRoles.ps1 new file mode 100644 index 0000000000000..1a281ef002eb7 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITAllowedRoles.ps1 @@ -0,0 +1,24 @@ +function Invoke-ListJITAllowedRoles { + <# + .FUNCTIONALITY + Entrypoint,AnyTenant + .ROLE + Identity.Role.Read + .DESCRIPTION + Returns the directory roles the calling user is permitted to assign via JIT Admin, based on the + JIT Role Template(s) attached to their CIPP custom role(s). When the caller is unrestricted the + full role catalog is available (Restricted = false). + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $Allowed = Get-CIPPJITAdminAllowedRoles -Headers $Request.Headers + + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = @{ + Restricted = $Allowed.Restricted + AllowedRoleIds = @($Allowed.AllowedRoleIds) + } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITRoleTemplates.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITRoleTemplates.ps1 new file mode 100644 index 0000000000000..8905296544e51 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListJITRoleTemplates.ps1 @@ -0,0 +1,47 @@ +function Invoke-ListJITRoleTemplates { + <# + .FUNCTIONALITY + Entrypoint,AnyTenant + .ROLE + Identity.Role.Read + .DESCRIPTION + Lists JIT Role Templates - named allow-lists of directory roles used to restrict which roles a + CIPP custom role may assign via JIT Admin. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + $Table = Get-CippTable -tablename 'templates' + $Filter = "PartitionKey eq 'JITRoleTemplate'" + + $Templates = (Get-CIPPAzDataTableEntity @Table -Filter $Filter) | ForEach-Object { + try { + $row = $_ + $data = $row.JSON | ConvertFrom-Json -Depth 100 -ErrorAction Stop + $data | Add-Member -NotePropertyMembers ([ordered]@{ + GUID = $row.GUID + RowKey = $row.RowKey + }) -Force + $data + } catch { + Write-LogMessage -headers $Headers -API $APIName -message "Failed to process JIT Role template: $($row.RowKey) - $($_.Exception.Message)" -sev 'Warning' + } + } + + $Templates = $Templates | Sort-Object -Property templateName + + # If a specific GUID is requested, filter to that template + if ($Request.query.GUID) { + $Templates = $Templates | Where-Object -Property GUID -EQ $Request.query.GUID + } + + $Templates = ConvertTo-Json -InputObject @($Templates) -Depth 100 + + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = $Templates + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListNewUserDefaults.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListNewUserDefaults.ps1 index cdcd4c66fb645..68a384011c33a 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListNewUserDefaults.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListNewUserDefaults.ps1 @@ -31,8 +31,10 @@ function Invoke-ListNewUserDefaults { try { $row = $_ $data = $row.JSON | ConvertFrom-Json -Depth 100 -ErrorAction Stop - $data | Add-Member -NotePropertyName 'GUID' -NotePropertyValue $row.GUID -Force - $data | Add-Member -NotePropertyName 'RowKey' -NotePropertyValue $row.RowKey -Force + $data | Add-Member -NotePropertyMembers ([ordered]@{ + GUID = $row.GUID + RowKey = $row.RowKey + }) -Force $data } catch { Write-Warning "Failed to process User Default template: $($row.RowKey) - $($_.Exception.Message)" diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListOffboardingProgress.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListOffboardingProgress.ps1 new file mode 100644 index 0000000000000..e96afac7ff28b --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListOffboardingProgress.ps1 @@ -0,0 +1,33 @@ +function Invoke-ListOffboardingProgress { + <# + .FUNCTIONALITY + Entrypoint,AnyTenant + .ROLE + Identity.User.Read + .SYNOPSIS + Get the live progress of an offboarding job + .DESCRIPTION + Returns the progress rows of an offboarding job started from the wizard: one row per user with + its overall status and the status and message of every step. Same rows as ListAsyncDeployment. + This is a read-only GET, so it carries a read role; an offboarding operator (who holds the + broader user write role) can still follow and re-run their jobs. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + # The DeploymentId handed back by ExecOffboardUser, also stored on each offboarding task + $DeploymentId = $Request.Query.DeploymentId + if (-not $DeploymentId) { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @{ Results = 'DeploymentId is required' } + }) + } + + # Rows carry the tenant they belong to; a tenant-restricted caller only gets rows in scope. + $Rows = @(Get-CIPPAsyncDeployment -JobId $DeploymentId | Select-CippAllowedTenantData -TenantProperty @('TenantFilter', 'Name')) + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = ConvertTo-Json -Depth 10 -InputObject $Rows + }) +} \ No newline at end of file diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUserCounts.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUserCounts.ps1 index 8e840b76a2b7c..b897bf97e809e 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUserCounts.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUserCounts.ps1 @@ -98,11 +98,32 @@ Function Invoke-ListUserCounts { } } + # PIM view of the Global Administrator role: how many of the admins are standing (permanent) + # versus eligible. Only meaningful on Entra ID P2 tenants; elsewhere every GA is permanent. + $PermanentGAs = $GAs + $EligibleGAs = 0 + $PIMCapable = $false + if ($TenantFilter -ne 'AllTenants') { + try { + $GARows = @(Get-CIPPPIMRoleAssignments -TenantFilter $TenantFilter -RoleDefinitionId '62e90394-69f5-4237-9190-012177145e10') + $PIMCapable = [bool](($GARows | Select-Object -First 1).PIMCapable) + if ($PIMCapable) { + $PermanentGAs = @($GARows | Where-Object { $_.AssignmentType -eq 'Permanent' }).Count + $EligibleGAs = @($GARows | Where-Object { $_.AssignmentType -eq 'Eligible' }).Count + } + } catch { + Write-Information "Could not read PIM assignments for the Global Administrator role: $($_.Exception.Message)" + } + } + $Counts = @{ - Users = $Users - LicUsers = $LicUsers - Gas = $GAs - Guests = $Guests + Users = $Users + LicUsers = $LicUsers + Gas = $GAs + PermanentGas = $PermanentGAs + EligibleGas = $EligibleGAs + PIMCapable = $PIMCapable + Guests = $Guests } return ([HttpResponseContext]@{ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUserMailboxDetails.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUserMailboxDetails.ps1 index c28b9d95cc1d4..583d8263442a8 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUserMailboxDetails.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUserMailboxDetails.ps1 @@ -17,6 +17,22 @@ function Invoke-ListUserMailboxDetails { Write-Host "UserID: $UserID" Write-Host "UserMail: $UserMail" + # Archive size and item count are the slow part of the mailbox detail (Get-MailboxStatistics + # -Archive). Set-CIPPDBCacheMailboxes already caches both per mailbox, keyed by the Entra object + # id, so when the reporting DB has a row for this user we read them from there and drop that + # cmdlet from the bulk request; only fall back to the live call when there is no cached row. + $CachedMailbox = $null + try { + $ReportingTable = Get-CIPPTable -TableName 'CippReportingDB' + $CachedEntity = Get-CIPPAzDataTableEntity @ReportingTable -Filter "PartitionKey eq '$TenantFilter' and RowKey eq 'Mailboxes-$UserID'" + if ($CachedEntity.Data) { + $CachedMailbox = $CachedEntity.Data | ConvertFrom-Json + } + } catch { + $CachedMailbox = $null + } + $UseCachedArchiveStats = $null -ne $CachedMailbox + try { $Requests = @( @{ @@ -24,36 +40,39 @@ function Invoke-ListUserMailboxDetails { CmdletName = 'Get-Mailbox' Parameters = @{ Identity = $UserID } } - }, + } @{ CmdletInput = @{ CmdletName = 'Get-MailboxPermission' Parameters = @{ Identity = $UserID } } - }, + } @{ CmdletInput = @{ CmdletName = 'Get-CASMailbox' Parameters = @{ Identity = $UserID } } - }, + } @{ CmdletInput = @{ CmdletName = 'Get-OrganizationConfig' } - }, - @{ - CmdletInput = @{ - CmdletName = 'Get-MailboxStatistics' - Parameters = @{ Identity = $UserID; Archive = $true } + } + # Only fetch archive statistics live when the reporting DB has no cached copy. + if (-not $UseCachedArchiveStats) { + @{ + CmdletInput = @{ + CmdletName = 'Get-MailboxStatistics' + Parameters = @{ Identity = $UserID; Archive = $true } + } } - }, + } @{ CmdletInput = @{ CmdletName = 'Get-BlockedSenderAddress' Parameters = @{ SenderAddress = $UserMail } } - }, + } @{ CmdletInput = @{ CmdletName = 'Get-RecipientPermission' @@ -185,7 +204,6 @@ function Invoke-ListUserMailboxDetails { $ProhibitSendQuotaString = $MailboxDetailedRequest.ProhibitSendQuota -split ' ' $ProhibitSendReceiveQuotaString = $MailboxDetailedRequest.ProhibitSendReceiveQuota -split ' ' $TotalItemSizeString = $StatsRequest.TotalItemSize -split ' ' - $TotalArchiveItemSizeString = (Get-ExoOnlineStringBytes -SizeString $ArchiveSizeRequest.TotalItemSize) / 1GB $ProhibitSendQuota = try { [math]::Round([float]($ProhibitSendQuotaString[0]), 2) } catch { 0 } $ProhibitSendReceiveQuota = try { [math]::Round([float]($ProhibitSendReceiveQuotaString[0]), 2) } catch { 0 } @@ -194,8 +212,15 @@ function Invoke-ListUserMailboxDetails { $TotalItemSize = try { [math]::Round([float]($TotalItemSizeString[0]) / $ItemSizeType, 2) } catch { 0 } if ($ArchiveEnabled -eq $true) { - $TotalArchiveItemSize = try { [math]::Round([float]($TotalArchiveItemSizeString[0]), 2) } catch { 0 } - $TotalArchiveItemCount = try { [math]::Round($ArchiveSizeRequest.ItemCount, 2) } catch { 0 } + if ($UseCachedArchiveStats) { + # The reporting DB stores ArchiveSize as a byte count and ArchiveItemCount as an integer. + $TotalArchiveItemSize = try { [math]::Round([float]$CachedMailbox.ArchiveSize / 1GB, 2) } catch { 0 } + $TotalArchiveItemCount = try { [math]::Round([float]$CachedMailbox.ArchiveItemCount, 2) } catch { 0 } + } else { + $TotalArchiveItemSizeString = (Get-ExoOnlineStringBytes -SizeString $ArchiveSizeRequest.TotalItemSize) / 1GB + $TotalArchiveItemSize = try { [math]::Round([float]($TotalArchiveItemSizeString[0]), 2) } catch { 0 } + $TotalArchiveItemCount = try { [math]::Round($ArchiveSizeRequest.ItemCount, 2) } catch { 0 } + } } # Parse InPlaceHolds to determine hold types if available diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUsers.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUsers.ps1 index a43c639147c95..aecc61f06115c 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUsers.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUsers.ps1 @@ -75,12 +75,14 @@ Function Invoke-ListUsers { } } $UserData | ForEach-Object { - $_ | Add-Member -MemberType NoteProperty -Name 'onPremisesSyncEnabled' -Value ([bool]($_.onPremisesSyncEnabled)) -Force - $_ | Add-Member -MemberType NoteProperty -Name 'username' -Value ($_.userPrincipalName -split '@' | Select-Object -First 1) -Force - $_ | Add-Member -MemberType NoteProperty -Name 'Aliases' -Value ($_.ProxyAddresses -join ', ') -Force $SkuID = $_.AssignedLicenses.skuid - $_ | Add-Member -MemberType NoteProperty -Name 'LicJoined' -Value ((@($SkuID | ForEach-Object { ($ConversionTable | Where-Object guid -EQ ([string]$_) | Select-Object -First 1 -ExpandProperty Product_Display_Name) }) -join ', ')) -Force - $_ | Add-Member -MemberType NoteProperty -Name 'primDomain' -Value @{value = ($_.userPrincipalName -split '@' | Select-Object -Last 1); label = ($_.userPrincipalName -split '@' | Select-Object -Last 1); } -Force + $_ | Add-Member -NotePropertyMembers ([ordered]@{ + onPremisesSyncEnabled = [bool]($_.onPremisesSyncEnabled) + username = ($_.userPrincipalName -split '@' | Select-Object -First 1) + Aliases = ($_.ProxyAddresses -join ', ') + LicJoined = ((@($SkuID | ForEach-Object { ($ConversionTable | Where-Object guid -EQ ([string]$_) | Select-Object -First 1 -ExpandProperty Product_Display_Name) }) -join ', ')) + primDomain = @{value = ($_.userPrincipalName -split '@' | Select-Object -Last 1); label = ($_.userPrincipalName -split '@' | Select-Object -Last 1); } + }) -Force $_ } } elseif ($null -ne (Get-CippRequestContext).AllowedTenants) { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-RemoveJITRoleTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-RemoveJITRoleTemplate.ps1 new file mode 100644 index 0000000000000..89df493bd0c06 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-RemoveJITRoleTemplate.ps1 @@ -0,0 +1,50 @@ +function Invoke-RemoveJITRoleTemplate { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Identity.Role.ReadWrite + .DESCRIPTION + Deletes a JIT Role Template. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + try { + $ID = $Request.Query.ID ?? $Request.Body.ID + + if ([string]::IsNullOrWhiteSpace($ID)) { + throw 'ID is required' + } + + $Table = Get-CippTable -tablename 'templates' + $SafeID = ConvertTo-CIPPODataFilterValue -Value $ID -Type Guid + $Filter = "PartitionKey eq 'JITRoleTemplate' and RowKey eq '$SafeID'" + $Template = Get-CIPPAzDataTableEntity @Table -Filter $Filter + + if ($Template) { + Remove-AzDataTableEntity @Table -Entity $Template + $Result = "Successfully deleted JIT Role Template with ID: $ID" + Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Info' + $StatusCode = [HttpStatusCode]::OK + } else { + $Result = "JIT Role Template with ID $ID not found" + Write-LogMessage -headers $Headers -API $APIName -message $Result -sev 'Warning' + $StatusCode = [HttpStatusCode]::NotFound + } + + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to delete JIT Role Template: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::InternalServerError + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{'Results' = "$Result" } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListGroupUsage.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListGroupUsage.ps1 new file mode 100644 index 0000000000000..7d8c54af49fb9 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListGroupUsage.ps1 @@ -0,0 +1,29 @@ +function Invoke-ListGroupUsage { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Identity.Group.Read + .DESCRIPTION + Compiles where each Entra group is used (Conditional Access, Intune assignments, group-based + licensing, Teams, nested groups, Entra roles, enterprise applications, Exchange transport + rules) from the CIPP reporting database cache. Always served from cache — no live Graph calls. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $TenantFilter = $Request.Query.tenantFilter + + try { + $GraphRequest = Get-CIPPGroupUsageReport -TenantFilter $TenantFilter -ErrorAction Stop + $StatusCode = [HttpStatusCode]::OK + } catch { + $StatusCode = [HttpStatusCode]::InternalServerError + $GraphRequest = $_.Exception.Message + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @($GraphRequest) + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListInactiveAccounts.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListInactiveAccounts.ps1 index cb08149fc8efe..1609511ecb6bd 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListInactiveAccounts.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListInactiveAccounts.ps1 @@ -98,8 +98,9 @@ function Get-InactiveUsersFromDB { } $InactiveUsers = foreach ($User in $Users) { - # Skip disabled users by default - if ($User.accountEnabled -eq $false) { continue } + # Disabled (blocked) users are kept: a dormant, already-blocked account is a cleanup + # candidate, and the accountEnabled field below lets the report show which inactive + # accounts are already blocked and need no further action. # Skip guest users if ($User.userType -eq 'Guest') { continue } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListMFAUsers.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListMFAUsers.ps1 index cf7f46962c0bd..4bf91153098d0 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListMFAUsers.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListMFAUsers.ps1 @@ -5,7 +5,7 @@ function Invoke-ListMFAUsers { .ROLE Identity.User.Read .DESCRIPTION - Lists users and their MFA registration status for a tenant. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants. + Lists users and their MFA registration status for a tenant. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants. When manualPagination is also set, one page is returned per request as { Results, Metadata } with a continuation token in Metadata.nextLink. #> [CmdletBinding()] param($Request, $TriggerMetadata) @@ -13,10 +13,30 @@ function Invoke-ListMFAUsers { $TenantFilter = $Request.Query.tenantFilter # Serve from the reporting database cache instead of live Graph. Much faster, especially for AllTenants. $UseReportDB = $Request.Query.UseReportDB -eq $true + # Return one page per request as { Results, Metadata } with a continuation token in Metadata.nextLink; cached reads only. + $ManualPagination = $Request.Query.manualPagination -and [System.Convert]::ToBoolean($Request.Query.manualPagination) try { # If UseReportDB is specified, retrieve from report database if ($UseReportDB) { try { + if ($ManualPagination) { + # Rows per page, clamped between 250 and 10000. Defaults to 5000. + $PageSize = 5000 + if ($Request.Query.PageSize -as [int]) { + $PageSize = [Math]::Min([Math]::Max([int]$Request.Query.PageSize, 250), 10000) + } + # Continuation token from the previous page's Metadata.nextLink; opaque to callers. + $Page = Get-CIPPMFAStateReport -TenantFilter $TenantFilter -PageSize $PageSize -ContinuationToken $Request.Query.nextLink -ErrorAction Stop + $Metadata = @{} + if ($Page.NextToken) { $Metadata.nextLink = $Page.NextToken } + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = [PSCustomObject]@{ + Results = @($Page.Items) + Metadata = $Metadata + } + }) + } $GraphRequest = Get-CIPPMFAStateReport -TenantFilter $TenantFilter -ErrorAction Stop $StatusCode = [HttpStatusCode]::OK } catch { @@ -46,8 +66,10 @@ function Invoke-ListMFAUsers { UPN = 'Loading data for all tenants. Please check back in a few minutes' } $Batch = $TenantList | ForEach-Object { - $_ | Add-Member -NotePropertyName FunctionName -NotePropertyValue 'ListMFAUsersQueue' - $_ | Add-Member -NotePropertyName QueueId -NotePropertyValue $Queue.RowKey + $_ | Add-Member -NotePropertyMembers ([ordered]@{ + FunctionName = 'ListMFAUsersQueue' + QueueId = $Queue.RowKey + }) $_ } if (($Batch | Measure-Object).Count -gt 0) { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-DLP/Invoke-AddDlpCompliancePolicyTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-DLP/Invoke-AddDlpCompliancePolicyTemplate.ps1 index c45e6e38fdd9d..8c8bf8bd25ebe 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-DLP/Invoke-AddDlpCompliancePolicyTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-DLP/Invoke-AddDlpCompliancePolicyTemplate.ps1 @@ -87,12 +87,12 @@ Function Invoke-AddDlpCompliancePolicyTemplate { PartitionKey = 'DlpCompliancePolicyTemplate' } $Result = "Successfully created DLP Compliance Policy Template: $($Ordered['name']) with GUID $GUID" - Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Debug' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ $Result = "Failed to create DLP Compliance Policy Template: $($ErrorMessage.NormalizedError)" - Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' -LogData $ErrorMessage + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' -LogData $ErrorMessage $StatusCode = [HttpStatusCode]::InternalServerError } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-Retention/Invoke-AddRetentionCompliancePolicyTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-Retention/Invoke-AddRetentionCompliancePolicyTemplate.ps1 index 9c3830cebc1ee..43b3baa48ad70 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-Retention/Invoke-AddRetentionCompliancePolicyTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-Retention/Invoke-AddRetentionCompliancePolicyTemplate.ps1 @@ -124,12 +124,12 @@ Function Invoke-AddRetentionCompliancePolicyTemplate { PartitionKey = 'RetentionCompliancePolicyTemplate' } $Result = "Successfully created Retention Compliance Policy Template: $($Ordered['name']) with GUID $GUID" - Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Debug' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ $Result = "Failed to create Retention Compliance Policy Template: $($ErrorMessage.NormalizedError)" - Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' -LogData $ErrorMessage + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' -LogData $ErrorMessage $StatusCode = [HttpStatusCode]::InternalServerError } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-Retention/Invoke-ListRetentionCompliancePolicy.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-Retention/Invoke-ListRetentionCompliancePolicy.ps1 index c8aa16e242752..d47cbcc8eca6c 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-Retention/Invoke-ListRetentionCompliancePolicy.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-Retention/Invoke-ListRetentionCompliancePolicy.ps1 @@ -11,12 +11,59 @@ Function Invoke-ListRetentionCompliancePolicy { param($Request, $TriggerMetadata) $TenantFilter = $Request.Query.tenantFilter + # Get-RetentionCompliancePolicy only populates the per-location properties (ExchangeLocation, ...) when + # -DistributionDetail is set. Without it the flat 'Workload' string it returns is a fixed superset + # ('Exchange, SharePoint, OneDriveForBusiness, Skype, ModernGroup, DynamicScope') that does not reflect + # the policy's real scope, so we derive the scope from the populated location fields instead. + $LocationLabels = [ordered]@{ + ExchangeLocation = 'Exchange' + SharePointLocation = 'SharePoint' + OneDriveLocation = 'OneDrive' + ModernGroupLocation = 'Microsoft 365 Groups' + TeamsChatLocation = 'Teams Chats' + TeamsChannelLocation = 'Teams Channels' + SkypeLocation = 'Skype' + PublicFolderLocation = 'Public Folders' + AdaptiveScopeLocation = 'Adaptive Scope' + } + try { - $Policies = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-RetentionCompliancePolicy' -Compliance -AsApp | Select-Object * -ExcludeProperty *odata*, *data.type* + # Teams-scoped retention policies are not returned by the default call - they require -TeamsPolicyOnly. + # Fetch both sets (with distribution detail for the real location data) and merge, de-duped by Guid. + $Policies = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-RetentionCompliancePolicy' -cmdParams @{ DistributionDetail = $true } -Compliance -AsApp | Select-Object * -ExcludeProperty *odata*, *data.type* + $TeamsPolicies = try { + New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-RetentionCompliancePolicy' -cmdParams @{ DistributionDetail = $true; TeamsPolicyOnly = $true } -Compliance -AsApp | Select-Object * -ExcludeProperty *odata*, *data.type* + } catch { @() } + + $SeenGuids = [System.Collections.Generic.HashSet[string]]::new() + $AllPolicies = @(@($Policies) + @($TeamsPolicies) | Where-Object { $_ -and $SeenGuids.Add([string]$_.Guid) }) + $Rules = New-ExoRequest -tenantid $TenantFilter -cmdlet 'Get-RetentionComplianceRule' -Compliance -AsApp | Select-Object * -ExcludeProperty *odata*, *data.type* - $GraphRequest = $Policies | Select-Object *, - @{l = 'AssociatedRules'; e = { $name = $_.Name; @($Rules | Where-Object { $_.Policy -eq $name }) } }, - @{l = 'RuleCount'; e = { $name = $_.Name; (@($Rules | Where-Object { $_.Policy -eq $name })).Count } } + + $GraphRequest = foreach ($Policy in $AllPolicies) { + # Get-RetentionComplianceRule reports its parent policy via the policy Guid, not the policy Name. + $PolicyRules = @($Rules | Where-Object { $_.Policy -eq $Policy.Guid }) + $PrimaryRule = $PolicyRules | Select-Object -First 1 + + # Real scope is the set of location fields that actually carry a value. + $Locations = foreach ($Field in $LocationLabels.Keys) { + if (@($Policy.$Field).Where({ $_ }).Count -gt 0) { $LocationLabels[$Field] } + } + + $RetentionDuration = if ($PrimaryRule) { + if ([string]::IsNullOrEmpty([string]$PrimaryRule.RetentionDuration) -or $PrimaryRule.RetentionDuration -eq 'Unlimited') { 'Unlimited' } else { $PrimaryRule.RetentionDuration } + } else { $null } + + # Note: Get-RetentionCompliancePolicy -DistributionDetail returns its own (empty) 'Locations' + # property, so the derived scope summary is exposed as 'ScopedLocations' to avoid the collision + # (Select-Object silently drops a computed property whose name already exists on the object). + $Policy | Select-Object *, + @{l = 'AssociatedRules'; e = { $PolicyRules } }, + @{l = 'RuleCount'; e = { $PolicyRules.Count } }, + @{l = 'ScopedLocations'; e = { @($Locations) -join ', ' } }, + @{l = 'RetentionAction'; e = { $PrimaryRule.RetentionComplianceAction } }, + @{l = 'RetentionDuration'; e = { $RetentionDuration } } + } $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-SensitivityLabel/Invoke-AddSensitivityLabelTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-SensitivityLabel/Invoke-AddSensitivityLabelTemplate.ps1 index b11d2771ea8fe..fa126d8aa740b 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-SensitivityLabel/Invoke-AddSensitivityLabelTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Compliance-SensitivityLabel/Invoke-AddSensitivityLabelTemplate.ps1 @@ -54,12 +54,12 @@ Function Invoke-AddSensitivityLabelTemplate { PartitionKey = 'SensitivityLabelTemplate' } $Result = "Successfully created Sensitivity Label Template: $DisplayName with GUID $GUID" - Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Debug' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ $Result = "Failed to create Sensitivity Label Template: $($ErrorMessage.NormalizedError)" - Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' -LogData $ErrorMessage + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' -LogData $ErrorMessage $StatusCode = [HttpStatusCode]::InternalServerError } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Incidents/Invoke-ExecMdoAlertsList.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Incidents/Invoke-ExecMdoAlertsList.ps1 index a6ece00125709..636336f3f8893 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Incidents/Invoke-ExecMdoAlertsList.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Incidents/Invoke-ExecMdoAlertsList.ps1 @@ -5,7 +5,7 @@ function Invoke-ExecMDOAlertsList { .ROLE Security.Alert.Read .DESCRIPTION - Lists Microsoft Defender for Office 365 alerts for a tenant, filtered to that service source. tenantFilter=AllTenants reads the cached alert table rather than querying each tenant live. + Lists Microsoft Defender for Office 365 and Defender for Endpoint alerts for a tenant, filtered to those service sources. tenantFilter=AllTenants reads the cached alert table rather than querying each tenant live. #> [CmdletBinding()] param($Request, $TriggerMetadata) @@ -15,7 +15,7 @@ function Invoke-ExecMDOAlertsList { try { $GraphRequest = if ($TenantFilter -ne 'AllTenants') { # Single tenant functionality - New-GraphGetRequest -uri "https://graph.microsoft.com/beta/security/alerts_v2?`$filter=serviceSource eq 'microsoftDefenderForOffice365'" -tenantid $TenantFilter + New-GraphGetRequest -uri "https://graph.microsoft.com/beta/security/alerts_v2?`$filter=serviceSource eq 'microsoftDefenderForOffice365' or serviceSource eq 'microsoftDefenderForEndpoint'" -tenantid $TenantFilter } else { # AllTenants functionality $Table = Get-CIPPTable -TableName cachealertsandincidents diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Safe-Links-Policy/Invoke-AddSafeLinksPolicyTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Safe-Links-Policy/Invoke-AddSafeLinksPolicyTemplate.ps1 index 4d3c4b5cc2602..79c42cce7cec4 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Safe-Links-Policy/Invoke-AddSafeLinksPolicyTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Safe-Links-Policy/Invoke-AddSafeLinksPolicyTemplate.ps1 @@ -17,8 +17,9 @@ Function Invoke-AddSafeLinksPolicyTemplate { try { $GUID = (New-Guid).GUID - # Validate required fields - if ([string]::IsNullOrEmpty($Request.body.Name)) { + # Validate required fields. The "create template from policy" row action posts the policy + # row, which carries Name/PolicyName but no TemplateName. + if ([string]::IsNullOrEmpty($Request.body.Name) -and [string]::IsNullOrEmpty($Request.body.TemplateName)) { throw "Template name is required but was not provided" } @@ -29,8 +30,9 @@ Function Invoke-AddSafeLinksPolicyTemplate { # Create a new ordered hashtable to store selected properties $policyObject = [ordered]@{} - # Set name and comments - prioritize template-specific fields - $policyObject["TemplateName"] = $Request.body.TemplateName + # Set name and comments - prioritize template-specific fields, falling back to the policy + # name so a template made from a policy is not listed with a blank name. + $policyObject["TemplateName"] = if (-not [string]::IsNullOrEmpty($Request.body.TemplateName)) { $Request.body.TemplateName } else { $Request.body.PolicyName } $policyObject["TemplateDescription"] = $Request.body.TemplateDescription # For templates, if no specific policy description is provided, use template description as default diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Safe-Links-Policy/Invoke-ExecNewSafeLinksPolicy.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Safe-Links-Policy/Invoke-ExecNewSafeLinksPolicy.ps1 index bd731bd8e810f..5830edb409bcc 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Safe-Links-Policy/Invoke-ExecNewSafeLinksPolicy.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Security/Safe-Links-Policy/Invoke-ExecNewSafeLinksPolicy.ps1 @@ -17,6 +17,16 @@ function Invoke-ExecNewSafeLinksPolicy { # Interact with query parameters or the body of the request. $TenantFilter = $Request.Query.tenantFilter ?? $Request.Body.tenantFilter + # Exchange cmdlets need one tenant. With All Tenants selected the request used to fall through + # the authorisation check, skip the cmdlets and still report success, so the policy was never + # created anywhere while the logbook said it was. + if ([string]::IsNullOrWhiteSpace($TenantFilter) -or $TenantFilter -eq 'AllTenants') { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @{ Results = 'Select a single tenant before creating a Safe Links policy. Safe Links policies cannot be created with All Tenants selected.' } + }) + } + # Extract policy settings from body $PolicyName = $Request.Body.PolicyName $EnableSafeLinksForEmail = $Request.Body.EnableSafeLinksForEmail diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecBulkRemoveSharingLinks.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecBulkRemoveSharingLinks.ps1 index a4608323d50ab..ccdf6a0440293 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecBulkRemoveSharingLinks.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecBulkRemoveSharingLinks.ps1 @@ -54,27 +54,33 @@ function Invoke-ExecBulkRemoveSharingLinks { $Revoked = [System.Collections.Generic.List[string]]::new() $Failed = [System.Collections.Generic.List[string]]::new() - foreach ($Link in $Targets) { - try { - $null = New-GraphPostRequest -uri "https://graph.microsoft.com/v1.0/drives/$($Link.driveId)/items/$($Link.itemId)/permissions/$($Link.permissionId)" -tenantid $TenantFilter -type DELETE -asapp $true - $Revoked.Add("$($Link.fileName) ($($Link.classification))") + + # Batch the DELETEs through Graph $batch (New-GraphBulkRequest, ~20 per request) instead of + # one sequential call per link - a heavily-shared site can have hundreds/thousands. + $BulkRequests = @(for ($i = 0; $i -lt $Targets.Count; $i++) { + $Link = $Targets[$i] + @{ + id = "$i" + method = 'DELETE' + url = "drives/$($Link.driveId)/items/$($Link.itemId)/permissions/$($Link.permissionId)" + } + }) + $Responses = @(New-GraphBulkRequest -tenantid $TenantFilter -Requests $BulkRequests -asapp $true -Version 'v1.0') + + foreach ($Response in $Responses) { + $Link = $Targets[[int]$Response.id] + $Status = [int]$Response.status + # 2xx = revoked; 404 = the link was already gone (treat as revoked). Either way, clean + # the reporting cache row so it does not linger. + if (($Status -ge 200 -and $Status -lt 300) -or $Status -eq 404) { + $Revoked.Add($(if ($Status -eq 404) { "$($Link.fileName) (already removed)" } else { "$($Link.fileName) ($($Link.classification))" })) if ($Link.id) { - try { - Remove-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSharingLinks' -ItemId $Link.id - } catch { + try { Remove-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSharingLinks' -ItemId $Link.id } catch { Write-Information "Revoked link but could not update reporting cache row $($Link.id): $($_.Exception.Message)" } } - } catch { - # A 404 means the link was already gone; treat as revoked and clean the cache row. - if ($_.Exception.Message -match 'itemNotFound|404') { - $Revoked.Add("$($Link.fileName) (already removed)") - if ($Link.id) { - try { Remove-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSharingLinks' -ItemId $Link.id } catch {} - } - } else { - $Failed.Add("$($Link.fileName): $($_.Exception.Message)") - } + } else { + $Failed.Add("$($Link.fileName): $($Response.body.error.message ?? "status $Status")") } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecEmptySiteRecycleBin.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecEmptySiteRecycleBin.ps1 new file mode 100644 index 0000000000000..55d9a6140b6b2 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecEmptySiteRecycleBin.ps1 @@ -0,0 +1,134 @@ +function Invoke-ExecEmptySiteRecycleBin { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Sharepoint.SiteRecycleBin.ReadWrite + .DESCRIPTION + Permanently empty a site recycle bin (first stage, second stage, or both). + Item ids are used only server-side; the response never includes file names. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $TenantFilter = $Request.Body.tenantFilter ?? $Request.Body.TenantFilter + $SiteUrl = $Request.Body.SiteUrl + $Stage = [string]($Request.Body.Stage ?? 'Both') + + try { + if ([string]::IsNullOrWhiteSpace($TenantFilter)) { throw 'tenantFilter is required.' } + if ([string]::IsNullOrWhiteSpace($SiteUrl)) { throw 'SiteUrl is required.' } + if ($Stage -notin @('First', 'Second', 'Both')) { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @{ Results = "Invalid Stage '$Stage'. Valid values: First, Second, Both." } + }) + } + + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $Scope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri + $DeletedCount = 0 + $Errors = [System.Collections.Generic.List[string]]::new() + + function Invoke-CIPPRecycleDeleteAll { + param([string]$Uri) + $null = New-GraphPostRequest -uri $Uri -tenantid $TenantFilter -scope $Scope -type POST -body '{}' -contentType 'application/json;odata=nometadata' -AddedHeaders $JsonAccept -UseCertificate -AsApp $true + } + + function Invoke-CIPPRecycleDeleteByIdsBatch { + param( + [ValidateSet('First', 'Second')] + [string]$TargetStage + ) + $StateFilter = if ($TargetStage -eq 'Second') { 2 } else { 1 } + $BatchDeleted = 0 + $NextUri = "$BaseUri/site/RecycleBin?`$select=Id,ItemState&`$top=100&`$orderby=DeletedDate desc" + $Guard = 0 + while ($NextUri -and $Guard -lt 200) { + $Guard++ + $Page = New-GraphGetRequest -uri $NextUri -tenantid $TenantFilter -scope $Scope -extraHeaders $JsonAccept -UseCertificate -AsApp $true -noPagination $true -SkipValueExtraction + $Items = @($Page.value) + $NextLink = $Page.'@odata.nextLink' + $Ids = @( + foreach ($Item in $Items) { + $State = 0 + try { $State = [int]$Item.ItemState } catch { $State = 0 } + if ($State -eq $StateFilter -and $Item.Id) { [string]$Item.Id } + } + ) + if ($Ids.Count -eq 0) { + if ([string]::IsNullOrWhiteSpace($NextLink)) { break } + $NextUri = $NextLink + continue + } + for ($i = 0; $i -lt $Ids.Count; $i += 25) { + $Chunk = @($Ids[$i..([Math]::Min($i + 24, $Ids.Count - 1))]) + $DeleteBody = ConvertTo-Json -Compress -Depth 5 -InputObject @{ ids = @($Chunk) } + $null = New-GraphPostRequest -uri "$BaseUri/site/RecycleBin/DeleteByIds" -tenantid $TenantFilter -scope $Scope -type POST -body $DeleteBody -contentType 'application/json;odata=nometadata' -AddedHeaders $JsonAccept -UseCertificate -AsApp $true + $BatchDeleted += $Chunk.Count + } + # After deletes, restart from the first page so we do not skip items when the list shifts. + $NextUri = "$BaseUri/site/RecycleBin?`$select=Id,ItemState&`$top=100&`$orderby=DeletedDate desc" + } + return $BatchDeleted + } + + if ($Stage -in @('First', 'Both')) { + try { + Invoke-CIPPRecycleDeleteAll -Uri "$BaseUri/web/RecycleBin/deleteAll()" + $DeletedCount += 1 # deleteAll does not return a count; mark attempt + } catch { + try { + $DeletedCount += Invoke-CIPPRecycleDeleteByIdsBatch -TargetStage First + } catch { + $Errors.Add("First stage: $($_.Exception.Message)") + } + } + } + + if ($Stage -in @('Second', 'Both')) { + try { + Invoke-CIPPRecycleDeleteAll -Uri "$BaseUri/site/RecycleBin/deleteAllSecondStageItems" + $DeletedCount += 1 + } catch { + try { + Invoke-CIPPRecycleDeleteAll -Uri "$BaseUri/site/RecycleBin/deleteAll()" + $DeletedCount += 1 + } catch { + try { + $DeletedCount += Invoke-CIPPRecycleDeleteByIdsBatch -TargetStage Second + } catch { + $Errors.Add("Second stage: $($_.Exception.Message)") + } + } + } + } + + if ($Errors.Count -gt 0 -and $DeletedCount -eq 0) { + throw ($Errors -join '; ') + } + + $Results = "Emptied recycle bin ($Stage) for $SiteUrl." + if ($Errors.Count -gt 0) { + $Results += " Partial warnings: $($Errors -join '; ')" + } + Write-LogMessage -Headers $Headers -API $APIName -tenant $TenantFilter -message $Results -sev Info + $StatusCode = [HttpStatusCode]::OK + $Body = @{ Results = $Results; deletedAttempts = $DeletedCount } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Results = "Failed to empty recycle bin on $($SiteUrl): $($ErrorMessage.NormalizedError)" + Write-LogMessage -Headers $Headers -API $APIName -tenant $TenantFilter -message $Results -sev Error -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::BadRequest + $Body = @{ Results = $Results } + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = $Body + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecReactivateSite.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecReactivateSite.ps1 new file mode 100644 index 0000000000000..270e63b8409e2 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecReactivateSite.ps1 @@ -0,0 +1,81 @@ +function Invoke-ExecReactivateSite { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Sharepoint.Site.ReadWrite + .SYNOPSIS + Reactivate an archived SharePoint or OneDrive site. + .DESCRIPTION + Reactivates (unarchives) a Microsoft 365 Archive site through the Graph beta + site: unarchive endpoint (POST /beta/sites/{site-id}/unarchive). Primarily used to + reactivate archived OneDrive accounts before granting permissions to them. + Reactivation is asynchronous (can take up to 24 hours) and, for fully-archived + accounts, may incur Microsoft 365 Archive charges and require Unlicensed OneDrive + billing to be enabled on the tenant. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + # Tenant the archived site belongs to. + $TenantFilter = $Request.Body.tenantFilter + # Full web URL of the archived site / OneDrive (the row's webUrl). + $SiteUrl = $Request.Body.SiteUrl + # Site-collection GUID (the row's siteId / sharepointIds.siteId). Used to build the Graph + # composite site id without touching the locked, archived site. + $SiteId = $Request.Body.SiteId + # Web GUID (the row's webId / sharepointIds.webId). + $WebId = $Request.Body.WebId + + try { + if ([string]::IsNullOrWhiteSpace($TenantFilter)) { throw 'tenantFilter is required.' } + if ([string]::IsNullOrWhiteSpace($SiteUrl)) { throw 'SiteUrl is required.' } + + $SiteHost = ([System.Uri]$SiteUrl).Host + if ([string]::IsNullOrWhiteSpace($SiteHost)) { throw "SiteUrl '$SiteUrl' is not a valid URL." } + + # Prefer building the Graph composite id ({host},{siteCollectionId},{webId}) from the + # ids the site listing already carries: an archived site is locked, so avoid any lookup + # against it. Fall back to resolving the id by path only when those ids are absent. + if (-not [string]::IsNullOrWhiteSpace($SiteId) -and -not [string]::IsNullOrWhiteSpace($WebId)) { + $GraphSiteId = '{0},{1},{2}' -f $SiteHost, $SiteId, $WebId + } else { + $RelativePath = ([System.Uri]$SiteUrl).AbsolutePath.TrimStart('/') + $Resolved = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/sites/$($SiteHost):/$($RelativePath)?`$select=id" -tenantid $TenantFilter -AsApp $true + $GraphSiteId = $Resolved.id + } + + if ([string]::IsNullOrWhiteSpace($GraphSiteId)) { + throw "Could not determine the site id for $SiteUrl." + } + + # site: unarchive is beta-only. App-only auth is used deliberately: the SAM app holds the + # Sites.FullControl.All application role, which this endpoint accepts, so no per-admin + # SharePoint-admin role is required. A 202 with an empty body (Invoke-CIPPRestMethod + # returns $null) is the success signal - no exception means reactivation was accepted. + $null = New-GraphPOSTRequest -uri "https://graph.microsoft.com/beta/sites/$GraphSiteId/unarchive" -tenantid $TenantFilter -AsApp $true -type POST -body '' + + $Results = "Reactivation started for $SiteUrl. It can take up to 24 hours to complete. If the account was fully archived, this may incur Microsoft 365 Archive charges and requires Unlicensed OneDrive billing to be enabled on the tenant." + Write-LogMessage -Headers $Headers -API $APIName -tenant $TenantFilter -message $Results -sev Info + $StatusCode = [HttpStatusCode]::OK + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Results = "Failed to reactivate $($SiteUrl): $($ErrorMessage.NormalizedError)" + # A 423 (Locked) / "blocked" response is a known limitation of the beta unarchive endpoint + # for archived sites, and a billing failure means Unlicensed OneDrive billing is off. In + # both cases the reliable fallback is the SharePoint admin center. + if ($ErrorMessage.NormalizedError -match '423|[Ll]ocked|blocked|billing') { + $Results += ' Reactivation may need Unlicensed OneDrive billing enabled on the tenant, or the site cannot be reactivated via the API right now - reactivate it from the SharePoint admin center.' + } + Write-LogMessage -Headers $Headers -API $APIName -tenant $TenantFilter -message $Results -sev Error -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::BadRequest + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{ 'Results' = $Results } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecRestoreRecycleBinItems.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecRestoreRecycleBinItems.ps1 index cfad4b5705659..cc8eb40a4efb5 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecRestoreRecycleBinItems.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecRestoreRecycleBinItems.ps1 @@ -22,10 +22,10 @@ function Invoke-ExecRestoreRecycleBinItems { if (-not $SiteUrl) { throw 'SiteUrl is required.' } if ($Ids.Count -eq 0) { throw 'No recycle bin items were selected.' } - $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter - $Scope = "$($SharePointInfo.SharePointUrl)/.default" - $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $Scope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri $RestoreBody = ConvertTo-Json -Compress -Depth 5 -InputObject @{ ids = @($Ids) } try { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSetSharePointMember.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSetSharePointMember.ps1 index fdffad7a36c74..3a65a68860458 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSetSharePointMember.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSetSharePointMember.ps1 @@ -75,10 +75,10 @@ function Invoke-ExecSetSharePointMember { $SiteUrl = $Request.Body.URL if (-not $SiteUrl) { throw 'No site URL was provided for this site.' } - $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter - $Scope = "$($SharePointInfo.SharePointUrl)/.default" - $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $Scope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri $RoleGroup = $AssociatedGroups[[string]$Role] $RoleLabel = ([string]$Role).ToLower().TrimEnd('s') $Article = if ($RoleLabel -match '^[aeiou]') { 'an' } else { 'a' } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSharePointTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSharePointTemplate.ps1 index fbb70900fda51..3a8c38165e330 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSharePointTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSharePointTemplate.ps1 @@ -124,8 +124,10 @@ function Invoke-ExecSharePointTemplate { $Body = $Templates | ForEach-Object { $TemplateData = $_.JSON | ConvertFrom-Json $OutputObject = $TemplateData | Select-Object -Property * - $OutputObject | Add-Member -NotePropertyName 'TemplateId' -NotePropertyValue $_.RowKey -Force - $OutputObject | Add-Member -NotePropertyName 'Timestamp' -NotePropertyValue $_.Timestamp.DateTime.ToString('yyyy-MM-ddTHH:mm:ssZ') -Force + $OutputObject | Add-Member -NotePropertyMembers ([ordered]@{ + TemplateId = $_.RowKey + Timestamp = $_.Timestamp.DateTime.ToString('yyyy-MM-ddTHH:mm:ssZ') + }) -Force return $OutputObject } } @@ -198,8 +200,10 @@ function Invoke-ExecSharePointTemplate { $Body = $Templates | ForEach-Object { $TemplateData = $_.JSON | ConvertFrom-Json $OutputObject = $TemplateData | Select-Object -Property * - $OutputObject | Add-Member -NotePropertyName 'TemplateId' -NotePropertyValue $_.RowKey -Force - $OutputObject | Add-Member -NotePropertyName 'Timestamp' -NotePropertyValue $_.Timestamp.DateTime.ToString('yyyy-MM-ddTHH:mm:ssZ') -Force + $OutputObject | Add-Member -NotePropertyMembers ([ordered]@{ + TemplateId = $_.RowKey + Timestamp = $_.Timestamp.DateTime.ToString('yyyy-MM-ddTHH:mm:ssZ') + }) -Force return $OutputObject } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSiteBrowserLibraryCopy.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSiteBrowserLibraryCopy.ps1 new file mode 100644 index 0000000000000..3d388181849e4 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSiteBrowserLibraryCopy.ps1 @@ -0,0 +1,80 @@ +function Invoke-ExecSiteBrowserLibraryCopy { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Sharepoint.Site.ReadWrite + .DESCRIPTION + Starts or preflights a SharePoint document library content copy (CreateCopyJobs + MoveButKeepSource). + Actions: PreflightLibraryCopy, StartLibraryCopy. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $TenantFilter = $Request.Body.tenantFilter ?? $Request.Body.TenantFilter + $Action = $Request.Body.Action ?? $Request.Query.Action + $StatusCode = [HttpStatusCode]::OK + + try { + if ([string]::IsNullOrWhiteSpace($TenantFilter)) { throw 'tenantFilter is required.' } + if ([string]::IsNullOrWhiteSpace($Action)) { throw 'Action is required.' } + if ($Action -notin @('PreflightLibraryCopy', 'StartLibraryCopy')) { + throw "Unknown Action '$Action'. Supported: PreflightLibraryCopy, StartLibraryCopy." + } + + $User = try { + [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($Headers.'x-ms-client-principal')) | ConvertFrom-Json + } catch { $null } + $StartedBy = $User.userDetails ?? $Headers.'x-ms-client-principal-name' ?? 'CIPP-API' + + $ConflictRaw = $Request.Body.NameConflictBehavior ?? $Request.Body.nameConflictBehavior ?? 'Replace' + $NameConflictBehavior = switch ([string]$ConflictRaw) { + 'Fail' { 0 } + 'Replace' { 1 } + default { [int]$ConflictRaw } + } + + $Params = @{ + Mode = $Action + TenantFilter = $TenantFilter + SourceSiteId = [string]($Request.Body.SourceSiteId ?? $Request.Body.sourceSiteId) + SourceSiteUrl = [string]($Request.Body.SourceSiteUrl ?? $Request.Body.sourceSiteUrl) + SourceListId = [string]($Request.Body.SourceListId ?? $Request.Body.sourceListId) + SourceSiteName = [string]($Request.Body.SourceSiteName ?? $Request.Body.sourceSiteName) + SourceLibraryName = [string]($Request.Body.SourceLibraryName ?? $Request.Body.sourceLibraryName) + DestSiteId = [string]($Request.Body.DestSiteId ?? $Request.Body.destSiteId) + DestSiteUrl = [string]($Request.Body.DestSiteUrl ?? $Request.Body.destSiteUrl) + DestListId = [string]($Request.Body.DestListId ?? $Request.Body.destListId) + DestSiteName = [string]($Request.Body.DestSiteName ?? $Request.Body.destSiteName) + DestLibraryName = [string]($Request.Body.DestLibraryName ?? $Request.Body.destLibraryName) + NameConflictBehavior = $NameConflictBehavior + StartedBy = $StartedBy + Headers = $Headers + APIName = $APIName + } + + if ([string]::IsNullOrWhiteSpace($Params.SourceListId)) { throw 'SourceListId is required.' } + if ([string]::IsNullOrWhiteSpace($Params.DestListId)) { throw 'DestListId is required.' } + if ([string]::IsNullOrWhiteSpace($Params.SourceSiteId) -and [string]::IsNullOrWhiteSpace($Params.SourceSiteUrl)) { + throw 'SourceSiteId or SourceSiteUrl is required.' + } + if ([string]::IsNullOrWhiteSpace($Params.DestSiteId) -and [string]::IsNullOrWhiteSpace($Params.DestSiteUrl)) { + throw 'DestSiteId or DestSiteUrl is required.' + } + + $Result = Start-CIPPSharePointLibraryCopy @Params + Write-LogMessage -Headers $Headers -API $APIName -tenant $TenantFilter -message "Library copy action $Action completed." -sev Info + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to run Action '$Action'. Error: $($ErrorMessage.NormalizedError)" + Write-LogMessage -Headers $Headers -API $APIName -tenant $TenantFilter -message $Result -sev Error -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::BadRequest + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{ Results = $Result } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSiteBrowserPermissions.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSiteBrowserPermissions.ps1 index b6834377d59a4..e609e06f67356 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSiteBrowserPermissions.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSiteBrowserPermissions.ps1 @@ -234,10 +234,10 @@ function Invoke-ExecSiteBrowserPermissions { $GroupId = $Request.Body.GroupId if ([string]::IsNullOrWhiteSpace($GroupId)) { throw 'GroupId is required.' } - $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter - $Scope = "$($SharePointInfo.SharePointUrl)/.default" - $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $Scope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri $Principals = ConvertTo-BrowserPermissionPrincipals ` -PrincipalId $Request.Body.PrincipalId ` diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSharePointTemplates.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSharePointTemplates.ps1 index ba1088f590efb..1e7b3f9619d8b 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSharePointTemplates.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSharePointTemplates.ps1 @@ -40,8 +40,10 @@ function Invoke-ListSharePointTemplates { # Surface scalar counts so the list can show/sort them without inspecting the nested arrays. $SiteTemplates = @($TemplateData.siteTemplates | Where-Object { $_ }) $LibraryCount = ($SiteTemplates | ForEach-Object { @($_.libraries | Where-Object { $_ }).Count } | Measure-Object -Sum).Sum - $TemplateObject | Add-Member -NotePropertyName 'SiteTemplateCount' -NotePropertyValue ([int]$SiteTemplates.Count) -Force - $TemplateObject | Add-Member -NotePropertyName 'LibraryCount' -NotePropertyValue ([int]$LibraryCount) -Force + $TemplateObject | Add-Member -NotePropertyMembers ([ordered]@{ + SiteTemplateCount = ([int]$SiteTemplates.Count) + LibraryCount = ([int]$LibraryCount) + }) -Force return $TemplateObject } catch { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSharepointSettings.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSharepointSettings.ps1 index e7db82d04897d..6f0538c5b4013 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSharepointSettings.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSharepointSettings.ps1 @@ -9,16 +9,13 @@ Function Invoke-ListSharepointSettings { #> [CmdletBinding()] param($Request, $TriggerMetadata) - # XXX - Seems to be an unused endpoint? -Bobby - - # Interact with query parameters or the body of the request. $Tenant = $Request.Query.tenantFilter - $Request = New-GraphGetRequest -tenantid $Tenant -Uri 'https://graph.microsoft.com/beta/admin/sharepoint/settings' + $SharePointSettings = New-GraphGetRequest -tenantid $Tenant -Uri 'https://graph.microsoft.com/beta/admin/sharepoint/settings' -AsApp $true return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK - Body = @($Request) + Body = @($SharePointSettings) }) } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteActivity.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteActivity.ps1 index a57482965dce8..a32ad761e491c 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteActivity.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteActivity.ps1 @@ -69,8 +69,10 @@ function Invoke-ListSiteActivity { if ($RowSiteId -ne $LookupSiteId) { continue } } - $Row | Add-Member -NotePropertyName 'Tenant' -NotePropertyValue $Tenant -Force - $Row | Add-Member -NotePropertyName 'CacheTimestamp' -NotePropertyValue $CacheTimestamp -Force + $Row | Add-Member -NotePropertyMembers ([ordered]@{ + Tenant = $Tenant + CacheTimestamp = $CacheTimestamp + }) -Force [void]$AllResults.Add($Row) } } catch { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteBrowser.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteBrowser.ps1 index 29538fe0213dc..725eb4f53c378 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteBrowser.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteBrowser.ps1 @@ -27,22 +27,6 @@ function Invoke-ListSiteBrowser { }) } - function ConvertTo-StorageUsedBytes { - param($Raw) - if ($null -eq $Raw -or $Raw -eq '') { return $null } - $Clean = ([string]$Raw).Replace(',', '').Trim() - if ($Clean -eq '') { return $null } - try { return [int64][double]$Clean } catch { return $null } - } - - function ConvertTo-NullableInt64 { - param($Raw) - if ($null -eq $Raw -or $Raw -eq '') { return $null } - $Clean = ([string]$Raw).Replace(',', '').Trim() - if ($Clean -eq '') { return $null } - try { return [int64][double]$Clean } catch { return $null } - } - function ConvertTo-SiteTypeLabel { param( [string]$Template, @@ -178,8 +162,6 @@ function Invoke-ListSiteBrowser { } $RootWebTemplate = [string]$Row.TemplateName - $StorageRaw = if ($null -ne $Row.'StorageUsed.') { $Row.'StorageUsed.' } else { $Row.StorageUsed } - $FilesRaw = if ($null -ne $Row.'NumOfFiles.') { $Row.'NumOfFiles.' } else { $Row.NumOfFiles } $Results.Add([PSCustomObject]@{ type = 'site' @@ -191,10 +173,10 @@ function Invoke-ListSiteBrowser { description = $GraphSite.description webUrl = $(if ($RowUrl) { $RowUrl } else { $GraphSite.webUrl }) createdDateTime = $(if ($Row.TimeCreated) { $Row.TimeCreated } else { $GraphSite.createdDateTime }) - storageUsedInBytes = ConvertTo-StorageUsedBytes -Raw $StorageRaw + storageUsedInBytes = $Row.StorageUsed siteType = ConvertTo-SiteTypeLabel -Template $RootWebTemplate -ItemType 'site' rootWebTemplate = $RootWebTemplate - fileCount = ConvertTo-NullableInt64 -Raw $FilesRaw + fileCount = $Row.NumOfFiles }) } @@ -221,7 +203,7 @@ function Invoke-ListSiteBrowser { if ([string]::IsNullOrWhiteSpace($SiteId)) { $SiteId = $SiteMeta.id } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $BaseUri = (Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl -SharePointInfo $SharePointInfo).BaseUri $SiteInfo = [PSCustomObject]@{ id = $SiteId webUrl = $SiteUrl @@ -234,27 +216,44 @@ function Invoke-ListSiteBrowser { foreach ($List in @($Lists | Where-Object { $_.list.hidden -ne $true -and $_.list.template -in @('documentLibrary', 'webPageLibrary') })) { $StorageUsed = $null $FileCount = $null + $FileStreamSize = $null + $MetadataSize = $null + $VersionEstimate = $null try { $Metrics = New-GraphGetRequest -uri "$BaseUri/web/lists(guid'$($List.id)')/RootFolder?`$select=StorageMetrics&`$expand=StorageMetrics" -tenantid $TenantFilter -scope $SpoScope -extraHeaders $JsonAccept -UseCertificate -AsApp $true - $StorageUsed = ConvertTo-StorageUsedBytes -Raw $Metrics.StorageMetrics.TotalSize - $FileCount = ConvertTo-NullableInt64 -Raw $Metrics.StorageMetrics.TotalFileCount + $TotalSize = ConvertTo-SPOAdminListInt64 -Raw $Metrics.StorageMetrics.TotalSize + $FileStreamSize = ConvertTo-SPOAdminListInt64 -Raw $Metrics.StorageMetrics.TotalFileStreamSize + $MetadataSize = ConvertTo-SPOAdminListInt64 -Raw $Metrics.StorageMetrics.MetadataSize + $FileCount = ConvertTo-SPOAdminListInt64 -Raw $Metrics.StorageMetrics.TotalFileCount + $StorageUsed = $TotalSize + if ($null -ne $TotalSize) { + $Tip = if ($null -ne $FileStreamSize) { $FileStreamSize } else { [int64]0 } + $Meta = if ($null -ne $MetadataSize) { $MetadataSize } else { [int64]0 } + $VersionEstimate = [Math]::Max([int64]0, $TotalSize - $Tip - $Meta) + } } catch { $StorageUsed = $null $FileCount = $null + $FileStreamSize = $null + $MetadataSize = $null + $VersionEstimate = $null } $Results.Add([PSCustomObject]@{ - type = 'library' - id = $List.id - siteId = $SiteId - displayName = $List.displayName - name = $List.name - template = $List.list.template - siteType = ConvertTo-SiteTypeLabel -ItemType 'library' -LibraryTemplate $List.list.template - webUrl = $List.webUrl - createdDateTime = $List.createdDateTime - storageUsedInBytes = $StorageUsed - fileCount = $FileCount + type = 'library' + id = $List.id + siteId = $SiteId + displayName = $List.displayName + name = $List.name + template = $List.list.template + siteType = ConvertTo-SiteTypeLabel -ItemType 'library' -LibraryTemplate $List.list.template + webUrl = $List.webUrl + createdDateTime = $List.createdDateTime + storageUsedInBytes = $StorageUsed + fileStreamSizeInBytes = $FileStreamSize + metadataSizeInBytes = $MetadataSize + versionEstimateBytes = $VersionEstimate + fileCount = $FileCount }) } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteBrowserLibraryCopy.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteBrowserLibraryCopy.ps1 new file mode 100644 index 0000000000000..068387a360c31 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteBrowserLibraryCopy.ps1 @@ -0,0 +1,37 @@ +function Invoke-ListSiteBrowserLibraryCopy { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Sharepoint.Site.Read + .DESCRIPTION + Returns sanitized aggregate status for a SharePoint library copy operation (OperationId). + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $TenantFilter = $Request.Query.tenantFilter ?? $Request.Query.TenantFilter ?? $Request.Body.tenantFilter ?? $Request.Body.TenantFilter + $OperationId = $Request.Query.OperationId ?? $Request.Query.operationId ?? $Request.Body.OperationId ?? $Request.Body.operationId + $StatusCode = [HttpStatusCode]::OK + + try { + if ([string]::IsNullOrWhiteSpace($TenantFilter)) { throw 'tenantFilter is required.' } + if ([string]::IsNullOrWhiteSpace($OperationId)) { throw 'OperationId is required.' } + + $Result = Update-CIPPSharePointLibraryCopyStatus -TenantFilter $TenantFilter -OperationId $OperationId + Write-LogMessage -Headers $Headers -API $APIName -tenant $TenantFilter ` + -message "Library copy status $OperationId -> $($Result.Status)" -sev Debug + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to retrieve library copy status: $($ErrorMessage.NormalizedError)" + Write-LogMessage -Headers $Headers -API $APIName -tenant $TenantFilter -message $Result -sev Error -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::BadRequest + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{ Results = $Result } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteBrowserPermissions.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteBrowserPermissions.ps1 index 94eef3575ac98..7b1631acc33ec 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteBrowserPermissions.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteBrowserPermissions.ps1 @@ -153,10 +153,10 @@ function Invoke-ListSiteBrowserPermissions { $IsLibrary = -not [string]::IsNullOrWhiteSpace($ListId) try { - $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter - $SpoScope = "$($SharePointInfo.SharePointUrl)/.default" - $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $SpoScope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri # --- Target / inheritance --- $TargetTitle = $null @@ -164,8 +164,19 @@ function Invoke-ListSiteBrowserPermissions { if ($IsLibrary) { try { $ListInfo = New-GraphGetRequest -uri "$BaseUri/web/lists(guid'$ListId')?`$select=HasUniqueRoleAssignments,Title,Id" -tenantid $TenantFilter -scope $SpoScope -extraHeaders $JsonAccept -UseCertificate -AsApp $true - $HasUniqueRoleAssignments = [bool]$ListInfo.HasUniqueRoleAssignments $TargetTitle = $ListInfo.Title + # [bool]$null is $false — that hides "Fix inheritance" when the property is not + # projected. Probe the scalar endpoint before treating the library as inheriting. + $HasUniqueRaw = $ListInfo.HasUniqueRoleAssignments + if ($null -eq $HasUniqueRaw) { + try { + $Probe = New-GraphGetRequest -uri "$BaseUri/web/lists(guid'$ListId')/HasUniqueRoleAssignments" -tenantid $TenantFilter -scope $SpoScope -extraHeaders $JsonAccept -UseCertificate -AsApp $true + $HasUniqueRaw = if ($null -ne $Probe.PSObject.Properties['value']) { $Probe.value } else { $Probe } + } catch { + $HasUniqueRaw = $null + } + } + $HasUniqueRoleAssignments = $HasUniqueRaw -eq $true -or "$HasUniqueRaw" -eq 'true' } catch { $Errors.Add([PSCustomObject]@{ section = 'target'; message = $_.Exception.Message }) } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteMembers.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteMembers.ps1 index d1f2627b12d16..893e9faa6ee2d 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteMembers.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteMembers.ps1 @@ -34,10 +34,10 @@ Function Invoke-ListSiteMembers { $Members = [System.Collections.Generic.List[object]]::new() try { - $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter - $Scope = "$($SharePointInfo.SharePointUrl)/.default" - $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $Scope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri $RoleGroups = [ordered]@{ 'Owners' = 'associatedownergroup' diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSitePermissions.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSitePermissions.ps1 index 5710dc9d498df..d4b1981e15feb 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSitePermissions.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSitePermissions.ps1 @@ -29,10 +29,10 @@ function Invoke-ListSitePermissions { try { if ([string]::IsNullOrWhiteSpace($SiteUrl)) { throw 'SiteUrl is required.' } - $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter - $Scope = "$($SharePointInfo.SharePointUrl)/.default" - $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $Scope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri # Scope: a document library, or the site root web when no list was supplied. $IsLibrary = -not [string]::IsNullOrWhiteSpace($ListId) diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteRecycleBin.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteRecycleBin.ps1 index b0530cb6d2ad8..8993c803fe9f6 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteRecycleBin.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteRecycleBin.ps1 @@ -20,10 +20,10 @@ function Invoke-ListSiteRecycleBin { try { if (-not $SiteUrl) { throw 'SiteUrl is required.' } - $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter - $Scope = "$($SharePointInfo.SharePointUrl)/.default" - $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $Scope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri $Items = New-GraphGetRequest -uri "$BaseUri/site/RecycleBin?`$top=500&`$orderby=DeletedDate desc" -tenantid $TenantFilter -scope $Scope -extraHeaders $JsonAccept -UseCertificate -AsApp $true diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteRecycleBinSummary.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteRecycleBinSummary.ps1 new file mode 100644 index 0000000000000..e461cb3f51e91 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteRecycleBinSummary.ps1 @@ -0,0 +1,97 @@ +function Invoke-ListSiteRecycleBinSummary { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Sharepoint.SiteRecycleBin.Read + .DESCRIPTION + Aggregate recycle bin sizes for a site (counts + bytes by stage). Never returns + item titles, leaf names, or paths — storage-report privacy ceiling. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $TenantFilter = $Request.Query.TenantFilter ?? $Request.Query.tenantFilter ?? $Request.Body.TenantFilter ?? $Request.Body.tenantFilter + $SiteUrl = $Request.Query.SiteUrl ?? $Request.Body.SiteUrl + $MaxItems = [int]($Request.Query.MaxItems ?? $Request.Body.MaxItems ?? 5000) + if ($MaxItems -lt 1) { $MaxItems = 5000 } + if ($MaxItems -gt 20000) { $MaxItems = 20000 } + + try { + if ([string]::IsNullOrWhiteSpace($TenantFilter)) { throw 'tenantFilter is required.' } + if ([string]::IsNullOrWhiteSpace($SiteUrl)) { throw 'SiteUrl is required.' } + + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $Scope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri + + $FirstCount = [int64]0 + $FirstBytes = [int64]0 + $SecondCount = [int64]0 + $SecondBytes = [int64]0 + $Seen = 0 + $Capped = $false + $NextUri = "$BaseUri/site/RecycleBin?`$select=Id,Size,ItemState&`$top=500&`$orderby=DeletedDate desc" + + while ($NextUri) { + $Page = New-GraphGetRequest -uri $NextUri -tenantid $TenantFilter -scope $Scope -extraHeaders $JsonAccept -UseCertificate -AsApp $true -noPagination $true -SkipValueExtraction + $Items = @() + $NextLink = $null + if ($null -ne $Page.value) { + $Items = @($Page.value) + $NextLink = $Page.'@odata.nextLink' + } elseif ($Page -is [System.Array]) { + $Items = @($Page) + } elseif ($Page.PSObject.Properties.Name -contains 'Id') { + $Items = @($Page) + } + + foreach ($Item in $Items) { + if ($Seen -ge $MaxItems) { + $Capped = $true + break + } + $Seen++ + $Size = 0 + try { $Size = [int64][double]$Item.Size } catch { $Size = 0 } + $State = 0 + try { $State = [int]$Item.ItemState } catch { $State = 0 } + if ($State -eq 2) { + $SecondCount++ + $SecondBytes += $Size + } else { + $FirstCount++ + $FirstBytes += $Size + } + } + + if ($Capped -or [string]::IsNullOrWhiteSpace($NextLink)) { break } + $NextUri = $NextLink + } + + $Body = [PSCustomObject]@{ + siteUrl = $SiteUrl.TrimEnd('/') + itemCount = $FirstCount + $SecondCount + totalBytes = $FirstBytes + $SecondBytes + firstStageCount = $FirstCount + firstStageBytes = $FirstBytes + secondStageCount = $SecondCount + secondStageBytes = $SecondBytes + capped = $Capped + scannedItems = $Seen + } + $StatusCode = [HttpStatusCode]::OK + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Body = "Failed to summarize recycle bin for $($SiteUrl): $($ErrorMessage.NormalizedError)" + Write-LogMessage -Headers $Request.Headers -API $APIName -tenant $TenantFilter -message $Body -sev Error -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::BadRequest + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{ Results = $Body } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteRoleDefinitions.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteRoleDefinitions.ps1 index f82dec1dddf60..bae31ce644515 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteRoleDefinitions.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteRoleDefinitions.ps1 @@ -22,10 +22,10 @@ function Invoke-ListSiteRoleDefinitions { try { if ([string]::IsNullOrWhiteSpace($SiteUrl)) { throw 'SiteUrl is required.' } - $SharePointInfo = Get-SharePointAdminLink -Public $false -tenantFilter $TenantFilter - $Scope = "$($SharePointInfo.SharePointUrl)/.default" - $JsonAccept = @{ Accept = 'application/json;odata=nometadata' } - $BaseUri = "$($SiteUrl.TrimEnd('/'))/_api" + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $Scope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri $RoleDefinitions = @(New-GraphGetRequest -uri "$BaseUri/web/roledefinitions?`$select=Id,Name,Description,RoleTypeKind,Hidden,Order" -tenantid $TenantFilter -scope $Scope -extraHeaders $JsonAccept -UseCertificate -AsApp $true) diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteStorageComposition.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteStorageComposition.ps1 new file mode 100644 index 0000000000000..4ffe18289266f --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteStorageComposition.ps1 @@ -0,0 +1,93 @@ +function Invoke-ListSiteStorageComposition { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Sharepoint.Site.Read + .DESCRIPTION + Site-level storage composition at library ceiling: tip / previous-version estimate / + recycle estimate from root web StorageMetrics + site StorageUsed. No file names. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $TenantFilter = $Request.Query.TenantFilter ?? $Request.Query.tenantFilter ?? $Request.Body.TenantFilter ?? $Request.Body.tenantFilter + $SiteUrl = $Request.Query.SiteUrl ?? $Request.Body.SiteUrl + + function ConvertTo-StorageBytes { + param($Raw) + if ($null -eq $Raw -or $Raw -eq '') { return $null } + $Clean = ([string]$Raw).Replace(',', '').Trim() + if ($Clean -eq '') { return $null } + try { return [int64][double]$Clean } catch { return $null } + } + + try { + if ([string]::IsNullOrWhiteSpace($TenantFilter)) { throw 'tenantFilter is required.' } + if ([string]::IsNullOrWhiteSpace($SiteUrl)) { throw 'SiteUrl is required.' } + + $RestContext = Resolve-CIPPSharePointRestContext -TenantFilter $TenantFilter -SiteUrl $SiteUrl + $SpoScope = $RestContext.Scope + $JsonAccept = $RestContext.Headers + $BaseUri = $RestContext.BaseUri + + $RootMetrics = New-GraphGetRequest -uri "$BaseUri/web/RootFolder?`$select=StorageMetrics&`$expand=StorageMetrics" -tenantid $TenantFilter -scope $SpoScope -extraHeaders $JsonAccept -UseCertificate -AsApp $true + $TotalSize = ConvertTo-StorageBytes -Raw $RootMetrics.StorageMetrics.TotalSize + $FileStreamSize = ConvertTo-StorageBytes -Raw $RootMetrics.StorageMetrics.TotalFileStreamSize + $MetadataSize = ConvertTo-StorageBytes -Raw $RootMetrics.StorageMetrics.MetadataSize + $FileCount = ConvertTo-StorageBytes -Raw $RootMetrics.StorageMetrics.TotalFileCount + + $Tip = if ($null -ne $FileStreamSize) { $FileStreamSize } else { [int64]0 } + $Meta = if ($null -ne $MetadataSize) { $MetadataSize } else { [int64]0 } + $Total = if ($null -ne $TotalSize) { $TotalSize } else { [int64]0 } + $VersionEstimate = [Math]::Max([int64]0, $Total - $Tip - $Meta) + + $StorageUsed = $null + try { + $Usage = New-GraphGetRequest -uri "$BaseUri/site/Usage" -tenantid $TenantFilter -scope $SpoScope -extraHeaders $JsonAccept -UseCertificate -AsApp $true + $StorageUsed = ConvertTo-StorageBytes -Raw $Usage.StorageUsageBytes + if ($null -eq $StorageUsed) { + $StorageUsed = ConvertTo-StorageBytes -Raw $Usage.StorageUsed + } + } catch { + $StorageUsed = $null + } + if ($null -eq $StorageUsed) { + try { + $Web = New-GraphGetRequest -uri "$BaseUri/site?`$select=Usage" -tenantid $TenantFilter -scope $SpoScope -extraHeaders $JsonAccept -UseCertificate -AsApp $true + $StorageUsed = ConvertTo-StorageBytes -Raw $Web.Usage.StorageUsedInBytes + } catch { + $StorageUsed = $null + } + } + + $RecycleEstimate = $null + if ($null -ne $StorageUsed -and $null -ne $TotalSize) { + $RecycleEstimate = [Math]::Max([int64]0, $StorageUsed - $TotalSize) + } + + $Body = [PSCustomObject]@{ + siteUrl = $SiteUrl.TrimEnd('/') + storageUsedInBytes = $StorageUsed + tipBytes = $Tip + metadataSizeInBytes = $Meta + totalSizeInBytes = $Total + versionEstimateBytes = $VersionEstimate + recycleEstimateBytes = $RecycleEstimate + fileCount = $FileCount + estimatesLabeled = $true + } + $StatusCode = [HttpStatusCode]::OK + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Body = "Failed to get storage composition for $($SiteUrl): $($ErrorMessage.NormalizedError)" + Write-LogMessage -Headers $Request.Headers -API $APIName -tenant $TenantFilter -message $Body -sev Error -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::BadRequest + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{ Results = $Body } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSites.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSites.ps1 index 7c70a742e9b2e..19c874be7152a 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSites.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSites.ps1 @@ -5,7 +5,7 @@ function Invoke-ListSites { .ROLE Sharepoint.Site.Read .DESCRIPTION - Lists SharePoint sites or OneDrive usage for a tenant. Requires a Type parameter (SharePointSiteUsage or OneDriveUsageAccount). Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants. + Lists SharePoint sites or OneDrive usage for a tenant. Requires a Type parameter (SharePointSiteUsage or OneDriveUsageAccount). SharePoint live data uses SPO admin RLD plus Graph enrichment; OneDrive live data uses Graph usage reports. Supports UseReportDB=true query parameter to retrieve cached data from the reporting database for significantly better performance, especially when querying AllTenants. #> [CmdletBinding()] param($Request, $TriggerMetadata) @@ -55,86 +55,69 @@ function Invoke-ListSites { } } - $Tenant = Get-Tenants -TenantFilter $TenantFilter - $TenantId = $Tenant.customerId - - if ($Type -eq 'SharePointSiteUsage') { - $Filter = 'isPersonalSite eq false' - } else { - $Filter = 'isPersonalSite eq true' - } - try { - $BulkRequests = @( - @{ - id = 'listAllSites' - method = 'GET' - url = "sites/getAllSites?`$filter=$($Filter)&`$select=id,createdDateTime,description,name,displayName,isPersonalSite,lastModifiedDateTime,webUrl,siteCollection,sharepointIds&`$top=999" - } - @{ - id = 'usage' - method = 'GET' - url = "reports/get$($type)Detail(period='D7')?`$format=application/json&`$top=999" + if ($Type -eq 'SharePointSiteUsage') { + $Built = Get-CIPPSharePointSiteUsageRows -TenantFilter $TenantFilter -LogApi 'ListSites' + $UsageBySiteId = [System.Collections.Generic.Dictionary[string, object]]::new([System.StringComparer]::OrdinalIgnoreCase) + foreach ($UsageRow in @($Built.UsageRows)) { + if (-not [string]::IsNullOrWhiteSpace($UsageRow.siteId)) { + $UsageBySiteId[[string]$UsageRow.siteId.Trim('{}')] = $UsageRow + } } - ) - - $Result = New-GraphBulkRequest -tenantid $TenantFilter -Requests @($BulkRequests) -asapp $true - $Sites = ($Result | Where-Object { $_.id -eq 'listAllSites' }).body.value - $UsageResponse = $Result | Where-Object { $_.id -eq 'usage' } - if ($UsageResponse.status -and $UsageResponse.status -ne 200) { - throw ($UsageResponse.body.error.message ?? "Usage report request failed with status $($UsageResponse.status)") - } - $UsageBody = $UsageResponse.body - if ($UsageBody -is [string]) { - $UsageJson = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($UsageBody)) - $Usage = ($UsageJson | ConvertFrom-Json).value - } else { - $Usage = @($UsageBody.value) - } - $GraphRequest = foreach ($Site in $Sites) { - $SiteUsage = $Usage | Where-Object { $_.siteId -eq $Site.sharepointIds.siteId } - [PSCustomObject]@{ - siteId = $Site.sharepointIds.siteId - webId = $Site.sharepointIds.webId - createdDateTime = $Site.createdDateTime - displayName = $Site.displayName - webUrl = $Site.webUrl - ownerDisplayName = $SiteUsage.ownerDisplayName - ownerPrincipalName = $SiteUsage.ownerPrincipalName - lastActivityDate = $SiteUsage.lastActivityDate - fileCount = $SiteUsage.fileCount - # Null, not 0, when the usage report has no row for this site: '0' reads as an - # authoritative "this site is empty" and is indistinguishable from a real empty - # site, which is exactly the confusion an absent usage report should not create. - storageUsedInGigabytes = if ($null -ne $SiteUsage.storageUsedInBytes) { [math]::round([double]$SiteUsage.storageUsedInBytes / 1GB, 2) } else { $null } - storageAllocatedInGigabytes = if ($null -ne $SiteUsage.storageAllocatedInBytes) { [math]::round([double]$SiteUsage.storageAllocatedInBytes / 1GB, 2) } else { $null } - storageUsedInBytes = $SiteUsage.storageUsedInBytes - storageAllocatedInBytes = $SiteUsage.storageAllocatedInBytes - rootWebTemplate = $SiteUsage.rootWebTemplate - reportRefreshDate = $SiteUsage.reportRefreshDate - AutoMapUrl = '' + $GraphRequest = foreach ($Site in @($Built.SiteListing)) { + $SiteUsage = $null + [void]$UsageBySiteId.TryGetValue([string]$Site.sharepointIds.siteId.Trim('{}'), [ref]$SiteUsage) + ConvertTo-CIPPSharePointSiteUsagePayload -Site $Site -SiteUsage $SiteUsage } - } - - $int = 0 - if ($Type -eq 'SharePointSiteUsage') { - $Requests = foreach ($Site in $GraphRequest) { + } else { + $BulkRequests = @( + @{ + id = 'listAllSites' + method = 'GET' + url = "sites/getAllSites?`$filter=isPersonalSite eq true&`$select=id,createdDateTime,description,name,displayName,isPersonalSite,lastModifiedDateTime,webUrl,siteCollection,sharepointIds&`$top=999" + } @{ - id = $int++ + id = 'usage' method = 'GET' - url = "sites/$($Site.siteId)/lists?`$select=id,name,list,parentReference" + url = "reports/get$($type)Detail(period='D7')?`$format=application/json&`$top=999" } + ) + + $Result = New-GraphBulkRequest -tenantid $TenantFilter -Requests @($BulkRequests) -asapp $true + $Sites = ($Result | Where-Object { $_.id -eq 'listAllSites' }).body.value + $UsageResponse = $Result | Where-Object { $_.id -eq 'usage' } + if ($UsageResponse.status -and $UsageResponse.status -ne 200) { + throw ($UsageResponse.body.error.message ?? "Usage report request failed with status $($UsageResponse.status)") } - try { - $Requests = (New-GraphBulkRequest -tenantid $TenantFilter -scope 'https://graph.microsoft.com/.default' -Requests @($Requests) -asapp $true).body.value | Where-Object { $_.list.template -eq 'DocumentLibrary' } - } catch { - Write-LogMessage -Headers $Headers -Message "Error getting auto map urls: $($_.Exception.Message)" -Sev 'Error' -tenant $TenantFilter -API 'ListSites' -LogData (Get-CippException -Exception $_) + $UsageBody = $UsageResponse.body + if ($UsageBody -is [string]) { + $UsageJson = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($UsageBody)) + $Usage = ($UsageJson | ConvertFrom-Json).value + } else { + $Usage = @($UsageBody.value) } - $GraphRequest = foreach ($Site in $GraphRequest) { - $ListId = ($Requests | Where-Object { $_.parentReference.siteId -like "*$($Site.siteId)*" }).id - $site.AutoMapUrl = "tenantId=$($TenantId)&webId={$($Site.webId)}&siteid={$($Site.siteId)}&webUrl=$($Site.webUrl)&listId={$($ListId)}" - $site + + $GraphRequest = foreach ($Site in $Sites) { + $SiteUsage = $Usage | Where-Object { $_.siteId -eq $Site.sharepointIds.siteId } + [PSCustomObject]@{ + siteId = $Site.sharepointIds.siteId + webId = $Site.sharepointIds.webId + createdDateTime = $Site.createdDateTime + displayName = $Site.displayName + webUrl = $Site.webUrl + ownerDisplayName = $SiteUsage.ownerDisplayName + ownerPrincipalName = $SiteUsage.ownerPrincipalName + lastActivityDate = $SiteUsage.lastActivityDate + fileCount = $SiteUsage.fileCount + storageUsedInGigabytes = if ($null -ne $SiteUsage.storageUsedInBytes) { [math]::round([double]$SiteUsage.storageUsedInBytes / 1GB, 2) } else { $null } + storageAllocatedInGigabytes = if ($null -ne $SiteUsage.storageAllocatedInBytes) { [math]::round([double]$SiteUsage.storageAllocatedInBytes / 1GB, 2) } else { $null } + storageUsedInBytes = $SiteUsage.storageUsedInBytes + storageAllocatedInBytes = $SiteUsage.storageAllocatedInBytes + rootWebTemplate = $SiteUsage.rootWebTemplate + reportRefreshDate = $SiteUsage.reportRefreshDate + AutoMapUrl = '' + } } } $StatusCode = [HttpStatusCode]::OK diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListStorageCleanupScan.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListStorageCleanupScan.ps1 new file mode 100644 index 0000000000000..b58dd4bebd1a7 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListStorageCleanupScan.ps1 @@ -0,0 +1,131 @@ +function Invoke-ListStorageCleanupScan { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Sharepoint.Site.Read + .DESCRIPTION + Reads the hold-only StorageCleanupScan CIPPDB cache and rebuilds the scans map expected by + the storage report cleanup opportunity helpers. No live enumeration — refresh via + ExecCIPPDBCache Name=StorageCleanupScan. Report-private; not used by other List APIs. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $TenantFilter = $Request.Query.tenantFilter ?? $Request.Body.tenantFilter ?? $Request.Query.TenantFilter ?? $Request.Body.TenantFilter + + if ([string]::IsNullOrWhiteSpace($TenantFilter)) { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @{ Results = 'tenantFilter is required.' } + }) + } + + try { + $CacheRows = @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'StorageCleanupScan') + } catch { + $CacheRows = @() + } + + $CleanupSynced = $false + $LastDataRefresh = $null + try { + $CountRow = Get-CIPPDbItem -TenantFilter $TenantFilter -Type 'StorageCleanupScan' -CountsOnly | Select-Object -First 1 + if ($CountRow) { $CleanupSynced = $true } + if ($CountRow.Timestamp) { $LastDataRefresh = $CountRow.Timestamp } + } catch {} + + $SiteRows = @($CacheRows | Where-Object { $_.rowType -eq 'Site' }) + $LibraryRows = @($CacheRows | Where-Object { $_.rowType -eq 'Library' }) + + $LibrariesBySiteUrl = @{} + foreach ($Lib in $LibraryRows) { + $Key = [string]$Lib.siteUrl + if ([string]::IsNullOrWhiteSpace($Key)) { continue } + $Key = $Key.TrimEnd('/') + if (-not $LibrariesBySiteUrl.ContainsKey($Key)) { + $LibrariesBySiteUrl[$Key] = [System.Collections.Generic.List[object]]::new() + } + $LibrariesBySiteUrl[$Key].Add([PSCustomObject]@{ + id = $Lib.libraryId + name = $Lib.libraryName + displayName = $Lib.libraryDisplayName + storageUsedInBytes = $Lib.storageUsedInBytes + versionEstimateBytes = $Lib.versionEstimateBytes + }) + } + + $Scans = @{} + $SitesScanned = 0 + $SitesSkipped = 0 + $LibrariesScanned = 0 + $SitesWithRecycle = 0 + + foreach ($Site in $SiteRows) { + $SitesScanned++ + if ($Site.collectionStatus -eq 'Skipped') { $SitesSkipped++ } + + $SiteUrl = [string]$Site.siteUrl + if ([string]::IsNullOrWhiteSpace($SiteUrl)) { continue } + $NormalizedUrl = $SiteUrl.TrimEnd('/') + + $Libraries = @() + if ($LibrariesBySiteUrl.ContainsKey($NormalizedUrl)) { + $Libraries = @($LibrariesBySiteUrl[$NormalizedUrl]) + } + $LibrariesScanned += $Libraries.Count + + $Recycle = $null + if ($null -ne $Site.recycleTotalBytes -or $null -ne $Site.recycleItemCount) { + $SitesWithRecycle++ + $Recycle = [PSCustomObject]@{ + siteUrl = $NormalizedUrl + totalBytes = $Site.recycleTotalBytes + itemCount = $Site.recycleItemCount + firstStageBytes = $Site.recycleFirstStageBytes + firstStageCount = $Site.recycleFirstStageCount + secondStageBytes = $Site.recycleSecondStageBytes + secondStageCount = $Site.recycleSecondStageCount + capped = $Site.recycleCapped + scannedItems = $Site.recycleScannedItems + } + } + + $ScanEntry = @{ + libraries = $Libraries + recycle = $Recycle + } + $Scans[$SiteUrl] = $ScanEntry + if ($SiteUrl -ne $NormalizedUrl) { + $Scans[$NormalizedUrl] = $ScanEntry + } + } + + # Libraries whose site row is missing (should not happen after a full store) still surface. + foreach ($Key in $LibrariesBySiteUrl.Keys) { + if ($Scans.ContainsKey($Key)) { continue } + $Scans[$Key] = @{ + libraries = @($LibrariesBySiteUrl[$Key]) + recycle = $null + } + $SitesScanned++ + $LibrariesScanned += $LibrariesBySiteUrl[$Key].Count + } + + $Body = [PSCustomObject]@{ + summary = [PSCustomObject]@{ + cleanupSynced = $CleanupSynced + lastDataRefresh = $LastDataRefresh + sitesScanned = $SitesScanned + sitesSkipped = $SitesSkipped + librariesScanned = $LibrariesScanned + sitesWithRecycle = $SitesWithRecycle + } + scans = $Scans + } + + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = $Body + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-AddAlert.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-AddAlert.ps1 index 8afe3d021f1c0..fac3cedb5a371 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-AddAlert.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-AddAlert.ps1 @@ -38,15 +38,18 @@ function Invoke-AddAlert { $Actions = $Request.Body.actions | ConvertTo-Json -Compress -Depth 10 | Out-String $RowKey = $Request.Body.RowKey ? $Request.Body.RowKey : (New-Guid).ToString() $CompleteObject = @{ - Tenants = [string]$TenantsJson - excludedTenants = [string]$excludedTenantsJson - Conditions = [string]$Conditions - Actions = [string]$Actions - type = $Request.Body.logbook.value - RowKey = $RowKey - PartitionKey = 'Webhookv2' - AlertComment = [string]$Request.Body.AlertComment - CustomSubject = [string]$Request.Body.CustomSubject + Tenants = [string]$TenantsJson + excludedTenants = [string]$excludedTenantsJson + Conditions = [string]$Conditions + Actions = [string]$Actions + type = $Request.Body.logbook.value + RowKey = $RowKey + PartitionKey = 'Webhookv2' + AlertComment = [string]$Request.Body.AlertComment + CustomSubject = [string]$Request.Body.CustomSubject + # The audit form posts the raw form values, so an autocomplete selection arrives as a + # {label, value} object - unwrap it to the bare Halo priority id before storing. + PsaTicketPriority = [string]($Request.Body.PsaTicketPriority.value ?? $Request.Body.PsaTicketPriority) } $WebhookTable = Get-CippTable -TableName 'WebhookRules' if ($Request.Body.RowKey) { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-AddScriptedAlert.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-AddScriptedAlert.ps1 index 7efff1a444d2d..d04f7298eeb45 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-AddScriptedAlert.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-AddScriptedAlert.ps1 @@ -4,60 +4,38 @@ function Invoke-AddScriptedAlert { Entrypoint .ROLE CIPP.Alert.ReadWrite + .DESCRIPTION + Creates or updates a scripted CIPP alert, stored as a hidden scheduled task. + + A selection of two or more tenants or groups is stored verbatim and expanded on every run, + so tenant group membership is always current. #> [CmdletBinding()] param($Request, $TriggerMetadata) - $tenantsJsonForStorage = $null - + # The tenants, tenant groups or *All Tenants the alert applies to. At least one is required. if ($Request.Body.tenantFilter -is [array] -and @($Request.Body.tenantFilter).Count -eq 1) { $Request.Body | Add-Member -MemberType NoteProperty -Name 'tenantFilter' -Value $Request.Body.tenantFilter[0] -Force } if ($Request.Body.tenantFilter -is [array] -and @($Request.Body.tenantFilter).Count -gt 1) { - try { - $originalSelection = @($Request.Body.tenantFilter) - $tenantsJsonForStorage = $originalSelection | ConvertTo-Json -Compress -Depth 10 - - $hasAllTenants = @($originalSelection | Where-Object { $_.value -eq 'AllTenants' }).Count -gt 0 - - if (-not $hasAllTenants) { - $ExpandedSelection = Expand-CIPPTenantGroups -TenantFilter $originalSelection - $targetDomains = @($ExpandedSelection | ForEach-Object { $_.value }) - - $AllTenantsList = Get-Tenants -IncludeErrors - $computedExcluded = @($AllTenantsList.defaultDomainName | Where-Object { $_ -notin $targetDomains }) - - $existingEntries = @() - if ($Request.Body.PSObject.Properties['excludedTenants'] -and $Request.Body.excludedTenants) { - $existingEntries = @($Request.Body.excludedTenants) - } - # Keep user-picked groups as typed objects so Add-CIPPScheduledTask stores them - # for runtime expansion instead of flattening them into the domain list - $excludedGroupEntries = @($existingEntries | Where-Object { $_.type -eq 'Group' }) - $existingExcluded = @($existingEntries | Where-Object { $_.type -ne 'Group' } | ForEach-Object { $_.value ?? $_ }) - $mergedExcluded = @($existingExcluded + $computedExcluded) | Where-Object { $_ } | Select-Object -Unique + $Request.Body | Add-Member -MemberType NoteProperty -Name 'Tenants' -Value @($Request.Body.tenantFilter) -Force - $excludedValue = @($mergedExcluded | ForEach-Object { - [PSCustomObject]@{ value = $_; label = $_ } - }) + $excludedGroupEntries - $Request.Body | Add-Member -MemberType NoteProperty -Name 'excludedTenants' -Value $excludedValue -Force - } - - if (-not $Request.Body.PSObject.Properties['RowKey'] -or -not $Request.Body.RowKey) { - $Request.Body | Add-Member -MemberType NoteProperty -Name 'RowKey' -Value ((New-Guid).Guid) -Force - } - - $tenantFilterValue = [PSCustomObject]@{ + # Tenant stays 'AllTenants' - the execution gates gate on that literal; Tenants holds the real scope. + $Request.Body | Add-Member -MemberType NoteProperty -Name 'tenantFilter' -Value ([PSCustomObject]@{ value = 'AllTenants' label = '*All Tenants' type = 'Tenant' - } - $Request.Body | Add-Member -MemberType NoteProperty -Name 'tenantFilter' -Value $tenantFilterValue -Force - } catch { - Write-Warning "Failed to process multi-tenant alert selection: $($_.Exception.Message)" - $tenantsJsonForStorage = $null - } + }) -Force + } + + # Tenants or tenant groups to skip even when they fall within the selection above. Optional. + if ($Request.Body.excludedTenants) { + # Add-CIPPScheduledTask drops entries with no value, so wrap bare domain strings. + $NormalizedExclusions = @(@($Request.Body.excludedTenants) | Where-Object { $_ } | ForEach-Object { + if ($_.value) { $_ } else { [PSCustomObject]@{ value = [string]$_; label = [string]$_; type = 'Tenant' } } + }) + $Request.Body | Add-Member -MemberType NoteProperty -Name 'excludedTenants' -Value $NormalizedExclusions -Force } $ForwardRequest = @{ @@ -65,20 +43,6 @@ function Invoke-AddScriptedAlert { Body = $Request.Body Headers = $Request.Headers } - $Response = Invoke-AddScheduledItem -Request $ForwardRequest -TriggerMetadata $TriggerMetadata - - if ($tenantsJsonForStorage) { - try { - $Table = Get-CIPPTable -TableName 'ScheduledTasks' - $null = Update-AzDataTableEntity -Force @Table -Entity @{ - PartitionKey = 'ScheduledTask' - RowKey = [string]$Request.Body.RowKey - Tenants = [string]$tenantsJsonForStorage - } - } catch { - Write-Warning "Failed to persist multi-tenant selection for alert: $($_.Exception.Message)" - } - } - return $Response + return Invoke-AddScheduledItem -Request $ForwardRequest -TriggerMetadata $TriggerMetadata } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-ExecScheduleAuditExclusionVacation.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-ExecScheduleAuditExclusionVacation.ps1 index 702a61d5800e7..741d78c1a992c 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-ExecScheduleAuditExclusionVacation.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-ExecScheduleAuditExclusionVacation.ps1 @@ -67,6 +67,7 @@ function Invoke-ExecScheduleAuditExclusionVacation { }) -hidden $false $Result = "Successfully scheduled location alert exclusion vacation mode for $UserDisplay." + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-ListAlertsQueue.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-ListAlertsQueue.ps1 index 81f7e6013b88f..c00ca3409328a 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-ListAlertsQueue.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-ListAlertsQueue.ps1 @@ -38,14 +38,15 @@ function Invoke-ListAlertsQueue { CustomSubject = $Task.CustomSubject Enabled = $Task.Disabled -ne $true RawAlert = @{ - Conditions = @($Conditions) - Actions = @($($Task.Actions | ConvertFrom-Json -Depth 10 -ErrorAction SilentlyContinue)) - Tenants = @($Tenants) - type = $Task.type - RowKey = $Task.RowKey - PartitionKey = $Task.PartitionKey - AlertComment = $Task.AlertComment - CustomSubject = $Task.CustomSubject + Conditions = @($Conditions) + Actions = @($($Task.Actions | ConvertFrom-Json -Depth 10 -ErrorAction SilentlyContinue)) + Tenants = @($Tenants) + type = $Task.type + RowKey = $Task.RowKey + PartitionKey = $Task.PartitionKey + AlertComment = $Task.AlertComment + CustomSubject = $Task.CustomSubject + PsaTicketPriority = $Task.PsaTicketPriority } } @@ -69,8 +70,14 @@ function Invoke-ListAlertsQueue { } catch { Write-Warning "Failed to expand tenant group for webhook access check: $($_.Exception.Message)" } + } elseif ($Tenant.value -eq 'AllTenants') { + # AllTenants alerts cover the caller's own tenants, so restricted readers may see them + $HasAccess = $true } else { - if ($AllowedTenants -contains $Tenant.customerId) { + # Selector objects store customerId under addedFields; fall back to resolving + # the stored defaultDomainName for entries saved without it + $CustomerId = $Tenant.addedFields.customerId ?? $Tenant.customerId ?? ($TenantList | Where-Object -Property defaultDomainName -EQ $Tenant.value).customerId + if ($AllowedTenants -contains $CustomerId) { $HasAccess = $true } } @@ -112,7 +119,11 @@ function Invoke-ListAlertsQueue { type = $_.type ?? 'Tenant' } }) - $ExcludedTenants = @() + # A legacy row's excludedTenants is a snapshot of every unselected tenant, ignored at + # run time and hidden here. A versioned row's is the operator's own picks. + if (-not $Task.TenantSelectionVersion) { + $ExcludedTenants = @() + } } catch { Write-Warning "Failed to parse Tenants for alert task $($Task.RowKey): $($_.Exception.Message)" $TenantsForDisplay = @([PSCustomObject]@{ @@ -209,9 +220,13 @@ function Invoke-ListAlertsQueue { break } } + } elseif ($TenantItem.value -eq 'AllTenants') { + # AllTenants alerts cover the caller's own tenants, so restricted readers may see them + $HasAccess = $true } else { $TenantInfo = $TenantList | Where-Object -Property defaultDomainName -EQ $TenantItem.value - if ($TenantInfo -and $AllowedTenants -contains $TenantInfo.customerId) { + $CustomerId = $TenantItem.addedFields.customerId ?? $TenantInfo.customerId + if ($AllowedTenants -contains $CustomerId) { $HasAccess = $true } } @@ -220,6 +235,9 @@ function Invoke-ListAlertsQueue { } catch { Write-Warning "Failed to parse Tenants for access check on task $($Task.RowKey): $($_.Exception.Message)" } + } elseif ($Task.Tenant -eq 'AllTenants') { + # AllTenants alerts cover the caller's own tenants, so restricted readers may see them + $HasAccess = $true } else { # Regular single-tenant access check $Tenant = $TenantList | Where-Object -Property defaultDomainName -EQ $Task.Tenant diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-PublicWebhooks.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-PublicWebhooks.ps1 index aa8be40e3db2e..0a14ff6ab5e34 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-PublicWebhooks.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-PublicWebhooks.ps1 @@ -12,17 +12,25 @@ function Invoke-PublicWebhooks { $CIPPURL = [string]$url Write-Host $url + # Graph (and Partner Center) validate a new subscription by POSTing a token and comparing the raw + # response body to it byte for byte. The response has to be the bare token as text/plain - the + # default application/json content type re-quotes the string, and Graph then rejects the + # subscription with "did not return the expected validation token". + $ContentType = 'application/json' if ($Request.Query.ValidationToken) { Write-Host 'Validation token received - query ValidationToken' - $body = $Request.Query.ValidationToken + $body = [string]$Request.Query.ValidationToken + $ContentType = 'text/plain' $StatusCode = [HttpStatusCode]::OK } elseif ($Request.Body.validationCode) { Write-Host 'Validation token received - body validationCode' - $body = $Request.Body.validationCode + $body = [string]$Request.Body.validationCode + $ContentType = 'text/plain' $StatusCode = [HttpStatusCode]::OK } elseif ($Request.Query.validationCode) { Write-Host 'Validation token received - query validationCode' - $body = $Request.Query.validationCode + $body = [string]$Request.Query.validationCode + $ContentType = 'text/plain' $StatusCode = [HttpStatusCode]::OK } elseif ($Request.Query.CIPPID) { $CIPPID = ConvertTo-CIPPODataFilterValue -Value $Request.Query.CIPPID -Type Guid @@ -53,6 +61,7 @@ function Invoke-PublicWebhooks { FunctionName = 'PublicWebhookProcess' } Add-CIPPAzDataTableEntity @WebhookIncoming -Entity $Entity + Write-LogMessage -headers $Headers -API ($Request.Params.CIPPEndpoint ?? 'PublicWebhooks') -tenant 'Global' -message "Graph subscription webhook received and queued (CIPPID=$($Request.Query.CIPPID))" -Sev 'Info' } elseif ($Request.Query.Type -eq 'PartnerCenter') { [pscustomobject]$ReceivedItem = $Request.Body @@ -66,6 +75,7 @@ function Invoke-PublicWebhooks { FunctionName = 'PublicWebhookProcess' } Add-CIPPAzDataTableEntity @WebhookIncoming -Entity $Entity + Write-LogMessage -headers $Headers -API ($Request.Params.CIPPEndpoint ?? 'PublicWebhooks') -tenant 'Global' -message "Partner Center webhook received and queued (CIPPID=$($Request.Query.CIPPID))" -Sev 'Info' } else { $Body = 'This webhook is not authorized.' $StatusCode = [HttpStatusCode]::Forbidden @@ -80,7 +90,8 @@ function Invoke-PublicWebhooks { } return ([HttpResponseContext]@{ - StatusCode = $StatusCode - Body = $Body + StatusCode = $StatusCode + Body = $Body + ContentType = $ContentType }) } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-RemoveWebhookAlert.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-RemoveWebhookAlert.ps1 index 764a0d1524379..c18be0402cf6e 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-RemoveWebhookAlert.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Alerts/Invoke-RemoveWebhookAlert.ps1 @@ -19,6 +19,7 @@ Function Invoke-RemoveWebhookAlert { $Entity = $WebhookRow | Where-Object -Property RowKey -EQ $Request.query.ID Remove-CIPPAzDataTableEntity -Force @WebhookTable -Entity $Entity | Out-Null $Results = "Removed Alert Rule for $($Request.query.TenantFilter)" + Write-LogMessage -headers $Request.Headers -API $APIName -tenant $Request.query.TenantFilter -message $Results -Sev 'Info' } else { if ($Request.query.TenantFilter -eq 'AllTenants') { $Tenants = Get-Tenants -IncludeAll -IncludeErrors | Select-Object -ExpandProperty defaultDomainName @@ -31,7 +32,7 @@ Function Invoke-RemoveWebhookAlert { } Remove-CIPPAzDataTableEntity -Force @Table -Entity $CompleteObject -ErrorAction SilentlyContinue | Out-Null } catch { - Write-LogMessage -headers $Request.Headers -API $APIName -message "Failed to remove webhook for AllTenants. $($_.Exception.Message)" -Sev 'Error' + Write-LogMessage -headers $Request.Headers -API $APIName -tenant 'Global' -message "Failed to remove webhook for AllTenants. $($_.Exception.Message)" -Sev 'Error' } } else { $Tenants = $Request.query.TenantFilter @@ -41,12 +42,14 @@ Function Invoke-RemoveWebhookAlert { Remove-CIPPGraphSubscription -TenantFilter $Tenant -Type 'AuditLog' $Entity = $WebhookRow | Where-Object -Property RowKey -EQ $Request.query.ID Remove-CIPPAzDataTableEntity -Force @WebhookTable -Entity $Entity | Out-Null - "Removed Alert Rule for $($Request.query.TenantFilter)" + $Message = "Removed Alert Rule for $($Request.query.TenantFilter)" + Write-LogMessage -headers $Request.Headers -API $APIName -tenant $Tenant -message $Message -Sev 'Info' + $Message } } $body = [pscustomobject]@{'Results' = $Results } } catch { - Write-LogMessage -headers $Request.Headers -API $APINAME -message "Failed to remove webhook alert. $($_.Exception.Message)" -Sev 'Error' + Write-LogMessage -headers $Request.Headers -API $APINAME -tenant 'Global' -message "Failed to remove webhook alert. $($_.Exception.Message)" -Sev 'Error' $body = [pscustomobject]@{'Results' = "Failed to remove webhook alert: $($_.Exception.Message)" } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Application Approval/Invoke-ExecAddMultiTenantApp.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Application Approval/Invoke-ExecAddMultiTenantApp.ps1 index e53ce5c3924fd..11a88caf4c7c8 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Application Approval/Invoke-ExecAddMultiTenantApp.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Application Approval/Invoke-ExecAddMultiTenantApp.ps1 @@ -6,6 +6,8 @@ function Invoke-ExecAddMultiTenantApp { Tenant.Application.ReadWrite #> param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers if ($Request.Body.configMode -eq 'manual') { $DelegateResources = $request.body.permissions | Where-Object -Property origin -EQ 'Delegated' | ForEach-Object { @{ id = $_.id; type = 'Scope' } } $DelegateResourceAccess = @{ ResourceAppId = '00000003-0000-0000-c000-000000000000'; resourceAccess = $DelegateResources } @@ -45,15 +47,18 @@ function Invoke-ExecAddMultiTenantApp { } $null = Start-CIPPOrchestrator -InputObject $InputObject $Results = 'Deploying {0} to {1}, see the logbook for details' -f $Request.Body.AppId, ($Request.Body.tenantFilter.label -join ', ') + Write-LogMessage -headers $Headers -API $APIName -message $Results -Sev 'Info' } catch { - $ErrorMsg = Get-NormalizedError -message $($_.Exception.Message) - $Results = "Function Error: $ErrorMsg" + $ErrorMessage = Get-CippException -Exception $_ + $Results = "Function Error: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -message $Results -Sev 'Error' -LogData $ErrorMessage } $StatusCode = [HttpStatusCode]::OK } catch { - $ErrorMsg = Get-NormalizedError -message $($_.Exception.Message) - $Results = "Function Error: $ErrorMsg" + $ErrorMessage = Get-CippException -Exception $_ + $Results = "Function Error: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -message $Results -Sev 'Error' -LogData $ErrorMessage $StatusCode = [HttpStatusCode]::BadRequest } } elseif ($Request.Body.configMode -eq 'template') { @@ -83,8 +88,11 @@ function Invoke-ExecAddMultiTenantApp { } $null = Start-CIPPOrchestrator -InputObject $InputObject $Results = 'Deploying {0} to {1}, see the logbook for details' -f $Request.Body.selectedTemplate.label, ($Request.Body.tenantFilter.label -join ', ') + Write-LogMessage -headers $Headers -API $APIName -message $Results -Sev 'Info' } catch { - $Results = "Error queuing application - $($_.Exception.Message)" + $ErrorMessage = Get-CippException -Exception $_ + $Results = "Error queuing application - $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -message $Results -Sev 'Error' -LogData $ErrorMessage } $StatusCode = [HttpStatusCode]::OK } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Application Approval/Invoke-ExecAppApprovalTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Application Approval/Invoke-ExecAppApprovalTemplate.ps1 index 3440b114303ee..003f81cb6836f 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Application Approval/Invoke-ExecAppApprovalTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Application Approval/Invoke-ExecAppApprovalTemplate.ps1 @@ -126,11 +126,12 @@ function Invoke-ExecAppApprovalTemplate { # Create output object preserving original structure $outputObject = $templateData | Select-Object -Property * - # Add the TemplateId (RowKey) to the output - $outputObject | Add-Member -NotePropertyName 'TemplateId' -NotePropertyValue $_.RowKey -Force - - # Add timestamp from the table entity - $outputObject | Add-Member -NotePropertyName 'Timestamp' -NotePropertyValue $_.Timestamp.DateTime.ToString('yyyy-MM-ddTHH:mm:ssZ') -Force + $outputObject | Add-Member -NotePropertyMembers ([ordered]@{ + # Add the TemplateId (RowKey) to the output + TemplateId = $_.RowKey + # Add timestamp from the table entity + Timestamp = $_.Timestamp.DateTime.ToString('yyyy-MM-ddTHH:mm:ssZ') + }) -Force return $outputObject } @@ -148,11 +149,12 @@ function Invoke-ExecAppApprovalTemplate { # Create output object preserving original structure $outputObject = $templateData | Select-Object -Property * - # Add the TemplateId (RowKey) to the output - $outputObject | Add-Member -NotePropertyName 'TemplateId' -NotePropertyValue $_.RowKey -Force - - # Add timestamp from the table entity - $outputObject | Add-Member -NotePropertyName 'Timestamp' -NotePropertyValue $_.Timestamp.DateTime.ToString('yyyy-MM-ddTHH:mm:ssZ') -Force + $outputObject | Add-Member -NotePropertyMembers ([ordered]@{ + # Add the TemplateId (RowKey) to the output + TemplateId = $_.RowKey + # Add timestamp from the table entity + Timestamp = $_.Timestamp.DateTime.ToString('yyyy-MM-ddTHH:mm:ssZ') + }) -Force return $outputObject } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Application Approval/Invoke-ExecApplication.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Application Approval/Invoke-ExecApplication.ps1 index 6436c66157592..8cabce7bf585e 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Application Approval/Invoke-ExecApplication.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Application Approval/Invoke-ExecApplication.ps1 @@ -7,8 +7,10 @@ function Invoke-ExecApplication { #> [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers $ValidTypes = @('applications', 'servicePrincipals') - $ValidActions = @('Update', 'Upsert', 'Delete', 'RemoveKey', 'RemovePassword') + $ValidActions = @('Update', 'Upsert', 'Delete', 'RemoveKey', 'RemovePassword', 'Hide', 'Show') $Id = $Request.Query.Id ?? $Request.Body.Id $Type = $Request.Query.Type ?? $Request.Body.Type @@ -95,6 +97,7 @@ function Invoke-ExecApplication { state = 'success' details = @($Response) } + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Results.resultText -Sev 'Info' } else { # For password credentials, use bulk removePassword requests $BulkRequests = foreach ($KeyId in $KeyIds) { @@ -123,14 +126,49 @@ function Invoke-ExecApplication { state = if ($FailureCount -eq 0) { 'success' } else { 'error' } details = @($BulkResults) } + if ($FailureCount -eq 0) { + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Results.resultText -Sev 'Info' + } else { + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Results.resultText -Sev 'Error' + } + } + } elseif ($Action -eq 'Hide' -or $Action -eq 'Show') { + # MyApps portal visibility is stored as the 'HideApp' string in the service + # principal 'tags' collection. tags is a replace-collection on PATCH, so read the + # current tags and add/remove only HideApp to avoid clobbering the other tags + # (e.g. WindowsAzureActiveDirectoryIntegratedApp, which marks the app as SSO-integrated). + $Hidden = $Action -eq 'Hide' + $CurrentObject = New-GraphGetRequest -Uri $Uri -tenantid $TenantFilter -AsApp $true + # Rebuild the collection in a single @() subexpression (no in-place array growth): + # keep every tag except HideApp, then append HideApp only when hiding. + $Tags = @( + $CurrentObject.tags | Where-Object { $_ -ne 'HideApp' } + if ($Hidden) { 'HideApp' } + ) + # Encode each tag individually and wrap in brackets so tags is always a JSON array: + # a whole-collection ConvertTo-Json collapses a single-element array to a scalar (Graph + # rejects it) and emits nothing for an empty array. This handles 0, 1 and many tags. + $TagsJson = '[' + (($Tags | ForEach-Object { ConvertTo-Json -InputObject $_ -Compress }) -join ',') + ']' + $PatchBody = '{{"tags":{0}}}' -f $TagsJson + $null = New-GraphPOSTRequest -Uri $Uri -Type 'PATCH' -Body $PatchBody -tenantid $TenantFilter -AsApp $true + + $Results = @{ + resultText = if ($Hidden) { + "Hid '$($CurrentObject.displayName)' from the MyApps portal" + } else { + "Made '$($CurrentObject.displayName)' visible in the MyApps portal" + } + state = 'success' } + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Results.resultText -Sev 'Info' } else { - # Handle regular actions + # Handle regular actions (Update, Upsert, Delete) $null = New-GraphPOSTRequest @PostParams -tenantid $TenantFilter -AsApp $true $Results = @{ resultText = "Successfully executed $Action on $Type with Id: $Id" state = 'success' } + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Results.resultText -Sev 'Info' } return ([HttpResponseContext]@{ @@ -138,10 +176,12 @@ function Invoke-ExecApplication { Body = @{ Results = $Results } }) } catch { + $ErrorMessage = Get-CippException -Exception $_ $Results = @{ - resultText = "Failed to execute $Action on $Type with Id: $Id. Error: $($_.Exception.Message)" + resultText = "Failed to execute $Action on $Type with Id: $Id. Error: $($ErrorMessage.NormalizedError)" state = 'error' } + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Results.resultText -Sev 'Error' -LogData $ErrorMessage return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::InternalServerError diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-AddTenant.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-AddTenant.ps1 index 3d83a04a2bd6d..87086a1ad8d93 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-AddTenant.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-AddTenant.ps1 @@ -7,6 +7,7 @@ function Invoke-AddTenant { #> [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint $Headers = $Request.Headers @@ -78,10 +79,12 @@ function Invoke-AddTenant { } if (!$CanCreateCustomers) { + $Result = 'You do not have permission to create customers. You must be a Tier 1 or Tier 2 CSP.' + Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' $Body = @{ - $Results = @(@{ + Results = @(@{ state = 'error' - resultText = 'You do not have permission to create customers. You must be a Tier 1 or Tier 2 CSP.' + resultText = $Result }) } } else { @@ -147,6 +150,8 @@ function Invoke-AddTenant { #### + $Result = "Tenant created successfully for $TenantName.onmicrosoft.com (username: $($Response.userCredentials.userName)@$TenantName.onmicrosoft.com)" + Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Info' $Body = @{ Results = @(@{ state = 'success' @@ -155,10 +160,13 @@ function Invoke-AddTenant { }) } } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to create tenant: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -message $Result -Sev 'Error' -LogData $ErrorMessage $Body = @{ Results = @(@{ state = 'error' - resultText = "Failed to create tenant: $($_.Exception.Message)" + resultText = $Result }) } $StatusCode = [HttpStatusCode]::BadRequest diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-EditTenant.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-EditTenant.ps1 index 1f034f561df2f..f1e53408b8749 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-EditTenant.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-EditTenant.ps1 @@ -38,6 +38,7 @@ function Invoke-EditTenant { Write-Host 'Removing alias' Remove-CIPPAzDataTableEntity @PropertiesTable -Entity $AliasEntity $null = Get-Tenants -TenantFilter $customerId -TriggerRefresh + Write-LogMessage -headers $Headers -API $APIName -tenant $Tenant.defaultDomainName -TenantId $Tenant.customerId -message "Removed tenant alias for $($Tenant.defaultDomainName)" -Sev 'Info' } } else { $aliasEntity = @{ @@ -50,11 +51,16 @@ function Invoke-EditTenant { $Tenant | Add-Member -NotePropertyName 'originalDisplayName' -NotePropertyValue $tenant.displayName -Force $Tenant.displayName = $tenantAlias $null = Add-CIPPAzDataTableEntity @TenantTable -Entity $Tenant -Force + Write-LogMessage -headers $Headers -API $APIName -tenant $Tenant.defaultDomainName -TenantId $Tenant.customerId -message "Set tenant alias to '$tenantAlias'" -Sev 'Info' } # Update tenant groups $GroupTable = Get-CippTable -TableName 'TenantGroups' - $StaticGroups = Get-CIPPAzDataTableEntity @GroupTable -Filter "PartitionKey eq 'TenantGroup' and GroupType ne 'dynamic'" + # Table-service comparisons skip entities missing the property, so a server-side + # "GroupType ne 'dynamic'" drops static groups created before GroupType existed and + # they can never be added or removed here - treat a missing GroupType as static instead + $AllGroups = Get-CIPPAzDataTableEntity @GroupTable -Filter "PartitionKey eq 'TenantGroup'" + $StaticGroups = $AllGroups | Where-Object { $_.GroupType -ne 'dynamic' } $StaticGroupIds = $StaticGroups.RowKey $CurrentGroupMemberships = Get-CIPPAzDataTableEntity @GroupMembersTable -Filter "customerId eq '$customerId'" foreach ($Group in $tenantGroups) { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-ExecAddSPN.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-ExecAddSPN.ps1 index 966ecb0072e90..e1fd10c4b39b5 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-ExecAddSPN.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-ExecAddSPN.ps1 @@ -16,6 +16,7 @@ Function Invoke-ExecAddSPN { try { $null = New-GraphPostRequest -uri 'https://graph.microsoft.com/v1.0/servicePrincipals' -tenantid $env:TenantID -type POST -Body "{ `"appId`": `"2832473f-ec63-45fb-976f-5d45a7d4bb91`" }" -NoAuthCheck $true $Result = "Successfully completed request. Add your GDAP migration permissions to your SAM application here: https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/CallAnAPI/appId/$($env:ApplicationID)/isMSAApp/ " + Write-LogMessage -headers $Headers -API $APIName -tenant $env:TenantID -message 'Successfully added GDAP migration service principal (SPN)' -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-ExecOnboardTenant.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-ExecOnboardTenant.ps1 index 78199c7cc1e65..e0758ab8eb28d 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-ExecOnboardTenant.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-ExecOnboardTenant.ps1 @@ -31,6 +31,14 @@ function Invoke-ExecOnboardTenant { $TenMinutesAgo = (Get-Date).AddMinutes(-10).ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:ssZ') $TenantOnboarding = Get-CIPPAzDataTableEntity @OnboardTable -Filter "RowKey eq '$SafeId' and Timestamp ge datetime'$TenMinutesAgo'" if (!$TenantOnboarding -or [bool]$Request.Body.Retry) { + # Recover exclude flag from any prior row before overwrite (poll restarts omit it from the body) + $ExistingOnboarding = Get-CIPPAzDataTableEntity @OnboardTable -Filter "RowKey eq '$SafeId'" + if ($Request.Body.PSObject.Properties.Name -contains 'standardsExcludeAllTenants') { + $StandardsExcludeAllTenants = [bool]$Request.Body.standardsExcludeAllTenants + } else { + $StandardsExcludeAllTenants = [bool]$ExistingOnboarding.StandardsExcludeAllTenants + } + $OnboardingSteps = [PSCustomObject]@{ 'Step1' = @{ 'Status' = 'pending' @@ -59,14 +67,15 @@ function Invoke-ExecOnboardTenant { } } $TenantOnboarding = [PSCustomObject]@{ - PartitionKey = 'Onboarding' - RowKey = [string]$SafeId - CustomerId = '' - Status = 'queued' - OnboardingSteps = [string](ConvertTo-Json -InputObject $OnboardingSteps -Compress) - Relationship = '' - Logs = '' - Exception = '' + PartitionKey = 'Onboarding' + RowKey = [string]$SafeId + CustomerId = '' + Status = 'queued' + OnboardingSteps = [string](ConvertTo-Json -InputObject $OnboardingSteps -Compress) + Relationship = '' + Logs = '' + Exception = '' + StandardsExcludeAllTenants = $StandardsExcludeAllTenants } Add-CIPPAzDataTableEntity @OnboardTable -Entity $TenantOnboarding -Force -ErrorAction Stop @@ -77,7 +86,7 @@ function Invoke-ExecOnboardTenant { AddMissingGroups = $Request.Body.addMissingGroups IgnoreMissingRoles = $Request.Body.ignoreMissingRoles AutoMapRoles = $Request.Body.autoMapRoles - StandardsExcludeAllTenants = $Request.Body.standardsExcludeAllTenants + StandardsExcludeAllTenants = $StandardsExcludeAllTenants } $InputObject = @{ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-ExecSendOrgMessage.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-ExecSendOrgMessage.ps1 index 65336dcd7486d..f02e274815bcf 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-ExecSendOrgMessage.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-ExecSendOrgMessage.ps1 @@ -7,12 +7,15 @@ Function Invoke-ExecSendOrgMessage { #> [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers # Interact with query parameters or the body of the request. $TenantFilter = $Request.Query.TenantFilter $Device = $request.query.ID + $MessageType = $request.Query.type try { - $type = switch ($request.Query.type) { + $type = switch ($MessageType) { 'taskbar' { '844ec9d0-dd31-459c-a1e7-21fb1b39d5da' $placementDetails = @(@{ @@ -99,11 +102,15 @@ Function Invoke-ExecSendOrgMessage { Write-Host $tmpbody $GraphRequest = New-GraphPOSTRequest -noauthcheck $true -type 'POST' -uri 'https://graph.microsoft.com/beta/deviceManagement/organizationalMessageDetails' -tenantid $tenantfilter -body $tmpbody + $Result = "Successfully sent organizational message of type '$MessageType'" + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { - $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to send organizational message of type '$MessageType': $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -tenant $TenantFilter -message $Result -Sev 'Error' -LogData $ErrorMessage $StatusCode = [HttpStatusCode]::Forbidden - $GraphRequest = $ErrorMessage + $GraphRequest = $ErrorMessage.NormalizedError } return [HttpResponseContext]@{ StatusCode = $StatusCode diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-RemoveTenantCapabilitiesCache.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-RemoveTenantCapabilitiesCache.ps1 index 776386a3101f1..1880fff66a9c6 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-RemoveTenantCapabilitiesCache.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Administration/Tenant/Invoke-RemoveTenantCapabilitiesCache.ps1 @@ -12,8 +12,8 @@ function Invoke-RemoveTenantCapabilitiesCache { $Headers = $Request.Headers - # Get the tenant identifier from query parameters - $DefaultDomainName = $Request.Query.defaultDomainName + # Get the tenant identifier from the request body (POST) or query (legacy GET). + $DefaultDomainName = $Request.Body.defaultDomainName ?? $Request.Query.defaultDomainName if (-not $DefaultDomainName) { $body = [pscustomobject]@{'Results' = 'Missing required parameter: defaultDomainName' } $StatusCode = [HttpStatusCode]::BadRequest diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-AddCATemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-AddCATemplate.ps1 index 4bbd5ad79df3d..0daa40288a518 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-AddCATemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-AddCATemplate.ps1 @@ -27,13 +27,13 @@ Function Invoke-AddCATemplate { GUID = "$GUID" } $Result = "Created CA Template $($Name) with GUID $GUID" - Write-LogMessage -headers $Headers -API $APIName -message "Created CA Template $($Name) with GUID $GUID" -Sev 'Debug' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Created CA Template $($Name) with GUID $GUID" -Sev 'Info' $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ $Result = "Failed to create CA Template: $($ErrorMessage.NormalizedError)" - Write-LogMessage -headers $Headers -API $APIName -message "Failed to create CA Template: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Failed to create CA Template: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage $StatusCode = [HttpStatusCode]::InternalServerError } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ExecCAExclusion.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ExecCAExclusion.ps1 index 834ba2df0ff51..0543359359db6 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ExecCAExclusion.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ExecCAExclusion.ps1 @@ -185,12 +185,15 @@ function Invoke-ExecCAExclusion { Reference = $Request.Body.reference } Add-CIPPScheduledTask -Task $TravelRemoveTask -hidden $false - $Results += "Successfully scheduled temporary travel policy '$TravelPolicyName' restricting sign-ins to $($TravelCountries -join ', '). The policy and named location will be removed at the end date." + $TravelResult = "Successfully scheduled temporary travel policy '$TravelPolicyName' restricting sign-ins to $($TravelCountries -join ', '). The policy and named location will be removed at the end date." + Write-LogMessage -headers $Headers -API 'Invoke-ExecCAExclusion' -message $TravelResult -Sev 'Info' -tenant $TenantFilter + $Results += $TravelResult } if ($DuplicateGroupWarning) { $Results += $DuplicateGroupWarning } + Write-LogMessage -headers $Headers -API 'Invoke-ExecCAExclusion' -message "Successfully added vacation mode schedule for $Username on policy '$PolicyName'." -Sev 'Info' -tenant $TenantFilter $body = @{ Results = $Results } } else { $Parameters = @{ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ListCAtemplates.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ListCAtemplates.ps1 index 7c08fb3741ed4..f15d37c9ef3c2 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ListCAtemplates.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ListCAtemplates.ps1 @@ -48,10 +48,12 @@ function Invoke-ListCAtemplates { templates = @($packageTemplates | ForEach-Object { try { $data = $_.JSON | ConvertFrom-Json -Depth 100 -ErrorAction SilentlyContinue - $data | Add-Member -NotePropertyName 'GUID' -NotePropertyValue $_.GUID -Force - $data | Add-Member -NotePropertyName 'package' -NotePropertyValue $_.Package -Force - $data | Add-Member -NotePropertyName 'source' -NotePropertyValue $_.Source -Force - $data | Add-Member -NotePropertyName 'isSynced' -NotePropertyValue (![string]::IsNullOrEmpty($_.SHA)) -Force + $data | Add-Member -NotePropertyMembers ([ordered]@{ + GUID = $_.GUID + package = $_.Package + source = $_.Source + isSynced = (![string]::IsNullOrEmpty($_.SHA)) + }) -Force $data } catch { } @@ -71,10 +73,12 @@ function Invoke-ListCAtemplates { try { $row = $_ $data = $row.JSON | ConvertFrom-Json -Depth 100 -ErrorAction Stop - $data | Add-Member -NotePropertyName 'GUID' -NotePropertyValue $row.GUID -Force - $data | Add-Member -NotePropertyName 'source' -NotePropertyValue $row.Source -Force - $data | Add-Member -NotePropertyName 'isSynced' -NotePropertyValue (![string]::IsNullOrEmpty($row.SHA)) -Force - $data | Add-Member -NotePropertyName 'package' -NotePropertyValue $row.Package -Force + $data | Add-Member -NotePropertyMembers ([ordered]@{ + GUID = $row.GUID + source = $row.Source + isSynced = (![string]::IsNullOrEmpty($row.SHA)) + package = $row.Package + }) -Force $data } catch { Write-Warning "Failed to process CA template: $($row.RowKey) - $($_.Exception.Message)" diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ListConditionalAccessPolicies.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ListConditionalAccessPolicies.ps1 index 09ff7e2b6b290..2a30b47017737 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ListConditionalAccessPolicies.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ListConditionalAccessPolicies.ps1 @@ -5,7 +5,7 @@ function Invoke-ListConditionalAccessPolicies { .ROLE Tenant.ConditionalAccess.Read .DESCRIPTION - Lists Conditional Access policies for a tenant with resolved display names for users, groups, applications, and locations. + Lists Conditional Access policies for a tenant with resolved display names for users, groups, applications, and locations. When manualPagination is set on an AllTenants read, one page is returned per request with a continuation token in Metadata.nextLink. #> [CmdletBinding()] param($Request, $TriggerMetadata) @@ -200,8 +200,22 @@ function Invoke-ListConditionalAccessPolicies { # AllTenants functionality $Table = Get-CIPPTable -TableName cacheCAPolicies $PartitionKey = 'CAPolicy' - $Filter = "PartitionKey eq '$PartitionKey'" - $Rows = Get-CIPPAzDataTableEntity @Table -filter $Filter | Where-Object -Property Timestamp -GT (Get-Date).AddMinutes(-60) + # Return one page per request with a continuation token in Metadata.nextLink; AllTenants reads only. + $ManualPagination = $Request.Query.manualPagination -and [System.Convert]::ToBoolean($Request.Query.manualPagination) + if ($ManualPagination) { + # Rows per page, clamped between 250 and 10000. Defaults to 5000. + $PageSize = 5000 + if ($Request.Query.PageSize -as [int]) { + $PageSize = [Math]::Min([Math]::Max([int]$Request.Query.PageSize, 250), 10000) + } + $FreshClause = "Timestamp ge datetime'{0}'" -f (Get-Date).AddMinutes(-60).ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:ss.fffK') + # Continuation token from the previous page's Metadata.nextLink; opaque to callers. + $Page = Get-CIPPPagedTableRows -Table $Table -PartitionKeys @($PartitionKey) -PageSize $PageSize -ContinuationToken $Request.Query.nextLink -ExtraFilterClauses @($FreshClause) + $Rows = @($Page.Rows) + } else { + $Filter = "PartitionKey eq '$PartitionKey'" + $Rows = Get-CIPPAzDataTableEntity @Table -filter $Filter | Where-Object -Property Timestamp -GT (Get-Date).AddMinutes(-60) + } $QueueReference = '{0}-{1}' -f $TenantFilter, $PartitionKey $RunningQueue = Get-CIPPQueueData -Reference $QueueReference | Where-Object { $_.Status -notmatch 'Completed' -and $_.Status -notmatch 'Failed' } # If a queue is running, we will not start a new one @@ -210,7 +224,7 @@ function Invoke-ListConditionalAccessPolicies { QueueMessage = 'Still loading data for all tenants. Please check back in a few more minutes' QueueId = $RunningQueue.RowKey } - } elseif (!$Rows -and !$RunningQueue) { + } elseif (!$Rows -and !$RunningQueue -and !$Request.Query.nextLink) { # If no rows are found and no queue is running, we will start a new one $TenantList = Get-Tenants -IncludeErrors $Queue = New-CippQueueEntry -Name 'Conditional Access Policies - All Tenants' -Link '/tenant/conditional/list-policies?customerId=AllTenants' -Reference $QueueReference -TotalTasks ($TenantList | Measure-Object).Count @@ -235,11 +249,26 @@ function Invoke-ListConditionalAccessPolicies { $Metadata = [PSCustomObject]@{ QueueId = $RunningQueue.RowKey ?? $null } - $Policies = $Rows | Select-CippAllowedTenantData -TenantProperty 'Tenant' - # Output all policies from all tenants the caller is allowed to see - foreach ($policy in $Policies) { - ($policy.Policy | ConvertFrom-Json) + if ($ManualPagination -and $Page.NextToken) { + $Metadata | Add-Member -NotePropertyName 'nextLink' -NotePropertyValue $Page.NextToken + } + # Each cached Policy blob is already the final shape; stitch the allowed rows + # into Results verbatim instead of parsing and letting Craft re-serialize. + $AllowedRows = @($Rows | Select-CippAllowedTenantData -TenantProperty 'Tenant') + $JsonParts = [System.Collections.Generic.List[string]]::new($AllowedRows.Count) + foreach ($Row in $AllowedRows) { + $Blob = [string]$Row.Policy + if ([string]::IsNullOrWhiteSpace($Blob)) { continue } + $Blob = $Blob.Trim() + if ($Blob[0] -eq '{' -or $Blob[0] -eq '[') { $JsonParts.Add($Blob) } } + $ResultsJson = '[' + ($JsonParts -join ',') + ']' + $MetadataJson = ConvertTo-Json -InputObject $Metadata -Depth 5 -Compress + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + ContentType = 'application/json' + Body = '{"Results":' + $ResultsJson + ',"Metadata":' + $MetadataJson + '}' + }) } } $StatusCode = [HttpStatusCode]::OK diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecAddGDAPRole.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecAddGDAPRole.ps1 index f02dff9d052be..ab6cae75ea7d2 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecAddGDAPRole.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecAddGDAPRole.ps1 @@ -7,6 +7,8 @@ function Invoke-ExecAddGDAPRole { #> [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers $Action = $Request.Body.Action ?? $Request.Query.Action ?? 'AddRoleSimple' $GroupBlockList = @('All Users', 'AdminAgents', 'HelpdeskAgents', 'SalesAgents') @@ -16,155 +18,111 @@ function Invoke-ExecAddGDAPRole { $Results = @($Groups) } 'AddRoleAdvanced' { - $Mappings = $Request.Body.mappings - $Table = Get-CIPPTable -TableName 'GDAPRoles' - $ExistingGroups = New-GraphGetRequest -NoAuthCheck $True -uri 'https://graph.microsoft.com/beta/groups?$filter=securityEnabled eq true&$select=id,displayName&$top=999' -tenantid $env:TenantID -AsApp $true - $Results = [System.Collections.Generic.List[object]]::new() - $ErrorsFound = $false - $Entities = foreach ($Mapping in $Mappings) { - $GroupId = $Mapping.GroupId - if ($ExistingGroups.id -contains $GroupId) { - $ExistingGroup = $ExistingGroups | Where-Object -Property id -EQ $GroupId - if ($ExistingGroup.displayName -in $GroupBlockList) { - $Results.Add(@{ - state = 'error' - resultText = "Group $($ExistingGroup.displayName) is a reserved group and cannot be mapped to a GDAP role" - }) - $ErrorsFound = $true - } else { - @{ - PartitionKey = 'Roles' - RowKey = $GroupId - RoleName = $Mapping.RoleName - GroupName = $ExistingGroup.displayName - GroupId = $GroupId - roleDefinitionId = $Mapping.roleDefinitionId + try { + $Mappings = $Request.Body.mappings + $Table = Get-CIPPTable -TableName 'GDAPRoles' + $ExistingGroups = New-GraphGetRequest -NoAuthCheck $True -uri 'https://graph.microsoft.com/beta/groups?$filter=securityEnabled eq true&$select=id,displayName&$top=999' -tenantid $env:TenantID -AsApp $true + $Results = [System.Collections.Generic.List[object]]::new() + $ErrorsFound = $false + $Entities = foreach ($Mapping in $Mappings) { + $GroupId = $Mapping.GroupId + if ($ExistingGroups.id -contains $GroupId) { + $ExistingGroup = $ExistingGroups | Where-Object -Property id -EQ $GroupId + if ($ExistingGroup.displayName -in $GroupBlockList) { + $Results.Add(@{ + state = 'error' + resultText = "Group $($ExistingGroup.displayName) is a reserved group and cannot be mapped to a GDAP role" + }) + $ErrorsFound = $true + } else { + @{ + PartitionKey = 'Roles' + RowKey = $GroupId + RoleName = $Mapping.RoleName + GroupName = $ExistingGroup.displayName + GroupId = $GroupId + roleDefinitionId = $Mapping.roleDefinitionId + } + $Results.Add(@{ + state = 'success' + resultText = "Mapped $($ExistingGroup.displayName) to $($Mapping.RoleName)" + }) } - $Results.Add(@{ - state = 'success' - resultText = "Mapped $($ExistingGroup.displayName) to $($Mapping.RoleName)" - }) } } - } - if (($Entities | Measure-Object).Count -gt 0) { - Write-Warning "Adding $($Entities.Count) entities to table" - Write-Information ($Entities | ConvertTo-Json -Depth 10 -Compress) - Add-CIPPAzDataTableEntity @Table -Entity $Entities -Force - } elseif ($ErrorsFound -eq $false) { - $Results.Add(@{ - state = 'success' - resultText = 'All role mappings already exist' + if (($Entities | Measure-Object).Count -gt 0) { + Write-Warning "Adding $($Entities.Count) entities to table" + Write-Information ($Entities | ConvertTo-Json -Depth 10 -Compress) + Add-CIPPAzDataTableEntity @Table -Entity $Entities -Force + $Result = "Added $($Entities.Count) GDAP role mapping(s)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' + } elseif ($ErrorsFound -eq $false) { + $Results.Add(@{ + state = 'success' + resultText = 'All role mappings already exist' + }) + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message 'All GDAP role mappings already exist' -Sev 'Info' + } else { + $Result = 'Failed to add GDAP role mappings: reserved groups cannot be mapped' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to add GDAP role mappings: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' -LogData $ErrorMessage + $Results = @(@{ + state = 'error' + resultText = $Result }) } } 'AddRoleSimple' { - $CippDefaults = @( - @{ label = 'Application Administrator'; value = '9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3' }, - @{ label = 'User Administrator'; value = 'fe930be7-5e62-47db-91af-98c3a49a38b1' }, - @{ label = 'Intune Administrator'; value = '3a2c62db-5318-420d-8d74-23affee5d9d5' }, - @{ label = 'Exchange Administrator'; value = '29232cdf-9323-42fd-ade2-1d097af3e4de' }, - @{ label = 'Security Administrator'; value = '194ae4cb-b126-40b2-bd5b-6091b380977d' }, - @{ label = 'Cloud App Security Administrator'; value = '892c5842-a9a6-463a-8041-72aa08ca3cf6' }, - @{ label = 'Cloud Device Administrator'; value = '7698a772-787b-4ac8-901f-60d6b08affd2' }, - @{ label = 'Teams Administrator'; value = '69091246-20e8-4a56-aa4d-066075b2a7a8' }, - @{ label = 'SharePoint Administrator'; value = 'f28a1f50-f6e7-4571-818b-6a12f2af6b6c' }, - @{ label = 'Authentication Policy Administrator'; value = '0526716b-113d-4c15-b2c8-68e3c22b9f80' }, - @{ label = 'Privileged Role Administrator'; value = 'e8611ab8-c189-46e8-94e1-60213ab1f814' }, - @{ label = 'Privileged Authentication Administrator'; value = '7be44c8a-adaf-4e2a-84d6-ab2649e08a13' }, - @{ label = 'Billing Administrator'; value = 'b0f54661-2d74-4c50-afa3-1ec803f12efe' }, - @{ label = 'Global Reader'; value = 'f2ef992c-3afb-46b9-b7cf-a126ee74c451' }, - @{ label = 'Domain Name Administrator'; value = '8329153b-31d0-4727-b945-745eb3bc5f31' } - ) - - $Groups = $Request.Body.gdapRoles ?? $CippDefaults + try { + $CippDefaults = @( + @{ label = 'Application Administrator'; value = '9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3' }, + @{ label = 'User Administrator'; value = 'fe930be7-5e62-47db-91af-98c3a49a38b1' }, + @{ label = 'Intune Administrator'; value = '3a2c62db-5318-420d-8d74-23affee5d9d5' }, + @{ label = 'Exchange Administrator'; value = '29232cdf-9323-42fd-ade2-1d097af3e4de' }, + @{ label = 'Security Administrator'; value = '194ae4cb-b126-40b2-bd5b-6091b380977d' }, + @{ label = 'Cloud App Security Administrator'; value = '892c5842-a9a6-463a-8041-72aa08ca3cf6' }, + @{ label = 'Cloud Device Administrator'; value = '7698a772-787b-4ac8-901f-60d6b08affd2' }, + @{ label = 'Teams Administrator'; value = '69091246-20e8-4a56-aa4d-066075b2a7a8' }, + @{ label = 'SharePoint Administrator'; value = 'f28a1f50-f6e7-4571-818b-6a12f2af6b6c' }, + @{ label = 'Authentication Policy Administrator'; value = '0526716b-113d-4c15-b2c8-68e3c22b9f80' }, + @{ label = 'Privileged Role Administrator'; value = 'e8611ab8-c189-46e8-94e1-60213ab1f814' }, + @{ label = 'Privileged Authentication Administrator'; value = '7be44c8a-adaf-4e2a-84d6-ab2649e08a13' }, + @{ label = 'Billing Administrator'; value = 'b0f54661-2d74-4c50-afa3-1ec803f12efe' }, + @{ label = 'Global Reader'; value = 'f2ef992c-3afb-46b9-b7cf-a126ee74c451' }, + @{ label = 'Domain Name Administrator'; value = '8329153b-31d0-4727-b945-745eb3bc5f31' } + ) - $CustomSuffix = $Request.Body.customSuffix - $Table = Get-CIPPTable -TableName 'GDAPRoles' + $Groups = $Request.Body.gdapRoles ?? $CippDefaults + $CustomSuffix = $Request.Body.customSuffix - $Results = [System.Collections.Generic.List[string]]::new() - $Requests = [System.Collections.Generic.List[object]]::new() - $ExistingGroups = New-GraphGetRequest -NoAuthCheck $True -uri 'https://graph.microsoft.com/beta/groups' -tenantid $env:TenantID -AsApp $true + $Mapping = New-CIPPGDAPRoleMapping -Roles $Groups -CustomSuffix $CustomSuffix + $Results = $Mapping.Results + $RoleMappings = $Mapping.RoleMappings - $ExistingRoleMappings = foreach ($Group in $Groups) { - $RoleName = $Group.label ?? $Group.Name - $Value = $Group.value ?? $Group.ObjectId - - if ($CustomSuffix) { - $GroupName = "M365 GDAP $($RoleName) - $CustomSuffix" - $MailNickname = "M365GDAP$(($RoleName).replace(' ',''))$($CustomSuffix.replace(' ',''))" - } else { - $GroupName = "M365 GDAP $($RoleName)" - $MailNickname = "M365GDAP$(($RoleName).replace(' ',''))" - } - - if ($GroupName -in $ExistingGroups.displayName) { - @{ - PartitionKey = 'Roles' - RowKey = ($ExistingGroups | Where-Object -Property displayName -EQ $GroupName | Select-Object -First 1).id - RoleName = $RoleName - GroupName = $GroupName - GroupId = ($ExistingGroups | Where-Object -Property displayName -EQ $GroupName | Select-Object -First 1).id - roleDefinitionId = $Value - } - $Results.Add("$GroupName already exists") + $Created = @($Results | Where-Object { $_ -like 'Created *' }) + $Failed = @($Results | Where-Object { $_ -like 'Could not create GDAP group:*' }) + if ($Failed.Count -gt 0) { + $Result = "GDAP role mapping completed with errors. Created: $($Created.Count), Failed: $($Failed.Count)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' } else { - $Requests.Add(@{ - id = $Value - url = '/groups' - method = 'POST' - headers = @{ - 'Content-Type' = 'application/json' - } - body = @{ - displayName = $GroupName - description = "This group is used to manage M365 partner tenants at the $($RoleName) level." - securityEnabled = $true - mailEnabled = $false - mailNickname = $MailNickname - } - }) + $Result = "GDAP role mapping completed. Groups created/reused: $($RoleMappings.Count)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' } - } - if ($ExistingRoleMappings) { - Add-CIPPAzDataTableEntity @Table -Entity $ExistingRoleMappings -Force - } - if ($Requests) { - $ReturnedData = New-GraphBulkRequest -Requests $Requests -tenantid $env:TenantID -NoAuthCheck $True -asapp $true - $NewRoleMappings = foreach ($Return in $ReturnedData) { - if ($Return.body.error) { - $Results.Add("Could not create GDAP group: $($Return.body.error.message)") - } else { - $GroupName = $Return.body.displayName - @{ - PartitionKey = 'Roles' - RowKey = $Return.body.id - RoleName = $Return.body.displayName -replace '^M365 GDAP ', '' -replace " - $CustomSuffix$", '' - GroupName = $Return.body.displayName - GroupId = $Return.body.id - roleDefinitionId = $Return.id - } - $Results.Add("Created $($GroupName)") - } + if ($Request.Body.templateId) { + # Add-CIPPGDAPRoleTemplate already writes customer-visible logs for the template path + Add-CIPPGDAPRoleTemplate -Headers $Request.Headers -TemplateId $Request.Body.templateId -RoleMappings ($RoleMappings | Select-Object -Property RoleName, GroupName, GroupId, roleDefinitionId) + $Results.Add("Added role mappings to template $($Request.Body.templateId)") } - Write-Information ($NewRoleMappings | ConvertTo-Json -Depth 10 -Compress) - if ($NewRoleMappings) { - Add-CIPPAzDataTableEntity @Table -Entity $NewRoleMappings -Force - } - } - - $RoleMappings = [System.Collections.Generic.List[object]]::new() - if ($ExistingRoleMappings) { - $RoleMappings.AddRange(@($ExistingRoleMappings)) - } - if ($NewRoleMappings) { - $RoleMappings.AddRange(@($NewRoleMappings)) - } - - if ($Request.Body.templateId) { - Add-CIPPGDAPRoleTemplate -TemplateId $Request.Body.templateId -RoleMappings ($RoleMappings | Select-Object -Property RoleName, GroupName, GroupId, roleDefinitionId) - $Results.Add("Added role mappings to template $($Request.Body.templateId)") + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Failed to add GDAP roles: $($ErrorMessage.NormalizedError)" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Error' -LogData $ErrorMessage + $Results = @($Result) } } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPAccessAssignment.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPAccessAssignment.ps1 index 41155b7e5d81b..4b64b0235f5e8 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPAccessAssignment.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPAccessAssignment.ps1 @@ -167,11 +167,13 @@ function Invoke-ExecGDAPAccessAssignment { $Results = foreach ($Result in $BulkResults) { $Message = $Messages | Where-Object id -EQ $Result.id if ($Result.status -in @('201', '202', '204')) { + Write-LogMessage -headers $Request.Headers -API $APIName -tenant 'Global' -message $Message.message -Sev 'Info' @{ resultText = $Message.message state = 'success' } } else { + Write-LogMessage -headers $Request.Headers -API $APIName -tenant 'Global' -message "Error: $($Message.message): $($Result.body.error.message)" -Sev 'Error' @{ resultText = "Error: $($Message.message): $($Result.body.error.message)" state = 'error' @@ -184,6 +186,7 @@ function Invoke-ExecGDAPAccessAssignment { resultText = 'This relationship already has the correct access assignments' state = 'success' } + Write-LogMessage -headers $Request.Headers -API $APIName -tenant 'Global' -message 'GDAP access assignments already correct; no changes applied' -Sev 'Info' } else { $Results = @() } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPInviteApproved.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPInviteApproved.ps1 index 39f5b4e3a32dd..1fd5f61191811 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPInviteApproved.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPInviteApproved.ps1 @@ -7,12 +7,24 @@ Function Invoke-ExecGDAPInviteApproved { #> [CmdletBinding()] param($Request, $TriggerMetadata) - Set-CIPPGDAPInviteGroups - $body = @{Results = @('Processing recently activated GDAP relationships') } + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + try { + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message 'Started processing recently activated GDAP relationships' -Sev 'Info' + Set-CIPPGDAPInviteGroups + $body = @{Results = @('Processing recently activated GDAP relationships') } + $StatusCode = [HttpStatusCode]::OK + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Failed to process recently activated GDAP relationships: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage + $body = @{Results = @("Failed to process recently activated GDAP relationships: $($ErrorMessage.NormalizedError)") } + $StatusCode = [HttpStatusCode]::InternalServerError + } return ([HttpResponseContext]@{ - StatusCode = [HttpStatusCode]::OK + StatusCode = $StatusCode Body = $body }) diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPRepairRoleMappings.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPRepairRoleMappings.ps1 index 2421e3a14218c..fc93ef2cd8476 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPRepairRoleMappings.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPRepairRoleMappings.ps1 @@ -15,16 +15,27 @@ function Invoke-ExecGDAPRepairRoleMappings { $Results = [System.Collections.Generic.List[object]]::new() try { - # Fetch the partner tenant security groups once and reuse them for every store we repair - $PartnerGroups = New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/groups?$filter=securityEnabled eq true&$select=id,displayName&$top=999' -tenantid $env:TenantID -NoAuthCheck $true -AsApp $true + # Fetch the partner tenant security groups once and reuse them for every store we repair. + # Groups recreated by one pass are appended so later passes re-link instead of creating duplicates. + $PartnerGroups = [System.Collections.Generic.List[object]]::new() + foreach ($Group in (New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/groups?$filter=securityEnabled eq true&$select=id,displayName&$top=999' -tenantid $env:TenantID -NoAuthCheck $true -AsApp $true)) { + $PartnerGroups.Add($Group) + } + $AddCreatedGroups = { + param($Check) + foreach ($Created in ($Check.Results | Where-Object { $_.Status -eq 'Created' })) { + $PartnerGroups.Add([PSCustomObject]@{ id = $Created.GroupId; displayName = $Created.GroupName }) + } + } # Repair the GDAPRoles registry (stale group ids are remapped to the existing "M365 GDAP" group) $RolesTable = Get-CIPPTable -TableName 'GDAPRoles' $StoredRoles = Get-CIPPAzDataTableEntity @RolesTable -Filter "PartitionKey eq 'Roles'" if (($StoredRoles | Measure-Object).Count -gt 0) { - $RoleCheck = Test-CIPPGDAPGroupMappings -RoleMappings $StoredRoles -PartnerGroups $PartnerGroups -WriteBack -APIName $APIName -Headers $Headers + $RoleCheck = Test-CIPPGDAPGroupMappings -RoleMappings $StoredRoles -PartnerGroups @($PartnerGroups) -CreateMissing -WriteBack -APIName $APIName -Headers $Headers + & $AddCreatedGroups $RoleCheck foreach ($Result in $RoleCheck.Results) { - if ($Result.Status -eq 'Stale') { + if ($Result.Status -in @('Stale', 'Created')) { $Results.Add(@{ resultText = "GDAP Roles: $($Result.Message)"; state = 'success' }) } elseif ($Result.Status -eq 'Missing') { $Results.Add(@{ resultText = "GDAP Roles: $($Result.Message)"; state = 'error' }) @@ -43,9 +54,10 @@ function Invoke-ExecGDAPRepairRoleMappings { } if (($TemplateMappings | Measure-Object).Count -eq 0) { continue } - $TemplateCheck = Test-CIPPGDAPGroupMappings -RoleMappings $TemplateMappings -PartnerGroups $PartnerGroups -TemplateId $Template.RowKey -APIName $APIName -Headers $Headers + $TemplateCheck = Test-CIPPGDAPGroupMappings -RoleMappings $TemplateMappings -PartnerGroups @($PartnerGroups) -CreateMissing -TemplateId $Template.RowKey -APIName $APIName -Headers $Headers + & $AddCreatedGroups $TemplateCheck foreach ($Result in $TemplateCheck.Results) { - if ($Result.Status -eq 'Stale') { + if ($Result.Status -in @('Stale', 'Created')) { $Results.Add(@{ resultText = "Template '$($Template.RowKey)': $($Result.Message)"; state = 'success' }) } elseif ($Result.Status -eq 'Missing') { $Results.Add(@{ resultText = "Template '$($Template.RowKey)': $($Result.Message)"; state = 'error' }) diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPRoleTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPRoleTemplate.ps1 index abb2b84eabdb7..cbc3e88350db7 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPRoleTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPRoleTemplate.ps1 @@ -18,10 +18,10 @@ function Invoke-ExecGDAPRoleTemplate { if ($Request.Query.TemplateId) { $Template = $Templates | Where-Object -Property RowKey -EQ $Request.Query.TemplateId if (!$Template) { - Write-LogMessage -headers $Headers -API $APIName -message "GDAP role template '$($Request.Query.TemplateId)' not found" -sev 'Warning' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "GDAP role template '$($Request.Query.TemplateId)' not found" -sev 'Warning' $Body = @{} } else { - Write-LogMessage -headers $Headers -API $APIName -message "Retrieved GDAP role template '$($Request.Query.TemplateId)'" -Sev 'Info' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Retrieved GDAP role template '$($Request.Query.TemplateId)'" -Sev 'Info' $Body = @{ TemplateId = $Template.RowKey RoleMappings = @($Template.RoleMappings | ConvertFrom-Json) @@ -37,12 +37,52 @@ function Invoke-ExecGDAPRoleTemplate { $RoleMappings = $Request.Body.RoleMappings } Write-Information ($RoleMappings | ConvertTo-Json) - Add-CIPPGDAPRoleTemplate -TemplateId $RowKey -RoleMappings $RoleMappings - Write-LogMessage -headers $Headers -API $APIName -message "Added role mappings to GDAP template '$RowKey'" -Sev 'Info' + Add-CIPPGDAPRoleTemplate -Headers $Request.Headers -TemplateId $RowKey -RoleMappings $RoleMappings + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Added role mappings to GDAP template '$RowKey'" -Sev 'Info' $Body = @{ Results = "Added role mappings to template $RowKey" } } + 'Save' { + # Template-first save: creates any group mappings the editor asked for, then + # writes the full mapping set to the template in one shot. + $NewTemplateId = $Request.Body.TemplateId + $OriginalTemplateId = $Request.Body.OriginalTemplateId + $SaveResults = [System.Collections.Generic.List[string]]::new() + $RoleMappings = [System.Collections.Generic.List[object]]::new() + + foreach ($Mapping in @($Request.Body.RoleMappings)) { + if ($Mapping) { $RoleMappings.Add($Mapping) } + } + + $NewRoles = @($Request.Body.NewRoles | Where-Object { $_ }) + if ($NewRoles.Count -gt 0) { + $NewMappings = New-CIPPGDAPRoleMapping -Roles $NewRoles -CustomSuffix $Request.Body.CustomSuffix + foreach ($Message in $NewMappings.Results) { + $SaveResults.Add([string]$Message) + } + foreach ($Mapping in $NewMappings.RoleMappings) { + if ($Mapping.GroupId -notin $RoleMappings.GroupId) { + $RoleMappings.Add($Mapping) + } + } + } + + if ($OriginalTemplateId -and $OriginalTemplateId -ne $NewTemplateId) { + $OldTemplate = $Templates | Where-Object -Property RowKey -EQ $OriginalTemplateId + if ($OldTemplate) { + Remove-CIPPAzDataTableEntity -Force @Table -Entity $OldTemplate + $SaveResults.Add("Renamed template $OriginalTemplateId to $NewTemplateId") + } + } + + Add-CIPPGDAPRoleTemplate -Headers $Request.Headers -TemplateId $NewTemplateId -RoleMappings @($RoleMappings | Select-Object -Property RoleName, GroupName, GroupId, roleDefinitionId) -Overwrite + $SaveResults.Add("Saved template $NewTemplateId") + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Saved GDAP role template '$NewTemplateId' with $($RoleMappings.Count) role mappings" -Sev 'Info' + $Body = @{ + Results = @($SaveResults) + } + } 'Edit' { # Use OriginalTemplateId if provided (for rename), otherwise use TemplateId $OriginalRowKey = $Request.Body.OriginalTemplateId ?? $Request.Body.TemplateId @@ -54,21 +94,21 @@ function Invoke-ExecGDAPRoleTemplate { # If the template ID is being changed, delete the old one and create a new one if ($OriginalRowKey -ne $NewRowKey) { Remove-CIPPAzDataTableEntity -Force @Table -Entity $Template - Add-CIPPGDAPRoleTemplate -TemplateId $NewRowKey -RoleMappings $RoleMappings -Overwrite - Write-LogMessage -headers $Headers -API $APIName -message "Renamed GDAP template from '$OriginalRowKey' to '$NewRowKey' and updated role mappings" -Sev 'Info' + Add-CIPPGDAPRoleTemplate -Headers $Request.Headers -TemplateId $NewRowKey -RoleMappings $RoleMappings -Overwrite + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Renamed GDAP template from '$OriginalRowKey' to '$NewRowKey' and updated role mappings" -Sev 'Info' $Body = @{ Results = "Renamed template from $OriginalRowKey to $NewRowKey and updated role mappings" } } else { # Just update the existing template - Add-CIPPGDAPRoleTemplate -TemplateId $NewRowKey -RoleMappings $RoleMappings -Overwrite - Write-LogMessage -headers $Headers -API $APIName -message "Updated role mappings for GDAP template '$NewRowKey'" -Sev 'Info' + Add-CIPPGDAPRoleTemplate -Headers $Request.Headers -TemplateId $NewRowKey -RoleMappings $RoleMappings -Overwrite + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Updated role mappings for GDAP template '$NewRowKey'" -Sev 'Info' $Body = @{ Results = "Updated role mappings for template $NewRowKey" } } } else { - Write-LogMessage -headers $Headers -API $APIName -message "GDAP role template '$OriginalRowKey' not found for editing" -sev 'Warning' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "GDAP role template '$OriginalRowKey' not found for editing" -sev 'Warning' $Body = @{ Results = "Template $OriginalRowKey not found" } @@ -79,19 +119,19 @@ function Invoke-ExecGDAPRoleTemplate { $Template = $Templates | Where-Object -Property RowKey -EQ $RowKey if ($Template) { Remove-CIPPAzDataTableEntity -Force @Table -Entity $Template - Write-LogMessage -headers $Headers -API $APIName -message "Deleted GDAP role template '$RowKey'" -Sev 'Info' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Deleted GDAP role template '$RowKey'" -Sev 'Info' $Body = @{ Results = "Deleted template $RowKey" } } else { - Write-LogMessage -headers $Headers -API $APIName -message "GDAP role template '$RowKey' not found for deletion" -sev 'Warning' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "GDAP role template '$RowKey' not found for deletion" -sev 'Warning' $Body = @{ Results = "Template $RowKey not found" } } } default { - Write-LogMessage -headers $Headers -API $APIName -message "Retrieved $($Templates.Count) GDAP role templates" -Sev 'Info' + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Retrieved $($Templates.Count) GDAP role templates" -Sev 'Info' $Results = foreach ($Template in $Templates) { [PSCustomObject]@{ TemplateId = $Template.RowKey diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ListGDAPRoles.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ListGDAPRoles.ps1 index 6adf7f039471d..1b425430e32ff 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ListGDAPRoles.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ListGDAPRoles.ps1 @@ -6,9 +6,14 @@ Function Invoke-ListGDAPRoles { Tenant.Relationship.Read .DESCRIPTION Lists the configured GDAP role-to-security-group mappings used for delegated admin access. + Pass ?validate=true to annotate each mapping with the state of its partner tenant group. #> [CmdletBinding()] param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $Table = Get-CIPPTable -TableName 'GDAPRoles' $Groups = Get-CIPPAzDataTableEntity @Table @@ -21,6 +26,48 @@ Function Invoke-ListGDAPRoles { } } + # Opt-in only: other consumers of this endpoint depend on the unannotated shape. + if ($Request.Query.validate -eq $true -and ($MappedGroups | Measure-Object).Count -gt 0) { + try { + # The helper fetches the partner tenant groups itself; keeping Graph out of this + # entrypoint keeps the documented response shape to the mapping fields. + $Check = Test-CIPPGDAPGroupMappings -RoleMappings $MappedGroups -APIName $APIName -Headers $Headers + + # A read-only check reports one result per mapping; Valid keeps the original id, the + # other states carry it as OldGroupId. + $StatusLookup = @{} + foreach ($Result in $Check.Results) { + $Key = if ($Result.OldGroupId) { $Result.OldGroupId } else { $Result.GroupId } + if ($Key) { $StatusLookup[[string]$Key] = $Result } + } + + $MappedGroups = foreach ($Group in $MappedGroups) { + $Status = $StatusLookup[[string]$Group.GroupId] + [PSCustomObject]@{ + GroupName = $Group.GroupName + GroupId = $Group.GroupId + RoleName = $Group.RoleName + roleDefinitionId = $Group.roleDefinitionId + GroupStatus = $Status.Status ?? 'Unknown' + GroupStatusMessage = $Status.Message ?? '' + } + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -headers $Headers -API $APIName -message "Could not validate GDAP group mappings: $($ErrorMessage.NormalizedError)" -Sev 'Warning' -LogData $ErrorMessage + $MappedGroups = foreach ($Group in $MappedGroups) { + [PSCustomObject]@{ + GroupName = $Group.GroupName + GroupId = $Group.GroupId + RoleName = $Group.RoleName + roleDefinitionId = $Group.roleDefinitionId + GroupStatus = 'Unknown' + GroupStatusMessage = '' + } + } + } + } + return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK Body = @($MappedGroups) diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ExecLicensePricing.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ExecLicensePricing.ps1 new file mode 100644 index 0000000000000..00ce81108b753 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ExecLicensePricing.ps1 @@ -0,0 +1,76 @@ +function Invoke-ExecLicensePricing { + <# + .FUNCTIONALITY + Entrypoint,AnyTenant + .ROLE + Tenant.Directory.ReadWrite + .DESCRIPTION + Manage MSP-global license price overrides used by the license optimization report. + SetPrice upserts a per-SKU monthly price; RemovePrice deletes an override so the SKU falls + back to the shipped MSRP estimate. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $Table = Get-CIPPTable -TableName 'LicensePricing' + + try { + # SetPrice or RemovePrice + $Action = $Request.Body.Action + if ([string]::IsNullOrWhiteSpace($Action)) { throw 'Action is required.' } + # The SKU GUID (skuId) the price applies to + $SkuId = ([string]$Request.Body.skuId).ToLowerInvariant() + if ([string]::IsNullOrWhiteSpace($SkuId)) { throw 'skuId is required.' } + + # Overrides are currency-scoped: one row per (skuId, currency), so an AUD override and a + # USD override for the same SKU coexist. RowKey = "{skuId}-{currency}". + $Currency = if ($Request.Body.Currency) { [string]$Request.Body.Currency } else { 'USD' } + $RowKey = '{0}-{1}' -f $SkuId, $Currency.ToLowerInvariant() + + switch ($Action) { + 'SetPrice' { + # Monthly price per seat, in the given currency + $MonthlyPrice = $Request.Body.MonthlyPrice -as [double] + if ($null -eq $MonthlyPrice) { throw 'MonthlyPrice must be a number.' } + + $Entity = @{ + PartitionKey = 'Price' + RowKey = $RowKey + 'skuId' = $SkuId + 'skuPartNumber' = [string]$Request.Body.skuPartNumber + 'Product_Display_Name' = [string]$Request.Body.Product_Display_Name + 'MonthlyPrice' = [double]$MonthlyPrice + 'Currency' = $Currency + } + Add-CIPPAzDataTableEntity @Table -Entity $Entity -Force + $Result = "Success. Set price for $SkuId to $Currency $MonthlyPrice per month." + Write-LogMessage -API $APIName -headers $Headers -message $Result -Sev 'Info' + } + 'RemovePrice' { + $Filter = "PartitionKey eq 'Price' and RowKey eq '{0}'" -f $RowKey + $Entity = Get-CIPPAzDataTableEntity @Table -Filter $Filter -Property PartitionKey, RowKey + if ($Entity) { + Remove-CIPPAzDataTableEntity -Force @Table -Entity $Entity + } + $Result = "Success. Removed the $Currency price override for $SkuId. It will fall back to the shipped estimate." + Write-LogMessage -API $APIName -headers $Headers -message $Result -Sev 'Info' + } + default { + $StatusCode = [HttpStatusCode]::BadRequest + $Result = "Invalid action specified: $Action" + } + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $StatusCode = [HttpStatusCode]::InternalServerError + $Result = "Failed to update license pricing. $($ErrorMessage.NormalizedError)" + Write-LogMessage -API $APIName -headers $Headers -message $Result -Sev 'Error' -LogData $ErrorMessage + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode ?? [HttpStatusCode]::OK + Body = [pscustomobject]@{ 'Results' = $Result } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ListLicenseOptimization.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ListLicenseOptimization.ps1 new file mode 100644 index 0000000000000..d39e7e6331b23 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ListLicenseOptimization.ps1 @@ -0,0 +1,57 @@ +function Invoke-ListLicenseOptimization { + <# + .FUNCTIONALITY + Entrypoint,AnyTenant + .ROLE + Tenant.Directory.Read + .DESCRIPTION + License cost-optimization report for a tenant: a monetary summary plus reclaim + opportunities across five waste tiers (unassigned seats, disabled and inactive licensed + accounts, mailbox-only downgrade candidates, and redundant overlapping SKUs). Computed from + the reporting-DB cache. For tenantFilter=AllTenants it returns a per-tenant summary money + map (ranked by reclaimable spend) instead of the full opportunity detail. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + # The tenant to report on, or AllTenants for the cross-tenant summary money map + $TenantFilter = $Request.Query.tenantFilter ?? $Request.Body.tenantFilter + # Sign-in age in days past which an enabled licensed user counts as inactive (default 90) + $InactiveDays = ($Request.Query.inactiveDays ?? $Request.Body.inactiveDays) -as [int] + if (-not $InactiveDays -or $InactiveDays -le 0) { $InactiveDays = 90 } + # Currency the money figures are resolved in (ISO code); defaults to USD + $Currency = $Request.Query.currency ?? $Request.Body.currency + if ([string]::IsNullOrWhiteSpace($Currency)) { $Currency = 'USD' } + + try { + if ($TenantFilter -eq 'AllTenants') { + $Summaries = [System.Collections.Generic.List[object]]::new() + foreach ($Tenant in (Get-Tenants -IncludeErrors)) { + try { + $Report = Get-CIPPLicenseOptimization -TenantFilter $Tenant.defaultDomainName -InactiveDays $InactiveDays -Currency $Currency + if ($Report.Summary.DataAvailable) { $Summaries.Add($Report.Summary) } + } catch { + Write-Information "License optimization failed for $($Tenant.defaultDomainName): $($_.Exception.Message)" + } + } + $Results = @($Summaries | Sort-Object -Property ReclaimableMonthly -Descending) + } else { + if ([string]::IsNullOrWhiteSpace($TenantFilter)) { throw 'tenantFilter is required.' } + $Results = Get-CIPPLicenseOptimization -TenantFilter $TenantFilter -InactiveDays $InactiveDays -Currency $Currency + } + $StatusCode = [System.Net.HttpStatusCode]::OK + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $StatusCode = [System.Net.HttpStatusCode]::InternalServerError + $Results = "Failed to build license optimization report. $($ErrorMessage.NormalizedError)" + Write-LogMessage -API $APIName -headers $Headers -message $Results -Sev 'Error' -LogData $ErrorMessage + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = [pscustomobject]@{ 'Results' = $Results } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ListLicensePricing.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ListLicensePricing.ps1 new file mode 100644 index 0000000000000..efbb7bd4814f1 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ListLicensePricing.ps1 @@ -0,0 +1,41 @@ +function Invoke-ListLicensePricing { + <# + .FUNCTIONALITY + Entrypoint,AnyTenant + .ROLE + Tenant.Directory.Read + .DESCRIPTION + Lists the resolved monthly price for every known license SKU: MSP price overrides merged + over the shipped MSRP estimates. Consumed by the license optimization report and its + price-management UI. Each row carries a Source of Override, Estimate, or Unknown. + + Prices are resolved in the requested currency (?currency=, default USD). The response also + carries the list of currencies present in the price data so the UI can offer a selector. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + # Currency to resolve prices in (ISO code); defaults to USD + $Currency = $Request.Query.currency ?? $Request.Body.currency + if ([string]::IsNullOrWhiteSpace($Currency)) { $Currency = 'USD' } + + try { + $Results = @(Get-CIPPLicensePrice -Currency $Currency) + $Currencies = @(Get-CIPPLicensePrice -ListCurrencies) + $StatusCode = [HttpStatusCode]::OK + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $StatusCode = [HttpStatusCode]::InternalServerError + $Results = "Failed to list license pricing. $($ErrorMessage.NormalizedError)" + $Currencies = @('USD') + Write-LogMessage -API $APIName -headers $Headers -message $Results -Sev 'Error' -LogData $ErrorMessage + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = [pscustomobject]@{ 'Results' = $Results; 'Currencies' = $Currencies; 'Currency' = $Currency } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ListServiceHealth.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ListServiceHealth.ps1 index 949257de04a87..14aadf4e6d60b 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ListServiceHealth.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Reports/Invoke-ListServiceHealth.ps1 @@ -19,8 +19,10 @@ Function Invoke-ListServiceHealth { $TenantName = $_.displayName Write-Host "Processed Service Health for $TenantName via AllTenants" $prop = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/admin/serviceAnnouncement/issues?`$filter=endDateTime eq null" -tenantid $_.defaultDomainName - $prop | Add-Member -NotePropertyName 'tenant' -NotePropertyValue $TenantName - $prop | Add-Member -NotePropertyName 'defaultDomainName' -NotePropertyValue $_.defaultDomainName + $prop | Add-Member -NotePropertyMembers ([ordered]@{ + tenant = $TenantName + defaultDomainName = $_.defaultDomainName + }) $prop } } else { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-AddBPATemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-AddBPATemplate.ps1 index 7fd804076cf2c..1c7b8da46100f 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-AddBPATemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-AddBPATemplate.ps1 @@ -19,11 +19,11 @@ Function Invoke-AddBPATemplate { PartitionKey = 'BPATemplate' GUID = $Request.body.name } - Write-LogMessage -headers $Request.Headers -API $APINAME -message "Created BPA named $($Request.body.name)" -Sev 'Debug' + Write-LogMessage -headers $Request.Headers -API $APINAME -tenant 'Global' -message "Created BPA named $($Request.body.name)" -Sev 'Info' $body = [pscustomobject]@{'Results' = 'Successfully added template' } } catch { - Write-LogMessage -headers $Request.Headers -API $APINAME -message "BPA Template Creation failed: $($_.Exception.Message)" -Sev 'Error' + Write-LogMessage -headers $Request.Headers -API $APINAME -tenant 'Global' -message "BPA Template Creation failed: $($_.Exception.Message)" -Sev 'Error' $body = [pscustomobject]@{'Results' = "BPA Template Creation failed: $($_.Exception.Message)" } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecDriftClone.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecDriftClone.ps1 index ff43f91dd0f01..ab232e5ed1de2 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecDriftClone.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecDriftClone.ps1 @@ -8,6 +8,9 @@ function Invoke-ExecDriftClone { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint ?? 'ExecDriftClone' + $Headers = $Request.Headers + try { $TemplateId = $Request.Body.id @@ -22,9 +25,22 @@ function Invoke-ExecDriftClone { }) return } - $CloneResult = New-CippStandardsDriftClone -TemplateId $TemplateId -UpgradeToDrift -Headers $Request.Headers + $CloneResult = New-CippStandardsDriftClone -TemplateId $TemplateId -UpgradeToDrift + if ($CloneResult -like 'Failed*') { + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $CloneResult -Sev 'Error' + $Results = [pscustomobject]@{ + 'Results' = $CloneResult + 'Success' = $false + } + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::InternalServerError + Body = $Results + }) + } + + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $CloneResult -Sev 'Info' $Results = [pscustomobject]@{ - 'Results' = $CloneResult + 'Results' = 'Clone Completed successfully' 'Success' = $true } @@ -33,6 +49,8 @@ function Invoke-ExecDriftClone { Body = $Results }) } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message "Failed to create drift clone: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage $Results = [pscustomobject]@{ 'Results' = "Failed to create drift clone: $($_.Exception.Message)" 'Success' = $false diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecStandardConvert.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecStandardConvert.ps1 index e69cf05ed25e4..7f331705a2382 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecStandardConvert.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecStandardConvert.ps1 @@ -8,6 +8,9 @@ function Invoke-ExecStandardConvert { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + function Convert-SingleStandardItem { param( [Parameter(Mandatory)] @@ -198,10 +201,12 @@ function Invoke-ExecStandardConvert { foreach ($OldStd in $StandardsToConvert) { $Converted = Convert-OldStandardToNewFormat $OldStd ($AllTenantsExclusions) $GUID = [guid]::NewGuid() - $Converted | Add-Member -NotePropertyName 'GUID' -NotePropertyValue $GUID -Force - $Converted | Add-Member -NotePropertyName 'createdAt' -NotePropertyValue ((Get-Date).ToUniversalTime()) -Force - $Converted | Add-Member -NotePropertyName 'updatedBy' -NotePropertyValue 'System' -Force - $Converted | Add-Member -NotePropertyName 'updatedAt' -NotePropertyValue (Get-Date).ToUniversalTime() -Force + $Converted | Add-Member -NotePropertyMembers ([ordered]@{ + GUID = $GUID + createdAt = ((Get-Date).ToUniversalTime()) + updatedBy = 'System' + updatedAt = (Get-Date).ToUniversalTime() + }) -Force $JSON = ConvertTo-Json -Depth 100 -InputObject $Converted -Compress $Table = Get-CippTable -tablename 'templates' @@ -229,8 +234,12 @@ function Invoke-ExecStandardConvert { } } + $Result = "Successfully converted $($StandardsToConvert.Count) legacy standard(s) to new format" + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Result -Sev 'Info' + return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK Body = 'Successfully converted legacy standards to new format' }) } + diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecStandardsRun.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecStandardsRun.ps1 index 4c5e977b8dc0a..3294de543ffd9 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecStandardsRun.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecStandardsRun.ps1 @@ -26,11 +26,14 @@ function Invoke-ExecStandardsRun { $_.guid -like $TemplateId } + # [bool] over an array (or the string 'false') is always $true, which flipped wildcard runs to manual-only. + $RunManually = @($Templates).Count -eq 1 -and ("$(@($Templates)[0].runManually)" -eq 'True') + # Call the wrapper - it handles queuing internally via Start-CIPPOrchestrator try { - $null = New-CIPPStandardsRun -TenantFilter $TenantFilter -TemplateID $TemplateId -runManually ([bool]$Templates.runManually) -Force + $null = New-CIPPStandardsRun -TenantFilter $TenantFilter -TemplateID $TemplateId -runManually $RunManually -Force $TemplateName = if ($TemplateId -eq '*') { 'All' } else { "$($Templates.templateName) ($($Templates.GUID))" } - $RunMode = if ([bool]$Templates.runManually) { ' (Manual Only)' } else { '' } + $RunMode = if ($RunManually) { ' (Manual Only)' } else { '' } $Results = "Successfully started Standards Run for tenant: $TenantFilter - Template: $TemplateName$RunMode" Write-LogMessage -headers $Headers -tenant $TenantFilter -API $APIName -message $Results -Sev 'Info' } catch { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecUpdateBaselineDeviation.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecUpdateBaselineDeviation.ps1 index 7042137b20eb2..87139a9149f72 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecUpdateBaselineDeviation.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecUpdateBaselineDeviation.ps1 @@ -40,14 +40,17 @@ function Invoke-ExecUpdateBaselineDeviation { $Now = [int64]([datetimeoffset]::UtcNow.ToUnixTimeSeconds()) $Table.Force = $true foreach ($TaskEntity in $Entities) { - $TaskEntity | Add-Member -NotePropertyName 'Status' -NotePropertyValue 'Compliant' -Force - $TaskEntity | Add-Member -NotePropertyName 'Compliant' -NotePropertyValue $true -Force - $TaskEntity | Add-Member -NotePropertyName 'LastRemediated' -NotePropertyValue $Now -Force + $TaskProps = [ordered]@{ + Status = 'Compliant' + Compliant = $true + LastRemediated = $Now + } if ($TaskEntity.CurrentValue) { $CurrentTask = $TaskEntity.CurrentValue | ConvertFrom-Json $CurrentTask | Add-Member -NotePropertyName 'completed' -NotePropertyValue $true -Force - $TaskEntity | Add-Member -NotePropertyName 'CurrentValue' -NotePropertyValue (ConvertTo-Json -Compress -Depth 20 -InputObject $CurrentTask) -Force + $TaskProps['CurrentValue'] = (ConvertTo-Json -Compress -Depth 20 -InputObject $CurrentTask) } + $TaskEntity | Add-Member -NotePropertyMembers $TaskProps -Force Add-CIPPAzDataTableEntity @Table -Entity $TaskEntity $null = Add-CIPPBaselineHistoryEvent -TenantFilter $TaskEntity.PartitionKey -Standard $Standard -Mode 'triage' -TriggeredBy $User -Outcome 'Task Completed' -Detail 'Marked completed for all tenants from the standard view' } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecUpdateDriftDeviation.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecUpdateDriftDeviation.ps1 index b50e0163fd80d..49b3236cea62e 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecUpdateDriftDeviation.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecUpdateDriftDeviation.ps1 @@ -85,12 +85,7 @@ function Invoke-ExecUpdateDriftDeviation { try { $user = $request.headers.'x-ms-client-principal' $username = ([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($user)) | ConvertFrom-Json).userDetails - $Result = Set-CIPPDriftDeviation -TenantFilter $TenantFilter -StandardName $Deviation.standardName -Status $Deviation.status -Reason $Reason -user $username - [PSCustomObject]@{ - success = $true - result = $Result - } - Write-LogMessage -tenant $TenantFilter -Headers $Request.Headers -API $APINAME -message "Updated drift deviation status for $($Deviation.standardName) to $($Deviation.status) with reason: $Reason" -Sev 'Info' + # The status is written at the end of this block, after the action it implies succeeds. if ($Deviation.status -eq 'DeniedRemediate') { $Setting = $Deviation.standardName -replace 'standards\.', '' $StandardTemplate = Get-CIPPTenantAlignment -TenantFilter $TenantFilter | Where-Object -Property standardType -EQ 'drift' @@ -110,8 +105,10 @@ function Invoke-ExecUpdateDriftDeviation { if (-not $MatchedTemplate) { Write-LogMessage -tenant $TenantFilter -Headers $Request.Headers -API $APINAME -message "Could not find IntuneTemplate $TemplateId in drift standard settings for remediation" -Sev 'Warning' } else { - $MatchedTemplate | Add-Member -MemberType NoteProperty -Name 'remediate' -Value $true -Force - $MatchedTemplate | Add-Member -MemberType NoteProperty -Name 'report' -Value $true -Force + $MatchedTemplate | Add-Member -NotePropertyMembers ([ordered]@{ + remediate = $true + report = $true + }) -Force $Settings = $MatchedTemplate } } elseif ($Setting -like '*ConditionalAccessTemplate*') { @@ -127,8 +124,10 @@ function Invoke-ExecUpdateDriftDeviation { if (-not $MatchedTemplate) { Write-LogMessage -tenant $TenantFilter -Headers $Request.Headers -API $APINAME -message "Could not find ConditionalAccessTemplate $TemplateId in drift standard settings for remediation" -Sev 'Warning' } else { - $MatchedTemplate | Add-Member -MemberType NoteProperty -Name 'remediate' -Value $true -Force - $MatchedTemplate | Add-Member -MemberType NoteProperty -Name 'report' -Value $true -Force + $MatchedTemplate | Add-Member -NotePropertyMembers ([ordered]@{ + remediate = $true + report = $true + }) -Force $Settings = $MatchedTemplate } } elseif ($Setting -like '*QuarantineTemplate*') { @@ -150,8 +149,10 @@ function Invoke-ExecUpdateDriftDeviation { if (-not $MatchedTemplate) { Write-LogMessage -tenant $TenantFilter -Headers $Request.Headers -API $APINAME -message "Could not find QuarantineTemplate '$PolicyName' in drift standard settings for remediation" -Sev 'Warning' } else { - $MatchedTemplate | Add-Member -MemberType NoteProperty -Name 'remediate' -Value $true -Force - $MatchedTemplate | Add-Member -MemberType NoteProperty -Name 'report' -Value $true -Force + $MatchedTemplate | Add-Member -NotePropertyMembers ([ordered]@{ + remediate = $true + report = $true + }) -Force $Settings = $MatchedTemplate } } elseif ($Setting -like '*ReusableSettingsTemplate*') { @@ -161,8 +162,10 @@ function Invoke-ExecUpdateDriftDeviation { if (-not $MatchedTemplate) { Write-LogMessage -tenant $TenantFilter -Headers $Request.Headers -API $APINAME -message "Could not find ReusableSettingsTemplate $TemplateId in drift standard settings for remediation" -Sev 'Warning' } else { - $MatchedTemplate | Add-Member -MemberType NoteProperty -Name 'remediate' -Value $true -Force - $MatchedTemplate | Add-Member -MemberType NoteProperty -Name 'report' -Value $true -Force + $MatchedTemplate | Add-Member -NotePropertyMembers ([ordered]@{ + remediate = $true + report = $true + }) -Force $Settings = $MatchedTemplate } } else { @@ -175,8 +178,10 @@ function Invoke-ExecUpdateDriftDeviation { } $StandardTemplate.PSObject.Properties.Remove('standards') } - $StandardTemplate | Add-Member -MemberType NoteProperty -Name 'remediate' -Value $true -Force - $StandardTemplate | Add-Member -MemberType NoteProperty -Name 'report' -Value $true -Force + $StandardTemplate | Add-Member -NotePropertyMembers ([ordered]@{ + remediate = $true + report = $true + }) -Force $Settings = $StandardTemplate } if ($Settings) { @@ -235,6 +240,7 @@ function Invoke-ExecUpdateDriftDeviation { success = $false error = "The deviation status was updated, but no remediation task was scheduled: '$Setting' could not be resolved from the drift template settings. Verify the template still exists in the template library and is included in the drift template, or re-save the drift template." } + Write-LogMessage -tenant $TenantFilter -Headers $Request.Headers -API $APINAME -message "Could not find standard $Setting in drift standard settings for remediation" -Sev 'Warning' } } if ($Deviation.status -eq 'deniedDelete') { @@ -296,6 +302,14 @@ function Invoke-ExecUpdateDriftDeviation { } + + # Task queued / policy gone; a throw above leaves the row untouched. + $Result = Set-CIPPDriftDeviation -TenantFilter $TenantFilter -StandardName $Deviation.standardName -Status $Deviation.status -Reason $Reason -user $username + [PSCustomObject]@{ + success = $true + result = $Result + } + Write-LogMessage -tenant $TenantFilter -Headers $Request.Headers -API $APINAME -message "Updated drift deviation status for $($Deviation.standardName) to $($Deviation.status) with reason: $Reason" -Sev 'Info' } catch { [PSCustomObject]@{ standardName = $Deviation.standardName diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ListStandardsCompare.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ListStandardsCompare.ps1 index a85cf546adb2d..2767a8d4c5cab 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ListStandardsCompare.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ListStandardsCompare.ps1 @@ -23,6 +23,8 @@ function Invoke-ListStandardsCompare { $ScopedTemplateGuids = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) $ScopedQuarantineNames = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + # Plain standard keys in scope (standards., and one key per reusable settings template). + $ScopedStandardKeys = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) foreach ($Entry in $StandardList) { switch ($Entry.Standard) { { $_ -in @('IntuneTemplate', 'ConditionalAccessTemplate') } { @@ -32,16 +34,35 @@ function Invoke-ListStandardsCompare { $DisplayName = $Entry.Settings.displayName.value ?? $Entry.Settings.displayName if ($DisplayName) { $null = $ScopedQuarantineNames.Add($DisplayName) } } + 'ReusableSettingsTemplate' { + foreach ($Item in @($Entry.Settings.TemplateList)) { + $Id = if ($Item.value) { [string]$Item.value } else { [string]$Item } + if ($Id) { $null = $ScopedStandardKeys.Add("standards.ReusableSettingsTemplate.$Id") } + } + } + default { + if ($Entry.Standard) { $null = $ScopedStandardKeys.Add("standards.$($Entry.Standard)") } + } } } + # A report row carries the id of the template whose settings last ran the standard. With the + # three-tier merge that is the tenant-specific or group template, so filtering rows on that id + # hid every standard an AllTenants template shares with a more specific one and the page said + # the data had never been collected. Rows are matched on the standard key instead, and the + # selected template's own definition is read so its overridden standards still count as in scope + # (Get-CIPPStandards only emits the template that won the merge). + if ($TemplateFilter) { + $TemplateScope = Get-CIPPStandardsTemplateScope -TemplateId $TemplateFilter + $ScopedStandardKeys.UnionWith($TemplateScope.StandardKeys) + $ScopedTemplateGuids.UnionWith($TemplateScope.TemplateGuids) + $ScopedQuarantineNames.UnionWith($TemplateScope.QuarantineNames) + } + $Filters = [system.collections.generic.list[string]]::new() if ($TenantFilter) { $Filters.Add("PartitionKey eq '{0}'" -f $TenantFilter) } - if ($TemplateFilter) { - $Filters.Add("TemplateId eq '{0}'" -f $TemplateFilter) - } $Filter = $Filters -join ' and ' $Tenants = Get-Tenants -IncludeErrors @@ -68,6 +89,9 @@ function Invoke-ListStandardsCompare { } $DecodedName = -join $Chars if (-not $ScopedQuarantineNames.Contains($DecodedName)) { continue } + } elseif ($TemplateFilter -and $Standard.TemplateId -ne $TemplateFilter -and -not $ScopedStandardKeys.Contains($FieldName)) { + # Not written by this template and not one of its standards: belongs to another template. + continue } # decode field names that are hex encoded (e.g. QuarantineTemplates) diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-listStandardTemplates.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-listStandardTemplates.ps1 index eb71fa0dcbfb2..5cc6f94bdc0d0 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-listStandardTemplates.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-listStandardTemplates.ps1 @@ -40,12 +40,14 @@ function Invoke-listStandardTemplates { } } if ($Data) { - $Data | Add-Member -NotePropertyName 'GUID' -NotePropertyValue $_.GUID -Force - $Data | Add-Member -NotePropertyName 'source' -NotePropertyValue $_.Source -Force - $Data | Add-Member -NotePropertyName 'isSynced' -NotePropertyValue (![string]::IsNullOrEmpty($_.SHA)) -Force + $DataProps = [ordered]@{ + GUID = $_.GUID + source = $_.Source + isSynced = (![string]::IsNullOrEmpty($_.SHA)) + } if (!$Data.excludedTenants) { - $Data | Add-Member -NotePropertyName 'excludedTenants' -NotePropertyValue @() -Force + $DataProps['excludedTenants'] = @() } else { if ($Data.excludedTenants -and $Data.excludedTenants -ne 'excludedTenants') { $Data.excludedTenants = @($Data.excludedTenants) @@ -53,6 +55,7 @@ function Invoke-listStandardTemplates { $Data.excludedTenants = @() } } + $Data | Add-Member -NotePropertyMembers $DataProps -Force # Re-expand TemplateList-Tags live so stale addedFields snapshots don't show removed templates if ($Data.standards) { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-AddTestReport.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-AddTestReport.ps1 index aebb578e1f419..b7bd9969cc268 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-AddTestReport.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-AddTestReport.ps1 @@ -56,14 +56,16 @@ function Invoke-AddTestReport { # Save to table Add-CIPPAzDataTableEntity -Entity $Report @ReportTable -Force + $Result = if ($IsUpdate) { "Successfully updated custom report '$($Body.name)'" } else { "Successfully created custom report '$($Body.name)'" } + Write-LogMessage -user $Request.Headers.'x-ms-client-principal' -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $Body = [PSCustomObject]@{ - Results = if ($IsUpdate) { 'Successfully updated custom report' } else { 'Successfully created custom report' } + Results = $Result ReportId = $ReportId } $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ - Write-LogMessage -user $Request.Headers.'x-ms-client-principal' -API $APIName -message "Failed to save report: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage + Write-LogMessage -user $Request.Headers.'x-ms-client-principal' -API $APIName -tenant 'Global' -message "Failed to save report: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage $Body = [PSCustomObject]@{ Results = "Failed to save report: $($ErrorMessage.NormalizedError)" } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-DeleteTestReport.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-DeleteTestReport.ps1 index 6f82effad9a89..888c676e94bdf 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-DeleteTestReport.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-DeleteTestReport.ps1 @@ -17,13 +17,15 @@ function Invoke-DeleteTestReport { $ExistingReport = Get-CIPPAzDataTableEntity @Table -Filter "RowKey eq '$ReportId'" Remove-CIPPAzDataTableEntity @Table -Entity $ExistingReport + $Result = 'Successfully deleted custom report' + Write-LogMessage -user $Request.Headers.'x-ms-client-principal' -API $APIName -tenant 'Global' -message $Result -Sev 'Info' $Body = [PSCustomObject]@{ - Results = 'Successfully deleted custom report' + Results = $Result } $StatusCode = [HttpStatusCode]::OK } catch { $ErrorMessage = Get-CippException -Exception $_ - Write-LogMessage -user $Request.Headers.'x-ms-client-principal' -API $APIName -message "Failed to delete report: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage + Write-LogMessage -user $Request.Headers.'x-ms-client-principal' -API $APIName -tenant 'Global' -message "Failed to delete report: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage $Body = [PSCustomObject]@{ Results = "Failed to delete report: $($ErrorMessage.NormalizedError)" } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-ExecTestRefresh.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-ExecTestRefresh.ps1 index 19f79b929263e..8ba6fe35f1dd9 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-ExecTestRefresh.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-ExecTestRefresh.ps1 @@ -20,6 +20,7 @@ function Invoke-ExecTestRefresh { Add-CIPPAzDataTableEntity @Table -Entity $TestResult -Force $StatusCode = [HttpStatusCode]::OK $Body = [PSCustomObject]@{ Results = "Successfully updated test $TestName for tenant $TenantFilter"; Metadata = $TestResult } + Write-LogMessage -headers $Request.Headers -API $APIName -tenant $TenantFilter -message "Successfully refreshed test $TestName for tenant $TenantFilter" -Sev 'Info' } else { return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::NotFound @@ -28,9 +29,11 @@ function Invoke-ExecTestRefresh { } } catch { $StatusCode = [HttpStatusCode]::BadRequest + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -headers $Request.Headers -API $APIName -tenant $TenantFilter -message "Failed to refresh test $TestName for ${TenantFilter}: $($ErrorMessage.NormalizedError)" -Sev 'Error' -LogData $ErrorMessage $Body = @{ Message = "Failed to update test $TestName for $TenantFilter" - Error = Get-CippException -Exception $_ + Error = $ErrorMessage } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-ListTests.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-ListTests.ps1 index 567ff124015ea..77408930154e9 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-ListTests.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-ListTests.ps1 @@ -194,9 +194,11 @@ function Invoke-ListTests { $ScriptGuid = ($TestResult.RowKey -replace '^CustomScript-', '') if (-not [string]::IsNullOrWhiteSpace($ScriptGuid) -and $CustomScriptMetadataLookup.ContainsKey($ScriptGuid)) { $CustomMetadata = $CustomScriptMetadataLookup[$ScriptGuid] - $TestResult | Add-Member -NotePropertyName 'Description' -NotePropertyValue ($CustomMetadata.Description) -Force - $TestResult | Add-Member -NotePropertyName 'ReturnType' -NotePropertyValue ($CustomMetadata.ReturnType) -Force - $TestResult | Add-Member -NotePropertyName 'MarkdownTemplate' -NotePropertyValue ($CustomMetadata.MarkdownTemplate) -Force + $TestResult | Add-Member -NotePropertyMembers ([ordered]@{ + Description = ($CustomMetadata.Description) + ReturnType = ($CustomMetadata.ReturnType) + MarkdownTemplate = ($CustomMetadata.MarkdownTemplate) + }) -Force } } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tools/Invoke-ExecGraphExplorerPreset.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tools/Invoke-ExecGraphExplorerPreset.ps1 index bcaebf761c298..c49bae8d88350 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tools/Invoke-ExecGraphExplorerPreset.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tools/Invoke-ExecGraphExplorerPreset.ps1 @@ -108,6 +108,15 @@ function Invoke-ExecGraphExplorerPreset { $Message = $_.Exception.Message $StatusCode = [HttpStatusCode]::BadRequest } + + if ($Action -in @('Save', 'Delete', 'Copy')) { + if ($Success) { + Write-LogMessage -headers $Headers -API ($Request.Params.CIPPEndpoint) -tenant 'Global' -message $Message -Sev 'Info' + } else { + Write-LogMessage -headers $Headers -API ($Request.Params.CIPPEndpoint) -tenant 'Global' -message $Message -Sev 'Error' + } + } + return ([HttpResponseContext]@{ StatusCode = $StatusCode Body = @{ diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ExecCommunityRepo.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ExecCommunityRepo.ps1 index 335a5d0b684e7..16802f16f4431 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ExecCommunityRepo.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ExecCommunityRepo.ps1 @@ -12,6 +12,9 @@ function Invoke-ExecCommunityRepo { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $Action = $Request.Body.Action $Id = $Request.Body.Id if ($Request.Body.Id) { @@ -371,6 +374,14 @@ function Invoke-ExecCommunityRepo { } } + if ($Results) { + if ($Results.state -eq 'success') { + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Results.resultText -Sev 'Info' + } elseif ($Results.state -eq 'error') { + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Results.resultText -Sev 'Error' + } + } + $Body = @{ Results = @($Results) } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ExecGitHubAction.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ExecGitHubAction.ps1 index 709e3a6b076f5..7ee5c0d77fbf9 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ExecGitHubAction.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ExecGitHubAction.ps1 @@ -12,6 +12,9 @@ function Invoke-ExecGitHubAction { [CmdletBinding()] param($Request, $TriggerMetadata) + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + $Action = $Request.Query.Action ?? $Request.Body.Action if ($Request.Query.Action) { @@ -50,7 +53,18 @@ function Invoke-ExecGitHubAction { $Results = @($Files) } 'ImportTemplate' { - $Results = Import-CommunityTemplate @SplatParams + try { + $Results = Import-CommunityTemplate @SplatParams + $ResultText = if ($Results -is [string]) { $Results } elseif ($Results.resultText) { $Results.resultText } else { 'Template imported' } + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $ResultText -Sev 'Info' + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Results = @{ + resultText = "Error importing template: $($ErrorMessage.NormalizedError)" + state = 'error' + } + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Results.resultText -Sev 'Error' -LogData $ErrorMessage + } } 'CreateRepo' { try { @@ -77,6 +91,7 @@ function Invoke-ExecGitHubAction { resultText = "Repository '$($Repo.name)' created" state = 'success' } + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Results.resultText -Sev 'Info' } } catch { Write-Information (Get-CippException -Exception $_ | ConvertTo-Json) @@ -84,6 +99,7 @@ function Invoke-ExecGitHubAction { resultText = 'You may not have permission to create repositories, check your PAT scopes and try again - {0}' -f $_.Exception.Message state = 'error' } + Write-LogMessage -headers $Headers -API $APIName -tenant 'Global' -message $Results.resultText -Sev 'Error' } } default { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ListCommunityRepoTemplates.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ListCommunityRepoTemplates.ps1 index b4e30f5613999..31ec0dac5c756 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ListCommunityRepoTemplates.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ListCommunityRepoTemplates.ps1 @@ -93,7 +93,8 @@ function Invoke-ListCommunityRepoTemplates { 'ExConnectorTemplate', 'AppTemplate', 'ContactTemplate', 'JITAdminTemplate', 'UserDefaultTemplate', 'AssignmentFilterTemplate', 'IntuneReusableSettingTemplate', 'SharePointTemplate', 'DlpCompliancePolicyTemplate', 'RetentionCompliancePolicyTemplate', - 'SensitivityLabelTemplate', 'SensitiveInfoTypeTemplate', 'BaselineTemplate' + 'SensitivityLabelTemplate', 'SensitiveInfoTypeTemplate', 'BaselineTemplate', + 'PIMRoleSettingsTemplate' ) $Warnings = [System.Collections.Generic.List[string]]::new() diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ListCommunityRepos.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ListCommunityRepos.ps1 index ab34213ee8185..70e8aa932e901 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ListCommunityRepos.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/GitHub/Invoke-ListCommunityRepos.ps1 @@ -51,10 +51,12 @@ function Invoke-ListCommunityRepos { $DefaultsChanged = $true } elseif ($Existing.TemplateTypes -ne $TemplateTypesJson -or $Existing.BuiltIn -ne $Repo.BuiltIn -or $Existing.Description -ne $Repo.Description -or $Existing.Name -ne $Repo.Name) { # Upgrade path: sync built-in metadata onto rows seeded by older versions - $Existing | Add-Member -NotePropertyName 'TemplateTypes' -NotePropertyValue $TemplateTypesJson -Force - $Existing | Add-Member -NotePropertyName 'BuiltIn' -NotePropertyValue $Repo.BuiltIn -Force - $Existing | Add-Member -NotePropertyName 'Description' -NotePropertyValue $Repo.Description -Force - $Existing | Add-Member -NotePropertyName 'Name' -NotePropertyValue $Repo.Name -Force + $Existing | Add-Member -NotePropertyMembers ([ordered]@{ + TemplateTypes = $TemplateTypesJson + BuiltIn = $Repo.BuiltIn + Description = $Repo.Description + Name = $Repo.Name + }) -Force Add-CIPPAzDataTableEntity @Table -Entity $Existing -Force $DefaultsChanged = $true } diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardAntiPhishPolicy.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardAntiPhishPolicy.ps1 index c202a60b3ff68..968b9b5e38085 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardAntiPhishPolicy.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardAntiPhishPolicy.ps1 @@ -127,6 +127,13 @@ function Invoke-CIPPStandardAntiPhishPolicy { $CurrentState = $ExistingPolicy | Select-Object Name, Enabled, PhishThresholdLevel, EnableMailboxIntelligence, EnableMailboxIntelligenceProtection, EnableSpoofIntelligence, EnableFirstContactSafetyTips, EnableSimilarUsersSafetyTips, EnableSimilarDomainsSafetyTips, EnableUnusualCharactersSafetyTips, EnableUnauthenticatedSender, EnableViaTag, AuthenticationFailAction, SpoofQuarantineTag, MailboxIntelligenceProtectionAction, MailboxIntelligenceQuarantineTag, TargetedUserProtectionAction, TargetedUserQuarantineTag, TargetedDomainProtectionAction, TargetedDomainQuarantineTag, EnableOrganizationDomainsProtection, EnableTargetedDomainsProtection, EnableTargetedUserProtection + # Get-AntiPhishPolicy only populates Enabled for the built-in default policy; on a custom policy + # the active state lives on its rule's State (see Invoke-ListAntiPhishingFilters). Without this + # the compare shows Enabled = null and the policy reads Non-Compliant even while it is active. + if ($CurrentState -and $null -ne $ExistingRule.State) { + $CurrentState.Enabled = $ExistingRule.State -eq 'Enabled' + } + if ($MDOLicensed) { $StateIsCorrect = ($CurrentState.Name -eq $PolicyName) -and ($CurrentState.Enabled -eq $true) -and diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardAppDeploy.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardAppDeploy.ps1 index 4c3aaea63d830..828d5c9103017 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardAppDeploy.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardAppDeploy.ps1 @@ -17,7 +17,7 @@ function Invoke-CIPPStandardAppDeploy { Automatically deploys approved business applications across all company locations and users, ensuring consistent access to essential tools and maintaining standardized software configurations. This streamlines application management and reduces IT deployment overhead. ADDEDCOMPONENT {"type":"select","multiple":false,"creatable":false,"label":"App Approval Mode","name":"standards.AppDeploy.mode","options":[{"label":"Template","value":"template"},{"label":"Copy Permissions","value":"copy"}]} - {"type":"autoComplete","multiple":true,"creatable":false,"label":"Select Applications","name":"standards.AppDeploy.templateIds","api":{"url":"/api/ListAppApprovalTemplates","labelField":"TemplateName","valueField":"TemplateId","queryKey":"StdAppApprovalTemplateList","addedField":{"AppId":"AppId"}},"condition":{"field":"standards.AppDeploy.mode","compareType":"is","compareValue":"template"}} + {"type":"autoComplete","multiple":true,"creatable":false,"label":"Select Applications","name":"standards.AppDeploy.templateIds","api":{"url":"/api/ListAppApprovalTemplates","labelField":"TemplateName","valueField":"TemplateId","queryKey":"StdAppApprovalTemplateList","addedField":{"AppId":"AppId"},"templateView":{"title":"App Approval Template"}},"condition":{"field":"standards.AppDeploy.mode","compareType":"is","compareValue":"template"}} {"type":"textField","name":"standards.AppDeploy.appids","label":"Application IDs, comma separated","condition":{"field":"standards.AppDeploy.mode","compareType":"isNot","compareValue":"template"}} IMPACT Low Impact diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardAuthenticationMethods.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardAuthenticationMethods.ps1 index 542041def8ca8..f16f32e0c1d37 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardAuthenticationMethods.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardAuthenticationMethods.ps1 @@ -7,8 +7,8 @@ function Invoke-CIPPStandardAuthenticationMethods { .SYNOPSIS (Label) Configure Authentication Methods .DESCRIPTION - (Helptext) Configures all authentication methods for the tenant including Microsoft Authenticator, FIDO2, SMS, Voice, Email OTP, Temporary Access Pass, Software OATH, Hardware OATH, Certificate-based, and QR Code Pin. Enable or disable each method and optionally target specific groups. - (DocsDescription) Unified standard to configure all authentication method policies in a single place. Each method can be independently enabled or disabled, targeted to all users or specific groups using group name wildcards, and configured with method-specific settings such as TAP lifetime, QR code pin length, Authenticator software OTP, and Email OTP external user access with exclude group targeting. + (Helptext) Configures all authentication methods for the tenant including Microsoft Authenticator, FIDO2, SMS, Voice, Email OTP, Temporary Access Pass, Software OATH, Hardware OATH, Certificate-based, and QR Code Pin. Set each method to Enabled, Disabled or Not Configured and optionally target specific groups. Methods set to Not Configured (or left blank) keep the tenant's current setting. + (DocsDescription) Unified standard to configure all authentication method policies in a single place. Each method can be independently set to Enabled, Disabled or Not Configured (leaving the tenant's current configuration untouched), targeted to all users or specific groups using group name wildcards, and configured with method-specific settings such as TAP lifetime, QR code pin length, Authenticator software OTP, and Email OTP external user access with exclude group targeting. .NOTES CAT Entra (AAD) Standards @@ -16,39 +16,39 @@ function Invoke-CIPPStandardAuthenticationMethods { EXECUTIVETEXT Provides centralized control over all tenant authentication methods from a single standard. Administrators can enable phishing-resistant methods like FIDO2 and Microsoft Authenticator while disabling less secure options like SMS and Voice. Each method supports group-level targeting using wildcard group names, allowing staged rollouts and granular control. ADDEDCOMPONENT - {"type":"switch","name":"standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled","label":"Microsoft Authenticator","defaultValue":false} - {"type":"textField","name":"standards.AuthenticationMethods.MicrosoftAuthenticatorGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled","compareType":"is","compareValue":true}} - {"type":"switch","name":"standards.AuthenticationMethods.MicrosoftAuthenticatorSoftwareOath","label":"Enable Software OTP in Authenticator","defaultValue":false,"condition":{"field":"standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled","compareType":"is","compareValue":true}} - {"type":"autoComplete","multiple":false,"creatable":false,"label":"Show Application Name in Push Notifications","name":"standards.AuthenticationMethods.MicrosoftAuthenticatorDisplayAppInfo","options":[{"label":"Microsoft managed","value":"default"},{"label":"Enabled","value":"enabled"},{"label":"Disabled","value":"disabled"}],"condition":{"field":"standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled","compareType":"is","compareValue":true}} - {"type":"autoComplete","multiple":false,"creatable":false,"label":"Show Geographic Location in Push Notifications","name":"standards.AuthenticationMethods.MicrosoftAuthenticatorDisplayLocation","options":[{"label":"Microsoft managed","value":"default"},{"label":"Enabled","value":"enabled"},{"label":"Disabled","value":"disabled"}],"condition":{"field":"standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled","compareType":"is","compareValue":true}} - {"type":"autoComplete","multiple":false,"creatable":false,"label":"Companion App (Authenticator Lite)","name":"standards.AuthenticationMethods.MicrosoftAuthenticatorCompanionApp","options":[{"label":"Microsoft managed","value":"default"},{"label":"Enabled","value":"enabled"},{"label":"Disabled","value":"disabled"}],"condition":{"field":"standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled","compareType":"is","compareValue":true}} - {"type":"switch","name":"standards.AuthenticationMethods.FIDO2Enabled","label":"FIDO2 Security Keys","defaultValue":false} - {"type":"textField","name":"standards.AuthenticationMethods.FIDO2Group","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.FIDO2Enabled","compareType":"is","compareValue":true}} - {"type":"switch","name":"standards.AuthenticationMethods.TAPEnabled","label":"Temporary Access Pass","defaultValue":false} - {"type":"textField","name":"standards.AuthenticationMethods.TAPGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.TAPEnabled","compareType":"is","compareValue":true}} - {"type":"autoComplete","multiple":false,"creatable":false,"label":"TAP Usage Mode","name":"standards.AuthenticationMethods.TAPUsableOnce","options":[{"label":"Only Once","value":"true"},{"label":"Multiple Logons","value":"false"}],"condition":{"field":"standards.AuthenticationMethods.TAPEnabled","compareType":"is","compareValue":true}} - {"type":"number","name":"standards.AuthenticationMethods.TAPDefaultLifetime","label":"TAP Default Lifetime (minutes)","defaultValue":60,"condition":{"field":"standards.AuthenticationMethods.TAPEnabled","compareType":"is","compareValue":true}} - {"type":"number","name":"standards.AuthenticationMethods.TAPMinLifetime","label":"TAP Minimum Lifetime (minutes)","defaultValue":60,"condition":{"field":"standards.AuthenticationMethods.TAPEnabled","compareType":"is","compareValue":true}} - {"type":"number","name":"standards.AuthenticationMethods.TAPMaxLifetime","label":"TAP Maximum Lifetime (minutes)","defaultValue":480,"condition":{"field":"standards.AuthenticationMethods.TAPEnabled","compareType":"is","compareValue":true}} - {"type":"number","name":"standards.AuthenticationMethods.TAPDefaultLength","label":"TAP Length (characters)","defaultValue":8,"condition":{"field":"standards.AuthenticationMethods.TAPEnabled","compareType":"is","compareValue":true}} - {"type":"switch","name":"standards.AuthenticationMethods.SoftwareOathEnabled","label":"Third-Party Software OATH Tokens","defaultValue":false} - {"type":"textField","name":"standards.AuthenticationMethods.SoftwareOathGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.SoftwareOathEnabled","compareType":"is","compareValue":true}} - {"type":"switch","name":"standards.AuthenticationMethods.HardwareOathEnabled","label":"Hardware OATH Tokens","defaultValue":false} - {"type":"textField","name":"standards.AuthenticationMethods.HardwareOathGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.HardwareOathEnabled","compareType":"is","compareValue":true}} - {"type":"switch","name":"standards.AuthenticationMethods.SMSEnabled","label":"SMS","defaultValue":false} - {"type":"textField","name":"standards.AuthenticationMethods.SMSGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.SMSEnabled","compareType":"is","compareValue":true}} - {"type":"switch","name":"standards.AuthenticationMethods.VoiceEnabled","label":"Voice Call","defaultValue":false} - {"type":"textField","name":"standards.AuthenticationMethods.VoiceGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.VoiceEnabled","compareType":"is","compareValue":true}} - {"type":"switch","name":"standards.AuthenticationMethods.EmailEnabled","label":"Email OTP","defaultValue":false} - {"type":"textField","name":"standards.AuthenticationMethods.EmailGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.EmailEnabled","compareType":"is","compareValue":true}} - {"type":"autoComplete","multiple":false,"creatable":false,"label":"Allow external users to use Email OTP","name":"standards.AuthenticationMethods.EmailAllowExternalIdToUseEmailOtp","options":[{"label":"Microsoft managed (default)","value":"default"},{"label":"Enabled","value":"enabled"},{"label":"Disabled","value":"disabled"}],"condition":{"field":"standards.AuthenticationMethods.EmailEnabled","compareType":"is","compareValue":true}} - {"type":"textField","name":"standards.AuthenticationMethods.EmailExcludeGroup","label":"Exclude Group Name (wildcard supported, blank = no exclusions)","required":false,"condition":{"field":"standards.AuthenticationMethods.EmailEnabled","compareType":"is","compareValue":true}} - {"type":"switch","name":"standards.AuthenticationMethods.x509CertificateEnabled","label":"Certificate-Based Authentication","defaultValue":false} - {"type":"textField","name":"standards.AuthenticationMethods.x509CertificateGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.x509CertificateEnabled","compareType":"is","compareValue":true}} - {"type":"switch","name":"standards.AuthenticationMethods.QRCodePinEnabled","label":"QR Code Pin","defaultValue":false} - {"type":"textField","name":"standards.AuthenticationMethods.QRCodePinGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.QRCodePinEnabled","compareType":"is","compareValue":true}} - {"type":"number","name":"standards.AuthenticationMethods.QRCodeLifetimeInDays","label":"QR Code Lifetime (days, 1-395)","defaultValue":365,"condition":{"field":"standards.AuthenticationMethods.QRCodePinEnabled","compareType":"is","compareValue":true}} - {"type":"number","name":"standards.AuthenticationMethods.QRCodePinLength","label":"QR Code PIN Length (8-20)","defaultValue":8,"condition":{"field":"standards.AuthenticationMethods.QRCodePinEnabled","compareType":"is","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"required":false,"name":"standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled","label":"Microsoft Authenticator","helperText":"Not Configured or blank leaves the tenant's current setting untouched.","options":[{"label":"Enabled","value":true},{"label":"Disabled","value":false},{"label":"Not Configured","value":"notConfigured"}]} + {"type":"textField","name":"standards.AuthenticationMethods.MicrosoftAuthenticatorGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled","compareType":"valueEq","compareValue":true}} + {"type":"switch","name":"standards.AuthenticationMethods.MicrosoftAuthenticatorSoftwareOath","label":"Enable Software OTP in Authenticator","defaultValue":false,"condition":{"field":"standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"label":"Show Application Name in Push Notifications","name":"standards.AuthenticationMethods.MicrosoftAuthenticatorDisplayAppInfo","options":[{"label":"Microsoft managed","value":"default"},{"label":"Enabled","value":"enabled"},{"label":"Disabled","value":"disabled"}],"condition":{"field":"standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"label":"Show Geographic Location in Push Notifications","name":"standards.AuthenticationMethods.MicrosoftAuthenticatorDisplayLocation","options":[{"label":"Microsoft managed","value":"default"},{"label":"Enabled","value":"enabled"},{"label":"Disabled","value":"disabled"}],"condition":{"field":"standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"label":"Companion App (Authenticator Lite)","name":"standards.AuthenticationMethods.MicrosoftAuthenticatorCompanionApp","options":[{"label":"Microsoft managed","value":"default"},{"label":"Enabled","value":"enabled"},{"label":"Disabled","value":"disabled"}],"condition":{"field":"standards.AuthenticationMethods.MicrosoftAuthenticatorEnabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"required":false,"name":"standards.AuthenticationMethods.FIDO2Enabled","label":"FIDO2 Security Keys","helperText":"Not Configured or blank leaves the tenant's current setting untouched.","options":[{"label":"Enabled","value":true},{"label":"Disabled","value":false},{"label":"Not Configured","value":"notConfigured"}]} + {"type":"textField","name":"standards.AuthenticationMethods.FIDO2Group","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.FIDO2Enabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"required":false,"name":"standards.AuthenticationMethods.TAPEnabled","label":"Temporary Access Pass","helperText":"Not Configured or blank leaves the tenant's current setting untouched.","options":[{"label":"Enabled","value":true},{"label":"Disabled","value":false},{"label":"Not Configured","value":"notConfigured"}]} + {"type":"textField","name":"standards.AuthenticationMethods.TAPGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.TAPEnabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"label":"TAP Usage Mode","name":"standards.AuthenticationMethods.TAPUsableOnce","options":[{"label":"Only Once","value":"true"},{"label":"Multiple Logons","value":"false"}],"condition":{"field":"standards.AuthenticationMethods.TAPEnabled","compareType":"valueEq","compareValue":true}} + {"type":"number","name":"standards.AuthenticationMethods.TAPDefaultLifetime","label":"TAP Default Lifetime (minutes)","defaultValue":60,"condition":{"field":"standards.AuthenticationMethods.TAPEnabled","compareType":"valueEq","compareValue":true}} + {"type":"number","name":"standards.AuthenticationMethods.TAPMinLifetime","label":"TAP Minimum Lifetime (minutes)","defaultValue":60,"condition":{"field":"standards.AuthenticationMethods.TAPEnabled","compareType":"valueEq","compareValue":true}} + {"type":"number","name":"standards.AuthenticationMethods.TAPMaxLifetime","label":"TAP Maximum Lifetime (minutes)","defaultValue":480,"condition":{"field":"standards.AuthenticationMethods.TAPEnabled","compareType":"valueEq","compareValue":true}} + {"type":"number","name":"standards.AuthenticationMethods.TAPDefaultLength","label":"TAP Length (characters)","defaultValue":8,"condition":{"field":"standards.AuthenticationMethods.TAPEnabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"required":false,"name":"standards.AuthenticationMethods.SoftwareOathEnabled","label":"Third-Party Software OATH Tokens","helperText":"Not Configured or blank leaves the tenant's current setting untouched.","options":[{"label":"Enabled","value":true},{"label":"Disabled","value":false},{"label":"Not Configured","value":"notConfigured"}]} + {"type":"textField","name":"standards.AuthenticationMethods.SoftwareOathGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.SoftwareOathEnabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"required":false,"name":"standards.AuthenticationMethods.HardwareOathEnabled","label":"Hardware OATH Tokens","helperText":"Not Configured or blank leaves the tenant's current setting untouched.","options":[{"label":"Enabled","value":true},{"label":"Disabled","value":false},{"label":"Not Configured","value":"notConfigured"}]} + {"type":"textField","name":"standards.AuthenticationMethods.HardwareOathGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.HardwareOathEnabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"required":false,"name":"standards.AuthenticationMethods.SMSEnabled","label":"SMS","helperText":"Not Configured or blank leaves the tenant's current setting untouched.","options":[{"label":"Enabled","value":true},{"label":"Disabled","value":false},{"label":"Not Configured","value":"notConfigured"}]} + {"type":"textField","name":"standards.AuthenticationMethods.SMSGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.SMSEnabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"required":false,"name":"standards.AuthenticationMethods.VoiceEnabled","label":"Voice Call","helperText":"Not Configured or blank leaves the tenant's current setting untouched.","options":[{"label":"Enabled","value":true},{"label":"Disabled","value":false},{"label":"Not Configured","value":"notConfigured"}]} + {"type":"textField","name":"standards.AuthenticationMethods.VoiceGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.VoiceEnabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"required":false,"name":"standards.AuthenticationMethods.EmailEnabled","label":"Email OTP","helperText":"Not Configured or blank leaves the tenant's current setting untouched.","options":[{"label":"Enabled","value":true},{"label":"Disabled","value":false},{"label":"Not Configured","value":"notConfigured"}]} + {"type":"textField","name":"standards.AuthenticationMethods.EmailGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.EmailEnabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"label":"Allow external users to use Email OTP","name":"standards.AuthenticationMethods.EmailAllowExternalIdToUseEmailOtp","options":[{"label":"Microsoft managed (default)","value":"default"},{"label":"Enabled","value":"enabled"},{"label":"Disabled","value":"disabled"}],"condition":{"field":"standards.AuthenticationMethods.EmailEnabled","compareType":"valueEq","compareValue":true}} + {"type":"textField","name":"standards.AuthenticationMethods.EmailExcludeGroup","label":"Exclude Group Name (wildcard supported, blank = no exclusions)","required":false,"condition":{"field":"standards.AuthenticationMethods.EmailEnabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"required":false,"name":"standards.AuthenticationMethods.x509CertificateEnabled","label":"Certificate-Based Authentication","helperText":"Not Configured or blank leaves the tenant's current setting untouched.","options":[{"label":"Enabled","value":true},{"label":"Disabled","value":false},{"label":"Not Configured","value":"notConfigured"}]} + {"type":"textField","name":"standards.AuthenticationMethods.x509CertificateGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.x509CertificateEnabled","compareType":"valueEq","compareValue":true}} + {"type":"autoComplete","multiple":false,"creatable":false,"required":false,"name":"standards.AuthenticationMethods.QRCodePinEnabled","label":"QR Code Pin","helperText":"Not Configured or blank leaves the tenant's current setting untouched.","options":[{"label":"Enabled","value":true},{"label":"Disabled","value":false},{"label":"Not Configured","value":"notConfigured"}]} + {"type":"textField","name":"standards.AuthenticationMethods.QRCodePinGroup","label":"Target Group Name (wildcard supported, blank = All Users)","required":false,"condition":{"field":"standards.AuthenticationMethods.QRCodePinEnabled","compareType":"valueEq","compareValue":true}} + {"type":"number","name":"standards.AuthenticationMethods.QRCodeLifetimeInDays","label":"QR Code Lifetime (days, 1-395)","defaultValue":365,"condition":{"field":"standards.AuthenticationMethods.QRCodePinEnabled","compareType":"valueEq","compareValue":true}} + {"type":"number","name":"standards.AuthenticationMethods.QRCodePinLength","label":"QR Code PIN Length (8-20)","defaultValue":8,"condition":{"field":"standards.AuthenticationMethods.QRCodePinEnabled","compareType":"valueEq","compareValue":true}} IMPACT High Impact ADDEDDATE @@ -83,11 +83,18 @@ function Invoke-CIPPStandardAuthenticationMethods { @{ Id = 'QRCodePin'; RemediationId = 'QRCodePin'; SettingKey = 'QRCodePin'; Label = 'QR Code Pin' } ) - # Determine which methods the user has explicitly configured + # Determine which methods the user has explicitly configured. The Enabled fields were + # switches (raw booleans) and are now autoCompletes ({label, value} wrappers) offering + # Enabled/Disabled/Not Configured - accept both shapes so existing templates keep their + # behaviour. Anything unrecognised (blank, 'notConfigured') means the method is not + # managed by this standard and the tenant's current configuration is left untouched. $ConfiguredMethods = foreach ($Method in $AuthMethods) { $EnabledKey = "$($Method.SettingKey)Enabled" - $EnabledValue = $Settings.$EnabledKey - if ($null -eq $EnabledValue) { continue } + $EnabledValue = $Settings.$EnabledKey.value ?? $Settings.$EnabledKey + $EnabledState = if ("$EnabledValue" -eq 'True' -or "$EnabledValue" -eq 'enabled') { $true } + elseif ("$EnabledValue" -eq 'False' -or "$EnabledValue" -eq 'disabled') { $false } + else { $null } + if ($null -eq $EnabledState) { continue } $GroupName = $Settings."$($Method.SettingKey)Group" $ExcludeGroupName = $Settings."$($Method.SettingKey)ExcludeGroup" [PSCustomObject]@{ @@ -95,7 +102,7 @@ function Invoke-CIPPStandardAuthenticationMethods { RemediationId = $Method.RemediationId Key = $Method.SettingKey Label = $Method.Label - Enabled = [bool]$EnabledValue + Enabled = $EnabledState GroupName = if ([string]::IsNullOrWhiteSpace($GroupName)) { $null } else { $GroupName } ExcludeGroupName = if ([string]::IsNullOrWhiteSpace($ExcludeGroupName)) { $null } else { $ExcludeGroupName } } diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardConditionalAccessTemplate.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardConditionalAccessTemplate.ps1 index 9f40cdbce9b6e..79a7326274e46 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardConditionalAccessTemplate.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardConditionalAccessTemplate.ps1 @@ -121,8 +121,11 @@ function Invoke-CIPPStandardConditionalAccessTemplate { $Policy = if ($JSONObj) { $JSONObj | ConvertFrom-Json -Depth 100 } else { $null } if ($null -eq $Policy) { - Write-LogMessage -API 'Standards' -tenant $Tenant -message "Conditional Access template '$($Settings.TemplateList.label)' ($($Settings.TemplateList.value)) could not be loaded from the template store - skipping." -Sev 'Error' - Set-CIPPStandardsCompareField -FieldName $FieldName -CurrentValue @{ Differences = "Template '$($Settings.TemplateList.label)' could not be loaded from the template store." } -ExpectedValue @{ Differences = @() } -Tenant $Tenant + # Same wording as Invoke-CIPPCATemplateBatch, so the report row says which template is + # gone and what to do about it instead of a bare "could not be loaded". + $MissingText = "Template '$($Settings.TemplateList.label)' ($($Settings.TemplateList.value)) no longer exists in the template library. Remove it from the standards template or select the template again." + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Conditional Access template '$($Settings.TemplateList.label)' ($($Settings.TemplateList.value)) could not be loaded from the template store - skipping. $MissingText" -Sev 'Error' + Set-CIPPStandardsCompareField -FieldName $FieldName -CurrentValue @{ Differences = $MissingText } -ExpectedValue @{ Differences = @() } -Tenant $Tenant return } diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDefaultPlatformRestrictions.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDefaultPlatformRestrictions.ps1 index 19218bfbaff55..2d3c9052d4855 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDefaultPlatformRestrictions.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDefaultPlatformRestrictions.ps1 @@ -7,8 +7,8 @@ function Invoke-CIPPStandardDefaultPlatformRestrictions { .SYNOPSIS (Label) Device enrollment restrictions .DESCRIPTION - (Helptext) Sets the default platform restrictions for enrolling devices into Intune. Note: Do not block personally owned if platform is blocked. - (DocsDescription) Sets the default platform restrictions for enrolling devices into Intune. Note: Do not block personally owned if platform is blocked. + (Helptext) Sets the default platform restrictions for enrolling devices into Intune, including optional minimum and maximum OS version limits per platform (Android Enterprise, Android, iOS/iPadOS and Windows). Note: Do not block personally owned if platform is blocked. + (DocsDescription) Sets the default platform restrictions for enrolling devices into Intune, including optional minimum and maximum OS version limits per platform (Android Enterprise, Android, iOS/iPadOS and Windows). Note: Do not block personally owned if platform is blocked. .NOTES CAT Intune Standards @@ -19,14 +19,22 @@ function Invoke-CIPPStandardDefaultPlatformRestrictions { ADDEDCOMPONENT {"type":"switch","name":"standards.DefaultPlatformRestrictions.platformAndroidForWorkBlocked","label":"Block platform Android Enterprise (work profile)","default":false} {"type":"switch","name":"standards.DefaultPlatformRestrictions.personalAndroidForWorkBlocked","label":"Block personally owned Android Enterprise (work profile)","default":false} + {"type":"textField","name":"standards.DefaultPlatformRestrictions.osMinimumVersionAndroidForWork","label":"Android Enterprise (work profile) minimum OS version","helperText":"Example: 11.0. Leave blank to not enforce a minimum.","required":false} + {"type":"textField","name":"standards.DefaultPlatformRestrictions.osMaximumVersionAndroidForWork","label":"Android Enterprise (work profile) maximum OS version","helperText":"Example: 14.0. Leave blank to not enforce a maximum.","required":false} {"type":"switch","name":"standards.DefaultPlatformRestrictions.platformAndroidBlocked","label":"Block platform Android","default":false} {"type":"switch","name":"standards.DefaultPlatformRestrictions.personalAndroidBlocked","label":"Block personally owned Android","default":false} + {"type":"textField","name":"standards.DefaultPlatformRestrictions.osMinimumVersionAndroid","label":"Android minimum OS version","helperText":"Example: 10.0. Leave blank to not enforce a minimum.","required":false} + {"type":"textField","name":"standards.DefaultPlatformRestrictions.osMaximumVersionAndroid","label":"Android maximum OS version","helperText":"Example: 13.0. Leave blank to not enforce a maximum.","required":false} {"type":"switch","name":"standards.DefaultPlatformRestrictions.platformiOSBlocked","label":"Block platform iOS","default":false} {"type":"switch","name":"standards.DefaultPlatformRestrictions.personaliOSBlocked","label":"Block personally owned iOS","default":false} + {"type":"textField","name":"standards.DefaultPlatformRestrictions.osMinimumVersioniOS","label":"iOS/iPadOS minimum OS version","helperText":"Example: 16.1. Leave blank to not enforce a minimum.","required":false} + {"type":"textField","name":"standards.DefaultPlatformRestrictions.osMaximumVersioniOS","label":"iOS/iPadOS maximum OS version","helperText":"Example: 18.0. Leave blank to not enforce a maximum.","required":false} {"type":"switch","name":"standards.DefaultPlatformRestrictions.platformMacOSBlocked","label":"Block platform macOS","default":false} {"type":"switch","name":"standards.DefaultPlatformRestrictions.personalMacOSBlocked","label":"Block personally owned macOS","default":false} {"type":"switch","name":"standards.DefaultPlatformRestrictions.platformWindowsBlocked","label":"Block platform Windows","default":false} {"type":"switch","name":"standards.DefaultPlatformRestrictions.personalWindowsBlocked","label":"Block personally owned Windows","default":false} + {"type":"textField","name":"standards.DefaultPlatformRestrictions.osMinimumVersionWindows","label":"Windows minimum OS version","helperText":"Example: 10.0.19045.0. Leave blank to not enforce a minimum.","required":false} + {"type":"textField","name":"standards.DefaultPlatformRestrictions.osMaximumVersionWindows","label":"Windows maximum OS version","helperText":"Example: 10.0.22631.0. Leave blank to not enforce a maximum.","required":false} IMPACT Low Impact ADDEDDATE @@ -87,6 +95,22 @@ function Invoke-CIPPStandardDefaultPlatformRestrictions { personalWindowsBlocked = [bool]$Settings.personalWindowsBlocked } + # Optional minimum/maximum OS version per platform. macOS is intentionally absent - the Intune + # enrollment restriction for macOS carries no version limit. Each is enforced ONLY when the + # operator supplied it: a blank field means 'no opinion', so it is left out of the compare, + # the report and the remediation body. osMinimumVersion/osMaximumVersion are free-form strings + # on Graph, compared as strings. + $VersionMap = @( + @{ Setting = 'osMinimumVersionAndroidForWork'; Restriction = 'androidForWorkRestriction'; Property = 'osMinimumVersion' } + @{ Setting = 'osMaximumVersionAndroidForWork'; Restriction = 'androidForWorkRestriction'; Property = 'osMaximumVersion' } + @{ Setting = 'osMinimumVersionAndroid'; Restriction = 'androidRestriction'; Property = 'osMinimumVersion' } + @{ Setting = 'osMaximumVersionAndroid'; Restriction = 'androidRestriction'; Property = 'osMaximumVersion' } + @{ Setting = 'osMinimumVersioniOS'; Restriction = 'iosRestriction'; Property = 'osMinimumVersion' } + @{ Setting = 'osMaximumVersioniOS'; Restriction = 'iosRestriction'; Property = 'osMaximumVersion' } + @{ Setting = 'osMinimumVersionWindows'; Restriction = 'windowsRestriction'; Property = 'osMinimumVersion' } + @{ Setting = 'osMaximumVersionWindows'; Restriction = 'windowsRestriction'; Property = 'osMaximumVersion' } + ) + $StateIsCorrect = ($CurrentState.androidForWorkRestriction.platformBlocked -eq $DesiredState.platformAndroidForWorkBlocked) -and ($CurrentState.androidForWorkRestriction.personalDeviceEnrollmentBlocked -eq $DesiredState.personalAndroidForWorkBlocked) -and ($CurrentState.androidRestriction.platformBlocked -eq $DesiredState.platformAndroidBlocked) -and @@ -111,46 +135,65 @@ function Invoke-CIPPStandardDefaultPlatformRestrictions { personalWindowsBlocked = $CurrentState.windowsRestriction.personalDeviceEnrollmentBlocked } + # Fold in the configured version limits: grade only the fields the operator set, and surface + # both the desired and current value on the compare/report objects so a version drift is visible. + foreach ($Check in $VersionMap) { + $DesiredVersion = "$($Settings.($Check.Setting))" + if ([string]::IsNullOrWhiteSpace($DesiredVersion)) { continue } + $CurrentVersion = "$($CurrentState.($Check.Restriction).($Check.Property))" + $DesiredState | Add-Member -NotePropertyName $Check.Setting -NotePropertyValue $DesiredVersion -Force + $CompareField | Add-Member -NotePropertyName $Check.Setting -NotePropertyValue $CurrentVersion -Force + if ($CurrentVersion -ne $DesiredVersion) { $StateIsCorrect = $false } + } + $ExpectedValue = $DesiredState if ($Settings.remediate -eq $true) { if ($StateIsCorrect -eq $true) { Write-LogMessage -API 'Standards' -Tenant $Tenant -Message 'DefaultPlatformRestrictions is already applied correctly.' -Sev Info } else { + $RemediationBody = [PSCustomObject]@{ + '@odata.type' = '#microsoft.graph.deviceEnrollmentPlatformRestrictionsConfiguration' + androidForWorkRestriction = [PSCustomObject]@{ + '@odata.type' = 'microsoft.graph.deviceEnrollmentPlatformRestriction' + platformBlocked = $DesiredState.platformAndroidForWorkBlocked + personalDeviceEnrollmentBlocked = $DesiredState.personalAndroidForWorkBlocked + } + androidRestriction = [PSCustomObject]@{ + '@odata.type' = 'microsoft.graph.deviceEnrollmentPlatformRestriction' + platformBlocked = $DesiredState.platformAndroidBlocked + personalDeviceEnrollmentBlocked = $DesiredState.personalAndroidBlocked + } + iosRestriction = [PSCustomObject]@{ + '@odata.type' = 'microsoft.graph.deviceEnrollmentPlatformRestriction' + platformBlocked = $DesiredState.platformiOSBlocked + personalDeviceEnrollmentBlocked = $DesiredState.personaliOSBlocked + } + macOSRestriction = [PSCustomObject]@{ + '@odata.type' = 'microsoft.graph.deviceEnrollmentPlatformRestriction' + platformBlocked = $DesiredState.platformMacOSBlocked + personalDeviceEnrollmentBlocked = $DesiredState.personalMacOSBlocked + } + windowsRestriction = [PSCustomObject]@{ + '@odata.type' = 'microsoft.graph.deviceEnrollmentPlatformRestriction' + platformBlocked = $DesiredState.platformWindowsBlocked + personalDeviceEnrollmentBlocked = $DesiredState.personalWindowsBlocked + } + } + # Only write a version limit the operator set; a blank field is left off the payload + # so an unconfigured platform keeps whatever version limit it already has. + foreach ($Check in $VersionMap) { + $DesiredVersion = "$($Settings.($Check.Setting))" + if ([string]::IsNullOrWhiteSpace($DesiredVersion)) { continue } + $RemediationBody.($Check.Restriction) | Add-Member -NotePropertyName $Check.Property -NotePropertyValue $DesiredVersion -Force + } $cmdParam = @{ tenantid = $Tenant uri = "https://graph.microsoft.com/beta/deviceManagement/deviceEnrollmentConfigurations/$($CurrentState.id)" AsApp = $false Type = 'PATCH' ContentType = 'application/json; charset=utf-8' - Body = [PSCustomObject]@{ - '@odata.type' = '#microsoft.graph.deviceEnrollmentPlatformRestrictionsConfiguration' - androidForWorkRestriction = [PSCustomObject]@{ - '@odata.type' = 'microsoft.graph.deviceEnrollmentPlatformRestriction' - platformBlocked = $DesiredState.platformAndroidForWorkBlocked - personalDeviceEnrollmentBlocked = $DesiredState.personalAndroidForWorkBlocked - } - androidRestriction = [PSCustomObject]@{ - '@odata.type' = 'microsoft.graph.deviceEnrollmentPlatformRestriction' - platformBlocked = $DesiredState.platformAndroidBlocked - personalDeviceEnrollmentBlocked = $DesiredState.personalAndroidBlocked - } - iosRestriction = [PSCustomObject]@{ - '@odata.type' = 'microsoft.graph.deviceEnrollmentPlatformRestriction' - platformBlocked = $DesiredState.platformiOSBlocked - personalDeviceEnrollmentBlocked = $DesiredState.personaliOSBlocked - } - macOSRestriction = [PSCustomObject]@{ - '@odata.type' = 'microsoft.graph.deviceEnrollmentPlatformRestriction' - platformBlocked = $DesiredState.platformMacOSBlocked - personalDeviceEnrollmentBlocked = $DesiredState.personalMacOSBlocked - } - windowsRestriction = [PSCustomObject]@{ - '@odata.type' = 'microsoft.graph.deviceEnrollmentPlatformRestriction' - platformBlocked = $DesiredState.platformWindowsBlocked - personalDeviceEnrollmentBlocked = $DesiredState.personalWindowsBlocked - } - } | ConvertTo-Json -Compress -Depth 10 + Body = $RemediationBody | ConvertTo-Json -Compress -Depth 10 } try { $null = New-GraphPostRequest @cmdParam diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDeployContactTemplates.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDeployContactTemplates.ps1 index 75154d84641ee..0fa614dc1e356 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDeployContactTemplates.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDeployContactTemplates.ps1 @@ -153,7 +153,7 @@ function Invoke-CIPPStandardDeployContactTemplates { @{ Template = 'jobTitle'; Current = $ExtendedContact.Title } @{ Template = 'city'; Current = $ExtendedContact.City } @{ Template = 'postalCode'; Current = $ExtendedContact.PostalCode } - @{ Template = 'country'; Current = $ExtendedContact.CountryOrRegion } + @{ Template = 'country'; Current = $ExtendedContact.CountryOrRegion; IsCountry = $true } @{ Template = 'mobilePhone'; Current = $ExtendedContact.MobilePhone } ) @@ -172,9 +172,13 @@ function Invoke-CIPPStandardDeployContactTemplates { # Only compare if template specifies a value; empty template fields are not enforced. if ([string]::IsNullOrWhiteSpace($TemplateValue)) { continue } + # country: the template stores an ISO code ('US') but Exchange returns the + # full name ('United States'), so normalise both to a code before comparing. # Case-insensitive compare for email; exact for everything else. $IsEmail = $Field.Template -eq 'email' - $Mismatch = if ($IsEmail) { + $Mismatch = if ($Field.IsCountry) { + [string]::IsNullOrWhiteSpace($CurrentValue) -or (ConvertTo-CIPPCountryCode $TemplateValue) -ne (ConvertTo-CIPPCountryCode $CurrentValue) + } elseif ($IsEmail) { [string]::IsNullOrWhiteSpace($CurrentValue) -or -not $TemplateValue.Equals($CurrentValue, [System.StringComparison]::OrdinalIgnoreCase) } else { [string]::IsNullOrWhiteSpace($CurrentValue) -or $TemplateValue -ne $CurrentValue diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableGuests.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableGuests.ps1 index beb979a11cadf..3f7068abcda74 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableGuests.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableGuests.ps1 @@ -7,8 +7,8 @@ function Invoke-CIPPStandardDisableGuests { .SYNOPSIS (Label) Disable Guest accounts that have not logged on for a number of days .DESCRIPTION - (Helptext) Blocks login for guest users that have not logged in for a number of days - (DocsDescription) Blocks login for guest users that have not logged in for a number of days + (Helptext) Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone. + (DocsDescription) Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone. .NOTES CAT Entra (AAD) Standards @@ -18,6 +18,7 @@ function Invoke-CIPPStandardDisableGuests { Automatically disables external guest accounts that haven't been used for a number of days, reducing security risks from dormant accounts while maintaining access for active external collaborators. This helps maintain a clean user directory and reduces potential attack vectors. ADDEDCOMPONENT {"type":"number","name":"standards.DisableGuests.days","required":true,"defaultValue":90,"label":"Days of inactivity"} + {"type":"switch","name":"standards.DisableGuests.IncludeNeverSignedIn","label":"Disable accounts that have not yet signed in","defaultValue":false} IMPACT Medium Impact ADDEDDATE @@ -48,6 +49,8 @@ function Invoke-CIPPStandardDisableGuests { } #we're done. $checkDays = if ($Settings.days) { $Settings.days } else { 90 } # Default to 90 days if not set. Pre v8.5.0 compatibility + # Off unless the template turns it on, so templates that predate the switch keep skipping guests with no sign-in on record. + $IncludeNeverSignedIn = $Settings.IncludeNeverSignedIn -eq $true $Days = (Get-Date).AddDays(-$checkDays).ToUniversalTime() $Lookup = $Days.ToString('o') $AuditLookup = (Get-Date).AddDays(-7).ToUniversalTime().ToString('o') @@ -55,18 +58,29 @@ function Invoke-CIPPStandardDisableGuests { try { $GraphRequest = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users?`$filter=createdDateTime le $Lookup and userType eq 'Guest' and accountEnabled eq true &`$select=id,UserPrincipalName,signInActivity,mail,userType,accountEnabled,createdDateTime,externalUserState" -scope 'https://graph.microsoft.com/.default' -tenantid $Tenant - $EnrichedGuests = foreach ($guest in $GraphRequest) { - if ($guest.signInActivity -and $guest.signInActivity.lastSuccessfulSignInDateTime) { - $lastSignIn = [datetime]$guest.signInActivity.lastSuccessfulSignInDateTime - if ($lastSignIn.ToUniversalTime() -le $Days) { + $StaleGuests = foreach ($guest in $GraphRequest) { + # Newest of the interactive, non-interactive and successful sign-in timestamps - the view the + # Entra portal and the inactive-guest alert give - rather than successful sign-ins alone, which + # stay old while a blocked or disabled guest keeps trying. + $LastSignIn = Get-CIPPLastSignInDateTime -SignInActivity $guest.signInActivity + if ($LastSignIn) { + if ($LastSignIn -le $Days) { + $guest | Add-Member -NotePropertyMembers ([ordered]@{ + LastSignInDateTime = $LastSignIn + NeverSignedIn = $false + }) -Force $guest } - } elseif ($guest.externalUserState -eq 'PendingAcceptance') { - # Never accepted the invite; createdDateTime is already <= $Days due to the server-side filter + } elseif ($IncludeNeverSignedIn) { + # No sign-in attempt on record; createdDateTime is already <= $Days due to the server-side filter + $guest | Add-Member -NotePropertyMembers ([ordered]@{ + LastSignInDateTime = $null + NeverSignedIn = $true + }) -Force $guest } } - $GraphRequest = @($EnrichedGuests) + $GraphRequest = @($StaleGuests) } catch { $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message Write-LogMessage -API 'Standards' -Tenant $Tenant -Message "Could not get the DisableGuests state for $Tenant. Error: $ErrorMessage" -Sev Error @@ -76,7 +90,7 @@ function Invoke-CIPPStandardDisableGuests { $AuditResults = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/auditLogs/directoryAudits?`$filter=activityDisplayName eq 'Enable account' and activityDateTime ge $AuditLookup&`$select=targetResources" -scope 'https://graph.microsoft.com/.default' -tenantid $Tenant $RecentlyReactivatedUsers = @(foreach ($AuditEntry in $AuditResults) { $AuditEntry.targetResources[0].id }) | Select-Object -Unique - $GraphRequest = $GraphRequest | Where-Object { -not ($RecentlyReactivatedUsers -contains $_.id) } + $GraphRequest = @($GraphRequest | Where-Object { -not ($RecentlyReactivatedUsers -contains $_.id) }) if ($Settings.remediate -eq $true) { if ($GraphRequest.Count -gt 0) { @@ -100,17 +114,12 @@ function Invoke-CIPPStandardDisableGuests { $result = $BulkResults[$i] $guest = $GraphRequest[$i] - $lastSignIn = $guest.signInActivity?.lastSuccessfulSignInDateTime - if (-not $lastSignIn -and $guest.EnrichedLastSignInDateTime) { - $lastSignIn = $guest.EnrichedLastSignInDateTime - } - if ($result.status -eq 200 -or $result.status -eq 204) { $guest.accountEnabled = $false - $reason = if ($guest.externalUserState -eq 'PendingAcceptance') { - "unredeemed invite created $($guest.createdDateTime)" + $reason = if ($guest.NeverSignedIn) { + "never signed in, created $($guest.createdDateTime)" } else { - "last sign-in: $lastSignIn" + "last sign-in: $($guest.LastSignInDateTime.ToString('o'))" } Write-LogMessage -API 'Standards' -tenant $tenant -message "Disabled guest $($guest.UserPrincipalName) ($($guest.id)). Reason: $reason" -sev Info } else { @@ -123,16 +132,16 @@ function Invoke-CIPPStandardDisableGuests { Write-LogMessage -API 'Standards' -tenant $tenant -message "Failed to process bulk disable guests request: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage } } else { - Write-LogMessage -API 'Standards' -tenant $tenant -message "No guests accounts with a login longer than $checkDays days ago - all guest accounts are already compliant." -sev Info + Write-LogMessage -API 'Standards' -tenant $tenant -message "No guest accounts without a sign-in in the last $checkDays days - all guest accounts are already compliant." -sev Info } } if ($Settings.alert -eq $true) { if ($GraphRequest.Count -gt 0) { - $Filtered = $GraphRequest | Select-Object -Property UserPrincipalName, id, signInActivity, mail, userType, accountEnabled, externalUserState, createdDateTime - $PendingCount = @($Filtered | Where-Object { $_.externalUserState -eq 'PendingAcceptance' }).Count - $StaleCount = $Filtered.Count - $PendingCount - $AlertMessage = "Stale guest accounts found: $($GraphRequest.Count) total ($StaleCount inactive >$checkDays days, $PendingCount unredeemed invites >$checkDays days old)" + $Filtered = @($GraphRequest | Select-Object -Property UserPrincipalName, id, signInActivity, LastSignInDateTime, NeverSignedIn, mail, userType, accountEnabled, externalUserState, createdDateTime) + $NeverSignedInCount = @($Filtered | Where-Object { $_.NeverSignedIn }).Count + $StaleCount = $Filtered.Count - $NeverSignedInCount + $AlertMessage = "Stale guest accounts found: $($GraphRequest.Count) total ($StaleCount with no sign-in attempt in $checkDays days, $NeverSignedInCount never signed in and created more than $checkDays days ago)" Write-StandardsAlert -message $AlertMessage -object $Filtered -tenant $tenant -standardName 'DisableGuests' -standardId $Settings.standardId Write-LogMessage -API 'Standards' -tenant $tenant -message $AlertMessage -sev Info } else { @@ -140,26 +149,28 @@ function Invoke-CIPPStandardDisableGuests { } } if ($Settings.report -eq $true) { - $Filtered = $GraphRequest | Where-Object { $_.accountEnabled } | Select-Object -Property UserPrincipalName, id, signInActivity, EnrichedLastSignInDateTime, mail, userType, accountEnabled, externalUserState, createdDateTime - $PendingInvites = @($Filtered | Where-Object { $_.externalUserState -eq 'PendingAcceptance' }) - $StaleSignIns = @($Filtered | Where-Object { $_.externalUserState -ne 'PendingAcceptance' }) + $Filtered = @($GraphRequest | Where-Object { $_.accountEnabled } | Select-Object -Property UserPrincipalName, id, signInActivity, LastSignInDateTime, NeverSignedIn, mail, userType, accountEnabled, externalUserState, createdDateTime) + $NeverSignedIn = @($Filtered | Where-Object { $_.NeverSignedIn }) + $StaleSignIns = @($Filtered | Where-Object { -not $_.NeverSignedIn }) $CurrentValue = [PSCustomObject]@{ - GuestsDisabledAfterDays = $checkDays - GuestsDisabledAccountCount = $Filtered.Count - GuestsStaleSignInCount = $StaleSignIns.Count - GuestsPendingAcceptanceCount = $PendingInvites.Count - GuestsDisabledAccountDetails = @($Filtered) - GuestsPendingAcceptanceDetails = $PendingInvites + GuestsDisabledAfterDays = $checkDays + GuestsIncludeNeverSignedIn = $IncludeNeverSignedIn + GuestsDisabledAccountCount = $Filtered.Count + GuestsStaleSignInCount = $StaleSignIns.Count + GuestsNeverSignedInCount = $NeverSignedIn.Count + GuestsDisabledAccountDetails = $Filtered + GuestsNeverSignedInDetails = $NeverSignedIn } $ExpectedValue = [PSCustomObject]@{ - GuestsDisabledAfterDays = $checkDays - GuestsDisabledAccountCount = 0 - GuestsStaleSignInCount = 0 - GuestsPendingAcceptanceCount = 0 - GuestsDisabledAccountDetails = @() - GuestsPendingAcceptanceDetails = @() + GuestsDisabledAfterDays = $checkDays + GuestsIncludeNeverSignedIn = $IncludeNeverSignedIn + GuestsDisabledAccountCount = 0 + GuestsStaleSignInCount = 0 + GuestsNeverSignedInCount = 0 + GuestsDisabledAccountDetails = @() + GuestsNeverSignedInDetails = @() } Set-CIPPStandardsCompareField -FieldName 'standards.DisableGuests' -CurrentValue $CurrentValue -ExpectedValue $ExpectedValue -TenantFilter $Tenant diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableInactiveUsers.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableInactiveUsers.ps1 index 2bc0aec72ac66..19a1e9fd792c2 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableInactiveUsers.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableInactiveUsers.ps1 @@ -68,14 +68,18 @@ function Invoke-CIPPStandardDisableInactiveUsers { if ($user.signInActivity.lastSuccessfulSignInDateTime) { $lastSignIn = [datetime]$user.signInActivity.lastSuccessfulSignInDateTime if ($lastSignIn.ToUniversalTime() -le $Days) { - $user | Add-Member -NotePropertyName 'EnrichedLastSignInDateTime' -NotePropertyValue $user.signInActivity.lastSuccessfulSignInDateTime -Force - $user | Add-Member -NotePropertyName 'NeverSignedIn' -NotePropertyValue $false -Force + $user | Add-Member -NotePropertyMembers ([ordered]@{ + EnrichedLastSignInDateTime = $user.signInActivity.lastSuccessfulSignInDateTime + NeverSignedIn = $false + }) -Force $user } } else { # signInActivity present but no successful sign-in; createdDateTime already <= $Days via server-side filter - $user | Add-Member -NotePropertyName 'EnrichedLastSignInDateTime' -NotePropertyValue $null -Force - $user | Add-Member -NotePropertyName 'NeverSignedIn' -NotePropertyValue $true -Force + $user | Add-Member -NotePropertyMembers ([ordered]@{ + EnrichedLastSignInDateTime = $null + NeverSignedIn = $true + }) -Force $user } } diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableSharedMailbox.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableSharedMailbox.ps1 index 1e2f629a31e50..2eb5ae184ff72 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableSharedMailbox.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableSharedMailbox.ps1 @@ -36,16 +36,35 @@ function Invoke-CIPPStandardDisableSharedMailbox { param($Tenant, $Settings) + # Separate catches so a cold user cache and an Exchange failure read differently. try { - $AllUsers = New-CIPPDbRequest -TenantFilter $Tenant -Type 'Users' - $UserList = $AllUsers | Where-Object { - $_.accountEnabled -eq $true -and - $_.onPremisesSyncEnabled -ne $true - } - $SharedMailboxList = (New-GraphGetRequest -uri "https://outlook.office365.com/adminapi/beta/$($Tenant)/Mailbox" -Tenantid $Tenant -scope ExchangeOnline | Where-Object { $_.RecipientTypeDetails -eq 'SharedMailbox' -or $_.RecipientTypeDetails -eq 'SchedulingMailbox' -and $_.UserPrincipalName -in $UserList.UserPrincipalName }) + $AllUsers = @(New-CIPPDbRequest -TenantFilter $Tenant -Type 'Users') } catch { $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message - Write-LogMessage -API 'Standards' -Tenant $Tenant -Message "Could not get the DisableSharedMailbox state for $Tenant. Error: $ErrorMessage" -Sev Error + Write-LogMessage -API 'Standards' -Tenant $Tenant -Message "Could not get the DisableSharedMailbox state for $Tenant, could not read the cached user list. Error: $ErrorMessage" -Sev Error + return + } + + if ($AllUsers.Count -eq 0) { + # No user cache means enabled and disabled look alike; reporting nothing beats reporting everything. + Write-LogMessage -API 'Standards' -Tenant $Tenant -Message "Could not get the DisableSharedMailbox state for $Tenant, the cached user list is empty. Run a user data collection for this tenant first." -Sev Warning + return + } + + $UserList = $AllUsers | Where-Object { + $_.accountEnabled -eq $true -and + $_.onPremisesSyncEnabled -ne $true + } + + try { + # (A -or B) -and C: same meaning as before, parentheses for readability. + $SharedMailboxList = @(New-GraphGetRequest -uri "https://outlook.office365.com/adminapi/beta/$($Tenant)/Mailbox" -Tenantid $Tenant -scope ExchangeOnline | Where-Object { + ($_.RecipientTypeDetails -eq 'SharedMailbox' -or $_.RecipientTypeDetails -eq 'SchedulingMailbox') -and + $_.UserPrincipalName -in $UserList.UserPrincipalName + }) + } catch { + $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message + Write-LogMessage -API 'Standards' -Tenant $Tenant -Message "Could not get the DisableSharedMailbox state for $Tenant, could not list mailboxes from Exchange. Error: $ErrorMessage" -Sev Error return } @@ -65,6 +84,7 @@ function Invoke-CIPPStandardDisableSharedMailbox { } } + $DisabledKeys = [System.Collections.Generic.HashSet[string]]::new([StringComparer]::OrdinalIgnoreCase) try { $BulkResults = New-GraphBulkRequest -tenantid $Tenant -Requests @($BulkRequests) @@ -74,12 +94,16 @@ function Invoke-CIPPStandardDisableSharedMailbox { if ($result.status -eq 200 -or $result.status -eq 204) { Write-LogMessage -API 'Standards' -tenant $Tenant -message "Entra account for shared mailbox $($Mailbox.DisplayName) ($($Mailbox.ObjectKey)) disabled." -sev Info + $null = $DisabledKeys.Add("$($Mailbox.ObjectKey)") $UpdateDB = $true } else { $errorMsg = if ($result.body.error.message) { $result.body.error.message } else { "Unknown error (Status: $($result.status))" } Write-LogMessage -API 'Standards' -tenant $Tenant -message "Failed to disable Entra account for shared mailbox $($Mailbox.DisplayName) ($($Mailbox.ObjectKey)): $errorMsg" -sev Error } } + + # Report what is left after remediation, not what was found. + $SharedMailboxList = @($SharedMailboxList | Where-Object { -not $DisabledKeys.Contains("$($_.ObjectKey)") }) } catch { $ErrorMessage = Get-CippException -Exception $_ Write-LogMessage -API 'Standards' -tenant $Tenant -message "Failed to process bulk disable shared mailboxes request: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardEnableMailboxAuditing.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardEnableMailboxAuditing.ps1 index 9f34f19c89e07..3d0f4dade4237 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardEnableMailboxAuditing.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardEnableMailboxAuditing.ps1 @@ -66,73 +66,51 @@ function Invoke-CIPPStandardEnableMailboxAuditing { try { New-ExoRequest -tenantid $Tenant -cmdlet 'Set-OrganizationConfig' -cmdParams @{AuditDisabled = $false } -useSystemMailbox $true Write-LogMessage -API 'Standards' -tenant $Tenant -message 'Tenant level mailbox audit enabled' -sev Info - $LogMessage = 'Tenant level mailbox audit enabled. ' } catch { $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message Write-LogMessage -API 'Standards' -tenant $Tenant -message "Failed to enable tenant level mailbox audit. Error: $ErrorMessage" -sev Error } } else { - $LogMessage = 'Tenant level mailbox audit already enabled. ' + Write-LogMessage -API 'Standards' -tenant $Tenant -message 'Tenant level mailbox audit already enabled' -sev Info } - # Commented out because MS recommends NOT doing this anymore. From docs: https://learn.microsoft.com/en-us/purview/audit-mailboxes#verify-mailbox-auditing-on-by-default-is-turned-on - # When you turn on mailbox auditing on by default for the organization, the AuditEnabled property for affected mailboxes doesn't change from False to True. In other words, mailbox auditing on by default ignores the AuditEnabled property on mailboxes. - # Auditing is automatically turned on when you create a new mailbox. You don't need to manually enable mailbox auditing for new users. - # You don't need to manage the mailbox actions that are audited. A predefined set of mailbox actions are audited by default for each sign-in type (Admin, Delegate, and Owner). - # When Microsoft releases a new mailbox action, the action might be added automatically to the list of mailbox actions that are audited by default (subject to the user having the appropriate license). This result means you don't need to add new actions on mailboxes as they're released. - # You have a consistent mailbox auditing policy across your organization because you're auditing the same actions for all mailboxes. - #$Mailboxes = New-ExoRequest -tenantid $Tenant -cmdlet 'Get-Mailbox' -cmdParams @{filter = "auditenabled -eq 'False'" } -useSystemMailbox $true -Select 'AuditEnabled,UserPrincipalName' - #$Request = $mailboxes | ForEach-Object { - # @{ - # CmdletInput = @{ - # CmdletName = 'Set-Mailbox' - # Parameters = @{Identity = $_.UserPrincipalName; AuditEnabled = $true } - # } - #} - #} - - #$BatchResults = New-ExoBulkRequest -tenantid $tenant -cmdletArray @($Request) - #$BatchResults | ForEach-Object { - # if ($_.error) { - # $ErrorMessage = Get-NormalizedError -Message $_.error - # Write-Host "Failed to enable user level mailbox audit for $($_.target). Error: $ErrorMessage" - # Write-LogMessage -API 'Standards' -tenant $Tenant -message "Failed to enable user level mailbox audit for $($_.target). Error: $ErrorMessage" -sev Error - # } - #} - - # Disable audit bypass for all mailboxes that have it enabled + # Per-mailbox AuditEnabled is intentionally not set here. With mailbox auditing on by default + # (AuditDisabled = $false, set above) Microsoft applies the default per-sign-in-type audit + # action sets and Get-Mailbox reports AuditEnabled = True on supported mailboxes, so enabling + # each mailbox individually is redundant. + # https://learn.microsoft.com/en-us/purview/audit-mailboxes + + # Disable audit bypass for any mailbox that has it enabled, so no user is excluded from + # auditing. The bypass flag is not a Get-Mailbox property - it lives on the association. + try { + $BypassMailboxes = @(New-ExoRequest -tenantid $Tenant -cmdlet 'Get-MailboxAuditBypassAssociation' -useSystemMailbox $true | Where-Object { $_.AuditBypassEnabled -eq $true }) + } catch { + $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Failed to retrieve mailbox audit bypass associations. Error: $ErrorMessage" -sev Error + $BypassMailboxes = @() + } - #$BypassMailboxes = New-ExoRequest -tenantid $Tenant -cmdlet 'Get-MailboxAuditBypassAssociation' -select 'GUID, AuditBypassEnabled, Name' -useSystemMailbox $true | Where-Object { $_.AuditBypassEnabled -eq $true } - $Request = foreach ($Mailbox in $BypassMailboxes) { - @{ - CmdletInput = @{ - CmdletName = 'Set-MailboxAuditBypassAssociation' - Parameters = @{Identity = $Mailbox.Guid; AuditBypassEnabled = $false } + if ($BypassMailboxes.Count -gt 0) { + $Request = foreach ($Mailbox in $BypassMailboxes) { + @{ + CmdletInput = @{ + CmdletName = 'Set-MailboxAuditBypassAssociation' + Parameters = @{Identity = $Mailbox.Guid; AuditBypassEnabled = $false } + } } } - } - $BatchResults = New-ExoBulkRequest -tenantid $tenant -cmdletArray @($Request) - foreach ($Result in $BatchResults) { - if ($Result.error) { - $ErrorMessage = Get-NormalizedError -Message $Result.error - Write-LogMessage -API 'Standards' -tenant $tenant -message "Failed to disable mailbox audit bypass for $($Result.target). Error: $ErrorMessage" -sev Error + $BatchResults = New-ExoBulkRequest -tenantid $tenant -cmdletArray @($Request) + foreach ($Result in $BatchResults) { + if ($Result.error) { + $ErrorMessage = Get-NormalizedError -Message $Result.error + Write-LogMessage -API 'Standards' -tenant $tenant -message "Failed to disable mailbox audit bypass for $($Result.target). Error: $ErrorMessage" -sev Error + } } - } - - $LogMessage = if ($Mailboxes.Count -eq 0 -and $BypassMailboxes.Count -eq 0) { - # Make log message smaller if both are already in the desired state - 'User level mailbox audit already enabled and mailbox audit bypass already disabled for all mailboxes' + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Disabled mailbox audit bypass for $($BypassMailboxes.Count) mailbox(es)" -sev Info } else { - if ($Mailboxes.Count -eq 0) { - 'User level mailbox audit already enabled for all mailboxes. ' - } - if ($BypassMailboxes.Count -eq 0) { - 'Mailbox audit bypass already disabled for all mailboxes' - } + Write-LogMessage -API 'Standards' -tenant $Tenant -message 'No mailboxes have audit bypass enabled' -sev Info } - - Write-LogMessage -API 'Standards' -tenant $Tenant -message $LogMessage -sev Info } if ($Settings.alert -eq $true) { diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardExternalComplianceTrusted.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardExternalComplianceTrusted.ps1 new file mode 100644 index 0000000000000..9f3f8d50348e2 --- /dev/null +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardExternalComplianceTrusted.ps1 @@ -0,0 +1,97 @@ +function Invoke-CIPPStandardExternalComplianceTrusted { + <# + .FUNCTIONALITY + Internal + .COMPONENT + (APIName) ExternalComplianceTrusted + .SYNOPSIS + (Label) Sets the Cross-tenant access setting to trust external compliant devices + .DESCRIPTION + (Helptext) Sets the state of the Cross-tenant access setting to trust external compliant devices. This allows guest users to use a compliant device from their home tenant to access your tenant. + (DocsDescription) Sets the state of the Cross-tenant access setting to trust external compliant devices. This allows guest users to use a compliant device from their home tenant to access your tenant. + .NOTES + CAT + Entra (AAD) Standards + ADDEDCOMPONENT + {"type":"autoComplete","multiple":false,"creatable":false,"label":"Select value","name":"standards.ExternalComplianceTrusted.state","options":[{"label":"Enabled","value":"true"},{"label":"Disabled","value":"false"}]} + IMPACT + Low Impact + ADDEDDATE + 2026-08-25 + POWERSHELLEQUIVALENT + Update-MgBetaPolicyCrossTenantAccessPolicyDefault + RECOMMENDEDBY + REQUIREDCAPABILITIES + "AAD_PREMIUM" + "AAD_PREMIUM_P2" + UPDATECOMMENTBLOCK + Run the Tools\Update-StandardsComments.ps1 script to update this comment block + .LINK + https://docs.cipp.app/user-documentation/tenant/standards/alignment/templates/available-standards + #> + + param($Tenant, $Settings) + $TestResult = Test-CIPPStandardLicense -StandardName 'ExternalComplianceTrusted' -TenantFilter $Tenant -Preset Entra + + if ($TestResult -eq $false) { + return $true + } #we're done. + + try { + $ExternalComplianceTrusted = (New-GraphGetRequest -uri 'https://graph.microsoft.com/v1.0/policies/crossTenantAccessPolicy/default?$select=inboundTrust' -tenantid $Tenant) + } catch { + $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message + Write-LogMessage -API 'Standards' -Tenant $Tenant -Message "Could not get the ExternalComplianceTrusted state for $Tenant. Error: $ErrorMessage" -Sev Error + return + } + + # Get state value using null-coalescing operator + $state = $Settings.state.value ?? $Settings.state + $WantedState = if ($state -eq 'true') { $true } else { $false } + $StateMessage = if ($WantedState) { 'enabled' } else { 'disabled' } + + # Input validation + if (([string]::IsNullOrWhiteSpace($state) -or $state -eq 'Select a value') -and ($Settings.remediate -eq $true -or $Settings.alert -eq $true)) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message 'ExternalComplianceTrusted: Invalid state parameter set' -sev Error + return + } + + if ($Settings.remediate -eq $true) { + if ($ExternalComplianceTrusted.inboundTrust.isCompliantDeviceAccepted -eq $WantedState ) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "External Compliance Trusted is already $StateMessage." -sev Info + } else { + try { + $NewBody = $ExternalComplianceTrusted + $NewBody.inboundTrust.isCompliantDeviceAccepted = $WantedState + $NewBody = ConvertTo-Json -Depth 10 -InputObject $NewBody -Compress + $null = New-GraphPostRequest -tenantid $Tenant -Uri 'https://graph.microsoft.com/v1.0/policies/crossTenantAccessPolicy/default' -Type patch -Body $NewBody -ContentType 'application/json' + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Set External Compliance Trusted to $StateMessage." -sev Info + } catch { + $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Failed to set External Compliance Trusted to $StateMessage. Error: $ErrorMessage" -sev Error + } + } + } + + if ($Settings.report -eq $true) { + $CurrentValue = @{ + isCompliantDeviceAccepted = $ExternalComplianceTrusted.inboundTrust.isCompliantDeviceAccepted + } + $ExpectedValue = @{ + isCompliantDeviceAccepted = $WantedState + } + + Set-CIPPStandardsCompareField -FieldName 'standards.ExternalComplianceTrusted' -CurrentValue $CurrentValue -ExpectedValue $ExpectedValue -TenantFilter $Tenant + Add-CIPPBPAField -FieldName 'ExternalComplianceTrusted' -FieldValue $ExternalComplianceTrusted.inboundTrust.isCompliantDeviceAccepted -StoreAs bool -Tenant $Tenant + } + + if ($Settings.alert -eq $true) { + + if ($ExternalComplianceTrusted.inboundTrust.isCompliantDeviceAccepted -eq $WantedState) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "External Compliance Trusted is $StateMessage." -sev Info + } else { + Write-StandardsAlert -message "External Compliance Trusted is not $StateMessage" -object $ExternalComplianceTrusted.inboundTrust -tenant $Tenant -standardName 'ExternalComplianceTrusted' -standardId $Settings.standardId + Write-LogMessage -API 'Standards' -tenant $Tenant -message "External Compliance Trusted is not $StateMessage." -sev Info + } + } +} diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardFIDO2PasskeyProfiles.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardFIDO2PasskeyProfiles.ps1 index 583299a88cb46..6604da3920db0 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardFIDO2PasskeyProfiles.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardFIDO2PasskeyProfiles.ps1 @@ -55,6 +55,16 @@ function Invoke-CIPPStandardFIDO2PasskeyProfiles { return } + # An AAGUID allow/block list only takes effect while key restrictions are enforced + # (keyRestrictions.isEnforced = $true). With the 'Enforce AAGUID Key Restrictions' switch left off, + # isEnforced was $false, so AAGUIDs an operator added were stored but never applied - the profile + # kept no active key restriction and any authenticator could still register, which reads as "the + # AAGUIDs did not add to the profile". Supplying AAGUIDs is an implicit request to restrict to them, + # so enable enforcement whenever AAGUIDs are present. (Confirmed live against Graph beta.) + if ($AAGUIDs.Count -gt 0) { + $EnforceKeyRestrictions = $true + } + # Get current FIDO2 configuration try { $CurrentConfig = New-GraphGetRequest -Uri 'https://graph.microsoft.com/beta/policies/authenticationmethodspolicy/authenticationMethodConfigurations/Fido2' -tenantid $Tenant -AsApp $true diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardGroupTemplate.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardGroupTemplate.ps1 index 562bb79e29ee3..9d8be26df013d 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardGroupTemplate.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardGroupTemplate.ps1 @@ -47,7 +47,24 @@ function Invoke-CIPPStandardGroupTemplate { $Table = Get-CippTable -tablename 'templates' $Filter = "PartitionKey eq 'GroupTemplate' and (RowKey eq '$($Settings.TemplateList.value -join "' or RowKey eq '")')" - $GroupTemplates = (Get-CIPPAzDataTableEntity @Table -Filter $Filter).JSON | ConvertFrom-Json + # Resolve %variables% (e.g. %tenantname%) in the template body before any comparison. Groups are + # created through New-GraphPostRequest, which substitutes these tokens, so the tenant's actual + # group ends up named with the resolved value. Comparing the raw token-bearing name against it + # never matched, which recreated the group on every run and left the report permanently + # non-compliant. Replacement runs against the serialized JSON (escaped for that context), exactly + # as Push-CIPPStandard does for the settings. + $TemplateRows = @(Get-CIPPAzDataTableEntity @Table -Filter $Filter) + $GroupTemplates = foreach ($TemplateJSON in $TemplateRows.JSON) { + if ($TemplateJSON -match '%') { + $TemplateJSON = Get-CIPPTextReplacement -TenantFilter $Tenant -Text $TemplateJSON -EscapeForJson + } + $TemplateJSON | ConvertFrom-Json + } + + # Referenced ids may no longer exist (deleted, or recreated by the library sync); report that instead of passing. + $RequestedIds = @(@($Settings.TemplateList.value) | Where-Object { -not [string]::IsNullOrWhiteSpace($_) }) + $ResolvedIds = @(@($TemplateRows.RowKey) + @($GroupTemplates.GUID) | Where-Object { $_ } | Select-Object -Unique) + $MissingIds = @($RequestedIds | Where-Object { $_ -notin $ResolvedIds }) if ('dynamicDistribution' -in $GroupTemplates.groupType) { try { @@ -59,6 +76,10 @@ function Invoke-CIPPStandardGroupTemplate { } } + if ($MissingIds.Count -gt 0) { + Write-LogMessage -API 'Standards' -tenant $tenant -message "Group Template: $($MissingIds.Count) of $($RequestedIds.Count) selected group templates no longer exist (ids: $($MissingIds -join ', ')). Re-select them in the standards template." -sev 'Error' + } + if ($Settings.remediate -eq $true) { #Because the list name changed from TemplateList to groupTemplate by someone :@, we'll need to set it back to TemplateList foreach ($Template in $GroupTemplates) { @@ -127,8 +148,10 @@ function Invoke-CIPPStandardGroupTemplate { # Only update if the template specifies this should be a dynamic group if ($NormalizedGroupType -eq 'Dynamic' -and $groupobj.membershipRules) { if ($CheckExisting.membershipRule -ne $groupobj.membershipRules) { - $PatchBody | Add-Member -NotePropertyName 'membershipRule' -NotePropertyValue $groupobj.membershipRules - $PatchBody | Add-Member -NotePropertyName 'membershipRuleProcessingState' -NotePropertyValue 'On' + $PatchBody | Add-Member -NotePropertyMembers ([ordered]@{ + membershipRule = $groupobj.membershipRules + membershipRuleProcessingState = 'On' + }) $ChangesNeeded.Add("membershipRule: '$($CheckExisting.membershipRule)' → '$($groupobj.membershipRules)'") } } @@ -257,10 +280,12 @@ function Invoke-CIPPStandardGroupTemplate { } $CurrentValue = @{ - MissingGroups = $MissingGroups ? @($MissingGroups) : @() + MissingGroups = $MissingGroups ? @($MissingGroups) : @() + MissingTemplates = @($MissingIds) } $ExpectedValue = @{ - MissingGroups = @() + MissingGroups = @() + MissingTemplates = @() } Set-CIPPStandardsCompareField -FieldName 'standards.GroupTemplate' -CurrentValue $CurrentValue -ExpectedValue $ExpectedValue -TenantFilter $Tenant diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardIntuneAppTemplateDeploy.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardIntuneAppTemplateDeploy.ps1 index 2e917798fffae..92210a6de1849 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardIntuneAppTemplateDeploy.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardIntuneAppTemplateDeploy.ps1 @@ -16,7 +16,7 @@ function Invoke-CIPPStandardIntuneAppTemplateDeploy { EXECUTIVETEXT Automatically deploys approved Intune applications across all managed tenants, ensuring consistent software availability and reducing manual deployment overhead. Supports WinGet, Office, Chocolatey, Win32, and MSP application types. ADDEDCOMPONENT - {"type":"autoComplete","multiple":true,"creatable":false,"label":"Select Application Templates","name":"standards.IntuneAppTemplateDeploy.templateIds","api":{"url":"/api/ListAppTemplates","labelField":"Displayname","valueField":"GUID","queryKey":"StdIntuneAppTemplateList"}} + {"type":"autoComplete","multiple":true,"creatable":false,"label":"Select Application Templates","name":"standards.IntuneAppTemplateDeploy.templateIds","api":{"url":"/api/ListAppTemplates","labelField":"displayName","valueField":"GUID","queryKey":"StdIntuneAppTemplateList","templateView":{"title":"Application Template"}}} IMPACT Medium Impact ADDEDDATE @@ -52,9 +52,10 @@ function Invoke-CIPPStandardIntuneAppTemplateDeploy { $Table = Get-CIPPTable -TableName 'templates' $MissingApps = [System.Collections.Generic.List[PSCustomObject]]::new() $CurrentAppNames = @($CurrentApps.displayName) - # Office is a singleton per tenant that Graph always names 'Microsoft 365 Apps for Windows 10 - # and later', which never matches the name the template stores, so track it by type instead. + # Office and Edge are singletons per tenant whose Graph display name may differ from the + # template, so track them by type instead. $OfficeDeployed = @($CurrentApps | Where-Object { $_.'@odata.type' -eq '#microsoft.graph.officeSuiteApp' }).Count -gt 0 + $EdgeDeployed = @($CurrentApps | Where-Object { $_.'@odata.type' -eq '#microsoft.graph.windowsMicrosoftEdgeApp' }).Count -gt 0 foreach ($TemplateId in $TemplateIds) { $Entity = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'AppTemplate' and RowKey eq '$TemplateId'" @@ -75,7 +76,11 @@ function Invoke-CIPPStandardIntuneAppTemplateDeploy { $AppType = [string]$AppTypes[$i] $DisplayName = [string]($Config.ApplicationName ?? $Config.displayName ?? $AppNames[$i]) - $IsDeployed = if ($AppType -eq 'officeApp') { $OfficeDeployed } else { $DisplayName -in $CurrentAppNames } + $IsDeployed = switch ($AppType) { + 'officeApp' { $OfficeDeployed } + 'edgeApp' { $EdgeDeployed } + default { $DisplayName -in $CurrentAppNames } + } if (-not $IsDeployed) { $MissingApps.Add([PSCustomObject]@{ @@ -109,17 +114,20 @@ function Invoke-CIPPStandardIntuneAppTemplateDeploy { 'win32ScriptApp' { 'Win32ScriptApp' } 'mspApp' { 'MSPApp' } 'officeApp' { 'OfficeApp' } + 'edgeApp' { 'EdgeApp' } default { $App.AppType } } # Build AppConfig in the same format as the apps queue # Assignment info comes from the template's per-app config $DeployConfig = $App.Config | ConvertTo-Json -Depth 100 | ConvertFrom-Json -Depth 100 - $DeployConfig | Add-Member -NotePropertyName 'type' -NotePropertyValue $QueueType -Force - $DeployConfig | Add-Member -NotePropertyName 'Applicationname' -NotePropertyValue $App.AppName -Force # Compute assignTo the same way the HTTP handlers do $AppAssignTo = if ($DeployConfig.AssignTo -eq 'customGroup') { $DeployConfig.CustomGroup } else { $DeployConfig.AssignTo } - $DeployConfig | Add-Member -NotePropertyName 'assignTo' -NotePropertyValue $AppAssignTo -Force + $DeployConfig | Add-Member -NotePropertyMembers ([ordered]@{ + type = $QueueType + Applicationname = $App.AppName + assignTo = $AppAssignTo + }) -Force $null = New-CIPPIntuneAppDeployment -AppConfig $DeployConfig -TenantFilter $Tenant -APIName 'Standards' Write-LogMessage -API 'Standards' -tenant $Tenant -message "Deployed Intune app '$($App.AppName)' ($($App.AppType)) from template '$($App.TemplateName)'." -sev Info diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardIntuneTemplate.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardIntuneTemplate.ps1 index 11d2b55f1956a..605cf571ccb19 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardIntuneTemplate.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardIntuneTemplate.ps1 @@ -46,12 +46,20 @@ function Invoke-CIPPStandardIntuneTemplate { $Table = Get-CippTable -tablename 'templates' $Filter = "PartitionKey eq 'IntuneTemplate'" - $Template = (Get-CIPPAzDataTableEntity @Table -Filter $Filter | Where-Object -Property RowKey -Like "$($Settings.TemplateList.value)*").JSON | ConvertFrom-Json -ErrorAction SilentlyContinue + # The template picker surfaces the row's GUID column while the engine keys on RowKey (built-in + # templates are keyed '.IntuneTemplate.json'). CIPP writes both to the same value, but a + # template re-synced from a repo by an older release can carry a JSON GUID that no longer matches + # its RowKey - accept either rather than reporting a template that is sitting in the table as gone. + $TemplateRef = [string]$Settings.TemplateList.value + $Template = (Get-CIPPAzDataTableEntity @Table -Filter $Filter | Where-Object { $_.RowKey -like "$TemplateRef*" -or $_.GUID -eq $TemplateRef } | Select-Object -First 1).JSON | ConvertFrom-Json -ErrorAction SilentlyContinue Write-Information "[IntuneTemplate][$Tenant] TableLoad: $([int]($sw.Elapsed - $lap).TotalMilliseconds)ms" $lap = $sw.Elapsed if ($null -eq $Template) { - Write-LogMessage -API 'Standards' -tenant $tenant -message "Failed to find template $($Settings.TemplateList.value). Has this Intune Template been deleted?" -sev 'Error' + # Name the template the standard still points at: the id alone sends people searching the + # template table for a row that was deleted, when the fix is in the standards template. + $TemplateLabel = if ($Settings.TemplateList.label) { "'$($Settings.TemplateList.label)' " } else { '' } + Write-LogMessage -API 'Standards' -tenant $tenant -message "Intune template $TemplateLabel($TemplateRef) no longer exists in the template library. Remove it from the standards or drift template, or select the template again." -sev 'Error' return $true } diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardMDMScope.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardMDMScope.ps1 index 0a5c332fa0e3c..5b28217010e33 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardMDMScope.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardMDMScope.ps1 @@ -45,7 +45,7 @@ function Invoke-CIPPStandardMDMScope { } #we're done. try { - $CurrentInfo = New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/policies/mobileDeviceManagementPolicies/0000000a-0000-0000-c000-000000000000?$select=termsOfUseUrl,discoveryUrl,complianceUrl,appliesTo&$expand=includedGroups($select=displayName)' -tenantid $Tenant + $CurrentInfo = New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/policies/mobileDeviceManagementPolicies/0000000a-0000-0000-c000-000000000000?$select=termsOfUseUrl,discoveryUrl,complianceUrl,appliesTo&$expand=includedGroups($select=id,displayName)' -tenantid $Tenant } catch { $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message Write-LogMessage -API 'Standards' -Tenant $Tenant -Message "Could not get the MDM Scope state for $Tenant. Error: $ErrorMessage" -Sev Error diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardOneDriveLicensedQuota.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardOneDriveLicensedQuota.ps1 index 2bc839171ddee..ce5e8eae86efc 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardOneDriveLicensedQuota.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardOneDriveLicensedQuota.ps1 @@ -119,18 +119,15 @@ function Invoke-CIPPStandardOneDriveLicensedQuota { if ($BelowQuota.Count -eq 0) { Write-LogMessage -API 'Standards' -tenant $Tenant -message 'All entitled users already have a OneDrive quota of 5 TB or more.' -sev Info } else { + # One concurrent batch instead of ~2s per drive serially. + $BulkSites = @($BelowQuota | ForEach-Object { @{ SiteUrl = $_.siteUrl; Properties = @{ StorageMaximumLevel = $TargetQuotaMB; StorageWarningLevel = $WarningLevelMB } } }) + $BulkResults = @(Set-CIPPSPOSiteBulk -TenantFilter $Tenant -Sites $BulkSites -UseCertificate) foreach ($Drive in $BelowQuota) { - try { - $SetResponse = Set-CIPPSPOSite -TenantFilter $Tenant -SiteUrl $Drive.siteUrl -Properties @{ - StorageMaximumLevel = $TargetQuotaMB - StorageWarningLevel = $WarningLevelMB - } - $CsomError = ($SetResponse | Where-Object { $_.ErrorInfo } | Select-Object -First 1).ErrorInfo.ErrorMessage - if ($CsomError) { throw $CsomError } + $BulkResult = $BulkResults | Where-Object { $_.SiteUrl -eq $Drive.siteUrl } | Select-Object -First 1 + if ($BulkResult -and $BulkResult.Success) { Write-LogMessage -API 'Standards' -tenant $Tenant -message "Raised OneDrive quota for $($Drive.userPrincipalName) from $($Drive.currentQuotaGB)GB to $($Drive.targetQuotaGB)GB" -sev Info - } catch { - $ErrorMessage = Get-CippException -Exception $_ - Write-LogMessage -API 'Standards' -tenant $Tenant -message "Failed to raise OneDrive quota for $($Drive.userPrincipalName): $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + } else { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Failed to raise OneDrive quota for $($Drive.userPrincipalName): $($BulkResult.Error)" -sev Error } } } diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardOutBoundSpamAlert.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardOutBoundSpamAlert.ps1 index e7879f4e62adf..42cbee0630acc 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardOutBoundSpamAlert.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardOutBoundSpamAlert.ps1 @@ -16,6 +16,8 @@ function Invoke-CIPPStandardOutBoundSpamAlert { "CIS M365 5.0 (2.1.6)" ADDEDCOMPONENT {"type":"textField","name":"standards.OutBoundSpamAlert.OutboundSpamContact","label":"Outbound spam contact"} + {"type":"switch","name":"standards.OutBoundSpamAlert.BccSuspiciousOutboundMail","label":"BCC suspicious outbound mail to a mailbox"} + {"type":"textField","name":"standards.OutBoundSpamAlert.BccSuspiciousOutboundContact","label":"BCC recipient for suspicious outbound mail"} IMPACT Low Impact ADDEDDATE @@ -51,28 +53,58 @@ function Invoke-CIPPStandardOutBoundSpamAlert { return } + $Contacts = $Settings.OutboundSpamContact + # BccSuspiciousOutboundMail is opt-in: only graded/remediated when the operator enables the + # toggle. CIS 2.1.6 requires both the flag AND a recipient, so a compliant state needs the + # additional recipients too when a BCC contact is supplied. + $ManageBcc = $Settings.BccSuspiciousOutboundMail -eq $true + $BccContacts = $Settings.BccSuspiciousOutboundContact + + $CurrentNotifyRecipients = @($CurrentInfo.NotifyOutboundSpamRecipients) -join ', ' + $NotifyIsCorrect = ($CurrentInfo.NotifyOutboundSpam -eq $true) -and ($CurrentNotifyRecipients -eq "$Contacts") + + $CurrentBccRecipients = @($CurrentInfo.BccSuspiciousOutboundAdditionalRecipients) -join ', ' + if (-not $ManageBcc) { + $BccIsCorrect = $true + } elseif ([string]::IsNullOrWhiteSpace($BccContacts)) { + $BccIsCorrect = $CurrentInfo.BccSuspiciousOutboundMail -eq $true + } else { + $BccIsCorrect = ($CurrentInfo.BccSuspiciousOutboundMail -eq $true) -and ($CurrentBccRecipients -eq "$BccContacts") + } + $StateIsCorrect = $NotifyIsCorrect -and $BccIsCorrect + if ($Settings.remediate -eq $true) { - if ($CurrentInfo.NotifyOutboundSpam -ne $true -or $CurrentInfo.NotifyOutboundSpamRecipients -ne $settings.OutboundSpamContact) { - $Contacts = $settings.OutboundSpamContact + if ($StateIsCorrect -eq $true) { + Write-LogMessage -API 'Standards' -tenant $tenant -message "Outbound spam filter alert is already set to $($CurrentInfo.NotifyOutboundSpamRecipients)" -sev Info + } else { + $cmdParams = @{ + Identity = 'Default' + NotifyOutboundSpam = $true + NotifyOutboundSpamRecipients = $Contacts + } + if ($ManageBcc) { + $cmdParams.BccSuspiciousOutboundMail = $true + if (-not [string]::IsNullOrWhiteSpace($BccContacts)) { + $cmdParams.BccSuspiciousOutboundAdditionalRecipients = $BccContacts + } + } try { - New-ExoRequest -tenantid $tenant -cmdlet 'Set-HostedOutboundSpamFilterPolicy' -cmdParams @{ Identity = 'Default'; NotifyOutboundSpam = $true; NotifyOutboundSpamRecipients = $Contacts } -useSystemMailbox $true + New-ExoRequest -tenantid $tenant -cmdlet 'Set-HostedOutboundSpamFilterPolicy' -cmdParams $cmdParams -useSystemMailbox $true Write-LogMessage -API 'Standards' -tenant $tenant -message "Set outbound spam filter alert to $($Contacts)" -sev Info } catch { $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message Write-LogMessage -API 'Standards' -tenant $tenant -message "Could not set outbound spam contact to $($Contacts). $ErrorMessage" -sev Error } - } else { - Write-LogMessage -API 'Standards' -tenant $tenant -message "Outbound spam filter alert is already set to $($CurrentInfo.NotifyOutboundSpamRecipients)" -sev Info } } if ($Settings.alert -eq $true) { - if ($CurrentInfo.NotifyOutboundSpam -eq $true) { + if ($StateIsCorrect -eq $true) { Write-LogMessage -API 'Standards' -tenant $tenant -message "Outbound spam filter alert is set to $($CurrentInfo.NotifyOutboundSpamRecipients)" -sev Info } else { - $Object = $CurrentInfo | Select-Object -Property NotifyOutboundSpamRecipients, NotifyOutboundSpam + $Object = $CurrentInfo | Select-Object -Property NotifyOutboundSpam, NotifyOutboundSpamRecipients, BccSuspiciousOutboundMail, BccSuspiciousOutboundAdditionalRecipients Write-StandardsAlert -message 'Outbound spam filter alert is not set' -object $Object -tenant $tenant -standardName 'OutBoundSpamAlert' -standardId $Settings.standardId Write-LogMessage -API 'Standards' -tenant $tenant -message 'Outbound spam filter alert is not set' -sev Info } @@ -82,11 +114,17 @@ function Invoke-CIPPStandardOutBoundSpamAlert { Add-CIPPBPAField -FieldName 'OutboundSpamAlert' -FieldValue $CurrentInfo.NotifyOutboundSpam -StoreAs bool -Tenant $tenant $CurrentValue = @{ NotifyOutboundSpam = $CurrentInfo.NotifyOutboundSpam - NotifyOutboundSpamRecipients = ($CurrentInfo.NotifyOutboundSpamRecipients -join ', ') + NotifyOutboundSpamRecipients = $CurrentNotifyRecipients } $ExpectedValue = @{ NotifyOutboundSpam = $true - NotifyOutboundSpamRecipients = $settings.OutboundSpamContact + NotifyOutboundSpamRecipients = $Contacts + } + if ($ManageBcc) { + $CurrentValue.BccSuspiciousOutboundMail = $CurrentInfo.BccSuspiciousOutboundMail + $CurrentValue.BccSuspiciousOutboundAdditionalRecipients = $CurrentBccRecipients + $ExpectedValue.BccSuspiciousOutboundMail = $true + $ExpectedValue.BccSuspiciousOutboundAdditionalRecipients = $BccContacts } Set-CIPPStandardsCompareField -FieldName 'standards.OutBoundSpamAlert' -CurrentValue $CurrentValue -ExpectedValue $ExpectedValue -Tenant $tenant } diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardPIMRoleSettings.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardPIMRoleSettings.ps1 new file mode 100644 index 0000000000000..3d583f23f4c70 --- /dev/null +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardPIMRoleSettings.ps1 @@ -0,0 +1,197 @@ +function Invoke-CIPPStandardPIMRoleSettings { + <# + .FUNCTIONALITY + Internal + .COMPONENT + (APIName) PIMRoleSettings + .SYNOPSIS + (Label) PIM Role Settings Template + .DESCRIPTION + (Helptext) Deploys a Privileged Identity Management role settings template to the tenant: activation limits, MFA or authentication context, justification, approval, eligibility and active-assignment expiry and notification rules for the roles the template covers. Templates cannot weaken settings below CIPP's secure floor. + (DocsDescription) Deploys a Privileged Identity Management role settings template to the tenant. The template defines, for a set of roles, the maximum activation duration, whether activation requires MFA or an authentication context, justification, ticket and approval requirements, the maximum lifetime of eligible and active assignments, and additional notification recipients. Templates are validated against CIPP's secure floor (activation within 24 hours with MFA or an authentication context and a justification; eligible and active assignments must expire within a year; active assignments require a justification) and are refused, not adjusted, when they fall below it. Requires Entra ID P2. + .NOTES + CAT + Templates + MULTIPLE + True + DISABLEDFEATURES + {"report":false,"warn":false,"remediate":false} + IMPACT + High Impact + ADDEDDATE + 2026-08-23 + TAG + EXECUTIVETEXT + Enforces consistent Privileged Identity Management settings so that administrator roles can only be used for a limited time, after strong authentication and with a recorded reason. This keeps standing administrative access to a minimum and makes every use of privilege visible and accountable. + ADDEDCOMPONENT + {"type":"autoComplete","name":"TemplateList","multiple":false,"required":true,"creatable":false,"label":"Select PIM Role Settings Template","api":{"url":"/api/ListPIMRoleSettingsTemplates","labelField":"templateName","valueField":"GUID","queryKey":"ListPIMRoleSettingsTemplates","showRefresh":true,"templateView":{"title":"PIM Role Settings Template"}}} + POWERSHELLEQUIVALENT + Update-MgBetaPolicyRoleManagementPolicyRule + RECOMMENDEDBY + "CIPP" + REQUIREDCAPABILITIES + "AAD_PREMIUM_P2" + UPDATECOMMENTBLOCK + Run the tools\Update-StandardsComments.ps1 script to update this comment block + .LINK + https://docs.cipp.app/user-documentation/tenant/standards/alignment/templates/available-standards + #> + + param($Tenant, $Settings) + + $TemplateId = $Settings.TemplateList.value ?? $Settings.TemplateList + $FieldName = "standards.PIMRoleSettings.$TemplateId" + + $TestResult = Test-CIPPStandardLicense -StandardName 'PIMRoleSettings' -TenantFilter $Tenant -Preset EntraP2 + if ($TestResult -eq $false) { + Set-CIPPStandardsCompareField -FieldName $FieldName -FieldValue 'This tenant does not have the Entra ID P2 license required for Privileged Identity Management.' -LicenseAvailable $false -TenantFilter $Tenant + return $true + } + + if ([string]::IsNullOrWhiteSpace($TemplateId)) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message 'PIMRoleSettings: no template selected.' -sev Error + return + } + + # Load and re-validate the template: a template row edited by hand must not be able to push a + # tenant below the floor, so the check runs at deploy time as well as at save time. + $Table = Get-CippTable -tablename 'templates' + $SafeId = ConvertTo-CIPPODataFilterValue -Value $TemplateId -Type String + $TemplateRow = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'PIMRoleSettingsTemplate' and (RowKey eq '$SafeId' or GUID eq '$SafeId')" | Select-Object -First 1 + if (-not $TemplateRow) { + $Message = "PIM role settings template $TemplateId could not be found." + Write-LogMessage -API 'Standards' -tenant $Tenant -message $Message -sev Error + Set-CIPPStandardsCompareField -FieldName $FieldName -CurrentValue @{ Differences = $Message } -ExpectedValue @{ Differences = @() } -TenantFilter $Tenant + return + } + $Template = $TemplateRow.JSON | ConvertFrom-Json -Depth 100 + $TemplateSettings = ConvertTo-CIPPPIMRoleSettings -InputObject $Template.settings + $Floor = Test-CIPPPIMRoleSettingsFloor -Settings $TemplateSettings + if (-not $Floor.Valid) { + $Message = "PIM role settings template '$($Template.templateName)' is below the secure floor and was not applied: $($Floor.Errors -join ' ')" + Write-LogMessage -API 'Standards' -tenant $Tenant -message $Message -sev Error + Set-CIPPStandardsCompareField -FieldName $FieldName -CurrentValue @{ Differences = $Message } -ExpectedValue @{ Differences = @() } -TenantFilter $Tenant + return + } + foreach ($Warning in $Floor.Warnings) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "PIM role settings template '$($Template.templateName)': $Warning" -sev Warning + } + + try { + $Policies = @(Get-CIPPPIMRolePolicies -TenantFilter $Tenant) + } catch { + $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Could not read PIM role policies: $ErrorMessage" -sev Error + return + } + if ($Policies.Count -eq 0) { + $Message = 'No PIM role management policies were returned. Privileged Identity Management may not be onboarded in this tenant yet; open PIM once in the Entra admin center.' + Write-LogMessage -API 'Standards' -tenant $Tenant -message $Message -sev Warning + Set-CIPPStandardsCompareField -FieldName $FieldName -CurrentValue @{ Differences = $Message } -ExpectedValue @{ Differences = @() } -TenantFilter $Tenant + return + } + + # Role names for messages; PIM's roleDefinitionId is the template id for built-in roles. + $RoleNames = @{} + foreach ($Entry in (Get-CIPPPrivilegedRoleTemplateIds -WithNames)) { $RoleNames[$Entry.Id] = $Entry.DisplayName } + try { + foreach ($Definition in @(New-GraphGetRequest -uri 'https://graph.microsoft.com/v1.0/roleManagement/directory/roleDefinitions?$select=id,templateId,displayName' -tenantid $Tenant)) { + if ($Definition.id) { $RoleNames[$Definition.id] = $Definition.displayName } + if ($Definition.templateId) { $RoleNames[$Definition.templateId] = $Definition.displayName } + } + } catch { + Write-Information "Could not list role definitions for $Tenant`: $($_.Exception.Message)" + } + + $RoleIds = switch ("$($Template.roleScope)") { + 'AllRoles' { @($Policies.RoleDefinitionId) } + 'Custom' { @($Template.roles | ForEach-Object { $_.value ?? $_ } | Where-Object { $_ }) } + default { @(Get-CIPPPrivilegedRoleTemplateIds -Set Privileged) } + } + + # Approvers are stored by name/UPN so a template works across tenants; resolve them here. + $ResolvedApprovers = @() + if ($TemplateSettings.activationRequiresApproval) { + foreach ($Approver in @("$($TemplateSettings.approvers)" -split '[,;]' | ForEach-Object { $_.Trim() } | Where-Object { $_ })) { + try { + if ($Approver -match '@') { + $SafeUpn = ConvertTo-CIPPODataFilterValue -Value $Approver -Type String + $User = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/users?`$filter=userPrincipalName eq '$SafeUpn'&`$select=id,userPrincipalName" -tenantid $Tenant | Select-Object -First 1 + if ($User) { $ResolvedApprovers += [ordered]@{ '@odata.type' = '#microsoft.graph.singleUser'; userId = $User.id; description = $User.userPrincipalName } } + else { Write-LogMessage -API 'Standards' -tenant $Tenant -message "PIMRoleSettings: approver '$Approver' was not found." -sev Warning } + } else { + $SafeName = ConvertTo-CIPPODataFilterValue -Value $Approver -Type String + $Group = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/groups?`$filter=displayName eq '$SafeName'&`$select=id,displayName" -tenantid $Tenant | Select-Object -First 1 + if ($Group) { $ResolvedApprovers += [ordered]@{ '@odata.type' = '#microsoft.graph.groupMembers'; groupId = $Group.id; description = $Group.displayName } } + else { Write-LogMessage -API 'Standards' -tenant $Tenant -message "PIMRoleSettings: approver group '$Approver' was not found." -sev Warning } + } + } catch { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "PIMRoleSettings: could not resolve approver '$Approver': $($_.Exception.Message)" -sev Warning + } + } + if ($ResolvedApprovers.Count -eq 0) { + $Message = "PIM role settings template '$($Template.templateName)' requires approval but none of its approvers exist in this tenant; the template was not applied." + Write-LogMessage -API 'Standards' -tenant $Tenant -message $Message -sev Error + Set-CIPPStandardsCompareField -FieldName $FieldName -CurrentValue @{ Differences = $Message } -ExpectedValue @{ Differences = @() } -TenantFilter $Tenant + return + } + } + + function Get-RoleDifferences { + param($PolicySet) + $PolicyByRole = @{} + foreach ($Policy in $PolicySet) { $PolicyByRole[$Policy.RoleDefinitionId] = $Policy } + $Found = [System.Collections.Generic.List[object]]::new() + foreach ($RoleId in $RoleIds) { + $RoleLabel = $RoleNames[$RoleId] ?? $RoleId + $Policy = $PolicyByRole[$RoleId] + if (-not $Policy) { + $Found.Add([PSCustomObject]@{ Role = $RoleLabel; RoleDefinitionId = $RoleId; Policy = $null; Desired = $null; Differences = @([PSCustomObject]@{ Role = $RoleLabel; Rule = '-'; Property = 'policy'; Expected = 'present'; Current = 'no PIM policy for this role' }) }) + continue + } + $Desired = ConvertTo-CIPPPIMPolicyRules -Settings $TemplateSettings -CurrentRules $Policy.Rules -ResolvedApprovers $ResolvedApprovers + $Differences = @(Compare-CIPPPIMRoleSettings -DesiredRules $Desired -CurrentRules $Policy.Rules -RoleName $RoleLabel) + $Found.Add([PSCustomObject]@{ Role = $RoleLabel; RoleDefinitionId = $RoleId; Policy = $Policy; Desired = $Desired; Differences = $Differences }) + } + return $Found + } + + $RoleStates = Get-RoleDifferences -PolicySet $Policies + $Drifted = @($RoleStates | Where-Object { $_.Differences.Count -gt 0 }) + + if ($Settings.remediate -eq $true) { + if ($Drifted.Count -eq 0) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "PIM role settings already match template '$($Template.templateName)' for $($RoleStates.Count) role(s)." -sev Info + } else { + foreach ($State in $Drifted) { + if (-not $State.Policy) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "PIMRoleSettings: no PIM policy exists for $($State.Role); cannot apply the template to it." -sev Warning + continue + } + $null = Set-CIPPPIMRoleSettings -TenantFilter $Tenant -PolicyId $State.Policy.PolicyId -DesiredRules $State.Desired -CurrentRules $State.Policy.Rules -RoleName $State.Role -APIName 'Standards' + } + # Re-read so the report reflects the post-remediation state. + try { + $RoleStates = Get-RoleDifferences -PolicySet @(Get-CIPPPIMRolePolicies -TenantFilter $Tenant) + $Drifted = @($RoleStates | Where-Object { $_.Differences.Count -gt 0 }) + } catch { + Write-Information "Could not re-read PIM policies after remediation: $($_.Exception.Message)" + } + } + } + + $DifferenceText = @($Drifted | ForEach-Object { $State = $_; $State.Differences | ForEach-Object { "$($State.Role): $($_.Rule).$($_.Property) expected '$($_.Expected)', found '$($_.Current)'" } }) + + if ($Settings.alert -eq $true) { + if ($Drifted.Count -eq 0) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "PIM role settings match template '$($Template.templateName)'." -sev Info + } else { + Write-StandardsAlert -message "PIM role settings for $($Drifted.Count) role(s) differ from template '$($Template.templateName)'" -object @{ Template = $Template.templateName; Differences = $DifferenceText } -tenant $Tenant -standardName 'PIMRoleSettings' -standardId $Settings.standardId + Write-LogMessage -API 'Standards' -tenant $Tenant -message "PIM role settings for $($Drifted.Count) role(s) differ from template '$($Template.templateName)'." -sev Info + } + } + + if ($Settings.report -eq $true) { + Set-CIPPStandardsCompareField -FieldName $FieldName -CurrentValue @{ Differences = @($DifferenceText) } -ExpectedValue @{ Differences = @() } -TenantFilter $Tenant + } +} diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardQuarantineRequestAlert.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardQuarantineRequestAlert.ps1 index 144141a671cce..0726c64b08447 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardQuarantineRequestAlert.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardQuarantineRequestAlert.ps1 @@ -63,11 +63,22 @@ function Invoke-CIPPStandardQuarantineRequestAlert { return } - $StateIsCorrect = if ($State -eq 'removed') { - !$CurrentState - } else { - ($CurrentState.NotifyUser -contains $Settings.NotifyUser) + # Expected recipients, normalised (blanks removed, sorted, de-duplicated) so the alert's actual + # recipients and the configured recipients can be compared as values, order-insensitively. + $ExpectedNotify = if ($State -eq 'removed') { @() } else { @($Settings.NotifyUser | Where-Object { $_ } | Sort-Object -Unique) } + + # State is a value comparison of the alert's recipients against the expected recipients. Wrapped in a + # scriptblock so it can be re-evaluated against a fresh read after remediation (see below), and so the + # report's Current/Expected fields below are the exact values this comparison is made on. + $GetStateIsCorrect = { + if ($State -eq 'removed') { + -not $CurrentState + } else { + $CurrentNotify = @($CurrentState.NotifyUser | Where-Object { $_ } | Sort-Object -Unique) + ($CurrentNotify -join "`n") -eq ($ExpectedNotify -join "`n") + } } + $StateIsCorrect = & $GetStateIsCorrect if ($Settings.remediate -eq $true) { if ($StateIsCorrect -eq $true) { @@ -115,6 +126,17 @@ function Invoke-CIPPStandardQuarantineRequestAlert { } } } + # Re-read the live state after remediating so the alert and report modes below reflect what was + # actually applied this run, not the pre-remediation snapshot. Without this, a freshly created or + # updated alert still reports its old (usually empty) recipients until the next scheduled run, + # which reads as "nothing changed" immediately after a force run. + try { + $CurrentState = New-ExoRequest -TenantId $Tenant -cmdlet 'Get-ProtectionAlert' -Compliance | Where-Object { $_.Name -eq $PolicyName } + $StateIsCorrect = & $GetStateIsCorrect + } catch { + $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message + Write-LogMessage -API 'Standards' -Tenant $Tenant -Message "Could not re-check the QuarantineRequestAlert state after remediation for $Tenant. Error: $ErrorMessage" -Sev Error + } } if ($Settings.alert -eq $true) { @@ -134,11 +156,14 @@ function Invoke-CIPPStandardQuarantineRequestAlert { if ($Settings.report -eq $true) { Add-CIPPBPAField -FieldName 'QuarantineRequestAlert' -FieldValue $StateIsCorrect -StoreAs bool -Tenant $Tenant + # Both sides are normalised the same way and kept as arrays (a bare @() around an if-expression + # unrolls a single element to a scalar, which would never match the array-shaped Current value). + # Compliance is then decided by CurrentValue -eq ExpectedValue in Get-CIPPTenantAlignment. $CurrentValue = @{ - NotifyUser = @($CurrentState.NotifyUser | Where-Object { $_ }) + NotifyUser = @($CurrentState.NotifyUser | Where-Object { $_ } | Sort-Object -Unique) } $ExpectedValue = @{ - NotifyUser = if ($State -eq 'removed') { @() } else { @($Settings.NotifyUser) } + NotifyUser = @($ExpectedNotify) } Set-CIPPStandardsCompareField -FieldName 'standards.QuarantineRequestAlert' -CurrentValue $CurrentValue -ExpectedValue $ExpectedValue -Tenant $Tenant } diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardSPGuestPeoplePicker.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardSPGuestPeoplePicker.ps1 new file mode 100644 index 0000000000000..c4c2541501253 --- /dev/null +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardSPGuestPeoplePicker.ps1 @@ -0,0 +1,136 @@ +function Invoke-CIPPStandardSPGuestPeoplePicker { + <# + .FUNCTIONALITY + Internal + .COMPONENT + (APIName) SPGuestPeoplePicker + .SYNOPSIS + (Label) Show guest users in the SharePoint People Picker + .DESCRIPTION + (Helptext) Controls whether guest (external) users already in the tenant appear as suggestions in the SharePoint and OneDrive People Picker. Enforces the wanted state on BOTH the tenant default and every existing site collection - they are set independently, so changing the tenant default does not update existing sites. The per-site picture is read from the SharePoint reporting cache (refreshed daily), so a large tenant is never enumerated live during a run; a 24h rerun guard stops the write sweep from repeating before that cache refreshes and re-evaluates the result. + (DocsDescription) Enforces ShowPeoplePickerSuggestionsForGuestUsers at both levels it is set independently: the tenant default (Set-SPOTenant) and each site collection (Set-SPOSite). Which sites differ is decided from the SPOSites reporting cache (populated by the daily SharePoint cache run) rather than the live site enumeration, which on a large tenant is hundreds of CSOM calls and lags a just-applied write. The tenant default is read through the cached SharePoint tenant configuration. Remediation sets the tenant default and sweeps every differing site once, then records a 24-hour rerun guard: the write is not repeated until the next daily cache run reflects the change, at which point the standard re-evaluates from the refreshed cache. Guests are not shown by default even when they exist in the tenant, and changing the tenant default does not retroactively change existing sites, so both are covered. + .NOTES + CAT + SharePoint Standards + TAG + EXECUTIVETEXT + Makes existing external collaborators discoverable (or hidden) when sharing SharePoint and OneDrive content, consistently across the tenant default and every existing site. This keeps the sharing experience predictable and prevents individual sites from drifting away from the agreed collaboration posture. + ADDEDCOMPONENT + {"type":"autoComplete","multiple":false,"creatable":false,"label":"Guest People Picker suggestions","name":"standards.SPGuestPeoplePicker.state","options":[{"label":"Show guests in the People Picker","value":"true"},{"label":"Hide guests in the People Picker","value":"false"}]} + IMPACT + Low Impact + ADDEDDATE + 2026-09-03 + POWERSHELLEQUIVALENT + Set-SPOTenant / Set-SPOSite -ShowPeoplePickerSuggestionsForGuestUsers \$true or \$false + RECOMMENDEDBY + "CIPP" + REQUIREDCAPABILITIES + "SHAREPOINTWAC" + "SHAREPOINTSTANDARD" + "SHAREPOINTENTERPRISE" + "SHAREPOINTENTERPRISE_EDU" + "ONEDRIVE_BASIC" + "ONEDRIVE_ENTERPRISE" + UPDATECOMMENTBLOCK + Run the Tools\Update-StandardsComments.ps1 script to update this comment block + .LINK + https://docs.cipp.app/user-documentation/tenant/standards/alignment/templates/available-standards + #> + + param($Tenant, $Settings) + $TestResult = Test-CIPPStandardLicense -StandardName 'SPGuestPeoplePicker' -TenantFilter $Tenant -Preset SharePoint + + if ($TestResult -eq $false) { + return $true + } #we're done. + + # Input validation + $StateValue = $Settings.state.value ?? $Settings.state + if (([string]::IsNullOrWhiteSpace($StateValue) -or $StateValue -eq 'Select a value') -and ($Settings.remediate -eq $true -or $Settings.alert -eq $true)) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message 'SPGuestPeoplePicker: Invalid state parameter set' -sev Error + return + } + $WantedState = [System.Convert]::ToBoolean($StateValue) + $HumanReadableState = if ($WantedState -eq $true) { 'shown' } else { 'hidden' } + + # Decide what to change from cache, not live. The per-site picture comes from the SPOSites + # reporting cache (refreshed by the daily SharePoint CIPPDB run) - never the live enumeration, + # which on a large tenant is hundreds of CSOM calls and lags a just-applied write by minutes. + # The tenant default is a single setting read through Get-CIPPSPOTenant's own 1h cache - unlike + # the delegated SPOTenant reporting collector, this works app-only with the certificate on + # tenants without a SharePoint-admin GDAP user - and the same object is the write handle below. + try { + $CurrentTenant = Get-CIPPSPOTenant -TenantFilter $Tenant -UseCertificate | Select-Object -First 1 + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API 'Standards' -Tenant $Tenant -Message "Could not read the SharePoint tenant configuration for SPGuestPeoplePicker on $Tenant. Error: $($ErrorMessage.NormalizedError)" -Sev Error -LogData $ErrorMessage + return + } + if (-not $CurrentTenant) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message 'SPGuestPeoplePicker: no SharePoint tenant configuration available yet - it will populate on the next SharePoint cache run' -sev Info + return + } + + $Sites = @(New-CIPPDbRequest -TenantFilter $Tenant -Type 'SPOSites' | Where-Object { $_ -and $_.Url }) + $TenantValue = [bool]$CurrentTenant.ShowPeoplePickerSuggestionsForGuestUsers + $NonCompliantSites = @($Sites | Where-Object { [bool]$_.ShowPeoplePickerSuggestionsForGuestUsers -ne $WantedState }) + $TenantIsCorrect = ($TenantValue -eq $WantedState) + $StateIsCorrect = $TenantIsCorrect -and ($NonCompliantSites.Count -eq 0) + + if ($Settings.remediate -eq $true) { + if ($StateIsCorrect -eq $true) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Guest People Picker suggestions are already correctly set to $HumanReadableState on the tenant default and all $($Sites.Count) sites" -sev Info + } elseif (Test-CIPPRerun -Tenant $Tenant -API 'SPGuestPeoplePicker' -Interval 86400) { + # The write sweep already ran for this tenant within the last 24h (Test-CIPPRerun records + # it, and the baseline executor shares this key). Its input, the SPOSites cache, only + # refreshes daily, so re-running now would re-issue the same writes against a stale picture + # and push SharePoint into throttling. Wait for the next daily cache run to reflect the + # change and re-evaluate the true result. Alert/report below still run every time. + Write-LogMessage -API 'Standards' -tenant $Tenant -message 'SPGuestPeoplePicker: write sweep already ran within the last 24h - skipping it until the next cache run re-evaluates the result' -sev Info + } else { + if (-not $TenantIsCorrect) { + try { + $null = $CurrentTenant | Set-CIPPSPOTenant -Properties @{ ShowPeoplePickerSuggestionsForGuestUsers = $WantedState } -UseCertificate + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Failed to set the tenant default guest People Picker suggestions to $HumanReadableState. Error: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + } + } + if ($NonCompliantSites.Count -gt 0) { + $BulkSites = @($NonCompliantSites | ForEach-Object { @{ SiteUrl = $_.Url; Properties = @{ ShowPeoplePickerSuggestionsForGuestUsers = $WantedState } } }) + $Results = @(Set-CIPPSPOSiteBulk -TenantFilter $Tenant -Sites $BulkSites -UseCertificate) + $FailedSites = @($Results | Where-Object { -not $_.Success }) + foreach ($Bad in $FailedSites) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Failed to set guest People Picker to $HumanReadableState on $($Bad.SiteUrl)$(if ($Bad.Error) { ": $($Bad.Error)" })" -sev Error + } + $Succeeded = $Results.Count - $FailedSites.Count + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Set guest People Picker to $HumanReadableState on $Succeeded of $($NonCompliantSites.Count) site(s)" -sev Info + } + } + } + + if ($Settings.alert -eq $true) { + if ($StateIsCorrect -eq $true) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Guest People Picker suggestions are correctly set to $HumanReadableState everywhere" -sev Info + } else { + $TenantPart = if ($TenantIsCorrect) { 'the tenant default is correct' } else { "the tenant default is not $HumanReadableState" } + $Message = "Guest People Picker suggestions are not set to ${HumanReadableState}: $TenantPart and $($NonCompliantSites.Count) site(s) differ" + Write-StandardsAlert -message $Message -object @{ TenantDefault = $TenantValue; NonCompliantSiteCount = $NonCompliantSites.Count } -tenant $Tenant -standardName 'SPGuestPeoplePicker' -standardId $Settings.standardId + Write-LogMessage -API 'Standards' -tenant $Tenant -message $Message -sev Info + } + } + + if ($Settings.report -eq $true) { + $CurrentValue = @{ + TenantDefault = $TenantValue + NonCompliantSiteCount = $NonCompliantSites.Count + } + $ExpectedValue = @{ + TenantDefault = $WantedState + NonCompliantSiteCount = 0 + } + Set-CIPPStandardsCompareField -FieldName 'standards.SPGuestPeoplePicker' -CurrentValue $CurrentValue -ExpectedValue $ExpectedValue -Tenant $Tenant + Add-CIPPBPAField -FieldName 'SPGuestPeoplePicker' -FieldValue $StateIsCorrect -StoreAs bool -Tenant $Tenant + } +} diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardSPOVersionControl.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardSPOVersionControl.ps1 index b1f147d96ce6b..47c9d681bebe7 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardSPOVersionControl.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardSPOVersionControl.ps1 @@ -63,7 +63,8 @@ function Invoke-CIPPStandardSPOVersionControl { } try { - $CurrentState = Get-CIPPSPOTenant -TenantFilter $Tenant | Select-Object -Property _ObjectIdentity_, TenantFilter, EnableAutoExpirationVersionTrim, MajorVersionLimit, ExpireVersionsAfterDays + # SharePoint app-only requires the SAM certificate; delegated is not available on every tenant. + $CurrentState = Get-CIPPSPOTenant -TenantFilter $Tenant -UseCertificate | Select-Object -Property _ObjectIdentity_, TenantFilter, EnableAutoExpirationVersionTrim, MajorVersionLimit, ExpireVersionsAfterDays } catch { $ErrorMessage = Get-CippException -Exception $_ Write-LogMessage -API 'Standards' -Tenant $Tenant -message "Could not get the SPOVersionControl state for $Tenant. Error: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage @@ -72,21 +73,39 @@ function Invoke-CIPPStandardSPOVersionControl { if ($DesiredAutoTrim) { $StateIsCorrect = $CurrentState.EnableAutoExpirationVersionTrim -eq $true + + # With automatic trimming on, SharePoint manages the version limit and expiry itself, so + # they are not part of the desired state. The compare report and drift detection grade + # the current and expected objects as a whole, so the tenant-managed values must be left + # out of both sides - a null placeholder on the expected side never matches and marked + # every auto-trim tenant non-compliant. + $CurrentValue = [PSCustomObject]@{ + EnableAutoExpirationVersionTrim = $CurrentState.EnableAutoExpirationVersionTrim + } + $ExpectedValue = [PSCustomObject]@{ + EnableAutoExpirationVersionTrim = $true + } } else { $StateIsCorrect = ($CurrentState.EnableAutoExpirationVersionTrim -eq $false) -and ($CurrentState.MajorVersionLimit -eq $DesiredMajorVersionLimit) -and ($CurrentState.ExpireVersionsAfterDays -eq $DesiredExpireVersionsAfterDays) - } - $CurrentValue = [PSCustomObject]@{ - EnableAutoExpirationVersionTrim = $CurrentState.EnableAutoExpirationVersionTrim - MajorVersionLimit = $CurrentState.MajorVersionLimit - ExpireVersionsAfterDays = $CurrentState.ExpireVersionsAfterDays + $CurrentValue = [PSCustomObject]@{ + EnableAutoExpirationVersionTrim = $CurrentState.EnableAutoExpirationVersionTrim + MajorVersionLimit = $CurrentState.MajorVersionLimit + ExpireVersionsAfterDays = $CurrentState.ExpireVersionsAfterDays + } + $ExpectedValue = [PSCustomObject]@{ + EnableAutoExpirationVersionTrim = $false + MajorVersionLimit = $DesiredMajorVersionLimit + ExpireVersionsAfterDays = $DesiredExpireVersionsAfterDays + } } - $ExpectedValue = [PSCustomObject]@{ - EnableAutoExpirationVersionTrim = $DesiredAutoTrim - MajorVersionLimit = if ($DesiredAutoTrim) { $null } else { $DesiredMajorVersionLimit } - ExpireVersionsAfterDays = if ($DesiredAutoTrim) { $null } else { $DesiredExpireVersionsAfterDays } + + $ExpectedDescription = if ($DesiredAutoTrim) { + 'AutoTrim=True (version limit and expiry managed by Microsoft)' + } else { + "AutoTrim=False, MajorVersionLimit=$DesiredMajorVersionLimit, ExpireVersionsAfterDays=$DesiredExpireVersionsAfterDays" } if ($Settings.remediate -eq $true) { @@ -109,8 +128,8 @@ function Invoke-CIPPStandardSPOVersionControl { @{ Type = 'Int32'; Value = $DesiredExpireVersionsAfterDays } ) } - $CurrentState | Set-CIPPSPOTenant -MethodName 'SetFileVersionPolicy' -MethodParameters $MethodParams - Write-LogMessage -API 'Standards' -tenant $Tenant -message "Successfully configured SharePoint version control (AutoTrim: $DesiredAutoTrim, MajorVersionLimit: $DesiredMajorVersionLimit, ExpireVersionsAfterDays: $DesiredExpireVersionsAfterDays)" -sev Info + $CurrentState | Set-CIPPSPOTenant -MethodName 'SetFileVersionPolicy' -MethodParameters $MethodParams -UseCertificate + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Successfully configured SharePoint version control ($ExpectedDescription)" -sev Info # Apply to all existing sites and their document libraries if ($Settings.ApplyToExistingSites -eq $true) { @@ -128,15 +147,14 @@ function Invoke-CIPPStandardSPOVersionControl { $SiteProperties.ExpireVersionsAfterDays = $DesiredExpireVersionsAfterDays } - foreach ($Site in $Sites) { - try { - Set-CIPPSPOSite -TenantFilter $Tenant -SiteUrl $Site.webUrl -Properties $SiteProperties - } catch { - $SiteError = Get-CippException -Exception $_ - Write-LogMessage -API 'Standards' -tenant $Tenant -message "Failed to set version policy for site $($Site.webUrl): $($SiteError.NormalizedError)" -sev Error -LogData $SiteError - } + # One concurrent batch instead of ~2s per site serially. + $BulkSites = @($Sites | ForEach-Object { @{ SiteUrl = $_.webUrl; Properties = $SiteProperties } }) + $BulkResults = @(Set-CIPPSPOSiteBulk -TenantFilter $Tenant -Sites $BulkSites -UseCertificate) + $FailedSites = @($BulkResults | Where-Object { -not $_.Success }) + foreach ($FailedSite in $FailedSites) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Failed to set version policy for site $($FailedSite.SiteUrl): $($FailedSite.Error)" -sev Error } - Write-LogMessage -API 'Standards' -tenant $Tenant -message 'Finished applying version policy to existing sites' -sev Info + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Finished applying version policy to $($Sites.Count - $FailedSites.Count) of $($Sites.Count) existing sites" -sev Info } } catch { $ErrorMessage = Get-CippException -Exception $_ @@ -149,7 +167,7 @@ function Invoke-CIPPStandardSPOVersionControl { if ($StateIsCorrect) { Write-LogMessage -API 'Standards' -tenant $Tenant -message 'SharePoint version control settings are configured correctly' -sev Info } else { - $Message = "SharePoint version control is not configured correctly. Current: AutoTrim=$($CurrentState.EnableAutoExpirationVersionTrim), MajorVersionLimit=$($CurrentState.MajorVersionLimit), ExpireVersionsAfterDays=$($CurrentState.ExpireVersionsAfterDays). Expected: AutoTrim=$DesiredAutoTrim, MajorVersionLimit=$DesiredMajorVersionLimit, ExpireVersionsAfterDays=$DesiredExpireVersionsAfterDays" + $Message = "SharePoint version control is not configured correctly. Current: AutoTrim=$($CurrentState.EnableAutoExpirationVersionTrim), MajorVersionLimit=$($CurrentState.MajorVersionLimit), ExpireVersionsAfterDays=$($CurrentState.ExpireVersionsAfterDays). Expected: $ExpectedDescription" Write-StandardsAlert -message $Message -object $CurrentState -tenant $Tenant -standardName 'SPOVersionControl' -standardId $Settings.standardId } } diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardSpamFilterPolicy.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardSpamFilterPolicy.ps1 index 08ca43604c1d8..569ba58f16ac3 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardSpamFilterPolicy.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardSpamFilterPolicy.ps1 @@ -39,6 +39,7 @@ function Invoke-CIPPStandardSpamFilterPolicy { {"type":"autoComplete","required":true,"multiple":false,"creatable":true,"label":"High Confidence Spam Quarantine Tag","name":"standards.SpamFilterPolicy.HighConfidenceSpamQuarantineTag","options":[{"label":"AdminOnlyAccessPolicy","value":"AdminOnlyAccessPolicy"},{"label":"DefaultFullAccessPolicy","value":"DefaultFullAccessPolicy"},{"label":"DefaultFullAccessWithNotificationPolicy","value":"DefaultFullAccessWithNotificationPolicy"}]} {"type":"autoComplete","required":true,"multiple":false,"creatable":false,"label":"Bulk Spam Action","name":"standards.SpamFilterPolicy.BulkSpamAction","options":[{"label":"Quarantine the message","value":"Quarantine"},{"label":"Move message to Junk Email folder","value":"MoveToJmf"}]} {"type":"autoComplete","required":true,"multiple":false,"creatable":true,"label":"Bulk Quarantine Tag","name":"standards.SpamFilterPolicy.BulkQuarantineTag","options":[{"label":"AdminOnlyAccessPolicy","value":"AdminOnlyAccessPolicy"},{"label":"DefaultFullAccessPolicy","value":"DefaultFullAccessPolicy"},{"label":"DefaultFullAccessWithNotificationPolicy","value":"DefaultFullAccessWithNotificationPolicy"}]} + {"type":"autoComplete","required":false,"multiple":false,"creatable":false,"label":"Bulk moves enabled (deliver bulk mail below the threshold to the Promotions folder - Preview)","name":"standards.SpamFilterPolicy.BulkMovesEnabled","options":[{"label":"On","value":"On"},{"label":"Off","value":"Off"}]} {"type":"autoComplete","required":true,"multiple":false,"creatable":false,"label":"Phish Spam Action","name":"standards.SpamFilterPolicy.PhishSpamAction","options":[{"label":"Quarantine the message","value":"Quarantine"},{"label":"Move message to Junk Email folder","value":"MoveToJmf"}]} {"type":"autoComplete","required":true,"multiple":false,"creatable":true,"label":"Phish Quarantine Tag","name":"standards.SpamFilterPolicy.PhishQuarantineTag","options":[{"label":"AdminOnlyAccessPolicy","value":"AdminOnlyAccessPolicy"},{"label":"DefaultFullAccessPolicy","value":"DefaultFullAccessPolicy"},{"label":"DefaultFullAccessWithNotificationPolicy","value":"DefaultFullAccessWithNotificationPolicy"}]} {"type":"autoComplete","required":true,"multiple":false,"creatable":true,"label":"High Confidence Phish Quarantine Tag","name":"standards.SpamFilterPolicy.HighConfidencePhishQuarantineTag","options":[{"label":"AdminOnlyAccessPolicy","value":"AdminOnlyAccessPolicy"},{"label":"DefaultFullAccessPolicy","value":"DefaultFullAccessPolicy"},{"label":"DefaultFullAccessWithNotificationPolicy","value":"DefaultFullAccessWithNotificationPolicy"}]} @@ -131,6 +132,10 @@ function Invoke-CIPPStandardSpamFilterPolicy { $PhishSpamAction = $Settings.PhishSpamAction.value ?? $Settings.PhishSpamAction $PhishQuarantineTag = $Settings.PhishQuarantineTag.value ?? $Settings.PhishQuarantineTag $HighConfidencePhishQuarantineTag = $Settings.HighConfidencePhishQuarantineTag.value ?? $Settings.HighConfidencePhishQuarantineTag + # BulkMovesEnabled is in Preview and not available in every organization, so it is only + # compared and written when explicitly configured On or Off. + $BulkMovesEnabled = $Settings.BulkMovesEnabled.value ?? $Settings.BulkMovesEnabled + $BulkMovesConfigured = $BulkMovesEnabled -in @('On', 'Off') # Normalize list settings to clean string arrays. Values may arrive as a proper array or as a # single comma-delimited string; splitting and trimming makes Compare-Object and remediation reliable. @@ -186,6 +191,7 @@ function Invoke-CIPPStandardSpamFilterPolicy { ($CurrentState.MarkAsSpamFromAddressAuthFail -eq 'Off') -and ($CurrentState.MarkAsSpamNdrBackscatter -eq 'Off') -and ($CurrentState.MarkAsSpamBulkMail -eq 'On') -and + ((-not $BulkMovesConfigured) -or ($CurrentState.BulkMovesEnabled -eq $BulkMovesEnabled)) -and ($CurrentState.InlineSafetyTipsEnabled -eq $true) -and ($CurrentState.PhishZapEnabled -eq $true) -and ($CurrentState.SpamZapEnabled -eq $true) -and @@ -261,6 +267,9 @@ function Invoke-CIPPStandardSpamFilterPolicy { } else { $cmdParams.Add('EnableRegionBlockList', $false) } + if ($BulkMovesConfigured) { + $cmdParams.Add('BulkMovesEnabled', $BulkMovesEnabled) + } if ($CurrentState.Name -eq $PolicyName) { @@ -390,6 +399,10 @@ function Invoke-CIPPStandardSpamFilterPolicy { $CurrentValue['RegionBlockList'] = $CurrentState.RegionBlockList $ExpectedValue['RegionBlockList'] = $RegionBlockList } + if ($BulkMovesConfigured) { + $CurrentValue['BulkMovesEnabled'] = "$($CurrentState.BulkMovesEnabled)" + $ExpectedValue['BulkMovesEnabled'] = $BulkMovesEnabled + } Set-CIPPStandardsCompareField -FieldName 'standards.SpamFilterPolicy' -CurrentValue $CurrentValue -ExpectedValue $ExpectedValue -Tenant $Tenant } diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardTeamsGlobalMeetingPolicy.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardTeamsGlobalMeetingPolicy.ps1 index 1882b76f6b7a7..62ca8f2ca0a1d 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardTeamsGlobalMeetingPolicy.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardTeamsGlobalMeetingPolicy.ps1 @@ -7,8 +7,8 @@ function Invoke-CIPPStandardTeamsGlobalMeetingPolicy { .SYNOPSIS (Label) Define Global Meeting Policy for Teams .DESCRIPTION - (Helptext) Defines the CIS recommended global meeting policy for Teams. This includes AllowAnonymousUsersToJoinMeeting, AllowAnonymousUsersToStartMeeting, AutoAdmittedUsers, AllowPSTNUsersToBypassLobby, MeetingChatEnabledType, DesignatedPresenterRoleMode, AllowExternalParticipantGiveRequestControl, AllowParticipantGiveRequestControl - (DocsDescription) Defines the CIS recommended global meeting policy for Teams. This includes AllowAnonymousUsersToJoinMeeting, AllowAnonymousUsersToStartMeeting, AutoAdmittedUsers, AllowPSTNUsersToBypassLobby, MeetingChatEnabledType, DesignatedPresenterRoleMode, AllowExternalParticipantGiveRequestControl, AllowParticipantGiveRequestControl + (Helptext) Defines the CIS recommended global meeting policy for Teams. This includes AllowAnonymousUsersToJoinMeeting, AllowAnonymousUsersToStartMeeting, AutoAdmittedUsers, AllowPSTNUsersToBypassLobby, MeetingChatEnabledType, DesignatedPresenterRoleMode, AllowExternalParticipantGiveRequestControl, AllowParticipantGiveRequestControl, AllowExternalNonTrustedMeetingChat, AllowCloudRecording + (DocsDescription) Defines the CIS recommended global meeting policy for Teams. This includes AllowAnonymousUsersToJoinMeeting, AllowAnonymousUsersToStartMeeting, AutoAdmittedUsers, AllowPSTNUsersToBypassLobby, MeetingChatEnabledType, DesignatedPresenterRoleMode, AllowExternalParticipantGiveRequestControl, AllowParticipantGiveRequestControl, AllowExternalNonTrustedMeetingChat, AllowCloudRecording .NOTES CAT Teams Standards @@ -30,12 +30,14 @@ function Invoke-CIPPStandardTeamsGlobalMeetingPolicy { {"type":"autoComplete","required":true,"multiple":false,"creatable":false,"name":"standards.TeamsGlobalMeetingPolicy.MeetingChatEnabledType","label":"Meeting chat policy","options":[{"label":"On for everyone","value":"Enabled"},{"label":"On for everyone but anonymous users","value":"EnabledExceptAnonymous"},{"label":"Off for everyone","value":"Disabled"}]} {"type":"switch","name":"standards.TeamsGlobalMeetingPolicy.AllowParticipantGiveRequestControl","label":"Participants can give or request control"} {"type":"switch","name":"standards.TeamsGlobalMeetingPolicy.AllowExternalParticipantGiveRequestControl","label":"External participants can give or request control"} + {"type":"autoComplete","required":false,"multiple":false,"creatable":false,"name":"standards.TeamsGlobalMeetingPolicy.AllowExternalNonTrustedMeetingChat","label":"External meeting chat","helperText":"CIS 8.5.8 recommends Off. Leave blank to keep the tenant's current value.","options":[{"label":"Off (CIS recommended)","value":false},{"label":"On","value":true}]} + {"type":"autoComplete","required":false,"multiple":false,"creatable":false,"name":"standards.TeamsGlobalMeetingPolicy.AllowCloudRecording","label":"Meeting cloud recording","helperText":"CIS 8.5.9 recommends Off. Leave blank to keep the tenant's current value.","options":[{"label":"Off (CIS recommended)","value":false},{"label":"On","value":true}]} IMPACT Low Impact ADDEDDATE 2024-11-12 POWERSHELLEQUIVALENT - Set-CsTeamsMeetingPolicy -AllowAnonymousUsersToJoinMeeting \$false -AllowAnonymousUsersToStartMeeting \$false -AutoAdmittedUsers \$AutoAdmittedUsers -AllowPSTNUsersToBypassLobby \$false -MeetingChatEnabledType EnabledExceptAnonymous -DesignatedPresenterRoleMode \$DesignatedPresenterRoleMode -AllowExternalParticipantGiveRequestControl \$false -AllowParticipantGiveRequestControl \$false + Set-CsTeamsMeetingPolicy -AllowAnonymousUsersToJoinMeeting \$false -AllowAnonymousUsersToStartMeeting \$false -AutoAdmittedUsers \$AutoAdmittedUsers -AllowPSTNUsersToBypassLobby \$false -MeetingChatEnabledType EnabledExceptAnonymous -DesignatedPresenterRoleMode \$DesignatedPresenterRoleMode -AllowExternalParticipantGiveRequestControl \$false -AllowParticipantGiveRequestControl \$false -AllowExternalNonTrustedMeetingChat \$false -AllowCloudRecording \$false RECOMMENDEDBY "CIS" REQUIREDCAPABILITIES @@ -58,7 +60,7 @@ function Invoke-CIPPStandardTeamsGlobalMeetingPolicy { try { $CurrentState = New-TeamsRequestV2 -TenantFilter $Tenant -Type 'TeamsMeetingPolicy' -Action Get -Identity 'Global' | - Select-Object AllowAnonymousUsersToJoinMeeting, AllowAnonymousUsersToStartMeeting, AutoAdmittedUsers, AllowPSTNUsersToBypassLobby, MeetingChatEnabledType, DesignatedPresenterRoleMode, AllowExternalParticipantGiveRequestControl, AllowParticipantGiveRequestControl + Select-Object AllowAnonymousUsersToJoinMeeting, AllowAnonymousUsersToStartMeeting, AutoAdmittedUsers, AllowPSTNUsersToBypassLobby, MeetingChatEnabledType, DesignatedPresenterRoleMode, AllowExternalParticipantGiveRequestControl, AllowParticipantGiveRequestControl, AllowExternalNonTrustedMeetingChat, AllowCloudRecording } catch { $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message Write-LogMessage -API 'Standards' -Tenant $Tenant -Message "Could not get the TeamsGlobalMeetingPolicy state for $Tenant. Error: $ErrorMessage" -Sev Error @@ -84,6 +86,15 @@ function Invoke-CIPPStandardTeamsGlobalMeetingPolicy { $AllowExternalParticipantGiveRequestControl = $Settings.AllowExternalParticipantGiveRequestControl ?? $false $AllowParticipantGiveRequestControl = $Settings.AllowParticipantGiveRequestControl ?? $false + # Opt-in booleans (autoComplete Off/On, or blank to keep the tenant's current value). Unlike the + # switches above, a blank here means "do not manage" so existing deployments are never surprised + # into disabling external chat or cloud recording. The option value can arrive as a real bool or + # as "true"/"false", so ToBoolean handles both; blank/absent falls back to the current state. + $RawExternalChat = $Settings.AllowExternalNonTrustedMeetingChat.value ?? $Settings.AllowExternalNonTrustedMeetingChat + $AllowExternalNonTrustedMeetingChat = if ($null -eq $RawExternalChat -or "$RawExternalChat" -eq '') { $CurrentState.AllowExternalNonTrustedMeetingChat } else { [System.Convert]::ToBoolean($RawExternalChat) } + $RawCloudRecording = $Settings.AllowCloudRecording.value ?? $Settings.AllowCloudRecording + $AllowCloudRecording = if ($null -eq $RawCloudRecording -or "$RawCloudRecording" -eq '') { $CurrentState.AllowCloudRecording } else { [System.Convert]::ToBoolean($RawCloudRecording) } + $StateIsCorrect = ($CurrentState.AllowAnonymousUsersToJoinMeeting -eq $AllowAnonymousUsersToJoinMeeting) -and ($CurrentState.AllowAnonymousUsersToStartMeeting -eq $AllowAnonymousUsersToStartMeeting) -and ($CurrentState.AutoAdmittedUsers -eq $AutoAdmittedUsers) -and @@ -91,7 +102,9 @@ function Invoke-CIPPStandardTeamsGlobalMeetingPolicy { ($CurrentState.MeetingChatEnabledType -eq $MeetingChatEnabledType) -and ($CurrentState.DesignatedPresenterRoleMode -eq $DesignatedPresenterRoleMode) -and ($CurrentState.AllowExternalParticipantGiveRequestControl -eq $AllowExternalParticipantGiveRequestControl) -and - ($CurrentState.AllowParticipantGiveRequestControl -eq $AllowParticipantGiveRequestControl) + ($CurrentState.AllowParticipantGiveRequestControl -eq $AllowParticipantGiveRequestControl) -and + ($CurrentState.AllowExternalNonTrustedMeetingChat -eq $AllowExternalNonTrustedMeetingChat) -and + ($CurrentState.AllowCloudRecording -eq $AllowCloudRecording) if ($Settings.remediate -eq $true) { @@ -108,6 +121,8 @@ function Invoke-CIPPStandardTeamsGlobalMeetingPolicy { DesignatedPresenterRoleMode = $DesignatedPresenterRoleMode AllowExternalParticipantGiveRequestControl = $AllowExternalParticipantGiveRequestControl AllowParticipantGiveRequestControl = $AllowParticipantGiveRequestControl + AllowExternalNonTrustedMeetingChat = $AllowExternalNonTrustedMeetingChat + AllowCloudRecording = $AllowCloudRecording } try { @@ -140,6 +155,8 @@ function Invoke-CIPPStandardTeamsGlobalMeetingPolicy { DesignatedPresenterRoleMode = $CurrentState.DesignatedPresenterRoleMode AllowExternalParticipantGiveRequestControl = $CurrentState.AllowExternalParticipantGiveRequestControl AllowParticipantGiveRequestControl = $CurrentState.AllowParticipantGiveRequestControl + AllowExternalNonTrustedMeetingChat = $CurrentState.AllowExternalNonTrustedMeetingChat + AllowCloudRecording = $CurrentState.AllowCloudRecording } $ExpectedValue = @{ AllowAnonymousUsersToJoinMeeting = $AllowAnonymousUsersToJoinMeeting @@ -150,6 +167,8 @@ function Invoke-CIPPStandardTeamsGlobalMeetingPolicy { DesignatedPresenterRoleMode = $DesignatedPresenterRoleMode AllowExternalParticipantGiveRequestControl = $AllowExternalParticipantGiveRequestControl AllowParticipantGiveRequestControl = $AllowParticipantGiveRequestControl + AllowExternalNonTrustedMeetingChat = $AllowExternalNonTrustedMeetingChat + AllowCloudRecording = $AllowCloudRecording } Set-CIPPStandardsCompareField -FieldName 'standards.TeamsGlobalMeetingPolicy' -CurrentValue $CurrentValue -ExpectedValue $ExpectedValue -Tenant $Tenant Add-CIPPBPAField -FieldName 'TeamsGlobalMeetingPolicy' -FieldValue $StateIsCorrect -StoreAs bool -Tenant $Tenant diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardTeamsZAP.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardTeamsZAP.ps1 index 7b3c19c146d28..6beea759304c8 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardTeamsZAP.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardTeamsZAP.ps1 @@ -42,10 +42,25 @@ function Invoke-CIPPStandardTeamsZAP { $TestResult = Test-CIPPStandardLicense -StandardName 'TeamsZAP' -TenantFilter $Tenant -Preset Exchange if ($TestResult -eq $false) { return $true } + # The Teams protection policy only exists on tenants with Defender for Office 365 - Exchange + # Online returns 403 for Get-TeamsProtectionPolicy on any other tenant. Gate on the license + # (which records a 'License Missing' report row) instead of logging an error every run. + $MDOTestResult = Test-CIPPStandardLicense -StandardName 'TeamsZAP' -TenantFilter $Tenant -Preset DefenderForOffice365 + if ($MDOTestResult -eq $false) { return $true } + try { $CurrentState = (New-ExoRequest -tenantid $Tenant -cmdlet 'Get-TeamsProtectionPolicy' -cmdParams @{ Identity = 'Teams Protection Policy' }).ZapEnabled } catch { $ErrorMessage = Get-CippException -Exception $_ + if ($ErrorMessage.NormalizedError -match '\b403\b') { + # The capability check passed but Exchange still refused the cmdlet: the plan carries the + # capability without Teams protection (or the tenant has not been onboarded yet). Report + # it as a licensing gap rather than a failure so it does not surface as an error every run. + $LicenseMessage = 'License Missing: Exchange Online returned 403 for Get-TeamsProtectionPolicy. Teams protection requires Defender for Office 365 on this tenant.' + Write-LogMessage -API 'Standards' -tenant $Tenant -message "TeamsZAP: $LicenseMessage" -sev Info + Set-CIPPStandardsCompareField -FieldName 'standards.TeamsZAP' -FieldValue $LicenseMessage -LicenseAvailable $false -TenantFilter $Tenant + return $true + } Write-LogMessage -API 'Standards' -tenant $Tenant -message "TeamsZAP: Failed to get Teams Protection Policy. Error: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage return } diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardUserSubmissions.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardUserSubmissions.ps1 index 13f53548e564d..cf8e2f4a6ae13 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardUserSubmissions.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardUserSubmissions.ps1 @@ -8,7 +8,7 @@ function Invoke-CIPPStandardUserSubmissions { (Label) Set the state of the built-in Report button in Outlook .DESCRIPTION (Helptext) Set the state of the spam submission button in Outlook - (DocsDescription) Set the state of the built-in Report button in Outlook. This gives the users the ability to report emails as spam or phish. + (DocsDescription) Set the state of the built-in Report button in Outlook. This gives the users the ability to report emails as spam or phish. When a destination email address is set, the 'Send reported items to' setting controls whether reported messages go to Microsoft and the reporting mailbox, or to the reporting mailbox only (for third-party phishing report services). .NOTES CAT Exchange Standards @@ -18,6 +18,7 @@ function Invoke-CIPPStandardUserSubmissions { ADDEDCOMPONENT {"type":"autoComplete","multiple":false,"label":"Select value","name":"standards.UserSubmissions.state","options":[{"label":"Enabled","value":"enable"},{"label":"Disabled","value":"disable"}]} {"type":"textField","name":"standards.UserSubmissions.email","required":false,"label":"Destination email address"} + {"type":"autoComplete","multiple":false,"label":"Send reported items to (when a destination email address is set)","name":"standards.UserSubmissions.reportDestination","options":[{"label":"Microsoft and my reporting mailbox","value":"Both"},{"label":"My reporting mailbox only","value":"Mailbox"}]} IMPACT Medium Impact ADDEDDATE @@ -48,6 +49,11 @@ function Invoke-CIPPStandardUserSubmissions { $state = $Settings.state.value ?? $Settings.state $Email = Get-CIPPTextReplacement -TenantFilter $Tenant -Text $Settings.email + # 'Send reported items to' only applies when a destination email address is set. + # Missing/blank keeps the pre-existing behavior: report to Microsoft as well as the mailbox. + $Destination = $Settings.reportDestination.value ?? $Settings.reportDestination + $ReportToMicrosoft = [string]::IsNullOrWhiteSpace($Email) -or $Destination -ne 'Mailbox' + # Input validation if ($Settings.remediate -eq $true -or $Settings.alert -eq $true) { if (!($state -eq 'enable' -or $state -eq 'disable')) { @@ -82,7 +88,7 @@ function Invoke-CIPPStandardUserSubmissions { ($PolicyState.ReportPhishAddresses.Count -eq 0) $RuleIsCorrect = ($RuleState.length -eq 0) -or ($RuleState.State -ne 'Enabled') } else { - $PolicyIsCorrect = ($PolicyState.EnableReportToMicrosoft -eq $true) -and + $PolicyIsCorrect = ($PolicyState.EnableReportToMicrosoft -eq $ReportToMicrosoft) -and ($PolicyState.ReportJunkToCustomizedAddress -eq $true) -and ($PolicyState.ReportJunkAddresses -eq $Email) -and ($PolicyState.ReportNotJunkToCustomizedAddress -eq $true) -and @@ -128,7 +134,7 @@ function Invoke-CIPPStandardUserSubmissions { } } else { $PolicyParams = @{ - EnableReportToMicrosoft = $true + EnableReportToMicrosoft = $ReportToMicrosoft ReportJunkToCustomizedAddress = $true ReportJunkAddresses = $Email ReportNotJunkToCustomizedAddress = $true @@ -209,7 +215,7 @@ function Invoke-CIPPStandardUserSubmissions { if ($StateIsCorrect -eq $true) { Write-LogMessage -API 'Standards' -tenant $Tenant -message 'User Submission policy is properly configured.' -sev Info } else { - if ($Policy.EnableReportToMicrosoft -eq $true) { + if ($PolicyState.EnableReportToMicrosoft -eq $true) { Write-StandardsAlert -message 'User Submission policy is enabled but incorrectly configured' -object $PolicyState -tenant $Tenant -standardName 'UserSubmissions' -standardId $Settings.standardId Write-LogMessage -API 'Standards' -tenant $Tenant -message 'User Submission policy is enabled but incorrectly configured' -sev Info } else { @@ -243,7 +249,7 @@ function Invoke-CIPPStandardUserSubmissions { } } $ExpectedValue = @{ - EnableReportToMicrosoft = $state -eq 'enable' + EnableReportToMicrosoft = ($state -eq 'enable') -and $ReportToMicrosoft ReportJunkToCustomizedAddress = if ([string]::IsNullOrWhiteSpace($Email)) { $false } else { $true } ReportNotJunkToCustomizedAddress = if ([string]::IsNullOrWhiteSpace($Email)) { $false } else { $true } ReportPhishToCustomizedAddress = if ([string]::IsNullOrWhiteSpace($Email)) { $false } else { $true } diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardcalDefault.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardcalDefault.ps1 index 6a7d9836a3927..d4d50f185a4f5 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardcalDefault.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardcalDefault.ps1 @@ -64,16 +64,42 @@ function Invoke-CIPPStandardcalDefault { } # Filter to only Default user permissions that don't match target level - $DefaultPermissions = $CalendarPermissions | Where-Object { $_.User -eq 'Default' } + $DefaultPermissions = @($CalendarPermissions | Where-Object { $_.User -eq 'Default' }) $NeedsUpdate = @($DefaultPermissions | Where-Object { $currentRights = if ($_.AccessRights -is [array]) { $_.AccessRights -join ',' } else { $_.AccessRights } $currentRights -ne $permissionLevel }) - $CurrentValue = if ($NeedsUpdate.Count -eq 0) { + # Coverage is graded separately from compliance: a mailbox with no cached Default row can + # never enter $NeedsUpdate, so an incomplete collection used to read as a clean sweep. + # Matched by identity, not counts - a stale row for a deleted mailbox would offset a newly + # uncovered one. Identity is ":\", keyed by UPN, alias or Exchange GUID. + $Mailboxes = @(New-CIPPDbRequest -TenantFilter $Tenant -Type 'Mailboxes' -Fields 'UPN', 'primarySmtpAddress', 'Id', 'ExternalDirectoryObjectId') + + $GradedIds = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + foreach ($Permission in $DefaultPermissions) { + $MailboxId = ("$($Permission.Identity)" -split ':\\')[0] + # An empty key would match every mailbox missing that field and hide real gaps. + if ($MailboxId) { $null = $GradedIds.Add($MailboxId) } + } + + $UncheckedMailboxes = @($Mailboxes | Where-Object { + $Keys = [string[]]@($_.UPN, $_.primarySmtpAddress, $_.Id, $_.ExternalDirectoryObjectId | Where-Object { $_ }) + -not $GradedIds.Overlaps($Keys) + }) + $Unchecked = $UncheckedMailboxes.Count + + $UncheckedNames = @($UncheckedMailboxes | ForEach-Object { $_.UPN ? $_.UPN : $_.primarySmtpAddress }) + $UncheckedSample = ($UncheckedNames | Select-Object -First 10) -join ', ' + $CoverageWarning = "$Unchecked of $($Mailboxes.Count) mailboxes have no cached Default calendar permission and were NOT evaluated ($UncheckedSample). The calendar permission cache is incomplete." + + $CurrentValue = if ($NeedsUpdate.Count -eq 0 -and $Unchecked -eq 0) { [PSCustomObject]@{ state = 'Configured correctly' } } else { - [PSCustomObject]@{ NonCompliantCalendars = $NeedsUpdate | Select-Object -Property Identity, AccessRights } + [PSCustomObject]@{ + NonCompliantCalendars = @($NeedsUpdate | Select-Object -Property Identity, AccessRights) + UncheckedMailboxes = $Unchecked + } } $ExpectedValue = [PSCustomObject]@{ state = 'Configured correctly' @@ -81,7 +107,11 @@ function Invoke-CIPPStandardcalDefault { if ($Settings.remediate -eq $true) { if ($NeedsUpdate.Count -eq 0) { - Write-LogMessage -API 'Standards' -tenant $Tenant -message 'All calendars already have the correct default permission level.' -sev Info + if ($Unchecked -gt 0) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "All $($DefaultPermissions.Count) checked calendars already have the correct default permission level, but $CoverageWarning" -sev Warning + } else { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "All $($DefaultPermissions.Count) calendars already have the correct default permission level." -sev Info + } } else { $UpdateDB = $false try { @@ -124,7 +154,11 @@ function Invoke-CIPPStandardcalDefault { if ($Settings.alert -eq $true) { if ($NeedsUpdate.Count -eq 0) { - Write-LogMessage -API 'Standards' -tenant $Tenant -message 'Default calendar permissions are correctly configured for all mailboxes' -sev Info + if ($Unchecked -gt 0) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Default calendar permissions are correctly configured for all $($DefaultPermissions.Count) checked mailboxes, but $CoverageWarning" -sev Warning + } else { + Write-LogMessage -API 'Standards' -tenant $Tenant -message 'Default calendar permissions are correctly configured for all mailboxes' -sev Info + } } else { Write-StandardsAlert -message "Default calendar permission is not set to $permissionLevel for $($NeedsUpdate.Count) calendars" -object ($NeedsUpdate | Select-Object -Property Identity, AccessRights) -tenant $Tenant -standardName 'calDefault' -standardId $Settings.standardId Write-LogMessage -API 'Standards' -tenant $Tenant -message "Default calendar permission is not set to $permissionLevel for $($NeedsUpdate.Count) calendars" -sev Info diff --git a/Modules/CIPPTests/Public/Helpers/ConvertTo-CippMarkdownCell.ps1 b/Modules/CIPPTests/Public/Helpers/ConvertTo-CippMarkdownCell.ps1 index c6cbc88b51981..e1788d2b40563 100644 --- a/Modules/CIPPTests/Public/Helpers/ConvertTo-CippMarkdownCell.ps1 +++ b/Modules/CIPPTests/Public/Helpers/ConvertTo-CippMarkdownCell.ps1 @@ -38,6 +38,8 @@ function ConvertTo-CippMarkdownCell { $Text = [string]$Value if ([string]::IsNullOrEmpty($Text)) { return '' } - return ($Text -replace '\|', '\|' -replace '\r?\n', ' ').Trim() + # Backslashes first: they are the escape character the frontend table parser honours, + # so a literal one (CONTOSO\jdoe) has to be doubled before the pipe escape adds new ones. + return ($Text -replace '\\', '\\' -replace '\|', '\|' -replace '\r?\n', ' ').Trim() } } diff --git a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_1.ps1 b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_1.ps1 index 545d6281a5893..f0daa4b672546 100644 --- a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_1.ps1 +++ b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_1.ps1 @@ -9,7 +9,14 @@ function Invoke-CippTestCIS_2_1_1 { $SafeLinks = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoSafeLinksPolicies' if (-not $SafeLinks) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'CIS_2_1_1' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'ExoSafeLinksPolicies cache not found. Please refresh the cache for this tenant.' -Risk 'High' -Name 'Safe Links for Office Applications is enabled' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Email Protection' + # A Count marker means the cache was collected but the tenant has no Safe Links policy - + # that is a real failure (Safe Links is not enabled), not a missing cache. No marker + # means the type was never collected, so a Cache refresh is the correct guidance. + if (Get-CIPPDbItem -TenantFilter $Tenant -Type 'ExoSafeLinksPolicies' -CountsOnly) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'CIS_2_1_1' -TestType 'Identity' -Status 'Failed' -ResultMarkdown 'No Safe Links policy exists for this tenant, so Safe Links for Office applications is not enabled.' -Risk 'High' -Name 'Safe Links for Office Applications is enabled' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Email Protection' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'CIS_2_1_1' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'ExoSafeLinksPolicies has not been collected for this tenant. Run a Cache refresh (Cache & Tests); if it persists, the tenant may not have Defender for Office 365.' -Risk 'High' -Name 'Safe Links for Office Applications is enabled' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Email Protection' + } return } diff --git a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_11.ps1 b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_11.ps1 index 26dcfb8d7d145..cc7ba1a7da29c 100644 --- a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_11.ps1 +++ b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_11.ps1 @@ -13,16 +13,21 @@ function Invoke-CippTestCIS_2_1_11 { return } - $Default = $Malware | Where-Object { $_.IsDefault -eq $true } | Select-Object -First 1 - if (-not $Default) { $Default = $Malware | Select-Object -First 1 } - + # Comprehensive filtering is enforced by whichever malware policy applies via its rule, not + # only the built-in Default (which is capped at ~50 file types) - CIPP's own standard creates + # a non-default policy for exactly this. Grade the best policy that meets the bar. # CIS v7 defines a comprehensive list of 186 extensions and requires at least 90% adoption (>= 168). - $FileTypeCount = ($Default.FileTypes | Measure-Object).Count + $Policies = @($Malware) + $Compliant = $Policies | Where-Object { $_.EnableFileFilter -eq $true -and (($_.FileTypes | Measure-Object).Count -ge 168) } | Select-Object -First 1 - if ($Default.EnableFileFilter -eq $true -and $FileTypeCount -ge 168) { + if ($Compliant) { + $FileTypeCount = ($Compliant.FileTypes | Measure-Object).Count $Status = 'Passed' - $Result = "Comprehensive attachment filtering is applied — $FileTypeCount file types blocked on '$($Default.Identity)'." + $Result = "Comprehensive attachment filtering is applied — $FileTypeCount file types blocked on '$($Compliant.Identity)'." } else { + $Default = $Policies | Where-Object { $_.IsDefault -eq $true } | Select-Object -First 1 + if (-not $Default) { $Default = $Policies | Select-Object -First 1 } + $FileTypeCount = ($Default.FileTypes | Measure-Object).Count $Status = 'Failed' $Result = "Attachment filter on '$($Default.Identity)' is not comprehensive (EnableFileFilter: $($Default.EnableFileFilter), FileTypes count: $FileTypeCount, expected >= 168 — 90% of the CIS v7 186-extension list)." } diff --git a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_3.ps1 b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_3.ps1 index adac4d1ec2536..7ec17f0236226 100644 --- a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_3.ps1 +++ b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_3.ps1 @@ -13,15 +13,18 @@ function Invoke-CippTestCIS_2_1_3 { return } - $Default = $Malware | Where-Object { $_.IsDefault -eq $true } | Select-Object -First 1 - if (-not $Default) { $Default = $Malware | Select-Object -First 1 } + # The CIPP malware standard sets these notifications on the non-default policy it applies via + # a rule, not on the built-in Default - so accept any policy that has them configured, not + # only the IsDefault one (which otherwise makes a compliant tenant false-fail). + $Policies = @($Malware) + $Compliant = $Policies | Where-Object { $_.EnableInternalSenderAdminNotifications -eq $true -and -not [string]::IsNullOrWhiteSpace($_.InternalSenderAdminAddress) } | Select-Object -First 1 - $HasRecipients = $Default.EnableInternalSenderAdminNotifications -eq $true -and -not [string]::IsNullOrWhiteSpace($Default.InternalSenderAdminAddress) - - if ($HasRecipients) { + if ($Compliant) { $Status = 'Passed' - $Result = "Internal sender admin notifications enabled on '$($Default.Identity)'. Recipient: $($Default.InternalSenderAdminAddress)." + $Result = "Internal sender admin notifications enabled on '$($Compliant.Identity)'. Recipient: $($Compliant.InternalSenderAdminAddress)." } else { + $Default = $Policies | Where-Object { $_.IsDefault -eq $true } | Select-Object -First 1 + if (-not $Default) { $Default = $Policies | Select-Object -First 1 } $Status = 'Failed' $Result = "Internal sender admin notifications are not configured on '$($Default.Identity)'.`n`n- EnableInternalSenderAdminNotifications: $($Default.EnableInternalSenderAdminNotifications)`n- InternalSenderAdminAddress: '$($Default.InternalSenderAdminAddress)'" } diff --git a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_4.ps1 b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_4.ps1 index 935c5ec645b83..f76297dcf85be 100644 --- a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_4.ps1 +++ b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_4.ps1 @@ -9,7 +9,14 @@ function Invoke-CippTestCIS_2_1_4 { $SA = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoSafeAttachmentPolicies' if (-not $SA) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'CIS_2_1_4' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'ExoSafeAttachmentPolicies cache not found. Please refresh the cache for this tenant.' -Risk 'High' -Name 'Safe Attachments policy is enabled' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Email Protection' + # A Count marker means the cache was collected but the tenant has no Safe Attachments + # policy - that is a real failure, not a missing cache. No marker means the type was + # never collected, so a Cache refresh is the correct guidance. + if (Get-CIPPDbItem -TenantFilter $Tenant -Type 'ExoSafeAttachmentPolicies' -CountsOnly) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'CIS_2_1_4' -TestType 'Identity' -Status 'Failed' -ResultMarkdown 'No Safe Attachments policy exists for this tenant, so Safe Attachments is not enabled.' -Risk 'High' -Name 'Safe Attachments policy is enabled' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Email Protection' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'CIS_2_1_4' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'ExoSafeAttachmentPolicies has not been collected for this tenant. Run a Cache refresh (Cache & Tests); if it persists, the tenant may not have Defender for Office 365.' -Risk 'High' -Name 'Safe Attachments policy is enabled' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Email Protection' + } return } diff --git a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_5.ps1 b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_5.ps1 index c5a9c4c94d74f..7c7f7f9c535f5 100644 --- a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_5.ps1 +++ b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_5.ps1 @@ -9,7 +9,14 @@ function Invoke-CippTestCIS_2_1_5 { $Atp = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoAtpPolicyForO365' if (-not $Atp) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'CIS_2_1_5' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'ExoAtpPolicyForO365 cache not found. Please refresh the cache for this tenant.' -Risk 'High' -Name 'Safe Attachments for SharePoint, OneDrive, and Teams is enabled' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Email Protection' + # A Count marker means the cache was collected but the tenant has no ATP policy - that is + # a real failure, not a missing cache. No marker means the type was never collected, so a + # Cache refresh is the correct guidance. + if (Get-CIPPDbItem -TenantFilter $Tenant -Type 'ExoAtpPolicyForO365' -CountsOnly) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'CIS_2_1_5' -TestType 'Identity' -Status 'Failed' -ResultMarkdown 'No ATP policy for Office 365 exists for this tenant, so Safe Attachments for SharePoint, OneDrive and Teams is not enabled.' -Risk 'High' -Name 'Safe Attachments for SharePoint, OneDrive, and Teams is enabled' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Email Protection' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'CIS_2_1_5' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'ExoAtpPolicyForO365 has not been collected for this tenant. Run a Cache refresh (Cache & Tests); if it persists, the tenant may not have Defender for Office 365.' -Risk 'High' -Name 'Safe Attachments for SharePoint, OneDrive, and Teams is enabled' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Email Protection' + } return } diff --git a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_6_1_2.ps1 b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_6_1_2.ps1 index bbd546c7f849c..18a3a3d6a3808 100644 --- a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_6_1_2.ps1 +++ b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_6_1_2.ps1 @@ -14,14 +14,21 @@ function Invoke-CippTestCIS_6_1_2 { } $User = $Mailboxes | Where-Object { $_.RecipientTypeDetails -eq 'UserMailbox' } - $Failures = $User | Where-Object { $_.AuditEnabled -eq $false -or -not $_.AuditOwner -or $_.AuditOwner.Count -eq 0 } + # CIS 6.1.2 requires per-mailbox audit ACTIONS to be configured. With mailbox auditing on by + # default Microsoft applies the default action sets and Get-Mailbox reports AuditEnabled = True, + # so the reliable signal is a non-empty AuditOwner (the effective owner actions) or a + # DefaultAuditSet that still lists the Owner sign-in type (Microsoft-managed defaults). + # AuditEnabled itself can arrive as a string from EXO REST and is not graded directly. + $Failures = $User | Where-Object { + @($_.AuditOwner).Count -eq 0 -and ("$($_.DefaultAuditSet)" -notmatch 'Owner') + } if ($Failures.Count -eq 0) { $Status = 'Passed' - $Result = "All $($User.Count) user mailbox(es) have auditing enabled with audit actions configured." + $Result = "All $($User.Count) user mailbox(es) have owner audit actions configured." } else { $Status = 'Failed' - $Result = "$($Failures.Count) of $($User.Count) user mailbox(es) have auditing disabled or no audit actions configured." + $Result = "$($Failures.Count) of $($User.Count) user mailbox(es) have no owner audit actions configured." } Add-CippTestResult -TenantFilter $Tenant -TestId 'CIS_6_1_2' -TestType 'Identity' -Status $Status -ResultMarkdown $Result -Risk 'High' -Name 'Mailbox audit actions are configured' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Audit & Compliance' diff --git a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_7_2_11.ps1 b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_7_2_11.ps1 index f2c3acda87f14..8f5673303bf20 100644 --- a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_7_2_11.ps1 +++ b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_7_2_11.ps1 @@ -15,12 +15,22 @@ function Invoke-CippTestCIS_7_2_11 { $Cfg = $SPO | Select-Object -First 1 - if ($Cfg.DefaultLinkPermission -eq 'View') { + # The SPOTenant cache comes from the SharePoint CSOM endpoint, which returns + # DefaultLinkPermission as a numeric SharingPermissionType (None=0, View=1, Edit=2) - not the + # friendly name Get-SPOTenant shows. Normalise before comparing, or every tenant false-fails. + $PermissionName = switch ("$($Cfg.DefaultLinkPermission)") { + '0' { 'None' } + '1' { 'View' } + '2' { 'Edit' } + default { "$($Cfg.DefaultLinkPermission)" } + } + + if ($PermissionName -eq 'View') { $Status = 'Passed' $Result = 'DefaultLinkPermission is set to View.' } else { $Status = 'Failed' - $Result = "DefaultLinkPermission is set to $($Cfg.DefaultLinkPermission). CIS requires View." + $Result = "DefaultLinkPermission is set to $PermissionName. CIS requires View." } Add-CippTestResult -TenantFilter $Tenant -TestId 'CIS_7_2_11' -TestType 'Identity' -Status $Status -ResultMarkdown $Result -Risk 'Medium' -Name 'The SharePoint default sharing link permission is set' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Data Protection' diff --git a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_7_2_7.ps1 b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_7_2_7.ps1 index 7622e8f0968d1..90e8c4a7afcc4 100644 --- a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_7_2_7.ps1 +++ b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_7_2_7.ps1 @@ -14,14 +14,26 @@ function Invoke-CippTestCIS_7_2_7 { } $Cfg = $SPO | Select-Object -First 1 + + # The SPOTenant cache comes from the SharePoint CSOM endpoint, which returns + # DefaultSharingLinkType as a numeric SharingLinkType (None=0, Direct=1, Internal=2, + # AnonymousAccess=3) - not the friendly name Get-SPOTenant shows. Normalise before comparing, + # or every tenant false-fails. + $LinkTypeName = switch ("$($Cfg.DefaultSharingLinkType)") { + '0' { 'None' } + '1' { 'Direct' } + '2' { 'Internal' } + '3' { 'AnonymousAccess' } + default { "$($Cfg.DefaultSharingLinkType)" } + } $Acceptable = @('Direct', 'Internal') - if ($Cfg.DefaultSharingLinkType -in $Acceptable) { + if ($LinkTypeName -in $Acceptable) { $Status = 'Passed' - $Result = "DefaultSharingLinkType is restricted ($($Cfg.DefaultSharingLinkType))." + $Result = "DefaultSharingLinkType is restricted ($LinkTypeName)." } else { $Status = 'Failed' - $Result = "DefaultSharingLinkType is too permissive ($($Cfg.DefaultSharingLinkType)). Set to Direct or Internal." + $Result = "DefaultSharingLinkType is too permissive ($LinkTypeName). Set to Direct or Internal." } Add-CippTestResult -TenantFilter $Tenant -TestId 'CIS_7_2_7' -TestType 'Identity' -Status $Status -ResultMarkdown $Result -Risk 'Medium' -Name 'Link sharing is restricted in SharePoint and OneDrive' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'External Collaboration' diff --git a/Modules/CIPPTests/Public/Tests/GenericTests/Identity/Invoke-CippTestGenericTest011.ps1 b/Modules/CIPPTests/Public/Tests/GenericTests/Identity/Invoke-CippTestGenericTest011.ps1 index 3930ff44c207b..a6236c9921308 100644 --- a/Modules/CIPPTests/Public/Tests/GenericTests/Identity/Invoke-CippTestGenericTest011.ps1 +++ b/Modules/CIPPTests/Public/Tests/GenericTests/Identity/Invoke-CippTestGenericTest011.ps1 @@ -43,8 +43,10 @@ function Invoke-CippTestGenericTest011 { $AllIntuneTemplates = @($RawIntuneTemplates | ForEach-Object { $JSONData = $_.JSON | ConvertFrom-Json -Depth 10 $data = $JSONData.RAWJson | ConvertFrom-Json -Depth 10 - $data | Add-Member -NotePropertyName 'displayName' -NotePropertyValue $JSONData.Displayname -Force - $data | Add-Member -NotePropertyName 'GUID' -NotePropertyValue $_.RowKey -Force + $data | Add-Member -NotePropertyMembers ([ordered]@{ + displayName = $JSONData.Displayname + GUID = $_.RowKey + }) -Force $data }) } catch { $AllIntuneTemplates = @() } diff --git a/Modules/CIPPTests/Public/Tests/ZTNA/Identity/Invoke-CippTestZTNA21811.ps1 b/Modules/CIPPTests/Public/Tests/ZTNA/Identity/Invoke-CippTestZTNA21811.ps1 index 3f937afc706e1..4df1dcf46c521 100644 --- a/Modules/CIPPTests/Public/Tests/ZTNA/Identity/Invoke-CippTestZTNA21811.ps1 +++ b/Modules/CIPPTests/Public/Tests/ZTNA/Identity/Invoke-CippTestZTNA21811.ps1 @@ -13,7 +13,17 @@ function Invoke-CippTestZTNA21811 { return } - $misconfiguredDomains = $domains | Where-Object { $_.passwordValidityPeriodInDays -ne 2147483647 } + # Subdomains cannot carry their own password policy (Graph returns null and blocks updates), + # so evaluate root-level domains only — same derivation as Invoke-CIPPStandardPasswordExpireDisabled. + $DomainIds = @($domains.id) + $SubDomains = foreach ($id in $DomainIds) { + foreach ($parent in $DomainIds) { + if ($id -ne $parent -and $id.EndsWith(".$parent")) { + $id; break + } + } + } + $misconfiguredDomains = $domains | Where-Object { $_.id -notin $SubDomains -and $null -ne $_.passwordValidityPeriodInDays -and $_.passwordValidityPeriodInDays -ne 2147483647 } $users = Get-CIPPTestData -TenantFilter $Tenant -Type 'Users' @@ -21,7 +31,8 @@ function Invoke-CippTestZTNA21811 { if ($users) { $misconfiguredUsers = foreach ($user in $users) { $userDomain = $user.userPrincipalName.Split('@')[-1] - $domainPolicy = $misconfiguredDomains | Where-Object { $_.id -eq $userDomain } + # Subdomain UPNs inherit the root domain's policy, so match on the suffix too + $domainPolicy = $misconfiguredDomains | Where-Object { $_.id -eq $userDomain -or $userDomain.EndsWith(".$($_.id)") } if (($user.passwordPolicies -notlike '*DisablePasswordExpiration*') -and ($domainPolicy)) { [PSCustomObject]@{ id = $user.id diff --git a/Modules/CippExtensions/Public/Extension Functions/Register-CippExtensionScheduledTasks.ps1 b/Modules/CippExtensions/Public/Extension Functions/Register-CippExtensionScheduledTasks.ps1 index e514464ceac84..cda40b544fca5 100644 --- a/Modules/CippExtensions/Public/Extension Functions/Register-CippExtensionScheduledTasks.ps1 +++ b/Modules/CippExtensions/Public/Extension Functions/Register-CippExtensionScheduledTasks.ps1 @@ -31,6 +31,18 @@ function Register-CIPPExtensionScheduledTasks { $ExtensionConfig = $Config.$Extension if ($ExtensionConfig.Enabled -eq $true -or $Extension -eq 'CustomData') { if ($Extension -eq 'Sherweb') { + # Mapping a tenant for CSP licensing must not enrol it into daily migration checks. + # Only schedule migration tasks when automated migration is explicitly enabled; when + # it is off, clean up any tasks that were previously created so they stop firing. + if ($ExtensionConfig.AutoMigrations -ne $true) { + $SherwebMigTasks | ForEach-Object { + Write-Information "Sherweb automated migration disabled: Cleaning up scheduled task $($_.Name) for tenant $($_.Tenant)" + $Entity = $_ | Select-Object -Property PartitionKey, RowKey + Remove-CIPPAzDataTableEntity -Force @ScheduledTasksTable -Entity $Entity + } + $SherwebMigTasks = @() # Clear the list since we removed them all + continue + } # Sherweb migration tasks - schedule per mapped tenant $SherwebMappings = Get-CIPPAzDataTableEntity @MappingsTable -Filter "PartitionKey eq 'SherwebMapping'" foreach ($Mapping in $SherwebMappings) { diff --git a/Modules/CippExtensions/Public/Halo/Get-HaloPriority.ps1 b/Modules/CippExtensions/Public/Halo/Get-HaloPriority.ps1 index 5b99bf0dfa0f1..629b97c3c2422 100644 --- a/Modules/CippExtensions/Public/Halo/Get-HaloPriority.ps1 +++ b/Modules/CippExtensions/Public/Halo/Get-HaloPriority.ps1 @@ -36,23 +36,14 @@ function Get-HaloPriority { } $Headers = @{ Authorization = "Bearer $($Token.access_token)" } - $TicketTypeRecord = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/tickettype/$TicketType" -ContentType 'application/json' -Method GET -Headers $Headers - - # Halo's /tickettype/{id} response uses different field names for the linked SLA across - # versions. Check the known variants in priority order, take the first non-zero match. - $SlaIdCandidates = @('default_sla', 'default_sla_id', 'sla_id', 'slaid', 'sla') - $SlaId = $null - foreach ($Field in $SlaIdCandidates) { - $Value = $TicketTypeRecord.$Field - if ($Value -and ([int]$Value) -gt 0) { - $SlaId = [int]$Value - break - } - } + $SlaId = Get-HaloTicketTypeSlaId -TicketType $TicketType -Configuration $Configuration -Token $Token if (-not $SlaId) { + # New-HaloPSATicket applies the same test and omits priority_id entirely for this + # ticket type, so the message describes what will actually happen rather than just + # explaining an empty list. return @(@{ - name = 'The selected Ticket Type has no SLA attached, so there are no priorities to pick from. Attach an SLA to the ticket type in HaloPSA, or leave this blank.' + name = 'The selected Ticket Type has no SLA attached, so there are no priorities to pick from. Tickets will be created without a priority and HaloPSA will apply its own. Attach an SLA to the ticket type in HaloPSA to choose one here.' priorityid = -1 }) } diff --git a/Modules/CippExtensions/Public/Halo/Get-HaloTicketTypeSlaId.ps1 b/Modules/CippExtensions/Public/Halo/Get-HaloTicketTypeSlaId.ps1 new file mode 100644 index 0000000000000..1211f599654dc --- /dev/null +++ b/Modules/CippExtensions/Public/Halo/Get-HaloTicketTypeSlaId.ps1 @@ -0,0 +1,53 @@ +function Get-HaloTicketTypeSlaId { + <# + .SYNOPSIS + Resolve the SLA id attached to a HaloPSA ticket type, or $null when it has none. + .DESCRIPTION + Priorities in HaloPSA are defined per priority per SLA - the same priority_id means a + different thing under a different SLA (response and resolution targets are set on the + SLA/priority pair). A ticket type with no SLA therefore has no priority set that can be + meaningfully chosen from, which is why both the settings dropdown and the ticket writer + need to agree on whether one is attached. + + Shared by Get-HaloPriority (to decide whether there is anything to offer) and + New-HaloPSATicket (to decide whether to send priority_id at all), so the two cannot drift + apart and start disagreeing about the same ticket type. + .PARAMETER TicketType + The ticket type id to resolve. + .PARAMETER Configuration + The HaloPSA extension configuration, for ResourceURL. + .PARAMETER Token + An existing Halo token, so callers that already hold one do not fetch a second. + .OUTPUTS + [int] the SLA id, or $null when the ticket type has no SLA or could not be read. + #> + [CmdletBinding()] + param ( + $TicketType, + $Configuration, + $Token + ) + + if (-not $TicketType) { return $null } + + try { + $Headers = @{ Authorization = "Bearer $($Token.access_token)" } + $TicketTypeRecord = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/tickettype/$TicketType" -ContentType 'application/json' -Method GET -Headers $Headers + + # Halo's /tickettype/{id} response uses different field names for the linked SLA across + # versions. Check the known variants in order and take the first usable match. Halo uses + # -1 for "none", so anything not greater than zero counts as no SLA. + foreach ($Field in @('default_sla', 'default_sla_id', 'sla_id', 'slaid', 'sla')) { + $Value = $TicketTypeRecord.$Field + if ($Value -and ([int]$Value) -gt 0) { + return [int]$Value + } + } + return $null + } catch { + # Callers treat $null as "no SLA" and omit the priority, which is the safe direction: + # a transient lookup failure should not put an arbitrary priority on a ticket. + Write-Information "Could not resolve the SLA for HaloPSA ticket type $TicketType : $($_.Exception.Message)" + return $null + } +} diff --git a/Modules/CippExtensions/Public/Halo/New-HaloPSATicket.ps1 b/Modules/CippExtensions/Public/Halo/New-HaloPSATicket.ps1 index 5cddec481ebe8..21b79d3fd87cf 100644 --- a/Modules/CippExtensions/Public/Halo/New-HaloPSATicket.ps1 +++ b/Modules/CippExtensions/Public/Halo/New-HaloPSATicket.ps1 @@ -6,7 +6,12 @@ function New-HaloPSATicket { $client, [string]$UserUPN, [string]$AzureOID, - [string]$DisplayName + [string]$DisplayName, + # Per-alert priority override. Left untyped so callers can hand over either a raw Halo + # priority id or the {label, value} shape the alert form stores, matching how the + # integration-wide DefaultPriority is read below. + $TicketPriority, + [int]$TicketId ) #Get HaloPSA Token based on the config we have. $Table = Get-CIPPTable -TableName Extensionsconfig @@ -16,8 +21,12 @@ function New-HaloPSATicket { # Resolve affected user to a HaloPSA contact when the integration is configured for it. # Unmatched users fall through to userlookup.id = -1 (the client's General User contact). + # An explicit TicketId means the caller already knows which ticket the work belongs to, so there + # is nothing to resolve - the target ticket carries its own user. This is the case that matters + # for onboarding: a user created seconds ago is never a HaloPSA contact yet, so matching would + # always miss and stamp the ticket with the General User fallback. $MatchedUser = $null - $UserLinkActive = $Configuration.LinkTicketsToUsers -and ($UserUPN -or $AzureOID) + $UserLinkActive = $TicketId -le 0 -and $Configuration.LinkTicketsToUsers -and ($UserUPN -or $AzureOID) if ($UserLinkActive) { $MatchedUser = Get-HaloUser -AzureOID $AzureOID -Email $UserUPN -ClientId $client -Configuration $Configuration -Token $token if (-not $MatchedUser) { @@ -37,67 +46,85 @@ function New-HaloPSATicket { # from the General User (id = -1). $SiteId = if ($MatchedUser) { $MatchedUser.site_id } else { $null } - if ($Configuration.ConsolidateTickets) { + # A caller-supplied TicketId targets a ticket CIPP did not open - a scheduled task carrying a PSA + # reference back to the request it came from - so it bypasses the consolidation table entirely. + # Otherwise fall back to the ticket CIPP opened for this title, when consolidation is enabled. + $TargetTicketId = $null + if ($TicketId -gt 0) { + $TargetTicketId = $TicketId + Write-Information "Targeting caller-supplied HaloPSA ticket: $TargetTicketId" + } elseif ($Configuration.ConsolidateTickets) { $ExistingTicket = Get-CIPPAzDataTableEntity @TicketTable -Filter "PartitionKey eq 'HaloPSA' and RowKey eq '$($client)-$($TitleHash)'" if ($ExistingTicket) { Write-Information "Ticket already exists in HaloPSA: $($ExistingTicket.TicketID)" + $TargetTicketId = $ExistingTicket.TicketID + } + } - $Ticket = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/Tickets/$($ExistingTicket.TicketID)?includedetails=true&includelastaction=false&nocache=undefined&includeusersassets=false&isdetailscreen=true" -ContentType 'application/json; charset=utf-8' -Method Get -Headers @{Authorization = "Bearer $($token.access_token)" } -SkipHttpErrorCheck - if ($Ticket.id) { - if (!$Ticket.hasbeenclosed) { - Write-Information 'Ticket is still open, adding new note' - # Halo won't take a note without an outcome - it answers "An Outcome must be entered - # for this Action" - so fall back to 7, the built-in Internal Note outcome, when the - # integration hasn't been given one. The failure this used to hit was the API user not - # having rights to the action, which is caught below and falls back to a new ticket so - # the alert still lands somewhere. - $Outcome = if ($Configuration.Outcome) { - $Configuration.Outcome.value ?? $Configuration.Outcome - } else { - 7 + if ($TargetTicketId) { + $Ticket = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/Tickets/$($TargetTicketId)?includedetails=true&includelastaction=false&nocache=undefined&includeusersassets=false&isdetailscreen=true" -ContentType 'application/json; charset=utf-8' -Method Get -Headers @{Authorization = "Bearer $($token.access_token)" } -SkipHttpErrorCheck + if ($Ticket.id) { + if (!$Ticket.hasbeenclosed) { + Write-Information 'Ticket is still open, adding new note' + # Halo won't take a note without an outcome - it answers "An Outcome must be entered + # for this Action" - so fall back to 7, the built-in Internal Note outcome, when the + # integration hasn't been given one. The failure this used to hit was the API user not + # having rights to the action, which is caught below and falls back to a new ticket so + # the alert still lands somewhere. + $Outcome = if ($Configuration.Outcome) { + $Configuration.Outcome.value ?? $Configuration.Outcome + } else { + 7 + } + $Object = [PSCustomObject]@{ + ticket_id = $TargetTicketId + outcome_id = $Outcome + hiddenfromuser = $true + note_html = $description + } + + $body = ConvertTo-Json -Compress -Depth 10 -InputObject @($Object) + $NoteAdded = $false + try { + if ($PSCmdlet.ShouldProcess('Add note to HaloPSA ticket', 'Add note')) { + $Action = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/actions" -ContentType 'application/json; charset=utf-8' -Method Post -Body $body -Headers @{Authorization = "Bearer $($token.access_token)" } + Write-Information "Note added to ticket in HaloPSA: $TargetTicketId" + $NoteAdded = $true } - $Object = [PSCustomObject]@{ - ticket_id = $ExistingTicket.TicketID - outcome_id = $Outcome - hiddenfromuser = $true - note_html = $description + } + catch { + $Message = if ($_.ErrorDetails.Message) { + Get-NormalizedError -Message $_.ErrorDetails.Message } - - $body = ConvertTo-Json -Compress -Depth 10 -InputObject @($Object) - $NoteAdded = $false - try { - if ($PSCmdlet.ShouldProcess('Add note to HaloPSA ticket', 'Add note')) { - $Action = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/actions" -ContentType 'application/json; charset=utf-8' -Method Post -Body $body -Headers @{Authorization = "Bearer $($token.access_token)" } - Write-Information "Note added to ticket in HaloPSA: $($ExistingTicket.TicketID)" - $NoteAdded = $true - } + else { + $_.Exception.message } - catch { - $Message = if ($_.ErrorDetails.Message) { - Get-NormalizedError -Message $_.ErrorDetails.Message - } - else { - $_.Exception.message - } - # Don't return here - if appending a note failed (e.g. permissions on the action, - # invalid outcome_id) we still want to create a fresh ticket so the alert isn't lost. - $OutcomeHint = if ($Configuration.Outcome) { - "Outcome $Outcome is set for this integration - check the HaloPSA API user can run that action." - } else { - "No Outcome is configured, so the built-in Internal Note action ($Outcome) was used. If it has been removed or the API user cannot run it, pick a different Outcome on the HaloPSA integration page." - } - Write-LogMessage -message "Failed to add note to HaloPSA ticket $($ExistingTicket.TicketID): $Message - falling back to creating a new ticket. $OutcomeHint" -API 'HaloPSATicket' -sev Warning -LogData (Get-CippException -Exception $_) - Write-Information "Failed to add note to HaloPSA ticket: $Message; creating a new ticket instead" - Write-Information "Body we tried to ship: $body" + # Don't return here - if appending a note failed (e.g. permissions on the action, + # invalid outcome_id) we still want to create a fresh ticket so the alert isn't lost. + $OutcomeHint = if ($Configuration.Outcome) { + "Outcome $Outcome is set for this integration - check the HaloPSA API user can run that action." + } else { + "No Outcome is configured, so the built-in Internal Note action ($Outcome) was used. If it has been removed or the API user cannot run it, pick a different Outcome on the HaloPSA integration page." } + Write-LogMessage -message "Failed to add note to HaloPSA ticket $($TargetTicketId): $Message - falling back to creating a new ticket. $OutcomeHint" -API 'HaloPSATicket' -sev Warning -LogData (Get-CippException -Exception $_) + Write-Information "Failed to add note to HaloPSA ticket: $Message; creating a new ticket instead" + Write-Information "Body we tried to ship: $body" + } - if ($NoteAdded) { - return "Note added to ticket in HaloPSA: $($ExistingTicket.TicketID)" - } + if ($NoteAdded) { + return "Note added to ticket in HaloPSA: $TargetTicketId" } } else { - Write-Information 'Existing ticket could not be found. Creating a new ticket instead.' + # Falling through to a new ticket keeps the result from being lost, but silently doing so + # reads as CIPP ignoring the reference, so say which ticket was skipped and why. + Write-LogMessage -message "HaloPSA ticket $TargetTicketId is closed - the update was raised as a new ticket instead." -API 'HaloPSATicket' -sev Warning + } + } + else { + Write-Information 'Existing ticket could not be found. Creating a new ticket instead.' + if ($TicketId -gt 0) { + Write-LogMessage -message "HaloPSA ticket $TargetTicketId could not be found - the update was raised as a new ticket instead. Check the reference on the scheduled task." -API 'HaloPSATicket' -sev Warning } } } @@ -137,15 +164,45 @@ function New-HaloPSATicket { $TicketType = $Configuration.TicketType.value ?? $Configuration.TicketType $object | Add-Member -MemberType NoteProperty -Name 'tickettype_id' -Value $TicketType -Force } - if ($Configuration.DefaultPriority) { - $Priority = $Configuration.DefaultPriority.value ?? $Configuration.DefaultPriority - $PriorityInt = $Priority -as [int] + # Priority sources in precedence order: the per-alert override configured on the alert, then the + # integration-wide default. Both can be stored as a {label, value} autocomplete object or as a + # raw id depending on where they were saved, so unwrap .value first. A value that isn't a usable + # Halo priority id falls through to the next source rather than failing the ticket - Halo applies + # the SLA default when priority_id is absent. + # + # This only runs on the create path. The note path above (a caller-supplied TicketId or a + # ConsolidateTickets match) returns before here, so appending a note to an existing ticket + # deliberately leaves its priority alone - the same way tickettype_id is not re-applied. + $PrioritySources = @( + @{ Label = 'alert'; Value = ($TicketPriority.value ?? $TicketPriority) } + @{ Label = 'HaloPSA.DefaultPriority'; Value = ($Configuration.DefaultPriority.value ?? $Configuration.DefaultPriority) } + ) + $ResolvedPriority = $null + $PrioritySource = $null + foreach ($Source in $PrioritySources) { + if ([string]::IsNullOrWhiteSpace([string]$Source.Value)) { continue } + $PriorityInt = $Source.Value -as [int] if ($PriorityInt -and $PriorityInt -gt 0) { - $object | Add-Member -MemberType NoteProperty -Name 'priority_id' -Value $PriorityInt -Force + $ResolvedPriority = $PriorityInt + $PrioritySource = $Source.Label + break + } + # Value isn't a valid Halo priority id (legacy data, hint-row selection, etc.). Skip it rather + # than crashing the cast and try the next source. + Write-LogMessage -message "HaloPSA priority value '$($Source.Value)' from $($Source.Label) is not a valid priority id - falling back" -API 'HaloPSATicket' -sev Warning + } + + # A priority id only means something within an SLA - the same id maps to a different priority + # under a different SLA. When the ticket type has no SLA there is nothing for it to resolve + # against, so send no priority and let Halo apply its own rather than gambling on whichever SLA + # it happens to pick. This is the same test Get-HaloPriority uses to decide it has nothing to + # offer, so a priority can never be sent that the settings page would not have let you choose. + # Only checked when there is a priority to send, so the common path costs no extra API call. + if ($ResolvedPriority) { + if (Get-HaloTicketTypeSlaId -TicketType ($Configuration.TicketType.value ?? $Configuration.TicketType) -Configuration $Configuration -Token $token) { + $object | Add-Member -MemberType NoteProperty -Name 'priority_id' -Value $ResolvedPriority -Force } else { - # Stored value isn't a valid Halo priority id (legacy data, hint-row selection, etc.). - # Skip priority_id rather than crashing the cast - Halo will fall back to its default. - Write-LogMessage -message "HaloPSA.DefaultPriority value '$Priority' is not a valid integer - omitting priority_id from ticket payload" -API 'HaloPSATicket' -sev Warning + Write-Information "Ticket type has no SLA attached - omitting priority_id ($ResolvedPriority from $PrioritySource) so HaloPSA applies its own priority" } } # Halo records tickets created over the API as 'Manual' unless the payload carries a source, so diff --git a/Modules/CippExtensions/Public/New-CippExtAlert.ps1 b/Modules/CippExtensions/Public/New-CippExtAlert.ps1 index afd594eeff913..e32ab469f2278 100644 --- a/Modules/CippExtensions/Public/New-CippExtAlert.ps1 +++ b/Modules/CippExtensions/Public/New-CippExtAlert.ps1 @@ -15,11 +15,13 @@ function New-CippExtAlert { if ($Configuration.HaloPSA.enabled) { $MappingFile = Get-CIPPAzDataTableEntity @MappingTable -Filter "PartitionKey eq 'HaloMapping'" $TenantId = (Get-Tenants -TenantFilter $Alert.TenantId).customerId - Write-Host "TenantId: $TenantId" $MappedId = ($MappingFile | Where-Object { $_.RowKey -eq $TenantId }).IntegrationId - Write-Host "MappedId: $MappedId" - if (!$mappedId) { $MappedId = 1 } - Write-Host "MappedId: $MappedId" + if (!$MappedId) { + # Unmapped tenants land on client 1; say so instead of doing it silently. + $MappedId = 1 + Write-LogMessage -API 'HaloPSATicket' -tenant $Alert.TenantId -message "No HaloPSA client mapping for tenant $($Alert.TenantId) - the ticket was raised against Halo client id 1. Map the tenant under Settings > Integrations > HaloPSA." -sev Warning + } + Write-Information "HaloPSA client for tenant $($Alert.TenantId): $MappedId" $TicketParams = @{ Title = $Alert.AlertTitle @@ -27,7 +29,52 @@ function New-CippExtAlert { Client = $MappedId } - if ($Alert.AffectedUser -and $Configuration.HaloPSA.LinkTicketsToUsers) { + # A task can name the ticket the work came from, so the PSA copy lands as a note + # on that ticket instead of opening a second one. Two sources, in order: + # + # PsaTicketId - the ticket box on the user/offboarding/scheduler forms, shown + # only when this integration is enabled. Unambiguous, so it wins. + # Reference - free text, and only an [ID:nnnn] token in it counts. That is + # HaloPSA's own subject token, which is also what makes the + # emailed copy thread onto the same ticket. A bare number is + # deliberately NOT accepted: the reference legitimately holds + # order numbers, asset tags and change ids, and treating one as + # a ticket id would append a starter's password to an unrelated + # ticket. + # + # Reading both is this extension's job: the formats are Halo's, and the scheduler + # passes the values through untouched. + $ReferencedTicketId = 0 + $TicketCandidate = if ($Alert.PsaTicketId) { + "$($Alert.PsaTicketId)".Trim() + } elseif ("$($Alert.Reference)" -match '\[ID:(\d+)\]') { + $Matches[1] + } else { + $null + } + if ($TicketCandidate) { + # TryParse rather than a cast: a long run of digits is a valid match but an + # invalid ticket id, and an overflow here would cost the alert entirely. + $ParsedTicketId = 0 + if ([int]::TryParse($TicketCandidate, [ref]$ParsedTicketId) -and $ParsedTicketId -gt 0) { + $ReferencedTicketId = $ParsedTicketId + $TicketParams.TicketId = $ReferencedTicketId + Write-Information "Alert targets HaloPSA ticket $ReferencedTicketId - adding a note to it instead of creating a ticket" + # Setting both and disagreeing is easy to do by accident, and the effect is + # confusing: the reference is what the notification title shows, so the note + # lands on a ticket the title never mentions and it looks like nothing + # happened. Say where it actually went. + if ($Alert.PsaTicketId -and "$($Alert.Reference)" -match '\[ID:(\d+)\]' -and $Matches[1] -ne "$ReferencedTicketId") { + Write-LogMessage -API 'HaloPSATicket' -tenant $Alert.TenantId -message "Task targets HaloPSA ticket $ReferencedTicketId from its ticket field, but its reference names ticket $($Matches[1]). The note was added to $ReferencedTicketId." -sev Warning + } + } else { + Write-LogMessage -API 'HaloPSATicket' -tenant $Alert.TenantId -message "'$TicketCandidate' is not a usable HaloPSA ticket id - raising a new ticket instead." -sev Warning + } + } + + # A referenced ticket already carries its own end user, so skip the contact lookup + # (and the Graph call under it) entirely. + if ($ReferencedTicketId -le 0 -and $Alert.AffectedUser -and $Configuration.HaloPSA.LinkTicketsToUsers) { $UPN = $Alert.AffectedUser.UPN $OID = $Alert.AffectedUser.AzureOID $Display = $Alert.AffectedUser.DisplayName @@ -50,6 +97,13 @@ function New-CippExtAlert { if ($Display) { $TicketParams.DisplayName = $Display } } + # Per-alert priority beats the integration-wide DefaultPriority. Unlike the + # user fields above this is NOT gated on LinkTicketsToUsers - priority applies + # to every ticket, and it must also work when no global default is configured. + if ($Alert.PsaTicketPriority) { + $TicketParams.TicketPriority = $Alert.PsaTicketPriority + } + New-HaloPSATicket @TicketParams } } diff --git a/Modules/CippExtensions/Public/NinjaOne/Invoke-NinjaOneTenantSync.ps1 b/Modules/CippExtensions/Public/NinjaOne/Invoke-NinjaOneTenantSync.ps1 index b6bdf1b9097f5..4b740b1d2eb46 100644 --- a/Modules/CippExtensions/Public/NinjaOne/Invoke-NinjaOneTenantSync.ps1 +++ b/Modules/CippExtensions/Public/NinjaOne/Invoke-NinjaOneTenantSync.ps1 @@ -583,14 +583,6 @@ function Invoke-NinjaOneTenantSync { DeviceLink = $ParsedDeviceName } - Add-CIPPAzDataTableEntity @DeviceTable -Entity @{ - PartitionKey = $Customer.CustomerId - RowKey = $device.AzureADDeviceId - RawDevice = "$($ParsedDevice | ConvertTo-Json -Depth 100 -Compress)" - } -Force - - $ParsedDevices.add($ParsedDevice) - ### Update NinjaOne Device Fields if ($MatchedNinjaDevice) { $NinjaDeviceUpdate = [PSCustomObject]@{} @@ -607,8 +599,8 @@ function Invoke-NinjaOneTenantSync { Icon = 'fas fa-laptop' }, @{ - Name = 'View Devices in CIPP' - Link = "https://$($CIPPURL)/endpoint/MEM/devices?tenantFilter=$($Customer.defaultDomainName)" + Name = 'View Device in CIPP' + Link = "https://$($CIPPURL)/endpoint/MEM/devices/device?deviceId=$($Device.id)&tenantFilter=$($Customer.defaultDomainName)" Icon = 'far fa-eye' } ) @@ -713,15 +705,30 @@ function Invoke-NinjaOneTenantSync { } - # Update Device + # Update Device. Default to success so devices with no mapped fields are still cached. + $DeviceFieldsUpdated = $true if ($MappedFields.DeviceSummary -or $MappedFields.DeviceLinks -or $MappedFields.DeviceCompliance) { + $DeviceFieldsUpdated = $false try { $UpdateBody = $NinjaDeviceUpdate | ConvertTo-Json -Depth 100 $Result = Invoke-WebRequest -Uri "https://$($Configuration.Instance)/api/v2/device/$($MatchedNinjaDevice.id)/custom-fields" -Method PATCH -Headers @{Authorization = "Bearer $($token.access_token)" } -ContentType 'application/json; charset=utf-8' -Body $UpdateBody + $DeviceFieldsUpdated = $true } catch { - Write-Verbose "Error details: $($_ | ConvertTo-Json -Depth 5)" + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -tenant $TenantFilter -API 'NinjaOneSync' -message "Failed to update NinjaOne custom fields for device '$($Device.deviceName)' ($($MatchedNinjaDevice.id)): $($ErrorMessage.NormalizedError)" -Sev 'Warning' -LogData $ErrorMessage } } + + # Only cache the device once its fields have been written, so a failed update is retried on the next sync instead of being skipped permanently. + if ($DeviceFieldsUpdated) { + Add-CIPPAzDataTableEntity @DeviceTable -Entity @{ + PartitionKey = $Customer.CustomerId + RowKey = $device.AzureADDeviceId + RawDevice = "$($ParsedDevice | ConvertTo-Json -Depth 100 -Compress)" + } -Force + + $ParsedDevices.add($ParsedDevice) + } } # Enable Device Updates Subscription if needed. diff --git a/Modules/CippExtensions/Public/Sherweb/Invoke-SherwebMigration.ps1 b/Modules/CippExtensions/Public/Sherweb/Invoke-SherwebMigration.ps1 index 89c3d749d3175..3d5dd1cd2a3ad 100644 --- a/Modules/CippExtensions/Public/Sherweb/Invoke-SherwebMigration.ps1 +++ b/Modules/CippExtensions/Public/Sherweb/Invoke-SherwebMigration.ps1 @@ -13,6 +13,11 @@ function Invoke-SherwebMigration { return } + if ($Config.AutoMigrations -ne $true) { + Write-Information "Sherweb automated migration is disabled, skipping migration check for $TenantFilter" + return + } + # Get licenses within the transfer window (renewing within 7 days) $Licenses = Get-CIPPLicenseOverview -TenantFilter $TenantFilter | Where-Object { $null -ne $_.TermInfo -and ($_.TermInfo | Where-Object { $_.DaysUntilRenew -le 7 -and $_.DaysUntilRenew -ge 0 }) @@ -43,7 +48,14 @@ function Invoke-SherwebMigration { if (-not $LicencesToMigrate) { return } - switch -wildcard ($Config.migrationMethods) { + # migrationMethods and migrateToLicense are autoComplete fields, stored as { label, value } + # objects (older configs may hold a bare string). Match on the value only: wildcard-matching + # the whole object stringifies the label too, and every method label contains 'cancellation + # window', so notify-only and buy-and-notify would both wrongly trigger the cancel branch. + $MigrationMethod = if ($null -ne $Config.migrationMethods.value) { $Config.migrationMethods.value } else { $Config.migrationMethods } + $MigrateToLicense = if ($null -ne $Config.migrateToLicense.value) { $Config.migrateToLicense.value } else { $Config.migrateToLicense } + + switch -wildcard ($MigrationMethod) { '*notify*' { $Subject = "Sherweb Migration: $($TenantFilter) - $($LicencesToMigrate.Count) licenses to migrate" $HTMLContent = New-CIPPAlertTemplate -Data $LicencesToMigrate -Format 'html' -InputObject 'sherwebmig' @@ -55,7 +67,7 @@ function Invoke-SherwebMigration { '*buy*' { try { foreach ($MigLicense in $LicencesToMigrate) { - $PotentialLicense = Get-SherwebCatalog -TenantFilter $TenantFilter | Where-Object { $_.microsoftSkuId -eq $MigLicense.SkuId -and $_.sku -like "*$($Config.migrateToLicense)" } | Select-Object -First 1 + $PotentialLicense = Get-SherwebCatalog -TenantFilter $TenantFilter | Where-Object { $_.microsoftSkuId -eq $MigLicense.SkuId -and $_.sku -like "*$MigrateToLicense" } | Select-Object -First 1 if (-not $PotentialLicense) { throw "Cannot buy new license: no matching license found in catalog for SKU $($MigLicense.SkuId)" } diff --git a/Modules/DNSHealth/1.1.8/DNSHealth.psd1 b/Modules/DNSHealth/1.1.10/DNSHealth.psd1 similarity index 89% rename from Modules/DNSHealth/1.1.8/DNSHealth.psd1 rename to Modules/DNSHealth/1.1.10/DNSHealth.psd1 index a9d8c70eac4bc..033942650dc6d 100644 --- a/Modules/DNSHealth/1.1.8/DNSHealth.psd1 +++ b/Modules/DNSHealth/1.1.10/DNSHealth.psd1 @@ -12,7 +12,7 @@ RootModule = 'DNSHealth.psm1' # Version number of this module. - ModuleVersion = '1.1.8' + ModuleVersion = '1.1.10' # Supported PSEditions # CompatiblePSEditions = @() @@ -53,8 +53,14 @@ # Modules that must be imported into the global environment prior to importing this module #RequiredModules = @('') - # Assemblies that must be loaded prior to importing this module - # RequiredAssemblies = @() + # Assemblies that must be loaded prior to importing this module. + # Preloads the precompiled SevenTinyRsa.dll (Source/SevenTinyRsa/) so + # Get-RsaPublicKeyInfo finds [SevenTiny.Bantina.Security.RSACommon] + # already registered — its existing Add-Type guard then short-circuits + # via the `-as [type]` check. Required for hosts where runtime + # `Add-Type -Language CSharp` fails (e.g. embedded-PowerShell hosts + # with no $PSHOME/ref reference-assemblies directory). + RequiredAssemblies = @('SevenTinyRsa.dll') # Script files (.ps1) that are run in the caller's environment prior to importing this module. ScriptsToProcess = @() @@ -78,7 +84,7 @@ #VariablesToExport = '*' # Aliases to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no aliases to export. - #AliasesToExport = '*' + AliasesToExport = @() # DSC resources to export from this module # DscResourcesToExport = @() diff --git a/Modules/DNSHealth/1.1.8/DNSHealth.psm1 b/Modules/DNSHealth/1.1.10/DNSHealth.psm1 similarity index 99% rename from Modules/DNSHealth/1.1.8/DNSHealth.psm1 rename to Modules/DNSHealth/1.1.10/DNSHealth.psm1 index 113996bb69e9d..47dd5f93e5454 100644 --- a/Modules/DNSHealth/1.1.8/DNSHealth.psm1 +++ b/Modules/DNSHealth/1.1.10/DNSHealth.psm1 @@ -2069,7 +2069,14 @@ function Read-SpfRecord { # Look for expected include record and report pass or fail if ($ExpectedInclude -ne '') { - if ($RecordList.Domain -notcontains $ExpectedInclude) { + $SpfMatch = $SpfResults.MailProvider.SpfMatch + $RegexMatchedDomain = if ($SpfMatch) { + $RecordList.Domain | Where-Object { $_ -match $SpfMatch } | Select-Object -First 1 + } + + if ($RegexMatchedDomain) { + $ValidationPasses.Add('The expected mail provider entry is part of the record.') | Out-Null + } elseif ($RecordList.Domain -notcontains $ExpectedInclude) { $ExpectedIncludeSpf = Read-SpfRecord -Domain $ExpectedInclude -Level ExpectedInclude $ExpectedIPCount = $ExpectedIncludeSpf.IPAddresses | Measure-Object | Select-Object -ExpandProperty Count $FoundIPCount = Compare-Object $IPAddresses $ExpectedIncludeSpf.IPAddresses -IncludeEqual | Where-Object -Property SideIndicator -EQ '==' | Measure-Object | Select-Object -ExpandProperty Count @@ -2228,7 +2235,7 @@ function Read-SpfRecord { # Output SpfResults object $SpfResults } -#EndRegion './Public/Records/Read-SPFRecord.ps1' 577 +#EndRegion './Public/Records/Read-SPFRecord.ps1' 584 #Region './Public/Records/Read-TlsRptRecord.ps1' -1 function Read-TlsRptRecord { @@ -3036,3 +3043,4 @@ function Test-MtaSts { $MtaSts } #EndRegion './Public/Tests/Test-MtaSts.ps1' 58 + diff --git a/Modules/DNSHealth/1.1.8/MailProviders/AppRiver.json b/Modules/DNSHealth/1.1.10/MailProviders/AppRiver.json similarity index 100% rename from Modules/DNSHealth/1.1.8/MailProviders/AppRiver.json rename to Modules/DNSHealth/1.1.10/MailProviders/AppRiver.json diff --git a/Modules/DNSHealth/1.1.8/MailProviders/BarracudaESS.json b/Modules/DNSHealth/1.1.10/MailProviders/BarracudaESS.json similarity index 100% rename from Modules/DNSHealth/1.1.8/MailProviders/BarracudaESS.json rename to Modules/DNSHealth/1.1.10/MailProviders/BarracudaESS.json diff --git a/Modules/DNSHealth/1.1.8/MailProviders/Google.json b/Modules/DNSHealth/1.1.10/MailProviders/Google.json similarity index 100% rename from Modules/DNSHealth/1.1.8/MailProviders/Google.json rename to Modules/DNSHealth/1.1.10/MailProviders/Google.json diff --git a/Modules/DNSHealth/1.1.8/MailProviders/HornetSecurity.json b/Modules/DNSHealth/1.1.10/MailProviders/HornetSecurity.json similarity index 100% rename from Modules/DNSHealth/1.1.8/MailProviders/HornetSecurity.json rename to Modules/DNSHealth/1.1.10/MailProviders/HornetSecurity.json diff --git a/Modules/DNSHealth/1.1.8/MailProviders/Intermedia.json b/Modules/DNSHealth/1.1.10/MailProviders/Intermedia.json similarity index 100% rename from Modules/DNSHealth/1.1.8/MailProviders/Intermedia.json rename to Modules/DNSHealth/1.1.10/MailProviders/Intermedia.json diff --git a/Modules/DNSHealth/1.1.8/MailProviders/Microsoft365.json b/Modules/DNSHealth/1.1.10/MailProviders/Microsoft365.json similarity index 100% rename from Modules/DNSHealth/1.1.8/MailProviders/Microsoft365.json rename to Modules/DNSHealth/1.1.10/MailProviders/Microsoft365.json diff --git a/Modules/DNSHealth/1.1.8/MailProviders/Mimecast.json b/Modules/DNSHealth/1.1.10/MailProviders/Mimecast.json similarity index 84% rename from Modules/DNSHealth/1.1.8/MailProviders/Mimecast.json rename to Modules/DNSHealth/1.1.10/MailProviders/Mimecast.json index 1ab6820344b00..79553389bfc22 100644 --- a/Modules/DNSHealth/1.1.8/MailProviders/Mimecast.json +++ b/Modules/DNSHealth/1.1.10/MailProviders/Mimecast.json @@ -1,6 +1,6 @@ { "Name": "Mimecast", - "MxMatch": "(?[a-z]{2})-smtp-inbound-[0-9].mimecast.com", + "MxMatch": "^(?[a-z]{2,3})-smtp-inbound-[0-9]\\.mimecast\\.(?:com|co\\.za)", "SpfInclude": "{0}._netblocks.mimecast.com", "SpfReplace": [ "Prefix" ], "Selectors": [], diff --git a/Modules/DNSHealth/1.1.10/MailProviders/MimecastOffshore.json b/Modules/DNSHealth/1.1.10/MailProviders/MimecastOffshore.json new file mode 100644 index 0000000000000..371d416997ca8 --- /dev/null +++ b/Modules/DNSHealth/1.1.10/MailProviders/MimecastOffshore.json @@ -0,0 +1,10 @@ +{ + "Name": "Mimecast Offshore", + "MxMatch": "^(?[a-z]{2,3})-smtp-inbound-[0-9]\\.mimecast-offshore\\.com", + "SpfInclude": "", + "SpfReplace": [], + "Selectors": [], + "_MxComment": "https://community.mimecast.com/s/article/Connect-Application-Modifying-Your-MX-Records-673313100", + "_SpfComment": "Offshore (Jersey) region netblock include is not publicly documented; leave empty so no incorrect SPF include is asserted.", + "_DkimComment": "https://community.mimecast.com/s/article/DNS-Authentication-Configuration-Guide-345109074" +} diff --git a/Modules/DNSHealth/1.1.8/MailProviders/Null.json b/Modules/DNSHealth/1.1.10/MailProviders/Null.json similarity index 100% rename from Modules/DNSHealth/1.1.8/MailProviders/Null.json rename to Modules/DNSHealth/1.1.10/MailProviders/Null.json diff --git a/Modules/DNSHealth/1.1.8/MailProviders/Proofpoint.json b/Modules/DNSHealth/1.1.10/MailProviders/Proofpoint.json similarity index 100% rename from Modules/DNSHealth/1.1.8/MailProviders/Proofpoint.json rename to Modules/DNSHealth/1.1.10/MailProviders/Proofpoint.json diff --git a/Modules/DNSHealth/1.1.8/MailProviders/Reflexion.json b/Modules/DNSHealth/1.1.10/MailProviders/Reflexion.json similarity index 100% rename from Modules/DNSHealth/1.1.8/MailProviders/Reflexion.json rename to Modules/DNSHealth/1.1.10/MailProviders/Reflexion.json diff --git a/Modules/DNSHealth/1.1.8/MailProviders/Sophos.json b/Modules/DNSHealth/1.1.10/MailProviders/Sophos.json similarity index 68% rename from Modules/DNSHealth/1.1.8/MailProviders/Sophos.json rename to Modules/DNSHealth/1.1.10/MailProviders/Sophos.json index e246ef694a116..491bd2bcc925f 100644 --- a/Modules/DNSHealth/1.1.8/MailProviders/Sophos.json +++ b/Modules/DNSHealth/1.1.10/MailProviders/Sophos.json @@ -1,8 +1,9 @@ { "Name": "Sophos", "MxMatch": "mx-[0-9]{2}-(?(us|eu))-(?(central|east|west))-(?([0-9])).prod.hydra.sophos.com", + "SpfMatch": "^_spf[._][a-z0-9]+.*\\.sophos\\.com$", "SpfInclude": "_spf.prod.hydra.sophos.com", "_MxComment": "https://docs.sophos.com/central/Customer/help/en-us/central/Customer/learningContents/Configure365.html", - "_SpfComment": "https://docs.sophos.com/central/Customer/help/en-us/central/Customer/tasks/updatingspf.html", + "_SpfComment": "https://docs.sophos.com/central/customer/help/en-us/ManageYourProducts/EmailSecurity/EmailDomainInfo/index.html#emailspfrecords", "_DkimComment": "https://docs.sophos.com/central/Customer/help/en-us/central/Customer/common/learningContents/DkimKeys.html" } \ No newline at end of file diff --git a/Modules/DNSHealth/1.1.8/MailProviders/SpamTitan.json b/Modules/DNSHealth/1.1.10/MailProviders/SpamTitan.json similarity index 100% rename from Modules/DNSHealth/1.1.8/MailProviders/SpamTitan.json rename to Modules/DNSHealth/1.1.10/MailProviders/SpamTitan.json diff --git a/Modules/DNSHealth/1.1.8/MailProviders/SymantecCloud.json b/Modules/DNSHealth/1.1.10/MailProviders/SymantecCloud.json similarity index 100% rename from Modules/DNSHealth/1.1.8/MailProviders/SymantecCloud.json rename to Modules/DNSHealth/1.1.10/MailProviders/SymantecCloud.json diff --git a/Modules/DNSHealth/1.1.8/MailProviders/_template.json b/Modules/DNSHealth/1.1.10/MailProviders/_template.json similarity index 100% rename from Modules/DNSHealth/1.1.8/MailProviders/_template.json rename to Modules/DNSHealth/1.1.10/MailProviders/_template.json diff --git a/Modules/DNSHealth/1.1.8/PSGetModuleInfo.xml b/Modules/DNSHealth/1.1.10/PSGetModuleInfo.xml similarity index 71% rename from Modules/DNSHealth/1.1.8/PSGetModuleInfo.xml rename to Modules/DNSHealth/1.1.10/PSGetModuleInfo.xml index a5693b78886a9..c9b3a0ec124d6 100644 --- a/Modules/DNSHealth/1.1.8/PSGetModuleInfo.xml +++ b/Modules/DNSHealth/1.1.10/PSGetModuleInfo.xml @@ -7,20 +7,34 @@ DNSHealth - 1.1.8 + 1.1.10 Module CIPP DNS Health Check Module John Duprey johnduprey 2023 John Duprey -
2026-05-08T15:46:09-04:00
- +
2026-08-24T16:52:31+08:00
+ +
2026-08-25T00:59:14.3697426+08:00
+ + + + Microsoft.PowerShell.Commands.DisplayHintType + System.Enum + System.ValueType + System.Object + + DateTime + 2 + + +
https://github.com/johnduprey/DNSHealth - - + + System.Object[] System.Array System.Object @@ -29,23 +43,23 @@ PSModule - - + + System.Collections.Hashtable System.Object - Workflow - - + Cmdlet + + - Function - - + Command + + Read-DmarcPolicy Read-MtaStsPolicy @@ -69,17 +83,9 @@ - RoleCapability - - - - DscResource - - - - Command - - + Function + + Read-DmarcPolicy Read-MtaStsPolicy @@ -103,22 +109,30 @@ - Cmdlet - + DscResource + + + + RoleCapability + + + + Workflow + - - + + https://www.powershellgallery.com/api/v2 PSGallery NuGet - - + + System.Management.Automation.PSCustomObject System.Object @@ -129,24 +143,24 @@ True True 0 - 495 - 32431 - 5/8/2026 3:46:09 PM -04:00 - 5/8/2026 3:46:09 PM -04:00 - 5/8/2026 3:46:09 PM -04:00 + 606 + 35781 + 24/08/2026 4:52:31 PM +08:00 + 24/08/2026 4:52:31 PM +08:00 + 24/08/2026 4:52:31 PM +08:00 PSModule PSFunction_Read-DmarcPolicy PSCommand_Read-DmarcPolicy PSFunction_Read-MtaStsPolicy PSCommand_Read-MtaStsPolicy PSFunction_Add-MailProvider PSCommand_Add-MailProvider PSFunction_Get-MailProvider PSCommand_Get-MailProvider PSFunction_Read-AutoDiscoverRecord PSCommand_Read-AutoDiscoverRecord PSFunction_Read-DkimRecord PSCommand_Read-DkimRecord PSFunction_Read-MtaStsRecord PSCommand_Read-MtaStsRecord PSFunction_Read-MXRecord PSCommand_Read-MXRecord PSFunction_Read-NSRecord PSCommand_Read-NSRecord PSFunction_Read-SPFRecord PSCommand_Read-SPFRecord PSFunction_Read-TlsRptRecord PSCommand_Read-TlsRptRecord PSFunction_Read-WhoisRecord PSCommand_Read-WhoisRecord PSFunction_Remove-MailProvider PSCommand_Remove-MailProvider PSFunction_Resolve-DnsHttpsQuery PSCommand_Resolve-DnsHttpsQuery PSFunction_Set-DnsResolver PSCommand_Set-DnsResolver PSFunction_Test-DNSSEC PSCommand_Test-DNSSEC PSFunction_Test-HttpsCertificate PSCommand_Test-HttpsCertificate PSFunction_Test-MtaSts PSCommand_Test-MtaSts PSIncludes_Function False - 2026-05-08T15:46:09Z - 1.1.8 + 2026-08-24T16:52:31Z + 1.1.10 John Duprey false Module - DNSHealth.nuspec|MailProviders\SymantecCloud.json|MailProviders\Microsoft365.json|MailProviders\Sophos.json|DNSHealth.psd1|MailProviders\Intermedia.json|MailProviders\SpamTitan.json|MailProviders\AppRiver.json|DNSHealth.psm1|MailProviders\Reflexion.json|MailProviders\_template.json|MailProviders\BarracudaESS.json|MailProviders\Null.json|MailProviders\HornetSecurity.json|MailProviders\Google.json|MailProviders\Proofpoint.json|MailProviders\Mimecast.json + DNSHealth.nuspec|MailProviders\Mimecast.json|MailProviders\BarracudaESS.json|MailProviders\SpamTitan.json|DNSHealth.psd1|MailProviders\AppRiver.json|MailProviders\Null.json|MailProviders\HornetSecurity.json|MailProviders\MimecastOffshore.json|MailProviders\Sophos.json|MailProviders\_template.json|SevenTinyRsa.dll|MailProviders\Proofpoint.json|MailProviders\Microsoft365.json|MailProviders\Reflexion.json|DNSHealth.psm1|MailProviders\Intermedia.json|MailProviders\SymantecCloud.json|MailProviders\Google.json a300d2b0-d468-46d1-88a3-e442a76b655b 7.0
- /Users/johnduprey/GitHub/CIPP Workspace/CIPP-API/Modules/DNSHealth/1.1.8 + C:\Users\Zac\Documents\PowerShell\Modules\DNSHealth\1.1.10 diff --git a/Modules/DNSHealth/1.1.10/SevenTinyRsa.dll b/Modules/DNSHealth/1.1.10/SevenTinyRsa.dll new file mode 100644 index 0000000000000000000000000000000000000000..1770c9c9f3e7e8a0a55e02b03a7ed2c77652c6a9 GIT binary patch literal 5120 zcmeHLO>7&-6@I%b{)qaqmy#v_#5H5Zj%vwUQluy`juVk0Wh=I9MU))dO<^y|k+jWn zm)Tt@rh&9}nxyR^MvcZr5g0wRK#`_B7)}BhX@eq{q5obL=HYug1!{W!YY=#A42h6*H_@{&+D~wJS{P>WbXga6MZfIw~o& zX@B3}nxnl(yJH&_}Ni;U2>^fs1If;AKB<4)FLzy8sHDH-*kV$4&Wn?cNYM zgmxBwk8@^%=-a#yceb;B7PG9(e(1Q?!ZH?Ed8f#@}dnKlf0$>=OD?kkF`rA-j!T13IV$m@#6W0NUBFYYF~ zhQK9({^w*zyp7&QXMELNn_lPzx93+7+6KFbB9R8PR~|$T5qA?vN65weL^}Jr!nO*g zt34LKNR(_3+lW81cW4`cXMCVX0O8)Ajz2Lt4e#1yV}wX>5ZMOz3w(y-O-IU|j+Bj# z?hzgMP{YDOXRCux63HJ>rN)STJ#BqGf%cfp$Bp<2^t27_2Eqr9Hjuz=jTrGIIN0u& zs!wgZx~E?aT__it=SN#mSt;77hMwLk0JZ(;ZD7>Sp2!|GVs8fz2fg8847dZrA49{zkk6?d`w(9? z{IjUgbzBkfyrKAXKdvjle$s;X#1$I$^{RZyP%aso+_$eUB6sw44n;%Z%S!Mv zM}qw)BjNs&o#D_WW90As`*Ouca#CXj^7Xu$(&Ab&o=jvQV2zrfFJsVwFA?=(&-P+Z z3=}=bu$EkIF&Of<$-qL9hQaggKX7PaI*9H$vteq$FFDXeV zIZOzJ5ZjIOT!o1C2yh;xCqiQ>9icA?eZI- zuSlFO3Hq#{lEB9V|F-b(P32WNLS=dve!efi3=e++jnHX@BVl3lKD`P*3o@ri6h7kX z=oO@!0{@=ieg6g0WeDl6PpdTvx=`Hf)QK|zuKo>!?pnK^M=%exx&;*|87b&Y0=^eyy z3jA;7v-BiMQiZ-wb;SUE3G_)?R;u)S`Vcj}pFU59q)`W5A&q+IJD@udzeWS}GtePw zgBFVe^Z@2lqe+T`9uasEw2V2bND|?xhIO-rT)Kg$t3+)V{51l&(XQj(`gS-^?+ML% z>|MU#;7Q!(?P<$Pj?kGiMNjvPa@KM5`m|+u^Yt1l8t2);#3;=%y|MtiL|U*u_u!0O zSuxo|^x&*xtm+<{uGUOeWfu2iTY2W`hUq>;bHyxWMn^|dlbJ*!J5|VKlBq&I5zmh2 z$ELE$(NuaeKU&CTQ@N>pJRdKNXA{|6ZX}h;jE`p1>8X)?a*B#|*JD*}`ZyKYDzoMd zt3K!IRHEs;;nr+dFPV(yRxHn`vMGa^mBYGK0o3T%(9j9pTwy#j^1CsbbQnUXNxNDz zOy(S77IOepvK}^mX$7i0E3GUo@d4Jbtn0FB$*j*CUMoDWJ4?))!YPG4Wjjx7w4cHl zCz#`+J{y(O)}rlHMe%g=W347_YtdL*L6Ga5%(2CyzR0}#9OlGbbM7Z5jOUoCpA%e* zzM09agV`*5YaN>k?m)NdYl=oK1@0Lo!!*2BEtX2Ij}pPTSvuuE zT&cEFGL7;PR&U6yQ>;}?lV(`ecDR=5)rRBS{@J3*%DfhQp&_U$xLL-Ym|WH!${CjK z)cNvdT<}o5RpxjQw6bSAO(%InU$Sf$%inE6jVv|4e#|K{XVoY(x3L_M2bMoX?wjWe z&R>0pnOVaO^Jr#uz7jB+OV}H>Z{ zOng%sx`{0*_Gn|}Vi#cQRt+S`>pI&kWiyW=E3Y`1A#KvB*F1iLt}WNsHj$Rov1cq@ zYubtD1yR?@U%xZ`&-2G#`Q_`s%P#akPHizs3M(;^0$@~?i{1U9uAPDC!Du!V2!wa? zuUd#^)Ix}4DSAr%LV%>5fo|SmXMocvgM$#R0Inbq^a+y8y8;N~bsNnnLEly_1Vakf zgs(k(=F94DA`d7*bu&ChGu`kn?+idEHJ)~#;V+tbx$iM#cg(g5=gO?cm&E+CV?X6e zu#-hz2PN979V^UF+78RsYQv31d2n@Hi^D;8@9nM29}lKpKZf}W^Byr+s1kLyE=`<@ zB?@6zF)U_ZNZ>?)56)x~X+jt(r88_SHC`_1W2NNSct+RL$;HL7L^?H^%&>SuABk7e zY_yCgGJnA%R(^E9vx%P?E#TK0=W7mqm-8{sZEVeRxUV^b#Pg;(qZ<}g-7>1c#Qx&i zTYKPRbG$3qzVG?N&wtP*Nm5{=zyA)A#90YP#0%^D`=>FKYXi>h_-}`k6F6Im7Zpc1 zj{_r}pdy_CEzlgeX}pz>L7oPk@_%*Fn{DrZ-?8y9F5-b_?1hLyX1#@6EC^Y$sXnE#)_YyJ;`PkHeF5BI;Wz`p_I CQzm2p literal 0 HcmV?d00001 diff --git a/Shared/CIPPSharp/CIPPRestClient.cs b/Shared/CIPPSharp/CIPPRestClient.cs index b4fa13e6d5326..f0cd53d979e00 100644 --- a/Shared/CIPPSharp/CIPPRestClient.cs +++ b/Shared/CIPPSharp/CIPPRestClient.cs @@ -37,6 +37,45 @@ public sealed class HttpResult public Dictionary ResponseHeaders { get; init; } = new(); } + // ===================================================================== + // CIPPConcurrentRequest / CIPPConcurrentResult + // ===================================================================== + // One PowerShell call, many async HTTP requests. PowerShell builds the + // request list (and acquires any auth token once, passing it in Headers), + // then calls CIPPRestClient.SendConcurrent — the .NET side fans the requests + // out concurrently, bounded by a semaphore, with Retry-After / backoff on + // 429 and 5xx. This keeps concurrency in .NET (robust async) rather than + // ForEach-Object -Parallel runspaces in the PowerShell worker. Per-hostname + // connection caps (see the pool design above) still apply, so a burst to one + // host cannot exceed that host's connection budget. + // ===================================================================== + public sealed class CIPPConcurrentRequest + { + public string Uri { get; set; } = string.Empty; + public string Method { get; set; } = "GET"; + public string? Body { get; set; } + public Dictionary? Headers { get; set; } + public string? ContentType { get; set; } + public int TimeoutSec { get; set; } = 100; + public int MaximumRedirection { get; set; } = -1; + } + + /// + /// Per-request outcome, returned in the same order as the input requests. + /// A failed request never aborts the batch: transport failures land in + /// , HTTP responses (including 4xx/5xx after retries) land + /// in . Index maps back to the caller's request array. + /// + public sealed class CIPPConcurrentResult + { + public int Index { get; init; } + public bool IsSuccess { get; init; } + public int StatusCode { get; init; } + public HttpResult? Result { get; init; } + public string? Error { get; init; } + public int Attempts { get; init; } + } + // ===================================================================== // CIPPResponseHeaders / CIPPHttpResponse / CIPPHttpRequestException // ===================================================================== @@ -141,10 +180,11 @@ public CIPPHttpRequestException(string message, int statusCode, Dictionary + /// SharePoint / OneDrive client — dedicated lane for SPO admin CSOM (ProcessQuery) and + /// SPO REST (_api) against *.sharepoint.com, which have no server-side $batch. Concurrent + /// per-site writes (Set-CIPPSPOSiteBulk via SendConcurrent) fan out here. HTTP/2 is disabled + /// so MaxConnectionsPerServer is a true concurrency ceiling (5) rather than a connection count + /// that H2 stream-multiplexing could exceed. Measured on a 526-site tenant, 5 in flight throttled + /// far less than 8-10 (43 vs 56 x HTTP 429) and finished sooner — SPO's CSOM-admin throttle is a + /// sustained-rate limit, so a lower ceiling plus the once-per-24h sweep guard is the throttle-safe + /// combination. Cap: 5 connections. + /// + private static HttpClient BuildSpoClient() => new HttpClient(new SocketsHttpHandler + { + AutomaticDecompression = DecompressionMethods.All, + PooledConnectionLifetime = TimeSpan.FromMinutes(30), + PooledConnectionIdleTimeout = TimeSpan.FromMinutes(2), + EnableMultipleHttp2Connections = false, + AllowAutoRedirect = true, + MaxAutomaticRedirections = 10, + MaxConnectionsPerServer = 5, + }) { Timeout = Timeout.InfiniteTimeSpan }; + /// /// DNS client — dedicated lane for DoH (DNS-over-HTTPS) providers. /// Covers dns.google.com and cloudflare-dns.com. These services @@ -405,6 +467,7 @@ _loginClient is not null && _complianceClient is not null && _partnerCenterClient is not null && _adminPlaneClient is not null && + _spoClient is not null && _dnsClient is not null && _defaultClient is not null) return; @@ -421,6 +484,7 @@ _dnsClient is not null && _complianceClient = BuildComplianceClient(); _partnerCenterClient = BuildPartnerCenterClient(); _adminPlaneClient = BuildAdminPlaneClient(); + _spoClient = BuildSpoClient(); _dnsClient = BuildDnsClient(); _defaultClient = BuildDefaultClient(); } @@ -506,6 +570,12 @@ var h when h.EndsWith(".partnercenter.microsoft.com", // Rule 6 — Microsoft admin/reporting/security lanes var h when IsAdminPlaneHost(h) => (_adminPlaneClient!, "AdminPlane", host), + // Rule 6b — SharePoint / OneDrive (CSOM ProcessQuery + _api REST). Covers the + // tenant, -admin and -my hosts. No server-side $batch, so concurrent per-site + // requests fan out here, capped at 10 connections. + var h when h.EndsWith(".sharepoint.com", + StringComparison.OrdinalIgnoreCase) => (_spoClient!, "SPO", host), + // Rule 7 — DNS-over-HTTPS providers (low connection cap) var h when h.Equals("dns.google.com", StringComparison.OrdinalIgnoreCase) => (_dnsClient!, "DNS", host), @@ -800,6 +870,112 @@ public static async Task SendAsync( } } + // ----------------------------------------------------------------- + // Concurrent fan-out — one PowerShell call, many async requests + // ----------------------------------------------------------------- + // PowerShell passes a list of requests (each already carrying its auth + // header) and gets back one result per request, in order. Concurrency is + // bounded by maxConcurrency here AND by each destination's + // MaxConnectionsPerServer cap, whichever is tighter. 429/5xx are retried + // with Retry-After (when present) or exponential backoff with jitter. A + // single request's failure is captured, never thrown, so the batch always + // completes and the caller can act on partial success. + // + // Synchronous shim for PowerShell (cannot await Tasks natively). Safe here + // for the same reason Send() is — no SynchronizationContext to deadlock on. + // ----------------------------------------------------------------- + public static CIPPConcurrentResult[] SendConcurrent( + IEnumerable requests, + int maxConcurrency = 8, + int maxRetries = 3) + { + return SendConcurrentAsync(requests, maxConcurrency, maxRetries) + .GetAwaiter().GetResult(); + } + + public static async Task SendConcurrentAsync( + IEnumerable requests, + int maxConcurrency = 8, + int maxRetries = 3) + { + var list = requests is null ? new List() : requests.ToList(); + if (list.Count == 0) return Array.Empty(); + if (maxConcurrency < 1) maxConcurrency = 1; + if (maxRetries < 0) maxRetries = 0; + + using var gate = new SemaphoreSlim(maxConcurrency, maxConcurrency); + var tasks = new Task[list.Count]; + for (int i = 0; i < list.Count; i++) + { + int index = i; + var req = list[i]; + tasks[i] = Task.Run(async () => + { + await gate.WaitAsync().ConfigureAwait(false); + try { return await SendOneWithRetryAsync(index, req, maxRetries).ConfigureAwait(false); } + finally { gate.Release(); } + }); + } + return await Task.WhenAll(tasks).ConfigureAwait(false); + } + + private static async Task SendOneWithRetryAsync( + int index, CIPPConcurrentRequest req, int maxRetries) + { + var attempt = 0; + while (true) + { + attempt++; + try + { + // skipErrorCheck: 429/5xx must come back as results (not thrown) so we can + // decide whether to retry; the caller inspects StatusCode/Content itself. + var res = await SendAsync(req.Uri, req.Method, req.Body, req.Headers, + req.ContentType, skipErrorCheck: true, + timeoutSec: req.TimeoutSec, + maximumRedirection: req.MaximumRedirection).ConfigureAwait(false); + + var retryable = res.StatusCode == 429 || (res.StatusCode >= 500 && res.StatusCode <= 599); + if (retryable && attempt <= maxRetries) + { + await Task.Delay(RetryDelay(res, attempt)).ConfigureAwait(false); + continue; + } + return new CIPPConcurrentResult + { + Index = index, IsSuccess = res.IsSuccess, StatusCode = res.StatusCode, + Result = res, Attempts = attempt, + }; + } + catch (Exception ex) + { + if (attempt <= maxRetries) + { + await Task.Delay(RetryDelay(null, attempt)).ConfigureAwait(false); + continue; + } + return new CIPPConcurrentResult + { + Index = index, IsSuccess = false, StatusCode = 0, + Error = ex.Message, Attempts = attempt, + }; + } + } + } + + private static TimeSpan RetryDelay(HttpResult? res, int attempt) + { + // Honour a sane Retry-After (seconds) when the server sends one. + if (res is not null && + res.ResponseHeaders.TryGetValue("Retry-After", out var ra) && + ra.Length > 0 && int.TryParse(ra[0], out var secs) && secs > 0 && secs <= 300) + return TimeSpan.FromSeconds(secs); + + // Otherwise exponential backoff (1s, 2s, 4s, capped 8s) with jitter. + var baseMs = Math.Min(8000, 1000 * (int)Math.Pow(2, attempt - 1)); + return TimeSpan.FromMilliseconds(baseMs + Random.Shared.Next(0, 1000)); + } + // ----------------------------------------------------------------- // Content decoding // ----------------------------------------------------------------- diff --git a/Shared/CIPPSharp/bin/CIPPSharp.dll b/Shared/CIPPSharp/bin/CIPPSharp.dll index f66102fb695bf864c453fa3b9eb897f3457efaca..4b71bbc8b79b04afe1265b688d8ecfb8e8788c38 100644 GIT binary patch literal 71168 zcmdqKd3+RA)<1l!s=Ip4Qr$^+XCom=ha%nC00l$@1jPjv6f}S%;7&vf(%=?41VKSX zkpb6XRNNPwQOA8>P{$D+868(ZP#pJd#8K3V@AsU0JE^GS`2L>f{r&Owhn#!1d+xd0 zxwoor6$eebNEkv05B`4mL5Ta1(r+}wUj|(e=T|s!t?znpEx^HHMiY4 zp?%iLRmaRaSX8G;~Mkwg0;%@#C?RApc&%Yf1Gnp zuC#5Ux+WxqsM3E_9i{h;@A(T($uJAFRrt}y(CjO(iW&Z&Vt zv#~wXehe7w8+_!779w^1M#KBY_T%O_P$XXkeC9SN`ib7&u566%N9~Fq`KAl6C|oAQ z`_~E4Hz%w7D$q~whzk*{N1CAYaNRCJsvB8i>z*ugg@`sAVhk*z9Lrb$SQgaH#vx|9 z$u1>Dwqi1L%D_m+Z8Sgll;33NQ~<4y)yM1qR(0~C@by&#r%btink&204+^b{-J9E~ zBz8Ud;1fr4y@gfO4j<+wF35*V$(SrY7!k>N7+7U12sC)=ic+EO7~xJ8Ok9(UOLsyM zEjiCidIWNMgiAfUKRJpPsa9!?N^4b`RB4?`2T=OAo|dC*XgSKId$W{D&-Y|0lb-L* zQYJm$%yK4f*BenMgWDC8huU?-rQn#uR|2Z$A(JNiBU|@0)w)!M*+Gz7H$B6)$$SSD zYBF>N0!@#%(SG2Q6DC6^Mf@f^&3tmo>>%hg5I=4=GM}6@I|w>W0Ni`*^F{EDepMrj z+b`|YljQ2p^d$SpJ*l*N9d!^odiuTBPp8Gj?sd}{f;0YfepBxMFu#W(!1vB?%KvNn zjtu^{zUyh3-Jwh^GgPI+R61Oxd#H4TO7~RhNJ^>AbTLj&1JN`2$tIeWOk(nrMVkC% zktRP`q{&Yf^?YBJEb96GEL)@)y9M?T1<(gr1UVKwPn_XT0jgL)C72xqxhIC-LLwP1 zsZ^7z!<```h@5ETiP=F=MugK;L?F-14uUcw%uo@5JT*HA%7`#tMFjHP>>$Vy0TE;` z;Cctu#AN7<0*VMSn)y^SvxA^B20%s-Io=+DToHH?Q`}M>e zs>!bzw^X(NHf|~AP+fmb%%RHvnwUea@vCAEwaW~ z;FPS8Z5Z`Me93u5q(~sANVq$S$?;N#vEoM?cSk!Di10x(oo{wr2uv@tF%M~M_0u!& zV!G6evSyEvE~rMKK(u)m1=THJFkIC zvLRmAxeiFT`5DY-#v@0vizGJsJ(c|}u+BI@FcvZ+n!P{d(nfc*i+tT0^rcPHJ^=j9 z^%|zOE>02gvqg|fEJGYgA|+pcY^CVu3_w@f@QX;Pv~jd*lw^ZZ7pw2U*1_W(h|=nR zBZV3y!Bv+>4#?z&;ENXEH$4V|log z#HguIk43$)s2Pg}Qu|vTE5JoXgI2Jzu`vwT&}ahA7;MC&UMmo5>1PG)DX@|*ChhoC z>DuAMfr<%MYcya5R1t&L137{U^_iBB0-$Mm8+?{Id@Gt-DfMg3w33QH77e9NhS`vG zB5Z|XEkmuaEU%FS?(!NUZq8KlAZYn3tDI>->ny(&MimMH8ybUvGa5ZsIHmWsHAxBNUWDy!nobn+%I7R^r$w(_j}E20Hffo!os<-oW;g;pUdbR;wz{H9eXtCkO& z`BuJ_cj4?oPx<_#_UiuO2h;ftlx{te#xm>% zv{JCM1f6C&GboQwH=UVegvQV9(4(ImDW%Q2Uaz-bg-KZI%z{q3QjbYd$yEDjFxqc~ z%svK~eJt6~+i&erZUA+6FIBF$KiW&>>+R3>Q0c;)*@PTh$hoOk%1*r6OZRA_!)PSd z>-A;WKfZ#^BX(w1<|C@2nph!UI?vY|FB){S-WzW+`V|^_gO6uNp)hio=JVK1$Q<^k zgMQ~Ym?nK2<2;x-0U%G025A@#u!2_Tif9<4=R{J%hz$3HA!jyN7)){i1kqWW44JJ( zX3MkkWVW(^mFKi619>%9Tu#63qkd}O8CC9lX#j&j8aT?=LG$0rcTOTJhxn}g5*urz z>C6EgElAZy3ha{!Eeu$NJw+9&qF$FpLFW|8{?gX`NI`e3f`YgM#^yeiSQ>EVk`@{y zGmlJqGVPRjU9CGOY6hGPajjuzWA;ZZdp=P`k)lX(BxWxFVHHOsRxBD-u16wq=TxwV zPl3J_cTNL7Cz|MKP0O?rQx&ysRI8Pf0H5A!pH9|GknIdYN{8*l(2bPZXM#$0bP%ts zV<9Ew{&a<3dTNz9S+F|JrO1ik6&(Hua`ly60NI>qg;hSMW-$N09Ho4CF^9ZA%Bt{n z{1%EmzS@gmZThs(@0-i6QinR9gLDtvTlxXLSlS(f zQ>quy3Cl?4AY4FZb;qiDWQb48A!~^8oJnFq9)i)6y#%$Y*DstMx6w%G4j=T+17;go zO`_E_1!h{+R%lJM2JX~2DTwx7xE+)!G2u8hv-a+0iFsV8`V%wL3$s-~<5c7B-kBdmXa~armR(-yw>A)Vg zRUdD4E{DLvSc1zQrS4ooyn!(GJ0KP`g3AE6hypog#I9DOr<9O<*ur(m< z1BWM@>;cswSyaH2gvVDyIScTxAZ7{-iV;ZjksDt>N{WXBTt%}RM47@g=ev#$M3gmHKNs3%~`g>F*7Y~KQ@eLW18IyV3| zj0`Z#RJ>Wl8>kl5Sjzy*qw-?A@RQ7Gzt8X7h#YnPcx%`%UE|Hws3~ZDAJz=7s7Je? z4Xq3!hZ!{0qLD>5kJ&-6!Q_sqmz2)S1J)G3Pc9Ei%7ZlQGdphLdM4^jv)lZNMkW}+ zWYm)-f#tD%7!8K)r!jgfBzdWh%)g+9-H$imtOqB1b5GH{YFXZH^J_A68-#WM8Iujs zy39LZB`t3UX=gD>JyFvyU6kWeO60gSYq)Cxc)jZ#i~%_o&!n*!45SgeT_aIeP!7bt z<52ElPZ#IuT97P9(T*=74bhnCI3Lc))hW`x9o?xo)Tt>icYiSRF?p|dbdmFzex9V! zf$*ZT`6ZFkin5r49_S&gda{^yq=!)B@m7sSx7ovBC5urasBa2X20gaJA!a~sCy;^CL$(!nW zNmeu&@sySb88O~mhIL+-o!gPYxdR|?7&=Ns4Es(HJzHd%cdGp-FnulK)VP-1mJZ8f z$XSq{Yg)NQX4@!f8oGCp@zVe@cN2CGKx$uQBR$gcNLT!W2N{;fXAeeW(J1pZSHqg+ zo%2g};OMbIiCmP$W^H0*bpLIxL zW2mG&HiAy76Z71y`6X#S$eJXv5r|SYW@xHjT|4b59{NUxw`j8|cA!}c(Km8a+TfFo zr+NijTkb4H##=9#i|D9&P*I3nDZlCWU&%p2wf$%DywpNpEO4bSwkGPqwMptQJ$E%? zSYCCV(5=O~wW#SsqY`gTycL%pfHw9ML7-q+rlhWf#v04hM9Q!TSu1shD(+g#<7x4D z;;r>QGZe%%PF_GdzSrsK08?tM!B{i|#<{TYujg92!F`Dr(!;U5)HHwKil_&@oN(<0 zy{Wp0SMCK(pYtd@GzRHgQ@B`i9s|+fCu}A#Xq`fgP1q}V-Mc~d%a0}bYM;F5ka1v; z7<`=U54v_Ag}D-O`y%## z%|L@;`SKv4IPtT~meTZFo(2z0c`QFKRDM~`lW<2}F!^ysN*Z2xxdH4w4wiGu?2hf; zGp7Q{hCrQ#l8idbTW0y|0LN=AZgBZLNaPz3UE^^n~{s~&$c^dhDs@z4{o`I;&|D2nz3V^~lFmVN%NE zTGep#)-9NRKzZv@k7kkM_Bt{B2YCZ>_4e;jnRdg#&gJ=BF+r2ZuBRDSOR*@Z7~;fq}O zG8ewugx$qxcxYyI$h9MVjx$w9PuW;ct zE_|R1Z*t+gx$qG#e2fbp@4_d!@aZmmmJ2`0g=buNhYLU3gQ1_k$GLDk?e3W` z9WH#C3t#QR*SYXJT=;`7{3#dyybFKTg}>#(KXBn+y6{~tTr+$947l*93omowH7>lt zg%5S%qg?p@E__N4-h~+Bsjt?H>=B5M^z6V8w9PK&7=0ol4qv;bJ;sF%2F?^1_9hBN ze**~Wouw3;UIHHSIWHr@(;55kNE3r6XI?>?2l`c{^zg)fjSx>N9`V?(6N)H}#{zqz zSmzDUV84l^VH@^Lp6*y3));vy6>v6_x^HW-U#bJ8M+!bEwtT!EmDBb66j6JI+(+pm zE#|JxJ!3G$V$>;yIu!_ZFy83X?U7XD%oZ3Ag1r?f`TrKuP--NeWNZVLXQT@ZY~{BD z=Uct$8q;|jgyJE22Nc`NU?UxL-X)=C{{uuLodd)H^KyGWLo{Js zM5NF8hegQ~pSlmObaBo_2!wxuYZI{ze^`11+El<_F$^o9=u-oF`ovYh0+~jmZ-X1S zvoBrtaWx{opLN+QU4Bk(S=}ykSBB6;+?9byKz5}+6^r;~R|b7}=0MFUd(tm^ayv}< z-972!o~$nrXy*5*ef%)`K9G9<3N#Gvw6B;?NlYe1q-oe6Kq2i5tXM!IWcU#Dic^Uw z!XA(N{Xj8%X|CVbi<-YmoSspap@9-;*NEsYu0fuNsG{=`_D3*ccG38yhv3knNnm6d z0RvVggAp()atubm=$B(K0!C$y!N{q4=f@}_OX_;&6GDkEAC*&)RXKG=!04Z2Fakz( zj==~R@LxK`2pF|F1|wi3a|}knz$}tk7`an9MMdiEGY|x_RG40QES=Et=*4tE$K~Sy zP~0qxz#K+}WH188z#M}SFwl)sgAp)NIR+zOq;m{L`l%MVGIxleAuJ=zr)aXCaPt|p zUjt>N{SkZ?2wRqcM;;x-H6p_K94ZaCK59P!)iP~dPzUP|Fw%KS!@*vj9+Fai%(MTT z->e@bvpBel4)zc`iGcTw>UmB^ABh7)P&o(!h1nI%o#OWR>NGB^h; z4WgW9>PC?#^A!rQ{{^6Xy!oEYT*}5``3(3N_)Wje*HB3oJGfQ}CNUQ1x7TQU7f1&I zp@%0F?>pkfo$qDxZ%QhIPB*9hoF9;8aJDU&?9>1q9f0=ghWP)YyrN$yZxt5^0PN|Wt5?SG-Xn8WS)9}A*(JoMT|9{Hs+i$sX`HS`Y-ybK5UmPd@ zcl%Elh#CSb6V@!-z+}vBM1+Wl;_P#rE|jDl!BuQTFlBpt=Iog|ZipbSo-t`M<533g zwl?IO?I$BFmdWSOR_E@p)V_`aWyVig&GvhH#H9RhrUDS9tRTEjz>_72uTX9d$gqw^B$T<^BS1-Na@tj-aX=ZD@reysZx^V;DW_D+@_G}{Y;J)Pr;hf+tH?L+%=4lvuN_vH*T z+ZXrc)S2y1_T>~|oc86=?HVrME2g7-`gM+kgL=HJ^AAY*iRW!Vx=pNpW(E%dal@S? zP6%jS=NO;{l>gXQ8B1hNnIuwK-p{%~79)&wQ|DfgQBk+|&5gA+mzyLqcdDUtlv2N= zuR0dtoH|LAXL|$n!1kSem9bcx863+;HAv#*Q8nrx=o}4#T)`-E*Bap@XPYFdBGG2Q zz~)q7uWIQAZ9Ve6`DVV)UV?f%c(H*_@!17Psm{8{K)0WaPdMEl%;Lfh@k!6V!Ksmb zlT%N23#Z=fW=?SubgM+X*=-Urvu{bnm&Fw!$2d$4qzk1=_)gJ1+FK{kR@G&yOD*yDtZs1+3%ZUmy?~U(P)gS_YEP`UQmoS z;#23?6%fvz#`i1je!yd_;~s-i zP8UkCjb5PjhbX&-jYXS-;wh{@^y5XLh@bB86zseUdan70bLwWM7TJn?d2e4uEP^>ZB#~v^*H;J2U`~f5o%i<@BSPlN zB8e;u?dIuxpsylAO3n^RWLXdP)j_Pu>5!!Jp}t~F=UiDNk!6i0#fSSUVzTG#kVKaC zNM9Yy-kc6eIv?#T#-z@bMG{#SMZwO;`YK|g=M+goFUq7kAMdMU^_E2vzK)}F+o{SD zyNvXo=&O$zZDw$Y6k~uSbdEb^BM7BB_XgSdWM6Geax*iKwMk<4BgGAUbr1l|42~nf zB1t-*>MKShFf%C@lfN=dB2X`r-+eaZ3m0d6cw@vVxQO}htKi1$UF?g%U z_*r(s)8K0#i`;nTaRicUk|n)YzV7^``3MT?irB@Mm+y3z^3U+4mg1v4i=Aa(U~c;zH?uy1LEdTh#LN*nmr6+y302lsp%kkm@$J7XthlZ`3AKpGlsJV zm9S_+PhtP5+(rBKs7Qa}>`&5k5ED&jCAlceaaNI^^bG7U)G66hr-nR(>(=1)#M+uQ zRTCQNX3}sFBF&`7siTCQr=^&jcQA2G2gjF!iw@{B}azTsw*6$|#39ZIEqTy|KN zrLzMO*=gwlJjV>W%JRvwo_F6fHdR@9V(7TuvX-JO+{d!GovB{b&Zu=v=Mf@H{L38%h}Cyu$KcUBe*omQwHrvciHK%qM#Gn67fGBkKo=bZOwJp_ z*&7V3{nYmuhXQD>?=e=`B*qFZh=S>`>5M~Kx7DcIN_za12`9)FB+OEAX%5ylQUar@?;JoY!YDy6Lu(JSU`hahyT}ArN3@PehU~F=K5l zMP?P>gdUBP_&@FsychT&(ITdOj~OVkTWGjC}Od!8#i-AO89v{3*Z2L`v*S-+}tCK1~adi@Tc9cm=o7r%9CwY!zKR$#~^l-3~>ZD@| z9!hGlPO5CcIShnCCj;f#?vpQqEIJ$-YCM__mS1yHyxvTkx_vE5U35gRv}jTc15che z7%G~M&&^kln57BP(8u>WV*wn~LcRtgmcj!foQKBk50egu;Z#Q_^;AoE(bOK}^|E>n z-eAIe9%{;C#A3U%;nCevNVHctCxPA^^(+Cd7dgLOVY2Za= z16pRp=S&Bk-ha_#*u~)l3~Tc^`$+KWxbdLkm#tUACUI_+n~xe6r;2_2cy`(!cfky+f2k~|ZS~ZAhWD2Cu?C;lViuRNNMc!j1jKkWG=$&Q^8*xEwUzRwD35RHE|CY6|V=1=Bc^< z*TuOgKS1S^dBo}5+ehq=b2RE9+vpg=$gp!P)y?%f61$q4{5%DE2pXR~1P#X?f;ypx zps|!AdfUk_?B<-G24CYf!p{u$CT6fVdYgLh;+n-piU$iUO*iK_xQP=h*sG`$E7b@% ze1MPNNeHJ3G3`#q2;|8^Yb)qeKsUUHM{c_Nz!}{Sk#lE%QE|LLD4@R6MJLiG@(IH{ z7?i~xk77fqYM+DqWxPo`5h+jjbe@S4W)nFR`f5pirO%SeuH~h|ST}oI1I})J1h;Si z5_|jH0Z2YQN4{axuj4dc<0#o)x|k?RW=lU`Su_o;5s%qzC^)UvcY4uAyv})mbeq`w znwgUzOLmdOo&&V5zEM`@WDxa@+`%?2EA{QY_#73ko5xH~@HzAPQl2mMgBJ0uKLz@; zk(px@XKs`cN#Q&V70$tg@qcxaekYBUR_x?*hxM_(vLILJ)X~#iigTvNr3ZC-MO$m- zH*GWIGkEm4Xh#3&h-7W`qN;0YKhYM{V^||_y=;cInsu?Z&{mP_U)%^3(NbZegEczm z_O#CD+f{y#XF|MfYF=PU04s~vsH|!stNH@k+S8-vJ#I&F`hxi&_rPT<&?SWakx^`m zv^}n4^msxqXY_1BFJ$x_LXiR4<^pZ#&=)MDG@~zAK

Pg5{JRqc6ae)f%Sj3r?l< zFns}yfQAG01!#7yVXVGjIHe=>1?N#ZSYL2HrA_*R6_gHOhs)?VTtj6lRT*nbw5hYY zZPQxmSg=`NnP{u8tim5e-V56lS6?sy2Jq5kz{EWx+)OZ0c?3$V6zMZ7XSU%0s^g&3 zqrTLBh|P0>UXOm%a7xUqY;J4CTXP7{_B`;7c&mrIAjfR~5z{jPov&}Lf*s!4{c&rt zS|&C@B~&e*&BQ0F-of#z5CW+6ytblh!-+?<*$lfQrK%H zw>3tdMz2o|?*eHB+o}YzwoRwk+v06axLFv@kF`Y$@K=bxNGgr@;lfsAwv*}WaiLWZ zM->am@s@-YvGQB-c2NWtn}Sw>v^wZX3x=8z>QY{qDVQF$D)(!HO20PC!n->4prUzx zXFg0vqbb{pawA5Ith|1(jkmR|B3H}h^)ymcHqu|wNYS5bq`Z2xe@~of)~1}T6{EUn zh6Va=x9E)1c*k%QgU}3Bj{(6%;R6rO0=N@OP4hXY0tvfk0ea{NvkF67w6)?jwbRIN zOoVjY{JCM(8pKt~>Cow|Ly$LGs*kVi6A9ri$2B2#6GP|7{g;kYr^lZmV;o%r-hh4_ z41Z;?Is>MIn9rFr$){ll=)z-e2{f9+9_Md>UCMdiwc ziI~#?gvJP7Il_sXRtX{W_|BUi=C_9Y zRwz>7EQHmDlFW9@nIs0{>qw&o5aBJ$EJRj8lFodXQOmOMUeB9AiM5&1{8nd+qPJ2S zZgt*5nsbGAl4%^m#4&D9%0nlka}wNvF{6dpWp$#2bgfm0@#u|4BT;71-Y(yYfLa8x z-9Wyl}R2A0Yt; zVG#}BaUP=7mkZ`SD~R(5@$Fjx9SlJ;$qUL))t(@kYn5>}Fr#Osp<~2Qphbk2E$7cf z+jjucSzw5I79VFL(+C4f^#!6WFC9)rYC3;oIYNw*zf82>S%Ug@nthj2+)yzyOCd;h zk;KLVnX+pEoL7*E?k&xR8NRo~2pDZS1|wjclw&Xg#+)335iqbXkTw_rtBGipD=$w($VFZjba|}kn=*Te`0b^l~!N}3NO%vxQqo)1TQu_Wgd z;Q{$FUb-SwwhKuia}Ko=7A&C42)&52VIvXDEGK#u(HL&@`+O9CO+eM~c$w;StPZ!r zvScs28lZk(^^F2DE8q0bamYG<)1V&aD9%2}hOu7AZyr#N%-d{_?mNnsqDD*deaPOH zOY;3nNmKJB<&8?ophisQyELdNlli8+kLSrZ>AfkeE#Ucji=jqN=KFI>ep15L3A{iS z`z4QaF51K8C)X@KmG*;PfwmGu5c-YSps4XV5?J3&4w*{1S6RRpvs{Fn_9nn6?rkobN}Li-2WT0XV+} zfZf$d8m_{X22PJ+e5or9^(I8v?4XhDac07Kmw)mlK!acZ!~1G9)ZJZA;~ia}rNN%` zXD>kFtU)>Idh`)-T#bCUgznGnjF3cb7+y`mRg+lyXF zC_Smcg;3^GIMjunqXz|&S8a4qedg3x7ij#>ZGAtZ<5H>|(#uqOIj1T|yUwq3^2;4^ zl<}b87aw}e?q%@XzdFBGiLWQ*itFLuf$Y& z_q!^mbTuKlCd;K5R}^1|BE=s)r^N+BFdM*1P0!tfoEB&OoGz4XyAFd1&u58J&ztFf zFYOmQa(h2!zO!> zEX=1r(%vmQ$;O^wIqTq8%((`T9ALPx{Zso z)E4ZF5T!{F(ic+FT|655XuVkFf}I;+haW6AOtZ1Ln_YvUMqfuTyU2C=G=kZM8R)UG zj+o#wV z=joN*(slMZVBZMA)@Wa@eG{0N_hJm3(UIPdzhm%Mjy5kun)~^H3;+*%Z9a=S7S-Hc zwuWKfER9fK;h%t)=&KjtSJ2!Cv_LJy=lH8d3A*0#A|%c&$m84!kj0h{pZ6h1CtoRb z)`Q=0s?^jwHWBMKuwu?10O|8b_8)=JZ!z>4IbD)mob$DF$W`H=eEgm@9i?*Y;RC|iUDd&DF$~Wv`G#jqU z9{`o)uPp`bYY-getB$xfZ@-`Jt{(|j13p*K{$vj|64a(1Y80sLJ=7Rb@AXh)afJ^{ z_Cy#-?+#*6Y7f1G{E1~ABrp6a950siLz1q}(GN>HB57#ib$il``gKdzN!?P|V<^4; z$ivj~;f8{G5dx!u)a^%LC-W#k_GOU5Of(*(cMz)j;W3E*bMGf|-SD%$e>Ix$SM@>%+`UwLf2B z6Xg6GkNJi1C*l}7g-GcKRO|(C7ShL%CWxtiG%xYR9Pt|d8iA{M`ByZZVQ(PI7;jkT z-}VcEn1OluDnz)eG{KBdjgQ4-5cWcZ5g7n^Y*Pf}ImRJy42M9 zG|10~Wxaz0QHUsY1wqP(*-AkWUHv*JygHrTjuhk@lynebXW>HjZK4+v?06a(!U}(e zGE4TKf!f&mn#lbo^fJ$qj1BSG(ac{!XWxNDaP_94RpjHa=O93I*$h$oM437p!Hb%y zJ#qQ{JfXNV5eY^@_6r~^Og<}wVcbF1oWBwaw=kR+fiwj17BTQmz>)WF#CmXR1Vbhd zcRpeZdiHU82ks?!h8Lhu^$y%l@W_2Mj1qx!2D>l`>2_Gi7Ze1d_(D|s@Gu=tyn*KH{$V0^z*Q7RE>W|z0JF3}4tm)LvNrS`s?6V!&3OetHP5R=Q$%k+5Ux3| z0jv92krn0^tPA8C|8#fbhay4Q_@QVN9Z)1qM2oFrhe~KDv5NUU1Q{+~2P+wk{j49j zm-n+y;Ojg^(gW3Tdn}~5^mBcucf5u6iZ$a6GRzvn<#Wi)8z?u6>pL1_jWuRsM2h-X z?;uvP!Cz;;35Ar`-b{M$D!oZ+B;k{`#B#Pk7<0A)MoS_k_FIG`A_;pN5Vf$#IhV-3 z4}CS~5;}dxE42mhB4R|5Aezt@Qrca7Ms8u@IhU}vlgYSl#k2o_d~0?AB8*0BNGw%~ z&LMAUy`|K78@eei7V9>;tvc7VvlnBob(cm8(R^*g9On^eIcc;Z2&h~C2s?w!IY1O8QqwSmTmbCF>(RL zRoQrD_!LwB1y_J>2m|>YkfLrQrNve2b!?-eIjqgx;~wO7wVkTcKTtotgKBMeQ844S zafqAVx6)2z-UAk`j#Rh5M@{=as7STaZ$eEV7@XH5z&D{jgogbQtJxnTN#O=`Tw1A# z)U=Q2QLb@YsbO8Kzbc-3g5Tz$57PwClr2!URmIOw!HeQ+k<^RMCs1`h1&G$BYOGr4 zGeVPAc_e9n4iw23Ncam#&Od=cg+t5BDzwxhwAAK83tQwKKSG%&LhcWLTt*$rsFP*X z{l6*0)g}M6HyRFh^+&^)o|YUC8Q^Nk0q&L@z%7Yz#dY~nL%J#@cW^PA_r71EmXhJM zcQUTdl;JyNUxAKRwErF*SH@SC4Kb^tvcvfo_zfYT(;3B}i}uUxk0FFl*wAotMoXOi zpz%bXLdAX6GG`p8{pdau=yGR2q@gVrVtC4(4oytj=};zMz64WIoD zOklq=X0pb6rU>FP8b?e=8bO--g|RCLfuKDWVgfz5)qo0Y#qpI-oO1)=-h1I&qynKw z;L8O)cAzTo6#;&RQ|-aEF6eK`7=AfE-l*sIVkq#s`Nt}KDwhOTfc`zwnTYDR01!hd zx+9%v^7B;Dh1BiOU5dZsNBpI*b0PWY@7*JkorA#J0$Kf!_~>gf6&uLCU3{?UySU;o z@TTE!U*KcmC$9BgLvI=OF4@Mkr^H@JpeM09ehd+=%P)emo{8bUeD(|K+71an1)hC| z8J_{tszWJ`8;DfOoB0+N!+z&GBn=_@NL4Dd`cYF@5c#}_$^U-%{u7eE4n((D1 zG9FWQWkIAbbMe8|?9-s}E#@2Hmb8BXwm@a{q$;&vCQc7*@K{zF%Kinq_yUI~`)5Y* zjK}#N9%Y{ei5p<_IWFA5Ff;!KlRmGL!pAn~DUjunrU(5YK;K$Q#T@hmUK{BQB)0ySOX2s8c>{Sv;^5+PXL9 zAU?=TmF}QA(mSO+gt|`g(@f&hiezVSVV2+a!o=3HpOyM-6T47oFIP9tsqDEY3H%mwh-;el;ZK z_~9U5%m)aei}@fB)ji~>j*IzSl*+dta529dbx)f7?jQkO%v0K3d{(Y|C?6~#vhX8W z`lPm5bsMVCSc`$g6k@y>6wOgbz*@JCi=mV!hA=*S8EP$?L+`-)>uEm2Qq4mjaWw5b zSXS3)emvFZYcv{T>Kcu1L`dI#*>90u`Hl|;>`uPV<;EmI)Tb|`)OC%5cRH3!>hoV!J=)p*LiJX0&x%2U)-g6@zS14vzH|gbW&sM9${Zs^2Cq9ag z#fVc~r3R%}N+UR+Pipv5K55}g`J|-tslzPm?aMg6lZc{hi=1!F454B@WF=QDpW~vs z($BsDO#g-TxK+0q!2ko7&2z=@>FM6_+{^a6#xsU0?|IHbiZ+JN#8`x!y^Ix6tz8qah$ zUyWz%H4ZyqZ%uB8_>lOiLmHbK2R9FH8BQj=Vh-Tk@p!kZQ;5w-Pag#Qu=(w?PdOn& z8k5h&Jur-dnkk2gqUCa5R5O0c{^KC41-+phvc2cf?ByT))sDF8npA+C`&JuF4#Pb` zYg;4!&}w22{Lx;~1daA${&S%5kH!%1`KBXXhQBcWc%ep0avG4O_>15VJ%Zoe<-{jz zCzkX}n&KsfiNvtl0x>;F{PPoq_$bZ;C42WX#SaOB4>5e5;d16rWqdcz`|mi}Nu?Sq zOz~!XSgk4cf;CfI$1t5B={nZ@p}1c%D28}u1%qN7peYttFUK2hS9xazr;A`M-P5J89~O7kFC&KHdXmsRGA%Nq%v0C=hRtcGe`k}~>T zDqaMhFJ=!~R%wc4tg#|rJQ5|mCQZKe;~E`j%nHWDjYTJ?O2xFw%c@GnD-D-b^%J{Q z+*MjFF7`gyh}J+}yvEHnI=TFm0j5ZJ$ig)S;fpF7D@sLv(`8krxE#4mQ2}pFv4L|P z7bDFl(E>m4*>+PbH~J-g8l7`D#c`FS`4%{)XsaezSkaA77TpK0OtE)0;XjlvZ!Q(P z6_aoM0ZpNCuKQX4xFRa?a`Zw!QC@jhX;AFN?Yuu*nB4DtT1~yjIi;zvyo7wVLtm9$JN5gWR$QbvcUYB|rD;mYO&E@dqX~XCj z5z_{dKaz$7hWDG zi)xlt_7elcq;o+d>HM>V;1>+reT2_rcnLf)#i?B4H(cT&Y^|LwTX~HY5iuHVb&Qya zFZ>NAs>A_I{heh4#8jr14K5@0Q-?COUVQ7aa+~;`Ww;E1=F=jkk)QY!Tzj+W=3p9l+^z1V=I4 zy`Jz6<{z9q9c7(YK($+sdi59mql+Om>XrijX242VySaWbU{@W%(-}X=Cj9CF1g~Vy zzgYTldAF}cEHAzSdDm875BOp8ZGe-wo!?}g%bF;c+vc}y&CDbIv#F8jo!zPlKG{U@ z*$~0QN(s&^Cb(Oi;HS*roAJ$z*D-!R+I&)1SslT@mJwW-T8th!&7yv3WjKuCmHA0< zIvGC3u$=jGBcy+^MXD=2a4~a=!=sU_WxyuDjm;wguPY^; z3u_4eu9@KNs3X?K7Q#I5J5 zECzhVOZd4a!Tvtttnm?E<|jDQPn;c$Yl1lY>%^JGdGF-BL(L1pdD^@h@F3r9fUo%; zfN#&?kUrkGPLj7f+4DbDJp=wE&vStP#7Hy6%IX)3G%>>XyNmM%@Y1HY0dK8%4^rLx zG2l1eoq)HRyI8*)u*GW@_u450zP=yX3~}%0qh)~CPXOl`?%8j6%p4vho#OJ*7-JDH zLDMWjn7z-e1sv-e2zZZ=${p!%1WvwDS%ZO3V2&A}@fkC_T|SRQ>9VH(s2>k}Z42oP zFrH&?C%XKc23)p7Z_8++#!LDmjAKwri}&wE?nr{@jd()6Jf}E@6=_~^e=(xaMzpyN zbELm0DChv^%lwXF(&>WEb>eKmv&4BQOK{zDtxctm9kAL}ugi)jR$;jj=lI_UPsHNc zswiLaOk9x9lvJX)b~t3GGxfAMd%%swhImR**`n2&M|`iS`m*J?m)h1};CGJyNPD8; z743>TsBWgmE6!BZpt|+NUU8P9s_X9nb)KR=tG@@-Zxyvy@{ub=736Qd=?^~)2jOi7ys;(A4q z%|fwRQDn1F96(DnY@VN-XjtM)VCH*WBf3726WZg@}ngNm`KTE|oHc^*|q3Lh6 zGEq5DQuCvKDJ~au^oV4OqAwO#h?f;rTm4FLKar?snSWT*8=zVgHHoPM6xGJmv62$Y zOSeLE2HnCEt3-V@{;MmoP*J;ucNABN>zKMk46N7{sunXFxCAl1>{EQZ@+RztC||PX z+hSX+87yV1%Di|zcJmM^do2}?rNw=?$4Z)+WFpoqCgb)B)uFYhHa1v{;|uFc#3xND zd^>%IqP{2^92+J^?;$nUH17)SA=ZwNR9kX*Y=n4>sa4{orct1F>`Ag!iL%;P@MLP* z7^(SE<@nfM;@BQ)LTt1cwl`~v;-bT1W5sKV(n@E<_7TnFdadj$j$rB>|G5}T`-&Ng zx~%B<*uLUKMIBf_#TYN_7}fZ z)Yp}##P%1zQ`Fjlov{PNwTilZ;BrvwC55qMiUY-8lfef*JMfa&!NR)_wZu98g#)jO9U}4-^;&E> z-iAa&vF!a=A*f144GXT;CW!%x8jm}2lSH$kI{U5G4i&=`b#XsU94f|0ifeS3I7P|s zYhJA#CQen<6V1oR4ik$MMQuGsM>7;yFcatUo^1DqfZpdp%Wb?xF6DO%Ho`_8oEt10jMS5i6kz$;ptO3u&ej`p$n%~zyADbcOE2^<+wKhX6R@Avg4;0Q2 z=PD{xO0rdonmh0n6-Gn=R~vCDqigINl~MQq;#j(AZ~Z7qxA z=ZeXbWC;loGsLLvs<9d3iqHe1^HFlvGttem1d%=}rKShO9lt_MR+O*dq4@8_=ZdPWexrD; zII>l09v^ zNjF*HS$X^!5BS* zWk)OOhFZ$!D5|rb@^vVxjWw4kYO77M)r$HsOw?71x;joJY+-7ZxXk}HsP`2$r}Vw} zEyA89@LMHTm3|UmFA~Q}Dw_H#{zvg=rfAgt5WiELc>>AK@o!JA*6tK%De9j|P24HY zSJcCh{Yk7=)L$X{lUS>$OCh^UT&Jj8AiGQ4rl@&=mA<>h-HJLV;7Qyq9#PbRkliDm zR@70D-6Q_0sGA|XSG=mIKS6e{*ruo(YFBIbiT4$CcP;ko;tNG}*1s3LU+hxUvid;c zexaWz>(^HIUhn}CRMdjHK;i)rRn*n-mA(f>nWEOmJ&6ZJt)jNt?*$(cX+?c(2NDm7 z-4yj<_`Tr6Vx*$J2?r7ni+vR}CX}CeL>#QBBSIyhj!@LekUc79C~7fekBSo&b$Zi# z!NA0;Xr&F}MMXV4V72y?cui3o2Wa9cv0YK4&|^=F zZzaXPJS_@mbIU7gZXarGAL=uvmO!%*yVpRQ?6G0+^BGa5s7XvUOG*wZ!==9}zVAbgIGHthU-zmQ&s0wH5T=&ke&*D~tD;p= zduuZiuZdZTnj>Z>UKg_!b*4T)@rIbEs2e?t5^st#n36U(i^WP7)Xz(77FW7tTf_}Y z)@ZCuY!UakWLw1}N;Xtqnb;~`aLL{huPE6-{m8<%#OF-O7`aV+@6y~RJf~1?m*7ms z#ffbqsHofZixY2)LPb3Q*$xp?)Hjg*LzFA(1JCag?~7_h?ISKud?@I97i9A?ZC&DH z(W0nV^mU0(#2$)z#&c`pGci_C+q~-%pNk2KT5YaNd?BVND&@O1@ufIQQCIrbC3cDv z6qWR^OME5fDyq$YYvOBhhN3=&>>F{GqQYWbVwX5yQIqvs6W@t7ikbsoz8Ak&)Wh)Q z-{J;E?QPzj=oSwuYLmGk@q^f)s8-(#388IM)H}Y{61w&QQ?hRj?TbFt_e%3~?d^o2 zjdrM&wrh*)c)MrD>Jp%6h$(h_I_8d z%%^>$D3bZL=B2$dzqS`s=lE%t5YYBj6zviM+98UfT|!VhLQ%9!2x>DGH5{^#cA}yV zfGniVlN8Ufu(p&bIR?YpMSWzKF||b0XdfrS+Bzxoe_ayD%hPUF)EdN|Jnare4G4Xi z$kXmuRD!9;C57^KLH2=?wT7n{h1z#a$OGbC?y)-l9o;N*0oRef zs^QKjwQYV8we~YDg@qnirr!J}R#-^)JPQkb;_zT$p&xfj|4;P)0c$$$ZIb;i9?w7J z?BpK&Qx(-q>g-{HvdMzcv5h1`<-pSOsCL2Ajv!N>oJ32%Mk zZ-9PrE;s>EiI}G0`2yuykJ=gHVvYtfdfdvbO}HVR;QGpVvXW;FeM&a!E*Ep8 z=C#PHi9GnAi*1enQ~ZyxFMpaK+ztP?_->mL|Ec91XE~40{{(;9@6-;t5p@k_haq;y zILAz9{#>5R%VRZSm#D>G5`T608-Tw?`~^fYu74~*JRJfI;=7)-hi+jwoZ%RT`!k%x za4N%DfEu3SQ{KgZ#rVz~;i~}4#N`YLuM(D4Tw5n*0~U�n_3O-qC!)D`A+QJ%{<( z^E|dtBu1r=!vB7F_J9-dZG6JZ885;;`O|?DoX2&hN^u&6IpeNQt z_=)upequd@pIGn7cJ^dD;}{>u_yoo$Fg}^_$&ByGrHo@Zf#GC^3;D_SLVohSl%ISr z74+nLsh}s{O9egoUdm6tm-3VErGlP(FXboSE7<-Dw!en)HH@!d%WD|!($5~ysaXcK z)p|kq-tI!1T&0y5KNMZB^*0Wwc^Gg|dV}^5OE)mwrH?B5RvTzc9`u8@k=t;Wer4He zZI^!Vz(ReOKC-M>A8ssdDFZ&XBB{3+pWv=~i!rYz1As#m#t) zewQ9k?+!S6&?tSQSktl(^nXaD^p|n(a0)n9csiu_md(;98OtkXGh6_UH?>IL%wEkh z&Mfb5?11G)W0yW*(6`zSQB^S1SH^mT!dje7qzEWE383zyd@l0S3)9m?VZDY$s zV~9p|8KP19JjC8k*1j&8>6vG|7d_5XVt7+0dD0rS`6iwGNo&+2yY!(&7kQ{pmkWZI zcs6reQ7`-s{KwEco4GDWDj$w+DTcL`#Tz}xvL|!clle;eoAgf4LiTwB*KsLy#(P(= z&OBpC?XlhsT;Da&nde=|{;c5kS<4o#Q+A#zz1q88;e%3}y(Na#teMm@FB%)Utu}IB zJjA_!7uzSFCz*G#H5!d3#^lY>dFK6MT5O(KVtC@GnGdng8(5$CSD6p-$UN5=S~SVr zs7ide=@E06ep%@zbCz*nygz!UxOS)6U;Ay`^!3*=jfK8}+U?Pp?`7zlVxYF5rP|j5 z%LH$L^kuGB3w!c1xASnNS)Cf{8v{*(H#Cm)?T_~tmy6+AxNa=)uS*Jjmt*E0?Ay#1 z#;}EfT4ii8N*s)*A_KLoc`oobi&y$ewCBn+^xEV>m-}|GeS(b!!Rx@G@vuw3yW(Ns zG+%aTH0pNnnE4nw)AhxG&-)%niKckmc(G!O?^$hm-41XXV;=#|XeM~2{ZGJgDT0sN z8Z@WWXyRPt{o41saau*U?_BLLXb#jj!~_0;`ddu}fV0ah{M$JSZ8s9l%W;mJdYq!u zEd6`nS7{#ozW5}6SSP%Q@p8SiX1Tvse>^?WNW{J^u?Uu$>x<{7tR&VFEw4i^VLFqSlzf&VG^lR4L9&NZ2H9m)P2 z%do`Q)pB^C#F*Z4VPFn(<}+N#a4EwTfa8K|0EZj9xFvTPYs3G<5zfxiB|(o~TWyLW zhO1EPN5G*zDgrb`z_X-rQ*f}|vJVe2+z4ojmlNKt< zY1cQ82v5=;?KcL}q0I+{cfiAm#zwA1z+;793~ffkSmaPKlBOGb^fz@ydp2}W=JD>n>h}63~JTc9-4!*J*2ZyU(>QUFD&~J>(`aQ zsdvH#^+k~}q;v}4ff%2Yw38}s$}58AbhN;cz{7?);Lf~qaIVs7*}_8{h1N6N0N9Ag zOc6K@X`_)gXgwMNAF{@t2K8(aMhMQ@@(Qx2LA_iH4$9?dFvOs^y zO<#e#83XkN;oks%JdOCK?_W7Df1v&x<8<#~lQwtYP5Ebdc9#Aj|44&cev@`_@R9su zjn7k?^5+<(HSgrlH^|Opwlm+L8NErnF(?Wavd&W0S;0ChSXyFS79U!$25qvBXD#>3 zVo!1H;RUN0Ue0iT{Rscef-&g#;|tb#7NW!!Uh5~bhm+yqbbYc;9;Uh6o!lBbxqWtW z``ipWg<=vc6ct{_y>K1(!g}t7yA0YDOw#8L99($6=c9_@(4l@`&n;hKEUDV)*%??c&&M;43Sf!gICrg9{2D;<|6( zx^LvVZ{)hq)Bk|BqG)_);Z&WTkWOWrQ}ug_rWmtf?UCSY{Tw_8pRNBTys@xEFD}N2 z1x}oj>g8f8e0~W&Y_EB}@MUhj&D__UxtDkFuHX#MYcZeof#)8K_Fej$O#~k+%d^tl zdTDOGG`HRk9=$ubXLlI1^VtcGoNLEgcWAejcUVJo>g(^hE*=l{^*C;GkB9nt9NQen zHpj8ea@G%fXlxX*{sh)9V*NWbr{!~N0_U2*xh8O~N!pt7oAM}X>5-4Q^~%{oEnBGN zym>eQkcs5snf*dQ?7jh8#f1?+-cQ{O_;-d|#CG6ciGKjj(Jlp?tE~l`udM?-UAqBr zp>``^mv%egQtfWQ<=O*)E3`)eFVZ#uuF;+ayi9uma4qzM;%e=sNWOSV`zR6-&uae! ze4gPZKwbP@`x=_BYr6oqXx-3!mo-0Nolh8k!J1#O<}TL!H#GgitCNQT-H7_}!Ybj# zj8E15;LOwi3C;pN4|rCOM1$gNJr4X_y(-#YoFtwuONtJ$u6O|ckFE#G8*$3}x{^km z?!FDMOl$MqKZ$$#%gUc*{!d1CcvTXm z^k;qz^YNtv@W(J`EOW*(XC_-XhB?PDr;9mDbn20-8NZhKk1_rv` zTxa&Z^SU!2hQL4+MG=4o5-Gk!2q5^hDT;WKkVt|iK#7W_0tPb|z=(qxXdWaX#n~A} zUOS<@wj;Y@JNAZ*zvfc;l=$8+#okWM!Sil_+ahvPpTJ#QS}x z?+X}E6>sfU@eY*Sf>C>nC_Pw|w@LHTTxhD8)ap`xV+z`tD5Q<8WLt5a` z1k)cCd`9pY!RrFA2)rinhQM?S^KNOmtbVTZsNf?lY~76Db%9p|zKAqG-FZ#$8v@lj zk;XdaO$&Zh;Ece!z~?0P#dYNQ+PW9iROf4;6gzubnRifNMqpiFL*NyGR|Q@ZcwOKP zfj0%JBwK1ErR@TH1P%%uNwUO@;JGB_))4$Tp)*cy2v8 z)YpGfJ#%M6D9=gkOxq{b&)?Z-W6CSQzkcU6z;&Ci3*|-|YpB{ksfIS!+sXfmz-t0; z2vjMlzrdc<3+kJjds3Ix-)_#O$n!aYMu*fy;8lS=w~4(Hm=V~x?FAL;YzY1wVC~MU zLb)oG>w;ew{56TaDY&tLd@=$X09{G-xSe>9z`@&@e&%+zDW) z1qCO31ix`R+jUcLwUM}iQ&0DIrUmcWNIpje9~68>@QkFX3*Hd=6~V6xeogS}lIDis zH-)b55dL?NXIk(c!H)_)DEN%v8Nus@Vda~K!FYjeof$OLb)OMO-ZlrlzQGN^%VT5z`;8y;Tgd*5?dF%A@~)+uS%M0 zf?pS0Z5D2ug`418Hd6EIs{JP*b1Rw0= zm>ulon9X#utcJkr0*x-#Jl#co=;>l?MkrSS4|l!@%6mF*Aol8pn?hIJ#M1(Mx|x0p z;Cnic3T3eSvU;X-M(~EjUKRMFq`9H<-bD^Qcd^_pcQNmbP%?K>8V!M01ztxi%0FxOGR z2L+!Iye_cO!`faE{F=ZU0@dBZLEuq=GXm=ZuLxB4d{RBV`RF~I)9V7S2~=B1IVx~w z3tLwgctzkffj0!It&F`Q@S4CI0@b~wU%QueP}>NPZWGS|&xZI{haSdXQ27$xwQI*) zW;4dJ@gC!b@v!-R^SSWVuoX!~yQ6!e=b|r1{~)?O_C)N3*ekJ+b&vIS>w@($>({J5 zw*JPl;yv-#5`U5SZsP9}2U{jvKGyOFEs=HI>&oliyY8#&et+E^t$nRuZ*5BsBo8Eq zlb4c9>r?HYX^+EqH&h7!!g$INf%hC$9e74{J3^cBdi>p>Y{!ZIU3i=Nezjip;VB57 z%H!SZ4xBo^11EvEV=b~1r*IXX(p#JGC4ddBfc5RfXYM6Fa&HRo?K?LD{`JmIz@e=@ zfV=yc=8c_9^Zl*FFAKgb=_``{!R<`{fo)9xp`G^vzGK@iz{B_V0iG3D6!_)a_JZ=n z&Vzv6_a6rQ{$0d>YsXQ*SSKm5+X#QHpU~X-5a3_lPW<5n^M16O@UQxOKAPvB+&2mO zuiV3wU){;rEnVjT)vhN1U%j7{FW)u?xc*M!=FS43uEURQdpWVomf4h~Xd`;lb3;fCWv!Kih z{DQzQZeg0sJ6YE9y@a3L$TZ*CPWx`Ugvrt#@-1Xm3IOlVphFb*xl z#}J@nIOPE?Gof+qfbGyS6WX=`a3lVi(6~*2o1mK}-nHlg#5)#%op^&1XC<)KGgUX9 z-Ty6*J%KM{;T=st6DPwT20jC5stn3B@V?qf;8~Pus2m{9 zVxUY@J&DpxtRc?=7Epqz7EywUuV%dyumr9qo(4_>J`YZYdLN*PbIe)b?*}y12b2x` zgMg-b30zIQ;hP8i_uz^X1mK4!)!<~RPlJ<*Q$7{I&!`&UXVpc(&*A-K6YneYvn8(p zns_$xF5q7RG}SNR4P`_9GN7qm#j{XD{R*I|epUTA@N0mkx{fbc7&t@uZs1?WK_CPB zgzo|V>v(Ev;LPGr0RK&O8TfAjn(B45!%)8si1Q9;hoOE4&{SVRI}E(%_d(#li}#%k ze7W@n;J>Fn4E(>l!5vg;NJi=)qltC3Qjiwn(7bb zz3evtP4!3WD(HU8qC!y9LlxTaEt!{9Zulr15Fs+W}3r z+xQG%ukks+`*G^mRDH%T0`4)s04?5Q?gHFv?#A=z{lK@VgTS|{w*lX(4g#%bf6Q86wU z&l^9DUFEMD33I~S9NHFoDD+rpCUhb6-q6p5ej)T~==&iv91kA~p9((~z83!D@SleN zGQ2agKQbA~N1lni5c%E6L(vaJKN9^yv@jQt>(lGU*PmYB-L|#uzP6ue z`>D2{Y5R+|@3#%NPqaVU{{Hrlw12Jro9%m2Z%ZxRXFvll0sfc@*ZJH(`1?0$p33ll z6RC%Bx?nZ!GR}gnq@7E>2d80pmcajIQX!o4S($DkwHfDGR?|L`Zl--6r#n`s`z4&+ zSWWvvdNu7_Dk|@Dt!zhUQ=OkoeFFJ|y<&UpEW)cUp8KkZ#2G+xHl2EK9MoshwD0?ZAHy( z#&5JfWBg9*C)B3ofcZf3;m|@d8~PhuJJvrHikg>0Ep7i!?k~1o4qa>eTIf5WXN)85 zpHL6A|3m1Z_8;Jig|D`64F3tP@8Q~!+87>6Q9kPMkweqd0|%%3`_$oMc6B75nJ<LF5AWGU}d?OWlqElEuYR*r5y+i7tpFHyO=2oV^BsfW$p5k8$$I? zXXfoG`;tp>s@~s!i@GD?VZ=$Y{%K%qXanO{sT#V-$pz^FyQTD;R8-|#)j*dHaRm9S zkRF+=s(?;@F43T`1*bIM`*Ke{m^O*7)dCwM-#jUB;MkXHa;p>J>yx+Qpn!#T@j1k2*VEtm5V> z3$Qhm#f?8W4Q$Qf;-o+i0`nASMTaB8E@n$Peyi-rJ`7QHxL7)4=P=&0RfmwNqGiy0 z9nD@R_H4GI#IMA%~u!B*wyl~7de1PN0hhX40^UIs^h2a-+!xW z?3bn^etLScn!zkPST1Ll$BX$YRcJE*wEY0`Iz`@!3+UC-dAmqSF!gFp?4R*@^dGoY zRS-d&GNSbW{Z#el0}et&JJq-q2hhtlCj4T>W=)vk!1VORa%Sm(nzyUdXQ##vdQ5<= zIYgOab^Qls4ywUIe!h56jf@-`>Ki_EV02*5$nfC7y+dOoLt|s3d-v}f7#STq*mr2( z=*YgYp`qd7{RamQ9vB@O9NTxWzn{1L!w2>sV)k(~h(j)0t}V{0Ss%p|sT-SLv`e+>q@9&IP5D7I&y8`4@Mon;?=ib* zm-AVf(xytIj_Ft4Bp?xk75xQC8H+x}&Maz5^JrF&V$#%+Ygis(v4*lsu}yj{c6d$GNiXe4PGOkB zDI3qJtXMK29L7pZYbaB(Cob6K1(G;ChXx?Eba%T=Fz%&tz92Xi?Z zWZq8KW()bsf}K-K9tJCImoceByA{$*LT?sC7AKC zQW+!5OAEuAhimh+lb3?1NQk`s&~(X*I9AK&)L~j=C*zU)^z>NXE`Um>{cHtpZ-7QK zt}RC;K&9BB5dq2=3{Olp41kLOnexfJ4P3np=TB1oDlEgi>NGDu=Lz;~r_ zJaT?|noB!4V~)gE8^z`nVhNkczAcsR-lO~9mJt!Od!qm5r%IS$JN6c`9?43mB$)U$1#b(UN)EI z>dGw>j8`1n)|^)?NmIiH^%86Cvbed?l*3Wx=7>Qts>2veYviKDvCLgFPJEwcevU<$ zD4s3mFEvLGXRw=<8^mavmE8|jL{}w=*b?zVG@M>XJiU)D$`tXTYos zR{*n}gAOm$isv2tjE%j(tgXf?+~$}lKe~Wv8e0<}RSJ2)(Oe#TiEyhiRjc8^ge_xu zvQ#UB4!?tY33R)qZocJ^`UQflV<1Sc!_%<jnCu)1 zE$Yq76Ztut+}*{5Q<$T$*danG;+3&KT~J$Bu)y5SHaghY zZkw2W60Mg2y=*~PDQxZKirJSPl12Pm8!^ zjG*hwvLHhim@&Amvo$X>^~R1_i zcd=AH??BXsObYeaHOluH6cW(v1V<#x5C^Gg`9=Q5am^yaEh zK4Z^KV(n60K7&1iicgo#y-~eSz~K{!qFuh)r_WjgG^8LenQx79ncm+ z;}^KYsZAcXP4M^yD;Js&S*Bo4aJD@pFV-TAWz*#oT zm0ED_&XxivNF6b?U>Ap$N9;-#GbK~X4*LqqF&j%^z0Vu84IV9PLr%!)@OEU_>nIFk zrb>E=O}pw~leO83{Fw`NqBO6T@bqM&JXxsCV-5t+&xI78cP-EgpvN!Re8Qs2!2p)6 zLd-aK{S-!B%;%7jU2?)M&I5I3Dkp?ZlM1&hVW~3Zsz$k_g%>?yFM*yD=PL1pPTNNIei0JD_E=2t-oj=A*a3T!bTrnEGDOiWsN3X|wWSsqU)8;4iW z&x3`6m``pxEcNCPTEc{+j^(SzYqMv|;Ok){rEGmHH0WswG;yEVsM7 zZg)0!s5RKM!x(fn30y`eGe!6|^f-E51|`%>9!sFb`Y!8rdH~*bf}0&S(Rm&fd^V+@ z9r)8HpL+yCY;N#k*MF=c+MJ}QpL87Qdkbs#2z5^!G(xR{$&Mz%_JoN%utF^3^osC18Ey{To z{UiYlpsqu3;jAmLf)af42*1ePTI8&&AX$3a!4w-3{Uy9?t?`sqiQkgu^hqN_)TBC7}MmlAgg-Y?l?!132io-in1r zT*xzOkVg%g9z{Fq=RBB(b6TC&(+zS=V=9rE+*zW^;!Cez%CzHj&1748iE9`ed(!-q zQ*MGu?p0SS)E<{KUO9_R;_?cWN6>Zt0?*z-J!V&BpBgCK^in}j-taXsNy%LApn5;v z2|$|=>&(R9>#UI~r|mL)9Slo|@kHq&?gfDym!1;@85OgbRuq=YywN(!G%O4?CI)z= zQg{nPELxndagG*{fMx_j^0+Y&4m@`bPJ>Ov+&kg=(%Ectj31t=tsr=taoP;|K}_pzLK;06FWYnQ zcortl+ZSCDqfh1wc(@^3B^5d&{tT%%LD05pX^Fb-wbJzlX(YK`Vpn35qaqazSQRDf zD(7hccys*)jpY7Ag&jd_Siw_u{}hzMoW@7aut2)IwKdYXep=!fD6Io4NmP&(`;3xk zC535%n~hp{d_L(ip0)#pItHBeS+yTEnc>u`tLfTEHBINs3$ZNESn4=G$VhEAr3wx@ zy(kYnlwmuZVDN<3jtpS+bz zFYRGPiG!=NubMN|w5_|`ebS>9MnCnDYD?eJL#_Bd>janOc*>MrM%)sdR2(kR0oW*z z#Bo5?uoIHW7b^;@+){aY^b!mjm(qT1>6DzY=dr6$M)jOkgs$$2nM`37aKZB{bpn4* zbM(PIXi~xFcOk(*yd!VlJ=854Epiv)By4>i`bTrVCtz5$E@dvcE^9XM0Kt){yTL6< zz3pyD){9tag|+8MGr;L&atZ5am&AlvRfzlN(k8jd0#%^IsG*!8J=wYbORt_RbqW{f zG~wd(7-1mg5sXVCx79S}SxwWP=E}S>?a7=Bl@-TW&Ud)1brx|>UDEV|liaa($L#{< zN?qfX6ArqL!+tf9)%7-IMc9Fme$*)fn#8OOOG(HqbX_F1Af$Ni3p@bVlYzD{otR6W zcC0AKUo*ho29IZHCSE`bPg+=^%gDn*PGg*>l2SU>BQgZCnX1wb3${kN1L5xR$&!vs z1Y3JOSPF5Sqx@51Qh6*(OBbnxuKvl?QmjMmjLiO8VFM0Ew7fVekYUpiq&wV6&9KH_8OwSbcXrFx89jDra_ z!mykKLv{=}5Dnb@~m@l3# zWQtz8%xa3HJBE`{3;Ot(nw}2?Bo;eJ`Jx+J2m~Z{a;fCTVVpat#Ef2YgP1B@R7SiU z57AA*il~Y+H^Z3e0d>SQo>Mdth2==G;-<-Ys8;)6$xgR=Np+_?LC2m|ogfXTvoR_< zbEZ_Py5aF+wk-P&7;4^A4|%lZnp(-?%bq9=P$~~ zSr5|imI68yu#{@Sx0)*Jq^1VT(?j7Wi(5WR58!$RZxz1_ZwRIF24xBV3V4UHf^_pp*dkIy;@))mcmhq3c&uzdj)T6M0mX6>^wlDBMMA*` z^SF&?A74Q8*uObxW*$upc8e>9QH2qSR1`VRH3BXorOxXMjpATkP9QF;&f}d{c2%(C z{Z5KOM+q)~lbhP-bHEqt`dJ8#-A%!l@j|$kiV7{`lgw^=i7g-=f7Be`eQ~hZB~6Ji zl?vg)YxDRtbqF7Aj`gDcIi(`^ptdS@58jC5{c)tkr<+5>d-3KQUgV2ag`bL1rH~^w zhqkdE8IgsGv3^x>x`?)__(iFu4Qv*ejXbJ_SRU9ss0&ENHme9R6(a=KI7^|L>GJSL zKU#FT90D4rf|Bn=k>~=jIn_c51`_RQ8%?Nu+ zMOa(nkXNLn<^Y8sC};~Pgi=$aWG;~gC`?ZoF)wmSi=_Qd+Za=kI#y6G_L7QSKwBt< zC6vip*$C+va$*lt%cyf2{8O!U!8mKtKMWN8Hqo%QWP*`J1_B>+*V~tgeyhzb^%9og{ z_Z%J6Ocgr@`!)q#pq)?yy^tt-a0!y3E))^AG42*c*3@sxi;{3tstq*5t8=JPH-0rI zJeELuO46TpdO@M=@kA5<&ilN_mr&mS6HeRaQEmq9T6pW$v>fx&sU5wr5&xuI1FZSH zNOvt+vEL|9_MY1s)j~U~^QitGCO`X8-4o2gu|`d$mQh|T2YtJ1wN%-2bJCMGzR$29 z-(~P>6XT2mt=sxmdA!v48sO@5T5r_-y^!$_(Zdh2Px7b-o@^l>whK`AvS=OkllWQ^ z^=h*D^oo4L$l>NwhyJg*ZWx3#sq;m6R0SCa7)y8cLb|jtw19MG7#|o3u}P$!zz0fl zptB!1KH0}~vb-9{M${>MX@cLmVIS5|68;LI!*w@8I-3=MYOPi9X%N`AOI8 zE#-0#Z9)+jZ3TPF?|H8#Tite0?yT>csRrF1qCLr?9`uB&uxhjnuB_j(E{CZ5I<;$o znBLXEx3DccI5*9rZuGxs*>BmFjr4(-Y8h|I52CeNcZ|@FD%C-Y$Uc~Nc)%LMUs%FF zwRISt^=bT@LOjbEMjGw2oCJ0We%z2!_uo3z6!H|%pOg*9c@A7u=s{TCdHCo!D1v$J z66)lJjPHly*=V_+FdVRX0v;qNUb7Mz|YoUPk@!&61ueq~%(H8sWReX{0KFx=k6=+i>Ts zL9bBH=xI2} zsXw`sE1iFqx*c`$7X|bcci_7nxM!#nD|4+($+}SLX+X}kY+Dgn6?bh>skd71(ufT% zg`|WYtwmbD*Xkpse)pTd{LO!y={x%2&%b`dd^P@l6;2z51((){0BLV$Fe&H*L?cAI zG)zW;r|Q3_Z{M>vq%5;Tbr_*&hr(qfVunkKZAdkijShSVNI6(6Z8EWPVpy8hp`tP2 z0Du}K%?=~3LdjI4k?iVh+mKoZ#vMk7*%9gpcSKNxi7SLFj4P62aVwKJ%uVMWa_(X0 z9!bVla5Otmr;ynZHaj9{O`Ft3TA|U~Hl%JtCH*RNL_1YHGPWy~ zOFh0Jb=E+apebl~#v;W~z!IpwV!G;idvCM573HC2~1~%IrWoPat|cnLRNP$Ag8-5Neo^UG`%$wACDPkzCBkv0pVjT!hUd^ ziGn9L#uBN=lgZQ+|B=Kyg6MGKQCM*N?qJT;6RAs-eCiyVnmUL7RMylJ$+dKWRio)f zO{HI%59*V8g0^m|HI|^&LNEU)Dkj~YG}+@&hCtg)C=g6sXAEQ*i&XuC?e!0{1)c5n zkIMfKceZ1YNu~~{tqf+EI;2dt*WU+Ih71BfEf%p;@Q)^A;Z*$-?e(kj|5HMQT}0wf zaTKQ-uftX@(p)DyQM3-;6Kg>xr}UQ-?e$N447}RJ(uUdAUVj;KG20Tb9IcU7y$N`=4abz;-@`Jg=^YZejX_3DaTD)a{LLMd5wbztt+C z`nNc(n=*$tz8#JtLdts{cCNj#A=YOYMq9UvB#`BKv@ccvMr#Z`O65$|e?6Iudl=@d zq)7j}p=2V#j{Az4Omw6}G%g*K@OML^=^U@XEjN*sh-30>ufJiW(#&=f_qYt8H;@wp zMPj5{A3~_n&Ul3Z1`KwVRr?UrGbe10!>cQ`o#os#1R)O~!sH_qP`d<~_aj35xWjq7 z@cVcqh8fL*K+R;Ew)y{yngrv@-uM8N8yu37_5+@&OeT_!K?D|{Chl$vh1hxBMz?SB z^w87xrrS&;U}IqN6Ul_fBav=1kIjG>JV?9$9NX?;41e(>F-Ub=y3_dhXv z9D_L7jal{|`dH~7CM(CAWv%1bypm{dJb+t78Hu(;9GU=alrZ%A0gS5zd$REWAgG%$ ziGrIYZ75SFQ<8`l+ zuP4*+eQAxBWsGBpnp8ZbLFu)&iROOoSbnK)rpp*8YdGHiz>gQQ)ozwQGdBbnSk>D zTQVrYLVOFdiis1`VYH-CNr~uCEio99&q9!J*>r|3WJt%tGS38L_L3tr+>tcc4KKOf z@KQ{LtTxV63c~tEs!?OZ6FX^DK9Op?Bh@&YNOnaMsm5dNjVDr#3|o_G*i`fcsQFHl ziyP?PW6+RJ$h{L26oUEnu?SQhQ&3|O{}Z&u5;z^Zt;?;K9t)`x7OEo#_ht9)CGjfS zg{ey!=p&U7jZ};pWQ50mrym}%LNf2_L zJRxpO>cricf2V{Ugd^Ujt_qaT^(OV;##BnTnKx)Q{FI3J)E1d7Xkr2>X<{T~CE(|4 ztN4nT!&fl;P(xVBf56m(i3JE|VT?K>(PzS)?N)6xT&ARXUe7$O_s3c+OjVoE(zt=y zr4bPrhrmgT$Q>eQ8cu2Km1iFiN3+poB&pE2iC)3vW9EJnBx2BB$=^X2T-eIgf>NlJ zQd$emAd7`zZ>44;ABq7FNJr!B0jUEKsZ^_zNfLgbUA!j8?~ogd|Dr5_P-(jHO!(|5 z21%;1)d>Tue>AqkN~JNCO6Oo@M0rUUz-y8|p!7cogVU30>`2wWooeiMD#JT# zw>#D7$8d(uK)swcNfag4-q?r#-gwg0lLDGhq(cU`i!isM_RpS8HNJ~RfjOj272ypk z!qr~t*~egdNy4~mY)x9)@!0BY5qz6T>ffdrqX}RqZWU|sCiSBJCVT`(&}hMq_Gj&Y z=y$uK7lfkU?TdalW`2huH3BYApf5iZrSk&ch4p)?-M8Wp5xWLUW5b5w}!R;vD95k6xmeB2>24w5Yp5|a|&PQ%0WuvX75JDRoqcC9Qo z#m9EZ-3rSPodT;fT~4>sjR$igahBpX9w=NFc$5|*J5y7+v^|Kh7w+%+uI+<96%F#R}8Lo{k0fc!qp8AvyT=~&d&Tti3~@1~1<paQDG>a z3LgbMs-G=|5k|6bj`Sbk7v^_K!Ote38-6D;%dtRL2E4sFW0pKAjdb@Q!1>h*Xy+Lc-e zMKQ%hQw7#Y_MBLXw-wOp1oYB$MaWtak`lQpclnrXa2>Uz?~et7gTa^a3xM|<3?$mU zqFq1MkB0vm3%@G)Z{y`04nc$wN4wC@;BdQ}z5Fv;X#3C@oGf6<)pvDF+EM%}sOu~17 zp@C8)TT~>K>*8zypHji!!=?)s^DqIa9CkQVIJJP){JGXHq=bn^7Q|vz6ynM|rm#f9 zB8de}p&-?jnu7l&D^Lu)PO|Al0(gX2Y-7=lVS@RAcr0z)RsS4zVD#N|?%Mx@T6QHd z4>N@`l4PFeP>Rcj8!@yom9}&$^o~pKLIfIy)iWCNABXc{~Pg-IKevE;>EYgxC$R*S7)NlvN|`W`V< z25g{EjF=IEv{r}4Sp`YxKYt5NOR_(Z6mIsnF(0D)Fn5Yj68Mv9C|jmmGj&)x1ocax zW>yk)h1(sAg7{-Ha=s0r08q@`=2Mrorpbq*Pv4OR3QFfk)QF}=B{ zY%O5V4Hb~BOl%Utx4;6F5L*T4UYV$gVebhl1Uk^ zCrmK?7y97Pj!taJaN{Kb+qoV4wgd)&Nf06k6GRB21o$f*$_j0l%fvky-wy7gVwQs? zkq%>hJ9OsS0ZzPHfwv}**OfKdP{N>hMwstq%iw&3U$=pYYs$R+ zQ5-@(g@d{78?SgT1)qw*7vMPu;`e}|?&v)=IyH<}o$-3+ea_qP4_r9d+Xn{8+q{o8 zI3I`RM-MFKNFznkP;njumN&JPT4$)3`!Ng&^!N7hAC6}js#gNL_V*p=%j~oF?aA#u zFv|})?#a#VAIRpief_g@vvY^~_8yoU*gJ-e0sM^;{8@@M^R51nF~6j|>n%SmsL=EJ*TTR30*A!_;ZCg%F?ok+JQpAH z&Y`j!G4f&9m@lpKgn7u>a=-l(Or3D_3W=SJ%!?yDI^znQ95-otRG%Ra^Bi$ljv#y4 zrC>KZ>i~_wEskpO9Vl2XU8D)3QzV*%fJ;Xfw7CVhRX_TT!QbKg$X@>*A)a6F4@@$yKaa1w`b)gnG-Q?_mSWC8R1U@Le?F?ZuhbQ+XiJiDG|)W7`x8A-s9PQt>W zzOquHX*i+WOlP{|xXv9l)NLF_&hNGmj067i#w2?A5u8su18f{8YfkaQtAJxXWrN?V z;s5!MG8m}K^3!*mzK|b>oHo!70k;uc2DtLn#2B9P^8~{HIX)|YvuI_W)e`aLu}kfTWDelU zsC{VDKD7rW?FD5P_(4dnUnp}(H-Pf-p;@HuN9>$jhY(`wImGS-%u(FP$Nm^ZAMhN@ oB2w~%Xc`*1vS<8yuz&uU{?Z2i&XiIMhyR(@?_a9*|5XD22l=Ew1poj5 literal 64512 zcmd4434B!5**|{nGI!QYa%am%$U4a-GZR)7aDfPlC@Lt_09uKF3Zhps;1&{sEP|p) z;YC3dP~34xs}?O(v~}O8+6oAYw(hl}6}9;PKF_(6+^Fr__y7L>zt4X(&v~}g(y)QXnb7gS8UpknyRr&gSAPnp_~mlvpUOpiWBh*63r_WW?`ow?NZ zh^mU9(npB>;24towW$bE0lWgC5Cx2@(r;pr|NNT-Ir#L`#H59!O8<9-4oNKhHp1@7 zguw2FR1iP@4OK)4yv5M#@nhM)qbr2)x#T|3$GPZ+SyL~W1-jtx0FZHB9lt^GuR@4P z4K3N0$)MOb_{bUkTFP^9D5|TWW$FwYisY++&s+xI<}_qDREVRybA)({$`wEIO%)z- z{~YjE3L&{H`X7OwYHOhofqH~R6#hcBiV><>8?jZrjk!WZ`)HyOmXVIB%?2zDs7Av8 zBi-97Aw{-gFtkg-NEccte()*2!O$)PTA!#dtbeWI{JEi9D|(F^ck2XKbh{@MnjCgl zY`dJ;_2h$BoW=PTW~>E1Tv&8<7%n9fGWkG6Bxj;wl`bWa(Q9L=;K2mpb_Gn_oGg^? z1S3jvrib(hI8-bRts zu&0e8sbQmyBXPOjjy!2xuIM~eu7_U-jxlH%pi?|#(qMmN>0a!VE~R0#66DfNpJ`cS zzLgR+7}~vnrbk#PKk&&3gQ1-wes3$yd~(WYC1_`eUuZQjpPV#W3EI5@xc1oRYvCLH zDvpe|T-U88$BNA%>(JW?c(QzYC`ELFKaqMnE+IWtU(1agXmOU2GsJOJ6D)_e$sUHzNb zXr;{U>fh)E=->IU@}vGu>P9QU?){tM8*JO%zhe*VJi1$};D|r%-xT{_^zVTf;Jf-a z#s5$0jtu^Hb=O%kheDZ3<}fE5=!AouaIg~|?u17;;gJ+lnW;|H<^OH>!E15*+ zCyUhi$s%=rvPhkuEUIB|8(CDtzBaZGjn7ds;Yd1kZ{lq15K&WJ#s8m$E7h%mw#5y*3+ zl^~A@7(tE#uC`K642Jd)pcp}hGM{p0v=X!%0ptiG+uM_HoPHIVEgM#KYb~6)pSBjt zo@_1M#t_cbPsb3>(@)0`&eBiE5Y7>gA&%{?Y}rR6-Q2u16u2t$GmO~W4!q(Q7<0Tl z=3It$+p}}bp`83D?Uu6k-?dvBb11L>$(Tc#|4+soDvkeW%%Sr6Z^xWu57`i+M#MU#0v0x|q1TpN> z?{7m=y`3diG_MkwJiYFUI-9K1dWJdjf7mRaa_P5T6-R{tYGXNG?)m`^cAQ4EZ0y7(OVf^(*7od_gtSSs>apT*KUfIO=9Xdt11 zzok}R*c9~odWTi7JqAoGg#t={a#0BD$=jMp>N%M$C?0~qJ0z$`$9 zPKRd3XP5;tYhl<7n_)BWnrZ!>_WFh#b?}ED4Eqcy)lXNgUy^cx3a^4Hm8)8Q=0OFE zb~)c+o)K8xn3|PADFxb#QE7&KCdKiphCPXlQ2V(bdi0YmrKFFl)~hY+&H?hpFI_(N#8;{4`j~)$Wx;MYDRTtzznX5hR}M>B_*`TQ0FjYPXh~$ zNj880D(h8EM(Zo1<(YXhTB+a6v!^=-@~YRYrr+KnKQ-`sC*4`n02+Zb@Jnwi^?x&L zpGQ_s_L|{h3v;Al&j20GPt`>7t@8;j@S6plNfkIr{YfSToeL=X>$}5|{DX-y8pLfd zc6Q6e0>6!(&IOX4NhbAd3k4om>CT86emhHCbKpYs{)lPKA}SV%MdFc!H5-H(k4DTy zH0rn>i4@uwfjwv(^vy#1V&F5PMV+N-8fMXWhuSlw$;?TBPi(R-A?wA6b}1nx1NWop zMoO&9KqXsSiC5Y>hk_oybeT_jYL?n{*=|*5l)M4=owuC`QXM z#*{`X><+}MCETnq%bVl{UuxK&DW(!1=(Vl_W4LZ6q8pE6s?FSus$HJTF2x z7<)@UpcYFGCg7A)i>QPvNM>WWfXqCYsOXeod|C`yCdz##i3xcCT2C8zdcAthv_fkM zq%)#k=v@iS(lDDutEdZ1GONts%4jv*skWCwW?xOJrgvhr#?+%pvpQO9CQbgcuYstu zl&a6>-y1{B8i)7I5NjDUP;fHqxxQ0{zH@!{T8N^)>~ab)^0)sNoO4a=FT>&NuOLiz zki^0ukg`{ja@|0rE6h3@{6N&g5WEVAr=MpROga@Fv8?OBsa zvp%f%KB1Fs))zL}t06GamQYK&qi(MuUN0EC0Z6g67EskJ4_vVf0$9!(_D!TzXRkvr z_-v}EkXe`Zg2SCn)__wXZKzE>36Ix9xee8)*9*}&h1MTnpr^o~I2>UZA^nK|Eod+P zu+7(vPd)K^{FVKP??+K>K)kyUhR6th^enRnVII#FCnB-58mrgJPcQFnLpNaG3;_HV z!fC1sWH$l^6QO}91EF%M__#cht?2G@e$Hz}M@6L>wJmRB7V88`bYuKR%PvT* zTVb%oz6~&Qq@P)a!)qp9FK1Fs^sO^>CoYx?KZ%_7d42Znh*9e+Yzq0LYrMD`G7hEh z#hl?0^(YsVp_zRhH54$MNuv#QtQ)NaGX_^oy`)s09x$i)ymESQq})hDUZWL-fP5C! z8pc6m2er&Q;6O5}w~@fqEiYPwX8EX%-VI4!sx|vZsA2Wv@!OlgX+sNglIB^<^c*za zAVc>+Xkn?DN@k+9+24VcG(D}P-9{r>)bL3cWxJFT*)9#Io8fU2&BWCh{jx1yMr|?R zPh;$MwM3ag*$}(8L%D{%L|myV0n|C#j7PkJkk=Qj7+ZBYJ4IUdqB=Fnp-N48xcURx z=gE7u74wJQh7m?jYBWka(R`9fDX}(;IXd((-RNysNj(hMx~F0&s?8b*D{UBhNCi`f zo({`Uwib$yA&G>TQ_xVzgEou^#G&TchB1fmS%hOmARN<(-iDDzPwH(LQ*>@4bCFm+ zwUPT^A)xVEt)#cXi|Tqwmi5*OQ%X@#OYq_{r1HFM-;W6P0|0pg??eGbH0wbSol9gH zcf9ownBKm_opvp`eOpaklf58)p<(7GnLR_KY3ObyYb8oKCcZ35+++bYiq)6m<{4sCpy&DAbc3 zB(cyYQtj7u*Ljt69%CJnSZFFK-NK-gYQMg_=4+(+8`dO=g@Gt#p@*jGooA;b#FlU5 z@D}Z3h7_kZ{WW^TNE; z9B;yZlQ*$4s^i%tb*h?s8qrLT^PF%{NgPz7h8KlOyp@Gbc>Dmgu$~A21@cGw7b<}c^Yc1$W)kZvWEogY{-@-$!pSnARhb4O}h>VZ0Nx-0W0Wn_1 zTEXL94YFT8Ov&rL@}WbH1N}t*sj@!k*?kE5O2qA7+UGoqVj5BZ^)wRnw!GiDz|Uyj zRK7Ri<;p9TYy40wFBa8fQIEj`oV^V`MvZ}(B}BxqFdX6`(Dd?9As?Z9n4{&y5(CE8 zc?e)$+HZQJ{$1$e0+BlBDW4P?{)}dN^B|#d;%BEVN7HBO86Bo{)5jB)Pp0z}+;JY5 ze0U-y4G+BB4))-aWS=q)CJycFQ~qSeUuz;It=9C^oBmu|KSw-Pp`h_Y5oLQM$~NjQ z+l;~EX?^x-7!GFNMAr%V5^Y$0=mYY~pN7j?+X=KuSZt!K&A5 zR{-UuOFfE3w%d(j;tz5U=E}}J7&>|i$oBODVo=Rn7+o;-&>UBU@{ghXb9*bY@YR;@ zkeL=u!^-8wTrvTJ+pgXRkB^Cz82MLf=nC(X>syuh;a^ND?$XF?T(Ajbc(D^O8ceTrg45>03V9QKyqrtS++JkR=hd5} zZoh7PiyA!k4>U1dM*-uPEe5BfkZSX6VA=Tq$(DTBkPj@$mO>X^?!xO_cyAYemOW!kb8E_|vB$7y$Ge`$5$SGe#ME_{Ovf53(R#)Uua!e4aZZ@TbzT=<7B z{7V;pz=bPDm!EzY9(CcRF1*@>XI%JUE_{d!AL+u!b>bZuWAyqeHD(=-@sZ9BG(pSk zIFHfiV#MKR*R-x(lhJUeK(nw64P;*f2&nBPG&bR>FA((Fcv7R&84HhMfujCnvu_~G z1C1G#4^J#ic38Hj3M0COfg1}CzlmdkBap0(u{i+t+Xymyux8Q^CTcOq$VVx^y_3|v zyW>8o4wQ}*yi#m>c|Phv&+p?z&82c3rHZt;aBc34K@;JjE9$P=T0_PZb)9)kBkv8^l?(gFK@5-QdQ z2r`c&FUrA$)tMKRaBl9b6UWcYt@$+38}lMY`ka55l=Q;!$KXj9_gsX)@Gl<0-yZy7 z>JcbY0e{87ZvndHfKHz{3z#6&ScdL_8`#;GE_*o}5%15s?2#@%FPE%tm$@o~C?c*( zf5b1V(w9m^e6lJ7UYt2lamt$X$(q~?Q$BZ1dbuX+^973eFH}B082u}ddf!qM40hU= z;z3fWPskufnws??6w+S*Qmil)aIB9&FTIF}7}j`P?V$&L*X;IY_yRYijTBZJ$pP_0$l;pRSzxyWJz!gSWHsP%Tz6DcYdgpHP|7^X_)`KQ_53zk||)4-MWQBvp+Obs7Th0MTS_=()UBM=POO|y|S%LJ==-kITH@fX` zLa(~)T*W%O{;keAtds9^`STMy!&s-kTc?hEJ`!dF5T5!WiN83{r{rs-zsZ+fz z^EocpQM5fx3L9Jsc=)~Z-zu2x8H)3AR~(-+A7W31?l+riz-W1=%Z6SUOr37DcmthP zL7d}_mQ;7nK%-?$cTTO*vZ6aDX0*K6okLpzoW4g)MEdk=M@P}s!s+en5%Ou;Iv@v) zT_}?*4w$f+OAw6?uJPz}l(x+`NDms2K*RF-=sS5qSRY3bhWeITQxZtfoYovzp< zk+D;m_P&n#E#1}kbg7fX@oWH49kw@iSKdp?A^#aw{p0QZK#(i9c2|G5%Qi`z zj70nR1QtF5>mXCrXqpdu!baFjI~s-^hDqEIv+@yAo>h^BE>=`D_7s5G_B2dIgxdCd z4z;#FaHzLE$DyYU8)cB=mLayp2=TOG|A-Ky4ZBZ-c-x*~B;K~2!#UEV6_w)`QC6fg z{UJyn{!;o;N`DK-QQMy2P-}aV!+6_oIGiKJR!rI=%8EO-0^(_mh4kYAD#knA++^Bs zgPyCsyhkOMK(u5BNh~~jrP^=ruCuR8ha~NHbQix*;zBk-5(|$yDQ+|Ec$jmi^+A^% zlE}2~>aO#bE*+Az-`!pO*RHfkBGaM<*S@K{;)h*!NFvj^r@PKaT{{y=vz*5J7^B#BImdTslI-4#FYQY49m^>wQK zq3$|Zp6BY6B)rPE@F0>ZFQ%6aQtg|&>wiJ|C0v0dq3fA^ZAY5#S1@qQAQv6v(lI%q1}6Lc0cQ6O7El0v%@frb8O7^<*;t3;bIU(yI=K2w zJVN4?i_WJS-s0t5X}n>f{Vcmk&v;wDLu~B-<_E=vHz$j`o{HS@OTwr==V{5smydRI zuMA_KsGxCF-b*Z+dpLZxa0@d~OSg%PWP+|N8TIW0DGzu?>;+NgU#eL+x91&?6hed6 z^+rPD%PP~y2fh9JI%YIGO)1Phsxz^FmG0cZohs6wLiQ(V*x$jneF3>B)1g~X2A)kl z;#B0RvNKPaJdN{~@#u-^eH14rSv;p1NsS(OjHFIaI!2P6r>TRSxA8b<*co7RkLYwk zKGW5}epRRabj~CShjNt;&ONd#0_}ZuK)TsWp z4IH|3Z1q8Cl=97sbPek`%!n?N%%`iNu4H|Dfgtn5?tm|C_~f3J*SRN~5hG@G?O~0E zZ^)0C2y~?#Or^Y>c1WhBvI7xWY3Y2N=>%M9d1YEJy7$ivC#^hj*zm5j79g!8(&BQa zd{H?g*9nzdh)j)hk1f4paAHpR$2~SW5Ixbr##3L=+@^ff$MSeogTe=S=5MAE|OPls4pA~|LB)H7){i-4?<0;cjBG#n zlI$Rf-5=;&O!7{@(d+?W)YI9ZM)?)BU3HJP!Y0vH4uMiSWY~uytlh2E?iPr`XJE9u z zqcX3VkT(A~rNnd#cbd>&X>jNyD7{XClI$cX)lPyE&Jp$Pa(q1k);efJkt7aK107T@ zv{$T(8<27x%B(_&t&!;+Lm@!-p5wv zQlQ0*xlU+d)YC~S8_-;ud@tZ8Xj#b1+!2V&<7&lUH6(jR#zQv)jdscajjP8{YQHpW ztnrP^FWSj-T!HXnS92tC(oT6&(FKnswM08*)^Cph;h@I><=*avE(z7dCU!*q8(wo;-U!O!PiG*I#wftO(JooA0&SYz(eS(3{Z`DQuRH zM5+PJuzm%bAz%AYSnV5{dqSu2dYL`@c=FmwTk}~bkl$38)+k_EJkA+;oMS$OHFb1# z%Jjf%QFxp``$XssLMkrOJ_)?2EI`wUcsx=zCS}r`O_+;r7 zvq{|HanDG{VTR-9&kF zy_&(U<~l!jflh+jXD5N$?jooXIwjPWazs}-`GnOc=cgtvf}fC?*?iP_plkFt)UL_3 z?R_#7l&<3i2wW*N@G$6{-dAAU-d zF$mG8abgkQxvekZ{!-s>F8BJgpg#?fd5q%74RSO zLYt1=2H%h5)Y-E@4t|_bjKa#``xu>1=tf4*CUiBU3kbc2(S?LU3l=T}nrT&MW9m>c zS#|bo3eQt#UqRtyb@pNkC#tj2C6vsm>TGHOnG@96Cs8;|ojsbu!`0d7+DfLsI{Qir zd#kgrqOeY#JrOO4t_EewQ>pUA^rGp`y~XJhnylq0m-_Oe>GkCm_=CuE&2)#W&c=ML z-~}?jq3PC2QdDP;1q(NFFDsuk9hdR!$*Aqm@&%xOmD&)L>Qi} zso-mcO*&UWj(PTvnEEJGzPh^tcGgjsyl;2h^v-S~Yq&gvQPsIEYmyJ+zz+Ea6=5cm zwJ{it8Ys=Qz)2UVA!_kh>S4hE6jo(1^wKCcLt99{G)qkS;WSu30q&@RTwGI$e1P@IuR} z4o=v&ZoGY}FOyfctuC(eYoo!#L3(y`t(P$*f3|iZT%?PM0#MUg*@kh`st=T|v6~GnC_*bzmlCkI= zIf`ZC7B63q^IkJ;$XZs~1CC6X{ zjHx*WBVb_GlF2dx#yL3#BVe4HV=w~7v>byGFsA1ij2y3KFGXRs5#el{LFc@j4kKX9 z$T1iJ0}CVR2_s-!kYg}%mTFPQ`AMs(KVIeAlx<|#Ne^QTogH8jTh-|&FNBX>q6VR6dhmC(%imukV5t{DyMmjwi0?d zM?*~nvU7;WxSgjT(E>*ESb{jj9MZ&!bO@snznHJ?+mOik8+Fb(9Eb z^sxg zdupv$QRWaXb;7GTbYirq{Ayb(^*h2Cx$L&4BcY7V8!ubPTbPG-b_Df~vpmcNEBj zculpER5LeGx~(M0Q|C}{Fg_jba?MaI*trdMg1bhsBKhZ}dOO$&`wl?9NP8zC_}G+n z7m!S&T8OIUWKB=oQxr?4>rpLKY-(36nTYyBFk^^K!s{~Lk+^$Hv=MAOOjKcM0$fXfkXMOcI|_oIG^uX>2L@P`3R43+(I z3yMy&9wp1vFLm**kDj=xUv7s8yFH_f!tsT}{)i~nnHWRln8$6K20iX$JnA*_s7H}h zQ*YZrp}aAJ=@TPWYS&e;thSOM3K4~_agXAmx6-(Ws(uC(Uhiys2_eYeQ_xC;H3=@X zy-f5Rf~}7uLdd~?Ly;wW3sCw*ihVGl*u~O4jVBh=r{MdpnR!0B<@1 ze;PRAK0~bE?2e$xOI7SE|&cwY)FiUiRjbq<9GyKozP&EtN zUWa^l+w2oCG|(K9NR^;+$Xl9kDYV~!Zc0fc4r&L@T35HD?++OVOQIz|=Czceo@K{t z83L4FRy0epZ^F=JKVt#KLteDK0YIa>=`ifK5TWf&hubW*>_35-p5r29p;_nfK*ei- zibw^o0ixxRa=8d-RB0NJg;w777EC$=Rk=#v;Y#g#7fTVfl?2gpbq*GItFrJ)@wu4F*{eZkLO|94i5=8ZN}*GFt$3PnhP6q9u~Q~o zW#?q+&&Z$JO1Y-5JmF!E%El&c`q*--DEl_BXjP=DWgQjmPEe65M<0v66a*i43Gm&T z-O#Y!VKr+Hf)qA}3#FCnNOjAXoyyg2E7h!PRyxU3P4F8S*{?ASTqaAPbhk5penuk( zzG%mu?uDxTE#2E+xZb{grX&t{1+g^dabIS^P?86cDVoXWPLDx6pctRo{kZa1$7P$eh1@&(P_XU zH)SU^E$d_CZFl4U!iLxS1ST*(HjY*JStf#U8HFPzB8(u+{X$q31VPXm3u6Kus474O z7Gn4kA?`VWC_qR*;^TXXVlhIzUEOI1sse91^Vv$3j{P*y-;y!>a(uk?%kNIm!0YBu zar7x&608AzBf?1-)loj;FdE$vjy8B-OLQP~`?J~M@B0yd0qk5uK4L|dTO*R46T#aB zS^barA3`=B3&^8ge6Z--o#IsRCgAT_;6vdjp7owaZE4o0RL0ny{Szp@Pss=vf6g%& z0psl)gOS{QN>X=rLmILgw$?kakQRQ3)r6hJsLF+qCxW@_iQrP**TpOw3E3>49 zugsE?%C}V7SnpWIRm+Q{tk1~#2D-#BYkaoTX>>3)Bi~0Va;a7?jz0DHqZQc{_~P0{ z0~-1?^zYNZ?;wip5i#k2_WLX_alF zdc?Sq!yy|A`g&xb`sf+Rvf*-OVXK8X7)i)t_E?rS`TKe|7kSZ=wK#74eTqY%4Ovd4+G`)#dvW1kY!9CBs3?4>0~gf-Kw{Cs=DeUt)-*uw#hN8IDU3 zzKf-&a4Jtn&!`FrLto|(hy}A3;Nuf@9#-0J8awM!1*p zy?~R2(L;#&j^;u55Ef0fpZ5rhlT!rC0Iw56U?(DC*6PyhL+E<#@Y1<(-F*g{zaSx7}F#g!=ko?<}{!sDgS zmjpxsmvbrG`Ka{aq#@D`1ZPGGo?J=LW=1DWIKN; zBF>ZL1gDn~yaArnik4_8%BrQ3QvW(b{FSWJw~jo#o9!P{`+P~gI3!8ZR<=C8g77!k zaP$J9=Xs3qcgp;Z=$4vx1%ydX5##C`!}tHtX~eSx8K5bntS zk*NbH_dytq-(>0v*1Spl$z^4oc$;OHdW84_|GvprObv&XFK~MI52li^@&)`lz|^Uj zGX}xNcP=YC;U)Rf#IoJUU6-HlVyBm6hq5p4i+m*xKi)$l|3Z8qOr=u%Jva>Y;|q-d z+#VwQG{%RA?gIX&(7k{I^Bx535qbphggnwo=8=9s)>j!nkM+M~{Y@d#{}t<-d3}+} zoX{c4n2yQnd~-~P*H7>ki{Jx*eZ{lIi%e6Tn_2?=)T(8GZ`G|bD@Ako2Ec0zZUWp^ zu-aQGD)I@p3pM~+bp)HkcLDBV&0iGU2V82d2tNdyBkF$*IFI2}hTr!h&i#znFxBPvvy~tgHn-g8hGxz5TPY5uBpPYA@Nj2l@@l1Aup^1jjP|664qE zzX9h)<~%B%2EIroc!B;J;0h1nDTClrgE&7hevX$oo4my7<0D+*xD_gKsyXgBj=SIU z4mjr;UjRO890VNZ4dSykx5TNezAP__Dk7$pxj0q8x25U<8%ujb`j9>V@L|spfF~M_ ztbZ)v4*euoEZi~_u^wdeelF)7CY5uqx@PbVuDg3<#981coyUuBLMwVoXXu#*YZHuF zfcF}g0#hJ0>4GRMaj{c2dgGY&8wcId&Ff9 zb$0b{qaJa&Lk+Fl4(dvW`l#+%P``4hwyKvvt&tRbdC!mUk}@TI35o?+*9-BCAYVeF zqFPeqOGxyoA!?CtLwdB9Ck8syuDVHjo){`A&R?ErVoKV~7q>bT*(?w{9g1ugh~sI( zgU#Pojn+(YibJi1O;b#8sGE>KQ=H{cS0jI>nC?(hlh1-`ai~XXUIKNQL)}~VI;hJX z>f)NWKrNLN{2UcD#ZIQApT*)2yn>Q>FA*#0p$a8IewK)DuqqH(gY@h5tx_t=v0@-< zw7DzVL(tYfQ4`JgqGe)-LoF`|s)~XXLP0e=&TZq?V?SiXAHUIn=Ks z$HoSVq1f)B+?Hjo4-OV<50})PRik2ui>*v87cJ>iK7>q#4HW~AW=-+7d3J1=c*~(4ENqD#Bl-;QvU03Ajj2VxlhKxr6=yosFC&-6 zjuq!R)U>*B+6Zx>LtR`qFE&D4>QKv4i}5dv&2y+5QcGgTi7OpyY}q(%r1+IXomn<7 zHd5T+P>=aj2JSZveGPQfNztI6*wuN!=McLF{)lHhG zlf(drI;Q5a*vaBFN%{U!_uJSQF~y<&m|CHX5i=d??t zi9=ET#)##Tf@d#6_LL(lkN-I~Ry^M+dk54fOf46O)_)pn5~m+4>!F3I7aVFVQ%8)D zvJZNZ=0=CQj%6rB{FaL_QwtpGX{Po&)F(_$87VdY;{Os>);rWY^#?%dqonMv^tZ}H zvB068F7?Jw7oRxPtX_GzEWGeUsVORB@n*4^sa2xGERLTg_BhmI{uJ&7Orq@$c%}!A zj<<+SOsx`|D#yfUiMBB$TP1#j_Bl&zVM?~vS)%?Fk}dMxXO7cmiGB|Cm^m*tOC0V{ zqHM94ErvN%ylhEqwixA5Ety4ui^N!mT96qRzet=RDQ+(piwl`rC87;y#4i@#J5)i> zv*UBbE2m1&UWlC^Zx?-Vz(;;2iemA3Vv<9>*=tt(a`C-GEiV5wI$xYSPHG+3&rUUwWl~1ze22cC@P7?B6gb8q>@-H=sH5K-!2x{cB77KlA5o@<|5wd z4%KWej9)2=#!Fe&S{h#}uAjhG#N>up{2Ea-QOamkTqd?U)bq&0GBNgaDXR;98ogG0 z&(w0UqwGUa{mx*S?~fQUuN6l*)WPas#jh2|JJer%t3aLOP-QhFyTGBouB3Q$W0ywZ zwRI%B!l7+G+*QmDf4c7gZ~iHDaAZ zX^^cEcR1AZkli5ecc|S}3Z6h8bEqeL%e-sFHivr6w_+jn zLwyC=P2xR=`T??=#3v5*b>#|Wo!IYC9;CNU{L`V<)-4LG7oMpyN4M5(i?0`9hq|eH zQDB2eIMkih+u|EUxkLRTzRY{GsB@^Z;#=Z3i#`tJt6dbhMGSPPMD4ctEuzt(o(V1r zY!o9MYDaKee4{wUp^gbW6TekVaHxraS3ym7sF{%6CeCxHg^=AQW;s-OdQsqZF~^~L zr?A8@E_tN_&G4mB#hLb*%) z&Y>oz6>*n%-l6uOl7l)FSrfN#UE$nhrIBDLJ-2DNgMso5<9Be5c$@JSnC))Gu)Y z`&)6oL;V6fsawTthq_QrC$NIWh6?26BEyh9u9Q@WY3E#hk6UL7lq|eYxGkSFN+3;x*eLYiUAJwJ25`-x;WCI zu2sh;c8Fsg>Joi&;tg@KL*3{ZpLkO=In*J>_{3YH*`Zb$lM{ay(;dq19iMnxWF2ZI zsGVYtLp|c1oY*ZEI@Dm__{2Nn8ixwOmp$S-hf1lF6Yq-k4%Gl(-V=8^)Fk+_Pdw;Q zKX}ehyf1$5P+4P6;sf!DLp^0IO8iB9;!r1fuT6X?zF}&w;=_kfKN211Q(5m-j>0p2VFfx20K6R*6U_;^y@s&gMVCtWeLVCADmYhTRTjU!M9H;FUhcP8n-!Fzq8GE*0 zjAClOxE|*V`^B{mbrDW*_KWLXnqP_aj_fn#tNgEET@jB5>BQ*O2;m0{DMk8WL`xEX zC7u^GaS5O<#@Ep)*k^!-n1`pz?)s158AcU*A??oZjkqdyV93rrY-c&!nFjlK>aU^m z%m=~o3Hmo+yT`S#BdQ1qzrhZ#B6?*AUKb#kWDj>$5Z+iyFv1)UpeAkrUl&Ea3JN@8 zdl^Zm`pFaGV}=D(Atih(@~#SB3B`IQMzP9aA*WB4HSr?n>kZE19cDp+CLSvyo$_Qs zfyz?BKSg}c{A4jn$y=3mG%*sKoDO}S)Qzj+g-X&t89u1uW%ibESsMQu_JUVAJ6&bf zowJg2N1Dh*ifo2)7>=3+U&C$;<(K%mSogzERSd95^Eb#Zb~@NAH@=Xqkp(GLu){;; zu!Bp+XecPqVVO$)-dI5a?d=p4c(Kn@P~gLk5XJhR>TiRGs#D96gzXkrz&C0TB(0|f;NbV&1UZig}!?Z`+Akk*hi z=GakTM|vV{cHxS+t%70==xoob@N!9#4&MDo32WkVF5%5w+HTHIbN7FTBg=u>tt#F? z3(>@Ts3~2{Mz8S*FZk&7XbE0n1Ny{ZaQwKWLOC75?feY1d`%oc-ckEpw%;?Ka7{eH z`IS9)DEE;|xNP09xF=bYIufSY&Uo&*S8(h7-{6I?FMo<4+ztOv@!d8h{&SX3;+E-# zKdoiTsch${5gvyJ^SIZ}{CG(@&YLRmSBXErm|Cget(XRg)i7XMe8_Y7hdg(O_$(^K zXHhfRLQD+q^-KKw5%<-ci!VSD-h=TNb|WtVPH-mg#~o0;)-t@AKqpuO_ylW!pcAYC ze1bKAPp}5?3Dyy8=Lohloblm|k79fj<6{{g%lHwT%5a9G7>;E)hfl)h@JZMLJ_%bO z=p<}`pp&o#f=#v=t3MC@*js9#Bs%UZEUN zFR3k152&9N#nnODzDz0bJtaxCuQsM41^7q61M1_w7K_IaOA&pwK(Cbgm{@4`0YB2~ zP{6qjL(~_<{>(AZ|JF*WJFt5-4xDcS6CpjfxLF;e^(>vna5gx?nyc<)ubQ>;l1gnK zEH`Ke)TKD?NT!`is$3;GoHWCnXO%aJzq+ON-HpSN=!7eHr(XDRE<)D~1u@oeY( zu7u7^&m8t=DVNV$wy@E$b5YTH&n5@YSUWw%+M2XtP|3Way})Jl0@uYBuKmqypL`x; zY-VfJ8V$6`h2~7-F;NklX%uUZ$1XOuu+Q6BpZM#HE!;AfX#X_F7%w;}PDwv$98gCV zy=pXTO1u)aGqrNRQK=jkH@uZfuT+7zm$KAMcy~Y_Crip7GgaQcuuSlDNOy3)`m!fG zxSR($nq}5u-bQE=JUw-!cciit`(%TZq1D5H-%(iLU5%c5l6NOtXk-h$l=q|akm5d^ zAM{enjU~W0M3;Gsl{v)O8;~z1xr?&e^oHOLuwasavY|fwMpQG2ma*1pkoyJKzwD;KxY?n)sKJ#1h2)hxbof zUg<&a5@jbe{pw|LpUmu72eSbM}bfH?!0Gk`fqaNOYxi?x9bU-^o)XEGW8 zDCUf1csj!=3}*no=br^QNc)0w{e^Z(@bBIOTJNH&fUYhs$H^hXbya(W2Gb9F_Xr9JO!dgMkGqjUG!?>Xl1X>Vqp`VV$y8 z{UneKE>}LV1_al#o#jele1$ScrSV76?+#oTSj+fE=#L62dRf#C&S4+cGTa1ch|LVQ zF!bvaqSpuS)Q*YY7@P;VF*r{xuiEF`#P+u^+^i;w9t&<(7o;Bxu4en2RB8`nl!naS z;25Q@$6p}bn*K7l9o~-CHgS#={hNRt+=95{)XnO1X`FbgUj_6K*$IWVaDF#&S#4&x zh2bXkA9XdMOu$0+CUGDYP<%VLEuxYm`3C6CdUGK71Bs^CC@A?mCrnP ziIqIp98lBAX0?WG*07y4QXHfWV9q>^P7nt$f4TClzts1D^0D<%-WN)H#TR)8lymXC z?pMbI{{j5AUWV|i5A+Cx{p$UU(=Nxe%9`57@J#*Iq7mUEG%ERLm8bltg@Hw8IOmn*Xxit23`RwQN*#J8Q zVk9iwlfQs#VFA~|Qm%!S8qMY-)it#*g>A zIPcTcD^XT7ik?s~M&+|LwmC+f6B(y9!`c~vW;In(AezR3=_3a2+EO6qqmE(jB zKF=t4K<``GQm~mzZwuG;7Ov%eJe$wdZ;Gui*sIUM&hP>CGK{4(FW**>=F&@Z>7}{! z#wdf(o@v~;yC4sDMBV@#E#3hfEB*@DB)-6t@Qq@K>BC(!g1f|Uz^}wezyZp)kPcLS z06ap$KeH!>Dt^G>N*M4sB?>r7DFPg=lmU)assNjmI>6JFG~gtqFW?mD2gJF`p=MZI zt(=5!WG`370sa@m)qpB)nM{D@2IX|XTa{*L-ou&?u+GB_A7jlYSaTa|J`GKHtDFs( zr;YKPhszQeDPCkVJ~yuW6pcbQ54FHrjU-NP>w2@Q_Y-e z=2YVx=gi_p<_}~3Fy=QiXEJjpGiM%i<}+tLa~1%?Lxpm*fu*;w^cI$GW&SqiKgIl~ zn7@bldzt?p^WS5>P|1#>vd=2}tdh@o^9iX`GQXPnc;^WGM&=Atsca{4+{w)EV0=E~ z>lwd=@vV$M#rS&+6|Ggoi!{K^(Q1wC3}ZMPobkoYj8A4bjWy>nKA+(RhPN=>#_%bI z+gWpuMtRxGoc9>w%~EhQol>b_ypr*1hC`Xt$oMdw{Ap%**(4a~oV;YRS|McWuY#hks2D<0zOfGA1E8yPk;oX2nj!#y6dzri3sw=vwyQ1_CB z4lha9Gu+OcJzmljK7zWBbSfAh%5b=kJfFmP2g3!-Sz1Uf?G? z`+!d?76IZ{FdWKocz|>!G2Rhie;D7+{Cxq=X>f(;SF8uG5~GTngJfYI!wn3#G29cp zMU)opWn2l7P9?)ehRqD;F+E4%gvs)@FvU{x2@YpCg<*5S3hePV z7hENF6g8S8ox*Sf!;K90G8`JAa+}1kIYRAi9>Wa`w?;UX$O^HyXd83(FlR4w_A*CA zNk@s2juIsc70jt*d?@3Mj89^`gW-CH8<@Y9@okLnVSF#+BF2_uSK+>81>=>B4`sZO z@kxv~Gv2}Yycqegp79OL-^%zl=I>#AFZg-IBF^^X>@(w)j1OhJF-|&@7;k2N2jlY? zU(fgk*4fJVHs}zLBNd zV6CKh5A*jjUldX*6%2H2N7$#+}BS zhUGoOyTbdZSMyc+2Ki?BuJ>Vt4qO?yHn1x2X5jCELBWfHcL%ozi$V>di$blTCqr+9 z+VdXC`%~VoJTvUiSF!i2;XfUFyB@5X46K=acty-FO7SVip5RpBwYF;fEA6$ob=e1d zze6EC2HX*%25)Z&oa{Z4z}F`tzX7}}N%+cY!Y`@b3OK&*X~56wo&%g$^)lciY0}wS zM>@T$3BQx^dsu%t>rYFP{^K>I|6tt?z}A{S0lt^o4fs97c$)Afk#|X2_W|J3sgD3B zml6I!?Pq}7O1=U7uI`_JQ_`flBx2xnWNRVe6?GxtGS+~&3H%9@;ue>YoyD01I8!(k zwWb94$G)C`m5lqVDD^w*h<{Ht!ID~nZv_dS9VgBDYD&e+@ZBoH-|$s|e=kGLPq?4? zch*r__f!)+J5KzPTEgE75A;7NGp4Cjh??P!(5*69E^) z9(_@J4B(Zpp^B?uLlsN$W|Atd#`ls`-0YqRxJ;Y@c&#`SaFu9=o$CNqoSRPuz8X-) zy{xIgZva%qTKxL}3ZB!>0e%xsNa&{2G~nyuog(NtLKQc|J4M_AsEUp7P7${Ps^T`B zY$)P(KvmpOStMG2|mX_SqM zJJ44HeuwhFc{QLa{)rPFoHYTe;s>z;xKLIA_bC4bXeieKdX?3HK0M=~r71U})qJF+ z06$SOIEVTSc!l^IaJ-WQyb?Q&8N6Zk3)Iy@)WvG?BA#`3;jPy1k%Fpt6ra*V8Lc!a zS>+;Ssd63mKweP->d9)UR;L}Wjn^h=7io*No3#hEC$#T0Rrl+I^po`Q`d0lN{R90I zz20-E=Ty%$PpfBz=Vj0F#2KZ7TSP7mD{dMVUD@9?}Sc^Btx z$h#x&zP#;u&*#0CH#$5yJUhH7e0%u*@MGb3!ykr!o&W!|_pPy!9oczx`@z0!ialgg zqm{Dchg3o_yaHmn7_ zKx9M-40wMizy@n4MrJ{kLUTr=jg_}JaW_aeRz;rj)AAIA3) zeDNA^*rOp>qaoNLJf#ae_9(v7_&$d3<9L?$34EV~jeAOb-vwAH+=zfrNtyluwWdX)8T^)l`?!MhYxRqAKe&ppce zS@oMzKdUCCepdb966)NX2?+D3)YX5Pg~EYe%@kwC{eWj zL+TD-Z&<%?6|G-Mcdb86-?6@*KDPcc{SL~%4)}-aw}<{2(!+^|>?ac6wl60>v5VFp z+jEJBho82d7+y&Hv3e;xtEi_hVQ@2y_OtG_{rbC@auAZam-J?Hujz5kF{#OaQ#}jyf9y$n^iB| za69WY=b+j0JGF{`eJ?C1y3Oi}f84BGuL1_l>y>hOz2>*;&hc8^@%{PPGNEj0j;W3A z+ixFlIi1R(tJ@JM%a328OgUS4Qd#%?Qe&gy(glTbN%WM##g{oHy;vU+u%{ z<1|rDtL`aCjJxs8#%iRV4L^}4fHXL7U9>^594$ZdO7*K@0V zKyYHecF+a5I^vt<@4q9S~3`rAX1^6`y_}0w+U6_3plPX!WyU-nyp>8 zim6)Z7y#wRruNI_m1e7X+-PK)pGg1=d`b? z1GiJYQ`%S#8$s$!pGS<-1TMU}tXAr^gXXeYU%$3GyLRnrVPSrKZDsk&>c;x&#zx`F z(&EB;VPkpr+G1gSabtCLZEb0JVfkudb!B65d2WuUrM0U|*VunZ15#(w0Jslscl|Zk zOb!KrtyZ;Lcdx4#cD&j>r{iumFu@v7dq}0#Tz5N8t?pl!ah6&gr@pnS)AX>go(AND z4Pp`^5IIvotkOWEeRu;vVy@}=YFgiNj*w!bI<>esyRtsNxV&1JoxQSjbzyDk>gww3 z;>O0p!rc7QMxn5{wzRP{yS92|d3AMTc6niOv9MHF+L*frKCY~DY})Qk;vlvGdJ9(>(wgaE=sL} z3B*(wl1ageuir@|b|iwhPD4Wmjg5L04knmmnp8iptWLCR)TRm4Ifu?zkwJZ~FVF;iXSsnTr|3Er#Q#jnp89Sf)X6G$#kkH1jw?&nP=R83$2L&B8&1P_G7y zHn>U~1V>6VSVm7g2t~Z7J>dY$AgW#1j=?Gts11UnzRy7@(Yfz9$Mu#|{Y4*ZxPdM= z{j=dDohJQmwRQiDYNZYqhLu*c>JK()6g-$m16}HAac;3V#B)o{BpYay0nh3&?Cu~v z(%|QnF{(YIUg4gOh|egxDS_Y_1%YhOMcDL>=@_I_ChEYz%!+dmeMKzL8nm)ASV;b1 zb#!)__H5hDJI&hBVAVATyBgIM82K|wSKWhJQx;`dB80mR>XzdjxRF;c9l}~3wqSSZ z#*KLwA0c}Bat%PLU6k`hnFK}VnRr*7+U2}cH#?oSUJ|N?tPI6p?xLCpPY1hhl52LDBwmZJdq^%{%HghZRa6GfY(2q%O z3w2q-o&(kEhlz^~Kn;V=ZXM6X-pHZTMD^9y5q1J7LsdfL!k|vHKtes?h0c~M)D2Z~ z@Q^atQfS_*d95Zx-B%p1#^rx}=YUH}SUO+e=WG|Sne`UJ6Ibm*SrI9U_qgdas{j?@ zP1vUYN{b-_lBHS)$BrDyj@wQHKv~6sYPW<2L@H#H?AA2(=GCp*zRT8w2-I|DR1>=b z=tZJM%E{frFbRSu?aNbgVWD*20+wGvASU9V(Uk5bL4+-=+#Sh@u4_0vw=B}6j+x(5 z0)xukB}u<}h%FaYgnmm8Ok*C`u| z^NAHXad)w#=9#5|-iWZ{iiF6M;uHSvIG$8vtfi|NUnRp0(oo-R?@k*L4Cs`|TER+n z8(m1xRqO6v_u#xR9fw5+_7w!-I<5Z+Um4f}oe1wJL(!2p)8?fib+oXti}l zA$PnO=c3T5pNkbpS@5DB*4=#v`>J~HECTPk`$Yugo#S0BMEwXZTRjE680Acf710FL zf;hbH97#v9@?b1jWmLPBPSj?=bkWPDYf)sktWonirqb5-rcKiwGLDp`{LVPvEDs^yTd_m z)+=1LIHUo9#P7M>J6B#jgSD6d9dp(@$LfBq3QUURmfJi)(l{lP!@AvnwFWQ*=5=(E z>okP;>uwwHsvN^jgc)js@q9Bd2%UOO-SKLwi*MV9A;XjYwYFRbSUYqpcU5_hmp8b0 zfk_FkTm*(p;N==temYh6x*D}wm4HB17#0Zm+$V-9s$f^8E&yX4Lsx(WGD=$Q@(rvIs;vDqh!#7lBlUSV5>Cw3_MJ{SY34p$IrtJYM%*uvpV0Scij-A;>Ut-`IA zP_||-f~tWnAWSr~ybT)Ka+-)=7(vVg4YWX)>_lUz`YbC=dh~E198`zlGuIU2*BA7r zaO57j)g8+Sd$WP+38mohvc&UX5LUg$LLz zO+$P+sR`(V#IFY-k_q;<=qwdD%UF2LY2)QMZksA~#-&qLguzgb5Bn9((LhgbyPX*_ z5_Yk57r%;q_g*_FLhSce|EAGb%He}BTJcN%C_iU1SGuULHO(-?a6YZK6jKAZ0 z2v0C2!Nyyy`#9I-$T=CtE#OhJ0`H)(nB_@KXTJi3OEfGej2O&?T>?OIEGO5LV)@ub z!WeX>!kRM`Ic>GzVvsev{#(9U+4F_; z3~GIs4Rlp*=re_bzyqs4!%9TrvW=&B9YCkTp_qbTWKpTPET#cvb5T1gMu2LH5Ekgv z9=8!?V!*%8Co@8 zNtCIppR)WAiI#nE-9UlfFdedi;i9h?-J1!i-EO8ARQOmGm*FC^;-UE3ieAndm`6Go;{9YLAX@tl#87&B|>iepE z2)@P24VR;kO^>M13_1i`5`=_-2Yh!BgFr)wCmPTD%6tW$>jr|LL|O~t5y>Fv z7oDy+9i`(4>?d+9A8eG#x`|P{tAi1&H@KKk(fu|;*-9OLmRc1k6jzUsamT~H2!qiZ zZYS_>kTP27DBe-E+O1+dYEPfIr?=W=IH9m`kR{mm{yzACsxmuYb!!KQpp@p{r0;7` z+2^f+o6QZ}=Ku_ebHFZi#GCJ!VxSgdug{{!3TsD!agux7 z8-&wVg(HEngO0G!1W0sFVgS*W4wyy(kyEj;7~(bX`rAomhr# zGGfx#)dV+|Bz61Gikrl+8lI{>dVsL5wcI!TP zc_f$BWX}_8l>@nx<4AE|OT)Od(kX-l?hyhDcfWQdZRps=*H;)dqvF>bgL`XCxyXu( z0dvt&Du|H?0D3<)*hP)(wk%Jutrgtxq4TAdJ|momk84(r)n2Q5EQG-)=()!Pm5=cb z(|7TWEp8y4=)T8*XF4oGQDDPF`bIE19aYkK>?=t~haGPSSYL%KG}_4Z-@_vlE7=gRg_^!CT`DUSCOV^a^$7?bk_5Z?i@c!yk!prE0ffS+!FY}o?* zG|K{(kn!<4!Qd(5dl(+&Ta{s+7E8c}0)E!M4J@)8H;m!f05f#mh-qX8X}N{63ZCbB z6>auYyJRp{j1t^KO96J&&ee#m7xut3ikpo0@R*_Iib@{ip~7IiOdX=!2domLGDjMc zCYHim5AXm{@_D52^1sXs=&vf3egf3u(M3E3!}IIF#DhCYrf2XA<9IkH(~` znSG3nbU4Bbl_7l{v~(Y1Rm1m%N*Ad;q+HZdBTUthIso(#SRAuTGo>;-qSaycLN(L< z)lf_K%PFAKR8Y2iUpRV*)IKO^VH|3ht#^=C!<=X8owM~$>_q_kOsEjFZ_e5vD4;jIrsN2Y z7rMo=fKzp%>o~#Otjvi70d|EW@?(|FI!?STKaYNpCL6E0r=x+{y>ju zsnxLVi!^=(oDjaGt1QXzi1u-&HBiIMHw8kw4oWizfRJKx_AW~#MT%91Z4si+CPeUYS#CzqG-#BxYYhMol4 z_SEOq39<2pqtkd=+Uofk@c3tt@Jp0Q4Rqj24eDX74ca}?I_f3UXK^&7B_0HxWtIWgcJ-O;wR6e>vYMI|fZ5C7E?~8_#8{rz)byU9_+-b!jJ` zLr&M#e6lXA1GjQ%e zD+WK`#-Dm>4H5AU{z@okduzbavBnlsM~J^x@uG+Gu}Y{@hup{m&eJMdQOTEJF%J-1 zuJ_={2fz<-^X=Rn4#+lZh z(VX_glpMKQ1%xpJv2`n?#xvfJWs#R--N4$DV(mv}l=X5D{_FO1zodqGt?9x}v(V4h z*(!r}_WBHHih_B@c$e`+J5tfX(p%i zF*k&C{^URE(_h#Z^LAoFO<2jH35Bnf%~$~_b1~mLwkGg~3uRK7=>(CLDPeCmo+-~r z3pjv+Tw=l+#xH>9d%fJ$bdkU}iEj$ube`SyqnO4M=A1O= zlsTt!nZ6bi6QC)X!28uE(iqK{&?2MI$p7xS-K`5myrM)l)FerGg2ov`Dh#9beD53Mz2Abca#KlGNFtek zBWX`3rgF*g-Z#?HtG? z#I{HAk*21Q*3F}@F3KD1Nsjp)8w>#vY5XdA?{~mm(vroHpwPdk$A#mBWlt-%jo}Ir zsc9%VBuHVB?yQ`ow=6MhqGUswRDm=C2#FqsyvHWg7~AE9K>{rV!h{4y(PB6hG(#DK z(Rj@eM1gVP2vLuqtNck%S{@z445r?Q`ase)CNOkbX^nYP6Kao8vGmwS9~ny|FwF0Y zy2Z5ak~N$SaDa~zU4c9R|0Wb@4cG|U$W8LY64LC4p~ayRn^xsCl1W2j!E0zGRWF%@ z7Uq(umCNNWWit6gDGkKlrDhysnE5)UfKH~e%nx*6qZnOKl&EDURbm2oAw%?hN<5Yk zc3d3)S~53k+tAgMUyjeC92rD8NI8rXxEq^hWH@V3BgRhGh1hI#uB#4DC&4J%lm|4& zrNPlG8LN|VxZNiTBM};aOIB3F9?k}Y#p~vDU9uQTYZ!jIZVo@8fzsC^QIBLYQ#NJ> zKNDa+<|6C|=b0#Y?hBc0zLd-5Z}E>Ho{@#XnZ}DcAhq1XteJl!-zMktI~;0$2me&o z{2RHmbb+MNbc0fnE9*gh@^8@A-5SkgX|*8b4hR#m=Mt1Slp!{@1QZA+ZZZQfj79$B z>*FWi;0PwiPd=T(0R5HDPlpR0$R@gvDO=j9kjE$ds1imE3 zvalSZ>5K(J5<@xg0!C*lHzD-)ek9suD2Dr(%EA8UC>hw!w@~N17ob~kpHK#!r>7q8 zeTw&QkM~wab#8@jJt024_gQKP1!!vgt1xrpy>w>Q!cWFu!tXQ^1m2(ga5MvXQZ@4@ z-_PZS!xTJLPI&)k$y_!|v3-)rWhbVSG%XY4@1G?_&pBI>wgV(PI}F!3e)1zLKh0`? zg7dIUpC6$nriqjY6W&9vcah}^(+eqBSx|QJ9`RWdc{1w+x`)!76rO~ZEQc33YkP%M z44Qp>ESV&4FIkr&i==0UHV2my*(^)|EOIuN4co|0k0nsg%)-9O2aZH*K!x?0WDDaRhJBw+ojcYb$jAMj@gN7;_R9$B9BMKreh7Chm%yCLLu0a>3 zhrp;PikV@QhH?Kjs}Ez2%i|`0g8|_PoCS1iC|2fKDmvB_Dco7jnI_F;#j62W>CTwLO(|D585J_Y}THbw)+^(a4|=oMJSlD z7=9L$2jUKx@IK_&D_B%fh!E*bi_uw*^E;6n%j%OoNQVzzUNZkvw+qn6I_Bo1z&@rOoIKBa3jdpE@aZscsPn)1OHiCOv&tI9-Ip3 z(o-V8Zi5^#iysB&5G5pZ3Jyj%xeiv@_y(x(?}AN@Lnjau8Vm~I(h&_qrM?M2V)!f( z*t?6OFQ@?Tx1LRBd89X6mtZ5m{y4nkEolzSk(f}E0v!xuK0U|b@EF|k1O-Plk(S8U zW@Cup#O45#mPT@R7ST9o9tQD~@sq!TQ-H}w0{#*D@RRIp0)gfwHFn9$WI^&z#=ojv zg7ti6#D))nq3?}bF#NqyIgW$JgpJA>TqX{E4F&P;HHiRwk61aXGESmOFwk(Rp8>=a z6jtg_FgBKE#p&`2`840VY>45R)LqW^p2I|jnn0t>n52jt8}H5GKb%6EJn3K{2|QG=wS?&QK>fRz zFaI5bLgU~zwSp&T1(#v@ckjUH5`?MNdn{+`h~P1^cK?(pC!f-Qan@6akBNc!Ow{5t zxNpN~jNqy9cbypPF9)ob1X+JMV*O<}Wz!%v0mqG+&Y zH6~o=M`Fy7I&YESB+Q^#k#E0L{`=$qDf@TrKYC~4r=L9cqc7WY-&=m=TT8bW?SK9D z>#sa=<-hzxdqF<`<0V_k=TBd4qY6&>_SSnQ|{HOS&j+pvWys<4c z+m#pb@%Ian`w}W8hDH-Zlj)&Hznm`(L9lmV{f8t1v=c)KhPt9hgnc(Tlz$T6XHr8@ zR31KNxrAOO0c9D=!UzNoHcEaRCEw?2hc3s&0NPaya~d*`{75f`^6TvLpOB{4;3edg zzh%xlW5|QB$Wno>Qfg=_|7LOs=5Q!qB}KA}!Cu0}<*3Q%#ZF(&?#oG!T;~PtKn3zg zAd=xEVosBS_l?>|ycW-7$HSh3$SW#F#1+rPDxyh7#%T`!Cm8QIgG+MzQ$ju?2WaE~ z=?(KRB{;BK!a=c0pqaH0;sTjdm3G+#(X8?m4~slp4l7+o_T*PNEFFNbvyTY-4dQhT z8{kKvG|(N)3HU-ak>CMKW;K!GAaAcj$Y9q;Iw zfZYKYJB~yA4s8g=n}6~FSUY$MK@!L_qthwueFY#8h-o9oAC6+Ifk1Kz>@`Tdh4oW{ zl*0w#m7vqG@>+U;+7Bt?h5ErcGK~%n>H*~dk6~Jc@~o}WXhE!TB7a4=hF-F0-v+Z_ zrnzZjWx-9xd6PoKBpS%#I|{697NG1T*qp=>VKdGMnUI2o$^SwMD>-biSipl#HB%R! zH(39DB;3JX+4?YnkX?TLf$3ogPJh62{Ja{{kgVpB4T`3%(fkf7n2j*-9VwZtNWupM zNm&$PuLK0h78Dlua6MR=@Q6hogd}#HDePInL1lCF>5Ngr08Q^A7m)}vON3%dQ{FOT7B;b>2*89k|%qwE?=21(P5)ZwKn<;PO z*2CZlIot)0C&KaWTsjbZUbNK1Gq($+H9X~r$GN^_9(sN8-tx>W8pu5uK9g4tU^Z9Q~PY1dF^ABQpc(XaQZM|OK!X1IC zfmb?st}9RYvd&MRLL1V}*96YnOz zzl3@BAm@qsJeY)W!F$Dv(5hDuB<~`%iFd%?=8N`l+(4S2@239zf60{N?2(T?;|jKX zII*=6H2|E}@wLz@uRL$yN-3`bZ{o@+?`7iWNihe}4V%0JBDj7n2Dv?DmP7`Ohrf~&sZ0e Notifications*" + } + } + } + + Context "'Send to integration' is on" { + BeforeEach { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { @{ sendtoIntegration = $true } } + } + + It 'reports success and keeps the ticket text the extension returned' { + Mock -CommandName New-CippExtAlert -MockWith { 'Ticket created in HaloPSA: 1380' } + + $Result = Send-CIPPAlert @script:PsaParams + + $Result | Should -BeLike 'Sent PSA alert:*' + $Result | Should -BeLike '*Ticket created in HaloPSA: 1380*' + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { $sev -eq 'info' -and $message -like 'Sent PSA alert*' } + } + + It 'still reports success when the extension returns nothing' { + $Result = Send-CIPPAlert @script:PsaParams + + $Result | Should -Be 'Sent PSA alert: User Offboarding - contoso.onmicrosoft.com - Offboard AdeleV' + } + + It 'returns an error when the extension reports a failed ticket' { + # New-HaloPSATicket returns this string instead of throwing, which is why the caller + # has to inspect it. + Mock -CommandName New-CippExtAlert -MockWith { 'Failed to send ticket to HaloPSA: Unauthorized' } + + $Result = Send-CIPPAlert @script:PsaParams + + $Result | Should -Be 'Error: Failed to send ticket to HaloPSA: Unauthorized' + } + + It 'logs the failed ticket at error severity and never claims it was sent' { + Mock -CommandName New-CippExtAlert -MockWith { 'Failed to send ticket to HaloPSA: Unauthorized' } + + $null = Send-CIPPAlert @script:PsaParams + + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { + $sev -eq 'Error' -and $message -like '*PSA delivery failed for*Failed to send ticket to HaloPSA: Unauthorized*' + } + Should -Invoke Write-LogMessage -Times 0 -Exactly -ParameterFilter { $message -like 'Sent PSA alert*' } + } + + It 'treats an Error-prefixed result as a failure too' { + Mock -CommandName New-CippExtAlert -MockWith { 'Error: no HaloPSA token could be retrieved' } + + Send-CIPPAlert @script:PsaParams | Should -Be 'Error: Error: no HaloPSA token could be retrieved' + } + } +} diff --git a/Tests/Alerts/Send-CIPPScheduledTaskAlert.ResultEnvelope.Tests.ps1 b/Tests/Alerts/Send-CIPPScheduledTaskAlert.ResultEnvelope.Tests.ps1 new file mode 100644 index 0000000000000..7a4e08f767e7a --- /dev/null +++ b/Tests/Alerts/Send-CIPPScheduledTaskAlert.ResultEnvelope.Tests.ps1 @@ -0,0 +1,162 @@ +# Pester tests for how Send-CIPPScheduledTaskAlert renders a result envelope. +# Commands that also serve an HTTP caller return one row carrying the result lines plus the extras +# that caller needs: New-CIPPUserTask hands back Results alongside Username, Password, CopyFrom and +# the whole Graph user object. ConvertTo-Html turns that single row into a column per key, so the +# readable lines ended up squeezed into one cell beside a flattened 78-property Graph object - the +# notification email and the PSA ticket were a single unreadable row. +# +# The split is deliberately a rendering change only: $Results is not modified, so the webhook payload +# and the stored task results keep the shape they have always had, and nothing is dropped from the +# email or ticket either - the extras move below the table instead of beside it. + +BeforeAll { + Add-Type -AssemblyName System.Web -ErrorAction SilentlyContinue + + $BackendRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $BackendRoot 'Modules/CIPPCore/Public/Send-CIPPScheduledTaskAlert.ps1' + + function Get-CippTable { param([string]$TableName) } + function Get-CIPPAzDataTableEntity { param($TableName, $Filter, $Property, $First) } + function Get-Tenants { param($TenantFilter, [switch]$IncludeErrors) } + function Get-CIPPTextReplacement { param($Text, $TenantFilter, [switch]$EscapeForJson) } + function Send-CIPPAlert { + param($Type, $Title, $HTMLContent, $JSONContent, $TenantFilter, $altEmail, $altWebhook, + $APIName, $SchemaSource, $InvokingCommand, $Headers, $TableName, $RowKey, + $Attachments, $AffectedUser, [switch]$UseStandardizedSchema) + } + function Write-LogMessage { param($API, $tenant, $message, $sev, $LogData, $headers) } + + . (Join-Path $BackendRoot 'Modules/CIPPCore/Public/ConvertTo-PSAHtml.ps1') + . (Join-Path $BackendRoot 'Modules/CIPPCore/Public/GraphHelper/Get-AlertContentHash.ps1') + . $FunctionPath + + # The shape Push-ExecScheduledCommand hands over for a New-CIPPUserTask run: one row, because + # Select-Object * promotes the returned hashtable's keys to properties. + function New-EnvelopeResult { + $Lines = [System.Collections.Generic.List[string]]::new() + @( + 'Created New User.' + 'Username: starter@contoso.com' + 'Password: https://pwpush.example/p/abc' + 'Successfully added Starter to group Retail' + ) | ForEach-Object { $Lines.Add($_) } + + , @([pscustomobject]@{ + Results = $Lines + Username = 'starter@contoso.com' + Password = 'https://pwpush.example/p/abc' + CopyFrom = [pscustomobject]@{ Success = @('group A'); Error = @(); Skipped = @('group B') } + User = [pscustomobject]@{ + id = '00000000-0000-0000-0000-000000000001' + displayName = 'New Starter' + userPrincipalName = 'starter@contoso.com' + businessPhones = @('01603 888888') + } + }) + } + + function Get-TableColumns { + # ConvertTo-PSAHtml rewrites

with inline styles on the PSA path, so the header cells + # cannot be matched as a bare tag. + param([string]$Html, [int]$TableIndex = 0) + $Tables = [regex]::Matches($Html, '(?s)]*>.*?
') + if ($Tables.Count -le $TableIndex) { return @() } + @([regex]::Matches($Tables[$TableIndex].Value, ']*>(.*?)') | ForEach-Object { $_.Groups[1].Value }) + } + function Get-TableRowCount { + param([string]$Html, [int]$TableIndex = 0) + $Tables = [regex]::Matches($Html, '(?s)]*>.*?') + if ($Tables.Count -le $TableIndex) { return 0 } + ([regex]::Matches($Tables[$TableIndex].Value, '')).Count - 1 + } +} + +Describe 'Send-CIPPScheduledTaskAlert - result envelope rendering' { + BeforeEach { + $script:SentAlerts = [System.Collections.Generic.List[object]]::new() + $script:TaskInfo = [pscustomobject]@{ + RowKey = 'task-1' + Name = 'New user creation: starter@contoso.com' + Command = 'New-CIPPUserTask' + PostExecution = 'psa' + Parameters = '{}' + } + + Mock -CommandName Get-CippTable -MockWith { param([string]$TableName) @{ TableName = $TableName } } + Mock -CommandName Get-Tenants -MockWith { [pscustomobject]@{ customerId = 'customer-guid' } } + Mock -CommandName Get-CIPPTextReplacement -MockWith { param($Text, $TenantFilter) $Text } + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + param($TableName, $Filter) + if ($TableName -eq 'Extensionsconfig') { + return [pscustomobject]@{ config = (@{ HaloPSA = @{ Enabled = $false } } | ConvertTo-Json -Depth 5) } + } + $null + } + Mock -CommandName Send-CIPPAlert -MockWith { + param($Type, $Title, $HTMLContent) + $script:SentAlerts.Add([pscustomobject]@{ Type = $Type; HTMLContent = $HTMLContent }) + } + } + + Context 'a New-CIPPUserTask style envelope' { + BeforeEach { + Send-CIPPScheduledTaskAlert -Results (New-EnvelopeResult) -TaskInfo $script:TaskInfo -TenantFilter 'contoso.com' -TaskType 'Scheduled Task' + $script:Html = $script:SentAlerts[0].HTMLContent + } + + It 'renders the result lines as the table, one row each' { + Get-TableColumns -Html $script:Html -TableIndex 0 | Should -Be @('Results') + Get-TableRowCount -Html $script:Html -TableIndex 0 | Should -Be 4 + } + + It 'keeps the Graph user object rather than dropping it' { + # The whole point of rendering the extras below instead of unwrapping upstream. + $script:Html | Should -Match 'Additional detail' + $script:Html | Should -Match 'displayName: New Starter' + $script:Html | Should -Match '00000000-0000-0000-0000-000000000001' + } + + It 'keeps the other envelope fields too' { + foreach ($Field in 'Username', 'Password', 'CopyFrom', 'User') { + $script:Html | Should -Match ">$Field<" + } + } + + It 'puts the extras in their own table below the results' { + Get-TableColumns -Html $script:Html -TableIndex 1 | Should -Be @('Field', 'Value') + $script:Html.IndexOf('Additional detail') | Should -BeGreaterThan $script:Html.IndexOf('Created New User.') + } + } + + Context 'result shapes that are not envelopes' { + It 'renders an array of strings as before' { + Send-CIPPScheduledTaskAlert -Results @('First line', 'Second line') -TaskInfo $script:TaskInfo -TenantFilter 'contoso.com' -TaskType 'Scheduled Task' + + $Html = $script:SentAlerts[0].HTMLContent + Get-TableColumns -Html $Html -TableIndex 0 | Should -Be @('Text') + $Html | Should -Not -Match 'Additional detail' + } + + It 'renders a normal multi-row result set as before' { + $Rows = @( + [pscustomobject]@{ UserPrincipalName = 'a@contoso.com'; MFA = 'Disabled' } + [pscustomobject]@{ UserPrincipalName = 'b@contoso.com'; MFA = 'Disabled' } + ) + Send-CIPPScheduledTaskAlert -Results $Rows -TaskInfo $script:TaskInfo -TenantFilter 'contoso.com' -TaskType 'Scheduled Task' + + $Html = $script:SentAlerts[0].HTMLContent + Get-TableColumns -Html $Html -TableIndex 0 | Should -Be @('UserPrincipalName', 'MFA') + $Html | Should -Not -Match 'Additional detail' + } + + It 'leaves a single row that has no Results member alone' { + $Row = @([pscustomobject]@{ UserPrincipalName = 'a@contoso.com'; MFA = 'Disabled' }) + Send-CIPPScheduledTaskAlert -Results $Row -TaskInfo $script:TaskInfo -TenantFilter 'contoso.com' -TaskType 'Scheduled Task' + + $Html = $script:SentAlerts[0].HTMLContent + Get-TableColumns -Html $Html -TableIndex 0 | Should -Be @('UserPrincipalName', 'MFA') + $Html | Should -Not -Match 'Additional detail' + } + } +} diff --git a/Tests/Alerts/Send-CIPPScheduledTaskAlert.Tests.ps1 b/Tests/Alerts/Send-CIPPScheduledTaskAlert.Tests.ps1 index a54de402c6022..2308d7fbd2f6c 100644 --- a/Tests/Alerts/Send-CIPPScheduledTaskAlert.Tests.ps1 +++ b/Tests/Alerts/Send-CIPPScheduledTaskAlert.Tests.ps1 @@ -70,12 +70,14 @@ Describe 'Send-CIPPScheduledTaskAlert - PSA snooze links' { } Mock -CommandName Send-CIPPAlert -MockWith { - param($Type, $Title, $HTMLContent, $JSONContent, $TenantFilter, $AffectedUser) + param($Type, $Title, $HTMLContent, $JSONContent, $TenantFilter, $AffectedUser, $PSAReference, $PSATicketId) $script:SentAlerts.Add([pscustomobject]@{ Type = $Type Title = $Title HTMLContent = $HTMLContent AffectedUser = $AffectedUser + PSAReference = $PSAReference + PSATicketId = $PSATicketId }) } } @@ -151,4 +153,64 @@ Describe 'Send-CIPPScheduledTaskAlert - PSA snooze links' { $script:SentAlerts[0].HTMLContent | Should -Match 'Snooze Individual Alerts' } } + + # The task's reference is what lets a PSA add the result to the ticket the request came from + # rather than opening a second one, so every PSA call has to carry it - including the per-user + # split, or a split task's notes would land in new tickets while the consolidated one threads. + Context 'when the task carries a reference' { + BeforeEach { + $script:TaskInfo | Add-Member -NotePropertyName Reference -NotePropertyValue '[ID:1380] Starter Creation' -Force + } + + It 'passes it on the consolidated ticket' { + $script:LinkTicketsToUsers = $false + + Send-CIPPScheduledTaskAlert -Results $script:Results -TaskInfo $script:TaskInfo -TenantFilter 'contoso.com' -TaskType 'Alert' + + $script:SentAlerts.Count | Should -Be 1 + $script:SentAlerts[0].PSAReference | Should -Be '[ID:1380] Starter Creation' + } + + It 'passes it on every split ticket' { + Send-CIPPScheduledTaskAlert -Results $script:Results -TaskInfo $script:TaskInfo -TenantFilter 'contoso.com' -TaskType 'Alert' + + $script:SentAlerts.Count | Should -Be 2 + foreach ($Alert in $script:SentAlerts) { + $Alert.PSAReference | Should -Be '[ID:1380] Starter Creation' + } + } + + It 'passes an explicit PsaTicketId alongside it' { + $script:TaskInfo | Add-Member -NotePropertyName PsaTicketId -NotePropertyValue '1380' -Force + $script:LinkTicketsToUsers = $false + + Send-CIPPScheduledTaskAlert -Results $script:Results -TaskInfo $script:TaskInfo -TenantFilter 'contoso.com' -TaskType 'Alert' + + $script:SentAlerts[0].PSATicketId | Should -Be '1380' + } + + It 'keeps the ticket id out of the email subject entirely' { + # PsaTicketId drives the PSA note and nothing else. A mail-ingesting PSA threads on + # whatever the operator chose to put in Reference, so the subject must not be stamped + # with a ticket token nobody asked for. + $script:TaskInfo | Add-Member -NotePropertyName PsaTicketId -NotePropertyValue '1380' -Force + $script:TaskInfo | Add-Member -NotePropertyName Reference -NotePropertyValue 'Starter Creation' -Force + $script:TaskInfo.PostExecution = 'email' + + Send-CIPPScheduledTaskAlert -Results $script:Results -TaskInfo $script:TaskInfo -TenantFilter 'contoso.com' -TaskType 'Alert' + + $script:SentAlerts[0].Type | Should -Be 'email' + $script:SentAlerts[0].Title | Should -Not -Match '\[ID:' + $script:SentAlerts[0].Title | Should -BeLike '*Reference: Starter Creation*' + } + + It 'sends nothing extra when the task has no reference' { + $script:TaskInfo | Add-Member -NotePropertyName Reference -NotePropertyValue $null -Force + $script:LinkTicketsToUsers = $false + + Send-CIPPScheduledTaskAlert -Results $script:Results -TaskInfo $script:TaskInfo -TenantFilter 'contoso.com' -TaskType 'Alert' + + $script:SentAlerts[0].PSAReference | Should -BeNullOrEmpty + } + } } diff --git a/Tests/Baselines/BaselineDisableGuests.Tests.ps1 b/Tests/Baselines/BaselineDisableGuests.Tests.ps1 new file mode 100644 index 0000000000000..c1dd46cc61f56 --- /dev/null +++ b/Tests/Baselines/BaselineDisableGuests.Tests.ps1 @@ -0,0 +1,119 @@ +# Get-CIPPBaselineDisableGuestsState mirrors the DisableGuests standard: the same newest-attempt +# rule, the same IncludeNeverSignedIn switch (off by default and off for templates that predate +# it) and the same 7-day grace after an admin re-enables an account. Each test pins one of those, +# because drift between the standard and the baseline shows up as a guest one path disables and +# the other reports compliant. + +BeforeAll { + $script:RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $Baselines = Join-Path $script:RepoRoot 'Modules/CIPPCore/Public/Baselines' + + function New-GraphGetRequest { param($uri, $tenantid, $scope, $AsApp) } + function Write-LogMessage { param($API, $tenant, $message, $Sev, $LogData) } + + . (Join-Path $script:RepoRoot 'Modules/CIPPCore/Public/Get-CIPPLastSignInDateTime.ps1') + . (Join-Path $Baselines 'Get-CIPPBaselineDisableGuestsState.ps1') + + $script:Tenant = 'contoso.onmicrosoft.com' + $script:Now = (Get-Date).ToUniversalTime() + + # Guests go through ConvertFrom-Json, the shape New-GraphGetRequest hands the hook. Each + # *DaysAgo is how far back that signInActivity timestamp sits; leave all three out for a guest + # with no sign-in on record. + function script:New-Guest { + param( + [string]$Id, + [string]$Upn, + [int]$CreatedDaysAgo = 400, + [Nullable[int]]$InteractiveDaysAgo, + [Nullable[int]]$NonInteractiveDaysAgo, + [Nullable[int]]$SuccessfulDaysAgo + ) + $Stamp = { param($DaysAgo) if ($null -ne $DaysAgo) { $script:Now.AddDays(-$DaysAgo).ToString('o') } else { $null } } + $Guest = [ordered]@{ + id = $Id + userPrincipalName = $Upn + mail = $Upn + userType = 'Guest' + accountEnabled = $true + createdDateTime = $script:Now.AddDays(-$CreatedDaysAgo).ToString('o') + } + if ($null -ne $InteractiveDaysAgo -or $null -ne $NonInteractiveDaysAgo -or $null -ne $SuccessfulDaysAgo) { + $Guest.signInActivity = [ordered]@{ + lastSignInDateTime = & $Stamp $InteractiveDaysAgo + lastNonInteractiveSignInDateTime = & $Stamp $NonInteractiveDaysAgo + lastSuccessfulSignInDateTime = & $Stamp $SuccessfulDaysAgo + } + } + $Guest | ConvertTo-Json -Depth 5 | ConvertFrom-Json + } + + # A rendered template item. Omit -IncludeNeverSignedIn to model a template saved before the + # switch existed. + function script:New-DisableGuestsItem { + param([Nullable[int]]$Days, [Nullable[bool]]$IncludeNeverSignedIn) + $Variables = [PSCustomObject]@{} + if ($null -ne $Days) { $Variables | Add-Member -NotePropertyName days -NotePropertyValue $Days } + if ($null -ne $IncludeNeverSignedIn) { $Variables | Add-Member -NotePropertyName IncludeNeverSignedIn -NotePropertyValue $IncludeNeverSignedIn } + [PSCustomObject]@{ Variables = $Variables } + } +} + +Describe 'Get-CIPPBaselineDisableGuestsState' { + BeforeEach { + $script:guests = @() + $script:audits = @() + Mock New-GraphGetRequest { + param($uri) + if ($uri -like '*directoryAudits*') { return $script:audits } + return $script:guests + } + } + + It 'judges inactivity on the newest sign-in attempt, not the last successful sign-in' { + $script:guests = @( + New-Guest -Id 'g1' -Upn 'bas_example.com#EXT#@contoso.onmicrosoft.com' -SuccessfulDaysAgo 300 -InteractiveDaysAgo 154 -NonInteractiveDaysAgo 3 + New-Guest -Id 'stale' -Upn 'stale@example.com' -SuccessfulDaysAgo 250 -InteractiveDaysAgo 200 -NonInteractiveDaysAgo 190 + ) + + $Prepared = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem -Days 180) -TenantFilter $script:Tenant + + @($Prepared.Current.offenders) | Should -Be @('stale@example.com') + @($Prepared.Current.targets).id | Should -Be @('stale') + } + + It 'skips guests with no sign-in on record unless IncludeNeverSignedIn is on' { + $script:guests = @(New-Guest -Id 'pending' -Upn 'pending@example.com') + + $Legacy = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem -Days 90) -TenantFilter $script:Tenant + @($Legacy.Current.offenders) | Should -BeNullOrEmpty + + $Off = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem -Days 90 -IncludeNeverSignedIn $false) -TenantFilter $script:Tenant + @($Off.Current.offenders) | Should -BeNullOrEmpty + + $On = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem -Days 90 -IncludeNeverSignedIn $true) -TenantFilter $script:Tenant + @($On.Current.offenders) | Should -Be @('pending@example.com') + @($On.Current.targets).id | Should -Be @('pending') + } + + It 'leaves a guest an admin re-enabled in the last 7 days alone' { + $script:guests = @(New-Guest -Id 'stale' -Upn 'stale@example.com' -InteractiveDaysAgo 200) + $script:audits = @([pscustomobject]@{ targetResources = @([pscustomobject]@{ id = 'stale' }) }) + + $Prepared = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem -Days 90) -TenantFilter $script:Tenant + + @($Prepared.Current.offenders) | Should -BeNullOrEmpty + @($Prepared.Current.targets) | Should -BeNullOrEmpty + } + + It 'falls back to 90 days when the template carries no value' { + $script:guests = @( + New-Guest -Id 'over' -Upn 'over@example.com' -InteractiveDaysAgo 100 + New-Guest -Id 'under' -Upn 'under@example.com' -InteractiveDaysAgo 80 + ) + + $Prepared = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem) -TenantFilter $script:Tenant + + @($Prepared.Current.offenders) | Should -Be @('over@example.com') + } +} diff --git a/Tests/Baselines/BaselineEntraHeavies.Tests.ps1 b/Tests/Baselines/BaselineEntraHeavies.Tests.ps1 index 772f763b278c9..08fa17b073f0c 100644 --- a/Tests/Baselines/BaselineEntraHeavies.Tests.ps1 +++ b/Tests/Baselines/BaselineEntraHeavies.Tests.ps1 @@ -91,6 +91,24 @@ Describe 'Get-CIPPBaselineAuthenticationMethodsState' { (Get-Verdict -Expected $Prepared.Expected -Current $Prepared.Current).Count | Should -Be 0 } + It "the 'notConfigured' state skips the method exactly like an absent variable" { + # The Enabled switches became three-state autoCompletes; Not Configured must never + # grade or write. SMS is enabled in the tenant, so treating it as $false would drift. + Mock New-CIPPDbRequest { @($script:AuthPolicy | ConvertTo-Cached) } + $Item = [PSCustomObject]@{ Variables = [PSCustomObject]@{ MicrosoftAuthenticatorEnabled = $true; SMSEnabled = 'notConfigured' } } + $Prepared = Get-CIPPBaselineAuthenticationMethodsState -Item $Item -TenantFilter $script:Tenant + @($Prepared.Current.methodsOutOfPolicy).Count | Should -Be 0 + @($Prepared.Current.remediationSets).Count | Should -Be 0 + } + + It 'accepts an option wrapper the pipeline did not unwrap' { + Mock New-CIPPDbRequest { @($script:AuthPolicy | ConvertTo-Cached) } + $Item = [PSCustomObject]@{ Variables = [PSCustomObject]@{ SMSEnabled = [PSCustomObject]@{ label = 'Disabled'; value = $false } } } + $Prepared = Get-CIPPBaselineAuthenticationMethodsState -Item $Item -TenantFilter $script:Tenant + $Prepared.Current.methodsOutOfPolicy | Should -Match 'SMS' + $Prepared.Current.remediationSets[0].Params.Enabled | Should -BeFalse + } + It 'a drifted method contributes named drifts AND a remediation parameter set' { Mock New-CIPPDbRequest { @($script:AuthPolicy | ConvertTo-Cached) } $Item = [PSCustomObject]@{ Variables = [PSCustomObject]@{ SMSEnabled = $false } } @@ -180,6 +198,30 @@ Describe 'Get-CIPPBaselineFIDO2PasskeyProfilesState' { $type -eq 'PATCH' -and $AsApp -eq $true -and $body -match 'p-other' -and $body -match 'guid-1' } } + + It 'expects enforcement whenever AAGUIDs are supplied, even with the enforce switch off' { + # HubSpot 47469698699: Graph only retains a profile's AAGUID list while isEnforced = $true, + # so the expected state must enforce when AAGUIDs are present or the executor's write (which + # also enforces) would perpetually read back as drift. + Mock New-CIPPDbRequest { @($script:Fido2 | ConvertTo-Cached) } + $Item = [PSCustomObject]@{ Variables = [PSCustomObject]@{ PasskeyTypes = 'deviceBound'; AttestationEnforcement = 'registrationOnly'; EnforceKeyRestrictions = $false; EnforcementType = 'allow'; AAGUIDs = 'de1e552d-db1d-4423-a619-566b625cdc84' } } + $Prepared = Get-CIPPBaselineFIDO2PasskeyProfilesState -Item $Item -TenantFilter $script:Tenant + $Prepared.Expected.keyRestrictionsEnforced | Should -BeTrue + @($Prepared.Expected.aaGuids) | Should -Be @('de1e552d-db1d-4423-a619-566b625cdc84') + } + + It 'enforces key restrictions in the PATCH when AAGUIDs are supplied without the enforce switch' { + Mock New-GraphPostRequest { $script:capturedBody = $body } + $Current = [PSCustomObject]@{ + defaultProfileId = 'p-default' + allProfiles = @($script:Fido2.passkeyProfiles | ConvertTo-Cached) + } + Invoke-CIPPBaselineFIDO2PasskeyProfiles -Remediate ([PSCustomObject]@{ passkeyTypes = 'deviceBound'; attestationEnforcement = 'registrationOnly'; enforceKeyRestrictions = $false; enforcementType = 'allow'; aaGuids = 'de1e552d-db1d-4423-a619-566b625cdc84' }) -TenantFilter $script:Tenant -Current $Current + $Body = $script:capturedBody | ConvertFrom-Json + $Default = @($Body.passkeyProfiles) | Where-Object { $_.id -eq 'p-default' } + $Default.keyRestrictions.isEnforced | Should -BeTrue + @($Default.keyRestrictions.aaGuids) | Should -Be @('de1e552d-db1d-4423-a619-566b625cdc84') + } } Describe 'Get-CIPPBaselineOauthConsentState' { diff --git a/Tests/Baselines/BaselineExchangeBatch.Tests.ps1 b/Tests/Baselines/BaselineExchangeBatch.Tests.ps1 index c3fabe6f1b671..56c544125edf3 100644 --- a/Tests/Baselines/BaselineExchangeBatch.Tests.ps1 +++ b/Tests/Baselines/BaselineExchangeBatch.Tests.ps1 @@ -127,6 +127,31 @@ Describe 'Get-CIPPBaselineUserSubmissionsState' { Invoke-CIPPBaselineUserSubmissions -Remediate ([PSCustomObject]@{ state = 'disable' }) -TenantFilter $script:Tenant -Current $Current Should -Invoke New-ExoRequest -Times 1 -Exactly -ParameterFilter { $cmdlet -eq 'Remove-ReportSubmissionRule' } } + + It 'grades reporting-to-Microsoft OFF as compliant for the mailbox-only destination, and as drift without it' { + # Issue #409: tenants using a third-party phishing service keep EnableReportToMicrosoft + # off - the mailbox-only destination must not read that as drift. + Mock New-CIPPDbRequest { + if ($Type -eq 'ReportSubmissionPolicy') { @(@{ EnableReportToMicrosoft = $false; ReportJunkToCustomizedAddress = $true; ReportJunkAddresses = @('soc@contoso.com'); ReportNotJunkToCustomizedAddress = $true; ReportNotJunkAddresses = @('soc@contoso.com'); ReportPhishToCustomizedAddress = $true; ReportPhishAddresses = @('soc@contoso.com') } | ConvertTo-Cached) } + else { @(@{ State = 'Enabled'; SentTo = @('soc@contoso.com') } | ConvertTo-Cached) } + } + $Item = [PSCustomObject]@{ Variables = [PSCustomObject]@{ state = 'enable'; email = 'soc@contoso.com'; reportDestination = 'Mailbox' } } + $Prepared = Get-CIPPBaselineUserSubmissionsState -Item $Item -TenantFilter $script:Tenant + (Get-Verdict -Expected $Prepared.Expected -Current $Prepared.Current).Count | Should -Be 0 + + $Legacy = [PSCustomObject]@{ Variables = [PSCustomObject]@{ state = 'enable'; email = 'soc@contoso.com' } } + $Prepared = Get-CIPPBaselineUserSubmissionsState -Item $Legacy -TenantFilter $script:Tenant + (Get-Verdict -Expected $Prepared.Expected -Current $Prepared.Current).Count | Should -BeGreaterThan 0 + } + + It 'writes EnableReportToMicrosoft false when remediating the mailbox-only destination' { + Mock New-ExoRequest { } + $Current = [PSCustomObject]@{ policyExists = $true; ruleExists = $true; ruleEnabled = $true; resolvedEmail = 'soc@contoso.com'; reportDestination = 'Mailbox' } + Invoke-CIPPBaselineUserSubmissions -Remediate ([PSCustomObject]@{ state = 'enable' }) -TenantFilter $script:Tenant -Current $Current + Should -Invoke New-ExoRequest -Times 1 -Exactly -ParameterFilter { + $cmdlet -eq 'Set-ReportSubmissionPolicy' -and $cmdParams.EnableReportToMicrosoft -eq $false -and $cmdParams.ReportPhishAddresses -eq 'soc@contoso.com' + } + } } Describe 'Get-CIPPBaselineRetentionPolicyTagState' { @@ -299,4 +324,18 @@ Describe 'Get-CIPPBaselineSpamFilterPolicyState block-list write params' { @($Prepared.Current.extraPolicyParams.RegionBlockList) | Should -BeExactly @('KP', 'RU') $Prepared.Expected.enableRegionBlockList | Should -BeTrue } + + It 'never grades or writes BulkMovesEnabled unless explicitly configured - the parameter is in Preview and not available in every organization' { + $Item = [PSCustomObject]@{ Variables = [PSCustomObject]@{ } } + $Prepared = Get-CIPPBaselineSpamFilterPolicyState -Item $Item -TenantFilter $script:Tenant + $Prepared.Expected.PSObject.Properties.Name | Should -Not -Contain 'bulkMovesEnabled' + $Prepared.Current.extraPolicyParams.PSObject.Properties.Name | Should -Not -Contain 'BulkMovesEnabled' + } + + It 'grades and writes BulkMovesEnabled when configured On, unwrapping an option wrapper if the picker saved one' { + $Item = [PSCustomObject]@{ Variables = [PSCustomObject]@{ BulkMovesEnabled = [PSCustomObject]@{ label = 'On'; value = 'On' } } } + $Prepared = Get-CIPPBaselineSpamFilterPolicyState -Item $Item -TenantFilter $script:Tenant + $Prepared.Expected.bulkMovesEnabled | Should -BeExactly 'On' + $Prepared.Current.extraPolicyParams.BulkMovesEnabled | Should -BeExactly 'On' + } } diff --git a/Tests/Baselines/BaselineOneOffStandards.Tests.ps1 b/Tests/Baselines/BaselineOneOffStandards.Tests.ps1 index af2a4702c8ec8..ef0b39145ca94 100644 --- a/Tests/Baselines/BaselineOneOffStandards.Tests.ps1 +++ b/Tests/Baselines/BaselineOneOffStandards.Tests.ps1 @@ -18,7 +18,7 @@ BeforeAll { . (Join-Path $script:RepoRoot 'Modules/CIPPCore/Public/Compare-CIPPIntuneObject.ps1') . (Join-Path $Baselines 'Get-CIPPBaselineCacheRows.ps1') . (Join-Path $Baselines 'Test-CIPPBaselineCacheCollected.ps1') - foreach ($Name in @('ExternalMFATrusted', 'IntuneDeviceRetirementDays', 'AppManagementPolicy', 'EnableAppConsentRequests', 'TeamsFederationConfiguration', 'OMEBranding')) { + foreach ($Name in @('ExternalMFATrusted', 'ExternalComplianceTrusted', 'IntuneDeviceRetirementDays', 'AppManagementPolicy', 'EnableAppConsentRequests', 'TeamsFederationConfiguration', 'OMEBranding')) { . (Join-Path $Baselines "Get-CIPPBaseline${Name}State.ps1") . (Join-Path $Baselines "Invoke-CIPPBaseline${Name}.ps1") } @@ -58,6 +58,30 @@ Describe 'Get-CIPPBaselineExternalMFATrustedState' { } } +Describe 'Get-CIPPBaselineExternalComplianceTrustedState' { + It 'grades the compliance switch in BOTH directions' { + Mock New-CIPPDbRequest { @(@{ inboundTrust = @{ isCompliantDeviceAccepted = $true } } | ConvertTo-Cached) } + $Off = [PSCustomObject]@{ Variables = [PSCustomObject]@{ state = $false } } + $Prepared = Get-CIPPBaselineExternalComplianceTrustedState -Item $Off -TenantFilter $script:Tenant + (Get-Verdict -Expected $Prepared.Expected -Current $Prepared.Current).Count | Should -BeGreaterThan 0 + $On = [PSCustomObject]@{ Variables = [PSCustomObject]@{ state = $true } } + $Prepared2 = Get-CIPPBaselineExternalComplianceTrustedState -Item $On -TenantFilter $script:Tenant + (Get-Verdict -Expected $Prepared2.Expected -Current $Prepared2.Current).Count | Should -Be 0 + } + + It 'patches the merged inboundTrust, never the lone flag' { + Mock New-GraphGetRequest { [PSCustomObject]@{ inboundTrust = [PSCustomObject]@{ isMfaAccepted = $true; isCompliantDeviceAccepted = $false; isHybridAzureADJoinedDeviceAccepted = $true } } } + Mock New-GraphPostRequest { } + Invoke-CIPPBaselineExternalComplianceTrusted -Remediate ([PSCustomObject]@{ trusted = $true }) -TenantFilter $script:Tenant -Current $null + Should -Invoke New-GraphPostRequest -Times 1 -Exactly -ParameterFilter { + $type -eq 'PATCH' -and + $body -match '"isCompliantDeviceAccepted":\s*true' -and + $body -match 'isMfaAccepted' -and + $body -match 'isHybridAzureADJoinedDeviceAccepted' + } + } +} + Describe 'Get-CIPPBaselineIntuneDeviceRetirementDaysState' { BeforeAll { $script:DaysItem = [PSCustomObject]@{ Variables = [PSCustomObject]@{ days = 90 } } } BeforeEach { Mock Get-CIPPDbItem { [PSCustomObject]@{ RowKey = 'ManagedDeviceCleanupRules-Count'; DataCount = 1 } } } diff --git a/Tests/Baselines/BaselineSPGuestPeoplePicker.Tests.ps1 b/Tests/Baselines/BaselineSPGuestPeoplePicker.Tests.ps1 new file mode 100644 index 0000000000000..b7e6dadfb22e5 --- /dev/null +++ b/Tests/Baselines/BaselineSPGuestPeoplePicker.Tests.ps1 @@ -0,0 +1,118 @@ +# SPGuestPeoplePicker reads from cache: the prepare hook derives offenders/targets from +# Get-CIPPSPOTenant (the tenant default, 1h-cached) + the SPOSites reporting cache (New-CIPPDbRequest), +# and the executor writes then stops - the next daily cache read verifies. The write sweep is guarded to +# once per 24h per tenant by Test-CIPPRerun. Static counting mocks only. + +BeforeAll { + $script:RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $Baselines = Join-Path $script:RepoRoot 'Modules/CIPPCore/Public/Baselines' + + function Get-CIPPSPOTenant { param($TenantFilter, [switch]$UseCertificate, [switch]$SkipCache) } + function New-CIPPDbRequest { param($TenantFilter, $Type, $Fields) } + function Set-CIPPSPOTenant { [CmdletBinding()] param([Parameter(ValueFromPipeline)]$InputObject, $Properties, [switch]$UseCertificate) process {} } + function Set-CIPPSPOSiteBulk { param($TenantFilter, $Sites, $MaxConcurrency, $MaxRetries, [switch]$UseCertificate) } + function Test-CIPPRerun { param($TenantFilter, $API, [int64]$Interval) } + function Write-LogMessage { param($API, $tenant, $message, $Sev, $LogData) } + function Write-Information { param($MessageData) } + + . (Join-Path $Baselines 'Get-CIPPBaselineSPGuestPeoplePickerState.ps1') + . (Join-Path $Baselines 'Invoke-CIPPBaselineSPGuestPeoplePicker.ps1') + + $script:Tenant = 'contoso.onmicrosoft.com' + function script:New-Site { param([string]$Url, [bool]$Show) [PSCustomObject]@{ Url = $Url; ShowPeoplePickerSuggestionsForGuestUsers = $Show } } + function script:New-Item2 { param([bool]$ShowGuests) [PSCustomObject]@{ Variables = [PSCustomObject]@{ showGuests = $ShowGuests } } } +} + +Describe 'Get-CIPPBaselineSPGuestPeoplePickerState' { + It 'flags the tenant default and sites that differ (wanted = show)' { + Mock Get-CIPPSPOTenant { [PSCustomObject]@{ ShowPeoplePickerSuggestionsForGuestUsers = $false } } + Mock New-CIPPDbRequest { @((New-Site 'https://c.sharepoint.com/sites/A' $false), (New-Site 'https://c.sharepoint.com/sites/B' $true)) } + $p = Get-CIPPBaselineSPGuestPeoplePickerState -Item (New-Item2 -ShowGuests $true) -TenantFilter $script:Tenant + @($p.Current.offenders) | Should -Be @('Tenant default', 'https://c.sharepoint.com/sites/A') + @($p.Current.targets)[0].Scope | Should -Be 'tenant' + @($p.Current.targets)[1].SiteUrl | Should -Be 'https://c.sharepoint.com/sites/A' + } + + It 'flags only what differs (wanted = hide)' { + Mock Get-CIPPSPOTenant { [PSCustomObject]@{ ShowPeoplePickerSuggestionsForGuestUsers = $false } } + Mock New-CIPPDbRequest { @((New-Site 'https://c.sharepoint.com/sites/B' $true)) } + $p = Get-CIPPBaselineSPGuestPeoplePickerState -Item (New-Item2 -ShowGuests $false) -TenantFilter $script:Tenant + @($p.Current.offenders) | Should -Be @('https://c.sharepoint.com/sites/B') + } + + It 'is compliant when the tenant default and every cached site already match' { + Mock Get-CIPPSPOTenant { [PSCustomObject]@{ ShowPeoplePickerSuggestionsForGuestUsers = $true } } + Mock New-CIPPDbRequest { @((New-Site 'https://c.sharepoint.com/sites/A' $true)) } + $p = Get-CIPPBaselineSPGuestPeoplePickerState -Item (New-Item2 -ShowGuests $true) -TenantFilter $script:Tenant + @($p.Current.offenders) | Should -BeNullOrEmpty + } + + It 'returns null Current when the tenant read fails' { + Mock Get-CIPPSPOTenant { throw 'SharePoint admin access denied' } + Mock New-CIPPDbRequest { @() } + $p = Get-CIPPBaselineSPGuestPeoplePickerState -Item (New-Item2 -ShowGuests $true) -TenantFilter $script:Tenant + $p.Current | Should -BeNullOrEmpty + } +} + +Describe 'Invoke-CIPPBaselineSPGuestPeoplePicker' { + BeforeEach { + Mock Write-LogMessage {} + Mock Test-CIPPRerun { $false } + Mock Get-CIPPSPOTenant { [PSCustomObject]@{ _ObjectIdentity_ = 'id'; TenantFilter = $script:Tenant; ShowPeoplePickerSuggestionsForGuestUsers = $true } } + Mock Set-CIPPSPOTenant {} + $script:Remediate = [PSCustomObject]@{ executor = 'SPGuestPeoplePicker'; useCertificate = $true } + } + + It 'writes the tenant default and sites, without a verification re-read' { + Mock Set-CIPPSPOSiteBulk { @( + [PSCustomObject]@{ SiteUrl = 'https://c.sharepoint.com/sites/A'; Success = $true; Error = $null } + [PSCustomObject]@{ SiteUrl = 'https://c.sharepoint.com/sites/B'; Success = $true; Error = $null } + ) } + $Current = [PSCustomObject]@{ targets = @( + [PSCustomObject]@{ Scope = 'tenant'; SiteUrl = $null; Wanted = $true } + [PSCustomObject]@{ Scope = 'site'; SiteUrl = 'https://c.sharepoint.com/sites/A'; Wanted = $true } + [PSCustomObject]@{ Scope = 'site'; SiteUrl = 'https://c.sharepoint.com/sites/B'; Wanted = $true } + ) } + Invoke-CIPPBaselineSPGuestPeoplePicker -Remediate $script:Remediate -TenantFilter $script:Tenant -Current $Current + Should -Invoke Set-CIPPSPOTenant -Times 1 -Exactly + Should -Invoke Set-CIPPSPOSiteBulk -Times 1 -Exactly + } + + It 'skips the write sweep entirely inside the 24h rerun guard' { + Mock Test-CIPPRerun { $true } + Mock Set-CIPPSPOSiteBulk {} + $Current = [PSCustomObject]@{ targets = @( + [PSCustomObject]@{ Scope = 'tenant'; SiteUrl = $null; Wanted = $true } + [PSCustomObject]@{ Scope = 'site'; SiteUrl = 'https://c.sharepoint.com/sites/A'; Wanted = $true } + ) } + Invoke-CIPPBaselineSPGuestPeoplePicker -Remediate $script:Remediate -TenantFilter $script:Tenant -Current $Current + Should -Invoke Set-CIPPSPOTenant -Times 0 -Exactly + Should -Invoke Set-CIPPSPOSiteBulk -Times 0 -Exactly + } + + It 'tolerates a per-site failure without throwing' { + Mock Set-CIPPSPOSiteBulk { @( + [PSCustomObject]@{ SiteUrl = 'https://c.sharepoint.com/sites/A'; Success = $true; Error = $null } + [PSCustomObject]@{ SiteUrl = 'https://c.sharepoint.com/sites/B'; Success = $false; Error = 'denied' } + ) } + $Current = [PSCustomObject]@{ targets = @( + [PSCustomObject]@{ Scope = 'site'; SiteUrl = 'https://c.sharepoint.com/sites/A'; Wanted = $true } + [PSCustomObject]@{ Scope = 'site'; SiteUrl = 'https://c.sharepoint.com/sites/B'; Wanted = $true } + ) } + { Invoke-CIPPBaselineSPGuestPeoplePicker -Remediate $script:Remediate -TenantFilter $script:Tenant -Current $Current } | Should -Not -Throw + } + + It 'throws when the whole site write batch fails' { + Mock Set-CIPPSPOSiteBulk { throw 'denied' } + $Current = [PSCustomObject]@{ targets = @([PSCustomObject]@{ Scope = 'site'; SiteUrl = 'https://c.sharepoint.com/sites/A'; Wanted = $true }) } + { Invoke-CIPPBaselineSPGuestPeoplePicker -Remediate $script:Remediate -TenantFilter $script:Tenant -Current $Current } | Should -Throw + } + + It 'does nothing when there are no targets' { + Mock Set-CIPPSPOSiteBulk {} + Invoke-CIPPBaselineSPGuestPeoplePicker -Remediate $script:Remediate -TenantFilter $script:Tenant -Current ([PSCustomObject]@{ targets = @() }) + Should -Invoke Set-CIPPSPOSiteBulk -Times 0 -Exactly + Should -Invoke Test-CIPPRerun -Times 0 -Exactly + } +} diff --git a/Tests/Baselines/BaselineSharePointBatch.Tests.ps1 b/Tests/Baselines/BaselineSharePointBatch.Tests.ps1 index 2ba93cd8e13c9..dacd79f4f55b0 100644 --- a/Tests/Baselines/BaselineSharePointBatch.Tests.ps1 +++ b/Tests/Baselines/BaselineSharePointBatch.Tests.ps1 @@ -15,8 +15,9 @@ BeforeAll { function New-GraphGetRequest { param($uri, $tenantid, $AsApp) } function New-GraphBulkRequest { param($tenantid, $Requests) } function Get-CIPPSPOTenant { param($TenantFilter) } - function Set-CIPPSPOTenant { [CmdletBinding()] param([Parameter(ValueFromPipeline = $true)]$InputObject, $Properties, $MethodName, $MethodParameters) process { } } + function Set-CIPPSPOTenant { [CmdletBinding()] param([Parameter(ValueFromPipeline = $true)]$InputObject, $Properties, $MethodName, $MethodParameters, [switch]$UseCertificate) process { } } function Set-CIPPSPOSite { param($TenantFilter, $SiteUrl, $Properties) } + function Set-CIPPSPOSiteBulk { [CmdletBinding()] param($TenantFilter, $Sites, $MaxConcurrency, $MaxRetries, [switch]$UseCertificate) } function Get-CIPPTextReplacement { param($TenantFilter, $Text) $Text } function Get-NormalizedError { param($Message) "$Message" } @@ -160,10 +161,18 @@ Describe 'Get-CIPPBaselineSPOVersionControlState' { Mock Get-CIPPSPOTenant { [PSCustomObject]@{ _ObjectIdentity_ = 'fresh'; TenantFilter = $script:Tenant } } Mock Set-CIPPSPOTenant { } Mock New-GraphGetRequest { @([PSCustomObject]@{ webUrl = 'https://c.sharepoint.com/sites/bad' }, [PSCustomObject]@{ webUrl = 'https://c.sharepoint.com/sites/good' }) } - Mock Set-CIPPSPOSite { if ($SiteUrl -like '*bad') { throw 'site locked' } } - Invoke-CIPPBaselineSPOVersionControl -Remediate ([PSCustomObject]@{ enableAutoTrim = $true; applyToExistingSites = $true }) -TenantFilter $script:Tenant -Current $null - Should -Invoke Set-CIPPSPOSite -Times 2 -Exactly - Should -Invoke Set-CIPPSPOSite -Times 1 -Exactly -ParameterFilter { $SiteUrl -like '*good' -and $Properties.InheritVersionPolicyFromTenant -eq $true } + # The fan-out is now one concurrent Set-CIPPSPOSiteBulk call; a per-site failure comes back + # as Success=$false in its result rather than a thrown exception, and must not abort the run. + Mock Set-CIPPSPOSiteBulk { + @(foreach ($Site in $Sites) { + [PSCustomObject]@{ SiteUrl = $Site.SiteUrl; Success = ($Site.SiteUrl -notlike '*bad'); Error = if ($Site.SiteUrl -like '*bad') { 'site locked' } else { $null } } + }) + } + { Invoke-CIPPBaselineSPOVersionControl -Remediate ([PSCustomObject]@{ enableAutoTrim = $true; applyToExistingSites = $true }) -TenantFilter $script:Tenant -Current $null } | Should -Not -Throw + Should -Invoke Set-CIPPSPOSiteBulk -Times 1 -Exactly + Should -Invoke Set-CIPPSPOSiteBulk -Times 1 -Exactly -ParameterFilter { + @($Sites).Count -eq 2 -and @($Sites | Where-Object { $_.SiteUrl -like '*good' -and $_.Properties.InheritVersionPolicyFromTenant -eq $true }).Count -eq 1 + } } } diff --git a/Tests/DBCache/Clear-CIPPDbCache.Tests.ps1 b/Tests/DBCache/Clear-CIPPDbCache.Tests.ps1 new file mode 100644 index 0000000000000..fde375b2acfa1 --- /dev/null +++ b/Tests/DBCache/Clear-CIPPDbCache.Tests.ps1 @@ -0,0 +1,208 @@ +# Pester tests for Clear-CIPPDbCache and Remove-CIPPDbItem. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function Get-CippTable { param($tablename) @{ TableName = $tablename } } + + function Get-FakeTableList { + param([string]$TableName) + if ([string]::IsNullOrWhiteSpace($TableName)) { $TableName = 'CippReportingDB' } + if (-not $script:FakeTables.ContainsKey($TableName)) { + $script:FakeTables[$TableName] = [System.Collections.Generic.List[object]]::new() + } + $TableName + } + + function Invoke-FakeTableFilter { + param($Rows, [string]$Filter) + $Result = @($Rows) + if ($Filter -match "PartitionKey eq '([^']*)'") { + $Pk = $Matches[1] + $Result = @($Result | Where-Object { $_.PartitionKey -eq $Pk }) + } + if ($Filter -match "RowKey eq '([^']*)'") { + $Rk = $Matches[1] + $Result = @($Result | Where-Object { $_.RowKey -eq $Rk }) + } + if ($Filter -match "RowKey ge '([^']*)'") { + $Ge = $Matches[1] + $Result = @($Result | Where-Object { $_.RowKey -ge $Ge }) + } + if ($Filter -match "RowKey lt '([^']*)'") { + $Lt = $Matches[1] + $Result = @($Result | Where-Object { $_.RowKey -lt $Lt }) + } + if ($Filter -match 'DataCount ge 0') { + $Result = @($Result | Where-Object { $null -ne $_.DataCount }) + } + $Result + } + + function ConvertTo-FakeEntity { + param($Entity) + if ($Entity -is [hashtable]) { return [pscustomobject]$Entity } + $Clone = [ordered]@{} + foreach ($Property in $Entity.PSObject.Properties) { $Clone[$Property.Name] = $Property.Value } + [pscustomobject]$Clone + } + + function Get-CIPPAzDataTableEntity { + param($TableName, $Context, $Filter, $Property, $First, [switch]$Count) + $Name = Get-FakeTableList -TableName $(if ($TableName) { $TableName } else { 'CippReportingDB' }) + $Rows = $script:FakeTables[$Name] + $Matched = @(Invoke-FakeTableFilter -Rows $Rows -Filter $Filter | ForEach-Object { ConvertTo-FakeEntity -Entity $_ }) + if ($First -and $Matched.Count -gt $First) { + $Matched = $Matched[0..($First - 1)] + } + $Matched + } + + function Add-CIPPAzDataTableEntity { + [CmdletBinding()] + param($TableName, $Context, $Entity, [switch]$Force, [switch]$CreateTableIfNotExists) + $Name = Get-FakeTableList -TableName $(if ($TableName) { $TableName } else { 'CippReportingDB' }) + $Rows = $script:FakeTables[$Name] + foreach ($Item in @($Entity)) { + if ($null -eq $Item) { continue } + $New = ConvertTo-FakeEntity -Entity $Item + $Existing = $null + for ($i = 0; $i -lt $Rows.Count; $i++) { + if ($Rows[$i].PartitionKey -eq $New.PartitionKey -and $Rows[$i].RowKey -eq $New.RowKey) { + $Existing = $Rows[$i] + break + } + } + if ($Existing) { + if (-not $Force) { continue } + [void]$Rows.Remove($Existing) + } + [void]$Rows.Add($New) + } + } + + function Remove-CIPPAzDataTableEntity { + param($TableName, $Context, $Entity, [switch]$Force) + $Name = Get-FakeTableList -TableName $(if ($TableName) { $TableName } else { 'CippReportingDB' }) + $Rows = $script:FakeTables[$Name] + foreach ($Item in @($Entity)) { + if ($null -eq $Item) { continue } + $Existing = $null + for ($i = 0; $i -lt $Rows.Count; $i++) { + if ($Rows[$i].PartitionKey -eq $Item.PartitionKey -and $Rows[$i].RowKey -eq $Item.RowKey) { + $Existing = $Rows[$i] + break + } + } + if ($Existing) { [void]$Rows.Remove($Existing) } + } + } + + function Get-AzDataTableEntity { + param($TableName, $Context, $Filter, $Property, $First, [switch]$Count) + Get-CIPPAzDataTableEntity @PSBoundParameters + } + + function Remove-AzDataTableEntity { + param($TableName, $Context, $Entity, [switch]$Force) + Remove-CIPPAzDataTableEntity @PSBoundParameters + } + + function Write-LogMessage { param($headers, $API, $tenant, $message, $sev, $LogData) } + function Get-CippException { param($Exception) [pscustomobject]@{ NormalizedError = "$Exception" } } + function Get-Tenants { + param($TenantFilter, [switch]$IncludeErrors) + switch -Regex ($TenantFilter) { + '^(contoso\.com|contoso\.onmicrosoft\.com)$' { + return [pscustomobject]@{ customerId = 'tenant-guid-1'; defaultDomainName = 'contoso.com' } + } + '^(fabrikam\.com)$' { + return [pscustomobject]@{ customerId = 'tenant-guid-2'; defaultDomainName = 'fabrikam.com' } + } + default { return $null } + } + } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPDbItem.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Remove-CIPPDbItem.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Clear-CIPPDbCache.ps1') +} + +Describe 'Remove-CIPPDbItem' { + BeforeEach { + $script:FakeTables = @{} + Add-CIPPAzDataTableEntity -TableName 'CippReportingDB' -Entity @( + @{ PartitionKey = 'contoso.com'; RowKey = 'Users-user-1'; Data = '{"id":"user-1"}'; Type = 'Users'; ETag = 'etag-1' } + @{ PartitionKey = 'contoso.com'; RowKey = 'Users-Count'; DataCount = 2; ETag = 'etag-c' } + ) -Force + } + + It 'removes by RowKey and decrements DataCount' { + Remove-CIPPDbItem -TenantFilter 'contoso.com' -Type 'Users' -RowKey 'Users-user-1' -ETag 'etag-1' + + $Remaining = @($script:FakeTables['CippReportingDB']) + ($Remaining | Where-Object { $_.RowKey -eq 'Users-user-1' }).Count | Should -Be 0 + ($Remaining | Where-Object { $_.RowKey -eq 'Users-Count' }).DataCount | Should -Be 1 + } + + It 'removes by ItemId and decrements DataCount' { + Remove-CIPPDbItem -TenantFilter 'contoso.com' -Type 'Users' -ItemId 'user-1' + + $Remaining = @($script:FakeTables['CippReportingDB']) + ($Remaining | Where-Object { $_.RowKey -eq 'Users-user-1' }).Count | Should -Be 0 + ($Remaining | Where-Object { $_.RowKey -eq 'Users-Count' }).DataCount | Should -Be 1 + } + + It 'rejects RowKey that does not match Type' { + { Remove-CIPPDbItem -TenantFilter 'contoso.com' -Type 'Users' -RowKey 'Groups-g1' } | Should -Throw '*does not match type*' + } +} + +Describe 'Clear-CIPPDbCache' { + BeforeEach { + $script:FakeTables = @{} + Add-CIPPAzDataTableEntity -TableName 'CippReportingDB' -Entity @( + @{ PartitionKey = 'contoso.com'; RowKey = 'Users-user-1'; Data = '{"id":"user-1"}'; Type = 'Users' } + @{ PartitionKey = 'contoso.com'; RowKey = 'Users-user-2'; Data = '{"id":"user-2"}'; Type = 'Users' } + @{ PartitionKey = 'contoso.com'; RowKey = 'Users-Count'; DataCount = 2 } + @{ PartitionKey = 'contoso.com'; RowKey = 'Groups-g1'; Data = '{"id":"g1"}'; Type = 'Groups' } + @{ PartitionKey = 'contoso.com'; RowKey = 'Groups-Count'; DataCount = 1 } + @{ PartitionKey = 'fabrikam.com'; RowKey = 'Users-user-a'; Data = '{"id":"user-a"}'; Type = 'Users' } + @{ PartitionKey = 'fabrikam.com'; RowKey = 'Users-Count'; DataCount = 1 } + ) -Force + } + + It 'empties one tenant type and resets Count to 0' { + $Result = Clear-CIPPDbCache -TenantFilter 'contoso.com' -Type 'Users' + + # Data rows only (Count is upserted to 0, not counted as a delete). + $Result.RemovedCount | Should -Be 2 + $Result.Tenant | Should -Be 'contoso.com' + $Result.Type | Should -Be 'Users' + + $Remaining = @($script:FakeTables['CippReportingDB']) + ($Remaining | Where-Object { $_.PartitionKey -eq 'contoso.com' -and $_.RowKey -like 'Users-user*' }).Count | Should -Be 0 + ($Remaining | Where-Object { $_.PartitionKey -eq 'contoso.com' -and $_.RowKey -eq 'Users-Count' }).DataCount | Should -Be 0 + ($Remaining | Where-Object { $_.RowKey -eq 'Groups-g1' }).Count | Should -Be 1 + ($Remaining | Where-Object { $_.PartitionKey -eq 'fabrikam.com' -and $_.RowKey -eq 'Users-user-a' }).Count | Should -Be 1 + } + + It 'empties a type across AllTenants partitions' { + $Result = Clear-CIPPDbCache -TenantFilter 'AllTenants' -Type 'Users' + + $Result.RemovedCount | Should -Be 3 + $Result.Tenant | Should -Be 'AllTenants' + + $Remaining = @($script:FakeTables['CippReportingDB']) + ($Remaining | Where-Object { $_.RowKey -like 'Users-user*' }).Count | Should -Be 0 + ($Remaining | Where-Object { $_.RowKey -eq 'Users-Count' -and $_.DataCount -eq 0 }).Count | Should -Be 2 + ($Remaining | Where-Object { $_.RowKey -eq 'Groups-g1' }).Count | Should -Be 1 + } + + It 'returns RemovedCount 0 when nothing matches' { + $Result = Clear-CIPPDbCache -TenantFilter 'contoso.com' -Type 'Devices' + $Result.RemovedCount | Should -Be 0 + $Remaining = @($script:FakeTables['CippReportingDB']) + ($Remaining | Where-Object { $_.RowKey -eq 'Devices-Count' }).DataCount | Should -Be 0 + } +} diff --git a/Tests/DBCache/OneDriveLongPaths.Tests.ps1 b/Tests/DBCache/OneDriveLongPaths.Tests.ps1 new file mode 100644 index 0000000000000..73b7e5ba5a2cf --- /dev/null +++ b/Tests/DBCache/OneDriveLongPaths.Tests.ps1 @@ -0,0 +1,328 @@ +# Pester tests for OneDriveLongPaths fan-out, skip-no-UPN, and checkpoint resume. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function Get-CippTable { param($tablename) @{ TableName = $tablename } } + + function Get-FakeTableRows { + param([string]$TableName) + if (-not $script:FakeTables.ContainsKey($TableName)) { + $script:FakeTables[$TableName] = [System.Collections.Generic.List[object]]::new() + } + , $script:FakeTables[$TableName] + } + + function Invoke-FakeTableFilter { + param($Rows, [string]$Filter) + $Result = @($Rows) + if ($Filter -match "PartitionKey eq '([^']*)'") { + $Pk = $Matches[1] + $Result = @($Result | Where-Object { $_.PartitionKey -eq $Pk }) + } + if ($Filter -match "RowKey eq '([^']*)'") { + $Rk = $Matches[1] + $Result = @($Result | Where-Object { $_.RowKey -eq $Rk }) + } + $Result + } + + function ConvertTo-FakeEntity { + param($Entity) + if ($Entity -is [hashtable]) { return [pscustomobject]$Entity } + $Clone = [ordered]@{} + foreach ($Property in $Entity.PSObject.Properties) { $Clone[$Property.Name] = $Property.Value } + [pscustomobject]$Clone + } + + function Get-CIPPAzDataTableEntity { + param($TableName, $Filter, $Property, [switch]$Count) + $Rows = Get-FakeTableRows -TableName $TableName + foreach ($Row in (Invoke-FakeTableFilter -Rows $Rows -Filter $Filter)) { + ConvertTo-FakeEntity -Entity $Row + } + } + + function Add-CIPPAzDataTableEntity { + [CmdletBinding()] + param($TableName, $Entity, [switch]$Force, [switch]$CreateTableIfNotExists) + $Rows = Get-FakeTableRows -TableName $TableName + foreach ($Item in @($Entity)) { + if ($null -eq $Item) { continue } + $New = ConvertTo-FakeEntity -Entity $Item + $Existing = $Rows | Where-Object { $_.PartitionKey -eq $New.PartitionKey -and $_.RowKey -eq $New.RowKey } | Select-Object -First 1 + if ($Existing) { + if (-not $Force) { continue } + [void]$Rows.Remove($Existing) + } + $Rows.Add($New) + } + } + + function Remove-CIPPAzDataTableEntity { + param($TableName, $Entity, [switch]$Force) + $Rows = Get-FakeTableRows -TableName $TableName + foreach ($Item in @($Entity)) { + if ($null -eq $Item) { continue } + $Existing = $Rows | Where-Object { $_.PartitionKey -eq $Item.PartitionKey -and $_.RowKey -eq $Item.RowKey } | Select-Object -First 1 + if ($Existing) { [void]$Rows.Remove($Existing) } + } + } + + function Write-LogMessage { param($headers, $API, $tenant, $message, $sev, $LogData) } + function Get-CippException { param($Exception) [pscustomobject]@{ NormalizedError = "$Exception" } } + function Get-Tenants { param($TenantFilter, [switch]$IncludeErrors) [pscustomobject]@{ customerId = 'tenant-guid'; defaultDomainName = 'contoso.com' } } + function ConvertTo-CIPPODataFilterValue { param($Value, $Type) [string]$Value } + function Update-CippQueueEntry { param($RowKey, $Status, $Name, $TotalTasks, [switch]$IncrementTotalTasks) } + function Start-CIPPOrchestrator { + param($InputObject, $InputObjectGuid, [switch]$CallerIsQueueTrigger) + $script:Orchestrations.Add($InputObject) + } + function Get-CIPPDbItem { param($TenantFilter, $Type, [switch]$CountsOnly) @() } + function New-GraphGetRequest { + param($uri, $tenantid, $scope, $AsApp, [bool]$noPagination, $NoAuthCheck, [bool]$skipTokenCache, $Caller, [switch]$ComplexFilter, [switch]$CountOnly, [switch]$IncludeResponseHeaders, [hashtable]$extraHeaders, [switch]$ReturnRawResponse, [switch]$SkipValueExtraction, [switch]$Stream, [switch]$UseCertificate, $Headers) + & $script:GraphGetHandler $uri $SkipValueExtraction + } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Add-CIPPDbItem.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPDriveItemCloudPathLength.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheOneDriveLongPaths.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/OneDrive Long Paths/Push-DBCacheOneDriveLongPaths.ps1') +} + +Describe 'Set-CIPPDBCacheOneDriveLongPaths' { + BeforeEach { + $script:FakeTables = @{} + $script:Orchestrations = [System.Collections.Generic.List[object]]::new() + $env:CIPP_ONEDRIVE_LONGPATHS_TIMEBOX_SECONDS = '99999' + } + + It 'fans out personal sites and passes UPN when usage map has it' { + $script:GraphGetHandler = { + param($Uri, $SkipValueExtraction) + if ($Uri -match '/organization') { + return @([pscustomobject]@{ displayName = 'Contoso' }) + } + if ($Uri -match 'getAllSites') { + return @( + [pscustomobject]@{ + id = 'contoso-my.sharepoint.com,aaaa,bbbb' + webUrl = 'https://contoso-my.sharepoint.com/personal/known_contoso_com' + sharepointIds = [pscustomobject]@{ siteId = 'site-known' } + } + [pscustomobject]@{ + id = 'contoso-my.sharepoint.com,cccc,dddd' + webUrl = 'https://contoso-my.sharepoint.com/personal/unknown_contoso_com' + sharepointIds = [pscustomobject]@{ siteId = 'site-unknown' } + } + ) + } + if ($Uri -match 'getOneDriveUsageAccountDetail') { + return @([pscustomobject]@{ siteId = 'site-known'; ownerPrincipalName = 'known@contoso.com' }) + } + @() + } + + Set-CIPPDBCacheOneDriveLongPaths -TenantFilter 'contoso.com' + + $script:Orchestrations.Count | Should -Be 1 + $Batch = @($script:Orchestrations[0].Batch) + $Batch.Count | Should -Be 2 + ($Batch | Where-Object { $_.OwnerPrincipalName -eq 'known@contoso.com' }).Count | Should -Be 1 + ($Batch | Where-Object { $_.SiteId -eq 'contoso-my.sharepoint.com,cccc,dddd' -and [string]::IsNullOrWhiteSpace($_.OwnerPrincipalName) }).Count | Should -Be 1 + $Batch[0].InferredLocalRootFixedLength | Should -Be (('C:\Users\').Length + ('\OneDrive - Contoso\').Length) + ((Get-FakeTableRows -TableName 'CippOneDriveLongPathsState') | Where-Object { $_.RowKey -eq 'scan' }).Count | Should -Be 1 + } +} + +Describe 'Push-DBCacheOneDriveLongPaths' { + BeforeEach { + $script:FakeTables = @{} + $script:Orchestrations = [System.Collections.Generic.List[object]]::new() + $env:CIPP_ONEDRIVE_LONGPATHS_TIMEBOX_SECONDS = '99999' + Add-CIPPAzDataTableEntity -TableName 'CippOneDriveLongPathsState' -Entity @{ + PartitionKey = 'contoso.com' + RowKey = 'scan' + ScanId = 'scan-1' + } -Force + } + + It 'writes allowlisted counts and resumes from checkpoint with running totals' { + $LongFolder = ('F' * 200) + $LongName = ('N' * 80) + '.docx' + # Cloud length ~281; with local root for known@contoso / Contoso this exceeds 260. + + $script:GraphGetHandler = { + param($Uri, $SkipValueExtraction) + if ($Uri -match '/sites/.+/drive\?') { + return [pscustomobject]@{ + id = 'b!drive1' + name = 'Documents' + driveType = 'documentLibrary' + owner = [pscustomobject]@{ user = [pscustomobject]@{ userPrincipalName = 'known@contoso.com' } } + } + } + if ($Uri -match '/root/delta' -and $Uri -notmatch 'token=page2') { + $Page = [pscustomobject]@{ + value = @( + [pscustomobject]@{ + id = 'item1' + name = $LongName + folder = $null + file = [pscustomobject]@{} + parentReference = [pscustomobject]@{ path = "/drives/b!drive1/root:/$LongFolder" } + } + ) + '@odata.nextLink' = 'https://graph.microsoft.com/beta/drives/b!drive1/root/delta?token=page2' + } + if ($SkipValueExtraction) { return $Page } + return $Page.value + } + if ($Uri -match 'token=page2') { + $Page = [pscustomobject]@{ + value = @( + [pscustomobject]@{ + id = 'item2' + name = 'short.txt' + folder = $null + file = [pscustomobject]@{} + parentReference = [pscustomobject]@{ path = '/drives/b!drive1/root:' } + } + ) + '@odata.deltaLink' = 'https://graph.microsoft.com/beta/drives/b!drive1/root/delta?token=done' + } + if ($SkipValueExtraction) { return $Page } + return $Page.value + } + @() + } + + $Item = [pscustomobject]@{ + FunctionName = 'DBCacheOneDriveLongPaths' + TenantFilter = 'contoso.com' + SiteId = 'contoso-my.sharepoint.com,aaaa,bbbb' + OwnerPrincipalName = 'known@contoso.com' + OrgDisplayName = 'Contoso' + InferredLocalRootFixedLength = ('C:\Users\').Length + ('\OneDrive - Contoso\').Length + ScanId = 'scan-1' + } + + # Force timebox after first page so resume carries counts. + $env:CIPP_ONEDRIVE_LONGPATHS_TIMEBOX_SECONDS = '0' + Push-DBCacheOneDriveLongPaths -Item $Item + $script:Orchestrations.Count | Should -Be 1 + + $Chk = (Get-FakeTableRows -TableName 'CippOneDriveLongPathsState') | Where-Object { $_.RowKey -like 'chk-*' } | Select-Object -First 1 + $Chk | Should -Not -BeNullOrEmpty + $Chk.StateJson | Should -Not -BeNullOrEmpty + $State = $Chk.StateJson | ConvertFrom-Json + $State.CountOver260 | Should -BeGreaterThan 0 + $State.PSObject.Properties.Name | Should -Not -Contain 'path' + $Carried260 = [int]$State.CountOver260 + + $env:CIPP_ONEDRIVE_LONGPATHS_TIMEBOX_SECONDS = '99999' + $Resume = $script:Orchestrations[0].Batch[0] + Push-DBCacheOneDriveLongPaths -Item $Resume + + $CacheRows = Get-FakeTableRows -TableName 'CippReportingDB' + $CacheRows.Count | Should -Be 1 + $Data = $CacheRows[0].Data | ConvertFrom-Json + $Data.ownerPrincipalName | Should -Be 'known@contoso.com' + $Data.countOver260 | Should -Be $Carried260 + $Data.countOver400 | Should -Be 0 + @($Data.PSObject.Properties.Name | Sort-Object) | Should -Be @('countOver260', 'countOver400', 'id', 'ownerPrincipalName') + $Data.PSObject.Properties.Name | Should -Not -Contain 'webUrl' + $Data.PSObject.Properties.Name | Should -Not -Contain 'name' + } + + It 'resolves owner from drive when UPN was not passed' { + Add-CIPPAzDataTableEntity -TableName 'CippOneDriveLongPathsState' -Entity @{ + PartitionKey = 'contoso.com' + RowKey = 'scan' + ScanId = 'scan-owner' + } -Force + $script:GraphGetHandler = { + param($Uri, $SkipValueExtraction) + if ($Uri -match '/sites/.+/drive\?') { + return [pscustomobject]@{ + id = 'b!drive1' + name = 'Documents' + owner = [pscustomobject]@{ user = [pscustomobject]@{ userPrincipalName = 'fromdrive@contoso.com' } } + } + } + if ($Uri -match '/root/delta') { + $Page = [pscustomobject]@{ + value = @() + '@odata.deltaLink' = 'https://graph.microsoft.com/beta/drives/b!drive1/root/delta?token=done' + } + if ($SkipValueExtraction) { return $Page } + return @() + } + @() + } + + Push-DBCacheOneDriveLongPaths -Item ([pscustomobject]@{ + TenantFilter = 'contoso.com' + SiteId = 'site1' + OwnerPrincipalName = '' + OrgDisplayName = 'Contoso' + InferredLocalRootFixedLength = ('C:\Users\').Length + ('\OneDrive - Contoso\').Length + ScanId = 'scan-owner' + }) + + $Data = (Get-FakeTableRows -TableName 'CippReportingDB')[0].Data | ConvertFrom-Json + $Data.ownerPrincipalName | Should -Be 'fromdrive@contoso.com' + } + + It 'does not $select webUrl on delta' { + Add-CIPPAzDataTableEntity -TableName 'CippOneDriveLongPathsState' -Entity @{ + PartitionKey = 'contoso.com' + RowKey = 'scan' + ScanId = 'scan-2' + } -Force + $script:SeenDelta = $null + $script:GraphGetHandler = { + param($Uri, $SkipValueExtraction) + if ($Uri -match '/sites/.+/drive\?') { + return [pscustomobject]@{ + id = 'b!drive1' + name = 'Documents' + owner = [pscustomobject]@{ user = [pscustomobject]@{ userPrincipalName = 'u@contoso.com' } } + } + } + if ($Uri -match '/root/delta') { + $script:SeenDelta = $Uri + $Page = [pscustomobject]@{ + value = @() + '@odata.deltaLink' = 'https://graph.microsoft.com/beta/drives/b!drive1/root/delta?token=done' + } + if ($SkipValueExtraction) { return $Page } + return @() + } + @() + } + + Push-DBCacheOneDriveLongPaths -Item ([pscustomobject]@{ + TenantFilter = 'contoso.com' + SiteId = 'site1' + OwnerPrincipalName = 'u@contoso.com' + OrgDisplayName = 'Contoso' + InferredLocalRootFixedLength = ('C:\Users\').Length + ('\OneDrive - Contoso\').Length + ScanId = 'scan-2' + }) + + $script:SeenDelta | Should -Match 'parentReference' + $script:SeenDelta | Should -Not -Match 'webUrl' + } + + It 'no-ops when ScanId is superseded' { + $script:GraphGetHandler = { param($Uri, $SkipValueExtraction) throw 'should not call graph' } + Push-DBCacheOneDriveLongPaths -Item ([pscustomobject]@{ + TenantFilter = 'contoso.com' + SiteId = 'site1' + OwnerPrincipalName = 'u@contoso.com' + ScanId = 'old-scan' + }) + (Get-FakeTableRows -TableName 'CippReportingDB').Count | Should -Be 0 + } +} diff --git a/Tests/DBCache/Push-GetCalendarPermissionsBatch.Tests.ps1 b/Tests/DBCache/Push-GetCalendarPermissionsBatch.Tests.ps1 new file mode 100644 index 0000000000000..c11ce40b02d6a --- /dev/null +++ b/Tests/DBCache/Push-GetCalendarPermissionsBatch.Tests.ps1 @@ -0,0 +1,134 @@ +# Pester tests for Push-GetCalendarPermissionsBatch +# +# Phase 1 caches each mailbox's calendar folder name forever; Phase 2 reads permissions from +# it. Get-MailboxFolderStatistics returns EVERY calendar folder flattened under one +# OperationGuid, so picking the wrong row is silent and permanent - it cached holiday +# calendars for over half a tenant, and those mailboxes then cached no permissions at all. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Push-GetCalendarPermissionsBatch.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $FunctionPath) { throw 'Could not locate Push-GetCalendarPermissionsBatch.ps1 under Modules/' } + + # Minimal stubs so Mock has commands to replace during tests. + function Write-LogMessage { param($API, $tenant, $message, $sev, $LogData) } + function Get-CippTable { param($tablename) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property) } + function Add-CIPPAzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function New-ExoBulkRequest { param($tenantid, $cmdletArray, $useSystemMailbox, $Anchor, $NoAuthCheck, $Select, $ReturnWithCommand) } + + . $FunctionPath + + function New-WorkItem { + param($Mailboxes = @('user1@contoso.com')) + [PSCustomObject]@{ + TenantFilter = 'contoso.onmicrosoft.com' + Mailboxes = $Mailboxes + BatchNumber = 1 + TotalBatches = 1 + } + } + + function New-FolderStat { + param($UPN, $Name, $FolderType) + [PSCustomObject]@{ Name = $Name; FolderType = $FolderType; OperationGuid = $UPN } + } +} + +Describe 'Push-GetCalendarPermissionsBatch' { + BeforeEach { + $script:CacheEntries = @() + $script:FolderStats = @() + $script:PermResults = @() + $script:Written = [System.Collections.Generic.List[object]]::new() + $script:ExoCalls = [System.Collections.Generic.List[object]]::new() + + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Get-CippTable -MockWith { @{ Context = 'CalendarFolderCache' } } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $script:CacheEntries } + Mock -CommandName Add-CIPPAzDataTableEntity -MockWith { foreach ($e in @($Entity)) { $script:Written.Add($e) } } + Mock -CommandName New-ExoBulkRequest -MockWith { + $Name = @($cmdletArray)[0].CmdletInput.CmdletName + $script:ExoCalls.Add([PSCustomObject]@{ Cmdlet = $Name; Select = $Select; Array = @($cmdletArray) }) + if ($Name -eq 'Get-MailboxFolderStatistics') { $script:FolderStats } else { $script:PermResults } + } + } + + It 'caches the root calendar even when a subfolder is the last folder returned' { + # The exact ordering that produced the bug: the root arrives first and a localised + # holiday calendar arrives last, so last-wins cached the holiday calendar. + $script:FolderStats = @( + New-FolderStat -UPN 'user1@contoso.com' -Name 'Calendar' -FolderType 'Calendar' + New-FolderStat -UPN 'user1@contoso.com' -Name 'Helligdage i Danmark' -FolderType 'User Created' + New-FolderStat -UPN 'user1@contoso.com' -Name 'Birthdays' -FolderType 'Birthday' + ) + + Push-GetCalendarPermissionsBatch -Item (New-WorkItem) + + $script:Written.Count | Should -Be 1 + $script:Written[0].FolderName | Should -Be 'Calendar' + $script:Written[0].FolderType | Should -Be 'Calendar' + $script:Written[0].RowKey | Should -Be 'user1@contoso.com' + + # ...and Phase 2 must then ask for that folder, not the holiday calendar. + $Phase2 = @($script:ExoCalls | Where-Object { $_.Cmdlet -eq 'Get-MailboxFolderPermission' }) + $Phase2.Count | Should -Be 1 + $Phase2[0].Array[0].CmdletInput.Parameters.Identity | Should -Be 'user1@contoso.com:\Calendar' + } + + It 'skips a mailbox with no root calendar rather than caching a guess' { + $script:FolderStats = @( + New-FolderStat -UPN 'user1@contoso.com' -Name 'United States holidays' -FolderType 'User Created' + ) + + Push-GetCalendarPermissionsBatch -Item (New-WorkItem) + + # Nothing cached, and no permission request built - a wrong name here would stick forever. + $script:Written.Count | Should -Be 0 + Should -Invoke Add-CIPPAzDataTableEntity -Times 0 -Exactly + @($script:ExoCalls | Where-Object { $_.Cmdlet -eq 'Get-MailboxFolderPermission' }).Count | Should -Be 0 + } + + It 'treats a cache entry with no FolderType as a miss so a poisoned cache self-heals' { + # Rows written before the fix carry a folder name but no FolderType, and the name alone + # cannot say whether it is the root or a subfolder. + $script:CacheEntries = @( + [PSCustomObject]@{ PartitionKey = 'contoso.onmicrosoft.com'; RowKey = 'user1@contoso.com'; FolderName = 'Helligdage i Danmark' } + ) + $script:FolderStats = @( + New-FolderStat -UPN 'user1@contoso.com' -Name 'Calendar' -FolderType 'Calendar' + ) + + Push-GetCalendarPermissionsBatch -Item (New-WorkItem) + + @($script:ExoCalls | Where-Object { $_.Cmdlet -eq 'Get-MailboxFolderStatistics' }).Count | Should -Be 1 + $script:Written[0].FolderName | Should -Be 'Calendar' + } + + It 'trusts a cache entry stamped as a root calendar and skips discovery' { + $script:CacheEntries = @( + [PSCustomObject]@{ PartitionKey = 'contoso.onmicrosoft.com'; RowKey = 'user1@contoso.com'; FolderName = 'Kalender'; FolderType = 'Calendar' } + ) + + Push-GetCalendarPermissionsBatch -Item (New-WorkItem) + + @($script:ExoCalls | Where-Object { $_.Cmdlet -eq 'Get-MailboxFolderStatistics' }).Count | Should -Be 0 + $Phase2 = @($script:ExoCalls | Where-Object { $_.Cmdlet -eq 'Get-MailboxFolderPermission' }) + $Phase2[0].Array[0].CmdletInput.Parameters.Identity | Should -Be 'user1@contoso.com:\Kalender' + } + + It 'returns the permissions it read under the Get-MailboxFolderPermission key' { + $script:CacheEntries = @( + [PSCustomObject]@{ PartitionKey = 'contoso.onmicrosoft.com'; RowKey = 'user1@contoso.com'; FolderName = 'Calendar'; FolderType = 'Calendar' } + ) + $script:PermResults = @( + [PSCustomObject]@{ Identity = 'user1@contoso.com:\Calendar'; User = 'Default'; AccessRights = @('Reviewer'); FolderName = 'Calendar'; OperationGuid = 'user1@contoso.com' } + ) + + $Result = Push-GetCalendarPermissionsBatch -Item (New-WorkItem) + + @($Result['Get-MailboxFolderPermission']).Count | Should -Be 1 + @($Result['Get-MailboxFolderPermission'])[0].User | Should -Be 'Default' + } +} diff --git a/Tests/DBCache/Set-CIPPDBCache.Memory.Tests.ps1 b/Tests/DBCache/Set-CIPPDBCache.Memory.Tests.ps1 index 5dce87099fa6f..dd1758ac09323 100644 --- a/Tests/DBCache/Set-CIPPDBCache.Memory.Tests.ps1 +++ b/Tests/DBCache/Set-CIPPDBCache.Memory.Tests.ps1 @@ -30,6 +30,9 @@ BeforeAll { function New-ExoRequest { param($cmdlet, $cmdParams, $Select, $Anchor, $useSystemMailbox, $tenantid, $NoAuthCheck, [switch]$Compliance, $ApiVersion, $ModuleVersion, [switch]$AsApp, [switch]$UseCertificate) } function Test-CIPPStandardLicense { param($StandardName, $TenantFilter, $Preset, [switch]$SkipLog) } function Get-Tenants { param($TenantFilter, [switch]$IncludeErrors) } + function Get-CIPPSPOSite { param($TenantFilter, $SiteUrl) @() } + function Get-SharePointAdminLink { param($Public, $tenantFilter) [PSCustomObject]@{ AdminUrl = 'https://contoso-admin.sharepoint.com'; SharePointUrl = 'https://contoso.sharepoint.com' } } + function Get-CIPPSPOAdminListData { param($TenantFilter, $AdminUrl, $Type) @() } function Update-CippQueueEntry { param($RowKey, $TotalTasks, [switch]$IncrementTotalTasks) } function Start-CIPPOrchestrator { param($InputObject, $InputObjectGuid, [switch]$CallerIsQueueTrigger) } function Get-ExoOnlineStringBytes { param($SizeString) } @@ -80,6 +83,8 @@ BeforeAll { # Real helper, not a stub: it is pure logic with no external calls, and the mailbox collector's # AutoExpandingArchive/AutoExpandingArchiveScope columns are part of the row shape under test. . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPAutoExpandingArchiveState.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/ConvertTo-SPOUsageRootWebTemplate.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPSharePointSiteUsageRows.ps1') . (Get-CollectorPath 'Set-CIPPDBCacheGroups') . (Get-CollectorPath 'Set-CIPPDBCacheTeams') @@ -119,9 +124,11 @@ Describe 'DBCache collectors reworked for bounded memory' { Set-CIPPDBCacheGroups -TenantFilter 'contoso.com' + Should -Invoke New-GraphGetRequest -Times 1 -Exactly -ParameterFilter { $Stream.IsPresent } $script:DbWrites.Count | Should -Be 1 $Rows = $script:DbWrites[0].Rows $Rows.Count | Should -Be 2 + $script:DbWrites[0].EndRan | Should -BeTrue # Members are matched by id, not by position - the bulk response above is deliberately # in a different order than the group list. ($Rows | Where-Object id -EQ 'g1').members.id | Should -Be @('u1a', 'u1b') @@ -130,23 +137,46 @@ Describe 'DBCache collectors reworked for bounded memory' { It 'emits the computed properties in the documented order' { Mock -CommandName New-GraphGetRequest -MockWith { - @([pscustomobject]@{ id = 'g1'; displayName = 'One'; mail = 'one@contoso.com'; groupTypes = @('Unified'); mailEnabled = $true; securityEnabled = $false; resourceProvisioningOptions = @('Team') }) + @([pscustomobject]@{ id = 'g1'; displayName = 'One'; mail = 'one@contoso.com'; groupTypes = @('Unified'); mailEnabled = $true; securityEnabled = $false; resourceProvisioningOptions = @('Team'); owners = @([pscustomobject]@{ id = 'o1'; userPrincipalName = 'owner1@contoso.com' }) }) } Mock -CommandName New-GraphBulkRequest -MockWith { - @([pscustomobject]@{ id = 'g1'; body = [pscustomobject]@{ value = @() } }) + @([pscustomobject]@{ id = 'g1'; body = [pscustomobject]@{ value = @([pscustomobject]@{ id = 'u1'; userPrincipalName = 'user1@contoso.com' }) } }) } Set-CIPPDBCacheGroups -TenantFilter 'contoso.com' + Should -Invoke New-GraphGetRequest -Times 1 -Exactly -ParameterFilter { $Stream.IsPresent } $Row = $script:DbWrites[0].Rows[0] - $Added = @($Row.PSObject.Properties.Name) | Select-Object -Last 6 - $Added | Should -Be @('members', 'primDomain', 'teamsEnabled', 'dynamicGroupBool', 'groupType', 'calculatedGroupType') + # membersCsv/ownersCsv are precomputed so the paged list read can stream the blob + # verbatim; both sit next to their source arrays in the emitted order. hasOwner is + # set unconditionally right after, so the AsRawJson paged read has a stable owner + # flag even for a genuinely owner-less group (where ownersCsv itself never gets set). + $Added = @($Row.PSObject.Properties.Name) | Select-Object -Last 9 + $Added | Should -Be @('members', 'membersCsv', 'ownersCsv', 'hasOwner', 'primDomain', 'teamsEnabled', 'dynamicGroupBool', 'groupType', 'calculatedGroupType') + $Row.membersCsv | Should -Be 'user1@contoso.com' + $Row.ownersCsv | Should -Be 'owner1@contoso.com' + $Row.hasOwner | Should -BeTrue $Row.groupType | Should -Be 'Microsoft 365' $Row.calculatedGroupType | Should -Be 'm365' $Row.primDomain | Should -Be 'contoso.com' $Row.teamsEnabled | Should -BeTrue } + It 'sets hasOwner to false for a genuinely owner-less group' { + Mock -CommandName New-GraphGetRequest -MockWith { + @([pscustomobject]@{ id = 'g1'; displayName = 'One'; mail = 'one@contoso.com'; groupTypes = @('Unified'); mailEnabled = $true; securityEnabled = $false; resourceProvisioningOptions = @('Team'); owners = @() }) + } + Mock -CommandName New-GraphBulkRequest -MockWith { + @([pscustomobject]@{ id = 'g1'; body = [pscustomobject]@{ value = @() } }) + } + + Set-CIPPDBCacheGroups -TenantFilter 'contoso.com' + + $Row = $script:DbWrites[0].Rows[0] + $Row.hasOwner | Should -BeFalse + $Row.PSObject.Properties.Name | Should -Not -Contain 'ownersCsv' + } + It 'omits the members property entirely when no member lookup ran' { # No group carries an id, so no member requests are built - the pre-existing no-members shape. Mock -CommandName New-GraphGetRequest -MockWith { @@ -156,6 +186,7 @@ Describe 'DBCache collectors reworked for bounded memory' { Set-CIPPDBCacheGroups -TenantFilter 'contoso.com' + Should -Invoke New-GraphGetRequest -Times 1 -Exactly -ParameterFilter { $Stream.IsPresent } $Row = $script:DbWrites[0].Rows[0] $Row.PSObject.Properties.Name | Should -Not -Contain 'members' $Row.groupType | Should -Be 'Mail-Enabled Security' @@ -169,8 +200,74 @@ Describe 'DBCache collectors reworked for bounded memory' { Set-CIPPDBCacheGroups -TenantFilter 'contoso.com' + Should -Invoke New-GraphGetRequest -Times 1 -Exactly -ParameterFilter { $Stream.IsPresent } $script:DbWrites[0].Rows[0].PSObject.Properties.Name | Should -Contain 'members' } + + It 'fetches members in batches of 50 and uses a single writer end block' { + $Groups = 1..105 | ForEach-Object { + [pscustomobject]@{ + id = ('g{0:D3}' -f $_) + displayName = "Group $_" + mail = "g$_@contoso.com" + groupTypes = @() + mailEnabled = $true + securityEnabled = $true + resourceProvisioningOptions = @() + } + } + Mock -CommandName New-GraphGetRequest -MockWith { $Groups } + $script:BulkCallCount = 0 + Mock -CommandName New-GraphBulkRequest -MockWith { + $script:BulkCallCount++ + foreach ($Request in $Requests) { + [pscustomobject]@{ id = $Request.id; body = [pscustomobject]@{ value = @() } } + } + } + + Set-CIPPDBCacheGroups -TenantFilter 'contoso.com' + + Should -Invoke New-GraphGetRequest -Times 1 -Exactly -ParameterFilter { $Stream.IsPresent } + $script:BulkCallCount | Should -Be 3 + $script:DbWrites.Count | Should -Be 1 + $script:DbWrites[0].Rows.Count | Should -Be 105 + $script:DbWrites[0].EndRan | Should -BeTrue + } + + It 'writes nothing when the stream is empty, preserving the previous cache' { + Mock -CommandName New-GraphGetRequest -MockWith { @() } + Mock -CommandName New-GraphBulkRequest -MockWith { throw 'should not be called' } + + Set-CIPPDBCacheGroups -TenantFilter 'contoso.com' + + Should -Invoke New-GraphGetRequest -Times 1 -Exactly -ParameterFilter { $Stream.IsPresent } + Should -Invoke New-GraphBulkRequest -Times 0 -Exactly + $script:DbWrites.Count | Should -Be 1 + $script:DbWrites[0].Rows.Count | Should -Be 0 + $script:DbWrites[0].EndRan | Should -BeFalse + } + + It 'skips member lookup for dynamic groups and omits the members property' { + Mock -CommandName New-GraphGetRequest -MockWith { + @( + [pscustomobject]@{ id = 'g-static'; displayName = 'Static'; mail = 'static@contoso.com'; groupTypes = @(); mailEnabled = $true; securityEnabled = $true; resourceProvisioningOptions = @() } + [pscustomobject]@{ id = 'g-dynamic'; displayName = 'Dynamic'; mail = 'dynamic@contoso.com'; groupTypes = @('DynamicMembership'); mailEnabled = $false; securityEnabled = $true; resourceProvisioningOptions = @(); membershipRule = '(user.department -eq "Sales")' } + ) + } + Mock -CommandName New-GraphBulkRequest -MockWith { + param($Requests) + $Requests.id | Should -Be @('g-static') + @([pscustomobject]@{ id = 'g-static'; body = [pscustomobject]@{ value = @([pscustomobject]@{ id = 'u1'; userPrincipalName = 'u1@contoso.com' }) } }) + } + + Set-CIPPDBCacheGroups -TenantFilter 'contoso.com' + + Should -Invoke New-GraphGetRequest -Times 1 -Exactly -ParameterFilter { $Stream.IsPresent } + $Rows = $script:DbWrites[0].Rows + ($Rows | Where-Object id -EQ 'g-static').members.userPrincipalName | Should -Be @('u1@contoso.com') + ($Rows | Where-Object id -EQ 'g-dynamic').PSObject.Properties.Name | Should -Not -Contain 'members' + ($Rows | Where-Object id -EQ 'g-dynamic').dynamicGroupBool | Should -BeTrue + } } Context 'Set-CIPPDBCacheTeams' { @@ -193,15 +290,46 @@ Describe 'DBCache collectors reworked for bounded memory' { Context 'Set-CIPPDBCacheSharePointSiteUsage' { BeforeEach { + Mock -CommandName Get-CIPPSPOSite -MockWith { @() } + Mock -CommandName Get-CIPPSPOAdminListData -MockWith { + @( + [pscustomobject]@{ + Title = 'Site One' + SiteUrl = 'https://c/s1' + SiteId = '{site-1}' + StorageUsed = [int64]1073741824 + StorageQuota = [int64]1024 + StorageQuotaBytes = [int64](1024 * 1MB) + NumOfFiles = [int64]10 + TemplateName = 'STS#3' + SiteOwnerEmail = 'owner1@contoso.com' + SiteOwnerName = 'Owner One' + LastActivityOn = '2026-01-01' + TimeCreated = '2020-01-01' + } + [pscustomobject]@{ + Title = 'Site Two' + SiteUrl = 'https://c/s2' + SiteId = '{site-2}' + StorageUsed = [int64]2048 + StorageQuota = [int64]2048 + StorageQuotaBytes = [int64](2048 * 1MB) + NumOfFiles = [int64]2 + TemplateName = 'GROUP#0' + SiteOwnerEmail = 'owner2@contoso.com' + SiteOwnerName = 'Owner Two' + LastActivityOn = '2026-02-01' + TimeCreated = '2021-01-01' + } + ) + } Mock -CommandName New-GraphBulkRequest -MockWith { - # First call: the site listing + usage report. Second call: the per-site lists. if ($Requests[0].id -eq 'listAllSites') { return @( [pscustomobject]@{ id = 'listAllSites'; body = [pscustomobject]@{ value = @( [pscustomobject]@{ id = 's1'; displayName = 'Site One'; webUrl = 'https://c/s1'; isPersonalSite = $false; sharepointIds = [pscustomobject]@{ siteId = 'site-1'; webId = 'web-1' } } [pscustomobject]@{ id = 's2'; displayName = 'Site Two'; webUrl = 'https://c/s2'; isPersonalSite = $false; sharepointIds = [pscustomobject]@{ siteId = 'site-2'; webId = 'web-2' } } ) } } - [pscustomobject]@{ id = 'usage'; status = 200; body = [pscustomobject]@{ value = @([pscustomobject]@{ siteId = 'site-1' }) } } ) } return @( @@ -233,8 +361,39 @@ Describe 'DBCache collectors reworked for bounded memory' { Set-CIPPDBCacheSharePointSiteUsage -TenantFilter 'contoso.com' ($script:DbWrites | Where-Object Type -EQ 'SharePointSiteListing').Rows.Count | Should -Be 2 - ($script:DbWrites | Where-Object Type -EQ 'SharePointSiteUsage').Rows.Count | Should -Be 1 - ($script:DbWrites | Where-Object Type -EQ 'SharePointSiteUsage').Rows[0].id | Should -Be 'site-1' + ($script:DbWrites | Where-Object Type -EQ 'SharePointSiteUsage').Rows.Count | Should -Be 2 + ($script:DbWrites | Where-Object Type -EQ 'SharePointSiteUsage').Rows[0].siteId | Should -Be 'site-1' + ($script:DbWrites | Where-Object Type -EQ 'SharePointSiteUsage').Rows[0].storageUsedInBytes | Should -Be 1073741824 + ($script:DbWrites | Where-Object Type -EQ 'SharePointSiteUsage').Rows[0].storageAllocatedInBytes | Should -Be (1024 * 1MB) + ($script:DbWrites | Where-Object Type -EQ 'SharePointSiteUsage').Rows[0].ownerPrincipalName | Should -Be 'owner1@contoso.com' + ($script:DbWrites | Where-Object Type -EQ 'SharePointSiteUsage').Rows[0].rootWebTemplate | Should -Be 'STS' + ($script:DbWrites | Where-Object Type -EQ 'SharePointSiteUsage').Rows[1].rootWebTemplate | Should -Be 'Group' + ($script:DbWrites | Where-Object Type -EQ 'SharePointSiteUsage').Rows[0].reportRefreshDate | Should -Not -BeNullOrEmpty + } + + It 'merges file-level archive fields from Get-CIPPSPOSite into the site listing' { + Mock -CommandName Get-CIPPSPOSite -MockWith { + @( + [pscustomobject]@{ + Url = 'https://c/s1' + ArchivedFileDiskUsed = 1073741824 + AllowFileArchive = $true + } + [pscustomobject]@{ + Url = 'https://c/s2/' + ArchivedFileDiskUsed = 0 + AllowFileArchive = $false + } + ) + } + + Set-CIPPDBCacheSharePointSiteUsage -TenantFilter 'contoso.com' + + $Listing = ($script:DbWrites | Where-Object Type -EQ 'SharePointSiteListing').Rows + ($Listing | Where-Object id -EQ 's1').archivedFileDiskUsedBytes | Should -Be 1073741824 + ($Listing | Where-Object id -EQ 's1').allowFileArchive | Should -BeTrue + ($Listing | Where-Object id -EQ 's2').archivedFileDiskUsedBytes | Should -Be 0 + ($Listing | Where-Object id -EQ 's2').allowFileArchive | Should -BeFalse } } diff --git a/Tests/DBCache/Set-CIPPDBCacheDefenderCVEs.Flush.Tests.ps1 b/Tests/DBCache/Set-CIPPDBCacheDefenderCVEs.Flush.Tests.ps1 index 137fd91f0444d..c48b56ee80dca 100644 --- a/Tests/DBCache/Set-CIPPDBCacheDefenderCVEs.Flush.Tests.ps1 +++ b/Tests/DBCache/Set-CIPPDBCacheDefenderCVEs.Flush.Tests.ps1 @@ -122,7 +122,8 @@ Describe 'Set-CIPPDBCacheDefenderCVEs flush semantics' { $Batch.Count | Should -Be 1 $Batch[0].PartitionKey | Should -Be $script:Tenant $Batch[0].Type | Should -Be 'DefenderCVEs' - $Batch[0].RowKey | Should -BeLike 'DefenderCVEs-*' + # Stable, idempotent RowKey derived from the CVE id (was a random GUID per run). + $Batch[0].RowKey | Should -Be 'DefenderCVEs-CVE-2024-0001' # Get-CIPPCVEReport reads these fields off the deserialised Data blob. $Payload = $Batch[0].Data | ConvertFrom-Json diff --git a/Tests/DBCache/Set-CIPPDBCacheDefenderCVEs.Tests.ps1 b/Tests/DBCache/Set-CIPPDBCacheDefenderCVEs.Tests.ps1 index d04d4025a0667..8c3b4ab1e7900 100644 --- a/Tests/DBCache/Set-CIPPDBCacheDefenderCVEs.Tests.ps1 +++ b/Tests/DBCache/Set-CIPPDBCacheDefenderCVEs.Tests.ps1 @@ -14,6 +14,9 @@ BeforeAll { function Get-DefenderTvmRaw { param($TenantId, [int]$MaxPages, [switch]$Stream) } function Get-CippException { param($Exception) } function Write-LogMessage { param($API, $tenant, $message, $sev, $LogData) } + # Not a capability (licence) error by default, so the outer catch takes the normal + # 'CVE Cache Refresh failed' path rather than the skip-and-return branch. + function Test-CIPPCacheCapabilityError { param($Message) $false } function Add-CIPPDbItem { [CmdletBinding()] param( @@ -82,38 +85,31 @@ Describe 'Set-CIPPDBCacheDefenderCVEs' { $Row.PartitionKey | Should -Be 'CVE-2024-0001' $Row.RowKey | Should -Be $script:Tenant + # Stable RowKey source: Add-CIPPDbItem derives "DefenderCVEs-". + $Row.id | Should -Be 'CVE-2024-0001' $Row.customerId | Should -Be $script:Tenant $Row.cveId | Should -Be 'CVE-2024-0001' $Row.softwareVendor | Should -Be 'microsoft' $Row.softwareName | Should -Be 'edge' + $Row.softwareVersion | Should -Be '120.0.0' $Row.vulnerabilitySeverityLevel | Should -Be 'High' - $Row.recommendedSecurityUpdate | Should -Be 'KB5034123' - $Row.recommendedSecurityUpdateUrl | Should -Be 'https://support.microsoft.com/kb/5034123' $Row.exploitabilityLevel | Should -Be 'ExploitIsPublic' $Row.deviceCount | Should -Be 1 # PowerShell 7's -UFormat drops the literal '+' prefix, so the stored stamp is # a bare ISO-8601 UTC string truncated to whole seconds. $Row.lastUpdated | Should -Match '^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.000Z$' + # Dropped fields are no longer stored. + $Row.PSObject.Properties.Name | Should -Not -Contain 'recommendedSecurityUpdate' + $Row.PSObject.Properties.Name | Should -Not -Contain 'recommendedSecurityUpdateUrl' + + # Minimal per-device payload: id and name only. $Devices = $Row.deviceDetailsJson | ConvertFrom-Json $Devices.deviceId | Should -Be 'd1' $Devices.deviceName | Should -Be 'PC-1' - $Devices.osVersion | Should -Be '10.0.19045' - $Devices.softwareVersion | Should -Be '120.0.0' - $Devices.diskPaths | Should -Be '' - $Devices.registryPaths | Should -Be '' - } - - It 'joins disk and registry path arrays with semicolons' { - Mock -CommandName Get-DefenderTvmRaw -MockWith { - New-TvmRecord -diskPaths @('C:\a\edge.exe', 'C:\b\edge.exe') -registryPaths @('HKLM\SOFTWARE\X') - } - - Set-CIPPDBCacheDefenderCVEs -TenantFilter $script:Tenant - - $Devices = $script:Rows[0].deviceDetailsJson | ConvertFrom-Json - $Devices.diskPaths | Should -Be 'C:\a\edge.exe;C:\b\edge.exe' - $Devices.registryPaths | Should -Be 'HKLM\SOFTWARE\X' + $Devices.PSObject.Properties.Name | Should -Not -Contain 'osVersion' + $Devices.PSObject.Properties.Name | Should -Not -Contain 'diskPaths' + $Devices.PSObject.Properties.Name | Should -Not -Contain 'registryPaths' } It 'serialises a single device as a JSON object and multiple devices as a JSON array' { @@ -157,11 +153,37 @@ Describe 'Set-CIPPDBCacheDefenderCVEs' { $Row = $script:Rows[0] $Row.softwareVendor | Should -Be '' $Row.softwareName | Should -Be '' + $Row.softwareVersion | Should -Be '' $Row.vulnerabilitySeverityLevel | Should -Be '' - $Row.recommendedSecurityUpdate | Should -Be '' - $Row.recommendedSecurityUpdateUrl | Should -Be '' $Row.exploitabilityLevel | Should -Be '' } + + It 'counts a device once and stores it once when the same device reports the CVE across several software packages' { + Mock -CommandName Get-DefenderTvmRaw -MockWith { + New-TvmRecord -cveId 'CVE-DEDUP' -deviceId 'd1' -deviceName 'PC-1' -softwareName 'edge' + New-TvmRecord -cveId 'CVE-DEDUP' -deviceId 'd1' -deviceName 'PC-1' -softwareName 'chrome' + New-TvmRecord -cveId 'CVE-DEDUP' -deviceId 'd2' -deviceName 'PC-2' -softwareName 'edge' + } + + Set-CIPPDBCacheDefenderCVEs -TenantFilter $script:Tenant + + $script:Rows.Count | Should -Be 1 + $script:Rows[0].deviceCount | Should -Be 2 + (($script:Rows[0].deviceDetailsJson | ConvertFrom-Json).deviceId | Sort-Object) | Should -Be @('d1', 'd2') + } + + It 'skips software-inventory rows with no CVE without throwing or logging an error' { + Mock -CommandName Get-DefenderTvmRaw -MockWith { + [pscustomobject]@{ cveId = $null; deviceId = 'd0'; deviceName = 'PC-0' } + New-TvmRecord -cveId 'CVE-2024-0009' -deviceId 'd1' + } + + Set-CIPPDBCacheDefenderCVEs -TenantFilter $script:Tenant + + $script:Rows.Count | Should -Be 1 + $script:Rows[0].cveId | Should -Be 'CVE-2024-0009' + Should -Invoke Write-LogMessage -Times 0 -Exactly -ParameterFilter { $sev -eq 'Error' } + } } Context 'CVE bucketing' { diff --git a/Tests/DBCache/SharePointSharingLinks.Resume.Tests.ps1 b/Tests/DBCache/SharePointSharingLinks.Resume.Tests.ps1 index 3ab76fd014d1f..3e608cc6d309e 100644 --- a/Tests/DBCache/SharePointSharingLinks.Resume.Tests.ps1 +++ b/Tests/DBCache/SharePointSharingLinks.Resume.Tests.ps1 @@ -392,11 +392,15 @@ Describe 'Per-drive sharing-links scan' { Context 'incremental scan from a stored delta token' { BeforeEach { $script:ScanId = 'scan-incr-1' + # LastFullScanUtc must sit inside the incremental window (Push-...'s $FullScanDays, + # default 14) or the drive falls back to a full scan. Anchor it to "now" so the + # fixture never drifts out of the window as the calendar advances past a fixed date. + $script:LastFullScanUtc = [string]([DateTimeOffset]::UtcNow.AddDays(-1).ToString('o')) Initialize-TestScan -ScanId $script:ScanId -TotalSites 1 Add-CIPPAzDataTableEntity -TableName 'CippSharingLinksState' -Entity @{ PartitionKey = 'contoso.com'; RowKey = 'delta-b!driveone'; DriveId = 'b!driveone'; SiteId = 'contoso.sharepoint.com,site1,web1' DeltaLink = 'https://graph.microsoft.com/beta/drives/b!driveone/root/delta?token=stored' - LastScanId = 'previous-scan'; LastScanUtc = '2026-08-10T00:00:00Z'; LastFullScanUtc = '2026-08-10T00:00:00Z' + LastScanId = 'previous-scan'; LastScanUtc = $script:LastFullScanUtc; LastFullScanUtc = $script:LastFullScanUtc } Add-CacheRow -RowKey 'SharePointSharingLinks-b!driveone_01ITEMX_permOld' Add-CacheRow -RowKey 'SharePointSharingLinks-b!driveone_01ITEMY_permKeep' @@ -427,7 +431,7 @@ Describe 'Per-drive sharing-links scan' { $DriveState = Get-CIPPSharingLinksDriveState -TenantFilter 'contoso.com' -DriveId 'b!driveone' $DriveState.DeltaLink | Should -BeLike '*token=newer' # Incremental completion must not claim a full scan happened. - $DriveState.LastFullScanUtc | Should -Be '2026-08-10T00:00:00Z' + $DriveState.LastFullScanUtc | Should -Be $script:LastFullScanUtc } It 'falls back to a classic full scan when the stored token is rejected' { @@ -452,7 +456,7 @@ Describe 'Per-drive sharing-links scan' { $DriveState = Get-CIPPSharingLinksDriveState -TenantFilter 'contoso.com' -DriveId 'b!driveone' $DriveState.DeltaLink | Should -BeLike '*token=rebuilt' - $DriveState.LastFullScanUtc | Should -Not -Be '2026-08-10T00:00:00Z' + $DriveState.LastFullScanUtc | Should -Not -Be $script:LastFullScanUtc } } diff --git a/Tests/Endpoint/Invoke-AddAppTemplate.Tests.ps1 b/Tests/Endpoint/Invoke-AddAppTemplate.Tests.ps1 new file mode 100644 index 0000000000000..e7c8b9721f342 --- /dev/null +++ b/Tests/Endpoint/Invoke-AddAppTemplate.Tests.ps1 @@ -0,0 +1,171 @@ +# Pester tests for Invoke-AddAppTemplate +# Covers the guard that keeps applications CIPP cannot rebuild at deploy time out of +# application templates: a config carrying an IntuneBody read straight off Graph (it has an id) +# describes an app whose installer content lives inside Intune. Office and Edge are the exception +# because their body builders replay the stored body after stripping the read-only properties. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + # ContentType is unused by this endpoint but must be here: the endpoint is loaded through + # [ScriptBlock]::Create, which resolves HttpResponseContext against the runspace type table + # shared by every test file loaded the same way. The first such definition wins for the whole + # run, and this file sorts first, so a narrower shape would make the endpoints that do set + # ContentType fail their cast and fall into the wrong branch. + class HttpResponseContext { + [int]$StatusCode + [object]$Body + [object]$ContentType + } + + # Only the helpers these tests actually reach are stubbed. Get-CIPPAzDataTableEntity is not, + # because the endpoint only calls it on the GUID upsert path, which no test here exercises. + function Get-CippTable { param($tablename) @{} } + function Add-CIPPAzDataTableEntity { param([switch]$Force, $Entity) $script:LastEntity = $Entity } + function Write-LogMessage { param($headers, $API, $message, $Sev, $LogData) } + function Get-CippException { + param($Exception) + [pscustomobject]@{ NormalizedError = "$Exception" } + } + + $EndpointPath = Join-Path $RepoRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/Applications/Invoke-AddAppTemplate.ps1' + $EndpointScript = [ScriptBlock]::Create("using namespace System.Net`n" + (Get-Content -LiteralPath $EndpointPath -Raw)) + . $EndpointScript + + # A row as the Applications list hands it to Save as Template: the Graph object, id and all. + function New-GraphAppRow { + param([string]$OdataType, [string]$DisplayName) + [pscustomobject]@{ + '@odata.type' = $OdataType + id = '11111111-2222-3333-4444-555555555555' + displayName = $DisplayName + publishingState = 'published' + createdDateTime = '2026-01-01T00:00:00Z' + } + } + + function New-TemplateRequest { + param([object[]]$Apps, [string]$DisplayName = 'Template A') + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'AddAppTemplate' } + Headers = @{ Authorization = 'Bearer token' } + Body = [pscustomobject]@{ + displayName = $DisplayName + description = '' + apps = $Apps + } + } + } +} + +Describe 'Invoke-AddAppTemplate' { + BeforeEach { + $script:LastEntity = $null + } + + It 'rejects an app whose config holds a Graph body with an id' { + $Row = New-GraphAppRow -OdataType '#microsoft.graph.win32LobApp' -DisplayName 'FortiClient' + $Request = New-TemplateRequest -Apps @( + [pscustomobject]@{ + appType = 'chocolateyApp' + appName = 'FortiClient' + config = (@{ ApplicationName = 'FortiClient'; IntuneBody = $Row; AssignTo = 'On' } | ConvertTo-Json -Depth 15 -Compress) + } + ) + + $Response = Invoke-AddAppTemplate -Request $Request -TriggerMetadata $null + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::InternalServerError) + $Response.Body.Results | Should -Match "'FortiClient' is an existing Intune application with uploaded installer content" + $Response.Body.Results | Should -Match 'rebuilt from a package or script at deployment' + $script:LastEntity | Should -BeNullOrEmpty + } + + It 'rejects the same body when the config is supplied as an object rather than a string' { + $Row = New-GraphAppRow -OdataType '#microsoft.graph.win32LobApp' -DisplayName 'FortiClient' + $Request = New-TemplateRequest -Apps @( + [pscustomobject]@{ + appType = 'win32ScriptApp' + appName = 'FortiClient' + config = [pscustomobject]@{ ApplicationName = 'FortiClient'; IntuneBody = $Row; AssignTo = 'On' } + } + ) + + $Response = Invoke-AddAppTemplate -Request $Request -TriggerMetadata $null + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::InternalServerError) + $Response.Body.Results | Should -Match 'uploaded installer content' + $script:LastEntity | Should -BeNullOrEmpty + } + + It 'rejects the whole template when only one of its apps carries a Graph body' { + $Row = New-GraphAppRow -OdataType '#microsoft.graph.winGetApp' -DisplayName 'Notepad++' + $Request = New-TemplateRequest -Apps @( + [pscustomobject]@{ + appType = 'chocolateyApp' + appName = 'Firefox' + config = (@{ ApplicationName = 'Firefox'; packagename = 'firefox'; AssignTo = 'On' } | ConvertTo-Json -Depth 15 -Compress) + } + [pscustomobject]@{ + appType = 'StoreApp' + appName = 'Notepad++' + config = (@{ ApplicationName = 'Notepad++'; IntuneBody = $Row; AssignTo = 'On' } | ConvertTo-Json -Depth 15 -Compress) + } + ) + + $Response = Invoke-AddAppTemplate -Request $Request -TriggerMetadata $null + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::InternalServerError) + $Response.Body.Results | Should -Match "'Notepad\+\+' is an existing Intune application" + $script:LastEntity | Should -BeNullOrEmpty + } + + It 'still accepts an Office template saved from an existing deployment' { + $Row = New-GraphAppRow -OdataType '#microsoft.graph.officeSuiteApp' -DisplayName 'Microsoft 365 Apps' + $Request = New-TemplateRequest -Apps @( + [pscustomobject]@{ + appType = 'officeApp' + appName = 'Microsoft 365 Apps' + config = (@{ ApplicationName = 'Microsoft 365 Apps'; IntuneBody = $Row; AssignTo = 'On' } | ConvertTo-Json -Depth 15 -Compress) + } + ) + + $Response = Invoke-AddAppTemplate -Request $Request -TriggerMetadata $null + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $Response.Body.Results | Should -Match 'Successfully saved app template' + $script:LastEntity.PartitionKey | Should -Be 'AppTemplate' + $script:LastEntity.JSON | Should -Match '"officeApp"' + } + + It 'still accepts an Edge template saved from an existing deployment' { + $Row = New-GraphAppRow -OdataType '#microsoft.graph.windowsMicrosoftEdgeApp' -DisplayName 'Microsoft Edge' + $Request = New-TemplateRequest -Apps @( + [pscustomobject]@{ + appType = 'edgeApp' + appName = 'Microsoft Edge' + config = (@{ ApplicationName = 'Microsoft Edge'; IntuneBody = $Row; AssignTo = 'On' } | ConvertTo-Json -Depth 15 -Compress) + } + ) + + $Response = Invoke-AddAppTemplate -Request $Request -TriggerMetadata $null + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $script:LastEntity.JSON | Should -Match '"edgeApp"' + } + + It 'still accepts a wizard built template with no stored Graph body' { + $Request = New-TemplateRequest -Apps @( + [pscustomobject]@{ + appType = 'chocolateyApp' + appName = 'Firefox' + config = (@{ applicationName = 'Firefox'; packagename = 'firefox'; AssignTo = 'On' } | ConvertTo-Json -Depth 15 -Compress) + } + ) + + $Response = Invoke-AddAppTemplate -Request $Request -TriggerMetadata $null + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $script:LastEntity.JSON | Should -Match '"firefox"' + } +} diff --git a/Tests/Endpoint/Invoke-AddPIMRoleSettingsTemplate.Tests.ps1 b/Tests/Endpoint/Invoke-AddPIMRoleSettingsTemplate.Tests.ps1 new file mode 100644 index 0000000000000..71a238604586b --- /dev/null +++ b/Tests/Endpoint/Invoke-AddPIMRoleSettingsTemplate.Tests.ps1 @@ -0,0 +1,215 @@ +# Pester tests for Invoke-AddPIMRoleSettingsTemplate. +# +# A PIM role settings template that weakens a tenant below the secure floor must be rejected at +# save time with the reasons, and nothing may be written. A template above the recommended +# activation (8h) but inside the hard cap (24h) saves with a warning that reaches the logbook. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-AddPIMRoleSettingsTemplate.ps1' + if (-not (Test-Path $FunctionPath)) { throw "Could not locate Invoke-AddPIMRoleSettingsTemplate.ps1 at $FunctionPath" } + + class HttpResponseContext { + [object]$StatusCode + [object]$Body + } + $Accelerators = [PSObject].Assembly.GetType('System.Management.Automation.TypeAccelerators') + if (-not ('HttpStatusCode' -as [type])) { + $Accelerators::Add('HttpStatusCode', [System.Net.HttpStatusCode]) + } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/PIM/ConvertTo-CIPPPIMRoleSettings.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/PIM/Test-CIPPPIMRoleSettingsFloor.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/PIM/ConvertFrom-CIPPPIMPolicyRules.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/PIM/Repair-CIPPPIMRoleSettingsFloor.ps1') + + function Get-CIPPPIMRolePolicies { param($TenantFilter) } + function Get-CippTable { param($tablename) @{} } + function Get-CIPPAzDataTableEntity { param($Filter) } + function Add-CIPPAzDataTableEntity { param($Entity, $Force) } + function ConvertTo-CIPPODataFilterValue { param($Value, $Type) $Value } + function Write-LogMessage { param($headers, $API, $tenant, $message, $Sev, $LogData) } + function Get-CippException { param($Exception) @{ NormalizedError = "$Exception" } } + + . $FunctionPath + + function New-TemplateRequest { + param([hashtable]$Settings = @{}, [hashtable]$Body = @{}) + $DefaultSettings = @{ + activationMaxDuration = 'PT8H' + activationRequires = @{ label = 'MFA'; value = 'MFA' } + activationRequiresJustification = $true + eligibilityMaxDuration = 'P365D' + activeAssignmentMaxDuration = 'P180D' + activeAssignmentRequiresJustification = $true + } + foreach ($Key in $Settings.Keys) { $DefaultSettings[$Key] = $Settings[$Key] } + $RequestBody = [pscustomobject]@{ + templateName = 'Secure PIM' + description = 'test' + roleScope = @{ label = 'Privileged roles'; value = 'PrivilegedRoles' } + roles = @() + settings = [pscustomobject]$DefaultSettings + } + foreach ($Key in $Body.Keys) { $RequestBody | Add-Member -NotePropertyName $Key -NotePropertyValue $Body[$Key] -Force } + [pscustomobject]@{ + Body = $RequestBody + Headers = @{ 'x-ms-client-principal' = [Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes('{"userDetails":"tester@cipp"}')) } + Params = @{ CIPPEndpoint = 'AddPIMRoleSettingsTemplate' } + } + } +} + +Describe 'Invoke-AddPIMRoleSettingsTemplate' { + BeforeEach { + $script:Saved = $null + Mock Get-CippTable { @{} } + Mock Get-CIPPAzDataTableEntity { $null } + Mock Add-CIPPAzDataTableEntity { $script:Saved = $Entity } + Mock Write-LogMessage {} + } + + It 'saves a template that meets the floor' { + $Response = Invoke-AddPIMRoleSettingsTemplate -Request (New-TemplateRequest) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + Should -Invoke Add-CIPPAzDataTableEntity -Times 1 -Exactly + $script:Saved.PartitionKey | Should -Be 'PIMRoleSettingsTemplate' + $Stored = $script:Saved.JSON | ConvertFrom-Json + $Stored.templateName | Should -Be 'Secure PIM' + $Stored.roleScope | Should -Be 'PrivilegedRoles' + $Stored.settings.activationRequires | Should -Be 'MFA' + $Stored.settings.activationMaxDuration | Should -Be 'PT8H' + $Stored.createdBy | Should -Be 'tester@cipp' + } + + It 'rejects a template below the floor and writes nothing' { + $Response = Invoke-AddPIMRoleSettingsTemplate -Request (New-TemplateRequest @{ activationRequires = 'None'; activationMaxDuration = 'PT48H' }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + $Text = ($Response.Body.Results | ForEach-Object { if ($_ -is [string]) { $_ } else { $_.resultText } }) -join ' ' + $Text | Should -Match 'below the secure floor' + $Text | Should -Match 'exceeds the maximum of PT24H' + $Text | Should -Match 'must require MFA or an authentication context' + Should -Invoke Add-CIPPAzDataTableEntity -Times 0 -Exactly + } + + It 'rejects a template that allows permanent eligibility' { + $Response = Invoke-AddPIMRoleSettingsTemplate -Request (New-TemplateRequest @{ eligibilityMaxDuration = '' }) + # An empty duration is normalised to the secure default, so permanence can only be + # expressed by exceeding the cap - which is refused. + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $Response = Invoke-AddPIMRoleSettingsTemplate -Request (New-TemplateRequest @{ eligibilityMaxDuration = 'P10Y' }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + } + + It 'saves with a warning when activation exceeds the recommended 8h but not the 24h cap' { + $Response = Invoke-AddPIMRoleSettingsTemplate -Request (New-TemplateRequest @{ activationMaxDuration = 'PT12H' }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $Warnings = @($Response.Body.Results | Where-Object { $_ -isnot [string] -and $_.state -eq 'warning' }) + $Warnings.Count | Should -Be 1 + $Warnings[0].resultText | Should -Match 'exceeds the recommended PT8H' + Should -Invoke Write-LogMessage -Times 1 -ParameterFilter { $Sev -eq 'Warning' -and $message -match 'exceeds the recommended' } + } + + It 'requires roles when the scope is Custom' { + $Response = Invoke-AddPIMRoleSettingsTemplate -Request (New-TemplateRequest -Body @{ roleScope = 'Custom'; roles = @() }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + Should -Invoke Add-CIPPAzDataTableEntity -Times 0 -Exactly + } + + It 'updates in place when a GUID is supplied and keeps the original creator' { + $script:Existing = [pscustomobject]@{ RowKey = 'abc'; GUID = 'abc'; JSON = (@{ templateName = 'Old'; createdBy = 'first@cipp'; createdDate = '2026-01-01T00:00:00Z' } | ConvertTo-Json -Compress) } + Mock Get-CIPPAzDataTableEntity { $script:Existing } + $Response = Invoke-AddPIMRoleSettingsTemplate -Request (New-TemplateRequest -Body @{ GUID = 'abc' }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $script:Saved.RowKey | Should -Be 'abc' + ($script:Saved.JSON | ConvertFrom-Json).createdBy | Should -Be 'first@cipp' + ($script:Saved.JSON | ConvertFrom-Json).updatedBy | Should -Be 'tester@cipp' + } + + Context 'capture from a role' { + BeforeEach { + # Roles & PIM page action: no settings, no roleScope, just the role to capture. + $script:CaptureBody = @{ + captureRoleId = '644ef478-e28f-4e28-b9dc-3fdde9aa0b1f' + captureRoleName = 'Printer Administrator' + tenantFilter = 'tenant.example.com' + roleScope = $null + roles = @() + settings = $null + description = '' + } + } + + It 'captures a compliant role exactly, with no adjustments' { + Mock Get-CIPPPIMRolePolicies { + @([pscustomobject]@{ + RoleDefinitionId = '644ef478-e28f-4e28-b9dc-3fdde9aa0b1f' + PolicyId = 'DirectoryRole_p1' + Rules = @( + @{ id = 'Expiration_EndUser_Assignment'; isExpirationRequired = $true; maximumDuration = 'PT4H' } + @{ id = 'Enablement_EndUser_Assignment'; enabledRules = @('MultiFactorAuthentication', 'Justification') } + @{ id = 'Expiration_Admin_Eligibility'; isExpirationRequired = $true; maximumDuration = 'P180D' } + @{ id = 'Expiration_Admin_Assignment'; isExpirationRequired = $true; maximumDuration = 'P90D' } + @{ id = 'Enablement_Admin_Assignment'; enabledRules = @('MultiFactorAuthentication', 'Justification') } + ) + }) + } + $Response = Invoke-AddPIMRoleSettingsTemplate -Request (New-TemplateRequest -Body $script:CaptureBody) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $Stored = $script:Saved.JSON | ConvertFrom-Json + $Stored.settings.activationMaxDuration | Should -Be 'PT4H' + $Stored.settings.activationRequires | Should -Be 'MFA' + $Stored.settings.eligibilityMaxDuration | Should -Be 'P180D' + $Stored.settings.activeAssignmentMaxDuration | Should -Be 'P90D' + $Stored.roleScope | Should -Be 'Custom' + @($Stored.roles).value | Should -Be '644ef478-e28f-4e28-b9dc-3fdde9aa0b1f' + $Stored.description | Should -Match 'Captured from the Printer Administrator role' + @($Response.Body.Results | Where-Object { $_ -isnot [string] -and $_.resultText -match 'Raised to the secure floor' }).Count | Should -Be 0 + } + + It 'raises a below-floor role to the floor and reports every raise' { + Mock Get-CIPPPIMRolePolicies { + # Entra defaults: no MFA on activation, permanent eligibility and active allowed. + @([pscustomobject]@{ + RoleDefinitionId = '644ef478-e28f-4e28-b9dc-3fdde9aa0b1f' + PolicyId = 'DirectoryRole_p1' + Rules = @( + @{ id = 'Expiration_EndUser_Assignment'; isExpirationRequired = $true; maximumDuration = 'PT8H' } + @{ id = 'Enablement_EndUser_Assignment'; enabledRules = @('Justification') } + @{ id = 'Expiration_Admin_Eligibility'; isExpirationRequired = $false; maximumDuration = 'P365D' } + @{ id = 'Expiration_Admin_Assignment'; isExpirationRequired = $false; maximumDuration = 'P180D' } + @{ id = 'Enablement_Admin_Assignment'; enabledRules = @('Justification') } + ) + }) + } + $Response = Invoke-AddPIMRoleSettingsTemplate -Request (New-TemplateRequest -Body $script:CaptureBody) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $Stored = $script:Saved.JSON | ConvertFrom-Json + $Stored.settings.activationRequires | Should -Be 'MFA' + $Stored.settings.eligibilityMaxDuration | Should -Be 'P365D' + $Stored.settings.activeAssignmentMaxDuration | Should -Be 'P365D' + $Raises = @($Response.Body.Results | Where-Object { $_ -isnot [string] -and $_.resultText -match 'Raised to the secure floor' }) + $Raises.Count | Should -Be 3 + ($Raises.resultText -join ' ') | Should -Match 'MFA' + ($Raises.resultText -join ' ') | Should -Match 'Eligible assignments' + ($Raises.resultText -join ' ') | Should -Match 'Active assignments' + Should -Invoke Write-LogMessage -Times 3 -ParameterFilter { $Sev -eq 'Warning' -and $message -match 'raised to the secure floor' } + } + + It 'returns 400 when the role has no PIM policy in the tenant' { + Mock Get-CIPPPIMRolePolicies { @() } + $Response = Invoke-AddPIMRoleSettingsTemplate -Request (New-TemplateRequest -Body $script:CaptureBody) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + ($Response.Body.Results -join ' ') | Should -Match 'No PIM role management policy' + Should -Invoke Add-CIPPAzDataTableEntity -Times 0 -Exactly + } + + It 'requires a single tenant to capture from' { + $script:CaptureBody.tenantFilter = 'AllTenants' + $Response = Invoke-AddPIMRoleSettingsTemplate -Request (New-TemplateRequest -Body $script:CaptureBody) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + ($Response.Body.Results -join ' ') | Should -Match 'single tenantFilter' + Should -Invoke Add-CIPPAzDataTableEntity -Times 0 -Exactly + } + } +} diff --git a/Tests/Endpoint/Invoke-EditTenant.Tests.ps1 b/Tests/Endpoint/Invoke-EditTenant.Tests.ps1 new file mode 100644 index 0000000000000..3655260a282b3 --- /dev/null +++ b/Tests/Endpoint/Invoke-EditTenant.Tests.ps1 @@ -0,0 +1,140 @@ +# Pester tests for Invoke-EditTenant +# +# Tenant group membership changes are gated on the group being static. Groups created +# before dynamic groups shipped have no GroupType property at all, and the table service +# skips property-missing entities in comparison filters - so the static/dynamic split has +# to happen client-side or those groups can never be added or removed from this endpoint +# (CyberDrain/CIPP#389). + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Invoke-EditTenant.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $FunctionPath) { throw 'Could not locate Invoke-EditTenant.ps1 under Modules/' } + + class HttpResponseContext { + [object]$StatusCode + [object]$Body + } + + $Accelerators = [psobject].Assembly.GetType('System.Management.Automation.TypeAccelerators') + if (-not $Accelerators::Get.ContainsKey('HttpStatusCode')) { + $Accelerators::Add('HttpStatusCode', [System.Net.HttpStatusCode]) + } + + function Get-CippTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter) } + function Add-CIPPAzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Remove-CIPPAzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Get-Tenants { param($TenantFilter, [switch]$TriggerRefresh) } + function Get-TenantGroups { param([switch]$SkipCache) } + function Write-LogMessage { param($headers, $API, $tenant, $TenantId, $message, $Sev) } + + . $FunctionPath + + $script:CustomerId = 'f0e1d2c3-0000-0000-0000-000000000001' + $script:StaticGroupId = '11111111-1111-1111-1111-111111111111' + $script:LegacyGroupId = '22222222-2222-2222-2222-222222222222' + $script:DynamicGroupId = '33333333-3333-3333-3333-333333333333' + + function New-EditRequest { + param($TenantGroups) + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'EditTenant' } + Headers = @{ } + Body = [pscustomobject]@{ + customerId = $script:CustomerId + tenantAlias = $null + tenantGroups = $TenantGroups + } + Query = [pscustomobject]@{ } + } + } +} + +Describe 'Invoke-EditTenant tenant groups' { + BeforeEach { + $script:GroupEntities = @( + [pscustomobject]@{ PartitionKey = 'TenantGroup'; RowKey = $script:StaticGroupId; Name = 'Whatever - Do this'; GroupType = 'static' } + # Legacy group: created before dynamic groups existed, no GroupType property at all + [pscustomobject]@{ PartitionKey = 'TenantGroup'; RowKey = $script:LegacyGroupId; Name = 'Whatever - Exclude that' } + [pscustomobject]@{ PartitionKey = 'TenantGroup'; RowKey = $script:DynamicGroupId; Name = 'Whatever - Dynamic'; GroupType = 'dynamic' } + ) + $script:MemberEntities = @() + + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Get-CippTable -MockWith { @{ Context = $TableName } } + Mock -CommandName Add-CIPPAzDataTableEntity -MockWith { } + Mock -CommandName Remove-CIPPAzDataTableEntity -MockWith { } + Mock -CommandName Get-TenantGroups -MockWith { } + Mock -CommandName Get-Tenants -MockWith { + [pscustomobject]@{ customerId = $script:CustomerId; defaultDomainName = 'contoso.onmicrosoft.com'; displayName = 'Contoso' } + } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + switch ($Context) { + 'TenantGroups' { + if ($Filter -like '*GroupType*') { + # Emulate table-service semantics: a comparison filter on GroupType + # skips entities that do not carry the property at all + $script:GroupEntities | Where-Object { $null -ne $_.PSObject.Properties['GroupType'] -and $_.GroupType -ne 'dynamic' } + } else { + $script:GroupEntities + } + } + 'TenantGroupMembers' { + if ($Filter -like "*'$($script:CustomerId)'*") { $script:MemberEntities } else { @() } + } + default { @() } + } + } + } + + It 'adds membership for a legacy group that has no GroupType property' { + $Request = New-EditRequest -TenantGroups @( + [pscustomobject]@{ groupId = $script:StaticGroupId; groupName = 'Whatever - Do this' } + [pscustomobject]@{ groupId = $script:LegacyGroupId; groupName = 'Whatever - Exclude that' } + ) + + $Response = Invoke-EditTenant -Request $Request -TriggerMetadata $null + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + Should -Invoke Add-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { + $Entity.GroupId -eq $script:StaticGroupId -and $Entity.customerId -eq $script:CustomerId + } + Should -Invoke Add-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { + $Entity.GroupId -eq $script:LegacyGroupId -and $Entity.customerId -eq $script:CustomerId + } + } + + It 'does not add membership for a dynamic group' { + $Request = New-EditRequest -TenantGroups @( + [pscustomobject]@{ groupId = $script:DynamicGroupId; groupName = 'Whatever - Dynamic' } + ) + + $Response = Invoke-EditTenant -Request $Request -TriggerMetadata $null + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + Should -Invoke Add-CIPPAzDataTableEntity -Times 0 -Exactly + } + + It 'removes a deselected legacy group that has no GroupType property' { + $script:MemberEntities = @( + [pscustomobject]@{ + PartitionKey = 'Member' + RowKey = '{0}-{1}' -f $script:LegacyGroupId, $script:CustomerId + GroupId = $script:LegacyGroupId + customerId = $script:CustomerId + } + ) + $Request = New-EditRequest -TenantGroups @( + [pscustomobject]@{ groupId = $script:StaticGroupId; groupName = 'Whatever - Do this' } + ) + + $Response = Invoke-EditTenant -Request $Request -TriggerMetadata $null + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + Should -Invoke Remove-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { + $Entity.GroupId -eq $script:LegacyGroupId + } + } +} diff --git a/Tests/Endpoint/Invoke-ExecAppServiceDomains.Tests.ps1 b/Tests/Endpoint/Invoke-ExecAppServiceDomains.Tests.ps1 new file mode 100644 index 0000000000000..931edc72ea4b1 --- /dev/null +++ b/Tests/Endpoint/Invoke-ExecAppServiceDomains.Tests.ps1 @@ -0,0 +1,74 @@ +# Pester tests for the AddBinding action of Invoke-ExecAppServiceDomains. +# ARM only validates ownership through the alias record when customHostNameDnsRecordType is set +# explicitly; without it the bind demands an asuid TXT record and fails on a perfectly good CNAME. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecAppServiceDomains.ps1' + if (-not (Test-Path $FunctionPath)) { throw "Could not locate Invoke-ExecAppServiceDomains.ps1 at $FunctionPath" } + + class HttpResponseContext { + [object]$StatusCode + [object]$Body + } + $Accelerators = [PSObject].Assembly.GetType('System.Management.Automation.TypeAccelerators') + if (-not ('HttpStatusCode' -as [type])) { + $Accelerators::Add('HttpStatusCode', [System.Net.HttpStatusCode]) + } + + function Get-CIPPAppServiceSite { param($ApiVersion) } + function New-CIPPAzRestRequest { param($Uri, $Method, $Body, $ContentType) } + function Write-LogMessage { param($API, $headers, $message, $sev, $LogData) } + function Get-CippException { param($Exception) @{ NormalizedError = "$Exception" } } + + . $FunctionPath + + function New-DomainRequest { + param([string]$Action, [string]$Hostname) + [pscustomobject]@{ + Body = [pscustomobject]@{ Action = $Action; Hostname = $Hostname } + Query = [pscustomobject]@{} + Headers = @{} + Params = @{ CIPPEndpoint = 'ExecAppServiceDomains' } + } + } +} + +Describe 'Invoke-ExecAppServiceDomains AddBinding' { + BeforeEach { + Mock -CommandName Get-CIPPAppServiceSite -MockWith { + [pscustomobject]@{ + SiteName = 'cippxyz' + ArmBase = 'https://management.azure.com/subscriptions/sub/resourceGroups/rg/providers/Microsoft.Web/sites/cippxyz' + ApiVersion = '2024-11-01' + Site = [pscustomobject]@{ properties = [pscustomobject]@{ defaultHostName = 'cippxyz.azurewebsites.net'; inboundIpAddress = '1.2.3.4' } } + } + } + Mock -CommandName New-CIPPAzRestRequest -MockWith { [pscustomobject]@{} } + Mock -CommandName Write-LogMessage + } + + It 'binds a subdomain with CNAME validation' { + $Response = Invoke-ExecAppServiceDomains -Request (New-DomainRequest -Action 'AddBinding' -Hostname 'Portal.Contoso.com ') + + $Response.StatusCode | Should -Be ([HttpStatusCode]::OK) + Should -Invoke New-CIPPAzRestRequest -Times 1 -Exactly -ParameterFilter { + $Method -eq 'PUT' -and $Uri -like '*/hostNameBindings/portal.contoso.com?*' -and $Body.properties.customHostNameDnsRecordType -eq 'CName' + } + } + + It 'binds an apex domain with A record validation' { + Invoke-ExecAppServiceDomains -Request (New-DomainRequest -Action 'AddBinding' -Hostname 'contoso.com') | Out-Null + + Should -Invoke New-CIPPAzRestRequest -Times 1 -Exactly -ParameterFilter { + $Body.properties.customHostNameDnsRecordType -eq 'A' + } + } + + It 'refuses the platform hostname' { + $Response = Invoke-ExecAppServiceDomains -Request (New-DomainRequest -Action 'AddBinding' -Hostname 'cippxyz.azurewebsites.net') + + $Response.StatusCode | Should -Be ([HttpStatusCode]::BadRequest) + Should -Invoke New-CIPPAzRestRequest -Times 0 + } +} diff --git a/Tests/Endpoint/Invoke-ExecCippReplacemap.Tests.ps1 b/Tests/Endpoint/Invoke-ExecCippReplacemap.Tests.ps1 index ee56f7fe95b96..35517c9315279 100644 --- a/Tests/Endpoint/Invoke-ExecCippReplacemap.Tests.ps1 +++ b/Tests/Endpoint/Invoke-ExecCippReplacemap.Tests.ps1 @@ -35,6 +35,7 @@ BeforeAll { function Add-CIPPAzDataTableEntity { param($Entity, [switch]$Force) $script:SavedEntity = $Entity } function Remove-CIPPAzDataTableEntity { param($Entity, [switch]$Force) $script:RemovedEntity = $Entity } function Get-Tenants { param($TenantFilter, [switch]$IncludeErrors) } + function Write-LogMessage { param($headers, $API, $tenant, $message, $Sev, $LogData) } . $FunctionPath diff --git a/Tests/Endpoint/Invoke-ExecEmptySiteRecycleBin.Tests.ps1 b/Tests/Endpoint/Invoke-ExecEmptySiteRecycleBin.Tests.ps1 new file mode 100644 index 0000000000000..7cf4917211e4a --- /dev/null +++ b/Tests/Endpoint/Invoke-ExecEmptySiteRecycleBin.Tests.ps1 @@ -0,0 +1,148 @@ +# Pester tests for Invoke-ExecEmptySiteRecycleBin and Invoke-ListSiteRecycleBinSummary + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $ExecPath = Join-Path $RepoRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecEmptySiteRecycleBin.ps1' + $SummaryPath = Join-Path $RepoRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteRecycleBinSummary.ps1' + if (-not (Test-Path $ExecPath)) { throw "Could not locate $ExecPath" } + if (-not (Test-Path $SummaryPath)) { throw "Could not locate $SummaryPath" } + + class HttpResponseContext { + [object]$StatusCode + [object]$Body + } + $Accelerators = [PSObject].Assembly.GetType('System.Management.Automation.TypeAccelerators') + if (-not ('HttpStatusCode' -as [type])) { + $Accelerators::Add('HttpStatusCode', [System.Net.HttpStatusCode]) + } + + function Get-SharePointAdminLink { param($Public, $tenantFilter) [PSCustomObject]@{ SharePointUrl = 'https://contoso.sharepoint.com'; AdminUrl = 'https://contoso-admin.sharepoint.com' } } + function Resolve-CIPPSharePointRestContext { + param($TenantFilter, $SiteUrl) + $BaseUri = 'https://contoso.sharepoint.com/sites/a/_api' + [PSCustomObject]@{ + Scope = 'https://contoso.sharepoint.com/.default' + Headers = @{ Accept = 'application/json;odata=nometadata' } + BaseUri = $BaseUri + WebUri = "$BaseUri/web" + } + } + function Write-LogMessage { param($Headers, $API, $tenant, $message, $sev, $LogData) } + function Get-CippException { param($Exception) [PSCustomObject]@{ NormalizedError = $Exception.Message } } + + . $ExecPath + . $SummaryPath +} + +Describe 'Invoke-ExecEmptySiteRecycleBin' { + BeforeEach { + $script:GraphPostCalls = 0 + function global:New-GraphPostRequest { + param( + $uri, $tenantid, $scope, $type, $body, $contentType, $AddedHeaders, + [switch]$UseCertificate, + $AsApp + ) + $script:GraphPostCalls++ + } + function global:New-GraphGetRequest { + param( + $uri, $tenantid, $scope, $AsApp, $extraHeaders, + [switch]$UseCertificate, + [bool]$noPagination, + [switch]$SkipValueExtraction + ) + } + } + + It 'returns BadRequest when SiteUrl is missing' { + $Response = Invoke-ExecEmptySiteRecycleBin -Request ([pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ExecEmptySiteRecycleBin' } + Headers = @{} + Body = [pscustomobject]@{ tenantFilter = 'contoso.onmicrosoft.com'; Stage = 'Both' } + }) + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + } + + It 'returns BadRequest for invalid Stage' { + $Response = Invoke-ExecEmptySiteRecycleBin -Request ([pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ExecEmptySiteRecycleBin' } + Headers = @{} + Body = [pscustomobject]@{ + tenantFilter = 'contoso.onmicrosoft.com' + SiteUrl = 'https://contoso.sharepoint.com/sites/a' + Stage = 'Nope' + } + }) + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + $Response.Body.Results | Should -Match 'Invalid Stage' + } + + It 'calls deleteAll endpoints for Both' { + $Response = Invoke-ExecEmptySiteRecycleBin -Request ([pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ExecEmptySiteRecycleBin' } + Headers = @{} + Body = [pscustomobject]@{ + tenantFilter = 'contoso.onmicrosoft.com' + SiteUrl = 'https://contoso.sharepoint.com/sites/a' + Stage = 'Both' + } + }) + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $script:GraphPostCalls | Should -Be 2 + $Response.Body.Results | Should -Match 'Emptied recycle bin' + } +} + +Describe 'Invoke-ListSiteRecycleBinSummary' { + BeforeEach { + function global:New-GraphGetRequest { + param( + $uri, $tenantid, $scope, $AsApp, $extraHeaders, + [switch]$UseCertificate, + [bool]$noPagination, + [switch]$SkipValueExtraction + ) + [PSCustomObject]@{ + value = @( + [PSCustomObject]@{ Id = '1'; Size = 100; ItemState = 1 } + [PSCustomObject]@{ Id = '2'; Size = 50; ItemState = 2 } + ) + '@odata.nextLink' = $null + } + } + } + + It 'returns BadRequest when SiteUrl is missing' { + $Response = Invoke-ListSiteRecycleBinSummary -Request ([pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ListSiteRecycleBinSummary' } + Headers = @{} + Query = @{ tenantFilter = 'contoso.onmicrosoft.com' } + Body = @{} + }) + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + } + + It 'aggregates sizes without returning names' { + $Response = Invoke-ListSiteRecycleBinSummary -Request ([pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ListSiteRecycleBinSummary' } + Headers = @{} + Query = @{ + tenantFilter = 'contoso.onmicrosoft.com' + SiteUrl = 'https://contoso.sharepoint.com/sites/a' + } + Body = @{} + }) + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $Response.Body.Results.totalBytes | Should -Be 150 + $Response.Body.Results.firstStageBytes | Should -Be 100 + $Response.Body.Results.secondStageBytes | Should -Be 50 + ($Response.Body.Results.PSObject.Properties.Name -contains 'Title') | Should -BeFalse + ($Response.Body.Results.PSObject.Properties.Name -contains 'LeafName') | Should -BeFalse + } +} diff --git a/Tests/Endpoint/Invoke-ExecOffboardUser.Tests.ps1 b/Tests/Endpoint/Invoke-ExecOffboardUser.Tests.ps1 index 29c067ff56ee7..a29f313a3b3fd 100644 --- a/Tests/Endpoint/Invoke-ExecOffboardUser.Tests.ps1 +++ b/Tests/Endpoint/Invoke-ExecOffboardUser.Tests.ps1 @@ -23,7 +23,10 @@ BeforeAll { } function Test-CIPPOffboardingRequest { param($Body) } - function Add-CIPPScheduledTask { param($Task, $hidden, $Headers, $RunNow, $DisallowDuplicateName) } + function Add-CIPPScheduledTask { param($Task, $hidden, $Headers, [switch]$RunNow, $DisallowDuplicateName, $RowKey) } + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter) } + function New-CIPPAsyncDeployment { param($JobId, $Names, $StepTitles, $Source) } function Write-LogMessage { param($headers, $API, $tenant, $message, $Sev, $LogData) } . $FunctionPath @@ -42,6 +45,32 @@ BeforeAll { Body = $RequestBody Headers = @{} Params = @{ CIPPEndpoint = 'ExecOffboardUser' } + Query = @{} + } + } + + function New-RerunRequest { + param([string]$Action, [hashtable]$Body = @{}) + $RequestBody = [pscustomobject]@{ TaskId = 'task-1'; tenantFilter = 'contoso.com' } + foreach ($Key in $Body.Keys) { + $RequestBody | Add-Member -NotePropertyName $Key -NotePropertyValue $Body[$Key] -Force + } + [pscustomobject]@{ + Body = $RequestBody + Headers = @{} + Params = @{ CIPPEndpoint = 'ExecOffboardUser' } + Query = @{ Action = $Action } + } + } + + function New-StoredOffboardingTask { + param([string]$Command = 'Invoke-CIPPOffboardingJob', [string]$Tenant = 'contoso.com') + [pscustomobject]@{ + RowKey = 'task-1' + Command = $Command + Tenant = $Tenant + Reference = 'ticket-42' + Parameters = (@{ Username = 'pat@contoso.com'; options = @{ RevokeSessions = $true; DisableSignIn = $true }; DeploymentId = 'job-1' } | ConvertTo-Json -Compress) } } } @@ -50,6 +79,7 @@ Describe 'Invoke-ExecOffboardUser' { BeforeEach { Mock -CommandName Write-LogMessage -MockWith { } Mock -CommandName Add-CIPPScheduledTask -MockWith { 'Successfully added task' } + Mock -CommandName New-CIPPAsyncDeployment -MockWith { 'job-1' } Mock -CommandName Test-CIPPOffboardingRequest -MockWith { [pscustomobject]@{ IsValid = $true @@ -156,6 +186,92 @@ Describe 'Invoke-ExecOffboardUser' { } } + Context 'Live progress' { + It 'creates one queued progress row per user and hands the job id to every offboarding job' { + $Request = New-OffboardRequest -Users @('one@contoso.com', 'two@contoso.com') + + $Response = Invoke-ExecOffboardUser -Request $Request + + Should -Invoke New-CIPPAsyncDeployment -Times 1 -Exactly -ParameterFilter { + (@($Names) -join ',') -eq 'one@contoso.com,two@contoso.com' -and $Source -eq 'Offboarding' + } + Should -Invoke Add-CIPPScheduledTask -Times 2 -Exactly -ParameterFilter { $Task.Parameters.DeploymentId -eq 'job-1' } + $Response.Body.DeploymentId | Should -Be 'job-1' + } + + It 'does not hand back a job id for a deferred offboarding, which is watched from its task page' { + $Request = New-OffboardRequest -Body @{ Scheduled = [pscustomobject]@{ enabled = $true; date = 1785000000 } } + + $Response = Invoke-ExecOffboardUser -Request $Request + + Should -Invoke Add-CIPPScheduledTask -Times 1 -Exactly -ParameterFilter { $Task.Parameters.DeploymentId -eq 'job-1' } + $Response.Body.PSObject.Properties['DeploymentId'] | Should -BeNullOrEmpty + } + + It 'still queues the offboarding when the progress rows cannot be created' { + Mock -CommandName New-CIPPAsyncDeployment -MockWith { throw 'table unavailable' } + + $Response = Invoke-ExecOffboardUser -Request (New-OffboardRequest) + + $Response.StatusCode | Should -Be ([HttpStatusCode]::OK) + Should -Invoke Add-CIPPScheduledTask -Times 1 -Exactly -ParameterFilter { $null -eq $Task.Parameters.DeploymentId } + $Response.Body.PSObject.Properties['DeploymentId'] | Should -BeNullOrEmpty + } + } + + Context 'Re-running' { + BeforeEach { + Mock -CommandName Get-CIPPTable -MockWith { @{ Context = 'ctx' } } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { New-StoredOffboardingTask } + } + + It 'queues the whole task again through Run Now' { + $Response = Invoke-ExecOffboardUser -Request (New-RerunRequest -Action 'Rerun') + + $Response.StatusCode | Should -Be ([HttpStatusCode]::OK) + Should -Invoke Add-CIPPScheduledTask -Times 1 -Exactly -ParameterFilter { $RunNow -eq $true -and $RowKey -eq 'task-1' } + } + + It 'queues a single step as its own task under the same progress job' { + $Response = Invoke-ExecOffboardUser -Request (New-RerunRequest -Action 'RerunStep' -Body @{ StepIndex = 1; StepTitle = 'Disable sign in' }) + + $Response.StatusCode | Should -Be ([HttpStatusCode]::OK) + Should -Invoke Add-CIPPScheduledTask -Times 1 -Exactly -ParameterFilter { + $RunNow -eq $true -and + $Task.Command.value -eq 'Invoke-CIPPOffboardingJob' -and + $Task.TenantFilter -eq 'contoso.com' -and + $Task.Name -like '*Disable sign in*' -and + $Task.Reference -eq 'ticket-42' -and + $Task.Parameters.Username -eq 'pat@contoso.com' -and + $Task.Parameters.DeploymentId -eq 'job-1' -and + $Task.Parameters.options.DisableSignIn -eq $true -and + (@($Task.Parameters.StepIndexes) -join ',') -eq '1' + } + } + + It 'accepts step zero' { + $null = Invoke-ExecOffboardUser -Request (New-RerunRequest -Action 'RerunStep' -Body @{ StepIndex = 0 }) + + Should -Invoke Add-CIPPScheduledTask -Times 1 -Exactly -ParameterFilter { (@($Task.Parameters.StepIndexes) -join ',') -eq '0' } + } + + It 'refuses a task that belongs to another tenant' { + $Response = Invoke-ExecOffboardUser -Request (New-RerunRequest -Action 'Rerun' -Body @{ tenantFilter = 'other.com' }) + + $Response.StatusCode | Should -Be ([HttpStatusCode]::BadRequest) + Should -Invoke Add-CIPPScheduledTask -Times 0 -Exactly + } + + It 'refuses a task that is not an offboarding job' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { New-StoredOffboardingTask -Command 'Invoke-Something' } + + $Response = Invoke-ExecOffboardUser -Request (New-RerunRequest -Action 'RerunStep' -Body @{ StepIndex = 1 }) + + $Response.StatusCode | Should -Be ([HttpStatusCode]::BadRequest) + Should -Invoke Add-CIPPScheduledTask -Times 0 -Exactly + } + } + Context 'Guard rails' { It 'rejects an invalid request without queueing anything' { Mock -CommandName Test-CIPPOffboardingRequest -MockWith { diff --git a/Tests/Endpoint/Invoke-ExecPIMRoleAssignment.Tests.ps1 b/Tests/Endpoint/Invoke-ExecPIMRoleAssignment.Tests.ps1 new file mode 100644 index 0000000000000..73108f933a445 --- /dev/null +++ b/Tests/Endpoint/Invoke-ExecPIMRoleAssignment.Tests.ps1 @@ -0,0 +1,163 @@ +# Pester tests for Invoke-ExecPIMRoleAssignment. +# +# The endpoint is the API/MCP-facing gate for PIM assignment changes. These tests pin its input +# contract: every change needs a justification, any schedule-creating action needs an expiration, +# and a request that spells out permanence ('noExpiration', 'permanent', ...) is refused before +# Invoke-CIPPPIMAssignmentAction is ever called. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ExecPIMRoleAssignment.ps1' + if (-not (Test-Path $FunctionPath)) { throw "Could not locate Invoke-ExecPIMRoleAssignment.ps1 at $FunctionPath" } + + class HttpResponseContext { + [object]$StatusCode + [object]$Body + } + $Accelerators = [PSObject].Assembly.GetType('System.Management.Automation.TypeAccelerators') + if (-not ('HttpStatusCode' -as [type])) { + $Accelerators::Add('HttpStatusCode', [System.Net.HttpStatusCode]) + } + + function Invoke-CIPPPIMAssignmentAction { param($TenantFilter, $Action, $PrincipalId, $RoleDefinitionId, $DirectoryScopeId, $AssignmentType, $Duration, $EndDateTime, $Justification, $TimeZone, $Headers, $APIName) } + function Write-LogMessage { param($headers, $API, $tenant, $message, $Sev, $LogData) } + function Get-CippException { param($Exception) @{ NormalizedError = "$Exception" } } + + . $FunctionPath + + function New-PimRequest { + param([hashtable]$Body = @{}) + $RequestBody = [pscustomobject]@{ + tenantFilter = 'contoso.onmicrosoft.com' + Action = 'GrantActive' + PrincipalId = 'user-guid' + RoleDefinitionId = '62e90394-69f5-4237-9190-012177145e10' + DirectoryScopeId = '/' + AssignmentType = 'Eligible' + Duration = 'PT4H' + Justification = 'Ticket 42' + } + foreach ($Key in $Body.Keys) { + if ($null -eq $Body[$Key]) { $RequestBody.PSObject.Properties.Remove($Key) } + else { $RequestBody | Add-Member -NotePropertyName $Key -NotePropertyValue $Body[$Key] -Force } + } + [pscustomobject]@{ + Body = $RequestBody + Headers = @{} + Params = @{ CIPPEndpoint = 'ExecPIMRoleAssignment' } + } + } +} + +Describe 'Invoke-ExecPIMRoleAssignment' { + BeforeEach { + Mock Invoke-CIPPPIMAssignmentAction { [pscustomobject]@{ resultText = 'done'; state = 'success' } } + Mock Write-LogMessage {} + } + + Context 'time zone for the result wording' { + It 'passes the browser time zone through, and leaves it out when the request has none' { + $null = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest -Body @{ TimeZone = 'Australia/Perth' }) -TriggerMetadata $null + Should -Invoke Invoke-CIPPPIMAssignmentAction -Times 1 -Exactly -ParameterFilter { $TimeZone -eq 'Australia/Perth' -and $Duration -eq 'PT4H' } + $null = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest) -TriggerMetadata $null + Should -Invoke Invoke-CIPPPIMAssignmentAction -Times 1 -Exactly -ParameterFilter { [string]::IsNullOrEmpty($TimeZone) } + } + } + + Context 'input validation (nothing reaches PIM)' { + It 'returns 400 when required fields are missing' { + $Response = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest @{ PrincipalId = $null }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + $Response.Body.Results[0].resultText | Should -Match 'required' + Should -Invoke Invoke-CIPPPIMAssignmentAction -Times 0 -Exactly + } + + It 'returns 400 for an unknown action' { + $Response = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest @{ Action = 'MakePermanent' }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + $Response.Body.Results[0].resultText | Should -Match 'not supported' + Should -Invoke Invoke-CIPPPIMAssignmentAction -Times 0 -Exactly + } + + It 'returns 400 without a justification' { + $Response = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest @{ Justification = '' }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + $Response.Body.Results[0].resultText | Should -Match 'justification' + Should -Invoke Invoke-CIPPPIMAssignmentAction -Times 0 -Exactly + } + + It 'refuses a duration that asks for permanence: <_>' -ForEach @('noExpiration', 'permanent', 'never', 'unlimited') { + $Response = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest @{ Duration = $_ }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + $Response.Body.Results[0].resultText | Should -Match 'Permanent \(no-expiration\) assignments cannot be created' + Should -Invoke Invoke-CIPPPIMAssignmentAction -Times 0 -Exactly + } + + It 'refuses an end date that asks for permanence' { + $Response = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest @{ Duration = $null; EndDateTime = 'noExpiration' }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + Should -Invoke Invoke-CIPPPIMAssignmentAction -Times 0 -Exactly + } + + It 'requires an expiration for <_>' -ForEach @('GrantActive', 'Extend', 'Renew') { + $Response = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest @{ Action = $_; Duration = $null }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + $Response.Body.Results[0].resultText | Should -Match 'requires a Duration or an EndDateTime' + Should -Invoke Invoke-CIPPPIMAssignmentAction -Times 0 -Exactly + } + + It 'rejects Duration and EndDateTime together' { + $Response = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest @{ EndDateTime = '2099-01-01T00:00:00Z' }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + $Response.Body.Results[0].resultText | Should -Match 'not both' + } + + It 'rejects an unparseable end date' { + $Response = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest @{ Duration = $null; EndDateTime = 'next tuesday' }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + $Response.Body.Results[0].resultText | Should -Match 'not a valid date' + } + } + + Context 'forwarding to Invoke-CIPPPIMAssignmentAction' { + It 'passes the duration, scope, type and justification through' { + $Response = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $Response.Body.Results[0].state | Should -Be 'success' + Should -Invoke Invoke-CIPPPIMAssignmentAction -Times 1 -Exactly -ParameterFilter { + $Action -eq 'GrantActive' -and $Duration -eq 'PT4H' -and $DirectoryScopeId -eq '/' -and $AssignmentType -eq 'Eligible' -and $Justification -eq 'Ticket 42' -and $null -eq $EndDateTime + } + } + + It 'converts a unix-seconds end date to a UTC datetime' { + $Unix = [System.DateTimeOffset]::UtcNow.AddHours(6).ToUnixTimeSeconds() + $null = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest @{ Duration = $null; EndDateTime = $Unix }) + Should -Invoke Invoke-CIPPPIMAssignmentAction -Times 1 -Exactly -ParameterFilter { + $EndDateTime -is [datetime] -and [math]::Abs(($EndDateTime - [datetime]::UtcNow).TotalHours - 6) -lt 0.1 + } + } + + It 'unwraps label/value objects from the dialog' { + $Request = New-PimRequest @{ + Action = [pscustomobject]@{ label = 'Convert to eligible'; value = 'ConvertToEligible' } + Duration = [pscustomobject]@{ label = '1 year'; value = 'P365D' } + } + $null = Invoke-ExecPIMRoleAssignment -Request $Request + Should -Invoke Invoke-CIPPPIMAssignmentAction -Times 1 -Exactly -ParameterFilter { $Action -eq 'ConvertToEligible' -and $Duration -eq 'P365D' } + } + + It 'lets Remove through without an expiration' { + $Response = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest @{ Action = 'Remove'; Duration = $null }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + Should -Invoke Invoke-CIPPPIMAssignmentAction -Times 1 -Exactly -ParameterFilter { $Action -eq 'Remove' } + } + + It 'returns 400 with the refusal message when the action throws' { + Mock Invoke-CIPPPIMAssignmentAction { throw 'Refusing: last active Global Administrator' } + $Response = Invoke-ExecPIMRoleAssignment -Request (New-PimRequest @{ Action = 'Remove'; Duration = $null }) + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + $Response.Body.Results[0].state | Should -Be 'error' + $Response.Body.Results[0].resultText | Should -Match 'last active Global Administrator' + } + } +} diff --git a/Tests/Endpoint/Invoke-ExecRefreshMyAccess.Tests.ps1 b/Tests/Endpoint/Invoke-ExecRefreshMyAccess.Tests.ps1 index 9e66df0c79f21..8854b86d5c5cb 100644 --- a/Tests/Endpoint/Invoke-ExecRefreshMyAccess.Tests.ps1 +++ b/Tests/Endpoint/Invoke-ExecRefreshMyAccess.Tests.ps1 @@ -128,6 +128,10 @@ Describe 'Invoke-ExecRefreshMyAccess' { $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::TooManyRequests) Should -Invoke Test-CIPPAccessUserRole -Times 0 -Exactly Should -Invoke Start-UserSyncTimer -Times 0 -Exactly + # A throttle the operator can't see is a throttle nobody can diagnose — the 429 must be logged. + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { + $API -eq 'RefreshMyAccess' -and $sev -eq 'Info' -and $message -match 'cooldown' + } } It 'allows a refresh once the cooldown has elapsed' { diff --git a/Tests/Endpoint/Invoke-ExecSiteBrowserLibraryCopy.Tests.ps1 b/Tests/Endpoint/Invoke-ExecSiteBrowserLibraryCopy.Tests.ps1 new file mode 100644 index 0000000000000..0c855f76b7053 --- /dev/null +++ b/Tests/Endpoint/Invoke-ExecSiteBrowserLibraryCopy.Tests.ps1 @@ -0,0 +1,105 @@ +# Pester tests for Invoke-ExecSiteBrowserLibraryCopy and Invoke-ListSiteBrowserLibraryCopy + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $ExecPath = Join-Path $RepoRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ExecSiteBrowserLibraryCopy.ps1' + $ListPath = Join-Path $RepoRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSiteBrowserLibraryCopy.ps1' + if (-not (Test-Path $ExecPath)) { throw "Could not locate $ExecPath" } + if (-not (Test-Path $ListPath)) { throw "Could not locate $ListPath" } + + class HttpResponseContext { + [object]$StatusCode + [object]$Body + } + $Accelerators = [PSObject].Assembly.GetType('System.Management.Automation.TypeAccelerators') + if (-not ('HttpStatusCode' -as [type])) { + $Accelerators::Add('HttpStatusCode', [System.Net.HttpStatusCode]) + } + + function Start-CIPPSharePointLibraryCopy { + param( + [string]$Mode, + [string]$TenantFilter, + [int]$NameConflictBehavior + ) + } + function Update-CIPPSharePointLibraryCopyStatus { + param([string]$TenantFilter, [string]$OperationId) + } + function Write-LogMessage { param($Headers, $API, $tenant, $message, $sev) } + function Get-CippException { param($Exception) [PSCustomObject]@{ NormalizedError = $Exception.Message } } + + . $ExecPath + . $ListPath +} + +Describe 'Invoke-ExecSiteBrowserLibraryCopy' { + BeforeEach { + Mock Start-CIPPSharePointLibraryCopy { [PSCustomObject]@{ EligibleRootCount = 3; WarnLevel = 'none'; Message = 'ok' } } + } + + It 'returns BadRequest when tenantFilter is missing' { + $Response = Invoke-ExecSiteBrowserLibraryCopy -Request ([pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ExecSiteBrowserLibraryCopy' } + Headers = @{} + Body = [pscustomobject]@{ Action = 'PreflightLibraryCopy' } + }) + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + Should -Invoke Start-CIPPSharePointLibraryCopy -Times 0 -Exactly + } + + It 'calls PreflightLibraryCopy with conflict behavior mapping' { + $Response = Invoke-ExecSiteBrowserLibraryCopy -Request ([pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ExecSiteBrowserLibraryCopy' } + Headers = @{ 'x-ms-client-principal-name' = 'admin@contoso.com' } + Body = [pscustomobject]@{ + Action = 'PreflightLibraryCopy' + tenantFilter = 'contoso.com' + SourceSiteId = 'site-a' + SourceListId = 'list-a' + DestSiteId = 'site-b' + DestListId = 'list-b' + NameConflictBehavior = 'Fail' + } + }) + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + Should -Invoke Start-CIPPSharePointLibraryCopy -Times 1 -Exactly + } +} + +Describe 'Invoke-ListSiteBrowserLibraryCopy' { + BeforeEach { + Mock Update-CIPPSharePointLibraryCopyStatus { + [PSCustomObject]@{ + OperationId = 'op-1' + Status = 'Processing' + JobsComplete = 1 + JobsTotal = 2 + } + } + } + + It 'returns BadRequest when OperationId is missing' { + $Response = Invoke-ListSiteBrowserLibraryCopy -Request ([pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ListSiteBrowserLibraryCopy' } + Headers = @{} + Query = @{ tenantFilter = 'contoso.com' } + }) + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::BadRequest) + } + + It 'returns sanitized status in Results' { + $Response = Invoke-ListSiteBrowserLibraryCopy -Request ([pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ListSiteBrowserLibraryCopy' } + Headers = @{} + Query = @{ tenantFilter = 'contoso.com'; OperationId = 'op-1' } + }) + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $Response.Body.Results.Status | Should -Be 'Processing' + $Response.Body.Results.JobsTotal | Should -Be 2 + } +} diff --git a/Tests/Endpoint/Invoke-ListConditionalAccessPolicies.Tests.ps1 b/Tests/Endpoint/Invoke-ListConditionalAccessPolicies.Tests.ps1 new file mode 100644 index 0000000000000..990d546056cc6 --- /dev/null +++ b/Tests/Endpoint/Invoke-ListConditionalAccessPolicies.Tests.ps1 @@ -0,0 +1,154 @@ +# Pester tests for the AllTenants branch of Invoke-ListConditionalAccessPolicies +# Validates the manualPagination contract over the cacheCAPolicies table, the queue +# fallback on a cold cache (and its suppression mid-walk), and the legacy unpaged path. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + class HttpResponseContext { + [int]$StatusCode + [object]$Body + [object]$ContentType + } + + # Rows-exist path returns a raw-JSON string Body; queue/cold paths return an object. + function ConvertFrom-ResponseBody { + param($Response) + if ($Response.Body -is [string]) { return ($Response.Body | ConvertFrom-Json) } + return $Response.Body + } + + # Stub every CIPP helper the exercised paths call so Pester's Mock has a command to replace. + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property, $First) } + function Get-CIPPPagedTableRows { param($Table, $PartitionKeys, $RowKeyGe, $RowKeyLt, $ExtraFilterClauses, $PageSize, $MaxQueries, $ContinuationToken) } + function Get-CIPPQueueData { param($Reference) } + function New-CippQueueEntry { param($Name, $Link, $Reference, $TotalTasks) } + function Start-CIPPOrchestrator { param($InputObject) } + function Get-Tenants { param($TenantFilter, [switch]$IncludeErrors) } + function New-GraphBulkRequest { param($Requests, $tenantid, $asapp) } + function Get-NormalizedError { param($Message) $Message } + # Real passthrough, not a Mock: the endpoint pipes rows into it, and pipeline binding + # inside Pester mock bodies is unreliable. + function Select-CippAllowedTenantData { param([Parameter(ValueFromPipeline)]$Row, $TenantProperty) process { $Row } } + + $EndpointPath = Join-Path $RepoRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ListConditionalAccessPolicies.ps1' + $EndpointScript = [ScriptBlock]::Create("using namespace System.Net`n" + (Get-Content -LiteralPath $EndpointPath -Raw)) + . $EndpointScript + + function New-CaRequest { + param([hashtable]$Query = @{}) + $Merged = @{ tenantFilter = 'AllTenants' } + foreach ($Key in $Query.Keys) { $Merged[$Key] = $Query[$Key] } + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ListConditionalAccessPolicies' } + Headers = @{ Authorization = 'token' } + Query = [pscustomobject]$Merged + } + } + + function New-CacheRow { + param([string]$Tenant, [string]$Id) + [PSCustomObject]@{ + PartitionKey = 'CAPolicy' + RowKey = [guid]::NewGuid().ToString() + Tenant = $Tenant + Timestamp = (Get-Date) + Policy = (@{ id = $Id; displayName = "Policy $Id"; Tenant = $Tenant } | ConvertTo-Json -Compress) + } + } +} + +Describe 'Invoke-ListConditionalAccessPolicies AllTenants' { + BeforeEach { + Mock -CommandName Get-CIPPTable -MockWith { @{ Context = 'fake' } } + Mock -CommandName Get-CIPPQueueData -MockWith { $null } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { @() } + Mock -CommandName Get-CIPPPagedTableRows -MockWith { [PSCustomObject]@{ Rows = @(); NextToken = $null } } + Mock -CommandName New-CippQueueEntry -MockWith { @{ RowKey = 'queue-1' } } + Mock -CommandName Start-CIPPOrchestrator -MockWith { 'instance-1' } + Mock -CommandName Get-Tenants -MockWith { @([PSCustomObject]@{ defaultDomainName = 'a.com' }) } + } + + It 'serves a paged { Results, Metadata } page with nextLink and clamps PageSize' { + Mock -CommandName Get-CIPPPagedTableRows -MockWith { + [PSCustomObject]@{ + Rows = @((New-CacheRow 'a.com' 'p1'), (New-CacheRow 'b.com' 'p2')) + NextToken = 'CAPolicy|some-guid' + } + } + + $response = Invoke-ListConditionalAccessPolicies -Request (New-CaRequest -Query @{ manualPagination = 'true'; PageSize = '10' }) -TriggerMetadata $null + + $response.StatusCode | Should -Be 200 + $response.ContentType | Should -Be 'application/json' + $response.Body | Should -BeOfType [string] + $body = ConvertFrom-ResponseBody $response + $body.Results | Should -HaveCount 2 + $body.Results.id | Should -Contain 'p1' + $body.Metadata.nextLink | Should -Be 'CAPolicy|some-guid' + Should -Invoke Get-CIPPPagedTableRows -Times 1 -ParameterFilter { + ($PartitionKeys -join ',') -eq 'CAPolicy' -and $PageSize -eq 250 -and + ($ExtraFilterClauses -join '') -like 'Timestamp ge datetime*' + } + Should -Invoke Start-CIPPOrchestrator -Times 0 + } + + It 'stitches the cached Policy blob verbatim without a parse round-trip' { + $rowA = New-CacheRow 'a.com' 'p1' + Mock -CommandName Get-CIPPPagedTableRows -MockWith { + [PSCustomObject]@{ Rows = @($rowA); NextToken = $null } + }.GetNewClosure() + + $response = Invoke-ListConditionalAccessPolicies -Request (New-CaRequest -Query @{ manualPagination = 'true' }) -TriggerMetadata $null + + # Exact stored blob bytes must appear verbatim; a parse + re-serialize would restyle them. + $response.Body | Should -BeLike ('*' + $rowA.Policy + '*') + $body = ConvertFrom-ResponseBody $response + $body.Results.id | Should -Be 'p1' + } + + It 'omits nextLink on the final page' { + Mock -CommandName Get-CIPPPagedTableRows -MockWith { + [PSCustomObject]@{ Rows = @((New-CacheRow 'a.com' 'p1')); NextToken = $null } + } + + $response = Invoke-ListConditionalAccessPolicies -Request (New-CaRequest -Query @{ manualPagination = 'true' }) -TriggerMetadata $null + + $body = ConvertFrom-ResponseBody $response + $body.Results | Should -HaveCount 1 + $body.Metadata.nextLink | Should -BeNullOrEmpty + Should -Invoke Get-CIPPPagedTableRows -Times 1 -ParameterFilter { $PageSize -eq 5000 } + } + + It 'queues the fan-out on a cold cache first page' { + $response = Invoke-ListConditionalAccessPolicies -Request (New-CaRequest -Query @{ manualPagination = 'true' }) -TriggerMetadata $null + + $response.Body.Metadata.QueueMessage | Should -Match 'Loading data' + @($response.Body.Results) | Should -HaveCount 0 + Should -Invoke Start-CIPPOrchestrator -Times 1 + } + + It 'does not re-queue when an empty page arrives mid-walk' { + $response = Invoke-ListConditionalAccessPolicies -Request (New-CaRequest -Query @{ manualPagination = 'true'; nextLink = 'CAPolicy|stale' }) -TriggerMetadata $null + + $body = ConvertFrom-ResponseBody $response + @($body.Results) | Should -HaveCount 0 + Should -Invoke Start-CIPPOrchestrator -Times 0 + Should -Invoke New-CippQueueEntry -Times 0 + } + + It 'keeps the legacy unpaged full fetch without manualPagination' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + @((New-CacheRow 'a.com' 'p1'), (New-CacheRow 'b.com' 'p2'), (New-CacheRow 'c.com' 'p3')) + } + + $response = Invoke-ListConditionalAccessPolicies -Request (New-CaRequest) -TriggerMetadata $null + + $body = ConvertFrom-ResponseBody $response + $body.Results | Should -HaveCount 3 + $body.Metadata.nextLink | Should -BeNullOrEmpty + Should -Invoke Get-CIPPPagedTableRows -Times 0 + Should -Invoke Get-CIPPAzDataTableEntity -Times 1 + } +} diff --git a/Tests/Endpoint/Invoke-ListGroups.Tests.ps1 b/Tests/Endpoint/Invoke-ListGroups.Tests.ps1 new file mode 100644 index 0000000000000..0d422788b606e --- /dev/null +++ b/Tests/Endpoint/Invoke-ListGroups.Tests.ps1 @@ -0,0 +1,133 @@ +# Pester tests for the reporting-database branch of Invoke-ListGroups +# Validates the legacy bare-array shape and the manualPagination contract +# ({ Results, Metadata } pages chained via Metadata.nextLink). + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + class HttpResponseContext { + [int]$StatusCode + [object]$Body + [object]$ContentType + } + + # Paged path returns a raw-JSON string Body; the legacy path returns an object. + function ConvertFrom-ResponseBody { + param($Response) + if ($Response.Body -is [string]) { return ($Response.Body | ConvertFrom-Json) } + return $Response.Body + } + + # Stub every CIPP helper the exercised paths call so Pester's Mock has a command to replace. + function Get-CIPPGroupsReport { param($TenantFilter, $PageSize, $ContinuationToken, [switch]$AsRawJson) } + function New-GraphGetRequest { param($uri, $tenantid) } + function New-GraphBulkRequest { param($Requests, $tenantid) } + function Get-GraphBulkResultByID { param($Results, $ID) } + function Convert-AzureAdObjectIdToSid { param($ObjectID) } + function Get-NormalizedError { param($Message) $Message } + + $EndpointPath = Join-Path $RepoRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Groups/Invoke-ListGroups.ps1' + $EndpointScript = [ScriptBlock]::Create("using namespace System.Net`n" + (Get-Content -LiteralPath $EndpointPath -Raw)) + . $EndpointScript + + function New-GroupsRequest { + param([hashtable]$Query = @{}) + $Merged = @{ tenantFilter = 'AllTenants' } + foreach ($Key in $Query.Keys) { $Merged[$Key] = $Query[$Key] } + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ListGroups' } + Headers = @{ Authorization = 'token' } + Query = [pscustomobject]$Merged + } + } + + function New-GroupRow { + param([string]$Id) + [pscustomobject]@{ + id = $Id + displayName = "Group $Id" + members = @([pscustomobject]@{ id = 'u1'; userPrincipalName = 'u1@contoso.com' }) + membersCsv = 'u1@contoso.com' + Tenant = 'contoso.onmicrosoft.com' + } + } + + # Mirror what Get-CIPPGroupsReport -AsRawJson returns: the group blobs pre-stitched + # into a JSON array string, with a continuation token. + function New-GroupsPageJson { + param([object[]]$Rows, [string]$NextToken) + $parts = foreach ($row in $Rows) { $row | ConvertTo-Json -Depth 10 -Compress } + [PSCustomObject]@{ + CippPagedJson = '[' + ($parts -join ',') + ']' + NextToken = $NextToken + } + } +} + +Describe 'Invoke-ListGroups report database branch' { + BeforeEach { + Mock -CommandName New-GraphGetRequest -MockWith { throw 'live Graph should not be called' } + Mock -CommandName New-GraphBulkRequest -MockWith { throw 'live Graph should not be called' } + } + + It 'returns the legacy bare array without manualPagination' { + Mock -CommandName Get-CIPPGroupsReport -MockWith { @((New-GroupRow 'g1'), (New-GroupRow 'g2')) } + + $response = Invoke-ListGroups -Request (New-GroupsRequest) -TriggerMetadata $null + + $response.StatusCode | Should -Be 200 + $response.Body | Should -HaveCount 2 + $response.Body[0].members | Should -HaveCount 1 + Should -Invoke Get-CIPPGroupsReport -Times 1 -ParameterFilter { + $TenantFilter -eq 'AllTenants' -and -not $PageSize + } + } + + It 'returns { Results, Metadata } pages with members intact when manualPagination is set' { + Mock -CommandName Get-CIPPGroupsReport -MockWith { + New-GroupsPageJson -Rows @((New-GroupRow 'g1')) -NextToken 'contoso.onmicrosoft.com|Groups-abc' + } + + $response = Invoke-ListGroups -Request (New-GroupsRequest -Query @{ + manualPagination = 'true'; PageSize = '7'; nextLink = 'prev|token' + }) -TriggerMetadata $null + + $response.StatusCode | Should -Be 200 + $response.ContentType | Should -Be 'application/json' + $response.Body | Should -BeOfType [string] + $body = ConvertFrom-ResponseBody $response + $body.Results | Should -HaveCount 1 + $body.Results[0].members[0].userPrincipalName | Should -Be 'u1@contoso.com' + $body.Metadata.nextLink | Should -Be 'contoso.onmicrosoft.com|Groups-abc' + # PageSize 7 is below the 100 floor and must be clamped; the incoming token is + # forwarded verbatim, and the read runs in raw-JSON mode. + Should -Invoke Get-CIPPGroupsReport -Times 1 -ParameterFilter { + $TenantFilter -eq 'AllTenants' -and $PageSize -eq 100 -and $ContinuationToken -eq 'prev|token' -and $AsRawJson + } + } + + It 'omits nextLink on the final page but keeps the paged shape and default size' { + Mock -CommandName Get-CIPPGroupsReport -MockWith { + New-GroupsPageJson -Rows @((New-GroupRow 'g1')) -NextToken $null + } + + $response = Invoke-ListGroups -Request (New-GroupsRequest -Query @{ + UseReportDB = 'true'; manualPagination = 'true' + }) -TriggerMetadata $null + + $body = ConvertFrom-ResponseBody $response + $body.Results | Should -HaveCount 1 + $body.Metadata.nextLink | Should -BeNullOrEmpty + $body.PSObject.Properties.Name | Should -Contain 'Metadata' + Should -Invoke Get-CIPPGroupsReport -Times 1 -ParameterFilter { $PageSize -eq 750 } + } + + It 'returns InternalServerError when the paged report read fails' { + Mock -CommandName Get-CIPPGroupsReport -MockWith { throw 'No groups data found in reporting database for AllTenants. Sync the report data first.' } + + $response = Invoke-ListGroups -Request (New-GroupsRequest -Query @{ manualPagination = 'true' }) -TriggerMetadata $null + + $response.StatusCode | Should -Be 500 + "$($response.Body)" | Should -Match 'Sync the report data first' + } +} diff --git a/Tests/Endpoint/Invoke-ListGuestUsers.Tests.ps1 b/Tests/Endpoint/Invoke-ListGuestUsers.Tests.ps1 index 7c2346f68df16..816577e6e06a2 100644 --- a/Tests/Endpoint/Invoke-ListGuestUsers.Tests.ps1 +++ b/Tests/Endpoint/Invoke-ListGuestUsers.Tests.ps1 @@ -20,7 +20,7 @@ BeforeAll { function Get-CippException { param($Exception) @{ NormalizedError = $Exception } } function Test-CIPPStandardLicense { param($StandardName, $TenantFilter, $RequiredCapabilities, $Preset, [switch]$SkipLog) } function New-GraphGetRequest { param($uri, $tenantid, [switch]$ComplexFilter) } - function Get-CIPPGuestUsersReport { param($TenantFilter) } + function Get-CIPPGuestUsersReport { param($TenantFilter, $PageSize, $ContinuationToken) } function Write-LogMessage { param($headers, $API, $tenant, $message, $Sev, $LogData) } . $FunctionPath @@ -277,4 +277,80 @@ Describe 'Invoke-ListGuestUsers' { Should -Invoke Get-CIPPGuestUsersReport -Times 1 -ParameterFilter { $TenantFilter -eq 'AllTenants' } Should -Invoke New-GraphGetRequest -Times 0 } + + Context 'manualPagination' { + BeforeEach { + Mock -CommandName New-GraphGetRequest -MockWith { throw 'live Graph should not be called' } + } + + It 'returns a { Results, Metadata } page with nextLink and clamps PageSize' { + Mock -CommandName Get-CIPPGuestUsersReport -MockWith { + [PSCustomObject]@{ + Items = @( + [pscustomobject]@{ + id = 'g-1'; displayName = 'Guest'; mail = 'g@partner.com' + userPrincipalName = 'g_partner.com#EXT#@contoso.onmicrosoft.com' + createdDateTime = (Get-Date).AddDays(-10).ToString('o'); accountEnabled = $true + externalUserState = 'PendingAcceptance'; externalUserStateChangeDateTime = $null + signInLogsCapable = $true + CacheTimestamp = '2026-08-18T10:00:00Z'; Tenant = 'contoso.onmicrosoft.com' + } + ) + NextToken = 'contoso.onmicrosoft.com|Guests-abc' + } + } + + $response = Invoke-ListGuestUsers -Request (New-GuestRequest -Query @{ + tenantFilter = 'AllTenants'; manualPagination = 'true'; PageSize = '10'; nextLink = 'prev|token' + }) -TriggerMetadata $null + + $response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $response.Body.Results | Should -HaveCount 1 + $response.Body.Results[0].status | Should -Be 'Pending Acceptance' + $response.Body.Results[0].Tenant | Should -Be 'contoso.onmicrosoft.com' + $response.Body.Metadata.nextLink | Should -Be 'contoso.onmicrosoft.com|Guests-abc' + # PageSize 10 is below the floor and must be clamped to 250; the incoming + # continuation token is forwarded verbatim. + Should -Invoke Get-CIPPGuestUsersReport -Times 1 -ParameterFilter { + $TenantFilter -eq 'AllTenants' -and $PageSize -eq 250 -and $ContinuationToken -eq 'prev|token' + } + } + + It 'omits nextLink on the final page but keeps the paged shape' { + Mock -CommandName Get-CIPPGuestUsersReport -MockWith { + [PSCustomObject]@{ Items = @(); NextToken = $null } + } + + $response = Invoke-ListGuestUsers -Request (New-GuestRequest -Query @{ + UseReportDB = 'true'; manualPagination = 'true' + }) -TriggerMetadata $null + + $response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + @($response.Body.Results) | Should -HaveCount 0 + $response.Body.Metadata.nextLink | Should -BeNullOrEmpty + $response.Body.PSObject.Properties.Name | Should -Contain 'Metadata' + } + + It 'keeps the legacy bare array for live reads even when manualPagination is set' { + Mock -CommandName Get-CIPPGuestUsersReport -MockWith { throw 'report cache should not be called' } + Mock -CommandName New-GraphGetRequest -MockWith { + @( + [pscustomobject]@{ + id = 'g-1'; displayName = 'Guest'; mail = 'g@partner.com' + userPrincipalName = 'g_partner.com#EXT#@contoso.onmicrosoft.com' + createdDateTime = (Get-Date).AddDays(-10).ToString('o'); accountEnabled = $true + externalUserState = 'PendingAcceptance'; externalUserStateChangeDateTime = $null + } + ) + } + + $response = Invoke-ListGuestUsers -Request (New-GuestRequest -Query @{ manualPagination = 'true' }) -TriggerMetadata $null + + $response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + # No Results wrapper: the body is the plain row array. + $response.Body | Should -HaveCount 1 + $response.Body[0].status | Should -Be 'Pending Acceptance' + Should -Invoke Get-CIPPGuestUsersReport -Times 0 + } + } } diff --git a/Tests/Endpoint/Invoke-ListLicenseOptimization.Tests.ps1 b/Tests/Endpoint/Invoke-ListLicenseOptimization.Tests.ps1 new file mode 100644 index 0000000000000..41ec4aba925a4 --- /dev/null +++ b/Tests/Endpoint/Invoke-ListLicenseOptimization.Tests.ps1 @@ -0,0 +1,96 @@ +# Pester tests for Invoke-ListLicenseOptimization — single-tenant report, AllTenants money map, +# the required-tenant guard, and error handling. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Invoke-ListLicenseOptimization.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $FunctionPath) { throw 'Could not locate Invoke-ListLicenseOptimization.ps1 under Modules/' } + + class HttpResponseContext { + [int]$StatusCode + [object]$Body + } + + function Get-CippException { param($Exception) @{ NormalizedError = $Exception } } + function Get-CIPPLicenseOptimization { param($TenantFilter, $InactiveDays) } + function Get-Tenants { param([switch]$IncludeErrors) } + function Write-LogMessage { param($headers, $API, $tenant, $message, $Sev, $LogData) } + + . $FunctionPath + + function New-OptRequest { + param([hashtable]$Query = @{}) + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ListLicenseOptimization' } + Headers = @{ Authorization = 'token' } + Query = [pscustomobject]$Query + Body = [pscustomobject]@{} + } + } +} + +Describe 'Invoke-ListLicenseOptimization' { + BeforeEach { + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Get-CippException -MockWith { param($Exception) @{ NormalizedError = "$Exception" } } + } + + It 'returns the full report for a single tenant' { + Mock -CommandName Get-CIPPLicenseOptimization -MockWith { + [pscustomobject]@{ + Summary = [pscustomobject]@{ Tenant = $TenantFilter; ReclaimableMonthly = 100; DataAvailable = $true } + Opportunities = @([pscustomobject]@{ Tier = 'UnassignedSeats'; MonthlySaving = 100 }) + } + } + + $Response = Invoke-ListLicenseOptimization -Request (New-OptRequest @{ tenantFilter = 'contoso.com' }) + + $Response.StatusCode | Should -Be 200 + $Response.Body.Results.Summary.ReclaimableMonthly | Should -Be 100 + $Response.Body.Results.Opportunities.Count | Should -Be 1 + Should -Invoke Get-CIPPLicenseOptimization -Times 1 -Exactly + } + + It 'passes the inactiveDays override through' { + Mock -CommandName Get-CIPPLicenseOptimization -MockWith { + [pscustomobject]@{ Summary = [pscustomobject]@{ DataAvailable = $true }; Opportunities = @() } + } + + $null = Invoke-ListLicenseOptimization -Request (New-OptRequest @{ tenantFilter = 'contoso.com'; inactiveDays = '30' }) + + Should -Invoke Get-CIPPLicenseOptimization -Times 1 -Exactly -ParameterFilter { $InactiveDays -eq 30 } + } + + It 'returns a ranked per-tenant summary money map for AllTenants' { + Mock -CommandName Get-Tenants -MockWith { + @( + [pscustomobject]@{ defaultDomainName = 'a.com' } + [pscustomobject]@{ defaultDomainName = 'b.com' } + [pscustomobject]@{ defaultDomainName = 'empty.com' } + ) + } + Mock -CommandName Get-CIPPLicenseOptimization -MockWith { + $Map = @{ 'a.com' = 50; 'b.com' = 200; 'empty.com' = 0 } + [pscustomobject]@{ + Summary = [pscustomobject]@{ Tenant = $TenantFilter; ReclaimableMonthly = $Map[$TenantFilter]; DataAvailable = ($TenantFilter -ne 'empty.com') } + Opportunities = @() + } + } + + $Response = Invoke-ListLicenseOptimization -Request (New-OptRequest @{ tenantFilter = 'AllTenants' }) + + $Response.StatusCode | Should -Be 200 + # empty.com has no cached data and is dropped; the rest are ranked by reclaimable spend + $Response.Body.Results.Count | Should -Be 2 + $Response.Body.Results[0].Tenant | Should -Be 'b.com' + $Response.Body.Results[1].Tenant | Should -Be 'a.com' + } + + It 'fails when no tenant is supplied and it is not AllTenants' { + $Response = Invoke-ListLicenseOptimization -Request (New-OptRequest @{}) + + $Response.StatusCode | Should -Be 500 + $Response.Body.Results | Should -Match 'tenantFilter is required' + } +} diff --git a/Tests/Endpoint/Invoke-ListLogs.Tests.ps1 b/Tests/Endpoint/Invoke-ListLogs.Tests.ps1 new file mode 100644 index 0000000000000..fa90116aa1d1d --- /dev/null +++ b/Tests/Endpoint/Invoke-ListLogs.Tests.ps1 @@ -0,0 +1,297 @@ +# Pester tests for Invoke-ListLogs +# Validates the manualPagination contract (page shape, keyset continuation, split-row guard, +# cross-day walk, query budget), the client-side severity/user filters, the legacy +# unpaginated shape, and single-entry lookup including tick-derived partitions. + +BeforeAll { + # Resolve by name under Modules/ so the test survives the function moving between modules. + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Invoke-ListLogs.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $FunctionPath) { throw 'Could not locate Invoke-ListLogs.ps1 under Modules/' } + $ConverterPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'ConvertTo-CIPPODataFilterValue.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $ConverterPath) { throw 'Could not locate ConvertTo-CIPPODataFilterValue.ps1 under Modules/' } + + # Azure Functions binding types do not exist outside the Functions host - fake them. + class HttpResponseContext { + [int]$StatusCode + [object]$Body + } + + $Accelerators = [psobject].Assembly.GetType('System.Management.Automation.TypeAccelerators') + if (-not $Accelerators::Get.ContainsKey('HttpStatusCode')) { + $Accelerators::Add('HttpStatusCode', [System.Net.HttpStatusCode]) + } + + # Stub every CIPP helper the function calls so Pester's Mock has a command to replace. + function Get-CIPPTable { param($tablename) @{ Context = ($tablename ?? 'CippLogs') } } + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property, $First, $Skip, $Sort, [switch]$Count, $MaxRetries) } + function Test-CIPPAccess { param($Request, [switch]$TenantList) } + function Get-Tenants { param([switch]$IncludeErrors) } + + . $ConverterPath + . $FunctionPath + + # Deterministic partitioning: pin the timezone the endpoint reads. + $script:OldTz = $env:CIPP_TIMEZONE + $env:CIPP_TIMEZONE = 'UTC' + + function New-FakeRowKey([datetime]$InstantUtc, [string]$Suffix = 'aaaaaaaaaaaa') { + '{0:D19}-{1}' -f ([DateTime]::MaxValue.Ticks - $InstantUtc.Ticks), $Suffix + } + + # Rows land in the partition of their instant's UTC date, mirroring Write-LogMessage. + # $RowKey deliberately untyped: [string]$null coerces to '' and would defeat the ?? fallback. + function New-FakeLogRow([datetime]$InstantUtc, [int]$Seq, [string]$Severity = 'Info', [string]$Username = 'user@contoso.com', $RowKey = $null) { + [pscustomobject]@{ + PartitionKey = $InstantUtc.ToString('yyyyMMdd') + RowKey = $RowKey ?? (New-FakeRowKey $InstantUtc) + Timestamp = [System.DateTimeOffset]::new($InstantUtc) + Tenant = 'contoso.onmicrosoft.com' + API = 'FakeApi' + Message = "seq $Seq" + Username = $Username + Severity = $Severity + LogData = '' + } + } + + # Static store the table mock reads; ordinal (PartitionKey, RowKey) order like the service. + function Select-FakeRows { + param($Filter, $First) + $Rows = @($script:FakeLogRows) + if ($Filter -match "PartitionKey eq '([^']+)'") { $PK = $Matches[1]; $Rows = @($Rows | Where-Object { $_.PartitionKey -eq $PK }) } + if ($Filter -match "PartitionKey ge '([^']+)'") { $PK = $Matches[1]; $Rows = @($Rows | Where-Object { [string]::CompareOrdinal($_.PartitionKey, $PK) -ge 0 }) } + if ($Filter -match "PartitionKey le '([^']+)'") { $PK = $Matches[1]; $Rows = @($Rows | Where-Object { [string]::CompareOrdinal($_.PartitionKey, $PK) -le 0 }) } + if ($Filter -match "RowKey gt '([^']+)'") { $RK = $Matches[1]; $Rows = @($Rows | Where-Object { [string]::CompareOrdinal($_.RowKey, $RK) -gt 0 }) } + if ($Filter -match "RowKey eq '([^']+)'") { $RK = $Matches[1]; $Rows = @($Rows | Where-Object { $_.RowKey -eq $RK }) } + $Sorted = [System.Collections.Generic.List[object]]::new() + $Sorted.AddRange($Rows) + $Sorted.Sort([System.Comparison[object]] { param($a, $b) [string]::CompareOrdinal("$($a.PartitionKey)|$($a.RowKey)", "$($b.PartitionKey)|$($b.RowKey)") }) + if ($First) { @($Sorted | Select-Object -First $First) } else { @($Sorted) } + } + + function New-LogsRequest { + param([hashtable]$Query = @{}) + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ListLogs' } + Headers = @{ Authorization = 'token' } + Query = [pscustomobject]$Query + } + } +} + +AfterAll { + $env:CIPP_TIMEZONE = $script:OldTz +} + +Describe 'Invoke-ListLogs pagination' { + BeforeEach { + Mock -CommandName Test-CIPPAccess -MockWith { @('AllTenants') } + Mock -CommandName Get-Tenants -MockWith { @() } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { Select-FakeRows -Filter $Filter -First $First } + } + + It 'returns a full page with a continuation token, newest entries first' { + $Base = [datetime]::new(2025, 6, 10, 12, 0, 0, [System.DateTimeKind]::Utc) + $script:FakeLogRows = foreach ($i in 1..120) { New-FakeLogRow $Base.AddSeconds($i) $i } + + $response = Invoke-ListLogs -Request (New-LogsRequest -Query @{ + Filter = 'true'; StartDate = '20250610'; EndDate = '20250610' + manualPagination = 'true'; PageSize = '50' + }) -TriggerMetadata $null + + $response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $response.Body.Results | Should -HaveCount 50 + $response.Body.Results[0].Message | Should -Be 'seq 120' + $response.Body.Results[49].Message | Should -Be 'seq 71' + # Pin the record shape: the paged and legacy paths build this literal separately and + # the frontend treats their rows interchangeably. + $response.Body.Results[0].PSObject.Properties.Name | Should -Be @( + 'DateTime', 'Tenant', 'API', 'Message', 'User', 'Severity', 'LogData', + 'TenantID', 'AppId', 'IP', 'RowKey', 'StandardInfo', 'DateFilter') + $response.Body.Metadata.nextLink | Should -Be ('20250610|{0}' -f $response.Body.Results[49].RowKey) + # One chunk fills the page: exactly one CippLogs read. + Should -Invoke Get-CIPPAzDataTableEntity -Times 1 -Exactly + } + + It 'continues after the token without duplicates and skips -partN split rows' { + $Base = [datetime]::new(2025, 6, 10, 12, 0, 0, [System.DateTimeKind]::Utc) + $Rows = [System.Collections.Generic.List[object]]::new() + foreach ($i in 1..120) { $Rows.Add((New-FakeLogRow $Base.AddSeconds($i) $i)) } + $script:FakeLogRows = $Rows + + $PageOne = Invoke-ListLogs -Request (New-LogsRequest -Query @{ + Filter = 'true'; StartDate = '20250610'; EndDate = '20250610' + manualPagination = 'true'; PageSize = '50' + }) -TriggerMetadata $null + $BoundaryKey = $PageOne.Body.Results[49].RowKey + # A split-entity continuation row for the boundary entity sorts right after it and + # must not surface as an entity of its own on the next page. + $PartRow = New-FakeLogRow $Base.AddSeconds(71) 71 -RowKey "$BoundaryKey-part2" + $Rows.Add($PartRow) + $script:FakeLogRows = $Rows + + $PageTwo = Invoke-ListLogs -Request (New-LogsRequest -Query @{ + Filter = 'true'; StartDate = '20250610'; EndDate = '20250610' + manualPagination = 'true'; PageSize = '50' + nextLink = $PageOne.Body.Metadata.nextLink + }) -TriggerMetadata $null + + $PageTwo.Body.Results | Should -HaveCount 50 + $PageTwo.Body.Results[0].Message | Should -Be 'seq 70' + $PageTwo.Body.Results.RowKey | Should -Not -Contain "$BoundaryKey-part2" + $Overlap = @($PageTwo.Body.Results.RowKey | Where-Object { $PageOne.Body.Results.RowKey -contains $_ }) + $Overlap | Should -HaveCount 0 + } + + It 'walks the date range newest day first, skipping empty days, and omits nextLink when exhausted' { + $DayNew = [datetime]::new(2025, 6, 10, 12, 0, 0, [System.DateTimeKind]::Utc) + $DayOld = [datetime]::new(2025, 6, 7, 12, 0, 0, [System.DateTimeKind]::Utc) + $script:FakeLogRows = @( + foreach ($i in 1..10) { New-FakeLogRow $DayNew.AddSeconds($i) $i } + foreach ($i in 301..305) { New-FakeLogRow $DayOld.AddSeconds($i) $i } + ) + + $response = Invoke-ListLogs -Request (New-LogsRequest -Query @{ + Filter = 'true'; StartDate = '20250607'; EndDate = '20250610' + manualPagination = 'true'; PageSize = '50' + }) -TriggerMetadata $null + + $response.Body.Results | Should -HaveCount 15 + $response.Body.Results[0].Message | Should -Be 'seq 10' + $response.Body.Results[9].Message | Should -Be 'seq 1' + $response.Body.Results[10].Message | Should -Be 'seq 305' + $response.Body.Results[14].Message | Should -Be 'seq 301' + $response.Body.Metadata.nextLink | Should -BeNullOrEmpty + } + + It 'bounds table reads per request and resumes via nextLink over an empty range' { + $script:FakeLogRows = @() + + $PageOne = Invoke-ListLogs -Request (New-LogsRequest -Query @{ + Filter = 'true'; StartDate = '20250527'; EndDate = '20250610' + manualPagination = 'true'; PageSize = '50' + }) -TriggerMetadata $null + + $PageOne.Body.Results | Should -HaveCount 0 + # 15-day range, 10-query budget: page one stops mid-walk with a resumable token. + $PageOne.Body.Metadata.nextLink | Should -Not -BeNullOrEmpty + Should -Invoke Get-CIPPAzDataTableEntity -Times 10 -Exactly + + $PageTwo = Invoke-ListLogs -Request (New-LogsRequest -Query @{ + Filter = 'true'; StartDate = '20250527'; EndDate = '20250610' + manualPagination = 'true'; PageSize = '50' + nextLink = $PageOne.Body.Metadata.nextLink + }) -TriggerMetadata $null + + $PageTwo.Body.Results | Should -HaveCount 0 + $PageTwo.Body.Metadata.nextLink | Should -BeNullOrEmpty + } + + It 'applies severity and username filters client-side within pages' { + $Base = [datetime]::new(2025, 6, 10, 12, 0, 0, [System.DateTimeKind]::Utc) + $script:FakeLogRows = @( + New-FakeLogRow $Base.AddSeconds(1) 1 'Info' 'alice@contoso.com' + New-FakeLogRow $Base.AddSeconds(2) 2 'Error' 'alice@contoso.com' + New-FakeLogRow $Base.AddSeconds(3) 3 'Error' 'bob@contoso.com' + New-FakeLogRow $Base.AddSeconds(4) 4 'Debug' 'alice@contoso.com' + ) + + $response = Invoke-ListLogs -Request (New-LogsRequest -Query @{ + Filter = 'true'; StartDate = '20250610'; EndDate = '20250610' + Severity = 'Error'; User = 'alice*' + manualPagination = 'true'; PageSize = '50' + }) -TriggerMetadata $null + + $response.Body.Results | Should -HaveCount 1 + $response.Body.Results[0].Message | Should -Be 'seq 2' + } + + It 'keeps the legacy unpaginated bare-array shape when manualPagination is absent' { + $Base = [datetime]::new(2025, 6, 10, 12, 0, 0, [System.DateTimeKind]::Utc) + $script:FakeLogRows = foreach ($i in 1..5) { New-FakeLogRow $Base.AddSeconds($i) $i } + + $response = Invoke-ListLogs -Request (New-LogsRequest -Query @{ + Filter = 'true'; StartDate = '20250610'; EndDate = '20250610' + }) -TriggerMetadata $null + + # Bare array of entries - no Results/Metadata wrapper - with the same record shape + # as the paged path. + $response.Body | Should -HaveCount 5 + $response.Body[0].PSObject.Properties.Name | Should -Be @( + 'DateTime', 'Tenant', 'API', 'Message', 'User', 'Severity', 'LogData', + 'TenantID', 'AppId', 'IP', 'RowKey', 'StandardInfo', 'DateFilter') + Should -Invoke Get-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { + $Filter -match "PartitionKey ge '20250610' and PartitionKey le '20250610'" + } + } + + It 'widens a filtered query without dates to the last N days via Days, on both paths' { + # The scoped log drawers pass Days=N so a run that finished last night is still + # visible early the next day. Timezone is pinned to UTC by the harness. + $script:FakeLogRows = @() + $Today = [DateTime]::UtcNow.Date + $From = $Today.AddDays(-6).ToString('yyyyMMdd') + $To = $Today.ToString('yyyyMMdd') + + $null = Invoke-ListLogs -Request (New-LogsRequest -Query @{ Filter = 'true'; Days = '7' }) -TriggerMetadata $null + Should -Invoke Get-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { + $Filter -match "PartitionKey ge '$From' and PartitionKey le '$To'" + } + + # Paged: the day walk covers the same seven partitions (all empty here) and completes. + $response = Invoke-ListLogs -Request (New-LogsRequest -Query @{ Filter = 'true'; Days = '7'; manualPagination = 'true' }) -TriggerMetadata $null + $response.Body.Metadata.nextLink | Should -BeNullOrEmpty + Should -Invoke Get-CIPPAzDataTableEntity -Times 7 -Exactly -ParameterFilter { $Filter -match "PartitionKey eq '" } + Should -Invoke Get-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { $Filter -match "PartitionKey eq '$From'" } + Should -Invoke Get-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { $Filter -match "PartitionKey eq '$To'" } + } +} + +Describe 'Invoke-ListLogs single entry' { + BeforeEach { + Mock -CommandName Test-CIPPAccess -MockWith { @('AllTenants') } + Mock -CommandName Get-Tenants -MockWith { @() } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { Select-FakeRows -Filter $Filter -First $First } + } + + It 'derives the day partition from an inverted-ticks RowKey when no DateFilter is given' { + $Instant = [datetime]::new(2025, 6, 8, 12, 0, 0, [System.DateTimeKind]::Utc) + $Row = New-FakeLogRow $Instant 42 + $script:FakeLogRows = @($Row) + + $response = Invoke-ListLogs -Request (New-LogsRequest -Query @{ logentryid = $Row.RowKey }) -TriggerMetadata $null + + $response.Body | Should -HaveCount 1 + $response.Body[0].RowKey | Should -Be $Row.RowKey + $response.Body[0].DateFilter | Should -Be '20250608' + Should -Invoke Get-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { + $Filter -match "PartitionKey eq '20250608'" + } + } + + It 'honours an explicit DateFilter and still resolves legacy GUID RowKeys' { + $Instant = [datetime]::new(2025, 6, 8, 12, 0, 0, [System.DateTimeKind]::Utc) + $Row = New-FakeLogRow $Instant 7 -RowKey 'd6b31653-b3a4-4a54-9761-d5a2b746a349' + $script:FakeLogRows = @($Row) + + $response = Invoke-ListLogs -Request (New-LogsRequest -Query @{ + logentryid = $Row.RowKey; DateFilter = '20250608' + }) -TriggerMetadata $null + + $response.Body | Should -HaveCount 1 + $response.Body[0].RowKey | Should -Be $Row.RowKey + # The single-entry shape exposes Standard, not StandardInfo. + $response.Body[0].PSObject.Properties.Name | Should -Contain 'Standard' + $response.Body[0].PSObject.Properties.Name | Should -Not -Contain 'StandardInfo' + } + + It 'rejects log entry ids that are not plain hex-and-hyphen strings' { + $script:FakeLogRows = @() + { + Invoke-ListLogs -Request (New-LogsRequest -Query @{ logentryid = "x' or PartitionKey gt '" }) -TriggerMetadata $null + } | Should -Throw '*Invalid log entry id*' + } +} diff --git a/Tests/Endpoint/Invoke-ListMailboxes.Tests.ps1 b/Tests/Endpoint/Invoke-ListMailboxes.Tests.ps1 new file mode 100644 index 0000000000000..8fadadafa5564 --- /dev/null +++ b/Tests/Endpoint/Invoke-ListMailboxes.Tests.ps1 @@ -0,0 +1,113 @@ +# Pester tests for Invoke-ListMailboxes +# Validates the reporting-database branch: the legacy bare-array shape, and the +# manualPagination contract ({ Results, Metadata } pages chained via Metadata.nextLink). + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + class HttpResponseContext { + [int]$StatusCode + [object]$Body + } + + # Stub every CIPP helper the function calls so Pester's Mock has a command to replace. + function Get-CIPPMailboxesReport { param($TenantFilter, $PageSize, $ContinuationToken) } + function New-ExoRequest { param($tenantid, $cmdlet, $cmdParams, $Select) } + function Get-CIPPAutoExpandingArchiveState { param($MailboxAutoExpandingArchiveEnabled, $OrgAutoExpandingArchiveEnabled) } + function Get-NormalizedError { param($Message) $Message } + + $EndpointPath = Join-Path $RepoRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Administration/Invoke-ListMailboxes.ps1' + $EndpointScript = [ScriptBlock]::Create("using namespace System.Net`n" + (Get-Content -LiteralPath $EndpointPath -Raw)) + . $EndpointScript + + function New-MailboxRequest { + param([hashtable]$Query = @{}) + $Merged = @{ tenantFilter = 'contoso.onmicrosoft.com' } + foreach ($Key in $Query.Keys) { $Merged[$Key] = $Query[$Key] } + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ListMailboxes' } + Headers = @{ Authorization = 'token' } + Query = [pscustomobject]$Merged + } + } +} + +Describe 'Invoke-ListMailboxes report database branch' { + BeforeEach { + Mock -CommandName New-ExoRequest -MockWith { throw 'live EXO should not be called' } + } + + It 'returns the legacy bare array without manualPagination' { + Mock -CommandName Get-CIPPMailboxesReport -MockWith { + @( + [pscustomobject]@{ displayName = 'Box One'; UPN = 'one@contoso.com'; CacheTimestamp = '2026-08-18T10:00:00Z' } + [pscustomobject]@{ displayName = 'Box Two'; UPN = 'two@contoso.com'; CacheTimestamp = '2026-08-18T10:00:00Z' } + ) + } + + $response = Invoke-ListMailboxes -Request (New-MailboxRequest -Query @{ UseReportDB = 'true' }) -TriggerMetadata $null + + $response.StatusCode | Should -Be 200 + $response.Body | Should -HaveCount 2 + $response.Body[0].displayName | Should -Be 'Box One' + Should -Invoke Get-CIPPMailboxesReport -Times 1 -ParameterFilter { + $TenantFilter -eq 'contoso.onmicrosoft.com' -and -not $PageSize + } + } + + It 'returns { Results, Metadata } pages when manualPagination is set' { + Mock -CommandName Get-CIPPMailboxesReport -MockWith { + [PSCustomObject]@{ + Items = @( + [pscustomobject]@{ displayName = 'Box One'; UPN = 'one@contoso.com'; Tenant = 'contoso.onmicrosoft.com' } + ) + NextToken = 'contoso.onmicrosoft.com|Mailboxes-abc' + } + } + + $response = Invoke-ListMailboxes -Request (New-MailboxRequest -Query @{ + tenantFilter = 'AllTenants'; UseReportDB = 'true'; manualPagination = 'true'; PageSize = '9999'; nextLink = 'prev|token' + }) -TriggerMetadata $null + + $response.StatusCode | Should -Be 200 + $response.Body.Results | Should -HaveCount 1 + $response.Body.Results[0].displayName | Should -Be 'Box One' + $response.Body.Metadata.nextLink | Should -Be 'contoso.onmicrosoft.com|Mailboxes-abc' + # PageSize 9999 is inside the 250-10000 clamp and passes through; the incoming + # continuation token is forwarded verbatim. + Should -Invoke Get-CIPPMailboxesReport -Times 1 -ParameterFilter { + $TenantFilter -eq 'AllTenants' -and $PageSize -eq 9999 -and $ContinuationToken -eq 'prev|token' + } + } + + It 'omits nextLink on the final page but keeps the paged shape' { + Mock -CommandName Get-CIPPMailboxesReport -MockWith { + [PSCustomObject]@{ + Items = @([pscustomobject]@{ displayName = 'Box One' }) + NextToken = $null + } + } + + $response = Invoke-ListMailboxes -Request (New-MailboxRequest -Query @{ + UseReportDB = 'true'; manualPagination = 'true' + }) -TriggerMetadata $null + + $response.StatusCode | Should -Be 200 + $response.Body.Results | Should -HaveCount 1 + $response.Body.Metadata.nextLink | Should -BeNullOrEmpty + $response.Body.PSObject.Properties.Name | Should -Contain 'Metadata' + # No PageSize in the request: the default lands between the clamp bounds. + Should -Invoke Get-CIPPMailboxesReport -Times 1 -ParameterFilter { $PageSize -eq 5000 } + } + + It 'returns InternalServerError when the paged report read fails' { + Mock -CommandName Get-CIPPMailboxesReport -MockWith { throw 'No mailbox data found in reporting database. Sync the report data first.' } + + $response = Invoke-ListMailboxes -Request (New-MailboxRequest -Query @{ + UseReportDB = 'true'; manualPagination = 'true' + }) -TriggerMetadata $null + + $response.StatusCode | Should -Be 500 + "$($response.Body)" | Should -Match 'Sync the report data first' + } +} diff --git a/Tests/Endpoint/Invoke-ListMessageTrace.Tests.ps1 b/Tests/Endpoint/Invoke-ListMessageTrace.Tests.ps1 new file mode 100644 index 0000000000000..8a64d94f69f6d --- /dev/null +++ b/Tests/Endpoint/Invoke-ListMessageTrace.Tests.ps1 @@ -0,0 +1,146 @@ +# Pester tests for Invoke-ListMessageTrace +# Regression coverage for the "days" window off-by-epsilon: two separate Get-Date/UtcNow +# calls for Start/End made a "last 10 days" search span slightly over 10 days and trip the +# 10-day-window guard. Also covers that an explicit range genuinely over 10 days is still rejected. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + class HttpResponseContext { + [int]$StatusCode + [object]$Body + } + + # Stub every CIPP helper the function calls so Pester's Mock has a command to replace. + function New-GraphGetRequest { param($uri, $tenantid, $AsApp, $NoAuthCheck) } + function New-GraphPostRequest { param($Uri, $tenantid, $type, $body, $NoAuthCheck) } + function New-ExoRequest { param($TenantId, $Cmdlet, $CmdParams) } + function Write-LogMessage { param($headers, $API, $tenant, $message, $Sev) } + function Get-NormalizedError { param($message) $message } + + function Get-WindowFromUri { + param([string]$Uri) + $Decoded = [uri]::UnescapeDataString($Uri) + if ($Decoded -match 'receivedDateTime ge (\S+) and receivedDateTime le (\S+)') { + [pscustomobject]@{ + Start = [DateTime]::Parse($Matches[1], [cultureinfo]::InvariantCulture, 'AdjustToUniversal') + End = [DateTime]::Parse($Matches[2], [cultureinfo]::InvariantCulture, 'AdjustToUniversal') + } + } + } + + $EndpointPath = Join-Path $RepoRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ListMessageTrace.ps1' + $EndpointScript = [ScriptBlock]::Create("using namespace System.Net`n" + (Get-Content -LiteralPath $EndpointPath -Raw)) + . $EndpointScript + + function New-MessageTraceRequest { + param([hashtable]$Body = @{}) + $Merged = @{ tenantFilter = 'contoso.onmicrosoft.com' } + foreach ($Key in $Body.Keys) { $Merged[$Key] = $Body[$Key] } + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ListMessageTrace' } + Headers = @{ Authorization = 'token' } + Body = [pscustomobject]$Merged + } + } +} + +Describe 'Invoke-ListMessageTrace date window validation' { + BeforeEach { + Mock -CommandName New-GraphGetRequest -MockWith { + @([pscustomobject]@{ id = 'trace1'; messageId = 'msg1'; status = 'delivered'; subject = 'hi'; recipientAddress = 'to@contoso.com'; senderAddress = 'from@contoso.com'; receivedDateTime = (Get-Date).ToUniversalTime().ToString('o'); size = 100; fromIP = '1.1.1.1'; toIP = '2.2.2.2' }) + } + Mock -CommandName New-GraphPostRequest -MockWith { } + Mock -CommandName New-ExoRequest -MockWith { throw 'live EXO should not be called' } + Mock -CommandName Write-LogMessage -MockWith { } + } + + It 'does not reject a "last 10 days" relative search' { + $response = Invoke-ListMessageTrace -Request (New-MessageTraceRequest -Body @{ days = 10 }) -TriggerMetadata $null + + $response.StatusCode | Should -Be 200 + $response.Body.Metadata.Error | Should -BeNullOrEmpty + $response.Body.Results | Should -HaveCount 1 + } + + It 'rejects an explicit range spanning 10 days and 60 seconds' { + $End = [DateTimeOffset]::UtcNow + $Start = $End.AddDays(-10).AddSeconds(-60) + + $response = Invoke-ListMessageTrace -Request (New-MessageTraceRequest -Body @{ + startDate = $Start.ToUnixTimeSeconds().ToString() + endDate = $End.ToUnixTimeSeconds().ToString() + }) -TriggerMetadata $null + + $response.StatusCode | Should -Be 500 + $response.Body.Metadata.Error | Should -Match '10 day window' + } +} + +# Regression coverage for the messageId-with-no-window case: Graph applies a silent ~48h +# default when no receivedDateTime filter is present, so an explicit backward sweep in +# 10-day pages (Graph's per-request window cap) is required to find older messages. +Describe 'Invoke-ListMessageTrace messageId sweep' { + BeforeEach { + $script:CallUris = [System.Collections.Generic.List[string]]::new() + $script:CallCount = 0 + Mock -CommandName New-GraphPostRequest -MockWith { } + Mock -CommandName New-ExoRequest -MockWith { throw 'live EXO should not be called' } + Mock -CommandName Write-LogMessage -MockWith { } + } + + It 'sweeps backwards in 10-day windows and stops at the first hit' { + Mock -CommandName New-GraphGetRequest -MockWith { + $script:CallCount++ + $script:CallUris.Add($uri) + if ($script:CallCount -lt 3) { return @() } + @([pscustomobject]@{ id = 'trace1'; messageId = 'msg1'; status = 'delivered'; subject = 'hi'; recipientAddress = 'to@contoso.com'; senderAddress = 'from@contoso.com'; receivedDateTime = (Get-Date).ToUniversalTime().ToString('o'); size = 100; fromIP = '1.1.1.1'; toIP = '2.2.2.2' }) + } + + $response = Invoke-ListMessageTrace -Request (New-MessageTraceRequest -Body @{ messageId = 'msg1' }) -TriggerMetadata $null + + $response.StatusCode | Should -Be 200 + $response.Body.Results | Should -HaveCount 1 + Should -Invoke -CommandName New-GraphGetRequest -Times 3 -Exactly + $script:CallUris.Count | Should -Be 3 + + $Windows = @($script:CallUris | ForEach-Object { Get-WindowFromUri $_ }) + $Windows.Count | Should -Be 3 + foreach ($Window in $Windows) { + ($Window.End - $Window.Start).TotalDays | Should -BeLessOrEqual 10 + } + # Contiguous, moving backwards: each window's End equals the previous window's Start. + ($Windows[0].End - [DateTime]::UtcNow).TotalMinutes | Should -BeLessThan 1 + $Windows[1].End | Should -Be $Windows[0].Start + $Windows[2].End | Should -Be $Windows[1].Start + } + + It 'returns an empty, non-error result when no window contains a match' { + Mock -CommandName New-GraphGetRequest -MockWith { + $script:CallCount++ + $script:CallUris.Add($uri) + @() + } + + $response = Invoke-ListMessageTrace -Request (New-MessageTraceRequest -Body @{ messageId = 'msg-not-found' }) -TriggerMetadata $null + + Should -Invoke -CommandName New-GraphGetRequest -Times 9 -Exactly + $response.StatusCode | Should -Be 200 + $response.Body.Results | Should -HaveCount 0 + $response.Body.Metadata.Error | Should -BeNullOrEmpty + } + + It 'does not sweep when an explicit window is supplied alongside messageId' { + Mock -CommandName New-GraphGetRequest -MockWith { + $script:CallCount++ + $script:CallUris.Add($uri) + @([pscustomobject]@{ id = 'trace1'; messageId = 'msg1'; status = 'delivered'; subject = 'hi'; recipientAddress = 'to@contoso.com'; senderAddress = 'from@contoso.com'; receivedDateTime = (Get-Date).ToUniversalTime().ToString('o'); size = 100; fromIP = '1.1.1.1'; toIP = '2.2.2.2' }) + } + + $response = Invoke-ListMessageTrace -Request (New-MessageTraceRequest -Body @{ messageId = 'msg1'; days = 3 }) -TriggerMetadata $null + + $response.StatusCode | Should -Be 200 + $response.Body.Results | Should -HaveCount 1 + Should -Invoke -CommandName New-GraphGetRequest -Times 1 -Exactly + } +} diff --git a/Tests/Endpoint/Invoke-ListScheduledItems.TenantDomains.Tests.ps1 b/Tests/Endpoint/Invoke-ListScheduledItems.TenantDomains.Tests.ps1 new file mode 100644 index 0000000000000..1d3d6645a38a6 --- /dev/null +++ b/Tests/Endpoint/Invoke-ListScheduledItems.TenantDomains.Tests.ps1 @@ -0,0 +1,96 @@ +# Regression tests for CyberDrain/CIPP#491 - scheduler tenant-selector filtering. +# +# A scheduled task is stored against whichever tenant identifier the caller supplied when it was +# created (customerId, default domain, or the initial .onmicrosoft.com domain). The list endpoint +# used to resolve the selected tenant to only its default domain + customerId, so a task created via +# the API against the initial domain was filtered out of the tenant view and only reappeared under +# "*AllTenants". Both the storage query filter and the allowed-tenant access check must accept all +# three identifiers. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Invoke-ListScheduledItems.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $FunctionPath) { throw 'Could not locate Invoke-ListScheduledItems.ps1 under Modules/' } + + class HttpResponseContext { + [object]$StatusCode + [object]$Body + } + + $Accelerators = [psobject].Assembly.GetType('System.Management.Automation.TypeAccelerators') + if (-not $Accelerators::Get.ContainsKey('HttpStatusCode')) { + $Accelerators::Add('HttpStatusCode', [System.Net.HttpStatusCode]) + } + + # Stubs so Mock has commands to replace. + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property) } + function Test-CIPPAccess { param($Request, [switch]$TenantList) } + function Get-Tenants { param($TenantFilter, [switch]$IncludeErrors, [switch]$SkipList, [switch]$IncludeAll, [switch]$TriggerRefresh, [switch]$SkipDomains, [switch]$CleanOld) } + # Return the raw value so filter assertions are predictable (the real helper quotes/escapes). + function ConvertTo-CIPPODataFilterValue { param($Value, $Type) $Value } + + . $FunctionPath + + $script:Contoso = [pscustomobject]@{ + customerId = 'aaaaaaaa-1111-2222-3333-444444444444' + defaultDomainName = 'contoso.com' # custom domain made default in M365 + initialDomainName = 'contoso.onmicrosoft.com' # differs from default - the bug's trigger + } + $script:Fabrikam = [pscustomobject]@{ + customerId = 'bbbbbbbb-1111-2222-3333-444444444444' + defaultDomainName = 'fabrikam.com' + initialDomainName = 'fabrikam.onmicrosoft.com' + } + + function New-ListRequest { + param($TenantFilter) + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ListScheduledItems' } + Headers = @{} + Query = [pscustomobject]@{} + Body = [pscustomobject]@{ tenantFilter = $TenantFilter } + } + } +} + +Describe 'Invoke-ListScheduledItems tenant identifier resolution (#491)' { + BeforeEach { + $script:CapturedFilter = $null + Mock -CommandName Get-CIPPTable -MockWith { @{ Context = $TableName } } + # -TenantFilter call resolves the selected tenant; -IncludeErrors call builds the display/access lookup. + Mock -CommandName Get-Tenants -ParameterFilter { $TenantFilter } -MockWith { $script:Contoso } + Mock -CommandName Get-Tenants -ParameterFilter { $IncludeErrors } -MockWith { @($script:Contoso, $script:Fabrikam) } + } + + It 'builds a storage filter that matches default domain, initial domain, and customerId' { + Mock -CommandName Test-CIPPAccess -MockWith { 'AllTenants' } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $script:CapturedFilter = $Filter; @() } + + $null = Invoke-ListScheduledItems -Request (New-ListRequest -TenantFilter 'contoso.com') + + $script:CapturedFilter | Should -Match "Tenant eq 'contoso\.com'" + $script:CapturedFilter | Should -Match "Tenant eq 'contoso\.onmicrosoft\.com'" + $script:CapturedFilter | Should -Match "Tenant eq 'aaaaaaaa-1111-2222-3333-444444444444'" + } + + It 'returns a task stored under the initial domain to a tenant-scoped caller' { + # Scoped (non-AllTenants) caller: the access check must accept the initial domain too. + Mock -CommandName Test-CIPPAccess -MockWith { @('aaaaaaaa-1111-2222-3333-444444444444') } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + @( + [pscustomobject]@{ RowKey = '1'; Name = 'Task-Default'; Command = 'Invoke-CIPPOffboardingJob'; Tenant = 'contoso.com' } + [pscustomobject]@{ RowKey = '2'; Name = 'Task-Initial'; Command = 'Invoke-CIPPOffboardingJob'; Tenant = 'contoso.onmicrosoft.com' } + [pscustomobject]@{ RowKey = '3'; Name = 'Task-Other'; Command = 'Invoke-CIPPOffboardingJob'; Tenant = 'fabrikam.onmicrosoft.com' } + ) + } + + $Response = Invoke-ListScheduledItems -Request (New-ListRequest -TenantFilter 'contoso.com') + $Names = @($Response.Body.Name) + + $Names | Should -Contain 'Task-Default' + $Names | Should -Contain 'Task-Initial' # regressed before the fix: dropped by the access check + $Names | Should -Not -Contain 'Task-Other' + } +} diff --git a/Tests/Extensions/New-CippExtAlert.TicketReference.Tests.ps1 b/Tests/Extensions/New-CippExtAlert.TicketReference.Tests.ps1 new file mode 100644 index 0000000000000..461194db5ef2e --- /dev/null +++ b/Tests/Extensions/New-CippExtAlert.TicketReference.Tests.ps1 @@ -0,0 +1,193 @@ +# Pester tests for the ticket reference New-CippExtAlert hands to HaloPSA. +# A scheduled task's reference travels with the alert untouched; reading it is this extension's job +# because [ID:nnnn] is HaloPSA's own token - the same one it uses to thread emailed replies onto a +# ticket. When one is present the alert becomes a note on that ticket, and the affected-user lookup +# (plus the Graph call under it) is skipped, since the ticket already carries its end user. + +BeforeAll { + $BackendRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $BackendRoot 'Modules/CippExtensions/Public/New-CippExtAlert.ps1' + + function Get-CIPPTable { param([string]$TableName) } + function Get-CIPPAzDataTableEntity { param($TableName, $Filter, $Property, $First) } + function Get-Tenants { param($TenantFilter, [switch]$IncludeErrors) } + function New-HaloPSATicket { param($Title, $Description, $Client, $UserUPN, $AzureOID, $DisplayName, $TicketId) } + function New-GradientAlert { param($Title, $Description, $Client) } + function New-GraphGetRequest { param($uri, $tenantid, $AsApp) } + function Write-LogMessage { param($API, $tenant, $message, $sev, $LogData, $headers) } + + . $FunctionPath + + function New-Alert { + param($Reference, $AffectedUser, $PsaTicketId) + $Alert = [pscustomobject]@{ + TenantId = 'contoso.onmicrosoft.com' + AlertTitle = '[CIPP] Scheduled Task - contoso - New user creation' + AlertText = '

body

' + } + if ($Reference) { $Alert | Add-Member -NotePropertyName Reference -NotePropertyValue $Reference } + if ($PsaTicketId) { $Alert | Add-Member -NotePropertyName PsaTicketId -NotePropertyValue $PsaTicketId } + if ($AffectedUser) { $Alert | Add-Member -NotePropertyName AffectedUser -NotePropertyValue $AffectedUser } + $Alert + } + + $script:NewStarter = [pscustomobject]@{ UPN = 'new.starter@contoso.com'; DisplayName = 'New Starter' } +} + +Describe 'New-CippExtAlert - HaloPSA ticket reference' { + BeforeEach { + $script:TicketArgs = $null + Mock -CommandName Get-CIPPTable -MockWith { param([string]$TableName) @{ TableName = $TableName } } + Mock -CommandName Get-Tenants -MockWith { [pscustomobject]@{ customerId = 'customer-guid' } } + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName New-GraphGetRequest -MockWith { [pscustomobject]@{ id = 'oid-guid'; displayName = 'New Starter' } } + # An explicit param block is required: a Pester mock body without one leaves + # $PSBoundParameters empty, which silently passes every "was not passed" assertion. + Mock -CommandName New-HaloPSATicket -MockWith { + param($Title, $Description, $Client, $UserUPN, $AzureOID, $DisplayName, $TicketId) + $script:TicketArgs = [pscustomobject]@{ + Title = $Title; Client = $Client; UserUPN = $UserUPN + AzureOID = $AzureOID; DisplayName = $DisplayName; TicketId = $TicketId + } + } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + param($TableName, $Filter) + if ($Filter -like '*HaloMapping*') { return [pscustomobject]@{ RowKey = 'customer-guid'; IntegrationId = 19 } } + [pscustomobject]@{ + config = (@{ HaloPSA = @{ enabled = $true; LinkTicketsToUsers = $true } } | ConvertTo-Json -Depth 5) + } + } + } + + Context 'The task carries an explicit ticket id' { + It 'uses PsaTicketId when it is set' { + # Set from the ticket box on the user / offboarding / scheduler forms. + New-CippExtAlert -Alert (New-Alert -PsaTicketId 1380) + + $script:TicketArgs.TicketId | Should -Be 1380 + } + + It 'accepts it as a string, which is how the task row stores it' { + New-CippExtAlert -Alert (New-Alert -PsaTicketId '1380') + + $script:TicketArgs.TicketId | Should -Be 1380 + } + + It 'wins over an [ID:] token in the reference' { + New-CippExtAlert -Alert (New-Alert -PsaTicketId 1380 -Reference '[ID:99] older reference') + + $script:TicketArgs.TicketId | Should -Be 1380 + } + + It 'warns when the reference names a different ticket' { + # The reference is what the notification title shows, so a mismatch puts the note on a + # ticket the title never mentions - which reads as the feature not working at all. + New-CippExtAlert -Alert (New-Alert -PsaTicketId 1380 -Reference '[ID:1376] Starter Creation') + + $script:TicketArgs.TicketId | Should -Be 1380 + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { + $sev -eq 'Warning' -and $message -like '*targets HaloPSA ticket 1380*' -and $message -like '*names ticket 1376*' + } + } + + It 'stays quiet when both name the same ticket' { + New-CippExtAlert -Alert (New-Alert -PsaTicketId 1380 -Reference '[ID:1380] Starter Creation') + + $script:TicketArgs.TicketId | Should -Be 1380 + Should -Invoke Write-LogMessage -Times 0 -Exactly + } + + It 'skips the contact lookup like any targeted ticket' { + New-CippExtAlert -Alert (New-Alert -PsaTicketId 1380 -AffectedUser $script:NewStarter) + + Should -Invoke New-GraphGetRequest -Times 0 -Exactly + $script:TicketArgs.UserUPN | Should -BeNullOrEmpty + } + + It 'warns and raises a new ticket when the value is not a usable id' { + New-CippExtAlert -Alert (New-Alert -PsaTicketId 'not-a-ticket') + + $script:TicketArgs.TicketId | Should -BeNullOrEmpty + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { $sev -eq 'Warning' -and $message -like '*not a usable HaloPSA ticket id*' } + } + } + + Context 'The reference names a ticket' { + It 'passes the ticket id through to HaloPSA' { + New-CippExtAlert -Alert (New-Alert -Reference '[ID:1380] Starter Creation of FirstName LastName') + + $script:TicketArgs.TicketId | Should -Be 1380 + } + + It 'finds the token wherever it sits in the reference' { + New-CippExtAlert -Alert (New-Alert -Reference 'Starter Creation - see [ID:42] for detail') + + $script:TicketArgs.TicketId | Should -Be 42 + } + + It 'refuses a digit run too large to be a ticket id, and warns' { + New-CippExtAlert -Alert (New-Alert -Reference '[ID:99999999999999999999]') + + $script:TicketArgs.TicketId | Should -BeNullOrEmpty + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { $sev -eq 'Warning' -and $message -like '*not a usable HaloPSA ticket id*' } + } + + It 'skips the contact lookup and its Graph call' { + New-CippExtAlert -Alert (New-Alert -Reference '[ID:1380] Starter' -AffectedUser $script:NewStarter) + + Should -Invoke New-GraphGetRequest -Times 0 -Exactly + $script:TicketArgs.UserUPN | Should -BeNullOrEmpty + $script:TicketArgs.AzureOID | Should -BeNullOrEmpty + } + } + + Context 'The reference names no ticket' { + It 'sends no ticket id for a free-text reference' { + New-CippExtAlert -Alert (New-Alert -Reference 'Starter Creation of FirstName LastName') + + $script:TicketArgs.TicketId | Should -BeNullOrEmpty + } + + It 'sends no ticket id when there is no reference at all' { + New-CippExtAlert -Alert (New-Alert) + + $script:TicketArgs.TicketId | Should -BeNullOrEmpty + } + + It 'still resolves the affected user' { + New-CippExtAlert -Alert (New-Alert -AffectedUser $script:NewStarter) + + Should -Invoke New-GraphGetRequest -Times 1 -Exactly + $script:TicketArgs.UserUPN | Should -Be 'new.starter@contoso.com' + $script:TicketArgs.AzureOID | Should -Be 'oid-guid' + } + + It 'ignores a reference that merely contains digits' { + # 'PO 1380' or 'INV-2024-1389' are free text, not a ticket number. + New-CippExtAlert -Alert (New-Alert -Reference 'PO 1380') + + $script:TicketArgs.TicketId | Should -BeNullOrEmpty + } + + It 'ignores a reference with digits embedded in an identifier' { + New-CippExtAlert -Alert (New-Alert -Reference 'INV-2024-1389') + + $script:TicketArgs.TicketId | Should -BeNullOrEmpty + } + + It 'ignores a bare number - a reference is free text, not a ticket id' { + # Deliberate: order numbers, asset tags and change ids all live in this field, and + # treating one as a ticket id would append a starter's password to an unrelated ticket. + # [ID:nnnn] is required, which is also what Halo's own email threading matches on. + New-CippExtAlert -Alert (New-Alert -Reference '1389') + + $script:TicketArgs.TicketId | Should -BeNullOrEmpty + } + + It 'ignores a bare number with surrounding whitespace' { + New-CippExtAlert -Alert (New-Alert -Reference ' 1389 ') + + $script:TicketArgs.TicketId | Should -BeNullOrEmpty + } + } +} diff --git a/Tests/Extensions/New-HaloPSATicket.Priority.Tests.ps1 b/Tests/Extensions/New-HaloPSATicket.Priority.Tests.ps1 new file mode 100644 index 0000000000000..9e1b859ecb9c1 --- /dev/null +++ b/Tests/Extensions/New-HaloPSATicket.Priority.Tests.ps1 @@ -0,0 +1,159 @@ +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function Get-CIPPTable { param($TableName) @{} } + function Get-CIPPAzDataTableEntity { param($Filter, $Property) } + function Add-CIPPAzDataTableEntity { param($Entity, [switch]$Force) } + function Get-HaloToken { param($configuration) } + function Get-HaloTicketTypeSlaId { param($TicketType, $Configuration, $Token) } + function Get-HaloUser { param($AzureOID, $Email, $ClientId, $Configuration, $Token) } + function Get-StringHash { param($String) } + function Get-NormalizedError { param($Message) } + function Get-CippException { param($Exception) } + function Write-LogMessage { param($API, $tenant, $message, $sev, $LogData) } + + . (Join-Path $RepoRoot 'Modules/CippExtensions/Public/Halo/New-HaloPSATicket.ps1') + + # Rebuilds the Extensionsconfig row the function reads on every call. DefaultPriority is the + # integration-wide setting; the per-alert override arrives as the -TicketPriority parameter. + function New-HaloConfigRow { + param($DefaultPriority, [switch]$ConsolidateTickets) + $Halo = @{ + ResourceURL = 'https://halo.example.com/api' + TicketType = 1 + ConsolidateTickets = [bool]$ConsolidateTickets + } + if ($PSBoundParameters.ContainsKey('DefaultPriority')) { $Halo.DefaultPriority = $DefaultPriority } + [pscustomobject]@{ config = (@{ HaloPSA = $Halo } | ConvertTo-Json -Depth 5 -Compress) } + } + + # The ticket payload is only observable as the JSON body handed to Invoke-RestMethod. + function Get-SentTicket { + param($Body) + @($Body | ConvertFrom-Json)[0] + } +} + +Describe 'New-HaloPSATicket priority resolution' { + BeforeEach { + $script:SentBody = $null + + Mock Get-CIPPTable { @{} } + Mock Get-HaloToken { @{ access_token = 'token' } } + # Ticket type has an SLA unless a test says otherwise - priority is only sent when one is + # attached, because a priority id is meaningless outside the SLA that defines it. + Mock Get-HaloTicketTypeSlaId { 1 } + Mock Get-StringHash { 'hash' } + Mock Add-CIPPAzDataTableEntity {} + Mock Write-LogMessage {} + Mock Invoke-RestMethod { + $script:SentBody = $Body + @{ id = 42 } + } + } + + Context 'when creating a new ticket' { + BeforeEach { + Mock Get-CIPPAzDataTableEntity { New-HaloConfigRow -DefaultPriority 3 } + } + + It 'uses the per-alert priority over the integration default' { + $null = New-HaloPSATicket -title 'Alert' -description 'Body' -client 1 -TicketPriority 5 + + (Get-SentTicket -Body $script:SentBody).priority_id | Should -Be 5 + } + + It 'unwraps the {label, value} shape saved by the alert form' { + $null = New-HaloPSATicket -title 'Alert' -description 'Body' -client 1 -TicketPriority @{ label = 'Critical'; value = 5 } + + (Get-SentTicket -Body $script:SentBody).priority_id | Should -Be 5 + } + + It 'falls back to the integration default when no per-alert priority is set' { + $null = New-HaloPSATicket -title 'Alert' -description 'Body' -client 1 + + (Get-SentTicket -Body $script:SentBody).priority_id | Should -Be 3 + } + + It 'falls back to the integration default when the per-alert value is empty' { + $null = New-HaloPSATicket -title 'Alert' -description 'Body' -client 1 -TicketPriority '' + + (Get-SentTicket -Body $script:SentBody).priority_id | Should -Be 3 + } + + It 'falls back and warns when the per-alert value is a hint row' { + # -1 is the id Get-HaloPriority uses for its explanatory rows. It casts to a truthy + # int, so only the -gt 0 guard keeps it out of the payload. + $null = New-HaloPSATicket -title 'Alert' -description 'Body' -client 1 -TicketPriority -1 + + (Get-SentTicket -Body $script:SentBody).priority_id | Should -Be 3 + Should -Invoke Write-LogMessage -Times 1 -ParameterFilter { + $sev -eq 'Warning' -and $message -like "*from alert is not a valid priority id*" + } + } + } + + Context 'when the ticket type has no SLA' { + BeforeEach { + Mock Get-CIPPAzDataTableEntity { New-HaloConfigRow -DefaultPriority 3 } + Mock Get-HaloTicketTypeSlaId { $null } + } + + It 'omits priority_id even when the alert asks for one' { + # A priority id resolves against an SLA, so with none attached there is nothing for it + # to mean. Halo applies its own priority instead of us gambling on the SLA it picks. + $null = New-HaloPSATicket -title 'Alert' -description 'Body' -client 1 -TicketPriority 5 + + (Get-SentTicket -Body $script:SentBody).PSObject.Properties.Name | Should -Not -Contain 'priority_id' + } + + It 'omits priority_id when only the integration default is set' { + $null = New-HaloPSATicket -title 'Alert' -description 'Body' -client 1 + + (Get-SentTicket -Body $script:SentBody).PSObject.Properties.Name | Should -Not -Contain 'priority_id' + } + + It 'does not look up the SLA when there is no priority to send' { + Mock Get-CIPPAzDataTableEntity { New-HaloConfigRow } + + $null = New-HaloPSATicket -title 'Alert' -description 'Body' -client 1 + + Should -Invoke Get-HaloTicketTypeSlaId -Times 0 + } + } + + Context 'when neither priority is configured' { + BeforeEach { + Mock Get-CIPPAzDataTableEntity { New-HaloConfigRow } + } + + It 'omits priority_id entirely and logs nothing' { + $null = New-HaloPSATicket -title 'Alert' -description 'Body' -client 1 + + $Ticket = Get-SentTicket -Body $script:SentBody + $Ticket.PSObject.Properties.Name | Should -Not -Contain 'priority_id' + Should -Invoke Write-LogMessage -Times 0 + } + } + + Context 'when consolidating onto an existing open ticket' { + BeforeEach { + Mock Get-CIPPAzDataTableEntity -ParameterFilter { $Filter } { [pscustomobject]@{ TicketID = 99 } } + Mock Get-CIPPAzDataTableEntity -ParameterFilter { -not $Filter } { New-HaloConfigRow -DefaultPriority 3 -ConsolidateTickets } + Mock Invoke-RestMethod -ParameterFilter { $Method -eq 'Get' } { @{ id = 99; hasbeenclosed = $false } } + Mock Invoke-RestMethod -ParameterFilter { $Method -eq 'Post' } { + $script:SentBody = $Body + @{ id = 100 } + } + } + + It 'leaves the existing ticket priority alone' { + # Priority is deliberately create-path only - appending a note must not overwrite a + # priority a technician has since changed on the ticket. + $Result = New-HaloPSATicket -title 'Alert' -description 'Body' -client 1 -TicketPriority 5 + + $Result | Should -BeLike 'Note added to ticket in HaloPSA*' + (Get-SentTicket -Body $script:SentBody).PSObject.Properties.Name | Should -Not -Contain 'priority_id' + } + } +} diff --git a/Tests/Extensions/New-HaloPSATicket.TicketTarget.Tests.ps1 b/Tests/Extensions/New-HaloPSATicket.TicketTarget.Tests.ps1 new file mode 100644 index 0000000000000..ccd844a9304be --- /dev/null +++ b/Tests/Extensions/New-HaloPSATicket.TicketTarget.Tests.ps1 @@ -0,0 +1,169 @@ +# Pester tests for targeting an existing HaloPSA ticket from New-HaloPSATicket. +# A scheduled task raised from a Halo request carries that request's ticket in its reference, so the +# result belongs on that ticket rather than in a second one. The emailed copy already threads onto it +# via the [ID:nnnn] token in the subject; this is the PSA side of the same behaviour. It also sidesteps +# contact matching: an onboarding task creates the user seconds before the ticket is raised, so +# Get-HaloUser can never match and every ticket landed on the client's General User. + +BeforeAll { + $BackendRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $BackendRoot 'Modules/CippExtensions/Public/Halo/New-HaloPSATicket.ps1' + + function Get-CIPPTable { param([string]$TableName) } + function Get-CIPPAzDataTableEntity { param($TableName, $Filter, $Property, $First) } + function Add-CIPPAzDataTableEntity { param($TableName, $Entity, [switch]$Force) } + function Get-HaloToken { param($configuration) } + function Get-HaloUser { param($AzureOID, $Email, $ClientId, $Configuration, $Token) } + function Get-StringHash { param($String) } + function Get-NormalizedError { param($Message) } + function Get-CippException { param($Exception) } + function Write-LogMessage { param($API, $tenant, $message, $sev, $LogData, $headers) } + + . $FunctionPath + + function New-HaloConfigRow { + param([bool]$ConsolidateTickets = $false, [bool]$LinkTicketsToUsers = $true) + [pscustomobject]@{ + config = (@{ + HaloPSA = @{ + Enabled = $true + ResourceURL = 'https://halo.example.com/api' + TicketType = 21 + ConsolidateTickets = $ConsolidateTickets + LinkTicketsToUsers = $LinkTicketsToUsers + Outcome = @{ label = 'CIPP Update'; value = 155 } + } + } | ConvertTo-Json -Depth 5) + } + } + + # Records every call so a test can tell an /actions note from a /Tickets create. The mock body + # runs in Pester's own scope, not this function's, so the switches have to travel as script-scoped + # variables rather than closure captures. + function Set-RestMock { + param([bool]$TicketExists = $true, [bool]$Closed = $false, [switch]$NoteFails) + $script:Calls = [System.Collections.Generic.List[object]]::new() + $script:MockTicketExists = $TicketExists + $script:MockClosed = $Closed + $script:MockNoteFails = [bool]$NoteFails + Mock -CommandName Invoke-RestMethod -MockWith { + param($Uri, $ContentType, $Method, $Body, $Headers, [switch]$SkipHttpErrorCheck) + $script:Calls.Add([pscustomobject]@{ Uri = $Uri; Method = $Method; Body = $Body }) + if ($Method -eq 'Get') { + if (-not $script:MockTicketExists) { return @{} } + return @{ id = 1380; hasbeenclosed = $script:MockClosed } + } + if ($Uri -like '*/actions') { + if ($script:MockNoteFails) { throw 'Access denied to this action' } + return @{ id = 5555 } + } + @{ id = 1382 } + } + } + + function Get-NoteCall { $script:Calls | Where-Object { $_.Uri -like '*/actions' } | Select-Object -First 1 } + function Get-CreateCall { $script:Calls | Where-Object { $_.Uri -like '*/Tickets' -and $_.Method -eq 'Post' } | Select-Object -First 1 } +} + +Describe 'New-HaloPSATicket - targeting a referenced ticket' { + BeforeEach { + Mock -CommandName Get-CIPPTable -MockWith { param([string]$TableName) @{ TableName = $TableName } } + Mock -CommandName Get-HaloToken -MockWith { @{ access_token = 'token' } } + Mock -CommandName Get-StringHash -MockWith { 'hash' } + Mock -CommandName Add-CIPPAzDataTableEntity -MockWith { } + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Get-NormalizedError -MockWith { param($Message) $Message } + Mock -CommandName Get-CippException -MockWith { @{} } + Mock -CommandName Get-HaloUser -MockWith { $null } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { New-HaloConfigRow } + } + + Context 'The referenced ticket is open' { + BeforeEach { Set-RestMock } + + It 'adds a note to that ticket instead of creating one' { + $Result = New-HaloPSATicket -title 'Test alert' -description '

body

' -client 19 -TicketId 1380 + + $Result | Should -Be 'Note added to ticket in HaloPSA: 1380' + Get-CreateCall | Should -BeNullOrEmpty + $Note = @((Get-NoteCall).Body | ConvertFrom-Json)[0] + $Note.ticket_id | Should -Be 1380 + $Note.note_html | Should -Be '

body

' + } + + It 'uses the configured outcome for the note' { + $null = New-HaloPSATicket -title 'Test alert' -description '

body

' -client 19 -TicketId 1380 + + $Note = @((Get-NoteCall).Body | ConvertFrom-Json)[0] + $Note.outcome_id | Should -Be 155 + } + + It 'does not try to match a HaloPSA contact for the affected user' { + # The point of the feature: the ticket already has its user, and a just-created starter + # would never match anyway. + $null = New-HaloPSATicket -title 'Test alert' -description '

body

' -client 19 -TicketId 1380 -UserUPN 'new.starter@contoso.com' + + Should -Invoke Get-HaloUser -Times 0 -Exactly + } + + It 'ignores the consolidation table when a ticket is named' { + # Consolidation is keyed on a hash of the title; an explicit ticket must win over it. + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + param($TableName, $Filter) + if ($Filter) { return [pscustomobject]@{ TicketID = 999 } } + New-HaloConfigRow -ConsolidateTickets $true + } + + $null = New-HaloPSATicket -title 'Test alert' -description '

body

' -client 19 -TicketId 1380 + + $Note = @((Get-NoteCall).Body | ConvertFrom-Json)[0] + $Note.ticket_id | Should -Be 1380 + } + } + + Context 'The referenced ticket cannot take the note' { + It 'creates a new ticket and warns when the ticket is closed' { + Set-RestMock -Closed $true + + $null = New-HaloPSATicket -title 'Test alert' -description '

body

' -client 19 -TicketId 1380 + + Get-NoteCall | Should -BeNullOrEmpty + Get-CreateCall | Should -Not -BeNullOrEmpty + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { $sev -eq 'Warning' -and $message -like '*1380 is closed*' } + } + + It 'creates a new ticket and warns when the ticket does not exist' { + Set-RestMock -TicketExists $false + + $null = New-HaloPSATicket -title 'Test alert' -description '

body

' -client 19 -TicketId 1380 + + Get-CreateCall | Should -Not -BeNullOrEmpty + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { $sev -eq 'Warning' -and $message -like '*could not be found*' } + } + + It 'creates a new ticket when the note is rejected' { + Set-RestMock -NoteFails + + $null = New-HaloPSATicket -title 'Test alert' -description '

body

' -client 19 -TicketId 1380 + + Get-CreateCall | Should -Not -BeNullOrEmpty + } + } + + Context 'No ticket is referenced' { + BeforeEach { Set-RestMock } + + It 'creates a ticket exactly as before' { + $Result = New-HaloPSATicket -title 'Test alert' -description '

body

' -client 19 + + $Result | Should -Be 'Ticket created in HaloPSA: 1382' + Get-NoteCall | Should -BeNullOrEmpty + } + + It 'still resolves the affected user' { + $null = New-HaloPSATicket -title 'Test alert' -description '

body

' -client 19 -UserUPN 'existing@contoso.com' + + Should -Invoke Get-HaloUser -Times 1 -Exactly + } + } +} diff --git a/Tests/GraphHelper/Get-ClassicAPIToken.CertificateAuth.Tests.ps1 b/Tests/GraphHelper/Get-ClassicAPIToken.CertificateAuth.Tests.ps1 new file mode 100644 index 0000000000000..bc0a58a21fa3d --- /dev/null +++ b/Tests/GraphHelper/Get-ClassicAPIToken.CertificateAuth.Tests.ps1 @@ -0,0 +1,72 @@ +# Get-ClassicAPIToken is the second SAM-app token path (the classic v1 /oauth2/token endpoint used +# by New-ClassicAPIGetRequest). It must honour certificate-exclusive auth too, otherwise the flag +# would be enabled while classic API calls still sent the client secret. The v1 endpoint also needs +# the assertion audience to be the v1 token endpoint, not the default v2 one - pinned here. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function Get-CIPPSAMCertificate { param([switch]$SkipCache) } + function New-CIPPCertificateAssertion { param($TenantId, $AppId, $Certificate, $Audience) } + function Invoke-CIPPRestMethod { param($Uri, $Body, $ContentType, $Method) } + function Get-CippTable { param($tablename) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter) } + function Update-AzDataTableEntity { param($Context, $Entity, [switch]$Force) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/GraphHelper/Get-ClassicAPIToken.ps1') +} + +Describe 'Get-ClassicAPIToken certificate-exclusive gating' { + BeforeEach { + $script:classictoken = $null # clear the per-key token cache between cases + $script:SavedEnv = @{} + foreach ($Name in 'CertificateAuthMode', 'ApplicationID', 'ApplicationSecret', 'TenantID', 'RefreshToken') { + $script:SavedEnv[$Name] = [Environment]::GetEnvironmentVariable($Name) + } + $env:ApplicationID = 'sam-app-id' + $env:ApplicationSecret = 'sam-secret' + $env:RefreshToken = 'sam-refresh-token' + $env:TenantID = '11111111-2222-3333-4444-555555555555' + + Mock Get-CIPPSAMCertificate { [pscustomobject]@{ Certificate = 'CERT-OBJECT' } } + Mock New-CIPPCertificateAssertion { 'signed.jwt.assertion' } + Mock Invoke-CIPPRestMethod { @{ access_token = 't'; expires_on = ([int](Get-Date -UFormat %s) + 3600) } } + Mock Get-CippTable { @{} } + Mock Get-CIPPAzDataTableEntity { $null } + Mock Update-AzDataTableEntity {} + } + + AfterEach { + foreach ($Name in $script:SavedEnv.Keys) { + if ($null -eq $script:SavedEnv[$Name]) { Remove-Item "env:$Name" -ErrorAction SilentlyContinue } + else { Set-Item "env:$Name" -Value $script:SavedEnv[$Name] } + } + } + + It 'signs a certificate assertion (not the client secret) for the classic v1 endpoint when the flag is on' { + $env:CertificateAuthMode = $true + + $null = Get-ClassicAPIToken -tenantID 'contoso.onmicrosoft.com' -Resource 'https://api.example.com' + + # The assertion audience must be the v1 token endpoint for the target tenant. + Should -Invoke New-CIPPCertificateAssertion -Times 1 -Exactly -ParameterFilter { + $Audience -eq 'https://login.microsoftonline.com/contoso.onmicrosoft.com/oauth2/token' + } + Should -Invoke Invoke-CIPPRestMethod -Times 1 -Exactly -ParameterFilter { + $Body.ContainsKey('client_assertion') -and + $Body['client_assertion_type'] -eq 'urn:ietf:params:oauth:client-assertion-type:jwt-bearer' -and + -not $Body.ContainsKey('client_secret') + } + } + + It 'uses the client secret when the flag is off' { + Remove-Item env:CertificateAuthMode -ErrorAction SilentlyContinue + + $null = Get-ClassicAPIToken -tenantID 'contoso.onmicrosoft.com' -Resource 'https://api.example.com' + + Should -Invoke New-CIPPCertificateAssertion -Times 0 -Exactly + Should -Invoke Invoke-CIPPRestMethod -Times 1 -Exactly -ParameterFilter { + $Body['client_secret'] -eq 'sam-secret' -and -not $Body.ContainsKey('client_assertion') + } + } +} diff --git a/Tests/GraphHelper/Get-GraphToken.CertificateAuth.Tests.ps1 b/Tests/GraphHelper/Get-GraphToken.CertificateAuth.Tests.ps1 new file mode 100644 index 0000000000000..ffb8f08f31f84 --- /dev/null +++ b/Tests/GraphHelper/Get-GraphToken.CertificateAuth.Tests.ps1 @@ -0,0 +1,110 @@ +# The certificate-exclusive auth flag lets CIPP authenticate its SAM application with the SAM +# certificate instead of the client secret. Two invariants must never regress: +# 1. When the flag is on, the SAM app's own tokens (app-only AND delegated) use the certificate. +# 2. It is scoped to the SAM app only - callers passing an explicit $AppID/$AppSecret authenticate +# a different application whose registration does not carry the SAM certificate, so they must +# keep using the secret even while the flag is on. +# A regression in either direction is a broad authentication outage, so both are pinned here. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function Get-CIPPAuthentication { $true } + function Get-CippTable { param($tablename) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property) } + function Add-CIPPAzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Update-AzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Get-CIPPSAMCertificate { param([switch]$SkipCache) } + function Get-GraphTokenFromCert { param($TenantId, $AppId, $Scope, $Certificate, [switch]$SkipCache) } + function New-CIPPCertificateAssertion { param($TenantId, $AppId, $Certificate) } + function Invoke-CIPPRestMethod { param($Method, $Uri, $Body, $ContentType) } + function Get-CippKeyVaultName {} + function Get-CippKeyVaultSecret { param($VaultName, $Name, [switch]$AsPlainText) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/GraphHelper/Get-GraphToken.ps1') +} + +Describe 'Get-GraphToken certificate-exclusive gating' { + BeforeEach { + # A clean, non-direct-tenant environment: the tenant we ask for equals $env:TenantID so the + # direct-tenant refresh-token branch is never taken. + $script:SavedEnv = @{} + foreach ($Name in 'CertificateAuthMode', 'ApplicationID', 'ApplicationSecret', 'TenantID', 'RefreshToken', 'SetFromProfile') { + $script:SavedEnv[$Name] = [Environment]::GetEnvironmentVariable($Name) + } + $env:ApplicationID = 'sam-app-id' + $env:ApplicationSecret = 'sam-secret' + $env:TenantID = '11111111-2222-3333-4444-555555555555' + $env:RefreshToken = 'sam-refresh-token' + $env:SetFromProfile = 'true' # skip the Get-CIPPAuthentication reload inside the function + + Mock Get-CippTable { @{} } + Mock Get-CIPPAzDataTableEntity { $null } + Mock Add-CIPPAzDataTableEntity {} + Mock Update-AzDataTableEntity {} + Mock Get-CIPPSAMCertificate { [pscustomobject]@{ Certificate = 'CERT-OBJECT'; Thumbprint = 'ABC' } } + Mock Get-GraphTokenFromCert { @{ access_token = 'cert-token'; expires_in = 3600 } } + Mock New-CIPPCertificateAssertion { 'signed.jwt.assertion' } + Mock Invoke-CIPPRestMethod { @{ access_token = 'secret-token'; expires_in = 3600 } } + } + + AfterEach { + foreach ($Name in $script:SavedEnv.Keys) { + if ($null -eq $script:SavedEnv[$Name]) { + Remove-Item "env:$Name" -ErrorAction SilentlyContinue + } else { + Set-Item "env:$Name" -Value $script:SavedEnv[$Name] + } + } + } + + It 'uses the certificate for an app-only SAM token when the flag is on' { + $env:CertificateAuthMode = $true + + $null = Get-GraphToken -AsApp $true + + Should -Invoke Get-GraphTokenFromCert -Times 1 -Exactly + Should -Invoke Invoke-CIPPRestMethod -Times 0 -Exactly + } + + It 'uses a certificate assertion (not the client secret) for a delegated SAM token when the flag is on' { + $env:CertificateAuthMode = $true + + $null = Get-GraphToken + + Should -Invoke New-CIPPCertificateAssertion -Times 1 -Exactly + Should -Invoke Get-GraphTokenFromCert -Times 0 -Exactly + Should -Invoke Invoke-CIPPRestMethod -Times 1 -Exactly -ParameterFilter { + $Body.ContainsKey('client_assertion') -and + $Body['client_assertion_type'] -eq 'urn:ietf:params:oauth:client-assertion-type:jwt-bearer' -and + -not $Body.ContainsKey('client_secret') + } + } + + It 'still uses the client secret when the flag is off' { + Remove-Item env:CertificateAuthMode -ErrorAction SilentlyContinue + + $null = Get-GraphToken -AsApp $true + + Should -Invoke Get-GraphTokenFromCert -Times 0 -Exactly + Should -Invoke Invoke-CIPPRestMethod -Times 1 -Exactly -ParameterFilter { + $Body['client_secret'] -eq 'sam-secret' -and -not $Body.ContainsKey('client_assertion') + } + } + + It 'does NOT use the SAM certificate for a different app passed with an explicit AppID/AppSecret, even when the flag is on' { + # This is the guard: the SAM certificate is not registered on an arbitrary application, so + # forcing it here would break every extension/other-app token. The explicit secret must win. + $env:CertificateAuthMode = $true + + $null = Get-GraphToken -AppID 'other-app-id' -AppSecret 'other-app-secret' + + Should -Invoke Get-GraphTokenFromCert -Times 0 -Exactly + Should -Invoke New-CIPPCertificateAssertion -Times 0 -Exactly + Should -Invoke Invoke-CIPPRestMethod -Times 1 -Exactly -ParameterFilter { + $Body['client_id'] -eq 'other-app-id' -and + $Body['client_secret'] -eq 'other-app-secret' -and + -not $Body.ContainsKey('client_assertion') + } + } +} diff --git a/Tests/GraphHelper/Get-Tenants.RefreshLoop.Tests.ps1 b/Tests/GraphHelper/Get-Tenants.RefreshLoop.Tests.ps1 new file mode 100644 index 0000000000000..916947d3e2fbe --- /dev/null +++ b/Tests/GraphHelper/Get-Tenants.RefreshLoop.Tests.ps1 @@ -0,0 +1,225 @@ +# Get-Tenants is the only writer of the Tenants cache, and its refresh loop decides when a cached +# row is trusted as-is and when its domains are re-read from Graph. These pin the rules that were +# found broken in the field: a healthy row's default domain was never re-derived (a custom domain +# made default after onboarding stayed .onmicrosoft.com for months), a refresh scoped to one +# tenant was defeated by a matching Alias, the by-domain form of that refresh matched no +# relationships at all, and a transient failure of the domains read could overwrite a good custom +# default with the fallback's initial domain. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function Get-CippTable { param($tablename) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property) } + function Get-AzDataTableEntity { param($Context, $Filter) } + function Add-CIPPAzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Add-AzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Remove-CIPPAzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function New-GraphGetRequest { param($uri, $tenantid, $NoAuthCheck) } + function Write-LogMessage { param($API, $tenant, $message, $Sev, $LogData, $headers, $level) } + function Get-CippException { param($Exception) } + function ConvertTo-CIPPODataFilterValue { param($Value, $Type) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/GraphHelper/Get-Tenants.ps1') + + $script:OrigRefreshToken = $env:RefreshToken + $script:OrigTenantID = $env:TenantID + $env:RefreshToken = 'pester' + $env:TenantID = 'ffffffff-ffff-ffff-ffff-ffffffffffff' + + $script:GuidA = '11111111-1111-1111-1111-111111111111' + $script:GuidB = '22222222-2222-2222-2222-222222222222' + + # LastRefresh is a [DateTimeOffset] here on purpose - that is what the table hands back, and + # the staleness check must cope with it (a [datetime] cast of it throws). + function New-CachedRow { + param($Guid, $DisplayName, $Default, $Initial, $LastRefresh) + [PSCustomObject]@{ + PartitionKey = 'Tenants' + RowKey = $Guid + customerId = $Guid + displayName = $DisplayName + defaultDomainName = $Default + initialDomainName = $Initial + delegatedPrivilegeStatus = 'granularDelegatedAdminPrivileges' + Excluded = $false + GraphErrorCount = 0 + LastGraphError = '' + RequiresRefresh = $false + LastRefresh = $LastRefresh + } + } + function New-Relationship { + param($Guid, $DisplayName) + [PSCustomObject]@{ + displayName = "GDAP-$DisplayName" + customer = [PSCustomObject]@{ tenantId = $Guid; displayName = $DisplayName } + autoExtendDuration = 'P180D' + endDateTime = (Get-Date).AddYears(1).ToString('o') + } + } + function New-Domain { + param($Id, [bool]$IsDefault, [bool]$IsInitial) + [PSCustomObject]@{ id = $Id; isDefault = $IsDefault; isInitial = $IsInitial } + } +} + +AfterAll { + $env:RefreshToken = $script:OrigRefreshToken + $env:TenantID = $script:OrigTenantID +} + +Describe 'Get-Tenants refresh loop' { + BeforeEach { + $script:RowsByKey = @{} + $script:Relationships = @() + $script:Aliases = @{} + $script:DomainsByTenant = @{} + $script:ThrowDomainsFor = @() + $script:FallbackDomain = 'fallback.onmicrosoft.com' + + Mock Get-CippTable { @{} } + Mock ConvertTo-CIPPODataFilterValue { $Value } + Mock Write-LogMessage {} + Mock Get-CippException { @{} } + Mock Add-CIPPAzDataTableEntity {} + Mock Get-AzDataTableEntity { + if ($Filter -match "PartitionKey eq '([^']+)'" -and $script:Aliases.ContainsKey($Matches[1])) { + return [PSCustomObject]@{ Value = $script:Aliases[$Matches[1]] } + } + $null + } + Mock Get-CIPPAzDataTableEntity { + if ([string]::IsNullOrEmpty($Filter)) { return [PSCustomObject]@{ state = 'gdap' } } # tenantMode + if ($Filter -like '*Excluded eq true*') { return $null } # skip list + if ($Filter -match "RowKey eq '([^']+)'") { return $script:RowsByKey[$Matches[1]] } # one tenant + return @($script:RowsByKey.Values) # cache read + } + Mock New-GraphGetRequest { + if ($uri -like '*delegatedAdminRelationships*') { return $script:Relationships } + if ($uri -like '*beta/domains*') { + if ($script:ThrowDomainsFor -contains $tenantid) { throw 'domains read failed' } + return $script:DomainsByTenant[$tenantid] + } + if ($uri -like '*findTenantInformationByTenantId*') { return [PSCustomObject]@{ defaultDomainName = $script:FallbackDomain } } + throw "unexpected Graph call: $uri" + } + } + + Context 'bulk refresh (no TenantFilter)' { + BeforeEach { + $script:Relationships = @(New-Relationship -Guid $script:GuidA -DisplayName 'Contoso') + $script:DomainsByTenant[$script:GuidA] = @( + (New-Domain -Id 'contoso.com' -IsDefault $true -IsInitial $false), + (New-Domain -Id 'contoso.onmicrosoft.com' -IsDefault $false -IsInitial $true) + ) + } + + It 'trusts a fresh healthy row and does not re-read its domains' { + $script:RowsByKey[$script:GuidA] = New-CachedRow -Guid $script:GuidA -DisplayName 'Contoso' -Default 'contoso.com' -Initial 'contoso.onmicrosoft.com' -LastRefresh ([DateTimeOffset]::UtcNow.AddDays(-2)) + + $Result = Get-Tenants -IncludeAll -TriggerRefresh + + Should -Invoke New-GraphGetRequest -ParameterFilter { $uri -like '*beta/domains*' } -Times 0 -Exactly + @($Result).Count | Should -Be 1 + $Result.defaultDomainName | Should -Be 'contoso.com' + } + + It 're-reads domains for a row last derived over 7 days ago and picks up the new default' { + # Cached while .onmicrosoft.com was still the default; a custom domain has since been made default in M365. + $script:RowsByKey[$script:GuidA] = New-CachedRow -Guid $script:GuidA -DisplayName 'Contoso' -Default 'contoso.onmicrosoft.com' -Initial 'contoso.onmicrosoft.com' -LastRefresh ([DateTimeOffset]::UtcNow.AddDays(-30)) + + $Result = Get-Tenants -IncludeAll -TriggerRefresh + + Should -Invoke New-GraphGetRequest -ParameterFilter { $uri -like '*beta/domains*' } -Times 1 -Exactly + $Result.defaultDomainName | Should -Be 'contoso.com' + $Result.RequiresRefresh | Should -BeFalse + $Result.LastRefresh | Should -BeGreaterThan (Get-Date).ToUniversalTime().AddMinutes(-1) + } + + It 'treats a row with no LastRefresh as stale' { + $script:RowsByKey[$script:GuidA] = New-CachedRow -Guid $script:GuidA -DisplayName 'Contoso' -Default 'contoso.onmicrosoft.com' -Initial 'contoso.onmicrosoft.com' -LastRefresh $null + + $null = Get-Tenants -IncludeAll -TriggerRefresh + + Should -Invoke New-GraphGetRequest -ParameterFilter { $uri -like '*beta/domains*' } -Times 1 -Exactly + } + + It "does not let one tenant's fallback flag the next tenant for refresh" { + $script:Relationships = @( + (New-Relationship -Guid $script:GuidA -DisplayName 'Contoso'), + (New-Relationship -Guid $script:GuidB -DisplayName 'Fabrikam') + ) + $Stale = [DateTimeOffset]::UtcNow.AddDays(-30) + $script:RowsByKey[$script:GuidA] = New-CachedRow -Guid $script:GuidA -DisplayName 'Contoso' -Default 'contoso.onmicrosoft.com' -Initial 'contoso.onmicrosoft.com' -LastRefresh $Stale + $script:RowsByKey[$script:GuidB] = New-CachedRow -Guid $script:GuidB -DisplayName 'Fabrikam' -Default 'fabrikam.onmicrosoft.com' -Initial 'fabrikam.onmicrosoft.com' -LastRefresh $Stale + $script:DomainsByTenant[$script:GuidB] = @( + (New-Domain -Id 'fabrikam.com' -IsDefault $true -IsInitial $false), + (New-Domain -Id 'fabrikam.onmicrosoft.com' -IsDefault $false -IsInitial $true) + ) + $script:ThrowDomainsFor = @($script:GuidA) + + $null = Get-Tenants -IncludeAll -TriggerRefresh + + # A fell back and is flagged; B read fine and must not inherit the flag. + Should -Invoke Add-CIPPAzDataTableEntity -ParameterFilter { $Entity.customerId -eq $script:GuidA -and $Entity.RequiresRefresh -eq $true } -Times 1 -Exactly + Should -Invoke Add-CIPPAzDataTableEntity -ParameterFilter { $Entity.customerId -eq $script:GuidB -and $Entity.defaultDomainName -eq 'fabrikam.com' -and $Entity.RequiresRefresh -eq $false } -Times 1 -Exactly + } + } + + Context 'refresh scoped to one tenant' { + BeforeEach { + $script:Relationships = @(New-Relationship -Guid $script:GuidA -DisplayName 'Contoso') + $script:DomainsByTenant[$script:GuidA] = @( + (New-Domain -Id 'contoso.com' -IsDefault $true -IsInitial $false), + (New-Domain -Id 'contoso.onmicrosoft.com' -IsDefault $false -IsInitial $true) + ) + # Fresh and healthy: only the scoping should force the re-read. + $script:RowsByKey[$script:GuidA] = New-CachedRow -Guid $script:GuidA -DisplayName 'Contoso' -Default 'contoso.onmicrosoft.com' -Initial 'contoso.onmicrosoft.com' -LastRefresh ([DateTimeOffset]::UtcNow.AddDays(-2)) + } + + It 're-reads domains even when the tenant alias matches its display name' { + $script:Aliases[$script:GuidA] = 'Contoso' + + $Result = Get-Tenants -TriggerRefresh -TenantFilter $script:GuidA + + Should -Invoke New-GraphGetRequest -ParameterFilter { $uri -like '*beta/domains*' } -Times 1 -Exactly + $Result.defaultDomainName | Should -Be 'contoso.com' + } + + It 'resolves a domain filter to the customerId and scopes the relationship pull to it' { + $Result = Get-Tenants -TriggerRefresh -TenantFilter 'contoso.onmicrosoft.com' + + Should -Invoke New-GraphGetRequest -ParameterFilter { $uri -like '*delegatedAdminRelationships*' -and $uri -like "*customer/tenantId eq '$($script:GuidA)'*" } -Times 1 -Exactly + Should -Invoke New-GraphGetRequest -ParameterFilter { $uri -like '*beta/domains*' } -Times 1 -Exactly + @($Result).Count | Should -Be 1 + $Result.defaultDomainName | Should -Be 'contoso.com' + } + } + + Context 'when the domains read fails' { + BeforeEach { + $script:Relationships = @(New-Relationship -Guid $script:GuidA -DisplayName 'Contoso') + $script:ThrowDomainsFor = @($script:GuidA) + $script:FallbackDomain = 'contoso.onmicrosoft.com' + } + + It "keeps a cached custom default over the fallback's initial domain and flags the row for retry" { + $script:RowsByKey[$script:GuidA] = New-CachedRow -Guid $script:GuidA -DisplayName 'Contoso' -Default 'contoso.com' -Initial 'contoso.onmicrosoft.com' -LastRefresh ([DateTimeOffset]::UtcNow.AddDays(-30)) + + $Result = Get-Tenants -IncludeAll -TriggerRefresh + + Should -Invoke Add-CIPPAzDataTableEntity -ParameterFilter { $Entity.RequiresRefresh -eq $true -and $Entity.defaultDomainName -eq 'contoso.com' -and $Entity.initialDomainName -eq 'contoso.onmicrosoft.com' } -Times 1 -Exactly + $Result.defaultDomainName | Should -Be 'contoso.com' + } + + It 'takes the fallback value when there is no custom default to protect' { + $script:RowsByKey[$script:GuidA] = New-CachedRow -Guid $script:GuidA -DisplayName 'Contoso' -Default 'contoso.onmicrosoft.com' -Initial 'contoso.onmicrosoft.com' -LastRefresh ([DateTimeOffset]::UtcNow.AddDays(-30)) + + $Result = Get-Tenants -IncludeAll -TriggerRefresh + + Should -Invoke Add-CIPPAzDataTableEntity -ParameterFilter { $Entity.RequiresRefresh -eq $true -and $Entity.defaultDomainName -eq 'contoso.onmicrosoft.com' } -Times 1 -Exactly + $Result.defaultDomainName | Should -Be 'contoso.onmicrosoft.com' + } + } +} diff --git a/Tests/GraphHelper/New-CIPPMFAConnectorToken.Tests.ps1 b/Tests/GraphHelper/New-CIPPMFAConnectorToken.Tests.ps1 new file mode 100644 index 0000000000000..bcb4237ecb99d --- /dev/null +++ b/Tests/GraphHelper/New-CIPPMFAConnectorToken.Tests.ps1 @@ -0,0 +1,63 @@ +# New-CIPPMFAConnectorToken caches a long-lived connector secret per tenant so the expensive provisioning +# (adding a credential to the MFA client SP) only runs when no usable cached secret exists. These tests pin +# that a cached secret is reused without provisioning, and that a cache miss provisions and stores one. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function New-GraphGetRequest { param($uri, $tenantid, $AsApp) } + function New-GraphPostRequest { param($uri, $tenantid, $type, $body, $AsApp) } + function Update-AppManagementPolicy { param($TenantFilter, $ApplicationId, [switch]$ServicePrincipal) } + function Get-CIPPTable { param($tablename) } + function Get-CIPPAzDataTableEntity { param($Filter) } + function Add-CIPPAzDataTableEntity { param($Entity, [switch]$Force) } + function Get-Tenants { param($TenantFilter) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/GraphHelper/New-CIPPMFAConnectorToken.ps1') + + $script:TenantGuid = '11111111-1111-1111-1111-111111111111' + $script:MFAAppID = '981f26a1-7f43-403b-a875-f8b09b8cd720' +} + +Describe 'New-CIPPMFAConnectorToken secret caching' { + BeforeEach { + # Force the dev (DevSecrets table) storage path so the assertions are deterministic. + $env:NonLocalHostAzurite = 'true' + Mock Get-CIPPTable { @{ Context = 'stub' } } + Mock Add-CIPPAzDataTableEntity {} + Mock Update-AppManagementPolicy {} + # Token exchange + Mock Invoke-RestMethod { [pscustomobject]@{ access_token = 'TOKEN123' } } + # SP lookup returns the MFA client SP so provisioning finds it (no SP create) + Mock New-GraphGetRequest { @([pscustomobject]@{ id = 'mfa-sp-id'; appId = $script:MFAAppID }) } + # addPassword returns a fresh secret + Mock New-GraphPostRequest { [pscustomobject]@{ secretText = 'NEWSECRET' } } + } + + AfterEach { + Remove-Item env:NonLocalHostAzurite -ErrorAction SilentlyContinue + } + + It 'reuses a cached secret without provisioning' { + Mock Get-CIPPAzDataTableEntity { [pscustomobject]@{ SecretValue = 'CACHEDSECRET' } } + + $result = New-CIPPMFAConnectorToken -TenantFilter $script:TenantGuid + + $result.AccessToken | Should -Be 'TOKEN123' + # No provisioning: neither the SP lookup nor addPassword should run on a cache hit. + Should -Not -Invoke New-GraphGetRequest + Should -Not -Invoke New-GraphPostRequest + Should -Not -Invoke Add-CIPPAzDataTableEntity + } + + It 'provisions and stores a new secret on a cache miss' { + Mock Get-CIPPAzDataTableEntity { $null } + + $result = New-CIPPMFAConnectorToken -TenantFilter $script:TenantGuid + + $result.AccessToken | Should -Be 'TOKEN123' + # addPassword is the only New-GraphPostRequest here (the SP already exists), and the new secret is cached. + Should -Invoke New-GraphPostRequest -Times 1 -Exactly + Should -Invoke Add-CIPPAzDataTableEntity -Times 1 -Exactly + } +} diff --git a/Tests/GraphHelper/New-GraphBulkRequest.Paging.Tests.ps1 b/Tests/GraphHelper/New-GraphBulkRequest.Paging.Tests.ps1 new file mode 100644 index 0000000000000..293b0d8dbee2a --- /dev/null +++ b/Tests/GraphHelper/New-GraphBulkRequest.Paging.Tests.ps1 @@ -0,0 +1,115 @@ +# New-GraphBulkRequest follows @odata.nextLink for every $batch item by re-batching the +# continuation pages. A continuation page that fails used to vanish without a trace: the parent +# item kept status 200 and only its first page, so a caller that treats "status < 400" as "the +# collection is complete" (the drift engine's stale-row prune does) worked from a partial list. +# On tenants with more than one page of settings-catalog policies a throttled page 2 therefore +# looked like "those policies are gone", their accepted drift rows were pruned, and they came +# back as New on the next run. These tests pin the retry and the incomplete marker. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function Get-AuthorisedRequest { param($Uri, $TenantID) } + function Get-GraphToken { param($tenantid, $scope, $AsApp) } + function Get-CippTable { param($tablename) } + function Get-CIPPAzDataTableEntity { param($Filter, $TableName) } + function Update-AzDataTableEntity { param($Entity, [switch]$Force, $TableName) } + function Invoke-CIPPRestMethod { param($Uri, $Method, $Headers, $ContentType, $Body) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/GraphHelper/New-GraphBulkRequest.ps1') + + function New-BatchReply { + param($Responses) + [pscustomobject]@{ responses = @($Responses) } + } + function New-PageItem { + param($Id, $Status = 200, $Values = @(), $NextLink, $Headers = $null, $Error = $null) + $Body = [pscustomobject]@{ value = @($Values) } + if ($NextLink) { $Body | Add-Member -NotePropertyName '@odata.nextLink' -NotePropertyValue $NextLink } + if ($Error) { $Body | Add-Member -NotePropertyName 'error' -NotePropertyValue ([pscustomobject]@{ message = $Error }) } + [pscustomobject]@{ id = $Id; status = $Status; headers = $Headers; body = $Body } + } +} + +Describe 'New-GraphBulkRequest continuation paging' { + BeforeEach { + $script:Calls = [System.Collections.Generic.List[string]]::new() + $script:Replies = [System.Collections.Generic.Queue[object]]::new() + Mock Get-AuthorisedRequest { $true } + Mock Get-GraphToken { @{} } + Mock Get-CippTable { @{} } + Mock Get-CIPPAzDataTableEntity { $null } + Mock Update-AzDataTableEntity {} + Mock Start-Sleep {} + Mock Invoke-CIPPRestMethod { + $script:Calls.Add($Body) + $script:Replies.Dequeue() + } + $script:Requests = @(@{ id = 'cp'; url = 'deviceManagement/configurationPolicies?$top=999'; method = 'GET' }) + $script:Next = 'https://graph.microsoft.com/beta/deviceManagement/configurationPolicies?$top=999&$skiptoken=page2' + } + + It 'merges every continuation page into the parent item' { + $script:Replies.Enqueue((New-BatchReply (New-PageItem -Id 'cp' -Values @(@{ id = 'p1' }, @{ id = 'p2' }) -NextLink $script:Next))) + $script:Replies.Enqueue((New-BatchReply (New-PageItem -Id 'cp' -Values @(@{ id = 'p3' })))) + + $Result = @(New-GraphBulkRequest -Requests $script:Requests -tenantid 'contoso.onmicrosoft.com' -asapp $true) + + $Result.Count | Should -Be 1 + @($Result[0].body.value).id | Should -Be @('p1', 'p2', 'p3') + $Result[0].PSObject.Properties['PagingIncomplete'] | Should -BeNullOrEmpty + $script:Calls.Count | Should -Be 2 + } + + It 'retries a throttled continuation page once, honouring Retry-After' { + $script:Replies.Enqueue((New-BatchReply (New-PageItem -Id 'cp' -Values @(@{ id = 'p1' }) -NextLink $script:Next))) + $script:Replies.Enqueue((New-BatchReply (New-PageItem -Id 'cp' -Status 429 -Headers ([pscustomobject]@{ 'Retry-After' = '3' }) -Error 'throttled'))) + $script:Replies.Enqueue((New-BatchReply (New-PageItem -Id 'cp' -Values @(@{ id = 'p2' })))) + + $Result = @(New-GraphBulkRequest -Requests $script:Requests -tenantid 'contoso.onmicrosoft.com' -asapp $true -WarningAction SilentlyContinue) + + @($Result[0].body.value).id | Should -Be @('p1', 'p2') + $Result[0].PSObject.Properties['PagingIncomplete'] | Should -BeNullOrEmpty + $script:Calls.Count | Should -Be 3 + $script:Calls[2] | Should -Match 'skiptoken=page2' + Should -Invoke Start-Sleep -Times 1 -Exactly -ParameterFilter { $Seconds -eq 3 } + } + + It 'marks the parent incomplete when the continuation page keeps failing' { + $script:Replies.Enqueue((New-BatchReply (New-PageItem -Id 'cp' -Values @(@{ id = 'p1' }) -NextLink $script:Next))) + $script:Replies.Enqueue((New-BatchReply (New-PageItem -Id 'cp' -Status 429 -Error 'throttled'))) + $script:Replies.Enqueue((New-BatchReply (New-PageItem -Id 'cp' -Status 503 -Error 'busy'))) + + $Result = @(New-GraphBulkRequest -Requests $script:Requests -tenantid 'contoso.onmicrosoft.com' -asapp $true -WarningVariable Warnings -WarningAction SilentlyContinue) + + @($Result[0].body.value).id | Should -Be @('p1') + $Result[0].status | Should -Be 200 + $Result[0].PagingIncomplete | Should -BeTrue + $Result[0].PagingError | Should -Match '503' + $Result[0].PagingError | Should -Match 'busy' + @($Warnings) | Where-Object { $_ -match 'incomplete' } | Should -Not -BeNullOrEmpty + $script:Calls.Count | Should -Be 3 + } + + It 'marks the parent incomplete when the batch reply omits the continuation page' { + $script:Replies.Enqueue((New-BatchReply (New-PageItem -Id 'cp' -Values @(@{ id = 'p1' }) -NextLink $script:Next))) + $script:Replies.Enqueue((New-BatchReply @())) + + $Result = @(New-GraphBulkRequest -Requests $script:Requests -tenantid 'contoso.onmicrosoft.com' -asapp $true -WarningAction SilentlyContinue) + + @($Result[0].body.value).id | Should -Be @('p1') + $Result[0].PagingIncomplete | Should -BeTrue + $Result[0].PagingError | Should -Match 'missing' + } + + It 'leaves items that never paged untouched' { + $script:Replies.Enqueue((New-BatchReply @((New-PageItem -Id 'cp' -Values @(@{ id = 'p1' })), (New-PageItem -Id 'other' -Status 429 -Error 'throttled')))) + + $Result = @(New-GraphBulkRequest -Requests ($script:Requests + @(@{ id = 'other'; url = 'x'; method = 'GET' })) -tenantid 'contoso.onmicrosoft.com' -asapp $true) + + $Result.Count | Should -Be 2 + ($Result | Where-Object id -eq 'cp').PSObject.Properties['PagingIncomplete'] | Should -BeNullOrEmpty + ($Result | Where-Object id -eq 'other').status | Should -Be 429 + $script:Calls.Count | Should -Be 1 + } +} diff --git a/Tests/GraphHelper/Update-AppManagementPolicy.CertificateOnly.Tests.ps1 b/Tests/GraphHelper/Update-AppManagementPolicy.CertificateOnly.Tests.ps1 new file mode 100644 index 0000000000000..85a4bf8ecc4d5 --- /dev/null +++ b/Tests/GraphHelper/Update-AppManagementPolicy.CertificateOnly.Tests.ps1 @@ -0,0 +1,91 @@ +# In certificate-only mode CIPP adds no client secret, so the app management policy exemption must +# NOT disable the password-addition block - doing so would re-permit secrets on the CIPP app and +# defeat the tenant's "Block password addition" (Secure Future Initiative) policy. It must still +# disable the key-credential restrictions so the SAM certificate can be registered. Both are pinned. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function New-GraphBulkRequest { param($Requests, $NoAuthCheck, $asapp, $tenantid, $headers) } + function New-GraphPostRequest { param($uri, $type, $body, $asapp, $NoAuthCheck, $tenantid, $headers) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/GraphHelper/Update-AppManagementPolicy.ps1') +} + +Describe 'Update-AppManagementPolicy certificate-only exemption' { + BeforeEach { + $script:CreatedPolicyBody = $null + $script:SavedEnv = @{} + foreach ($Name in 'CertificateAuthMode', 'ApplicationID') { $script:SavedEnv[$Name] = [Environment]::GetEnvironmentVariable($Name) } + Remove-Item env:CertificateAuthMode -ErrorAction SilentlyContinue + $env:ApplicationID = 'sam-app-id' + + # Default tenant policy blocks BOTH password addition and asymmetric key lifetime. + Mock New-GraphBulkRequest { + @( + [pscustomobject]@{ id = 'defaultPolicy'; body = [pscustomobject]@{ + applicationRestrictions = [pscustomobject]@{ + passwordCredentials = @([pscustomobject]@{ restrictionType = 'passwordAddition'; state = 'enabled' }) + keyCredentials = @([pscustomobject]@{ restrictionType = 'asymmetricKeyLifetime'; state = 'enabled' }) + } + } } + [pscustomobject]@{ id = 'appPolicies'; body = [pscustomobject]@{ value = @() } } + [pscustomobject]@{ id = 'appRegistration'; body = [pscustomobject]@{ id = 'cipp-obj-id'; appId = 'cipp-app-id'; displayName = 'CIPP-SAM' } } + ) + } + + # Capture the created exemption policy body; the assignment call just needs to succeed. + Mock New-GraphPostRequest -ParameterFilter { $uri -eq 'https://graph.microsoft.com/v1.0/policies/appManagementPolicies' } { + $script:CreatedPolicyBody = $body | ConvertFrom-Json + [pscustomobject]@{ id = 'new-policy-id' } + } + Mock New-GraphPostRequest { [pscustomobject]@{ id = 'new-policy-id' } } + } + + AfterEach { + foreach ($Name in $script:SavedEnv.Keys) { + if ($null -eq $script:SavedEnv[$Name]) { Remove-Item "env:$Name" -ErrorAction SilentlyContinue } + else { Set-Item "env:$Name" -Value $script:SavedEnv[$Name] } + } + } + + It 'omits the password-credential exemption in certificate-only mode (key exemption still applied)' { + $null = Update-AppManagementPolicy -TenantFilter 'contoso' -ApplicationId 'cipp-app-id' -CertificateOnly $true + + $script:CreatedPolicyBody | Should -Not -BeNullOrEmpty + # Password block left in force - no passwordCredentials exemption. + $script:CreatedPolicyBody.restrictions.PSObject.Properties.Name | Should -Not -Contain 'passwordCredentials' + # Key restrictions still disabled so the SAM certificate can be registered. + $KeyTypes = $script:CreatedPolicyBody.restrictions.keyCredentials.restrictionType + $KeyTypes | Should -Contain 'asymmetricKeyLifetime' + $KeyTypes | Should -Contain 'trustedCertificateAuthority' + } + + It 'includes the password-credential exemption in secret mode' { + $null = Update-AppManagementPolicy -TenantFilter 'contoso' -ApplicationId 'cipp-app-id' -CertificateOnly $false + + $script:CreatedPolicyBody | Should -Not -BeNullOrEmpty + $PwdTypes = $script:CreatedPolicyBody.restrictions.passwordCredentials.restrictionType + $PwdTypes | Should -Contain 'passwordAddition' + $PwdTypes | Should -Contain 'symmetricKeyAddition' + $script:CreatedPolicyBody.restrictions.keyCredentials.restrictionType | Should -Contain 'asymmetricKeyLifetime' + } + + It 'defaults to skipping the password exemption for the SAM app when the flag is on' { + $env:CertificateAuthMode = $true + + $null = Update-AppManagementPolicy -TenantFilter 'contoso' -ApplicationId 'sam-app-id' + + $script:CreatedPolicyBody.restrictions.PSObject.Properties.Name | Should -Not -Contain 'passwordCredentials' + } + + It 'still exempts the password for a NON-SAM app even when the flag is on' { + # The global flag must not strip the password exemption from other app registrations, which + # legitimately use a secret - only the SAM app authenticates with the certificate. + $env:CertificateAuthMode = $true + + $null = Update-AppManagementPolicy -TenantFilter 'contoso' -ApplicationId 'some-other-app' + + $script:CreatedPolicyBody.restrictions.passwordCredentials.restrictionType | Should -Contain 'passwordAddition' + } +} diff --git a/Tests/GraphHelper/Update-AppManagementPolicy.ExemptionBody.Tests.ps1 b/Tests/GraphHelper/Update-AppManagementPolicy.ExemptionBody.Tests.ps1 new file mode 100644 index 0000000000000..9d234e4af7ca0 --- /dev/null +++ b/Tests/GraphHelper/Update-AppManagementPolicy.ExemptionBody.Tests.ps1 @@ -0,0 +1,136 @@ +# Update-AppManagementPolicy builds the "CIPP Exemption Policy" body that Graph must accept. Graph +# rejects the whole appManagementPolicy create when it carries a restriction type it does not need, or +# a lifetime-type restriction (asymmetricKeyLifetime) without a valid maxLifetime. These tests pin the +# emitted body so a hardened tenant's default policy no longer blocks the exemption. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function New-GraphBulkRequest { param($Requests, $NoAuthCheck, $asapp, $tenantid, $headers) } + function New-GraphPostRequest { param($uri, $type, $body, $asapp, $NoAuthCheck, $tenantid, $headers) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/GraphHelper/Update-AppManagementPolicy.ps1') + + $script:AppId = '981f26a1-7f43-403b-a875-f8b09b8cd720' + + # Builds the three-item bulk response the function expects, with the caller-supplied default policy + # restrictions and an empty app-policy list (no existing exemption, app not yet targeted). + function New-BulkResponse { + param($PasswordRestrictions = @(), $KeyRestrictions = @()) + @( + [PSCustomObject]@{ id = 'defaultPolicy'; body = [PSCustomObject]@{ + applicationRestrictions = [PSCustomObject]@{ + passwordCredentials = $PasswordRestrictions + keyCredentials = $KeyRestrictions + } + } + } + [PSCustomObject]@{ id = 'appPolicies'; body = [PSCustomObject]@{ value = @() } } + [PSCustomObject]@{ id = 'appRegistration'; body = [PSCustomObject]@{ id = 'mfa-app-object-id'; appId = $script:AppId; displayName = 'Azure Multi-Factor Auth Client' } } + ) + } +} + +Describe 'Update-AppManagementPolicy exemption body' { + BeforeEach { + $script:CreateBody = $null + $script:AssignUri = $null + # Certificate-only mode is exercised in the sibling CertificateOnly suite; pin it off here so the + # body-shape assertions do not depend on the host's CertificateAuthMode environment variable. + $script:SavedCertMode = [Environment]::GetEnvironmentVariable('CertificateAuthMode') + Remove-Item env:CertificateAuthMode -ErrorAction SilentlyContinue + + Mock New-GraphPostRequest { + if ($uri -match 'policies/appManagementPolicies$') { + $script:CreateBody = $body | ConvertFrom-Json + } + if ($uri -match 'appManagementPolicies/\$ref$') { + $script:AssignUri = $uri + } + [PSCustomObject]@{ id = 'created-policy-id' } + } + } + + AfterEach { + if ($null -eq $script:SavedCertMode) { Remove-Item env:CertificateAuthMode -ErrorAction SilentlyContinue } + else { $env:CertificateAuthMode = $script:SavedCertMode } + } + + It 'emits only the passwordCredentials block when the default policy blocks password addition' { + Mock New-GraphBulkRequest { + New-BulkResponse -PasswordRestrictions @([PSCustomObject]@{ restrictionType = 'passwordAddition'; state = 'enabled' }) + } + + $null = Update-AppManagementPolicy -TenantFilter 'contoso.onmicrosoft.com' -ApplicationId $script:AppId -CertificateOnly $false + + $script:CreateBody | Should -Not -BeNullOrEmpty + $script:CreateBody.restrictions.passwordCredentials | Should -Not -BeNullOrEmpty + # No key credentials are blocked, so the body must not drag in a keyCredentials restriction Graph would reject. + $script:CreateBody.restrictions.PSObject.Properties.Name | Should -Not -Contain 'keyCredentials' + } + + It 'emits an asymmetricKeyLifetime restriction with a non-null maxLifetime when key credentials are blocked' { + Mock New-GraphBulkRequest { + New-BulkResponse -KeyRestrictions @([PSCustomObject]@{ restrictionType = 'asymmetricKeyLifetime'; state = 'enabled'; maxLifetime = 'P90D' }) + } + + $null = Update-AppManagementPolicy -TenantFilter 'contoso.onmicrosoft.com' -ApplicationId $script:AppId -CertificateOnly $false + + $script:CreateBody | Should -Not -BeNullOrEmpty + $Lifetime = $script:CreateBody.restrictions.keyCredentials | Where-Object { $_.restrictionType -eq 'asymmetricKeyLifetime' } + $Lifetime | Should -Not -BeNullOrEmpty + $Lifetime.maxLifetime | Should -Not -BeNullOrEmpty + # It echoes the tenant default's value when the default exposes one. + $Lifetime.maxLifetime | Should -Be 'P90D' + } + + It 'falls back to a conservative maxLifetime when the default policy does not expose one' { + Mock New-GraphBulkRequest { + New-BulkResponse -KeyRestrictions @([PSCustomObject]@{ restrictionType = 'asymmetricKeyLifetime'; state = 'enabled' }) + } + + $null = Update-AppManagementPolicy -TenantFilter 'contoso.onmicrosoft.com' -ApplicationId $script:AppId -CertificateOnly $false + + $Lifetime = $script:CreateBody.restrictions.keyCredentials | Where-Object { $_.restrictionType -eq 'asymmetricKeyLifetime' } + $Lifetime.maxLifetime | Should -Be 'P730D' + } + + It 'assigns the exemption to the application registration by default' { + Mock New-GraphBulkRequest { + New-BulkResponse -PasswordRestrictions @([PSCustomObject]@{ restrictionType = 'passwordAddition'; state = 'enabled' }) + } + + $null = Update-AppManagementPolicy -TenantFilter 'contoso.onmicrosoft.com' -ApplicationId $script:AppId -CertificateOnly $false + + $script:AssignUri | Should -Not -BeNullOrEmpty + $script:AssignUri | Should -Match '/applications/' + $script:AssignUri | Should -Not -Match '/servicePrincipals/' + } + + It 'assigns the exemption to the service principal when -ServicePrincipal is set' { + Mock New-GraphBulkRequest { + New-BulkResponse -PasswordRestrictions @([PSCustomObject]@{ restrictionType = 'passwordAddition'; state = 'enabled' }) + } + + $null = Update-AppManagementPolicy -TenantFilter 'contoso.onmicrosoft.com' -ApplicationId $script:AppId -CertificateOnly $false -ServicePrincipal + + $script:AssignUri | Should -Not -BeNullOrEmpty + $script:AssignUri | Should -Match '/servicePrincipals/' + $script:AssignUri | Should -Not -Match '/applications/' + } + + It 'treats an already-assigned policy reference as success, not a failure' { + Mock New-GraphBulkRequest { + New-BulkResponse -PasswordRestrictions @([PSCustomObject]@{ restrictionType = 'passwordAddition'; state = 'enabled' }) + } + # The target already has the policy assigned, so the $ref POST returns a duplicate-reference error. + Mock New-GraphPostRequest -ParameterFilter { $uri -match 'appManagementPolicies/\$ref$' } { + throw "One or more added object references already exist for the following modified properties: 'appManagementPolicies'." + } + + # A throw here would surface as a test error, which is the failure we are guarding against. + $result = Update-AppManagementPolicy -TenantFilter 'contoso.onmicrosoft.com' -ApplicationId $script:AppId -CertificateOnly $false -ServicePrincipal + $result.PolicyAction | Should -Not -Match 'Failed' + $result.PolicyAction | Should -Match 'assigned' + } +} diff --git a/Tests/Private/Add-CIPPDbItem.Tests.ps1 b/Tests/Private/Add-CIPPDbItem.Tests.ps1 index 1a982fdbf16f0..2fd4f8fa94cf0 100644 --- a/Tests/Private/Add-CIPPDbItem.Tests.ps1 +++ b/Tests/Private/Add-CIPPDbItem.Tests.ps1 @@ -85,6 +85,27 @@ Describe 'Add-CIPPDbItem authoritative empty collections' { } } + It 'projects every row-level split marker so the cleanup reassembles split orphans instead of dropping them' { + # Regression for #462. Get-AzDataTableLargeEntity only reassembles a split entity when the + # projection carries all of OriginalEntityId, PartIndex and PartCount. Selecting a subset + # (OriginalEntityId alone) made the module recognise a split row but fail to reassemble it, + # throw IncompleteEntity, and drop the whole entity - so the sweep never saw stale split + # rows from earlier runs and one uncollectable generation accumulated per run. The sweep + # relies on reassembly (each logical entity carries its RunId), so all three must be present. + Mock Get-CIPPAzDataTableEntity { @() } + + Add-CIPPDbItem -TenantFilter 'contoso.onmicrosoft.com' -Type 'IntuneIntents' -Data @( + [PSCustomObject]@{ id = 'new-policy' } + ) + + Should -Invoke Get-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { + $Property -contains 'OriginalEntityId' -and + $Property -contains 'PartIndex' -and + $Property -contains 'PartCount' -and + $Property -contains 'RunId' + } + } + It 'stamps every written row with the run id the cleanup keys on' { $script:Flushed = [System.Collections.Generic.List[object]]::new() Mock Add-CIPPAzDataTableEntity { $script:Flushed.AddRange(@($Entity)) } diff --git a/Tests/Private/Format-CIPPCAPolicy.Tests.ps1 b/Tests/Private/Format-CIPPCAPolicy.Tests.ps1 index 0401056ac55fd..14490235e8b28 100644 --- a/Tests/Private/Format-CIPPCAPolicy.Tests.ps1 +++ b/Tests/Private/Format-CIPPCAPolicy.Tests.ps1 @@ -326,6 +326,60 @@ Describe 'Format-CIPPCAPolicy' { } } + Context 'sessionControls.signInFrequency canonicalization' { + It 'casts a numeric string value to an int' { + $Policy = Convert-Policy '{ + "displayName": "CA201", + "conditions": { "users": { "includeUsers": ["All"] } }, + "sessionControls": { "signInFrequency": { "isEnabled": true, "frequencyInterval": "timeBased", "type": "hours", "value": "12" } } + }' + $Policy.sessionControls.signInFrequency.value | Should -Be 12 + $Policy.sessionControls.signInFrequency.value | Should -BeOfType [int] + } + + It 'sets value and type to explicit null when frequencyInterval is everyTime' { + $Policy = Convert-Policy '{ + "displayName": "CA201", + "conditions": { "users": { "includeUsers": ["All"] } }, + "sessionControls": { "signInFrequency": { "isEnabled": true, "frequencyInterval": "everyTime" } } + }' + $Policy.sessionControls.signInFrequency.PSObject.Properties.Name | Should -Contain 'value' + $Policy.sessionControls.signInFrequency.PSObject.Properties.Name | Should -Contain 'type' + $Policy.sessionControls.signInFrequency.value | Should -BeNullOrEmpty + $Policy.sessionControls.signInFrequency.type | Should -BeNullOrEmpty + } + + It 'overrides a stale value/type with null even when everyTime carries leftovers' { + $Policy = Convert-Policy '{ + "displayName": "CA201", + "conditions": { "users": { "includeUsers": ["All"] } }, + "sessionControls": { "signInFrequency": { "isEnabled": true, "frequencyInterval": "everyTime", "type": "hours", "value": "12" } } + }' + $Policy.sessionControls.signInFrequency.value | Should -BeNullOrEmpty + $Policy.sessionControls.signInFrequency.type | Should -BeNullOrEmpty + } + + It 'leaves an int value under timeBased unchanged' { + $Policy = Convert-Policy '{ + "displayName": "CA201", + "conditions": { "users": { "includeUsers": ["All"] } }, + "sessionControls": { "signInFrequency": { "isEnabled": true, "frequencyInterval": "timeBased", "type": "days", "value": 4 } } + }' + $Policy.sessionControls.signInFrequency.value | Should -Be 4 + $Policy.sessionControls.signInFrequency.type | Should -Be 'days' + } + + It 'casts a disabled signInFrequency with a string value too - Graph validates disabled sub-objects' { + $Policy = Convert-Policy '{ + "displayName": "CA201", + "conditions": { "users": { "includeUsers": ["All"] } }, + "sessionControls": { "signInFrequency": { "isEnabled": false, "frequencyInterval": "timeBased", "type": "hours", "value": "12" } } + }' + $Policy.sessionControls.signInFrequency.value | Should -Be 12 + $Policy.sessionControls.signInFrequency.value | Should -BeOfType [int] + } + } + Context 'edge cases' { It 'does nothing to a policy with no conditions at all' { { Convert-Policy '{"displayName":"CA201"}' } | Should -Not -Throw diff --git a/Tests/Private/Get-CIPPCVEReport.Tests.ps1 b/Tests/Private/Get-CIPPCVEReport.Tests.ps1 index a17aa0c425012..77903bebc2fa3 100644 --- a/Tests/Private/Get-CIPPCVEReport.Tests.ps1 +++ b/Tests/Private/Get-CIPPCVEReport.Tests.ps1 @@ -26,29 +26,34 @@ BeforeAll { param( $CveId = 'CVE-2024-0001', $Tenant = 'contoso.onmicrosoft.com', - $Devices = @(@{ deviceId = 'd1'; deviceName = 'PC-1'; osVersion = '10.0.19045'; softwareVersion = '120.0.0'; diskPaths = ''; registryPaths = '' }), - $LastUpdated = '2026-08-12T00:00:00.000Z' + $Devices = @(@{ deviceId = 'd1'; deviceName = 'PC-1' }), + $LastUpdated = '2026-08-12T00:00:00.000Z', + # The collector writes a unique-device count the reader trusts; default it to the + # number of stored device fragments, but allow tests to force a mismatch. + $DeviceCount ) + # Only the id and name are stored per device, whatever richer objects a caller passes. + $StoredDevices = @($Devices | ForEach-Object { @{ deviceId = $_.deviceId; deviceName = $_.deviceName } }) $Payload = @{ - PartitionKey = $CveId - RowKey = $Tenant - customerId = $Tenant - cveId = $CveId - softwareVendor = 'microsoft' - softwareName = 'edge' - vulnerabilitySeverityLevel = 'High' - recommendedSecurityUpdate = 'KB5034123' - recommendedSecurityUpdateUrl = 'https://support.microsoft.com/kb/5034123' - exploitabilityLevel = 'ExploitIsPublic' - deviceCount = @($Devices).Count + PartitionKey = $CveId + RowKey = $Tenant + id = $CveId + customerId = $Tenant + cveId = $CveId + softwareVendor = 'microsoft' + softwareName = 'edge' + softwareVersion = '120.0.0' + vulnerabilitySeverityLevel = 'High' + exploitabilityLevel = 'ExploitIsPublic' + deviceCount = if ($PSBoundParameters.ContainsKey('DeviceCount')) { $DeviceCount } else { $StoredDevices.Count } # Piped, not -InputObject: one device stays a bare object, several become an # array - the exact shape the collector writes. - deviceDetailsJson = [string]($Devices | ConvertTo-Json -Compress) - lastUpdated = $LastUpdated + deviceDetailsJson = [string]($StoredDevices | ConvertTo-Json -Compress) + lastUpdated = $LastUpdated } [pscustomobject]@{ PartitionKey = $Tenant - RowKey = "DefenderCVEs-$([guid]::NewGuid())" + RowKey = "DefenderCVEs-$CveId" Data = [string]($Payload | ConvertTo-Json -Depth 100 -Compress) Type = 'DefenderCVEs' } @@ -81,8 +86,8 @@ Describe 'Get-CIPPCVEReport' { It 'returns one aggregated entry per CVE with every field the frontend reads' { Mock -CommandName Get-CIPPDbItem -MockWith { New-CveRow -CveId 'CVE-B' -Devices @( - @{ deviceId = 'd1'; deviceName = 'PC-1'; osVersion = ''; softwareVersion = ''; diskPaths = 'C:\a\edge.exe'; registryPaths = 'HKLM\SOFTWARE\X' } - @{ deviceId = 'd2'; deviceName = 'PC-2'; osVersion = ''; softwareVersion = ''; diskPaths = ''; registryPaths = '' } + @{ deviceId = 'd1'; deviceName = 'PC-1' } + @{ deviceId = 'd2'; deviceName = 'PC-2' } ) New-CveRow -CveId 'CVE-A' New-CountRow @@ -100,13 +105,15 @@ Describe 'Get-CIPPCVEReport' { $B.exploitabilityLevel | Should -Be 'ExploitIsPublic' $B.softwareName | Should -Be 'edge' $B.softwareVendor | Should -Be 'microsoft' + $B.softwareVersion | Should -Be '120.0.0' $B.deviceCount | Should -Be 2 $B.tenantCount | Should -Be 1 @($B.affectedTenants).customerId | Should -Be @($script:Tenant) (@($B.affectedDevices).deviceName | Sort-Object) | Should -Be @('PC-1', 'PC-2') - @($B.diskPaths).Count | Should -Be 1 - @($B.diskPaths)[0].diskPaths | Should -Be 'C:\a\edge.exe' - @($B.registryPaths)[0].registryPaths | Should -Be 'HKLM\SOFTWARE\X' + (@($B.affectedDevices).deviceId | Sort-Object) | Should -Be @('d1', 'd2') + # registryPaths / diskPaths are no longer part of the response. + $B.PSObject.Properties.Name | Should -Not -Contain 'registryPaths' + $B.PSObject.Properties.Name | Should -Not -Contain 'diskPaths' $B.exceptionStatus | Should -Be 'None' $B.hasException | Should -BeFalse # ConvertFrom-Json turns the ISO stamp in the Data blob into a DateTime, so the @@ -114,18 +121,20 @@ Describe 'Get-CIPPCVEReport' { ([datetime]$B.cacheTimeStamp).ToUniversalTime().Ticks | Should -Be ([datetime]::Parse('2026-08-12T00:00:00Z', [cultureinfo]::InvariantCulture, [System.Globalization.DateTimeStyles]::AdjustToUniversal)).Ticks } - It 'deduplicates devices by name within a row' { + It 'trusts the stored unique-device count rather than recounting fragments' { + # Dedupe now happens at write time, so the reader takes deviceCount as authoritative + # even if it differs from the number of device fragments present. Mock -CommandName Get-CIPPDbItem -MockWith { - New-CveRow -CveId 'CVE-A' -Devices @( - @{ deviceId = 'd1'; deviceName = 'PC-1'; osVersion = ''; softwareVersion = '1.0'; diskPaths = ''; registryPaths = '' } - @{ deviceId = 'd1'; deviceName = 'PC-1'; osVersion = ''; softwareVersion = '2.0'; diskPaths = ''; registryPaths = '' } + New-CveRow -CveId 'CVE-A' -DeviceCount 5 -Devices @( + @{ deviceId = 'd1'; deviceName = 'PC-1' } + @{ deviceId = 'd2'; deviceName = 'PC-2' } ) } $Result = @(Get-CIPPCVEReport -TenantFilter $script:Tenant) - $Result[0].deviceCount | Should -Be 1 - @($Result[0].affectedDevices).Count | Should -Be 1 + $Result[0].deviceCount | Should -Be 5 + @($Result[0].affectedDevices).Count | Should -Be 2 } It 'returns a bare empty array when the cache only holds the count row' { diff --git a/Tests/Private/Get-CIPPDbItemPage.Tests.ps1 b/Tests/Private/Get-CIPPDbItemPage.Tests.ps1 new file mode 100644 index 0000000000000..f69ce7e8ff37f --- /dev/null +++ b/Tests/Private/Get-CIPPDbItemPage.Tests.ps1 @@ -0,0 +1,84 @@ +# Pester tests for Get-CIPPDbItemPage +# Validates the reporting-database partition plan (count-row enumeration intersected with +# managed tenants, alphabetical), the single-tenant plan, the RowKey range handed to the +# walker, and count-marker removal. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + # Stub every helper the function calls so Pester's Mock has a command to replace. + function Get-CippTable { param($tablename) } + function Get-CIPPDbItem { param($TenantFilter, $Type, [switch]$CountsOnly) } + function Get-Tenants { param($TenantFilter, [switch]$IncludeErrors) } + function Get-CIPPPagedTableRows { + param($Table, $PartitionKeys, $RowKeyGe, $RowKeyLt, $ExtraFilterClauses, $PageSize, $MaxQueries, $ContinuationToken) + } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPDbItemPage.ps1') +} + +Describe 'Get-CIPPDbItemPage' { + BeforeEach { + Mock -CommandName Get-CippTable -MockWith { @{ Context = 'fake' } } + Mock -CommandName Get-CIPPDbItem -MockWith { @() } + Mock -CommandName Get-CIPPPagedTableRows -MockWith { + [PSCustomObject]@{ + Rows = [System.Collections.Generic.List[object]]@( + [PSCustomObject]@{ PartitionKey = 'alpha.onmicrosoft.com'; RowKey = 'Guests-1'; Data = '{}' } + [PSCustomObject]@{ PartitionKey = 'alpha.onmicrosoft.com'; RowKey = 'Guests-Count'; DataCount = 1 } + ) + NextToken = 'alpha.onmicrosoft.com|Guests-Count' + } + } + } + + It 'builds the AllTenants plan from count rows, managed tenants only, alphabetical' { + Mock -CommandName Get-CIPPDbItem -MockWith { + @( + [PSCustomObject]@{ PartitionKey = 'zeta.onmicrosoft.com'; RowKey = 'Guests-Count'; DataCount = 5 } + [PSCustomObject]@{ PartitionKey = 'alpha.onmicrosoft.com'; RowKey = 'Guests-Count'; DataCount = 2 } + # Has cached data but is no longer managed - must be excluded from the walk. + [PSCustomObject]@{ PartitionKey = 'gone.onmicrosoft.com'; RowKey = 'Guests-Count'; DataCount = 9 } + ) + } + Mock -CommandName Get-Tenants -MockWith { + @( + [PSCustomObject]@{ defaultDomainName = 'alpha.onmicrosoft.com' } + [PSCustomObject]@{ defaultDomainName = 'zeta.onmicrosoft.com' } + ) + } + + $Result = Get-CIPPDbItemPage -TenantFilter 'AllTenants' -Type 'Guests' -PageSize 500 -ContinuationToken 'tok' + + Should -Invoke Get-CIPPDbItem -Times 1 -ParameterFilter { $TenantFilter -eq 'allTenants' -and $Type -eq 'Guests' -and $CountsOnly } + Should -Invoke Get-CIPPPagedTableRows -Times 1 -ParameterFilter { + ($PartitionKeys -join ',') -eq 'alpha.onmicrosoft.com,zeta.onmicrosoft.com' -and + $RowKeyGe -eq 'Guests-' -and $RowKeyLt -eq 'Guests.' -and + $PageSize -eq 500 -and $ContinuationToken -eq 'tok' + } + # The count marker row is stripped; the data row and token pass through. + $Result.Items | Should -HaveCount 1 + $Result.Items[0].RowKey | Should -Be 'Guests-1' + $Result.NextToken | Should -Be 'alpha.onmicrosoft.com|Guests-Count' + } + + It 'walks a single tenant partition after normalizing the tenant filter' { + Mock -CommandName Get-Tenants -MockWith { + [PSCustomObject]@{ defaultDomainName = 'alpha.onmicrosoft.com' } + } + + $null = Get-CIPPDbItemPage -TenantFilter 'alpha.onmicrosoft.com' -Type 'Mailboxes' + + Should -Invoke Get-Tenants -Times 1 -ParameterFilter { $TenantFilter -eq 'alpha.onmicrosoft.com' } + Should -Invoke Get-CIPPDbItem -Times 0 + Should -Invoke Get-CIPPPagedTableRows -Times 1 -ParameterFilter { + ($PartitionKeys -join ',') -eq 'alpha.onmicrosoft.com' -and $RowKeyGe -eq 'Mailboxes-' -and $RowKeyLt -eq 'Mailboxes.' + } + } + + It 'throws when the single tenant cannot be resolved' { + Mock -CommandName Get-Tenants -MockWith { $null } + + { Get-CIPPDbItemPage -TenantFilter 'missing.example.com' -Type 'Guests' } | Should -Throw "*not found*" + } +} diff --git a/Tests/Private/Get-CIPPDriveItemCloudPathLength.Tests.ps1 b/Tests/Private/Get-CIPPDriveItemCloudPathLength.Tests.ps1 new file mode 100644 index 0000000000000..f517a9b9b8528 --- /dev/null +++ b/Tests/Private/Get-CIPPDriveItemCloudPathLength.Tests.ps1 @@ -0,0 +1,36 @@ +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPDriveItemCloudPathLength.ps1') +} + +Describe 'Get-CIPPDriveItemCloudPathLength' { + It 'returns name length for root children' { + Get-CIPPDriveItemCloudPathLength -ParentPath '/drives/b!abc/root:' -Name 'file.docx' | Should -Be 9 + } + + It 'includes nested folders after root:' { + # Folder/Sub/file.docx = 6+1+3+1+9 = 20 + Get-CIPPDriveItemCloudPathLength -ParentPath '/drives/b!abc/root:/Folder/Sub' -Name 'file.docx' | Should -Be 20 + } + + It 'URL-decodes before measuring' { + # "My Folder"/a.txt -> My Folder/a.txt = 9+1+5 = 15 + Get-CIPPDriveItemCloudPathLength -ParentPath '/drive/root:/My%20Folder' -Name 'a.txt' | Should -Be 15 + } + + It 'returns 0 for empty name' { + Get-CIPPDriveItemCloudPathLength -ParentPath '/drive/root:/X' -Name '' | Should -Be 0 + } +} + +Describe 'inferred local + cloud threshold' { + It 'combines tenant-fixed root length with UPN local-part and cloud path' { + $Org = 'Contoso' + $Fixed = ('C:\Users\').Length + ("\OneDrive - $Org\").Length + $LocalPart = 'user' + $Cloud = 250 + $Inferred = $Fixed + $LocalPart.Length + $Cloud + ($Inferred -gt 260) | Should -Be $true + ($Cloud -gt 400) | Should -Be $false + } +} diff --git a/Tests/Private/Get-CIPPGroupsReport.Tests.ps1 b/Tests/Private/Get-CIPPGroupsReport.Tests.ps1 new file mode 100644 index 0000000000000..f5183e523cb62 --- /dev/null +++ b/Tests/Private/Get-CIPPGroupsReport.Tests.ps1 @@ -0,0 +1,99 @@ +# Pester tests for Get-CIPPGroupsReport -AsRawJson +# Validates that a page is stitched from the stored blobs verbatim (no member array is +# ever deserialized), with per-row CacheTimestamp and (AllTenants only) Tenant spliced in. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + # Stub the helpers the exercised path touches so Pester's Mock has a command to replace. + function Get-CIPPDbItemPage { param($TenantFilter, $Type, $PageSize, $ContinuationToken) } + function Get-CIPPDbItem { param($TenantFilter, $Type) } + function Get-Tenants { param($TenantFilter, [switch]$IncludeErrors) } + function Write-LogMessage { param($API, $tenant, $message, $sev) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPGroupsReport.ps1') + + function New-GroupBlob { + param([string]$Id, [string[]]$Upns) + $members = @(foreach ($u in $Upns) { [PSCustomObject]@{ id = $u; userPrincipalName = $u } }) + [PSCustomObject]@{ + id = $Id + displayName = "Group $Id" + members = $members + membersCsv = ($Upns -join ',') + } | ConvertTo-Json -Depth 10 -Compress + } + + function New-PageItem { + param([string]$Tenant, [string]$Blob, $Timestamp) + [PSCustomObject]@{ PartitionKey = $Tenant; Timestamp = $Timestamp; Data = $Blob } + } +} + +Describe 'Get-CIPPGroupsReport -AsRawJson' { + It 'stitches blobs verbatim and splices Tenant + CacheTimestamp for AllTenants' { + $ts = [datetimeoffset]'2024-05-01T10:00:00Z' + $blobA = New-GroupBlob -Id 'g1' -Upns @('a@contoso.com', 'b@contoso.com') + $blobB = New-GroupBlob -Id 'g2' -Upns @('c@fabrikam.com') + $page = [PSCustomObject]@{ + Items = @( + (New-PageItem -Tenant 'contoso.onmicrosoft.com' -Blob $blobA -Timestamp $ts), + (New-PageItem -Tenant 'fabrikam.onmicrosoft.com' -Blob $blobB -Timestamp $ts) + ) + NextToken = 'fabrikam.onmicrosoft.com|Groups-xyz' + } + Mock -CommandName Get-CIPPDbItemPage -MockWith { $page }.GetNewClosure() + + $result = Get-CIPPGroupsReport -TenantFilter 'AllTenants' -PageSize 100 -AsRawJson + + $result.NextToken | Should -Be 'fabrikam.onmicrosoft.com|Groups-xyz' + # The stored blob (minus its closing brace) must appear byte-for-byte — proof the + # member array was streamed, not parsed and rebuilt. Literal Contains, not -BeLike: + # the members array's [ ] are wildcard metacharacters. + $result.CippPagedJson.Contains($blobA.Substring(0, $blobA.Length - 1)) | Should -BeTrue + + $parsed = $result.CippPagedJson | ConvertFrom-Json + $parsed | Should -HaveCount 2 + $parsed[0].members | Should -HaveCount 2 + $parsed[0].members[0].userPrincipalName | Should -Be 'a@contoso.com' + $parsed[0].membersCsv | Should -Be 'a@contoso.com,b@contoso.com' + $parsed[0].Tenant | Should -Be 'contoso.onmicrosoft.com' + $parsed[1].Tenant | Should -Be 'fabrikam.onmicrosoft.com' + $parsed[0].CacheTimestamp | Should -Not -BeNullOrEmpty + } + + It 'does not splice a Tenant field for a single-tenant read' { + $blob = New-GroupBlob -Id 'g1' -Upns @('a@contoso.com') + $page = [PSCustomObject]@{ + Items = @((New-PageItem -Tenant 'contoso.onmicrosoft.com' -Blob $blob -Timestamp ([datetimeoffset]::UtcNow))) + NextToken = $null + } + Mock -CommandName Get-CIPPDbItemPage -MockWith { $page }.GetNewClosure() + + $result = Get-CIPPGroupsReport -TenantFilter 'contoso.onmicrosoft.com' -PageSize 100 -AsRawJson + $parsed = $result.CippPagedJson | ConvertFrom-Json + + $parsed.PSObject.Properties.Name | Should -Not -Contain 'Tenant' + $parsed.CacheTimestamp | Should -Not -BeNullOrEmpty + $result.NextToken | Should -BeNullOrEmpty + } + + It 'skips empty or malformed blobs' { + $good = New-GroupBlob -Id 'g1' -Upns @('a@contoso.com') + $page = [PSCustomObject]@{ + Items = @( + (New-PageItem -Tenant 'contoso.onmicrosoft.com' -Blob '' -Timestamp ([datetimeoffset]::UtcNow)), + (New-PageItem -Tenant 'contoso.onmicrosoft.com' -Blob ' ' -Timestamp ([datetimeoffset]::UtcNow)), + (New-PageItem -Tenant 'contoso.onmicrosoft.com' -Blob $good -Timestamp ([datetimeoffset]::UtcNow)) + ) + NextToken = $null + } + Mock -CommandName Get-CIPPDbItemPage -MockWith { $page }.GetNewClosure() + + $result = Get-CIPPGroupsReport -TenantFilter 'AllTenants' -PageSize 100 -AsRawJson + $parsed = @($result.CippPagedJson | ConvertFrom-Json) + + $parsed | Should -HaveCount 1 + $parsed[0].id | Should -Be 'g1' + } +} diff --git a/Tests/Private/Get-CIPPLicenseOptimization.Tests.ps1 b/Tests/Private/Get-CIPPLicenseOptimization.Tests.ps1 new file mode 100644 index 0000000000000..40c1879f2da09 --- /dev/null +++ b/Tests/Private/Get-CIPPLicenseOptimization.Tests.ps1 @@ -0,0 +1,158 @@ +# Pester tests for Get-CIPPLicenseOptimization — the five-tier waste join and summary math. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Get-CIPPLicenseOptimization.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $FunctionPath) { throw 'Could not locate Get-CIPPLicenseOptimization.ps1 under Modules/' } + + function Get-CIPPLicensePrice { param($SkuId) } + function New-CIPPDbRequest { param($TenantFilter, $Type, $Fields) } + + . $FunctionPath + + # SKU GUIDs + $script:E5 = 'c7df2760-2c81-4ef7-b578-5b5392b571df' + $script:E3 = '6fd2c87f-b296-42f0-b197-1e91e994b900' + $script:ExP1 = '4b9405b0-7788-4568-add1-99614e613b69' + $script:ExP2 = '19ec0d23-8335-4cbd-94ac-6050e30712fa' + + function New-Lic { param($SkuId, $Name, $Total, $Used, $PlanIds) + [pscustomobject]@{ + skuId = $SkuId + License = $Name + TotalLicenses = "$Total" + CountUsed = "$Used" + ServicePlans = @($PlanIds | ForEach-Object { [pscustomobject]@{ servicePlanId = $_ } }) + } + } + function New-User { param($Upn, $Enabled, $LastSignIn, $Skus, $Type = 'Member', $Resource = $false) + [pscustomobject]@{ + userPrincipalName = $Upn + accountEnabled = $Enabled + userType = $Type + isResourceAccount = $Resource + signInActivity = if ($LastSignIn) { [pscustomobject]@{ lastSignInDateTime = $LastSignIn; lastNonInteractiveSignInDateTime = $null } } else { $null } + assignedLicenses = @($Skus | ForEach-Object { [pscustomobject]@{ skuId = $_; disabledPlans = @() } }) + } + } +} + +Describe 'Get-CIPPLicenseOptimization' { + BeforeEach { + Mock -CommandName Get-CIPPLicensePrice -MockWith { + @( + [pscustomobject]@{ skuId = $script:E5; Product_Display_Name = 'Office 365 E5'; MonthlyPrice = 38.0; Currency = 'USD'; Source = 'Estimate' } + [pscustomobject]@{ skuId = $script:E3; Product_Display_Name = 'Office 365 E3'; MonthlyPrice = 23.0; Currency = 'USD'; Source = 'Estimate' } + [pscustomobject]@{ skuId = $script:ExP1; Product_Display_Name = 'Exchange Online (Plan 1)'; MonthlyPrice = 4.0; Currency = 'USD'; Source = 'Estimate' } + [pscustomobject]@{ skuId = $script:ExP2; Product_Display_Name = 'Exchange Online (Plan 2)'; MonthlyPrice = 8.0; Currency = 'USD'; Source = 'Estimate' } + ) + } + + $script:Recent = (Get-Date).AddDays(-5).ToString('o') + $script:Old = (Get-Date).AddDays(-200).ToString('o') + + # E3 plan set is a strict superset of Exchange P1's -> P1 is redundant when held together. + $script:Licenses = @( + New-Lic $script:E5 'Office 365 E5' 10 8 @('EXCH1', 'SPO', 'TEAMS') + New-Lic $script:E3 'Office 365 E3' 5 5 @('EXCH1', 'SPO', 'TEAMS') + New-Lic $script:ExP1 'Exchange Online (Plan 1)' 3 2 @('EXCH1') + ) + $script:Users = @( + New-User 'u1@contoso.com' $true $script:Recent @($script:E5) # tier4: exchange-only on E5 + New-User 'u2@contoso.com' $false $script:Recent @($script:E5) # tier2: disabled + New-User 'u3@contoso.com' $true $script:Old @($script:E3) # tier3: inactive + New-User 'u4@contoso.com' $true $script:Recent @($script:E3, $script:ExP1) # tier5: overlap + New-User 'guest@ext.com' $true $script:Recent @($script:E5) 'Guest' # excluded + New-User 'room@contoso.com' $true $script:Recent @($script:E5) 'Member' $true # excluded (resource) + ) + # u1 mailbox-only; u4 uses collaboration too (so not a downgrade candidate) + $script:Activity = @( + [pscustomobject]@{ userPrincipalName = 'u1@contoso.com'; exchangeLastActivityDate = $script:Recent; oneDriveLastActivityDate = ''; sharePointLastActivityDate = ''; teamsLastActivityDate = ''; yammerLastActivityDate = '' } + [pscustomobject]@{ userPrincipalName = 'u4@contoso.com'; exchangeLastActivityDate = $script:Recent; oneDriveLastActivityDate = $script:Recent; sharePointLastActivityDate = ''; teamsLastActivityDate = $script:Recent; yammerLastActivityDate = '' } + ) + } + + It 'computes the monthly spend from assigned seats x price' { + $Report = Get-CIPPLicenseOptimization -TenantFilter 'contoso.com' -Licenses $script:Licenses -Users $script:Users -ActivityDetail $script:Activity + # 8*38 + 5*23 + 2*4 = 427 + $Report.Summary.MonthlySpend | Should -Be 427.0 + $Report.Summary.PriceCoverage | Should -Be 1 + } + + It 'flags unassigned seats (tier 1) with per-seat pricing' { + $Report = Get-CIPPLicenseOptimization -TenantFilter 'contoso.com' -Licenses $script:Licenses -Users $script:Users -ActivityDetail $script:Activity + $Opp = $Report.Opportunities | Where-Object { $_.Tier -eq 'UnassignedSeats' -and $_.skuId -eq $script:E5 } + $Opp.Seats | Should -Be 2 + $Opp.MonthlySaving | Should -Be 76.0 + } + + It 'flags a disabled account (tier 2)' { + $Report = Get-CIPPLicenseOptimization -TenantFilter 'contoso.com' -Licenses $script:Licenses -Users $script:Users -ActivityDetail $script:Activity + $Opp = $Report.Opportunities | Where-Object { $_.Tier -eq 'DisabledAccount' } + $Opp.Seats | Should -Be 1 + $Opp.MonthlySaving | Should -Be 38.0 + $Opp.Users | Should -Contain 'u2@contoso.com' + } + + It 'flags an inactive account (tier 3)' { + $Report = Get-CIPPLicenseOptimization -TenantFilter 'contoso.com' -Licenses $script:Licenses -Users $script:Users -ActivityDetail $script:Activity + $Opp = $Report.Opportunities | Where-Object { $_.Tier -eq 'Inactive' } + $Opp.Seats | Should -Be 1 + $Opp.MonthlySaving | Should -Be 23.0 + $Opp.Users | Should -Contain 'u3@contoso.com' + } + + It 'flags a mailbox-only premium user for review (tier 4) without claiming a saving' { + $Report = Get-CIPPLicenseOptimization -TenantFilter 'contoso.com' -Licenses $script:Licenses -Users $script:Users -ActivityDetail $script:Activity + $Opp = $Report.Opportunities | Where-Object { $_.Tier -eq 'Downgrade' } + $Opp.Seats | Should -Be 1 + # Review only: no monetary saving is claimed, but the SKU itself is priced (E5). + $Opp.MonthlySaving | Should -Be 0 + $Opp.UnitCost | Should -Be 38.0 + $Opp.PriceKnown | Should -BeTrue + $Opp.Users | Should -Contain 'u1@contoso.com' + } + + It 'flags a redundant overlapping SKU (tier 5)' { + $Report = Get-CIPPLicenseOptimization -TenantFilter 'contoso.com' -Licenses $script:Licenses -Users $script:Users -ActivityDetail $script:Activity + $Opp = $Report.Opportunities | Where-Object { $_.Tier -eq 'Overlap' } + $Opp.skuId | Should -Be $script:ExP1 + $Opp.Seats | Should -Be 1 + $Opp.MonthlySaving | Should -Be 4.0 + } + + It 'totals reclaimable spend and reclaimable seats' { + $Report = Get-CIPPLicenseOptimization -TenantFilter 'contoso.com' -Licenses $script:Licenses -Users $script:Users -ActivityDetail $script:Activity + # 76 (t1 E5) + 4 (t1 ExP1) + 38 (t2) + 23 (t3) + 0 (t4 review) + 4 (t5) = 145 + $Report.Summary.ReclaimableMonthly | Should -Be 145.0 + # tiers 1-3 seats only: (2+1) + 1 + 1 = 5 + $Report.Summary.ReclaimableSeats | Should -Be 5 + $Report.Summary.AnonymizedReports | Should -BeFalse + } + + It 'excludes guests and resource accounts from per-user tiers' { + $Report = Get-CIPPLicenseOptimization -TenantFilter 'contoso.com' -Licenses $script:Licenses -Users $script:Users -ActivityDetail $script:Activity + $AllUsers = @($Report.Opportunities.Users) + $AllUsers | Should -Not -Contain 'guest@ext.com' + $AllUsers | Should -Not -Contain 'room@contoso.com' + } + + It 'marks unpriced SKUs as PriceKnown false with zero saving' { + $NoPriceLic = @(New-Lic '00000000-0000-0000-0000-000000000000' 'Mystery SKU' 4 2 @('X')) + $Report = Get-CIPPLicenseOptimization -TenantFilter 'contoso.com' -Licenses $NoPriceLic -Users @() -ActivityDetail @() + $Opp = $Report.Opportunities | Where-Object { $_.Tier -eq 'UnassignedSeats' } + $Opp.PriceKnown | Should -BeFalse + $Opp.UnitCost | Should -BeNullOrEmpty + $Opp.MonthlySaving | Should -Be 0 + $Opp.Seats | Should -Be 2 + } + + It 'detects anonymized usage reports when activity UPNs do not match users' { + $AnonActivity = @( + [pscustomobject]@{ userPrincipalName = 'AB6E27EA1F9A4C00'; exchangeLastActivityDate = $script:Recent; oneDriveLastActivityDate = ''; sharePointLastActivityDate = ''; teamsLastActivityDate = ''; yammerLastActivityDate = '' } + ) + $Report = Get-CIPPLicenseOptimization -TenantFilter 'contoso.com' -Licenses $script:Licenses -Users $script:Users -ActivityDetail $AnonActivity + $Report.Summary.AnonymizedReports | Should -BeTrue + } +} diff --git a/Tests/Private/Get-CIPPLicensePrice.Tests.ps1 b/Tests/Private/Get-CIPPLicensePrice.Tests.ps1 new file mode 100644 index 0000000000000..5f768c16f6c9a --- /dev/null +++ b/Tests/Private/Get-CIPPLicensePrice.Tests.ps1 @@ -0,0 +1,151 @@ +# Pester tests for Get-CIPPLicensePrice — estimates from CSV, overrides win, unknown SKUs. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Get-CIPPLicensePrice.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $FunctionPath) { throw 'Could not locate Get-CIPPLicensePrice.ps1 under Modules/' } + + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Filter, $Property) } + + . $FunctionPath + + # The function joins $env:CIPPRootPath to locate the defaults CSV; the CSV read itself is + # mocked, so any non-empty base path is enough to get past Join-Path. + $script:SavedRoot = $env:CIPPRootPath + $env:CIPPRootPath = "$TestDrive" + + # SKU GUIDs used across the cases + $script:E5 = '06ebc4ee-1bb5-47dd-8120-11324bc54e06' + $script:E3 = '6fd2c87f-b296-42f0-b197-1e91e994b900' +} + +AfterAll { + $env:CIPPRootPath = $script:SavedRoot +} + +Describe 'Get-CIPPLicensePrice' { + BeforeEach { + Mock -CommandName Test-Path -MockWith { $true } + Mock -CommandName Import-Csv -MockWith { + @( + [pscustomobject]@{ skuId = $script:E5; skuPartNumber = 'ENTERPRISEPREMIUM'; Product_Display_Name = 'Office 365 E5'; MonthlyPrice = '38.00'; Currency = 'USD' } + [pscustomobject]@{ skuId = $script:E3; skuPartNumber = 'ENTERPRISEPACK'; Product_Display_Name = 'Office 365 E3'; MonthlyPrice = '23.00'; Currency = 'USD' } + ) + } + Mock -CommandName Get-CIPPTable -MockWith { @{ Context = 'fake' } } + # Default: no overrides + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { @() } + } + + It 'returns the shipped estimate when no override exists' { + $Result = Get-CIPPLicensePrice -SkuId $script:E5 + + $Result.MonthlyPrice | Should -Be 38.00 + $Result.Source | Should -Be 'Estimate' + $Result.Currency | Should -Be 'USD' + } + + It 'lets an override win over the estimate' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + @([pscustomobject]@{ PartitionKey = 'Price'; RowKey = $script:E5; skuId = $script:E5; skuPartNumber = 'ENTERPRISEPREMIUM'; Product_Display_Name = 'Office 365 E5'; MonthlyPrice = 30.0; Currency = 'USD' }) + } + + $Result = Get-CIPPLicensePrice -SkuId $script:E5 + + $Result.MonthlyPrice | Should -Be 30.0 + $Result.Source | Should -Be 'Override' + } + + It 'returns Source Unknown with a null price for an unknown SKU' { + $Result = Get-CIPPLicensePrice -SkuId '00000000-0000-0000-0000-000000000000' + + $Result.Source | Should -Be 'Unknown' + $Result.MonthlyPrice | Should -BeNullOrEmpty + } + + It 'is case-insensitive on the requested SKU GUID' { + $Result = Get-CIPPLicensePrice -SkuId $script:E5.ToUpper() + + $Result.Source | Should -Be 'Estimate' + $Result.MonthlyPrice | Should -Be 38.00 + } + + It 'returns every known SKU when no SkuId is given' { + $Result = @(Get-CIPPLicensePrice) + + $Result.Count | Should -Be 2 + ($Result.skuId | Sort-Object) | Should -Be (@($script:E3, $script:E5) | Sort-Object) + } + + It 'merges an override-only SKU into the full list' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + @([pscustomobject]@{ PartitionKey = 'Price'; RowKey = 'aaaa1111-2222-3333-4444-555566667777'; skuId = 'aaaa1111-2222-3333-4444-555566667777'; skuPartNumber = 'CUSTOM'; Product_Display_Name = 'Custom SKU'; MonthlyPrice = 5.0; Currency = 'USD' }) + } + + $Result = @(Get-CIPPLicensePrice) + + $Result.Count | Should -Be 3 + ($Result | Where-Object { $_.skuId -eq 'aaaa1111-2222-3333-4444-555566667777' }).Source | Should -Be 'Override' + } +} + +Describe 'Get-CIPPLicensePrice - multi-currency' { + BeforeEach { + Mock -CommandName Test-Path -MockWith { $true } + # E5 priced in USD and AUD; E3 in USD only + Mock -CommandName Import-Csv -MockWith { + @( + [pscustomobject]@{ skuId = $script:E5; skuPartNumber = 'ENTERPRISEPREMIUM'; Product_Display_Name = 'Office 365 E5'; MonthlyPrice = '38.00'; Currency = 'USD' } + [pscustomobject]@{ skuId = $script:E5; skuPartNumber = 'ENTERPRISEPREMIUM'; Product_Display_Name = 'Office 365 E5'; MonthlyPrice = '60.00'; Currency = 'AUD' } + [pscustomobject]@{ skuId = $script:E3; skuPartNumber = 'ENTERPRISEPACK'; Product_Display_Name = 'Office 365 E3'; MonthlyPrice = '23.00'; Currency = 'USD' } + ) + } + Mock -CommandName Get-CIPPTable -MockWith { @{ Context = 'fake' } } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { @() } + } + + It 'resolves the price in the requested currency' { + $Result = Get-CIPPLicensePrice -SkuId $script:E5 -Currency 'AUD' + + $Result.MonthlyPrice | Should -Be 60.00 + $Result.Currency | Should -Be 'AUD' + $Result.Source | Should -Be 'Estimate' + } + + It 'reports Unknown (no cross-currency fallback) when the SKU lacks the requested currency' { + $Result = Get-CIPPLicensePrice -SkuId $script:E3 -Currency 'AUD' + + $Result.Source | Should -Be 'Unknown' + $Result.MonthlyPrice | Should -BeNullOrEmpty + # SKU metadata is still surfaced so the row remains identifiable + $Result.skuPartNumber | Should -Be 'ENTERPRISEPACK' + } + + It 'omits SKUs with no price in the requested currency from the full list' { + $Result = @(Get-CIPPLicensePrice -Currency 'AUD') + + $Result.Count | Should -Be 1 + ($Result | Where-Object { $_.skuId -eq $script:E3 }) | Should -BeNullOrEmpty + ($Result | Where-Object { $_.skuId -eq $script:E5 }).MonthlyPrice | Should -Be 60.00 + } + + It 'lists the distinct currencies present' { + $Result = @(Get-CIPPLicensePrice -ListCurrencies) + + $Result | Should -Be @('AUD', 'USD') + } + + It 'scopes an override to its currency' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + @([pscustomobject]@{ PartitionKey = 'Price'; RowKey = "$($script:E5)-aud"; skuId = $script:E5; skuPartNumber = 'ENTERPRISEPREMIUM'; Product_Display_Name = 'Office 365 E5'; MonthlyPrice = 55.0; Currency = 'AUD' }) + } + + (Get-CIPPLicensePrice -SkuId $script:E5 -Currency 'AUD').MonthlyPrice | Should -Be 55.0 + (Get-CIPPLicensePrice -SkuId $script:E5 -Currency 'AUD').Source | Should -Be 'Override' + # USD is untouched by the AUD override + (Get-CIPPLicensePrice -SkuId $script:E5 -Currency 'USD').MonthlyPrice | Should -Be 38.00 + (Get-CIPPLicensePrice -SkuId $script:E5 -Currency 'USD').Source | Should -Be 'Estimate' + } +} diff --git a/Tests/Private/Get-CIPPPagedTableRows.Tests.ps1 b/Tests/Private/Get-CIPPPagedTableRows.Tests.ps1 new file mode 100644 index 0000000000000..c458192a23f83 --- /dev/null +++ b/Tests/Private/Get-CIPPPagedTableRows.Tests.ps1 @@ -0,0 +1,200 @@ +# Pester tests for Get-CIPPPagedTableRows +# Validates the cross-partition range-scan pager: row-count paging independent of how many +# partitions the data spans, continuation token round-trips (including escaping), plan +# membership filtering, and the query-count economy that motivated the range design. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + # Stub so Pester's Mock has a command to replace. + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property, $First) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/ConvertTo-CIPPODataFilterValue.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPPagedTableRows.ps1') + + # In-memory table emulation for the filter shapes the pager emits (PK/RK ranges, the + # OR resume clause, ordinal ordering, -First). Test keys never contain quotes. + function Select-FakeRows { + param([object[]]$Rows, [string]$Filter, $First) + $PkGe = if ($Filter -match "PartitionKey ge '([^']*)'") { $Matches[1] } else { $null } + $PkLe = if ($Filter -match "PartitionKey le '([^']*)'") { $Matches[1] } else { $null } + $RkGe = if ($Filter -match "RowKey ge '([^']*)'") { $Matches[1] } else { $null } + $RkLt = if ($Filter -match "RowKey lt '([^']*)'") { $Matches[1] } else { $null } + $Resume = if ($Filter -match "\(\(PartitionKey gt '([^']*)'\) or \(PartitionKey eq '[^']*' and RowKey gt '([^']*)'\)\)") { + @{ Pk = $Matches[1]; Rk = $Matches[2] } + } else { $null } + $Out = @($Rows | Where-Object { + $Row = $_ + $Keep = (-not $PkGe -or [string]::CompareOrdinal($Row.PartitionKey, $PkGe) -ge 0) -and + (-not $PkLe -or [string]::CompareOrdinal($Row.PartitionKey, $PkLe) -le 0) -and + (-not $RkGe -or [string]::CompareOrdinal($Row.RowKey, $RkGe) -ge 0) -and + (-not $RkLt -or [string]::CompareOrdinal($Row.RowKey, $RkLt) -lt 0) + if ($Keep -and $Resume) { + $Keep = ([string]::CompareOrdinal($Row.PartitionKey, $Resume.Pk) -gt 0) -or + ($Row.PartitionKey -ceq $Resume.Pk -and [string]::CompareOrdinal($Row.RowKey, $Resume.Rk) -gt 0) + } + $Keep + } | Sort-Object -Property @{ Expression = { $_.PartitionKey }; Ascending = $true }, @{ Expression = { $_.RowKey }; Ascending = $true }) + if ($First) { $Out = @($Out | Select-Object -First ([int]$First)) } + $Out + } + + function New-FakeRow { + param([string]$Pk, [string]$Rk) + [PSCustomObject]@{ PartitionKey = $Pk; RowKey = $Rk; Data = "$Pk/$Rk" } + } +} + +Describe 'Get-CIPPPagedTableRows' { + BeforeEach { + $script:FakeRows = @() + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + Select-FakeRows -Rows $script:FakeRows -Filter $Filter -First $First + } + } + + It 'walks partitions in ordinal order and completes with a null token when everything fits' { + $script:FakeRows = @( + New-FakeRow 'tenantB' 'Guests-2' + New-FakeRow 'tenantA' 'Guests-1' + New-FakeRow 'tenantB' 'Guests-1' + ) + + $Page = Get-CIPPPagedTableRows -Table @{ Context = 'fake' } -PartitionKeys @('tenantA', 'tenantB') -PageSize 100 + + $Page.Rows | Should -HaveCount 3 + $Page.Rows[0].Data | Should -Be 'tenantA/Guests-1' + $Page.Rows[1].Data | Should -Be 'tenantB/Guests-1' + $Page.Rows[2].Data | Should -Be 'tenantB/Guests-2' + $Page.NextToken | Should -BeNullOrEmpty + } + + It 'pages many small partitions in one page with a bounded query count' { + # The complaint this design answers: row-count paging must not degrade with the + # partition count. 60 one-row tenants fit one 100-row page in a couple of queries. + $script:FakeRows = foreach ($i in 1..60) { + New-FakeRow ('tenant{0:D3}' -f $i) 'Users-1' + } + $Plan = @(1..60 | ForEach-Object { 'tenant{0:D3}' -f $_ }) + + $Page = Get-CIPPPagedTableRows -Table @{ Context = 'fake' } -PartitionKeys $Plan -PageSize 100 + + $Page.Rows | Should -HaveCount 60 + $Page.NextToken | Should -BeNullOrEmpty + Should -Invoke Get-CIPPAzDataTableEntity -Times 2 -Exactly + } + + It 'returns full coverage without duplicates when paging with continuation tokens' { + $script:FakeRows = foreach ($Tenant in 'tenantA', 'tenantB') { + foreach ($i in 1..5) { New-FakeRow $Tenant ('Users-{0:D2}' -f $i) } + } + + $Collected = [System.Collections.Generic.List[string]]::new() + $Token = $null + $Pages = 0 + do { + $Page = Get-CIPPPagedTableRows -Table @{ Context = 'fake' } -PartitionKeys @('tenantA', 'tenantB') -PageSize 3 -ContinuationToken $Token + foreach ($Row in $Page.Rows) { $Collected.Add($Row.Data) } + $Token = $Page.NextToken + $Pages++ + } while ($Token -and $Pages -lt 20) + + $Pages | Should -BeLessThan 20 + $Collected | Should -HaveCount 10 + ($Collected | Sort-Object -Unique) | Should -HaveCount 10 + $Collected[0] | Should -Be 'tenantA/Users-01' + $Collected[-1] | Should -Be 'tenantB/Users-05' + } + + It 'applies the RowKey range bounds' { + $script:FakeRows = @( + New-FakeRow 'tenantA' 'Groups-1' + New-FakeRow 'tenantA' 'Guests-1' + New-FakeRow 'tenantA' 'Guests-Count' + New-FakeRow 'tenantA' 'Mailboxes-1' + ) + + $Page = Get-CIPPPagedTableRows -Table @{ Context = 'fake' } -PartitionKeys @('tenantA') -RowKeyGe 'Guests-' -RowKeyLt 'Guests.' -PageSize 100 + + # Only the Guests-* range: no Groups, no Mailboxes. The count marker is inside the + # range by design; callers remove it. + $Page.Rows.RowKey | Should -Be @('Guests-1', 'Guests-Count') + } + + It 'drops rows from partitions outside the plan but keeps advancing the cursor' { + # gone.example sits ordinally between the plan tenants and floods the range with + # rows; they must be filtered out without stalling or re-reading. + $script:FakeRows = @(New-FakeRow 'aaa.example' 'Users-1') + + @(foreach ($i in 1..6) { New-FakeRow 'gone.example' ('Users-{0}' -f $i) }) + + @(New-FakeRow 'zzz.example' 'Users-1') + + $Collected = [System.Collections.Generic.List[string]]::new() + $Token = $null + $Pages = 0 + do { + $Page = Get-CIPPPagedTableRows -Table @{ Context = 'fake' } -PartitionKeys @('aaa.example', 'zzz.example') -PageSize 3 -ContinuationToken $Token + foreach ($Row in $Page.Rows) { $Collected.Add($Row.Data) } + $Token = $Page.NextToken + $Pages++ + } while ($Token -and $Pages -lt 10) + + $Collected | Should -Be @('aaa.example/Users-1', 'zzz.example/Users-1') + } + + It 'ends a short page with a token when MaxQueries runs out before PageSize' { + # Every chunk is full of non-plan rows, so kept rows stay short of PageSize and + # the safety bound has to end the page with resumable progress. + $script:FakeRows = @(foreach ($i in 1..9) { New-FakeRow 'gone.example' ('Users-{0}' -f $i) }) + + @(New-FakeRow 'zzz.example' 'Users-1') + + $Page1 = Get-CIPPPagedTableRows -Table @{ Context = 'fake' } -PartitionKeys @('aaa.example', 'zzz.example') -PageSize 3 -MaxQueries 2 + $Page1.Rows | Should -HaveCount 0 + $Page1.NextToken | Should -Not -BeNullOrEmpty + + # Chaining the short pages still reaches everything exactly once. + $Collected = [System.Collections.Generic.List[string]]::new() + $Token = $Page1.NextToken + $Pages = 1 + do { + $Page = Get-CIPPPagedTableRows -Table @{ Context = 'fake' } -PartitionKeys @('aaa.example', 'zzz.example') -PageSize 3 -MaxQueries 2 -ContinuationToken $Token + foreach ($Row in $Page.Rows) { $Collected.Add($Row.Data) } + $Token = $Page.NextToken + $Pages++ + } while ($Token -and $Pages -lt 10) + + $Pages | Should -BeLessThan 10 + $Collected | Should -Be @('zzz.example/Users-1') + } + + It 'round-trips tokens whose keys contain the separator and non-ASCII characters' { + $script:FakeRows = @( + New-FakeRow 'tenant|pipe' 'Users-aä' + New-FakeRow 'tenant|pipe' 'Users-b' + ) + + $Page1 = Get-CIPPPagedTableRows -Table @{ Context = 'fake' } -PartitionKeys @('tenant|pipe') -PageSize 1 + $Page1.Rows | Should -HaveCount 1 + $Page1.Rows[0].RowKey | Should -Be 'Users-aä' + $Page1.NextToken | Should -Not -BeNullOrEmpty + + $Page2 = Get-CIPPPagedTableRows -Table @{ Context = 'fake' } -PartitionKeys @('tenant|pipe') -PageSize 1 -ContinuationToken $Page1.NextToken + $Page2.Rows | Should -HaveCount 1 + $Page2.Rows[0].RowKey | Should -Be 'Users-b' + } + + It 'ANDs extra filter clauses onto every query' { + $script:FakeRows = @(New-FakeRow 'tenantA' 'Users-1') + + $null = Get-CIPPPagedTableRows -Table @{ Context = 'fake' } -PartitionKeys @('tenantA') -PageSize 10 -ExtraFilterClauses @("Severity eq 'Error'") + + Should -Invoke Get-CIPPAzDataTableEntity -ParameterFilter { $Filter -like "*and Severity eq 'Error'" } + } + + It 'returns an empty completed page for an empty partition plan' { + $Page = Get-CIPPPagedTableRows -Table @{ Context = 'fake' } -PartitionKeys @() -PageSize 10 + + $Page.Rows | Should -HaveCount 0 + $Page.NextToken | Should -BeNullOrEmpty + Should -Invoke Get-CIPPAzDataTableEntity -Times 0 + } +} diff --git a/Tests/Private/Get-CIPPSharePointCopyJobProgress.Tests.ps1 b/Tests/Private/Get-CIPPSharePointCopyJobProgress.Tests.ps1 new file mode 100644 index 0000000000000..1a3bdb55aca66 --- /dev/null +++ b/Tests/Private/Get-CIPPSharePointCopyJobProgress.Tests.ps1 @@ -0,0 +1,205 @@ +# Pester tests for Get-CIPPSharePointCopyJobProgress sanitization + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPSharePointCopyJobProgress.ps1' + $QueuePath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPSharePointCopyJobQueueLogs.ps1' + if (-not (Test-Path $FunctionPath)) { throw "Could not locate $FunctionPath" } + if (-not (Test-Path $QueuePath)) { throw "Could not locate $QueuePath" } + + function Get-SharePointAdminLink { param($Public, $tenantFilter) [PSCustomObject]@{ SharePointUrl = 'https://contoso.sharepoint.com' } } + function New-GraphPOSTRequest { param($uri, $tenantid, $body) } + + . $QueuePath + . $FunctionPath +} + +Describe 'Get-CIPPSharePointCopyJobProgress' { + It 'aggregates errors without returning raw log paths' { + Mock New-GraphPOSTRequest { + [PSCustomObject]@{ + d = [PSCustomObject]@{ + GetCopyJobProgress = [PSCustomObject]@{ + JobState = 0 + Logs = @( + '{"Event":"JobError","Url":"/sites/x/secret/file.docx","Message":"failed"}' + '{"Event":"JobProgress","ObjectsProcessed":10,"TotalExpectedSPObjects":20,"TotalErrors":1}' + ) + } + } + } + } + Mock Get-CIPPSharePointCopyJobQueueLogs { @() } + + $Result = Get-CIPPSharePointCopyJobProgress -TenantFilter 'contoso.com' -SourceSiteUrl 'https://contoso.sharepoint.com/sites/a' -CopyJobInfo @{ + JobId = 'job-1'; JobQueueUri = 'https://queue'; EncryptionKey = 'key' + } + + $Result.TotalErrors | Should -BeGreaterThan 0 + $Result.ErrorMessages.Count | Should -BeGreaterThan 0 + $Result | Get-Member -Name Url | Should -BeNullOrEmpty + ($Result | ConvertTo-Json) | Should -Not -Match 'secret/file' + ($Result.ErrorMessages -join ' ') | Should -Not -Match 'secret/file' + } + + It 'reads OData verbose Logs.results and Event-based job errors' { + Mock New-GraphPOSTRequest { + [PSCustomObject]@{ + d = [PSCustomObject]@{ + GetCopyJobProgress = [PSCustomObject]@{ + JobState = 0 + Logs = [PSCustomObject]@{ + results = @( + '{"Event":"JobEnd","TotalErrors":1}' + '{"Event":"JobError","ObjectType":"File","ErrorType":"Microsoft.SharePoint.SPException","ErrorCode":"-2147024816","Message":"Access denied."}' + ) + } + } + } + } + } + Mock Get-CIPPSharePointCopyJobQueueLogs { @() } + + $Result = Get-CIPPSharePointCopyJobProgress -TenantFilter 'contoso.com' -SourceSiteUrl 'https://contoso.sharepoint.com/sites/a' -CopyJobInfo @{ + JobId = 'job-2'; JobQueueUri = 'https://queue'; EncryptionKey = 'key' + } + + $Result.TotalErrors | Should -BeGreaterThan 0 + ($Result.ErrorMessages -join ' ') | Should -Match 'Access denied' + ($Result.ErrorMessages -join ' ') | Should -Match 'File' + } + + It 'falls back to Azure queue logs when REST logs omit JobError detail' { + Mock New-GraphPOSTRequest { + [PSCustomObject]@{ + d = [PSCustomObject]@{ + GetCopyJobProgress = [PSCustomObject]@{ + JobState = 0 + Logs = @('{"Event":"JobEnd","TotalErrors":1}') + } + } + } + } + Mock Get-CIPPSharePointCopyJobQueueLogs { + @([PSCustomObject]@{ + Event = 'JobError' + ObjectType = 'File' + Message = 'Access denied.' + ErrorCode = '-2147024816' + }) + } + + $Result = Get-CIPPSharePointCopyJobProgress -TenantFilter 'contoso.com' -SourceSiteUrl 'https://contoso.sharepoint.com/sites/a' -CopyJobInfo @{ + JobId = 'job-3'; JobQueueUri = 'https://queue.example/messages?sas=1'; EncryptionKey = 'key' + } + + ($Result.ErrorMessages -join ' ') | Should -Match 'Access denied' + } + + It 'sanitizes path-like content from error messages' { + Mock New-GraphPOSTRequest { + [PSCustomObject]@{ + d = [PSCustomObject]@{ + GetCopyJobProgress = [PSCustomObject]@{ + JobState = 0 + Logs = @( + '{"Event":"JobError","Message":"Could not copy /sites/hr/Shared Documents/report.docx because access denied"}' + ) + } + } + } + } + Mock Get-CIPPSharePointCopyJobQueueLogs { @() } + + $Result = Get-CIPPSharePointCopyJobProgress -TenantFilter 'contoso.com' -SourceSiteUrl 'https://contoso.sharepoint.com/sites/a' -CopyJobInfo @{ + JobId = 'job-sanitize'; JobQueueUri = 'https://queue'; EncryptionKey = 'key' + } + + ($Result.ErrorMessages -join ' ') | Should -Not -Match 'Shared Documents' + ($Result.ErrorMessages -join ' ') | Should -Not -Match 'report\.docx' + ($Result.ErrorMessages -join ' ') | Should -Match 'access denied' + } + + It 'sends copyJobInfo wrapper in GetCopyJobProgress POST body' { + $script:CapturedBody = $null + Mock New-GraphPOSTRequest { + param($body) + $script:CapturedBody = $body + [PSCustomObject]@{ + d = [PSCustomObject]@{ + GetCopyJobProgress = [PSCustomObject]@{ + JobState = 0 + Logs = @() + } + } + } + } + Mock Get-CIPPSharePointCopyJobQueueLogs { @() } + + $null = Get-CIPPSharePointCopyJobProgress -TenantFilter 'contoso.com' -SourceSiteUrl 'https://contoso.sharepoint.com/sites/a' -CopyJobInfo @{ + JobId = 'job-body'; JobQueueUri = 'https://queue'; EncryptionKey = 'key' + } + + $ParsedBody = $script:CapturedBody | ConvertFrom-Json + $ParsedBody.copyJobInfo.JobId | Should -Be 'job-body' + $ParsedBody.copyJobInfo.JobQueueUri | Should -Be 'https://queue' + $ParsedBody.copyJobInfo.EncryptionKey | Should -Be 'key' + $ParsedBody.copyJobInfo.__metadata.type | Should -Be 'SP.CopyMigrationInfo' + } + + It 'unwraps OData collection wrappers stored as CopyJobInfo' { + $script:CapturedBody = $null + Mock New-GraphPOSTRequest { + param($body) + $script:CapturedBody = $body + [PSCustomObject]@{ + d = [PSCustomObject]@{ + GetCopyJobProgress = [PSCustomObject]@{ + JobState = 0 + Logs = @('{"Event":"JobEnd","TotalErrors":0}') + } + } + } + } + Mock Get-CIPPSharePointCopyJobQueueLogs { @() } + + $Result = Get-CIPPSharePointCopyJobProgress -TenantFilter 'contoso.com' -SourceSiteUrl 'https://contoso.sharepoint.com/sites/a' -CopyJobInfo ([PSCustomObject]@{ + __metadata = [PSCustomObject]@{ type = 'Collection(SP.CopyMigrationInfo)' } + results = @( + [PSCustomObject]@{ + JobId = 'job-from-results' + JobQueueUri = 'https://queue/messages' + EncryptionKey = 'key' + } + ) + }) + + $ParsedBody = $script:CapturedBody | ConvertFrom-Json + $ParsedBody.copyJobInfo.JobId | Should -Be 'job-from-results' + $Result.IsComplete | Should -Be $true + } + + It 'uses queue logs when GetCopyJobProgress REST fails' { + Mock New-GraphPOSTRequest { throw 'REST unavailable' } + Mock Get-CIPPSharePointCopyJobQueueLogs { + @([PSCustomObject]@{ + Event = 'JobEnd' + TotalErrors = 1 + ObjectsProcessed = 0 + }, + [PSCustomObject]@{ + Event = 'JobError' + ObjectType = 'File' + Message = 'Access denied.' + }) + } + + $Result = Get-CIPPSharePointCopyJobProgress -TenantFilter 'contoso.com' -SourceSiteUrl 'https://contoso.sharepoint.com/sites/a' -CopyJobInfo @{ + JobId = 'job-rest-fail'; JobQueueUri = 'https://queue.example/messages?sas=1'; EncryptionKey = 'key' + } + + $Result.IsComplete | Should -Be $true + $Result.TotalErrors | Should -BeGreaterThan 0 + ($Result.ErrorMessages -join ' ') | Should -Match 'Access denied' + } +} diff --git a/Tests/Private/Get-CIPPSharePointLibraryCopyOperation.Tests.ps1 b/Tests/Private/Get-CIPPSharePointLibraryCopyOperation.Tests.ps1 new file mode 100644 index 0000000000000..b1ff13b26a694 --- /dev/null +++ b/Tests/Private/Get-CIPPSharePointLibraryCopyOperation.Tests.ps1 @@ -0,0 +1,117 @@ +# Pester tests for SharePointLibraryCopy operation store helpers + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPSharePointLibraryCopyOperation.ps1' + $SetPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Set-CIPPSharePointLibraryCopyOperation.ps1' + if (-not (Test-Path $FunctionPath)) { throw "Could not locate $FunctionPath" } + if (-not (Test-Path $SetPath)) { throw "Could not locate $SetPath" } + + function Get-CIPPTable { + param($TableName) + @{ Context = [pscustomobject]@{ TableName = $TableName } } + } + + $script:TableRows = @() + + function Get-CIPPAzDataTableEntity { + param($Context, $Filter) + if ($Filter -match "PartitionKey eq '([^']+)' and RowKey eq '([^']+)'") { + $tenant = $Matches[1] + $rowKey = $Matches[2] + return @($script:TableRows | Where-Object { $_.PartitionKey -eq $tenant -and $_.RowKey -eq $rowKey }) + } + if ($Filter -match "PartitionKey eq '([^']+)' and startswith\(RowKey, '([^']+)'\)") { + $tenant = $Matches[1] + $prefix = $Matches[2] + return @($script:TableRows | Where-Object { $_.PartitionKey -eq $tenant -and $_.RowKey.StartsWith($prefix) }) + } + if ($Filter -match "PartitionKey eq '([^']+)'$") { + $tenant = $Matches[1] + return @($script:TableRows | Where-Object { $_.PartitionKey -eq $tenant }) + } + return @() + } + + function Remove-CIPPAzDataTableEntity { + param($Context, $Entity, [switch]$Force) + foreach ($Row in @($Entity)) { + $script:TableRows = @($script:TableRows | Where-Object { + -not ($_.PartitionKey -eq $Row.PartitionKey -and $_.RowKey -eq $Row.RowKey) + }) + } + } + + function Add-CIPPAzDataTableEntity { + param($Context, $Entity, [switch]$Force, [string]$OperationType = 'Add') + foreach ($Row in @($Entity)) { + $Existing = $script:TableRows | Where-Object { + $_.PartitionKey -eq $Row.PartitionKey -and $_.RowKey -eq $Row.RowKey + } | Select-Object -First 1 + if ($Existing -and $OperationType -eq 'UpsertMerge') { + foreach ($Key in $Row.Keys) { + $Existing.$Key = $Row[$Key] + } + } elseif ($Existing -and $Force) { + $script:TableRows = @($script:TableRows | Where-Object { + -not ($_.PartitionKey -eq $Row.PartitionKey -and $_.RowKey -eq $Row.RowKey) + }) + $script:TableRows += [pscustomobject]$Row + } else { + $script:TableRows += [pscustomobject]$Row + } + } + } + + . $FunctionPath + . $SetPath +} + +Describe 'Get-CIPPSharePointLibraryCopyOperation' { + BeforeEach { + $script:TableRows = @() + } + + It 'loads the primary row by exact RowKey' { + $OpId = [guid]::NewGuid().Guid + $script:TableRows = @( + [pscustomobject]@{ + PartitionKey = 'contoso.com' + RowKey = $OpId + JobHandleCount = 2 + CopyJobInfos = '[{"JobId":"a"}]' + HandleStates = '[]' + Status = 'Processing' + } + ) + + $Result = Get-CIPPSharePointLibraryCopyOperation -TenantFilter 'contoso.com' -OperationId $OpId + + $Result.OperationId | Should -Be $OpId + $Result.CopyJobInfos.Count | Should -Be 1 + } + + It 'merges status updates without deleting CopyJobInfos' { + $OpId = [guid]::NewGuid().Guid + $script:TableRows = @( + [pscustomobject]@{ + PartitionKey = 'contoso.com' + RowKey = $OpId + JobHandleCount = 1 + CopyJobInfos = '[{"JobId":"a"}]' + HandleStates = '[]' + Status = 'Processing' + } + ) + + Set-CIPPSharePointLibraryCopyOperation -TenantFilter 'contoso.com' -OperationId $OpId -Entity @{ + Status = 'Completed' + HandleStates = '[{"Status":"Success","IsComplete":true}]' + } + + $Result = Get-CIPPSharePointLibraryCopyOperation -TenantFilter 'contoso.com' -OperationId $OpId + $Result.Status | Should -Be 'Completed' + $Result.CopyJobInfos.Count | Should -Be 1 + ($script:TableRows | Measure-Object).Count | Should -Be 1 + } +} diff --git a/Tests/Private/Get-CippApiClient.Tests.ps1 b/Tests/Private/Get-CippApiClient.Tests.ps1 new file mode 100644 index 0000000000000..1c54ed75d2884 --- /dev/null +++ b/Tests/Private/Get-CippApiClient.Tests.ps1 @@ -0,0 +1,102 @@ +# Pester tests for Get-CippApiClient. +# +# IPRange is stored as a JSON array string. Blank or unparseable means unrestricted (Any). +# A stored literal '[]' must mean the same thing, and must never leak an extra element into +# the returned client list. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Authentication/Get-CippApiClient.ps1' + + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($TableName, $Filter) } + + . $FunctionPath + + $script:AppId = '11111111-2222-3333-4444-555555555555' +} + +Describe 'Get-CippApiClient' { + BeforeEach { + Mock -CommandName Get-CIPPTable -MockWith { @{ TableName = 'ApiClients' } } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $script:Rows } + } + + Context 'IPRange stored as an empty array' { + BeforeEach { + $script:Rows = @( + [pscustomobject]@{ PartitionKey = 'ApiClients'; RowKey = $script:AppId; AppName = 'Empty'; Role = 'readonly'; IPRange = '[]'; Enabled = $true; MCPAllowed = $false } + ) + } + + It 'returns only the client, no extra element' { + $Result = @(Get-CippApiClient -AppId $script:AppId) + $Result.Count | Should -Be 1 + $Result[0].ClientId | Should -Be $script:AppId + } + + It 'treats the empty array as Any' { + $Result = Get-CippApiClient -AppId $script:AppId + @($Result.IPRange) | Should -Be @('Any') + } + } + + Context 'IPRange stored with ranges' { + BeforeEach { + $script:Rows = @( + [pscustomobject]@{ PartitionKey = 'ApiClients'; RowKey = $script:AppId; AppName = 'Ranged'; Role = 'readonly'; IPRange = '["10.0.0.0/8","192.168.1.1"]'; Enabled = $true; MCPAllowed = $true } + ) + } + + It 'returns the parsed ranges' { + $Result = Get-CippApiClient -AppId $script:AppId + @($Result.IPRange) | Should -Be @('10.0.0.0/8', '192.168.1.1') + } + + It 'does not add Any alongside real ranges' { + $Result = Get-CippApiClient -AppId $script:AppId + @($Result.IPRange) | Should -Not -Contain 'Any' + } + } + + Context 'IPRange blank' { + BeforeEach { + $script:Rows = @( + [pscustomobject]@{ PartitionKey = 'ApiClients'; RowKey = $script:AppId; AppName = 'Blank'; Role = 'readonly'; IPRange = ''; Enabled = $true; MCPAllowed = $false } + ) + } + + It 'treats blank as Any' { + $Result = Get-CippApiClient -AppId $script:AppId + @($Result.IPRange) | Should -Be @('Any') + } + } + + Context 'IPRange unparseable' { + BeforeEach { + $script:Rows = @( + [pscustomobject]@{ PartitionKey = 'ApiClients'; RowKey = $script:AppId; AppName = 'Broken'; Role = 'readonly'; IPRange = 'not json'; Enabled = $true; MCPAllowed = $false } + ) + } + + It 'treats unparseable as Any' { + $Result = Get-CippApiClient -AppId $script:AppId + @($Result.IPRange) | Should -Be @('Any') + } + } + + Context 'Multiple clients, one with an empty array' { + BeforeEach { + $script:Rows = @( + [pscustomobject]@{ PartitionKey = 'ApiClients'; RowKey = 'aaaaaaaa-0000-0000-0000-000000000001'; AppName = 'One'; Role = 'readonly'; IPRange = '[]'; Enabled = $true; MCPAllowed = $false } + [pscustomobject]@{ PartitionKey = 'ApiClients'; RowKey = 'aaaaaaaa-0000-0000-0000-000000000002'; AppName = 'Two'; Role = 'editor'; IPRange = '["10.0.0.0/8"]'; Enabled = $true; MCPAllowed = $false } + ) + } + + It 'returns exactly one object per stored row' { + $Result = @(Get-CippApiClient) + $Result.Count | Should -Be 2 + $Result.ClientId | Should -Be @('aaaaaaaa-0000-0000-0000-000000000001', 'aaaaaaaa-0000-0000-0000-000000000002') + } + } +} diff --git a/Tests/Private/Get-CippHttpPermissions.Tests.ps1 b/Tests/Private/Get-CippHttpPermissions.Tests.ps1 new file mode 100644 index 0000000000000..36c1319517cb2 --- /dev/null +++ b/Tests/Private/Get-CippHttpPermissions.Tests.ps1 @@ -0,0 +1,114 @@ +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function Get-CIPPTable { param($tablename) @{} } + function Get-CIPPAzDataTableEntity { param($Filter, $Property) } + function Add-CIPPAzDataTableEntity { param($Entity, [switch]$Force) } + function Get-CIPPHttpFunctions { param([switch]$ByRole, [switch]$ByRoleGroup) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Authentication/Test-CippHttpPermissionUniverse.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Authentication/Get-CippHttpPermissions.ps1') + + # A plausible universe: 60 names shaped Area.Object.Read/ReadWrite, including the core one. + $script:FullUniverse = @( + 'CIPP.Core.Read' + 'CIPP.Core.ReadWrite' + foreach ($Area in 'Identity', 'Exchange', 'Tenant', 'Endpoint', 'Security', 'Teams', 'Sharepoint') { + foreach ($Object in 'User', 'Group', 'Device', 'Mailbox', 'Policy') { + "$Area.$Object.Read" + "$Area.$Object.ReadWrite" + } + } + ) + + $env:CIPPNG = 'true' + $env:APP_VERSION = '10.9.1' +} + +Describe 'Test-CippHttpPermissionUniverse' { + It 'accepts a full universe' { + Test-CippHttpPermissionUniverse -Permissions $script:FullUniverse | Should -BeTrue + } + + It 'accepts the None placeholder among real permissions' { + Test-CippHttpPermissionUniverse -Permissions (@('None') + $script:FullUniverse) | Should -BeTrue + } + + It 'rejects an empty or missing list' { + Test-CippHttpPermissionUniverse -Permissions @() | Should -BeFalse + Test-CippHttpPermissionUniverse -Permissions $null | Should -BeFalse + } + + It 'rejects a truncated enumeration' { + Test-CippHttpPermissionUniverse -Permissions ($script:FullUniverse | Select-Object -First 12) | Should -BeFalse + } + + It 'rejects a universe without the core read permission' { + $NoCore = @($script:FullUniverse | Where-Object { $_ -ne 'CIPP.Core.Read' }) + Test-CippHttpPermissionUniverse -Permissions $NoCore | Should -BeFalse + } + + It 'rejects an error string persisted as a permission' { + $WithError = @('Function Error Exception of type System.OutOfMemoryException was thrown') + $script:FullUniverse + Test-CippHttpPermissionUniverse -Permissions $WithError | Should -BeFalse + } +} + +Describe 'Get-CippHttpPermissions' { + BeforeEach { + $script:CippHttpPermissions = $null + $script:CippHttpPermissionsVersion = $null + Mock Add-CIPPAzDataTableEntity {} + } + + It 'serves a valid cached universe without enumerating' { + Mock Get-CIPPAzDataTableEntity { [PSCustomObject]@{ Permissions = ($script:FullUniverse | ConvertTo-Json -Compress) } } + Mock Get-CIPPHttpFunctions { throw 'should not enumerate' } + + $Result = Get-CippHttpPermissions + + @($Result).Count | Should -Be $script:FullUniverse.Count + Should -Invoke Add-CIPPAzDataTableEntity -Times 0 -Exactly + } + + It 'recomputes and replaces a cached universe that is an error string' { + Mock Get-CIPPAzDataTableEntity { [PSCustomObject]@{ Permissions = '"Function Error Exception of type System.OutOfMemoryException was thrown"' } } + Mock Get-CIPPHttpFunctions { $script:FullUniverse | ForEach-Object { [PSCustomObject]@{ Permission = $_; Count = 1 } } } + + $Result = Get-CippHttpPermissions 3>$null + + $Result | Should -Contain 'CIPP.Core.Read' + @($Result).Count | Should -Be $script:FullUniverse.Count + Should -Invoke Add-CIPPAzDataTableEntity -Times 1 -Exactly + } + + It 'recomputes a cached universe that is too short to be real' { + Mock Get-CIPPAzDataTableEntity { [PSCustomObject]@{ Permissions = (@('CIPP.Core.Read', 'Identity.User.Read') | ConvertTo-Json -Compress) } } + Mock Get-CIPPHttpFunctions { $script:FullUniverse | ForEach-Object { [PSCustomObject]@{ Permission = $_; Count = 1 } } } + + $Result = Get-CippHttpPermissions 3>$null + + @($Result).Count | Should -Be $script:FullUniverse.Count + Should -Invoke Add-CIPPAzDataTableEntity -Times 1 -Exactly + } + + It 'serves but does not persist a truncated enumeration' { + Mock Get-CIPPAzDataTableEntity { $null } + Mock Get-CIPPHttpFunctions { @('CIPP.Core.Read', 'Identity.User.Read', 'None') | ForEach-Object { [PSCustomObject]@{ Permission = $_; Count = 1 } } } + + $Result = Get-CippHttpPermissions 3>$null + + @($Result).Count | Should -Be 3 + Should -Invoke Add-CIPPAzDataTableEntity -Times 0 -Exactly + # Nothing memoized either: the next call must try again. + $script:CippHttpPermissions | Should -BeNullOrEmpty + } + + It 'lets an enumeration failure surface instead of caching it' { + Mock Get-CIPPAzDataTableEntity { $null } + Mock Get-CIPPHttpFunctions { throw 'Failed to enumerate HTTP function permissions: boom' } + + { Get-CippHttpPermissions } | Should -Throw -ExpectedMessage '*Failed to enumerate*' + Should -Invoke Add-CIPPAzDataTableEntity -Times 0 -Exactly + } +} diff --git a/Tests/Private/Get-DefenderCves.Tests.ps1 b/Tests/Private/Get-DefenderCves.Tests.ps1 index 46e1b2d5c750f..e7218a5f7deb2 100644 --- a/Tests/Private/Get-DefenderCves.Tests.ps1 +++ b/Tests/Private/Get-DefenderCves.Tests.ps1 @@ -47,8 +47,9 @@ BeforeAll { } } - # A record the fold cannot bucket: Hashtable.ContainsKey rejects a null key, so this - # trips the per-record catch instead of producing a row. + # A TVM software-inventory row with no CVE. The fold skips these up front (counting them + # as skipped) rather than trying to bucket a null key, which previously threw and was + # logged per-record as an 'Allover Build' error. function New-UnbucketableRecord { param($deviceId = 'd-bad') [pscustomobject]@{ cveId = $null; deviceId = $deviceId } @@ -246,21 +247,17 @@ Describe 'get-DefenderCVEs' { $Received | ForEach-Object { @($_).Count | Should -Be 1 } } - It 'folds each record as it arrives rather than after the whole fetch completes' { + It 'skips records with no CVE without throwing or logging an error' { Mock -CommandName Get-DefenderTvmRaw -MockWith { - New-TvmRecord -cveId 'CVE-A' -deviceId 'd1' - New-UnbucketableRecord - throw 'page 3 failed' + New-UnbucketableRecord -deviceId 'd0' + New-TvmRecord -cveId 'CVE-2024-0009' -deviceId 'd1' } - { get-DefenderCVEs -TenantFilter $script:Tenant } | Should -Throw + $Result = @(get-DefenderCVEs -TenantFilter $script:Tenant) - # The unbucketable record is only ever logged from inside the fold. A buffered - # fetch would throw before a single record reached the fold, so this log is the - # observable proof that stage 1 streams. - Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { - $message -like 'Allover Build*' - } + $Result.cveId | Should -Be 'CVE-2024-0009' + Should -Invoke Write-LogMessage -Times 0 -Exactly -ParameterFilter { $message -like 'Allover Build*' } + Should -Invoke Write-LogMessage -Times 0 -Exactly -ParameterFilter { $sev -eq 'Error' } } } diff --git a/Tests/Private/Get-GraphRequestList.Paging.Tests.ps1 b/Tests/Private/Get-GraphRequestList.Paging.Tests.ps1 new file mode 100644 index 0000000000000..f618f77f44897 --- /dev/null +++ b/Tests/Private/Get-GraphRequestList.Paging.Tests.ps1 @@ -0,0 +1,219 @@ +# Pester tests for the paged AllTenants cache serve in Get-GraphRequestList +# Validates that ManualPagination + RawJsonArray serves pages bounded by the byte budget +# alone (never a tenant count), fetched as span range queries, with a continuation token; +# that the key scan never fetches Data payloads; that the queue fallback still triggers on +# a cold cache; and that the unpaged fast path is intact. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + # Stub every CIPP helper the exercised paths call so Pester's Mock has a command to replace. + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property, $First) } + function Get-Tenants { param($TenantFilter, [switch]$IncludeErrors) } + function Get-CIPPQueueData { param($Reference) } + function Get-StringHash { param($String) } + function New-CippQueueEntry { param($Name, $Link, $Reference, $TotalTasks) } + function Start-CIPPOrchestrator { param($InputObject) } + function New-GraphGetRequest { param($uri, $tenantid) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/ConvertTo-CIPPODataFilterValue.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/GraphRequests/Get-GraphRequestList.ps1') + + # Emulates a span fetch: blobs inside the [From, To] RowKey range in ordinal order. + function Select-FakeBlobRows { + param([string]$Filter) + if ($Filter -notmatch "RowKey ge '([^']*)' and RowKey le '([^']*)~'") { return @() } + $From = $Matches[1] + $To = $Matches[2] + $Keys = [string[]]@($script:TenantBlobs.Keys) + [System.Array]::Sort($Keys, [System.Collections.IComparer][StringComparer]::Ordinal) + @($Keys | Where-Object { + [string]::CompareOrdinal($_, $From) -ge 0 -and [string]::CompareOrdinal($_, $To) -le 0 + } | ForEach-Object { + [PSCustomObject]@{ PartitionKey = 'PKHASH'; RowKey = $_; Data = $script:TenantBlobs[$_] } + }) + } +} + +Describe 'Get-GraphRequestList paged AllTenants cache serve' { + BeforeEach { + Mock -CommandName Get-StringHash -MockWith { 'PKHASH' } + Mock -CommandName Get-CIPPTable -MockWith { @{ Context = 'fake' } } + Mock -CommandName Get-CIPPQueueData -MockWith { $null } + Mock -CommandName Get-Tenants -MockWith { + @( + [PSCustomObject]@{ defaultDomainName = 'a.com' } + [PSCustomObject]@{ defaultDomainName = 'b.com' } + [PSCustomObject]@{ defaultDomainName = 'c.com' } + ) + } + + # Key scans (Property set) return raw physical rows incl. '-part' rows and an + # unmanaged tenant (b0gus.com) inside the span range; data fetches return blobs. + $script:TenantBlobs = @{ + 'a.com' = '[{"id":"a1"},{"id":"a2"}]' + 'b.com' = '[{"id":"b1"}]' + 'b0gus.com' = '[{"id":"bogus"}]' + 'c.com' = '[{"id":"c1"}]' + } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + if ($Property) { + @( + [PSCustomObject]@{ PartitionKey = 'PKHASH'; RowKey = 'a.com' } + [PSCustomObject]@{ PartitionKey = 'PKHASH'; RowKey = 'b.com' } + [PSCustomObject]@{ PartitionKey = 'PKHASH'; RowKey = 'b.com-part1' } + [PSCustomObject]@{ PartitionKey = 'PKHASH'; RowKey = 'b.com-part2' } + [PSCustomObject]@{ PartitionKey = 'PKHASH'; RowKey = 'b0gus.com' } + [PSCustomObject]@{ PartitionKey = 'PKHASH'; RowKey = 'c.com' } + ) + } else { + Select-FakeBlobRows -Filter $Filter + } + } + } + + It 'serves all managed tenants in one span when they fit, with valid JSON and no token' { + $Result = Get-GraphRequestList -TenantFilter 'AllTenants' -Endpoint 'users' -ManualPagination -RawJsonArray + + $Result.PSObject.Properties.Name | Should -Contain 'CippPagedJson' + $Result.CippNextLink | Should -BeNullOrEmpty + $Parsed = $Result.CippPagedJson | ConvertFrom-Json + # a.com's two rows plus one each from b.com and c.com. b0gus.com sits inside the + # span's RowKey range but is unmanaged, so it must be dropped; the part rows + # deduplicate into b.com's count. + $Parsed | Should -HaveCount 4 + $Parsed.id | Should -Be @('a1', 'a2', 'b1', 'c1') + # The key scan must project keys only - never Data payloads, and never a subset of + # the split-entity markers (a partial marker projection makes the module fail + # reassembly and drop split tenants from the plan entirely). + Should -Invoke Get-CIPPAzDataTableEntity -Times 1 -ParameterFilter { + $null -ne $Property -and $Property -notcontains 'OriginalEntityId' -and $Property -notcontains 'Data' + } + # One span covers all three tenants: exactly one range fetch. + Should -Invoke Get-CIPPAzDataTableEntity -Times 1 -ParameterFilter { $Filter -like "*RowKey ge*" } + } + + It 'resumes after the tenant named by the incoming nextLink token' { + $Result = Get-GraphRequestList -TenantFilter 'AllTenants' -Endpoint 'users' -ManualPagination -RawJsonArray -nextLink 'a.com' + + $Parsed = $Result.CippPagedJson | ConvertFrom-Json + $Parsed.id | Should -Be @('b1', 'c1') + $Result.CippNextLink | Should -BeNullOrEmpty + Should -Invoke Get-CIPPAzDataTableEntity -Times 0 -ParameterFilter { $Filter -like "*RowKey ge 'a.com'*" } + } + + It 'ends the page on the character budget mid-span and resumes from the token' { + # b.com's blob alone exceeds the 4M character budget. All three tenants share one + # span, so the budget must end the page inside the span: c.com's fetched blob is + # discarded and served by the next page. + $script:TenantBlobs['b.com'] = '[{"id":"b1","pad":"' + ('x' * 4200000) + '"}]' + + $Result = Get-GraphRequestList -TenantFilter 'AllTenants' -Endpoint 'users' -ManualPagination -RawJsonArray + + $Result.CippNextLink | Should -Be 'b.com' + $Ids = ($Result.CippPagedJson | ConvertFrom-Json).id + $Ids | Should -Contain 'a1' + $Ids | Should -Not -Contain 'c1' + + $Next = Get-GraphRequestList -TenantFilter 'AllTenants' -Endpoint 'users' -ManualPagination -RawJsonArray -nextLink $Result.CippNextLink + ($Next.CippPagedJson | ConvertFrom-Json).id | Should -Be @('c1') + $Next.CippNextLink | Should -BeNullOrEmpty + } + + It 'honours a MaxPageBytes override, clamped to the floor' { + # a.com's ~300KB exceeds the 256KB floor that the 1-byte request clamps up to, so + # the page ends after the first tenant even though all three share a span. + $script:TenantBlobs['a.com'] = '[{"id":"a1","pad":"' + ('x' * 300000) + '"}]' + + $Result = Get-GraphRequestList -TenantFilter 'AllTenants' -Endpoint 'users' -ManualPagination -RawJsonArray -MaxPageBytes 1 + + $Result.CippNextLink | Should -Be 'a.com' + $Next = Get-GraphRequestList -TenantFilter 'AllTenants' -Endpoint 'users' -ManualPagination -RawJsonArray -MaxPageBytes 1 -nextLink $Result.CippNextLink + ($Next.CippPagedJson | ConvertFrom-Json).id | Should -Be @('b1', 'c1') + $Next.CippNextLink | Should -BeNullOrEmpty + } + + It 'never re-serves earlier tenants on resume when tenant casing is mixed' { + # Ordinal order puts 'CyberDrainDev.com' (uppercase C) before 'cipp.com'; a + # culture-aware plan sort ordered them the other way round, so resuming after + # CyberDrainDev re-served cipp's rows and the chain returned duplicates. + Mock -CommandName Get-Tenants -MockWith { + @( + [PSCustomObject]@{ defaultDomainName = 'CyberDrainDev.com' } + [PSCustomObject]@{ defaultDomainName = 'cipp.com' } + ) + } + $script:TenantBlobs = @{ + 'CyberDrainDev.com' = '[{"id":"cdd1"}]' + 'cipp.com' = '[{"id":"cipp1"}]' + } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + if ($Property) { + @( + [PSCustomObject]@{ PartitionKey = 'PKHASH'; RowKey = 'cipp.com' } + [PSCustomObject]@{ PartitionKey = 'PKHASH'; RowKey = 'CyberDrainDev.com' } + ) + } else { + Select-FakeBlobRows -Filter $Filter + } + } + + $Full = Get-GraphRequestList -TenantFilter 'AllTenants' -Endpoint 'users' -ManualPagination -RawJsonArray + ($Full.CippPagedJson | ConvertFrom-Json).id | Should -Be @('cdd1', 'cipp1') + + $Resumed = Get-GraphRequestList -TenantFilter 'AllTenants' -Endpoint 'users' -ManualPagination -RawJsonArray -nextLink 'CyberDrainDev.com' + ($Resumed.CippPagedJson | ConvertFrom-Json).id | Should -Be @('cipp1') + } + + It 'serves many small tenants in one page regardless of tenant count' { + # The complaint span fetching answers: 60 tiny tenants must not need 60 requests + # or 60 queries - they share spans and land in a single page. + $script:ManyTenants = @(1..60 | ForEach-Object { 'tenant{0:D3}.example' -f $_ }) + Mock -CommandName Get-Tenants -MockWith { + @($script:ManyTenants | ForEach-Object { [PSCustomObject]@{ defaultDomainName = $_ } }) + } + $script:TenantBlobs = @{} + foreach ($Tenant in $script:ManyTenants) { $script:TenantBlobs[$Tenant] = ('[{{"id":"{0}"}}]' -f $Tenant) } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + if ($Property) { + @($script:ManyTenants | ForEach-Object { [PSCustomObject]@{ PartitionKey = 'PKHASH'; RowKey = $_ } }) + } else { + Select-FakeBlobRows -Filter $Filter + } + } + + $Result = Get-GraphRequestList -TenantFilter 'AllTenants' -Endpoint 'users' -ManualPagination -RawJsonArray + + $Result.CippNextLink | Should -BeNullOrEmpty + ($Result.CippPagedJson | ConvertFrom-Json) | Should -HaveCount 60 + # 60 one-row tenants at 40 rows per span: two range fetches, one page. + Should -Invoke Get-CIPPAzDataTableEntity -Times 2 -ParameterFilter { $Filter -like "*RowKey ge*" } + } + + It 'falls through to the queue flow when the cache is cold' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { @() } + Mock -CommandName New-CippQueueEntry -MockWith { @{ RowKey = 'queue-1' } } + Mock -CommandName Start-CIPPOrchestrator -MockWith { 'instance-1' } + + $Result = Get-GraphRequestList -TenantFilter 'AllTenants' -Endpoint 'users' -ManualPagination -RawJsonArray + + $Result.Queued | Should -BeTrue + $Result.QueueId | Should -Be 'queue-1' + Should -Invoke Start-CIPPOrchestrator -Times 1 + } + + It 'keeps the unpaged raw concat path when ManualPagination is not set' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + @( + [PSCustomObject]@{ PartitionKey = 'PKHASH'; RowKey = 'a.com'; OriginalEntityId = $null; Data = '[{"id":"a1"}]' } + [PSCustomObject]@{ PartitionKey = 'PKHASH'; RowKey = 'c.com'; OriginalEntityId = $null; Data = '[{"id":"c1"}]' } + ) + } + + $Result = Get-GraphRequestList -TenantFilter 'AllTenants' -Endpoint 'users' -RawJsonArray + + $Result | Should -BeOfType [string] + ($Result | ConvertFrom-Json).id | Should -Be @('a1', 'c1') + } +} diff --git a/Tests/Private/Invoke-CIPPCustomDomainCertificate.Tests.ps1 b/Tests/Private/Invoke-CIPPCustomDomainCertificate.Tests.ps1 new file mode 100644 index 0000000000000..4808b7a483b55 --- /dev/null +++ b/Tests/Private/Invoke-CIPPCustomDomainCertificate.Tests.ps1 @@ -0,0 +1,120 @@ +# Pester tests for Invoke-CIPPCustomDomainCertificate +# Managed certificate issuance outlives a request, so the function has to hand off to a hidden +# retry task - and stop handing off once the certificate is bound, the domain is gone, or the +# attempt budget is spent. An unbounded reschedule is the bug these tests guard. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Functions/Invoke-CIPPCustomDomainCertificate.ps1' + + function Get-CIPPAppServiceSite { param($ApiVersion) } + function New-CIPPAzRestRequest { param($Uri, $Method, $Body) } + function Add-CIPPScheduledTask { param($Task, $Hidden) } + function Write-LogMessage { param($API, $message, $sev, $tenant, $headers, $LogData) } + function Get-CippException { param($Exception) @{ NormalizedError = "$Exception" } } + + . $FunctionPath +} + +Describe 'Invoke-CIPPCustomDomainCertificate' { + BeforeEach { + $script:Hostname = 'portal.contoso.com' + $script:SiteState = [pscustomobject]@{ + SiteName = 'cippxyz' + ArmBase = 'https://management.azure.com/subscriptions/sub/resourceGroups/rg/providers/Microsoft.Web/sites/cippxyz' + CertBase = 'https://management.azure.com/subscriptions/sub/resourceGroups/rg/providers/Microsoft.Web/certificates' + ApiVersion = '2024-11-01' + Site = [pscustomobject]@{ + location = 'westeurope' + properties = [pscustomobject]@{ + serverFarmId = '/subscriptions/sub/resourceGroups/rg/providers/Microsoft.Web/serverfarms/plan' + hostNames = @('cippxyz.azurewebsites.net', $script:Hostname) + hostNameSslStates = @([pscustomobject]@{ name = $script:Hostname; sslState = 'Disabled' }) + } + } + Certificates = @() + } + Mock -CommandName Get-CIPPAppServiceSite -MockWith { $script:SiteState } + # Nothing issued yet: the PUT returns a cert without a thumbprint and the poll list stays empty + Mock -CommandName New-CIPPAzRestRequest -MockWith { + if ($Method -eq 'PUT') { [pscustomobject]@{ properties = [pscustomobject]@{ thumbprint = $null } } } + else { [pscustomobject]@{ value = @() } } + } + Mock -CommandName Add-CIPPScheduledTask -MockWith { 'Task created' } + Mock -CommandName Write-LogMessage + Mock -CommandName Start-Sleep + } + + It 'does nothing when the hostname is not bound (the domain was removed)' { + $script:SiteState.Site.properties.hostNames = @('cippxyz.azurewebsites.net') + + $Result = Invoke-CIPPCustomDomainCertificate -Hostname $script:Hostname + + $Result | Should -Match 'No hostname binding' + Should -Invoke New-CIPPAzRestRequest -Times 0 + Should -Invoke Add-CIPPScheduledTask -Times 0 + } + + It 'does nothing when the binding is already secured' { + $script:SiteState.Site.properties.hostNameSslStates[0].sslState = 'SniEnabled' + + Invoke-CIPPCustomDomainCertificate -Hostname $script:Hostname | Should -Match 'already secured' + Should -Invoke New-CIPPAzRestRequest -Times 0 + Should -Invoke Add-CIPPScheduledTask -Times 0 + } + + It 'binds an already-issued certificate for the hostname without creating another' { + $script:SiteState.Certificates = @([pscustomobject]@{ + name = 'whatever-the-portal-called-it' + properties = [pscustomobject]@{ canonicalName = $script:Hostname; thumbprint = 'ABC123' } + }) + + Invoke-CIPPCustomDomainCertificate -Hostname $script:Hostname | Should -Match 'SNI SSL enabled' + + Should -Invoke New-CIPPAzRestRequest -Times 1 -Exactly -ParameterFilter { + $Method -eq 'PUT' -and $Uri -like '*/hostNameBindings/portal.contoso.com?*' -and $Body.properties.thumbprint -eq 'ABC123' -and $Body.properties.sslState -eq 'SniEnabled' + } + Should -Invoke Add-CIPPScheduledTask -Times 0 + } + + It 'creates the certificate in the plan resource group and schedules a hidden retry when it is not issued yet' { + $Result = Invoke-CIPPCustomDomainCertificate -Hostname $script:Hostname + + $Result | Should -Match 'attempt 1 of 4' + Should -Invoke New-CIPPAzRestRequest -Times 1 -Exactly -ParameterFilter { + $Method -eq 'PUT' -and $Uri -like "*/certificates/portal.contoso.com-cippxyz?*" -and $Body.properties.canonicalName -eq 'portal.contoso.com' + } + Should -Invoke New-CIPPAzRestRequest -Times 0 -ParameterFilter { $Uri -like '*/hostNameBindings/*' } + Should -Invoke Add-CIPPScheduledTask -Times 1 -Exactly -ParameterFilter { + $Hidden -eq $true -and $Task.Parameters.Attempt -eq 2 -and $Task.Parameters.Hostname -eq 'portal.contoso.com' -and $Task.Reference -eq 'CustomDomainCert-portal.contoso.com' + } + } + + It 'treats a 409 on create as an issuance already in flight rather than a failure' { + Mock -CommandName New-CIPPAzRestRequest -MockWith { + if ($Method -eq 'PUT') { throw 'Azure REST API call failed: Found a duplicate certificate (Status: Conflict)' } + [pscustomobject]@{ value = @() } + } + + $Result = Invoke-CIPPCustomDomainCertificate -Hostname $script:Hostname + + $Result | Should -Match 'still being issued' + Should -Invoke Add-CIPPScheduledTask -Times 1 + } + + It 'gives up on the last attempt instead of rescheduling again' { + $Result = Invoke-CIPPCustomDomainCertificate -Hostname $script:Hostname -Attempt 4 + + $Result | Should -Match 'Giving up after 4 attempts' + Should -Invoke Add-CIPPScheduledTask -Times 0 + } + + It 'reschedules after a failed attempt so a transient ARM error does not strand the domain' { + Mock -CommandName New-CIPPAzRestRequest -MockWith { throw 'Azure REST API call failed: boom (Status: 500)' } + + $Result = Invoke-CIPPCustomDomainCertificate -Hostname $script:Hostname -Attempt 2 + + $Result | Should -Match 'failed: .*boom.*attempt 2 of 4' + Should -Invoke Add-CIPPScheduledTask -Times 1 -Exactly -ParameterFilter { $Task.Parameters.Attempt -eq 3 } + } +} diff --git a/Tests/Private/Invoke-CIPPOffboardingJob.DeleteUser.Tests.ps1 b/Tests/Private/Invoke-CIPPOffboardingJob.DeleteUser.Tests.ps1 new file mode 100644 index 0000000000000..5c0115a89265a --- /dev/null +++ b/Tests/Private/Invoke-CIPPOffboardingJob.DeleteUser.Tests.ps1 @@ -0,0 +1,77 @@ +# Pester tests for the DeleteUser guard in Invoke-CIPPOffboardingJob: +# - When DeleteUser is true, only Remove-CIPPUser and Set-CIPPSharePointPerms may run +# - When DeleteUser is false/absent, other selected tasks still run + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $JobPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Invoke-CIPPOffboardingJob.ps1' + $HtmlPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Test-CIPPHtmlIsEmpty.ps1' + if (-not (Test-Path $JobPath)) { throw "Could not locate Invoke-CIPPOffboardingJob.ps1 at $JobPath" } + if (-not (Test-Path $HtmlPath)) { throw "Could not locate Test-CIPPHtmlIsEmpty.ps1 at $HtmlPath" } + + function New-GraphGetRequest { param($uri, $tenantid) } + function Get-CIPPTextReplacement { param($TenantFilter, $Text, [switch]$EscapeForJson) } + function Start-CIPPOrchestrator { param($InputObject) } + function Write-LogMessage { param($API, $tenant, $message, $sev, $headers, $LogData) } + function Get-CippException { param($Exception) @{ NormalizedError = "$Exception" } } + function Write-Information { param($MessageData) } + + . $HtmlPath + . $JobPath +} + +Describe 'Invoke-CIPPOffboardingJob DeleteUser guard' { + BeforeEach { + $script:CapturedInput = $null + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Write-Information -MockWith { } + Mock -CommandName Get-CIPPTextReplacement -MockWith { $Text } + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ + id = 'user-id-1' + displayName = 'Pat Lee' + onPremisesSyncEnabled = $false + onPremisesImmutableId = $null + } + } + Mock -CommandName Start-CIPPOrchestrator -MockWith { + $script:CapturedInput = $InputObject + 'orch-1' + } + } + + It 'only runs Remove-CIPPUser and Set-CIPPSharePointPerms when DeleteUser is true' { + $Options = [pscustomobject]@{ + DeleteUser = $true + ConvertToShared = $true + RemoveLicenses = $true + RevokeSessions = $true + HideFromGAL = $true + RemoveMFADevices = $true + OnedriveAccess = @(@{ value = 'helper-id-1' }) + } + + $null = Invoke-CIPPOffboardingJob -TenantFilter 'contoso.com' -Username 'pat@contoso.com' -Options $Options + + $script:CapturedInput.Batch | Should -Not -BeNullOrEmpty + $Cmdlets = $script:CapturedInput.Batch | ForEach-Object { $_.Cmdlet } | Sort-Object -Unique + $Cmdlets | Should -Be @('Remove-CIPPUser', 'Set-CIPPSharePointPerms') + } + + It 'runs other selected tasks when DeleteUser is false' { + $Options = [pscustomobject]@{ + DeleteUser = $false + ConvertToShared = $true + RemoveLicenses = $true + RevokeSessions = $true + } + + $null = Invoke-CIPPOffboardingJob -TenantFilter 'contoso.com' -Username 'pat@contoso.com' -Options $Options + + $Cmdlets = $script:CapturedInput.Batch | ForEach-Object { $_.Cmdlet } | Sort-Object -Unique + $Cmdlets | Should -Contain 'Set-CIPPMailboxType' + $Cmdlets | Should -Contain 'Remove-CIPPLicense' + $Cmdlets | Should -Contain 'Revoke-CIPPSessions' + $Cmdlets | Should -Not -Contain 'Remove-CIPPUser' + } +} diff --git a/Tests/Private/Invoke-CIPPOffboardingJob.Progress.Tests.ps1 b/Tests/Private/Invoke-CIPPOffboardingJob.Progress.Tests.ps1 new file mode 100644 index 0000000000000..263ad80e78646 --- /dev/null +++ b/Tests/Private/Invoke-CIPPOffboardingJob.Progress.Tests.ps1 @@ -0,0 +1,128 @@ +# Pester tests for the live-progress wiring in Invoke-CIPPOffboardingJob. +# +# The wizard hands the job a DeploymentId. The job must turn the selected tasks into the step list of +# that user's status row, stamp every queued task with its step so the workers (which run in parallel) +# report to the right place, and close the row as failed when the job never gets as far as queueing. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $JobPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Invoke-CIPPOffboardingJob.ps1' + $HtmlPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Test-CIPPHtmlIsEmpty.ps1' + if (-not (Test-Path $JobPath)) { throw "Could not locate Invoke-CIPPOffboardingJob.ps1 at $JobPath" } + + function New-GraphGetRequest { param($uri, $tenantid) } + function Get-CIPPTextReplacement { param($TenantFilter, $Text, [switch]$EscapeForJson) } + function Start-CIPPOrchestrator { param($InputObject) } + function Write-LogMessage { param($API, $tenant, $message, $sev, $headers, $LogData) } + function Get-CippException { param($Exception) @{ NormalizedError = "$Exception" } } + function Write-Information { param($MessageData) } + function New-CIPPAsyncDeployment { param($JobId, $Names, $StepTitles, $Source, $TaskId, $TenantFilter) } + function Set-CIPPAsyncDeploymentStep { param($JobId, $Name, $StepIndex, $StepStatus, $Message) } + function Set-CIPPAsyncDeploymentStatus { param($JobId, $Name, $Status, $Logs) } + + . $HtmlPath + . $JobPath +} + +Describe 'Invoke-CIPPOffboardingJob live progress' { + BeforeEach { + $script:CapturedInput = $null + $script:StepTitles = $null + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Write-Information -MockWith { } + Mock -CommandName Get-CIPPTextReplacement -MockWith { $Text } + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ id = 'user-id-1'; displayName = 'Pat Lee'; onPremisesSyncEnabled = $false; onPremisesImmutableId = $null } + } + Mock -CommandName Start-CIPPOrchestrator -MockWith { $script:CapturedInput = $InputObject; 'orch-1' } + Mock -CommandName New-CIPPAsyncDeployment -MockWith { $script:StepTitles = @($StepTitles); $JobId } + Mock -CommandName Set-CIPPAsyncDeploymentStatus -MockWith { } + Mock -CommandName Set-CIPPAsyncDeploymentStep -MockWith { } + } + + It 'gives the row one step per selected task, in execution order, and stamps each task with its step' { + $Options = [pscustomobject]@{ RevokeSessions = $true; DisableSignIn = $true; RemoveLicenses = $true } + + $null = Invoke-CIPPOffboardingJob -TenantFilter 'contoso.com' -Username 'pat@contoso.com' -Options $Options -DeploymentId 'job-1' -TaskInfo ([pscustomobject]@{ RowKey = 'task-1' }) + + Should -Invoke New-CIPPAsyncDeployment -Times 1 -Exactly -ParameterFilter { + $JobId -eq 'job-1' -and (@($Names) -join ',') -eq 'pat@contoso.com' -and $Source -eq 'Offboarding' -and $TaskId -eq 'task-1' -and $TenantFilter -eq 'contoso.com' + } + $script:StepTitles | Should -Be @('Revoke all sessions', 'Disable sign in', 'Remove licenses') + $Batch = @($script:CapturedInput.Batch) + $Batch.Cmdlet | Should -Be @('Revoke-CIPPSessions', 'Set-CIPPSignInState', 'Remove-CIPPLicense') + $Batch.StepIndex | Should -Be @(0, 1, 2) + $Batch.DeploymentId | Should -Be @('job-1', 'job-1', 'job-1') + $Batch.DeploymentName | Should -Be @('pat@contoso.com', 'pat@contoso.com', 'pat@contoso.com') + $script:CapturedInput.PostExecution.Parameters.DeploymentId | Should -Be 'job-1' + Should -Invoke Set-CIPPAsyncDeploymentStatus -Times 1 -Exactly -ParameterFilter { + $JobId -eq 'job-1' -and $Name -eq 'pat@contoso.com' -and $Status -eq 'running' + } + } + + It 'closes the row as failed when the job cannot even be queued' { + Mock -CommandName New-GraphGetRequest -MockWith { throw 'user not found' } + + { Invoke-CIPPOffboardingJob -TenantFilter 'contoso.com' -Username 'pat@contoso.com' -Options ([pscustomobject]@{ RevokeSessions = $true }) -DeploymentId 'job-1' } | Should -Throw + + Should -Invoke Set-CIPPAsyncDeploymentStatus -Times 1 -Exactly -ParameterFilter { + $JobId -eq 'job-1' -and $Status -eq 'failed' -and $Logs -like '*user not found*' + } + } + + It 'runs only the requested step and resets just that step on the existing row' { + $Options = [pscustomobject]@{ RevokeSessions = $true; DisableSignIn = $true; RemoveLicenses = $true } + + $null = Invoke-CIPPOffboardingJob -TenantFilter 'contoso.com' -Username 'pat@contoso.com' -Options $Options -DeploymentId 'job-1' -StepIndexes @(1) + + $Batch = @($script:CapturedInput.Batch) + $Batch.Count | Should -Be 1 + $Batch[0].Cmdlet | Should -Be 'Set-CIPPSignInState' + $Batch[0].StepIndex | Should -Be 1 + Should -Invoke New-CIPPAsyncDeployment -Times 0 -Exactly + Should -Invoke Set-CIPPAsyncDeploymentStep -Times 1 -Exactly -ParameterFilter { + $JobId -eq 'job-1' -and $Name -eq 'pat@contoso.com' -and $StepIndex -eq 1 -and $StepStatus -eq 'pending' + } + Should -Invoke Set-CIPPAsyncDeploymentStatus -Times 1 -Exactly -ParameterFilter { $Status -eq 'running' } + } + + It 'refuses a step re-run for a step that does not exist' { + $Options = [pscustomobject]@{ RevokeSessions = $true } + + { Invoke-CIPPOffboardingJob -TenantFilter 'contoso.com' -Username 'pat@contoso.com' -Options $Options -DeploymentId 'job-1' -StepIndexes @(7) } | Should -Throw + + Should -Invoke Start-CIPPOrchestrator -Times 0 -Exactly + } + + It 'puts a pending notification step per configured channel on the row from the start' { + $Options = [pscustomobject]@{ RevokeSessions = $true; DisableSignIn = $true } + + $null = Invoke-CIPPOffboardingJob -TenantFilter 'contoso.com' -Username 'pat@contoso.com' -Options $Options -DeploymentId 'job-1' -TaskInfo ([pscustomobject]@{ RowKey = 'task-1'; PostExecution = 'Webhook,Email' }) + + $script:StepTitles.Count | Should -Be 4 + $script:StepTitles[0] | Should -Be 'Revoke all sessions' + $script:StepTitles[2].Title | Should -Be 'Notify via Webhook' + $script:StepTitles[2].Kind | Should -Be 'notify' + $script:StepTitles[3].Title | Should -Be 'Notify via Email' + # Notification steps are not tasks: nothing extra is queued for them + @($script:CapturedInput.Batch).Count | Should -Be 2 + } + + It 'still starts the offboarding when the progress row cannot be written' { + Mock -CommandName New-CIPPAsyncDeployment -MockWith { throw 'An error occurred while sending the request.' } + + $Result = Invoke-CIPPOffboardingJob -TenantFilter 'contoso.com' -Username 'pat@contoso.com' -Options ([pscustomobject]@{ RevokeSessions = $true }) -DeploymentId 'job-1' + + Should -Invoke Start-CIPPOrchestrator -Times 1 -Exactly + $Result | Should -BeLike 'Offboarding job started*' + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { $sev -eq 'Warn' -and $message -like '*progress row*' } + } + + It 'leaves progress alone when no job id was given' { + $null = Invoke-CIPPOffboardingJob -TenantFilter 'contoso.com' -Username 'pat@contoso.com' -Options ([pscustomobject]@{ RevokeSessions = $true }) + + Should -Invoke New-CIPPAsyncDeployment -Times 0 -Exactly + Should -Invoke Set-CIPPAsyncDeploymentStatus -Times 0 -Exactly + @($script:CapturedInput.Batch)[0].Keys | Should -Not -Contain 'DeploymentId' + } +} diff --git a/Tests/Private/Invoke-CIPPPIMAssignmentAction.Tests.ps1 b/Tests/Private/Invoke-CIPPPIMAssignmentAction.Tests.ps1 new file mode 100644 index 0000000000000..f8e14f355e425 --- /dev/null +++ b/Tests/Private/Invoke-CIPPPIMAssignmentAction.Tests.ps1 @@ -0,0 +1,220 @@ +# Pester tests for Invoke-CIPPPIMAssignmentAction - the guards around PIM assignment changes. +# +# What must hold regardless of caller: +# - no PIM write on a tenant without Entra ID P2; +# - the last active Global Administrator is never converted or removed; +# - CIPP-SAM's own assignment, group-inherited rows and service-principal conversions are refused; +# - ConvertToEligible confirms the eligibility exists BEFORE the active assignment is removed; +# - lifetimes above the policy cap are refused (never clamped); +# - nothing is ever posted with a noExpiration schedule. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/PIM/New-CIPPPIMScheduleRequest.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/PIM/Invoke-CIPPPIMAssignmentAction.ps1') + + function Test-CIPPStandardLicense { param($StandardName, $TenantFilter, $Preset, [switch]$SkipLog) $true } + function Get-CIPPPIMRoleAssignments { param($TenantFilter, $PrincipalId, $RoleDefinitionId, [switch]$FromCache, [switch]$IncludePolicy) } + function Get-CIPPPIMRolePolicies { param($TenantFilter, $RoleDefinitionId, [switch]$FromCache) } + function New-GraphPOSTRequest { param($uri, $tenantid, $body, $type, $AsApp) } + function New-GraphGetRequest { param($uri, $tenantid, $AsApp) } + function Get-CIPPTable { param($TableName) @{} } + function Get-CIPPAzDataTableEntity { param($Filter) } + function Write-LogMessage { param($headers, $API, $tenant, $message, $Sev, $LogData) } + + $script:GA = '62e90394-69f5-4237-9190-012177145e10' + $script:Target = 'user-1' + + function New-Row { + param([string]$Principal = 'user-1', [string]$Type = 'Permanent', [string]$MemberType = 'Direct', [string]$PrincipalType = 'User', [string]$Role = $script:GA, [string]$AppId = $null, [datetime]$End = [datetime]::MinValue) + [pscustomobject]@{ + PrincipalId = $Principal + PrincipalDisplayName = "Name $Principal" + PrincipalUserPrincipalName = "$Principal@contoso.com" + PrincipalType = $PrincipalType + PrincipalAppId = $AppId + RoleDefinitionId = $Role + RoleDisplayName = 'Global Administrator' + AssignmentType = $Type + MemberType = $MemberType + DirectoryScopeId = '/' + EndDateTime = if ($End -eq [datetime]::MinValue) { $null } else { $End } + RoleAssignmentId = 'ra-1' + } + } + + function Invoke-Convert { + param([hashtable]$Extra = @{}) + Invoke-CIPPPIMAssignmentAction -TenantFilter 'contoso.onmicrosoft.com' -Action ConvertToEligible -PrincipalId $script:Target -RoleDefinitionId $script:GA -AssignmentType Permanent -Justification 'test' @Extra + } +} + +Describe 'Invoke-CIPPPIMAssignmentAction' { + BeforeEach { + $script:Posts = [System.Collections.Generic.List[object]]::new() + $env:ApplicationID = 'sam-app-id' + Mock Test-CIPPStandardLicense { $true } + Mock Get-CIPPPIMRolePolicies { [pscustomobject]@{ RoleDefinitionId = $script:GA; PolicyId = 'pol'; Settings = [pscustomobject]@{ eligibilityMaxDuration = 'P365D'; activeAssignmentMaxDuration = 'P180D' } } } + Mock Get-CIPPTable { @{} } + Mock Get-CIPPAzDataTableEntity { $null } + Mock Write-LogMessage {} + Mock Start-Sleep {} + Mock New-GraphPOSTRequest { + $script:Posts.Add([pscustomobject]@{ Uri = $uri; Body = ($body | ConvertFrom-Json); Type = $type }) + [pscustomobject]@{ id = 'req' } + } + # Default tenant: the target holds GA permanently, another admin also holds it permanently. + Mock Get-CIPPPIMRoleAssignments { + $Rows = @((New-Row -Principal 'user-1'), (New-Row -Principal 'user-2')) + if ($PrincipalId) { $Rows = $Rows | Where-Object { $_.PrincipalId -eq $PrincipalId } } + if ($RoleDefinitionId) { $Rows = $Rows | Where-Object { $_.RoleDefinitionId -eq $RoleDefinitionId } } + @($Rows) + } + # Eligibility read-back after creation: present. + # Eligibility read-back: present. Post-removal instance poll: already gone. + Mock New-GraphGetRequest { + if ($uri -match 'roleAssignmentScheduleInstances') { @() } + else { @([pscustomobject]@{ id = 'elig-1'; principalId = 'user-1'; roleDefinitionId = $script:GA; directoryScopeId = '/' }) } + } + } + + It 'refuses on a tenant without Entra ID P2 and posts nothing' { + Mock Test-CIPPStandardLicense { $false } + { Invoke-Convert } | Should -Throw '*not licensed for Entra ID P2*' + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly + } + + It 'refuses to convert the last active Global Administrator' { + Mock Get-CIPPPIMRoleAssignments { + $Rows = @((New-Row -Principal 'user-1'), (New-Row -Principal 'user-2' -Type 'Eligible')) + if ($PrincipalId) { $Rows = $Rows | Where-Object { $_.PrincipalId -eq $PrincipalId } } + @($Rows) + } + { Invoke-Convert } | Should -Throw '*last active Global Administrator*' + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly + } + + It 'refuses to remove the last active Global Administrator' { + Mock Get-CIPPPIMRoleAssignments { + $Rows = @((New-Row -Principal 'user-1')) + if ($PrincipalId) { $Rows = $Rows | Where-Object { $_.PrincipalId -eq $PrincipalId } } + @($Rows) + } + { Invoke-CIPPPIMAssignmentAction -TenantFilter 'contoso.onmicrosoft.com' -Action Remove -PrincipalId 'user-1' -RoleDefinitionId $script:GA -AssignmentType Permanent -Justification 'test' } | Should -Throw '*last active Global Administrator*' + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly + } + + It 'refuses to touch the CIPP-SAM application' { + Mock Get-CIPPPIMRoleAssignments { @((New-Row -Principal 'user-1' -PrincipalType 'ServicePrincipal' -AppId 'sam-app-id'), (New-Row -Principal 'user-2')) | Where-Object { -not $PrincipalId -or $_.PrincipalId -eq $PrincipalId } } + { Invoke-Convert } | Should -Throw '*CIPP-SAM*' + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly + } + + It 'refuses a row inherited through a group' { + Mock Get-CIPPPIMRoleAssignments { @((New-Row -Principal 'user-1' -MemberType 'Group'), (New-Row -Principal 'user-2')) | Where-Object { -not $PrincipalId -or $_.PrincipalId -eq $PrincipalId } } + { Invoke-Convert } | Should -Throw '*role-assignable group*' + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly + } + + It 'refuses to convert a service principal (PIM eligibility is users and groups only)' { + Mock Get-CIPPPIMRoleAssignments { @((New-Row -Principal 'user-1' -PrincipalType 'ServicePrincipal' -AppId 'other-app'), (New-Row -Principal 'user-2')) | Where-Object { -not $PrincipalId -or $_.PrincipalId -eq $PrincipalId } } + { Invoke-Convert } | Should -Throw '*service principal*' + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly + } + + Context 'ConvertToEligible' { + It 'creates the eligibility, confirms it, then removes the active assignment - in that order' { + $Result = Invoke-Convert + $Result.state | Should -Be 'success' + $script:Posts.Count | Should -Be 2 + $script:Posts[0].Uri | Should -Match 'roleEligibilityScheduleRequests$' + $script:Posts[0].Body.action | Should -Be 'adminAssign' + $script:Posts[0].Body.scheduleInfo.expiration.type | Should -Be 'afterDuration' + $script:Posts[0].Body.scheduleInfo.expiration.duration | Should -Be 'P365D' + $script:Posts[1].Uri | Should -Match 'roleAssignmentScheduleRequests$' + $script:Posts[1].Body.action | Should -Be 'adminRemove' + Should -Invoke New-GraphGetRequest -Times 1 -ParameterFilter { $uri -match 'roleEligibilitySchedules' } + $Result.Before | Should -Be 'Permanent' + $Result.After | Should -Match '^Eligible until' + } + + It 'leaves the active assignment alone when the eligibility cannot be confirmed' { + Mock New-GraphGetRequest { @() } + { Invoke-Convert } | Should -Throw '*could not be confirmed*' + $script:Posts.Count | Should -Be 1 + $script:Posts[0].Body.action | Should -Be 'adminAssign' + } + + It 'refuses an eligibility lifetime above the policy cap instead of clamping it' { + Mock Get-CIPPPIMRolePolicies { [pscustomobject]@{ RoleDefinitionId = $script:GA; PolicyId = 'pol'; Settings = [pscustomobject]@{ eligibilityMaxDuration = 'P180D'; activeAssignmentMaxDuration = 'P180D' } } } + { Invoke-Convert @{ Duration = 'P365D' } } | Should -Throw '*exceeds the maximum allowed*' + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly + } + + It 'never posts a noExpiration schedule' { + $null = Invoke-Convert + foreach ($Post in $script:Posts) { + (ConvertTo-Json -InputObject $Post.Body -Depth 10 -Compress) | Should -Not -Match 'noExpiration' + } + } + } + + Context 'GrantActive' { + It 'posts a time-bound assignment within the cap' { + Mock Get-CIPPPIMRoleAssignments { @((New-Row -Principal 'user-1' -Type 'Eligible'), (New-Row -Principal 'user-2')) | Where-Object { -not $PrincipalId -or $_.PrincipalId -eq $PrincipalId } } + $Result = Invoke-CIPPPIMAssignmentAction -TenantFilter 'contoso.onmicrosoft.com' -Action GrantActive -PrincipalId 'user-1' -RoleDefinitionId $script:GA -AssignmentType Eligible -Duration 'PT4H' -Justification 'test' + $Result.state | Should -Be 'success' + $script:Posts.Count | Should -Be 1 + $script:Posts[0].Uri | Should -Match 'roleAssignmentScheduleRequests$' + $script:Posts[0].Body.scheduleInfo.expiration.duration | Should -Be 'PT4H' + } + + It 'applies the JIT admin maximum duration as a cap' { + Mock Get-CIPPAzDataTableEntity { [pscustomobject]@{ MaxDuration = 'PT2H' } } + Mock Get-CIPPPIMRoleAssignments { @((New-Row -Principal 'user-1' -Type 'Eligible'), (New-Row -Principal 'user-2')) | Where-Object { -not $PrincipalId -or $_.PrincipalId -eq $PrincipalId } } + { Invoke-CIPPPIMAssignmentAction -TenantFilter 'contoso.onmicrosoft.com' -Action GrantActive -PrincipalId 'user-1' -RoleDefinitionId $script:GA -AssignmentType Eligible -Duration 'PT4H' -Justification 'test' } | Should -Throw '*exceeds the maximum allowed*' + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly + } + + It 'refuses without an expiration' { + { Invoke-CIPPPIMAssignmentAction -TenantFilter 'contoso.onmicrosoft.com' -Action GrantActive -PrincipalId 'user-1' -RoleDefinitionId $script:GA -AssignmentType Eligible -Justification 'test' } | Should -Throw '*needs a Duration or EndDateTime*' + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly + } + + It 'words the end time in the caller''s time zone, and in labelled UTC when the zone is unknown or absent' { + Mock Get-CIPPPIMRoleAssignments { @((New-Row -Principal 'user-1' -Type 'Eligible'), (New-Row -Principal 'user-2')) | Where-Object { -not $PrincipalId -or $_.PrincipalId -eq $PrincipalId } } + # A future instant (the builder refuses a past end), at 08:06 UTC on some day next month: + # Perth is UTC+8 all year, so the worded time is 16:06 on the same date. + $End = [datetime]::SpecifyKind([datetime]::UtcNow.AddDays(30).Date.AddHours(8).AddMinutes(6).AddSeconds(36), 'Utc') + $UtcText = $End.ToString('yyyy-MM-dd') + ' 08:06' + $PerthText = $End.ToString('yyyy-MM-dd') + ' 16:06' + $Perth = Invoke-CIPPPIMAssignmentAction -TenantFilter 'contoso.onmicrosoft.com' -Action GrantActive -PrincipalId 'user-1' -RoleDefinitionId $script:GA -AssignmentType Eligible -EndDateTime $End -Justification 'test' -TimeZone 'Australia/Perth' + $Perth.resultText | Should -Match "until $PerthText \(Australia/Perth\)\.$" + $Perth.After | Should -Be "Active until $PerthText (Australia/Perth)" + $Perth.EndDateTime | Should -Be $End -Because 'the zone only changes the wording, never the stored end' + $Unknown = Invoke-CIPPPIMAssignmentAction -TenantFilter 'contoso.onmicrosoft.com' -Action GrantActive -PrincipalId 'user-1' -RoleDefinitionId $script:GA -AssignmentType Eligible -EndDateTime $End -Justification 'test' -TimeZone 'Mars/Olympus_Mons' + $Unknown.resultText | Should -Match "until $UtcText UTC\.$" + $None = Invoke-CIPPPIMAssignmentAction -TenantFilter 'contoso.onmicrosoft.com' -Action GrantActive -PrincipalId 'user-1' -RoleDefinitionId $script:GA -AssignmentType Eligible -EndDateTime $End -Justification 'test' + $None.resultText | Should -Match "until $UtcText UTC\.$" + # the Graph request itself always carries the UTC instant + ([datetime]$script:Posts[-1].Body.scheduleInfo.expiration.endDateTime).ToUniversalTime().ToString('s') | Should -Be $End.ToString('s') + } + } + + Context 'Remove' { + It 'removes an eligibility through the eligibility schedule' { + Mock Get-CIPPPIMRoleAssignments { @((New-Row -Principal 'user-1' -Type 'Eligible'), (New-Row -Principal 'user-2')) | Where-Object { -not $PrincipalId -or $_.PrincipalId -eq $PrincipalId } } + $Result = Invoke-CIPPPIMAssignmentAction -TenantFilter 'contoso.onmicrosoft.com' -Action Remove -PrincipalId 'user-1' -RoleDefinitionId $script:GA -AssignmentType Eligible -Justification 'test' + $Result.After | Should -Be 'None' + $script:Posts[0].Uri | Should -Match 'roleEligibilityScheduleRequests$' + $script:Posts[0].Body.action | Should -Be 'adminRemove' + } + + It 'removes an active assignment when another Global Administrator remains' { + $Result = Invoke-CIPPPIMAssignmentAction -TenantFilter 'contoso.onmicrosoft.com' -Action Remove -PrincipalId 'user-1' -RoleDefinitionId $script:GA -AssignmentType Permanent -Justification 'test' + $Result.After | Should -Be 'None' + $script:Posts[0].Uri | Should -Match 'roleAssignmentScheduleRequests$' + $script:Posts[0].Body.action | Should -Be 'adminRemove' + } + } +} diff --git a/Tests/Private/Invoke-CIPPSharePointCreateCopyJobs.Tests.ps1 b/Tests/Private/Invoke-CIPPSharePointCreateCopyJobs.Tests.ps1 new file mode 100644 index 0000000000000..032f51ba94ba2 --- /dev/null +++ b/Tests/Private/Invoke-CIPPSharePointCreateCopyJobs.Tests.ps1 @@ -0,0 +1,47 @@ +# Pester tests for Invoke-CIPPSharePointCreateCopyJobs OData verbose handle parsing + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Invoke-CIPPSharePointCreateCopyJobs.ps1' + if (-not (Test-Path $FunctionPath)) { throw "Could not locate $FunctionPath" } + + function Get-SharePointAdminLink { param($Public, $tenantFilter) [PSCustomObject]@{ SharePointUrl = 'https://contoso.sharepoint.com' } } + function New-GraphPOSTRequest { param($uri, $tenantid, $body, $contentType) } + + . $FunctionPath +} + +Describe 'Invoke-CIPPSharePointCreateCopyJobs' { + It 'unwraps OData verbose CreateCopyJobs.results into normalized handles' { + Mock New-GraphPOSTRequest { + [PSCustomObject]@{ + d = [PSCustomObject]@{ + CreateCopyJobs = [PSCustomObject]@{ + __metadata = [PSCustomObject]@{ type = 'Collection(SP.CopyMigrationInfo)' } + results = @( + [PSCustomObject]@{ + EncryptionKey = 'abc123base64=' + JobId = 'd0a42793-f995-4ce2-b0fb-cc3c0e819e19' + JobQueueUri = 'https://queue.core.windows.net/job?sv=1&sig=x' + SourceListItemUniqueIds = [PSCustomObject]@{ + results = @('208875e4-2659-433d-acd8-4d77fc76e1ef') + } + } + ) + } + } + } + } + + $Result = Invoke-CIPPSharePointCreateCopyJobs -TenantFilter 'contoso.com' ` + -SourceSiteUrl 'https://contoso.sharepoint.com/sites/a' ` + -ExportObjectUris @('https://contoso.sharepoint.com/sites/a/Shared%20Documents/Folder') ` + -DestinationUri 'https://contoso.sharepoint.com/sites/b/Shared%20Documents' + + $Result.Count | Should -Be 1 + $Result[0].JobId | Should -Be 'd0a42793-f995-4ce2-b0fb-cc3c0e819e19' + $Result[0].JobQueueUri | Should -Match 'queue.core.windows.net' + $Result[0].EncryptionKey | Should -Be 'abc123base64=' + ($Result[0] | Get-Member -Name SourceListItemUniqueIds -ErrorAction SilentlyContinue) | Should -BeNullOrEmpty + } +} diff --git a/Tests/Private/New-CIPPPIMScheduleRequest.Tests.ps1 b/Tests/Private/New-CIPPPIMScheduleRequest.Tests.ps1 new file mode 100644 index 0000000000000..fffb8d45eed0f --- /dev/null +++ b/Tests/Private/New-CIPPPIMScheduleRequest.Tests.ps1 @@ -0,0 +1,120 @@ +# Pester tests for New-CIPPPIMScheduleRequest - the only builder of PIM schedule request bodies. +# +# The security rule these tests pin down: CIPP never creates a permanent (no-expiration) role +# assignment or eligibility. Every caller - endpoint, standard, scheduled task - goes through this +# function, so "it refuses to build without an expiration" is the whole guarantee. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/PIM/New-CIPPPIMScheduleRequest.ps1') + + $script:Common = @{ + PrincipalId = 'aaaaaaaa-0000-0000-0000-000000000001' + RoleDefinitionId = '62e90394-69f5-4237-9190-012177145e10' + Justification = 'Ticket 1234' + } +} + +Describe 'New-CIPPPIMScheduleRequest' { + Context 'refuses permanent / no-expiration input' { + It 'throws when neither Duration nor EndDateTime is given for <_>' -ForEach @('adminAssign', 'adminUpdate', 'adminExtend', 'adminRenew') { + { New-CIPPPIMScheduleRequest -Kind Assignment -Action $_ @script:Common } | Should -Throw '*never creates permanent*' + { New-CIPPPIMScheduleRequest -Kind Eligibility -Action $_ @script:Common } | Should -Throw '*never creates permanent*' + } + + It 'throws when the duration asks for permanence by name: <_>' -ForEach @('noExpiration', 'permanent', 'never', 'unlimited', 'none', ' NoExpiration ') { + { New-CIPPPIMScheduleRequest -Kind Eligibility -Action adminAssign -Duration $_ @script:Common } | Should -Throw '*permanent (no-expiration)*' + } + + It 'throws on a duration that is not ISO 8601' { + { New-CIPPPIMScheduleRequest -Kind Assignment -Action adminAssign -Duration '8 hours' @script:Common } | Should -Throw '*not a valid ISO 8601 duration*' + } + + It 'throws on a zero-length duration' { + { New-CIPPPIMScheduleRequest -Kind Assignment -Action adminAssign -Duration 'PT0S' @script:Common } | Should -Throw '*greater than zero*' + } + + It 'throws when EndDateTime is in the past' { + { New-CIPPPIMScheduleRequest -Kind Assignment -Action adminAssign -EndDateTime ([datetime]::UtcNow.AddHours(-1)) @script:Common } | Should -Throw '*not in the future*' + } + + It 'throws when both Duration and EndDateTime are given' { + { New-CIPPPIMScheduleRequest -Kind Assignment -Action adminAssign -Duration 'PT1H' -EndDateTime ([datetime]::UtcNow.AddHours(2)) @script:Common } | Should -Throw '*not both*' + } + + It 'throws when a duration exceeds MaxDuration instead of clamping it' { + { New-CIPPPIMScheduleRequest -Kind Assignment -Action adminAssign -Duration 'PT10H' -MaxDuration 'PT8H' @script:Common } | Should -Throw '*exceeds the maximum allowed*' + } + + It 'throws when an end date exceeds MaxDuration instead of clamping it' { + { New-CIPPPIMScheduleRequest -Kind Eligibility -Action adminAssign -EndDateTime ([datetime]::UtcNow.AddDays(400)) -MaxDuration 'P365D' @script:Common } | Should -Throw '*exceeds the maximum allowed*' + } + + It 'throws on an invalid MaxDuration rather than ignoring the cap' { + { New-CIPPPIMScheduleRequest -Kind Assignment -Action adminAssign -Duration 'PT1H' -MaxDuration 'forever' @script:Common } | Should -Throw '*MaxDuration*' + } + } + + Context 'builds valid time-bound bodies' { + It 'emits an afterDuration expiration for a duration' { + $Request = New-CIPPPIMScheduleRequest -Kind Assignment -Action adminAssign -Duration 'PT4H' -MaxDuration 'PT8H' @script:Common + + $Request.Uri | Should -Be 'https://graph.microsoft.com/v1.0/roleManagement/directory/roleAssignmentScheduleRequests' + $Request.Body.action | Should -Be 'adminAssign' + $Request.Body.principalId | Should -Be $script:Common.PrincipalId + $Request.Body.roleDefinitionId | Should -Be $script:Common.RoleDefinitionId + $Request.Body.directoryScopeId | Should -Be '/' + $Request.Body.justification | Should -Be 'Ticket 1234' + $Request.Body.scheduleInfo.expiration.type | Should -Be 'afterDuration' + $Request.Body.scheduleInfo.expiration.duration | Should -Be 'PT4H' + $Request.ExpirationType | Should -Be 'afterDuration' + ($Request.EndDateTime - [datetime]::UtcNow).TotalHours | Should -BeGreaterThan 3.9 + ($Request.EndDateTime - [datetime]::UtcNow).TotalHours | Should -BeLessThan 4.1 + } + + It 'emits an afterDateTime expiration for an end date, in UTC' { + $End = [datetime]::UtcNow.AddDays(30) + $Request = New-CIPPPIMScheduleRequest -Kind Eligibility -Action adminAssign -EndDateTime $End -MaxDuration 'P365D' @script:Common + + $Request.Uri | Should -Be 'https://graph.microsoft.com/v1.0/roleManagement/directory/roleEligibilityScheduleRequests' + $Request.Body.scheduleInfo.expiration.type | Should -Be 'afterDateTime' + $Request.Body.scheduleInfo.expiration.endDateTime | Should -Match '^\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}Z$' + $Request.Body.scheduleInfo.startDateTime | Should -Match 'Z$' + $Request.EndDateTime | Should -Be $End + } + + It 'accepts a year-long eligibility within the P365D cap' { + $Request = New-CIPPPIMScheduleRequest -Kind Eligibility -Action adminAssign -Duration 'P1Y' -MaxDuration 'P365D' @script:Common + $Request.Body.scheduleInfo.expiration.duration | Should -Be 'P1Y' + } + + It 'uses the explicit scope and start when given' { + $Start = [datetime]::UtcNow.AddHours(1) + $Request = New-CIPPPIMScheduleRequest -Kind Assignment -Action adminAssign -Duration 'PT1H' -StartDateTime $Start -DirectoryScopeId '/administrativeUnits/abc' @script:Common + $Request.Body.directoryScopeId | Should -Be '/administrativeUnits/abc' + $Request.StartDateTime | Should -Be $Start + } + + It 'adds ticketInfo when a ticket is supplied' { + $Request = New-CIPPPIMScheduleRequest -Kind Assignment -Action adminExtend -Duration 'PT2H' -TicketNumber 'INC-1' -TicketSystem 'Halo' @script:Common + $Request.Body.ticketInfo.ticketNumber | Should -Be 'INC-1' + $Request.Body.ticketInfo.ticketSystem | Should -Be 'Halo' + } + + It 'never emits noExpiration for any schedule-creating action' -ForEach @('adminAssign', 'adminUpdate', 'adminExtend', 'adminRenew') { + $Request = New-CIPPPIMScheduleRequest -Kind Assignment -Action $_ -Duration 'PT1H' @script:Common + (ConvertTo-Json -InputObject $Request.Body -Depth 10 -Compress) | Should -Not -Match 'noExpiration' + $Request.Body.scheduleInfo.expiration.type | Should -BeIn @('afterDuration', 'afterDateTime') + } + } + + Context 'adminRemove' { + It 'needs no schedule and carries no expiration' { + $Request = New-CIPPPIMScheduleRequest -Kind Eligibility -Action adminRemove @script:Common + $Request.Body.action | Should -Be 'adminRemove' + $Request.Body.Contains('scheduleInfo') | Should -BeFalse + $Request.EndDateTime | Should -BeNullOrEmpty + $Request.ExpirationType | Should -BeNullOrEmpty + } + } +} diff --git a/Tests/Private/New-CIPPUserTask.Tests.ps1 b/Tests/Private/New-CIPPUserTask.Tests.ps1 index d00318ffe2783..33e2d9c86ba8b 100644 --- a/Tests/Private/New-CIPPUserTask.Tests.ps1 +++ b/Tests/Private/New-CIPPUserTask.Tests.ps1 @@ -225,6 +225,39 @@ Describe 'New-CIPPUserTask' { $Result.Results | Should -Contain 'Scheduled SendAs on the shared mailbox Facility in 15 minutes.' } + It 'grants FullAccess without automapping when the no-automap variant is selected' { + $UserObj = New-TestUserObj -SharedMailboxes @( + [pscustomobject]@{ label = 'Facility'; value = 'facility@contoso.com' } + ) -SharedMailboxPermission ([pscustomobject]@{ label = 'Full Access (no Automapping)'; value = 'FullAccessNoAutoMap' }) + + $Result = New-CIPPUserTask -UserObj $UserObj + + Should -Invoke Add-CIPPScheduledTask -Times 1 -Exactly -ParameterFilter { + $Task.Parameters.PermissionLevel -eq 'FullAccess' -and + $Task.Parameters.AutoMap -eq $false + } + $Result.Results | Should -Contain 'Scheduled FullAccess (no automapping) on the shared mailbox Facility in 15 minutes. Automapping is off, so the user adds the mailbox to Outlook themselves.' + } + + It 'lets the no-automap variant win when both FullAccess variants are selected' { + # One grant carries one automapping flag; scheduling both would make the second + # Add-MailboxPermission fail on the already existing permission entry anyway. + $UserObj = New-TestUserObj -SharedMailboxes @( + [pscustomobject]@{ label = 'Facility'; value = 'facility@contoso.com' } + ) -SharedMailboxPermission @( + [pscustomobject]@{ label = 'Full Access'; value = 'FullAccess' } + [pscustomobject]@{ label = 'Full Access (no Automapping)'; value = 'FullAccessNoAutoMap' } + ) + + $null = New-CIPPUserTask -UserObj $UserObj + + Should -Invoke Add-CIPPScheduledTask -Times 1 -Exactly + Should -Invoke Add-CIPPScheduledTask -Times 1 -Exactly -ParameterFilter { + $Task.Parameters.PermissionLevel -eq 'FullAccess' -and + $Task.Parameters.AutoMap -eq $false + } + } + It 'schedules one task per permission level when several are selected' { $UserObj = New-TestUserObj -SharedMailboxes @( [pscustomobject]@{ label = 'Facility'; value = 'facility@contoso.com' } diff --git a/Tests/Private/Push-CIPPOffboardingComplete.PostExecution.Tests.ps1 b/Tests/Private/Push-CIPPOffboardingComplete.PostExecution.Tests.ps1 new file mode 100644 index 0000000000000..81c7d192dbf2d --- /dev/null +++ b/Tests/Private/Push-CIPPOffboardingComplete.PostExecution.Tests.ps1 @@ -0,0 +1,115 @@ +# Pester tests for the post-execution tracking in Push-CIPPOffboardingComplete. +# +# When an offboarding task has notification channels configured, the delivery outcome of each one +# must be kept with the task (PostExecutionResults) and appended to the user's progress row as a +# step, so a webhook that returned 500 is as visible as a cmdlet that failed. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPOffboardingComplete.ps1' + if (-not (Test-Path $FunctionPath)) { throw "Could not locate Push-CIPPOffboardingComplete.ps1 at $FunctionPath" } + + function Get-CippTable { param($tablename) } + function Update-AzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Add-CIPPAzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Write-LogMessage { param($API, $tenant, $message, $sev, $headers, $LogData) } + function Write-Information { param($MessageData) } + function Get-CippException { param($Exception) @{ NormalizedError = "$Exception" } } + function Send-CIPPScheduledTaskAlert { param($Results, $TaskInfo, $TenantFilter, $TaskType) } + function Get-CIPPAsyncDeployment { param($JobId) } + function Set-CIPPAsyncDeploymentStatus { param($JobId, $Name, $Status, $Logs) } + function Add-CIPPAsyncDeploymentStep { param($JobId, $Name, $Title, $StepStatus, $Message, $Kind) } + function Set-CIPPAsyncDeploymentStep { param($JobId, $Name, $StepIndex, $StepStatus, $Message) } + + . $FunctionPath + + function New-CompletionItem { + param([string]$PostExecution = 'Webhook,Email') + [pscustomobject]@{ + Parameters = [pscustomobject]@{ + TaskInfo = [pscustomobject]@{ PartitionKey = 'ScheduledTask'; RowKey = 'task-1'; PostExecution = $PostExecution } + TenantFilter = 'contoso.com' + Username = 'pat@contoso.com' + Headers = @{} + DeploymentId = 'job-1' + } + Results = @('Successfully revoked sessions for pat@contoso.com') + } + } +} + +Describe 'Push-CIPPOffboardingComplete post-execution tracking' { + BeforeEach { + Mock -CommandName Get-CippTable -MockWith { @{ Context = 'ctx' } } + Mock -CommandName Update-AzDataTableEntity -MockWith { } + Mock -CommandName Add-CIPPAzDataTableEntity -MockWith { } + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Write-Information -MockWith { } + Mock -CommandName Set-CIPPAsyncDeploymentStatus -MockWith { } + Mock -CommandName Add-CIPPAsyncDeploymentStep -MockWith { } + Mock -CommandName Set-CIPPAsyncDeploymentStep -MockWith { } + Mock -CommandName Send-CIPPScheduledTaskAlert -MockWith { + @( + [pscustomobject]@{ Channel = 'Webhook'; Result = 'Error: Webhook returned status code 500 for https://hooks.example' } + [pscustomobject]@{ Channel = 'Email'; Result = 'Sent an email alert: Offboarding' } + ) + } + # The row as the job created it: the action steps, then one pending notification step per channel. + Mock -CommandName Get-CIPPAsyncDeployment -MockWith { + [pscustomobject]@{ + Name = 'pat@contoso.com' + Steps = @( + [pscustomobject]@{ Title = 'Revoke all sessions'; Status = 'succeeded' } + [pscustomobject]@{ Title = 'Remove from all groups'; Status = 'failed' } + [pscustomobject]@{ Title = 'Notify via Webhook'; Status = 'pending'; Kind = 'notify' } + [pscustomobject]@{ Title = 'Notify via Email'; Status = 'pending'; Kind = 'notify' } + ) + } + } + } + + It 'stores each delivery outcome on the task and fills in the matching notification step' { + $null = Push-CIPPOffboardingComplete -Item (New-CompletionItem) + + Should -Invoke Send-CIPPScheduledTaskAlert -Times 1 -Exactly -ParameterFilter { $TaskType -eq 'User Offboarding' } + Should -Invoke Update-AzDataTableEntity -Times 1 -Exactly -ParameterFilter { + $Entity.RowKey -eq 'task-1' -and $Entity.PostExecutionResults -like '*"Channel":"Webhook"*' -and $Entity.PostExecutionResults -like '*status code 500*' + } + # Both notification steps go running while the deliveries are made... + Should -Invoke Set-CIPPAsyncDeploymentStep -Times 2 -Exactly -ParameterFilter { $StepStatus -eq 'running' -and $Message -eq 'Sending' } + # ...then each one gets its own outcome, at its own index. + Should -Invoke Set-CIPPAsyncDeploymentStep -Times 1 -Exactly -ParameterFilter { + $JobId -eq 'job-1' -and $Name -eq 'pat@contoso.com' -and $StepIndex -eq 2 -and $StepStatus -eq 'failed' -and $Message -like 'Error: Webhook*' + } + Should -Invoke Set-CIPPAsyncDeploymentStep -Times 1 -Exactly -ParameterFilter { $StepIndex -eq 3 -and $StepStatus -eq 'succeeded' } + Should -Invoke Add-CIPPAsyncDeploymentStep -Times 0 -Exactly + } + + It 'appends the notification step when the row was created without one' { + Mock -CommandName Get-CIPPAsyncDeployment -MockWith { + [pscustomobject]@{ Name = 'pat@contoso.com'; Steps = @([pscustomobject]@{ Title = 'Revoke all sessions'; Status = 'succeeded' }) } + } + + $null = Push-CIPPOffboardingComplete -Item (New-CompletionItem) + + Should -Invoke Add-CIPPAsyncDeploymentStep -Times 1 -Exactly -ParameterFilter { + $Title -eq 'Notify via Webhook' -and $StepStatus -eq 'failed' -and $Kind -eq 'notify' -and $Message -like 'Error: Webhook*' + } + Should -Invoke Add-CIPPAsyncDeploymentStep -Times 1 -Exactly -ParameterFilter { $Title -eq 'Notify via Email' -and $StepStatus -eq 'succeeded' } + } + + It 'closes the progress row as failed when a notification failed' { + $null = Push-CIPPOffboardingComplete -Item (New-CompletionItem) + + Should -Invoke Set-CIPPAsyncDeploymentStatus -Times 1 -Exactly -ParameterFilter { $JobId -eq 'job-1' -and $Status -eq 'failed' } + } + + It 'sends nothing and records nothing when no channel is configured' { + $null = Push-CIPPOffboardingComplete -Item (New-CompletionItem -PostExecution '') + + Should -Invoke Send-CIPPScheduledTaskAlert -Times 0 -Exactly + Should -Invoke Add-CIPPAsyncDeploymentStep -Times 0 -Exactly + Should -Invoke Set-CIPPAsyncDeploymentStep -Times 0 -Exactly + Should -Invoke Update-AzDataTableEntity -Times 0 -Exactly -ParameterFilter { $null -ne $Entity.PostExecutionResults } + } +} diff --git a/Tests/Private/Push-CIPPOffboardingTask.Progress.Tests.ps1 b/Tests/Private/Push-CIPPOffboardingTask.Progress.Tests.ps1 new file mode 100644 index 0000000000000..38ab9e6ac6885 --- /dev/null +++ b/Tests/Private/Push-CIPPOffboardingTask.Progress.Tests.ps1 @@ -0,0 +1,96 @@ +# Pester tests for the live-progress reporting in Push-CIPPOffboardingTask. +# +# The activity runs one offboarding cmdlet and reports to the step the job stamped on it. Most +# cmdlets do not throw for per-item problems - Remove-CIPPGroups returns 'Error: ...' lines next to +# 'Successfully removed ...' lines - so a returned error line must show as a failed step, or the +# progress view says Succeeded over a message that starts with Error. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-CIPPOffboardingTask.ps1' + if (-not (Test-Path $FunctionPath)) { throw "Could not locate Push-CIPPOffboardingTask.ps1 at $FunctionPath" } + + function Set-CIPPAsyncDeploymentStep { param($JobId, $Name, $StepIndex, $StepStatus, $Message) } + function Write-Information { param($MessageData) } + + . $FunctionPath + + # The activity only runs cmdlets it can find in the CIPPCore module, so the fakes live in a + # throwaway module of that name. Remove-CIPPGroups hands back whatever the test put in + # $global:CippTestResult; Set-CIPPSignInState always throws. + $script:FakeCore = New-Module -Name CIPPCore -ScriptBlock { + function Remove-CIPPGroups { param($userid, $tenantFilter) $global:CippTestResult } + function Set-CIPPSignInState { param($userid, $TenantFilter) throw 'boom' } + } | Import-Module -PassThru -Force + + function New-TaskItem { + param([string]$Cmdlet, [switch]$NoJob) + $Item = [pscustomobject]@{ + FunctionName = 'CIPPOffboardingTask' + Cmdlet = $Cmdlet + Parameters = @{ userid = 'user-id-1'; tenantFilter = 'contoso.com' } + } + if (-not $NoJob) { + $Item | Add-Member -NotePropertyName DeploymentId -NotePropertyValue 'job-1' + $Item | Add-Member -NotePropertyName DeploymentName -NotePropertyValue 'pat@contoso.com' + $Item | Add-Member -NotePropertyName StepIndex -NotePropertyValue 2 + } + $Item + } +} + +AfterAll { + Remove-Module -Name CIPPCore -Force -ErrorAction SilentlyContinue + Remove-Variable -Name CippTestResult -Scope Global -ErrorAction SilentlyContinue +} + +Describe 'Push-CIPPOffboardingTask live progress' { + BeforeEach { + Mock -CommandName Write-Information -MockWith { } + Mock -CommandName Set-CIPPAsyncDeploymentStep -MockWith { } + } + + It 'marks the step failed when the cmdlet returns an error line without throwing' { + $global:CippTestResult = @( + "Error: Could not remove pat@contoso.com from group 'All Users' because it is a Dynamic Group." + "Successfully removed pat@contoso.com from group 'Sales'" + ) + + $null = Push-CIPPOffboardingTask -Item (New-TaskItem -Cmdlet 'Remove-CIPPGroups') + + Should -Invoke Set-CIPPAsyncDeploymentStep -Times 1 -Exactly -ParameterFilter { + $JobId -eq 'job-1' -and $Name -eq 'pat@contoso.com' -and $StepIndex -eq 2 -and $StepStatus -eq 'running' + } + Should -Invoke Set-CIPPAsyncDeploymentStep -Times 1 -Exactly -ParameterFilter { + $StepStatus -eq 'failed' -and $Message -eq "Error: Could not remove pat@contoso.com from group 'All Users' because it is a Dynamic Group.`nSuccessfully removed pat@contoso.com from group 'Sales'" + } + } + + It 'marks the step succeeded and keeps every returned line' { + $global:CippTestResult = @('Successfully removed pat@contoso.com from group Sales', 'Successfully removed pat@contoso.com from group Ops') + + $Result = Push-CIPPOffboardingTask -Item (New-TaskItem -Cmdlet 'Remove-CIPPGroups') + + Should -Invoke Set-CIPPAsyncDeploymentStep -Times 1 -Exactly -ParameterFilter { + $StepStatus -eq 'succeeded' -and $Message -eq "Successfully removed pat@contoso.com from group Sales`nSuccessfully removed pat@contoso.com from group Ops" + } + @($Result).Count | Should -Be 2 + } + + It 'marks the step failed with the error text when the cmdlet throws' { + $Result = Push-CIPPOffboardingTask -Item (New-TaskItem -Cmdlet 'Set-CIPPSignInState') + + $Result | Should -Be 'Failed to execute Set-CIPPSignInState : boom' + Should -Invoke Set-CIPPAsyncDeploymentStep -Times 1 -Exactly -ParameterFilter { + $StepStatus -eq 'failed' -and $Message -eq 'Failed to execute Set-CIPPSignInState : boom' + } + } + + It 'leaves progress alone when the task carries no job id' { + $global:CippTestResult = 'done' + + $null = Push-CIPPOffboardingTask -Item (New-TaskItem -Cmdlet 'Remove-CIPPGroups' -NoJob) + + Should -Invoke Set-CIPPAsyncDeploymentStep -Times 0 -Exactly + } +} diff --git a/Tests/Private/Remove-CIPPUserTeamsPhoneDIDs.Tests.ps1 b/Tests/Private/Remove-CIPPUserTeamsPhoneDIDs.Tests.ps1 new file mode 100644 index 0000000000000..667711a787cb5 --- /dev/null +++ b/Tests/Private/Remove-CIPPUserTeamsPhoneDIDs.Tests.ps1 @@ -0,0 +1,90 @@ +BeforeAll { + # Resolve by name under Modules/ so the test survives the function moving between modules. + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Remove-CIPPUserTeamsPhoneDIDs.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $FunctionPath) { throw 'Could not locate Remove-CIPPUserTeamsPhoneDIDs.ps1 under Modules/' } + + # Stub every CIPP helper the function calls so Pester's Mock has a command to replace. + function New-GraphGetRequest { param($uri, $tenantid) } + function New-GraphPOSTRequest { param($uri, $tenantid, $body, $type) } + function New-GraphBulkRequest { param($tenantid, $Requests) } + function Get-CippTeamsNumberType { param($NumberType) } + function Get-CippException { param($Exception) } + function Write-LogMessage { param($headers, $API, $tenant, $message, $Sev, $LogData) } + + . $FunctionPath +} + +Describe 'Remove-CIPPUserTeamsPhoneDIDs' { + BeforeEach { + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName New-GraphBulkRequest -MockWith { } + Mock -CommandName New-GraphPOSTRequest -MockWith { } + Mock -CommandName Get-CippException -MockWith { [pscustomobject]@{ NormalizedError = 'boom' } } + Mock -CommandName Get-CippTeamsNumberType -MockWith { 'directRouting' } + Mock -CommandName New-GraphGetRequest -MockWith { + @( + [pscustomobject]@{ telephoneNumber = '+15551000001'; numberType = 'DirectRouting'; assignmentTargetId = 'user-1'; assignmentStatus = 'userAssigned' } + [pscustomobject]@{ telephoneNumber = '+15551000002'; numberType = 'DirectRouting'; assignmentTargetId = 'user-1'; assignmentStatus = 'userAssigned' } + [pscustomobject]@{ telephoneNumber = '+15551000003'; numberType = 'CallingPlan'; assignmentTargetId = 'user-2'; assignmentStatus = 'userAssigned' } + [pscustomobject]@{ telephoneNumber = '+15551000004'; numberType = 'DirectRouting'; assignmentTargetId = 'user-1'; assignmentStatus = 'unassigned' } + ) + } + } + + It 'reads the assignments from v1.0 and unassigns each of the user''s numbers on its own request' { + $Result = Remove-CIPPUserTeamsPhoneDIDs -UserID 'user-1' -Username 'pat@contoso.com' -TenantFilter 'contoso.com' + + Should -Invoke New-GraphGetRequest -Times 1 -Exactly -ParameterFilter { + $uri -eq 'https://graph.microsoft.com/v1.0/admin/teams/telephoneNumberManagement/numberAssignments' + } + Should -Invoke New-GraphPOSTRequest -Times 2 -Exactly -ParameterFilter { + $uri -eq 'https://graph.microsoft.com/v1.0/admin/teams/telephoneNumberManagement/numberAssignments/unassignNumber' + } + Should -Invoke New-GraphPOSTRequest -Times 1 -Exactly -ParameterFilter { $body -match '\+15551000001' } + Should -Invoke New-GraphPOSTRequest -Times 1 -Exactly -ParameterFilter { $body -match '\+15551000002' } + # An unassigned number and another user's number are left alone. + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly -ParameterFilter { $body -match '\+15551000003|\+15551000004' } + @($Result)[-1] | Should -Be "Completed processing 2 DIDs for user 'pat@contoso.com': 2 successful, 0 failed" + } + + It 'never uses a bulk request' { + $null = Remove-CIPPUserTeamsPhoneDIDs -UserID 'user-1' -TenantFilter 'contoso.com' + + Should -Invoke New-GraphBulkRequest -Times 0 -Exactly + } + + It 'normalises the number type for the action' { + $null = Remove-CIPPUserTeamsPhoneDIDs -UserID 'user-1' -TenantFilter 'contoso.com' + + Should -Invoke Get-CippTeamsNumberType -Times 2 -Exactly -ParameterFilter { $NumberType -eq 'DirectRouting' } + Should -Invoke New-GraphPOSTRequest -Times 2 -Exactly -ParameterFilter { $body -match 'directRouting' } + } + + It 'reports a failure per number and keeps going' { + Mock -CommandName New-GraphPOSTRequest -ParameterFilter { $body -match '\+15551000001' } -MockWith { throw 'Number is locked' } + + $Result = Remove-CIPPUserTeamsPhoneDIDs -UserID 'user-1' -Username 'pat@contoso.com' -TenantFilter 'contoso.com' + + @($Result)[0] | Should -BeLike "Failed to remove Teams Phone DID: '+15551000001'*boom" + @($Result)[1] | Should -BeLike "Successfully removed Teams Phone DID: '+15551000002'*" + @($Result)[-1] | Should -Be "Completed processing 2 DIDs for user 'pat@contoso.com': 1 successful, 1 failed" + } + + It 'returns a message and posts nothing when the user has no assigned numbers' { + $Result = Remove-CIPPUserTeamsPhoneDIDs -UserID 'user-99' -Username 'sam@contoso.com' -TenantFilter 'contoso.com' + + $Result | Should -Be "No Teams Phone DIDs found assigned to user: 'sam@contoso.com' - 'user-99'" + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly + } + + It 'returns a message when the tenant has no numbers at all' { + Mock -CommandName New-GraphGetRequest -MockWith { } + + $Result = Remove-CIPPUserTeamsPhoneDIDs -UserID 'user-1' -TenantFilter 'contoso.com' + + $Result | Should -Be 'No Teams Phone DIDs found in tenant' + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly + } +} diff --git a/Tests/Private/Repair-CIPPPIMRoleSettingsFloor.Tests.ps1 b/Tests/Private/Repair-CIPPPIMRoleSettingsFloor.Tests.ps1 new file mode 100644 index 0000000000000..a27de3b5df664 --- /dev/null +++ b/Tests/Private/Repair-CIPPPIMRoleSettingsFloor.Tests.ps1 @@ -0,0 +1,143 @@ +# Pester tests for Repair-CIPPPIMRoleSettingsFloor. +# +# Capturing a role's live PIM settings into a template must never store anything below the +# secure floor: offending values are raised to the closest value the floor allows, every raise +# is reported, and settings already at or above the floor pass through untouched. Whatever goes +# in, the repaired output must always satisfy Test-CIPPPIMRoleSettingsFloor. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/PIM/Repair-CIPPPIMRoleSettingsFloor.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/PIM/Test-CIPPPIMRoleSettingsFloor.ps1') + + function New-CapturedSettings { + param([hashtable]$Overrides = @{}) + $Settings = @{ + activationMaxDuration = 'PT4H' + activationRequires = 'MFA' + authenticationContextClaimValue = '' + activationRequiresJustification = $true + activationRequiresTicket = $false + activationRequiresApproval = $false + approvers = '' + eligibilityMaxDuration = 'P180D' + activeAssignmentMaxDuration = 'P90D' + activeAssignmentRequiresMfa = $true + activeAssignmentRequiresJustification = $true + notificationRecipients = '' + notificationLevel = 'All' + } + foreach ($Key in $Overrides.Keys) { $Settings[$Key] = $Overrides[$Key] } + [pscustomobject]$Settings + } +} + +Describe 'Repair-CIPPPIMRoleSettingsFloor' { + It 'passes compliant settings through untouched with no adjustments' { + $Input = New-CapturedSettings + $Result = Repair-CIPPPIMRoleSettingsFloor -Settings $Input + $Result.Adjustments.Count | Should -Be 0 + foreach ($Property in $Input.PSObject.Properties.Name) { + $Result.Settings.$Property | Should -Be $Input.$Property -Because $Property + } + } + + It 'raises permanent (null) durations to the floor maximum' { + $Result = Repair-CIPPPIMRoleSettingsFloor -Settings (New-CapturedSettings @{ + activationMaxDuration = $null + eligibilityMaxDuration = $null + activeAssignmentMaxDuration = $null + }) + $Result.Settings.activationMaxDuration | Should -Be 'PT24H' + $Result.Settings.eligibilityMaxDuration | Should -Be 'P365D' + $Result.Settings.activeAssignmentMaxDuration | Should -Be 'P365D' + $Result.Adjustments.Count | Should -Be 3 + ($Result.Adjustments -join ' ') | Should -Match 'permanent allowed' + } + + It 'lowers durations above the floor maximum instead of refusing them' { + $Result = Repair-CIPPPIMRoleSettingsFloor -Settings (New-CapturedSettings @{ + activationMaxDuration = 'P2D' + eligibilityMaxDuration = 'P10Y' + }) + $Result.Settings.activationMaxDuration | Should -Be 'PT24H' + $Result.Settings.eligibilityMaxDuration | Should -Be 'P365D' + $Result.Adjustments.Count | Should -Be 2 + } + + It 'requires MFA when activation demanded neither MFA nor an authentication context' { + $Result = Repair-CIPPPIMRoleSettingsFloor -Settings (New-CapturedSettings @{ activationRequires = 'None' }) + $Result.Settings.activationRequires | Should -Be 'MFA' + ($Result.Adjustments -join ' ') | Should -Match 'MFA' + } + + It 'keeps a valid authentication context in place of MFA' { + $Result = Repair-CIPPPIMRoleSettingsFloor -Settings (New-CapturedSettings @{ + activationRequires = 'AuthenticationContext' + authenticationContextClaimValue = 'c1' + }) + $Result.Adjustments.Count | Should -Be 0 + $Result.Settings.activationRequires | Should -Be 'AuthenticationContext' + $Result.Settings.authenticationContextClaimValue | Should -Be 'c1' + } + + It 'falls back to MFA when the authentication context has no usable claim value' { + $Result = Repair-CIPPPIMRoleSettingsFloor -Settings (New-CapturedSettings @{ + activationRequires = 'AuthenticationContext' + authenticationContextClaimValue = '' + }) + $Result.Settings.activationRequires | Should -Be 'MFA' + ($Result.Adjustments -join ' ') | Should -Match 'claim value' + } + + It 'enables missing justifications' { + $Result = Repair-CIPPPIMRoleSettingsFloor -Settings (New-CapturedSettings @{ + activationRequiresJustification = $false + activeAssignmentRequiresJustification = $false + }) + $Result.Settings.activationRequiresJustification | Should -BeTrue + $Result.Settings.activeAssignmentRequiresJustification | Should -BeTrue + $Result.Adjustments.Count | Should -Be 2 + } + + It 'disables approval when no approver could be captured' { + $Result = Repair-CIPPPIMRoleSettingsFloor -Settings (New-CapturedSettings @{ + activationRequiresApproval = $true + approvers = '' + }) + $Result.Settings.activationRequiresApproval | Should -BeFalse + ($Result.Adjustments -join ' ') | Should -Match 'approval disabled' + } + + It 'keeps approval with captured approvers' { + $Result = Repair-CIPPPIMRoleSettingsFloor -Settings (New-CapturedSettings @{ + activationRequiresApproval = $true + approvers = 'SOC Approvers' + }) + $Result.Adjustments.Count | Should -Be 0 + $Result.Settings.activationRequiresApproval | Should -BeTrue + $Result.Settings.approvers | Should -Be 'SOC Approvers' + } + + It 'drops notification recipients that are not e-mail addresses and fixes an invalid level' { + $Result = Repair-CIPPPIMRoleSettingsFloor -Settings (New-CapturedSettings @{ + notificationRecipients = 'soc@msp.example, not-an-address' + notificationLevel = 'Everything' + }) + $Result.Settings.notificationRecipients | Should -Be 'soc@msp.example' + $Result.Settings.notificationLevel | Should -Be 'All' + $Result.Adjustments.Count | Should -Be 2 + } + + It 'always produces settings that satisfy the secure floor' { + $Cases = @( + (New-CapturedSettings @{ activationMaxDuration = $null; activationRequires = 'None'; activationRequiresJustification = $false; eligibilityMaxDuration = $null; activeAssignmentMaxDuration = $null; activeAssignmentRequiresJustification = $false }) + (New-CapturedSettings @{ activationMaxDuration = 'garbage'; eligibilityMaxDuration = '-P1D'; notificationRecipients = 'nope'; notificationLevel = 'x' }) + (New-CapturedSettings @{ activationRequires = 'AuthenticationContext'; authenticationContextClaimValue = 'zzz'; activationRequiresApproval = $true; approvers = '' }) + ) + foreach ($Case in $Cases) { + $Result = Repair-CIPPPIMRoleSettingsFloor -Settings $Case + (Test-CIPPPIMRoleSettingsFloor -Settings $Result.Settings).Valid | Should -BeTrue + } + } +} diff --git a/Tests/Private/Resolve-CIPPSharePointRestContext.Tests.ps1 b/Tests/Private/Resolve-CIPPSharePointRestContext.Tests.ps1 new file mode 100644 index 0000000000000..3eb35a58c77cc --- /dev/null +++ b/Tests/Private/Resolve-CIPPSharePointRestContext.Tests.ps1 @@ -0,0 +1,46 @@ +# Pester tests for Resolve-CIPPSharePointRestContext + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Resolve-CIPPSharePointRestContext.ps1' + + function Get-SharePointAdminLink { param($Public, $tenantFilter) } + + . $FunctionPath +} + +Describe 'Resolve-CIPPSharePointRestContext' { + BeforeEach { + $script:SharePointInfo = [PSCustomObject]@{ + SharePointUrl = 'https://contoso.sharepoint.com' + AdminUrl = 'https://contoso-admin.sharepoint.com' + } + + Mock -CommandName Get-SharePointAdminLink -MockWith { $script:SharePointInfo } + } + + It 'builds scope, headers and site-scoped REST URIs from the admin link' { + $Result = Resolve-CIPPSharePointRestContext -TenantFilter 'contoso.onmicrosoft.com' -SiteUrl 'https://contoso.sharepoint.com/sites/HR/' + + $Result.Scope | Should -Be 'https://contoso.sharepoint.com/.default' + $Result.Headers.Accept | Should -Be 'application/json;odata=nometadata' + $Result.SiteUrl | Should -Be 'https://contoso.sharepoint.com/sites/HR' + $Result.BaseUri | Should -Be 'https://contoso.sharepoint.com/sites/HR/_api' + $Result.WebUri | Should -Be 'https://contoso.sharepoint.com/sites/HR/_api/web' + $Result.SharePointInfo | Should -Be $script:SharePointInfo + } + + It 'reuses SharePointInfo when supplied' { + Resolve-CIPPSharePointRestContext -TenantFilter 'contoso.onmicrosoft.com' -SiteUrl 'https://contoso.sharepoint.com/sites/HR' -SharePointInfo $script:SharePointInfo | Out-Null + + Should -Invoke Get-SharePointAdminLink -Times 0 -Exactly + } + + It 'looks up SharePointInfo when it was not supplied' { + Resolve-CIPPSharePointRestContext -TenantFilter 'contoso.onmicrosoft.com' -SiteUrl 'https://contoso.sharepoint.com/sites/HR' | Out-Null + + Should -Invoke Get-SharePointAdminLink -Times 1 -Exactly -ParameterFilter { + $Public -eq $false -and $tenantFilter -eq 'contoso.onmicrosoft.com' + } + } +} diff --git a/Tests/Private/Set-CIPPAsyncDeploymentStep.Tests.ps1 b/Tests/Private/Set-CIPPAsyncDeploymentStep.Tests.ps1 new file mode 100644 index 0000000000000..34b399be2993c --- /dev/null +++ b/Tests/Private/Set-CIPPAsyncDeploymentStep.Tests.ps1 @@ -0,0 +1,95 @@ +# Pester tests for Set-CIPPAsyncDeploymentStep. +# +# Offboarding steps run on different workers at the same time and all write into one Steps JSON +# property of the same row. The write is ETag-checked; when it is rejected the function must re-read +# the row so the retry carries the other worker's update instead of overwriting it. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/AsyncDeployment/Set-CIPPAsyncDeploymentStep.ps1' + if (-not (Test-Path $FunctionPath)) { throw "Could not locate Set-CIPPAsyncDeploymentStep.ps1 at $FunctionPath" } + + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter) } + function Update-CIPPAzDataTableEntity { param($Context, $Entity, $OperationType, [switch]$Force, $MaxRetries) } + + . $FunctionPath + + function New-Row { + param([string]$FirstStepStatus = 'pending') + [pscustomobject]@{ + PartitionKey = 'job-1' + RowKey = 'pat@contoso.com' + ETag = 'W/"1"' + Status = 'running' + Steps = (ConvertTo-Json -Compress -InputObject @( + @{ Title = 'Revoke all sessions'; Status = $FirstStepStatus; Message = '' } + @{ Title = 'Disable sign in'; Status = 'pending'; Message = '' } + )) + } + } +} + +Describe 'Set-CIPPAsyncDeploymentStep' { + BeforeEach { + $script:Written = [System.Collections.Generic.List[object]]::new() + Mock -CommandName Get-CIPPTable -MockWith { @{ Context = 'ctx' } } + Mock -CommandName Start-Sleep -MockWith { } + } + + It 'writes the step without -Force so a concurrent update is detected rather than overwritten' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { New-Row } + Mock -CommandName Update-CIPPAzDataTableEntity -MockWith { $script:Written.Add($Entity) } + + Set-CIPPAsyncDeploymentStep -JobId 'job-1' -Name 'pat@contoso.com' -StepIndex 1 -StepStatus 'succeeded' -Message 'Done' + + Should -Invoke Update-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { -not $Force } + $Steps = @($script:Written[0].Steps | ConvertFrom-Json) + $Steps[1].Status | Should -Be 'succeeded' + $Steps[1].Message | Should -Be 'Done' + $Steps[0].Status | Should -Be 'pending' + } + + It 're-reads the row and retries when the write is rejected, keeping the other worker''s step' { + # First read: nothing done yet. Second read, after the rejected write: another worker has + # finished step 0 in between, and that must survive. + $script:Reads = 0 + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + $script:Reads++ + if ($script:Reads -eq 1) { New-Row } else { New-Row -FirstStepStatus 'succeeded' } + } + $script:Writes = 0 + Mock -CommandName Update-CIPPAzDataTableEntity -MockWith { + $script:Writes++ + if ($script:Writes -eq 1) { throw 'Precondition Failed' } + $script:Written.Add($Entity) + } + + Set-CIPPAsyncDeploymentStep -JobId 'job-1' -Name 'pat@contoso.com' -StepIndex 1 -StepStatus 'running' -Message 'In progress' + + Should -Invoke Get-CIPPAzDataTableEntity -Times 2 -Exactly + Should -Invoke Update-CIPPAzDataTableEntity -Times 2 -Exactly + $Steps = @($script:Written[0].Steps | ConvertFrom-Json) + $Steps[0].Status | Should -Be 'succeeded' + $Steps[1].Status | Should -Be 'running' + } + + It 'gives up quietly after five rejected writes' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { New-Row } + Mock -CommandName Update-CIPPAzDataTableEntity -MockWith { throw 'Precondition Failed' } + + { Set-CIPPAsyncDeploymentStep -JobId 'job-1' -Name 'pat@contoso.com' -StepIndex 0 -StepStatus 'failed' -Message 'x' } | Should -Not -Throw + + Should -Invoke Update-CIPPAzDataTableEntity -Times 5 -Exactly + } + + It 'trims an oversized message so the row stays writable' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { New-Row } + Mock -CommandName Update-CIPPAzDataTableEntity -MockWith { $script:Written.Add($Entity) } + + Set-CIPPAsyncDeploymentStep -JobId 'job-1' -Name 'pat@contoso.com' -StepIndex 0 -StepStatus 'succeeded' -Message ('x' * 5000) + + $Steps = @($script:Written[0].Steps | ConvertFrom-Json) + $Steps[0].Message.Length | Should -BeLessThan 2100 + } +} diff --git a/Tests/Private/Set-CIPPFeatureFlag.Force.Tests.ps1 b/Tests/Private/Set-CIPPFeatureFlag.Force.Tests.ps1 new file mode 100644 index 0000000000000..3226e4af8a4aa --- /dev/null +++ b/Tests/Private/Set-CIPPFeatureFlag.Force.Tests.ps1 @@ -0,0 +1,44 @@ +# Hidden, system-managed feature flags (e.g. CertificateAuthentication) have AllowUserToggle=false so +# they never appear on the user settings page. The flows that own them (the Setup Wizard) set them +# with -Force. If -Force stopped bypassing the AllowUserToggle guard, the wizard could no longer +# enable certificate authentication - so the bypass is pinned here, along with the guard it bypasses. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function Get-CippTable { param($TableName) } + function Add-CIPPAzDataTableEntity { param($Context, $Entity, [switch]$Force) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Set-CIPPFeatureFlag.ps1') + + # Minimal FeatureFlags.json with a system-managed flag the user may not toggle. + $ConfigDir = Join-Path $TestDrive 'Config' + New-Item -ItemType Directory -Path $ConfigDir -Force | Out-Null + @( + @{ Id = 'SystemManagedFlag'; Name = 'System Managed'; Description = ''; Enabled = $false; AllowUserToggle = $false; Timers = @(); Endpoints = @(); Pages = @(); Hidden = $true } + ) | ConvertTo-Json -Depth 5 -AsArray | Set-Content -Path (Join-Path $ConfigDir 'FeatureFlags.json') + $env:CIPPRootPath = $TestDrive +} + +Describe 'Set-CIPPFeatureFlag -Force' { + BeforeEach { + Mock Get-CippTable { @{} } + Mock Add-CIPPAzDataTableEntity {} + } + + It 'refuses to set a non-user-toggleable flag without -Force' { + $Result = Set-CIPPFeatureFlag -Id 'SystemManagedFlag' -Enabled $true -WarningAction SilentlyContinue + + $Result | Should -BeFalse + Should -Invoke Add-CIPPAzDataTableEntity -Times 0 -Exactly + } + + It 'sets a non-user-toggleable flag when -Force is passed' { + $Result = Set-CIPPFeatureFlag -Id 'SystemManagedFlag' -Enabled $true -Force + + $Result | Should -BeTrue + Should -Invoke Add-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { + $Entity.RowKey -eq 'SystemManagedFlag' -and $Entity.Enabled -eq $true + } + } +} diff --git a/Tests/Private/Set-CIPPSAMCertificate.Tests.ps1 b/Tests/Private/Set-CIPPSAMCertificate.Tests.ps1 new file mode 100644 index 0000000000000..c84734e881577 --- /dev/null +++ b/Tests/Private/Set-CIPPSAMCertificate.Tests.ps1 @@ -0,0 +1,60 @@ +# Pester tests for Set-CIPPSAMCertificate +# Dev-mode storage writes the PFX into the DevSecrets Secret row. A certificate-only First Setup +# registers the certificate before that row exists, so the function must create it rather than throw. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Set-CIPPSAMCertificate.ps1' + + # Minimal stubs so Mock has commands to replace during tests + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter) } + function Add-AzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Update-CIPPSAMCertificateEnvCache { param($Name, $PfxBase64) } + function Get-CippKeyVaultName { } + + . $FunctionPath +} + +Describe 'Set-CIPPSAMCertificate dev-mode storage' { + BeforeEach { + $script:OriginalStorage = $env:AzureWebJobsStorage + $script:OriginalNonLocal = $env:NonLocalHostAzurite + $env:AzureWebJobsStorage = 'UseDevelopmentStorage=true' + $env:NonLocalHostAzurite = $null + + $script:Written = $null + Mock -CommandName Get-CIPPTable -MockWith { @{ Context = 'stub-table' } } + Mock -CommandName Add-AzDataTableEntity -MockWith { $script:Written = $Entity } + Mock -CommandName Update-CIPPSAMCertificateEnvCache -MockWith { } + } + + AfterEach { + $env:AzureWebJobsStorage = $script:OriginalStorage + $env:NonLocalHostAzurite = $script:OriginalNonLocal + } + + It 'creates the Secret row when DevSecrets is empty (fresh certificate-only setup)' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $null } + + $Result = Set-CIPPSAMCertificate -PfxBase64 'cGZ4' + + $Result.StorageMode | Should -Be 'DevTable' + Should -Invoke -CommandName Add-AzDataTableEntity -Times 1 -Exactly + $script:Written.PartitionKey | Should -Be 'Secret' + $script:Written.RowKey | Should -Be 'Secret' + $script:Written.SAMCertificate | Should -Be 'cGZ4' + } + + It 'updates the existing Secret row without touching its other properties' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + [PSCustomObject]@{ PartitionKey = 'Secret'; RowKey = 'Secret'; tenantid = 'tenant-a'; applicationid = 'app-a' } + } + + $null = Set-CIPPSAMCertificate -PfxBase64 'bmV3' + + $script:Written.tenantid | Should -Be 'tenant-a' + $script:Written.applicationid | Should -Be 'app-a' + $script:Written.SAMCertificate | Should -Be 'bmV3' + } +} diff --git a/Tests/Private/Start-UserSyncTimer.Tests.ps1 b/Tests/Private/Start-UserSyncTimer.Tests.ps1 new file mode 100644 index 0000000000000..7bea3fd39af86 --- /dev/null +++ b/Tests/Private/Start-UserSyncTimer.Tests.ps1 @@ -0,0 +1,183 @@ +# Pester tests for the stale-role self-heal in Start-UserSyncTimer (the 15-minute user sync). +# +# The sync derives each user's auto-roles from the AccessRoleGroups table. When a role's +# group mapping survives (a migration, say) but its definition in CustomRoles does not, the +# user is left carrying an auto-role that Test-CIPPAccess cannot resolve - which denies every +# request, base role included. The fix makes the sync skip mappings whose role no longer +# exists, so the orphaned auto-role drops off every affected user on the next run instead of +# being re-stamped forever. A failed CustomRoles lookup must NOT be read as "no roles exist" +# (that would strip every custom role from everyone), so it degrades to pruning nothing. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Start-UserSyncTimer.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $FunctionPath) { throw 'Could not locate Start-UserSyncTimer.ps1 under Modules/' } + + # Shims so Mock has real commands to intercept. Get-CippTable stays a plain shim - it just + # tags each table so the storage mocks can route on TableName. + function Get-CippTable { param($TableName) @{ TableName = $TableName } } + function Get-CIPPAzDataTableEntity { param($TableName, $Filter, $Property) } + function Add-CIPPAzDataTableEntity { param($TableName, $Entity, [switch]$Force) } + function Remove-CIPPAzDataTableEntity { param($TableName, $Entity, [switch]$Force) } + function New-GraphGetRequest { param($uri, $NoAuthCheck, $AsApp) } + function Write-LogMessage { param($API, $tenant, $message, $sev, $LogData) } + function Get-CippException { param($Exception) @{ NormalizedError = "$Exception" } } + + . $FunctionPath +} + +Describe 'Start-UserSyncTimer - stale role self-heal' { + BeforeEach { + # editor is a base role and maps to its group; 'service team' maps to a group too but + # has no CustomRoles definition on this instance - it is the orphan to prune. + $script:AccessGroups = @( + [pscustomobject]@{ PartitionKey = 'AccessRoleGroups'; RowKey = 'editor'; GroupId = 'grp-editor'; GroupName = 'SG-APP-CIPP-editor' } + [pscustomobject]@{ PartitionKey = 'AccessRoleGroups'; RowKey = 'service team'; GroupId = 'grp-serviceteam'; GroupName = 'SG-APP-CIPP-serviceteam' } + ) + # Only servicedesk is actually defined - 'service team' is deliberately absent. + $script:CustomRoles = @( + [pscustomobject]@{ PartitionKey = 'CustomRoles'; RowKey = 'servicedesk' } + ) + $script:CustomRolesThrow = $false + # The affected user already carries the phantom role from a prior (pre-fix) run. + $script:ExistingUsers = @( + [pscustomobject]@{ + PartitionKey = 'User' + RowKey = 'aaron.macleod@centaris.com' + Roles = '["editor","service team"]' + AutoRoles = '["editor","service team"]' + ManualRoles = '[]' + Source = 'Auto' + LastSync = '2026-08-17T00:00:00.0000000Z' + } + ) + + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Add-CIPPAzDataTableEntity -MockWith { } + Mock -CommandName Remove-CIPPAzDataTableEntity -MockWith { } + + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + switch ($TableName) { + 'AccessRoleGroups' { return $script:AccessGroups } + 'CustomRoles' { if ($script:CustomRolesThrow) { throw 'storage unavailable' }; return $script:CustomRoles } + 'allowedUsers' { return $script:ExistingUsers } + default { return @() } + } + } + + # Both groups contain the same single member. + Mock -CommandName New-GraphGetRequest -MockWith { + if ($uri -like '*grp-editor*' -or $uri -like '*grp-serviceteam*') { + return @([pscustomobject]@{ '@odata.type' = '#microsoft.graph.user'; userPrincipalName = 'Aaron.MacLeod@centaris.com'; accountEnabled = $true }) + } + return @() + } + } + + It 'never queries the group whose role has no definition' { + $null = Start-UserSyncTimer + + Should -Invoke New-GraphGetRequest -Times 0 -Exactly -ParameterFilter { $uri -like '*grp-serviceteam*' } + Should -Invoke New-GraphGetRequest -Times 1 -Exactly -ParameterFilter { $uri -like '*grp-editor*' } + } + + It 'rewrites the affected user with the orphaned auto-role stripped' { + $null = Start-UserSyncTimer + + Should -Invoke Add-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { + $TableName -eq 'allowedUsers' -and + $Entity.RowKey -eq 'aaron.macleod@centaris.com' -and + $Entity.Roles -eq '["editor"]' -and + $Entity.AutoRoles -eq '["editor"]' + } + } + + It 'logs which orphaned role it pruned, on the run that prunes it' { + $null = Start-UserSyncTimer + + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { + $sev -eq 'Info' -and $message -like '*Pruned auto-role*' -and $message -like '*service team*' + } + } + + It 'keeps the role when the CustomRoles lookup fails, rather than stripping everything' { + $script:CustomRolesThrow = $true + + $null = Start-UserSyncTimer + + # Unknown validity => prune nothing: the phantom group is still queried and the role kept. + Should -Invoke New-GraphGetRequest -Times 1 -Exactly -ParameterFilter { $uri -like '*grp-serviceteam*' } + Should -Invoke Add-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { + $TableName -eq 'allowedUsers' -and $Entity.Roles -eq '["editor","service team"]' + } + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { + $sev -eq 'Warning' -and $message -like '*could not load custom roles*' + } + } +} + +# B2B guests carry a UPN like user_home.com#EXT#@tenant.onmicrosoft.com. '#' is illegal in a Table +# Storage RowKey (the OutOfRangeInput crash in issue #458), and with a multi-tenant sign-in the token +# presents the guest's home email (their 'mail'), not the #EXT# UPN. The sync must key the row on a +# clean, matchable identity so the write succeeds AND the auth layer can look the guest up. +Describe 'Start-UserSyncTimer - B2B guest keying' { + BeforeEach { + $script:AccessGroups = @( + [pscustomobject]@{ PartitionKey = 'AccessRoleGroups'; RowKey = 'editor'; GroupId = 'grp-editor'; GroupName = 'SG-APP-CIPP-editor' } + ) + $script:CustomRoles = @() + $script:ExistingUsers = @() + $script:GuestMember = $null + + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Add-CIPPAzDataTableEntity -MockWith { } + Mock -CommandName Remove-CIPPAzDataTableEntity -MockWith { } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + switch ($TableName) { + 'AccessRoleGroups' { return $script:AccessGroups } + 'CustomRoles' { return $script:CustomRoles } + 'allowedUsers' { return $script:ExistingUsers } + default { return @() } + } + } + Mock -CommandName New-GraphGetRequest -MockWith { + if ($uri -like '*grp-editor*') { return @($script:GuestMember) } + return @() + } + } + + It 'keys a guest on their mail (home email), never the #EXT# UPN' { + $script:GuestMember = [pscustomobject]@{ + '@odata.type' = '#microsoft.graph.user' + userPrincipalName = 'zr-dev_dev.johnwduprey.com#EXT#@contoso.onmicrosoft.com' + mail = 'ZR-Dev@dev.johnwduprey.com' + accountEnabled = $true + } + + $null = Start-UserSyncTimer + + Should -Invoke Add-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { + $TableName -eq 'allowedUsers' -and + $Entity.RowKey -eq 'zr-dev@dev.johnwduprey.com' -and + $Entity.RowKey -notmatch '#' + } + } + + It 'decodes the #EXT# UPN back to the invited address when mail is missing' { + $script:GuestMember = [pscustomobject]@{ + '@odata.type' = '#microsoft.graph.user' + userPrincipalName = 'bob_smith_fabrikam.com#EXT#@contoso.onmicrosoft.com' + mail = $null + accountEnabled = $true + } + + $null = Start-UserSyncTimer + + Should -Invoke Add-CIPPAzDataTableEntity -Times 1 -Exactly -ParameterFilter { + $TableName -eq 'allowedUsers' -and + $Entity.RowKey -eq 'bob_smith@fabrikam.com' -and + $Entity.RowKey -notmatch '#' + } + } +} diff --git a/Tests/Private/Test-CIPPAccess.BlockedEndpoints.Tests.ps1 b/Tests/Private/Test-CIPPAccess.BlockedEndpoints.Tests.ps1 new file mode 100644 index 0000000000000..56feb718ecd9a --- /dev/null +++ b/Tests/Private/Test-CIPPAccess.BlockedEndpoints.Tests.ps1 @@ -0,0 +1,219 @@ +# Regression tests for tenant-scoped BlockedEndpoints in Test-CIPPAccess. +# +# BlockedEndpoints used to throw before tenant resolution, so a role scoped to T1 that blocked an +# endpoint also blocked that endpoint on T2. Deny still wins, but only when the blocking role's +# tenant scope covers the request target. +# +# Driven through the APIClient path (aad idp + GUID principal name). + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $AuthDir = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Authentication' + $FunctionPath = Join-Path $AuthDir 'Test-CIPPAccess.ps1' + $ScopeHelperPath = Join-Path $AuthDir 'Test-CippRoleTenantScope.ps1' + + function Get-CippApiClient { param($AppId) } + function Test-IpInRange { param($IPAddress, $Range) $false } + function Get-CIPPRolePermissions { param($Role) } + function Get-Tenants { param([switch]$IncludeErrors) @() } + function Get-CippAccessScopeRule { param($Role) } + function Expand-CIPPTenantGroups { param($TenantFilter) @() } + + . $ScopeHelperPath + . $FunctionPath + + $script:CIPPFunctionPermissions = @{ + 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } + } + $script:CIPPBaseRoles = [pscustomobject]@{} + + $script:Tenant1 = [pscustomobject]@{ customerId = 'tenant-1'; defaultDomainName = 't1.example.com' } + $script:Tenant2 = [pscustomobject]@{ customerId = 'tenant-2'; defaultDomainName = 't2.example.com' } + + function New-EndpointRequest { + param( + [string]$TenantId, + [object]$TenantFilterBody + ) + $Body = if ($PSBoundParameters.ContainsKey('TenantFilterBody')) { + @{ tenantFilter = $TenantFilterBody } + } elseif ($TenantId) { + @{ tenantFilter = $TenantId } + } else { + @{} + } + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ExecResetPass' } + Headers = @{ + 'x-ms-client-principal-idp' = 'aad' + 'x-ms-client-principal-name' = '11111111-1111-1111-1111-111111111111' + 'x-forwarded-for' = '1.2.3.4' + } + Query = @{} + Body = $Body + } + } + + function New-RoleObject { + param( + [string]$Name, + [string[]]$Permissions = @('Identity.User.ReadWrite'), + [object[]]$AllowedTenants = @('AllTenants'), + [object[]]$BlockedTenants = @(), + [string[]]$BlockedEndpoints = @() + ) + [pscustomobject]@{ + Role = $Name + Permissions = $Permissions + AllowedTenants = $AllowedTenants + BlockedTenants = $BlockedTenants + BlockedEndpoints = $BlockedEndpoints + } + } +} + +Describe 'Test-CIPPAccess BlockedEndpoints tenant scoping' { + BeforeEach { + Mock -CommandName Get-Tenants -MockWith { @($script:Tenant1, $script:Tenant2) } + Mock -CommandName Expand-CIPPTenantGroups -MockWith { @() } + } + + It 'blocks when AllTenants role lists the endpoint' { + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'TestApp'; Role = @('allrole'); IPRange = @('Any') } + } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + New-RoleObject -Name 'allrole' -BlockedEndpoints @('ExecResetPass') + } + + { Test-CIPPAccess -Request (New-EndpointRequest -TenantId 'tenant-1') } | + Should -Throw -ExpectedMessage '*has blocked this endpoint: ExecResetPass*' + } + + It 'blocks when scoped role covers the request tenant' { + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'TestApp'; Role = @('t1role'); IPRange = @('Any') } + } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + New-RoleObject -Name 't1role' -AllowedTenants @('tenant-1') -BlockedEndpoints @('ExecResetPass') + } + + { Test-CIPPAccess -Request (New-EndpointRequest -TenantId 'tenant-1') } | + Should -Throw -ExpectedMessage '*has blocked this endpoint: ExecResetPass*' + } + + It 'allows T2 when RoleA blocks on T1 and RoleB grants T2 without a block' { + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'TestApp'; Role = @('roleA', 'roleB'); IPRange = @('Any') } + } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + param($Role) + switch ($Role) { + 'roleA' { + New-RoleObject -Name 'roleA' -AllowedTenants @('tenant-1') -BlockedEndpoints @('ExecResetPass') + } + 'roleB' { + New-RoleObject -Name 'roleB' -AllowedTenants @('tenant-2') -BlockedEndpoints @() + } + default { throw "Unexpected role $Role" } + } + } + + $result = Test-CIPPAccess -Request (New-EndpointRequest -TenantId 'tenant-2') + $result | Should -BeTrue + } + + It 'denies out-of-scope tenant with tenant message when only a blocking scoped role is held' { + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'TestApp'; Role = @('t1role'); IPRange = @('Any') } + } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + New-RoleObject -Name 't1role' -AllowedTenants @('tenant-1') -BlockedEndpoints @('ExecResetPass') + } + + { Test-CIPPAccess -Request (New-EndpointRequest -TenantId 'tenant-2') } | + Should -Throw -ExpectedMessage '*Access to this tenant is not allowed*' + } + + It 'allows when role grants the endpoint with no block and tenant is in scope' { + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'TestApp'; Role = @('t1role'); IPRange = @('Any') } + } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + New-RoleObject -Name 't1role' -AllowedTenants @('tenant-1') -BlockedEndpoints @() + } + + $result = Test-CIPPAccess -Request (New-EndpointRequest -TenantId 'tenant-1') + $result | Should -BeTrue + } + + It 'fail-closes the block when tenantFilter does not map to a known tenant' { + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'TestApp'; Role = @('t1role'); IPRange = @('Any') } + } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + New-RoleObject -Name 't1role' -AllowedTenants @('tenant-1') -BlockedEndpoints @('ExecResetPass') + } + + { Test-CIPPAccess -Request (New-EndpointRequest -TenantId 'tenant-unknown') } | + Should -Throw -ExpectedMessage '*has blocked this endpoint: ExecResetPass*' + } + + It 'fail-closes the block when the request has no tenantFilter (does not invent partner TenantID)' { + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'TestApp'; Role = @('t1role'); IPRange = @('Any') } + } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + New-RoleObject -Name 't1role' -AllowedTenants @('tenant-1') -BlockedEndpoints @('ExecResetPass') + } + + $env:TenantID = 'partner-tenant-id' + { Test-CIPPAccess -Request (New-EndpointRequest) } | + Should -Throw -ExpectedMessage '*has blocked this endpoint: ExecResetPass*' + } + + It 'blocks a granted group-shaped tenantFilter when the endpoint is blocked' { + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'TestApp'; Role = @('grouprole'); IPRange = @('Any') } + } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + New-RoleObject -Name 'grouprole' ` + -AllowedTenants @([pscustomobject]@{ type = 'Group'; value = 'group-allowed'; label = 'Allowed Group' }) ` + -BlockedEndpoints @('ExecResetPass') + } + + $GroupBody = [pscustomobject]@{ type = 'Group'; value = 'group-allowed'; label = 'Allowed Group' } + { Test-CIPPAccess -Request (New-EndpointRequest -TenantFilterBody $GroupBody) } | + Should -Throw -ExpectedMessage '*has blocked this endpoint: ExecResetPass*' + } + + It 'does not apply the block for an ungranted group; allow path denies the group' { + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'TestApp'; Role = @('grouprole'); IPRange = @('Any') } + } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + New-RoleObject -Name 'grouprole' ` + -AllowedTenants @([pscustomobject]@{ type = 'Group'; value = 'group-allowed'; label = 'Allowed Group' }) ` + -BlockedEndpoints @('ExecResetPass') + } + + $GroupBody = [pscustomobject]@{ type = 'Group'; value = 'group-notgranted'; label = 'Other Group' } + { Test-CIPPAccess -Request (New-EndpointRequest -TenantFilterBody $GroupBody) } | + Should -Throw -ExpectedMessage '*Access to this tenant is not allowed*' + } + + It 'does not block when the role lists BlockedEndpoints but does not grant the permission' { + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'TestApp'; Role = @('norole'); IPRange = @('Any') } + } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + New-RoleObject -Name 'norole' ` + -Permissions @('Identity.User.Read') ` + -AllowedTenants @('AllTenants') ` + -BlockedEndpoints @('ExecResetPass') + } + + { Test-CIPPAccess -Request (New-EndpointRequest -TenantId 'tenant-1') } | + Should -Throw -ExpectedMessage '*required permission: Identity.User.ReadWrite*' + } +} diff --git a/Tests/Private/Test-CIPPAccess.TenantGroupAuth.Tests.ps1 b/Tests/Private/Test-CIPPAccess.TenantGroupAuth.Tests.ps1 new file mode 100644 index 0000000000000..4b817dee8e107 --- /dev/null +++ b/Tests/Private/Test-CIPPAccess.TenantGroupAuth.Tests.ps1 @@ -0,0 +1,87 @@ +# Regression tests for the tenant-group authorization gap in Test-CIPPAccess. +# +# A requested tenant GROUP ({type:'Group', value:}) used to resolve to a null $Tenant and fall +# through to an unconditional allow, so a restricted role could target a group it was never granted. +# The fix authorizes a group request by group identity: allow iff the requested group GUID is one of +# the role's granted group entries; otherwise hard-deny. Members are never expanded for the decision. +# +# Driven through the APIClient path (aad idp + GUID principal name), which skips the user/impersonation +# branch and reaches the per-endpoint permission evaluation with a restricted role. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $AuthDir = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Authentication' + $FunctionPath = Join-Path $AuthDir 'Test-CIPPAccess.ps1' + $ScopeHelperPath = Join-Path $AuthDir 'Test-CippRoleTenantScope.ps1' + + # Stubs for the surface the APIClient path touches. + function Get-CippApiClient { param($AppId) } + function Test-IpInRange { param($IPAddress, $Range) $false } + function Get-CIPPRolePermissions { param($Role) } + function Get-Tenants { param([switch]$IncludeErrors) @() } + function Get-CippAccessScopeRule { param($Role) } + function Expand-CIPPTenantGroups { param($TenantFilter) @() } + + . $ScopeHelperPath + . $FunctionPath + + # Bypass the config-file reads by pre-seeding the runspace caches the function guards on. + $script:CIPPFunctionPermissions = @{ + 'Invoke-AddScheduledItem' = @{ Role = 'CIPP.Scheduler.ReadWrite'; Functionality = 'Entrypoint' } + } + $script:CIPPBaseRoles = [pscustomobject]@{} + + # A request from an API client, scoped by a restricted custom role, asking to act on a group. + function New-GroupRequest { + param([string]$RequestedGroupId) + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'AddScheduledItem' } + Headers = @{ + 'x-ms-client-principal-idp' = 'aad' + 'x-ms-client-principal-name' = '11111111-1111-1111-1111-111111111111' + 'x-forwarded-for' = '1.2.3.4' + } + Query = @{} + Body = @{ tenantFilter = [pscustomobject]@{ type = 'Group'; value = $RequestedGroupId; label = 'Requested Group' } } + } + } + + # The restricted role grants exactly one group ('group-allowed') and nothing else. + function Set-RestrictedRoleMocks { + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'TestApp'; Role = @('grouprole'); IPRange = @('Any') } + } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ + Role = 'grouprole' + Permissions = @('CIPP.Scheduler.ReadWrite') + AllowedTenants = @([pscustomobject]@{ type = 'Group'; value = 'group-allowed'; label = 'Allowed Group' }) + BlockedTenants = @() + BlockedEndpoints = @() + } + } + Mock -CommandName Get-Tenants -MockWith { @() } + } +} + +Describe 'Test-CIPPAccess tenant-group authorization' { + BeforeEach { Set-RestrictedRoleMocks } + + It 'allows a request for a group the role was granted' { + $result = Test-CIPPAccess -Request (New-GroupRequest -RequestedGroupId 'group-allowed') + $result | Should -BeTrue + } + + It 'denies a request for a group the role was NOT granted' { + { Test-CIPPAccess -Request (New-GroupRequest -RequestedGroupId 'group-notgranted') } | + Should -Throw -ExpectedMessage '*not allowed*' + } + + It 'authorizes by group identity, never by expanding members' { + # If the decision expanded members it would have to call Expand-CIPPTenantGroups; it must not. + Mock -CommandName Expand-CIPPTenantGroups -MockWith { throw 'membership must not be expanded for the access decision' } + $result = Test-CIPPAccess -Request (New-GroupRequest -RequestedGroupId 'group-allowed') + $result | Should -BeTrue + Should -Invoke -CommandName Expand-CIPPTenantGroups -Times 0 + } +} diff --git a/Tests/Private/Test-CIPPPIMRoleSettingsFloor.Tests.ps1 b/Tests/Private/Test-CIPPPIMRoleSettingsFloor.Tests.ps1 new file mode 100644 index 0000000000000..691e9b94237a3 --- /dev/null +++ b/Tests/Private/Test-CIPPPIMRoleSettingsFloor.Tests.ps1 @@ -0,0 +1,197 @@ +# Pester tests for the PIM role settings secure floor and its normaliser. +# +# The floor is what stops a PIM role settings template - saved through the editor, hand-edited in +# the templates table, or deployed by the PIMRoleSettings standard - from weakening a tenant's +# privileged access. Templates below it are rejected, never clamped, so each rule gets a test +# proving it rejects, plus the one case that is allowed-but-warned (activation above 8h, up to 24h). + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/PIM/Test-CIPPPIMRoleSettingsFloor.ps1') + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/PIM/ConvertTo-CIPPPIMRoleSettings.ps1') + + function New-SecureSettings { + param([hashtable]$Override = @{}) + $Settings = @{ + activationMaxDuration = 'PT8H' + activationRequires = 'MFA' + authenticationContextClaimValue = '' + activationRequiresJustification = $true + activationRequiresTicket = $false + activationRequiresApproval = $false + approvers = '' + eligibilityMaxDuration = 'P365D' + activeAssignmentMaxDuration = 'P180D' + activeAssignmentRequiresMfa = $true + activeAssignmentRequiresJustification = $true + notificationRecipients = '' + notificationLevel = 'All' + } + foreach ($Key in $Override.Keys) { $Settings[$Key] = $Override[$Key] } + return ConvertTo-CIPPPIMRoleSettings -InputObject $Settings + } +} + +Describe 'Test-CIPPPIMRoleSettingsFloor' { + It 'accepts the secure defaults with no warnings' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings) + $Result.Valid | Should -BeTrue + $Result.Errors | Should -BeNullOrEmpty + $Result.Warnings | Should -BeNullOrEmpty + } + + It 'rejects a null settings object' { + (Test-CIPPPIMRoleSettingsFloor -Settings $null).Valid | Should -BeFalse + } + + Context 'activation' { + It 'warns, but allows, an activation maximum between 8h and 24h' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ activationMaxDuration = 'PT12H' }) + $Result.Valid | Should -BeTrue + $Result.Warnings | Should -Match 'exceeds the recommended PT8H' + } + + It 'allows exactly 24h' { + (Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ activationMaxDuration = 'PT24H' })).Valid | Should -BeTrue + } + + It 'rejects an activation maximum above 24h' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ activationMaxDuration = 'PT25H' }) + $Result.Valid | Should -BeFalse + $Result.Errors | Should -Match 'exceeds the maximum of PT24H' + } + + It 'rejects an activation with no expiration' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ activationMaxDuration = $null }) + # The normaliser substitutes the secure default for an absent value, so feed the + # canonical object directly to simulate a policy that does not require expiration. + $Settings = New-SecureSettings + $Settings.activationMaxDuration = $null + $Result = Test-CIPPPIMRoleSettingsFloor -Settings $Settings + $Result.Valid | Should -BeFalse + $Result.Errors | Should -Match 'Role activation must expire' + } + + It 'rejects activation without MFA or an authentication context' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ activationRequires = 'None' }) + $Result.Valid | Should -BeFalse + $Result.Errors | Should -Match 'must require MFA or an authentication context' + } + + It 'accepts an authentication context with a claim value in place of MFA' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ activationRequires = 'AuthenticationContext'; authenticationContextClaimValue = 'c1' }) + $Result.Valid | Should -BeTrue + } + + It 'rejects an authentication context without a claim value' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ activationRequires = 'AuthenticationContext' }) + $Result.Valid | Should -BeFalse + $Result.Errors | Should -Match 'claim value' + } + + It 'rejects activation without a justification' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ activationRequiresJustification = $false }) + $Result.Valid | Should -BeFalse + $Result.Errors | Should -Match 'Role activation must require a justification' + } + + It 'rejects approval without approvers' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ activationRequiresApproval = $true }) + $Result.Valid | Should -BeFalse + $Result.Errors | Should -Match 'no approvers' + } + + It 'accepts approval with approvers' { + (Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ activationRequiresApproval = $true; approvers = 'Security Team' })).Valid | Should -BeTrue + } + } + + Context 'eligibility and active assignments' { + It 'rejects eligibility beyond a year' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ eligibilityMaxDuration = 'P400D' }) + $Result.Valid | Should -BeFalse + $Result.Errors | Should -Match 'Eligible assignments.*exceeds the maximum of P365D' + } + + It 'rejects eligibility with no expiration (permanent eligibility)' { + $Settings = New-SecureSettings + $Settings.eligibilityMaxDuration = '' + $Result = Test-CIPPPIMRoleSettingsFloor -Settings $Settings + $Result.Valid | Should -BeFalse + $Result.Errors | Should -Match 'Eligible assignments must expire' + } + + It 'rejects active assignments beyond a year' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ activeAssignmentMaxDuration = 'P2Y' }) + $Result.Valid | Should -BeFalse + $Result.Errors | Should -Match 'Active assignments.*exceeds the maximum of P365D' + } + + It 'rejects active assignments with no expiration (permanent active)' { + $Settings = New-SecureSettings + $Settings.activeAssignmentMaxDuration = $null + $Result = Test-CIPPPIMRoleSettingsFloor -Settings $Settings + $Result.Valid | Should -BeFalse + $Result.Errors | Should -Match 'Active assignments must expire' + } + + It 'rejects active assignments without a justification' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ activeAssignmentRequiresJustification = $false }) + $Result.Valid | Should -BeFalse + $Result.Errors | Should -Match 'active assignment must require a justification' + } + + It 'reports every violation at once' { + $Settings = New-SecureSettings @{ activationRequires = 'None'; activationRequiresJustification = $false; eligibilityMaxDuration = 'P2Y' } + $Result = Test-CIPPPIMRoleSettingsFloor -Settings $Settings + $Result.Errors.Count | Should -Be 3 + } + } + + Context 'notifications' { + It 'rejects an invalid recipient address' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ notificationRecipients = 'soc@contoso.com, not-an-address' }) + $Result.Valid | Should -BeFalse + $Result.Errors | Should -Match "'not-an-address' is not a valid" + } + + It 'rejects an unknown notification level when recipients are set' { + $Result = Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ notificationRecipients = 'soc@contoso.com'; notificationLevel = 'Everything' }) + $Result.Valid | Should -BeFalse + $Result.Errors | Should -Match 'notificationLevel' + } + + It 'accepts valid recipients' { + (Test-CIPPPIMRoleSettingsFloor -Settings (New-SecureSettings @{ notificationRecipients = 'soc@contoso.com; ops@contoso.com'; notificationLevel = 'Critical' })).Valid | Should -BeTrue + } + } +} + +Describe 'ConvertTo-CIPPPIMRoleSettings' { + It 'unwraps autoComplete label/value objects and string booleans from a request body' { + $Body = [pscustomobject]@{ + activationMaxDuration = [pscustomobject]@{ label = '4 hours'; value = 'PT4H' } + activationRequires = @{ label = 'MFA'; value = 'MFA' } + activationRequiresJustification = 'true' + activationRequiresTicket = 'false' + notificationRecipients = @('a@contoso.com', [pscustomobject]@{ label = 'b@contoso.com'; value = 'b@contoso.com' }) + } + $Settings = ConvertTo-CIPPPIMRoleSettings -InputObject $Body + $Settings.activationMaxDuration | Should -Be 'PT4H' + $Settings.activationRequires | Should -Be 'MFA' + $Settings.activationRequiresJustification | Should -BeTrue + $Settings.activationRequiresTicket | Should -BeFalse + $Settings.notificationRecipients | Should -Be 'a@contoso.com, b@contoso.com' + } + + It 'applies the secure defaults for missing properties' { + $Settings = ConvertTo-CIPPPIMRoleSettings -InputObject @{} + $Settings.activationMaxDuration | Should -Be 'PT8H' + $Settings.activationRequires | Should -Be 'MFA' + $Settings.activationRequiresJustification | Should -BeTrue + $Settings.eligibilityMaxDuration | Should -Be 'P365D' + $Settings.activeAssignmentMaxDuration | Should -Be 'P180D' + $Settings.activeAssignmentRequiresJustification | Should -BeTrue + (Test-CIPPPIMRoleSettingsFloor -Settings $Settings).Valid | Should -BeTrue + } +} diff --git a/Tests/Private/Test-CIPPSharePointLibraryCopyEligible.Tests.ps1 b/Tests/Private/Test-CIPPSharePointLibraryCopyEligible.Tests.ps1 new file mode 100644 index 0000000000000..dfcab1c5ee499 --- /dev/null +++ b/Tests/Private/Test-CIPPSharePointLibraryCopyEligible.Tests.ps1 @@ -0,0 +1,26 @@ +# Pester tests for Test-CIPPSharePointLibraryCopyEligible.ps1 + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Test-CIPPSharePointLibraryCopyEligible.ps1' + if (-not (Test-Path $FunctionPath)) { throw "Could not locate $FunctionPath" } + . $FunctionPath +} + +Describe 'Test-CIPPSharePointLibraryCopyEligible' { + It 'accepts a normal document library' { + (Test-CIPPSharePointLibraryCopyEligible -Template 'documentLibrary' -Title 'HR Docs' -Name 'HRDocs').Eligible | Should -Be $true + } + + It 'rejects Site Pages template' { + (Test-CIPPSharePointLibraryCopyEligible -Template 'webPageLibrary' -Title 'Site Pages').Eligible | Should -Be $false + } + + It 'rejects Site Assets by title' { + (Test-CIPPSharePointLibraryCopyEligible -Template 'documentLibrary' -Title 'Site Assets').Eligible | Should -Be $false + } + + It 'rejects SiteAssets internal name' { + (Test-CIPPSharePointLibraryCopyEligible -Template 'documentLibrary' -Title 'Docs' -Name 'SiteAssets').Eligible | Should -Be $false + } +} diff --git a/Tests/Private/Update-CIPPSharePointLibraryCopyStatus.Tests.ps1 b/Tests/Private/Update-CIPPSharePointLibraryCopyStatus.Tests.ps1 new file mode 100644 index 0000000000000..3633140a6dd90 --- /dev/null +++ b/Tests/Private/Update-CIPPSharePointLibraryCopyStatus.Tests.ps1 @@ -0,0 +1,111 @@ +# Pester tests for Update-CIPPSharePointLibraryCopyStatus + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $UpdatePath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Update-CIPPSharePointLibraryCopyStatus.ps1' + if (-not (Test-Path $UpdatePath)) { throw "Could not locate $UpdatePath" } + + function Set-CIPPSharePointLibraryCopyOperation { param([string]$TenantFilter, [string]$OperationId, [hashtable]$Entity) } + function Get-CIPPSharePointLibraryCopyOperation { param([string]$TenantFilter, [string]$OperationId) } + function Get-CIPPSharePointCopyJobProgress { param([string]$TenantFilter, [string]$SourceSiteUrl, $CopyJobInfo) } + + . $UpdatePath +} + +Describe 'Update-CIPPSharePointLibraryCopyStatus' { + BeforeEach { + $script:ProgressCalls = 0 + + Mock Get-CIPPSharePointLibraryCopyOperation { + [PSCustomObject]@{ + OperationId = $OperationId + SourceSiteUrl = 'https://contoso.sharepoint.com/sites/a' + SourceSiteName = 'Site A' + SourceLibraryName = 'Docs' + DestSiteName = 'Site B' + DestLibraryName = 'Archive' + StartedBy = 'admin' + Status = 'Processing' + JobHandleCount = 1 + Expiry = ([DateTime]::UtcNow.AddDays(7)).ToString('o') + CopyJobInfos = @([PSCustomObject]@{ JobId = 'job-1'; JobQueueUri = 'https://queue'; EncryptionKey = 'key' }) + HandleStates = @([PSCustomObject]@{ Status = 'Queued'; IsComplete = $false }) + SanitizedSnapshot = $null + } + } + + Mock Get-CIPPSharePointCopyJobProgress { + $script:ProgressCalls++ + [PSCustomObject]@{ + Status = 'Processing' + IsComplete = $false + ObjectsProcessed = 1 + TotalExpectedObjects = 5 + FilesCreated = 0 + BytesProcessed = 0 + TotalErrors = 0 + TotalWarnings = 0 + ErrorMessages = @() + WarningMessages = @() + } + } + } + + It 'polls unfinished handles once per request' { + $null = Update-CIPPSharePointLibraryCopyStatus -TenantFilter 'contoso.com' -OperationId ([guid]::NewGuid().Guid) + + $script:ProgressCalls | Should -Be 1 + } + + It 'skips already-complete handles' { + Mock Get-CIPPSharePointLibraryCopyOperation { + [PSCustomObject]@{ + OperationId = $OperationId + SourceSiteUrl = 'https://contoso.sharepoint.com/sites/a' + SourceSiteName = 'Site A' + SourceLibraryName = 'Docs' + DestSiteName = 'Site B' + DestLibraryName = 'Archive' + StartedBy = 'admin' + Status = 'Processing' + JobHandleCount = 2 + Expiry = ([DateTime]::UtcNow.AddDays(7)).ToString('o') + CopyJobInfos = @( + [PSCustomObject]@{ JobId = 'job-1'; JobQueueUri = 'https://queue'; EncryptionKey = 'key' } + [PSCustomObject]@{ JobId = 'job-2'; JobQueueUri = 'https://queue'; EncryptionKey = 'key' } + ) + HandleStates = @( + [PSCustomObject]@{ Status = 'Complete'; IsComplete = $true; TotalErrors = 0 } + [PSCustomObject]@{ Status = 'Queued'; IsComplete = $false } + ) + SanitizedSnapshot = $null + } + } + + $null = Update-CIPPSharePointLibraryCopyStatus -TenantFilter 'contoso.com' -OperationId ([guid]::NewGuid().Guid) + + $script:ProgressCalls | Should -Be 1 + } + + It 'returns cached snapshot for terminal operations without live polling' { + Mock Get-CIPPSharePointLibraryCopyOperation { + [PSCustomObject]@{ + Status = 'Completed' + HandleStates = @() + SanitizedSnapshot = [PSCustomObject]@{ + OperationId = 'done-op' + Status = 'Completed' + JobsComplete = 1 + JobsTotal = 1 + TotalErrors = 0 + Message = 'Library copy completed.' + } + } + } + + $Result = Update-CIPPSharePointLibraryCopyStatus -TenantFilter 'contoso.com' -OperationId 'done-op' + + $Result.Status | Should -Be 'Completed' + $script:ProgressCalls | Should -Be 0 + } +} diff --git a/Tests/Reports/ConvertTo-CippMarkdownCell.Tests.ps1 b/Tests/Reports/ConvertTo-CippMarkdownCell.Tests.ps1 index bfe47f0e2e403..856f77189f875 100644 --- a/Tests/Reports/ConvertTo-CippMarkdownCell.Tests.ps1 +++ b/Tests/Reports/ConvertTo-CippMarkdownCell.Tests.ps1 @@ -26,6 +26,16 @@ Describe 'ConvertTo-CippMarkdownCell' { } } + Context 'Backslash escaping' { + It 'doubles a literal backslash so the parser does not treat it as an escape' { + ConvertTo-CippMarkdownCell -Value 'CONTOSO\jdoe' | Should -Be 'CONTOSO\\jdoe' + } + + It 'keeps a backslash before a pipe from swallowing the pipe escape' { + ConvertTo-CippMarkdownCell -Value 'C:\|x' | Should -Be 'C:\\\|x' + } + } + Context 'Newline handling' { It 'collapses a newline that would split the row in two' { ConvertTo-CippMarkdownCell -Value "Line1`nLine2" | Should -Be 'Line1 Line2' diff --git a/Tests/Reports/Get-CIPPDrift.Tests.ps1 b/Tests/Reports/Get-CIPPDrift.Tests.ps1 index 4f1fbe8964a3f..baafcef363a34 100644 --- a/Tests/Reports/Get-CIPPDrift.Tests.ps1 +++ b/Tests/Reports/Get-CIPPDrift.Tests.ps1 @@ -529,6 +529,47 @@ Describe 'Get-CIPPDrift - stale drift entity pruning' { $script:RemovedDriftEntities.Count | Should -Be 0 } + It 'does not remove a decided IntuneTemplates row when a continuation page of the policy inventory failed' { + # New-GraphBulkRequest keeps status 200 on an item whose later page failed and flags it + # PagingIncomplete instead. Policies on the missing page are absent from the inventory, so + # without this gate their accepted rows were pruned as "gone" and re-created as New on the + # next run (the reported reset of customer-specific deviations every couple of days). + $script:DriftEntityRows = @(New-DriftEntity -StandardName 'IntuneTemplates.policy-on-page-two' -Status 'CustomerSpecific' -Reason 'customer specific' -User 'admin@msp.com') + Mock -CommandName Test-CIPPStandardLicense -MockWith { param($StandardName, $TenantFilter, $Preset) $Preset -eq 'Intune' } + Mock -CommandName New-GraphBulkRequest -MockWith { + param($Requests, $tenantid, $asapp) + foreach ($r in $Requests) { + $Item = [pscustomobject]@{ id = $r.id; status = 200; body = @{ value = @() } } + if ($r.id -eq 'deviceManagement/configurationPolicies') { + $Item | Add-Member -NotePropertyName 'PagingIncomplete' -NotePropertyValue $true + $Item | Add-Member -NotePropertyName 'PagingError' -NotePropertyValue 'continuation page returned 429' + } + $Item + } + } + + Get-CIPPDrift -TenantFilter 'contoso.onmicrosoft.com' -WarningVariable Warnings -WarningAction SilentlyContinue | Out-Null + + $script:RemovedDriftEntities.Count | Should -Be 0 + @($Warnings) | Where-Object { $_ -match 'incomplete' -and $_ -match '429' } | Should -Not -BeNullOrEmpty + } + + It 'still prunes a vanished IntuneTemplates row when every page of the inventory succeeded' { + # Control for the test above: same rows, same inventory, no incomplete flag - the row has no + # matching tenant policy and is correctly removed. + $script:DriftEntityRows = @(New-DriftEntity -StandardName 'IntuneTemplates.policy-really-gone' -Status 'CustomerSpecific' -Reason 'customer specific' -User 'admin@msp.com') + Mock -CommandName Test-CIPPStandardLicense -MockWith { param($StandardName, $TenantFilter, $Preset) $Preset -eq 'Intune' } + Mock -CommandName New-GraphBulkRequest -MockWith { + param($Requests, $tenantid, $asapp) + foreach ($r in $Requests) { [pscustomobject]@{ id = $r.id; status = 200; body = @{ value = @() } } } + } + + Get-CIPPDrift -TenantFilter 'contoso.onmicrosoft.com' | Out-Null + + $script:RemovedDriftEntities.Count | Should -Be 1 + $script:RemovedDriftEntities[0].StandardName | Should -Be 'IntuneTemplates.policy-really-gone' + } + It 'does not remove a drift row that is still referenced by the current alignment' { $script:DriftEntityRows = @(New-DriftEntity -StandardName 'standards.StillRelevant') Mock -CommandName Get-CIPPTenantAlignment -MockWith { diff --git a/Tests/Reports/Get-CIPPLicenseOverview.Tests.ps1 b/Tests/Reports/Get-CIPPLicenseOverview.Tests.ps1 new file mode 100644 index 0000000000000..93f783dd43b34 --- /dev/null +++ b/Tests/Reports/Get-CIPPLicenseOverview.Tests.ps1 @@ -0,0 +1,120 @@ +# Pester tests for Get-CIPPLicenseOverview +# Focus: the exclusion/dropdown gate that decides which SKUs each caller sees. +# - Reporting/alert callers (no -IncludeExcluded) drop every excluded SKU. +# - Picker callers (-IncludeExcluded) keep excluded SKUs so they stay assignable, +# unless the SKU has been explicitly hidden from the dropdown (ShowInLicenseDropdown = $false). +# Regression guard for free/self-service SKUs (e.g. Power Automate Free) vanishing from the +# add-license picker because they ship as default reporting exclusions. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPLicenseOverview.ps1' + + # ConversionTable.csv is read directly off disk (not via a mockable command), so point the + # function at the real backend config. Pretty-name resolution falls back to skuPartNumber for + # SKUs missing from the CSV, which is all this test relies on. + $env:CIPPRootPath = $RepoRoot + + # Minimal stubs so Mock has commands to replace (only Get-CIPPLicenseOverview is dot-sourced, + # not the whole module). + function New-GraphGetRequest { param($uri, $scope, $TenantID, $AsApp) } + function New-GraphBulkRequest { param($Requests, $TenantID, $asapp) } + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Table) } + function Initialize-CIPPExcludedLicenses { } + + . $FunctionPath + + $script:FlowFreeGuid = 'f30db892-07e9-47e9-837c-80727f46fd3d' # Microsoft Power Automate Free (default exclusion) + $script:E5Guid = '06ebc4ee-1bb5-47dd-8120-11324bc54e06' # SPE_E5 (not excluded) + + # Builds the New-GraphBulkRequest response shape from a set of subscribedSkus. + function New-BulkResult { + param($Skus) + @( + [pscustomobject]@{ id = 'subscribedSkus'; body = [pscustomobject]@{ value = @($Skus) } } + [pscustomobject]@{ id = 'directorySubscriptions'; body = [pscustomobject]@{ value = @() } } + [pscustomobject]@{ id = 'licensedUsers'; body = [pscustomobject]@{ value = @() } } + [pscustomobject]@{ id = 'licensedGroups'; body = [pscustomobject]@{ value = @() } } + ) + } + + function New-Sku { + param($SkuId, $PartNumber) + [pscustomobject]@{ + skuId = $SkuId + skuPartNumber = $PartNumber + consumedUnits = 1 + prepaidUnits = [pscustomobject]@{ enabled = 10000 } + subscriptionIds = @() + servicePlans = @() + } + } +} + +Describe 'Get-CIPPLicenseOverview exclusion/dropdown gate' { + BeforeEach { + $script:Tenant = 'contoso.onmicrosoft.com' + Mock -CommandName New-GraphGetRequest -MockWith { @() } + Mock -CommandName Get-CIPPTable -MockWith { @{ TableName = 'ExcludedLicenses' } } + Mock -CommandName Initialize-CIPPExcludedLicenses -MockWith { } + Mock -CommandName New-GraphBulkRequest -MockWith { + New-BulkResult -Skus @( + (New-Sku -SkuId $script:FlowFreeGuid -PartNumber 'FLOW_FREE'), + (New-Sku -SkuId $script:E5Guid -PartNumber 'SPE_E5') + ) + } + } + + It 'keeps a default-excluded free SKU in the picker (IncludeExcluded) so it stays assignable' { + # Default-config exclusion: GUID present, no ExcludedEverywhere / ShowInLicenseDropdown set. + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + @([pscustomobject]@{ GUID = $script:FlowFreeGuid; Product_Display_Name = 'Microsoft Power Automate Free' }) + } + + $Result = Get-CIPPLicenseOverview -TenantFilter $script:Tenant -IncludeExcluded + + @($Result).skuId | Should -Contain $script:FlowFreeGuid + @($Result).skuId | Should -Contain $script:E5Guid + } + + It 'drops the excluded SKU from reporting callers (no IncludeExcluded)' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + @([pscustomobject]@{ GUID = $script:FlowFreeGuid; Product_Display_Name = 'Microsoft Power Automate Free' }) + } + + $Result = Get-CIPPLicenseOverview -TenantFilter $script:Tenant + + @($Result).skuId | Should -Not -Contain $script:FlowFreeGuid + @($Result).skuId | Should -Contain $script:E5Guid + } + + It 'hides an excluded SKU from the picker only when ShowInLicenseDropdown is explicitly false' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + @([pscustomobject]@{ + GUID = $script:FlowFreeGuid + Product_Display_Name = 'Microsoft Power Automate Free' + ShowInLicenseDropdown = $false + }) + } + + $Result = Get-CIPPLicenseOverview -TenantFilter $script:Tenant -IncludeExcluded + + @($Result).skuId | Should -Not -Contain $script:FlowFreeGuid + @($Result).skuId | Should -Contain $script:E5Guid + } + + It 'treats ExcludedEverywhere = false as alert-only, leaving the SKU visible to reporting' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + @([pscustomobject]@{ + GUID = $script:FlowFreeGuid + Product_Display_Name = 'Microsoft Power Automate Free' + ExcludedEverywhere = $false + }) + } + + $Result = Get-CIPPLicenseOverview -TenantFilter $script:Tenant + + @($Result).skuId | Should -Contain $script:FlowFreeGuid + } +} diff --git a/Tests/Scheduler/Add-CIPPScheduledTask.TenantCoercion.Tests.ps1 b/Tests/Scheduler/Add-CIPPScheduledTask.TenantCoercion.Tests.ps1 new file mode 100644 index 0000000000000..8949e1027e75c --- /dev/null +++ b/Tests/Scheduler/Add-CIPPScheduledTask.TenantCoercion.Tests.ps1 @@ -0,0 +1,143 @@ +# Regression tests for the scheduler tenant-authorization gap (INC-2026-003 Finding 3). +# +# A scheduled command's own tenant parameter (Tenant / TenantId, or an explicit TenantFilter in the +# stored Parameters) used to be persisted verbatim and executed with no authorization check against +# the caller's allowed-tenant scope. Only the picker's TenantFilter was authorized. This let a task +# created against tenant A carry a Parameters.Tenant of tenant B and run unchecked. +# +# Creation-time defense (this file): Add-CIPPScheduledTask strips any tenant-identifying parameter +# from the stored Parameters and logs at Error when the stored value pointed at a different tenant +# than the picked one. The authorized tenant is injected at execution instead (see the companion +# Push-ExecScheduledCommand.TenantCoercion.Tests.ps1). + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Add-CIPPScheduledTask.ps1' + + # Stubs so Mock has commands to replace. + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property) } + function Add-CIPPAzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Update-AzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Add-CippQueueMessage { param($Cmdlet, $Parameters) } + function Get-CIPPSchedulerBlockedCommands { @() } + function Get-NormalizedError { param($Message) $Message } + function Write-LogMessage { param($headers, $API, $message, $Sev, $tenant, $tenantid, $LogData) } + function New-CIPPTaskDeltaQuery { param($Trigger, $TenantFilter, $PartitionKey) } + + . $FunctionPath + + # Build a synthetic Get-Command result: the real Add-CIPPScheduledTask gates on $Command.Module + # (must be an allowed CIPP module) and reads $Command.Parameters.ContainsKey(...). Rather than + # register real functions in a fake module, hand back an object with just those two surfaces. + function New-FakeCommand { + param([string]$Module = 'CIPPCore', [string[]]$ParamNames) + $params = @{} + foreach ($p in $ParamNames) { $params[$p] = [pscustomobject]@{ Name = $p } } + [pscustomobject]@{ Module = $Module; Parameters = $params } + } + + # Capture what actually gets written to the ScheduledTasks table. + $script:CapturedEntity = $null + $script:LoggedErrors = [System.Collections.Generic.List[string]]::new() +} + +Describe 'Add-CIPPScheduledTask tenant-parameter coercion' { + BeforeEach { + $script:CapturedEntity = $null + $script:LoggedErrors = [System.Collections.Generic.List[string]]::new() + Mock -CommandName Get-CIPPTable -MockWith { @{ Context = 'stub' } } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $null } + Mock -CommandName Add-CIPPAzDataTableEntity -MockWith { $script:CapturedEntity = $Entity } + Mock -CommandName Update-AzDataTableEntity -MockWith { } + Mock -CommandName Add-CippQueueMessage -MockWith { } + Mock -CommandName Write-LogMessage -MockWith { + if ($Sev -eq 'Error') { $script:LoggedErrors.Add([string]$message) } + } + # Default: a command that declares its own -Tenant parameter (the gap shape). Individual + # tests override this for the no-tenant-parameter case. + Mock -CommandName Get-Command -MockWith { + New-FakeCommand -ParamNames @('TenantFilter', 'AuthenticationMethodId', 'Enabled') + } + } + + It 'strips a mismatched Tenant parameter so it is never persisted' { + $Task = [pscustomobject]@{ + Name = 'Evil cross-tenant task' + Command = 'Set-CIPPAuthenticationPolicy' + TenantFilter = 'authorized.onmicrosoft.com' + Parameters = [pscustomobject]@{ + Tenant = 'victim.onmicrosoft.com' + AuthenticationMethodId = 'SMS' + Enabled = $true + } + } + + Add-CIPPScheduledTask -Task $Task + + $script:CapturedEntity | Should -Not -BeNullOrEmpty + $StoredParams = $script:CapturedEntity.Parameters | ConvertFrom-Json + # The tenant-identifying key must be gone; the benign parameters survive. + $StoredParams.PSObject.Properties.Name | Should -Not -Contain 'Tenant' + $StoredParams.AuthenticationMethodId | Should -Be 'SMS' + # The task's own tenant scope is still the authorized picker value. + $script:CapturedEntity.Tenant | Should -Be 'authorized.onmicrosoft.com' + } + + It 'logs an Error naming both tenants when the stored value points elsewhere' { + $Task = [pscustomobject]@{ + Name = 'Evil cross-tenant task' + Command = 'Set-CIPPAuthenticationPolicy' + TenantFilter = 'authorized.onmicrosoft.com' + Parameters = [pscustomobject]@{ + Tenant = 'victim.onmicrosoft.com' + AuthenticationMethodId = 'SMS' + Enabled = $true + } + } + + Add-CIPPScheduledTask -Task $Task + + $script:LoggedErrors.Count | Should -BeGreaterThan 0 + ($script:LoggedErrors -join "`n") | Should -Match 'victim\.onmicrosoft\.com' + ($script:LoggedErrors -join "`n") | Should -Match 'authorized\.onmicrosoft\.com' + } + + It 'strips a matching Tenant parameter silently (no Error) since execution re-injects it' { + $Task = [pscustomobject]@{ + Name = 'Legit task' + Command = 'Set-CIPPAuthenticationPolicy' + TenantFilter = 'authorized.onmicrosoft.com' + Parameters = [pscustomobject]@{ + Tenant = 'authorized.onmicrosoft.com' + AuthenticationMethodId = 'SMS' + Enabled = $true + } + } + + Add-CIPPScheduledTask -Task $Task + + $StoredParams = $script:CapturedEntity.Parameters | ConvertFrom-Json + $StoredParams.PSObject.Properties.Name | Should -Not -Contain 'Tenant' + $script:LoggedErrors.Count | Should -Be 0 + } + + It 'leaves non-tenant parameters untouched for a command with no tenant parameter' { + function Get-CIPPHarmlessThing { param($Foo, $Bar) } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $null } + + $Task = [pscustomobject]@{ + Name = 'Harmless task' + Command = 'Get-CIPPHarmlessThing' + TenantFilter = 'authorized.onmicrosoft.com' + Parameters = [pscustomobject]@{ Foo = 'a'; Bar = 'b' } + } + + Add-CIPPScheduledTask -Task $Task + + $StoredParams = $script:CapturedEntity.Parameters | ConvertFrom-Json + $StoredParams.Foo | Should -Be 'a' + $StoredParams.Bar | Should -Be 'b' + $script:LoggedErrors.Count | Should -Be 0 + } +} diff --git a/Tests/Scheduler/Add-CIPPScheduledTask.TenantSelection.Tests.ps1 b/Tests/Scheduler/Add-CIPPScheduledTask.TenantSelection.Tests.ps1 new file mode 100644 index 0000000000000..8a767e9cebfe2 --- /dev/null +++ b/Tests/Scheduler/Add-CIPPScheduledTask.TenantSelection.Tests.ps1 @@ -0,0 +1,95 @@ +# Pins the storage contract for a multi-entry tenant selection on a scheduled task. +# +# The selection is stored verbatim for Start-UserTasksOrchestrator to expand, and +# TenantSelectionVersion marks excludedTenants as the operator's own picks rather than the snapshot +# older rows carry. It must land in the single task write - the selection used to be added by a +# second table call afterwards, so a failure there left an alert scoped to every tenant. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Add-CIPPScheduledTask.ps1' + + # Stubs so Mock has commands to replace. + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property) } + function Add-CIPPAzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Update-AzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Add-CippQueueMessage { param($Cmdlet, $Parameters) } + function Get-CIPPSchedulerBlockedCommands { @() } + function Get-NormalizedError { param($Message) $Message } + function Write-LogMessage { param($headers, $API, $message, $Sev, $tenant, $tenantid, $LogData) } + function New-CIPPTaskDeltaQuery { param($Trigger, $TenantFilter, $PartitionKey) } + + . $FunctionPath + + function New-FakeCommand { + param([string]$Module = 'CIPPCore', [string[]]$ParamNames) + $params = @{} + foreach ($p in $ParamNames) { $params[$p] = [pscustomobject]@{ Name = $p } } + [pscustomobject]@{ Module = $Module; Parameters = $params } + } + + function New-SelectionTask { + param($Tenants) + $Task = [pscustomobject]@{ + Name = 'Scripted alert fixture' + Command = 'Get-CIPPAlertFixture' + TenantFilter = [pscustomobject]@{ value = 'AllTenants'; label = '*All Tenants'; type = 'Tenant' } + Parameters = [pscustomobject]@{ Threshold = 5 } + } + if ($Tenants) { $Task | Add-Member -MemberType NoteProperty -Name 'Tenants' -Value $Tenants } + $Task + } +} + +Describe 'Add-CIPPScheduledTask tenant selection storage' { + BeforeEach { + $script:Persisted = [System.Collections.Generic.List[object]]::new() + Mock -CommandName Get-CIPPTable -MockWith { @{ Context = 'stub' } } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $null } + Mock -CommandName Add-CIPPAzDataTableEntity -MockWith { $script:Persisted.Add($Entity) } + Mock -CommandName Update-AzDataTableEntity -MockWith { } + Mock -CommandName Add-CippQueueMessage -MockWith { } + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Get-Command -MockWith { + New-FakeCommand -ParamNames @('TenantFilter', 'Threshold') + } + } + + It 'persists the selection and the version marker in the same entity as the task' { + $Selection = @( + [pscustomobject]@{ value = 'group-1'; label = 'Group 1'; type = 'Group' } + [pscustomobject]@{ value = 'group-2'; label = 'Group 2'; type = 'Group' } + ) + + Add-CIPPScheduledTask -Task (New-SelectionTask -Tenants $Selection) + + $script:Persisted | Should -HaveCount 1 + $Entity = $script:Persisted[0] + $Entity.TenantSelectionVersion | Should -Be 2 + $Entity.Tenant | Should -Be 'AllTenants' + + $Stored = @($Entity.Tenants | ConvertFrom-Json) + $Stored | Should -HaveCount 2 + $Stored.value | Should -Contain 'group-1' + $Stored.value | Should -Contain 'group-2' + } + + It 'leaves an already-serialized selection alone so a restored backup is not double-encoded' { + $Json = '[{"value":"group-1","label":"Group 1","type":"Group"}]' + + Add-CIPPScheduledTask -Task (New-SelectionTask -Tenants $Json) + + $script:Persisted[0].Tenants | Should -Be $Json + } + + It 'writes no selection or marker for a single-tenant task' { + # The entity write is a replace, so omitting both clears them when an alert is edited down + # to one tenant. + Add-CIPPScheduledTask -Task (New-SelectionTask) + + $Entity = $script:Persisted[0] + $Entity.ContainsKey('Tenants') | Should -BeFalse + $Entity.ContainsKey('TenantSelectionVersion') | Should -BeFalse + } +} diff --git a/Tests/Scheduler/Get-CIPPScheduledTaskNextRun.Tests.ps1 b/Tests/Scheduler/Get-CIPPScheduledTaskNextRun.Tests.ps1 new file mode 100644 index 0000000000000..4e68e730c7d31 --- /dev/null +++ b/Tests/Scheduler/Get-CIPPScheduledTaskNextRun.Tests.ps1 @@ -0,0 +1,41 @@ +# Recurrence parsing for scheduled tasks. The orchestrator uses this to close out a run that had no +# tenants in scope; 0 means the task does not repeat and should be completed instead of rescheduled. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPScheduledTaskNextRun.ps1') + + function Get-UnixNow { [int64](([datetime]::UtcNow) - (Get-Date '1/1/1970')).TotalSeconds } +} + +Describe 'Get-CIPPScheduledTaskNextRun' { + It 'adds the interval to the last scheduled time' { + $Last = (Get-UnixNow) - 60 + Get-CIPPScheduledTaskNextRun -Recurrence '1d' -ScheduledTime $Last | Should -Be ($Last + 86400) + } + + It 'parses minutes and hours' { + $Last = (Get-UnixNow) - 60 + Get-CIPPScheduledTaskNextRun -Recurrence '30m' -ScheduledTime $Last | Should -Be ($Last + 1800) + Get-CIPPScheduledTaskNextRun -Recurrence '4h' -ScheduledTime $Last | Should -Be ($Last + 14400) + } + + It 'treats a bare number as days, the shape older tasks carry' { + $Last = (Get-UnixNow) - 60 + Get-CIPPScheduledTaskNextRun -Recurrence '7' -ScheduledTime $Last | Should -Be ($Last + 604800) + } + + It 'returns 0 for a task that does not repeat' { + Get-CIPPScheduledTaskNextRun -Recurrence '0' -ScheduledTime 1 | Should -Be 0 + Get-CIPPScheduledTaskNextRun -Recurrence $null -ScheduledTime 1 | Should -Be 0 + Get-CIPPScheduledTaskNextRun -Recurrence 'never' -ScheduledTime 1 | Should -Be 0 + } + + It 'does not replay a backlog when the last run is far in the past' { + # A task stuck or disabled for a year must schedule one run from now, not catch up. + $Now = Get-UnixNow + $Next = Get-CIPPScheduledTaskNextRun -Recurrence '1d' -ScheduledTime 1 + $Next | Should -BeGreaterOrEqual ($Now + 86400) + $Next | Should -BeLessOrEqual ($Now + 86400 + 5) + } +} diff --git a/Tests/Scheduler/Push-ExecScheduledCommand.TenantCoercion.Tests.ps1 b/Tests/Scheduler/Push-ExecScheduledCommand.TenantCoercion.Tests.ps1 new file mode 100644 index 0000000000000..2fe31294c847d --- /dev/null +++ b/Tests/Scheduler/Push-ExecScheduledCommand.TenantCoercion.Tests.ps1 @@ -0,0 +1,128 @@ +# Regression tests for the scheduler tenant-authorization gap (INC-2026-003 Finding 3), execution side. +# +# Even if a stored task somehow carries a tenant-identifying parameter (legacy rows created before the +# creation-time strip, or a direct table write), Push-ExecScheduledCommand must force every tenant +# parameter the command declares to the task's own authorized tenant before invoking it. This is the +# class-closing defense: it protects every current and future cmdlet regardless of its parameter name. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Push-ExecScheduledCommand.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $FunctionPath) { throw 'Could not locate Push-ExecScheduledCommand.ps1 under Modules/' } + + # Stubs for the module surface Push-ExecScheduledCommand touches. + function Set-CippScheduledTaskContext { param($TaskId) } + function Set-CippUserAgentContext { param($Headers, $Source, $TaskId) } + function Get-CippTable { param($tablename) } + function Get-AzDataTableEntity { param($Context, $Filter) } + function Update-AzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Add-CIPPAzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Get-Tenants { param($TenantFilter) } + function Get-CIPPSchedulerBlockedCommands { @() } + function Write-LogMessage { param($headers, $API, $message, $sev, $tenant, $tenantid, $LogData) } + function Send-CIPPScheduledTaskAlert { param($Results, $TaskInfo, $TenantFilter, $TaskType, $Attachments) } + function Get-CippException { param($Exception) @{ NormalizedError = "$Exception" } } + + # The command under test records exactly which tenant it was invoked against. It declares its own + # -Tenant (the report-cmdlet shape that is NOT alias-renamed, so the parameter really is 'Tenant' + # and survives the SUT's unknown-parameter strip). + $script:InvokedWith = $null + function Get-CIPPTenantScopedReport { + [CmdletBinding()] + param([Parameter(Mandatory = $true)]$Tenant, $AuthenticationMethodId, $Enabled) + $script:InvokedWith = @{ Tenant = $Tenant; AuthenticationMethodId = $AuthenticationMethodId } + return 'ok' + } + + # The SUT reads $Command.Module (must be an allowed CIPP module) and $Command.Parameters for the + # unknown-parameter strip and the tenant coercion, but invokes the command by name string. Mock + # Get-Command so the real in-scope function is what actually runs, while the metadata gate passes. + function New-FakeCommand { + param([string]$Module = 'CIPPCore', [string[]]$ParamNames) + $params = @{} + foreach ($p in $ParamNames) { $params[$p] = [pscustomobject]@{ Name = $p } } + [pscustomobject]@{ Module = $Module; Parameters = $params } + } + + . $FunctionPath +} + +Describe 'Push-ExecScheduledCommand tenant-parameter coercion' { + BeforeEach { + $script:InvokedWith = $null + Mock -CommandName Set-CippScheduledTaskContext -MockWith { } + Mock -CommandName Set-CippUserAgentContext -MockWith { } + Mock -CommandName Get-CippTable -MockWith { @{ Context = 'stub' } } + Mock -CommandName Update-AzDataTableEntity -MockWith { } + Mock -CommandName Add-CIPPAzDataTableEntity -MockWith { } + Mock -CommandName Get-Tenants -MockWith { [pscustomobject]@{ customerId = 'cust-authorized' } } + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Send-CIPPScheduledTaskAlert -MockWith { } + # A live, non-completed task row so execution proceeds. + Mock -CommandName Get-AzDataTableEntity -MockWith { + [pscustomobject]@{ PartitionKey = 'ScheduledTask'; RowKey = 'task-1'; TaskState = 'Running' } + } + # Metadata for the module gate + parameter strip; the real function runs via & by name. + Mock -CommandName Get-Command -MockWith { + New-FakeCommand -ParamNames @('Tenant', 'AuthenticationMethodId', 'Enabled') + } -ParameterFilter { $Name -eq 'Get-CIPPTenantScopedReport' } + + $script:BaseItem = @{ + Command = 'Get-CIPPTenantScopedReport' + TaskInfo = [pscustomobject]@{ + PartitionKey = 'ScheduledTask' + RowKey = 'task-1' + Name = 'Auth policy task' + Tenant = 'authorized.onmicrosoft.com' + Recurrence = '0' + } + } + } + + It 'overrides a mismatched stored Tenant with the authorized task tenant' { + $Item = $script:BaseItem.Clone() + $Item.Parameters = @{ + Tenant = 'victim.onmicrosoft.com' + AuthenticationMethodId = 'SMS' + Enabled = $true + } + + Push-ExecScheduledCommand -Item ([pscustomobject]$Item) + + $script:InvokedWith | Should -Not -BeNullOrEmpty + # The command must have run against the task's authorized tenant, never the stored one. + $script:InvokedWith.Tenant | Should -Be 'authorized.onmicrosoft.com' + $script:InvokedWith.Tenant | Should -Not -Be 'victim.onmicrosoft.com' + } + + It 'logs an Error when the stored tenant value differed from the authorized tenant' { + $Item = $script:BaseItem.Clone() + $Item.Parameters = @{ + Tenant = 'victim.onmicrosoft.com' + AuthenticationMethodId = 'SMS' + Enabled = $true + } + + Push-ExecScheduledCommand -Item ([pscustomobject]$Item) + + Should -Invoke -CommandName Write-LogMessage -Times 1 -ParameterFilter { + $sev -eq 'Error' -and $message -match 'victim\.onmicrosoft\.com' -and $message -match 'authorized\.onmicrosoft\.com' + } + } + + It 'runs cleanly with no Error log when no tenant parameter is stored' { + $Item = $script:BaseItem.Clone() + $Item.Parameters = @{ + AuthenticationMethodId = 'SMS' + Enabled = $true + } + + Push-ExecScheduledCommand -Item ([pscustomobject]$Item) + + $script:InvokedWith.Tenant | Should -Be 'authorized.onmicrosoft.com' + Should -Invoke -CommandName Write-LogMessage -Times 0 -ParameterFilter { + $sev -eq 'Error' -and $message -match 'does not match the authorized tenant' + } + } +} diff --git a/Tests/Scheduler/Start-UpdateTokensTimer.CertificateAuth.Tests.ps1 b/Tests/Scheduler/Start-UpdateTokensTimer.CertificateAuth.Tests.ps1 new file mode 100644 index 0000000000000..cbf22c9ba9859 --- /dev/null +++ b/Tests/Scheduler/Start-UpdateTokensTimer.CertificateAuth.Tests.ps1 @@ -0,0 +1,69 @@ +# The weekly token timer renews the SAM app's client secret. In certificate-exclusive mode CIPP adds +# no secret, so the timer must NOT call addPassword - otherwise it fails on tenants blocking password +# addition, or silently re-creates a secret on a secret-less install, defeating the feature. Pinned here. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function Get-GraphToken { param([switch]$ReturnRefresh, $TenantId) } + function Get-CIPPTable { param($tablename) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter) } + function Get-Tenants { param([switch]$IncludeAll, [switch]$SkipList) } + function Add-AzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function New-GraphGetRequest { param($uri, $NoAuthCheck, $AsApp) } + function New-GraphPostRequest { param($uri, $type, $Body, $NoAuthCheck, $AsApp) } + function Update-AppManagementPolicy {} + function Update-CIPPSAMCertificate {} + function Write-LogMessage { param($API, $message, $sev, $tenant, $tenantid, $LogData) } + function Get-CippException { param($Exception) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-UpdateTokensTimer.ps1') +} + +Describe 'Start-UpdateTokensTimer certificate mode' { + BeforeEach { + $script:SavedEnv = @{} + foreach ($Name in 'CertificateAuthMode', 'ApplicationID', 'TenantID', 'AzureWebJobsStorage') { $script:SavedEnv[$Name] = [Environment]::GetEnvironmentVariable($Name) } + $env:ApplicationID = 'sam-app-id' + $env:TenantID = '11111111-2222-3333-4444-555555555555' + $env:AzureWebJobsStorage = 'UseDevelopmentStorage=true' # dev branch - no Key Vault + + Mock Get-GraphToken { @{ Refresh_token = 'refresh-token' } } + Mock Get-CIPPTable { @{} } + Mock Get-CIPPAzDataTableEntity { $null } # no dev secret row, no direct tenants + Mock Get-Tenants { @() } # no direct tenants to refresh + Mock Add-AzDataTableEntity {} + # Secret-less install: the app registration has no password credentials. + Mock New-GraphGetRequest { + [pscustomobject]@{ id = 'app-obj-id'; passwordCredentials = @(); servicePrincipalLockConfiguration = [pscustomobject]@{ isEnabled = $true } } + } + Mock New-GraphPostRequest { [pscustomobject]@{ secretText = 's'; keyId = 'k'; endDateTime = (Get-Date).AddYears(1) } } + Mock Update-AppManagementPolicy { [pscustomobject]@{ PolicyAction = 'none' } } + Mock Update-CIPPSAMCertificate { [pscustomobject]@{ Renewed = $false; Thumbprint = 'abc'; NotAfter = (Get-Date).AddYears(1) } } + Mock Write-LogMessage {} + Mock Get-CippException { @{} } + } + + AfterEach { + foreach ($Name in $script:SavedEnv.Keys) { + if ($null -eq $script:SavedEnv[$Name]) { Remove-Item "env:$Name" -ErrorAction SilentlyContinue } + else { Set-Item "env:$Name" -Value $script:SavedEnv[$Name] } + } + } + + It 'does NOT generate a client secret when certificate mode is on' { + $env:CertificateAuthMode = $true + + Start-UpdateTokensTimer -Confirm:$false + + Should -Invoke New-GraphPostRequest -Times 0 -Exactly -ParameterFilter { $uri -match 'addPassword' } + } + + It 'still generates a client secret when certificate mode is off (guard proven)' { + Remove-Item env:CertificateAuthMode -ErrorAction SilentlyContinue + + Start-UpdateTokensTimer -Confirm:$false + + Should -Invoke New-GraphPostRequest -Times 1 -Exactly -ParameterFilter { $uri -match 'addPassword' } + } +} diff --git a/Tests/Scheduler/Start-UserTasksOrchestrator.TenantGroups.Tests.ps1 b/Tests/Scheduler/Start-UserTasksOrchestrator.TenantGroups.Tests.ps1 new file mode 100644 index 0000000000000..5766fa847f4f5 --- /dev/null +++ b/Tests/Scheduler/Start-UserTasksOrchestrator.TenantGroups.Tests.ps1 @@ -0,0 +1,353 @@ +# Regression tests for scripted-alert tenant scope. +# +# Groups used to be expanded at save time, with the complement of the selection frozen into +# excludedTenants, so a tenant joining a targeted group afterwards never received the alert. Scope is +# now resolved here on every run from the verbatim Tenants selection. Rows written by the old code +# lack TenantSelectionVersion; their excludedTenants is that snapshot and is ignored, while +# excludedTenantGroups was never part of it and always applies. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Start-UserTasksOrchestrator.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $FunctionPath) { throw 'Could not locate Start-UserTasksOrchestrator.ps1 under Modules/' } + + # Stubs so Mock has commands to replace. + function Get-CippTable { param($tablename) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property) } + function Update-AzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function Get-Tenants { param($TenantFilter, [switch]$IncludeErrors) } + function Get-CIPPSchedulerBlockedCommands { @() } + function Expand-CIPPTenantGroups { param($TenantFilter) } + function New-CippQueueEntry { param($Name, $Reference, $TotalTasks) } + function Start-CIPPOrchestrator { param($InputObject) } + function Get-CIPPScheduledTaskNextRun { param($Recurrence, $ScheduledTime) } + # Parameter names bind case-insensitively, so one $Sev covers the SUT's -Sev and -sev calls. + function Write-LogMessage { param($headers, $API, $message, $Sev, $tenant, $tenantid, $LogData) } + + # A real function, so the SUT's Get-Command lookup resolves without mocking Pester's own + # Get-Command. It declares TenantFilter, which is what drives the per-tenant parameter stamping. + function Get-CIPPAlertFixture { param($TenantFilter, $Threshold) } + + . $FunctionPath + + # Four managed tenants; group-1 holds a + b, group-2 holds c, group-excluded holds c. + function New-TenantList { + @( + [pscustomobject]@{ defaultDomainName = 'a.onmicrosoft.com'; customerId = 'cust-a'; displayName = 'A' } + [pscustomobject]@{ defaultDomainName = 'b.onmicrosoft.com'; customerId = 'cust-b'; displayName = 'B' } + [pscustomobject]@{ defaultDomainName = 'c.onmicrosoft.com'; customerId = 'cust-c'; displayName = 'C' } + [pscustomobject]@{ defaultDomainName = 'd.onmicrosoft.com'; customerId = 'cust-d'; displayName = 'D' } + ) + } + + function New-TaskRow { + param([hashtable]$Overrides = @{}) + $Row = @{ + PartitionKey = 'ScheduledTask' + RowKey = 'task-1' + Name = 'Scripted alert fixture' + Command = 'Get-CIPPAlertFixture' + Parameters = '{}' + ScheduledTime = 1 + TaskState = 'Planned' + Recurrence = '0' + Tenant = 'AllTenants' + ETag = 'etag-1' + } + foreach ($Key in $Overrides.Keys) { $Row[$Key] = $Overrides[$Key] } + [pscustomobject]$Row + } + + # The tenant each fanned-out command was stamped with, in batch order. + function Get-ScopedTenants { + @($script:StartedBatches | ForEach-Object { $_.Parameters.TenantFilter }) + } + + # The two groups a multi-select alert stores verbatim. + $script:TwoGroupSelection = ConvertTo-Json -Compress -Depth 5 -InputObject @( + [pscustomobject]@{ value = 'group-1'; label = 'Group 1'; type = 'Group' } + [pscustomobject]@{ value = 'group-2'; label = 'Group 2'; type = 'Group' } + ) +} + +Describe 'Start-UserTasksOrchestrator tenant scope resolution' { + BeforeEach { + $script:StartedBatches = [System.Collections.Generic.List[object]]::new() + $script:LoggedMessages = [System.Collections.Generic.List[string]]::new() + $script:TaskUpdates = [System.Collections.Generic.List[object]]::new() + + Mock -CommandName Get-CippTable -MockWith { @{ Context = 'stub' } } + Mock -CommandName Update-AzDataTableEntity -MockWith { $script:TaskUpdates.Add($Entity) } + Mock -CommandName Get-CIPPScheduledTaskNextRun -MockWith { 0 } + Mock -CommandName Get-CIPPSchedulerBlockedCommands -MockWith { @() } + Mock -CommandName New-CippQueueEntry -MockWith { [pscustomobject]@{ RowKey = 'queue-1' } } + Mock -CommandName Get-Tenants -MockWith { New-TenantList } + Mock -CommandName Write-LogMessage -MockWith { + $script:LoggedMessages.Add([string]$message) + } + Mock -CommandName Start-CIPPOrchestrator -MockWith { + foreach ($Item in @($InputObject.Batch)) { $script:StartedBatches.Add($Item) } + } + # Mirrors the real helper: group entries expand to their members, everything else - the + # AllTenants sentinel included - passes through untouched. + Mock -CommandName Expand-CIPPTenantGroups -MockWith { + foreach ($Entry in @($TenantFilter)) { + switch ($Entry.value) { + 'group-1' { + [pscustomobject]@{ value = 'a.onmicrosoft.com'; type = 'Tenant' } + [pscustomobject]@{ value = 'b.onmicrosoft.com'; type = 'Tenant' } + } + 'group-2' { [pscustomobject]@{ value = 'c.onmicrosoft.com'; type = 'Tenant' } } + 'group-excluded' { [pscustomobject]@{ value = 'c.onmicrosoft.com'; type = 'Tenant' } } + 'group-empty' { } + default { $Entry } + } + } + } + } + + It 'includes a group member that a legacy snapshot still lists as excluded' { + # The reported bug: b joined group-1 after the alert was saved, so it sits in the frozen + # complement. Without TenantSelectionVersion that column is a snapshot and must not apply. + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ + Tenants = $script:TwoGroupSelection + excludedTenants = 'b.onmicrosoft.com,d.onmicrosoft.com' + } + } + + Start-UserTasksOrchestrator + + $Scoped = Get-ScopedTenants + $Scoped | Should -Contain 'b.onmicrosoft.com' + $Scoped | Should -Contain 'a.onmicrosoft.com' + $Scoped | Should -Contain 'c.onmicrosoft.com' + # d is in neither group, so it is out of scope on the selection alone. + $Scoped | Should -Not -Contain 'd.onmicrosoft.com' + } + + It 'logs only the snapshot exclusions that were actually in scope' { + # b is in group-1 and was being wrongly excluded; d is in neither group, so dropping it from + # the snapshot changes nothing and is not worth reporting. + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ + Tenants = $script:TwoGroupSelection + excludedTenants = 'b.onmicrosoft.com,d.onmicrosoft.com' + } + } + + Start-UserTasksOrchestrator + + ($script:LoggedMessages -join "`n") | Should -Match 'ignored 1 stale snapshot exclusions' + } + + It 'stays quiet when a legacy snapshot would not have changed the outcome' { + # Otherwise every legacy row logs the same no-op on every run, forever. + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ + Tenants = $script:TwoGroupSelection + excludedTenants = 'd.onmicrosoft.com' + } + } + + Start-UserTasksOrchestrator + + ($script:LoggedMessages -join "`n") | Should -Not -Match 'stale snapshot exclusions' + } + + It 'applies excludedTenants on a versioned row' { + # Written by the current code, so the column holds only the operator's own picks. + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ + Tenants = $script:TwoGroupSelection + TenantSelectionVersion = 2 + excludedTenants = 'b.onmicrosoft.com' + } + } + + Start-UserTasksOrchestrator + + $Scoped = Get-ScopedTenants + $Scoped | Should -Not -Contain 'b.onmicrosoft.com' + $Scoped | Should -Contain 'a.onmicrosoft.com' + $Scoped | Should -Contain 'c.onmicrosoft.com' + } + + It 'expands excludedTenantGroups on a legacy row, since it was never part of the snapshot' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ + Tenants = $script:TwoGroupSelection + excludedTenants = 'b.onmicrosoft.com' + excludedTenantGroups = (ConvertTo-Json -Compress -Depth 5 -InputObject @( + [pscustomobject]@{ value = 'group-excluded'; label = 'Excluded'; type = 'Group' })) + } + } + + Start-UserTasksOrchestrator + + $Scoped = Get-ScopedTenants + # c is excluded via the group; b is not, because the snapshot column is ignored. + $Scoped | Should -Not -Contain 'c.onmicrosoft.com' + $Scoped | Should -Contain 'b.onmicrosoft.com' + } + + It 'fans out to every tenant when the selection carries the AllTenants sentinel' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ + Tenants = (ConvertTo-Json -Compress -Depth 5 -InputObject @( + [pscustomobject]@{ value = 'AllTenants'; label = '*All Tenants'; type = 'Tenant' } + [pscustomobject]@{ value = 'group-1'; label = 'Group 1'; type = 'Group' })) + TenantSelectionVersion = 2 + } + } + + Start-UserTasksOrchestrator + + Get-ScopedTenants | Should -HaveCount 4 + } + + It 'still resolves a single stored group when no Tenants column is present' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ + Tenant = 'group-1' + TenantGroup = '{"value":"group-1","label":"Group 1","type":"Group"}' + } + } + + Start-UserTasksOrchestrator + + $Scoped = Get-ScopedTenants + $Scoped | Should -HaveCount 2 + $Scoped | Should -Contain 'a.onmicrosoft.com' + $Scoped | Should -Contain 'b.onmicrosoft.com' + } + + It 'keeps operator exclusions on a legacy selection that includes AllTenants' { + # The old save path skipped the complement when the selection carried the sentinel, so these + # exclusions are the operator's own and must survive despite the missing version marker. + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ + Tenants = (ConvertTo-Json -Compress -Depth 5 -InputObject @( + [pscustomobject]@{ value = 'AllTenants'; label = '*All Tenants'; type = 'Tenant' } + [pscustomobject]@{ value = 'group-1'; label = 'Group 1'; type = 'Group' })) + excludedTenants = 'b.onmicrosoft.com' + } + } + + Start-UserTasksOrchestrator + + $Scoped = Get-ScopedTenants + $Scoped | Should -HaveCount 3 + $Scoped | Should -Not -Contain 'b.onmicrosoft.com' + } + + It 'fails the task rather than queuing an AllTenants run when expansion throws' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ Tenants = $script:TwoGroupSelection; TenantSelectionVersion = 2 } + } + Mock -CommandName Expand-CIPPTenantGroups -MockWith { throw 'tenant group store unavailable' } + + Start-UserTasksOrchestrator + + Get-ScopedTenants | Should -HaveCount 0 + $Failed = @($script:TaskUpdates | Where-Object { $_.TaskState -eq 'Failed' }) + $Failed | Should -HaveCount 1 + $Failed[0].Results | Should -Match 'Failed to expand tenant selection' + } + + It 'keeps a recurring task alive when expansion throws' { + # Failed is terminal, so parking a recurring task there on a transient table read would stop + # it permanently. + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ Tenants = $script:TwoGroupSelection; TenantSelectionVersion = 2; Recurrence = '1d' } + } + Mock -CommandName Expand-CIPPTenantGroups -MockWith { throw 'tenant group store unavailable' } + Mock -CommandName Get-CIPPScheduledTaskNextRun -MockWith { 1700000000 } + + Start-UserTasksOrchestrator + + $Failed = @($script:TaskUpdates | Where-Object { $_.TaskState -like 'Failed*' }) + $Failed | Should -HaveCount 1 + $Failed[0].TaskState | Should -Be 'Failed - Planned' + $Failed[0].ScheduledTime | Should -Be '1700000000' + } + + It 'ignores a stored selection on a row the execution gates read as single-tenant' { + # Tenant is not the AllTenants literal, so Push-ExecScheduledCommand would treat any fan-out + # here as a single-tenant run: no per-tenant results, and concurrent parent-row writes. + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ Tenant = 'a.onmicrosoft.com'; Tenants = $script:TwoGroupSelection } + } + + Start-UserTasksOrchestrator + + $Scoped = Get-ScopedTenants + $Scoped | Should -HaveCount 1 + $Scoped | Should -Contain 'a.onmicrosoft.com' + } + + It 'reschedules a recurring task whose groups all resolved empty' { + # Otherwise the row stays Pending, is reclaimed as stale every hour, and never advances. + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ + Tenants = (ConvertTo-Json -Compress -Depth 5 -InputObject @( + [pscustomobject]@{ value = 'group-empty'; label = 'Empty'; type = 'Group' })) + TenantSelectionVersion = 2 + Recurrence = '1d' + } + } + Mock -CommandName Get-CIPPScheduledTaskNextRun -MockWith { 1700000000 } + + Start-UserTasksOrchestrator + + Get-ScopedTenants | Should -HaveCount 0 + $Closed = @($script:TaskUpdates | Where-Object { $_.Results -eq 'No tenants in scope for this task.' }) + $Closed | Should -HaveCount 1 + $Closed[0].TaskState | Should -Be 'Planned' + $Closed[0].ScheduledTime | Should -Be '1700000000' + } + + It 'completes a one-off task whose groups all resolved empty' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ + Tenants = (ConvertTo-Json -Compress -Depth 5 -InputObject @( + [pscustomobject]@{ value = 'group-empty'; label = 'Empty'; type = 'Group' })) + TenantSelectionVersion = 2 + } + } + + Start-UserTasksOrchestrator + + $Closed = @($script:TaskUpdates | Where-Object { $_.Results -eq 'No tenants in scope for this task.' }) + $Closed | Should -HaveCount 1 + $Closed[0].TaskState | Should -Be 'Completed' + $Closed[0].ContainsKey('ScheduledTime') | Should -BeFalse + } + + It 'leaves a plain single-tenant task alone' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ Tenant = 'a.onmicrosoft.com' } + } + + Start-UserTasksOrchestrator + + $Scoped = Get-ScopedTenants + $Scoped | Should -HaveCount 1 + $Scoped | Should -Contain 'a.onmicrosoft.com' + Should -Invoke -CommandName Expand-CIPPTenantGroups -Times 0 + } + + It 'fans out to an AllTenants task that stored no selection' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + New-TaskRow @{ excludedTenants = 'd.onmicrosoft.com' } + } + + Start-UserTasksOrchestrator + + $Scoped = Get-ScopedTenants + $Scoped | Should -HaveCount 3 + # No Tenants column means no snapshot, so the exclusion is the operator's and still applies. + $Scoped | Should -Not -Contain 'd.onmicrosoft.com' + } +} diff --git a/Tests/Standards/Invoke-CIPPStandardConditionalAccessTemplate.Tests.ps1 b/Tests/Standards/Invoke-CIPPStandardConditionalAccessTemplate.Tests.ps1 index ffdc7f6f5e017..b764e37651a20 100644 --- a/Tests/Standards/Invoke-CIPPStandardConditionalAccessTemplate.Tests.ps1 +++ b/Tests/Standards/Invoke-CIPPStandardConditionalAccessTemplate.Tests.ps1 @@ -125,7 +125,7 @@ Describe 'Invoke-CIPPStandardConditionalAccessTemplate template resolution' { Invoke-CIPPStandardConditionalAccessTemplate -Tenant $script:Tenant -Settings $Settings ($script:logs | Where-Object { $_.Message -match 'could not be loaded from the template store' -and $_.Sev -eq 'Error' }) | Should -Not -BeNullOrEmpty - $script:compareFields[0].Current.Differences | Should -Match 'could not be loaded from the template store' + $script:compareFields[0].Current.Differences | Should -Match 'no longer exists in the template library' } It 'does not attempt a deployment with a null template body' { diff --git a/Tests/Standards/Invoke-CIPPStandardDisableGuests.Tests.ps1 b/Tests/Standards/Invoke-CIPPStandardDisableGuests.Tests.ps1 new file mode 100644 index 0000000000000..06b4ff7946737 --- /dev/null +++ b/Tests/Standards/Invoke-CIPPStandardDisableGuests.Tests.ps1 @@ -0,0 +1,230 @@ +# Pester tests for Invoke-CIPPStandardDisableGuests +# +# Pins the selection rules behind the "guest disabled despite recent activity" reports: +# - inactivity is judged on the newest sign-in ATTEMPT, interactive or non-interactive - the +# view the Entra portal and the inactive-guest alert give - not on the last successful +# sign-in alone, which stays old while a blocked or disabled guest keeps trying; +# - guests with no sign-in on record are skipped unless IncludeNeverSignedIn is on, and a +# template that predates the switch behaves as off; +# - a guest an admin re-enabled in the last 7 days is left alone. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $Modules = Join-Path $RepoRoot 'Modules' + # Resolve by name under Modules/ so the test survives the functions moving between modules. + $StandardPath = Get-ChildItem -Path $Modules -Recurse -Filter 'Invoke-CIPPStandardDisableGuests.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $StandardPath) { throw 'Could not locate Invoke-CIPPStandardDisableGuests.ps1 under Modules/' } + $HelperPath = Get-ChildItem -Path $Modules -Recurse -Filter 'Get-CIPPLastSignInDateTime.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $HelperPath) { throw 'Could not locate Get-CIPPLastSignInDateTime.ps1 under Modules/' } + + # Stubs mirror the real signatures and are advanced functions on purpose: strict parameter + # binding makes signature drift in the standard fail loudly here instead of silently + # landing in $args. + function Test-CIPPStandardLicense { [CmdletBinding()] param($StandardName, $TenantFilter, $Preset, [switch]$SkipLog) } + function New-GraphGetRequest { [CmdletBinding()] param($uri, $tenantid, $scope, $AsApp, $noPagination, $NoAuthCheck, $skipTokenCache, $ComplexFilter, $CountOnly) } + function New-GraphBulkRequest { [CmdletBinding()] param($tenantid, $NoAuthCheck, $scope, $asapp, $Requests, $NoPaginateIds, $Version, $Headers) } + function Write-LogMessage { [CmdletBinding()] param($API, $tenant, $Tenant2, $message, $sev, $headers, $LogData) } + function Write-StandardsAlert { [CmdletBinding()] param($message, $object, $tenant, $standardName, $standardId) } + function Set-CIPPStandardsCompareField { [CmdletBinding()] param($FieldName, $FieldValue, $CurrentValue, $ExpectedValue, $TenantFilter, $Tenant) } + function Add-CIPPBPAField { [CmdletBinding()] param($FieldName, $FieldValue, $StoreAs, $Tenant) } + function Get-NormalizedError { [CmdletBinding()] param($Message) $Message } + function Get-CippException { [CmdletBinding()] param($Exception) @{ NormalizedError = $Exception.Exception.Message } } + + . $HelperPath + . $StandardPath + + # Script scope: Pester 5 evaluates the Describe body at discovery, so plain variables + # declared there are not in scope inside It blocks or mocks at run time. + $script:Tenant = 'contoso.onmicrosoft.com' + $script:Now = (Get-Date).ToUniversalTime() + + # Guests go through ConvertFrom-Json, the shape New-GraphGetRequest hands the standard. Each + # *DaysAgo is how far back that signInActivity timestamp sits; leave all three out for a guest + # with no sign-in on record. + function script:New-Guest { + param( + [string]$Id, + [string]$Upn, + [string]$State = 'Accepted', + [int]$CreatedDaysAgo = 400, + [Nullable[int]]$InteractiveDaysAgo, + [Nullable[int]]$NonInteractiveDaysAgo, + [Nullable[int]]$SuccessfulDaysAgo + ) + $Stamp = { param($DaysAgo) if ($null -ne $DaysAgo) { $script:Now.AddDays(-$DaysAgo).ToString('o') } else { $null } } + $Guest = [ordered]@{ + id = $Id + userPrincipalName = $Upn + mail = $Upn + userType = 'Guest' + accountEnabled = $true + createdDateTime = $script:Now.AddDays(-$CreatedDaysAgo).ToString('o') + externalUserState = $State + } + if ($null -ne $InteractiveDaysAgo -or $null -ne $NonInteractiveDaysAgo -or $null -ne $SuccessfulDaysAgo) { + $Guest.signInActivity = [ordered]@{ + lastSignInDateTime = & $Stamp $InteractiveDaysAgo + lastNonInteractiveSignInDateTime = & $Stamp $NonInteractiveDaysAgo + lastSuccessfulSignInDateTime = & $Stamp $SuccessfulDaysAgo + } + } + $Guest | ConvertTo-Json -Depth 5 | ConvertFrom-Json + } +} + +Describe 'Invoke-CIPPStandardDisableGuests' { + BeforeEach { + $script:logs = [System.Collections.Generic.List[object]]::new() + $script:alerts = [System.Collections.Generic.List[object]]::new() + $script:compare = [System.Collections.Generic.List[object]]::new() + $script:disabled = [System.Collections.Generic.List[string]]::new() + $script:guests = @() + $script:audits = @() + + Mock -CommandName Test-CIPPStandardLicense -MockWith { $true } + Mock -CommandName Add-CIPPBPAField -MockWith { } + Mock -CommandName Write-LogMessage -MockWith { + param($API, $tenant, $message, $sev, $LogData) + $script:logs.Add(@{ Message = $message; Sev = $sev }) + } + Mock -CommandName Write-StandardsAlert -MockWith { + param($message, $object, $tenant, $standardName, $standardId) + $script:alerts.Add(@{ Message = $message; Object = @($object) }) + } + Mock -CommandName Set-CIPPStandardsCompareField -MockWith { + param($FieldName, $FieldValue, $CurrentValue, $ExpectedValue, $TenantFilter, $Tenant) + $script:compare.Add(@{ Current = $CurrentValue; Expected = $ExpectedValue }) + } + Mock -CommandName New-GraphGetRequest -MockWith { + param($uri, $tenantid, $scope) + if ($uri -like '*directoryAudits*') { return $script:audits } + return $script:guests + } + Mock -CommandName New-GraphBulkRequest -MockWith { + param($tenantid, $Requests) + @(foreach ($Request in $Requests) { + $script:disabled.Add(($Request.url -replace '^users/', '')) + [pscustomobject]@{ id = $Request.id; status = 204; body = $null } + }) + } + } + + Context 'inactivity is judged on the newest sign-in attempt' { + It 'keeps a guest whose last successful sign-in is old but who attempted a sign-in inside the window' { + # The reported shape: a successful sign-in 300 days back, an interactive attempt 154 days + # back and a non-interactive attempt 3 days back, against a 180-day threshold. + $script:guests = @(New-Guest -Id 'g1' -Upn 'bas_example.com#EXT#@contoso.onmicrosoft.com' -SuccessfulDaysAgo 300 -InteractiveDaysAgo 154 -NonInteractiveDaysAgo 3) + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 180 } + + Should -Invoke New-GraphBulkRequest -Times 0 -Exactly + @($script:disabled) | Should -BeNullOrEmpty + @($script:logs | Where-Object { $_.Message -like '*already compliant*' }).Count | Should -Be 1 + } + + It 'disables a guest whose newest attempt of any kind is outside the window, and logs that date' { + $script:guests = @( + New-Guest -Id 'stale' -Upn 'stale@example.com' -SuccessfulDaysAgo 250 -InteractiveDaysAgo 200 -NonInteractiveDaysAgo 190 + New-Guest -Id 'active' -Upn 'active@example.com' -SuccessfulDaysAgo 250 -InteractiveDaysAgo 200 -NonInteractiveDaysAgo 100 + ) + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 180 } + + @($script:disabled) | Should -Be @('stale') + $Lines = @($script:logs | Where-Object { $_.Message -like 'Disabled guest stale@example.com (stale). Reason: last sign-in: *' }) + $Lines.Count | Should -Be 1 + # The newest attempt (non-interactive, 190 days back) is the one reported - not the successful one. + $Logged = ([datetime]($Lines[0].Message -replace '^.*Reason: last sign-in: ', '')).ToUniversalTime() + [math]::Abs(($Logged - $script:Now.AddDays(-190)).TotalMinutes) | Should -BeLessThan 1 + } + + It 'counts a lastSuccessfulSignInDateTime that runs ahead of both attempt timestamps as activity' { + $script:guests = @(New-Guest -Id 'ahead' -Upn 'ahead@example.com' -InteractiveDaysAgo 200 -SuccessfulDaysAgo 10) + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 180 } + + @($script:disabled) | Should -BeNullOrEmpty + } + } + + Context 'guests with no sign-in on record' { + It 'are skipped when the template predates the switch or has it off' { + $script:guests = @(New-Guest -Id 'pending' -Upn 'pending@example.com' -State 'PendingAcceptance') + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 90 } + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 90; IncludeNeverSignedIn = $false } + + Should -Invoke New-GraphBulkRequest -Times 0 -Exactly + @($script:disabled) | Should -BeNullOrEmpty + } + + It 'are disabled only when IncludeNeverSignedIn is on, with the invitation age as the reason' { + $script:guests = @( + New-Guest -Id 'pending' -Upn 'pending@example.com' -State 'PendingAcceptance' + New-Guest -Id 'fresh' -Upn 'fresh@example.com' -InteractiveDaysAgo 5 + ) + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 90; IncludeNeverSignedIn = $true } + + @($script:disabled) | Should -Be @('pending') + @($script:logs | Where-Object { $_.Message -like 'Disabled guest pending@example.com (pending). Reason: never signed in, created *' }).Count | Should -Be 1 + } + } + + Context 'recently re-enabled guests' { + It 'are left alone for 7 days after an admin re-enables them' { + $script:guests = @(New-Guest -Id 'stale' -Upn 'stale@example.com' -InteractiveDaysAgo 200) + $script:audits = @([pscustomobject]@{ targetResources = @([pscustomobject]@{ id = 'stale' }) }) + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 90 } + + Should -Invoke New-GraphBulkRequest -Times 0 -Exactly + @($script:disabled) | Should -BeNullOrEmpty + } + } + + Context 'alert and report' { + It 'splits stale sign-ins from never-signed-in guests and records the switch' { + $script:guests = @( + New-Guest -Id 'stale' -Upn 'stale@example.com' -InteractiveDaysAgo 200 + New-Guest -Id 'pending' -Upn 'pending@example.com' -State 'PendingAcceptance' + New-Guest -Id 'active' -Upn 'active@example.com' -NonInteractiveDaysAgo 2 + ) + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ alert = $true; report = $true; days = 90; IncludeNeverSignedIn = $true } + + $script:alerts.Count | Should -Be 1 + $script:alerts[0].Message | Should -Match '2 total \(1 with no sign-in attempt in 90 days, 1 never signed in' + @($script:alerts[0].Object | Where-Object { $_.NeverSignedIn }).id | Should -Be 'pending' + + $script:compare.Count | Should -Be 1 + $Current = $script:compare[0].Current + $Current.GuestsDisabledAfterDays | Should -Be 90 + $Current.GuestsIncludeNeverSignedIn | Should -BeTrue + $Current.GuestsDisabledAccountCount | Should -Be 2 + $Current.GuestsStaleSignInCount | Should -Be 1 + $Current.GuestsNeverSignedInCount | Should -Be 1 + @($Current.GuestsNeverSignedInDetails).id | Should -Be 'pending' + @($Current.GuestsDisabledAccountDetails | Where-Object { -not $_.NeverSignedIn }).LastSignInDateTime | Should -Not -BeNullOrEmpty + + $Expected = $script:compare[0].Expected + $Expected.GuestsDisabledAccountCount | Should -Be 0 + $Expected.GuestsStaleSignInCount | Should -Be 0 + $Expected.GuestsNeverSignedInCount | Should -Be 0 + $Expected.GuestsIncludeNeverSignedIn | Should -BeTrue + } + + It 'reports the switch off and no never-signed-in guests when the template omits it' { + $script:guests = @(New-Guest -Id 'pending' -Upn 'pending@example.com' -State 'PendingAcceptance') + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ report = $true; days = 90 } + + $Current = $script:compare[0].Current + $Current.GuestsIncludeNeverSignedIn | Should -BeFalse + $Current.GuestsDisabledAccountCount | Should -Be 0 + $Current.GuestsNeverSignedInCount | Should -Be 0 + } + } +} diff --git a/Tests/Standards/Invoke-CIPPStandardDisableSharedMailbox.Tests.ps1 b/Tests/Standards/Invoke-CIPPStandardDisableSharedMailbox.Tests.ps1 new file mode 100644 index 0000000000000..9eafd3f7d686d --- /dev/null +++ b/Tests/Standards/Invoke-CIPPStandardDisableSharedMailbox.Tests.ps1 @@ -0,0 +1,228 @@ +# Pester tests for Invoke-CIPPStandardDisableSharedMailbox +# +# Pins the behaviour behind the "denied deviation that never remediates" reports: +# - a remediating run reports what it leaves behind, not the list it found. It used to disable +# the accounts and then write the pre-remediation list to the compare field, so drift showed +# the same deviation after every successful run; +# - the selection itself covers both mailbox types and only accounts that are still enabled and +# cloud-only. -and and -or share one precedence level in PowerShell and associate left to +# right, so the unparenthesised original meant the same thing - these pin it against a +# "fix" that regroups it as A -or (B -and C); +# - the user cache and the Exchange mailbox list fail with distinct messages. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $Modules = Join-Path $RepoRoot 'Modules' + # Resolve by name under Modules/ so the test survives the function moving between modules. + $StandardPath = Get-ChildItem -Path $Modules -Recurse -Filter 'Invoke-CIPPStandardDisableSharedMailbox.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $StandardPath) { throw 'Could not locate Invoke-CIPPStandardDisableSharedMailbox.ps1 under Modules/' } + + # Stubs mirror the real signatures and are advanced functions on purpose: strict parameter + # binding makes signature drift in the standard fail loudly here instead of silently + # landing in $args. + function New-CIPPDbRequest { [CmdletBinding()] param($TenantFilter, $Type, $Fields) } + function New-GraphGetRequest { [CmdletBinding()] param($uri, $tenantid, $scope, $AsApp, $noPagination, $NoAuthCheck, $skipTokenCache, $ComplexFilter, $CountOnly) } + function New-GraphBulkRequest { [CmdletBinding()] param($tenantid, $NoAuthCheck, $scope, $asapp, $Requests, $NoPaginateIds, $Version, $Headers) } + function Set-CIPPDBCacheUsers { [CmdletBinding()] param($TenantFilter) } + function Write-LogMessage { [CmdletBinding()] param($API, $tenant, $Tenant2, $message, $sev, $headers, $LogData) } + function Write-StandardsAlert { [CmdletBinding()] param($message, $object, $tenant, $standardName, $standardId) } + function Set-CIPPStandardsCompareField { [CmdletBinding()] param($FieldName, $FieldValue, $CurrentValue, $ExpectedValue, $TenantFilter, $Tenant) } + function Add-CIPPBPAField { [CmdletBinding()] param($FieldName, $FieldValue, $StoreAs, $Tenant) } + function Get-NormalizedError { [CmdletBinding()] param($Message) $Message } + function Get-CippException { [CmdletBinding()] param($Exception) @{ NormalizedError = $Exception.Exception.Message } } + + . $StandardPath + + # Script scope: Pester 5 evaluates the Describe body at discovery, so plain variables + # declared there are not in scope inside It blocks or mocks at run time. + $script:Tenant = 'contoso.onmicrosoft.com' + + # Both shapes go through ConvertFrom-Json, matching what the cache and the adminapi hand back. + function script:New-CachedUser { + param( + [string]$Id, + [string]$Upn, + [bool]$Enabled = $true, + [bool]$OnPremSynced = $false + ) + [ordered]@{ + id = $Id + userPrincipalName = $Upn + accountEnabled = $Enabled + onPremisesSyncEnabled = $OnPremSynced + } | ConvertTo-Json -Depth 5 | ConvertFrom-Json + } + + function script:New-Mailbox { + param( + [string]$Id, + [string]$Upn, + [string]$Type = 'SharedMailbox' + ) + [ordered]@{ + ObjectKey = $Id + UserPrincipalName = $Upn + DisplayName = $Upn + RecipientTypeDetails = $Type + } | ConvertTo-Json -Depth 5 | ConvertFrom-Json + } +} + +Describe 'Invoke-CIPPStandardDisableSharedMailbox' { + BeforeEach { + $script:logs = [System.Collections.Generic.List[object]]::new() + $script:alerts = [System.Collections.Generic.List[object]]::new() + $script:compare = [System.Collections.Generic.List[object]]::new() + $script:patched = [System.Collections.Generic.List[string]]::new() + $script:users = @() + $script:mailboxes = @() + # Object keys the bulk PATCH should answer with a failure instead of a 204. + $script:failKeys = @() + + Mock -CommandName Add-CIPPBPAField -MockWith { } + Mock -CommandName Set-CIPPDBCacheUsers -MockWith { } + Mock -CommandName Write-LogMessage -MockWith { + param($API, $tenant, $message, $sev, $LogData) + $script:logs.Add(@{ Message = $message; Sev = $sev }) + } + Mock -CommandName Write-StandardsAlert -MockWith { + param($message, $object, $tenant, $standardName, $standardId) + $script:alerts.Add(@{ Message = $message; Object = @($object) }) + } + Mock -CommandName Set-CIPPStandardsCompareField -MockWith { + param($FieldName, $FieldValue, $CurrentValue, $ExpectedValue, $TenantFilter, $Tenant) + $script:compare.Add(@{ Current = $CurrentValue; Expected = $ExpectedValue }) + } + Mock -CommandName New-CIPPDbRequest -MockWith { $script:users } + Mock -CommandName New-GraphGetRequest -MockWith { $script:mailboxes } + Mock -CommandName New-GraphBulkRequest -MockWith { + param($tenantid, $Requests) + @(foreach ($Request in $Requests) { + $Key = $Request.url -replace '^users/', '' + $script:patched.Add($Key) + if ($script:failKeys -contains $Key) { + [pscustomobject]@{ id = $Request.id; status = 403; body = [pscustomobject]@{ error = [pscustomobject]@{ message = 'Insufficient privileges' } } } + } else { + [pscustomobject]@{ id = $Request.id; status = 204; body = $null } + } + }) + } + } + + Context 'selection' { + It 'reports a shared mailbox whose Entra account is already disabled as compliant' { + $script:users = @(New-CachedUser -Id 'shared1' -Upn 'shared@contoso.com' -Enabled $false) + $script:mailboxes = @(New-Mailbox -Id 'shared1' -Upn 'shared@contoso.com') + + Invoke-CIPPStandardDisableSharedMailbox -Tenant $script:Tenant -Settings @{ report = $true } + + $script:compare.Count | Should -Be 1 + @($script:compare[0].Current.DisableSharedMailbox) | Should -BeNullOrEmpty + } + + It 'reports a shared mailbox whose Entra account is still enabled as non-compliant' { + $script:users = @(New-CachedUser -Id 'shared1' -Upn 'shared@contoso.com') + $script:mailboxes = @(New-Mailbox -Id 'shared1' -Upn 'shared@contoso.com') + + Invoke-CIPPStandardDisableSharedMailbox -Tenant $script:Tenant -Settings @{ report = $true } + + @($script:compare[0].Current.DisableSharedMailbox).UserPrincipalName | Should -Be 'shared@contoso.com' + @($script:compare[0].Expected.DisableSharedMailbox) | Should -BeNullOrEmpty + } + + It 'applies the same join to scheduling mailboxes and skips directory-synced accounts' { + $script:users = @( + New-CachedUser -Id 'room1' -Upn 'room@contoso.com' + New-CachedUser -Id 'sched1' -Upn 'sched@contoso.com' -Enabled $false + New-CachedUser -Id 'synced1' -Upn 'synced@contoso.com' -OnPremSynced $true + ) + $script:mailboxes = @( + New-Mailbox -Id 'room1' -Upn 'room@contoso.com' -Type 'SchedulingMailbox' + New-Mailbox -Id 'sched1' -Upn 'sched@contoso.com' -Type 'SchedulingMailbox' + New-Mailbox -Id 'synced1' -Upn 'synced@contoso.com' + New-Mailbox -Id 'user1' -Upn 'user@contoso.com' -Type 'UserMailbox' + ) + + Invoke-CIPPStandardDisableSharedMailbox -Tenant $script:Tenant -Settings @{ report = $true } + + @($script:compare[0].Current.DisableSharedMailbox).UserPrincipalName | Should -Be 'room@contoso.com' + } + } + + Context 'remediation' { + It 'disables only the mailboxes whose account is still enabled' { + $script:users = @( + New-CachedUser -Id 'enabled1' -Upn 'enabled@contoso.com' + New-CachedUser -Id 'disabled1' -Upn 'disabled@contoso.com' -Enabled $false + ) + $script:mailboxes = @( + New-Mailbox -Id 'enabled1' -Upn 'enabled@contoso.com' + New-Mailbox -Id 'disabled1' -Upn 'disabled@contoso.com' + ) + + Invoke-CIPPStandardDisableSharedMailbox -Tenant $script:Tenant -Settings @{ remediate = $true } + + @($script:patched) | Should -Be @('enabled1') + } + + It 'reports the post-remediation state, not the state it found' { + $script:users = @(New-CachedUser -Id 'enabled1' -Upn 'enabled@contoso.com') + $script:mailboxes = @(New-Mailbox -Id 'enabled1' -Upn 'enabled@contoso.com') + + Invoke-CIPPStandardDisableSharedMailbox -Tenant $script:Tenant -Settings @{ remediate = $true; alert = $true; report = $true } + + @($script:patched) | Should -Be @('enabled1') + @($script:compare[0].Current.DisableSharedMailbox) | Should -BeNullOrEmpty + $script:alerts.Count | Should -Be 0 + } + + It 'keeps a mailbox it failed to disable in the report' { + $script:users = @( + New-CachedUser -Id 'ok1' -Upn 'ok@contoso.com' + New-CachedUser -Id 'bad1' -Upn 'bad@contoso.com' + ) + $script:mailboxes = @( + New-Mailbox -Id 'ok1' -Upn 'ok@contoso.com' + New-Mailbox -Id 'bad1' -Upn 'bad@contoso.com' + ) + $script:failKeys = @('bad1') + + Invoke-CIPPStandardDisableSharedMailbox -Tenant $script:Tenant -Settings @{ remediate = $true; report = $true } + + @($script:compare[0].Current.DisableSharedMailbox).UserPrincipalName | Should -Be 'bad@contoso.com' + } + } + + Context 'failure reporting' { + It 'names the cached user list when the database read fails' { + Mock -CommandName New-CIPPDbRequest -MockWith { throw 'table unavailable' } + + Invoke-CIPPStandardDisableSharedMailbox -Tenant $script:Tenant -Settings @{ report = $true } + + Should -Invoke New-GraphGetRequest -Times 0 -Exactly + @($script:logs | Where-Object { $_.Message -like '*could not read the cached user list*' }).Count | Should -Be 1 + $script:compare.Count | Should -Be 0 + } + + It 'names Exchange when the mailbox list fails' { + $script:users = @(New-CachedUser -Id 'shared1' -Upn 'shared@contoso.com') + Mock -CommandName New-GraphGetRequest -MockWith { throw 'Exchange is down' } + + Invoke-CIPPStandardDisableSharedMailbox -Tenant $script:Tenant -Settings @{ report = $true } + + @($script:logs | Where-Object { $_.Message -like '*could not list mailboxes from Exchange*' }).Count | Should -Be 1 + $script:compare.Count | Should -Be 0 + } + + It 'reports nothing at all when the user cache is empty' { + $script:users = @() + + Invoke-CIPPStandardDisableSharedMailbox -Tenant $script:Tenant -Settings @{ report = $true } + + Should -Invoke New-GraphGetRequest -Times 0 -Exactly + @($script:logs | Where-Object { $_.Message -like '*cached user list is empty*' }).Count | Should -Be 1 + $script:compare.Count | Should -Be 0 + } + } +} diff --git a/Tests/Standards/Invoke-CIPPStandardExternalComplianceTrusted.Tests.ps1 b/Tests/Standards/Invoke-CIPPStandardExternalComplianceTrusted.Tests.ps1 new file mode 100644 index 0000000000000..f11203bd218db --- /dev/null +++ b/Tests/Standards/Invoke-CIPPStandardExternalComplianceTrusted.Tests.ps1 @@ -0,0 +1,62 @@ +# Pester tests for Invoke-CIPPStandardExternalComplianceTrusted. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $StandardPath = Join-Path $RepoRoot 'Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardExternalComplianceTrusted.ps1' + + function Test-CIPPStandardLicense { [CmdletBinding()] param($StandardName, $TenantFilter, $Preset, [switch]$SkipLog) } + function New-GraphGetRequest { [CmdletBinding()] param($uri, $tenantid, $AsApp) } + function New-GraphPostRequest { [CmdletBinding()] param($tenantid, $uri, $type, $body, $AsApp, $ContentType) } + function Write-LogMessage { [CmdletBinding()] param($API, $tenant, $message, $sev, $LogData) } + function Write-StandardsAlert { [CmdletBinding()] param($message, $object, $tenant, $standardName, $standardId) } + function Set-CIPPStandardsCompareField { [CmdletBinding()] param($FieldName, $CurrentValue, $ExpectedValue, $TenantFilter) } + function Add-CIPPBPAField { [CmdletBinding()] param($FieldName, $FieldValue, $StoreAs, $Tenant) } + function Get-NormalizedError { [CmdletBinding()] param($Message) $Message } + + . $StandardPath + $script:Tenant = 'contoso.onmicrosoft.com' +} + +Describe 'Invoke-CIPPStandardExternalComplianceTrusted' { + BeforeEach { + Mock Test-CIPPStandardLicense { $true } + Mock New-GraphGetRequest { + [PSCustomObject]@{ + inboundTrust = [PSCustomObject]@{ + isMfaAccepted = $false + isCompliantDeviceAccepted = $false + isHybridAzureADJoinedDeviceAccepted = $true + } + } + } + Mock New-GraphPostRequest { } + Mock Write-LogMessage { } + Mock Write-StandardsAlert { } + Mock Set-CIPPStandardsCompareField { } + Mock Add-CIPPBPAField { } + } + + It 'remediates compliant-device trust without resetting sibling trust flags' { + Invoke-CIPPStandardExternalComplianceTrusted -Tenant $script:Tenant -Settings @{ remediate = $true; state = 'true' } + + Should -Invoke New-GraphPostRequest -Times 1 -Exactly -ParameterFilter { + $type -eq 'patch' -and + ($body | ConvertFrom-Json).inboundTrust.isCompliantDeviceAccepted -eq $true -and + ($body | ConvertFrom-Json).inboundTrust.isMfaAccepted -eq $false -and + ($body | ConvertFrom-Json).inboundTrust.isHybridAzureADJoinedDeviceAccepted -eq $true + } + } + + It 'reports the compliant-device property as the comparison field' { + Invoke-CIPPStandardExternalComplianceTrusted -Tenant $script:Tenant -Settings @{ report = $true; state = 'true' } + + Should -Invoke Set-CIPPStandardsCompareField -Times 1 -Exactly -ParameterFilter { + $FieldName -eq 'standards.ExternalComplianceTrusted' -and + $CurrentValue.isCompliantDeviceAccepted -eq $false -and + $ExpectedValue.isCompliantDeviceAccepted -eq $true + } + Should -Invoke Add-CIPPBPAField -Times 1 -Exactly -ParameterFilter { + $FieldName -eq 'ExternalComplianceTrusted' -and $FieldValue -eq $false + } + } +} diff --git a/Tests/Standards/Invoke-CIPPStandardFIDO2PasskeyProfiles.Tests.ps1 b/Tests/Standards/Invoke-CIPPStandardFIDO2PasskeyProfiles.Tests.ps1 new file mode 100644 index 0000000000000..33b4d529a0802 --- /dev/null +++ b/Tests/Standards/Invoke-CIPPStandardFIDO2PasskeyProfiles.Tests.ps1 @@ -0,0 +1,162 @@ +# Pester tests for Invoke-CIPPStandardFIDO2PasskeyProfiles +# +# HubSpot 47469698699: AAGUIDs added to the passkey profile did not take effect. A profile's AAGUID +# allow/block list only applies while keyRestrictions.isEnforced = $true; sent with isEnforced = $false +# the list is stored but inert - the profile keeps no active restriction (confirmed live against Graph +# beta). The standard exposed the AAGUIDs field and the "Enforce AAGUID Key Restrictions" switch as +# independent inputs, so an operator who added AAGUIDs without toggling the switch got an unenforced, +# ineffective list. The remediation must now enforce key restrictions whenever AAGUIDs are supplied. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $StandardPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Invoke-CIPPStandardFIDO2PasskeyProfiles.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $StandardPath) { throw 'Could not locate Invoke-CIPPStandardFIDO2PasskeyProfiles.ps1 under Modules/' } + + function New-GraphGetRequest { [CmdletBinding()] param($Uri, $tenantid, $AsApp) $script:mockCurrentConfig } + function New-GraphPostRequest { [CmdletBinding()] param($tenantid, $Uri, $Type, $Body, $ContentType, $AsApp) $script:lastBody = $Body } + function Write-LogMessage { [CmdletBinding()] param($API, $tenant, $message, $sev, $LogData, $headers) $script:logs.Add(@{ Message = $message; Sev = $sev }) } + function Write-StandardsAlert { [CmdletBinding()] param($message, $object, $tenant, $standardName, $standardId) } + function Set-CIPPStandardsCompareField { [CmdletBinding()] param($FieldName, $CurrentValue, $ExpectedValue, $TenantFilter) } + function Add-CIPPBPAField { [CmdletBinding()] param($FieldName, $FieldValue, $StoreAs, $Tenant) } + function Get-CippException { [CmdletBinding()] param($Exception) @{ NormalizedError = $Exception.Exception.Message } } + + . $StandardPath + + $script:Tenant = 'contoso.onmicrosoft.com' + $script:AndroidAAGUID = 'de1e552d-db1d-4423-a619-566b625cdc84' + $script:OperatorAAGUID = '11111111-1111-1111-1111-111111111111' + + # A tenant with the Microsoft default profile (no restrictions) plus an operator-managed profile + # that already carries an AAGUID - the remediation must resend the operator profile untouched. + function script:New-MockConfig { + [pscustomobject]@{ + '@odata.type' = '#microsoft.graph.fido2AuthenticationMethodConfiguration' + id = 'fido2' + state = 'enabled' + defaultPasskeyProfile = 'p-default' + passkeyProfiles = @( + [pscustomobject]@{ id = 'p-default'; name = 'Microsoft default profile'; passkeyTypes = 'deviceBound'; attestationEnforcement = 'disabled'; keyRestrictions = [pscustomobject]@{ isEnforced = $false; enforcementType = 'block'; aaGuids = @() } } + [pscustomobject]@{ id = 'p-custom'; name = 'Operator profile'; passkeyTypes = 'synced'; attestationEnforcement = 'registrationOnly'; keyRestrictions = [pscustomobject]@{ isEnforced = $true; enforcementType = 'allow'; aaGuids = @($script:OperatorAAGUID) } } + ) + } + } +} + +Describe 'Invoke-CIPPStandardFIDO2PasskeyProfiles remediation' { + BeforeEach { + $script:logs = [System.Collections.Generic.List[object]]::new() + $script:lastBody = $null + $script:mockCurrentConfig = script:New-MockConfig + } + + It 'enforces key restrictions when AAGUIDs are supplied even though the enforce switch is off' { + # The core regression: without this, isEnforced was $false and Graph dropped the AAGUIDs. + $Settings = @{ + remediate = $true + PasskeyTypes = 'deviceBound,synced' + AttestationEnforcement = 'disabled' + EnforceKeyRestrictions = $false + EnforcementType = 'allow' + AAGUIDs = $script:AndroidAAGUID + } + + Invoke-CIPPStandardFIDO2PasskeyProfiles -Tenant $script:Tenant -Settings $Settings + + $script:lastBody | Should -Not -BeNullOrEmpty + $body = $script:lastBody | ConvertFrom-Json + $default = @($body.passkeyProfiles) | Where-Object { $_.id -eq 'p-default' } + $default.keyRestrictions.isEnforced | Should -BeTrue + @($default.keyRestrictions.aaGuids) | Should -Be @($script:AndroidAAGUID) + $default.keyRestrictions.enforcementType | Should -Be 'allow' + } + + It 'serializes a single AAGUID as a JSON array' { + $Settings = @{ + remediate = $true + PasskeyTypes = 'deviceBound,synced' + AttestationEnforcement = 'disabled' + EnforceKeyRestrictions = $true + EnforcementType = 'allow' + AAGUIDs = $script:AndroidAAGUID + } + + Invoke-CIPPStandardFIDO2PasskeyProfiles -Tenant $script:Tenant -Settings $Settings + + # Guards the classic ConvertTo-Json single-element unwrap: aaGuids must be [".."], not "..". + $script:lastBody | Should -Match '"aaGuids":\[' + } + + It 'resends every other passkey profile untouched (the PATCH replaces the whole collection)' { + $Settings = @{ + remediate = $true + PasskeyTypes = 'deviceBound,synced' + AttestationEnforcement = 'disabled' + EnforceKeyRestrictions = $true + EnforcementType = 'allow' + AAGUIDs = $script:AndroidAAGUID + } + + Invoke-CIPPStandardFIDO2PasskeyProfiles -Tenant $script:Tenant -Settings $Settings + + $body = $script:lastBody | ConvertFrom-Json + @($body.passkeyProfiles).Count | Should -Be 2 + $operator = @($body.passkeyProfiles) | Where-Object { $_.id -eq 'p-custom' } + $operator | Should -Not -BeNullOrEmpty + @($operator.keyRestrictions.aaGuids) | Should -Be @($script:OperatorAAGUID) + } + + It 'preserves multiple supplied AAGUIDs on the default profile' { + $Settings = @{ + remediate = $true + PasskeyTypes = 'deviceBound,synced' + AttestationEnforcement = 'disabled' + EnforceKeyRestrictions = $false + EnforcementType = 'allow' + AAGUIDs = "$script:AndroidAAGUID, 90a3ccdf-635c-4729-a248-9b709135078f" + } + + Invoke-CIPPStandardFIDO2PasskeyProfiles -Tenant $script:Tenant -Settings $Settings + + $body = $script:lastBody | ConvertFrom-Json + $default = @($body.passkeyProfiles) | Where-Object { $_.id -eq 'p-default' } + @($default.keyRestrictions.aaGuids).Count | Should -Be 2 + @($default.keyRestrictions.aaGuids) | Should -Contain '90a3ccdf-635c-4729-a248-9b709135078f' + $default.keyRestrictions.isEnforced | Should -BeTrue + } + + It 'does not enforce or send AAGUIDs when none are supplied' { + # passkeyTypes differs from the tenant so remediation still fires and we can inspect the body. + $Settings = @{ + remediate = $true + PasskeyTypes = 'synced' + AttestationEnforcement = 'disabled' + EnforceKeyRestrictions = $false + EnforcementType = 'allow' + AAGUIDs = '' + } + + Invoke-CIPPStandardFIDO2PasskeyProfiles -Tenant $script:Tenant -Settings $Settings + + $body = $script:lastBody | ConvertFrom-Json + $default = @($body.passkeyProfiles) | Where-Object { $_.id -eq 'p-default' } + $default.keyRestrictions.isEnforced | Should -BeFalse + @($default.keyRestrictions.aaGuids).Count | Should -Be 0 + } + + It 'refuses to enforce with no AAGUIDs and does not PATCH' { + $Settings = @{ + remediate = $true + PasskeyTypes = 'deviceBound,synced' + AttestationEnforcement = 'disabled' + EnforceKeyRestrictions = $true + EnforcementType = 'allow' + AAGUIDs = '' + } + + Invoke-CIPPStandardFIDO2PasskeyProfiles -Tenant $script:Tenant -Settings $Settings + + $script:lastBody | Should -BeNullOrEmpty + @($script:logs | Where-Object { $_.Sev -eq 'Error' }).Count | Should -Be 1 + } +} diff --git a/Tests/Standards/Invoke-CIPPStandardGroupTemplate.Tests.ps1 b/Tests/Standards/Invoke-CIPPStandardGroupTemplate.Tests.ps1 index 0d57c7b166ba2..e21a988a8dbcc 100644 --- a/Tests/Standards/Invoke-CIPPStandardGroupTemplate.Tests.ps1 +++ b/Tests/Standards/Invoke-CIPPStandardGroupTemplate.Tests.ps1 @@ -27,6 +27,8 @@ BeforeAll { function Set-CIPPStandardsCompareField { [CmdletBinding()] param($FieldName, $CurrentValue, $ExpectedValue, $TenantFilter) } function Write-LogMessage { [CmdletBinding()] param($API, $tenant, $message, $sev, $headers, $LogData, $User) } function Get-NormalizedError { [CmdletBinding()] param($Message) $Message } + # Default no-op: only the variable-name tests mock this to actually substitute tokens. + function Get-CIPPTextReplacement { [CmdletBinding()] param($TenantFilter, $Text, [switch]$EscapeForJson) $Text } . $StandardPath @@ -61,6 +63,23 @@ BeforeAll { } } + # A generic template whose displayName carries a %tenantname% token, the way an operator writes + # a per-tenant group name. New-GraphPostRequest resolves the token at creation time, so the real + # group is named 'Contoso-Group'. + $script:VariableGroupName = '%tenantname%-Group' + $script:ResolvedGroupName = 'Contoso-Group' + function script:New-VariableTemplateEntity { + [pscustomobject]@{ + JSON = ([pscustomobject]@{ + displayName = $script:VariableGroupName + description = 'Test description' + groupType = 'generic' + membershipRules = $null + GUID = '33333333-3333-3333-3333-333333333333' + } | ConvertTo-Json -Depth 10) + } + } + function script:New-Settings { param([switch]$Remediate, [switch]$Report) [pscustomobject]@{ @@ -107,6 +126,40 @@ Describe 'Invoke-CIPPStandardGroupTemplate' { } } + Context 'template display name contains a %variable%' { + BeforeEach { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { script:New-VariableTemplateEntity } + # Resolve %tenantname% the way Get-CIPPTextReplacement does at runtime, so comparisons run + # against the same name New-GraphPostRequest gives the real group. + Mock -CommandName Get-CIPPTextReplacement -MockWith { + param($TenantFilter, $Text, [switch]$EscapeForJson) + $Text -replace '%tenantname%', 'Contoso' + } + } + + It 'does not recreate the group when the resolved-name group already exists' { + Mock -CommandName New-GraphGetRequest -MockWith { + @([pscustomobject]@{ id = 'existing-id'; displayName = $script:ResolvedGroupName; description = 'Test description'; membershipRule = $null }) + } + + Invoke-CIPPStandardGroupTemplate -Tenant $script:Tenant -Settings (script:New-Settings -Remediate) + + Should -Invoke -CommandName New-CIPPGroup -Times 0 -Exactly -Because 'the group exists under its resolved name, so recreating it would make a duplicate' + } + + It 'reports compliant when the resolved-name group exists' { + Mock -CommandName New-GraphGetRequest -MockWith { + @([pscustomobject]@{ id = 'existing-id'; displayName = $script:ResolvedGroupName; description = 'Test description'; membershipRule = $null }) + } + + Invoke-CIPPStandardGroupTemplate -Tenant $script:Tenant -Settings (script:New-Settings -Report) + + Should -Invoke -CommandName Set-CIPPStandardsCompareField -Times 1 -Exactly -ParameterFilter { + @($CurrentValue.MissingGroups).Count -eq 0 + } -Because 'the resolved name matches an existing group, so nothing is missing' + } + } + Context 'existing groups cannot be read' { It 'creates no groups when the Graph read fails, avoiding duplicate twins' { Mock -CommandName New-GraphGetRequest -MockWith { throw 'Request not authorised for tenant' } diff --git a/Tests/Standards/Invoke-CIPPStandardOneDriveLicensedQuota.Tests.ps1 b/Tests/Standards/Invoke-CIPPStandardOneDriveLicensedQuota.Tests.ps1 index f18b714f4da79..ad9d488808345 100644 --- a/Tests/Standards/Invoke-CIPPStandardOneDriveLicensedQuota.Tests.ps1 +++ b/Tests/Standards/Invoke-CIPPStandardOneDriveLicensedQuota.Tests.ps1 @@ -18,7 +18,7 @@ BeforeAll { function Test-CIPPStandardLicense { [CmdletBinding()] param($StandardName, $TenantFilter, $RequiredCapabilities, $Preset, [switch]$SkipLog) } function New-GraphGetRequest { [CmdletBinding()] param($uri, $tenantid, $AsApp, $NoAuthCheck, $skipTokenCache, [switch]$ComplexFilter, $CountOnly) } function New-GraphBulkRequest { [CmdletBinding()] param($tenantid, $NoAuthCheck, $scope, $asapp, $Requests, $NoPaginateIds, $Version, $Headers) } - function Set-CIPPSPOSite { [CmdletBinding()] param($TenantFilter, $SiteUrl, $Properties) } + function Set-CIPPSPOSiteBulk { [CmdletBinding()] param($TenantFilter, $Sites, $MaxConcurrency, $MaxRetries, [switch]$UseCertificate) } function Write-LogMessage { [CmdletBinding()] param($API, $tenant, $message, $sev, $headers, $LogData) } function Write-StandardsAlert { [CmdletBinding()] param($message, $object, $tenant, $standardName, $standardId) } function Set-CIPPStandardsCompareField { [CmdletBinding()] param($FieldName, $CurrentValue, $ExpectedValue, $Tenant) } @@ -77,10 +77,15 @@ Describe 'Invoke-CIPPStandardOneDriveLicensedQuota' { param($API, $tenant, $message, $sev, $LogData) $script:logs.Add(@{ Message = $message; Sev = $sev }) } - Mock -CommandName Set-CIPPSPOSite -MockWith { - param($TenantFilter, $SiteUrl, $Properties) - $script:setCalls.Add(@{ SiteUrl = $SiteUrl; Properties = $Properties }) - return @([pscustomobject]@{ SchemaVersion = '15.0.0.0'; ErrorInfo = $null }) + # The standard raises quotas through one concurrent Set-CIPPSPOSiteBulk fan-out rather than + # a Set-CIPPSPOSite call per drive. Expand its -Sites back into the per-site records the + # assertions read, and grade every site a success unless a test overrides this mock. + Mock -CommandName Set-CIPPSPOSiteBulk -MockWith { + param($TenantFilter, $Sites, $MaxConcurrency, $MaxRetries, [switch]$UseCertificate) + @(foreach ($Site in $Sites) { + $script:setCalls.Add(@{ SiteUrl = $Site.SiteUrl; Properties = $Site.Properties }) + [pscustomobject]@{ SiteUrl = $Site.SiteUrl; Success = $true; Error = $null } + }) } } @@ -162,13 +167,16 @@ Describe 'Invoke-CIPPStandardOneDriveLicensedQuota' { } It 'continues with the remaining drives when one CSOM update fails' { - Mock -CommandName Set-CIPPSPOSite -MockWith { - param($TenantFilter, $SiteUrl, $Properties) - $script:setCalls.Add(@{ SiteUrl = $SiteUrl; Properties = $Properties }) - if ($SiteUrl -match 'u1_contoso_com') { - return @([pscustomobject]@{ ErrorInfo = [pscustomobject]@{ ErrorMessage = 'Access denied.' } }) - } - return @([pscustomobject]@{ ErrorInfo = $null }) + Mock -CommandName Set-CIPPSPOSiteBulk -MockWith { + param($TenantFilter, $Sites, $MaxConcurrency, $MaxRetries, [switch]$UseCertificate) + @(foreach ($Site in $Sites) { + $script:setCalls.Add(@{ SiteUrl = $Site.SiteUrl; Properties = $Site.Properties }) + if ($Site.SiteUrl -match 'u1_contoso_com') { + [pscustomobject]@{ SiteUrl = $Site.SiteUrl; Success = $false; Error = 'Access denied.' } + } else { + [pscustomobject]@{ SiteUrl = $Site.SiteUrl; Success = $true; Error = $null } + } + }) } { Invoke-CIPPStandardOneDriveLicensedQuota -Tenant $script:Tenant -Settings @{ remediate = $true } } | diff --git a/Tests/Standards/Invoke-CIPPStandardQuarantineRequestAlert.Tests.ps1 b/Tests/Standards/Invoke-CIPPStandardQuarantineRequestAlert.Tests.ps1 new file mode 100644 index 0000000000000..4a2b4a963e88c --- /dev/null +++ b/Tests/Standards/Invoke-CIPPStandardQuarantineRequestAlert.Tests.ps1 @@ -0,0 +1,178 @@ +# Pester tests for Invoke-CIPPStandardQuarantineRequestAlert +# +# The standard manages a CIPP-owned Protection Alert ('CIPP User requested to release a quarantined +# message'). The regression these tests guard against: report/compliance was computed from a snapshot +# read BEFORE remediation, so a freshly created or updated alert still reported its old (empty) +# recipients until the next scheduled run - which the tenant saw as "force ran, nothing changed". +# The fix re-reads the live state after remediating so the compare field reflects what was applied. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $StandardPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Invoke-CIPPStandardQuarantineRequestAlert.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $StandardPath) { throw 'Could not locate Invoke-CIPPStandardQuarantineRequestAlert.ps1 under Modules/' } + + function Test-CIPPStandardLicense { [CmdletBinding()] param($StandardName, $TenantFilter, $Preset, [switch]$SkipLog) } + function New-ExoRequest { [CmdletBinding()] param($tenantid, $cmdlet, $cmdParams, [switch]$Compliance, $UseSystemMailbox) } + function Write-LogMessage { [CmdletBinding()] param($API, $Tenant, $Message, $sev, $LogData) } + function Write-StandardsAlert { [CmdletBinding()] param($message, $object, $tenant, $standardName, $standardId) } + function Set-CIPPStandardsCompareField { [CmdletBinding()] param($FieldName, $FieldValue, $CurrentValue, $ExpectedValue, $TenantFilter) } + function Add-CIPPBPAField { [CmdletBinding()] param($FieldName, $FieldValue, $StoreAs, $Tenant) } + function Get-NormalizedError { [CmdletBinding()] param($Message) $Message } + + . $StandardPath + + $script:Tenant = 'contoso.onmicrosoft.com' + $script:PolicyName = 'CIPP User requested to release a quarantined message' + $script:NotifyUser = 'helpdesk@dpndbl.com' +} + +Describe 'Invoke-CIPPStandardQuarantineRequestAlert' { + BeforeEach { + # $script:alertObj models the tenant's live Protection Alert: $null = it does not exist. + $script:alertObj = $null + $script:compareFields = [System.Collections.Generic.List[object]]::new() + $script:bpaFields = [System.Collections.Generic.List[object]]::new() + + Mock -CommandName Test-CIPPStandardLicense -MockWith { $true } + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Write-StandardsAlert -MockWith { } + Mock -CommandName Add-CIPPBPAField -MockWith { + param($FieldName, $FieldValue, $StoreAs, $Tenant) + $script:bpaFields.Add([pscustomobject]@{ Field = $FieldName; FieldValue = $FieldValue }) + } + Mock -CommandName Set-CIPPStandardsCompareField -MockWith { + param($FieldName, $FieldValue, $CurrentValue, $ExpectedValue, $TenantFilter) + $script:compareFields.Add([pscustomobject]@{ Field = $FieldName; Current = $CurrentValue; Expected = $ExpectedValue }) + } + # Stateful EXO mock: reads reflect the current alert; writes mutate it, so a re-read after + # remediation sees the applied change. + Mock -CommandName New-ExoRequest -MockWith { + param($tenantid, $cmdlet, $cmdParams, [switch]$Compliance, $UseSystemMailbox) + switch ($cmdlet) { + 'Get-ProtectionAlert' { return $script:alertObj } + 'New-ProtectionAlert' { $script:alertObj = [pscustomobject]@{ Name = $cmdParams.name; NotifyUser = @($cmdParams.NotifyUser) }; return } + 'Set-ProtectionAlert' { $script:alertObj = [pscustomobject]@{ Name = $cmdParams.Identity; NotifyUser = @($cmdParams.NotifyUser) }; return } + 'Remove-ProtectionAlert' { $script:alertObj = $null; return } + default { return } + } + } + } + + It 'reports the freshly created alert as compliant in the same run' { + # Core regression: with no alert present, a remediate+report run must create the alert AND + # report the applied recipients as compliant - not the pre-remediation empty snapshot. + Invoke-CIPPStandardQuarantineRequestAlert -Tenant $script:Tenant -Settings @{ + NotifyUser = $script:NotifyUser + state = 'enabled' + remediate = $true + report = $true + } + + Should -Invoke New-ExoRequest -Times 1 -Exactly -ParameterFilter { $cmdlet -eq 'New-ProtectionAlert' } + $script:compareFields.Count | Should -Be 1 + $script:compareFields[0].Current.NotifyUser | Should -Contain $script:NotifyUser + $script:bpaFields[0].FieldValue | Should -BeTrue + } + + It 'updates recipients on an existing alert and reports the applied value' { + $script:alertObj = [pscustomobject]@{ Name = $script:PolicyName; NotifyUser = @('old@contoso.com') } + + Invoke-CIPPStandardQuarantineRequestAlert -Tenant $script:Tenant -Settings @{ + NotifyUser = $script:NotifyUser + state = 'enabled' + remediate = $true + report = $true + } + + Should -Invoke New-ExoRequest -Times 1 -Exactly -ParameterFilter { $cmdlet -eq 'Set-ProtectionAlert' } + $script:compareFields[0].Current.NotifyUser | Should -Contain $script:NotifyUser + $script:bpaFields[0].FieldValue | Should -BeTrue + } + + It 'reports an existing correctly configured alert as compliant without writing' { + $script:alertObj = [pscustomobject]@{ Name = $script:PolicyName; NotifyUser = @($script:NotifyUser) } + + Invoke-CIPPStandardQuarantineRequestAlert -Tenant $script:Tenant -Settings @{ + NotifyUser = $script:NotifyUser + state = 'enabled' + report = $true + } + + Should -Invoke New-ExoRequest -Times 0 -ParameterFilter { $cmdlet -in @('New-ProtectionAlert', 'Set-ProtectionAlert') } + $script:compareFields[0].Current.NotifyUser | Should -Contain $script:NotifyUser + $script:bpaFields[0].FieldValue | Should -BeTrue + } + + It 'writes Current and Expected as matching arrays when compliant' { + # Compliance is decided by CurrentValue -eq ExpectedValue, so both sides must carry the same + # shape. A single-element Expected must stay an array (a bare @() around an if-expression would + # unroll it to a scalar and never match the array-shaped Current value). + $script:alertObj = [pscustomobject]@{ Name = $script:PolicyName; NotifyUser = @($script:NotifyUser) } + + Invoke-CIPPStandardQuarantineRequestAlert -Tenant $script:Tenant -Settings @{ + NotifyUser = $script:NotifyUser + state = 'enabled' + report = $true + } + + $Current = $script:compareFields[0].Current.NotifyUser + $Expected = $script:compareFields[0].Expected.NotifyUser + ($Current -is [array]) | Should -BeTrue + ($Expected -is [array]) | Should -BeTrue + ($Current -join '|') | Should -Be ($Expected -join '|') + } + + It 'treats an alert with an unexpected extra recipient as non-compliant' { + # Exact-set semantics: an address CIPP did not configure is drift, even though the configured + # address is present. + $script:alertObj = [pscustomobject]@{ Name = $script:PolicyName; NotifyUser = @($script:NotifyUser, 'extra@contoso.com') } + + Invoke-CIPPStandardQuarantineRequestAlert -Tenant $script:Tenant -Settings @{ + NotifyUser = $script:NotifyUser + state = 'enabled' + report = $true + } + + $script:bpaFields[0].FieldValue | Should -BeFalse + $script:compareFields[0].Current.NotifyUser | Should -Contain 'extra@contoso.com' + } + + It 'reports a missing alert as non-compliant with no recipients' { + Invoke-CIPPStandardQuarantineRequestAlert -Tenant $script:Tenant -Settings @{ + NotifyUser = $script:NotifyUser + state = 'enabled' + report = $true + } + + $script:bpaFields[0].FieldValue | Should -BeFalse + @($script:compareFields[0].Current.NotifyUser) | Should -BeNullOrEmpty + } + + It 'removes the alert and reports compliant when state is removed' { + $script:alertObj = [pscustomobject]@{ Name = $script:PolicyName; NotifyUser = @($script:NotifyUser) } + + Invoke-CIPPStandardQuarantineRequestAlert -Tenant $script:Tenant -Settings @{ + state = 'removed' + remediate = $true + report = $true + } + + Should -Invoke New-ExoRequest -Times 1 -Exactly -ParameterFilter { $cmdlet -eq 'Remove-ProtectionAlert' } + $script:bpaFields[0].FieldValue | Should -BeTrue + } + + It 'skips everything when the tenant is not licensed for Exchange' { + Mock -CommandName Test-CIPPStandardLicense -MockWith { $false } + + Invoke-CIPPStandardQuarantineRequestAlert -Tenant $script:Tenant -Settings @{ + NotifyUser = $script:NotifyUser + state = 'enabled' + remediate = $true + report = $true + } + + Should -Invoke New-ExoRequest -Times 0 + $script:compareFields.Count | Should -Be 0 + } +} diff --git a/Tests/Standards/Invoke-CIPPStandardSPOVersionControl.Tests.ps1 b/Tests/Standards/Invoke-CIPPStandardSPOVersionControl.Tests.ps1 new file mode 100644 index 0000000000000..c64e96c63123d --- /dev/null +++ b/Tests/Standards/Invoke-CIPPStandardSPOVersionControl.Tests.ps1 @@ -0,0 +1,149 @@ +# Pester tests for Invoke-CIPPStandardSPOVersionControl +# +# Issue #503: with automatic version trimming enabled the standard still wrote null placeholders +# for MajorVersionLimit / ExpireVersionsAfterDays into the expected object while the current +# object carried the tenant-managed numbers. The compare report and drift detection grade the +# two objects as a whole, so every auto-trim tenant showed as non-compliant even though the +# standard itself considered the state correct. In auto-trim mode only the trim flag is graded. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $StandardPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Invoke-CIPPStandardSPOVersionControl.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $StandardPath) { throw 'Could not locate Invoke-CIPPStandardSPOVersionControl.ps1 under Modules/' } + + function Test-CIPPStandardLicense { [CmdletBinding()] param($StandardName, $TenantFilter, $Preset, [switch]$SkipLog) } + function Get-CIPPSPOTenant { [CmdletBinding()] param($TenantFilter, [switch]$UseCertificate) } + function Set-CIPPSPOTenant { [CmdletBinding()] param([Parameter(ValueFromPipeline)]$InputObject, $MethodName, $MethodParameters, [switch]$UseCertificate) } + function Set-CIPPSPOSiteBulk { [CmdletBinding()] param($TenantFilter, $Sites, [switch]$UseCertificate) } + function New-GraphGetRequest { [CmdletBinding()] param($uri, $tenantid, $AsApp, $NoAuthCheck, $skipTokenCache) } + function Write-LogMessage { [CmdletBinding()] param($API, $tenant, $Tenant2, $message, $sev, $headers, $LogData) } + function Write-StandardsAlert { [CmdletBinding()] param($message, $object, $tenant, $standardName, $standardId) } + function Set-CIPPStandardsCompareField { [CmdletBinding()] param($FieldName, $CurrentValue, $ExpectedValue, $TenantFilter) } + function Add-CIPPBPAField { [CmdletBinding()] param($FieldName, $FieldValue, $StoreAs, $Tenant) } + function Get-CippException { [CmdletBinding()] param($Exception) @{ NormalizedError = $Exception.Exception.Message } } + + . $StandardPath + + $script:Tenant = 'contoso.onmicrosoft.com' +} + +Describe 'Invoke-CIPPStandardSPOVersionControl report' { + BeforeEach { + $script:Compare = $null + $script:Bpa = $null + $script:Alerts = [System.Collections.Generic.List[object]]::new() + + Mock -CommandName Test-CIPPStandardLicense -MockWith { $true } + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Set-CIPPSPOTenant -MockWith { } + Mock -CommandName Write-StandardsAlert -MockWith { + param($message, $object, $tenant, $standardName, $standardId) + $script:Alerts.Add($message) + } + Mock -CommandName Set-CIPPStandardsCompareField -MockWith { + param($FieldName, $CurrentValue, $ExpectedValue, $TenantFilter) + $script:Compare = @{ FieldName = $FieldName; Current = $CurrentValue; Expected = $ExpectedValue } + } + Mock -CommandName Add-CIPPBPAField -MockWith { + param($FieldName, $FieldValue, $StoreAs, $Tenant) + $script:Bpa = $FieldValue + } + } + + Context 'automatic trimming desired' { + BeforeEach { + # A tenant with auto-trim on still reports the limits SharePoint manages for it. + Mock -CommandName Get-CIPPSPOTenant -MockWith { + [pscustomobject]@{ + _ObjectIdentity_ = 'id' + TenantFilter = $script:Tenant + EnableAutoExpirationVersionTrim = $true + MajorVersionLimit = 500 + ExpireVersionsAfterDays = 30 + } + } + } + + It 'grades only the trim flag so tenant-managed limits are not drift' { + Invoke-CIPPStandardSPOVersionControl -Tenant $script:Tenant -Settings @{ EnableAutoTrim = $true; report = $true } + + $script:Compare.FieldName | Should -Be 'standards.SPOVersionControl' + @($script:Compare.Current.PSObject.Properties.Name) | Should -Be @('EnableAutoExpirationVersionTrim') + @($script:Compare.Expected.PSObject.Properties.Name) | Should -Be @('EnableAutoExpirationVersionTrim') + $script:Compare.Current.EnableAutoExpirationVersionTrim | Should -BeTrue + $script:Compare.Expected.EnableAutoExpirationVersionTrim | Should -BeTrue + # The same whole-object comparison the report and drift paths perform. + ($script:Compare.Current | ConvertTo-Json -Compress) | Should -Be ($script:Compare.Expected | ConvertTo-Json -Compress) + $script:Bpa | Should -BeTrue + } + + It 'still reports a tenant that has automatic trimming off' { + Mock -CommandName Get-CIPPSPOTenant -MockWith { + [pscustomobject]@{ + _ObjectIdentity_ = 'id' + TenantFilter = $script:Tenant + EnableAutoExpirationVersionTrim = $false + MajorVersionLimit = 500 + ExpireVersionsAfterDays = 0 + } + } + + Invoke-CIPPStandardSPOVersionControl -Tenant $script:Tenant -Settings @{ EnableAutoTrim = $true; report = $true; alert = $true } + + $script:Compare.Current.EnableAutoExpirationVersionTrim | Should -BeFalse + $script:Compare.Expected.EnableAutoExpirationVersionTrim | Should -BeTrue + $script:Bpa | Should -BeFalse + $script:Alerts.Count | Should -Be 1 + $script:Alerts[0] | Should -Match 'managed by Microsoft' + $script:Alerts[0] | Should -Not -Match 'Expected: .*MajorVersionLimit=' + } + + It 'does not write when the tenant already trims automatically' { + Invoke-CIPPStandardSPOVersionControl -Tenant $script:Tenant -Settings @{ EnableAutoTrim = $true; remediate = $true } + + Should -Invoke -CommandName Set-CIPPSPOTenant -Times 0 -Exactly + } + } + + Context 'fixed limits desired' { + It 'grades the flag and both limits' { + Mock -CommandName Get-CIPPSPOTenant -MockWith { + [pscustomobject]@{ + _ObjectIdentity_ = 'id' + TenantFilter = $script:Tenant + EnableAutoExpirationVersionTrim = $false + MajorVersionLimit = 50 + ExpireVersionsAfterDays = 365 + } + } + + Invoke-CIPPStandardSPOVersionControl -Tenant $script:Tenant -Settings @{ EnableAutoTrim = $false; MajorVersionLimit = 50; ExpireVersionsAfterDays = 365; report = $true } + + @($script:Compare.Expected.PSObject.Properties.Name | Sort-Object) | Should -Be @('EnableAutoExpirationVersionTrim', 'ExpireVersionsAfterDays', 'MajorVersionLimit') + $script:Compare.Expected.EnableAutoExpirationVersionTrim | Should -BeFalse + $script:Compare.Expected.MajorVersionLimit | Should -Be 50 + $script:Compare.Expected.ExpireVersionsAfterDays | Should -Be 365 + ($script:Compare.Current | ConvertTo-Json -Compress) | Should -Be ($script:Compare.Expected | ConvertTo-Json -Compress) + $script:Bpa | Should -BeTrue + } + + It 'reports a limit that differs from the configured one' { + Mock -CommandName Get-CIPPSPOTenant -MockWith { + [pscustomobject]@{ + _ObjectIdentity_ = 'id' + TenantFilter = $script:Tenant + EnableAutoExpirationVersionTrim = $false + MajorVersionLimit = 500 + ExpireVersionsAfterDays = 365 + } + } + + Invoke-CIPPStandardSPOVersionControl -Tenant $script:Tenant -Settings @{ EnableAutoTrim = $false; MajorVersionLimit = 50; ExpireVersionsAfterDays = 365; report = $true } + + $script:Compare.Current.MajorVersionLimit | Should -Be 500 + $script:Compare.Expected.MajorVersionLimit | Should -Be 50 + $script:Bpa | Should -BeFalse + } + } +} diff --git a/Tests/Standards/Invoke-CIPPStandardUserSubmissions.Tests.ps1 b/Tests/Standards/Invoke-CIPPStandardUserSubmissions.Tests.ps1 index fa625aa7d5b9f..4c72eb5038a6b 100644 --- a/Tests/Standards/Invoke-CIPPStandardUserSubmissions.Tests.ps1 +++ b/Tests/Standards/Invoke-CIPPStandardUserSubmissions.Tests.ps1 @@ -12,7 +12,7 @@ BeforeAll { function Test-CIPPStandardLicense { [CmdletBinding()] param($StandardName, $TenantFilter, $Preset, [switch]$SkipLog) } function Get-CIPPTextReplacement { [CmdletBinding()] param($TenantFilter, $Text, [switch]$EscapeForJson) } - function New-ExoRequest { [CmdletBinding()] param($tenantid, $cmdlet, $cmdParams, [switch]$UseSystemMailbox) } + function New-ExoRequest { [CmdletBinding()] param($tenantid, $cmdlet, $cmdParams, $UseSystemMailbox) } function Write-LogMessage { [CmdletBinding()] param($API, $tenant, $message, $sev, $LogData) } function Write-StandardsAlert { [CmdletBinding()] param($message, $object, $tenant, $standardName, $standardId) } function Set-CIPPStandardsCompareField { @@ -117,6 +117,74 @@ Describe 'Invoke-CIPPStandardUserSubmissions comparison payload' { $Comparison.Current.CustomDestinationRule.SentTo | Should -Be $Email } + It 'expects reporting to Microsoft OFF when the destination is the reporting mailbox only' { + $Email = 'phish@contoso.com' + $script:policyState = [pscustomobject]@{ + EnableReportToMicrosoft = $false + ReportJunkToCustomizedAddress = $true + ReportNotJunkToCustomizedAddress = $true + ReportPhishToCustomizedAddress = $true + ReportJunkAddresses = $Email + ReportNotJunkAddresses = $Email + ReportPhishAddresses = $Email + } + $script:ruleState = [pscustomobject]@{ + State = 'Enabled' + SentTo = $Email + } + + Invoke-CIPPStandardUserSubmissions -Tenant $script:Tenant -Settings @{ + state = 'enable' + email = $Email + reportDestination = 'Mailbox' + report = $true + } + + $Comparison = $script:compareFields[0] + $Comparison.Expected.EnableReportToMicrosoft | Should -BeFalse + $Comparison.Expected.CustomDestinationRule.State | Should -Be 'Enabled' + $Comparison.Expected.CustomDestinationRule.SentTo | Should -Be $Email + $Comparison.Current.EnableReportToMicrosoft | Should -BeFalse + } + + It 'remediates to the reporting mailbox only without re-enabling reporting to Microsoft' { + # The exact regression from issue #409: a tenant set to 'My reporting mailbox only' + # must not be flipped back to reporting to Microsoft by the standard. + $Email = 'phish@contoso.com' + $script:ruleState = @() + + Invoke-CIPPStandardUserSubmissions -Tenant $script:Tenant -Settings @{ + state = 'enable' + email = $Email + reportDestination = 'Mailbox' + remediate = $true + } + + Should -Invoke New-ExoRequest -Times 1 -Exactly -ParameterFilter { + $cmdlet -eq 'Set-ReportSubmissionPolicy' -and + $cmdParams.EnableReportToMicrosoft -eq $false -and + $cmdParams.ReportPhishToCustomizedAddress -eq $true -and + $cmdParams.ReportPhishAddresses -eq $Email + } + } + + It 'still remediates to Microsoft and the reporting mailbox when no destination is chosen' { + $Email = 'phish@contoso.com' + $script:ruleState = @() + + Invoke-CIPPStandardUserSubmissions -Tenant $script:Tenant -Settings @{ + state = 'enable' + email = $Email + remediate = $true + } + + Should -Invoke New-ExoRequest -Times 1 -Exactly -ParameterFilter { + $cmdlet -eq 'Set-ReportSubmissionPolicy' -and + $cmdParams.EnableReportToMicrosoft -eq $true -and + $cmdParams.ReportPhishAddresses -eq $Email + } + } + It 'shows both reporting and the custom destination rule disabled when the standard is disabled' { $script:policyState = [pscustomobject]@{ EnableReportToMicrosoft = $false diff --git a/Tests/Standards/Invoke-CIPPStandardcalDefault.Coverage.Tests.ps1 b/Tests/Standards/Invoke-CIPPStandardcalDefault.Coverage.Tests.ps1 new file mode 100644 index 0000000000000..a399c1fbf5358 --- /dev/null +++ b/Tests/Standards/Invoke-CIPPStandardcalDefault.Coverage.Tests.ps1 @@ -0,0 +1,125 @@ +# Pester tests for the coverage guard in Invoke-CIPPStandardcalDefault. +# +# Regression under test: only mailboxes with a cached 'Default' row are graded, so a missing +# mailbox could never enter $NeedsUpdate and an incomplete collection read as a clean sweep. +# On a real tenant 44 of 79 went uncollected; the standard saw 35 rows, all correct, and +# logged the all-clear while 8 of the unseen mailboxes were misconfigured. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardcalDefault.ps1' + if (-not (Test-Path $FunctionPath)) { throw "Could not locate $FunctionPath" } + + # Minimal stubs so Mock has commands to replace during tests. + function Write-LogMessage { param($API, $tenant, $message, $sev, $LogData) } + function Test-CIPPStandardLicense { param($StandardName, $TenantFilter, $Preset) } + function New-CIPPDbRequest { param($TenantFilter, $Type, [string[]]$Fields) } + function Set-CIPPStandardsCompareField { param($FieldName, $CurrentValue, $ExpectedValue, $TenantFilter) } + function Add-CIPPBPAField { param($FieldName, $FieldValue, $StoreAs, $Tenant) } + function Write-StandardsAlert { param($message, $object, $tenant, $standardName, $standardId) } + function New-ExoRequest { param($tenantid, $cmdlet, $cmdParams) } + function Set-CIPPDBCacheMailboxes { param($TenantFilter) } + function Get-CippException { param($Exception) } + + . $FunctionPath + + function New-CalRow { + param($Upn, $Rights) + [PSCustomObject]@{ Identity = "$Upn`:\Calendar"; User = 'Default'; AccessRights = @($Rights) } + } +} + +Describe 'Invoke-CIPPStandardcalDefault coverage guard' { + BeforeEach { + $script:Messages = [System.Collections.Generic.List[object]]::new() + $script:Compared = $null + + Mock -CommandName Test-CIPPStandardLicense -MockWith { $true } + Mock -CommandName Write-LogMessage -MockWith { $script:Messages.Add([PSCustomObject]@{ Message = $message; Sev = $sev }) } + Mock -CommandName Set-CIPPStandardsCompareField -MockWith { $script:Compared = $CurrentValue } + Mock -CommandName Add-CIPPBPAField -MockWith { } + Mock -CommandName Write-StandardsAlert -MockWith { } + # Nothing here may reach Exchange: every case below is a no-drift case. + Mock -CommandName New-ExoRequest -MockWith { throw 'New-ExoRequest must not be called' } + + # Pester 5 runs a Describe body at discovery, so shared fixtures have to be built here + # to exist when an It actually runs. + $script:Settings = @{ permissionLevel = 'Reviewer'; remediate = $true; alert = $true; report = $true } + } + + It 'reports a clean sweep only when every cached mailbox was graded' { + Mock -CommandName New-CIPPDbRequest -MockWith { + if ($Type -eq 'Mailboxes') { @(1..3 | ForEach-Object { [PSCustomObject]@{ UPN = "u$_@x.com" } }) } + else { @(1..3 | ForEach-Object { New-CalRow -Upn "u$_@x.com" -Rights 'Reviewer' }) } + } + + Invoke-CIPPStandardcalDefault -Tenant 'contoso.onmicrosoft.com' -Settings $script:Settings + + $script:Compared.state | Should -Be 'Configured correctly' + @($script:Messages | Where-Object { $_.Sev -eq 'Warning' }).Count | Should -Be 0 + @($script:Messages | Where-Object { $_.Message -like 'All 3 calendars already*' }).Count | Should -Be 1 + } + + It 'does not claim alignment when mailboxes were never evaluated' { + # 3 mailboxes cached, but only 1 has a Default calendar row - the shape the collector bug + # produced. Every graded row is already correct, so the old code logged the all-clear. + Mock -CommandName New-CIPPDbRequest -MockWith { + if ($Type -eq 'Mailboxes') { @(1..3 | ForEach-Object { [PSCustomObject]@{ UPN = "u$_@x.com" } }) } + else { @(New-CalRow -Upn 'u1@x.com' -Rights 'Reviewer') } + } + + Invoke-CIPPStandardcalDefault -Tenant 'contoso.onmicrosoft.com' -Settings $script:Settings + + $script:Compared.state | Should -BeNullOrEmpty + $script:Compared.UncheckedMailboxes | Should -Be 2 + @($script:Compared.NonCompliantCalendars).Count | Should -Be 0 + + $Warnings = @($script:Messages | Where-Object { $_.Sev -eq 'Warning' }) + $Warnings.Count | Should -Be 2 # one from the remediate branch, one from the alert branch + $Warnings[0].Message | Should -BeLike '*2 of 3 mailboxes have no cached Default calendar permission and were NOT evaluated*' + $Warnings[0].Message | Should -BeLike '*u2@x.com*' # names them, not just a count + } + + It 'does not let a stale row for a deleted mailbox mask an uncovered one' { + # ghost@x.com was deleted but still has a Default row; u2@x.com is genuinely uncovered. + # Counts net to 2 - 2 = 0 and read as full coverage; identities see the gap. + Mock -CommandName New-CIPPDbRequest -MockWith { + if ($Type -eq 'Mailboxes') { @(1..2 | ForEach-Object { [PSCustomObject]@{ UPN = "u$_@x.com" } }) } + else { @(New-CalRow -Upn 'u1@x.com' -Rights 'Reviewer'; New-CalRow -Upn 'ghost@x.com' -Rights 'Reviewer') } + } + + Invoke-CIPPStandardcalDefault -Tenant 'contoso.onmicrosoft.com' -Settings $script:Settings + + $script:Compared.UncheckedMailboxes | Should -Be 1 + @($script:Messages | Where-Object { $_.Sev -eq 'Warning' -and $_.Message -like '*u2@x.com*' }).Count | Should -Be 2 + } + + It 'matches a mailbox whose calendar Identity is an Exchange GUID, not a UPN' { + # Get-MailboxFolderPermission echoes its own canonical identity, which on the real tenant + # was the ExternalDirectoryObjectId - without the key fan-out this reads as uncovered. + Mock -CommandName New-CIPPDbRequest -MockWith { + if ($Type -eq 'Mailboxes') { + @([PSCustomObject]@{ UPN = 'u1@x.com'; ExternalDirectoryObjectId = '25a48edf-ef11-423e-aa2d-ce4831b94b51' }) + } else { + @([PSCustomObject]@{ Identity = '25a48edf-ef11-423e-aa2d-ce4831b94b51:\Calendar'; User = 'Default'; AccessRights = @('Reviewer') }) + } + } + + Invoke-CIPPStandardcalDefault -Tenant 'contoso.onmicrosoft.com' -Settings $script:Settings + + $script:Compared.state | Should -Be 'Configured correctly' + } + + It 'still flags real drift, and counts coverage alongside it' { + Mock -CommandName New-CIPPDbRequest -MockWith { + if ($Type -eq 'Mailboxes') { @(1..4 | ForEach-Object { [PSCustomObject]@{ UPN = "u$_@x.com" } }) } + else { @(New-CalRow -Upn 'u1@x.com' -Rights 'Reviewer'; New-CalRow -Upn 'u2@x.com' -Rights 'AvailabilityOnly') } + } + Mock -CommandName New-ExoRequest -MockWith { } + + Invoke-CIPPStandardcalDefault -Tenant 'contoso.onmicrosoft.com' -Settings $script:Settings + + @($script:Compared.NonCompliantCalendars).Count | Should -Be 1 + $script:Compared.UncheckedMailboxes | Should -Be 2 + } +} diff --git a/Tests/Static/PIMSecureDirection.Tests.ps1 b/Tests/Static/PIMSecureDirection.Tests.ps1 new file mode 100644 index 0000000000000..403a2984d722d --- /dev/null +++ b/Tests/Static/PIMSecureDirection.Tests.ps1 @@ -0,0 +1,80 @@ +# Source invariant: CIPP's PIM surfaces only move privileged access in the secure direction. +# +# The maintainer's rule is that CIPP must be able to convert permanent assignments to eligible and +# create time-bound active assignments, but must never - through any UI, standard, template, API +# or MCP path - create a permanent assignment, convert eligible to permanent, or weaken PIM role +# settings below the secure floor. New-CIPPPIMScheduleRequest enforces the expiration rule and +# Test-CIPPPIMRoleSettingsFloor the settings rule; this test makes sure nothing routes around them: +# +# 1. the PIM schedule-request endpoints are only addressed from the builder, so every request +# body passes its expiration checks; +# 2. no PIM-related source assigns a 'noExpiration' schedule; +# 3. no PIM-related source re-introduces the legacy permanent directoryRoles/members/$ref write; +# 4. every file that PATCHes a PIM role policy rule validates against the floor first. + +BeforeAll { + $BackendRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $ModulesRoot = Join-Path $BackendRoot 'Modules' + + $script:PIMFiles = @( + Get-ChildItem -Path (Join-Path $ModulesRoot 'CIPPCore/Public/PIM') -Filter '*.ps1' -File + Get-ChildItem -Path (Join-Path $ModulesRoot 'CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles') -Filter '*.ps1' -File + Get-ChildItem -Path (Join-Path $ModulesRoot 'CIPPStandards/Public/Standards') -Filter 'Invoke-CIPPStandardPIM*.ps1' -File + Get-ChildItem -Path (Join-Path $ModulesRoot 'CIPPAlerts/Public/Alerts') -Filter 'Get-CIPPAlertPermanentActiveAdminAssigned.ps1' -File + ) + if ($script:PIMFiles.Count -lt 10) { throw "Expected the PIM source set to be present; found $($script:PIMFiles.Count) files" } + + $script:Sources = foreach ($File in $script:PIMFiles) { + [pscustomobject]@{ Name = $File.Name; Text = [System.IO.File]::ReadAllText($File.FullName) } + } + + $script:AllSources = foreach ($File in (Get-ChildItem -Path $ModulesRoot -Filter '*.ps1' -File -Recurse)) { + [pscustomobject]@{ Name = $File.Name; Text = [System.IO.File]::ReadAllText($File.FullName) } + } +} + +Describe 'PIM secure-direction invariants' { + It 'addresses the schedule-request endpoints only from New-CIPPPIMScheduleRequest' { + $Pattern = [regex]'role(Eligibility|Assignment)ScheduleRequests' + $Offenders = @($script:AllSources | Where-Object { $_.Name -ne 'New-CIPPPIMScheduleRequest.ps1' -and $Pattern.IsMatch($_.Text) } | ForEach-Object { $_.Name }) + # The builder's tests mention the URIs in assertions; sources elsewhere may not. + $Offenders | Should -BeNullOrEmpty -Because 'every schedule request must go through the builder that refuses no-expiration schedules' + } + + It 'never assigns a noExpiration schedule type' { + # The string may appear in a rejection regex or in read-side detection, never as a value + # being set on a request. + $Pattern = [regex]"(type|expiration)\s*=\s*['""]noExpiration['""]" + $Offenders = @($script:Sources | Where-Object { $Pattern.IsMatch($_.Text) } | ForEach-Object { $_.Name }) + $Offenders | Should -BeNullOrEmpty + } + + It 'does not re-introduce the permanent directoryRoles member write' { + $Pattern = [regex]'directoryRoles[^\r\n]*members/\$ref' + $Offenders = @($script:Sources | Where-Object { $Pattern.IsMatch($_.Text) } | ForEach-Object { $_.Name }) + $Offenders | Should -BeNullOrEmpty -Because 'the PIM surfaces must not create permanent role memberships' + } + + It 'validates against the secure floor wherever role policy rules are written' { + $Writers = @($script:AllSources | Where-Object { $_.Text -match 'roleManagementPolicies/[^\r\n]*?/rules/' -and $_.Text -match 'PATCH' }) + $Writers.Count | Should -BeGreaterThan 0 + foreach ($Writer in $Writers) { + # Set-CIPPPIMRoleSettings is the writer; its callers must have run the floor check. + $Writer.Name | Should -Be 'Set-CIPPPIMRoleSettings.ps1' + } + $Callers = @($script:AllSources | Where-Object { $_.Name -ne 'Set-CIPPPIMRoleSettings.ps1' -and $_.Text -match 'Set-CIPPPIMRoleSettings\b' -and $_.Name -notlike '*.Tests.ps1' }) + $Callers.Count | Should -BeGreaterThan 0 + foreach ($Caller in $Callers) { + $Caller.Text | Should -Match 'Test-CIPPPIMRoleSettingsFloor' -Because "$($Caller.Name) writes PIM policy rules and must validate the floor first" + } + } + + It 'keeps every secure-direction action inside Invoke-CIPPPIMAssignmentAction or the builder' { + # The endpoint and the standards must delegate; they may not post schedule requests directly. + $Direct = @($script:Sources | Where-Object { + $_.Name -notin @('New-CIPPPIMScheduleRequest.ps1', 'Invoke-CIPPPIMAssignmentAction.ps1') -and + $_.Text -match 'New-CIPPPIMScheduleRequest\b' + } | ForEach-Object { $_.Name }) + $Direct | Should -BeNullOrEmpty + } +} diff --git a/Tests/Tenant/Invoke-ExecGDAPRepairRoleMappings.Tests.ps1 b/Tests/Tenant/Invoke-ExecGDAPRepairRoleMappings.Tests.ps1 new file mode 100644 index 0000000000000..6af4b4006d98d --- /dev/null +++ b/Tests/Tenant/Invoke-ExecGDAPRepairRoleMappings.Tests.ps1 @@ -0,0 +1,81 @@ +# Repair must recreate groups that no longer exist, not just report them: the UI promises +# "Recreate ... as a new, empty security group", and a group created by the registry pass must be +# visible to the template pass so shared mappings re-link instead of creating a duplicate. + +BeforeAll { + $BackendRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $BackendRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ExecGDAPRepairRoleMappings.ps1' + + ([PSObject].Assembly.GetType('System.Management.Automation.TypeAccelerators')).GetMethod('Add').Invoke( + $null, @('HttpStatusCode', [System.Net.HttpStatusCode])) + + class HttpResponseContext { + [int]$StatusCode + [object]$Body + } + + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property) } + function New-GraphGetRequest { param($uri, $tenantid, $NoAuthCheck, $AsApp) } + function Test-CIPPGDAPGroupMappings { param($RoleMappings, $PartnerGroups, [switch]$CreateMissing, [switch]$WriteBack, $TemplateId, $APIName, $Headers) } + function Test-CIPPGDAPRelationships { param($Headers) } + function Write-LogMessage { param($headers, $API, $tenant, $message, $Sev, $LogData) } + function Get-CippException { param($Exception) @{ NormalizedError = $Exception.Exception.Message } } + + . $FunctionPath + + $script:Request = [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ExecGDAPRepairRoleMappings' } + Headers = @{} + } +} + +Describe 'Invoke-ExecGDAPRepairRoleMappings' { + BeforeEach { + $script:Calls = [System.Collections.Generic.List[object]]::new() + Mock -CommandName Get-CIPPTable -MockWith { @{ Context = $TableName } } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + if ($Context -eq 'GDAPRoles') { + @([PSCustomObject]@{ RoleName = 'Helpdesk Administrator'; GroupName = 'M365 GDAP Helpdesk Administrator'; GroupId = 'gone'; roleDefinitionId = 'role-helpdesk' }) + } else { + @([PSCustomObject]@{ RowKey = 'Template A'; RoleMappings = '[{"RoleName":"Helpdesk Administrator","GroupName":"M365 GDAP Helpdesk Administrator","GroupId":"gone","roleDefinitionId":"role-helpdesk"}]' }) + } + } + Mock -CommandName New-GraphGetRequest -MockWith { @([PSCustomObject]@{ id = 'existing-1'; displayName = 'M365 GDAP Global Reader' }) } + Mock -CommandName Test-CIPPGDAPRelationships -MockWith { } + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Test-CIPPGDAPGroupMappings -MockWith { + $script:Calls.Add(@{ CreateMissing = [bool]$CreateMissing; PartnerGroupIds = @($PartnerGroups.id); TemplateId = $TemplateId }) + $Status = if ($PartnerGroups.displayName -contains 'M365 GDAP Helpdesk Administrator') { 'Stale' } elseif ($CreateMissing) { 'Created' } else { 'Missing' } + [PSCustomObject]@{ + Results = @([PSCustomObject]@{ RoleName = 'Helpdesk Administrator'; GroupName = 'M365 GDAP Helpdesk Administrator'; GroupId = 'new-1'; Status = $Status; Message = "status $Status"; OldGroupId = 'gone' }) + RoleMappings = @() + Valid = ($Status -ne 'Missing') + MissingGroups = @() + } + } + } + + It 'asks the validator to recreate missing groups on both passes' { + $null = Invoke-ExecGDAPRepairRoleMappings -Request $script:Request -TriggerMetadata $null + + $script:Calls.Count | Should -Be 2 + $script:Calls[0].CreateMissing | Should -BeTrue + $script:Calls[1].CreateMissing | Should -BeTrue + } + + It 'reports a recreated group as success' { + $Response = Invoke-ExecGDAPRepairRoleMappings -Request $script:Request -TriggerMetadata $null + + $Response.StatusCode | Should -Be 200 + @($Response.Body.Results | Where-Object { $_.state -eq 'error' }).Count | Should -Be 0 + $Response.Body.Results[0].resultText | Should -Match 'status Created' + } + + It 'feeds groups created by the registry pass into the template pass' { + $Response = Invoke-ExecGDAPRepairRoleMappings -Request $script:Request -TriggerMetadata $null + + $script:Calls[1].PartnerGroupIds | Should -Contain 'new-1' + $Response.Body.Results[1].resultText | Should -Match 'status Stale' + } +} diff --git a/Tests/Tenant/Invoke-ListGDAPRoles.Validate.Tests.ps1 b/Tests/Tenant/Invoke-ListGDAPRoles.Validate.Tests.ps1 new file mode 100644 index 0000000000000..50cbce2f03594 --- /dev/null +++ b/Tests/Tenant/Invoke-ListGDAPRoles.Validate.Tests.ps1 @@ -0,0 +1,97 @@ +# The ?validate=true annotation is opt-in: other consumers of ListGDAPRoles read the plain +# four-property shape, and a Graph failure must degrade to Unknown rather than break the list. + +BeforeAll { + $BackendRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $BackendRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/GDAP/Invoke-ListGDAPRoles.ps1' + + # The Functions worker exposes [HttpStatusCode] as an accelerator; register it for tests. + ([PSObject].Assembly.GetType('System.Management.Automation.TypeAccelerators')).GetMethod('Add').Invoke( + $null, @('HttpStatusCode', [System.Net.HttpStatusCode])) + + class HttpResponseContext { + [int]$StatusCode + [object]$Body + } + + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property) } + function New-GraphGetRequest { param($uri, $tenantid, $NoAuthCheck, $AsApp) } + function Test-CIPPGDAPGroupMappings { param($RoleMappings, $PartnerGroups, $APIName, $Headers) } + function Write-LogMessage { param($headers, $API, $tenant, $message, $Sev, $LogData) } + function Get-CippException { param($Exception) @{ NormalizedError = $Exception.Exception.Message } } + + . $FunctionPath + + function New-Request { + param($Validate) + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ListGDAPRoles' } + Headers = @{} + Query = @{ validate = $Validate } + } + } +} + +Describe 'Invoke-ListGDAPRoles' { + BeforeEach { + Mock -CommandName Get-CIPPTable -MockWith { @{ Context = 'stub' } } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + @( + [PSCustomObject]@{ + GroupName = 'M365 GDAP User Administrator' + GroupId = 'group-user-admin' + RoleName = 'User Administrator' + roleDefinitionId = 'role-user-admin' + } + [PSCustomObject]@{ + GroupName = 'M365 GDAP Intune Administrator' + GroupId = 'group-intune' + RoleName = 'Intune Administrator' + roleDefinitionId = 'role-intune' + } + ) + } + Mock -CommandName New-GraphGetRequest -MockWith { @() } + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Test-CIPPGDAPGroupMappings -MockWith { + [PSCustomObject]@{ + Results = @( + [PSCustomObject]@{ RoleName = 'User Administrator'; GroupName = 'M365 GDAP User Administrator'; GroupId = 'group-user-admin'; Status = 'Valid'; Message = ''; OldGroupId = $null } + [PSCustomObject]@{ RoleName = 'Intune Administrator'; GroupName = 'M365 GDAP Intune Administrator'; GroupId = 'group-intune-new'; Status = 'Stale'; Message = 'stale id'; OldGroupId = 'group-intune' } + ) + } + } + } + + It 'returns the plain mapping shape without the flag' { + $Response = Invoke-ListGDAPRoles -Request (New-Request) -TriggerMetadata $null + + Should -Invoke Test-CIPPGDAPGroupMappings -Times 0 + Should -Invoke New-GraphGetRequest -Times 0 + $Response.Body.Count | Should -Be 2 + $Response.Body[0].PSObject.Properties.Name | Should -Be @('GroupName', 'GroupId', 'RoleName', 'roleDefinitionId') + } + + It 'annotates each mapping with its group status when asked' { + $Response = Invoke-ListGDAPRoles -Request (New-Request -Validate $true) -TriggerMetadata $null + + Should -Invoke Test-CIPPGDAPGroupMappings -Times 1 + $Valid = $Response.Body | Where-Object -Property GroupId -EQ 'group-user-admin' + $Valid.GroupStatus | Should -Be 'Valid' + # A stale result carries the original id as OldGroupId, so it still lands on its own row. + $Stale = $Response.Body | Where-Object -Property GroupId -EQ 'group-intune' + $Stale.GroupStatus | Should -Be 'Stale' + $Stale.GroupStatusMessage | Should -Be 'stale id' + } + + It 'degrades to Unknown when the group check fails' { + Mock -CommandName Test-CIPPGDAPGroupMappings -MockWith { throw 'graph is down' } + + $Response = Invoke-ListGDAPRoles -Request (New-Request -Validate $true) -TriggerMetadata $null + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $Response.Body.GroupStatus | Should -Be @('Unknown', 'Unknown') + Should -Invoke Write-LogMessage -Times 1 -ParameterFilter { $Sev -eq 'Warning' } + } +} diff --git a/Tests/Tenant/New-CIPPGDAPRoleMapping.Tests.ps1 b/Tests/Tenant/New-CIPPGDAPRoleMapping.Tests.ps1 new file mode 100644 index 0000000000000..7225afac67c77 --- /dev/null +++ b/Tests/Tenant/New-CIPPGDAPRoleMapping.Tests.ps1 @@ -0,0 +1,119 @@ +# Group creation behind GDAP role mappings: a role whose 'M365 GDAP ' group already +# exists must be reused rather than recreated, and the rows written to GDAPRoles must carry the +# shape Invoke-ListGDAPRoles and the role templates read back. + +BeforeAll { + $BackendRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $BackendRoot 'Modules/CIPPCore/Public/New-CIPPGDAPRoleMapping.ps1' + + # Stubs so Mock has commands to replace. + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter, $Property) } + function Add-CIPPAzDataTableEntity { param($Context, $Entity, [switch]$Force) } + function New-GraphGetRequest { param($uri, $tenantid, $NoAuthCheck, $AsApp) } + function New-GraphBulkRequest { param($Requests, $tenantid, $NoAuthCheck, $asapp) } + + . $FunctionPath + + $script:WrittenEntities = [System.Collections.Generic.List[object]]::new() + $script:BulkRequests = $null +} + +Describe 'New-CIPPGDAPRoleMapping' { + BeforeEach { + $script:WrittenEntities = [System.Collections.Generic.List[object]]::new() + $script:BulkRequests = $null + + Mock -CommandName Get-CIPPTable -MockWith { @{ Context = 'stub' } } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $null } + Mock -CommandName Add-CIPPAzDataTableEntity -MockWith { + foreach ($Item in @($Entity)) { $script:WrittenEntities.Add($Item) } + } + Mock -CommandName New-GraphGetRequest -MockWith { + @( + [PSCustomObject]@{ id = 'group-existing'; displayName = 'M365 GDAP User Administrator' } + [PSCustomObject]@{ id = 'group-suffixed'; displayName = 'M365 GDAP User Administrator - Helpdesk' } + ) + } + Mock -CommandName New-GraphBulkRequest -MockWith { + $script:BulkRequests = $Requests + foreach ($Item in $Requests) { + [PSCustomObject]@{ + id = $Item.id + body = [PSCustomObject]@{ + id = "new-$($Item.id)" + displayName = $Item.body.displayName + } + } + } + } + } + + It 'reuses an existing group with the default name' { + $Result = New-CIPPGDAPRoleMapping -Roles @( + @{ label = 'User Administrator'; value = 'role-user-admin' } + ) + + Should -Invoke New-GraphBulkRequest -Times 0 + $Result.RoleMappings.Count | Should -Be 1 + $Result.RoleMappings[0].GroupId | Should -Be 'group-existing' + $Result.Results | Should -Contain 'M365 GDAP User Administrator already exists' + } + + It 'creates a group for a role that has none' { + $Result = New-CIPPGDAPRoleMapping -Roles @( + @{ label = 'Intune Administrator'; value = 'role-intune' } + ) + + $script:BulkRequests.Count | Should -Be 1 + $script:BulkRequests[0].body.displayName | Should -Be 'M365 GDAP Intune Administrator' + $script:BulkRequests[0].body.mailNickname | Should -Be 'M365GDAPIntuneAdministrator' + $Result.RoleMappings[0].GroupId | Should -Be 'new-role-intune' + $Result.RoleMappings[0].RoleName | Should -Be 'Intune Administrator' + $Result.RoleMappings[0].roleDefinitionId | Should -Be 'role-intune' + $Result.Results | Should -Contain 'Created M365 GDAP Intune Administrator' + } + + It 'honours a custom suffix for both reused and created groups' { + $Result = New-CIPPGDAPRoleMapping -Roles @( + @{ label = 'User Administrator'; value = 'role-user-admin' } + @{ label = 'Exchange Administrator'; value = 'role-exchange' } + ) -CustomSuffix 'Helpdesk' + + $Reused = $Result.RoleMappings | Where-Object -Property RoleName -EQ 'User Administrator' + $Reused.GroupId | Should -Be 'group-suffixed' + $Reused.GroupName | Should -Be 'M365 GDAP User Administrator - Helpdesk' + + $script:BulkRequests[0].body.displayName | Should -Be 'M365 GDAP Exchange Administrator - Helpdesk' + $script:BulkRequests[0].body.mailNickname | Should -Be 'M365GDAPExchangeAdministratorHelpdesk' + + # The suffix is stripped back off for the stored role name. + $Created = $Result.RoleMappings | Where-Object -Property RoleName -EQ 'Exchange Administrator' + $Created.GroupName | Should -Be 'M365 GDAP Exchange Administrator - Helpdesk' + } + + It 'writes GDAPRoles rows in the expected shape' { + $null = New-CIPPGDAPRoleMapping -Roles @( + @{ label = 'User Administrator'; value = 'role-user-admin' } + @{ label = 'Intune Administrator'; value = 'role-intune' } + ) + + $script:WrittenEntities.Count | Should -Be 2 + foreach ($Entity in $script:WrittenEntities) { + $Entity.PartitionKey | Should -Be 'Roles' + $Entity.RowKey | Should -Be $Entity.GroupId + $Entity.Keys | Should -Contain 'RoleName' + $Entity.Keys | Should -Contain 'GroupName' + $Entity.Keys | Should -Contain 'roleDefinitionId' + } + } + + It 'accepts the catalog shape (Name/ObjectId) as well as label/value' { + $Result = New-CIPPGDAPRoleMapping -Roles @( + [PSCustomObject]@{ Name = 'User Administrator'; ObjectId = 'role-user-admin' } + ) + + $Result.RoleMappings[0].GroupId | Should -Be 'group-existing' + $Result.RoleMappings[0].roleDefinitionId | Should -Be 'role-user-admin' + } +} diff --git a/Tests/Webhooks/Test-CIPPAuditLogRules.Tests.ps1 b/Tests/Webhooks/Test-CIPPAuditLogRules.Tests.ps1 index 05382be2e0600..9aa6d74db31a4 100644 --- a/Tests/Webhooks/Test-CIPPAuditLogRules.Tests.ps1 +++ b/Tests/Webhooks/Test-CIPPAuditLogRules.Tests.ps1 @@ -89,21 +89,22 @@ Describe 'Test-CIPPAuditLogRules record shaping' { switch ($TableName) { 'WebhookRules' { [pscustomobject]@{ - PartitionKey = 'WebhookRules' - RowKey = 'rule-1' - Tenants = (@('AllTenants') | ConvertTo-Json -Compress) - excludedTenants = $null - Conditions = (@( + PartitionKey = 'WebhookRules' + RowKey = 'rule-1' + Tenants = (@('AllTenants') | ConvertTo-Json -Compress) + excludedTenants = $null + Conditions = (@( @{ Property = @{ label = 'Operation' } Operator = @{ label = 'eq' } Input = @{ value = 'Set-Mailbox' } } ) | ConvertTo-Json -Compress -Depth 5) - Actions = (@('generatemail') | ConvertTo-Json -Compress) - Type = 'Audit' - AlertComment = 'test comment' - CustomSubject = '' + Actions = (@('generatemail') | ConvertTo-Json -Compress) + Type = 'Audit' + AlertComment = 'test comment' + CustomSubject = '' + PsaTicketPriority = '5' } } 'cacheauditloglookups' { @@ -243,6 +244,9 @@ Describe 'Test-CIPPAuditLogRules record shaping' { $data.CIPPAction | Should -Not -BeNullOrEmpty $data.CIPPClause | Should -Not -BeNullOrEmpty $data.CIPPAlertComment | Should -Be 'test comment' + # Covers the full per-alert priority chain through this function: the config + # projection, the where-clause object, and the stamp onto the matched record. + $data.CIPPPsaTicketPriority | Should -Be '5' } It 'dispatches the matched record to webhook processing' { diff --git a/version_latest.txt b/version_latest.txt index 8709113af4b9a..4843a6d662fa9 100644 --- a/version_latest.txt +++ b/version_latest.txt @@ -1 +1 @@ -10.9.1 \ No newline at end of file +10.10.0 \ No newline at end of file From e9901cbdfd3bf97586186769379fbf8c9bcdc968 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Tue, 8 Sep 2026 18:57:39 +0000 Subject: [PATCH 2/4] Merge pull request #525 from CyberDrain/dev fix: dev to hotfix Synced from CyberDrain/CIPP@0ea6c5926d3764e066ec035043f14e6a8e5cf4fa --- Config/openapi.json | 557 +++++++++++++++++- Config/standards.json | 23 + .../Push-CIPPStandardsApplyBatch.ps1 | 16 +- .../Start-CIPPOrchestrator.ps1 | 34 +- .../Functions/Test-CIPPStandardLicense.ps1 | 5 +- .../Get-CIPPSharePointSiteUsageReport.ps1 | 188 +++--- .../GraphHelper/New-CIPPMFAConnectorToken.ps1 | 10 +- .../Invoke-CIPPMigrateOneDriveShortCuts.ps1 | 120 ++++ .../Public/Invoke-CIPPOffboardingJob.ps1 | 11 +- .../Public/New-CIPPOneDriveShortCut.ps1 | 74 ++- .../Public/Standards/New-CIPPStandardsRun.ps1 | 13 +- .../Invoke-AddAssignmentFilterTemplate.ps1 | 1 - .../MEM/Invoke-EditAssignmentFilter.ps1 | 1 - .../MEM/Invoke-ExecAssignmentFilter.ps1 | 1 - .../Invoke-ListAssignmentFilterTemplates.ps1 | 1 - .../Invoke-RemoveAssignmentFilterTemplate.ps1 | 1 - .../Invoke-ExecMigrateOneDriveShortCuts.ps1 | 38 ++ .../Users/Invoke-ExecOneDriveShortCut.ps1 | 9 +- .../Invoke-ExecRemoveOneDriveShortCut.ps1 | 41 ++ .../Invoke-ListUserOneDriveShortcuts.ps1 | 96 +++ .../Standards/Invoke-AddStandardsTemplate.ps1 | 37 +- ...Invoke-ExecGenerateReportBuilderReport.ps1 | 2 +- ...e-CIPPStandardMigrateOneDriveShortcuts.ps1 | 116 ++++ .../Public/Halo/Get-HaloMapping.ps1 | 3 +- .../Public/Halo/Get-HaloPriority.ps1 | 5 +- .../Public/Halo/Get-HaloRequestSource.ps1 | 3 +- .../Public/Halo/Get-HaloTicketOutcome.ps1 | 7 +- .../Public/Halo/Get-HaloTicketType.ps1 | 3 +- .../Public/Halo/Get-HaloTicketTypeSlaId.ps1 | 3 +- .../Public/Halo/Get-HaloToken.ps1 | 3 +- .../Public/Halo/Get-HaloUser.ps1 | 5 +- .../Public/Halo/Invoke-HaloAutoMap.ps1 | 5 +- .../Public/Halo/New-HaloPSATicket.ps1 | 7 +- .../New-HaloPSATicket.Priority.Tests.ps1 | 1 + Tests/Extensions/New-HaloPSATicket.Tests.ps1 | 1 + .../New-HaloPSATicket.TicketTarget.Tests.ps1 | 1 + .../New-CIPPMFAConnectorToken.Tests.ps1 | 49 ++ version_latest.txt | 2 +- 38 files changed, 1339 insertions(+), 154 deletions(-) create mode 100644 Modules/CIPPCore/Public/Invoke-CIPPMigrateOneDriveShortCuts.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecMigrateOneDriveShortCuts.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecRemoveOneDriveShortCut.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUserOneDriveShortcuts.ps1 create mode 100644 Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardMigrateOneDriveShortcuts.ps1 diff --git a/Config/openapi.json b/Config/openapi.json index 4bc57c7d41509..e019e964185ff 100644 --- a/Config/openapi.json +++ b/Config/openapi.json @@ -6280,7 +6280,7 @@ "Tenant > Standards" ], "requestBody": { - "required": true, + "required": false, "content": { "application/json": { "schema": { @@ -6299,9 +6299,6 @@ "type": "string" } }, - "required": [ - "tenantFilter" - ], "additionalProperties": true, "x-cipp-passthrough": true, "description": "This endpoint forwards the request body onward rather than reading a fixed set of fields. The properties listed here are the ones it is known to read; others may be accepted." @@ -6341,7 +6338,8 @@ "bearerAuth": [] } ], - "x-cipp-role": "Tenant.Standards.ReadWrite" + "x-cipp-role": "Tenant.Standards.ReadWrite", + "x-cipp-any-tenant": true } }, "/api/AddStoreApp": { @@ -26072,6 +26070,66 @@ "x-cipp-role": "Security.Alert.Read" } }, + "/api/ExecMigrateOneDriveShortCuts": { + "post": { + "summary": "ExecMigrateOneDriveShortCuts", + "operationId": "ExecMigrateOneDriveShortCuts", + "tags": [ + "Identity > Administration > Users" + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "$ref": "#/components/schemas/LabelValue" + }, + "tenantFilter": { + "type": "string" + }, + "username": { + "$ref": "#/components/schemas/LabelValue" + } + }, + "required": [ + "tenantFilter" + ] + } + } + } + }, + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Identity.User.ReadWrite" + } + }, "/api/ExecModifyCalPerms": { "post": { "summary": "ExecModifyCalPerms", @@ -28367,6 +28425,9 @@ "schema": { "type": "object", "properties": { + "destination": { + "$ref": "#/components/schemas/LabelValue" + }, "siteUrl": { "$ref": "#/components/schemas/LabelValue" }, @@ -29831,6 +29892,69 @@ "x-cipp-role": "Exchange.Mailbox.ReadWrite" } }, + "/api/ExecRemoveOneDriveShortCut": { + "post": { + "summary": "ExecRemoveOneDriveShortCut", + "operationId": "ExecRemoveOneDriveShortCut", + "tags": [ + "Identity > Administration > Users" + ], + "requestBody": { + "required": true, + "content": { + "application/json": { + "schema": { + "type": "object", + "properties": { + "id": { + "$ref": "#/components/schemas/LabelValue" + }, + "name": { + "$ref": "#/components/schemas/LabelValue" + }, + "tenantFilter": { + "type": "string" + }, + "username": { + "$ref": "#/components/schemas/LabelValue" + } + }, + "required": [ + "tenantFilter" + ] + } + } + } + }, + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Identity.User.ReadWrite" + } + }, "/api/ExecRemoveRestrictedUser": { "post": { "summary": "ExecRemoveRestrictedUser", @@ -61263,6 +61387,429 @@ "x-cipp-role": "Exchange.Mailbox.Read" } }, + "/api/ListUserOneDriveShortcuts": { + "get": { + "summary": "ListUserOneDriveShortcuts", + "operationId": "ListUserOneDriveShortcuts", + "tags": [ + "Identity > Administration > Users" + ], + "description": "Lists OneDrive remoteItem shortcuts for a user from the drive root and the Shortcuts folder.", + "parameters": [ + { + "$ref": "#/components/parameters/tenantFilter" + }, + { + "name": "userId", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "userPrincipalName", + "in": "query", + "required": true, + "schema": { + "type": "string" + } + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the Microsoft Graph entity it queries. This endpoint returns the Graph response as-is without selecting fields, so these are the properties the entity CAN carry (x-cipp-field-source: graph-entity) rather than a proven projection - Graph returns a default subset unless asked otherwise.", + "properties": { + "aboutMe": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "accountEnabled": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "ageGroup": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "assignedLicenses": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "assignedPlans": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "authorizationInfo": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "birthday": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "businessPhones": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "city": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "cloudLicensing": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "cloudRealtimeCommunicationInfo": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "companyName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "consentProvidedForMinor": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "country": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "createdDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "creationType": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "customSecurityAttributes": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "deletedDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "department": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "deviceEnrollmentLimit": { + "type": "integer", + "x-cipp-field-source": "graph-entity" + }, + "deviceKeys": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "displayName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "employeeHireDate": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "employeeId": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "employeeLeaveDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "employeeOrgData": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "employeeType": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "externalUserState": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "externalUserStateChangeDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "faxNumber": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "givenName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "hireDate": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "id": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "identities": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "identityGovernance": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "identityParentId": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "imAddresses": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "infoCatalogs": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "interests": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "isLicenseReconciliationNeeded": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "isManagementRestricted": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "isResourceAccount": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "jobTitle": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "lastPasswordChangeDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "legalAgeGroupClassification": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "licenseAssignmentStates": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "mail": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "mailboxSettings": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "mailNickname": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "mobilePhone": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "mySite": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "officeLocation": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesDistinguishedName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesDomainName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesExtensionAttributes": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesImmutableId": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesLastSyncDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesProvisioningErrors": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesSamAccountName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesSecurityIdentifier": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesSipInfo": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesSyncEnabled": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "onPremisesUserPrincipalName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "otherMails": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "passwordPolicies": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "passwordProfile": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "pastProjects": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "postalCode": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "preferredDataLocation": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "preferredLanguage": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "preferredName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "print": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "provisionedPlans": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "proxyAddresses": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "refreshTokensValidFromDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "responsibilities": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "schools": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "securityIdentifier": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "serviceProvisioningErrors": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "showInAddressList": { + "type": "boolean", + "x-cipp-field-source": "graph-entity" + }, + "signInActivity": { + "type": "object", + "x-cipp-field-source": "graph-entity" + }, + "signInSessionsValidFromDateTime": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "skills": { + "type": "array", + "x-cipp-field-source": "graph-entity" + }, + "state": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "streetAddress": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "surname": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "usageLocation": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "userPrincipalName": { + "type": "string", + "x-cipp-field-source": "graph-entity" + }, + "userType": { + "type": "string", + "x-cipp-field-source": "graph-entity" + } + } + } + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Identity.User.Read" + } + }, "/api/ListUserPhoto": { "get": { "summary": "ListUserPhoto", diff --git a/Config/standards.json b/Config/standards.json index 5e79d23e0fcca..c645548e7d22a 100644 --- a/Config/standards.json +++ b/Config/standards.json @@ -5395,6 +5395,29 @@ "ONEDRIVEENTERPRISE" ] }, + { + "name": "standards.MigrateOneDriveShortcuts", + "cat": "SharePoint Standards", + "tag": [], + "helpText": "Finds SharePoint library shortcuts sitting in each user's OneDrive root and moves them into the Shortcuts folder (PATCH move into special/shortcuts), matching the optional Microsoft UI location.", + "docsDescription": "Over time Add shortcut to OneDrive can leave many remote library links in the OneDrive root. Microsoft also supports placing those links in an optional Shortcuts folder. This standard lists each enabled member user's OneDrive root with Prefer Include-Feature=AddToOneDrive, then for any remoteItem shortcuts still outside Shortcuts moves them into special/shortcuts. Users without a provisioned OneDrive are skipped. Failures name the user, shortcut, and site URL when available.", + "executiveText": "Keeps employee OneDrive roots tidy by moving SharePoint library shortcuts into the dedicated Shortcuts folder instead of leaving them scattered among personal files.", + "addedComponent": [], + "label": "Migrate OneDrive root shortcuts to the Shortcuts folder", + "impact": "Low Impact", + "impactColour": "info", + "addedDate": "2026-09-08", + "powershellEquivalent": "PATCH drive/items/{id} parentReference → special/shortcuts", + "recommendedBy": [], + "requiredCapabilities": [ + "SHAREPOINTWAC", + "SHAREPOINTSTANDARD", + "SHAREPOINTENTERPRISE", + "SHAREPOINTENTERPRISE_EDU", + "SHAREPOINTENTERPRISE_GOV", + "ONEDRIVEENTERPRISE" + ] + }, { "name": "standards.SPFileRequests", "cat": "SharePoint Standards", diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Standards/Push-CIPPStandardsApplyBatch.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Standards/Push-CIPPStandardsApplyBatch.ps1 index e15912a163472..7000366e8e5d1 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Standards/Push-CIPPStandardsApplyBatch.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Standards/Push-CIPPStandardsApplyBatch.ps1 @@ -48,9 +48,23 @@ function Push-CIPPStandardsApplyBatch { Write-Information "Aggregated $($AllStandards.Count) standards from all tenants: $($AllStandards | ConvertTo-Json -Depth 5 -Compress)" + # Match the list phase's per-scope naming (see New-CIPPStandardsRun): once concurrent + # single-tenant list runs no longer collide, their apply phases must not collide either. The + # scope comes from the aggregated standards, which already carry Tenant and TemplateId: a single + # tenant and/or a single template contributes that part of the suffix, so two manual runs for the + # same tenant but different templates get distinct apply runs. The all-tenants sweep aggregates + # many tenants (and templates), so both parts drop and it keeps the bare name. + $ApplyTenants = @($AllStandards.Tenant | Where-Object { $_ } | Sort-Object -Unique) + $ApplyTemplates = @($AllStandards.TemplateId | Where-Object { $_ } | Sort-Object -Unique) + $ApplyScope = @( + if ($ApplyTenants.Count -eq 1) { $ApplyTenants[0] } + if ($ApplyTemplates.Count -eq 1) { $ApplyTemplates[0] } + ) -join '-' + $OrchestratorName = if ($ApplyScope) { "StandardsApply-$ApplyScope" } else { 'StandardsApply' } + # Start orchestrator to apply standards $InputObject = [PSCustomObject]@{ - OrchestratorName = 'StandardsApply' + OrchestratorName = $OrchestratorName Batch = @($AllStandards) SkipLog = $true } diff --git a/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-CIPPOrchestrator.ps1 b/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-CIPPOrchestrator.ps1 index b03862179a2a7..29a90d26f7945 100644 --- a/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-CIPPOrchestrator.ps1 +++ b/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-CIPPOrchestrator.ps1 @@ -131,12 +131,33 @@ function Start-CIPPOrchestrator { # is exactly where this call runs. $ParentRunName = if ($null -ne $OpContext) { $OpContext.PSObject.Properties['RunName'].Value } - Write-Information "Craft: Queuing orchestrator '$OrchestratorName' ($TaskCount tasks, P$Priority$(if ($PostExecFunctionName) { ", PostExec: $PostExecFunctionName" })$(if ($ParentRunName) { ", Parent: $ParentRunName" }))" - # An older Craft runtime exposes the 6-parameter method only; probing the arity keeps this - # wrapper deployable against both. Passing 7 arguments to the old method would not degrade — - # it would throw a method-resolution error and fail the orchestration outright. + # Sequential mode: opt-in per run (e.g. offboarding, where a later step must not race the ones + # before it). Craft runs the batch one task at a time in payload order instead of fanning out. + # Absent/false marshals to $false, so existing callers are unaffected. + $Sequential = [bool]($InputObject.Sequential) + + Write-Information "Craft: Queuing orchestrator '$OrchestratorName' ($TaskCount tasks, P$Priority$(if ($Sequential) { ', Sequential' })$(if ($PostExecFunctionName) { ", PostExec: $PostExecFunctionName" })$(if ($ParentRunName) { ", Parent: $ParentRunName" }))" + # Probe the method arity so this wrapper stays deployable against older Craft runtimes: the + # 8-parameter form adds Sequential, the 7-parameter form adds ParentRunName, and the oldest + # exposes 6. Passing more arguments than the deployed method accepts would throw a + # method-resolution error and fail the orchestration outright, so match what is present. $QueueMethod = [Craft.Services.OrchestratorBridge].GetMethod('QueueOrchestrationFromFile') - if ($QueueMethod.GetParameters().Count -ge 7) { + $ParamCount = $QueueMethod.GetParameters().Count + if ($ParamCount -ge 8) { + [Craft.Services.OrchestratorBridge]::QueueOrchestrationFromFile( + $OrchestratorName, + $BatchPath, + $Priority, + $PostExecFunctionName, + $PostExecParametersJson, + $InputObject.Reference, + $ParentRunName, + $Sequential + ) + } elseif ($ParamCount -ge 7) { + if ($Sequential) { + Write-Warning "Craft: Sequential requested for '$OrchestratorName' but the deployed Craft runtime does not support it (running fan-out)" + } [Craft.Services.OrchestratorBridge]::QueueOrchestrationFromFile( $OrchestratorName, $BatchPath, @@ -147,6 +168,9 @@ function Start-CIPPOrchestrator { $ParentRunName ) } else { + if ($Sequential) { + Write-Warning "Craft: Sequential requested for '$OrchestratorName' but the deployed Craft runtime does not support it (running fan-out)" + } [Craft.Services.OrchestratorBridge]::QueueOrchestrationFromFile( $OrchestratorName, $BatchPath, diff --git a/Modules/CIPPCore/Public/Functions/Test-CIPPStandardLicense.ps1 b/Modules/CIPPCore/Public/Functions/Test-CIPPStandardLicense.ps1 index 4a998a6e6a9f7..2df16dfc7ba5a 100644 --- a/Modules/CIPPCore/Public/Functions/Test-CIPPStandardLicense.ps1 +++ b/Modules/CIPPCore/Public/Functions/Test-CIPPStandardLicense.ps1 @@ -45,8 +45,9 @@ function Test-CIPPStandardLicense { Exchange = @('EXCHANGE_S_STANDARD', 'EXCHANGE_S_ENTERPRISE', 'EXCHANGE_S_STANDARD_GOV', 'EXCHANGE_S_ENTERPRISE_GOV', 'EXCHANGE_LITE') - SharePoint = @('SHAREPOINTWAC', 'SHAREPOINTSTANDARD', 'SHAREPOINTENTERPRISE', - 'SHAREPOINTENTERPRISE_EDU', 'SHAREPOINTENTERPRISE_GOV', + SharePoint = @('SHAREPOINTWAC', 'SHAREPOINTWAC_EDU', + 'SHAREPOINTSTANDARD', 'SHAREPOINTSTANDARD_EDU', + 'SHAREPOINTENTERPRISE', 'SHAREPOINTENTERPRISE_EDU', 'SHAREPOINTENTERPRISE_GOV', 'ONEDRIVE_BASIC', 'ONEDRIVE_ENTERPRISE') Intune = @('INTUNE_A', 'MDM_Services', 'EMS', 'SCCM', 'MICROSOFTINTUNEPLAN1') Entra = @('AAD_PREMIUM', 'AAD_PREMIUM_P2') diff --git a/Modules/CIPPCore/Public/Get-CIPPSharePointSiteUsageReport.ps1 b/Modules/CIPPCore/Public/Get-CIPPSharePointSiteUsageReport.ps1 index 6556c06095c27..5e46dd1df8111 100644 --- a/Modules/CIPPCore/Public/Get-CIPPSharePointSiteUsageReport.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPSharePointSiteUsageReport.ps1 @@ -1,94 +1,94 @@ -function Get-CIPPSharePointSiteUsageReport { - <# - .SYNOPSIS - Generates a SharePoint site usage report from the CIPP Reporting database - - .DESCRIPTION - Retrieves cached SharePoint site listing and usage data and combines them to match - the payload shape of Invoke-ListSites for Type=SharePointSiteUsage. - - .PARAMETER TenantFilter - The tenant to generate the report for - #> - [CmdletBinding()] - param( - [Parameter(Mandatory = $true)] - [string]$TenantFilter - ) - - try { - if ($TenantFilter -eq 'AllTenants') { - $AllSiteItems = @(Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'SharePointSiteListing' | Where-Object { $_.RowKey -ne 'SharePointSiteListing-Count' }) - $AllUsageItems = @(Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'SharePointSiteUsage' | Where-Object { $_.RowKey -ne 'SharePointSiteUsage-Count' }) - - $TenantList = Get-Tenants -IncludeErrors - $ValidTenants = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) - foreach ($T in $TenantList) { [void]$ValidTenants.Add($T.defaultDomainName) } - - $UsageBySiteId = [System.Collections.Generic.Dictionary[string, object]]::new([System.StringComparer]::OrdinalIgnoreCase) - foreach ($UsageItem in $AllUsageItems) { - $UsageRow = $UsageItem.Data | ConvertFrom-Json -Depth 10 - if (-not [string]::IsNullOrWhiteSpace($UsageRow.siteId)) { - $UsageBySiteId[[string]$UsageRow.siteId.Trim('{}')] = $UsageRow - } - } - - $AllResults = [System.Collections.Generic.List[PSCustomObject]]::new() - foreach ($SiteItem in $AllSiteItems) { - $Tenant = $SiteItem.PartitionKey - if (-not $ValidTenants.Contains($Tenant)) { continue } - - $Site = $SiteItem.Data | ConvertFrom-Json -Depth 10 - if ($Site.isPersonalSite -eq $true) { continue } - - $SiteUsage = $null - [void]$UsageBySiteId.TryGetValue([string]$Site.sharepointIds.siteId.Trim('{}'), [ref]$SiteUsage) - - $AllResults.Add((ConvertTo-CIPPSharePointSiteUsagePayload -Site $Site -SiteUsage $SiteUsage -Tenant $Tenant)) - } - return $AllResults - } - - $SiteItems = @(Get-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSiteListing' | Where-Object { $_.RowKey -ne 'SharePointSiteListing-Count' }) - if (-not $SiteItems) { - throw 'No SharePoint site listing data found in reporting database. Sync SharePointSiteUsage cache first.' - } - - $UsageItems = @(Get-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSiteUsage' | Where-Object { $_.RowKey -ne 'SharePointSiteUsage-Count' }) - - $LatestSiteTimestamp = ($SiteItems | Where-Object { $_.Timestamp } | Sort-Object Timestamp -Descending | Select-Object -First 1).Timestamp - $LatestUsageTimestamp = ($UsageItems | Where-Object { $_.Timestamp } | Sort-Object Timestamp -Descending | Select-Object -First 1).Timestamp - $CacheTimestamp = if ($LatestSiteTimestamp -and $LatestUsageTimestamp) { - if ($LatestSiteTimestamp -gt $LatestUsageTimestamp) { $LatestSiteTimestamp } else { $LatestUsageTimestamp } - } else { - $LatestSiteTimestamp ?? $LatestUsageTimestamp - } - - $UsageBySiteId = [System.Collections.Generic.Dictionary[string, object]]::new([System.StringComparer]::OrdinalIgnoreCase) - foreach ($UsageItem in $UsageItems) { - $UsageRow = $UsageItem.Data | ConvertFrom-Json -Depth 10 - if (-not [string]::IsNullOrWhiteSpace($UsageRow.siteId)) { - $UsageBySiteId[[string]$UsageRow.siteId.Trim('{}')] = $UsageRow - } - } - - $Report = [System.Collections.Generic.List[PSCustomObject]]::new() - foreach ($SiteItem in $SiteItems) { - $Site = $SiteItem.Data | ConvertFrom-Json -Depth 10 - if ($Site.isPersonalSite -eq $true) { - continue - } - - $SiteUsage = $null - [void]$UsageBySiteId.TryGetValue([string]$Site.sharepointIds.siteId.Trim('{}'), [ref]$SiteUsage) - - $Report.Add((ConvertTo-CIPPSharePointSiteUsagePayload -Site $Site -SiteUsage $SiteUsage -CacheTimestamp $CacheTimestamp)) - } - - return $Report | Sort-Object -Property displayName - - } catch { - Write-LogMessage -API 'SharePointSiteUsageReport' -tenant $TenantFilter -message "Failed to generate SharePoint site usage report: $($_.Exception.Message)" -sev Error -LogData (Get-CippException -Exception $_) - throw - } -} +function Get-CIPPSharePointSiteUsageReport { + <# + .SYNOPSIS + Generates a SharePoint site usage report from the CIPP Reporting database + + .DESCRIPTION + Retrieves cached SharePoint site listing and usage data and combines them to match + the payload shape of Invoke-ListSites for Type=SharePointSiteUsage. + + .PARAMETER TenantFilter + The tenant to generate the report for + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$TenantFilter + ) + + try { + if ($TenantFilter -eq 'AllTenants') { + $AllSiteItems = @(Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'SharePointSiteListing' | Where-Object { $_.RowKey -ne 'SharePointSiteListing-Count' }) + $AllUsageItems = @(Get-CIPPDbItem -TenantFilter 'allTenants' -Type 'SharePointSiteUsage' | Where-Object { $_.RowKey -ne 'SharePointSiteUsage-Count' }) + + $TenantList = Get-Tenants -IncludeErrors + $ValidTenants = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + foreach ($T in $TenantList) { [void]$ValidTenants.Add($T.defaultDomainName) } + + $UsageBySiteId = [System.Collections.Generic.Dictionary[string, object]]::new([System.StringComparer]::OrdinalIgnoreCase) + foreach ($UsageItem in $AllUsageItems) { + $UsageRow = $UsageItem.Data | ConvertFrom-Json -Depth 10 + if (-not [string]::IsNullOrWhiteSpace($UsageRow.siteId)) { + $UsageBySiteId[[string]$UsageRow.siteId.Trim('{}')] = $UsageRow + } + } + + $AllResults = [System.Collections.Generic.List[PSCustomObject]]::new() + foreach ($SiteItem in $AllSiteItems) { + $Tenant = $SiteItem.PartitionKey + if (-not $ValidTenants.Contains($Tenant)) { continue } + + $Site = $SiteItem.Data | ConvertFrom-Json -Depth 10 + if ($Site.isPersonalSite -eq $true) { continue } + + $SiteUsage = $null + [void]$UsageBySiteId.TryGetValue([string]$Site.sharepointIds.siteId.Trim('{}'), [ref]$SiteUsage) + + $AllResults.Add((ConvertTo-CIPPSharePointSiteUsagePayload -Site $Site -SiteUsage $SiteUsage -Tenant $Tenant)) + } + return $AllResults + } + + $SiteItems = @(Get-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSiteListing' | Where-Object { $_.RowKey -ne 'SharePointSiteListing-Count' }) + if (-not $SiteItems) { + throw 'No SharePoint site listing data found in reporting database. Sync SharePointSiteUsage cache first.' + } + + $UsageItems = @(Get-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointSiteUsage' | Where-Object { $_.RowKey -ne 'SharePointSiteUsage-Count' }) + + $LatestSiteTimestamp = ($SiteItems | Where-Object { $_.Timestamp } | Sort-Object Timestamp -Descending | Select-Object -First 1).Timestamp + $LatestUsageTimestamp = ($UsageItems | Where-Object { $_.Timestamp } | Sort-Object Timestamp -Descending | Select-Object -First 1).Timestamp + $CacheTimestamp = if ($LatestSiteTimestamp -and $LatestUsageTimestamp) { + if ($LatestSiteTimestamp -gt $LatestUsageTimestamp) { $LatestSiteTimestamp } else { $LatestUsageTimestamp } + } else { + $LatestSiteTimestamp ?? $LatestUsageTimestamp + } + + $UsageBySiteId = [System.Collections.Generic.Dictionary[string, object]]::new([System.StringComparer]::OrdinalIgnoreCase) + foreach ($UsageItem in $UsageItems) { + $UsageRow = $UsageItem.Data | ConvertFrom-Json -Depth 10 + if (-not [string]::IsNullOrWhiteSpace($UsageRow.siteId)) { + $UsageBySiteId[[string]$UsageRow.siteId.Trim('{}')] = $UsageRow + } + } + + $Report = [System.Collections.Generic.List[PSCustomObject]]::new() + foreach ($SiteItem in $SiteItems) { + $Site = $SiteItem.Data | ConvertFrom-Json -Depth 10 + if ($Site.isPersonalSite -eq $true) { + continue + } + + $SiteUsage = $null + [void]$UsageBySiteId.TryGetValue([string]$Site.sharepointIds.siteId.Trim('{}'), [ref]$SiteUsage) + + $Report.Add((ConvertTo-CIPPSharePointSiteUsagePayload -Site $Site -SiteUsage $SiteUsage -CacheTimestamp $CacheTimestamp)) + } + + return $Report | Sort-Object -Property displayName + + } catch { + Write-LogMessage -API 'SharePointSiteUsageReport' -tenant $TenantFilter -message "Failed to generate SharePoint site usage report: $($_.Exception.Message)" -sev Error -LogData (Get-CippException -Exception $_) + throw + } +} diff --git a/Modules/CIPPCore/Public/GraphHelper/New-CIPPMFAConnectorToken.ps1 b/Modules/CIPPCore/Public/GraphHelper/New-CIPPMFAConnectorToken.ps1 index 994d7acb1e45b..8442e57f70d3c 100644 --- a/Modules/CIPPCore/Public/GraphHelper/New-CIPPMFAConnectorToken.ps1 +++ b/Modules/CIPPCore/Public/GraphHelper/New-CIPPMFAConnectorToken.ps1 @@ -41,7 +41,15 @@ function New-CIPPMFAConnectorToken { $Row = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'NPSSecret' and RowKey eq '$TenantId'" return $Row.SecretValue } - return Get-CippKeyVaultSecret -Name $SecretName -AsPlainText -ErrorAction SilentlyContinue + # A missing secret is the normal first-call state for a tenant. The Key Vault helper throws on a + # 404 rather than returning nothing, so treat not-found as "nothing cached yet" and let provisioning + # create the secret. Any other retrieval failure is a real problem and propagates. + try { + return Get-CippKeyVaultSecret -Name $SecretName -AsPlainText -ErrorAction Stop + } catch { + if ($_.Exception.Message -match '404') { return $null } + throw + } } function Set-StoredSecret { param($Value) diff --git a/Modules/CIPPCore/Public/Invoke-CIPPMigrateOneDriveShortCuts.ps1 b/Modules/CIPPCore/Public/Invoke-CIPPMigrateOneDriveShortCuts.ps1 new file mode 100644 index 0000000000000..12bd32153aee4 --- /dev/null +++ b/Modules/CIPPCore/Public/Invoke-CIPPMigrateOneDriveShortCuts.ps1 @@ -0,0 +1,120 @@ + +function Invoke-CIPPMigrateOneDriveShortCuts { + <# + .SYNOPSIS + Migrates OneDrive root shortcuts into the Shortcuts folder. + .DESCRIPTION + Lists drive root children with Prefer: Include-Feature=AddToOneDrive, then PATCH-moves + each remoteItem shortcut that is not already under Shortcuts into special/shortcuts. + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param ( + [Parameter(Mandatory = $true)] + [string]$Username, + + [Parameter(Mandatory = $true)] + $TenantFilter, + + $Headers, + + [string]$APIName = 'Migrate OneDrive shortcuts', + + [string]$ItemId, + + [switch]$ListOnly + ) + + $PreferHeaders = @{ Prefer = 'Include-Feature=AddToOneDrive' } + $EscapedUser = [System.Uri]::EscapeDataString($Username) + $ListUri = "https://graph.microsoft.com/beta/users/$EscapedUser/drive/root/children?`$select=id,name,remoteItem,parentReference" + + try { + $RootChildren = @(New-GraphGetRequest -uri $ListUri -tenantid $TenantFilter -asapp $true -extraHeaders $PreferHeaders) + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Normalized = $ErrorMessage.NormalizedError + if ($Normalized -match 'itemNotFound|ResourceNotFound|404|does not have a drive|no drive') { + $Result = "No OneDrive found for $Username" + if (-not $ListOnly) { + Write-LogMessage -API $APIName -headers $Headers -message $Result -Sev 'Info' + } + if ($ListOnly) { return @() } + throw $Result + } + $Result = "Could not list OneDrive shortcuts for $Username : $Normalized" + Write-LogMessage -API $APIName -headers $Headers -message $Result -Sev 'Error' -LogData $ErrorMessage + throw $Result + } + + $ToMigrate = @($RootChildren | Where-Object { + $_.remoteItem -and + ($_.parentReference.path -notmatch '/Shortcuts(/|$)') + }) + + if (-not [string]::IsNullOrWhiteSpace($ItemId)) { + $ToMigrate = @($ToMigrate | Where-Object { $_.id -eq $ItemId }) + if ($ToMigrate.Count -eq 0 -and -not $ListOnly) { + $Result = "No root OneDrive shortcut with id $ItemId found for $Username" + Write-LogMessage -API $APIName -headers $Headers -message $Result -Sev 'Info' + throw $Result + } + } + + if ($ListOnly) { + return $ToMigrate + } + + if ($ToMigrate.Count -eq 0) { + $Result = "No root OneDrive shortcuts to migrate for $Username" + Write-LogMessage -API $APIName -headers $Headers -message $Result -Sev 'Info' + return $Result + } + + # Resolve the Shortcuts destination folder once per run. + try { + $ShortcutsFolder = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users/$EscapedUser/drive/special/shortcuts?`$select=id,name" -tenantid $TenantFilter -asapp $true + $ShortcutsFolderId = $ShortcutsFolder.id + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Could not resolve the Shortcuts folder (special/shortcuts) for $Username : $($ErrorMessage.NormalizedError)" + Write-LogMessage -API $APIName -headers $Headers -message $Result -Sev 'Error' -LogData $ErrorMessage + throw $Result + } + + $Migrated = [System.Collections.Generic.List[string]]::new() + $Failures = [System.Collections.Generic.List[string]]::new() + + foreach ($Item in $ToMigrate) { + $ShortcutName = [string]$Item.name + $SiteUrl = $Item.remoteItem.sharepointIds.siteUrl + $SiteSuffix = if ($SiteUrl) { " (site $SiteUrl)" } else { '' } + + try { + $MoveBody = @{ + parentReference = @{ id = $ShortcutsFolderId } + } | ConvertTo-Json -Depth 5 + $null = New-GraphPOSTRequest -uri "https://graph.microsoft.com/beta/users/$EscapedUser/drive/items/$($Item.id)" -tenantid $TenantFilter -type 'PATCH' -body $MoveBody -asapp $true + $Migrated.Add($ShortcutName) + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $FailMsg = "Could not migrate OneDrive shortcut '$ShortcutName' for ${Username}${SiteSuffix}: $($ErrorMessage.NormalizedError)" + Write-LogMessage -API $APIName -headers $Headers -message $FailMsg -Sev 'Error' -LogData $ErrorMessage + $Failures.Add($FailMsg) + } + } + + $Summary = "Migrated $($Migrated.Count) OneDrive shortcut(s) to the Shortcuts folder for $Username" + if ($Migrated.Count -gt 0) { + $Summary += ": $($Migrated -join ', ')" + } + if ($Failures.Count -gt 0) { + $Summary += ". Failures ($($Failures.Count)): $($Failures -join ' | ')" + Write-LogMessage -API $APIName -headers $Headers -message $Summary -Sev 'Error' + throw $Summary + } + + Write-LogMessage -API $APIName -headers $Headers -message $Summary -Sev 'Info' + return $Summary +} diff --git a/Modules/CIPPCore/Public/Invoke-CIPPOffboardingJob.ps1 b/Modules/CIPPCore/Public/Invoke-CIPPOffboardingJob.ps1 index 0c5025cd28673..f901d1e28f747 100644 --- a/Modules/CIPPCore/Public/Invoke-CIPPOffboardingJob.ps1 +++ b/Modules/CIPPCore/Public/Invoke-CIPPOffboardingJob.ps1 @@ -446,12 +446,21 @@ function Invoke-CIPPOffboardingJob { } } - # Start orchestration + # Start orchestration. + # + # Offboarding steps must run in payload order — a later step can undo an earlier one if they race + # (e.g. convert-to-shared reverting mailbox grants added a step earlier). DurableMode='Sequence' is + # the legacy Azure Functions durable flag and is kept for that host; Craft ignores it and instead + # honours Sequential, which pins the whole run to ONE worker and runs the steps one at a time in + # order. Start-CIPPOrchestrator probes the Craft bridge arity, so on a Craft too old to know + # Sequential it logs a warning and falls back to fan-out rather than failing — safe here because the + # grant steps are already idempotent (they read the ACE back), so the ordering is belt-and-suspenders. $InputObject = [PSCustomObject]@{ OrchestratorName = "OffboardingUser_$($Username)_$TenantFilter" Batch = @($Batch) SkipLog = $true DurableMode = 'Sequence' + Sequential = $true } # Add post-execution handler if TaskInfo is provided (from scheduled task) diff --git a/Modules/CIPPCore/Public/New-CIPPOneDriveShortCut.ps1 b/Modules/CIPPCore/Public/New-CIPPOneDriveShortCut.ps1 index 7121eab0005a1..8ae8023ddcc95 100644 --- a/Modules/CIPPCore/Public/New-CIPPOneDriveShortCut.ps1 +++ b/Modules/CIPPCore/Public/New-CIPPOneDriveShortCut.ps1 @@ -7,10 +7,17 @@ function New-CIPPOneDriveShortCut { $URL, $TenantFilter, $APIName = 'Create OneDrive shortcut', - $Headers + $Headers, + [ValidateSet('root', 'shortcuts')] + [string]$Destination = 'root' ) - Write-Host "Received $Username and $UserId. We're using $URL and $TenantFilter" + Write-Host "Received $Username and $UserId. We're using $URL and $TenantFilter (destination=$Destination)" try { + $SPOTenant = Get-CIPPSPOTenant -TenantFilter $TenantFilter | Select-Object -First 1 + if ($SPOTenant.DisableAddToOneDrive -eq $true) { + throw "Add shortcut to OneDrive is disabled for this tenant (DisableAddToOneDrive). Enable it via the 'Set Add Shortcuts To OneDrive button state' standard, or Set-SPOTenant -DisableAddShortcutsToOneDrive `$false." + } + # Unwrap SharePoint browser URLs — e.g. AllItems.aspx?id=... or onedrive.aspx?id=... # The `id` query parameter holds the server-relative path to the folder, URL-encoded. if ($URL -match '[?&]id=([^&]+)') { @@ -20,21 +27,50 @@ function New-CIPPOneDriveShortCut { Write-Host "Resolved browser URL to: $URL" } - # Find site by prefix match (longest match wins — handles subsites correctly) - $SiteInfo = (New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/sites/' -tenantid $TenantFilter -asapp $true) | - Where-Object { $URL -like "$($_.weburl.TrimEnd('/'))/*" -or $URL -eq $_.weburl.TrimEnd('/') } | - Sort-Object { $_.weburl.Length } -Descending | - Select-Object -First 1 + # Strip list view paths so Shared Documents/Forms/AllItems.aspx resolves as the library + $URL = ($URL -replace '/Forms/AllItems\.aspx.*$', '' -replace '/Forms/.*$', '').TrimEnd('/') + + $ParsedUri = [System.Uri]$URL + $Hostname = $ParsedUri.Host + $AbsPath = [Uri]::UnescapeDataString($ParsedUri.AbsolutePath).TrimEnd('/') + + # Resolve site via hostname:path (avoids paging gaps on GET /sites). Try longest path first for subsites. + $SiteInfo = $null + $Candidates = [System.Collections.Generic.List[string]]::new() + if ($AbsPath -match '^/(sites|teams)/') { + $Parts = @($AbsPath.TrimStart('/') -split '/') + for ($i = $Parts.Length; $i -ge 2; $i--) { + $Candidates.Add('/' + ($Parts[0..($i - 1)] -join '/')) + } + } elseif ($AbsPath -match '^(?/personal/[^/]+)') { + $Candidates.Add($Matches['od']) + } else { + throw "Could not parse a SharePoint site path from URL: $URL" + } + + foreach ($Candidate in $Candidates) { + try { + $SiteInfo = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/sites/${Hostname}:${Candidate}?`$select=id,displayName,webUrl" -tenantid $TenantFilter -asapp $true + if ($SiteInfo.id) { break } + } catch { + $SiteInfo = $null + } + } if (-not $SiteInfo) { throw "Could not find a SharePoint site matching URL: $URL" } # Extract whatever comes after the site URL (library name + optional folder path) - $RelativePath = $URL.Substring($SiteInfo.weburl.TrimEnd('/').Length).TrimStart('/') + $SitePath = ([System.Uri]$SiteInfo.webUrl).AbsolutePath.TrimEnd('/') + $RelativePath = if ($AbsPath.Length -gt $SitePath.Length -and $AbsPath.StartsWith($SitePath, [System.StringComparison]::OrdinalIgnoreCase)) { + $AbsPath.Substring($SitePath.Length).TrimStart('/') + } else { + '' + } if ([string]::IsNullOrWhiteSpace($RelativePath)) { - # ── Root shortcut (original behaviour) ────────────────────────────── + # Same as the proven test script / HAR: default library via sites/{id}/drive sharePointIds $SPIds = (New-GraphGetRequest -uri "https://graph.microsoft.com/beta/sites/$($SiteInfo.id)/drive?`$select=SharepointIds" -tenantid $TenantFilter -asapp $true).SharePointIds $body = [PSCustomObject]@{ name = 'Documents' @@ -52,37 +88,31 @@ function New-CIPPOneDriveShortCut { $ShortcutDisplayName = $SiteInfo.displayName } else { # ── Subfolder shortcut ─────────────────────────────────────────────── - # Split "SharedDocuments/Folder123" into library name and optional subfolder $PathParts = $RelativePath -split '/' $LibraryName = [Uri]::UnescapeDataString($PathParts[0]) $FolderPath = if ($PathParts.Count -gt 1) { ($PathParts[1..($PathParts.Count - 1)] | ForEach-Object { [Uri]::UnescapeDataString($_) }) -join '/' } else { $null } - # Find the drive (document library) whose name matches the first path segment $Drives = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/sites/$($SiteInfo.id)/drives?`$select=id,name,webUrl" -tenantid $TenantFilter -asapp $true $Drive = $Drives | Where-Object { $_.name -eq $LibraryName -or [Uri]::UnescapeDataString($_.webUrl.TrimEnd('/').Split('/')[-1]) -eq $LibraryName } | Select-Object -First 1 - # Fall back to the default drive when no name match is found if (-not $Drive) { $Drive = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/sites/$($SiteInfo.id)/drive?`$select=id,name" -tenantid $TenantFilter -asapp $true } - # Resolve the target driveItem — subfolder or library root if ($FolderPath) { $EncodedFolderPath = ($FolderPath -split '/' | ForEach-Object { [Uri]::EscapeDataString($_) }) -join '/' $FolderItem = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/drives/$($Drive.id)/root:/$($EncodedFolderPath)?`$select=id,name,parentReference" -tenantid $TenantFilter -asapp $true $DisplayName = $FolderItem.name } else { $FolderItem = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/drives/$($Drive.id)/root?`$select=id,name" -tenantid $TenantFilter -asapp $true - # Graph returns name='root' for a drive's root item — use the drive (library) name instead $DisplayName = $Drive.name } - # POST body for subfolder uses driveItem.id + drive.id (not sharepointIds) $body = [PSCustomObject]@{ name = $DisplayName remoteItem = @{ @@ -94,9 +124,17 @@ function New-CIPPOneDriveShortCut { $ShortcutDisplayName = "$($SiteInfo.displayName) / $DisplayName" } - $null = New-GraphPOSTRequest -method POST "https://graph.microsoft.com/beta/users/$Username/drive/root/children" -body $Body -tenantid $TenantFilter -asapp $true - Write-LogMessage -API $APIName -headers $Headers -message "Created OneDrive shortcut called $ShortcutDisplayName for $Username" -Sev 'info' - return "Successfully created OneDrive Shortcut for $Username called $ShortcutDisplayName" + # Proven path is root/children. special/shortcuts create is optional/undocumented. + $PostUri = if ($Destination -eq 'shortcuts') { + "https://graph.microsoft.com/beta/users/$Username/drive/special/shortcuts/children" + } else { + "https://graph.microsoft.com/beta/users/$Username/drive/root/children" + } + $DestinationLabel = if ($Destination -eq 'shortcuts') { 'Shortcuts folder' } else { 'OneDrive root' } + + $null = New-GraphPOSTRequest -uri $PostUri -body $body -tenantid $TenantFilter -asapp $true + Write-LogMessage -API $APIName -headers $Headers -message "Created OneDrive shortcut called $ShortcutDisplayName for $Username in $DestinationLabel" -Sev 'info' + return "Successfully created OneDrive Shortcut for $Username called $ShortcutDisplayName in $DestinationLabel" } catch { $ErrorMessage = Get-CippException -Exception $_ $Result = "Could not add OneDrive shortcut to $Username : $($ErrorMessage.NormalizedError)" diff --git a/Modules/CIPPCore/Public/Standards/New-CIPPStandardsRun.ps1 b/Modules/CIPPCore/Public/Standards/New-CIPPStandardsRun.ps1 index f6183ddd08885..33c339232eb57 100644 --- a/Modules/CIPPCore/Public/Standards/New-CIPPStandardsRun.ps1 +++ b/Modules/CIPPCore/Public/Standards/New-CIPPStandardsRun.ps1 @@ -80,9 +80,20 @@ function New-CIPPStandardsRun { Write-Information "Built batch of $($Batch.Count) tenant standards list activities: $($Batch | ConvertTo-Json -Depth 5 -Compress)" + # The orchestrator name is the run identity, and a second run of the same name is skipped as + # "already active" while the caller is still told it started. A fixed 'StandardsList' therefore + # drops concurrent manual runs for different tenants/templates. Suffix the name with the run + # scope so each tenant/template gets its own run; the full scheduled sweep (allTenants + all + # templates) keeps the bare name, since it is a single run with nothing to collide with. + $RunScope = @( + if ($TenantFilter -and $TenantFilter -ne 'allTenants') { $TenantFilter } + if ($TemplateID -and $TemplateID -ne '*') { $TemplateID } + ) -join '-' + $OrchestratorName = if ($RunScope) { "StandardsList-$RunScope" } else { 'StandardsList' } + # Start orchestrator with distributed batch and post-exec aggregation $InputObject = [PSCustomObject]@{ - OrchestratorName = 'StandardsList' + OrchestratorName = $OrchestratorName Batch = @($Batch) PostExecution = @{ FunctionName = 'CIPPStandardsApplyBatch' diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddAssignmentFilterTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddAssignmentFilterTemplate.ps1 index d43f3555a4e28..3f8dbfa5a8bb7 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddAssignmentFilterTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-AddAssignmentFilterTemplate.ps1 @@ -56,7 +56,6 @@ function Invoke-AddAssignmentFilterTemplate { } - # Associate values to output bindings by calling 'Push-OutputBinding'. return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK Body = $body diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-EditAssignmentFilter.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-EditAssignmentFilter.ps1 index a3fda1715b35b..29a488aede822 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-EditAssignmentFilter.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-EditAssignmentFilter.ps1 @@ -53,7 +53,6 @@ function Invoke-EditAssignmentFilter { $StatusCode = [HttpStatusCode]::InternalServerError } - # Associate values to output bindings by calling 'Push-OutputBinding'. return ([HttpResponseContext]@{ StatusCode = $StatusCode Body = @{'Results' = $Result } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ExecAssignmentFilter.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ExecAssignmentFilter.ps1 index f08bc7bbbafb3..146159f80cc48 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ExecAssignmentFilter.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ExecAssignmentFilter.ps1 @@ -44,7 +44,6 @@ function Invoke-ExecAssignmentFilter { $StatusCode = [HttpStatusCode]::InternalServerError } - # Associate values to output bindings by calling 'Push-OutputBinding'. return ([HttpResponseContext]@{ StatusCode = $StatusCode Body = @{'Results' = $Result } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListAssignmentFilterTemplates.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListAssignmentFilterTemplates.ps1 index de465d96a1ab7..7d6a7cbf1bd62 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListAssignmentFilterTemplates.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-ListAssignmentFilterTemplates.ps1 @@ -31,7 +31,6 @@ function Invoke-ListAssignmentFilterTemplates { if ($ID) { $Templates = $Templates | Where-Object -Property GUID -EQ $ID } - # Associate values to output bindings by calling 'Push-OutputBinding'. return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK Body = @($Templates) diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-RemoveAssignmentFilterTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-RemoveAssignmentFilterTemplate.ps1 index ccab5a1289605..e8973960f75c9 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-RemoveAssignmentFilterTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Endpoint/MEM/Invoke-RemoveAssignmentFilterTemplate.ps1 @@ -33,7 +33,6 @@ Function Invoke-RemoveAssignmentFilterTemplate { } - # Associate values to output bindings by calling 'Push-OutputBinding'. return ([HttpResponseContext]@{ StatusCode = $StatusCode Body = @{'Results' = $Result } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecMigrateOneDriveShortCuts.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecMigrateOneDriveShortCuts.ps1 new file mode 100644 index 0000000000000..2dc2e4d0d0bd1 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecMigrateOneDriveShortCuts.ps1 @@ -0,0 +1,38 @@ +Function Invoke-ExecMigrateOneDriveShortCuts { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Identity.User.ReadWrite + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + $Headers = $Request.Headers + + $TenantFilter = $Request.Body.tenantFilter + $Username = $Request.Body.username + if ($Username -is [psobject] -and $Username.value) { $Username = $Username.value } + $ItemId = $Request.Body.id + if ($ItemId -is [psobject] -and $ItemId.value) { $ItemId = $ItemId.value } + + try { + $MigrateParams = @{ + Username = $Username + TenantFilter = $TenantFilter + Headers = $Headers + } + if (-not [string]::IsNullOrWhiteSpace([string]$ItemId)) { + $MigrateParams.ItemId = $ItemId + } + $Result = Invoke-CIPPMigrateOneDriveShortCuts @MigrateParams + $StatusCode = [HttpStatusCode]::OK + } catch { + $Result = $_.Exception.Message + $StatusCode = [HttpStatusCode]::InternalServerError + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{'Results' = $Result } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecOneDriveShortCut.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecOneDriveShortCut.ps1 index 822fd952191fd..86fe4df0c5064 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecOneDriveShortCut.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecOneDriveShortCut.ps1 @@ -15,9 +15,16 @@ Function Invoke-ExecOneDriveShortCut { $Username = $Request.Body.username $UserId = $Request.Body.userid $URL = $Request.Body.siteUrl.value + $Destination = $Request.Body.destination + if ($Destination -is [psobject] -and $Destination.value) { + $Destination = $Destination.value + } + if ([string]::IsNullOrWhiteSpace([string]$Destination)) { + $Destination = 'root' + } Try { - $Result = New-CIPPOneDriveShortCut -Username $Username -UserId $UserId -TenantFilter $TenantFilter -URL $URL -Headers $Headers + $Result = New-CIPPOneDriveShortCut -Username $Username -UserId $UserId -TenantFilter $TenantFilter -URL $URL -Destination $Destination -Headers $Headers $StatusCode = [HttpStatusCode]::OK } catch { $Result = $_.Exception.Message diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecRemoveOneDriveShortCut.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecRemoveOneDriveShortCut.ps1 new file mode 100644 index 0000000000000..015174bc2ccba --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ExecRemoveOneDriveShortCut.ps1 @@ -0,0 +1,41 @@ +Function Invoke-ExecRemoveOneDriveShortCut { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Identity.User.ReadWrite + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + $Headers = $Request.Headers + + $TenantFilter = $Request.Body.tenantFilter + $Username = $Request.Body.username + if ($Username -is [psobject] -and $Username.value) { $Username = $Username.value } + $ItemId = $Request.Body.id + if ($ItemId -is [psobject] -and $ItemId.value) { $ItemId = $ItemId.value } + $Name = $Request.Body.name + if ($Name -is [psobject] -and $Name.value) { $Name = $Name.value } + + try { + if ([string]::IsNullOrWhiteSpace($Username) -or [string]::IsNullOrWhiteSpace($ItemId)) { + throw 'username and id are required to remove an OneDrive shortcut' + } + $EscapedUser = [System.Uri]::EscapeDataString($Username) + $null = New-GraphPOSTRequest -uri "https://graph.microsoft.com/beta/users/$EscapedUser/drive/items/$ItemId" -tenantid $TenantFilter -type 'DELETE' -asapp $true + $Label = if ($Name) { "'$Name'" } else { $ItemId } + $Result = "Removed OneDrive shortcut $Label for $Username" + Write-LogMessage -API 'Remove OneDrive shortcut' -headers $Headers -message $Result -Sev 'Info' + $StatusCode = [HttpStatusCode]::OK + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Result = "Could not remove OneDrive shortcut for $Username : $($ErrorMessage.NormalizedError)" + Write-LogMessage -API 'Remove OneDrive shortcut' -headers $Headers -message $Result -Sev 'Error' -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::InternalServerError + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{'Results' = $Result } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUserOneDriveShortcuts.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUserOneDriveShortcuts.ps1 new file mode 100644 index 0000000000000..4dce26840f72f --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-ListUserOneDriveShortcuts.ps1 @@ -0,0 +1,96 @@ +Function Invoke-ListUserOneDriveShortcuts { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Identity.User.Read + .DESCRIPTION + Lists OneDrive remoteItem shortcuts for a user from the drive root and the Shortcuts folder. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $TenantFilter = $Request.Query.tenantFilter + $UserId = $Request.Query.userId + $Username = $Request.Query.userPrincipalName + + if ([string]::IsNullOrWhiteSpace($Username) -and -not [string]::IsNullOrWhiteSpace($UserId)) { + $User = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users/$UserId`?`$select=userPrincipalName" -tenantid $TenantFilter -asapp $true + $Username = $User.userPrincipalName + } + + if ([string]::IsNullOrWhiteSpace($Username)) { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @(@{ Results = 'userPrincipalName or userId is required' }) + }) + } + + $PreferHeaders = @{ Prefer = 'Include-Feature=AddToOneDrive' } + $EscapedUser = [System.Uri]::EscapeDataString($Username) + $Select = 'id,name,remoteItem,parentReference,createdDateTime,lastModifiedDateTime' + + $Results = [System.Collections.Generic.List[object]]::new() + + try { + $RootChildren = @(New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users/$EscapedUser/drive/root/children?`$select=$Select" -tenantid $TenantFilter -asapp $true -extraHeaders $PreferHeaders) + foreach ($Item in ($RootChildren | Where-Object { $_.remoteItem })) { + $Location = if ($Item.parentReference.path -match '/Shortcuts(/|$)') { 'Shortcuts folder' } else { 'OneDrive root' } + $Results.Add([PSCustomObject]@{ + id = $Item.id + name = $Item.name + location = $Location + siteUrl = $Item.remoteItem.sharepointIds.siteUrl + remoteItemId = $Item.remoteItem.id + remoteDriveId = $Item.remoteItem.parentReference.driveId + createdDateTime = $Item.createdDateTime + lastModifiedDateTime = $Item.lastModifiedDateTime + userPrincipalName = $Username + userId = $UserId + }) + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + if ($ErrorMessage.NormalizedError -match 'itemNotFound|ResourceNotFound|404|does not have a drive|no drive') { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = @() + }) + } + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::InternalServerError + Body = @(@{ Results = "Could not list OneDrive root shortcuts for $Username : $($ErrorMessage.NormalizedError)" }) + }) + } + + try { + $ShortcutChildren = @(New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users/$EscapedUser/drive/special/shortcuts/children?`$select=$Select" -tenantid $TenantFilter -asapp $true -extraHeaders $PreferHeaders) + foreach ($Item in $ShortcutChildren) { + # Avoid duplicates if root listing already returned Shortcuts children + if ($Results.id -contains $Item.id) { continue } + $Results.Add([PSCustomObject]@{ + id = $Item.id + name = $Item.name + location = 'Shortcuts folder' + siteUrl = $Item.remoteItem.sharepointIds.siteUrl + remoteItemId = $Item.remoteItem.id + remoteDriveId = $Item.remoteItem.parentReference.driveId + createdDateTime = $Item.createdDateTime + lastModifiedDateTime = $Item.lastModifiedDateTime + userPrincipalName = $Username + userId = $UserId + }) + } + } catch { + # special/shortcuts may 404 when the folder has never been created — treat as empty + $ErrorMessage = Get-CippException -Exception $_ + if ($ErrorMessage.NormalizedError -notmatch 'itemNotFound|ResourceNotFound|404|special') { + Write-LogMessage -API 'ListUserOneDriveShortcuts' -headers $Request.Headers -message "Could not list Shortcuts folder for $Username : $($ErrorMessage.NormalizedError)" -Sev 'Warning' -LogData $ErrorMessage + } + } + + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = @($Results) + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-AddStandardsTemplate.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-AddStandardsTemplate.ps1 index 3f38f3f73e4c5..679aec62d08c7 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-AddStandardsTemplate.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-AddStandardsTemplate.ps1 @@ -1,7 +1,7 @@ function Invoke-AddStandardsTemplate { <# .FUNCTIONALITY - Entrypoint + Entrypoint,AnyTenant .ROLE Tenant.Standards.ReadWrite #> @@ -14,6 +14,41 @@ function Invoke-AddStandardsTemplate { throw 'Invalid Tenant Selection. A standard must be assigned to at least 1 tenant.' } + # tenantFilter is a *list* (and may include AllTenants or tenant groups), so this endpoint is + # AnyTenant and validates the whole list here: standards runs execute app-level without + # re-checking custom-role access, so this is the boundary that stops a scoped caller assigning + # standards to tenants outside their scope. + $AllowedTenants = Test-CIPPAccess -Request $Request -TenantList + if ($AllowedTenants -notcontains 'AllTenants') { + $OutOfScope = foreach ($Item in @($Request.Body.tenantFilter)) { + if ($Item.value -eq 'AllTenants') { + # Assigning to every tenant requires an unrestricted (AllTenants) scope. + 'All Tenants' + continue + } + if ($Item.type -eq 'Group') { + foreach ($TargetId in @(Expand-CIPPTenantGroups -TenantFilter @($Item)).addedFields.customerId) { + if ($AllowedTenants -notcontains $TargetId) { $Item.label ?? $Item.value } + } + continue + } + # Single tenant: resolve to a customerId. An unresolved value is $null, which is never + # in the allowed list, so -notcontains fails closed on its own. + $TargetId = $Item.addedFields.customerId ?? (Get-Tenants -TenantFilter $Item.value).customerId + if ($AllowedTenants -notcontains $TargetId) { + $Item.label ?? $Item.value + } + } + if (($OutOfScope | Measure-Object).Count -gt 0) { + $Denied = $OutOfScope -join ', ' + Write-LogMessage -headers $Headers -API $APIName -message "Blocked standards template save; caller is not permitted for: $Denied" -Sev 'Warning' + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::Forbidden + Body = "Access to one or more of the selected tenants is not allowed: $Denied" + }) + } + } + $GUID = $Request.body.GUID ? $request.body.GUID : (New-Guid).GUID #updatedBy = $request.headers.'x-ms-client-principal' #updatedAt = (Get-Date).ToUniversalTime() diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/Report-Builder/Invoke-ExecGenerateReportBuilderReport.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/Report-Builder/Invoke-ExecGenerateReportBuilderReport.ps1 index 6e076663583e7..50a73242f55f5 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/Report-Builder/Invoke-ExecGenerateReportBuilderReport.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tools/Report-Builder/Invoke-ExecGenerateReportBuilderReport.ps1 @@ -66,7 +66,7 @@ function Invoke-ExecGenerateReportBuilderReport { $StatusCode = [HttpStatusCode]::BadRequest } - Push-OutputBinding -Name Response -Value ([HttpResponseContext]@{ + return ([HttpResponseContext]@{ StatusCode = $StatusCode Body = ConvertTo-Json -InputObject $Result -Depth 20 }) diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardMigrateOneDriveShortcuts.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardMigrateOneDriveShortcuts.ps1 new file mode 100644 index 0000000000000..65c1c43719b8d --- /dev/null +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardMigrateOneDriveShortcuts.ps1 @@ -0,0 +1,116 @@ +function Invoke-CIPPStandardMigrateOneDriveShortcuts { + <# + .FUNCTIONALITY + Internal + .COMPONENT + (APIName) MigrateOneDriveShortcuts + .SYNOPSIS + (Label) Migrate OneDrive root shortcuts to the Shortcuts folder + .DESCRIPTION + (Helptext) Finds SharePoint library shortcuts sitting in each user's OneDrive root and moves them into the Shortcuts folder (PATCH move into special/shortcuts), matching the optional Microsoft UI location. + (DocsDescription) Over time Add shortcut to OneDrive can leave many remote library links in the OneDrive root. Microsoft also supports placing those links in an optional Shortcuts folder. This standard lists each enabled member user's OneDrive root with Prefer Include-Feature=AddToOneDrive, then for any remoteItem shortcuts still outside Shortcuts moves them into special/shortcuts. Users without a provisioned OneDrive are skipped. Failures name the user, shortcut, and site URL when available. + .NOTES + CAT + SharePoint Standards + TAG + EXECUTIVETEXT + Keeps employee OneDrive roots tidy by moving SharePoint library shortcuts into the dedicated Shortcuts folder instead of leaving them scattered among personal files. + ADDEDCOMPONENT + IMPACT + Low Impact + ADDEDDATE + 2026-09-08 + POWERSHELLEQUIVALENT + PATCH drive/items/{id} parentReference → special/shortcuts + RECOMMENDEDBY + REQUIREDCAPABILITIES + "SHAREPOINTWAC" + "SHAREPOINTSTANDARD" + "SHAREPOINTENTERPRISE" + "SHAREPOINTENTERPRISE_EDU" + "SHAREPOINTENTERPRISE_GOV" + "ONEDRIVEENTERPRISE" + UPDATECOMMENTBLOCK + Run the Tools\Update-StandardsComments.ps1 script to update this comment block + .LINK + https://docs.cipp.app/user-documentation/tenant/standards/alignment/templates/available-standards + #> + + param($Tenant, $Settings) + + $TestResult = Test-CIPPStandardLicense -StandardName 'MigrateOneDriveShortcuts' -TenantFilter $Tenant -RequiredCapabilities @('SHAREPOINTWAC', 'SHAREPOINTSTANDARD', 'SHAREPOINTENTERPRISE', 'SHAREPOINTENTERPRISE_EDU', 'SHAREPOINTENTERPRISE_GOV', 'ONEDRIVEENTERPRISE') + if ($TestResult -eq $false) { + return $true + } + + try { + $AllUsers = New-CIPPDbRequest -TenantFilter $Tenant -Type 'Users' + $CandidateUsers = @($AllUsers | Where-Object { + $_.accountEnabled -eq $true -and + $_.userType -eq 'Member' -and + -not [string]::IsNullOrWhiteSpace($_.userPrincipalName) + }) + } catch { + $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message + Write-LogMessage -API 'Standards' -Tenant $Tenant -Message "Could not get the MigrateOneDriveShortcuts state for $Tenant. Error: $ErrorMessage" -Sev Error + return + } + + $UsersWithRootShortcuts = [System.Collections.Generic.List[object]]::new() + + foreach ($User in $CandidateUsers) { + try { + $RootShortcuts = @(Invoke-CIPPMigrateOneDriveShortCuts -Username $User.userPrincipalName -TenantFilter $Tenant -ListOnly) + if ($RootShortcuts.Count -gt 0) { + $UsersWithRootShortcuts.Add([PSCustomObject]@{ + userPrincipalName = $User.userPrincipalName + displayName = $User.displayName + shortcutCount = $RootShortcuts.Count + shortcuts = @($RootShortcuts | ForEach-Object { $_.name }) + }) + } + } catch { + # No OneDrive or list failure: skip quietly for scan (migrate helper already classifies no-drive). + $Msg = $_.Exception.Message + if ($Msg -notmatch 'No OneDrive found') { + Write-LogMessage -API 'Standards' -tenant $Tenant -message "MigrateOneDriveShortcuts: could not scan $($User.userPrincipalName): $Msg" -sev Warning + } + } + } + + if ($Settings.remediate -eq $true) { + if ($UsersWithRootShortcuts.Count -eq 0) { + Write-LogMessage -API 'Standards' -tenant $Tenant -message 'No root OneDrive shortcuts found to migrate.' -sev Info + } else { + foreach ($Row in @($UsersWithRootShortcuts)) { + try { + $Result = Invoke-CIPPMigrateOneDriveShortCuts -Username $Row.userPrincipalName -TenantFilter $Tenant + Write-LogMessage -API 'Standards' -tenant $Tenant -message $Result -sev Info + } catch { + Write-LogMessage -API 'Standards' -tenant $Tenant -message $_.Exception.Message -sev Error + } + } + } + } + + if ($Settings.alert -eq $true) { + if ($UsersWithRootShortcuts.Count -gt 0) { + Write-StandardsAlert -message "Users with OneDrive shortcuts still in the root: $($UsersWithRootShortcuts.Count)" -object $UsersWithRootShortcuts -tenant $Tenant -standardName 'MigrateOneDriveShortcuts' -standardId $Settings.standardId + Write-LogMessage -API 'Standards' -tenant $Tenant -message "Users with OneDrive shortcuts still in the root: $($UsersWithRootShortcuts.Count)" -sev Info + } else { + Write-LogMessage -API 'Standards' -tenant $Tenant -message 'No root OneDrive shortcuts found.' -sev Info + } + } + + if ($Settings.report -eq $true) { + $FieldValue = @($UsersWithRootShortcuts | Select-Object userPrincipalName, displayName, shortcutCount, shortcuts) + $CurrentValue = [PSCustomObject]@{ + UsersWithRootShortcuts = $FieldValue + } + $ExpectedValue = [PSCustomObject]@{ + UsersWithRootShortcuts = @() + } + Set-CIPPStandardsCompareField -FieldName 'standards.MigrateOneDriveShortcuts' -CurrentValue $CurrentValue -ExpectedValue $ExpectedValue -Tenant $Tenant + Add-CIPPBPAField -FieldName 'MigrateOneDriveShortcuts' -FieldValue $FieldValue -StoreAs json -Tenant $Tenant + } +} diff --git a/Modules/CippExtensions/Public/Halo/Get-HaloMapping.ps1 b/Modules/CippExtensions/Public/Halo/Get-HaloMapping.ps1 index 2bd9fe338efe2..554fd8e35590c 100644 --- a/Modules/CippExtensions/Public/Halo/Get-HaloMapping.ps1 +++ b/Modules/CippExtensions/Public/Halo/Get-HaloMapping.ps1 @@ -42,9 +42,10 @@ function Get-HaloMapping { $Configuration = ((Get-CIPPAzDataTableEntity @Table).config | ConvertFrom-Json -ea stop).HaloPSA $Token = Get-HaloToken -configuration $Configuration + $UserAgent = Get-CippUserAgent $i = 1 $RawHaloClients = do { - $Result = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/Client?page_no=$i&page_size=999&pageinate=true" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($token.access_token)" } + $Result = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/Client?page_no=$i&page_size=999&pageinate=true" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($token.access_token)" } $Result.clients | Select-Object * -ExcludeProperty logo $i++ $pagecount = [Math]::Ceiling($Result.record_count / 999) diff --git a/Modules/CippExtensions/Public/Halo/Get-HaloPriority.ps1 b/Modules/CippExtensions/Public/Halo/Get-HaloPriority.ps1 index 629b97c3c2422..7e388a167de6e 100644 --- a/Modules/CippExtensions/Public/Halo/Get-HaloPriority.ps1 +++ b/Modules/CippExtensions/Public/Halo/Get-HaloPriority.ps1 @@ -36,6 +36,7 @@ function Get-HaloPriority { } $Headers = @{ Authorization = "Bearer $($Token.access_token)" } + $UserAgent = Get-CippUserAgent $SlaId = Get-HaloTicketTypeSlaId -TicketType $TicketType -Configuration $Configuration -Token $Token if (-not $SlaId) { @@ -51,7 +52,7 @@ function Get-HaloPriority { # The /SLA/{id} response shape varies between Halo versions: some return full priority # objects under .priorities, some only IDs. Resolve both by fetching the canonical # priority list and filtering by ID, which works regardless of the SLA payload shape. - $Sla = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/SLA/$SlaId" -ContentType 'application/json' -Method GET -Headers $Headers + $Sla = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/SLA/$SlaId" -ContentType 'application/json' -Method GET -Headers $Headers $SlaPriorityIds = @() if ($Sla.priorities) { @@ -60,7 +61,7 @@ function Get-HaloPriority { } } - $AllPriorities = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/Priority" -ContentType 'application/json' -Method GET -Headers $Headers + $AllPriorities = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/Priority" -ContentType 'application/json' -Method GET -Headers $Headers if ($SlaPriorityIds.Count -gt 0) { $AllPriorities | Where-Object { $_.id -in $SlaPriorityIds } | Sort-Object -Property priorityorder, name diff --git a/Modules/CippExtensions/Public/Halo/Get-HaloRequestSource.ps1 b/Modules/CippExtensions/Public/Halo/Get-HaloRequestSource.ps1 index 1aa8179773618..56cb989eafc74 100644 --- a/Modules/CippExtensions/Public/Halo/Get-HaloRequestSource.ps1 +++ b/Modules/CippExtensions/Public/Halo/Get-HaloRequestSource.ps1 @@ -21,8 +21,9 @@ function Get-HaloRequestSource { try { $Configuration = ((Get-CIPPAzDataTableEntity @Table).config | ConvertFrom-Json -ea stop).HaloPSA $Token = Get-HaloToken -configuration $Configuration + $UserAgent = Get-CippUserAgent - $Response = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/lookup?lookupid=22&showall=true" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($Token.access_token)" } + $Response = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/lookup?lookupid=22&showall=true" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($Token.access_token)" } # Halo returns a bare array here, but some of its lookup responses wrap the rows. Handle # both so a version difference reads as "no sources" rather than throwing. diff --git a/Modules/CippExtensions/Public/Halo/Get-HaloTicketOutcome.ps1 b/Modules/CippExtensions/Public/Halo/Get-HaloTicketOutcome.ps1 index c3e19b9b17076..2b1aa93c1b056 100644 --- a/Modules/CippExtensions/Public/Halo/Get-HaloTicketOutcome.ps1 +++ b/Modules/CippExtensions/Public/Halo/Get-HaloTicketOutcome.ps1 @@ -20,13 +20,14 @@ function Get-HaloTicketOutcome { try { $Configuration = ((Get-CIPPAzDataTableEntity @Table).config | ConvertFrom-Json -ea stop).HaloPSA $Token = Get-HaloToken -configuration $Configuration + $UserAgent = Get-CippUserAgent if (-not $TicketType) { $TicketType = $Configuration.TicketType.value ?? $Configuration.TicketType } if ($TicketType) { - $WorkflowId = (Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/tickettype/$TicketType" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($Token.access_token)" }).workflow_id - $Workflow = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/workflow/$WorkflowId" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($Token.access_token)" } - $Outcomes = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/outcome" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($Token.access_token)" } + $WorkflowId = (Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/tickettype/$TicketType" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($Token.access_token)" }).workflow_id + $Workflow = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/workflow/$WorkflowId" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($Token.access_token)" } + $Outcomes = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/outcome" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($Token.access_token)" } $Outcomes | Where-Object { $_.id -in $Workflow.steps.actions.action_id } | Sort-Object -Property buttonname } else { diff --git a/Modules/CippExtensions/Public/Halo/Get-HaloTicketType.ps1 b/Modules/CippExtensions/Public/Halo/Get-HaloTicketType.ps1 index 6ed6d21e40541..60b7bbd7a6d74 100644 --- a/Modules/CippExtensions/Public/Halo/Get-HaloTicketType.ps1 +++ b/Modules/CippExtensions/Public/Halo/Get-HaloTicketType.ps1 @@ -14,8 +14,9 @@ function Get-HaloTicketType { try { $Configuration = ((Get-CIPPAzDataTableEntity @Table).config | ConvertFrom-Json -ea stop).HaloPSA $Token = Get-HaloToken -configuration $Configuration + $UserAgent = Get-CippUserAgent - Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/TicketType?showall=true" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($Token.access_token)" } + Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/TicketType?showall=true" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($Token.access_token)" } } catch { $Message = if ($_.ErrorDetails.Message) { Get-NormalizedError -Message $_.ErrorDetails.Message diff --git a/Modules/CippExtensions/Public/Halo/Get-HaloTicketTypeSlaId.ps1 b/Modules/CippExtensions/Public/Halo/Get-HaloTicketTypeSlaId.ps1 index 1211f599654dc..1bc9fec3cb7c4 100644 --- a/Modules/CippExtensions/Public/Halo/Get-HaloTicketTypeSlaId.ps1 +++ b/Modules/CippExtensions/Public/Halo/Get-HaloTicketTypeSlaId.ps1 @@ -32,7 +32,8 @@ function Get-HaloTicketTypeSlaId { try { $Headers = @{ Authorization = "Bearer $($Token.access_token)" } - $TicketTypeRecord = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/tickettype/$TicketType" -ContentType 'application/json' -Method GET -Headers $Headers + $UserAgent = Get-CippUserAgent + $TicketTypeRecord = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/tickettype/$TicketType" -ContentType 'application/json' -Method GET -Headers $Headers # Halo's /tickettype/{id} response uses different field names for the linked SLA across # versions. Check the known variants in order and take the first usable match. Halo uses diff --git a/Modules/CippExtensions/Public/Halo/Get-HaloToken.ps1 b/Modules/CippExtensions/Public/Halo/Get-HaloToken.ps1 index 6ca2edaeefb70..311ada8742ba0 100644 --- a/Modules/CippExtensions/Public/Halo/Get-HaloToken.ps1 +++ b/Modules/CippExtensions/Public/Halo/Get-HaloToken.ps1 @@ -13,7 +13,8 @@ function Get-HaloToken { scope = 'all' } if ($Configuration.Tenant -ne 'None') { $Tenant = "?tenant=$($Configuration.Tenant)" } - $token = Invoke-RestMethod -Uri "$($Configuration.AuthURL)/token$Tenant" -Method Post -Body $body -ContentType 'application/x-www-form-urlencoded' + $UserAgent = Get-CippUserAgent + $token = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.AuthURL)/token$Tenant" -Method Post -Body $body -ContentType 'application/x-www-form-urlencoded' return $token } else { throw 'No Halo configuration' diff --git a/Modules/CippExtensions/Public/Halo/Get-HaloUser.ps1 b/Modules/CippExtensions/Public/Halo/Get-HaloUser.ps1 index cc2df9f62cb99..119dbe6d235a5 100644 --- a/Modules/CippExtensions/Public/Halo/Get-HaloUser.ps1 +++ b/Modules/CippExtensions/Public/Halo/Get-HaloUser.ps1 @@ -34,6 +34,7 @@ function Get-HaloUser { ) $Headers = @{ Authorization = "Bearer $($Token.access_token)" } + $UserAgent = Get-CippUserAgent $BaseUri = "$($Configuration.ResourceURL)/Users?client_id=$ClientId&includeinactive=false&pageinate=false" $BuildResult = { @@ -58,7 +59,7 @@ function Get-HaloUser { filter_value = $FilterValue }) $EncodedFilter = [System.Uri]::EscapeDataString($Filter) - $Response = Invoke-RestMethod -Uri "$BaseUri&advanced_search=$EncodedFilter" -ContentType 'application/json' -Method GET -Headers $Headers + $Response = Invoke-RestMethod -UserAgent $UserAgent -Uri "$BaseUri&advanced_search=$EncodedFilter" -ContentType 'application/json' -Method GET -Headers $Headers if ($Response.users) { return $Response.users } return $Response } catch { @@ -77,7 +78,7 @@ function Get-HaloUser { param($Term) try { $EncodedTerm = [System.Uri]::EscapeDataString($Term) - $Response = Invoke-RestMethod -Uri "$BaseUri&search=$EncodedTerm" -ContentType 'application/json' -Method GET -Headers $Headers + $Response = Invoke-RestMethod -UserAgent $UserAgent -Uri "$BaseUri&search=$EncodedTerm" -ContentType 'application/json' -Method GET -Headers $Headers if ($Response.users) { return $Response.users } return $Response } catch { diff --git a/Modules/CippExtensions/Public/Halo/Invoke-HaloAutoMap.ps1 b/Modules/CippExtensions/Public/Halo/Invoke-HaloAutoMap.ps1 index 96056480149ed..b4e7bb662968c 100644 --- a/Modules/CippExtensions/Public/Halo/Invoke-HaloAutoMap.ps1 +++ b/Modules/CippExtensions/Public/Halo/Invoke-HaloAutoMap.ps1 @@ -29,11 +29,12 @@ function Invoke-HaloAutoMap { $GuidRegex = '^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$' $Headers = @{Authorization = "Bearer $($Token.access_token)" } + $UserAgent = Get-CippUserAgent # type=2 connections are Halo's customer-tenant (Microsoft 365) integrations; the # connection detail carries the client <-> Azure tenant ID mapping table. try { - $ConnectionsResponse = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/AzureADConnection?type=2" -Method GET -ContentType 'application/json' -Headers $Headers + $ConnectionsResponse = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/AzureADConnection?type=2" -Method GET -ContentType 'application/json' -Headers $Headers $Connections = if ($ConnectionsResponse -is [array]) { $ConnectionsResponse } elseif ($ConnectionsResponse.id) { @@ -43,7 +44,7 @@ function Invoke-HaloAutoMap { } $HaloTenantMappings = foreach ($Connection in $Connections) { - $Detail = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/AzureADConnection/$($Connection.id)?type=2&includedetails=true&includetenants=true" -Method GET -ContentType 'application/json' -Headers $Headers + $Detail = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/AzureADConnection/$($Connection.id)?type=2&includedetails=true&includetenants=true" -Method GET -ContentType 'application/json' -Headers $Headers $Detail.mappings_client | Where-Object { $_.azure_tenant_id -match $GuidRegex -and $_.client_id } } } catch { diff --git a/Modules/CippExtensions/Public/Halo/New-HaloPSATicket.ps1 b/Modules/CippExtensions/Public/Halo/New-HaloPSATicket.ps1 index 21b79d3fd87cf..f8bdc32b7a71e 100644 --- a/Modules/CippExtensions/Public/Halo/New-HaloPSATicket.ps1 +++ b/Modules/CippExtensions/Public/Halo/New-HaloPSATicket.ps1 @@ -18,6 +18,7 @@ function New-HaloPSATicket { $Configuration = ((Get-CIPPAzDataTableEntity @Table).config | ConvertFrom-Json).HaloPSA $TicketTable = Get-CIPPTable -TableName 'PSATickets' $token = Get-HaloToken -configuration $Configuration + $UserAgent = Get-CippUserAgent # Resolve affected user to a HaloPSA contact when the integration is configured for it. # Unmatched users fall through to userlookup.id = -1 (the client's General User contact). @@ -62,7 +63,7 @@ function New-HaloPSATicket { } if ($TargetTicketId) { - $Ticket = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/Tickets/$($TargetTicketId)?includedetails=true&includelastaction=false&nocache=undefined&includeusersassets=false&isdetailscreen=true" -ContentType 'application/json; charset=utf-8' -Method Get -Headers @{Authorization = "Bearer $($token.access_token)" } -SkipHttpErrorCheck + $Ticket = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/Tickets/$($TargetTicketId)?includedetails=true&includelastaction=false&nocache=undefined&includeusersassets=false&isdetailscreen=true" -ContentType 'application/json; charset=utf-8' -Method Get -Headers @{Authorization = "Bearer $($token.access_token)" } -SkipHttpErrorCheck if ($Ticket.id) { if (!$Ticket.hasbeenclosed) { Write-Information 'Ticket is still open, adding new note' @@ -87,7 +88,7 @@ function New-HaloPSATicket { $NoteAdded = $false try { if ($PSCmdlet.ShouldProcess('Add note to HaloPSA ticket', 'Add note')) { - $Action = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/actions" -ContentType 'application/json; charset=utf-8' -Method Post -Body $body -Headers @{Authorization = "Bearer $($token.access_token)" } + $Action = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/actions" -ContentType 'application/json; charset=utf-8' -Method Post -Body $body -Headers @{Authorization = "Bearer $($token.access_token)" } Write-Information "Note added to ticket in HaloPSA: $TargetTicketId" $NoteAdded = $true } @@ -228,7 +229,7 @@ function New-HaloPSATicket { Write-Information $body try { if ($PSCmdlet.ShouldProcess('Send ticket to HaloPSA', 'Create ticket')) { - $Ticket = Invoke-RestMethod -Uri "$($Configuration.ResourceURL)/Tickets" -ContentType 'application/json; charset=utf-8' -Method Post -Body $body -Headers @{Authorization = "Bearer $($token.access_token)" } + $Ticket = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/Tickets" -ContentType 'application/json; charset=utf-8' -Method Post -Body $body -Headers @{Authorization = "Bearer $($token.access_token)" } Write-Information "Ticket created in HaloPSA: $($Ticket.id)" if ($Configuration.ConsolidateTickets) { diff --git a/Tests/Extensions/New-HaloPSATicket.Priority.Tests.ps1 b/Tests/Extensions/New-HaloPSATicket.Priority.Tests.ps1 index 9e1b859ecb9c1..c3329dc8438be 100644 --- a/Tests/Extensions/New-HaloPSATicket.Priority.Tests.ps1 +++ b/Tests/Extensions/New-HaloPSATicket.Priority.Tests.ps1 @@ -5,6 +5,7 @@ BeforeAll { function Get-CIPPAzDataTableEntity { param($Filter, $Property) } function Add-CIPPAzDataTableEntity { param($Entity, [switch]$Force) } function Get-HaloToken { param($configuration) } + function Get-CippUserAgent { 'CIPP/test' } function Get-HaloTicketTypeSlaId { param($TicketType, $Configuration, $Token) } function Get-HaloUser { param($AzureOID, $Email, $ClientId, $Configuration, $Token) } function Get-StringHash { param($String) } diff --git a/Tests/Extensions/New-HaloPSATicket.Tests.ps1 b/Tests/Extensions/New-HaloPSATicket.Tests.ps1 index 089917cd505d9..8c412b4240a7a 100644 --- a/Tests/Extensions/New-HaloPSATicket.Tests.ps1 +++ b/Tests/Extensions/New-HaloPSATicket.Tests.ps1 @@ -14,6 +14,7 @@ BeforeAll { function Get-CIPPAzDataTableEntity { param($TableName, $Filter, $Property, $First) } function Add-CIPPAzDataTableEntity { param($TableName, $Entity, [switch]$Force) } function Get-HaloToken { param($configuration) } + function Get-CippUserAgent { 'CIPP/test' } function Get-HaloUser { param($AzureOID, $Email, $ClientId, $Configuration, $Token) } function Get-StringHash { param($String) } function Get-NormalizedError { param($Message) } diff --git a/Tests/Extensions/New-HaloPSATicket.TicketTarget.Tests.ps1 b/Tests/Extensions/New-HaloPSATicket.TicketTarget.Tests.ps1 index ccd844a9304be..7667dd3c9e495 100644 --- a/Tests/Extensions/New-HaloPSATicket.TicketTarget.Tests.ps1 +++ b/Tests/Extensions/New-HaloPSATicket.TicketTarget.Tests.ps1 @@ -13,6 +13,7 @@ BeforeAll { function Get-CIPPAzDataTableEntity { param($TableName, $Filter, $Property, $First) } function Add-CIPPAzDataTableEntity { param($TableName, $Entity, [switch]$Force) } function Get-HaloToken { param($configuration) } + function Get-CippUserAgent { 'CIPP/test' } function Get-HaloUser { param($AzureOID, $Email, $ClientId, $Configuration, $Token) } function Get-StringHash { param($String) } function Get-NormalizedError { param($Message) } diff --git a/Tests/GraphHelper/New-CIPPMFAConnectorToken.Tests.ps1 b/Tests/GraphHelper/New-CIPPMFAConnectorToken.Tests.ps1 index bcb4237ecb99d..e34ac330e0f7a 100644 --- a/Tests/GraphHelper/New-CIPPMFAConnectorToken.Tests.ps1 +++ b/Tests/GraphHelper/New-CIPPMFAConnectorToken.Tests.ps1 @@ -12,6 +12,8 @@ BeforeAll { function Get-CIPPAzDataTableEntity { param($Filter) } function Add-CIPPAzDataTableEntity { param($Entity, [switch]$Force) } function Get-Tenants { param($TenantFilter) } + function Get-CippKeyVaultSecret { param($Name, [switch]$AsPlainText) } + function Set-CippKeyVaultSecret { param($Name, $SecretValue) } . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/GraphHelper/New-CIPPMFAConnectorToken.ps1') @@ -61,3 +63,50 @@ Describe 'New-CIPPMFAConnectorToken secret caching' { Should -Invoke Add-CIPPAzDataTableEntity -Times 1 -Exactly } } + +Describe 'New-CIPPMFAConnectorToken Key Vault (production) storage path' { + BeforeEach { + # Production path: no dev-storage markers, so the secret is read from and written to Key Vault. + $script:SavedStorage = [Environment]::GetEnvironmentVariable('AzureWebJobsStorage') + Remove-Item env:AzureWebJobsStorage -ErrorAction SilentlyContinue + Remove-Item env:NonLocalHostAzurite -ErrorAction SilentlyContinue + Mock Set-CippKeyVaultSecret {} + Mock Update-AppManagementPolicy {} + Mock Invoke-RestMethod { [pscustomobject]@{ access_token = 'TOKEN123' } } + Mock New-GraphGetRequest { @([pscustomobject]@{ id = 'mfa-sp-id'; appId = $script:MFAAppID }) } + Mock New-GraphPostRequest { [pscustomobject]@{ secretText = 'NEWSECRET' } } + } + + AfterEach { + if ($null -ne $script:SavedStorage) { $env:AzureWebJobsStorage = $script:SavedStorage } + } + + It 'provisions when Key Vault has no cached secret yet (404) instead of failing' { + # The Key Vault helper throws on a missing secret rather than returning nothing; the first call for a + # tenant must treat that as a cache miss and provision, not surface the 404 to the user. + Mock Get-CippKeyVaultSecret { throw "Failed to retrieve secret 'NPS-x' from vault 'cippx': Response status code does not indicate success: 404" } + + $result = New-CIPPMFAConnectorToken -TenantFilter $script:TenantGuid + + $result.AccessToken | Should -Be 'TOKEN123' + Should -Invoke New-GraphPostRequest -Times 1 -Exactly + Should -Invoke Set-CippKeyVaultSecret -Times 1 -Exactly + } + + It 'reuses a cached Key Vault secret without provisioning' { + Mock Get-CippKeyVaultSecret { 'CACHEDSECRET' } + + $result = New-CIPPMFAConnectorToken -TenantFilter $script:TenantGuid + + $result.AccessToken | Should -Be 'TOKEN123' + Should -Not -Invoke New-GraphPostRequest + Should -Not -Invoke Set-CippKeyVaultSecret + } + + It 'surfaces a non-404 Key Vault failure rather than silently reprovisioning' { + Mock Get-CippKeyVaultSecret { throw "Failed to retrieve secret 'NPS-x' from vault 'cippx': Response status code does not indicate success: 403" } + + { New-CIPPMFAConnectorToken -TenantFilter $script:TenantGuid } | Should -Throw -ExpectedMessage '*403*' + Should -Not -Invoke New-GraphPostRequest + } +} diff --git a/version_latest.txt b/version_latest.txt index 4843a6d662fa9..b4ebbcb7157d2 100644 --- a/version_latest.txt +++ b/version_latest.txt @@ -1 +1 @@ -10.10.0 \ No newline at end of file +10.10.1 \ No newline at end of file From 0933a3c3a42d81c6f5a79e3b903e8e90fef31288 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Fri, 11 Sep 2026 18:57:39 +0000 Subject: [PATCH 3/4] Merge pull request #582 from CyberDrain/dev Synced from CyberDrain/CIPP@ad6ed320abf3e882fa2420b8e1b477365a6304d4 --- .../Entra (AAD) Standards/DisableGuests.json | 27 +- .../DisableSelfServiceLicenses.json | 4 +- Config/CIPPTimers.json | 9 + Config/PermissionsTranslator.json | 6110 +++++++++-------- Config/SAMManifest.json | 4 + Config/intuneCategories.json | 2 +- Config/intuneCollection.json | 2 +- Config/openapi.json | 270 +- Config/standards.json | 22 +- .../Push-ExecScheduledCommand.ps1 | 24 +- .../Push-StoreSharePointPermissions.ps1 | 191 +- .../Get-CIPPAlertUserReportedPhishing.ps1 | 8 +- .../Alerts/Get-CIPPAlertVulnerabilities.ps1 | 10 +- Modules/CIPPCore/CIPPCore.psm1 | 21 +- .../Authentication/Find-CippBaseRole.ps1 | 22 + .../Get-CippRequestIPAddress.ps1 | 12 + .../Authentication/New-CippMeResponse.ps1 | 160 + .../Public/Authentication/New-CIPPSSOApp.ps1 | 3 +- .../Public/Authentication/Test-CIPPAccess.ps1 | 179 +- .../Test-CippRoleTenantScope.ps1 | 33 +- .../Update-CIPPSSOPreconsent.ps1 | 4 +- .../Update-CIPPSSORedirectUri.ps1 | 61 +- .../Get-CIPPBaselineDisableGuestsState.ps1 | 45 +- ...aselineDisableSelfServiceLicensesState.ps1 | 4 +- ...CIPPBaselineDisableSelfServiceLicenses.ps1 | 2 +- .../Start-DomainOrchestrator.ps1 | 64 +- .../Start-InstanceHealthSample.ps1 | 123 + .../Timer Functions/Start-TableCleanup.ps1 | 12 + .../Public/Functions/Get-CIPPEgressLedger.ps1 | 44 + .../Get-CIPPInstanceHealthSample.ps1 | 119 + .../Public/Functions/Test-CIPPStalledRun.ps1 | 32 + .../Write-CIPPInstanceBootMarker.ps1 | 55 + .../Get-CIPPCAPolicyIdentityCoverage.ps1 | 604 ++ .../Get-CIPPIntuneCompareExclusions.ps1 | 1 + .../GraphHelper/New-GraphGetRequest.ps1 | 5 +- .../GraphHelper/New-GraphPOSTRequest.ps1 | 5 +- .../GraphRequests/Get-GraphRequestList.ps1 | 7 + .../MCP/ConvertTo-CippMcpArgumentShape.ps1 | 73 + .../Public/MCP/Get-CippMcpToolResult.ps1 | 4 +- .../Public/MCP/Invoke-CippMcpApiRequest.ps1 | 15 +- .../Public/New-CIPPIntuneTemplate.ps1 | 7 + .../Public/PIM/Get-CIPPPIMRoleAssignments.ps1 | 4 + .../Select-CIPPIntuneAvailableSetting.ps1 | 34 +- .../CIPPCore/Public/Set-CIPPIntunePolicy.ps1 | 28 +- ...CIPPDBCacheSelfServicePurchaseProducts.ps1 | 11 +- .../Set-CIPPDBCacheSharePointPermissions.ps1 | 5 + .../CIPP/Settings/Invoke-ExecAccessChecks.ps1 | 19 +- .../Invoke-ListInstanceDiagnostics.ps1 | 393 ++ .../CIPP/Setup/Invoke-ExecTokenExchange.ps1 | 9 +- .../Tools/Invoke-ListExoRequest.ps1 | 6 +- .../Roles/Invoke-ListPIMRoles.ps1 | 2 + .../Administration/Users/Invoke-AddUser.ps1 | 15 + .../Users/Invoke-AddUserBulk.ps1 | 15 + .../Invoke-ListAzureADConnectStatus.ps1 | 12 +- .../Identity/Reports/Invoke-ListSignIns.ps1 | 8 +- .../Invoke-ListSharepointQuota.ps1 | 8 +- .../Invoke-ListCAPolicyCoverage.ps1 | 44 + .../Standards/Invoke-ExecDomainAnalyser.ps1 | 4 +- .../Tests/Invoke-ListTestResultsTenants.ps1 | 11 + .../Invoke-CIPPStandardDisableGuests.ps1 | 205 +- ...CIPPStandardDisableSelfServiceLicenses.ps1 | 32 +- .../CIS/Identity/Invoke-CippTestCIS_2_1_7.ps1 | 5 + .../Identity/Invoke-CippTestCISAMSEXO102.md | 11 +- .../Identity/Invoke-CippTestCISAMSEXO102.ps1 | 8 +- .../ORCA/Identity/Invoke-CippTestORCA105.ps1 | 6 +- .../ORCA/Identity/Invoke-CippTestORCA113.ps1 | 6 +- .../ORCA/Identity/Invoke-CippTestORCA124.ps1 | 6 +- .../ORCA/Identity/Invoke-CippTestORCA156.ps1 | 6 +- .../ORCA/Identity/Invoke-CippTestORCA158.ps1 | 6 +- .../ORCA/Identity/Invoke-CippTestORCA179.ps1 | 6 +- .../ORCA/Identity/Invoke-CippTestORCA225.ps1 | 6 +- .../ORCA/Identity/Invoke-CippTestORCA226.ps1 | 6 +- .../ORCA/Identity/Invoke-CippTestORCA227.ps1 | 6 +- .../ORCA/Identity/Invoke-CippTestORCA234.ps1 | 6 +- .../ORCA/Identity/Invoke-CippTestORCA236.ps1 | 6 +- .../ORCA/Identity/Invoke-CippTestORCA237.ps1 | 6 +- .../ORCA/Identity/Invoke-CippTestORCA238.ps1 | 6 +- .../Public/Halo/Get-HaloTicketType.ps1 | 6 +- ...et-CIPPAlertUserReportedPhishing.Tests.ps1 | 91 + .../Baselines/BaselineDisableGuests.Tests.ps1 | 74 +- .../Baselines/BaselineEntraHeavies.Tests.ps1 | 2 +- .../Push-StoreSharePointPermissions.Tests.ps1 | 187 + .../Invoke-ExecTokenExchange.Tests.ps1 | 107 + ...ListInstanceDiagnostics.Timeline.Tests.ps1 | 81 + Tests/Extensions/Get-HaloTicketType.Tests.ps1 | 26 + Tests/Mcp/Invoke-CippMcpApiRequest.Tests.ps1 | 84 +- ...Get-CIPPCAPolicyIdentityCoverage.Tests.ps1 | 565 ++ Tests/Private/Get-CIPPEgressLedger.Tests.ps1 | 34 + .../Get-CIPPInstanceHealthSample.Tests.ps1 | 151 + .../Get-CippRequestIPAddress.Tests.ps1 | 40 + ...elect-CIPPIntuneAvailableSetting.Tests.ps1 | 125 + .../Set-CIPPIntunePolicy.Enrollment.Tests.ps1 | 126 + ...Test-CIPPAccess.BlockedEndpoints.Tests.ps1 | 3 + Tests/Private/Test-CIPPAccess.Core.Tests.ps1 | 654 ++ .../Test-CIPPAccess.TenantGroupAuth.Tests.ps1 | 3 + Tests/Private/Test-CIPPStalledRun.Tests.ps1 | 52 + .../Update-CIPPSSOPreconsent.Tests.ps1 | 6 +- .../Update-CIPPSSORedirectUri.Tests.ps1 | 135 + ...Invoke-CIPPStandardDisableGuests.Tests.ps1 | 125 +- version_latest.txt | 2 +- 100 files changed, 8565 insertions(+), 3480 deletions(-) create mode 100644 Modules/CIPPCore/Private/Authentication/Find-CippBaseRole.ps1 create mode 100644 Modules/CIPPCore/Private/Authentication/Get-CippRequestIPAddress.ps1 create mode 100644 Modules/CIPPCore/Private/Authentication/New-CippMeResponse.ps1 create mode 100644 Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-InstanceHealthSample.ps1 create mode 100644 Modules/CIPPCore/Public/Functions/Get-CIPPEgressLedger.ps1 create mode 100644 Modules/CIPPCore/Public/Functions/Get-CIPPInstanceHealthSample.ps1 create mode 100644 Modules/CIPPCore/Public/Functions/Test-CIPPStalledRun.ps1 create mode 100644 Modules/CIPPCore/Public/Functions/Write-CIPPInstanceBootMarker.ps1 create mode 100644 Modules/CIPPCore/Public/Get-CIPPCAPolicyIdentityCoverage.ps1 create mode 100644 Modules/CIPPCore/Public/MCP/ConvertTo-CippMcpArgumentShape.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListInstanceDiagnostics.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ListCAPolicyCoverage.ps1 create mode 100644 Tests/Alerts/Get-CIPPAlertUserReportedPhishing.Tests.ps1 create mode 100644 Tests/DBCache/Push-StoreSharePointPermissions.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-ExecTokenExchange.Tests.ps1 create mode 100644 Tests/Endpoint/Invoke-ListInstanceDiagnostics.Timeline.Tests.ps1 create mode 100644 Tests/Extensions/Get-HaloTicketType.Tests.ps1 create mode 100644 Tests/Private/Get-CIPPCAPolicyIdentityCoverage.Tests.ps1 create mode 100644 Tests/Private/Get-CIPPEgressLedger.Tests.ps1 create mode 100644 Tests/Private/Get-CIPPInstanceHealthSample.Tests.ps1 create mode 100644 Tests/Private/Get-CippRequestIPAddress.Tests.ps1 create mode 100644 Tests/Private/Select-CIPPIntuneAvailableSetting.Tests.ps1 create mode 100644 Tests/Private/Set-CIPPIntunePolicy.Enrollment.Tests.ps1 create mode 100644 Tests/Private/Test-CIPPAccess.Core.Tests.ps1 create mode 100644 Tests/Private/Test-CIPPStalledRun.Tests.ps1 create mode 100644 Tests/Private/Update-CIPPSSORedirectUri.Tests.ps1 diff --git a/Config/BaselineStandards/Entra (AAD) Standards/DisableGuests.json b/Config/BaselineStandards/Entra (AAD) Standards/DisableGuests.json index 8af928e5ab5f5..1c2bef28ea966 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/DisableGuests.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/DisableGuests.json @@ -5,11 +5,11 @@ "tag": [ "SMB1001 (2.8)" ], - "impact": "Medium Impact", - "helpText": "Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone.", - "executiveText": "Automatically disables external guest accounts that haven't been used for a number of days, reducing security risks from dormant accounts while maintaining access for active external collaborators. This helps maintain a clean user directory and reduces potential attack vectors.", - "docsDescription": "Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled.", - "impactColour": "warning", + "impact": "High Impact", + "helpText": "Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Optionally soft-deletes already-disabled guests after a configurable grace period past that threshold (0 = never delete). Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone. Deleted guests remain recoverable from Deleted Items for about 30 days.", + "executiveText": "Automatically disables external guest accounts that haven't been used for a number of days, and can optionally remove already-disabled dormant guests after an additional grace period. This reduces security risks from abandoned external access, keeps the directory clean, and avoids errors when previously disabled guests need to be invited back.", + "docsDescription": "Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Remediation first disables stale enabled guests, and later soft-deletes guests that are already disabled once they have been inactive for the disable threshold plus the configured grace delta (deletion age = days + deleteGraceDays). The disable-before-delete grace is further guaranteed by never deleting a guest in the same pass it was disabled. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone. Graph user DELETE is a soft-delete (recoverable from Deleted Items for about 30 days).", + "impactColour": "danger", "addedDate": "2022-10-20", "powershellEquivalent": "Graph API", "appliesToTest": [ @@ -33,6 +33,17 @@ "required": true, "default": 90 }, + "deleteGraceDays": { + "type": "number", + "label": "Grace days after disable before deletion (0 = never delete). Guests are deleted once inactive for the disable threshold plus this many additional days.", + "default": 0, + "validators": { + "min": { + "value": 0, + "message": "Minimum value is 0" + } + } + }, "IncludeNeverSignedIn": { "type": "switch", "label": "Disable accounts that have not yet signed in", @@ -54,11 +65,17 @@ ], "writes": [ { + "from": "guestsToDisable", "method": "PATCH", "uri": "users/%id%", "body": { "accountEnabled": false } + }, + { + "from": "guestsToDelete", + "method": "DELETE", + "uri": "users/%id%" } ] } diff --git a/Config/BaselineStandards/Entra (AAD) Standards/DisableSelfServiceLicenses.json b/Config/BaselineStandards/Entra (AAD) Standards/DisableSelfServiceLicenses.json index 21f7901a1b460..f455425dff757 100644 --- a/Config/BaselineStandards/Entra (AAD) Standards/DisableSelfServiceLicenses.json +++ b/Config/BaselineStandards/Entra (AAD) Standards/DisableSelfServiceLicenses.json @@ -6,10 +6,10 @@ "impact": "Medium Impact", "helpText": "Disables self-service purchasing for every product (with optional product-id exclusions), email-based subscription signup, and optionally trial autoclaim.", "executiveText": "Stops employees buying Microsoft licenses on personal cards outside procurement - keeping licensing centralized, supported and cost-controlled.", - "docsDescription": "Grades every self-service purchasable product against Disabled (excluded product ids stay Enabled), email-based subscription signup against off, and - when trials are disabled - the autoclaim policy. Requires the Billing Administrator GDAP role to read the product list. Remediation writes each drifted product on its own endpoint.", + "docsDescription": "Grades every self-service purchasable product against Disabled (excluded product ids stay Enabled), email-based subscription signup against off, and - when trials are disabled - the autoclaim policy. Remediation writes each drifted product on its own endpoint.", "impactColour": "warning", "addedDate": "2026-08-16", - "powershellEquivalent": "MSCommerce / licensing.m365.microsoft.com policy API", + "powershellEquivalent": "Update-MSCommerceProductPolicy -PolicyId AllowSelfServicePurchase -Value Disabled", "recommendedBy": [], "requiredCapabilities": [], "disabledFeatures": { diff --git a/Config/CIPPTimers.json b/Config/CIPPTimers.json index 56d42c3e97375..48bbfec9312bb 100644 --- a/Config/CIPPTimers.json +++ b/Config/CIPPTimers.json @@ -284,5 +284,14 @@ "RunOnProcessor": true, "TZOffset": true, "PreferredProcessor": "standards" + }, + { + "Id": "3f7a1c92-58d4-4e0b-9a13-6c2b8d45e7f1", + "Command": "Start-InstanceHealthSample", + "Description": "Sample container log health into the InstanceHealth table", + "Cron": "0 */5 * * * *", + "Priority": 0, + "RunOnProcessor": true, + "IsSystem": true } ] diff --git a/Config/PermissionsTranslator.json b/Config/PermissionsTranslator.json index 5e6ce04fe8aaf..74cc01fc96763 100644 --- a/Config/PermissionsTranslator.json +++ b/Config/PermissionsTranslator.json @@ -6,6 +6,34 @@ "origin": "Delegated (1ES Resource Management PPE)", "value": "manage_ado_pools" }, + { + "description": "Allows the application to edit or delete documents and list items in all site collections on behalf of the signed-in user.", + "displayName": "Edit or delete items in all site collections", + "id": "89fe6a52-be36-487e-b7d8-d061c450a026", + "origin": "Delegated (Microsoft Graph)", + "value": "Sites.ReadWrite.All" + }, + { + "description": "Allow the application to access a subset of site collections on behalf of the signed-in user. The specific site collections and the permissions granted will be configured in SharePoint Online.", + "displayName": "Access selected Sites, on behalf of the signed-in user", + "id": "f89c84ef-20d0-4b54-87e9-02e856d66d53", + "origin": "Delegated (Microsoft Graph)", + "value": "Sites.Selected" + }, + { + "description": "Allows the app to be able to send emails from the user’s mailbox using the SMTP AUTH client submission protocol.", + "displayName": "Send emails from mailboxes using SMTP AUTH.", + "id": "258f6531-6087-4cc4-bb90-092c5fb3ed3f", + "origin": "Delegated (Microsoft Graph)", + "value": "SMTP.Send" + }, + { + "description": "Allows the app to read your organization's SPIFFE trust domains and child resources on behalf of the user.", + "displayName": "Read SPIFFE trust domains and child resources", + "id": "9b4aa4b1-aaf3-41b7-b743-698b27e77ff6", + "origin": "Delegated (Microsoft Graph)", + "value": "SpiffeTrustDomain.Read.All" + }, { "description": "Allows the app to read and write your organization's SPIFFE trust domains and child resources on behalf of the user.", "displayName": "Read and write SPIFFE trust domains and child resources", @@ -97,6 +125,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "Tasks.ReadWrite.Shared" }, + { + "description": "Allows the application to read documents and list items in all site collections on behalf of the signed-in user", + "displayName": "Read items in all site collections", + "id": "205e70e5-aba6-4c52-a976-6d2d46c48043", + "origin": "Delegated (Microsoft Graph)", + "value": "Sites.Read.All" + }, { "description": "Allows the app to create teams on behalf of the signed-in user.", "displayName": "Create teams", @@ -105,53 +140,46 @@ "value": "Team.Create" }, { - "description": "Read the names and descriptions of teams, on behalf of the signed-in user.", - "displayName": "Read the names and descriptions of teams", - "id": "485be79e-c497-4b35-9400-0e3fa7f2a5d4", - "origin": "Delegated (Microsoft Graph)", - "value": "Team.ReadBasic.All" - }, - { - "description": "Read the members of teams, on behalf of the signed-in user.", - "displayName": "Read the members of teams", - "id": "2497278c-d82d-46a2-b1ce-39d4cdde5570", + "description": "Allows the application to create or delete document libraries and lists in all site collections on behalf of the signed-in user.", + "displayName": "Create, edit, and delete items and lists in all site collections", + "id": "65e50fdc-43b7-4915-933e-e8138f11f40a", "origin": "Delegated (Microsoft Graph)", - "value": "TeamMember.Read.All" + "value": "Sites.Manage.All" }, { - "description": "Add and remove members from teams, on behalf of the signed-in user. Also allows changing a member's role, for example from owner to non-owner.", - "displayName": "Add and remove members from teams", - "id": "4a06efd2-f825-4e34-813e-82a57b03d1ee", + "description": "Allow the application to create site collections on behalf of the signed in user. Upon creation the application will be granted Sites.Selected(delegated) + FullControl to the newly created site.", + "displayName": "Create Site Collections, on behalf of the signed-in user", + "id": "0e2e68e1-3f32-4e10-9281-f749e097fcbe", "origin": "Delegated (Microsoft Graph)", - "value": "TeamMember.ReadWrite.All" + "value": "Sites.Create.All" }, { - "description": "Allows the app to read your organization's SPIFFE trust domains and child resources on behalf of the user.", - "displayName": "Read SPIFFE trust domains and child resources", - "id": "9b4aa4b1-aaf3-41b7-b743-698b27e77ff6", + "description": "Allows the app to read all Exchange service activity, on behalf of the signed-in user.", + "displayName": "Read all Exchange service activity", + "id": "1fe7aa48-9373-4a47-8df3-168335e0f4c9", "origin": "Delegated (Microsoft Graph)", - "value": "SpiffeTrustDomain.Read.All" + "value": "ServiceActivity-Exchange.Read.All" }, { - "description": "Add and remove members from all teams, on behalf of the signed-in user. Does not allow adding or removing a member with the owner role. Additionally, does not allow the app to elevate an existing member to the owner role.", - "displayName": "Add and remove members with non-owner role for all teams", - "id": "2104a4db-3a2f-4ea0-9dba-143d457dc666", + "description": "Allows the app to read all Microsoft 365 Web service activity, on behalf of the signed-in user.", + "displayName": "Read all Microsoft 365 Web service activity", + "id": "d74c75b1-d5a9-479d-902d-92f8f99182c1", "origin": "Delegated (Microsoft Graph)", - "value": "TeamMember.ReadWriteNonOwnerRole.All" + "value": "ServiceActivity-Microsoft365Web.Read.All" }, { - "description": "Allows the app to be able to send emails from the user’s mailbox using the SMTP AUTH client submission protocol.", - "displayName": "Send emails from mailboxes using SMTP AUTH.", - "id": "258f6531-6087-4cc4-bb90-092c5fb3ed3f", + "description": "Allows the app to read all One Drive service activity, on behalf of the signed-in user.", + "displayName": "Read all One Drive service activity", + "id": "347e3c16-30f3-4ac7-9b52-fc3c053de9c9", "origin": "Delegated (Microsoft Graph)", - "value": "SMTP.Send" + "value": "ServiceActivity-OneDrive.Read.All" }, { - "description": "Allows the application to edit or delete documents and list items in all site collections on behalf of the signed-in user.", - "displayName": "Edit or delete items in all site collections", - "id": "89fe6a52-be36-487e-b7d8-d061c450a026", + "description": "Allows the app to read all Teams service activity, on behalf of the signed-in user.", + "displayName": "Read all Teams service activity", + "id": "404d76f0-e10e-460a-92be-ef19600c54d1", "origin": "Delegated (Microsoft Graph)", - "value": "Sites.ReadWrite.All" + "value": "ServiceActivity-Teams.Read.All" }, { "description": "Allows the app to read your tenant's service health information on behalf of the signed-in user. Health information may include service issues or service health overviews.", @@ -244,13 +272,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "SignInIdentifier.ReadWrite.All" }, - { - "description": "Allow the application to create site collections on behalf of the signed in user. Upon creation the application will be granted Sites.Selected(delegated) + FullControl to the newly created site.", - "displayName": "Create Site Collections, on behalf of the signed-in user", - "id": "0e2e68e1-3f32-4e10-9281-f749e097fcbe", - "origin": "Delegated (Microsoft Graph)", - "value": "Sites.Create.All" - }, { "description": "Allows the application to have full control of all site collections on behalf of the signed-in user.", "displayName": "Have full control of all site collections", @@ -259,46 +280,46 @@ "value": "Sites.FullControl.All" }, { - "description": "Allows the application to create or delete document libraries and lists in all site collections on behalf of the signed-in user.", - "displayName": "Create, edit, and delete items and lists in all site collections", - "id": "65e50fdc-43b7-4915-933e-e8138f11f40a", + "description": "Read the names and descriptions of teams, on behalf of the signed-in user.", + "displayName": "Read the names and descriptions of teams", + "id": "485be79e-c497-4b35-9400-0e3fa7f2a5d4", "origin": "Delegated (Microsoft Graph)", - "value": "Sites.Manage.All" + "value": "Team.ReadBasic.All" }, { - "description": "Allows the application to read documents and list items in all site collections on behalf of the signed-in user", - "displayName": "Read items in all site collections", - "id": "205e70e5-aba6-4c52-a976-6d2d46c48043", + "description": "Read the members of teams, on behalf of the signed-in user.", + "displayName": "Read the members of teams", + "id": "2497278c-d82d-46a2-b1ce-39d4cdde5570", "origin": "Delegated (Microsoft Graph)", - "value": "Sites.Read.All" + "value": "TeamMember.Read.All" }, { - "description": "Allow the application to access a subset of site collections on behalf of the signed-in user. The specific site collections and the permissions granted will be configured in SharePoint Online.", - "displayName": "Access selected Sites, on behalf of the signed-in user", - "id": "f89c84ef-20d0-4b54-87e9-02e856d66d53", + "description": "Add and remove members from teams, on behalf of the signed-in user. Also allows changing a member's role, for example from owner to non-owner.", + "displayName": "Add and remove members from teams", + "id": "4a06efd2-f825-4e34-813e-82a57b03d1ee", "origin": "Delegated (Microsoft Graph)", - "value": "Sites.Selected" + "value": "TeamMember.ReadWrite.All" }, { - "description": "Allows the app to read all Teams service activity, on behalf of the signed-in user.", - "displayName": "Read all Teams service activity", - "id": "404d76f0-e10e-460a-92be-ef19600c54d1", + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in teams the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Manage selected Teams apps installed in teams", + "id": "9131c833-9a49-4c54-b38f-615ecfc4fc69", "origin": "Delegated (Microsoft Graph)", - "value": "ServiceActivity-Teams.Read.All" + "value": "TeamsAppInstallation.ReadWriteSelectedForTeam" }, { - "description": "Allows the app to read the signed-in user's teamwork activity feed.", - "displayName": "Read user's teamwork activity feed", - "id": "0e755559-83fb-4b44-91d0-4cc721b9323e", + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps installed for the signed in user. Does not give the ability to read application-specific settings.", + "displayName": "Manage selected Teams apps installed for a user", + "id": "ea819e27-c92a-4118-b83b-4540b125d744", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsActivity.Read" + "value": "TeamsAppInstallation.ReadWriteSelectedForUser" }, { - "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in chats the signed-in user can access. Gives the ability to manage permission grants for accessing those specific chats' data.", - "displayName": "Manage installation and permission grants of selected Teams apps in chats", - "id": "d1ba22c6-3f02-4c91-addb-bc3399bcca88", + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in chats the signed-in user can access.", + "displayName": "Allow the Teams app to manage itself in chats", + "id": "0ce33576-30e8-43b7-99e5-62f8569a4002", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ManageSelectedForChat" + "value": "TeamsAppInstallation.ReadWriteSelfForChat" }, { "description": "Allows a Teams app to read, install, upgrade, and uninstall itself to teams the signed-in user can access.", @@ -399,32 +420,46 @@ "value": "TeamsTab.ReadWriteSelfForTeam" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for the signed-in user.", - "displayName": "Allow the Teams app to manage only its own tabs for a user", - "id": "395dfec1-a0b9-465f-a783-8250a430cb8c", + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in chats the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Manage selected Teams apps installed in chats", + "id": "690aa3b6-4b71-41c2-a990-77a8c4768d2b", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsTab.ReadWriteSelfForUser" + "value": "TeamsAppInstallation.ReadWriteSelectedForChat" }, { - "description": "Allows the app to read your tenant's acquired telephone number details on behalf of the signed-in admin user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", - "displayName": "Read Tenant-Acquired Telephone Number Details", - "id": "1bc6eab1-058d-4557-b011-d4c41cec88b7", + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps installed for the signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Manage user's installed Teams apps", + "id": "093f8818-d05f-49b8-95bc-9d2a73e9a43c", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsTelephoneNumber.Read.All" + "value": "TeamsAppInstallation.ReadWriteForUser" }, { - "description": "Allows the app to read and modify your tenant's acquired telephone number details on behalf of the signed-in admin user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", - "displayName": "Read and Modify Tenant-Acquired Telephone Number Details", - "id": "424b07a8-1209-4d17-9fe4-9018a93a1024", + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in teams the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Manage installed Teams apps in teams", + "id": "2e25a044-2580-450d-8859-42eeb6e996c0", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsTelephoneNumber.ReadWrite.All" + "value": "TeamsAppInstallation.ReadWriteForTeam" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in chats the signed-in user can access.", - "displayName": "Allow the Teams app to manage itself in chats", - "id": "0ce33576-30e8-43b7-99e5-62f8569a4002", + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in chats the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Manage installed Teams apps in chats", + "id": "aa85bf13-d771-4d5d-a9e6-bca04ce44edf", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteSelfForChat" + "value": "TeamsAppInstallation.ReadWriteForChat" + }, + { + "description": "Add and remove members from all teams, on behalf of the signed-in user. Does not allow adding or removing a member with the owner role. Additionally, does not allow the app to elevate an existing member to the owner role.", + "displayName": "Add and remove members with non-owner role for all teams", + "id": "2104a4db-3a2f-4ea0-9dba-143d457dc666", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamMember.ReadWriteNonOwnerRole.All" + }, + { + "description": "Allows the app to read the signed-in user's teamwork activity feed.", + "displayName": "Read user's teamwork activity feed", + "id": "0e755559-83fb-4b44-91d0-4cc721b9323e", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsActivity.Read" }, { "description": "Allows the app to create new notifications in users' teamwork activity feeds on behalf of the signed in user. These notifications may not be discoverable or be held or governed by compliance policies.", @@ -434,18 +469,11 @@ "value": "TeamsActivity.Send" }, { - "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps installed for the signed in user. Does not give the ability to read application-specific settings.", - "displayName": "Manage selected Teams apps installed for a user", - "id": "ea819e27-c92a-4118-b83b-4540b125d744", - "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteSelectedForUser" - }, - { - "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in chats the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Manage selected Teams apps installed in chats", - "id": "690aa3b6-4b71-41c2-a990-77a8c4768d2b", + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in chats the signed-in user can access. Gives the ability to manage permission grants for accessing those specific chats' data.", + "displayName": "Manage installation and permission grants of selected Teams apps in chats", + "id": "d1ba22c6-3f02-4c91-addb-bc3399bcca88", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteSelectedForChat" + "value": "TeamsAppInstallation.ManageSelectedForChat" }, { "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in teams the signed-in user can access. Gives the ability to manage permission grants for accessing those specific teams' data.", @@ -475,6 +503,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "TeamsAppInstallation.ReadForTeam" }, + { + "description": "Allows the app to export all Sentiment Survey, on behalf of the signed-in user.", + "displayName": "Export all Sentiment Survey", + "id": "df9fd94d-51ff-443d-8f31-ae4dc1b5b8d8", + "origin": "Delegated (Microsoft Graph)", + "value": "SentimentSurvey.Export.All" + }, { "description": "Allows the app to read the Teams apps that are installed for the signed-in user. Does not give the ability to read application-specific settings.", "displayName": "Read user's installed Teams apps", @@ -482,13 +517,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "TeamsAppInstallation.ReadForUser" }, - { - "description": "Allows the app to read the selected Teams apps that are installed in chats the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Read selected installed Teams apps in chats", - "id": "0f3420c2-c6ec-46de-ab72-fd51267087d5", - "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadSelectedForChat" - }, { "description": "Allows the app to read the selected Teams apps that are installed in teams the signed-in user can access. Does not give the ability to read application-specific settings.", "displayName": "Read selected installed Teams apps in teams", @@ -546,53 +574,60 @@ "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForUser" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in chats the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Manage installed Teams apps in chats", - "id": "aa85bf13-d771-4d5d-a9e6-bca04ce44edf", + "description": "Allows the app to read the selected Teams apps that are installed in chats the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Read selected installed Teams apps in chats", + "id": "0f3420c2-c6ec-46de-ab72-fd51267087d5", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteForChat" + "value": "TeamsAppInstallation.ReadSelectedForChat" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in teams the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Manage installed Teams apps in teams", - "id": "2e25a044-2580-450d-8859-42eeb6e996c0", + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for the signed-in user.", + "displayName": "Allow the Teams app to manage only its own tabs for a user", + "id": "395dfec1-a0b9-465f-a783-8250a430cb8c", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteForTeam" + "value": "TeamsTab.ReadWriteSelfForUser" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps installed for the signed-in user. Does not give the ability to read application-specific settings.", - "displayName": "Manage user's installed Teams apps", - "id": "093f8818-d05f-49b8-95bc-9d2a73e9a43c", + "description": "Allows the app to get sensitivity labels.", + "displayName": "Get labels app scope.", + "id": "8b377c27-ea19-4863-a948-8a8588c8f2c3", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteForUser" + "value": "SensitivityLabels.Read.All" }, { - "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in teams the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Manage selected Teams apps installed in teams", - "id": "9131c833-9a49-4c54-b38f-615ecfc4fc69", + "description": "Allows the app to evaluate all sensitivity label.", + "displayName": "Evaluate labels tenant scope.", + "id": "a42e3c42-b31e-4919-b699-696dca5dc9e7", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteSelectedForTeam" + "value": "SensitivityLabel.Evaluate.All" }, { - "description": "Allows the app to read all One Drive service activity, on behalf of the signed-in user.", - "displayName": "Read all One Drive service activity", - "id": "347e3c16-30f3-4ac7-9b52-fc3c053de9c9", - "origin": "Delegated (Microsoft Graph)", - "value": "ServiceActivity-OneDrive.Read.All" + "description": "Allows the app to read and update admin report settings, such as whether to display concealed information in reports, on behalf of the signed-in user.", + "displayName": "Read and write admin report settings", + "id": "b955410e-7715-4a88-a940-dfd551018df3", + "origin": "Delegated (Microsoft Graph)", + "value": "ReportSettings.ReadWrite.All" }, { - "description": "Allows the app to read all Microsoft 365 Web service activity, on behalf of the signed-in user.", - "displayName": "Read all Microsoft 365 Web service activity", - "id": "d74c75b1-d5a9-479d-902d-92f8f99182c1", + "description": "Allows the app to read the resource specific permissions granted on the chat, on behalf of the signed-in user.", + "displayName": "Read resource specific permissions granted on a chat", + "id": "cb530fca-534b-4e72-aa74-bca7e8bbd06f", "origin": "Delegated (Microsoft Graph)", - "value": "ServiceActivity-Microsoft365Web.Read.All" + "value": "ResourceSpecificPermissionGrant.ReadForChat" }, { - "description": "Allows the app to read all Exchange service activity, on behalf of the signed-in user.", - "displayName": "Read all Exchange service activity", - "id": "1fe7aa48-9373-4a47-8df3-168335e0f4c9", + "description": "Allows the app to read the resource specific permissions granted on the team, on behalf of the signed-in user.", + "displayName": "Read resource specific permissions granted on a team", + "id": "eafad40c-bf7a-415a-b7f8-acdf5706b58f", "origin": "Delegated (Microsoft Graph)", - "value": "ServiceActivity-Exchange.Read.All" + "value": "ResourceSpecificPermissionGrant.ReadForTeam" + }, + { + "description": "Allows the app to read the resource specific permissions granted on a user account, on behalf of the signed-in user.", + "displayName": "Read resource specific permissions granted on a user account", + "id": "f1d91a8f-88e7-4774-8401-b668d5bca0c5", + "origin": "Delegated (Microsoft Graph)", + "value": "ResourceSpecificPermissionGrant.ReadForUser" }, { "description": "Allows the app to read your organization's risk prevention providers, on behalf of the signed-in user.", @@ -685,6 +720,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "RoleManagement.Read.Exchange" }, + { + "description": "Allows the app to read admin report settings, such as whether to display concealed information in reports, on behalf of the signed-in user", + "displayName": "Read admin report settings", + "id": "84fac5f4-33a9-4100-aa38-a20c6d29e5e7", + "origin": "Delegated (Microsoft Graph)", + "value": "ReportSettings.Read.All" + }, { "description": "Allows the app to read and manage the Cloud PC role-based access control (RBAC) settings, on behalf of the signed-in user. This includes reading and managing Cloud PC role definitions and role assignments.", "displayName": "Read and write Cloud PC RBAC settings", @@ -693,53 +735,46 @@ "value": "RoleManagement.ReadWrite.CloudPC" }, { - "description": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes reading M365 Defender role definitions and role assignments.", - "displayName": "Read M365 Defender RBAC configuration", - "id": "d8914f8f-9f64-4bd1-b4d3-f5a701ed8457", - "origin": "Delegated (Microsoft Graph)", - "value": "RoleManagement.ReadWrite.Defender" - }, - { - "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes instantiating directory roles and managing directory role membership, and reading directory role templates, directory roles and memberships.", - "displayName": "Read and write directory RBAC settings", - "id": "d01b97e9-cbc0-49fe-810a-750afd5527a3", + "description": "Allows an app to read all service usage reports on behalf of the signed-in user. Services that provide usage reports include Office 365 and Azure Active Directory.", + "displayName": "Read all usage reports", + "id": "02e97553-ed7b-43d0-ab3c-f8bace0d040c", "origin": "Delegated (Microsoft Graph)", - "value": "RoleManagement.ReadWrite.Directory" + "value": "Reports.Read.All" }, { - "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your organization's Exchange Online service, on behalf of the signed-in user. This includes reading, creating, updating, and deleting Exchange management role definitions, role groups, role group membership, role assignments, management scopes, and role assignment policies.", - "displayName": "Read and write Exchange Online RBAC configuration", - "id": "c1499fe0-52b1-4b22-bed2-7a244e0e879f", + "description": "Allow the application to create, update and delete any data from Records Management, such as configuration, labels, and policies on behalf of the signed-in user.", + "displayName": "Read and write Records Management configuration, labels, and policies", + "id": "f2833d75-a4e6-40ab-86d4-6dfe73c97605", "origin": "Delegated (Microsoft Graph)", - "value": "RoleManagement.ReadWrite.Exchange" + "value": "RecordsManagement.ReadWrite.All" }, { - "description": "Allows the app to read the resource specific permissions granted on a user account, on behalf of the signed-in user.", - "displayName": "Read resource specific permissions granted on a user account", - "id": "f1d91a8f-88e7-4774-8401-b668d5bca0c5", + "description": "Allows the app to delete time-based eligibility schedules for access to Azure AD groups, on behalf of the signed-in user.", + "displayName": "Delete eligibility schedules for access to Azure AD groups", + "id": "c5ea9ab4-9b41-4c09-a400-53e652fb5096", "origin": "Delegated (Microsoft Graph)", - "value": "ResourceSpecificPermissionGrant.ReadForUser" + "value": "PrivilegedEligibilitySchedule.Remove.AzureADGroup" }, { - "description": "Allows the app to read the role-based access control (RBAC) alerts for your company's directory, on behalf of the signed-in user. This includes reading alert statuses, alert definitions, alert configurations and incidents that lead to an alert.", - "displayName": "Read all alert data for your company's directory", - "id": "cce71173-f76d-446e-97ff-efb2d82e11b1", + "description": "Allows the app to see your users' basic profile (e.g., name, picture, user name, email address)", + "displayName": "View users' basic profile", + "id": "14dad69e-099b-42c9-810b-d002981feec1", "origin": "Delegated (Microsoft Graph)", - "value": "RoleManagementAlert.Read.Directory" + "value": "profile" }, { - "description": "Allows the app to read the resource specific permissions granted on the team, on behalf of the signed-in user.", - "displayName": "Read resource specific permissions granted on a team", - "id": "eafad40c-bf7a-415a-b7f8-acdf5706b58f", + "description": "Allows the app to read all profile photos of users and groups, on behalf of the signed-in user.", + "displayName": "Read profile photo of a user or group", + "id": "469cd065-729e-4dee-b1fa-d92e0fab6310", "origin": "Delegated (Microsoft Graph)", - "value": "ResourceSpecificPermissionGrant.ReadForTeam" + "value": "ProfilePhoto.Read.All" }, { - "description": "Allows the app to read and update admin report settings, such as whether to display concealed information in reports, on behalf of the signed-in user.", - "displayName": "Read and write admin report settings", - "id": "b955410e-7715-4a88-a940-dfd551018df3", + "description": "Allows the app to read and write all profile photos of users and groups, on behalf of the signed-in user.", + "displayName": "Read and write profile photo of a user or group", + "id": "f5b24df7-511e-48bb-ae88-643f023b55e1", "origin": "Delegated (Microsoft Graph)", - "value": "ReportSettings.ReadWrite.All" + "value": "ProfilePhoto.ReadWrite.All" }, { "description": "Allows the app to read programs and program controls that the signed-in user has access to in the organization.", @@ -832,13 +867,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "RecordsManagement.Read.All" }, - { - "description": "Allow the application to create, update and delete any data from Records Management, such as configuration, labels, and policies on behalf of the signed-in user.", - "displayName": "Read and write Records Management configuration, labels, and policies", - "id": "f2833d75-a4e6-40ab-86d4-6dfe73c97605", - "origin": "Delegated (Microsoft Graph)", - "value": "RecordsManagement.ReadWrite.All" - }, { "description": "Allows the app to read available properties of remoteTenantGroups, on behalf of the signed-in user.", "displayName": "Read RemoteTenantGroups information", @@ -847,46 +875,53 @@ "value": "RemoteTenantGroups.Read.All" }, { - "description": "Allows an app to read all service usage reports on behalf of the signed-in user. Services that provide usage reports include Office 365 and Azure Active Directory.", - "displayName": "Read all usage reports", - "id": "02e97553-ed7b-43d0-ab3c-f8bace0d040c", + "description": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes reading M365 Defender role definitions and role assignments.", + "displayName": "Read M365 Defender RBAC configuration", + "id": "d8914f8f-9f64-4bd1-b4d3-f5a701ed8457", "origin": "Delegated (Microsoft Graph)", - "value": "Reports.Read.All" + "value": "RoleManagement.ReadWrite.Defender" }, { - "description": "Allows the app to read admin report settings, such as whether to display concealed information in reports, on behalf of the signed-in user", - "displayName": "Read admin report settings", - "id": "84fac5f4-33a9-4100-aa38-a20c6d29e5e7", + "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes instantiating directory roles and managing directory role membership, and reading directory role templates, directory roles and memberships.", + "displayName": "Read and write directory RBAC settings", + "id": "d01b97e9-cbc0-49fe-810a-750afd5527a3", "origin": "Delegated (Microsoft Graph)", - "value": "ReportSettings.Read.All" + "value": "RoleManagement.ReadWrite.Directory" }, { - "description": "Allows the app to read the resource specific permissions granted on the chat, on behalf of the signed-in user.", - "displayName": "Read resource specific permissions granted on a chat", - "id": "cb530fca-534b-4e72-aa74-bca7e8bbd06f", + "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your organization's Exchange Online service, on behalf of the signed-in user. This includes reading, creating, updating, and deleting Exchange management role definitions, role groups, role group membership, role assignments, management scopes, and role assignment policies.", + "displayName": "Read and write Exchange Online RBAC configuration", + "id": "c1499fe0-52b1-4b22-bed2-7a244e0e879f", "origin": "Delegated (Microsoft Graph)", - "value": "ResourceSpecificPermissionGrant.ReadForChat" + "value": "RoleManagement.ReadWrite.Exchange" }, { - "description": "Allows the app to read and manage the role-based access control (RBAC) alerts for your company's directory, on behalf of the signed-in user. This includes managing alert settings, initiating alert scans, dismissing alerts, remediating alert incidents, and reading alert statuses, alert definitions, alert configurations and incidents that lead to an alert.", - "displayName": "Read all alert data, configure alerts, and take actions on all alerts for your company's directory", - "id": "435644c6-a5b1-40bf-8f52-fe8e5b53e19c", + "description": "Allows the app to read your organization’s security events on behalf of the signed-in user.", + "displayName": "Read your organization’s security events", + "id": "64733abd-851e-478a-bffb-e47a14b18235", "origin": "Delegated (Microsoft Graph)", - "value": "RoleManagementAlert.ReadWrite.Directory" + "value": "SecurityEvents.Read.All" }, { - "description": "Allows the app to read policies in Privileged Identity Management for Groups, on behalf of the signed-in user.", - "displayName": "Read all policies in PIM for Groups", - "id": "7e26fdff-9cb1-4e56-bede-211fe0e420e8", + "description": "Allows the app to read your organization’s security events on behalf of the signed-in user. Also allows the app to update editable properties in security events on behalf of the signed-in user.", + "displayName": "Read and update your organization’s security events", + "id": "6aedf524-7e1c-45a7-bd76-ded8cab8d0fc", "origin": "Delegated (Microsoft Graph)", - "value": "RoleManagementPolicy.Read.AzureADGroup" + "value": "SecurityEvents.ReadWrite.All" }, { - "description": "Allows the app to read policies for privileged role-based access control (RBAC) assignments of your company's directory, on behalf of the signed-in user.", - "displayName": "Read all policies for privileged role assignments of your company's directory", - "id": "3de2cdbe-0ff5-47d5-bdee-7f45b4749ead", + "description": "Allows the app to read all the identity security available identity accounts", + "displayName": "Read identity security available identity accounts", + "id": "3e9ed69a-a48e-473c-8b97-413016703a37", "origin": "Delegated (Microsoft Graph)", - "value": "RoleManagementPolicy.Read.Directory" + "value": "SecurityIdentitiesAccount.Read.All" + }, + { + "description": "Allows the app to read and write identity security available actions on behalf of the signed-in identity.", + "displayName": "Read and perform identity security available actions", + "id": "818229ce-20e4-47bd-92f4-bc94dbb37a56", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityIdentitiesActions.ReadWrite.All" }, { "description": "Allows the app to read the sensors window auditing configuration of the signed in user", @@ -980,60 +1015,60 @@ "value": "SensitivityLabel.Evaluate" }, { - "description": "Allows the app to evaluate all sensitivity label.", - "displayName": "Evaluate labels tenant scope.", - "id": "a42e3c42-b31e-4919-b699-696dca5dc9e7", + "description": "Allows the app to read and write Security Copilot resources owned by the signed-in user on their behalf.", + "displayName": "Read and write individually owned Security Copilot resources of the signed-in user", + "id": "206291b0-2167-47a7-a640-6cdc1df710ba", "origin": "Delegated (Microsoft Graph)", - "value": "SensitivityLabel.Evaluate.All" + "value": "SecurityCopilotWorkspaces.ReadWrite.All" }, { - "description": "Allows the app to get sensitivity labels.", - "displayName": "Get labels user scope.", - "id": "1aeb73ce-68d7-49b7-913a-eedc80844551", + "description": "Allows the app to read all Security Copilot signed-in user's resources on behalf of the signed-in user", + "displayName": "Read all Security Copilot resources for the signed-in user", + "id": "84499c31-ac2e-44d3-a0cf-a6c386d4dfe8", "origin": "Delegated (Microsoft Graph)", - "value": "SensitivityLabel.Read" + "value": "SecurityCopilotWorkspaces.Read.All" }, { - "description": "Allows the app to get sensitivity labels.", - "displayName": "Get labels app scope.", - "id": "8b377c27-ea19-4863-a948-8a8588c8f2c3", + "description": "Read email metadata, security detection details, and execute remediation actions like deleting an email, on behalf of the signed in user.", + "displayName": "Read metadata, detection details, and execute remediation actions on emails in your organization", + "id": "48eb8c83-6e58-46e7-a6d3-8805822f5940", "origin": "Delegated (Microsoft Graph)", - "value": "SensitivityLabels.Read.All" + "value": "SecurityAnalyzedMessage.ReadWrite.All" }, { - "description": "Allows the app to export all Sentiment Survey, on behalf of the signed-in user.", - "displayName": "Export all Sentiment Survey", - "id": "df9fd94d-51ff-443d-8f31-ae4dc1b5b8d8", + "description": "Read email metadata and security detection details on behalf of the signed in user.", + "displayName": "Read metadata and detection details for emails in your organization", + "id": "53e6783e-b127-4a35-ab3a-6a52d80a9077", "origin": "Delegated (Microsoft Graph)", - "value": "SentimentSurvey.Export.All" + "value": "SecurityAnalyzedMessage.Read.All" }, { - "description": "Allows the app to read and write identity security available actions on behalf of the signed-in identity.", - "displayName": "Read and perform identity security available actions", - "id": "818229ce-20e4-47bd-92f4-bc94dbb37a56", + "description": "Allows the app to read the role-based access control (RBAC) alerts for your company's directory, on behalf of the signed-in user. This includes reading alert statuses, alert definitions, alert configurations and incidents that lead to an alert.", + "displayName": "Read all alert data for your company's directory", + "id": "cce71173-f76d-446e-97ff-efb2d82e11b1", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityIdentitiesActions.ReadWrite.All" + "value": "RoleManagementAlert.Read.Directory" }, { - "description": "Allows the app to read all the identity security available identity accounts", - "displayName": "Read identity security available identity accounts", - "id": "3e9ed69a-a48e-473c-8b97-413016703a37", + "description": "Allows the app to read and manage the role-based access control (RBAC) alerts for your company's directory, on behalf of the signed-in user. This includes managing alert settings, initiating alert scans, dismissing alerts, remediating alert incidents, and reading alert statuses, alert definitions, alert configurations and incidents that lead to an alert.", + "displayName": "Read all alert data, configure alerts, and take actions on all alerts for your company's directory", + "id": "435644c6-a5b1-40bf-8f52-fe8e5b53e19c", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityIdentitiesAccount.Read.All" + "value": "RoleManagementAlert.ReadWrite.Directory" }, { - "description": "Allows the app to read your organization’s security events on behalf of the signed-in user. Also allows the app to update editable properties in security events on behalf of the signed-in user.", - "displayName": "Read and update your organization’s security events", - "id": "6aedf524-7e1c-45a7-bd76-ded8cab8d0fc", + "description": "Allows the app to read policies in Privileged Identity Management for Groups, on behalf of the signed-in user.", + "displayName": "Read all policies in PIM for Groups", + "id": "7e26fdff-9cb1-4e56-bede-211fe0e420e8", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityEvents.ReadWrite.All" + "value": "RoleManagementPolicy.Read.AzureADGroup" }, { - "description": "Allows the app to read your organization’s security events on behalf of the signed-in user.", - "displayName": "Read your organization’s security events", - "id": "64733abd-851e-478a-bffb-e47a14b18235", + "description": "Allows the app to read policies for privileged role-based access control (RBAC) assignments of your company's directory, on behalf of the signed-in user.", + "displayName": "Read all policies for privileged role assignments of your company's directory", + "id": "3de2cdbe-0ff5-47d5-bdee-7f45b4749ead", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityEvents.Read.All" + "value": "RoleManagementPolicy.Read.Directory" }, { "description": "Allows the app to read policies in Privileged Identity Management for App Roles, on behalf of the signed-in user.", @@ -1063,6 +1098,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "RoleManagementPolicy.ReadWrite.EntraAppRole" }, + { + "description": "Allows the app to get sensitivity labels.", + "displayName": "Get labels user scope.", + "id": "1aeb73ce-68d7-49b7-913a-eedc80844551", + "origin": "Delegated (Microsoft Graph)", + "value": "SensitivityLabel.Read" + }, { "description": "Allows the app to read schedule, schedule groups, shifts and associated entities in the Teams or Shifts application on behalf of the signed-in user.", "displayName": "Read user schedule items", @@ -1070,13 +1112,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "Schedule.Read.All" }, - { - "description": "Allows the app to manage schedule, schedule groups, shifts and associated entities in the Teams or Shifts application on behalf of the signed-in user.", - "displayName": "Read and write user schedule items", - "id": "63f27281-c9d9-4f29-94dd-6942f7f1feb0", - "origin": "Delegated (Microsoft Graph)", - "value": "Schedule.ReadWrite.All" - }, { "description": "Allows the app to read/write schedule permissions for a specific role in Shifts application on behalf of the signed-in user.", "displayName": "Read/Write schedule permissions for a role.", @@ -1091,13 +1126,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "SearchConfiguration.Read.All" }, - { - "description": "Allows the app to read your tenant's user configurations on behalf of the signed-in admin user. User configuration may include attributes related to user, such as telephone number, assigned policies, etc.", - "displayName": "Read Teams user configurations", - "id": "5c469ce4-dab5-4afd-b9de-14f1ba4004a7", - "origin": "Delegated (Microsoft Graph)", - "value": "TeamsUserConfiguration.Read.All" - }, { "description": "Allows the app to read and write search configuration, on behalf of the signed-in user.", "displayName": "Read and write your organization's search configuration", @@ -1105,6 +1133,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "SearchConfiguration.ReadWrite.All" }, + { + "description": "Allows the app to read security actions, on behalf of the signed-in user.", + "displayName": "Read your organization's security actions", + "id": "1638cddf-07a4-4de2-8645-69c96cacad73", + "origin": "Delegated (Microsoft Graph)", + "value": "SecurityActions.Read.All" + }, { "description": "Allows the app to read or update security actions, on behalf of the signed-in user.", "displayName": "Read and update your organization's security actions", @@ -1134,60 +1169,46 @@ "value": "SecurityAlert.ReadWrite.All" }, { - "description": "Read email metadata and security detection details on behalf of the signed in user.", - "displayName": "Read metadata and detection details for emails in your organization", - "id": "53e6783e-b127-4a35-ab3a-6a52d80a9077", + "description": "Allows the app to manage schedule, schedule groups, shifts and associated entities in the Teams or Shifts application on behalf of the signed-in user.", + "displayName": "Read and write user schedule items", + "id": "63f27281-c9d9-4f29-94dd-6942f7f1feb0", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityAnalyzedMessage.Read.All" + "value": "Schedule.ReadWrite.All" }, { - "description": "Read email metadata, security detection details, and execute remediation actions like deleting an email, on behalf of the signed in user.", - "displayName": "Read metadata, detection details, and execute remediation actions on emails in your organization", - "id": "48eb8c83-6e58-46e7-a6d3-8805822f5940", - "origin": "Delegated (Microsoft Graph)", - "value": "SecurityAnalyzedMessage.ReadWrite.All" - }, - { - "description": "Allows the app to read all Security Copilot signed-in user's resources on behalf of the signed-in user", - "displayName": "Read all Security Copilot resources for the signed-in user", - "id": "84499c31-ac2e-44d3-a0cf-a6c386d4dfe8", - "origin": "Delegated (Microsoft Graph)", - "value": "SecurityCopilotWorkspaces.Read.All" - }, - { - "description": "Allows the app to read and write Security Copilot resources owned by the signed-in user on their behalf.", - "displayName": "Read and write individually owned Security Copilot resources of the signed-in user", - "id": "206291b0-2167-47a7-a640-6cdc1df710ba", + "description": "Allows the app to read your tenant's acquired telephone number details on behalf of the signed-in admin user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", + "displayName": "Read Tenant-Acquired Telephone Number Details", + "id": "1bc6eab1-058d-4557-b011-d4c41cec88b7", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityCopilotWorkspaces.ReadWrite.All" + "value": "TeamsTelephoneNumber.Read.All" }, { - "description": "Allows the app to read security actions, on behalf of the signed-in user.", - "displayName": "Read your organization's security actions", - "id": "1638cddf-07a4-4de2-8645-69c96cacad73", + "description": "Allows the app to read and modify your tenant's acquired telephone number details on behalf of the signed-in admin user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", + "displayName": "Read and Modify Tenant-Acquired Telephone Number Details", + "id": "424b07a8-1209-4d17-9fe4-9018a93a1024", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityActions.Read.All" + "value": "TeamsTelephoneNumber.ReadWrite.All" }, { - "description": "Allows the app to read the available Teams templates, on behalf of the signed-in user.", - "displayName": "Read available Teams templates", - "id": "cd87405c-5792-4f15-92f7-debc0db6d1d6", + "description": "Allows the app to read your tenant's user configurations on behalf of the signed-in admin user. User configuration may include attributes related to user, such as telephone number, assigned policies, etc.", + "displayName": "Read Teams user configurations", + "id": "5c469ce4-dab5-4afd-b9de-14f1ba4004a7", "origin": "Delegated (Microsoft Graph)", - "value": "TeamTemplates.Read" + "value": "TeamsUserConfiguration.Read.All" }, { - "description": "Allows the app to read the teamwork settings of the organization, on behalf of the signed-in user.", - "displayName": "Read organizational teamwork settings", - "id": "594f4bb6-c083-4cf9-8aa8-213823bdf351", + "description": "Allows the app to read Windows Hello authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' Windows Hello methods", + "id": "ff37d46d-b88a-4e0c-85ee-7e26c37b18eb", "origin": "Delegated (Microsoft Graph)", - "value": "Teamwork.Read.All" + "value": "UserAuthMethod-WindowsHello.Read.All" }, { - "description": "Allows the app to read the Teams app settings on behalf of the signed-in user.", - "displayName": "Read Teams app settings", - "id": "44e060c4-bbdc-4256-a0b9-dcc0396db368", + "description": "Allows the app to read and write the signed-in user's Windows Hello authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's Windows Hello authentication methods", + "id": "f11e1db9-d419-4a24-b677-792723ffd727", "origin": "Delegated (Microsoft Graph)", - "value": "TeamworkAppSettings.Read.All" + "value": "UserAuthMethod-WindowsHello.ReadWrite" }, { "description": "Allows the app to read and write Windows Hello authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", @@ -1294,6 +1315,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "VerifiedId-Profile.Read.All" }, + { + "description": "Allows the app to read the signed-in user's Windows Hello authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's Windows Hello methods", + "id": "efe2b5aa-3a8e-486c-b0be-cc4d185c1b40", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-WindowsHello.Read" + }, { "description": "This role can read and write Verified Id profiles in a tenant.", "displayName": "Read and write Verified Id profiles", @@ -1302,39 +1330,32 @@ "value": "VerifiedId-Profile.ReadWrite.All" }, { - "description": "Allows an application to read virtual appointments for the signed-in user. Only an organizer or participant user can read their virtual appointments. ", - "displayName": "Read a user's virtual appointments", - "id": "27470298-d3b8-4b9c-aad4-6334312a3eac", - "origin": "Delegated (Microsoft Graph)", - "value": "VirtualAppointment.Read" - }, - { - "description": "Allows the app to read and write the signed-in user's Windows Hello authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write the signed-in user's Windows Hello authentication methods", - "id": "f11e1db9-d419-4a24-b677-792723ffd727", + "description": "Allows the app to read and write Temporary Access Pass authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' Temporary Access Pass methods.", + "id": "05de4a66-e51a-4312-842a-30c8094698d2", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-WindowsHello.ReadWrite" + "value": "UserAuthMethod-TAP.ReadWrite.All" }, { - "description": "Allows an application to read and write virtual appointments for the signed-in user. Only an organizer or participant user can read and write their virtual appointments. ", - "displayName": "Read and write a user's virtual appointments ", - "id": "2ccc2926-a528-4b17-b8bb-860eed29d64c", + "description": "Allows the app to read Temporary Access Pass authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' Temporary Access Pass methods", + "id": "6976c635-c9c2-41e6-a21d-e6913a155273", "origin": "Delegated (Microsoft Graph)", - "value": "VirtualAppointment.ReadWrite" + "value": "UserAuthMethod-TAP.Read.All" }, { - "description": "Allows the app to read Windows Hello authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' Windows Hello methods", - "id": "ff37d46d-b88a-4e0c-85ee-7e26c37b18eb", + "description": "Allows the app to read and write the signed-in user's phone authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's phone authentication methods", + "id": "6c4aad61-f76b-46ad-a22c-57d4d3d962af", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-WindowsHello.Read.All" + "value": "UserAuthMethod-Phone.ReadWrite" }, { - "description": "Allows the app to read and write Temporary Access Pass authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' Temporary Access Pass methods.", - "id": "05de4a66-e51a-4312-842a-30c8094698d2", + "description": "Allows the app to read and write Phone methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' phone methods.", + "id": "48c99302-9a24-4f27-a8a7-acef4debba14", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-TAP.ReadWrite.All" + "value": "UserAuthMethod-Phone.ReadWrite.All" }, { "description": "Allows the app to read the signed-in user's platform credential authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", @@ -1441,13 +1462,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "UserAuthMethod-TAP.Read" }, - { - "description": "Allows the app to read Temporary Access Pass authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' Temporary Access Pass methods", - "id": "6976c635-c9c2-41e6-a21d-e6913a155273", - "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-TAP.Read.All" - }, { "description": "Allows the app to read and write the signed-in user's Temporary Access Pass authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", "displayName": "Read and write the signed-in user's Temporary Access Pass authentication methods", @@ -1456,11 +1470,18 @@ "value": "UserAuthMethod-TAP.ReadWrite" }, { - "description": "Allows the app to read the signed-in user's Windows Hello authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read the signed-in user's Windows Hello methods", - "id": "efe2b5aa-3a8e-486c-b0be-cc4d185c1b40", + "description": "Allows an application to read virtual appointments for the signed-in user. Only an organizer or participant user can read their virtual appointments. ", + "displayName": "Read a user's virtual appointments", + "id": "27470298-d3b8-4b9c-aad4-6334312a3eac", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-WindowsHello.Read" + "value": "VirtualAppointment.Read" + }, + { + "description": "Allows an application to read and write virtual appointments for the signed-in user. Only an organizer or participant user can read and write their virtual appointments. ", + "displayName": "Read and write a user's virtual appointments ", + "id": "2ccc2926-a528-4b17-b8bb-860eed29d64c", + "origin": "Delegated (Microsoft Graph)", + "value": "VirtualAppointment.ReadWrite" }, { "description": "Allows an application to send notifications for virtual appointments for the signed-in user.", @@ -1470,18 +1491,18 @@ "value": "VirtualAppointmentNotification.Send" }, { - "description": "Allows the app to read virtual events created by you", - "displayName": "Read your virtual events", - "id": "6b616635-ae58-433a-a918-8c45e4f304dc", - "origin": "Delegated (Microsoft Graph)", - "value": "VirtualEvent.Read" + "description": "Read PFX certificate requests and send certificates to Microsoft Intune.", + "displayName": "PFX certificate management", + "id": "907d16c7-7591-49a4-b523-6fd42e5f2c7e", + "origin": "Application (Microsoft Intune API)", + "value": "pfx_cert_provider" }, { - "description": "Allows the app to read and write virtual events for you", - "displayName": "Read and write your virtual events", - "id": "d38d189c-e29b-4344-8b3b-829bfa81380b", - "origin": "Delegated (Microsoft Graph)", - "value": "VirtualEvent.ReadWrite" + "description": "Send SCEP challenges to Intune for certificate request validation. ", + "displayName": "SCEP challenge validation", + "id": "39d724e8-6a34-4930-9a36-364082c35716", + "origin": "Application (Microsoft Intune API)", + "value": "scep_challenge_provider" }, { "description": "Allow the telecom expense management app to send and receive device telecom and Wi-Fi data usage information, including phone number, with Intune to help analyze and manage data usage costs of corporate-owned devices.", @@ -1581,27 +1602,6 @@ "origin": "Application (Microsoft Mixed Reality)", "value": "mixedreality.signin" }, - { - "description": "Sign in to synthetics service", - "displayName": "syntest.signin", - "id": "9f56f4b8-4de2-4e83-a632-45d1e4b47400", - "origin": "Delegated (Microsoft Mixed Reality)", - "value": "syntest.signin" - }, - { - "description": "Send SCEP challenges to Intune for certificate request validation. ", - "displayName": "SCEP challenge validation", - "id": "39d724e8-6a34-4930-9a36-364082c35716", - "origin": "Application (Microsoft Intune API)", - "value": "scep_challenge_provider" - }, - { - "description": "Read PFX certificate requests and send certificates to Microsoft Intune.", - "displayName": "PFX certificate management", - "id": "907d16c7-7591-49a4-b523-6fd42e5f2c7e", - "origin": "Application (Microsoft Intune API)", - "value": "pfx_cert_provider" - }, { "description": "Allows the app to send partner compliance policies and its Azure AD Group assignment to Microsoft Intune without a signed-in user.", "displayName": "Manage partner compliance policies with Microsoft Intune.", @@ -1616,6 +1616,34 @@ "origin": "Application (Microsoft Intune API)", "value": "get_device_compliance" }, + { + "description": "Grants access to the Intune data warehouse API", + "displayName": "Get data warehouse information from Microsoft Intune", + "id": "3d9dc976-32fb-45a8-90bd-c9f8a850d098", + "origin": "Application (Microsoft Intune API)", + "value": "get_data_warehouse" + }, + { + "description": "Allows user to view their BitLocker recovery keys", + "displayName": "Read BitLocker recovery keys", + "id": "ecff1a9d-e6bb-4e01-9136-c8825bbfceb3", + "origin": "Delegated (Microsoft Intune AAD BitLocker Recovery Key Integration)", + "value": "IntuneAADBitLockerRecoveryKey.Read" + }, + { + "description": "Allows the app to read virtual events created by you", + "displayName": "Read your virtual events", + "id": "6b616635-ae58-433a-a918-8c45e4f304dc", + "origin": "Delegated (Microsoft Graph)", + "value": "VirtualEvent.Read" + }, + { + "description": "Allows the app to read and write virtual events for you", + "displayName": "Read and write your virtual events", + "id": "d38d189c-e29b-4344-8b3b-829bfa81380b", + "origin": "Delegated (Microsoft Graph)", + "value": "VirtualEvent.ReadWrite" + }, { "description": "Allows the app to read all Windows update deployment settings for the organization on behalf of the signed-in user.", "displayName": "Read all Windows update deployment settings", @@ -1658,6 +1686,13 @@ "origin": "Application (Microsoft Graph Connectors Core)", "value": "ContentDomain.ReadWrite" }, + { + "description": "Allows the app to read phone authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' phone authentication methods", + "id": "20cf4ae1-09b9-4d29-a6f8-43e1820ce60c", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Phone.Read.All" + }, { "description": "Read and Write permission of Content Domain Items into all content domain shards. ", "displayName": "ContentDomainItem.ReadWrite.All", @@ -1665,20 +1700,6 @@ "origin": "Application (Microsoft Graph Connectors Core)", "value": "ContentDomainItem.ReadWrite.All" }, - { - "description": "Read and Write permission of Content Domain Items into the content domain shard owned by the application. ", - "displayName": "ContentDomainItem.ReadWrite.OwnedBy", - "id": "83447e6a-d68b-4373-bd75-efab237f20ba", - "origin": "Application (Microsoft Graph Connectors Core)", - "value": "ContentDomainItem.ReadWrite.OwnedBy" - }, - { - "description": "Allows the app to read and write Phone methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' phone methods.", - "id": "48c99302-9a24-4f27-a8a7-acef4debba14", - "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Phone.ReadWrite.All" - }, { "description": "Read all published labels and label policies for an organization.", "displayName": "InformationProtectionPolicy.Read.All", @@ -1722,32 +1743,11 @@ "value": "MicrosoftTunnelGatewayEnrollment" }, { - "description": "Allows user to view their BitLocker recovery keys", - "displayName": "Read BitLocker recovery keys", - "id": "ecff1a9d-e6bb-4e01-9136-c8825bbfceb3", - "origin": "Delegated (Microsoft Intune AAD BitLocker Recovery Key Integration)", - "value": "IntuneAADBitLockerRecoveryKey.Read" - }, - { - "description": "Grants access to the Intune data warehouse API", - "displayName": "Get data warehouse information from Microsoft Intune", - "id": "3d9dc976-32fb-45a8-90bd-c9f8a850d098", - "origin": "Application (Microsoft Intune API)", - "value": "get_data_warehouse" - }, - { - "description": "Allows the app to read and write all profile photos of users and groups, on behalf of the signed-in user.", - "displayName": "Read and write profile photo of a user or group", - "id": "f5b24df7-511e-48bb-ae88-643f023b55e1", - "origin": "Delegated (Microsoft Graph)", - "value": "ProfilePhoto.ReadWrite.All" - }, - { - "description": "Allows the app to read and write the signed-in user's phone authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write the signed-in user's phone authentication methods", - "id": "6c4aad61-f76b-46ad-a22c-57d4d3d962af", - "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Phone.ReadWrite" + "description": "Read and Write permission of Content Domain Items into the content domain shard owned by the application. ", + "displayName": "ContentDomainItem.ReadWrite.OwnedBy", + "id": "83447e6a-d68b-4373-bd75-efab237f20ba", + "origin": "Application (Microsoft Graph Connectors Core)", + "value": "ContentDomainItem.ReadWrite.OwnedBy" }, { "description": "Allows the app to read the signed-in user's phone authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", @@ -1757,18 +1757,46 @@ "value": "UserAuthMethod-Phone.Read" }, { - "description": "Allows the application to read Tenant Governance settings on behalf of the signed-in user.", - "displayName": "Read Tenant Governance settings", - "id": "4ad3e05f-2467-49d9-baa2-8e4de7bcee9b", + "description": "Allows the app to read and write password authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' password methods.", + "id": "7f5b683d-df96-4690-a88d-6e336ed6dc7c", "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-Setting.Read.All" + "value": "UserAuthMethod-Password.ReadWrite.All" }, { - "description": "Allows the application to read Tenant Governance settings and update them on behalf of the signed-in user.", - "displayName": "Read and write Tenant Governance settings", - "id": "135f3533-12fc-4608-97ac-5c5cea64baf0", + "description": "Allows the app to read and write the signed-in user's password authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's password authentication methods", + "id": "60cce20d-d41e-4594-b391-84bbf8cc31f3", "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-Setting.ReadWrite.All" + "value": "UserAuthMethod-Password.ReadWrite" + }, + { + "description": "Allows the application to list and read all Tenant Governance requests on behalf of the signed-in user.", + "displayName": "Read Tenant Governance requests", + "id": "a924b9f1-7af0-4982-aecf-b6e0e10b2830", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-Request.Read.All" + }, + { + "description": "Allows the application to list, read, create, and update Tenant Governance requests on behalf of the signed-in user.", + "displayName": "Read and write Tenant Governance requests", + "id": "3c7a434e-4e5d-413f-be82-b77ea4ba5a4d", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-Request.ReadWrite.All" + }, + { + "description": "Allows the application to read Tenant Governance settings on behalf of the signed-in user.", + "displayName": "Read Tenant Governance settings", + "id": "4ad3e05f-2467-49d9-baa2-8e4de7bcee9b", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-Setting.Read.All" + }, + { + "description": "Allows the application to read Tenant Governance settings and update them on behalf of the signed-in user.", + "displayName": "Read and write Tenant Governance settings", + "id": "135f3533-12fc-4608-97ac-5c5cea64baf0", + "origin": "Delegated (Microsoft Graph)", + "value": "TenantGovernance-Setting.ReadWrite.All" }, { "description": "Allows the app to read the term store data that the signed-in user has access to. This includes all sets, groups and terms in the term store.", @@ -1862,46 +1890,53 @@ "value": "Topic.Read.All" }, { - "description": "Allows the app to read trust framework key set properties on behalf of the signed-in user.", - "displayName": "Read trust framework key sets", - "id": "7ad34336-f5b1-44ce-8682-31d7dfcd9ab9", + "description": "Allows the application to list, read, and update Tenant Governance relationships on behalf of the signed-in user.", + "displayName": "Read and write Tenant Governance relationships", + "id": "3fbcd6a3-a9a5-4d69-8a78-acc7d7195180", "origin": "Delegated (Microsoft Graph)", - "value": "TrustFrameworkKeySet.Read.All" + "value": "TenantGovernance-Relationship.ReadWrite.All" }, { - "description": "Allows the app to read and write trust framework key set properties on behalf of the signed-in user.", - "displayName": "Read and write trust framework key sets", - "id": "39244520-1e7d-4b4a-aee0-57c65826e427", + "description": "Allows the application to list and read all Tenant Governance relationships on behalf of the signed-in user.", + "displayName": "Read Tenant Governance relationships", + "id": "0b1c2458-4845-477b-a704-3cce8b06bf28", "origin": "Delegated (Microsoft Graph)", - "value": "TrustFrameworkKeySet.ReadWrite.All" + "value": "TenantGovernance-Relationship.Read.All" }, { - "description": "Allows the application to list, read, create, and update Tenant Governance requests on behalf of the signed-in user.", - "displayName": "Read and write Tenant Governance requests", - "id": "3c7a434e-4e5d-413f-be82-b77ea4ba5a4d", + "description": "Allows the application to list, read, and refresh related tenants information on behalf of the signed-in user.", + "displayName": "Read and write related tenants", + "id": "e61db2de-de55-461e-942d-52a028ed1076", "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-Request.ReadWrite.All" + "value": "TenantGovernance-RelatedTenant.ReadWrite.All" }, { - "description": "Allows the app to read basic unified group properties, memberships and owners of the group the signed-in guest is a member of.", - "displayName": "Read unified group memberships as guest", - "id": "73e75199-7c3e-41bb-9357-167164dbb415", + "description": "Allows the application to list and read related tenants information on behalf of the signed-in user.", + "displayName": "Read related tenants", + "id": "9caaca93-f090-4b9a-b4bb-17de251354d4", "origin": "Delegated (Microsoft Graph)", - "value": "UnifiedGroupMember.Read.AsGuest" + "value": "TenantGovernance-RelatedTenant.Read.All" }, { - "description": "Allows the application to list and read all Tenant Governance requests on behalf of the signed-in user.", - "displayName": "Read Tenant Governance requests", - "id": "a924b9f1-7af0-4982-aecf-b6e0e10b2830", + "description": "Allows the app to read the available Teams templates, on behalf of the signed-in user.", + "displayName": "Read available Teams templates", + "id": "cd87405c-5792-4f15-92f7-debc0db6d1d6", "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-Request.Read.All" + "value": "TeamTemplates.Read" }, { - "description": "Allows the application to list and read all Tenant Governance relationships on behalf of the signed-in user.", - "displayName": "Read Tenant Governance relationships", - "id": "0b1c2458-4845-477b-a704-3cce8b06bf28", + "description": "Allows the app to read the teamwork settings of the organization, on behalf of the signed-in user.", + "displayName": "Read organizational teamwork settings", + "id": "594f4bb6-c083-4cf9-8aa8-213823bdf351", "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-Relationship.Read.All" + "value": "Teamwork.Read.All" + }, + { + "description": "Allows the app to read the Teams app settings on behalf of the signed-in user.", + "displayName": "Read Teams app settings", + "id": "44e060c4-bbdc-4256-a0b9-dcc0396db368", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkAppSettings.Read.All" }, { "description": "Allows the app to read and write the Teams app settings on behalf of the signed-in user.", @@ -1938,6 +1973,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "TeamworkDevice.ReadWrite.All" }, + { + "description": "Allows the app to read trust framework key set properties on behalf of the signed-in user.", + "displayName": "Read trust framework key sets", + "id": "7ad34336-f5b1-44ce-8682-31d7dfcd9ab9", + "origin": "Delegated (Microsoft Graph)", + "value": "TrustFrameworkKeySet.Read.All" + }, { "description": "Allows the app to read the signed-in user's sections (folders) for organizing chats and channels in Teams.", "displayName": "Read your sections", @@ -1945,13 +1987,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "TeamworkSection.Read" }, - { - "description": "Allows the app to read and write the signed-in user's sections (folders) for organizing chats and channels in Teams.", - "displayName": "Read and write your sections", - "id": "70dbe5e8-39b9-40f3-8c65-3ec7b00ad804", - "origin": "Delegated (Microsoft Graph)", - "value": "TeamworkSection.ReadWrite" - }, { "description": "Allows the app to read tags in Teams, on behalf of the signed-in user.", "displayName": "Read tags in Teams", @@ -2009,25 +2044,25 @@ "value": "TenantGovernance-PolicyTemplate.ReadWrite.All" }, { - "description": "Allows the application to list and read related tenants information on behalf of the signed-in user.", - "displayName": "Read related tenants", - "id": "9caaca93-f090-4b9a-b4bb-17de251354d4", + "description": "Allows the app to read and write the signed-in user's sections (folders) for organizing chats and channels in Teams.", + "displayName": "Read and write your sections", + "id": "70dbe5e8-39b9-40f3-8c65-3ec7b00ad804", "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-RelatedTenant.Read.All" + "value": "TeamworkSection.ReadWrite" }, { - "description": "Allows the application to list, read, and refresh related tenants information on behalf of the signed-in user.", - "displayName": "Read and write related tenants", - "id": "e61db2de-de55-461e-942d-52a028ed1076", + "description": "Allows the app to read, create, and delete time-based eligibility schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", + "displayName": "Read, create, and delete eligibility schedules for app permission grants and app role assignments", + "id": "f7ff1cb0-e255-4bb3-b24a-6708c60c5418", "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-RelatedTenant.ReadWrite.All" + "value": "PrivilegedEligibilitySchedule.ReadWrite.EntraAppRole" }, { - "description": "Allows the application to list, read, and update Tenant Governance relationships on behalf of the signed-in user.", - "displayName": "Read and write Tenant Governance relationships", - "id": "3fbcd6a3-a9a5-4d69-8a78-acc7d7195180", + "description": "Allows the app to read and write trust framework key set properties on behalf of the signed-in user.", + "displayName": "Read and write trust framework key sets", + "id": "39244520-1e7d-4b4a-aee0-57c65826e427", "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-Relationship.ReadWrite.All" + "value": "TrustFrameworkKeySet.ReadWrite.All" }, { "description": "Allows the app to create users, on behalf of the signed-in user.", @@ -2037,18 +2072,18 @@ "value": "User.Create" }, { - "description": "Allows the app to delete and restore all users, on behalf of the signed-in user.", - "displayName": "Delete and restore users", - "id": "4bb440cd-2cf2-4f90-8004-aa2acd2537c5", + "description": "Allows the app to read external authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' external authentication methods", + "id": "cbca9646-4c34-4cea-8e54-9a7088018820", "origin": "Delegated (Microsoft Graph)", - "value": "User.DeleteRestore.All" + "value": "UserAuthMethod-External.Read.All" }, { - "description": "Allows the app to enable and disable users' accounts, on behalf of the signed-in user.", - "displayName": "Enable and disable user accounts", - "id": "f92e74e7-2563-467f-9dd0-902688cb5863", + "description": "Allows the app to read and write the signed-in user's external authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's external authentication methods", + "id": "28c2e8f9-828a-4691-a090-f2f0b7fc07b3", "origin": "Delegated (Microsoft Graph)", - "value": "User.EnableDisableAccount.All" + "value": "UserAuthMethod-External.ReadWrite" }, { "description": "Allows the app to read and write external authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", @@ -2156,46 +2191,46 @@ "value": "UserAuthMethod-Password.Read.All" }, { - "description": "Allows the app to read and write the signed-in user's password authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write the signed-in user's password authentication methods", - "id": "60cce20d-d41e-4594-b391-84bbf8cc31f3", + "description": "Allows the app to read the signed-in user's external authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's external authentication methods", + "id": "d1739827-146b-4f7f-b52c-1c509253aa57", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Password.ReadWrite" + "value": "UserAuthMethod-External.Read" }, { - "description": "Allows the app to read and write password authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' password methods.", - "id": "7f5b683d-df96-4690-a88d-6e336ed6dc7c", + "description": "Allows the app to read and write email methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' email methods.", + "id": "074f680f-c89e-45be-880e-5d0642860a1c", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Password.ReadWrite.All" + "value": "UserAuthMethod-Email.ReadWrite.All" }, { - "description": "Allows the app to read and write the signed-in user's external authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write the signed-in user's external authentication methods", - "id": "28c2e8f9-828a-4691-a090-f2f0b7fc07b3", + "description": "Allows the app to read and write the signed-in user's email authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's email authentication methods", + "id": "696aa421-62dc-4c99-be16-015b23444089", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-External.ReadWrite" + "value": "UserAuthMethod-Email.ReadWrite" }, { - "description": "Allows the app to read external authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' external authentication methods", - "id": "cbca9646-4c34-4cea-8e54-9a7088018820", + "description": "Allows the app to read email methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' email methods", + "id": "76caaf3a-ebdb-40a3-9299-4196e636f290", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-External.Read.All" + "value": "UserAuthMethod-Email.Read.All" }, { - "description": "Allows the app to read the signed-in user's external authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read the signed-in user's external authentication methods", - "id": "d1739827-146b-4f7f-b52c-1c509253aa57", + "description": "Allows the app to delete and restore all users, on behalf of the signed-in user.", + "displayName": "Delete and restore users", + "id": "4bb440cd-2cf2-4f90-8004-aa2acd2537c5", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-External.Read" + "value": "User.DeleteRestore.All" }, { - "description": "Allows the app to read and write email methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' email methods.", - "id": "074f680f-c89e-45be-880e-5d0642860a1c", + "description": "Allows the app to enable and disable users' accounts, on behalf of the signed-in user.", + "displayName": "Enable and disable user accounts", + "id": "f92e74e7-2563-467f-9dd0-902688cb5863", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Email.ReadWrite.All" + "value": "User.EnableDisableAccount.All" }, { "description": "Allows the app to export data (e.g. customer content or system-generated logs), associated with any user in your company, when the app is used by a privileged user (e.g. a Company Administrator).", @@ -2239,6 +2274,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "User.ReadBasic.All" }, + { + "description": "Allows the app to read basic unified group properties, memberships and owners of the group the signed-in guest is a member of.", + "displayName": "Read unified group memberships as guest", + "id": "73e75199-7c3e-41bb-9357-167164dbb415", + "origin": "Delegated (Microsoft Graph)", + "value": "UnifiedGroupMember.Read.AsGuest" + }, { "description": "Allows the app to read and update users, on behalf of the signed-in user.", "displayName": "Read and update users", @@ -2246,20 +2288,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "User.ReadUpdate.All" }, - { - "description": "Allows the app to read your profile. It also allows the app to update your profile information on your behalf.", - "displayName": "Read and write access to user profile", - "id": "b4e74841-8e56-480b-be8b-910348b18b4c", - "origin": "Delegated (Microsoft Graph)", - "value": "User.ReadWrite" - }, - { - "description": "Allows the app to read phone authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' phone authentication methods", - "id": "20cf4ae1-09b9-4d29-a6f8-43e1820ce60c", - "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Phone.Read.All" - }, { "description": "Allows the app to read and write the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user.", "displayName": "Read and write all users' full profiles", @@ -2267,6 +2295,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "User.ReadWrite.All" }, + { + "description": "Allow the app to revoke all sign in sessions for a user, on behalf of a signed-in user.", + "displayName": "Revoke all sign in sessions for a user", + "id": "fc30e98b-8810-4501-81f5-c20a3196387b", + "origin": "Delegated (Microsoft Graph)", + "value": "User.RevokeSessions.All" + }, { "description": "Allows the app to read and report the signed-in user's activity in the app.", "displayName": "Read and write app activity to users' activity feed", @@ -2310,53 +2345,39 @@ "value": "UserAuthMethod-Email.Read" }, { - "description": "Allows the app to read email methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' email methods", - "id": "76caaf3a-ebdb-40a3-9299-4196e636f290", + "description": "Allows the app to read your profile. It also allows the app to update your profile information on your behalf.", + "displayName": "Read and write access to user profile", + "id": "b4e74841-8e56-480b-be8b-910348b18b4c", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Email.Read.All" + "value": "User.ReadWrite" }, { - "description": "Allows the app to read and write the signed-in user's email authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write the signed-in user's email authentication methods", - "id": "696aa421-62dc-4c99-be16-015b23444089", + "description": "Allows the app to read, create, and delete time-based eligibility schedules for access to Azure AD groups, on behalf of the signed-in user.", + "displayName": "Read, create, and delete eligibility schedules for access to Azure AD groups", + "id": "ba974594-d163-484e-ba39-c330d5897667", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Email.ReadWrite" + "value": "PrivilegedEligibilitySchedule.ReadWrite.AzureADGroup" }, { - "description": "Allow the app to revoke all sign in sessions for a user, on behalf of a signed-in user.", - "displayName": "Revoke all sign in sessions for a user", - "id": "fc30e98b-8810-4501-81f5-c20a3196387b", + "description": "Allows the app to read time-based eligibility schedules for access to Azure AD groups, on behalf of the signed-in user.", + "displayName": "Read eligibility schedules for access to Azure AD groups", + "id": "8f44f93d-ecef-46ae-a9bf-338508d44d6b", "origin": "Delegated (Microsoft Graph)", - "value": "User.RevokeSessions.All" + "value": "PrivilegedEligibilitySchedule.Read.AzureADGroup" }, { - "description": "Allows the app to read all profile photos of users and groups, on behalf of the signed-in user.", - "displayName": "Read profile photo of a user or group", - "id": "469cd065-729e-4dee-b1fa-d92e0fab6310", + "description": "Allows the application to manage file storage container type registrations on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", + "displayName": "Manage file storage container type registrations on behalf of the signed in user", + "id": "c319a7df-930e-44c0-a43b-7e5e9c7f4f24", "origin": "Delegated (Microsoft Graph)", - "value": "ProfilePhoto.Read.All" + "value": "FileStorageContainerTypeReg.Manage.All" }, { - "description": "Allows the app to see your users' basic profile (e.g., name, picture, user name, email address)", - "displayName": "View users' basic profile", - "id": "14dad69e-099b-42c9-810b-d002981feec1", + "description": "Allows the application to manage selected file storage container type registrations on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", + "displayName": "Access selected file storage container type registrations.", + "id": "d1e4f63a-1569-475c-b9b2-bdc140405e38", "origin": "Delegated (Microsoft Graph)", - "value": "profile" - }, - { - "description": "Allows the app to delete time-based eligibility schedules for access to Azure AD groups, on behalf of the signed-in user.", - "displayName": "Delete eligibility schedules for access to Azure AD groups", - "id": "c5ea9ab4-9b41-4c09-a400-53e652fb5096", - "origin": "Delegated (Microsoft Graph)", - "value": "PrivilegedEligibilitySchedule.Remove.AzureADGroup" - }, - { - "description": "Allows the application to manage selected file storage container type registrations on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", - "displayName": "Access selected file storage container type registrations.", - "id": "d1e4f63a-1569-475c-b9b2-bdc140405e38", - "origin": "Delegated (Microsoft Graph)", - "value": "FileStorageContainerTypeReg.Selected" + "value": "FileStorageContainerTypeReg.Selected" }, { "description": "Allows the app to read and write financials data on behalf of the signed-in user.", @@ -2463,6 +2484,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "Group-XTenantIdentitySync.Read.All" }, + { + "description": "Allows the application to manage file storage container types on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", + "displayName": "Manage file storage container types on behalf of the signed in user", + "id": "8e6ec84c-5fcd-4cc7-ac8a-2296efc0ed9b", + "origin": "Delegated (Microsoft Graph)", + "value": "FileStorageContainerType.Manage.All" + }, { "description": "Allows the app to read all scenario health monitoring alerts", "displayName": "Read all scenario health monitoring alerts", @@ -2471,32 +2499,25 @@ "value": "HealthMonitoringAlert.Read.All" }, { - "description": "Allows the application to manage file storage container type registrations on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", - "displayName": "Manage file storage container type registrations on behalf of the signed in user", - "id": "c319a7df-930e-44c0-a43b-7e5e9c7f4f24", - "origin": "Delegated (Microsoft Graph)", - "value": "FileStorageContainerTypeReg.Manage.All" - }, - { - "description": "Allows the app to read and write all scenario monitoring alerts, on behalf of the signed-in user.", - "displayName": "Read and write all scenario monitoring alerts", - "id": "b7c60f27-2195-4d5f-96a7-6b98bdfd9664", + "description": "Allows the application to utilize the file storage container platform to manage containers on behalf of the signed in user. The specific file storage containers and the permissions granted to them will be configured in Microsoft 365 by the developer of each container type.", + "displayName": "Access selected file storage containers", + "id": "085ca537-6565-41c2-aca7-db852babc212", "origin": "Delegated (Microsoft Graph)", - "value": "HealthMonitoringAlert.ReadWrite.All" + "value": "FileStorageContainer.Selected" }, { - "description": "Allows the application to manage file storage container types on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", - "displayName": "Manage file storage container types on behalf of the signed in user", - "id": "8e6ec84c-5fcd-4cc7-ac8a-2296efc0ed9b", + "description": "Allow the application to access files explicitly permissioned to the application on behalf of the signed in user. The specific files and the permissions granted will be configured in SharePoint Online or OneDrive.", + "displayName": "Access selected Files, on behalf of the signed-in user", + "id": "ef2779dc-ef1b-4211-8310-8a0ac2450081", "origin": "Delegated (Microsoft Graph)", - "value": "FileStorageContainerType.Manage.All" + "value": "Files.SelectedOperations.Selected" }, { - "description": "Allows the application to utilize the file storage container administration capabilities on behalf of an administrator user.", - "displayName": "Manage all file storage containers", - "id": "527b6d64-cdf5-4b8b-b336-4aa0b8ca2ce5", + "description": "Allows the app to search the email message trace on behalf of the signed-in user.", + "displayName": "Search the email message trace", + "id": "b2e7d27e-14e7-41ad-bb15-a88ceb9c3e90", "origin": "Delegated (Microsoft Graph)", - "value": "FileStorageContainer.Manage.All" + "value": "ExchangeMessageTrace.Read.All" }, { "description": "Allows the app to read all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", @@ -2611,18 +2632,18 @@ "value": "Files.ReadWrite.Selected" }, { - "description": "Allow the application to access files explicitly permissioned to the application on behalf of the signed in user. The specific files and the permissions granted will be configured in SharePoint Online or OneDrive.", - "displayName": "Access selected Files, on behalf of the signed-in user", - "id": "ef2779dc-ef1b-4211-8310-8a0ac2450081", + "description": "Allows the application to utilize the file storage container administration capabilities on behalf of an administrator user.", + "displayName": "Manage all file storage containers", + "id": "527b6d64-cdf5-4b8b-b336-4aa0b8ca2ce5", "origin": "Delegated (Microsoft Graph)", - "value": "Files.SelectedOperations.Selected" + "value": "FileStorageContainer.Manage.All" }, { - "description": "Allows the application to utilize the file storage container platform to manage containers on behalf of the signed in user. The specific file storage containers and the permissions granted to them will be configured in Microsoft 365 by the developer of each container type.", - "displayName": "Access selected file storage containers", - "id": "085ca537-6565-41c2-aca7-db852babc212", + "description": "Allows the app to read and write all scenario monitoring alerts, on behalf of the signed-in user.", + "displayName": "Read and write all scenario monitoring alerts", + "id": "b7c60f27-2195-4d5f-96a7-6b98bdfd9664", "origin": "Delegated (Microsoft Graph)", - "value": "FileStorageContainer.Selected" + "value": "HealthMonitoringAlert.ReadWrite.All" }, { "description": "Allows the app to read all scenario health monitoring alert configurations", @@ -2639,11 +2660,39 @@ "value": "HealthMonitoringAlertConfig.ReadWrite.All" }, { - "description": "Allows the app to read identity notification settings, email templates, and prerequisites on behalf of the signed-in user.", - "displayName": "Read identity notification settings and templates", - "id": "59cd3e28-aa9c-4f72-a734-1b592eb06853", + "description": "Allows the app to upload data files to a data connector on behalf of the signed-in user.", + "displayName": "Upload files to a data connector", + "id": "fc47391d-ab2c-410f-9059-5600f7af660d", "origin": "Delegated (Microsoft Graph)", - "value": "IdentityNotifications.Read.All" + "value": "IndustryData-DataConnector.Upload" + }, + { + "description": "Allows the app to read inbound data flows on behalf of the signed-in user.", + "displayName": "View inbound flow definitions", + "id": "cb0774da-a605-42af-959c-32f438fb38f4", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-InboundFlow.Read.All" + }, + { + "description": "Allows the app to read and write inbound data flows on behalf of the signed-in user.", + "displayName": "Manage inbound flow definitions", + "id": "97044676-2cec-40ee-bd70-38df444c9e70", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-InboundFlow.ReadWrite.All" + }, + { + "description": "Allows the app to read outbound data flows on behalf of the signed-in user.", + "displayName": "View outbound flow definitions", + "id": "4741a003-8952-4be4-9217-33a0ac327122", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-OutboundFlow.Read.All" + }, + { + "description": "Allows the app to read and write outbound data flows on behalf of the signed-in user.", + "displayName": "Manage outbound flow definitions", + "id": "aeb68e0b-e562-4a1f-b6dd-3484ad0cbb4b", + "origin": "Delegated (Microsoft Graph)", + "value": "IndustryData-OutboundFlow.ReadWrite.All" }, { "description": "Allows the app to read reference definitions on behalf of the signed-in user.", @@ -2730,67 +2779,67 @@ "value": "LearningAssignedCourse.Read" }, { - "description": "Allows the app to read learning content in the organization's directory, on behalf of the signed-in user.", - "displayName": "Read learning content", - "id": "ea4c1fd9-6a9f-4432-8e5d-86e06cc0da77", + "description": "Allows the app to read and write data connectors on behalf of the signed-in user.", + "displayName": "Manage data connector definitions", + "id": "5ce933ac-3997-4280-aed0-cc072e5c062a", "origin": "Delegated (Microsoft Graph)", - "value": "LearningContent.Read.All" + "value": "IndustryData-DataConnector.ReadWrite.All" }, { - "description": "Allows the app to manage learning content in the organization's directory, on behalf of the signed-in user.", - "displayName": "Manage learning content", - "id": "53cec1c4-a65f-4981-9dc1-ad75dbf1c077", + "description": "Allows the app to read data connectors on behalf of the signed-in user.", + "displayName": "View data connector definitions", + "id": "d19c0de5-7ecb-4aba-b090-da35ebcd5425", "origin": "Delegated (Microsoft Graph)", - "value": "LearningContent.ReadWrite.All" + "value": "IndustryData-DataConnector.Read.All" }, { - "description": "Allows the app to read data for the learning provider in the organization's directory, on behalf of the signed-in user.", - "displayName": "Read learning provider", - "id": "dd8ce36f-9245-45ea-a99e-8ac398c22861", + "description": "Allows the app to read basic Industry Data service and resource information on behalf of the signed-in user.", + "displayName": "Read basic Industry Data service and resource definitions", + "id": "60382b96-1f5e-46ea-a544-0407e489e588", "origin": "Delegated (Microsoft Graph)", - "value": "LearningProvider.Read" + "value": "IndustryData.ReadBasic.All" }, { - "description": "Allows the app to create, update, read, and delete data for the learning provider in the organization's directory, on behalf of the signed-in user.", - "displayName": "Manage learning provider", - "id": "40c2eb57-abaf-49f5-9331-e90fd01f7130", + "description": "Allows the app to have the same access to mailboxes as the signed-in user via IMAP protocol.", + "displayName": "Read and write access to mailboxes via IMAP.", + "id": "652390e4-393a-48de-9484-05f9b1212954", "origin": "Delegated (Microsoft Graph)", - "value": "LearningProvider.ReadWrite" + "value": "IMAP.AccessAsUser.All" }, { - "description": "Allows the app to read data for the learner's self-initiated courses in the organization's directory, on behalf of the signed-in user.", - "displayName": "Read user's self-initiated courses", - "id": "f6403ef7-4a96-47be-a190-69ba274c3f11", + "description": "Allows the app to read own identity diagnostics information, including symptoms, runs, statuses, and results for the signed-in user", + "displayName": "Read your identity diagnostics", + "id": "3839e465-e636-4c8e-b959-340182fb0567", "origin": "Delegated (Microsoft Graph)", - "value": "LearningSelfInitiatedCourse.Read" + "value": "IdentityDiagnostic.Read" }, { - "description": "Allows the app to read and write outbound data flows on behalf of the signed-in user.", - "displayName": "Manage outbound flow definitions", - "id": "aeb68e0b-e562-4a1f-b6dd-3484ad0cbb4b", + "description": "Allows the app to read all identity diagnostics information, including symptoms, runs, statuses, and results for all users in the organization, on behalf of the signed-in user.", + "displayName": "Read all identity diagnostics", + "id": "9181fb3f-4b8e-45ef-98ae-41774b813b80", "origin": "Delegated (Microsoft Graph)", - "value": "IndustryData-OutboundFlow.ReadWrite.All" + "value": "IdentityDiagnostic.Read.All" }, { - "description": "Allows the app to read outbound data flows on behalf of the signed-in user.", - "displayName": "View outbound flow definitions", - "id": "4741a003-8952-4be4-9217-33a0ac327122", + "description": "Allows the app to start identity diagnostic processes for the signed-in user.", + "displayName": "Start identity diagnostics", + "id": "1ad58246-a11b-4ea3-9b75-8b6c315cbe21", "origin": "Delegated (Microsoft Graph)", - "value": "IndustryData-OutboundFlow.Read.All" + "value": "IdentityDiagnostic.StartDiagnosis" }, { - "description": "Allows the app to read and write inbound data flows on behalf of the signed-in user.", - "displayName": "Manage inbound flow definitions", - "id": "97044676-2cec-40ee-bd70-38df444c9e70", + "description": "Allows the app to start identity diagnostic processes for all users in the organization, on behalf of the signed-in user.", + "displayName": "Start identity diagnostics for all users", + "id": "51470ff5-62b6-4aef-9a3a-d8c8a1e66d09", "origin": "Delegated (Microsoft Graph)", - "value": "IndustryData-InboundFlow.ReadWrite.All" + "value": "IdentityDiagnostic.StartDiagnosis.All" }, { - "description": "Allows the app to read inbound data flows on behalf of the signed-in user.", - "displayName": "View inbound flow definitions", - "id": "cb0774da-a605-42af-959c-32f438fb38f4", + "description": "Allows the app to read identity notification settings, email templates, and prerequisites on behalf of the signed-in user.", + "displayName": "Read identity notification settings and templates", + "id": "59cd3e28-aa9c-4f72-a734-1b592eb06853", "origin": "Delegated (Microsoft Graph)", - "value": "IndustryData-InboundFlow.Read.All" + "value": "IdentityNotifications.Read.All" }, { "description": "Allows the app to read and write identity notification settings, customize email templates, and send test emails on behalf of the signed-in user.", @@ -2813,6 +2862,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "IdentityProvider.ReadWrite.All" }, + { + "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange Web Services.", + "displayName": "Access mailboxes as the signed-in user via Exchange Web Services", + "id": "9769c687-087d-48ac-9cb3-c37dde652038", + "origin": "Delegated (Microsoft Graph)", + "value": "EWS.AccessAsUser.All" + }, { "description": "Allows the app to read identity risk event information for all users in your organization on behalf of the signed-in user.", "displayName": "Read identity risk event information", @@ -2820,13 +2876,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "IdentityRiskEvent.Read.All" }, - { - "description": "Allows the app to read and update identity risk event information for all users in your organization on behalf of the signed-in user. Update operations include confirming risk event detections. ", - "displayName": "Read and write risk event information", - "id": "9e4862a5-b68f-479e-848a-4e07e25c9916", - "origin": "Delegated (Microsoft Graph)", - "value": "IdentityRiskEvent.ReadWrite.All" - }, { "description": "Allows the app to read risky agents information in your organization, on behalf of the signed-in user.", "displayName": "Read risky agents information", @@ -2848,13 +2897,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "IdentityRiskyServicePrincipal.Read.All" }, - { - "description": "Allows the app to search the email message trace on behalf of the signed-in user.", - "displayName": "Search the email message trace", - "id": "b2e7d27e-14e7-41ad-bb15-a88ceb9c3e90", - "origin": "Delegated (Microsoft Graph)", - "value": "ExchangeMessageTrace.Read.All" - }, { "description": "Allows the app to read and update identity risky service principal information for all service principals in your organization, on behalf of the signed-in user. Update operations include dismissing risky service principals.", "displayName": "Read and write all identity risky service principal information", @@ -2862,6 +2904,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "IdentityRiskyServicePrincipal.ReadWrite.All" }, + { + "description": "Allows the app to read identity risky user information for all users in your organization on behalf of the signed-in user.", + "displayName": "Read identity risky user information", + "id": "d04bb851-cb7c-4146-97c7-ca3e71baf56c", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityRiskyUser.Read.All" + }, { "description": "Allows the app to read and update identity risky user information for all users in your organization on behalf of the signed-in user. Update operations include dismissing risky users.", "displayName": "Read and write risky user information", @@ -2884,67 +2933,39 @@ "value": "IdentityUserFlow.ReadWrite.All" }, { - "description": "Allows the app to have the same access to mailboxes as the signed-in user via IMAP protocol.", - "displayName": "Read and write access to mailboxes via IMAP.", - "id": "652390e4-393a-48de-9484-05f9b1212954", - "origin": "Delegated (Microsoft Graph)", - "value": "IMAP.AccessAsUser.All" - }, - { - "description": "Allows the app to read basic Industry Data service and resource information on behalf of the signed-in user.", - "displayName": "Read basic Industry Data service and resource definitions", - "id": "60382b96-1f5e-46ea-a544-0407e489e588", - "origin": "Delegated (Microsoft Graph)", - "value": "IndustryData.ReadBasic.All" - }, - { - "description": "Allows the app to read data connectors on behalf of the signed-in user.", - "displayName": "View data connector definitions", - "id": "d19c0de5-7ecb-4aba-b090-da35ebcd5425", - "origin": "Delegated (Microsoft Graph)", - "value": "IndustryData-DataConnector.Read.All" - }, - { - "description": "Allows the app to read and write data connectors on behalf of the signed-in user.", - "displayName": "Manage data connector definitions", - "id": "5ce933ac-3997-4280-aed0-cc072e5c062a", - "origin": "Delegated (Microsoft Graph)", - "value": "IndustryData-DataConnector.ReadWrite.All" - }, - { - "description": "Allows the app to upload data files to a data connector on behalf of the signed-in user.", - "displayName": "Upload files to a data connector", - "id": "fc47391d-ab2c-410f-9059-5600f7af660d", + "description": "Allows the app to read and update identity risk event information for all users in your organization on behalf of the signed-in user. Update operations include confirming risk event detections. ", + "displayName": "Read and write risk event information", + "id": "9e4862a5-b68f-479e-848a-4e07e25c9916", "origin": "Delegated (Microsoft Graph)", - "value": "IndustryData-DataConnector.Upload" + "value": "IdentityRiskEvent.ReadWrite.All" }, { - "description": "Allows the app to read identity risky user information for all users in your organization on behalf of the signed-in user.", - "displayName": "Read identity risky user information", - "id": "d04bb851-cb7c-4146-97c7-ca3e71baf56c", + "description": "Allows the app to read learning content in the organization's directory, on behalf of the signed-in user.", + "displayName": "Read learning content", + "id": "ea4c1fd9-6a9f-4432-8e5d-86e06cc0da77", "origin": "Delegated (Microsoft Graph)", - "value": "IdentityRiskyUser.Read.All" + "value": "LearningContent.Read.All" }, { - "description": "Allows an app to read license assignments for users and groups, on behalf of the signed-in user.", - "displayName": "Read all license assignments.", - "id": "f395577a-0960-456b-979f-7228de0c5996", + "description": "Allows the app to read or write your organization's authentication event listeners on behalf of the signed-in user.", + "displayName": "Read and write your organization's authentication event listeners", + "id": "d11625a6-fe21-4fc6-8d3d-063eba5525ad", "origin": "Delegated (Microsoft Graph)", - "value": "LicenseAssignment.Read.All" + "value": "EventListener.ReadWrite.All" }, { - "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange Web Services.", - "displayName": "Access mailboxes as the signed-in user via Exchange Web Services", - "id": "9769c687-087d-48ac-9cb3-c37dde652038", + "description": "Allows the app to list the all the snapshots, create a recovery job and enumerate the changes of a specific recovery job, on behalf of the signed-in user.", + "displayName": "Create preview and recovery job, read recovery job and snapshots", + "id": "8269c6ff-41d7-4172-a783-b2ce38322e42", "origin": "Delegated (Microsoft Graph)", - "value": "EWS.AccessAsUser.All" + "value": "EntraBackup.ReadWrite.Recovery" }, { - "description": "Allows the app to read your organization's authentication event listeners on behalf of the signed-in user.", - "displayName": "Read your organization's authentication event listeners", - "id": "f7dd3bed-5eec-48da-bc73-1c0ef50bc9a1", + "description": "Allows the app to create device objects based on device templates owned by the signed-in user, on behalf of the signed in user.", + "displayName": "Create devices based on owned device templates", + "id": "edc92e89-a987-48a9-911a-a7b1967dd7b1", "origin": "Delegated (Microsoft Graph)", - "value": "EventListener.Read.All" + "value": "Device.CreateFromOwnedTemplate" }, { "description": "Allows the app to read a user's list of devices on behalf of the signed-in user.", @@ -3059,39 +3080,39 @@ "value": "DeviceManagementRBAC.Read.All" }, { - "description": "Allows the app to read and write the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings.", - "displayName": "Read and write Microsoft Intune RBAC settings", - "id": "0c5e8a55-87a6-4556-93ab-adc52c4d862d", + "description": "Allows the app to launch another app or communicate with another app on a user's device on behalf of the signed-in user.", + "displayName": "Communicate with user devices", + "id": "bac3b9c2-b516-4ef4-bd3b-c2ef73d8d804", "origin": "Delegated (Microsoft Graph)", - "value": "DeviceManagementRBAC.ReadWrite.All" + "value": "Device.Command" }, { - "description": "Allows the app to create device objects based on device templates owned by the signed-in user, on behalf of the signed in user.", - "displayName": "Create devices based on owned device templates", - "id": "edc92e89-a987-48a9-911a-a7b1967dd7b1", + "description": "Allows the app to read and write the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings.", + "displayName": "Read and write Microsoft Intune RBAC settings", + "id": "0c5e8a55-87a6-4556-93ab-adc52c4d862d", "origin": "Delegated (Microsoft Graph)", - "value": "Device.CreateFromOwnedTemplate" + "value": "DeviceManagementRBAC.ReadWrite.All" }, { - "description": "Allows the app to read Microsoft Intune device compliance scripts, device management scripts, device shell scripts, device custom attribute shell scripts and device health scripts on behalf of the signed in user.", - "displayName": "Read Microsoft Intune Scripts", - "id": "d32381d8-ee89-4220-9c83-b672aa68d404", + "description": "Allows the app to manage permission grants for delegated permissions exposed by any API (including Microsoft Graph), on behalf of the signed in user.", + "displayName": "Manage all delegated permission grants", + "id": "41ce6ca6-6826-4807-84f1-1c82854f7ee5", "origin": "Delegated (Microsoft Graph)", - "value": "DeviceManagementScripts.Read.All" + "value": "DelegatedPermissionGrant.ReadWrite.All" }, { - "description": "Allows the app to launch another app or communicate with another app on a user's device on behalf of the signed-in user.", - "displayName": "Communicate with user devices", - "id": "bac3b9c2-b516-4ef4-bd3b-c2ef73d8d804", + "description": "Allows the app to manage (create-update-terminate) Delegated Admin relationships with customers as well as role assignments to security groups for active Delegated Admin relationships on behalf of the signed-in user.", + "displayName": "Manage Delegated Admin relationships with customers", + "id": "885f682f-a990-4bad-a642-36736a74b0c7", "origin": "Delegated (Microsoft Graph)", - "value": "Device.Command" + "value": "DelegatedAdminRelationship.ReadWrite.All" }, { - "description": "Allows the app to read delegated permission grants, on behalf of the signed in user.", - "displayName": "Read delegated permission grants", - "id": "a197cdc4-a8e8-4d49-9d35-4ca7c83887b4", + "description": "Allows the application to list and query any shared user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant on behalf of the signed-in user.", + "displayName": "Read all shared cross-tenant user profiles and export their data", + "id": "759dcd16-3c90-463c-937e-abf89f991c18", "origin": "Delegated (Microsoft Graph)", - "value": "DelegatedPermissionGrant.Read.All" + "value": "CrossTenantUserProfileSharing.Read.All" }, { "description": "Allows the application to list and query user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export and remove external user data (e.g. customer content or system-generated logs), associated with the current tenant on behalf of the signed-in user.", @@ -3206,18 +3227,18 @@ "value": "DelegatedAdminRelationship.Read.All" }, { - "description": "Allows the app to manage (create-update-terminate) Delegated Admin relationships with customers as well as role assignments to security groups for active Delegated Admin relationships on behalf of the signed-in user.", - "displayName": "Manage Delegated Admin relationships with customers", - "id": "885f682f-a990-4bad-a642-36736a74b0c7", + "description": "Allows the app to read delegated permission grants, on behalf of the signed in user.", + "displayName": "Read delegated permission grants", + "id": "a197cdc4-a8e8-4d49-9d35-4ca7c83887b4", "origin": "Delegated (Microsoft Graph)", - "value": "DelegatedAdminRelationship.ReadWrite.All" + "value": "DelegatedPermissionGrant.Read.All" }, { - "description": "Allows the app to manage permission grants for delegated permissions exposed by any API (including Microsoft Graph), on behalf of the signed in user.", - "displayName": "Manage all delegated permission grants", - "id": "41ce6ca6-6826-4807-84f1-1c82854f7ee5", + "description": "Allows the app to read Microsoft Intune device compliance scripts, device management scripts, device shell scripts, device custom attribute shell scripts and device health scripts on behalf of the signed in user.", + "displayName": "Read Microsoft Intune Scripts", + "id": "d32381d8-ee89-4220-9c83-b672aa68d404", "origin": "Delegated (Microsoft Graph)", - "value": "DelegatedPermissionGrant.ReadWrite.All" + "value": "DeviceManagementScripts.Read.All" }, { "description": "Allows the app to read and write Microsoft Intune device compliance scripts, device management scripts, device shell scripts, device custom attribute shell scripts and device health scripts on behalf of the signed in user.", @@ -3234,11 +3255,11 @@ "value": "DeviceManagementServiceConfig.Read.All" }, { - "description": "Allows the app to read and write Microsoft Intune service properties including device enrollment and third party service connection configuration.", - "displayName": "Read and write Microsoft Intune configuration", - "id": "662ed50a-ac44-4eef-ad86-62eed9be2a29", + "description": "Allows the app to read the user's modules and resources on behalf of the signed-in user.", + "displayName": "Read the user's class modules and resources", + "id": "484859e8-b9e2-4e92-b910-84db35dadd29", "origin": "Delegated (Microsoft Graph)", - "value": "DeviceManagementServiceConfig.ReadWrite.All" + "value": "EduCurricula.Read" }, { "description": "Allows the app to read and write user's modules and resources on behalf of the signed-in user.", @@ -3352,20 +3373,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "EntraBackup.ReadWrite.Preview" }, - { - "description": "Allows the app to list the all the snapshots, create a recovery job and enumerate the changes of a specific recovery job, on behalf of the signed-in user.", - "displayName": "Create preview and recovery job, read recovery job and snapshots", - "id": "8269c6ff-41d7-4172-a783-b2ce38322e42", - "origin": "Delegated (Microsoft Graph)", - "value": "EntraBackup.ReadWrite.Recovery" - }, - { - "description": "Allows the app to read the user's modules and resources on behalf of the signed-in user.", - "displayName": "Read the user's class modules and resources", - "id": "484859e8-b9e2-4e92-b910-84db35dadd29", - "origin": "Delegated (Microsoft Graph)", - "value": "EduCurricula.Read" - }, { "description": "Allows the app to read and write assignments without grades on behalf of the user.", "displayName": "Read and write users' class assignments without grades", @@ -3387,6 +3394,20 @@ "origin": "Delegated (Microsoft Graph)", "value": "EduAssignments.ReadBasic" }, + { + "description": "Allows the app to read assignments and their grades on behalf of the user.", + "displayName": "Read users' class assignments and their grades", + "id": "091460c9-9c4a-49b2-81ef-1f3d852acce2", + "origin": "Delegated (Microsoft Graph)", + "value": "EduAssignments.Read" + }, + { + "description": "Allows the app to read and write Microsoft Intune service properties including device enrollment and third party service connection configuration.", + "displayName": "Read and write Microsoft Intune configuration", + "id": "662ed50a-ac44-4eef-ad86-62eed9be2a29", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementServiceConfig.ReadWrite.All" + }, { "description": "Allows the app to create device templates on behalf of the signed in user. The user is marked as owners of the created device template. As a member of owners, the user will be allowed to manage devices created from the template.", "displayName": "Create device templates", @@ -3436,6 +3457,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "DirectoryRecommendations.Read.All" }, + { + "description": "Allows the app to read your organization's authentication event listeners on behalf of the signed-in user.", + "displayName": "Read your organization's authentication event listeners", + "id": "f7dd3bed-5eec-48da-bc73-1c0ef50bc9a1", + "origin": "Delegated (Microsoft Graph)", + "value": "EventListener.Read.All" + }, { "description": "Allows the app to read and update Azure AD recommendations, on behalf of the signed-in user.", "displayName": "Read and update Azure AD recommendations", @@ -3444,18 +3472,11 @@ "value": "DirectoryRecommendations.ReadWrite.All" }, { - "description": "Allows the app to read or write your organization's authentication event listeners on behalf of the signed-in user.", - "displayName": "Read and write your organization's authentication event listeners", - "id": "d11625a6-fe21-4fc6-8d3d-063eba5525ad", - "origin": "Delegated (Microsoft Graph)", - "value": "EventListener.ReadWrite.All" - }, - { - "description": "Allows the app to read all domain properties on behalf of the signed-in user.", - "displayName": "Read domains.", - "id": "2f9ee017-59c1-4f1d-9472-bd5529a7b311", + "description": "Allows the app to read and write all domain properties on behalf of the signed-in user. Also allows the app to add, verify and remove domains.", + "displayName": "Read and write domains", + "id": "0b5d694c-a244-4bde-86e6-eb5cd07730fe", "origin": "Delegated (Microsoft Graph)", - "value": "Domain.Read.All" + "value": "Domain.ReadWrite.All" }, { "description": "Allows the app to read internal federation configuration for a domain.", @@ -3507,39 +3528,60 @@ "value": "EduAdministration.ReadWrite" }, { - "description": "Allows the app to read assignments and their grades on behalf of the user.", - "displayName": "Read users' class assignments and their grades", - "id": "091460c9-9c4a-49b2-81ef-1f3d852acce2", + "description": "Allows the app to read all domain properties on behalf of the signed-in user.", + "displayName": "Read domains.", + "id": "2f9ee017-59c1-4f1d-9472-bd5529a7b311", "origin": "Delegated (Microsoft Graph)", - "value": "EduAssignments.Read" + "value": "Domain.Read.All" }, { - "description": "Allows the app to read and write all domain properties on behalf of the signed-in user. Also allows the app to add, verify and remove domains.", - "displayName": "Read and write domains", - "id": "0b5d694c-a244-4bde-86e6-eb5cd07730fe", + "description": "Allows the app to manage learning content in the organization's directory, on behalf of the signed-in user.", + "displayName": "Manage learning content", + "id": "53cec1c4-a65f-4981-9dc1-ad75dbf1c077", "origin": "Delegated (Microsoft Graph)", - "value": "Domain.ReadWrite.All" + "value": "LearningContent.ReadWrite.All" }, { - "description": "Allows the Application to read and write the user's data pertaining to itself in the Intune Mobile Application Management service", - "displayName": "Read and Write the User's App Management data", - "id": "3c7192af-9629-4473-9276-d35e4e4b36c5", - "origin": "Delegated (Microsoft Mobile Application Management)", - "value": "DeviceManagementManagedApps.ReadWrite" + "description": "Allows the app to read data for the learning provider in the organization's directory, on behalf of the signed-in user.", + "displayName": "Read learning provider", + "id": "dd8ce36f-9245-45ea-a99e-8ac398c22861", + "origin": "Delegated (Microsoft Graph)", + "value": "LearningProvider.Read" }, { - "description": "Allows an app to manage license assignments for users and groups, on behalf of the signed-in user.", - "displayName": "Manage all license assignments", - "id": "f55016cc-149c-447e-8f21-7cf3ec1d6350", + "description": "Allows the app to create, update, read, and delete data for the learning provider in the organization's directory, on behalf of the signed-in user.", + "displayName": "Manage learning provider", + "id": "40c2eb57-abaf-49f5-9331-e90fd01f7130", "origin": "Delegated (Microsoft Graph)", - "value": "LicenseAssignment.ReadWrite.All" + "value": "LearningProvider.ReadWrite" }, { - "description": "Allows the app to read, create, update and delete identity lifecycle policies for agent identities that the signed-in user has access to in the organization.", - "displayName": "Read and write identity lifecycle policies for agent identities", - "id": "f2292ca5-46fc-4195-9b4d-16491bf9bf7f", + "description": "Allows the app to read policies related to consent and permission grants for applications, on behalf of the signed-in user.", + "displayName": "Read consent and permission grant policies", + "id": "414de6ea-2d92-462f-b120-6e2a809a6d01", "origin": "Delegated (Microsoft Graph)", - "value": "LifecyclePolicies-AgentId.ReadWrite.All" + "value": "Policy.Read.PermissionGrant" + }, + { + "description": "Allows the application to read the organization's recovery policy on behalf of the signed-in user.", + "displayName": "Read your organization's recovery policy", + "id": "61faa1e9-0931-4f9a-94ba-bc2e3505c685", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.Recovery" + }, + { + "description": "Allows the app to read and write your organization's directory access review default policy on behalf of the signed-in user.", + "displayName": "Read and write your organization's directory access review default policy", + "id": "4f5bc9c8-ea54-4772-973a-9ca119cb0409", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.AccessReview" + }, + { + "description": "Allows the app to read and write your organization's application configuration policies on behalf of the signed-in user. This includes policies such as activityBasedTimeoutPolicy, claimsMappingPolicy, homeRealmDiscoveryPolicy, tokenIssuancePolicy and tokenLifetimePolicy.", + "displayName": "Read and write your organization's application configuration policies", + "id": "b27add92-efb2-4f16-84f5-8108ba77985c", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.ApplicationConfiguration" }, { "description": "Allows the app to read and write the authentication flow policies, on behalf of the signed-in user.", @@ -3632,6 +3674,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "Policy.ReadWrite.IdentityProtection" }, + { + "description": "Allows the app to read your organization’s identity protection policy on behalf of the signed-in user.", + "displayName": "Read your organization’s identity protection policy", + "id": "d146432f-b803-4ed4-8d42-ba74193a6ede", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.IdentityProtection" + }, { "description": "Allows the app to read and write your organization's mobility management policies on behalf of the signed-in user. For example, a mobility management policy can set the enrollment scope for a given mobility management application.", "displayName": "Read and write your organization's mobility management policies", @@ -3640,53 +3689,46 @@ "value": "Policy.ReadWrite.MobilityManagement" }, { - "description": "Allows the app to manage policies related to consent and permission grants for applications, on behalf of the signed-in user.", - "displayName": "Manage consent and permission grant policies", - "id": "2672f8bb-fd5e-42e0-85e1-ec764dd2614e", - "origin": "Delegated (Microsoft Graph)", - "value": "Policy.ReadWrite.PermissionGrant" - }, - { - "description": "Allows the application to read and update the organization's recovery policy on behalf of the signed-in user.", - "displayName": "Read and write your organization's recovery policy", - "id": "1e7a2f4c-e602-4b1b-9547-304dd65c4cc2", + "description": "Allows the app to read your organization's device configuration policies on behalf of the signed-in user. For example, device registration policy can limit initial provisioning controls using quota restrictions, additional authentication and authorization checks.", + "displayName": "Read your organization's device configuration policies", + "id": "3616a4b0-6746-49c4-a678-4c237599074d", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.ReadWrite.Recovery" + "value": "Policy.Read.DeviceConfiguration" }, { - "description": "Allows the app to read and write your organization's security defaults policy on behalf of the signed-in user.", - "displayName": "Read and write your organization's security defaults policy", - "id": "0b2a744c-2abf-4f1e-ad7e-17a087e2be99", + "description": "Allows the app to read your organization's conditional access policies on behalf of the signed-in user.", + "displayName": "Read your organization's conditional access policies", + "id": "633e0fce-8c58-4cfb-9495-12bbd5a24f7c", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.ReadWrite.SecurityDefaults" + "value": "Policy.Read.ConditionalAccess" }, { - "description": "Allows the app to read and write your organization's application configuration policies on behalf of the signed-in user. This includes policies such as activityBasedTimeoutPolicy, claimsMappingPolicy, homeRealmDiscoveryPolicy, tokenIssuancePolicy and tokenLifetimePolicy.", - "displayName": "Read and write your organization's application configuration policies", - "id": "b27add92-efb2-4f16-84f5-8108ba77985c", + "description": "Allows the app to read and write organization-wide Microsoft To Do settings on behalf of the signed-in user.", + "displayName": "Read and write organization-wide Microsoft To Do settings", + "id": "087502c2-5263-433e-abe3-8f77231a0627", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.ReadWrite.ApplicationConfiguration" + "value": "OrgSettings-Todo.ReadWrite.All" }, { - "description": "Allows the app to read and write your organization's trust framework policies on behalf of the signed-in user.", - "displayName": "Read and write your organization's trust framework policies", - "id": "cefba324-1a70-4a6e-9c1d-fd670b7ae392", + "description": "Allows the app to read all of billing data from Microsoft for your company's tenant, on behalf of the signed-in user. This includes reading billed and unbilled Usage and Invoice reconciliation data.", + "displayName": "Read all billing data for your company's tenant", + "id": "8804798e-5934-4e30-8ce3-ef88257cecd4", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.ReadWrite.TrustFramework" + "value": "PartnerBilling.Read.All" }, { - "description": "Allows the app to read and write your organization's directory access review default policy on behalf of the signed-in user.", - "displayName": "Read and write your organization's directory access review default policy", - "id": "4f5bc9c8-ea54-4772-973a-9ca119cb0409", + "description": "Allows the app to read security alerts of customer with CSP relationship on behalf of the partner signed-in user.", + "displayName": "Read security alerts of customer with CSP relationship", + "id": "5567b981-0bf1-4796-9038-0648b46e116d", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.ReadWrite.AccessReview" + "value": "PartnerSecurity.Read.All" }, { - "description": "Allows the app to read policies related to consent and permission grants for applications, on behalf of the signed-in user.", - "displayName": "Read consent and permission grant policies", - "id": "414de6ea-2d92-462f-b120-6e2a809a6d01", + "description": "Allows the app to read security alerts and update status of alerts of customer with CSP relationship on behalf of the partner signed-in user.", + "displayName": "Read security alerts and update status of security alerts of customer with CSP relationship", + "id": "0cd2c1f6-94a1-4075-ab8c-0b1aff2e1ad5", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.Read.PermissionGrant" + "value": "PartnerSecurity.ReadWrite.All" }, { "description": "Allows the app to read available properties of pending external user profiles, on behalf of the signed-in user.", @@ -3779,13 +3821,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "Policy.Read.B2BManagementPolicy" }, - { - "description": "Allows the app to read your organization's conditional access policies on behalf of the signed-in user.", - "displayName": "Read your organization's conditional access policies", - "id": "633e0fce-8c58-4cfb-9495-12bbd5a24f7c", - "origin": "Delegated (Microsoft Graph)", - "value": "Policy.Read.ConditionalAccess" - }, { "description": "Allows the app to read your organization's cross tenant access policies on behalf of the signed-in user.", "displayName": "Read your organization's cross tenant access policies", @@ -3794,46 +3829,53 @@ "value": "Policy.Read.CrossTenantAccess" }, { - "description": "Allows the app to read your organization's device configuration policies on behalf of the signed-in user. For example, device registration policy can limit initial provisioning controls using quota restrictions, additional authentication and authorization checks.", - "displayName": "Read your organization's device configuration policies", - "id": "3616a4b0-6746-49c4-a678-4c237599074d", + "description": "Allows the app to manage policies related to consent and permission grants for applications, on behalf of the signed-in user.", + "displayName": "Manage consent and permission grant policies", + "id": "2672f8bb-fd5e-42e0-85e1-ec764dd2614e", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.Read.DeviceConfiguration" + "value": "Policy.ReadWrite.PermissionGrant" }, { - "description": "Allows the app to read your organization’s identity protection policy on behalf of the signed-in user.", - "displayName": "Read your organization’s identity protection policy", - "id": "d146432f-b803-4ed4-8d42-ba74193a6ede", - "origin": "Delegated (Microsoft Graph)", - "value": "Policy.Read.IdentityProtection" + "description": "Allows the application to read and update the organization's recovery policy on behalf of the signed-in user.", + "displayName": "Read and write your organization's recovery policy", + "id": "1e7a2f4c-e602-4b1b-9547-304dd65c4cc2", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.Recovery" }, { - "description": "Allows the application to read the organization's recovery policy on behalf of the signed-in user.", - "displayName": "Read your organization's recovery policy", - "id": "61faa1e9-0931-4f9a-94ba-bc2e3505c685", + "description": "Allows the app to read and write your organization's security defaults policy on behalf of the signed-in user.", + "displayName": "Read and write your organization's security defaults policy", + "id": "0b2a744c-2abf-4f1e-ad7e-17a087e2be99", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.Read.Recovery" + "value": "Policy.ReadWrite.SecurityDefaults" }, { - "description": "Allows the app to have the same access to mailboxes as the signed-in user via POP protocol.", - "displayName": "Read and write access to mailboxes via POP.", - "id": "d7b7f2d9-0f45-4ea1-9d42-e50810c06991", + "description": "Allows the application to read and update the metadata of print jobs that the signed-in user created. Does not allow access to print job document content.", + "displayName": "Read and write basic information of user's print jobs", + "id": "6f2d22f2-1cb6-412c-a17c-3336817eaa82", "origin": "Delegated (Microsoft Graph)", - "value": "POP.AccessAsUser.All" + "value": "PrintJob.ReadWriteBasic" }, { - "description": "Allows the app to read preauthorization grants for service principals on behalf of the signed-in user.", - "displayName": "Read all preauthorization grants", - "id": "9c98cbde-410c-4719-9058-166504f17863", + "description": "Allows the application to read and update the metadata of print jobs on behalf of the signed-in user. Does not allow access to print job document content.", + "displayName": "Read and write basic information of print jobs", + "id": "3a0db2f6-0d2a-4c19-971b-49109b19ad3d", "origin": "Delegated (Microsoft Graph)", - "value": "PreAuthorizationGrant.Read.All" + "value": "PrintJob.ReadWriteBasic.All" }, { - "description": "Allows the app to read presence information on behalf of the signed-in user. Presence information includes activity, availability, status note, calendar out-of-office message, timezone and location.", - "displayName": "Read user's presence information", - "id": "76bc735e-aecd-4a1d-8b4c-2b915deabb79", + "description": "Allows the application to read tenant-wide print settings on behalf of the signed-in user.", + "displayName": "Read tenant-wide print settings", + "id": "490f32fd-d90f-4dd7-a601-ff6cdc1a3f6c", "origin": "Delegated (Microsoft Graph)", - "value": "Presence.Read" + "value": "PrintSettings.Read.All" + }, + { + "description": "Allows the application to read and write tenant-wide print settings on behalf of the signed-in user.", + "displayName": "Read and write tenant-wide print settings", + "id": "9ccc526a-c51c-4e5c-a1fd-74726ef50b8f", + "origin": "Delegated (Microsoft Graph)", + "value": "PrintSettings.ReadWrite.All" }, { "description": "Allows the app to read time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD built-in and custom administrative roles, on behalf of the signed-in user.", @@ -3927,60 +3969,60 @@ "value": "PrivilegedAssignmentSchedule.Remove.AzureADGroup" }, { - "description": "Allows the app to read time-based eligibility schedules for access to Azure AD groups, on behalf of the signed-in user.", - "displayName": "Read eligibility schedules for access to Azure AD groups", - "id": "8f44f93d-ecef-46ae-a9bf-338508d44d6b", + "description": "Allows the application to read and update the metadata and document content of print jobs on behalf of the signed-in user. ", + "displayName": "Read and write print jobs", + "id": "036b9544-e8c5-46ef-900a-0646cc42b271", "origin": "Delegated (Microsoft Graph)", - "value": "PrivilegedEligibilitySchedule.Read.AzureADGroup" + "value": "PrintJob.ReadWrite.All" }, { - "description": "Allows the app to read time-based eligibility schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", - "displayName": "Read eligibility schedules for app permission grants and app role assignments", - "id": "9b9eb231-5483-4f3c-89e9-9d5048dafe9d", + "description": "Allows the application to read and update the metadata and document content of print jobs that the signed-in user created.", + "displayName": "Read and write user's print jobs", + "id": "b81dd597-8abb-4b3f-a07a-820b0316ed04", "origin": "Delegated (Microsoft Graph)", - "value": "PrivilegedEligibilitySchedule.Read.EntraAppRole" + "value": "PrintJob.ReadWrite" }, { - "description": "Allows the app to read, create, and delete time-based eligibility schedules for access to Azure AD groups, on behalf of the signed-in user.", - "displayName": "Read, create, and delete eligibility schedules for access to Azure AD groups", - "id": "ba974594-d163-484e-ba39-c330d5897667", + "description": "Allows the application to read the metadata of print jobs on behalf of the signed-in user. Does not allow access to print job document content.", + "displayName": "Read basic information of print jobs", + "id": "04ce8d60-72ce-4867-85cf-6d82f36922f3", "origin": "Delegated (Microsoft Graph)", - "value": "PrivilegedEligibilitySchedule.ReadWrite.AzureADGroup" + "value": "PrintJob.ReadBasic.All" }, { - "description": "Allows the app to read, create, and delete time-based eligibility schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", - "displayName": "Read, create, and delete eligibility schedules for app permission grants and app role assignments", - "id": "f7ff1cb0-e255-4bb3-b24a-6708c60c5418", + "description": "Allows the application to read the metadata of print jobs that the signed-in user created. Does not allow access to print job document content.", + "displayName": "Read basic information of user's print jobs", + "id": "6a71a747-280f-4670-9ca0-a9cbf882b274", "origin": "Delegated (Microsoft Graph)", - "value": "PrivilegedEligibilitySchedule.ReadWrite.EntraAppRole" + "value": "PrintJob.ReadBasic" }, { - "description": "Allows the application to read and write tenant-wide print settings on behalf of the signed-in user.", - "displayName": "Read and write tenant-wide print settings", - "id": "9ccc526a-c51c-4e5c-a1fd-74726ef50b8f", + "description": "Allows the app to read and write your organization's trust framework policies on behalf of the signed-in user.", + "displayName": "Read and write your organization's trust framework policies", + "id": "cefba324-1a70-4a6e-9c1d-fd670b7ae392", "origin": "Delegated (Microsoft Graph)", - "value": "PrintSettings.ReadWrite.All" + "value": "Policy.ReadWrite.TrustFramework" }, { - "description": "Allows the application to read tenant-wide print settings on behalf of the signed-in user.", - "displayName": "Read tenant-wide print settings", - "id": "490f32fd-d90f-4dd7-a601-ff6cdc1a3f6c", + "description": "Allows the app to have the same access to mailboxes as the signed-in user via POP protocol.", + "displayName": "Read and write access to mailboxes via POP.", + "id": "d7b7f2d9-0f45-4ea1-9d42-e50810c06991", "origin": "Delegated (Microsoft Graph)", - "value": "PrintSettings.Read.All" + "value": "POP.AccessAsUser.All" }, { - "description": "Allows the application to read and update the metadata of print jobs on behalf of the signed-in user. Does not allow access to print job document content.", - "displayName": "Read and write basic information of print jobs", - "id": "3a0db2f6-0d2a-4c19-971b-49109b19ad3d", + "description": "Allows the app to read preauthorization grants for service principals on behalf of the signed-in user.", + "displayName": "Read all preauthorization grants", + "id": "9c98cbde-410c-4719-9058-166504f17863", "origin": "Delegated (Microsoft Graph)", - "value": "PrintJob.ReadWriteBasic.All" + "value": "PreAuthorizationGrant.Read.All" }, { - "description": "Allows the application to read and update the metadata of print jobs that the signed-in user created. Does not allow access to print job document content.", - "displayName": "Read and write basic information of user's print jobs", - "id": "6f2d22f2-1cb6-412c-a17c-3336817eaa82", + "description": "Allows the app to read presence information on behalf of the signed-in user. Presence information includes activity, availability, status note, calendar out-of-office message, timezone and location.", + "displayName": "Read user's presence information", + "id": "76bc735e-aecd-4a1d-8b4c-2b915deabb79", "origin": "Delegated (Microsoft Graph)", - "value": "PrintJob.ReadWriteBasic" + "value": "Presence.Read" }, { "description": "Allows the app to read presence information of all users in the directory on behalf of the signed-in user. Presence information includes activity, availability, status note, calendar out-of-office message, timezone and location.", @@ -4010,6 +4052,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "PrintConnector.ReadWrite.All" }, + { + "description": "Allows the app to read organization-wide Microsoft To Do settings on behalf of the signed-in user.", + "displayName": "Read organization-wide Microsoft To Do settings", + "id": "7ff96f41-f022-45ba-acd8-ef3f03063d6b", + "origin": "Delegated (Microsoft Graph)", + "value": "OrgSettings-Todo.Read.All" + }, { "description": "Allows the application to create (register) printers on behalf of the signed-in user. ", "displayName": "Register printers ", @@ -4017,13 +4066,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "Printer.Create" }, - { - "description": "Allows the application to create (register), read, update, and delete (unregister) printers on behalf of the signed-in user. ", - "displayName": "Register, read, update, and unregister printers", - "id": "93dae4bd-43a1-4a23-9a1a-92957e1d9121", - "origin": "Delegated (Microsoft Graph)", - "value": "Printer.FullControl.All" - }, { "description": "Allows the application to read printers on behalf of the signed-in user. ", "displayName": "Read printers", @@ -4038,13 +4080,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "Printer.ReadWrite.All" }, - { - "description": "Allows the app to read security alerts and update status of alerts of customer with CSP relationship on behalf of the partner signed-in user.", - "displayName": "Read security alerts and update status of security alerts of customer with CSP relationship", - "id": "0cd2c1f6-94a1-4075-ab8c-0b1aff2e1ad5", - "origin": "Delegated (Microsoft Graph)", - "value": "PartnerSecurity.ReadWrite.All" - }, { "description": "Allows the application to read printer shares on behalf of the signed-in user. ", "displayName": "Read printer shares", @@ -4052,6 +4087,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "PrinterShare.Read.All" }, + { + "description": "Allows the application to read basic information about printer shares on behalf of the signed-in user. Does not allow reading access control information.", + "displayName": "Read basic information about printer shares", + "id": "5fa075e9-b951-4165-947b-c63396ff0a37", + "origin": "Delegated (Microsoft Graph)", + "value": "PrinterShare.ReadBasic.All" + }, { "description": "Allows the application to read and update printer shares on behalf of the signed-in user. ", "displayName": "Read and write printer shares", @@ -4081,60 +4123,60 @@ "value": "PrintJob.Read.All" }, { - "description": "Allows the application to read the metadata of print jobs that the signed-in user created. Does not allow access to print job document content.", - "displayName": "Read basic information of user's print jobs", - "id": "6a71a747-280f-4670-9ca0-a9cbf882b274", + "description": "Allows the application to create (register), read, update, and delete (unregister) printers on behalf of the signed-in user. ", + "displayName": "Register, read, update, and unregister printers", + "id": "93dae4bd-43a1-4a23-9a1a-92957e1d9121", "origin": "Delegated (Microsoft Graph)", - "value": "PrintJob.ReadBasic" + "value": "Printer.FullControl.All" }, { - "description": "Allows the application to read the metadata of print jobs on behalf of the signed-in user. Does not allow access to print job document content.", - "displayName": "Read basic information of print jobs", - "id": "04ce8d60-72ce-4867-85cf-6d82f36922f3", + "description": "Allows the app to read and write organization-wide Microsoft 365 apps installation settings on behalf of the signed-in user.", + "displayName": "Read and write organization-wide Microsoft 365 apps installation settings", + "id": "1ff35e91-19eb-42d8-aa2d-cc9891127ae5", "origin": "Delegated (Microsoft Graph)", - "value": "PrintJob.ReadBasic.All" + "value": "OrgSettings-Microsoft365Install.ReadWrite.All" }, { - "description": "Allows the application to read and update the metadata and document content of print jobs that the signed-in user created.", - "displayName": "Read and write user's print jobs", - "id": "b81dd597-8abb-4b3f-a07a-820b0316ed04", + "description": "Allows the app to read organization-wide Microsoft 365 apps installation settings on behalf of the signed-in user.", + "displayName": "Read organization-wide Microsoft 365 apps installation settings", + "id": "8cbdb9f6-9c2e-451a-814d-ec606e5d0212", "origin": "Delegated (Microsoft Graph)", - "value": "PrintJob.ReadWrite" + "value": "OrgSettings-Microsoft365Install.Read.All" }, { - "description": "Allows the application to read and update the metadata and document content of print jobs on behalf of the signed-in user. ", - "displayName": "Read and write print jobs", - "id": "036b9544-e8c5-46ef-900a-0646cc42b271", + "description": "Allows the app to read and write organization-wide Microsoft Forms settings on behalf of the signed-in user.", + "displayName": "Read and write organization-wide Microsoft Forms settings", + "id": "346c19ff-3fb2-4e81-87a0-bac9e33990c1", "origin": "Delegated (Microsoft Graph)", - "value": "PrintJob.ReadWrite.All" + "value": "OrgSettings-Forms.ReadWrite.All" }, { - "description": "Allows the application to read basic information about printer shares on behalf of the signed-in user. Does not allow reading access control information.", - "displayName": "Read basic information about printer shares", - "id": "5fa075e9-b951-4165-947b-c63396ff0a37", + "description": "Allows the app to create, read, update, and delete email in user mailboxes. Does not include permission to send mail.", + "displayName": "Read and write access to user mail ", + "id": "024d486e-b451-40bb-833d-3e66d98c5c73", "origin": "Delegated (Microsoft Graph)", - "value": "PrinterShare.ReadBasic.All" + "value": "Mail.ReadWrite" }, { - "description": "Allows the app to read identity lifecycle policies for agent identities that the signed-in user has access to in the organization.", - "displayName": "Read identity lifecycle policies for agent identities", - "id": "65857db0-62ac-4279-aa73-c2b5dab186f5", + "description": "Allows the app to create, read, update, and delete mail a user has permission to access, including their own and shared mail. Does not include permission to send mail.", + "displayName": "Read and write user and shared mail", + "id": "5df07973-7d5d-46ed-9847-1271055cbd51", "origin": "Delegated (Microsoft Graph)", - "value": "LifecyclePolicies-AgentId.Read.All" + "value": "Mail.ReadWrite.Shared" }, { - "description": "Allows the app to read security alerts of customer with CSP relationship on behalf of the partner signed-in user.", - "displayName": "Read security alerts of customer with CSP relationship", - "id": "5567b981-0bf1-4796-9038-0648b46e116d", + "description": "Allows the app to send mail as users in the organization.", + "displayName": "Send mail as a user ", + "id": "e383f46e-2787-4529-855e-0e479a3ffac0", "origin": "Delegated (Microsoft Graph)", - "value": "PartnerSecurity.Read.All" + "value": "Mail.Send" }, { - "description": "Allows the app to read and write organization-wide Microsoft To Do settings on behalf of the signed-in user.", - "displayName": "Read and write organization-wide Microsoft To Do settings", - "id": "087502c2-5263-433e-abe3-8f77231a0627", + "description": "Allows the app to send mail as the signed-in user, including sending on-behalf of others.", + "displayName": "Send mail on behalf of others", + "id": "a367ab51-6b49-43bf-a716-a1fb06d2a174", "origin": "Delegated (Microsoft Graph)", - "value": "OrgSettings-Todo.ReadWrite.All" + "value": "Mail.Send.Shared" }, { "description": "Allows the app to create, read, update, and delete email, including contents of non-draft emails in user mailboxes, on behalf of the signed-in user. Does not include permission to send mail.", @@ -4228,60 +4270,67 @@ "value": "MailTips.ReadBasic.Shared" }, { - "description": "Allows the app to read all managed tenant information on behalf of the signed-in user.", - "displayName": "Read all managed tenant information", - "id": "dc34164e-6c4a-41a0-be89-3ae2fbad7cd3", + "description": "Allows the app to read mail the signed-in user can access, including their own and shared mail, except for body, bodyPreview, uniqueBody, attachments, extensions, and any extended properties.", + "displayName": "Read user and shared basic mail", + "id": "b11fa0e7-fdb7-4dc9-b1f1-59facd463480", "origin": "Delegated (Microsoft Graph)", - "value": "ManagedTenants.Read.All" + "value": "Mail.ReadBasic.Shared" }, { - "description": "Allows the app to read and write all managed tenant information on behalf of the signed-in user.", - "displayName": "Read and write all managed tenant information", - "id": "b31fa710-c9b3-4d9e-8f5e-8036eecddab9", + "description": "Allows the app to read email in the signed-in user's mailbox except body, previewBody, attachments and any extended properties.", + "displayName": "Read user basic mail", + "id": "a4b8392a-d8d1-4954-a029-8e668a39a170", "origin": "Delegated (Microsoft Graph)", - "value": "ManagedTenants.ReadWrite.All" + "value": "Mail.ReadBasic" }, { - "description": "Allows the app to read the memberships of hidden groups and administrative units on behalf of the signed-in user, for those hidden groups and administrative units that the signed-in user has access to.", - "displayName": "Read hidden memberships", - "id": "f6a3db3e-f7e8-4ed2-a414-557c8c9830be", + "description": "Allows the app to read mail a user can access, including their own and shared mail.", + "displayName": "Read user and shared mail", + "id": "7b9103a5-4610-446b-9670-80643382c1fa", "origin": "Delegated (Microsoft Graph)", - "value": "Member.Read.Hidden" + "value": "Mail.Read.Shared" }, { - "description": "Allows the app to read multi-tenant organization details and tenants on behalf of the signed-in user.", - "displayName": "Read multi-tenant organization details and tenants", - "id": "526aa72a-5878-49fe-bf4e-357973af9b06", + "description": "Allows the app to read the signed-in user's mailbox.", + "displayName": "Read user mail ", + "id": "570282fd-fa5c-430d-a7fd-fc8dc98a9dca", "origin": "Delegated (Microsoft Graph)", - "value": "MultiTenantOrganization.Read.All" + "value": "Mail.Read" }, { - "description": "Allows the app to send mail as the signed-in user, including sending on-behalf of others.", - "displayName": "Send mail on behalf of others", - "id": "a367ab51-6b49-43bf-a716-a1fb06d2a174", + "description": "Allows the app to read data for the learner's self-initiated courses in the organization's directory, on behalf of the signed-in user.", + "displayName": "Read user's self-initiated courses", + "id": "f6403ef7-4a96-47be-a190-69ba274c3f11", "origin": "Delegated (Microsoft Graph)", - "value": "Mail.Send.Shared" + "value": "LearningSelfInitiatedCourse.Read" }, { - "description": "Allows the app to read multi-tenant organization basic details and active tenants on behalf of the signed-in user.", - "displayName": "Read multi-tenant organization basic details and active tenants", - "id": "225db56b-15b2-4daa-acb3-0eec2bbe4849", + "description": "Allows an app to read license assignments for users and groups, on behalf of the signed-in user.", + "displayName": "Read all license assignments.", + "id": "f395577a-0960-456b-979f-7228de0c5996", "origin": "Delegated (Microsoft Graph)", - "value": "MultiTenantOrganization.ReadBasic.All" + "value": "LicenseAssignment.Read.All" }, { - "description": "Allows the app to send mail as users in the organization.", - "displayName": "Send mail as a user ", - "id": "e383f46e-2787-4529-855e-0e479a3ffac0", + "description": "Allows an app to manage license assignments for users and groups, on behalf of the signed-in user.", + "displayName": "Manage all license assignments", + "id": "f55016cc-149c-447e-8f21-7cf3ec1d6350", "origin": "Delegated (Microsoft Graph)", - "value": "Mail.Send" + "value": "LicenseAssignment.ReadWrite.All" }, { - "description": "Allows the app to create, read, update, and delete email in user mailboxes. Does not include permission to send mail.", - "displayName": "Read and write access to user mail ", - "id": "024d486e-b451-40bb-833d-3e66d98c5c73", + "description": "Allows the app to read identity lifecycle policies for agent identities that the signed-in user has access to in the organization.", + "displayName": "Read identity lifecycle policies for agent identities", + "id": "65857db0-62ac-4279-aa73-c2b5dab186f5", "origin": "Delegated (Microsoft Graph)", - "value": "Mail.ReadWrite" + "value": "LifecyclePolicies-AgentId.Read.All" + }, + { + "description": "Allows the app to read, create, update and delete identity lifecycle policies for agent identities that the signed-in user has access to in the organization.", + "displayName": "Read and write identity lifecycle policies for agent identities", + "id": "f2292ca5-46fc-4195-9b4d-16491bf9bf7f", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecyclePolicies-AgentId.ReadWrite.All" }, { "description": "Allows the app to read identity lifecycle policies for external guests on behalf of the signed-in user.", @@ -4304,6 +4353,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "LifecycleWorkflows.Read.All" }, + { + "description": "Allows the app to read all managed tenant information on behalf of the signed-in user.", + "displayName": "Read all managed tenant information", + "id": "dc34164e-6c4a-41a0-be89-3ae2fbad7cd3", + "origin": "Delegated (Microsoft Graph)", + "value": "ManagedTenants.Read.All" + }, { "description": "Allows the app to create, update, list, read and delete all workflows, tasks and related lifecycle workflows resources on behalf of the signed-in user.", "displayName": "Read and write all lifecycle workflows resources", @@ -4311,13 +4367,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "LifecycleWorkflows.ReadWrite.All" }, - { - "description": "Allows the app to read all Lifecycle workflows custom task extensions on behalf of a signed-in user.", - "displayName": "Read all Lifecycle workflows custom task extensions", - "id": "2973a298-1d69-4f87-8d30-7025f0ec19d7", - "origin": "Delegated (Microsoft Graph)", - "value": "LifecycleWorkflows-CustomExt.Read.All" - }, { "description": "Allows the app to create, update, list, read and delete all Lifecycle workflows custom task extensions on behalf of a signed-in user.", "displayName": "Read and write all Lifecycle workflows custom task extensions", @@ -4375,60 +4424,60 @@ "value": "Lists.SelectedOperations.Selected" }, { - "description": "Allows the app to read the signed-in user's mailbox.", - "displayName": "Read user mail ", - "id": "570282fd-fa5c-430d-a7fd-fc8dc98a9dca", + "description": "Allows the app to read all Lifecycle workflows custom task extensions on behalf of a signed-in user.", + "displayName": "Read all Lifecycle workflows custom task extensions", + "id": "2973a298-1d69-4f87-8d30-7025f0ec19d7", "origin": "Delegated (Microsoft Graph)", - "value": "Mail.Read" + "value": "LifecycleWorkflows-CustomExt.Read.All" }, { - "description": "Allows the app to read mail a user can access, including their own and shared mail.", - "displayName": "Read user and shared mail", - "id": "7b9103a5-4610-446b-9670-80643382c1fa", + "description": "Allows the app to read time-based eligibility schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", + "displayName": "Read eligibility schedules for app permission grants and app role assignments", + "id": "9b9eb231-5483-4f3c-89e9-9d5048dafe9d", "origin": "Delegated (Microsoft Graph)", - "value": "Mail.Read.Shared" + "value": "PrivilegedEligibilitySchedule.Read.EntraAppRole" }, { - "description": "Allows the app to read email in the signed-in user's mailbox except body, previewBody, attachments and any extended properties.", - "displayName": "Read user basic mail", - "id": "a4b8392a-d8d1-4954-a029-8e668a39a170", + "description": "Allows the app to read and write all managed tenant information on behalf of the signed-in user.", + "displayName": "Read and write all managed tenant information", + "id": "b31fa710-c9b3-4d9e-8f5e-8036eecddab9", "origin": "Delegated (Microsoft Graph)", - "value": "Mail.ReadBasic" + "value": "ManagedTenants.ReadWrite.All" }, { - "description": "Allows the app to read mail the signed-in user can access, including their own and shared mail, except for body, bodyPreview, uniqueBody, attachments, extensions, and any extended properties.", - "displayName": "Read user and shared basic mail", - "id": "b11fa0e7-fdb7-4dc9-b1f1-59facd463480", + "description": "Allows the app to read multi-tenant organization details and tenants on behalf of the signed-in user.", + "displayName": "Read multi-tenant organization details and tenants", + "id": "526aa72a-5878-49fe-bf4e-357973af9b06", "origin": "Delegated (Microsoft Graph)", - "value": "Mail.ReadBasic.Shared" + "value": "MultiTenantOrganization.Read.All" }, { - "description": "Allows the app to create, read, update, and delete mail a user has permission to access, including their own and shared mail. Does not include permission to send mail.", - "displayName": "Read and write user and shared mail", - "id": "5df07973-7d5d-46ed-9847-1271055cbd51", + "description": "Allows the app to read online meeting details on behalf of the signed-in user.", + "displayName": "Read user's online meetings", + "id": "9be106e1-f4e3-4df5-bdff-e4bc531cbe43", "origin": "Delegated (Microsoft Graph)", - "value": "Mail.ReadWrite.Shared" + "value": "OnlineMeetings.Read" }, { - "description": "Allows the app to read and write multi-tenant organization details and tenants on behalf of the signed-in user.", - "displayName": "Read and write multi-tenant organization details and tenants", - "id": "77af1528-84f3-4023-8d90-d219cd433108", + "description": "Allows the app to read and create online meetings on behalf of the signed-in user.", + "displayName": "Read and create user's online meetings", + "id": "a65f2972-a4f8-4f5e-afd7-69ccb046d5dc", "origin": "Delegated (Microsoft Graph)", - "value": "MultiTenantOrganization.ReadWrite.All" + "value": "OnlineMeetings.ReadWrite" }, { - "description": "Allows the app to read configuration used for OAuth 2.0 mutual-TLS client authentication, on behalf of the signed-in user. This includes reading trusted certificate authorities.", - "displayName": "Read all configurations used for mutual-TLS client authentication.", - "id": "51ae584e-e736-4718-897b-10af70f8e3cc", + "description": "Allows the app to read all transcripts of online meetings, on behalf of the signed-in user.", + "displayName": "Read all transcripts of online meetings.", + "id": "30b87d18-ebb1-45db-97f8-82ccb1f0190c", "origin": "Delegated (Microsoft Graph)", - "value": "MutualTlsOauthConfiguration.Read.All" + "value": "OnlineMeetingTranscript.Read.All" }, { - "description": "Allows the app to read and update configuration used for OAuth 2.0 mutual-TLS client authentication, on behalf of the signed-in user. This includes adding and updating trusted certificate authorities.", - "displayName": "Read and write all configurations used for mutual-TLS client authentication.", - "id": "a51115bc-f64f-498f-bcee-00dcd28f4a03", + "description": "Allows the app to read all on-premises directory synchronization information for the organization, on behalf of the signed-in user.", + "displayName": "Read all on-premises directory synchronization information", + "id": "f6609722-4100-44eb-b747-e6ca0536989d", "origin": "Delegated (Microsoft Graph)", - "value": "MutualTlsOauthConfiguration.ReadWrite.All" + "value": "OnPremDirectorySynchronization.Read.All" }, { "description": "Allows the app to read and write all on-premises directory synchronization information for the organization, on behalf of the signed-in user.", @@ -4522,60 +4571,60 @@ "value": "OrgSettings-Forms.Read.All" }, { - "description": "Allows the app to read and write organization-wide Microsoft Forms settings on behalf of the signed-in user.", - "displayName": "Read and write organization-wide Microsoft Forms settings", - "id": "346c19ff-3fb2-4e81-87a0-bac9e33990c1", + "description": "Allows the app to read all recordings of online meetings, on behalf of the signed-in user.", + "displayName": "Read all recordings of online meetings.", + "id": "190c2bb6-1fdd-4fec-9aa2-7d571b5e1fe3", "origin": "Delegated (Microsoft Graph)", - "value": "OrgSettings-Forms.ReadWrite.All" + "value": "OnlineMeetingRecording.Read.All" }, { - "description": "Allows the app to read organization-wide Microsoft 365 apps installation settings on behalf of the signed-in user.", - "displayName": "Read organization-wide Microsoft 365 apps installation settings", - "id": "8cbdb9f6-9c2e-451a-814d-ec606e5d0212", + "description": "Allows the app to read online meeting artifacts on behalf of the signed-in user.", + "displayName": "Read user's online meeting artifacts", + "id": "110e5abb-a10c-4b59-8b55-9b4daa4ef743", "origin": "Delegated (Microsoft Graph)", - "value": "OrgSettings-Microsoft365Install.Read.All" + "value": "OnlineMeetingArtifact.Read.All" }, { - "description": "Allows the app to read and write organization-wide Microsoft 365 apps installation settings on behalf of the signed-in user.", - "displayName": "Read and write organization-wide Microsoft 365 apps installation settings", - "id": "1ff35e91-19eb-42d8-aa2d-cc9891127ae5", + "description": "Allows the app to read all AI Insights for online meetings, on behalf of the signed-in user.", + "displayName": "Read all AI Insights for online meetings.", + "id": "166741d6-eeb8-46fe-91f4-817d2af7bc88", "origin": "Delegated (Microsoft Graph)", - "value": "OrgSettings-Microsoft365Install.ReadWrite.All" + "value": "OnlineMeetingAiInsight.Read.All" }, { - "description": "Allows the app to read organization-wide Microsoft To Do settings on behalf of the signed-in user.", - "displayName": "Read organization-wide Microsoft To Do settings", - "id": "7ff96f41-f022-45ba-acd8-ef3f03063d6b", + "description": "Allows the app to see and update the data you gave it access to, even when users are not currently using the app. This does not give the app any additional permissions.", + "displayName": "Maintain access to data you have given it access to", + "id": "7427e0e9-2fba-42fe-b0c0-848c9e6a8182", "origin": "Delegated (Microsoft Graph)", - "value": "OrgSettings-Todo.Read.All" + "value": "offline_access" }, { - "description": "Allows the app to read all on-premises directory synchronization information for the organization, on behalf of the signed-in user.", - "displayName": "Read all on-premises directory synchronization information", - "id": "f6609722-4100-44eb-b747-e6ca0536989d", + "description": "Allows the app to read multi-tenant organization basic details and active tenants on behalf of the signed-in user.", + "displayName": "Read multi-tenant organization basic details and active tenants", + "id": "225db56b-15b2-4daa-acb3-0eec2bbe4849", "origin": "Delegated (Microsoft Graph)", - "value": "OnPremDirectorySynchronization.Read.All" + "value": "MultiTenantOrganization.ReadBasic.All" }, { - "description": "Allows the app to read all transcripts of online meetings, on behalf of the signed-in user.", - "displayName": "Read all transcripts of online meetings.", - "id": "30b87d18-ebb1-45db-97f8-82ccb1f0190c", + "description": "Allows the app to read and write multi-tenant organization details and tenants on behalf of the signed-in user.", + "displayName": "Read and write multi-tenant organization details and tenants", + "id": "77af1528-84f3-4023-8d90-d219cd433108", "origin": "Delegated (Microsoft Graph)", - "value": "OnlineMeetingTranscript.Read.All" + "value": "MultiTenantOrganization.ReadWrite.All" }, { - "description": "Allows the app to read and create online meetings on behalf of the signed-in user.", - "displayName": "Read and create user's online meetings", - "id": "a65f2972-a4f8-4f5e-afd7-69ccb046d5dc", + "description": "Allows the app to read configuration used for OAuth 2.0 mutual-TLS client authentication, on behalf of the signed-in user. This includes reading trusted certificate authorities.", + "displayName": "Read all configurations used for mutual-TLS client authentication.", + "id": "51ae584e-e736-4718-897b-10af70f8e3cc", "origin": "Delegated (Microsoft Graph)", - "value": "OnlineMeetings.ReadWrite" + "value": "MutualTlsOauthConfiguration.Read.All" }, { - "description": "Allows the app to read online meeting details on behalf of the signed-in user.", - "displayName": "Read user's online meetings", - "id": "9be106e1-f4e3-4df5-bdff-e4bc531cbe43", + "description": "Allows the app to read and update configuration used for OAuth 2.0 mutual-TLS client authentication, on behalf of the signed-in user. This includes adding and updating trusted certificate authorities.", + "displayName": "Read and write all configurations used for mutual-TLS client authentication.", + "id": "a51115bc-f64f-498f-bcee-00dcd28f4a03", "origin": "Delegated (Microsoft Graph)", - "value": "OnlineMeetings.Read" + "value": "MutualTlsOauthConfiguration.ReadWrite.All" }, { "description": "Allows the app to read all network access information on behalf of the signed-in user.", @@ -4605,6 +4654,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "NetworkAccessBranch.ReadWrite.All" }, + { + "description": "Allows the app to read the memberships of hidden groups and administrative units on behalf of the signed-in user, for those hidden groups and administrative units that the signed-in user has access to.", + "displayName": "Read hidden memberships", + "id": "f6a3db3e-f7e8-4ed2-a414-557c8c9830be", + "origin": "Delegated (Microsoft Graph)", + "value": "Member.Read.Hidden" + }, { "description": "Allows the app to read your organization's security and routing network access policies on behalf of the signed-in user.", "displayName": "Read security and routing policies for network access", @@ -4612,13 +4668,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "NetworkAccessPolicy.Read.All" }, - { - "description": "Allows the app to read and write your organization's security and routing network access policies on behalf of the signed-in user.", - "displayName": "Read and write security and routing policies for network access", - "id": "b1fbad0f-ef6e-42ed-8676-bca7fa3e7291", - "origin": "Delegated (Microsoft Graph)", - "value": "NetworkAccessPolicy.ReadWrite.All" - }, { "description": "Allows the app to read all network access reports on behalf of the signed-in user.", "displayName": "Read all network access reports", @@ -4626,19 +4675,12 @@ "origin": "Delegated (Microsoft Graph)", "value": "NetworkAccess-Reports.Read.All" }, - { - "description": "Allows the app to read the titles of OneNote notebooks and sections and to create new pages, notebooks, and sections on behalf of the signed-in user.", - "displayName": "Create user OneNote notebooks", - "id": "9d822255-d64d-4b7a-afdb-833b9a97ed02", - "origin": "Delegated (Microsoft Graph)", - "value": "Notes.Create" - }, - { - "description": "Allows the app to read all of billing data from Microsoft for your company's tenant, on behalf of the signed-in user. This includes reading billed and unbilled Usage and Invoice reconciliation data.", - "displayName": "Read all billing data for your company's tenant", - "id": "8804798e-5934-4e30-8ce3-ef88257cecd4", + { + "description": "Allows the app to read the titles of OneNote notebooks and sections and to create new pages, notebooks, and sections on behalf of the signed-in user.", + "displayName": "Create user OneNote notebooks", + "id": "9d822255-d64d-4b7a-afdb-833b9a97ed02", "origin": "Delegated (Microsoft Graph)", - "value": "PartnerBilling.Read.All" + "value": "Notes.Create" }, { "description": "Allows the app to read OneNote notebooks on behalf of the signed-in user.", @@ -4647,6 +4689,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "Notes.Read" }, + { + "description": "Allows the app to read OneNote notebooks that the signed-in user has access to in the organization.", + "displayName": "Read all OneNote notebooks that user can access", + "id": "dfabfca6-ee36-4db2-8208-7a28381419b3", + "origin": "Delegated (Microsoft Graph)", + "value": "Notes.Read.All" + }, { "description": "Allows the app to read, share, and modify OneNote notebooks on behalf of the signed-in user.", "displayName": "Read and write user OneNote notebooks", @@ -4676,39 +4725,25 @@ "value": "Notifications.ReadWrite.CreatedByApp" }, { - "description": "Allows the app to see and update the data you gave it access to, even when users are not currently using the app. This does not give the app any additional permissions.", - "displayName": "Maintain access to data you have given it access to", - "id": "7427e0e9-2fba-42fe-b0c0-848c9e6a8182", - "origin": "Delegated (Microsoft Graph)", - "value": "offline_access" - }, - { - "description": "Allows the app to read all AI Insights for online meetings, on behalf of the signed-in user.", - "displayName": "Read all AI Insights for online meetings.", - "id": "166741d6-eeb8-46fe-91f4-817d2af7bc88", - "origin": "Delegated (Microsoft Graph)", - "value": "OnlineMeetingAiInsight.Read.All" - }, - { - "description": "Allows the app to read online meeting artifacts on behalf of the signed-in user.", - "displayName": "Read user's online meeting artifacts", - "id": "110e5abb-a10c-4b59-8b55-9b4daa4ef743", + "description": "Allows the app to read and write your organization's security and routing network access policies on behalf of the signed-in user.", + "displayName": "Read and write security and routing policies for network access", + "id": "b1fbad0f-ef6e-42ed-8676-bca7fa3e7291", "origin": "Delegated (Microsoft Graph)", - "value": "OnlineMeetingArtifact.Read.All" + "value": "NetworkAccessPolicy.ReadWrite.All" }, { - "description": "Allows the app to read all recordings of online meetings, on behalf of the signed-in user.", - "displayName": "Read all recordings of online meetings.", - "id": "190c2bb6-1fdd-4fec-9aa2-7d571b5e1fe3", + "description": "Allows the application to list and query user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export external user data (e.g. customer content or system-generated logs), associated with the current tenant on behalf of the signed-in user.", + "displayName": "Read shared cross-tenant user profile and export data", + "id": "cb1ba48f-d22b-4325-a07f-74135a62ee41", "origin": "Delegated (Microsoft Graph)", - "value": "OnlineMeetingRecording.Read.All" + "value": "CrossTenantUserProfileSharing.Read" }, { - "description": "Allows the app to read OneNote notebooks that the signed-in user has access to in the organization.", - "displayName": "Read all OneNote notebooks that user can access", - "id": "dfabfca6-ee36-4db2-8208-7a28381419b3", - "origin": "Delegated (Microsoft Graph)", - "value": "Notes.Read.All" + "description": "Sign in to synthetics service", + "displayName": "syntest.signin", + "id": "9f56f4b8-4de2-4e83-a632-45d1e4b47400", + "origin": "Delegated (Microsoft Mixed Reality)", + "value": "syntest.signin" }, { "description": "Allows the app to uninstall Microsoft Entra Connect Sync Agent and offboard SSPR for the tenant", @@ -4718,18 +4753,11 @@ "value": "PasswordWriteback.OffboardClient.All" }, { - "description": "Allows the app to refresh and recreate on-premises configuration for Microsoft self-service password reset.", - "displayName": "Read, write and manage self-service password reset writeback configuration", - "id": "fc7e8088-95b5-453e-8bef-b17ecfec5ba3", - "origin": "Application (Microsoft password reset service)", - "value": "PasswordWriteback.RefreshClient.All" - }, - { - "description": "Allows the app to register a newer version of on-premises Microsoft Entra Connect Sync Agent.", - "displayName": "Read, write and manage Microsoft Entra Connect Sync Agent", - "id": "e006e431-a65b-4f3e-8808-77d29d4c5f1a", - "origin": "Application (Microsoft password reset service)", - "value": "PasswordWriteback.RegisterClientVersion.All" + "description": " ", + "displayName": "OrgApp.Reshare (retired)", + "id": "02d9fa8b-e936-407b-a8f2-9b8fa5bda3bc", + "origin": "Delegated (Power BI Service)", + "value": "OrgApp.Reshare.All" }, { "description": " ", @@ -4844,39 +4872,39 @@ "value": "Report.Reshare.All" }, { - "description": " ", - "displayName": "RetailDataManager.Execute (retired)", - "id": "5793b2af-bc3b-4f1d-bbb1-9a3e359dd8e1", + "description": "Allows modifying org apps on the user’s behalf.", + "displayName": "Read and write org apps", + "id": "38536678-0d9f-4f82-88e5-a13a78d1d209", "origin": "Delegated (Power BI Service)", - "value": "RetailDataManager.Execute.All" + "value": "OrgApp.ReadWrite.All" }, { "description": " ", - "displayName": "OrgApp.Reshare (retired)", - "id": "02d9fa8b-e936-407b-a8f2-9b8fa5bda3bc", + "displayName": "RetailDataManager.Execute (retired)", + "id": "5793b2af-bc3b-4f1d-bbb1-9a3e359dd8e1", "origin": "Delegated (Power BI Service)", - "value": "OrgApp.Reshare.All" + "value": "RetailDataManager.Execute.All" }, { - "description": "Allows reading retail data manager items on the user’s behalf.", - "displayName": "Read retail data manager items", - "id": "1ddcbaa9-c4cf-4684-9048-e04a12739a8c", + "description": "Allows reading org apps on the user’s behalf.", + "displayName": "Read org apps", + "id": "d27d5544-b17d-471f-9a02-ef09d6720508", "origin": "Delegated (Power BI Service)", - "value": "RetailDataManager.Read.All" + "value": "OrgApp.Read.All" }, { - "description": "Allows modifying org apps on the user’s behalf.", - "displayName": "Read and write org apps", - "id": "38536678-0d9f-4f82-88e5-a13a78d1d209", + "description": "Allows the app to make API calls that read OneLake metadata on your behalf.", + "displayName": "Make API calls that read OneLake metadata", + "id": "547211ef-7223-404f-8519-fee52fda6402", "origin": "Delegated (Power BI Service)", - "value": "OrgApp.ReadWrite.All" + "value": "OneLake.Read.All" }, { - "description": "Allows the app to make API calls that read and write OneLake metadata, on your behalf.", - "displayName": "Make API calls that read and write OneLake metadata", - "id": "ada1b44b-4474-40ed-b32c-e3543dccec0e", + "description": " ", + "displayName": "MirroredDatabase.Reshare (retired)", + "id": "c18991d0-0a42-4567-983a-1993bc79f327", "origin": "Delegated (Power BI Service)", - "value": "OneLake.ReadWrite.All" + "value": "MirroredDatabase.Reshare.All" }, { "description": "Allows executing ML experiments on the user’s behalf.", @@ -4991,18 +5019,18 @@ "value": "Notebook.Reshare.All" }, { - "description": "Allows the app to make API calls that read OneLake metadata on your behalf.", - "displayName": "Make API calls that read OneLake metadata", - "id": "547211ef-7223-404f-8519-fee52fda6402", + "description": "Allows the app to make API calls that read and write OneLake metadata, on your behalf.", + "displayName": "Make API calls that read and write OneLake metadata", + "id": "ada1b44b-4474-40ed-b32c-e3543dccec0e", "origin": "Delegated (Power BI Service)", - "value": "OneLake.Read.All" + "value": "OneLake.ReadWrite.All" }, { - "description": "Allows reading org apps on the user’s behalf.", - "displayName": "Read org apps", - "id": "d27d5544-b17d-471f-9a02-ef09d6720508", + "description": "Allows reading retail data manager items on the user’s behalf.", + "displayName": "Read retail data manager items", + "id": "1ddcbaa9-c4cf-4684-9048-e04a12739a8c", "origin": "Delegated (Power BI Service)", - "value": "OrgApp.Read.All" + "value": "RetailDataManager.Read.All" }, { "description": "Allows modifying retail data manager items on the user’s behalf.", @@ -5019,11 +5047,11 @@ "value": "RetailDataManager.Reshare.All" }, { - "description": " ", - "displayName": "Scorecard.Execute (retired)", - "id": "dc75a12a-fef2-436d-8311-fed5b7e3a9d0", + "description": "The app can view all storage accounts registered with Power BI that the signed in user is an admin of.", + "displayName": "View all storage accounts", + "id": "e677843f-76d8-44d3-bcdb-ec40dea919e7", "origin": "Delegated (Power BI Service)", - "value": "Scorecard.Execute.All" + "value": "StorageAccount.Read.All" }, { "description": "The app can view and edit all storage accounts registered with Power BI that the signed in user is an admin of.", @@ -5137,20 +5165,6 @@ "origin": "Delegated (Power BI Service)", "value": "Warehouse.Reshare.All" }, - { - "description": "Allows the app to make API calls that require restore permissions on all Warehouses, on behalf of the signed-in user.", - "displayName": "Make API calls that require restore permissions on all Warehouses", - "id": "7da32ee4-ec68-43a4-b13a-b5385ad9770e", - "origin": "Delegated (Power BI Service)", - "value": "Warehouse.Restore.All" - }, - { - "description": "The app can view all storage accounts registered with Power BI that the signed in user is an admin of.", - "displayName": "View all storage accounts", - "id": "e677843f-76d8-44d3-bcdb-ec40dea919e7", - "origin": "Delegated (Power BI Service)", - "value": "StorageAccount.Read.All" - }, { "description": " ", "displayName": "SQLEndpoint.Reshare (retired)", @@ -5172,6 +5186,20 @@ "origin": "Delegated (Power BI Service)", "value": "SQLEndpoint.Read.All" }, + { + "description": " ", + "displayName": "SQLEndpoint.Execute (retired)", + "id": "aa70d616-e57e-4a5a-84cd-07de4250dd2e", + "origin": "Delegated (Power BI Service)", + "value": "SQLEndpoint.Execute.All" + }, + { + "description": " ", + "displayName": "Scorecard.Execute (retired)", + "id": "dc75a12a-fef2-436d-8311-fed5b7e3a9d0", + "origin": "Delegated (Power BI Service)", + "value": "Scorecard.Execute.All" + }, { "description": "Allows the app to make API calls that require read permissions on all scorecards, on behalf of the signed-in user.", "displayName": "Make API calls that require read permissions on all scorecards", @@ -5222,25 +5250,25 @@ "value": "SemanticModel.ReadWrite.All" }, { - "description": " ", - "displayName": "SemanticModel.Reshare (retired)", - "id": "868c9b47-9e35-4c69-bac3-042213ef72a3", + "description": "Allows modifying mirrored databases on the user’s behalf.", + "displayName": "Read and write mirrored databases", + "id": "2eb0ab4e-195e-45ec-9eb3-3b9842bea4f4", "origin": "Delegated (Power BI Service)", - "value": "SemanticModel.Reshare.All" + "value": "MirroredDatabase.ReadWrite.All" }, { "description": " ", - "displayName": "MirroredDatabase.Reshare (retired)", - "id": "c18991d0-0a42-4567-983a-1993bc79f327", + "displayName": "SemanticModel.Reshare (retired)", + "id": "868c9b47-9e35-4c69-bac3-042213ef72a3", "origin": "Delegated (Power BI Service)", - "value": "MirroredDatabase.Reshare.All" + "value": "SemanticModel.Reshare.All" }, { - "description": "Allows executing spark job definitions on the user’s behalf.", - "displayName": "Execute spark job definitions", - "id": "3492d2fc-251d-4a2b-8be4-97f06fd6d0d4", + "description": "Allows reading spark job definitions on the user’s behalf.", + "displayName": "Read spark job definitions", + "id": "beaf3087-05af-4060-a0a5-29779c902004", "origin": "Delegated (Power BI Service)", - "value": "SparkJobDefinition.Execute.All" + "value": "SparkJobDefinition.Read.All" }, { "description": "Allows modifying spark job definitions on the user’s behalf.", @@ -5292,39 +5320,39 @@ "value": "SQLDatabase.Reshare.All" }, { - "description": " ", - "displayName": "SQLEndpoint.Execute (retired)", - "id": "aa70d616-e57e-4a5a-84cd-07de4250dd2e", + "description": "Allows executing spark job definitions on the user’s behalf.", + "displayName": "Execute spark job definitions", + "id": "3492d2fc-251d-4a2b-8be4-97f06fd6d0d4", "origin": "Delegated (Power BI Service)", - "value": "SQLEndpoint.Execute.All" + "value": "SparkJobDefinition.Execute.All" }, { - "description": "Allows reading spark job definitions on the user’s behalf.", - "displayName": "Read spark job definitions", - "id": "beaf3087-05af-4060-a0a5-29779c902004", + "description": "Allows the app to make API calls that require restore permissions on all Warehouses, on behalf of the signed-in user.", + "displayName": "Make API calls that require restore permissions on all Warehouses", + "id": "7da32ee4-ec68-43a4-b13a-b5385ad9770e", "origin": "Delegated (Power BI Service)", - "value": "SparkJobDefinition.Read.All" + "value": "Warehouse.Restore.All" }, { - "description": " ", - "displayName": "WarehouseSnapshot.Execute (retired)", - "id": "f132046a-f99f-4e2f-af2c-bcc6690050a5", + "description": "Allows reading mirrored databases on the user’s behalf.", + "displayName": "Read mirrored databases", + "id": "10051e25-9077-418c-a076-32a2d35132a2", "origin": "Delegated (Power BI Service)", - "value": "WarehouseSnapshot.Execute.All" + "value": "MirroredDatabase.Read.All" }, { - "description": "Allows modifying mirrored databases on the user’s behalf.", - "displayName": "Read and write mirrored databases", - "id": "2eb0ab4e-195e-45ec-9eb3-3b9842bea4f4", + "description": " ", + "displayName": "MirroredDatabase.Execute (retired)", + "id": "67d4aa3f-531f-4db2-a382-7db42788fd35", "origin": "Delegated (Power BI Service)", - "value": "MirroredDatabase.ReadWrite.All" + "value": "MirroredDatabase.Execute.All" }, { - "description": "Allows the app to create and manage external data shares for all mirrored Databases, on behalf of the signed-in user.", - "displayName": "Allows the app to create and manage external data shares for all mirrored Databases", - "id": "eb433b13-ec6d-487b-8411-b5fadda75072", + "description": "Allows reading eventhouses on the user’s behalf.", + "displayName": "Read eventhouses", + "id": "cd1718e4-3e09-4381-a6e1-183e245f8613", "origin": "Delegated (Power BI Service)", - "value": "MirroredDatabase.ExternalDataShare.All" + "value": "Eventhouse.Read.All" }, { "description": "Allows modifying eventhouses on the user’s behalf.", @@ -5438,6 +5466,13 @@ "origin": "Delegated (Power BI Service)", "value": "GraphInstance.Reshare.All" }, + { + "description": " ", + "displayName": "Eventhouse.Execute (retired)", + "id": "0a5f551e-003b-482b-b5fb-7124a9510ba1", + "origin": "Delegated (Power BI Service)", + "value": "Eventhouse.Execute.All" + }, { "description": "Allows the app to make API calls that executes requests on all API for GraphQL items, on behalf of the signed-in user.", "displayName": "Make API calls that executes requests on all API for GraphQL items", @@ -5446,32 +5481,25 @@ "value": "GraphQL.Execute.All" }, { - "description": "Allows reading eventhouses on the user’s behalf.", - "displayName": "Read eventhouses", - "id": "cd1718e4-3e09-4381-a6e1-183e245f8613", - "origin": "Delegated (Power BI Service)", - "value": "Eventhouse.Read.All" - }, - { - "description": "Allows executing GraphQLApis on the user’s behalf.", - "displayName": "Execute GraphQLApis", - "id": "cece14a0-0fa7-4de3-b458-69bd0cfea634", + "description": " ", + "displayName": "Environment.Reshare (retired)", + "id": "72e814f5-a6b9-4316-b2ca-d07f426c178c", "origin": "Delegated (Power BI Service)", - "value": "GraphQLApi.Execute.All" + "value": "Environment.Reshare.All" }, { - "description": " ", - "displayName": "Eventhouse.Execute (retired)", - "id": "0a5f551e-003b-482b-b5fb-7124a9510ba1", + "description": "Allows reading environment items on the user’s behalf.", + "displayName": "Read environment items", + "id": "80a4f621-10a7-45e5-a961-79e9b81831d0", "origin": "Delegated (Power BI Service)", - "value": "Eventhouse.Execute.All" + "value": "Environment.Read.All" }, { - "description": "Allows modifying environment items on the user’s behalf.", - "displayName": "Read and write environment items", - "id": "995d4201-6a2d-45c6-bad2-9f2aba89298d", + "description": "Allows reading Databricks workspaces catalog metadata on the user’s behalf.", + "displayName": "Read Databricks workspaces catalog metadata.", + "id": "6cadaf62-a218-4d72-a641-0f85c813ece3", "origin": "Delegated (Power BI Service)", - "value": "Environment.ReadWrite.All" + "value": "DatabricksCatalog.Read.All" }, { "description": "Allows executing dataflows on the user’s behalf.", @@ -5586,18 +5614,18 @@ "value": "Environment.Execute.All" }, { - "description": "Allows reading environment items on the user’s behalf.", - "displayName": "Read environment items", - "id": "80a4f621-10a7-45e5-a961-79e9b81831d0", + "description": "Allows modifying environment items on the user’s behalf.", + "displayName": "Read and write environment items", + "id": "995d4201-6a2d-45c6-bad2-9f2aba89298d", "origin": "Delegated (Power BI Service)", - "value": "Environment.Read.All" + "value": "Environment.ReadWrite.All" }, { - "description": " ", - "displayName": "Environment.Reshare (retired)", - "id": "72e814f5-a6b9-4316-b2ca-d07f426c178c", + "description": "Allows executing GraphQLApis on the user’s behalf.", + "displayName": "Execute GraphQLApis", + "id": "cece14a0-0fa7-4de3-b458-69bd0cfea634", "origin": "Delegated (Power BI Service)", - "value": "Environment.Reshare.All" + "value": "GraphQLApi.Execute.All" }, { "description": "Allows reading GraphQLApis on the user’s behalf.", @@ -5615,10 +5643,10 @@ }, { "description": " ", - "displayName": "GraphQLApi.Reshare (retired)", - "id": "88cf9f59-aa53-4386-ae14-3c8263713766", + "displayName": "KQLQueryset.Execute (retired)", + "id": "b84b0d8d-9870-4b2b-92d2-9bfa7f940db3", "origin": "Delegated (Power BI Service)", - "value": "GraphQLApi.Reshare.All" + "value": "KQLQueryset.Execute.All" }, { "description": "Allows reading KQL querysets on the user’s behalf.", @@ -5732,20 +5760,6 @@ "origin": "Delegated (Power BI Service)", "value": "MirroredAzureDatabricksCatalog.Reshare.All" }, - { - "description": " ", - "displayName": "MirroredDatabase.Execute (retired)", - "id": "67d4aa3f-531f-4db2-a382-7db42788fd35", - "origin": "Delegated (Power BI Service)", - "value": "MirroredDatabase.Execute.All" - }, - { - "description": " ", - "displayName": "KQLQueryset.Execute (retired)", - "id": "b84b0d8d-9870-4b2b-92d2-9bfa7f940db3", - "origin": "Delegated (Power BI Service)", - "value": "KQLQueryset.Execute.All" - }, { "description": " ", "displayName": "KQLDataConnection.Reshare (retired)", @@ -5767,6 +5781,20 @@ "origin": "Delegated (Power BI Service)", "value": "KQLDataConnection.Read.All" }, + { + "description": " ", + "displayName": "KQLDataConnection.Execute (retired)", + "id": "6872ffe8-d8d4-46f9-9a32-5537dad08dd2", + "origin": "Delegated (Power BI Service)", + "value": "KQLDataConnection.Execute.All" + }, + { + "description": " ", + "displayName": "GraphQLApi.Reshare (retired)", + "id": "88cf9f59-aa53-4386-ae14-3c8263713766", + "origin": "Delegated (Power BI Service)", + "value": "GraphQLApi.Reshare.All" + }, { "description": "Allows the app to make API calls that require audit permissions on all items, on behalf of the signed-in user.", "displayName": "Make API calls that require audit permissions on all items", @@ -5816,6 +5844,13 @@ "origin": "Delegated (Power BI Service)", "value": "ItemMetadata.Read.All" }, + { + "description": "Allows the app to create and manage external data shares for all mirrored Databases, on behalf of the signed-in user.", + "displayName": "Allows the app to create and manage external data shares for all mirrored Databases", + "id": "eb433b13-ec6d-487b-8411-b5fadda75072", + "origin": "Delegated (Power BI Service)", + "value": "MirroredDatabase.ExternalDataShare.All" + }, { "description": "Allows the app to make API calls that can read and write the item metadata of all Fabric items, on behalf of the signed-in user.", "displayName": "Make API calls that can read and write item metadata for all Fabric items", @@ -5824,18 +5859,11 @@ "value": "ItemMetadata.ReadWrite.All" }, { - "description": "Allows reading mirrored databases on the user’s behalf.", - "displayName": "Read mirrored databases", - "id": "10051e25-9077-418c-a076-32a2d35132a2", - "origin": "Delegated (Power BI Service)", - "value": "MirroredDatabase.Read.All" - }, - { - "description": " ", - "displayName": "KQLDashboard.Execute (retired)", - "id": "6132db85-22d5-486c-b094-56eb8f746628", + "description": "Allows reading KQL dashboards on the user’s behalf.", + "displayName": "Read KQL dashboards", + "id": "f19ea7d7-2f31-4c6d-9845-d5480c5d1798", "origin": "Delegated (Power BI Service)", - "value": "KQLDashboard.Execute.All" + "value": "KQLDashboard.Read.All" }, { "description": "Allows modifying KQL dashboards on the user’s behalf.", @@ -5888,24 +5916,17 @@ }, { "description": " ", - "displayName": "KQLDataConnection.Execute (retired)", - "id": "6872ffe8-d8d4-46f9-9a32-5537dad08dd2", - "origin": "Delegated (Power BI Service)", - "value": "KQLDataConnection.Execute.All" - }, - { - "description": "Allows reading KQL dashboards on the user’s behalf.", - "displayName": "Read KQL dashboards", - "id": "f19ea7d7-2f31-4c6d-9845-d5480c5d1798", + "displayName": "KQLDashboard.Execute (retired)", + "id": "6132db85-22d5-486c-b094-56eb8f746628", "origin": "Delegated (Power BI Service)", - "value": "KQLDashboard.Read.All" + "value": "KQLDashboard.Execute.All" }, { - "description": "Allows reading Databricks workspaces catalog metadata on the user’s behalf.", - "displayName": "Read Databricks workspaces catalog metadata.", - "id": "6cadaf62-a218-4d72-a641-0f85c813ece3", + "description": " ", + "displayName": "WarehouseSnapshot.Execute (retired)", + "id": "f132046a-f99f-4e2f-af2c-bcc6690050a5", "origin": "Delegated (Power BI Service)", - "value": "DatabricksCatalog.Read.All" + "value": "WarehouseSnapshot.Execute.All" }, { "description": "Allows reading warehouse snapshots on the user’s behalf.", @@ -5915,11 +5936,11 @@ "value": "WarehouseSnapshot.Read.All" }, { - "description": " ", - "displayName": "WarehouseSnapshot.Reshare (retired)", - "id": "7e23ffe1-cea7-435d-94ce-4a7b4e8b38a0", + "description": "Allows modifying warehouse snapshots on the user’s behalf.", + "displayName": "Read and write warehouse snapshots", + "id": "00a826b4-8fc8-4273-b68f-5947f7d13795", "origin": "Delegated (Power BI Service)", - "value": "WarehouseSnapshot.Reshare.All" + "value": "WarehouseSnapshot.ReadWrite.All" }, { "description": "Allows the app to read any alert", @@ -6488,13 +6509,6 @@ "origin": "Application (WindowsDefenderATP)", "value": "Vulnerability.Read.All" }, - { - "description": "Allows modifying warehouse snapshots on the user’s behalf.", - "displayName": "Read and write warehouse snapshots", - "id": "00a826b4-8fc8-4273-b68f-5947f7d13795", - "origin": "Delegated (Power BI Service)", - "value": "WarehouseSnapshot.ReadWrite.All" - }, { "description": "Allows the app to have the same access to information in the directory as the signed-in user.", "displayName": "Access the directory as the signed-in user", @@ -6502,6 +6516,13 @@ "origin": "Delegated (Windows Azure Active Directory)", "value": "Directory.AccessAsUser.All" }, + { + "description": "Allows the app to read all your organization's policies without a signed-in user. ", + "displayName": "Read your organization's policies", + "id": "6c2d1b1d-a490-4178-ba6b-7efceda9129b", + "origin": "Application (Windows Azure Active Directory)", + "value": "Policy.Read.All" + }, { "description": "Allows the app to read the memberships of hidden groups and administrative units without a signed-in user.", "displayName": "Read all hidden memberships", @@ -6635,13 +6656,6 @@ "origin": "Application (Purview Ecosystem)", "value": "Purview.UploadActivity.All" }, - { - "description": "Allows the caller to perform product signup eligibility check for the given user", - "displayName": "Users.Signup.Product", - "id": "62c3283a-e0b2-4608-85d5-013e99604063", - "origin": "Delegated (Signup)", - "value": "Users.Signup.Product" - }, { "description": "Allows the app access to Purview Read SensitivityLabels APIs", "displayName": "Read Sensitivity Labels for Purview", @@ -6649,6 +6663,13 @@ "origin": "Application (Purview Ecosystem)", "value": "Purview.SensitivityLabels.Read" }, + { + "description": "Allows the app access to Purview File SensitivityLabels APIs", + "displayName": "File Sensitivity Labels for Purview", + "id": "a817e1ed-b6e2-4214-a252-ab12ec7dad09", + "origin": "Application (Purview Ecosystem)", + "value": "Purview.SensitivityLabels.File" + }, { "description": "Allows the app access to Purview SensitivityLabels APIs", "displayName": "Sensitivity Labels for Purview", @@ -6656,6 +6677,13 @@ "origin": "Application (Purview Ecosystem)", "value": "Purview.SensitivityLabels.All" }, + { + "description": " ", + "displayName": "WarehouseSnapshot.Reshare (retired)", + "id": "7e23ffe1-cea7-435d-94ce-4a7b4e8b38a0", + "origin": "Delegated (Power BI Service)", + "value": "WarehouseSnapshot.Reshare.All" + }, { "description": "Allows the app to make API calls that commit workspace content and setting to remote git repository, on behalf of the signed-in user.", "displayName": "Make API calls that commit workspace content and setting to remote git repository.", @@ -6705,6 +6733,13 @@ "origin": "Application (Purview Ecosystem)", "value": "Purview.Activities.UploadBatch.All" }, + { + "description": "Allows the caller to perform product signup eligibility check for the given user", + "displayName": "Users.Signup.Product", + "id": "62c3283a-e0b2-4608-85d5-013e99604063", + "origin": "Delegated (Signup)", + "value": "Users.Signup.Product" + }, { "description": "Allows the app create access to data assets and metadata.", "displayName": "Create Assets for Purview", @@ -6712,13 +6747,6 @@ "origin": "Application (Purview Ecosystem)", "value": "Purview.Assets.Create" }, - { - "description": "Allows the app delete access to data assets and metadata.", - "displayName": "Delete Assets for Purview", - "id": "f6893e92-b5aa-4634-870a-e2bc4d2d7fad", - "origin": "Application (Purview Ecosystem)", - "value": "Purview.Assets.Delete" - }, { "description": "Allows the app read access to data assets and metadata.", "displayName": "Read Assets for Purview", @@ -6776,11 +6804,18 @@ "value": "Purview.ProtectionScopes.Read.All" }, { - "description": "Allows the app access to Purview File SensitivityLabels APIs", - "displayName": "File Sensitivity Labels for Purview", - "id": "a817e1ed-b6e2-4214-a252-ab12ec7dad09", + "description": "Allows the app delete access to data assets and metadata.", + "displayName": "Delete Assets for Purview", + "id": "f6893e92-b5aa-4634-870a-e2bc4d2d7fad", "origin": "Application (Purview Ecosystem)", - "value": "Purview.SensitivityLabels.File" + "value": "Purview.Assets.Delete" + }, + { + "description": " ", + "displayName": "DataAgent.Reshare (retired)", + "id": "82b1d51c-42df-4ba9-9aee-bbba1e3f2ab7", + "origin": "Delegated (Power BI Service)", + "value": "DataAgent.Reshare.All" }, { "description": "Allows the app create an on-demand Skype meeting and join guest users into Skype for Business services", @@ -6789,13 +6824,6 @@ "origin": "Application (Skype for Business Online)", "value": "Anonymous" }, - { - "description": "Allows the app to send and receive audio and video; and manage audio/video service scenarios", - "displayName": "Send/Receive Audio and Video (preview)", - "id": "05a4e3e8-cfa6-4934-bb91-b6fc4ce6f340", - "origin": "Application (Skype for Business Online)", - "value": "Conversations.AudioVideo" - }, { "description": "Allows the app to send and receive instant messages; and manage instant messaging service scenarios", "displayName": "Send/Receive Instant Messages (preview)", @@ -6979,11 +7007,11 @@ "value": "User.ReadWrite" }, { - "description": "Allows the app to read all your organization's policies without a signed-in user. ", - "displayName": "Read your organization's policies", - "id": "6c2d1b1d-a490-4178-ba6b-7efceda9129b", - "origin": "Application (Windows Azure Active Directory)", - "value": "Policy.Read.All" + "description": "Allows the app to send and receive audio and video; and manage audio/video service scenarios", + "displayName": "Send/Receive Audio and Video (preview)", + "id": "05a4e3e8-cfa6-4934-bb91-b6fc4ce6f340", + "origin": "Application (Skype for Business Online)", + "value": "Conversations.AudioVideo" }, { "description": "Allows the app to access the SQL Adx Proxy on behalf of the signed-in user.", @@ -7056,25 +7084,39 @@ "value": "PhysicalRP.ReadWrite" }, { - "description": "Allows the application to list and query any shared user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant on behalf of the signed-in user.", - "displayName": "Read all shared cross-tenant user profiles and export their data", - "id": "759dcd16-3c90-463c-937e-abf89f991c18", - "origin": "Delegated (Microsoft Graph)", - "value": "CrossTenantUserProfileSharing.Read.All" + "description": "Allows the Application to read and write the user's data pertaining to itself in the Intune Mobile Application Management service", + "displayName": "Read and Write the User's App Management data", + "id": "3c7192af-9629-4473-9276-d35e4e4b36c5", + "origin": "Delegated (Microsoft Mobile Application Management)", + "value": "DeviceManagementManagedApps.ReadWrite" }, { - "description": " ", - "displayName": "DataAgent.Reshare (retired)", - "id": "82b1d51c-42df-4ba9-9aee-bbba1e3f2ab7", + "description": "Allows modifying data agents on the user’s behalf.", + "displayName": "Read and write data agents", + "id": "c23fda5c-561f-4890-ad72-5f57bb7496fd", "origin": "Delegated (Power BI Service)", - "value": "DataAgent.Reshare.All" + "value": "DataAgent.ReadWrite.All" }, { - "description": "Allows reading data agents on the user’s behalf.", - "displayName": "Read data agents", - "id": "40fa91d5-73ef-412c-a8c8-c8658670d0eb", + "description": "Allows executing data agents on the user’s behalf.", + "displayName": "Execute data agents", + "id": "c6756612-6853-4145-a661-90c1d045b2dc", "origin": "Delegated (Power BI Service)", - "value": "DataAgent.Read.All" + "value": "DataAgent.Execute.All" + }, + { + "description": "Allow application to access user’s mailbox via POP protocol", + "displayName": "POP.AccessAsApp", + "id": "cb842b43-da6e-4506-86fe-bb12199c656d", + "origin": "Application (Office 365 Exchange Online)", + "value": "POP.AccessAsApp" + }, + { + "description": "Download all reports via the Office 365 reporting web service", + "displayName": "ReportingWebService.Read.All", + "id": "b4d5a5c7-c085-487f-b922-ef0d6ebde6b1", + "origin": "Application (Office 365 Exchange Online)", + "value": "ReportingWebService.Read.All" }, { "description": "Allows the app to have send access to all mailboxes", @@ -7181,6 +7223,13 @@ "origin": "Delegated (Office 365 Exchange Online)", "value": "Contacts.ReadWrite" }, + { + "description": "Allows the app to read company places (conference rooms and room lists) for calendar events and other applications, without a signed-in user.", + "displayName": "Read all company places", + "id": "4830e04b-48ac-4de5-bbd9-8aceb58e506b", + "origin": "Application (Office 365 Exchange Online)", + "value": "Place.Read.All" + }, { "description": "Allows the app to create, read, update, and delete contacts a user has permissions to, including their own and shared contacts.", "displayName": "Read and write user and shared contacts ", @@ -7189,39 +7238,32 @@ "value": "Contacts.ReadWrite.All" }, { - "description": "Allows the app to create, read, update, and delete contacts a user has permissions to, including their own and shared contacts.", - "displayName": "Read and write user and shared contacts ", - "id": "c54cba4f-60fe-4332-b0de-b5990fd1999e", - "origin": "Delegated (Office 365 Exchange Online)", - "value": "Contacts.ReadWrite.Shared" - }, - { - "description": "Download all reports via the Office 365 reporting web service", - "displayName": "ReportingWebService.Read.All", - "id": "b4d5a5c7-c085-487f-b922-ef0d6ebde6b1", + "description": "Allows the application to read and write tenant-wide people settings without a signed-in user.", + "displayName": "Read and write all tenant-wide people settings", + "id": "98ed40ef-611a-4479-bd35-eaa7863e946a", "origin": "Application (Office 365 Exchange Online)", - "value": "ReportingWebService.Read.All" + "value": "PeopleSettings.ReadWrite.All" }, { - "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange ActiveSync.", - "displayName": "Access mailboxes via Exchange ActiveSync", - "id": "266d2589-20b5-4f91-9a03-89247d1be8da", - "origin": "Delegated (Office 365 Exchange Online)", - "value": "EAS.AccessAsUser.All" + "description": "Allows the app to read and write the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed SKUs and tenant branding information.", + "displayName": "Organization.ReadWrite.All", + "id": "c976971c-a54d-4835-a240-2479e3dac74a", + "origin": "Application (Office 365 Exchange Online)", + "value": "Organization.ReadWrite.All" }, { - "description": "Allow application to access user’s mailbox via POP protocol", - "displayName": "POP.AccessAsApp", - "id": "cb842b43-da6e-4506-86fe-bb12199c656d", + "description": "Allows the app to read events of all calendars without a signed-in user.", + "displayName": "Read calendars in all mailboxes", + "id": "798ee544-9d2d-430c-a058-570e29e34338", "origin": "Application (Office 365 Exchange Online)", - "value": "POP.AccessAsApp" + "value": "Calendars.Read" }, { - "description": "Allows the application to read and write tenant-wide people settings without a signed-in user.", - "displayName": "Read and write all tenant-wide people settings", - "id": "98ed40ef-611a-4479-bd35-eaa7863e946a", + "description": "Allows the app to read events of all R without a signed-in user", + "displayName": "Read calendars in all mailboxes", + "id": "2dfdc6dc-2fa7-4a2c-a922-dbd4f85d17be", "origin": "Application (Office 365 Exchange Online)", - "value": "PeopleSettings.ReadWrite.All" + "value": "Calendars.Read.All" }, { "description": "Allows the app to create, read, update, and delete events of all calendars without a signed-in user.", @@ -7328,13 +7370,6 @@ "origin": "Application (Office 365 Exchange Online)", "value": "Organization.Read.All" }, - { - "description": "Allows the app to read and write the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed SKUs and tenant branding information.", - "displayName": "Organization.ReadWrite.All", - "id": "c976971c-a54d-4835-a240-2479e3dac74a", - "origin": "Application (Office 365 Exchange Online)", - "value": "Organization.ReadWrite.All" - }, { "description": "Allows the application to read tenant-wide people settings without a signed-in user.", "displayName": "Read all tenant-wide people settings", @@ -7343,11 +7378,18 @@ "value": "PeopleSettings.Read.All" }, { - "description": "Allows the app to read company places (conference rooms and room lists) for calendar events and other applications, without a signed-in user.", - "displayName": "Read all company places", - "id": "4830e04b-48ac-4de5-bbd9-8aceb58e506b", - "origin": "Application (Office 365 Exchange Online)", - "value": "Place.Read.All" + "description": "Allows the app to create, read, update, and delete contacts a user has permissions to, including their own and shared contacts.", + "displayName": "Read and write user and shared contacts ", + "id": "c54cba4f-60fe-4332-b0de-b5990fd1999e", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Contacts.ReadWrite.Shared" + }, + { + "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange ActiveSync.", + "displayName": "Access mailboxes via Exchange ActiveSync", + "id": "266d2589-20b5-4f91-9a03-89247d1be8da", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "EAS.AccessAsUser.All" }, { "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange Web Services.", @@ -7357,18 +7399,18 @@ "value": "EWS.AccessAsUser.All" }, { - "description": "Allows the app to manage a limited set of Exchange Online configuration objects via the adminapi/v2.0 endpoint. This permission is intended for specific scenarios and requires appropriate Exchange RBAC role assignments. This permission replaces the previous Exchange.ManageV2 permission.", - "displayName": "Manage Exchange Online Admin API", - "id": "9f021f4d-e924-4317-bf46-8db5e8340c6c", + "description": "This allows application to host MyDay Owa powered experience for shared mailbox and calendar", + "displayName": "OPX.MyDay.Shared", + "id": "405782ba-4062-4ea3-bd33-f7c731841e3b", "origin": "Delegated (Office 365 Exchange Online)", - "value": "Exchange.AdminAPI.Manage" + "value": "OPX.MyDay.Shared" }, { - "description": "Allows the app to manage the organization's Exchange environment, such as mailboxes, groups, and other configuration objects. To enable management actions, an admin must assign the appropriate roles to the app user.", - "displayName": "Manage Exchange configuration", - "id": "ab4f2b77-0b06-4fc1-a9de-02113fc2ab7c", + "description": "Allows the app to read the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed SKUs and tenant branding information.", + "displayName": "Organization.Read.All", + "id": "1d490c92-d2ca-4a30-b52e-6edf5f279f4d", "origin": "Delegated (Office 365 Exchange Online)", - "value": "Exchange.Manage" + "value": "Organization.Read.All" }, { "description": "Allows the app to read and write the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed SKUs and tenant branding information.", @@ -7476,46 +7518,46 @@ "value": "User.Read.All" }, { - "description": "Allows the app to read a basic set of profile properties of other users in your organization on behalf of the signed-in user. This includes display name, first and last name, email address and photo.", - "displayName": "Read all users' basic profiles", - "id": "9b005f11-86f0-45f7-8c27-4fff5d849916", + "description": "This allows application to host MyDay Owa powered experience for both user and shared mailbox and calendar", + "displayName": "OPX.MyDay.All", + "id": "d056cee4-aed2-4aa4-b2a9-292fe18b06d2", "origin": "Delegated (Office 365 Exchange Online)", - "value": "User.ReadBasic.All" + "value": "OPX.MyDay.All" }, { - "description": "Allows the app to read a basic set of profile properties of users in your company or school on behalf of the signed-in user. Includes display name, photo, and email address.", - "displayName": "Read all users' basic profiles", - "id": "6222dbab-a24c-4210-9d91-2f47cf565614", + "description": "This allows the application to host MyDay Owa powered experience", + "displayName": "OPX.MyDay", + "id": "8cac6046-ce43-4348-855c-efd9d956b7bf", "origin": "Delegated (Office 365 Exchange Online)", - "value": "User.ReadBasic.All" + "value": "OPX.MyDay" }, { - "description": "Allows the app to read the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed SKUs and tenant branding information.", - "displayName": "Organization.Read.All", - "id": "1d490c92-d2ca-4a30-b52e-6edf5f279f4d", + "description": "Allows the app to create, read, update and delete user notes", + "displayName": "Create, read, update and delete user notes", + "id": "1b69a6c3-108d-42d0-a3ec-fafcd610e80b", "origin": "Delegated (Office 365 Exchange Online)", - "value": "Organization.Read.All" + "value": "Notes.ReadWrite" }, { - "description": "This allows application to host MyDay Owa powered experience for shared mailbox and calendar", - "displayName": "OPX.MyDay.Shared", - "id": "405782ba-4062-4ea3-bd33-f7c731841e3b", + "description": "Allows the app to read user notes", + "displayName": "Read user notes", + "id": "505d82a7-24f3-4632-bffc-4d21625b31de", "origin": "Delegated (Office 365 Exchange Online)", - "value": "OPX.MyDay.Shared" + "value": "Notes.Read" }, { - "description": "This allows application to host MyDay Owa powered experience for both user and shared mailbox and calendar", - "displayName": "OPX.MyDay.All", - "id": "d056cee4-aed2-4aa4-b2a9-292fe18b06d2", + "description": "Allows the app to manage a limited set of Exchange Online configuration objects via the adminapi/v2.0 endpoint. This permission is intended for specific scenarios and requires appropriate Exchange RBAC role assignments. This permission replaces the previous Exchange.ManageV2 permission.", + "displayName": "Manage Exchange Online Admin API", + "id": "9f021f4d-e924-4317-bf46-8db5e8340c6c", "origin": "Delegated (Office 365 Exchange Online)", - "value": "OPX.MyDay.All" + "value": "Exchange.AdminAPI.Manage" }, { - "description": "This allows the application to host MyDay Owa powered experience", - "displayName": "OPX.MyDay", - "id": "8cac6046-ce43-4348-855c-efd9d956b7bf", + "description": "Allows the app to manage the organization's Exchange environment, such as mailboxes, groups, and other configuration objects. To enable management actions, an admin must assign the appropriate roles to the app user.", + "displayName": "Manage Exchange configuration", + "id": "ab4f2b77-0b06-4fc1-a9de-02113fc2ab7c", "origin": "Delegated (Office 365 Exchange Online)", - "value": "OPX.MyDay" + "value": "Exchange.Manage" }, { "description": "Allows the app to manage a limited set of Exchange Online configuration objects via the adminapi/v2.0 endpoint. This permission is intended for specific scenarios and requires appropriate Exchange RBAC role assignments.", @@ -7559,6 +7601,13 @@ "origin": "Delegated (Office 365 Exchange Online)", "value": "Mail.Read.All" }, + { + "description": "Allow the application full access to the OCM service on behalf of the signed-in user", + "displayName": "Have full access to the OCM Service ", + "id": "9454efbe-3f0a-4074-9ec5-a25adefb6f87", + "origin": "Delegated (O365SBRM Service)", + "value": "user_impersonation" + }, { "description": "Allows the app to read mail a user can access, including their own and shared mail.", "displayName": "Read user and shared mail ", @@ -7566,20 +7615,6 @@ "origin": "Delegated (Office 365 Exchange Online)", "value": "Mail.Read.Shared" }, - { - "description": "Allows the app to read the signed-in user's mailbox except body, previewBody, attachments and any extended properties.", - "displayName": "Read user basic mail", - "id": "dab085de-3e14-432f-a47f-84b6457059c4", - "origin": "Delegated (Office 365 Exchange Online)", - "value": "Mail.ReadBasic" - }, - { - "description": "Allows the app to read events of all R without a signed-in user", - "displayName": "Read calendars in all mailboxes", - "id": "2dfdc6dc-2fa7-4a2c-a922-dbd4f85d17be", - "origin": "Application (Office 365 Exchange Online)", - "value": "Calendars.Read.All" - }, { "description": "Allows the app to create, read, update, and delete email in user mailboxes. Does not include permission to send mail.", "displayName": "Read and write user mail", @@ -7587,6 +7622,13 @@ "origin": "Delegated (Office 365 Exchange Online)", "value": "Mail.ReadWrite" }, + { + "description": "Allows the app to create, read, update, and delete mail a user has permission to access, including their own and shared mail. Does not include permission to send mail.", + "displayName": "Read and write user and shared mail ", + "id": "140e747e-90d3-4de0-8618-85a0cc7a1129", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Mail.ReadWrite.All" + }, { "description": "Allows the app to create, read, update, and delete mail a user has permission to access, including their own and shared mail. Does not include permission to send mail.", "displayName": "Read and write user and shared mail ", @@ -7630,46 +7672,46 @@ "value": "MailboxSettings.ReadWrite" }, { - "description": "Allows the app to read user notes", - "displayName": "Read user notes", - "id": "505d82a7-24f3-4632-bffc-4d21625b31de", + "description": "Allows the app to read the signed-in user's mailbox except body, previewBody, attachments and any extended properties.", + "displayName": "Read user basic mail", + "id": "dab085de-3e14-432f-a47f-84b6457059c4", "origin": "Delegated (Office 365 Exchange Online)", - "value": "Notes.Read" + "value": "Mail.ReadBasic" }, { - "description": "Allows the app to create, read, update and delete user notes", - "displayName": "Create, read, update and delete user notes", - "id": "1b69a6c3-108d-42d0-a3ec-fafcd610e80b", + "description": "Allows the app to read a basic set of profile properties of users in your company or school on behalf of the signed-in user. Includes display name, photo, and email address.", + "displayName": "Read all users' basic profiles", + "id": "6222dbab-a24c-4210-9d91-2f47cf565614", "origin": "Delegated (Office 365 Exchange Online)", - "value": "Notes.ReadWrite" + "value": "User.ReadBasic.All" }, { - "description": "Allows the app to create, read, update, and delete mail a user has permission to access, including their own and shared mail. Does not include permission to send mail.", - "displayName": "Read and write user and shared mail ", - "id": "140e747e-90d3-4de0-8618-85a0cc7a1129", - "origin": "Delegated (Office 365 Exchange Online)", - "value": "Mail.ReadWrite.All" + "description": "A placeholder scope for preauth", + "displayName": "PreAuthPlaceholder", + "id": "25b4ea33-257e-47f5-b778-8df9c7e10548", + "origin": "Delegated (o365.servicecommunications.microsoft.com)", + "value": "PreAuthPlaceholder" }, { - "description": "Allows the app to create, read, and write a set of the current user's profile properties in your company or school. Includes display name, photo, and email address.", - "displayName": "Read and write user profiles", - "id": "f9408c03-bd3d-48c4-8bee-17a72d20bd9c", - "origin": "Delegated (Office 365 Exchange Online)", - "value": "User.ReadWrite" + "description": "This allows teams users to access HAPI", + "displayName": "teams", + "id": "e734da10-5e7c-48a0-a906-1a0d8b751264", + "origin": "Delegated (O365 Demeter)", + "value": "teams" }, { - "description": "Allows the app to read events of all calendars without a signed-in user.", - "displayName": "Read calendars in all mailboxes", - "id": "798ee544-9d2d-430c-a058-570e29e34338", - "origin": "Application (Office 365 Exchange Online)", - "value": "Calendars.Read" + "description": "Allows for all operations of library resources", + "displayName": "Librarian", + "id": "59699edb-24d7-488d-a355-2b0e39dce24c", + "origin": "Application (Microsoft Premonition)", + "value": "Library.ReadWrite" }, { - "description": "A placeholder scope for preauth", - "displayName": "PreAuthPlaceholder", - "id": "25b4ea33-257e-47f5-b778-8df9c7e10548", - "origin": "Delegated (o365.servicecommunications.microsoft.com)", - "value": "PreAuthPlaceholder" + "description": "Allows a client to access Premonition API on users behalf", + "displayName": "Access Premonition API", + "id": "33ee90e9-11ee-4949-81e2-b93e26b390d6", + "origin": "Delegated (Microsoft Premonition)", + "value": "All" }, { "description": "Allows the application to call Purview APIs without a signed-in user", @@ -7777,32 +7819,11 @@ "value": "Documents.Read.All" }, { - "description": "Our app will be a one stop shop for current and prospective customers who need Security, Privacy, and Compliance information around Microsoft Cloud (Azure, Dynamics CRM Online and Office 365). It should be open any tenant who has AAD record – trial tenants as well as paid tenant across Microsoft Cloud.", - "displayName": "Microsoft Service Trust", - "id": "b55dae21-0932-4324-a1cd-45a046d7a6e1", - "origin": "Delegated (Microsoft Service Trust)", - "value": "Trust.Content.All" - }, - { - "description": "Allows a client to access Premonition API on users behalf", - "displayName": "Access Premonition API", - "id": "33ee90e9-11ee-4949-81e2-b93e26b390d6", - "origin": "Delegated (Microsoft Premonition)", - "value": "All" - }, - { - "description": "Allows the app to run advanced hunting queries", - "displayName": "Run advanced hunting queries", - "id": "7734e8e5-8dde-42fc-b5ae-6eafea078693", - "origin": "Application (Microsoft Threat Protection)", - "value": "AdvancedHunting.Read.All" - }, - { - "description": "Allows for all operations of library resources", - "displayName": "Librarian", - "id": "59699edb-24d7-488d-a355-2b0e39dce24c", + "description": "Allows reading library resources", + "displayName": "Visitor", + "id": "91fb9a45-6b1c-4d38-b915-4f1987a64c1c", "origin": "Application (Microsoft Premonition)", - "value": "Library.ReadWrite" + "value": "Library.Read" }, { "description": "Allows control plane operations of VNETs owned by the user", @@ -7811,6 +7832,27 @@ "origin": "Delegated (Microsoft Power Platform Service - PROD)", "value": "VNET.ReadWrite" }, + { + "description": "Allow access the Office People API", + "displayName": "Access the Office People API", + "id": "9eb61caf-4504-44c6-9d98-48e6a1ab8639", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "User.ReadWrite" + }, + { + "description": "Allows the app to refresh and recreate on-premises configuration for Microsoft self-service password reset.", + "displayName": "Read, write and manage self-service password reset writeback configuration", + "id": "fc7e8088-95b5-453e-8bef-b17ecfec5ba3", + "origin": "Application (Microsoft password reset service)", + "value": "PasswordWriteback.RefreshClient.All" + }, + { + "description": "Allows the app to register a newer version of on-premises Microsoft Entra Connect Sync Agent.", + "displayName": "Read, write and manage Microsoft Entra Connect Sync Agent", + "id": "e006e431-a65b-4f3e-8808-77d29d4c5f1a", + "origin": "Application (Microsoft password reset service)", + "value": "PasswordWriteback.RegisterClientVersion.All" + }, { "description": "Directory.AccessAsUser.All", "displayName": "Directory.AccessAsUser.All", @@ -7916,13 +7958,6 @@ "origin": "Delegated (Microsoft People Cards Service)", "value": "User.Read.All" }, - { - "description": "Allow access the Office People API", - "displayName": "Access the Office People API", - "id": "9eb61caf-4504-44c6-9d98-48e6a1ab8639", - "origin": "Delegated (Microsoft People Cards Service)", - "value": "User.ReadWrite" - }, { "description": "Allows data plane access to all VNETs on the system", "displayName": "VNET.Read.All", @@ -7931,11 +7966,18 @@ "value": "VNET.Read.All" }, { - "description": "Allows reading library resources", - "displayName": "Visitor", - "id": "91fb9a45-6b1c-4d38-b915-4f1987a64c1c", - "origin": "Application (Microsoft Premonition)", - "value": "Library.Read" + "description": "Our app will be a one stop shop for current and prospective customers who need Security, Privacy, and Compliance information around Microsoft Cloud (Azure, Dynamics CRM Online and Office 365). It should be open any tenant who has AAD record – trial tenants as well as paid tenant across Microsoft Cloud.", + "displayName": "Microsoft Service Trust", + "id": "b55dae21-0932-4324-a1cd-45a046d7a6e1", + "origin": "Delegated (Microsoft Service Trust)", + "value": "Trust.Content.All" + }, + { + "description": "Allows the app to run advanced hunting queries", + "displayName": "Run advanced hunting queries", + "id": "7734e8e5-8dde-42fc-b5ae-6eafea078693", + "origin": "Application (Microsoft Threat Protection)", + "value": "AdvancedHunting.Read.All" }, { "description": "Allows the app to create or update any custom detection rule", @@ -7945,18 +7987,18 @@ "value": "CustomDetections.ReadWrite.All" }, { - "description": "Allows the app to read any incident", - "displayName": "Read all incidents", - "id": "a9790345-4595-42e4-971a-ccdc79f19b7c", - "origin": "Application (Microsoft Threat Protection)", - "value": "Incident.Read.All" + "description": "Read Write Access To MDLRest APIs", + "displayName": "MDLRest.ReadWrite", + "id": "bd79113c-40b8-4608-8c47-994bf0c2853d", + "origin": "Delegated (Microsoft.MileIQ.RESTService)", + "value": "MDLRest.ReadWrite" }, { - "description": "Allows the app to create or update any incident", - "displayName": "Read and write all incidents", - "id": "8d90f441-09cf-4fdc-ab45-e874fa3a28e8", - "origin": "Application (Microsoft Threat Protection)", - "value": "Incident.ReadWrite.All" + "description": "Allow the application full access to the Azure Key Vault service on behalf of the signed-in user", + "displayName": "Have full access to Azure Service Bus service", + "id": "40e16207-c5fd-4916-8ca4-64565f2367ca", + "origin": "Delegated (Microsoft.ServiceBus)", + "value": "user_impersonation" }, { "description": "Allows the app to read and write MCP tools on behalf of the user.", @@ -8064,32 +8106,32 @@ "value": "subscriptions.read" }, { - "description": "This allows teams users to access HAPI", - "displayName": "teams", - "id": "e734da10-5e7c-48a0-a906-1a0d8b751264", - "origin": "Delegated (O365 Demeter)", - "value": "teams" + "description": "Read Access To MDLRest APIs", + "displayName": "MDLRest.Read", + "id": "9b5904c8-49e7-4d21-81c0-118a2a9c7d81", + "origin": "Delegated (Microsoft.MileIQ.RESTService)", + "value": "MDLRest.Read" }, { - "description": "Allow the application full access to the Azure Key Vault service on behalf of the signed-in user", - "displayName": "Have full access to Azure Service Bus service", - "id": "40e16207-c5fd-4916-8ca4-64565f2367ca", - "origin": "Delegated (Microsoft.ServiceBus)", - "value": "user_impersonation" + "description": "MileIQ.All", + "displayName": "MileIQ.All", + "id": "d26f02bb-ae28-4375-9184-101879252b0f", + "origin": "Delegated (Microsoft.MileIQ.Dashboard)", + "value": "MileIQ.All" }, { - "description": "Read Write Access To MDLRest APIs", - "displayName": "MDLRest.ReadWrite", - "id": "bd79113c-40b8-4608-8c47-994bf0c2853d", - "origin": "Delegated (Microsoft.MileIQ.RESTService)", - "value": "MDLRest.ReadWrite" + "description": "Allows the app to read any incident", + "displayName": "Read all incidents", + "id": "a9790345-4595-42e4-971a-ccdc79f19b7c", + "origin": "Application (Microsoft Threat Protection)", + "value": "Incident.Read.All" }, { - "description": "Read Access To MDLRest APIs", - "displayName": "MDLRest.Read", - "id": "9b5904c8-49e7-4d21-81c0-118a2a9c7d81", - "origin": "Delegated (Microsoft.MileIQ.RESTService)", - "value": "MDLRest.Read" + "description": "Allows the app to create or update any incident", + "displayName": "Read and write all incidents", + "id": "8d90f441-09cf-4fdc-ab45-e874fa3a28e8", + "origin": "Application (Microsoft Threat Protection)", + "value": "Incident.ReadWrite.All" }, { "description": "Allows the app to run advanced hunting queries, that the signed-in user can execute.", @@ -8140,20 +8182,6 @@ "origin": "Delegated (Microsoft.Azconfig)", "value": "FeatureFlag.Read" }, - { - "description": "Allow the application to write feature flags on behalf of the signed-in user.", - "displayName": "Write Feature Flags", - "id": "f3cb665c-6320-4ae2-996d-b58707ade4c3", - "origin": "Delegated (Microsoft.Azconfig)", - "value": "FeatureFlag.Write" - }, - { - "description": "Allow the application full access to the OCM service on behalf of the signed-in user", - "displayName": "Have full access to the OCM Service ", - "id": "9454efbe-3f0a-4074-9ec5-a25adefb6f87", - "origin": "Delegated (O365SBRM Service)", - "value": "user_impersonation" - }, { "description": "Allow the application to delete key-values on behalf of the signed-in user.", "displayName": "Delete Key-Values", @@ -8161,6 +8189,13 @@ "origin": "Delegated (Microsoft.Azconfig)", "value": "KeyValue.Delete" }, + { + "description": "Allow the application to read key-values on behalf of the signed-in user.", + "displayName": "Read Key-Values", + "id": "8d17f7f7-030c-4b57-8129-cfb5a16433cd", + "origin": "Delegated (Microsoft.Azconfig)", + "value": "KeyValue.Read" + }, { "description": "Allow the application to write key-values on behalf of the signed-in user.", "displayName": "Write Key-Values", @@ -8204,25 +8239,25 @@ "value": "user_impersonation" }, { - "description": "MileIQ.All", - "displayName": "MileIQ.All", - "id": "d26f02bb-ae28-4375-9184-101879252b0f", - "origin": "Delegated (Microsoft.MileIQ.Dashboard)", - "value": "MileIQ.All" + "description": "Allow the application to write feature flags on behalf of the signed-in user.", + "displayName": "Write Feature Flags", + "id": "f3cb665c-6320-4ae2-996d-b58707ade4c3", + "origin": "Delegated (Microsoft.Azconfig)", + "value": "FeatureFlag.Write" }, { - "description": "Allow the application to read key-values on behalf of the signed-in user.", - "displayName": "Read Key-Values", - "id": "8d17f7f7-030c-4b57-8129-cfb5a16433cd", - "origin": "Delegated (Microsoft.Azconfig)", - "value": "KeyValue.Read" + "description": "Allows the app to read a basic set of profile properties of other users in your organization on behalf of the signed-in user. This includes display name, first and last name, email address and photo.", + "displayName": "Read all users' basic profiles", + "id": "9b005f11-86f0-45f7-8c27-4fff5d849916", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "User.ReadBasic.All" }, { - "description": "Allows modifying data agents on the user’s behalf.", - "displayName": "Read and write data agents", - "id": "c23fda5c-561f-4890-ad72-5f57bb7496fd", - "origin": "Delegated (Power BI Service)", - "value": "DataAgent.ReadWrite.All" + "description": "Allows the app to create, read, and write a set of the current user's profile properties in your company or school. Includes display name, photo, and email address.", + "displayName": "Read and write user profiles", + "id": "f9408c03-bd3d-48c4-8bee-17a72d20bd9c", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "User.ReadWrite" }, { "description": "c", @@ -8232,11 +8267,11 @@ "value": "activitydata.tenant.read" }, { - "description": "This allows the app to read AirAdminAction alerts", - "displayName": "AirAdminAction.tenant.read", - "id": "cc02f7ae-3d9b-42c9-bc91-3424d92c5547", - "origin": "Application (Office 365 Information Protection)", - "value": "AirAdminAction.tenant.read" + "description": "Allows the app to create, read, update, and delete documents and list items in all site collections on behalf of the signed-in user.", + "displayName": "Read and write items in all site collections", + "id": "640ddd16-e5b7-4d71-9690-3f4022699ee7", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "AllSites.Write" }, { "description": "Allows the app to read the current user's enterprise resources.", @@ -8350,6 +8385,13 @@ "origin": "Delegated (Office 365 SharePoint Online)", "value": "Sites.Selected" }, + { + "description": "Allows the app to read documents and list items in all site collections on behalf of the signed-in user.", + "displayName": "Read items in all site collections", + "id": "4e0d77b0-96ba-4398-af14-3baa780278f4", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "AllSites.Read" + }, { "description": "Allows the app to read site collection metadata using the SharePoint admin site, on behalf of the signed-in user.", "displayName": "Can view site collection metadata from the admin site", @@ -8358,32 +8400,25 @@ "value": "SitesMetadataAdmin.Read.All" }, { - "description": "Allows the app to create, read, update, and delete documents and list items in all site collections on behalf of the signed-in user.", - "displayName": "Read and write items in all site collections", - "id": "640ddd16-e5b7-4d71-9690-3f4022699ee7", - "origin": "Delegated (Office 365 SharePoint Online)", - "value": "AllSites.Write" - }, - { - "description": "Allows the app to read and write site collection metadata using the SharePoint admin site, on behalf of the signed-in user.", - "displayName": "Can view and edit site collection metadata from the admin site", - "id": "9aaa3660-6678-4cb8-b4b5-be92b6f4fbf0", + "description": "Allows the app to read, create, update, and delete document libraries and lists in all site collections on behalf of the signed-in user.", + "displayName": "Read and write items and lists in all site collections", + "id": "b3f70a70-8a4b-4f95-9573-d71c496a53f4", "origin": "Delegated (Office 365 SharePoint Online)", - "value": "SitesMetadataAdmin.ReadWrite.All" + "value": "AllSites.Manage" }, { - "description": "Allows the app to read documents and list items in all site collections on behalf of the signed-in user.", - "displayName": "Read items in all site collections", - "id": "4e0d77b0-96ba-4398-af14-3baa780278f4", - "origin": "Delegated (Office 365 SharePoint Online)", - "value": "AllSites.Read" + "description": "Allows the app to read and update user profiles and to read basic site info without a signed in user.", + "displayName": "Read and write user profiles", + "id": "741f803b-c850-494e-b5df-cde7c675a1ca", + "origin": "Application (Office 365 SharePoint Online)", + "value": "User.ReadWrite.All" }, { - "description": "Allows the app to have full control of all site collections on behalf of the signed-in user.", - "displayName": "Have full control of all site collections", - "id": "56680e0d-d2a3-4ae1-80d8-3c4f2100e3d0", - "origin": "Delegated (Office 365 SharePoint Online)", - "value": "AllSites.FullControl" + "description": "Allow the application to provision OneDrive for Business drives for users in the tenant, without a signed-in user.", + "displayName": "Provision OneDrive for Business drives without a signed-in user.", + "id": "7689db6e-2939-41b4-98b7-13c05a52bcd6", + "origin": "Application (Office 365 SharePoint Online)", + "value": "OneDrive.Provision.All" }, { "description": "Read, write and manage Cross-Tenant migration settings and tasks, without a signed-in user", @@ -8498,18 +8533,18 @@ "value": "User.Read.All" }, { - "description": "Allows the app to read and update user profiles and to read basic site info without a signed in user.", - "displayName": "Read and write user profiles", - "id": "741f803b-c850-494e-b5df-cde7c675a1ca", - "origin": "Application (Office 365 SharePoint Online)", - "value": "User.ReadWrite.All" + "description": "Allows the app to have full control of all site collections on behalf of the signed-in user.", + "displayName": "Have full control of all site collections", + "id": "56680e0d-d2a3-4ae1-80d8-3c4f2100e3d0", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "AllSites.FullControl" }, { - "description": "Allows the app to read, create, update, and delete document libraries and lists in all site collections on behalf of the signed-in user.", - "displayName": "Read and write items and lists in all site collections", - "id": "b3f70a70-8a4b-4f95-9573-d71c496a53f4", + "description": "Allows the app to read and write site collection metadata using the SharePoint admin site, on behalf of the signed-in user.", + "displayName": "Can view and edit site collection metadata from the admin site", + "id": "9aaa3660-6678-4cb8-b4b5-be92b6f4fbf0", "origin": "Delegated (Office 365 SharePoint Online)", - "value": "AllSites.Manage" + "value": "SitesMetadataAdmin.ReadWrite.All" }, { "description": "Allows the app to submit project task status updates the signed-in user.", @@ -8526,11 +8561,11 @@ "value": "TenantReports.Read.All" }, { - "description": "Allows the app to read and write tenant reports via the SharePoint admin site, on behalf of the signed-in user.", - "displayName": "Can view and edit tenant reports from the admin site", - "id": "fb471c34-3a48-412f-969b-e2b9bc071042", - "origin": "Delegated (Office 365 SharePoint Online)", - "value": "TenantReports.ReadWrite.All" + "description": "Allow the application full access to the Azure Data Lake service on behalf of the signed-in user.", + "displayName": "Have full access to the Azure Data Lake service", + "id": "c655ab60-056e-4dd8-8cd0-6b5398bf6002", + "origin": "Delegated (Power BI Service)", + "value": "Code.AccessAzureDataLake.All" }, { "description": "Allow the application full access to the Azure Key Vault service on behalf of the signed-in user.", @@ -8644,20 +8679,6 @@ "origin": "Delegated (Power BI Service)", "value": "Dashboard.Reshare.All" }, - { - "description": "Allows executing data agents on the user’s behalf.", - "displayName": "Execute data agents", - "id": "c6756612-6853-4145-a661-90c1d045b2dc", - "origin": "Delegated (Power BI Service)", - "value": "DataAgent.Execute.All" - }, - { - "description": "Allow the application full access to the Azure Data Lake service on behalf of the signed-in user.", - "displayName": "Have full access to the Azure Data Lake service", - "id": "c655ab60-056e-4dd8-8cd0-6b5398bf6002", - "origin": "Delegated (Power BI Service)", - "value": "Code.AccessAzureDataLake.All" - }, { "description": "Allow the application to access Azure Data Explorer on behalf of the signed-in user.", "displayName": "Access Azure Data Explorer", @@ -8679,6 +8700,20 @@ "origin": "Delegated (Power BI Service)", "value": "Catalog.Read.All" }, + { + "description": "The app can view and edit all Power BI Premium and Power BI Embedded capacities that the signed in user has access to.", + "displayName": "Read and write all capacities", + "id": "4eabc3d1-b762-40ff-9da5-0e18fdf11230", + "origin": "Delegated (Power BI Service)", + "value": "Capacity.ReadWrite.All" + }, + { + "description": "Allows the app to read and write tenant reports via the SharePoint admin site, on behalf of the signed-in user.", + "displayName": "Can view and edit tenant reports from the admin site", + "id": "fb471c34-3a48-412f-969b-e2b9bc071042", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "TenantReports.ReadWrite.All" + }, { "description": "Allows the app to read managed metadata and to read basic site info on behalf of the signed-in user.", "displayName": "Read managed metadata", @@ -8728,6 +8763,13 @@ "origin": "Delegated (Office365 Zoom)", "value": "Connector.Read" }, + { + "description": "Allows the app to read and write migration data via the SharePoint admin site without a signed-in user.", + "displayName": "Read and write access to migration data on the SharePoint admin site", + "id": "dfe5a59c-77fe-436b-9a47-375a284cf302", + "origin": "Application (Office 365 SharePoint Online)", + "value": "Migration.ReadWrite.All" + }, { "description": "Allow app to download the ediscovery exported data", "displayName": "eDiscovery.Export.Download", @@ -8735,13 +8777,6 @@ "origin": "Delegated (Office365 Zoom)", "value": "eDiscovery.Export.Download" }, - { - "description": "Allow the application to provision OneDrive for Business drives for users in the tenant, without a signed-in user.", - "displayName": "Provision OneDrive for Business drives without a signed-in user.", - "id": "7689db6e-2939-41b4-98b7-13c05a52bcd6", - "origin": "Application (Office 365 SharePoint Online)", - "value": "OneDrive.Provision.All" - }, { "description": "Legacy scope used by Office Client", "displayName": "user_impersonation", @@ -8780,37 +8815,23 @@ { "description": "The app can view all Power BI apps the signed in user has access to.", "displayName": "View all Power BI apps", - "id": "8b01a991-5a5a-47f8-91a2-84d6bfd72c02", - "origin": "Delegated (Power BI Service)", - "value": "App.Read.All" - }, - { - "description": "The app can view all Power BI Premium and Power BI Embedded capacities that the signed in user has access to.", - "displayName": "View all capacities", - "id": "76e2ebd5-0dfb-4a5b-93c7-ed89e0362834", - "origin": "Delegated (Power BI Service)", - "value": "Capacity.Read.All" - }, - { - "description": "The app can view and edit all Power BI Premium and Power BI Embedded capacities that the signed in user has access to.", - "displayName": "Read and write all capacities", - "id": "4eabc3d1-b762-40ff-9da5-0e18fdf11230", + "id": "8b01a991-5a5a-47f8-91a2-84d6bfd72c02", "origin": "Delegated (Power BI Service)", - "value": "Capacity.ReadWrite.All" + "value": "App.Read.All" }, { - "description": "c", - "displayName": "AggConsumptionBillingReport.Read.All", - "id": "f9d2daf6-8028-48d1-b4c1-b963f7ae7a73", - "origin": "Application (Office 365 Information Protection)", - "value": "AggConsumptionBillingReport.Read.All" + "description": "The app can view all Power BI Premium and Power BI Embedded capacities that the signed in user has access to.", + "displayName": "View all capacities", + "id": "76e2ebd5-0dfb-4a5b-93c7-ed89e0362834", + "origin": "Delegated (Power BI Service)", + "value": "Capacity.Read.All" }, { - "description": "Allows the app to read and write migration data via the SharePoint admin site without a signed-in user.", - "displayName": "Read and write access to migration data on the SharePoint admin site", - "id": "dfe5a59c-77fe-436b-9a47-375a284cf302", + "description": "Allows the app to read migration data via the SharePoint admin site without a signed-in user.", + "displayName": "Read access to migration data on the SharePoint admin site", + "id": "b7155856-e8b7-4ba1-bf43-8c9912353676", "origin": "Application (Office 365 SharePoint Online)", - "value": "Migration.ReadWrite.All" + "value": "Migration.Read.All" }, { "description": "Allows the app to search across sharepoint content. This is used for 3S unfurl route.", @@ -8819,6 +8840,20 @@ "origin": "Delegated (Office 365 Search Service)", "value": "SubstrateSearchServiceFiles.ReadAll" }, + { + "description": "Allows the app to search across the users office content. This content includes relevant people, documents, emails and skype messages.", + "displayName": "Search across the office content of the user", + "id": "2aec0168-f9e2-4ce1-bb0f-1145f35f5a64", + "origin": "Delegated (Office 365 Search Service)", + "value": "SubstrateSearch-Internal.ReadWrite" + }, + { + "description": "c", + "displayName": "MessageTraceDetail.tenant.read", + "id": "85e837d7-9e4b-4bb2-9535-08bb51aa974a", + "origin": "Application (Office 365 Information Protection)", + "value": "MessageTraceDetail.tenant.read" + }, { "description": "This allows apps to read the MtpAction", "displayName": "MtpAction.tenant.read", @@ -8933,38 +8968,45 @@ }, { "description": "c", - "displayName": "RemediationEmailResult.Read.All", - "id": "cae0e51f-af85-4f35-870d-9f024147648d", + "displayName": "MessageTrace.Read.All", + "id": "06ab0d31-7112-476e-a479-66394bec63d6", "origin": "Application (Office 365 Information Protection)", - "value": "RemediationEmailResult.Read.All" + "value": "MessageTrace.Read.All" }, { - "description": "c", - "displayName": "MessageTraceDetail.tenant.read", - "id": "85e837d7-9e4b-4bb2-9535-08bb51aa974a", + "description": "This scope allows Apps to read tenant's MessageEventSummary data", + "displayName": "messageeventsummary.tenant.read", + "id": "51aa070e-cc8b-45a9-8530-3fc96b0aa701", "origin": "Application (Office 365 Information Protection)", - "value": "MessageTraceDetail.tenant.read" + "value": "messageeventsummary.tenant.read" }, { "description": "c", - "displayName": "RemediationEmailResult.ReadWrite.All", - "id": "dac43cb8-9b13-43b1-bc17-e7eb8fe26717", + "displayName": "M365ContentExplorer.Read.All", + "id": "26872368-3756-4995-a1d0-73cfa9d8f83a", "origin": "Application (Office 365 Information Protection)", - "value": "RemediationEmailResult.ReadWrite.All" + "value": "M365ContentExplorer.Read.All" }, { "description": "c", - "displayName": "MessageTrace.Read.All", - "id": "06ab0d31-7112-476e-a479-66394bec63d6", + "displayName": "InsiderRiskData.Read.All", + "id": "57fee0bb-e97d-4e5c-a663-2b0c7ce0db37", "origin": "Application (Office 365 Information Protection)", - "value": "MessageTrace.Read.All" + "value": "InsiderRiskData.Read.All" }, { "description": "c", - "displayName": "M365ContentExplorer.Read.All", - "id": "26872368-3756-4995-a1d0-73cfa9d8f83a", + "displayName": "AggConsumptionBillingReport.Read.All", + "id": "f9d2daf6-8028-48d1-b4c1-b963f7ae7a73", "origin": "Application (Office 365 Information Protection)", - "value": "M365ContentExplorer.Read.All" + "value": "AggConsumptionBillingReport.Read.All" + }, + { + "description": "This allows the app to read AirAdminAction alerts", + "displayName": "AirAdminAction.tenant.read", + "id": "cc02f7ae-3d9b-42c9-bc91-3424d92c5547", + "origin": "Application (Office 365 Information Protection)", + "value": "AirAdminAction.tenant.read" }, { "description": "This allows apps to write the AirAdminAction alerts", @@ -9010,17 +9052,17 @@ }, { "description": "c", - "displayName": "AzureActivityData.Read.All", - "id": "926c05c5-5941-491b-973a-509c2a4a2542", + "displayName": "RemediationEmailResult.Read.All", + "id": "cae0e51f-af85-4f35-870d-9f024147648d", "origin": "Application (Office 365 Information Protection)", - "value": "AzureActivityData.Read.All" + "value": "RemediationEmailResult.Read.All" }, { "description": "c", - "displayName": "compliancestatus.tenant.read", - "id": "59c90462-e42e-4698-8a51-196ebd407166", + "displayName": "AzureActivityData.Read.All", + "id": "926c05c5-5941-491b-973a-509c2a4a2542", "origin": "Application (Office 365 Information Protection)", - "value": "compliancestatus.tenant.read" + "value": "AzureActivityData.Read.All" }, { "description": "c", @@ -9080,24 +9122,24 @@ }, { "description": "c", - "displayName": "InsiderRiskData.Read.All", - "id": "57fee0bb-e97d-4e5c-a663-2b0c7ce0db37", + "displayName": "compliancestatus.tenant.read", + "id": "59c90462-e42e-4698-8a51-196ebd407166", "origin": "Application (Office 365 Information Protection)", - "value": "InsiderRiskData.Read.All" + "value": "compliancestatus.tenant.read" }, { - "description": "This scope allows Apps to read tenant's MessageEventSummary data", - "displayName": "messageeventsummary.tenant.read", - "id": "51aa070e-cc8b-45a9-8530-3fc96b0aa701", - "origin": "Application (Office 365 Information Protection)", - "value": "messageeventsummary.tenant.read" + "description": "Allows reading data agents on the user’s behalf.", + "displayName": "Read data agents", + "id": "40fa91d5-73ef-412c-a8c8-c8658670d0eb", + "origin": "Delegated (Power BI Service)", + "value": "DataAgent.Read.All" }, { - "description": "This allows to change RoleGroupMember to the tenant", - "displayName": "RoleGroupMember.tenant.write", - "id": "abe60d99-0a67-4250-afc0-290614d84b41", + "description": "c", + "displayName": "RemediationEmailResult.ReadWrite.All", + "id": "dac43cb8-9b13-43b1-bc17-e7eb8fe26717", "origin": "Application (Office 365 Information Protection)", - "value": "RoleGroupMember.tenant.write" + "value": "RemediationEmailResult.ReadWrite.All" }, { "description": "c", @@ -9107,11 +9149,11 @@ "value": "TenantLicenseStatus.Read.All" }, { - "description": "c", - "displayName": "ThreatSubmission.ReadWrite.All", - "id": "944c8d5a-fdcd-4aac-af4d-3366942700d5", - "origin": "Application (Office 365 Information Protection)", - "value": "ThreatSubmission.ReadWrite.All" + "description": "Allows the application to read service health information for your organization.", + "displayName": "Read activity reports for your organization", + "id": "b3b78c39-cb1d-4d17-820a-25d9196a800e", + "origin": "Application (Office 365 Management APIs)", + "value": "ActivityReports.Read" }, { "description": "Allows the application to read service health information for your organization.", @@ -9155,13 +9197,6 @@ "origin": "Delegated (Office 365 Management APIs)", "value": "ActivityFeed.ReadDlp" }, - { - "description": "Allows the application to read service health information for your organization.", - "displayName": "Read activity reports for your organization", - "id": "b3b78c39-cb1d-4d17-820a-25d9196a800e", - "origin": "Delegated (Office 365 Management APIs)", - "value": "ActivityReports.Read" - }, { "description": "Allows the application to read all the AppCatalog", "displayName": "Read App Catalog", @@ -9198,11 +9233,18 @@ "value": "QnA.Read.All" }, { - "description": "Allows the app to search across the users office content. This content includes relevant people, documents, emails and skype messages.", - "displayName": "Search across the office content of the user", - "id": "2aec0168-f9e2-4ce1-bb0f-1145f35f5a64", - "origin": "Delegated (Office 365 Search Service)", - "value": "SubstrateSearch-Internal.ReadWrite" + "description": "RbacTenantStatus.Write", + "displayName": "RbacTenantStatus.Write", + "id": "4e26c42d-fab0-4daa-9ea6-d860a28aa7d0", + "origin": "Delegated (Office 365 Information Protection)", + "value": "RbacTenantStatus.Write" + }, + { + "description": "c", + "displayName": "ThreatSubmission.ReadWrite.All", + "id": "944c8d5a-fdcd-4aac-af4d-3366942700d5", + "origin": "Application (Office 365 Information Protection)", + "value": "ThreatSubmission.ReadWrite.All" }, { "description": "c", @@ -9239,6 +9281,13 @@ "origin": "Delegated (Office 365 Information Protection)", "value": "alert.write" }, + { + "description": "This allows to change RoleGroupMember to the tenant", + "displayName": "RoleGroupMember.tenant.write", + "id": "abe60d99-0a67-4250-afc0-290614d84b41", + "origin": "Application (Office 365 Information Protection)", + "value": "RoleGroupMember.tenant.write" + }, { "description": "AtpStandardPolicy.Tenant.Read", "displayName": "AtpStandardPolicy.Tenant.Read", @@ -9247,18 +9296,11 @@ "value": "AtpStandardPolicy.Tenant.Read" }, { - "description": "Allows the app to read migration data via the SharePoint admin site without a signed-in user.", - "displayName": "Read access to migration data on the SharePoint admin site", - "id": "b7155856-e8b7-4ba1-bf43-8c9912353676", - "origin": "Application (Office 365 SharePoint Online)", - "value": "Migration.Read.All" - }, - { - "description": "AtpStandardPolicy.Tenant.Write", - "displayName": "AtpStandardPolicy.Tenant.Write", - "id": "9945d5be-d9cb-45d0-b347-3f827c0d374d", + "description": "LabelAnalyticsActivityData.Read.All", + "displayName": "LabelAnalyticsActivityData.Read.All", + "id": "2da9421b-01d5-43ec-9c8e-b1bfa4a8b2bb", "origin": "Delegated (Office 365 Information Protection)", - "value": "AtpStandardPolicy.Tenant.Write" + "value": "LabelAnalyticsActivityData.Read.All" }, { "description": "This allows user to read M365ContentExplorer", @@ -9296,25 +9338,11 @@ "value": "RbacTenantStatus.Read" }, { - "description": "RbacTenantStatus.Write", - "displayName": "RbacTenantStatus.Write", - "id": "4e26c42d-fab0-4daa-9ea6-d860a28aa7d0", - "origin": "Delegated (Office 365 Information Protection)", - "value": "RbacTenantStatus.Write" - }, - { - "description": "LabelAnalyticsActivityData.Read.All", - "displayName": "LabelAnalyticsActivityData.Read.All", - "id": "2da9421b-01d5-43ec-9c8e-b1bfa4a8b2bb", + "description": "AtpStandardPolicy.Tenant.Write", + "displayName": "AtpStandardPolicy.Tenant.Write", + "id": "9945d5be-d9cb-45d0-b347-3f827c0d374d", "origin": "Delegated (Office 365 Information Protection)", - "value": "LabelAnalyticsActivityData.Read.All" - }, - { - "description": "Allows the application to list and query user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export external user data (e.g. customer content or system-generated logs), associated with the current tenant on behalf of the signed-in user.", - "displayName": "Read shared cross-tenant user profile and export data", - "id": "cb1ba48f-d22b-4325-a07f-74135a62ee41", - "origin": "Delegated (Microsoft Graph)", - "value": "CrossTenantUserProfileSharing.Read" + "value": "AtpStandardPolicy.Tenant.Write" }, { "description": "Allows the application to obtain basic tenant information about another target tenant within the Azure AD ecosystem on behalf of the signed-in user.", @@ -9330,6 +9358,34 @@ "origin": "Delegated (Microsoft Graph)", "value": "CopilotSettings-LimitedMode.ReadWrite" }, + { + "description": "Allows the app to read organization-wide copilot limited mode setting on behalf of the signed-in user.", + "displayName": "Read organization-wide copilot limited mode setting", + "id": "aeb2982d-632d-4155-b533-18756ab6fdd8", + "origin": "Delegated (Microsoft Graph)", + "value": "CopilotSettings-LimitedMode.Read" + }, + { + "description": "View discovery alerts, reports, apps, and other related information", + "displayName": "discovery.read", + "id": "e9aa7b67-ea0d-435b-ab36-592cd9b23d61", + "origin": "Application (Microsoft Cloud App Security)", + "value": "discovery.read" + }, + { + "description": "Manage alerts, activities, policies, and other investigation-related information", + "displayName": "investigation.manage", + "id": "a832eaa3-0cfc-4a2b-9af1-27c5b092dd40", + "origin": "Application (Microsoft Cloud App Security)", + "value": "investigation.manage" + }, + { + "description": "View alerts, activities and policies", + "displayName": "investigation.read", + "id": "83bc8d83-2679-44ef-b813-d5f556fc4474", + "origin": "Application (Microsoft Cloud App Security)", + "value": "investigation.read" + }, { "description": "Manage all settings", "displayName": "settings.manage", @@ -9351,27 +9407,6 @@ "origin": "Delegated (Microsoft Cloud App Security)", "value": "discovery.manage" }, - { - "description": "View discovery alerts, reports, apps, and other related information", - "displayName": "discovery.read", - "id": "e9aa7b67-ea0d-435b-ab36-592cd9b23d61", - "origin": "Delegated (Microsoft Cloud App Security)", - "value": "discovery.read" - }, - { - "description": "Manage alerts, activities, policies, and other investigation-related information", - "displayName": "investigation.manage", - "id": "a832eaa3-0cfc-4a2b-9af1-27c5b092dd40", - "origin": "Delegated (Microsoft Cloud App Security)", - "value": "investigation.manage" - }, - { - "description": "View alerts, activities and policies", - "displayName": "investigation.read", - "id": "83bc8d83-2679-44ef-b813-d5f556fc4474", - "origin": "Delegated (Microsoft Cloud App Security)", - "value": "investigation.read" - }, { "description": "Allows the application to access the Cognitive Services API acting as users in the organization.", "displayName": "Access Cognitive Services API as organization users.", @@ -9415,39 +9450,25 @@ "value": "dds.read" }, { - "description": "Allows the app to be added to your list of devices and apps.", - "displayName": "Be added to your list of devices and apps", - "id": "b2c5a8a4-d75c-4c8d-ab0e-325d6d89c9e1", - "origin": "Delegated (Microsoft Device Directory Service)", - "value": "dds.register" - }, - { - "description": "Scope to allow FirstParty APPS to make PolicySync calls", - "displayName": "EopPolicySync.AccessAsApp", - "id": "c79b0778-99a8-4d45-9063-3f160ec2776d", - "origin": "Application (Microsoft Exchange Online Protection)", - "value": "EopPolicySync.AccessAsApp" - }, - { - "description": "c", - "displayName": "Exchange.ManageAsApp", - "id": "455e5cd2-84e8-4751-8344-5672145dfa17", - "origin": "Application (Microsoft Exchange Online Protection)", - "value": "Exchange.ManageAsApp" + "description": "Allows the app to be added to your list of devices and apps.", + "displayName": "Be added to your list of devices and apps", + "id": "b2c5a8a4-d75c-4c8d-ab0e-325d6d89c9e1", + "origin": "Delegated (Microsoft Device Directory Service)", + "value": "dds.register" }, { - "description": "c", - "displayName": "ThreatSubmission.ReadWrite.All", - "id": "8f819283-077c-4c68-aa24-0ad706da26e0", - "origin": "Application (Microsoft Exchange Online Protection)", - "value": "ThreatSubmission.ReadWrite.All" + "description": "This scope allows working with Microsoft Project Arcadia Workspaces' Artifacts API.", + "displayName": "workspaceartifacts.management", + "id": "f99087ab-db8f-46be-8ff0-613ef11c6ed8", + "origin": "Delegated (Microsoft Azure Synapse Gateway)", + "value": "workspaceartifacts.management" }, { - "description": "Used to get token for agent to get network scan tasks", - "displayName": "NetworkScanAgent.Operate", - "id": "2adb0da9-d999-4186-85a4-0b66bbd9a535", - "origin": "Application (MDATPNetworkScanAgent)", - "value": "NetworkScanAgent.Operate" + "description": "Allows read and write access to cluster node level actions, between the Azure Stack HCI cluster node and the cloud", + "displayName": "Read and write access to cluster node level actions", + "id": "bbe8afc9-f3ba-4955-bb5f-1cfb6960b242", + "origin": "Application (Microsoft Azure Stack HCI Service)", + "value": "AzureStackHCI.ClusterNode.ReadWrite" }, { "description": "This allows users to install a new MDATP network scan agent", @@ -9477,6 +9498,20 @@ "origin": "Delegated (Medeina Service)", "value": "Medeina.Temp" }, + { + "description": "Allows the app to perform all Perception operations on behalf of the signed-in user.", + "displayName": "Operate all Perception data", + "id": "42d4b992-1186-4bbf-8d8b-b7d4e975b3f1", + "origin": "Delegated (Medeina Service)", + "value": "Perception.Operate.All" + }, + { + "description": "Allows the app to read all Perception data on behalf of the signed-in user.", + "displayName": "Read all Perception data", + "id": "0f74f1fb-bd3b-46ca-8375-7242a5d8bf36", + "origin": "Delegated (Medeina Service)", + "value": "Perception.Read.All" + }, { "description": "Allows users to access the Medeina APIs", "displayName": "Mediena.Access", @@ -9484,6 +9519,20 @@ "origin": "Delegated (Medeina Service Dev)", "value": "Medeina.Access" }, + { + "description": "Allows the app to perform all Perception operations on behalf of the signed-in user.", + "displayName": "Operate all Perception data", + "id": "db134baa-3828-4205-90f4-0cc110a17e16", + "origin": "Delegated (Medeina Service Dev)", + "value": "Perception.Operate.All" + }, + { + "description": "Allows the app to read all Perception data on behalf of the signed-in user.", + "displayName": "Read all Perception data", + "id": "abfe9a83-8353-4342-81dd-925768109f8a", + "origin": "Delegated (Medeina Service Dev)", + "value": "Perception.Read.All" + }, { "description": "Allow the application to access all the APIs registered with App Service", "displayName": "Access APIs registered with App Service", @@ -9540,13 +9589,6 @@ "origin": "Application (Microsoft Azure Stack HCI Service)", "value": "AzureStackHCI.ClusterNode.Read" }, - { - "description": "Allows read and write access to cluster node level actions, between the Azure Stack HCI cluster node and the cloud", - "displayName": "Read and write access to cluster node level actions", - "id": "bbe8afc9-f3ba-4955-bb5f-1cfb6960b242", - "origin": "Application (Microsoft Azure Stack HCI Service)", - "value": "AzureStackHCI.ClusterNode.ReadWrite" - }, { "description": "Stream Analytics access to Power BI", "displayName": "Stream Analytics access to Power BI", @@ -9555,32 +9597,46 @@ "value": "user_impersonation" }, { - "description": "This scope allows working with Microsoft Project Arcadia Workspaces' Artifacts API.", - "displayName": "workspaceartifacts.management", - "id": "f99087ab-db8f-46be-8ff0-613ef11c6ed8", - "origin": "Delegated (Microsoft Azure Synapse Gateway)", - "value": "workspaceartifacts.management" + "description": "Scope to allow FirstParty APPS to make PolicySync calls", + "displayName": "EopPolicySync.AccessAsApp", + "id": "c79b0778-99a8-4d45-9063-3f160ec2776d", + "origin": "Application (Microsoft Exchange Online Protection)", + "value": "EopPolicySync.AccessAsApp" }, { - "description": "Allows the app to read access reviews, reviewers, decisions and settings in the organization, without a signed-in user.", - "displayName": "Read all access reviews", - "id": "d07a8cc0-3d51-4b77-b3b0-32704d1f69fa", + "description": "c", + "displayName": "Exchange.ManageAsApp", + "id": "455e5cd2-84e8-4751-8344-5672145dfa17", + "origin": "Application (Microsoft Exchange Online Protection)", + "value": "Exchange.ManageAsApp" + }, + { + "description": "c", + "displayName": "ThreatSubmission.ReadWrite.All", + "id": "8f819283-077c-4c68-aa24-0ad706da26e0", + "origin": "Application (Microsoft Exchange Online Protection)", + "value": "ThreatSubmission.ReadWrite.All" + }, + { + "description": "Allows the client to read, update, create, and delete agent identities without a signed-in user.", + "displayName": "Read and write all agent identities", + "id": "dcf7150a-88d4-4fe6-9be1-c2744c455397", "origin": "Application (Microsoft Graph)", - "value": "AccessReview.Read.All" + "value": "AgentIdentity.ReadWrite.All" }, { - "description": "Allows the app to read, update, delete and perform actions on access reviews, reviewers, decisions and settings in the organization, without a signed-in user.", - "displayName": "Manage all access reviews", - "id": "ef5f7d5c-338f-44b0-86c3-351f46c8bb5f", + "description": "Allows updating agent identity blueprint credentials without a signed-in user.", + "displayName": "Update agent identity blueprint credentials", + "id": "0510736e-bdfb-4b37-9a1f-89b4a074763a", "origin": "Application (Microsoft Graph)", - "value": "AccessReview.ReadWrite.All" + "value": "AgentIdentityBlueprint.AddRemoveCreds.All" }, { - "description": "Allows the app to read, update, delete and perform actions on access reviews, reviewers, decisions and settings in the organization for group and app memberships, without a signed-in user.", - "displayName": "Manage access reviews for group and app memberships", - "id": "18228521-a591-40f1-b215-5fad4488c117", + "description": "Allows creating new agent identity blueprints without a signed-in user.", + "displayName": "Create agent identity blueprints.", + "id": "ea4b2453-ad2d-4d94-9155-10d5d9493ce9", "origin": "Application (Microsoft Graph)", - "value": "AccessReview.ReadWrite.Membership" + "value": "AgentIdentityBlueprint.Create" }, { "description": "Allows deleting or restoring agent identity blueprints without a signed-in user.", @@ -9681,53 +9737,53 @@ "value": "AgentInstance.ReadWrite.All" }, { - "description": "Allows the app to create, read, update, and delete agent instances that designate the calling app as their manager in your organization's Agent Registry without a signed-in user.", - "displayName": "Read and write managed-by agent instances in Agent Registry", - "id": "782ab1bf-24f1-4c27-8bbc-2006d42792a6", + "description": "Allows the app to read all agent identities without a signed-in user.", + "displayName": "Read all agent identities", + "id": "b2b8f011-2898-4234-9092-5059f6c1ebfa", "origin": "Application (Microsoft Graph)", - "value": "AgentInstance.ReadWrite.ManagedBy" + "value": "AgentIdentity.Read.All" }, { - "description": "Allows the app to read agent registration information without a signed-in user.", - "displayName": "Read all agent registrations", - "id": "d3acceb6-4673-47c0-aeac-582f2c7cf72c", + "description": "Allows the client to enable or disable agent identities without a signed-in user.", + "displayName": "Enable or disable agent identities", + "id": "69ee0943-4fa4-4ec8-8e52-d12e4ea661a3", "origin": "Application (Microsoft Graph)", - "value": "AgentRegistration.Read.All" + "value": "AgentIdentity.EnableDisable.All" }, { - "description": "Allows the app to read and write agent registration information without a signed-in user.", - "displayName": "Read and write all agent registrations", - "id": "39fb8c64-7bd3-4107-8515-14d6e55ddda4", + "description": "Allows the client to delete and restore agent identities without a signed-in user.", + "displayName": "Delete and restore agent identities", + "id": "5b016f9b-18eb-41d4-869a-66931914d1c8", "origin": "Application (Microsoft Graph)", - "value": "AgentRegistration.ReadWrite.All" + "value": "AgentIdentity.DeleteRestore.All" }, { - "description": "Allows creating new agent identity blueprints without a signed-in user.", - "displayName": "Create agent identity blueprints.", - "id": "ea4b2453-ad2d-4d94-9155-10d5d9493ce9", + "description": "Allows the app to create agent identities as the parent agent identity blueprint and fully manage them, including reading, updating, and deleting, without a signed-in user.", + "displayName": "Create and manage agent identities as the parent agent identity blueprint", + "id": "4c390976-b2b7-42e0-9187-c6be3bead001", "origin": "Application (Microsoft Graph)", - "value": "AgentIdentityBlueprint.Create" + "value": "AgentIdentity.CreateAsManager" }, { - "description": "Allows updating agent identity blueprint credentials without a signed-in user.", - "displayName": "Update agent identity blueprint credentials", - "id": "0510736e-bdfb-4b37-9a1f-89b4a074763a", + "description": "Allows the app to read access reviews, reviewers, decisions and settings in the organization, without a signed-in user.", + "displayName": "Read all access reviews", + "id": "d07a8cc0-3d51-4b77-b3b0-32704d1f69fa", "origin": "Application (Microsoft Graph)", - "value": "AgentIdentityBlueprint.AddRemoveCreds.All" + "value": "AccessReview.Read.All" }, { - "description": "Allows the client to read, update, create, and delete agent identities without a signed-in user.", - "displayName": "Read and write all agent identities", - "id": "dcf7150a-88d4-4fe6-9be1-c2744c455397", + "description": "Allows the app to read, update, delete and perform actions on access reviews, reviewers, decisions and settings in the organization, without a signed-in user.", + "displayName": "Manage all access reviews", + "id": "ef5f7d5c-338f-44b0-86c3-351f46c8bb5f", "origin": "Application (Microsoft Graph)", - "value": "AgentIdentity.ReadWrite.All" + "value": "AccessReview.ReadWrite.All" }, { - "description": "Allows the app to read all agent identities without a signed-in user.", - "displayName": "Read all agent identities", - "id": "b2b8f011-2898-4234-9092-5059f6c1ebfa", + "description": "Allows the app to read, update, delete and perform actions on access reviews, reviewers, decisions and settings in the organization for group and app memberships, without a signed-in user.", + "displayName": "Manage access reviews for group and app memberships", + "id": "18228521-a591-40f1-b215-5fad4488c117", "origin": "Application (Microsoft Graph)", - "value": "AgentIdentity.Read.All" + "value": "AccessReview.ReadWrite.Membership" }, { "description": "Allows an app to read all acronyms without a signed-in user.", @@ -9764,6 +9820,13 @@ "origin": "Application (Microsoft Graph)", "value": "AgentCard.ReadWrite.All" }, + { + "description": "Used to get token for agent to get network scan tasks", + "displayName": "NetworkScanAgent.Operate", + "id": "2adb0da9-d999-4186-85a4-0b66bbd9a535", + "origin": "Application (MDATPNetworkScanAgent)", + "value": "NetworkScanAgent.Operate" + }, { "description": "Allows the app to read and update agent cards that designate the calling app as their manager and manage their skills in your organization's Agent Registry without a signed-in user.", "displayName": "Read and write managed-by agent cards in Agent Registry", @@ -9771,13 +9834,6 @@ "origin": "Application (Microsoft Graph)", "value": "AgentCard.ReadWrite.ManagedBy" }, - { - "description": "Allows the app to read all agent card manifests in your organization's Agent Registry without a signed-in user.", - "displayName": "Read all agent card manifests in Agent Registry", - "id": "3ee18438-e6e5-4858-8f1c-d7b723b45213", - "origin": "Application (Microsoft Graph)", - "value": "AgentCardManifest.Read.All" - }, { "description": "Allows the app to read and write to all agent card manifests in your organization's Agent Registry without a signed-in user.", "displayName": "Read and write all agent card manifests in Agent Registry", @@ -9785,13 +9841,6 @@ "origin": "Application (Microsoft Graph)", "value": "AgentCardManifest.ReadWrite.All" }, - { - "description": "Allows an application to read or write Customer Key Encryption Tenant Data", - "displayName": "Read or Write Customer Key Encryption Tenant Data", - "id": "e85fa438-368f-4c1d-909a-5760a4e045ae", - "origin": "Delegated (M365DataAtRestEncryption)", - "value": "CustomerKeyTenant-Internal.ReadWrite.All" - }, { "description": "Allows the app to read and write agent card manifests that name it as manager in your organization's Agent Registry without a signed-in user.", "displayName": "Read and write managed-by agent card manifests in Agent Registry", @@ -9799,6 +9848,13 @@ "origin": "Application (Microsoft Graph)", "value": "AgentCardManifest.ReadWrite.ManagedBy" }, + { + "description": "Allows the app to read all collections and their membership in your organization's Agent Registry without a signed-in user.", + "displayName": "Read all collections in Agent Registry, except quarantined and global", + "id": "e65ee1da-d1d5-467b-bdd0-3e9bb94e6e0c", + "origin": "Application (Microsoft Graph)", + "value": "AgentCollection.Read.All" + }, { "description": "Allows the app to create, read, update, and delete all collections and manage their membership in your organization's Agent Registry without a signed-in user.", "displayName": "Read and write all collections in Agent Registry, except quarantined and global", @@ -9835,60 +9891,25 @@ "value": "AgentIdentity.Create.All" }, { - "description": "Allows the app to create agent identities as the parent agent identity blueprint and fully manage them, including reading, updating, and deleting, without a signed-in user.", - "displayName": "Create and manage agent identities as the parent agent identity blueprint", - "id": "4c390976-b2b7-42e0-9187-c6be3bead001", - "origin": "Application (Microsoft Graph)", - "value": "AgentIdentity.CreateAsManager" - }, - { - "description": "Allows the client to delete and restore agent identities without a signed-in user.", - "displayName": "Delete and restore agent identities", - "id": "5b016f9b-18eb-41d4-869a-66931914d1c8", - "origin": "Application (Microsoft Graph)", - "value": "AgentIdentity.DeleteRestore.All" - }, - { - "description": "Allows the client to enable or disable agent identities without a signed-in user.", - "displayName": "Enable or disable agent identities", - "id": "69ee0943-4fa4-4ec8-8e52-d12e4ea661a3", - "origin": "Application (Microsoft Graph)", - "value": "AgentIdentity.EnableDisable.All" - }, - { - "description": "Allows the app to read all collections and their membership in your organization's Agent Registry without a signed-in user.", - "displayName": "Read all collections in Agent Registry, except quarantined and global", - "id": "e65ee1da-d1d5-467b-bdd0-3e9bb94e6e0c", + "description": "Allows the app to read all agent card manifests in your organization's Agent Registry without a signed-in user.", + "displayName": "Read all agent card manifests in Agent Registry", + "id": "3ee18438-e6e5-4858-8f1c-d7b723b45213", "origin": "Application (Microsoft Graph)", - "value": "AgentCollection.Read.All" + "value": "AgentCardManifest.Read.All" }, { - "description": "Allows the app to read terms of use agreements, without a signed in user.", - "displayName": "Read all terms of use agreements", - "id": "2f3e6f8c-093b-4c57-a58b-ba5ce494a169", + "description": "Allows the app to create, read, update, and delete agent instances that designate the calling app as their manager in your organization's Agent Registry without a signed-in user.", + "displayName": "Read and write managed-by agent instances in Agent Registry", + "id": "782ab1bf-24f1-4c27-8bbc-2006d42792a6", "origin": "Application (Microsoft Graph)", - "value": "Agreement.Read.All" - }, - { - "description": "Allows an application to read or write Microsoft Managed Key Data", - "displayName": "Read or Write Microsoft Managed Key Data", - "id": "ac23b270-1dc3-4ee4-bd56-d7eb945c2332", - "origin": "Application (M365DataAtRestEncryption)", - "value": "MicrosoftManagedKey-Internal.ReadWrite.All" - }, - { - "description": "Allows an application to delete Customer Key Encryption Tenant data", - "displayName": "Delete Customer Key Encryption Tenant Data", - "id": "ef16fcfc-1309-42bc-9c0c-7eb48a9d5f02", - "origin": "Application (M365DataAtRestEncryption)", - "value": "CustomerKeyTenant-Internal.Delete.All" + "value": "AgentInstance.ReadWrite.ManagedBy" }, { - "description": "Allows the uesr to Read and Write Asset Resource, on behalf of the signed-in user.", - "displayName": "Read and Write Asset Resource", - "id": "3e2a4aea-4efd-4851-9af9-de64ccbb354f", - "origin": "Delegated (EASM API)", - "value": "AssetResource.ReadWrite.All" + "description": "Allows an application to read or write Customer Key Encryption Tenant Data", + "displayName": "Read or Write Customer Key Encryption Tenant Data", + "id": "e85fa438-368f-4c1d-909a-5760a4e045ae", + "origin": "Delegated (M365DataAtRestEncryption)", + "value": "CustomerKeyTenant-Internal.ReadWrite.All" }, { "description": "Allows the user to read DiscoveryGroup, on behalf of the signed-in user.", @@ -10002,6 +10023,27 @@ "origin": "Application (Fidalgo Dataplane Public)", "value": "actonbehalfof.create.all" }, + { + "description": "Allows users to access Fidalgo resources.", + "displayName": "access_as_user", + "id": "983c9dc3-3bcf-4538-9937-bab8b1a31d86", + "origin": "Delegated (Fidalgo Dataplane Public)", + "value": "access_as_user" + }, + { + "description": "Allows the uesr to Read and Write Asset Resource, on behalf of the signed-in user.", + "displayName": "Read and Write Asset Resource", + "id": "3e2a4aea-4efd-4851-9af9-de64ccbb354f", + "origin": "Delegated (EASM API)", + "value": "AssetResource.ReadWrite.All" + }, + { + "description": "Allow the application to access Fiji Storage on behalf of the signed-in user.", + "displayName": "Access Fiji Storage", + "id": "4e5661b3-5a0d-47fc-b7a6-e5b659cfea8b", + "origin": "Delegated (Fiji Storage)", + "value": "user_impersonation" + }, { "description": "Allows the user to read Asset Resource, including asset resource, asset audit trails, asset summary and asset snapshot, on behalf of the signed-in user.", "displayName": "Read Asset Resource information", @@ -10009,33 +10051,12 @@ "origin": "Delegated (EASM API)", "value": "AssetResource.Read.All" }, - { - "description": "Allows users to access Fidalgo resources.", - "displayName": "access_as_user", - "id": "983c9dc3-3bcf-4538-9937-bab8b1a31d86", - "origin": "Delegated (Fidalgo Dataplane Public)", - "value": "access_as_user" - }, { "description": "Dynamics 365 is a business management solution that’s connecting people and processes like never before. From day one, it makes ordering, selling, invoicing, and reporting easier and faster.", - "displayName": "Access as the signed-in user", - "id": "bce0976a-cb0b-473b-8800-84eda9f8e447", + "displayName": "Access Dynamics 365 Business Central as the signed-in user", + "id": "2fb13c28-9d89-417f-9af2-ec3065bc16e6", "origin": "Delegated (Dynamics 365 Business Central)", - "value": "user_impersonation" - }, - { - "description": "Grants full access to the Business Central automation APIs. These APIs provide the capability to automate company setup.", - "displayName": "Full access to automation", - "id": "d365bc00-a990-0000-00bc-160000000001", - "origin": "Application (Dynamics 365 Business Central)", - "value": "Automation.ReadWrite.All" - }, - { - "description": "Allows calling debugging APIs", - "displayName": "UserScope-PPE.Debug.All", - "id": "f6c5fb21-2e2e-42f4-a961-ffb661669441", - "origin": "Application (DirectoryLookupService)", - "value": "UserScope-PPE.Debug.All" + "value": "Financials.ReadWrite.All" }, { "description": "This allows app to run ppe tenant userscope in DLS", @@ -10150,17 +10171,17 @@ "value": "app_access" }, { - "description": "Dynamics 365 is a business management solution that’s connecting people and processes like never before. From day one, it makes ordering, selling, invoicing, and reporting easier and faster.", - "displayName": "Access Dynamics 365 Business Central as the signed-in user", - "id": "2fb13c28-9d89-417f-9af2-ec3065bc16e6", - "origin": "Delegated (Dynamics 365 Business Central)", - "value": "Financials.ReadWrite.All" + "description": "Grants full access to the Business Central automation APIs. These APIs provide the capability to automate company setup.", + "displayName": "Full access to automation", + "id": "d365bc00-a990-0000-00bc-160000000001", + "origin": "Application (Dynamics 365 Business Central)", + "value": "Automation.ReadWrite.All" }, { - "description": "Allow the application to access Fiji Storage on behalf of the signed-in user.", - "displayName": "Access Fiji Storage", - "id": "4e5661b3-5a0d-47fc-b7a6-e5b659cfea8b", - "origin": "Delegated (Fiji Storage)", + "description": "Dynamics 365 is a business management solution that’s connecting people and processes like never before. From day one, it makes ordering, selling, invoicing, and reporting easier and faster.", + "displayName": "Access as the signed-in user", + "id": "bce0976a-cb0b-473b-8800-84eda9f8e447", + "origin": "Delegated (Dynamics 365 Business Central)", "value": "user_impersonation" }, { @@ -10178,11 +10199,11 @@ "value": "ExternalConnection.Read.All" }, { - "description": "Allow Healthcare Agent Service APIs to process the data sent to it.", - "displayName": "Healthcare Agent Service APIs Process", - "id": "28e41776-5350-4c1e-9ee4-689de5cb6d85", - "origin": "Delegated (Health Safeguards REST API)", - "value": "HealthcareAgentServiceApis.Process" + "description": "Allows the app to read external connections without a signed-in user. The app can only read external connections that it is authorized to. ", + "displayName": "ExternalConnection.Read.OwnedBy", + "id": "6ed7b42a-d211-4a23-9d86-4ad9bb3cd8c9", + "origin": "Application (Graph Connector Service)", + "value": "ExternalConnection.Read.OwnedBy" }, { "description": "Invoke Diagnostics", @@ -10296,6 +10317,20 @@ "origin": "Application (M365DataAtRestEncryption)", "value": "CustomerKeyTenant.Read.All" }, + { + "description": "Allows an application to delete Customer Key Encryption Tenant data", + "displayName": "Delete Customer Key Encryption Tenant Data", + "id": "ef16fcfc-1309-42bc-9c0c-7eb48a9d5f02", + "origin": "Application (M365DataAtRestEncryption)", + "value": "CustomerKeyTenant-Internal.Delete.All" + }, + { + "description": "Allow Healthcare Agent Service APIs to process the data sent to it.", + "displayName": "Healthcare Agent Service APIs Process", + "id": "28e41776-5350-4c1e-9ee4-689de5cb6d85", + "origin": "Delegated (Health Safeguards REST API)", + "value": "HealthcareAgentServiceApis.Process" + }, { "description": "Access the Azure Health Bot", "displayName": "AzureHealthBot.PortalAccess", @@ -10317,20 +10352,6 @@ "origin": "Delegated (Graph Connector Service)", "value": "ExternalItem.ReadWrite.OwnedBy" }, - { - "description": "Allows the app to read and write all external items on behalf of a signed-in user. The signed-in user must be an administrator.", - "displayName": "ExternalItem.ReadWrite.All", - "id": "565c16dd-b86f-4528-9d73-af8687391f02", - "origin": "Delegated (Graph Connector Service)", - "value": "ExternalItem.ReadWrite.All" - }, - { - "description": "Allows the app to read external connections without a signed-in user. The app can only read external connections that it is authorized to. ", - "displayName": "ExternalConnection.Read.OwnedBy", - "id": "6ed7b42a-d211-4a23-9d86-4ad9bb3cd8c9", - "origin": "Application (Graph Connector Service)", - "value": "ExternalConnection.Read.OwnedBy" - }, { "description": "Allows the app to read and write all external connections without a signed-in user.", "displayName": "ExternalConnection.ReadWrite.All", @@ -10388,11 +10409,18 @@ "value": "ExternalItem.ReadWrite.OwnedBy" }, { - "description": "Allows the app to read all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", - "displayName": "ExternalConnection.Read.All", - "id": "feac6de7-1991-4608-8905-0bed2fd3f86f", - "origin": "Delegated (Graph Connector Service)", - "value": "ExternalConnection.Read.All" + "description": "Allows an application to read or write Microsoft Managed Key Data", + "displayName": "Read or Write Microsoft Managed Key Data", + "id": "ac23b270-1dc3-4ee4-bd56-d7eb945c2332", + "origin": "Application (M365DataAtRestEncryption)", + "value": "MicrosoftManagedKey-Internal.ReadWrite.All" + }, + { + "description": "Allows the app to read all webhook connection details without a signed-in user.", + "displayName": "WebhookData.Read.All", + "id": "875b7cce-8b8e-4f69-8744-0d0d285c25f3", + "origin": "Application (Graph Connector Service)", + "value": "WebhookData.Read.All" }, { "description": "Allows the app to read external connections on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read external connections that it is authorized to. ", @@ -10437,32 +10465,46 @@ "value": "ExternalItem.Read.OwnedBy" }, { - "description": "Allows the app to read all webhook connection details without a signed-in user.", - "displayName": "WebhookData.Read.All", - "id": "875b7cce-8b8e-4f69-8744-0d0d285c25f3", - "origin": "Application (Graph Connector Service)", - "value": "WebhookData.Read.All" + "description": "Allows the app to read and write all external items on behalf of a signed-in user. The signed-in user must be an administrator.", + "displayName": "ExternalItem.ReadWrite.All", + "id": "565c16dd-b86f-4528-9d73-af8687391f02", + "origin": "Delegated (Graph Connector Service)", + "value": "ExternalItem.ReadWrite.All" }, { - "description": "This allows app to run test tenant userscope in DLS", - "displayName": "UserScope-Dev.ReadWrite.All", - "id": "dc532015-4941-4351-b852-8781cf87c6e5", - "origin": "Application (DirectoryLookupService)", - "value": "UserScope-Dev.ReadWrite.All" + "description": "Allows the app to read all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", + "displayName": "ExternalConnection.Read.All", + "id": "feac6de7-1991-4608-8905-0bed2fd3f86f", + "origin": "Delegated (Graph Connector Service)", + "value": "ExternalConnection.Read.All" }, { - "description": "Allows the app to read and write terms of use agreements, without a signed in user.", - "displayName": "Read and write all terms of use agreements", - "id": "c9090d00-6101-42f0-a729-c41074260d47", + "description": "Allows the app to read agent registration information without a signed-in user.", + "displayName": "Read all agent registrations", + "id": "d3acceb6-4673-47c0-aeac-582f2c7cf72c", "origin": "Application (Microsoft Graph)", - "value": "Agreement.ReadWrite.All" + "value": "AgentRegistration.Read.All" }, { - "description": "Allows the app to read all AI enterprise interactions.", - "displayName": "Read all AI enterprise interactions.", - "id": "839c90ab-5771-41ee-aef8-a562e8487c1e", + "description": "Allows the app to read and write agent registration information without a signed-in user.", + "displayName": "Read and write all agent registrations", + "id": "39fb8c64-7bd3-4107-8515-14d6e55ddda4", "origin": "Application (Microsoft Graph)", - "value": "AiEnterpriseInteraction.Read.All" + "value": "AgentRegistration.ReadWrite.All" + }, + { + "description": "Allows the app to read terms of use agreements, without a signed in user.", + "displayName": "Read all terms of use agreements", + "id": "2f3e6f8c-093b-4c57-a58b-ba5ce494a169", + "origin": "Application (Microsoft Graph)", + "value": "Agreement.Read.All" + }, + { + "description": "Allows the app to update the on-premises sync behavior of all contacts in all mailboxes without a signed-in user.", + "displayName": "Read and update the on-premises sync behavior of contacts", + "id": "c8948c23-e66b-42db-83fd-770b71ab78d2", + "origin": "Application (Microsoft Graph)", + "value": "Contacts-OnPremisesSyncBehavior.ReadWrite.All" }, { "description": "Allows the app to process and evaluate content for data security, governance and compliance outcomes at tenant scope.", @@ -10577,32 +10619,32 @@ "value": "CustomDetection.Read.All" }, { - "description": "Allows the app to read and write custom detection rules without a signed-in user.", - "displayName": "Read and write all custom detection rules", - "id": "e0fd9c8d-a12e-4cc9-9827-20c8c3cd6fb8", + "description": "Allows the app to read app consent requests and approvals, and deny or approve those requests without a signed-in user.", + "displayName": "Read and write all consent requests", + "id": "9f1b81a7-0223-4428-bfa4-0bcb5535f27d", "origin": "Application (Microsoft Graph)", - "value": "CustomDetection.ReadWrite.All" + "value": "ConsentRequest.ReadWrite.All" }, { - "description": "Allows the app to update the on-premises sync behavior of all contacts in all mailboxes without a signed-in user.", - "displayName": "Read and update the on-premises sync behavior of contacts", - "id": "c8948c23-e66b-42db-83fd-770b71ab78d2", + "description": "Allows the app to read and write all Configuration Monitoring entities, without a signed-in user.", + "displayName": "Read and write all Configuration Monitoring entities", + "id": "cfa85bfb-2ee8-4e13-8e7f-489e57a015a1", "origin": "Application (Microsoft Graph)", - "value": "Contacts-OnPremisesSyncBehavior.ReadWrite.All" + "value": "ConfigurationMonitoring.ReadWrite.All" }, { - "description": "Allows the app to read custom security attribute assignments for all principals in the tenant without a signed in user.", - "displayName": "Read custom security attribute assignments", - "id": "3b37c5a4-1226-493d-bec3-5d6c6b866f3f", + "description": "Allows the app to read all one-to-one or group chat messages in Microsoft Teams for chats where the associated Teams application is installed, without a signed-in user.", + "displayName": "Read all chat messages for chats where the associated Teams application is installed.", + "id": "1c1b4c8e-3cc7-4c58-8470-9b92c9d5848b", "origin": "Application (Microsoft Graph)", - "value": "CustomSecAttributeAssignment.Read.All" + "value": "Chat.Read.WhereInstalled" }, { - "description": "Allows the app to read app consent requests and approvals, and deny or approve those requests without a signed-in user.", - "displayName": "Read and write all consent requests", - "id": "9f1b81a7-0223-4428-bfa4-0bcb5535f27d", + "description": "Read names and members of all one-to-one and group chats in Microsoft Teams, without a signed-in user.", + "displayName": "Read names and members of all chat threads", + "id": "b2e060da-3baf-4687-9611-f4ebc0f0cbde", "origin": "Application (Microsoft Graph)", - "value": "ConsentRequest.ReadWrite.All" + "value": "Chat.ReadBasic.All" }, { "description": "Allows the app to read names and members of all one-to-one and group chats in Microsoft Teams where the associated Teams application is installed, without a signed-in user.", @@ -10709,13 +10751,6 @@ "origin": "Application (Microsoft Graph)", "value": "ConfigurationMonitoring.Read.All" }, - { - "description": "Allows the app to read and write all Configuration Monitoring entities, without a signed-in user.", - "displayName": "Read and write all Configuration Monitoring entities", - "id": "cfa85bfb-2ee8-4e13-8e7f-489e57a015a1", - "origin": "Application (Microsoft Graph)", - "value": "ConfigurationMonitoring.ReadWrite.All" - }, { "description": "Allows the app to read consent requests and approvals without a signed-in user.", "displayName": "Read all consent requests", @@ -10723,6 +10758,20 @@ "origin": "Application (Microsoft Graph)", "value": "ConsentRequest.Read.All" }, + { + "description": "Allows the app to read and write custom detection rules without a signed-in user.", + "displayName": "Read and write all custom detection rules", + "id": "e0fd9c8d-a12e-4cc9-9827-20c8c3cd6fb8", + "origin": "Application (Microsoft Graph)", + "value": "CustomDetection.ReadWrite.All" + }, + { + "description": "Allows the app to read custom security attribute assignments for all principals in the tenant without a signed in user.", + "displayName": "Read custom security attribute assignments", + "id": "3b37c5a4-1226-493d-bec3-5d6c6b866f3f", + "origin": "Application (Microsoft Graph)", + "value": "CustomSecAttributeAssignment.Read.All" + }, { "description": "Allows the app to read and write custom security attribute assignments for all principals in the tenant without a signed in user.", "displayName": "Read and write custom security attribute assignments", @@ -10731,18 +10780,18 @@ "value": "CustomSecAttributeAssignment.ReadWrite.All" }, { - "description": "Allows the app to read all audit logs for events that contain information about custom security attributes, without a signed-in user.", - "displayName": "Read all custom security attribute audit logs", - "id": "2a4f026d-e829-4e84-bdbf-d981a2703059", + "description": "Allows the app to read and write properties of Microsoft Intune-managed deployment plans and their ring configurations, without a signed-in user.", + "displayName": "Read and write Microsoft Intune Deployment Plans", + "id": "68356fd1-028d-4ce3-b724-241dec11127a", "origin": "Application (Microsoft Graph)", - "value": "CustomSecAttributeAuditLogs.Read.All" + "value": "DeviceManagementDeploymentPlans.ReadWrite.All" }, { - "description": "Allows the app to read custom security attribute definitions for the tenant without a signed in user.", - "displayName": "Read custom security attribute definitions", - "id": "b185aa14-d8d2-42c1-a685-0f5596613624", + "description": "Allows the app to perform remote high impact actions such as wiping the device or resetting the passcode on devices managed by Microsoft Intune, without a signed-in user.", + "displayName": "Perform user-impacting remote actions on Microsoft Intune devices", + "id": "5b07b0dd-2377-4e44-a38d-703f09a0dc3c", "origin": "Application (Microsoft Graph)", - "value": "CustomSecAttributeDefinition.Read.All" + "value": "DeviceManagementManagedDevices.PrivilegedOperations.All" }, { "description": "Allows the app to read the properties of devices managed by Microsoft Intune, without a signed-in user.", @@ -10850,46 +10899,46 @@ "value": "DirectoryRecommendations.ReadWrite.All" }, { - "description": "Allows the app to read all domain properties without a signed-in user.", - "displayName": "Read domains", - "id": "dbb9058a-0e50-45d7-ae91-66909b5d4664", + "description": "Allows the app to read properties of Microsoft Intune-managed deployment plans and their ring configurations, without a signed-in user.", + "displayName": "Read Microsoft Intune Deployment Plans", + "id": "c5825671-0390-4bf2-b99b-80496fd4b673", "origin": "Application (Microsoft Graph)", - "value": "Domain.Read.All" + "value": "DeviceManagementDeploymentPlans.Read.All" }, { - "description": "Allows the app to read and write all domain properties without a signed in user. Also allows the app to add, verify and remove domains.", - "displayName": "Read and write domains", - "id": "7e05723c-0bb0-42da-be95-ae9f08a6e53c", + "description": "Allows the app to read and write properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups, without a signed-in user.", + "displayName": "Read and write Microsoft Intune device configuration and policies", + "id": "9241abd9-d0e6-425a-bd4f-47ba86e767a4", "origin": "Application (Microsoft Graph)", - "value": "Domain.ReadWrite.All" + "value": "DeviceManagementConfiguration.ReadWrite.All" }, { - "description": "Allows the app to perform remote high impact actions such as wiping the device or resetting the passcode on devices managed by Microsoft Intune, without a signed-in user.", - "displayName": "Perform user-impacting remote actions on Microsoft Intune devices", - "id": "5b07b0dd-2377-4e44-a38d-703f09a0dc3c", + "description": "Allows the app to read properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups, without a signed-in user.", + "displayName": "Read Microsoft Intune device configuration and policies", + "id": "dc377aa6-52d8-4e23-b271-2a7ae04cedf3", "origin": "Application (Microsoft Graph)", - "value": "DeviceManagementManagedDevices.PrivilegedOperations.All" + "value": "DeviceManagementConfiguration.Read.All" }, { - "description": "Allows the app to read and write properties of Microsoft Intune-managed deployment plans and their ring configurations, without a signed-in user.", - "displayName": "Read and write Microsoft Intune Deployment Plans", - "id": "68356fd1-028d-4ce3-b724-241dec11127a", + "description": "Allows the app to read and write certification authority information without a signed-in user.", + "displayName": "Read and write Microsoft Cloud PKI objects", + "id": "f15eb2ba-ef8a-4f70-991d-da5d045154e2", "origin": "Application (Microsoft Graph)", - "value": "DeviceManagementDeploymentPlans.ReadWrite.All" + "value": "DeviceManagementCloudCA.ReadWrite.All" }, { - "description": "Allows the app to read properties of Microsoft Intune-managed deployment plans and their ring configurations, without a signed-in user.", - "displayName": "Read Microsoft Intune Deployment Plans", - "id": "c5825671-0390-4bf2-b99b-80496fd4b673", + "description": "Allows the app to read all audit logs for events that contain information about custom security attributes, without a signed-in user.", + "displayName": "Read all custom security attribute audit logs", + "id": "2a4f026d-e829-4e84-bdbf-d981a2703059", "origin": "Application (Microsoft Graph)", - "value": "DeviceManagementDeploymentPlans.Read.All" + "value": "CustomSecAttributeAuditLogs.Read.All" }, { - "description": "Allows the app to read and write properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups, without a signed-in user.", - "displayName": "Read and write Microsoft Intune device configuration and policies", - "id": "9241abd9-d0e6-425a-bd4f-47ba86e767a4", + "description": "Allows the app to read custom security attribute definitions for the tenant without a signed in user.", + "displayName": "Read custom security attribute definitions", + "id": "b185aa14-d8d2-42c1-a685-0f5596613624", "origin": "Application (Microsoft Graph)", - "value": "DeviceManagementConfiguration.ReadWrite.All" + "value": "CustomSecAttributeDefinition.Read.All" }, { "description": "Allows the app to read and write custom security attribute definitions for the tenant without a signed in user.", @@ -10933,6 +10982,13 @@ "origin": "Application (Microsoft Graph)", "value": "DelegatedAdminRelationship.Read.All" }, + { + "description": "Allows the app to read all 1-to-1 or group chat messages in Microsoft Teams.", + "displayName": "Read all chat messages", + "id": "6b7d71aa-70aa-4810-a8d9-5d9fb2830017", + "origin": "Application (Microsoft Graph)", + "value": "Chat.Read.All" + }, { "description": "Allows the app to manage (create-update-terminate) Delegated Admin relationships with customers and role assignments to security groups for active Delegated Admin relationships without a signed-in user.", "displayName": "Manage Delegated Admin relationships with customers", @@ -10940,20 +10996,6 @@ "origin": "Application (Microsoft Graph)", "value": "DelegatedAdminRelationship.ReadWrite.All" }, - { - "description": "Allows the app to read all delegated permission grants, without a signed-in user.", - "displayName": "Read all delegated permission grants", - "id": "81b4724a-58aa-41c1-8a55-84ef97466587", - "origin": "Application (Microsoft Graph)", - "value": "DelegatedPermissionGrant.Read.All" - }, - { - "description": "Read names and members of all one-to-one and group chats in Microsoft Teams, without a signed-in user.", - "displayName": "Read names and members of all chat threads", - "id": "b2e060da-3baf-4687-9611-f4ebc0f0cbde", - "origin": "Application (Microsoft Graph)", - "value": "Chat.ReadBasic.All" - }, { "description": "Allows the app to manage permission grants for delegated permissions exposed by any API (including Microsoft Graph), without a signed-in user.", "displayName": "Manage all delegated permission grants", @@ -10961,6 +11003,13 @@ "origin": "Application (Microsoft Graph)", "value": "DelegatedPermissionGrant.ReadWrite.All" }, + { + "description": "Allows the app to read your organization's devices' configuration information without a signed-in user.", + "displayName": "Read all devices", + "id": "7438b122-aefc-4978-80ed-43db9fcc7715", + "origin": "Application (Microsoft Graph)", + "value": "Device.Read.All" + }, { "description": "Allows the app to read device local credential properties including passwords, without a signed-in user.", "displayName": "Read device local credential passwords", @@ -10997,46 +11046,46 @@ "value": "DeviceManagementCloudCA.Read.All" }, { - "description": "Allows the app to read and write certification authority information without a signed-in user.", - "displayName": "Read and write Microsoft Cloud PKI objects", - "id": "f15eb2ba-ef8a-4f70-991d-da5d045154e2", + "description": "Allows the app to read all delegated permission grants, without a signed-in user.", + "displayName": "Read all delegated permission grants", + "id": "81b4724a-58aa-41c1-8a55-84ef97466587", "origin": "Application (Microsoft Graph)", - "value": "DeviceManagementCloudCA.ReadWrite.All" + "value": "DelegatedPermissionGrant.Read.All" }, { - "description": "Allows the app to read properties of Microsoft Intune-managed device configuration and device compliance policies and their assignment to groups, without a signed-in user.", - "displayName": "Read Microsoft Intune device configuration and policies", - "id": "dc377aa6-52d8-4e23-b271-2a7ae04cedf3", + "description": "Allows the app to delete and recover deleted chats, without a signed-in user.", + "displayName": "Delete and recover deleted chats", + "id": "9c7abde0-eacd-4319-bf9e-35994b1a1717", "origin": "Application (Microsoft Graph)", - "value": "DeviceManagementConfiguration.Read.All" + "value": "Chat.ManageDeletion.All" }, { - "description": "Allows the app to read your organization's devices' configuration information without a signed-in user.", - "displayName": "Read all devices", - "id": "7438b122-aefc-4978-80ed-43db9fcc7715", + "description": "Allows the app to create chats without a signed-in user. ", + "displayName": "Create chats", + "id": "d9c48af6-9ad9-47ad-82c3-63757137b9af", "origin": "Application (Microsoft Graph)", - "value": "Device.Read.All" + "value": "Chat.Create" }, { - "description": "Allows the app to read terms of use acceptance statuses, without a signed in user.", - "displayName": "Read all terms of use acceptance statuses", - "id": "d8e4ec18-f6c0-4620-8122-c8b1f2bf400e", + "description": "Read and write the names, descriptions, and settings of all channels, without a signed-in user.", + "displayName": "Read and write the names, descriptions, and settings of all channels", + "id": "243cded2-bd16-4fd6-a953-ff8177894c3d", "origin": "Application (Microsoft Graph)", - "value": "AgreementAcceptance.Read.All" + "value": "ChannelSettings.ReadWrite.All" }, { - "description": "Allows the app to read all one-to-one or group chat messages in Microsoft Teams for chats where the associated Teams application is installed, without a signed-in user.", - "displayName": "Read all chat messages for chats where the associated Teams application is installed.", - "id": "1c1b4c8e-3cc7-4c58-8470-9b92c9d5848b", + "description": "Allows the app to read and query audit logs from Endpoint Data Loss Prevention workload, without a signed-in user", + "displayName": "Read audit logs data from Endpoint Data Loss Prevention workload", + "id": "0bc85aed-7b0b-437a-bac8-3b29a1b84c99", "origin": "Application (Microsoft Graph)", - "value": "Chat.Read.WhereInstalled" + "value": "AuditLogsQuery-Endpoint.Read.All" }, { - "description": "Allows the app to delete and recover deleted chats, without a signed-in user.", - "displayName": "Delete and recover deleted chats", - "id": "9c7abde0-eacd-4319-bf9e-35994b1a1717", + "description": "Allows the app to read and query audit logs from Entra (Azure AD) workload, without a signed-in user", + "displayName": "Read audit logs data from Entra (Azure AD) workload", + "id": "7276d950-48fc-4269-8348-f22f2bb296d0", "origin": "Application (Microsoft Graph)", - "value": "Chat.ManageDeletion.All" + "value": "AuditLogsQuery-Entra.Read.All" }, { "description": "Allows the app to read and query audit logs from Exchange workload, without a signed-in user", @@ -11144,46 +11193,53 @@ "value": "BitlockerKey.Read.All" }, { - "description": "Allows an app to read basic BitLocker key properties for all devices, without a signed-in user. Does not allow read of the recovery key.", - "displayName": "Read all BitLocker keys basic information", - "id": "f690d423-6b29-4d04-98c6-694c42282419", + "description": "Allows the app to read and query audit logs from Dynamics CRM workload, without a signed-in user", + "displayName": "Read audit logs data from Dynamics CRM workload", + "id": "20e6f8e4-ffac-4cf7-82f7-70ddb7564318", "origin": "Application (Microsoft Graph)", - "value": "BitlockerKey.ReadBasic.All" + "value": "AuditLogsQuery-CRM.Read.All" }, { - "description": "Allows an app to read, write and manage bookings appointments, businesses, customers, services, and staff on behalf of the signed-in user.", - "displayName": "Manage bookings information", - "id": "6b22000a-1228-42ec-88db-b8c00399aecb", + "description": "Allows the app to read and query audit logs from all services.", + "displayName": "Read audit logs data from all services", + "id": "5e1e9171-754d-478c-812c-f1755a9a4c2d", "origin": "Application (Microsoft Graph)", - "value": "Bookings.Manage.All" + "value": "AuditLogsQuery.Read.All" }, { - "description": "Allows the app to read and query audit logs from Entra (Azure AD) workload, without a signed-in user", - "displayName": "Read audit logs data from Entra (Azure AD) workload", - "id": "7276d950-48fc-4269-8348-f22f2bb296d0", + "description": "Allows the app to read and query your audit log activities, without a signed-in user.", + "displayName": "Read all audit log data", + "id": "b0afded3-3588-46d8-8b3d-9842eff778da", "origin": "Application (Microsoft Graph)", - "value": "AuditLogsQuery-Entra.Read.All" + "value": "AuditLog.Read.All" }, { - "description": "Allows an app to read Bookings appointments, businesses, customers, services, and staff without a signed-in user. ", - "displayName": "Read all Bookings related resources.", - "id": "6e98f277-b046-4193-a4f2-6bf6a78cd491", + "description": "Allows the application to upload bulk activity audit logs to the audit store.", + "displayName": "Upload activity audit logs to the audit store.", + "id": "f6318678-2713-4bb6-b123-233e7336c1bd", "origin": "Application (Microsoft Graph)", - "value": "Bookings.Read.All" + "value": "AuditActivity.Write" }, { - "description": "Allows the app to read and query audit logs from Endpoint Data Loss Prevention workload, without a signed-in user", - "displayName": "Read audit logs data from Endpoint Data Loss Prevention workload", - "id": "0bc85aed-7b0b-437a-bac8-3b29a1b84c99", + "description": "Allows the app to read and write terms of use agreements, without a signed in user.", + "displayName": "Read and write all terms of use agreements", + "id": "c9090d00-6101-42f0-a729-c41074260d47", "origin": "Application (Microsoft Graph)", - "value": "AuditLogsQuery-Endpoint.Read.All" + "value": "Agreement.ReadWrite.All" }, { - "description": "Allows the app to read and query audit logs from all services.", - "displayName": "Read audit logs data from all services", - "id": "5e1e9171-754d-478c-812c-f1755a9a4c2d", + "description": "Allows the app to read terms of use acceptance statuses, without a signed in user.", + "displayName": "Read all terms of use acceptance statuses", + "id": "d8e4ec18-f6c0-4620-8122-c8b1f2bf400e", "origin": "Application (Microsoft Graph)", - "value": "AuditLogsQuery.Read.All" + "value": "AgreementAcceptance.Read.All" + }, + { + "description": "Allows the app to read all AI enterprise interactions.", + "displayName": "Read all AI enterprise interactions.", + "id": "839c90ab-5771-41ee-aef8-a562e8487c1e", + "origin": "Application (Microsoft Graph)", + "value": "AiEnterpriseInteraction.Read.All" }, { "description": "Allows the app to read the API connectors used in user authentication flows, without a signed-in user.", @@ -11220,6 +11276,13 @@ "origin": "Application (Microsoft Graph)", "value": "Application.Read.All" }, + { + "description": "Allows an app to read basic BitLocker key properties for all devices, without a signed-in user. Does not allow read of the recovery key.", + "displayName": "Read all BitLocker keys basic information", + "id": "f690d423-6b29-4d04-98c6-694c42282419", + "origin": "Application (Microsoft Graph)", + "value": "BitlockerKey.ReadBasic.All" + }, { "description": "Allows the app to read and update all apps in your organization, without a signed-in user.", "displayName": "Read and update all apps", @@ -11227,13 +11290,6 @@ "origin": "Application (Microsoft Graph)", "value": "Application.ReadUpdate.All" }, - { - "description": "Allows the app to create, read, update and delete applications and service principals without a signed-in user. Allows management of app role assignments, except those exposed by Microsoft Graph. Does not allow management of delegated permission grants.", - "displayName": "Read and write all applications", - "id": "1bfefb4e-e0b5-418b-a88f-73c46d2cc8e9", - "origin": "Application (Microsoft Graph)", - "value": "Application.ReadWrite.All" - }, { "description": "Allows the app to create other applications, and fully manage those applications (read, update, update application secrets and delete), without a signed-in user. It cannot update any apps that it is not an owner of.", "displayName": "Manage apps that this app creates or owns", @@ -11291,25 +11347,25 @@ "value": "AuditActivity.Read" }, { - "description": "Allows the application to upload bulk activity audit logs to the audit store.", - "displayName": "Upload activity audit logs to the audit store.", - "id": "f6318678-2713-4bb6-b123-233e7336c1bd", + "description": "Allows the app to create, read, update and delete applications and service principals without a signed-in user. Allows management of app role assignments, except those exposed by Microsoft Graph. Does not allow management of delegated permission grants.", + "displayName": "Read and write all applications", + "id": "1bfefb4e-e0b5-418b-a88f-73c46d2cc8e9", "origin": "Application (Microsoft Graph)", - "value": "AuditActivity.Write" + "value": "Application.ReadWrite.All" }, { - "description": "Allows the app to read and query your audit log activities, without a signed-in user.", - "displayName": "Read all audit log data", - "id": "b0afded3-3588-46d8-8b3d-9842eff778da", - "origin": "Application (Microsoft Graph)", - "value": "AuditLog.Read.All" + "description": "Allows calling debugging APIs", + "displayName": "UserScope-PPE.Debug.All", + "id": "f6c5fb21-2e2e-42f4-a961-ffb661669441", + "origin": "Application (DirectoryLookupService)", + "value": "UserScope-PPE.Debug.All" }, { - "description": "Allows the app to read and query audit logs from Dynamics CRM workload, without a signed-in user", - "displayName": "Read audit logs data from Dynamics CRM workload", - "id": "20e6f8e4-ffac-4cf7-82f7-70ddb7564318", + "description": "Allows an app to read, write and manage bookings appointments, businesses, customers, services, and staff on behalf of the signed-in user.", + "displayName": "Manage bookings information", + "id": "6b22000a-1228-42ec-88db-b8c00399aecb", "origin": "Application (Microsoft Graph)", - "value": "AuditLogsQuery-CRM.Read.All" + "value": "Bookings.Manage.All" }, { "description": "Allows an app to read and write bookings appointments, businesses, customers, services, and staff on behalf of the signed-in user. Does not allow create, delete and publish of booking businesses.", @@ -11319,18 +11375,18 @@ "value": "Bookings.ReadWrite.All" }, { - "description": "Allows an app to read and write Bookings appointments and customers, and additionally allows reading businesses, services, and staff without a signed-in user.", - "displayName": "Read and write all Bookings related resources.", - "id": "9769393e-5a9f-4302-9e3d-7e018ecb64a7", + "description": "Allows the app to place outbound calls to a single user and transfer calls to users in your organization’s directory, without a signed-in user.", + "displayName": "Initiate outgoing 1 to 1 calls from the app", + "id": "284383ee-7f6e-4e40-a2a8-e85dcb029101", "origin": "Application (Microsoft Graph)", - "value": "BookingsAppointment.ReadWrite.All" + "value": "Calls.Initiate.All" }, { - "description": "Allows an app to read all bookmarks without a signed-in user.", - "displayName": "Read all bookmarks", - "id": "be95e614-8ef3-49eb-8464-1c9503433b86", + "description": "Allows the app to place outbound calls to multiple users and add participants to meetings in your organization, without a signed-in user.", + "displayName": "Initiate outgoing group calls from the app", + "id": "4c277553-8a09-487b-8023-29ee378d8324", "origin": "Application (Microsoft Graph)", - "value": "Bookmark.Read.All" + "value": "Calls.InitiateGroupCall.All" }, { "description": "Allows the app to join group calls and scheduled meetings in your organization, without a signed-in user. The app will be joined with the privileges of a directory user to meetings in your organization.", @@ -11438,46 +11494,46 @@ "value": "ChannelSettings.Read.All" }, { - "description": "Read and write the names, descriptions, and settings of all channels, without a signed-in user.", - "displayName": "Read and write the names, descriptions, and settings of all channels", - "id": "243cded2-bd16-4fd6-a953-ff8177894c3d", + "description": "Allows the app to get direct access to media streams in a call, without a signed-in user.", + "displayName": "Access media streams in a call as an app", + "id": "a7a681dc-756e-4909-b988-f160edc6655f", "origin": "Application (Microsoft Graph)", - "value": "ChannelSettings.ReadWrite.All" + "value": "Calls.AccessMedia.All" }, { - "description": "Allows the app to create chats without a signed-in user. ", - "displayName": "Create chats", - "id": "d9c48af6-9ad9-47ad-82c3-63757137b9af", + "description": "Allows the app to read call records for all calls and online meetings without a signed-in user.", + "displayName": "Read all call records", + "id": "45bbb07e-7321-4fd7-a8f6-3ff27e6a81c8", "origin": "Application (Microsoft Graph)", - "value": "Chat.Create" + "value": "CallRecords.Read.All" }, { - "description": "Allows the app to place outbound calls to multiple users and add participants to meetings in your organization, without a signed-in user.", - "displayName": "Initiate outgoing group calls from the app", - "id": "4c277553-8a09-487b-8023-29ee378d8324", + "description": "Allows the app to read all PSTN and direct routing call log data without a signed-in user.", + "displayName": "Read PSTN and direct routing call log data", + "id": "a2611786-80b3-417e-adaa-707d4261a5f0", "origin": "Application (Microsoft Graph)", - "value": "Calls.InitiateGroupCall.All" + "value": "CallRecord-PstnCalls.Read.All" }, { - "description": "Allows the app to place outbound calls to a single user and transfer calls to users in your organization’s directory, without a signed-in user.", - "displayName": "Initiate outgoing 1 to 1 calls from the app", - "id": "284383ee-7f6e-4e40-a2a8-e85dcb029101", + "description": "Allows the app to read call recordings for all calls without a signed-in user.", + "displayName": "Read all call recordings", + "id": "ce8fb1f1-5e1f-44a0-b102-4ec28454d0dc", "origin": "Application (Microsoft Graph)", - "value": "Calls.Initiate.All" + "value": "CallRecordings.Read.All" }, { - "description": "Allows the app to get direct access to media streams in a call, without a signed-in user.", - "displayName": "Access media streams in a call as an app", - "id": "a7a681dc-756e-4909-b988-f160edc6655f", + "description": "Allows an app to read and write Bookings appointments and customers, and additionally allows reading businesses, services, and staff without a signed-in user.", + "displayName": "Read and write all Bookings related resources.", + "id": "9769393e-5a9f-4302-9e3d-7e018ecb64a7", "origin": "Application (Microsoft Graph)", - "value": "Calls.AccessMedia.All" + "value": "BookingsAppointment.ReadWrite.All" }, { - "description": "Allows the app to read call records for all calls and online meetings without a signed-in user.", - "displayName": "Read all call records", - "id": "45bbb07e-7321-4fd7-a8f6-3ff27e6a81c8", + "description": "Allows an app to read all bookmarks without a signed-in user.", + "displayName": "Read all bookmarks", + "id": "be95e614-8ef3-49eb-8464-1c9503433b86", "origin": "Application (Microsoft Graph)", - "value": "CallRecords.Read.All" + "value": "Bookmark.Read.All" }, { "description": "Allows an app to read all browser site lists configured for your organization, without a signed-in user.", @@ -11517,23 +11573,16 @@ { "description": "Allows the app to fully manage the data associated with the business scenarios it owns, without a signed-in user.", "displayName": "Read and write data for all business scenarios this app creates or owns", - "id": "f2d21f22-5d80-499e-91cc-0a8a4ce16f54", - "origin": "Application (Microsoft Graph)", - "value": "BusinessScenarioData.ReadWrite.OwnedBy" - }, - { - "description": "Allows the app to read work hours and locations settings, recurrences, and occurrences for all users in the organization, without a signed-in user.", - "displayName": "Read all users' work hours and locations", - "id": "470229df-a15a-4b08-9d95-8c534862b362", + "id": "f2d21f22-5d80-499e-91cc-0a8a4ce16f54", "origin": "Application (Microsoft Graph)", - "value": "Calendars.Read.All" + "value": "BusinessScenarioData.ReadWrite.OwnedBy" }, { - "description": "Allows the app to read all 1-to-1 or group chat messages in Microsoft Teams.", - "displayName": "Read all chat messages", - "id": "6b7d71aa-70aa-4810-a8d9-5d9fb2830017", + "description": "Allows an app to read Bookings appointments, businesses, customers, services, and staff without a signed-in user. ", + "displayName": "Read all Bookings related resources.", + "id": "6e98f277-b046-4193-a4f2-6bf6a78cd491", "origin": "Application (Microsoft Graph)", - "value": "Chat.Read.All" + "value": "Bookings.Read.All" }, { "description": "Allows the app to read events of all calendars, except for properties such as body, attachments, and extensions, without a signed-in user.", @@ -11585,39 +11634,32 @@ "value": "CallEvents-Emergency.Read.All" }, { - "description": "Allows the app to read call recordings for all calls without a signed-in user.", - "displayName": "Read all call recordings", - "id": "ce8fb1f1-5e1f-44a0-b102-4ec28454d0dc", - "origin": "Application (Microsoft Graph)", - "value": "CallRecordings.Read.All" - }, - { - "description": "Allows the app to read all PSTN and direct routing call log data without a signed-in user.", - "displayName": "Read PSTN and direct routing call log data", - "id": "a2611786-80b3-417e-adaa-707d4261a5f0", + "description": "Allows the app to read work hours and locations settings, recurrences, and occurrences for all users in the organization, without a signed-in user.", + "displayName": "Read all users' work hours and locations", + "id": "470229df-a15a-4b08-9d95-8c534862b362", "origin": "Application (Microsoft Graph)", - "value": "CallRecord-PstnCalls.Read.All" + "value": "Calendars.Read.All" }, { - "description": "Allows the app to read internal federation configuration for a domain.", - "displayName": "Read internal federation configuration for a domain.", - "id": "c0e5a7b0-e8b7-40a7-b8e0-8249e6ea81d5", + "description": "Allows the app to read all domain properties without a signed-in user.", + "displayName": "Read domains", + "id": "dbb9058a-0e50-45d7-ae91-66909b5d4664", "origin": "Application (Microsoft Graph)", - "value": "Domain-InternalFederation.Read.All" + "value": "Domain.Read.All" }, { - "description": "Allows calling debugging APIs", - "displayName": "UserScope-Dev.Debug.All", - "id": "d3aaaaff-f3e8-4b2f-8285-12478a43eb7d", + "description": "This allows app to run test tenant userscope in DLS", + "displayName": "UserScope-Dev.ReadWrite.All", + "id": "dc532015-4941-4351-b852-8781cf87c6e5", "origin": "Application (DirectoryLookupService)", - "value": "UserScope-Dev.Debug.All" + "value": "UserScope-Dev.ReadWrite.All" }, { - "description": "Allows calling debugging APIs", - "displayName": "UserScope.Debug.All", - "id": "9c87ec21-0463-42cf-a35b-1b1e81ac135f", + "description": "This allows app to run prod tenant userscope in DLS", + "displayName": "UserScope.ReadWrite.All", + "id": "6f6965e3-3c5a-47e2-81a6-9c40ddacc7f6", "origin": "Application (DirectoryLookupService)", - "value": "UserScope.Debug.All" + "value": "UserScope.ReadWrite.All" }, { "description": "Grants the ability to read, write, and manage symbols.", @@ -12760,13 +12802,6 @@ "origin": "Delegated (Azure DevOps)", "value": "vso.auditstreams_manage" }, - { - "description": "This allows app to run prod tenant userscope in DLS", - "displayName": "UserScope.ReadWrite.All", - "id": "6f6965e3-3c5a-47e2-81a6-9c40ddacc7f6", - "origin": "Application (DirectoryLookupService)", - "value": "UserScope.ReadWrite.All" - }, { "description": "Allows user to read Condition resources in their own compartment.", "displayName": "user.Condition.read", @@ -12774,6 +12809,13 @@ "origin": "Delegated (Azure Healthcare APIs)", "value": "user.Condition.read" }, + { + "description": "Allows user to read Device resources in their own compartment.", + "displayName": "user.Device.read", + "id": "a246e7b9-d55c-43a2-9b5a-b3341bc1a57d", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Device.read" + }, { "description": "Allows user to read DiagnosticReport resources in their own compartment.", "displayName": "user.DiagnosticReport.read", @@ -12781,13 +12823,6 @@ "origin": "Delegated (Azure Healthcare APIs)", "value": "user.DiagnosticReport.read" }, - { - "description": "c", - "displayName": "Skype Bot Reviewer", - "id": "ae068e81-caaf-43a2-8081-717c1fb700d0", - "origin": "Application (Bot Framework Dev Portal)", - "value": "SkypeReviewer" - }, { "description": "Read-only access to Bcos resources", "displayName": "Bcos.ReadOnly", @@ -12893,13 +12928,6 @@ "origin": "Application (Configuration Manager Microservice)", "value": "CmCollectionData.write" }, - { - "description": "c", - "displayName": "RBAC Test Role Prod", - "id": "b6c09b98-4044-4869-976f-625da4f561c3", - "origin": "Application (Bot Framework Dev Portal)", - "value": "RBACTestRoleProd" - }, { "description": "Allows to call service API to query collection data", "displayName": "Read collection data", @@ -12908,25 +12936,32 @@ "value": "Collection.Read.All" }, { - "description": "Support engineers for prod devportal", - "displayName": "Prod Devportal Support", - "id": "b1de6b77-7554-4b4d-9db5-dc90af4bbe89", + "description": "c", + "displayName": "Skype Bot Reviewer", + "id": "ae068e81-caaf-43a2-8081-717c1fb700d0", "origin": "Application (Bot Framework Dev Portal)", - "value": "ProdSupport" + "value": "SkypeReviewer" }, { - "description": "Users of scratch / ppe devportal", - "displayName": "Internal Devportal User", - "id": "0e91f604-29c5-475d-9463-5494ee9b147e", + "description": "Allows to call service API to query device data", + "displayName": "Read device data", + "id": "15fdfc00-27d5-4f79-8a38-8efe91e3c1cc", + "origin": "Application (Configuration Manager Microservice)", + "value": "Device.Read.All" + }, + { + "description": "c", + "displayName": "RBAC Test Role Prod", + "id": "b6c09b98-4044-4869-976f-625da4f561c3", "origin": "Application (Bot Framework Dev Portal)", - "value": "IntUser" + "value": "RBACTestRoleProd" }, { - "description": "Allows the app to search all calendars and to read their properties on behalf of the signed-in user. ", - "displayName": "Read all calendars", - "id": "73c5d1d0-1ba7-4978-ad4c-32f0a8a1a9ed", - "origin": "Delegated (Bing)", - "value": "Calendar.Read.All" + "description": "Admins for prod devportal", + "displayName": "Prod Devportal Admin", + "id": "9160be5e-b0e2-4961-9419-21dc535897ca", + "origin": "Application (Bot Framework Dev Portal)", + "value": "ProdAdmin" }, { "description": "Allows the app to search all calendars and to read their properties for default on behalf of the signed-in user. ", @@ -13041,18 +13076,18 @@ "value": "IntSupport" }, { - "description": "Admins for prod devportal", - "displayName": "Prod Devportal Admin", - "id": "9160be5e-b0e2-4961-9419-21dc535897ca", + "description": "Users of scratch / ppe devportal", + "displayName": "Internal Devportal User", + "id": "0e91f604-29c5-475d-9463-5494ee9b147e", "origin": "Application (Bot Framework Dev Portal)", - "value": "ProdAdmin" + "value": "IntUser" }, { - "description": "Allows to call service API to query device data", - "displayName": "Read device data", - "id": "15fdfc00-27d5-4f79-8a38-8efe91e3c1cc", - "origin": "Application (Configuration Manager Microservice)", - "value": "Device.Read.All" + "description": "Support engineers for prod devportal", + "displayName": "Prod Devportal Support", + "id": "b1de6b77-7554-4b4d-9db5-dc90af4bbe89", + "origin": "Application (Bot Framework Dev Portal)", + "value": "ProdSupport" }, { "description": "Allows to call service API to query or modify device data", @@ -13069,11 +13104,11 @@ "value": "InventoryClass.Read.All" }, { - "description": "Permission to create seeding offer", - "displayName": "CREATE/START Seeding offer for a tenant", - "id": "072da657-3fd6-47c8-914c-384bed197d2a", - "origin": "Application (Consumption Billing)", - "value": "Purview.Offer.Seeding.Create" + "description": "Allows to call service API to query notification and notification result", + "displayName": "Read notification or notification result", + "id": "20bd8bbf-3063-4a8f-ae4f-f2f5e5bda666", + "origin": "Application (Configuration Manager Microservice)", + "value": "Notification.Read.All" }, { "description": "Read Permission for seeding offers", @@ -13166,6 +13201,20 @@ "origin": "Application (DirectoryLookupService)", "value": "Users.Read.All" }, + { + "description": "Allows calling debugging APIs", + "displayName": "UserScope.Debug.All", + "id": "9c87ec21-0463-42cf-a35b-1b1e81ac135f", + "origin": "Application (DirectoryLookupService)", + "value": "UserScope.Debug.All" + }, + { + "description": "Permission to create seeding offer", + "displayName": "CREATE/START Seeding offer for a tenant", + "id": "072da657-3fd6-47c8-914c-384bed197d2a", + "origin": "Application (Consumption Billing)", + "value": "Purview.Offer.Seeding.Create" + }, { "description": "Permission to update seeding offer consumption", "displayName": "Update consumption against a feature as part of seeding offers", @@ -13187,20 +13236,6 @@ "origin": "Application (Consumption Billing)", "value": "Purview.Offer.FreeTrial.Create" }, - { - "description": "Permission to update free trials consumption", - "displayName": "Update consumption against a feature as part of free trials", - "id": "30d79437-9413-4983-80b2-b9c64df69cde", - "origin": "Application (Consumption Billing)", - "value": "Purview.Offer.FreeTrial.ConsumedUnits.Write" - }, - { - "description": "Allows to call service API to query notification and notification result", - "displayName": "Read notification or notification result", - "id": "20bd8bbf-3063-4a8f-ae4f-f2f5e5bda666", - "origin": "Application (Configuration Manager Microservice)", - "value": "Notification.Read.All" - }, { "description": "Allows to call service API to query or modify notification and notification result", "displayName": "Read or write notification and notification result", @@ -13209,18 +13244,18 @@ "value": "Notification.ReadWrite.All" }, { - "description": "Allows the app to list buildings and to read their properties on behalf of the signed-in user. ", - "displayName": "Read all buildings", - "id": "b74d6cc7-732d-424d-9f47-b08e1404f765", + "description": "Allows the app to search all calendars and to read their properties on behalf of the signed-in user. ", + "displayName": "Read all calendars", + "id": "73c5d1d0-1ba7-4978-ad4c-32f0a8a1a9ed", "origin": "Delegated (Bing)", - "value": "Building.Read.All" + "value": "Calendar.Read.All" }, { - "description": "Allows the app to create and manage connector configurations. The app would use the connector configuration to send actionable messages to your inbox or a group of your choice.", - "displayName": "Read and write connector configurations", - "id": "ba9c6a98-63fd-487c-b835-c1f895764e25", - "origin": "Delegated (Connectors)", - "value": "webhook.readwrite.all" + "description": "Access Connections Service Api", + "displayName": "Access Connections Service Api", + "id": "04d2d44f-432b-4f9b-be28-cb651a028099", + "origin": "Delegated (ConnectionsService)", + "value": "user_impersonation" }, { "description": "Authorized to call the Consumption Billing reporting API for a single tenant id", @@ -13272,18 +13307,25 @@ "value": "Purview.Account.Read.Any" }, { - "description": "Access Connections Service Api", - "displayName": "Access Connections Service Api", - "id": "04d2d44f-432b-4f9b-be28-cb651a028099", - "origin": "Delegated (ConnectionsService)", - "value": "user_impersonation" + "description": "Permission to update free trials consumption", + "displayName": "Update consumption against a feature as part of free trials", + "id": "30d79437-9413-4983-80b2-b9c64df69cde", + "origin": "Application (Consumption Billing)", + "value": "Purview.Offer.FreeTrial.ConsumedUnits.Write" }, { - "description": "Allows user to read Device resources in their own compartment.", - "displayName": "user.Device.read", - "id": "a246e7b9-d55c-43a2-9b5a-b3341bc1a57d", - "origin": "Delegated (Azure Healthcare APIs)", - "value": "user.Device.read" + "description": "Allows the app to create and manage connector configurations. The app would use the connector configuration to send actionable messages to your inbox or a group of your choice.", + "displayName": "Read and write connector configurations", + "id": "ba9c6a98-63fd-487c-b835-c1f895764e25", + "origin": "Delegated (Connectors)", + "value": "webhook.readwrite.all" + }, + { + "description": "Allows the app to list buildings and to read their properties on behalf of the signed-in user. ", + "displayName": "Read all buildings", + "id": "b74d6cc7-732d-424d-9f47-b08e1404f765", + "origin": "Delegated (Bing)", + "value": "Building.Read.All" }, { "description": "Allows the app to list bookmarks and to read their properties on behalf of the signed-in user. ", @@ -13293,18 +13335,11 @@ "value": "Bookmark.Read.All" }, { - "description": "Allows members of a special preview group to use experimental features of Bing", - "displayName": "Preview User", - "id": "cfc0dc64-9211-4513-9d32-c387680182cf", - "origin": "Application (Bing)", - "value": "bawuser" - }, - { - "description": "Allow the application full access to the Azure Key Vault service on behalf of the signed-in user", - "displayName": "Have full access to the Azure Key Vault service", - "id": "f53da476-18e3-4152-8e01-aec403e6edc0", - "origin": "Delegated (Azure Key Vault)", - "value": "user_impersonation" + "description": "Allows the app to list Acronym and to read their properties on behalf of the signed-in user. ", + "displayName": "Read all Acronyms", + "id": "92bacdd9-8c69-46f7-a004-387210ecd2eb", + "origin": "Delegated (Bing)", + "value": "Acronym.Read.All" }, { "description": "this allows to read user profile", @@ -13418,13 +13453,6 @@ "origin": "Application (Azure Signup Api)", "value": "Qualification_Commercial" }, - { - "description": "Allow the application to access Inference Service on behalf of the signed-in user.", - "displayName": "Access Inference Service", - "id": "a1e1f816-e7ca-4a34-900a-f863a751e400", - "origin": "Delegated (Azure Inference Service)", - "value": "Azure.Inference.User" - }, { "description": "Allow user to add dod qualification.", "displayName": "Qualification_DOD", @@ -13432,6 +13460,20 @@ "origin": "Application (Azure Signup Api)", "value": "Qualification_DOD" }, + { + "description": "Allow the application full access to the Azure Key Vault service on behalf of the signed-in user", + "displayName": "Have full access to the Azure Key Vault service", + "id": "f53da476-18e3-4152-8e01-aec403e6edc0", + "origin": "Delegated (Azure Key Vault)", + "value": "user_impersonation" + }, + { + "description": "Allow the application to access Inference Service on behalf of the signed-in user.", + "displayName": "Access Inference Service", + "id": "a1e1f816-e7ca-4a34-900a-f863a751e400", + "origin": "Delegated (Azure Inference Service)", + "value": "Azure.Inference.User" + }, { "description": "Have the permissions to read models, deployments and environments.", "displayName": "Inference ML reader", @@ -13440,11 +13482,11 @@ "value": "Azure.Inference.MLReader" }, { - "description": "Have the permissions to execute inference calls.", - "displayName": "Inference executor", - "id": "92ad2108-b071-46c2-8ac0-1dcf9a2c4fd6", + "description": "Have the permissions to create and modify models, deployments and environments; update traffic of deployments and perform; and scale up deployments.", + "displayName": "Inference ML administrator", + "id": "90d1b19a-1849-4c47-9d91-ed1842c92f52", "origin": "Application (Azure Inference Service)", - "value": "Azure.Inference.Executor" + "value": "Azure.Inference.MLAdministrator" }, { "description": "Allows user to read DocumentReference resources in their own compartment.", @@ -13502,6 +13544,13 @@ "origin": "Delegated (Azure Healthcare APIs)", "value": "user.Observation.read" }, + { + "description": "Allow user to add gcc high qualification.", + "displayName": "Qualification_GCCHigh", + "id": "ab0c514c-6a2b-4a77-81bc-74019dff79d3", + "origin": "Application (Azure Signup Api)", + "value": "Qualification_GCCHigh" + }, { "description": "Allows user to read Organization resources in their own compartment.", "displayName": "user.Organization.read", @@ -13509,13 +13558,6 @@ "origin": "Delegated (Azure Healthcare APIs)", "value": "user.Organization.read" }, - { - "description": "Allows user to read Patient resources in their own compartment.", - "displayName": "user.Patient.read", - "id": "56998e01-1f00-4832-a130-c358e252acf2", - "origin": "Delegated (Azure Healthcare APIs)", - "value": "user.Patient.read" - }, { "description": "Allows user to read Practitioner resources in their own compartment.", "displayName": "user.Practitioner.read", @@ -13566,18 +13608,25 @@ "value": "Azure.Inference.Admin" }, { - "description": "Have the permissions to create and modify models, deployments and environments; update traffic of deployments and perform; and scale up deployments.", - "displayName": "Inference ML administrator", - "id": "90d1b19a-1849-4c47-9d91-ed1842c92f52", + "description": "Have the permissions to execute inference calls.", + "displayName": "Inference executor", + "id": "92ad2108-b071-46c2-8ac0-1dcf9a2c4fd6", "origin": "Application (Azure Inference Service)", - "value": "Azure.Inference.MLAdministrator" + "value": "Azure.Inference.Executor" }, { - "description": "Allow user to add gcc high qualification.", - "displayName": "Qualification_GCCHigh", - "id": "ab0c514c-6a2b-4a77-81bc-74019dff79d3", - "origin": "Application (Azure Signup Api)", - "value": "Qualification_GCCHigh" + "description": "Allows user to read Patient resources in their own compartment.", + "displayName": "user.Patient.read", + "id": "56998e01-1f00-4832-a130-c358e252acf2", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Patient.read" + }, + { + "description": "Allows calling debugging APIs", + "displayName": "UserScope-Dev.Debug.All", + "id": "d3aaaaff-f3e8-4b2f-8285-12478a43eb7d", + "origin": "Application (DirectoryLookupService)", + "value": "UserScope-Dev.Debug.All" }, { "description": "Allow user to add government qualification.", @@ -13587,18 +13636,11 @@ "value": "Qualification_Government" }, { - "description": "Provides delegated role to the caller.", - "displayName": "SignupPlatformDelegatedRole", - "id": "8de2faed-dae7-4e94-8d5d-a49be218c680", + "description": "Allows partners to add tags with charity namespace.", + "displayName": "Tag_charity", + "id": "eb6f173a-fd78-41c4-9208-e2df4e4e0475", "origin": "Application (Azure Signup Api)", - "value": "SignupPlatformDelegatedRole" - }, - { - "description": "Allows the app to make API calls that require read and write permissions on ContextualSupport Service, on behalf of the signed-in user.", - "displayName": "Make API calls that require read and write permissions on ContextualSupport Service", - "id": "c21cb1c4-59a0-4474-939f-6e57bf66bfde", - "origin": "Delegated (Azure-WaaS-ContextualSupport-Service)", - "value": "ContextualSupport.ReadWrite.All" + "value": "Tag_charity" }, { "description": "Address Customer Master Reader", @@ -13712,6 +13754,20 @@ "origin": "Application (Billing)", "value": "SubscriptionMigrator" }, + { + "description": "Allows members of a special preview group to use experimental features of Bing", + "displayName": "Preview User", + "id": "cfc0dc64-9211-4513-9d32-c387680182cf", + "origin": "Application (Bing)", + "value": "bawuser" + }, + { + "description": "Allows the app to make API calls that require read and write permissions on ContextualSupport Service, on behalf of the signed-in user.", + "displayName": "Make API calls that require read and write permissions on ContextualSupport Service", + "id": "c21cb1c4-59a0-4474-939f-6e57bf66bfde", + "origin": "Delegated (Azure-WaaS-ContextualSupport-Service)", + "value": "ContextualSupport.ReadWrite.All" + }, { "description": "Allow the app to submit and retrieve jobs.", "displayName": "Jobs.ReadWrite", @@ -13733,20 +13789,6 @@ "origin": "Application (AzureCommunicationsGateway)", "value": "ProvisioningAPI.WriteUser" }, - { - "description": "Allows an application to invoke any write (POST, PUT) operation across the provisioning API.", - "displayName": "ProvisioningAPI.Write", - "id": "31e9e2c5-f52d-4a97-9962-5c4fc2d1bcc1", - "origin": "Application (AzureCommunicationsGateway)", - "value": "ProvisioningAPI.Write" - }, - { - "description": "Allows partners to add tags with charity namespace.", - "displayName": "Tag_charity", - "id": "eb6f173a-fd78-41c4-9208-e2df4e4e0475", - "origin": "Application (Azure Signup Api)", - "value": "Tag_charity" - }, { "description": "Allows partners to add tags with ea namespace.", "displayName": "Tag_ea", @@ -13796,13 +13838,6 @@ "origin": "Application (Azure SQL Database)", "value": "app_impersonation" }, - { - "description": "Allows the app to list Acronym and to read their properties on behalf of the signed-in user. ", - "displayName": "Read all Acronyms", - "id": "92bacdd9-8c69-46f7-a004-387210ecd2eb", - "origin": "Delegated (Bing)", - "value": "Acronym.Read.All" - }, { "description": "Access Azure SQL DB and Data Warehouse", "displayName": "Access Azure SQL DB and Data Warehouse", @@ -13811,11 +13846,18 @@ "value": "user_impersonation" }, { - "description": "Allow the application to access Azure Storage on behalf of the signed-in user.", - "displayName": "Access Azure Storage", - "id": "03e0da56-190b-40ad-a80c-ea378c433f7f", - "origin": "Delegated (Azure Storage)", - "value": "user_impersonation" + "description": "Provides delegated role to the caller.", + "displayName": "SignupPlatformDelegatedRole", + "id": "8de2faed-dae7-4e94-8d5d-a49be218c680", + "origin": "Application (Azure Signup Api)", + "value": "SignupPlatformDelegatedRole" + }, + { + "description": "Allows the application to create conversation threads and reply on existing threads for the SRE agents that user has access to", + "displayName": "Create conversation threads with SRE agents and reply on existing conversation threads", + "id": "c41153e1-cb8a-4a26-ac7e-e6457e0716cf", + "origin": "Delegated (Azure SRE Agent)", + "value": "Threads.ReadWrite.All" }, { "description": "Allow the application full access to the Azure Time Series Insights service on behalf of the signed-in user.", @@ -13867,18 +13909,32 @@ "value": "ProvisioningAPI.ReadUser" }, { - "description": "Allows the application to create conversation threads and reply on existing threads for the SRE agents that user has access to", - "displayName": "Create conversation threads with SRE agents and reply on existing conversation threads", - "id": "c41153e1-cb8a-4a26-ac7e-e6457e0716cf", - "origin": "Delegated (Azure SRE Agent)", - "value": "Threads.ReadWrite.All" + "description": "Allows an application to invoke any write (POST, PUT) operation across the provisioning API.", + "displayName": "ProvisioningAPI.Write", + "id": "31e9e2c5-f52d-4a97-9962-5c4fc2d1bcc1", + "origin": "Application (AzureCommunicationsGateway)", + "value": "ProvisioningAPI.Write" }, { - "description": "Allows the app to manage restricted resources based on the other permissions granted to the app, on behalf of the signed-in user.", - "displayName": "Manage restricted resources in the directory", - "id": "cba5390f-ed6a-4b7f-b657-0efc2210ed20", - "origin": "Delegated", - "value": "Directory.Write.Restricted" + "description": "Allow the application to access Azure Storage on behalf of the signed-in user.", + "displayName": "Access Azure Storage", + "id": "03e0da56-190b-40ad-a80c-ea378c433f7f", + "origin": "Delegated (Azure Storage)", + "value": "user_impersonation" + }, + { + "description": "Allows the app to read and write all domain properties without a signed in user. Also allows the app to add, verify and remove domains.", + "displayName": "Read and write domains", + "id": "7e05723c-0bb0-42da-be95-ae9f08a6e53c", + "origin": "Application (Microsoft Graph)", + "value": "Domain.ReadWrite.All" + }, + { + "description": "Allows the app to read internal federation configuration for a domain.", + "displayName": "Read internal federation configuration for a domain.", + "id": "c0e5a7b0-e8b7-40a7-b8e0-8249e6ea81d5", + "origin": "Application (Microsoft Graph)", + "value": "Domain-InternalFederation.Read.All" }, { "description": "Allows the app to create, read, update and delete internal federation configuration for a domain.", @@ -13888,11 +13944,11 @@ "value": "Domain-InternalFederation.ReadWrite.All" }, { - "description": "Allows the app to read and write eDiscovery objects such as cases, custodians, review sets and other related objects without a signed-in user.", - "displayName": "Read and write all eDiscovery objects", - "id": "b2620db1-3bf7-4c5b-9cb9-576d29eac736", + "description": "Allows the app to read, update and delete identities that are associated with a user's account, without a signed in user. This controls the identities users can sign-in with.", + "displayName": "Manage all users' identities", + "id": "c529cfca-c91b-489c-af2b-d92990b66ce6", "origin": "Application (Microsoft Graph)", - "value": "eDiscovery.ReadWrite.All" + "value": "User.ManageIdentities.All" }, { "description": "Allows the app to read a basic set of profile properties of other users in your organization without a signed-in user. Includes display name, first and last name, email address, open extensions, and photo.", @@ -13992,6 +14048,13 @@ "origin": "Application (Microsoft Graph)", "value": "UserAuthMethod-HardwareOATH.Delete.All" }, + { + "description": "Allows the app to invite guest users to the organization, without a signed-in user.", + "displayName": "Invite guest users to the organization", + "id": "09850681-111b-4a89-9bed-3f2cae46d706", + "origin": "Application (Microsoft Graph)", + "value": "User.Invite.All" + }, { "description": "Allows the app to read HardwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", "displayName": "Read all users' HardwareOATH authentication methods", @@ -14000,25 +14063,25 @@ "value": "UserAuthMethod-HardwareOATH.Read.All" }, { - "description": "Allows the application to read and write HardwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' HardwareOATH authentication methods", - "id": "7e9ebcc1-90aa-4471-8051-e68d6b4e9c89", + "description": "Allows the app to delete and restore all users, without a signed-in user.", + "displayName": "Delete and restore all users", + "id": "eccc023d-eccf-4e7b-9683-8813ab36cecc", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-HardwareOATH.ReadWrite.All" + "value": "User.DeleteRestore.All" }, { - "description": "Allows the application to delete Microsoft Authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify Microsoft Authentication methods.", - "displayName": "Delete all users' Microsoft Authentication methods", - "id": "ae494ca6-9612-417a-972a-ef52efaf2de3", + "description": "Allows the application to list and read related tenants information without a signed-in user.", + "displayName": "Read related tenants", + "id": "7ced9a83-8e7c-46df-b3e0-6b45a6ecedcd", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-MicrosoftAuthApp.Delete.All" + "value": "TenantGovernance-RelatedTenant.Read.All" }, { - "description": "Allows the app to read, update and delete identities that are associated with a user's account, without a signed in user. This controls the identities users can sign-in with.", - "displayName": "Manage all users' identities", - "id": "c529cfca-c91b-489c-af2b-d92990b66ce6", + "description": "Allows the application to list and read all Tenant Governance relationships without a signed-in user.", + "displayName": "Read Tenant Governance relationships", + "id": "41c250d0-8793-44e1-a130-5fdbd5bccd0a", "origin": "Application (Microsoft Graph)", - "value": "User.ManageIdentities.All" + "value": "TenantGovernance-Relationship.Read.All" }, { "description": "Allows the application to list and read all Tenant Governance requests without a signed-in user.", @@ -14125,13 +14188,6 @@ "origin": "Application (Microsoft Graph)", "value": "User.Create" }, - { - "description": "Allows the app to delete and restore all users, without a signed-in user.", - "displayName": "Delete and restore all users", - "id": "eccc023d-eccf-4e7b-9683-8813ab36cecc", - "origin": "Application (Microsoft Graph)", - "value": "User.DeleteRestore.All" - }, { "description": "Allows the app to enable and disable users' accounts, without a signed-in user.", "displayName": "Enable and disable user accounts", @@ -14140,11 +14196,18 @@ "value": "User.EnableDisableAccount.All" }, { - "description": "Allows the app to invite guest users to the organization, without a signed-in user.", - "displayName": "Invite guest users to the organization", - "id": "09850681-111b-4a89-9bed-3f2cae46d706", + "description": "Allows the application to read and write HardwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' HardwareOATH authentication methods", + "id": "7e9ebcc1-90aa-4471-8051-e68d6b4e9c89", "origin": "Application (Microsoft Graph)", - "value": "User.Invite.All" + "value": "UserAuthMethod-HardwareOATH.ReadWrite.All" + }, + { + "description": "Allows the application to delete Microsoft Authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify Microsoft Authentication methods.", + "displayName": "Delete all users' Microsoft Authentication methods", + "id": "ae494ca6-9612-417a-972a-ef52efaf2de3", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-MicrosoftAuthApp.Delete.All" }, { "description": "Allows the app to read Microsoft authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", @@ -14154,18 +14217,18 @@ "value": "UserAuthMethod-MicrosoftAuthApp.Read.All" }, { - "description": "Allows the application to read and write Microsoft Authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' Microsoft Authentication methods", - "id": "c833c349-a1ab-4b6d-94a2-fa9a8674420c", + "description": "Allows the app to read Temporary Access Pass authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' Temporary Access Pass methods", + "id": "bf82209c-b22b-4747-ac88-a68be99032cf", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-MicrosoftAuthApp.ReadWrite.All" + "value": "UserAuthMethod-TAP.Read.All" }, { - "description": "Allows the application to delete passkey authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify passkey authentication methods.", - "displayName": "Delete all users' passkey authentication methods", - "id": "9563fbd0-03a7-466e-8042-63d668b7d1a3", + "description": "Allows the application to read and write Temporary Access Pass authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' Temporary Access Pass methods", + "id": "627169a8-8c15-451c-861a-5b80e383de5c", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-Passkey.Delete.All" + "value": "UserAuthMethod-TAP.ReadWrite.All" }, { "description": "Allows the application to delete Windows Hello authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify Windows Hello authentication methods.", @@ -14273,46 +14336,46 @@ "value": "VerifiedId-Profile.Read.All" }, { - "description": "Allows the application to read virtual appointments for all users, without a signed-in user. The app must also be authorized to access an individual user’s data by the online meetings application access policy.", - "displayName": "Read all virtual appointments for users, as authorized by online meetings application access policy", - "id": "d4f67ec2-59b5-4bdc-b4af-d78f6f9c1954", + "description": "Allows the application to delete Temporary Access Pass authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify Temporary Access Pass authentication methods.", + "displayName": "Delete all users' Temporary Access Pass authentication methods", + "id": "4f872e9d-d232-4ecd-ab9c-337cbdb184e5", "origin": "Application (Microsoft Graph)", - "value": "VirtualAppointment.Read.All" + "value": "UserAuthMethod-TAP.Delete.All" }, { - "description": "Allows the application to read and write virtual appointments for all users, without a signed-in user. The app must also be authorized to access an individual user’s data by the online meetings application access policy.", - "displayName": "Read-write all virtual appointments for users, as authorized by online meetings app access policy", - "id": "bf46a256-f47d-448f-ab78-f226fff08d40", + "description": "Allows the application to read and write SoftwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' SoftwareOATH methods", + "id": "787442d4-3c6e-4e99-aa95-8ccca20a48ff", "origin": "Application (Microsoft Graph)", - "value": "VirtualAppointment.ReadWrite.All" + "value": "UserAuthMethod-SoftwareOATH.ReadWrite.All" }, { - "description": "Allows the application to read and write Temporary Access Pass authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' Temporary Access Pass methods", - "id": "627169a8-8c15-451c-861a-5b80e383de5c", + "description": "Allows the app to read SoftwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' SoftwareOATH methods", + "id": "a6b423df-a0c8-411d-a809-a4a5985d2939", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-TAP.ReadWrite.All" + "value": "UserAuthMethod-SoftwareOATH.Read.All" }, { - "description": "Allows the app to read Temporary Access Pass authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' Temporary Access Pass methods", - "id": "bf82209c-b22b-4747-ac88-a68be99032cf", + "description": "Allows the application to delete SoftwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify SoftwareOATH authentication methods.", + "displayName": "Delete all users' SoftwareOATH authentication methods", + "id": "e5676e10-1a16-452b-ad10-71f54b755852", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-TAP.Read.All" + "value": "UserAuthMethod-SoftwareOATH.Delete.All" }, { - "description": "Allows the application to delete Temporary Access Pass authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify Temporary Access Pass authentication methods.", - "displayName": "Delete all users' Temporary Access Pass authentication methods", - "id": "4f872e9d-d232-4ecd-ab9c-337cbdb184e5", + "description": "Allows the application to read and write Microsoft Authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' Microsoft Authentication methods", + "id": "c833c349-a1ab-4b6d-94a2-fa9a8674420c", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-TAP.Delete.All" + "value": "UserAuthMethod-MicrosoftAuthApp.ReadWrite.All" }, { - "description": "Allows the application to read and write SoftwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' SoftwareOATH methods", - "id": "787442d4-3c6e-4e99-aa95-8ccca20a48ff", + "description": "Allows the application to delete passkey authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify passkey authentication methods.", + "displayName": "Delete all users' passkey authentication methods", + "id": "9563fbd0-03a7-466e-8042-63d668b7d1a3", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-SoftwareOATH.ReadWrite.All" + "value": "UserAuthMethod-Passkey.Delete.All" }, { "description": "Allows the app to read passkey authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", @@ -14356,6 +14419,13 @@ "origin": "Application (Microsoft Graph)", "value": "UserAuthMethod-Phone.Read.All" }, + { + "description": "Allows the application to list and read all Tenant Governance policy templates without a signed-in user.", + "displayName": "Read Tenant Governance policy templates", + "id": "eb9465d8-e7c0-4301-8e51-927f34ee3134", + "origin": "Application (Microsoft Graph)", + "value": "TenantGovernance-PolicyTemplate.Read.All" + }, { "description": "Allows the application to read and write phone methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", "displayName": "Read and write all users' phone methods", @@ -14363,20 +14433,6 @@ "origin": "Application (Microsoft Graph)", "value": "UserAuthMethod-Phone.ReadWrite.All" }, - { - "description": "Allows the application to delete platform credentials methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify platform credentials methods.", - "displayName": "Delete all users' platform credentials methods", - "id": "bd760918-651f-4e67-b66f-8f614384dec2", - "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-PlatformCred.Delete.All" - }, - { - "description": "Allows the application to list and read all Tenant Governance relationships without a signed-in user.", - "displayName": "Read Tenant Governance relationships", - "id": "41c250d0-8793-44e1-a130-5fdbd5bccd0a", - "origin": "Application (Microsoft Graph)", - "value": "TenantGovernance-Relationship.Read.All" - }, { "description": "Allows the app to read platform credentials methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", "displayName": "Read all users' platform credentials methods", @@ -14384,6 +14440,13 @@ "origin": "Application (Microsoft Graph)", "value": "UserAuthMethod-PlatformCred.Read.All" }, + { + "description": "Allows the application to read and write platform credentials methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' platform credentials methods", + "id": "1a87acf4-a9ca-4576-a974-452ea265d5f6", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-PlatformCred.ReadWrite.All" + }, { "description": "Allows the application to delete QR authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify QR authentication methods.", "displayName": "Delete all users' QR authentication methods", @@ -14427,46 +14490,46 @@ "value": "UserAuthMethod-ResourceKey.ReadWrite.All" }, { - "description": "Allows the application to delete SoftwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify SoftwareOATH authentication methods.", - "displayName": "Delete all users' SoftwareOATH authentication methods", - "id": "e5676e10-1a16-452b-ad10-71f54b755852", + "description": "Allows the application to delete platform credentials methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify platform credentials methods.", + "displayName": "Delete all users' platform credentials methods", + "id": "bd760918-651f-4e67-b66f-8f614384dec2", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-SoftwareOATH.Delete.All" + "value": "UserAuthMethod-PlatformCred.Delete.All" }, { - "description": "Allows the app to read SoftwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' SoftwareOATH methods", - "id": "a6b423df-a0c8-411d-a809-a4a5985d2939", + "description": "Allows the application to read virtual appointments for all users, without a signed-in user. The app must also be authorized to access an individual user’s data by the online meetings application access policy.", + "displayName": "Read all virtual appointments for users, as authorized by online meetings application access policy", + "id": "d4f67ec2-59b5-4bdc-b4af-d78f6f9c1954", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-SoftwareOATH.Read.All" + "value": "VirtualAppointment.Read.All" }, { - "description": "Allows the application to read and write platform credentials methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' platform credentials methods", - "id": "1a87acf4-a9ca-4576-a974-452ea265d5f6", + "description": "Allows the application to list and read all Tenant Governance invitations without a signed-in user.", + "displayName": "Read Tenant Governance invitations", + "id": "3f4f98e9-6faf-4e5f-814b-ed2ed8a4ec9e", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-PlatformCred.ReadWrite.All" + "value": "TenantGovernance-Invitation.Read.All" }, { - "description": "Allows the application to send notification regarding virtual appointments as any user, without a signed-in user. The app must also be authorized to access an individual user's data by the online meetings application access policy.", - "displayName": "Send notification regarding virtual appointments as any user", - "id": "97e45b36-1250-48e4-bd70-2df6dab7e94a", + "description": "Allows the app to read and write tags in Teams without a signed-in user.", + "displayName": "Read and write tags in Teams", + "id": "a3371ca5-911d-46d6-901c-42c8c7a937d8", "origin": "Application (Microsoft Graph)", - "value": "VirtualAppointmentNotification.Send" + "value": "TeamworkTag.ReadWrite.All" }, { - "description": "Allows the application to list and read related tenants information without a signed-in user.", - "displayName": "Read related tenants", - "id": "7ced9a83-8e7c-46df-b3e0-6b45a6ecedcd", + "description": "Allows the app to create teams without a signed-in user. ", + "displayName": "Create teams", + "id": "23fc2474-f741-46ce-8465-674744c5c361", "origin": "Application (Microsoft Graph)", - "value": "TenantGovernance-RelatedTenant.Read.All" + "value": "Team.Create" }, { - "description": "Allows the application to list and read all Tenant Governance invitations without a signed-in user.", - "displayName": "Read Tenant Governance invitations", - "id": "3f4f98e9-6faf-4e5f-814b-ed2ed8a4ec9e", + "description": "Get a list of all teams, without a signed-in user.", + "displayName": "Get a list of all teams", + "id": "2280dda6-0bfd-44ee-a2f4-cb867cfc4c1e", "origin": "Application (Microsoft Graph)", - "value": "TenantGovernance-Invitation.Read.All" + "value": "Team.ReadBasic.All" }, { "description": "Read the members of all teams, without a signed-in user.", @@ -14573,6 +14636,13 @@ "origin": "Application (Microsoft Graph)", "value": "TeamsAppInstallation.ReadSelectedForUser.All" }, + { + "description": "Allows the app to create, read, update and delete all users’ tasks and task lists in your organization, without a signed-in user", + "displayName": "Read and write all users’ tasks and tasklists", + "id": "44e666d1-d276-445b-a5fc-8815eeb81d55", + "origin": "Application (Microsoft Graph)", + "value": "Tasks.ReadWrite.All" + }, { "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any chat, without a signed-in user. Gives the ability to manage permission grants for accessing those specific chats' data.", "displayName": "Manage installation and permission grants of Teams apps for all chats", @@ -14581,39 +14651,32 @@ "value": "TeamsAppInstallation.ReadWriteAndConsentForChat.All" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any team, without a signed-in user. Gives the ability to manage permission grants for accessing those specific teams' data.", - "displayName": "Manage installation and permission grants of Teams apps for all teams", - "id": "b0c13be0-8e20-4bc5-8c55-963c23a39ce9", - "origin": "Application (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteAndConsentForTeam.All" - }, - { - "description": "Get a list of all teams, without a signed-in user.", - "displayName": "Get a list of all teams", - "id": "2280dda6-0bfd-44ee-a2f4-cb867cfc4c1e", + "description": "Allows the app to read all users’ tasks and task lists in your organization, without a signed-in user.", + "displayName": "Read all users’ tasks and tasklist", + "id": "f10e1f91-74ed-437f-a6fd-d6ae88e26c1f", "origin": "Application (Microsoft Graph)", - "value": "Team.ReadBasic.All" + "value": "Tasks.Read.All" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any user account, without a signed-in user. Gives the ability to manage permission grants for accessing those specific users' data.", - "displayName": "Manage installation and permission grants of Teams apps in a user account", - "id": "32ca478f-f89e-41d0-aaf8-101deb7da510", + "description": "Allows the application to upload bulk user data to the identity synchronization service, without a signed-in user.", + "displayName": "Upload user data to the identity synchronization service", + "id": "db31e92a-b9ea-4d87-bf6a-75a37a9ca35a", "origin": "Application (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteAndConsentForUser.All" + "value": "SynchronizationData-User.Upload" }, { - "description": "Allows the app to create teams without a signed-in user. ", - "displayName": "Create teams", - "id": "23fc2474-f741-46ce-8465-674744c5c361", + "description": "Allows the app to read, create, edit, and delete all the short notes without a signed-in user.", + "displayName": "Read, create, edit, and delete all users' short notes", + "id": "842c284c-763d-4a97-838d-79787d129bab", "origin": "Application (Microsoft Graph)", - "value": "Team.Create" + "value": "ShortNotes.ReadWrite.All" }, { - "description": "Allows the app to read all users’ tasks and task lists in your organization, without a signed-in user.", - "displayName": "Read all users’ tasks and tasklist", - "id": "f10e1f91-74ed-437f-a6fd-d6ae88e26c1f", + "description": "Allows the app to read your organization's sign-in identifiers, without a signed-in user.", + "displayName": "Read all sign-in identifiers", + "id": "28e1fe78-598f-4df4-b55e-18bf34218925", "origin": "Application (Microsoft Graph)", - "value": "Tasks.Read.All" + "value": "SignInIdentifier.Read.All" }, { "description": "Allows the app to read and write your organization's sign-in identifiers, without a signed-in user.", @@ -14720,13 +14783,6 @@ "origin": "Application (Microsoft Graph)", "value": "Synchronization.ReadWrite.All" }, - { - "description": "Allows the application to upload bulk user data to the identity synchronization service, without a signed-in user.", - "displayName": "Upload user data to the identity synchronization service", - "id": "db31e92a-b9ea-4d87-bf6a-75a37a9ca35a", - "origin": "Application (Microsoft Graph)", - "value": "SynchronizationData-User.Upload" - }, { "description": "Allows the application to upload bulk user data to the identity synchronization service for apps that this application creates or owns, without a signed-in user.", "displayName": "Upload user data to the identity sync service for apps that this application creates or owns", @@ -14735,11 +14791,18 @@ "value": "SynchronizationData-User.Upload.OwnedBy" }, { - "description": "Allows the app to create, read, update and delete all users’ tasks and task lists in your organization, without a signed-in user", - "displayName": "Read and write all users’ tasks and tasklists", - "id": "44e666d1-d276-445b-a5fc-8815eeb81d55", + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any team, without a signed-in user. Gives the ability to manage permission grants for accessing those specific teams' data.", + "displayName": "Manage installation and permission grants of Teams apps for all teams", + "id": "b0c13be0-8e20-4bc5-8c55-963c23a39ce9", "origin": "Application (Microsoft Graph)", - "value": "Tasks.ReadWrite.All" + "value": "TeamsAppInstallation.ReadWriteAndConsentForTeam.All" + }, + { + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any user account, without a signed-in user. Gives the ability to manage permission grants for accessing those specific users' data.", + "displayName": "Manage installation and permission grants of Teams apps in a user account", + "id": "32ca478f-f89e-41d0-aaf8-101deb7da510", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentForUser.All" }, { "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any chat, without a signed-in user, and manage its permission grants for accessing those specific chats' data.", @@ -14749,18 +14812,18 @@ "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForChat.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any team, without a signed-in user, and manage its permission grants for accessing those specific teams' data.", - "displayName": "Allow the Teams app to manage itself and its permission grants for all teams", - "id": "1e4be56c-312e-42b8-a2c9-009600d732c0", + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs in any team, without a signed-in user.", + "displayName": "Allow the Teams app to manage only its own tabs for all teams", + "id": "91c32b81-0ef0-453f-a5c7-4ce2e562f449", "origin": "Application (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForTeam.All" + "value": "TeamsTab.ReadWriteSelfForTeam.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any user account, without a signed-in user, and manage its permission grants for accessing those specific users' data.", - "displayName": "Allow the Teams app to manage itself and its permission grants in all user accounts", - "id": "a87076cf-6abd-4e56-8559-4dbdf41bef96", + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for any user, without a signed-in user.", + "displayName": "Allow the Teams app to manage only its own tabs for all users", + "id": "3c42dec6-49e8-4a0a-b469-36cff0d9da93", "origin": "Application (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForUser.All" + "value": "TeamsTab.ReadWriteSelfForUser.All" }, { "description": "Allows the app to read your tenant's acquired telephone number details, without a signed-in user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", @@ -14868,46 +14931,46 @@ "value": "TeamworkTag.Read.All" }, { - "description": "Allows the app to read and write tags in Teams without a signed-in user.", - "displayName": "Read and write tags in Teams", - "id": "a3371ca5-911d-46d6-901c-42c8c7a937d8", + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for any chat, without a signed-in user.", + "displayName": "Allow the Teams app to manage only its own tabs for all chats", + "id": "9f62e4a2-a2d6-4350-b28b-d244728c4f86", "origin": "Application (Microsoft Graph)", - "value": "TeamworkTag.ReadWrite.All" + "value": "TeamsTab.ReadWriteSelfForChat.All" }, { - "description": "Allows the app to read all group chat or channel targeted messages in Microsoft Teams.", - "displayName": "Read all targeted messages of group chat or channel", - "id": "b0cfd829-be18-4b31-bb0e-ec1df8197ba3", + "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs for any user, without a signed-in user.", + "displayName": "Allow the app to manage all tabs for all users", + "id": "425b4b59-d5af-45c8-832f-bb0b7402348a", "origin": "Application (Microsoft Graph)", - "value": "TeamworkTargetedMessage.Read.All" + "value": "TeamsTab.ReadWriteForUser.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for any user, without a signed-in user.", - "displayName": "Allow the Teams app to manage only its own tabs for all users", - "id": "3c42dec6-49e8-4a0a-b469-36cff0d9da93", + "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs in any team, without a signed-in user.", + "displayName": "Allow the Teams app to manage all tabs for all teams", + "id": "6163d4f4-fbf8-43da-a7b4-060fe85ed148", "origin": "Application (Microsoft Graph)", - "value": "TeamsTab.ReadWriteSelfForUser.All" + "value": "TeamsTab.ReadWriteForTeam.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs in any team, without a signed-in user.", - "displayName": "Allow the Teams app to manage only its own tabs for all teams", - "id": "91c32b81-0ef0-453f-a5c7-4ce2e562f449", + "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs for any chat, without a signed-in user.", + "displayName": "Allow the Teams app to manage all tabs for all chats", + "id": "fd9ce730-a250-40dc-bd44-8dc8d20f39ea", "origin": "Application (Microsoft Graph)", - "value": "TeamsTab.ReadWriteSelfForTeam.All" + "value": "TeamsTab.ReadWriteForChat.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for any chat, without a signed-in user.", - "displayName": "Allow the Teams app to manage only its own tabs for all chats", - "id": "9f62e4a2-a2d6-4350-b28b-d244728c4f86", + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any team, without a signed-in user, and manage its permission grants for accessing those specific teams' data.", + "displayName": "Allow the Teams app to manage itself and its permission grants for all teams", + "id": "1e4be56c-312e-42b8-a2c9-009600d732c0", "origin": "Application (Microsoft Graph)", - "value": "TeamsTab.ReadWriteSelfForChat.All" + "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForTeam.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs for any user, without a signed-in user.", - "displayName": "Allow the app to manage all tabs for all users", - "id": "425b4b59-d5af-45c8-832f-bb0b7402348a", + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any user account, without a signed-in user, and manage its permission grants for accessing those specific users' data.", + "displayName": "Allow the Teams app to manage itself and its permission grants in all user accounts", + "id": "a87076cf-6abd-4e56-8559-4dbdf41bef96", "origin": "Application (Microsoft Graph)", - "value": "TeamsTab.ReadWriteForUser.All" + "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForUser.All" }, { "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any chat, without a signed-in user. Does not give the ability to read application-specific settings.", @@ -14951,6 +15014,13 @@ "origin": "Application (Microsoft Graph)", "value": "TeamsAppInstallation.ReadWriteSelectedForUser.All" }, + { + "description": "Allows the app to read all group chat or channel targeted messages in Microsoft Teams.", + "displayName": "Read all targeted messages of group chat or channel", + "id": "b0cfd829-be18-4b31-bb0e-ec1df8197ba3", + "origin": "Application (Microsoft Graph)", + "value": "TeamworkTargetedMessage.Read.All" + }, { "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any chat, without a signed-in user.", "displayName": "Allow the Teams app to manage itself for all chats", @@ -14958,20 +15028,6 @@ "origin": "Application (Microsoft Graph)", "value": "TeamsAppInstallation.ReadWriteSelfForChat.All" }, - { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in any team, without a signed-in user.", - "displayName": "Allow the Teams app to manage itself for all teams", - "id": "9f67436c-5415-4e7f-8ac1-3014a7132630", - "origin": "Application (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteSelfForTeam.All" - }, - { - "description": "Allows the application to list and read all Tenant Governance policy templates without a signed-in user.", - "displayName": "Read Tenant Governance policy templates", - "id": "eb9465d8-e7c0-4301-8e51-927f34ee3134", - "origin": "Application (Microsoft Graph)", - "value": "TenantGovernance-PolicyTemplate.Read.All" - }, { "description": "Allows a Teams app to read, install, upgrade, and uninstall itself to any user, without a signed-in user.", "displayName": "Allow the app to manage itself for all users", @@ -14979,6 +15035,13 @@ "origin": "Application (Microsoft Graph)", "value": "TeamsAppInstallation.ReadWriteSelfForUser.All" }, + { + "description": "Read all team's settings, without a signed-in user.", + "displayName": "Read all teams' settings", + "id": "242607bd-1d2c-432c-82eb-bdb27baa23ab", + "origin": "Application (Microsoft Graph)", + "value": "TeamSettings.Read.All" + }, { "description": "Read and change all teams' settings, without a signed-in user.", "displayName": "Read and change all teams' settings", @@ -15016,38 +15079,31 @@ }, { "description": "Read and write tabs in any team in Microsoft Teams, without a signed-in user. This does not give access to the content inside the tabs.", - "displayName": "Read and write tabs in Microsoft Teams.", - "id": "a96d855f-016b-47d7-b51c-1218a98d791c", - "origin": "Application (Microsoft Graph)", - "value": "TeamsTab.ReadWrite.All" - }, - { - "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs for any chat, without a signed-in user.", - "displayName": "Allow the Teams app to manage all tabs for all chats", - "id": "fd9ce730-a250-40dc-bd44-8dc8d20f39ea", + "displayName": "Read and write tabs in Microsoft Teams.", + "id": "a96d855f-016b-47d7-b51c-1218a98d791c", "origin": "Application (Microsoft Graph)", - "value": "TeamsTab.ReadWriteForChat.All" + "value": "TeamsTab.ReadWrite.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs in any team, without a signed-in user.", - "displayName": "Allow the Teams app to manage all tabs for all teams", - "id": "6163d4f4-fbf8-43da-a7b4-060fe85ed148", + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in any team, without a signed-in user.", + "displayName": "Allow the Teams app to manage itself for all teams", + "id": "9f67436c-5415-4e7f-8ac1-3014a7132630", "origin": "Application (Microsoft Graph)", - "value": "TeamsTab.ReadWriteForTeam.All" + "value": "TeamsAppInstallation.ReadWriteSelfForTeam.All" }, { - "description": "Read all team's settings, without a signed-in user.", - "displayName": "Read all teams' settings", - "id": "242607bd-1d2c-432c-82eb-bdb27baa23ab", + "description": "Allows the application to read and write virtual appointments for all users, without a signed-in user. The app must also be authorized to access an individual user’s data by the online meetings application access policy.", + "displayName": "Read-write all virtual appointments for users, as authorized by online meetings app access policy", + "id": "bf46a256-f47d-448f-ab78-f226fff08d40", "origin": "Application (Microsoft Graph)", - "value": "TeamSettings.Read.All" + "value": "VirtualAppointment.ReadWrite.All" }, { - "description": "Allows the app to read your organization's sign-in identifiers, without a signed-in user.", - "displayName": "Read all sign-in identifiers", - "id": "28e1fe78-598f-4df4-b55e-18bf34218925", + "description": "Allows the application to send notification regarding virtual appointments as any user, without a signed-in user. The app must also be authorized to access an individual user's data by the online meetings application access policy.", + "displayName": "Send notification regarding virtual appointments as any user", + "id": "97e45b36-1250-48e4-bd70-2df6dab7e94a", "origin": "Application (Microsoft Graph)", - "value": "SignInIdentifier.Read.All" + "value": "VirtualAppointmentNotification.Send" }, { "description": "Allows the app to read all virtual events without a signed-in user.", @@ -15057,11 +15113,11 @@ "value": "VirtualEvent.Read.All" }, { - "description": "Allows the app to read all Windows update deployment settings for the organization without a signed-in user.", - "displayName": "Read all Windows update deployment settings", - "id": "50a8bf5f-b06a-4ac7-881f-3ca0c4be7550", - "origin": "Application (Microsoft Graph)", - "value": "WindowsUpdates.Read.All" + "description": "Allows the app to read events in user calendars, except for properties such as body, attachments, and extensions.", + "displayName": "Read basic details of user calendars", + "id": "662d75ba-a364-42ad-adee-f5f880ea4878", + "origin": "Delegated (Microsoft Graph)", + "value": "Calendars.ReadBasic" }, { "description": "Allows the app to create, read, update, and delete events in user calendars.", @@ -15175,6 +15231,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "ChannelMember.ReadWrite.All" }, + { + "description": "Allows the app to read events in all calendars that the user can access, including delegate and shared calendars.", + "displayName": "Read user and shared calendars", + "id": "2b9c4092-424d-4249-948d-b43879977640", + "origin": "Delegated (Microsoft Graph)", + "value": "Calendars.Read.Shared" + }, { "description": "Allows an app to edit channel messages in Microsoft Teams, on behalf of the signed-in user.", "displayName": "Edit user's channel messages", @@ -15183,32 +15246,25 @@ "value": "ChannelMessage.Edit" }, { - "description": "Allows the app to read events in user calendars, except for properties such as body, attachments, and extensions.", - "displayName": "Read basic details of user calendars", - "id": "662d75ba-a364-42ad-adee-f5f880ea4878", - "origin": "Delegated (Microsoft Graph)", - "value": "Calendars.ReadBasic" - }, - { - "description": "Allows an app to read a channel's messages in Microsoft Teams, on behalf of the signed-in user.", - "displayName": "Read user channel messages", - "id": "767156cb-16ae-4d10-8f8b-41b657c8c8c8", + "description": "Allows the app to read events in user calendars.", + "displayName": "Read user calendars ", + "id": "465a38f9-76ea-45b9-9f34-9e8b0d4b0b42", "origin": "Delegated (Microsoft Graph)", - "value": "ChannelMessage.Read.All" + "value": "Calendars.Read" }, { - "description": "Allows the app to read events in all calendars that the user can access, including delegate and shared calendars.", - "displayName": "Read user and shared calendars", - "id": "2b9c4092-424d-4249-948d-b43879977640", + "description": "Allows the app to read all data associated with the business scenarios it owns. Data access will be attributed to the signed-in user.", + "displayName": "Read all data for business scenarios this app creates or owns", + "id": "25b265c4-5d34-4e44-952d-b567f6d3b96d", "origin": "Delegated (Microsoft Graph)", - "value": "Calendars.Read.Shared" + "value": "BusinessScenarioData.Read.OwnedBy" }, { - "description": "Allows the app to fully manage all data associated with the business scenarios it owns. Data access and changes will be attributed to the signed-in user.", - "displayName": "Read and write all data for business scenarios this app creates or owns", - "id": "19932d57-2952-4c60-8634-3655c79fc527", + "description": "Allows the app to read restore sessions, on behalf of the signed in user.", + "displayName": "Read restore sessions", + "id": "94b36f78-434f-4904-8c08-421d9a9c1dc2", "origin": "Delegated (Microsoft Graph)", - "value": "BusinessScenarioData.ReadWrite.OwnedBy" + "value": "BackupRestore-Restore.Read.All" }, { "description": "Allows the app to search the backup snapshots for Microsoft 365 resources, and restore Microsoft 365 resources from a backed-up snapshot, on behalf of the signed in user.", @@ -15323,18 +15379,18 @@ "value": "BusinessScenarioConfig.ReadWrite.OwnedBy" }, { - "description": "Allows the app to read all data associated with the business scenarios it owns. Data access will be attributed to the signed-in user.", - "displayName": "Read all data for business scenarios this app creates or owns", - "id": "25b265c4-5d34-4e44-952d-b567f6d3b96d", + "description": "Allows the app to fully manage all data associated with the business scenarios it owns. Data access and changes will be attributed to the signed-in user.", + "displayName": "Read and write all data for business scenarios this app creates or owns", + "id": "19932d57-2952-4c60-8634-3655c79fc527", "origin": "Delegated (Microsoft Graph)", - "value": "BusinessScenarioData.Read.OwnedBy" + "value": "BusinessScenarioData.ReadWrite.OwnedBy" }, { - "description": "Allows the app to read events in user calendars.", - "displayName": "Read user calendars ", - "id": "465a38f9-76ea-45b9-9f34-9e8b0d4b0b42", + "description": "Allows an app to read a channel's messages in Microsoft Teams, on behalf of the signed-in user.", + "displayName": "Read user channel messages", + "id": "767156cb-16ae-4d10-8f8b-41b657c8c8c8", "origin": "Delegated (Microsoft Graph)", - "value": "Calendars.Read" + "value": "ChannelMessage.Read.All" }, { "description": "Allows the app to read and write channel messages, on behalf of the signed-in user. This doesn't allow the app to edit the policyViolation of a channel message.", @@ -15351,11 +15407,11 @@ "value": "ChannelMessage.Send" }, { - "description": "Read all channel names, channel descriptions, and channel settings, on behalf of the signed-in user.", - "displayName": "Read the names, descriptions, and settings of channels", - "id": "233e0cf1-dd62-48bc-b65b-b38fe87fcf8e", + "description": "Allows the app to read and approve consent requests on behalf of the signed in user.", + "displayName": "Read and approve consent requests", + "id": "e694a3a1-7878-46d8-8c29-3d195f6589f4", "origin": "Delegated (Microsoft Graph)", - "value": "ChannelSettings.Read.All" + "value": "ConsentRequest.ReadApprove.All" }, { "description": "Allows the app to read app consent requests and approvals, and deny or approve those requests on behalf of the signed-in user.", @@ -15469,20 +15525,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "CopilotPolicySettings.ReadWrite" }, - { - "description": "Allows the app to read organization-wide copilot limited mode setting on behalf of the signed-in user.", - "displayName": "Read organization-wide copilot limited mode setting", - "id": "aeb2982d-632d-4155-b533-18756ab6fdd8", - "origin": "Delegated (Microsoft Graph)", - "value": "CopilotSettings-LimitedMode.Read" - }, - { - "description": "Allows the app to read and approve consent requests on behalf of the signed in user.", - "displayName": "Read and approve consent requests", - "id": "e694a3a1-7878-46d8-8c29-3d195f6589f4", - "origin": "Delegated (Microsoft Graph)", - "value": "ConsentRequest.ReadApprove.All" - }, { "description": "Allows the app to read consent requests and approvals on behalf of the signed-in user.", "displayName": "Read consent requests", @@ -15504,6 +15546,20 @@ "origin": "Delegated (Microsoft Graph)", "value": "ConsentRequest.Create" }, + { + "description": "Allows the app to read and write all Configuration Monitoring entities on behalf of the signed-in user.", + "displayName": "Read and write all Configuration Monitoring entities", + "id": "54505ce9-e719-41f7-a7cc-dbe114e1d811", + "origin": "Delegated (Microsoft Graph)", + "value": "ConfigurationMonitoring.ReadWrite.All" + }, + { + "description": "Read all channel names, channel descriptions, and channel settings, on behalf of the signed-in user.", + "displayName": "Read the names, descriptions, and settings of channels", + "id": "233e0cf1-dd62-48bc-b65b-b38fe87fcf8e", + "origin": "Delegated (Microsoft Graph)", + "value": "ChannelSettings.Read.All" + }, { "description": "Read and write the names, descriptions, and settings of all channels, on behalf of the signed-in user.", "displayName": "Read and write the names, descriptions, and settings of channels", @@ -15553,6 +15609,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "Chat.ReadWrite.All" }, + { + "description": "Allows the app to monitor backup and restore jobs, view quota usage and billing details, on behalf of the signed in user.", + "displayName": "Read monitoring, quota and billing information for the tenant", + "id": "b4e98de1-4600-4e90-b5e1-7c1dfef04e5c", + "origin": "Delegated (Microsoft Graph)", + "value": "BackupRestore-Monitor.Read.All" + }, { "description": "Read the members of chats, on behalf of the signed-in user.", "displayName": "Read the members of chats", @@ -15561,18 +15624,11 @@ "value": "ChatMember.Read" }, { - "description": "Allows the app to read restore sessions, on behalf of the signed in user.", - "displayName": "Read restore sessions", - "id": "94b36f78-434f-4904-8c08-421d9a9c1dc2", - "origin": "Delegated (Microsoft Graph)", - "value": "BackupRestore-Restore.Read.All" - }, - { - "description": "Add and remove members from chats, on behalf of the signed-in user.", - "displayName": "Add and remove members from chats", - "id": "dea13482-7ea6-488f-8b98-eb5bbecf033d", + "description": "Allows an app to read one-to-one and group chat messages, on behalf of the signed-in user.", + "displayName": "Read user chat messages", + "id": "cdcdac3a-fd45-410d-83ef-554db620e5c7", "origin": "Delegated (Microsoft Graph)", - "value": "ChatMember.ReadWrite" + "value": "ChatMessage.Read" }, { "description": "Allows an app to send one-to-one and group chat messages in Microsoft Teams, on behalf of the signed-in user.", @@ -15624,39 +15680,39 @@ "value": "ConfigurationMonitoring.Read.All" }, { - "description": "Allows the app to read and write all Configuration Monitoring entities on behalf of the signed-in user.", - "displayName": "Read and write all Configuration Monitoring entities", - "id": "54505ce9-e719-41f7-a7cc-dbe114e1d811", + "description": "Add and remove members from chats, on behalf of the signed-in user.", + "displayName": "Add and remove members from chats", + "id": "dea13482-7ea6-488f-8b98-eb5bbecf033d", "origin": "Delegated (Microsoft Graph)", - "value": "ConfigurationMonitoring.ReadWrite.All" + "value": "ChatMember.ReadWrite" }, { - "description": "Allows an app to read one-to-one and group chat messages, on behalf of the signed-in user.", - "displayName": "Read user chat messages", - "id": "cdcdac3a-fd45-410d-83ef-554db620e5c7", + "description": "Allows the app to update or read the status of M365 backup service (enable/disable), on behalf of the signed in user.", + "displayName": "Update or read the status of the M365 backup service", + "id": "96d46335-d92d-41b8-bc9f-273a692381ea", "origin": "Delegated (Microsoft Graph)", - "value": "ChatMessage.Read" + "value": "BackupRestore-Control.ReadWrite.All" }, { - "description": "Allows the app to read and write anonymous users' virtual event registrations, without a signed-in user", - "displayName": "Read and write anonymous users' virtual event registrations", - "id": "23211fc1-f9d1-4e8e-8e9e-08a5d0a109bb", - "origin": "Application (Microsoft Graph)", - "value": "VirtualEventRegistration-Anon.ReadWrite.All" + "description": "Allows the app to read the status of M365 backup service (enable/disable), on behalf of the signed in user.", + "displayName": "Read the status of the M365 backup service", + "id": "af598c63-4292-4437-b925-e996354d3854", + "origin": "Delegated (Microsoft Graph)", + "value": "BackupRestore-Control.Read.All" }, { - "description": "Allows the app to monitor backup and restore jobs, view quota usage and billing details, on behalf of the signed in user.", - "displayName": "Read monitoring, quota and billing information for the tenant", - "id": "b4e98de1-4600-4e90-b5e1-7c1dfef04e5c", + "description": "Allows the app to read and update the backup configuration, and list of Microsoft 365 service resources to be backed-up, on behalf of the signed in user.", + "displayName": "Read and edit backup configuration policies", + "id": "a0244d16-171c-4496-8ffb-7b9b6954d339", "origin": "Delegated (Microsoft Graph)", - "value": "BackupRestore-Monitor.Read.All" + "value": "BackupRestore-Configuration.ReadWrite.All" }, { - "description": "Allows the app to read the status of M365 backup service (enable/disable), on behalf of the signed in user.", - "displayName": "Read the status of the M365 backup service", - "id": "af598c63-4292-4437-b925-e996354d3854", + "description": "Allows the app to read and update the communication configuration of agent blueprints on behalf of the signed-in user.", + "displayName": "Read and write agent communication configuration", + "id": "15e0db35-0641-4175-b014-c2cb39286338", "origin": "Delegated (Microsoft Graph)", - "value": "BackupRestore-Control.Read.All" + "value": "AgentCommunicationConfiguration.ReadWrite" }, { "description": "Allows the client to create agent identities on behalf of the signed-in user, even if the client is not the parent agent identity blueprint.", @@ -15770,27 +15826,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "AgentIdentityBlueprintPrincipal.Read.All" }, - { - "description": "Allows the app to read, update, create, and delete agent identity blueprint principals on behalf of the signed-in user.", - "displayName": "Read and write all agent identity blueprint principals.", - "id": "bf2cad6a-9082-438a-9a63-95fa2687af65", - "origin": "Delegated (Microsoft Graph)", - "value": "AgentIdentityBlueprintPrincipal.ReadWrite.All" - }, - { - "description": "Allows the app to read and update the communication configuration of agent blueprints on behalf of the signed-in user.", - "displayName": "Read and write agent communication configuration", - "id": "15e0db35-0641-4175-b014-c2cb39286338", - "origin": "Delegated (Microsoft Graph)", - "value": "AgentCommunicationConfiguration.ReadWrite" - }, - { - "description": "Allows the app to create agent users, read and write the full set of profile properties, reports, and managers of agent ID users, delete and restore agent users in your organization, and read basic company properties, on behalf of the signed-in user.", - "displayName": "Read and write all agent ID users' full profiles", - "id": "ad57fb88-4658-4fd6-ab7d-e43184b08e4e", - "origin": "Delegated (Microsoft Graph)", - "value": "AgentIdUser.ReadWrite.All" - }, { "description": "Allows the app to read the communication configuration of agent blueprints on behalf of the signed-in user.", "displayName": "Read agent communication configuration", @@ -15798,6 +15833,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "AgentCommunicationConfiguration.Read" }, + { + "description": "Allows the app to read and update quarantined collection and manage its membership in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read and write quarantined collection in Agent Registry", + "id": "ae331cc9-9f51-484b-a90b-124f2e4a6398", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCollection.ReadWrite.Quarantined" + }, { "description": "Allows the app to read and update global collection and manage its membership in your organization's Agent Registry on behalf of the signed-in user.", "displayName": "Read and write global collection in Agent Registry", @@ -15805,6 +15847,27 @@ "origin": "Delegated (Microsoft Graph)", "value": "AgentCollection.ReadWrite.Global" }, + { + "description": "Allows the app to create, read, update, and delete collections and manage their membership in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read and write collections in Agent Registry, except quarantined and global", + "id": "6d8a7002-a05e-4b95-a768-0e6f0badc6c8", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCollection.ReadWrite.All" + }, + { + "description": "Allows the app to read and write anonymous users' virtual event registrations, without a signed-in user", + "displayName": "Read and write anonymous users' virtual event registrations", + "id": "23211fc1-f9d1-4e8e-8e9e-08a5d0a109bb", + "origin": "Application (Microsoft Graph)", + "value": "VirtualEventRegistration-Anon.ReadWrite.All" + }, + { + "description": "Allows the app to read all Windows update deployment settings for the organization without a signed-in user.", + "displayName": "Read all Windows update deployment settings", + "id": "50a8bf5f-b06a-4ac7-881f-3ca0c4be7550", + "origin": "Application (Microsoft Graph)", + "value": "WindowsUpdates.Read.All" + }, { "description": "Allows the app to read and write all Windows update deployment settings for the organization without a signed-in user.", "displayName": "Read and write all Windows update deployment settings", @@ -15848,18 +15911,18 @@ "value": "AccessReview.ReadWrite.Membership" }, { - "description": "Allows an app to read all acronyms that the signed-in user can access.", - "displayName": "Read all acronyms that the user can access", - "id": "9084c10f-a2d6-4713-8732-348def50fe02", + "description": "Allows the app to read, update, create, and delete agent identity blueprint principals on behalf of the signed-in user.", + "displayName": "Read and write all agent identity blueprint principals.", + "id": "bf2cad6a-9082-438a-9a63-95fa2687af65", "origin": "Delegated (Microsoft Graph)", - "value": "Acronym.Read.All" + "value": "AgentIdentityBlueprintPrincipal.ReadWrite.All" }, { - "description": "Allows the app to read administrative units and administrative unit membership on behalf of the signed-in user.", - "displayName": "Read administrative units", - "id": "3361d15d-be43-4de6-b441-3c746d05163d", + "description": "Allows an app to read all acronyms that the signed-in user can access.", + "displayName": "Read all acronyms that the user can access", + "id": "9084c10f-a2d6-4713-8732-348def50fe02", "origin": "Delegated (Microsoft Graph)", - "value": "AdministrativeUnit.Read.All" + "value": "Acronym.Read.All" }, { "description": "Allows the app to create, read, update, and delete administrative units and manage administrative unit membership on behalf of the signed-in user.", @@ -15918,25 +15981,25 @@ "value": "AgentCollection.Read.Quarantined" }, { - "description": "Allows the app to create, read, update, and delete collections and manage their membership in your organization's Agent Registry on behalf of the signed-in user.", - "displayName": "Read and write collections in Agent Registry, except quarantined and global", - "id": "6d8a7002-a05e-4b95-a768-0e6f0badc6c8", + "description": "Allows the app to read administrative units and administrative unit membership on behalf of the signed-in user.", + "displayName": "Read administrative units", + "id": "3361d15d-be43-4de6-b441-3c746d05163d", "origin": "Delegated (Microsoft Graph)", - "value": "AgentCollection.ReadWrite.All" + "value": "AdministrativeUnit.Read.All" }, { - "description": "Allows the app to read and update quarantined collection and manage its membership in your organization's Agent Registry on behalf of the signed-in user.", - "displayName": "Read and write quarantined collection in Agent Registry", - "id": "ae331cc9-9f51-484b-a90b-124f2e4a6398", - "origin": "Delegated (Microsoft Graph)", - "value": "AgentCollection.ReadWrite.Quarantined" + "description": "Allows the app to read all the short notes without a signed-in user.", + "displayName": "Read all users' short notes", + "id": "0c7d31ec-31ca-4f58-b6ec-9950b6b0de69", + "origin": "Application (Microsoft Graph)", + "value": "ShortNotes.Read.All" }, { - "description": "Allows the app to create agent users, read and write the full set of profile properties, reports, and managers of agent ID users in your organization, delete and restore agent users under an agent blueprint, and read basic company properties, on behalf of the signed-in user.", - "displayName": "Read and write full profiles of agent ID users under an agent blueprint", - "id": "52a417d9-0b3c-4466-9a3b-66960de73d74", + "description": "Allows the app to create agent users, read and write the full set of profile properties, reports, and managers of agent ID users, delete and restore agent users in your organization, and read basic company properties, on behalf of the signed-in user.", + "displayName": "Read and write all agent ID users' full profiles", + "id": "ad57fb88-4658-4fd6-ab7d-e43184b08e4e", "origin": "Delegated (Microsoft Graph)", - "value": "AgentIdUser.ReadWrite.IdentityParentedBy" + "value": "AgentIdUser.ReadWrite.All" }, { "description": "Allows the app to read agent instances and their related collections in your organization's Agent Registry on behalf of the signed-in user.", @@ -15946,11 +16009,11 @@ "value": "AgentInstance.Read.All" }, { - "description": "Allows the app to create, read, update, and delete agent instances in your organization's Agent Registry on behalf of the signed-in user.", - "displayName": "Read and write agent instances in Agent Registry", - "id": "fc79e324-da24-497a-b5ec-e7de08320375", + "description": "Allows the app to provision, read, create, and respond to approvals on behalf of the signed-in user.", + "displayName": "Read, create, and respond to approvals", + "id": "6768d3af-4562-48ff-82d2-c5e19eb21b9c", "origin": "Delegated (Microsoft Graph)", - "value": "AgentInstance.ReadWrite.All" + "value": "ApprovalSolution.ReadWrite" }, { "description": "Allows the app to read and respond to approvals on behalf of the signed-in user.", @@ -16064,20 +16127,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "BackupRestore-Configuration.Read.All" }, - { - "description": "Allows the app to read and update the backup configuration, and list of Microsoft 365 service resources to be backed-up, on behalf of the signed in user.", - "displayName": "Read and edit backup configuration policies", - "id": "a0244d16-171c-4496-8ffb-7b9b6954d339", - "origin": "Delegated (Microsoft Graph)", - "value": "BackupRestore-Configuration.ReadWrite.All" - }, - { - "description": "Allows the app to provision, read, create, and respond to approvals on behalf of the signed-in user.", - "displayName": "Read, create, and respond to approvals", - "id": "6768d3af-4562-48ff-82d2-c5e19eb21b9c", - "origin": "Delegated (Microsoft Graph)", - "value": "ApprovalSolution.ReadWrite" - }, { "description": "Allows the app to read approvals on behalf of the signed-in user.", "displayName": "Read approvals", @@ -16099,6 +16148,20 @@ "origin": "Delegated (Microsoft Graph)", "value": "Application-RemoteDesktopConfig.ReadWrite.All" }, + { + "description": "Allows the app to create, read, update and delete applications and service principals on behalf of the signed-in user. Allows management of app role assignments, except those exposed by Microsoft Graph. Does not allow management of delegated permission grants.", + "displayName": "Read and write applications", + "id": "bdfbf15f-ee85-4955-8675-146e8e5296b5", + "origin": "Delegated (Microsoft Graph)", + "value": "Application.ReadWrite.All" + }, + { + "description": "Allows the app to create, read, update, and delete agent instances in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read and write agent instances in Agent Registry", + "id": "fc79e324-da24-497a-b5ec-e7de08320375", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentInstance.ReadWrite.All" + }, { "description": "Allows the user to read all agent registration information", "displayName": "Read all agent registrations", @@ -16148,6 +16211,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "AiEnterpriseInteraction.Read" }, + { + "description": "Allows the app to create agent users, read and write the full set of profile properties, reports, and managers of agent ID users in your organization, delete and restore agent users under an agent blueprint, and read basic company properties, on behalf of the signed-in user.", + "displayName": "Read and write full profiles of agent ID users under an agent blueprint", + "id": "52a417d9-0b3c-4466-9a3b-66960de73d74", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdUser.ReadWrite.IdentityParentedBy" + }, { "description": "Allows the app to read the signed-in user's activity statistics, such as how much time the user has spent on emails, in meetings, or in chat sessions.", "displayName": "Read user activity statistics", @@ -16156,18 +16226,11 @@ "value": "Analytics.Read" }, { - "description": "Allows the app to update or read the status of M365 backup service (enable/disable), on behalf of the signed in user.", - "displayName": "Update or read the status of the M365 backup service", - "id": "96d46335-d92d-41b8-bc9f-273a692381ea", - "origin": "Delegated (Microsoft Graph)", - "value": "BackupRestore-Control.ReadWrite.All" - }, - { - "description": "Allows the app to read the API connectors used in user authentication flows, on behalf of the signed-in user.", - "displayName": "Read API connectors for authentication flows", - "id": "1b6ff35f-31df-4332-8571-d31ea5a4893f", + "description": "Allows the app to read, create and manage the API connectors used in user authentication flows, on behalf of the signed-in user.", + "displayName": "Read and write API connectors for authentication flows", + "id": "c67b52c5-7c69-48b6-9d48-7b3af3ded914", "origin": "Delegated (Microsoft Graph)", - "value": "APIConnectors.Read.All" + "value": "APIConnectors.ReadWrite.All" }, { "description": "Allows the app to read the apps in the app catalogs.", @@ -16219,39 +16282,53 @@ "value": "Application.ReadUpdate.All" }, { - "description": "Allows the app to create, read, update and delete applications and service principals on behalf of the signed-in user. Allows management of app role assignments, except those exposed by Microsoft Graph. Does not allow management of delegated permission grants.", - "displayName": "Read and write applications", - "id": "bdfbf15f-ee85-4955-8675-146e8e5296b5", + "description": "Allows the app to read the API connectors used in user authentication flows, on behalf of the signed-in user.", + "displayName": "Read API connectors for authentication flows", + "id": "1b6ff35f-31df-4332-8571-d31ea5a4893f", "origin": "Delegated (Microsoft Graph)", - "value": "Application.ReadWrite.All" + "value": "APIConnectors.Read.All" }, { - "description": "Allows the app to read, create and manage the API connectors used in user authentication flows, on behalf of the signed-in user.", - "displayName": "Read and write API connectors for authentication flows", - "id": "c67b52c5-7c69-48b6-9d48-7b3af3ded914", - "origin": "Delegated (Microsoft Graph)", - "value": "APIConnectors.ReadWrite.All" + "description": "Allows the application to read and change the tenant-level settings of SharePoint and OneDrive, without a signed-in user.", + "displayName": "Read and change SharePoint and OneDrive tenant settings", + "id": "19b94e34-907c-4f43-bde9-38b1909ed408", + "origin": "Application (Microsoft Graph)", + "value": "SharePointTenantSettings.ReadWrite.All" }, { - "description": "Allows the app to read eDiscovery objects such as cases, custodians, review sets and other related objects without a signed-in user.", - "displayName": "Read all eDiscovery objects", - "id": "50180013-6191-4d1e-a373-e590ff4e66af", + "description": "Allows the application to read the tenant-level settings of SharePoint and OneDrive, without a signed-in user.", + "displayName": "Read SharePoint and OneDrive tenant settings", + "id": "83d4163d-a2d8-4d3b-9695-4ae3ca98f888", "origin": "Application (Microsoft Graph)", - "value": "eDiscovery.Read.All" + "value": "SharePointTenantSettings.Read.All" }, { - "description": "Allows the app to read, create, edit, and delete all the short notes without a signed-in user.", - "displayName": "Read, create, edit, and delete all users' short notes", - "id": "842c284c-763d-4a97-838d-79787d129bab", + "description": "Allows the app to read your tenant's SharePoint Cross-Tenant migration settings and tasks, without a signed-in user.", + "displayName": "Read SharePoint Cross-Tenant migration settings and tasks", + "id": "f5fa52a5-b9ab-4dc3-885e-9e5b4a67068e", "origin": "Application (Microsoft Graph)", - "value": "ShortNotes.ReadWrite.All" + "value": "SharePointCrossTenantMigration.Read.All" }, { - "description": "Allows the application to read and change the tenant-level settings of SharePoint and OneDrive, without a signed-in user.", - "displayName": "Read and change SharePoint and OneDrive tenant settings", - "id": "19b94e34-907c-4f43-bde9-38b1909ed408", + "description": "Allows an app to manage license assignments for users and groups, without a signed-in user.", + "displayName": "Manage all license assignments", + "id": "5facf0c1-8979-4e95-abcf-ff3d079771c0", "origin": "Application (Microsoft Graph)", - "value": "SharePointTenantSettings.ReadWrite.All" + "value": "LicenseAssignment.ReadWrite.All" + }, + { + "description": "Allows the app to read identity lifecycle policies for agent identities in the organization, without a signed-in user.", + "displayName": "Read identity lifecycle policies for agent identities", + "id": "6343d63f-034f-45b5-832d-9f9d7632e182", + "origin": "Application (Microsoft Graph)", + "value": "LifecyclePolicies-AgentId.Read.All" + }, + { + "description": "Allows the app to read, create, update and delete identity lifecycle policies for agent identities in the organization, without a signed-in user.", + "displayName": "Read and write identity lifecycle policies for agent identities", + "id": "00d1c504-8dc7-461b-8a0b-dc15c8f1bd5a", + "origin": "Application (Microsoft Graph)", + "value": "LifecyclePolicies-AgentId.ReadWrite.All" }, { "description": "Allows the app to list and read all workflows, tasks and related lifecycle workflows resources without a signed-in user.", @@ -16345,39 +16422,46 @@ "value": "Mail.ReadBasic.All" }, { - "description": "Allows the app to create, read, update, and delete all email, including contents of non-draft emails in user mailboxes, without a signed-in user. Does not include permission to send mail.", - "displayName": "Read and write mail in all mailboxes, including modifying existing non-draft mails", - "id": "e118f1da-5c1c-46cf-bff6-8858d786f46f", + "description": "Allows an app to read license assignments for users and groups, without a signed-in user.", + "displayName": "Read all license assignments.", + "id": "e2f98668-2877-4f38-a2f4-8202e0717aa1", "origin": "Application (Microsoft Graph)", - "value": "Mail-Advanced.ReadWrite.All" + "value": "LicenseAssignment.Read.All" }, { - "description": "Allows the app to read, create, update and delete identity lifecycle policies for agent identities in the organization, without a signed-in user.", - "displayName": "Read and write identity lifecycle policies for agent identities", - "id": "00d1c504-8dc7-461b-8a0b-dc15c8f1bd5a", + "description": "Allows the app to create, update, read and delete all self-initiated courses in the organization's directory, without a signed-in user.", + "displayName": "Read and write all self-initiated courses", + "id": "7654ed61-8965-4025-846a-0856ec02b5b0", "origin": "Application (Microsoft Graph)", - "value": "LifecyclePolicies-AgentId.ReadWrite.All" + "value": "LearningSelfInitiatedCourse.ReadWrite.All" }, { - "description": "Allows the app to read all users' UserConfiguration objects.", - "displayName": "Read all users' UserConfiguration objects", - "id": "27d9d776-f4d2-426d-80ad-5f22f2b01b0a", + "description": "Allows the app to manage all learning content in the organization's directory, without a signed-in user.", + "displayName": "Manage all learning content", + "id": "444d6fcb-b738-41e5-b103-ac4f2a2628a3", "origin": "Application (Microsoft Graph)", - "value": "MailboxConfigItem.Read" + "value": "LearningContent.ReadWrite.All" }, { - "description": "Allows the app to read identity lifecycle policies for agent identities in the organization, without a signed-in user.", - "displayName": "Read identity lifecycle policies for agent identities", - "id": "6343d63f-034f-45b5-832d-9f9d7632e182", + "description": "Allows the app to read and write outbound data flows without a signed-in user.", + "displayName": "Manage outbound flow definitions", + "id": "24a65b4a-e501-47e2-8849-d679517887f0", "origin": "Application (Microsoft Graph)", - "value": "LifecyclePolicies-AgentId.Read.All" + "value": "IndustryData-OutboundFlow.ReadWrite.All" }, { - "description": "Allows an app to read license assignments for users and groups, without a signed-in user.", - "displayName": "Read all license assignments.", - "id": "e2f98668-2877-4f38-a2f4-8202e0717aa1", + "description": "Allows the app to read reference definitions without a signed-in user.", + "displayName": "View reference definitions", + "id": "6ee891c3-74a4-4148-8463-0c834375dfaf", "origin": "Application (Microsoft Graph)", - "value": "LicenseAssignment.Read.All" + "value": "IndustryData-ReferenceDefinition.Read.All" + }, + { + "description": "Allows the app to read and write reference definitions without a signed-in user.", + "displayName": "Manage reference definitions", + "id": "bda16293-63d3-45b7-b16b-833841d27d56", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-ReferenceDefinition.ReadWrite.All" }, { "description": "Allows the app to read current and previous IndustryData runs without a signed-in user.", @@ -16477,13 +16561,6 @@ "origin": "Application (Microsoft Graph)", "value": "LearningContent.Read.All" }, - { - "description": "Allows the app to manage all learning content in the organization's directory, without a signed-in user.", - "displayName": "Manage all learning content", - "id": "444d6fcb-b738-41e5-b103-ac4f2a2628a3", - "origin": "Application (Microsoft Graph)", - "value": "LearningContent.ReadWrite.All" - }, { "description": "Allows the app to read data for all self-initiated courses in the organization's directory, without a signed-in user.", "displayName": "Read all self-initiated courses", @@ -16492,39 +16569,39 @@ "value": "LearningSelfInitiatedCourse.Read.All" }, { - "description": "Allows the app to create, update, read and delete all self-initiated courses in the organization's directory, without a signed-in user.", - "displayName": "Read and write all self-initiated courses", - "id": "7654ed61-8965-4025-846a-0856ec02b5b0", + "description": "Allows the app to create, read, update, and delete all email, including contents of non-draft emails in user mailboxes, without a signed-in user. Does not include permission to send mail.", + "displayName": "Read and write mail in all mailboxes, including modifying existing non-draft mails", + "id": "e118f1da-5c1c-46cf-bff6-8858d786f46f", "origin": "Application (Microsoft Graph)", - "value": "LearningSelfInitiatedCourse.ReadWrite.All" + "value": "Mail-Advanced.ReadWrite.All" }, { - "description": "Allows an app to manage license assignments for users and groups, without a signed-in user.", - "displayName": "Manage all license assignments", - "id": "5facf0c1-8979-4e95-abcf-ff3d079771c0", + "description": "Allows the app to read all users' UserConfiguration objects.", + "displayName": "Read all users' UserConfiguration objects", + "id": "27d9d776-f4d2-426d-80ad-5f22f2b01b0a", "origin": "Application (Microsoft Graph)", - "value": "LicenseAssignment.ReadWrite.All" + "value": "MailboxConfigItem.Read" }, { - "description": "Allows the app to create, read, update and delete all users' UserConfiguration objects.", - "displayName": "Read and write all users' UserConfiguration objects", - "id": "aa6d92d4-b25a-4640-aefe-3e3231e5e736", + "description": "Allows the app to read all network access reports without a signed-in user.", + "displayName": "Read all network access reports", + "id": "40049381-3cc1-42af-94ec-5ce755db4b0d", "origin": "Application (Microsoft Graph)", - "value": "MailboxConfigItem.ReadWrite" + "value": "NetworkAccess-Reports.Read.All" }, { - "description": "Allows the app to read all the users' mailbox folders, without signed-in user.", - "displayName": "Read all the users' mailbox folders", - "id": "99280d24-a782-4793-93cc-0888549957f6", + "description": "Allows the app to read all the OneNote notebooks in your organization, without a signed-in user.", + "displayName": "Read all OneNote notebooks", + "id": "3aeca27b-ee3a-4c2b-8ded-80376e2134a4", "origin": "Application (Microsoft Graph)", - "value": "MailboxFolder.Read.All" + "value": "Notes.Read.All" }, { - "description": "Allows the app to read and write all the users' mailbox folders, without signed-in user.", - "displayName": "Read and write all the users' mailbox folders", - "id": "fef87b92-8391-4589-9da7-eb93dab7dc8a", + "description": "Allows the app to read all the OneNote notebooks in your organization, without a signed-in user.", + "displayName": "Read and write all OneNote notebooks", + "id": "0c458cef-11f3-48c2-a568-c66751c238c0", "origin": "Application (Microsoft Graph)", - "value": "MailboxFolder.ReadWrite.All" + "value": "Notes.ReadWrite.All" }, { "description": "Allows the app to read all AI Insights for all online meetings, without a signed-in user.", @@ -16625,53 +16702,53 @@ "value": "OrganizationalBranding.ReadWrite.All" }, { - "description": "Allows the app to read all organizational contacts without a signed-in user. These contacts are managed by the organization and are different from a user's personal contacts.", - "displayName": "Read organizational contacts", - "id": "e1a88a34-94c4-4418-be12-c87b00e26bea", + "description": "Allows the app to read and write your organization's network access policies, without a signed-in user.", + "displayName": "Read and write all security and routing policies for network access", + "id": "f0c341be-8348-4989-8e43-660324294538", "origin": "Application (Microsoft Graph)", - "value": "OrgContact.Read.All" + "value": "NetworkAccessPolicy.ReadWrite.All" }, { - "description": "Allows the app to read organization-wide apps and services settings, without a signed-in user.", - "displayName": "Read organization-wide apps and services settings", - "id": "56c84fa9-ea1f-4a15-90f2-90ef41ece2c9", + "description": "Allows the app to read your organization's network access policies, without a signed-in user.", + "displayName": "Read all security and routing policies for network access", + "id": "8a3d36bf-cb46-4bcc-bec9-8d92829dab84", "origin": "Application (Microsoft Graph)", - "value": "OrgSettings-AppsAndServices.Read.All" + "value": "NetworkAccessPolicy.Read.All" }, { - "description": "Allows the app to read and write organization-wide apps and services settings, without a signed-in user.", - "displayName": "Read and write organization-wide apps and services settings", - "id": "4a8e4191-c1c8-45f8-b801-f9a1a5ee6ad3", + "description": "Allows the app to read and write your organization's network access branches, without a signed-in user.", + "displayName": "Read and write properties of all branches for network access", + "id": "8137102d-ec16-4191-aaf8-7aeda8026183", "origin": "Application (Microsoft Graph)", - "value": "OrgSettings-AppsAndServices.ReadWrite.All" + "value": "NetworkAccessBranch.ReadWrite.All" }, { - "description": "Allows the app to read all the OneNote notebooks in your organization, without a signed-in user.", - "displayName": "Read and write all OneNote notebooks", - "id": "0c458cef-11f3-48c2-a568-c66751c238c0", + "description": "Allows the app to read your organization's network access branches, without a signed-in user.", + "displayName": "Read properties of all branches for network access", + "id": "39ae4a24-1ef0-49e8-9d63-2a66f5c39edd", "origin": "Application (Microsoft Graph)", - "value": "Notes.ReadWrite.All" + "value": "NetworkAccessBranch.Read.All" }, { - "description": "Allows the app to read all the OneNote notebooks in your organization, without a signed-in user.", - "displayName": "Read all OneNote notebooks", - "id": "3aeca27b-ee3a-4c2b-8ded-80376e2134a4", + "description": "Allows the app to create, read, update and delete all users' UserConfiguration objects.", + "displayName": "Read and write all users' UserConfiguration objects", + "id": "aa6d92d4-b25a-4640-aefe-3e3231e5e736", "origin": "Application (Microsoft Graph)", - "value": "Notes.Read.All" + "value": "MailboxConfigItem.ReadWrite" }, { - "description": "Allows the app to read all network access reports without a signed-in user.", - "displayName": "Read all network access reports", - "id": "40049381-3cc1-42af-94ec-5ce755db4b0d", + "description": "Allows the app to read all the users' mailbox folders, without signed-in user.", + "displayName": "Read all the users' mailbox folders", + "id": "99280d24-a782-4793-93cc-0888549957f6", "origin": "Application (Microsoft Graph)", - "value": "NetworkAccess-Reports.Read.All" + "value": "MailboxFolder.Read.All" }, { - "description": "Allows the app to read and write your organization's network access policies, without a signed-in user.", - "displayName": "Read and write all security and routing policies for network access", - "id": "f0c341be-8348-4989-8e43-660324294538", + "description": "Allows the app to read and write all the users' mailbox folders, without signed-in user.", + "displayName": "Read and write all the users' mailbox folders", + "id": "fef87b92-8391-4589-9da7-eb93dab7dc8a", "origin": "Application (Microsoft Graph)", - "value": "NetworkAccessPolicy.ReadWrite.All" + "value": "MailboxFolder.ReadWrite.All" }, { "description": "Allows the app to export all the users' mailbox items, without signed-in user.", @@ -16708,6 +16785,13 @@ "origin": "Application (Microsoft Graph)", "value": "MailboxSettings.Read" }, + { + "description": "Allows the app to read outbound data flows without a signed-in user.", + "displayName": "View outbound flow definitions", + "id": "61d0354c-5d88-483c-b974-a37ec3395a2c", + "origin": "Application (Microsoft Graph)", + "value": "IndustryData-OutboundFlow.Read.All" + }, { "description": "Allows the app to create, read, update, and delete user's mailbox settings without a signed-in user. Does not include permission to send mail.", "displayName": "Read and write all user mailbox settings", @@ -16715,13 +16799,6 @@ "origin": "Application (Microsoft Graph)", "value": "MailboxSettings.ReadWrite" }, - { - "description": "Allows the app to read mail tips for all users in the organization without a signed-in user. Mail tips include automatic replies, mailbox status, custom tips, and delivery information.", - "displayName": "Read mail tips for all users", - "id": "a2c9652d-4d7f-4e4e-9d75-ac32fdc6f413", - "origin": "Application (Microsoft Graph)", - "value": "MailTips.ReadBasic.All" - }, { "description": "Allows the app to read the memberships of hidden groups and administrative units without a signed-in user.", "displayName": "Read all hidden memberships", @@ -16729,13 +16806,6 @@ "origin": "Application (Microsoft Graph)", "value": "Member.Read.Hidden" }, - { - "description": "Allows the app to read and write reference definitions without a signed-in user.", - "displayName": "Manage reference definitions", - "id": "bda16293-63d3-45b7-b16b-833841d27d56", - "origin": "Application (Microsoft Graph)", - "value": "IndustryData-ReferenceDefinition.ReadWrite.All" - }, { "description": "Allows the app to read all multi-tenant organization details and tenants, without a signed-in user.", "displayName": "Read all multi-tenant organization details and tenants", @@ -16743,6 +16813,13 @@ "origin": "Application (Microsoft Graph)", "value": "MultiTenantOrganization.Read.All" }, + { + "description": "Allows the app to read multi-tenant organization basic details and active tenants, without a signed-in user.", + "displayName": "Read multi-tenant organization basic details and active tenants", + "id": "f9c2b2a7-3895-4b2e-80f6-c924b456e50b", + "origin": "Application (Microsoft Graph)", + "value": "MultiTenantOrganization.ReadBasic.All" + }, { "description": "Allows the app to read and write all multi-tenant organization details and tenants, without a signed-in user.", "displayName": "Read and write all multi-tenant organization details and tenants", @@ -16779,53 +16856,39 @@ "value": "NetworkAccess.ReadWrite.All" }, { - "description": "Allows the app to read your organization's network access branches, without a signed-in user.", - "displayName": "Read properties of all branches for network access", - "id": "39ae4a24-1ef0-49e8-9d63-2a66f5c39edd", - "origin": "Application (Microsoft Graph)", - "value": "NetworkAccessBranch.Read.All" - }, - { - "description": "Allows the app to read and write your organization's network access branches, without a signed-in user.", - "displayName": "Read and write properties of all branches for network access", - "id": "8137102d-ec16-4191-aaf8-7aeda8026183", - "origin": "Application (Microsoft Graph)", - "value": "NetworkAccessBranch.ReadWrite.All" - }, - { - "description": "Allows the app to read your organization's network access policies, without a signed-in user.", - "displayName": "Read all security and routing policies for network access", - "id": "8a3d36bf-cb46-4bcc-bec9-8d92829dab84", + "description": "Allows the app to read mail tips for all users in the organization without a signed-in user. Mail tips include automatic replies, mailbox status, custom tips, and delivery information.", + "displayName": "Read mail tips for all users", + "id": "a2c9652d-4d7f-4e4e-9d75-ac32fdc6f413", "origin": "Application (Microsoft Graph)", - "value": "NetworkAccessPolicy.Read.All" + "value": "MailTips.ReadBasic.All" }, { - "description": "Allows the app to read multi-tenant organization basic details and active tenants, without a signed-in user.", - "displayName": "Read multi-tenant organization basic details and active tenants", - "id": "f9c2b2a7-3895-4b2e-80f6-c924b456e50b", + "description": "Allows the app to read and write inbound data flows without a signed-in user.", + "displayName": "Manage inbound flow definitions", + "id": "e688c61f-d4c6-4d64-a197-3bcf6ba1d6ad", "origin": "Application (Microsoft Graph)", - "value": "MultiTenantOrganization.ReadBasic.All" + "value": "IndustryData-InboundFlow.ReadWrite.All" }, { - "description": "Allows the app to read organization-wide Dynamics customer voice settings, without a signed-in user.", - "displayName": "Read organization-wide Dynamics customer voice settings", - "id": "c18ae2dc-d9f3-4495-a93f-18980a0e159f", + "description": "Allows the app to read inbound data flows without a signed-in user.", + "displayName": "View inbound flow definitions", + "id": "305f6ba2-049a-4b1b-88bb-fe7e08758a00", "origin": "Application (Microsoft Graph)", - "value": "OrgSettings-DynamicsVoice.Read.All" + "value": "IndustryData-InboundFlow.Read.All" }, { - "description": "Allows the app to read reference definitions without a signed-in user.", - "displayName": "View reference definitions", - "id": "6ee891c3-74a4-4148-8463-0c834375dfaf", + "description": "Allows the app to upload data files to a data connector without a signed-in user.", + "displayName": "Upload files to a data connector", + "id": "9334c44b-a7c6-4350-8036-6bf8e02b4c1f", "origin": "Application (Microsoft Graph)", - "value": "IndustryData-ReferenceDefinition.Read.All" + "value": "IndustryData-DataConnector.Upload" }, { - "description": "Allows the app to read outbound data flows without a signed-in user.", - "displayName": "View outbound flow definitions", - "id": "61d0354c-5d88-483c-b974-a37ec3395a2c", + "description": "Allows the app to list all Viva Engage roles and role memberships without a signed-in user.", + "displayName": "Read all Viva Engage roles and role memberships", + "id": "30614864-4114-45ef-bdd9-0dd7894a1cc4", "origin": "Application (Microsoft Graph)", - "value": "IndustryData-OutboundFlow.Read.All" + "value": "EngagementRole.Read.All" }, { "description": "Allows the app to assign Viva Engage role to a user, and remove a Viva Engage role from a user without a signed-in user.", @@ -16933,39 +16996,46 @@ "value": "FileIngestion.Ingest" }, { - "description": "Allows the app to manage onboarding for a Hybrid Cloud tenant, without a signed-in user.", - "displayName": "Manage onboarding for a Hybrid Cloud tenant", - "id": "766c601b-c009-4438-8290-c8b05fa00c4b", + "description": "Allows the app to list Viva Engage Teams QA conversations, and to read their properties without a signed-in user.", + "displayName": "Read all Viva Engage Teams QA conversations", + "id": "d746beae-b46e-446e-924a-5b805a5c4467", "origin": "Application (Microsoft Graph)", - "value": "FileIngestionHybridOnboarding.Manage" + "value": "EngagementMeetingConversation.Read.All" }, { - "description": "Allows the app to list all Viva Engage roles and role memberships without a signed-in user.", - "displayName": "Read all Viva Engage roles and role memberships", - "id": "30614864-4114-45ef-bdd9-0dd7894a1cc4", + "description": "Allows the app to export Viva Engage data for compliance, GDPR, and admin scenarios without a signed-in user.", + "displayName": "Export Viva Engage data", + "id": "eda8c187-a7d5-42cb-b2e1-c9142f63899f", "origin": "Application (Microsoft Graph)", - "value": "EngagementRole.Read.All" + "value": "EngagementExport.Read.All" }, { - "description": "Allows the app to read all files in all site collections without a signed in user.", - "displayName": "Read files in all site collections", - "id": "01d4889c-1287-42c6-ac1f-5d1e02578ef6", + "description": "Allows the app to create Viva Engage conversations, read all conversation properties, update conversation properties, and delete conversations without a signed-in user.", + "displayName": "Read and write all Viva Engage conversations", + "id": "bfbd4840-fba0-43a7-93a9-465b687e47d0", "origin": "Application (Microsoft Graph)", - "value": "Files.Read.All" + "value": "EngagementConversation.ReadWrite.All" }, { - "description": "Allows the app to list Viva Engage Teams QA conversations, and to read their properties without a signed-in user.", - "displayName": "Read all Viva Engage Teams QA conversations", - "id": "d746beae-b46e-446e-924a-5b805a5c4467", + "description": "Allows the app to list Viva Engage conversations, and to read their properties without a signed-in user.", + "displayName": "Read all Viva Engage conversations", + "id": "2c495153-cd0e-41b4-9980-3bcecf1ca22f", "origin": "Application (Microsoft Graph)", - "value": "EngagementMeetingConversation.Read.All" + "value": "EngagementConversation.Read.All" }, { - "description": "Allows the app to create Viva Engage conversations, read all conversation properties, update conversation properties, and delete conversations without a signed-in user.", - "displayName": "Read and write all Viva Engage conversations", - "id": "bfbd4840-fba0-43a7-93a9-465b687e47d0", + "description": "Allows the app to read eDiscovery objects such as cases, custodians, review sets and other related objects without a signed-in user.", + "displayName": "Read all eDiscovery objects", + "id": "50180013-6191-4d1e-a373-e590ff4e66af", "origin": "Application (Microsoft Graph)", - "value": "EngagementConversation.ReadWrite.All" + "value": "eDiscovery.Read.All" + }, + { + "description": "Allows the app to read and write eDiscovery objects such as cases, custodians, review sets and other related objects without a signed-in user.", + "displayName": "Read and write all eDiscovery objects", + "id": "b2620db1-3bf7-4c5b-9cb9-576d29eac736", + "origin": "Application (Microsoft Graph)", + "value": "eDiscovery.ReadWrite.All" }, { "description": "Read the state and settings of all Microsoft education apps.", @@ -17009,6 +17079,13 @@ "origin": "Application (Microsoft Graph)", "value": "EduAssignments.ReadWriteBasic.All" }, + { + "description": "Allows the app to manage onboarding for a Hybrid Cloud tenant, without a signed-in user.", + "displayName": "Manage onboarding for a Hybrid Cloud tenant", + "id": "766c601b-c009-4438-8290-c8b05fa00c4b", + "origin": "Application (Microsoft Graph)", + "value": "FileIngestionHybridOnboarding.Manage" + }, { "description": "Allows the app to read all modules and resources, without a signed-in user.", "displayName": "Read all class modules and resources", @@ -17016,13 +17093,6 @@ "origin": "Application (Microsoft Graph)", "value": "EduCurricula.Read.All" }, - { - "description": "Allows the app to read and write all modules and resources, without a signed-in user.", - "displayName": "Read and write all class modules and resources", - "id": "6a0c2318-d59d-4c7d-bf2e-5f3902dc2593", - "origin": "Application (Microsoft Graph)", - "value": "EduCurricula.ReadWrite.All" - }, { "description": "Allows the app to read all tenant users reading assignments submissions data without a signed-in user.", "displayName": "Read all tenant reading assignments submissions data", @@ -17080,25 +17150,25 @@ "value": "EngagementConversation.Migration.All" }, { - "description": "Allows the app to list Viva Engage conversations, and to read their properties without a signed-in user.", - "displayName": "Read all Viva Engage conversations", - "id": "2c495153-cd0e-41b4-9980-3bcecf1ca22f", + "description": "Allows the app to read and write all modules and resources, without a signed-in user.", + "displayName": "Read and write all class modules and resources", + "id": "6a0c2318-d59d-4c7d-bf2e-5f3902dc2593", "origin": "Application (Microsoft Graph)", - "value": "EngagementConversation.Read.All" + "value": "EduCurricula.ReadWrite.All" }, { - "description": "Allows the app to export Viva Engage data for compliance, GDPR, and admin scenarios without a signed-in user.", - "displayName": "Export Viva Engage data", - "id": "eda8c187-a7d5-42cb-b2e1-c9142f63899f", + "description": "Allows the app to read all organizational contacts without a signed-in user. These contacts are managed by the organization and are different from a user's personal contacts.", + "displayName": "Read organizational contacts", + "id": "e1a88a34-94c4-4418-be12-c87b00e26bea", "origin": "Application (Microsoft Graph)", - "value": "EngagementExport.Read.All" + "value": "OrgContact.Read.All" }, { - "description": "Allows the app to read, create, update and delete all files in all site collections without a signed in user.", - "displayName": "Read and write files in all site collections", - "id": "75359482-378d-4052-8f01-80520e7db3cd", + "description": "Allows the app to read all files in all site collections without a signed in user.", + "displayName": "Read files in all site collections", + "id": "01d4889c-1287-42c6-ac1f-5d1e02578ef6", "origin": "Application (Microsoft Graph)", - "value": "Files.ReadWrite.All" + "value": "Files.Read.All" }, { "description": "Allows the app to read, create, update and delete files in the application's folder without a signed in user.", @@ -17108,11 +17178,25 @@ "value": "Files.ReadWrite.AppFolder" }, { - "description": "Allow the application to access a subset of files without a signed in user. The specific files and the permissions granted will be configured in SharePoint Online or OneDrive.", - "displayName": "Access selected Files without a signed in user.", - "id": "bd61925e-3bf4-4d62-bc0b-06b06c96d95c", + "description": "Allows the app to read identity notification settings, email templates, and prerequisites without a signed-in user.", + "displayName": "Read all identity notification settings and templates", + "id": "52ced3dd-dbb6-41a0-9ce5-61a056be97b8", "origin": "Application (Microsoft Graph)", - "value": "Files.SelectedOperations.Selected" + "value": "IdentityNotifications.Read.All" + }, + { + "description": "Allows the app to read and write identity notification settings, customize email templates, and send test emails without a signed-in user.", + "displayName": "Read and write all identity notification settings and templates", + "id": "d9fe7b9f-cb27-4289-9cb4-54debd9d3c25", + "origin": "Application (Microsoft Graph)", + "value": "IdentityNotifications.ReadWrite.All" + }, + { + "description": "Allows the app to read your organization’s identity (authentication) providers’ properties without a signed in user.", + "displayName": "Read identity providers", + "id": "e321f0bb-e7f7-481e-bb28-e3b0b32d4bd0", + "origin": "Application (Microsoft Graph)", + "value": "IdentityProvider.Read.All" }, { "description": "Allows the app to read and write your organization’s identity (authentication) providers’ properties without a signed in user.", @@ -17205,54 +17289,26 @@ "origin": "Application (Microsoft Graph)", "value": "IndustryData-DataConnector.Read.All" }, - { - "description": "Allows the app to read and write data connectors without a signed-in user.", - "displayName": "Manage data connector definitions", - "id": "eda0971c-482e-4345-b28f-69c309cb8a34", - "origin": "Application (Microsoft Graph)", - "value": "IndustryData-DataConnector.ReadWrite.All" - }, - { - "description": "Allows the app to upload data files to a data connector without a signed-in user.", - "displayName": "Upload files to a data connector", - "id": "9334c44b-a7c6-4350-8036-6bf8e02b4c1f", - "origin": "Application (Microsoft Graph)", - "value": "IndustryData-DataConnector.Upload" - }, - { - "description": "Allows the app to read inbound data flows without a signed-in user.", - "displayName": "View inbound flow definitions", - "id": "305f6ba2-049a-4b1b-88bb-fe7e08758a00", - "origin": "Application (Microsoft Graph)", - "value": "IndustryData-InboundFlow.Read.All" - }, - { - "description": "Allows the app to read and write inbound data flows without a signed-in user.", - "displayName": "Manage inbound flow definitions", - "id": "e688c61f-d4c6-4d64-a197-3bcf6ba1d6ad", - "origin": "Application (Microsoft Graph)", - "value": "IndustryData-InboundFlow.ReadWrite.All" - }, - { - "description": "Allows the app to read your organization’s identity (authentication) providers’ properties without a signed in user.", - "displayName": "Read identity providers", - "id": "e321f0bb-e7f7-481e-bb28-e3b0b32d4bd0", + { + "description": "Allows the app to read and write data connectors without a signed-in user.", + "displayName": "Manage data connector definitions", + "id": "eda0971c-482e-4345-b28f-69c309cb8a34", "origin": "Application (Microsoft Graph)", - "value": "IdentityProvider.Read.All" + "value": "IndustryData-DataConnector.ReadWrite.All" }, { - "description": "Allows the app to read and write identity notification settings, customize email templates, and send test emails without a signed-in user.", - "displayName": "Read and write all identity notification settings and templates", - "id": "d9fe7b9f-cb27-4289-9cb4-54debd9d3c25", + "description": "Allows the app to start identity diagnostic processes for all users in the organization, without a signed-in user.", + "displayName": "Start identity diagnostics for all users", + "id": "2607bb8b-0a9b-4f53-9d2f-6f81b99ac145", "origin": "Application (Microsoft Graph)", - "value": "IdentityNotifications.ReadWrite.All" + "value": "IdentityDiagnostic.StartDiagnosis.All" }, { - "description": "Allows the app to read identity notification settings, email templates, and prerequisites without a signed-in user.", - "displayName": "Read all identity notification settings and templates", - "id": "52ced3dd-dbb6-41a0-9ce5-61a056be97b8", + "description": "Allows the app to read all identity diagnostics information, including symptoms, runs, statuses, and results for all users in the organization, without a signed-in user.", + "displayName": "Read all identity diagnostics", + "id": "bb1e8ab4-fe40-4b26-82ec-65dfaf4d367b", "origin": "Application (Microsoft Graph)", - "value": "IdentityNotifications.Read.All" + "value": "IdentityDiagnostic.Read.All" }, { "description": "Allows the app to read and write all scenario monitoring alerts, without a signed-in user.", @@ -17261,6 +17317,20 @@ "origin": "Application (Microsoft Graph)", "value": "HealthMonitoringAlertConfig.ReadWrite.All" }, + { + "description": "Allows the app to read all scenario health monitoring alert configurations, without a signed-in user.", + "displayName": "Read all scenario health monitoring alert configurations", + "id": "bb424d73-e898-4c97-9d42-688c32810003", + "origin": "Application (Microsoft Graph)", + "value": "HealthMonitoringAlertConfig.Read.All" + }, + { + "description": "Allow the application to access a subset of files without a signed in user. The specific files and the permissions granted will be configured in SharePoint Online or OneDrive.", + "displayName": "Access selected Files without a signed in user.", + "id": "bd61925e-3bf4-4d62-bc0b-06b06c96d95c", + "origin": "Application (Microsoft Graph)", + "value": "Files.SelectedOperations.Selected" + }, { "description": "Allows the application to utilize the file storage container platform to manage containers, without a signed-in user. The specific file storage containers and the permissions granted to them will be configured in Microsoft 365 by the developer of each container type.", "displayName": "Access selected file storage containers", @@ -17310,6 +17380,13 @@ "origin": "Application (Microsoft Graph)", "value": "Group-Conversation.Read.All" }, + { + "description": "Allows the app to read, create, update and delete all files in all site collections without a signed in user.", + "displayName": "Read and write files in all site collections", + "id": "75359482-378d-4052-8f01-80520e7db3cd", + "origin": "Application (Microsoft Graph)", + "value": "Files.ReadWrite.All" + }, { "description": "Allows the app to read and write conversations of the groups this app has access to without a signed-in user.", "displayName": "Read and write all group conversations", @@ -17318,18 +17395,11 @@ "value": "Group-Conversation.ReadWrite.All" }, { - "description": "Allows the app to read and write outbound data flows without a signed-in user.", - "displayName": "Manage outbound flow definitions", - "id": "24a65b4a-e501-47e2-8849-d679517887f0", - "origin": "Application (Microsoft Graph)", - "value": "IndustryData-OutboundFlow.ReadWrite.All" - }, - { - "description": "Allows the app to read memberships and basic group properties for all groups without a signed-in user.", - "displayName": "Read all group memberships", - "id": "98830695-27a2-44f7-8c18-0c3ebc9698f6", + "description": "Allows the app to list groups, read basic properties, read and update the membership of the groups this app has access to without a signed-in user. Group properties and owners cannot be updated and groups cannot be deleted.", + "displayName": "Read and write all group memberships", + "id": "dbaae8cf-10b5-4b86-a4a1-f871c94c6695", "origin": "Application (Microsoft Graph)", - "value": "GroupMember.Read.All" + "value": "GroupMember.ReadWrite.All" }, { "description": "Allows the app to read and write groups' disableNesting property without a signed-in user.", @@ -17381,39 +17451,46 @@ "value": "HealthMonitoringAlert.ReadWrite.All" }, { - "description": "Allows the app to read all scenario health monitoring alert configurations, without a signed-in user.", - "displayName": "Read all scenario health monitoring alert configurations", - "id": "bb424d73-e898-4c97-9d42-688c32810003", + "description": "Allows the app to read memberships and basic group properties for all groups without a signed-in user.", + "displayName": "Read all group memberships", + "id": "98830695-27a2-44f7-8c18-0c3ebc9698f6", "origin": "Application (Microsoft Graph)", - "value": "HealthMonitoringAlertConfig.Read.All" + "value": "GroupMember.Read.All" }, { - "description": "Allows the app to list groups, read basic properties, read and update the membership of the groups this app has access to without a signed-in user. Group properties and owners cannot be updated and groups cannot be deleted.", - "displayName": "Read and write all group memberships", - "id": "dbaae8cf-10b5-4b86-a4a1-f871c94c6695", + "description": "Allows the app to manage restricted resources based on the other permissions granted to the app, on behalf of the signed-in user.", + "displayName": "Manage restricted resources in the directory", + "id": "cba5390f-ed6a-4b7f-b657-0efc2210ed20", + "origin": "Delegated", + "value": "Directory.Write.Restricted" + }, + { + "description": "Allows the app to read organization-wide apps and services settings, without a signed-in user.", + "displayName": "Read organization-wide apps and services settings", + "id": "56c84fa9-ea1f-4a15-90f2-90ef41ece2c9", "origin": "Application (Microsoft Graph)", - "value": "GroupMember.ReadWrite.All" + "value": "OrgSettings-AppsAndServices.Read.All" }, { - "description": "Allows the app to read all the short notes without a signed-in user.", - "displayName": "Read all users' short notes", - "id": "0c7d31ec-31ca-4f58-b6ec-9950b6b0de69", + "description": "Allows the app to read organization-wide Dynamics customer voice settings, without a signed-in user.", + "displayName": "Read organization-wide Dynamics customer voice settings", + "id": "c18ae2dc-d9f3-4495-a93f-18980a0e159f", "origin": "Application (Microsoft Graph)", - "value": "ShortNotes.Read.All" + "value": "OrgSettings-DynamicsVoice.Read.All" }, { - "description": "Allows the app to read and write organization-wide Dynamics customer voice settings, without a signed-in user.", - "displayName": "Read and write organization-wide Dynamics customer voice settings", - "id": "c3f1cc32-8bbd-4ab6-bd33-f270e0d9e041", + "description": "Allows the app to read role-based access control (RBAC) settings for all RBAC providers without a signed-in user. This includes reading role definitions and role assignments.", + "displayName": "Read role management data for all RBAC providers", + "id": "c7fbd983-d9aa-4fa7-84b8-17382c103bc4", "origin": "Application (Microsoft Graph)", - "value": "OrgSettings-DynamicsVoice.ReadWrite.All" + "value": "RoleManagement.Read.All" }, { - "description": "Allows the app to read and write organization-wide Microsoft Forms settings, without a signed-in user.", - "displayName": "Read and write organization-wide Microsoft Forms settings", - "id": "2cb92fee-97a3-4034-8702-24a6f5d0d1e9", + "description": "Allows the app to read the Cloud PC role-based access control (RBAC) settings, without a signed-in user.", + "displayName": "Read Cloud PC RBAC settings", + "id": "031a549a-bb80-49b6-8032-2068448c6a3c", "origin": "Application (Microsoft Graph)", - "value": "OrgSettings-Forms.ReadWrite.All" + "value": "RoleManagement.Read.CloudPC" }, { "description": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, without a signed-in user.", @@ -17520,6 +17597,13 @@ "origin": "Application (Microsoft Graph)", "value": "RoleManagementPolicy.ReadWrite.EntraAppRole" }, + { + "description": "Delete all eligible privileged role-based access control (RBAC) assignments of your company's directory, without a signed-in user.", + "displayName": "Delete all eligible role assignments of your company's directory", + "id": "79c7e69c-0d9f-4eff-97a8-49170a5a08ba", + "origin": "Application (Microsoft Graph)", + "value": "RoleEligibilitySchedule.Remove.Directory" + }, { "description": "Allows the app to read all schedules, schedule groups, shifts and associated entities in the Teams or Shifts application without a signed-in user.", "displayName": "Read all schedule items", @@ -17528,39 +17612,32 @@ "value": "Schedule.Read.All" }, { - "description": "Allows the app to manage all schedules, schedule groups, shifts and associated entities in the Teams or Shifts application without a signed-in user.", - "displayName": "Read and write all schedule items", - "id": "b7760610-0545-4e8a-9ec3-cce9e63db01c", - "origin": "Application (Microsoft Graph)", - "value": "Schedule.ReadWrite.All" - }, - { - "description": "Allows the app to read the Cloud PC role-based access control (RBAC) settings, without a signed-in user.", - "displayName": "Read Cloud PC RBAC settings", - "id": "031a549a-bb80-49b6-8032-2068448c6a3c", + "description": "Allows the app to read and manage the eligible role-based access control (RBAC) assignments and schedules for your company's directory, without a signed-in user. This includes managing eligible directory role membership, and reading directory role templates, directory roles and eligible memberships.", + "displayName": "Read, update, and delete all eligible role assignments and schedules for your company's directory", + "id": "fee28b28-e1f3-4841-818e-2704dc62245f", "origin": "Application (Microsoft Graph)", - "value": "RoleManagement.Read.CloudPC" + "value": "RoleEligibilitySchedule.ReadWrite.Directory" }, { - "description": "Allows the app to read/write schedule permissions for a specific role in Shifts application without a signed-in user.", - "displayName": "Read/Write schedule permissions for a role", - "id": "7239b71d-b402-4150-b13d-78ecfe8df441", + "description": "Delete all active privileged role-based access control (RBAC) assignments of your company's directory, without a signed-in user.", + "displayName": "Delete all active role assignments of your company's directory", + "id": "d3495511-98b7-4df3-b317-4e35c19f6129", "origin": "Application (Microsoft Graph)", - "value": "SchedulePermissions.ReadWrite.All" + "value": "RoleAssignmentSchedule.Remove.Directory" }, { - "description": "Allows the app to read role-based access control (RBAC) settings for all RBAC providers without a signed-in user. This includes reading role definitions and role assignments.", - "displayName": "Read role management data for all RBAC providers", - "id": "c7fbd983-d9aa-4fa7-84b8-17382c103bc4", + "description": "Allows the application to read and write certificate-based authentication configuration such as all public key infrastructures (PKI) and certificate authorities (CA) configured for the organization, without a signed-in user.", + "displayName": "Read and write all certificate based authentication configurations", + "id": "a2b63618-5350-462d-b1b3-ba6eb3684e26", "origin": "Application (Microsoft Graph)", - "value": "RoleManagement.Read.All" + "value": "PublicKeyInfrastructure.ReadWrite.All" }, { - "description": "Allows the app to read and manage the eligible role-based access control (RBAC) assignments and schedules for your company's directory, without a signed-in user. This includes managing eligible directory role membership, and reading directory role templates, directory roles and eligible memberships.", - "displayName": "Read, update, and delete all eligible role assignments and schedules for your company's directory", - "id": "fee28b28-e1f3-4841-818e-2704dc62245f", + "description": "Allows the application to read pull-print printers without a signed-in user. ", + "displayName": "Read pull-print printers", + "id": "f369d3b8-fe98-4772-85e1-b23e7cf41982", "origin": "Application (Microsoft Graph)", - "value": "RoleEligibilitySchedule.ReadWrite.Directory" + "value": "PullPrintPrinter.Read.All" }, { "description": "Allows an app to read all question and answers, without a signed-in user.", @@ -17667,13 +17744,6 @@ "origin": "Application (Microsoft Graph)", "value": "RoleAssignmentSchedule.ReadWrite.Directory" }, - { - "description": "Delete all active privileged role-based access control (RBAC) assignments of your company's directory, without a signed-in user.", - "displayName": "Delete all active role assignments of your company's directory", - "id": "d3495511-98b7-4df3-b317-4e35c19f6129", - "origin": "Application (Microsoft Graph)", - "value": "RoleAssignmentSchedule.Remove.Directory" - }, { "description": "Allows the app to read the eligible role-based access control (RBAC) assignments and schedules for your company's directory, without a signed-in user. This includes reading directory role templates, and directory roles.", "displayName": "Read all eligible role assignments and role schedules for your company's directory", @@ -17682,11 +17752,18 @@ "value": "RoleEligibilitySchedule.Read.Directory" }, { - "description": "Delete all eligible privileged role-based access control (RBAC) assignments of your company's directory, without a signed-in user.", - "displayName": "Delete all eligible role assignments of your company's directory", - "id": "79c7e69c-0d9f-4eff-97a8-49170a5a08ba", + "description": "Allows the app to manage all schedules, schedule groups, shifts and associated entities in the Teams or Shifts application without a signed-in user.", + "displayName": "Read and write all schedule items", + "id": "b7760610-0545-4e8a-9ec3-cce9e63db01c", "origin": "Application (Microsoft Graph)", - "value": "RoleEligibilitySchedule.Remove.Directory" + "value": "Schedule.ReadWrite.All" + }, + { + "description": "Allows the app to read/write schedule permissions for a specific role in Shifts application without a signed-in user.", + "displayName": "Read/Write schedule permissions for a role", + "id": "7239b71d-b402-4150-b13d-78ecfe8df441", + "origin": "Application (Microsoft Graph)", + "value": "SchedulePermissions.ReadWrite.All" }, { "description": "Allows the app to trigger the working time policies and read the working time status for other users in your organization, without a signed-in user.", @@ -17696,18 +17773,18 @@ "value": "Schedule-WorkingTime.ReadWrite.All" }, { - "description": "Allows the app to read search configurations, without a signed-in user.", - "displayName": "Read your organization's search configuration", - "id": "ada977a5-b8b1-493b-9a91-66c206d76ecf", + "description": "Allows the app to read and write identity security available user actions without a signed-in user.", + "displayName": "Read and perform all identity security available user actions", + "id": "b4146a3a-dd4f-4af4-8d91-7cc0eef3d041", "origin": "Application (Microsoft Graph)", - "value": "SearchConfiguration.Read.All" + "value": "SecurityIdentitiesUserActions.ReadWrite.All" }, { - "description": "Allows the app to read and write search configurations, without a signed-in user.", - "displayName": "Read and write your organization's search configuration", - "id": "0e778b85-fefa-466d-9eec-750569d92122", + "description": "Allows the app to read all security incidents, without a signed-in user.", + "displayName": "Read all security incidents", + "id": "45cc0394-e837-488b-a098-1918f48d186c", "origin": "Application (Microsoft Graph)", - "value": "SearchConfiguration.ReadWrite.All" + "value": "SecurityIncident.Read.All" }, { "description": "Allows the app to read and write to all security incidents, without a signed-in user.", @@ -17815,46 +17892,46 @@ "value": "SharePointCrossTenantMigration.Manage.All" }, { - "description": "Allows the app to read your tenant's SharePoint Cross-Tenant migration settings and tasks, without a signed-in user.", - "displayName": "Read SharePoint Cross-Tenant migration settings and tasks", - "id": "f5fa52a5-b9ab-4dc3-885e-9e5b4a67068e", + "description": "Allows the app to read all the identity security available user actions without a signed-in user.", + "displayName": "Read all identity security available user actions", + "id": "3e5d0bee-973f-4736-a123-4e1ab146f3a8", "origin": "Application (Microsoft Graph)", - "value": "SharePointCrossTenantMigration.Read.All" + "value": "SecurityIdentitiesUserActions.Read.All" }, { - "description": "Allows the application to read the tenant-level settings of SharePoint and OneDrive, without a signed-in user.", - "displayName": "Read SharePoint and OneDrive tenant settings", - "id": "83d4163d-a2d8-4d3b-9695-4ae3ca98f888", + "description": "Allows the app to read and write identity security sensors without a signed-in user.", + "displayName": "Read and write all identity security sensors", + "id": "d4dcee6d-0774-412a-b06c-aeabbd99e816", "origin": "Application (Microsoft Graph)", - "value": "SharePointTenantSettings.Read.All" + "value": "SecurityIdentitiesSensors.ReadWrite.All" }, { - "description": "Allows the app to read all security incidents, without a signed-in user.", - "displayName": "Read all security incidents", - "id": "45cc0394-e837-488b-a098-1918f48d186c", + "description": "Allows the app to read all the identity security sensors without a signed-in user.", + "displayName": "Read all identity security sensors", + "id": "5f0ffea2-f474-4cf2-9834-61cda2bcea5c", "origin": "Application (Microsoft Graph)", - "value": "SecurityIncident.Read.All" + "value": "SecurityIdentitiesSensors.Read.All" }, { - "description": "Allows the app to read and write identity security available user actions without a signed-in user.", - "displayName": "Read and perform all identity security available user actions", - "id": "b4146a3a-dd4f-4af4-8d91-7cc0eef3d041", + "description": "Allows the app to read and write identity security sensor migration without a signed-in user.", + "displayName": "Read and write all identity security sensor migration", + "id": "afd28a5a-707f-4edf-85c2-c446291e63da", "origin": "Application (Microsoft Graph)", - "value": "SecurityIdentitiesUserActions.ReadWrite.All" + "value": "SecurityIdentitiesMigration.ReadWrite.All" }, { - "description": "Allows the app to read all the identity security available user actions without a signed-in user.", - "displayName": "Read all identity security available user actions", - "id": "3e5d0bee-973f-4736-a123-4e1ab146f3a8", + "description": "Allows the app to read search configurations, without a signed-in user.", + "displayName": "Read your organization's search configuration", + "id": "ada977a5-b8b1-493b-9a91-66c206d76ecf", "origin": "Application (Microsoft Graph)", - "value": "SecurityIdentitiesUserActions.Read.All" + "value": "SearchConfiguration.Read.All" }, { - "description": "Allows the app to read and write identity security sensors without a signed-in user.", - "displayName": "Read and write all identity security sensors", - "id": "d4dcee6d-0774-412a-b06c-aeabbd99e816", + "description": "Allows the app to read and write search configurations, without a signed-in user.", + "displayName": "Read and write your organization's search configuration", + "id": "0e778b85-fefa-466d-9eec-750569d92122", "origin": "Application (Microsoft Graph)", - "value": "SecurityIdentitiesSensors.ReadWrite.All" + "value": "SearchConfiguration.ReadWrite.All" }, { "description": "Allows the app to read security actions, without a signed-in user.", @@ -17898,6 +17975,13 @@ "origin": "Application (Microsoft Graph)", "value": "SecurityAnalyzedMessage.Read.All" }, + { + "description": "Allows the application to read certificate-based authentication configuration such as all public key infrastructures (PKI) and certificate authorities (CA) configured for the organization, without a signed-in user.", + "displayName": "Read all certificate based authentication configurations", + "id": "214fda0c-514a-4650-b037-b562b1a66124", + "origin": "Application (Microsoft Graph)", + "value": "PublicKeyInfrastructure.Read.All" + }, { "description": "Read email metadata and security detection details, and execute remediation actions like deleting an email, without a signed-in user.", "displayName": "Read metadata, detection details, and execute remediation actions on all emails in your organization", @@ -17905,20 +17989,6 @@ "origin": "Application (Microsoft Graph)", "value": "SecurityAnalyzedMessage.ReadWrite.All" }, - { - "description": "Allows the app to read your organization’s security events without a signed-in user.", - "displayName": "Read your organization’s security events", - "id": "bf394140-e372-4bf9-a898-299cfc7564e5", - "origin": "Application (Microsoft Graph)", - "value": "SecurityEvents.Read.All" - }, - { - "description": "Allows the application to read pull-print printers without a signed-in user. ", - "displayName": "Read pull-print printers", - "id": "f369d3b8-fe98-4772-85e1-b23e7cf41982", - "origin": "Application (Microsoft Graph)", - "value": "PullPrintPrinter.Read.All" - }, { "description": "Allows the app to read your organization’s security events without a signed-in user. Also allows the app to update editable properties in security events.", "displayName": "Read and update your organization’s security events", @@ -17926,6 +17996,13 @@ "origin": "Application (Microsoft Graph)", "value": "SecurityEvents.ReadWrite.All" }, + { + "description": "Allows the app to read all the identity security available identity accounts without a signed-in user.", + "displayName": "Read all identity security available identity accounts", + "id": "c5bc96f5-b4a1-4cfc-8189-d5f0d772278f", + "origin": "Application (Microsoft Graph)", + "value": "SecurityIdentitiesAccount.Read.All" + }, { "description": "Allows the app to read and write identity security available actions without a signed-in user.", "displayName": "Read and perform all identity security available actions", @@ -17969,46 +18046,46 @@ "value": "SecurityIdentitiesMigration.Read.All" }, { - "description": "Allows the app to read and write identity security sensor migration without a signed-in user.", - "displayName": "Read and write all identity security sensor migration", - "id": "afd28a5a-707f-4edf-85c2-c446291e63da", + "description": "Allows the app to read your organization’s security events without a signed-in user.", + "displayName": "Read your organization’s security events", + "id": "bf394140-e372-4bf9-a898-299cfc7564e5", "origin": "Application (Microsoft Graph)", - "value": "SecurityIdentitiesMigration.ReadWrite.All" + "value": "SecurityEvents.Read.All" }, { - "description": "Allows the app to read all the identity security sensors without a signed-in user.", - "displayName": "Read all identity security sensors", - "id": "5f0ffea2-f474-4cf2-9834-61cda2bcea5c", + "description": "Allows the app to read and query your provisioning log activities, without a signed-in user.", + "displayName": "Read all provisioning log data", + "id": "091937d3-3e38-47a1-8649-b2f99d3035f1", "origin": "Application (Microsoft Graph)", - "value": "SecurityIdentitiesSensors.Read.All" + "value": "ProvisioningLog.Read.All" }, { - "description": "Allows the app to read all the identity security available identity accounts without a signed-in user.", - "displayName": "Read all identity security available identity accounts", - "id": "c5bc96f5-b4a1-4cfc-8189-d5f0d772278f", + "description": "Allows the app to identify Purview data protection, compliance and governance policy scopes defined for an individual user.", + "displayName": "Compute Purview policies for an individual user", + "id": "fe696d63-5e1f-4515-8232-cccc316903c6", "origin": "Application (Microsoft Graph)", - "value": "SecurityIdentitiesAccount.Read.All" + "value": "ProtectionScopes.Compute.User" }, { - "description": "Allows the app to read organization-wide Microsoft Forms settings, without a signed-in user.", - "displayName": "Read organization-wide Microsoft Forms settings", - "id": "434d7c66-07c6-4b1f-ab21-417cf2cdaaca", + "description": "Allows the app to identify Purview data protection, compliance and governance policy scopes defined for all users across tenant.", + "displayName": "Compute Purview policies at tenant scope", + "id": "e5a76501-dbb0-492c-ab55-5d09e8837263", "origin": "Application (Microsoft Graph)", - "value": "OrgSettings-Forms.Read.All" + "value": "ProtectionScopes.Compute.All" }, { - "description": "Allows the application to read and write certificate-based authentication configuration such as all public key infrastructures (PKI) and certificate authorities (CA) configured for the organization, without a signed-in user.", - "displayName": "Read and write all certificate based authentication configurations", - "id": "a2b63618-5350-462d-b1b3-ba6eb3684e26", + "description": "Allows the app to read all your organization's B2BManagement policies without a signed in user.", + "displayName": "Read your organization's B2BManagement policies", + "id": "227900ff-df89-40f8-90e2-8157cf6995d5", "origin": "Application (Microsoft Graph)", - "value": "PublicKeyInfrastructure.ReadWrite.All" + "value": "Policy.Read.B2BManagementPolicy" }, { - "description": "Allows the app to read and query your provisioning log activities, without a signed-in user.", - "displayName": "Read all provisioning log data", - "id": "091937d3-3e38-47a1-8649-b2f99d3035f1", + "description": "Allows the app to read your organization's conditional access policies, without a signed-in user.", + "displayName": "Read your organization's conditional access policies", + "id": "37730810-e9ba-4e46-b07e-8ca78d182097", "origin": "Application (Microsoft Graph)", - "value": "ProvisioningLog.Read.All" + "value": "Policy.Read.ConditionalAccess" }, { "description": "Allows the app to read your organization's cross tenant access policies without a signed-in user.", @@ -18116,46 +18193,53 @@ "value": "Policy.ReadWrite.CrossTenantCapability" }, { - "description": "Allows the application to read and write your organization's device configuration policies without a signed-in user. For example, device registration policy can limit initial provisioning controls using quota restrictions, additional authentication and authorization checks.", - "displayName": "Read and write your organization's device configuration policies", - "id": "230fb2d5-aa21-49c1-bfa7-ae1be179d867", + "description": "Allows the app to read all authentication method policies for the tenant, without a signed-in user. ", + "displayName": "Read authentication method policies", + "id": "8e3bc81b-d2f3-4b7b-838c-32c88218d2f0", "origin": "Application (Microsoft Graph)", - "value": "Policy.ReadWrite.DeviceConfiguration" + "value": "Policy.Read.AuthenticationMethod" }, { - "description": "Allows the application to read and update the organization's external identities policy without a signed-in user. For example, external identities policy controls if users invited to access resources in your organization via B2B collaboration or B2B direct connect are allowed to self-service leave.", - "displayName": "Read and write your organization's external identities policy", - "id": "03cc4f92-788e-4ede-b93f-199424d144a5", + "description": "Allows the app to read all your organization's policies without a signed in user.", + "displayName": "Read your organization's policies", + "id": "246dd0d5-5bd0-4def-940b-0421030a5b68", "origin": "Application (Microsoft Graph)", - "value": "Policy.ReadWrite.ExternalIdentities" + "value": "Policy.Read.All" }, { - "description": "Allows the app to read your organization's conditional access policies, without a signed-in user.", - "displayName": "Read your organization's conditional access policies", - "id": "37730810-e9ba-4e46-b07e-8ca78d182097", + "description": "Allows the app to read and write telemetry for all workplace devices, without a signed-in user.", + "displayName": "Read and write telemetry for all workplace devices.", + "id": "27fc435f-44e2-4b30-bf3c-e0ce74aed618", "origin": "Application (Microsoft Graph)", - "value": "Policy.Read.ConditionalAccess" + "value": "PlaceDeviceTelemetry.ReadWrite.All" }, { - "description": "Allows the app to read and write feature rollout policies without a signed-in user. Includes abilities to assign and remove users and groups to rollout of a specific feature.", - "displayName": "Read and write feature rollout policies", - "id": "2044e4f1-e56c-435b-925c-44cd8f6ba89a", + "description": "Allows the app to read and write all workplace devices, without a signed-in user.", + "displayName": "Read and write all workplace devices", + "id": "2d510721-5c4e-43cd-bfdb-ac0f8819fb92", "origin": "Application (Microsoft Graph)", - "value": "Policy.ReadWrite.FeatureRollout" + "value": "PlaceDevice.ReadWrite.All" }, { - "description": "Allows the app to read all your organization's B2BManagement policies without a signed in user.", - "displayName": "Read your organization's B2BManagement policies", - "id": "227900ff-df89-40f8-90e2-8157cf6995d5", + "description": "Allows the app to read and write organization-wide Dynamics customer voice settings, without a signed-in user.", + "displayName": "Read and write organization-wide Dynamics customer voice settings", + "id": "c3f1cc32-8bbd-4ab6-bd33-f270e0d9e041", "origin": "Application (Microsoft Graph)", - "value": "Policy.Read.B2BManagementPolicy" + "value": "OrgSettings-DynamicsVoice.ReadWrite.All" }, { - "description": "Allows the app to read all your organization's policies without a signed in user.", - "displayName": "Read your organization's policies", - "id": "246dd0d5-5bd0-4def-940b-0421030a5b68", + "description": "Allows the app to read organization-wide Microsoft Forms settings, without a signed-in user.", + "displayName": "Read organization-wide Microsoft Forms settings", + "id": "434d7c66-07c6-4b1f-ab21-417cf2cdaaca", "origin": "Application (Microsoft Graph)", - "value": "Policy.Read.All" + "value": "OrgSettings-Forms.Read.All" + }, + { + "description": "Allows the app to read and write organization-wide Microsoft Forms settings, without a signed-in user.", + "displayName": "Read and write organization-wide Microsoft Forms settings", + "id": "2cb92fee-97a3-4034-8702-24a6f5d0d1e9", + "origin": "Application (Microsoft Graph)", + "value": "OrgSettings-Forms.ReadWrite.All" }, { "description": "Allows the app to read organization-wide Microsoft 365 apps installation settings, without a signed-in user.", @@ -18192,6 +18276,13 @@ "origin": "Application (Microsoft Graph)", "value": "PartnerBilling.Read.All" }, + { + "description": "Allows the application to read and write your organization's device configuration policies without a signed-in user. For example, device registration policy can limit initial provisioning controls using quota restrictions, additional authentication and authorization checks.", + "displayName": "Read and write your organization's device configuration policies", + "id": "230fb2d5-aa21-49c1-bfa7-ae1be179d867", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.DeviceConfiguration" + }, { "description": "Allows the app to read security alerts of customer with CSP relationship, without a signed-in user.", "displayName": "Read security alerts of customer with CSP relationship", @@ -18199,13 +18290,6 @@ "origin": "Application (Microsoft Graph)", "value": "PartnerSecurity.Read.All" }, - { - "description": "Allows the app to read security alerts and update status of alerts of customer with CSP relationship, without a signed-in user.", - "displayName": "Read security alerts and update status of security alerts of customer with CSP relationship", - "id": "04a2c935-5b4b-474a-be42-11f53111f271", - "origin": "Application (Microsoft Graph)", - "value": "PartnerSecurity.ReadWrite.All" - }, { "description": "Allows the app to read available properties of pending external user profiles, without a signed-in user.", "displayName": "Read all pending external user profiles", @@ -18263,25 +18347,25 @@ "value": "PlaceDevice.Read.All" }, { - "description": "Allows the app to read and write all workplace devices, without a signed-in user.", - "displayName": "Read and write all workplace devices", - "id": "2d510721-5c4e-43cd-bfdb-ac0f8819fb92", + "description": "Allows the app to read security alerts and update status of alerts of customer with CSP relationship, without a signed-in user.", + "displayName": "Read security alerts and update status of security alerts of customer with CSP relationship", + "id": "04a2c935-5b4b-474a-be42-11f53111f271", "origin": "Application (Microsoft Graph)", - "value": "PlaceDevice.ReadWrite.All" + "value": "PartnerSecurity.ReadWrite.All" }, { - "description": "Allows the app to read and write telemetry for all workplace devices, without a signed-in user.", - "displayName": "Read and write telemetry for all workplace devices.", - "id": "27fc435f-44e2-4b30-bf3c-e0ce74aed618", + "description": "Allows the app to read and write organization-wide apps and services settings, without a signed-in user.", + "displayName": "Read and write organization-wide apps and services settings", + "id": "4a8e4191-c1c8-45f8-b801-f9a1a5ee6ad3", "origin": "Application (Microsoft Graph)", - "value": "PlaceDeviceTelemetry.ReadWrite.All" + "value": "OrgSettings-AppsAndServices.ReadWrite.All" }, { - "description": "Allows the app to read all authentication method policies for the tenant, without a signed-in user. ", - "displayName": "Read authentication method policies", - "id": "8e3bc81b-d2f3-4b7b-838c-32c88218d2f0", + "description": "Allows the application to read and update the organization's external identities policy without a signed-in user. For example, external identities policy controls if users invited to access resources in your organization via B2B collaboration or B2B direct connect are allowed to self-service leave.", + "displayName": "Read and write your organization's external identities policy", + "id": "03cc4f92-788e-4ede-b93f-199424d144a5", "origin": "Application (Microsoft Graph)", - "value": "Policy.Read.AuthenticationMethod" + "value": "Policy.ReadWrite.ExternalIdentities" }, { "description": "Allows the application to read and update the organization's federated token validation policy without a signed-in user.", @@ -18291,18 +18375,18 @@ "value": "Policy.ReadWrite.FedTokenValidation" }, { - "description": "Allows the app to read and write your organization’s identity protection policy without a signed-in user.", - "displayName": "Read and write your organization’s identity protection policy ", - "id": "2dcf8603-09eb-4078-b1ec-d30a1a76b873", + "description": "Allows the app to request and manage time-based assignment and just-in-time elevation of Azure resources (like your subscriptions, resource groups, storage, compute) in your organization, without a signed-in user.", + "displayName": "Read and write privileged access to Azure resources", + "id": "6f9d5abc-2db6-400b-a267-7de22a40fb87", "origin": "Application (Microsoft Graph)", - "value": "Policy.ReadWrite.IdentityProtection" + "value": "PrivilegedAccess.ReadWrite.AzureResources" }, { - "description": "Allows the app to manage policies related to consent and permission grants for applications, without a signed-in user.", - "displayName": "Manage consent and permission grant policies", - "id": "a402ca1c-2696-4531-972d-6e5ee4aa11ea", + "description": "Allows the app to read Privileged Access (PIM) custom extensions for your organization, without a signed-in user.", + "displayName": "Read Privileged Access (PIM) custom extensions", + "id": "e7ebe2d9-6e26-487a-8286-191d623a6904", "origin": "Application (Microsoft Graph)", - "value": "Policy.ReadWrite.PermissionGrant" + "value": "PrivilegedAccess-CustomExt.Read.All" }, { "description": "Allows the app to read and write Privileged Access (PIM) custom extensions for your organization, without a signed-in user.", @@ -18410,46 +18494,46 @@ "value": "ProgramControl.ReadWrite.All" }, { - "description": "Allows the app to identify Purview data protection, compliance and governance policy scopes defined for all users across tenant.", - "displayName": "Compute Purview policies at tenant scope", - "id": "e5a76501-dbb0-492c-ab55-5d09e8837263", + "description": "Allows the app to request and manage time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups in your organization, without a signed-in user.", + "displayName": "Read and write privileged access to Azure AD groups", + "id": "2f6817f8-7b12-4f0f-bc18-eeaf60705a9e", "origin": "Application (Microsoft Graph)", - "value": "ProtectionScopes.Compute.All" + "value": "PrivilegedAccess.ReadWrite.AzureADGroup" }, { - "description": "Allows the app to identify Purview data protection, compliance and governance policy scopes defined for an individual user.", - "displayName": "Compute Purview policies for an individual user", - "id": "fe696d63-5e1f-4515-8232-cccc316903c6", + "description": "Allows the app to request and manage time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD built-in and custom administrative roles in your organization, without a signed-in user.", + "displayName": "Read and write privileged access to Azure AD roles", + "id": "854d9ab1-6657-4ec8-be45-823027bcd009", "origin": "Application (Microsoft Graph)", - "value": "ProtectionScopes.Compute.User" + "value": "PrivilegedAccess.ReadWrite.AzureAD" }, { - "description": "Allows the app to read Privileged Access (PIM) custom extensions for your organization, without a signed-in user.", - "displayName": "Read Privileged Access (PIM) custom extensions", - "id": "e7ebe2d9-6e26-487a-8286-191d623a6904", + "description": "Allows the app to read time-based assignment and just-in-time elevation of user privileges to audit Azure resources in your organization, without a signed-in user.", + "displayName": "Read privileged access to Azure resources", + "id": "5df6fe86-1be0-44eb-b916-7bd443a71236", "origin": "Application (Microsoft Graph)", - "value": "PrivilegedAccess-CustomExt.Read.All" + "value": "PrivilegedAccess.Read.AzureResources" }, { - "description": "Allows the app to request and manage time-based assignment and just-in-time elevation of Azure resources (like your subscriptions, resource groups, storage, compute) in your organization, without a signed-in user.", - "displayName": "Read and write privileged access to Azure resources", - "id": "6f9d5abc-2db6-400b-a267-7de22a40fb87", + "description": "Allows the app to read time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups in your organization, without a signed-in user.", + "displayName": "Read privileged access to Azure AD groups", + "id": "01e37dc9-c035-40bd-b438-b2879c4870a6", "origin": "Application (Microsoft Graph)", - "value": "PrivilegedAccess.ReadWrite.AzureResources" + "value": "PrivilegedAccess.Read.AzureADGroup" }, { - "description": "Allows the app to request and manage time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups in your organization, without a signed-in user.", - "displayName": "Read and write privileged access to Azure AD groups", - "id": "2f6817f8-7b12-4f0f-bc18-eeaf60705a9e", + "description": "Allows the app to read and write your organization’s identity protection policy without a signed-in user.", + "displayName": "Read and write your organization’s identity protection policy ", + "id": "2dcf8603-09eb-4078-b1ec-d30a1a76b873", "origin": "Application (Microsoft Graph)", - "value": "PrivilegedAccess.ReadWrite.AzureADGroup" + "value": "Policy.ReadWrite.IdentityProtection" }, { - "description": "Allows the app to request and manage time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD built-in and custom administrative roles in your organization, without a signed-in user.", - "displayName": "Read and write privileged access to Azure AD roles", - "id": "854d9ab1-6657-4ec8-be45-823027bcd009", + "description": "Allows the app to manage policies related to consent and permission grants for applications, without a signed-in user.", + "displayName": "Manage consent and permission grant policies", + "id": "a402ca1c-2696-4531-972d-6e5ee4aa11ea", "origin": "Application (Microsoft Graph)", - "value": "PrivilegedAccess.ReadWrite.AzureAD" + "value": "Policy.ReadWrite.PermissionGrant" }, { "description": "Allows the application to read and update the organization's recovery policy without a signed-in user.", @@ -18493,6 +18577,13 @@ "origin": "Application (Microsoft Graph)", "value": "Presence.ReadWrite.All" }, + { + "description": "Allows the app to read and write feature rollout policies without a signed-in user. Includes abilities to assign and remove users and groups to rollout of a specific feature.", + "displayName": "Read and write feature rollout policies", + "id": "2044e4f1-e56c-435b-925c-44cd8f6ba89a", + "origin": "Application (Microsoft Graph)", + "value": "Policy.ReadWrite.FeatureRollout" + }, { "description": "Allows the application to read printers without a signed-in user. ", "displayName": "Read printers", @@ -18500,20 +18591,6 @@ "origin": "Application (Microsoft Graph)", "value": "Printer.Read.All" }, - { - "description": "Allows the application to read and update printers without a signed-in user. Does not allow creating (registering) or deleting (unregistering) printers.", - "displayName": "Read and update printers", - "id": "f5b3f73d-6247-44df-a74c-866173fddab0", - "origin": "Application (Microsoft Graph)", - "value": "Printer.ReadWrite.All" - }, - { - "description": "Allows the application to read certificate-based authentication configuration such as all public key infrastructures (PKI) and certificate authorities (CA) configured for the organization, without a signed-in user.", - "displayName": "Read all certificate based authentication configurations", - "id": "214fda0c-514a-4650-b037-b562b1a66124", - "origin": "Application (Microsoft Graph)", - "value": "PublicKeyInfrastructure.Read.All" - }, { "description": "Allows the application to perform advanced operations like redirecting a print job to another printer without a signed-in user. Also allows the application to read and update the metadata of print jobs.", "displayName": "Perform advanced operations on print jobs", @@ -18521,6 +18598,13 @@ "origin": "Application (Microsoft Graph)", "value": "PrintJob.Manage.All" }, + { + "description": "Allows the application to read the metadata and document content of print jobs without a signed-in user. ", + "displayName": "Read print jobs", + "id": "ac6f956c-edea-44e4-bd06-64b1b4b9aec9", + "origin": "Application (Microsoft Graph)", + "value": "PrintJob.Read.All" + }, { "description": "Allows the application to read the metadata of print jobs without a signed-in user. Does not allow access to print job document content.", "displayName": "Read basic information for print jobs", @@ -18564,25 +18648,11 @@ "value": "PrivilegedAccess.Read.AzureAD" }, { - "description": "Allows the app to read time-based assignment and just-in-time elevation (including scheduled elevation) of Azure AD groups in your organization, without a signed-in user.", - "displayName": "Read privileged access to Azure AD groups", - "id": "01e37dc9-c035-40bd-b438-b2879c4870a6", - "origin": "Application (Microsoft Graph)", - "value": "PrivilegedAccess.Read.AzureADGroup" - }, - { - "description": "Allows the app to read time-based assignment and just-in-time elevation of user privileges to audit Azure resources in your organization, without a signed-in user.", - "displayName": "Read privileged access to Azure resources", - "id": "5df6fe86-1be0-44eb-b916-7bd443a71236", - "origin": "Application (Microsoft Graph)", - "value": "PrivilegedAccess.Read.AzureResources" - }, - { - "description": "Allows the application to read the metadata and document content of print jobs without a signed-in user. ", - "displayName": "Read print jobs", - "id": "ac6f956c-edea-44e4-bd06-64b1b4b9aec9", + "description": "Allows the application to read and update printers without a signed-in user. Does not allow creating (registering) or deleting (unregistering) printers.", + "displayName": "Read and update printers", + "id": "f5b3f73d-6247-44df-a74c-866173fddab0", "origin": "Application (Microsoft Graph)", - "value": "PrintJob.Read.All" + "value": "Printer.ReadWrite.All" }, { "description": "Access Microsoft Teams and Skype for Business data as the signed in user", diff --git a/Config/SAMManifest.json b/Config/SAMManifest.json index b4ddb1320508b..b4f29624ddd64 100644 --- a/Config/SAMManifest.json +++ b/Config/SAMManifest.json @@ -14,6 +14,10 @@ { "resourceAppId": "aeb86249-8ea3-49e2-900b-54cc8e308f85", "resourceAccess": [ + { + "id": "78ff4d1f-611d-4a41-9989-698762b46a0e", + "type": "Role" + }, { "id": "fc946a4f-bc4d-413b-a090-b2c86113ec4f", "type": "Scope" diff --git a/Config/intuneCategories.json b/Config/intuneCategories.json index 07353ca0444bf..59f3636247f9c 100644 --- a/Config/intuneCategories.json +++ b/Config/intuneCategories.json @@ -1 +1 @@ -[{"id":"005ddf8f-da22-4b23-ab02-289f8f6c7960","displayName":"Internet Explorer","description":"Administrative Templates Internet Explorer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["a1fbe395-3b60-475f-8a34-3710d6b2e09f","b491424f-100c-4f84-9b9c-8573b2ff9ac7","d4bf78d5-f6da-463d-85a3-d763e6fbe32b","3f6bb987-17dc-4442-a946-c1c5b1d089d7","f26fe4c2-d073-4e51-90bf-61c4bbdeb4f2","bd63ba46-330b-4c49-bfb7-114e1d0cf5e4"],"platforms":"windows10","technologies":"mdm"},{"id":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","displayName":"Startup, home page and new tab page","description":"Microsoft Edge\\Startup, home page and new tab page","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"0101d1d0-1e54-47b0-a749-62c6bd7ab3da","displayName":"BitLocker Drive Encryption","description":"Administrative Templates\\Windows Components\\BitLocker Drive Encryption","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["949a5b32-bbe6-40f6-9d73-99cf9fafe75f","27e0674a-ea53-4f63-9c2e-fe76aa1021d0","36aafec3-7ffb-4ab9-bef9-b8bb431bf8b3"],"platforms":"windows10","technologies":"mdm"},{"id":"015936bf-8273-4499-bb71-33b385ee7d16","displayName":"Hard Disk Settings","description":"Administrative Templates\\System\\Power Management\\Hard Disk Settings","helpText":null,"parentCategoryId":"62b373da-c112-40f4-9047-9cc3e8d8ab13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"01bbe7c3-10eb-40a3-8387-c74c33c294b1","displayName":"Video and Display Settings","description":"Administrative Templates\\System\\Power Management\\Video and Display Settings","helpText":null,"parentCategoryId":"62b373da-c112-40f4-9047-9cc3e8d8ab13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"01d16911-19a1-4dcb-8089-ffa4781d977c","displayName":"Windows Ink Workspace","description":"Windows Ink Workspace","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"01d16911-19a1-4dcb-8089-ffa4781d977c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"01da0c26-af30-4eb2-a899-7d5e7ecb9738","displayName":"Video and Display Settings","description":"Administrative Templates Power Management Video and Display Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"01f2fac4-fdab-4391-bebe-ebdf6d8fcc77","displayName":"QoS Packet Scheduler","description":"Administrative Templates\\Network\\QoS Packet Scheduler","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["67c06154-a798-44bb-83c8-d706a3709c10","3426ef3d-40f5-474e-a493-4a1545c62348","82d20a08-90b8-4e6d-940a-5574844d1b26"],"platforms":"windows10","technologies":"mdm"},{"id":"023116df-a32c-43b0-a384-d6fe7ad9fabe","displayName":"WinRM Service","description":"Administrative Templates\\Windows Components\\Windows Remote Management (WinRM)\\WinRM Service","helpText":null,"parentCategoryId":"a37dba52-d558-47fb-9d46-a5d3bdc5fdd7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0236af48-9ce0-44d5-b085-de2323d7348e","displayName":"Scripting","description":"Administrative Templates\\System\\App-V\\Scripting","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"023e0367-b563-4fae-8fb6-589c836ee223","displayName":"Add or Remove Programs","description":"Administrative Templates Add or Remove Programs","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"025c640e-51e2-4f04-85e3-a13f30b5e08c","displayName":"Encoding","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\Encoding","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"038b49c9-4f13-4ace-be8d-bd076bffa23e","displayName":"Save","description":"Microsoft Publisher 2016\\Publisher Options\\Save","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"03a966f7-8f8e-4ecb-aab3-055fe907f5ab","displayName":"Security Account Manager","description":"Administrative Templates Security Account Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","displayName":"Manage Restricted Permissions","description":"Microsoft Office 2016\\Manage Restricted Permissions","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0456dcd5-c003-4a8b-80e6-61bacf854330","displayName":"RD Licensing","description":"Administrative Templates Remote Desktop Services RD Licensing","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","displayName":"Microsoft Publisher 2016","description":"Microsoft Publisher 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["9caa3b08-b545-4c21-a3b7-b5d2302c1a81","0cea32b4-28be-4164-ae2a-6db33b9dadb7","c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","c6c1120b-988c-4581-a21c-b9786a821242"],"platforms":"windows10","technologies":"mdm"},{"id":"0497eec4-fe3a-44f2-8caf-b5ab11839893","displayName":"Games","description":"Games","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0497eec4-fe3a-44f2-8caf-b5ab11839893","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"04b46099-4ee5-4def-8e04-569c988057a9","displayName":"Identity and sign-in","description":"Microsoft Edge - Default Settings (users can override)\\ Identity and sign-in","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"05305a87-0b19-41bb-bf1e-0bd92bfcdc16","displayName":"Push To Install","description":"Administrative Templates Push To Install","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"055293ad-c585-40c0-b66c-76ff5cc0a332","displayName":"Microsoft Office SmartArt","description":"Microsoft Office 2016\\Microsoft Office SmartArt","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"05811ceb-2954-426c-8afa-2a53f02480cc","displayName":"Permit or deny screen capture","description":"Microsoft Edge\\ Permit or deny screen capture","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"05a6f86f-dab7-4888-97a1-db3457f00974","displayName":"Writing Assistance","description":"Microsoft Office 2016 Writing Assistance","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"060e7533-6c2f-4ed1-9173-f3de58de4bed","displayName":"Internet Calendars","description":"Microsoft Outlook 2016\\Account Settings\\Internet Calendars","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0696109e-045f-486a-9a6b-ab7877887bed","displayName":"Document Information Panel","description":"Microsoft Office 2016\\Document Information Panel","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"06a85f5b-2614-4467-91cf-4a64d0c9326f","displayName":"Network Usage Rules","description":"Networking > Network Usage Rules","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"06c4a76a-805b-4370-9d80-08e720ab2305","displayName":"View options for time units in 'Project1'","description":"Microsoft Project 2016\\Project Options\\Edit\\View options for time units in 'Project1'","helpText":null,"parentCategoryId":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"07221402-6a9c-4440-ae6f-3217ce5ad8fd","displayName":"Attack Surface Reduction","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Microsoft Defender Exploit Guard\\ Attack Surface Reduction","helpText":null,"parentCategoryId":"49abf969-2a98-4479-b234-6990b152cb21","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0775f21c-9ca1-446d-b1dc-3cea45f15605","displayName":"Files","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\Files","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"07c023d3-0899-40af-a04f-805876d99a9b","displayName":"Microsoft Management Console","description":"Administrative Templates Microsoft Management Console","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["acb49e73-5a6a-479b-9d58-c3cd7f632e9b"],"platforms":"windows10","technologies":"mdm"},{"id":"08677354-6f67-455e-a430-4d8d2fbabe84","displayName":"Web Rtc settings","description":"Microsoft Edge Web Rtc settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"088b8d8d-5f3f-4979-aa18-b3c4b2616a24","displayName":"Sound Recorder","description":"Administrative Templates Sound Recorder","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","displayName":"Disk Quotas","description":"Administrative Templates Disk Quotas","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"08c5f391-e156-4a72-bbb9-3670f2f63a56","displayName":"SmartScreen settings","description":"Microsoft Edge\\SmartScreen settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"0937f5ff-aabc-49a9-a94f-6f98c4702580","displayName":"Qo S Packet Scheduler","description":"Administrative Templates Qo S Packet Scheduler","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["4ca3b8c7-0350-4043-b96d-918f24df0a3b","c87ae066-cc1a-44c9-8645-1db2359f7484","cf968979-f316-47cb-a207-bf9ef28cd1aa"],"platforms":"windows10","technologies":"mdm"},{"id":"098942c3-afe3-40c8-823f-37f0b5b13ad4","displayName":"Remote access","description":"Google Google Chrome Remote access","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"09c02465-dc11-457e-9eac-19fc542e4cda","displayName":"MAPS","description":"Administrative Templates Microsoft Defender Antivirus MAPS","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a1347d2-90c0-407a-baa0-e4859260532a","displayName":"BitLocker","description":"BitLocker","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","displayName":"General options for 'Project1'","description":"Microsoft Project 2016\\Project Options\\General\\General options for 'Project1'","helpText":null,"parentCategoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a803a48-789a-48b0-b928-e52d56ab17f1","displayName":"Wi-Fi Settings","description":"Wi-Fi Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0a803a48-789a-48b0-b928-e52d56ab17f1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a9f982a-3515-4728-a231-fa000eb9e550","displayName":"User Preferences","description":"Preferences > User Preferences","helpText":null,"parentCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","displayName":"Profile Containers","description":"FS Logix Profile Containers","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":["479c2edd-6539-4e1d-96ba-518d6f6264c3","719595d8-ab5d-4418-88aa-8cd55c2964ba"],"platforms":"windows10","technologies":"mdm"},{"id":"0b635a19-976c-4c28-a642-87ede7649bef","displayName":"Playback","description":"Administrative Templates\\Windows Components\\Windows Media Player\\Playback","helpText":null,"parentCategoryId":"22ebd92b-80b6-493d-99d8-3c72f1a0827e","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0bae3158-5f75-4e25-acf4-859d2612f892","displayName":"Cloud Cache","description":"FS Logix ODFC Containers Cloud Cache","helpText":null,"parentCategoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0be23ead-c5f7-4ea5-9ec5-64c05d19cf5d","displayName":"Data Roaming","description":"Managed Settings Data Roaming","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"0be98651-a552-4470-b2dc-71c66a5ce1e6","displayName":"Presentation Services","description":"Microsoft Office 2016\\Present Online\\Presentation Services","helpText":null,"parentCategoryId":"5bf4c2ba-be08-4cda-bf33-d10707580d78","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","displayName":"RD Connection Broker","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host RD Connection Broker","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0c2613c9-a7c7-4458-8b0d-2fff13e2beeb","displayName":"Connections","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Connections","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0cc63077-26e9-4fbd-a343-fd88102efd7e","displayName":"Application Compatibility","description":"Administrative Templates\\Windows Components\\Application Compatibility","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","displayName":"Security","description":"Microsoft Publisher 2016\\Security","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["30da5d88-cf03-41f4-ab55-51ead91b3844"],"platforms":"windows10","technologies":"mdm"},{"id":"0d37dddd-6575-485c-92dd-37a3c23edbf9","displayName":"BitLocker Drive Encryption","description":"Administrative Templates BitLocker Drive Encryption","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["acbc98d1-689b-4f9c-9c5a-e6bbf305e654","a18508d1-fd74-4955-8032-3bd9219a0944","8e6b8d0c-faf6-41e6-8e31-4389a5470caf"],"platforms":"windows10","technologies":"mdm"},{"id":"0d4cf1d9-d8ad-4628-bd71-fa0de6598f28","displayName":"Content settings","description":"Microsoft Edge - Default Settings (users can override)\\Content settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","displayName":"System Logging","description":"System Configuration > System Logging","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","displayName":"Wireless Network Preference","description":"Wireless Network Preference","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0e1122f8-2bbf-475b-bce0-9e43a2f5e475","displayName":"Schedule Scan","description":"Microsoft Defender Schedule Scan","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"0e6c9053-73d6-4c56-9147-53513f6eefd8","displayName":"Windows Update For Business","description":"Windows Update For Business","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","displayName":"Microsoft Project 2016","description":"Microsoft Project 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["1266b519-e436-4698-8ff4-442acc97efd4","e344b25a-2046-4e70-a3b9-1a418613861f"],"platforms":"windows10","technologies":"mdm"},{"id":"0e937777-d01a-4180-a937-c2010451a529","displayName":"Login Window Login Items","description":"Login > Login Window Login Items","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"0ef80736-8b59-4c6a-8bdc-e2b246b30e92","displayName":"Integration","description":"Administrative Templates\\System\\App-V\\Integration","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f05f2c4-3a19-482f-82e8-92a46a4fcbfd","displayName":"Windows Sandbox","description":"Windows Sandbox","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0f05f2c4-3a19-482f-82e8-92a46a4fcbfd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f42fc50-66c8-4b70-9904-64f8d662c930","displayName":"Custom","description":"Microsoft Word 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"740e7a10-3774-4a1c-9970-6907e0f0b848","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f6020d9-278b-4284-894a-bc4a70c8cf32","displayName":"Display Language","description":"Microsoft Office 2016\\Language Preferences\\Display Language","helpText":null,"parentCategoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f6d725e-2c2d-4926-8e78-3d2d5867eef5","displayName":"Win RM Client","description":"Administrative Templates Windows Remote Management Win RM Win RM Client","helpText":null,"parentCategoryId":"364787de-93e4-4fd6-9608-dce1ad8f88c2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"10247787-95ea-4507-93de-dbd166df12b5","displayName":"Legacy Browser Support","description":"Google Google Chrome Legacy Browser Support","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1043e7ed-8651-44b2-b918-7230c0b75a6c","displayName":"Profile settings","description":"Microsoft Edge Profile settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"10835ce3-31c8-4ec6-aa00-c5af48e550a8","displayName":"Virtualization","description":"Administrative Templates App-V Virtualization","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"114356a4-dfc9-44e9-9a62-f1d601d48445","displayName":"Mail Setup","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Setup","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"119ca05b-5f1f-4714-a942-2a76b05d2a7b","displayName":"Lock Down","description":"Lock Down","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"119ca05b-5f1f-4714-a942-2a76b05d2a7b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"11c4cf0f-a03d-4309-93b2-011be4c410d5","displayName":"Screensaver User","description":"User Experience > Screensaver User","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"11d26400-1d13-4dd6-ab4b-cb323494b127","displayName":"Intelligence Settings","description":"Declarative Device Management preview Intelligence Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"120b24dd-c04a-4291-8f24-9c48fcdc1434","displayName":"Cryptography compliance policies","description":"Microsoft Edge Cryptography compliance policies","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12142994-4b30-486c-bab1-9206528b2b96","displayName":"Accessibility settings","description":"Google Google Chrome - Default Settings users can override Accessibility settings","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1219a9c2-dccb-445f-9f90-8e86e2de22d6","displayName":"Windows Remote Shell","description":"Administrative Templates\\Windows Components\\Windows Remote Shell","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1266b519-e436-4698-8ff4-442acc97efd4","displayName":"Project Options","description":"Microsoft Project 2016\\Project Options","helpText":null,"parentCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["db47f067-f435-4095-8b98-aa3805bc0050","84b7f123-e849-40f9-914b-4b97b57bd3b4","9ecb05b7-e942-4b60-9040-d612385f5c67","6ad0e199-ff50-4e86-b22f-b55ef4ff2329","28c4859e-1faa-4b51-96cf-068cb4354093","623d41fb-000e-41d8-b955-373f8c700def","3265b420-4c88-4f7b-92cc-4e23d9452eb1","20ed0d61-bbf7-421e-8926-0921c7ff7e75","8e48532a-ff0e-4422-82e2-6956b6786005","5bd8c27a-0141-4bbf-93f7-214b2389ff2d"],"platforms":"windows10","technologies":"mdm"},{"id":"12a1b259-a0d5-4505-aedf-b8ca811cd5f9","displayName":"Remote Assistance","description":"Administrative Templates\\System\\Remote Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","displayName":"Trusted Locations","description":"Microsoft Access 2016\\Application Settings\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12ec8efa-2dcc-4c0c-9166-72ecc3cd463e","displayName":"Common Open File Dialog","description":"Administrative Templates Common Open File Dialog","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","displayName":"Customizable Error Messages","description":"Microsoft Word 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13123148-c522-437f-b316-d78f5cc0d28d","displayName":"Shared Workspace","description":"Microsoft Office 2016\\Global Options\\Customize\\Shared Workspace","helpText":null,"parentCategoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["725adbdf-1eb8-45c4-8eb1-44747bd1615d"],"platforms":"windows10","technologies":"mdm"},{"id":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","displayName":"AirPlay","description":"AirPlay > AirPlay","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"13467142-14e7-4380-8573-4866e842c7f6","displayName":"Antivirus engine","description":"Microsoft Defender > Antivirus engine","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"135e4013-43b8-4227-99fd-54ddeac4e329","displayName":"Protected View","description":"Microsoft Office 2016\\Security Settings\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"139974ad-f615-442b-b3dc-84a44e3ec663","displayName":"Experience","description":"Experience","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13cc3b63-a150-4cf2-8d76-309975603c8e","displayName":"Loader Override Settings","description":"Microsoft Edge WebView2\\Loader Override Settings","helpText":null,"parentCategoryId":"c945edd8-c865-4932-806d-83752e3f46ad","rootCategoryId":"c945edd8-c865-4932-806d-83752e3f46ad","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13eb248a-4549-4d23-9ada-23b40edf36bf","displayName":"Reminder Options","description":"Microsoft Outlook 2016\\Outlook Options\\Other\\Advanced\\Reminder Options","helpText":null,"parentCategoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","displayName":"Time Providers","description":"Administrative Templates Windows Time Service Time Providers","helpText":null,"parentCategoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13f62499-a266-42c8-a4dc-531efcea55cb","displayName":"Microsoft Edge Dev","description":"Microsoft Edge Update\\Applications\\Microsoft Edge Dev","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"148a6f4e-8816-4c00-87a3-57481c85c331","displayName":"Startup Home page and New Tab page","description":"Google Google Chrome Startup Home page and New Tab page","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"14df2cb2-fc75-43af-87f8-a1fbd56a64e3","displayName":"Kerberos","description":"Kerberos","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"14df2cb2-fc75-43af-87f8-a1fbd56a64e3","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"14fa4ad9-525c-440d-a295-a279c73f97f1","displayName":"Widgets","description":"Widgets","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"14fa4ad9-525c-440d-a295-a279c73f97f1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","displayName":"Enterprise Cloud Print","description":"Enterprise Cloud Print","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","displayName":"Microsoft Lync Feature Policies","description":"Skype for Business 2016\\Microsoft Lync Feature Policies","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1526dde4-6726-470e-aebf-3272ae70a99c","displayName":"Server Manager","description":"Administrative Templates\\System\\Server Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1551f6d3-415c-44a8-b184-393de7c42adf","displayName":"Advanced Error Reporting Settings","description":"Administrative Templates Windows Error Reporting Advanced Error Reporting Settings","helpText":null,"parentCategoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"156f2e6a-6638-4749-9f43-e7acc4aba762","displayName":"Windows Installer","description":"Administrative Templates Windows Installer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"15be55d8-7477-4274-9b09-b775bce68416","displayName":"Software Update Enforce Latest","description":"Declarative Device Management preview Software Update Enforce Latest","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1638d9ec-63d5-4d6b-b1b6-4b0402268e36","displayName":"Tenant Restrictions","description":"Administrative Templates\\ Windows Components\\ Tenant Restrictions","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1653fa6c-aa99-4918-92c7-1df85d8843e1","displayName":"Startup, home page and new tab page","description":"Microsoft Edge - Default Settings (users can override)\\Startup, home page and new tab page","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1671dfc3-a1dd-4178-9093-10fb6b62586a","displayName":"Cryptography","description":"Microsoft Project 2016\\Project Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"623d41fb-000e-41d8-b955-373f8c700def","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1671f10e-7300-46e3-a93f-ef38bf906cb1","displayName":"Mime Sniffing Safety Feature","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Mime Sniffing Safety Feature","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","displayName":"Scareware Blocker settings","description":"Microsoft Edge Scareware Blocker settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"1720d60f-40a6-471c-8e4c-efbacaf46997","displayName":"Cryptography","description":"Microsoft Outlook 2016\\Security\\Cryptography","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff"],"platforms":"windows10","technologies":"mdm"},{"id":"174ffe92-3770-4688-aa21-85b7535cf374","displayName":"Printing","description":"Printing > Printing","helpText":null,"parentCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","rootCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","displayName":"Install and Update Settings","description":"Visual Studio Install and Update Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"176ed477-020a-41af-8859-0605c2caad98","displayName":"Portable Operating System","description":"Administrative Templates\\Windows Components\\Portable Operating System","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"17bc9899-d157-4eac-a949-810b4a841e28","displayName":"Restrict File Download","description":"Administrative Templates Internet Explorer Security Features Restrict File Download","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"17f0fdd3-e292-4ecb-ab5f-e4848e9cae1a","displayName":"Button Settings","description":"Administrative Templates\\System\\Power Management\\Button Settings","helpText":null,"parentCategoryId":"62b373da-c112-40f4-9047-9cc3e8d8ab13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"180b2a03-16d4-43cd-ba84-9b4546753ef4","displayName":"Removable Storage Access","description":"Administrative Templates\\System\\Removable Storage Access","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"18296501-4825-47ea-835d-66a01aba9384","displayName":"Notification bar","description":"Administrative Templates Internet Explorer Security Features Notification bar","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1829cdc1-1bed-4058-9aba-9b778cd3d955","displayName":"Global Preferences","description":"Preferences > Global Preferences","helpText":null,"parentCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"183628a3-d0a5-47de-b444-e132d634ca38","displayName":"Server Settings","description":"Microsoft Excel 2016\\Miscellaneous\\Server Settings","helpText":null,"parentCategoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"184981d4-712b-425e-b0a3-93eac7fbd3ee","displayName":"Consent","description":"Administrative Templates Windows Error Reporting Consent","helpText":null,"parentCategoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"184aa343-0f0b-4bf5-aeeb-42111fedfbbf","displayName":"Internet Communication Management","description":"Administrative Templates\\System\\Internet Communication Management","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["72dfdba4-e7bb-4f09-862c-e003ea763452"],"platforms":"windows10","technologies":"mdm"},{"id":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","displayName":"Remote Assistance","description":"Administrative Templates Remote Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"187e5f4f-a789-4487-a848-7bf0f41597c7","displayName":"Preferences","description":"Preferences","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":["1829cdc1-1bed-4058-9aba-9b778cd3d955","0a9f982a-3515-4728-a231-fa000eb9e550","c7c1ed5a-a2ec-4237-bbf1-d5723f94d033"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"18893f00-c309-4695-bcaf-b66286ad99c1","displayName":"Camera","description":"Camera","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"18893f00-c309-4695-bcaf-b66286ad99c1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"18b972fd-74f2-4345-9449-087c80dd38a3","displayName":"Windows Boot Performance Diagnostics","description":"Administrative Templates Windows Boot Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"18db3d59-661b-47ec-900a-bf75495ca598","displayName":"Regional and Language Options","description":"Administrative Templates\\Control Panel\\Regional and Language Options","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["e50b312c-2bb3-4565-9212-080dba8d3d85"],"platforms":"windows10","technologies":"mdm"},{"id":"191a84f2-13b5-4609-808f-8b743b7f0247","displayName":"Microsoft Outlook","description":"Microsoft Outlook > Microsoft Outlook","helpText":null,"parentCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1942922a-cba9-44c8-871f-3d915c62bd06","displayName":"Help","description":"Microsoft Office 2016\\Help","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1943deba-33f7-4c3d-98c8-6b5319ec98ab","displayName":"Driver Installation","description":"Administrative Templates Driver Installation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1979a12b-2a72-438d-9de7-320d1b38e777","displayName":"Password","description":"Microsoft OneNote 2016\\OneNote Options\\Password","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"19ab385f-14f5-47cd-87b2-f4784eedcdd9","displayName":"Windows Media Digital Rights Management","description":"Administrative Templates Windows Media Digital Rights Management","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"19ba782c-3594-45da-b829-72b54f6d45c7","displayName":"Microsoft OneDrive","description":"Microsoft Office > Microsoft OneDrive","helpText":null,"parentCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1a0386fd-354b-441e-a0d6-1523c209dae7","displayName":"General","description":"Microsoft Publisher 2016\\Publisher Options\\General","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1a056b49-3fb9-4097-b286-c5f493208578","displayName":"Personal Hotspot","description":"Managed Settings Personal Hotspot","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"1a2a4fc8-c54b-4906-a422-7dd51a196211","displayName":"Setup","description":"Administrative Templates Event Log Service Setup","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ae8c95a-5748-4647-80f8-b447e60601a2","displayName":"Add-ins","description":"Microsoft OneNote 2016\\OneNote Options\\Add-ins","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1aef6e33-cb5c-4ad5-b433-c198750bbc98","displayName":"Locked-Down Local Machine Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Locked-Down Local Machine Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1b1be733-8615-4738-8797-c159d4d484be","displayName":"Wireless Display","description":"Administrative Templates\\Network\\Wireless Display","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","displayName":"Preferences","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["2fbb7677-651a-4b62-8b8c-d502ea29936b","decab1d2-3474-4727-87c0-d0bc648f2458","8e7b730f-c3c9-4e04-9e45-ce06be97908c","d0a1763a-5cdf-4672-8596-435ec1d94b54","2b03e224-c77c-4bb0-8491-cec0b64d9a86"],"platforms":"windows10","technologies":"mdm"},{"id":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","displayName":"Excel Options","description":"Microsoft Excel 2016\\Excel Options","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","67eb1dab-7805-41bb-af5a-798dc7e29f23","d1e2bb0d-6c0e-4f40-9f2e-52055edc14b5","5886bba1-bc05-46ca-afbf-66d1b4265ca4","3503e1ba-8168-4b55-92b1-84613292cadc","9215e382-4e7b-4554-8c80-80277136b544","cd1855c4-f7d1-4bed-8d6e-b8c1aab72007"],"platforms":"windows10","technologies":"mdm"},{"id":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","displayName":"Default message text for a reply...","description":"Microsoft Office 2016\\Collaboration Settings\\Default message text for a reply...","helpText":null,"parentCategoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1bfef2c3-a561-4e7a-8f0f-0944bc79c20f","displayName":"Spelling","description":"Microsoft OneNote 2016\\OneNote Options\\Spelling","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","displayName":"Lanman Server","description":"Lanman Server","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ccd3115-55e7-464f-9bb9-d38a92191306","displayName":"Edge Website Typo Protection settings","description":"Microsoft Edge - Default Settings users can override Edge Website Typo Protection settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1cda8821-d9e2-485e-8d78-1829593d41ca","displayName":"BranchCache","description":"Administrative Templates\\Network\\BranchCache","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1d5e7986-870c-444b-bf09-78bbf82a53fa","displayName":"Personal Data Encryption","description":"Personal Data Encryption","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1d5e7986-870c-444b-bf09-78bbf82a53fa","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1d6d392c-8b32-459b-b114-af964a4bbbc5","displayName":"Certificate management settings","description":"Google Google Chrome Certificate management settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1dabc7da-bdf8-4c60-95de-427a4b2cb6bf","displayName":"Digital Locker","description":"Administrative Templates Digital Locker","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1dd655c9-a1f3-4780-befb-cab19922277d","displayName":"Personalization","description":"Personalization","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ed81d90-7326-4d0b-8934-b0a8bdddc5ce","displayName":"App runtime","description":"Administrative Templates\\Windows Components\\App runtime","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ed9f90e-d8b6-413f-bfc2-face955141bc","displayName":"Windows Mobility Center","description":"Administrative Templates Windows Mobility Center","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1f31ae2d-4867-4733-b52c-cecc0128e10c","displayName":"Scheduled Maintenance","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Scheduled Maintenance","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1f5d8243-cb7e-4b52-a12f-5f0e070d2769","displayName":"Virtualization","description":"Administrative Templates\\System\\App-V\\Virtualization","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1fa3b0c3-e453-4ef3-80aa-a7474d8eb354","displayName":"Digital Locker","description":"Administrative Templates\\Windows Components\\Digital Locker","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1fbc29d7-0530-4208-b506-9df648a402e9","displayName":"Voice Roaming","description":"Managed Settings Voice Roaming","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"1fcd72cb-7c09-4e7b-a314-97a88df6e623","displayName":"Recovery Lock Password","description":"Recovery Lock Password","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1fcd72cb-7c09-4e7b-a314-97a88df6e623","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1fddd12c-a630-47f0-9633-638808e228f9","displayName":"Review Tab","description":"Microsoft Word 2016\\Review Tab","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["d79c9f9a-f469-4f39-a66a-6f7d5ee77e81","7bee4dea-82a4-4a03-b903-654b374819b1"],"platforms":"windows10","technologies":"mdm"},{"id":"200c575d-37d9-405b-aa92-c7a3da6f9358","displayName":"User Interface","description":"Administrative Templates\\Windows Components\\Windows Media Player\\User Interface","helpText":null,"parentCategoryId":"22ebd92b-80b6-493d-99d8-3c72f1a0827e","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a","displayName":"Platform Update","description":"Microsoft Defender Platform Update","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"20b71dc7-cf08-4534-9e52-d297dd071ca5","displayName":"Enhanced Phishing Protection","description":"Smart Screen\\ Enhanced Phishing Protection","helpText":null,"parentCategoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","rootCategoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20bacabf-cd07-48be-a184-f0ae76d31e4a","displayName":"Contact Tab","description":"Microsoft Office 2016\\Contact Card\\Contact Tab","helpText":null,"parentCategoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20ceae56-e189-46ec-a440-791ce7454017","displayName":"Printing","description":"Google Google Chrome - Default Settings users can override Printing","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20ed0d61-bbf7-421e-8926-0921c7ff7e75","displayName":"Calculation","description":"Microsoft Project 2016\\Project Options\\Calculation","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","ed137c3d-d7bc-48f3-ad86-ff194fc6820d"],"platforms":"windows10","technologies":"mdm"},{"id":"2108b443-384c-4bb3-9b9f-acb4a754a86a","displayName":"Web Options...","description":"Microsoft Word 2016\\Word Options\\Advanced\\Web Options...","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["d804205d-6c12-4f40-86a0-aa5a5355370f","56e510be-ca39-46a2-9eb2-6f1af6d4b16a"],"platforms":"windows10","technologies":"mdm"},{"id":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","displayName":"Attack Surface Reduction","description":"Administrative Templates Microsoft Defender Antivirus Microsoft Defender Exploit Guard Attack Surface Reduction","helpText":null,"parentCategoryId":"ad84cea3-5664-4e42-a9d6-1446828bea45","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"216de445-a80d-4981-b151-3b4466edc808","displayName":"Extensions","description":"Google Google Chrome Extensions","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"22086dab-6c7f-408f-bd0c-cc34b2ad086d","displayName":"Ctrl+Alt+Del Options","description":"Administrative Templates\\System\\Ctrl+Alt+Del Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"224dc683-c0e0-4783-8ba8-8f02c76d161d","displayName":"Domains","description":"Networking > Domains","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"2257f7e1-3e88-4d4d-a666-437bbe42baca","displayName":"Applications","description":"Device Restriction Applications","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"22a2a407-0f28-481d-bdbe-1f9cb6d589c3","displayName":" EDR preferences","description":"Microsoft Defender EDR preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"22ebd92b-80b6-493d-99d8-3c72f1a0827e","displayName":"Windows Media Player","description":"Administrative Templates\\Windows Components\\Windows Media Player","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["c7c32942-a139-4d7e-a19e-3495d5e372e7","200c575d-37d9-405b-aa92-c7a3da6f9358","0b635a19-976c-4c28-a642-87ede7649bef"],"platforms":"windows10","technologies":"mdm"},{"id":"22f2b16b-e1af-45fa-8d2f-687854b72c02","displayName":"Data Protection","description":"Data Protection","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"22f2b16b-e1af-45fa-8d2f-687854b72c02","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","displayName":"Login","description":"Login","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":["0e937777-d01a-4180-a937-c2010451a529","6efb8802-223a-46a7-b13f-a68f28f8b2c2","9859957e-34f1-4669-9f95-2b7c79fff052","8f831e0a-feb7-4cbb-acc1-2e583f3f4de3"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"2373de26-8270-4e74-a53f-9aeb55d5553c","displayName":"Microsoft AutoUpdate (MAU)","description":"Microsoft AutoUpdate (MAU)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"23c09e06-5bee-4b20-a391-36549bf0f620","displayName":"Signing","description":"Microsoft Office 2016\\Signing","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"23e93393-4a75-44e6-9693-208eedb06976","displayName":"Advanced Error Reporting Settings","description":"Administrative Templates\\Windows Components\\Windows Error Reporting\\Advanced Error Reporting Settings","helpText":null,"parentCategoryId":"d9b7efad-fe18-4c98-925b-c4a5db0f2815","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"23fd467e-24f8-4200-8b19-c6c11afa8926","displayName":"Security","description":"Microsoft Access 2016\\Application Settings\\Security","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["7eaa5e09-e5ab-4051-b557-64a124ae497c","a9edc695-b4a9-4111-b07d-627f934f5a1a"],"platforms":"windows10","technologies":"mdm"},{"id":"2461b964-02f6-4da2-921a-f7e8f868c69d","displayName":"Enhanced Storage Access","description":"Administrative Templates Enhanced Storage Access","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"24b30053-14d2-4430-9966-281e926a6918","displayName":"Trusted Platform Module Services","description":"Administrative Templates Trusted Platform Module Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"24f6d328-64e7-4490-be38-452ac3b61f6f","displayName":"Trusted Catalogs","description":"Microsoft Office 2016\\Security Settings\\Trust Center\\Trusted Catalogs","helpText":null,"parentCategoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"251c6873-bf5b-4d85-8185-3c4973b6f33c","displayName":"Show","description":"Microsoft Project 2016\\Project Options\\View\\Show","helpText":null,"parentCategoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"253fda23-118b-48c7-b24a-27b8c93df41a","displayName":"Macro Security","description":"Microsoft Visio 2016\\Visio Options\\Security\\Macro Security","helpText":null,"parentCategoryId":"2ea63962-4cac-4a5c-9181-e6a364489db0","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2592e8ea-5eb0-482b-b41e-eab92f33ac07","displayName":"Planner Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Planner Options","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"25a84f2d-dbac-457e-b734-bc2605305f2b","displayName":"Cryptography","description":"Microsoft OneNote 2016\\OneNote Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"25df12bc-5ebd-4db2-8930-5d27690f3e60","displayName":"Message Format","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\Internet Formatting\\Message Format","helpText":null,"parentCategoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"264202da-475b-476e-bbc7-3c252f777145","displayName":"Device security group","description":"Device security group","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"264202da-475b-476e-bbc7-3c252f777145","childCategoryIds":[],"platforms":"windows10","technologies":"enrollment"},{"id":"2694014c-e044-45a0-99b1-1694bd01827a","displayName":"User Accounts","description":"Administrative Templates\\Control Panel\\User Accounts","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"269c487f-8902-486a-88dd-db9b9b4454b8","displayName":"Network protection","description":"Microsoft Defender Network protection","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"26c1af84-7c09-4910-8b2f-486072fef710","displayName":"Kiosk Browser","description":"Kiosk Browser","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"26c1af84-7c09-4910-8b2f-486072fef710","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"26dfd0a7-546b-4583-b0c7-85b98ac5a40c","displayName":"Tools | Macro","description":"Microsoft Project 2016\\Project Options\\Security\\Tools | Macro","helpText":null,"parentCategoryId":"623d41fb-000e-41d8-b955-373f8c700def","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"27087ae6-d02f-4b54-a143-6cde89c04989","displayName":"Device and Driver Compatibility","description":"Administrative Templates Device and Driver Compatibility","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2764869c-54a3-462b-bc72-c580621ab6bb","displayName":"Customize Ribbon","description":"Microsoft Visio 2016\\Visio Options\\Customize Ribbon","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","displayName":"Cryptography","description":"Microsoft Excel 2016\\Excel Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"27e0674a-ea53-4f63-9c2e-fe76aa1021d0","displayName":"Operating System Drives","description":"Administrative Templates\\Windows Components\\BitLocker Drive Encryption\\Operating System Drives","helpText":null,"parentCategoryId":"0101d1d0-1e54-47b0-a749-62c6bd7ab3da","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","displayName":"Default message text for a review request...","description":"Microsoft Office 2016\\Collaboration Settings\\Default message text for a review request...","helpText":null,"parentCategoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"28831364-ca54-4f31-acca-1aa0c7a7d3d2","displayName":"Data Recovery","description":"Microsoft Excel 2016\\Data Recovery","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"28ab8eed-623a-4e9b-813e-13256472dbaf","displayName":"Customizable Error Messages","description":"Microsoft PowerPoint 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"28c4859e-1faa-4b51-96cf-068cb4354093","displayName":"View","description":"Microsoft Project 2016\\Project Options\\View","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["70b0e7ef-ceac-4c25-8f9f-5a6bf07163b6","251c6873-bf5b-4d85-8185-3c4973b6f33c"],"platforms":"windows10","technologies":"mdm"},{"id":"290ec637-e780-4e95-9834-6368ac0437d1","displayName":"Power Management","description":"Administrative Templates Power Management","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["3b64e99d-0359-4264-be38-c544c647f493","7226f8a2-c542-471a-8d9e-e0df527325d3","86b4fa22-f6f1-4ca5-8fe4-8788f9b3fd89","01da0c26-af30-4eb2-a899-7d5e7ecb9738","5d03766c-9480-43f2-9e85-461a44c821d4","91c02e14-8848-485d-8844-b9933fa888ec"],"platforms":"windows10","technologies":"mdm"},{"id":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","displayName":"MIME to MAPI Conversion","description":"Microsoft Outlook 2016\\MIME to MAPI Conversion","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"297f09f9-0a48-4058-81b8-66a630a3c0ea","displayName":"Disk NV Cache","description":"Administrative Templates\\System\\Disk NV Cache","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","displayName":"Device and Resource Redirection","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Device and Resource Redirection","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2ac8fe19-ca17-4533-8818-a5e12030de51","displayName":"MSI Corrupted File Recovery","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\MSI Corrupted File Recovery","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2af24920-f611-4f03-99a6-205773869ae6","displayName":"Protected Content","description":"Microsoft Edge Protected Content","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","displayName":"Contact Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Contact Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2b3d275d-4a48-4ac8-9c14-4dc5aa20a80b","displayName":"Network Sharing","description":"Administrative Templates Network Sharing","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2b54b208-5459-4e40-8db1-002cb90495bc","displayName":"Windows Memory Leak Diagnosis","description":"Administrative Templates Windows Memory Leak Diagnosis","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2b8e43c0-e66b-4bec-b20d-54a1f7151212","displayName":"Display","description":"Administrative Templates\\Control Panel\\Display","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","displayName":"Printers","description":"Administrative Templates\\Printers","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2c156b7e-99c8-4a21-a828-4f9b94479b0d","displayName":"Time Zone","description":"Managed Settings Time Zone","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","displayName":"Threats","description":"Administrative Templates Microsoft Defender Antivirus Threats","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","displayName":"Applications","description":"Microsoft Edge Update\\Applications","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":["797ac384-f48e-4567-b931-33a6ce923b94","7b91ab31-7ed5-4de9-bd49-d04303fd3c74","13f62499-a266-42c8-a4dc-531efcea55cb","3bb9ca38-645e-479c-ac5f-01959aec9c30"],"platforms":"windows10","technologies":"mdm"},{"id":"2cbf2609-1f6a-4597-84e2-a57da0ad0472","displayName":"Locale Services","description":"Administrative Templates\\System\\Locale Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2cc013ad-e5a3-42d9-b2b6-2a872a4c086d","displayName":"Session Time Limits","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Session Time Limits","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","displayName":"Passcode","description":"Declarative Device Management (DDM)\\ Passcode","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"2d5a483f-b408-426d-9234-2883eae20afb","displayName":"Tools | Options | General | Web Options...","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["025c640e-51e2-4f04-85e3-a13f30b5e08c","8ee1d8d2-582f-401b-927a-993016f4290d","0775f21c-9ca1-446d-b1dc-3cea45f15605","eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510"],"platforms":"windows10","technologies":"mdm"},{"id":"2d6891a4-ee83-4e55-8e23-09513e1306e4","displayName":"Microsoft Office Document Cache","description":"Microsoft Office 2016\\Microsoft Office Document Cache","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2d842579-300e-4a24-bc42-7c39af62c468","displayName":"File Share Shadow Copy Provider","description":"Administrative Templates\\System\\File Share Shadow Copy Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2d8634c7-19ca-46e0-923d-019ba18ff4e0","displayName":"RD Licensing","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\RD Licensing","helpText":null,"parentCategoryId":"572bc940-42d4-4e00-ac55-012e9b90f6df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2dc7de59-a2b5-4f4a-96a4-597927af0617","displayName":"AutoPlay Policies","description":"Administrative Templates\\Windows Components\\AutoPlay Policies","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","displayName":"Kerberos","description":"Administrative Templates Kerberos","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2e241b46-e5ae-41d7-a559-fe40819e86f4","displayName":"Typosquatting Checker settings","description":"Microsoft Edge\\ Typosquatting Checker settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2e3f0407-6387-41b4-b6c2-ada4354be759","displayName":"Licensing Settings","description":"Microsoft Office 2016 (Machine)\\Licensing Settings","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2e57e23c-4847-4864-8e8e-5f6add1f7a84","displayName":"Windows Color System","description":"Administrative Templates\\Windows Components\\Windows Color System","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2e71c6fd-dafa-444d-9542-55d838331939","displayName":"NTFS","description":"Administrative Templates\\System\\Filesystem\\NTFS","helpText":null,"parentCategoryId":"50fb9f56-84f1-4fa9-83f5-0aa0bca8ff49","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2ea4b701-fcb8-46b2-a83f-c792b861f5ad","displayName":"Accessories","description":"Administrative Templates\\Windows Components\\Tablet PC\\Accessories","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2ea63962-4cac-4a5c-9181-e6a364489db0","displayName":"Security","description":"Microsoft Visio 2016\\Visio Options\\Security","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["f34e3da0-b440-43dc-a368-4fd39646a9c5","253fda23-118b-48c7-b24a-27b8c93df41a"],"platforms":"windows10","technologies":"mdm"},{"id":"2eed22da-106f-4c93-9a45-5ce803b50233","displayName":"Offline Editing","description":"Microsoft Visio 2016\\Visio Options\\Save\\Offline Editing","helpText":null,"parentCategoryId":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f524350-1bdb-4eee-a96d-b656bc2b0d70","displayName":"Sudo","description":"Sudo","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"2f524350-1bdb-4eee-a96d-b656bc2b0d70","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f56761a-8e8b-4788-a589-a73ab91818e6","displayName":"Web Archives","description":"Microsoft Office 2016\\Web Archives","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f6205e9-8680-4b8f-97f3-be12e252e038","displayName":"Track changes and compare","description":"Microsoft Word 2016\\Word Options\\Track changes and compare","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f85405a-7472-44ce-8c05-b59bb54912d5","displayName":"Playback","description":"Administrative Templates Windows Media Player Playback","helpText":null,"parentCategoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","displayName":"Trusted Locations","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2fbb7677-651a-4b62-8b8c-d502ea29936b","displayName":"E-mail Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["897675f9-0d1b-437b-ba0a-584fbd54df95","71f4af65-b7fa-4c54-bf73-19b0c7ffe162"],"platforms":"windows10","technologies":"mdm"},{"id":"304a579b-ff3b-4897-8bb8-5a1dda45356f","displayName":"Schedule options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\Schedule\\Schedule options for Microsoft Project","helpText":null,"parentCategoryId":"db47f067-f435-4095-8b98-aa3805bc0050","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","displayName":"Background Intelligent Transfer Service BITS","description":"Administrative Templates Background Intelligent Transfer Service BITS","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"30da5d88-cf03-41f4-ab55-51ead91b3844","displayName":"Trust Center","description":"Microsoft Publisher 2016\\Security\\Trust Center","helpText":null,"parentCategoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"30fcb92f-4d0c-4dbf-95d0-a86350e9efc6","displayName":"Hotspot Authentication","description":"Administrative Templates\\Network\\Hotspot Authentication","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"31070051-859e-4d27-9df3-c07b8a2d2179","displayName":"Word Options","description":"Microsoft Word 2016\\Word Options","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","dc049161-17c6-411e-906b-a871b33651cd","2f6205e9-8680-4b8f-97f3-be12e252e038","89be4acb-fdf9-447b-ad16-9a5af1d68b8b","ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","f9e53433-d8d9-4eaf-bdf3-d32de60d686e","bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","83087772-6560-4488-a1c5-bb6e4889e868"],"platforms":"windows10","technologies":"mdm"},{"id":"311e1dac-a77c-4bc0-a376-35ad55923b7d","displayName":"Start","description":"Start","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3181c361-f4f0-44ff-82cc-24aac8075843","displayName":"Sound Recorder","description":"Administrative Templates\\Windows Components\\Sound Recorder","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"31d3b4c4-767e-403a-834c-51f3691bbf2b","displayName":"Security Center","description":"Administrative Templates Security Center","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"320ccaa3-a391-4d29-a9c4-594561f4104d","displayName":"Miscellaneous","description":"Microsoft Word 2016\\Miscellaneous","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["b206e4ef-a288-4fb7-a7ee-4a30b4df3b98"],"platforms":"windows10","technologies":"mdm"},{"id":"32180186-7378-4d45-b0cc-c533a124bdbc","displayName":"Access- Denied Assistance","description":"Administrative Templates Access- Denied Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","displayName":"General","description":"Microsoft Project 2016\\Project Options\\General","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["0a6bc3ed-c4cd-4928-bcbf-247369a51515","501e47c0-6c18-4a88-9366-adc0bbc2c9b4"],"platforms":"windows10","technologies":"mdm"},{"id":"32b20540-8fe9-4730-a4b0-ff41f6b13a97","displayName":"Windows System Responsiveness Performance Diagnostics","description":"Administrative Templates Windows System Responsiveness Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","displayName":"Microsoft Office 2016 (Machine)","description":"Microsoft Office 2016 (Machine)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":["5d8272e2-1ed3-4a8d-9555-9a87fa13d078","712d184f-d9ac-45fc-9eea-aade3a22b55e","f0190b73-0d5c-410e-bce1-e03aa1f62ed4","2e3f0407-6387-41b4-b6c2-ada4354be759","8c879ddf-7acf-45f3-81d3-2c78c7a1321b","86dae9f9-7eb1-4566-8558-b63fa2e20fee"],"platforms":"windows10","technologies":"mdm"},{"id":"32ee73d6-947f-45e9-856b-793b584c626d","displayName":"MAPS","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\MAPS","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","displayName":"","description":"Administrative Templates","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"33a43c22-104b-4683-995b-5652cfd5b490","displayName":"Windows AI","description":"Windows AI","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"33a43c22-104b-4683-995b-5652cfd5b490","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"33b9194b-4027-4c23-b662-52f25db7f839","displayName":"International","description":"Microsoft Access 2016\\Application Settings\\International","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"33fb4f49-5c7f-472c-a0f3-e05646a55902","displayName":"Improved Error Reporting","description":"Microsoft Office 2016\\Improved Error Reporting","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3426ef3d-40f5-474e-a493-4a1545c62348","displayName":"DSCP value of conforming packets","description":"Administrative Templates\\Network\\QoS Packet Scheduler\\DSCP value of conforming packets","helpText":null,"parentCategoryId":"01f2fac4-fdab-4391-bebe-ebdf6d8fcc77","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"343eb575-3ac8-4da9-b66d-ce84b84be7c3","displayName":"Project Guide settings","description":"Microsoft Project 2016\\Project Options\\Interface\\Project Guide settings","helpText":null,"parentCategoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3453c694-bc38-4082-9d3d-886e385df927","displayName":"Event Viewer","description":"Administrative Templates Event Viewer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","displayName":"Window Frame Coloring","description":"Administrative Templates Desktop Window Manager Window Frame Coloring","helpText":null,"parentCategoryId":"d52dd970-febb-4891-8eb7-1c8616cfb6cb","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"34c07941-8f52-43ad-b0ca-a7284655afb4","displayName":"Office.com Sharing Service","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Office.com Sharing Service","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3503e1ba-8168-4b55-92b1-84613292cadc","displayName":"Advanced","description":"Microsoft Excel 2016\\Excel Options\\Advanced","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["b90fb0dc-b8c1-4fc3-b9f9-dfbda4b3f03d"],"platforms":"windows10","technologies":"mdm"},{"id":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","displayName":"Editing Languages","description":"Microsoft Office 2016\\Language Preferences\\Editing Languages","helpText":null,"parentCategoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["60ea21c6-4c2b-4510-83f4-3a2d04fd99a0"],"platforms":"windows10","technologies":"mdm"},{"id":"35525ba9-da99-460e-afd3-ba86506b0ba3","displayName":"File Explorer","description":"Administrative Templates\\Windows Components\\File Explorer","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["7c34b514-0fb4-4868-8418-cb9b28f9f6e3","93decccd-de24-4ec4-b21c-e08c14f13576","e21bab5b-308d-4dcd-b6bb-a019e7347373"],"platforms":"windows10","technologies":"mdm"},{"id":"3588f84a-69de-4900-910c-09a5b69e5d99","displayName":"Virtualization Based Technology","description":"Virtualization Based Technology","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3588f84a-69de-4900-910c-09a5b69e5d99","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"35f245bd-8d1f-424c-83de-a80be27a6a4e","displayName":"Desktop Alert","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options\\Advanced E-mail Options\\Desktop Alert","helpText":null,"parentCategoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"361859d9-1382-47c3-b9ec-9251a62fbb25","displayName":"Time Machine","description":"User Experience > Time Machine","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","displayName":"System Policy Control","description":"System Policy","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","childCategoryIds":["64538726-8745-4e7a-b370-332f725b58bf","763525a0-8456-4336-a8d1-392253e8fdd8"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","displayName":"Removed policies","description":"Google Google Chrome Removed policies","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"363982dd-fc96-49ce-a499-f6401f2c212b","displayName":"iSCSI","description":"Administrative Templates\\System\\iSCSI","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["f5e39798-0511-462f-b859-f892fdde4328","b62de64d-03ed-4e09-be5c-5cc93e34ea47","7d7f6a09-2088-4f1f-a1f1-14fbca93a808"],"platforms":"windows10","technologies":"mdm"},{"id":"364787de-93e4-4fd6-9608-dce1ad8f88c2","displayName":"Windows Remote Management Win RM","description":"Administrative Templates Windows Remote Management Win RM","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","0f6d725e-2c2d-4926-8e78-3d2d5867eef5"],"platforms":"windows10","technologies":"mdm"},{"id":"366a0d4a-8f27-44e7-82d0-d2eafe5b6d6f","displayName":"Windows Standby/Resume Performance Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Windows Standby/Resume Performance Diagnostics","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"36aafec3-7ffb-4ab9-bef9-b8bb431bf8b3","displayName":"Fixed Data Drives","description":"Administrative Templates\\Windows Components\\BitLocker Drive Encryption\\Fixed Data Drives","helpText":null,"parentCategoryId":"0101d1d0-1e54-47b0-a749-62c6bd7ab3da","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","displayName":"Google Chrome","description":"Google Google Chrome","helpText":null,"parentCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":["1d6d392c-8b32-459b-b114-af964a4bbbc5","fa2722a8-dcfd-4e14-a429-2b0041642c77","3634c01b-1a85-4f50-9f52-63bc10bf0e39","b811c4fe-7ff0-4bd1-a454-0918d4e2f896","d9432f48-3072-4171-9031-4ebead394151","5900ac65-f656-459c-bd82-1329a862544d","5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","d4ad9168-8c49-45d6-a7e5-86ba990fff3e","ac821e49-1996-4d6c-99d4-9c3c3e4737b6","216de445-a80d-4981-b151-3b4466edc808","da78ddbc-fc94-48f9-8808-4b160d6f1d50","f7486553-9e63-4d63-9423-56e5ffe48700","b46f4e70-d3d1-4177-8e22-62f806d4568c","62499519-97eb-43e7-ae96-d7909c5820d3","59d29716-55b0-4014-a458-38b408ff9530","70498fad-5ddb-4730-8130-d755ff675760","93ed2300-658d-40f3-8211-9295a240579c","8c35f124-e249-43e3-9044-ecc0b0a5855a","f66e6bf2-a437-4d36-b46c-e965b31a5d4f","a5a38799-7bf1-4b83-86fe-62729cd9ed9d","4cd10f38-02cf-40f2-aa87-ad70a2190a1a","f00e9baf-9bbf-48e4-aaac-57410730f016","463e6791-7d54-4964-a36b-63bbedb7d0cd","148a6f4e-8816-4c00-87a3-57481c85c331","4aa852ab-6269-4883-906f-0a0944fa1261","895e0884-6b60-4bb0-b2ab-3a1642103db7","10247787-95ea-4507-93de-dbd166df12b5","098942c3-afe3-40c8-823f-37f0b5b13ad4","b485695b-0fae-41ae-861c-3030769b28df"],"platforms":"windows10","technologies":"mdm"},{"id":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","displayName":"Trust Center","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"85810387-3320-4056-bae2-953beeb246f7","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["42ce9a9b-0574-4b5c-993b-7679de80be47","76ad3567-c6cb-43b5-b91d-a52a34853c03","4d69af55-f100-45fa-92e1-56d46434c647"],"platforms":"windows10","technologies":"mdm"},{"id":"3800661e-5841-4499-8d4e-914527435f59","displayName":"Streaming","description":"Administrative Templates\\System\\App-V\\Streaming","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"394ae912-b5c9-45a0-8883-84791c6acb16","displayName":"RemoteApp and Desktop Connections","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\RemoteApp and Desktop Connections","helpText":null,"parentCategoryId":"572bc940-42d4-4e00-ac55-012e9b90f6df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"394b2dfb-3404-4668-94af-5acc825fcf51","displayName":"System Restore","description":"Administrative Templates\\System\\System Restore","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"395a548d-737b-41fe-8449-c68c51e3a349","displayName":"Input Panel","description":"Administrative Templates Input Panel","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3969f56d-a8b5-4509-86fb-00eb481665fa","displayName":"Advanced Page","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Advanced Page","helpText":null,"parentCategoryId":"586c5c5a-15cd-4592-beae-1709c6daf5b7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"39e4c352-be9c-4e75-8111-8236279c7f1e","displayName":"Cloud Desktop","description":"Cloud Desktop","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"39e4c352-be9c-4e75-8111-8236279c7f1e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3a28f10c-cb75-4f85-871b-87eb9dcd883c","displayName":"TCPIP Settings","description":"Administrative Templates\\Network\\TCPIP Settings","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["f52d9745-eaf4-4e39-84b2-6b32c3b15aa3","d512207c-854d-482d-8e52-26637eef24e3"],"platforms":"windows10","technologies":"mdm"},{"id":"3a901a80-e2b6-470c-9658-d66ba5458370","displayName":"Remote App and Desktop Connections","description":"Administrative Templates Remote Desktop Services Remote App and Desktop Connections","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","displayName":"Certificate management settings","description":"Microsoft Edge Certificate management settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"3afbcb74-88c5-4a41-bdc2-82c117b4e82e","displayName":"Applications","description":"Administrative Templates\\Windows Components\\Microsoft User Experience Virtualization\\Applications","helpText":null,"parentCategoryId":"9e857bed-81f8-4dfc-b049-c93eb68b4064","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","displayName":"Scheduling options for 'Project1'","description":"Microsoft Project 2016\\Project Options\\Schedule\\Scheduling options for 'Project1'","helpText":null,"parentCategoryId":"db47f067-f435-4095-8b98-aa3805bc0050","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","displayName":"Account Management","description":"Account Management","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b64e99d-0359-4264-be38-c544c647f493","displayName":"Sleep Settings","description":"Administrative Templates Power Management Sleep Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b7e16e7-171f-4169-8904-c8483b06700d","displayName":"Custom","description":"Microsoft Excel 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","displayName":"Password manager and protection","description":"Microsoft Edge\\Password manager and protection","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"3bb9ca38-645e-479c-ac5f-01959aec9c30","displayName":"Microsoft Edge","description":"Microsoft Edge Update\\Applications\\Microsoft Edge","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3bbaff1b-7d59-4b9c-ab53-c235d72b2fb0","displayName":"Protection From Zone Elevation","description":"Administrative Templates Internet Explorer Security Features Protection From Zone Elevation","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3c46dc04-e649-41b9-be99-04b771303fdd","displayName":"eSIM","description":"eSIM","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3c7f15ef-a539-411c-93f1-5f97b7bd5519","displayName":"Bluetooth","description":"Managed Settings Bluetooth","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"3ccd987e-bfca-4838-98ea-576de34b3ebe","displayName":"Certain Hours","description":"Certain Hours","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3ccd987e-bfca-4838-98ea-576de34b3ebe","childCategoryIds":[],"platforms":"android,iOS","technologies":"exchangeOnline"},{"id":"3d32fb39-ff23-48d9-9890-c8625d2d21e9","displayName":"Group Policy","description":"Administrative Templates\\Windows Components\\Microsoft Management Console\\Restricted/Permitted snap-ins\\Group Policy","helpText":null,"parentCategoryId":"9e882396-4a1c-4d06-a62d-8d910ded8e7d","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["61205786-952e-489c-91f7-5654a5bde11b","814e9e4d-b838-4747-a257-72390a535d56"],"platforms":"windows10","technologies":"mdm"},{"id":"3db7e884-6077-4b96-ace3-005a6b49ecc0","displayName":"Hyperlink appearance in 'Project1'","description":"Microsoft Project 2016\\Project Options\\Edit\\Hyperlink appearance in 'Project1'","helpText":null,"parentCategoryId":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3deb76aa-8336-4ff9-aa98-4dcaf8901468","displayName":"Shutdown","description":"Administrative Templates\\System\\Shutdown","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3e50e056-24bf-46c3-975f-b0aedbc96329","displayName":"Protection From Zone Elevation","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Protection From Zone Elevation","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3e98c3bc-254c-445f-a1c8-4a93c2e0fcf2","displayName":"Tablet PC Pen Training","description":"Administrative Templates\\Windows Components\\Tablet PC\\Tablet PC Pen Training","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3edb2860-b77b-4240-af16-fb34d45d6ba1","displayName":"Performance","description":"Microsoft Edge\\Performance","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"3f216590-fb12-4f8e-924f-2a6895d94126","displayName":"Folder Home Pages for Outlook Special Folders","description":"Microsoft Outlook 2016\\Folder Home Pages for Outlook Special Folders","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","displayName":"FileVault","description":"FileVault > FileVault","helpText":null,"parentCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"3f61a5fe-8508-44dd-bcf0-83273643026a","displayName":"Smart Screen","description":"Smart Screen","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","childCategoryIds":["20b71dc7-cf08-4534-9e52-d297dd071ca5"],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"3f693856-7cbb-4a1c-93be-0d05aa41059f","displayName":"i SCSI","description":"Administrative Templatesi SCSI","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["60ea8de3-bc6d-4b01-974a-a53860fe4ef6","ca1aedf4-b951-45f5-a77c-dec776a82e21","6c1d9109-e4d1-4718-a537-dd685464fdbe"],"platforms":"windows10","technologies":"mdm"},{"id":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","displayName":"Internet Control Panel","description":"Administrative Templates Internet Explorer Internet Control Panel","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["8d503574-f93a-4277-a30d-19895d46dd13","822bd634-4d01-486e-adad-8085968fd1c4"],"platforms":"windows10","technologies":"mdm"},{"id":"3f8299b3-6803-4576-be08-7c311d04b8b9","displayName":"Attachment Manager","description":"Administrative Templates\\Windows Components\\Attachment Manager","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3f8986f3-195d-4ee5-ae8d-96a007b20883","displayName":"Windows Location Provider","description":"Administrative Templates Windows Location Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3fa63a9d-e22d-4fc8-8464-a13b56461115","displayName":"Predefined","description":"Microsoft Excel 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3fbd3b29-bafd-4adf-89e4-3be612dee275","displayName":"Network settings","description":"Microsoft Edge Network settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"40605d4b-d999-4235-9a5a-59fad165ec51","displayName":"Locked-Down Restricted Sites Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Locked-Down Restricted Sites Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4086190d-2e5b-439d-8426-08492ebb8c9f","displayName":"Local Machine Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Local Machine Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","displayName":"Disk NV Cache","description":"Administrative Templates Disk NV Cache","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"41081a6b-ec9f-4b4f-b6ae-1d4dda162654","displayName":"Folder Redirection","description":"Administrative Templates\\System\\Folder Redirection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4124fc05-5c98-4790-a2a9-4ba2dee3d9b3","displayName":"Explorer Frame Pane","description":"Administrative Templates Explorer Frame Pane","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"41ba590e-9105-4eda-92fb-13c7d34b8eee","displayName":"DC Locator DNS Records","description":"Administrative Templates Net Logon DC Locator DNS Records","helpText":null,"parentCategoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"424a0e73-8002-42e3-b47d-2062fc17c3b3","displayName":"Troubleshooting and Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["439f1603-5241-40c7-a5fe-44ae6744543f","5c1c00f2-def5-4064-925d-aedf4aa0f060","b4272e06-316f-4f9a-a198-93f4168f0c78","366a0d4a-8f27-44e7-82d0-d2eafe5b6d6f","94f6e868-1296-4811-b404-1afa2d50bc7c","2ac8fe19-ca17-4533-8818-a5e12030de51","78b3d753-d84d-496b-a93c-d577ab5865bd","8eb61398-1074-4fa0-8bd4-04d751a9ccad","9c815001-eace-4aa6-a929-14af0a46aaf5","a24e6384-a862-4d0e-8f6c-eb99e5f6a9db","1f31ae2d-4867-4733-b52c-cecc0128e10c","7bc264db-6da2-4c6b-a357-aec47c717737","a4f5cedd-a8f7-4def-b8b6-8fbf9ce9e0d8","f783d1ea-2f9b-4fcb-96cc-fb455cfe69f9"],"platforms":"windows10","technologies":"mdm"},{"id":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","displayName":"Application Compatibility","description":"Administrative Templates Application Compatibility","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"428f107c-2167-4bc2-9293-8f1d6728a0c5","displayName":"Scan","description":"Administrative Templates Microsoft Defender Antivirus Scan","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","displayName":"AirPrint","description":"Printing > AirPrint","helpText":null,"parentCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","rootCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"42a6198f-bdec-402e-b619-315400b65488","displayName":"Software Update","description":"Declarative Device Management (DDM) Software Update","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"42ce9a9b-0574-4b5c-993b-7679de80be47","displayName":"Protected View","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","displayName":"Telemetry Dashboard","description":"Microsoft Office 2016\\Telemetry Dashboard","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","displayName":"SharePoint Lists","description":"Microsoft Outlook 2016\\Account Settings\\SharePoint Lists","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43057320-7058-46d5-86f9-a56c80bbf8b9","displayName":"Private Network Request Settings","description":"Microsoft Edge\\ Private Network Request Settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"431c3b32-abe7-4534-81a1-9f10c8e0c512","displayName":"Scan","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Scan","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4331c310-93b0-4383-8c55-acd653f37f80","displayName":"Network Inspection System","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Network Inspection System","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","displayName":"Microsoft Edge - Default Settings (users can override)","description":"Microsoft Edge - Default Settings (users can override)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":["04b46099-4ee5-4def-8e04-569c988057a9","6f1386e5-148d-4dc3-84d1-79df721e3233","a7b038e5-3af5-41fe-919e-e8befe83a9a5","fea97af7-df89-4fde-8e2b-f8e7f7b6b741","48965ad9-3011-4722-855b-7179fef89954","1653fa6c-aa99-4918-92c7-1df85d8843e1","6b71fbf6-7156-471a-b488-3eece04bda86","7db75ddb-f702-49f8-ae2b-991d1afd2d17","a877a2ff-f144-421f-814c-593e972a8a20","1ccd3115-55e7-464f-9bb9-d38a92191306","6fafeb5c-65ce-4993-b421-46e60da69131","acabc66f-5faf-4a13-af32-322ccfc1a5b3","70dd505d-40d4-4685-b639-67efc9274ec4","8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","b96b63eb-0292-4a73-85d7-c68d330c109e","0d4cf1d9-d8ad-4628-bd71-fa0de6598f28"],"platforms":"windows10","technologies":"mdm"},{"id":"439f1603-5241-40c7-a5fe-44ae6744543f","displayName":"Application Compatibility Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Application Compatibility Diagnostics","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"439f715e-5511-44fd-9a0f-644ba7cc6baf","displayName":"Logon","description":"Administrative Templates Logon","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43eca758-22c0-4625-8f12-85a8a34ea8b1","displayName":"Windows Logon Options","description":"Administrative Templates Windows Logon Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43fc9dcc-1e66-4108-bded-2d005eeb7ccb","displayName":"Microsoft Edge WebView","description":"Microsoft Edge Update\\Microsoft Edge WebView","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"441d6cc4-e51f-453e-a44d-8394509415be","displayName":"Predefined","description":"Microsoft Publisher 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"9caa3b08-b545-4c21-a3b7-b5d2302c1a81","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"444409a4-8b03-402d-91d0-1cd9565fb0fb","displayName":"Windows Color System","description":"Administrative Templates Windows Color System","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","displayName":"Business Data","description":"Microsoft Office 2016\\Business Data","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["952f69c8-2644-48df-976b-01fd624cbb3a","a6e0cee7-34a0-4ca2-b4da-f819a057b532","c72d9f00-d625-43ec-add4-514891035839"],"platforms":"windows10","technologies":"mdm"},{"id":"44774d3d-387b-4fa7-8de4-d82b039c06d1","displayName":"Display","description":"Microsoft OneNote 2016\\OneNote Options\\Display","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4479c9b6-8e08-424f-a20a-2058126dc048","displayName":"Data Collection and Preview Builds","description":"Administrative Templates\\Windows Components\\Data Collection and Preview Builds","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"449201b6-5002-42d1-85ed-d288fb6552da","displayName":"Smart Documents (Word, Excel)","description":"Microsoft Office 2016\\Smart Documents (Word, Excel)","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","displayName":"Internet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Internet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"44e27b70-4bdb-4aec-a75d-0568a1edc332","displayName":"Predefined","description":"Microsoft Word 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"740e7a10-3774-4a1c-9970-6907e0f0b848","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4560c525-12a1-4536-9cca-338330e58389","displayName":"Add-on Management","description":"Administrative Templates Internet Explorer Security Features Add-on Management","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"45a89c1f-0a34-4f78-b28f-d30b623fa423","displayName":"Identity and sign-in","description":"Microsoft Edge\\ Identity and sign-in","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"45d15759-2add-40db-9294-d1b391515dba","displayName":"Folder Redirection","description":"Administrative Templates Folder Redirection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","displayName":"Carddav","description":"Accounts > CardDAV","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"463e6791-7d54-4964-a36b-63bbedb7d0cd","displayName":"Microsoft Active Directory management settings","description":"Google Google Chrome Microsoft Active Directory management settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"46af3391-ed6d-4ada-aef7-02dac2a1b136","displayName":"Xsan","description":"Xsan > Xsan","helpText":null,"parentCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","rootCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"46eaa2b7-341b-4e39-be21-c3ea09dd5778","displayName":"Microsoft Edge Web View2 Runtime","description":"Microsoft Edge Update Microsoft Edge Web View2 Runtime","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"476e0bfc-ddb6-4612-8446-bed86e875141","displayName":"Fault Tolerant Heap","description":"Administrative Templates Fault Tolerant Heap","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"478ed057-8ee7-4dd2-8276-06dad8f85397","displayName":"Services","description":"Microsoft Office 2016\\Services","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["a5607145-2bd3-4473-a8ee-d7fa5c2f2675"],"platforms":"windows10","technologies":"mdm"},{"id":"479c2edd-6539-4e1d-96ba-518d6f6264c3","displayName":"Container and Directory Naming","description":"FS Logix Profile Containers Container and Directory Naming","helpText":null,"parentCategoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"486dc66e-960c-4622-b3cb-3ff9a2d434eb","displayName":"Device Installation","description":"Administrative Templates\\System\\Device Installation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["979412d7-6716-440c-9a64-5889026d73da"],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"486f25cc-c865-446e-95b2-c5b061883a7a","displayName":"I Pv6 Transition Technologies","description":"Administrative Templates TCPIP Settings I Pv6 Transition Technologies","helpText":null,"parentCategoryId":"785c6df2-c6d0-4d6e-bd73-c3b62caca754","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"48965ad9-3011-4722-855b-7179fef89954","displayName":"Games settings","description":"Microsoft Edge - Default Settings users can override Games settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"48b8705b-58a8-4504-ab7a-2704980f4577","displayName":"Microsoft Defender","description":"Microsoft Defender","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":["d40a32e1-ab3e-4cbc-aa03-4766792e563e","67cd904c-78e0-4e77-9dd4-c713b21763f3","5c4df3be-80b0-40cc-a8c8-0258120b0de5","20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a","269c487f-8902-486a-88dd-db9b9b4454b8","22a2a407-0f28-481d-bdbe-1f9cb6d589c3","13467142-14e7-4380-8573-4866e842c7f6","b77a3a7b-6fab-4240-b5c3-852aa78781d5","a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","64c8233f-3057-4485-b902-d71a312318d7","d2191717-e304-46f7-bcc0-55e6477026c9","93099bd4-c685-434b-9d72-f0cb6db5e753","0e1122f8-2bbf-475b-bce0-9e43a2f5e475"],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"48be5f9d-4941-4189-8015-dd78f87aacd5","displayName":"Administrative Templates","description":"Administrative Templates","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["07c023d3-0899-40af-a04f-805876d99a9b","180b2a03-16d4-43cd-ba84-9b4546753ef4","6bed088c-c9b0-4149-b26f-df0c247cdb5b","78d3d93f-03d0-4fa0-be56-be4bca0a7b3b","87e607d8-500d-4dba-a58f-d7695945c973","a7e7529f-1030-41da-8b4d-024e1c08bbac","99ba9e42-9872-4a03-a615-fc4a4cebc067","c01c7d3f-ace1-48bf-abce-e8a02ba877ab","634e4243-284b-4cb7-a7e6-08ca7e262937","c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","909339a5-8f04-4fa2-8807-5d38c83ef547","08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","f3027ba5-9a2f-42c6-9872-ec21f726929c","395a548d-737b-41fe-8449-c68c51e3a349","d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","5dcea340-0469-4f43-b270-a49ed0597201","5371d50c-0aaa-425a-a075-2cb1c59968b9","03a966f7-8f8e-4ecb-aab3-055fe907f5ab","088b8d8d-5f3f-4979-aa18-b3c4b2616a24","50fb9f56-84f1-4fa9-83f5-0aa0bca8ff49","41081a6b-ec9f-4b4f-b6ae-1d4dda162654","2cbf2609-1f6a-4597-84e2-a57da0ad0472","53936d6e-5445-4897-8a40-e3f810ea50c4","b49cb414-bdfb-49d4-af5d-176ded4f9591","6b87c5da-cfd9-44bc-be05-ed08eb2144c7","fff51673-04b8-4277-98ef-4baffbd8d192","444409a4-8b03-402d-91d0-1cd9565fb0fb","cef993dc-bf18-44f7-8e9f-465ef1a0f144","156f2e6a-6638-4749-9f43-e7acc4aba762","bd04d2ce-3275-496c-8cc1-e17ab19888a3","cebd5934-9dfe-4278-966d-b9d880cb30e7","dbb76878-34a9-4f87-bbc6-4de7ea223ff4","e6b767af-2ce1-4c91-9360-15abbb0bf3bc","2b54b208-5459-4e40-8db1-002cb90495bc","2d842579-300e-4a24-bc42-7c39af62c468","32b20540-8fe9-4730-a4b0-ff41f6b13a97","73a3a483-dcba-4b34-b7cb-9c68c871864c","8280dcb9-f2bc-417b-b4ef-cd6c35398f94","8d27fb75-5aeb-44f0-aab2-064cc4b9ecd6","ac0a894c-173a-48fc-b961-901f28463c77","023e0367-b563-4fae-8fb6-589c836ee223","76bbc368-9d0b-4aa7-b8e2-2dcfd864b9ee","2461b964-02f6-4da2-921a-f7e8f868c69d","98dc5bd0-2b16-4263-ba2f-62115b680017","edd1e620-09e1-47ea-abc8-1e241a174ed9","439f715e-5511-44fd-9a0f-644ba7cc6baf","d982a1ef-84be-4832-99d4-8b71a4644b74","dad3971c-b07b-461b-8ead-6eda80ee57e1","b524d6e2-75bc-4409-ae3d-07605707d7ee","751cf9ec-7214-4b38-a09e-24922684bd8f","dab7104a-b79c-4318-afb0-5d5cfed9caa9","0937f5ff-aabc-49a9-a94f-6f98c4702580","c6a912c5-0334-40fb-8dc5-f2d2547b8071","fe3cb879-8869-4163-91d7-e432abd75da8","b6bb653a-73f0-42f4-b097-1ce556310904","930d2960-3f70-48ca-9ead-b65a5a037c07","5161db41-7947-49ea-b9b3-dd92539e6783","43eca758-22c0-4625-8f12-85a8a34ea8b1","d4c9d046-a8c0-46f0-bd62-bc4d1614e891","18b972fd-74f2-4345-9449-087c80dd38a3","27087ae6-d02f-4b54-a143-6cde89c04989","6c7168c3-6f34-4086-af0b-ed0b74301dc9","734bed4f-be52-46ef-ae60-8fd195dc8f4d","93c28398-faef-4ca5-9667-f5ed004da32c","3334730b-b9f7-4c99-bde8-57f6b2cd826f","32180186-7378-4d45-b0cc-c533a124bdbc","425669eb-3a49-43d1-98a5-0fcc5b04ffcb","56fdfd66-f34d-4bf8-b951-f130114ffb3d","736134cb-4d82-427a-97b7-d219ac6a22f0","9b894b32-3697-4a83-9731-3db2a35455ad","cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","ad47f904-ede2-4b12-849e-bf751d88abf5","c859dc1a-fdeb-4591-af97-79d078ee715b","f14fcb64-a868-4531-a3b4-c3cdf03c2b99","476e0bfc-ddb6-4612-8446-bed86e875141","72972c43-36a3-4034-8cc8-334c99087798","005ddf8f-da22-4b23-ab02-289f8f6c7960","3f693856-7cbb-4a1c-93be-0d05aa41059f","68a3b82d-d1f4-422d-bfee-2168ec260ad7","dc16dbf0-aac8-4ff3-a546-1ddb55650f47","1851afa1-5177-4268-8dfc-5b5e1a17ff7f","31d3b4c4-767e-403a-834c-51f3691bbf2b","daf3f2c8-f6a5-40bd-96b3-2c6a28931614","c08e929f-742a-4cd8-a7e6-9a3d170fe020","d9f5ccc9-5180-43b7-9c81-89ac3364ce00","dd9a3dad-5851-4899-a5c1-c23318986846","f96201d4-894e-4a72-87fb-22146039a802","364787de-93e4-4fd6-9608-dce1ad8f88c2","65873bfe-2798-42fc-ae33-02295b23b3d3","8e19ed1e-e870-4769-bd6f-321f6f47023b","4d36a1f3-29f9-45af-9480-32891a0bf8ef","e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","4124fc05-5c98-4790-a2a9-4ba2dee3d9b3","9dbd66e3-4544-4ca8-a118-272c874bc684","e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","8c30a64e-ad24-47a0-97a8-52320360fd88","643081a4-132d-463e-9d86-c8650cb2a011","6424714c-e50a-4b53-acbf-8739825ebf0b","2becddf1-d8ea-49ec-8560-c8c401faa9bb","05305a87-0b19-41bb-bf1e-0bd92bfcdc16","297f09f9-0a48-4058-81b8-66a630a3c0ea","363982dd-fc96-49ce-a499-f6401f2c212b","fe65603b-1980-446b-ae17-516eb885c6be","785c6df2-c6d0-4d6e-bd73-c3b62caca754","abf781d7-1179-4f24-8d01-5611db14eddc","7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","8eed5d21-a5e9-4bc7-b2df-4526af3e2726","be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","4dd8280d-6c01-4a06-bfd1-e1cb4c529494","f14074a2-de74-48df-b273-48791217ef4d","f926f6e3-1bd6-4259-ae7c-e14108568882","22086dab-6c7f-408f-bd0c-cc34b2ad086d","6cd02266-a42f-4675-b83e-37360dbf3c68","71f349a7-1ca3-4945-8c7d-fd68df3759ac","1dabc7da-bdf8-4c60-95de-427a4b2cb6bf","75e080fb-3ed7-4a73-a6e0-eb93f0119d68","d0e46713-238c-42b7-a996-653cf952c367","7d331987-7e2d-4975-b23b-d99a5af26ddf","b3b2fc04-4b88-4a1c-8370-04573019eebe","b40cfb22-8f17-4317-bcbb-c1c871497446","94a92db4-8704-487b-b0c5-c15d6ac20e6d","5be35eeb-62e9-4317-8804-018a9dd31149","60b55db1-53fc-45ea-93d3-e4372b1e19a5","deadde1d-7e7f-4577-bd6e-fc237c3854c5","bc4f0cce-a5cc-44c9-9e50-b504e09e7eb1","80ed7629-87dd-4bb1-8ea0-555f20d3b156","bedf20d1-1f5a-4840-8458-6d0fa974b664","62b373da-c112-40f4-9047-9cc3e8d8ab13","9329c2bd-9e56-4394-9c89-5726e8b76f2f","394b2dfb-3404-4668-94af-5acc825fcf51","1ed9f90e-d8b6-413f-bfc2-face955141bc","b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","87667b72-85ce-48c2-8023-e6db7f5fe739","0d37dddd-6575-485c-92dd-37a3c23edbf9","184aa343-0f0b-4bf5-aeeb-42111fedfbbf","24b30053-14d2-4430-9966-281e926a6918","99b4ac32-50b5-4659-a7a1-94bc708ae71a","b6d13875-fd8e-41a0-a712-3dab8b75b93f","7a3a7335-4837-4bc5-9282-448402a05d89","e3ca94a7-e506-4133-8fae-41931dc863a5","86e78a4b-706a-4ec8-be90-439461abb29d","cc13d92c-673f-4af7-9748-50342fc8795a","45d15759-2add-40db-9294-d1b391515dba","2de362c7-2c4a-4b24-bda3-f82cb6ed5990","50e243ad-0e21-43f5-b5dc-31ec61ee43d0","4beed579-3d9c-4c6d-9e88-e7df5e2b4613","be9bdbec-b52e-4174-9c5b-cf765dee855b","a24f4ab6-289a-450a-b438-1c4bb1214942","df0be435-d790-485a-b355-6f00eae29511","12a1b259-a0d5-4505-aedf-b8ca811cd5f9","ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","3f8986f3-195d-4ee5-ae8d-96a007b20883","f69e6993-2e88-4938-bfe5-cea9ab21a858","7f363efe-1ea5-4eb8-baf7-8c34456b43fc","86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","a57b27b6-48e0-42b2-812a-2be86c113a0c","9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","788355e5-e113-4b17-ada9-fb5ef38bffa1","40c593b9-63cf-4b10-ad26-1ceb7c9491fe","3453c694-bc38-4082-9d3d-886e385df927","88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","6f0e6df6-8654-4b57-b1d5-2160c5a0a54e","c48917c1-fd99-405f-b1d2-9dfec169e5d8","9aaa7ee2-727d-426f-8a2b-6b10a4cd084f","e042b102-b12c-48d1-86ef-f6d296da5b95","902f5df1-31d6-44ee-ba95-2561199db35f","5c9a2f21-d3a8-4295-a803-e0535aa29489","3deb76aa-8336-4ff9-aa98-4dcaf8901468","90e3acc6-80d5-41b4-8141-a8620a211c0e","f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","c9a65baa-de10-4818-97a2-b61babb28060","cae68a5f-9d1e-44e8-a34b-6a390b88c451","ffd1a98f-0fac-47fe-813f-7510d0dacbc3","424a0e73-8002-42e3-b47d-2062fc17c3b3","53ba922e-db4d-489c-b5ab-dbc4b8321206","e972d9fe-a9b7-4a65-a88f-0958fab19584","12ec8efa-2dcc-4c0c-9166-72ecc3cd463e","5536b5f4-3d31-4290-acea-9bef323bb83d","60b898a9-0490-4599-b7f1-3cd451236266","290ec637-e780-4e95-9834-6368ac0437d1","f1278d6b-60ec-4369-88cf-21df47caaec6","f8bb78a3-d1e4-4c5d-8b0a-904a83830519","9b0b8f3b-8e08-4083-9e2b-2e6bfeb01f83","f4fd69bc-8622-411d-91bb-0e214f8fb112","1526dde4-6726-470e-aebf-3272ae70a99c","e740736f-75f9-481d-990c-02018abc2ea5","30918d48-dafd-4b25-be63-70f6c7ba8a3d","5c3d081f-6f7c-4650-8a40-200f44eb4794","6e1431f2-131e-4cf2-bb60-87b889f1d11b","1943deba-33f7-4c3d-98c8-6b5319ec98ab","5133d5ea-1a12-494f-afb2-5cfaf41d9518","6d4184ab-a66c-47f1-b54e-af55f654e2a5","2b3d275d-4a48-4ac8-9c14-4dc5aa20a80b","a34ade49-964d-407c-9f60-2e8cd9dfef05","19ab385f-14f5-47cd-87b2-f4784eedcdd9","486dc66e-960c-4622-b3cb-3ff9a2d434eb","76c53aab-0288-4ac1-b399-0104e04c6457","58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","d52dd970-febb-4891-8eb7-1c8616cfb6cb","8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","e50acc0f-d177-4803-aa31-fc97eeb60ff2"],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"48cb2bee-74be-4165-bc19-89c5b1c50c00","displayName":"Email","description":"Email","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"48f508a5-5a2c-4d20-8d89-2d352a209907","displayName":"Reporting","description":"Administrative Templates\\System\\App-V\\Reporting","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"49abf969-2a98-4479-b234-6990b152cb21","displayName":"Microsoft Defender Exploit Guard","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Microsoft Defender Exploit Guard","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["98c9cd71-f6eb-4dfd-b045-85c7e0b44487","07221402-6a9c-4440-ae6f-3217ce5ad8fd"],"platforms":"windows10","technologies":"mdm"},{"id":"49d75a11-64c6-43d1-bc25-0ab156ff4216","displayName":"Microsoft Defender Antivirus","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["32ee73d6-947f-45e9-856b-793b584c626d","c4665793-15ea-44c9-bd0a-d542b3915fe0","5fe14828-4e5b-42ae-87b2-89a579045d1e","4331c310-93b0-4383-8c55-acd653f37f80","4f48b5aa-e887-49ea-a16e-3bb379ccc47c","ad100c6c-9a9a-42cf-8f42-b31c406c1a56","49abf969-2a98-4479-b234-6990b152cb21","a0f1f801-7fce-427c-b5e2-6c6b30065fa5","e06fb472-94c1-4dd9-afdf-6bb2ddaa3dc6","d99ac221-1000-44d8-9ab4-5cdac69562ed","edba50d5-da3c-48cb-8e50-381ad0bfaaaf","431c3b32-abe7-4534-81a1-9f10c8e0c512","eb5baf57-86c8-4bfa-ac3a-53025686e37c"],"platforms":"windows10","technologies":"mdm"},{"id":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","displayName":"Time Language Settings","description":"Time Language Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","displayName":"Firewall","description":"Firewall","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"4a7b0e92-ba43-46aa-96e8-c5839dbcb524","displayName":"Note Flags","description":"Microsoft OneNote 2016\\OneNote Options\\Note Flags","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4a832199-a841-4b6a-84fa-51365902a742","displayName":"Places Bar Locations","description":"Microsoft Office 2016\\File Open/Save dialog box\\Places Bar Locations","helpText":null,"parentCategoryId":"92be4fc7-8095-441c-b52b-9861c21bc337","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4aa852ab-6269-4883-906f-0a0944fa1261","displayName":"Allow or deny screen capture","description":"Google Google Chrome Allow or deny screen capture","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4ad00da1-5ed6-47d8-aef3-70f5bcbbbc77","displayName":"Network Provider","description":"Administrative Templates\\Network\\Network Provider","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","displayName":"Customizable Error Messages","description":"Microsoft Office 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4b2f3557-98e9-48d2-9b78-bcb100f72372","displayName":"Sleep Settings","description":"Administrative Templates\\System\\Power Management\\Sleep Settings","helpText":null,"parentCategoryId":"62b373da-c112-40f4-9047-9cc3e8d8ab13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4b540860-0858-48f4-8830-18383bb1766f","displayName":"Licensing","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Licensing","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","displayName":"Scripts","description":"Administrative Templates Scripts","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4c604a0e-9339-4c01-9536-b689bd0abe5f","displayName":"Remote Desktop Connection Client","description":"Administrative Templates Remote Desktop Services Remote Desktop Connection Client","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","displayName":"DSCP value of conforming packets","description":"Administrative Templates Qo S Packet Scheduler DSCP value of conforming packets","helpText":null,"parentCategoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4cd10f38-02cf-40f2-aa87-ad70a2190a1a","displayName":"Protected Content","description":"Google Google Chrome Protected Content","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","displayName":"Credentials Delegation","description":"Administrative Templates Credentials Delegation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4d69af55-f100-45fa-92e1-56d46434c647","displayName":"File Block Settings","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4dae3032-1f16-4ace-911b-a957db0b8089","displayName":"AutoFormat as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type","helpText":null,"parentCategoryId":"dc049161-17c6-411e-906b-a871b33651cd","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["b6cafb2c-81be-40cf-90d8-788f713f7099","e8ce968b-91cb-4301-ba98-b37d42bc5213","62492a4c-fd70-4275-ae5e-d60e200e3553"],"platforms":"windows10","technologies":"mdm"},{"id":"4dd8280d-6c01-4a06-bfd1-e1cb4c529494","displayName":"Wireless Display","description":"Administrative Templates Wireless Display","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","displayName":"Customize","description":"Microsoft Office 2016\\Global Options\\Customize","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["13123148-c522-437f-b316-d78f5cc0d28d"],"platforms":"windows10","technologies":"mdm"},{"id":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","displayName":"RSS Feeds","description":"Microsoft Outlook 2016\\Account Settings\\RSS Feeds","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e4deef0-4528-47d5-8869-4143c506f18b","displayName":"Custom","description":"Microsoft Visio 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"c67c9e69-6e69-4b63-868c-3b3df5d17e47","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e62ada2-f091-49e1-99dd-ffdf5cf558cd","displayName":"General Options","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\General Options","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e8db19c-cb8e-4361-8849-1d435d50bb66","displayName":"Handwriting","description":"Handwriting","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4e8db19c-cb8e-4361-8849-1d435d50bb66","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f081af6-7b21-44fc-8dd9-d4e0a61a474d","displayName":"Control Policy Conflict","description":"Control Policy Conflict","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4f081af6-7b21-44fc-8dd9-d4e0a61a474d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f29ef5c-6ca0-4b09-893f-01755a670877","displayName":"System Services","description":"System Services","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4f29ef5c-6ca0-4b09-893f-01755a670877","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f48b5aa-e887-49ea-a16e-3bb379ccc47c","displayName":"Threats","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Threats","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f671de2-9777-4969-acf3-8d90c733434c","displayName":"Escrow Certificates","description":"Microsoft Office 2016\\Security Settings\\Escrow Certificates","helpText":null,"parentCategoryId":"50b4bc60-802c-477a-9366-80e09154595f","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4fc4d2f3-35ee-43ec-a033-ef78da571e70","displayName":"Smart Card","description":"Administrative Templates\\Windows Components\\Smart Card","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"500d2bb1-5186-447c-818f-401f2d9065ce","displayName":"Windows Logon","description":"Windows Logon","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"500d2bb1-5186-447c-818f-401f2d9065ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5011ca61-1a58-42da-9c66-7763236acc84","displayName":"Streaming","description":"Administrative Templates App-V Streaming","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"501b5a30-253c-48b7-ab40-de1d100e4358","displayName":"Microsoft Teams","description":"Microsoft Teams","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"501b5a30-253c-48b7-ab40-de1d100e4358","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","displayName":"General options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\General\\General options for Microsoft Project","helpText":null,"parentCategoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","displayName":"Tablet PC","description":"Administrative Templates\\Windows Components\\Tablet PC","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["cc8a93d5-503f-4d46-ac42-65e169642237","e8514a44-e44c-47af-a714-7697ebb2baf7","2ea4b701-fcb8-46b2-a83f-c792b861f5ad","90bbab80-ecf0-47c6-bf01-76b26a3dc503","aa67f0c0-4eb0-492f-a528-decd3e256a22","3e98c3bc-254c-445f-a1c8-4a93c2e0fcf2","917d0fb9-b5dd-401b-982b-1d32f6e0a306","575369a6-17a2-435e-81d4-71772e7d55b5"],"platforms":"windows10","technologies":"mdm"},{"id":"508b2c0e-f572-4a50-93bf-566e5b827c0e","displayName":"Printers","description":"Printers","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"508b2c0e-f572-4a50-93bf-566e5b827c0e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"50b4bc60-802c-477a-9366-80e09154595f","displayName":"Security Settings","description":"Microsoft Office 2016\\Security Settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["512f133b-9d53-46b8-834f-52501f9b6527","4f671de2-9777-4969-acf3-8d90c733434c","efb8c441-bad5-4e2f-b07c-5ac299cf3d22"],"platforms":"windows10","technologies":"mdm"},{"id":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","displayName":"Lanman Server","description":"Administrative Templates Lanman Server","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"50fb9f56-84f1-4fa9-83f5-0aa0bca8ff49","displayName":"Filesystem","description":"Administrative Templates\\System\\Filesystem","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["2e71c6fd-dafa-444d-9542-55d838331939"],"platforms":"windows10","technologies":"mdm"},{"id":"512f133b-9d53-46b8-834f-52501f9b6527","displayName":"Digital Signatures","description":"Microsoft Office 2016\\Security Settings\\Digital Signatures","helpText":null,"parentCategoryId":"50b4bc60-802c-477a-9366-80e09154595f","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","displayName":"Hardware Buttons","description":"Administrative Templates Hardware Buttons","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5161db41-7947-49ea-b9b3-dd92539e6783","displayName":"Start Menu and Taskbar","description":"Administrative Templates\\Start Menu and Taskbar","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["cb98f9d4-d921-4a8b-a763-cf69ce2ada62"],"platforms":"windows10","technologies":"mdm"},{"id":"517e55f5-729f-4b4d-9555-33baa95a0e5a","displayName":"Application Guard","description":"Microsoft Office 2016\\Security Settings\\Trust Center\\Application Guard","helpText":null,"parentCategoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"51e0cebb-cac4-4905-9b31-539295e4b85b","displayName":"Proofing","description":"Microsoft Publisher 2016\\Publisher Options\\Proofing","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","displayName":"Accounts","description":"Accounts > Accounts","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"522c3302-7a25-4904-a274-66cef9fd6aa0","displayName":"Microsoft Office","description":"Microsoft Office","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":["b5169b74-41be-460a-9402-b13b6c22582b","19ba782c-3594-45da-b829-72b54f6d45c7","191a84f2-13b5-4609-808f-8b743b7f0247"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"5261c543-0bf4-49a8-9657-45e2044420d1","displayName":"Messaging","description":"Messaging","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5261c543-0bf4-49a8-9657-45e2044420d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"526e363a-84db-4256-a13c-e01c8c646e26","displayName":"Idle Browser Actions","description":"Microsoft Edge Idle Browser Actions","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"52e76943-bfc9-4fb5-bdc8-5d4e8c6a436e","displayName":"Remote Remediation","description":"Remote Remediation","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"52e76943-bfc9-4fb5-bdc8-5d4e8c6a436e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5371d50c-0aaa-425a-a075-2cb1c59968b9","displayName":"MS Security Guide","description":"Administrative Templates\\MS Security Guide","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"53936d6e-5445-4897-8a40-e3f810ea50c4","displayName":"Shutdown Options","description":"Administrative Templates\\System\\Shutdown Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"53ba922e-db4d-489c-b5ab-dbc4b8321206","displayName":"Microsoft User Experience Virtualization","description":"Administrative Templates Microsoft User Experience Virtualization","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["c0ea0178-ad93-4596-94b2-9d7d1bbe8789","5966d21b-220b-4937-9323-c6dd46cda942"],"platforms":"windows10","technologies":"mdm"},{"id":"5401711f-292a-487a-be18-f99593a0477c","displayName":"Font","description":"System Configuration\\ Font","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","displayName":"Connections","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Connections","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","displayName":"Startup Home page and New Tab page","description":"Google Google Chrome - Default Settings users can override Startup Home page and New Tab page","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5536b5f4-3d31-4290-acea-9bef323bb83d","displayName":"Ctrl Alt Del Options","description":"Administrative Templates Ctrl Alt Del Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"55a61bb8-e023-4741-8213-99995c5902e5","displayName":"System","description":"Administrative Templates Event Log Service System","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"55c888df-44ff-49d1-808e-ad9cb8429aff","displayName":"Device Health Monitoring","description":"Device Health Monitoring","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"55c888df-44ff-49d1-808e-ad9cb8429aff","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"55eebd7c-beb9-48b6-907f-df4997e18bdb","displayName":"Predefined","description":"Microsoft Access 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"b8158968-c839-4d37-9eb8-887bd6fd7402","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"569c6b8d-9491-471b-9960-17e3ac60734a","displayName":"RSS Feeds","description":"Administrative Templates\\Windows Components\\RSS Feeds","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"56c54112-2991-4bda-9e01-e6868bd07726","displayName":"Printer Provisioning","description":"Printer Provisioning","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"56c54112-2991-4bda-9e01-e6868bd07726","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"56e510be-ca39-46a2-9eb2-6f1af6d4b16a","displayName":"Browser","description":"Microsoft Word 2016\\Word Options\\Advanced\\Web Options...\\Browser","helpText":null,"parentCategoryId":"2108b443-384c-4bb3-9b9f-acb4a754a86a","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","displayName":"Branch Cache","description":"Administrative Templates Branch Cache","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"572bc940-42d4-4e00-ac55-012e9b90f6df","displayName":"Remote Desktop Services","description":"Administrative Templates\\Windows Components\\Remote Desktop Services","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["2d8634c7-19ca-46e0-923d-019ba18ff4e0","66e289cf-85cb-425f-94a1-54777950f78b","85c586a6-6b68-48b2-8050-c4fb86aff486","394ae912-b5c9-45a0-8883-84791c6acb16","a4877a42-7e62-4216-a477-0b35357ab313"],"platforms":"windows10","technologies":"mdm"},{"id":"57514d69-d9b1-469a-9b54-b5e94320c2a1","displayName":"Windows Subsystem For Linux","description":"Windows Subsystem For Linux","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","childCategoryIds":["a787672d-4a33-455b-a2db-e340eb35a5c8"],"platforms":"windows10","technologies":"mdm"},{"id":"575369a6-17a2-435e-81d4-71772e7d55b5","displayName":"Input Panel","description":"Administrative Templates\\Windows Components\\Tablet PC\\Input Panel","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"577d5951-fc56-4906-90bc-2c508c6611ad","displayName":"Microsoft Defender for Endpoint","description":"Microsoft Defender for Endpoint","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"577d5951-fc56-4906-90bc-2c508c6611ad","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"579d6272-8708-4b22-a352-89cbd705ca82","displayName":"Security","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Security","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","displayName":"Credential User Interface","description":"Administrative Templates Credential User Interface","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5838ed03-2902-4931-92cf-e349ab09c9b8","displayName":"PowerPoint Designer","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...\\PowerPoint Designer","helpText":null,"parentCategoryId":"af14a55b-d79b-4299-946c-b7582412b748","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"586c5c5a-15cd-4592-beae-1709c6daf5b7","displayName":"Internet Control Panel","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["d2da164d-dd77-4489-b67f-d7fbdb19cde2","3969f56d-a8b5-4509-86fb-00eb481665fa"],"platforms":"windows10","technologies":"mdm"},{"id":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","displayName":"General","description":"Microsoft Excel 2016\\Excel Options\\General","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","displayName":"Locked- Down Trusted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Trusted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5900ac65-f656-459c-bd82-1329a862544d","displayName":"Deprecated policies","description":"Google Google Chrome Deprecated policies","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5915e06c-9b74-4c5e-86de-93e67ae183de","displayName":"Online Assistance","description":"Administrative Templates\\Windows Components\\Online Assistance","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5966d21b-220b-4937-9323-c6dd46cda942","displayName":"Applications","description":"Administrative Templates Microsoft User Experience Virtualization Applications","helpText":null,"parentCategoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","displayName":"Directory Service","description":"Authentication > Directory Service","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","displayName":"Trust Center","description":"Microsoft Office 2016\\Privacy\\Trust Center","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"59d29716-55b0-4014-a458-38b408ff9530","displayName":"Content settings","description":"Google Google Chrome Content settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5a92aaed-3c64-4074-bacf-91dc1896d6f1","displayName":"Windows PowerShell","description":"Administrative Templates\\Windows Components\\Windows PowerShell","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5b1be2c5-9939-4b2e-b29b-b22069455c90","displayName":"Microsoft Save As PDF and XPS add-ins","description":"Microsoft Office 2016\\Microsoft Save As PDF and XPS add-ins","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","displayName":"FileVault Options","description":"FileVault > FileVault Options","helpText":null,"parentCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"5b832259-c30b-43bb-b249-9d3ea4d5b028","displayName":"Customizable Error Messages","description":"Microsoft Excel 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","displayName":"Group Policy snap-in extensions","description":"Administrative Templates Group Policy Group Policy snap-in extensions","helpText":null,"parentCategoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","displayName":"Application Guard settings","description":"Microsoft Edge\\Application Guard settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","displayName":"Edit","description":"Microsoft Project 2016\\Project Options\\Edit","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["d33133b4-77df-429a-9580-ed70f7da676d","3db7e884-6077-4b96-ace3-005a6b49ecc0","06c4a76a-805b-4370-9d80-08e720ab2305"],"platforms":"windows10","technologies":"mdm"},{"id":"5be35eeb-62e9-4317-8804-018a9dd31149","displayName":"Online Assistance","description":"Administrative Templates Online Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bf4c2ba-be08-4cda-bf33-d10707580d78","displayName":"Present Online","description":"Microsoft Office 2016\\Present Online","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["0be98651-a552-4470-b2dc-71c66a5ce1e6"],"platforms":"windows10","technologies":"mdm"},{"id":"5c1c00f2-def5-4064-925d-aedf4aa0f060","displayName":"Microsoft Support Diagnostic Tool","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Microsoft Support Diagnostic Tool","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5c3d081f-6f7c-4650-8a40-200f44eb4794","displayName":"File Classification Infrastructure","description":"Administrative Templates\\System\\File Classification Infrastructure","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5c4224e0-6a48-4665-9332-958d98124157","displayName":"File Block Settings","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","displayName":"Tamper protection","description":"Microsoft Defender Tamper protection","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"5c645a3e-bc39-44e9-8786-4c82e0553d22","displayName":"ODFC Containers","description":"FS Logix ODFC Containers","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":["81eb92d0-acda-4ea2-8183-29ed5457276b","0bae3158-5f75-4e25-acf4-859d2612f892"],"platforms":"windows10","technologies":"mdm"},{"id":"5c722b3f-9d77-428a-b859-3fb556162cd6","displayName":"Cellular","description":"Networking > Cellular","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"5c9a2f21-d3a8-4295-a803-e0535aa29489","displayName":"System Restore","description":"Administrative Templates System Restore","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","displayName":"Auditing","description":"Auditing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"5cd6dc4f-b231-449f-bc10-16041b73356a","displayName":"Contact Card","description":"Microsoft Office 2016\\Contact Card","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["20bacabf-cd07-48be-a184-f0ae76d31e4a"],"platforms":"windows10","technologies":"mdm"},{"id":"5d03766c-9480-43f2-9e85-461a44c821d4","displayName":"Button Settings","description":"Administrative Templates Power Management Button Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d19c257-8b7e-4071-9303-19317c94d7f7","displayName":"Credential User Interface","description":"Administrative Templates\\Windows Components\\Credential User Interface","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d4e843b-2848-4508-9143-cb3217c2fe83","displayName":"RDP Shortpath","description":"Administrative Templates Windows Components Remote Desktop Services Remote Desktop Session Host Azure Virtual Desktop RDP Shortpath","helpText":null,"parentCategoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d8272e2-1ed3-4a8d-9555-9a87fa13d078","displayName":"Customize","description":"Microsoft Office 2016 (Machine)\\Global Options\\Customize","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","displayName":"Browser","description":"Browser","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"5dcea340-0469-4f43-b270-a49ed0597201","displayName":"Mitigation Options","description":"Administrative Templates Mitigation Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","displayName":"Other","description":"Microsoft Outlook 2016\\Outlook Options\\Other","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["6535c74f-74ac-4713-9c7a-ae15f62e97aa","f29a5e42-24f5-47fb-bdcf-9ed9418035ee"],"platforms":"windows10","technologies":"mdm"},{"id":"5e692f3e-1911-43b0-9192-64c2e65b7c10","displayName":"Education","description":"Education","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","displayName":"Downloads","description":"Microsoft Edge Downloads","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","displayName":"Microsoft Visio 2016","description":"Microsoft Visio 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["c67c9e69-6e69-4b63-868c-3b3df5d17e47","e6f727b7-f474-4010-b214-83149ffdac2b","d5b3cab7-d486-4f74-8525-6bd740b950bc","f106d9e2-60ce-4e16-b74d-bd9ef401d7ba"],"platforms":"windows10","technologies":"mdm"},{"id":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","displayName":"Generative AI","description":"Google Google Chrome Generative AI","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","displayName":"OneDrive","description":"OneDrive","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5f048379-3a42-43f0-9fd5-d269f292aa35","displayName":"Workflow Cache","description":"Microsoft Office 2016\\Miscellaneous\\Workflow Cache","helpText":null,"parentCategoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","displayName":"Remote Session Environment","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Remote Session Environment","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["b7bde490-eac6-4f57-8808-e0786b8191a1"],"platforms":"windows10","technologies":"mdm"},{"id":"5f71c40e-01aa-42d2-9c8c-7d560126cd4b","displayName":"App Analytics","description":"Managed Settings App Analytics","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","displayName":"Trust Center","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["8391e79d-d618-47c3-979c-83544da43739","c8cdd1a5-3f43-47c5-a775-d27bba4411f5","fe786056-6f4a-4d16-bff4-5fbb640308d2"],"platforms":"windows10","technologies":"mdm"},{"id":"5fe14828-4e5b-42ae-87b2-89a579045d1e","displayName":"Real-time Protection","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Real-time Protection","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"607a1c39-a3db-496f-8db6-c99d67f5f76c","displayName":"Tools | Security","description":"Microsoft Access 2016\\Tools | Security","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["a788a6e5-ab3f-41e5-96c8-ee59627dcb4d"],"platforms":"windows10","technologies":"mdm"},{"id":"60a3188c-7ee3-40db-8f9f-33648dc74555","displayName":"Shutdown Options","description":"Administrative Templates\\Windows Components\\Shutdown Options","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60b55db1-53fc-45ea-93d3-e4372b1e19a5","displayName":"Shutdown","description":"Administrative Templates Shutdown","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60b898a9-0490-4599-b7f1-3cd451236266","displayName":"Microsoft account","description":"Administrative Templates Microsoft account","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","displayName":"Enabled Editing Languages","description":"Microsoft Office 2016\\Language Preferences\\Editing Languages\\Enabled Editing Languages","helpText":null,"parentCategoryId":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60ea8de3-bc6d-4b01-974a-a53860fe4ef6","displayName":"i SCSI Target Discovery","description":"Administrative Templatesi SCS Ii SCSI Target Discovery","helpText":null,"parentCategoryId":"3f693856-7cbb-4a1c-93be-0d05aa41059f","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"61205786-952e-489c-91f7-5654a5bde11b","displayName":"Resultant Set of Policy snap-in extensions","description":"Administrative Templates\\Windows Components\\Microsoft Management Console\\Restricted/Permitted snap-ins\\Group Policy\\Resultant Set of Policy snap-in extensions","helpText":null,"parentCategoryId":"3d32fb39-ff23-48d9-9890-c8625d2d21e9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"618e0144-c57c-45e1-8b55-94dd3d9fec33","displayName":"Windows Connection Manager","description":"Administrative Templates\\Network\\Windows Connection Manager","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","displayName":"E-mail Options","description":"Microsoft Word 2016\\Word Options\\Advanced\\E-mail Options","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"622c83ff-f780-47e6-8b9c-bf82552e3f04","displayName":"Scripted Window Security Restrictions","description":"Administrative Templates Internet Explorer Security Features Scripted Window Security Restrictions","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"623d41fb-000e-41d8-b955-373f8c700def","displayName":"Security","description":"Microsoft Project 2016\\Project Options\\Security","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["26dfd0a7-546b-4583-b0c7-85b98ac5a40c","1671dfc3-a1dd-4178-9093-10fb6b62586a","cc50f179-0c39-4486-a555-de5a6e6ed365"],"platforms":"windows10","technologies":"mdm"},{"id":"62492a4c-fd70-4275-ae5e-d60e200e3553","displayName":"Apply as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type\\Apply as you type","helpText":null,"parentCategoryId":"4dae3032-1f16-4ace-911b-a957db0b8089","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"62499519-97eb-43e7-ae96-d7909c5820d3","displayName":"Printing","description":"Google Google Chrome Printing","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"62b373da-c112-40f4-9047-9cc3e8d8ab13","displayName":"Power Management","description":"Administrative Templates\\System\\Power Management","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["01bbe7c3-10eb-40a3-8387-c74c33c294b1","17f0fdd3-e292-4ecb-ab5f-e4848e9cae1a","7120bf9e-e5f6-42cd-8f7e-15d2ca445c37","015936bf-8273-4499-bb71-33b385ee7d16","4b2f3557-98e9-48d2-9b78-bcb100f72372","d5585700-13a0-4ab4-9b19-4c15c1ead170"],"platforms":"windows10","technologies":"mdm"},{"id":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","displayName":"Remote Desktop Session Host","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["579d6272-8708-4b22-a352-89cbd705ca82","b40b8f80-c0e6-4494-8085-f90cadc167a9","0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","5454d0eb-7eaa-4500-a1fb-f69b76aed740","2a1bbe00-0730-430e-8d19-3eec2fd6b63c","4b540860-0858-48f4-8830-18383bb1766f","5f28f9ff-58f8-43af-9692-3d06e083bbd9","89ad0055-1603-420e-940d-9944a63e3da9","ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","f1455024-7de9-448f-8d8f-a42db2af0a35"],"platforms":"windows10","technologies":"mdm"},{"id":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","displayName":"Security","description":"Security","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":["d68abc4d-559a-4339-be48-c41a77a87034","8abddb23-7036-4ba8-8912-529279a849ea","f4a8384f-9e4e-4fc6-9ee2-28fa5260347a"],"platforms":"iOS,macOS,windows10","technologies":"mdm,appleRemoteManagement"},{"id":"634e4243-284b-4cb7-a7e6-08ca7e262937","displayName":"Attachment Manager","description":"Administrative Templates Attachment Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6355e85b-aeef-49e8-b8c9-5d6cd9a39985","displayName":"Extension snap-ins","description":"Administrative Templates\\Windows Components\\Microsoft Management Console\\Restricted/Permitted snap-ins\\Extension snap-ins","helpText":null,"parentCategoryId":"9e882396-4a1c-4d06-a62d-8d910ded8e7d","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"63b9904f-bbdf-4461-954a-c1d67fa8b357","displayName":"File Explorer","description":"File Explorer","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"63ca5d8b-829d-42c5-92e8-35f9ca47fb0e","displayName":"IMAP","description":"Microsoft Outlook 2016\\Account Settings\\IMAP","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"63e167a4-65be-4d34-9e9c-186466f2b064","displayName":"Troubleshooting","description":"Troubleshooting","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"63e167a4-65be-4d34-9e9c-186466f2b064","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6424714c-e50a-4b53-acbf-8739825ebf0b","displayName":"Personalization","description":"Administrative Templates Personalization","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"643081a4-132d-463e-9d86-c8650cb2a011","displayName":"Network Provider","description":"Administrative Templates Network Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"64538726-8745-4e7a-b370-332f725b58bf","displayName":"System Policy Managed","description":"System Policy > System Policy Managed","helpText":null,"parentCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","rootCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"64c8233f-3057-4485-b902-d71a312318d7","displayName":"Scheduled scan configuration","description":"Microsoft Defender Scheduled scan configuration","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","displayName":"Network Isolation","description":"Network Isolation","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"65087b94-7e45-4d74-a50d-df4377b67499","displayName":"Parental Controls Dictionary","description":"Parental Controls > Parental Controls Dictionary","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"652a676c-9d60-4c9a-88b6-823a24961a9b","displayName":"Copilot Settings","description":"Visual Studio Copilot Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","displayName":"Advanced","description":"Microsoft Outlook 2016\\Outlook Options\\Other\\Advanced","helpText":null,"parentCategoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["13eb248a-4549-4d23-9ada-23b40edf36bf"],"platforms":"windows10","technologies":"mdm"},{"id":"65873bfe-2798-42fc-ae33-02295b23b3d3","displayName":"Security Account Manager","description":"Administrative Templates System Security Account Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"66395272-f132-4170-b88e-87f794f987f4","displayName":"File Locations","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\File Locations","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"66448b13-cc0a-4ffe-9ad5-62c4821dc77f","displayName":"Setup","description":"Administrative Templates\\Windows Components\\Event Log Service\\Setup","helpText":null,"parentCategoryId":"fcddcc0b-7cf8-4ebc-a818-d10689603263","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"66615d2a-fec9-47f1-8eaf-9813e30cc023","displayName":"Extensions","description":"Microsoft Edge\\Extensions","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"66c92e07-234b-4992-a081-9afe4c113ba3","displayName":"SCEP certificate","description":"SCEP certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"66c92e07-234b-4992-a081-9afe4c113ba3","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"66e289cf-85cb-425f-94a1-54777950f78b","displayName":"Remote Desktop Session Host","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host","helpText":null,"parentCategoryId":"572bc940-42d4-4e00-ac55-012e9b90f6df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["92503b7f-9fa0-4365-8482-57dd61e6d535","cc9231e6-ed1b-4680-aff4-bc72f16733c0","8778eb21-bf7c-41a7-bae1-412c0e3029db","2cc013ad-e5a3-42d9-b2b6-2a872a4c086d","b237a91d-a442-4a7e-8169-1bd6c798f490","bd1bf2cb-c806-479b-a68c-af9dffd438c9","ce572b49-4d47-47b6-b787-ac1252753581","0c2613c9-a7c7-4458-8b0d-2fff13e2beeb","845ff38a-408b-449c-9ef3-7fdc331027df","fe52de11-190e-4429-96c1-106b22724456","f3264346-fdc4-4e23-9a2a-dcfc34022e59"],"platforms":"windows10","technologies":"mdm"},{"id":"6730f0be-a129-4b48-942f-e4ddf69fee66","displayName":"Customizable Error Messages","description":"Microsoft Access 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6776f6fa-8836-408c-b91c-1e444e0cba5c","displayName":"Security Features","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["1671f10e-7300-46e3-a93f-ef38bf906cb1","a126378d-a916-476e-ad91-e3bd82fd3a48","91ed1812-8841-4eb3-b24e-a5e1f4eaa6c8","3e50e056-24bf-46c3-975f-b0aedbc96329","d39f73b0-9d26-4d4c-a8b0-d1b720890d2e","89c0381d-3b9b-4be5-8077-ffb18d47e910","829d1e81-4cbc-4259-bd0e-8cc44870f00e","8d5ce834-5b70-4ec2-8d07-eae26ab6493f","b74f852c-d19b-4a22-a44a-431f7a72a4d6"],"platforms":"windows10","technologies":"mdm"},{"id":"67b48a23-9bc3-48f5-bf6e-c9b3cd7000e4","displayName":"File Revocation","description":"Administrative Templates\\Windows Components\\File Revocation","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"67c06154-a798-44bb-83c8-d706a3709c10","displayName":"Layer-2 priority value","description":"Administrative Templates\\Network\\QoS Packet Scheduler\\Layer-2 priority value","helpText":null,"parentCategoryId":"01f2fac4-fdab-4391-bebe-ebdf6d8fcc77","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"67cd904c-78e0-4e77-9dd4-c713b21763f3","displayName":"User interface preferences","description":"Microsoft Defender > User interface preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"67eb1dab-7805-41bb-af5a-798dc7e29f23","displayName":"Autocorrect Options","description":"Microsoft Excel 2016\\Excel Options\\Proofing\\Autocorrect Options","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"68237832-f376-4f0e-ba26-4e06fce7a35d","displayName":"Device Installation Restrictions","description":"Administrative Templates Device Installation Device Installation Restrictions","helpText":null,"parentCategoryId":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"684799ba-398b-4728-aa21-40c8469cbe87","displayName":"Printers","description":"Administrative Templates\\Control Panel\\Printers","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"686ae3dd-a663-4484-854e-8f8d578fe3b8","displayName":"Converters","description":"Microsoft PowerPoint 2016 (Machine)\\Converters","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"686ae3dd-a663-4484-854e-8f8d578fe3b8","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"68a3b82d-d1f4-422d-bfee-2168ec260ad7","displayName":"Portable Operating System","description":"Administrative Templates Portable Operating System","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"69931627-230d-4df9-bbef-e3eac64ea8ef","displayName":"Additional Actions","description":"Microsoft Office 2016\\Tools | AutoCorrect Options... (Excel, PowerPoint and Access)\\Additional Actions","helpText":null,"parentCategoryId":"8084033c-156a-4d1b-ab0b-159541810459","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"69ec00d9-5698-4b8b-ad54-8d9a537a0fa9","displayName":"Internet Information Services","description":"Administrative Templates\\Windows Components\\Internet Information Services","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","displayName":"Advanced","description":"Microsoft Publisher 2016\\Publisher Options\\Advanced","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["77b0357b-412e-4a81-9469-e20a5f1345fd"],"platforms":"windows10","technologies":"mdm"},{"id":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","displayName":"Save","description":"Microsoft Project 2016\\Project Options\\Save","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["dfd5d749-c68c-448f-ab3f-851c09f09df4","e13ec567-e29c-4ca0-b599-e8c43587f10a","d679b407-a753-40aa-bc9f-175f363b0eff"],"platforms":"windows10","technologies":"mdm"},{"id":"6ae0d607-832c-403b-b3bc-c563e390ebad","displayName":"Save/Open","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Save/Open","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","displayName":"Server Settings","description":"Microsoft Office 2016\\Server Settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["8e143bee-82fa-4e45-8bd0-c4032b0182d2"],"platforms":"windows10","technologies":"mdm"},{"id":"6b71fbf6-7156-471a-b488-3eece04bda86","displayName":"Printing","description":"Microsoft Edge - Default Settings (users can override)\\Printing","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","displayName":"Tools | Options | Spelling","description":"Microsoft Office 2016\\Tools | Options | Spelling","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["df357f0c-78fe-4aee-a465-f3da7499077e"],"platforms":"windows10","technologies":"mdm"},{"id":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","displayName":"Math Settings","description":"Declarative Device Management preview Math Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"6b87c5da-cfd9-44bc-be05-ed08eb2144c7","displayName":"User Accounts","description":"Administrative Templates User Accounts","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","displayName":"Desktop","description":"Administrative Templates\\Desktop","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["f4f0dfd7-4638-4173-8b3b-0f08608bf330","a69e7a98-5af7-4834-bae1-2a1047663a71"],"platforms":"windows10","technologies":"mdm"},{"id":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","displayName":"Network Connectivity Status Indicator","description":"Administrative Templates Network Connectivity Status Indicator","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6c142a01-47fa-422d-8135-29e81bc970cc","displayName":"Conversion Service","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...\\Conversion Service","helpText":null,"parentCategoryId":"af14a55b-d79b-4299-946c-b7582412b748","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6c1d9109-e4d1-4718-a537-dd685464fdbe","displayName":"i SCSI Security","description":"Administrative Templatesi SCS Ii SCSI Security","helpText":null,"parentCategoryId":"3f693856-7cbb-4a1c-93be-0d05aa41059f","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6c7168c3-6f34-4086-af0b-ed0b74301dc9","displayName":"Security Settings","description":"Administrative Templates Service Control Manager Settings Security Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6cd02266-a42f-4675-b83e-37360dbf3c68","displayName":"WLAN Media Cost","description":"Administrative Templates WLAN Service WLAN Media Cost","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6d1e32eb-61f7-4907-b9fe-b83fda8ad67d","displayName":"Customize Ribbon","description":"Microsoft Publisher 2016\\Publisher Options\\Customize Ribbon","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6d4184ab-a66c-47f1-b54e-af55f654e2a5","displayName":"Hotspot Authentication","description":"Administrative Templates Hotspot Authentication","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","displayName":"Related Website Sets Settings","description":"Microsoft Edge Related Website Sets Settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"6d6b289c-c1e9-4004-b5ab-3123920cf10d","displayName":"Password manager","description":"Google Google Chrome - Default Settings users can override Password manager","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","displayName":"Link- Layer Topology Discovery","description":"Administrative Templates Link- Layer Topology Discovery","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6efb8802-223a-46a7-b13f-a68f28f8b2c2","displayName":"Login Items","description":"Login > Login Items","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"6f0e6df6-8654-4b57-b1d5-2160c5a0a54e","displayName":"Pen Flicks Learning","description":"Administrative Templates Pen Flicks Learning","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6f1386e5-148d-4dc3-84d1-79df721e3233","displayName":"Default search provider","description":"Microsoft Edge - Default Settings (users can override)\\Default search provider","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6fafeb5c-65ce-4993-b421-46e60da69131","displayName":"HTTP authentication","description":"Microsoft Edge - Default Settings (users can override)\\HTTP authentication","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","displayName":"General","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Advanced\\Web Options...\\General","helpText":null,"parentCategoryId":"76b233cc-f977-4305-b02f-deef6667251d","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70063d93-03f0-462e-9943-b0241b88d54d","displayName":"Desktop App Installer","description":"Administrative Templates Windows Components Desktop App Installer","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70498fad-5ddb-4730-8130-d755ff675760","displayName":"Default search provider","description":"Google Google Chrome Default search provider","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70b0e7ef-ceac-4c25-8f9f-5a6bf07163b6","displayName":"Calendar Type","description":"Microsoft Project 2016\\Project Options\\View\\Calendar Type","helpText":null,"parentCategoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70b5da13-9c31-4857-890d-b7eb223729c3","displayName":"Firewall","description":"Networking > Firewall","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"70c4566f-a079-4a8e-ac97-0736b405df1d","displayName":"Work profile password","description":"Device Restriction Work profile password","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"70d374bf-6444-4b74-a879-a29e4d44c566","displayName":"News And Interests","description":"News And Interests","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"70d374bf-6444-4b74-a879-a29e4d44c566","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70dd505d-40d4-4685-b639-67efc9274ec4","displayName":"Typosquatting Checker settings","description":"Microsoft Edge - Default Settings (users can override)\\ Typosquatting Checker settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7120bf9e-e5f6-42cd-8f7e-15d2ca445c37","displayName":"Power Throttling Settings","description":"Administrative Templates\\System\\Power Management\\Power Throttling Settings","helpText":null,"parentCategoryId":"62b373da-c112-40f4-9047-9cc3e8d8ab13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"712d184f-d9ac-45fc-9eea-aade3a22b55e","displayName":"Volume Activation","description":"Microsoft Office 2016 (Machine)\\Volume Activation","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"717b634f-72a6-44f6-92c5-e1397bb10f40","displayName":"Keyboard Filter","description":"Keyboard Filter","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"719595d8-ab5d-4418-88aa-8cd55c2964ba","displayName":"Cloud Cache","description":"FS Logix Profile Containers Cloud Cache","helpText":null,"parentCategoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"71f349a7-1ca3-4945-8c7d-fd68df3759ac","displayName":"Enhanced Storage Access","description":"Administrative Templates\\System\\Enhanced Storage Access","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","displayName":"Tracking Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options\\Tracking Options","helpText":null,"parentCategoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"71f79fa3-14c0-4df8-bf9c-8476e36ea755","displayName":"Operating system settings","description":"Operating system settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"71f79fa3-14c0-4df8-bf9c-8476e36ea755","childCategoryIds":[],"platforms":"windows10","technologies":"windowsOsRecovery"},{"id":"71f9795f-defc-4b03-a2b4-31e129b6f861","displayName":"Network Sharing","description":"Administrative Templates\\Windows Components\\Network Sharing","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7226f8a2-c542-471a-8d9e-e0df527325d3","displayName":"Notification Settings","description":"Administrative Templates Power Management Notification Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"724d930a-7a3c-4171-a17c-431cee336518","displayName":"Software Update Settings","description":"Managed Settings Software Update Settings","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"725adbdf-1eb8-45c4-8eb1-44747bd1615d","displayName":"Define Shared Workspace URL's","description":"Microsoft Office 2016\\Global Options\\Customize\\Shared Workspace\\Define Shared Workspace URL's","helpText":null,"parentCategoryId":"13123148-c522-437f-b316-d78f5cc0d28d","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"728890f5-bddd-4b69-a1b6-efb221d902d4","displayName":"RemoteFX USB Device Redirection","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Connection Client\\RemoteFX USB Device Redirection","helpText":null,"parentCategoryId":"a4877a42-7e62-4216-a477-0b35357ab313","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72972c43-36a3-4034-8cc8-334c99087798","displayName":"Instant Search","description":"Administrative Templates Instant Search","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72a7524b-11c5-4695-9fcf-6cf30c8ba2b9","displayName":"First Run","description":"Microsoft Office 2016\\First Run","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72dfdba4-e7bb-4f09-862c-e003ea763452","displayName":"Internet Communication settings","description":"Administrative Templates\\System\\Internet Communication Management\\Internet Communication settings","helpText":null,"parentCategoryId":"184aa343-0f0b-4bf5-aeeb-42111fedfbbf","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72f61c7d-e5d2-4170-baf3-c953c1082e19","displayName":"Controlled Folder Access","description":"Administrative Templates Microsoft Defender Antivirus Microsoft Defender Exploit Guard Controlled Folder Access","helpText":null,"parentCategoryId":"ad84cea3-5664-4e42-a9d6-1446828bea45","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73415dea-0103-4427-83c5-6c97bf81af1d","displayName":"Save Documents","description":"Microsoft Visio 2016\\Visio Options\\Save\\Save Documents","helpText":null,"parentCategoryId":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"734bed4f-be52-46ef-ae60-8fd195dc8f4d","displayName":"Access-Denied Assistance","description":"Administrative Templates\\System\\Access-Denied Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"736134cb-4d82-427a-97b7-d219ac6a22f0","displayName":"Corrupted File Recovery","description":"Administrative Templates Corrupted File Recovery","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73935f55-c845-40ce-819e-838c0041f6fa","displayName":"Resultant Set of Policy snap-in extensions","description":"Administrative Templates Group Policy Resultant Set of Policy snap-in extensions","helpText":null,"parentCategoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73a3a483-dcba-4b34-b7cb-9c68c871864c","displayName":"Remote Procedure Call","description":"Administrative Templates\\System\\Remote Procedure Call","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73bc2db9-d37f-4add-a64d-a8239273edb3","displayName":"Check Accessibility","description":"Microsoft Word 2016\\File Tab\\Check Accessibility","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"740e7a10-3774-4a1c-9970-6907e0f0b848","displayName":"Disable Items in User Interface","description":"Microsoft Word 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["0f42fc50-66c8-4b70-9904-64f8d662c930","44e27b70-4bdb-4aec-a75d-0568a1edc332"],"platforms":"windows10","technologies":"mdm"},{"id":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","displayName":"BITS","description":"BITS","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7444c3f0-214b-45ea-9b8e-f74b81543644","displayName":"Microsoft account","description":"Administrative Templates\\Windows Components\\Microsoft account","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7490c4fd-c326-42f7-9908-006504616d4c","displayName":"Trust Center","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["5c4224e0-6a48-4665-9332-958d98124157","2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","fe54701d-42bd-47f0-9c49-26ff6a928b32","e36863b6-3232-4a29-be02-32ee67cc48b9"],"platforms":"windows10","technologies":"mdm"},{"id":"751cf9ec-7214-4b38-a09e-24922684bd8f","displayName":"Presentation Settings","description":"Administrative Templates Presentation Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"756d2b0b-5f06-45e7-b5c5-c066deb5ed2f","displayName":"Extension snap-ins","description":"Administrative Templates Microsoft Management Console Restricted Permitted snap-ins Extension snap-ins","helpText":null,"parentCategoryId":"acb49e73-5a6a-479b-9d58-c3cd7f632e9b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7574a907-5608-491f-8011-c57d487457f4","displayName":"Sync your settings","description":"Administrative Templates\\Windows Components\\Sync your settings","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"75ad885f-6118-4508-a2fd-bb26be931c3f","displayName":"Outlook Today Settings","description":"Microsoft Outlook 2016\\Outlook Today Settings","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"75e080fb-3ed7-4a73-a6e0-eb93f0119d68","displayName":"Event Logging","description":"Administrative Templates Event Logging","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","displayName":"File Block Settings","description":"Microsoft Visio 2016\\Visio Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"760376f3-6b74-4992-89eb-aa41d6190e94","displayName":"Subscription Activation","description":"Microsoft Office 2016\\Subscription Activation","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"763525a0-8456-4336-a8d1-392253e8fdd8","displayName":"System Policy Control","description":"System Policy\\ System Policy Control","helpText":null,"parentCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","rootCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"7652894d-4667-443f-b925-b1686a942729","displayName":"Disable Items in User Interface","description":"Microsoft Outlook 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["8184df77-410e-41a6-b687-88de05769977","d59dfcc1-6c35-41de-bfb6-de94b8120ca5"],"platforms":"windows10","technologies":"mdm"},{"id":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","displayName":"File Provider","description":"System Configuration > File Provider","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"76ad3567-c6cb-43b5-b91d-a52a34853c03","displayName":"Trusted Locations","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76b233cc-f977-4305-b02f-deef6667251d","displayName":"Advanced","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Advanced","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["6fd44fd0-80d1-47a0-acad-c115e5b807b6"],"platforms":"windows10","technologies":"mdm"},{"id":"76bbc368-9d0b-4aa7-b8e2-2dcfd864b9ee","displayName":"Audit Process Creation","description":"Administrative Templates Audit Process Creation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76c53aab-0288-4ac1-b399-0104e04c6457","displayName":"Application Compatibility Diagnostics","description":"Administrative Templates Application Compatibility Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76c8131a-62fe-4134-aeac-d999f01911ed","displayName":"Network Connections","description":"Administrative Templates\\Network\\Network Connections","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76e34834-6d47-4e06-b14c-aa2888cdce27","displayName":"Generative AI","description":"Microsoft Edge Generative AI","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76f2d08c-0a3f-4f4e-ad04-51aa16aea0bf","displayName":"Intranet Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Intranet Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","displayName":"Publishing","description":"Administrative Templates App-V Publishing","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"77b0357b-412e-4a81-9469-e20a5f1345fd","displayName":"Complex scripts","description":"Microsoft Publisher 2016\\Publisher Options\\Advanced\\Complex scripts","helpText":null,"parentCategoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"77ca5e78-a1fe-456e-9814-034b1ea2658d","displayName":"PowerPoint Designer","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\PowerPoint Designer","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"78497707-c3e4-400b-a6bc-1813c3689fdc","displayName":"Preferences","description":"Microsoft Edge Update\\Preferences","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"785c6df2-c6d0-4d6e-bd73-c3b62caca754","displayName":"TCPIP Settings","description":"Administrative Templates TCPIP Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["91789113-6339-4e96-8e1d-73a4dec4967f","486f25cc-c865-446e-95b2-c5b061883a7a"],"platforms":"windows10","technologies":"mdm"},{"id":"788355e5-e113-4b17-ada9-fb5ef38bffa1","displayName":"App-V","description":"Administrative Templates App-V","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["7740c7ba-aa61-4486-ad26-cb8721a2efb4","e7cc16d8-f74f-4cd7-890d-9b4082a19c39","efabaf11-42e4-48ab-81ca-4514199d239b","b9201072-3681-4e95-ad90-869e6166b129","10835ce3-31c8-4ec6-aa00-c5af48e550a8","5011ca61-1a58-42da-9c66-7763236acc84","ea9a092f-dd93-41d4-9bbb-118de1213578","f125d7cd-a333-4f24-a5f4-99fc289c6d22"],"platforms":"windows10","technologies":"mdm"},{"id":"78906e32-f4fb-453b-939b-05717ffaae59","displayName":"ActiveX Installer Service","description":"Administrative Templates\\Windows Components\\ActiveX Installer Service","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"78b3d753-d84d-496b-a93c-d577ab5865bd","displayName":"Scripted Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Scripted Diagnostics","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"78d3d93f-03d0-4fa0-be56-be4bca0a7b3b","displayName":"Trusted Platform Module Services","description":"Administrative Templates\\System\\Trusted Platform Module Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"794337be-8833-4b9a-bb88-8a030141578d","displayName":"Search","description":"Search","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"794337be-8833-4b9a-bb88-8a030141578d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"797ac384-f48e-4567-b931-33a6ce923b94","displayName":"Microsoft Edge Canary","description":"Microsoft Edge Update\\Applications\\Microsoft Edge Canary","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7a3a7335-4837-4bc5-9282-448402a05d89","displayName":"Control Panel","description":"Administrative Templates\\Control Panel","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["e6231142-3d39-44a7-9522-6a3357bd439f","2694014c-e044-45a0-99b1-1694bd01827a","18db3d59-661b-47ec-900a-bf75495ca598","a809df26-b5db-4af9-b247-a539ada4e869","2b8e43c0-e66b-4bec-b20d-54a1f7151212","684799ba-398b-4728-aa21-40c8469cbe87","f4eaa5be-1498-482e-abe6-de4fed7e3302"],"platforms":"windows10","technologies":"mdm"},{"id":"7a85e72a-a755-4903-b1fd-4939049380f4","displayName":"Privacy","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Privacy","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7a8b936d-b4b0-408f-bec5-3c97050730f8","displayName":"Shared paths","description":"Microsoft Office 2016\\Shared paths","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7aeaf6f8-5511-4216-9483-28f432a5a08f","displayName":"Server Settings","description":"Microsoft PowerPoint 2016\\Miscellaneous\\Server Settings","helpText":null,"parentCategoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","displayName":"App Lock","description":"App Management > App Lock","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","displayName":"Extensible Single Sign On (SSO)","description":"Authentication > Extensible Single Sign On (SSO)","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm"},{"id":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","displayName":"Microsoft Edge Beta","description":"Microsoft Edge Update\\Applications\\Microsoft Edge Beta","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7bc264db-6da2-4c6b-a357-aec47c717737","displayName":"Disk Diagnostic","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Disk Diagnostic","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7bee4dea-82a4-4a03-b903-654b374819b1","displayName":"Chinese Conversion | Convert with Options","description":"Microsoft Word 2016\\Review Tab\\Chinese Conversion | Convert with Options","helpText":null,"parentCategoryId":"1fddd12c-a630-47f0-9633-638808e228f9","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7c34b514-0fb4-4868-8418-cb9b28f9f6e3","displayName":"Previous Versions","description":"Administrative Templates\\Windows Components\\File Explorer\\Previous Versions","helpText":null,"parentCategoryId":"35525ba9-da99-460e-afd3-ba86506b0ba3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","displayName":"Windows Connect Now","description":"Administrative Templates Windows Connect Now","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7d331987-7e2d-4975-b23b-d99a5af26ddf","displayName":"IME","description":"Administrative Templates IME","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7d7f6a09-2088-4f1f-a1f1-14fbca93a808","displayName":"General iSCSI","description":"Administrative Templates\\System\\iSCSI\\General iSCSI","helpText":null,"parentCategoryId":"363982dd-fc96-49ce-a499-f6401f2c212b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7d9e5b9b-84e7-473c-b6ca-a1629448df55","displayName":"Safari Extension Settings","description":"Declarative Device Management preview Extension Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","displayName":"Performance","description":"Microsoft Edge - Default Settings (users can override)\\Performance","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","displayName":"Predefined","description":"Microsoft PowerPoint 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7eaa5e09-e5ab-4051-b557-64a124ae497c","displayName":"Cryptography","description":"Microsoft Access 2016\\Application Settings\\Security\\Cryptography","helpText":null,"parentCategoryId":"23fd467e-24f8-4200-8b19-c6c11afa8926","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7ecdd7c9-6ab2-4dac-88ef-9bdad46e1f66","displayName":"Parental Controls Game Center","description":"Parental Controls > Parental Controls Game Center","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","displayName":"Display","description":"Microsoft Word 2016\\Word Options\\Display","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","displayName":"Display","description":"Display","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","displayName":"Regional and Language Options","description":"Administrative Templates Regional and Language Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["9a79d480-8cb4-47b5-95c7-5da56eea5bb8"],"platforms":"windows10","technologies":"mdm"},{"id":"7f431009-e8fe-460e-b247-06c838c8a914","displayName":"Location and Sensors","description":"Administrative Templates\\Windows Components\\Location and Sensors","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["d6595bc3-dd73-44a3-8b32-d57af6e40208"],"platforms":"windows10","technologies":"mdm"},{"id":"7f461268-0fb6-4247-b6db-52515d42a20e","displayName":"User Interface","description":"Administrative Templates Windows Media Player User Interface","helpText":null,"parentCategoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f4d325e-bff8-4d91-8313-614243e55e6d","displayName":"DC Locator DNS Records","description":"Administrative Templates\\System\\Net Logon\\DC Locator DNS Records","helpText":null,"parentCategoryId":"bedf20d1-1f5a-4840-8458-6d0fa974b664","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f5517b0-3ff7-4f7e-aa4c-3d2ccbf37bdc","displayName":"VPN Connection","description":"VPN Connection","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7f5517b0-3ff7-4f7e-aa4c-3d2ccbf37bdc","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7fc23813-7a7c-412a-b9bd-eda07e6b1f5d","displayName":"List Sync","description":"List Sync","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7fc23813-7a7c-412a-b9bd-eda07e6b1f5d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7fc3275d-5ef6-4806-88b0-210bb175c182","displayName":"Network List Manager","description":"Network List Manager","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7fc3275d-5ef6-4806-88b0-210bb175c182","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"8028dead-8f13-4fe3-9998-ba1e841324d7","displayName":"Windows Apps","description":"Administrative Templates\\Windows Components\\Microsoft User Experience Virtualization\\Windows Apps","helpText":null,"parentCategoryId":"9e857bed-81f8-4dfc-b049-c93eb68b4064","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"802f3065-0bf1-4578-9d6d-ab1ef02db3ec","displayName":"Feedback Settings","description":"Visual Studio Feedback Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8084033c-156a-4d1b-ab0b-159541810459","displayName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","description":"Microsoft Office 2016\\Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["69931627-230d-4df9-bbef-e3eac64ea8ef"],"platforms":"windows10","technologies":"mdm"},{"id":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","displayName":"Config Refresh","description":"Config Refresh","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"80ed7629-87dd-4bb1-8ea0-555f20d3b156","displayName":"Mitigation Options","description":"Administrative Templates\\System\\Mitigation Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"80f5fb2f-e74a-4533-81aa-a92163f49e16","displayName":"Local Machine Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Local Machine Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"811f63f1-1619-4b48-b8f0-3d388729bd47","displayName":"Xsan","description":"Xsan","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","childCategoryIds":["46af3391-ed6d-4ada-aef7-02dac2a1b136","fd3717c1-dcf8-4038-b7f7-4ad3359a9d32"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"814e9e4d-b838-4747-a257-72390a535d56","displayName":"Group Policy snap-in extensions","description":"Administrative Templates\\Windows Components\\Microsoft Management Console\\Restricted/Permitted snap-ins\\Group Policy\\Group Policy snap-in extensions","helpText":null,"parentCategoryId":"3d32fb39-ff23-48d9-9890-c8625d2d21e9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8184df77-410e-41a6-b687-88de05769977","displayName":"Custom","description":"Microsoft Outlook 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"7652894d-4667-443f-b925-b1686a942729","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"81bc8383-43a5-4c6a-9d51-951e86028934","displayName":"Project Guide settings for 'Project1'","description":"Microsoft Project 2016\\Project Options\\Interface\\Project Guide settings for 'Project1'","helpText":null,"parentCategoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"81c518f1-522e-4957-b850-e8a66d2ab215","displayName":"Games settings","description":"Microsoft Edge Games settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"81eb92d0-acda-4ea2-8183-29ed5457276b","displayName":"Container and Directory Naming","description":"FS Logix ODFC Containers Container and Directory Naming","helpText":null,"parentCategoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","displayName":"Remediation","description":"Administrative Templates Microsoft Defender Antivirus Remediation","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"822bd634-4d01-486e-adad-8085968fd1c4","displayName":"Advanced Page","description":"Administrative Templates Internet Explorer Internet Control Panel Advanced Page","helpText":null,"parentCategoryId":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"826db7fb-889b-4a99-80a6-38347ba37f21","displayName":"Recurring item configuration","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Recurring item configuration","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8280dcb9-f2bc-417b-b4ef-cd6c35398f94","displayName":"Driver Installation","description":"Administrative Templates\\System\\Driver Installation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"829d1e81-4cbc-4259-bd0e-8cc44870f00e","displayName":"Restrict ActiveX Install","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Restrict ActiveX Install","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"82a437a8-6be8-4003-a951-951999e86db8","displayName":"Parental Controls","description":"Parental Controls","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":["f019963f-f4ed-4429-b6e3-babfb24c36a8","7ecdd7c9-6ab2-4dac-88ef-9bdad46e1f66","f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","dc270c70-1cf4-4d98-ad26-8c2d441173f1","65087b94-7e45-4d74-a50d-df4377b67499"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"82a9c23f-2c09-4479-9cd3-e7f185d7676f","displayName":"Offline Files","description":"Administrative Templates\\Network\\Offline Files","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"82d173f9-ba0b-4b09-bbb8-68cba4916162","displayName":"Privacy Preferences Policy Control","description":"Privacy > Privacy Preferences Policy Control","helpText":null,"parentCategoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","rootCategoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"82d20a08-90b8-4e6d-940a-5574844d1b26","displayName":"DSCP value of non-conforming packets","description":"Administrative Templates\\Network\\QoS Packet Scheduler\\DSCP value of non-conforming packets","helpText":null,"parentCategoryId":"01f2fac4-fdab-4391-bebe-ebdf6d8fcc77","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"82ecfab7-b76a-4cec-8e76-859db4599ac2","displayName":"Cached Exchange Mode","description":"Microsoft Outlook 2016\\Account Settings\\Exchange\\Cached Exchange Mode","helpText":null,"parentCategoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"83087772-6560-4488-a1c5-bb6e4889e868","displayName":"Advanced","description":"Microsoft Word 2016\\Word Options\\Advanced","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["bc65521d-e48a-4e95-899f-49df827808ca","e63361ad-a54b-4557-acc7-02c272a3e58d","61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","2108b443-384c-4bb3-9b9f-acb4a754a86a"],"platforms":"windows10","technologies":"mdm"},{"id":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","displayName":"Caldav","description":"Accounts > CalDAV","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"832f3a51-5e73-4541-8f14-1323cd9919bc","displayName":"When sending a message","description":"Microsoft Outlook 2016 Outlook Options Preferences E-mail Options Advanced E-mail Options When sending a message","helpText":null,"parentCategoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8391e79d-d618-47c3-979c-83544da43739","displayName":"Protected View","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","displayName":"Multi SIM","description":"Multi SIM","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"83febe72-a64f-4051-9071-1efae1ea9a15","displayName":"Disk Management","description":"Declarative Device Management preview Disk Management","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"macOS","technologies":"appleRemoteManagement"},{"id":"845ff38a-408b-449c-9ef3-7fdc331027df","displayName":"Azure Virtual Desktop","description":"Administrative Templates Windows Components Remote Desktop Services Remote Desktop Session Host Azure Virtual Desktop","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["5d4e843b-2848-4508-9143-cb3217c2fe83"],"platforms":"windows10","technologies":"mdm"},{"id":"8495c82c-f273-4bcc-8886-6751103a9c7b","displayName":"Proofing","description":"Microsoft Visio 2016 Visio Options Proofing","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["af9b2941-29f9-4ee5-ae09-215f4e242943"],"platforms":"windows10","technologies":"mdm"},{"id":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","displayName":"User Experience","description":"User Experience","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":["e42edcd8-fcb0-4255-a774-c78b34f0b0c9","cc388035-b49c-493e-a598-14b0d0de4359","361859d9-1382-47c3-b9ec-9251a62fbb25","c00d6468-cac3-429c-ada5-ba3adf4982a8","11c4cf0f-a03d-4309-93b2-011be4c410d5","b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","ff90bf4b-0583-4761-a1c4-5aa4b50c5872","d8f06fcf-7328-43ac-b5b7-f7166b5333de"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"84b7f123-e849-40f9-914b-4b97b57bd3b4","displayName":"Interface","description":"Microsoft Project 2016\\Project Options\\Interface","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["343eb575-3ac8-4da9-b66d-ce84b84be7c3","81bc8383-43a5-4c6a-9d51-951e86028934","fe7c8652-17d4-40a7-869c-f7cfc3454402"],"platforms":"windows10","technologies":"mdm"},{"id":"84de2eed-843c-401b-a3fd-e21be88f2365","displayName":"Pen","description":"Microsoft OneNote 2016\\OneNote Options\\Pen","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"853d5a82-91e4-4c53-8338-fd1a3d9b542c","displayName":"MK Protocol Security Restriction","description":"Administrative Templates Internet Explorer Security Features MK Protocol Security Restriction","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"853f4181-42e8-411c-91cf-c06968c0a543","displayName":"Time Server","description":"System Configuration > Time Server","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"85810387-3320-4056-bae2-953beeb246f7","displayName":"Security","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["9544c86b-47bb-4cb2-a725-63214a0454f4","36ddafde-fdc7-4787-bf6e-2291446ccc6b"],"platforms":"windows10","technologies":"mdm"},{"id":"859f3bfb-70f6-447a-822e-680ac98e91ce","displayName":"Microsoft Visual Studio","description":"Visual Studio","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":["802f3065-0bf1-4578-9d6d-ab1ef02db3ec","175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","b3b30966-47ac-4b54-a75a-04418d5c6153","d9d5f333-9402-4459-8ef1-e29330cac8be","652a676c-9d60-4c9a-88b6-823a24961a9b","96277512-3d35-4876-ad74-2d849348799e"],"platforms":"windows10","technologies":"mdm"},{"id":"85c586a6-6b68-48b2-8050-c4fb86aff486","displayName":"RD Gateway","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\RD Gateway","helpText":null,"parentCategoryId":"572bc940-42d4-4e00-ac55-012e9b90f6df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"865a5fd9-f9be-496d-acb4-cd7cdb03e19f","displayName":"Security Center","description":"Administrative Templates\\Windows Components\\Security Center","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","displayName":"Disable Items in User Interface","description":"Microsoft Office 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86b4fa22-f6f1-4ca5-8fe4-8788f9b3fd89","displayName":"Power Throttling Settings","description":"Administrative Templates Power Management Power Throttling Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","displayName":"Updates","description":"Microsoft Office 2016 (Machine)\\Updates","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86e78a4b-706a-4ec8-be90-439461abb29d","displayName":"File Revocation","description":"Administrative Templates File Revocation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","displayName":"SSL Configuration Settings","description":"Administrative Templates SSL Configuration Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"87667b72-85ce-48c2-8023-e6db7f5fe739","displayName":"Work Folders","description":"Administrative Templates Work Folders","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8778eb21-bf7c-41a7-bae1-412c0e3029db","displayName":"Licensing","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Licensing","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"87e607d8-500d-4dba-a58f-d7695945c973","displayName":"Early Launch Antimalware","description":"Administrative Templates\\System\\Early Launch Antimalware","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"87f460f4-8403-419c-bfb4-44dec5edcccb","displayName":"Media Management Disc Burning","description":"Media Management > Media Management Disc Burning","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"87f460f4-8403-419c-bfb4-44dec5edcccb","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","displayName":"Lanman Workstation","description":"Administrative Templates Lanman Workstation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"88b16683-81f2-450a-9bf2-42f582e0b748","displayName":"Stationery and Fonts","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\Stationery and Fonts","helpText":null,"parentCategoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"891d2958-5a8c-479c-aa68-69b1b6c735e1","displayName":"Shared PC","description":"Shared PC","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"89519fc9-9b38-4401-8767-b0a047cae515","displayName":"Device Restriction","description":"Device Restriction","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":["2257f7e1-3e88-4d4d-a666-437bbe42baca","929c169a-3480-467c-9f47-d1836b359ef7","bf8e3e9c-f7e7-4a43-8898-2caf7b01d987","70c4566f-a079-4a8e-ac97-0736b405df1d","990880db-3f64-4436-ab4a-d7d5181dfa5d","f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","aad0d3ef-88f5-4b22-831b-27093eafbc64","b6733d23-eadc-486a-abfc-62b78698a16c"],"platforms":"androidEnterprise,aosp","technologies":"android"},{"id":"895e0884-6b60-4bb0-b2ab-3a1642103db7","displayName":"Native Messaging","description":"Google Google Chrome Native Messaging","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","displayName":"Downloads","description":"Microsoft Edge - Default Settings users can override Downloads","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"897675f9-0d1b-437b-ba0a-584fbd54df95","displayName":"Advanced E-mail Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options\\Advanced E-mail Options","helpText":null,"parentCategoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["35f245bd-8d1f-424c-83de-a80be27a6a4e","832f3a51-5e73-4541-8f14-1323cd9919bc"],"platforms":"windows10","technologies":"mdm"},{"id":"89ad0055-1603-420e-940d-9944a63e3da9","displayName":"Profiles","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Profiles","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","displayName":"Save","description":"Microsoft Word 2016\\Word Options\\Save","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"89c0381d-3b9b-4be5-8077-ffb18d47e910","displayName":"Add-on Management","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Add-on Management","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8a03aebc-9249-4917-a1c3-2957717d9123","displayName":"Real-time Protection","description":"Administrative Templates Microsoft Defender Antivirus Real-time Protection","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8a409581-8ea5-493c-9e9e-2190f66381c3","displayName":"DirectAccess Client Experience Settings","description":"Administrative Templates\\Network\\DirectAccess Client Experience Settings","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8aa3383a-efac-4ec4-841d-06e3e18646d8","displayName":"Default search provider","description":"Microsoft Edge\\Default search provider","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"8abddb23-7036-4ba8-8912-529279a849ea","displayName":"Security Preferences","description":"Security > Security Preferences","helpText":null,"parentCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8b0e5a63-c309-430b-8521-7bd21e715b90","displayName":"Office 2016 Converters","description":"Microsoft Office 2016\\Office 2016 Converters","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8b7e662c-0410-4e33-ae11-edb7c717d914","displayName":"Restricted Browsing","description":"Microsoft Office 2016\\File Open/Save dialog box\\Restricted Browsing","helpText":null,"parentCategoryId":"92be4fc7-8095-441c-b52b-9861c21bc337","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","displayName":"Immersive Reader settings","description":"Microsoft Edge Immersive Reader settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"8c30a64e-ad24-47a0-97a8-52320360fd88","displayName":"Net Logon","description":"Administrative Templates Net Logon","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["41ba590e-9105-4eda-92fb-13c7d34b8eee"],"platforms":"windows10","technologies":"mdm"},{"id":"8c35f124-e249-43e3-9044-ecc0b0a5855a","displayName":"Idle Browser Actions","description":"Google Google Chrome Idle Browser Actions","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8c75a12d-664d-43ba-a3aa-5259425f9b37","displayName":"Energy Saver","description":"System Configuration > Energy Saver","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","displayName":"App Settings","description":"Declarative Device Management preview App Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"8c879ddf-7acf-45f3-81d3-2c78c7a1321b","displayName":"Miscellaneous","description":"Microsoft Office 2016 (Machine)\\Miscellaneous","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8caf4546-4ed8-4e8a-b9e7-5ab48c13b709","displayName":"PackageManagement","description":"Administrative Templates\\System\\App-V\\PackageManagement","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8ccb6340-4f25-4bda-a527-127d269b3cbf","displayName":"Windows Calendar","description":"Administrative Templates\\Windows Components\\Windows Calendar","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8cefd936-362e-4a24-bc76-e078b6fd13fa","displayName":"Screensaver","description":"System Configuration > Screensaver","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","displayName":"Trusted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Trusted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8d27fb75-5aeb-44f0-aab2-064cc4b9ecd6","displayName":"Audit Process Creation","description":"Administrative Templates\\System\\Audit Process Creation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8d4a5b79-8399-4075-a71f-80ac3099ae78","displayName":"Bluetooth","description":"Bluetooth","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"8d503574-f93a-4277-a30d-19895d46dd13","displayName":"Security Page","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page","helpText":null,"parentCategoryId":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["4086190d-2e5b-439d-8426-08492ebb8c9f","58ae30f4-10a2-4144-a593-b5f5bd93c10d","dfede24d-d1c8-4e20-82a3-89e1b52057d5","99dfe848-181d-480a-bd20-3f93f04b6f5c","fca9261c-1e93-467d-90cf-ba9108e4cb2e","8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","ac014aea-e417-46ad-a4a5-9a1fb1030882","44c15b2f-10da-4e1e-836b-8b71c19fe34c"],"platforms":"windows10","technologies":"mdm"},{"id":"8d5ce834-5b70-4ec2-8d07-eae26ab6493f","displayName":"Consistent Mime Handling","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Consistent Mime Handling","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8d9eaa88-a2b4-42e7-83e5-8dc12f51d36b","displayName":"Eap","description":"Eap","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"8d9eaa88-a2b4-42e7-83e5-8dc12f51d36b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","displayName":"Device Installation","description":"Administrative Templates Device Installation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["68237832-f376-4f0e-ba26-4e06fce7a35d"],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"8dca6b5f-ff9c-44c8-9822-008acef616aa","displayName":"Security","description":"Administrative Templates\\Windows Components\\Event Log Service\\Security","helpText":null,"parentCategoryId":"fcddcc0b-7cf8-4ebc-a818-d10689603263","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","displayName":"SharePoint Server","description":"Microsoft Office 2016\\Server Settings\\SharePoint Server","helpText":null,"parentCategoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e19ed1e-e870-4769-bd6f-321f6f47023b","displayName":"Application Compatibility Settings","description":"Administrative Templates\\System\\Distributed COM\\Application Compatibility Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e48532a-ff0e-4422-82e2-6956b6786005","displayName":"Customize Ribbon","description":"Microsoft Project 2016\\Project Options\\Customize Ribbon","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","displayName":"Intranet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Intranet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","displayName":"Removable Data Drives","description":"Administrative Templates BitLocker Drive Encryption Removable Data Drives","helpText":null,"parentCategoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","displayName":"Junk E-mail","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Junk E-mail","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8eb61398-1074-4fa0-8bd4-04d751a9ccad","displayName":"Windows Memory Leak Diagnosis","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Windows Memory Leak Diagnosis","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8ee1d8d2-582f-401b-927a-993016f4290d","displayName":"Browsers","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\Browsers","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","displayName":"Windows Error Reporting","description":"Administrative Templates Windows Error Reporting","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["1551f6d3-415c-44a8-b184-393de7c42adf","184981d4-712b-425e-b0a3-93eac7fbd3ee"],"platforms":"windows10","technologies":"mdm"},{"id":"8efd284f-5a56-4da8-8821-f51984ff954d","displayName":"Associated Domains","description":"App Management > Associated Domains","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","displayName":"Login Window Behavior","description":"Login > Login Window Behavior","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8ff93a7a-503c-4955-89be-900d475b7c5e","displayName":"Managed Settings","description":"Managed Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":["0be23ead-c5f7-4ea5-9ec5-64c05d19cf5d","99d68d97-63b7-4f49-83dd-1ad3b3281d0d","1fbc29d7-0530-4208-b506-9df648a402e9","5f71c40e-01aa-42d2-9c8c-7d560126cd4b","b32726b3-b0e9-465b-86f8-b61ad8af52f0","ef7328b1-c666-40fe-a933-57b14bc77dd3","e7dccaa6-2b16-4dd3-b835-83ca641d0c80","3c7f15ef-a539-411c-93f1-5f97b7bd5519","1a056b49-3fb9-4097-b286-c5f493208578","724d930a-7a3c-4171-a17c-431cee336518","dd68a290-1ba7-470f-afca-339f443a767c","2c156b7e-99c8-4a21-a828-4f9b94479b0d"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","displayName":"Networking","description":"Administrative Templates Windows Media Player Networking","helpText":null,"parentCategoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"902f5df1-31d6-44ee-ba95-2561199db35f","displayName":"Sync your settings","description":"Administrative Templates Sync your settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","displayName":"Global HTTP Proxy","description":"Proxies > Global HTTP Proxy","helpText":null,"parentCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","rootCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"907fd656-2a80-4f34-8615-a3acb11a2b95","displayName":"Custom","description":"Microsoft Publisher 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"9caa3b08-b545-4c21-a3b7-b5d2302c1a81","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"909339a5-8f04-4fa2-8807-5d38c83ef547","displayName":"Device Guard","description":"Administrative Templates Device Guard","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"90bbab80-ecf0-47c6-bf01-76b26a3dc503","displayName":"Touch Input","description":"Administrative Templates\\Windows Components\\Tablet PC\\Touch Input","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"90e3acc6-80d5-41b4-8141-a8620a211c0e","displayName":"Tenant Restrictions","description":"Administrative Templates Tenant Restrictions","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","displayName":"Online Content","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...\\Online Content","helpText":null,"parentCategoryId":"af14a55b-d79b-4299-946c-b7582412b748","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","displayName":"Local Policies Security Options","description":"Local Policies Security Options","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91789113-6339-4e96-8e1d-73a4dec4967f","displayName":"Parameters","description":"Administrative Templates TCPIP Settings Parameters","helpText":null,"parentCategoryId":"785c6df2-c6d0-4d6e-bd73-c3b62caca754","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"917d0fb9-b5dd-401b-982b-1d32f6e0a306","displayName":"Pen UX Behaviors","description":"Administrative Templates\\Windows Components\\Tablet PC\\Pen UX Behaviors","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","displayName":"International Options","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\International Options","helpText":null,"parentCategoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91c02e14-8848-485d-8844-b9933fa888ec","displayName":"Hard Disk Settings","description":"Administrative Templates Power Management Hard Disk Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91ed1812-8841-4eb3-b24e-a5e1f4eaa6c8","displayName":"Restrict File Download","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Restrict File Download","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9215e382-4e7b-4554-8c80-80277136b544","displayName":"Formulas","description":"Microsoft Excel 2016\\Excel Options\\Formulas","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"92503b7f-9fa0-4365-8482-57dd61e6d535","displayName":"RD Connection Broker","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\RD Connection Broker","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"929c169a-3480-467c-9f47-d1836b359ef7","displayName":"Connectivity","description":"Device Restriction Connectivity","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"92be4fc7-8095-441c-b52b-9861c21bc337","displayName":"File Open/Save dialog box","description":"Microsoft Office 2016\\File Open/Save dialog box","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["8b7e662c-0410-4e33-ae11-edb7c717d914","4a832199-a841-4b6a-84fa-51365902a742"],"platforms":"windows10","technologies":"mdm"},{"id":"92d69c43-75ac-49b1-a3ef-9350079eef86","displayName":"Content settings","description":"Microsoft Edge\\Content settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","displayName":"Account Settings","description":"Microsoft Outlook 2016\\Account Settings","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["060e7533-6c2f-4ed1-9173-f3de58de4bed","43053249-ecd1-4d9f-9fa9-c05e7713da7f","c4dbc05f-da1e-440d-8beb-91bf9dad1875","b161cf66-abfa-4a36-a9ac-c20ca60594e0","63ca5d8b-829d-42c5-92e8-35f9ca47fb0e","ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","4e349e4a-dd0b-4175-8974-a2a0f5e35b4d"],"platforms":"windows10","technologies":"mdm"},{"id":"93099bd4-c685-434b-9d72-f0cb6db5e753","displayName":"Cloud delivered protection preferences","description":"Microsoft Defender > Cloud-delivered protection preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"930d2960-3f70-48ca-9ead-b65a5a037c07","displayName":"SNMP","description":"Administrative Templates SNMP","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9329c2bd-9e56-4394-9c89-5726e8b76f2f","displayName":"Scripts","description":"Administrative Templates\\System\\Scripts","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93a20c17-1e34-4778-8c95-91a46980ea75","displayName":"Out of Office Assistant","description":"Microsoft Outlook 2016\\Outlook Options\\Out of Office Assistant","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93c28398-faef-4ca5-9667-f5ed004da32c","displayName":"Internet Information Services","description":"Administrative Templates Internet Information Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93decccd-de24-4ec4-b21c-e08c14f13576","displayName":"Common Open File Dialog","description":"Administrative Templates\\Windows Components\\File Explorer\\Common Open File Dialog","helpText":null,"parentCategoryId":"35525ba9-da99-460e-afd3-ba86506b0ba3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93ed2300-658d-40f3-8211-9295a240579c","displayName":"HTTP authentication","description":"Google Google Chrome HTTP authentication","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"949a5b32-bbe6-40f6-9d73-99cf9fafe75f","displayName":"Removable Data Drives","description":"Administrative Templates\\Windows Components\\BitLocker Drive Encryption\\Removable Data Drives","helpText":null,"parentCategoryId":"0101d1d0-1e54-47b0-a749-62c6bd7ab3da","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","displayName":"Notifications","description":"Administrative Templates Notifications","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94b5c25e-3af3-4c08-b738-a0527f91dc22","displayName":"Security Intelligence Updates","description":"Administrative Templates Microsoft Defender Antivirus Security Intelligence Updates","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94ce8206-be22-496c-aa72-f3560e2a5c8d","displayName":"Links","description":"Microsoft Office 2016 Links","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94f6e868-1296-4811-b404-1afa2d50bc7c","displayName":"Windows Boot Performance Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Windows Boot Performance Diagnostics","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","displayName":"Storage","description":"Storage","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","displayName":"Accounts","description":"Accounts","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":["5214f1e7-a5a9-4de5-80b4-2f7084a8d068","fa20bbc3-d25d-4a7f-a349-9b211d186e21","ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","9ba1b877-865a-4104-8376-b43a0c75b04b","831dcaee-a6fa-4893-a32d-e13fdf7d3777","45fe783f-a80b-42d9-ab3c-8c4081be8d05"],"platforms":"iOS,macOS,windows10","technologies":"mdm,appleRemoteManagement"},{"id":"952f69c8-2644-48df-976b-01fd624cbb3a","displayName":"Database","description":"Microsoft Office 2016\\Business Data\\Database","helpText":null,"parentCategoryId":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9544c86b-47bb-4cb2-a725-63214a0454f4","displayName":"Cryptography","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"85810387-3320-4056-bae2-953beeb246f7","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"957a5b24-ed7a-4f84-9d73-7b6131367396","displayName":"Advanced","description":"Microsoft Visio 2016\\Visio Options\\Advanced","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["bec8c55d-5aee-4d87-a17d-34d5b3b78f19","4e62ada2-f091-49e1-99dd-ffdf5cf558cd","98cefd27-a980-4070-ba45-3696b623810d","f59804be-7fc6-43c3-9baa-942aab85be84","6ae0d607-832c-403b-b3bc-c563e390ebad","66395272-f132-4170-b88e-87f794f987f4"],"platforms":"windows10","technologies":"mdm"},{"id":"96277512-3d35-4876-ad74-2d849348799e","displayName":"Privacy Settings","description":"Visual Studio Privacy Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"962a2377-ad9a-4654-a526-a77c14152fd7","displayName":"Content settings","description":"Google Google Chrome - Default Settings users can override Content settings","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"979412d7-6716-440c-9a64-5889026d73da","displayName":"Device Installation Restrictions","description":"Administrative Templates\\System\\Device Installation\\Device Installation Restrictions","helpText":null,"parentCategoryId":"486dc66e-960c-4622-b3cb-3ff9a2d434eb","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"9859957e-34f1-4669-9f95-2b7c79fff052","displayName":"Service Management - Managed Login Items","description":"Login > Service Management - Managed Login Items","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"9865907f-b775-4d36-9578-a016c5105dfe","displayName":"AutoSave","description":"Microsoft Office 2016\\AutoSave","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"98c9cd71-f6eb-4dfd-b045-85c7e0b44487","displayName":"Controlled Folder Access","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Microsoft Defender Exploit Guard\\ Controlled Folder Access","helpText":null,"parentCategoryId":"49abf969-2a98-4479-b234-6990b152cb21","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"98cefd27-a980-4070-ba45-3696b623810d","displayName":"Shape Search","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Shape Search","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"98dc5bd0-2b16-4263-ba2f-62115b680017","displayName":"Group Policy","description":"Administrative Templates Group Policy","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["73935f55-c845-40ce-819e-838c0041f6fa","5bb9fb31-007d-4e3f-967b-11e865fcdc70"],"platforms":"windows10","technologies":"mdm"},{"id":"98e76d3e-9e52-45b3-b0c7-f029023121e9","displayName":"Privacy","description":"Privacy","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","childCategoryIds":["82d173f9-ba0b-4b09-bbb8-68cba4916162"],"platforms":"macOS,windows10","technologies":"mdm"},{"id":"990880db-3f64-4436-ab4a-d7d5181dfa5d","displayName":"Personal Profile","description":"Device Restriction Personal Profile","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"992a8a1e-428e-41cb-948e-4e5da86105fa","displayName":"Device Guard","description":"Device Guard","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"992a8a1e-428e-41cb-948e-4e5da86105fa","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"99b4ac32-50b5-4659-a7a1-94bc708ae71a","displayName":"Device Health Attestation Service","description":"Administrative Templates Device Health Attestation Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"99ba9e42-9872-4a03-a615-fc4a4cebc067","displayName":"Active Directory","description":"Administrative Templates Active Directory","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"99d68d97-63b7-4f49-83dd-1ad3b3281d0d","displayName":"Diagnostic Submission","description":"Managed Settings Diagnostic Submission","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"99dfe848-181d-480a-bd20-3f93f04b6f5c","displayName":"Locked- Down Intranet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Intranet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9a2bfe77-7e03-4a24-a9fa-c42a225a28b8","displayName":"Intelligent Services","description":"Microsoft Excel 2016\\Intelligent Services","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9a7843b4-6ec1-47c4-906b-75b8866e97c2","displayName":"Maps","description":"Maps","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9a7843b4-6ec1-47c4-906b-75b8866e97c2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9a79d480-8cb4-47b5-95c7-5da56eea5bb8","displayName":"Handwriting personalization","description":"Administrative Templates Regional and Language Options Handwriting personalization","helpText":null,"parentCategoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9aaa7ee2-727d-426f-8a2b-6b10a4cd084f","displayName":"RSS Feeds","description":"Administrative Templates RSS Feeds","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9ad70461-c727-40da-8484-250369b6a119","displayName":"Client Coexistence","description":"Administrative Templates\\System\\App-V\\Client Coexistence","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9b0b8f3b-8e08-4083-9e2b-2e6bfeb01f83","displayName":"Kerberos","description":"Administrative Templates\\System\\Kerberos","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","displayName":"Miscellaneous","description":"Microsoft Office 2016\\Miscellaneous","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["5f048379-3a42-43f0-9fd5-d269f292aa35"],"platforms":"windows10","technologies":"mdm"},{"id":"9b74c5a8-98f8-49f0-b4eb-51e071d75776","displayName":"Task Scheduler","description":"Task Scheduler","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9b74c5a8-98f8-49f0-b4eb-51e071d75776","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9b894b32-3697-4a83-9731-3db2a35455ad","displayName":"Cursors","description":"Administrative Templates Cursors","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9ba1b877-865a-4104-8376-b43a0c75b04b","displayName":"LDAP","description":"Accounts > LDAP","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"9bad0513-ac85-431c-86d9-9e3167f9b403","displayName":"Locked-Down Intranet Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Locked-Down Intranet Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","displayName":"Remote Desktop","description":"Remote Desktop Command","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"9c815001-eace-4aa6-a929-14af0a46aaf5","displayName":"Windows Shutdown Performance Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Windows Shutdown Performance Diagnostics","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9caa3b08-b545-4c21-a3b7-b5d2302c1a81","displayName":"Disable Items in User Interface","description":"Microsoft Publisher 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["441d6cc4-e51f-453e-a44d-8394509415be","907fd656-2a80-4f34-8615-a3acb11a2b95"],"platforms":"windows10","technologies":"mdm"},{"id":"9d14bbed-327d-4c38-ac02-6b916909bdd9","displayName":"Microsoft Edge","description":"Microsoft Edge Apple","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"9d26f3a1-6a54-4043-bda2-bfeb84e80524","displayName":"System","description":"Administrative Templates\\Windows Components\\Event Log Service\\System","helpText":null,"parentCategoryId":"fcddcc0b-7cf8-4ebc-a818-d10689603263","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9d6a14ba-11f5-423d-afc0-8d30be1153c1","displayName":"Link-Layer Topology Discovery","description":"Administrative Templates\\Network\\Link-Layer Topology Discovery","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9dbd66e3-4544-4ca8-a118-272c874bc684","displayName":"Local Security Authority","description":"Administrative Templates Local Security Authority","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9e857bed-81f8-4dfc-b049-c93eb68b4064","displayName":"Microsoft User Experience Virtualization","description":"Administrative Templates\\Windows Components\\Microsoft User Experience Virtualization","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["8028dead-8f13-4fe3-9998-ba1e841324d7","3afbcb74-88c5-4a41-bdc2-82c117b4e82e"],"platforms":"windows10","technologies":"mdm"},{"id":"9e882396-4a1c-4d06-a62d-8d910ded8e7d","displayName":"Restricted/Permitted snap-ins","description":"Administrative Templates\\Windows Components\\Microsoft Management Console\\Restricted/Permitted snap-ins","helpText":null,"parentCategoryId":"c483faac-cebf-448a-8f90-e8a125c0c4af","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["3d32fb39-ff23-48d9-9890-c8625d2d21e9","6355e85b-aeef-49e8-b8c9-5d6cd9a39985"],"platforms":"windows10","technologies":"mdm"},{"id":"9ecb05b7-e942-4b60-9040-d612385f5c67","displayName":"Calendar","description":"Microsoft Project 2016\\Project Options\\Calendar","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","displayName":"Locked- Down Restricted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Restricted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","displayName":"User Rights","description":"User Rights","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","displayName":"Accessories","description":"Administrative Templates Accessories","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a004deb8-6f52-4411-8d94-41563a8203fc","displayName":"Quarantine","description":"Administrative Templates Microsoft Defender Antivirus Quarantine","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a01c03d4-ec76-4c01-b982-de71620feb19","displayName":"Printing","description":"Printing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","childCategoryIds":["174ffe92-3770-4688-aa21-85b7535cf374","429c4b85-a2b4-46ed-afa0-6c89c08a5544"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","displayName":"Microsoft App Store","description":"Microsoft App Store","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a0f1f801-7fce-427c-b5e2-6c6b30065fa5","displayName":"MpEngine","description":"Administrative Templates\\Windows Components\\Microsoft Defender Antivirus\\MpEngine","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a126378d-a916-476e-ad91-e3bd82fd3a48","displayName":"Notification bar","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Notification bar","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a18508d1-fd74-4955-8032-3bd9219a0944","displayName":"Fixed Data Drives","description":"Administrative Templates BitLocker Drive Encryption Fixed Data Drives","helpText":null,"parentCategoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a185940c-7899-4ab6-867d-7559352cf8d2","displayName":"OneNote Options","description":"Microsoft OneNote 2016\\OneNote Options","helpText":null,"parentCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":["1ae8c95a-5748-4647-80f8-b447e60601a2","44774d3d-387b-4fa7-8de4-d82b039c06d1","1979a12b-2a72-438d-9de7-320d1b38e777","c492dd55-8876-4b1b-b620-615cc9b65ef8","a87f9d6a-0c84-4cad-839f-e912c6006c12","fa471a57-af7b-4ccf-b6ba-4c57a7230498","acfe6c36-66ab-4a3e-86b0-a178377427d2","1bfef2c3-a561-4e7a-8f0f-0944bc79c20f","ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","84de2eed-843c-401b-a3fd-e21be88f2365","4a7b0e92-ba43-46aa-96e8-c5839dbcb524","25a84f2d-dbac-457e-b734-bc2605305f2b","ab8301d6-b122-4d40-868a-d00d3c0f1916","c02141e6-0725-4f6f-9138-83d10c6bc104","e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf"],"platforms":"windows10","technologies":"mdm"},{"id":"a1d83497-da94-407f-bbc5-9f65ebc5f9fb","displayName":"Windows Mobility Center","description":"Administrative Templates\\Windows Components\\Windows Mobility Center","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a1fbe395-3b60-475f-8a34-3710d6b2e09f","displayName":"Browsing","description":"Administrative Templates Internet Explorer Internet Settings Advanced settings Browsing","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","displayName":"Custom","description":"Microsoft PowerPoint 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a2230bb9-81a5-4e95-bc7f-0fbc9ecb5de4","displayName":"Instant Search","description":"Administrative Templates\\Windows Components\\Instant Search","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a24e6384-a862-4d0e-8f6c-eb99e5f6a9db","displayName":"Windows Resource Exhaustion Detection and Resolution","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Windows Resource Exhaustion Detection and Resolution","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a24f4ab6-289a-450a-b438-1c4bb1214942","displayName":"App-V","description":"Administrative Templates\\System\\App-V","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["ea812d2c-1cf9-4132-9b33-12bb7ac17dbd","9ad70461-c727-40da-8484-250369b6a119","48f508a5-5a2c-4d20-8d89-2d352a209907","3800661e-5841-4499-8d4e-914527435f59","1f5d8243-cb7e-4b52-a12f-5f0e070d2769","0ef80736-8b59-4c6a-8bdc-e2b246b30e92","8caf4546-4ed8-4e8a-b9e7-5ab48c13b709","0236af48-9ce0-44d5-b085-de2323d7348e"],"platforms":"windows10","technologies":"mdm"},{"id":"a25a7a02-4bac-411b-9d02-10cb3297cb17","displayName":"Microsoft Edge","description":"Microsoft Edge","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":["43057320-7058-46d5-86f9-a56c80bbf8b9","fb1e99d0-b921-4b19-9842-17e3e7987528","45a89c1f-0a34-4f78-b28f-d30b623fa423","b3c8c6d9-28bb-475a-9353-4a0e657b33c7","1043e7ed-8651-44b2-b918-7230c0b75a6c","ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","81c518f1-522e-4957-b850-e8a66d2ab215","526e363a-84db-4256-a13c-e01c8c646e26","d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","2e241b46-e5ae-41d7-a559-fe40819e86f4","d17b08e6-de3b-445b-ab14-1d47e62efdcf","05811ceb-2954-426c-8afa-2a53f02480cc","2af24920-f611-4f03-99a6-205773869ae6","6d529e48-5477-4ceb-8ff7-c6e959a0e24f","5bd0eaf1-1818-44e8-9168-fc75c5739cc8","92d69c43-75ac-49b1-a3ef-9350079eef86","66615d2a-fec9-47f1-8eaf-9813e30cc023","dfab5866-1712-4bbf-8edf-5b080b315b9b","3edb2860-b77b-4240-af16-fb34d45d6ba1","ae78ab75-2d0d-418c-be6f-9e64642de4e2","3ba8106d-4b2f-4775-939d-1cc8703a41dc","fe845e81-5993-4a65-b22a-decfc5928c65","16ea64a1-563e-43cc-b34a-728c8e7cd13c","08c5f391-e156-4a72-bbb9-3670f2f63a56","120b24dd-c04a-4291-8f24-9c48fcdc1434","5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","3fbd3b29-bafd-4adf-89e4-3be612dee275","8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","fddc444c-3591-4a50-865b-d8993b798e12","3abaf4c2-d5db-4b3b-a461-b1a208231b36","8aa3383a-efac-4ec4-841d-06e3e18646d8","eb6409fc-fb52-413d-ae4b-eff017b52b30","c6099521-a05f-480a-8562-7e71318e2cda","00d7396c-cadc-4d29-86ba-fe4df2ecb110","08677354-6f67-455e-a430-4d8d2fbabe84","76e34834-6d47-4e06-b14c-aa2888cdce27","ef8760ac-a77c-4055-a812-a95bfbf9c00a"],"platforms":"android,iOS,macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"a279f35f-cd71-4489-b0c3-545ea1aa229d","displayName":"Local Security Authority","description":"Local Security Authority","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a279f35f-cd71-4489-b0c3-545ea1aa229d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","displayName":"Disable Items in User Interface","description":"Microsoft Excel 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["3b7e16e7-171f-4169-8904-c8483b06700d","3fa63a9d-e22d-4fc8-8464-a13b56461115"],"platforms":"windows10","technologies":"mdm"},{"id":"a28dd311-46e8-4868-89ab-d3745c0bca21","displayName":"Security","description":"Administrative Templates Event Log Service Security","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a321fc04-d0cb-45ec-a6bf-51d60249922d","displayName":"Automatic Picture Download Settings","description":"Microsoft Outlook 2016\\Security\\Automatic Picture Download Settings","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a33fb618-0ad1-40a3-b94b-49c90c49ea03","displayName":"RemoteFX for Windows Server 2008 R2","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Remote Session Environment\\RemoteFX for Windows Server 2008 R2","helpText":null,"parentCategoryId":"ce572b49-4d47-47b6-b787-ac1252753581","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a34ade49-964d-407c-9f60-2e8cd9dfef05","displayName":"Smart Card","description":"Administrative Templates Smart Card","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","displayName":"Programmatic Security","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Programmatic Security","helpText":null,"parentCategoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf"],"platforms":"windows10","technologies":"mdm"},{"id":"a37dba52-d558-47fb-9d46-a5d3bdc5fdd7","displayName":"Windows Remote Management (WinRM)","description":"Administrative Templates\\Windows Components\\Windows Remote Management (WinRM)","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["c919e047-97fc-489f-ab0e-bcb070e36c55","023116df-a32c-43b0-a384-d6fe7ad9fabe"],"platforms":"windows10","technologies":"mdm"},{"id":"a3e48951-624d-4fee-b470-d17ce16e6b0c","displayName":"Secure Boot","description":"Secure Boot","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a3e48951-624d-4fee-b470-d17ce16e6b0c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","displayName":"Features","description":"Microsoft Defender Features","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"a3ec7cde-bca6-4e3e-9f7e-f66a43196924","displayName":"Windows Backup And Restore","description":"Windows Backup And Restore","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a3ec7cde-bca6-4e3e-9f7e-f66a43196924","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","displayName":"Graph settings","description":"Microsoft Office 2016\\Graph settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a42e2248-d2dc-4476-a92d-d152fd67e04b","displayName":"Audio Accessory","description":"Declarative Device Management preview Audio Accessory","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS","technologies":"appleRemoteManagement"},{"id":"a4877a42-7e62-4216-a477-0b35357ab313","displayName":"Remote Desktop Connection Client","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Connection Client","helpText":null,"parentCategoryId":"572bc940-42d4-4e00-ac55-012e9b90f6df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["728890f5-bddd-4b69-a1b6-efb221d902d4"],"platforms":"windows10","technologies":"mdm"},{"id":"a4bffc2b-76af-48d3-acdf-8566e51ef163","displayName":"Restricted Sites Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Restricted Sites Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a4f5cedd-a8f7-4def-b8b6-8fbf9ce9e0d8","displayName":"Windows System Responsiveness Performance Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Windows System Responsiveness Performance Diagnostics","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a4fb2510-977f-42ff-9033-6f1eb98f141b","displayName":"Device Lock","description":"Device Lock","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5060182-4d22-412b-bd0e-3a1e009b36c6","displayName":"Client Interface","description":"Administrative Templates Microsoft Defender Antivirus Client Interface","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a51a8665-045d-482d-b68b-2128959c8b31","displayName":"WWAN UI Settings","description":"Administrative Templates\\Network\\WWAN Service\\WWAN UI Settings","helpText":null,"parentCategoryId":"fc8f887c-cfd9-4bea-bfac-2214d06dba99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a53581a1-e9d7-4ba4-9dea-cea90d40cca1","displayName":"Work Folders","description":"Administrative Templates\\Windows Components\\Work Folders","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5607145-2bd3-4473-a8ee-d7fa5c2f2675","displayName":"Fax","description":"Microsoft Office 2016\\Services\\Fax","helpText":null,"parentCategoryId":"478ed057-8ee7-4dd2-8276-06dad8f85397","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a561e59a-09b7-4106-a6fa-0b82036a5b49","displayName":"RD Gateway","description":"Administrative Templates Remote Desktop Services RD Gateway","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a57b27b6-48e0-42b2-812a-2be86c113a0c","displayName":"Application Compatibility Settings","description":"Administrative Templates Distributed COM Application Compatibility Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a57f0abc-605b-433e-b7da-45ee127188cd","displayName":"Event Logging","description":"Administrative Templates\\Windows Components\\Event Logging","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","displayName":"Password manager","description":"Google Google Chrome Password manager","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","displayName":"Reporting","description":"Administrative Templates Microsoft Defender Antivirus Reporting","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","displayName":"Co-authoring","description":"Microsoft Office 2016\\Collaboration Settings\\Co-authoring","helpText":null,"parentCategoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5ce858b-74c2-4663-9b3e-068d31349a13","displayName":"Cryptography","description":"Microsoft Word 2016\\Word Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","displayName":"Lanman Workstation","description":"Lanman Workstation","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a69e7a98-5af7-4834-bae1-2a1047663a71","displayName":"Desktop","description":"Administrative Templates\\Desktop\\Desktop","helpText":null,"parentCategoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","displayName":"Synchronization","description":"Microsoft Office 2016\\Business Data\\Synchronization","helpText":null,"parentCategoryId":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","displayName":"Wireless Display","description":"Wireless Display","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6fe8038-136b-4d50-bf04-8e232409c0d2","displayName":"Web Content Filter","description":"Web > Web Content Filter","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"a754c9bd-2116-4dd6-9014-07f914869145","displayName":"Proxies","description":"Proxies","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","childCategoryIds":["b8ed9eb3-17de-4091-b08b-7adb2fe13271","906df5cd-1d9e-49d0-ab32-cf5c5a041974"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"a77e6e83-a02e-4a51-a27e-6437ea42aeb5","displayName":"Human Presence","description":"Human Presence","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a77e6e83-a02e-4a51-a27e-6437ea42aeb5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a787672d-4a33-455b-a2db-e340eb35a5c8","displayName":"WSL container","description":"Windows Subsystem for Linux WSL container","helpText":null,"parentCategoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","rootCategoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a788a6e5-ab3f-41e5-96c8-ee59627dcb4d","displayName":"Workgroup Administrator...","description":"Microsoft Access 2016\\Tools | Security\\Workgroup Administrator...","helpText":null,"parentCategoryId":"607a1c39-a3db-496f-8db6-c99d67f5f76c","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a79b2d36-7dea-4a84-81ef-27f99296bccf","displayName":"Authentication","description":"Authentication","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":["f35cc803-3a06-4262-b38b-a5295321f756","c3fdc01d-0648-4dcb-855d-7afe78bf1d89","7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","5995d2ad-5ec7-49d2-ada2-d9c2b57746ba"],"platforms":"iOS,macOS,windows10","technologies":"mdm,appleRemoteManagement"},{"id":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","displayName":"SmartScreen settings","description":"Microsoft Edge - Default Settings (users can override)\\SmartScreen settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a7b1c291-6bec-499b-9018-6120950cd5a6","displayName":"App Control for Business","description":"App Control for Business","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a7d55d90-e1d1-4577-8bfd-fe2641bce461","displayName":"User Interface Options","description":"Microsoft Visio 2016\\Visio Options\\General\\User Interface Options","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a7e7529f-1030-41da-8b4d-024e1c08bbac","displayName":"Windows Standby Resume Performance Diagnostics","description":"Administrative Templates Windows Standby Resume Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a809df26-b5db-4af9-b247-a539ada4e869","displayName":"Add or Remove Programs","description":"Administrative Templates\\Control Panel\\Add or Remove Programs","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a877a2ff-f144-421f-814c-593e972a8a20","displayName":"Password manager and protection","description":"Microsoft Edge - Default Settings (users can override)\\Password manager and protection","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a87f9d6a-0c84-4cad-839f-e912c6006c12","displayName":"Send to OneNote","description":"Microsoft OneNote 2016\\OneNote Options\\Send to OneNote","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","displayName":"Microsoft Office 2016","description":"Microsoft Office 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["042ab9cf-9524-4dd4-b049-4d5f4ff7053f","2d6891a4-ee83-4e55-8e23-09513e1306e4","af14a55b-d79b-4299-946c-b7582412b748","bc633a5a-c712-49a6-9f56-775ca9321df4","5cd6dc4f-b231-449f-bc10-16041b73356a","eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","adf11731-7089-4e2e-8dde-4bd9ef86b067","449201b6-5002-42d1-85ed-d288fb6552da","cc29afc6-309c-4a0d-86f6-60081ae7cd4c","72a7524b-11c5-4695-9fcf-6cf30c8ba2b9","eb947c30-3c43-4d34-a566-a842a1a142f3","6aeb1df3-d796-4c5b-921d-9f3970a754cc","866eedbc-ffd9-457d-b02b-7b163d55c4bd","44541a16-c3a2-4be1-ba42-4fc15bde4c46","da04d4b8-bd11-439e-9663-5fd2399d9cc1","760376f3-6b74-4992-89eb-aa41d6190e94","5b1be2c5-9939-4b2e-b29b-b22069455c90","94ce8206-be22-496c-aa72-f3560e2a5c8d","2f56761a-8e8b-4788-a589-a73ab91818e6","05a6f86f-dab7-4888-97a1-db3457f00974","055293ad-c585-40c0-b66c-76ff5cc0a332","9b2ad6d8-8837-4c50-89d5-7507b69c7dec","8b0e5a63-c309-430b-8521-7bd21e715b90","59c9b1c4-1757-4cf3-9b27-954dafe016d5","7a8b936d-b4b0-408f-bec5-3c97050730f8","42d8353a-a135-4c2d-8d06-c6cf9961c6c5","9865907f-b775-4d36-9578-a016c5105dfe","b94cbc54-e565-44f2-a27a-a63b2514d8bf","4e0d279d-5ddd-4c4e-8590-6ed92129444d","5bf4c2ba-be08-4cda-bf33-d10707580d78","23c09e06-5bee-4b20-a391-36549bf0f620","8084033c-156a-4d1b-ab0b-159541810459","0696109e-045f-486a-9a6b-ab7877887bed","1942922a-cba9-44c8-871f-3d915c62bd06","33fb4f49-5c7f-472c-a0f3-e05646a55902","4aec010d-487a-4752-8e66-aedb9e4fbb5a","92be4fc7-8095-441c-b52b-9861c21bc337","50b4bc60-802c-477a-9366-80e09154595f","e86f24d3-8531-4298-b064-692ea795b1d9","a40e47b0-5b27-4e4d-b2ef-42f20540e812","478ed057-8ee7-4dd2-8276-06dad8f85397","6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","2d5a483f-b408-426d-9234-2883eae20afb"],"platforms":"windows10","technologies":"mdm"},{"id":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","displayName":"Save","description":"Microsoft Excel 2016\\Excel Options\\Save","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","displayName":"Security","description":"Microsoft Outlook 2016\\Security","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["a321fc04-d0cb-45ec-a6bf-51d60249922d","1720d60f-40a6-471c-8e4c-efbacaf46997","c3db5686-3bb2-437c-8906-60da1a1fa844","d4e5541e-ab77-4e6c-8046-1fb80ee705ad"],"platforms":"windows10","technologies":"mdm"},{"id":"a9edc695-b4a9-4111-b07d-627f934f5a1a","displayName":"Trust Center","description":"Microsoft Access 2016\\Application Settings\\Security\\Trust Center","helpText":null,"parentCategoryId":"23fd467e-24f8-4200-8b19-c6c11afa8926","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["12ad5ec7-346d-4b8b-9eba-d826cdb61c31"],"platforms":"windows10","technologies":"mdm"},{"id":"aa67f0c0-4eb0-492f-a528-decd3e256a22","displayName":"Hardware Buttons","description":"Administrative Templates\\Windows Components\\Tablet PC\\Hardware Buttons","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"aad0d3ef-88f5-4b22-831b-27093eafbc64","displayName":"Users and Accounts","description":"Device Restriction User and Accounts","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","displayName":"Logging","description":"FS Logix Logging","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","displayName":"Consistent Mime Handling","description":"Administrative Templates Internet Explorer Security Features Consistent Mime Handling","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ab6aa2f6-87bf-4a06-a206-e0902af3e4bc","displayName":"WWAN Media Cost","description":"Administrative Templates\\Network\\WWAN Service\\WWAN Media Cost","helpText":null,"parentCategoryId":"fc8f887c-cfd9-4bea-bfac-2214d06dba99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ab754829-54a1-4082-abfa-56bae0b07ff3","displayName":"Presentation Settings","description":"Administrative Templates\\Windows Components\\Presentation Settings","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ab8301d6-b122-4d40-868a-d00d3c0f1916","displayName":"Other","description":"Microsoft OneNote 2016\\OneNote Options\\Other","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"abf781d7-1179-4f24-8d01-5611db14eddc","displayName":"Touch Input","description":"Administrative Templates Touch Input","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac014aea-e417-46ad-a4a5-9a1fb1030882","displayName":"Locked- Down Internet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Internet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac0a894c-173a-48fc-b961-901f28463c77","displayName":"Direct Access Client Experience Settings","description":"Administrative Templates Direct Access Client Experience Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","displayName":"User Profiles","description":"Administrative Templates User Profiles","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","displayName":"Related Website Sets Settings","description":"Google Google Chrome Related Website Sets Settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","displayName":"Sleeping Tabs settings","description":"Microsoft Edge - Default Settings (users can override)\\Sleeping Tabs settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acb49e73-5a6a-479b-9d58-c3cd7f632e9b","displayName":"Restricted Permitted snap-ins","description":"Administrative Templates Microsoft Management Console Restricted Permitted snap-ins","helpText":null,"parentCategoryId":"07c023d3-0899-40af-a04f-805876d99a9b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["756d2b0b-5f06-45e7-b5c5-c066deb5ed2f"],"platforms":"windows10","technologies":"mdm"},{"id":"acbc106b-796a-4ba3-ab5f-c130530ad455","displayName":"Earned Value options for Project1","description":"Microsoft Project 2016\\Project Options\\Calculation\\Calculation options for 'Project1'\\Earned Value options for Project1","helpText":null,"parentCategoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","displayName":"Operating System Drives","description":"Administrative Templates BitLocker Drive Encryption Operating System Drives","helpText":null,"parentCategoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"accec716-3bf1-4a33-882d-3538d32fcbbc","displayName":"Browsing","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Settings\\Advanced settings\\Browsing","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acfe6c36-66ab-4a3e-86b0-a178377427d2","displayName":"Save","description":"Microsoft OneNote 2016\\OneNote Options\\Save","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ad100c6c-9a9a-42cf-8f42-b31c406c1a56","displayName":"Security Intelligence Updates","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Security Intelligence Updates","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ad1ecbf4-75da-4dc1-9354-7d00c0e2af72","displayName":"Allday","description":"Allday","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ad1ecbf4-75da-4dc1-9354-7d00c0e2af72","childCategoryIds":[],"platforms":"android,iOS","technologies":"exchangeOnline"},{"id":"ad47f904-ede2-4b12-849e-bf751d88abf5","displayName":"Display","description":"Administrative Templates Display","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ad84cea3-5664-4e42-a9d6-1446828bea45","displayName":"Microsoft Defender Exploit Guard","description":"Administrative Templates Microsoft Defender Antivirus Microsoft Defender Exploit Guard","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["210b9c4d-e72a-45a4-97d3-339a6b30c49c","72f61c7d-e5d2-4170-baf3-c953c1082e19"],"platforms":"windows10","technologies":"mdm"},{"id":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","displayName":"Save","description":"Microsoft Visio 2016\\Visio Options\\Save","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["2eed22da-106f-4c93-9a45-5ce803b50233","73415dea-0103-4427-83c5-6c97bf81af1d"],"platforms":"windows10","technologies":"mdm"},{"id":"adc4eb7f-0f34-4f43-b361-dc42363eccab","displayName":"Mp Engine","description":"Administrative Templates Microsoft Defender Antivirus Mp Engine","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"adf11731-7089-4e2e-8dde-4bd9ef86b067","displayName":"What's New","description":"Microsoft Office 2016\\What's New","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","displayName":"Sleeping Tabs settings","description":"Microsoft Edge\\Sleeping Tabs settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","displayName":"Signature Status dialog box","description":"Microsoft Outlook 2016\\Security\\Cryptography\\Signature Status dialog box","helpText":null,"parentCategoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"af14a55b-d79b-4299-946c-b7582412b748","displayName":"Tools | Options | General | Service Options...","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","5838ed03-2902-4931-92cf-e349ab09c9b8","6c142a01-47fa-422d-8135-29e81bc970cc"],"platforms":"windows10","technologies":"mdm"},{"id":"af351b0c-3d9e-4b18-957b-8179e4eaba15","displayName":"Safe Browsing settings","description":"Google Google Chrome - Default Settings users can override Safe Browsing settings","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"af9b2941-29f9-4ee5-ae09-215f4e242943","displayName":"AutoCorrect Options","description":"Microsoft Visio 2016\\Visio Options\\Proofing\\AutoCorrect Options","helpText":null,"parentCategoryId":"8495c82c-f273-4bcc-8886-6751103a9c7b","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","displayName":"Microsoft One Note 2016","description":"Microsoft One Note 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":["b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","a185940c-7899-4ab6-867d-7559352cf8d2"],"platforms":"windows10","technologies":"mdm"},{"id":"b03bfdc7-f42a-400e-935b-2b07fc71a7f1","displayName":"Mime Sniffing Safety Feature","description":"Administrative Templates Internet Explorer Security Features Mime Sniffing Safety Feature","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","displayName":"Custom","description":"Microsoft One Note 2016 Disable Items in User Interface Custom","helpText":null,"parentCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b1393de2-587f-4516-a35d-58098f2be3c9","displayName":"WLAN Media Cost","description":"Administrative Templates\\Network\\WLAN Service\\WLAN Media Cost","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b13e38a0-6ad6-4a1f-b53f-d8ca94847586","displayName":"SNMP","description":"Administrative Templates\\Network\\SNMP","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b1585568-da15-41fc-a1d0-5d0b194de84c","displayName":"Locked-Down Internet Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Locked-Down Internet Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b161cf66-abfa-4a36-a9ac-c20ca60594e0","displayName":"Exchange ActiveSync","description":"Microsoft Outlook 2016\\Account Settings\\Exchange ActiveSync","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b206e4ef-a288-4fb7-a7ee-4a30b4df3b98","displayName":"Server Settings","description":"Microsoft Word 2016\\Miscellaneous\\Server Settings","helpText":null,"parentCategoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b221d3c2-e05a-4210-bf9c-2d7c7c0fd35a","displayName":"SSL Configuration Settings","description":"Administrative Templates\\Network\\SSL Configuration Settings","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b237a91d-a442-4a7e-8169-1bd6c798f490","displayName":"Profiles","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Profiles","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b260992a-8216-4bfa-b60a-4eeea1f356c9","displayName":"News and interests","description":"Feeds","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b260992a-8216-4bfa-b60a-4eeea1f356c9","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b2b85670-5475-4148-ab3d-c4c86b4d5af0","displayName":"PKCS imported certificate","description":"PKCS imported certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b2b85670-5475-4148-ab3d-c4c86b4d5af0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b32726b3-b0e9-465b-86f8-b61ad8af52f0","displayName":"Default Applications","description":"Managed Settings Default Applications","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"b3282777-8e27-4029-b153-6f6e5b86b53c","displayName":"HomeGroup","description":"Administrative Templates\\Windows Components\\HomeGroup","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b382d980-7459-4850-a45e-75dd99488972","displayName":"Software Update Settings","description":"Declarative Device Management preview Software Update Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"b3b2fc04-4b88-4a1c-8370-04573019eebe","displayName":"LAPS","description":"Administrative Templates\\LAPS","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b3b30966-47ac-4b54-a75a-04418d5c6153","displayName":"Dev Tunnel Settings","description":"Visual Studio Dev Tunnel Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","displayName":"PDF Reader","description":"Microsoft Edge PDF Reader","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"b3e317cd-c580-478e-885c-666ce3079e78","displayName":"Outlook Social Connector","description":"Microsoft Outlook 2016\\Outlook Social Connector","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b40b8f80-c0e6-4494-8085-f90cadc167a9","displayName":"Temporary folders","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Temporary folders","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b40cfb22-8f17-4317-bcbb-c1c871497446","displayName":"Location and Sensors","description":"Administrative Templates Location and Sensors","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b4272e06-316f-4f9a-a198-93f4168f0c78","displayName":"Corrupted File Recovery","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Corrupted File Recovery","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b46f4e70-d3d1-4177-8e22-62f806d4568c","displayName":"Other","description":"Google Google Chrome Other","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b473c6fa-a971-4e5d-ad15-2c27c17c5d3e","displayName":"Power BI","description":"Microsoft Excel 2016\\Power BI","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b485695b-0fae-41ae-861c-3030769b28df","displayName":"Safe Browsing settings","description":"Google Google Chrome Safe Browsing settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","displayName":"Security Features","description":"Administrative Templates Internet Explorer Security Features","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","e6911a08-946f-4b70-99cb-2a8b92c461e0","622c83ff-f780-47e6-8b9c-bf82552e3f04","853d5a82-91e4-4c53-8338-fd1a3d9b542c","3bbaff1b-7d59-4b9c-ab53-c235d72b2fb0","b03bfdc7-f42a-400e-935b-2b07fc71a7f1","4560c525-12a1-4536-9cca-338330e58389","17bc9899-d157-4eac-a949-810b4a841e28","18296501-4825-47ea-835d-66a01aba9384"],"platforms":"windows10","technologies":"mdm"},{"id":"b49cb414-bdfb-49d4-af5d-176ded4f9591","displayName":"User Profiles","description":"Administrative Templates\\System\\User Profiles","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b5006d56-dc0b-4a07-95ee-d6d6e3000f9f","displayName":"Time Providers","description":"Administrative Templates\\System\\Windows Time Service\\Time Providers","helpText":null,"parentCategoryId":"bd04d2ce-3275-496c-8cc1-e17ab19888a3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b5169b74-41be-460a-9402-b13b6c22582b","displayName":"Microsoft Office","description":"Microsoft Office > Microsoft Office","helpText":null,"parentCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"b5234c18-e555-409e-9550-59b89d1672f1","displayName":"Window Frame Coloring","description":"Administrative Templates\\Windows Components\\Desktop Window Manager\\Window Frame Coloring","helpText":null,"parentCategoryId":"be6b97de-f120-4d89-b7c9-b548d061bac8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b524d6e2-75bc-4409-ae3d-07605707d7ee","displayName":"Pen UX Behaviors","description":"Administrative Templates Pen UX Behaviors","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","displayName":"Windows Power Shell","description":"Administrative Templates Windows Power Shell","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b62de64d-03ed-4e09-be5c-5cc93e34ea47","displayName":"iSCSI Security","description":"Administrative Templates\\System\\iSCSI\\iSCSI Security","helpText":null,"parentCategoryId":"363982dd-fc96-49ce-a499-f6401f2c212b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b6650a16-32bc-4344-ac98-8f20486c6b0b","displayName":"Cellular Private Network","description":"Cellular Private Network","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"b6733d23-eadc-486a-abfc-62b78698a16c","displayName":"General","description":"Device Restriction General","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise,aosp","technologies":"android"},{"id":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","displayName":"Managed Menu Extras","description":"User Experience > Managed Menu Extras","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"b6bb653a-73f0-42f4-b097-1ce556310904","displayName":"Scripted Diagnostics","description":"Administrative Templates Scripted Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b6cafb2c-81be-40cf-90d8-788f713f7099","displayName":"Replace as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type\\Replace as you type","helpText":null,"parentCategoryId":"4dae3032-1f16-4ace-911b-a957db0b8089","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","displayName":"App Package Deployment","description":"Administrative Templates App Package Deployment","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b74f852c-d19b-4a22-a44a-431f7a72a4d6","displayName":"Scripted Window Security Restrictions","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Scripted Window Security Restrictions","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","displayName":"Endpoint Detection and Response (EDR) preferences","description":"Microsoft Defender > Endpoint Detection and Response (EDR) preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"b792508d-da03-4174-bcf1-666d128ee8ad","displayName":"AutoFormat as you type","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Proofing\\AutoFormat as you type","helpText":null,"parentCategoryId":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b7bde490-eac6-4f57-8808-e0786b8191a1","displayName":"Remote FX for Windows Server 2008 R2","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Remote Session Environment Remote FX for Windows Server 2008 R2","helpText":null,"parentCategoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","displayName":"Web Rtc settings","description":"Google Google Chrome Web Rtc settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b8158968-c839-4d37-9eb8-887bd6fd7402","displayName":"Disable Items in User Interface","description":"Microsoft Access 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["dba1a547-e288-45ac-8553-27a3b564699e","55eebd7c-beb9-48b6-907f-df4997e18bdb"],"platforms":"windows10","technologies":"mdm"},{"id":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","displayName":"Win RM Service","description":"Administrative Templates Windows Remote Management Win RM Win RM Service","helpText":null,"parentCategoryId":"364787de-93e4-4fd6-9608-dce1ad8f88c2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b85d9c04-4923-4fdf-a425-424686d47859","displayName":"Siri Settings","description":"Declarative Device Management preview Siri Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"b8adcde1-500a-430f-8636-f97eaae2a2c6","displayName":"Japanese Find","description":"Microsoft Word 2016\\Japanese Find","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","displayName":"Network Proxy Configuration","description":"Proxies > Network Proxy Configuration","helpText":null,"parentCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","rootCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"b90fb0dc-b8c1-4fc3-b9f9-dfbda4b3f03d","displayName":"General","description":"Microsoft Excel 2016\\Excel Options\\Advanced\\Web Options...\\General","helpText":null,"parentCategoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b9201072-3681-4e95-ad90-869e6166b129","displayName":"Client Coexistence","description":"Administrative Templates App-V Client Coexistence","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b92241c7-e419-4dc7-b373-08e595c1db1d","displayName":"Operating system","description":"Operating system","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b92241c7-e419-4dc7-b373-08e595c1db1d","childCategoryIds":[],"platforms":"windows10","technologies":"windowsOsRecovery"},{"id":"b94cbc54-e565-44f2-a27a-a63b2514d8bf","displayName":"DLP","description":"Microsoft Office 2016\\DLP","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b96b63eb-0292-4a73-85d7-c68d330c109e","displayName":"Extensions","description":"Microsoft Edge - Default Settings (users can override)\\ Extensions","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b9aafd85-b42a-4742-bbba-770b93678a52","displayName":"Locked-Down Trusted Sites Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Locked-Down Trusted Sites Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b9ab4d39-9e28-4897-aa34-0201a35ea989","displayName":"Right-to-left","description":"Microsoft Outlook 2016\\Outlook Options\\Right-to-left","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ba1d333c-e19b-4470-bbab-d040a633c3a3","displayName":"IME","description":"Administrative Templates\\Windows Components\\IME","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ba7097b2-cd24-4394-9b3e-2c281ed30ae5","displayName":"Windows Media Digital Rights Management","description":"Administrative Templates\\Windows Components\\Windows Media Digital Rights Management","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ba7686de-e6ee-4af9-b1a5-265b03e08367","displayName":"Microsoft PowerPoint 2016","description":"Microsoft PowerPoint 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["ceacf7fa-fa6e-434d-a381-e20e5245d180","da92dfd6-a29e-42a0-92ed-276bb6904455","28ab8eed-623a-4e9b-813e-13256472dbaf","e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","f5babdb3-c718-4675-b977-6c7bc7e6f886","da1503cb-e474-4545-8e77-cdd577f34a08"],"platforms":"windows10","technologies":"mdm"},{"id":"bb54b081-5004-4f05-a46c-f5b948f57b82","displayName":"NTFS","description":"Administrative Templates Filesystem NTFS","helpText":null,"parentCategoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","displayName":"System Configuration","description":"System Configuration","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":["768d9aa4-7407-4ed9-b97f-2385b8cadb47","8cefd936-362e-4a24-bc76-e078b6fd13fa","cb33668b-933f-4424-8d2d-8bdf0e61bddd","0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","5401711f-292a-487a-be18-f99593a0477c","dec8381a-0a61-406b-842b-fc6ae9930795","853f4181-42e8-411c-91cf-c06968c0a543","8c75a12d-664d-43ba-a3aa-5259425f9b37"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"bbe51018-a17d-46c4-9517-ff45c54d8d18","displayName":"DNS Settings","description":"Networking > DNS Settings","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"bc4f0cce-a5cc-44c9-9e50-b504e09e7eb1","displayName":"KDC","description":"Administrative Templates\\System\\KDC","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bc58391f-664c-42dd-9d18-269e65f324a7","displayName":"Miscellaneous","description":"Microsoft Excel 2016\\Miscellaneous","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["183628a3-d0a5-47de-b444-e132d634ca38"],"platforms":"windows10","technologies":"mdm"},{"id":"bc633a5a-c712-49a6-9f56-775ca9321df4","displayName":"Downloading Framework Components","description":"Microsoft Office 2016\\Downloading Framework Components","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bc65521d-e48a-4e95-899f-49df827808ca","displayName":"File Locations","description":"Microsoft Word 2016\\Word Options\\Advanced\\File Locations","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bce24fbf-4caf-449f-a210-5dd31a368b22","displayName":"Removed policies","description":"Google Google Chrome - Default Settings users can override Removed policies","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd04d2ce-3275-496c-8cc1-e17ab19888a3","displayName":"Windows Time Service","description":"Administrative Templates\\System\\Windows Time Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["b5006d56-dc0b-4a07-95ee-d6d6e3000f9f"],"platforms":"windows10","technologies":"mdm"},{"id":"bd1bf2cb-c806-479b-a68c-af9dffd438c9","displayName":"Security","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Security","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd1dad69-5cbe-415e-8565-e87b15cd4431","displayName":"General","description":"Microsoft Access 2016\\Application Settings\\General","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd5533e1-f1ee-4994-8a79-cffe02b12d5c","displayName":"FileVault Recovery Key Escrow","description":"FileVault > FileVault Recovery Key Escrow","helpText":null,"parentCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","displayName":"Compatibility View","description":"Administrative Templates Internet Explorer Compatibility View","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","displayName":"General","description":"Microsoft Word 2016\\Word Options\\General","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd7d2b68-118d-40ee-9dfd-39b2a22a2082","displayName":"Windows Connect Now","description":"Administrative Templates\\Network\\Windows Connect Now","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd8dacbf-ab7b-4a93-8294-7db61b9d49b4","displayName":"DNS Client","description":"Administrative Templates\\Network\\DNS Client","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bdc32a5e-2bce-46b1-9838-ed557b1e287e","displayName":"Cryptography","description":"Cryptography","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"bdc32a5e-2bce-46b1-9838-ed557b1e287e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"be6b97de-f120-4d89-b7c9-b548d061bac8","displayName":"Desktop Window Manager","description":"Administrative Templates\\Windows Components\\Desktop Window Manager","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["b5234c18-e555-409e-9550-59b89d1672f1"],"platforms":"windows10","technologies":"mdm"},{"id":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","displayName":"Windows Time Service","description":"Administrative Templates Windows Time Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["13f025df-7d3f-4ecd-bd38-d7af7853b66e"],"platforms":"windows10","technologies":"mdm"},{"id":"be9bdbec-b52e-4174-9c5b-cf765dee855b","displayName":"Store","description":"Administrative Templates Store","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","displayName":"Editing Options","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Editing Options","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bedf20d1-1f5a-4840-8458-6d0fa974b664","displayName":"Net Logon","description":"Administrative Templates\\System\\Net Logon","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["7f4d325e-bff8-4d91-8313-614243e55e6d"],"platforms":"windows10","technologies":"mdm"},{"id":"bf8e3e9c-f7e7-4a43-8898-2caf7b01d987","displayName":"System Security","description":"Device Restriction System Security","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"c00d6468-cac3-429c-ada5-ba3adf4982a8","displayName":"Accessibility","description":"User Experience > Accessibility","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","displayName":"ActiveX Installer Service","description":"Administrative Templates ActiveX Installer Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c0204a51-a73c-46a6-8626-deeadcabe6ac","displayName":"Licensing","description":"Licensing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c0204a51-a73c-46a6-8626-deeadcabe6ac","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c02141e6-0725-4f6f-9138-83d10c6bc104","displayName":"Backup","description":"Microsoft OneNote 2016\\OneNote Options\\Backup","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c08e929f-742a-4cd8-a7e6-9a3d170fe020","displayName":"Disk Quotas","description":"Administrative Templates\\System\\Disk Quotas","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","displayName":"Windows Apps","description":"Administrative Templates Microsoft User Experience Virtualization Windows Apps","helpText":null,"parentCategoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c14c2e8b-0081-46e0-89ac-48ade3b83408","displayName":"Remote Desktop","description":"Remote Desktop","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c14c2e8b-0081-46e0-89ac-48ade3b83408","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c20ba4a5-483d-417c-bd96-de3cd83303e1","displayName":"Maintenance Scheduler","description":"Administrative Templates\\Windows Components\\Maintenance Scheduler","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c26b2f10-f2c0-45f2-955c-5379dd12f206","displayName":"Compatibility View","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Compatibility View","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3857f91-3df8-472f-9b5a-b10778c715c0","displayName":"Google Chrome - Default Settings users can override","description":"Google Google Chrome - Default Settings users can override","helpText":null,"parentCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":["20ceae56-e189-46ec-a440-791ce7454017","54f2e032-bdcc-4877-b7a0-973d0a7c1653","d97d6d8f-0a1a-4160-89aa-d624a36954a2","af351b0c-3d9e-4b18-957b-8179e4eaba15","12142994-4b30-486c-bab1-9206528b2b96","de643352-007f-4a47-8c83-d75a79516b39","962a2377-ad9a-4654-a526-a77c14152fd7","bce24fbf-4caf-449f-a210-5dd31a368b22","6d6b289c-c1e9-4004-b5ab-3123920cf10d"],"platforms":"windows10","technologies":"mdm"},{"id":"c3ab8d44-b353-4a8a-a526-ffd743fb7ff8","displayName":"Miscellaneous","description":"Microsoft Access 2016\\Miscellaneous","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3b5e77d-c00d-4578-84c9-289362ad0b00","displayName":"Save","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Save","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3db5686-3bb2-437c-8906-60da1a1fa844","displayName":"Trust Center","description":"Microsoft Outlook 2016\\Security\\Trust Center","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3dfb294-a7c0-48af-b705-59c4e257d48c","displayName":"Declarative Device Management (DDM)","description":"Declarative Device Management (DDM)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":["15be55d8-7477-4274-9b09-b775bce68416","11d26400-1d13-4dd6-ab4b-cb323494b127","42a6198f-bdec-402e-b619-315400b65488","83febe72-a64f-4051-9071-1efae1ea9a15","a42e2248-d2dc-4476-a92d-d152fd67e04b","b85d9c04-4923-4fdf-a425-424686d47859","b382d980-7459-4850-a45e-75dd99488972","6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","8c86f511-1729-4fe9-b0b2-111d9044e1ba","d9654cb3-57c8-487c-90a5-454e15336731","7d9e5b9b-84e7-473c-b6ca-a1629448df55","e0ab6868-4b53-4310-b665-f7c979941db7","dba26132-cba6-4178-93c3-f02476532f08","ddb64e9d-34b9-44f4-9980-a6623f14e445","2cdd4a96-23c1-4419-b88c-41bbaa119e68"],"platforms":"iOS,macOS,visionOS,tvOS","technologies":"mdm,appleRemoteManagement"},{"id":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","displayName":"Identification (Deprecated)","description":"Authentication > Identification","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"c400a917-cdff-4e15-a70f-59b82df4c038","displayName":"Attachment Security","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Attachment Security","helpText":null,"parentCategoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c4665793-15ea-44c9-bd0a-d542b3915fe0","displayName":"Remediation","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Remediation","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c483faac-cebf-448a-8f90-e8a125c0c4af","displayName":"Microsoft Management Console","description":"Administrative Templates\\Windows Components\\Microsoft Management Console","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["9e882396-4a1c-4d06-a62d-8d910ded8e7d"],"platforms":"windows10","technologies":"mdm"},{"id":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","displayName":"Remote Desktop Services","description":"Administrative Templates Remote Desktop Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["0456dcd5-c003-4a8b-80e6-61bacf854330","4c604a0e-9339-4c01-9536-b689bd0abe5f","62bbe0df-b9b2-453f-a2f1-ee66291d4956","3a901a80-e2b6-470c-9658-d66ba5458370","a561e59a-09b7-4106-a6fa-0b82036a5b49"],"platforms":"windows10","technologies":"mdm"},{"id":"c492dd55-8876-4b1b-b620-615cc9b65ef8","displayName":"Versions and Recyle Bin","description":"Microsoft OneNote 2016\\OneNote Options\\Versions and Recyle Bin","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c4ce54b8-e555-4447-9791-dd8e9dbb86b0","displayName":"Tenant Lockdown","description":"Tenant Lockdown","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c4ce54b8-e555-4447-9791-dd8e9dbb86b0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","displayName":"Exchange","description":"Microsoft Outlook 2016\\Account Settings\\Exchange","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["82ecfab7-b76a-4cec-8e76-859db4599ac2","e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5"],"platforms":"windows10","technologies":"mdm"},{"id":"c4e48b1b-6d88-434f-a717-d5bab28eb245","displayName":"Wi-Fi Connection","description":"Wi-Fi Connection","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c4e48b1b-6d88-434f-a717-d5bab28eb245","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c6099521-a05f-480a-8562-7e71318e2cda","displayName":"Printing","description":"Microsoft Edge\\Printing","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"c64ee570-d51c-4286-9a47-367b833754e4","displayName":"Store","description":"Administrative Templates\\Windows Components\\Store","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c67c9e69-6e69-4b63-868c-3b3df5d17e47","displayName":"Disable Items in User Interface","description":"Microsoft Visio 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","4e4deef0-4528-47d5-8869-4143c506f18b"],"platforms":"windows10","technologies":"mdm"},{"id":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","displayName":"Removable Storage Access","description":"Administrative Templates Removable Storage Access","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"c6b72060-8ecb-41d8-8625-2984dd756d4a","displayName":"Free/Busy Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Free/Busy Options","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c6c1120b-988c-4581-a21c-b9786a821242","displayName":"Miscellaneous","description":"Microsoft Publisher 2016\\Miscellaneous","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c72d9f00-d625-43ec-add4-514891035839","displayName":"Web Service","description":"Microsoft Office 2016\\Business Data\\Web Service","helpText":null,"parentCategoryId":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","displayName":"Publisher Options","description":"Microsoft Publisher 2016\\Publisher Options","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["51e0cebb-cac4-4905-9b31-539295e4b85b","1a0386fd-354b-441e-a0d6-1523c209dae7","6d1e32eb-61f7-4907-b9fe-b83fda8ad67d","69f3ad9d-871d-42b3-8e10-07dc076a4d32","038b49c9-4f13-4ace-be8d-bd076bffa23e"],"platforms":"windows10","technologies":"mdm"},{"id":"c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","displayName":"System Preferences","description":"Preferences > System Preferences","helpText":null,"parentCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"c7c32942-a139-4d7e-a19e-3495d5e372e7","displayName":"Networking","description":"Administrative Templates\\Windows Components\\Windows Media Player\\Networking","helpText":null,"parentCategoryId":"22ebd92b-80b6-493d-99d8-3c72f1a0827e","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c805d788-1950-4ed1-adfb-771f12564a0c","displayName":"Exclusions","description":"Administrative Templates Microsoft Defender Antivirus Exclusions","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c859dc1a-fdeb-4591-af97-79d078ee715b","displayName":"Event Forwarding","description":"Administrative Templates Event Forwarding","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c87ae066-cc1a-44c9-8645-1db2359f7484","displayName":"Layer-2 priority value","description":"Administrative Templates Qo S Packet Scheduler Layer-2 priority value","helpText":null,"parentCategoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","displayName":"File Block Settings","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c919e047-97fc-489f-ab0e-bcb070e36c55","displayName":"WinRM Client","description":"Administrative Templates\\Windows Components\\Windows Remote Management (WinRM)\\WinRM Client","helpText":null,"parentCategoryId":"a37dba52-d558-47fb-9d46-a5d3bdc5fdd7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c945edd8-c865-4932-806d-83752e3f46ad","displayName":"Microsoft Edge Web View2","description":"Microsoft Edge Web View2","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c945edd8-c865-4932-806d-83752e3f46ad","childCategoryIds":["13cc3b63-a150-4cf2-8d76-309975603c8e"],"platforms":"windows10","technologies":"mdm"},{"id":"c95a5920-ad56-4668-a6ad-19c3eb428557","displayName":"Lanman Workstation","description":"Administrative Templates\\Network\\Lanman Workstation","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","displayName":"Auto Play Policies","description":"Administrative Templates Auto Play Policies","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c9a65baa-de10-4818-97a2-b61babb28060","displayName":"Microsoft Defender Antivirus","description":"Administrative Templates Microsoft Defender Antivirus","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","428f107c-2167-4bc2-9293-8f1d6728a0c5","adc4eb7f-0f34-4f43-b361-dc42363eccab","cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","2c43699e-90b5-4da6-9689-fe5ad3b25ac9","94b5c25e-3af3-4c08-b738-a0527f91dc22","8a03aebc-9249-4917-a1c3-2957717d9123","c805d788-1950-4ed1-adfb-771f12564a0c","a5a56a36-6d60-4f74-a3c6-d82ed979b24a","a5060182-4d22-412b-bd0e-3a1e009b36c6","ad84cea3-5664-4e42-a9d6-1446828bea45","a004deb8-6f52-4411-8d94-41563a8203fc","09c02465-dc11-457e-9eac-19fc542e4cda"],"platforms":"windows10","technologies":"mdm"},{"id":"c9ab1080-67a7-4d6c-8213-056d4eb08ea0","displayName":"Credential Providers","description":"Credential Providers","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c9ab1080-67a7-4d6c-8213-056d4eb08ea0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c9ce70f5-a64b-442f-ac96-992eedf6a5df","displayName":"Device and Driver Compatibility","description":"Administrative Templates\\Windows Components\\Device and Driver Compatibility","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ca1aedf4-b951-45f5-a77c-dec776a82e21","displayName":"General i SCSI","description":"Administrative Templatesi SCSI General i SCSI","helpText":null,"parentCategoryId":"3f693856-7cbb-4a1c-93be-0d05aa41059f","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","displayName":"Full Disk Encryption","description":"Full Disk Encryption","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":["5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","3f56adc1-2207-4033-a6e2-07f64c08e3ff","bd5533e1-f1ee-4994-8a79-cffe02b12d5c"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cae68a5f-9d1e-44e8-a34b-6a390b88c451","displayName":"Credentials Delegation","description":"Administrative Templates\\System\\Credentials Delegation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cb1e177e-8f06-4a69-8215-ec1e91c19e30","displayName":"Notifications","description":"Notifications","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"cb1e177e-8f06-4a69-8215-ec1e91c19e30","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","displayName":"System Extensions","description":"System Configuration > System Extensions","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"cb6472c8-3e22-4029-af98-8a97f03a5a44","displayName":"PST Settings","description":"Microsoft Outlook 2016\\Miscellaneous\\PST Settings","helpText":null,"parentCategoryId":"f5a1a387-6665-4527-b532-88a64a76e732","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cb8e8500-0336-4277-b3d9-9177cc967dcf","displayName":"Text Input","description":"Text Input","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cb98f9d4-d921-4a8b-a763-cf69ce2ada62","displayName":"Notifications","description":"Administrative Templates\\Start Menu and Taskbar\\Notifications","helpText":null,"parentCategoryId":"5161db41-7947-49ea-b9b3-dd92539e6783","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cbb98485-6a36-47b8-b450-7821e08507ac","displayName":"Web Options - General","description":"Microsoft Access 2016\\Application Settings\\Web Options...\\General","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","displayName":"Network Inspection System","description":"Administrative Templates Microsoft Defender Antivirus Network Inspection System","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cc13d92c-673f-4af7-9748-50342fc8795a","displayName":"Filesystem","description":"Administrative Templates Filesystem","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["bb54b081-5004-4f05-a46c-f5b948f57b82"],"platforms":"windows10","technologies":"mdm"},{"id":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","displayName":"Collaboration Settings","description":"Microsoft Office 2016\\Collaboration Settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","1b97e23d-996f-4b8e-9abf-53cfa0fc8917","2806d29a-7c7a-4ff0-baa2-4a0044425ea6"],"platforms":"windows10","technologies":"mdm"},{"id":"cc388035-b49c-493e-a598-14b0d0de4359","displayName":"Dock","description":"User Experience > Dock","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cc50f179-0c39-4486-a555-de5a6e6ed365","displayName":"Trust Center","description":"Microsoft Project 2016\\Project Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"623d41fb-000e-41d8-b955-373f8c700def","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cc8a93d5-503f-4d46-ac42-65e169642237","displayName":"Cursors","description":"Administrative Templates\\Windows Components\\Tablet PC\\Cursors","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cc9231e6-ed1b-4680-aff4-bc72f16733c0","displayName":"Temporary folders","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Temporary folders","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","displayName":"Offline Files","description":"Administrative Templates Offline Files","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","displayName":"Mobile Accounts","description":"Accounts > Mobile Accounts","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cd16477e-7cff-4c24-ba7a-cc4342779f4b","displayName":"Trusted Sites Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Trusted Sites Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","displayName":"Security","description":"Microsoft Excel 2016\\Excel Options\\Security","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["7490c4fd-c326-42f7-9908-006504616d4c","27ccaa0b-8755-4116-a0e3-b5d21d68ab65"],"platforms":"windows10","technologies":"mdm"},{"id":"cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","displayName":"WWAN Service","description":"Administrative Templates WWAN Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["eefc9ae4-b9ae-4d77-8b68-359b9e5ec6f7","edf3754c-b22d-4946-a744-4773240a5883"],"platforms":"windows10","technologies":"mdm"},{"id":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","displayName":"Desktop App Installer","description":"Administrative Templates Desktop App Installer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ce0b1189-57ea-4444-a93e-e4be17160f18","displayName":"Windows Installer","description":"Administrative Templates\\Windows Components\\Windows Installer","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","displayName":"Uncategorized","description":"Microsoft Edge\\ Uncategorized","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"android,iOS,macOS,windows10","technologies":"mobileApplicationManagement"},{"id":"ce572b49-4d47-47b6-b787-ac1252753581","displayName":"Remote Session Environment","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Remote Session Environment","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["a33fb618-0ad1-40a3-b94b-49c90c49ea03"],"platforms":"windows10","technologies":"mdm"},{"id":"ceacf7fa-fa6e-434d-a381-e20e5245d180","displayName":"Co-authoring","description":"Microsoft PowerPoint 2016\\Collaboration Settings\\Co-authoring","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cebd5934-9dfe-4278-966d-b9d880cb30e7","displayName":"Windows Shutdown Performance Diagnostics","description":"Administrative Templates Windows Shutdown Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","displayName":"Windows Components","description":"Administrative Templates\\Windows Components","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["1fa3b0c3-e453-4ef3-80aa-a7474d8eb354","49d75a11-64c6-43d1-bc25-0ab156ff4216","78906e32-f4fb-453b-939b-05717ffaae59","9e857bed-81f8-4dfc-b049-c93eb68b4064","a37dba52-d558-47fb-9d46-a5d3bdc5fdd7","be6b97de-f120-4d89-b7c9-b548d061bac8","c483faac-cebf-448a-8f90-e8a125c0c4af","4479c9b6-8e08-424f-a20a-2058126dc048","5d19c257-8b7e-4071-9303-19317c94d7f7","ab754829-54a1-4082-abfa-56bae0b07ff3","b3282777-8e27-4029-b153-6f6e5b86b53c","fd16aa29-dae5-49b5-910e-88f3078ce2da","1638d9ec-63d5-4d6b-b1b6-4b0402268e36","176ed477-020a-41af-8859-0605c2caad98","35525ba9-da99-460e-afd3-ba86506b0ba3","60a3188c-7ee3-40db-8f9f-33648dc74555","70063d93-03f0-462e-9943-b0241b88d54d","d11e32cf-ac55-401a-a81a-232adc304afc","572bc940-42d4-4e00-ac55-012e9b90f6df","5a92aaed-3c64-4074-bacf-91dc1896d6f1","67b48a23-9bc3-48f5-bf6e-c9b3cd7000e4","a1d83497-da94-407f-bbc5-9f65ebc5f9fb","c20ba4a5-483d-417c-bd96-de3cd83303e1","ce0b1189-57ea-4444-a93e-e4be17160f18","f60cd3c8-a91b-4542-b09f-129dfc7e589c","1219a9c2-dccb-445f-9f90-8e86e2de22d6","1ed81d90-7326-4d0b-8934-b0a8bdddc5ce","69ec00d9-5698-4b8b-ad54-8d9a537a0fa9","71f9795f-defc-4b03-a2b4-31e129b6f861","7444c3f0-214b-45ea-9b8e-f74b81543644","7574a907-5608-491f-8011-c57d487457f4","a2230bb9-81a5-4e95-bc7f-0fbc9ecb5de4","a53581a1-e9d7-4ba4-9dea-cea90d40cca1","c64ee570-d51c-4286-9a47-367b833754e4","c9ce70f5-a64b-442f-ac96-992eedf6a5df","e9aff162-feb0-400a-aa68-8dd8deb93275","0101d1d0-1e54-47b0-a749-62c6bd7ab3da","0cc63077-26e9-4fbd-a343-fd88102efd7e","22ebd92b-80b6-493d-99d8-3c72f1a0827e","5915e06c-9b74-4c5e-86de-93e67ae183de","865a5fd9-f9be-496d-acb4-cd7cdb03e19f","8ccb6340-4f25-4bda-a527-127d269b3cbf","ba1d333c-e19b-4470-bbab-d040a633c3a3","d4bdfec1-2e40-49d2-b8f2-e5b15f072b10","7f431009-e8fe-460e-b247-06c838c8a914","2e57e23c-4847-4864-8e8e-5f6add1f7a84","3f8299b3-6803-4576-be08-7c311d04b8b9","50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","d9b7efad-fe18-4c98-925b-c4a5db0f2815","2dc7de59-a2b5-4f4a-96a4-597927af0617","4fc4d2f3-35ee-43ec-a033-ef78da571e70","569c6b8d-9491-471b-9960-17e3ac60734a","a57f0abc-605b-433e-b7da-45ee127188cd","ba7097b2-cd24-4394-9b3e-2c281ed30ae5","3181c361-f4f0-44ff-82cc-24aac8075843","fcddcc0b-7cf8-4ebc-a818-d10689603263","ffb6de77-8f2d-4b45-9cd4-00bb75cd496c"],"platforms":"windows10","technologies":"mdm"},{"id":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","displayName":"Networking","description":"Networking","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":["e95335ec-2704-47ab-8b40-f602b31eeb9d","06a85f5b-2614-4467-91cf-4a64d0c9326f","70b5da13-9c31-4857-890d-b7eb223729c3","5c722b3f-9d77-428a-b859-3fb556162cd6","bbe51018-a17d-46c4-9517-ff45c54d8d18","224dc683-c0e0-4783-8ba8-8f02c76d161d"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cf968979-f316-47cb-a207-bf9ef28cd1aa","displayName":"DSCP value of non-conforming packets","description":"Administrative Templates Qo S Packet Scheduler DSCP value of non-conforming packets","helpText":null,"parentCategoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","displayName":"Google","description":"Google","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":["36c83fb3-c18c-472b-b39e-617c2f8a7fbd","c3857f91-3df8-472f-9b5a-b10778c715c0"],"platforms":"windows10","technologies":"mdm"},{"id":"d0a1763a-5cdf-4672-8596-435ec1d94b54","displayName":"Search Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Search Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","displayName":"Application Settings","description":"Microsoft Access 2016\\Application Settings","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["23fd467e-24f8-4200-8b19-c6c11afa8926","bd1dad69-5cbe-415e-8565-e87b15cd4431","33b9194b-4027-4c23-b662-52f25db7f839","cbb98485-6a36-47b8-b450-7821e08507ac"],"platforms":"windows10","technologies":"mdm"},{"id":"d0e46713-238c-42b7-a996-653cf952c367","displayName":"Home Group","description":"Administrative Templates Home Group","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d0ff97aa-cf53-460e-be82-2c521a56eec6","displayName":"Outlook Options","description":"Microsoft Outlook 2016\\Outlook Options","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["114356a4-dfc9-44e9-9a62-f1d601d48445","d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","93a20c17-1e34-4778-8c95-91a46980ea75","f2bf77fd-37df-448b-8959-6478abf96f6f","fa6bfb01-34f6-4c54-89b9-f7e717e6d394","5e3f61b6-52b7-4c74-a101-33c1cf34a749","fcc8ad48-a1e7-4cba-adae-7c916cbbc897","b9ab4d39-9e28-4897-aa34-0201a35ea989","e87c8824-e7c4-4fca-a3c1-0376d45d7f9f"],"platforms":"windows10","technologies":"mdm"},{"id":"d11e32cf-ac55-401a-a81a-232adc304afc","displayName":"Event Forwarding","description":"Administrative Templates\\Windows Components\\Event Forwarding","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","displayName":"HTTP authentication","description":"Microsoft Edge\\HTTP authentication","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d1e2bb0d-6c0e-4f40-9f2e-52055edc14b5","displayName":"Customize Ribbon","description":"Microsoft Excel 2016\\Excel Options\\Customize Ribbon","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d2191717-e304-46f7-bcc0-55e6477026c9","displayName":"Exclusion Settings","description":"Microsoft Defender Exclusion Settings","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","displayName":"Schedule View","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Schedule View","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","displayName":"Security Page","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page","helpText":null,"parentCategoryId":"586c5c5a-15cd-4592-beae-1709c6daf5b7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["ecfb5fea-26cc-494b-9e5e-88b5e51a5be0","40605d4b-d999-4235-9a5a-59fad165ec51","1aef6e33-cb5c-4ad5-b433-c198750bbc98","b1585568-da15-41fc-a1d0-5d0b194de84c","b9aafd85-b42a-4742-bbba-770b93678a52","cd16477e-7cff-4c24-ba7a-cc4342779f4b","76f2d08c-0a3f-4f4e-ad04-51aa16aea0bf","80f5fb2f-e74a-4533-81aa-a92163f49e16","a4bffc2b-76af-48d3-acdf-8566e51ef163","9bad0513-ac85-431c-86d9-9e3167f9b403"],"platforms":"windows10","technologies":"mdm"},{"id":"d2f1d28a-682d-49e9-bb71-0782e4a06c1b","displayName":"Task Manager","description":"Task Manager","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d2f1d28a-682d-49e9-bb71-0782e4a06c1b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d33133b4-77df-429a-9580-ed70f7da676d","displayName":"Edit options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\Edit\\Edit options for Microsoft Project","helpText":null,"parentCategoryId":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d39f73b0-9d26-4d4c-a8b0-d1b720890d2e","displayName":"MK Protocol Security Restriction","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\MK Protocol Security Restriction","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d40a32e1-ab3e-4cbc-aa03-4766792e563e","displayName":"Performance Profiles Configuration","description":"Microsoft Defender Performance Profiles Configuration","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"d4943981-47b2-4a86-848b-860e8ca47381","displayName":"Microsoft Edge Update","description":"Microsoft Edge Update","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":["2c7e8e8e-47fe-48ba-8cb4-55ce296edced","46eaa2b7-341b-4e39-be21-c3ea09dd5778","43fc9dcc-1e66-4108-bded-2d005eeb7ccb","78497707-c3e4-400b-a6bc-1813c3689fdc","ff543267-540e-4e37-a1e9-daf6a5e16ba7"],"platforms":"windows10","technologies":"mdm"},{"id":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","displayName":"Privacy Sandbox policies","description":"Google Google Chrome Privacy Sandbox policies","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4bdfec1-2e40-49d2-b8f2-e5b15f072b10","displayName":"Event Viewer","description":"Administrative Templates\\Windows Components\\Event Viewer","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","displayName":"Delete Browsing History","description":"Administrative Templates Internet Explorer Delete Browsing History","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","displayName":"Windows Connection Manager","description":"Administrative Templates Windows Connection Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","displayName":"Security Form Settings","description":"Microsoft Outlook 2016\\Security\\Security Form Settings","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["e11f4bd4-9041-49c9-9b8c-163827d606ce","a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","c400a917-cdff-4e15-a70f-59b82df4c038"],"platforms":"windows10","technologies":"mdm"},{"id":"d512207c-854d-482d-8e52-26637eef24e3","displayName":"Parameters","description":"Administrative Templates\\Network\\TCPIP Settings\\Parameters","helpText":null,"parentCategoryId":"3a28f10c-cb75-4f85-871b-87eb9dcd883c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d52dd970-febb-4891-8eb7-1c8616cfb6cb","displayName":"Desktop Window Manager","description":"Administrative Templates Desktop Window Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["349c31c1-9b5b-42c8-91f2-aa41f4a36a71"],"platforms":"windows10","technologies":"mdm"},{"id":"d5585700-13a0-4ab4-9b19-4c15c1ead170","displayName":"Notification Settings","description":"Administrative Templates\\System\\Power Management\\Notification Settings","helpText":null,"parentCategoryId":"62b373da-c112-40f4-9047-9cc3e8d8ab13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d59dfcc1-6c35-41de-bfb6-de94b8120ca5","displayName":"Predefined","description":"Microsoft Outlook 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"7652894d-4667-443f-b925-b1686a942729","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","displayName":"KDC","description":"Administrative Templates KDC","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d5b3cab7-d486-4f74-8525-6bd740b950bc","displayName":"Customizable Error Messages","description":"Microsoft Visio 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d5d99ca9-9995-4724-bc46-fd07f362898c","displayName":"Cellular","description":"Cellular","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d6595bc3-dd73-44a3-8b32-d57af6e40208","displayName":"Windows Location Provider","description":"Administrative Templates\\Windows Components\\Location and Sensors\\Windows Location Provider","helpText":null,"parentCategoryId":"7f431009-e8fe-460e-b247-06c838c8a914","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d679b407-a753-40aa-bc9f-175f363b0eff","displayName":"File locations","description":"Microsoft Project 2016\\Project Options\\Save\\File locations","helpText":null,"parentCategoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d68abc4d-559a-4339-be48-c41a77a87034","displayName":"Passcode","description":"Security > Passcode","helpText":null,"parentCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","displayName":"Spelling","description":"Microsoft Outlook 2016\\Outlook Options\\Spelling","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d79c9f9a-f469-4f39-a66a-6f7d5ee77e81","displayName":"Language | Set Proofing Language...","description":"Microsoft Word 2016\\Review Tab\\Language | Set Proofing Language...","helpText":null,"parentCategoryId":"1fddd12c-a630-47f0-9633-638808e228f9","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d804205d-6c12-4f40-86a0-aa5a5355370f","displayName":"Files","description":"Microsoft Word 2016\\Word Options\\Advanced\\Web Options...\\Files","helpText":null,"parentCategoryId":"2108b443-384c-4bb3-9b9f-acb4a754a86a","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d875dca1-dc97-4cc5-9df3-c50b813622a3","displayName":"NS Extension Management","description":"App Management > NS Extension Management","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","displayName":"Finder","description":"User Experience > Finder","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"d9432f48-3072-4171-9031-4ebead394151","displayName":"Accessibility settings","description":"Google Google Chrome Accessibility settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9654cb3-57c8-487c-90a5-454e15336731","displayName":"External Intelligence Settings","description":"Declarative Device Management preview External Intelligence Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","displayName":"Kiosk Mode settings","description":"Microsoft Edge\\Kiosk Mode settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","displayName":"Default search provider","description":"Google Google Chrome - Default Settings users can override Default search provider","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d982a1ef-84be-4832-99d4-8b71a4644b74","displayName":"Network Connections","description":"Administrative Templates Network Connections","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d99ac221-1000-44d8-9ab4-5cdac69562ed","displayName":"Quarantine","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Quarantine","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9b5c806-099f-4be8-96e4-1152e99cbf26","displayName":"Check Accessibility","description":"Microsoft Excel 2016\\File tab\\Check Accessibility","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9b7efad-fe18-4c98-925b-c4a5db0f2815","displayName":"Windows Error Reporting","description":"Administrative Templates\\Windows Components\\Windows Error Reporting","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["23e93393-4a75-44e6-9693-208eedb06976","e781bfae-233f-463f-a85b-7299ce5a87c5"],"platforms":"windows10","technologies":"mdm"},{"id":"d9d5f333-9402-4459-8ef1-e29330cac8be","displayName":"Live Share Settings","description":"Visual Studio Live Share Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9f5ccc9-5180-43b7-9c81-89ac3364ce00","displayName":"File Share Shadow Copy Provider","description":"Administrative Templates File Share Shadow Copy Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","displayName":"Readiness Toolkit","description":"Microsoft Office 2016\\Readiness Toolkit","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"da1503cb-e474-4545-8e77-cdd577f34a08","displayName":"Miscellaneous","description":"Microsoft PowerPoint 2016\\Miscellaneous","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["7aeaf6f8-5511-4216-9483-28f432a5a08f"],"platforms":"windows10","technologies":"mdm"},{"id":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","displayName":"First- Party Sets Settings","description":"Google Google Chrome First- Party Sets Settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"da92dfd6-a29e-42a0-92ed-276bb6904455","displayName":"PowerPoint Options","description":"Microsoft PowerPoint 2016\\PowerPoint Options","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["77ca5e78-a1fe-456e-9814-034b1ea2658d","e2610f41-9a95-47e5-9fc9-572e26dc6baa","76b233cc-f977-4305-b02f-deef6667251d","85810387-3320-4056-bae2-953beeb246f7","c3b5e77d-c00d-4578-84c9-289362ad0b00","f5007db5-6ee6-4bbd-a391-9727902aad6d","f66fb7e4-a968-4969-b627-f99aaad0dfc3"],"platforms":"windows10","technologies":"mdm"},{"id":"daa2ea69-8026-465a-942c-75eb0396d5b9","displayName":"Autonomous Single App Mode","description":"App Management > Autonomous Single App Mode","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","displayName":"Previous Versions","description":"Administrative Templates Previous Versions","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dad3971c-b07b-461b-8ead-6eda80ee57e1","displayName":"Network","description":"Administrative Templates\\Network","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["fd49df1b-bfad-4ed5-85c2-046a32fa8782","4ad00da1-5ed6-47d8-aef3-70f5bcbbbc77","bd7d2b68-118d-40ee-9dfd-39b2a22a2082","de5640ce-1975-407e-a1b6-7eaa164cd159","01f2fac4-fdab-4391-bebe-ebdf6d8fcc77","76c8131a-62fe-4134-aeac-d999f01911ed","8a409581-8ea5-493c-9e9e-2190f66381c3","bd8dacbf-ab7b-4a93-8294-7db61b9d49b4","82a9c23f-2c09-4479-9cd3-e7f185d7676f","f2345e03-bcd9-48fc-9c52-11ae06ba625a","b13e38a0-6ad6-4a1f-b53f-d8ca94847586","1b1be733-8615-4738-8797-c159d4d484be","618e0144-c57c-45e1-8b55-94dd3d9fec33","30fcb92f-4d0c-4dbf-95d0-a86350e9efc6","9d6a14ba-11f5-423d-afc0-8d30be1153c1","c95a5920-ad56-4668-a6ad-19c3eb428557","1cda8821-d9e2-485e-8d78-1829593d41ca","3a28f10c-cb75-4f85-871b-87eb9dcd883c","fc8f887c-cfd9-4bea-bfac-2214d06dba99","b221d3c2-e05a-4210-bf9c-2d7c7c0fd35a","b1393de2-587f-4516-a35d-58098f2be3c9"],"platforms":"windows10","technologies":"mdm"},{"id":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","displayName":"Shutdown Options","description":"Administrative Templates Shutdown Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","displayName":"Internet Formatting","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\Internet Formatting","helpText":null,"parentCategoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["25df12bc-5ebd-4db2-8930-5d27690f3e60"],"platforms":"windows10","technologies":"mdm"},{"id":"db47f067-f435-4095-8b98-aa3805bc0050","displayName":"Schedule","description":"Microsoft Project 2016\\Project Options\\Schedule","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","304a579b-ff3b-4897-8bb8-5a1dda45356f"],"platforms":"windows10","technologies":"mdm"},{"id":"dba1a547-e288-45ac-8553-27a3b564699e","displayName":"Custom","description":"Microsoft Access 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"b8158968-c839-4d37-9eb8-887bd6fd7402","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dba26132-cba6-4178-93c3-f02476532f08","displayName":"Keyboard Settings","description":"Declarative Device Management preview Keyboard Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","displayName":"Windows File Protection","description":"Administrative Templates\\System\\Windows File Protection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","displayName":"PKCS certificate","description":"PKCS certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dc049161-17c6-411e-906b-a871b33651cd","displayName":"Proofing","description":"Microsoft Word 2016\\Word Options\\Proofing","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["e95db55a-8337-416d-a61f-e60f55cc0d13","4dae3032-1f16-4ace-911b-a957db0b8089"],"platforms":"windows10","technologies":"mdm"},{"id":"dc16dbf0-aac8-4ff3-a546-1ddb55650f47","displayName":"Programs","description":"Administrative Templates Programs","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","displayName":"Parental Controls Content Filter","description":"Parental Controls > Parental Controls Content Filter","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"dd68a290-1ba7-470f-afca-339f443a767c","displayName":"MDM Options","description":"Managed Settings MDM Options","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","displayName":"Calculation options for 'Project1'","description":"Microsoft Project 2016\\Project Options\\Calculation\\Calculation options for 'Project1'","helpText":null,"parentCategoryId":"20ed0d61-bbf7-421e-8926-0921c7ff7e75","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["acbc106b-796a-4ba3-ab5f-c130530ad455"],"platforms":"windows10","technologies":"mdm"},{"id":"dd9a3dad-5851-4899-a5c1-c23318986846","displayName":"File Classification Infrastructure","description":"Administrative Templates File Classification Infrastructure","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dd9e4ae2-a432-4c48-a73a-52c75c3e5279","displayName":"Trusted Certificate","description":"Trusted Certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"dd9e4ae2-a432-4c48-a73a-52c75c3e5279","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ddb64e9d-34b9-44f4-9980-a6623f14e445","displayName":"Custom Profile","description":"Declarative Device Management preview Custom Profile","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"visionOS,tvOS","technologies":"appleRemoteManagement"},{"id":"ddcc8634-edc3-40ef-a444-45f806439c18","displayName":"Application Defaults","description":"Application Defaults","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ddcc8634-edc3-40ef-a444-45f806439c18","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"de5640ce-1975-407e-a1b6-7eaa164cd159","displayName":"Network Connectivity Status Indicator","description":"Administrative Templates\\Network\\Network Connectivity Status Indicator","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"de643352-007f-4a47-8c83-d75a79516b39","displayName":"Deprecated policies","description":"Google Google Chrome - Default Settings users can override Deprecated policies","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"de8dd733-3bb6-4ce5-9f93-475caac1862c","displayName":"Application","description":"Administrative Templates\\Windows Components\\Event Log Service\\Application","helpText":null,"parentCategoryId":"fcddcc0b-7cf8-4ebc-a818-d10689603263","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"de9a9583-d660-4bdc-83bc-404c8c488267","displayName":"Memory Dump","description":"Memory Dump","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"de9a9583-d660-4bdc-83bc-404c8c488267","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dea96bde-003b-46fa-a960-baf62289c57d","displayName":"Delete Browsing History","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Delete Browsing History","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"deadde1d-7e7f-4577-bd6e-fc237c3854c5","displayName":"Group Policy","description":"Administrative Templates\\System\\Group Policy","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dec8381a-0a61-406b-842b-fc6ae9930795","displayName":"Lock Screen Message","description":"System Configuration > Lock Screen Message","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"decab1d2-3474-4727-87c0-d0bc648f2458","displayName":"Calendar Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","826db7fb-889b-4a99-80a6-38347ba37f21","c6b72060-8ecb-41d8-8625-2984dd756d4a","2592e8ea-5eb0-482b-b41e-eab92f33ac07","34c07941-8f52-43ad-b0ca-a7284655afb4"],"platforms":"windows10","technologies":"mdm"},{"id":"df0be435-d790-485a-b355-6f00eae29511","displayName":"Device Guard","description":"Administrative Templates\\System\\Device Guard","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"df357f0c-78fe-4aee-a465-f3da7499077e","displayName":"Proofing Data Collection","description":"Microsoft Office 2016\\Tools | Options | Spelling\\Proofing Data Collection","helpText":null,"parentCategoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dfab5866-1712-4bbf-8edf-5b080b315b9b","displayName":"Manageability","description":"Microsoft Edge\\Manageability","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"dfd5d749-c68c-448f-ab3f-851c09f09df4","displayName":"Auto Save Options","description":"Microsoft Project 2016\\Project Options\\Save\\Auto Save Options","helpText":null,"parentCategoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","displayName":"Locked- Down Local Machine Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Local Machine Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","displayName":"MSS (Legacy)","description":"Administrative Templates\\MSS (Legacy)","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e042b102-b12c-48d1-86ef-f6d296da5b95","displayName":"Server Manager","description":"Administrative Templates Server Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e06fb472-94c1-4dd9-afdf-6bb2ddaa3dc6","displayName":"Client Interface","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Client Interface","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","displayName":"FSLogix","description":"FSLogix","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":["ab2be8b5-5912-4909-8d8b-e66edf4ab097","0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","f2d139ed-a314-48b7-b700-4d11adfcc309","5c645a3e-bc39-44e9-8786-4c82e0553d22"],"platforms":"windows10","technologies":"mdm"},{"id":"e0ab6868-4b53-4310-b665-f7c979941db7","displayName":"Safari Browser","description":"Declarative Device Management preview Safari Browser","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"e0dfe97e-348d-4d30-a6a1-e0de1989236e","displayName":"Other","description":"Microsoft Office 2016\\Language Preferences\\Other","helpText":null,"parentCategoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e0e10e94-325c-49e6-ab48-4f146254395f","displayName":"Form Region Settings","description":"Microsoft Outlook 2016\\Form Region Settings","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e11f4bd4-9041-49c9-9b8c-163827d606ce","displayName":"Custom Form Security","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Custom Form Security","helpText":null,"parentCategoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e13ec567-e29c-4ca0-b599-e8c43587f10a","displayName":"Tools | Local Project Cache","description":"Microsoft Project 2016\\Project Options\\Save\\Tools | Local Project Cache","helpText":null,"parentCategoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e1a2f289-40d8-4e7c-b0a6-cd36f0ee9111","displayName":"InfoPath Integration","description":"Microsoft Outlook 2016\\InfoPath Integration","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e21bab5b-308d-4dcd-b6bb-a019e7347373","displayName":"Explorer Frame Pane","description":"Administrative Templates\\Windows Components\\File Explorer\\Explorer Frame Pane","helpText":null,"parentCategoryId":"35525ba9-da99-460e-afd3-ba86506b0ba3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","displayName":"Proofing","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Proofing","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["b792508d-da03-4174-bcf1-666d128ee8ad"],"platforms":"windows10","technologies":"mdm"},{"id":"e2a41bef-2f82-409e-9d20-0fe335390f60","displayName":"Microsoft Excel 2016","description":"Microsoft Excel 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["bc58391f-664c-42dd-9d18-269e65f324a7","1b6ac108-26b0-44f4-95a1-f848d1e90d76","d9b5c806-099f-4be8-96e4-1152e99cbf26","9a2bfe77-7e03-4a24-a9fa-c42a225a28b8","a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","28831364-ca54-4f31-acca-1aa0c7a7d3d2","b473c6fa-a971-4e5d-ad15-2c27c17c5d3e","5b832259-c30b-43bb-b249-9d3ea4d5b028"],"platforms":"windows10","technologies":"mdm"},{"id":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","displayName":"Delivery Optimization","description":"Delivery Optimization","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e344b25a-2046-4e70-a3b9-1a418613861f","displayName":"Miscellaneous","description":"Microsoft Project 2016\\Miscellaneous","helpText":null,"parentCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","displayName":"Offline Address Book","description":"Microsoft Outlook 2016\\Account Settings\\Exchange\\Offline Address Book","helpText":null,"parentCategoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e36863b6-3232-4a29-be02-32ee67cc48b9","displayName":"External Content","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\External Content","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e3a7d1a6-ab02-4c88-86d9-0b541c033d13","displayName":"Federated Authentication","description":"Federated Authentication","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e3a7d1a6-ab02-4c88-86d9-0b541c033d13","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e3ca94a7-e506-4133-8fae-41931dc863a5","displayName":"Disk Diagnostic","description":"Administrative Templates Disk Diagnostic","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e42edcd8-fcb0-4255-a774-c78b34f0b0c9","displayName":"Desktop","description":"User Experience > Desktop","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","displayName":"E-mail","description":"Microsoft OneNote 2016\\OneNote Options\\E-mail","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e50acc0f-d177-4803-aa31-fc97eeb60ff2","displayName":"MSI Corrupted File Recovery","description":"Administrative Templates MSI Corrupted File Recovery","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e50b312c-2bb3-4565-9212-080dba8d3d85","displayName":"Handwriting personalization","description":"Administrative Templates\\Control Panel\\Regional and Language Options\\Handwriting personalization","helpText":null,"parentCategoryId":"18db3d59-661b-47ec-900a-bf75495ca598","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e522c142-5666-4090-a7f4-1da1487f5384","displayName":"Co-authoring","description":"Microsoft Word 2016\\Collaboration Settings\\Co-authoring","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","displayName":"Disable Items in User Interface","description":"Microsoft PowerPoint 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","a20fe651-0f0a-4ddd-9d8b-273f17c89e22"],"platforms":"windows10","technologies":"mdm"},{"id":"e6231142-3d39-44a7-9522-6a3357bd439f","displayName":"Personalization","description":"Administrative Templates\\Control Panel\\Personalization","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e63361ad-a54b-4557-acc7-02c272a3e58d","displayName":"Smart cut and paste","description":"Microsoft Word 2016\\Word Options\\Advanced\\Smart cut and paste","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6911a08-946f-4b70-99cb-2a8b92c461e0","displayName":"Restrict ActiveX Install","description":"Administrative Templates Internet Explorer Security Features Restrict ActiveX Install","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6b767af-2ce1-4c91-9360-15abbb0bf3bc","displayName":"Remote FX USB Device Redirection","description":"Administrative Templates Remote FX USB Device Redirection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6f727b7-f474-4010-b214-83149ffdac2b","displayName":"Miscellaneous","description":"Microsoft Visio 2016\\Miscellaneous","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","displayName":"DNS Client","description":"Administrative Templates DNS Client","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e73ddc98-e465-43b0-bfd8-8a18cd9d4830","displayName":"Exploit Guard","description":"Exploit Guard","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e73ddc98-e465-43b0-bfd8-8a18cd9d4830","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"e740736f-75f9-481d-990c-02018abc2ea5","displayName":"Local Security Authority","description":"Administrative Templates System Local Security Authority","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e781bfae-233f-463f-a85b-7299ce5a87c5","displayName":"Consent","description":"Administrative Templates\\Windows Components\\Windows Error Reporting\\Consent","helpText":null,"parentCategoryId":"d9b7efad-fe18-4c98-925b-c4a5db0f2815","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e7ae2b99-0479-475f-af5c-96457121fcd0","displayName":"Windows Hello For Business","description":"Windows Hello For Business","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","displayName":"Reporting","description":"Administrative Templates App-V Reporting","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e7dccaa6-2b16-4dd3-b835-83ca641d0c80","displayName":"Accessibility Settings","description":"Managed Settings Accessibility Settings","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","displayName":"Defender","description":"Defender","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"e8514a44-e44c-47af-a714-7697ebb2baf7","displayName":"Pen Flicks Learning","description":"Administrative Templates\\Windows Components\\Tablet PC\\Pen Flicks Learning","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e865337e-db9f-4d4c-b9fe-35030792c942","displayName":"Microsoft Outlook 2016","description":"Microsoft Outlook 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["3f216590-fb12-4f8e-924f-2a6895d94126","e0e10e94-325c-49e6-ab48-4f146254395f","d0ff97aa-cf53-460e-be82-2c521a56eec6","fb721630-fc42-465b-ba22-ab670698c8b5","92d9620c-92b6-45ec-b7d6-2f9ed0751e78","f77040df-7dd2-4916-b6a0-5ef962686d4e","b3e317cd-c580-478e-885c-666ce3079e78","e1a2f289-40d8-4e7c-b0a6-cd36f0ee9111","a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","75ad885f-6118-4508-a2fd-bb26be931c3f","7652894d-4667-443f-b925-b1686a942729","ee62e9fc-14c8-4f24-aa7e-89524087a802","2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","f5a1a387-6665-4527-b532-88a64a76e732"],"platforms":"windows10","technologies":"mdm"},{"id":"e86f24d3-8531-4298-b064-692ea795b1d9","displayName":"Diagnostics","description":"Microsoft Office 2016 Diagnostics","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","displayName":"Compose Messages","description":"Microsoft Outlook 2016\\Outlook Options\\Mail\\Compose Messages","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e8ce968b-91cb-4301-ba98-b37d42bc5213","displayName":"Automatically as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type\\Automatically as you type","helpText":null,"parentCategoryId":"4dae3032-1f16-4ace-911b-a957db0b8089","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e905d6cf-7820-48d4-86e0-b55fa991a5ad","displayName":"Profile Removal Password","description":"Managed Devices > Profile Removal Password","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e905d6cf-7820-48d4-86e0-b55fa991a5ad","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","displayName":"Trusted Add-ins","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Programmatic Security\\Trusted Add-ins","helpText":null,"parentCategoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e95335ec-2704-47ab-8b40-f602b31eeb9d","displayName":"Content Caching","description":"Networking > Content Caching","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"e95db55a-8337-416d-a61f-e60f55cc0d13","displayName":"AutoCorrect","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoCorrect","helpText":null,"parentCategoryId":"dc049161-17c6-411e-906b-a871b33651cd","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e972d9fe-a9b7-4a65-a88f-0958fab19584","displayName":"App runtime","description":"Administrative Templates App runtime","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e9aff162-feb0-400a-aa68-8dd8deb93275","displayName":"Windows Logon Options","description":"Administrative Templates\\Windows Components\\Windows Logon Options","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","displayName":"Power","description":"Power","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","displayName":"Session Time Limits","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Session Time Limits","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ea812d2c-1cf9-4132-9b33-12bb7ac17dbd","displayName":"Publishing","description":"Administrative Templates\\System\\App-V\\Publishing","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ea9a092f-dd93-41d4-9bbb-118de1213578","displayName":"Integration","description":"Administrative Templates App-V Integration","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","displayName":"IME (Japanese)","description":"Microsoft Office 2016\\IME (Japanese)","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb5baf57-86c8-4bfa-ac3a-53025686e37c","displayName":"Reporting","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Reporting","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb6409fc-fb52-413d-ae4b-eff017b52b30","displayName":"Experimentation","description":"Microsoft Edge\\ Experimentation","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb947c30-3c43-4d34-a566-a842a1a142f3","displayName":"Language Preferences","description":"Microsoft Office 2016\\Language Preferences","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["0f6020d9-278b-4284-894a-bc4a70c8cf32","e0dfe97e-348d-4d30-a6a1-e0de1989236e","3512a9f5-d692-4a1f-aedd-1bd431ae893e"],"platforms":"windows10","technologies":"mdm"},{"id":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","displayName":"Security","description":"Microsoft Word 2016\\Word Options\\Security","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["5f7e1206-359d-49d7-82c3-f6b6a6eddf65","a5ce858b-74c2-4663-9b3e-068d31349a13"],"platforms":"windows10","technologies":"mdm"},{"id":"ecfb5fea-26cc-494b-9e5e-88b5e51a5be0","displayName":"Internet Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Internet Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ed137c3d-d7bc-48f3-ad86-ff194fc6820d","displayName":"Calculation options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\Calculation\\Calculation options for Microsoft Project","helpText":null,"parentCategoryId":"20ed0d61-bbf7-421e-8926-0921c7ff7e75","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ed24097d-3bb7-459c-83fb-f0090d1ad8dd","displayName":"Speech","description":"Speech","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ed24097d-3bb7-459c-83fb-f0090d1ad8dd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eda31027-9270-4959-801b-397fa05512e2","displayName":"Restrictions","description":"Restrictions","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"eda31027-9270-4959-801b-397fa05512e2","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"edba50d5-da3c-48cb-8e50-381ad0bfaaaf","displayName":"Exclusions","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Exclusions","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"edd1e620-09e1-47ea-abc8-1e241a174ed9","displayName":"Locale Services","description":"Administrative Templates Locale Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"edf3754c-b22d-4946-a744-4773240a5883","displayName":"WWAN Media Cost","description":"Administrative Templates WWAN Service WWAN Media Cost","helpText":null,"parentCategoryId":"cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ee62e9fc-14c8-4f24-aa7e-89524087a802","displayName":"Customizable Error Messages","description":"Microsoft Outlook 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eec07ad3-24ef-4502-8125-9fc988650a7c","displayName":"Settings","description":"Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510","displayName":"General","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\General","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eefc9ae4-b9ae-4d77-8b68-359b9e5ec6f7","displayName":"WWAN UI Settings","description":"Administrative Templates WWAN Service WWAN UI Settings","helpText":null,"parentCategoryId":"cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","displayName":"Edge Workspaces settings","description":"Microsoft Edge Edge Workspaces settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"ef7328b1-c666-40fe-a933-57b14bc77dd3","displayName":"Wallpaper","description":"Managed Settings Wallpaper","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","displayName":"Native Messaging","description":"Microsoft Edge\\Native Messaging","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"ef8b8f2d-7791-4c44-a4f2-e39051f2e715","displayName":"Above Lock","description":"Above Lock","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ef8b8f2d-7791-4c44-a4f2-e39051f2e715","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"efabaf11-42e4-48ab-81ca-4514199d239b","displayName":"Scripting","description":"Administrative Templates App-V Scripting","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","displayName":"Trust Center","description":"Microsoft Office 2016\\Security Settings\\Trust Center","helpText":null,"parentCategoryId":"50b4bc60-802c-477a-9366-80e09154595f","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["135e4013-43b8-4227-99fd-54ddeac4e329","24f6d328-64e7-4490-be38-452ac3b61f6f","517e55f5-729f-4b4d-9555-33baa95a0e5a"],"platforms":"windows10","technologies":"mdm"},{"id":"effee722-f6ec-440e-a892-bf645bc341ff","displayName":"Reboot","description":"Reboot","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"effee722-f6ec-440e-a892-bf645bc341ff","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f00e9baf-9bbf-48e4-aaac-57410730f016","displayName":"Sign-in settings","description":"Google Google Chrome Sign-in settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f0190b73-0d5c-410e-bce1-e03aa1f62ed4","displayName":"Security Settings","description":"Microsoft Office 2016 (Machine)\\Security Settings","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":["fa8e7b34-c736-47ec-be83-a9f1960d5281"],"platforms":"windows10","technologies":"mdm"},{"id":"f019963f-f4ed-4429-b6e3-babfb24c36a8","displayName":"Parental Controls Application Restrictions","description":"Parental Controls > Parental Controls Application Restrictions","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","displayName":"Connectivity","description":"Connectivity","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f10138ba-123a-43bc-8031-4458ba327374","displayName":"Mixed Reality","description":"Mixed Reality","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f10138ba-123a-43bc-8031-4458ba327374","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","displayName":"Visio Options","description":"Microsoft Visio 2016\\Visio Options","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["ad9610c6-d1c5-4c7a-9e74-58b810dd759d","2ea63962-4cac-4a5c-9181-e6a364489db0","8495c82c-f273-4bcc-8886-6751103a9c7b","2764869c-54a3-462b-bc72-c580621ab6bb","957a5b24-ed7a-4f84-9d73-7b6131367396","a7d55d90-e1d1-4577-8bfd-fe2641bce461"],"platforms":"windows10","technologies":"mdm"},{"id":"f125d7cd-a333-4f24-a5f4-99fc289c6d22","displayName":"Package Management","description":"Administrative Templates App-V Package Management","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f1278d6b-60ec-4369-88cf-21df47caaec6","displayName":"Remote Procedure Call","description":"Administrative Templates Remote Procedure Call","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","displayName":"App Store","description":"App Store > App Store","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f14074a2-de74-48df-b273-48791217ef4d","displayName":"Security Settings","description":"Administrative Templates\\System\\Service Control Manager Settings\\Security Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f1455024-7de9-448f-8d8f-a42db2af0a35","displayName":"Printer Redirection","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Printer Redirection","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","displayName":"Event Log Service","description":"Administrative Templates Event Log Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["55a61bb8-e023-4741-8213-99995c5902e5","fecd321b-9a48-4f97-bbed-b335f9ccebdb","a28dd311-46e8-4868-89ab-d3745c0bca21","1a2a4fc8-c54b-4906-a422-7dd51a196211"],"platforms":"windows10","technologies":"mdm"},{"id":"f2345e03-bcd9-48fc-9c52-11ae06ba625a","displayName":"Background Intelligent Transfer Service (BITS)","description":"Administrative Templates\\Network\\Background Intelligent Transfer Service (BITS)","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f26fe4c2-d073-4e51-90bf-61c4bbdeb4f2","displayName":"Privacy","description":"Administrative Templates Internet Explorer Privacy","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","displayName":"AutoArchive","description":"Microsoft Outlook 2016\\Outlook Options\\Other\\AutoArchive","helpText":null,"parentCategoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f2bf77fd-37df-448b-8959-6478abf96f6f","displayName":"Mail Format","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","88b16683-81f2-450a-9bf2-42f582e0b748","91bf761c-1a1e-4a3a-adbf-27288ea7b0b3"],"platforms":"windows10","technologies":"mdm"},{"id":"f2d139ed-a314-48b7-b700-4d11adfcc309","displayName":"Cloud Cache Service","description":"FS Logix Cloud Cache Service","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f3027ba5-9a2f-42c6-9872-ec21f726929c","displayName":"Early Launch Antimalware","description":"Administrative Templates Early Launch Antimalware","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f3264346-fdc4-4e23-9a2a-dcfc34022e59","displayName":"Printer Redirection","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Printer Redirection","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f34e3da0-b440-43dc-a368-4fd39646a9c5","displayName":"Trust Center","description":"Microsoft Visio 2016\\Visio Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"2ea63962-4cac-4a5c-9181-e6a364489db0","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["75f9bfd8-8ee2-47b0-b080-a4d179724ca8"],"platforms":"windows10","technologies":"mdm"},{"id":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","displayName":"Device password","description":"Device Restriction Device password","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise,aosp","technologies":"android"},{"id":"f35cc803-3a06-4262-b38b-a5295321f756","displayName":"Extensible Single Sign On Kerberos","description":"Authentication > Extensible Single Sign On Kerberos","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm"},{"id":"f36a78cf-46cf-418e-a98e-032f6cfad224","displayName":"App Management","description":"App Management","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":["d875dca1-dc97-4cc5-9df3-c50b813622a3","7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","daa2ea69-8026-465a-942c-75eb0396d5b9","8efd284f-5a56-4da8-8821-f51984ff954d"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","displayName":"Smart Card","description":"Security > Smart Card","helpText":null,"parentCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","displayName":"Windows Media Player","description":"Administrative Templates Windows Media Player","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["2f85405a-7472-44ce-8c05-b59bb54912d5","902a93e8-8beb-46c5-ba26-4e2bf6161e22","7f461268-0fb6-4247-b6db-52515d42a20e"],"platforms":"windows10","technologies":"mdm"},{"id":"f4eaa5be-1498-482e-abe6-de4fed7e3302","displayName":"Programs","description":"Administrative Templates\\Control Panel\\Programs","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f4f0dfd7-4638-4173-8b3b-0f08608bf330","displayName":"Active Directory","description":"Administrative Templates\\Desktop\\Active Directory","helpText":null,"parentCategoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f4fd69bc-8622-411d-91bb-0e214f8fb112","displayName":"Logon","description":"Administrative Templates\\System\\Logon","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f5007db5-6ee6-4bbd-a391-9727902aad6d","displayName":"General","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\General","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f52d9745-eaf4-4e39-84b2-6b32c3b15aa3","displayName":"IPv6 Transition Technologies","description":"Administrative Templates\\Network\\TCPIP Settings\\IPv6 Transition Technologies","helpText":null,"parentCategoryId":"3a28f10c-cb75-4f85-871b-87eb9dcd883c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f59804be-7fc6-43c3-9baa-942aab85be84","displayName":"Display","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Display","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f59f7502-cd01-4ea7-9925-2231f88596f0","displayName":"Dma Guard","description":"Dma Guard","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f59f7502-cd01-4ea7-9925-2231f88596f0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f5a1a387-6665-4527-b532-88a64a76e732","displayName":"Miscellaneous","description":"Microsoft Outlook 2016\\Miscellaneous","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["ffb0a109-2507-42b3-b26f-9f667f2d5029","cb6472c8-3e22-4029-af98-8a97f03a5a44"],"platforms":"windows10","technologies":"mdm"},{"id":"f5babdb3-c718-4675-b977-6c7bc7e6f886","displayName":"Check Accessibility","description":"Microsoft PowerPoint 2016\\File Tab\\Check Accessibility","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f5e39798-0511-462f-b859-f892fdde4328","displayName":"iSCSI Target Discovery","description":"Administrative Templates\\System\\iSCSI\\iSCSI Target Discovery","helpText":null,"parentCategoryId":"363982dd-fc96-49ce-a499-f6401f2c212b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","displayName":"Internet Explorer","description":"Administrative Templates\\Windows Components\\Internet Explorer","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["dea96bde-003b-46fa-a960-baf62289c57d","6776f6fa-8836-408c-b91c-1e444e0cba5c","accec716-3bf1-4a33-882d-3538d32fcbbc","c26b2f10-f2c0-45f2-955c-5379dd12f206","586c5c5a-15cd-4592-beae-1709c6daf5b7","7a85e72a-a755-4903-b1fd-4939049380f4"],"platforms":"windows10","technologies":"mdm"},{"id":"f62e0f2a-4363-4246-8057-1dc811fe4360","displayName":"System","description":"System","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","displayName":"Local Network Access settings","description":"Google Google Chrome Local Network Access settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f66fb7e4-a968-4969-b627-f99aaad0dfc3","displayName":"Customize Ribbon","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Customize Ribbon","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f69e6993-2e88-4938-bfe5-cea9ab21a858","displayName":"Windows Remote Shell","description":"Administrative Templates Windows Remote Shell","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","displayName":"Parental Controls Time Limits","description":"Parental Controls > Parental Controls Time Limits","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","displayName":"Windows Defender Security Center","description":"Windows Defender Security Center","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f7486553-9e63-4d63-9423-56e5ffe48700","displayName":"Google Cast","description":"Google Google Chrome Google Cast","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f77040df-7dd2-4916-b6a0-5ef962686d4e","displayName":"Meeting Workspace","description":"Microsoft Outlook 2016\\Meeting Workspace","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f783d1ea-2f9b-4fcb-96cc-fb455cfe69f9","displayName":"Fault Tolerant Heap","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Fault Tolerant Heap","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f8a973d8-b5d6-4d3e-9e82-63f61107fd0c","displayName":"Windows Licensing","description":"Windows Licensing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f8a973d8-b5d6-4d3e-9e82-63f61107fd0c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f8bb78a3-d1e4-4c5d-8b0a-904a83830519","displayName":"Shared Folders","description":"Administrative Templates\\Shared Folders","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f8f4d337-4c55-4518-91c4-f7f77703d843","displayName":"Software Update","description":"System Updates > Software Update","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f926f6e3-1bd6-4259-ae7c-e14108568882","displayName":"Microsoft Support Diagnostic Tool","description":"Administrative Templates Microsoft Support Diagnostic Tool","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f96201d4-894e-4a72-87fb-22146039a802","displayName":"Device Health Attestation Service","description":"Administrative Templates\\System\\Device Health Attestation Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f9e53433-d8d9-4eaf-bdf3-d32de60d686e","displayName":"Customize Ribbon","description":"Microsoft Word 2016\\Word Options\\Customize Ribbon","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","displayName":"Subscribed Calendars","description":"Accounts Subscribed Calendars","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"fa2722a8-dcfd-4e14-a429-2b0041642c77","displayName":"Network settings","description":"Google Google Chrome Network settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","displayName":"Windows App","description":"Windows App","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","displayName":"Editing","description":"Microsoft OneNote 2016\\OneNote Options\\Editing","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa6bfb01-34f6-4c54-89b9-f7e717e6d394","displayName":"Customize Ribbon","description":"Microsoft Outlook 2016\\Outlook Options\\Customize Ribbon","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa8e7b34-c736-47ec-be83-a9f1960d5281","displayName":"IE Security","description":"Microsoft Office 2016 (Machine)\\Security Settings\\IE Security","helpText":null,"parentCategoryId":"f0190b73-0d5c-410e-bce1-e03aa1f62ed4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","displayName":"Microsoft Word 2016","description":"Microsoft Word 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["1fddd12c-a630-47f0-9633-638808e228f9","73bc2db9-d37f-4add-a64d-a8239273edb3","b8adcde1-500a-430f-8636-f97eaae2a2c6","12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","e522c142-5666-4090-a7f4-1da1487f5384","320ccaa3-a391-4d29-a9c4-594561f4104d","31070051-859e-4d27-9df3-c07b8a2d2179","740e7a10-3774-4a1c-9970-6907e0f0b848"],"platforms":"windows10","technologies":"mdm"},{"id":"fb1e99d0-b921-4b19-9842-17e3e7987528","displayName":"Edge Website Typo Protection settings","description":"Microsoft Edge Edge Website Typo Protection settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"fb721630-fc42-465b-ba22-ab670698c8b5","displayName":"Search Folders","description":"Microsoft Outlook 2016\\Search Folders","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fc8f887c-cfd9-4bea-bfac-2214d06dba99","displayName":"WWAN Service","description":"Administrative Templates\\Network\\WWAN Service","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["a51a8665-045d-482d-b68b-2128959c8b31","ab6aa2f6-87bf-4a06-a206-e0902af3e4bc"],"platforms":"windows10","technologies":"mdm"},{"id":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","displayName":"Restricted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Restricted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","displayName":"Delegates","description":"Microsoft Outlook 2016\\Outlook Options\\Delegates","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fcddcc0b-7cf8-4ebc-a818-d10689603263","displayName":"Event Log Service","description":"Administrative Templates\\Windows Components\\Event Log Service","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["de8dd733-3bb6-4ce5-9f93-475caac1862c","8dca6b5f-ff9c-44c8-9822-008acef616aa","9d26f3a1-6a54-4043-bda2-bfeb84e80524","66448b13-cc0a-4ffe-9ad5-62c4821dc77f"],"platforms":"windows10","technologies":"mdm"},{"id":"fd16aa29-dae5-49b5-910e-88f3078ce2da","displayName":"Push To Install","description":"Administrative Templates\\Windows Components\\Push To Install","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","displayName":"Xsan Preferences","description":"Xsan > Xsan Preferences","helpText":null,"parentCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","rootCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"fd49df1b-bfad-4ed5-85c2-046a32fa8782","displayName":"Lanman Server","description":"Administrative Templates\\Network\\Lanman Server","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fddc444c-3591-4a50-865b-d8993b798e12","displayName":"Cast","description":"Microsoft Edge\\Cast","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"fe3cb879-8869-4163-91d7-e432abd75da8","displayName":"Scheduled Maintenance","description":"Administrative Templates Scheduled Maintenance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe52de11-190e-4429-96c1-106b22724456","displayName":"Device and Resource Redirection","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Device and Resource Redirection","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe54701d-42bd-47f0-9c49-26ff6a928b32","displayName":"Protected View","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe65603b-1980-446b-ae17-516eb885c6be","displayName":"Tablet PC Pen Training","description":"Administrative Templates Tablet PC Pen Training","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe786056-6f4a-4d16-bff4-5fbb640308d2","displayName":"Trusted Locations","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe7c8652-17d4-40a7-869c-f7cfc3454402","displayName":"Show indicators and Option butons for","description":"Microsoft Project 2016\\Project Options\\Interface\\Show indicators and Option butons for","helpText":null,"parentCategoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe845e81-5993-4a65-b22a-decfc5928c65","displayName":"Proxy server","description":"Microsoft Edge\\Proxy server","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","displayName":"Scareware Blocker settings","description":"Microsoft Edge - Default Settings users can override Scareware Blocker settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","displayName":"Application","description":"Administrative Templates Event Log Service Application","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","displayName":"Predefined","description":"Microsoft Visio 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"c67c9e69-6e69-4b63-868c-3b3df5d17e47","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ff543267-540e-4e37-a1e9-daf6a5e16ba7","displayName":"Proxy Server","description":"Microsoft Edge Update\\Proxy Server","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","displayName":"E-mail","description":"Microsoft Outlook 2016\\Account Settings\\E-mail","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","displayName":"Notifications","description":"User Experience > Notifications","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"ffb0a109-2507-42b3-b26f-9f667f2d5029","displayName":"Miscellaneous","description":"Microsoft Outlook 2016\\Miscellaneous\\Miscellaneous","helpText":null,"parentCategoryId":"f5a1a387-6665-4527-b532-88a64a76e732","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","displayName":"Microsoft Access 2016","description":"Microsoft Access 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["607a1c39-a3db-496f-8db6-c99d67f5f76c","6730f0be-a129-4b48-942f-e4ddf69fee66","b8158968-c839-4d37-9eb8-887bd6fd7402","d0a3bbad-8ed0-4545-8249-9e464a13e1b7","c3ab8d44-b353-4a8a-a526-ffd743fb7ff8"],"platforms":"windows10","technologies":"mdm"},{"id":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","displayName":"App Package Deployment","description":"Administrative Templates\\Windows Components\\App Package Deployment","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ffd1a98f-0fac-47fe-813f-7510d0dacbc3","displayName":"Windows Resource Exhaustion Detection and Resolution","description":"Administrative Templates Windows Resource Exhaustion Detection and Resolution","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","displayName":"Audio and Video","description":"Microsoft OneNote 2016\\OneNote Options\\Audio and Video","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fff51673-04b8-4277-98ef-4baffbd8d192","displayName":"Windows Calendar","description":"Administrative Templates Windows Calendar","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"}] +[{"id":"005ddf8f-da22-4b23-ab02-289f8f6c7960","displayName":"Internet Explorer","description":"Administrative Templates Internet Explorer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["f26fe4c2-d073-4e51-90bf-61c4bbdeb4f2","a1fbe395-3b60-475f-8a34-3710d6b2e09f","d4bf78d5-f6da-463d-85a3-d763e6fbe32b","3f6bb987-17dc-4442-a946-c1c5b1d089d7","bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","b491424f-100c-4f84-9b9c-8573b2ff9ac7"],"platforms":"windows10","technologies":"mdm"},{"id":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","displayName":"Startup, home page and new tab page","description":"Microsoft Edge\\Startup, home page and new tab page","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"01d16911-19a1-4dcb-8089-ffa4781d977c","displayName":"Windows Ink Workspace","description":"Windows Ink Workspace","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"01d16911-19a1-4dcb-8089-ffa4781d977c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"01da0c26-af30-4eb2-a899-7d5e7ecb9738","displayName":"Video and Display Settings","description":"Administrative Templates Power Management Video and Display Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"023e0367-b563-4fae-8fb6-589c836ee223","displayName":"Add or Remove Programs","description":"Administrative Templates Add or Remove Programs","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"025c640e-51e2-4f04-85e3-a13f30b5e08c","displayName":"Encoding","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\Encoding","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"038b49c9-4f13-4ace-be8d-bd076bffa23e","displayName":"Save","description":"Microsoft Publisher 2016\\Publisher Options\\Save","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"03a966f7-8f8e-4ecb-aab3-055fe907f5ab","displayName":"Security Account Manager","description":"Administrative Templates Security Account Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","displayName":"Manage Restricted Permissions","description":"Microsoft Office 2016\\Manage Restricted Permissions","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0456dcd5-c003-4a8b-80e6-61bacf854330","displayName":"RD Licensing","description":"Administrative Templates Remote Desktop Services RD Licensing","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","displayName":"Microsoft Publisher 2016","description":"Microsoft Publisher 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["9caa3b08-b545-4c21-a3b7-b5d2302c1a81","c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","c6c1120b-988c-4581-a21c-b9786a821242","0cea32b4-28be-4164-ae2a-6db33b9dadb7"],"platforms":"windows10","technologies":"mdm"},{"id":"0497eec4-fe3a-44f2-8caf-b5ab11839893","displayName":"Games","description":"Games","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0497eec4-fe3a-44f2-8caf-b5ab11839893","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"04b46099-4ee5-4def-8e04-569c988057a9","displayName":"Identity and sign-in","description":"Microsoft Edge - Default Settings (users can override)\\ Identity and sign-in","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"05305a87-0b19-41bb-bf1e-0bd92bfcdc16","displayName":"Push To Install","description":"Administrative Templates Push To Install","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"055293ad-c585-40c0-b66c-76ff5cc0a332","displayName":"Microsoft Office SmartArt","description":"Microsoft Office 2016\\Microsoft Office SmartArt","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"05811ceb-2954-426c-8afa-2a53f02480cc","displayName":"Permit or deny screen capture","description":"Microsoft Edge\\ Permit or deny screen capture","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"05a6f86f-dab7-4888-97a1-db3457f00974","displayName":"Writing Assistance","description":"Microsoft Office 2016 Writing Assistance","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"060e7533-6c2f-4ed1-9173-f3de58de4bed","displayName":"Internet Calendars","description":"Microsoft Outlook 2016\\Account Settings\\Internet Calendars","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0696109e-045f-486a-9a6b-ab7877887bed","displayName":"Document Information Panel","description":"Microsoft Office 2016\\Document Information Panel","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"06a85f5b-2614-4467-91cf-4a64d0c9326f","displayName":"Network Usage Rules","description":"Networking > Network Usage Rules","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"06c4a76a-805b-4370-9d80-08e720ab2305","displayName":"View options for time units in 'Project1'","description":"Microsoft Project 2016\\Project Options\\Edit\\View options for time units in 'Project1'","helpText":null,"parentCategoryId":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0775f21c-9ca1-446d-b1dc-3cea45f15605","displayName":"Files","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\Files","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"07c023d3-0899-40af-a04f-805876d99a9b","displayName":"Microsoft Management Console","description":"Administrative Templates Microsoft Management Console","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["acb49e73-5a6a-479b-9d58-c3cd7f632e9b"],"platforms":"windows10","technologies":"mdm"},{"id":"08677354-6f67-455e-a430-4d8d2fbabe84","displayName":"Web Rtc settings","description":"Microsoft Edge Web Rtc settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"088b8d8d-5f3f-4979-aa18-b3c4b2616a24","displayName":"Sound Recorder","description":"Administrative Templates Sound Recorder","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","displayName":"Disk Quotas","description":"Administrative Templates Disk Quotas","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"08c5f391-e156-4a72-bbb9-3670f2f63a56","displayName":"SmartScreen settings","description":"Microsoft Edge\\SmartScreen settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"0937f5ff-aabc-49a9-a94f-6f98c4702580","displayName":"Qo S Packet Scheduler","description":"Administrative Templates Qo S Packet Scheduler","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["cf968979-f316-47cb-a207-bf9ef28cd1aa","4ca3b8c7-0350-4043-b96d-918f24df0a3b","c87ae066-cc1a-44c9-8645-1db2359f7484"],"platforms":"windows10","technologies":"mdm"},{"id":"098942c3-afe3-40c8-823f-37f0b5b13ad4","displayName":"Remote access","description":"Google Google Chrome Remote access","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"09c02465-dc11-457e-9eac-19fc542e4cda","displayName":"MAPS","description":"Administrative Templates Microsoft Defender Antivirus MAPS","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a1347d2-90c0-407a-baa0-e4859260532a","displayName":"BitLocker","description":"BitLocker","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","displayName":"General options for 'Project1'","description":"Microsoft Project 2016\\Project Options\\General\\General options for 'Project1'","helpText":null,"parentCategoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a803a48-789a-48b0-b928-e52d56ab17f1","displayName":"Wi-Fi Settings","description":"Wi-Fi Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0a803a48-789a-48b0-b928-e52d56ab17f1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a9f982a-3515-4728-a231-fa000eb9e550","displayName":"User Preferences","description":"Preferences > User Preferences","helpText":null,"parentCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","displayName":"Profile Containers","description":"FS Logix Profile Containers","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":["479c2edd-6539-4e1d-96ba-518d6f6264c3","719595d8-ab5d-4418-88aa-8cd55c2964ba"],"platforms":"windows10","technologies":"mdm"},{"id":"0bae3158-5f75-4e25-acf4-859d2612f892","displayName":"Cloud Cache","description":"FS Logix ODFC Containers Cloud Cache","helpText":null,"parentCategoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0be23ead-c5f7-4ea5-9ec5-64c05d19cf5d","displayName":"Data Roaming","description":"Managed Settings Data Roaming","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"0be98651-a552-4470-b2dc-71c66a5ce1e6","displayName":"Presentation Services","description":"Microsoft Office 2016\\Present Online\\Presentation Services","helpText":null,"parentCategoryId":"5bf4c2ba-be08-4cda-bf33-d10707580d78","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","displayName":"RD Connection Broker","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host RD Connection Broker","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","displayName":"Security","description":"Microsoft Publisher 2016\\Security","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["30da5d88-cf03-41f4-ab55-51ead91b3844"],"platforms":"windows10","technologies":"mdm"},{"id":"0d37dddd-6575-485c-92dd-37a3c23edbf9","displayName":"BitLocker Drive Encryption","description":"Administrative Templates BitLocker Drive Encryption","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["8e6b8d0c-faf6-41e6-8e31-4389a5470caf","a18508d1-fd74-4955-8032-3bd9219a0944","acbc98d1-689b-4f9c-9c5a-e6bbf305e654"],"platforms":"windows10","technologies":"mdm"},{"id":"0d4cf1d9-d8ad-4628-bd71-fa0de6598f28","displayName":"Content settings","description":"Microsoft Edge - Default Settings (users can override)\\Content settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","displayName":"System Logging","description":"System Configuration > System Logging","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","displayName":"Wireless Network Preference","description":"Wireless Network Preference","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0e1122f8-2bbf-475b-bce0-9e43a2f5e475","displayName":"Schedule Scan","description":"Microsoft Defender Schedule Scan","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"0e6c9053-73d6-4c56-9147-53513f6eefd8","displayName":"Windows Update For Business","description":"Windows Update For Business","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","displayName":"Microsoft Project 2016","description":"Microsoft Project 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["e344b25a-2046-4e70-a3b9-1a418613861f","1266b519-e436-4698-8ff4-442acc97efd4"],"platforms":"windows10","technologies":"mdm"},{"id":"0e937777-d01a-4180-a937-c2010451a529","displayName":"Login Window Login Items","description":"Login > Login Window Login Items","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"0f05f2c4-3a19-482f-82e8-92a46a4fcbfd","displayName":"Windows Sandbox","description":"Windows Sandbox","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0f05f2c4-3a19-482f-82e8-92a46a4fcbfd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f42fc50-66c8-4b70-9904-64f8d662c930","displayName":"Custom","description":"Microsoft Word 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"740e7a10-3774-4a1c-9970-6907e0f0b848","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f6020d9-278b-4284-894a-bc4a70c8cf32","displayName":"Display Language","description":"Microsoft Office 2016\\Language Preferences\\Display Language","helpText":null,"parentCategoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f6d725e-2c2d-4926-8e78-3d2d5867eef5","displayName":"Win RM Client","description":"Administrative Templates Windows Remote Management Win RM Win RM Client","helpText":null,"parentCategoryId":"364787de-93e4-4fd6-9608-dce1ad8f88c2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"10247787-95ea-4507-93de-dbd166df12b5","displayName":"Legacy Browser Support","description":"Google Google Chrome Legacy Browser Support","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1043e7ed-8651-44b2-b918-7230c0b75a6c","displayName":"Profile settings","description":"Microsoft Edge Profile settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"10835ce3-31c8-4ec6-aa00-c5af48e550a8","displayName":"Virtualization","description":"Administrative Templates App-V Virtualization","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"114356a4-dfc9-44e9-9a62-f1d601d48445","displayName":"Mail Setup","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Setup","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"119ca05b-5f1f-4714-a942-2a76b05d2a7b","displayName":"Lock Down","description":"Lock Down","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"119ca05b-5f1f-4714-a942-2a76b05d2a7b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"11c4cf0f-a03d-4309-93b2-011be4c410d5","displayName":"Screensaver User","description":"User Experience > Screensaver User","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"11d26400-1d13-4dd6-ab4b-cb323494b127","displayName":"Intelligence Settings","description":"Declarative Device Management preview Intelligence Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"120b24dd-c04a-4291-8f24-9c48fcdc1434","displayName":"Cryptography compliance policies","description":"Microsoft Edge Cryptography compliance policies","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12142994-4b30-486c-bab1-9206528b2b96","displayName":"Accessibility settings","description":"Google Google Chrome - Default Settings users can override Accessibility settings","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1266b519-e436-4698-8ff4-442acc97efd4","displayName":"Project Options","description":"Microsoft Project 2016\\Project Options","helpText":null,"parentCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["9ecb05b7-e942-4b60-9040-d612385f5c67","8e48532a-ff0e-4422-82e2-6956b6786005","623d41fb-000e-41d8-b955-373f8c700def","28c4859e-1faa-4b51-96cf-068cb4354093","84b7f123-e849-40f9-914b-4b97b57bd3b4","20ed0d61-bbf7-421e-8926-0921c7ff7e75","db47f067-f435-4095-8b98-aa3805bc0050","6ad0e199-ff50-4e86-b22f-b55ef4ff2329","3265b420-4c88-4f7b-92cc-4e23d9452eb1","5bd8c27a-0141-4bbf-93f7-214b2389ff2d"],"platforms":"windows10","technologies":"mdm"},{"id":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","displayName":"Trusted Locations","description":"Microsoft Access 2016\\Application Settings\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12ec8efa-2dcc-4c0c-9166-72ecc3cd463e","displayName":"Common Open File Dialog","description":"Administrative Templates Common Open File Dialog","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","displayName":"Customizable Error Messages","description":"Microsoft Word 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13123148-c522-437f-b316-d78f5cc0d28d","displayName":"Shared Workspace","description":"Microsoft Office 2016\\Global Options\\Customize\\Shared Workspace","helpText":null,"parentCategoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["725adbdf-1eb8-45c4-8eb1-44747bd1615d"],"platforms":"windows10","technologies":"mdm"},{"id":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","displayName":"AirPlay","description":"AirPlay > AirPlay","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"13467142-14e7-4380-8573-4866e842c7f6","displayName":"Antivirus engine","description":"Microsoft Defender > Antivirus engine","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"135e4013-43b8-4227-99fd-54ddeac4e329","displayName":"Protected View","description":"Microsoft Office 2016\\Security Settings\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"139974ad-f615-442b-b3dc-84a44e3ec663","displayName":"Experience","description":"Experience","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13cc3b63-a150-4cf2-8d76-309975603c8e","displayName":"Loader Override Settings","description":"Microsoft Edge WebView2\\Loader Override Settings","helpText":null,"parentCategoryId":"c945edd8-c865-4932-806d-83752e3f46ad","rootCategoryId":"c945edd8-c865-4932-806d-83752e3f46ad","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13eb248a-4549-4d23-9ada-23b40edf36bf","displayName":"Reminder Options","description":"Microsoft Outlook 2016\\Outlook Options\\Other\\Advanced\\Reminder Options","helpText":null,"parentCategoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","displayName":"Time Providers","description":"Administrative Templates Windows Time Service Time Providers","helpText":null,"parentCategoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13f62499-a266-42c8-a4dc-531efcea55cb","displayName":"Microsoft Edge Dev","description":"Microsoft Edge Update\\Applications\\Microsoft Edge Dev","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"148a6f4e-8816-4c00-87a3-57481c85c331","displayName":"Startup Home page and New Tab page","description":"Google Google Chrome Startup Home page and New Tab page","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"14df2cb2-fc75-43af-87f8-a1fbd56a64e3","displayName":"Kerberos","description":"Kerberos","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"14df2cb2-fc75-43af-87f8-a1fbd56a64e3","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"14fa4ad9-525c-440d-a295-a279c73f97f1","displayName":"Widgets","description":"Widgets","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"14fa4ad9-525c-440d-a295-a279c73f97f1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","displayName":"Enterprise Cloud Print","description":"Enterprise Cloud Print","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","displayName":"Microsoft Lync Feature Policies","description":"Skype for Business 2016\\Microsoft Lync Feature Policies","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1551f6d3-415c-44a8-b184-393de7c42adf","displayName":"Advanced Error Reporting Settings","description":"Administrative Templates Windows Error Reporting Advanced Error Reporting Settings","helpText":null,"parentCategoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"156f2e6a-6638-4749-9f43-e7acc4aba762","displayName":"Windows Installer","description":"Administrative Templates Windows Installer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"15be55d8-7477-4274-9b09-b775bce68416","displayName":"Software Update Enforce Latest","description":"Declarative Device Management preview Software Update Enforce Latest","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1653fa6c-aa99-4918-92c7-1df85d8843e1","displayName":"Startup, home page and new tab page","description":"Microsoft Edge - Default Settings (users can override)\\Startup, home page and new tab page","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1671dfc3-a1dd-4178-9093-10fb6b62586a","displayName":"Cryptography","description":"Microsoft Project 2016\\Project Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"623d41fb-000e-41d8-b955-373f8c700def","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","displayName":"Scareware Blocker settings","description":"Microsoft Edge Scareware Blocker settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"1720d60f-40a6-471c-8e4c-efbacaf46997","displayName":"Cryptography","description":"Microsoft Outlook 2016\\Security\\Cryptography","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff"],"platforms":"windows10","technologies":"mdm"},{"id":"174ffe92-3770-4688-aa21-85b7535cf374","displayName":"Printing","description":"Printing > Printing","helpText":null,"parentCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","rootCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","displayName":"Install and Update Settings","description":"Visual Studio Install and Update Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"17bc9899-d157-4eac-a949-810b4a841e28","displayName":"Restrict File Download","description":"Administrative Templates Internet Explorer Security Features Restrict File Download","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"18296501-4825-47ea-835d-66a01aba9384","displayName":"Notification bar","description":"Administrative Templates Internet Explorer Security Features Notification bar","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1829cdc1-1bed-4058-9aba-9b778cd3d955","displayName":"Global Preferences","description":"Preferences > Global Preferences","helpText":null,"parentCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"183628a3-d0a5-47de-b444-e132d634ca38","displayName":"Server Settings","description":"Microsoft Excel 2016\\Miscellaneous\\Server Settings","helpText":null,"parentCategoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"184981d4-712b-425e-b0a3-93eac7fbd3ee","displayName":"Consent","description":"Administrative Templates Windows Error Reporting Consent","helpText":null,"parentCategoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","displayName":"Remote Assistance","description":"Administrative Templates Remote Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"187e5f4f-a789-4487-a848-7bf0f41597c7","displayName":"Preferences","description":"Preferences","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":["c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","0a9f982a-3515-4728-a231-fa000eb9e550","1829cdc1-1bed-4058-9aba-9b778cd3d955"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"18893f00-c309-4695-bcaf-b66286ad99c1","displayName":"Camera","description":"Camera","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"18893f00-c309-4695-bcaf-b66286ad99c1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"18b972fd-74f2-4345-9449-087c80dd38a3","displayName":"Windows Boot Performance Diagnostics","description":"Administrative Templates Windows Boot Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"191a84f2-13b5-4609-808f-8b743b7f0247","displayName":"Microsoft Outlook","description":"Microsoft Outlook > Microsoft Outlook","helpText":null,"parentCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1942922a-cba9-44c8-871f-3d915c62bd06","displayName":"Help","description":"Microsoft Office 2016\\Help","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1943deba-33f7-4c3d-98c8-6b5319ec98ab","displayName":"Driver Installation","description":"Administrative Templates Driver Installation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1979a12b-2a72-438d-9de7-320d1b38e777","displayName":"Password","description":"Microsoft OneNote 2016\\OneNote Options\\Password","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"19ab385f-14f5-47cd-87b2-f4784eedcdd9","displayName":"Windows Media Digital Rights Management","description":"Administrative Templates Windows Media Digital Rights Management","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"19ba782c-3594-45da-b829-72b54f6d45c7","displayName":"Microsoft OneDrive","description":"Microsoft Office > Microsoft OneDrive","helpText":null,"parentCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1a0386fd-354b-441e-a0d6-1523c209dae7","displayName":"General","description":"Microsoft Publisher 2016\\Publisher Options\\General","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1a056b49-3fb9-4097-b286-c5f493208578","displayName":"Personal Hotspot","description":"Managed Settings Personal Hotspot","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"1a2a4fc8-c54b-4906-a422-7dd51a196211","displayName":"Setup","description":"Administrative Templates Event Log Service Setup","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ae8c95a-5748-4647-80f8-b447e60601a2","displayName":"Add-ins","description":"Microsoft OneNote 2016\\OneNote Options\\Add-ins","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","displayName":"Preferences","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["decab1d2-3474-4727-87c0-d0bc648f2458","2b03e224-c77c-4bb0-8491-cec0b64d9a86","d0a1763a-5cdf-4672-8596-435ec1d94b54","8e7b730f-c3c9-4e04-9e45-ce06be97908c","2fbb7677-651a-4b62-8b8c-d502ea29936b"],"platforms":"windows10","technologies":"mdm"},{"id":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","displayName":"Excel Options","description":"Microsoft Excel 2016\\Excel Options","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["9215e382-4e7b-4554-8c80-80277136b544","cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","67eb1dab-7805-41bb-af5a-798dc7e29f23","d1e2bb0d-6c0e-4f40-9f2e-52055edc14b5","5886bba1-bc05-46ca-afbf-66d1b4265ca4","a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","3503e1ba-8168-4b55-92b1-84613292cadc"],"platforms":"windows10","technologies":"mdm"},{"id":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","displayName":"Default message text for a reply...","description":"Microsoft Office 2016\\Collaboration Settings\\Default message text for a reply...","helpText":null,"parentCategoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1bfef2c3-a561-4e7a-8f0f-0944bc79c20f","displayName":"Spelling","description":"Microsoft OneNote 2016\\OneNote Options\\Spelling","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","displayName":"Lanman Server","description":"Lanman Server","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ccd3115-55e7-464f-9bb9-d38a92191306","displayName":"Edge Website Typo Protection settings","description":"Microsoft Edge - Default Settings users can override Edge Website Typo Protection settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1d5e7986-870c-444b-bf09-78bbf82a53fa","displayName":"Personal Data Encryption","description":"Personal Data Encryption","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1d5e7986-870c-444b-bf09-78bbf82a53fa","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1d6d392c-8b32-459b-b114-af964a4bbbc5","displayName":"Certificate management settings","description":"Google Google Chrome Certificate management settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1dabc7da-bdf8-4c60-95de-427a4b2cb6bf","displayName":"Digital Locker","description":"Administrative Templates Digital Locker","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1dd655c9-a1f3-4780-befb-cab19922277d","displayName":"Personalization","description":"Personalization","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ed9f90e-d8b6-413f-bfc2-face955141bc","displayName":"Windows Mobility Center","description":"Administrative Templates Windows Mobility Center","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1fbc29d7-0530-4208-b506-9df648a402e9","displayName":"Voice Roaming","description":"Managed Settings Voice Roaming","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"1fcd72cb-7c09-4e7b-a314-97a88df6e623","displayName":"Recovery Lock Password","description":"Recovery Lock Password","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1fcd72cb-7c09-4e7b-a314-97a88df6e623","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1fddd12c-a630-47f0-9633-638808e228f9","displayName":"Review Tab","description":"Microsoft Word 2016\\Review Tab","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["7bee4dea-82a4-4a03-b903-654b374819b1","d79c9f9a-f469-4f39-a66a-6f7d5ee77e81"],"platforms":"windows10","technologies":"mdm"},{"id":"20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a","displayName":"Platform Update","description":"Microsoft Defender Platform Update","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"20b71dc7-cf08-4534-9e52-d297dd071ca5","displayName":"Enhanced Phishing Protection","description":"Smart Screen\\ Enhanced Phishing Protection","helpText":null,"parentCategoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","rootCategoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20bacabf-cd07-48be-a184-f0ae76d31e4a","displayName":"Contact Tab","description":"Microsoft Office 2016\\Contact Card\\Contact Tab","helpText":null,"parentCategoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20ceae56-e189-46ec-a440-791ce7454017","displayName":"Printing","description":"Google Google Chrome - Default Settings users can override Printing","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20ed0d61-bbf7-421e-8926-0921c7ff7e75","displayName":"Calculation","description":"Microsoft Project 2016\\Project Options\\Calculation","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","ed137c3d-d7bc-48f3-ad86-ff194fc6820d"],"platforms":"windows10","technologies":"mdm"},{"id":"2108b443-384c-4bb3-9b9f-acb4a754a86a","displayName":"Web Options...","description":"Microsoft Word 2016\\Word Options\\Advanced\\Web Options...","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["56e510be-ca39-46a2-9eb2-6f1af6d4b16a","d804205d-6c12-4f40-86a0-aa5a5355370f"],"platforms":"windows10","technologies":"mdm"},{"id":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","displayName":"Attack Surface Reduction","description":"Administrative Templates Microsoft Defender Antivirus Microsoft Defender Exploit Guard Attack Surface Reduction","helpText":null,"parentCategoryId":"ad84cea3-5664-4e42-a9d6-1446828bea45","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"216de445-a80d-4981-b151-3b4466edc808","displayName":"Extensions","description":"Google Google Chrome Extensions","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"224dc683-c0e0-4783-8ba8-8f02c76d161d","displayName":"Domains","description":"Networking > Domains","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"2257f7e1-3e88-4d4d-a666-437bbe42baca","displayName":"Applications","description":"Device Restriction Applications","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"22a2a407-0f28-481d-bdbe-1f9cb6d589c3","displayName":" EDR preferences","description":"Microsoft Defender EDR preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"22f2b16b-e1af-45fa-8d2f-687854b72c02","displayName":"Data Protection","description":"Data Protection","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"22f2b16b-e1af-45fa-8d2f-687854b72c02","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","displayName":"Login","description":"Login","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":["9859957e-34f1-4669-9f95-2b7c79fff052","6efb8802-223a-46a7-b13f-a68f28f8b2c2","8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","0e937777-d01a-4180-a937-c2010451a529"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"2373de26-8270-4e74-a53f-9aeb55d5553c","displayName":"Microsoft AutoUpdate (MAU)","description":"Microsoft AutoUpdate (MAU)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"23c09e06-5bee-4b20-a391-36549bf0f620","displayName":"Signing","description":"Microsoft Office 2016\\Signing","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"23fd467e-24f8-4200-8b19-c6c11afa8926","displayName":"Security","description":"Microsoft Access 2016\\Application Settings\\Security","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["a9edc695-b4a9-4111-b07d-627f934f5a1a","7eaa5e09-e5ab-4051-b557-64a124ae497c"],"platforms":"windows10","technologies":"mdm"},{"id":"2461b964-02f6-4da2-921a-f7e8f868c69d","displayName":"Enhanced Storage Access","description":"Administrative Templates Enhanced Storage Access","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"24b30053-14d2-4430-9966-281e926a6918","displayName":"Trusted Platform Module Services","description":"Administrative Templates Trusted Platform Module Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"24f6d328-64e7-4490-be38-452ac3b61f6f","displayName":"Trusted Catalogs","description":"Microsoft Office 2016\\Security Settings\\Trust Center\\Trusted Catalogs","helpText":null,"parentCategoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"251c6873-bf5b-4d85-8185-3c4973b6f33c","displayName":"Show","description":"Microsoft Project 2016\\Project Options\\View\\Show","helpText":null,"parentCategoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"253fda23-118b-48c7-b24a-27b8c93df41a","displayName":"Macro Security","description":"Microsoft Visio 2016\\Visio Options\\Security\\Macro Security","helpText":null,"parentCategoryId":"2ea63962-4cac-4a5c-9181-e6a364489db0","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2592e8ea-5eb0-482b-b41e-eab92f33ac07","displayName":"Planner Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Planner Options","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"25a84f2d-dbac-457e-b734-bc2605305f2b","displayName":"Cryptography","description":"Microsoft OneNote 2016\\OneNote Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"25df12bc-5ebd-4db2-8930-5d27690f3e60","displayName":"Message Format","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\Internet Formatting\\Message Format","helpText":null,"parentCategoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"264202da-475b-476e-bbc7-3c252f777145","displayName":"Device security group","description":"Device security group","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"264202da-475b-476e-bbc7-3c252f777145","childCategoryIds":[],"platforms":"windows10","technologies":"enrollment"},{"id":"269c487f-8902-486a-88dd-db9b9b4454b8","displayName":"Network protection","description":"Microsoft Defender Network protection","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"26c1af84-7c09-4910-8b2f-486072fef710","displayName":"Kiosk Browser","description":"Kiosk Browser","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"26c1af84-7c09-4910-8b2f-486072fef710","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"26dfd0a7-546b-4583-b0c7-85b98ac5a40c","displayName":"Tools | Macro","description":"Microsoft Project 2016\\Project Options\\Security\\Tools | Macro","helpText":null,"parentCategoryId":"623d41fb-000e-41d8-b955-373f8c700def","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"27087ae6-d02f-4b54-a143-6cde89c04989","displayName":"Device and Driver Compatibility","description":"Administrative Templates Device and Driver Compatibility","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2764869c-54a3-462b-bc72-c580621ab6bb","displayName":"Customize Ribbon","description":"Microsoft Visio 2016\\Visio Options\\Customize Ribbon","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","displayName":"Cryptography","description":"Microsoft Excel 2016\\Excel Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"27f47083-6e1b-4fc7-938b-ecd846b79d78","displayName":"Web Content Filter","description":"Declarative Device Management preview Web Content Filter","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","displayName":"Default message text for a review request...","description":"Microsoft Office 2016\\Collaboration Settings\\Default message text for a review request...","helpText":null,"parentCategoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"28831364-ca54-4f31-acca-1aa0c7a7d3d2","displayName":"Data Recovery","description":"Microsoft Excel 2016\\Data Recovery","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"28ab8eed-623a-4e9b-813e-13256472dbaf","displayName":"Customizable Error Messages","description":"Microsoft PowerPoint 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"28c4859e-1faa-4b51-96cf-068cb4354093","displayName":"View","description":"Microsoft Project 2016\\Project Options\\View","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["70b0e7ef-ceac-4c25-8f9f-5a6bf07163b6","251c6873-bf5b-4d85-8185-3c4973b6f33c"],"platforms":"windows10","technologies":"mdm"},{"id":"290ec637-e780-4e95-9834-6368ac0437d1","displayName":"Power Management","description":"Administrative Templates Power Management","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["3b64e99d-0359-4264-be38-c544c647f493","01da0c26-af30-4eb2-a899-7d5e7ecb9738","91c02e14-8848-485d-8844-b9933fa888ec","7226f8a2-c542-471a-8d9e-e0df527325d3","86b4fa22-f6f1-4ca5-8fe4-8788f9b3fd89","5d03766c-9480-43f2-9e85-461a44c821d4"],"platforms":"windows10","technologies":"mdm"},{"id":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","displayName":"MIME to MAPI Conversion","description":"Microsoft Outlook 2016\\MIME to MAPI Conversion","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","displayName":"Device and Resource Redirection","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Device and Resource Redirection","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2af24920-f611-4f03-99a6-205773869ae6","displayName":"Protected Content","description":"Microsoft Edge Protected Content","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","displayName":"Contact Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Contact Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2b3d275d-4a48-4ac8-9c14-4dc5aa20a80b","displayName":"Network Sharing","description":"Administrative Templates Network Sharing","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2b54b208-5459-4e40-8db1-002cb90495bc","displayName":"Windows Memory Leak Diagnosis","description":"Administrative Templates Windows Memory Leak Diagnosis","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","displayName":"Printers","description":"Administrative Templates\\Printers","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2c156b7e-99c8-4a21-a828-4f9b94479b0d","displayName":"Time Zone","description":"Managed Settings Time Zone","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","displayName":"Threats","description":"Administrative Templates Microsoft Defender Antivirus Threats","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","displayName":"Applications","description":"Microsoft Edge Update\\Applications","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":["3bb9ca38-645e-479c-ac5f-01959aec9c30","7b91ab31-7ed5-4de9-bd49-d04303fd3c74","13f62499-a266-42c8-a4dc-531efcea55cb","797ac384-f48e-4567-b931-33a6ce923b94"],"platforms":"windows10","technologies":"mdm"},{"id":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","displayName":"Passcode","description":"Declarative Device Management (DDM)\\ Passcode","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"2d5a483f-b408-426d-9234-2883eae20afb","displayName":"Tools | Options | General | Web Options...","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["8ee1d8d2-582f-401b-927a-993016f4290d","0775f21c-9ca1-446d-b1dc-3cea45f15605","eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510","025c640e-51e2-4f04-85e3-a13f30b5e08c"],"platforms":"windows10","technologies":"mdm"},{"id":"2d6891a4-ee83-4e55-8e23-09513e1306e4","displayName":"Microsoft Office Document Cache","description":"Microsoft Office 2016\\Microsoft Office Document Cache","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","displayName":"Kerberos","description":"Administrative Templates Kerberos","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2e3f0407-6387-41b4-b6c2-ada4354be759","displayName":"Licensing Settings","description":"Microsoft Office 2016 (Machine)\\Licensing Settings","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2ea63962-4cac-4a5c-9181-e6a364489db0","displayName":"Security","description":"Microsoft Visio 2016\\Visio Options\\Security","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["f34e3da0-b440-43dc-a368-4fd39646a9c5","253fda23-118b-48c7-b24a-27b8c93df41a"],"platforms":"windows10","technologies":"mdm"},{"id":"2eed22da-106f-4c93-9a45-5ce803b50233","displayName":"Offline Editing","description":"Microsoft Visio 2016\\Visio Options\\Save\\Offline Editing","helpText":null,"parentCategoryId":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f524350-1bdb-4eee-a96d-b656bc2b0d70","displayName":"Sudo","description":"Sudo","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"2f524350-1bdb-4eee-a96d-b656bc2b0d70","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f56761a-8e8b-4788-a589-a73ab91818e6","displayName":"Web Archives","description":"Microsoft Office 2016\\Web Archives","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f6205e9-8680-4b8f-97f3-be12e252e038","displayName":"Track changes and compare","description":"Microsoft Word 2016\\Word Options\\Track changes and compare","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f85405a-7472-44ce-8c05-b59bb54912d5","displayName":"Playback","description":"Administrative Templates Windows Media Player Playback","helpText":null,"parentCategoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","displayName":"Trusted Locations","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2fbb7677-651a-4b62-8b8c-d502ea29936b","displayName":"E-mail Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["897675f9-0d1b-437b-ba0a-584fbd54df95","71f4af65-b7fa-4c54-bf73-19b0c7ffe162"],"platforms":"windows10","technologies":"mdm"},{"id":"304a579b-ff3b-4897-8bb8-5a1dda45356f","displayName":"Schedule options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\Schedule\\Schedule options for Microsoft Project","helpText":null,"parentCategoryId":"db47f067-f435-4095-8b98-aa3805bc0050","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","displayName":"Background Intelligent Transfer Service BITS","description":"Administrative Templates Background Intelligent Transfer Service BITS","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"30da5d88-cf03-41f4-ab55-51ead91b3844","displayName":"Trust Center","description":"Microsoft Publisher 2016\\Security\\Trust Center","helpText":null,"parentCategoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"31070051-859e-4d27-9df3-c07b8a2d2179","displayName":"Word Options","description":"Microsoft Word 2016\\Word Options","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["89be4acb-fdf9-447b-ad16-9a5af1d68b8b","ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","83087772-6560-4488-a1c5-bb6e4889e868","dc049161-17c6-411e-906b-a871b33651cd","bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","2f6205e9-8680-4b8f-97f3-be12e252e038","f9e53433-d8d9-4eaf-bdf3-d32de60d686e","7f07427b-9bc2-4bfc-a74e-1a1d8961bd89"],"platforms":"windows10","technologies":"mdm"},{"id":"311e1dac-a77c-4bc0-a376-35ad55923b7d","displayName":"Start","description":"Start","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"31d3b4c4-767e-403a-834c-51f3691bbf2b","displayName":"Security Center","description":"Administrative Templates Security Center","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"320ccaa3-a391-4d29-a9c4-594561f4104d","displayName":"Miscellaneous","description":"Microsoft Word 2016\\Miscellaneous","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["b206e4ef-a288-4fb7-a7ee-4a30b4df3b98"],"platforms":"windows10","technologies":"mdm"},{"id":"32180186-7378-4d45-b0cc-c533a124bdbc","displayName":"Access- Denied Assistance","description":"Administrative Templates Access- Denied Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","displayName":"General","description":"Microsoft Project 2016\\Project Options\\General","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["501e47c0-6c18-4a88-9366-adc0bbc2c9b4","0a6bc3ed-c4cd-4928-bcbf-247369a51515"],"platforms":"windows10","technologies":"mdm"},{"id":"32b20540-8fe9-4730-a4b0-ff41f6b13a97","displayName":"Windows System Responsiveness Performance Diagnostics","description":"Administrative Templates Windows System Responsiveness Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","displayName":"Microsoft Office 2016 (Machine)","description":"Microsoft Office 2016 (Machine)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":["712d184f-d9ac-45fc-9eea-aade3a22b55e","86dae9f9-7eb1-4566-8558-b63fa2e20fee","8c879ddf-7acf-45f3-81d3-2c78c7a1321b","f0190b73-0d5c-410e-bce1-e03aa1f62ed4","5d8272e2-1ed3-4a8d-9555-9a87fa13d078","2e3f0407-6387-41b4-b6c2-ada4354be759"],"platforms":"windows10","technologies":"mdm"},{"id":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","displayName":"","description":"Administrative Templates","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"33a43c22-104b-4683-995b-5652cfd5b490","displayName":"Windows AI","description":"Windows AI","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"33a43c22-104b-4683-995b-5652cfd5b490","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"33b9194b-4027-4c23-b662-52f25db7f839","displayName":"International","description":"Microsoft Access 2016\\Application Settings\\International","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"33fb4f49-5c7f-472c-a0f3-e05646a55902","displayName":"Improved Error Reporting","description":"Microsoft Office 2016\\Improved Error Reporting","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"343eb575-3ac8-4da9-b66d-ce84b84be7c3","displayName":"Project Guide settings","description":"Microsoft Project 2016\\Project Options\\Interface\\Project Guide settings","helpText":null,"parentCategoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3453c694-bc38-4082-9d3d-886e385df927","displayName":"Event Viewer","description":"Administrative Templates Event Viewer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","displayName":"Window Frame Coloring","description":"Administrative Templates Desktop Window Manager Window Frame Coloring","helpText":null,"parentCategoryId":"d52dd970-febb-4891-8eb7-1c8616cfb6cb","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"34c07941-8f52-43ad-b0ca-a7284655afb4","displayName":"Office.com Sharing Service","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Office.com Sharing Service","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3503e1ba-8168-4b55-92b1-84613292cadc","displayName":"Advanced","description":"Microsoft Excel 2016\\Excel Options\\Advanced","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["b90fb0dc-b8c1-4fc3-b9f9-dfbda4b3f03d"],"platforms":"windows10","technologies":"mdm"},{"id":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","displayName":"Editing Languages","description":"Microsoft Office 2016\\Language Preferences\\Editing Languages","helpText":null,"parentCategoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["60ea21c6-4c2b-4510-83f4-3a2d04fd99a0"],"platforms":"windows10","technologies":"mdm"},{"id":"3588f84a-69de-4900-910c-09a5b69e5d99","displayName":"Virtualization Based Technology","description":"Virtualization Based Technology","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3588f84a-69de-4900-910c-09a5b69e5d99","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"35f245bd-8d1f-424c-83de-a80be27a6a4e","displayName":"Desktop Alert","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options\\Advanced E-mail Options\\Desktop Alert","helpText":null,"parentCategoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"361859d9-1382-47c3-b9ec-9251a62fbb25","displayName":"Time Machine","description":"User Experience > Time Machine","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","displayName":"System Policy Control","description":"System Policy","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","childCategoryIds":["763525a0-8456-4336-a8d1-392253e8fdd8","64538726-8745-4e7a-b370-332f725b58bf"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","displayName":"Removed policies","description":"Google Google Chrome Removed policies","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"364787de-93e4-4fd6-9608-dce1ad8f88c2","displayName":"Windows Remote Management Win RM","description":"Administrative Templates Windows Remote Management Win RM","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["0f6d725e-2c2d-4926-8e78-3d2d5867eef5","b83cafe6-7d8b-4e3b-890d-ce50e548cfc6"],"platforms":"windows10","technologies":"mdm"},{"id":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","displayName":"Google Chrome","description":"Google Google Chrome","helpText":null,"parentCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":["70498fad-5ddb-4730-8130-d755ff675760","5900ac65-f656-459c-bd82-1329a862544d","a5a38799-7bf1-4b83-86fe-62729cd9ed9d","216de445-a80d-4981-b151-3b4466edc808","4cd10f38-02cf-40f2-aa87-ad70a2190a1a","d4ad9168-8c49-45d6-a7e5-86ba990fff3e","8c35f124-e249-43e3-9044-ecc0b0a5855a","d9432f48-3072-4171-9031-4ebead394151","ac821e49-1996-4d6c-99d4-9c3c3e4737b6","fa2722a8-dcfd-4e14-a429-2b0041642c77","b46f4e70-d3d1-4177-8e22-62f806d4568c","10247787-95ea-4507-93de-dbd166df12b5","098942c3-afe3-40c8-823f-37f0b5b13ad4","62499519-97eb-43e7-ae96-d7909c5820d3","3634c01b-1a85-4f50-9f52-63bc10bf0e39","148a6f4e-8816-4c00-87a3-57481c85c331","4aa852ab-6269-4883-906f-0a0944fa1261","f66e6bf2-a437-4d36-b46c-e965b31a5d4f","da78ddbc-fc94-48f9-8808-4b160d6f1d50","1d6d392c-8b32-459b-b114-af964a4bbbc5","895e0884-6b60-4bb0-b2ab-3a1642103db7","b811c4fe-7ff0-4bd1-a454-0918d4e2f896","463e6791-7d54-4964-a36b-63bbedb7d0cd","f00e9baf-9bbf-48e4-aaac-57410730f016","59d29716-55b0-4014-a458-38b408ff9530","b485695b-0fae-41ae-861c-3030769b28df","5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","f7486553-9e63-4d63-9423-56e5ffe48700","93ed2300-658d-40f3-8211-9295a240579c"],"platforms":"windows10","technologies":"mdm"},{"id":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","displayName":"Trust Center","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"85810387-3320-4056-bae2-953beeb246f7","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["42ce9a9b-0574-4b5c-993b-7679de80be47","4d69af55-f100-45fa-92e1-56d46434c647","76ad3567-c6cb-43b5-b91d-a52a34853c03"],"platforms":"windows10","technologies":"mdm"},{"id":"395a548d-737b-41fe-8449-c68c51e3a349","displayName":"Input Panel","description":"Administrative Templates Input Panel","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"39e4c352-be9c-4e75-8111-8236279c7f1e","displayName":"Cloud Desktop","description":"Cloud Desktop","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"39e4c352-be9c-4e75-8111-8236279c7f1e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3a901a80-e2b6-470c-9658-d66ba5458370","displayName":"Remote App and Desktop Connections","description":"Administrative Templates Remote Desktop Services Remote App and Desktop Connections","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","displayName":"Certificate management settings","description":"Microsoft Edge Certificate management settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","displayName":"Scheduling options for 'Project1'","description":"Microsoft Project 2016\\Project Options\\Schedule\\Scheduling options for 'Project1'","helpText":null,"parentCategoryId":"db47f067-f435-4095-8b98-aa3805bc0050","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","displayName":"Account Management","description":"Account Management","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b64e99d-0359-4264-be38-c544c647f493","displayName":"Sleep Settings","description":"Administrative Templates Power Management Sleep Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b7e16e7-171f-4169-8904-c8483b06700d","displayName":"Custom","description":"Microsoft Excel 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","displayName":"Password manager and protection","description":"Microsoft Edge\\Password manager and protection","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"3bb9ca38-645e-479c-ac5f-01959aec9c30","displayName":"Microsoft Edge","description":"Microsoft Edge Update\\Applications\\Microsoft Edge","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3bbaff1b-7d59-4b9c-ab53-c235d72b2fb0","displayName":"Protection From Zone Elevation","description":"Administrative Templates Internet Explorer Security Features Protection From Zone Elevation","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3c46dc04-e649-41b9-be99-04b771303fdd","displayName":"eSIM","description":"eSIM","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3c7f15ef-a539-411c-93f1-5f97b7bd5519","displayName":"Bluetooth","description":"Managed Settings Bluetooth","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"3ccd987e-bfca-4838-98ea-576de34b3ebe","displayName":"Certain Hours","description":"Certain Hours","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3ccd987e-bfca-4838-98ea-576de34b3ebe","childCategoryIds":[],"platforms":"android,iOS","technologies":"exchangeOnline"},{"id":"3db7e884-6077-4b96-ace3-005a6b49ecc0","displayName":"Hyperlink appearance in 'Project1'","description":"Microsoft Project 2016\\Project Options\\Edit\\Hyperlink appearance in 'Project1'","helpText":null,"parentCategoryId":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3edb2860-b77b-4240-af16-fb34d45d6ba1","displayName":"Performance","description":"Microsoft Edge\\Performance","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"3f216590-fb12-4f8e-924f-2a6895d94126","displayName":"Folder Home Pages for Outlook Special Folders","description":"Microsoft Outlook 2016\\Folder Home Pages for Outlook Special Folders","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","displayName":"FileVault","description":"FileVault > FileVault","helpText":null,"parentCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"3f61a5fe-8508-44dd-bcf0-83273643026a","displayName":"Smart Screen","description":"Smart Screen","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","childCategoryIds":["20b71dc7-cf08-4534-9e52-d297dd071ca5"],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"3f693856-7cbb-4a1c-93be-0d05aa41059f","displayName":"i SCSI","description":"Administrative Templatesi SCSI","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["6c1d9109-e4d1-4718-a537-dd685464fdbe","ca1aedf4-b951-45f5-a77c-dec776a82e21","60ea8de3-bc6d-4b01-974a-a53860fe4ef6"],"platforms":"windows10","technologies":"mdm"},{"id":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","displayName":"Internet Control Panel","description":"Administrative Templates Internet Explorer Internet Control Panel","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["822bd634-4d01-486e-adad-8085968fd1c4","8d503574-f93a-4277-a30d-19895d46dd13"],"platforms":"windows10","technologies":"mdm"},{"id":"3f8986f3-195d-4ee5-ae8d-96a007b20883","displayName":"Windows Location Provider","description":"Administrative Templates Windows Location Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3fa63a9d-e22d-4fc8-8464-a13b56461115","displayName":"Predefined","description":"Microsoft Excel 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3fbd3b29-bafd-4adf-89e4-3be612dee275","displayName":"Network settings","description":"Microsoft Edge Network settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"4086190d-2e5b-439d-8426-08492ebb8c9f","displayName":"Local Machine Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Local Machine Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","displayName":"Disk NV Cache","description":"Administrative Templates Disk NV Cache","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4124fc05-5c98-4790-a2a9-4ba2dee3d9b3","displayName":"Explorer Frame Pane","description":"Administrative Templates Explorer Frame Pane","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"41ba590e-9105-4eda-92fb-13c7d34b8eee","displayName":"DC Locator DNS Records","description":"Administrative Templates Net Logon DC Locator DNS Records","helpText":null,"parentCategoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","displayName":"Application Compatibility","description":"Administrative Templates Application Compatibility","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"428f107c-2167-4bc2-9293-8f1d6728a0c5","displayName":"Scan","description":"Administrative Templates Microsoft Defender Antivirus Scan","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","displayName":"AirPrint","description":"Printing > AirPrint","helpText":null,"parentCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","rootCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"42a6198f-bdec-402e-b619-315400b65488","displayName":"Software Update","description":"Declarative Device Management (DDM) Software Update","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"42ce9a9b-0574-4b5c-993b-7679de80be47","displayName":"Protected View","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","displayName":"Telemetry Dashboard","description":"Microsoft Office 2016\\Telemetry Dashboard","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","displayName":"SharePoint Lists","description":"Microsoft Outlook 2016\\Account Settings\\SharePoint Lists","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43057320-7058-46d5-86f9-a56c80bbf8b9","displayName":"Private Network Request Settings","description":"Microsoft Edge\\ Private Network Request Settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","displayName":"Microsoft Edge - Default Settings (users can override)","description":"Microsoft Edge - Default Settings (users can override)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":["a877a2ff-f144-421f-814c-593e972a8a20","fea97af7-df89-4fde-8e2b-f8e7f7b6b741","6f1386e5-148d-4dc3-84d1-79df721e3233","1653fa6c-aa99-4918-92c7-1df85d8843e1","8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","48965ad9-3011-4722-855b-7179fef89954","b96b63eb-0292-4a73-85d7-c68d330c109e","7db75ddb-f702-49f8-ae2b-991d1afd2d17","acabc66f-5faf-4a13-af32-322ccfc1a5b3","1ccd3115-55e7-464f-9bb9-d38a92191306","6fafeb5c-65ce-4993-b421-46e60da69131","a7b038e5-3af5-41fe-919e-e8befe83a9a5","0d4cf1d9-d8ad-4628-bd71-fa0de6598f28","6b71fbf6-7156-471a-b488-3eece04bda86","04b46099-4ee5-4def-8e04-569c988057a9"],"platforms":"windows10","technologies":"mdm"},{"id":"439f715e-5511-44fd-9a0f-644ba7cc6baf","displayName":"Logon","description":"Administrative Templates Logon","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43eca758-22c0-4625-8f12-85a8a34ea8b1","displayName":"Windows Logon Options","description":"Administrative Templates Windows Logon Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43fc9dcc-1e66-4108-bded-2d005eeb7ccb","displayName":"Microsoft Edge WebView","description":"Microsoft Edge Update\\Microsoft Edge WebView","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"441d6cc4-e51f-453e-a44d-8394509415be","displayName":"Predefined","description":"Microsoft Publisher 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"9caa3b08-b545-4c21-a3b7-b5d2302c1a81","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"444409a4-8b03-402d-91d0-1cd9565fb0fb","displayName":"Windows Color System","description":"Administrative Templates Windows Color System","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","displayName":"Business Data","description":"Microsoft Office 2016\\Business Data","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["a6e0cee7-34a0-4ca2-b4da-f819a057b532","952f69c8-2644-48df-976b-01fd624cbb3a","c72d9f00-d625-43ec-add4-514891035839"],"platforms":"windows10","technologies":"mdm"},{"id":"44774d3d-387b-4fa7-8de4-d82b039c06d1","displayName":"Display","description":"Microsoft OneNote 2016\\OneNote Options\\Display","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"449201b6-5002-42d1-85ed-d288fb6552da","displayName":"Smart Documents (Word, Excel)","description":"Microsoft Office 2016\\Smart Documents (Word, Excel)","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","displayName":"Internet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Internet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"44e27b70-4bdb-4aec-a75d-0568a1edc332","displayName":"Predefined","description":"Microsoft Word 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"740e7a10-3774-4a1c-9970-6907e0f0b848","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4560c525-12a1-4536-9cca-338330e58389","displayName":"Add-on Management","description":"Administrative Templates Internet Explorer Security Features Add-on Management","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"45a89c1f-0a34-4f78-b28f-d30b623fa423","displayName":"Identity and sign-in","description":"Microsoft Edge\\ Identity and sign-in","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"45d15759-2add-40db-9294-d1b391515dba","displayName":"Folder Redirection","description":"Administrative Templates Folder Redirection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","displayName":"Carddav","description":"Accounts > CardDAV","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"463e6791-7d54-4964-a36b-63bbedb7d0cd","displayName":"Microsoft Active Directory management settings","description":"Google Google Chrome Microsoft Active Directory management settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"46af3391-ed6d-4ada-aef7-02dac2a1b136","displayName":"Xsan","description":"Xsan > Xsan","helpText":null,"parentCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","rootCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"46eaa2b7-341b-4e39-be21-c3ea09dd5778","displayName":"Microsoft Edge Web View2 Runtime","description":"Microsoft Edge Update Microsoft Edge Web View2 Runtime","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"476e0bfc-ddb6-4612-8446-bed86e875141","displayName":"Fault Tolerant Heap","description":"Administrative Templates Fault Tolerant Heap","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"478ed057-8ee7-4dd2-8276-06dad8f85397","displayName":"Services","description":"Microsoft Office 2016\\Services","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["a5607145-2bd3-4473-a8ee-d7fa5c2f2675"],"platforms":"windows10","technologies":"mdm"},{"id":"479c2edd-6539-4e1d-96ba-518d6f6264c3","displayName":"Container and Directory Naming","description":"FS Logix Profile Containers Container and Directory Naming","helpText":null,"parentCategoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"486f25cc-c865-446e-95b2-c5b061883a7a","displayName":"I Pv6 Transition Technologies","description":"Administrative Templates TCPIP Settings I Pv6 Transition Technologies","helpText":null,"parentCategoryId":"785c6df2-c6d0-4d6e-bd73-c3b62caca754","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"48965ad9-3011-4722-855b-7179fef89954","displayName":"Games settings","description":"Microsoft Edge - Default Settings users can override Games settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"48b8705b-58a8-4504-ab7a-2704980f4577","displayName":"Microsoft Defender","description":"Microsoft Defender","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":["93099bd4-c685-434b-9d72-f0cb6db5e753","a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","22a2a407-0f28-481d-bdbe-1f9cb6d589c3","64c8233f-3057-4485-b902-d71a312318d7","d2191717-e304-46f7-bcc0-55e6477026c9","0e1122f8-2bbf-475b-bce0-9e43a2f5e475","13467142-14e7-4380-8573-4866e842c7f6","269c487f-8902-486a-88dd-db9b9b4454b8","d40a32e1-ab3e-4cbc-aa03-4766792e563e","67cd904c-78e0-4e77-9dd4-c713b21763f3","b77a3a7b-6fab-4240-b5c3-852aa78781d5","5c4df3be-80b0-40cc-a8c8-0258120b0de5","20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a"],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"48be5f9d-4941-4189-8015-dd78f87aacd5","displayName":"Administrative Templates","description":"Administrative Templates","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["27087ae6-d02f-4b54-a143-6cde89c04989","6c7168c3-6f34-4086-af0b-ed0b74301dc9","7f363efe-1ea5-4eb8-baf7-8c34456b43fc","736134cb-4d82-427a-97b7-d219ac6a22f0","40c593b9-63cf-4b10-ad26-1ceb7c9491fe","005ddf8f-da22-4b23-ab02-289f8f6c7960","b3b2fc04-4b88-4a1c-8370-04573019eebe","9dbd66e3-4544-4ca8-a118-272c874bc684","e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","1ed9f90e-d8b6-413f-bfc2-face955141bc","476e0bfc-ddb6-4612-8446-bed86e875141","c6a912c5-0334-40fb-8dc5-f2d2547b8071","18b972fd-74f2-4345-9449-087c80dd38a3","19ab385f-14f5-47cd-87b2-f4784eedcdd9","2b54b208-5459-4e40-8db1-002cb90495bc","75e080fb-3ed7-4a73-a6e0-eb93f0119d68","88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","643081a4-132d-463e-9d86-c8650cb2a011","0937f5ff-aabc-49a9-a94f-6f98c4702580","86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","b6d13875-fd8e-41a0-a712-3dab8b75b93f","76bbc368-9d0b-4aa7-b8e2-2dcfd864b9ee","5be35eeb-62e9-4317-8804-018a9dd31149","dd9a3dad-5851-4899-a5c1-c23318986846","9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","6424714c-e50a-4b53-acbf-8739825ebf0b","902f5df1-31d6-44ee-ba95-2561199db35f","785c6df2-c6d0-4d6e-bd73-c3b62caca754","94a92db4-8704-487b-b0c5-c15d6ac20e6d","788355e5-e113-4b17-ada9-fb5ef38bffa1","58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","72972c43-36a3-4034-8cc8-334c99087798","dab7104a-b79c-4318-afb0-5d5cfed9caa9","dc16dbf0-aac8-4ff3-a546-1ddb55650f47","05305a87-0b19-41bb-bf1e-0bd92bfcdc16","03a966f7-8f8e-4ecb-aab3-055fe907f5ab","5c9a2f21-d3a8-4295-a803-e0535aa29489","60b898a9-0490-4599-b7f1-3cd451236266","8c30a64e-ad24-47a0-97a8-52320360fd88","b524d6e2-75bc-4409-ae3d-07605707d7ee","a34ade49-964d-407c-9f60-2e8cd9dfef05","87667b72-85ce-48c2-8023-e6db7f5fe739","99b4ac32-50b5-4659-a7a1-94bc708ae71a","1dabc7da-bdf8-4c60-95de-427a4b2cb6bf","e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","edd1e620-09e1-47ea-abc8-1e241a174ed9","b40cfb22-8f17-4317-bcbb-c1c871497446","d982a1ef-84be-4832-99d4-8b71a4644b74","24b30053-14d2-4430-9966-281e926a6918","53ba922e-db4d-489c-b5ab-dbc4b8321206","cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","e3ca94a7-e506-4133-8fae-41931dc863a5","c859dc1a-fdeb-4591-af97-79d078ee715b","5133d5ea-1a12-494f-afb2-5cfaf41d9518","9aaa7ee2-727d-426f-8a2b-6b10a4cd084f","f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","f69e6993-2e88-4938-bfe5-cea9ab21a858","be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","0d37dddd-6575-485c-92dd-37a3c23edbf9","5536b5f4-3d31-4290-acea-9bef323bb83d","d52dd970-febb-4891-8eb7-1c8616cfb6cb","68a3b82d-d1f4-422d-bfee-2168ec260ad7","1851afa1-5177-4268-8dfc-5b5e1a17ff7f","3f8986f3-195d-4ee5-ae8d-96a007b20883","6bed088c-c9b0-4149-b26f-df0c247cdb5b","7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","4dd8280d-6c01-4a06-bfd1-e1cb4c529494","a7e7529f-1030-41da-8b4d-024e1c08bbac","4124fc05-5c98-4790-a2a9-4ba2dee3d9b3","b6bb653a-73f0-42f4-b097-1ce556310904","abf781d7-1179-4f24-8d01-5611db14eddc","ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","43eca758-22c0-4625-8f12-85a8a34ea8b1","5371d50c-0aaa-425a-a075-2cb1c59968b9","be9bdbec-b52e-4174-9c5b-cf765dee855b","8eed5d21-a5e9-4bc7-b2df-4526af3e2726","a57b27b6-48e0-42b2-812a-2be86c113a0c","99ba9e42-9872-4a03-a615-fc4a4cebc067","d0e46713-238c-42b7-a996-653cf952c367","d9f5ccc9-5180-43b7-9c81-89ac3364ce00","07c023d3-0899-40af-a04f-805876d99a9b","8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","395a548d-737b-41fe-8449-c68c51e3a349","d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","daf3f2c8-f6a5-40bd-96b3-2c6a28931614","cebd5934-9dfe-4278-966d-b9d880cb30e7","3f693856-7cbb-4a1c-93be-0d05aa41059f","2de362c7-2c4a-4b24-bda3-f82cb6ed5990","c48917c1-fd99-405f-b1d2-9dfec169e5d8","fe3cb879-8869-4163-91d7-e432abd75da8","3334730b-b9f7-4c99-bde8-57f6b2cd826f","f14fcb64-a868-4531-a3b4-c3cdf03c2b99","3453c694-bc38-4082-9d3d-886e385df927","cc13d92c-673f-4af7-9748-50342fc8795a","31d3b4c4-767e-403a-834c-51f3691bbf2b","32180186-7378-4d45-b0cc-c533a124bdbc","4d36a1f3-29f9-45af-9480-32891a0bf8ef","290ec637-e780-4e95-9834-6368ac0437d1","909339a5-8f04-4fa2-8807-5d38c83ef547","1943deba-33f7-4c3d-98c8-6b5319ec98ab","50e243ad-0e21-43f5-b5dc-31ec61ee43d0","6f0e6df6-8654-4b57-b1d5-2160c5a0a54e","4beed579-3d9c-4c6d-9e88-e7df5e2b4613","c9a65baa-de10-4818-97a2-b61babb28060","f926f6e3-1bd6-4259-ae7c-e14108568882","93c28398-faef-4ca5-9667-f5ed004da32c","023e0367-b563-4fae-8fb6-589c836ee223","56fdfd66-f34d-4bf8-b951-f130114ffb3d","2b3d275d-4a48-4ac8-9c14-4dc5aa20a80b","e042b102-b12c-48d1-86ef-f6d296da5b95","cef993dc-bf18-44f7-8e9f-465ef1a0f144","dbb76878-34a9-4f87-bbc6-4de7ea223ff4","364787de-93e4-4fd6-9608-dce1ad8f88c2","c01c7d3f-ace1-48bf-abce-e8a02ba877ab","2461b964-02f6-4da2-921a-f7e8f868c69d","088b8d8d-5f3f-4979-aa18-b3c4b2616a24","b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","e972d9fe-a9b7-4a65-a88f-0958fab19584","425669eb-3a49-43d1-98a5-0fcc5b04ffcb","12ec8efa-2dcc-4c0c-9166-72ecc3cd463e","f1278d6b-60ec-4369-88cf-21df47caaec6","6b87c5da-cfd9-44bc-be05-ed08eb2144c7","444409a4-8b03-402d-91d0-1cd9565fb0fb","30918d48-dafd-4b25-be63-70f6c7ba8a3d","6cd02266-a42f-4675-b83e-37360dbf3c68","45d15759-2add-40db-9294-d1b391515dba","2becddf1-d8ea-49ec-8560-c8c401faa9bb","930d2960-3f70-48ca-9ead-b65a5a037c07","156f2e6a-6638-4749-9f43-e7acc4aba762","e6b767af-2ce1-4c91-9360-15abbb0bf3bc","ffd1a98f-0fac-47fe-813f-7510d0dacbc3","ac0a894c-173a-48fc-b961-901f28463c77","634e4243-284b-4cb7-a7e6-08ca7e262937","f3027ba5-9a2f-42c6-9872-ec21f726929c","98dc5bd0-2b16-4263-ba2f-62115b680017","cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","d4c9d046-a8c0-46f0-bd62-bc4d1614e891","6d4184ab-a66c-47f1-b54e-af55f654e2a5","7d331987-7e2d-4975-b23b-d99a5af26ddf","6e1431f2-131e-4cf2-bb60-87b889f1d11b","439f715e-5511-44fd-9a0f-644ba7cc6baf","5dcea340-0469-4f43-b270-a49ed0597201","ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","60b55db1-53fc-45ea-93d3-e4372b1e19a5","90e3acc6-80d5-41b4-8141-a8620a211c0e","32b20540-8fe9-4730-a4b0-ff41f6b13a97","76c53aab-0288-4ac1-b399-0104e04c6457","9b894b32-3697-4a83-9731-3db2a35455ad","ad47f904-ede2-4b12-849e-bf751d88abf5","86e78a4b-706a-4ec8-be90-439461abb29d","751cf9ec-7214-4b38-a09e-24922684bd8f","fff51673-04b8-4277-98ef-4baffbd8d192","e50acc0f-d177-4803-aa31-fc97eeb60ff2","fe65603b-1980-446b-ae17-516eb885c6be"],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"48cb2bee-74be-4165-bc19-89c5b1c50c00","displayName":"Email","description":"Email","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","displayName":"Time Language Settings","description":"Time Language Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","displayName":"Firewall","description":"Firewall","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"4a6c4488-bbcf-4b5b-9156-7aa1b10a6010","displayName":"DNS Proxy","description":"Declarative Device Management preview Network DNS Proxy","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"4a7b0e92-ba43-46aa-96e8-c5839dbcb524","displayName":"Note Flags","description":"Microsoft OneNote 2016\\OneNote Options\\Note Flags","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4a832199-a841-4b6a-84fa-51365902a742","displayName":"Places Bar Locations","description":"Microsoft Office 2016\\File Open/Save dialog box\\Places Bar Locations","helpText":null,"parentCategoryId":"92be4fc7-8095-441c-b52b-9861c21bc337","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4aa852ab-6269-4883-906f-0a0944fa1261","displayName":"Allow or deny screen capture","description":"Google Google Chrome Allow or deny screen capture","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","displayName":"Customizable Error Messages","description":"Microsoft Office 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4b540860-0858-48f4-8830-18383bb1766f","displayName":"Licensing","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Licensing","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","displayName":"Scripts","description":"Administrative Templates Scripts","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4c604a0e-9339-4c01-9536-b689bd0abe5f","displayName":"Remote Desktop Connection Client","description":"Administrative Templates Remote Desktop Services Remote Desktop Connection Client","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","displayName":"DSCP value of conforming packets","description":"Administrative Templates Qo S Packet Scheduler DSCP value of conforming packets","helpText":null,"parentCategoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4cd10f38-02cf-40f2-aa87-ad70a2190a1a","displayName":"Protected Content","description":"Google Google Chrome Protected Content","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","displayName":"Credentials Delegation","description":"Administrative Templates Credentials Delegation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4d69af55-f100-45fa-92e1-56d46434c647","displayName":"File Block Settings","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4dae3032-1f16-4ace-911b-a957db0b8089","displayName":"AutoFormat as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type","helpText":null,"parentCategoryId":"dc049161-17c6-411e-906b-a871b33651cd","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["62492a4c-fd70-4275-ae5e-d60e200e3553","b6cafb2c-81be-40cf-90d8-788f713f7099","e8ce968b-91cb-4301-ba98-b37d42bc5213"],"platforms":"windows10","technologies":"mdm"},{"id":"4dd8280d-6c01-4a06-bfd1-e1cb4c529494","displayName":"Wireless Display","description":"Administrative Templates Wireless Display","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","displayName":"Customize","description":"Microsoft Office 2016\\Global Options\\Customize","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["13123148-c522-437f-b316-d78f5cc0d28d"],"platforms":"windows10","technologies":"mdm"},{"id":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","displayName":"RSS Feeds","description":"Microsoft Outlook 2016\\Account Settings\\RSS Feeds","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e4deef0-4528-47d5-8869-4143c506f18b","displayName":"Custom","description":"Microsoft Visio 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"c67c9e69-6e69-4b63-868c-3b3df5d17e47","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e62ada2-f091-49e1-99dd-ffdf5cf558cd","displayName":"General Options","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\General Options","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e8db19c-cb8e-4361-8849-1d435d50bb66","displayName":"Handwriting","description":"Handwriting","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4e8db19c-cb8e-4361-8849-1d435d50bb66","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f081af6-7b21-44fc-8dd9-d4e0a61a474d","displayName":"Control Policy Conflict","description":"Control Policy Conflict","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4f081af6-7b21-44fc-8dd9-d4e0a61a474d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f29ef5c-6ca0-4b09-893f-01755a670877","displayName":"System Services","description":"System Services","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4f29ef5c-6ca0-4b09-893f-01755a670877","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f671de2-9777-4969-acf3-8d90c733434c","displayName":"Escrow Certificates","description":"Microsoft Office 2016\\Security Settings\\Escrow Certificates","helpText":null,"parentCategoryId":"50b4bc60-802c-477a-9366-80e09154595f","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"500d2bb1-5186-447c-818f-401f2d9065ce","displayName":"Windows Logon","description":"Windows Logon","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"500d2bb1-5186-447c-818f-401f2d9065ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5011ca61-1a58-42da-9c66-7763236acc84","displayName":"Streaming","description":"Administrative Templates App-V Streaming","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"501b5a30-253c-48b7-ab40-de1d100e4358","displayName":"Microsoft Teams","description":"Microsoft Teams","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"501b5a30-253c-48b7-ab40-de1d100e4358","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","displayName":"General options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\General\\General options for Microsoft Project","helpText":null,"parentCategoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"508b2c0e-f572-4a50-93bf-566e5b827c0e","displayName":"Printers","description":"Printers","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"508b2c0e-f572-4a50-93bf-566e5b827c0e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"50b4bc60-802c-477a-9366-80e09154595f","displayName":"Security Settings","description":"Microsoft Office 2016\\Security Settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["4f671de2-9777-4969-acf3-8d90c733434c","512f133b-9d53-46b8-834f-52501f9b6527","efb8c441-bad5-4e2f-b07c-5ac299cf3d22"],"platforms":"windows10","technologies":"mdm"},{"id":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","displayName":"Lanman Server","description":"Administrative Templates Lanman Server","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"512f133b-9d53-46b8-834f-52501f9b6527","displayName":"Digital Signatures","description":"Microsoft Office 2016\\Security Settings\\Digital Signatures","helpText":null,"parentCategoryId":"50b4bc60-802c-477a-9366-80e09154595f","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","displayName":"Hardware Buttons","description":"Administrative Templates Hardware Buttons","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"517e55f5-729f-4b4d-9555-33baa95a0e5a","displayName":"Application Guard","description":"Microsoft Office 2016\\Security Settings\\Trust Center\\Application Guard","helpText":null,"parentCategoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"51e0cebb-cac4-4905-9b31-539295e4b85b","displayName":"Proofing","description":"Microsoft Publisher 2016\\Publisher Options\\Proofing","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","displayName":"Accounts","description":"Accounts > Accounts","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"522c3302-7a25-4904-a274-66cef9fd6aa0","displayName":"Microsoft Office","description":"Microsoft Office","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":["19ba782c-3594-45da-b829-72b54f6d45c7","b5169b74-41be-460a-9402-b13b6c22582b","191a84f2-13b5-4609-808f-8b743b7f0247"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"5261c543-0bf4-49a8-9657-45e2044420d1","displayName":"Messaging","description":"Messaging","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5261c543-0bf4-49a8-9657-45e2044420d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"526e363a-84db-4256-a13c-e01c8c646e26","displayName":"Idle Browser Actions","description":"Microsoft Edge Idle Browser Actions","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"52e76943-bfc9-4fb5-bdc8-5d4e8c6a436e","displayName":"Remote Remediation","description":"Remote Remediation","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"52e76943-bfc9-4fb5-bdc8-5d4e8c6a436e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5371d50c-0aaa-425a-a075-2cb1c59968b9","displayName":"MS Security Guide","description":"Administrative Templates\\MS Security Guide","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"53ba922e-db4d-489c-b5ab-dbc4b8321206","displayName":"Microsoft User Experience Virtualization","description":"Administrative Templates Microsoft User Experience Virtualization","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["5966d21b-220b-4937-9323-c6dd46cda942","c0ea0178-ad93-4596-94b2-9d7d1bbe8789"],"platforms":"windows10","technologies":"mdm"},{"id":"5401711f-292a-487a-be18-f99593a0477c","displayName":"Font","description":"System Configuration\\ Font","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","displayName":"Connections","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Connections","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","displayName":"Startup Home page and New Tab page","description":"Google Google Chrome - Default Settings users can override Startup Home page and New Tab page","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5536b5f4-3d31-4290-acea-9bef323bb83d","displayName":"Ctrl Alt Del Options","description":"Administrative Templates Ctrl Alt Del Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"55a61bb8-e023-4741-8213-99995c5902e5","displayName":"System","description":"Administrative Templates Event Log Service System","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"55c888df-44ff-49d1-808e-ad9cb8429aff","displayName":"Device Health Monitoring","description":"Device Health Monitoring","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"55c888df-44ff-49d1-808e-ad9cb8429aff","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"55eebd7c-beb9-48b6-907f-df4997e18bdb","displayName":"Predefined","description":"Microsoft Access 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"b8158968-c839-4d37-9eb8-887bd6fd7402","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"56c54112-2991-4bda-9e01-e6868bd07726","displayName":"Printer Provisioning","description":"Printer Provisioning","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"56c54112-2991-4bda-9e01-e6868bd07726","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"56e510be-ca39-46a2-9eb2-6f1af6d4b16a","displayName":"Browser","description":"Microsoft Word 2016\\Word Options\\Advanced\\Web Options...\\Browser","helpText":null,"parentCategoryId":"2108b443-384c-4bb3-9b9f-acb4a754a86a","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","displayName":"Branch Cache","description":"Administrative Templates Branch Cache","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"57514d69-d9b1-469a-9b54-b5e94320c2a1","displayName":"Windows Subsystem For Linux","description":"Windows Subsystem For Linux","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","childCategoryIds":["a787672d-4a33-455b-a2db-e340eb35a5c8"],"platforms":"windows10","technologies":"mdm"},{"id":"577d5951-fc56-4906-90bc-2c508c6611ad","displayName":"Microsoft Defender for Endpoint","description":"Microsoft Defender for Endpoint","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"577d5951-fc56-4906-90bc-2c508c6611ad","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"579d6272-8708-4b22-a352-89cbd705ca82","displayName":"Security","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Security","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","displayName":"Credential User Interface","description":"Administrative Templates Credential User Interface","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5838ed03-2902-4931-92cf-e349ab09c9b8","displayName":"PowerPoint Designer","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...\\PowerPoint Designer","helpText":null,"parentCategoryId":"af14a55b-d79b-4299-946c-b7582412b748","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","displayName":"General","description":"Microsoft Excel 2016\\Excel Options\\General","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","displayName":"Locked- Down Trusted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Trusted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5900ac65-f656-459c-bd82-1329a862544d","displayName":"Deprecated policies","description":"Google Google Chrome Deprecated policies","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5966d21b-220b-4937-9323-c6dd46cda942","displayName":"Applications","description":"Administrative Templates Microsoft User Experience Virtualization Applications","helpText":null,"parentCategoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","displayName":"Directory Service","description":"Authentication > Directory Service","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","displayName":"Trust Center","description":"Microsoft Office 2016\\Privacy\\Trust Center","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"59d29716-55b0-4014-a458-38b408ff9530","displayName":"Content settings","description":"Google Google Chrome Content settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5b1be2c5-9939-4b2e-b29b-b22069455c90","displayName":"Microsoft Save As PDF and XPS add-ins","description":"Microsoft Office 2016\\Microsoft Save As PDF and XPS add-ins","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","displayName":"FileVault Options","description":"FileVault > FileVault Options","helpText":null,"parentCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"5b832259-c30b-43bb-b249-9d3ea4d5b028","displayName":"Customizable Error Messages","description":"Microsoft Excel 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","displayName":"Group Policy snap-in extensions","description":"Administrative Templates Group Policy Group Policy snap-in extensions","helpText":null,"parentCategoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","displayName":"Application Guard settings","description":"Microsoft Edge\\Application Guard settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","displayName":"Edit","description":"Microsoft Project 2016\\Project Options\\Edit","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["d33133b4-77df-429a-9580-ed70f7da676d","06c4a76a-805b-4370-9d80-08e720ab2305","3db7e884-6077-4b96-ace3-005a6b49ecc0"],"platforms":"windows10","technologies":"mdm"},{"id":"5be35eeb-62e9-4317-8804-018a9dd31149","displayName":"Online Assistance","description":"Administrative Templates Online Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bf4c2ba-be08-4cda-bf33-d10707580d78","displayName":"Present Online","description":"Microsoft Office 2016\\Present Online","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["0be98651-a552-4470-b2dc-71c66a5ce1e6"],"platforms":"windows10","technologies":"mdm"},{"id":"5c4224e0-6a48-4665-9332-958d98124157","displayName":"File Block Settings","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","displayName":"Tamper protection","description":"Microsoft Defender Tamper protection","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"5c645a3e-bc39-44e9-8786-4c82e0553d22","displayName":"ODFC Containers","description":"FS Logix ODFC Containers","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":["0bae3158-5f75-4e25-acf4-859d2612f892","81eb92d0-acda-4ea2-8183-29ed5457276b"],"platforms":"windows10","technologies":"mdm"},{"id":"5c722b3f-9d77-428a-b859-3fb556162cd6","displayName":"Cellular","description":"Networking > Cellular","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"5c9a2f21-d3a8-4295-a803-e0535aa29489","displayName":"System Restore","description":"Administrative Templates System Restore","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","displayName":"Content Cache Settings","description":"Declarative Device Management preview Content Cache Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"macOS","technologies":"appleRemoteManagement"},{"id":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","displayName":"Auditing","description":"Auditing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"5cd6dc4f-b231-449f-bc10-16041b73356a","displayName":"Contact Card","description":"Microsoft Office 2016\\Contact Card","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["20bacabf-cd07-48be-a184-f0ae76d31e4a"],"platforms":"windows10","technologies":"mdm"},{"id":"5d03766c-9480-43f2-9e85-461a44c821d4","displayName":"Button Settings","description":"Administrative Templates Power Management Button Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d4e843b-2848-4508-9143-cb3217c2fe83","displayName":"RDP Shortpath","description":"Administrative Templates Windows Components Remote Desktop Services Remote Desktop Session Host Azure Virtual Desktop RDP Shortpath","helpText":null,"parentCategoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d8272e2-1ed3-4a8d-9555-9a87fa13d078","displayName":"Customize","description":"Microsoft Office 2016 (Machine)\\Global Options\\Customize","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","displayName":"Browser","description":"Browser","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"5dcea340-0469-4f43-b270-a49ed0597201","displayName":"Mitigation Options","description":"Administrative Templates Mitigation Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","displayName":"Other","description":"Microsoft Outlook 2016\\Outlook Options\\Other","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["f29a5e42-24f5-47fb-bdcf-9ed9418035ee","6535c74f-74ac-4713-9c7a-ae15f62e97aa"],"platforms":"windows10","technologies":"mdm"},{"id":"5e692f3e-1911-43b0-9192-64c2e65b7c10","displayName":"Education","description":"Education","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","displayName":"Downloads","description":"Microsoft Edge Downloads","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","displayName":"Microsoft Visio 2016","description":"Microsoft Visio 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["c67c9e69-6e69-4b63-868c-3b3df5d17e47","f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","d5b3cab7-d486-4f74-8525-6bd740b950bc","e6f727b7-f474-4010-b214-83149ffdac2b"],"platforms":"windows10","technologies":"mdm"},{"id":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","displayName":"Generative AI","description":"Google Google Chrome Generative AI","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","displayName":"OneDrive","description":"OneDrive","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5f048379-3a42-43f0-9fd5-d269f292aa35","displayName":"Workflow Cache","description":"Microsoft Office 2016\\Miscellaneous\\Workflow Cache","helpText":null,"parentCategoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","displayName":"Remote Session Environment","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Remote Session Environment","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["b7bde490-eac6-4f57-8808-e0786b8191a1"],"platforms":"windows10","technologies":"mdm"},{"id":"5f71c40e-01aa-42d2-9c8c-7d560126cd4b","displayName":"App Analytics","description":"Managed Settings App Analytics","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","displayName":"Trust Center","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["fe786056-6f4a-4d16-bff4-5fbb640308d2","c8cdd1a5-3f43-47c5-a775-d27bba4411f5","8391e79d-d618-47c3-979c-83544da43739"],"platforms":"windows10","technologies":"mdm"},{"id":"607a1c39-a3db-496f-8db6-c99d67f5f76c","displayName":"Tools | Security","description":"Microsoft Access 2016\\Tools | Security","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["a788a6e5-ab3f-41e5-96c8-ee59627dcb4d"],"platforms":"windows10","technologies":"mdm"},{"id":"60b55db1-53fc-45ea-93d3-e4372b1e19a5","displayName":"Shutdown","description":"Administrative Templates Shutdown","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60b898a9-0490-4599-b7f1-3cd451236266","displayName":"Microsoft account","description":"Administrative Templates Microsoft account","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","displayName":"Enabled Editing Languages","description":"Microsoft Office 2016\\Language Preferences\\Editing Languages\\Enabled Editing Languages","helpText":null,"parentCategoryId":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60ea8de3-bc6d-4b01-974a-a53860fe4ef6","displayName":"i SCSI Target Discovery","description":"Administrative Templatesi SCS Ii SCSI Target Discovery","helpText":null,"parentCategoryId":"3f693856-7cbb-4a1c-93be-0d05aa41059f","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","displayName":"E-mail Options","description":"Microsoft Word 2016\\Word Options\\Advanced\\E-mail Options","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"622c83ff-f780-47e6-8b9c-bf82552e3f04","displayName":"Scripted Window Security Restrictions","description":"Administrative Templates Internet Explorer Security Features Scripted Window Security Restrictions","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"623d41fb-000e-41d8-b955-373f8c700def","displayName":"Security","description":"Microsoft Project 2016\\Project Options\\Security","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["26dfd0a7-546b-4583-b0c7-85b98ac5a40c","cc50f179-0c39-4486-a555-de5a6e6ed365","1671dfc3-a1dd-4178-9093-10fb6b62586a"],"platforms":"windows10","technologies":"mdm"},{"id":"62492a4c-fd70-4275-ae5e-d60e200e3553","displayName":"Apply as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type\\Apply as you type","helpText":null,"parentCategoryId":"4dae3032-1f16-4ace-911b-a957db0b8089","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"62499519-97eb-43e7-ae96-d7909c5820d3","displayName":"Printing","description":"Google Google Chrome Printing","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","displayName":"Remote Desktop Session Host","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["5f28f9ff-58f8-43af-9692-3d06e083bbd9","579d6272-8708-4b22-a352-89cbd705ca82","b40b8f80-c0e6-4494-8085-f90cadc167a9","89ad0055-1603-420e-940d-9944a63e3da9","5454d0eb-7eaa-4500-a1fb-f69b76aed740","ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","f1455024-7de9-448f-8d8f-a42db2af0a35","4b540860-0858-48f4-8830-18383bb1766f","0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","2a1bbe00-0730-430e-8d19-3eec2fd6b63c"],"platforms":"windows10","technologies":"mdm"},{"id":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","displayName":"Security","description":"Security","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":["d68abc4d-559a-4339-be48-c41a77a87034","8abddb23-7036-4ba8-8912-529279a849ea","f4a8384f-9e4e-4fc6-9ee2-28fa5260347a"],"platforms":"iOS,macOS,windows10","technologies":"mdm,appleRemoteManagement"},{"id":"634e4243-284b-4cb7-a7e6-08ca7e262937","displayName":"Attachment Manager","description":"Administrative Templates Attachment Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"63b9904f-bbdf-4461-954a-c1d67fa8b357","displayName":"File Explorer","description":"File Explorer","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"63ca5d8b-829d-42c5-92e8-35f9ca47fb0e","displayName":"IMAP","description":"Microsoft Outlook 2016\\Account Settings\\IMAP","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"63e167a4-65be-4d34-9e9c-186466f2b064","displayName":"Troubleshooting","description":"Troubleshooting","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"63e167a4-65be-4d34-9e9c-186466f2b064","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6424714c-e50a-4b53-acbf-8739825ebf0b","displayName":"Personalization","description":"Administrative Templates Personalization","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"643081a4-132d-463e-9d86-c8650cb2a011","displayName":"Network Provider","description":"Administrative Templates Network Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"64538726-8745-4e7a-b370-332f725b58bf","displayName":"System Policy Managed","description":"System Policy > System Policy Managed","helpText":null,"parentCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","rootCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"64c8233f-3057-4485-b902-d71a312318d7","displayName":"Scheduled scan configuration","description":"Microsoft Defender Scheduled scan configuration","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","displayName":"Network Isolation","description":"Network Isolation","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"65087b94-7e45-4d74-a50d-df4377b67499","displayName":"Parental Controls Dictionary","description":"Parental Controls > Parental Controls Dictionary","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"652a676c-9d60-4c9a-88b6-823a24961a9b","displayName":"Copilot Settings","description":"Visual Studio Copilot Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","displayName":"Advanced","description":"Microsoft Outlook 2016\\Outlook Options\\Other\\Advanced","helpText":null,"parentCategoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["13eb248a-4549-4d23-9ada-23b40edf36bf"],"platforms":"windows10","technologies":"mdm"},{"id":"66395272-f132-4170-b88e-87f794f987f4","displayName":"File Locations","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\File Locations","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"66615d2a-fec9-47f1-8eaf-9813e30cc023","displayName":"Extensions","description":"Microsoft Edge\\Extensions","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"66c92e07-234b-4992-a081-9afe4c113ba3","displayName":"SCEP certificate","description":"SCEP certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"66c92e07-234b-4992-a081-9afe4c113ba3","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6730f0be-a129-4b48-942f-e4ddf69fee66","displayName":"Customizable Error Messages","description":"Microsoft Access 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"67cd904c-78e0-4e77-9dd4-c713b21763f3","displayName":"User interface preferences","description":"Microsoft Defender > User interface preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"67eb1dab-7805-41bb-af5a-798dc7e29f23","displayName":"Autocorrect Options","description":"Microsoft Excel 2016\\Excel Options\\Proofing\\Autocorrect Options","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"68237832-f376-4f0e-ba26-4e06fce7a35d","displayName":"Device Installation Restrictions","description":"Administrative Templates Device Installation Device Installation Restrictions","helpText":null,"parentCategoryId":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"686ae3dd-a663-4484-854e-8f8d578fe3b8","displayName":"Converters","description":"Microsoft PowerPoint 2016 (Machine)\\Converters","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"686ae3dd-a663-4484-854e-8f8d578fe3b8","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"68a3b82d-d1f4-422d-bfee-2168ec260ad7","displayName":"Portable Operating System","description":"Administrative Templates Portable Operating System","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"69931627-230d-4df9-bbef-e3eac64ea8ef","displayName":"Additional Actions","description":"Microsoft Office 2016\\Tools | AutoCorrect Options... (Excel, PowerPoint and Access)\\Additional Actions","helpText":null,"parentCategoryId":"8084033c-156a-4d1b-ab0b-159541810459","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","displayName":"Advanced","description":"Microsoft Publisher 2016\\Publisher Options\\Advanced","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["77b0357b-412e-4a81-9469-e20a5f1345fd"],"platforms":"windows10","technologies":"mdm"},{"id":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","displayName":"Save","description":"Microsoft Project 2016\\Project Options\\Save","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["dfd5d749-c68c-448f-ab3f-851c09f09df4","e13ec567-e29c-4ca0-b599-e8c43587f10a","d679b407-a753-40aa-bc9f-175f363b0eff"],"platforms":"windows10","technologies":"mdm"},{"id":"6ae0d607-832c-403b-b3bc-c563e390ebad","displayName":"Save/Open","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Save/Open","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","displayName":"Server Settings","description":"Microsoft Office 2016\\Server Settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["8e143bee-82fa-4e45-8bd0-c4032b0182d2"],"platforms":"windows10","technologies":"mdm"},{"id":"6b71fbf6-7156-471a-b488-3eece04bda86","displayName":"Printing","description":"Microsoft Edge - Default Settings (users can override)\\Printing","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","displayName":"Tools | Options | Spelling","description":"Microsoft Office 2016\\Tools | Options | Spelling","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["df357f0c-78fe-4aee-a465-f3da7499077e"],"platforms":"windows10","technologies":"mdm"},{"id":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","displayName":"Math Settings","description":"Declarative Device Management preview Math Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"6b87c5da-cfd9-44bc-be05-ed08eb2144c7","displayName":"User Accounts","description":"Administrative Templates User Accounts","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","displayName":"Desktop","description":"Administrative Templates\\Desktop","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","displayName":"Network Connectivity Status Indicator","description":"Administrative Templates Network Connectivity Status Indicator","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6c142a01-47fa-422d-8135-29e81bc970cc","displayName":"Conversion Service","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...\\Conversion Service","helpText":null,"parentCategoryId":"af14a55b-d79b-4299-946c-b7582412b748","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6c1d9109-e4d1-4718-a537-dd685464fdbe","displayName":"i SCSI Security","description":"Administrative Templatesi SCS Ii SCSI Security","helpText":null,"parentCategoryId":"3f693856-7cbb-4a1c-93be-0d05aa41059f","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6c7168c3-6f34-4086-af0b-ed0b74301dc9","displayName":"Security Settings","description":"Administrative Templates Service Control Manager Settings Security Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6cd02266-a42f-4675-b83e-37360dbf3c68","displayName":"WLAN Media Cost","description":"Administrative Templates WLAN Service WLAN Media Cost","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6d1e32eb-61f7-4907-b9fe-b83fda8ad67d","displayName":"Customize Ribbon","description":"Microsoft Publisher 2016\\Publisher Options\\Customize Ribbon","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6d4184ab-a66c-47f1-b54e-af55f654e2a5","displayName":"Hotspot Authentication","description":"Administrative Templates Hotspot Authentication","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","displayName":"Related Website Sets Settings","description":"Microsoft Edge Related Website Sets Settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"6d6b289c-c1e9-4004-b5ab-3123920cf10d","displayName":"Password manager","description":"Google Google Chrome - Default Settings users can override Password manager","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","displayName":"Link- Layer Topology Discovery","description":"Administrative Templates Link- Layer Topology Discovery","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6efb8802-223a-46a7-b13f-a68f28f8b2c2","displayName":"Login Items","description":"Login > Login Items","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"6f0e6df6-8654-4b57-b1d5-2160c5a0a54e","displayName":"Pen Flicks Learning","description":"Administrative Templates Pen Flicks Learning","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6f1386e5-148d-4dc3-84d1-79df721e3233","displayName":"Default search provider","description":"Microsoft Edge - Default Settings (users can override)\\Default search provider","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6fafeb5c-65ce-4993-b421-46e60da69131","displayName":"HTTP authentication","description":"Microsoft Edge - Default Settings (users can override)\\HTTP authentication","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","displayName":"General","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Advanced\\Web Options...\\General","helpText":null,"parentCategoryId":"76b233cc-f977-4305-b02f-deef6667251d","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70498fad-5ddb-4730-8130-d755ff675760","displayName":"Default search provider","description":"Google Google Chrome Default search provider","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70b0e7ef-ceac-4c25-8f9f-5a6bf07163b6","displayName":"Calendar Type","description":"Microsoft Project 2016\\Project Options\\View\\Calendar Type","helpText":null,"parentCategoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70b5da13-9c31-4857-890d-b7eb223729c3","displayName":"Firewall","description":"Networking > Firewall","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"70c4566f-a079-4a8e-ac97-0736b405df1d","displayName":"Work profile password","description":"Device Restriction Work profile password","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"70d374bf-6444-4b74-a879-a29e4d44c566","displayName":"News And Interests","description":"News And Interests","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"70d374bf-6444-4b74-a879-a29e4d44c566","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"712d184f-d9ac-45fc-9eea-aade3a22b55e","displayName":"Volume Activation","description":"Microsoft Office 2016 (Machine)\\Volume Activation","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"717b634f-72a6-44f6-92c5-e1397bb10f40","displayName":"Keyboard Filter","description":"Keyboard Filter","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"719595d8-ab5d-4418-88aa-8cd55c2964ba","displayName":"Cloud Cache","description":"FS Logix Profile Containers Cloud Cache","helpText":null,"parentCategoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","displayName":"Tracking Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options\\Tracking Options","helpText":null,"parentCategoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"71f79fa3-14c0-4df8-bf9c-8476e36ea755","displayName":"Operating system settings","description":"Operating system settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"71f79fa3-14c0-4df8-bf9c-8476e36ea755","childCategoryIds":[],"platforms":"windows10","technologies":"windowsOsRecovery"},{"id":"7226f8a2-c542-471a-8d9e-e0df527325d3","displayName":"Notification Settings","description":"Administrative Templates Power Management Notification Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"724d930a-7a3c-4171-a17c-431cee336518","displayName":"Software Update Settings","description":"Managed Settings Software Update Settings","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"725adbdf-1eb8-45c4-8eb1-44747bd1615d","displayName":"Define Shared Workspace URL's","description":"Microsoft Office 2016\\Global Options\\Customize\\Shared Workspace\\Define Shared Workspace URL's","helpText":null,"parentCategoryId":"13123148-c522-437f-b316-d78f5cc0d28d","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72972c43-36a3-4034-8cc8-334c99087798","displayName":"Instant Search","description":"Administrative Templates Instant Search","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72a7524b-11c5-4695-9fcf-6cf30c8ba2b9","displayName":"First Run","description":"Microsoft Office 2016\\First Run","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72f61c7d-e5d2-4170-baf3-c953c1082e19","displayName":"Controlled Folder Access","description":"Administrative Templates Microsoft Defender Antivirus Microsoft Defender Exploit Guard Controlled Folder Access","helpText":null,"parentCategoryId":"ad84cea3-5664-4e42-a9d6-1446828bea45","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73415dea-0103-4427-83c5-6c97bf81af1d","displayName":"Save Documents","description":"Microsoft Visio 2016\\Visio Options\\Save\\Save Documents","helpText":null,"parentCategoryId":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"736134cb-4d82-427a-97b7-d219ac6a22f0","displayName":"Corrupted File Recovery","description":"Administrative Templates Corrupted File Recovery","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73935f55-c845-40ce-819e-838c0041f6fa","displayName":"Resultant Set of Policy snap-in extensions","description":"Administrative Templates Group Policy Resultant Set of Policy snap-in extensions","helpText":null,"parentCategoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73bc2db9-d37f-4add-a64d-a8239273edb3","displayName":"Check Accessibility","description":"Microsoft Word 2016\\File Tab\\Check Accessibility","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"740e7a10-3774-4a1c-9970-6907e0f0b848","displayName":"Disable Items in User Interface","description":"Microsoft Word 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["0f42fc50-66c8-4b70-9904-64f8d662c930","44e27b70-4bdb-4aec-a75d-0568a1edc332"],"platforms":"windows10","technologies":"mdm"},{"id":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","displayName":"BITS","description":"BITS","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7490c4fd-c326-42f7-9908-006504616d4c","displayName":"Trust Center","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["5c4224e0-6a48-4665-9332-958d98124157","fe54701d-42bd-47f0-9c49-26ff6a928b32","e36863b6-3232-4a29-be02-32ee67cc48b9","2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7"],"platforms":"windows10","technologies":"mdm"},{"id":"751cf9ec-7214-4b38-a09e-24922684bd8f","displayName":"Presentation Settings","description":"Administrative Templates Presentation Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"756d2b0b-5f06-45e7-b5c5-c066deb5ed2f","displayName":"Extension snap-ins","description":"Administrative Templates Microsoft Management Console Restricted Permitted snap-ins Extension snap-ins","helpText":null,"parentCategoryId":"acb49e73-5a6a-479b-9d58-c3cd7f632e9b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"75ad885f-6118-4508-a2fd-bb26be931c3f","displayName":"Outlook Today Settings","description":"Microsoft Outlook 2016\\Outlook Today Settings","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"75e080fb-3ed7-4a73-a6e0-eb93f0119d68","displayName":"Event Logging","description":"Administrative Templates Event Logging","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","displayName":"File Block Settings","description":"Microsoft Visio 2016\\Visio Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"760376f3-6b74-4992-89eb-aa41d6190e94","displayName":"Subscription Activation","description":"Microsoft Office 2016\\Subscription Activation","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"763525a0-8456-4336-a8d1-392253e8fdd8","displayName":"System Policy Control","description":"System Policy\\ System Policy Control","helpText":null,"parentCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","rootCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"7652894d-4667-443f-b925-b1686a942729","displayName":"Disable Items in User Interface","description":"Microsoft Outlook 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["d59dfcc1-6c35-41de-bfb6-de94b8120ca5","8184df77-410e-41a6-b687-88de05769977"],"platforms":"windows10","technologies":"mdm"},{"id":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","displayName":"File Provider","description":"System Configuration > File Provider","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"76ad3567-c6cb-43b5-b91d-a52a34853c03","displayName":"Trusted Locations","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76b233cc-f977-4305-b02f-deef6667251d","displayName":"Advanced","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Advanced","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["6fd44fd0-80d1-47a0-acad-c115e5b807b6"],"platforms":"windows10","technologies":"mdm"},{"id":"76bbc368-9d0b-4aa7-b8e2-2dcfd864b9ee","displayName":"Audit Process Creation","description":"Administrative Templates Audit Process Creation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76c53aab-0288-4ac1-b399-0104e04c6457","displayName":"Application Compatibility Diagnostics","description":"Administrative Templates Application Compatibility Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76e34834-6d47-4e06-b14c-aa2888cdce27","displayName":"Generative AI","description":"Microsoft Edge Generative AI","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","displayName":"Publishing","description":"Administrative Templates App-V Publishing","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"77b0357b-412e-4a81-9469-e20a5f1345fd","displayName":"Complex scripts","description":"Microsoft Publisher 2016\\Publisher Options\\Advanced\\Complex scripts","helpText":null,"parentCategoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"77ca5e78-a1fe-456e-9814-034b1ea2658d","displayName":"PowerPoint Designer","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\PowerPoint Designer","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"78497707-c3e4-400b-a6bc-1813c3689fdc","displayName":"Preferences","description":"Microsoft Edge Update\\Preferences","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"785c6df2-c6d0-4d6e-bd73-c3b62caca754","displayName":"TCPIP Settings","description":"Administrative Templates TCPIP Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["486f25cc-c865-446e-95b2-c5b061883a7a","91789113-6339-4e96-8e1d-73a4dec4967f"],"platforms":"windows10","technologies":"mdm"},{"id":"788355e5-e113-4b17-ada9-fb5ef38bffa1","displayName":"App-V","description":"Administrative Templates App-V","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["7740c7ba-aa61-4486-ad26-cb8721a2efb4","5011ca61-1a58-42da-9c66-7763236acc84","e7cc16d8-f74f-4cd7-890d-9b4082a19c39","efabaf11-42e4-48ab-81ca-4514199d239b","b9201072-3681-4e95-ad90-869e6166b129","f125d7cd-a333-4f24-a5f4-99fc289c6d22","ea9a092f-dd93-41d4-9bbb-118de1213578","10835ce3-31c8-4ec6-aa00-c5af48e550a8"],"platforms":"windows10","technologies":"mdm"},{"id":"794337be-8833-4b9a-bb88-8a030141578d","displayName":"Search","description":"Search","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"794337be-8833-4b9a-bb88-8a030141578d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"797ac384-f48e-4567-b931-33a6ce923b94","displayName":"Microsoft Edge Canary","description":"Microsoft Edge Update\\Applications\\Microsoft Edge Canary","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7a8b936d-b4b0-408f-bec5-3c97050730f8","displayName":"Shared paths","description":"Microsoft Office 2016\\Shared paths","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7aeaf6f8-5511-4216-9483-28f432a5a08f","displayName":"Server Settings","description":"Microsoft PowerPoint 2016\\Miscellaneous\\Server Settings","helpText":null,"parentCategoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","displayName":"App Lock","description":"App Management > App Lock","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","displayName":"Extensible Single Sign On (SSO)","description":"Authentication > Extensible Single Sign On (SSO)","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm"},{"id":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","displayName":"Microsoft Edge Beta","description":"Microsoft Edge Update\\Applications\\Microsoft Edge Beta","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7bee4dea-82a4-4a03-b903-654b374819b1","displayName":"Chinese Conversion | Convert with Options","description":"Microsoft Word 2016\\Review Tab\\Chinese Conversion | Convert with Options","helpText":null,"parentCategoryId":"1fddd12c-a630-47f0-9633-638808e228f9","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","displayName":"Windows Connect Now","description":"Administrative Templates Windows Connect Now","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7d331987-7e2d-4975-b23b-d99a5af26ddf","displayName":"IME","description":"Administrative Templates IME","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7d9e5b9b-84e7-473c-b6ca-a1629448df55","displayName":"Safari Extension Settings","description":"Declarative Device Management preview Extension Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","displayName":"Performance","description":"Microsoft Edge - Default Settings (users can override)\\Performance","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","displayName":"Predefined","description":"Microsoft PowerPoint 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7eaa5e09-e5ab-4051-b557-64a124ae497c","displayName":"Cryptography","description":"Microsoft Access 2016\\Application Settings\\Security\\Cryptography","helpText":null,"parentCategoryId":"23fd467e-24f8-4200-8b19-c6c11afa8926","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7ecdd7c9-6ab2-4dac-88ef-9bdad46e1f66","displayName":"Parental Controls Game Center","description":"Parental Controls > Parental Controls Game Center","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","displayName":"Display","description":"Microsoft Word 2016\\Word Options\\Display","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","displayName":"Display","description":"Display","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","displayName":"Regional and Language Options","description":"Administrative Templates Regional and Language Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["9a79d480-8cb4-47b5-95c7-5da56eea5bb8"],"platforms":"windows10","technologies":"mdm"},{"id":"7f461268-0fb6-4247-b6db-52515d42a20e","displayName":"User Interface","description":"Administrative Templates Windows Media Player User Interface","helpText":null,"parentCategoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f5517b0-3ff7-4f7e-aa4c-3d2ccbf37bdc","displayName":"VPN Connection","description":"VPN Connection","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7f5517b0-3ff7-4f7e-aa4c-3d2ccbf37bdc","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7fc23813-7a7c-412a-b9bd-eda07e6b1f5d","displayName":"List Sync","description":"List Sync","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7fc23813-7a7c-412a-b9bd-eda07e6b1f5d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7fc3275d-5ef6-4806-88b0-210bb175c182","displayName":"Network List Manager","description":"Network List Manager","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7fc3275d-5ef6-4806-88b0-210bb175c182","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"802f3065-0bf1-4578-9d6d-ab1ef02db3ec","displayName":"Feedback Settings","description":"Visual Studio Feedback Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8084033c-156a-4d1b-ab0b-159541810459","displayName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","description":"Microsoft Office 2016\\Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["69931627-230d-4df9-bbef-e3eac64ea8ef"],"platforms":"windows10","technologies":"mdm"},{"id":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","displayName":"Config Refresh","description":"Config Refresh","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"811f63f1-1619-4b48-b8f0-3d388729bd47","displayName":"Xsan","description":"Xsan","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","childCategoryIds":["46af3391-ed6d-4ada-aef7-02dac2a1b136","fd3717c1-dcf8-4038-b7f7-4ad3359a9d32"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8184df77-410e-41a6-b687-88de05769977","displayName":"Custom","description":"Microsoft Outlook 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"7652894d-4667-443f-b925-b1686a942729","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"81bc8383-43a5-4c6a-9d51-951e86028934","displayName":"Project Guide settings for 'Project1'","description":"Microsoft Project 2016\\Project Options\\Interface\\Project Guide settings for 'Project1'","helpText":null,"parentCategoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"81c518f1-522e-4957-b850-e8a66d2ab215","displayName":"Games settings","description":"Microsoft Edge Games settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"81eb92d0-acda-4ea2-8183-29ed5457276b","displayName":"Container and Directory Naming","description":"FS Logix ODFC Containers Container and Directory Naming","helpText":null,"parentCategoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","displayName":"Remediation","description":"Administrative Templates Microsoft Defender Antivirus Remediation","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"822bd634-4d01-486e-adad-8085968fd1c4","displayName":"Advanced Page","description":"Administrative Templates Internet Explorer Internet Control Panel Advanced Page","helpText":null,"parentCategoryId":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"826db7fb-889b-4a99-80a6-38347ba37f21","displayName":"Recurring item configuration","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Recurring item configuration","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"82a437a8-6be8-4003-a951-951999e86db8","displayName":"Parental Controls","description":"Parental Controls","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":["7ecdd7c9-6ab2-4dac-88ef-9bdad46e1f66","f019963f-f4ed-4429-b6e3-babfb24c36a8","f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","65087b94-7e45-4d74-a50d-df4377b67499","dc270c70-1cf4-4d98-ad26-8c2d441173f1"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"82d173f9-ba0b-4b09-bbb8-68cba4916162","displayName":"Privacy Preferences Policy Control","description":"Privacy > Privacy Preferences Policy Control","helpText":null,"parentCategoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","rootCategoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"82ecfab7-b76a-4cec-8e76-859db4599ac2","displayName":"Cached Exchange Mode","description":"Microsoft Outlook 2016\\Account Settings\\Exchange\\Cached Exchange Mode","helpText":null,"parentCategoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"83087772-6560-4488-a1c5-bb6e4889e868","displayName":"Advanced","description":"Microsoft Word 2016\\Word Options\\Advanced","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["bc65521d-e48a-4e95-899f-49df827808ca","e63361ad-a54b-4557-acc7-02c272a3e58d","2108b443-384c-4bb3-9b9f-acb4a754a86a","61ecc5ec-c494-420b-a27b-a8d2fbdd7df1"],"platforms":"windows10","technologies":"mdm"},{"id":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","displayName":"Caldav","description":"Accounts > CalDAV","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"832f3a51-5e73-4541-8f14-1323cd9919bc","displayName":"When sending a message","description":"Microsoft Outlook 2016 Outlook Options Preferences E-mail Options Advanced E-mail Options When sending a message","helpText":null,"parentCategoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8391e79d-d618-47c3-979c-83544da43739","displayName":"Protected View","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","displayName":"Multi SIM","description":"Multi SIM","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"83febe72-a64f-4051-9071-1efae1ea9a15","displayName":"Disk Management","description":"Declarative Device Management preview Disk Management","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"macOS","technologies":"appleRemoteManagement"},{"id":"845ff38a-408b-449c-9ef3-7fdc331027df","displayName":"Azure Virtual Desktop","description":"Administrative Templates Windows Components Remote Desktop Services Remote Desktop Session Host Azure Virtual Desktop","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["5d4e843b-2848-4508-9143-cb3217c2fe83"],"platforms":"windows10","technologies":"mdm"},{"id":"8495c82c-f273-4bcc-8886-6751103a9c7b","displayName":"Proofing","description":"Microsoft Visio 2016 Visio Options Proofing","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["af9b2941-29f9-4ee5-ae09-215f4e242943"],"platforms":"windows10","technologies":"mdm"},{"id":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","displayName":"User Experience","description":"User Experience","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":["c00d6468-cac3-429c-ada5-ba3adf4982a8","d8f06fcf-7328-43ac-b5b7-f7166b5333de","e42edcd8-fcb0-4255-a774-c78b34f0b0c9","ff90bf4b-0583-4761-a1c4-5aa4b50c5872","11c4cf0f-a03d-4309-93b2-011be4c410d5","cc388035-b49c-493e-a598-14b0d0de4359","b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","361859d9-1382-47c3-b9ec-9251a62fbb25"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"84b7f123-e849-40f9-914b-4b97b57bd3b4","displayName":"Interface","description":"Microsoft Project 2016\\Project Options\\Interface","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["fe7c8652-17d4-40a7-869c-f7cfc3454402","343eb575-3ac8-4da9-b66d-ce84b84be7c3","81bc8383-43a5-4c6a-9d51-951e86028934"],"platforms":"windows10","technologies":"mdm"},{"id":"84de2eed-843c-401b-a3fd-e21be88f2365","displayName":"Pen","description":"Microsoft OneNote 2016\\OneNote Options\\Pen","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"853d5a82-91e4-4c53-8338-fd1a3d9b542c","displayName":"MK Protocol Security Restriction","description":"Administrative Templates Internet Explorer Security Features MK Protocol Security Restriction","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"853f4181-42e8-411c-91cf-c06968c0a543","displayName":"Time Server","description":"System Configuration > Time Server","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"85810387-3320-4056-bae2-953beeb246f7","displayName":"Security","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["36ddafde-fdc7-4787-bf6e-2291446ccc6b","9544c86b-47bb-4cb2-a725-63214a0454f4"],"platforms":"windows10","technologies":"mdm"},{"id":"859f3bfb-70f6-447a-822e-680ac98e91ce","displayName":"Microsoft Visual Studio","description":"Visual Studio","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":["b3b30966-47ac-4b54-a75a-04418d5c6153","175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","802f3065-0bf1-4578-9d6d-ab1ef02db3ec","d9d5f333-9402-4459-8ef1-e29330cac8be","652a676c-9d60-4c9a-88b6-823a24961a9b","96277512-3d35-4876-ad74-2d849348799e"],"platforms":"windows10","technologies":"mdm"},{"id":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","displayName":"Disable Items in User Interface","description":"Microsoft Office 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86b4fa22-f6f1-4ca5-8fe4-8788f9b3fd89","displayName":"Power Throttling Settings","description":"Administrative Templates Power Management Power Throttling Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","displayName":"Updates","description":"Microsoft Office 2016 (Machine)\\Updates","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86e78a4b-706a-4ec8-be90-439461abb29d","displayName":"File Revocation","description":"Administrative Templates File Revocation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","displayName":"SSL Configuration Settings","description":"Administrative Templates SSL Configuration Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"87667b72-85ce-48c2-8023-e6db7f5fe739","displayName":"Work Folders","description":"Administrative Templates Work Folders","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"87f460f4-8403-419c-bfb4-44dec5edcccb","displayName":"Media Management Disc Burning","description":"Media Management > Media Management Disc Burning","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"87f460f4-8403-419c-bfb4-44dec5edcccb","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","displayName":"Lanman Workstation","description":"Administrative Templates Lanman Workstation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"88b16683-81f2-450a-9bf2-42f582e0b748","displayName":"Stationery and Fonts","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\Stationery and Fonts","helpText":null,"parentCategoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"891d2958-5a8c-479c-aa68-69b1b6c735e1","displayName":"Shared PC","description":"Shared PC","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"89519fc9-9b38-4401-8767-b0a047cae515","displayName":"Device Restriction","description":"Device Restriction","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":["95000481-a8b5-4e18-99e3-367666aee03f","70c4566f-a079-4a8e-ac97-0736b405df1d","929c169a-3480-467c-9f47-d1836b359ef7","990880db-3f64-4436-ab4a-d7d5181dfa5d","aad0d3ef-88f5-4b22-831b-27093eafbc64","f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","b6733d23-eadc-486a-abfc-62b78698a16c","2257f7e1-3e88-4d4d-a666-437bbe42baca","bf8e3e9c-f7e7-4a43-8898-2caf7b01d987"],"platforms":"androidEnterprise,aosp","technologies":"android"},{"id":"895e0884-6b60-4bb0-b2ab-3a1642103db7","displayName":"Native Messaging","description":"Google Google Chrome Native Messaging","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","displayName":"Downloads","description":"Microsoft Edge - Default Settings users can override Downloads","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"897675f9-0d1b-437b-ba0a-584fbd54df95","displayName":"Advanced E-mail Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options\\Advanced E-mail Options","helpText":null,"parentCategoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["832f3a51-5e73-4541-8f14-1323cd9919bc","35f245bd-8d1f-424c-83de-a80be27a6a4e"],"platforms":"windows10","technologies":"mdm"},{"id":"89ad0055-1603-420e-940d-9944a63e3da9","displayName":"Profiles","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Profiles","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","displayName":"Save","description":"Microsoft Word 2016\\Word Options\\Save","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"89c0381d-3b9b-4be5-8077-ffb18d47e910","displayName":"Add-on Management","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Add-on Management","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8a03aebc-9249-4917-a1c3-2957717d9123","displayName":"Real-time Protection","description":"Administrative Templates Microsoft Defender Antivirus Real-time Protection","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8aa3383a-efac-4ec4-841d-06e3e18646d8","displayName":"Default search provider","description":"Microsoft Edge\\Default search provider","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"8abddb23-7036-4ba8-8912-529279a849ea","displayName":"Security Preferences","description":"Security > Security Preferences","helpText":null,"parentCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8b0e5a63-c309-430b-8521-7bd21e715b90","displayName":"Office 2016 Converters","description":"Microsoft Office 2016\\Office 2016 Converters","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8b7e662c-0410-4e33-ae11-edb7c717d914","displayName":"Restricted Browsing","description":"Microsoft Office 2016\\File Open/Save dialog box\\Restricted Browsing","helpText":null,"parentCategoryId":"92be4fc7-8095-441c-b52b-9861c21bc337","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","displayName":"Immersive Reader settings","description":"Microsoft Edge Immersive Reader settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"8c30a64e-ad24-47a0-97a8-52320360fd88","displayName":"Net Logon","description":"Administrative Templates Net Logon","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["41ba590e-9105-4eda-92fb-13c7d34b8eee"],"platforms":"windows10","technologies":"mdm"},{"id":"8c35f124-e249-43e3-9044-ecc0b0a5855a","displayName":"Idle Browser Actions","description":"Google Google Chrome Idle Browser Actions","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8c75a12d-664d-43ba-a3aa-5259425f9b37","displayName":"Energy Saver","description":"System Configuration > Energy Saver","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","displayName":"App Settings","description":"Declarative Device Management preview App Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"8c879ddf-7acf-45f3-81d3-2c78c7a1321b","displayName":"Miscellaneous","description":"Microsoft Office 2016 (Machine)\\Miscellaneous","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8cefd936-362e-4a24-bc76-e078b6fd13fa","displayName":"Screensaver","description":"System Configuration > Screensaver","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","displayName":"Trusted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Trusted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8d4a5b79-8399-4075-a71f-80ac3099ae78","displayName":"Bluetooth","description":"Bluetooth","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"8d503574-f93a-4277-a30d-19895d46dd13","displayName":"Security Page","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page","helpText":null,"parentCategoryId":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","ac014aea-e417-46ad-a4a5-9a1fb1030882","fca9261c-1e93-467d-90cf-ba9108e4cb2e","8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","44c15b2f-10da-4e1e-836b-8b71c19fe34c","8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","99dfe848-181d-480a-bd20-3f93f04b6f5c","dfede24d-d1c8-4e20-82a3-89e1b52057d5","4086190d-2e5b-439d-8426-08492ebb8c9f","58ae30f4-10a2-4144-a593-b5f5bd93c10d"],"platforms":"windows10","technologies":"mdm"},{"id":"8d9eaa88-a2b4-42e7-83e5-8dc12f51d36b","displayName":"Eap","description":"Eap","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"8d9eaa88-a2b4-42e7-83e5-8dc12f51d36b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","displayName":"Device Installation","description":"Administrative Templates Device Installation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["68237832-f376-4f0e-ba26-4e06fce7a35d"],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","displayName":"SharePoint Server","description":"Microsoft Office 2016\\Server Settings\\SharePoint Server","helpText":null,"parentCategoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e48532a-ff0e-4422-82e2-6956b6786005","displayName":"Customize Ribbon","description":"Microsoft Project 2016\\Project Options\\Customize Ribbon","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","displayName":"Intranet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Intranet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","displayName":"Removable Data Drives","description":"Administrative Templates BitLocker Drive Encryption Removable Data Drives","helpText":null,"parentCategoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","displayName":"Junk E-mail","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Junk E-mail","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8ee1d8d2-582f-401b-927a-993016f4290d","displayName":"Browsers","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\Browsers","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","displayName":"Windows Error Reporting","description":"Administrative Templates Windows Error Reporting","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["184981d4-712b-425e-b0a3-93eac7fbd3ee","1551f6d3-415c-44a8-b184-393de7c42adf"],"platforms":"windows10","technologies":"mdm"},{"id":"8efd284f-5a56-4da8-8821-f51984ff954d","displayName":"Associated Domains","description":"App Management > Associated Domains","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","displayName":"Login Window Behavior","description":"Login > Login Window Behavior","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8ff93a7a-503c-4955-89be-900d475b7c5e","displayName":"Managed Settings","description":"Managed Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":["0be23ead-c5f7-4ea5-9ec5-64c05d19cf5d","1fbc29d7-0530-4208-b506-9df648a402e9","724d930a-7a3c-4171-a17c-431cee336518","e7dccaa6-2b16-4dd3-b835-83ca641d0c80","dd68a290-1ba7-470f-afca-339f443a767c","1a056b49-3fb9-4097-b286-c5f493208578","5f71c40e-01aa-42d2-9c8c-7d560126cd4b","2c156b7e-99c8-4a21-a828-4f9b94479b0d","3c7f15ef-a539-411c-93f1-5f97b7bd5519","ef7328b1-c666-40fe-a933-57b14bc77dd3","99d68d97-63b7-4f49-83dd-1ad3b3281d0d","b32726b3-b0e9-465b-86f8-b61ad8af52f0"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","displayName":"Networking","description":"Administrative Templates Windows Media Player Networking","helpText":null,"parentCategoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"902f5df1-31d6-44ee-ba95-2561199db35f","displayName":"Sync your settings","description":"Administrative Templates Sync your settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","displayName":"Global HTTP Proxy","description":"Proxies > Global HTTP Proxy","helpText":null,"parentCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","rootCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"907fd656-2a80-4f34-8615-a3acb11a2b95","displayName":"Custom","description":"Microsoft Publisher 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"9caa3b08-b545-4c21-a3b7-b5d2302c1a81","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"909339a5-8f04-4fa2-8807-5d38c83ef547","displayName":"Device Guard","description":"Administrative Templates Device Guard","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"90e3acc6-80d5-41b4-8141-a8620a211c0e","displayName":"Tenant Restrictions","description":"Administrative Templates Tenant Restrictions","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","displayName":"Online Content","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...\\Online Content","helpText":null,"parentCategoryId":"af14a55b-d79b-4299-946c-b7582412b748","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","displayName":"Local Policies Security Options","description":"Local Policies Security Options","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91789113-6339-4e96-8e1d-73a4dec4967f","displayName":"Parameters","description":"Administrative Templates TCPIP Settings Parameters","helpText":null,"parentCategoryId":"785c6df2-c6d0-4d6e-bd73-c3b62caca754","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","displayName":"International Options","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\International Options","helpText":null,"parentCategoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91c02e14-8848-485d-8844-b9933fa888ec","displayName":"Hard Disk Settings","description":"Administrative Templates Power Management Hard Disk Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9215e382-4e7b-4554-8c80-80277136b544","displayName":"Formulas","description":"Microsoft Excel 2016\\Excel Options\\Formulas","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"929c169a-3480-467c-9f47-d1836b359ef7","displayName":"Connectivity","description":"Device Restriction Connectivity","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"92be4fc7-8095-441c-b52b-9861c21bc337","displayName":"File Open/Save dialog box","description":"Microsoft Office 2016\\File Open/Save dialog box","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["4a832199-a841-4b6a-84fa-51365902a742","8b7e662c-0410-4e33-ae11-edb7c717d914"],"platforms":"windows10","technologies":"mdm"},{"id":"92d69c43-75ac-49b1-a3ef-9350079eef86","displayName":"Content settings","description":"Microsoft Edge\\Content settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","displayName":"Account Settings","description":"Microsoft Outlook 2016\\Account Settings","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["b161cf66-abfa-4a36-a9ac-c20ca60594e0","63ca5d8b-829d-42c5-92e8-35f9ca47fb0e","c4dbc05f-da1e-440d-8beb-91bf9dad1875","060e7533-6c2f-4ed1-9173-f3de58de4bed","4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","43053249-ecd1-4d9f-9fa9-c05e7713da7f"],"platforms":"windows10","technologies":"mdm"},{"id":"93099bd4-c685-434b-9d72-f0cb6db5e753","displayName":"Cloud delivered protection preferences","description":"Microsoft Defender > Cloud-delivered protection preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"930d2960-3f70-48ca-9ead-b65a5a037c07","displayName":"SNMP","description":"Administrative Templates SNMP","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93a20c17-1e34-4778-8c95-91a46980ea75","displayName":"Out of Office Assistant","description":"Microsoft Outlook 2016\\Outlook Options\\Out of Office Assistant","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93c28398-faef-4ca5-9667-f5ed004da32c","displayName":"Internet Information Services","description":"Administrative Templates Internet Information Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93ed2300-658d-40f3-8211-9295a240579c","displayName":"HTTP authentication","description":"Google Google Chrome HTTP authentication","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","displayName":"Notifications","description":"Administrative Templates Notifications","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94b5c25e-3af3-4c08-b738-a0527f91dc22","displayName":"Security Intelligence Updates","description":"Administrative Templates Microsoft Defender Antivirus Security Intelligence Updates","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94ce8206-be22-496c-aa72-f3560e2a5c8d","displayName":"Links","description":"Microsoft Office 2016 Links","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","displayName":"Storage","description":"Storage","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"95000481-a8b5-4e18-99e3-367666aee03f","displayName":"Power","description":"Device Restriction Power","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","displayName":"Accounts","description":"Accounts","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":["ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","fa20bbc3-d25d-4a7f-a349-9b211d186e21","5214f1e7-a5a9-4de5-80b4-2f7084a8d068","45fe783f-a80b-42d9-ab3c-8c4081be8d05","9ba1b877-865a-4104-8376-b43a0c75b04b","831dcaee-a6fa-4893-a32d-e13fdf7d3777"],"platforms":"iOS,macOS,windows10","technologies":"mdm,appleRemoteManagement"},{"id":"952f69c8-2644-48df-976b-01fd624cbb3a","displayName":"Database","description":"Microsoft Office 2016\\Business Data\\Database","helpText":null,"parentCategoryId":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9544c86b-47bb-4cb2-a725-63214a0454f4","displayName":"Cryptography","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"85810387-3320-4056-bae2-953beeb246f7","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"957a5b24-ed7a-4f84-9d73-7b6131367396","displayName":"Advanced","description":"Microsoft Visio 2016\\Visio Options\\Advanced","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["4e62ada2-f091-49e1-99dd-ffdf5cf558cd","6ae0d607-832c-403b-b3bc-c563e390ebad","bec8c55d-5aee-4d87-a17d-34d5b3b78f19","66395272-f132-4170-b88e-87f794f987f4","98cefd27-a980-4070-ba45-3696b623810d","f59804be-7fc6-43c3-9baa-942aab85be84"],"platforms":"windows10","technologies":"mdm"},{"id":"96277512-3d35-4876-ad74-2d849348799e","displayName":"Privacy Settings","description":"Visual Studio Privacy Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"962a2377-ad9a-4654-a526-a77c14152fd7","displayName":"Content settings","description":"Google Google Chrome - Default Settings users can override Content settings","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9859957e-34f1-4669-9f95-2b7c79fff052","displayName":"Service Management - Managed Login Items","description":"Login > Service Management - Managed Login Items","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"9865907f-b775-4d36-9578-a016c5105dfe","displayName":"AutoSave","description":"Microsoft Office 2016\\AutoSave","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"98cefd27-a980-4070-ba45-3696b623810d","displayName":"Shape Search","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Shape Search","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"98dc5bd0-2b16-4263-ba2f-62115b680017","displayName":"Group Policy","description":"Administrative Templates Group Policy","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["5bb9fb31-007d-4e3f-967b-11e865fcdc70","73935f55-c845-40ce-819e-838c0041f6fa"],"platforms":"windows10","technologies":"mdm"},{"id":"98e76d3e-9e52-45b3-b0c7-f029023121e9","displayName":"Privacy","description":"Privacy","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","childCategoryIds":["82d173f9-ba0b-4b09-bbb8-68cba4916162"],"platforms":"macOS,windows10","technologies":"mdm"},{"id":"990880db-3f64-4436-ab4a-d7d5181dfa5d","displayName":"Personal Profile","description":"Device Restriction Personal Profile","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"992a8a1e-428e-41cb-948e-4e5da86105fa","displayName":"Device Guard","description":"Device Guard","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"992a8a1e-428e-41cb-948e-4e5da86105fa","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"99b4ac32-50b5-4659-a7a1-94bc708ae71a","displayName":"Device Health Attestation Service","description":"Administrative Templates Device Health Attestation Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"99ba9e42-9872-4a03-a615-fc4a4cebc067","displayName":"Active Directory","description":"Administrative Templates Active Directory","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"99d68d97-63b7-4f49-83dd-1ad3b3281d0d","displayName":"Diagnostic Submission","description":"Managed Settings Diagnostic Submission","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"99dfe848-181d-480a-bd20-3f93f04b6f5c","displayName":"Locked- Down Intranet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Intranet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9a2bfe77-7e03-4a24-a9fa-c42a225a28b8","displayName":"Intelligent Services","description":"Microsoft Excel 2016\\Intelligent Services","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9a7843b4-6ec1-47c4-906b-75b8866e97c2","displayName":"Maps","description":"Maps","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9a7843b4-6ec1-47c4-906b-75b8866e97c2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9a79d480-8cb4-47b5-95c7-5da56eea5bb8","displayName":"Handwriting personalization","description":"Administrative Templates Regional and Language Options Handwriting personalization","helpText":null,"parentCategoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9aaa7ee2-727d-426f-8a2b-6b10a4cd084f","displayName":"RSS Feeds","description":"Administrative Templates RSS Feeds","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","displayName":"Miscellaneous","description":"Microsoft Office 2016\\Miscellaneous","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["5f048379-3a42-43f0-9fd5-d269f292aa35"],"platforms":"windows10","technologies":"mdm"},{"id":"9b74c5a8-98f8-49f0-b4eb-51e071d75776","displayName":"Task Scheduler","description":"Task Scheduler","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9b74c5a8-98f8-49f0-b4eb-51e071d75776","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9b894b32-3697-4a83-9731-3db2a35455ad","displayName":"Cursors","description":"Administrative Templates Cursors","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9ba1b877-865a-4104-8376-b43a0c75b04b","displayName":"LDAP","description":"Accounts > LDAP","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","displayName":"Remote Desktop","description":"Remote Desktop Command","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"9caa3b08-b545-4c21-a3b7-b5d2302c1a81","displayName":"Disable Items in User Interface","description":"Microsoft Publisher 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["441d6cc4-e51f-453e-a44d-8394509415be","907fd656-2a80-4f34-8615-a3acb11a2b95"],"platforms":"windows10","technologies":"mdm"},{"id":"9d14bbed-327d-4c38-ac02-6b916909bdd9","displayName":"Microsoft Edge","description":"Microsoft Edge Apple","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"9dbd66e3-4544-4ca8-a118-272c874bc684","displayName":"Local Security Authority","description":"Administrative Templates Local Security Authority","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9ecb05b7-e942-4b60-9040-d612385f5c67","displayName":"Calendar","description":"Microsoft Project 2016\\Project Options\\Calendar","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","displayName":"Locked- Down Restricted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Restricted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","displayName":"User Rights","description":"User Rights","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","displayName":"Accessories","description":"Administrative Templates Accessories","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a004deb8-6f52-4411-8d94-41563a8203fc","displayName":"Quarantine","description":"Administrative Templates Microsoft Defender Antivirus Quarantine","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a01c03d4-ec76-4c01-b982-de71620feb19","displayName":"Printing","description":"Printing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","childCategoryIds":["429c4b85-a2b4-46ed-afa0-6c89c08a5544","174ffe92-3770-4688-aa21-85b7535cf374"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","displayName":"Microsoft App Store","description":"Microsoft App Store","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a18508d1-fd74-4955-8032-3bd9219a0944","displayName":"Fixed Data Drives","description":"Administrative Templates BitLocker Drive Encryption Fixed Data Drives","helpText":null,"parentCategoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a185940c-7899-4ab6-867d-7559352cf8d2","displayName":"OneNote Options","description":"Microsoft OneNote 2016\\OneNote Options","helpText":null,"parentCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":["ab8301d6-b122-4d40-868a-d00d3c0f1916","a87f9d6a-0c84-4cad-839f-e912c6006c12","44774d3d-387b-4fa7-8de4-d82b039c06d1","acfe6c36-66ab-4a3e-86b0-a178377427d2","84de2eed-843c-401b-a3fd-e21be88f2365","c02141e6-0725-4f6f-9138-83d10c6bc104","1979a12b-2a72-438d-9de7-320d1b38e777","1bfef2c3-a561-4e7a-8f0f-0944bc79c20f","fa471a57-af7b-4ccf-b6ba-4c57a7230498","25a84f2d-dbac-457e-b734-bc2605305f2b","c492dd55-8876-4b1b-b620-615cc9b65ef8","e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","4a7b0e92-ba43-46aa-96e8-c5839dbcb524","ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","1ae8c95a-5748-4647-80f8-b447e60601a2"],"platforms":"windows10","technologies":"mdm"},{"id":"a1fbe395-3b60-475f-8a34-3710d6b2e09f","displayName":"Browsing","description":"Administrative Templates Internet Explorer Internet Settings Advanced settings Browsing","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","displayName":"Custom","description":"Microsoft PowerPoint 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a25a7a02-4bac-411b-9d02-10cb3297cb17","displayName":"Microsoft Edge","description":"Microsoft Edge","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":["3abaf4c2-d5db-4b3b-a461-b1a208231b36","45a89c1f-0a34-4f78-b28f-d30b623fa423","fe845e81-5993-4a65-b22a-decfc5928c65","66615d2a-fec9-47f1-8eaf-9813e30cc023","ef8760ac-a77c-4055-a812-a95bfbf9c00a","ae78ab75-2d0d-418c-be6f-9e64642de4e2","08677354-6f67-455e-a430-4d8d2fbabe84","76e34834-6d47-4e06-b14c-aa2888cdce27","8aa3383a-efac-4ec4-841d-06e3e18646d8","3edb2860-b77b-4240-af16-fb34d45d6ba1","81c518f1-522e-4957-b850-e8a66d2ab215","5bd0eaf1-1818-44e8-9168-fc75c5739cc8","c6099521-a05f-480a-8562-7e71318e2cda","2af24920-f611-4f03-99a6-205773869ae6","6d529e48-5477-4ceb-8ff7-c6e959a0e24f","b3c8c6d9-28bb-475a-9353-4a0e657b33c7","00d7396c-cadc-4d29-86ba-fe4df2ecb110","d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","92d69c43-75ac-49b1-a3ef-9350079eef86","d17b08e6-de3b-445b-ab14-1d47e62efdcf","ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","fddc444c-3591-4a50-865b-d8993b798e12","526e363a-84db-4256-a13c-e01c8c646e26","05811ceb-2954-426c-8afa-2a53f02480cc","120b24dd-c04a-4291-8f24-9c48fcdc1434","dfab5866-1712-4bbf-8edf-5b080b315b9b","08c5f391-e156-4a72-bbb9-3670f2f63a56","ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","eb6409fc-fb52-413d-ae4b-eff017b52b30","43057320-7058-46d5-86f9-a56c80bbf8b9","3fbd3b29-bafd-4adf-89e4-3be612dee275","3ba8106d-4b2f-4775-939d-1cc8703a41dc","fb1e99d0-b921-4b19-9842-17e3e7987528","16ea64a1-563e-43cc-b34a-728c8e7cd13c","1043e7ed-8651-44b2-b918-7230c0b75a6c","5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","8bcf8b08-35a3-49b7-8760-5fe3b767d6a6"],"platforms":"android,iOS,macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"a279f35f-cd71-4489-b0c3-545ea1aa229d","displayName":"Local Security Authority","description":"Local Security Authority","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a279f35f-cd71-4489-b0c3-545ea1aa229d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","displayName":"Disable Items in User Interface","description":"Microsoft Excel 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["3fa63a9d-e22d-4fc8-8464-a13b56461115","3b7e16e7-171f-4169-8904-c8483b06700d"],"platforms":"windows10","technologies":"mdm"},{"id":"a28dd311-46e8-4868-89ab-d3745c0bca21","displayName":"Security","description":"Administrative Templates Event Log Service Security","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a321fc04-d0cb-45ec-a6bf-51d60249922d","displayName":"Automatic Picture Download Settings","description":"Microsoft Outlook 2016\\Security\\Automatic Picture Download Settings","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a34ade49-964d-407c-9f60-2e8cd9dfef05","displayName":"Smart Card","description":"Administrative Templates Smart Card","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","displayName":"Programmatic Security","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Programmatic Security","helpText":null,"parentCategoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf"],"platforms":"windows10","technologies":"mdm"},{"id":"a3e48951-624d-4fee-b470-d17ce16e6b0c","displayName":"Secure Boot","description":"Secure Boot","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a3e48951-624d-4fee-b470-d17ce16e6b0c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","displayName":"Features","description":"Microsoft Defender Features","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"a3ec7cde-bca6-4e3e-9f7e-f66a43196924","displayName":"Windows Backup And Restore","description":"Windows Backup And Restore","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a3ec7cde-bca6-4e3e-9f7e-f66a43196924","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","displayName":"Graph settings","description":"Microsoft Office 2016\\Graph settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a42e2248-d2dc-4476-a92d-d152fd67e04b","displayName":"Audio Accessory","description":"Declarative Device Management preview Audio Accessory","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS","technologies":"appleRemoteManagement"},{"id":"a4fb2510-977f-42ff-9033-6f1eb98f141b","displayName":"Device Lock","description":"Device Lock","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5060182-4d22-412b-bd0e-3a1e009b36c6","displayName":"Client Interface","description":"Administrative Templates Microsoft Defender Antivirus Client Interface","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5607145-2bd3-4473-a8ee-d7fa5c2f2675","displayName":"Fax","description":"Microsoft Office 2016\\Services\\Fax","helpText":null,"parentCategoryId":"478ed057-8ee7-4dd2-8276-06dad8f85397","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a561e59a-09b7-4106-a6fa-0b82036a5b49","displayName":"RD Gateway","description":"Administrative Templates Remote Desktop Services RD Gateway","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a57b27b6-48e0-42b2-812a-2be86c113a0c","displayName":"Application Compatibility Settings","description":"Administrative Templates Distributed COM Application Compatibility Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","displayName":"Password manager","description":"Google Google Chrome Password manager","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","displayName":"Reporting","description":"Administrative Templates Microsoft Defender Antivirus Reporting","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","displayName":"Co-authoring","description":"Microsoft Office 2016\\Collaboration Settings\\Co-authoring","helpText":null,"parentCategoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5ce858b-74c2-4663-9b3e-068d31349a13","displayName":"Cryptography","description":"Microsoft Word 2016\\Word Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","displayName":"Lanman Workstation","description":"Lanman Workstation","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","displayName":"Synchronization","description":"Microsoft Office 2016\\Business Data\\Synchronization","helpText":null,"parentCategoryId":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","displayName":"Wireless Display","description":"Wireless Display","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6fe8038-136b-4d50-bf04-8e232409c0d2","displayName":"Web Content Filter","description":"Web > Web Content Filter","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"a754c9bd-2116-4dd6-9014-07f914869145","displayName":"Proxies","description":"Proxies","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","childCategoryIds":["906df5cd-1d9e-49d0-ab32-cf5c5a041974","b8ed9eb3-17de-4091-b08b-7adb2fe13271"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"a77e6e83-a02e-4a51-a27e-6437ea42aeb5","displayName":"Human Presence","description":"Human Presence","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a77e6e83-a02e-4a51-a27e-6437ea42aeb5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a787672d-4a33-455b-a2db-e340eb35a5c8","displayName":"WSL container","description":"Windows Subsystem for Linux WSL container","helpText":null,"parentCategoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","rootCategoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a788a6e5-ab3f-41e5-96c8-ee59627dcb4d","displayName":"Workgroup Administrator...","description":"Microsoft Access 2016\\Tools | Security\\Workgroup Administrator...","helpText":null,"parentCategoryId":"607a1c39-a3db-496f-8db6-c99d67f5f76c","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a79b2d36-7dea-4a84-81ef-27f99296bccf","displayName":"Authentication","description":"Authentication","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":["f35cc803-3a06-4262-b38b-a5295321f756","c3fdc01d-0648-4dcb-855d-7afe78bf1d89","7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","5995d2ad-5ec7-49d2-ada2-d9c2b57746ba"],"platforms":"iOS,macOS,windows10","technologies":"mdm,appleRemoteManagement"},{"id":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","displayName":"SmartScreen settings","description":"Microsoft Edge - Default Settings (users can override)\\SmartScreen settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a7b1c291-6bec-499b-9018-6120950cd5a6","displayName":"App Control for Business","description":"App Control for Business","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a7d55d90-e1d1-4577-8bfd-fe2641bce461","displayName":"User Interface Options","description":"Microsoft Visio 2016\\Visio Options\\General\\User Interface Options","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a7e7529f-1030-41da-8b4d-024e1c08bbac","displayName":"Windows Standby Resume Performance Diagnostics","description":"Administrative Templates Windows Standby Resume Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a877a2ff-f144-421f-814c-593e972a8a20","displayName":"Password manager and protection","description":"Microsoft Edge - Default Settings (users can override)\\Password manager and protection","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a87f9d6a-0c84-4cad-839f-e912c6006c12","displayName":"Send to OneNote","description":"Microsoft OneNote 2016\\OneNote Options\\Send to OneNote","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","displayName":"Microsoft Office 2016","description":"Microsoft Office 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["8084033c-156a-4d1b-ab0b-159541810459","94ce8206-be22-496c-aa72-f3560e2a5c8d","760376f3-6b74-4992-89eb-aa41d6190e94","50b4bc60-802c-477a-9366-80e09154595f","7a8b936d-b4b0-408f-bec5-3c97050730f8","8b0e5a63-c309-430b-8521-7bd21e715b90","9b2ad6d8-8837-4c50-89d5-7507b69c7dec","23c09e06-5bee-4b20-a391-36549bf0f620","af14a55b-d79b-4299-946c-b7582412b748","5cd6dc4f-b231-449f-bc10-16041b73356a","72a7524b-11c5-4695-9fcf-6cf30c8ba2b9","a40e47b0-5b27-4e4d-b2ef-42f20540e812","4e0d279d-5ddd-4c4e-8590-6ed92129444d","1942922a-cba9-44c8-871f-3d915c62bd06","478ed057-8ee7-4dd2-8276-06dad8f85397","5b1be2c5-9939-4b2e-b29b-b22069455c90","33fb4f49-5c7f-472c-a0f3-e05646a55902","b94cbc54-e565-44f2-a27a-a63b2514d8bf","0696109e-045f-486a-9a6b-ab7877887bed","59c9b1c4-1757-4cf3-9b27-954dafe016d5","6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","44541a16-c3a2-4be1-ba42-4fc15bde4c46","adf11731-7089-4e2e-8dde-4bd9ef86b067","cc29afc6-309c-4a0d-86f6-60081ae7cd4c","42d8353a-a135-4c2d-8d06-c6cf9961c6c5","bc633a5a-c712-49a6-9f56-775ca9321df4","e86f24d3-8531-4298-b064-692ea795b1d9","da04d4b8-bd11-439e-9663-5fd2399d9cc1","055293ad-c585-40c0-b66c-76ff5cc0a332","042ab9cf-9524-4dd4-b049-4d5f4ff7053f","2d5a483f-b408-426d-9234-2883eae20afb","9865907f-b775-4d36-9578-a016c5105dfe","eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","2f56761a-8e8b-4788-a589-a73ab91818e6","05a6f86f-dab7-4888-97a1-db3457f00974","2d6891a4-ee83-4e55-8e23-09513e1306e4","92be4fc7-8095-441c-b52b-9861c21bc337","eb947c30-3c43-4d34-a566-a842a1a142f3","6aeb1df3-d796-4c5b-921d-9f3970a754cc","449201b6-5002-42d1-85ed-d288fb6552da","866eedbc-ffd9-457d-b02b-7b163d55c4bd","4aec010d-487a-4752-8e66-aedb9e4fbb5a","5bf4c2ba-be08-4cda-bf33-d10707580d78"],"platforms":"windows10","technologies":"mdm"},{"id":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","displayName":"Save","description":"Microsoft Excel 2016\\Excel Options\\Save","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","displayName":"Security","description":"Microsoft Outlook 2016\\Security","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["d4e5541e-ab77-4e6c-8046-1fb80ee705ad","a321fc04-d0cb-45ec-a6bf-51d60249922d","c3db5686-3bb2-437c-8906-60da1a1fa844","1720d60f-40a6-471c-8e4c-efbacaf46997"],"platforms":"windows10","technologies":"mdm"},{"id":"a9edc695-b4a9-4111-b07d-627f934f5a1a","displayName":"Trust Center","description":"Microsoft Access 2016\\Application Settings\\Security\\Trust Center","helpText":null,"parentCategoryId":"23fd467e-24f8-4200-8b19-c6c11afa8926","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["12ad5ec7-346d-4b8b-9eba-d826cdb61c31"],"platforms":"windows10","technologies":"mdm"},{"id":"aad0d3ef-88f5-4b22-831b-27093eafbc64","displayName":"Users and Accounts","description":"Device Restriction User and Accounts","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","displayName":"Logging","description":"FS Logix Logging","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","displayName":"Consistent Mime Handling","description":"Administrative Templates Internet Explorer Security Features Consistent Mime Handling","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ab8301d6-b122-4d40-868a-d00d3c0f1916","displayName":"Other","description":"Microsoft OneNote 2016\\OneNote Options\\Other","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"abf781d7-1179-4f24-8d01-5611db14eddc","displayName":"Touch Input","description":"Administrative Templates Touch Input","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac014aea-e417-46ad-a4a5-9a1fb1030882","displayName":"Locked- Down Internet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Internet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac0a894c-173a-48fc-b961-901f28463c77","displayName":"Direct Access Client Experience Settings","description":"Administrative Templates Direct Access Client Experience Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","displayName":"User Profiles","description":"Administrative Templates User Profiles","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","displayName":"Related Website Sets Settings","description":"Google Google Chrome Related Website Sets Settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","displayName":"Sleeping Tabs settings","description":"Microsoft Edge - Default Settings (users can override)\\Sleeping Tabs settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acb49e73-5a6a-479b-9d58-c3cd7f632e9b","displayName":"Restricted Permitted snap-ins","description":"Administrative Templates Microsoft Management Console Restricted Permitted snap-ins","helpText":null,"parentCategoryId":"07c023d3-0899-40af-a04f-805876d99a9b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["756d2b0b-5f06-45e7-b5c5-c066deb5ed2f"],"platforms":"windows10","technologies":"mdm"},{"id":"acbc106b-796a-4ba3-ab5f-c130530ad455","displayName":"Earned Value options for Project1","description":"Microsoft Project 2016\\Project Options\\Calculation\\Calculation options for 'Project1'\\Earned Value options for Project1","helpText":null,"parentCategoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","displayName":"Operating System Drives","description":"Administrative Templates BitLocker Drive Encryption Operating System Drives","helpText":null,"parentCategoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acfe6c36-66ab-4a3e-86b0-a178377427d2","displayName":"Save","description":"Microsoft OneNote 2016\\OneNote Options\\Save","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ad1ecbf4-75da-4dc1-9354-7d00c0e2af72","displayName":"Allday","description":"Allday","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ad1ecbf4-75da-4dc1-9354-7d00c0e2af72","childCategoryIds":[],"platforms":"android,iOS","technologies":"exchangeOnline"},{"id":"ad47f904-ede2-4b12-849e-bf751d88abf5","displayName":"Display","description":"Administrative Templates Display","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ad84cea3-5664-4e42-a9d6-1446828bea45","displayName":"Microsoft Defender Exploit Guard","description":"Administrative Templates Microsoft Defender Antivirus Microsoft Defender Exploit Guard","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["210b9c4d-e72a-45a4-97d3-339a6b30c49c","72f61c7d-e5d2-4170-baf3-c953c1082e19"],"platforms":"windows10","technologies":"mdm"},{"id":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","displayName":"Save","description":"Microsoft Visio 2016\\Visio Options\\Save","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["73415dea-0103-4427-83c5-6c97bf81af1d","2eed22da-106f-4c93-9a45-5ce803b50233"],"platforms":"windows10","technologies":"mdm"},{"id":"adc4eb7f-0f34-4f43-b361-dc42363eccab","displayName":"Mp Engine","description":"Administrative Templates Microsoft Defender Antivirus Mp Engine","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"adf11731-7089-4e2e-8dde-4bd9ef86b067","displayName":"What's New","description":"Microsoft Office 2016\\What's New","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","displayName":"Sleeping Tabs settings","description":"Microsoft Edge\\Sleeping Tabs settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","displayName":"Signature Status dialog box","description":"Microsoft Outlook 2016\\Security\\Cryptography\\Signature Status dialog box","helpText":null,"parentCategoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"af14a55b-d79b-4299-946c-b7582412b748","displayName":"Tools | Options | General | Service Options...","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["6c142a01-47fa-422d-8135-29e81bc970cc","5838ed03-2902-4931-92cf-e349ab09c9b8","91041ad3-e0a6-43fd-bc7b-ad4c7dda5765"],"platforms":"windows10","technologies":"mdm"},{"id":"af351b0c-3d9e-4b18-957b-8179e4eaba15","displayName":"Safe Browsing settings","description":"Google Google Chrome - Default Settings users can override Safe Browsing settings","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"af9b2941-29f9-4ee5-ae09-215f4e242943","displayName":"AutoCorrect Options","description":"Microsoft Visio 2016\\Visio Options\\Proofing\\AutoCorrect Options","helpText":null,"parentCategoryId":"8495c82c-f273-4bcc-8886-6751103a9c7b","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","displayName":"Microsoft One Note 2016","description":"Microsoft One Note 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":["b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","a185940c-7899-4ab6-867d-7559352cf8d2"],"platforms":"windows10","technologies":"mdm"},{"id":"b03bfdc7-f42a-400e-935b-2b07fc71a7f1","displayName":"Mime Sniffing Safety Feature","description":"Administrative Templates Internet Explorer Security Features Mime Sniffing Safety Feature","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","displayName":"Custom","description":"Microsoft One Note 2016 Disable Items in User Interface Custom","helpText":null,"parentCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b161cf66-abfa-4a36-a9ac-c20ca60594e0","displayName":"Exchange ActiveSync","description":"Microsoft Outlook 2016\\Account Settings\\Exchange ActiveSync","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b206e4ef-a288-4fb7-a7ee-4a30b4df3b98","displayName":"Server Settings","description":"Microsoft Word 2016\\Miscellaneous\\Server Settings","helpText":null,"parentCategoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b260992a-8216-4bfa-b60a-4eeea1f356c9","displayName":"News and interests","description":"Feeds","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b260992a-8216-4bfa-b60a-4eeea1f356c9","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b2b85670-5475-4148-ab3d-c4c86b4d5af0","displayName":"PKCS imported certificate","description":"PKCS imported certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b2b85670-5475-4148-ab3d-c4c86b4d5af0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b32726b3-b0e9-465b-86f8-b61ad8af52f0","displayName":"Default Applications","description":"Managed Settings Default Applications","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"b382d980-7459-4850-a45e-75dd99488972","displayName":"Software Update Settings","description":"Declarative Device Management preview Software Update Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"b3b2fc04-4b88-4a1c-8370-04573019eebe","displayName":"LAPS","description":"Administrative Templates\\LAPS","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b3b30966-47ac-4b54-a75a-04418d5c6153","displayName":"Dev Tunnel Settings","description":"Visual Studio Dev Tunnel Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","displayName":"PDF Reader","description":"Microsoft Edge PDF Reader","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"b3e317cd-c580-478e-885c-666ce3079e78","displayName":"Outlook Social Connector","description":"Microsoft Outlook 2016\\Outlook Social Connector","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b40b8f80-c0e6-4494-8085-f90cadc167a9","displayName":"Temporary folders","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Temporary folders","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b40cfb22-8f17-4317-bcbb-c1c871497446","displayName":"Location and Sensors","description":"Administrative Templates Location and Sensors","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b46f4e70-d3d1-4177-8e22-62f806d4568c","displayName":"Other","description":"Google Google Chrome Other","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b473c6fa-a971-4e5d-ad15-2c27c17c5d3e","displayName":"Power BI","description":"Microsoft Excel 2016\\Power BI","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b485695b-0fae-41ae-861c-3030769b28df","displayName":"Safe Browsing settings","description":"Google Google Chrome Safe Browsing settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","displayName":"Security Features","description":"Administrative Templates Internet Explorer Security Features","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["4560c525-12a1-4536-9cca-338330e58389","e6911a08-946f-4b70-99cb-2a8b92c461e0","853d5a82-91e4-4c53-8338-fd1a3d9b542c","622c83ff-f780-47e6-8b9c-bf82552e3f04","18296501-4825-47ea-835d-66a01aba9384","17bc9899-d157-4eac-a949-810b4a841e28","ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","b03bfdc7-f42a-400e-935b-2b07fc71a7f1","3bbaff1b-7d59-4b9c-ab53-c235d72b2fb0"],"platforms":"windows10","technologies":"mdm"},{"id":"b5169b74-41be-460a-9402-b13b6c22582b","displayName":"Microsoft Office","description":"Microsoft Office > Microsoft Office","helpText":null,"parentCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"b524d6e2-75bc-4409-ae3d-07605707d7ee","displayName":"Pen UX Behaviors","description":"Administrative Templates Pen UX Behaviors","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","displayName":"Windows Power Shell","description":"Administrative Templates Windows Power Shell","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b6650a16-32bc-4344-ac98-8f20486c6b0b","displayName":"Cellular Private Network","description":"Cellular Private Network","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"b6733d23-eadc-486a-abfc-62b78698a16c","displayName":"General","description":"Device Restriction General","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise,aosp","technologies":"android"},{"id":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","displayName":"Managed Menu Extras","description":"User Experience > Managed Menu Extras","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"b6bb653a-73f0-42f4-b097-1ce556310904","displayName":"Scripted Diagnostics","description":"Administrative Templates Scripted Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b6cafb2c-81be-40cf-90d8-788f713f7099","displayName":"Replace as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type\\Replace as you type","helpText":null,"parentCategoryId":"4dae3032-1f16-4ace-911b-a957db0b8089","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","displayName":"App Package Deployment","description":"Administrative Templates App Package Deployment","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","displayName":"Endpoint Detection and Response (EDR) preferences","description":"Microsoft Defender > Endpoint Detection and Response (EDR) preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"b792508d-da03-4174-bcf1-666d128ee8ad","displayName":"AutoFormat as you type","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Proofing\\AutoFormat as you type","helpText":null,"parentCategoryId":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b7bde490-eac6-4f57-8808-e0786b8191a1","displayName":"Remote FX for Windows Server 2008 R2","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Remote Session Environment Remote FX for Windows Server 2008 R2","helpText":null,"parentCategoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","displayName":"Web Rtc settings","description":"Google Google Chrome Web Rtc settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b8158968-c839-4d37-9eb8-887bd6fd7402","displayName":"Disable Items in User Interface","description":"Microsoft Access 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["55eebd7c-beb9-48b6-907f-df4997e18bdb","dba1a547-e288-45ac-8553-27a3b564699e"],"platforms":"windows10","technologies":"mdm"},{"id":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","displayName":"Win RM Service","description":"Administrative Templates Windows Remote Management Win RM Win RM Service","helpText":null,"parentCategoryId":"364787de-93e4-4fd6-9608-dce1ad8f88c2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b85d9c04-4923-4fdf-a425-424686d47859","displayName":"Siri Settings","description":"Declarative Device Management preview Siri Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"b8adcde1-500a-430f-8636-f97eaae2a2c6","displayName":"Japanese Find","description":"Microsoft Word 2016\\Japanese Find","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","displayName":"Network Proxy Configuration","description":"Proxies > Network Proxy Configuration","helpText":null,"parentCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","rootCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"b90fb0dc-b8c1-4fc3-b9f9-dfbda4b3f03d","displayName":"General","description":"Microsoft Excel 2016\\Excel Options\\Advanced\\Web Options...\\General","helpText":null,"parentCategoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b9201072-3681-4e95-ad90-869e6166b129","displayName":"Client Coexistence","description":"Administrative Templates App-V Client Coexistence","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b92241c7-e419-4dc7-b373-08e595c1db1d","displayName":"Operating system","description":"Operating system","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b92241c7-e419-4dc7-b373-08e595c1db1d","childCategoryIds":[],"platforms":"windows10","technologies":"windowsOsRecovery"},{"id":"b94cbc54-e565-44f2-a27a-a63b2514d8bf","displayName":"DLP","description":"Microsoft Office 2016\\DLP","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b96b63eb-0292-4a73-85d7-c68d330c109e","displayName":"Extensions","description":"Microsoft Edge - Default Settings (users can override)\\ Extensions","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b9ab4d39-9e28-4897-aa34-0201a35ea989","displayName":"Right-to-left","description":"Microsoft Outlook 2016\\Outlook Options\\Right-to-left","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ba7686de-e6ee-4af9-b1a5-265b03e08367","displayName":"Microsoft PowerPoint 2016","description":"Microsoft PowerPoint 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["28ab8eed-623a-4e9b-813e-13256472dbaf","da92dfd6-a29e-42a0-92ed-276bb6904455","f5babdb3-c718-4675-b977-6c7bc7e6f886","ceacf7fa-fa6e-434d-a381-e20e5245d180","e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","da1503cb-e474-4545-8e77-cdd577f34a08"],"platforms":"windows10","technologies":"mdm"},{"id":"bb54b081-5004-4f05-a46c-f5b948f57b82","displayName":"NTFS","description":"Administrative Templates Filesystem NTFS","helpText":null,"parentCategoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","displayName":"System Configuration","description":"System Configuration","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":["8c75a12d-664d-43ba-a3aa-5259425f9b37","cb33668b-933f-4424-8d2d-8bdf0e61bddd","5401711f-292a-487a-be18-f99593a0477c","dec8381a-0a61-406b-842b-fc6ae9930795","768d9aa4-7407-4ed9-b97f-2385b8cadb47","8cefd936-362e-4a24-bc76-e078b6fd13fa","0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","853f4181-42e8-411c-91cf-c06968c0a543"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"bbe51018-a17d-46c4-9517-ff45c54d8d18","displayName":"DNS Settings","description":"Networking > DNS Settings","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"bc58391f-664c-42dd-9d18-269e65f324a7","displayName":"Miscellaneous","description":"Microsoft Excel 2016\\Miscellaneous","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["183628a3-d0a5-47de-b444-e132d634ca38"],"platforms":"windows10","technologies":"mdm"},{"id":"bc633a5a-c712-49a6-9f56-775ca9321df4","displayName":"Downloading Framework Components","description":"Microsoft Office 2016\\Downloading Framework Components","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bc65521d-e48a-4e95-899f-49df827808ca","displayName":"File Locations","description":"Microsoft Word 2016\\Word Options\\Advanced\\File Locations","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bce24fbf-4caf-449f-a210-5dd31a368b22","displayName":"Removed policies","description":"Google Google Chrome - Default Settings users can override Removed policies","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd1dad69-5cbe-415e-8565-e87b15cd4431","displayName":"General","description":"Microsoft Access 2016\\Application Settings\\General","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd5533e1-f1ee-4994-8a79-cffe02b12d5c","displayName":"FileVault Recovery Key Escrow","description":"FileVault > FileVault Recovery Key Escrow","helpText":null,"parentCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","displayName":"Compatibility View","description":"Administrative Templates Internet Explorer Compatibility View","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","displayName":"General","description":"Microsoft Word 2016\\Word Options\\General","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bdc32a5e-2bce-46b1-9838-ed557b1e287e","displayName":"Cryptography","description":"Cryptography","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"bdc32a5e-2bce-46b1-9838-ed557b1e287e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","displayName":"Windows Time Service","description":"Administrative Templates Windows Time Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["13f025df-7d3f-4ecd-bd38-d7af7853b66e"],"platforms":"windows10","technologies":"mdm"},{"id":"be9bdbec-b52e-4174-9c5b-cf765dee855b","displayName":"Store","description":"Administrative Templates Store","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","displayName":"Editing Options","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Editing Options","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bf8e3e9c-f7e7-4a43-8898-2caf7b01d987","displayName":"System Security","description":"Device Restriction System Security","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"c00d6468-cac3-429c-ada5-ba3adf4982a8","displayName":"Accessibility","description":"User Experience > Accessibility","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","displayName":"ActiveX Installer Service","description":"Administrative Templates ActiveX Installer Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c0204a51-a73c-46a6-8626-deeadcabe6ac","displayName":"Licensing","description":"Licensing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c0204a51-a73c-46a6-8626-deeadcabe6ac","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c02141e6-0725-4f6f-9138-83d10c6bc104","displayName":"Backup","description":"Microsoft OneNote 2016\\OneNote Options\\Backup","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","displayName":"Windows Apps","description":"Administrative Templates Microsoft User Experience Virtualization Windows Apps","helpText":null,"parentCategoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c14c2e8b-0081-46e0-89ac-48ade3b83408","displayName":"Remote Desktop","description":"Remote Desktop","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c14c2e8b-0081-46e0-89ac-48ade3b83408","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3857f91-3df8-472f-9b5a-b10778c715c0","displayName":"Google Chrome - Default Settings users can override","description":"Google Google Chrome - Default Settings users can override","helpText":null,"parentCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":["af351b0c-3d9e-4b18-957b-8179e4eaba15","12142994-4b30-486c-bab1-9206528b2b96","20ceae56-e189-46ec-a440-791ce7454017","de643352-007f-4a47-8c83-d75a79516b39","962a2377-ad9a-4654-a526-a77c14152fd7","d97d6d8f-0a1a-4160-89aa-d624a36954a2","6d6b289c-c1e9-4004-b5ab-3123920cf10d","54f2e032-bdcc-4877-b7a0-973d0a7c1653","bce24fbf-4caf-449f-a210-5dd31a368b22"],"platforms":"windows10","technologies":"mdm"},{"id":"c3ab8d44-b353-4a8a-a526-ffd743fb7ff8","displayName":"Miscellaneous","description":"Microsoft Access 2016\\Miscellaneous","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3b5e77d-c00d-4578-84c9-289362ad0b00","displayName":"Save","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Save","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3db5686-3bb2-437c-8906-60da1a1fa844","displayName":"Trust Center","description":"Microsoft Outlook 2016\\Security\\Trust Center","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3dfb294-a7c0-48af-b705-59c4e257d48c","displayName":"Declarative Device Management (DDM)","description":"Declarative Device Management (DDM)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":["11d26400-1d13-4dd6-ab4b-cb323494b127","b382d980-7459-4850-a45e-75dd99488972","6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","2cdd4a96-23c1-4419-b88c-41bbaa119e68","dba26132-cba6-4178-93c3-f02476532f08","a42e2248-d2dc-4476-a92d-d152fd67e04b","83febe72-a64f-4051-9071-1efae1ea9a15","d9654cb3-57c8-487c-90a5-454e15336731","b85d9c04-4923-4fdf-a425-424686d47859","42a6198f-bdec-402e-b619-315400b65488","ddb64e9d-34b9-44f4-9980-a6623f14e445","4a6c4488-bbcf-4b5b-9156-7aa1b10a6010","7d9e5b9b-84e7-473c-b6ca-a1629448df55","e0ab6868-4b53-4310-b665-f7c979941db7","5c9e9aaf-a36c-437f-b85a-cb78a527a80f","15be55d8-7477-4274-9b09-b775bce68416","27f47083-6e1b-4fc7-938b-ecd846b79d78","8c86f511-1729-4fe9-b0b2-111d9044e1ba"],"platforms":"iOS,macOS,visionOS,tvOS","technologies":"mdm,appleRemoteManagement"},{"id":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","displayName":"Identification (Deprecated)","description":"Authentication > Identification","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"c400a917-cdff-4e15-a70f-59b82df4c038","displayName":"Attachment Security","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Attachment Security","helpText":null,"parentCategoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","displayName":"Remote Desktop Services","description":"Administrative Templates Remote Desktop Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["3a901a80-e2b6-470c-9658-d66ba5458370","0456dcd5-c003-4a8b-80e6-61bacf854330","a561e59a-09b7-4106-a6fa-0b82036a5b49","4c604a0e-9339-4c01-9536-b689bd0abe5f","62bbe0df-b9b2-453f-a2f1-ee66291d4956"],"platforms":"windows10","technologies":"mdm"},{"id":"c492dd55-8876-4b1b-b620-615cc9b65ef8","displayName":"Versions and Recyle Bin","description":"Microsoft OneNote 2016\\OneNote Options\\Versions and Recyle Bin","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c4ce54b8-e555-4447-9791-dd8e9dbb86b0","displayName":"Tenant Lockdown","description":"Tenant Lockdown","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c4ce54b8-e555-4447-9791-dd8e9dbb86b0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","displayName":"Exchange","description":"Microsoft Outlook 2016\\Account Settings\\Exchange","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["82ecfab7-b76a-4cec-8e76-859db4599ac2","e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5"],"platforms":"windows10","technologies":"mdm"},{"id":"c4e48b1b-6d88-434f-a717-d5bab28eb245","displayName":"Wi-Fi Connection","description":"Wi-Fi Connection","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c4e48b1b-6d88-434f-a717-d5bab28eb245","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c6099521-a05f-480a-8562-7e71318e2cda","displayName":"Printing","description":"Microsoft Edge\\Printing","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"c67c9e69-6e69-4b63-868c-3b3df5d17e47","displayName":"Disable Items in User Interface","description":"Microsoft Visio 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","4e4deef0-4528-47d5-8869-4143c506f18b"],"platforms":"windows10","technologies":"mdm"},{"id":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","displayName":"Removable Storage Access","description":"Administrative Templates Removable Storage Access","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"c6b72060-8ecb-41d8-8625-2984dd756d4a","displayName":"Free/Busy Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Free/Busy Options","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c6c1120b-988c-4581-a21c-b9786a821242","displayName":"Miscellaneous","description":"Microsoft Publisher 2016\\Miscellaneous","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c72d9f00-d625-43ec-add4-514891035839","displayName":"Web Service","description":"Microsoft Office 2016\\Business Data\\Web Service","helpText":null,"parentCategoryId":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","displayName":"Publisher Options","description":"Microsoft Publisher 2016\\Publisher Options","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["69f3ad9d-871d-42b3-8e10-07dc076a4d32","51e0cebb-cac4-4905-9b31-539295e4b85b","1a0386fd-354b-441e-a0d6-1523c209dae7","038b49c9-4f13-4ace-be8d-bd076bffa23e","6d1e32eb-61f7-4907-b9fe-b83fda8ad67d"],"platforms":"windows10","technologies":"mdm"},{"id":"c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","displayName":"System Preferences","description":"Preferences > System Preferences","helpText":null,"parentCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"c805d788-1950-4ed1-adfb-771f12564a0c","displayName":"Exclusions","description":"Administrative Templates Microsoft Defender Antivirus Exclusions","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c859dc1a-fdeb-4591-af97-79d078ee715b","displayName":"Event Forwarding","description":"Administrative Templates Event Forwarding","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c87ae066-cc1a-44c9-8645-1db2359f7484","displayName":"Layer-2 priority value","description":"Administrative Templates Qo S Packet Scheduler Layer-2 priority value","helpText":null,"parentCategoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","displayName":"File Block Settings","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c945edd8-c865-4932-806d-83752e3f46ad","displayName":"Microsoft Edge Web View2","description":"Microsoft Edge Web View2","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c945edd8-c865-4932-806d-83752e3f46ad","childCategoryIds":["13cc3b63-a150-4cf2-8d76-309975603c8e"],"platforms":"windows10","technologies":"mdm"},{"id":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","displayName":"Auto Play Policies","description":"Administrative Templates Auto Play Policies","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c9a65baa-de10-4818-97a2-b61babb28060","displayName":"Microsoft Defender Antivirus","description":"Administrative Templates Microsoft Defender Antivirus","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["ad84cea3-5664-4e42-a9d6-1446828bea45","2c43699e-90b5-4da6-9689-fe5ad3b25ac9","c805d788-1950-4ed1-adfb-771f12564a0c","a004deb8-6f52-4411-8d94-41563a8203fc","adc4eb7f-0f34-4f43-b361-dc42363eccab","a5060182-4d22-412b-bd0e-3a1e009b36c6","94b5c25e-3af3-4c08-b738-a0527f91dc22","09c02465-dc11-457e-9eac-19fc542e4cda","cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","a5a56a36-6d60-4f74-a3c6-d82ed979b24a","428f107c-2167-4bc2-9293-8f1d6728a0c5","8a03aebc-9249-4917-a1c3-2957717d9123"],"platforms":"windows10","technologies":"mdm"},{"id":"c9ab1080-67a7-4d6c-8213-056d4eb08ea0","displayName":"Credential Providers","description":"Credential Providers","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c9ab1080-67a7-4d6c-8213-056d4eb08ea0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ca1aedf4-b951-45f5-a77c-dec776a82e21","displayName":"General i SCSI","description":"Administrative Templatesi SCSI General i SCSI","helpText":null,"parentCategoryId":"3f693856-7cbb-4a1c-93be-0d05aa41059f","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","displayName":"Full Disk Encryption","description":"Full Disk Encryption","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":["5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","3f56adc1-2207-4033-a6e2-07f64c08e3ff","bd5533e1-f1ee-4994-8a79-cffe02b12d5c"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cb1e177e-8f06-4a69-8215-ec1e91c19e30","displayName":"Notifications","description":"Notifications","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"cb1e177e-8f06-4a69-8215-ec1e91c19e30","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","displayName":"System Extensions","description":"System Configuration > System Extensions","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"cb6472c8-3e22-4029-af98-8a97f03a5a44","displayName":"PST Settings","description":"Microsoft Outlook 2016\\Miscellaneous\\PST Settings","helpText":null,"parentCategoryId":"f5a1a387-6665-4527-b532-88a64a76e732","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cb8e8500-0336-4277-b3d9-9177cc967dcf","displayName":"Text Input","description":"Text Input","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cbb98485-6a36-47b8-b450-7821e08507ac","displayName":"Web Options - General","description":"Microsoft Access 2016\\Application Settings\\Web Options...\\General","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","displayName":"Network Inspection System","description":"Administrative Templates Microsoft Defender Antivirus Network Inspection System","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cc13d92c-673f-4af7-9748-50342fc8795a","displayName":"Filesystem","description":"Administrative Templates Filesystem","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["bb54b081-5004-4f05-a46c-f5b948f57b82"],"platforms":"windows10","technologies":"mdm"},{"id":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","displayName":"Collaboration Settings","description":"Microsoft Office 2016\\Collaboration Settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["2806d29a-7c7a-4ff0-baa2-4a0044425ea6","a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","1b97e23d-996f-4b8e-9abf-53cfa0fc8917"],"platforms":"windows10","technologies":"mdm"},{"id":"cc388035-b49c-493e-a598-14b0d0de4359","displayName":"Dock","description":"User Experience > Dock","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cc50f179-0c39-4486-a555-de5a6e6ed365","displayName":"Trust Center","description":"Microsoft Project 2016\\Project Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"623d41fb-000e-41d8-b955-373f8c700def","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","displayName":"Offline Files","description":"Administrative Templates Offline Files","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","displayName":"Mobile Accounts","description":"Accounts > Mobile Accounts","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","displayName":"Security","description":"Microsoft Excel 2016\\Excel Options\\Security","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["27ccaa0b-8755-4116-a0e3-b5d21d68ab65","7490c4fd-c326-42f7-9908-006504616d4c"],"platforms":"windows10","technologies":"mdm"},{"id":"cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","displayName":"WWAN Service","description":"Administrative Templates WWAN Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["eefc9ae4-b9ae-4d77-8b68-359b9e5ec6f7","edf3754c-b22d-4946-a744-4773240a5883"],"platforms":"windows10","technologies":"mdm"},{"id":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","displayName":"Desktop App Installer","description":"Administrative Templates Desktop App Installer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","displayName":"Uncategorized","description":"Microsoft Edge\\ Uncategorized","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"android,iOS,macOS,windows10","technologies":"mobileApplicationManagement"},{"id":"ceacf7fa-fa6e-434d-a381-e20e5245d180","displayName":"Co-authoring","description":"Microsoft PowerPoint 2016\\Collaboration Settings\\Co-authoring","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cebd5934-9dfe-4278-966d-b9d880cb30e7","displayName":"Windows Shutdown Performance Diagnostics","description":"Administrative Templates Windows Shutdown Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","displayName":"Windows Components","description":"Administrative Templates\\Windows Components","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["f60cd3c8-a91b-4542-b09f-129dfc7e589c","ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","845ff38a-408b-449c-9ef3-7fdc331027df"],"platforms":"windows10","technologies":"mdm"},{"id":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","displayName":"Networking","description":"Networking","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":["5c722b3f-9d77-428a-b859-3fb556162cd6","224dc683-c0e0-4783-8ba8-8f02c76d161d","e95335ec-2704-47ab-8b40-f602b31eeb9d","bbe51018-a17d-46c4-9517-ff45c54d8d18","06a85f5b-2614-4467-91cf-4a64d0c9326f","70b5da13-9c31-4857-890d-b7eb223729c3"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cf968979-f316-47cb-a207-bf9ef28cd1aa","displayName":"DSCP value of non-conforming packets","description":"Administrative Templates Qo S Packet Scheduler DSCP value of non-conforming packets","helpText":null,"parentCategoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","displayName":"Google","description":"Google","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":["36c83fb3-c18c-472b-b39e-617c2f8a7fbd","c3857f91-3df8-472f-9b5a-b10778c715c0"],"platforms":"windows10","technologies":"mdm"},{"id":"d0a1763a-5cdf-4672-8596-435ec1d94b54","displayName":"Search Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Search Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","displayName":"Application Settings","description":"Microsoft Access 2016\\Application Settings","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["33b9194b-4027-4c23-b662-52f25db7f839","23fd467e-24f8-4200-8b19-c6c11afa8926","bd1dad69-5cbe-415e-8565-e87b15cd4431","cbb98485-6a36-47b8-b450-7821e08507ac"],"platforms":"windows10","technologies":"mdm"},{"id":"d0e46713-238c-42b7-a996-653cf952c367","displayName":"Home Group","description":"Administrative Templates Home Group","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d0ff97aa-cf53-460e-be82-2c521a56eec6","displayName":"Outlook Options","description":"Microsoft Outlook 2016\\Outlook Options","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["f2bf77fd-37df-448b-8959-6478abf96f6f","1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","b9ab4d39-9e28-4897-aa34-0201a35ea989","5e3f61b6-52b7-4c74-a101-33c1cf34a749","114356a4-dfc9-44e9-9a62-f1d601d48445","d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","93a20c17-1e34-4778-8c95-91a46980ea75","fa6bfb01-34f6-4c54-89b9-f7e717e6d394","fcc8ad48-a1e7-4cba-adae-7c916cbbc897"],"platforms":"windows10","technologies":"mdm"},{"id":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","displayName":"HTTP authentication","description":"Microsoft Edge\\HTTP authentication","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d1e2bb0d-6c0e-4f40-9f2e-52055edc14b5","displayName":"Customize Ribbon","description":"Microsoft Excel 2016\\Excel Options\\Customize Ribbon","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d2191717-e304-46f7-bcc0-55e6477026c9","displayName":"Exclusion Settings","description":"Microsoft Defender Exclusion Settings","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","displayName":"Schedule View","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Schedule View","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d2f1d28a-682d-49e9-bb71-0782e4a06c1b","displayName":"Task Manager","description":"Task Manager","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d2f1d28a-682d-49e9-bb71-0782e4a06c1b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d33133b4-77df-429a-9580-ed70f7da676d","displayName":"Edit options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\Edit\\Edit options for Microsoft Project","helpText":null,"parentCategoryId":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d40a32e1-ab3e-4cbc-aa03-4766792e563e","displayName":"Performance Profiles Configuration","description":"Microsoft Defender Performance Profiles Configuration","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"d4943981-47b2-4a86-848b-860e8ca47381","displayName":"Microsoft Edge Update","description":"Microsoft Edge Update","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":["78497707-c3e4-400b-a6bc-1813c3689fdc","46eaa2b7-341b-4e39-be21-c3ea09dd5778","ff543267-540e-4e37-a1e9-daf6a5e16ba7","43fc9dcc-1e66-4108-bded-2d005eeb7ccb","2c7e8e8e-47fe-48ba-8cb4-55ce296edced"],"platforms":"windows10","technologies":"mdm"},{"id":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","displayName":"Privacy Sandbox policies","description":"Google Google Chrome Privacy Sandbox policies","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","displayName":"Delete Browsing History","description":"Administrative Templates Internet Explorer Delete Browsing History","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","displayName":"Windows Connection Manager","description":"Administrative Templates Windows Connection Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","displayName":"Security Form Settings","description":"Microsoft Outlook 2016\\Security\\Security Form Settings","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["e11f4bd4-9041-49c9-9b8c-163827d606ce","c400a917-cdff-4e15-a70f-59b82df4c038","a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec"],"platforms":"windows10","technologies":"mdm"},{"id":"d52dd970-febb-4891-8eb7-1c8616cfb6cb","displayName":"Desktop Window Manager","description":"Administrative Templates Desktop Window Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["349c31c1-9b5b-42c8-91f2-aa41f4a36a71"],"platforms":"windows10","technologies":"mdm"},{"id":"d59dfcc1-6c35-41de-bfb6-de94b8120ca5","displayName":"Predefined","description":"Microsoft Outlook 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"7652894d-4667-443f-b925-b1686a942729","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","displayName":"KDC","description":"Administrative Templates KDC","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d5b3cab7-d486-4f74-8525-6bd740b950bc","displayName":"Customizable Error Messages","description":"Microsoft Visio 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d5d99ca9-9995-4724-bc46-fd07f362898c","displayName":"Cellular","description":"Cellular","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d679b407-a753-40aa-bc9f-175f363b0eff","displayName":"File locations","description":"Microsoft Project 2016\\Project Options\\Save\\File locations","helpText":null,"parentCategoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d68abc4d-559a-4339-be48-c41a77a87034","displayName":"Passcode","description":"Security > Passcode","helpText":null,"parentCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","displayName":"Spelling","description":"Microsoft Outlook 2016\\Outlook Options\\Spelling","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d79c9f9a-f469-4f39-a66a-6f7d5ee77e81","displayName":"Language | Set Proofing Language...","description":"Microsoft Word 2016\\Review Tab\\Language | Set Proofing Language...","helpText":null,"parentCategoryId":"1fddd12c-a630-47f0-9633-638808e228f9","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d804205d-6c12-4f40-86a0-aa5a5355370f","displayName":"Files","description":"Microsoft Word 2016\\Word Options\\Advanced\\Web Options...\\Files","helpText":null,"parentCategoryId":"2108b443-384c-4bb3-9b9f-acb4a754a86a","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d875dca1-dc97-4cc5-9df3-c50b813622a3","displayName":"NS Extension Management","description":"App Management > NS Extension Management","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","displayName":"Finder","description":"User Experience > Finder","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"d9432f48-3072-4171-9031-4ebead394151","displayName":"Accessibility settings","description":"Google Google Chrome Accessibility settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9654cb3-57c8-487c-90a5-454e15336731","displayName":"External Intelligence Settings","description":"Declarative Device Management preview External Intelligence Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","displayName":"Kiosk Mode settings","description":"Microsoft Edge\\Kiosk Mode settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","displayName":"Default search provider","description":"Google Google Chrome - Default Settings users can override Default search provider","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d982a1ef-84be-4832-99d4-8b71a4644b74","displayName":"Network Connections","description":"Administrative Templates Network Connections","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9b5c806-099f-4be8-96e4-1152e99cbf26","displayName":"Check Accessibility","description":"Microsoft Excel 2016\\File tab\\Check Accessibility","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9d5f333-9402-4459-8ef1-e29330cac8be","displayName":"Live Share Settings","description":"Visual Studio Live Share Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9f5ccc9-5180-43b7-9c81-89ac3364ce00","displayName":"File Share Shadow Copy Provider","description":"Administrative Templates File Share Shadow Copy Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","displayName":"Readiness Toolkit","description":"Microsoft Office 2016\\Readiness Toolkit","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"da1503cb-e474-4545-8e77-cdd577f34a08","displayName":"Miscellaneous","description":"Microsoft PowerPoint 2016\\Miscellaneous","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["7aeaf6f8-5511-4216-9483-28f432a5a08f"],"platforms":"windows10","technologies":"mdm"},{"id":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","displayName":"First- Party Sets Settings","description":"Google Google Chrome First- Party Sets Settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"da92dfd6-a29e-42a0-92ed-276bb6904455","displayName":"PowerPoint Options","description":"Microsoft PowerPoint 2016\\PowerPoint Options","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["e2610f41-9a95-47e5-9fc9-572e26dc6baa","77ca5e78-a1fe-456e-9814-034b1ea2658d","f66fb7e4-a968-4969-b627-f99aaad0dfc3","85810387-3320-4056-bae2-953beeb246f7","c3b5e77d-c00d-4578-84c9-289362ad0b00","76b233cc-f977-4305-b02f-deef6667251d","f5007db5-6ee6-4bbd-a391-9727902aad6d"],"platforms":"windows10","technologies":"mdm"},{"id":"daa2ea69-8026-465a-942c-75eb0396d5b9","displayName":"Autonomous Single App Mode","description":"App Management > Autonomous Single App Mode","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","displayName":"Previous Versions","description":"Administrative Templates Previous Versions","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","displayName":"Shutdown Options","description":"Administrative Templates Shutdown Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","displayName":"Internet Formatting","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\Internet Formatting","helpText":null,"parentCategoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["25df12bc-5ebd-4db2-8930-5d27690f3e60"],"platforms":"windows10","technologies":"mdm"},{"id":"db47f067-f435-4095-8b98-aa3805bc0050","displayName":"Schedule","description":"Microsoft Project 2016\\Project Options\\Schedule","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["304a579b-ff3b-4897-8bb8-5a1dda45356f","3b2806c8-bd29-44b5-b3e0-b2c54a6008f3"],"platforms":"windows10","technologies":"mdm"},{"id":"dba1a547-e288-45ac-8553-27a3b564699e","displayName":"Custom","description":"Microsoft Access 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"b8158968-c839-4d37-9eb8-887bd6fd7402","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dba26132-cba6-4178-93c3-f02476532f08","displayName":"Keyboard Settings","description":"Declarative Device Management preview Keyboard Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","displayName":"Windows File Protection","description":"Administrative Templates\\System\\Windows File Protection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","displayName":"PKCS certificate","description":"PKCS certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dc049161-17c6-411e-906b-a871b33651cd","displayName":"Proofing","description":"Microsoft Word 2016\\Word Options\\Proofing","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["e95db55a-8337-416d-a61f-e60f55cc0d13","4dae3032-1f16-4ace-911b-a957db0b8089"],"platforms":"windows10","technologies":"mdm"},{"id":"dc16dbf0-aac8-4ff3-a546-1ddb55650f47","displayName":"Programs","description":"Administrative Templates Programs","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","displayName":"Parental Controls Content Filter","description":"Parental Controls > Parental Controls Content Filter","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"dd68a290-1ba7-470f-afca-339f443a767c","displayName":"MDM Options","description":"Managed Settings MDM Options","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","displayName":"Calculation options for 'Project1'","description":"Microsoft Project 2016\\Project Options\\Calculation\\Calculation options for 'Project1'","helpText":null,"parentCategoryId":"20ed0d61-bbf7-421e-8926-0921c7ff7e75","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["acbc106b-796a-4ba3-ab5f-c130530ad455"],"platforms":"windows10","technologies":"mdm"},{"id":"dd9a3dad-5851-4899-a5c1-c23318986846","displayName":"File Classification Infrastructure","description":"Administrative Templates File Classification Infrastructure","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dd9e4ae2-a432-4c48-a73a-52c75c3e5279","displayName":"Trusted Certificate","description":"Trusted Certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"dd9e4ae2-a432-4c48-a73a-52c75c3e5279","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ddb64e9d-34b9-44f4-9980-a6623f14e445","displayName":"Custom Profile","description":"Declarative Device Management preview Custom Profile","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"visionOS,tvOS","technologies":"appleRemoteManagement"},{"id":"ddcc8634-edc3-40ef-a444-45f806439c18","displayName":"Application Defaults","description":"Application Defaults","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ddcc8634-edc3-40ef-a444-45f806439c18","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"de643352-007f-4a47-8c83-d75a79516b39","displayName":"Deprecated policies","description":"Google Google Chrome - Default Settings users can override Deprecated policies","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"de9a9583-d660-4bdc-83bc-404c8c488267","displayName":"Memory Dump","description":"Memory Dump","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"de9a9583-d660-4bdc-83bc-404c8c488267","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dec8381a-0a61-406b-842b-fc6ae9930795","displayName":"Lock Screen Message","description":"System Configuration > Lock Screen Message","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"decab1d2-3474-4727-87c0-d0bc648f2458","displayName":"Calendar Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["2592e8ea-5eb0-482b-b41e-eab92f33ac07","d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","c6b72060-8ecb-41d8-8625-2984dd756d4a","826db7fb-889b-4a99-80a6-38347ba37f21","34c07941-8f52-43ad-b0ca-a7284655afb4"],"platforms":"windows10","technologies":"mdm"},{"id":"df357f0c-78fe-4aee-a465-f3da7499077e","displayName":"Proofing Data Collection","description":"Microsoft Office 2016\\Tools | Options | Spelling\\Proofing Data Collection","helpText":null,"parentCategoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dfab5866-1712-4bbf-8edf-5b080b315b9b","displayName":"Manageability","description":"Microsoft Edge\\Manageability","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"dfd5d749-c68c-448f-ab3f-851c09f09df4","displayName":"Auto Save Options","description":"Microsoft Project 2016\\Project Options\\Save\\Auto Save Options","helpText":null,"parentCategoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","displayName":"Locked- Down Local Machine Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Local Machine Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","displayName":"MSS (Legacy)","description":"Administrative Templates\\MSS (Legacy)","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e042b102-b12c-48d1-86ef-f6d296da5b95","displayName":"Server Manager","description":"Administrative Templates Server Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","displayName":"FSLogix","description":"FSLogix","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":["ab2be8b5-5912-4909-8d8b-e66edf4ab097","5c645a3e-bc39-44e9-8786-4c82e0553d22","0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","f2d139ed-a314-48b7-b700-4d11adfcc309"],"platforms":"windows10","technologies":"mdm"},{"id":"e0ab6868-4b53-4310-b665-f7c979941db7","displayName":"Safari Browser","description":"Declarative Device Management preview Safari Browser","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"e0dfe97e-348d-4d30-a6a1-e0de1989236e","displayName":"Other","description":"Microsoft Office 2016\\Language Preferences\\Other","helpText":null,"parentCategoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e0e10e94-325c-49e6-ab48-4f146254395f","displayName":"Form Region Settings","description":"Microsoft Outlook 2016\\Form Region Settings","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e11f4bd4-9041-49c9-9b8c-163827d606ce","displayName":"Custom Form Security","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Custom Form Security","helpText":null,"parentCategoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e13ec567-e29c-4ca0-b599-e8c43587f10a","displayName":"Tools | Local Project Cache","description":"Microsoft Project 2016\\Project Options\\Save\\Tools | Local Project Cache","helpText":null,"parentCategoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e1a2f289-40d8-4e7c-b0a6-cd36f0ee9111","displayName":"InfoPath Integration","description":"Microsoft Outlook 2016\\InfoPath Integration","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","displayName":"Proofing","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Proofing","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["b792508d-da03-4174-bcf1-666d128ee8ad"],"platforms":"windows10","technologies":"mdm"},{"id":"e2a41bef-2f82-409e-9d20-0fe335390f60","displayName":"Microsoft Excel 2016","description":"Microsoft Excel 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["1b6ac108-26b0-44f4-95a1-f848d1e90d76","b473c6fa-a971-4e5d-ad15-2c27c17c5d3e","5b832259-c30b-43bb-b249-9d3ea4d5b028","28831364-ca54-4f31-acca-1aa0c7a7d3d2","9a2bfe77-7e03-4a24-a9fa-c42a225a28b8","a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","bc58391f-664c-42dd-9d18-269e65f324a7","d9b5c806-099f-4be8-96e4-1152e99cbf26"],"platforms":"windows10","technologies":"mdm"},{"id":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","displayName":"Delivery Optimization","description":"Delivery Optimization","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e344b25a-2046-4e70-a3b9-1a418613861f","displayName":"Miscellaneous","description":"Microsoft Project 2016\\Miscellaneous","helpText":null,"parentCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","displayName":"Offline Address Book","description":"Microsoft Outlook 2016\\Account Settings\\Exchange\\Offline Address Book","helpText":null,"parentCategoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e36863b6-3232-4a29-be02-32ee67cc48b9","displayName":"External Content","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\External Content","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e3a7d1a6-ab02-4c88-86d9-0b541c033d13","displayName":"Federated Authentication","description":"Federated Authentication","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e3a7d1a6-ab02-4c88-86d9-0b541c033d13","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e3ca94a7-e506-4133-8fae-41931dc863a5","displayName":"Disk Diagnostic","description":"Administrative Templates Disk Diagnostic","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e42edcd8-fcb0-4255-a774-c78b34f0b0c9","displayName":"Desktop","description":"User Experience > Desktop","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","displayName":"E-mail","description":"Microsoft OneNote 2016\\OneNote Options\\E-mail","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e50acc0f-d177-4803-aa31-fc97eeb60ff2","displayName":"MSI Corrupted File Recovery","description":"Administrative Templates MSI Corrupted File Recovery","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e522c142-5666-4090-a7f4-1da1487f5384","displayName":"Co-authoring","description":"Microsoft Word 2016\\Collaboration Settings\\Co-authoring","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","displayName":"Disable Items in User Interface","description":"Microsoft PowerPoint 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","a20fe651-0f0a-4ddd-9d8b-273f17c89e22"],"platforms":"windows10","technologies":"mdm"},{"id":"e63361ad-a54b-4557-acc7-02c272a3e58d","displayName":"Smart cut and paste","description":"Microsoft Word 2016\\Word Options\\Advanced\\Smart cut and paste","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6911a08-946f-4b70-99cb-2a8b92c461e0","displayName":"Restrict ActiveX Install","description":"Administrative Templates Internet Explorer Security Features Restrict ActiveX Install","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6b767af-2ce1-4c91-9360-15abbb0bf3bc","displayName":"Remote FX USB Device Redirection","description":"Administrative Templates Remote FX USB Device Redirection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6f727b7-f474-4010-b214-83149ffdac2b","displayName":"Miscellaneous","description":"Microsoft Visio 2016\\Miscellaneous","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","displayName":"DNS Client","description":"Administrative Templates DNS Client","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e73ddc98-e465-43b0-bfd8-8a18cd9d4830","displayName":"Exploit Guard","description":"Exploit Guard","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e73ddc98-e465-43b0-bfd8-8a18cd9d4830","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"e7ae2b99-0479-475f-af5c-96457121fcd0","displayName":"Windows Hello For Business","description":"Windows Hello For Business","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","displayName":"Reporting","description":"Administrative Templates App-V Reporting","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e7dccaa6-2b16-4dd3-b835-83ca641d0c80","displayName":"Accessibility Settings","description":"Managed Settings Accessibility Settings","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","displayName":"Defender","description":"Defender","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"e865337e-db9f-4d4c-b9fe-35030792c942","displayName":"Microsoft Outlook 2016","description":"Microsoft Outlook 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","7652894d-4667-443f-b925-b1686a942729","f77040df-7dd2-4916-b6a0-5ef962686d4e","d0ff97aa-cf53-460e-be82-2c521a56eec6","e0e10e94-325c-49e6-ab48-4f146254395f","3f216590-fb12-4f8e-924f-2a6895d94126","75ad885f-6118-4508-a2fd-bb26be931c3f","b3e317cd-c580-478e-885c-666ce3079e78","92d9620c-92b6-45ec-b7d6-2f9ed0751e78","f5a1a387-6665-4527-b532-88a64a76e732","ee62e9fc-14c8-4f24-aa7e-89524087a802","e1a2f289-40d8-4e7c-b0a6-cd36f0ee9111","fb721630-fc42-465b-ba22-ab670698c8b5"],"platforms":"windows10","technologies":"mdm"},{"id":"e86f24d3-8531-4298-b064-692ea795b1d9","displayName":"Diagnostics","description":"Microsoft Office 2016 Diagnostics","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","displayName":"Compose Messages","description":"Microsoft Outlook 2016\\Outlook Options\\Mail\\Compose Messages","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e8ce968b-91cb-4301-ba98-b37d42bc5213","displayName":"Automatically as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type\\Automatically as you type","helpText":null,"parentCategoryId":"4dae3032-1f16-4ace-911b-a957db0b8089","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e905d6cf-7820-48d4-86e0-b55fa991a5ad","displayName":"Profile Removal Password","description":"Managed Devices > Profile Removal Password","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e905d6cf-7820-48d4-86e0-b55fa991a5ad","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","displayName":"Trusted Add-ins","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Programmatic Security\\Trusted Add-ins","helpText":null,"parentCategoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e95335ec-2704-47ab-8b40-f602b31eeb9d","displayName":"Content Caching","description":"Networking > Content Caching","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"e95db55a-8337-416d-a61f-e60f55cc0d13","displayName":"AutoCorrect","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoCorrect","helpText":null,"parentCategoryId":"dc049161-17c6-411e-906b-a871b33651cd","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e972d9fe-a9b7-4a65-a88f-0958fab19584","displayName":"App runtime","description":"Administrative Templates App runtime","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","displayName":"Power","description":"Power","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","displayName":"Session Time Limits","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Session Time Limits","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ea9a092f-dd93-41d4-9bbb-118de1213578","displayName":"Integration","description":"Administrative Templates App-V Integration","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","displayName":"IME (Japanese)","description":"Microsoft Office 2016\\IME (Japanese)","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb6409fc-fb52-413d-ae4b-eff017b52b30","displayName":"Experimentation","description":"Microsoft Edge\\ Experimentation","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb947c30-3c43-4d34-a566-a842a1a142f3","displayName":"Language Preferences","description":"Microsoft Office 2016\\Language Preferences","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["e0dfe97e-348d-4d30-a6a1-e0de1989236e","0f6020d9-278b-4284-894a-bc4a70c8cf32","3512a9f5-d692-4a1f-aedd-1bd431ae893e"],"platforms":"windows10","technologies":"mdm"},{"id":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","displayName":"Security","description":"Microsoft Word 2016\\Word Options\\Security","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["5f7e1206-359d-49d7-82c3-f6b6a6eddf65","a5ce858b-74c2-4663-9b3e-068d31349a13"],"platforms":"windows10","technologies":"mdm"},{"id":"ed137c3d-d7bc-48f3-ad86-ff194fc6820d","displayName":"Calculation options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\Calculation\\Calculation options for Microsoft Project","helpText":null,"parentCategoryId":"20ed0d61-bbf7-421e-8926-0921c7ff7e75","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ed24097d-3bb7-459c-83fb-f0090d1ad8dd","displayName":"Speech","description":"Speech","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ed24097d-3bb7-459c-83fb-f0090d1ad8dd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eda31027-9270-4959-801b-397fa05512e2","displayName":"Restrictions","description":"Restrictions","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"eda31027-9270-4959-801b-397fa05512e2","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"edd1e620-09e1-47ea-abc8-1e241a174ed9","displayName":"Locale Services","description":"Administrative Templates Locale Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"edf3754c-b22d-4946-a744-4773240a5883","displayName":"WWAN Media Cost","description":"Administrative Templates WWAN Service WWAN Media Cost","helpText":null,"parentCategoryId":"cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ee62e9fc-14c8-4f24-aa7e-89524087a802","displayName":"Customizable Error Messages","description":"Microsoft Outlook 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eec07ad3-24ef-4502-8125-9fc988650a7c","displayName":"Settings","description":"Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510","displayName":"General","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\General","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eefc9ae4-b9ae-4d77-8b68-359b9e5ec6f7","displayName":"WWAN UI Settings","description":"Administrative Templates WWAN Service WWAN UI Settings","helpText":null,"parentCategoryId":"cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","displayName":"Edge Workspaces settings","description":"Microsoft Edge Edge Workspaces settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"ef7328b1-c666-40fe-a933-57b14bc77dd3","displayName":"Wallpaper","description":"Managed Settings Wallpaper","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","displayName":"Native Messaging","description":"Microsoft Edge\\Native Messaging","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"ef8b8f2d-7791-4c44-a4f2-e39051f2e715","displayName":"Above Lock","description":"Above Lock","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ef8b8f2d-7791-4c44-a4f2-e39051f2e715","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"efabaf11-42e4-48ab-81ca-4514199d239b","displayName":"Scripting","description":"Administrative Templates App-V Scripting","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","displayName":"Trust Center","description":"Microsoft Office 2016\\Security Settings\\Trust Center","helpText":null,"parentCategoryId":"50b4bc60-802c-477a-9366-80e09154595f","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["24f6d328-64e7-4490-be38-452ac3b61f6f","135e4013-43b8-4227-99fd-54ddeac4e329","517e55f5-729f-4b4d-9555-33baa95a0e5a"],"platforms":"windows10","technologies":"mdm"},{"id":"effee722-f6ec-440e-a892-bf645bc341ff","displayName":"Reboot","description":"Reboot","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"effee722-f6ec-440e-a892-bf645bc341ff","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f00e9baf-9bbf-48e4-aaac-57410730f016","displayName":"Sign-in settings","description":"Google Google Chrome Sign-in settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f0190b73-0d5c-410e-bce1-e03aa1f62ed4","displayName":"Security Settings","description":"Microsoft Office 2016 (Machine)\\Security Settings","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":["fa8e7b34-c736-47ec-be83-a9f1960d5281"],"platforms":"windows10","technologies":"mdm"},{"id":"f019963f-f4ed-4429-b6e3-babfb24c36a8","displayName":"Parental Controls Application Restrictions","description":"Parental Controls > Parental Controls Application Restrictions","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","displayName":"Connectivity","description":"Connectivity","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f10138ba-123a-43bc-8031-4458ba327374","displayName":"Mixed Reality","description":"Mixed Reality","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f10138ba-123a-43bc-8031-4458ba327374","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","displayName":"Visio Options","description":"Microsoft Visio 2016\\Visio Options","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["2764869c-54a3-462b-bc72-c580621ab6bb","8495c82c-f273-4bcc-8886-6751103a9c7b","2ea63962-4cac-4a5c-9181-e6a364489db0","a7d55d90-e1d1-4577-8bfd-fe2641bce461","ad9610c6-d1c5-4c7a-9e74-58b810dd759d","957a5b24-ed7a-4f84-9d73-7b6131367396"],"platforms":"windows10","technologies":"mdm"},{"id":"f125d7cd-a333-4f24-a5f4-99fc289c6d22","displayName":"Package Management","description":"Administrative Templates App-V Package Management","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f1278d6b-60ec-4369-88cf-21df47caaec6","displayName":"Remote Procedure Call","description":"Administrative Templates Remote Procedure Call","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","displayName":"App Store","description":"App Store > App Store","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f1455024-7de9-448f-8d8f-a42db2af0a35","displayName":"Printer Redirection","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Printer Redirection","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","displayName":"Event Log Service","description":"Administrative Templates Event Log Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["1a2a4fc8-c54b-4906-a422-7dd51a196211","55a61bb8-e023-4741-8213-99995c5902e5","fecd321b-9a48-4f97-bbed-b335f9ccebdb","a28dd311-46e8-4868-89ab-d3745c0bca21"],"platforms":"windows10","technologies":"mdm"},{"id":"f26fe4c2-d073-4e51-90bf-61c4bbdeb4f2","displayName":"Privacy","description":"Administrative Templates Internet Explorer Privacy","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","displayName":"AutoArchive","description":"Microsoft Outlook 2016\\Outlook Options\\Other\\AutoArchive","helpText":null,"parentCategoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f2bf77fd-37df-448b-8959-6478abf96f6f","displayName":"Mail Format","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","88b16683-81f2-450a-9bf2-42f582e0b748","db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad"],"platforms":"windows10","technologies":"mdm"},{"id":"f2d139ed-a314-48b7-b700-4d11adfcc309","displayName":"Cloud Cache Service","description":"FS Logix Cloud Cache Service","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f3027ba5-9a2f-42c6-9872-ec21f726929c","displayName":"Early Launch Antimalware","description":"Administrative Templates Early Launch Antimalware","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f34e3da0-b440-43dc-a368-4fd39646a9c5","displayName":"Trust Center","description":"Microsoft Visio 2016\\Visio Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"2ea63962-4cac-4a5c-9181-e6a364489db0","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["75f9bfd8-8ee2-47b0-b080-a4d179724ca8"],"platforms":"windows10","technologies":"mdm"},{"id":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","displayName":"Device password","description":"Device Restriction Device password","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise,aosp","technologies":"android"},{"id":"f35cc803-3a06-4262-b38b-a5295321f756","displayName":"Extensible Single Sign On Kerberos","description":"Authentication > Extensible Single Sign On Kerberos","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm"},{"id":"f36a78cf-46cf-418e-a98e-032f6cfad224","displayName":"App Management","description":"App Management","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":["7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","8efd284f-5a56-4da8-8821-f51984ff954d","daa2ea69-8026-465a-942c-75eb0396d5b9","d875dca1-dc97-4cc5-9df3-c50b813622a3"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","displayName":"Smart Card","description":"Security > Smart Card","helpText":null,"parentCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","displayName":"Windows Media Player","description":"Administrative Templates Windows Media Player","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["902a93e8-8beb-46c5-ba26-4e2bf6161e22","2f85405a-7472-44ce-8c05-b59bb54912d5","7f461268-0fb6-4247-b6db-52515d42a20e"],"platforms":"windows10","technologies":"mdm"},{"id":"f5007db5-6ee6-4bbd-a391-9727902aad6d","displayName":"General","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\General","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f59804be-7fc6-43c3-9baa-942aab85be84","displayName":"Display","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Display","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f59f7502-cd01-4ea7-9925-2231f88596f0","displayName":"Dma Guard","description":"Dma Guard","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f59f7502-cd01-4ea7-9925-2231f88596f0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f5a1a387-6665-4527-b532-88a64a76e732","displayName":"Miscellaneous","description":"Microsoft Outlook 2016\\Miscellaneous","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["ffb0a109-2507-42b3-b26f-9f667f2d5029","cb6472c8-3e22-4029-af98-8a97f03a5a44"],"platforms":"windows10","technologies":"mdm"},{"id":"f5babdb3-c718-4675-b977-6c7bc7e6f886","displayName":"Check Accessibility","description":"Microsoft PowerPoint 2016\\File Tab\\Check Accessibility","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","displayName":"Internet Explorer","description":"Administrative Templates\\Windows Components\\Internet Explorer","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["89c0381d-3b9b-4be5-8077-ffb18d47e910"],"platforms":"windows10","technologies":"mdm"},{"id":"f62e0f2a-4363-4246-8057-1dc811fe4360","displayName":"System","description":"System","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","displayName":"Local Network Access settings","description":"Google Google Chrome Local Network Access settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f66fb7e4-a968-4969-b627-f99aaad0dfc3","displayName":"Customize Ribbon","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Customize Ribbon","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f69e6993-2e88-4938-bfe5-cea9ab21a858","displayName":"Windows Remote Shell","description":"Administrative Templates Windows Remote Shell","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","displayName":"Parental Controls Time Limits","description":"Parental Controls > Parental Controls Time Limits","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","displayName":"Windows Defender Security Center","description":"Windows Defender Security Center","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f7486553-9e63-4d63-9423-56e5ffe48700","displayName":"Google Cast","description":"Google Google Chrome Google Cast","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f77040df-7dd2-4916-b6a0-5ef962686d4e","displayName":"Meeting Workspace","description":"Microsoft Outlook 2016\\Meeting Workspace","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f8a973d8-b5d6-4d3e-9e82-63f61107fd0c","displayName":"Windows Licensing","description":"Windows Licensing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f8a973d8-b5d6-4d3e-9e82-63f61107fd0c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f8f4d337-4c55-4518-91c4-f7f77703d843","displayName":"Software Update","description":"System Updates > Software Update","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f926f6e3-1bd6-4259-ae7c-e14108568882","displayName":"Microsoft Support Diagnostic Tool","description":"Administrative Templates Microsoft Support Diagnostic Tool","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f9e53433-d8d9-4eaf-bdf3-d32de60d686e","displayName":"Customize Ribbon","description":"Microsoft Word 2016\\Word Options\\Customize Ribbon","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","displayName":"Subscribed Calendars","description":"Accounts Subscribed Calendars","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"fa2722a8-dcfd-4e14-a429-2b0041642c77","displayName":"Network settings","description":"Google Google Chrome Network settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","displayName":"Windows App","description":"Windows App","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","displayName":"Editing","description":"Microsoft OneNote 2016\\OneNote Options\\Editing","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa6bfb01-34f6-4c54-89b9-f7e717e6d394","displayName":"Customize Ribbon","description":"Microsoft Outlook 2016\\Outlook Options\\Customize Ribbon","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa8e7b34-c736-47ec-be83-a9f1960d5281","displayName":"IE Security","description":"Microsoft Office 2016 (Machine)\\Security Settings\\IE Security","helpText":null,"parentCategoryId":"f0190b73-0d5c-410e-bce1-e03aa1f62ed4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","displayName":"Microsoft Word 2016","description":"Microsoft Word 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["31070051-859e-4d27-9df3-c07b8a2d2179","12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","e522c142-5666-4090-a7f4-1da1487f5384","1fddd12c-a630-47f0-9633-638808e228f9","73bc2db9-d37f-4add-a64d-a8239273edb3","740e7a10-3774-4a1c-9970-6907e0f0b848","b8adcde1-500a-430f-8636-f97eaae2a2c6","320ccaa3-a391-4d29-a9c4-594561f4104d"],"platforms":"windows10","technologies":"mdm"},{"id":"fb1e99d0-b921-4b19-9842-17e3e7987528","displayName":"Edge Website Typo Protection settings","description":"Microsoft Edge Edge Website Typo Protection settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"fb721630-fc42-465b-ba22-ab670698c8b5","displayName":"Search Folders","description":"Microsoft Outlook 2016\\Search Folders","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","displayName":"Restricted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Restricted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","displayName":"Delegates","description":"Microsoft Outlook 2016\\Outlook Options\\Delegates","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","displayName":"Xsan Preferences","description":"Xsan > Xsan Preferences","helpText":null,"parentCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","rootCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"fddc444c-3591-4a50-865b-d8993b798e12","displayName":"Cast","description":"Microsoft Edge\\Cast","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"fe3cb879-8869-4163-91d7-e432abd75da8","displayName":"Scheduled Maintenance","description":"Administrative Templates Scheduled Maintenance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe54701d-42bd-47f0-9c49-26ff6a928b32","displayName":"Protected View","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe65603b-1980-446b-ae17-516eb885c6be","displayName":"Tablet PC Pen Training","description":"Administrative Templates Tablet PC Pen Training","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe786056-6f4a-4d16-bff4-5fbb640308d2","displayName":"Trusted Locations","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe7c8652-17d4-40a7-869c-f7cfc3454402","displayName":"Show indicators and Option butons for","description":"Microsoft Project 2016\\Project Options\\Interface\\Show indicators and Option butons for","helpText":null,"parentCategoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe845e81-5993-4a65-b22a-decfc5928c65","displayName":"Proxy server","description":"Microsoft Edge\\Proxy server","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","displayName":"Scareware Blocker settings","description":"Microsoft Edge - Default Settings users can override Scareware Blocker settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","displayName":"Application","description":"Administrative Templates Event Log Service Application","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","displayName":"Predefined","description":"Microsoft Visio 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"c67c9e69-6e69-4b63-868c-3b3df5d17e47","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ff543267-540e-4e37-a1e9-daf6a5e16ba7","displayName":"Proxy Server","description":"Microsoft Edge Update\\Proxy Server","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","displayName":"E-mail","description":"Microsoft Outlook 2016\\Account Settings\\E-mail","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","displayName":"Notifications","description":"User Experience > Notifications","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"ffb0a109-2507-42b3-b26f-9f667f2d5029","displayName":"Miscellaneous","description":"Microsoft Outlook 2016\\Miscellaneous\\Miscellaneous","helpText":null,"parentCategoryId":"f5a1a387-6665-4527-b532-88a64a76e732","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","displayName":"Microsoft Access 2016","description":"Microsoft Access 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["d0a3bbad-8ed0-4545-8249-9e464a13e1b7","6730f0be-a129-4b48-942f-e4ddf69fee66","b8158968-c839-4d37-9eb8-887bd6fd7402","c3ab8d44-b353-4a8a-a526-ffd743fb7ff8","607a1c39-a3db-496f-8db6-c99d67f5f76c"],"platforms":"windows10","technologies":"mdm"},{"id":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","displayName":"App Package Deployment","description":"Administrative Templates\\Windows Components\\App Package Deployment","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ffd1a98f-0fac-47fe-813f-7510d0dacbc3","displayName":"Windows Resource Exhaustion Detection and Resolution","description":"Administrative Templates Windows Resource Exhaustion Detection and Resolution","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","displayName":"Audio and Video","description":"Microsoft OneNote 2016\\OneNote Options\\Audio and Video","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fff51673-04b8-4277-98ef-4baffbd8d192","displayName":"Windows Calendar","description":"Administrative Templates Windows Calendar","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"}] diff --git a/Config/intuneCollection.json b/Config/intuneCollection.json index a779a571b2807..964376a36c188 100644 --- a/Config/intuneCollection.json +++ b/Config/intuneCollection.json @@ -1 +1 @@ -[{"id":".globalpreferences_.globalpreferences","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"1829cdc1-1bed-4058-9aba-9b778cd3d955","categoryName":"Global Preferences","options":null},{"id":".globalpreferences_com.apple.autologout.autologoutdelay","displayName":"Auto Log Out Delay","description":"The autologout delay, in seconds. A value of 0 means autologout is off. In some cases, this delay may be restricted to values between 5 minutes and 24 hours.","helpText":null,"infoUrls":[],"categoryId":"1829cdc1-1bed-4058-9aba-9b778cd3d955","categoryName":"Global Preferences","options":null},{"id":".globalpreferences_multiplesessionenabled","displayName":"Multiple Session Enabled","description":"If false, disables fast user switching.","helpText":null,"infoUrls":[],"categoryId":"1829cdc1-1bed-4058-9aba-9b778cd3d955","categoryName":"Global Preferences","options":[{"id":".globalpreferences_multiplesessionenabled_false","displayName":"False","description":null,"helpText":null},{"id":".globalpreferences_multiplesessionenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetversionprefixmicrosoftedge","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetversionprefixmicrosoftedge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetversionprefixmicrosoftedge_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetversionprefixmicrosoftedge_part_targetversionprefix","displayName":"Target version (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","categoryName":"Microsoft Edge Beta","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta_part_targetversionprefix","displayName":"Target version (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","categoryName":"Microsoft Edge Beta","options":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary_part_targetversionprefix","displayName":"Target version (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"13f62499-a266-42c8-a4dc-531efcea55cb","categoryName":"Microsoft Edge Dev","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev_part_targetversionprefix","displayName":"Target version (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"13f62499-a266-42c8-a4dc-531efcea55cb","categoryName":"Microsoft Edge Dev","options":null},{"id":"3~policy~microsoft_edge_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 102.\r\n\r\nIf you enable this policy or leave it unset, the window.opener property is set to null unless the anchor specifies rel=\"opener\".\r\n\r\nIf you disable this policy, popups that target _blank are permitted to access (via JavaScript) the page that requested to open the popup.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"3~policy~microsoft_edge_targetblankimpliesnoopener_0","displayName":"Disabled","description":null,"helpText":null},{"id":"3~policy~microsoft_edge_targetblankimpliesnoopener_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"3~policy~microsoft_edge~httpauthentication_basicauthoverhttpenabled","displayName":"Allow Basic authentication for HTTP (User)","description":"If you enable this policy or leave it unset, Basic authentication challenges received over non-secure HTTP will be allowed.\r\n\r\nIf you disable this policy, non-secure HTTP requests from the Basic authentication scheme are blocked, and only secure HTTPS is allowed.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"3~policy~microsoft_edge~httpauthentication_basicauthoverhttpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"3~policy~microsoft_edge~httpauthentication_basicauthoverhttpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"ade_accountsettings_adminaccountfullname","displayName":"Admin account full name","description":"The full name for the administrator account. This field is to be defaulted to 'Admin'.","helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},{"id":"ade_accountsettings_adminaccountname","displayName":"Admin account username","description":"The account name for the administrator account. This field is to be defaulted to 'Admin'. For macOS ADE enrollment policies without user device affinity, we recommend configuring {{serialNumber}} as the unique identifier of userless devices.","helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},{"id":"ade_accountsettings_adminaccountpasswordrotation","displayName":"Admin account password rotation period (days)","description":null,"helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},{"id":"ade_accountsettings_createlocaladmin","displayName":"Create a local admin account","description":null,"helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_createlocaladmin_0","displayName":"No","description":null,"helpText":null},{"id":"ade_accountsettings_createlocaladmin_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_accountsettings_createlocalprimary","displayName":"Create a local primary account","description":null,"helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_createlocalprimary_0","displayName":"No","description":null,"helpText":null},{"id":"ade_accountsettings_createlocalprimary_1","displayName":"Yes - Standard Account Type","description":null,"helpText":null},{"id":"ade_accountsettings_createlocalprimary_2","displayName":"Yes - Administrator Account Type","description":null,"helpText":null}]},{"id":"ade_accountsettings_hideusersgroups","displayName":"Hide in Users and Groups","description":"Make the admin account hidden in the login window and Users & Groups.","helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_hideusersgroups_0","displayName":"Not Configured","description":null,"helpText":null},{"id":"ade_accountsettings_hideusersgroups_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_accountsettings_prefillaccountinfo","displayName":"Prefill account info","description":"If you select 'Yes', the account name and full name must be configured. Not configured allows the end user to configure these fields.","helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_prefillaccountinfo_0","displayName":"Not Configured","description":null,"helpText":null},{"id":"ade_accountsettings_prefillaccountinfo_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_accountsettings_primaryaccountfullname","displayName":"Primary account full name","description":"The full name for the account. Setup Assistant will user this value to prefill the Full Name field if 'Prefill account info' is set to 'Not configured'. This field is to be defaulted to the variable, {{username}}, for example, 'John Doe'.","helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},{"id":"ade_accountsettings_primaryaccountname","displayName":"Primary account name","description":"The account name for the account. Setup Assistant will use this value to prefill the Account Name field if 'Prefill account info' is set to 'Not configured'. This field is to be defaulted to the variable, {{partialupn}}, for example, 'John'. For macOS ADE enrollment policies without user device affinity, we recommend configuring {{serialNumber}} as the unique identifier of userless devices.","helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},{"id":"ade_accountsettings_restrictediting","displayName":"Restrict editing","description":"Prevent the end user from editing the full name and account name","helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_restrictediting_0","displayName":"Not configured","description":null,"helpText":null},{"id":"ade_accountsettings_restrictediting_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_activatecellulardata","displayName":"Carrier activation server URL","description":"","helpText":"http://activation.carrier.net","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_activatecellulardatachoices","displayName":"Activate cellular data","description":"Activates cellular data plans for devices enabled for eSIM. The carrier must enable activation for devices before you can use this command. You can also activate any time after device enrollment.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_activatecellulardatachoices_0","displayName":"No","description":null,"helpText":null},{"id":"ade_activatecellulardatachoices_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_appleconfiguratorcertificates","displayName":"Apple Configurator certificates","description":"Required to sync data with a supervised device. Make sure you save a local copy of the certificate that you can access later. You won't be able to make changes to the uploaded copy.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_appledevicenametemplate","displayName":"Device name template","description":"Create a unique name for your devices. Names must be 63 characters or less, and can contain letters (a-z, A-Z), numbers (0-9), and hyphens.Variables supported: {{SERIAL}}, {{DEVICETYPE}}","helpText":"{{DEVICETYPE}}-{{SERIAL}}","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_authenticationmethod","displayName":"Intune authentication method","description":"If your organization uses multifactor authentication, select Setup Assistant with modern authentication, which prompts users to authenticate based on settings in Entra.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":{"id":"ade_authenticationmethod_2","displayName":"Setup Assistant with modern authentication","description":null,"helpText":null}},{"id":"ade_awaitconfiguration_basic","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_awaitconfiguration_basic_0","displayName":"No","description":null,"helpText":null},{"id":"ade_awaitconfiguration_basic_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_devicenametemplatechoices","displayName":"Apple device name template","description":"You can create a standard naming format to make it easier to name devices as they enroll in Intune. By default, Apple uses the device type (such as iPad or iPhone) and serial number to name ADE devices.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_devicenametemplatechoices_0","displayName":"No","description":null,"helpText":null},{"id":"ade_devicenametemplatechoices_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_lockedenrollment","displayName":"Locked enrollment","description":"Blocks the user from removing the management profile through the Settings menu.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_lockedenrollment_0","displayName":"No","description":null,"helpText":null},{"id":"ade_lockedenrollment_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_macos_authenticationmethod","displayName":"Intune authentication method","description":"If your organization uses multifactor authentication, select Setup Assistant with modern authentication, which prompts users to authenticate based on settings in Entra.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":{"id":"ade_macos_authenticationmethod_2","displayName":"Setup Assistant with modern authentication","description":null,"helpText":null}},{"id":"ade_macos_awaitconfiguration","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_macos_awaitconfiguration_0","displayName":"No","description":null,"helpText":null},{"id":"ade_macos_awaitconfiguration_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_macos_useraffinity","displayName":"User affinity","description":"User affinity associates devices with users. Users must authenticate to enroll with user affinity.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_macos_useraffinity_1","displayName":"Enroll with user affinity","description":null,"helpText":null},{"id":"ade_macos_useraffinity_0","displayName":"Enroll without user affinity","description":null,"helpText":null}]},{"id":"ade_maximumcachedusers","displayName":"Maximum cached users","description":"The maximum number of users that can use a Shared iPad. You can cache up to 24 users on a 32GB or 64GB device.","helpText":null,"infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_maximumsecondsafterscreenlockbeofrepasswordisrequired","displayName":"Maximum seconds after screen lock before password is required","description":"Available for Shared iPads. Maximum seconds after screen lock before password is required (0-14,400 seconds). If a device has a passcode, a change to a larger value doesn’t take effect until the user logs out or removes the passcode.","helpText":"Enter value","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_maximumsecondsinactivityuntiltemporarysessionlogsout","displayName":"Maximum seconds of inactivity until temporary session logs out","description":"Available for devices running iPadOS versions 14.5 and later. Enter a value in seconds (minimum value to add is 30 seconds). If there isn't any activity after the value you enter, then the temporary session automatically signs out. If you set the value to anything between 0-29, then the temporary session stays signed in. ","helpText":"Enter value","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_maximumsecondsinactivityuntiluserlogsout","displayName":"Maximum seconds of inactivity until user session logs out","description":"Available for devices running iPadOS versions 14.5 and later. Enter a value in seconds (minimum value to add is 30 seconds). If there isn't any activity after the value you enter, the user session automatically signs out. If you set the value to anything between 0-29, then the user session stays signed in.","helpText":"Enter value","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_modernauth_awaitfinalconfiguration","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_modernauth_awaitfinalconfiguration_0","displayName":"No","description":null,"helpText":null},{"id":"ade_modernauth_awaitfinalconfiguration_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_requiresharedipadtemporarysessiononly","displayName":"Require Shared iPad temporary session only","description":"Available for devices running iPadOS versions 14.5 and later. When set to Yes, users only see the Guest Welcome pane, and can only sign in as a guest user. Users can't sign in with a Managed Apple ID.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_requiresharedipadtemporarysessiononly_0","displayName":"Not configured","description":null,"helpText":null},{"id":"ade_requiresharedipadtemporarysessiononly_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_setupassistant_accessibility","displayName":"Accessibility","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_accessibility_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_accessibility_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_actionbutton","displayName":"Action Button","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_actionbutton_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_actionbutton_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_androidmigration","displayName":"Android migration","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_androidmigration_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_androidmigration_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_appearance","displayName":"Appearance","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_appearance_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_appearance_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_appleid","displayName":"Apple ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_appleid_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_appleid_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_applepay","displayName":"Apple Pay","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_applepay_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_applepay_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_appstore","displayName":"App Store","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_appstore_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_appstore_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_camerabutton","displayName":"Camera button","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_camerabutton_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_camerabutton_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_department","displayName":"Department","description":null,"helpText":"Appears to users on About Configuration screen","infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":null},{"id":"ade_setupassistant_departmentphone","displayName":"Department phone","description":null,"helpText":"Appears to users on About Configuration screen","infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":null},{"id":"ade_setupassistant_devicemigration","displayName":"Device to device migration","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_devicemigration_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_devicemigration_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_diagnosticsdata","displayName":"Diagnostics Data","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_diagnosticsdata_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_diagnosticsdata_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_enablelockdownmode","displayName":"Enable Lock down Mode","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_enablelockdownmode_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_enablelockdownmode_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_filevault","displayName":"FileVault","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_filevault_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_filevault_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_getstarted","displayName":"Get Started","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_getstarted_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_getstarted_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_iclouddiagnostics","displayName":"iCloud Diagnostics","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_iclouddiagnostics_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_iclouddiagnostics_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_icloudstorage","displayName":"iCloud Storage","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_icloudstorage_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_icloudstorage_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_imessagefacetime","displayName":"iMessage and FaceTime","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_imessagefacetime_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_imessagefacetime_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_intelligence","displayName":"Intelligence","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_intelligence_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_intelligence_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_locationservices","displayName":"Location services","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_locationservices_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_locationservices_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_multitasking","displayName":"Multitasking","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_multitasking_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_multitasking_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_osshowcase","displayName":"OS showcase","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_osshowcase_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_osshowcase_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_passcode","displayName":"Passcode","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_passcode_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_passcode_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_privacy","displayName":"Privacy","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_privacy_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_privacy_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_restore","displayName":"Restore","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_restore_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_restore_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_restorecompleted","displayName":"Restore completed","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_restorecompleted_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_restorecompleted_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_safety","displayName":"Emergency SOS","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_safety_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_safety_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_safetyandhandling","displayName":"Safety and handling","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_safetyandhandling_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_safetyandhandling_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_screensaver","displayName":"Screen Saver","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_screensaver_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_screensaver_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_screentime","displayName":"Screen Time","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_screentime_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_screentime_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_simsetup","displayName":"SIM setup","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_simsetup_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_simsetup_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_siri","displayName":"Siri","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_siri_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_siri_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_softwareupdate","displayName":"Software Update","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_softwareupdate_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_softwareupdate_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_softwareupdatecompleted","displayName":"Software Update completed","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_softwareupdatecompleted_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_softwareupdatecompleted_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_taptosetup","displayName":"Tap to Setup","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_taptosetup_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_taptosetup_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_termsandconditions","displayName":"Terms and conditions","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_termsandconditions_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_termsandconditions_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_termsofaddress","displayName":"Terms of Address","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_termsofaddress_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_termsofaddress_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_tips","displayName":"Tips","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_tips_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_tips_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_touchfaceid","displayName":"Touch ID and Face ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_touchfaceid_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_touchfaceid_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_tvhomescreensync","displayName":"TV Home Screen Sync","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_tvhomescreensync_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_tvhomescreensync_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_tvprovidersignin","displayName":"TV Provider Sign In","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_tvprovidersignin_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_tvprovidersignin_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_tvroom","displayName":"TV Room","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_tvroom_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_tvroom_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_unlockwithwatch","displayName":"Auto unlock with Apple Watch","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_unlockwithwatch_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_unlockwithwatch_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_voiceselection","displayName":"Voice selection","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_voiceselection_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_voiceselection_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_watchmigration","displayName":"Watch migration","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_watchmigration_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_watchmigration_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_webcontentfiltering","displayName":"Web Content Filtering","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_webcontentfiltering_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_webcontentfiltering_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_useraffinity","displayName":"User affinity","description":"User affinity associates devices with users. Users must authenticate to enroll with user affinity.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_useraffinity_1","displayName":"Enroll with user affinity","description":null,"helpText":null},{"id":"ade_useraffinity_0","displayName":"Enroll without user affinity","description":null,"helpText":null},{"id":"ade_useraffinity_2","displayName":"Enroll with Microsoft Entra ID shared mode","description":null,"helpText":null},{"id":"ade_useraffinity_3","displayName":"Enroll with Shared iPad","description":null,"helpText":null}]},{"id":"ade_useraffinity_awaitfinalconfiguration","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_useraffinity_awaitfinalconfiguration_0","displayName":"No","description":null,"helpText":null},{"id":"ade_useraffinity_awaitfinalconfiguration_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_useraffinitybasic","displayName":"User affinity","description":"User affinity associates devices with users. Users must authenticate to enroll with user affinity.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":{"id":"ade_useraffinitybasic_0","displayName":"Enroll without user affinity","description":null,"helpText":null}},{"id":"app_allowed","displayName":"Allowed","description":"The dictionary of allowed app settings.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_allowedapps","displayName":"Allowed Apps","description":"If present, the device only shows or launches apps with bundle IDs in the array. Include the value `com.apple.webapp` to allow all webclips. This applies to App Store apps, marketplace apps, and locally installed apps (using Configurator, Xcode, and so forth).","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_allowedbinaries","displayName":"Allowed Binaries","description":"If present, the device only allows binaries that match the binary identifier properties to run. A binary only matches when all the binary identifiers match. The device always runs system critical processes. Use \"codesign -dvvv \" to show the information you need to generate these values.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_allowedbinaries_item_cdhash","displayName":"CD Hash","description":"The code signature code directory hash of the binary.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_allowedbinaries_item_pathprefix","displayName":"Path Prefix","description":"The file system path prefix to match binaries.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_allowedbinaries_item_signingid","displayName":"Signing ID","description":"The code signature signing identifier of the binary.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_allowedbinaries_item_signingstate","displayName":"Signing State","description":"The code signing state to match binaries.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_allowed_allowedbinaries_item_signingstate_0","displayName":"All","description":null,"helpText":null},{"id":"app_allowed_allowedbinaries_item_signingstate_1","displayName":"TestFlight","description":null,"helpText":null},{"id":"app_allowed_allowedbinaries_item_signingstate_2","displayName":"DeveloperID","description":null,"helpText":null},{"id":"app_allowed_allowedbinaries_item_signingstate_3","displayName":"Enterprise","description":null,"helpText":null},{"id":"app_allowed_allowedbinaries_item_signingstate_4","displayName":"AppStore","description":null,"helpText":null},{"id":"app_allowed_allowedbinaries_item_signingstate_5","displayName":"Apple","description":null,"helpText":null}]},{"id":"app_allowed_allowedbinaries_item_teamid","displayName":"Team ID","description":"The code signature team identifier of the binary. Use the value \"*APPLE*\" instead of an empty string for Apple binaries with an empty team identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_alwaysallowmanagedapps","displayName":"Always Allow Managed Apps","description":"If `true`, the device implicitly includes managed apps in the effective allow list when `AllowedApps` or `AllowedBinaries` is present.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_allowed_alwaysallowmanagedapps_false","displayName":"Blocked","description":null,"helpText":null},{"id":"app_allowed_alwaysallowmanagedapps_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"app_allowed_deniedapps","displayName":"Denied Apps","description":"If present, the device prevents showing or launching apps with bundle IDs in the\narray. Include the value `com.apple.webapp` to restrict all webclips. This applies to\nApp Store apps, marketplace apps, and locally installed apps (using Configurator,\nXcode, and so forth).\n> Note:\n> Denying system apps may disable other functionality. For example, denying the App\nStore app may prevent users from accepting the terms and conditions for the user-based\nVolume Purchase Program (VPP).","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_deniedbinaries","displayName":"Denied Binaries","description":"If present, the device doesn't allow binaries that match the binary identifier properties to run. A binary only matches when all the binary identifiers match.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_deniedbinaries_item_cdhash","displayName":"CD Hash","description":"The code signature code directory hash of the binary.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_deniedbinaries_item_pathprefix","displayName":"Path Prefix","description":"The file system path prefix to match binaries.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_deniedbinaries_item_signingid","displayName":"Signing ID","description":"The code signature signing identifier of the binary.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_deniedbinaries_item_signingstate","displayName":"Signing State","description":"The code signing state to match binaries.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_allowed_deniedbinaries_item_signingstate_0","displayName":"All","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_1","displayName":"TestFlight","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_2","displayName":"DeveloperID","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_3","displayName":"Enterprise","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_4","displayName":"AppStore","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_5","displayName":"Apple","description":null,"helpText":null}]},{"id":"app_allowed_deniedbinaries_item_teamid","displayName":"Team ID","description":"The code signature team identifier of the binary. Use the value \"*APPLE*\" instead of an empty string for Apple binaries with an empty team identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_app","displayName":"com.apple.configuration.app.settings","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_privacy","displayName":"Privacy","description":"The dictionary of app settings.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_privacy_permissiondefaults","displayName":"Permission Defaults","description":"The dictionary of app privacy permission defaults. Each key in the dictionary is an app identifier. The dictionary values represent the permission defaults that the device applies for each matching app.\n\nIn iOS, the app identifier is a bundle ID, for example, \"com.example.app\".\n\nIn macOS, the app identifier is a composed identifier. The format of the composed identifier is either \"Bundle-ID\", \"Bundle-ID (Team-ID)\", or \"Bundle-ID {Designated-Requirement}\". \"Bundle-ID\" is the bundle identifier string of the app. \"Team-ID\" is the team identifier from the app's code signature. \"Designated-Requirement\" is the designated requirement string from the code signature of the app. For example, \"com.example.app\" for the bundle ID format, \"com.example.app (ABCD1234)\" for the team ID format, or \"com.example.app {anchor apple generic}\" for the designated requirement format. The device only applies defaults for an app if its code signature matches the composed identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_privacy_permissiondefaults_generickey","displayName":"ANY","description":"The dictionary that defines the app privacy permission defaults. Each key is an app identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_privacy_permissiondefaults_generickey_accessibility","displayName":"Accessibility","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of accessibility.\n* `Allow`: The app privacy permission default is set to allow use of accessibility.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_accessibility_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_accessibility_1","displayName":"Allow","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_bluetooth","displayName":"Bluetooth","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of Bluetooth.\n* `Allow`: The app privacy permission default is set to allow use of Bluetooth.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_bluetooth_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_bluetooth_1","displayName":"Allow","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_camera","displayName":"Camera","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of the camera.\n* `Allow`: The app privacy permission default is set to allow use of the camera.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_camera_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_camera_1","displayName":"Allow","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_dictation","displayName":"Dictation","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of dictation.\n* `Allow`: The app privacy permission default is set to allow use of dictation.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_dictation_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_dictation_1","displayName":"Allow","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_keytobereplaced","displayName":"Permission Defaults","description":"The dictionary of app privacy permission defaults. Each key in the dictionary is an app identifier. The dictionary values represent the permission defaults that the device applies for each matching app.\n\nIn iOS, the app identifier is a bundle ID, for example, \"com.example.app\".\n\nIn macOS, the app identifier is a composed identifier. The format of the composed identifier is either \"Bundle-ID\", \"Bundle-ID (Team-ID)\", or \"Bundle-ID {Designated-Requirement}\". \"Bundle-ID\" is the bundle identifier string of the app. \"Team-ID\" is the team identifier from the app's code signature. \"Designated-Requirement\" is the designated requirement string from the code signature of the app. For example, \"com.example.app\" for the bundle ID format, \"com.example.app (ABCD1234)\" for the team ID format, or \"com.example.app {anchor apple generic}\" for the designated requirement format. The device only applies defaults for an app if its code signature matches the composed identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_privacy_permissiondefaults_generickey_localnetwork","displayName":"Local Network","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of the local network.\n* `Allow`: The app privacy permission default is set to allow use of the local network.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_localnetwork_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_localnetwork_1","displayName":"Allow","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_location","displayName":"Location","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for access to location.\n* `WhileUsing`: The app privacy permission default is set to allow access to location only while the user is using the app In macOS, this is equivalent to `Always`.\n* `Always`: The app privacy permission default is set to allow access to location always.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_location_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_location_1","displayName":"WhileUsing","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_location_2","displayName":"Always","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_locationaccuracy","displayName":"Location Accuracy","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for access to precise location.\n* `Approximate`: The app privacy permission default is set to allow approximate access to location.\n* `Precise`: The app privacy permission default is set to allow precise access to location.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_locationaccuracy_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_locationaccuracy_1","displayName":"Approximate","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_locationaccuracy_2","displayName":"Precise","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_microphone","displayName":"Microphone","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of the microphone.\n* `Allow`: The app privacy permission default is set to allow use of the microphone.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_microphone_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_microphone_1","displayName":"Allow","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_organizationjustification","displayName":"Organization Justification","description":"Text you provide that clearly explains to the user the reason why the organization requires these app permission defaults. The device includes this text in the permission consent prompt it displays when it launches the app.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"apple_customprofile_profile","displayName":"Profile","description":"A admin uploaded profile to install.","helpText":null,"infoUrls":[],"categoryId":"ddb64e9d-34b9-44f4-9980-a6623f14e445","categoryName":"Custom Profile","options":null},{"id":"audioaccessory_audioaccessory","displayName":"com.apple.configuration.audio-accessory.settings","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":null},{"id":"audioaccessory_temporarypairing","displayName":"Temporary Pairing","description":"A dictionary that describes audio accessory temporary pairing behavior. The device enables temporary pairing when this key is present and the `Disabled` key isn't `false`. The device doesn't synchronize pairing information with iCloud when temporary pairing is active.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":null},{"id":"audioaccessory_temporarypairing_configuration","displayName":"Configuration","description":"A dictionary providing configuration for temporary pairing. Required if `Disabled` isn't present or is `false`.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":null},{"id":"audioaccessory_temporarypairing_configuration_unpairingtime","displayName":"Unpairing Time","description":"A dictionary that describes when the device automatically unpairs temporarily paired audio accessories.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":null},{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_hour","displayName":"Hour","description":"The local time hour (24-hour clock) when the device automatically unpairs temporarily paired audio accessories. Required when setting the `Policy` key to `Hour`.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":null},{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_policy","displayName":"Policy","description":"A string that specifies the device's unpairing policy.\n- `None`: The device doesn't automatically unpair. Use this only with a return to service device that you erase and reenroll when assigning it from one user to another.\n- `Hour`: The device automatically unpairs temporarily paired audio accessories at the local time that the `Hour` key specifies.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":[{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_policy_0","displayName":"None","description":null,"helpText":null},{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_policy_1","displayName":"Hour","description":null,"helpText":null}]},{"id":"audioaccessory_temporarypairing_disabled","displayName":"Disabled","description":"If `true`, temporary pairing of audio accessories is disabled.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":[{"id":"audioaccessory_temporarypairing_disabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"audioaccessory_temporarypairing_disabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.android.devicerestrictionpolicy.accountsblockmodification","displayName":"Block account changes","description":"If 'True', prevents users from updating or changing accounts when in kiosk mode. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to update user accounts on the device. Available for dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"aad0d3ef-88f5-4b22-831b-27093eafbc64","categoryName":"Users and Accounts","options":[{"id":"com.android.devicerestrictionpolicy.accountsblockmodification_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.accountsblockmodification_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.airplanemodeblocked","displayName":"Block airplane mode","description":"If 'True', the device is prevented from enabling airplane mode. If 'False', Intune doesn't change or update this setting. By default, the OS follows the default airplane mode behavior. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.airplanemodeblocked_false","displayName":"False","description":"The user is allowed to toggle airplane mode on or off.","helpText":null},{"id":"com.android.devicerestrictionpolicy.airplanemodeblocked_true","displayName":"True","description":"Airplane mode is disabled. The user is not allowed to toggle airplane mode on or off.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.appfunctions","displayName":"Block apps from exposing app functions","description":"If 'True', apps on fully managed devices, and apps in the work profile on corporate-owned devices with a work profile, are blocked from exposing app functions. If 'False', apps are allowed to expose app functions, which is the default OS behavior. Available for fully managed, dedicated, and corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"2257f7e1-3e88-4d4d-a666-437bbe42baca","categoryName":"Applications","options":[{"id":"com.android.devicerestrictionpolicy.appfunctions_false","displayName":"False","description":"Apps are allowed to expose app functions.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appfunctions_true","displayName":"True","description":"Apps are blocked from exposing app functions.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.appsallowinstallfromunknownsources","displayName":"Allow installation from unknown sources","description":"If 'True', allows users to enable unknown sources. This setting permits app installation from sources other than the Google Play Store, enabling users to side-load apps through alternative methods. If 'False', Intune doesn't change or update this setting. By default, the OS may prevent users from enabling unknown sources. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"2257f7e1-3e88-4d4d-a666-437bbe42baca","categoryName":"Applications","options":[{"id":"com.android.devicerestrictionpolicy.appsallowinstallfromunknownsources_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsallowinstallfromunknownsources_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy","displayName":"App auto-updates (work profile-level)","description":"Define the auto update policy for apps. Devices check for app updates daily. If set to 'User choice', the end user can set their preference in managed Google Play. If set to 'Never', apps will never auto-update. If set to 'Wi-Fi only', apps will only auto-update when the device is connected to Wi-Fi. If set to 'Always', apps will always auto-update. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"","infoUrls":[],"categoryId":"2257f7e1-3e88-4d4d-a666-437bbe42baca","categoryName":"Applications","options":[{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_notconfigured","displayName":"Not configured","description":"Not configured; this value is ignored.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_userchoice","displayName":"User choice","description":"The user can control auto-updates.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_never","displayName":"Never","description":"Apps are never auto-updated.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_wifionly","displayName":"Wi-Fi only","description":"Apps are auto-updated over Wi-Fi only.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_always","displayName":"Always","description":"Apps are auto-updated at any time. Data charges may apply.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.appsblockinstallfromunknownsourcesaosp","displayName":"Block user from turning on unknown sources","description":"If 'True', prevents users from sideloading apps. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to sideload apps from unknown sources.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.appsblockinstallfromunknownsourcesaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsblockinstallfromunknownsourcesaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.appsdefaultpermissionpolicy","displayName":"Default permission policy (work profile-level)","description":"Define the default permission policy for requests for runtime permissions. Available for fully managed, dedicated and corporate-owned work profile (at work profile level) devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.appsdefaultpermissionpolicy_devicedefault","displayName":"Device default","description":"Device default value, no intent.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsdefaultpermissionpolicy_prompt","displayName":"Prompt","description":"Prompt.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsdefaultpermissionpolicy_autogrant","displayName":"Auto grant","description":"Auto grant.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsdefaultpermissionpolicy_autodeny","displayName":"Auto deny","description":"Auto deny.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.appsrecommendskippingfirstusehints","displayName":"Skip first use hints","description":"If 'True', hides or skips suggestions from apps that step through tutorials, or hints when the app starts. If 'False', Intune doesn't change or update this setting. By default, the OS might show these suggestions when the app starts. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.appsrecommendskippingfirstusehints_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsrecommendskippingfirstusehints_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.assistcontentpolicy","displayName":"Block assist content sharing with privileged apps","description":"If 'True', blocks assist content (such as screenshots and app details) to be sent to a privileged app, like an assistant app. The setting can be used to block Circle to Search (AI feature). If set to 'False', Intune doesn't change or update this setting. By default, the OS might allow sharing assist content with privileged apps. Available for fully managed, dedicated, and corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.assistcontentpolicy_false","displayName":"False","description":"Assist content is allowed to be sent to a privileged app.","helpText":null},{"id":"com.android.devicerestrictionpolicy.assistcontentpolicy_true","displayName":"True","description":"Assist content is blocked from being sent to a privileged app.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.bluetoothblockconfiguration","displayName":"Block Bluetooth configuration","description":"If 'True', prevents users from configuring Bluetooth on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow using Bluetooth on the device. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblockconfiguration_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblockconfiguration_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.bluetoothblockconfigurationaosp","displayName":"Block Bluetooth configuration","description":"If 'True', prevents users from configuring Bluetooth on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to configure Bluetooth.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblockconfigurationaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblockconfigurationaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.bluetoothblockcontactsharing","displayName":"Block contact sharing via Bluetooth (work profile-level)","description":"If 'True', prevents sharing work profile contacts with paired Bluetooth devices, such as cars or mobile devices. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to share their contacts via Bluetooth. Available for corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblockcontactsharing_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblockcontactsharing_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.bluetoothblocked","displayName":"Block Bluetooth","description":"If 'True', disables Bluetooth entirely on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow Bluetooth to be used. Available for fully managed, dedicated, and corporate-owned work profile devices. In comparison, Bluetooth configuration disables the user from making changes to the Bluetooth toggle. As a result, it might be either 'On' or 'Off' depending on the state of Bluetooth prior to applying a policy with Bluetooth configuration enabled.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblocked_true","displayName":"True","description":"True","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblocked_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.bluetoothblockedaosp","displayName":"Block Bluetooth","description":"If 'True', disables Bluetooth on the device so that users can't pair with other devices. If 'False', Intune doesn't change or update this setting. By default, the OS might enable Bluetooth on the device.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblockedaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblockedaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.bluetoothblocksharing","displayName":"Block Bluetooth sharing","description":"If 'True', the device cannot share content over Bluetooth. If set to 'False', Intune doesn't change or update this setting. By default, the OS might allow Bluetooth sharing. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblocksharing_allowed","displayName":"False","description":"Bluetooth sharing is allowed.","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblocksharing_disallowed","displayName":"True","description":"Bluetooth sharing is not allowed.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.camerablocked","displayName":"Block access to camera (work profile-level)","description":"If 'True', prevents access to the camera on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow access to the camera. Intune only manages access to the device camera. It doesn't have access to pictures or videos. Available for fully managed, dedicated and corporate-owned work profile (at work profile level) devices. ","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.camerablocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.camerablocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.camerablockedaosp","displayName":"Block access to camera","description":"If 'True', prevents access to the camera on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow access to the camera. Intune only manages access to the device camera. It doesn't have access to pictures or videos.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.camerablockedaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.camerablockedaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.cellbroadcastsconfigblocked","displayName":"Block configuring cell broadcasts","description":"If 'True', the device is prevented from configuring cell broadcast messages. If 'False', Intune doesn't change or update this setting. By default, the OS might allow cell broadcast configuration. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.cellbroadcastsconfigblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.cellbroadcastsconfigblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.cellularblockwifitethering","displayName":"Block tethering and access to hotspots","description":"If 'True', prevents tethering and access to portable hotspots. If 'False', Intune doesn't change or update this setting. By default, the OS might allow tethering and access to portable hotspots. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.cellularblockwifitethering_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.cellularblockwifitethering_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.cellulartwogblocked","displayName":"Block cellular 2G","description":"If 'True', the device prevents cellular 2G functionality, restricting user access to the setting. If 'False', Intune doesn't change or update this setting. By default, the OS follows the default cellular 2G behavior. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.cellulartwogblocked_false","displayName":"False","description":"The user is allowed to toggle cellular 2G on or off.","helpText":null},{"id":"com.android.devicerestrictionpolicy.cellulartwogblocked_true","displayName":"True","description":"Cellular 2G is disabled. The user is not allowed to toggle cellular 2G on or off.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.certificatecredentialconfigurationdisabled","displayName":"Block users from configuring credentials (work profile-level)","description":"If 'True', prevents users from configuring certificates assigned to devices, even devices that aren't associated with a user account. If 'False', Intune doesn't change or update this setting. By default, the OS might make it possible for users to configure or change their credentials when they access them in the keystore. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"aad0d3ef-88f5-4b22-831b-27093eafbc64","categoryName":"Users and Accounts","options":[{"id":"com.android.devicerestrictionpolicy.certificatecredentialconfigurationdisabled_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.certificatecredentialconfigurationdisabled_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowcopypaste","displayName":"Allow copy and paste between work and personal profiles ","description":"If 'True', allows users copy and paste data between the work and personal profiles. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from pasting text into the personal profile that's copied from the work profile, allow users to copy text from the personal profile, and paste into the work profile or allow users to copy text from the work profile, and paste into the work profile. Available for corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowcopypaste_false","displayName":"False","description":"false","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowcopypaste_true","displayName":"True","description":"true","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing","displayName":"Data sharing between work and personal profile","description":"Choose if data can be shared between work and personal profiles. Available for corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_notconfigured","displayName":"Device default","description":"Not configured; this value defaults to CROSS_PROFILE_DATA_SHARING_UNSPECIFIED.","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_crossprofiledatasharingblocked","displayName":"Block all sharing between profiles","description":"Data cannot be shared from both the personal profile to work profile and the work profile to the personal profile.","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_datasharingfromworktopersonalblocked","displayName":"Block sharing from work to personal profile","description":"Prevents users from sharing data from the work profile to apps in the personal profile. Personal data can be shared with work apps.","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_crossprofiledatasharingallowed","displayName":"No restrictions on sharing","description":"Data from either profile can be shared with the other profile.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesshowworkcontactsinpersonalprofile","displayName":"Block searching of work contacts and displaying work contact caller-id in personal profile","description":"In the personal profile, 'True' prevents users from searching work contacts, and showing work caller ID information. If 'False', Intune doesn't change or update this setting. By default, the OS might allow searching work contacts, and show work caller IDs. Available for corporate-owned work profile devices. Available in Android 8.0 and later.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesshowworkcontactsinpersonalprofile_false","displayName":"False","description":"false","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesshowworkcontactsinpersonalprofile_true","displayName":"True","description":"true","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.dataroamingblocked","displayName":"Block roaming data services","description":"If 'True', prevents data roaming over the cellular network. If 'False', Intune doesn't change or update this setting. By default, the OS might allow data roaming when the device is on a cellular network. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.dataroamingblocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.dataroamingblocked_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.datetimeconfigurationblocked","displayName":"Block date and time changes","description":"If 'True', prevents users from manually setting the date and time. If False, Intune doesn't change or update this setting. By default, the OS might allow users to the set date and time on the device. Available for fully managed, dedicated and corporate-owned work profile (at work profile level) devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.datetimeconfigurationblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.datetimeconfigurationblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.enterprisedisplaynamevisibility","displayName":"Hide organization name","description":"If 'True', prevents the enterprise name from being displayed on the device (such as on the lock screen). If 'False', Intune doesn't change or update this setting. By default, the OS displays the enterprise name set during device setup. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.enterprisedisplaynamevisibility_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.enterprisedisplaynamevisibility_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.factoryresetblocked","displayName":"Block factory reset","description":"If 'True', prevents users from using the factory reset option in the device's settings. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to use this setting on the device. Available for fully managed and dedicated devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.factoryresetblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.factoryresetblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.factoryresetblockedaosp","displayName":"Block factory reset","description":"If 'True', prevents users from using the factory reset option in the device's settings. If 'False', Intune doesn't change or update this setting. By default, the OS might allow external media on the device.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.factoryresetblockedaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.factoryresetblockedaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.locationmode","displayName":"Location","description":"Select how location services are managed. 'Device Default' lets users turn location services on or off. 'Location enabled' requires location services to be on and prevents end users from turning it off. 'Location disabled' requires location services to be off and prevents end users from turning it on. When 'Location disabled' is configured, then any other setting that depends on the device location is affected, including the Locate device remote action that admins use. For corporate-owned work profile devices, this setting will only apply to devices running Android 10 or earlier. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.locationmode_notconfigured","displayName":"Device default","description":"No restrictions on the location detection setting and no specific behavior is set or enforced. This is the default.","helpText":null},{"id":"com.android.devicerestrictionpolicy.locationmode_disabled","displayName":"Location disabled","description":"Location detection setting is disabled on the device.","helpText":null},{"id":"com.android.devicerestrictionpolicy.locationmode_enforced","displayName":"Location enabled","description":"Location detection setting is enforced on the device.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.microphoneforcemute","displayName":"Block microphone adjustment","description":"If 'True', prevents users from unmuting the microphone and adjusting the microphone volume. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to use and adjust the volume of the microphone on the device. Available for fully managed, dedicated and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.microphoneforcemute_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.microphoneforcemute_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.minimumwifisecuritylevel","displayName":"Select minimum Wi-Fi security level","description":"Select what Wi-Fi security levels are required to connect to Wi-Fi networks. 'Open network security' allows the device to connect to all types of Wi-Fi networks. 'Personal network security' requires personal networks such as WEP, WPA2-PSK. 'Enterprise network security' requires enterprise EAP networks. 'Enterprise 192-bit network security' requires 192-bit networks. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.minimumwifisecuritylevel_opennetworksecurity","displayName":"Open network security","description":"The device is able to connect to all types of Wi-Fi networks.","helpText":null},{"id":"com.android.devicerestrictionpolicy.minimumwifisecuritylevel_personalnetworksecurity","displayName":"Personal network security","description":"A personal network such as WEP, WPA2-PSK is the minimum required security.","helpText":null},{"id":"com.android.devicerestrictionpolicy.minimumwifisecuritylevel_enterprisenetworksecurity","displayName":"Enterprise network security","description":"An enterprise EAP network is the minimum required security level.","helpText":null},{"id":"com.android.devicerestrictionpolicy.minimumwifisecuritylevel_enterprisebit192networksecurity","displayName":"Enterprise 192-bit network security","description":"A 192-bit enterprise network is the minimum required security level.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.mobilenetworksconfigblocked","displayName":"Block configuring mobile networks","description":"If 'True', the device is prevented from configuring mobile network settings. If 'False', Intune doesn't change or update this setting. By default, the OS might allow mobile network configuration. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.mobilenetworksconfigblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.mobilenetworksconfigblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.networkescapehatchallowed","displayName":"Allow network escape hatch","description":"If 'True', allows users to turn on the network escape hatch feature. If a network connection can't be made at boot time, the escape hatch prompts the user to temporarily connect to a network in order to refresh the device policy. After applying policy, the temporary network will be forgotten and the device will continue booting. This prevents being unable to connect to a network if there is no suitable network in the last policy and the device boots into an app in lock task mode, or the user is otherwise unable to reach device settings. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from turning on the network escape hatch feature on the device. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.networkescapehatchallowed_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.networkescapehatchallowed_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.networkresetblocked","displayName":"Block network reset","description":"If 'True', the device is prevented from performing a network settings reset. If 'False', Intune doesn't change or update this setting. By default, the OS might allow the user to reset network settings. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.networkresetblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.networkresetblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.nfcblockoutgoingbeam","displayName":"Block beaming data from apps using NFC (work profile-level)","description":"If 'True', prevents using the Near Field Communication (NFC) technology to beam data from apps. If 'False', Intune doesn't change or update this setting. By default, the OS might allow using NFC to share data between devices. Available for fully managed, dedicated and corporate-owned work profile (at work profile level) devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.nfcblockoutgoingbeam_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.nfcblockoutgoingbeam_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.outgoingcallsblocked","displayName":"Block outgoing calls","description":"If 'True', the device is prevented from making outgoing phone calls. If 'False', Intune doesn't change or update this setting. By default, the OS might allow outgoing calls. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.outgoingcallsblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.outgoingcallsblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.passwordblockkeyguard","displayName":"Disable lock screen","description":"If 'True', blocks all Keyguard lock screen features from being used. If 'False', Intune doesn't change or update this setting. By default, when the device is in lock screen, the OS might allow all the Keyguard features, such as camera, fingerprint unlock, and more. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordblockkeyguard_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordblockkeyguard_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.passwordexpirationdays","displayName":"Number of days until password expires","description":"Enter the number of days, until the device password must be changed, from 1-365. For example, enter 90 to expire the password after 90 days. When the password expires, users are prompted to create a new password. If the value is blank, Intune doesn't change or update this setting. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-365)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumlength","displayName":"Minimum password length","description":"Enter the minimum number of digits or characters the password must have, between 4 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (4-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumlengthaosp","displayName":"Minimum password length","description":"Enter the minimum number of digits or characters the password must have, from 4 to 16.","helpText":"Enter a number (4-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumlettercharacters","displayName":"Number of characters required","description":"Enter the number of characters the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumlowercasecharacters","displayName":"Number of lowercase characters required","description":"Enter the number of lowercase characters the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumnonlettercharacters","displayName":"Number of non-letter characters required","description":"Enter the number of non-letters (anything other than letters in the alphabet) the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumnumericcharacters","displayName":"Number of numeric characters required","description":"Enter the number of numeric characters (1, 2, 3, and so on) the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumsymbolcharacters","displayName":"Number of symbol characters required","description":"Enter the number of symbol characters (&, #, %, and so on) the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumuppercasecharacters","displayName":"Number of uppercase characters required","description":"Enter the number of uppercase characters the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp","displayName":"Maximum minutes of inactivity until screen locks","description":"Enter the maximum length of time, from 1 minute to 1 hour, that devices can be idle before the screen is automatically locked. Users must enter their credentials to regain access. For example, enter 5 to lock the device after 5 minutes of inactivity. Ignored by device if new time is longer than what's currently set on device. If set to Immediately, devices will use the minimum possible value per device.","helpText":"","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_1minute","displayName":"1 Minute","description":"Screen Timeout after 1 Minute of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_5minutes","displayName":"5 Minutes","description":"Screen Timeout after 5 Minutes of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_15minutes","displayName":"15 Minutes","description":"Screen Timeout after 15 Minutes of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_30minutes","displayName":"30 Minutes","description":"Screen Timeout after 30 Minutes of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_1hour","displayName":"1 Hour","description":"Screen Timeout after 1 Hour of Inactivity","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.passwordpreviouspasswordcounttoblock","displayName":"Number of passwords required before user can reuse a password","description":"Use this setting to restrict users from creating previously used passwords. Enter the number of previously used passwords that can't be used, from 1-24. For example, enter 5 so users can't set a new password to their current password or any of their previous four passwords. If the value is blank, Intune doesn't change or update this setting. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-24)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype","displayName":"Required password type","description":"Set the password’s complexity requirements. Additional password requirements will become available based on your selection. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level). For more details, see the information provided in the ‘Learn More’ section below.","helpText":"","infoUrls":["https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-for-work?WT.mc_id=Portal-fx#device-password"],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_devicedefault","displayName":"Device default","description":"Device default value, no intent.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_required","displayName":"Password required, no restrictions","description":"There must be a password set, but there are no restrictions on type.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_lowsecuritybiometric","displayName":"Weak Biometric","description":"Low security biometrics based password required.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_numeric","displayName":"Numeric","description":"At least numeric.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_numericcomplex","displayName":"Numeric Complex","description":"At least numeric with no repeating or ordered sequences.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_alphabetic","displayName":"Alphabetic","description":"At least alphabetic password.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_alphanumeric","displayName":"Alphanumeric","description":"At least alphanumeric password","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_alphanumericwithsymbols","displayName":"Alphanumeric with symbols","description":"At least alphanumeric with symbols.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp","displayName":"Required password type","description":"Set the password’s complexity requirements. Additional password requirements will become available based on your selection. For more details, see the information provided in the ‘Learn More’ section below.","helpText":"","infoUrls":["https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-aosp#:~:text=Required%20password%20type"],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_devicedefault","displayName":"Device default","description":"Device default value, no intent.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_required","displayName":"Password required, no restrictions","description":"There must be a password set, but there are no restrictions on type.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_lowsecuritybiometric","displayName":"Weak Biometric","description":"Low security biometrics based password required.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_numeric","displayName":"Numeric","description":"At least numeric.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_numericcomplex","displayName":"Numeric Complex","description":"At least numeric with no repeating or ordered sequences.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_alphabetic","displayName":"Alphabetic","description":"At least alphabetic password.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_alphanumeric","displayName":"Alphanumeric","description":"At least alphanumeric password","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_alphanumericwithsymbols","displayName":"Alphanumeric with symbols","description":"At least alphanumeric with symbols.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.passwordrequireunlock","displayName":"Required unlock frequency","description":"Select how long users have before they're required to unlock the device using a strong authentication method (password, PIN, or pattern). Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordrequireunlock_devicedefault","displayName":"Device default","description":null,"helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequireunlock_requiredpasswordunlockdailyoption","displayName":"24 hours since last PIN, password, or pattern unlock","description":null,"helpText":null}]},{"id":"com.android.devicerestrictionpolicy.passwordsigninfailurecountbeforefactoryreset","displayName":"Number of sign-in failures before wiping device","description":"Enter the number of wrong passwords allowed before the device is wiped, from 4-11. If the value is blank, Intune doesn't change or update this setting. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (4-11)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordsigninfailurecountbeforefactoryresetaosp","displayName":"Number of sign-in failures before wiping device","description":"Enter the number of sign-in attempts allowed, from 4 to 11, before the device is wiped. 0 (zero) might disable the device wipe functionality. When the value is blank, Intune doesn't change or update this setting.","helpText":"Enter a number (4-11)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.personalprofileappsallowinstallfromunknownsources","displayName":"Allow users to enable app installation from unknown sources in the personal profile","description":"If 'True, allows users to install apps from unknown sources in the personal profile. It allows users to install apps from sources other than the Google Play Store. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from installing apps from unknown sources in the personal profile. Available for corporate-owned work profile devices (at personal profile level).","helpText":null,"infoUrls":[],"categoryId":"990880db-3f64-4436-ab4a-d7d5181dfa5d","categoryName":"Personal Profile","options":[{"id":"com.android.devicerestrictionpolicy.personalprofileappsallowinstallfromunknownsources_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.personalprofileappsallowinstallfromunknownsources_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.personalprofilecamerablocked","displayName":"Block camera","description":"If 'True', prevents access to the camera during personal use. If 'False', Intune doesn't change or update this setting. By default, the OS might allow using the camera in the personal profile. Available for corporate-owned work profile devices (at personal profile level).","helpText":null,"infoUrls":[],"categoryId":"990880db-3f64-4436-ab4a-d7d5181dfa5d","categoryName":"Personal Profile","options":[{"id":"com.android.devicerestrictionpolicy.personalprofilecamerablocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.personalprofilecamerablocked_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.personalprofilescreencaptureblocked","displayName":"Block screen capture","description":"If 'True', prevents screen captures during personal and work use. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to get screen captures or screenshots in the personal and work profile. Available for corporate-owned work profile devices (applies at both work and personal profile level).","helpText":null,"infoUrls":[],"categoryId":"990880db-3f64-4436-ab4a-d7d5181dfa5d","categoryName":"Personal Profile","options":[{"id":"com.android.devicerestrictionpolicy.personalprofilescreencaptureblocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.personalprofilescreencaptureblocked_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.preferentialnetworkservice","displayName":"Allow selection of a preferential network service","description":"If 'True', the device will give priority to the specified network service over other available options (e.g., enterprise slice on 5G networks). If 'False', Intune doesn't change or update this setting. By default, the device connects using its default network selection process. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.preferentialnetworkservice_false","displayName":"False","description":"Preferential network service is disabled.","helpText":null},{"id":"com.android.devicerestrictionpolicy.preferentialnetworkservice_true","displayName":"True","description":"Preferential network service is enabled on the device.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.printingpolicy","displayName":"Block printing","description":"If 'True', the device is prevented from printing documents. If 'False', Intune doesn't change or update this setting. By default, the OS follows the default printing behavior. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.printingpolicy_false","displayName":"False","description":"The user is allowed to print.","helpText":null},{"id":"com.android.devicerestrictionpolicy.printingpolicy_true","displayName":"True","description":"The user is not allowed to print.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.privatespacepolicy","displayName":"Block private space","description":"If 'True', prevents users from creating or using private spaces on the device, ensuring that all data is stored within the corporate profile. All existing private spaces will be deleted. If 'False', Intune doesn't change or update this setting. By default, the OS might allow the creation of private spaces for personal data. Available for corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.privatespacepolicy_allowed","displayName":"False","description":"Users can create a private space profile.","helpText":null},{"id":"com.android.devicerestrictionpolicy.privatespacepolicy_disallowed","displayName":"True","description":"Users cannot create a private space profile. Supported only for company-owned devices with a work profile. Caution: Any existing private space will be removed.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.screencaptureblocked","displayName":"Block screen capture","description":"If 'True', prevents screenshots or screen captures on the device. It also prevents the content from being shown on display devices that don't have a secure video output. If 'False', Intune doesn't change or update this setting. By default, the OS might let users capture the screen contents as an image. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.screencaptureblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.screencaptureblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.screencaptureblockedaosp","displayName":"Block screen capture","description":"If 'True', prevents screenshots or screen captures on the device. It also prevents the content from being shown on display devices that don't have a secure video output. If 'False', Intune doesn't change or update this setting. By default, the OS might let users capture the screen contents as an image.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.screencaptureblockedaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.screencaptureblockedaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.securityallowdebuggingfeaturesaosp","displayName":"Allow users to turn on debugging features","description":"If 'True', permits users to access the debugging features on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from using the debugging features on the device.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.securityallowdebuggingfeaturesaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.securityallowdebuggingfeaturesaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.securitycommoncriteriamodeenabled","displayName":"Require Common Criteria mode​","description":"If 'True', enables an elevated set of security standards on the device most often used in highly sensitive organizations, such as government establishments. If 'False', Intune doesn't change or update this setting. Available for fully managed, dedicated and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"bf8e3e9c-f7e7-4a43-8898-2caf7b01d987","categoryName":"System Security","options":[{"id":"com.android.devicerestrictionpolicy.securitycommoncriteriamodeenabled_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.securitycommoncriteriamodeenabled_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.securitydevelopersettingsenabled","displayName":"Allow access to developer settings","description":"If 'True', allow users access developer settings on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from accessing developer settings on the device. Available for fully managed, dedicated and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.securitydevelopersettingsenabled_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.securitydevelopersettingsenabled_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.securityrequireverifyapps","displayName":"Require threat scan on apps","description":"If 'True', enables Google Play Protect to scan apps before and after they're installed. If it detects a threat, it might warn users to remove the app from the device. If 'False', Intune doesn't change or update this setting. By default, the OS might not enable or run Google Play Protect to scan apps. Available for fully managed, dedicated and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"bf8e3e9c-f7e7-4a43-8898-2caf7b01d987","categoryName":"System Security","options":[{"id":"com.android.devicerestrictionpolicy.securityrequireverifyapps_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.securityrequireverifyapps_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.setusericonblocked","displayName":"Block setting user icon","description":"If 'True', the device is prevented from changing the user icon. If 'False', Intune doesn't change or update this setting. By default, the OS might allow the user to change their icon. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.setusericonblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.setusericonblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.setwallpaperblocked","displayName":"Block setting wallpaper","description":"If 'True', the device is prevented from changing the wallpaper. If 'False', Intune doesn't change or update this setting. By default, the OS might allow the user to set a wallpaper. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.setwallpaperblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.setwallpaperblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.smsblocked","displayName":"Block SMS","description":"If 'True', the device is prevented from sending and receiving SMS messages. If 'False', Intune doesn't change or update this setting. By default, the OS might allow SMS messaging. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.smsblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.smsblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.statusbarblocked","displayName":"Block access to status bar","description":"If 'True', prevents access to the status bar, including notifications and quick settings. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users access to the status bar. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.statusbarblocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.statusbarblocked_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.storageallowusb","displayName":"Allow USB storage","description":"If 'True', allow users to access USB storage on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent access to USB storage. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.storageallowusb_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.storageallowusb_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.storageblockexternalmedia","displayName":"Block mounting of external media","description":"If 'True', prevents using or connecting any external media on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow external media on the device. Available for fully managed, dedicated and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.storageblockexternalmedia_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.storageblockexternalmedia_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.storageblockexternalmediaaosp","displayName":"Block mounting of external media","description":"If 'True', prevents users from using or connecting any external media on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to connect external media.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.storageblockexternalmediaaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.storageblockexternalmediaaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.storageblockusbfiletransferaosp","displayName":"Block USB file transfer","description":"If 'True', prevents users from transferring files over USB. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to transfer files.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.storageblockusbfiletransferaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.storageblockusbfiletransferaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.systemwindowsblocked","displayName":"Block notification windows","description":"If 'True', window notifications, including toasts, incoming calls, outgoing calls, system alerts, and system errors aren't shown on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might show notifications. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.systemwindowsblocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.systemwindowsblocked_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.ultrawidebandblocked","displayName":"Block ultra wideband","description":"If 'True', the device prevents ultra wideband functionality, restricting user access to the setting. If 'False', Intune doesn't change or update this setting. By default, the OS follows the default ultra wideband behavior. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.ultrawidebandblocked_false","displayName":"False","description":"The user is allowed to toggle ultra wideband on or off.","helpText":null},{"id":"com.android.devicerestrictionpolicy.ultrawidebandblocked_true","displayName":"True","description":"Ultra wideband is disabled. The user is not allowed to toggle ultra wideband on or off.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.usbdataaccess","displayName":"USB access","description":"Select what files and/or data can be transferred via USB. If you block file transfer, only files will be blocked from being transferred and other connection (such as mouse) will still be allowed. If you block USB data transfer, all data will be blocked. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.usbdataaccess_allowusbdatatransfer","displayName":"Allow USB data transfer","description":"All types of USB data transfers are allowed. usbFileTransferDisabled is ignored.","helpText":null},{"id":"com.android.devicerestrictionpolicy.usbdataaccess_disallowusbfiletransfer","displayName":"Disallow USB file transfer","description":"Transferring files over USB is disallowed. Other types of USB data connections, such as mouse and keyboard connection, are allowed. usbFileTransferDisabled is ignored.","helpText":null},{"id":"com.android.devicerestrictionpolicy.usbdataaccess_disallowusbdatatransfer","displayName":"Disallow USB data transfer","description":"When set, all types of USB data transfers are prohibited. Supported for devices running Android 12 or above with USB HAL 1.3 or above. If the setting is not supported, DISALLOW_USB_FILE_TRANSFER will be set. A NonComplianceDetail with API_LEVEL is reported if the Android version is less than 12. A NonComplianceDetail with DEVICE_INCOMPATIBLE is reported if the device does not have USB HAL 1.3 or above. usbFileTransferDisabled is ignored.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.userinitiatedaddesimsettings","displayName":"Block users from adding eSIM profiles","description":"If 'True', users cannot add eSIM profiles to the device. If 'False', Intune doesn't change or update this setting. By default, the OS allows users to add eSIM profiles. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.userinitiatedaddesimsettings_false","displayName":"False","description":"The user is allowed to add eSIM profiles on the device.","helpText":null},{"id":"com.android.devicerestrictionpolicy.userinitiatedaddesimsettings_true","displayName":"True","description":"The user is not allowed to add eSIM profiles on the device.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.volumeblockadjustment","displayName":"Block volume changes","description":"If 'True', prevents users from changing the device's volume, and also mutes the main volume. If 'False', Intune doesn't change or update this setting. By default, the OS might allow using the volume settings on the device. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.volumeblockadjustment_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.volumeblockadjustment_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.vpnconfigblocked","displayName":"Block configuring VPN","description":"If 'True', the device is prevented from configuring VPN connections. If 'False', Intune doesn't change or update this setting. By default, the OS might allow VPN configuration. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.vpnconfigblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.vpnconfigblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurations","displayName":"Block Wi-Fi access point configuration","description":"If 'True', prevents users from creating or changing any Wi-Fi configurations. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to change the Wi-Fi settings on the device. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurations_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurations_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurationsaosp","displayName":"Block Wi-Fi setting changes","description":"If 'True', prevents users from creating or changing any Wi-Fi configurations. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to change the Wi-Fi settings on the device.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurationsaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurationsaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.wifiblockeditpolicydefinedconfigurations","displayName":"Block Wi-Fi setting changes","description":"If 'True', prevents users from changing Wi-Fi settings created by the device owner. Users can create their own Wi-Fi configurations. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to change the Wi-Fi settings on the device. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wifiblockeditpolicydefinedconfigurations_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.wifiblockeditpolicydefinedconfigurations_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.wifidirectsettings","displayName":"Block Wi-Fi Direct","description":"If 'True', blocks Wi-Fi Direct (a direct, peer-to-peer connection between devices using Wi-Fi frequencies). If set to 'False', Intune doesn't change or update this setting. By default, the OS might allow Wi-Fi Direct. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wifidirectsettings_allowed","displayName":"False","description":"The user is allowed to use Wi-Fi direct.","helpText":null},{"id":"com.android.devicerestrictionpolicy.wifidirectsettings_disallowed","displayName":"True","description":"The user is not allowed to use Wi-Fi direct. A NonComplianceDetail with API_LEVEL is reported if the Android version is less than 13.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordexpirationdays","displayName":"Number of days until password expires","description":"Enter the number of days, until the work profile password must be changed, from 1-365. For example, enter 90 to expire the password after 90 days. When the password expires, users are prompted to create a new password. If the value is blank, Intune doesn't change or update this setting. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-365)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumlength","displayName":"Minimum password length","description":"Enter the minimum number of digits or characters the work profile password must have, between 4 and 16 characters. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (4-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumlettercharacters","displayName":"Number of characters required","description":"Enter the number of characters the work profile password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumlowercasecharacters","displayName":"Number of lowercase characters required","description":"Enter the number of lowercase characters the work profile password must have, between 1 and 16 characters. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumnonlettercharacters","displayName":"Number of non-letter characters required","description":"Enter the number of non-letters (anything other than letters in the alphabet) the work profile password must have, between 1 and 16 characters. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumnumericcharacters","displayName":"Number of numeric characters required","description":"Enter the number of numeric characters (1, 2, 3, and so on) the work profile password must have, between 1 and 16 characters. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumsymbolcharacters","displayName":"Number of symbol characters required","description":"Enter the number of symbol characters (&, #, %, and so on) the work profile password must have, between 1 and 16 characters. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumuppercasecharacters","displayName":"Number of uppercase characters required","description":"Enter the number of uppercase characters the work profile password must have, between 1 and 16 characters. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordpreviouspasswordcounttoblock","displayName":"Number of passwords required before user can reuse a password","description":"Use this setting to restrict users from creating previously used work profile passwords. Enter the number of previously used passwords that can't be used, from 1-24. For example, enter 5 so users can't set a new password to their current password or any of their previous four passwords. If the value is blank, Intune doesn't change or update this setting. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-24)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype","displayName":"Required password type","description":"Set the work profile password’s complexity requirements. Additional password requirements will become available based on your selection. Available for corporate-owned work profile devices (at work profile level). For more details, see the information provided in the ‘Learn More’ section below.","helpText":"","infoUrls":["https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-for-work?WT.mc_id=Portal-fx#device-password:~:text=owned%20work%20profiles.-,Required%20password%20type%3A,-Enter%20the%20required"],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":[{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_devicedefault","displayName":"Device default","description":"Device default value, no intent.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_required","displayName":"Password required, no restrictions","description":"There must be a password set, but there are no restrictions on type.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_lowsecuritybiometric","displayName":"Weak Biometric","description":"Low security biometrics based password required.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_numeric","displayName":"Numeric","description":"At least numeric.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_numericcomplex","displayName":"Numeric Complex","description":"At least numeric with no repeating or ordered sequences.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_alphabetic","displayName":"Alphabetic","description":"At least alphabetic password.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_alphanumeric","displayName":"Alphanumeric","description":"At least alphanumeric password","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_alphanumericwithsymbols","displayName":"Alphanumeric with symbols","description":"At least alphanumeric with symbols.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequireunlock","displayName":"Required unlock frequency","description":"Select how long users have before they're required to unlock the work profile using a strong authentication method (password, PIN, or pattern). Available for corporate-owned work profile devices (at work profile level).","helpText":"","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":[{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequireunlock_devicedefault","displayName":"Device default","description":null,"helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequireunlock_requiredpasswordunlockdailyoption","displayName":"24 hours since last PIN, password, or pattern unlock","description":null,"helpText":null}]},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordsigninfailurecountbeforefactoryreset","displayName":"Number of sign-in failures before wiping device","description":"Enter the number of wrong passwords allowed before the work profile is wiped, from 4-11. If the value is blank, Intune doesn't change or update this setting. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (4-11)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilewidgetsdefault","displayName":"Block widgets from work profile apps","description":"If 'True', prevents users from adding widgets exposed by work profile apps to the home screen. If set to 'False', Intune doesn't change or update this setting. By default, the OS might allow adding work profile widgets to the home screen. Available for corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"2257f7e1-3e88-4d4d-a666-437bbe42baca","categoryName":"Applications","options":[{"id":"com.android.devicerestrictionpolicy.workprofilewidgetsdefault_false","displayName":"False","description":"Work profile widgets are allowed. Users can add widgets exposed by work profile apps to the home screen.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilewidgetsdefault_true","displayName":"True","description":"Work profile widgets are disallowed. Users cannot add widgets from work profile apps to the home screen.","helpText":null}]},{"id":"com.apple.airplay_allowlist","displayName":"Allow List","description":"If present, only AirPlay destinations in this list are available to the device. This allow list applies to supervised devices.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_allowlist_item_deviceid","displayName":"Device ID (Deprecated)","description":"The device ID of the AirPlay destination in the format xx:xx:xx:xx:xx:xx. This field isn’t case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_allowlist_item_devicename","displayName":"Device Name","description":"The name of the AirPlay device.\n\nThe system limits the list of visible AirPlay destinations to devices that are present in the `AllowList` field of all installed AirPlay payloads.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_com.apple.airplay","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_passwords","displayName":"Password","description":"The password for the AirPlay destination.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_passwords_item_deviceid","displayName":"Device ID","description":"The device ID of the AirPlay destination; used in macOS.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_passwords_item_devicename","displayName":"Device Name","description":"The name of the AirPlay destination; used in iOS.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_passwords_item_password","displayName":"Password","description":"The password for the AirPlay destination.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airprint_airprint","displayName":"Printers","description":"A list of AirPrint printers that are presented to the user.","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},{"id":"com.apple.airprint_airprint_item_forcetls","displayName":"Force TLS","description":"If true, AirPrint connections are secured by Transport Layer Security (TLS). Available only in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":[{"id":"com.apple.airprint_airprint_item_forcetls_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.airprint_airprint_item_forcetls_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.airprint_airprint_item_ipaddress","displayName":"IP Address","description":"The IP address or hostname of the AirPrint destination.","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},{"id":"com.apple.airprint_airprint_item_port","displayName":"Port","description":"The listening port of the AirPrint destination. Available only in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},{"id":"com.apple.airprint_airprint_item_resourcepath","displayName":"Resource Path","description":"The resource path associated with the printer. This path corresponds to the rp parameter of the _ipps.tcp Bonjour record. For example: printers/Canon_MG5300_series, printers/Xerox_Phaser_7600, ipp/print, Epson_IPP_Printer","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},{"id":"com.apple.airprint_com.apple.airprint","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},{"id":"com.apple.app.lock_app","displayName":"App","description":"A dictionary that contains information about the app.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},{"id":"com.apple.app.lock_app_identifier","displayName":"App Identifier","description":"The bundle identifier of the app.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},{"id":"com.apple.app.lock_app_options","displayName":"Options","description":"A dictionary of options that the user cannot change.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},{"id":"com.apple.app.lock_app_options_disableautolock","displayName":"Disable Auto Lock","description":"If true, the device doesn't automatically go to sleep after an idle period.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disableautolock_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disableautolock_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_disabledevicerotation","displayName":"Disable Device Rotation","description":"If true, disables device rotation sensing.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disabledevicerotation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disabledevicerotation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_disableringerswitch","displayName":"Disable Ringer Switch","description":"If true, disables the ringer switch. When disabled, the ringer behavior depends on what position the switch was in when it was first disabled.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disableringerswitch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disableringerswitch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_disablesleepwakebutton","displayName":"Disable Sleep Wake Button","description":"If true, disables the sleep/wake button.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disablesleepwakebutton_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disablesleepwakebutton_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_disabletouch","displayName":"Disable Touch","description":"If true, disables the touch screen.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disabletouch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disabletouch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_disablevolumebuttons","displayName":"Disable Volume Buttons","description":"If true, disables the volume buttons.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disablevolumebuttons_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disablevolumebuttons_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enableassistivetouch","displayName":"Enable Assistive Touch","description":"If true, enables Assistive Touch.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enableassistivetouch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enableassistivetouch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enableinvertcolors","displayName":"Enable Invert Colors","description":"If true, enables Invert Colors. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enableinvertcolors_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enableinvertcolors_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enablemonoaudio","displayName":"Enable Mono Audio","description":"If true, enables Mono Audio.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enablemonoaudio_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enablemonoaudio_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enablespeakselection","displayName":"Enable Speak Selection","description":"If true, enables Speak Selection.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enablespeakselection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enablespeakselection_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enablevoicecontrol","displayName":"Enable Voice Control","description":"If true, enables Voice Control.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enablevoicecontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enablevoicecontrol_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enablevoiceover","displayName":"Enable Voice Over","description":"If true, enables Voice Over.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enablevoiceover_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enablevoiceover_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enablezoom","displayName":"Enable Zoom","description":"If true, enables Zoom. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enablezoom_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enablezoom_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_userenabledoptions","displayName":"User Enabled Options","description":"A dictionary of user-editable options.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},{"id":"com.apple.app.lock_app_userenabledoptions_assistivetouch","displayName":"Assistive Touch","description":"If true, allows the user to toggle Assistive Touch.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_assistivetouch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_assistivetouch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_userenabledoptions_invertcolors","displayName":"Invert Colors","description":"If true, allows the user to toggle Invert Colors. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_invertcolors_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_invertcolors_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_userenabledoptions_voicecontrol","displayName":"Voice Control","description":"If true, allows the user to toggle Voice Control.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_voicecontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_voicecontrol_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_userenabledoptions_voiceover","displayName":"Voice Over","description":"If true, allows the user to toggle Voice Over. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_voiceover_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_voiceover_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_userenabledoptions_zoom","displayName":"Zoom","description":"If true, allows the user to toggle Zoom. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_zoom_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_zoom_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_com.apple.app.lock","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},{"id":"com.apple.applicationaccess_allowaccountmodification","displayName":"Allow Account Modification","description":"If false, disables account modification. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowaccountmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowaccountmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowactivitycontinuation","displayName":"Allow Activity Continuation","description":"If false, disables activity continuation. Available in iOS 8 and later, and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowactivitycontinuation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowactivitycontinuation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowaddinggamecenterfriends","displayName":"Allow Adding Game Center Friends","description":"If false, prohibits adding friends to Game Center. As of iOS 13, requires a supervised device. Available in iOS 4.2.1 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowaddinggamecenterfriends_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowaddinggamecenterfriends_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowairdrop","displayName":"Allow AirDrop","description":"If false, disables AirDrop. Requires a supervised device. Available in iOS 7 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowairdrop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowairdrop_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowairplayincomingrequests","displayName":"Allow Air Play Incoming Requests","description":"If false, disables incoming AirPlay requests. Requires a supervised device. Available in macOS 12.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowairplayincomingrequests_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowairplayincomingrequests_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowairprint","displayName":"Allow AirPrint","description":"If false, disables AirPrint. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowairprint_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowairprint_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowairprintcredentialsstorage","displayName":"Allow AirPrint Credentials Storage","description":"If false, disables keychain storage of user name and password for AirPrint. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowairprintcredentialsstorage_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowairprintcredentialsstorage_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowairprintibeacondiscovery","displayName":"Allow AirPrint iBeacon Discovery","description":"If false, disables iBeacon discovery of AirPrint printers, which prevents spurious AirPrint Bluetooth beacons from phishing for network traffic. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowairprintibeacondiscovery_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowairprintibeacondiscovery_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappcellulardatamodification","displayName":"Allow App Cellular Data Modification","description":"If false, disables changing settings for cellular data usage for apps. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappcellulardatamodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappcellulardatamodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappclips","displayName":"Allow App Clips","description":"If false, prevents a user from adding any App Clips, and removes any existing App Clips on the device. Requires a supervised device. Available in iOS 14.0 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappclips_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappclips_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappinstallation","displayName":"Allow App Installation","description":"If false, disables the App Store, and its icon is removed from the Home screen. Users are unable to install or update their apps. In iOS 10 and later, MDM commands can override this restriction. As of iOS 13, this restriction requires a supervised device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappleintelligencereport","displayName":"Allow Apple Intelligence Report (Deprecated)","description":"When false, disables Apple Intelligence reports.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappleintelligencereport_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappleintelligencereport_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowapplepersonalizedadvertising","displayName":"Allow Apple Personalized Advertising","description":"If false, limits Apple personalized advertising. Available in iOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowapplepersonalizedadvertising_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowapplepersonalizedadvertising_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappremoval","displayName":"Allow App Removal","description":"If false, disables removal of apps from an iOS device. Requires a supervised device. Available in iOS 4.2.1 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappremoval_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappremoval_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappstobehidden","displayName":"Allow Apps To Be Hidden","description":"If false, disables the ability for the user to hide apps. It does not affect the user's ability to leave it in the App Library, while removing it from the home screen.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappstobehidden_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappstobehidden_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappstobelocked","displayName":"Allow Apps To Be Locked","description":"If false, disables the ability for the user to lock apps. Because hiding apps also requires locking them, disallowing locking also disallows hiding.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappstobelocked_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappstobelocked_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowardremotemanagementmodification","displayName":"Allow ARD Remote Management Modification","description":"If 'false', prevents modifying the Remote Management Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowardremotemanagementmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowardremotemanagementmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowassistant","displayName":"Allow Assistant (Deprecated)","description":"If false, disables Siri. Available in iOS 5 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowassistant_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowassistant_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowassistantusergeneratedcontent","displayName":"Allow Assistant User Generated Content (Deprecated)","description":"If false, prevents Siri from querying user-generated content from the web. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowassistantusergeneratedcontent_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowassistantusergeneratedcontent_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowassistantwhilelocked","displayName":"Allow Assistant While Locked (Deprecated)","description":"If false, disables Siri when the device is locked. This restriction is ignored if the device doesn’t have a passcode set. Available in iOS 5.1 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowassistantwhilelocked_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowassistantwhilelocked_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowautocorrection","displayName":"Allow Auto Correction (Deprecated)","description":"If false, disables keyboard autocorrection. Requires a supervised device. Available in iOS 8.1.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowautocorrection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowautocorrection_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowautodim","displayName":"Allow Auto Dim","description":"If set to false, disables auto dim on iPads with OLED displays.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowautodim_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowautodim_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowautomaticappdownloads","displayName":"Allow Automatic App Downloads","description":"If false, prevents automatic downloading of apps purchased on other devices. This setting doesn’t affect updates to existing apps. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowautomaticappdownloads_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowautomaticappdownloads_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowautounlock","displayName":"Allow Auto Unlock","description":"If false, disallows auto unlock. Available in macOS 10.12 and later, and iOS 14.5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowautounlock_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowautounlock_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowbluetoothmodification","displayName":"Allow Bluetooth Modification","description":"If false, prevents modification of Bluetooth settings. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowbluetoothmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowbluetoothmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowbluetoothsharingmodification","displayName":"Allow Bluetooth Sharing Modification","description":"If 'false', prevents modifying Bluetooth setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowbluetoothsharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowbluetoothsharingmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowbookstore","displayName":"Allow Bookstore","description":"If false, removes the Book Store tab from the Books app. Requires a supervised device. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowbookstore_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowbookstore_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowbookstoreerotica","displayName":"Allow Bookstore Erotica","description":"If false, the user can’t download Apple Books media that is tagged as erotica. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowbookstoreerotica_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowbookstoreerotica_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcallrecording","displayName":"Allow Call Recording","description":"If false, call recording is disabled.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcallrecording_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcallrecording_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcamera","displayName":"Allow Camera","description":"If false, disables the camera, and its icon is removed from the Home screen. Users are unable to take photographs. Requires a supervised device. Available in iOS 4 and later, and macOS 10.11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcamera_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcamera_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcellularplanmodification","displayName":"Allow Cellular Plan Modification","description":"If false, users can’t change any settings related to their cellular plan. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcellularplanmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcellularplanmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowchat","displayName":"Allow Chat","description":"If false, disables the use of the iMessage with supervised devices. If the device supports text messaging, the user can still send and receive text messages. Requires a supervised device. Available in iOS 5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowchat_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowchat_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudaddressbook","displayName":"Allow Cloud Address Book","description":"If false, disables iCloud Address Book services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudaddressbook_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudaddressbook_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudbackup","displayName":"Allow Cloud Backup","description":"If false, disables backing up the device to iCloud. Requires a supervised device. Available in iOS 5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudbackup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudbackup_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudbookmarks","displayName":"Allow Cloud Bookmarks","description":"If false, disables iCloud Bookmark sync. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudbookmarks_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudbookmarks_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudcalendar","displayName":"Allow Cloud Calendar","description":"If false, disables iCloud Calendar services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudcalendar_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudcalendar_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowclouddesktopanddocuments","displayName":"Allow Cloud Desktop And Documents","description":"If false, disables cloud desktop and document services. Available in macOS 10.12.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowclouddesktopanddocuments_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowclouddesktopanddocuments_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowclouddocumentsync","displayName":"Allow Cloud Document Sync","description":"If false, disables document and key-value syncing to iCloud. As of iOS 13, this restriction requires a supervised device. Available in iOS 5 and later, and macOS 10.11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowclouddocumentsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowclouddocumentsync_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudfreeform","displayName":"Allow Cloud Freeform","description":"If 'false', disallows iCloud Freeform services.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudfreeform_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudfreeform_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudkeychainsync","displayName":"Allow Cloud Keychain Sync","description":"If false, disables iCloud keychain synchronization. Requires a supervised device. Available in iOS 7 and later and macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudkeychainsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudkeychainsync_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudmail","displayName":"Allow Cloud Mail","description":"If false, disables iCloud Mail services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudmail_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudmail_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudnotes","displayName":"Allow Cloud Notes","description":"If false, disables iCloud Notes services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudnotes_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudnotes_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudphotolibrary","displayName":"Allow Cloud Photo Library","description":"If false, disables iCloud Photo Library. Any photos not fully downloaded from iCloud Photo Library to the device are removed from local storage. Available in iOS 9 and later, and macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudphotolibrary_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudphotolibrary_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudprivaterelay","displayName":"Allow Cloud Private Relay","description":"If false, disables iCloud Private Relay. For iOS devices, this restriction requires a supervised device. Available in macOS 12 and later, and iOS 15 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudprivaterelay_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudprivaterelay_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudreminders","displayName":"Allow Cloud Reminders","description":"If false, disables iCloud Reminder services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudreminders_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudreminders_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcontentcaching","displayName":"Allow Content Caching","description":"If false, disables content caching. As of 10.13.4 this is included in the content caching payload. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcontentcaching_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcontentcaching_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcontinuouspathkeyboard","displayName":"Allow Continuous Path Keyboard (Deprecated)","description":"If false, disables QuickPath keyboard. Requires a supervised device. Available in iOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcontinuouspathkeyboard_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcontinuouspathkeyboard_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdefaultbrowsermodification","displayName":"Allow Default Browser Modification","description":"If false, disables default browser preference modification. The MDM Settings command to set the default browser preference will still work when this is applied.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdefaultbrowsermodification_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdefaultbrowsermodification_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdefaultcallingappmodification","displayName":"Allow Default Calling App Modification","description":"If false, disables default calling app preference modification. The MDM Settings command to set the default calling app preference will still work when this is applied.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdefaultcallingappmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdefaultcallingappmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdefaultmessagingappmodification","displayName":"Allow Default Messaging App Modification","description":"If false, disables default messaging app preference modification. The MDM Settings command to set the default messaging app preference will still work when this is applied.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdefaultmessagingappmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdefaultmessagingappmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdefinitionlookup","displayName":"Allow Definition Lookup (Deprecated)","description":"If false, disables definition lookup. Requires a supervised device on iOS. Available in iOS 8.1.3 and later and macOS 10.11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdefinitionlookup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdefinitionlookup_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdevicenamemodification","displayName":"Allow Device Name Modification","description":"If false, prevents the user from changing the device name. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdevicenamemodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdevicenamemodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdiagnosticsubmission","displayName":"Allow Diagnostic Submission","description":"If false, prevents the device from automatically submitting diagnostic reports to Apple. Available in iOS 6 and later, and macOS 10.13 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdiagnosticsubmission_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdiagnosticsubmission_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdiagnosticsubmissionmodification","displayName":"Allow Diagnostic Submission Modification","description":"If false, disables changing the diagnostic submission and app analytics settings in the Diagnostics & Usage UI in Settings. Requires a supervised device. Available in iOS 9.3.2 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdiagnosticsubmissionmodification_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdiagnosticsubmissionmodification_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdictation","displayName":"Allow Dictation (Deprecated)","description":"If false, disallows dictation input. Requires a supervised device. Available in iOS 10.3 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdictation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdictation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowedcamerarestrictionbundleids","displayName":"Allowed Camera Restriction Bundle IDs","description":"If present, the system exempts apps with bundle IDs in the array from the `allowCamera` restriction. The system doesn't grant these apps access to the camera automatically; they're only exempted from the `allowCamera` restriction. This key has no effect when the camera isn't restricted. Multiple payloads combine using an intersect operation. Requires a supervised device.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_allowedexternalintelligenceworkspaceids","displayName":"Allowed External Intelligence Workspace IDs (Deprecated)","description":"An array of strings, but currently restricted to a single element. If present, Apple Intelligence allows use of only the given external integration workspace ID, and requires a sign-in to make requests. The user is required to sign in to integrations that support signing in. Multiple payloads combine using an intersect operation. This means the allowed set of workspace IDs can become the empty set if multiple payloads specify conflicting values.\n\nDeprecated: use the declarative management `com.apple.configuration.external-intelligence.settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_allowenablingrestrictions","displayName":"Allow Enabling Restrictions","description":"If false, disables the “Enable Restrictions” option in the Restrictions UI in Settings. In iOS 12 or later, if false, disables the “Enable ScreenTime” option in the ScreenTime UI in Settings and disables ScreenTime if already enabled. Requires a supervised device. Available in iOS 8 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowenablingrestrictions_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowenablingrestrictions_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowenterpriseapptrust","displayName":"Allow Enterprise App Trust","description":"If false, removes the Trust Enterprise Developer button in Settings > General > Profiles & Device Management, preventing apps from being provisioned by universal provisioning profiles. This restriction applies to free developer accounts. However, it doesn’t apply to enterprise app developers who are trusted because their apps were pushed through MDM. It also doesn’t revoke previously granted trust. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowenterpriseapptrust_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowenterpriseapptrust_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowenterprisebookbackup","displayName":"Allow Enterprise Book Backup","description":"If false, disables backup of Enterprise books. Available in iOS 8 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowenterprisebookbackup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowenterprisebookbackup_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowenterprisebookmetadatasync","displayName":"Allow Enterprise Book Metadata Sync","description":"If false, disables sync of Enterprise books, notes, and highlights. Available in iOS 8 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowenterprisebookmetadatasync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowenterprisebookmetadatasync_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowerasecontentandsettings","displayName":"Allow Erase Content And Settings","description":"If false, disables the Erase All Content And Settings option in the Reset UI. Requires a supervised device. Available in iOS 8 and later, and macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowerasecontentandsettings_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowerasecontentandsettings_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowesimmodification","displayName":"Allow ESIM Modification","description":"If false, disables modifications to carrier plan related settings (only available on select carriers). Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowesimmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowesimmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowesimoutgoingtransfers","displayName":"Allow ESIM Outgoing Transfers","description":"If 'false', prevents the transfer of an eSIM from the device on which the restriction is installed to a different device. Available in iOS 18 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowesimoutgoingtransfers_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowesimoutgoingtransfers_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowexplicitcontent","displayName":"Allow Explicit Content","description":"If false, hides explicit music or video content purchased from the iTunes Store. Explicit content is marked as such by content providers, such as record labels, when sold through the iTunes Store. As of iOS 13, requires a supervised device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowexplicitcontent_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowexplicitcontent_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowexternalintelligenceintegrations","displayName":"Allow External Intelligence Integrations (Deprecated)","description":"If false, disables the use of external, cloud-based intelligence services with Siri.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowexternalintelligenceintegrations_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowexternalintelligenceintegrations_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowexternalintelligenceintegrationssignin","displayName":"Allow External Intelligence Integrations Sign In (Deprecated)","description":"If false, forces external intelligence providers into anonymous mode. If a user is already signed in to an external intelligence provider, applying this restriction will cause them to be signed out.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowexternalintelligenceintegrationssignin_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowexternalintelligenceintegrationssignin_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfilesharingmodification","displayName":"Allow File Sharing Modification","description":"If 'false', prevents modifying File Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfilesharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfilesharingmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfilesnetworkdriveaccess","displayName":"Allow Files Network Drive Access","description":"If false, prevents connecting to network drives in the Files app. Requires a supervised device. Available in iOS 13.1 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfilesnetworkdriveaccess_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfilesnetworkdriveaccess_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfilesusbdriveaccess","displayName":"Allow Files USB Drive Access","description":"If false, prevents connecting to any connected USB devices in the Files app. Requires a supervised device. Available in iOS 13.1 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfilesusbdriveaccess_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfilesusbdriveaccess_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfindmydevice","displayName":"Allow Find My Device","description":"If false, disables Find My Device in the Find My app. Requires a supervised device. Available in iOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfindmydevice_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfindmydevice_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfindmyfriends","displayName":"Allow Find My Friends","description":"If false, disables Find My Friends in the Find My app. Requires a supervised device. Available in iOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfindmyfriends_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfindmyfriends_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfindmyfriendsmodification","displayName":"Allow Find My Friends Modification","description":"If false, disables changes to Find My Friends. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfindmyfriendsmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfindmyfriendsmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfingerprintforunlock","displayName":"Allow Fingerprint For Unlock","description":"If false, prevents Touch ID or Face ID from unlocking a device. Available in iOS 7 and later, and macOS 10.12.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfingerprintforunlock_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfingerprintforunlock_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfingerprintmodification","displayName":"Allow Fingerprint Modification","description":"If false, prevents the user from modifying Touch ID or Face ID. Requires a supervised device. Available in iOS 8.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfingerprintmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfingerprintmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowgamecenter","displayName":"Allow Game Center","description":"If false, disables Game Center, and its icon is removed from the Home screen. Requires a supervised device. Available in iOS 6 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowgamecenter_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowgamecenter_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowgenmoji","displayName":"Allow Genmoji (Deprecated)","description":"When false, prohibits creating new Genmoji.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowgenmoji_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowgenmoji_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowglobalbackgroundfetchwhenroaming","displayName":"Allow Global Background Fetch When Roaming","description":"If false, disables global background fetch activity when an iOS phone is roaming. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowglobalbackgroundfetchwhenroaming_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowglobalbackgroundfetchwhenroaming_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowhostpairing","displayName":"Allow Host Pairing","description":"If false, disables host pairing with the exception of the supervision host. If no supervision host certificate has been configured, all pairing is disabled. Host pairing lets the administrator control if an iOS device can pair with a host Mac or PC. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowhostpairing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowhostpairing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowimageplayground","displayName":"Allow Image Playground (Deprecated)","description":"If false, prohibits the use of image generation.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowimageplayground_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowimageplayground_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowimagewand","displayName":"Allow Image Wand (Deprecated)","description":"When false, prohibits the use of Image Wand.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowimagewand_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowimagewand_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowinapppurchases","displayName":"Allow In App Purchases","description":"If false, prohibits in-app purchasing. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowinapppurchases_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowinapppurchases_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowinternetsharingmodification","displayName":"Allow Internet Sharing Modification","description":"If 'false', prevents modifying Internet Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowinternetsharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowinternetsharingmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowiphonemirroring","displayName":"Allow iPhone Mirroring","description":"If false, prohibits the use of iPhone Mirroring. When used on macOS, this prevents the Mac from mirroring any iPhone. When used on iOS, this prevents the iPhone from mirroring to any Mac.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowiphonemirroring_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowiphonemirroring_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowiphonewidgetsonmac","displayName":"Allow iPhone Widgets On Mac","description":"If 'false', disallows iPhone widgets on a Mac that has signed in the same AppleID for iCloud. Supervised only.\nAvailable on iOS 17 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowiphonewidgetsonmac_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowiphonewidgetsonmac_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowitunes","displayName":"Allow iTunes","description":"If false, disables the iTunes Music Store, and its icon is removed from the Home screen. Users cannot preview, purchase, or download content. As of iOS 13, requires a supervised device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowitunes_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowitunes_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowitunesfilesharing","displayName":"Allow iTunes File Sharing","description":"If false, disables iTunes file sharing services. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowitunesfilesharing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowitunesfilesharing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowkeyboardshortcuts","displayName":"Allow Keyboard Shortcuts (Deprecated)","description":"If false, disables keyboard shortcuts. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowkeyboardshortcuts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowkeyboardshortcuts_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowlistedappbundleids","displayName":"Allow Listed App Bundle IDs","description":"If present, this property allows only bundle IDs listed in the array to be shown or launchable. Include the value com.apple.webapp to allow all webclips. Requires a supervised device. Available in iOS 9.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_allowlivevoicemail","displayName":"Allow Live Voicemail","description":"If set to false, disables live voicemail on the device.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlivevoicemail_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlivevoicemail_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowlocalusercreation","displayName":"Allow Local User Creation","description":"If 'false', prevents creating new users in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlocalusercreation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlocalusercreation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowlockscreencontrolcenter","displayName":"Allow Lock Screen Control Center","description":"If false, prevents Control Center from appearing on the Lock screen. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlockscreencontrolcenter_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlockscreencontrolcenter_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowlockscreennotificationsview","displayName":"Allow Lock Screen Notifications View","description":"If false, disables the Notifications history view on the lock screen, so users can’t view past notifications. However, they can still see notifications when they arrive. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlockscreennotificationsview_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlockscreennotificationsview_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowlockscreentodayview","displayName":"Allow Lock Screen Today View","description":"If false, disables the Today view in Notification Center on the lock screen. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlockscreentodayview_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlockscreentodayview_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmailprivacyprotection","displayName":"Allow Mail Privacy Protection","description":"If false, disables Mail Privacy Protection on the device. Available in iOS 15.2 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmailprivacyprotection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmailprivacyprotection_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmailsmartreplies","displayName":"Allow Mail Smart Replies (Deprecated)","description":"If false, disables smart replies in Mail.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmailsmartreplies_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmailsmartreplies_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmailsummary","displayName":"Allow Mail Summary (Deprecated)","description":"If false, disables the ability to create summaries of email messages manually. This does not affect automatic summary generation.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmailsummary_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmailsummary_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmanagedappscloudsync","displayName":"Allow Managed Apps Cloud Sync","description":"If false, prevents managed apps from using iCloud sync. Available in iOS 8 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmanagedappscloudsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmanagedappscloudsync_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmanagedtowriteunmanagedcontacts","displayName":"Allow Managed To Write Unmanaged Contacts","description":"If true, managed apps can write contacts to unmanaged contacts accounts. If Allow Open From Managed To Unmanaged is true, this restriction has no effect. If this restriction is set to true, you must install the payload through MDM. Available in iOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmanagedtowriteunmanagedcontacts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmanagedtowriteunmanagedcontacts_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmarketplaceappinstallation","displayName":"Allow Marketplace App Installation","description":"When 'false', the device prevents installation of alternative marketplace apps from the web, and prevents any installed alternative marketplace apps from installing apps.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmarketplaceappinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmarketplaceappinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmediasharingmodification","displayName":"Allow Media Sharing Modification","description":"If false, prevents modification of Media Sharing settings.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmediasharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmediasharingmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmultiplayergaming","displayName":"Allow Multiplayer Gaming","description":"If false, prohibits multiplayer gaming. Requires a supervised device. Available in iOS 4.1 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmultiplayergaming_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmultiplayergaming_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmusicservice","displayName":"Allow Music Service","description":"If false, disables the Music service, and the Music app reverts to classic mode. Requires a supervised device. Available in iOS 9.3 and later, and macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmusicservice_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmusicservice_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allownews","displayName":"Allow News","description":"If false, disables News. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allownews_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allownews_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allownfc","displayName":"Allow NFC","description":"If false, disables NFC. Requires a supervised device. Available in iOS 14.2 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allownfc_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allownfc_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allownotestranscription","displayName":"Allow Notes Transcription (Deprecated)","description":"If false, disables transcription in Notes.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allownotestranscription_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allownotestranscription_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allownotestranscriptionsummary","displayName":"Allow Notes Transcription Summary (Deprecated)","description":"If `false`, disables transcription summarization in Notes.\n\nDeprecated: use the declarative management `com.apple.configuration.intelligence.settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allownotestranscriptionsummary_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allownotestranscriptionsummary_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allownotificationsmodification","displayName":"Allow Notifications Modification","description":"If false, disables modification of notification settings. Requires a supervised device. Available in iOS 9.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allownotificationsmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allownotificationsmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowopenfrommanagedtounmanaged","displayName":"Allow Open From Managed To Unmanaged","description":"If false, documents in managed apps and accounts only open in other managed apps and accounts. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowopenfrommanagedtounmanaged_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowopenfrommanagedtounmanaged_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowopenfromunmanagedtomanaged","displayName":"Allow Open From Unmanaged To Managed","description":"If false, documents in unmanaged apps and accounts only open in other unmanaged apps and accounts. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowopenfromunmanagedtomanaged_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowopenfromunmanagedtomanaged_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowotapkiupdates","displayName":"Allow OTAPKI Updates","description":"If false, disables over-the-air PKI updates. Setting this restriction to false doesn’t disable CRL and OCSP checks. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowotapkiupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowotapkiupdates_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpairedwatch","displayName":"Allow Paired Watch","description":"If false, disables pairing with an Apple Watch. Any currently paired Apple Watch is unpaired and the watch’s content is erased. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpairedwatch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpairedwatch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpassbookwhilelocked","displayName":"Allow Passbook While Locked","description":"If false, hides Passbook notifications from the lock screen. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpassbookwhilelocked_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpassbookwhilelocked_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpasscodemodification","displayName":"Allow Passcode Modification","description":"If false, prevents the device passcode from being added, changed, or removed. This restriction is ignored by Shared iPads. Requires a supervised device. Available in iOS 9 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpasscodemodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpasscodemodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpasswordautofill","displayName":"Allow Password Auto Fill","description":"If false, disables the AutoFill Passwords feature in iOS (with Keychain and third-party password managers) and the user isn’t prompted to use a saved password in Safari or in apps. This restriction also disables Automatic Strong Passwords, and strong passwords are no longer suggested to users. It doesn’t prevent AutoFill for contact info and credit cards in Safari. Requires a supervised device. Available in iOS 12 and later, and macOS 10.14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpasswordautofill_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpasswordautofill_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpasswordproximityrequests","displayName":"Allow Password Proximity Requests","description":"If false, disables requesting passwords from nearby devices. Requires a supervised device. Available in iOS 12 and later, and macOS 10.14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpasswordproximityrequests_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpasswordproximityrequests_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpasswordsharing","displayName":"Allow Password Sharing","description":"If false, disables sharing passwords with the Airdrop Passwords feature. Requires a supervised device. Available in iOS 12 and later, and macOS 10.14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpasswordsharing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpasswordsharing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpersonalhotspotmodification","displayName":"Allow Personal Hotspot Modification","description":"If false, disables modifications of the personal hotspot setting. Requires a supervised device. Available in iOS 12.2 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpersonalhotspotmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpersonalhotspotmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpersonalizedhandwritingresults","displayName":"Allow Personalized Handwriting Results (Deprecated)","description":"If false, prevents the system from generating text in the user's handwriting.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpersonalizedhandwritingresults_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpersonalizedhandwritingresults_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowphotostream","displayName":"Allow Photo Stream (Deprecated)","description":"If false, disables Photo Stream. Available in iOS 5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowphotostream_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowphotostream_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpodcasts","displayName":"Allow Podcasts","description":"If false, disables podcasts. Requires a supervised device. Available in iOS 8 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpodcasts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpodcasts_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpredictivekeyboard","displayName":"Allow Predictive Keyboard (Deprecated)","description":"If false, disables predictive keyboards. Requires a supervised device. Available in iOS 8.1.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpredictivekeyboard_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpredictivekeyboard_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowprintersharingmodification","displayName":"Allow Printer Sharing Modification","description":"If 'false', prevents modifying Printer Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowprintersharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowprintersharingmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowproximitysetuptonewdevice","displayName":"Allow Proximity Setup To New Device","description":"If false, disables the prompt to set up new devices that are nearby. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowproximitysetuptonewdevice_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowproximitysetuptonewdevice_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowradioservice","displayName":"Allow Radio Service","description":"If false, disables Apple Music Radio. Requires a supervised device. Available in iOS 9.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowradioservice_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowradioservice_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowrapidsecurityresponseinstallation","displayName":"Allow Background Security Improvement Installation (Deprecated)","description":"If false, Rapid Security Response will be disabled. ","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowrapidsecurityresponseinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowrapidsecurityresponseinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowrapidsecurityresponseremoval","displayName":"Allow Background Security Improvement Removal (Deprecated)","description":"If false, users are unable to remove the Rapid Security Response option.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowrapidsecurityresponseremoval_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowrapidsecurityresponseremoval_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowrcsmessaging","displayName":"Allow RCS Messaging","description":"If false, prevents the use of RCS messaging.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowrcsmessaging_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowrcsmessaging_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowremoteappleeventsmodification","displayName":"Allow Remote Apple Events Modification","description":"If 'false', prevents modifying Remote Apple Events Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowremoteappleeventsmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowremoteappleeventsmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowremotescreenobservation","displayName":"Allow Remote Screen Observation","description":"If false, disables remote screen observation by the Classroom app. If Allow Screen Shot is set to false, the Classroom app doesn't observe remote screens. Required a supervised device until iOS 13 and macOS 10.15. Available in iOS 12 and later, and macOS 10.14.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowremotescreenobservation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowremotescreenobservation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowrosettausageawareness","displayName":"Allow Rosetta Usage Awareness","description":"If `false`, disables Rosetta usage awareness. When Rosetta usage awareness is active, the device displays a pop-up dialog to the user when launching an app that uses Rosetta. The pop-up dialog indicates that Rosetta will be removed in a future version of the operating system so that the user can contact the app vendor regarding a replacement for the current app.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowrosettausageawareness_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowrosettausageawareness_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsafari","displayName":"Allow Safari","description":"If false, disables the Safari web browser app, and its icon is removed from the Home screen. This setting also prevents users from opening web clips. As of iOS 13, requires a supervised device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsafari_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsafari_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsafarihistoryclearing","displayName":"Allow Safari History Clearing","description":"If `false`, the system disables the ability to clear browsing history in Safari.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsafarihistoryclearing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsafarihistoryclearing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsafariprivatebrowsing","displayName":"Allow Safari Private Browsing","description":"If `false`, the system disables the ability to use private browsing in Safari.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsafariprivatebrowsing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsafariprivatebrowsing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsafarisummary","displayName":"Allow Safari Summary (Deprecated)","description":"If false, disables the ability to summarize content in Safari.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsafarisummary_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsafarisummary_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsatelliteconnection","displayName":"Allow Satellite Connection","description":"If `false`, the system prohibits the connection to and use of satellite services.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsatelliteconnection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsatelliteconnection_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowscreenshot","displayName":"Allow Screen Shot","description":"If false, disables saving a screenshot of the display and capturing a screen recording. It also disables the Classroom app from observing remote screens. Available in iOS 4 and later, and macOS 10.14.4 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowscreenshot_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowscreenshot_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowshareddevicetemporarysession","displayName":"Allow Shared Device Temporary Session","description":"If false, temporary sessions aren’t available on Shared iPad. Available in iOS 13.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowshareddevicetemporarysession_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowshareddevicetemporarysession_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsharedstream","displayName":"Allow Shared Stream","description":"If false, disables Shared Photo Stream. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsharedstream_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsharedstream_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowspellcheck","displayName":"Allow Spell Check (Deprecated)","description":"If false, disables keyboard spell-check. Requires a supervised device. Available in iOS 8.1.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowspellcheck_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowspellcheck_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowspotlightinternetresults","displayName":"Allow Spotlight Internet Results","description":"If false, disables Spotlight Internet search results in Siri Suggestions. Available in iOS 8 and later, and macOS 10.11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowspotlightinternetresults_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowspotlightinternetresults_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowstartupdiskmodification","displayName":"Allow Startup Disk Modification","description":"If 'false', prevents modification of Startup Disk setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowstartupdiskmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowstartupdiskmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsystemappremoval","displayName":"Allow System App Removal","description":"If false, disables the removal of system apps from the device. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsystemappremoval_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsystemappremoval_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowtimemachinebackup","displayName":"Allow Time Machine Backup","description":"If 'false', prevents modification of Time Machine settings in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowtimemachinebackup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowtimemachinebackup_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowuiappinstallation","displayName":"Allow UI App Installation","description":"If false, disables the App Store, and its icon is removed from the Home screen. However, users may continue to use host apps (iTunes, Configurator) to install or update their apps. In iOS 10 and later, MDM commands can override this restriction. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowuiappinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowuiappinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowuiconfigurationprofileinstallation","displayName":"Allow UI Configuration Profile Installation","description":"If false, prohibits the user from installing configuration profiles and certificates interactively. Requires a supervised device. Available in iOS 6 and later and macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowuiconfigurationprofileinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowuiconfigurationprofileinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowuniversalcontrol","displayName":"Allow Universal Control","description":"If false, disables Universal Control. Available in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowuniversalcontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowuniversalcontrol_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowunmanagedtoreadmanagedcontacts","displayName":"Allow Unmanaged To Read Managed Contacts","description":"If true, unmanaged apps can read from managed contacts accounts. If Allow Open From Managed To Unmanaged is true, this restriction has no effect. If this restriction is set to true, you must install the payload through MDM. Available in iOS 12 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowunmanagedtoreadmanagedcontacts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowunmanagedtoreadmanagedcontacts_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowunpairedexternalboottorecovery","displayName":"Allow Unpaired External Boot To Recovery","description":"If true, allows devices to be booted into recovery by an unpaired device. Requires a supervised device. Available in iOS 14.5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowunpairedexternalboottorecovery_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowunpairedexternalboottorecovery_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowuntrustedtlsprompt","displayName":"Allow Untrusted TLS Prompt","description":"If false, automatically rejects untrusted HTTPS certificates without prompting the user. Available in iOS 5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowuntrustedtlsprompt_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowuntrustedtlsprompt_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowusbrestrictedmode","displayName":"Allow USB Restricted Mode","description":"If false, allows the device to always connect to USB accessories while locked. On macOS, allows new USB accessories to connect without authorization.\r\nRequires a supervised device. Available in iOS 11.4.1 and later and macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowusbrestrictedmode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowusbrestrictedmode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowvideoconferencing","displayName":"Allow Video Conferencing","description":"If false, hides the FaceTime app. As of iOS 13, requires a supervised device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowvideoconferencing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowvideoconferencing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowvideoconferencingremotecontrol","displayName":"Allow Video Conferencing Remote Control (Deprecated)","description":"If `false`, disables the ability for a remote FaceTime session to request control of the device.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowvideoconferencingremotecontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowvideoconferencingremotecontrol_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowvisualintelligencesummary","displayName":"Allow Visual Intelligence Summary (Deprecated)","description":"If `false`, the system disables visual intelligence summarization.\n\nDeprecated: use the declarative management `com.apple.configuration.intelligence.settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowvisualintelligencesummary_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowvisualintelligencesummary_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowvoicedialing","displayName":"Allow Voice Dialing (Deprecated)","description":"If false, disables voice dialing if the device is locked with a passcode. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowvoicedialing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowvoicedialing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowvpncreation","displayName":"Allow VPN Creation","description":"If false, disables the creation of VPN configurations. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowvpncreation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowvpncreation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowwallpapermodification","displayName":"Allow Wallpaper Modification","description":"If false, prevents wallpaper from being changed. Requires a supervised device. Available in iOS 9 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowwallpapermodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowwallpapermodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowwebdistributionappinstallation","displayName":"Allow Web Distribution App Installation","description":"When 'false', the device prevents installation of apps directly from the web.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowwebdistributionappinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowwebdistributionappinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowwritingtools","displayName":"Allow Writing Tools (Deprecated)","description":"If false, disables Apple Intelligence writing tools.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowwritingtools_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowwritingtools_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_autonomoussingleappmodepermittedappids","displayName":"Autonomous Single App Mode Permitted App IDs","description":"If present, allows apps identified by the bundle IDs listed in the array to autonomously enter Single App Mode. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_blockedappbundleids","displayName":"Blocked App Bundle IDs","description":"If present, prevents bundle IDs listed in the array from being shown or launchable. Include the value com.apple.webapp to restrict all webclips. Requires a supervised device. Available in iOS 9.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_com.apple.applicationaccess","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_deniediccidsforimessagefacetime","displayName":"Denied ICCIDs For iMessage And FaceTime","description":"An array of strings representing ICCIDs of cellular plans. The device prevents use of any matching cellular networks in iMessage and FaceTime. The array must contain no more than 4 ICCID strings.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_deniediccidsforrcs","displayName":"Denied ICCIDs For RCS","description":"An array of strings representing ICCIDs of cellular plans. The device prevents use of any matching cellular networks with RCS messaging. The array must contain no more than 4 ICCID strings.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_enforcedfingerprinttimeout","displayName":"Enforced Fingerprint Timeout","description":"The value, in seconds, after which the fingerprint unlock will require a password to authenticate. The default value is 48 hours.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_enforcedsoftwareupdatedelay","displayName":"Enforced Software Update Delay (Deprecated)","description":"Sets how many days to delay a software update on the device. With this restriction in place, the user doesn't see a software update until the specified number of days after the software update release date. This value is used by Force Delayed App Software Updates and Force Delayed Software Updates. Requires a supervised device in iOS. Available in iOS 11.3 and later, and macOS 10.13.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_enforcedsoftwareupdatemajorosdeferredinstalldelay","displayName":"Enforced Software Update Major OS Deferred Install Delay (Deprecated)","description":"This restriction allows the admin to set how many days to delay a major software update on the device. When this restriction is in place the user sees a software update only after the specified delay after the release of the software update. This value controls the delay for Force Delayed Major Software Updates. Available in macOS 11.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_enforcedsoftwareupdateminorosdeferredinstalldelay","displayName":"Enforced Software Update Minor OS Deferred Install Delay (Deprecated)","description":"This restriction allows the admin to set how many days to delay a minor OS software update on the device. When this restriction is in place the user see a software update only after the specified delay after the release of the software update. This value controls the delay for Force Delayed Software Updates. Available in macOS 11.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_enforcedsoftwareupdatenonosdeferredinstalldelay","displayName":"Enforced Software Update Non OS Deferred Install Delay (Deprecated)","description":"This restriction allows the admin to set how many days to delay an app software update on the device. When this restriction is in place the user sees a non-OS software update only after the specified delay after the release of the software. This value controls the delay for Force Delayed App Software Updates. Available in macOS 11.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_forceairdropunmanaged","displayName":"Force AirDrop Unmanaged","description":"If true, causes AirDrop to be considered an unmanaged drop target. Available in iOS 9 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceairdropunmanaged_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceairdropunmanaged_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceairplayoutgoingrequestspairingpassword","displayName":"Force AirPlay Outgoing Requests Pairing Password","description":"If true, forces all devices receiving AirPlay requests from this device to use a pairing password. Available in iOS 7.1 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceairplayoutgoingrequestspairingpassword_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceairplayoutgoingrequestspairingpassword_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceairprinttrustedtlsrequirement","displayName":"Force AirPrint Trusted TLS Requirement","description":"If true, requires trusted certificates for TLS printing communication. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceairprinttrustedtlsrequirement_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceairprinttrustedtlsrequirement_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceassistantprofanityfilter","displayName":"Force Assistant Profanity Filter (Deprecated)","description":"If true, forces the use of the profanity filter assistant. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceassistantprofanityfilter_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceassistantprofanityfilter_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceauthenticationbeforeautofill","displayName":"Force Authentication Before Auto Fill","description":"If true, the user must authenticate before passwords or credit card information can be autofilled in Safari and Apps. If this restriction isn’t enforced, the user can toggle this feature in Settings. Only supported on devices with Face ID or Touch ID. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceauthenticationbeforeautofill_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceauthenticationbeforeautofill_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceautomaticdateandtime","displayName":"Force Automatic Date And Time","description":"If true, enables the Set Automatically feature in Date & Time and can’t be disabled by the user. The device’s time zone is updated only when the device can determine its location using a cellular connection or Wi-Fi with location services enabled. Requires a supervised device. Available in iOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceautomaticdateandtime_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceautomaticdateandtime_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcebypassscreencapturealert","displayName":"Force Bypass Screen Capture Alert","description":"If set to true, then the presentation of a screen capture alert will be bypassed.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcebypassscreencapturealert_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcebypassscreencapturealert_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcecaptiveportalconnectionfromlockscreen","displayName":"Force Captive Portal Connection From Lock Screen","description":"If `true`, the system allows use of the captive WiFi portal at login or unlock.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcecaptiveportalconnectionfromlockscreen_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcecaptiveportalconnectionfromlockscreen_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceclassroomautomaticallyjoinclasses","displayName":"Force Classroom Automatically Join Classes","description":"If true, automatically gives permission to the teacher’s requests without prompting the student. Requires a supervised device. Available in iOS 11 and later, and macOS 10.14.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceclassroomautomaticallyjoinclasses_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceclassroomautomaticallyjoinclasses_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceclassroomrequestpermissiontoleaveclasses","displayName":"Force Classroom Request Permission To Leave Classes","description":"If true, a student enrolled in an unmanaged course through Classroom requests permission from the teacher when attempting to leave the course. Requires a supervised device. Available in iOS 11.3 and later, and macOS 10.14.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceclassroomrequestpermissiontoleaveclasses_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceclassroomrequestpermissiontoleaveclasses_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceclassroomunpromptedappanddevicelock","displayName":"Force Classroom Unprompted App And Device Lock","description":"If true, allows the teacher to lock apps or the device without prompting the student. Requires a supervised device. Available in iOS 11 and later, and macOS 10.14.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceclassroomunpromptedappanddevicelock_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceclassroomunpromptedappanddevicelock_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceclassroomunpromptedscreenobservation","displayName":"Force Classroom Unprompted Screen Observation","description":"If `true` and `ScreenObservationPermissionModificationAllowed` is also `true` in the Education payload, a student enrolled in a managed course through the Classroom app automatically gives permission to that course teacher's requests to observe the student's screen without prompting the student.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceclassroomunpromptedscreenobservation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceclassroomunpromptedscreenobservation_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcedelayedappsoftwareupdates","displayName":"Force Delayed App Software Updates (Deprecated)","description":"If set to true, delays user visibility of major OS Software Updates. Available in macOS 11.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcedelayedappsoftwareupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcedelayedappsoftwareupdates_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcedelayedmajorsoftwareupdates","displayName":"Force Delayed Major Software Updates (Deprecated)","description":"If true, delays user visibility of non-OS Software Updates. Requires a supervised device. Visibility of Operating System updates is controlled through Force Delayed Software Updates. The delay is 30 days unless Enforced Software Update Delay is set to another value. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcedelayedmajorsoftwareupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcedelayedmajorsoftwareupdates_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcedelayedsoftwareupdates","displayName":"Force Delayed Software Updates (Deprecated)","description":"If true, delays user visibility of software updates. In macOS, seed build updates are allowed, without delay. The delay is 30 days unless Enforced Software Update Delay is set to another value. Available in iOS 11.3 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcedelayedsoftwareupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcedelayedsoftwareupdates_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceencryptedbackup","displayName":"Force Encrypted Backup","description":"If true, encrypts all backups. Available in iOS 4 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceencryptedbackup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceencryptedbackup_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceitunesstorepasswordentry","displayName":"Force iTunes Store Password Entry (Deprecated)","description":"If true, forces the user to enter their iTunes password for each transaction. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceitunesstorepasswordentry_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceitunesstorepasswordentry_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcelimitadtracking","displayName":"Force Limit Ad Tracking","description":"If true, limits ad tracking. Additionally, it disables app tracking and the Allow Apps To Request To Track setting. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcelimitadtracking_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcelimitadtracking_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceondeviceonlydictation","displayName":"Force On Device Only Dictation (Deprecated)","description":"If true, disables connections to Siri servers for the purposes of dictation. Available in iOS 14.5 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceondeviceonlydictation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceondeviceonlydictation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceondeviceonlytranslation","displayName":"Force On Device Only Translation (Deprecated)","description":"If true, the device won’t connect to Siri servers for the purposes of translation. Available in iOS 15 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceondeviceonlytranslation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceondeviceonlytranslation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcepreserveesimonerase","displayName":"Force Preserve ESIM On Erase","description":"If set to true, eSIM will be preserved when a device is erased due to too many failed password attempt or the \"Erase All Content and Settings\" option in Settings > General > Reset. eSIM will not be preserved if the device is erased by FindMy.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcepreserveesimonerase_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcepreserveesimonerase_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcewatchwristdetection","displayName":"Force Watch Wrist Detection","description":"If true, forces a paired Apple Watch to use Wrist Detection. Available in iOS 8.2 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcewatchwristdetection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcewatchwristdetection_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcewificonfigurationonlockscreen","displayName":"Force Wifi Configuration On Lock Screen","description":"If `true`, the system allows the user to select WiFi networks at login or unlock.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcewificonfigurationonlockscreen_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcewificonfigurationonlockscreen_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcewifipoweron","displayName":"Force WiFi Power On","description":"If true, prevents Wi-Fi from being turned off in Settings or Control Center, even by entering or leaving Airplane Mode. It doesn’t prevent selecting which Wi-Fi network to use. Requires a supervised device. Available in iOS 13.0 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcewifipoweron_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcewifipoweron_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcewifitoallowednetworksonly","displayName":"Force WiFi To Allowed Networks Only","description":"If true, limits device to only join Wi-Fi networks set-up via configuration profile. Requires a supervised device. Available in iOS 14.5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcewifitoallowednetworksonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcewifitoallowednetworksonly_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsau","displayName":"Rating Apps - Australia","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsau_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsca","displayName":"Rating Apps - Canada","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsca_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsde","displayName":"Rating Apps - Germany","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsde_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsexemptedbundleids","displayName":"Rating Apps Exempted Bundle IDs","description":"If present, the system exempts apps with bundle IDs in the array from age-based rating restrictions. The system uses intersection combine rules to combine multiple payloads and any exceptions that parental control apps provide, including ScreenTime.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_ratingappsfr","displayName":"Rating Apps - France","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsfr_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsgb","displayName":"Rating Apps - Great Britain","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsgb_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsie","displayName":"Rating Apps - Ireland","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsie_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsjp","displayName":"Rating Apps - Japan","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsjp_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsnz","displayName":"Rating Apps - New Zealand","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsnz_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsus","displayName":"Rating Apps - United States","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsus_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsus_1","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsus_2","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsus_3","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsus_4","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsus_5","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesau","displayName":"Rating Movies - Australia","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesau_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_2","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_3","displayName":"M","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_4","displayName":"MA15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_5","displayName":"R18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_6","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesca","displayName":"Rating Movies - Canada","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesca_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesca_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesca_2","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesca_3","displayName":"14A","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesca_4","displayName":"18A","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesca_5","displayName":"R","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesca_6","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesde","displayName":"Rating Movies - Germany","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesde_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesde_1","displayName":"Ab 0 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesde_2","displayName":"Ab 6 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesde_3","displayName":"Ab 12 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesde_4","displayName":"Ab 16 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesde_5","displayName":"Ab 18 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesde_6","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesfr","displayName":"Rating Movies - France","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesfr_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesfr_2","displayName":"10","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesfr_3","displayName":"12","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesfr_4","displayName":"16","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesfr_5","displayName":"18","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesfr_6","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesgb","displayName":"Rating Movies - Great Britain","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesgb_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_1","displayName":"U","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_2","displayName":"UC","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_3","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_4","displayName":"12","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_5","displayName":"12A","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_6","displayName":"15","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_7","displayName":"18","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_8","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesie","displayName":"Rating Movies - Ireland","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesie_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_2","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_3","displayName":"12A","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_4","displayName":"15A","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_5","displayName":"16","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_6","displayName":"18","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_7","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesjp","displayName":"Rating Movies - Japan","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesjp_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesjp_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesjp_2","displayName":"PG-12","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesjp_3","displayName":"R15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesjp_4","displayName":"R18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesjp_5","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesnz","displayName":"Rating Movies - New Zealand","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesnz_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_2","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_3","displayName":"M","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_4","displayName":"R13","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_5","displayName":"R15","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_6","displayName":"R16","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_7","displayName":"R18","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_8","displayName":"R","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_9","displayName":"RP16","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_10","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesus","displayName":"Rating Movies - United States","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesus_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesus_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesus_2","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesus_3","displayName":"PG-13","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesus_4","displayName":"R","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesus_5","displayName":"NC-17","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesus_6","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingregion","displayName":"Rating Region","description":"The country key that profile tools use to display the proper ratings for the given region. This data isn’t recognized or reported by the client.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingregion_0","displayName":"United States","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_1","displayName":"Australia","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_2","displayName":"Canada","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_3","displayName":"Germany","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_4","displayName":"France","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_5","displayName":"Ireland","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_6","displayName":"Japan","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_7","displayName":"New Zealand","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_8","displayName":"Great Britain","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsau","displayName":"Rating TV Shows - Australia","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsau_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_1","displayName":"P","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_2","displayName":"C","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_3","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_4","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_5","displayName":"M","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_6","displayName":"MA15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_7","displayName":"AV15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_8","displayName":"All","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_9","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsca","displayName":"Rating TV Shows - Canada","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsca_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_1","displayName":"C","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_2","displayName":"C8","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_3","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_4","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_5","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_6","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_7","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsde","displayName":"Rating TV Shows - Germany","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsde_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_1","displayName":"Ab 0 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_2","displayName":"Ab 6 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_3","displayName":"Ab 12 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_4","displayName":"Ab 16 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_5","displayName":"Ab 18 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_7","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsfr","displayName":"Rating TV Shows - France","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsfr_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_1","displayName":"-10","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_2","displayName":"-12","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_3","displayName":"-16","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_4","displayName":"-18","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_5","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsgb","displayName":"Rating TV Shows - Great Britain","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsgb_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsgb_1","displayName":"Caution","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsgb_2","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsie","displayName":"Rating TV Shows - Ireland","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsie_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsie_1","displayName":"GA","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsie_2","displayName":"CH","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsie_3","displayName":"YA","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsie_4","displayName":"PS","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsie_5","displayName":"MA","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsie_6","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsjp","displayName":"Rating TV Shows - Japan","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsjp_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsjp_1","displayName":"Explicit Allowed","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsjp_2","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsnz","displayName":"Rating TV Shows - New Zealand","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsnz_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsnz_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsnz_2","displayName":"PGR","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsnz_3","displayName":"AO","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsnz_4","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsus","displayName":"Rating TV Shows - United States","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsus_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_1","displayName":"TV-Y","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_2","displayName":"TV-Y7","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_3","displayName":"TV-G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_4","displayName":"TV-PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_5","displayName":"TV-14","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_6","displayName":"TB-MA","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_7","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_requiremanagedpasteboard","displayName":"Require Managed Pasteboard","description":"If true, copy and paste functionality respects the Allow Open From Managed To Unmanaged and Allow Open From Unmanaged To Managed restrictions. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_requiremanagedpasteboard_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_requiremanagedpasteboard_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_safariacceptcookies","displayName":"Safari Accept Cookies","description":"This value defines the conditions under which the device accepts cookies. The user-facing settings changed in iOS 11, although the possible values remain the same. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariacceptcookies_0","displayName":"Prevent Cross-Site Tracking and Block All Cookies are enabled and the user canʼt disable either setting.","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariacceptcookies_1","displayName":"Prevent Cross-Site Tracking is enabled and the user canʼt disable it. Block All Cookies is not enabled, although the user can enable it.","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariacceptcookies_2","displayName":"Prevent Cross-Site Tracking is enabled and Block All Cookies is not enabled. The user can toggle either setting.","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_safariallowautofill","displayName":"Safari Allow Autofill","description":"If false, disables Safari AutoFill for passwords, contact info, and credit cards and also prevents the Keychain from being used for AutoFill. Though third-party password managers are allowed and apps can use AutoFill. As of iOS 13, requires a supervised device. Available in iOS 4 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariallowautofill_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariallowautofill_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_safariallowjavascript","displayName":"Safari Allow Java Script","description":"If false, Safari doesn’t execute JavaScript. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariallowjavascript_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariallowjavascript_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_safariallowpopups","displayName":"Safari Allow Popups","description":"If false, Safari doesn’t allow pop-up windows. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariallowpopups_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariallowpopups_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_safariforcefraudwarning","displayName":"Safari Force Fraud Warning","description":"If true, enables Safari fraud warning. Available in iOS 4 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariforcefraudwarning_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariforcefraudwarning_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess.new_com.apple.applicationaccess.new","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f019963f-f4ed-4429-b6e3-babfb24c36a8","categoryName":"Parental Controls Application Restrictions","options":null},{"id":"com.apple.applicationaccess.new_familycontrolsenabled","displayName":"Family Controls Enabled","description":"If true, enables app access restrictions.","helpText":null,"infoUrls":[],"categoryId":"f019963f-f4ed-4429-b6e3-babfb24c36a8","categoryName":"Parental Controls Application Restrictions","options":[{"id":"com.apple.applicationaccess.new_familycontrolsenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess.new_familycontrolsenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.appstore_com.apple.appstore","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","categoryName":"App Store","options":null},{"id":"com.apple.appstore_disablesoftwareupdatenotifications","displayName":"Disable Software Update Notifications","description":"If true, disables software update notifications. Available in macOS 10.10 and later.","helpText":null,"infoUrls":[],"categoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","categoryName":"App Store","options":[{"id":"com.apple.appstore_disablesoftwareupdatenotifications_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.appstore_disablesoftwareupdatenotifications_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.appstore_restrict-store-disable-app-adoption","displayName":"Restrict-store-disable-app-adoption","description":"If true, disables app adoption by users. Available in macOS 10.10 and later.","helpText":null,"infoUrls":[],"categoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","categoryName":"App Store","options":[{"id":"com.apple.appstore_restrict-store-disable-app-adoption_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.appstore_restrict-store-disable-app-adoption_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.appstore_restrict-store-softwareupdate-only","displayName":"Restrict Store Software Update Only","description":"If true, prevents App Store from launching. Available in macOS 10.14 and later. Restricts installations to software updates only in macOS 10.10 - 10.13.","helpText":null,"infoUrls":[],"categoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","categoryName":"App Store","options":[{"id":"com.apple.appstore_restrict-store-softwareupdate-only_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.appstore_restrict-store-softwareupdate-only_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.asam_allowedapplications","displayName":"Allowed Applications","description":"An array of dictionaries that specifies the apps that can be granted access to the Accessibility APIs.","helpText":null,"infoUrls":[],"categoryId":"daa2ea69-8026-465a-942c-75eb0396d5b9","categoryName":"Autonomous Single App Mode","options":null},{"id":"com.apple.asam_allowedapplications_item_bundleidentifier","displayName":"Bundle Identifier","description":"The unique bundle identifier. If two dictionaries contain the same Bundle Identifier value but a different Team Identifier value, this will be considered an error and the profile won't be installed.","helpText":null,"infoUrls":[],"categoryId":"daa2ea69-8026-465a-942c-75eb0396d5b9","categoryName":"Autonomous Single App Mode","options":null},{"id":"com.apple.asam_allowedapplications_item_teamidentifier","displayName":"Team Identifier","description":"The developer's team identifier, used when the app was signed.","helpText":null,"infoUrls":[],"categoryId":"daa2ea69-8026-465a-942c-75eb0396d5b9","categoryName":"Autonomous Single App Mode","options":null},{"id":"com.apple.asam_com.apple.asam","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"daa2ea69-8026-465a-942c-75eb0396d5b9","categoryName":"Autonomous Single App Mode","options":null},{"id":"com.apple.assetcache.managed_allowcachedelete","displayName":"Allow Cache Delete","description":"Allow the system to purge content from the cache automatically when it needs disk space for other apps (i.e. when free disk space runs low on the computer). Customers who want Content Caching to be as effective as possible should turn this setting off.\r\nAvailable in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_allowcachedelete_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_allowcachedelete_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_allowpersonalcaching","displayName":"Allow Personal Caching","description":"If true, caches the user's iCloud data. Clients may take some time (hours or days) to react to changes to this setting; it doesn't have an immediate effect.\r\nAt least one of the Allow Personal Caching or Allow Shared Caching settings must be true.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_allowpersonalcaching_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_allowpersonalcaching_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_allowsharedcaching","displayName":"Allow Shared Caching","description":"If true, caches non-iCloud content, such as apps and software updates. Clients may take some time (hours, days) to react to changes to this setting; it does not have an immediate effect.\r\nAt least one of the Allow Personal Caching or Allow Shared Caching settings must be true. ","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_allowsharedcaching_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_allowsharedcaching_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_autoactivation","displayName":"Auto Activation","description":"If true, automatically activates the content cache when possible and prevents it from being disabled. If the Allow Content Caching restriction is set to false, Auto Activation is also false.\r\nRemoving a profile that set Auto Activation to true does not deactivate the Content Cache.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_autoactivation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_autoactivation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_autoenabletetheredcaching","displayName":"Auto Enable Tethered Caching","description":"Automatically enable Internet connection sharing when possible and prevent disabling Internet connection sharing. Deny Tethered Caching overrides Auto Enable Tethered Caching. Tethered caching requires Content Caching. Available in macOS 10.15.4 and later.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_autoenabletetheredcaching_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_autoenabletetheredcaching_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_cachelimit","displayName":"Cache Limit","description":"The maximum number of bytes of disk space that will be used for the content cache. A value of 0 means unlimited disk space.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_com.apple.assetcache.managed","displayName":"Top Level Setting Group Collection","description":"com.apple.AssetCache.managed","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_datapath","displayName":"Data Path","description":"The path to the directory used to store cached content. Changing this setting manually doesn't automatically move cached content from the old location to the new one. To move content automatically, use the Sharing preference's Content Caching pane. The value must be (or end with) /Library/Application Support/Apple/AssetCache/Data.\r\nA directory and its intermediates are created for the given data path if it doesn't already exist. The directory is owned by _assetcache:_assetcache and has mode 0750. Its immediate parent directory (.../Library/Application Support/Apple/AssetCache) is owned by _assetcache:_assetcache and has mode 0755. ","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_denytetheredcaching","displayName":"Deny Tethered Caching","description":"If true, disables tethered caching.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_denytetheredcaching_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_denytetheredcaching_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_displayalerts","displayName":"Display Alerts","description":"If true, Content Caching displays exceptional conditions (alerts) as system notifications in the upper corner of the screen. Alerts were automatically displayed starting in macOS 10.13. In macOS 10.15 the alerts are off by default, but still available via this setting.\r\nAvailable in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_displayalerts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_displayalerts_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_keepawake","displayName":"Keep Awake","description":"If true, prevents the computer from sleeping as long as Content Caching is on (System Preferences > Sharing > Content Caching is on). Customers who want Content Caching to be as available as musch as possible should turn this setting on.\r\nAvailable in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_keepawake_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_keepawake_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_listenranges","displayName":"Listen Ranges","description":"The range of client IP addresses to serve.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_listenranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_listenranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_listenranges_item_type","displayName":"IP Address Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_listenranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_listenranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_listenrangesonly","displayName":"Listen Ranges Only","description":"If true, the content cache provides content to the clients in the Listen Ranges.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_listenrangesonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_listenrangesonly_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_listenwithpeersandparents","displayName":"Listen With Peers And Parents","description":"If true, the content cache provides content to the clients in the union of the Listen Ranges, Peer Listen Ranges and Parents.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_listenwithpeersandparents_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_listenwithpeersandparents_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_localsubnetsonly","displayName":"Local Subnets Only","description":"If true, the content cache offers content to clients only on the same immediate local network only. No content is offered to clients on other networks reachable by the content cache. If LocalSubnetsOnly is set to true, ListenRanges will be ignored.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_localsubnetsonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_localsubnetsonly_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_logclientidentity","displayName":"Log Client Identity","description":"If true, the Content Cache logs the IP address and port number of the clients that request content. ","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_logclientidentity_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_logclientidentity_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_parents","displayName":"Parents","description":"An array of the local IP addresses of other content caches that this cache should download from or upload to, instead of downloading from or uploading to Apple directly. Invalid addresses and addresses of computers that aren't content caches are ignored. Parent caches that become unavailable are skipped. If all parent content caches become unavailable, the content cache downloads from or uploads to Apple directly, until a parent content cache becomes available again.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy","displayName":"Parent Selection Policy","description":"The policy to implement when choosing among more than one configured parent content cache. With every policy, parent caches that are temporarily unavailable are skipped.\r\nfirst-available: Always use the first available parent in the Parents list. Use this policy to designate permanent primary, secondary, and subsequent parents.\r\n\r\nurl-path-hash: Hash the path part of the requested URL so that the same parent is always used for the same URL. This is useful for maximizing the size of the combined caches of the parents.\r\n\r\nrandom: Choose a parent at random. Use this policy for load balancing.\r\n\r\nround-robin: Rotate through the parents in order. Use this policy for load balancing.\r\n\r\nsticky-available: Use the first available parent that is available in the Parents list until it becomes unavailable, then advance to the next one. Use this policy for designating floating primary, secondary, and subsequent parents. ","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_parentselectionpolicy_0","displayName":"first-available","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_1","displayName":"url-path-hash","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_2","displayName":"random","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_3","displayName":"round-robin","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_4","displayName":"sticky-available","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_peerfilterranges","displayName":"Peer Filter Ranges","description":"The ranges of peer IP addresses that the content cache uses to filter its list of peers to query for content. The content cache only queries peers in Peer Filter Ranges. When Peer Filter Ranges is an empty array, the content cache doesn't query any peers.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_peerfilterranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_peerfilterranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_peerfilterranges_item_type","displayName":"IP Address Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_peerfilterranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_peerfilterranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_peerlistenranges","displayName":"Peer Listen Ranges","description":"The ranges of peer IP addresses the content cache responds to. When Peer Listen Ranges is an empty array, the content cache responds with an error to all cache queries.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_peerlistenranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_peerlistenranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_peerlistenranges_item_type","displayName":"IP Address Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_peerlistenranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_peerlistenranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_peerlocalsubnetsonly","displayName":"Peer Local Subnets Only","description":"If true, the content cache only peers with other content caches on the same immediate local network, rather than with content caches that use the same public IP address as the device. When Peer Local Subnets Only is true, it overrides the configuration of Peer Filter Ranges and Peer Listen Ranges. If the network changes, the local network peering restrictions update appropriately. If false, the content cache defers to Peer Filter Ranges and Peer Listen Ranges for configuring the peering restrictions.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_peerlocalsubnetsonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_peerlocalsubnetsonly_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_port","displayName":"Port","description":"The TCP port number on which the content cache accepts requests for uploads or downloads. Set the port to 0 to pick a random, available port.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_publicranges","displayName":"Public Ranges","description":"The ranges of public IP addresses that the cloud servers should use for matching clients to content caches.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_publicranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_publicranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_publicranges_item_type","displayName":"IP Address Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_publicranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_publicranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},{"id":"com.apple.associated-domains_com.apple.associated-domains","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8efd284f-5a56-4da8-8821-f51984ff954d","categoryName":"Associated Domains","options":null},{"id":"com.apple.associated-domains_configuration","displayName":"Configuration","description":"Map apps to their associated domains.","helpText":null,"infoUrls":[],"categoryId":"8efd284f-5a56-4da8-8821-f51984ff954d","categoryName":"Associated Domains","options":null},{"id":"com.apple.associated-domains_configuration_item_applicationidentifier","displayName":"Application Identifier","description":"The app identifier to associate the domains with.","helpText":null,"infoUrls":[],"categoryId":"8efd284f-5a56-4da8-8821-f51984ff954d","categoryName":"Associated Domains","options":null},{"id":"com.apple.associated-domains_configuration_item_associateddomains","displayName":"Associated Domains","description":"The domains to be associated with the app. Each string is in the form of \"service:domain\". Domains should be fully qualified hostnames, like www.example.com.","helpText":null,"infoUrls":[],"categoryId":"8efd284f-5a56-4da8-8821-f51984ff954d","categoryName":"Associated Domains","options":null},{"id":"com.apple.associated-domains_configuration_item_enabledirectdownloads","displayName":"Enable Direct Downloads","description":"If true, data for this domain should be downloaded directly instead of through a CDN. The entitlement value for this domain must be set to service:domain?mode=managed or this value will be ignored. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"8efd284f-5a56-4da8-8821-f51984ff954d","categoryName":"Associated Domains","options":[{"id":"com.apple.associated-domains_configuration_item_enabledirectdownloads_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.associated-domains_configuration_item_enabledirectdownloads_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.caldav.account_caldavaccountdescription","displayName":"Cal DAV Account Description","description":"The description of the account.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.caldav.account_caldavhostname","displayName":"Cal DAV Host Name","description":"The server’s address.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.caldav.account_caldavpassword","displayName":"Cal DAV Password","description":"The user’s password. This is only used with encrypted profiles.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.caldav.account_caldavport","displayName":"Cal DAV Port","description":"The server’s port.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.caldav.account_caldavprincipalurl","displayName":"Cal DAV Principal URL","description":"The base URL to the user’s calendar.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.caldav.account_caldavusername","displayName":"Cal DAV Username","description":"The user name for logins.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.caldav.account_caldavusessl","displayName":"Cal DAV Use SSL","description":"If true, enables SSL.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":[{"id":"com.apple.caldav.account_caldavusessl_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.caldav.account_caldavusessl_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.caldav.account_com.apple.caldav.account","displayName":"Top Level Setting Group Collection","description":"com.apple.caldav.account","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.carddav.account_carddavaccountdescription","displayName":"Card DAV Account Description","description":"The description of the account.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.carddav.account_carddavhostname","displayName":"Card DAV Host Name","description":"The server’s address.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.carddav.account_carddavpassword","displayName":"Card DAV Password","description":"The user’s password.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.carddav.account_carddavport","displayName":"Card DAV Port","description":"The server’s port.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.carddav.account_carddavprincipalurl","displayName":"Card DAV Principal URL","description":"The base URL to the user’s address book.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.carddav.account_carddavusername","displayName":"Card DAV Username","description":"The user name for logins.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.carddav.account_carddavusessl","displayName":"Card DAV Use SSL","description":"If true, enables SSL.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":[{"id":"com.apple.carddav.account_carddavusessl_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.carddav.account_carddavusessl_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.carddav.account_com.apple.carddav.account","displayName":"Top Level Setting Group Collection","description":"com.apple.carddav.account","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.cellular_apns","displayName":"APNs","description":"An array of access point dictionaries.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmask","displayName":"Allowed Protocol Mask","description":"The supported Internet Protocol versions. Available in iOS 10.3 and later.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_allowedprotocolmask_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmask_1","displayName":"IPv6","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmask_2","displayName":"Both","description":null,"helpText":null}]},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming","displayName":"Allowed Protocol Mask In Domestic Roaming","description":"The supported Internet Protocol versions while roaming domestically. Available in iOS 10.3 and later.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming_1","displayName":"IPv6","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming_2","displayName":"Both","description":null,"helpText":null}]},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming","displayName":"Allowed Protocol Mask In Roaming","description":"The supported Internet Protocol versions while roaming. Available in iOS 10.3 and later.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming_1","displayName":"IPv6","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming_2","displayName":"Both","description":null,"helpText":null}]},{"id":"com.apple.cellular_apns_item_authenticationtype","displayName":"Authentication Type","description":"The authentication type for logging in.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_authenticationtype_0","displayName":"CHAP","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_authenticationtype_1","displayName":"PAP","description":null,"helpText":null}]},{"id":"com.apple.cellular_apns_item_enablexlat464","displayName":"Enable XLAT464","description":"If true, enables XLAT464. Available in iOS 16 and later.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_enablexlat464_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_enablexlat464_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.cellular_apns_item_name","displayName":"Name","description":"The name for this configuration.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_apns_item_password","displayName":"Password","description":"The user's password for the APN.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_apns_item_proxyport","displayName":"Proxy Port","description":"The proxy server's port number.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_apns_item_proxyserver","displayName":"Proxy Server","description":"The proxy server's address.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_apns_item_username","displayName":"Username","description":"The user name for the APN.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_attachapn","displayName":"Attach APN","description":"A configuration dictionary.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_attachapn_allowedprotocolmask","displayName":"Allowed Protocol Mask","description":"The supported Internet Protocol versions.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_attachapn_allowedprotocolmask_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.cellular_attachapn_allowedprotocolmask_1","displayName":"IPv6","description":null,"helpText":null},{"id":"com.apple.cellular_attachapn_allowedprotocolmask_2","displayName":"Both","description":null,"helpText":null}]},{"id":"com.apple.cellular_attachapn_authenticationtype","displayName":"Authentication Type","description":"The authentication type for logging in.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_attachapn_authenticationtype_0","displayName":"CHAP","description":null,"helpText":null},{"id":"com.apple.cellular_attachapn_authenticationtype_1","displayName":"PAP","description":null,"helpText":null}]},{"id":"com.apple.cellular_attachapn_name","displayName":"Name","description":"The name for this configuration.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_attachapn_password","displayName":"Password","description":"The password for the APN.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_attachapn_username","displayName":"Username","description":"The user name for the APN.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_com.apple.cellular","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellularprivatenetwork.managed_cellulardatapreferred","displayName":"Cellular Data Preferred","description":"Set to `true` to prefer this private network over Wi-Fi.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":[{"id":"com.apple.cellularprivatenetwork.managed_cellulardatapreferred_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.cellularprivatenetwork.managed_cellulardatapreferred_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.cellularprivatenetwork.managed_com.apple.cellularprivatenetwork.managed","displayName":"com.apple.cellularprivatenetwork.managed","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_csgnetworkidentifier","displayName":"Csg Network Identifier","description":"A string using the 3GPP \"CSG_ID\" format (defined in 3GPP 23.003, Section 4.7). The device uses this value to match a SIM present on the device.\n\nAll combinations of `NetworkIdentifier` and `CsgNetworkIdentifier` must be unique across all profiles installed on the device.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_datasetname","displayName":"Data Set Name","description":"The name of the private network configuration data set.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_enablenrstandalone","displayName":"Enable NR Standalone","description":"Set to `true` if this private network is NR Standalone.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":[{"id":"com.apple.cellularprivatenetwork.managed_enablenrstandalone_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.cellularprivatenetwork.managed_enablenrstandalone_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.cellularprivatenetwork.managed_geofences","displayName":"Geofences","description":"A list of up to 1000 geofences for private networks. Geofencing is only used on iPhone.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_geofences_item_geofenceid","displayName":"Geofence Id","description":"A geofence identifier that's unique within a list of geofences.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_geofences_item_latitude","displayName":"Latitude","description":"The latitude of the geofence.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_geofences_item_longitude","displayName":"Longitude","description":"The longitude of the geofence.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_geofences_item_radius","displayName":"Radius","description":"Specifies the radius of the geofence in meters. Set this value slightly greater than the private cellular network coverage area.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_networkidentifier","displayName":"Network Identifier","description":"A string using the 3GPP \"Coordinated NID\" (option 1 or option 2) format (defined in 3GPP 31.102, Section 12.7.1). The device uses this value to match a SIM present on the device.\n\nAll combinations of `NetworkIdentifier` and `CsgNetworkIdentifier` must be unique across all profiles installed on the device.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_versionnumber","displayName":"Version Number","description":"The version number of this dataset that the system uses to track updates.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.configurationprofile.identification_com.apple.configurationprofile.identification","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification","displayName":"Payload Identification (Deprecated)","description":"The dictionary containing details about the user.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_authmethod","displayName":"Auth Method","description":"The authorization method. Either the password is supplied in the profile or the user supplies it. ","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":[{"id":"com.apple.configurationprofile.identification_payloadidentification_authmethod_0","displayName":"Password","description":null,"helpText":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_authmethod_1","displayName":"UserEnteredPassword","description":null,"helpText":null}]},{"id":"com.apple.configurationprofile.identification_payloadidentification_emailaddress","displayName":"Email Address","description":"The address for the account.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_fullname","displayName":"Full Name","description":"The full name of the account.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_password","displayName":"Password","description":"The password for the account. Required when the Auth Method is of type password.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_prompt","displayName":"Prompt","description":"The custom instructions for the user, if needed.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_promptmessage","displayName":"Prompt Message","description":"The additional descriptive text for the user prompt.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_username","displayName":"User Name","description":"The UNIX user name for the accounts.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.desktop_com.apple.desktop","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"e42edcd8-fcb0-4255-a774-c78b34f0b0c9","categoryName":"Desktop","options":null},{"id":"com.apple.desktop_override-picture-path","displayName":"Override Picture Path","description":"The path to the desktop picture. If set, this picture is always locked.","helpText":null,"infoUrls":[],"categoryId":"e42edcd8-fcb0-4255-a774-c78b34f0b0c9","categoryName":"Desktop","options":null},{"id":"com.apple.dictionary_com.apple.dictionary","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"65087b94-7e45-4d74-a50d-df4377b67499","categoryName":"Parental Controls Dictionary","options":null},{"id":"com.apple.dictionary_parentalcontrol","displayName":"Parental Control","description":"If true, enables parental controls dictionary restrictions.","helpText":null,"infoUrls":[],"categoryId":"65087b94-7e45-4d74-a50d-df4377b67499","categoryName":"Parental Controls Dictionary","options":[{"id":"com.apple.dictionary_parentalcontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dictionary_parentalcontrol_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adallowmultidomainauth","displayName":"AD Allow Multi Domain Auth","description":"If true, allows authentication from any domain in the namespace.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adallowmultidomainauth_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adallowmultidomainauth_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adallowmultidomainauthflag","displayName":"AD Allow Multi Domain Auth Flag","description":"If true, enables the AD Allow Multi Domain Auth key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adallowmultidomainauthflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adallowmultidomainauthflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adcreatemobileaccountatlogin","displayName":"AD Create Mobile Account At Login","description":"If true, creates a mobile account at login.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adcreatemobileaccountatlogin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adcreatemobileaccountatlogin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adcreatemobileaccountatloginflag","displayName":"AD Create Mobile Account At Login Flag","description":"If true, enables the AD Create Mobile Account At Login key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adcreatemobileaccountatloginflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adcreatemobileaccountatloginflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_addefaultusershell","displayName":"AD Default User Shell","description":"The default user shell. ","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_addefaultusershellflag","displayName":"AD Default User Shell Flag","description":"If true, enables the AD Default User Shell key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_addefaultusershellflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_addefaultusershellflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_addomainadmingrouplist","displayName":"AD Domain Admin Group List","description":"The list of Active Directory groups that are granted admin access.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_addomainadmingrouplistflag","displayName":"AD Domain Admin Group List Flag","description":"If true, enables the AD Domain Admin Group List key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_addomainadmingrouplistflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_addomainadmingrouplistflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adforcehomelocal","displayName":"AD Force Home Local","description":"If true, forces a local home directory.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adforcehomelocal_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adforcehomelocal_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adforcehomelocalflag","displayName":"AD Force Home Local Flag","description":"If true, enables the AD Force Home Local key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adforcehomelocalflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adforcehomelocalflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_admapggidattribute","displayName":"AD Map GGID Attribute","description":"The map group GID to attribute.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_admapggidattributeflag","displayName":"AD Map GGID Attribute Flag","description":"If true, enables the AD Map GGID Attribute Flag key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admapggidattributeflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admapggidattributeflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_admapgidattribute","displayName":"AD Map GID Attribute","description":"The map GID to attribute.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_admapgidattributeflag","displayName":"AD Map GID Attribute Flag","description":"If true, enables the AD Map GID Attribute key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admapgidattributeflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admapgidattributeflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_admapuidattribute","displayName":"AD Map UID Attribute","description":"The map UID to attribute.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_admapuidattributeflag","displayName":"AD Map UID Attribute Flag","description":"If true, enables the AD Map UID Attribute key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admapuidattributeflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admapuidattributeflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_admountstyle","displayName":"AD Mount Style","description":"The network home protocol to use: afp or smb.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admountstyle_0","displayName":"afp","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admountstyle_1","displayName":"smb","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adnamespace","displayName":"AD Namespace","description":"The primary user account naming convention; either forest or domain.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adnamespace_0","displayName":"forest","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adnamespace_1","displayName":"domain","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adnamespaceflag","displayName":"AD Namespace Flag","description":"If true, enables the AD Namespace key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adnamespaceflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adnamespaceflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adorganizationalunit","displayName":"AD Organizational Unit","description":"The organizational unit where the joining computer object is added.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_adpacketencrypt","displayName":"AD Packet Encrypt","description":"The packet encryption policy.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_adpacketencryptflag","displayName":"AD Packet Encrypt Flag","description":"If true, enables the AD Packet Encrypt key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adpacketencryptflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adpacketencryptflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adpacketsign","displayName":"AD Packet Sign","description":"The packet signing policy.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_adpacketsignflag","displayName":"AD Packet Sign Flag","description":"If true, enables the AD Packet Sign key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adpacketsignflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adpacketsignflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adpreferreddcserver","displayName":"AD Preferred DC Server","description":"The preferred domain server.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_adpreferreddcserverflag","displayName":"AD Preferred DC Server Flag","description":"If true, enables the AD Preferred DC Server key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adpreferreddcserverflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adpreferreddcserverflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adrestrictddns","displayName":"AD Restrict DDNS","description":"If true, allows authentication from any domain in the namespace. ","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_adrestrictddnsflag","displayName":"AD Restrict DDNS Flag","description":"If true, enables the AD Restrict DDNS key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adrestrictddnsflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adrestrictddnsflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adtrustchangepassintervaldays","displayName":"AD Trust Change Pass Interval Days","description":"The number of days before requiring a change of the computer trust account password. 0 disables the feature.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_adtrustchangepassintervaldaysflag","displayName":"AD Trust Change Pass Interval Days Flag","description":"If true, enables the AD Trust Change Pass Interval Days key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adtrustchangepassintervaldaysflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adtrustchangepassintervaldaysflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adusewindowsuncpath","displayName":"AD Use Windows UNC Path","description":"If true, uses the UNC path from Active Directory to derive the network home location.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adusewindowsuncpath_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adusewindowsuncpath_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adusewindowsuncpathflag","displayName":"AD Use Windows UNC Path Flag","description":"If true, enables the AD Use Windows UNC Path key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adusewindowsuncpathflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adusewindowsuncpathflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adwarnuserbeforecreatingma","displayName":"AD Warn User Before Creating MA","description":"If true, enables the warning before creating the mobile account.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adwarnuserbeforecreatingma_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adwarnuserbeforecreatingma_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adwarnuserbeforecreatingmaflag","displayName":"AD Warn User Before Creating MA Flag","description":"If true, enables the AD Warn User Before Creating MA key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adwarnuserbeforecreatingmaflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adwarnuserbeforecreatingmaflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_clientid","displayName":"Client ID","description":"The client's identifier.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_com.apple.directoryservice.managed","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_description","displayName":"Description","description":"The directory service description.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_hostname","displayName":"Host Name","description":"The Active Directory domain to join.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_password","displayName":"Password","description":"The password of the account for the domain.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_username","displayName":"User Name","description":"The user name of the account for the domain.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.discrecording_burnsupport","displayName":"Burn Support","description":"If off, disables disc burning. If on, allows normal default operation. Setting this key to on doesn't enable disc burn support if it has already been disabled by other mechanisms or preferences. It also must be enabled with the Finder profile. If authenticate, requires authentication.","helpText":null,"infoUrls":[],"categoryId":"87f460f4-8403-419c-bfb4-44dec5edcccb","categoryName":"Media Management Disc Burning","options":[{"id":"com.apple.discrecording_burnsupport_0","displayName":"off","description":null,"helpText":null},{"id":"com.apple.discrecording_burnsupport_1","displayName":"authenticate","description":null,"helpText":null},{"id":"com.apple.discrecording_burnsupport_2","displayName":"on","description":null,"helpText":null}]},{"id":"com.apple.discrecording_com.apple.discrecording","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"87f460f4-8403-419c-bfb4-44dec5edcccb","categoryName":"Media Management Disc Burning","options":null},{"id":"com.apple.dnssettings.managed_com.apple.dnssettings.managed","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_dnssettings","displayName":"DNS Settings","description":"A dictionary that defines a configuration for an encrypted DNS server.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_dnssettings_dnsprotocol","displayName":"DNS Protocol","description":"The encrypted transport protocol used to communicate with the DNS server.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_dnssettings_dnsprotocol_0","displayName":"HTTPS","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_dnssettings_dnsprotocol_1","displayName":"TLS","description":null,"helpText":null}]},{"id":"com.apple.dnssettings.managed_dnssettings_serveraddresses","displayName":"Server Addresses","description":"An unordered list of DNS server IP address strings. These IP addresses can be a mixture of IPv4 and IPv6 addresses.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_dnssettings_servername","displayName":"Server Name","description":"The hostname of a DNS-over-TLS server used to validate the server certificate, as defined in RFC 7858. If no ServerAddresses are provided, the hostname will be used to determine the server addresses. This key must be present only if the DNSProtocol is TLS.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_dnssettings_serverurl","displayName":"Server URL","description":"The URI template of a DNS-over-HTTPS server, as defined in RFC 8484. This URL must use the https:// scheme, and the hostname or address in the URL will be used to validate the server certificate. If no ServerAddresses are provided, the hostname or address in the URL will be used to determine the server addresses. This key must be present only if the DNSProtocol is HTTPS.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_dnssettings_supplementalmatchdomains","displayName":"Supplemental Match Domains","description":"A list of domain strings used to determine which DNS queries will use the DNS server. If this array is not provided, all domains will use the DNS server.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules","displayName":"On Demand Rules","description":"An array of rules defining the DNS settings. If rules are not present, the system always applies the DNS settings. These rules are identical to the OnDemandRules array in VPN payloads.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_action","displayName":"Action","description":"The action to take if this dictionary matches the current network.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_action_0","displayName":"Connect","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_action_1","displayName":"Disconnect","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_action_2","displayName":"Evaluate Connection","description":null,"helpText":null}]},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters","displayName":"Action Parameters","description":"A dictionary that provides per-connection rules.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domainaction","displayName":"Domain Action (Deprecated)","description":" The DNS settings behavior for the specified domains.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domainaction_0","displayName":"Never Connect","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domainaction_1","displayName":"Connect If Needed","description":null,"helpText":null}]},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domains","displayName":"Domains (Deprecated)","description":"The domains for which this evaluation applies.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domainaction","displayName":"Domain Action","description":"The DNS settings behavior for the specified domains. Allowed values:\n\n* 'NeverConnect': Don't use the DNS Settings for the specified domains.\n* 'ConnectIfNeeded': Allow using the DNS Settings for the specified domains.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domainaction_0","displayName":"NeverConnect","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domainaction_1","displayName":"ConnectIfNeeded","description":null,"helpText":null}]},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domains","displayName":"Domains","description":"The domains for which this evaluation applies.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_dnsdomainmatch","displayName":"DNS Domain Match","description":"An array of domain names. This rule matches if any of the domain names in the specified list matches any domain in the device’s search domains list.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_dnsserveraddressmatch","displayName":"DNS Server Address Match","description":"An array of IP addresses. This rule matches if any of the network’s specified DNS servers match any entry in the array.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch","displayName":"Interface Type Match","description":"An interface type. If specified, this rule matches only if the primary network interface hardware matches the specified type.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch_0","displayName":"Ethernet","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch_1","displayName":"WiFi","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch_2","displayName":"Cellular","description":null,"helpText":null}]},{"id":"com.apple.dnssettings.managed_ondemandrules_item_ssidmatch","displayName":"SSID Match","description":"An array of SSIDs to match against the current network. If the network is not a Wi-Fi network or if the SSID does not appear in this array, the match fails. Omit this key and the corresponding array to match against any SSID.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_urlstringprobe","displayName":"URL String Probe","description":"A URL to probe. If this URL is successfully fetched (returning a 200 HTTP status code) without redirection, this rule matches.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_prohibitdisablement","displayName":"Prohibit Disablement","description":"If true, prohibits users from disabling DNS settings. This key is only available on supervised devices.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_prohibitdisablement_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_prohibitdisablement_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.dock_allowdockfixupoverride","displayName":"Allow Dock Fixup Override","description":"If true, use the file in /Library/Preferences/com.apple.dockfixup.plist when a new user or migrated user logs in. This option has no effect for existing users. Available in macOS 10.12 and later. Only available on the device channel.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_allowdockfixupoverride_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_allowdockfixupoverride_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_autohide","displayName":"Auto Hide","description":"If true, enables \"Automatically hide and show the dock.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_autohide_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_autohide_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_autohide-immutable","displayName":"Auto Hide Immutable","description":"If true, locks \"Automatically hide.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_autohide-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_autohide-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_com.apple.dock","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_contents-immutable","displayName":"Contents Immutable","description":"If true, disables changes to the dock.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_contents-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_contents-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_dblclickbehavior","displayName":"Double Click Behavior","description":"The behavior when the window's title bar is double-clicked.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_dblclickbehavior_0","displayName":"Minimize","description":null,"helpText":null},{"id":"com.apple.dock_dblclickbehavior_1","displayName":"Maximize","description":null,"helpText":null},{"id":"com.apple.dock_dblclickbehavior_2","displayName":"None","description":null,"helpText":null}]},{"id":"com.apple.dock_dblclickbehavior-immutable","displayName":"Double Click Behavior Immutable","description":"If true, locks \"Double-click a window's title bar.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_dblclickbehavior-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_dblclickbehavior-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_largesize","displayName":"Large Size","description":"The size of the largest magnification. ","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_launchanim","displayName":"Launch Animation","description":"If true, enables \"Animate opening applications.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_launchanim_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_launchanim_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_launchanim-immutable","displayName":"Launch Animation Immutable","description":"If true, locks \"Animate opening applications.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_launchanim-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_launchanim-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_magnification","displayName":"Magnification","description":"If true, enables magnification.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_magnification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_magnification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_magnify-immutable","displayName":"Magnify Immutable","description":"If true, locks magnification.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_magnify-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_magnify-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_magsize-immutable","displayName":"Magnification Size Immutable","description":"If true, locks the magnification slider.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_magsize-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_magsize-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_mcxdockspecialfolders","displayName":"MCX Dock Special Folders","description":"One or more special folders that may be created at user login time and placed in the dock.\n\nThe 'My Applications' item is only used for Simple Finder environments. The 'Original Network Home' item is only used for mobile account users.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_mineffect","displayName":"Minimize Effect","description":"The minimize effect.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_mineffect_0","displayName":"Genie","description":null,"helpText":null},{"id":"com.apple.dock_mineffect_1","displayName":"Scale","description":null,"helpText":null}]},{"id":"com.apple.dock_mineffect-immutable","displayName":"Minimize Effect Immutable","description":"If true, locks \"Minimize windows using.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_mineffect-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_mineffect-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_minimize-to-application","displayName":"Minimize To Application","description":"If true, enables \"Minimize windows into application icon.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_minimize-to-application_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_minimize-to-application_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_minintoapp-immutable","displayName":"Minimize Into Application Immutable","description":"If true, disables the \"Minimize windows into application icon\" checkbox.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_minintoapp-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_minintoapp-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_orientation","displayName":"Orientation","description":"The orientation of the dock. ","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_orientation_0","displayName":"Bottom","description":null,"helpText":null},{"id":"com.apple.dock_orientation_1","displayName":"Left","description":null,"helpText":null},{"id":"com.apple.dock_orientation_2","displayName":"Right","description":null,"helpText":null}]},{"id":"com.apple.dock_persistent-apps","displayName":"Persistent Apps","description":"Dock items located on the Applications side of the Dock that can be removed.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-apps_item_tile-data","displayName":"Tile Data","description":"The information about the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type","displayName":"File Type","description":"The type of file","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type_0","displayName":"URL","description":null,"helpText":null},{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type_1","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type_2","displayName":"Directory","description":null,"helpText":null}]},{"id":"com.apple.dock_persistent-apps_item_tile-data_label","displayName":"Label","description":"The label of the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-apps_item_tile-data_url","displayName":"URL","description":"The URL string.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-apps_item_tile-type","displayName":"Tile Type","description":"The type of tile.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_persistent-apps_item_tile-type_0","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_persistent-apps_item_tile-type_1","displayName":"Directory","description":null,"helpText":null},{"id":"com.apple.dock_persistent-apps_item_tile-type_2","displayName":"URL","description":null,"helpText":null}]},{"id":"com.apple.dock_persistent-others","displayName":"Persistent Others","description":"Dock items located on the Documents side of the Dock that can be removed.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-others_item_tile-data","displayName":"Tile Data","description":"The information about the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-others_item_tile-data_file-type","displayName":"File Type","description":"The type of file","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_persistent-others_item_tile-data_file-type_0","displayName":"URL","description":null,"helpText":null},{"id":"com.apple.dock_persistent-others_item_tile-data_file-type_1","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_persistent-others_item_tile-data_file-type_2","displayName":"Directory","description":null,"helpText":null}]},{"id":"com.apple.dock_persistent-others_item_tile-data_label","displayName":"Label","description":"The label of the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-others_item_tile-data_url","displayName":"URL","description":"The URL string","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-others_item_tile-type","displayName":"Tile Type","description":"The type of tile.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_persistent-others_item_tile-type_0","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_persistent-others_item_tile-type_1","displayName":"Directory","description":null,"helpText":null},{"id":"com.apple.dock_persistent-others_item_tile-type_2","displayName":"URL","description":null,"helpText":null}]},{"id":"com.apple.dock_position-immutable","displayName":"Position Immutable","description":"If true, locks the position.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_position-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_position-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_show-process-indicators","displayName":"Show Process Indicators","description":"If true, shows the process indicator.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_show-process-indicators_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_show-process-indicators_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_show-recents","displayName":"Show Recents","description":"If true, enables \"Show recent items.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_show-recents_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_show-recents_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_showindicators-immutable","displayName":"Show Indicators Immutable","description":"If true, locks \"Show indicators.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_showindicators-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_showindicators-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_showrecents-immutable","displayName":"Show Recents Immutable","description":"If true, disables \"Show recent applications\" checkbox.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_showrecents-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_showrecents-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_size-immutable","displayName":"Size Immutable","description":"If true, locks the size slider.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_size-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_size-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_static-apps","displayName":"Static Apps","description":"Dock items located on the Applications side of the Dock and cannot be removed from that location.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-apps_item_tile-data","displayName":"Tile Data","description":"The information about the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-apps_item_tile-data_file-type","displayName":"File Type","description":"The type of file","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-apps_item_tile-data_file-type_0","displayName":"URL","description":null,"helpText":null},{"id":"com.apple.dock_static-apps_item_tile-data_file-type_1","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_static-apps_item_tile-data_file-type_2","displayName":"Directory","description":null,"helpText":null}]},{"id":"com.apple.dock_static-apps_item_tile-data_label","displayName":"Label","description":"The label of the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-apps_item_tile-data_url","displayName":"URL","description":"The URL string","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-apps_item_tile-type","displayName":"Tile Type","description":"The type of tile.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-apps_item_tile-type_0","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_static-apps_item_tile-type_1","displayName":"Directory","description":null,"helpText":null},{"id":"com.apple.dock_static-apps_item_tile-type_2","displayName":"URL","description":null,"helpText":null}]},{"id":"com.apple.dock_static-only","displayName":"Static Only","description":"If true, uses the Static Apps and Static Others dictionaries for the dock and ignores any items in the Persistent Apps and Persistent Others dictionaries. If false, the contents are merged with the static items listed first.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-only_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_static-only_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_static-others","displayName":"Static Others","description":"Dock items located on the Documents side of the Dock and cannot be removed from that location.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-others_item_tile-data","displayName":"Tile Data","description":"The information about the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-others_item_tile-data_file-type","displayName":"File Type","description":"The type of file","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-others_item_tile-data_file-type_0","displayName":"URL","description":null,"helpText":null},{"id":"com.apple.dock_static-others_item_tile-data_file-type_1","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_static-others_item_tile-data_file-type_2","displayName":"Directory","description":null,"helpText":null}]},{"id":"com.apple.dock_static-others_item_tile-data_label","displayName":"Label","description":"The label of the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-others_item_tile-data_url","displayName":"URL","description":"The URL string","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-others_item_tile-type","displayName":"Tile Type","description":"The type of tile.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-others_item_tile-type_0","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_static-others_item_tile-type_1","displayName":"Directory","description":null,"helpText":null},{"id":"com.apple.dock_static-others_item_tile-type_2","displayName":"URL","description":null,"helpText":null}]},{"id":"com.apple.dock_tilesize","displayName":"Tile Size","description":"The tile size. Values must be in the range of 16 to 128.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_windowtabbing","displayName":"Window Tabbing","description":"Set the \"Prefer tabs when opening documents\" to the provided value.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_windowtabbing_0","displayName":"Manual","description":null,"helpText":null},{"id":"com.apple.dock_windowtabbing_1","displayName":"Always","description":null,"helpText":null},{"id":"com.apple.dock_windowtabbing_2","displayName":"Full Screen","description":null,"helpText":null}]},{"id":"com.apple.dock_windowtabbing-immutable","displayName":"Window Tabbing Immutable","description":"If true, disables \"Prefer tabs when opening documents\" checkbox.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_windowtabbing-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_windowtabbing-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.domains_com.apple.domains","displayName":"Top Level Setting Group Collection","description":"com.apple.domains","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},{"id":"com.apple.domains_crosssitetrackingpreventionrelaxedapps","displayName":"Cross Site Tracking Prevention Relaxed Apps","description":"An array of up to 10 strings representing app bundle-ids. Apps matching the bundle-ids listed here have relaxed enforcement of cross-site tracking prevention for the domains listed in `CrossSiteTrackingPreventionRelaxedDomains`.\n\nAvailable in iOS 18 and later and macOS 15 and later.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},{"id":"com.apple.domains_crosssitetrackingpreventionrelaxeddomains","displayName":"Cross Site Tracking Prevention Relaxed Domains","description":"Specify an array of up to ten domains \r\nwhen cross-site tracking is required for functionality.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},{"id":"com.apple.domains_emaildomains","displayName":"Email Domains","description":"An array of domains. Email addresses that lack a suffix matching any of these strings are considered out of domain and marked in Mail.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},{"id":"com.apple.domains_safaripasswordautofilldomains","displayName":"Safari Password Auto Fill Domains","description":"An array of domains. Users can only save passwords in Safari from URLs matching the patterns listed here. This property doesn’t disable the autofill feature itself. Supervised devices or Shared iPads need this property to enable saving passwords in Safari. Available in iOS 9.3 and later.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},{"id":"com.apple.domains_webdomains","displayName":"Web Domains","description":"An array of domains. URLs matching the patterns listed here are considered managed.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},{"id":"com.apple.extensiblesso_authenticationmethod","displayName":"Authentication Method (Deprecated)","description":"The Platform SSO authentication method the extension uses. Requires that the SSO Extension also supports the method.\nAvailable in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_authenticationmethod_0","displayName":"Password","description":null,"helpText":null},{"id":"com.apple.extensiblesso_authenticationmethod_1","displayName":"UserSecureEnclaveKey","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_com.apple.extensiblesso","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_com.apple.extensiblesso-kerberos_kerberos","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_deniedbundleidentifiers","displayName":"Denied Bundle Identifiers","description":"An array of bundle identifiers of apps that don't use SSO provided by this extension.\nAvailable in iOS 15 and later and macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_extensiondata","displayName":"Extension Data","description":"A dictionary of arbitrary data passed through to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_extensiondata_allowautomaticlogin_kerberos","displayName":"Allow Automatic Login","description":"If false, passwords are not allowed to be saved to the keychain.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_allowautomaticlogin_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_allowautomaticlogin_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_allowpassword_kerberos","displayName":"Allow Password","description":"If set to true, the user to switch the user interface to Password mode. (macOS only)","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_allowpassword_kerberos_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_allowpassword_kerberos_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_allowpasswordchange_kerberos","displayName":"Allow Password Change","description":"If false, disables password changes. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_allowpasswordchange_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_allowpasswordchange_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_allowplatformssoauthfallback_kerberos","displayName":"Allow Platform SSO OAuth Fallback","description":"If `true` and `usePlatformSSOTGT` is `true`, the system allows the user to manually sign in. Available in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_allowplatformssoauthfallback_kerberos_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_allowplatformssoauthfallback_kerberos_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_allowsmartcard_kerberos","displayName":"Allow Smart Card","description":"If set to true, the user to switch the user interface to SmartCard mode. (macOS only)","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_allowsmartcard_kerberos_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_allowsmartcard_kerberos_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_credentialbundleidacl_kerberos","displayName":"Credential Bundle ID ACL","description":"A list of bundle IDs allowed to access the ticket-granting ticket (TGT).","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_credentialusemode_kerberos","displayName":"Credential Use Mode","description":"This setting affects how the Kerberos Extension credential is used by other processes.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_credentialusemode_kerberos_0","displayName":"Always","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_credentialusemode_kerberos_1","displayName":"When Not Specified","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_credentialusemode_kerberos_2","displayName":"Kerberos Default ","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_customusernamelabel_kerberos","displayName":"Custom Username Label","description":"The custom user name label used in the Kerberos extension instead of “Username”. For example, “Company ID”. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_delayusersetup_kerberos","displayName":"Delay User Setup","description":"If true, doesn’t prompt the user to setup the Kerberos extension until either the administrator enables it with the app-sso tool or a Kerberos challenge is received. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_delayusersetup_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_delayusersetup_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_domainrealmmapping_generickey_kerberos_keytobereplaced","displayName":"Realm","description":"The name of the realm.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_domainrealmmapping_generickey_kerberos_string","displayName":"Domain Realm Mapping","description":"An array of DNS Suffixes that map to the realm.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_domainrealmmapping_kerberos","displayName":"Domain Realm Mapping","description":"A custom domain-realm mapping for Kerberos. This is used when the DNS name of hosts do not match the realm name. Most administrators will not need to customize this.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_domainrealmmapping_realm_kerberos","displayName":"Realm (Deprecated)","description":"The key should be the name of the realm, and the value is an array of DNS suffixes that map to the realm.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_generickey_boolean","displayName":"Value","description":"Keys and values to pass to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_extensiondata_generickey_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_generickey_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_generickey_integer","displayName":"Value","description":"Keys and values to pass to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_extensiondata_generickey_keytobereplaced","displayName":"Key","description":"Additional extension-specific data to pass to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_extensiondata_generickey_string","displayName":"Value","description":"Keys and values to pass to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_extensiondata_helptext_kerberos","displayName":"Help Text","description":"The text to be displayed to the user at the bottom of the Kerberos login window. It can be used to display help information or disclaimer text. Available in iOS 14 and later and macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_identityissuerautoselectfilter_kerberos","displayName":"Identity Issuer Auto Select Filter","description":"A string with wildcards that can use used to filter the list of available SmartCards by issuer. e.g \"*My CA2*\". If there is one remaining, it will be auto-selected. If there more than one remaining, then the list is shorter. (macOS only)","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_includekerberosappsinbundleidacl_kerberos","displayName":"Include Kerberos Apps In Bundle ID ACL","description":"If true, the Kerberos extension allows the standard kerberos utilities including TicketViewer and klist to access and use the credential. This is in addition to Include Managed Apps In Bundle ID ACL or the Credential Bundle ID ACL, if it is specified.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_includekerberosappsinbundleidacl_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_includekerberosappsinbundleidacl_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_includemanagedappsinbundleidacl_kerberos","displayName":"Include Managed Apps In Bundle ID ACL","description":"If true, the Kerberos extension allows only managed apps to access and use the credential. This is in addition to the Credential Bundle ID ACL, if it is specified. Available in iOS 14 and later, and macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_includemanagedappsinbundleidacl_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_includemanagedappsinbundleidacl_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_isdefaultrealm_kerberos","displayName":"Is Default Realm","description":"This property specifies it is the default realm if there is more than one Kerberos extension configuration.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_isdefaultrealm_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_isdefaultrealm_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_kerberos","displayName":"Extension Data","description":"This is the dictionary used by the Apple built-in Kerberos extension.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_monitorcredentialscache_kerberos","displayName":"Monitor Credentials Cache","description":"If false, the credential is requested on the next matching Kerberos challenge or network state change. If the credential is expired or missing, a new one will be created. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_monitorcredentialscache_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_monitorcredentialscache_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_performkerberosonly_kerberos","displayName":"Perform Kerberos Only","description":"If true, the Kerberos Extension handles Kerberos requests only. It doesn’t check for password expiration, show the password expiration in the menu, check for external password changes, perform password sync, or retrieve the home directory. Available in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_performkerberosonly_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_performkerberosonly_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_preferredkdcs_kerberos","displayName":"Preferred KDCs","description":"The ordered list of perferred Key Distribution Centers (KDCs) to use for Kerberos traffic. Use this if the servers are not discoverable via DNS. If the servers are specified, then they are used for both connectivity checks and attempted first for Kerberos traffic. If the servers do not respond, then the device falls back to DNS discovery. Each entry is formatted the same as it would be in a krb5.conf file.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_principalname_kerberos","displayName":"Principal Name","description":"The principal (aka username) to use. You do not need to include the realm.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_pwchangeurl_kerberos","displayName":"Password Change URL","description":"This URL will launch in the user’s default web browser when they initiate a password change. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_pwnotificationdays_kerberos","displayName":"Password Notification Days","description":"The number of days prior to password expiration when a notification of password expiration will be sent to the user. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_pwreqcomplexity_kerberos","displayName":"Password Req Complexity","description":"If true, passwords must meet Active Directory's definition of \"complex\". Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_pwreqcomplexity_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_pwreqcomplexity_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_pwreqhistory_kerberos","displayName":"Password Req History","description":"The number of prior passwords that cannot be re-used on this domain. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_pwreqlength_kerberos","displayName":"Password Req Length","description":"The minimum length of passwords on the domain. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_pwreqminage_kerberos","displayName":"Password Req Min Age","description":"The minimum age of passwords before they can be changed on this domain. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_pwreqtext_kerberos","displayName":"Password Req Text","description":"The text version of the domain's password requirements. Only for use if Password Req Complexity or Password Req Length aren’t specified. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_requiretlsforldap_kerberos","displayName":"Require TLS For LDAP","description":"Require that LDAP connections use TLS. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_requiretlsforldap_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_requiretlsforldap_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_requireuserpresence_kerberos","displayName":"Require User Presence","description":"If true, requires the user to provide Touch ID, Face ID or their passcode to access the keychain entry.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_requireuserpresence_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_requireuserpresence_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_sitecode_kerberos","displayName":"Site Code","description":"The name of the Active Directory site the Kerberos extension should use. Most administrators will never need to modify this value, as the Kerberos extension can normally find the site automatically.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_startinsmartcardmode_kerberos","displayName":"Start In Smart Card Mode","description":"If set to true, the user interface will start in SmartCard mode. (macOS only)","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_startinsmartcardmode_kerberos_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_startinsmartcardmode_kerberos_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_synclocalpassword_kerberos","displayName":"Sync Local Password","description":"If false, disables password sync. Note that this will not work if the user is logged in with a mobile account. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_synclocalpassword_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_synclocalpassword_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_useplatformssotgt_kerberos","displayName":"Use Platform SSOTGT","description":"If `true`, the system requires this configuration uses a TGT from Platform SSO instead of requesting a new one. Available in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_useplatformssotgt_kerberos_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_useplatformssotgt_kerberos_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_usesiteautodiscovery_kerberos","displayName":"Use Site Auto Discovery","description":"If false, the Kerberos extension doesn't automatically use LDAP and DNS to determine its AD site name.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_usesiteautodiscovery_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_usesiteautodiscovery_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensionidentifier","displayName":"Extension Identifier","description":"The bundle identifier of the app extension that performs SSO for the specified URLs.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_extensionidentifier_kerberos","displayName":"Extension Identifier","description":"This value must be com.apple.AppSSOKerberos.KerberosExtension for this extension.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":{"id":"com.apple.extensiblesso_extensionidentifier_kerberos_0","displayName":"com.apple.AppSSOKerberos.KerberosExtension","description":null,"helpText":null}},{"id":"com.apple.extensiblesso_hosts","displayName":"Hosts","description":"An array of host names or domain names that apps can authenticate through the app extension.\r\nRequired for Credential payloads. Ignored for Redirect payloads.\r\n\r\nHost or domain names are matched case-insensitively, and all the host/domain names of all installed Extensible SSO payloads must be unique.\r\n\r\nHosts that begin with a “.” are wildcard suffixes and match all subdomains; otherwise the host must be an exact match.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_hosts_kerberos","displayName":"Hosts","description":"One or more host or domain names for which the app extension performs SSO. Host or domain names are matched case-insensitively, and all the host/domain names of all installed Extensible SSO payloads must be unique. Hosts that begin with a “.” are wildcard suffixes and will match all subdomains, otherwise the host must be an exact match.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_ignored_$typepicker","displayName":"Type","description":"Keys and values to pass to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_ignored_0","displayName":"String","description":"String","helpText":null},{"id":"com.apple.extensiblesso_ignored_1","displayName":"Integer","description":"Integer","helpText":null},{"id":"com.apple.extensiblesso_ignored_2","displayName":"Boolean","description":"Boolean","helpText":null}]},{"id":"com.apple.extensiblesso_ignored_kerberos_$typepicker","displayName":"IGNORED","description":null,"helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":{"id":"com.apple.extensiblesso_ignored_kerberos_0","displayName":"Array","description":null,"helpText":null}},{"id":"com.apple.extensiblesso_platformsso","displayName":"Platform SSO","description":"This is the dictionary used to configure PlatformSSO.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_accountdisplayname","displayName":"Account Display Name","description":"The display name for the account in notifications and authentication requests.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_additionalgroups","displayName":"Additional Groups","description":"The list of groups that are created and do not have administrator access.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_administratorgroups","displayName":"Administrator Groups","description":"The list of groups that are used for administrator access. Membership will be requested during authentication.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_allowdeviceidentifiersinattestation","displayName":"Allow Device Identifiers In Attestation","description":"If `true`, the system includes the device UDID and serial number in Platform SSO attestations.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_allowdeviceidentifiersinattestation_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_allowdeviceidentifiersinattestation_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_authenticationgraceperiod","displayName":"Authentication Grace Period","description":"The amount of time after a 'FileVaultPolicy', 'LoginPolicy', or 'UnlockPolicy' is received or updated that unregistered local accounts can be used. Required when 'AllowAuthenticationGracePeriod' is set.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_authenticationmethod","displayName":"Authentication Method","description":"The Platform SSO authentication method to be used with the extension. Requires that the SSO Extension also support the method.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_authenticationmethod_0","displayName":"Password","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_authenticationmethod_1","displayName":"UserSecureEnclaveKey","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_authenticationmethod_2","displayName":"SmartCard","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_authorizationgroups","displayName":"Authorization Groups","description":"The pairing of Authorization Rights to group names. The Authorization Right will be updated to use the group when used.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_authorizationgroups_authorization right","displayName":"Authorization Right (Deprecated)","description":"The Authorization Right to update.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_authorizationgroups_generickey","displayName":"ANY","description":"The key is an access right value, the value is the group to be associated with that access right.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_authorizationgroups_generickey_keytobereplaced","displayName":"Authorization Groups","description":"The pairing of Authorization Rights to group names. When using this, the system updates the Authorization Right to use the group.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_authorizationgroups_group","displayName":"Group (Deprecated)","description":"The group to use for the Authorization Right.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_enableauthorization","displayName":"Enable Authorization","description":"Enables using identity provider accounts at authorization prompts. Requires 'UseSharedDeviceKeys' is true. The account will be assigned groups using the 'AdministratorGroups', 'AdditionalGroups', or 'AuthorizationGroups'.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_enableauthorization_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_enableauthorization_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_enablecreatefirstuserduringsetup","displayName":"Enable Create First User During Setup","description":"If `true`, the device uses Platform SSO to create the first user account on the Mac during `Setup Assistant`.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_enablecreatefirstuserduringsetup_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_enablecreatefirstuserduringsetup_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_enablecreateuseratlogin","displayName":"Enable Create User At Login","description":"Enables creating new users at the login window with either Passwords or SmartCards. Requires 'UseSharedDeviceKeys' is true.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_enablecreateuseratlogin_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_enablecreateuseratlogin_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_enableregistrationduringsetup","displayName":"Enable Registration During Setup","description":"If `true`, the system enables the PlatformSSO registration process during Setup Assistant on devices running macOS 26 and later. Set this key to `true` when configuring PlatformSSO before enrollment using the `com.apple.psso.required` error response.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_enableregistrationduringsetup_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_enableregistrationduringsetup_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_filevaultpolicy","displayName":"FileVault Policy","description":"The policy to apply when using Platform SSO at FileVault unlock on Apple Silicon Macs. Applies when 'AuthenticationMethod' is `Password`.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_loginfrequency","displayName":"Login Frequency","description":"The frequency where a full login is required instead of a refresh. Default is 18 hours. Must be > 1 hour.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_loginpolicy","displayName":"Login Policy","description":"The policy to apply when using Platform SSO at the login window. Applies when 'AuthenticationMethod' is `Password`.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_newuserauthorizationmode","displayName":"New User Authorization Mode","description":"This setting affects the permissions for accounts created at login by Platform SSO. It is only used when the account is created. Use of the following:\n* Standard\n The account will be a standard user.\n* Admin\n The account will be added to the local administrators group.\n* Groups\n The account will be assigned groups using the 'AdministratorGroups', 'AdditionalGroups', or 'AuthorizationGroups'.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_newuserauthorizationmode_0","displayName":"Standard","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_newuserauthorizationmode_1","displayName":"Admin","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_newuserauthorizationmode_2","displayName":"Groups","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_newuserauthorizationmode_3","displayName":"Temporary","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_nonplatformssoaccounts","displayName":"Non Platform SSO Accounts","description":"The list of local accounts that are not subject to the 'FileVaultPolicy', 'LoginPolicy', or 'UnlockPolicy'. The accounts are also not prompted to register for Platform SSO.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_offlinegraceperiod","displayName":"Offline Grace Period","description":"The amount of time after the last successful Platform SSO login a local account password can be used offline. Required when 'AllowOfflineGracePeriod' is set.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_tokentousermapping","displayName":"Token To User Mapping","description":"The attribute mapping used when creating new users or for authorization.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_tokentousermapping_accountname","displayName":"Account Name","description":"The claim name to use for the user's account name.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_tokentousermapping_fullname","displayName":"Full Name","description":"The claim name to use for the user's full name.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_unlockpolicy","displayName":"Unlock Policy","description":"The policy to apply when using Platform SSO at screensaver unlock. Applies when 'AuthenticationMethod' is `Password`.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_userauthorizationmode","displayName":"User Authorization Mode","description":"This setting affects the permissions after authentication by Platform SSO. It is applied each time user authenticates. Use of the following:\n* Standard\n The account will be a standard user. It will be removed from the 'admin' group.\n* Admin\n The account will be added to the local administrators group.\n* Groups\n The account will be assigned groups using the 'AdministratorGroups', 'AdditionalGroups', or 'AuthorizationGroups'.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_userauthorizationmode_0","displayName":"Standard","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_userauthorizationmode_1","displayName":"Admin","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_userauthorizationmode_2","displayName":"Groups","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_useshareddevicekeys","displayName":"Use Shared Device Keys","description":"If set to true, Platform SSO will use the same signing and encryption keys for all users.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_useshareddevicekeys_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_useshareddevicekeys_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_realm","displayName":"Realm","description":"The realm name for Credential payloads. Use proper capitalization for this value. This key is ignored for Redirect payloads.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_realm_kerberos","displayName":"Realm","description":"The Kerberos realm, which should be properly capitalized. If in an Active Directory forest, this is the realm where the user logs in.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_registrationtoken","displayName":"Registration Token","description":"The token this device uses for registration with Platform SSO. Use it for silent registration with the Identity Provider. Requires that 'AuthenticationMethod' isn't empty.\nAvailable in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_screenlockedbehavior","displayName":"Screen Locked Behavior","description":"When set to Do Not Handle, the request continues without SSO. Available in iOS 15 and later and macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":{"id":"com.apple.extensiblesso_screenlockedbehavior_0","displayName":"Do Not Handle","description":null,"helpText":null}},{"id":"com.apple.extensiblesso_teamidentifier","displayName":"Team Identifier","description":"The team identifier of the app extension. The device requires this key on macOS and ignores it elsewhere.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_teamidentifier_kerberos","displayName":"Team Identifier","description":"This value must be apple for the Kerberos extension.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":{"id":"com.apple.extensiblesso_teamidentifier_kerberos_0","displayName":"apple","description":null,"helpText":null}},{"id":"com.apple.extensiblesso_type","displayName":"Type","description":"The type of SSO.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_type_0","displayName":"Credential","description":null,"helpText":null},{"id":"com.apple.extensiblesso_type_1","displayName":"Redirect","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_type_kerberos","displayName":"Type","description":"This value must be Credential for the Kerberos extension.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":{"id":"com.apple.extensiblesso_type_kerberos_0","displayName":"Credential","description":null,"helpText":null}},{"id":"com.apple.extensiblesso_urls","displayName":"URLs","description":"An array of URL prefixes of identity providers where the app extension performs SSO. Required for Redirect payloads. Ignored for Credential payloads. The URLs must begin with http:// or https://, the scheme and host name are matched case-insensitively, query parameters and URL fragments are not allowed, and the URLs of all installed Extensible SSO payloads must be unique.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.familycontrols.contentfilter_com.apple.familycontrols.contentfilter","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_filterblacklist","displayName":"Filter Blocklist (Deprecated)","description":"The array of URLs that defines a deny list. When Restrict Web and Use Content Filter are enabled, no URLs in the deny list are available to the user.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_filterdenylist","displayName":"Filter Deny List","description":"The array of URLs that defines a deny list. When `restrictWeb` and `useContentFilter` are enabled, no URLs in the deny list are available to the user.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_filterwhitelist","displayName":"Filter Allowlist","description":"The array of URLs that defines an allow list. When Restrict Web and Use Content Filter are enabled, only URLs in the allow list are available to the user.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_restrictweb","displayName":"Restrict Web","description":"If true, enables web content filters.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":[{"id":"com.apple.familycontrols.contentfilter_restrictweb_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.contentfilter_restrictweb_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.contentfilter_sitewhitelist","displayName":"Site Allowlist","description":"An array of sites that defines an allow list. If specified, this defines additional allowed sites besides those in the automated allow list and deny list, including disallowed adult sites. This key is required if Allow List Enabled is true.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_sitewhitelist_item_address","displayName":"Address","description":"The site prefix, including http(s) scheme.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_sitewhitelist_item_pagetitle","displayName":"Page Title","description":"The site page title.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_usecontentfilter","displayName":"Use Content Filter","description":"If true, filters content automatically. ","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":[{"id":"com.apple.familycontrols.contentfilter_usecontentfilter_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.contentfilter_usecontentfilter_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.contentfilter_whitelistenabled","displayName":"Allowlist Enabled","description":"If true, enables web content filters.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":[{"id":"com.apple.familycontrols.contentfilter_whitelistenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.contentfilter_whitelistenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_com.apple.familycontrols.timelimits.v2","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_familycontrolsenabled","displayName":"Family Controls Enabled","description":"If true, enables time limits. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_familycontrolsenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_familycontrolsenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits","displayName":"Time Limits","description":"The time limits to enforce if Family Controls Enabled is enabled. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance","displayName":"Weekday Allowance","description":"The weekday allowance settings.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_enabled","displayName":"Enabled","description":"If true, enable these settings. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_enabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_end","displayName":"End","description":"The curfew end time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_rangetype","displayName":"Range Type","description":"The type of day range.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_rangetype_0","displayName":"Weekday","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_rangetype_1","displayName":"Weekend","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_secondsperday","displayName":"Seconds Per Day","description":"The allowance for that day, in seconds. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_start","displayName":"Start","description":"The curfew start time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew","displayName":"Weekday Curfew","description":"The weekday curfew settings.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_enabled","displayName":"Enabled","description":"If true, enable these settings. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_enabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_end","displayName":"End","description":"The curfew end time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_rangetype","displayName":"Range Type","description":"The type of day range.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_rangetype_0","displayName":"Weekday","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_rangetype_1","displayName":"Weekend","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_secondsperday","displayName":"Seconds Per Day","description":"The allowance for that day, in seconds. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_start","displayName":"Start","description":"The curfew start time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance","displayName":"Weekend Allowance","description":"The weekend allowance settings.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_enabled","displayName":"Enabled","description":"If true, enable these settings. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_enabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_end","displayName":"End","description":"The curfew end time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_rangetype","displayName":"Range Type","description":"The type of day range.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_rangetype_0","displayName":"Weekday","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_rangetype_1","displayName":"Weekend","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_secondsperday","displayName":"Seconds Per Day","description":"The allowance for that day, in seconds. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_start","displayName":"Start","description":"The curfew start time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew","displayName":"Weekend Curfew","description":"The weekend curfew settings.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_enabled","displayName":"Enabled","description":"If true, enable these settings. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_enabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_end","displayName":"End","description":"The curfew end time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_rangetype","displayName":"Range Type","description":"The type of day range.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_rangetype_0","displayName":"Weekday","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_rangetype_1","displayName":"Weekend","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_secondsperday","displayName":"Seconds Per Day","description":"The allowance for that day, in seconds. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_start","displayName":"Start","description":"The curfew start time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.fileproviderd_allowmanagedfileproviderstorequestattribution","displayName":"Allow Managed File Providers To Request Attribution","description":"If true, enables file providers access to the path of the requesting process.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":[{"id":"com.apple.fileproviderd_allowmanagedfileproviderstorequestattribution_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.fileproviderd_allowmanagedfileproviderstorequestattribution_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.fileproviderd_com.apple.fileproviderd","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},{"id":"com.apple.fileproviderd_managementallowsexternalvolumesyncing","displayName":"Management Allows External Volume Syncing","description":"If `false`, the device only allows File Provider extension volume synchronization for the system \"home\" volume and any data separated volume, and prevents synchronization with any other volumes. If `true``, the device allows File Provider extension volume synchronization for the system \"home\" volume, any data separated volume, and any encrypted APFS volumes (on either internal or external media).","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":[{"id":"com.apple.fileproviderd_managementallowsexternalvolumesyncing_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.fileproviderd_managementallowsexternalvolumesyncing_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.fileproviderd_managementallowsknownfoldersyncing","displayName":"Management Allows Known Folder Syncing","description":"If `false`, the device prevents the File Provider extension from using desktop and documents synchronization in any app. This doesn't impact the ability for apps to utilize the File Provider extension for file and folder syncing with remote storage.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":[{"id":"com.apple.fileproviderd_managementallowsknownfoldersyncing_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.fileproviderd_managementallowsknownfoldersyncing_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.fileproviderd_managementallowsremotesyncing","displayName":"Management Allows Remote Syncing","description":"If `false`, the device prevents the File Provider extension from using synchronization in any app. Also, none of the other options will be evaluated. Synchronization will be totally disabled for any application.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":[{"id":"com.apple.fileproviderd_managementallowsremotesyncing_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.fileproviderd_managementallowsremotesyncing_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.fileproviderd_managementdomainautoenablementlist","displayName":"Management Domain Auto Enablement List","description":"An array of strings representing the composed identifiers of apps. The device automatically enables the File Provider domains for the corresponding apps. The device doesn't enable existing domains if enrollment happens after they are created. The device doesn't prevent the user from disabling these File Provider domains. Users need to manually enable File Provider domains in the Finder if their corresponding apps aren't listed here. The format of the app identifiers is \"Bundle-ID (Team-ID)\", for example `com.example.app (ABCD1234)`.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},{"id":"com.apple.fileproviderd_managementexternalvolumesyncingallowlist","displayName":"Management External Volume Syncing Allow List","description":"An array of strings representing the composed identifiers of apps. The device allows the corresponding apps to use File Provider extension volume synchronization. If present, and `ManagementAllowsExternalVolumeSyncing` is set to `true`, the device allows only the apps in this list to use volume synchronization. This key is ignored if `ManagementAllowsExternalVolumeSyncing` is set to `false`. The format of the app identifiers is \"Bundle-ID (Team-ID)\", for example `com.example.app (ABCD1234)`.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},{"id":"com.apple.fileproviderd_managementknownfoldersyncingallowlist","displayName":"Management Known Folder Syncing Allow List","description":"An array of strings representing the composed identifiers of apps. The device allows the corresponding apps to use File Provider extension desktop and documents synchronization. If present, and `ManagementAllowsKnownFolderSyncing` is set to `true`, the device allows only the apps in this list to use desktop and documents synchronization. This key is ignored if `ManagementAllowsKnownFolderSyncing` is set to `false`. This setting doesn't impact the ability for apps to use File Provider extension volume access. The format of the app identifiers is \"Bundle-ID (Team-ID)\", for example `com.example.app (ABCD1234)`.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},{"id":"com.apple.fileproviderd_managementremotesyncingallowlist","displayName":"Management Remote Syncing Allow List","description":"An array of strings representing the composed identifiers of apps. The device allows the corresponding apps to use File Provider extension synchronization. If present, and `ManagementAllowsRemoteSyncing` is set to `true`, the device allows only the apps in this list to use synchronization. This key is ignored if `ManagementAllowsRemoteSyncing` is set to `false`. If present, the other options will only be evaluated for the apps in this list. The format of the app identifiers is \"Bundle-ID (Team-ID)\", for example `com.example.app (ABCD1234)`.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},{"id":"com.apple.finder_com.apple.finder","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":null},{"id":"com.apple.finder_prohibitburn","displayName":"Prohibit Burn","description":"If true, disables the Finder's burn support.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_prohibitburn_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_prohibitburn_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_prohibitconnectto","displayName":"Prohibit Connect To","description":"If true, prohibits users from using a dialog that lets them view, select, or manually connect to servers on the local network or on the internet.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_prohibitconnectto_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_prohibitconnectto_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_prohibiteject","displayName":"Prohibit Eject","description":"If true, users are prevented from ejecting any mounted volumes or media attached to the Mac.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_prohibiteject_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_prohibiteject_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_prohibitgotofolder","displayName":"Prohibit Go To Folder","description":"If true, users are prevented from opening a folder or file by typing the path to that item. ","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_prohibitgotofolder_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_prohibitgotofolder_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_showexternalharddrivesondesktop","displayName":"Show External Hard Drives On Desktop","description":"If false, mounted servers can not appear on the desktop.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_showexternalharddrivesondesktop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_showexternalharddrivesondesktop_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_showharddrivesondesktop","displayName":"Show Hard Drives On Desktop","description":"If true, hard drives can appear on the desktop.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_showharddrivesondesktop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_showharddrivesondesktop_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_showmountedserversondesktop","displayName":"Show Mounted Servers On Desktop","description":"If true, mounted servers can appear on the desktop.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_showmountedserversondesktop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_showmountedserversondesktop_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_showremovablemediaondesktop","displayName":"Show Removable Media On Desktop","description":"If false, removable media can not appear on the desktop.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_showremovablemediaondesktop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_showremovablemediaondesktop_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_warnonemptytrash","displayName":"Warn On Empty Trash","description":"If false, the warning before a user empties the Trash can be disabled.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_warnonemptytrash_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_warnonemptytrash_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.font_com.apple.font","displayName":"com.apple.font","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5401711f-292a-487a-be18-f99593a0477c","categoryName":"Font","options":null},{"id":"com.apple.font_font","displayName":"Font","description":"The contents of the font file.","helpText":null,"infoUrls":[],"categoryId":"5401711f-292a-487a-be18-f99593a0477c","categoryName":"Font","options":null},{"id":"com.apple.font_name","displayName":"Name","description":"The user-visible name for the font. This field is replaced by the actual name of the font after installation. Each payload must contain exactly one font file in trueType (.ttf) or OpenType (.otf) format. Collection formats (.ttc or .otc) are not supported.\n\nFonts are identified by their embedded PostScript names. Two fonts with the same PostScript name are considered to be the same font even if their contents differ. Installing two different fonts with the same PostScript name isn't supported, and the resulting behavior is undefined.","helpText":null,"infoUrls":[],"categoryId":"5401711f-292a-487a-be18-f99593a0477c","categoryName":"Font","options":null},{"id":"com.apple.gamed_com.apple.gamed","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"7ecdd7c9-6ab2-4dac-88ef-9bdad46e1f66","categoryName":"Parental Controls Game Center","options":null},{"id":"com.apple.gamed_gkfeatureaccountmodificationallowed","displayName":"GK Feature Account Modification Allowed","description":"If true, allows account modifications.","helpText":null,"infoUrls":[],"categoryId":"7ecdd7c9-6ab2-4dac-88ef-9bdad46e1f66","categoryName":"Parental Controls Game Center","options":[{"id":"com.apple.gamed_gkfeatureaccountmodificationallowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.gamed_gkfeatureaccountmodificationallowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.ldap.account_com.apple.ldap.account","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapaccountdescription","displayName":"LDAP Account Description","description":"The description of the account.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapaccounthostname","displayName":"LDAP Account Host Name","description":"The server’s address.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapaccountpassword","displayName":"LDAP Account Password","description":"The user’s password. The password is enabled only with encrypted profiles.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapaccountusername","displayName":"LDAP Account User Name","description":"The user name.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapaccountusessl","displayName":"LDAP Account Use SSL","description":"If true, enables SSL.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":[{"id":"com.apple.ldap.account_ldapaccountusessl_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.ldap.account_ldapaccountusessl_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.ldap.account_ldapsearchsettings","displayName":"LDAP Search Settings","description":"An array of search settings dictionaries.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingdescription","displayName":"LDAP Search Setting Description","description":"The description of this search setting.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope","displayName":"LDAP Search Setting Scope","description":"The type of recursion to use in the search. It is one of the following values:\r\n\r\nBase: Only the immediate node that the search base points to.\r\n\r\nOne Level: The node plus its immediate children.\r\n\r\nSubtree: The node plus all children, regardless of depth.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":[{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope_0","displayName":"Base","description":null,"helpText":null},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope_1","displayName":"OneLevel","description":null,"helpText":null},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope_2","displayName":"Subtree","description":null,"helpText":null}]},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingsearchbase","displayName":"LDAP Search Setting Search Base","description":"The path to the node where a search should start. ","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.loginitems.managed_autolaunchedapplicationdictionary-managed","displayName":"Auto Launch Items","description":"Auto Launch Login Items","helpText":null,"infoUrls":[],"categoryId":"6efb8802-223a-46a7-b13f-a68f28f8b2c2","categoryName":"Login Items","options":null},{"id":"com.apple.loginitems.managed_autolaunchedapplicationdictionary-managed_item_hide","displayName":"Hide","description":"If true, hide this item in the Users & Groups login items list.","helpText":null,"infoUrls":[],"categoryId":"6efb8802-223a-46a7-b13f-a68f28f8b2c2","categoryName":"Login Items","options":[{"id":"com.apple.loginitems.managed_autolaunchedapplicationdictionary-managed_item_hide_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginitems.managed_autolaunchedapplicationdictionary-managed_item_hide_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginitems.managed_autolaunchedapplicationdictionary-managed_item_path","displayName":"Path","description":"The URL or path string to the item's location.","helpText":null,"infoUrls":[],"categoryId":"6efb8802-223a-46a7-b13f-a68f28f8b2c2","categoryName":"Login Items","options":null},{"id":"com.apple.loginitems.managed_com.apple.loginitems.managed","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"6efb8802-223a-46a7-b13f-a68f28f8b2c2","categoryName":"Login Items","options":null},{"id":"com.apple.loginwindow_adminhostinfo","displayName":"Admin Host Info","description":"If this key is included in the payload, its value is displayed in the login window as additional computer information. Before macOS 10.10, this string could contain only certain information (host name, system version, or IP address). After macOS 10.10, setting this key to any value allows the user to click the time area of the menu bar to toggle through various computer information values.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_allowlist","displayName":"Allow List","description":"The list of user GUIDs or group GUIDs of users that are allowed to log in. An asterisk '*' string specifies all users or groups.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_autologinpassword","displayName":"Autologin Password","description":"Optional user password when setting up auto login. If this key does not exist, and a user name was specified, auto login will be set up the next time the specified user logs in to the client.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_autologinusername","displayName":"Autologin Username","description":"Sets up auto login with the specified short user name.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_com.apple.loginwindow","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_denylist","displayName":"Deny List","description":"The list of user GUIDs or group GUIDs of users that cannot log in. This list takes priority over the list in the Allow List key.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_disableconsoleaccess","displayName":"Disable Console Access","description":"If true, disregards the >console special user name, which will provide a command line UI.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_disableconsoleaccess_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_disableconsoleaccess_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_disablescreenlockimmediate","displayName":"Disable Screen Lock Immediate","description":"If true, disables the immediate Screen Lock functions. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_disablescreenlockimmediate_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_disablescreenlockimmediate_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_hideadminusers","displayName":"Hide Admin Users","description":"If true, hides administrator users when showing a user list.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_hideadminusers_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_hideadminusers_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_hidelocalusers","displayName":"Hide Local Users","description":"If true, shows only network and system users when showing a user list.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_hidelocalusers_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_hidelocalusers_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_includenetworkuser","displayName":"Include Network User","description":"If true, shows network users when showing a user list.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_includenetworkuser_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_includenetworkuser_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_loginwindowtext","displayName":"Login Window Text","description":"The text to display in the Login Window.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_logoutdisabledwhileloggedin","displayName":"Log Out Disabled While Logged In","description":"If true, disables the Log Out menu item when the user is logged in. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_logoutdisabledwhileloggedin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_logoutdisabledwhileloggedin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_poweroffdisabledwhileloggedin","displayName":"Power Off Disabled While Logged In","description":"If true, disables the Power Off menu item when the user is logged in.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_poweroffdisabledwhileloggedin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_poweroffdisabledwhileloggedin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_restartdisabled","displayName":"Restart Disabled","description":"If true, disables the Restart item.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_restartdisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_restartdisabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_restartdisabledwhileloggedin","displayName":"Restart Disabled While Logged In","description":"If true, disables the Restart menu item when the user is logged in.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_restartdisabledwhileloggedin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_restartdisabledwhileloggedin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_showfullname","displayName":"Show Full Name","description":"If true, shows the name and password dialog; if false, displays a list of users. Enabling this setting overrides the behavior of \"Show other users managed\". It's recommended to only use either \"Show full name\" or \"Show other users managed\", but not both.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_showfullname_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_showfullname_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_showinputmenu","displayName":"Show Input Menu","description":"If `true`, the system shows the Input Menu in the Login Window.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_showinputmenu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_showinputmenu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_showotherusers_managed","displayName":"Show Other Users Managed","description":"If true, displays Other... when showing a list of users.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_showotherusers_managed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_showotherusers_managed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_shutdowndisabled","displayName":"Shut Down Disabled","description":"If true, disables the Shut Down button.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_shutdowndisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_shutdowndisabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_shutdowndisabledwhileloggedin","displayName":"Shut Down Disabled While Logged In","description":"If true, disables the Shut Down menu item when the user is logged in.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_shutdowndisabledwhileloggedin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_shutdowndisabledwhileloggedin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_sleepdisabled","displayName":"Sleep Disabled","description":"If true, disables the Sleep button.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_sleepdisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_sleepdisabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_aadwebsitessousingthisprofileenabled","displayName":"Single sign-on for work or school sites using this profile enabled","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\n\nIf you enable or disable this policy, 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will be turned off.\n\nIf you don't configure this policy, users can control whether to use SSO using other credentials present on the machine in edge://settings/profiles/multiProfileSettings.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#aadwebsitessousingthisprofileenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_aadwebsitessousingthisprofileenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_aadwebsitessousingthisprofileenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_accesscontrolallowmethodsincorspreflightspecconformant","displayName":"Make Access-Control-Allow-Methods matching in CORS preflight spec conformant","description":"This policy controls whether request methods are uppercased when matching with Access-Control-Allow-Methods response headers in CORS preflight.\n\nIf you disable this policy, request methods are uppercased. This is the behavior on or before Microsoft Edge 108.\n\nIf you enable or don't configure this policy, request methods are not uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT.\n\nThis would reject fetch(url, {method: 'Foo'}) + \"Access-Control-Allow-Methods: FOO\" response header,\nand would accept fetch(url, {method: 'Foo'}) + \"Access-Control-Allow-Methods: Foo\" response header.\n\nNote: request methods \"post\" and \"put\" are not affected, while \"patch\" is affected.\n\nThis policy is intended to be temporary and will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#accesscontrolallowmethodsincorspreflightspecconformant"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_accesscontrolallowmethodsincorspreflightspecconformant_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_accesscontrolallowmethodsincorspreflightspecconformant_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_accessibilityimagelabelsenabled","displayName":"Let screen reader users get image descriptions from Microsoft","description":"Lets screen reader users get descriptions of unlabeled images on the web.\n\nIf you enable or don't configure this policy, users have the option of using an anonymous Microsoft service. This service provides automatic descriptions for unlabeled images users encounter on the web when they're using a screen reader.\n\nIf you disable this policy, users can't enable the Get Image Descriptions from Microsoft feature.\n\nWhen this feature is enabled, the content of images that need a generated description is sent to Microsoft servers to generate a description.\n\nNo cookies or other user data is sent to Microsoft, and Microsoft doesn't save or log any image content.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#accessibilityimagelabelsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_accessibilityimagelabelsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_accessibilityimagelabelsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_acknowledgeddatacollectionpolicy","displayName":"Automatically acknowledge data collection policy","description":"Suppress the Required Data Collection policy dialog from being shown to users.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/deployoffice/privacy/mac-privacy-preferences#preference-setting-for-the-required-data-notice-dialog-for-microsoft-autoupdate"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_acknowledgeddatacollectionpolicy_0","displayName":"Acknowledge - send required data","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_acknowledgeddatacollectionpolicy_1","displayName":"Acknowledge - send required and optional data (Deprecated)","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_additionaldnsquerytypesenabled","displayName":"Allow DNS queries for more DNS record types","description":"This policy controls whether Microsoft Edge can query more DNS record types when making insecure (non-Secure DNS) requests.\n\nIf this policy is unset or set to Enabled, more record types such as HTTPS (DNS type 65) may be queried in addition to A (DNS type 1) and AAAA (DNS type 28).\n\nIf this policy is set to Disabled, Microsoft Edge will only query A and AAAA record types for insecure DNS requests.\n\nThis setting doesn't affect DNS queries made via Secure DNS, which may always use more record types.\n\nNote: This is a temporary policy and is planned for removal in a future version of Microsoft Edge. After removal, Microsoft Edge will always be able to query more DNS types during insecure requests.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#additionaldnsquerytypesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_additionaldnsquerytypesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_additionaldnsquerytypesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_additionalsearchboxenabled","displayName":"Enable additional search box in browser","description":"A search box is an additional text input field located next to the address bar in a web browser. It allows users to perform web searches directly from the browser interface.\n\nIf you enable or don't configure this policy, the search box will be visible and available for use.\nUsers can toggle the search box in Edge Settings page edge://settings/appearance#SearchBoxInToolbar.\n\nIf you disable this policy, search box will not be visible, and users will have to use the address bar or navigate to a search engine to perform web searches.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#additionalsearchboxenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_additionalsearchboxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_additionalsearchboxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_addressbarmicrosoftsearchinbingproviderenabled","displayName":"Enable Microsoft Search in Bing suggestions in the address bar (Deprecated)","description":"Enables the display of relevant Microsoft Search in Bing suggestions in the address bar's suggestion list when the user types a search string in the address bar. If you enable or don't configure this policy, users can see internal results powered by Microsoft Search in Bing in the Microsoft Edge address bar suggestion list. To see the Microsoft Search in Bing results, the user must be signed into Microsoft Edge with their Azure AD account for that organization.\nIf you disable this policy, users can't see internal results in the Microsoft Edge address bar suggestion list.\nIf you have enabled the set of policies which forces a default search provider (\"DefaultSearchProviderEnabled\", \"DefaultSearchProviderName\" and \"DefaultSearchProviderSearchURL\"), and the search provider specified is not Bing, then this policy is not applicable and there will be no Microsoft Search in Bing suggestions in the address bar's suggestion list.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#addressbarmicrosoftsearchinbingproviderenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_addressbarmicrosoftsearchinbingproviderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_addressbarmicrosoftsearchinbingproviderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_addressbartrendingsuggestenabled","displayName":"Enable Microsoft Bing trending suggestions in the address bar","description":"This policy controls whether Microsoft Bing trending suggestions appear in the address bar’s suggestion dropdown when users click the address bar while on a New Tab Page.\n\nIf this policy is enabled or not configured, Microsoft Bing trending suggestions will appear in the address bar suggestion dropdown.\n\nIf this policy is disabled, Microsoft Edge will not display Microsoft Bing trending suggestions when users click the address bar.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#addressbartrendingsuggestenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_addressbartrendingsuggestenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_addressbartrendingsuggestenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_addressbarworksearchresultsenabled","displayName":"Enable Work Search suggestions in the address bar","description":"Enables the display of relevant workplace suggestions in the address bar’s suggestion dropdown when users type a query in the address bar.\n\nIf this policy is enabled or not configured, users can view internal work-related suggestions, such as bookmarks, files, and people results powered by Microsoft 365, in the Microsoft Edge address bar suggestion dropdown. To access these results, users must be signed into Microsoft Edge with their Entra ID account associated with that organization.\n\nIf this policy is disabled, users will not see internal workplace results in the Microsoft Edge address bar suggestion dropdown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#addressbarworksearchresultsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_addressbarworksearchresultsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_addressbarworksearchresultsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_adhoccodesigningforpwasenabled","displayName":"Native application signing during Progressive Web Application installation","description":"Enabling this policy or leaving it unset enables the use of ad-hoc signatures for the native application that's created when installing a Progressive Web Application (PWA). This ensures that each installed application has a unique identity to macOS system components.\n\nDisabling this policy will result in every native application created when installing Progressive Web Applications having the same identity. This can interfere with macOS functionality.\n\nOnly turn off the policy if you are using an endpoint security solution that blocks applications with an ad-hoc signature.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#adhoccodesigningforpwasenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_adhoccodesigningforpwasenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_adhoccodesigningforpwasenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads","description":"Controls whether ads are blocked on sites with intrusive ads. You can set this policy to one of the following options:\n\n* 1 = Allow ads on all sites.\n\n* 2 = Block ads on sites with intrusive ads (Default value).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#adssettingforintrusiveadssites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_adssettingforintrusiveadssites_0","displayName":"Allow ads on all sites","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_adssettingforintrusiveadssites_1","displayName":"Block ads on sites with intrusive ads. (Default value)","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_adstransparencyenabled","displayName":"Configure if the ads transparency feature is enabled","description":"Lets you decide whether the ads transparency feature is enabled. This behavior only applies to the \"balanced\" mode of tracking prevention, and does not impact \"basic\" or \"strict\" modes. Your users' tracking prevention level can be configured using the \"TrackingPrevention\" policy. AdsTransparencyEnabled will only have an effect if \"TrackingPrevention\" is set to TrackingPreventionBalanced or is not configured.\n\nIf you enable or don't configure this policy, transparency metadata provided by ads will be available to the user when the feature is active.\n\nWhen the feature is enabled, Tracking Prevention will enable exceptions for the associated ad providers that have met Microsoft's privacy standards.\n\nIf you disable this policy, Tracking Prevention will not adjust its behavior even when transparency metadata is provided by ads.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#adstransparencyenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_adstransparencyenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_adstransparencyenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_aigenthemesenabled","displayName":"Enables DALL-E themes generation","description":"This policy lets you generate browser themes using DALL-E and apply them to Microsoft Edge.\n\nIf you enable or don't configure this policy, the AI generated themes will be enabled.\n\nIf you disable this policy, the AI generated themes will be disabled for your organization.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#aigenthemesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_aigenthemesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_aigenthemesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allhttpauthschemesallowedfororigins","displayName":"List of origins that allow all HTTP authentication","description":"Set this policy to specify which origins allow all the HTTP authentication schemes Microsoft Edge supports regardless of the \"AuthSchemes\" policy.\n\nFormat the origin pattern according to this format (https://support.google.com/chrome/a?p=url_blocklist_filter_format). Up to 1,000 exceptions can be defined in \"AllHttpAuthSchemesAllowedForOrigins\".\nWildcards are allowed for the whole origin or parts of the origin. Parts include the scheme, host, or port.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allhttpauthschemesallowedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_allowbackforwardcacheforcachecontrolnostorepageenabled","displayName":"Allow pages with Cache-Control: no-store header to enter back/forward cache","description":"This policy controls if a page with Cache-Control: no-store header can be stored in back/forward cache. The website setting this header may not expect the page to be restored from back/forward cache since some sensitive information could still be displayed after the restoration even if it is no longer accessible.\n\nIf you enable or don't configure this policy, the page with Cache-Control: no-store header might be restored from back/forward cache unless the cache eviction is triggered (e.g. when there is HTTP-only cookie change to the site).\n\nIf you disable this policy, the page with Cache-Control: no-store header will not be stored in back/forward cache.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowbackforwardcacheforcachecontrolnostorepageenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowbackforwardcacheforcachecontrolnostorepageenabled_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowbackforwardcacheforcachecontrolnostorepageenabled_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowcertswithoutmatchingemailaddress","displayName":"Allow S/MIME certificates without a matching email address","description":"Allow users to decrypt and encrypt S/MIME messages when the S/MIME certificate does not match the email address.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#allow-smime-certificates-without-a-matching-email-address"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_allowcertswithoutmatchingemailaddress_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowcertswithoutmatchingemailaddress_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowcrossoriginauthprompt","displayName":"Allow cross-origin HTTP Basic Auth prompts","description":"Controls whether third-party sub-content on a page can open an HTTP Basic Auth dialog box.\n\nTypically, this is disabled as a phishing defense. If you don't configure this policy, it's disabled and third-party sub-content can't open a HTTP Basic Auth dialog box.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowcrossoriginauthprompt"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowcrossoriginauthprompt_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowcrossoriginauthprompt_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowdeletingbrowserhistory","displayName":"Enable deleting browser and download history","description":"Enables deleting browser history and download history and prevents users from changing this setting.\n\nNote that even with this policy is disabled, the browsing and download history aren't guaranteed to be retained: users can edit or delete the history database files directly, and the browser itself may remove (based on expiration period) or archive any or all history items at any time.\n\nIf you enable this policy or don't configure it, users can delete the browsing and download history.\n\nIf you disable this policy, users can't delete browsing and download history.\n\nIf you enable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you enable both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how this policy is configured.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowdeletingbrowserhistory"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowdeletingbrowserhistory_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowdeletingbrowserhistory_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace","description":"Setting the policy on Microsoft Edge turns on the restricted sign-in feature in Google Workspace and prevents users from changing this setting. Users can only access Google tools using accounts from the specified domains. To allow gmail or googlemail accounts, add consumer_accounts to the list of domains. This policy is based on the Chrome policy of the same name.\n\nIf you don't provide a domain name or leave this policy unset, users can access Google Workspace with any account.\n\nUsers cannot change or override this setting.\n\nNote: This policy causes the X-GoogApps-Allowed-Domains header to be appended to all HTTP and HTTPS requests to all google.com domains, as described in https://go.microsoft.com/fwlink/?linkid=2197973.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#alloweddomainsforapps"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_allowedemaildomains","displayName":"Allowed Email Domains","description":"Specify a list of email domains that are allowed to be added to the Outlook profile (e.g. contoso.com). Subdomains will be automatically included (e.g. specifying contoso.com will also allow foo.contoso.com).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#allow-only-corporate-mailboxes-to-be-added"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":null},{"id":"com.apple.managedclient.preferences_allowedthreats","displayName":"Allowed threats","description":"List of threats (identified by their name) that are not blocked by the product and are instead allowed to run.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#allowed-threats"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_allowfileselectiondialogs","displayName":"Allow file selection dialogs","description":"Allow access to local files by letting Microsoft Edge display file selection dialogs.\n\nIf you enable or don't configure this policy, users can open file selection dialogs as normal.\n\nIf you disable this policy, whenever the user performs an action that triggers a file selection dialog (like importing favorites, uploading files, or saving links), a message is displayed instead, and the user is assumed to have clicked Cancel on the file selection dialog.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowfileselectiondialogs"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowfileselectiondialogs_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowfileselectiondialogs_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowpopupsduringpageunload","displayName":"Allows a page to show popups during its unloading","description":"This policy allows an admin to specify that a page can show popups during its unloading.\n\nWhen the policy is set to enabled, pages are allowed to show popups while they're being unloaded.\n\nWhen the policy is set to disabled or unset, pages aren't allowed to show popups while they're being unloaded. This is as per the spec: (https://html.spec.whatwg.org/#apis-for-creating-and-navigating-browsing-contexts-by-name).\n\nThis policy will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowpopupsduringpageunload"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowpopupsduringpageunload_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowpopupsduringpageunload_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowsurfgame","displayName":"Allow surf game","description":"If you disable this policy, users won't be able to play the surf game when the device is offline or if the user navigates to edge://surf.\n\nIf you enable or don't configure this policy, users can play the surf game.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowsurfgame"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowsurfgame_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowsurfgame_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowsyncxhrinpagedismissal","displayName":"Allow pages to send synchronous XHR requests during page dismissal","description":"This policy lets you specify that a page can send synchronous XHR requests during page dismissal.\n\nIf you enable this policy, pages can send synchronous XHR requests during page dismissal.\n\nIf you disable this policy or don't configure this policy, pages aren't allowed to send synchronous XHR requests during page dismissal.\n\nThis policy is temporary and will be removed in a future release.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowsyncxhrinpagedismissal"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowsyncxhrinpagedismissal_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowsyncxhrinpagedismissal_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowtrackingforurls","displayName":"Configure tracking prevention exceptions for specific sites","description":"Configure the list of URL patterns that are excluded from tracking prevention.\n\nIf you configure this policy, the list of configured URL patterns is excluded from tracking prevention.\n\nIf you don't configure this policy, the global default value from the \"Block tracking of users' web-browsing activity\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowtrackingforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_allowvisualbasictobindtosystem","displayName":"Allow Visual Basic macros to use system APIs","description":"Allow Visual Basic macros to use DECLARE to bind to the system() OS API. Recommended: false.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_allowvisualbasictobindtosystem_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowvisualbasictobindtosystem_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowwebauthnwithbrokentlscerts","displayName":"Allow Web Authentication requests on sites with broken TLS certificates.","description":"If you enable this policy, Microsoft Edge will allow Web Authentication requests on websites that have TLS certificates with errors (i.e. websites considered not secure).\n\nIf you disable or don't configure this policy, the default behavior of blocking such requests will apply.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowwebauthnwithbrokentlscerts"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowwebauthnwithbrokentlscerts_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowwebauthnwithbrokentlscerts_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_alternateerrorpagesenabled","displayName":"Suggest similar pages when a webpage can’t be found","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\n\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\n\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\n\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\nSpecifically, there's a **Suggest similar pages when a webpage can’t be found** toggle, which the user can switch on or off. Note that if you have enable this policy (AlternateErrorPagesEnabled), the Suggest similar pages when a webpage can’t be found setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the Suggest similar pages when a webpage can’t be found setting is turned off, and the user can't change the setting by using the toggle.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#alternateerrorpagesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_alternateerrorpagesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_alternateerrorpagesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_alwaysopenpdfexternally","displayName":"Always open PDF files externally","description":"Disables the internal PDF viewer in Microsoft Edge.\n\nIf you enable this policy Microsoft Edge treats PDF files as downloads and lets users open them with the default application.\n\nIf you don't configure this policy or disable it, Microsoft Edge will open PDF files (unless the user disables it).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#alwaysopenpdfexternally"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_alwaysopenpdfexternally_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_alwaysopenpdfexternally_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for InPrivate and Guest profiles","description":"Configure this policy to allow/disallow ambient authentication for InPrivate and Guest profiles in Microsoft Edge.\n\nAmbient Authentication is http authentication with default credentials when explicit credentials aren't provided via NTLM/Kerberos/Negotiate challenge/response schemes.\n\nIf you set the policy to RegularOnly (value 0), it allows ambient authentication for Regular sessions only. InPrivate and Guest sessions won't be allowed to ambiently authenticate.\n\nIf you set the policy to InPrivateAndRegular (value 1), it allows ambient authentication for InPrivate and Regular sessions. Guest sessions won't be allowed to ambiently authenticate.\n\nIf you set the policy to GuestAndRegular (value 2), it allows ambient authentication for Guest and Regular sessions. InPrivate sessions won't be allowed to ambiently authenticate\n\nIf you set the policy to All (value 3), it allows ambient authentication for all sessions.\n\nNote that ambient authentication is always allowed on regular profiles.\n\nIf you don't configure this policy, InPrivate and Guest sessions will not be able to ambiently authenticate in future releases of Microsoft Edge, because they will be disallowed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#ambientauthenticationinprivatemodesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_ambientauthenticationinprivatemodesenabled_0","displayName":"Enable ambient authentication in regular sessions only.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_ambientauthenticationinprivatemodesenabled_1","displayName":"Enable ambient authentication in InPrivate and regular sessions","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_ambientauthenticationinprivatemodesenabled_2","displayName":"Enable ambient authentication in guest and regular sessions","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_ambientauthenticationinprivatemodesenabled_3","displayName":"Enable ambient authentication in regular, InPrivate and guest sessions","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_appcacheforceenabled","displayName":"Allows the AppCache feature to be re-enabled, even if it's turned off by default","description":"If you set this policy to true, the AppCache is enabled, even when AppCache in Microsoft Edge is not available by default.\n\nIf you set this policy to false, or don't set it, AppCache will follow Microsoft Edge's defaults.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#appcacheforceenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_appcacheforceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_appcacheforceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem","displayName":"Applications","description":null,"helpText":null,"infoUrls":["https://github.com/pbowden-msft/Payloads"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app","displayName":"Company Portal","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_application id","displayName":"Company Portal Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_lcid","displayName":"Company Portal LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app","displayName":"Microsoft Defender ATP (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_application id","displayName":"Microsoft Defender ATP Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_lcid","displayName":"Microsoft Defender ATP LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app","displayName":"Microsoft Defender","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_application id","displayName":"Microsoft Defender Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_lcid","displayName":"Microsoft Defender LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app","displayName":"Microsoft Edge Beta (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_application id","displayName":"Microsoft Edge Beta Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_lcid","displayName":"Microsoft Edge Beta LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app","displayName":"Microsoft Edge Canary (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_application id","displayName":"Microsoft Edge Canary Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_lcid","displayName":"Microsoft Edge Canary LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app","displayName":"Microsoft Edge Dev (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_application id","displayName":"Microsoft Edge Dev Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_lcid","displayName":"Microsoft Edge Dev LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app","displayName":"Microsoft Edge (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_application id","displayName":"Microsoft Edge Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_lcid","displayName":"Microsoft Edge LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app","displayName":"Microsoft Excel","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_application id","displayName":"Microsoft Excel Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_lcid","displayName":"Microsoft Excel LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app","displayName":"Microsoft OneNote","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_application id","displayName":"Microsoft OneNote Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_lcid","displayName":"Microsoft OneNote LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app","displayName":"Microsoft Outlook","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_application id","displayName":"Microsoft Outlook Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_lcid","displayName":"Microsoft Outlook LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app","displayName":"Microsoft PowerPoint","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_application id","displayName":"Microsoft PowerPoint Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_lcid","displayName":"Microsoft PowerPoint LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app","displayName":"Microsoft Remote Desktop (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_application id","displayName":"Microsoft Remote Desktop Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_lcid","displayName":"Microsoft Remote Desktop LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app","displayName":"Microsoft Teams (work or school).app","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_application id","displayName":"Microsoft Teams (work or school) Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_lcid","displayName":"Microsoft Teams (work or school) LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app","displayName":"Microsoft Teams classic","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_application id","displayName":"ApplicationsSystem//Applications/Microsoft Teams classic.app/Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_lcid","displayName":"Microsoft Teams classic LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app","displayName":"Microsoft Teams (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_application id","displayName":"Microsoft Teams Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_lcid","displayName":"Microsoft Teams LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app","displayName":"Microsoft Word","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_application id","displayName":"Microsoft Word Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_lcid","displayName":"Microsoft Word LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app","displayName":"OneDrive","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_application id","displayName":"OneDrive Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_lcid","displayName":"OneDrive LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app","displayName":"Skype for Business","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_application id","displayName":"Skype for Business Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_lcid","displayName":"Skype for Business LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app","displayName":"Windows App","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_application id","displayName":"Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname","displayName":"Channel Name","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_lcid","displayName":"LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_manifestserver","displayName":"Manifest Server","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app","displayName":"Microsoft Auto Update","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_application id","displayName":"Microsoft AutoUpdate Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_lcid","displayName":"Microsoft AutoUpdate LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_askbeforecloseenabled","displayName":"Get user confirmation before closing a browser window with multiple tabs","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\n\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\n\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#askbeforecloseenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_askbeforecloseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_askbeforecloseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_audiocaptureallowed","displayName":"Allow or block audio capture","description":"Allows you to set whether a user is prompted to grant a website access to their audio capture device. This policy applies to all URLs except for those configured in the \"AudioCaptureAllowedUrls\" list.\n\nIf you enable this policy or don't configure it (the default setting), the user is prompted for audio capture access except from the URLs in the \"AudioCaptureAllowedUrls\" list. These listed URLs are granted access without prompting.\n\nIf you disable this policy, the user is not prompted, and audio capture is accessible only to the URLs configured in \"AudioCaptureAllowedUrls\".\n\nThis policy affects all types of audio inputs, not only the built-in microphone.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#audiocaptureallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_audiocaptureallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_audiocaptureallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_audiocaptureallowedurls","displayName":"Sites that can access audio capture devices without requesting permission","description":"Specify websites, based on URL patterns, that can use audio capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to audio capture devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#audiocaptureallowedurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_audiosandboxenabled","displayName":"Allow the audio sandbox to run","description":"This policy controls the audio process sandbox.\n\nIf you enable this policy, the audio process will run sandboxed.\n\nIf you disable this policy, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\n\nIf you don't configure this policy, the default configuration for the audio sandbox will be used, which might differ based on the platform.\n\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#audiosandboxenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_audiosandboxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_audiosandboxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_authnegotiatedelegateallowlist","displayName":"Specifies a list of servers that Microsoft Edge can delegate user credentials to","description":"Configure the list of servers that Microsoft Edge can delegate to.\n\nSeparate multiple server names with commas. Wildcards (*) are allowed.\n\nIf you don't configure this policy Microsoft Edge won't delegate user credentials even if a server is detected as Intranet.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#authnegotiatedelegateallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_authschemes","displayName":"Supported authentication schemes","description":"Specifies which HTTP authentication schemes are supported.\n\nYou can configure the policy by using these values: 'basic', 'digest', 'ntlm', and 'negotiate'. Separate multiple values with commas.\n\nIf you don't configure this policy, all four schemes are used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#authschemes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_authserverallowlist","displayName":"Configure list of allowed authentication servers","description":"Specifies which servers to enable for integrated authentication. Integrated authentication is only enabled when Microsoft Edge receives an authentication challenge from a proxy or from a server in this list.\n\nSeparate multiple server names with commas. Wildcards (*) are allowed.\n\nIf you don't configure this policy, Microsoft Edge tries to detect if a server is on the intranet - only then will it respond to IWA requests. If the server is on the internet, IWA requests from it are ignored by Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#authserverallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_autodiscardsleepingtabsenabled","displayName":"Configure auto discard sleeping tabs","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab will need to be reloaded.\n\nIf the \"SleepingTabsEnabled\" policy is enabled, then this feature will be enabled by default.\n\nIf the \"SleepingTabsEnabled\" is disabled, then this feature will be disabled by default and cannot be enabled.\n\nIf enabled, idle background tabs will be discarded after 1.5 days.\n\nIf disabled, idle background tab will not be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autodiscardsleepingtabsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autodiscardsleepingtabsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autodiscardsleepingtabsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_autofilladdressenabled","displayName":"Enable AutoFill for addresses","description":"Enables the AutoFill feature and allows users to auto-complete address information in web forms using previously stored information.\n\nIf this policy is enabled or not configured, users can manage AutoFill for addresses in Microsoft Edge settings. AutoFill allows users to complete address fields in web forms using previously saved information.\n\nIf this policy is disabled, Microsoft Edge does not suggest, fill in, or save address information. AutoFill is also disabled for all web forms except payment and password fields, and previously saved addresses are not available.\n\nDisabling this policy also turns off \"EdgeAutofillMlEnabled\".\n\nNote that if you disable this policy you also stop all activity for all web forms, except payment and password forms. No further entries are saved, and Microsoft Edge won't suggest or AutoFill any previous entries.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autofilladdressenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autofilladdressenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autofilladdressenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_autofillcreditcardenabled","displayName":"Enable AutoFill for credit cards","description":"Enables Microsoft Edge's AutoFill feature and lets users auto complete credit card information in web forms using previously stored information.\n\nIf you disable this policy, AutoFill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.\n\nIf you enable this policy or don't configure it, users can control AutoFill for credit cards.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autofillcreditcardenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autofillcreditcardenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autofillcreditcardenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_autofillmembershipsenabled","displayName":"Save and fill memberships","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\n\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autofillmembershipsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autofillmembershipsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autofillmembershipsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_autoimportatfirstrun","displayName":"Automatically import another browser's data and settings at first run","description":"If you enable this policy, all supported datatypes and settings from the specified browser will be silently and automatically imported at first run. During the First Run Experience, the import section will also be skipped.\n\nThe browser data from Microsoft Edge Legacy will always be silently migrated at the first run, irrespective of the value of this policy. You can use the following values for this policy:\n\n* 0 = Automatically imports all supported datatypes and settings from the default browser\n\n* 1 = Automatically imports all supported datatypes and settings from Internet Explorer\n\n* 2 = Automatically imports all supported datatypes and settings from Google Chrome\n\n* 3 = Automatically imports all supported datatypes and settings from Safari\n\n* 4 = Disables automatic import, and the import section of the first-run experience is skipped\n\n* 5 = Automatically imports all supported datatypes and settings from Mozilla Firefox\n\nIf this policy is set to the default value (0), then the datatypes corresponding to the default browser on the managed device will be imported.\n\nIf the browser specified as the value of this policy is not present in the managed device, Microsoft Edge will simply skip the import without any notification to the user.\n\nIf you set this policy to 'DisabledAutoImport' (4), the import section of the first-run experience is skipped entirely and Microsoft Edge doesn't import browser data and settings automatically.\n\nIf this policy is set to the value of Internet Explorer (1), the following datatypes will be imported from Internet Explorer:\n1. Favorites or bookmarks\n2. Saved passwords\n3. Search engines\n4. Browsing history\n5. Home page\n\nIf this policy is set to the value of Google Chrome (2), the following datatypes will be imported from Google Chrome:\n1. Favorites\n2. Saved passwords\n3. Addresses and more\n4. Payment info\n5. Browsing history\n6. Settings\n7. Pinned and Open tabs\n8. Extensions\n9. Cookies\n\nNote: For more details on what is imported from Google Chrome, please see https://go.microsoft.com/fwlink/?linkid=2120835\n\nIf this policy is set to the value of Safari (3), user data is no longer imported into Microsoft Edge. This is due to the way Full Disk Access works on Mac.\nOn macOS Mojave and above, it's no longer possible to have automated and unattended import of Safari data into Microsoft Edge.\n\nStarting with Microsoft Edge version 83, if this policy is set to the value of Mozilla Firefox (5), the following datatypes will be imported from Mozilla Firefox:\n1. Favorites or bookmarks\n2. Saved passwords\n3. Addresses and more\n4. Browsing History\n\nIf you want to restrict specific datatypes from getting imported on the managed devices, you can use this policy with other policies such as \"ImportAutofillFormData\", \"ImportBrowserSettings\", \"ImportFavorites\", and etc.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoimportatfirstrun"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autoimportatfirstrun_0","displayName":"Automatically imports all supported datatypes and settings from the default browser","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autoimportatfirstrun_1","displayName":"Automatically imports all supported datatypes and settings from Internet Explorer","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autoimportatfirstrun_2","displayName":"Automatically imports all supported datatypes and settings from Google Chrome","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autoimportatfirstrun_3","displayName":"Automatically imports all supported datatypes and settings from Safari","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autoimportatfirstrun_4","displayName":"Disables automatic import, and the import section of the first-run experience is skipped","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autoimportatfirstrun_5","displayName":"Automatically imports all supported datatypes and settings from Mozilla Firefox","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_autolaunchprotocolscomponentenabled","displayName":"AutoLaunch Protocols Component Enabled","description":"Specifies whether the AutoLaunch Protocols component should be enabled. This component allows Microsoft to provide a list similar to that of the \"AutoLaunchProtocolsFromOrigins\" policy, allowing certain external protocols to launch without prompt or blocking certain protocols (on specified origins). By default, this component is enabled.\n\nIf you enable or don't configure this policy, the AutoLaunch Protocols component is enabled.\n\nIf you disable this policy, the AutoLaunch Protocols component is disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autolaunchprotocolscomponentenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autolaunchprotocolscomponentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autolaunchprotocolscomponentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_automaticallydownloadexternalcontent","displayName":"Download embedded images","description":"Automatically downloading images will provide users with a better messaging experience. However, be aware of the privacy considerations if you are enabling this setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#specify-when-pictures-are-downloaded-for-email"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_automaticallydownloadexternalcontent_0","displayName":"Never download images","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automaticallydownloadexternalcontent_1","displayName":"Automatically download images from users in the address book","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automaticallydownloadexternalcontent_2","displayName":"Always download images regardless of sender","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_automaticdefinitionupdateenabled","displayName":"Automatic security intelligence updates","description":"Determines whether security intelligence updates are installed automatically:","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-automatic-security-intelligence-updates"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"com.apple.managedclient.preferences_automaticdefinitionupdateenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automaticdefinitionupdateenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_automaticdownloadsallowedforurls","displayName":"Allow multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to perform multiple successive automatic downloads.\nIf you don't configure this policy, \"DefaultAutomaticDownloadsSetting\" applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automaticdownloadsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_automaticdownloadsblockedforurls","displayName":"Block multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, where multiple successive automatic downloads aren't allowed.\nIf you don't configure this policy, \"DefaultAutomaticDownloadsSetting\" applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automaticdownloadsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_automaticfullscreenallowedforurls","displayName":"Allow automatic full screen on specified sites","description":"For security reasons, the\nrequestFullscreen() web API\nrequires a prior user gesture (\"transient activation\") to be called or it will\nfail. Users' personal settings may allow certain origins to call this API\nwithout a prior user gesture.\n\nThis policy supersedes users' personal settings and allows matching origins to\ncall the API without a prior user gesture.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\nWildcards (*) are allowed.\n\nOrigins matching both blocked and allowed policy patterns will be blocked.\nOrigins not specified by policy or user settings will require a prior user\ngesture to call this API.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automaticfullscreenallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_automaticfullscreenblockedforurls","displayName":"Block automatic full screen on specified sites","description":"For security reasons, the\nrequestFullscreen() web API\nrequires a prior user gesture (\"transient activation\") to be called or it will\nfail. Users' personal settings may allow certain origins to call this API\nwithout a prior user gesture.\n\nThis policy supersedes users' personal settings and blocks matching origins\nfrom calling the API without a prior user gesture.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\nWildcards (*) are allowed.\n\nOrigins matching both blocked and allowed policy patterns will be blocked.\nOrigins not specified by policy or user settings will require a prior user\ngesture to call this API.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automaticfullscreenblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_automatichttpsdefault","displayName":"Configure Automatic HTTPS (Deprecated)","description":"This policy lets you manage settings for \"AutomaticHttpsDefault\", which switches connections from HTTP to HTTPS.\n\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\n\nMicrosoft Edge attempts to upgrade some navigations from HTTP to HTTPS, when possible. This policy can be used to disable this behavior. If set to \"AlwaysUpgrade\" or left unset, this feature will be enabled by default.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nStarting in Microsoft Edge 111, \"UpgradePossibleDomains\" is deprecated and is treated the same as \"DisableAutomaticHttps\". It won't work in Microsoft Edge version 114.\n\nPolicy options mapping:\n\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\n\n* UpgradeCapableDomains (1) = (Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\n\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automatichttpsdefault"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_automatichttpsdefault_0","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automatichttpsdefault_1","displayName":"(Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automatichttpsdefault_2","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_automaticsamplesubmission","displayName":"Enable / disable automatic sample submissions","description":"Determines whether suspicious samples (that are likely to contain threats) are sent to Microsoft. You are prompted if the submitted file is likely to contain personal information.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-automatic-sample-submissions"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"com.apple.managedclient.preferences_automaticsamplesubmission_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automaticsamplesubmission_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_automaticsamplesubmissionconsent","displayName":"Automatic sample submission Consent","description":"Sends sample files to Microsoft to help protect device users and your organization from potential threats","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-automatic-sample-submissions"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"com.apple.managedclient.preferences_automaticsamplesubmissionconsent_0","displayName":"none","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automaticsamplesubmissionconsent_1","displayName":"safe","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automaticsamplesubmissionconsent_2","displayName":"all","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_automaticuploadbandwidthpercentage","displayName":"Automatic upload bandwidth percentage","description":"Enables the sync app to automatically set the amount of bandwidth used based on available bandwidth for uploading files. Accepted values are from 1 through 99.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#automaticuploadbandwidthpercentage"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_autoopenallowedforurls","displayName":"URLs where AutoOpenFileTypes can apply","description":"A list of URLs to which \"AutoOpenFileTypes\" will apply to. This policy has no impact on automatically open values set by users via the download shelf ... > \"Always open files of this type\" menu entry.\n\nIf you set URLs in this policy, files will only automatically open by policy if the URL is part of this set and the file type is listed in \"AutoOpenFileTypes\". If either condition is false, the download won't automatically open by policy.\n\nIf you don't set this policy, all downloads where the file type is in \"AutoOpenFileTypes\" will automatically open.\n\nA URL pattern has to be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoopenallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_autoopenfiletypes","displayName":"List of file types that should be automatically opened on download","description":"This policy sets a list of file types that should be automatically opened on download. Note: The leading separator should not be included when listing the file type, so list \"txt\" instead of \".txt\".\n\nBy default, these file types will be automatically opened on all URLs. You can use the \"AutoOpenAllowedForURLs\" policy to restrict the URLs for which these file types will be automatically opened on.\n\nFiles with types that should be automatically opened will still be subject to the enabled Microsoft Defender SmartScreen checks and won't be opened if they fail those checks.\n\nFile types that a user has already specified to automatically be opened will continue to do so when downloaded. The user will continue to be able to specify other file types to be automatically opened.\n\nIf you don't set this policy, only file types that a user has already specified to automatically be opened will do so when downloaded.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoopenfiletypes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_autoplayallowed","displayName":"Allow media autoplay for websites","description":"This policy sets the media autoplay policy for websites.\n\nThe default setting, \"Not configured\" respects the current media autoplay settings and lets users configure their autoplay settings.\n\nSetting to \"Enabled\" sets media autoplay to \"Allow\". All websites are allowed to autoplay media. Users can’t override this policy.\n\nSetting to \"Disabled\" sets media autoplay to \"Block\". No websites are allowed to autoplay media. Users can’t override this policy.\n\nA tab will need to be closed and re-opened for this policy to take effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoplayallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autoplayallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autoplayallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_autoplayallowlist","displayName":"Allow media autoplay on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to autoplay media.\n\nIf you don't configure this policy, the global default value from the \"AutoplayAllowed\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nNote: * is not an accepted value for this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoplayallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_autoselectcertificateforurls","displayName":"Automatically select client certificates for these sites","description":"Setting the policy lets you make a list of URL patterns that specify sites for which Microsoft Edge can automatically select a client certificate. The value is an array of stringified JSON dictionaries, each with the form { \"pattern\": \"$URL_PATTERN\", \"filter\" : $FILTER }, where $URL_PATTERN is a content setting pattern. $FILTER restricts the client certificates the browser automatically selects from. Independent of the filter, only certificates that match the server's certificate request are selected.\n\nExamples for the usage of the $FILTER section:\n\n* When $FILTER is set to { \"ISSUER\": { \"CN\": \"$ISSUER_CN\" } }, only client certificates issued by a certificate with the CommonName $ISSUER_CN are selected.\n\n* When $FILTER contains both the \"ISSUER\" and the \"SUBJECT\" sections, only client certificates that satisfy both conditions are selected.\n\n* When $FILTER contains a \"SUBJECT\" section with the \"O\" value, a certificate needs at least one organization matching the specified value to be selected.\n\n* When $FILTER contains a \"SUBJECT\" section with a \"OU\" value, a certificate needs at least one organizational unit matching the specified value to be selected.\n\n* When $FILTER is set to {}, the selection of client certificates is not additionally restricted. Note that filters provided by the web server still apply.\n\nIf you leave the policy unset, there's no autoselection for any site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoselectcertificateforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_backgroundtemplatelistupdatesenabled","displayName":"Enables background updates to the list of available templates for Collections and other features that use templates","description":"Lets you enable or disable background updates to the list of available templates for Collections and other features that use templates. Templates are used to extract rich metadata from a webpage when the page is saved to a collection.\n\nIf you enable this setting or the setting is unconfigured, the list of available templates will be downloaded in the background from a Microsoft service every 24 hours.\n\nIf you disable this setting the list of available templates will be downloaded on demand. This type of download might result in small performance penalties for Collections and other features.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#backgroundtemplatelistupdatesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_backgroundtemplatelistupdatesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_backgroundtemplatelistupdatesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_basicauthoverhttpenabled","displayName":"Allow Basic authentication for HTTP","description":"If you enable this policy or leave it unset, Basic authentication challenges received over non-secure HTTP will be allowed.\n\nIf you disable this policy, non-secure HTTP requests from the Basic authentication scheme are blocked, and only secure HTTPS is allowed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#basicauthoverhttpenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_basicauthoverhttpenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_basicauthoverhttpenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_behaviormonitoring","displayName":"Behavior Monitoring","description":"Behavior Monitoring detections with Microsoft Defender for Endpoint.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/behavior-monitor-macos"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_behaviormonitoring_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_behaviormonitoring_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_bingadssuppression","displayName":"Block all ads on Bing search results","description":"Enables an ad-free search experience on Bing.com\n\nIf you enable this policy, then a user can search on bing.com and have an ad-free search experience. At the same time, the SafeSearch setting will be set to 'Strict' and can't be changed by the user.\n\nIf you don't configure this policy, then the default experience will have ads in the search results on bing.com. SafeSearch will be set to 'Moderate' by default and can be changed by the user.\n\nThis policy is only available for K-12 SKUs that are identified as EDU tenants by Microsoft.\n\nPlease refer to https://go.microsoft.com/fwlink/?linkid=2119711 to learn more about this policy or if the following scenarios apply to you:\n\n* You have an EDU tenant, but the policy doesn't work.\n\n* You had your IP whitelisted for having an ad free search experience.\n\n* You were experiencing an ad-free search experience on Microsoft Edge Legacy and want to upgrade to the new version of Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#bingadssuppression"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_bingadssuppression_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_bingadssuppression_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_blockexternalextensions","displayName":"Blocks external extensions from being installed","description":"Control the installation of external extensions.\n\nIf you enable this setting, external extensions are blocked from being installed.\n\nIf you disable this setting or leave it unset, external extensions are allowed to be installed.\n\nExternal extensions and their installation are documented at https://docs.microsoft.com/microsoft-edge/extensions-chromium/developer-guide/alternate-distribution-options.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#blockexternalextensions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_blockexternalextensions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blockexternalextensions_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_blockexternalsync","displayName":"Block external sync","description":"Prevents the sync app from syncing libraries and folders shared from other organizations.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#blockexternalsync"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_blockexternalsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blockexternalsync_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_blockthirdpartycookies","displayName":"Block third party cookies","description":"This policy controls whether third-party cookies are blocked in regular browsing sessions.\n\nIf you enable this policy, web page elements that are not from the domain shown in the address bar can't set cookies.\n\nIf you disable this policy, third-party cookies are allowed, including from domains other than the one shown in the address bar.\n\nIf you don't configure this policy, third-party cookies are allowed by default, but users can change this setting.\n\nNote: This policy doesn't apply in InPrivate mode. In InPrivate, third-party cookies are blocked by default and can only be allowed at the site level using the CookiesAllowedForUrls policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#blockthirdpartycookies"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_blockthirdpartycookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blockthirdpartycookies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_blocktruncatedcookies","displayName":"Block truncated cookies (Deprecated)","description":"This policy provides a temporary opt-out for changes to how Microsoft Edge handles cookies set via JavaScript that contain certain control characters (NULL, carriage return, and line feed).\nPreviously, the presence of any of these characters in a cookie string would cause it to be truncated but still set.\nNow, the presence of these characters will cause the whole cookie string to be ignored.\n\nIf you enable or don't configure this policy, the new behavior is enabled.\n\nIf you disable this policy, the old behavior is enabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#blocktruncatedcookies"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_blocktruncatedcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blocktruncatedcookies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_browseraddprofileenabled","displayName":"Enable profile creation from the Identity flyout menu or the Settings page","description":"Allows users to create new profiles, using the **Add profile** option.\nIf you enable this policy or don't configure it, Microsoft Edge allows users to use **Add profile** on the Identity flyout menu or the Settings page to create new profiles.\n\nIf you disable this policy, users cannot add new profiles from the Identity flyout menu or the Settings page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#browseraddprofileenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_browseraddprofileenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_browseraddprofileenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_browserguestmodeenabled","displayName":"Enable guest mode","description":"Enable the option to allow the use of guest profiles in Microsoft Edge. In a guest profile, the browser doesn't import browsing data from existing profiles, and it deletes browsing data when all guest profiles are closed.\n\nIf you enable this policy or don't configure it, Microsoft Edge lets users browse in guest profiles.\n\nIf you disable this policy, Microsoft Edge doesn't let users browse in guest profiles.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#browserguestmodeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_browserguestmodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_browserguestmodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_browsernetworktimequeriesenabled","displayName":"Allow queries to a Browser Network Time service","description":"Prevents Microsoft Edge from occasionally sending queries to a browser network time service to retrieve an accurate timestamp.\n\nIf you disable this policy, Microsoft Edge will stop sending queries to a browser network time service.\n\nIf you enable this policy or don't configure it, Microsoft Edge will occasionally send queries to a browser network time service.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#browsernetworktimequeriesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_browsernetworktimequeriesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_browsernetworktimequeriesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_browsersignin","displayName":"Browser sign-in settings","description":"Specify whether a user can sign into Microsoft Edge with their account and use account-related services like sync and single sign on. To control the availability of sync, use the \"SyncDisabled\" policy instead.\n\nIf you set this policy to 'Disable browser sign-in', make sure that you also set the \"NonRemovableProfileEnabled\" policy to disabled because \"NonRemovableProfileEnabled\" disables the creation of an automatically signed in browser profile. If both policies are set, Microsoft Edge will use the 'Disable browser sign-in' policy and behave as if \"NonRemovableProfileEnabled\" is set to disabled.\n\nIf you set this policy to 'Enable browser sign-in' (1), users can sign into the browser. Signing into the browser doesn't mean that sync is turned on by default; the user must separately opt-in to use this feature.\n\nIf you set this policy to 'Force browser sign-in' (2) users must sign into a profile to use the browser. By default, this will allow the user to choose whether they want to sync to their account, unless sync is disabled by the domain admin or with the \"SyncDisabled\" policy. The default value of \"BrowserGuestModeEnabled\" policy is set to false.\n\nIf you don't configure this policy users can decide if they want to enable the browser sign-in option and use it as they see fit.\n\n* 0 = Disable browser sign-in\n\n* 1 = Enable browser sign-in\n\n* 2 = Force users to sign-in to use the browser","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#browsersignin"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_browsersignin_0","displayName":"Disable browser sign-in","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_browsersignin_1","displayName":"Enable browser sign-in","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_browsersignin_2","displayName":"Force users to sign-in to use the browser","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_builtinaiapisenabled","displayName":"Allow pages to use the built-in AI APIs.","description":"Use this policy to control whether websites can access the built-in AI APIs, including the LanguageModel API, Summarization API, Writer API, and Rewriter API.\n\nEnable this policy to allow pages to use the APIs. If you don’t configure this policy, the APIs are still allowed.\n\nDisable this policy to block access to the APIs. The APIs will return an error when used.\n\nFor more information, see https://github.com/webmachinelearning/writing-assistance-apis/blob/main/README.md.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#builtinaiapisenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_builtinaiapisenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_builtinaiapisenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_builtincertificateverifierenabled","displayName":"Determines whether the built-in certificate verifier will be used to verify server certificates","description":"This policy is deprecated because it's intended to serve only as a short-term mechanism to give enterprises more time to update their environments and report issues if they are found to be incompatible with the built-in certificate verifier.\n\nThis policy is scheduled to be removed in Microsoft Edge for Mac OS X version 87, when support for the legacy certificate verifier on Mac OS X is planned to be removed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#builtincertificateverifierenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_builtincertificateverifierenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_builtincertificateverifierenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_builtindnsclientenabled","displayName":"Use built-in DNS client","description":"Controls whether to use the built-in DNS client.\n\nThis does not affect which DNS servers are used; just the software stack which is used to communicate with them. For example if the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It is however possible that the built-in DNS client will address servers in different ways by using more modern DNS-related protocols such as DNS-over-TLS.\n\nIf you enable this policy, the built-in DNS client is used, if it's available.\n\nIf you disable this policy, the client is never used.\n\nIf you don't configure this policy, the built-in DNS client is enabled by default on MacOS, and users can change whether to use the built-in DNS client by editing edge://flags or by specifying a command-line flag.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#builtindnsclientenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_builtindnsclientenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_builtindnsclientenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates.","description":"This policy determines the level of access users have when managing CA certificates in Microsoft Edge.\n\nSetting the policy to UserOnly (1) allows users to manage only user-imported certificates. Trust settings for built-in certificates cannot be changed.\n\nSetting the policy to None (2) lets users view certificates but not manage them.\n\nNote: The certificate management experience is available starting in Microsoft Edge version 136.\n\nPolicy options mapping:\n\n* All (0) = Allow users to manage all certificates\n\n* UserOnly (1) = Allow users to manage user certificates\n\n* None (2) = Disallow users from managing certificates\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cacertificatemanagementallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_cacertificatemanagementallowed_0","displayName":"Allow users to manage all certificates","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_cacertificatemanagementallowed_1","displayName":"Allow users to manage user certificates","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_cacertificatemanagementallowed_2","displayName":"Disallow users from managing certificates","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_cacertificates","displayName":"TLS server certificates that should be trusted by Microsoft Edge","description":"This policy enables a list of TLS certificates that should be trusted by Microsoft Edge for server authentication.\nCertificates should be base64-encoded.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cacertificates"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_cadistrustedcertificates","displayName":"TLS certificates that should be distrusted by Microsoft Edge for server authentication","description":"This policy enables defining a list of certificate public keys that should be distrusted by Microsoft Edge for TLS server\nauthentication.\n\nThe policy value is a list of base64-encoded X.509 certificates. Any\ncertificate with a matching SPKI (SubjectPublicKeyInfo) will be distrusted.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cadistrustedcertificates"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication","description":"This policy defines certificates that are not explicitly trusted or distrusted by Microsoft Edge but may be used as hints during certificate path-building.\n\nThe specified certificates will be considered as intermediates during path validation; the server's certificate must still chain to a trusted root to be considered valid.\n\nCertificates must be base64-encoded.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cahintcertificates"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek","displayName":"Specify first day of the week","description":"Set the first day of week in calendar view.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#specify-calendar-first-day-of-week"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_0","displayName":"Sunday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_1","displayName":"Monday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_4","displayName":"Thursday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_5","displayName":"Friday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_6","displayName":"Saturday","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_caplatformintegrationenabled","displayName":"Use user-added TLS certificates from platform trust stores for server authentication","description":"If enabled (or unset), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.\n\nIf disabled, user-added TLS certificates from platform trust stores will not be used in path-building for TLS server authentication.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#caplatformintegrationenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_caplatformintegrationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_caplatformintegrationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_certificatetransparencyenforcementdisabledforcas","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes","description":"Disables enforcement of Certificate Transparency requirements for a list of subjectPublicKeyInfo hashes.\n\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This allows certificates that would otherwise be untrusted because they were not properly publicly disclosed to still be used for Enterprise hosts.\n\nTo disable Certificate Transparency enforcement when this policy is set, one of the following sets of conditions must be met:\n1. The hash is of the server certificate's subjectPublicKeyInfo.\n2. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, that CA certificate is constrained via the X.509v3 nameConstraints extension, one or more directoryName nameConstraints are present in the permittedSubtrees, and the directoryName contains an organizationName attribute.\n3. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, the CA certificate has one or more organizationName attributes in the certificate Subject, and the server's certificate contains the same number of organizationName attributes, in the same order, and with byte-for-byte identical values.\n\nA subjectPublicKeyInfo hash is specified by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\n\nIf you disable this policy or don't configure it, any certificate that's required to be disclosed via Certificate Transparency will be treated as untrusted if it's not disclosed according to the Certificate Transparency policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#certificatetransparencyenforcementdisabledforcas"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_certificatetransparencyenforcementdisabledforlegacycas","displayName":"Disable Certificate Transparency enforcement for a list of legacy certificate authorities (Deprecated)","description":"Disables enforcing Certificate Transparency requirements for a list of legacy certificate authorities (Cas).\n\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This allows certificates that would otherwise be untrusted because they were not properly publicly disclosed, continue to be used for enterprise hosts.\n\nIn order for Certificate Transparency enforcement to be disabled, you must set the hash to a subjectPublicKeyInfo appearing in a CA certificate that is recognized as a legacy certificate authority (CA). A legacy CA is a CA that has been publicly trusted by default by one or more operating systems supported by Microsoft Edge.\n\nYou specify a subjectPublicKeyInfo hash by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\n\nIf you don't configure this policy, any certificate that's required to be disclosed via Certificate Transparency will be treated as untrusted if it isn't disclosed according to the Certificate Transparency policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#certificatetransparencyenforcementdisabledforlegacycas"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_certificatetransparencyenforcementdisabledforurls","displayName":"Disable Certificate Transparency enforcement for specific URLs","description":"Disables enforcing Certificate Transparency requirements for the listed URLs.\n\nThis policy lets you not disclose certificates for the hostnames in the specified URLs via Certificate Transparency. This lets you use certificates that would otherwise be untrusted, because they weren't properly publicly disclosed, but it makes it harder to detect mis-issued certificates for those hosts.\n\nForm your URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322. Because certificates are valid for a given hostname, independent of the scheme, port, or path, only the hostname part of the URL is considered. Wildcard hosts are not supported.\n\nIf you don't configure this policy, any certificate that should be disclosed via Certificate Transparency is treated as untrusted if it's not disclosed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#certificatetransparencyenforcementdisabledforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_channelname","displayName":"Update channel","description":"Specifies the channel to receive updates. The most stable channel is the Current Channel, which is recommended for the majority of your fleet. Users subscribed to the Preview Channel will receive production-quality updates a week before Current Channel users. Users subscribed to the Beta Channel will receive unsupported nightly builds that are designed for testing.","helpText":null,"infoUrls":["https://support.microsoft.com/office/update-office-for-mac-automatically-bfd1e497-c24d-4754-92ab-910a4074d7c1"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_2","displayName":"Current Channel (Deferred)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_3","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_4","displayName":"Current Channel (Monthly)","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_checkfordefinitionsupdate","displayName":"Check for definitions update","description":"Check for definitions update before initiating a scheduled scan","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":[{"id":"com.apple.managedclient.preferences_checkfordefinitionsupdate_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_checkfordefinitionsupdate_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_clearbrowsingdataonexit","displayName":"Clear browsing data when Microsoft Edge closes","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\n\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured \"DefaultCookiesSetting\"\n\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\n\nIf you enable this policy, don't enable the \"AllowDeletingBrowserHistory\" policy, because they both deal with deleting data. If you enable both, this policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"AllowDeletingBrowserHistory\".","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#clearbrowsingdataonexit"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_clearbrowsingdataonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_clearbrowsingdataonexit_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_clearcachedimagesandfilesonexit","displayName":"Clear cached images and files when Microsoft Edge closes","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\n\nIf you enable this policy, cached images and files will be deleted each time Microsoft Edge closes.\n\nIf you disable this policy, users cannot configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\n\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\n\nIf you disable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you configure both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"ClearCachedImagesAndFilesOnExit\".","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#clearcachedimagesandfilesonexit"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_clearcachedimagesandfilesonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_clearcachedimagesandfilesonexit_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_clipboardallowedforurls","displayName":"Allow clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\n\nSetting the policy lets you create a list of URL patterns that specify which sites can use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\n\nLeaving the policy unset means \"DefaultClipboardSetting\" applies for all sites if it's set. If it isn't set, the user's personal setting applies.\n\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#clipboardallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_clipboardblockedforurls","displayName":"Block clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\n\nSetting the policy lets you create a list of URL patterns that specify sites that can't use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\n\nLeaving the policy unset means \"DefaultClipboardSetting\" applies for all sites if it's set. If it isn't set, the user's personal setting applies.\n\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#clipboardblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_cloudblocklevel","displayName":"Cloud Block Level","description":"Determines how aggressive Defender for Endpoint will be in blocking and scanning suspicious files.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#configure-cloud-block-level"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"com.apple.managedclient.preferences_cloudblocklevel_0","displayName":"normal","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_cloudblocklevel_1","displayName":"moderate","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_cloudblocklevel_2","displayName":"high","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_cloudblocklevel_3","displayName":"high_plus","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_cloudblocklevel_4","displayName":"zero_tolerance","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_collectionsservicesandexportsblocklist","displayName":"Block access to a specified list of services and export targets in Collections","description":"List specific services and export targets that users can't access in the Collections feature in Microsoft Edge. This includes displaying additional data from Bing and exporting collections to Microsoft products or external partners.\n\nIf you enable this policy, services and export targets that match the given list are blocked.\n\nIf you don't configure this policy, no restrictions on the acceptable services and export targets are enforced.\n\nPolicy options mapping:\n\n* pinterest_suggestions (pinterest_suggestions) = Pinterest suggestions\n\n* collections_share (collections_share) = Sharing of Collections\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#collectionsservicesandexportsblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_commandlineflagsecuritywarningsenabled","displayName":"Enable security warnings for command-line flags","description":"If disabled, this policy prevents security warnings from appearing when Microsoft Edge is launched with potentially dangerous command-line flags.\n\nIf enabled or unset, security warnings are displayed when these command-line flags are used to launch Microsoft Edge.\n\nFor example, the --disable-gpu-sandbox flag generates this warning: You're using an unsupported command-line flag: --disable-gpu-sandbox. This poses stability and security risks.\n\nOn Windows, this policy is only available on instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro (or Enterprise) instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#commandlineflagsecuritywarningsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_commandlineflagsecuritywarningsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_commandlineflagsecuritywarningsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_componentupdatesenabled","displayName":"Enable component updates in Microsoft Edge","description":"If you enable or don't configure this policy, component updates are enabled in Microsoft Edge.\n\nIf you disable this policy or set it to false, component updates are disabled for all components in Microsoft Edge.\n\nHowever, some components are exempt from this policy. This includes any component that doesn't contain executable code, that doesn't significantly alter the behavior of the browser, or that's critical for security. That is, updates that are deemed \"critical for security\" are still applied even if you disable this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#componentupdatesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_componentupdatesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_componentupdatesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_composeinlineenabled","displayName":"Control access to Microsoft 365 Copilot writing assistance in Microsoft Edge for Business","description":"This policy controls whether users can use writing support features in Microsoft Edge for Business, such as Rewrite, which utilizes Microsoft 365 Copilot Chat. With Rewrite, users can receive help with drafting content, rewriting text, and adjusting style directly in their browser tab. In Edge, users can trigger it when highlighting editable content in their main browser through the right-click context menu.\n\nThis policy applies only to Microsoft Entra accounts and does not apply to Microsoft accounts.\n\nIf you enable this policy, users can use Rewrite in Microsoft Edge when logged in with an Entra account.\n\nIf you disable this policy, users within your tenant will not be able to use Rewrite.\n\nIf you don't configure this policy, the default behavior is as follows:\n\n- Rewrite is available to users\n\n- Users can enable or disable Microsoft 365 Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings.\n\nNote: Rewrite is not available on pages protected by data loss prevention (DLP) policies to help maintain compliance.\n\nLearn more about Microsoft 365 Copilot Chat data, privacy, and security here: https://go.microsoft.com/fwlink/?linkid=2321816","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#composeinlineenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_composeinlineenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_composeinlineenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_compressiondictionarytransportenabled","displayName":"Enable compression dictionary transport support","description":"This feature enables the use of dictionary-specific content encodings in the Accept-Encoding request header (\"sbr\" and \"zst-d\") when dictionaries are available for use.\n\nIf you enable this policy or don't configure it, Microsoft Edge will accept web contents using the compression dictionary transport feature.\n\nIf you disable this policy, Microsoft Edge will turn off the compression dictionary transport feature.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#compressiondictionarytransportenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_compressiondictionarytransportenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_compressiondictionarytransportenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_configuredonottrack","displayName":"Configure Do Not Track","description":"Specify whether to send Do Not Track requests to websites that ask for tracking info. Do Not Track requests let the websites you visit know that you don't want your browsing activity to be tracked. By default, Microsoft Edge doesn't send Do Not Track requests, but users can turn on this feature to send them.\n\nIf you enable this policy, Do Not Track requests are always sent to websites asking for tracking info.\n\nIf you disable this policy, requests are never sent.\n\nIf you don't configure this policy, users can choose whether to send these requests.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#configuredonottrack"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_configuredonottrack_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configuredonottrack_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users","description":"If FriendlyURLs are enabled, Microsoft Edge will compute additional representations of the URL and place them on the clipboard.\n\nThis policy configures what format will be pasted when the user pastes in external applications, or inside Microsoft Edge without the 'Paste as' context menu item.\n\nIf configured, this policy makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu will not be available.\n\n* Not configured = The user will be able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\n\n* 1 = No additional formats will be stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature will be disabled.\n\n* 3 = The user will get a friendly URL whenever they paste into surfaces that accept rich text. The plain URL will still be available for non-rich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\n\n* 4 = (Not currently used)\n\nThe richer formats may not be well-supported in some paste destinations and/or websites. As such, if this policy is to be configured, then the plain URL option is recommended.\n\nPolicy options mapping:\n\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\n\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.\n\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#configurefriendlyurlformat"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat_0","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat_1","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat_2","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_configureonlinetexttospeech","displayName":"Configure Online Text To Speech","description":"Set whether the browser can leverage Online Text to Speech voice fonts, part of Azure Cognitive Services. These voice fonts are higher quality than the pre-installed system voice fonts.\n\nIf you enable or don't configure this policy, web-based applications that use the SpeechSynthesis API can use Online Text to Speech voice fonts.\n\nIf you disable this policy, the voice fonts aren't available.\n\nRead more about this feature here:\nSpeechSynthesis API: https://go.microsoft.com/fwlink/?linkid=2110038\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2110141","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#configureonlinetexttospeech"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_configureonlinetexttospeech_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configureonlinetexttospeech_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_configureshare","displayName":"Configure the Share experience","description":"If you set this policy to 'ShareAllowed' (the default), users will be able to access the Share experience from the Settings and More Menu in Microsoft Edge to share with other apps on the system.\n\nIf you set this policy to 'ShareDisallowed', users won't be able to access the Share experience. If the Share button is on the toolbar, it will also be hidden.\n\nPolicy options mapping:\n\n* ShareAllowed (0) = Allow using the Share experience\n\n* ShareDisallowed (1) = Don't allow using the Share experience\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#configureshare"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_configureshare_0","displayName":"Allow using the Share experience","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configureshare_1","displayName":"Don't allow using the Share experience","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_consumerexperience","displayName":"Control sign-in to consumer version","description":"Specify whether users can sign into the consumer version of Microsoft Defender","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#control-sign-in-to-consumer-version-of-microsoft-defender"],"categoryId":"67cd904c-78e0-4e77-9dd4-c713b21763f3","categoryName":"User interface preferences","options":[{"id":"com.apple.managedclient.preferences_consumerexperience_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_consumerexperience_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_controldefaultstateofallowextensionfromotherstoressettingenabled","displayName":"Configure default state of Allow extensions from other stores setting","description":"This policy allows you to control the default state of the Allow extensions from other stores setting.\nThis policy can't be used to stop installation of extensions from other stores such as Chrome Web Store.\nTo stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098.\n\nWhen enabled, Allow extensions from other stores will be turned on. So, users won't have to turn on the flag manually\nwhile installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting.\nIf the user has already turned on the setting and then turned it off, this setting may not work.\nIf the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it will have no impact on\nuser settings and the setting will remain as it is.\n\nWhen disabled or not configured, the user can manage the Allow extensions from other store setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#controldefaultstateofallowextensionfromotherstoressettingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_controldefaultstateofallowextensionfromotherstoressettingenabled_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_controldefaultstateofallowextensionfromotherstoressettingenabled_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_cookiesallowedforurls","displayName":"Allow cookies on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to set cookies.\n\nIf you don't configure this policy, the global default value from the \"DefaultCookiesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nSee the \"CookiesBlockedForUrls\" and \"CookiesSessionOnlyForUrls\" policies for more information.\n\nNote there cannot be conflicting URL patterns set between these three policies:\n\n- \"CookiesBlockedForUrls\"\n\n- CookiesAllowedForUrls\n\n- \"CookiesSessionOnlyForUrls\"","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cookiesallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_cookiesblockedforurls","displayName":"Block cookies on specific sites","description":"Define a list of sites, based on URL patterns, that can't set cookies.\n\nIf you don't configure this policy, the global default value from the \"DefaultCookiesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nSee the \"CookiesAllowedForUrls\" and \"CookiesSessionOnlyForUrls\" policies for more information.\n\nNote there cannot be conflicting URL patterns set between these three policies:\n\n- CookiesBlockedForUrls\n\n- \"CookiesAllowedForUrls\"\n\n- \"CookiesSessionOnlyForUrls\"","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cookiesblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_cookiessessiononlyforurls","displayName":"Limit cookies from specific websites to the current session","description":"Cookies created by websites that match a URL pattern you define are deleted when the session ends (when the window closes).\n\nCookies created by websites that don't match the pattern are controlled by the \"DefaultCookiesSetting\" policy (if set) or by the user's personal configuration. This is also the default behavior if you don't configure this policy.\n\nIf Microsoft Edge is running in background mode, the session might not close when the last window is closed, meaning the cookies won't be cleared when the window closes. See the \"BackgroundModeEnabled\" policy for information about configuring what happens when Microsoft Edge runs in background mode.\n\nYou can also use the \"CookiesAllowedForUrls\" and \"CookiesBlockedForUrls\" policies to control which websites can create cookies.\n\nNote there cannot be conflicting URL patterns set between these three policies:\n\n- \"CookiesBlockedForUrls\"\n\n- \"CookiesAllowedForUrls\"\n\n- CookiesSessionOnlyForUrls\n\nIf you set the \"RestoreOnStartup\" policy to restore URLs from previous sessions, this policy is ignored, and cookies are stored permanently for those sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cookiessessiononlyforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_copilotpagecontext","displayName":"Control Copilot access to page context for Microsoft Entra ID profiles","description":"This policy controls access to page contents for Copilot in the Microsoft Edge sidebar when users are logged into their MSA Copilot account. This policy applies only to Microsoft Entra ID Microsoft Edge profiles. To summarize pages and interact with text selections, it needs to be able to access the page contents. This policy does not apply to MSA Microsoft Edge profiles. This policy doesn't control access for Copilot with enterprise data protection (EDP). Access for Copilot with enterprise data protection (EDP) is controlled by the \"EdgeEntraCopilotPageContext\" policy.\n\nIf you enable this policy, Copilot will have access to page content when logged in with Entra ID.\n\nIf this policy is not configured, the default behavior for non-EU countries is that access is initially enabled. For EU countries, the default behavior is that access is initially disabled. In both cases, if the policy is not configured, users can enable or disable Copilot's access to page content using the setting toggle in Microsoft Edge.\n\nIf you disable this policy, Copilot will not be able to access page context.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#copilotpagecontext"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_copilotpagecontext_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_copilotpagecontext_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request header support enabled","description":"This policy lets you configure support of CORS non-wildcard request headers.\n\nMicrosoft Edge version 97 introduces support for CORS non-wildcard request headers. When a script makes a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header must be explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. See https://go.microsoft.com/fwlink/?linkid=2180022 for more detail.\n\nIf you enable or don't configure the policy, Microsoft Edge will support the CORS non-wildcard request headers and behave as previously described.\n\nIf you disable this policy, Microsoft Edge will allow the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\n\nThis policy is a temporary workaround for the new CORS non-wildcard request header feature. It's intended to be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#corsnonwildcardrequestheaderssupport"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_corsnonwildcardrequestheaderssupport_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_corsnonwildcardrequestheaderssupport_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_createpasskeysinicloudkeychain","displayName":"Control whether passkey creation will default to iCloud Keychain.","description":"Microsoft Edge may direct\npasskey/WebAuthn creation requests directly to iCloud Keychain on macOS 13.5\nor later. If iCloud Keychain syncing is not enabled yet, this will\nprompt the user to sign in with iCloud, or might prompt them to enable iCloud\nKeychain syncing.\n\nIf this policy is set to \"true\" then iCloud Keychain will be the default\nwhenever the WebAuthn request is compatible with that choice.\n\nIf this policy isn't set then the default behavior depends on factors such as\nwhether iCloud Drive is enabled, or whether the user has recently used or\ncreated a credential in their\nMicrosoft Edge profile.\n\nIf this policy is set to false, iCloud Keychain will not be used by default\nand the previous behavior (of creating the credential in the Microsoft Edge profile) may be used\ninstead. Users will still be able to select iCloud Keychain as an option, and\nmay still see iCloud Keychain credentials when signing in.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#createpasskeysinicloudkeychain"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_createpasskeysinicloudkeychain_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_createpasskeysinicloudkeychain_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_csscustomstatedeprecatedsyntaxenabled","displayName":"Controls whether the deprecated :--foo syntax for CSS custom state is enabled (Deprecated)","description":"The :--foo syntax for the CSS custom state feature is being changed to :state(foo) in Microsoft Edge in order to comply with changes that have been made in Firefox and Safari. This policy lets the deprecated syntax to be used until Stable 133.\n\nThis deprecation might break some Microsoft Edge-only websites that use the deprecated :--foo syntax.\n\nIf you enable this policy, the deprecated syntax will be enabled.\n\nIf you disable this policy or don't set it, the deprecated syntax will be disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#csscustomstatedeprecatedsyntaxenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_csscustomstatedeprecatedsyntaxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_csscustomstatedeprecatedsyntaxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_customhelplink","displayName":"Specify custom help link","description":"Specify a link for the Help menu or the F1 key.\n\nIf you enable this policy, an admin can specify a link for the Help menu or the F1 key.\n\nIf you disable or don't configure this policy, the default link for the Help menu or the F1 key is used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#customhelplink"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_dailyconfiguration","displayName":"Daily and Hourly quick scan configuration","description":"Check for definitions update before initiating a scheduled scan","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_dailyconfiguration_interval","displayName":"Start time","description":"Specify how many hours should elapse before the next hourly quick scan. 0 indicates no hourly quick scan. 1 indicates a scan every hour. 24 indicates a scan once a day.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_dailyconfiguration_timeofday","displayName":"Time of day","description":"Specifies the time of day, as the number of minutes after midnight, to perform a daily quick scan.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_datalossprevention","displayName":"Use Data Loss Prevention","description":"Whether data loss prevention enforcement is enabled on the machine.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/compliance/data-loss-prevention-policies?view=o365-worldwide"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_datalossprevention_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_datalossprevention_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_dataurlinsvguseenabled","displayName":"Data URL support for SVGUseElement","description":"This policy enables Data URL support for SVGUseElement, which will be disabled\nby default starting in Edge stable version 119.\nIf this policy is Enabled, Data URLs will keep working in SVGUseElement.\nIf this policy is Disabled or left not set, Data URLs won't work in SVGUseElement.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#dataurlinsvguseenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_dataurlinsvguseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dataurlinsvguseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_dataurlwhitespacepreservationenabled","displayName":"DataURL Whitespace Preservation for all media types","description":"This policy provides a temporary opt-out for changes to how Edge handles whitepsace in data URLS.\nPreviously, whitespace would be kept only if the top level media type was text or contained the media type string xml.\nNow, whitespace will be preserved in all data URLs, regardless of media type.\n\nIf this policy is left unset or is set to True, the new behavior is enabled.\n\nWhen this policy is set to False, the old behavior is enabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#dataurlwhitespacepreservationenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_dataurlwhitespacepreservationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dataurlwhitespacepreservationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultautomaticdownloadssetting","displayName":"Default automatic downloads setting","description":"Administrators can use this policy to control whether websites can perform multiple downloads successively. Individual site behavior can be managed using the AutomaticDownloadsAllowedForUrls and AutomaticDownloadsBlockedForUrls policies.\n\nDefault behavior:\n\n- A user gesture is required for each additional download.\n\n- Users can modify their browser settings to disable successive downloads.\n\nPolicy options mapping:\n\n* AllowAutomaticDownloads (1) = Allow all websites to perform multiple downloads without requiring a user gesture between each download.\n\n* BlockAutomaticDownloads (2) = Prevent all websites from performing multiple downloads, even after a user gesture.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultautomaticdownloadssetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultautomaticdownloadssetting_0","displayName":"Allow all websites to perform multiple downloads without requiring a user gesture between each download.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultautomaticdownloadssetting_1","displayName":"Prevent all websites from performing multiple downloads, even after a user gesture.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultbrowsersettingenabled","displayName":"Set Microsoft Edge as default browser","description":"Configures the default browser checks in Microsoft Edge and prevents users from changing them.\n\nIf you enable this policy, Microsoft Edge always checks on startup whether it is the default browser and automatically registers itself, if possible.\n\nIf you disable this policy, Microsoft Edge never checks and disables user controls for setting this option.\n\nIf you don't configure this policy, Microsoft Edge lets the user control whether it's the default browser and whether to show user notifications when it isn't.\n\nNote for Windows administrators: This policy only works for PCs running Windows 7. For later versions of Windows, you have to deploy a \"default application associations\" file that makes Microsoft Edge the handler for the https and http protocols (and, optionally, the ftp protocol and file formats such as .html, .htm, .pdf, .svg, .webp). See https://go.microsoft.com/fwlink/?linkid=2094932 for more information.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultbrowsersettingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultbrowsersettingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultbrowsersettingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultclipboardsetting","displayName":"Default clipboard site permission","description":"This policy controls the default value for the clipboard site permission.\n\nSetting the policy to 2 blocks sites from using the clipboard site permission.\n\nSetting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use an API.\n\nThis policy can be overridden for specific URL patterns using the \"ClipboardAllowedForUrls\" and \"ClipboardBlockedForUrls\" policies.\n\nThis policy only affects clipboard operations controlled by the clipboard site permission and doesn't affect sanitized clipboard writes or trusted copy and paste operations.\n\nPolicy options mapping:\n\n* BlockClipboard (2) = Do not allow any site to use the clipboard site permission\n\n* AskClipboard (3) = Allow sites to ask the user to grant the clipboard site permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultclipboardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultclipboardsetting_0","displayName":"Do not allow any site to use the clipboard site permission","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultclipboardsetting_1","displayName":"Allow sites to ask the user to grant the clipboard site permission","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultcookiessetting","displayName":"Configure cookies","description":"Control whether websites can create cookies on the user's device. This policy is all or nothing - you can let all websites create cookies, or no websites create cookies. You can't use this policy to enable cookies from specific websites.\n\nSet the policy to 'SessionOnly' (4) to clear cookies when the session closes. If Microsoft Edge is running in background mode, the session might not close when the last window is closed, meaning the cookies won't be cleared when the window closes. See \"BackgroundModeEnabled\" policy for information about configuring what happens when Microsoft Edge runs in background mode.\n\nIf you don't configure this policy, the default 'AllowCookies' (1) is used, and users can change this setting in Microsoft Edge Settings. (If you don't want users to be able to change this setting, set the policy.)\n\n* 1 = Let all sites create cookies\n\n* 2 = Don't let any site create cookies\n\n* 4 = Keep cookies for the duration of the session","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultcookiessetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultcookiessetting_0","displayName":"Let all sites create cookies","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultcookiessetting_1","displayName":"Don't let any site create cookies","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultcookiessetting_2","displayName":"Keep cookies for the duration of the session","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultemailaddressordomain","displayName":"Default domain name","description":"Specify the domain or full email address of the Microsoft 365 mailbox to be added on first launch (e.g. contoso.com or fred@contoso.com).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#specify-microsoft-365-mailbox-to-be-added-on-first-launch"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":null},{"id":"com.apple.managedclient.preferences_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading","description":"If you set this policy to 3, websites can ask for read access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\n\nIf you don't set this policy, websites can ask for access. Users can change this setting.\n\nPolicy options mapping:\n\n* BlockFileSystemRead (2) = Don't allow any site to request read access to files and directories via the File System API\n\n* AskFileSystemRead (3) = Allow sites to ask the user to grant read access to files and directories via the File System API\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultfilesystemreadguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultfilesystemreadguardsetting_0","displayName":"Don't allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultfilesystemreadguardsetting_1","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing","description":"If you set this policy to 3, websites can ask for write access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\n\nIf you don't set this policy, websites can ask for access. Users can change this setting.\n\nPolicy options mapping:\n\n* BlockFileSystemWrite (2) = Don't allow any site to request write access to files and directories\n\n* AskFileSystemWrite (3) = Allow sites to ask the user to grant write access to files and directories\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultfilesystemwriteguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultfilesystemwriteguardsetting_0","displayName":"Don't allow any site to request write access to files and directories","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultfilesystemwriteguardsetting_1","displayName":"Allow sites to ask the user to grant write access to files and directories","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultgeolocationsetting","displayName":"Default geolocation setting","description":"Set whether websites can track users' physical locations. You can allow tracking by default (1), deny it by default (2), or ask the user each time a website requests their location (3).\n\nIf you don't configure this policy, 'AskGeolocation' policy is used and the user can change it.\n\n* 1 = Allow sites to track users' physical location\n\n* 2 = Don't allow any site to track users' physical location\n\n* 3 = Ask whenever a site wants to track users' physical location","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultgeolocationsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultgeolocationsetting_0","displayName":"Allow sites to track users' physical location","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultgeolocationsetting_1","displayName":"Don't allow any site to track users' physical location","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultgeolocationsetting_2","displayName":"Ask whenever a site wants to track users' physical location","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultimagessetting","displayName":"Default images setting","description":"Set whether websites can display images. You can allow images on all sites (1) or block them on all sites (2).\n\nIf you don't configure this policy, images are allowed by default, and the user can change this setting.\n\n* 1 = Allow all sites to show all images\n\n* 2 = Don't allow any site to show images","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultimagessetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultimagessetting_0","displayName":"Allow all sites to show all images","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultimagessetting_1","displayName":"Don't allow any site to show images","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions","description":"Allows you to set whether users can add exceptions to allow mixed content for specific sites.\n\nThis policy can be overridden for specific URL patterns using the \"InsecureContentAllowedForUrls\" and \"InsecureContentBlockedForUrls\" policies.\n\nIf this policy isn't set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.\n\n* 2 = Do not allow any site to load blockable mixed content\n\n* 3 = Allow users to add exceptions to allow blockable mixed content","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultinsecurecontentsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultinsecurecontentsetting_0","displayName":"Do not allow any site to load mixed content","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultinsecurecontentsetting_1","displayName":"Allow users to add exceptions to allow mixed content","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT","description":"Allows you to set whether Microsoft Edge will run the v8 JavaScript engine with JIT (Just In Time) compiler enabled or not.\n\nDisabling the JavaScript JIT will mean that Microsoft Edge may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Microsoft Edge to render web content in a more secure configuration.\n\nThis policy can be overridden for specific URL patterns using the \"JavaScriptJitAllowedForSites\" and \"JavaScriptJitBlockedForSites\" policies.\n\nIf you don't configure this policy, JavaScript JIT is enabled.\n\nPolicy options mapping:\n\n* AllowJavaScriptJit (1) = Allow any site to run JavaScript JIT\n\n* BlockJavaScriptJit (2) = Do not allow any site to run JavaScript JIT\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultjavascriptjitsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultjavascriptjitsetting_0","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultjavascriptjitsetting_1","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers","description":"Allows you to set whether Microsoft Edge will run the v8 JavaScript engine with more advanced JavaScript optimizations enabled.\n\nDisabling JavaScript optimizations (by setting this policy's value to 2) will mean that Microsoft Edge may render web content more slowly.\n\nThis policy can be overridden for specific URL patterns using the \"JavaScriptOptimizerAllowedForSites\" and \"JavaScriptOptimizerBlockedForSites\" policies.\n\nIf you don't configure this policy, JavaScript optimizations are enabled.\n\nPolicy options mapping:\n\n* AllowJavaScriptOptimizer (1) = Enable advanced JavaScript optimizations on all sites\n\n* BlockJavaScriptOptimizer (2) = Disable advanced JavaScript optimizations on all sites\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultjavascriptoptimizersetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultjavascriptoptimizersetting_0","displayName":"Enable advanced JavaScript optimizations on all sites","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultjavascriptoptimizersetting_1","displayName":"Disable advanced JavaScript optimizations on all sites","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultjavascriptsetting","displayName":"Default JavaScript setting","description":"Set whether websites can run JavaScript. You can allow it for all sites (1) or block it for all sites (2).\n\nIf you don't configure this policy, all sites can run JavaScript by default, and the user can change this setting.\n\n* 1 = Allow all sites to run JavaScript\n\n* 2 = Don't allow any site to run JavaScript","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultjavascriptsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultjavascriptsetting_0","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultjavascriptsetting_1","displayName":"Don't allow any site to run JavaScript","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultnotificationssetting","displayName":"Default notification setting","description":"Set whether websites can display desktop notifications. You can allow them by default (1), deny them by default (2), or have the user be asked each time a website wants to show a notification (3).\n\nIf you don't configure this policy, notifications are allowed by default, and the user can change this setting.\n\n* 1 = Allow sites to show desktop notifications\n\n* 2 = Don't allow any site to show desktop notifications\n\n* 3 = Ask every time a site wants to show desktop notifications","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultnotificationssetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultnotificationssetting_0","displayName":"Allow sites to show desktop notifications","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultnotificationssetting_1","displayName":"Don't allow any site to show desktop notifications","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultnotificationssetting_2","displayName":"Ask every time a site wants to show desktop notifications","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultpluginssetting","displayName":"Default Adobe Flash setting","description":"Determines whether websites that aren't covered by \"PluginsAllowedForUrls\" or \"PluginsBlockedForUrls\" can automatically run the Adobe Flash plug-in. You can select 'BlockPlugins' (2) to block Adobe Flash on all sites, or you can select 'ClickToPlay' (3) to let Adobe Flash run but require the user to click the placeholder to start it. In any case, the \"PluginsAllowedForUrls\" and \"PluginsBlockedForUrls\" policies take precedence over 'DefaultPluginsSetting'.\n\nAutomatic playback is only allowed for domains explicitly listed in the \"PluginsAllowedForUrls\" policy. If you want to enable automatic playback for all sites, consider adding http://* and https://* to this list.\n\nIf you don't configure this policy, the user can change this setting manually.\n\n* 2 = Block the Adobe Flash plug-in\n\n* 3 = Click to play\n\nThe former '1' option set allow-all, but this functionality is now only handled by the \"PluginsAllowedForUrls\" policy. Existing policies using '1' will operate in Click-to-play mode.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultpluginssetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultpluginssetting_0","displayName":"Block the Adobe Flash plugin","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultpluginssetting_1","displayName":"Click to play","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultpopupssetting","displayName":"Default pop-up window setting","description":"Set whether websites can show pop-up windows. You can allow them on all websites (1) or block them on all sites (2).\n\nIf you don't configure this policy, pop-up windows are blocked by default, and users can change this setting.\n\n* 1 = Allow all sites to show pop-ups\n\n* 2 = Don't allow any site to show pop-up windows","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultpopupssetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultpopupssetting_0","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultpopupssetting_1","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultprinterselection","displayName":"Default printer selection rules","description":"Overrides Microsoft Edge default printer selection rules. This policy determines the rules for selecting the default printer in Microsoft Edge, which happens the first time a user tries to print a page.\n\nWhen this policy is set, Microsoft Edge tries to find a printer that matches all of the specified attributes and uses it as default printer. If there are multiple printers that meet the criteria, the first printer that matches is used.\n\nIf you don't configure this policy or no matching printers are found within the timeout, the printer defaults to the built-in PDF printer or no printer, if the PDF printer isn't available.\n\nThe value is parsed as a JSON object, conforming to the following schema: { \"type\": \"object\", \"properties\": { \"idPattern\": { \"description\": \"Regular expression to match printer id.\", \"type\": \"string\" }, \"namePattern\": { \"description\": \"Regular expression to match printer display name.\", \"type\": \"string\" } } }\n\nOmitting a field means all values match; for example, if you don't specify connectivity Print Preview starts discovering all kinds of local printers. Regular expression patterns must follow the JavaScript RegExp syntax and matches are case sensitive.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultprinterselection"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchprovidercontextmenuaccessallowed","displayName":"Allow default search provider context menu search access","description":"Enables the use of a default search provider on the context menu.\n\nIf you set this policy to disabled the search context menu item that relies on your default search provider and sidebar search will not be available.\n\nIf this policy is set to enabled or not set, the context menu item for your default search provider and sidebar search will be available.\n\nThe policy value is only appled when the \"DefaultSearchProviderEnabled\" policy is enabled, and is not applicable otherwise.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidercontextmenuaccessallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultsearchprovidercontextmenuaccessallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultsearchprovidercontextmenuaccessallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultsearchproviderenabled","displayName":"Enable the default search provider","description":"Enables the use of a default search provider.\n\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\n\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured), the user can choose the default provider.\n\nIf you disable this policy, the user can't search from the address bar.\n\nIf you enable or disable this policy, users can't change or override it.\n\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchproviderenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultsearchproviderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultsearchproviderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultsearchproviderencodings","displayName":"Default search provider encodings","description":"Specify the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They are tried in the order provided.\n\nThis policy is optional. If not configured, the default, UTF-8, is used.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchproviderencodings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\n\nThis policy is optional. If you don't configure it, image search isn't available.\n\nSpecify Bing's Image Search URL as:\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\n\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\n\nSee \"DefaultSearchProviderImageURLPostParams\" policy to finish configuring image search.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchproviderimageurl"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it’s replaced with real image thumbnail data. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nSpecify Bing's Image Search URL Post Params as:\n'imageBin={google:imageThumbnailBase64}'.\n\nSpecify Google's Image Search URL Post Params as:\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\n\nIf you don’t set this policy, image search requests are sent using the GET method.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchproviderimageurlpostparams"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchproviderkeyword","displayName":"Default search provider keyword","description":"Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider.\n\nThis policy is optional. If you don't configure it, no keyword activates the search provider.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchproviderkeyword"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchprovidername","displayName":"Default search provider name","description":"Specifies the name of the default search provider.\n\nIf you enable this policy, you set the name of the default search provider.\n\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\n\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidername"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchprovidersearchurl","displayName":"Default search provider search URL","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\n\nSpecify Bing's search URL as:\n\n'{bing:baseURL}search?q={searchTerms}'.\n\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\n\nThis policy is required when you enable the \"DefaultSearchProviderEnabled\" policy; if you don't enable the latter policy, this policy is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidersearchurl"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions","description":"Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user has entered so far.\n\nThis policy is optional. If you don't configure it, users won't see search suggestions; they will see suggestions from their browsing history and favorites.\n\nBing's suggest URL can be specified as:\n\n'{bing:baseURL}qbox?query={searchTerms}'.\n\nGoogle's suggest URL can be specified as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidersuggesturl"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsensorssetting","displayName":"Default sensors setting","description":"Set whether websites can access and use sensors such as motion and light sensors. You can completely block or allow websites to get access to sensors.\n\nSetting the policy to 1 lets websites access and use sensors. Setting the policy to 2 denies acess to sensors.\n\nYou can override this policy for specific URL patterns by using the \"SensorsAllowedForUrls\" and \"SensorsBlockedForUrls\" policies.\n\nIf you don't configure this policy, websites can access and use sensors, and users can change this setting. This is the global default for \"SensorsAllowedForUrls\" and \"SensorsBlockedForUrls\".\n\nPolicy options mapping:\n\n* AllowSensors (1) = Allow sites to access sensors\n\n* BlockSensors (2) = Do not allow any site to access sensors\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsensorssetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultsensorssetting_0","displayName":"Allow sites to access sensors","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultsensorssetting_1","displayName":"Do not allow any site to access sensors","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultserialguardsetting","displayName":"Control use of the Serial API","description":"Set whether websites can access serial ports. You can completely block access or ask the user each time a website wants to get access to a serial port.\n\nSetting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\n\nYou can override this policy for specific URL patterns by using the \"SerialAskForUrls\" and \"SerialBlockedForUrls\" policies.\n\nIf you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting.\n\nPolicy options mapping:\n\n* BlockSerial (2) = Do not allow any site to request access to serial ports via the Serial API\n\n* AskSerial (3) = Allow sites to ask for user permission to access a serial port\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultserialguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultserialguardsetting_0","displayName":"Do not allow any site to request access to serial ports via the Serial API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultserialguardsetting_1","displayName":"Allow sites to ask for user permission to access a serial port","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting","displayName":"Set the default \"share additional operating system region\" setting","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\n\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting will be shared with the web through the default JavaScript locale. If shared, websites will be able to query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\n\nIf you set this policy to \"Limited\", the OS Regional format will only be shared if its language part matches the Microsoft Edge display language.\n\nIf you set this policy to \"Always\", the OS Regional format will always be shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months can be displayed in one language while the surrounding text is displayed in another language.\n\nIf you set this policy to \"Never\", the OS Regional format will never be shared.\n\nExample 1: In this example the OS Regional format is set to \"en-GB\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Limited\", or \"Always\".\n\nExample 2: In this example the OS Regional format is set to \"es-MX\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Always\" but will not if the policy is set to \"Limited\".\n\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282\n\nPolicy options mapping:\n\n* Limited (0) = Limited\n\n* Always (1) = Always share the OS Regional format\n\n* Never (2) = Never share the OS Regional format\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultshareadditionalosregionsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting_0","displayName":"Limited","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting_1","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting_2","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultstolocalopensave","displayName":"Default to local files for open/save","description":"Prefer the local file system when accessing the Open and Save dialogs.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-office"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_defaultstolocalopensave_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultstolocalopensave_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultthirdpartystoragepartitioningsetting","displayName":"Default setting for third-party storage partitioning (deprecated)","description":"This policy controls whether third-party storage partitioning is allowed by default.\n\nIf this policy is set to 1 - AllowPartitioning, or unset, third-party storage partitioning will be allowed by default. This default may be overridden for specific top-level origins by other means.\n\nIf this policy is set to 2 - BlockPartitioning, third-party storage partitioning will be disabled for all contexts.\n\nUse ThirdPartyStoragePartitioningBlockedForOrigins to disable third-party storage partitioning for specific top-level origins.\n\nThis feature will be removed starting in Microsoft Edge version 145. To ensure compatibility, use the requestStorageAccess method instead. For more information, see https://developer.mozilla.org/en-US/docs/Web/API/Document/requestStorageAccess.\n\nPolicy options mapping:\n\n* AllowPartitioning (1) = Allow third-party storage partitioning by default.\n\n* BlockPartitioning (2) = Disable third-party storage partitioning.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultthirdpartystoragepartitioningsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultthirdpartystoragepartitioningsetting_0","displayName":"Allow third-party storage partitioning by default.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultthirdpartystoragepartitioningsetting_1","displayName":"Disable third-party storage partitioning.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultweatherlocation","displayName":"Default weather location","description":"Sets the default weather location in the Calendar view. Enter the city and state or country (e.g. Redmond, WA or Paris, France)","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#specify-default-weather-location"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":null},{"id":"com.apple.managedclient.preferences_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API","description":"Control whether websites can access nearby Bluetooth devices. You can completely block access or require the site to ask the user each time it wants to access a Bluetooth device.\n\nIf you don't configure this policy, the default value (3, meaning users are asked each time) is used and users can change it.\n\n* 2 = Don't allow any site to request access to Bluetooth devices by using the Web Bluetooth API\n\n* 3 = Allow sites to ask the user to grant access to a nearby Bluetooth device","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultwebbluetoothguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultwebbluetoothguardsetting_0","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultwebbluetoothguardsetting_1","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultwebhidguardsetting","displayName":"Control use of the WebHID API","description":"Setting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices.\n\nLeaving it unset lets websites ask for access, but users can change this setting.\n\nThis policy can be overridden for specific url patterns using the \"WebHidAskForUrls\" and \"WebHidBlockedForUrls\" policies.\n\nPolicy options mapping:\n\n* BlockWebHid (2) = Do not allow any site to request access to HID devices via the WebHID API\n\n* AskWebHid (3) = Allow sites to ask the user to grant access to a HID device\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultwebhidguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultwebhidguardsetting_0","displayName":"Do not allow any site to request access to HID devices via the WebHID API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultwebhidguardsetting_1","displayName":"Allow sites to ask the user to grant access to a HID device","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API","description":"Set whether websites can access connected USB devices. You can completely block access or ask the user each time a website wants to get access to connected USB devices.\n\nYou can override this policy for specific URL patterns by using the \"WebUsbAskForUrls\" and \"WebUsbBlockedForUrls\" policies.\n\nIf you don't configure this policy, sites can ask users whether they can access the connected USB devices (3) by default, and users can change this setting.\n\n* 2 = Don't allow any site to request access to USB devices via the WebUSB API\n\n* 3 = Allow sites to ask the user to grant access to a connected USB device","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultwebusbguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultwebusbguardsetting_0","displayName":"Do not allow any site to request access to USB devices via the WebUSB API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultwebusbguardsetting_1","displayName":"Allow sites to ask the user to grant access to a connected USB device","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting","description":"Setting the policy to \"BlockWindowManagement\" (value 2) automatically denies the window management permission to sites by default. This limits the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\n\nSetting the policy to \"AskWindowManagement\" (value 3) by default prompts the user when the window management permission is requested. If users allow the permission, it extends the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\n\nNot configuring the policy means the \"AskWindowManagement\" policy applies, but users can change this setting.\n\nPolicy options mapping:\n\n* BlockWindowManagement (2) = Denies the Window Management permission on all sites by default\n\n* AskWindowManagement (3) = Ask every time a site wants obtain the Window Management permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultwindowmanagementsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultwindowmanagementsetting_0","displayName":"Denies the Window Management permission on all sites by default","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultwindowmanagementsetting_1","displayName":"Ask every time a site wants obtain the Window Management permission","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_definitionupdatedue","displayName":"Security intelligence update due (in days)","description":"Determines the number of days after which the last installed security intelligence updates are considered outdated.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-preferences#duration-for-security-intelligence-updates-due-in-days"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":null},{"id":"com.apple.managedclient.preferences_definitionupdatesinterval","displayName":"Security intelligence update interval (in seconds)","description":"Specifies the time interval (in seconds) after which security intelligence updates will be checked.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-preferences#security-intelligence-update-interval-in-seconds"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":null},{"id":"com.apple.managedclient.preferences_deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own.\n\nIf fixing them is possible, it usually requires complex user actions.\n\nEnabling this policy or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched.\n\nDisabling this policy means users will have their password manager data untouched, but will experience a broken password manager functionality.\n\nIf the policy is set, users can't override it in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#deletingundecryptablepasswordsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_deletingundecryptablepasswordsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_deletingundecryptablepasswordsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_developertoolsavailability","displayName":"Control where developer tools can be used","description":"Control where developer tools can be used.\n\nIf you set this policy to 'DeveloperToolsDisallowedForForceInstalledExtensions' (0, the default), users can access the developer tools and the JavaScript console in general, but not in the context of extensions installed by enterprise policy.\n\nIf you set this policy to 'DeveloperToolsAllowed' (1), users can access the developer tools and the JavaScript console in all contexts, including extensions installed by enterprise policy.\n\nIf you set this policy to 'DeveloperToolsDisallowed' (2), users can't access the developer tools or inspect website elements. Keyboard shortcuts and menu or context menu entries that open the developer tools or the JavaScript Console are disabled.\n\n* 0 = Block the developer tools on extensions installed by enterprise policy, allow in other contexts\n\n* 1 = Allow using the developer tools\n\n* 2 = Don't allow using the developer tools","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#developertoolsavailability"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_developertoolsavailability_0","displayName":"Block the developer tools on extensions installed by enterprise policy, allow in other contexts","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_developertoolsavailability_1","displayName":"Allow using the developer tools","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_developertoolsavailability_2","displayName":"Don't allow using the developer tools","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage","description":"This policy controls sending required and optional diagnostic data about browser usage to Microsoft.\n\nRequired diagnostic data is collected keep Microsoft Edge secure, up to date and performing as expected.\n\nOptional diagnostic data includes data about how you use the browser, websites you visit and crash reports to Microsoft for product and service improvement.\n\nThis policy is not supported on Windows 10 devices. To control this data collection on Windows 10, IT admins must use the Windows diagnostic data group policy. This policy will either be 'Allow Telemetry' or 'Allow Diagnostic Data', depending on the version of Windows. Learn more about Windows 10 diagnostic data collection: https://go.microsoft.com/fwlink/?linkid=2099569\n\nUse one of the following settings to configure this policy:\n\n'Off' turns off required and optional diagnostic data collection. This option is not recommended.\n\n'RequiredData' sends required diagnostic data but turns off optional diagnostic data collection. Microsoft Edge will send required diagnostic data to keep Microsoft Edge secure, up to date and performing as expected.\n\n'OptionalData' sends optional diagnostic data includes data about browser usage, websites that are visited, crash reports sent to Microsoft for product and service improvement.\n\nOn Windows 7/macOS, this policy controls sending required and optional data to Microsoft.\n\nIf you don't configure this policy or disable it, Microsoft Edge will default to the user's preference.\n\nPolicy options mapping:\n\n* Off (0) = Off (Not recommended)\n\n* RequiredData (1) = Required data\n\n* OptionalData (2) = Optional data\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#diagnosticdata"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_diagnosticdata_0","displayName":"Off (Not recommended)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_diagnosticdata_1","displayName":"Required data","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_diagnosticdata_2","displayName":"Optional data","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_diagnosticdatatypepreference","displayName":"Diagnostic data level","description":"Controls the amount of telemetry data sent by apps.","helpText":null,"infoUrls":["https://aka.ms/macdiagpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_diagnosticdatatypepreference_0","displayName":"Required data only","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_diagnosticdatatypepreference_1","displayName":"Required and Optional data","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_diagnosticdatatypepreference_2","displayName":"Do not send data","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_diagnosticlevel","displayName":"Diagnostic collection level","description":"Diagnostic data is used to keep Microsoft Defender ATP secure and up-to-date, detect, diagnose and fix problems, and also make product improvements. This setting determines the level of diagnostics sent by the product to Microsoft.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#diagnostic-collection-level"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"com.apple.managedclient.preferences_diagnosticlevel_0","displayName":"optional","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_diagnosticlevel_1","displayName":"required","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disable3dapis","displayName":"Disable support for 3D graphics APIs","description":"Prevent web pages from accessing the graphics processing unit (GPU). Specifically, web pages can't access the WebGL API and plug-ins can't use the Pepper 3D API.\n\nIf you don't configure or disable this policy, it potentially allows web pages to use the WebGL API and plug-ins to use the Pepper 3D API. Microsoft Edge might, by default, still require command line arguments to be passed in order to use these APIs.\n\nIf \"HardwareAccelerationModeEnabled\" policy is set to false, the setting for 'Disable3DAPIs' policy is ignored - it's the equivalent of setting 'Disable3DAPIs' policy to true.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#disable3dapis"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_disable3dapis_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disable3dapis_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableauthnegotiatecnamelookup","displayName":"Disable CNAME lookup when negotiating Kerberos authentication","description":"Determines whether the generated Kerberos SPN is based on the canonical DNS name (CNAME) or on the original name entered.\n\nIf you enable this policy, CNAME lookup is skipped and the server name (as entered) is used.\n\nIf you disable this policy or don't configure it, the canonical name of the server is used. This is determined through CNAME lookup.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#disableauthnegotiatecnamelookup"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_disableauthnegotiatecnamelookup_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableauthnegotiatecnamelookup_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableautoconfig","displayName":"Disable automatic sign in","description":"If you set this value to true the sync app is prevented from automatically signing in with an existing Azure AD credential that is made available to Microsoft applications.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#disableautoconfig"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_disableautoconfig_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableautoconfig_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablecloudfonts","displayName":"Disable cloud fonts","description":"Prevent users from selecting and downloading cloud-based fonts.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-office"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_disablecloudfonts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablecloudfonts_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablednsovertcpparsing","displayName":"Disable DNS over TCP parsing","description":"Disables parsing of DNS over TCP","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablednsovertcpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablednsovertcpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablednsparsing","displayName":"Disable DNS parsing","description":"Disables parsing of DNS traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablednsparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablednsparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disabledonotforward","displayName":"Disable 'Do Not Forward' options","description":"Prevent users from applying the Do Not Forward option to emails when using Microsoft 365 Message Encryption.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-do-not-forward"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disabledonotforward_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disabledonotforward_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableencryptonly","displayName":"Disable Microsoft 365 encryption options","description":"Prevent users from applying the Encrypt-Only option to emails when using Microsoft 365 Message Encryption.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-encrypt-only"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disableencryptonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableencryptonly_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableexport","displayName":"Disable export to OLM files","description":"Prevent users exporting data to the local file system.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-export"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disableexport_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableexport_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableftpparsing","displayName":"Disable FTP parsing","description":"Disables parsing of FTP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disableftpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableftpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablehttpparsing","displayName":"Disable HTTP parsing","description":"Disables parsing of HTTP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablehttpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablehttpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablehydrationtoast","displayName":"Disable download toasts","description":"Prevents toasts from appearing when applications cause file contents to be downloaded.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#disablehydrationtoast"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_disablehydrationtoast_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablehydrationtoast_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableicmpparsing","displayName":"Disable ICMP parsing","description":"Disables parsing of ICMP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disableicmpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableicmpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableimport","displayName":"Disable import from OLM and PST files","description":"Prevent users importing data from the local file system.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-import"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disableimport_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableimport_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableinboundconnectionfiltering","displayName":"Disable inbound connection filtering","description":"Disables filtering of inbound connections","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disableinboundconnectionfiltering_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableinboundconnectionfiltering_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableinsidercheckbox","displayName":"Disable Office Insider membership","description":"Prevent users from changing to an Office Insider channel and obtaining Preview or Beta updates. The default value is false.","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_disableinsidercheckbox_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableinsidercheckbox_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablepersonalsync","displayName":"Disable personal accounts","description":"Blocks users from signing in and syncing files in personal OneDrive accounts. If this key is set after a user has set up sync with a personal account, the user will be signed out.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#disablepersonalsync"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_disablepersonalsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablepersonalsync_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablerdpparsing","displayName":"Disable RDP parsing","description":"Disables parsing of RDP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablerdpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablerdpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablerespondtomeetingwithoutresponse","displayName":"Disable 'Do not send response'","description":"Prevent users from selecting 'Do not send response' when replying to a meeting request.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-outlook#disable-do-not-send-a-response"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disablerespondtomeetingwithoutresponse_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablerespondtomeetingwithoutresponse_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablescreenshots","displayName":"Disable taking screenshots","description":"Controls if users can take screenshots of the browser page.\n\nIf enabled, user can't take screenshots by using keyboard shortcuts or extension APIs.\n\nIf disabled or don't configure this policy, users can take screenshots.\n\nPlease note this policy controls screenshots taken from within the browser itself. Even if you enable this policy, users might still be able to take screenshots using some method outside of the browser (like using an operating system feature or another application).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#disablescreenshots"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_disablescreenshots_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablescreenshots_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablesignatures","displayName":"Disable email signatures","description":"Prevent users from adding, removing, and editing signatures","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-signatures"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disablesignatures_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablesignatures_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableskypemeeting","displayName":"Disable Skype for Business meeting support","description":"Prevent users from adding Skype for Business to meeting invites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-skype-for-business-online-meetings"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disableskypemeeting_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableskypemeeting_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablesmimecompose","displayName":"Disable S/MIME","description":"Prevent users from applying S/MIME option to email messages.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-smime"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disablesmimecompose_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablesmimecompose_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablesmtpparsing","displayName":"Disable SMTP parsing","description":"Disables parsing of SMTP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablesmtpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablesmtpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablesshparsing","displayName":"Disable SSH parsing","description":"Disables parsing of SSH traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablesshparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablesshparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableteamsmeeting","displayName":"Disable Microsoft Teams meeting support","description":"Prevent users from adding Teams to meeting invites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-teams-online-meetings"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disableteamsmeeting_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableteamsmeeting_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disabletlsparsing","displayName":"Disable TLS parsing","description":"Disables parsing of TLS traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disabletlsparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disabletlsparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disabletutorial","displayName":"Disable tutorial","description":"This setting prevents the tutorial from being shown to users after they set up OneDrive.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#disabletutorial"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_disabletutorial_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disabletutorial_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablevisualbasicexternaldylibs","displayName":"Prevent Visual Basic macros from using external dynamic libraries","description":"Recommended: true, unless third-party add-ins and extensions are being used.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_disablevisualbasicexternaldylibs_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablevisualbasicexternaldylibs_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablevisualbasicmacscript","displayName":"Prevent Visual Basic macros from using legacy MacScript","description":"Recommended: true.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_disablevisualbasicmacscript_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablevisualbasicmacscript_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablevisualbasictobindtopopen","displayName":"Prevent Visual Basic macros from using pipes to communicate","description":"Recommended: true, unless third-party add-ins and extensions are being used.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_disablevisualbasictobindtopopen_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablevisualbasictobindtopopen_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disallowedthreatactions","displayName":"Disallowed threat actions","description":"Restricts the actions that the local user of a device can take when threats are detected. The actions included in this list are not displayed in the user interface.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#disallowed-threat-actions"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_diskcachedir","displayName":"Set disk cache directory","description":"Configures the directory to use to store cached files.\n\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified the '--disk-cache-dir' flag. To avoid data loss or other unexpected errors, don't configure this policy to a volume's root directory or to a directory used for other purposes, because Microsoft Edge manages its contents.\n\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables you can use when specifying directories and paths.\n\nIf you don't configure this policy, the default cache directory is used, and users can override that default with the '--disk-cache-dir' command line flag.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#diskcachedir"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_diskcachesize","displayName":"Set disk cache size, in bytes","description":"Configures the size of the cache, in bytes, used to store files on the disk.\n\nIf you enable this policy, Microsoft Edge uses the provided cache size regardless of whether the user has specified the '--disk-cache-size' flag. The value specified in this policy isn't a hard boundary but rather a suggestion to the caching system; any value below a few megabytes is too small and will be rounded up to a reasonable minimum.\n\nIf you set the value of this policy to 0, the default cache size is used, and users can't change it.\n\nIf you don't configure this policy, the default size is used, but users can override it with the '--disk-cache-size' flag.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#diskcachesize"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_dnsinterceptionchecksenabled","displayName":"DNS interception checks enabled","description":"This policy configures a local switch that can be used to disable DNS interception checks. These checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\n\nThis detection might not be necessary in an enterprise environment where the network configuration is known. It can be disabled to avoid additional DNS and HTTP traffic on start-up and each DNS configuration change.\n\nIf you enable or don’t set this policy, the DNS interception checks are performed.\n\nIf you disable this policy, DNS interception checks aren’t performed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#dnsinterceptionchecksenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_dnsinterceptionchecksenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dnsinterceptionchecksenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode","displayName":"Control the mode of DNS-over-HTTPS","description":"Control the mode of the DNS-over-HTTPS resolver. Note that this policy will only set the default mode for each query. The mode can be overridden for special types of queries such as requests to resolve a DNS-over-HTTPS server hostname.\n\nThe \"off\" mode will disable DNS-over-HTTPS.\n\nThe \"automatic\" mode will send DNS-over-HTTPS queries first if a DNS-over-HTTPS server is available and may fallback to sending insecure queries on error.\n\nThe \"secure\" mode will only send DNS-over-HTTPS queries and will fail to resolve on error.\n\nIf you don't configure this policy, the browser might send DNS-over-HTTPS requests to a resolver associated with the user's configured system resolver.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#dnsoverhttpsmode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode_0","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode_1","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode_2","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver","description":"The URI template of the desired DNS-over-HTTPS resolver. To specify multiple DNS-over-HTTPS resolvers, separate the corresponding URI templates with spaces.\n\nIf you set \"DnsOverHttpsMode\" to \"secure\" then this policy must be set and cannot be empty.\n\nIf you set \"DnsOverHttpsMode\" to \"automatic\" and this policy is set then the URI templates specified will be used. If you don't set this policy, then hardcoded mappings will be used to attempt to upgrade the user's current DNS resolver to a DoH resolver operated by the same provider.\n\nIf the URI template contains a dns variable, requests to the resolver will use GET; otherwise requests will use POST.\n\nIncorrectly formatted templates will be ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#dnsoverhttpstemplates"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_doubleclickclosetabenabled","displayName":"Double Click feature in Microsoft Edge enabled (only available in China)","description":"This policy lets you configure the double click feature in Microsoft Edge.\n\nDouble Click lets users close a tab by double clicking the left mouse button.\n\nIf you enable or don't configure this policy, you can use the double click feature to close a tab on Microsoft Edge to start using this feature.\n\nIf you disable this policy, you can't use the double click feature in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#doubleclickclosetabenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_doubleclickclosetabenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_doubleclickclosetabenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_downloadbandwidthlimited","displayName":"Set maximum download throughput","description":"Sets the maximum download throughput rate in kilobytes (KB)/sec for computers running the OneDrive sync app. The minimum rate is 50 KB/sec and the maximum rate is 100,000 KB/sec.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#downloadbandwidthlimited"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_downloaddirectory","displayName":"Set download directory","description":"Configures the directory to use when downloading files.\n\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified one or chosen to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\n\nIf you disable or don't configure this policy, the default download directory is used, and the user can change it.\n\nIf you set an invalid path, Microsoft Edge will default to the user's default download directory.\n\nIf the folder specified by the path doesn't exist, the download will trigger a prompt that asks the user where they want to save their download.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#downloaddirectory"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_downloadrestrictions","displayName":"Allow download restrictions","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\n\nSet 'Block dangerous downloads' (1) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings.\n\nSet 'Block potentially dangerous downloads' (2) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous downloads.\n\nSet 'Block all downloads' (3) to block all downloads.\n\nIf you don't configure this policy or set the 'No special restrictions' (0) option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\n\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\n\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\n\n* 0 = No special restrictions\n\n* 1 = Block dangerous downloads\n\n* 2 = Block potentially dangerous downloads\n\n* 3 = Block all downloads","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#downloadrestrictions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_downloadrestrictions_1","displayName":"Block dangerous downloads","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_downloadrestrictions_2","displayName":"Block potentially dangerous downloads","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_downloadrestrictions_4","displayName":"Block malicious downloads","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_earlypreview","displayName":"Enable / disable early preview","description":"Whether EDR early preview features are enabled or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-early-preview"],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":[{"id":"com.apple.managedclient.preferences_earlypreview_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_earlypreview_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeassetdeliveryserviceenabled","displayName":"Allow features to download assets from the Asset Delivery Service","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\nThese assets can be config files or Machine Learning models that power the features that use this service.\n\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\n\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeassetdeliveryserviceenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeassetdeliveryserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeassetdeliveryserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeautofillmlenabled","displayName":"Machine learning powered autofill suggestions","description":"Allows ML technology to predict and fill in forms and text fields for better browsing. Your personal data is secure and will not be used elsewhere.\n\nIf you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data.\n\nIf you disable this policy, machine learning powered autofill suggestions will not be shown, and autofill will no longer use cloud-based machine learning models to enhance form filling with smarter, context aware suggestions. Instead, autofill will rely on basic form data without the benefits of machine learning.\n\nThis policy will be disabled if you disable \"AutofillAddressEnabled\"..","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeautofillmlenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeautofillmlenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeautofillmlenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgecollectionsenabled","displayName":"Enable the Collections feature","description":"Lets you allow users to access the Collections feature, where they can collect, organize, share, and export content more efficiently and with Office integration.\n\nIf you enable or don't configure this policy, users can access and use the Collections feature in Microsoft Edge.\n\nIf you disable this policy, users can't access and use Collections in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgecollectionsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgecollectionsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgecollectionsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgedisabledialprotocolforcastdiscovery","displayName":"Disable DIAL protocol for cast device discovery","description":"Enable this policy to disable the DIAL (Discovery And Launch) protocol for cast device discovery. (If EnableMediaRouter is disabled, this policy will have no effect).\n\nEnable this policy to disable DIAL protocol.\n\nBy default, Cast device discovery will use DIAL protocol.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgedisabledialprotocolforcastdiscovery"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgedisabledialprotocolforcastdiscovery_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgedisabledialprotocolforcastdiscovery_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeedropenabled","displayName":"Enable Drop feature in Microsoft Edge","description":"This policy lets you configure the Drop feature in Microsoft Edge.\n\nDrop lets users send messages or files to themselves.\n\nIf you enable or don't configure this policy, you can use the Drop feature in Microsoft Edge.\n\nIf you disable this policy, you can't use the Drop feature in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeedropenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeedropenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeedropenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeentracopilotpagecontext","displayName":"Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane","description":"This policy controls whether Copilot in the Microsoft Edge sidepane can access Microsoft Edge page content. This includes page summarization and similar contextual queries sent to Copilot.\n\nThis policy only applies to users who are signed in to Microsoft Edge with their Entra account and are using Copilot in the sidepane. This policy applies to all Copilot products in the Microsoft Edge sidepane - namely, Microsoft 365 Copilot Business Chat and Microsoft Copilot with enterprise data protection (EDP).\n\nIf you enable this policy, Copilot will be able to access Microsoft Edge page content when users ask a contextual query to Copilot in the Microsoft Edge sidepane.\n\nIf you disable this policy, Copilot will not be able to access Microsoft Edge page content.\n\nIf you don't configure this policy, the default behavior is as follows:\n\n- For non-EU countries, access is enabled by default.\n\n- For EU countries, access is disabled by default.\n\n- In both cases, if the policy is not configured, users can enable or disable Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings.\n\nExceptions to the preceding behavior include when a page is protected using data loss prevention (DLP) measures. In that case, Copilot will not be able to access Microsoft Edge page content even when this policy is enabled. This behavior is to ensure the integrity of DLP.\n\nLearn more about Copilot's data usage and consent at https://go.microsoft.com/fwlink/?linkid=2288056","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeentracopilotpagecontext"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeentracopilotpagecontext_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeentracopilotpagecontext_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgehistoryaisearchenabled","displayName":"Control access to AI-enhanced search in History","description":"This policy controls whether users can use AI-enhanced search in their browsing history in Microsoft Edge.\n\nWhen enabled or not configured, users can search using synonyms, natural language phrases, and minor spelling errors to find previously visited pages.\n\nWhen disabled, users can only perform exact match (verbatim) searches in their history.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgehistoryaisearchenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgehistoryaisearchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgehistoryaisearchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgemanagementextensionsfeedbackenabled","displayName":"Microsoft Edge management extensions feedback enabled","description":"This setting controls whether Microsoft Edge sends data about blocked extensions to the Microsoft Edge management service.\n\nThe 'EdgeManagementEnabled' policy must also be enabled for this setting to take effect.\n\nIf you enable this policy, Microsoft Edge will send data to the Microsoft Edge service when a user tries to install a blocked extension.\n\nIf you disable or don't configure this policy, Microsoft Edge won't send any data to the Microsoft Edge service about blocked extensions.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgemanagementextensionsfeedbackenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgemanagementextensionsfeedbackenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgemanagementextensionsfeedbackenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgemanagementpolicyoverridesplatformpolicy","displayName":"Microsoft Edge management service policy overrides platform policy.","description":"If you enable this policy, the cloud-based Microsoft Edge management service policy takes precedence if it conflicts with platform policy.\n\nIf you disable or don't configure this policy, platform policy takes precedence if it conflicts with the cloud-based Microsoft Edge management service policy.\n\nThis mandatory policy affects machine scope cloud-based Microsoft Edge management policies.\n\nMachine policies apply to all edge browser instances regardless of the user who is logged in.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgemanagementpolicyoverridesplatformpolicy"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgemanagementpolicyoverridesplatformpolicy_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgemanagementpolicyoverridesplatformpolicy_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgemanagementuserpolicyoverridescloudmachinepolicy","displayName":"Allow cloud-based Microsoft Edge management service user policies to override local user policies.","description":"If you enable this policy, cloud-based Microsoft Edge management service user policies takes precedence if it conflicts with local user policy.\n\nIf you disable or don't configure this policy, Microsoft Edge management service user policies will take precedence.\n\nThe policy can be combined with \"EdgeManagementPolicyOverridesPlatformPolicy\". If both policies are enabled, all cloud-based Microsoft Edge management service policies will take precedence over conflicting local service policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgemanagementuserpolicyoverridescloudmachinepolicy"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgemanagementuserpolicyoverridescloudmachinepolicy_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgemanagementuserpolicyoverridescloudmachinepolicy_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeopenexternallinkswithappspecifiedprofile","displayName":"Prioritize App specified profile to open external links","description":"This policy controls whether the profile specified by an app (such as Microsoft Teams or Outlook) is given priority when opening external links, instead of the profile selected in the Default profile for external links setting.\n\nPolicy behavior:\n1. Enabled or not configured: The app-specified profile is prioritized for opening external links. This behavior overrides the profile selected in settings, and the behavior defined by the EdgeDefaultProfileEnabled and EdgeOpenExternalLinksWithPrimaryWorkProfileEnabled policies. If the app doesn't specify a profile, this policy has no effect.\n2. Disabled: The profile selected in settings—along with the EdgeDefaultProfileEnabled and EdgeOpenExternalLinksWithPrimaryWorkProfileEnabled policies—will be used to determine which profile opens external links.\n\nNOTE:\nThis policy doesn't override user-defined preferences set through Automatic profile switching, including the Custom site switch setting located within it. If a user has configured specific sites to open in designated profiles, those preferences take precedence.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeopenexternallinkswithappspecifiedprofile"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeopenexternallinkswithappspecifiedprofile_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeopenexternallinkswithappspecifiedprofile_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeopenexternallinkswithprimaryworkprofileenabled","displayName":"Use Primary Work Profile as default to open external links","description":"This policy controls whether Microsoft Edge uses the Primary Work Profile as the default profile when opening external links.\n1. On Windows, the Primary Work Profile refers to the profile signed in with the Entra ID account used to enroll the device.\n2. On macOS and Linux, the Primary Work Profile is the only profile signed in with an Entra ID account. If multiple profiles are signed in with Entra ID accounts, the Primary Work Profile setting doesn't apply.\n\nPolicy behavior:\n1. If enabled or not configured, Microsoft Edge uses the Primary Work Profile as the default for opening external links.\n2. If disabled, the last used profile becomes the default for opening external links.\n\nNote: This policy doesn't override the following scenarios:\n1. If the EdgeDefaultProfileEnabled policy is set, it takes precedence over this policy.\n2. External links opened from Outlook or Microsoft Teams may be configured to launch in a specific profile, which can override the Primary Work Profile setting.\n3. If the user sets a preference for \"Default profile for external links\" in Profile preferences, that setting takes effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeopenexternallinkswithprimaryworkprofileenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeopenexternallinkswithprimaryworkprofileenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeopenexternallinkswithprimaryworkprofileenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeshoppingassistantenabled","displayName":"Shopping in Microsoft Edge Enabled","description":"This policy lets users compare the prices of a product they are looking at, get coupons from the website they're on, or auto-apply coupons during checkout.\n\nIf you enable or don't configure this policy, shopping features such as price comparison and coupons will be automatically applied for retail domains. Coupons for the current retailer and prices from other retailers will be fetched from a server.\n\nIf you disable this policy shopping features such as price comparison and coupons will not be automatically found for retail domains.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeshoppingassistantenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeshoppingassistantenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeshoppingassistantenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgesidebarappurlhostallowlist","displayName":"Allow specific apps to be opened in Microsoft Edge sidebar","description":"Define a list of sites, based on URL patterns, that are not subject to the \"EdgeSidebarAppUrlHostBlockList\".\n\nIf you don't configure this policy, a user can open any app in sidebar except the urls listed in \"EdgeSidebarAppUrlHostBlockList\".\n\nIf you configure this policy, the apps listed in the allow list could be opened in sidebar even if they are listed in the block list.\n\nBy default, all apps are allowed. However, if you prohibited apps by policy, you can use the list of allowed apps to change that policy.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgesidebarappurlhostallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_edgesidebarappurlhostblocklist","displayName":"Control which apps cannot be opened in Microsoft Edge sidebar","description":"Define a list of sites, based on URL patterns, that cannot be opened in sidebar.\n\nIf you don't configure this policy, a user can open any app in sidebar.\n\nIf the \"HubsSidebarEnabled\" policy is disabled, this list isn't used and no sidebar can be opened.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\n\nNote: A blocklist value of '*' means all apps are blocked unless they are explicitly listed in the \"EdgeSidebarAppUrlHostAllowList\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgesidebarappurlhostblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\n\nIf you don't configure this policy, no app is forced to be shown in sidebar.\n\nIf the \"HubsSidebarEnabled\" policy is disabled, this list isn't used and no sidebar can be shown.\n\nFor detailed information about valid url, see https://go.microsoft.com/fwlink/?linkid=2281313.\n\nNote: URL patterns are not supported in this policy. You should provide the exact URL of the app.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgesidebarappurlhostforcelist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_edgesidebarcustomizeenabled","displayName":"Enable sidebar customize","description":"Allow/Disallow to use sidebar customize.\n\nIf you enable or don't configure this policy, users will be able to access sidebar customize.\nIf you disable this policy, users will not be able to access the sidebar customize.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgesidebarcustomizeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgesidebarcustomizeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgesidebarcustomizeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgewalletetreeenabled","displayName":"Edge Wallet E-Tree Enabled","description":"The Edge Wallet E-Tree feature in Microsoft Edge allows users to plant a E-Tree for their own.\n\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\n\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgewalletetreeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgewalletetreeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgewalletetreeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeworkspacesenabled","displayName":"Enable Workspaces","description":"Microsoft Edge Workspaces helps improve productivity for users in your organization.\n\nIf you enable or don't configure this policy, users will be able to access the Microsoft Edge Workspaces feature.\nIf you disable this policy, users will not be able to access the Microsoft Edge Workspaces feature.\n\nTo learn more about the feature, see https://go.microsoft.com/fwlink/?linkid=2209950","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeworkspacesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeworkspacesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeworkspacesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_editfavoritesenabled","displayName":"Allows users to edit favorites","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\n\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#editfavoritesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_editfavoritesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_editfavoritesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_efficiencymode","displayName":"Configure when efficiency mode should become active","description":"This policy setting lets you configure when efficiency mode becomes active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, efficiency mode is disabled by default and does not become active. Please note that Windows Energy Saver settings can influence when efficiency mode becomes active on all devices.\n\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy \"SleepingTabsBlockedForUrls\".\n\nSet this policy to 'AlwaysActive' and efficiency mode is always active.\n\nSet this policy to 'NeverActive' and efficiency mode never becomes active.\n\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode becomes active when the device is unplugged.\n\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode becomes active when the device is unplugged and the battery is low.\n\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\nIf the device does not have a battery, efficiency mode never becomes active in any mode other than 'AlwaysActive' unless the setting or \"EfficiencyModeEnabled\" policy is enabled.\n\nThis policy has no effect if the \"EfficiencyModeEnabled\" policy is disabled.\n\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\n\nLearn more about energy saver: https://learn.microsoft.com/en-us/windows-hardware/design/component-guidelines/energy-saver\n\nPolicy options mapping:\n\n* AlwaysActive (0) = Efficiency mode is always active\n\n* NeverActive (1) = Efficiency mode is never active\n\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\n\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\n\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#efficiencymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_4","displayName":"When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes extra steps to save battery.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_5","displayName":"When the device is unplugged or unplugged and the battery is low, efficiency mode takes extra steps to save battery.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_efficiencymodeenabled","displayName":"Efficiency mode enabled","description":"Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and disabled otherwise.\n\nIf you enable this policy, efficiency mode will become active according to the setting chosen by the user. You can configure the efficiency mode setting using the \"EfficiencyMode\" policy. If the device does not have a battery, efficiency mode will always be active.\n\nIf you disable this policy, efficiency mode will never become active. The \"EfficiencyMode\" and \"EfficiencyModeOnPowerEnabled\" policies will have no effect.\n\nIf you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system.\n\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#efficiencymodeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_efficiencymodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_efficiencymodeonpowerenabled","displayName":"Enable efficiency mode when the device is connected to a power source","description":"Allows efficiency mode to become active when the device is connected to a power source. On devices with no battery, this policy has no effect.\n\nIf you enable this policy, efficiency mode will become active when the device is connected to a power source.\n\nIf you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source.\n\nThis policy has no effect if the \"EfficiencyModeEnabled\" policy is disabled.\n\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#efficiencymodeonpowerenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_efficiencymodeonpowerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymodeonpowerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enableallocsiclients","displayName":"Enable simultaneous edits for Office apps","description":"This setting lets multiple users use the Microsoft 365 Apps for enterprise, Office 2019, or Office 2016 desktop apps to simultaneously edit an Office file stored in OneDrive. It also lets users share files from the Office desktop apps.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#enableallocsiclients"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_enableallocsiclients_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableallocsiclients_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enableauthnegotiateport","displayName":"Include non-standard port in Kerberos SPN","description":"Specifies whether the generated Kerberos SPN should include a non-standard port.\n\nIf you enable this policy, and a user includes a non-standard port (a port other than 80 or 443) in a URL, that port is included in the generated Kerberos SPN.\n\nIf you don't configure or disable this policy, the generated Kerberos SPN won't include a port in any case.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enableauthnegotiateport"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enableauthnegotiateport_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableauthnegotiateport_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablebackgroundaccessibilitychecker","displayName":"Background accessibility checking","description":"The background accessibility checker automatically helps find and fix content in documents that may make it harder for people with disabilities to consume.","helpText":null,"infoUrls":[],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_enablebackgroundaccessibilitychecker_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablebackgroundaccessibilitychecker_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablecheckforupdatesbutton","displayName":"Enable check for updates","description":"Allow users to check for app updates. The default value is true.","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_enablecheckforupdatesbutton_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablecheckforupdatesbutton_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enabled","displayName":"Enable / disable cloud delivered protection","description":"Whether cloud delivered protection is enabled on the device or not. To improve the security of your services, we recommend keeping this feature turned on.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-cloud-delivered-protection"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"com.apple.managedclient.preferences_enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enabledeprecatedwebplatformfeatures","displayName":"Re-enable deprecated web platform features for a limited time","description":"Specify a list of deprecated web platform features to temporarily re-enable.\n\nThis policy lets you re-enable deprecated web platform features for a limited time. Features are identified by a string tag.\n\nIf you don't configure this policy, if the list is empty, or if a feature doesn't match one of the supported string tags, all deprecated web platform features remain disabled.\n\nWhile the policy itself is supported on the above platforms, the feature it's enabling might not be available on all of those platforms. Not all deprecated Web Platform features can be re-enabled. Only those explicitly listed below can be re-enabled, and only for a limited period of time, which differs per feature. You can review the intent behind the Web Platform feature changes at https://bit.ly/blinkintents.\n\nThe general format of the string tag is [DeprecatedFeatureName]_EffectiveUntil[yyyymmdd].\n\n* \"ExampleDeprecatedFeature_EffectiveUntil20080902\" = Enable ExampleDeprecatedFeature API through 2008/09/02","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enabledeprecatedwebplatformfeatures"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_enabledomainactionsdownload","displayName":"Enable Domain Actions Download from Microsoft","description":"In Microsoft Edge, Domain Actions represent a series of compatibility features that help the browser work correctly on the web.\n\nMicrosoft keeps a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken due to the new User Agent string on Microsoft Edge. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\n\nWhen the browser starts up and then periodically afterwards, the browser will contact the Experimentation and Configuration Service that contains the most up to date list of compatibility actions to perform. This list is saved locally after it is first retrieved so that subsequent requests will only update the list if the server's copy has changed.\n\nIf you enable this policy, the list of Domain Actions will continue to be downloaded from the Experimentation and Configuration Service.\n\nIf you disable this policy, the list of Domain Actions will no longer be downloaded from the Experimentation and Configuration Service.\n\nIf you don't configure this policy, the list of Domain Actions will continue to be downloaded from the Experimentation and Configuration Service.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enabledomainactionsdownload"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enabledomainactionsdownload_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enabledomainactionsdownload_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablefilehashcomputation","displayName":"Enable file hash computation","description":"Enables or disables file hash computation feature. When this feature is enabled Windows defender will compute hashes for files it scans. This will help in improving the accuracy of Custom Indicator matches. However, enabling Enable file hash computation may impact device performance.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#configure-file-hash-computation-feature"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_enablefilehashcomputation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablefilehashcomputation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablemediarouter","displayName":"Enable Google Cast","description":"Enable this policy to enable Google Cast. Users will be able to launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.\n\nDisable this policy to disable Google Cast.\n\nBy default, Google Cast is enabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enablemediarouter"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enablemediarouter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablemediarouter_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablenewoutlook","displayName":"Enable New Outlook","description":"Specify whether users should be allowed to switch between Classic and New Outlook.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#enable-new-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_enablenewoutlook_0","displayName":"Classic Outlook only","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablenewoutlook_1","displayName":"Default to Classic Outlook. Users may switch to New Outlook","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablenewoutlook_2","displayName":"Default to New Outlook. Users may revert to Classic Outlook","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablenewoutlook_3","displayName":"New Outlook only","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enableodignore","displayName":"Ignore named files","description":"This setting lets you enter keywords to prevent the OneDrive sync app from uploading certain files to OneDrive or SharePoint. You can enter complete names, such as setup.bin or use the asterisk (*) as a wildcard character to represent a series of characters, such as *.eml. Keywords aren't case-sensitive.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#allow-only-corporate-mailboxes-to-be-added"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_enableonlinerevocationchecks","displayName":"Enable online OCSP/CRL checks","description":"Online revocation checks don't provide a significant security benefit and are disabled by default.\n\nIf you enable this policy, Microsoft Edge will perform soft-fail, online OCSP/CRL checks. \"Soft fail\" means that if the revocation server can't be reached, the certificate will be considered valid.\n\nIf you disable the policy or don't configure it, Microsoft Edge won't perform online revocation checks.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enableonlinerevocationchecks"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enableonlinerevocationchecks_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableonlinerevocationchecks_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablerealtimeprotection","displayName":"Enable real-time protection (deprecated)","description":"Whether real-time protection (scan files as they are accessed) is enabled or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-real-time-protection"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_enablerealtimeprotection_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablerealtimeprotection_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablesetwarntoblock","displayName":"Enable set warn to block","description":"Converts warn determinations into blocks","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_enablesetwarntoblock_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablesetwarntoblock_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablesha1forlocalanchors","displayName":"Allow certificates signed using SHA-1 when issued by local trust anchors","description":"When this setting is enabled, Microsoft Edge allows connections secured by SHA-1 signed certificates so long as the the certificate chains to a locally-installed root certificate and is otherwise valid.\n\nNote that this policy depends on the operating system (OS) certificate verification stack allowing SHA-1 signatures. If an OS update changes the OS handling of SHA-1 certificates, this policy might no longer have effect. Further, this policy is intended as a temporary workaround to give enterprises more time to move away from SHA-1. This policy will be removed in Microsoft Edge 92 releasing in mid 2021.\n\nIf you don't set this policy or set it to false, or the SHA-1 certificate chains to a publicly trusted certificate root, then Microsoft Edge won't allow certificates signed by SHA-1.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enablesha1forlocalanchors"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enablesha1forlocalanchors_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablesha1forlocalanchors_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enableunsafeswiftshader","displayName":"Allow software WebGL fallback using SwiftShader","description":"Controls whether SwiftShader is used as a fallback for WebGL when hardware GPU acceleration isn't available.\n\nWhen enabled, Microsoft Edge uses SwiftShader to support WebGL on systems without GPU acceleration, such as headless environments or virtual machines.\n\nStarting in Microsoft Edge version 144, SwiftShader has been deprecated due to security concerns. As a result, WebGL context creation fails in scenarios where SwiftShader would have been used. Enabling this policy allows organizations to temporarily defer the deprecation and continue using SwiftShader.\n\nIf you disable or don't configure this policy, WebGL context creation may fail on systems without hardware acceleration. This could cause web content relying on WebGL to function incorrectly if it doesn't handle context creation failures.\n\nNote: This policy is temporary and scheduled for removal in a future release. Microsoft does not guarantee the security of environments where this policy is enabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enableunsafeswiftshader"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enableunsafeswiftshader_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableunsafeswiftshader_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_encryptedclienthelloenabled","displayName":"TLS Encrypted ClientHello Enabled","description":"Encrypted ClientHello (ECH) is an extension to TLS that encrypts the sensitive fields of ClientHello to improve privacy.\n\nIf ECH is enabled, Microsoft Edge might or might not use ECH depending on server support, the availability of the HTTPS DNS record, or the rollout status.\n\nIf you enable or do not configure this policy, Microsoft Edge will follow the default rollout process for ECH.\n\nIf this policy is disabled, Microsoft Edge will not enable ECH.\n\nBecause ECH is an evolving protocol, Microsoft Edge's implementation is subject to change.\n\nAs such, this policy is a temporary measure to control the initial experimental implementation. It will be replaced with final controls as the protocol finalizes.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#encryptedclienthelloenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_encryptedclienthelloenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_encryptedclienthelloenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enforcementlevel","displayName":"Enforcement level","description":"Specifies if network protection is disabled, in audit mode, or enforced","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_enforcementlevel_0","displayName":"disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_1","displayName":"audit","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_2","displayName":"block","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enforcementlevel_antivirusengine","displayName":"Enforcement level","description":"Antivirus engine enforcement mode","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences#enforcement-level-for-antivirus-engine"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_enforcementlevel_antivirusengine_0","displayName":"passive","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_antivirusengine_1","displayName":"on_demand","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_antivirusengine_2","displayName":"real_time","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection","displayName":"Enforcement level","description":"Specifies if tamper protection is disabled, in audit mode, or enforced","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":[{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection_0","displayName":"disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection_1","displayName":"audit","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection_2","displayName":"block","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge","description":"This policy lets you enhance the security state in Microsoft Edge.\n\nIf you set this policy to 'StandardMode', the enhanced mode will be turned off and Microsoft Edge will fallback to its standard security mode.\n\nIf you set this policy to 'BalancedMode', the security state will be in balanced mode.\n\nIf you set this policy to 'StrictMode', the security state will be in strict mode.\n\nIf you set this policy to 'BasicMode', the security state will be in basic mode.\n\nNote: Sites that use WebAssembly (WASM) are not supported on 32-bit systems when \"EnhanceSecurityMode\" is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\n\nStarting in Microsoft Edge 113, 'BasicMode' is deprecated and is treated the same as 'BalancedMode'. It won't work in Microsoft Edge version 116.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895\n\nPolicy options mapping:\n\n* StandardMode (0) = Standard mode\n\n* BalancedMode (1) = Balanced mode\n\n* StrictMode (2) = Strict mode\n\n* BasicMode (3) = (Deprecated) Basic mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enhancesecuritymode_0","displayName":"Standard mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymode_1","displayName":"Balanced mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymode_2","displayName":"Strict mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymode_3","displayName":"(Deprecated) Basic mode","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enhancesecuritymodebypasslistdomains","displayName":"Configure the list of domains for which enhance security mode will not be enforced","description":"Configure the list of enhance security trusted domains. This means that\nenhance security mode will not be enforced when loading the sites in trusted domains.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymodebypasslistdomains"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeenforcelistdomains","displayName":"Configure the list of domains for which enhance security mode will always be enforced","description":"Configure the list of enhance security untrusted domains. This means that\nenhance security mode will always be enforced when loading the sites in untrusted domains.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymodeenforcelistdomains"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeindicatoruienabled","displayName":"Manage the indicator UI of the Enhanced Security Mode (ESM) feature in Microsoft Edge","description":"This policy lets you manage whether the indicator User Interface (UI) for enhanced security mode is shown or not when ESM is turned on.\n\nIf you enable or don't configure this policy, the indicator UI is on.\n\nIf you disable this policy, the indicator UI is off.\n\nNote: If this policy is used, only the indicator User Interface experience is supressed - ESM is still turned on. For more information, see the \"EnhanceSecurityMode\" policy.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymodeindicatoruienabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enhancesecuritymodeindicatoruienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeindicatoruienabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeoptoutuxenabled","displayName":"Manage opt-out user experience for Enhanced Security Mode (ESM) in Microsoft Edge (Deprecated)","description":"This policy lets you manage whether the opt-out user experience for enhanced security mode is presented when ESM is turned on for Microsoft Edge.\n\nIf you enable or don't configure this policy, the UI for the opt-out user experience is on.\n\nIf you disable this policy, the UI for the opt-out user experience is off.\n\nNote: If this policy is used, only the User Interface for the opt-out experience is supressed - ESM is still turned on. For more information, see the \"EnhanceSecurityMode\" policy.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.\n\nAfter careful evaluation, we have determined that this experimental opt-out UX is not required. As a result, this policy will be deprecated and stop working after Edge version 130.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymodeoptoutuxenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enhancesecuritymodeoptoutuxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeoptoutuxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enterprisehardwareplatformapienabled","displayName":"Allow managed extensions to use the Enterprise Hardware Platform API","description":"When this policy is set to enabled, extensions installed by enterprise policy are allowed to use the Enterprise Hardware Platform API.\nWhen this policy is set to disabled or isn't set, no extensions are allowed to use the Enterprise Hardware Platform API.\nThis policy also applies to component extensions.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enterprisehardwareplatformapienabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enterprisehardwareplatformapienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enterprisehardwareplatformapienabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_exclusions","displayName":"Scan exclusions","description":"Entities that have been excluded from the scan. Exclusions can be specified by full paths, extensions, or file names.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#scan-exclusions"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_$type","displayName":"Type","description":null,"helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_exclusions_item_$type_0","displayName":"Path","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusions_item_$type_1","displayName":"File extension","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusions_item_$type_2","displayName":"File name","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_exclusions_item_args_tamperprotection","displayName":"Process's arguments","description":"Command line arguments","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_extension","displayName":"File extension","description":null,"helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_isdirectory","displayName":"Directory (selected) or file (not selected)","description":"Directory if selected, or file if not selected","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_exclusions_item_isdirectory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusions_item_isdirectory_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_exclusions_item_name","displayName":"Name","description":"Process name, either or full path or file name, wildcards supported","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_path","displayName":"Path","description":"Path to exclude, wildcards are supported","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_path_tamperprotection","displayName":"Process path","description":"Full and exact path to the process binary","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_signingid_tamperprotection","displayName":"Process's Signing Identifier","description":"Code signature Identifier","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_teamid_tamperprotection","displayName":"Process's TeamIdentifier","description":"Code signature TeamIdentifier","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":null},{"id":"com.apple.managedclient.preferences_exclusions_tamperprotection","displayName":"Process exclusions","description":"Defines process that can interfere with Defender without considering it tampering","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":null},{"id":"com.apple.managedclient.preferences_exclusionsmergepolicy","displayName":"Exclusions merge","description":"Specify the merge policy for exclusions. This can be a combination of administrator-defined and user-defined exclusions (merge) or only administrator-defined exclusions (admin_only). This setting can be used to restrict local users from defining their own exclusions.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#exclusion-merge-policy"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_exclusionsmergepolicy_0","displayName":"merge","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusionsmergepolicy_1","displayName":"admin_only","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users would not see a warning when downloading \"jnlp\" files from \"website1.com\", but see a download warning when downloading \"jnlp\" files from \"website2.com\".\n\nFiles with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\n\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.\n\nIf you enable this policy:\n\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list \"jnlp\" should be used instead of \".jnlp\".\n\nExample:\n\nThe following example value would prevent file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\n\n[\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\n]\n\nNote that while the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#exemptdomainfiletypepairsfromfiletypedownloadwarnings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service","description":"In Microsoft Edge, the Experimentation and Configuration Service is used to deploy Experimentation and Configuration payload.\n\nExperimentation payload consists of a list of early in development features that Microsoft is enabling for testing and feedback.\n\nConfiguration payload consists of a list of settings that Microsoft wants to deploy to Microsoft Edge to optimize user experience. For example, configuration payload may specify how often Microsoft Edge sends requests to the Experimentation and Configuration Service to retrieve the newest payload.\n\nIf you set this policy to \"Retrieve configurations and experiments\" mode, the full payload is downloaded from the Experimentation and Configuration Service. This includes both the experimentation and configuration payloads.\n\nIf you set this policy to \"Retrieve configurations only\" mode, only the configuration payload is delivered.\n\nIf you set this policy to \"Disable communication with the Experimentation and Configuration Service\" mode, the communication with the Experimentation and Configuration Service is stopped completely.\n\nIf you don't configure this policy, on a managed device on Stable and Beta channels the behavior is the same as the \"Retrieve configurations only\" mode.\n\nIf you don't configure this policy, on an unmanaged device the behavior is the same as the \"Retrieve configurations and experiments\" mode.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#experimentationandconfigurationservicecontrol"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_experimentationandconfigurationservicecontrol_0","displayName":"Retrieve configurations and experiments","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_experimentationandconfigurationservicecontrol_1","displayName":"Retrieve configurations only","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_experimentationandconfigurationservicecontrol_2","displayName":"Disable communication with the Experimentation and Configuration Service","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_explicitlyallowednetworkports","displayName":"Explicitly allowed network ports","description":"There is a list of restricted ports built into Microsoft Edge. Connections to these ports will fail. This policy allows bypassing that list. The set of ports is defined as a comma-separated list that outgoing connections should be permitted on.\n\nPorts are restricted to prevent Microsoft Edge from being used as a vector to exploit various network vulnerabilities. Setting this policy may expose your network to attacks. This policy is intended as a temporary workaround for error code \"ERR_UNSAFE_PORT\" while migrating a service running on a blocked port to a standard port (for example port 80 or 443).\n\nMalicious websites can easily detect that this policy is set, and for which ports, then use that information to target attacks.\n\nEach port listed in this policy is labeled with a date that it can be unblocked until. After that date the port will be restricted regardless of if it's specified by the value of this policy.\n\nLeaving the value empty or unset means that all restricted ports will be blocked. Invalid port values set through this policy will be ignored while valid ones will still be applied.\n\nThis policy overrides the \"--explicitly-allowed-ports\" command-line option.\n\nPolicy options mapping:\n\n* 554 (554) = port 554 (can be unblocked until 2021/10/15)\n\n* 10080 (10080) = port 10080 (can be unblocked until 2022/04/01)\n\n* 6566 (6566) = port 6566 (can be unblocked until 2021/10/15)\n\n* 989 (989) = port 989 (can be unblocked until 2022/02/01)\n\n* 990 (990) = port 990 (can be unblocked until 2022/02/01)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#explicitlyallowednetworkports"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extendedlogging","displayName":"Enable extended logging","description":"Write verbose logging events to /Library/Logs/Microsoft/autoupdate.log","helpText":null,"infoUrls":["https://macadmins.software/docs/MAU_38.pdf"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_extendedlogging_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extendedlogging_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_extensionallowedtypes","displayName":"Configure allowed extension types","description":"Controls which extension types can be installed and limits runtime access.\n\nThis setting defines the allowed types of extensions and which hosts they can interact with. The value is a list of strings, each of which should be one of the following: \"extension\", \"theme\", \"user_script\", and \"hosted_app\". See the Microsoft Edge extensions documentation for more information on these types.\n\nNote that this policy also affects extensions to be force-installed by using \"ExtensionInstallForcelist\" policy.\n\nIf you enable this policy, only extensions that match a type in the list are installed.\n\nIf you don't configure this policy, no restrictions on the acceptable extension types are enforced.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensionallowedtypes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page","description":"Control if users can turn on Developer Mode on edge://extensions.\n\nIf the policy isn't set, users can turn on developer mode on the extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\nIf the policy is set to Allow (0), users can turn on developer mode on the extensions page.\nIf the policy is set to Disallow (1), users cannot turn on developer mode on the extensions page.\n\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.\n\nPolicy options mapping:\n\n* Allow (0) = Allow the usage of developer mode on extensions page\n\n* Disallow (1) = Do not allow the usage of developer mode on extensions page\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensiondevelopermodesettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_extensiondevelopermodesettings_0","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extensiondevelopermodesettings_1","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant an extended background lifetime to connecting extensions.","description":"Extensions that connect to one of these origins will keep running as long as the port is connected.\nIf unset, the policy's default values are used. These are the app origins that offer SDKs that are known to not offer the possibility to restart a closed connection to a previous state:\n- Smart Card Connector\n- Citrix Receiver (stable, beta, back-up)\n- VMware Horizon (stable, beta)\n\nIf set, the default value list is extended with the newly configured values. The defaults and policy-provided entries will grant the exception to the connecting extensions, as long as the port is connected.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensionextendedbackgroundlifetimeforportconnectionstourls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensioninstallallowlist","displayName":"Allow specific extensions to be installed","description":"By default, all extensions are allowed. However, if you block all extensions by setting the 'ExtensionInstallBlockList' policy to \"*,\" users can only install extensions defined in this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensioninstallblocklist","displayName":"Control which extensions cannot be installed","description":"List specific extensions that users can NOT install in Microsoft Edge. When you deploy this policy, any extensions on this list that were previously installed will be disabled, and the user won't be able to enable them. If you remove an item from the list of blocked extensions, that extension is automatically re-enabled anywhere it was previously installed.\n\nUse \"*\" to block all extensions that aren't explicitly listed in the allow list.\n\nIf you don't configure this policy, users can install any extension in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensioninstallforcelist","displayName":"Control which extensions are installed silently","description":"Specifies extensions that are installed silently, without user interaction, and that the users can't uninstall or disable (\"force-installed\"). All permissions requested by the extensions are granted implicitly, without user interaction, including any additional permissions requested by future versions of the extension. Furthermore, permissions are granted for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These two APIs are only available to extensions that are force-installed.)\n\nThis policy takes precedence over a potentially conflicting \"ExtensionInstallBlocklist\" policy. When you take an extension off of the force-installed list it's automatically uninstalled by Microsoft Edge.\n\nFor Windows devices that aren't joined to a Microsoft Active Directory domain, forced installation is limited to extensions available in the Microsoft Store.\n\nNote that users can modify the source code of any extension by using Developer Tools, potentially rendering the extension dysfunctional. If this is a concern, set the \"DeveloperToolsAvailability\" policy.\n\nUse the following format to add an extension to the list:\n\n[extensionID];[updateURL]\n\n- extensionID - the 32-letter string found on edge://extensions when in developer mode.\n\n- updateURL (optional) is the address of the Update Manifest XML document for the app or extension, as described at https://go.microsoft.com/fwlink/?linkid=2095043. If you don't set the updateURL, the Microsoft Store update URL is used (currently https://edge.microsoft.com/extensionwebstorebase/v1/crx). Note that the update URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL indicated in the extension's manifest.\n\nFor example, gggmmkjegpiggikcnhidnjjhmicpibll;https://edge.microsoft.com/extensionwebstorebase/v1/crx installs the Microsoft Online app from the Microsoft Store \"update\" URL. For more information about hosting extensions, see: https://go.microsoft.com/fwlink/?linkid=2095044.\n\nIf you don't configure this policy, no extensions are installed automatically, and users can uninstall any extension in Microsoft Edge.\n\nNote that this policy doesn't apply to InPrivate mode.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallforcelist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensioninstallsources","displayName":"Configure extension and user script install sources","description":"Define URLs that can install extensions and themes.\n\nBy default, users have to download a *.crx file for each extension or script they want to install, and then drag it onto the Microsoft Edge settings page. This policy lets specific URLs use install the extension or script for the user.\n\nEach item in this list is an extension-style match pattern (see https://go.microsoft.com/fwlink/?linkid=2095039). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (in other words, the referrer) must be allowed by these patterns.\n\nThe \"ExtensionInstallBlocklist\" policy takes precedence over this policy. Any extensions that's on the block list won't be installed, even if it comes from a site on this list.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallsources"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensioninstalltypeblocklist","displayName":"Blocklist for extension install types","description":"The blocklist controls which extension install types are disallowed.\n\nSetting the \"command_line\" will block an extension from being loaded from command line.\n\nPolicy options mapping:\n\n* command_line (command_line) = Blocks extensions from being loaded from command line\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstalltypeblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability","description":"Control if Manifest v2 extensions can be used by browser.\n\nManifest v2 extensions support will be deprecated and all extensions need to be migrated to v3 in the future. More information about, and the timeline of the migration has not been established.\n\nIf the policy is set to Default or not set, v2 extension loading is decided by browser. This will follow the preceding timeline when it's established.\n\nIf the policy is set to Disable, v2 extensions installation are blocked, and existing ones are disabled. This option is going to be treated the same as if the policy is unset after v2 support is turned off by default.\n\nIf the policy is set to Enable, v2 extensions are allowed. The option is going to be treated the same as if the policy isn't set before v2 support is turned off by default.\n\nIf the policy is set to EnableForForcedExtensions, force installed v2 extensions are allowed. This includes extensions that are listed by \"ExtensionInstallForcelist\" or \"ExtensionSettings\" with installation_mode \"force_installed\" or \"normal_installed\". All other v2 extensions are disabled. The option is always available regardless of the manifest migration state.\n\nExtensions availabilities are still controlled by other policies.\n\nPolicy options mapping:\n\n* Default (0) = Default browser behavior\n\n* Disable (1) = Manifest v2 is disabled\n\n* Enable (2) = Manifest v2 is enabled\n\n* EnableForForcedExtensions (3) = Manifest v2 is enabled for forced extensions only\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensionmanifestv2availability"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_extensionmanifestv2availability_0","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extensionmanifestv2availability_1","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extensionmanifestv2availability_2","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extensionmanifestv2availability_3","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_extensionsperformancedetectorenabled","displayName":"Extensions Performance Detector enabled","description":"This policy controls if users can access the Extensions Performance Detector Recommended Action feature in Browser Essentials. This feature alerts extension users if their extensions are causing performance regressions in the browser and allows them to take action to resolve the issue.\n\nIf you enable or don't configure this policy, users will receive Extensions Performance Detector notifications from Browser Essentials. When there is an active alert, users will be able to view the impact of extensions on their browser's performance and make an informed decision to disable impacting extensions. The detector will exclude browser-managed extensions, such as Google Docs offline, component extensions, and organization-managed extensions (ie. extensions that cannot be disabled).\n\nIf you disable this policy, users will not receive notifications or be able to view the Extensions Performance Detector Recommended Action.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensionsperformancedetectorenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_extensionsperformancedetectorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extensionsperformancedetectorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_externalprotocoldialogshowalwaysopencheckbox","displayName":"Show an \"Always open\" checkbox in external protocol dialog","description":"This policy controls whether the \"Always open\" checkbox is shown on external protocol launch confirmation prompts.\n\nIf you set this policy to True, when an external protocol confirmation prompt is shown, the user can select \"Always open\". The user won’t get any future confirmation prompts for this protocol.\n\nIf you set this policy to False, or the policy is unset, the \"Always open\" checkbox isn’t displayed. The user will be prompted for confirmation every time an external protocol is invoked.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#externalprotocoldialogshowalwaysopencheckbox"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_externalprotocoldialogshowalwaysopencheckbox_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_externalprotocoldialogshowalwaysopencheckbox_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_familysafetysettingsenabled","displayName":"Allow users to configure Family safety","description":"This policy disables and completely hides the Family safety page in Settings. Navigation to edge://settings/familysafety will also be blocked. The Family safety page describes what features are available for family groups and how to join a family group. Learn more about family safety here: (https://go.microsoft.com/fwlink/?linkid=2098432).\n\nIf you enable this policy or don't configure it, the Family safety page will be shown.\n\nIf you disable this policy, the Family safety page will not be shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#familysafetysettingsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_familysafetysettingsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_familysafetysettingsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_favoritesbarenabled","displayName":"Enable favorites bar","description":"Enables or disables the favorites bar.\n\nIf you enable this policy, users will see the favorites bar.\n\nIf you disable this policy, users won't see the favorites bar.\n\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#favoritesbarenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_favoritesbarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_favoritesbarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_featureflagoverridescontrol","displayName":"Configure users ability to override feature flags","description":"Configures users ability to override state of feature flags.\nIf you set this policy to 'CommandLineOverridesEnabled', users can override state of feature flags using command line arguments but not edge://flags page.\n\nIf you set this policy to 'OverridesEnabled', users can override state of feature flags using command line arguments or edge://flags page.\n\nIf you set this policy to 'OverridesDisabled', users can't override state of feature flags using command line arguments or edge://flags page.\n\nIf you don't configure this policy, the behavior is the same as the 'OverridesEnabled'.\n\nPolicy options mapping:\n\n* CommandLineOverridesEnabled (2) = Allow users to override feature flags using command line arguments only\n\n* OverridesEnabled (1) = Allow users to override feature flags\n\n* OverridesDisabled (0) = Prevent users from overriding feature flags\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#featureflagoverridescontrol"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_featureflagoverridescontrol_0","displayName":"Prevent users from overriding feature flags","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_featureflagoverridescontrol_1","displayName":"Allow users to override feature flags","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_featureflagoverridescontrol_2","displayName":"Allow users to override feature flags using command line arguments only","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on shutdown","description":"Controls the duration (in seconds) that keepalive requests are allowed to prevent the browser from completing its shutdown.\n\nIf you configure this policy, the browser will block completing shutdown while it processes any outstanding keepalive requests (see https://fetch.spec.whatwg.org/#request-keepalive-flag) up to the maximum period of time specified by this policy.\n\nIf you disable or don't configure this policy, the default value of 0 seconds is used and outstanding keepalive requests will be immediately cancelled during browser shutdown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#fetchkeepalivedurationsecondsonshutdown"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_fileordirectorypickerwithoutgestureallowedfororigins","displayName":"Allow file or directory picker APIs to be called without prior user gesture","description":"For security reasons, the showOpenFilePicker(), showSaveFilePicker() and showDirectoryPicker() web APIs require a prior user gesture (\"transient activation\") to be called or will otherwise fail.\n\nIf you enable this policy, admins can specify origins on which these APIs can be called without prior user gesture.\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\n\nIf you disable or don't configure this policy, all origins will require a prior user gesture to call these APIs.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#fileordirectorypickerwithoutgestureallowedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_filesondemandenabled","displayName":"Enable Files On-Demand","description":"Specifies whether Files On-Demand is enabled. When set to true, new users who set up the sync app will download online-only files by default. When set to false, Files On-Demand will be disabled and users won't be able to turn it on. NOTE: This setting only applies to macOS Monterey 12.1 and earlier.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#filesondemandenabled"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_filesondemandenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_filesondemandenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_filesystemreadaskforurls","displayName":"Allow read access via the File System API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\n\nLeaving the policy unset means \"DefaultFileSystemReadGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemReadBlockedForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#filesystemreadaskforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_filesystemreadblockedforurls","displayName":"Block read access via the File System API on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\n\nIf you don't set this policy, \"DefaultFileSystemReadGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemReadAskForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#filesystemreadblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_filesystemwriteaskforurls","displayName":"Allow write access to files and directories on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system.\n\nIf you don't set this policy, \"DefaultFileSystemWriteGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemWriteBlockedForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#filesystemwriteaskforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_filesystemwriteblockedforurls","displayName":"Block write access to files and directories on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system.\n\nIf you don't set this policy, \"DefaultFileSystemWriteGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemWriteAskForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#filesystemwriteblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_forcebingsafesearch","displayName":"Enforce Bing SafeSearch","description":"Ensure that queries in Bing web search are done with SafeSearch set to the value specified. Users can't change this setting.\n\nIf you configure this policy to \"Off\", SafeSearch in Bing search falls back to the bing.com value.\n\nIf you configure this policy to \"Moderate\", the moderate setting is used in SafeSearch. The moderate setting filters adult videos and images but not text from search results.\n\nIf you configure this policy to \"Strict\", the strict setting in SafeSearch is used. The strict setting filters adult text, images, and videos.\n\nIf you disable this policy or don't configure it, SafeSearch in Bing search isn't enforced, and users can set the value they want on bing.com.\n\n* 0 = Don't configure search restrictions in Bing\n\n* 1 = Configure moderate search restrictions in Bing\n\n* 2 = Configure strict search restrictions in Bing","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcebingsafesearch"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcebingsafesearch_0","displayName":"Don't configure search restrictions in Bing","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcebingsafesearch_1","displayName":"Configure moderate search restrictions in Bing","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcebingsafesearch_2","displayName":"Configure strict search restrictions in Bing","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forcecertificatepromptsonmultiplematches","displayName":"Configure whether Microsoft Edge should automatically select a certificate when there are multiple certificate matches for a site configured with \"AutoSelectCertificateForUrls\"","description":"Toggles whether users are prompted to select a certificate if there are multiple certificates available and a site is configured with \"AutoSelectCertificateForUrls\". If you don't configure \"AutoSelectCertificateForUrls\" for a site, the user will always be prompted to select a certificate.\n\nIf you set this policy to True, Microsoft Edge will prompt a user to select a certificate for sites on the list defined in \"AutoSelectCertificateForUrls\" if and only if there is more than one certificate.\n\nIf you set this policy to False or don't configure it, Microsoft Edge will automatically select a certificate even if there are multiple matches for a certificate. The user will not be prompted to select a certificate for sites on the list defined in \"AutoSelectCertificateForUrls\".","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcecertificatepromptsonmultiplematches"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcecertificatepromptsonmultiplematches_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcecertificatepromptsonmultiplematches_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forceephemeralprofiles","displayName":"Enable use of ephemeral profiles","description":"Controls whether user profiles are switched to ephemeral mode. An ephemeral profile is created when a session begins, is deleted when the session ends, and is associated with the user's original profile.\n\nIf you enable this policy, profiles run in ephemeral mode. This lets users work from their own devices without saving browsing data to those devices. If you enable this policy as an OS policy (by using GPO on Windows, for example), it applies to every profile on the system.\n\nIf you disable this policy or don't configure it, users get their regular profiles when they sign in to the browser.\n\nIn ephemeral mode, profile data is saved on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies, and web databases aren't saved after the browser is closed. This doesn't prevent a user from manually downloading any data to disk, or from saving pages or printing them. If the user has enabled sync, all data is preserved in their sync accounts just like with regular profiles. Users can also use InPrivate browsing in ephemeral mode unless you explicitly disable this.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forceephemeralprofiles"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forceephemeralprofiles_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forceephemeralprofiles_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forcegooglesafesearch","displayName":"Enforce Google SafeSearch","description":"Forces queries in Google Web Search to be performed with SafeSearch set to active, and prevents users from changing this setting.\n\nIf you enable this policy, SafeSearch in Google Search is always active.\n\nIf you disable this policy or don't configure it, SafeSearch in Google Search isn't enforced.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcegooglesafesearch"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcegooglesafesearch_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcegooglesafesearch_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forcelegacydefaultreferrerpolicy","displayName":"Use a default referrer policy of no-referrer-when-downgrade.","description":"This enterprise policy is for short-term adaptation and will be removed in M82.\n\nMicrosoft Edge’s default referrer policy is being strengthened from its current value of no-referrer-when-downgrade to the more secure strict-origin-when-cross-origin through a gradual rollout targeting M80 stable.\n\nBefore the rollout, this enterprise policy will have no effect. After the rollout, when this enterprise policy is enabled, Microsoft Edge’s default referrer policy will be set to its pre-M80 value of no-referrer-when-downgrade.\n\nThis enterprise policy is disabled by default","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcelegacydefaultreferrerpolicy"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcelegacydefaultreferrerpolicy_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcelegacydefaultreferrerpolicy_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled.","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy.\nCurrently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers.\nThis enterprise policy can be used to opt out of this gradual deprecation by forcing the default to stay enabled.\n\nPages might depend on unload event handlers to save data or signal the end of a user session to the server.\nThis is not recommended because it's unreliable and impacts performance by blocking use of BackForwardCache.\nRecommended alternatives exist, but the unload event has been used for a long time. Some applications might still rely on them.\n\nIf you disable this policy or don't configure it, unload event handlers will gradually be deprecated in-line with the deprecation rollout and sites which don't set Permissions-Policy header will stop firing `unload` events.\n\nIf you enable this policy then unload event handlers will continue to work by default.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcepermissionpolicyunloaddefaultenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcepermissionpolicyunloaddefaultenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcepermissionpolicyunloaddefaultenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forcesync","displayName":"Force synchronization of browser data and do not show the sync consent prompt","description":"Forces data synchronization in Microsoft Edge. This policy also prevents the user from turning sync off.\n\nIf you don't configure this policy, users will be able to turn sync on or off. If you enable this policy, users will not be able to turn sync off.\n\nFor this policy to work as intended,\n\"BrowserSignin\" policy must not be configured, or must be set to enabled. If \"BrowserSignin\" is set to disabled, then \"ForceSync\" will not take affect.\n\n\"SyncDisabled\" must not be configured or must be set to False. If this is set to True, \"ForceSync\" will not take affect.\n\n0 = Do not automatically start sync and show the sync consent (default)\n1 = Force sync to be turned on for Azure AD/Azure AD-Degraded user profile and do not show the sync consent prompt","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcesync"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcesync_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcesync_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forcesynctypes","displayName":"Configure the list of types that are included for synchronization","description":"If you enable this policy all the specified data types will be included for synchronization for Azure AD/Azure AD-Degraded user profiles. This policy can be used to ensure the type of data uploaded to the Microsoft Edge synchronization service.\n\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", \"history\", \"openTabs\", \"edgeWallet\", \"collections\", \"apps\", and \"edgeFeatureUsage\". The \"edgeFeatureUsage\" data type will be supported starting in Microsoft Edge version 134. Note that these data type names are case sensitive.\n\nUsers will not be able to override the enabled data types.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcesynctypes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode","description":"Enforces a minimum Restricted Mode on YouTube and prevents users from picking a less restricted mode.\n\nSet to Strict (2) to enforce Strict Restricted Mode on YouTube.\n\nSet to Moderate (1) to enforce the user to only use Moderate Restricted Mode and Strict Restricted Mode on YouTube. They can't disable Restricted Mode.\n\nSet to Off (0) or don't configure this policy to not enforce Restricted Mode on YouTube. External policies such as YouTube policies might still enforce Restricted Mode.\n\n* 0 = Do not enforce Restricted Mode on YouTube\n\n* 1 = Enforce at least Moderate Restricted Mode on YouTube\n\n* 2 = Enforce Strict Restricted Mode for YouTube","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forceyoutuberestrict"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forceyoutuberestrict_0","displayName":"Do not enforce Restricted Mode on YouTube","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forceyoutuberestrict_1","displayName":"Enforce at least Moderate Restricted Mode on YouTube","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forceyoutuberestrict_2","displayName":"Enforce Strict Restricted Mode for YouTube","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_genailocalfoundationalmodelsettings","displayName":"Settings for GenAI local foundational model","description":"This policy controls whether Microsoft Edge downloads the foundational GenAI model and uses it for local inference.\n\nIf you enable this policy and set the value to Allowed (0), the model is downloaded automatically and used for inference.\n\nIf you enable this policy and set the value to Disallowed (1), the model is not downloaded.\n\nIf you disable or don't configure this policy, the default applies, and the model is downloaded automatically and used for inference.\n\nNote: This policy supports dynamic refresh, so changes take effect without requiring a browser restart.\n\nModel downloading can also be disabled by ComponentUpdatesEnabled.\n\nPolicy options mapping:\n\n* Allowed (0) = Downloads model automatically\n\n* Disallowed (1) = Do not download model\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#genailocalfoundationalmodelsettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_genailocalfoundationalmodelsettings_0","displayName":"Downloads model automatically","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_genailocalfoundationalmodelsettings_1","displayName":"Do not download model","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_geolocationblockedforurls","displayName":"Block geolocation on these sites","description":"Use this policy to define a list of URL patterns for sites that are blocked from accessing the user's geolocation. These sites also can't prompt the user for location permissions.\n\nIf you enable this policy, the list you provide determines which sites are blocked from requesting or accessing geolocation.\n\nIf you disable or don't configure this policy, DefaultGeolocationSetting applies to all sites, if configured. If it's not configured, the user’s personal browser setting is used.\n\nFor detailed information on valid url patterns, see the documentation on pattern formats: https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#geolocationblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\n\nIf you disable or don’t set this policy, the browser will use the default behavior of cross-site auth, which as of version 80, will be to scope HTTP server authentication credentials by top-level site. So, if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites.\n\nIf you enable this policy HTTP auth credentials entered in the context of one site will automatically be used in the context of another site.\n\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\n\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures and will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#globallyscopehttpauthcacheenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_globallyscopehttpauthcacheenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_globallyscopehttpauthcacheenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_gotointranetsiteforsinglewordentryinaddressbar","displayName":"Force direct intranet site navigation instead of searching on single word entries in the Address Bar","description":"If you enable this policy, the top auto-suggest result in the address bar suggestion list will navigate to intranet sites if the text entered in the address bar is a single word without punctuation.\n\nDefault navigation when typing a single word without punctuation will conduct a navigation to an intranet site matching the entered text.\n\nIf you enable this policy, the second auto-suggest result in the address bar suggestion list will conduct a web search exactly as it was entered, provided that this text is a single word without punctuation. The default search provider will be used unless a policy to prevent web search is also enabled.\n\nTwo effects of enabling this policy are:\n\nNavigation to sites in response to single word queries that would typically resolve to a history item will no longer happen. Instead, the browser will attempt navigate to internal sites that may not exist in an organization’s intranet. This will result in a 404 error.\n\nPopular, single-word search terms will require manual selection of search suggestions to properly conduct a search.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#gotointranetsiteforsinglewordentryinaddressbar"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_gotointranetsiteforsinglewordentryinaddressbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_gotointranetsiteforsinglewordentryinaddressbar_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_groupids","displayName":"Group identifier","description":"","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#group-identifiers"],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":null},{"id":"com.apple.managedclient.preferences_guardagainstappmodification","displayName":"Guard against app modification","description":"Retain and reuse app clones after the update cycle. This allows for future delta updates even when the source app has been modified by a third-party tool.","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_guardagainstappmodification_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_guardagainstappmodification_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_guidedswitchenabled","displayName":"Guided Switch Enabled","description":"Allows Microsoft Edge to prompt the user to switch to the appropriate profile when Microsoft Edge detects that a link is a personal or work link.\n\nIf you enable this policy, you'll be prompted to switch to another account if the current profile doesn't work for the requesting link.\n\nIf you disable this policy, you won't be prompted to switch to another account when there's a profile and link mismatch.\n\nIf this policy isn't configured, guided switch is turned on by default. A user can override this value in the browser settings.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#guidedswitchenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_guidedswitchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_guidedswitchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_happyeyeballsv3enabled","displayName":"Use the Happy Eyeballs V3 algorithm for connection attempts","description":"Controls whether Microsoft Edge uses the Happy Eyeballs V3 algorithm to optimize connection attempts. This algorithm improves reliability and performance in dual-stack (IPv4/IPv6) networks by racing connection attempts across IP versions and HTTP protocols (e.g., HTTP/3 vs. others). For more details, see https://datatracker.ietf.org/doc/draft-pauly-happy-happyeyeballs-v3.\n\nEnabled: Uses the algorithm for connection attempts.\n\nDisabled or not configured: Disables the algorithm.\n\nNote: This policy supports dynamic refresh.\n\nImportant: This policy is temporary and will be removed in a future version.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#happyeyeballsv3enabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_happyeyeballsv3enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_happyeyeballsv3enabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hardwareaccelerationmodeenabled","displayName":"Use hardware acceleration when available","description":"Specify to use hardware acceleration, if it's available. If you enable this policy or don't configure it, hardware acceleration is enabled unless a GPU feature is explicitly blocked.\n\nIf you disable this policy, hardware acceleration is disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#hardwareaccelerationmodeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_hardwareaccelerationmodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hardwareaccelerationmodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_headlessmodeenabled","displayName":"Control use of the Headless Mode","description":"This policy setting lets you decide whether users can launch Microsoft Edge in headless mode.\n\nIf you enable or don't configure this policy, Microsoft Edge allows use of the headless mode.\n\nIf you disable this policy, Microsoft Edge denies use of the headless mode.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#headlessmodeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_headlessmodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_headlessmodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hidedockicon","displayName":"Hide dock icon","description":"Specifies whether the dock icon for OneDrive is hidden.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#hidedockicon"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_hidedockicon_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hidedockicon_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hidefirstrunexperience","displayName":"Hide the First-run experience and splash screen","description":"If you enable this policy, the First-run experience and the splash screen will not be shown to users when they run Microsoft Edge for the first time.\n\nFor the configuration options shown in the First Run Experience, the browser will default to the following:\n\n-On the New Tab Page, the feed type will be set to MSN News and the layout to Inspirational.\n\n-The user will still be automatically signed into Microsoft Edge if the Windows account is of AAD or MSA type.\n\n-Sync will not be enabled by default and users will be able to turn on sync from the sync settings.\n\nIf you disable or don't configure this policy, the First-run experience and the Splash screen will be shown.\n\nNote: The specific configuration options shown to the user in the First Run Experience, can also be managed by using other specific policies. You can use the HideFirstRunExperience policy in combination with these policies to configure a specific browser experience on your managed devices. Some of these other policies are:\n\n-\"AutoImportAtFirstRun\"\n\n-\"NewTabPageLocation\"\n\n-\"NewTabPageSetFeedType\"\n\n-\"SyncDisabled\"\n\n-\"BrowserSignin\"\n\n-\"NonRemovableProfileEnabled\"","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#hidefirstrunexperience"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_hidefirstrunexperience_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hidefirstrunexperience_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hidefoldersonmycomputerrootinfolderlist","displayName":"Hide On My Computer folders","description":"Disable local folder storage.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#hide-local-folders"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_hidefoldersonmycomputerrootinfolderlist_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hidefoldersonmycomputerrootinfolderlist_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hidestatusmenuicon","displayName":"Show / hide status menu icon","description":"Whether the status menu icon (shown in the top-right corner of the screen) is hidden or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#show--hide-status-menu-icon"],"categoryId":"67cd904c-78e0-4e77-9dd4-c713b21763f3","categoryName":"User interface preferences","options":[{"id":"com.apple.managedclient.preferences_hidestatusmenuicon_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hidestatusmenuicon_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_homepageisnewtabpage","displayName":"Set the new tab page as the home page","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\n\nIf you enable this policy, the new tab page is always used for the home page, and the home page URL location is ignored.\n\nIf you disable this policy, the user's home page can't be the new tab page, unless the URL is set to 'edge://newtab'.\n\nIf not configured users can choose whether the new tab page is their home page.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#homepageisnewtabpage"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_homepageisnewtabpage_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_homepageisnewtabpage_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_homepagelocation","displayName":"Configure the home page URL","description":"Configures the default home page URL in Microsoft Edge.\n\nThe home page is the page opened by the Home button. The pages that open on startup are controlled by the \"RestoreOnStartup\" policies.\n\nYou can either set a URL here or set the home page to open the new tab page. If you select to open the new tab page, then this policy doesn't take effect.\n\nIf you enable this policy, users can't change their home page URL, but they can choose to use the new tab page as their home page.\n\nIf you disable or don't configure this policy, users can choose their own home page, as long as the \"HomepageIsNewTabPage\" policy isn't enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#homepagelocation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_howtocheck","displayName":"Enable AutoUpdate","description":"Specifies whether AutoUpdate should download and install updates. This value should be true unless you need to temporarily halt all updates.","helpText":null,"infoUrls":["https://support.microsoft.com/office/update-office-for-mac-automatically-bfd1e497-c24d-4754-92ab-910a4074d7c1"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_howtocheck_0","displayName":"True","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_howtocheck_1","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_howtocheck_2","displayName":"Manual Check","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hstspolicybypasslist","displayName":"Configure the list of names that will bypass the HSTS policy check","description":"Hostnames specified in this list will be exempt from the HSTS policy check that could potentially upgrade requests from \"http://\" to \"https://\". Only single-label hostnames are allowed in this policy. Hostnames must be canonicalized. Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific hostnames specified; it doesn't apply to subdomains of the names in the list.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#hstspolicybypasslist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_httpallowlist","displayName":"HTTP Allowlist","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that won't be upgraded to HTTPS. Organizations can use this policy to maintain access to servers that don't support HTTPS, without needing to disable \"HttpsUpgradesEnabled\".\n\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase.\n\nBlanket host wildcards (that is, \"*\" or \"[*]\") aren't allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies.\n\nNote: This policy doesn't apply to HSTS upgrades.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#httpallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled","description":"This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigations to HTTPS.\n\nIf this setting isn't set or is set to allowed, users are able to enable HTTPS-Only Mode.\nIf this setting is set to `disallowed`, users can't enable HTTPS-Only Mode.\nIf this setting is set to force_enabled, HTTPS-Only Mode is enabled in Strict mode and users can't disable it.\nIf this setting is set to force_balanced_enabled, HTTPS-Only Mode is enabled in Balanced mode and users can't disable it.\n\nIf you set this policy to a value that isn't supported by the version of Microsoft Edge that receives the policy, Microsoft Edge defaults to the allowed setting.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nPolicy options mapping:\n\n* allowed (allowed) = Don't restrict users' HTTPS-Only Mode setting\n\n* disallowed (disallowed) = Don't allow users to enable any HTTPS-Only Mode\n\n* force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode\n\n* force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#httpsonlymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_httpsonlymode_0","displayName":"Don't restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_httpsonlymode_1","displayName":"Don't allow users to enable any HTTPS-Only Mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_httpsonlymode_2","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_httpsonlymode_3","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_httpsupgradesenabled","displayName":"Enable automatic HTTPS upgrades","description":"As of Microsoft Edge version 120, Microsoft Edge tries to upgrade HTTP navigations to HTTPS whenever possible to improve security. Navigations to captive portals, IP addresses, and non-unique hostnames are excluded from automatic upgrades.\n\nIf this policy is enabled or not configured, automatic HTTPS upgrades are turned on by default.\n\nIf this policy is disabled, Microsoft Edge won't attempt to upgrade HTTP connections to HTTPS.\n\nTo exempt specific hostnames or hostname patterns from being upgraded, use the HttpAllowlist policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#httpsupgradesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_httpsupgradesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_httpsupgradesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hubssidebarenabled","displayName":"Show Hubs Sidebar","description":"The Sidebar is a launcher bar located on the right side of Microsoft Edge.\n\nIf you enable this policy, the Sidebar is always visible.\n\nIf you disable this policy, the Sidebar is never shown.\n\nIf you don't configure this policy, the Sidebar's visibility follows the user's Microsoft Edge settings.\n\nAs of Microsoft Edge version 141, the \"Microsoft365CopilotChatIconEnabled\" policy is the only means of controlling the display of Copilot in the toolbar.\n\nNote: The recommended version of this policy-also known as the \"Default Settings (users can override)\" policy-is obsolete. This policy has never supported the recommended capability.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#hubssidebarenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_hubssidebarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hubssidebarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_idletimeout","displayName":"Delay before running idle actions","description":"Triggers an action when the computer is idle.\n\nIf you set this policy, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy.\n\nIf you do not set this policy, no action will run.\n\nThe minimum threshold is 1 minute.\n\n\"User input\" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#idletimeout"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_idletimeoutactions","displayName":"Actions to run when the computer is idle","description":"When the timeout from the IdleTimeout policy is reached, the browser runs the actions configured in this policy.\n\nIf you don't configure the IdleTimeout policy, this policy has no effect.\n\nIf you don't configure this policy or no actions are selected, the IdleTimeout policy has no effect.\n\nSupported actions are:\n\n'close_browsers': close all browser windows and PWAs for this profile.\n\n'reload_pages': reload all webpages. For some pages, the user might be prompted for confirmation first.\n\n'sign_out': sign out of browser. (This action only applies to iOS.)\n\n'close_tabs': close all open tabs and create an NTP (New Tab Page). Supported in Android and iOS.\n\n'clear_browsing_history', 'clear_download_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', 'clear_autofill', 'clear_site_settings': clear the corresponding browsing data. Deleting cookies using this policy doesn't sign the user out of their profile, the user stays signed in.\n\nSetting 'clear_browsing_history', 'clear_password_signing', 'clear_autofill', and 'clear_site_settings' disables sync for the respective data types if sync isn't already disabled by setting either the SyncDisabled policy or BrowserSignin to disabled.\n\nPolicy options mapping:\n\n* close_browsers (close_browsers) = Close Browsers\n\n* clear_browsing_history (clear_browsing_history) = Clear Browsing History\n\n* clear_download_history (clear_download_history) = Clear Download History\n\n* clear_cookies_and_other_site_data (clear_cookies_and_other_site_data) = Clear Cookies and Other Site Data\n\n* clear_cached_images_and_files (clear_cached_images_and_files) = Clear Cached Images and Files\n\n* clear_password_signin (clear_password_signin) = Clear Password sign in\n\n* clear_autofill (clear_autofill) = Clear Autofill\n\n* clear_site_settings (clear_site_settings) = Clear Site Settings\n\n* reload_pages (reload_pages) = Reload Pages\n\n* sign_out (sign_out) = Sign Out\n\n* close_tabs (close_tabs) = Close Tabs\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#idletimeoutactions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_ignoreexclusions","displayName":"Ignore exclusions","description":"Should exclusions be ignored during a scheduled scan","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":[{"id":"com.apple.managedclient.preferences_ignoreexclusions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_ignoreexclusions_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_imagesallowedforurls","displayName":"Allow images on these sites","description":"Define a list of sites, based on URL patterns, that can display images.\n\nIf you don't configure this policy, the global default value is used for all sites either from the \"DefaultImagesSetting\" policy (if set) or the user's personal configuration.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#imagesallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_imagesblockedforurls","displayName":"Block images on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to display images.\n\nIf you don't configure this policy, the global default value from the \"DefaultImagesSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#imagesblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_importautofillformdata","displayName":"Allow importing of autofill form data","description":"Allows users to import autofill form data from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import autofill data is automatically selected.\n\nIf you disable this policy, autofill form data isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge will import autofill data on first run, but users can select or clear **autofill data** option during manual import.\n\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importautofillformdata"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importautofillformdata_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importautofillformdata_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importbrowsersettings","displayName":"Allow importing of browser settings","description":"Allows users to import browser settings from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, browser settings aren't imported at first run, and users can’t import them manually.\n\nIf you don’t configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\n\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importbrowsersettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importbrowsersettings_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importbrowsersettings_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importcookies","displayName":"Allow importing of Cookies","description":"Allows users to import Cookies from another browser into Microsoft Edge.\n\nIf you disable this policy, Cookies aren't imported on first run.\n\nIf you don’t configure this policy, Cookies are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\n\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importcookies"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importcookies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importextensions","displayName":"Allow importing of extensions","description":"Allows users to import extensions from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **favorites** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importextensions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importextensions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importextensions_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importfavorites","displayName":"Allow importing of favorites","description":"Allows users to import favorites from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Favorites** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, favorites aren't imported at first run, and users can’t import them manually.\n\nIf you don’t configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS) and Apple Safari (on macOS) browsers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importfavorites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importfavorites_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importfavorites_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importhistory","displayName":"Allow importing of browsing history","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Browsing history** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, browsing history data isn't imported at first run, and users can’t import this data manually.\n\nIf you don’t configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS) and Apple Safari (macOS) browsers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importhistory"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importhistory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importhistory_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importhomepage","displayName":"Allow importing of home page settings","description":"Allows users to import their home page setting from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import the home page setting is automatically selected.\n\nIf you disable this policy, the home page setting isn’t imported at first run, and users can’t import it manually.\n\nIf you don’t configure this policy, the home page setting is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports the home page setting on first run, but users can select or clear the **home page** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importhomepage"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importhomepage_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importhomepage_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importopentabs","displayName":"Allow importing of open tabs","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importopentabs"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importopentabs_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importopentabs_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importpaymentinfo","displayName":"Allow importing of payment info","description":"Allows users to import payment info from another browser into Microsoft Edge.\n\nIf you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, payment info isn’t imported at first run, and users can’t import it manually.\n\nIf you don’t configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import.\n\n**Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importpaymentinfo"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importpaymentinfo_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importpaymentinfo_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importsavedpasswords","displayName":"Allow importing of saved passwords","description":"Allows users to import saved passwords from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import saved passwords is automatically selected.\n\nIf you disable this policy, saved passwords aren't imported on first run, and users can't import them manually.\n\nIf you don't configure this policy, passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10) and Google Chrome (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importsavedpasswords"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importsavedpasswords_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importsavedpasswords_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importsearchengine","displayName":"Allow importing of search engine settings","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\n\nIf you enable, this policy, the option to import search engine settings is automatically selected.\n\nIf you disable this policy, search engine settings aren't imported at first run, and users can’t import them manually.\n\nIf you don’t configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importsearchengine"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importsearchengine_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importsearchengine_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importshortcuts","displayName":"Allow importing of shortcuts","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\n\nIf you disable this policy, Shortcuts aren't imported on first run.\n\nIf you don’t configure this policy, Shortcuts are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\n\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importshortcuts"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importshortcuts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importshortcuts_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_inappsupportenabled","displayName":"In-app support Enabled","description":"Microsoft Edge uses the in-app support feature (enabled by default) to allow users to contact our support agents directly from the browser. Also, by default, users can't disable (turn off) the in-app support feature.\n\nIf you enable this policy or don't configure it, users can invoke in-app support.\n\nIf you disable this policy, users can't invoke in-app support.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#inappsupportenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_inappsupportenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_inappsupportenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_inprivatemodeavailability","displayName":"Configure InPrivate mode availability","description":"Specifies whether the user can open pages in InPrivate mode in Microsoft Edge.\n\nIf you don't configure this policy or set it to 'Enabled' (0), users can open pages in InPrivate mode.\n\nSet this policy to 'Disable' (1) to stop users from using InPrivate mode.\n\nSet this policy to 'Forced' (2) to always use InPrivate mode.\n\n* 0 = InPrivate mode available\n\n* 1 = InPrivate mode disabled\n\n* 2 = InPrivate mode forced","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#inprivatemodeavailability"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_inprivatemodeavailability_0","displayName":"InPrivate mode available","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_inprivatemodeavailability_1","displayName":"InPrivate mode disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_inprivatemodeavailability_2","displayName":"InPrivate mode forced","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_insecurecontentallowedforurls","displayName":"Allow insecure content on specified sites","description":"Create a list of URL patterns to specify sites that can display insecure mixed content (that is, HTTP content on HTTPS sites).\n\nIf you don't configure this policy, blockable mixed content will be blocked and optionally blockable mixed content will be upgraded. However, users will be allowed to set exceptions to allow insecure mixed content for specific sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecurecontentallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_insecurecontentblockedforurls","displayName":"Block insecure content on specified sites","description":"Create a list of URL patterns to specify sites that aren't allowed to display blockable (i.e. active) mixed content (that is, HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled.\n\nIf you don't configure this policy, blockable mixed content will be blocked and optionally blockable mixed content will be upgraded. However, users will be allowed to set exceptions to allow insecure mixed content for specific sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecurecontentblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_insecureformswarningsenabled","displayName":"Enable warnings for insecure forms (deprecated)","description":"This policy controls the handling of insecure forms (forms submitted over HTTP) embedded in secure (HTTPS) sites in the browser.\nIf you enable this policy or don't set it, a full page warning will be shown when an insecure form is submitted. Additionally, a warning bubble will be shown next to the form fields when they are focused, and autofill will be disabled for those forms.\nIf you disable this policy, warnings will not be shown for insecure forms, and autofill will work normally.\n\nThis policy may be removed as soon as Edge 132. The feature is enabled by default since Edge 131.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecureformswarningsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_insecureformswarningsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_insecureformswarningsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_insecureprivatenetworkrequestsallowed","displayName":"Specifies whether to allow websites to make requests to any network endpoint in an insecure manner. (Deprecated)","description":"Controls whether websites are allowed to make requests to more-private network endpoints.\n\nWhen this policy is enabled, all Private Network Access checks are disabled for all origins. This may allow attackers to perform cross-site request forgery (CSRF) attacks on private network servers.\n\nWhen this policy is disabled or not configured, the default behavior for requests to more-private network endpoints will depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests, PrivateNetworkAccessSendPreflights, and PrivateNetworkAccessRespectPreflightResults feature flags. These flags may be controlled by experimentation or set via the command line.\n\nThis policy relates to the Private Network Access specification. See https://wicg.github.io/private-network-access/ for more details.\n\nA network endpoint is more private than another if:\n1) Its IP address is localhost and the other is not.\n2) Its IP address is private and the other is public.\nIn the future, depending on spec evolution, this policy might apply to all cross-origin requests directed at private IPs or localhost.\n\nWhen this policy enabled, websites are allowed to make requests to any network endpoint, subject to other cross-origin checks.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecureprivatenetworkrequestsallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_insecureprivatenetworkrequestsallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_insecureprivatenetworkrequestsallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from in an insecure manner (Deprecated)","description":"List of URL patterns. Requests initiated from websites served by matching origins are not subject to Private Network Access checks.\n\nIf this policy is not set, this policy behaves as if set to the empty list.\n\nFor origins not covered by the patterns specified here, the global default value will be used either from the \"InsecurePrivateNetworkRequestsAllowed\" policy, if it is set, or the user's personal configuration otherwise.\n\nFor detailed information on valid URL patterns, see [Filter format for URL list-based policies](/DeployEdge/edge-learnmmore-url-list-filter%20format).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecureprivatenetworkrequestsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_intensivewakeupthrottlingenabled","displayName":"Control the IntensiveWakeUpThrottling feature","description":"When enabled the IntensiveWakeUpThrottling feature causes Javascript timers in background tabs to be aggressively throttled and coalesced, running no more than once per minute after a page has been backgrounded for 5 minutes or more.\n\nThis is a web standards compliant feature, but it may break functionality on some websites by causing certain actions to be delayed by up to a minute. However, it results in significant CPU and battery savings when enabled. See https://bit.ly/30b1XR4 for more details.\n\nIf you enable this policy, the feature will be force enabled, and users will not be able to override this setting.\nIf you disable this policy, the feature will be force disabled, and users will not be able to override this setting.\nIf you don't configure this policy, the feature will be controlled by its own internal logic. Users can manually configure this setting.\n\nNote that the policy is applied per renderer process, with the most recent value of the policy setting in force when a renderer process starts. A full restart is required to ensure that all the loaded tabs receive a consistent policy setting. It is harmless for processes to be running with different values of this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#intensivewakeupthrottlingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_intensivewakeupthrottlingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intensivewakeupthrottlingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior","displayName":"Intranet Redirection Behavior","description":"This policy configures behavior for intranet redirection via DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\n\nIf this policy isn't configured, the browser will use the default behavior of DNS interception checks and intranet redirect suggestions. In M88, they are enabled by default but will be disabled by default in the future release.\n\n\"DNSInterceptionChecksEnabled\" is a related policy that might also disable DNS interception checks. However, this policy is a more flexible version which might separately control intranet redirection infobars and might be expanded in the future.\nIf either \"DNSInterceptionChecksEnabled\" or this policy make a request to disable interception checks, the checks will be disabled.\nIf DNS interception checks are disabled by this policy but \"GoToIntranetSiteForSingleWordEntryInAddressBar\" is enabled, single word queries will still result in intranet navigations.\n\nPolicy options mapping:\n\n* Default (0) = Use default browser behavior.\n\n* DisableInterceptionChecksDisableInfobar (1) = Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.\n\n* DisableInterceptionChecksEnableInfobar (2) = Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.\n\n* EnableInterceptionChecksEnableInfobar (3) = Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#intranetredirectbehavior"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_0","displayName":"Use default browser behavior.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_1","displayName":"Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_2","displayName":"Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_3","displayName":"Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_ipv6reachabilityoverrideenabled","displayName":"Enable IPv6 reachability check override","description":"This policy enables an override of the IPv6 reachability check. When overridden, the\nsystem will always query AAAA records when resolving host names. It applies to\nall users and interfaces on the device.\n\nIf you enable this policy, the IPv6 reachability check will be overridden.\n\nIf you disable or don't configure this policy, the IPv6 reachability check will not be overridden.\nThe system only queries AAAA records when it is reachable to a global IPv6 host.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#ipv6reachabilityoverrideenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_ipv6reachabilityoverrideenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_ipv6reachabilityoverrideenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_isolateorigins","displayName":"Enable site isolation for specific origins","description":"Specify origins to run in isolation, in their own process.\nThis policy also isolates origins named by subdomains - for example, specifying https://contoso.com/ will cause https://foo.contoso.com/ to be isolated as part of the https://contoso.com/ site.\nIf the policy is enabled, each of the named origins in a comma-separated list will run in its own process.\nIf you disable this policy, then both the 'IsolateOrigins' and 'SitePerProcess' features are disabled. Users can still enable 'IsolateOrigins' policy manually, via command line flags.\nIf you don't configure the policy, the user can change this setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#isolateorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_javascriptallowedforurls","displayName":"Allow JavaScript on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to run JavaScript.\n\nIf you don't configure this policy, the global default value from the \"DefaultJavaScriptSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_javascriptblockedforurls","displayName":"Block JavaScript on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to run JavaScript.\n\nIf you don't configure this policy, the global default value from the \"DefaultJavaScriptSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\n\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitAllowedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT enabled, but fabrikam.com will use the policy from \"DefaultJavaScriptJitSetting\", if set, or default to JavaScript JIT enabled.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptJitSetting\" applies to the site, if set, otherwise Javascript JIT is enabled for the site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptjitallowedforsites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_javascriptjitblockedforsites","displayName":"Block JavaScript from using JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are not allowed to run JavaScript JIT (Just In Time) compiler enabled.\n\nDisabling the JavaScript JIT will mean that Microsoft Edge may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Microsoft Edge to render web content in a more secure configuration.\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitBlockedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT disabled, but fabrikam.com will use the policy from \"DefaultJavaScriptJitSetting\", if set, or default to JavaScript JIT enabled.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptJitSetting\" applies to the site, if set, otherwise JavaScript JIT is enabled for the site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptjitblockedforsites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are enabled.\n\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the \"JavaScriptOptimizerAllowedForSites\" policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations enabled, but fabrikam.com will use the policy from \"DefaultJavaScriptOptimizerSetting\", if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptOptimizerSetting\" applies to the site, if set, otherwise Javascript optimization is enabled for the site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptoptimizerallowedforsites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are disabled.\n\nDisabling JavaScript optimizations will mean that Microsoft Edge may render web content more slowly.\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the \"JavaScriptOptimizerBlockedForSites\" policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations disabled, but fabrikam.com will use the policy from \"DefaultJavaScriptOptimizerSetting\", if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptOptimizerSetting\" applies to the site, if set, otherwise JavaScript optimization is enabled for the site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptoptimizerblockedforsites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_keyboardfocusablescrollersenabled","displayName":"Enable keyboard focusable scrollers (Deprecated)","description":"This policy provides a temporary opt-out for the new keyboard focusable scrollers behavior.\n\nWhen this policy is Enabled or unset, scrollers without focusable children are keyboard focusable by default. Further, scrollers are click focusable and programmatically focusable by default.\n\nWhen this policy is Disabled, scrollers are not focusable by default.\n\nThis policy is a temporary workaround and will be removed in Edge Stable 135.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#keyboardfocusablescrollersenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_keyboardfocusablescrollersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_keyboardfocusablescrollersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_kfmblockoptin","displayName":"Prevent users from using the Folder Backup feature (Known Folder Move)","description":"This setting prevents users from moving their Documents and Desktop folders to any OneDrive account.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmblockoptin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_kfmblockoptin_0","displayName":"No prevention","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmblockoptin_1","displayName":"Prevent Folder Backup","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmblockoptin_2","displayName":"Prevent Folder Backup and Redirect to local device","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_kfmblockoptout","displayName":"Force users to use the Folder Backup feature (Known Folder Move)","description":"This setting forces users to keep their Documents and Desktop folders directed to OneDrive.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmblockoptout"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_kfmblockoptout_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmblockoptout_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_kfmoptinwithwizard","displayName":"Prompt users to enable the Folder Backup feature (Known Folder Move)","description":"This setting displays a wizard that prompts users to move their Documents and Desktop folders to OneDrive. Enter your Microsoft 365 tenant ID to enable this feature.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmoptinwithwizard"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_kfmsilentoptin","displayName":"Automatically and silently enable the Folder Backup feature (Known Folder Move)","description":"Use this setting to redirect and move your users Documents and/or Desktop folders to OneDrive without any user interaction. Enter your Microsoft 365 tenant ID to enable this feature.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmsilentoptin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_kfmsilentoptindesktop","displayName":"Include ~/Desktop in Folder Backup (Known Folder Move)","description":null,"helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmsilentoptin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_kfmsilentoptindesktop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmsilentoptindesktop_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_kfmsilentoptindocuments","displayName":"Include ~/Documents in Folder Backup (Known Folder Move)","description":null,"helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmsilentoptin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_kfmsilentoptindocuments_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmsilentoptindocuments_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_kfmsilentoptinwithnotification","displayName":"Display a notification to users once their folders have been redirected","description":"Display a notification to users once their folders have been redirected","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmsilentoptin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_kfmsilentoptinwithnotification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmsilentoptinwithnotification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_kioskaddressbareditingenabled","displayName":"Configure address bar editing for kiosk mode public browsing experience","description":"This policy only applies to Microsoft Edge kiosk mode while using the public browsing experience.\r\n\r\nIf you enable or don't configure this policy, users can change the URL in the address bar.\r\n\r\nIf you disable this policy, it prevents users from changing the URL in the address bar.\r\n\r\nFor detailed information on configuring kiosk Mode, see https://go.microsoft.com/fwlink/?linkid=2137578.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#kioskaddressbareditingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_kioskaddressbareditingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kioskaddressbareditingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_legacysamesitecookiebehaviorenabled","displayName":"Enable default legacy SameSite cookie behavior setting","description":"Lets you revert all cookies to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", and removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute.\n\nYou can set the following values for this policy:\n\n* 1 = Revert to legacy SameSite behavior for cookies on all sites\n\n* 2 = Use SameSite-by-default behavior for cookies on all sites\n\nIf you don't set this policy, the default behavior for cookies that don't specify a SameSite attribute will depend on other configuration sources for the SameSite-by-default feature. This feature might be set by a field trial or by enabling the same-site-by-default-cookies flag in edge://flags.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#legacysamesitecookiebehaviorenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_legacysamesitecookiebehaviorenabled_0","displayName":"Revert to legacy SameSite behavior for cookies on all sites","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_legacysamesitecookiebehaviorenabled_1","displayName":"Use SameSite-by-default behavior for cookies on all sites","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_legacysamesitecookiebehaviorenabledfordomainlist","displayName":"Revert to legacy SameSite behavior for cookies on specified sites (Deprecated)","description":"Cookies set for domains match specified patterns will revert to legacy SameSite behavior.\n\nReverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", and removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute.\n\nIf you don't set this policy, the global default value will be used. The global default will also be used for cookies on domains not covered by the patterns you specify.\n\nThe global default value can be configured using the \"LegacySameSiteCookieBehaviorEnabled\" policy. If \"LegacySameSiteCookieBehaviorEnabled\" is unset, the global default value falls back to other configuration sources.\n\nNote that patterns you list in this policy are treated as domains, not URLs, so you should not specify a scheme or port.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#legacysamesitecookiebehaviorenabledfordomainlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_linkedaccountenabled","displayName":"Enable the linked account feature (Deprecated)","description":"Microsoft Edge guides a user to the account management page where they can link a Microsoft Account (MSA) to an Azure Active Directory (Azure AD) account.\n\nIf you enable or don't configure this policy, linked account information will be shown on a flyout. When the Azure AD profile doesn't have a linked account it will show \"Add account\".\n\nIf you disable this policy, linked accounts will be turned off and no extra information will be shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#linkedaccountenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_linkedaccountenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_linkedaccountenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_localnetworkaccessallowedforurls","displayName":"Allow sites to make requests to local network endpoints.","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions.\n\nIf an origin is specified by both this policy and the \"LocalNetworkAccessBlockedForUrls\" policy, the blocked list takes precedence.\n\nFor origins not covered by this policy, the user's personal settings and local network access restrictions will apply.\n\nFor guidance on valid URL pattern syntax, see:\nhttps://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns\n\nNote: This policy enables controlled exceptions to local network access restrictions. It allows specific public websites to access private IP addresses when necessary for trusted local communication scenarios. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localnetworkaccessallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_localnetworkaccessblockedforurls","displayName":"Block sites from making requests to local network endpoints.","description":"List of URL patterns. Requests initiated from websites served by matching origins are blocked from issuing Local Network Access requests.\n\nIf an origin is covered by both this policy and by \"LocalNetworkAccessAllowedForUrls\", this policy takes precedence.\n\nDepending on the stage of the rollout of Local Network Access, LocalNetworkAccessRestrictionsEnabled may also need to be enabled for this policy to block Local Network Access requests.\n\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\n\nFor detailed information on valid URL patterns, please see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\n\nNote: This policy improves local network security by blocking specified public websites from accessing private IP addresses. It helps prevent unauthorized external sites from reaching internal resources unless explicitly permitted. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localnetworkaccessblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to block requests from public websites to devices on a user's local network. (deprecated)","description":"Local Network Access restrictions prevent public websites from making\nrequests to devices on a user's local network without explicit user permission.\n\nIf you enable this policy, Microsoft Edge blocks\nany request that would otherwise trigger a DevTools warning\ndue to Local Network Access checks.\nThese requests are denied without prompting the user.\n\nIf you disable or don't configure this policy, Microsoft Edge handles\nthese requests using the default behavior, which may include showing warnings in DevTools\nand allowing the request to proceed depending on the context.\n\nNote: This feature improves local network security by deprecating direct access to private IP addresses from public websites\nunless explicitly granted by the user. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.\n\nStarting in version 140, Microsoft Edge introduces support for policies that manage Local Network Access behavior on a per-URL basis.\n\nYou can configure exceptions to allow specific URLs to bypass Local Network Access restrictions.\n\nYou can also block specific URLs from making Local Network Access requests.\n\nStarting from Microsoft Edge version 144, this policy is deprecated because Local Network Access restrictions is enabled by default. The policy will be removed in a future release.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localnetworkaccessrestrictionsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionstemporaryoptout","displayName":"Specifies whether to opt out of Local Network Access restrictions","description":"This policy allows for opting out of restrictions on requests to local network endpoints.\n\nIf you enable this policy, Local Network Access requests will only display warnings in Edge DevTools when Local Network Access checks fail.\n\nIf you disable or don't configure this policy, Local Network Access requests will follow the default handling behavior.\n\nFor more information about Local Network Access restrictions, see Local Network Access .\n\nTo allow specific URL patterns that should automatically be granted Local Network Access permission, use the LocalNetworkAccessAllowedForUrls policy.\n\nNote: This opt-out policy is temporary and will be removed after Microsoft Edge version 152.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localnetworkaccessrestrictionstemporaryoptout"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionstemporaryoptout_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionstemporaryoptout_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_localprovidersenabled","displayName":"Allow suggestions from local providers","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\n\nIf you enable this policy, suggestions from local providers are used.\n\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions will not appear.\n\nIf you do not configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\n\nNote that some features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the \"SavingBrowserHistoryDisabled\" policy.\n\nThis policy requires a browser restart to finish applying.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localprovidersenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_localprovidersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_localprovidersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_lowpriorityscheduledscan","displayName":"Low priority scheduled scan","description":"Should scheduled scan be run with low priority. (Scan might take longer to complete).","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":[{"id":"com.apple.managedclient.preferences_lowpriorityscheduledscan_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_lowpriorityscheduledscan_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_managedsearchengines","displayName":"Managed Search Engines","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine.\nYou do not need to specify the encoding. Starting in Microsoft Edge 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge 80.\n\nStarting in Microsoft Edge 83, you can enable search engine discovery with the allow_search_engine_discovery optional parameter. This parameter must be the first item in the list. If allow_search_engine_discovery is not specified, search engine discovery will be disabled by default. Starting in Microsoft Edge 84, you can set this policy as a recommended policy to allow search provider discovery. You do not need to add the allow_search_engine_discovery optional parameter.\n\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\n\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\n\nIf the \"DefaultSearchProviderSearchURL\" policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#managedsearchengines"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_allow_search_engine_discovery","displayName":"Allow search engine discovery","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_managedsearchengines_item_allow_search_engine_discovery_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_allow_search_engine_discovery_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_encoding","displayName":"Encoding","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_image_search_post_params","displayName":"Image search post params","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_image_search_url","displayName":"Image search URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_is_default","displayName":"Is default","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_managedsearchengines_item_is_default_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_is_default_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_keyword","displayName":"Keyword","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_name","displayName":"Name","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_search_url","displayName":"Search URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_suggest_url","displayName":"Suggest URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_mandatoryextensionsforinprivatenavigation","displayName":"Specify extensions users must allow in order to navigate using InPrivate mode","description":"This policy lets you specify a list of extension IDs that must be explicitly allowed by the user to run in InPrivate mode in order to enable InPrivate browsing.\n\nIf users don't allow all listed extensions to run in InPrivate mode, they'll be unable to navigate using InPrivate.\n\nIf any extension in the list isn't installed, InPrivate navigation is blocked.\n\nThis policy only applies when InPrivate mode is enabled. If InPrivate mode is disabled using the InPrivateModeAvailability policy, this policy has no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#mandatoryextensionsforinprivatenavigation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_manifestserver","displayName":"Deferred updates (Deprecated)","description":"You can tell AutoUpdate to either a) wait for a number of days to pass before downloading updates from the Current Channel, or b) stop Office from advancing beyond a given version. Deferred updates only affects Word, Excel, PowerPoint, Outlook, and OneNote. Other applications such as Edge, Defender, and Company Portal will receive updates based on the regular Current Channel schedule.","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_manifestserver_0","displayName":"Defer 3 days","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_1","displayName":"Defer 7 days","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_2","displayName":"Defer 14 days","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_3","displayName":"Defer 21 days","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_4","displayName":"Defer 28 days","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_5","displayName":"Defer 45 days","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_6","displayName":"Pause at 16.64 (August 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_7","displayName":"Pause at 16.63 (July 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_8","displayName":"Pause at 16.62 (June 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_9","displayName":"Pause at 16.61 (May 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_10","displayName":"Pause at 16.60 (April 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_11","displayName":"Pause at 16.59 (March 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_12","displayName":"Pause at 16.58 (February 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_13","displayName":"Pause at 16.57 (January 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_14","displayName":"Pause at 16.56 (December 2021 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_15","displayName":"Pause at 16.55 (November 2021 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_16","displayName":"Pause at 16.54 (October 2021 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_17","displayName":"Pause at 16.53 (September 2021 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_18","displayName":"Pause at 16.52 (August 2021 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_19","displayName":"Pause at 16.51 (July 2021 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_20","displayName":"Pause at 16.80 (December 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_21","displayName":"Pause at 16.79 (November 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_22","displayName":"Pause at 16.78 (October 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_23","displayName":"Pause at 16.77 (September 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_24","displayName":"Pause at 16.76 (August 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_25","displayName":"Pause at 16.75 (July 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_26","displayName":"Pause at 16.74 (June 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_27","displayName":"Pause at 16.73 (May 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_28","displayName":"Pause at 16.72 (April 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_29","displayName":"Pause at 16.71 (March 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_30","displayName":"Pause at 16.70 (February 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_31","displayName":"Pause at 16.69 (January 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_32","displayName":"Pause at 16.68 (December 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_33","displayName":"Pause at 16.67 (November 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_34","displayName":"Pause at 16.66 (October 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_35","displayName":"Pause at 16.65 (September 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_36","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_maxconnectionsperproxy","displayName":"Maximum number of concurrent connections to the proxy server","description":"Specifies the maximum number of simultaneous connections to the proxy server.\n\nSome proxy servers can't handle a high number of concurrent connections per client - you can solve this by setting this policy to a lower value.\n\nThe value of this policy should be lower than 100 and higher than 6. The default value is 32.\n\nSome web apps are known to consume many connections with hanging GETs - lowering the maximum connections below 32 may lead to browser networking hangs if too many of these kind of web apps are open.\n\nIf you don't configure this policy, the default value (32) is used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#maxconnectionsperproxy"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_maximumondemandscanthreads","displayName":"Degree of parallelism for on-demand scans","description":"Specifies the degree of parallelism for on-demand scans. This corresponds to the number of threads used to perform the scan and impacts the CPU usage, as well as the duration of the on-demand scan.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#degree-of-parallelism-for-on-demand-scans"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_mediaroutercastallowallips","displayName":"Allow Google Cast to connect to Cast devices on all IP addresses","description":"Enable this policy to let Google Cast connect to Cast devices on all IP addresses, not just RFC1918/RFC4193 private addresses.\n\nDisable this policy to restrict Google Cast to Cast devices on RFC1918/RFC4193 private addresses.\n\nIf you don't configure this policy, Google Cast connects to Cast devices on RFC1918/RFC4193 private addresses only, unless you enable the CastAllowAllIPs feature.\n\nIf the \"EnableMediaRouter\" policy is disabled, then this policy has no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#mediaroutercastallowallips"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_mediaroutercastallowallips_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_mediaroutercastallowallips_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_merge_policy","displayName":"Performance profiles merge policy","description":"Specify the merge policy for performance profiles. This can be a combination of administrator-defined and user-defined profiles (merge) or only administrator-defined profiles (admin_only).","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/performance-profiles"],"categoryId":"d40a32e1-ab3e-4cbc-aa03-4766792e563e","categoryName":"Performance Profiles Configuration","options":[{"id":"com.apple.managedclient.preferences_merge_policy_0","displayName":"merge","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_merge_policy_1","displayName":"admin_only","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_metricsreportingenabled","displayName":"Enable usage and crash-related data reporting","description":"This policy enables reporting of usage and crash-related data about Microsoft Edge to Microsoft.\n\nEnable this policy to send reporting of usage and crash-related data to Microsoft. Disable this policy to not send the data to Microsoft. In both cases, users can't change or override the setting.\n\nOn Windows 10, Beta and Stable channels, if you don’t configure this policy, Microsoft Edge will default to the Windows diagnostic data setting. If you enable this policy, Microsoft Edge will only send usage data if the Windows Diagnostic data setting is set to Enhanced or Full. If you disable this policy, Microsoft Edge will not send usage data. Crash-related data is sent based on the Windows Diagnostic data setting. Learn more about Windows Diagnostic data settings at https://go.microsoft.com/fwlink/?linkid=2099569\n\nOn Windows 10, Canary and Dev channels, this policy controls sending usage data. If this policy is not configured, Microsoft Edge will default to the user's preference. Crash-related data is sent based on the Windows Diagnostic data setting. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\n\nOn Windows 7, 8, and macOS, this policy controls sending usage and crash-related data. If you don’t configure this policy, Microsoft Edge will default to the user's preference.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#metricsreportingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_metricsreportingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_metricsreportingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_microsoft365copilotchaticonenabled","displayName":"Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar","description":"For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon will be shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users.\n\nThis policy only applies when users are accessing Copilot in the sidepane.\n\nIf the policy is enabled: Copilot will appear in the toolbar.\n\nIf the policy is disabled: Copilot won't appear in the toolbar.\n\nIf the policy isn't configured: Otherwise, Copilot shows in the toolbar and users may enable or disable Copilot from showing by using the Show Copilot toggle in settings.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#microsoft365copilotchaticonenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_microsoft365copilotchaticonenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_microsoft365copilotchaticonenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_microsoftedgeinsiderpromotionenabled","displayName":"Microsoft Edge Insider Promotion Enabled","description":"Shows content promoting the Microsoft Edge Insider channels on the About Microsoft Edge settings page.\n\nIf you enable or don't configure this policy, the Microsoft Edge Insider promotion content will be shown on the About Microsoft Edge page.\n\nIf you disable this policy, the Microsoft Edge Insider promotion content will not be shown on the About Microsoft Edge page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#microsoftedgeinsiderpromotionenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_microsoftedgeinsiderpromotionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_microsoftedgeinsiderpromotionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_microsofteditorproofingenabled","displayName":"Spell checking provided by Microsoft Editor","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages.\n\nIf you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields.\n\nIf you disable this policy, spell check can only be provided by local engines that use platform or Hunspell services. The results from these engines might be less informative than the results Microsoft Editor can provide.\n\nIf the \"SpellcheckEnabled\" policy is set to disabled, or the user disables spell checking in the settings page, this policy will have no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#microsofteditorproofingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_microsofteditorproofingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_microsofteditorproofingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_microsofteditorsynonymsenabled","displayName":"Synonyms are provided when using Microsoft Editor spell checker","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages, and synonyms can be suggested as an integrated feature.\n\nIf you enable this policy, Microsoft Editor spell checker will provide synonyms for suggestions for misspelled words.\n\nIf you disable or don't configure this policy, Microsoft Editor spell checker will not provide synonyms for suggestions for misspelled words.\n\nIf the \"SpellcheckEnabled\" policy or the \"MicrosoftEditorProofingEnabled\" policy are set to disabled, or the user disables spell checking or chooses not to use Microsoft Editor spell checker in the settings page, this policy will have no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#microsofteditorsynonymsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_microsofteditorsynonymsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_microsofteditorsynonymsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_msawebsitessousingthisprofileallowed","displayName":"Allow single sign-on for Microsoft personal sites using this profile","description":"'Allow single sign-on for Microsoft personal sites using this profile' option allows non-MSA profiles to be able to use single sign-on for Microsoft sites using MSA credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-MSA profiles only.\n\nIf you disable this policy, non-MSA profiles will not be able to use single sign-on for Microsoft sites using MSA credentials present on the machine.\n\nIf you enable this policy or don't configure it, users will be able to use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#msawebsitessousingthisprofileallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_msawebsitessousingthisprofileallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_msawebsitessousingthisprofileallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_mutationeventsenabled","displayName":"Enable deprecated/removed Mutation Events (Deprecated)","description":"This policy provides a temporary opt-in back to a deprecated and removed set of platform events named Mutation Events.\n\nIf you enable this policy, mutation events will continue to be fired, even if they've been disabled by default for normal web users.\n\nIf you disable or don't configure this policy, these events will not be fired.\n\nThis policy is a temporary workaround, and enterprises should still work to remove their dependencies on these mutation events.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#mutationeventsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_mutationeventsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_mutationeventsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_nativemessagingallowlist","displayName":"Control which native messaging hosts users can use","description":"List specific native messaging hosts that users can use in Microsoft Edge.\n\nBy default, all native messaging hosts are allowed. If you set the \"NativeMessagingBlocklist\" policy to *, all native messaging hosts are blocked, and only native messaging hosts listed in here are loaded.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#nativemessagingallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_nativemessagingblocklist","displayName":"Configure native messaging block list","description":"Specifies which native messaging hosts that shouldn't be used.\n\nUse '*' to block all native messaging hosts unless they are explicitly listed in the allow list.\n\nIf you don't configure this policy, Microsoft Edge will load all installed native messaging hosts.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#nativemessagingblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_nativemessaginguserlevelhosts","displayName":"Allow user-level native messaging hosts (installed without admin permissions)","description":"Enables user-level installation of native messaging hosts.\n\nIf you disable this policy, Microsoft Edge will only use native messaging hosts installed on the system level.\n\nBy default, if you don't configure this policy, Microsoft Edge will allow usage of user-level native messaging hosts.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#nativemessaginguserlevelhosts"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_nativemessaginguserlevelhosts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_nativemessaginguserlevelhosts_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_networkpredictionoptions","displayName":"Enable network prediction","description":"Enables network prediction and prevents users from changing this setting.\n\nThis controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages.\n\nIf you don't configure this policy, network prediction is enabled but the user can change it.\n\n* 0 = Predict network actions on any network connection\n\n* 2 = Don't predict network actions on any network connection","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#networkpredictionoptions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular. (Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_networkpredictionoptions_2","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newpdfreaderenabled","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\n\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\n\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newpdfreaderenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newpdfreaderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newpdfreaderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpageallowedbackgroundtypes","displayName":"Configure the background types allowed for the new tab page layout","description":"You can configure which types of background image that are allowed on the new tab page layout in Microsoft Edge.\n\nIf you don't configure this policy, all background image types on the new tab page are enabled.\n\nPolicy options mapping:\n\n* DisableImageOfTheDay (1) = Disable daily background image type\n\n* DisableCustomImage (2) = Disable custom background image type\n\n* DisableAll (3) = Disable all background image types\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpageallowedbackgroundtypes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpageallowedbackgroundtypes_0","displayName":"Disable daily background image type","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpageallowedbackgroundtypes_1","displayName":"Disable custom background image type","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpageallowedbackgroundtypes_2","displayName":"Disable all background image types","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpageapplauncherenabled","displayName":"Hide App Launcher on Microsoft Edge new tab page","description":"By default, the App Launcher is shown every time a user opens a new tab page.\n\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge new tab page and App Launcher is there for users.\n\nIf you disable this policy, App Launcher doesn't appear and users won't be able to launch M365 apps from Microsoft Edge new tab page via the App Launcher.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpageapplauncherenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpageapplauncherenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpageapplauncherenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagebingchatenabled","displayName":"Disable Bing chat entry-points on Microsoft Edge Enterprise new tab page","description":"By default, the Microsoft Edge new tab page includes three Bing Chat entry points: one inside the search box, one in the Bing autosuggest dropdown when users click or begin typing in the box, and one as a suggested prompt below the box.\n\nIf you enable or don't configure this policy, these Bing Chat entry points continue to appear on the new tab page.\n\nIf you disable this policy, all Bing Chat entry points are removed from the new tab page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagebingchatenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagebingchatenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagebingchatenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo","displayName":"New Tab Page Company Logo","description":"We are deprecating this policy because it doesn't work as expected and recommend that it not be used.\n\nSpecifies the company logo to use on the new tab page in Microsoft Edge.\n\nThe policy should be configured as a string that expresses the logo(s) in JSON format. For example: { \"default_logo\": { \"url\": \"https://www.contoso.com/logo.png\", \"hash\": \"cd0aa9856147b6c5b4ff2b7dfee5da20aa38253099ef1b4a64aced233c9afe29\" }, \"light_logo\": { \"url\": \"https://www.contoso.com/light_logo.png\", \"hash\": \"517d286edb416bb2625ccfcba9de78296e90da8e32330d4c9c8275c4c1c33737\" } }\n\nYou configure this policy by specifying the URL from which Microsoft Edge can download the logo and its cryptographic hash (SHA-256), which is used to verify the integrity of the download. The logo must be in PNG or SVG format, and its file size must not exceed 16 MB. The logo is downloaded and cached, and it will be redownloaded whenever the URL or the hash changes. The URL must be accessible without any authentication.\n\nThe 'default_logo' is required and will be used when there's no background image. If 'light_logo' is provided, it will be used when the user's new tab page has a background image. We recommend a horizontal logo with a transparent background that is left-aligned and vertically centered. The logo should have a minimum height of 32 pixels and an aspect ratio from 1:1 to 4:1. The 'default_logo' should have proper contrast against a white/black background while the 'light_logo' should have proper contrast against a background image.\n\nIf you enable this policy, Microsoft Edge downloads and shows the specified logo(s) on the new tab page. Users can't override or hide the logo(s).\n\nIf you disable or don't configure this policy, Microsoft Edge will show no company logo or a Microsoft logo on the new tab page.\n\nFor help with determining the SHA-256 hash, see https://docs.microsoft.com/powershell/module/microsoft.powershell.utility/get-filehash.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagecompanylogo"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_default_logo","displayName":"Default logo","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_default_logo_hash","displayName":"Hash","description":"The SHA-256 hash of the image.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_default_logo_url","displayName":"URL","description":"The URL from which the image can be downloaded.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_light_logo","displayName":"Light logo","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_light_logo_hash","displayName":"Hash","description":"The SHA-256 hash of the image.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_light_logo_url","displayName":"URL","description":"The URL from which the image can be downloaded.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogobackplatecolor","displayName":"Set the company logo backplate color on the new tab page.","description":"By default, the new tab page sets the company logo backplate color to the neutralStrokeActive (#cecece) constant.\n\nYou can configure this policy with a color hex code to change the company logo backplate color on the new tab page.\n\nIf this policy is not configured, the default neutralStrokeActive (#cecece) color will be used as the backplate color.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagecompanylogobackplatecolor"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogoenabled","displayName":"Hide the company logo on the Microsoft Edge new tab page","description":"By default, the company logo is shown on the new tab page if the company logo is configured in Admin Portal.\n\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge new tab page and the company logo is there for users.\n\nIf you disable this policy, the company logo doesn't appear on Microsoft Edge new tab page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagecompanylogoenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagecompanylogoenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogoenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagehidedefaulttopsites","displayName":"Hide the default top sites from the new tab page","description":"Hides the default top sites from the new tab page in Microsoft Edge.\n\nIf you set this policy to true, the default top site tiles are hidden.\n\nIf you set this policy to false or don't configure it, the default top site tiles remain visible.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagehidedefaulttopsites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagehidedefaulttopsites_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagehidedefaulttopsites_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagelocation","displayName":"Configure the new tab page URL","description":"Configures the default URL for the new tab page.\n\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\n\nThis policy doesn't determine which page opens on startup; that's controlled by the \"RestoreOnStartup\" policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\n\nIf you don't configure this policy, the default new tab page is used.\n\nIf you configure this policy *and* the \"NewTabPageSetFeedType\" policy, this policy has precedence.\n\nIf an invalid URL is provided, new tabs will open about://blank.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagelocation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks","displayName":"New Tab Page Managed Quick Links","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\n\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\n\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' is not provided, the URL is used as the default title. If 'pinned' is not provided, the default value is false.\n\nMicrosoft Edge presents these in the order listed, from left to right, with all pinned tiles displayed ahead of non-pinned tiles.\n\nIf the policy is set as mandatory, the 'pinned' field will be ignored and all tiles will be pinned. The tiles can't be deleted by the user and will always appear at the front of the quick links list.\n\nIf the policy is set as recommended, pinned tiles will remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying non-pinned links via this policy to an existing browser profile, the links may not appear at all, depending on how they rank compared to the user's browsing history.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagemanagedquicklinks"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks_item_pinned","displayName":"Pinned","description":"0 - Not Pinned; 1 - Pinned.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks_item_pinned_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks_item_pinned_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks_item_title","displayName":"Title","description":"The title to display.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks_item_url","displayName":"URL","description":"The URL for the quick link.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpageprerenderenabled","displayName":"Enable preload of the new tab page for faster rendering","description":"If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpageprerenderenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpageprerenderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpageprerenderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagequicklinksenabled","displayName":"Allow quick links on the new tab page","description":"If you enable or don't configure this policy, Microsoft Edge displays quick links on the new tab page, and the user can interact with the control, turning quick links on and off. Enabling this policy does not force quick links to be visible - the user can continue to turn quick links on and off.\n\nIf you disable this policy, Microsoft Edge hides quick links on the new tab page and disables the quick links control in the NTP settings flyout.\n\nThis policy only applies for Microsoft Edge local user profiles, profiles signed in using a Microsoft Account, and profiles signed in using Active Directory. To configure the Enterprise new tab page for profiles signed in using Azure Active Directory, use the M365 admin portal.\n\nRelated policies: \"NewTabPageAllowedBackgroundTypes\", \"NewTabPageContentEnabled\"","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagequicklinksenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagequicklinksenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagequicklinksenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagesearchbox","displayName":"Configure the new tab page search box experience","description":"You can configure the new tab page search box to use \"Search box (Recommended)\" or \"Address bar\" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\".\n\n If you disable or don't configure this policy and:\n\n- If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.\n- If the address bar default search engine is not Bing, users are offered an additional choice (use \"Address bar\") when searching on new tabs.\n\n\nIf you enable this policy and set it to:\n\n- \"Search box (Recommended)\" ('bing'), the new tab page uses the search box to search on new tabs.\n- \"Address bar\" ('redirect'), the new tab page search box uses the address bar to search on new tabs.\n\nPolicy options mapping:\n\n* bing (bing) = Search box (Recommended)\n\n* redirect (redirect) = Address bar\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagesearchbox"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagesearchbox_0","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagesearchbox_1","displayName":"Address bar","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagesetfeedtype","displayName":"Configure the Microsoft Edge new tab page experience","description":"Lets you choose either the Microsoft News or Office 365 feed experience for the new tab page.\n\nWhen you set this policy to Microsoft News feed experience (0), users will see the Microsoft News feed experience on the new tab page.\n\nWhen you set this policy to Office 365 feed experience (1), users with an Azure Active Directory browser sign-in will see the Office 365 feed experience on the new tab page.\n\nIf you disable or don't configure this policy:\n\n- Users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, as well as the standard new tab page feed experience.\n\n- Users without an Azure Active Directory browser sign-in will see the standard new tab page experience.\n\nIf you configure this policy *and* the \"NewTabPageLocation\" policy, \"NewTabPageLocation\" has precedence.\n\nDefault setting: Disabled or not configured.\n\n* 0 = Microsoft News feed experience\n\n* 1 = Office 365 feed experience","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagesetfeedtype"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagesetfeedtype_0","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagesetfeedtype_1","displayName":"Office 365 feed experience","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_notificationsallowedforurls","displayName":"Allow notifications on specific sites","description":"Define a list of sites, based on URL patterns, that can display notifications.\n\nIf you don't configure this policy, the global default value from the \"DefaultNotificationsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#notificationsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_notificationsblockedforurls","displayName":"Block notifications on specific sites","description":"Allows you to create a list of url patterns to specify sites that are not allowed to display notifications.\n\nIf you don’t set this policy, the global default value will be used for all sites. This default value will be from the \"DefaultNotificationsSetting\" policy if it’s set, or from the user's personal configuration. For detailed information on valid url patterns, see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#notificationsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_npssurveydisabled","displayName":"Disable user surveys","description":"Prevent survey and feedback dialogs from being shown to users.","helpText":null,"infoUrls":[],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_npssurveydisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_npssurveydisabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_ntlmv2enabled","displayName":"Control whether NTLMv2 authentication is enabled","description":"Controls whether NTLMv2 is enabled.\n\nAll recent versions of Samba and Windows servers support NTLMv2. You should only disable NTLMv2 to address issues with backwards compatibility as it reduces the security of authentication.\n\nIf you don't configure this policy, NTLMv2 is enabled by default.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#ntlmv2enabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_ntlmv2enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_ntlmv2enabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_officeactivationemailaddress","displayName":"Office Activation Email Address","description":"The sign in sheet for Word, Excel, PowerPoint, Outlook, and OneNote will be automatically populated with the specified value.","helpText":null,"infoUrls":[],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":null},{"id":"com.apple.managedclient.preferences_officeautosignin","displayName":"Enable automatic sign-in","description":"Suppress first run and welcome dialogs when launching apps.","helpText":null,"infoUrls":["https://aka.ms/outlookprefs"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_officeautosignin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_officeautosignin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_officeexperiencesanalyzingcontentpreference","displayName":"Allow experiences and functionality that analyzes user content","description":"Examples: PowerPoint Designer, editing suggestions, Excel data insights.","helpText":null,"infoUrls":["https://aka.ms/macoce"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_officeexperiencesanalyzingcontentpreference_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_officeexperiencesanalyzingcontentpreference_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_officeexperiencesdownloadingcontentpreference","displayName":"Allow experiences and functionality that downloads user content","description":"Examples: Office document templates, online 3D models, online videos.","helpText":null,"infoUrls":["https://aka.ms/macoce"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_officeexperiencesdownloadingcontentpreference_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_officeexperiencesdownloadingcontentpreference_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_officewebaddindisableomexcatalog","displayName":"Disable third-party store add-in catalog","description":"Prevent users from accessing and downloading third-party add-ins from the Microsoft store (affects Word, Excel, and PowerPoint).","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-add-ins"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_officewebaddindisableomexcatalog_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_officewebaddindisableomexcatalog_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdate","displayName":"Enable offline security intelligence updates","description":"Enables or disables offline security intelligence updates feature. When this feature is enabled Defender will use a local mirror server to update the signatures.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-support-offline-security-intelligence-update"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_offlinedefinitionupdate_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdate_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdatefallbacktocloud","displayName":"Fallback to Microsoft cloud updates","description":"Determine the Defender for Endpoint security intelligence update approach when offline mirror server fails to serve the update request. If set to true, the update is retried via the Microsoft cloud when offline security intelligence update failed.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-support-offline-security-intelligence-update#configure-the-endpoints"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_offlinedefinitionupdatefallbacktocloud_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdatefallbacktocloud_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdateurl","displayName":"URL for a security intelligence updates mirror server","description":"Sets the URL for a local offline security intelligence updates mirror server. When the feature is enabled Defender will use it to update the signatures.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-support-offline-security-intelligence-update#configure-the-endpoints"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdateverifysig","displayName":"offline security intelligence updates signature verification","description":"Offline security intelligence updates signature verification with Microsoft Defender for Endpoint. It is recommended to keep this setting enabled when offline updates are enabled.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-support-offline-security-intelligence-update"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_offlinedefinitionupdateverifysig_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdateverifysig_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_oldisablejunkoptionsprefkey","displayName":"Disable Junk settings","description":"Prevent users from applying Junk options to emails.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-junk-settings"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_oldisablejunkoptionsprefkey_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_oldisablejunkoptionsprefkey_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_oopprintdriversallowed","displayName":"Out-of-process print drivers allowed","description":"This policy determines whether Microsoft Edge handles interactions with printer drivers through a separate service process.\n\nUsing a service process for tasks like querying available printers, retrieving print driver settings, and submitting documents to local printers improves browser stability and prevents UI freezing during Print Preview.\n\nEnabled or Not Set: Microsoft Edge will use a separate service process for these printing tasks.\n\nDisabled: Microsoft Edge will perform these printing tasks within the browser process.\n\nNote: This policy will be deprecated in the future once the transition to out-of-process print drivers is fully implemented.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#oopprintdriversallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_oopprintdriversallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_oopprintdriversallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_openatlogin","displayName":"Open at login","description":"Specifies whether OneDrive starts automatically when the user logs in.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#openatlogin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_openatlogin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_openatlogin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_optionalconnectedexperiencespreference","displayName":"Allow optional connected experiences","description":"Allow usage of third-party data controller services. Note: All Outlook add-ins will be disabled if the value is set to false.","helpText":null,"infoUrls":["https://aka.ms/macoce"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_optionalconnectedexperiencespreference_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_optionalconnectedexperiencespreference_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_organizationalbrandingonworkprofileuienabled","displayName":"Allow the use of your organization's branding assets from Microsoft Entra on the profile-related UI of a work or school profile","description":"Allow the use of your organization's branding assets from Entra, if any, on the profile-related UI of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect.\n\nIf you enable this policy, your organization's branding assets from Entra will be used.\n\nIf you disable or don't configure this policy, your organization's branding assets from Entra won't be used.\n\nFor more information about configuring your organization's branding assets on Entra, please visit https://go.microsoft.com/fwlink/?linkid=2254514.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#organizationalbrandingonworkprofileuienabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_organizationalbrandingonworkprofileuienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_organizationalbrandingonworkprofileuienabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_organizationlogooverlayonappiconenabled","displayName":"Allow your organization's logo from Microsoft Entra to be overlaid on the Microsoft Edge app icon of a work or school profile","description":"Allow your organization's logo from Entra, if any, to be overlaid on the Microsoft Edge app icon of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect.\n\nIf you enable this policy, your organization's logo from Entra will be used.\n\nIf you disable or don't configure this policy, your organization's logo from Entra won't be used.\n\nFor more information about configuring your organization's logo on Entra, please visit https://go.microsoft.com/fwlink/?linkid=2254514.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#organizationlogooverlayonappiconenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_organizationlogooverlayonappiconenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_organizationlogooverlayonappiconenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_originagentclusterdefaultenabled","displayName":"Origin-keyed agent clustering enabled by default","description":"The Origin-Agent-Cluster: HTTP header controls whether a document is isolated in an origin-keyed agent cluster or in a site-keyed agent cluster. This has security implications because an origin-keyed agent cluster allows isolating documents by origin. The consequence of this for developers is that the document.domain accessor can no longer be set when origin-keyed agent clustering is enabled.\n\nIf you enable or don't configure this policy, documents without the Origin-Agent-Cluster: header will be assigned to origin-keyed agent clustering by default. On these documents, the document.domain accessor will not be settable.\n\nIf you disable this policy, documents without the Origin-Agent-Cluster: header will be assigned to site-keyed agent clusters by default. On these documents, the document.domain accessor will be settable.\n\nSee https://go.microsoft.com/fwlink/?linkid=2191896 for additional details.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#originagentclusterdefaultenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_originagentclusterdefaultenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_originagentclusterdefaultenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_originkeyedprocessesenabled","displayName":"Enable origin-keyed process isolation for improved security","description":"This policy enables origin-keyed process isolation for most pages, which improves security by separating content from different origins into distinct processes. This may increase the number of processes created. Users can override this setting by using command-line flags or edge://flags to turn the feature on or off.\n\nIf you enable this policy, most origins will be isolated, even from other origins within the same site. For related configuration, see the IsolateOrigins and SitePerProcess policies.\n\nIf you disable this policy, origins will not be isolated from the rest of their site unless the origin explicitly requests isolation.\n\nIf you don’t configure this policy, the browser will decide which origins to isolate and when. By default, this feature is disabled. The default state may change in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#originkeyedprocessesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_originkeyedprocessesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_originkeyedprocessesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_overridesecurityrestrictionsoninsecureorigin","displayName":"Control where security restrictions on insecure origins apply","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*.contoso.com\") for which security restrictions on insecure origins don't apply.\n\nThis policy allows you to specify permitted origins for legacy applications that cannot deploy TLS or for internal web development staging servers. It enables developers to test features requiring secure contexts without the need to configure TLS on the staging server. Patterns are only accepted for hostnames; URLs or origins with schemes must be exact matches. This policy also prevents the origin from being labeled \"Not Secure\" in the omnibox.\n\nSetting a list of URLs in this policy has the same effect as setting the command-line flag '--unsafely-treat-insecure-origin-as-secure' to a comma-separated list of the same URLs. If you enable this policy, it overrides the command-line flag.\n\nFor more information on secure contexts, see https://www.w3.org/TR/secure-contexts/.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#overridesecurityrestrictionsoninsecureorigin"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_partitionedbloburlusage","displayName":"Manage Blob URL Partitioning During Fetching and Navigation","description":"The \"PartitionedBlobUrlUsage\" policy controls whether Blob URLs are partitioned during fetching and navigation.\nIf this policy is set to Enabled or not set, Blob URLs are partitioned.\nIf this policy is set to Disabled, Blob URLs won't be partitioned. This represents the Blob URL behavior before Microsoft Edge version 135.\n\nIf storage partitioning is disabled for a given top-level origin either by \"ThirdPartyStoragePartitioningBlockedForOrigins\" or \"DefaultThirdPartyStoragePartitioningSetting\", then Blob URLs aren't partitioned.\n\nThe policy is scheduled to be available through Microsoft Edge version 146. After this version, the policy will be removed, and Microsoft Edge will no longer support unpartitioned blob storage.\n\nFor detailed information on third-party storage partitioning, see https://github.com/privacycg/storage-partitioning.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#partitionedbloburlusage"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_partitionedbloburlusage_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_partitionedbloburlusage_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passivemode","displayName":"Enable passive mode (deprecated)","description":"Whether the antivirus engine runs in passive mode or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-passive-mode"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_passivemode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passivemode_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passworddeleteonbrowsercloseenabled","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when the \"ClearBrowsingDataOnExit\" policy is enabled.\n\nIf you enable this policy, passwords won't be cleared when the browser closes.\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passworddeleteonbrowsercloseenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passworddeleteonbrowsercloseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passworddeleteonbrowsercloseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passwordexportenabled","displayName":"Enable exporting saved passwords from Password Manager","description":"This policy controls whether the Export Password button in edge://wallet/passwords is enabled.\n\nIf enabled or not configured, users can export saved passwords.\nIf disabled, the Export Password button is unavailable, preventing password exports.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordexportenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordexportenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordexportenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passwordmanagerenabled","displayName":"Enable saving passwords to the password manager","description":"Enable Microsoft Edge to save user passwords.\n\nIf you enable this policy, users can save their passwords in Microsoft Edge. The next time they visit the site, Microsoft Edge will enter the password automatically.\n\nIf you disable this policy, users can't save new passwords, but they can still use previously saved passwords.\n\nIf you enable or disable this policy, users can't change or override it in Microsoft Edge. If you don't configure it, users can save passwords, as well as turn this feature off.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordmanagerenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordmanagerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordmanagerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passwordmanagerrestrictlengthenabled","displayName":"Restrict the length of passwords that can be saved in the Password Manager","description":"Make Microsoft Edge restrict the length of usernames and/or passwords that can be saved in the Password Manager.\n\nIf you enable this policy, Microsoft Edge will not let the user save credentials with usernames and/or passwords longer than 256 characters.\n\nIf you disable or don't configure this policy, Microsoft Edge will let the user save credentials with arbitrarily long usernames and/or passwords.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordmanagerrestrictlengthenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordmanagerrestrictlengthenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordmanagerrestrictlengthenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passwordmonitorallowed","displayName":"Allow Microsoft Edge to monitor user passwords","description":"If you enable this policy and a user consents to enabling the policy, the user will get alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\n\nIf you disable this policy, users will not be asked for permission to enable this feature and will not be alerted. Their passwords will not be scanned.\n\nIf you disable this policy, users can't change or override the policy. However, if you enable or don't configure the policy, users can turn this feature on or off.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordmonitorallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordmonitorallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordmonitorallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL","description":"Configures the change password URL (HTTP and HTTPS schemes only).\n\nPassword protection service will send users to this URL to change their password after seeing a warning in the browser.\n\nIf you enable this policy, then password protection service sends users to this URL to change their password.\n\nIf you disable this policy or don't configure it, then password protection service will not redirect users to a change password URL.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordprotectionchangepasswordurl"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_passwordprotectionloginurls","displayName":"Configure the list of enterprise login URLs where password protection service should capture fingerprint of password","description":"Configure the list of enterprise login URLs (HTTP and HTTPS schemes only) where Microsoft Edge should capture the fingerprint of passwords and use it for password reuse detection.\n\nIf you enable this policy, the password protection service captures fingerprints of passwords on the defined URLs.\n\nIf you disable this policy or don't configure it, no password fingerprints are captured.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordprotectionloginurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_passwordprotectionwarningtrigger","displayName":"Configure password protection warning trigger","description":"Allows you to control when to trigger password protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites.\n\nYou can use the \"PasswordProtectionLoginURLs\" and \"PasswordProtectionChangePasswordURL\" policies to configure which passwords to protect.\n\nExemptions: Passwords for the sites listed in \"PasswordProtectionLoginURLs\" and \"PasswordProtectionChangePasswordURL\", as well as for the sites listed in \"SmartScreenAllowListDomains\", will not trigger a password-protection warning.\n\nSet to 'PasswordProtectionWarningOff' (0) to not show password protection warningss.\n\nSet to 'PasswordProtectionWarningOnPasswordReuse' (1) to show password protection warnings when the user reuses their protected password on a non-whitelisted site.\n\nIf you disable or don't configure this policy, then the warning trigger is not shown.\n\n* 0 = Password protection warning is off.\n\n* 1 = Password protection warning is triggered by password reuse.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordprotectionwarningtrigger"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordprotectionwarningtrigger_0","displayName":"Password protection warning is off","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordprotectionwarningtrigger_1","displayName":"Password protection warning is triggered by password reuse","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passwordrevealenabled","displayName":"Enable Password reveal button","description":"Lets you configure the default display of the browser password reveal button for password input fields on websites.\n\nIf you enable or don't configure this policy, the browser user setting defaults to displaying the password reveal button.\n\nIf you disable this policy, the browser user setting won't display the password reveal button.\n\nFor accessibility, users can change the browser setting from the default policy.\n\nThis policy only affects the browser password reveal button, it doesn't affect websites' custom reveal buttons.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordrevealenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordrevealenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordrevealenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_paymentmethodqueryenabled","displayName":"Allow websites to query for available payment methods","description":"Allows you to set whether websites can check if the user has payment methods saved.\n\nIf you disable this policy, websites that use PaymentRequest.canMakePayment or PaymentRequest.hasEnrolledInstrument API will be informed that no payment methods are available.\n\nIf you enable this policy or don't set this policy, websites can check if the user has payment methods saved.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#paymentmethodqueryenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_paymentmethodqueryenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_paymentmethodqueryenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_pdfsecuremode","displayName":"Secure mode and Certificate-based Digital Signature validation in native PDF reader","description":"The policy enables Digital Signature validation for PDF files in a secure environment, which shows the correct validation status of the signatures.\n\nIf you enable this policy, PDF files with Certificate-based digital signatures are opened with an option to view and verify the validity of the signatures with high security.\n\nIf you disable or don't configure this policy, the capability to view and verify the signature will not be available.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pdfsecuremode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pdfsecuremode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pdfsecuremode_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_pdfvieweroutofprocessiframeenabled","displayName":"Use out-of-process iframe PDF Viewer","description":"Determines whether the PDF viewer in Microsoft Edge uses an out-of-process iframe (OOPIF).\nThis will be the new PDF viewer architecture going forward, as it is simpler in design and makes adding new features easier. The current GuestView PDF viewer, which relies on an outdated and overly complex architecture, is being deprecated.\n\nWhen this policy is set to Enabled or not set, Microsoft Edge will use the OOPIF PDF viewer architecture. Once Enabled or not set, the default behavior will be decided by Microsoft Edge.\n\nWhen this policy is set to Disabled, Microsoft Edge will strictly use the existing GuestView PDF viewer. This approach embeds a web page with its own separate frame tree into another web page.\n\nThis policy will be removed in the future, after the OOPIF PDF viewer feature has fully rolled out.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pdfvieweroutofprocessiframeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pdfvieweroutofprocessiframeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pdfvieweroutofprocessiframeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_pdfxfaenabled","displayName":"XFA support in native PDF reader enabled","description":"Lets the Microsoft Edge browser enable XFA (XML Forms Architecture) support in the native PDF reader and allows users to open XFA PDF files in the browser.\n\nIf you enable this policy, XFA support in the native PDF reader will be enabled.\n\nIf you disable or don't configure this policy, Microsoft Edge will not enable XFA support in the native PDF reader.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pdfxfaenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pdfxfaenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pdfxfaenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_performancedetectorenabled","displayName":"Performance Detector Enabled","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\n\nIf you enable or don't configure this policy, performance detector is turned on.\n\nIf you disable this policy, performance detector is turned off.\n\nThe user can configure its behavior in edge://settings/system.\n\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#performancedetectorenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_performancedetectorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_performancedetectorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_performanceprofiles","displayName":"Performance Profiles","description":"Performance profiles","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/performance-profiles"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_performanceprofiles_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_performanceprofiles_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_personalizationreportingenabled","displayName":"Allow personalization of ads, search and news by sending browsing history to Microsoft","description":"This policy prevents Microsoft from collecting a user's Microsoft Edge browsing history to be used for personalizing advertising, search, news and other Microsoft services.\n\nThis setting is only available for users with a Microsoft account. This setting is not available for child accounts or enterprise accounts.\n\nIf you disable this policy, users can't change or override the setting. If this policy is enabled or not configured, Microsoft Edge will default to the user’s preference.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#personalizationreportingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_personalizationreportingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_personalizationreportingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_personalizetopsitesincustomizesidebarenabled","displayName":"Personalize my top sites in Customize Sidebar enabled by default","description":"This policy controls whether Microsoft Edge browser be allowed to use the browsing history to personalize the top sites in the customize sidebar page.\n\nIf you enable this policy, Microsoft Edge will use the browsing history to personalize the top sites in the customize sidebar page.\n\nIf you disable this policy, Microsoft Edge will not use the browsing history to personalize the top sites in the customize sidebar page.\n\nIf you don't configure this policy, the default behavior is to use the browsing history to personalize the top sites in the customize sidebar page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#personalizetopsitesincustomizesidebarenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_personalizetopsitesincustomizesidebarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_personalizetopsitesincustomizesidebarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_phoenixonboardingflowfrelaunched","displayName":"Hide the 'Personalize the new Outlook' dialog","description":"Suppress the welcome dialog that appears when users switch to New Outlook.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_phoenixonboardingflowfrelaunched_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_phoenixonboardingflowfrelaunched_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\n\nThe Picture in Picture floating overlay button lets user to watch videos in a floating window on top of other windows.\n\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\n\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pictureinpictureoverlayenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pictureinpictureoverlayenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pictureinpictureoverlayenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_pinbrowseressentialstoolbarbutton","displayName":"Pin browser essentials toolbar button","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\n\nWhen the button is pinned, it will always appear on the toolbar.\n\nWhen the button isn't pinned, it will only appear when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\n\nIf you enable or don't configure this policy, the Browser essentials button will be pinned on the toolbar.\n\nIf you disable this policy, the Browser essentials button won't be pinned on the toolbar.\n\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pinbrowseressentialstoolbarbutton"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pinbrowseressentialstoolbarbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pinbrowseressentialstoolbarbutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_pluginsallowedforurls","displayName":"Allow the Adobe Flash plug-in on specific sites","description":"Define a list of sites, based on URL patterns, that can run the Adobe Flash plug-in.\n\nIf you don't configure this policy, the global default value from the \"DefaultPluginsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pluginsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_pluginsblockedforurls","displayName":"Block the Adobe Flash plug-in on specific sites","description":"Define a list of sites, based on URL patterns, that are blocked from running Adobe Flash.\n\nIf you don't configure this policy, the global default value from the \"DefaultPluginsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pluginsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_popupsallowedforurls","displayName":"Allow pop-up windows on specific sites","description":"Define a list of sites, based on URL patterns, that can open pop-up windows.\n\nIf you don't configure this policy, the global default value from the \"DefaultPopupsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#popupsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_popupsblockedforurls","displayName":"Block pop-up windows on specific sites","description":"Define a list of sites, based on URL patterns, that are blocked from opening pop-up windows.\n\nIf you don't configure this policy, the global default value from the \"DefaultPopupsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#popupsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_postquantumkeyagreementenabled","displayName":"Enable post-quantum key agreement for TLS","description":"This policy configures whether Microsoft Edge offers a post-quantum key agreement algorithm in TLS. This lets supporting servers protect user traffic from being decrypted by quantum computers.\n\nIf you enable or don't configure this policy, Microsoft Edge offers a post-quantum key agreement in TLS connections. TLS connections are protected from quantum computers when communicating with compatible servers.\n\nIf you disable this policy, Microsoft Edge will not offer a post-quantum key agreement in TLS connections. User traffic is unprotected from decryption by quantum computers.\n\nOffering a post-quantum key agreement is backwards-compatible. Existing TLS servers and networking middleware are expected to ignore the new option and continue selecting previous options.\n\nHowever, devices that don't implement TLS correctly may malfunction when offered the new option. For example, they might disconnect in response to unrecognized options or the resulting larger messages. These devices aren't post-quantum-ready and will interfere with an enterprise's post-quantum transition. If this issue is encountered, administrators should contact the vendor for a fix.\n\nThis policy is a temporary measure and will be removed in future versions of Microsoft Edge. You can enable it to test for issues and you can disable it while you resolve issues.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#postquantumkeyagreementenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_postquantumkeyagreementenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_postquantumkeyagreementenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_precisegeolocationallowedforurls","displayName":"Allow precise geolocation on these sites","description":"This policy lets you specify a list of URL patterns for sites that are allowed to access the user's high-accuracy geolocation without prompting for permission.\n\nIf you leave this policy unset, DefaultGeolocationSetting applies to all sites (if configured). Otherwise, the user's personal setting is used.\n\nFor information about valid url patterns, see https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format. Wildcards (*) are supported.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#precisegeolocationallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_prefetchwithserviceworkerenabled","displayName":"Allow SpeculationRules prefetch for ServiceWorker-controlled URLs","description":"Controls whether SpeculationRules prefetch requests are allowed for\nServiceWorker-controlled URLs.\n\nStarting with Microsoft Edge version 138,\nprefetch requests to ServiceWorker-controlled URLs are allowed by default when\nthe PrefetchServiceWorker feature is enabled.\n\nIf this policy is enabled or not configured, that default behavior is used.\n\nTo restore the legacy behavior from versions prior to 138, where prefetch requests\nto ServiceWorker-controlled URLs were blocked, set this policy to disabled.\n\nThis policy is intended to be temporary and will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#prefetchwithserviceworkerenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_prefetchwithserviceworkerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_prefetchwithserviceworkerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverride","displayName":"Prevent bypassing Microsoft Defender SmartScreen prompts for sites","description":"This policy setting lets you decide whether users can override the Microsoft Defender SmartScreen warnings about potentially malicious websites.\n\nIf you enable this setting, users can't ignore Microsoft Defender SmartScreen warnings and they are blocked from continuing to the site.\n\nIf you disable or don't configure this setting, users can ignore Microsoft Defender SmartScreen warnings and continue to the site.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#preventsmartscreenpromptoverride"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverride_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverride_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverrideforfiles","displayName":"Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads","description":"This policy lets you determine whether users can override Microsoft Defender SmartScreen warnings about unverified downloads.\n\nIf you enable this policy, users in your organization can't ignore Microsoft Defender SmartScreen warnings, and they're prevented from completing the unverified downloads.\n\nIf you disable or don't configure this policy, users can ignore Microsoft Defender SmartScreen warnings and complete unverified downloads.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#preventsmartscreenpromptoverrideforfiles"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverrideforfiles_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverrideforfiles_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_preventtyposquattingpromptoverride","displayName":"Prevent bypassing Edge Website Typo Protection prompts for sites","description":"This policy setting lets you decide whether users can override the Edge Website Typo Protection warnings about potential typosquatting websites.\n\nIf you enable this setting, users can't ignore Edge Website Typo Protection warnings and they are blocked from continuing to the site.\n\nIf you disable or don't configure this setting, users can ignore Edge Website Typo Protection warnings and continue to the site.\n\nThis will only take effect when TyposquattingCheckerEnabled policy is not set or set to enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#preventtyposquattingpromptoverride"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_preventtyposquattingpromptoverride_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_preventtyposquattingpromptoverride_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill","description":"The feature helps users add an additional layer of privacy to their online accounts by requiring device authentication (as a way of confirming the user's identity) before the saved password is auto-filled into a web form. This ensures that non-authorized persons can't use saved passwords for autofill. Note that this feature does not protect against locally-running malware.\n\nThis group policy configures the radio button selector that enables this feature for users. It also has a frequency control where users can specify how often they would like to be prompted for authentication.\n\nIf you set this policy to 'Automatically', disable this policy, or don't configure this policy, autofill will not have any authentication flow.\n\nIf you set this policy to 'WithDevicePassword', users will have to enter their device password (or preferred mode of authentication under Windows) to prove their identity before their password is auto filled. Authentication modes include Windows Hello, PIN, face recognition, or fingerprint. The frequency for authentication prompt will be set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\n\nIf you set this policy to 'WithCustomPrimaryPassword', users will be asked to create their custom password and then to be redirected to Settings. After the custom password is set, users can authenticate themselves using the custom password and their passwords will get auto-filled after successful authentication. The frequency for authentication prompt will be set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\n\nIf you set this policy to 'AutofillOff', saved passwords will no longer be suggested for autofill.\n\nPolicy options mapping:\n\n* Automatically (0) = Automatically\n\n* WithDevicePassword (1) = With device password\n\n* WithCustomPrimaryPassword (2) = With custom primary password\n\n* AutofillOff (3) = Autofill off\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#primarypasswordsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_primarypasswordsetting_0","displayName":"Automatically","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_primarypasswordsetting_1","displayName":"With device password","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_primarypasswordsetting_2","displayName":"With custom primary password","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_primarypasswordsetting_3","displayName":"Autofill off","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printertypedenylist","displayName":"Disable printer types on the deny list","description":"The printer types on the deny list won't be discovered or have their capabilities fetched.\n\nPlacing all printer types on the deny list effectively disables printing, because there's no print destination for documents.\n\nIf you don't configure this policy, or the printer list is empty, all printer types are discoverable.\n\nPrinter destinations include extension printers and local printers. Extension printers are also known as print provider destinations, and include any destination that belongs to a Microsoft Edge extension.\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\n\nPolicy options mapping:\n\n* privet (privet) = Zeroconf-based (mDNS + DNS-SD) protocol destinations\n\n* extension (extension) = Extension-based destinations\n\n* pdf (pdf) = The 'Save as PDF' destination\n\n* local (local) = Local printer destinations\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printertypedenylist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_printheaderfooter","displayName":"Print headers and footers","description":"Force 'headers and footers' to be on or off in the printing dialog.\n\nIf you don't configure this policy, users can decide whether to print headers and footers.\n\nIf you disable this policy, users can't print headers and footers.\n\nIf you enable this policy, users always print headers and footers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printheaderfooter"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printheaderfooter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printheaderfooter_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode","description":"Restricts background graphics printing mode. If this policy isn't set there's no restriction on printing background graphics.\n\nPolicy options mapping:\n\n* any (any) = Allow printing with and without background graphics\n\n* enabled (enabled) = Allow printing only with background graphics\n\n* disabled (disabled) = Allow printing only without background graphics\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printingallowedbackgroundgraphicsmodes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printingallowedbackgroundgraphicsmodes_0","displayName":"Allow printing with and without background graphics","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printingallowedbackgroundgraphicsmodes_1","displayName":"Allow printing only without background graphics","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printingallowedbackgroundgraphicsmodes_2","displayName":"Allow printing only with background graphics","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode","description":"Overrides the last used setting for printing background graphics.\nIf you enable this setting, background graphics printing is enabled.\nIf you disable this setting, background graphics printing is disabled.\n\nPolicy options mapping:\n\n* enabled (enabled) = Enable background graphics printing mode by default\n\n* disabled (disabled) = Disable background graphics printing mode by default\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printingbackgroundgraphicsdefault"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printingbackgroundgraphicsdefault_0","displayName":"Disable background graphics printing mode by default","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printingbackgroundgraphicsdefault_1","displayName":"Enable background graphics printing mode by default","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printingenabled","displayName":"Enable printing","description":"Enables printing in Microsoft Edge and prevents users from changing this setting.\n\nIf you enable this policy or don't configure it, users can print.\n\nIf you disable this policy, users can't print from Microsoft Edge. Printing is disabled in the wrench menu, extensions, JavaScript applications, and so on. Users can still print from plug-ins that bypass Microsoft Edge while printing. For example, certain Adobe Flash applications have the print option in their context menu, which isn't covered by this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printingwebpagelayout","displayName":"Sets layout for printing","description":"Configuring this policy sets the layout for printing webpages.\n\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\n\nIf you enable this policy, the selected option is set as the layout option.\n\nPolicy options mapping:\n\n* portrait (0) = Sets layout option as portrait\n\n* landscape (1) = Sets layout option as landscape\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printingwebpagelayout"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printingwebpagelayout_0","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printingwebpagelayout_1","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printpdfasimagedefault","displayName":"Print PDF as Image Default","description":"Controls if Microsoft Edge makes the Print as image option the default when printing PDFs.\n\nIf you enable this policy, Microsoft Edge will default to setting the Print as image option in the Print Preview when printing a PDF.\n\nIf you disable or don't configure this policy, Microsoft Edge will not default to setting the Print as image option in the Print Preview when printing a PDF.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printpdfasimagedefault"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printpdfasimagedefault_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printpdfasimagedefault_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printpreviewusesystemdefaultprinter","displayName":"Set the system default printer as the default printer","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\n\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\n\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printpreviewusesystemdefaultprinter"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printpreviewusesystemdefaultprinter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printpreviewusesystemdefaultprinter_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI","description":"Controls print image resolution when Microsoft Edge prints PDFs with rasterization.\n\nWhen printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution will significantly increase the processing and printing time while a low resolution can lead to poor imaging quality.\n\nIf you set this policy, it allows a particular resolution to be specified for use when rasterizing PDFs for printing.\n\nIf you set this policy to zero or don't configure it, the system default resolution will be used during rasterization of page images.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printrasterizepdfdpi"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_printstickysettings","displayName":"Print preview sticky settings","description":"Specifies whether print preview should apply last used settings for Microsoft Edge PDF and webpages.\n\nIf you set this policy to 'EnableAll' or don't configure it, Microsoft Edge applies the last used print preview settings for both PDF and webpages.\n\nIf you set this policy to 'DisableAll', Microsoft Edge doesn't apply the last used print preview settings for both PDF and webpages.\n\nIf you set this policy to 'DisablePdf', Microsoft Edge doesn't apply the last used print preview settings for PDF printing and retains it for webpages.\n\nIf you set this policy to 'DisableWebpage', Microsoft Edge doesn't apply the last used print preview settings for webpage printing and retain it for PDF.\n\nThis policy is only available if you enable or don't configure the \"PrintingEnabled\" policy.\n\nPolicy options mapping:\n\n* EnableAll (0) = Enable sticky settings for PDF and Webpages\n\n* DisableAll (1) = Disable sticky settings for PDF and Webpages\n\n* DisablePdf (2) = Disable sticky settings for PDF\n\n* DisableWebpage (3) = Disable sticky settings for Webpages\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printstickysettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printstickysettings_0","displayName":"Enable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printstickysettings_1","displayName":"Disable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printstickysettings_2","displayName":"Disable sticky settings for PDF","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printstickysettings_3","displayName":"Disable sticky settings for Webpages","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_privatenetworkaccessrestrictionsenabled","displayName":"Specifies whether to apply restrictions to requests to more private network endpoints (Deprecated)","description":"Specifies whether to apply restrictions to requests to more private\nnetwork endpoints\n\nWhen this policy is Enabled, any time when a warning is supposed to be displayed in the DevTools due to Private Network Access checks failing, the request is blocked.\n\nWhen this policy is Disabled or unset, all Private Network Access warnings are not enforced and the requests are not blocked.\n\nSee https://wicg.github.io/private-network-access/ for Private Network Access restrictions.\n\nNote: A network endpoint is more private than another if:\n1) Its IP address is localhost and the other is not.\n2) Its IP address is private and the other is public.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#privatenetworkaccessrestrictionsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_privatenetworkaccessrestrictionsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_privatenetworkaccessrestrictionsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_proactiveauthenabled","displayName":"Enable Proactive Authentication","description":"Lets you configure whether to turn on Proactive Authentication.\n\nIf you enable this policy, Microsoft Edge tries to proactively authenticate the signed-in user with Microsoft services. At regular intervals, Microsoft Edge checks with an online service for an updated manifest that contains the configuration that governs how to do this.\n\nIf you disable this policy, Microsoft Edge doesn't try to proactively authenticate the signed-in user with Microsoft services. Microsoft Edge no longer checks with an online service for an updated manifest that contains the configuration for doing this.\n\nIf you don't configure this policy, Proactive Authentication is turned on.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proactiveauthenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_proactiveauthenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proactiveauthenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_proactiveauthworkflowenabled","displayName":"Enable proactive authentication","description":"This policy controls the proactive authentication in Microsoft Edge, that connects the signed-in user identity with Microsoft Bing, MSN and Copilot services for a smooth and consistent sign-in experience.\n\nIf you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser.\n\nIf you disable this policy, Microsoft Edge does not send authentications requests to these services and users will need to manually sign-in.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proactiveauthworkflowenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_proactiveauthworkflowenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proactiveauthworkflowenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_profiles","displayName":"Performance Profiles","description":"Names of performance profiles to apply.","helpText":null,"infoUrls":[],"categoryId":"d40a32e1-ab3e-4cbc-aa03-4766792e563e","categoryName":"Performance Profiles Configuration","options":null},{"id":"com.apple.managedclient.preferences_profiletypeinprofilebuttonenabled","displayName":"Controls the display of the profile button label for the work or school profile","description":"Controls whether the label for the work or school profile type is shown in the profile button.\n\nThis policy does not apply when the OrganizationalBrandingOnWorkProfileUIEnabled policy is enabled.\n\nIf you enable this policy, the label for the work or school profile type appears in the profile button.\n\nIf you disable this policy or leave it not configured, the label is not shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#profiletypeinprofilebuttonenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_profiletypeinprofilebuttonenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_profiletypeinprofilebuttonenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_promotionaltabsenabled","displayName":"Enable full-tab promotional content (deprecated)","description":"Control the presentation of full-tab promotional or educational content. This setting controls the presentation of welcome pages that help users sign into Microsoft Edge, choose their default browser, or learn about product features.\n\nIf you enable this policy (set it true) or don't configure it, Microsoft Edge can show full-tab content to users to provide product information.\n\nIf you disable (set to false) this policy, Microsoft Edge can't show full-tab content to users.\n\nThis is deprecated - use ShowRecommendationsEnabled instead.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#promotionaltabsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_promotionaltabsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_promotionaltabsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_promptfordownloadlocation","displayName":"Ask where to save downloaded files","description":"Set whether to ask where to save a file before downloading it.\n\nIf you enable this policy, the user is asked where to save each file before downloading; if you don't configure it, files are saved automatically to the default location, without asking the user.\n\nIf you don't configure this policy, the user will be able to change this setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#promptfordownloadlocation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_promptfordownloadlocation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_promptfordownloadlocation_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_promptonmultiplematchingcertificates","displayName":"Prompt the user to select a certificate when multiple certificates match","description":"This policy controls whether the user is prompted to select a client certificate when more than one certificate matches \"AutoSelectCertificateForUrls\".\nIf this policy is set to True, the user is prompted to select a client certificate whenever the auto-selection policy matches multiple certificates.\nIf this policy is set to False or not set, the user may only be prompted when no certificate matches the auto-selection.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#promptonmultiplematchingcertificates"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_promptonmultiplematchingcertificates_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_promptonmultiplematchingcertificates_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_proxy","displayName":"Set proxy for MDE communication","description":"Configure proxy for all MDE cloud communication. If not set, the system-wide proxy is used.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-preferences#proxy-for-defender-for-endpoint-communication"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":null},{"id":"com.apple.managedclient.preferences_proxybypasslist","displayName":"Configure proxy bypass rules","description":"Defines a list of hosts for which Microsoft Edge bypasses any proxy.\n\nThis policy is applied only if you have selected 'Use fixed proxy servers' in the \"ProxyMode\" policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, you can create a list of hosts for which Microsoft Edge doesn't use a proxy.\n\nIf you don't configure this policy, no list of hosts is created for which Microsoft Edge bypasses a proxy. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\n\nFor more detailed examples go to https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxybypasslist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_proxymode","displayName":"Configure proxy server settings","description":"Specify the proxy server settings used by Microsoft Edge. If you enable this policy, users can't change the proxy settings.\n\nIf you choose to never use a proxy server and to always connect directly, all other options are ignored.\n\nIf you choose to use system proxy settings, all other options are ignored.\n\nIf you choose to auto detect the proxy server, all other options are ignored.\n\nIf you choose fixed server proxy mode, you can specify further options in \"ProxyServer\" and 'Comma-separated list of proxy bypass rules'.\n\nIf you choose to use a .pac proxy script, you must specify the URL to the script in 'URL to a proxy .pac file'.\n\nFor detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.\n\nIf you enable this policy, Microsoft Edge will ignore all proxy-related options specified from the command line.\n\nIf you don't configure this policy users can choose their own proxy settings.\n\n* \"direct\" = Never use a proxy\n\n* \"auto_detect\" = Auto detect proxy settings\n\n* \"pac_script\" = Use a .pac proxy script\n\n* \"fixed_servers\" = Use fixed proxy servers\n\n* \"system\" = Use system proxy settings","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_proxymode_0","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_1","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_2","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_3","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_4","displayName":"Use system proxy settings","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_proxypacurl","displayName":"Set the proxy .pac file URL","description":"Specifies the URL for a proxy auto-config (PAC) file.\n\nThis policy is applied only if you selected 'Use a .pac proxy script' in the \"ProxyMode\" policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, you can specify the URL for a PAC file, which defines how the browser automatically chooses the appropriate proxy server for fetching a particular website.\n\nIf you disable or don't configure this policy, no PAC file is specified. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\n\nFor detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxypacurl"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_proxyserver","displayName":"Configure address or URL of proxy server","description":"Specifies the URL of the proxy server.\n\nThis policy is applied only if you have selected 'Use fixed proxy servers' in the \"ProxyMode\" policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, the proxy server configured by this policy will be used for all URLs.\n\nIf you disable or don't configure this policy, users can choose their own proxy settings while in this proxy mode. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\n\nFor more options and detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxyserver"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_proxysettings","displayName":"Proxy Settings","description":"Configures the proxy settings for Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge ignores all proxy-related options specified from the command line.\n\nIf you don't configure this policy, users can choose their own proxy settings.\n\nThis policy overrides the following individual policies:\n\n\"ProxyMode\"\n\"ProxyPacUrl\"\n\"ProxyServer\"\n\"ProxyBypassList\"\n\nThe ProxyMode field lets you specify the proxy server used by Microsoft Edge and prevents users from changing proxy settings.\n\nThe ProxyPacUrl field is a URL to a proxy .pac file.\n\nThe ProxyServer field is a URL for the proxy server.\n\nThe ProxyBypassList field is a list of proxy hosts that Microsoft Edge bypasses.\n\nIf you choose the 'direct' value as 'ProxyMode', a proxy is never used and all other fields are ignored.\n\nIf you choose the 'system' value as 'ProxyMode', the systems's proxy is used and all other fields are ignored.\n\nIf you choose the 'auto_detect' value as 'ProxyMode', all other fields are ignored.\n\nIf you choose the 'fixed_server' value as 'ProxyMode', the 'ProxyServer' and 'ProxyBypassList' fields are used.\n\nIf you choose the 'pac_script' value as 'ProxyMode', the 'ProxyPacUrl' and 'ProxyBypassList' fields are used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxysettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxybypasslist","displayName":"Proxy Bypass List","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxymode","displayName":"Proxy Mode","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_proxysettings_proxymode_0","displayName":"direct","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxymode_1","displayName":"auto_detect","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxymode_2","displayName":"pac_script","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxymode_3","displayName":"fixed_servers","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxymode_4","displayName":"system","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_proxysettings_proxypacurl","displayName":"Proxy PAC URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxyserver","displayName":"Proxy Server","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_qrcodegeneratorenabled","displayName":"Enable QR Code Generator","description":"This policy enables the QR Code generator feature in Microsoft Edge.\n\nIf you enable this policy or don't configure it, the QR Code Generator feature is enabled.\n\nIf you disable this policy, the QR Code Generator feature is disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#qrcodegeneratorenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_qrcodegeneratorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_qrcodegeneratorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_quicallowed","displayName":"Allow QUIC protocol","description":"Allows use of the QUIC protocol in Microsoft Edge.\n\nIf you enable this policy or don't configure it, the QUIC protocol is allowed.\n\nIf you disable this policy, the QUIC protocol is blocked.\n\nQUIC is a transport layer network protocol that can improve performance of web applications that currently use TCP.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#quicallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_quicallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_quicallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_quicksearchshowminimenu","displayName":"Enables Microsoft Edge mini menu (Deprecated)","description":"Enables Microsoft Edge mini menu on websites and PDFs. The mini menu is triggered on text selection and has basic actions like copy and smart actions like definitions.\n\nIf you enable or don't config this policy, selecting text on websites and PDFs will show the Microsoft Edge mini menu.\n\nIf you disable this policy, the Microsoft Edge mini menu will not be shown when text on websites and PDFs is selected.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#quicksearchshowminimenu"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_quicksearchshowminimenu_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_quicksearchshowminimenu_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_quickviewofficefilesenabled","displayName":"Manage QuickView Office files capability in Microsoft Edge","description":"Allows you to set whether users can view publicly accessible Office files on the web that aren't on OneDrive or SharePoint. (For example: Word documents, PowerPoint presentations, and Excel spreadsheets)\n\nIf you enable or don't configure this policy, these files can be viewed in Microsoft Edge using Office Viewer instead of downloading the files.\n\nIf you disable this policy, these files will be downloaded to be viewed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#quickviewofficefilesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_quickviewofficefilesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_quickviewofficefilesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_randomizescanstarttime","displayName":"Randomize scheduled scan start time","description":"Randomize the start time of a daily and weekly scheduled scan to any interval from 0 to 23 hours.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_readaloudenabled","displayName":"Enable Read Aloud feature in Microsoft Edge","description":"Enables the Read Aloud feature within Microsoft Edge.\nUsing this feature, users can listen to the content on the web page. This enables users to multi-task or improve their reading comprehension by hearing content at their own pace.\n\nIf you enable this policy or don't configure it, the Read Aloud option shows up in the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.\nIf you disable this policy, users can't access the Read Aloud feature from the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#readaloudenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_readaloudenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_readaloudenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_reduceipaddresschangenotificationenabled","displayName":"Enable Reduce IP Address Change Notification","description":"This policy lets you configure the Reduce IP address change notification feature in Microsoft Edge on macOS.\n\nIf you enable or don't configure this policy, the Reduce IP address change notification feature is enabled by default. This helps reduce unnecessary network change notifications when IP addresses change.\n\nIf you disable this policy, all IP address changes trigger network change notifications, regardless of the feature's status.\n\nThis feature is only available on macOS.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#reduceipaddresschangenotificationenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_reduceipaddresschangenotificationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_reduceipaddresschangenotificationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers","displayName":"Registered Protocol Handlers","description":"Register a list of protocol handlers. Set the protocol property to the scheme (like 'mailto') and the url property to the URL pattern of the application that handles the scheme. The pattern can include a '%s', which will be replaced by the handled URL.\n\nYou can recommend a specific value for this policy, but you can't require that your users use it.\n\nThe protocol handlers registered by policy are merged with any handlers registered by the user, and both are available for use. The user can override the protocol handlers installed by policy by installing a new default handler, but they can't remove a protocol handler registered by policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#registeredprotocolhandlers"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers_item_default","displayName":"Default","description":"A boolean flag indicating if the protocol handler should be set as the default.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers_item_default_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers_item_default_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers_item_protocol","displayName":"Protocol","description":"The protocol for the protocol handler.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers_item_url","displayName":"URL","description":"The URL of the protocol handler.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_relatedmatchescloudserviceenabled","displayName":"Configure Related Matches in Find on Page (Deprecated)","description":"Specifies how the user receives related matches in Find on Page, which provides spellcheck, synonyms, and Q&A results in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can receive related matches in Find on Page on all sites. The results are processed in a cloud service.\n\nIf you disable this policy, users can receive related matches in Find on Page on limited sites. The results are processed on the user's device.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relatedmatchescloudserviceenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_relatedmatchescloudserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_relatedmatchescloudserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_relatedwebsitesetsenabled","displayName":"Enable Related Website Sets (deprecated)","description":"This policy lets you control the enablement of the Related Website Sets feature. Related Website Sets (RWS) is a way for an organisation to declare relationships among sites, so that Microsoft Edge allows limited third-party cookie access for specific purposes across those sites.\n\nIf this policy set to True or unset, the Related Website Sets feature is enabled.\n\nIf this policy is set to False, the Related Website Sets feature is disabled.\n\nThis policy is deprecated as of Microsoft Edge version 144 with the deprecation of Related Website Sets.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relatedwebsitesetsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_relatedwebsitesetsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_relatedwebsitesetsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_relaunchfastifoutdated","displayName":"Relaunch browser quickly when the current version is outdated","description":"This policy specifies the minimum release age after which relaunch notifications become more aggressive. The release age is calculated from the time the currently running version was last served to clients.\n\nIf a browser relaunch is needed to finalize a pending update and the current version has been outdated for more than the number of days specified by this setting, the RelaunchNotificationPeriod policy is overridden to 2 hours. If the RelaunchNotification policy is set to 1 ('Required'), a browser relaunch will be forced at the end of the period.\n\nIf not set, or if the release age cannot be determined, the RelaunchNotificationPeriod policy will be used for all updates.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relaunchfastifoutdated"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_relaunchnotification","displayName":"Notify a user that a browser restart is recommended or required for pending updates","description":"Notify users that they need to restart Microsoft Edge to apply a pending update.\n\nIf you don't configure this policy, Microsoft Edge adds a recycle icon at the far right of the top menu bar to prompt users to restart the browser to apply the update.\n\nIf you enable this policy and set it to 'Recommended' (1), a recurring warning prompts users that a restart is recommended. Users can dismiss this warning and defer the restart.\n\nIf you set the policy to 'Required' (2), a recurring warning prompts users that the browser will be restarted automatically as soon as a notification period passes. The default period is seven days. You can configure this period with the \"RelaunchNotificationPeriod\" policy.\n\nThe user's session is restored when the browser restarts.\n\n* Recommended (1) = Show a recurring prompt to the user indicating that a restart is recommended\n\n* Required (2) = Show a recurring prompt to the user indicating that a restart is required","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relaunchnotification"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_relaunchnotification_0","displayName":"Recommended - Show a recurring prompt to the user indicating that a restart is recommended","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_relaunchnotification_1","displayName":"Required - Show a recurring prompt to the user indicating that a restart is required","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_relaunchnotificationperiod","displayName":"Set the time period for update notifications","description":"Allows you to set the time period, in milliseconds, over which users are notified that Microsoft Edge must be relaunched or that a Microsoft Edge OS device must be restarted to apply a pending update.\n\nOver this time period, the user will be repeatedly informed of the need for an update. For Microsoft Edge OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Microsoft Edge browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the \"RelaunchNotification\" policy follow this same schedule.\n\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relaunchnotificationperiod"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_remotedebuggingallowed","displayName":"Allow remote debugging","description":"Controls whether users may use remote debugging.\n\nIf you enable or don't configure this policy, users may use remote debugging by specifying --remote-debug-port and --remote-debugging-pipe command line switches.\n\nIf you disable this policy, users are not allowed to use remote debugging.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#remotedebuggingallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_remotedebuggingallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_remotedebuggingallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_resolvenavigationerrorsusewebservice","displayName":"Enable resolution of navigation errors using a web service","description":"Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi.\n\nIf you enable this policy, a web service is used for network connectivity tests.\n\nIf you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues.\n\n**Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues.\n\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\nSpecifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#resolvenavigationerrorsusewebservice"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_resolvenavigationerrorsusewebservice_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_resolvenavigationerrorsusewebservice_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_restoreonstartup","displayName":"Action to take on startup","description":"Specify how Microsoft Edge behaves when it starts.\n\nIf you want a new tab to always open on startup, choose 'Open new tab' (5).\n\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'Restore the last session' (1). The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\n\nIf you want to open a specific set of URLs, choose 'Open a list of URLs' (4).\n\nDisabling this setting is equivalent to leaving it not configured. Users will be able to change it in Microsoft Edge.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\n\n* 5 = Open a new tab\n\n* 1 = Restore the last session\n\n* 4 = Open a list of URLs","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restoreonstartup"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_restoreonstartup_0","displayName":"Restore the last session","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_restoreonstartup_1","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_restoreonstartup_2","displayName":"Open a new tab","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_restoreonstartup_3","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_restoreonstartupurls","displayName":"Sites to open when the browser starts","description":"Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup.\n\nThis policy only works if you also set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4).\n\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restoreonstartupurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_restoreonstartupuserurlsenabled","displayName":"Allow users to add and remove their own sites during startup when the RestoreOnStartupURLs policy is configured","description":"This policy only works if you set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4) and the \"RestoreOnStartupURLs\" policy as mandatory.\nIf you enable this policy, users are allowed to add and remove their own URLs to open when starting Edge while maintaining the admin specified mandatory list of sites specified by setting \"RestoreOnStartup\" policy to open a list of URLS and providing the list of sites in the \"RestoreOnStartupURLs\" policy.\n\nIf you disable or don't configure this policy, there is no change to how the \"RestoreOnStartup\" and \"RestoreOnStartupURLs\" policies work.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restoreonstartupuserurlsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_restoreonstartupuserurlsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_restoreonstartupuserurlsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_restorepdfview","displayName":"Restore PDF view","description":"Enables PDF View Recovery in Microsoft Edge.\n\nIf you enable or don't configure this policy Microsoft Edge will recover the last state of PDF view and land users to the section where they ended reading in the last session.\n\nIf you disable this policy Microsoft Edge will recover the last state of PDF view and land users at the start of the PDF file.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restorepdfview"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_restorepdfview_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_restorepdfview_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_restrictsignintopattern","displayName":"Restrict which accounts can be used as Microsoft Edge primary accounts","description":"Determines which accounts can be set as browser primary accounts in Microsoft Edge (the account that is chosen during the Sync opt-in flow).\n\nIf a user tries to set a browser primary account with a username that doesn't match this pattern, they are blocked and see an appropriate error message.\n\nIf you don't configure this policy or leave it blank, users can set any account as a browser primary account in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restrictsignintopattern"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_runallflashinallowmode","displayName":"Extend Adobe Flash content setting to all content","description":"If you enable this policy, all Adobe Flash content embedded in websites that are set to allow Adobe Flash in the content settings -- either by the user or by enterprise policy -- will run. This includes content from other origins and/or small content.\n\nTo control which websites are allowed to run Adobe Flash, see the specifications in the \"DefaultPluginsSetting\", \"PluginsAllowedForUrls\", and \"PluginsBlockedForUrls\" policies.\n\nIf you disable this policy or don't configure it, Adobe Flash content from other origins (from sites that aren't specified in the three policies mentioned immediately above) or small content might be blocked.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#runallflashinallowmode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_runallflashinallowmode_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_runallflashinallowmode_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_runscanwhenidle","displayName":"Run scheduled scan when idle","description":"Run scheduled scan when the device is idle. Only applicable for weekly full scans.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":[{"id":"com.apple.managedclient.preferences_runscanwhenidle_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_runscanwhenidle_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sameorigintabcaptureallowedbyorigins","displayName":"Allow Same Origin Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin.\n\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\n\nIf a site matches a URL pattern in this policy, the following policies will not be considered: \"TabCaptureAllowedByOrigins\", \"WindowCaptureAllowedByOrigins\", \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sameorigintabcaptureallowedbyorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_sandboxexternalprotocolblocked","displayName":"Allow Microsoft Edge to block navigations to external protocols in a sandboxed iframe","description":"Microsoft Edge will block navigations to external protocols inside a\nsandboxed iframe.\n\nIf you enable or don't configure this policy, Microsoft Edge will block those navigations.\n\nIf you disable this policy, Microsoft Edge will not block those navigations.\n\nThis can be used by administrators who need more time to update their internal website affected by this new restriction. This Enterprise policy is temporary; it's intended to be removed after Microsoft Edge version 117.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sandboxexternalprotocolblocked"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sandboxexternalprotocolblocked_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sandboxexternalprotocolblocked_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_savecookiesonexit","displayName":"Save cookies when Microsoft Edge closes","description":"When this policy is enabled, the specified set of cookies is exempt from deletion when the browser closes. This policy is only effective when:\n- The 'Cookies and other site data' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\n- The policy \"ClearBrowsingDataOnExit\" is enabled or\n- The policy \"DefaultCookiesSetting\" is set to 'Keep cookies for the duration of the session'.\n\nYou can define a list of sites, based on URL patterns, that will have their cookies preserved across sessions.\n\nNote: Users can still edit the cookie site list to add or remove URLs. However, they can't remove URLs that have been added by an Admin.\n\nIf you enable this policy, the list of cookies won't be cleared when the browser closes.\n\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#savecookiesonexit"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_savingbrowserhistorydisabled","displayName":"Disable saving browser history","description":"Disables saving browser history and prevents users from changing this setting.\n\nIf you enable this policy, browsing history isn't saved. This also disables tab syncing.\n\nIf you disable this policy or don't configure it, browsing history is saved.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#savingbrowserhistorydisabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_savingbrowserhistorydisabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_savingbrowserhistorydisabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_scanafterdefinitionupdate","displayName":"Run a scan after definitions are updated","description":"Specifies whether to start a process scan after new security intelligence updates are downloaded on the device. Enabling this setting will trigger an antivirus scan on the running processes of the device.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#run-a-scan-after-definitions-are-updated"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_scanafterdefinitionupdate_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scanafterdefinitionupdate_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_scanarchives","displayName":"Scanning inside archive files","description":"If true, Defender will unpack archives and scan files inside them. Otherwise archive content will be skipped, that will improve scanning performance.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#scan-archives-on-demand-antivirus-scans-only"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_scanarchives_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scanarchives_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_scanhistorymaximumitems","displayName":"Scan history size","description":"Specify the maximum number of entries to keep in the scan history. Entries include all on-demand scans performed in the past and all antivirus detections.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#maximum-number-of-items-in-the-antivirus-scan-history"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_scanresultsretentiondays","displayName":"Scan results retention","description":"Specify the number of days that results are retained in the scan history on the device. Old scan results are removed from the history. Old quarantined files that are also removed from the disk.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#antivirus-scan-history-retention-in-days"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_scarewareblockerallowlistdomains","displayName":"Configure the list of domains where Microsoft Edge Scareware blockers don't run","description":"This policy configures the list of trusted domains for Microsoft Edge Scareware blocker. When a website's source URL matches any domain in this list, Microsoft Edge Scareware blocker doesn't analyze that site.\n\nThis policy takes effect only if the ScarewareBlockerProtectionEnabled policy is enabled.\n\nIf you enable this policy, Microsoft Edge Scareware blocker trusts the specified domains.\n\nIf you disable or don't configure this policy, Microsoft Edge Scareware blocker analyzes all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockerallowlistdomains"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_scarewareblockerblocksdetectedsitesenabled","displayName":"Configure Microsoft Edge scareware blocker to block sites detected as potential tech scams","description":"This policy controls whether Microsoft Edge blocks sites that are detected as potential tech scams.\n\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\n\nIf you enable or don't configure this policy, Microsoft Edge blocks sites detected as potential tech scams.\n\nIf you disable this policy, Microsoft Edge doesn't block sites detected as potential tech scams.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockerblocksdetectedsitesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scarewareblockerblocksdetectedsitesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scarewareblockerblocksdetectedsitesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_scarewareblockerprotectionenabled","displayName":"Configure Microsoft Edge Scareware blocker protection","description":"This policy setting allows administrators to control whether Microsoft Edge enables Scareware blocker, an AI-powered feature for protecting users from potential tech scams. To support this feature, Microsoft Edge downloads a machine learning model file from Microsoft to the device.\n\nIf you enable or don’t configure this policy, Microsoft Edge Scareware blocker uses local AI to detect potential tech scams.\n\nIf you disable this policy, Microsoft Edge Scareware blocker is disabled. The machine learning model file doesn't download to the device, and if downloaded deletion occurs.\n\nWhen this policy is enabled, the policies \"ScarewareBlockerBlocksDetectedSitesEnabled\", \"ScarewareBlockerSendDetectedSitesToSmartScreenEnabled\", and \"ScarewareBlockerAllowListDomains\" can be used to configure the behavior of the Scareware blocker feature. If both of those policies are disabled, enabling this policy has no effect.\n\nWhen this policy is disabled, the policies \"ScarewareBlockerBlocksDetectedSitesEnabled\", \"ScarewareBlockerSendDetectedSitesToSmartScreenEnabled\", and \"ScarewareBlockerAllowListDomains\" have no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockerprotectionenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scarewareblockerprotectionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scarewareblockerprotectionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_scarewareblockersenddetectedsitestosmartscreenenabled","displayName":"Configure Microsoft Edge Scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen","description":"This policy controls whether Microsoft Edge shares URLs of sites that are detected as potential tech scams with Microsoft Defender SmartScreen.\n\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\n\nIf you enable this policy, Microsoft Edge shares URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.\n\nIf you disable or don't configure this policy, Microsoft Edge doesn't share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockersenddetectedsitestosmartscreenenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scarewareblockersenddetectedsitestosmartscreenenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scarewareblockersenddetectedsitestosmartscreenenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_scheduledscan","displayName":"Scheduled Scan","description":"Schedule scans with Microsoft Defender for Endpoint.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-schedule-scan"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_scheduledscan_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scheduledscan_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_screencaptureallowed","displayName":"Allow or deny screen capture","description":"If you enable this policy, or don't configure this policy, a web page can use screen-share APIs (for example, getDisplayMedia() or the Desktop Capture extension API) for a screen capture.\nIf you disable this policy, calls to screen-share APIs will fail. For example, if you're using a web-based online meeting, video or screen sharing will not work.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#screencaptureallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_screencaptureallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_screencaptureallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_screencaptureallowedbyorigins","displayName":"Allow Desktop, Window, and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture.\n\nLeaving the policy unset means that sites will not be considered for an override at this scope of Capture.\n\nThis policy is not considered if a site matches a URL pattern in any of the following policies: \"WindowCaptureAllowedByOrigins\", \"TabCaptureAllowedByOrigins\", \"SameOriginTabCaptureAllowedByOrigins\".\n\nIf a site matches a URL pattern in this policy, the \"ScreenCaptureAllowed\" will not be considered.\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#screencaptureallowedbyorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_screencapturewithoutgestureallowedfororigins","displayName":"Allow screen capture without prior user gesture","description":"For security reasons, the\ngetDisplayMedia() web API requires\na prior user gesture (\"transient activation\") to be called or the API will\nfail.\n\nWhen this policy is configured, admins can specify origins on which this API\ncan be called without prior user gesture.\n\nFor detailed information on valid url patterns, see\nhttps://go.microsoft.com/fwlink/?linkid=2095322. Note: * is not an accepted\nvalue for this policy.\n\nIf this policy is not configured, all origins require a prior user gesture to\ncall this API.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#screencapturewithoutgestureallowedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\n​\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL will be enabled.​\n\nIf you disable this policy, web page scrolling to specific text fragments via a URL will be disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scrolltotextfragmentenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scrolltotextfragmentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scrolltotextfragmentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_seamlesswebtobrowsersigninenabled","displayName":"Seamless Web To Browser Sign-in Enabled","description":"This policy only takes effect when the \"WebToBrowserSignInEnabled\" is enabled.\nIf this policy is enabled, users cannot turn off Seamless Web to Browser Sign-in feature from \"Automatic sign in on Microsoft Edge\" setting on Microsoft Edge profile settings page and that toggle will be greyed out.\nIf this policy is disabled, users cannot turn on Seamless Web to Browser Sign-in feature from \"Automatic sign in on Microsoft Edge\" setting on Microsoft Edge profile settings page and that toggle will be greyed out.\nIf this policy is not configured, users can turn on/off Seamless Web to Browser Sign-in feature from settings by themselves.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#seamlesswebtobrowsersigninenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_seamlesswebtobrowsersigninenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_seamlesswebtobrowsersigninenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_searchfiltersenabled","displayName":"Search Filters Enabled","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions will be shown.\n\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\n\nIf you disable this policy, the autosuggestion dropdown won't display the ribbon of available filters.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#searchfiltersenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_searchfiltersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_searchfiltersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_searchforimageenabled","displayName":"Search for image enabled","description":"This policy lets you configure the Image Search feature in the right-click context menu.\n\nIf you enable or don't configure this policy, then the \"Search the web for image\" option will be visible in the context menu.\n\nIf you disable this policy, then the \"Search the web for image\" will not be visible in the context menu.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#searchforimageenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_searchforimageenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_searchforimageenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_searchinsidebarenabled","displayName":"Search in Sidebar enabled","description":"Search in Sidebar allows users to open search result in sidebar (including sidebar search for Progressive Web Apps).\n\nIf you configure this policy to 'EnableSearchInSidebar' or don't configure it, Search in sidebar will be enabled.\n\nIf you configure this policy to 'DisableSearchInSidebarForKidsMode', Search in sidebar will be disabled when in Kids mode. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\n\nIf you configure this policy to 'DisableSearchInSidebar', Search in sidebar will be disabled. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\n\nPolicy options mapping:\n\n* EnableSearchInSidebar (0) = Enable search in sidebar\n\n* DisableSearchInSidebarForKidsMode (1) = Disable search in sidebar for Kids Mode\n\n* DisableSearchInSidebar (2) = Disable search in sidebar\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#searchinsidebarenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_searchinsidebarenabled_0","displayName":"Enable search in sidebar","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_searchinsidebarenabled_1","displayName":"Disable search in sidebar for Kids Mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_searchinsidebarenabled_2","displayName":"Disable search in sidebar","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_searchsuggestenabled","displayName":"Enable search suggestions","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\n\nIf you enable this policy, web search suggestions are used.\n\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\n\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#searchsuggestenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_searchsuggestenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_searchsuggestenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_securitykeypermitattestation","displayName":"Websites or domains that don't need permission to use direct Security Key attestation","description":"Specifies websites and domains that don't need explicit user permission when attestation certificates from security keys are requested. Additionally, a signal is sent to the security key indicating that it can use individual attestation. Without this, users are prompted each time a site requests attestation of security keys.\n\nSites (like https://contoso.com/some/path) only match as U2F appIDs. Domains (like contoso.com) only match as webauthn RP IDs. To cover both U2F and webauthn APIs for a given site, you need to list both the appID URL and domain.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#securitykeypermitattestation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_sendsiteinfotoimproveservices","displayName":"Send site information to improve Microsoft services","description":"This policy enables sending info about websites visited in Microsoft Edge to Microsoft to improve services like search.\n\nEnable this policy to send info about websites visited in Microsoft Edge to Microsoft. Disable this policy to not send info about websites visited in Microsoft Edge to Microsoft. In both cases, users can't change or override the setting.\n\nOn Windows 10, Beta and Stable if this policy is not configured, Microsoft Edge will default to the Windows diagnostic data setting. If this policy is enabled Microsoft Edge will only send info about websites visited in Microsoft Edge if the Windows Diagnostic data setting is set to Full. If this policy is disabled Microsoft Edge will not send info about websites visited. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\n\nOn Windows 10, Canary and Dev channels, this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.\n\nOn Windows 7, 8, and Mac this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sendsiteinfotoimproveservices"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sendsiteinfotoimproveservices_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sendsiteinfotoimproveservices_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sensorsallowedforurls","displayName":"Allow access to sensors on specific sites","description":"Define a list of sites, based on URL patterns, that can access and use sensors such as motion and light sensors.\n\nIf you don't configure this policy, the global default value from the \"DefaultSensorsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor URL patterns that don't match this policy, the following order of precedence is used: The \"SensorsBlockedForUrls\" policy (if there is a match), the \"DefaultSensorsSetting\" policy (if set), or the user's personal settings.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"SensorsBlockedForUrls\" policy. You can't allow and block a URL.\n\nFor detailed information about valid URL patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sensorsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_sensorsblockedforurls","displayName":"Block access to sensors on specific sites","description":"Define a list of sites, based on URL patterns, that can't access sensors such as motion and light sensors.\n\nIf you don't configure this policy, the global default value from the \"DefaultSensorsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor URL patterns that don't match this policy, the following order of precedence is used: The \"SensorsAllowedForUrls\" policy (if there is a match), the \"DefaultSensorsSetting\" policy (if set), or the user's personal settings.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"SensorsAllowedForUrls\" policy. You can't allow and block a URL.\n\nFor detailed information about valid URL patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sensorsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_serialallowallportsforurls","displayName":"Automatically grant sites permission to connect all serial ports","description":"Setting the policy allows you to list sites which are automatically granted permission to access all available serial ports.\n\nThe URLs must be valid, or the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered.\n\nThis policy overrides \"DefaultSerialGuardSetting\", \"SerialAskForUrls\", \"SerialBlockedForUrls\" and the user's preferences.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#serialallowallportsforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_serialaskforurls","displayName":"Allow the Serial API on specific sites","description":"Specifies URL patterns for sites that are allowed to request access to a serial port.\n\nIf not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings.\n\nFor unmatched sites, the following order applies:\n\n1. \"SerialBlockedForUrls\" (if matched).\n\n2. DefaultSerialGuardSetting (if set).\n\n3. User's settings.\n\nIf URL patterns in this policy conflict with those in \"SerialBlockedForUrls\", they will be ignored.\n\nFor detailed information about valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#serialaskforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_serialblockedforurls","displayName":"Block the Serial API on specific sites","description":"Specifies URL patterns for sites that aren't allowed to request access to a serial port.\n\nIf not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings.\n\nFor unmatched sites, the following order applies:\n\n1. SerialAskForUrls (if matched).\n\n2. DefaultSerialGuardSetting (if set).\n\n3. User's settings.\n\nURL patterns in this policy must not conflict with those in SerialAskForUrls. This policy takes precedence.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#serialblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup","description":"This policy controls whether Microsoft Edge enables the ServiceWorkerAutoPreload feature.\n\nWhen enabled or not configured, Microsoft Edge may initiate the main resource network request concurrently with the Service Worker bootstrap process. This can improve performance in scenarios where the Service Worker isn't already running.\n\nIf you disable this policy, Microsoft Edge will wait to dispatch the navigation request until after the Service Worker has started.\n\nThis is a temporary policy and will be removed in version 144 of Microsoft Edge.\n\nFor more information on the feature, see https://github.com/WICG/service-worker-auto-preload.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#serviceworkerautopreloadenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_serviceworkerautopreloadenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_serviceworkerautopreloadenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_serviceworkertocontrolsrcdociframeenabled","displayName":"Allow ServiceWorker to control srcdoc iframes","description":"https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with the \"allow-same-origin\" sandbox attribute to be under ServiceWorker control.\n\nBy default (if left unset) or when set to Enabled, Microsoft Edge makes srcdoc iframes with \"allow-same-origin\" sandbox attributes to be under ServiceWorker control.\n\nSetting the policy to Disabled prevents ServiceWorker control over srcdoc iframes.\n\nThis policy is temporary and planned for deprecation in 2026.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#serviceworkertocontrolsrcdociframeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_serviceworkertocontrolsrcdociframeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_serviceworkertocontrolsrcdociframeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sharebrowsinghistorywithcopilotsearchallowed","displayName":"Allow sharing tenant-approved browsing history with Microsoft 365 Copilot Search","description":"This policy controls whether browsing history in Microsoft Edge is shared with Microsoft 365 Copilot Search to provide more relevant search results. Only tenant-approved, work-related sites are shared.\n\nThis feature is available only to users who are signed in to Microsoft Edge with an Entra ID account and have an eligible Microsoft 365 Copilot license.\n\nIf you enable or don't configure this policy, browsing history will be shared with Microsoft 365 Copilot Search by default, and users can turn off sharing using the toggle in Microsoft Edge settings.\n\nIf you disable this policy, browsing history won't be shared with Microsoft 365 Copilot Search.\n\nLearn more about how Copilot uses data and consent at https://go.microsoft.com/fwlink/?linkid=2333202","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sharebrowsinghistorywithcopilotsearchallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sharebrowsinghistorywithcopilotsearchallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sharebrowsinghistorywithcopilotsearchallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sharedarraybufferunrestrictedaccessallowed","displayName":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context","description":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context. A SharedArrayBuffer is a binary data buffer that can be used to create views on shared memory. SharedArrayBuffers have a memory access vulnerability in several popular CPUs.\n\nIf you enable this policy, sites are allowed to use SharedArrayBuffers with no restrictions.\n\nIf you disable or don't configure this policy, sites are allowed to use SharedArrayBuffers only when cross-origin isolated.\n\nMicrosoft Edge will require cross-origin isolation when using SharedArrayBuffers from Microsoft Edge 91 onward for Web Compatibility reasons.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sharedarraybufferunrestrictedaccessallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sharedarraybufferunrestrictedaccessallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sharedarraybufferunrestrictedaccessallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sharedlinksenabled","displayName":"Show links shared from Microsoft 365 apps in History","description":"Allows Microsoft Edge to display links recently shared by or shared with the user from Microsoft 365 apps in History.\n\nIf you enable or don't configure this policy, Microsoft Edge displays links recently shared by or shared with the user from Microsoft 365 apps in History.\n\nIf you disable this policy, Microsoft Edge does not display links recently shared by or shared with the user from Microsoft 365 apps in History. The control in Microsoft Edge settings is disabled and set to off.\n\nThis policy only applies for Microsoft Edge local user profiles and profiles signed in using Azure Active Directory.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sharedlinksenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sharedlinksenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sharedlinksenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sharedworkerbloburlfixenabled","displayName":"Make SharedWorker blob URL behavior aligned with the specification","description":"According to Service Worker specification\nhttps://w3c.github.io/ServiceWorker/#control-and-use-worker-client, workers\nshould inherit controllers for blob URLs. Currently, only DedicatedWorkers\ninherit the controller, while SharedWorkers do not.\n\nEnabled/Unset: Microsoft Edge inherits\nthe controller for SharedWorker blob URLs, aligning with the specification.\n\nDisabled: Behavior remains unchanged, not aligning with the specification.\n\nThis policy is temporary and will be removed in a future update.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sharedworkerbloburlfixenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sharedworkerbloburlfixenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sharedworkerbloburlfixenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sharepointonpremfrontdoorurl","displayName":"SharePoint Server Front Door URL","description":"Specifies the SharePoint Server 2019 on-premises URL that the OneDrive sync app should try to authenticate and sync against.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#sharepointonpremfrontdoorurl"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_sharepointonpremprioritizationpolicy","displayName":"SharePoint Prioritization","description":"For hybrid scenarios where the email is the same for both SharePoint Server on-premises and SharePoint Online, determines whether or not the client should set up sync for SharePoint Server or SharePoint Online first during the first-run scenario.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#sharepointonpremprioritizationpolicy"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_sharepointonpremprioritizationpolicy_0","displayName":"Prioritize SharePoint Online","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sharepointonpremprioritizationpolicy_1","displayName":"Prioritize SharePoint Server","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sharepointonpremtenantname","displayName":"SharePoint Server Tenant Name","description":"Specifies the name of the folder created for syncing the SharePoint Server 2019 files specified in the Front Door URL.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#sharepointonpremtenantname"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_showacrobatsubscriptionbutton","displayName":"Shows button on native PDF viewer in Microsoft Edge that allows users to sign up for Adobe Acrobat subscription","description":"This policy lets the native PDF viewer in Microsoft Edge show a button that lets a user looking for advanced digital document features to discover and subscribe to premium offerings. This is done via the Acrobat extension.\n\nIf you enable or don't configure this policy, the button will show up on the native PDF viewer in Microsoft Edge. A user will be able to buy Adobe subscription to access their premium offerings.\n\nIf you disable this policy, the button won't be visible on the native PDF viewer in Microsoft Edge. A user won't be able to discover Adobe's advanced PDF tools or buy their subscriptions.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showacrobatsubscriptionbutton"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showacrobatsubscriptionbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showacrobatsubscriptionbutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showcasticonintoolbar","displayName":"Show the cast icon in the toolbar","description":"Set this policy to true to show the Cast toolbar icon on the toolbar or the overflow menu. Users won't be able to remove it.\n\nIf you don't configure this policy or if you disable it, users can pin or remove the icon by using its contextual menu.\n\nIf you've also set the \"EnableMediaRouter\" policy to false, then this policy is ignored, and the toolbar icon isn't shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showcasticonintoolbar"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showcasticonintoolbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showcasticonintoolbar_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showdocstageonlaunch","displayName":"Show Template Gallery on app launch","description":"Show the template picker when launching Word, Excel, and PowerPoint.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-office"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_showdocstageonlaunch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showdocstageonlaunch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showdownloadsinsecurewarningsenabled","displayName":"Enable insecure download warnings","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\n\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user will receive a UI warning, such as \"Insecure download blocked.\" The user will still have an option to proceed and download the item.\n\nIf you disable this policy, the warnings for insecure downloads will be suppressed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showdownloadsinsecurewarningsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showdownloadsinsecurewarningsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showdownloadsinsecurewarningsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showdownloadstoolbarbutton","displayName":"Show Downloads button on the toolbar","description":"Set this policy to always show the Downloads button on the toolbar.\n\nIf you enable this policy, the Downloads button is pinned to the toolbar.\n\nIf you disable or don't configure the policy, the Downloads button isn't shown on the toolbar by default. Users can toggle the Downloads button in edge://settings/appearance.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showdownloadstoolbarbutton"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showdownloadstoolbarbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showdownloadstoolbarbutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showhistorythumbnails","displayName":"Show thumbnail images for browsing history","description":"This policy lets you configure whether the history thumbnail feature collects and saves images for the sites you visit. When enabled, this feature makes it easier to identify sites when you hover over your history results.\nIf you don't configure this policy, the thumbnail feature is turned on after a user visits the history hub twice in the past 7 days.\nIf you enable this policy, the history thumbnail collects and saves images for visited sites.\nIf you disable this policy, the history thumbnail doesn't collect and save images for visited sites.\nWhen the feature is disabled, existing images are deleted on a per user basis, and the feature no longer collects or saves images when a site is visited.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showhistorythumbnails"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showhistorythumbnails_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showhistorythumbnails_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showhomebutton","displayName":"Show Home button on toolbar","description":"Shows the Home button on Microsoft Edge's toolbar.\n\nEnable this policy to always show the Home button. Disable it to never show the button.\n\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showhomebutton"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showhomebutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showhomebutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showmicrosoftrewards","displayName":"Show Microsoft Rewards experiences","description":"Show Microsoft Rewards experience and notifications.\nIf you enable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\n - The setting to enable Give mode will be enabled and respect the user's setting.\n\nIf you disable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will not see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be disabled and toggled off.\n\nIf you don't configure this policy:\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\n - The setting to enable Give mode will be enabled and respect the user's setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showmicrosoftrewards"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showmicrosoftrewards_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showmicrosoftrewards_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showofficeshortcutinfavoritesbar","displayName":"Show Microsoft Office shortcut in favorites bar","description":"Specifies whether to include a shortcut to Office.com in the favorites bar. For users signed into Microsoft Edge the shortcut takes users to their Microsoft Office apps and docs.\n\nIf this policy is enabled or not configure, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu.\n\nIf the policy is disabled, the shortcut won't be shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showofficeshortcutinfavoritesbar"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showofficeshortcutinfavoritesbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showofficeshortcutinfavoritesbar_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showpdfdefaultrecommendationsenabled","displayName":"Allow notifications to set Microsoft Edge as default PDF reader","description":"This policy setting lets you decide whether employees should receive recommendations to set Microsoft Edge as PDF handler.\n\nIf you enable or don't configure this setting, employees receive recommendations from Microsoft Edge to set itself as the default PDF handler.\n\nIf you disable this setting, employees will not receive any notifications from Microsoft Edge to set itself as the default PDF handler.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showpdfdefaultrecommendationsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showpdfdefaultrecommendationsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showpdfdefaultrecommendationsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showrecommendationsenabled","displayName":"Allow feature recommendations and browser assistance notifications from Microsoft Edge","description":"This setting controls the in-browser assistance notifications which are intended to help users get the most out of Microsoft Edge. This is done by recommending features and by helping them use browser features. These notifications take the form of dialog boxes, flyouts, coach marks and banners in the browser. An example of an assistance notification would be when a user has many tabs opened in the browser. In this instance Microsoft Edge may prompt the user to try out the vertical tabs feature which is designed to give better browser tab management.\n\nDisabling this policy will stop this message from appearing again even if the user has too many tabs open.\n Any features that have been disabled by a management policy are not suggested to users.\nIf you enable or don't configure this setting, users will receive recommendations or notifications from Microsoft Edge.\n If you disable this setting, users will not receive any recommendations or notifications from Microsoft Edge","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showrecommendationsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showrecommendationsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showrecommendationsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showtabpreviewenabled","displayName":"Enable tab preview on hover","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\n\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\n\nIf you disable this policy, tab previews will not be shown on hover.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showtabpreviewenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showtabpreviewenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showtabpreviewenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showwhatsnewonlaunch","displayName":"Show Whats New dialog","description":"Show the monthly Whats New dialog to users.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-office"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_showwhatsnewonlaunch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showwhatsnewonlaunch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support","description":"Enable support for Signed HTTP Exchange (SXG).\n\nIf this policy isn't set or enabled, Microsoft Edge will accept web contents served as Signed HTTP Exchanges.\n\nIf this policy is set to disabled, Signed HTTP Exchanges can't be loaded.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#signedhttpexchangeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_signedhttpexchangeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_signedhttpexchangeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_silentprintingenabled","displayName":"Enable Silent Printing","description":"This policy controls whether Microsoft Edge uses silent printing.\n\nIf you enable this policy, Edge automatically closes the print preview window and prints to the default printer using its default settings. If the default printer is Save as PDF, the file is saved to the user's Downloads folder.\n\nIf you disable or don't configure this policy, silent printing is disabled. The print preview window stays open and the user must choose print settings as usual.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#silentprintingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_silentprintingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_silentprintingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_siteperprocess","displayName":"Enable site isolation for every site","description":"The 'SitePerProcess' policy can be used to prevent users from opting out of the default behavior of isolating all sites. Note that you can also use the \"IsolateOrigins\" policy to isolate additional, finer-grained origins.\nIf you enable this policy, users can't opt out of the default behavior where each site runs in its own process.\nIf you disable or don’t configure this policy, a user can opt out of site isolation. (For example, by using \"Disable site isolation\" entry in edge://flags.) Disabling the policy or not configuring the policy doesn't turn off Site Isolation.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#siteperprocess"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_siteperprocess_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_siteperprocess_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sleepingtabsblockedforurls","displayName":"Block Sleeping Tabs on specific sites","description":"Define a list of sites, based on URL patterns, that are not allowed to be put to sleep by Sleeping Tabs.\n\nIf the policy \"SleepingTabsEnabled\" is disabled, this list is not used and no sites will be put to sleep automatically.\n\nIf you don't configure this policy, all sites will be eligible to be put to sleep unless the user's personal configuration blocks them.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sleepingtabsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_sleepingtabsenabled","displayName":"Configure Sleeping Tabs","description":"This policy setting lets you configure whether to turn on Sleeping Tabs. Sleeping Tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, Sleeping Tabs is turned on.\n\nIndividual sites may be blocked from being put to sleep by configuring the policy \"SleepingTabsBlockedForUrls\".\n\nIf you enable this setting, Sleeping Tabs is turned on.\n\nIf you disable this setting, Sleeping Tabs is turned off.\n\nIf you don't configure this setting, users can choose whether to use Sleeping Tabs.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sleepingtabsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sleepingtabsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if Sleeping Tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\n\nTabs are only put to sleep automatically when the policy \"SleepingTabsEnabled\" is enabled or is not configured and the user has enabled the Sleeping Tabs setting.\n\nIf you don't configure this policy, users can choose the timeout value.\n\nPolicy options mapping:\n\n* 5Minutes (300) = 5 minutes of inactivity\n\n* 15Minutes (900) = 15 minutes of inactivity\n\n* 30Minutes (1800) = 30 minutes of inactivity\n\n* 1Hour (3600) = 1 hour of inactivity\n\n* 2Hours (7200) = 2 hours of inactivity\n\n* 3Hours (10800) = 3 hours of inactivity\n\n* 6Hours (21600) = 6 hours of inactivity\n\n* 12Hours (43200) = 12 hours of inactivity\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sleepingtabstimeout"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_0","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_1","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_2","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_3","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_4","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_5","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_6","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_7","displayName":"12 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_8","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_smartactionsblocklist","displayName":"Block smart actions for a list of services","description":"List specific services, such as PDFs, and websites that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\n\nIf you enable the policy:\n - The smart action in the mini and full context menu will be disabled for all profiles for services that match the given list.\n - Users will not see the smart action in the mini and full context menu on text selection for services that match the given list.\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be disabled for services that match the given list.\n\nIf you disable or don't configure this policy:\n - The smart action in the mini and full context menu will be enabled for all profiles.\n - Users will see the smart action in the mini and full context menu on text selection.\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be enabled.\n\nPolicy options mapping:\n\n* smart_actions (smart_actions) = Smart actions in pdfs and on websites\n\n* smart_actions_website (smart_actions_website) = Smart actions on websites\n\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartactionsblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_smartscreenallowlistdomains","displayName":"Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings","description":"Configure the list of Microsoft Defender SmartScreen trusted domains. This means:\nMicrosoft Defender SmartScreen won't check for potentially malicious resources like phishing software and other malware if the source URLs match these domains.\nThe Microsoft Defender SmartScreen download protection service won't check downloads hosted on these domains.\n\nIf you enable this policy, Microsoft Defender SmartScreen trusts these domains.\nIf you disable or don't set this policy, default Microsoft Defender SmartScreen protection is applied to all resources.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender Advanced Threat Protection. You must configure your allow and block lists in Microsoft Defender Security Center instead.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartscreenallowlistdomains"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_smartscreendnsrequestsenabled","displayName":"Enable Microsoft Defender SmartScreen DNS requests","description":"This policy lets you configure whether to enable DNS requests made by Microsoft Defender SmartScreen. Note: Disabling DNS requests will prevent Microsoft Defender SmartScreen from getting IP addresses, and potentially impact the IP-based protections provided.\n\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen will make DNS requests.\n\nIf you disable this setting, Microsoft Defender SmartScreen will not make any DNS requests.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartscreendnsrequestsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_smartscreendnsrequestsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smartscreendnsrequestsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_smartscreenenabled","displayName":"Configure Microsoft Defender SmartScreen","description":"This policy setting lets you configure whether to turn on Microsoft Defender SmartScreen. Microsoft Defender SmartScreen provides warning messages to help protect your users from potential phishing scams and malicious software. By default, Microsoft Defender SmartScreen is turned on.\n\nIf you enable this setting, Microsoft Defender SmartScreen is turned on.\n\nIf you disable this setting, Microsoft Defender SmartScreen is turned off.\n\nIf you don't configure this setting, users can choose whether to use Microsoft Defender SmartScreen.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartscreenenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_smartscreenenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smartscreenenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_smartscreenpuaenabled","displayName":"Configure Microsoft Defender SmartScreen to block potentially unwanted apps","description":"This policy setting lets you configure whether to turn on blocking for potentially unwanted apps in Microsoft Defender SmartScreen. Potentially unwanted app blocking in Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking in Microsoft Defender SmartScreen is turned off by default.\n\nIf you enable this setting, potentially unwanted app blocking in Microsoft Defender SmartScreen is turned on.\n\nIf you disable this setting, potentially unwanted app blocking in Microsoft Defender SmartScreen is turned off.\n\nIf you don't configure this setting, users can choose whether to use potentially unwanted app blocking in Microsoft Defender SmartScreen.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartscreenpuaenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_smartscreenpuaenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smartscreenpuaenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder","displayName":"Set the order in which S/MIME certificates are considered","description":"Set the order in which certificates will be used to decrypt and encrypt S/MIME messages.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#set-the-order-in-which-smime-certificates-are-considered"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_0","displayName":"Contacts","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_1","displayName":"Global Address List","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_2","displayName":"Device","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_3","displayName":"LDAP","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_speechrecognitionenabled","displayName":"Configure Speech Recognition","description":"Set whether websites can use the W3C Web Speech API to recognize speech from the user. The Microsoft Edge implementation of the Web Speech API uses Azure Cognitive Services, so voice data will leave the machine.\n\nIf you enable or don't configure this policy, web-based applications that use the Web Speech API can use Speech Recognition.\n\nIf you disable this policy, Speech Recognition is not available through the Web Speech API.\n\nRead more about this feature here:\nSpeechRecognition API: https://go.microsoft.com/fwlink/?linkid=2143388\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2143680","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#speechrecognitionenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_speechrecognitionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_speechrecognitionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_spellcheckenabled","displayName":"Enable spellcheck","description":"If you enable or don't configure this policy, the user can use spellcheck.\n\nIf you disable this policy, the user can't use spellcheck and the \"SpellcheckLanguage\" and \"SpellcheckLanguageBlocklist\" policies are also disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#spellcheckenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_spellcheckenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_spellcheckenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_splitscreenenabled","displayName":"Enable split screen feature in Microsoft Edge","description":"This policy lets you configure the split screen feature in Microsoft Edge. This feature lets a user open two web pages in one tab.\n\nIf you enable or don't configure this policy, users can use the split screen feature in Microsoft Edge.\n\nIf you disable this policy, users can't use the split screen feature in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#splitscreenenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_splitscreenenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_splitscreenenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sslerroroverrideallowed","displayName":"Allow users to proceed from the HTTPS warning page","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure (default) this policy, users can click through these warning pages.\n\nIf you disable this policy, users are blocked from clicking through any warning page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sslerroroverrideallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sslerroroverrideallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sslerroroverrideallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sslerroroverrideallowedfororigins","displayName":"Allow users to proceed from the HTTPS warning page for specific origins","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure the \"SSLErrorOverrideAllowed\" policy, this policy does nothing.\n\nIf you disable the \"SSLErrorOverrideAllowed\" policy, configuring this policy lets you configure a list of origin patterns for sites where users can continue to click through SSL error pages. Users can't click through SSL error pages on origins that are not on this list.\n\nIf you don't configure this policy, the \"SSLErrorOverrideAllowed\" policy applies for all sites.\n\nFor detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy. This policy only matches based on origin, so any path or query in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sslerroroverrideallowedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_sslversionmin","displayName":"Minimum TLS version enabled","description":"Sets the minimum supported version of SSL. If you don't configure this policy, Microsoft Edge uses a default minimum version, TLS 1.0.\n\nIf you enable this policy, you can set the minimum version to one of the following values: \"tls1\", \"tls1.1\" or \"tls1.2\". When set, Microsoft Edge won't use any version of SSL/TLS lower than the specified version. Any unrecognized value is ignored.\n\n* \"tls1\" = TLS 1.0\n\n* \"tls1.1\" = TLS 1.1\n\n* \"tls1.2\" = TLS 1.2","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sslversionmin"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sslversionmin_0","displayName":"TLS 1.0","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sslversionmin_1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sslversionmin_2","displayName":"TLS 1.2","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_startdaemononapplaunch","displayName":"Register app on launch","description":"Force Office apps to register with AutoUpdate on each launch.","helpText":null,"infoUrls":["https://macadmins.software/docs/MAU_38.pdf"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_startdaemononapplaunch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_startdaemononapplaunch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_strictermixedcontenttreatmentenabled","displayName":"Enable stricter treatment for mixed content","description":"This policy controls the treatment for mixed content (HTTP content in HTTPS sites) in the browser.\n\nIf you set this policy to true or not set, audio and video mixed content will be automatically upgraded to HTTPS (that is, the URL will be rewritten as HTTPS, without a fallback if the resource isn’t available over HTTPS) and a 'Not Secure' warning will be shown in the URL bar for image mixed content.\n\nIf you set the policy to false, auto upgrades will be disabled for audio and video, and no warning will be shown for images.\n\nThis policy does not affect other types of mixed content other than audio, video, and images.\n\nThis policy will no longer take effect starting in Microsoft Edge 84.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#strictermixedcontenttreatmentenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_strictermixedcontenttreatmentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_strictermixedcontenttreatmentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_suppresso365autodiscoveroverride","displayName":"Use domain-based autodiscover instead of Office 365","description":"When true, autodiscover will contact the endpoint for the mailbox domain instead of the Office 365 service. This is recommended for on-premises Exchange mailboxes.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_suppresso365autodiscoveroverride_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_suppresso365autodiscoveroverride_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_suppressunsupportedoswarning","displayName":"Suppress the unsupported OS warning","description":"Suppresses the warning that appears when Microsoft Edge is running on a computer or operating system that is no longer supported.\n\nIf this policy is false or unset, the warnings will appear on such unsupported computers or operating systems.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#suppressunsupportedoswarning"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_suppressunsupportedoswarning_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_suppressunsupportedoswarning_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_switchintranetsitestoworkprofile","displayName":"Switch intranet sites to a work or school profile","description":"Allows Microsoft Edge to switch to the appropriate profile when Microsoft Edge detects that a URL is the intranet.\n\nIf you enable or don't configure this policy, navigations to intranet URLs will switch to the most recently used work or school profile if one exists.\n\nIf you disable this policy, navigations to intranet URLs will remain in the current browser profile.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#switchintranetsitestoworkprofile"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_switchintranetsitestoworkprofile_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_switchintranetsitestoworkprofile_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_syncdisabled","displayName":"Disable synchronization of data using Microsoft sync services","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\n\nIf you don't set this policy or apply it as recommended, users will be able to turn sync on or off. If you apply this policy as mandatory, users will not be able to turn sync on.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#syncdisabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_syncdisabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_syncdisabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_synctypeslistdisabled","displayName":"Configure the list of types that are excluded from synchronization","description":"If you enable this policy all the specified data types will be excluded from synchronization. This policy can be used to limit the type of data uploaded to the Microsoft Edge synchronization service.\n\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", and “collections”. Note that these data type names are case sensitive.\n\nUsers will not be able to override the disabled data types.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#synctypeslistdisabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_systemextensions","displayName":"Use System Extensions","description":"Whether system extensions are used on MacOS 10.15 (Catalina) or not.","helpText":null,"infoUrls":["https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-atp-for-mac-is-moving-to-system-extensions/ba-p/1608736"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_systemextensions_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_systemextensions_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_tabcaptureallowedbyorigins","displayName":"Allow Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Tab Capture.\n\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\n\nThis policy is not considered if a site matches a URL pattern in the \"SameOriginTabCaptureAllowedByOrigins\" policy.\n\nIf a site matches a URL pattern in this policy, the following policies will not be considered: \"WindowCaptureAllowedByOrigins\", \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tabcaptureallowedbyorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_tabfreezingenabled","displayName":"Allow freezing of background tabs","description":"Controls whether Microsoft Edge can freeze tabs that are in the background for at least 5 minutes.\n\nTab freezing reduces CPU, battery, and memory usage. Microsoft Edge uses heuristics to avoid freezing tabs that do useful work in the background, such as display notifications, play sound, and stream video.\n\nIf you enable or don't configure this policy, tabs that have been in the background for at least 5 minutes might be frozen.\n\nIf you disable this policy, no tabs will be frozen.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tabfreezingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_tabfreezingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_tabfreezingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_tabservicesenabled","displayName":"Enable tab organization suggestions","description":"This policy controls whether Microsoft Edge can use its tab organization service to help name or suggest tab groups to increase productivity.\n\nIf you enable or don't configure this policy, when a user creates a tab group or activates certain \"Group Similar Tabs\" features Microsoft Edge sends tab data to its tab organization service. This data includes URLs, page titles, and existing group information. The service uses this data to return suggestions for better groupings and group names.\n\nIf you disable this policy, no data will be sent to the tab organization service. Microsoft Edge won't suggest group names when a group is created and certain \"Group Similar Tabs\" features that rely on the service won't be available.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tabservicesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_tabservicesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_tabservicesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_tags","displayName":"Device tags","description":null,"helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#device-tags"],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":null},{"id":"com.apple.managedclient.preferences_tags_item_key","displayName":"Type of tag","description":"Specify a tag name and its value. The GROUP tag, tags the device with the specified value. The tag is reflected in the portal under the device page and can be used for filtering and grouping devices.","helpText":null,"infoUrls":[],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":{"id":"com.apple.managedclient.preferences_tags_item_key_0","displayName":"GROUP","description":null,"helpText":null}},{"id":"com.apple.managedclient.preferences_tags_item_value","displayName":"Value of tag","description":"Only one value per tag type can be set. Type of tags are unique, and should not be repeated in the same configuration profile.","helpText":null,"infoUrls":[],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":null},{"id":"com.apple.managedclient.preferences_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank","description":"If you enable this policy or leave it unset, the window.opener property is set to null unless the anchor specifies rel=\"opener\".\n\nIf you disable this policy, popups that target _blank are permitted to access (via JavaScript) the page that requested to open the popup.\n\nThis policy will be obsoleted in Microsoft Edge version 95.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#targetblankimpliesnoopener"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_targetblankimpliesnoopener_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_targetblankimpliesnoopener_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_taskmanagerendprocessenabled","displayName":"Enable ending processes in the Browser task manager","description":"If you enable or don't configure this policy, users can end processes in the Browser task manager. If you disable it, users can't end processes, and the End process button is disabled in the Browser task manager.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#taskmanagerendprocessenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_taskmanagerendprocessenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_taskmanagerendprocessenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_textpredictionenabled","displayName":"Text prediction enabled by default","description":"The Microsoft Turing service uses natural language processing to generate predictions for long-form editable text fields on web pages.\n\nIf you enable or don't configure this policy, text predictions will be provided for eligible text fields.\n\nIf you disable this policy, text predictions will not be provided in eligible text fields. Sites may still provide their own text predictions.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#textpredictionenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_textpredictionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_textpredictionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_thirdpartystoragepartitioningblockedfororigins","displayName":"Disable third-party storage partitioning for specific top-level origins (deprecated)","description":"This policy lets you set a list of URL patterns that specify top-level origins for which third-party storage partitioning (partitioning of cross-origin iframe storage) should be disabled.\n\nIf this policy isn't set or a top-level origin doesn't match one of the URL patterns, then the value from \"DefaultThirdPartyStoragePartitioningSetting\" will be used.\n\nNote that the patterns you list are treated as origins, not URLs, so you shouldn't specify a path. For detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nThis feature will be removed starting in Microsoft Edge version 145. To ensure compatibility, use the requestStorageAccess method instead. For more information, see https://developer.mozilla.org/en-US/docs/Web/API/Document/requestStorageAccess.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#thirdpartystoragepartitioningblockedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_threattypesettings","displayName":"Threat type settings","description":"The threatTypeSettings preference in the antivirus engine is used to control how certain threat types are handled by the product.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#threat-type-settings"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_threattypesettings_item_key","displayName":"Threat type","description":"Type of the threat for which the behavior is configured.","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_threattypesettings_item_key_0","displayName":"potentially_unwanted_application","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_threattypesettings_item_key_1","displayName":"archive_bomb","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_threattypesettings_item_value","displayName":"Action to take","description":"Action to take when coming across a threat of the type specified in the preceding section.","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_threattypesettings_item_value_0","displayName":"audit","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_threattypesettings_item_value_1","displayName":"block","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_threattypesettings_item_value_2","displayName":"off","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_threattypesettingsmergepolicy","displayName":"Threat type settings merge","description":"Specify the merge policy for threat type settings. This can be a combination of administrator-defined and user-defined settings (merge) or only administrator-defined settings (admin_only). This setting can be used to restrict local users from defining their own settings for different threat types.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#threat-type-settings-merge-policy"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_threattypesettingsmergepolicy_0","displayName":"merge","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_threattypesettingsmergepolicy_1","displayName":"admin_only","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_tls13earlydataenabled","displayName":"Control whether TLS 1.3 Early Data is enabled in Microsoft Edge","description":"This policy controls whether TLS 1.3 Early Data is enabled in Microsoft Edge.\n\nTLS 1.3 Early Data is an extension that allows an HTTP request to be sent in parallel with the TLS handshake. When enabled and supported by the server, this can improve page load performance.\n\nEnabled – Microsoft Edge enables TLS 1.3 Early Data.\n\nDisabled – Microsoft Edge disables TLS 1.3 Early Data.\n\nNot configured – Microsoft Edge follows the default rollout process for TLS 1.3 Early Data.\n\nNOTE: When this feature is enabled, whether TLS 1.3 Early Data is used depends on server support. Most modern TLS servers and middleware can handle or reject Early Data without interrupting the connection. However, improperly implemented TLS stacks may cause connection failures. If such issues occur, contact the device or software vendor for a resolution.\n\nThis policy is temporary and intended to help test for compatibility issues. It may be removed in a future release once the feature is fully rolled out.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tls13earlydataenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_tls13earlydataenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_tls13earlydataenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors.","description":"This policy controls a security feature in TLS 1.3 that protects connections against downgrade attacks. It is backwards-compatible and will not affect connections to compliant TLS 1.2 servers or proxies. However, older versions of some TLS-intercepting proxies have an implementation flaw which causes them to be incompatible.\n\nIf you set this policy to True, Microsoft Edge will enable these security protections for all connections.\n\nIf you set this policy to False or don’t set it, Microsoft Edge will disable these security protections for connections authenticated with locally-installed CA certificates. These protections are always enabled for connections authenticated with publicly-trusted CA certificates.\n\nThis policy may be used to test for any affected proxies and upgrade them. Affected proxies are expected to fail connections with an error code of ERR_TLS13_DOWNGRADE_DETECTED. A later version of Microsoft Edge will enable this option by default.\n\nAfter it is enabled by default, administrators who need more time to upgrade affected proxies may use this policy to temporarily disable this security feature. This policy will be removed after version 85.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tls13hardeningforlocalanchorsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_tls13hardeningforlocalanchorsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_tls13hardeningforlocalanchorsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_tlsciphersuitedenylist","displayName":"Specify the TLS cipher suites to disable","description":"Configure the list of cipher suites that are disabled for TLS connections.\n\nIf you configure this policy, the list of configured cipher suites will not be used when establishing TLS connections.\n\nIf you don't configure this policy, the browser will choose which TLS cipher suites to use.\n\nCipher suite values to be disabled are specified as 16-bit hexadecimal values. The values are assigned by the Internet Assigned Numbers Authority (IANA) registry.\n\nThe TLS 1.3 cipher suite TLS_AES_128_GCM_SHA256 (0x1301) is required for TLS 1.3 and can't be disabled by this policy.\n\nThis policy does not affect QUIC-based connections. QUIC can be turned off via the \"QuicAllowed\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tlsciphersuitedenylist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_totalmemorylimitmb","displayName":"Set limit on megabytes of memory a single Microsoft Edge instance can use.","description":"Configures the amount of memory that a single Microsoft Edge instance can use before tabs start getting discarded to save memory. The memory used by the tab will be freed and the tab will have to be reloaded when switched to.\n\nIf you enable this policy, the browser will start to discard tabs to save memory once the limitation is exceeded. However, there is no guarantee that the browser is always running under the limit. Any value under 1024 will be rounded up to 1024.\n\nIf you don't set this policy, the browser will only attempt to save memory when it has detected that the amount of physical memory on its machine is low.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#totalmemorylimitmb"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_trackingprevention","displayName":"Block tracking of users' web-browsing activity","description":"Lets you decide whether to block websites from tracking users' web-browsing activity.\n\nIf you enable this policy, you have the following options for setting the level of tracking prevention:\n\n* 0 = Off (no tracking prevention)\n\n* 1 = Basic (blocks harmful trackers, content and ads will be personalized)\n\n* 2 = Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)\n\n* 3 = Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)\n\nIf you disable this policy or don't configure it, users can set their own level of tracking prevention.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#trackingprevention"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_trackingprevention_0","displayName":"Off (no tracking prevention)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_trackingprevention_1","displayName":"Basic (blocks harmful trackers, content and ads will be personalized)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_trackingprevention_2","displayName":"Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_trackingprevention_3","displayName":"Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_translateenabled","displayName":"Enable Translate","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge offers translation functionality to the user by showing an integrated translate flyout when appropriate, and a translate option on the right-click context menu.\n\nDisable this policy to disable all built-in translate features.\n\nIf you don't configure the policy, users can choose whether to use the translation functionality or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#translateenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_translateenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_translateenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_trusto365autodiscoverredirect","displayName":"Trust Office 365 autodiscover redirects","description":"When true, users will not see a dialog if autodiscover redirects the client to a different server. Recommended: true.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_trusto365autodiscoverredirect_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_trusto365autodiscoverredirect_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_typosquattingallowlistdomains","displayName":"Configure the list of domains for which Edge Website Typo Protection won't trigger warnings","description":"Configure the list of Edge Website Typo Protection trusted domains. This means:\nEdge Website Typo Protection won't check for potentially malicious typosquatting websites.\n\nIf you enable this policy, Edge Website Typo Protection trusts these domains.\nIf you disable or don't set this policy, default Edge Website Typo Protection protection is applied to all resources.\n\nThis will only take effect when TyposquattingCheckerEnabled policy is not set or set to enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10/11 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender for Endpoint. You must configure your allow and block lists in Microsoft 365 Defender portal using Indicators (Settings > Endpoints > Indicators).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#typosquattingallowlistdomains"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_typosquattingcheckerenabled","displayName":"Configure Edge Website Typo Protection","description":"This policy setting lets you configure whether to turn on Edge Website Typo Protection. Edge Website Typo Protection provides warning messages to help protect your users from potential typosquatting sites. By default, Edge Website Typo Protection is turned on.\n\nIf you enable this policy, Edge Website Typo Protection is turned on.\n\nIf you disable this policy, Edge Website Typo Protection is turned off.\n\nIf you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#typosquattingcheckerenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_typosquattingcheckerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_typosquattingcheckerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_unthrottlednestedtimeoutenabled","displayName":"JavaScript setTimeout will not be clamped until a higher nesting threshold is set (deprecated)","description":"This policy is deprecated because it is a temporary policy for web standards compliance. It won't work in Microsoft Edge as soon as version 107.\nIf you enable this policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4ms, will not be clamped. This improves short horizon performance, but websites abusing the API will still eventually have their setTimeout usages clamped.\nIf you disable or don't configure policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4ms, will be clamped.\n\nThis is a web standards compliancy feature that may change task ordering on a web page, leading to unexpected behavior on sites that are dependent on a certain ordering.\nIt also may affect sites with a lot of usage of a timeout of 0ms for setTimeout. For example, increasing CPU load.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#unthrottlednestedtimeoutenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_unthrottlednestedtimeoutenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_unthrottlednestedtimeoutenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_updatecache","displayName":"Update cache server","description":"Specify the HTTP(S) URL of the server that you use for cached package updates (PKG files). You must include a trailing forward slash.","helpText":null,"infoUrls":["https://macadmins.software/docs/MAU_CachingServer.pdf"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_updatecheckfrequency","displayName":"Update check frequency (mins)","description":"Specify how often AutoUpdate checks for updates. The allowed range is 240 minutes (4 hours) - 720 minutes (12 hours).","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_updatedeadline.daysbeforeforcedquit","displayName":"Days before forced updates","description":"Specify the maximum number of days that an update can be pending before the user is forced to update the app. Set the value to 0 to disable forced updates.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/deployoffice/mac/mau-deadline"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_updatedeadline.finalcountdown","displayName":"Number of minutes for the final countdown timer","description":"Specify the number of minutes for the forced deadline countdown timer. The allowed range is 10 - 720 minutes (12 hours). The default is 60 minutes.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/deployoffice/mac/mau-deadline"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_updatepolicyoverride","displayName":"Specifies how Microsoft Edge Update handles available updates from Microsoft Edge","description":"If you enable this policy, Microsoft Edge Update handles Microsoft Edge updates according to how you configure the following options:\n\n- Automatic silent updates only: Updates are applied only when they're found by the periodic update check.\n\n- Manual updates only: Updates are applied only when the user runs a manual update check. (Not all apps provide an interface for this option.)\n\nIf you select manual updates, make sure you periodically check for updates by using Microsoft Autoupdate.\n\nIf you don't enable and configure this policy, Microsoft Edge Update automatically checks for updates.\n\nPolicy options mapping:\n\n* automatic-silent-only (automatic-silent-only) = Updates are applied only when they're found by the periodic update check.\n\n* manual-only (manual-only) = Updates are applied only when the user runs a manual update check. (Not all apps provide an interface for this option.)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#updatepolicyoverride"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_updatepolicyoverride_0","displayName":"silent-only - Updates are applied only when they're found by the periodic update check.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_updatepolicyoverride_1","displayName":"only - Updates are applied only when the user runs a manual update check. (Not all apps provide an interface for this option.)","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_updateroptimization","displayName":"Updater optimization technique","description":"By default AutoUpdate will optimize for smaller packages on the network. However, this can cause larger CPU overheads when security agents (e.g. CrowdStrike) are installed. Alternatively, you can choose to lower the CPU overheads to process updates but accept larger download packages","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_updateroptimization_0","displayName":"Lower network overhead","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_updateroptimization_1","displayName":"Lower processor overhead","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_updateroptimization_2","displayName":"Always use full updates","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_uploadbandwidthlimited","displayName":"Set maximum upload throughput","description":"Sets the maximum upload throughput rate in kilobytes (KB)/sec for computers running the OneDrive sync app. The minimum rate is 50 KB/sec and the maximum rate is 100,000 KB/sec.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#uploadbandwidthlimited"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_uploadfromphoneenabled","displayName":"Enable upload files from mobile in Microsoft Edge desktop","description":"This policy lets you configure the \"Upload from mobile\" feature in Microsoft Edge.\n\nUpload from mobile lets users select file from mobile devices to desktop when user upload file in a webpage in Microsoft Edge.\n\nIf you enable or don't configure this policy, you can use the Upload from mobile feature in Microsoft Edge.\n\nIf you disable this policy, you can't use the Upload from mobile feature in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#uploadfromphoneenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_uploadfromphoneenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_uploadfromphoneenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_urlallowlist","displayName":"Define a list of allowed URLs","description":"Allow access to the listed URLs, as exceptions to the URL block list.\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can use this policy to open exceptions to restrictive block lists. For example, you can include '*' in the block list to block all requests, and then use this policy to allow access to a limited list of URLs. You can use this policy to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths.\n\nThe most specific filter determines if a URL is blocked or allowed. The allowed list takes precedence over the block list.\n\nThis policy is limited to 1000 entries; subsequent entries are ignored.\n\nIf you don't configure this policy, there are no exceptions to the block list in the \"URLBlocklist\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#urlallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_urlblocklist","displayName":"Block access to a list of URLs","description":"Define a list of sites, based on URL patterns, that are blocked (your users can't load them).\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can define exceptions in the \"URLAllowlist\" policy. These policies are limited to 1000 entries; subsequent entries are ignored.\n\nNote that blocking internal 'edge://*' URLs isn't recommended - this may lead to unexpected errors.\n\nThis policy doesn't prevent the page from updating dynamically through JavaScript. For example, if you block 'contoso.com/abc', users might still be able to visit 'contoso.com' and click on a link to visit 'contoso.com/abc', as long as the page doesn't refresh.\n\nIf you don't configure this policy, no URLs are blocked.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#urlblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_useragentclienthintsenabled","displayName":"Enable the User-Agent Client Hints feature","description":"This policy is deprecated because it's only intended to be a short-term mechanism to give enterprises more time to update their web content if and when it's found to be incompatible with the User-Agent Client Hints feature. It won't work in Microsoft Edge version 89.\n\nWhen enabled the User-Agent Client Hints feature sends granular request headers that provide information about the user browser (for example, the browser version) and environment (for example, the system architecture).\n\nThis is an additive feature, but the new headers may break some websites that restrict the characters that requests may contain.\n\nIf you enable or don't configure this policy, the User-Agent Client Hints feature is enabled. If you disable this policy, this feature is unavailable.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#useragentclienthintsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_useragentclienthintsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_useragentclienthintsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_useragentreduction","displayName":"Enable or disable the User-Agent Reduction (deprecated)","description":"The User-Agent HTTP request header has been reduced by default since Microsoft Edge version 119. To continue receiving detailed platform information, migrate to User-Agent Client Hints, which replace the deprecated detailed User-Agent header. For more information, visit: https://web.dev/articles/migrate-to-ua-ch\n\nIf you don't configure this policy or set it to Default, the User-Agent header will be reduced and controlled by experimentation.\n\nSet this policy to 'ForceEnabled' to force the reduced version of the User-Agent request header for all origins.\n\nSet this policy to 'ForceDisabled' to always use the full (legacy) User-Agent header.\n\nTo learn more about the User-Agent string, read here:\n\nhttps://go.microsoft.com/fwlink/?linkid=2186267\n\nPolicy options mapping:\n\n* Default (0) = Reduced User Agent, or controlled by experimentation.\n\n* ForceDisabled (1) = Full (legacy) User Agent.\n\n* ForceEnabled (2) = Reduced User Agent.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#useragentreduction"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_useragentreduction_0","displayName":"Reduced User Agent, or controlled by experimentation.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_useragentreduction_1","displayName":"Full (legacy) User Agent.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_useragentreduction_2","displayName":"Reduced User Agent.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_userdatadir","displayName":"Set the user data directory","description":"Set the directory to use for storing user data.\n\nIf you enable this policy, Microsoft Edge uses the specified directory regardless of whether the user has set the '--user-data-dir' command-line flag.\n\nIf you don't enable this policy, the default profile path is used, but the user can override it by using the '--user-data-dir' flag. Users can find the directory for the profile at edge://version/ under profile path.\n\nTo avoid data loss or other errors, don't configure this policy to a volume's root directory or to a directory that's used for other purposes, because Microsoft Edge manages its contents.\n\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#userdatadir"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_userfeedbackallowed","displayName":"Allow user feedback","description":"Microsoft Edge uses the Edge Feedback feature (enabled by default) to allow users to send feedback, suggestions or customer surveys and to report any issues with the browser. Also, by default, users can't disable (turn off) the Edge Feedback feature.\n\nIf you enable this policy or don't configure it, users can invoke Edge Feedback.\n\nIf you disable this policy, users can't invoke Edge Feedback.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#userfeedbackallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_userfeedbackallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userfeedbackallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_userinitiatedfeedback","displayName":"User initiated feedback","description":"Specify whether users can submit feedback to Microsoft by going to Help > Send Feedback.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#diagnostic-collection-level"],"categoryId":"67cd904c-78e0-4e77-9dd4-c713b21763f3","categoryName":"User interface preferences","options":[{"id":"com.apple.managedclient.preferences_userinitiatedfeedback_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userinitiatedfeedback_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_userpreference_apptheming","displayName":"Set theme","description":"Set the theme color.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_userpreference_apptheming_0","displayName":"Blue","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_apptheming_1","displayName":"Purple","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_apptheming_2","displayName":"Pink","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_apptheming_3","displayName":"Orange","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_apptheming_4","displayName":"Red","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_apptheming_5","displayName":"Green","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_userpreference_maxchecklistdisplaydurationmet","displayName":"Hide the 'Get started with Outlook' control in the task pane","description":"Suppress the task pane control that advertises access to toolbar customization, notification preferences, theme, and adding secondary accounts.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_userpreference_maxchecklistdisplaydurationmet_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_maxchecklistdisplaydurationmet_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_usesystemprintdialog","displayName":"Print using system print dialog","description":"Shows the system print dialog instead of print preview.\n\nIf you enable this policy, Microsoft Edge opens the system print dialog instead of the built-in print preview when a user prints a page.\n\nIf you don't configure or disable this policy, print commands trigger the Microsoft Edge print preview screen.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#usesystemprintdialog"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_usesystemprintdialog_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_usesystemprintdialog_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_vbaobjectmodelistrusted","displayName":"Allow macros to modify Visual Basic projects","description":"Allow Visual Basic macros to modify Visual Basic projects. Recommended: false.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_vbaobjectmodelistrusted_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_vbaobjectmodelistrusted_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_verticaltabsallowed","displayName":"Configures availability of a vertical layout for tabs on the side of the browser","description":"Configures whether a user can access an alternative layout where tabs are vertically aligned on the side of the browser instead of at the top.\nWhen there are several tabs open, this layout provides better tab viewing and management. There's better visibility of the site titles,\nit's easier to scan aligned icons, and there's more space to manage and close tabs.\n\nIf you disable this policy, then the vertical tab layout will not be available as an option for users.\n\nIf you enable or don't configure this policy, the tab layout will still be at the top, but a user has the option to turn on vertical tabs on the side.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#verticaltabsallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_verticaltabsallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_verticaltabsallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_videocaptureallowed","displayName":"Allow or block video capture","description":"Control whether sites can capture video.\n\nIf enabled or not configured (default), the user will be asked about video capture access for all sites except those with URLs configured in the \"VideoCaptureAllowedUrls\" policy list, which will be granted access without prompting.\n\nIf you disable this policy, the user isn't prompted, and video capture is only available to URLs configured in \"VideoCaptureAllowedUrls\" policy.\n\nThis policy affects all types of video inputs, not only the built-in camera.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#videocaptureallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_videocaptureallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_videocaptureallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_videocaptureallowedurls","displayName":"Sites that can access video capture devices without requesting permission","description":"Specify websites, based on URL patterns, that can use video capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to video capture devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#videocaptureallowedurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_visualbasicentirelydisabled","displayName":"Prevent all Visual Basic macros from executing","description":"Prevent all Visual Basic code from running in Word, Excel, and PowerPoint - even from trusted locations like the default template. Requires 16.32 or later. Recommended: true, where macros should never be used.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_visualbasicentirelydisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_visualbasicentirelydisabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_visualbasicmacroexecutionstate","displayName":"Visual Basic macro policy","description":"Controls whether Visual Basic macros are allowed to execute in Word, Excel, and PowerPoint.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_visualbasicmacroexecutionstate_0","displayName":"Macros disabled by default, with warning to enable","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_visualbasicmacroexecutionstate_1","displayName":"Disable all macros","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_visualbasicmacroexecutionstate_2","displayName":"Always allow macros to run (potentially dangerous)","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_visualsearchenabled","displayName":"Visual search enabled","description":"Visual search lets you quickly explore more related content about entities in an image.\n\nIf you enable or don't configure this policy, visual search will be enabled via image hover, context menu, and search in sidebar.\n\nIf you disable this policy, visual search will be disabled and you won't be able to get more info about images via hover, context menu, and search in sidebar.\n\nNote: Visual Search in Web Capture is still managed by \"WebCaptureEnabled\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#visualsearchenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_visualsearchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_visualsearchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_walletdonationenabled","displayName":"Wallet Donation Enabled","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\n\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\n\nIf you disable this policy, users can't use the Wallet Donation feature.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#walletdonationenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_walletdonationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_walletdonationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_weather_update_automatically","displayName":"Disable automatic updating of weather location","description":"Prevent users from choosing Update Location Automatically for weather location.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-automatic-updating-of-weather-location"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_weather_update_automatically_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_weather_update_automatically_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webappinstallforcelist","displayName":"Web App Install Force List","description":"Specifies a list of websites that are installed silently, without user interaction, and which can't be uninstalled or disabled by the user.\n\nEach list item of the policy is an object with the following members:\n - \"url\", which is mandatory. \"url\" should be the URL of the web app to install.\n\nValues for the optional members are:\n - \"launch_container\" should be either \"window\" or \"tab\" to indicate how the Web App will be opened after it's installed.\n - \"create_desktop_shortcut\" should be true if a desktop shortcut should be created on Windows.\n\nIf \"default_launch_container\" is omitted, the app will open in a tab by default. Regardless of the value of \"default_launch_container\", users can change which container the app will open in. If \"create_desktop_shortcuts\" is omitted, no desktop shortcuts will be created.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webappinstallforcelist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_create_desktop_shortcut","displayName":"Create desktop shortcut","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_create_desktop_shortcut_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_create_desktop_shortcut_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_default_launch_container","displayName":"Default launch container","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_default_launch_container_0","displayName":"tab","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_default_launch_container_1","displayName":"window","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_url","displayName":"URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webaudiooutputbufferingenabled","displayName":"Enable adaptive buffering for Web Audio","description":"This policy determines whether the browser enables adaptive buffering\nfor Web Audio. Adaptive buffering can reduce audio glitches but may\nincrease latency to varying degrees.\n\nEnabled: The browser will always use adaptive buffering.\nDisabled or Not Set: The browser will automatically decide during the\n feature launch process whether to use adaptive buffering.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webaudiooutputbufferingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webaudiooutputbufferingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webaudiooutputbufferingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webauthenticationremotedesktopallowedorigins","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications.","description":"This policy defines a list of allowed HTTPS origins for remote desktop client applications that initiate WebAuthn API requests from a browsing session on a remote host.\n\nOrigins specified in this policy can request WebAuthn authentication for Relying Party IDs (RP IDs) they would not typically be authorized to claim.\n\nOnly HTTPS origins are supported. Wildcards are not permitted. Entries that do not\nmeet these requirements will be ignored.\n\nFor more information about the WebAuthn Remote Desktop Support feature, please see https://github.com/w3c/webauthn/wiki/Explainer:-Remote-Desktop-Support/a4e158c569f456c759d0ddd294a9015bd4d4eb9a.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webauthenticationremotedesktopallowedorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webcaptureenabled","displayName":"Enable web capture feature in Microsoft Edge","description":"Enables the web capture feature in Microsoft Edge that allows users to capture web content and annotate the capture using inking tools.\nIf you enable this policy or don't configure it, the Web capture option shows up in the context menu, Settings and more menu, and by using the keyboard shortcut, CTRL+SHIFT+S.\nIf you disable this policy, users can't access the web capture feature in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webcaptureenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webcaptureenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webcaptureenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84.","description":"The Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and have been disabled by default starting in M80. This policy allows these features to be selectively re-enabled until M84.\n\n If you set this policy is set to True, the Web Components v0 features will be enabled for all sites.\n\n If you set this policy to False or don't set this policy, the Web Components v0 features will be disabled by default, starting in M80.\n\n This policy will be removed after Microsoft Edge 84.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webcomponentsv0enabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webcomponentsv0enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webcomponentsv0enabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webdriveroverridesincompatiblepolicies","displayName":"Allow WebDriver to Override Incompatible Policies","description":"This policy was removed in M83, because it is not necessary anymore as\nWebDriver is now compatible with all existing policies.\n\nThis policy allows users of the WebDriver feature to override\npolicies which can interfere with its operation.\n\nCurrently this policy disables \"SitePerProcess\" and \"IsolateOrigins\" policies.\n\nIf the policy is enabled, WebDriver will be able to override incomaptible\npolicies.\nIf the policy is disabled or not configured, WebDriver will not be allowed\nto override incompatible policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webdriveroverridesincompatiblepolicies"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webdriveroverridesincompatiblepolicies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webdriveroverridesincompatiblepolicies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webhidallowalldevicesforurls","displayName":"Allow listed sites to connect to any HID device","description":"This setting allows you to list sites which are automatically granted permission to access all available devices.\n\nThe URLs must be valid or the policy is ignored. Only the origin (scheme, host and port) of the URL is evaluated.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\n\nThis policy overrides \"DefaultWebHidGuardSetting\", \"WebHidAskForUrls\", \"WebHidBlockedForUrls\" and the user's preferences.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webhidallowalldevicesforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webhidaskforurls","displayName":"Allow the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\n\nLeaving the policy unset means \"DefaultWebHidGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\n\n * \"WebHidBlockedForUrls\" (if there is a match),\n\n * \"DefaultWebHidGuardSetting\" (if set), or\n\n * Users' personal settings.\n\nURL patterns must not conflict with \"WebHidBlockedForUrls\". Neither policy takes precedence if a URL matches both patterns.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webhidaskforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webhidblockedforurls","displayName":"Block the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a HID device.\n\nLeaving the policy unset means \"DefaultWebHidGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\n\n * \"WebHidAskForUrls\" (if there is a match),\n\n * \"DefaultWebHidGuardSetting\" (if set), or\n\n * Users' personal settings.\n\nURL patterns can't conflict with \"WebHidAskForUrls\". Neither policy takes precedence if a URL matches both patterns.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webhidblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webrtcallowlegacytlsprotocols","displayName":"Allow legacy TLS/DTLS downgrade in WebRTC","description":"If you enable this policy, WebRTC peer connections can downgrade to obsolete\nversions of the TLS/DTLS (DTLS 1.0, TLS 1.0 and TLS 1.1) protocols.\nIf you disable or don't set this policy, these TLS/DTLS versions are\ndisabled.\n\nThis policy is temporary and will be removed in a future version\nof Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtcallowlegacytlsprotocols"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webrtcallowlegacytlsprotocols_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtcallowlegacytlsprotocols_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling","displayName":"Restrict exposure of local IP address by WebRTC","description":"Allows you to set whether or not WebRTC exposes the user's local IP address.\n\nIf you set this policy to \"AllowAllInterfaces\" ('default') or \"AllowPublicAndPrivateInterfaces\" ('default_public_and_private_interfaces'), WebRTC exposes the local IP address.\n\nIf you set this policy to \"AllowPublicInterfaceOnly\" ('default_public_interface_only') or \"DisableNonProxiedUdp\" ('disable_non_proxied_udp'), WebRTC doesn't expose the local IP address.\n\nIf you don't set this policy, or if you disable it, WebRTC exposes the local IP address.\n\n * 'default' = Allow all interfaces. This exposes the local IP address.\n * 'default_public_and_private_interfaces' = Allow public and private interfaces over http default route. This exposes the local IP address.\n * 'default_public_interface_only' = Allow public interface over http default route. This doesn't expose the local IP address.\n * 'disable_non_proxied_udp' = Use TCP unless proxy server supports UDP. This doesn't expose the local IP address.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtclocalhostiphandling"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_0","displayName":"Allow all interfaces. This exposes the local IP address","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_1","displayName":"Allow public and private interfaces over http default route. This exposes the local IP address","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_2","displayName":"Allow public interface over http default route. This doesn't expose the local IP address","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_3","displayName":"Use TCP unless proxy server supports UDP. This doesn't expose the local IP address","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webrtclocalipsallowedurls","displayName":"Manage exposure of local IP addressess by WebRTC","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*contoso.com*\") for which local IP address should be exposed by WebRTC.\n\nIf you enable this policy and set a list of origins (URLs) or hostname patterns, when edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will expose the local IP address for cases that match patterns in the list.\n\nIf you disable or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will not expose local IP addresses. The local IP address is concealed with an mDNS hostname.\n\nIf you enable, disable, or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, WebRTC will expose local IP addresses.\n\nPlease note that this policy weakens the protection of local IP addresses that might be needed by administrators.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtclocalipsallowedurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC","description":"This policy controls the use of post-quantum key agreement for WebRTC in Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge will offer post-quantum key agreement for WebRTC.\n\nIf you disable this policy, post-quantum key agreement will not be offered for WebRTC.\n\nIf you don't configure this policy, post-quantum key agreement will not be offered for WebRTC. A future version of Microsoft Edge may enable this feature by default.\n\nOffering a post-quantum key agreement is backwards compatible. Existing datagram transport layer security (DTLS) peers and networking middleware are expected to ignore the new option and continue using previous options.\n\nHowever, devices that don't correctly implement DTLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or larger message sizes. Such devices aren’t post-quantum-ready and may interfere with an organization's post-quantum transition. If this issue occurs, administrators should contact the device vendor for a fix.\n\nThis policy is temporary and will be removed in a future release.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtcpostquantumkeyagreement"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webrtcpostquantumkeyagreement_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtcpostquantumkeyagreement_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC","description":"Restricts the UDP port range used by WebRTC to a specified port interval (endpoints included).\n\nBy configuring this policy, you specify the range of local UDP ports that WebRTC can use.\n\nIf you don't configure this policy, or if you set it to an empty string or invalid port range, WebRTC can use any available local UDP port.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtcudpportrange"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webtobrowsersigninenabled","displayName":"Web To Browser Sign-in Enabled","description":"Allow user to sign in to the same account in Microsoft Edge when a user signs in to a Microsoft website.\nIf this policy is enabled or not configured, user are able to get sign in CTA or seamless sign in experience(if \"SeamlessWebToBrowserSignInEnabled\" is enabled) when user sign in on Microsoft website.\nIf this policy is disabled, user will not get sign in CTA or seamless sign in experience when user sign in on Microsoft website.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webtobrowsersigninenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webtobrowsersigninenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webtobrowsersigninenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webusbaskforurls","displayName":"Allow WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can ask the user for access to a USB device.\n\nIf you don't configure this policy, the global default value from the \"DefaultWebUsbGuardSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"WebUsbBlockedForUrls\" policy - you can't both allow and block a URL.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webusbaskforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webusbblockedforurls","displayName":"Block WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can't ask the user to grant them access to a USB device.\n\nIf you don't configure this policy, the global default value from the \"DefaultWebUsbGuardSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nURL patterns in this policy can't conflict with those configured in the \"WebUsbAskForUrls\" policy. You can't both allow and block a URL.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webusbblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_weeklyconfiguration","displayName":"Weekly scheduled scan configuration","description":"Should scheduled scan be run with low priority. (Scan might take longer to complete).","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_weeklyconfiguration_dayofweek","displayName":"Day of week","description":"Specifies the day of the week to perform a weekly scan. 0 indicates never. 1-7 indicates Sunday - Saturday. 8 indicates every day.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_weeklyconfiguration_scantype","displayName":"Scan type","description":"Specifies the type of scan to perform.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":[{"id":"com.apple.managedclient.preferences_weeklyconfiguration_scantype_0","displayName":"quick","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_weeklyconfiguration_scantype_1","displayName":"full","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_weeklyconfiguration_timeofday","displayName":"Time of day","description":"Specifies the time of day, as the number of minutes after midnight, to perform a weekly scan.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_whatsnewpageforentraprofilesenabled","displayName":"Control whether an informational webpage for Edge for Business is shown in the new tab after major browser updates","description":"Starting in Microsoft Edge version 145, users with Microsoft Entra ID profiles will see an informational page about new Edge for Business features after major browser updates. This page highlights recent enhancements designed to promote secure and productive browsing.\n\nThis policy controls whether users with Microsoft Entra ID profiles see this informational page. This policy applies only to Microsoft Entra ID profiles and does not apply to Microsoft account (MSA) profiles.\n\nThis policy is available starting in Microsoft Edge version 144 to allow configuration ahead of the changes introduced in version 145.\n\nIf you enable this policy or do not configure it, Microsoft Edge shows the informational page by default.\nIf you disable this policy, Microsoft Edge does not show the informational page to users.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#whatsnewpageforentraprofilesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_whatsnewpageforentraprofilesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_whatsnewpageforentraprofilesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_windowcaptureallowedbyorigins","displayName":"Allow Window and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Window and Tab Capture.\n\nLeaving the policy unset means that sites will not be considered for an override at this scope of Capture.\n\nThis policy is not considered if a site matches a URL pattern in any of the following policies: \"TabCaptureAllowedByOrigins\", \"SameOriginTabCaptureAllowedByOrigins\".\n\nIf a site matches a URL pattern in this policy, the following policies will not be considered: \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#windowcaptureallowedbyorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_windowmanagementallowedforurls","displayName":"Allow Window Management permission on specified sites","description":"Lets you configure a list of site url patterns that specify sites which will automatically grant the window management permission. This extends the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\n\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\n\nIf this policy isn't configured for a site, then the policy from \"DefaultWindowManagementSetting\" applies to the site, if configured. Otherwise the permission will follow the browser's defaults and let users choose this permission per site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#windowmanagementallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_windowmanagementblockedforurls","displayName":"Block Window Management permission on specified sites","description":"Lets you configure a list of site url patterns that specify sites which will automatically deny the window management permission. This limits the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\n\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\n\nIf this policy isn't configured for a site, then the policy from \"DefaultWindowManagementSetting\" applies to the site, if configured. Otherwise the permission will follow the browser's defaults and let users choose this permission per site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#windowmanagementblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_wpadquickcheckenabled","displayName":"Set WPAD optimization","description":"Allows you to turn off WPAD (Web Proxy Auto-Discovery) optimization in Microsoft Edge.\n\nIf you disable this policy, WPAD optimization is disabled, which makes the browser wait longer for DNS-based WPAD servers.\n\nIf you enable or don't configure the policy, WPAD optimization is enabled.\n\nIndependent of whether or how this policy is enabled, the WPAD optimization setting cannot be changed by users.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#wpadquickcheckenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_wpadquickcheckenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_wpadquickcheckenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_zstdcontentencodingenabled","displayName":"Enable zstd content encoding support (Deprecated)","description":"This feature enables advertising \"zstd\" support in the Accept-Encoding request header and support for decompressing zstd web content.\n\nIf you enable or don't configure this policy, Microsoft Edge will accept server responses compressed with zstd.\n\nIf you disable this policy, the zstd content encoding feature will not be advertised or supported when processing server responses.\n\nThis policy is temporary and will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#zstdcontentencodingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_zstdcontentencodingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_zstdcontentencodingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.mcx_cachedaccounts.askforsecuretokenauthbypass","displayName":"Ask For Secure Token Auth Bypass","description":"If true, bypasses the secure token authorization dialog. This dialog only appears on APFS volumes.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_cachedaccounts.askforsecuretokenauthbypass_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_cachedaccounts.askforsecuretokenauthbypass_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_cachedaccounts.expiry.delete.disusedseconds","displayName":"Expiry Delete Disused Seconds","description":"The minimum number of seconds a mobile account can exist before an automatic attempt is made to remove the mobile account. Set to 0 to try to remove it at next login or logout time. Set to -1 to never try to remove the mobile account.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":null},{"id":"com.apple.mcx_cachedaccounts.warnoncreate.allownever","displayName":"Warn On Create Allow Never","description":"If true, allows the user to stop the prompts about mobile account creation every time the user logs in. This key is only valid if Warn On Create is set to true.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_cachedaccounts.warnoncreate.allownever_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_cachedaccounts.warnoncreate.allownever_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.cachedaccounts.createatlogin","displayName":"Create At Login","description":"If true, creates the mobile account at login time.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_com.apple.cachedaccounts.createatlogin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.cachedaccounts.createatlogin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.cachedaccounts.warnoncreate","displayName":"Warn On Create","description":"If true, asks the user if the mobile account should be created and allow the user to not create it.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_com.apple.cachedaccounts.warnoncreate_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.cachedaccounts.warnoncreate_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower","displayName":"Desktop Power","description":"The settings for a desktop computer.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_automatic restart on power loss","displayName":"Automatic Restart On Power Loss","description":"If true, enables \"Start up automatically after a power failure.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_automatic restart on power loss_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_automatic restart on power loss_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_disk sleep timer","displayName":"Disk Sleep Timer","description":"The disk sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_display sleep timer","displayName":"Display Sleep Timer","description":"The display sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_dynamic power step","displayName":"Dynamic Power Step","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_dynamic power step_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_dynamic power step_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_reduce processor speed","displayName":"Reduce Processor Speed","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_reduce processor speed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_reduce processor speed_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_system sleep timer","displayName":"System Sleep Timer","description":"System sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_wake on lan","displayName":"Wake on LAN","description":"If true, enables \"Wake for network access.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_wake on lan_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_wake on lan_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_wake on modem ring","displayName":"Wake On Modem Ring","description":"If true, enables \"Wake for modem ring.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_wake on modem ring_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_wake on modem ring_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule","displayName":"Desktop Schedule","description":"The schedule for turning a computer on and off.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff","displayName":"Repeating Power Off","description":"The schedule for turning the device off. ","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype","displayName":"Event Type","description":"The type of action defined by this schedule.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype_0","displayName":"Wake","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype_1","displayName":"Power On","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype_2","displayName":"Wake Power On","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype_3","displayName":"Sleep","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype_4","displayName":"Shutdown","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype_5","displayName":"Restart","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_time","displayName":"Time","description":"The time, in minutes, since midnight.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays","displayName":"Weekdays","description":"One or more days of the week that the device will automatically shutdown. ","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_0","displayName":"Mon","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_1","displayName":"Tue","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_2","displayName":"Wed","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_3","displayName":"Thu","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_4","displayName":"Fri","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_5","displayName":"Sat","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_6","displayName":"Sun","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron","displayName":"Repeating Power On","description":"The schedule for powering the device on. ","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype","displayName":"Event Type","description":"The type of action defined by this schedule.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype_0","displayName":"Wake","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype_1","displayName":"Power On","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype_2","displayName":"Wake Power On","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype_3","displayName":"Sleep","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype_4","displayName":"Shutdown","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype_5","displayName":"Restart","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_time","displayName":"Time","description":"The time, in minutes, since midnight.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays","displayName":"Weekdays","description":"One or more days of the week that the device will automatically power on.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_0","displayName":"Mon","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_1","displayName":"Tue","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_2","displayName":"Wed","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_3","displayName":"Thu","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_4","displayName":"Fri","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_5","displayName":"Sat","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_6","displayName":"Sun","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower","displayName":"Laptop Power","description":"The settings for a laptop computer using AC power. ","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_automatic restart on power loss","displayName":"Automatic Restart On Power Loss","description":"If true, enables \"Start up automatically after a power failure.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_automatic restart on power loss_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_automatic restart on power loss_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_disk sleep timer","displayName":"Disk Sleep Timer","description":"The disk sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_display sleep timer","displayName":"Display Sleep Timer","description":"The display sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_dynamic power step","displayName":"Dynamic Power Step","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_dynamic power step_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_dynamic power step_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_reduce processor speed","displayName":"Reduce Processor Speed","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_reduce processor speed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_reduce processor speed_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_system sleep timer","displayName":"System Sleep Timer","description":"System sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on lan","displayName":"Wake on LAN","description":"If true, enables \"Wake for network access.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on lan_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on lan_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on modem ring","displayName":"Wake On Modem Ring","description":"If true, enables \"Wake for modem ring.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on modem ring_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on modem ring_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower","displayName":"Laptop Battery Power","description":"The settings for a laptop computer using battery power.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_automatic restart on power loss","displayName":"Automatic Restart On Power Loss","description":"If true, enables \"Start up automatically after a power failure.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_automatic restart on power loss_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_automatic restart on power loss_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_disk sleep timer","displayName":"Disk Sleep Timer","description":"The disk sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_display sleep timer","displayName":"Display Sleep Timer","description":"The display sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_dynamic power step","displayName":"Dynamic Power Step","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_dynamic power step_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_dynamic power step_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_reduce processor speed","displayName":"Reduce Processor Speed","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_reduce processor speed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_reduce processor speed_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_system sleep timer","displayName":"System Sleep Timer","description":"System sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on lan","displayName":"Wake on LAN","description":"If true, enables \"Wake for network access.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on lan_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on lan_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on modem ring","displayName":"Wake On Modem Ring","description":"If true, enables \"Wake for modem ring.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on modem ring_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on modem ring_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.mcx-accounts","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","categoryName":"Accounts","options":null},{"id":"com.apple.mcx_com.apple.mcx-energysaver","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.mcx-fdefilevaultoptions","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","categoryName":"FileVault Options","options":null},{"id":"com.apple.mcx_com.apple.mcx-mobileaccounts","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":null},{"id":"com.apple.mcx_com.apple.mcx-timeserver","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"853f4181-42e8-411c-91cf-c06968c0a543","categoryName":"Time Server","options":null},{"id":"com.apple.mcx_destroyfvkeyonstandby","displayName":"Destroy FV Key On Standby","description":"If true, prevents the OS from storing a temporary FileVault key in SMC or RAM for standby.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_destroyfvkeyonstandby_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_destroyfvkeyonstandby_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_disableguestaccount","displayName":"Disable Guest Account","description":"If true, disables the guest account. This property has no effect if Enable Guest Account is true.","helpText":null,"infoUrls":[],"categoryId":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","categoryName":"Accounts","options":[{"id":"com.apple.mcx_disableguestaccount_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_disableguestaccount_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_dontallowfdedisable","displayName":"Prevent FileVault From Being Disabled","description":"Set to true to prevent FileVault from being disabled.","helpText":null,"infoUrls":[],"categoryId":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","categoryName":"FileVault Options","options":[{"id":"com.apple.mcx_dontallowfdedisable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_dontallowfdedisable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_dontallowfdeenable","displayName":"Prevent FileVault From Being Enabled","description":"Set to true to prevent FileVault from being enabled.","helpText":null,"infoUrls":[],"categoryId":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","categoryName":"FileVault Options","options":[{"id":"com.apple.mcx_dontallowfdeenable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_dontallowfdeenable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_enableguestaccount","displayName":"Enable Guest Account","description":"If true, enables the guest account.","helpText":null,"infoUrls":[],"categoryId":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","categoryName":"Accounts","options":[{"id":"com.apple.mcx_enableguestaccount_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_enableguestaccount_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_sleepdisabled","displayName":"Sleep Disabled","description":"If true, disables sleep.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_sleepdisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_sleepdisabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_timeserver","displayName":"Time Server","description":"The NTP server to connect to. Use commas to separate multiple time servers.","helpText":null,"infoUrls":[],"categoryId":"853f4181-42e8-411c-91cf-c06968c0a543","categoryName":"Time Server","options":null},{"id":"com.apple.mcx_timezone","displayName":"Time Zone","description":"The time zone path location string in /usr/share/zoneinfo/; for example, America/Denver or Zulu. ","helpText":null,"infoUrls":[],"categoryId":"853f4181-42e8-411c-91cf-c06968c0a543","categoryName":"Time Server","options":null},{"id":"com.apple.mcx.filevault2_com.apple.mcx.filevault2","displayName":"Top Level Setting Group Collection","description":"com.apple.MCX.FileVault2","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},{"id":"com.apple.mcx.filevault2_defer","displayName":"Defer","description":"If true, defers enabling FileVault until the designated user logs out. For details, see fdesetup(8). The person enabling FileVault must be either a local user or a mobile account user.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":{"id":"com.apple.mcx.filevault2_defer_true","displayName":"Enabled","description":null,"helpText":null}},{"id":"com.apple.mcx.filevault2_deferdontaskatuserlogout","displayName":"Defer Dont Ask At User Logout","description":"If true, prevents requests for enabling FileVault at user logout time.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_deferdontaskatuserlogout_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_deferdontaskatuserlogout_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_deferforceatuserloginmaxbypassattempts","displayName":"Defer Force At User Login Max Bypass Attempts","description":"The maximum number of times users can bypass enabling FileVault before being required to enable it to log in. If the value is 0, the user will be required to enabled FileVault the next time they attempt to log in. Setting this key to –1 disables the feature.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},{"id":"com.apple.mcx.filevault2_enable","displayName":"Enable","description":"If true, enables FileVault.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_enable_0","displayName":"On","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_enable_1","displayName":"Off","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_forceenableinsetupassistant","displayName":"Force Enable In Setup Assistant","description":"If 'true', and installation of this payload occurs after enrolling with MDM in Setup Assistant, the system requests Setup Assistant to enable FileVault at setup time. In this case, the system also ignores all other keys in this payload, except for 'ShowRecoveryKey'.\nTo use this, enable the Await Device Configured DEP configuration option and send this profile with this key set, before sending the DeviceConfiguredCommand. An admin SecureToken user is required, otherwise the FileVault pane does not appear.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_forceenableinsetupassistant_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_forceenableinsetupassistant_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_outputpath","displayName":"Output Path","description":"The path to the location where the recovery key and computer information property list are stored.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},{"id":"com.apple.mcx.filevault2_password","displayName":"Password","description":"The password of the Open Directory user to be added to FileVault. Use the 'UserEntersMissingInfo' key if you want to prompt for this information.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths","displayName":"Recovery Key Rotation In Months","description":"The frequency to rotate the recovery key, in months","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_0","displayName":"Not configured","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_1","displayName":"1 month","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_2","displayName":"2 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_3","displayName":"3 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_4","displayName":"4 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_5","displayName":"5 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_6","displayName":"6 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_7","displayName":"7 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_8","displayName":"8 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_9","displayName":"9 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_10","displayName":"10 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_11","displayName":"11 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_12","displayName":"12 months","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_showrecoverykey","displayName":"Show Recovery Key","description":"If false, prevents display of the personal recovery key to the user after FileVault is enabled.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_showrecoverykey_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_showrecoverykey_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_usekeychain","displayName":"Use Keychain","description":"If 'true' and no certificate information is provided in this payload, the keychain created at '/Library/Keychains/FileVaultMaster.keychain' is used when the institutional recovery key is added.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_usekeychain_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_usekeychain_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_userecoverykey","displayName":"Use Recovery Key","description":"If true, creates a personal recovery key and displays it to the user.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":{"id":"com.apple.mcx.filevault2_userecoverykey_true","displayName":"Enabled","description":null,"helpText":null}},{"id":"com.apple.mcx.filevault2_userentersmissinginfo","displayName":"User Enters Missing Info","description":"If true, enables a prompt for missing user name or password fields.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_userentersmissinginfo_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_userentersmissinginfo_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_username","displayName":"Username","description":"The user name of the Open Directory user to be added to FileVault.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},{"id":"com.apple.mcx.timemachine_autobackup","displayName":"Auto Backup","description":"If true, performs automatic backups at regular intervals.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":[{"id":"com.apple.mcx.timemachine_autobackup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.timemachine_autobackup_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx.timemachine_backupallvolumes","displayName":"Backup All Volumes","description":"If true, backs up only the startup volume by default.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":[{"id":"com.apple.mcx.timemachine_backupallvolumes_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.timemachine_backupallvolumes_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx.timemachine_backupdesturl","displayName":"Backup Destination URL","description":"The URL of the backup destination.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},{"id":"com.apple.mcx.timemachine_backupsizemb","displayName":"Backup Size MB","description":"The backup size limit, in megabytes. Set to 0 for unlimited.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},{"id":"com.apple.mcx.timemachine_backupskipsys","displayName":"Backup Skip System","description":"If true, skips system files and folders by default.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":[{"id":"com.apple.mcx.timemachine_backupskipsys_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.timemachine_backupskipsys_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx.timemachine_basepaths","displayName":"Base Paths","description":"The list of paths to back up besides the startup volume.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},{"id":"com.apple.mcx.timemachine_com.apple.mcx.timemachine","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},{"id":"com.apple.mcx.timemachine_mobilebackups","displayName":"Mobile Backups","description":"If true, create local backup snapshots when not connected to the network.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":[{"id":"com.apple.mcx.timemachine_mobilebackups_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.timemachine_mobilebackups_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx.timemachine_skippaths","displayName":"Skip Paths","description":"The path to skip from start volume.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},{"id":"com.apple.mcxmenuextras_airport.menu","displayName":"AirPort","description":"If true, enables the AirPort menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_airport.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_airport.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_battery.menu","displayName":"Battery","description":"If true, enables the Battery menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_battery.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_battery.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_bluetooth.menu","displayName":"Bluetooth","description":"If true, enables the Bluetooth menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_bluetooth.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_bluetooth.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_clock.menu","displayName":"Clock","description":"If true, enables the Clock menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_clock.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_clock.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_com.apple.mcxmenuextras","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":null},{"id":"com.apple.mcxmenuextras_cpu.menu","displayName":"CPU","description":"If true, enables the CPU menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_cpu.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_cpu.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_delayseconds","displayName":"Delay Seconds","description":"The number of seconds to delay after login before adding or removing menu extras. If the delay is too short, the menu extras don't appear, or disappear from the menu bar.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":null},{"id":"com.apple.mcxmenuextras_displays.menu","displayName":"Displays","description":"If true, enables the Displays menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_displays.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_displays.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_eject.menu","displayName":"Eject","description":"If true, enables the Eject menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_eject.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_eject.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_fax.menu","displayName":"Fax","description":"If true, enables the Fax menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_fax.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_fax.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_homesync.menu","displayName":"HomeSync","description":"If true, enables the HomeSync menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_homesync.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_homesync.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_ichat.menu","displayName":"iChat","description":"If true, enables the iChat menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_ichat.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_ichat.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_ink.menu","displayName":"Ink","description":"If true, enables the Ink menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_ink.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_ink.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_irda.menu","displayName":"IrDA","description":"If true, enables the IrDA menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_irda.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_irda.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_maxwaitseconds","displayName":"Max Wait Seconds","description":"The maximum wait, in seconds, for all menu extras to be added or removed.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":null},{"id":"com.apple.mcxmenuextras_pccard.menu","displayName":"PCCard","description":"If true, enables the PCCard menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_pccard.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_pccard.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_ppp.menu","displayName":"PPP","description":"If true, enables the PPP menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_ppp.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_ppp.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_pppoe.menu","displayName":"PPPoE","description":"If true, enables the PPPoE menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_pppoe.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_pppoe.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_remotedesktop.menu","displayName":"Remote Desktop","description":"If true, enables the Remote Desktop menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_remotedesktop.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_remotedesktop.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_script menu.menu","displayName":"Script Menu","description":"If true, enables the Script menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_script menu.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_script menu.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_spaces.menu","displayName":"Spaces","description":"If true, enables the Spaces menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_spaces.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_spaces.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_sync.menu","displayName":"Sync","description":"If true, enables the Sync menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_sync.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_sync.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_textinput.menu","displayName":"Text Input","description":"If true, enables the Text Input menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_textinput.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_textinput.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_timemachine.menu","displayName":"TimeMachine","description":"If true, enables the TimeMachine menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_timemachine.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_timemachine.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_universalaccess.menu","displayName":"Universal Access","description":"If true, enables the Universal Access menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_universalaccess.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_universalaccess.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_user.menu","displayName":"User","description":"If true, enables the User menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_user.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_user.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_volume.menu","displayName":"Volume","description":"If true, enables the Volume menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_volume.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_volume.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_vpn.menu","displayName":"VPN","description":"If true, enables the VPN menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_vpn.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_vpn.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_wwan.menu","displayName":"WWAN","description":"If true, enables the WWAN menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_wwan.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_wwan.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_allowlocalprinters","displayName":"Allow Local Printers","description":"If true, allows printers that connect directly to a user's computer.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_allowlocalprinters_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_allowlocalprinters_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_com.apple.mcxprinting","displayName":"Top Level Setting Group Collection","description":"com.apple.mcxprinting","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_defaultprinter","displayName":"Default Printer","description":"The default printer for the user.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_defaultprinter_deviceuri","displayName":"Device URI","description":"The device URI.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_defaultprinter_displayname","displayName":"Display Name","description":"The display name.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_footerfontname","displayName":"Footer Font Name","description":"The footer font name.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_footerfontsize","displayName":"Footer Font Size","description":"The footer font size.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_printfooter","displayName":"Print Footer","description":"If true, prints the page footer (including the user name and date).","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_printfooter_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_printfooter_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_printmacaddress","displayName":"Print MAC Address","description":"If true, includes the MAC address.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_printmacaddress_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_printmacaddress_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_requireadmintoaddprinters","displayName":"Require Admin To Add Printers","description":"If true, requires an administrator password to add printers.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_requireadmintoaddprinters_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_requireadmintoaddprinters_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_requireadmintoprintlocally","displayName":"Require Admin To Print Locally","description":"If true, requires an administrator password to print locally.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_requireadmintoprintlocally_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_requireadmintoprintlocally_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_showonlymanagedprinters","displayName":"Show Only Managed Printers","description":"If true, shows only managed printers.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_showonlymanagedprinters_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_showonlymanagedprinters_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_userprinterlist","displayName":"User Printer List","description":"The printers available to a user.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer","displayName":"Printer","description":"A dictionary of printer details.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_deviceuri","displayName":"Device URI","description":"The device URI.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_displayname","displayName":"Display Name","description":"The display name.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_location","displayName":"Location","description":"The printer's location.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_model","displayName":"Model","description":"The printer's model.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_ppdurl","displayName":"PPD URL","description":"The printer's PPDURL.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_printerlocked","displayName":"Printer Locked","description":"If true, locks the printer.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_userprinterlist_printer_printerlocked_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_printerlocked_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mobiledevice.passwordpolicy_allowsimple","displayName":"Allow Simple Passcode","description":"If true, allows a simple passcode. A simple passcode contains repeated characters, or increasing or decreasing characters (such as 123 or CBA). Setting this value to false has the same result as setting Min Complex Characters to 1.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":[{"id":"com.apple.mobiledevice.passwordpolicy_allowsimple_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mobiledevice.passwordpolicy_allowsimple_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mobiledevice.passwordpolicy_changeatnextauth","displayName":"Change At Next Auth","description":"If true, causes a password reset to occur the next time the user tries to authenticate. If this key is set in a device profile, the setting takes effect for all users, and admin authentications may fail until the admin user password is also reset. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":[{"id":"com.apple.mobiledevice.passwordpolicy_changeatnextauth_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mobiledevice.passwordpolicy_changeatnextauth_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mobiledevice.passwordpolicy_com.apple.mobiledevice.passwordpolicy","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_customregex","displayName":"Custom Regex","description":"Specifies a regular expression, and its description, used to enforce password compliance. Use the simpler passcode restrictions whenever possible, and rely on regular expression matching only when necessary. Mistakes in regular expressions can lead to frustrating user experiences, such as unsatisfiable passcode policies, or policy descriptions that don't match the enforced policy.\n\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentdescription","displayName":"Password Content Description","description":"Contains a dictionary of keys for supported OS language IDs (for example, \"en-US\"), and whose values represent a localized description of the policy enforced by the regular expression. Use the special `default` key can for languages that aren't contained in the dictionary.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentdescription_generickey","displayName":"Description","description":"A localized description.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentdescription_generickey_keytobereplaced","displayName":"Password Content Description","description":"Contains a dictionary of keys for supported OS language IDs (for example, \"en-US\"), and whose values represent a localized description of the policy enforced by the regular expression. Use the special `default` key can for languages that aren't contained in the dictionary.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentregex","displayName":"Password Content Regex","description":"A regular expression string that they system matches against the password to determine whether it complies with a policy. The regular expression uses the ICU syntax (). The string must not exceed 2048 characters in length.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_forcepin","displayName":"Force PIN","description":"If true, forces the user to enter a PIN.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":[{"id":"com.apple.mobiledevice.passwordpolicy_forcepin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mobiledevice.passwordpolicy_forcepin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mobiledevice.passwordpolicy_maxfailedattempts","displayName":"Max Failed Attempts","description":"The number of allowed failed attempts to enter the passcode at the device's lock screen. After six failed attempts, a time delay is imposed before a passcode can be entered again. The delay increases with each attempt. In macOS, set Minutes Until Failed Login Reset to define a delay before the next passcode can be entered. When this number is exceeded in macOS, the device is locked; in iOS, the device is wiped.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_maxgraceperiod","displayName":"Max Grace Period","description":"The maximum grace period, in minutes, to unlock the phone without entering a passcode. The default is 0, which is no grace period and requires a passcode immediately. In macOS, this grace period value is translated to screen-saver settings.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_maxinactivity","displayName":"Max Inactivity","description":"The maximum number of minutes for which the device can be idle, without being unlocked by the user, before it gets locked by the system. When this limit is reached, the device is locked and the passcode must be entered. The user can edit this setting, but the value cannot exceed the Max Inactivity value. In macOS, this inactivity value is translated to screen-saver settings.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_maxpinageindays","displayName":"Max PIN Age In Days","description":"The number of days for which the passcode can remain unchanged. After this number of days, the user is forced to change the passcode before the device is unlocked.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_mincomplexchars","displayName":"Min Complex Characters","description":"The minimum number of complex characters that a passcode must contain. A complex character is a character other than a number or a letter, such as & % $ #. This property is ignored for User Enrollments.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_minlength","displayName":"Min Length","description":"The minimum overall length of the passcode. This parameter is independent of the also optional Min Complex Characters argument.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_minutesuntilfailedloginreset","displayName":"Minutes Until Failed Login Reset","description":"The number of minutes before the login is reset after the maximum number of unsuccessful login attempts is reached. This key requires setting Max Failed Attempts. Available in macOS 10.10 and later.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_pinhistory","displayName":"PIN History","description":"This value defines N, where the new passcode must be unique within the last N entries in the passcode history. ","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_requirealphanumeric","displayName":"Require Alphanumeric Passcode","description":"If true, requires alphabetic characters (abcd) instead of only numeric characters.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":[{"id":"com.apple.mobiledevice.passwordpolicy_requirealphanumeric_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mobiledevice.passwordpolicy_requirealphanumeric_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.networkusagerules_applicationrules","displayName":"Application Rules","description":"An array of application rules, that apply to only managed apps.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},{"id":"com.apple.networkusagerules_applicationrules_item_allowcellulardata","displayName":"Allow Cellular Data","description":"If false, disables cellular data for all matching managed apps.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":[{"id":"com.apple.networkusagerules_applicationrules_item_allowcellulardata_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.networkusagerules_applicationrules_item_allowcellulardata_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.networkusagerules_applicationrules_item_allowroamingcellulardata","displayName":"Allow Roaming Cellular Data","description":"If false, disables cellular data while roaming for all matching managed apps.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":[{"id":"com.apple.networkusagerules_applicationrules_item_allowroamingcellulardata_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.networkusagerules_applicationrules_item_allowroamingcellulardata_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.networkusagerules_applicationrules_item_appidentifiermatches","displayName":"App Identifier Matches","description":"A list of managed app identifiers, as strings, that must follow the associated rules. If this key is missing, the rules apply to all managed apps on the device. Each string in the AppIdentifierMatches array may either be an exact app identifier match (for example, com.mycompany.myapp) or it may specify a prefix match for the bundle ID by using the * wildcard character. If used, this character must appear after a period (.) and may only appear once, at the end of the string; for example, com.mycompany.*.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},{"id":"com.apple.networkusagerules_com.apple.networkusagerules","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},{"id":"com.apple.networkusagerules_simrules","displayName":"SIM Rules","description":"An array of SIM rules, that apply to all apps.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},{"id":"com.apple.networkusagerules_simrules_item_iccids","displayName":"ICCI Ds","description":"One or more ICCIDs of SIM cards for which the `WiFiAssistPolicy` applies. All ICCIDs in all installed Network Usage Rules payloads must be unique. An example ICCID is `89310410106543789301`.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},{"id":"com.apple.networkusagerules_simrules_item_wifiassistpolicy","displayName":"Wi Fi Assist Policy","description":"The Wi-Fi Assist policy to apply to the SIM cards specified in the ICCIDs. See About Wi-Fi Assist to learn more.\n* '2': Use the default system policy for the specified SIM card(s).\n* '3': Make Wi-Fi Assist switch more aggressively from a poor Wi-Fi connection to cellular data for the specified SIM card(s). This setting may increase cellular data use and may impact battery life.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":[{"id":"com.apple.networkusagerules_simrules_item_wifiassistpolicy_0","displayName":"2","description":null,"helpText":null},{"id":"com.apple.networkusagerules_simrules_item_wifiassistpolicy_1","displayName":"3","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_com.apple.notificationsettings","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":null},{"id":"com.apple.notificationsettings_notificationsettings","displayName":"Notification Settings","description":"An array of notification settings dictionaries.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":null},{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype","displayName":"Alert Type","description":"The type of alert for notifications for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype_1","displayName":"Temporary Banner","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype_2","displayName":"Persistent Banner","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_badgesenabled","displayName":"Badges Enabled","description":"If true, enables badges for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_badgesenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_badgesenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_bundleidentifier","displayName":"Bundle Identifier","description":"The bundle identifier of the app to which to apply these notification settings. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":null},{"id":"com.apple.notificationsettings_notificationsettings_item_criticalalertenabled","displayName":"Critical Alert Enabled","description":"If true, enables critical alerts that can ignore Do Not Disturb and ringer settings for this app. Available in iOS 12 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_criticalalertenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_criticalalertenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_groupingtype","displayName":"Grouping Type","description":"The type of grouping for notifications for this app. Available in iOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_groupingtype_0","displayName":"Automatic: Group notifications into app-specified groups","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_groupingtype_1","displayName":"By app: Group notifications into one group","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_groupingtype_2","displayName":"Off: Don't group notifications","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_notificationsenabled","displayName":"Notifications Enabled","description":"If true, enables notifications for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_notificationsenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_notificationsenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype","displayName":"Preview Type","description":"The type previews for notifications. This key overrides the value at Settings>Notifications>Show Previews. Available in iOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype_0","displayName":"Always: Previews will be shown when the device is locked and unlocked","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype_1","displayName":"When Unlocked: Previews will only be shown when the device is unlocked","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype_2","displayName":"Never: Previews will never be shown","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_showincarplay","displayName":"Show In Car Play","description":"If true, enables notifications in CarPlay for this app. Available in iOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_showincarplay_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_showincarplay_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_showinlockscreen","displayName":"Show In Lock Screen","description":"If true, enables notifications on the lock screen for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_showinlockscreen_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_showinlockscreen_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_showinnotificationcenter","displayName":"Show In Notification Center","description":"If true, enables notifications in the notification center for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_showinnotificationcenter_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_showinnotificationcenter_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_soundsenabled","displayName":"Sounds Enabled","description":"If true, enables sounds for this app.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_soundsenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_soundsenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.nsextension_allowedextensions","displayName":"Allowed Extensions","description":"An array of identifiers for extensions that are allowed to run on the system.","helpText":null,"infoUrls":[],"categoryId":"d875dca1-dc97-4cc5-9df3-c50b813622a3","categoryName":"NS Extension Management","options":null},{"id":"com.apple.nsextension_com.apple.nsextension","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"d875dca1-dc97-4cc5-9df3-c50b813622a3","categoryName":"NS Extension Management","options":null},{"id":"com.apple.nsextension_deniedextensionpoints","displayName":"Denied Extension Points","description":"An array of extension points for extensions that aren't allowed to run on the system.","helpText":null,"infoUrls":[],"categoryId":"d875dca1-dc97-4cc5-9df3-c50b813622a3","categoryName":"NS Extension Management","options":null},{"id":"com.apple.nsextension_deniedextensions","displayName":"Denied Extensions","description":"An array of identifiers for extensions that aren't allowed to run on the system.","helpText":null,"infoUrls":[],"categoryId":"d875dca1-dc97-4cc5-9df3-c50b813622a3","categoryName":"NS Extension Management","options":null},{"id":"com.apple.preference.security_com.apple.preference.security","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8abddb23-7036-4ba8-8912-529279a849ea","categoryName":"Security Preferences","options":null},{"id":"com.apple.preference.security_dontallowfirewallui","displayName":"Do Not Allow Firewall UI","description":"If true, disables user changes to the firewall settings.","helpText":null,"infoUrls":[],"categoryId":"8abddb23-7036-4ba8-8912-529279a849ea","categoryName":"Security Preferences","options":[{"id":"com.apple.preference.security_dontallowfirewallui_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.preference.security_dontallowfirewallui_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.preference.security_dontallowlockmessageui","displayName":"Do Not Allow Lock Message UI","description":"If true, disables user changes to the lock message. ","helpText":null,"infoUrls":[],"categoryId":"8abddb23-7036-4ba8-8912-529279a849ea","categoryName":"Security Preferences","options":[{"id":"com.apple.preference.security_dontallowlockmessageui_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.preference.security_dontallowlockmessageui_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.preference.security_dontallowpasswordresetui","displayName":"Do Not Allow Password Reset UI","description":"If true, disables user changes to the password.","helpText":null,"infoUrls":[],"categoryId":"8abddb23-7036-4ba8-8912-529279a849ea","categoryName":"Security Preferences","options":[{"id":"com.apple.preference.security_dontallowpasswordresetui_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.preference.security_dontallowpasswordresetui_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.preference.users_com.apple.preference.users","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"0a9f982a-3515-4728-a231-fa000eb9e550","categoryName":"User Preferences","options":null},{"id":"com.apple.preference.users_disableusingicloudpassword","displayName":"Disable Using iCloud Password","description":"If true, disables the iCloud password for local accounts.","helpText":null,"infoUrls":[],"categoryId":"0a9f982a-3515-4728-a231-fa000eb9e550","categoryName":"User Preferences","options":[{"id":"com.apple.preference.users_disableusingicloudpassword_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.preference.users_disableusingicloudpassword_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.profileremovalpassword_com.apple.profileremovalpassword","displayName":"Top Level Setting Group Collection","description":"com.apple.profileRemovalPassword","helpText":null,"infoUrls":[],"categoryId":"e905d6cf-7820-48d4-86e0-b55fa991a5ad","categoryName":"Profile Removal Password","options":null},{"id":"com.apple.profileremovalpassword_removalpassword","displayName":"Removal Password","description":"The password for allowing the profile to be removed.","helpText":null,"infoUrls":[],"categoryId":"e905d6cf-7820-48d4-86e0-b55fa991a5ad","categoryName":"Profile Removal Password","options":null},{"id":"com.apple.proxy.http.global_com.apple.proxy.http.global","displayName":"Top Level Setting Group Collection","description":"com.apple.proxy.http.global","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},{"id":"com.apple.proxy.http.global_proxycaptiveloginallowed","displayName":"Proxy Captive Login Allowed","description":"If true, allows the device to bypass the proxy server to display the login page for captive networks.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":[{"id":"com.apple.proxy.http.global_proxycaptiveloginallowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.proxy.http.global_proxycaptiveloginallowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.proxy.http.global_proxypacfallbackallowed","displayName":"Proxy PAC Fallback Allowed","description":"If true, allows connecting directly to the destination if the proxy autoconfiguration (PAC) file is unreachable. ","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":[{"id":"com.apple.proxy.http.global_proxypacfallbackallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.proxy.http.global_proxypacfallbackallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.proxy.http.global_proxypacurl","displayName":"Proxy PAC URL","description":"The URL of the PAC file that defines the proxy configuration. Starting in iOS 13 and macOS 10.15, only URLs that begin with http:// or https:// are allowed.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},{"id":"com.apple.proxy.http.global_proxypassword","displayName":"Proxy Password","description":"The password used to authenticate to the proxy server.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},{"id":"com.apple.proxy.http.global_proxyserver","displayName":"Proxy Server","description":"The proxy server's network address.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},{"id":"com.apple.proxy.http.global_proxyserverport","displayName":"Proxy Server Port","description":"The proxy server's port number.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},{"id":"com.apple.proxy.http.global_proxytype","displayName":"Proxy Type","description":"The proxy type. For a manual proxy type, the profile contains the proxy server address, including its port, and optionally a user name and password. For an auto proxy type, you can enter a PAC URL.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":[{"id":"com.apple.proxy.http.global_proxytype_0","displayName":"Manual","description":null,"helpText":null},{"id":"com.apple.proxy.http.global_proxytype_1","displayName":"Auto","description":null,"helpText":null}]},{"id":"com.apple.proxy.http.global_proxyusername","displayName":"Proxy Username","description":"The user name used to authenticate to the proxy server.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},{"id":"com.apple.screensaver_askforpassword","displayName":"Ask For Password","description":"If true, the user is prompted for a password when the screen saver is unlocked or stopped. When you use this prompt, you must also provide Ask For Password Delay. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":[{"id":"com.apple.screensaver_askforpassword_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.screensaver_askforpassword_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.screensaver_askforpassworddelay","displayName":"Ask For Password Delay","description":"The number of seconds to delay before the password will be required to unlock or stop the screen saver (the grace period). A value of 2147483647 (for example, 0x7FFFFFFF) disables this requirement. To use this option, you must set Ask For Password to true. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":null},{"id":"com.apple.screensaver_com.apple.screensaver","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":null},{"id":"com.apple.screensaver_loginwindowidletime","displayName":"Login Window Idle Time","description":"The number of seconds of inactivity before the screen saver activates (0 = Never activate). ","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":null},{"id":"com.apple.screensaver_loginwindowmodulepath","displayName":"Login Window Module Path","description":"The full path to the screen-saver module to use. ","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":null},{"id":"com.apple.screensaver_modulename","displayName":"Module Name","description":"The name of the screen saver module.","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":null},{"id":"com.apple.screensaver.user_com.apple.screensaver.user","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"11c4cf0f-a03d-4309-93b2-011be4c410d5","categoryName":"Screensaver User","options":null},{"id":"com.apple.screensaver.user_idletime","displayName":"Idle Time","description":"The number of seconds of inactivity before the screen saver activates (0 = Never activate).","helpText":null,"infoUrls":[],"categoryId":"11c4cf0f-a03d-4309-93b2-011be4c410d5","categoryName":"Screensaver User","options":null},{"id":"com.apple.screensaver.user_modulename","displayName":"Module Name","description":"The module name.","helpText":null,"infoUrls":[],"categoryId":"11c4cf0f-a03d-4309-93b2-011be4c410d5","categoryName":"Screensaver User","options":null},{"id":"com.apple.screensaver.user_modulepath","displayName":"Module Path","description":"A full path to the screen saver module to use.","helpText":null,"infoUrls":[],"categoryId":"11c4cf0f-a03d-4309-93b2-011be4c410d5","categoryName":"Screensaver User","options":null},{"id":"com.apple.security.fderecoverykeyescrow_com.apple.security.fderecoverykeyescrow","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"bd5533e1-f1ee-4994-8a79-cffe02b12d5c","categoryName":"FileVault Recovery Key Escrow","options":null},{"id":"com.apple.security.fderecoverykeyescrow_devicekey","displayName":"Device Key","description":"The string that's included in help text if the user appears to have forgotten the password. Site admins can use this key to look up the escrowed key for the particular computer. This key replaces the Record Number key used in the previous escrow mechanism. If the key is missing, the device serial number is used instead.","helpText":null,"infoUrls":[],"categoryId":"bd5533e1-f1ee-4994-8a79-cffe02b12d5c","categoryName":"FileVault Recovery Key Escrow","options":null},{"id":"com.apple.security.fderecoverykeyescrow_location","displayName":"Location","description":"The description of the location where the recovery key will be escrowed. This text will be inserted into the message the user sees when enabling FileVault.","helpText":null,"infoUrls":[],"categoryId":"bd5533e1-f1ee-4994-8a79-cffe02b12d5c","categoryName":"FileVault Recovery Key Escrow","options":null},{"id":"com.apple.security.firewall_allowsigned","displayName":"Allow Signed","description":"If true, allows built-in software to receive incoming connections. Available in macOS 12.3 and later.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_allowsigned_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_allowsigned_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_allowsignedapp","displayName":"Allow Signed App","description":"If true, allows downloaded signed software to receive incoming connections. Available in macOS 12.3 and later.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_allowsignedapp_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_allowsignedapp_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_applications","displayName":"Applications","description":"The list of apps with connections controlled by the firewall.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":null},{"id":"com.apple.security.firewall_applications_item_allowed","displayName":"Allowed","description":"If true, allows connections for the app.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_applications_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_applications_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_applications_item_bundleid","displayName":"Bundle ID","description":"The bundle identifier for an app.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":null},{"id":"com.apple.security.firewall_blockallincoming","displayName":"Block All Incoming","description":"If true, enables blocking of all incoming connections. ","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_blockallincoming_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_blockallincoming_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_com.apple.security.firewall","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":null},{"id":"com.apple.security.firewall_enablefirewall","displayName":"Enable Firewall","description":"If true, enables the firewall.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_enablefirewall_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_enablefirewall_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_enablelogging","displayName":"Enable Logging (Deprecated)","description":"If true, enables logging. Available in macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_enablelogging_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_enablelogging_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_enablestealthmode","displayName":"Enable Stealth Mode","description":"If true, enables stealth mode. ","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_enablestealthmode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_enablestealthmode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_loggingoption","displayName":"Logging Option (Deprecated)","description":"This string specifies the type of logging. Available in macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_loggingoption_0","displayName":"throttled","description":null,"helpText":null},{"id":"com.apple.security.firewall_loggingoption_1","displayName":"brief","description":null,"helpText":null},{"id":"com.apple.security.firewall_loggingoption_2","displayName":"detail","description":null,"helpText":null}]},{"id":"com.apple.security.smartcard_allowsmartcard","displayName":"Allow Smart Card","description":"If false, disables the SmartCard for logins, authorizations, and screen saver unlocking. It is still allowed for other functions, such as signing emails and accessing the web. A restart is required for a setting change to take effect. ","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":[{"id":"com.apple.security.smartcard_allowsmartcard_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.smartcard_allowsmartcard_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.smartcard_checkcertificatetrust","displayName":"Check Certificate Trust","description":"Disable certificate trust check: Turns off certificate trust check.\r\n\r\nEnable certificate trust check and standard validity check: Turns on certificate trust check. A standard validity check is performed but doesn't include additional revocation checks.\r\n\r\nEnable certificate trust check and soft revocation check: Turns on certificate trust check. A soft revocation check is also performed. Until the certificate is explicitly rejected by CRL/OCSP, it's considered valid. This setting means that unavailable or unreachable CRL/OCSP allow this check to succeed.\r\n\r\nEnable certificate trust check and hard revocation check: Turns on certificate trust check. A hard revocation check is also performed. Unless CRL/OCSP explicitly says \"This certificate is OK,\" it's considered invalid. This option is the most secure.","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":[{"id":"com.apple.security.smartcard_checkcertificatetrust_0","displayName":"Disable certificate trust check","description":null,"helpText":null},{"id":"com.apple.security.smartcard_checkcertificatetrust_1","displayName":"Enable certificate trust check and standard validity check","description":null,"helpText":null},{"id":"com.apple.security.smartcard_checkcertificatetrust_2","displayName":"Enable certificate trust check and soft revocation check","description":null,"helpText":null},{"id":"com.apple.security.smartcard_checkcertificatetrust_3","displayName":"Enable certificate trust check and hard revocation check","description":null,"helpText":null}]},{"id":"com.apple.security.smartcard_com.apple.security.smartcard","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":null},{"id":"com.apple.security.smartcard_enforcesmartcard","displayName":"Enforce Smart Card","description":"If true, a user can only log in or authenticate with a SmartCard. Ensure that users have a SmartCard before being targeted with this setting, or they may not be able to access the device. Available in macOS 10.13.2 and later.","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":[{"id":"com.apple.security.smartcard_enforcesmartcard_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.smartcard_enforcesmartcard_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.smartcard_onecardperuser","displayName":"One Card Per User","description":"If true, a user can pair with only one SmartCard, although existing pairings are allowed if already set up. ","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":[{"id":"com.apple.security.smartcard_onecardperuser_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.smartcard_onecardperuser_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.smartcard_tokenremovalaction","displayName":"Token Removal Action","description":"If set to Enabled, the screen saver is enabled when the SmartCard is removed. Available in macOS 10.13.4 and later.","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":[{"id":"com.apple.security.smartcard_tokenremovalaction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.security.smartcard_tokenremovalaction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.security.smartcard_userpairing","displayName":"User Pairing","description":"If false, users don't get the pairing dialog, although existing pairings still work. ","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":[{"id":"com.apple.security.smartcard_userpairing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.smartcard_userpairing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.servicemanagement_com.apple.servicemanagement","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},{"id":"com.apple.servicemanagement_rules","displayName":"Rules","description":"An array of rule dictionaries.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},{"id":"com.apple.servicemanagement_rules_item_comment","displayName":"Comment","description":"An optional description of the rule.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},{"id":"com.apple.servicemanagement_rules_item_ruletype","displayName":"Rule Type","description":"The type of comparision to make.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":[{"id":"com.apple.servicemanagement_rules_item_ruletype_0","displayName":"Bundle Identifier","description":null,"helpText":null},{"id":"com.apple.servicemanagement_rules_item_ruletype_1","displayName":"Bundle Identifier Prefix","description":null,"helpText":null},{"id":"com.apple.servicemanagement_rules_item_ruletype_2","displayName":"Label","description":null,"helpText":null},{"id":"com.apple.servicemanagement_rules_item_ruletype_3","displayName":"Label Prefix","description":null,"helpText":null},{"id":"com.apple.servicemanagement_rules_item_ruletype_4","displayName":"Team Identifier","description":null,"helpText":null}]},{"id":"com.apple.servicemanagement_rules_item_rulevalue","displayName":"Rule Value","description":"The value to compare with each login item's value, to determine a match to this rule.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},{"id":"com.apple.servicemanagement_rules_item_teamidentifier","displayName":"Team Identifier","description":"An additional constraint to limit the scope of the rule that is tested after matching the Rule Type and Rule Value.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},{"id":"com.apple.shareddeviceconfiguration_assettaginformation","displayName":"Asset Tag Information","description":"The asset tag information for the device, displayed in the Login Window and Lock Screen.","helpText":null,"infoUrls":[],"categoryId":"dec8381a-0a61-406b-842b-fc6ae9930795","categoryName":"Lock Screen Message","options":null},{"id":"com.apple.shareddeviceconfiguration_com.apple.shareddeviceconfiguration","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"dec8381a-0a61-406b-842b-fc6ae9930795","categoryName":"Lock Screen Message","options":null},{"id":"com.apple.shareddeviceconfiguration_lockscreenfootnote","displayName":"Lock Screen Footnote","description":"The footnote displayed in the login window and Lock screen. ","helpText":null,"infoUrls":[],"categoryId":"dec8381a-0a61-406b-842b-fc6ae9930795","categoryName":"Lock Screen Message","options":null},{"id":"com.apple.softwareupdate_allowprereleaseinstallation","displayName":"Allow Pre Release Installation (Deprecated)","description":"If true, prerelease software can be installed on this computer. ","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_allowprereleaseinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_allowprereleaseinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_automaticallyinstallappupdates","displayName":"Automatically Install App Updates (Deprecated)","description":"If false, deselects the \"Install app updates from the App Store\" option and prevents the user from changing the option. ","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_automaticallyinstallappupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_automaticallyinstallappupdates_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_automaticallyinstallmacosupdates","displayName":"Automatically Install Mac OS Updates (Deprecated)","description":"If false, restricts the \"Install macOS Updates\" option and prevents the user from changing the option.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_automaticallyinstallmacosupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_automaticallyinstallmacosupdates_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_automaticcheckenabled","displayName":"Automatic Check Enabled (Deprecated)","description":"If false, deselects the \"Check for updates\" option and prevents the user from changing the option.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_automaticcheckenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_automaticcheckenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_automaticdownload","displayName":"Automatic Download (Deprecated)","description":"If false, deselects the \"Download new updates when available from the App Store\" option and prevents the user from changing the option.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_automaticdownload_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_automaticdownload_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_com.apple.softwareupdate","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":null},{"id":"com.apple.softwareupdate_configdatainstall","displayName":"Config Data Install (Deprecated)","description":"If false, restricts the automatic installation of configuration data.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_configdatainstall_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_configdatainstall_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_criticalupdateinstall","displayName":"Critical Update Install (Deprecated)","description":"If false, disables the automatic installation of critical updates and prevents the user from changing the \"Install system data files and security updates\" option.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_criticalupdateinstall_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_criticalupdateinstall_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_restrict-software-update-require-admin-to-install","displayName":"Restrict Software Update Require Admin To Install (Deprecated)","description":"If true, restrict app installations to admin users. This key has the same function as the Restrict Store Require Admin To Install key in the App Store profile. ","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_restrict-software-update-require-admin-to-install_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_restrict-software-update-require-admin-to-install_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.subscribedcalendar.account_com.apple.subscribedcalendar.account","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":null},{"id":"com.apple.subscribedcalendar.account_subcalaccountdescription","displayName":"Account Description","description":"The description of the account.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":null},{"id":"com.apple.subscribedcalendar.account_subcalaccounthostname","displayName":"Account Host Name","description":"The server’s address.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":null},{"id":"com.apple.subscribedcalendar.account_subcalaccountpassword","displayName":"Account Password","description":"The user’s password.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":null},{"id":"com.apple.subscribedcalendar.account_subcalaccountusername","displayName":"Account Username","description":"The user's username.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":null},{"id":"com.apple.subscribedcalendar.account_subcalaccountusessl","displayName":"Account Use SSL","description":"If true, enables SSL.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":[{"id":"com.apple.subscribedcalendar.account_subcalaccountusessl_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.subscribedcalendar.account_subcalaccountusessl_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.system-extension-policy_allowedsystemextensions","displayName":"Allowed System Extensions","description":"A dictionary of approved system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension to install. It’s an error for the same team identifier to appear in both the AllowedTeamIdentifiers array and as a key in this dictionary.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowedsystemextensions_generickey","displayName":"Allowed System Extensions","description":"The mapping of team identifiers to arrays of bundle identifiers, where the bundle identifier defines the system extension to install.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowedsystemextensions_generickey_keytobereplaced","displayName":"Team Identifier","description":"Add a Team Identifier of valid and signed system extensions to load. The team identifier must be alphanumeric (letters and numbers) and have 10 characters. For example, enter ABCDE12345.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowedsystemextensiontypes","displayName":"Allowed System Extension Types","description":"A dictionary that maps a team identifier to an array of strings, where each string is a type of system extension that you can install for that team identifier. The allowed extension types are DriverExtension, NetworkExtension, and EndpointSecurityExtension. If there’s no entry for a specified team identifier in the dictionary, the system allows all extension types.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowedsystemextensiontypes_generickey","displayName":"Allowed System Extension Types","description":"The mapping of team identifier to an array of strings, where each string is a type of system extension that you can install for that team identifier.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowedsystemextensiontypes_generickey_keytobereplaced","displayName":"Team Identifier","description":"Add a Team Identifier of valid and signed system extensions to load. The team identifier must be alphanumeric (letters and numbers) and have 10 characters. For example, enter ABCDE12345.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowedteamidentifiers","displayName":"Allowed Team Identifiers","description":"An array of team identifiers that defines valid, signed system extensions that are allowable to load. Approved system extensions are those signed with any of the specified team identifiers. It’s an error for the same team identifier to appear in both this array and as a key in the Allowed System Extensions dictionary.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowuseroverrides","displayName":"Allow User Overrides","description":"If false, restricts users from approving additional system extensions that configuration profiles don’t explicitly allow.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":[{"id":"com.apple.system-extension-policy_allowuseroverrides_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.system-extension-policy_allowuseroverrides_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.system-extension-policy_com.apple.system-extension-policy","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_nonremovablefromuisystemextensions","displayName":"Non Removable From UI System Extensions","description":"A dictionary of system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension which cannot be disabled or uninstalled from System Settings or Finder. The set of system extensions between 'RemovableSystemExtensions' and 'NonRemovableFromUISystemExtensions' are allowed to overlap.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_nonremovablefromuisystemextensions_generickey","displayName":"ANY","description":"System extension bundle identifiers","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_nonremovablefromuisystemextensions_generickey_keytobereplaced","displayName":"Non Removable From UI System Extensions","description":"A dictionary of system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension which cannot be disabled or uninstalled from System Settings or Finder. The set of system extensions between 'RemovableSystemExtensions' and 'NonRemovableFromUISystemExtensions' are allowed to overlap.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_nonremovablesystemextensions","displayName":"Non Removable System Extensions","description":"A dictionary of system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension which cannot be disabled or uninstalled when SIP is enabled. It's an error for the same mapping to appear in the dictionary values corresponding to 'RemovableSystemExtensions' and 'NonRemovableSystemExtensions' keys.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_nonremovablesystemextensions_generickey","displayName":"ANY","description":"System extension bundle identifiers","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_nonremovablesystemextensions_generickey_keytobereplaced","displayName":"Non Removable System Extensions","description":"A dictionary of system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension which cannot be disabled or uninstalled when SIP is enabled. It's an error for the same mapping to appear in the dictionary values corresponding to 'RemovableSystemExtensions' and 'NonRemovableSystemExtensions' keys.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_removablesystemextensions","displayName":"Removable System Extensions","description":"A dictionary of system extensions that are allowed to remove themselves from the machine. The dictionary maps team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension. An application using the OSSystemExtensionDeactivationRequest API can deactivate the specified system extensions without requiring an administrator to authorize the operation. Available in macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_removablesystemextensions_generickey","displayName":"Removable System Extensions","description":"The dictionary maps team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_removablesystemextensions_generickey_keytobereplaced","displayName":"Team Identifier","description":"Add a Team Identifier of valid and signed system extensions to load. The team identifier must be alphanumeric (letters and numbers) and have 10 characters. For example, enter ABCDE12345.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system.logging_com.apple.system.logging","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","categoryName":"System Logging","options":null},{"id":"com.apple.system.logging_system","displayName":"System","description":"This dictionary has one key, Enable Private Data. Setting that value to true enables private data logging for the entire system.","helpText":null,"infoUrls":[],"categoryId":"0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","categoryName":"System Logging","options":null},{"id":"com.apple.system.logging_system_enable-private-data","displayName":"Enable Private Data","description":"Setting this value to true enables private data logging for the entire system.","helpText":null,"infoUrls":[],"categoryId":"0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","categoryName":"System Logging","options":[{"id":"com.apple.system.logging_system_enable-private-data_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.system.logging_system_enable-private-data_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_com.apple.systemconfiguration","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies","displayName":"Proxies","description":"The dictionary containing all the proxies for this device.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_exceptionslist","displayName":"Exceptions List","description":"The list of hosts and domains that should bypass proxy settings.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_fallbackallowed","displayName":"Fall Back Allowed","description":"If true, enables fallback.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_fallbackallowed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_fallbackallowed_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_ftpenable","displayName":"FTP Enable","description":"If true, enables FTP proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_ftpenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_ftpenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_ftppassive","displayName":"FTP Passive","description":"If true, enables passive FTP mode. ","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_ftppassive_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_ftppassive_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_ftpport","displayName":"FTP Port","description":"The FTP proxy port.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_ftpproxy","displayName":"FTP Proxy","description":"The host name or IP address for the FTP proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_gopherenable","displayName":"Gopher Enable","description":"If true, enables gopher proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_gopherenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_gopherenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_gopherport","displayName":"Gopher Port","description":"The gopher proxy port. ","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_gopherproxy","displayName":"Gopher Proxy","description":"The host name or IP address for the gopher proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_httpenable","displayName":"HTTP Enable","description":"If true, enables web proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_httpenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_httpenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_httpport","displayName":"HTTP Port","description":"The web proxy port.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_httpproxy","displayName":"HTTP Proxy","description":"The host name or IP address for the web proxy. ","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_httpsenable","displayName":"HTTPS Enable","description":"If true, enables secure web proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_httpsenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_httpsenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_httpsport","displayName":"HTTPS Port","description":"The secure web proxy port.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_httpsproxy","displayName":"HTTPS Proxy","description":"The host name or IP address for the secure web proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_proxyautoconfigenable","displayName":"Proxy Auto Config Enable","description":"If true, enables automatic proxy configuration.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_proxyautoconfigenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_proxyautoconfigenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_proxyautoconfigurlstring","displayName":"Proxy Auto Config URL String","description":"The automatic proxy configuration URL.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_proxycaptiveloginallowed","displayName":"Proxy Captive Login Allowed","description":"If true, allows client to log into captive portal network.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_proxycaptiveloginallowed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_proxycaptiveloginallowed_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_rtspenable","displayName":"RTSP Enable","description":"If true, enable streaming proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_rtspenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_rtspenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_rtspport","displayName":"RTSP Port","description":"The streaming proxy port.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_rtspproxy","displayName":"RTSP Proxy","description":"The host name or IP address for the streaming proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_socksenable","displayName":"SOCKS Enable","description":"If true, enable the SOCKS proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_socksenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_socksenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_socksportinteger","displayName":"SOCKS Port Integer","description":"The SOCKS proxy port.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_socksproxy","displayName":"SOCKS Proxy","description":"The host name or IP address for the SOCKS proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systempolicy.control_allowidentifieddevelopers","displayName":"Allow Identified Developers","description":"If true, enables Gatekeeper's \"Mac App Store and identified developers\" option.\r\nIf false, enables Gatekeeper's \"Mac App Store\" option.\r\n\r\nIf the value of Enable Assessment isn't set to true, this key has no effect.","helpText":null,"infoUrls":[],"categoryId":"763525a0-8456-4336-a8d1-392253e8fdd8","categoryName":"System Policy Control","options":[{"id":"com.apple.systempolicy.control_allowidentifieddevelopers_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systempolicy.control_allowidentifieddevelopers_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systempolicy.control_com.apple.systempolicy.control","displayName":"Top Level Setting Group Collection","description":"com.apple.systempolicy.control","helpText":null,"infoUrls":[],"categoryId":"763525a0-8456-4336-a8d1-392253e8fdd8","categoryName":"System Policy Control","options":null},{"id":"com.apple.systempolicy.control_enableassessment","displayName":"Enable Assessment","description":"If true, enables Gatekeeper.","helpText":null,"infoUrls":[],"categoryId":"763525a0-8456-4336-a8d1-392253e8fdd8","categoryName":"System Policy Control","options":[{"id":"com.apple.systempolicy.control_enableassessment_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systempolicy.control_enableassessment_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systempolicy.control_enablexprotectmalwareupload","displayName":"Enable XProtect Malware Upload","description":"If false, will prevent Gatekeeper from prompting the user to upload blocked malware to Apple for purposes of improving malware detection.","helpText":null,"infoUrls":[],"categoryId":"763525a0-8456-4336-a8d1-392253e8fdd8","categoryName":"System Policy Control","options":[{"id":"com.apple.systempolicy.control_enablexprotectmalwareupload_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.systempolicy.control_enablexprotectmalwareupload_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.systempolicy.managed_com.apple.systempolicy.managed","displayName":"Top Level Setting Group Collection","description":"com.apple.systempolicy.managed","helpText":null,"infoUrls":[],"categoryId":"64538726-8745-4e7a-b370-332f725b58bf","categoryName":"System Policy Managed","options":null},{"id":"com.apple.systempolicy.managed_disableoverride","displayName":"Disable Override","description":"If true, disables the Finder's contextual menu item.","helpText":null,"infoUrls":[],"categoryId":"64538726-8745-4e7a-b370-332f725b58bf","categoryName":"System Policy Managed","options":[{"id":"com.apple.systempolicy.managed_disableoverride_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systempolicy.managed_disableoverride_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systempreferences_com.apple.systempreferences","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","categoryName":"System Preferences","options":null},{"id":"com.apple.systempreferences_disabledpreferencepanes","displayName":"Disabled Preference Panes","description":"The list of disabled System Preferences panes.","helpText":null,"infoUrls":[],"categoryId":"c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","categoryName":"System Preferences","options":null},{"id":"com.apple.systempreferences_enabledpreferencepanes","displayName":"Enabled Preference Panes","description":"The list of enabled System Preferences panes.","helpText":null,"infoUrls":[],"categoryId":"c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","categoryName":"System Preferences","options":null},{"id":"com.apple.tcc.configuration-profile-policy_com.apple.tcc.configuration-profile-policy","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services","displayName":"Services","description":"A dictionary whose keys are limited to the privacy policy control services. In the case of conflicting specifications, the most restrictive setting (deny) is used.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility","displayName":"Accessibility (deprecated)","description":"Specifies the policies for the app via the Accessibility subsystem. This profile deprecated its ability to grant access as of macOS 26.2, and removes that ability in macOS 27.0.\n\nDeprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app-settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook","displayName":"Address Book","description":"Specifies the policies for contact information managed by the Contacts.app.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents","displayName":"Apple Events","description":"Specifies the policies for the app sending restricted AppleEvents to another process.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_aereceivercoderequirement","displayName":"AE Receiver Code Requirement","description":"The code requirement for the receiving binary.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_aereceiveridentifier","displayName":"AE Receiver Identifier","description":"The identifier of the process receiving an Apple Event sent by the Identifier process.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_aereceiveridentifiertype","displayName":"AE Receiver Identifier Type","description":"The type of AE Receiver Identifier value, either bundle ID or path.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_aereceiveridentifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_aereceiveridentifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways","displayName":"Bluetooth Always (deprecated)","description":"Specifies the policies for the app to access Bluetooth devices.\n\nDeprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app-settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_aereceivercoderequirement","displayName":"AE Receiver Code Requirement","description":"The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_aereceiveridentifier","displayName":"AE Receiver Identifier","description":"The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_aereceiveridentifiertype","displayName":"AE Receiver Identifier Type","description":"The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_aereceiveridentifiertype_0","displayName":"bundleID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_aereceiveridentifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_allowed","displayName":"Allowed","description":"If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.\n\n> Note:\n> Every payload needs to include either `Authorization` or `Allowed`, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_allowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_allowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_authorization","displayName":"Authorization","description":"The `Authorization` key is an optional replacement for the `Allowed` key, which has one of the following possible values:\n\n- `Allow`: Equivalent to a `true` value for the `Allowed` key\n- `Deny`: Equivalent to a `false` value for the `Allowed` key\n- `AllowStandardUserToSetSystemService`: Allows a standard (non-admin) user to configure the permissions for the specified app in the Privacy preferences for services that otherwise require admin authorization; only valid for the `ListenEvent` and `ScreenCapture` services\n\n> Note:\n> Every payload needs to include either `Authorization` or `Allowed`, but not both.\n\nAvailable in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_authorization_2","displayName":"AllowStandardUserToSetSystemService","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command ''codesign -display -r -''.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_comment","displayName":"Comment","description":"Not used.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifiertype_0","displayName":"bundleID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_staticcode","displayName":"Static Code","description":"If `true`, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_staticcode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_staticcode_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar","displayName":"Calendar","description":"Specifies the policies for calendar information managed by the Calendar.app.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_camera","displayName":"Camera (deprecated)","description":"A system camera. A profile can't grant access to the camera; it can only deny it.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence","displayName":"File Provider Presence","description":"Allows a File Provider application to know when the user is using files managed by the File Provider.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent","displayName":"Listen Event","description":"Allows the application to use CoreGraphics and HID APIs to listen to (receive) CGEvents and HID events from all processes. A profile can't grant access to these events; it can only deny it.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_allowed","displayName":"Allowed (Deprecated)","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary","displayName":"Media Library","description":"Allows the application to access Apple Music, music and video activity, and the media library.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone","displayName":"Microphone (deprecated)","description":"A system microphone. A profile can't grant access to the microphone; it can only deny it.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_photos","displayName":"Photos","description":"The pictures managed by the Photos app in `~/Pictures/.photoslibrary`.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent","displayName":"Post Event","description":"Specifies the policies for the application to use CoreGraphics APIs to send CGEvents to the system event stream.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders","displayName":"Reminders","description":"Specifies the policies for reminders information managed by the Reminders app.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture","displayName":"Screen Capture","description":"Allows the application to capture (read) the contents of the system display. A profile can't grant access to the contents; it can only deny it.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_allowed","displayName":"Allowed (Deprecated)","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition","displayName":"Speech Recognition (deprecated)","description":"Allows the application to use the system Speech Recognition facility and to send speech data to Apple.\n\nDeprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app-settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles","displayName":"System Policy All Files","description":"Allows the application access to all protected files, including system administration files.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles","displayName":"System Policy App Bundles","description":"Allows the application to update or delete other apps. Available in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata","displayName":"System Policy App Data","description":"Specifies the policies for the app to access the data of other apps.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_allowed","displayName":"Allowed","description":"If 'true', access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_allowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_allowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_authorization","displayName":"Authorization","description":"The 'Authorization' key is an optional replacement for the 'Allowed' key. Every payload must specify either 'Authorization' or 'Allowed', but not both.\n'Allow': Equivalent to a 'true' value for the 'Allowed' key.\n'Deny': Equivalent to a 'false' value for the 'Allowed' key.\n'AllowStandardUserToSetSystemService:' allows a standard (non-admin) user to configure the permissions for the specified app in the Privacy preferences for services that otherwise require admin authorization. 'AllowStandardUserToSetSystemService' is only valid for the 'ListenEvent' and 'ScreenCapture' services.\nAvailable in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_authorization_2","displayName":"AllowStandardUserToSetSystemService","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command ''codesign -display -r -''.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifiertype_0","displayName":"bundleID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_staticcode","displayName":"Static Code","description":"If `true`, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_staticcode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_staticcode_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder","displayName":"System Policy Desktop Folder","description":"Allows the application to access files in the user's Desktop folder.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder","displayName":"System Policy Documents Folder","description":"Allows the application to access files in the user's Documents folder.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder","displayName":"System Policy Downloads Folder","description":"Allows the application to access files in the user's Downloads folder.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes","displayName":"System Policy Network Volumes","description":"Allows the application to access files on network volumes.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes","displayName":"System Policy Removable Volumes","description":"Allows the application to access files on removable volumes.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles","displayName":"System Policy Sys Admin Files","description":"Allows the application access to some files used in system administration.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_closeviewfarpoint","displayName":"Close View Far Point","description":"The minimum zoom level in the Zoom options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_closeviewhotkeysenabled","displayName":"Close View Hotkeys Enabled","description":"If true, enables \"Use keyboard shortcuts\" in the Zoom options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_closeviewhotkeysenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_closeviewhotkeysenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_closeviewnearpoint","displayName":"Close View Near Point","description":"The maximum zoom level in the Zoom options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_closeviewscrollwheeltoggle","displayName":"Close View Scroll Wheel Toggle","description":"If true, enables \"Use scroll gesture\" in the Zoom options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_closeviewscrollwheeltoggle_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_closeviewscrollwheeltoggle_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_closeviewsmoothimages","displayName":"Close View Smooth Images","description":"If true, enables \"Smooth images\" in the Zoom options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_closeviewsmoothimages_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_closeviewsmoothimages_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_com.apple.universalaccess","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_contrast","displayName":"Contrast","description":"The contrast value in the Display options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_flashscreen","displayName":"Flash Screen","description":"If true, enables \"Flash the screen\" in the Audio options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_flashscreen_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_flashscreen_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_mousedriver","displayName":"Mouse Driver","description":"If true, enables Mouse Keys in the Mouse & Trackpad options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_mousedriver_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_mousedriver_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_mousedrivercursorsize","displayName":"Mouse Driver Cursor Size","description":"The size of the cursor.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_mousedriverignoretrackpad","displayName":"Mouse Driver Ignore Trackpad","description":"If true, ignores the built-in trackpad.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_mousedriverignoretrackpad_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_mousedriverignoretrackpad_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_mousedriverinitialdelay","displayName":"Mouse Driver Initial Delay","description":"The initial delay before moving the mouse with Mouse Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_mousedrivermaxspeed","displayName":"Mouse Driver Max Speed","description":"The maximum speed for the cursor when using Mouse Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_slowkey","displayName":"Slow Key","description":"If true, enables \"Slow Keys\" in the Keyboard options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_slowkey_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_slowkey_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_slowkeybeepon","displayName":"Slow Key Beep On","description":"If true, enables \"click key sounds\" for Slow Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_slowkeybeepon_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_slowkeybeepon_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_slowkeydelay","displayName":"Slow Key Delay","description":"The acceptance delay, in milliseconds, for Slow Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_stereoasmono","displayName":"Stereo as Mono","description":"If true, plays stereo audio as mono.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_stereoasmono_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_stereoasmono_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_stickykey","displayName":"Sticky Key","description":"If true, enables Sticky Keys in the Keyboard options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_stickykey_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_stickykey_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_stickykeybeeponmodifier","displayName":"Sticky Key Beep On Modifier","description":"If true, enables the beep when a modifier key is set for Sticky Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_stickykeybeeponmodifier_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_stickykeybeeponmodifier_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_stickykeyshowwindow","displayName":"Sticky Key Show Window","description":"If true, enables \"Display pressed keys on screen\" for Sticky Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_stickykeyshowwindow_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_stickykeyshowwindow_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_voiceoveronoffkey","displayName":"Voice Over On Off Key","description":"If true, enables Voice Over.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_voiceoveronoffkey_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_voiceoveronoffkey_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_whiteonblack","displayName":"White On Black","description":"If true, enables Invert Colors in Display Accommodations.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_whiteonblack_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_whiteonblack_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_allowlistbookmarks","displayName":"Allow List Bookmarks","description":"An array of dictionaries defining the pages that the user can visit.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_allowlistbookmarks_item_title","displayName":"Title","description":"The title of the bookmark.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_allowlistbookmarks_item_url","displayName":"URL","description":"The URL of the bookmark in the allow list.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_autofilterenabled","displayName":"Auto Filter Enabled","description":"If true, automatic filtering is in an enabled state. This function evaluates each web page as it loads and attempts to identify and block content not suitable for children. The search algorithm is complex and may vary from release to release, but it’s basically looking for adult language.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_autofilterenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_autofilterenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_com.apple.webcontent-filter","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_denylisturls","displayName":"Deny List URLs","description":"An array of URLs that are inaccessible. Limit the number of these URLs to about 500.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_filterbrowsers","displayName":"Filter Browsers","description":"If true, enables the filtering of WebKit traffic.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_filterbrowsers_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_filterbrowsers_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_filterdataproviderbundleidentifier","displayName":"Filter Data Provider Bundle Identifier","description":"The bundle identifier string of the filter data provider system extension. This string identifies the filter data provider when the filter starts running. This field is a requirement if Filter Sockets is true.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_filterdataproviderdesignatedrequirement","displayName":"Filter Data Provider Designated Requirement","description":"The designated requirement string that the system embeds in the code signature of the filter data provider system extension. This string identifies the filter data provider when the filter starts running. This field is a requirement if Filter Sockets is true.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_filtergrade","displayName":"Filter Grade","description":"This value is for deriving the relative order of content filters. Filters with a grade of firewall see network traffic before filters with a grade of inspector. The system doesn’t define the order of filters within a grade.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_filtergrade_0","displayName":"firewall","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_filtergrade_1","displayName":"inspector","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_filterpacketproviderbundleidentifier","displayName":"Filter Packet Provider Bundle Identifier","description":"The bundle identifier string of the filter packet provider system extension. This string identifies the filter packet provider when the filter starts running. This field is a requirement if Filter Packets is true.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_filterpacketproviderdesignatedrequirement","displayName":"Filter Packet Provider Designated Requirement","description":"The designated requirement string that the system embeds in the code signature of the filter packet provider system extension. This string identifies the filter packet provider when the filter starts running. This field is a requirement if Filter Packets is true.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_filterpackets","displayName":"Filter Packets","description":"If this value is true, the property enables the filtering of network packets. Either Filter Packets or Filter Sockets must be true for the filter to have an effect.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_filterpackets_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_filterpackets_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_filtersockets","displayName":"Filter Sockets","description":"If true, enables the filtering of socket traffic.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_filtersockets_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_filtersockets_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_filtertype","displayName":"Filter Type","description":"The type of filter, built-in or plug-in. In macOS, the system supports only the plug-in value.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_filtertype_0","displayName":"Built-in","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_filtertype_1","displayName":"Plug-in","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_hidedenylisturls","displayName":"Hide Deny List UR Ls","description":"If `true`, the device hides the `DenyListURLs` item in the profiles that display in Settings > General > VPN & Device Management.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_hidedenylisturls_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_hidedenylisturls_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_organization","displayName":"Organization","description":"The organization string that passes to the third-party plug-in.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_password","displayName":"Password","description":"The password for the service.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_permittedurls","displayName":"Permitted URLs","description":"An array or URLs that are accessible whether or not the automatic filter allows access. The system uses this array only when Auto Filter Enabled is true. Otherwise, it ignores this field.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_pluginbundleid","displayName":"Plugin Bundle ID","description":"The bundle ID of the plug-in that provides filtering service.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_safarihistoryretentionenabled","displayName":"Safari History Retention Enabled","description":"If `true`, this payload enforces a policy which requires retention of browsing history. This causes Safari to disable clearing of browsing history, and prevents the use of private browsing mode because that mode doesn't keep browsing history.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_safarihistoryretentionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_safarihistoryretentionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_serveraddress","displayName":"Server Address","description":"The server address, which may be the IP address, hostname, or URL.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_userdefinedname","displayName":"User Defined Name","description":"The display name for this filtering configuration.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_username","displayName":"User Name","description":"The user name for the service.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.xsan_com.apple.xsan","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":null},{"id":"com.apple.xsan_fsnameservers","displayName":"FS Name Servers","description":"An array of storage area network (SAN) File System Name Server coordinators. The list should contain the same addresses in the same order as the metadata controller (MDC) /Library/Preferences/Xsan/fsnameservers file. Xsan SAN clients automatically receive updates to the fsnameservers list from the SAN configuration servers whenever this list changes. StorNext administrators should update their profile whenever the fsnameservers list changes. This key is required for StorNext SANs.","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":null},{"id":"com.apple.xsan_sanauthmethod","displayName":"San Auth Method","description":"The authentication method for the SAN. This key is required for all Xsan SANs. It's optional for StorNext SANs but should be set if the StorNext SAN uses an auth_secret file. Only one value is accepted: auth_secret","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":{"id":"com.apple.xsan_sanauthmethod_0","displayName":"auth_secret","description":null,"helpText":null}},{"id":"com.apple.xsan_sanconfigurls","displayName":"San Config URLs","description":"An array of LDAP URLs where Xsan systems can obtain SAN configuration updates. This key is required for all Xsan SANs. There should be one entry for each Xsan MDC. Example URL: ldaps://mdc1.example.com:389","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":null},{"id":"com.apple.xsan_sanname","displayName":"San Name","description":"The name of the SAN. This key is required for all Xsan SANs. The name must exactly match the name of the SAN defined in the metadata server.","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":null},{"id":"com.apple.xsan_sharedsecret","displayName":"Shared Secret","description":"The shared secret used for Xsan network authentication. This key is required when the San Auth Method key is present. The value should equal the content of the MDC's /Library/Preferences/Xsan/.auth_secret file.","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":null},{"id":"com.apple.xsan.preferences_com.apple.xsan.preferences","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},{"id":"com.apple.xsan.preferences_denydlc","displayName":"Deny DLC","description":"An array of StorNext volume names. If the Xsan client is attempting to mount a volume named in this array, the client only mounts the volume if its logical units (LUNs) are available through Fibre Channel. It doesn't attempt to mount the volume using Distributed LAN Client (DLC).","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},{"id":"com.apple.xsan.preferences_denymount","displayName":"Deny Mount","description":"An array of Xsan or StorNext volume names. If no Only Mount array is present, the Xsan client automatically attempts to mount all SAN volumes except the volumes in this array. The system administrator can mount those volumes manually by using the xsanctl(8) mount command.","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},{"id":"com.apple.xsan.preferences_onlymount","displayName":"Only Mount","description":"An array of Xsan or StorNext volume names. The Xsan client attempts to automatically mount these volumes at startup. The system administrator can mount additional volumes manually by using the xsanctl(8) mount command.","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},{"id":"com.apple.xsan.preferences_preferdlc","displayName":"Prefer DLC","description":"An array of StorNext volume names. If the Xsan client is attempting to mount a volume named in this array, the Xsan client attempts to mount the volume using DLC. If DLC isn't available, the client attempts to mount the volume if its LUNs are available through Fibre Channel. The volume name must not also appear in Deny DLC.","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},{"id":"com.apple.xsan.preferences_usedlc","displayName":"Use DLC","description":"If true, use the DLC for all volumes.","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":[{"id":"com.apple.xsan.preferences_usedlc_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.xsan.preferences_usedlc_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.accesscontrolallowmethodsincorspreflightspecconformant","displayName":"Make Access-Control-Allow-Methods matching in CORS preflight spec conformant","description":"This policy controls whether request methods are uppercased when matching with Access-Control-Allow-Methods response headers in CORS preflight.\n\nIf you disable this policy, request methods are uppercased. This is the behavior on or before Microsoft Edge 108.\n\nIf you enable or don't configure this policy, request methods aren't uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT.\n\nThis would reject fetch(url, {method: 'Foo'}) + \"Access-Control-Allow-Methods: FOO\" response header,\nand would accept fetch(url, {method: 'Foo'}) + \"Access-Control-Allow-Methods: Foo\" response header.\n\nNote: request methods \"post\" and \"put\" aren't affected, while \"patch\" is affected.\n\nThis policy is intended to be temporary and will be removed in the future.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.accesscontrolallowmethodsincorspreflightspecconformant_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.accesscontrolallowmethodsincorspreflightspecconformant_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.accessibilityimagelabelsenabled","displayName":"Let screen reader users get image descriptions from Microsoft","description":"Lets screen reader users get descriptions of unlabeled images on the web.\n\nIf you enable or don't configure this policy, users have the option of using an anonymous Microsoft service. This service provides automatic descriptions for unlabeled images users encounter on the web when they're using a screen reader.\n\nIf you disable this policy, users can't enable the Get Image Descriptions from Microsoft feature.\n\nWhen this feature is enabled, the content of images that need a generated description is sent to Microsoft servers to generate a description.\n\nNo cookies or other user data is sent to Microsoft, and Microsoft doesn't save or log any image content.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.accessibilityimagelabelsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.accessibilityimagelabelsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.additionalsearchboxenabled","displayName":"Enable additional search box in browser","description":"A search box is another text input field located next to the address bar in a web browser. It allows users to perform web searches directly from the browser interface.\n\nIf you enable or don't configure this policy, the search box is visible and available for use.\nUsers can toggle the search box in Microsoft Edge Settings page edge://settings/appearance#SearchBoxInToolbar.\n\nIf you disable this policy, search box won't be visible, and users have to use the address bar or navigate to a search engine to perform web searches.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.additionalsearchboxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.additionalsearchboxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbareditingenabled","displayName":"Configure address bar editing","description":"If you enable or don't configure this policy, users can change the URL in the address bar.\n\nIf you disable this policy, it prevents users from changing the URL in the address bar.\n\nNote: This policy doesn't prevent the browser from navigating to any URL. Users can still navigate to any URL using the search option in the default New Tab Page, or using any link that leads to a web search engine. To ensure that users can only go to sites you expect, consider configuring the following policies in addition to this policy:\n\n- \"NewTabPageLocation\"\n\n- \"HomepageLocation\"\n\n- \"HomepageIsNewTabPage\"\n\n- \"URLBlocklist\" and \"URLAllowlist\" to scope the pages that browser can navigate to.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbareditingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbareditingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarmicrosoftsearchinbingproviderenabled","displayName":"Enable Microsoft Search in Bing suggestions in the address bar (Obsolete)","description":"Enables the display of relevant Microsoft Search in Bing suggestions in the address bar's suggestion list when the user enters a search query in the address bar. If you enable or don't configure this policy, users can see internal results powered by Microsoft Search in Bing in the Microsoft Edge address bar suggestion list. To access Microsoft Search in Bing results, the user must be signed in to Microsoft Edge with their organization's Azure AD account.\n\nIf you disable this policy, users won't see internal results in the Microsoft Edge address bar suggestion list.\n\nStarting with Microsoft Edge version 89, Microsoft Search in Bing suggestions will be available even if Bing isn't the user's default search provider.\n\nThis policy is no longer applicable due to changes in access to work search through Bing-related endpoints.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarmicrosoftsearchinbingproviderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarmicrosoftsearchinbingproviderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbartrendingsuggestenabled","displayName":"Enable Microsoft Bing trending suggestions in the address bar","description":"This policy controls whether Microsoft Bing trending suggestions appear in the address bar’s suggestion dropdown when users select the address bar while on a New Tab Page.\n\nIf this policy is enabled or not configured, Microsoft Bing trending suggestions appear in the address bar suggestion dropdown.\n\nIf this policy is disabled, Microsoft Edge doesn't display Microsoft Bing trending suggestions when users select the address bar.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbartrendingsuggestenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbartrendingsuggestenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarworksearchresultsenabled","displayName":"Enable Work Search suggestions in the address bar","description":"Enables the display of relevant workplace suggestions in the address bar’s suggestion dropdown when users type a query in the address bar.\n\nIf this policy is enabled or not configured, users can view internal work-related suggestions, such as bookmarks, files, and people results powered by Microsoft 365, in the Microsoft Edge address bar suggestion dropdown. To access these results, users must be signed into Microsoft Edge with their Entra ID account associated with that organization.\n\nIf this policy is disabled, users can't see internal workplace results in the Microsoft Edge address bar suggestion dropdown.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarworksearchresultsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarworksearchresultsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads","description":"Controls whether ads are blocked on sites with intrusive ads.\n\nPolicy options mapping:\n\n* AllowAds (1) = Allow ads on all sites\n\n* BlockAds (2) = Block ads on sites with intrusive ads. (Default value)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.adssettingforintrusiveadssites_allowads","displayName":"Allow ads on all sites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.adssettingforintrusiveadssites_blockads","displayName":"Block ads on sites with intrusive ads. (Default value)","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.adstransparencyenabled","displayName":"Configure if the ads transparency feature is enabled","description":"Lets you decide whether the ads transparency feature is enabled. This behavior only applies to the \"balanced\" mode of tracking prevention, and doesn't impact \"basic\" or \"strict\" modes. Your users' tracking prevention level can be configured using the \"TrackingPrevention\" policy. AdsTransparencyEnabled will only have an effect if \"TrackingPrevention\" is set to TrackingPreventionBalanced or isn't configured.\n\nIf you enable or don't configure this policy, transparency metadata provided by ads are available to the user when the feature is active.\n\nWhen the feature is enabled, Tracking Prevention enables exceptions for the associated ad providers that have met Microsoft's privacy standards.\n\nIf you disable this policy, Tracking Prevention won't adjust its behavior even when transparency metadata is provided by ads.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.adstransparencyenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.adstransparencyenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.aigenthemesenabled","displayName":"Enables DALL-E themes generation","description":"This policy lets you generate browser themes using DALL-E and apply them to Microsoft Edge.\n\nIf you enable or don't configure this policy, the AI generated themes are enabled.\n\nIf you disable this policy, the AI generated themes are disabled for your organization.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.aigenthemesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.aigenthemesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbackforwardcacheforcachecontrolnostorepageenabled","displayName":"Allow pages with Cache-Control: no-store header to enter back/forward cache","description":"This policy controls whether a page with Cache-Control: no-store header can be stored in back/forward cache. The website setting in this header may not expect the page to be restored from back/forward cache since some sensitive information could still be displayed after the restoration even if it's no longer accessible.\n\nIf you enable or don't configure this policy, the page with Cache-Control: no-store header is restored from back/forward cache unless the cache eviction is triggered (for example, when there's HTTP-only cookie change to the site).\n\nIf you disable this policy, the page with Cache-Control: no-store header isn't stored in back/forward cache.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbackforwardcacheforcachecontrolnostorepageenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbackforwardcacheforcachecontrolnostorepageenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge.","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\n\nBrowsing with Copilot is available only on domains specified in the \"BrowsingWithCopilotAllowList\" policy and is blocked on domains specified in the \"BrowsingWithCopilotBlockList\" policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\n\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\n\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?linkid=2346300.\n\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\n\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\n\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_recommended","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge. (users can override)","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\n\nBrowsing with Copilot is available only on domains specified in the \"BrowsingWithCopilotAllowList\" policy and is blocked on domains specified in the \"BrowsingWithCopilotBlockList\" policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\n\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\n\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?linkid=2346300.\n\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\n\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\n\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowdeletingbrowserhistory","displayName":"Enable deleting browser and download history","description":"Enables deleting browser history and download history and prevents users from changing this setting.\n\nEven if this policy is disabled, the browsing and download history aren't guaranteed to be retained: users can edit or delete the history database files directly, and the browser itself can remove (based on expiration period) or archive any or all history items at any time.\n\nIf you enable this policy or don't configure it, users can delete the browsing and download history.\n\nIf you disable this policy, users can't delete browsing and download history. Disabling this policy disables history sync and open tab sync.\n\nIf you enable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you enable both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how this policy is configured.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowdeletingbrowserhistory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowdeletingbrowserhistory_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace","description":"Setting the policy on Microsoft Edge turns on the restricted sign-in feature in Google Workspace and prevents users from changing this setting. Users can only access Google tools using accounts from the specified domains. To allow gmail or googlemail accounts, add consumer_accounts to the list of domains. This policy is based on the Chrome policy of the same name.\n\nIf you don't provide a domain name or leave this policy unset, users can access Google Workspace with any account.\n\nUsers can't change or override this setting.\n\nNote: This policy causes the X-GoogApps-Allowed-Domains header to be appended to all HTTP and HTTPS requests to all google.com domains, as described in https://go.microsoft.com/fwlink/?linkid=2197973.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowgamesmenu","displayName":"Allow users to access the games menu (Deprecated)","description":"This policy is deprecated because it can be managed using the \"HubsSidebarEnabled\" policy.\n\nIf you enable or don't configure this policy, users can access the games menu.\n\nIf you disable this policy, users won't be able to access the games menu.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowgamesmenu_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowgamesmenu_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowpopupsduringpageunload","displayName":"Allows a page to show popups during its unloading (Obsolete)","description":"This policy allows an admin to specify that a page can show popups during its unloading.\n\nWhen the policy is set to enabled, pages are allowed to show popups while they're being unloaded.\n\nWhen the policy is set to disabled or unset, pages aren't allowed to show popups while they're being unloaded. This restriction is as per the spec: (https://html.spec.whatwg.org/#apis-for-creating-and-navigating-browsing-contexts-by-name).\n\nThis policy was removed in Microsoft Edge 88 and is ignored if set.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowpopupsduringpageunload_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowpopupsduringpageunload_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsurfgame","displayName":"Allow surf game","description":"If you disable this policy, users won't be able to play the surf game when the device is offline or if the user navigates to edge://surf.\n\nIf you enable or don't configure this policy, users can play the surf game.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsurfgame_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsurfgame_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsyncxhrinpagedismissal","displayName":"Allow pages to send synchronous XHR requests during page dismissal (Obsolete)","description":"This policy is obsolete because it was only intended to be a short-term mechanism to give enterprises more time to update their web content if and when it was found to be incompatible with the change to disallow synchronous XHR requests during page dismissal. It doesn't work in Microsoft Edge after version 99.\n\nThis policy lets you specify that a page can send synchronous XHR requests during page dismissal.\n\nIf you enable this policy, pages can send synchronous XHR requests during page dismissal.\n\nIf you disable this policy or don't configure this policy, pages aren't allowed to send synchronous XHR requests during page dismissal.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsyncxhrinpagedismissal_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsyncxhrinpagedismissal_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsystemnotifications","displayName":"Allows system notifications","description":"Lets you use system notifications instead of Microsoft Edge's embedded Message Center on Windows and Linux.\n\nIf set to True or not set, Microsoft Edge is allowed to use system notifications.\n\nIf set to False, Microsoft Edge won't use system notifications. Microsoft Edge's embedded Message Center is used as a fallback.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsystemnotifications_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsystemnotifications_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowtrackingforurls","displayName":"Configure tracking prevention exceptions for specific sites","description":"Configure the list of URL patterns that are excluded from tracking prevention.\n\nIf you configure this policy, the list of configured URL patterns is excluded from tracking prevention.\n\nIf you don't configure this policy, the global default value from the \"Block tracking of users' web-browsing activity\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowwebauthnwithbrokentlscerts","displayName":"Allow Web Authentication requests on sites with broken TLS certificates.","description":"If you enable this policy, Microsoft Edge allows Web Authentication requests on websites that have TLS certificates with errors (that is, websites considered not secure).\n\nIf you disable or don't configure this policy, the default behavior of blocking such requests apply.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowwebauthnwithbrokentlscerts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowwebauthnwithbrokentlscerts_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alternateerrorpagesenabled","displayName":"Suggest similar pages when a webpage can't be found","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\n\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\n\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\n\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\nSpecifically, there's a **Suggest similar pages when a webpage can't be found** toggle, which the user can switch on or off. If you enable this policy (AlternateErrorPagesEnabled), the **Suggest similar pages when a webpage can't be found** setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the **Suggest similar pages when a webpage can't be found** setting is turned off, and the user can't change the setting by using the toggle.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.alternateerrorpagesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alternateerrorpagesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alternateerrorpagesenabled_recommended","displayName":"Suggest similar pages when a webpage can't be found (users can override)","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\n\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\n\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\n\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\nSpecifically, there's a **Suggest similar pages when a webpage can't be found** toggle, which the user can switch on or off. If you enable this policy (AlternateErrorPagesEnabled), the **Suggest similar pages when a webpage can't be found** setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the **Suggest similar pages when a webpage can't be found** setting is turned off, and the user can't change the setting by using the toggle.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.alternateerrorpagesenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alternateerrorpagesenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alwaysopenpdfexternally","displayName":"Always open PDF files externally","description":"Disables the internal PDF viewer in Microsoft Edge.\n\nIf you enable this policy Microsoft Edge treats PDF files as downloads and lets users open them with the default application.\n\nIf Microsoft Edge is the default PDF reader, PDF files aren't downloaded and continue to open in Microsoft Edge.\n\nIf you don't configure this policy or disable it, Microsoft Edge opens PDF files (unless the user disables it).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.alwaysopenpdfexternally_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alwaysopenpdfexternally_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.askbeforecloseenabled","displayName":"Get user confirmation before closing a browser window with multiple tabs","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\n\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\n\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.askbeforecloseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.askbeforecloseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.askbeforecloseenabled_recommended","displayName":"Get user confirmation before closing a browser window with multiple tabs (users can override)","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\n\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\n\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.askbeforecloseenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.askbeforecloseenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.audiocaptureallowedurls","displayName":"Sites that can access audio capture devices without requesting permission","description":"Specify websites, based on URL patterns, that can use audio capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to audio capture devices. Note, however, that the pattern \"*\", which matches any URL, isn't supported by this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled","displayName":"Configure auto discard sleeping tabs","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab needs to be reloaded.\n\nIf the \"SleepingTabsEnabled\" policy is enabled, then this feature is enabled by default.\n\nIf the \"SleepingTabsEnabled\" is disabled, then this feature is disabled by default and can't be enabled.\n\nIf enabled, idle background tabs will be discarded after 1.5 days.\n\nIf disabled, idle background tab won't be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_recommended","displayName":"Configure auto discard sleeping tabs (users can override)","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab needs to be reloaded.\n\nIf the \"SleepingTabsEnabled\" policy is enabled, then this feature is enabled by default.\n\nIf the \"SleepingTabsEnabled\" is disabled, then this feature is disabled by default and can't be enabled.\n\nIf enabled, idle background tabs will be discarded after 1.5 days.\n\nIf disabled, idle background tab won't be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled","displayName":"Enable AutoFill for addresses","description":"Enables the AutoFill feature and allows users to autocomplete address information in web forms through previously stored information.\n\nIf you have enabled or not configured this policy, users manage AutoFill for addresses in Microsoft Edge settings. AutoFill allows users to complete address fields in web forms using previously saved information.\n\nIf you have disabled this policy, Microsoft Edge doesn't suggest, fill in, or save address information. AutoFill is also disabled for all web forms except payment and password fields, and previously saved addresses aren't available.\n\nIf you disable this policy, then \"EdgeAutofillMlEnabled\" is turned off.\n\nIf you disable this policy, all activities for all web forms are stopped, except payment and password forms. No further entries are saved, and Microsoft Edge doesn't suggest or AutoFill any previous entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_recommended","displayName":"Enable AutoFill for addresses (users can override)","description":"Enables the AutoFill feature and allows users to autocomplete address information in web forms through previously stored information.\n\nIf you have enabled or not configured this policy, users manage AutoFill for addresses in Microsoft Edge settings. AutoFill allows users to complete address fields in web forms using previously saved information.\n\nIf you have disabled this policy, Microsoft Edge doesn't suggest, fill in, or save address information. AutoFill is also disabled for all web forms except payment and password fields, and previously saved addresses aren't available.\n\nIf you disable this policy, then \"EdgeAutofillMlEnabled\" is turned off.\n\nIf you disable this policy, all activities for all web forms are stopped, except payment and password forms. No further entries are saved, and Microsoft Edge doesn't suggest or AutoFill any previous entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillcreditcardenabled","displayName":"Enable AutoFill for payment instruments","description":"Enables Microsoft Edge's AutoFill feature and lets users auto complete payment instruments like credit or debit cards in web forms using previously stored information. Includes suggesting new payment instruments like Buy Now Pay Later (BNPL) in web forms and Express Checkout.\n\nIf you enable this policy or don't configure it, users can control AutoFill for payment instruments.\n\nIf you disable this policy, AutoFill never suggests, fills, or recommends new payment Instruments. Additionally, it won't save any payment instrument information that users submit while browsing the web.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillcreditcardenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillcreditcardenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillcreditcardenabled_recommended","displayName":"Enable AutoFill for payment instruments (users can override)","description":"Enables Microsoft Edge's AutoFill feature and lets users auto complete payment instruments like credit or debit cards in web forms using previously stored information. Includes suggesting new payment instruments like Buy Now Pay Later (BNPL) in web forms and Express Checkout.\n\nIf you enable this policy or don't configure it, users can control AutoFill for payment instruments.\n\nIf you disable this policy, AutoFill never suggests, fills, or recommends new payment Instruments. Additionally, it won't save any payment instrument information that users submit while browsing the web.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillcreditcardenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillcreditcardenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled","displayName":"Save and fill memberships","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\n\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_recommended","displayName":"Save and fill memberships (users can override)","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\n\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autolaunchprotocolscomponentenabled","displayName":"AutoLaunch Protocols Component Enabled","description":"Specifies whether the AutoLaunch Protocols component should be enabled. This component allows Microsoft to provide a list similar to that of the \"AutoLaunchProtocolsFromOrigins\" policy, allowing certain external protocols to launch without prompt or blocking certain protocols (on specified origins). By default, this component is enabled.\n\nIf you enable or don't configure this policy, the AutoLaunch Protocols component is enabled.\n\nIf you disable this policy, the AutoLaunch Protocols component is disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autolaunchprotocolscomponentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autolaunchprotocolscomponentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user","description":"Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator shouldn't be included when listing the protocol and the protocol should be all lower case. For example, list \"skype\" instead of \"skype:\", \"skype://\" or \"Skype\".\n\nIf you configure this policy, a protocol is only permitted to launch an external application without prompting by policy if:\n\n- the protocol is listed\n\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\n\nIf either condition is false, the external protocol launch prompt isn't omitted, by policy.\n\nIf you don't configure this policy, no protocols can launch without a prompt. Users can opt out of prompts on a per-protocol/per-site basis unless the \"ExternalProtocolDialogShowAlwaysOpenCheckbox\" policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users.\n\nThe origin-matching patterns use a similar format to those for the \"URLBlocklist\" policy, which are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\n\nHowever, origin-matching patterns for this policy can't contain \"/path\" or \"@query\" elements. Any pattern that contains a \"/path\" or \"@query\" element is ignored.\n\nThis policy doesn't work as expected with file://* wildcards.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automaticdownloadsallowedforurls","displayName":"Allow multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to perform multiple successive automatic downloads.\nIf you don't configure this policy, \"DefaultAutomaticDownloadsSetting\" applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automaticdownloadsblockedforurls","displayName":"Block multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, where multiple successive automatic downloads aren't allowed.\nIf you don't configure this policy, \"DefaultAutomaticDownloadsSetting\" applies for all sites, if that setting is active. If it isn't set, then the user's personal setting applies.\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automaticfullscreenallowedforurls","displayName":"Allow automatic full screen on specified sites","description":"For security reasons, the\nrequestFullscreen() web API\nrequires a prior user gesture (\"transient activation\") to be called or it\nfails. Users' personal settings can allow certain origins to call this API\nwithout a prior user gesture.\n\nThis policy supersedes users' personal settings and allows matching origins to\ncall the API without a prior user gesture.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\nWildcards (*) are allowed.\n\nOrigins matching both blocked and allowed policy patterns are blocked.\nOrigins not specified by policy or user settings require a prior user\ngesture to call this API.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automaticfullscreenblockedforurls","displayName":"Block automatic full screen on specified sites","description":"For security reasons, the\nrequestFullscreen() web API\nrequires a prior user gesture (\"transient activation\") to be called or it\nfails. Users' personal settings can allow certain origins to call this API\nwithout a prior user gesture.\n\nThis policy supersedes users' personal settings and blocks matching origins\nfrom calling the API without a prior user gesture.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\nWildcards (*) are allowed.\n\nOrigins matching both blocked and allowed policy patterns are blocked.\nOrigins not specified by policy or user settings require a prior user\ngesture to call this API.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault","displayName":"Configure Automatic HTTPS (Obsolete)","description":"This policy lets you manage settings for \"AutomaticHttpsDefault\", which switches connections from HTTP to HTTPS.\n\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\n\nMicrosoft Edge attempts to upgrade some navigations from HTTP to HTTPS, when possible. This policy can be used to disable this behavior. If set to \"AlwaysUpgrade\" or left unset, this feature is enabled by default.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nThis policy is obsolete, and is replaced with the policy \"HttpsUpgradesEnabled\".\n\nPolicy options mapping:\n\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\n\n* UpgradeCapableDomains (1) = (Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\n\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_disableautomatichttps","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_upgradecapabledomains","displayName":"(Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_alwaysupgrade","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended","displayName":"Configure Automatic HTTPS (Obsolete) (users can override)","description":"This policy lets you manage settings for \"AutomaticHttpsDefault\", which switches connections from HTTP to HTTPS.\n\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\n\nMicrosoft Edge attempts to upgrade some navigations from HTTP to HTTPS, when possible. This policy can be used to disable this behavior. If set to \"AlwaysUpgrade\" or left unset, this feature is enabled by default.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nThis policy is obsolete, and is replaced with the policy \"HttpsUpgradesEnabled\".\n\nPolicy options mapping:\n\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\n\n* UpgradeCapableDomains (1) = (Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\n\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended_disableautomatichttps","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended_upgradecapabledomains","displayName":"(Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended_alwaysupgrade","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoopenallowedforurls","displayName":"URLs where AutoOpenFileTypes can apply","description":"A list of URLs to which \"AutoOpenFileTypes\" applies to. This policy has no impact on automatically open values set by users via the download shelf ... > \"Always open files of this type\" menu entry.\n\nIf you set URLs in this policy, files will only automatically open by policy if the URL is part of this set and the file type is listed in \"AutoOpenFileTypes\". If either condition is false, the download won't automatically open by policy.\n\nIf you don't set this policy, all downloads where the file type is in \"AutoOpenFileTypes\" automatically opens.\n\nA URL pattern has to be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nThis policy doesn't work as expected with file://* wildcards.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoopenfiletypes","displayName":"List of file types that should be automatically opened on download","description":"This policy sets a list of file types that should be automatically opened on download. Note: The leading separator shouldn't be included when listing the file type, so list \"txt\" instead of \".txt\".\n\nBy default, these file types are automatically opened on all URLs. You can use the \"AutoOpenAllowedForURLs\" policy to restrict the URLs on which these file types are automatically opened.\n\nFiles with types that should be automatically opened are still subject to the enabled Microsoft Defender SmartScreen checks and won't be opened if they fail those checks.\n\nFile types that a user has already specified to automatically be opened continue to do so when downloaded. The user continues to be able to specify other file types to be automatically opened.\n\nIf you don't set this policy, only file types that a user has already specified to automatically be opened will do so when downloaded.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory or instances that enrolled for device management.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoplayallowed","displayName":"Allow media autoplay for websites","description":"This policy controls media autoplay behavior for websites.\n\nIf you don't configure this policy, Microsoft Edge uses the current media autoplay setting, and users can change their autoplay settings.\n\nIf you enable this policy, media autoplay is set to \"Allow\". All websites can autoplay media, and users can't override this setting.\n\nIf you disable this policy, media autoplay is set to \"Limit\" in Microsoft Edge version 148 and later. Autoplay is limited to webpages with high media engagement or active WebRTC streams, and users can't override this setting.\n\nIn versions 92 through 145, disabling this policy also set autoplay to \"Limit\". In versions 146 and 147, disabling this policy set autoplay to \"Block\".\n\nTabs must be closed and reopened for this policy to take effect.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoplayallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoplayallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoplayallowlist","displayName":"Allow media autoplay on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to autoplay media.\n\nIf you don't configure this policy, the global default value from the \"AutoplayAllowed\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nNote: * is not an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoselectcertificateforurls","displayName":"Automatically select client certificates for these sites","description":"Setting the policy lets you make a list of URL patterns that specify sites for which Microsoft Edge can automatically select a client certificate. The value is an array of stringified JSON dictionaries, each with the form { \"pattern\": \"$URL_PATTERN\", \"filter\" : $FILTER }, where $URL_PATTERN is a content setting pattern. $FILTER restricts the client certificates the browser automatically selects from. Independent of the filter, only certificates that match the server's certificate request are selected.\n\nExamples for the usage of the $FILTER section:\n\n* When $FILTER is set to { \"ISSUER\": { \"CN\": \"$ISSUER_CN\" } }, only client certificates issued by a certificate with the CommonName $ISSUER_CN are selected.\n\n* When $FILTER contains both the \"ISSUER\" and the \"SUBJECT\" sections, only client certificates that satisfy both conditions are selected.\n\n* When $FILTER contains a \"SUBJECT\" section with the \"O\" value, a certificate needs at least one organization matching the specified value to be selected.\n\n* When $FILTER contains a \"SUBJECT\" section with a \"OU\" value, a certificate needs at least one organizational unit matching the specified value to be selected.\n\n* When $FILTER is set to {}, the selection of client certificates isn't additionally restricted. Filters provided by the web server still apply.\n\nIf you leave the policy unset, there's no autoselection for any site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.backgroundtemplatelistupdatesenabled","displayName":"Enables background updates to the list of available templates for Collections and other features that use templates (Deprecated)","description":"This policy is deprecated because we are moving to a new policy. It won't work in Microsoft Edge as soon as version 104. The new policy to use is \"EdgeAssetDeliveryServiceEnabled\".\n\nLets you enable or disable background updates to the list of available templates for Collections and other features that use templates. Templates are used to extract rich metadata from a webpage when the page is saved to a collection.\n\nIf you enable this setting or the setting is unconfigured, the list of available templates are downloaded in the background from a Microsoft service every 24 hours.\n\nIf you disable this setting the list of available templates are downloaded on demand. This type of download might result in small performance penalties for Collections and other features.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.backgroundtemplatelistupdatesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.backgroundtemplatelistupdatesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.beforeunloadeventcancelbypreventdefaultenabled","displayName":"Control the behavior for the cancel dialog produced by the beforeunload event (Obsolete)","description":"This policy provides a temporary opt-out for two related fixes to the behavior of the confirmation dialog that’s shown by the beforeunload event.\n\nIf you've enabled this policy, the new (correct) behavior is used.\nIf you've disabled this policy, the old (legacy) behavior is used.\nIf you haven't configured this policy, the default behavior is used.\nNote: This policy is a temporary workaround and is going to be removed in a future release.\n\nNew and correct behavior: In `beforeunload`, calling `event.preventDefault()` triggers the confirmation dialog. Setting `event.returnValue` to the empty string doesn’t trigger the confirmation dialog.\n\nOld and legacy behavior: In `beforeunload`, calling `event.preventDefault()` doesn’t trigger the confirmation dialog. Setting `event.returnValue` to the empty string triggers the confirmation dialog.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.beforeunloadeventcancelbypreventdefaultenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.beforeunloadeventcancelbypreventdefaultenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockexternalextensions","displayName":"Blocks external extensions from being installed","description":"Control the installation of external extensions.\n\nIf you enable this setting, external extensions are blocked from being installed.\n\nIf you disable this setting or leave it unset, external extensions are allowed to be installed.\n\nExternal extensions and their installation are documented at [Alternate extension distribution methods](/microsoft-edge/extensions-chromium/developer-guide/alternate-distribution-options).","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockexternalextensions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockexternalextensions_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies","displayName":"Block third party cookies","description":"This policy controls whether third-party cookies are blocked in regular browsing sessions.\n\nIf you enable this policy, web page elements that are not from the domain shown in the address bar can't set cookies.\n\nIf you disable this policy, third-party cookies are allowed, including from domains other than the one shown in the address bar.\n\nIf you don't configure this policy, third-party cookies are allowed by default, but users can change this setting.\n\nNote: This policy doesn't apply in InPrivate mode. In InPrivate, third-party cookies are blocked by default and can only be allowed at the site level using the CookiesAllowedForUrls policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_recommended","displayName":"Block third party cookies (users can override)","description":"This policy controls whether third-party cookies are blocked in regular browsing sessions.\n\nIf you enable this policy, web page elements that are not from the domain shown in the address bar can't set cookies.\n\nIf you disable this policy, third-party cookies are allowed, including from domains other than the one shown in the address bar.\n\nIf you don't configure this policy, third-party cookies are allowed by default, but users can change this setting.\n\nNote: This policy doesn't apply in InPrivate mode. In InPrivate, third-party cookies are blocked by default and can only be allowed at the site level using the CookiesAllowedForUrls policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blocktruncatedcookies","displayName":"Block truncated cookies (Obsolete)","description":"This policy provides a temporary opt-out for changes to how Microsoft Edge handles cookies set via JavaScript that contain certain control characters (NULL, carriage return, and line feed).\nPreviously, the presence of any of these characters in a cookie string would cause it to be truncated but still set.\nNow, the presence of these characters will cause the whole cookie string to be ignored.\n\nIf you enable or don't configure this policy, the new behavior is enabled.\n\nIf you disable this policy, the old behavior is enabled.\n\nThis policy is obsolete because this policy was originally implemented as a safety measure if there was a breakage, but none have been reported.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.blocktruncatedcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blocktruncatedcookies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsernetworktimequeriesenabled","displayName":"Allow queries to a Browser Network Time service","description":"Prevents Microsoft Edge from occasionally sending queries to a browser network time service to retrieve an accurate timestamp.\n\nIf you disable this policy, Microsoft Edge stops sending queries to a browser network time service.\n\nIf you enable this policy or don't configure it, Microsoft Edge occasionally sends queries to a browser network time service.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsernetworktimequeriesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsernetworktimequeriesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsingdatalifetime","displayName":"Browsing Data Lifetime Settings","description":"This policy controls how long specific types of browsing data are retained.\nIf Sync is enabled, this policy has no effect.\n\nYou can specify the following data types:\n'browsing_history'\n'download_history'\n'cookies_and_other_site_data'\n'cached_images_and_files'\n'password_signin'\n'autofill'\n'site_settings'\n'hosted_app_data'\n\nMicrosoft Edge periodically deletes data of the selected types that's older than the value set by 'time_to_live_in_hours'.\n\nExpired data is removed 15 seconds after browser startup and every hour while the browser is running.\n\nNote: Deleting cookies using this policy doesn't sign the user out of their profile, the user stays signed in.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsingwithcopilotallowlist","displayName":"Browsing with Copilot Allowed URLs","description":"Allows you to define a list of URLs where browsing with Copilot is available. Users cannot modify this list.\n\nIf you enable this policy, browsing with Copilot is available only on the sites specified in the list. To allow a broader set of sites while blocking specific exceptions, configure this policy together with the \"BrowsingWithCopilotBlockList\" policy. For example, you can include '*' to allow all sites, and then use the block list to restrict access to specific URLs.\n\nYou can define exceptions based on schemes, subdomains, ports, or origins. When multiple filters apply, the most specific match determines whether a URL is allowed or blocked. The block list takes precedence over the allow list.\n\nIf you disable or do not configure this policy, browsing with Copilot is unavailable on all sites, even if the \"AllowBrowsingWithCopilot\" policy is enabled.\n\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. This policy applies only to the site origin; any path specified in the URL pattern is ignored. For guidance on formatting URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsingwithcopilotblocklist","displayName":"Browsing with Copilot Blocked URLs","description":"Controls the list of URLs where browsing with Copilot is blocked. Users can't modify this list.\n\nUse this policy to define exceptions to broader allowlists. For example, you can set \"BrowsingWithCopilotAllowList\" to '*' to allow all sites, and then use this policy to block access to specific URLs.\n\nThis policy supports blocking by scheme, subdomain, or port. When multiple URL patterns apply, the most specific match determines whether access is allowed or blocked. Blocklist entries take precedence over allowlist entries.\n\nIf you don't configure this policy, no exceptions are applied to \"BrowsingWithCopilotAllowList\".\n\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. URL matching is based on the site origin only; any path specified in the pattern is ignored.\n\nFor information about URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.builtinaiapisenabled","displayName":"Allow pages to use the built-in AI APIs.","description":"Use this policy to control whether websites can access the built-in AI APIs, including the LanguageModel API, Summarization API, Writer API, and Rewriter API.\n\nEnable this policy to allow pages to use the APIs. If you don’t configure this policy, the APIs are still allowed.\n\nDisable this policy to block access to the APIs. The APIs will return an error when used.\n\nFor more information, see https://github.com/webmachinelearning/writing-assistance-apis/blob/main/README.md.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.builtinaiapisenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.builtinaiapisenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates.","description":"This policy determines the level of access users have when managing CA certificates in Microsoft Edge.\n\nSetting the policy to UserOnly (1) allows users to manage only user-imported certificates. Trust settings for built-in certificates cannot be changed.\n\nSetting the policy to None (2) lets users view certificates but not manage them.\n\nNote: The certificate management experience is available starting in Microsoft Edge version 136.\n\nPolicy options mapping:\n\n* All (0) = Allow users to manage all certificates\n\n* UserOnly (1) = Allow users to manage user certificates\n\n* None (2) = Disallow users from managing certificates\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.cacertificatemanagementallowed_all","displayName":"Allow users to manage all certificates","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cacertificatemanagementallowed_useronly","displayName":"Allow users to manage user certificates","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cacertificatemanagementallowed_none","displayName":"Disallow users from managing certificates","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cacertificates","displayName":"TLS server certificates that should be trusted by Microsoft Edge","description":"This policy enables a list of Transport Layer Security (TLS) certificates that Microsoft Edge trusts for server authentication.\nCertificates should be base64 encoded.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Microsoft Edge for server authentication with constraints","description":"This policy enables a list of TLS certificates that should be trusted by Microsoft Edge for server authentication, with constraints added outside the certificate. If no constraint of a certain type is present, then any name of that type is allowed.\nCertificates should be base64-encoded. At least one constraint must be specified for each certificate.\n\nThe permitted_dns_names field is a list of DNS names that are allowed for the certificate. If the DNS name in the certificate request doesn't match one of the specified DNS names, the certificate isn't trusted.\n\nThe permitted_cidrs field is a list of CIDR (Classless Inter-Domain Routing) ranges that will be allowed for the certificate. If the IP address in the certificate request doesn't fall within one of the permitted CIDR ranges, the certificate isn't trusted.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cadistrustedcertificates","displayName":"TLS certificates that should be distrusted by Microsoft Edge for server authentication","description":"This policy enables defining a list of certificate public keys that should be distrusted by Microsoft Edge for TLS server\nauthentication.\n\nThe policy value is a list of base64-encoded X.509 certificates. Any\ncertificate with a matching SPKI (SubjectPublicKeyInfo) is distrusted.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication","description":"This policy defines certificates that Microsoft Edge doesn't explicitly trust or distrust but may be used as hints during certificate path-building.\n\nThe specified certificates are considered as intermediates during path validation; the server's certificate still chain to a trusted root to be considered valid.\n\nCertificates must be base64-encoded.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.caplatformintegrationenabled","displayName":"Use user-added TLS certificates from platform trust stores for server authentication","description":"If enabled (or unset), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.\n\nIf disabled, user-added TLS certificates from platform trust stores won't be used in path-building for TLS server authentication.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.caplatformintegrationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.caplatformintegrationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.certificatetransparencyenforcementdisabledforcas","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes","description":"Disables enforcement of Certificate Transparency requirements for a list of subjectPublicKeyInfo hashes.\n\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This allows certificates that would otherwise be untrusted because they weren't properly publicly disclosed to still be used for Enterprise hosts.\n\nTo disable Certificate Transparency enforcement when this policy is set, one of the following sets of conditions must be met:\n1. The hash is of the server certificate's subjectPublicKeyInfo.\n2. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, that CA certificate is constrained via the X.509v3 nameConstraints extension, one or more directoryName nameConstraints are present in the permittedSubtrees, and the directoryName contains an organizationName attribute.\n3. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, the CA certificate has one or more organizationName attributes in the certificate Subject, and the server's certificate contains the same number of organizationName attributes, in the same order, and with byte-for-byte identical values.\n\nA subjectPublicKeyInfo hash is specified by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\n\nIf you disable this policy or don't configure it, any certificate required to be disclosed via Certificate Transparency is treated as untrusted if not disclosed according to the Certificate Transparency policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.certificatetransparencyenforcementdisabledforlegacycas","displayName":"Disable Certificate Transparency enforcement for a list of legacy certificate authorities (Obsolete)","description":"Disables enforcing Certificate Transparency requirements for a list of legacy certificate authorities (Cas).\n\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This disablement of requirements allows otherwise-untrusted certificates (on account of not being publicly disclosed) to continue to be used for enterprise hosts.\n\nFor Certificate Transparency enforcement to be disabled, you must set the hash to a subjectPublicKeyInfo appearing in an authority-issued certificate that's recognized as a legacy certificate authority (CA). A legacy CA is a CA publicly trusted, by default, by one or more operating systems supported by Microsoft Edge.\n\nYou specify a subjectPublicKeyInfo hash by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\n\nIf you don't configure this policy, any certificate that's required to be disclosed via Certificate Transparency is treated as untrusted if it isn't disclosed according to the Certificate Transparency policy.\n\nThis policy is obsolete because the feature to disable Certificate Transparency enforcement for legacy certificates has been removed.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit","displayName":"Clear browsing data when Microsoft Edge closes","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\n\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured \"DefaultCookiesSetting\"\n\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\n\nIf you enable this policy, don't configure the \"AllowDeletingBrowserHistory\" or the \"ClearCachedImagesAndFilesOnExit\" policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured \"AllowDeletingBrowserHistory\" or \"ClearCachedImagesAndFilesOnExit\".\n\nTo exclude cookies from being deleted on exit, configure the \"SaveCookiesOnExit\" policy.\nTo exclude passwords from being deleted on exit, configure the \"PasswordDeleteOnBrowserCloseEnabled\" policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_recommended","displayName":"Clear browsing data when Microsoft Edge closes (users can override)","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\n\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured \"DefaultCookiesSetting\"\n\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\n\nIf you enable this policy, don't configure the \"AllowDeletingBrowserHistory\" or the \"ClearCachedImagesAndFilesOnExit\" policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured \"AllowDeletingBrowserHistory\" or \"ClearCachedImagesAndFilesOnExit\".\n\nTo exclude cookies from being deleted on exit, configure the \"SaveCookiesOnExit\" policy.\nTo exclude passwords from being deleted on exit, configure the \"PasswordDeleteOnBrowserCloseEnabled\" policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit","displayName":"Clear cached images and files when Microsoft Edge closes","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\n\nIf you enable this policy, cached images and files are deleted each time Microsoft Edge closes.\n\nIf you disable this policy, users can't configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\n\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\n\nIf you disable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you configure both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"ClearCachedImagesAndFilesOnExit\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_recommended","displayName":"Clear cached images and files when Microsoft Edge closes (users can override)","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\n\nIf you enable this policy, cached images and files are deleted each time Microsoft Edge closes.\n\nIf you disable this policy, users can't configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\n\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\n\nIf you disable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you configure both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"ClearCachedImagesAndFilesOnExit\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clipboardallowedforurls","displayName":"Allow clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\n\nSetting the policy lets you create a list of URL patterns that specify which sites can use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users can still paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\n\nLeaving the policy unset means \"DefaultClipboardSetting\" applies for all sites if it's set. If it isn't set, the user's personal setting applies.\n\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clipboardblockedforurls","displayName":"Block clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\n\nSetting the policy lets you create a list of URL patterns that specify sites that can't use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users can still paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\n\nLeaving the policy unset means \"DefaultClipboardSetting\" applies for all sites if it's set. If it isn't set, the user's personal setting applies.\n\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist","displayName":"Block access to a specified list of services and export targets in Collections","description":"List specific services and export targets that users can't access in the Collections feature in Microsoft Edge. This includes displaying additional data from Bing and exporting collections to Microsoft products or external partners.\n\nIf you enable this policy, services and export targets that match the given list are blocked.\n\nIf you don't configure this policy, no restrictions on the acceptable services and export targets are enforced.\n\nPolicy options mapping:\n\n* pinterest_suggestions (pinterest_suggestions) = Pinterest suggestions\n\n* collections_share (collections_share) = Sharing of Collections\n\n* local_pdf (local_pdf) = Save local PDFs in Collections to OneDrive\n\n* send_word (send_word) = Send collection to Microsoft Word\n\n* send_excel (send_excel) = Send collection to Microsoft Excel\n\n* send_onenote (send_onenote) = Send collection to Microsoft OneNote\n\n* send_pinterest (send_pinterest) = Send collection to Pinterest\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_pinterest_suggestions","displayName":"Pinterest suggestions","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_collections_share","displayName":"Sharing of Collections","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_local_pdf","displayName":"Save local PDFs in Collections to OneDrive","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_send_word","displayName":"Send collection to Microsoft Word","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_send_excel","displayName":"Send collection to Microsoft Excel","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_send_onenote","displayName":"Send collection to Microsoft OneNote","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_send_pinterest","displayName":"Send collection to Pinterest","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.composeinlineenabled","displayName":"Control access to Microsoft 365 Copilot writing assistance in Microsoft Edge for Business","description":"This policy controls whether users can use writing support features in Microsoft Edge for Business, such as Rewrite, which utilizes Microsoft 365 Copilot Chat. With Rewrite, users can receive help with drafting content, rewriting text, and adjusting style directly in their browser tab. In Microsoft Edge, users can trigger it when highlighting editable content in their main browser through the right-click context menu.\n\nThis policy applies only to Microsoft Entra accounts and doesn't apply to Microsoft accounts.\n\nIf you enable this policy, users can use Rewrite in Microsoft Edge when logged in with an Entra account.\n\nIf you disable this policy, users within your tenant can't use Rewrite.\n\nIf you don't configure this policy, the default behavior is as follows:\n\n- Rewrite is available to users\n\n- Users can enable or disable Microsoft 365 Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings.\n\nNote: Rewrite isn't available on pages protected by data loss prevention (DLP) policies to help maintain compliance.\n\nLearn more about Microsoft 365 Copilot Chat data, privacy, and security here: https://go.microsoft.com/fwlink/?linkid=2321816","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.composeinlineenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.composeinlineenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.compressiondictionarytransportenabled","displayName":"Enable compression dictionary transport support","description":"This feature enables the use of dictionary-specific content encodings in the Accept-Encoding request header (\"sbr\" and \"zst-d\") when dictionaries are available for use.\n\nIf you enable this policy or don't configure it, Microsoft Edge accepts web contents using the compression dictionary transport feature.\n\nIf you disable this policy, Microsoft Edge turns off the compression dictionary transport feature.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.compressiondictionarytransportenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.compressiondictionarytransportenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configuredonottrack","displayName":"Configure Do Not Track","description":"Specify whether to send Do Not Track requests to websites that ask for tracking info. Do Not Track requests let the websites you visit know that you don't want your browsing activity to be tracked. By default, Microsoft Edge doesn't send Do Not Track requests, but users can turn on this feature to send them.\n\nIf you enable this policy, Do Not Track requests are always sent to websites asking for tracking info.\n\nIf you disable this policy, requests are never sent.\n\nIf you don't configure this policy, users can choose whether to send these requests.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configuredonottrack_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configuredonottrack_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users","description":"If FriendlyURLs are enabled, Microsoft Edge computes more representations of the URL and places them on the clipboard.\n\nThis policy configures what format is pasted when the user pastes in external applications or inside Microsoft Edge without the 'Paste as' context menu item.\n\nIf you configure this policy, it makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu won't be available.\n\n* Not configured = The users are able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\n\n* 1 = No additional formats are stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge, and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature is disabled.\n\n* 3 = The user gets a friendly URL whenever they paste into surfaces that accept rich text. The plain URL is still available for nonrich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\n\n* 4 = (Not currently used)\n\nThe richer formats may not be supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy.\n\nThe recommended policy is available in Microsoft Edge 105 or later.\n\nPolicy options mapping:\n\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\n\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.\n\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_plaintext","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_titledhyperlink","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_webpreview","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (users can override)","description":"If FriendlyURLs are enabled, Microsoft Edge computes more representations of the URL and places them on the clipboard.\n\nThis policy configures what format is pasted when the user pastes in external applications or inside Microsoft Edge without the 'Paste as' context menu item.\n\nIf you configure this policy, it makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu won't be available.\n\n* Not configured = The users are able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\n\n* 1 = No additional formats are stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge, and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature is disabled.\n\n* 3 = The user gets a friendly URL whenever they paste into surfaces that accept rich text. The plain URL is still available for nonrich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\n\n* 4 = (Not currently used)\n\nThe richer formats may not be supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy.\n\nThe recommended policy is available in Microsoft Edge 105 or later.\n\nPolicy options mapping:\n\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\n\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.\n\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended_plaintext","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended_titledhyperlink","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended_webpreview","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurekeyboardshortcuts","displayName":"Configure the list of commands for which to disable keyboard shortcuts","description":"Configure the list of Microsoft Edge commands for which keyboard shortcuts must be disabled.\n\nSee https://go.microsoft.com/fwlink/?linkid=2186950 for a list of possible commands to disable.\n\nIf you enable this policy, commands in the 'disabled' list are no longer activated by keyboard shortcuts.\n\nIf you disable this policy, all keyboard shortcuts behave as usual.\n\nNote: Disabling a command only removes its shortcut mapping. Commands in the 'disabled' list still function if accessed via browser UI.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility","displayName":"Configure whether the Discover or Work feed tabs are shown on the New Tab Page.","description":"This policy configures whether the Discover or Work feed tabs are shown on the New Tab Page. By default, both Work and Discover tabs are enabled.\n\nIf you set this policy to 'EnableBothWorkDiscover' (0) or do not configure this policy, Microsoft Edge shows both the Work and Discover feed tabs on the new tab page.\n\nIf you set this policy to 'EnableOnlyWork' (1), Microsoft Edge shows only the Work feed tab on the new tab page.\n\nIf you set this policy to 'EnableOnlyDiscover' (2), Microsoft Edge shows only the Discover feed tab on the new tab page.\n\nThis policy works with the SetNTPDefaultFeedTab policy, which controls which feed tab is selected by default when both tabs are available.\n\nPolicy options mapping:\n\n* EnableBothWorkDiscover (0) = Enable both Work and Discover tabs\n\n* EnableOnlyWork (1) = Enable only Work tab\n\n* EnableOnlyDiscover (2) = Enable only Discover tab\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility_enablebothworkdiscover","displayName":"Enable both Work and Discover tabs","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility_enableonlywork","displayName":"Enable only Work tab","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility_enableonlydiscover","displayName":"Enable only Discover tab","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureonlinetexttospeech","displayName":"Configure Online Text To Speech","description":"Set whether the browser can apply Online Text to Speech voice fonts, part of Azure Cognitive Services. These voice fonts are higher quality than the pre-installed system voice fonts.\n\nIf you enable or don't configure this policy, web-based applications that use the SpeechSynthesis API can use Online Text to Speech voice fonts.\n\nIf you disable this policy, the voice fonts aren't available.\n\nRead more about this feature here:\nSpeechSynthesis API: https://go.microsoft.com/fwlink/?linkid=2110038\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2110141","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureonlinetexttospeech_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureonlinetexttospeech_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureshare","displayName":"Configure the Share experience","description":"If you set this policy to 'ShareAllowed' (the default), users can access the Share experience from the Settings and More Menu in Microsoft Edge to share with other apps on the system.\n\nIf you set this policy to 'ShareDisallowed', users can't access the Share experience. If the Share button is on the toolbar, it's hidden as well.\n\nPolicy options mapping:\n\n* ShareAllowed (0) = Allow using the Share experience\n\n* ShareDisallowed (1) = Don't allow using the Share experience\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureshare_shareallowed","displayName":"Allow using the Share experience","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureshare_sharedisallowed","displayName":"Don't allow using the Share experience","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.controldefaultstateofallowextensionfromotherstoressettingenabled","displayName":"Configure default state of Allow extensions from other stores setting","description":"This policy allows you to control the default state of the Allow extensions from other stores setting.\nThis policy can't be used to stop installation of extensions from other stores such as Chrome Web Store.\nTo stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098.\n\nWhen enabled, Allow extensions from other stores will be turned on. So, users won't have to turn on the flag manually\nwhile installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting.\nIf the user has already turned on the setting and then turned it off, this setting may not work.\nIf the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it will have no impact on\nuser settings and the setting will remain as it is.\n\nWhen disabled or not configured, the user can manage the Allow extensions from other store setting.\n","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.controldefaultstateofallowextensionfromotherstoressettingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.controldefaultstateofallowextensionfromotherstoressettingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.controldefaultstateofallowextensionfromotherstoressettingenabled_recommended","displayName":"Configure default state of Allow extensions from other stores setting (users can override)","description":"This policy allows you to control the default state of the Allow extensions from other stores setting.\nThis policy can't be used to stop installation of extensions from other stores such as Chrome Web Store.\nTo stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098.\n\nWhen enabled, Allow extensions from other stores are turned on. So, users don't have to turn on the flag manually\nwhile installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting.\nIf the user turned on the setting and then turned it off, this setting may not work.\nIf the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it has no impact on\nuser settings and the setting remains as it is.\n\nWhen disabled or not configured, the user can manage the Allow extensions from other store setting.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.controldefaultstateofallowextensionfromotherstoressettingenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.controldefaultstateofallowextensionfromotherstoressettingenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cookiesallowedforurls","displayName":"Allow cookies on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to set cookies. URL patterns can be a single URL indicating that the site can use cookies on all top-level sites. Patterns can also be two URLs delimited by a comma. The first specifies the site that should be allowed to use cookies. The second specifies the top-level site that the first value should be applied on. If you use a pair of URLs, the first value in the pair supports *, but the second value doesn't. Using * for the first value indicates that all sites can use cookies when the second URL is the top-level site.\n\nIf you don't configure this policy, the global default value from the \"DefaultCookiesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor more information, see the \"CookiesBlockedForUrls\" and \"CookiesSessionOnlyForUrls\" policies.\n\nNote there can't be conflicting URL patterns set between these three policies:\n\n- \"CookiesBlockedForUrls\"\n\n- CookiesAllowedForUrls\n\n- \"CookiesSessionOnlyForUrls\"\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.\n\nTo allow third-party cookies to be set, specify a pair of URL patterns delimited by a comma. The first value in the pair specifies the third-party site that should be allowed to use cookies. The second value in the pair specifies the top-level site that the first value should be applied on. The first value in the pair supports * but the second value doesn't.\n\nTo exclude cookies from being deleted on exit, configure the \"SaveCookiesOnExit\" policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cookiesblockedforurls","displayName":"Block cookies on specific sites","description":"Define a list of sites, based on URL patterns, that can't set cookies.\n\nIf you don't configure this policy, the global default value from the \"DefaultCookiesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nSee the \"CookiesAllowedForUrls\" and \"CookiesSessionOnlyForUrls\" policies for more information.\n\nNote there can't be conflicting URL patterns set between these three policies:\n\n- CookiesBlockedForUrls\n\n- \"CookiesAllowedForUrls\"\n\n- \"CookiesSessionOnlyForUrls\"\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cookiessessiononlyforurls","displayName":"Limit cookies from specific websites to the current session","description":"Cookies created by websites that match a URL pattern you define are deleted when the session ends (when the window closes).\n\nCookies created by websites that don't match the pattern are controlled by the \"DefaultCookiesSetting\" policy (if set) or by the user's personal configuration. This is also the default behavior if you don't configure this policy.\n\nYou can also use the \"CookiesAllowedForUrls\" and \"CookiesBlockedForUrls\" policies to control which websites can create cookies.\n\nNote there can't be conflicting URL patterns set between these three policies:\n\n- \"CookiesBlockedForUrls\"\n\n- \"CookiesAllowedForUrls\"\n\n- CookiesSessionOnlyForUrls\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.\n\nIf you set the \"RestoreOnStartup\" policy to restore URLs from previous sessions, this policy is ignored, and cookies are stored permanently for those sites.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotaddressbarsuggestionsenabled","displayName":"Enable Copilot address bar suggestions","description":"This policy controls whether Copilot chat suggestions appear in the address bar of Microsoft Edge.\n\nIf you enable this policy or don't configure it, Copilot chat suggestions appear in the address bar.\n\nIf you disable this policy, Copilot chat suggestions don't appear in the address bar.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotaddressbarsuggestionsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotaddressbarsuggestionsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotcdppagecontext","displayName":"Control Copilot with Commercial Data Protection access to page context for Microsoft Entra ID profiles (Obsolete)","description":"This policy has been obsoleted as of Edge 133. Instead of this obsolete policy, we recommend using \"EdgeEntraCopilotPageContext\".\n\nThis policy controls access to page contents for Copilot with Commercial Data Protection in the Edge sidebar. This policy applies only to Microsoft Entra ID profiles. To summarize pages and interact with text selections, it needs to be able to access the page contents. This policy doesn't apply to MSA profiles. This policy doesn't control access for Copilot without Commercial Data Protection. Access for Copilot without Commercial Data Protection is controlled by the policy CopilotPageContext.\n\nIf you enable this policy, Copilot with Commercial Data Protection will have access to page context.\n\nIf you don't configure this policy, a user can enable access to page context for Copilot with Commercial Data Protection using the setting toggle in Edge.\n\nIf you disable this policy, Copilot with Commercial Data Protection won't be able to access page context.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotcdppagecontext_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotcdppagecontext_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled","displayName":"Enable the Copilot new tab page","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\n\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\n\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\n\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\n\nIf you enable this policy, the Copilot new tab page is turned on.\n\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_recommended","displayName":"Enable the Copilot new tab page (users can override)","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\n\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\n\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\n\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\n\nIf you enable this policy, the Copilot new tab page is turned on.\n\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotpagecontext","displayName":"Control Copilot access to page context for Microsoft Entra ID profiles","description":"This policy controls whether Copilot in the Microsoft Edge side pane can access page content.\n\nThis policy applies only to Microsoft Entra ID profiles in Microsoft Edge. It doesn't apply to Microsoft account (MSA) profiles.\n\nCopilot requires access to page content to summarize pages and interact with text selections.\n\nThis policy doesn't control access for Copilot with enterprise data protection (EDP). Access for Copilot with EDP is controlled by the \"EdgeEntraCopilotPageContext\" policy.\n\nIf you enable this policy, Copilot can access page content.\n\nIf you disable this policy, Copilot can't access page content. This also disables the \"M365LinksAutoOpenCopilotEnabled\" feature, because Copilot requires page content access to provide contextual insights for Microsoft 365 links.\n\nIf you don't configure this policy:\n- Access is enabled by default in non-EU regions.\n- Access is disabled by default in EU regions.\n- Users can turn this setting on or off in Microsoft Edge settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotpagecontext_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotpagecontext_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request header support enabled","description":"This policy lets you configure support for CORS non-wildcard request headers.\n\nMicrosoft Edge version 97 introduces support for CORS non-wildcard request headers. When a script makes a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header is explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. For more information, see https://go.microsoft.com/fwlink/?linkid=2180022.\n\nIf you enable or don't configure the policy, Microsoft Edge supports the CORS non-wildcard request headers and behaves as previously described.\n\nIf you disable this policy, Microsoft Edge allows the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\n\nThis policy is a temporary workaround for the new CORS non-wildcard request header feature. It's planned to be removed in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.corsnonwildcardrequestheaderssupport_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.corsnonwildcardrequestheaderssupport_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cpuperformancetieroverride","displayName":"Override for the CPU performance tier","description":"This policy allows you to override the value returned by the CPU Performance API (that is, navigator.cpuPerformance).\n\nIf you enable this policy, the value of navigator.cpuPerformance is overridden with the specified value.\n\nIf you don’t configure this policy, the default performance tier calculation is used.\n\nYou can specify a value from 0 through 4.\n\nFor more information, see https://github.com/WICG/cpu-performance.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.createpasskeysinicloudkeychain","displayName":"Control whether passkey creation will default to iCloud Keychain.","description":"Microsoft Edge may direct\npasskey/WebAuthn creation requests directly to iCloud Keychain on macOS version 13.5\nor later. If iCloud Keychain syncing isn't enabled yet, this will\nprompt the user to sign in with iCloud, or might prompt them to enable iCloud\nKeychain syncing.\n\nIf you have enabled this policy, then iCloud Keychain is the default\nwhenever the WebAuthn request is compatible with that choice.\n\nIf you haven't configured this policy, then the default behavior depends on factors such as\nwhether iCloud Drive is enabled, or whether the user has recently used or\ncreated a credential in their\nMicrosoft Edge profile.\n\nIf you have disabled this policy, iCloud Keychain isn't used by default\nand the previous behavior (of creating the credential in the Microsoft Edge profile) is used\ninstead. Users can still select iCloud Keychain as an option, and\ncan still see iCloud Keychain credentials when signing in.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.createpasskeysinicloudkeychain_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.createpasskeysinicloudkeychain_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.crossoriginwebassemblymodulesharingenabled","displayName":"Specifies whether WebAssembly modules can be sent cross-origin (Obsolete)","description":"Specifies whether WebAssembly modules can be sent to another window or worker cross-origin. Cross-origin WebAssembly module sharing was deprecated as part of the efforts to deprecate document.domain, see https://github.com/mikewest/deprecating-document-domain. This policy allowed re-enabling of cross-origin WebAssembly module sharing. This policy is obsolete because it was intended to offer a longer transition period in the deprecation process.\n\nIf you enable this policy, sites can send WebAssembly modules cross-origin\nwithout restrictions.\n\nIf you disable or don't configure this policy, sites can only send\nWebAssembly modules to windows and workers in the same origin.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.crossoriginwebassemblymodulesharingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.crossoriginwebassemblymodulesharingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cryptowalletenabled","displayName":"Enable CryptoWallet feature (Obsolete)","description":"This policy is obsoleted because this feature will no longer be supported, starting in Microsoft Edge 128. There's no replacement for this policy.\n Enables CryptoWallet feature in Microsoft Edge.\n\n If you enable this policy or don't configure it, users can use CryptoWallet feature that allows users to securely store, manage, and transact digital assets such as Bitcoin, Ethereum, and other cryptocurrencies. Therefore, Microsoft Edge may access Microsoft servers to communicate with the web3 world during the use of the CryptoWallet feature.\n\n If you disable this policy, users can't use CryptoWallet feature.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.cryptowalletenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cryptowalletenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.csscustomstatedeprecatedsyntaxenabled","displayName":"Controls whether the deprecated :--foo syntax for CSS custom state is enabled (Obsolete)","description":"The :--foo syntax for the CSS custom state feature is being changed to :state(foo) in Microsoft Edge to comply with changes that are made in Firefox and Safari. This policy allows the deprecated syntax to be used until Stable 132.\n\nThis deprecation breaks some Microsoft Edge-only websites that use the deprecated :--foo syntax.\n\nIf you enable this policy, the deprecated syntax is enabled.\n\nIf you disable or don't configure this policy, the deprecated syntax is disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.csscustomstatedeprecatedsyntaxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.csscustomstatedeprecatedsyntaxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.customhelplink","displayName":"Specify custom help link","description":"Specify a link for the Help menu or the F1 key.\n\nIf you enable this policy, an admin can specify a link for the Help menu or the F1 key.\n\nIf you disable or don't configure this policy, the default link for the Help menu or the F1 key is used.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinsvguseenabled","displayName":"Data URL support for SVGUseElement","description":"This policy enables Data URL support for SVGUseElement, which is disabled\nby default starting in Microsoft Edge version 119.\nIf this policy is enabled, Data URLs keep working in SVGUseElement.\nIf this policy is disabled or not configured, Data URLs can't work in SVGUseElement.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinsvguseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinsvguseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinwebworkeropaqueoriginenabled","displayName":"Enable opaque origins for data URLs in Web Workers","description":"This policy controls whether Web Workers created from data URLs are assigned\na unique opaque origin.\n\nWeb Workers can be created using a data URL that contains the worker script.\nPreviously, these workers inherited the origin of the page that created them,\nwhich allowed them to access the same origin-bound data, such as local\nstorage and cookies.\n\nStarting in Microsoft Edge version\n149, Web Workers created from data URLs are assigned a unique opaque origin\nby default. This behavior improves security and aligns with the HTML\nspecification by isolating these workers from the page that created them.\n\nIf you enable this policy or don't configure it, Web Workers created from\ndata URLs are assigned a unique opaque origin.\n\nIf you disable this policy, Web Workers created from data URLs inherit the\norigin of the page that created them. Use this setting only as a temporary\nmitigation for compatibility issues with internal applications that depend\non the legacy behavior.\n\nThis policy is temporary and will be removed in Microsoft Edge\nversion 157.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinwebworkeropaqueoriginenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinwebworkeropaqueoriginenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultautomaticdownloadssetting","displayName":"Default automatic downloads setting","description":"Administrators can use this policy to control whether websites can perform multiple downloads successively. Individual site behavior can be managed using the AutomaticDownloadsAllowedForUrls and AutomaticDownloadsBlockedForUrls policies.\n\nDefault behavior:\n\n- A user gesture is required for each additional download.\n\n- Users can modify their browser settings to disable successive downloads.\n\nPolicy options mapping:\n\n* AllowAutomaticDownloads (1) = Allow all websites to perform multiple downloads without requiring a user gesture between each download.\n\n* BlockAutomaticDownloads (2) = Prevent all websites from performing multiple downloads, even after a user gesture.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultautomaticdownloadssetting_allowautomaticdownloads","displayName":"Allow all websites to perform multiple downloads without requiring a user gesture between each download.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultautomaticdownloadssetting_blockautomaticdownloads","displayName":"Prevent all websites from performing multiple downloads, even after a user gesture.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultclipboardsetting","displayName":"Default clipboard site permission","description":"This policy controls the default value for the clipboard site permission.\n\nSetting the policy to 2 blocks sites from using the clipboard site permission.\n\nSetting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use an API.\n\nThis policy can be overridden for specific URL patterns using the \"ClipboardAllowedForUrls\" and \"ClipboardBlockedForUrls\" policies.\n\nThis policy only affects clipboard operations controlled by the clipboard site permission and doesn't affect sanitized clipboard writes or trusted copy and paste operations.\n\nPolicy options mapping:\n\n* BlockClipboard (2) = Do not allow any site to use the clipboard site permission\n\n* AskClipboard (3) = Allow sites to ask the user to grant the clipboard site permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultclipboardsetting_blockclipboard","displayName":"Do not allow any site to use the clipboard site permission","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultclipboardsetting_askclipboard","displayName":"Allow sites to ask the user to grant the clipboard site permission","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultcookiessetting","displayName":"Configure cookies","description":"Control whether websites can create cookies on the user's device. This policy is all or nothing - you can let all websites create cookies, or no websites create cookies. You can't use this policy to enable cookies from specific websites.\n\nSet the policy to 'SessionOnly' to clear cookies when the session closes.\n\nIf you don't configure this policy, the default 'AllowCookies' is used, and users can change this setting in Microsoft Edge Settings. (If you don't want users to be able to change this setting, set the policy.)\n\nPolicy options mapping:\n\n* AllowCookies (1) = Let all sites create cookies\n\n* BlockCookies (2) = Don't let any site create cookies\n\n* SessionOnly (4) = Keep cookies for the duration of the session, except ones listed in \"SaveCookiesOnExit\"\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultcookiessetting_allowcookies","displayName":"Let all sites create cookies","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultcookiessetting_blockcookies","displayName":"Don't let any site create cookies","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultcookiessetting_sessiononly","displayName":"Keep cookies for the duration of the session, except ones listed in \"SaveCookiesOnExit\"","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultdownloaddirectory_recommended","displayName":"Set default download directory (users can override)","description":"This policy sets the default directory that Microsoft Edge uses to download files. Users can change the directory through browser settings.\n\nIf you don't configure this policy, Microsoft Edge uses the platform-specific default download directory.\n\nThis policy has no effect if the DownloadDirectory policy is set.\n\nFor a list of supported variables, see https://learn.microsoft.com/en-us/deployedge/edge-learnmore-create-user-directory-vars .","helpText":null,"infoUrls":[],"categoryId":"5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","categoryName":"Downloads","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading","description":"If you set this policy to 3, websites can ask for read access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\n\nIf you don't set this policy, websites can ask for access. Users can change this setting.\n\nPolicy options mapping:\n\n* BlockFileSystemRead (2) = Don't allow any site to request read access to files and directories via the File System API\n\n* AskFileSystemRead (3) = Allow sites to ask the user to grant read access to files and directories via the File System API\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemreadguardsetting_blockfilesystemread","displayName":"Don't allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemreadguardsetting_askfilesystemread","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing","description":"If you set this policy to 3, websites can ask for write access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\n\nIf you don't set this policy, websites can ask for access. Users can change this setting.\n\nPolicy options mapping:\n\n* BlockFileSystemWrite (2) = Don't allow any site to request write access to files and directories\n\n* AskFileSystemWrite (3) = Allow sites to ask the user to grant write access to files and directories\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemwriteguardsetting_blockfilesystemwrite","displayName":"Don't allow any site to request write access to files and directories","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemwriteguardsetting_askfilesystemwrite","displayName":"Allow sites to ask the user to grant write access to files and directories","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultgeolocationsetting","displayName":"Default geolocation setting","description":"Set whether websites can track users' physical locations. You can allow tracking by default ('AllowGeolocation'), deny it by default ('BlockGeolocation'), or ask the user each time a website requests their location ('AskGeolocation').\n\nIf you don't configure this policy, 'AskGeolocation' is used and the user can change it.\n\nPolicy options mapping:\n\n* AllowGeolocation (1) = Allow sites to track users' physical location\n\n* BlockGeolocation (2) = Don't allow any site to track users' physical location\n\n* AskGeolocation (3) = Ask whenever a site wants to track users' physical location\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultgeolocationsetting_allowgeolocation","displayName":"Allow sites to track users' physical location","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultgeolocationsetting_blockgeolocation","displayName":"Don't allow any site to track users' physical location","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultgeolocationsetting_askgeolocation","displayName":"Ask whenever a site wants to track users' physical location","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting","displayName":"Default idle detection setting","description":"Setting this policy to 1 - AllowIdleDetection allows websites to use the Idle Detection API without requesting user permission.\n\nSetting this policy to 2 - BlockIdleDetection prevents websites from using the Idle Detection API.\n\nSetting this policy to 3 - AskIdleDetection requires websites to request user permission each time before using the Idle Detection API.\n\nIf you do not configure this policy, users can decide whether to allow the Idle Detection API and can change this setting themselves.\n\nPolicy options mapping:\n\n* AllowIdleDetection (1) = Allow sites to detect idle state without asking the user\n\n* BlockIdleDetection (2) = Do not allow any site to detect the user's idle state\n\n* AskIdleDetection (3) = Ask every time a site wants to detect the user's idle state\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting_allowidledetection","displayName":"Allow sites to detect idle state without asking the user","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting_blockidledetection","displayName":"Do not allow any site to detect the user's idle state","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting_askidledetection","displayName":"Ask every time a site wants to detect the user's idle state","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultimagessetting","displayName":"Default images setting","description":"Set whether websites can display images. You can allow images on all sites ('AllowImages') or block them on all sites ('BlockImages').\n\nIf you don't configure this policy, images are allowed by default, and the user can change this setting.\n\nPolicy options mapping:\n\n* AllowImages (1) = Allow all sites to show all images\n\n* BlockImages (2) = Don't allow any site to show images\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultimagessetting_allowimages","displayName":"Allow all sites to show all images","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultimagessetting_blockimages","displayName":"Don't allow any site to show images","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions","description":"Allows you to set whether users can add exceptions to allow mixed content for specific sites.\n\nThis policy can be overridden for specific URL patterns using the \"InsecureContentAllowedForUrls\" and \"InsecureContentBlockedForUrls\" policies.\n\nIf this policy isn't set, users are allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.\n\nPolicy options mapping:\n\n* BlockInsecureContent (2) = Don't allow any site to load mixed content\n\n* AllowExceptionsInsecureContent (3) = Allow users to add exceptions to allow mixed content\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultinsecurecontentsetting_blockinsecurecontent","displayName":"Don't allow any site to load mixed content","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultinsecurecontentsetting_allowexceptionsinsecurecontent","displayName":"Allow users to add exceptions to allow mixed content","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT","description":"Allows you to set whether Microsoft Edge runs the v8 JavaScript engine with JIT (Just In Time) compiler enabled or not.\n\nDisabling the JavaScript JIT means that Microsoft Edge can render web content more slowly, and can also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT can allow Microsoft Edge to render web content in a more secure configuration.\n\nThis policy can be overridden for specific URL patterns using the \"JavaScriptJitAllowedForSites\" and \"JavaScriptJitBlockedForSites\" policies.\n\nIf you don't configure this policy, JavaScript JIT is enabled.\n\nPolicy options mapping:\n\n* AllowJavaScriptJit (1) = Allow any site to run JavaScript JIT\n\n* BlockJavaScriptJit (2) = Do not allow any site to run JavaScript JIT\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptjitsetting_allowjavascriptjit","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptjitsetting_blockjavascriptjit","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers","description":"Allows you to set whether Microsoft Edge will run the v8 JavaScript engine with more advanced JavaScript optimizations enabled.\n\nDisabling JavaScript optimizations (by setting this policy's value to 2) will mean that Microsoft Edge may render web content more slowly.\n\nThis policy can be overridden for specific URL patterns using the \"JavaScriptOptimizerAllowedForSites\" and \"JavaScriptOptimizerBlockedForSites\" policies.\n\nIf you don't configure this policy, JavaScript optimizations are enabled.\n\nPolicy options mapping:\n\n* AllowJavaScriptOptimizer (1) = Enable advanced JavaScript optimizations on all sites\n\n* BlockJavaScriptOptimizer (2) = Disable advanced JavaScript optimizations on all sites\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptoptimizersetting_allowjavascriptoptimizer","displayName":"Enable advanced JavaScript optimizations on all sites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptoptimizersetting_blockjavascriptoptimizer","displayName":"Disable advanced JavaScript optimizations on all sites","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptsetting","displayName":"Default JavaScript setting","description":"Set whether websites can run JavaScript. You can allow it for all sites ('AllowJavaScript') or block it for all sites ('BlockJavaScript').\n\nIf you don't configure this policy, all sites can run JavaScript by default, and the user can change this setting.\n\nPolicy options mapping:\n\n* AllowJavaScript (1) = Allow all sites to run JavaScript\n\n* BlockJavaScript (2) = Don't allow any site to run JavaScript\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptsetting_allowjavascript","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptsetting_blockjavascript","displayName":"Don't allow any site to run JavaScript","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultlocalfontssetting","displayName":"Default Local Fonts permission setting","description":"Setting this policy controls the default behavior for the local fonts permission.\n\nIf you set the policy to BlockLocalFonts (value 2), access to local fonts is denied by default. Sites are prevented from accessing information about local fonts.\n\nIf you set the policy to AskLocalFonts (value 3), users are prompted when a site requests access to local fonts. If permission is granted, the site can access information about local fonts.\n\nIf a site is included in \"LocalFontsAllowedForUrls\" or \"LocalFontsBlockedForUrls\", then that setting overrides the value set for this policy.\n\nIf you don't configure this policy, users are prompted by default and can change this setting.\n\nPolicy options mapping:\n\n* BlockLocalFonts (2) = Denies the Local Fonts permission on all sites by default\n\n* AskLocalFonts (3) = Ask every time a site wants to obtain the Local Fonts permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultlocalfontssetting_blocklocalfonts","displayName":"Denies the Local Fonts permission on all sites by default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultlocalfontssetting_asklocalfonts","displayName":"Ask every time a site wants to obtain the Local Fonts permission","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultnotificationssetting","displayName":"Default notification setting","description":"Set whether websites can display desktop notifications. You can allow them by default ('AllowNotifications'), deny them by default ('BlockNotifications'), or have the user be asked each time a website wants to show a notification ('AskNotifications').\n\nIf you don't configure this policy, notifications are allowed by default, and the user can change this setting.\n\nPolicy options mapping:\n\n* AllowNotifications (1) = Allow sites to show desktop notifications\n\n* BlockNotifications (2) = Don't allow any site to show desktop notifications\n\n* AskNotifications (3) = Ask every time a site wants to show desktop notifications\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultnotificationssetting_allownotifications","displayName":"Allow sites to show desktop notifications","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultnotificationssetting_blocknotifications","displayName":"Don't allow any site to show desktop notifications","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultnotificationssetting_asknotifications","displayName":"Ask every time a site wants to show desktop notifications","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpluginssetting","displayName":"Default Adobe Flash setting (Obsolete)","description":"This policy doesn't work because Flash is no longer supported by Microsoft Edge.\n\n\"PluginsAllowedForUrls\" and \"PluginsBlockedForUrls\" are checked first, then this policy. The options are 'ClickToPlay' and 'BlockPlugins'. If you set this policy to 'BlockPlugins', this plugin is denied for all websites. 'ClickToPlay' lets the Flash plugin run, but users click the placeholder to start it.\n\nIf you don't configure this policy, the user can change this setting manually.\n\nNote: Automatic playback is only for domains explicitly listed in the \"PluginsAllowedForUrls\" policy. To turn automatic playback on for all sites, add http://* and https://* to the allowed list of URLs.\n\nPolicy options mapping:\n\n* BlockPlugins (2) = Block the Adobe Flash plugin\n\n* ClickToPlay (3) = Click to play\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpluginssetting_blockplugins","displayName":"Block the Adobe Flash plugin","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpluginssetting_clicktoplay","displayName":"Click to play","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpopupssetting","displayName":"Default pop-up window setting","description":"Set whether websites can show pop-up windows. You can allow them on all websites ('AllowPopups') or block them on all sites ('BlockPopups').\n\nIf you don't configure this policy, pop-up windows are blocked by default, and users can change this setting.\n\nPolicy options mapping:\n\n* AllowPopups (1) = Allow all sites to show pop-ups\n\n* BlockPopups (2) = Do not allow any site to show popups\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpopupssetting_allowpopups","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpopupssetting_blockpopups","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultprinterselection","displayName":"Default printer selection rules","description":"Overrides Microsoft Edge default printer selection rules. This policy determines the rules for selecting the default printer in Microsoft Edge, which happens the first time a user tries to print a page.\n\nWhen this policy is set, Microsoft Edge tries to find a printer that matches all of the specified attributes and uses it as default printer. If there are multiple printers that meet the criteria, the first printer that matches is used.\n\nIf you don't configure this policy or no matching printers are found within the timeout, the printer defaults to the built-in PDF printer or no printer, if the PDF printer isn't available.\n\nThe value is parsed as a JSON object, conforming to the following schema: { \"type\": \"object\", \"properties\": { \"idPattern\": { \"description\": \"Regular expression to match printer id.\", \"type\": \"string\" }, \"namePattern\": { \"description\": \"Regular expression to match printer display name.\", \"type\": \"string\" } } }\n\nOmitting a field means all values match; for example, if you don't specify connectivity Print Preview starts discovering all kinds of local printers. Regular expression patterns must follow the JavaScript RegExp syntax and matches are case sensitive.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidercontextmenuaccessallowed","displayName":"Allow default search provider context menu search access","description":"Enables the use of a default search provider on the context menu.\n\nIf you disable this policy, the search context menu item that relies on your default search provider and sidebar search isn't available.\n\nIf you enable or don't configure this policy, the context menu item for your default search provider and sidebar search is available.\n\nThe policy value is only applied when the \"DefaultSearchProviderEnabled\" policy is enabled, and isn't applicable otherwise.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidercontextmenuaccessallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidercontextmenuaccessallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderenabled","displayName":"Enable the default search provider","description":"Enables the ability to use a default search provider.\n\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\n\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider.\n\nIf you disable this policy, the user can't search from the address bar.\n\nIf you enable or disable this policy, users can't change or override it.\n\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderenabled_recommended","displayName":"Enable the default search provider (users can override)","description":"Enables the ability to use a default search provider.\n\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\n\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider.\n\nIf you disable this policy, the user can't search from the address bar.\n\nIf you enable or disable this policy, users can't change or override it.\n\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderencodings","displayName":"Default search provider encodings","description":"Specify the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided.\n\nThis policy is optional. If not configured, the default, UTF-8, is used.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderencodings_recommended","displayName":"Default search provider encodings (users can override)","description":"Specify the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided.\n\nThis policy is optional. If not configured, the default, UTF-8, is used.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\n\nThis policy is optional. If you don't configure it, image search isn't available.\n\nSpecify Bing's Image Search URL as:\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\n\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\n\nSee \"DefaultSearchProviderImageURLPostParams\" policy to finish configuring image search.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderimageurl_recommended","displayName":"Specifies the search-by-image feature for the default search provider (users can override)","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\n\nThis policy is optional. If you don't configure it, image search isn't available.\n\nSpecify Bing's Image Search URL as:\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\n\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\n\nSee \"DefaultSearchProviderImageURLPostParams\" policy to finish configuring image search.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it's replaced with real image thumbnail data. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nSpecify Bing's Image Search URL Post Params as:\n'imageBin={google:imageThumbnailBase64}'.\n\nSpecify Google's Image Search URL Post Params as:\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\n\nIf you don't set this policy, image search requests are sent using the GET method.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderimageurlpostparams_recommended","displayName":"Parameters for an image URL that uses POST (users can override)","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it's replaced with real image thumbnail data. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nSpecify Bing's Image Search URL Post Params as:\n'imageBin={google:imageThumbnailBase64}'.\n\nSpecify Google's Image Search URL Post Params as:\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\n\nIf you don't set this policy, image search requests are sent using the GET method.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderkeyword","displayName":"Default search provider keyword","description":"Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider.\n\nThis policy is optional. If you don't configure it, no keyword activates the search provider.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderkeyword_recommended","displayName":"Default search provider keyword (users can override)","description":"Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider.\n\nThis policy is optional. If you don't configure it, no keyword activates the search provider.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidername","displayName":"Default search provider name","description":"Specifies the name of the default search provider.\n\nIf you enable this policy, you set the name of the default search provider.\n\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\n\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy isn't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidername_recommended","displayName":"Default search provider name (users can override)","description":"Specifies the name of the default search provider.\n\nIf you enable this policy, you set the name of the default search provider.\n\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\n\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy isn't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidersearchurl","displayName":"Default search provider search URL","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\n\nSpecify Bing's search URL as:\n\n'{bing:baseURL}search?q={searchTerms}'.\n\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\n\nThis policy is required when you enable the \"DefaultSearchProviderEnabled\" policy; if you don't enable the latter policy, this policy is ignored.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidersearchurl_recommended","displayName":"Default search provider search URL (users can override)","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\n\nSpecify Bing's search URL as:\n\n'{bing:baseURL}search?q={searchTerms}'.\n\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\n\nThis policy is required when you enable the \"DefaultSearchProviderEnabled\" policy; if you don't enable the latter policy, this policy is ignored.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions","description":"Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user entered so far.\n\nThis policy is optional. If you don't configure it, users can't see search suggestions; they see suggestions from their browsing history and favorites.\n\nBing's suggest URL can be specified as:\n\n'{bing:baseURL}qbox?query={searchTerms}'.\n\nGoogle's suggest URL can be specified as:\n\n'{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy isn't added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidersuggesturl_recommended","displayName":"Default search provider URL for suggestions (users can override)","description":"Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user entered so far.\n\nThis policy is optional. If you don't configure it, users can't see search suggestions; they see suggestions from their browsing history and favorites.\n\nBing's suggest URL can be specified as:\n\n'{bing:baseURL}qbox?query={searchTerms}'.\n\nGoogle's suggest URL can be specified as:\n\n'{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy isn't added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsensorssetting","displayName":"Default sensors setting","description":"Set whether websites can access and use sensors such as motion and light sensors. You can completely block or allow websites to get access to sensors.\n\nSetting the policy to 1 lets websites access and use sensors. Setting the policy to 2 denies access to sensors.\n\nYou can override this policy for specific URL patterns by using the \"SensorsAllowedForUrls\" and \"SensorsBlockedForUrls\" policies.\n\nIf you don't configure this policy, websites can access and use sensors, and users can change this setting. This setting is the global default for \"SensorsAllowedForUrls\" and \"SensorsBlockedForUrls\".\n\nPolicy options mapping:\n\n* AllowSensors (1) = Allow sites to access sensors\n\n* BlockSensors (2) = Do not allow any site to access sensors\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsensorssetting_allowsensors","displayName":"Allow sites to access sensors","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsensorssetting_blocksensors","displayName":"Do not allow any site to access sensors","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultserialguardsetting","displayName":"Control use of the Serial API","description":"Set whether websites can access serial ports. You can completely block access or ask the user each time a website wants to get access to a serial port.\n\nSetting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\n\nYou can override this policy for specific URL patterns by using the \"SerialAskForUrls\" and \"SerialBlockedForUrls\" policies.\n\nIf you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting.\n\nPolicy options mapping:\n\n* BlockSerial (2) = Do not allow any site to request access to serial ports via the Serial API\n\n* AskSerial (3) = Allow sites to ask for user permission to access a serial port\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultserialguardsetting_blockserial","displayName":"Do not allow any site to request access to serial ports via the Serial API","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultserialguardsetting_askserial","displayName":"Allow sites to ask for user permission to access a serial port","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting","displayName":"Set the default \"share additional operating system region\" setting","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\n\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting is shared with the web through the default JavaScript locale. If shared, websites can query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\n\nIf you set this policy to \"Limited\", the OS Regional format is shared only if its language part matches the Microsoft Edge display language.\n\nIf you set this policy to \"Always\", the OS Regional format is always shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months are displayed in one language while the surrounding text is displayed in another language.\n\nIf you set this policy to \"Never\", the OS Regional format is never shared.\n\nExample 1: In this example the OS Regional format is set to \"en-GB\", and the browser display language is set to \"en-US\". Then the OS Regional format is shared if the policy is set to \"Limited\", or \"Always\".\n\nExample 2: In this example the OS Regional format is set to \"es-MX\", and the browser display language is set to \"en-US\". Then the OS Regional format is shared if the policy is set to \"Always\"; however, the OS Regional format isn't shared if the policy is set to \"Limited\".\n\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282.\n\nPolicy options mapping:\n\n* Limited (0) = Limited\n\n* Always (1) = Always share the OS Regional format\n\n* Never (2) = Never share the OS Regional format\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_limited","displayName":"Limited","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_always","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_never","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended","displayName":"Set the default \"share additional operating system region\" setting (users can override)","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\n\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting is shared with the web through the default JavaScript locale. If shared, websites can query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\n\nIf you set this policy to \"Limited\", the OS Regional format is shared only if its language part matches the Microsoft Edge display language.\n\nIf you set this policy to \"Always\", the OS Regional format is always shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months are displayed in one language while the surrounding text is displayed in another language.\n\nIf you set this policy to \"Never\", the OS Regional format is never shared.\n\nExample 1: In this example the OS Regional format is set to \"en-GB\", and the browser display language is set to \"en-US\". Then the OS Regional format is shared if the policy is set to \"Limited\", or \"Always\".\n\nExample 2: In this example the OS Regional format is set to \"es-MX\", and the browser display language is set to \"en-US\". Then the OS Regional format is shared if the policy is set to \"Always\"; however, the OS Regional format isn't shared if the policy is set to \"Limited\".\n\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282.\n\nPolicy options mapping:\n\n* Limited (0) = Limited\n\n* Always (1) = Always share the OS Regional format\n\n* Never (2) = Never share the OS Regional format\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended_limited","displayName":"Limited","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended_always","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended_never","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultthirdpartystoragepartitioningsetting","displayName":"Default setting for third-party storage partitioning (Obsolete)","description":"This policy controls whether third-party storage partitioning is allowed by default.\n\nIf this policy is set to 1 - AllowPartitioning, or unset, third-party storage partitioning will be allowed by default. This default may be overridden for specific top-level origins by other means.\n\nIf this policy is set to 2 - BlockPartitioning, third-party storage partitioning will be disabled for all contexts.\n\nUse ThirdPartyStoragePartitioningBlockedForOrigins to disable third-party storage partitioning for specific top-level origins.\n\nThis feature has been removed starting in Microsoft Edge version 146. To ensure compatibility, use the requestStorageAccess method instead. For more information, see https://developer.mozilla.org/en-US/docs/Web/API/Document/requestStorageAccess.\n\nPolicy options mapping:\n\n* AllowPartitioning (1) = Allow third-party storage partitioning by default.\n\n* BlockPartitioning (2) = Disable third-party storage partitioning.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultthirdpartystoragepartitioningsetting_allowpartitioning","displayName":"Allow third-party storage partitioning by default.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultthirdpartystoragepartitioningsetting_blockpartitioning","displayName":"Disable third-party storage partitioning.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API","description":"Control whether websites can access nearby Bluetooth devices. You can completely block access or require the site to ask the user each time it wants to access a Bluetooth device.\n\nIf you don't configure this policy, the default value ('AskWebBluetooth', meaning users are asked each time) is used and users can change it.\n\nPolicy options mapping:\n\n* BlockWebBluetooth (2) = Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API\n\n* AskWebBluetooth (3) = Allow sites to ask the user to grant access to a nearby Bluetooth device\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebbluetoothguardsetting_blockwebbluetooth","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebbluetoothguardsetting_askwebbluetooth","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebhidguardsetting","displayName":"Control use of the WebHID API","description":"Setting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices.\n\nLeaving it unset lets websites ask for access, but users can change this setting.\n\nThis policy can be overridden for specific url patterns using the \"WebHidAskForUrls\" and \"WebHidBlockedForUrls\" policies.\n\nPolicy options mapping:\n\n* BlockWebHid (2) = Do not allow any site to request access to HID devices via the WebHID API\n\n* AskWebHid (3) = Allow sites to ask the user to grant access to a HID device\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebhidguardsetting_blockwebhid","displayName":"Do not allow any site to request access to HID devices via the WebHID API","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebhidguardsetting_askwebhid","displayName":"Allow sites to ask the user to grant access to a HID device","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebusbguardsetting","displayName":"Control use of the WebUSB API","description":"Set whether websites can access connected USB devices. You can completely block access or ask the user each time a website wants to get access to connected USB devices.\n\nYou can override this policy for specific URL patterns by using the \"WebUsbAskForUrls\" and \"WebUsbBlockedForUrls\" policies.\n\nIf you don't configure this policy, sites can ask users whether they can access the connected USB devices ('AskWebUsb') by default, and users can change this setting.\n\nPolicy options mapping:\n\n* BlockWebUsb (2) = Do not allow any site to request access to USB devices via the WebUSB API\n\n* AskWebUsb (3) = Allow sites to ask the user to grant access to a connected USB device\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebusbguardsetting_blockwebusb","displayName":"Do not allow any site to request access to USB devices via the WebUSB API","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebusbguardsetting_askwebusb","displayName":"Allow sites to ask the user to grant access to a connected USB device","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwindowmanagementsetting","displayName":"Default Window Management permission setting","description":"Setting the policy to \"BlockWindowManagement\" (value 2) automatically denies the window management permission to sites by default. This setting limits the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\n\nSetting the policy to \"AskWindowManagement\" (value 3) by default prompts the user when the window management permission is requested. If users allow the permission, it extends the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\n\nNot configuring the policy means the \"AskWindowManagement\" policy applies, but users can change this setting.\n\nPolicy options mapping:\n\n* BlockWindowManagement (2) = Denies the Window Management permission on all sites by default\n\n* AskWindowManagement (3) = Ask every time a site wants obtain the Window Management permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwindowmanagementsetting_blockwindowmanagement","displayName":"Denies the Window Management permission on all sites by default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwindowmanagementsetting_askwindowmanagement","displayName":"Ask every time a site wants obtain the Window Management permission","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.definepreferredlanguages","displayName":"Define an ordered list of preferred languages that websites should display in if the site supports the language","description":"Configures the language variants that Microsoft Edge sends to websites as part of the Accept-Language request HTTP header and prevents users from adding, removing, or changing the order of preferred languages in Microsoft Edge settings. Users who want to change the languages Microsoft Edge displays in or offers to translate pages to will be limited to the languages configured in this policy.\n\nIf you enable this policy, websites will appear in the first language in the list that they support unless other site-specific logic is used to determine the display language. The language variants defined in this policy override the languages configured as part of the \"SpellcheckLanguage\" policy.\n\nIf you don't configure or disable this policy, Microsoft Edge sends websites the user-specified preferred languages as part of the Accept-Language request HTTP header.\n\nFor detailed information on valid language variants, see https://go.microsoft.com/fwlink/?linkid=2148854.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.delaynavigationsforinitialsitelistdownload","displayName":"Require that the Enterprise Mode Site List is available before tab navigation","description":"Lets you specify whether Microsoft Edge tabs wait to navigate until the browser downloaded the initial Enterprise Mode Site List. This setting is intended for the scenario where the browser home page should load in Internet Explorer (IE) mode, and it's important that it does so on browser first run after IE mode is enabled. If this scenario doesn't exist, we recommend not enabling this setting because it negatively impacts the performance of loading the home page. The setting only applies when Microsoft Edge doesn't have a cached Enterprise Mode Site List, such as on browser first run after IE mode is enabled.\n\nThis setting works if \"InternetExplorerIntegrationLevel\" is set to 'IEMode' and if either the \"InternetExplorerIntegrationSiteList\" or the \"InternetExplorerIntegrationCloudSiteList\" policies be enabled, where the list has at least one entry.\n\nThe timeout behavior of this policy is configured with the \"NavigationDelayForInitialSiteListDownloadTimeout\" policy.\n\nIf you set this policy to 'All' and when Microsoft Edge doesn't have a cached version of the Enterprise Mode Site List, tabs delay navigating until the browser downloaded the site list. Sites configured to open in Internet Explorer mode by the site list load in Internet Explorer mode, even during the initial navigation of the browser. Sites that can't be configured to open in Internet Explorer, such as any site with a scheme other than http:, https:, file:, or ftp: don't delay navigating and load immediately in Microsoft Edge mode.\n\nWhen used with the \"InternetExplorerIntegrationCloudSiteList\" policy, during first launch of Microsoft Edge, there is a delay because implicit sign in needs to finish before Microsoft Edge attempts to download the site list from the Microsoft cloud since this requires authentication to the cloud service.\n\nIf you set this policy to 'None' or don't configure it and when Microsoft Edge doesn't have a cached version of the Enterprise Mode Site List, tabs navigate immediately and don't wait for the browser to download the Enterprise Mode Site List. Sites configured to open in Internet Explorer mode by the site list open in Microsoft Edge mode until the browser finished downloading the Enterprise Mode Site List.\n\nPolicy options mapping:\n\n* None (0) = None\n\n* All (1) = All eligible navigations\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.delaynavigationsforinitialsitelistdownload_none","displayName":"None","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.delaynavigationsforinitialsitelistdownload_all","displayName":"All eligible navigations","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values don't become decryptable on their own.\n\nIf fixing them is possible, it usually requires complex user actions.\n\nEnabling this policy or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state remain untouched.\n\nDisabling this policy means users will have their password manager data untouched but will experience a broken password manager functionality.\n\nIf the policy is set, users can't override it in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.deletingundecryptablepasswordsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.deletingundecryptablepasswordsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailability","displayName":"Control where developer tools can be used","description":"Controls whether users can access developer tools in Microsoft Edge.\n\nIf you set this policy to 'DeveloperToolsDisallowedForForceInstalledExtensions' (default), users can access developer tools and the JavaScript console, except in the context of extensions installed by enterprise policy.\n\nIf you set this policy to 'DeveloperToolsAllowed', users can access developer tools and the JavaScript console in all contexts, including extensions installed by enterprise policy.\n\nIf you set this policy to 'DeveloperToolsDisallowed', users cannot access developer tools or inspect website elements. Keyboard shortcuts, menu options, and context menu entries that open developer tools or the JavaScript console are disabled.\n\nAs of version 99, this policy also controls access to the 'View page source' feature. If you set this policy to 'DeveloperToolsDisallowed', users cannot view page source through keyboard shortcuts or the context menu. To fully block source viewing, add 'view-source:*' to the \"URLBlocklist\" policy.\n\nAs of version 119, this policy also controls whether developer mode for Isolated Web Apps can be enabled.\n\nAs of version 128, this policy does not control developer mode on the extensions page if the \"ExtensionDeveloperModeSettings\" policy is configured.\n\nDeveloper tools availability is determined in the following order of precedence:\n\n1. If a URL matches a pattern in \"DeveloperToolsAvailabilityAllowlist\", developer tools are allowed.\n2. If the allowlist is configured and the blocklist is not, URLs not on the allowlist are blocked.\n3. If a URL matches a pattern in \"DeveloperToolsAvailabilityBlocklist\", developer tools are blocked.\n4. If a URL is not covered by either list, this policy (\"DeveloperToolsAvailability\") applies.\n\nPolicy options mapping:\n\n* DeveloperToolsDisallowedForForceInstalledExtensions (0) = Block the developer tools on extensions installed by enterprise policy, allow in other contexts\n\n* DeveloperToolsAllowed (1) = Allow using the developer tools\n\n* DeveloperToolsDisallowed (2) = Don't allow using the developer tools\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailability_developertoolsdisallowedforforceinstalledextensions","displayName":"Block the developer tools on extensions installed by enterprise policy, allow in other contexts","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailability_developertoolsallowed","displayName":"Allow using the developer tools","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailability_developertoolsdisallowed","displayName":"Don't allow using the developer tools","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailabilityallowlist","displayName":"List of URL patterns for which developer tools are allowed to be opened","description":"This policy controls where developer tools can be used in Microsoft Edge by specifying an allowlist of URL patterns.\n\nURL patterns are matched against the URL of every frame on the page being inspected.\n\nIf you configure this policy and do not configure the \"DeveloperToolsAvailabilityBlocklist\" policy, developer tools are available only when every frame on the page matches a pattern in this allowlist. If any frame does not match, developer tools are blocked for the entire page. For information on the URL format, see https://go.microsoft.com/fwlink/?linkid=2095322 .\n\nIf you configure both this policy and the \"DeveloperToolsAvailabilityBlocklist\" policy, this allowlist takes precedence. URLs that match this allowlist are allowed even if they also match the blocklist. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither are governed by the \"DeveloperToolsAvailability\" policy.\n\nIf you disable or do not configure this policy, developer tools availability is determined by the \"DeveloperToolsAvailabilityBlocklist\" and \"DeveloperToolsAvailability\" policies.\n\nThis policy applies to developer tools opened for websites, extensions, and web applications.\n\nThis policy supports up to 1,000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailabilityblocklist","displayName":"List of URL patterns for which developer tools are blocked","description":"This policy specifies URL patterns where developer tools are blocked. For information on the URL format, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nURL patterns are evaluated against the URL of every frame on the page being inspected. If any frame matches a pattern in this policy, developer tools are blocked for the entire page.\n\nIf you configure this policy and do not configure the \"DeveloperToolsAvailabilityAllowlist\" policy, developer tools are blocked when any frame matches a pattern in this policy. If no frames match, availability is determined by the \"DeveloperToolsAvailability\" policy.\n\nIf you configure both this policy and the \"DeveloperToolsAvailabilityAllowlist\" policy, the allowlist takes precedence. URLs that match the allowlist are allowed, even if they also match this policy. URLs that match this policy (but not the allowlist) are blocked. If a URL matches neither, the \"DeveloperToolsAvailability\" policy determines availability.\n\nIf you disable or do not configure this policy, developer tools availability is determined by the \"DeveloperToolsAvailabilityAllowlist\" and \"DeveloperToolsAvailability\" policies.\n\nThis policy supports up to 1,000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.disable3dapis","displayName":"Disable support for 3D graphics APIs","description":"Prevent web pages from accessing the graphics processing unit (GPU). Specifically, web pages can't access the WebGL API and plug-ins can't use the Pepper 3D API.\n\nIf you don't configure or disable this policy, it potentially allows web pages to use the WebGL API and plug-ins to use the Pepper 3D API. Microsoft Edge might, by default, still require command line arguments to be passed in order to use these APIs.\n\nIf \"HardwareAccelerationModeEnabled\" policy is set to false, the setting for 'Disable3DAPIs' policy is ignored - it's the equivalent of setting 'Disable3DAPIs' policy to true.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.disable3dapis_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.disable3dapis_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.discoverpagecontextenabled","displayName":"Enable Discover access to page contents for AAD profiles (Obsolete)","description":"This policy is obsolete as of Microsoft Edge version 127. Two new Microsoft Edge Policies took its place. Those policies are CopilotPageContext (Control Copilot access to page contents for AAD profiles) and CopilotCDPPageContext (Control Copilot with Commercial Data Protection access to page contents for AAD profiles).\n\nThis policy didn't allow for separate control of Copilot and Copilot with Commercial Data Protection. The new policies allow separate control of these versions of Copilot. The new policies also allow admins to force-enable Copilot access to Microsoft Edge page contents by enabling the policy, whereas DiscoverPageContextEnabled only allows force-disabling of Copilot page access.\n\nThis policy controls Discover access to page contents for AAD profiles. Discover is an extension that hosts Bing Chat. To summarize pages and interact with text selections, it must access the page contents. When enabled, page contents are sent to Bing. This policy doesn't affect MSA profiles.\n\nIf you enable or don't configure this policy, Discover has access to page contents.\n\nIf you disable this policy, Discover can't access page contents.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.discoverpagecontextenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.discoverpagecontextenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.displaycapturepermissionspolicyenabled","displayName":"Specifies whether the display-capture permissions-policy is checked or skipped (Obsolete)","description":"This policy is obsolete. The policy was a temporary workaround for non-spec-compliant enterprise applications.\n\nThis policy stopped working in Microsoft Edge version 107 and was obsoleted in Microsoft Edge 110.\n\nThe display-capture permissions-policy gates access to getDisplayMedia(),\nas per this spec:\nhttps://www.w3.org/TR/screen-capture/#feature-policy-integration\nHowever, if this policy is Disabled, this requirement isn't enforced,\nand getDisplayMedia() is allowed from contexts that would otherwise be\nforbidden.\n\nIf you enable or don't configure this policy, sites can only call getDisplayMedia() from\ncontexts that are allowlisted by the display-capture permissions-policy.\n\nIf you disable this policy, sites can call getDisplayMedia() even from contexts\nwhich are not allowlisted by the display-capture permissions policy.\nOther restrictions may still apply.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.displaycapturepermissionspolicyenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.displaycapturepermissionspolicyenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.donotsilentlyblockprotocolsfromorigins","displayName":"Define a list of protocols that can not be silently blocked by anti-flood protection","description":"Allows you to create a list of protocols and an associated list of allowed origin patterns, for each protocol. These origins aren't silently blocked from launching an external application by anti-flood protection. The trailing separator shouldn't be included when listing the protocol. For example, list \"skype\" instead of \"skype:\" or \"skype://\".\n\nIf you configure this policy, a protocol is only permitted to bypass being silently blocked by anti-flood protection if:\n\n- the protocol is listed\n\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\n\nIf either condition is false, anti-flood protection protection blocks the external protocol launch.\n\nIf you don't configure this policy, no protocols can bypass being silently blocked.\n\nThe origin-matching patterns use a similar format to those patterns for the \"URLBlocklist\" policy, which are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\n\nHowever, origin-matching patterns for this policy can't contain \"/path\" or \"@query\" elements. Any pattern that contains a \"/path\" or \"@query\" element is ignored.\n\nThis policy doesn't work as expected with file://* wildcards.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.doubleclickclosetabenabled","displayName":"Double Click feature in Microsoft Edge enabled (only available in China)","description":"This policy lets you configure the double click feature in Microsoft Edge.\n\nDouble Click lets users close a tab by double clicking the left mouse button.\n\nIf you enable or don't configure this policy, you can use the double click feature to close a tab on Microsoft Edge to start using this feature.\n\nIf you disable this policy, you can't use the double click feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.doubleclickclosetabenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.doubleclickclosetabenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloaddirectory","displayName":"Set download directory","description":"Configures the directory to use when downloading files.\n\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user specified one or chose to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\n\nIf you disable or don't configure this policy, the default download directory is used, and the user can change it.\n\nIf you set an invalid path, Microsoft Edge defaults to the user's default download directory.\n\nIf the folder specified by the path doesn't exist, the download triggers a prompt that asks the user where they want to save their download.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloaddirectory_recommended","displayName":"Set download directory (users can override)","description":"Configures the directory to use when downloading files.\n\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user specified one or chose to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\n\nIf you disable or don't configure this policy, the default download directory is used, and the user can change it.\n\nIf you set an invalid path, Microsoft Edge defaults to the user's default download directory.\n\nIf the folder specified by the path doesn't exist, the download triggers a prompt that asks the user where they want to save their download.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions","displayName":"Allow download restrictions","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\n\nSet 'BlockDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known dangerous downloads or that have dangerous file type extensions.\n\nSet 'BlockPotentiallyDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous or unwanted downloads or that have dangerous file type extensions.\n\nSet 'BlockAllDownloads' to block all downloads.\n\nSet 'BlockMaliciousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known malicious downloads.\n\nIf you don't configure this policy or set the 'DefaultDownloadSecurity' option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\n\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\n\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\n\nPolicy options mapping:\n\n* DefaultDownloadSecurity (0) = No special restrictions\n\n* BlockDangerousDownloads (1) = Block malicious downloads and dangerous file types\n\n* BlockPotentiallyDangerousDownloads (2) = Block potentially dangerous or unwanted downloads and dangerous file types\n\n* BlockAllDownloads (3) = Block all downloads\n\n* BlockMaliciousDownloads (4) = Block malicious downloads\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_defaultdownloadsecurity","displayName":"No special restrictions","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_blockdangerousdownloads","displayName":"Block malicious downloads and dangerous file types","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_blockpotentiallydangerousdownloads","displayName":"Block potentially dangerous or unwanted downloads and dangerous file types","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_blockalldownloads","displayName":"Block all downloads","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_blockmaliciousdownloads","displayName":"Block malicious downloads","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_recommended","displayName":"Allow download restrictions (users can override)","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\n\nSet 'BlockDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known dangerous downloads or that have dangerous file type extensions.\n\nSet 'BlockPotentiallyDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous or unwanted downloads or that have dangerous file type extensions.\n\nSet 'BlockAllDownloads' to block all downloads.\n\nSet 'BlockMaliciousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known malicious downloads.\n\nIf you don't configure this policy or set the 'DefaultDownloadSecurity' option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\n\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\n\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\n\nPolicy options mapping:\n\n* DefaultDownloadSecurity (0) = No special restrictions\n\n* BlockDangerousDownloads (1) = Block malicious downloads and dangerous file types\n\n* BlockPotentiallyDangerousDownloads (2) = Block potentially dangerous or unwanted downloads and dangerous file types\n\n* BlockAllDownloads (3) = Block all downloads\n\n* BlockMaliciousDownloads (4) = Block malicious downloads\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_recommended_defaultdownloadsecurity","displayName":"No special restrictions","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_recommended_blockdangerousdownloads","displayName":"Block malicious downloads and dangerous file types","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_recommended_blockpotentiallydangerousdownloads","displayName":"Block potentially dangerous or unwanted downloads and dangerous file types","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_recommended_blockalldownloads","displayName":"Block all downloads","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_recommended_blockmaliciousdownloads","displayName":"Block malicious downloads","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled","displayName":"Allow features to download assets from the Asset Delivery Service","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\nThese assets can be config files or Machine Learning models that power the features that use this service.\n\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\n\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_recommended","displayName":"Allow features to download assets from the Asset Delivery Service (users can override)","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\nThese assets can be config files or Machine Learning models that power the features that use this service.\n\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\n\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeautofillmlenabled","displayName":"Machine learning powered autofill suggestions","description":"Allows ML technology to predict and fill in forms and text fields for better browsing. Your personal data is secure and isn't used elsewhere.\n\nIf you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data.\n\nIf you disable this policy, machine learning-powered autofill suggestions aren't shown, and autofill no longer uses cloud-based machine learning models to enhance form filling with smarter, context aware suggestions. Instead, autofill will rely on basic form data without the benefits of machine learning.\n\nThis policy will be disabled if you disable \"AutofillAddressEnabled\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeautofillmlenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeautofillmlenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeautofillmlenabled_recommended","displayName":"Machine learning powered autofill suggestions (users can override)","description":"Allows ML technology to predict and fill in forms and text fields for better browsing. Your personal data is secure and isn't used elsewhere.\n\nIf you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data.\n\nIf you disable this policy, machine learning-powered autofill suggestions aren't shown, and autofill no longer uses cloud-based machine learning models to enhance form filling with smarter, context aware suggestions. Instead, autofill will rely on basic form data without the benefits of machine learning.\n\nThis policy will be disabled if you disable \"AutofillAddressEnabled\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeautofillmlenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeautofillmlenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgecollectionsenabled","displayName":"Enable the Collections feature","description":"Lets you allow users to access the Collections feature, where they can collect, organize, share, and export content more efficiently and with Office integration.\n\nIf you enable or don't configure this policy, users can access and use the Collections feature in Microsoft Edge.\n\nIf you disable this policy, users can't access and use Collections in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgecollectionsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgecollectionsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled","displayName":"Discover feature In Microsoft Edge (Obsolete)","description":"This policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy.\n\nThis policy lets you configure the Discover feature in Microsoft Edge.\n\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\n\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\n\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_recommended","displayName":"Discover feature In Microsoft Edge (Obsolete) (users can override)","description":"This policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy.\n\nThis policy lets you configure the Discover feature in Microsoft Edge.\n\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\n\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\n\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeedropenabled","displayName":"Enable Drop feature in Microsoft Edge","description":"This policy lets you configure the Drop feature in Microsoft Edge.\n\nDrop lets users send messages or files to themselves.\n\nIf you enable or don't configure this policy, you can use the Drop feature in Microsoft Edge.\n\nIf you disable this policy, you can't use the Drop feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeedropenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeedropenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeenhanceimagesenabled","displayName":"Enhance images enabled (Obsolete)","description":"The enhance images feature is deprecated and starting in Microsoft Edge version 122, this policy will be removed. Set whether Microsoft Edge can automatically enhance images to show you sharper images with better color, lighting, and contrast.\n\nIf you enable this policy or don't configure the policy, Microsoft Edge automatically enhances images on specific web applications.\n\nIf you disable this policy, Microsoft Edge doesn't enhance images.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeenhanceimagesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeenhanceimagesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeentracopilotpagecontext","displayName":"Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane","description":"This policy controls whether Copilot in the Microsoft Edge side pane can access page content. This includes page summarization and other contextual queries.\n\nThis policy applies only to users who are signed in to Microsoft Edge with a Microsoft Entra account and are using Copilot in the side pane. It applies to Copilot experiences in the side pane, including Microsoft 365 Copilot Business Chat and Microsoft Copilot with enterprise data protection (EDP).\n\nIf you enable this policy, Copilot can access page content when users submit contextual queries in the side pane.\n\nIf you disable this policy, Copilot can't access page content. This also disables the M365LinksAutoOpenCopilotEnabled feature, because Copilot requires page content access to provide contextual insights for Microsoft 365 links.\n\nIf you don't configure this policy:\n- Access is enabled by default in non-EU regions.\n- Access is disabled by default in EU regions.\n- Users can turn this setting on or off in Microsoft Edge settings.\n\nCopilot can't access page content on pages protected by data loss prevention (DLP) policies, even if this policy is enabled.\n\nFor more information about Copilot data usage and consent, see https://go.microsoft.com/fwlink/?linkid=2288056","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeentracopilotpagecontext_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeentracopilotpagecontext_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgefollowenabled","displayName":"Enable Follow service in Microsoft Edge (Obsolete)","description":"Lets Microsoft Edge browser enable Follow service and apply it to users.\n\nUsers can use the Follow feature for an influencer, site, or topic in Microsoft Edge.\n\nIf you enable or don't configure this policy, Follow in Microsoft Edge is applied.\n\nIf you disable this policy, Microsoft Edge won't communicate with Follow service to provide the follow feature.\n\nThis policy is obsolete after version 126.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgefollowenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgefollowenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgehistoryaisearchenabled","displayName":"Control access to AI-enhanced search in History","description":"This policy controls whether users can use AI-enhanced search in their browsing history in Microsoft Edge.\n\nWhen enabled or not configured, users can search using synonyms, natural language phrases, and minor spelling errors to find previously visited pages.\n\nWhen disabled, users can only perform exact match (verbatim) searches in their history.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgehistoryaisearchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgehistoryaisearchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgemanagementextensionsfeedbackenabled","displayName":"Microsoft Edge management extensions feedback enabled","description":"This setting controls whether Microsoft Edge sends data about blocked extensions to the Microsoft Edge management service.\n\nThe 'EdgeManagementEnabled' policy must also be enabled for this setting to take effect.\n\nIf you enable this policy, Microsoft Edge sends data to the Microsoft Edge service when a user tries to install a blocked extension.\n\nIf you disable or don't configure this policy, Microsoft Edge can't send any data to the Microsoft Edge service about blocked extensions.","helpText":null,"infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgemanagementextensionsfeedbackenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgemanagementextensionsfeedbackenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesafehostingextensionenabled","displayName":"Control Microsoft Edge Safe Hosting Extension","description":"This policy controls whether the Microsoft Edge Safe Hosting component extension is installed automatically when users visit supported Microsoft services, such as Microsoft 365 Copilot app.\n\nThe Microsoft Edge Safe Hosting extension provides additional security capabilities for these services. When a user accesses a supported service, the extension installs automatically to enable those protections.\n\nIf you enable or don't configure this policy, the extension installs automatically and remains installed for 90 days after the user's last visit, then is removed if no further activity occurs.\n\nIf you disable this policy, the extension won't install automatically. If it’s already installed, it will be removed.\n\nNote: This policy controls only automatic installation. It doesn’t prevent users from manually installing other extensions from the Microsoft Edge Add-ons website.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesafehostingextensionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesafehostingextensionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeshoppingassistantenabled","displayName":"Shopping in Microsoft Edge Enabled","description":"This policy lets users compare the prices of a product they're looking at, get coupons or rebates from the website they're on, autoapply coupons, and help checkout faster using autofill data.\n\nIf you enable or don't configure this policy, shopping features such as price comparison, coupons, rebates, and express checkout are automatically applied for retail domains. Coupons for the current retailer and prices from other retailers are fetched from a server.\n\nIf you disable this policy, shopping features such as price comparison, coupons, rebates, and express checkout aren't automatically found for retail domains.\n\nStarting from version 90.0.818.56, the behavior of the messaging letting users know that there's a coupon, rebate, price comparison, or price history available on shopping domains is also done through a horizontal banner below the address bar. Previously, this messaging was done on the address bar.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeshoppingassistantenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeshoppingassistantenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeshoppingassistantenabled_recommended","displayName":"Shopping in Microsoft Edge Enabled (users can override)","description":"This policy lets users compare the prices of a product they're looking at, get coupons or rebates from the website they're on, autoapply coupons, and help checkout faster using autofill data.\n\nIf you enable or don't configure this policy, shopping features such as price comparison, coupons, rebates, and express checkout are automatically applied for retail domains. Coupons for the current retailer and prices from other retailers are fetched from a server.\n\nIf you disable this policy, shopping features such as price comparison, coupons, rebates, and express checkout aren't automatically found for retail domains.\n\nStarting from version 90.0.818.56, the behavior of the messaging letting users know that there's a coupon, rebate, price comparison, or price history available on shopping domains is also done through a horizontal banner below the address bar. Previously, this messaging was done on the address bar.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeshoppingassistantenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeshoppingassistantenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesidebarappurlhostallowlist","displayName":"Allow specific apps to be opened in Microsoft Edge sidebar","description":"Define a list of sites, based on URL patterns, that aren't subject to the \"EdgeSidebarAppUrlHostBlockList\".\n\nIf you don't configure this policy, a user can open any app in sidebar except the urls listed in \"EdgeSidebarAppUrlHostBlockList\".\n\nIf you configure this policy, the apps listed in the allow list could be opened in sidebar even if they are listed in the block list.\n\nBy default, all apps are allowed. However, if you prohibited apps by policy, you can use the list of allowed apps to change that policy.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesidebarappurlhostblocklist","displayName":"Control which apps cannot be opened in Microsoft Edge sidebar","description":"Define a list of sites, based on URL patterns, that cannot be opened in sidebar.\n\nIf you don't configure this policy, a user can open any app in sidebar.\n\nIf the \"HubsSidebarEnabled\" policy is disabled, this list isn't used and no sidebar can be opened.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\n\nNote: A blocklist value of '*' means all apps are blocked unless they are explicitly listed in the \"EdgeSidebarAppUrlHostAllowList\" policy.\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the sidebar.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\n\nIf you don't configure this policy, no app is forced to be shown in sidebar.\n\nIf the \"HubsSidebarEnabled\" policy is disabled, this list isn't used, and no sidebar can be shown.\n\nFor detailed information about valid URL, see https://go.microsoft.com/fwlink/?linkid=2281313.\n\nNote: URL patterns aren't supported in this policy. You should provide the exact URL of the app.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled","displayName":"Enable Wallet Checkout feature","description":"Enables Wallet Checkout feature in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can choose whether to use wallet checkout while shopping on Microsoft Edge.\n\nIf you disable this policy, users can't use wallet checkout while shopping on Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_recommended","displayName":"Enable Wallet Checkout feature (users can override)","description":"Enables Wallet Checkout feature in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can choose whether to use wallet checkout while shopping on Microsoft Edge.\n\nIf you disable this policy, users can't use wallet checkout while shopping on Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled","displayName":"Edge Wallet E-Tree Enabled (Deprecated)","description":"This policy is deprecated because the E-Tree feature has been removed from Microsoft Edge.\n\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\n\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_recommended","displayName":"Edge Wallet E-Tree Enabled (Deprecated) (users can override)","description":"This policy is deprecated because the E-Tree feature has been removed from Microsoft Edge.\n\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\n\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeworkspacesenabled","displayName":"Enable Workspaces","description":"Microsoft Edge Workspaces helps improve productivity for users in your organization.\n\nIf you enable or don't configure this policy, users can access the Microsoft Edge Workspaces feature.\nIf you disable this policy, users won't be able to access the Microsoft Edge Workspaces feature.\n\nTo learn more about the feature, see https://go.microsoft.com/fwlink/?linkid=2209950","helpText":null,"infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeworkspacesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeworkspacesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.editfavoritesenabled","displayName":"Allows users to edit favorites","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\n\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.editfavoritesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.editfavoritesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.editprofileenabled","displayName":"Enable editing profile in settings","description":"This policy controls whether users can modify profile properties (such as profile avatar) from the profile settings page.\n\nIf you enable or don't configure this policy, users can edit profile properties. The edit button is available on the profile settings page.\n\nIf you disable this policy, users can't edit profile properties. The edit button is disabled on the profile settings page.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.editprofileenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.editprofileenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enabledeprecatedwebplatformfeatures","displayName":"Re-enable deprecated web platform features for a limited time (Obsolete)","description":"This policy is obsolete because dedicated web platform policies are now used to manage individual web platform feature deprecations.\n\nSpecify a list of deprecated web platform features to temporarily re-enable.\n\nThis policy lets you re-enable deprecated web platform features for a limited time. Features are identified by a string tag.\n\nIf you don't configure this policy, if the list is empty, or if a feature doesn't match one of the supported string tags, all deprecated web platform features remain disabled.\n\nWhile the policy itself is supported on the above platforms, the feature it's enabling might not be available on all of those platforms. Not all deprecated Web Platform features can be re-enabled. Only the following explicitly listed features can be re-enabled, and only for a limited period of time, which differs per feature. You can review the intent behind the Web Platform feature changes at https://bit.ly/blinkintents.\n\nThe general format of the string tag is [DeprecatedFeatureName]_EffectiveUntil[yyyymmdd].\n\nPolicy options mapping:\n\n* ExampleDeprecatedFeature (ExampleDeprecatedFeature_EffectiveUntil20080902) = Enable ExampleDeprecatedFeature API through 2008/09/02\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":{"id":"com.microsoft.edge.mamedgeappconfigsettings.enabledeprecatedwebplatformfeatures_exampledeprecatedfeature","displayName":"Enable ExampleDeprecatedFeature API through 2008/09/02","description":null,"helpText":null}},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enablemediarouter","displayName":"Enable Google Cast","description":"Enable this policy to enable Google Cast. Users can launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.\n\nDisable this policy to disable Google Cast.\n\nBy default, Google Cast is enabled.","helpText":null,"infoUrls":[],"categoryId":"fddc444c-3591-4a50-865b-d8993b798e12","categoryName":"Cast","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enablemediarouter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enablemediarouter_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge","description":"This policy lets you enhance the security state in Microsoft Edge.\n\nIf you set this policy to 'StandardMode', the enhanced mode is turned off, and Microsoft Edge falls back to its standard security mode.\n\nIf you set this policy to 'BalancedMode', the security state is in balanced mode.\n\nIf you set this policy to 'StrictMode', the security state is in strict mode.\n\nIf you set this policy to 'BasicMode', the security state is in basic mode.\n\nNote: Sites that use WebAssembly (WASM) aren't supported on 32-bit systems when \"EnhanceSecurityMode\" is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\n\nStarting from Microsoft Edge version 113, 'BasicMode' is deprecated and is treated the same as 'BalancedMode'. It doesn't work in Microsoft Edge version 116.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.\n\nPolicy options mapping:\n\n* StandardMode (0) = Standard mode\n\n* BalancedMode (1) = Balanced mode\n\n* StrictMode (2) = Strict mode\n\n* BasicMode (3) = (Deprecated) Basic mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_standardmode","displayName":"Standard mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_balancedmode","displayName":"Balanced mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_strictmode","displayName":"Strict mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_basicmode","displayName":"(Deprecated) Basic mode","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeallowuserbypass","displayName":"Allow users to bypass Enhanced Security Mode","description":"Microsoft Edge lets users bypass Enhanced Security Mode on a site via Settings page or PageInfo flyout. This policy lets you configure whether users can bypass Enhanced Security Mode.\n\nIf you disable this policy, Microsoft Edge can't allow users to bypass Enhanced Security Mode.\n\nIf you enable or don't configure this policy, Microsoft Edge allows users to bypass Enhanced Security Mode.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeallowuserbypass_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeallowuserbypass_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypassintranet","displayName":"Enhanced Security Mode configuration for Intranet zone sites","description":"Microsoft Edge applies Enhanced Security Mode on Intranet zone sites by default. This can lead to Intranet zone sites acting in an unexpected manner.\n\nIf you enable this policy, Microsoft Edge can't apply Enhanced Security Mode on Intranet zone sites.\n\nIf you disable or don't configure this policy, Microsoft Edge applies Enhanced Security Mode on Intranet zone sites.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypassintranet_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypassintranet_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypasslistdomains","displayName":"Configure the list of domains for which enhance security mode will not be enforced","description":"Configures the list of enhance security trusted domains. This means that enhance security mode isn't enforced when loading the sites in trusted domains.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeenforcelistdomains","displayName":"Configure the list of domains for which enhance security mode will always be enforced","description":"Configure the list of enhance security untrusted domains. This means that\nenhance security mode is always enforced when loading the sites in untrusted domains.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeindicatoruienabled","displayName":"Manage the indicator UI of the Enhanced Security Mode (ESM) feature in Microsoft Edge","description":"This policy manages whether the indicator User Interface (UI) for enhanced security mode is shown or not when ESM is on.\n\nIf you enable or don't configure this policy, the indicator UI is on.\n\nIf you disable this policy, the indicator UI is off.\n\nNote: If this policy is used, only the indicator User Interface experience is supressed - ESM is still turned on. For more information, see the \"EnhanceSecurityMode\" policy.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeindicatoruienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeindicatoruienabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeoptoutuxenabled","displayName":"Manage opt-out user experience for Enhanced Security Mode (ESM) in Microsoft Edge (Obsolete)","description":"This policy is obsolete because we determined that this experimental opt-out UX isn't required.\n\nThis policy lets you manage whether the opt-out user experience for enhanced security mode is presented when ESM is turned on for Microsoft Edge.\n\nIf you enable or don't configure this policy, the UI for the opt-out user experience is on.\n\nIf you disable this policy, the UI for the opt-out user experience is off.\n\nNote: If this policy is used, only the User Interface for the opt-out experience is supressed - ESM is still turned on. For more information, see the \"EnhanceSecurityMode\" policy.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeoptoutuxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeoptoutuxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisehardwareplatformapienabled","displayName":"Allow managed extensions to use the Enterprise Hardware Platform API","description":"When this policy is set to enabled, extensions installed by enterprise policy are allowed to use the Enterprise Hardware Platform API.\nWhen this policy is set to disabled or isn't set, no extensions are allowed to use the Enterprise Hardware Platform API.\nThis policy also applies to component extensions.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisehardwareplatformapienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisehardwareplatformapienabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisemodesitelistmanagerallowed","displayName":"Allow access to the Enterprise Mode Site List Manager tool","description":"Allows you to set whether Enterprise Mode Site List Manager is available to users.\n\nIf you enable this policy, users can see the Enterprise Mode Site List Manager nav button on edge://compat page, navigate to the tool, and use it.\n\nIf you disable or don't configure this policy, users can't see the Enterprise Mode Site List Manager nav button and can't use it.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisemodesitelistmanagerallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisemodesitelistmanagerallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.eventpathenabled","displayName":"Re-enable the Event.path API until Microsoft Edge version 115 (Obsolete)","description":"Starting in Microsoft Edge version 109, the nonstandard API Event.path is removed to improve web compatibility. This policy re-enables the API until version 115.\n\nIf you enable this policy, the Event.path API is available.\n\nIf you disable this policy, the Event.path API is unavailable.\n\nIf you don't configure this policy, the Event.path API is in the following default states: available before version 109, and unavailable in version 109 to version 114.\n\nThis policy is made obsolete after Microsoft Edge version 115.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.eventpathenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.eventpathenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (Obsolete)","description":"This policy is obsoleted in favor of \"ExemptFileTypeDownloadWarnings\" because of a type mismatch that caused errors in Mac.\n\nYou can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that are exempted from file type extension-based download warnings. This exemption lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users don't see a warning when downloading \"jnlp\" files from \"website1.com\" but see a download warning when downloading \"jnlp\" files from \"website2.com\".\n\nFiles with file type extensions specified for domains identified by this policy are still subject to nonfile type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\n\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings show warnings to the user.\n\nIf you enable this policy:\n\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n* The file type extension entered must be in lower-cased ASCII. The leading separator shouldn't be included when listing the file type extension; so, list \"jnlp\" should be used instead of \".jnlp\".\n\nExample:\n\nThe following example value prevents file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It shows the user a file type extension-based download warning on any other domain for exe and jnlp files but not for swf files.\n\n[\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\n]\n\nWhile the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension isn't recommended due to security concerns. It's shown in the example merely to demonstrate the ability to do so.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.exemptfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that are exempted from file type extension-based download warnings. This exemption lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users can't see a warning when downloading \"jnlp\" files from \"website1.com\" but can see a download warning when downloading \"jnlp\" files from \"website2.com\".\n\nFiles with file type extensions specified for domains identified by this policy are still subject to nonfile type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\n\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings show warnings to the user.\n\nIf you enable this policy:\n\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n* The file type extension entered must be in lower-cased ASCII. The leading separator shouldn't be included when listing the file type extension; so, list \"jnlp\" should be used instead of \".jnlp\".\n\nExample:\n\nThe following example value prevents file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It shows the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\n\n[\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\n]\n\nWhile the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension isn't recommended due to security concerns. It's shown in the example merely to demonstrate the ability to do so.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.exemptsmartscreendownloadwarnings","displayName":"Disable SmartScreen AppRep based warnings for specified file types on specified domains","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that are exempted from SmartScreen AppRep warnings. For example, if the `vbe` extension is associated with \"contoso.com,\" users can't see a SmartScreen AppRep warning when downloading `vbe` files from \"contoso.com.\" They can, however, see a download warning when downloading `vbe` files from \"fabrikam.com.\"\n\nFiles with file type extensions specified for domains identified by this policy are still subject to file type extension-based security warnings and mixed-content download warnings.\n\nIf you disable this policy or don't configure it, files that trigger SmartScreen AppRep download warnings show warnings to the user.\n\nIf you enable this policy:\n\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n* The file type extension entered must be in lower-cased ASCII. The leading separator shouldn't be included when listing the file type extension; so, `vbe` should be used instead of `.vbe`.\n\nExample:\n\nThe following example prevents SmartScreen AppRep warnings on msi, exe, and vbe extensions for *.contoso.com domains. It might show the user a SmartScreen AppRep warning on any other domain for exe and msi files but not for vbe files.\n\n[\n { \"file_extension\": \"msi\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"vbe\", \"domains\": [\"*\"] }\n]\n\nNote: While the preceding example shows the suppression of SmartScreen AppRep download warnings for `vbe` files for all domains, applying suppression of such warnings for all domains isn't recommended due to security concerns. The ability to suppress warnings for all domains is shown in the example merely to demonstrate the ability to do so.","helpText":null,"infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes","displayName":"Configure allowed extension types","description":"Setting the policy controls which apps and extensions can be installed in Microsoft Edge, which hosts they can interact with, and limits runtime access.\n\nIf you don't set this policy, there aren't any restrictions on acceptable extension and app types.\n\nExtensions and apps, which have a type that's not on the list can't be installed. Each value should be one of these strings:\n\n* \"extension\"\n\n* \"theme\"\n\n* \"user_script\"\n\n* \"hosted_app\"\n\nSee the Microsoft Edge extensions documentation for more information about these types.\n\nNote: This policy also affects extensions and apps to be force-installed using \"ExtensionInstallForcelist\".\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.\n\nPolicy options mapping:\n\n* extension (extension) = Extension\n\n* theme (theme) = Theme\n\n* user_script (user_script) = User script\n\n* hosted_app (hosted_app) = Hosted app\n\n* legacy_packaged_app (legacy_packaged_app) = Legacy packaged app\n\n* platform_app (platform_app) = Platform app\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes_extension","displayName":"Extension","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes_theme","displayName":"Theme","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes_user_script","displayName":"User script","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes_hosted_app","displayName":"Hosted app","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes_legacy_packaged_app","displayName":"Legacy packaged app","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes_platform_app","displayName":"Platform app","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page","description":"Control if users can turn on Developer Mode on edge://extensions.\n\nIf the policy isn't set, users can turn on developer mode on the extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\nIf the policy is set to Allow (0), users can turn on developer mode on the extensions page.\nIf the policy is set to Disallow (1), users can't turn on developer mode on the extensions page.\n\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.\n\nPolicy options mapping:\n\n* Allow (0) = Allow the usage of developer mode on extensions page\n\n* Disallow (1) = Do not allow the usage of developer mode on extensions page\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensiondevelopermodesettings_allow","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensiondevelopermodesettings_disallow","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant an extended background lifetime to connecting extensions.","description":"Extensions that connect to one of these origins keep running as long as the port is connected.\nIf unset, the policy's default values are used. These are the app origins that offer software development kits (SDKs) that are known to not offer the possibility of restarting a closed connection to a previous state:\n- Smart Card Connector\n- Citrix Receiver (stable, beta, back-up)\n- VMware Horizon (stable, beta)\n\nIf set, the default value list is extended with the newly configured values. The defaults and policy-provided entries grant the exception to the connecting extensions as long as the port is connected.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallallowlist","displayName":"Allow specific extensions to be installed","description":"Setting this policy specifies which extensions aren't subject to the blocklist.\n\nA blocklist value of * means all extensions are blocked and users can only install extensions listed in the allow list.\n\nBy default, all extensions are allowed. However, if you prohibited extensions by policy, you can use the list of allowed extensions to change that policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallblocklist","displayName":"Control which extensions cannot be installed","description":"Lets you specify which extensions the users CANNOT install. Extensions already installed will be disabled if blocked, without a way for the user to enable them. After a disabled extension is removed from the blocklist it will automatically get re-enabled.\n\nA blocklist value of '*' means all extensions are blocked unless they are explicitly listed in the allowlist.\n\nIf this policy isn't set, the user can install any extension in Microsoft Edge.\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallforcelist","displayName":"Control which extensions are installed silently","description":"Set this policy to specify a list of apps and extensions that install silently, without user interaction. Users can't uninstall or turn off this setting. Permissions are granted implicitly, including the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. Note: These two APIs aren't available to apps and extensions that aren't force-installed.\n\nIf you don't set this policy, no apps or extensions are autoinstalled and users can uninstall any app in Microsoft Edge.\n\nThis policy supersedes \"ExtensionInstallBlocklist\" policy. If a previously force-installed app or extension is removed from this list, Microsoft Edge automatically uninstalls it.\n\nFor Windows instances not joined to a Microsoft Active Directory domain, forced installation is limited to apps and extensions listed in the Microsoft Edge Add-ons website.\n\nOn macOS instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be force installed if the instance is managed via MDM, or joined to a domain via MCX.\n\nThe source code of any extension can be altered by users with developer tools, potentially rendering the extension unfunctional. If there's a concern, configure the \"DeveloperToolsAvailability\" policy.\n\nEach list item of the policy is a string that contains an extension ID and, optionally, and an optional \"update\" URL separated by a semicolon (;). The extension ID is the 32-letter string found, for example, on edge://extensions when in Developer mode. If specified, the \"update\" URL should point to an Update Manifest XML document ( https://go.microsoft.com/fwlink/?linkid=2095043 ). The update URL should use one of the following schemes: http, https, or file. By default, the Microsoft Edge Add-ons website's update URL is used. The \"update\" URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL in the extension's manifest. The update url for subsequent updates can be overridden using the ExtensionSettings policy. See https://learn.microsoft.com/deployedge/microsoft-edge-manage-extensions-ref-guide.\n\nNote: This policy doesn't apply to InPrivate mode. Read about hosting extensions at [Publish and update extensions in the Microsoft Edge Add-ons website](/microsoft-edge/extensions-chromium/enterprise/hosting-and-updating).\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallsources","displayName":"Configure extension and user script install sources","description":"Define URLs that can install extensions and themes.\n\nDefine URLs that can install extensions and themes directly without having to drag and drop the packages to the edge://extensions page.\n\nEach item in this list is an extension-style match pattern (see https://go.microsoft.com/fwlink/?linkid=2095039). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (in other words, the referrer) must be allowed by these patterns. Don't host the files at a location that requires authentication.\n\nThe \"ExtensionInstallBlocklist\" policy takes precedence over this policy. Any extensions that's on the blocklist won't be installed, even if it comes from a site on this list.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstalltypeblocklist","displayName":"Blocklist for extension install types","description":"The blocklist controls which extension install types are disallowed.\n\nSetting the \"command_line\" will block an extension from being loaded from command line.\n\nPolicy options mapping:\n\n* command_line (command_line) = Blocks extensions from being loaded from command line\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstalltypeblocklist_command_line","displayName":"Blocks extensions from being loaded from command line","description":null,"helpText":null}},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability","description":"Control if Manifest v2 extensions can be used by browser.\n\nManifest v2 extensions support will be deprecated and all extensions need to be migrated to v3 in the future. More information about and the timeline of the migration hasn't been established.\n\nIf the policy is set to Default or not set, v2 extension loading is decided by browser. This follows the preceding timeline when it's established.\n\nIf the policy is set to Disable, v2 extensions installation are blocked, and existing ones are disabled. This option is going to be treated the same as if the policy is unset after v2 support is turned off by default.\n\nIf the policy is set to Enable, v2 extensions are allowed. The option is going to be treated the same as if the policy isn't set before v2 support is turned off by default.\n\nIf the policy is set to EnableForForcedExtensions, force installed v2 extensions are allowed. This includes extensions that are listed by \"ExtensionInstallForcelist\" or \"ExtensionSettings\" with installation_mode \"force_installed\" or \"normal_installed\". All other v2 extensions are disabled. The option is always available regardless of the manifest migration state.\n\nExtensions availabilities are still controlled by other policies.\n\nPolicy options mapping:\n\n* Default (0) = Default browser behavior\n\n* Disable (1) = Manifest v2 is disabled\n\n* Enable (2) = Manifest v2 is enabled\n\n* EnableForForcedExtensions (3) = Manifest v2 is enabled for forced extensions only\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_default","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_disable","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_enable","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_enableforforcedextensions","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsettings","displayName":"Configure extension management settings","description":"Setting this policy controls extension management settings for Microsoft Edge, including those configured by other extension-related policies. This policy supersedes any legacy policies.\n\nThis policy maps an extension ID or update URL to a specific configuration. You can define a default configuration using the special ID \"*\", which applies to extensions without a custom configuration.\n\nNote that any per-ID extension setting from either \"ExtensionInstallForcelist\", \"ExtensionInstallAllowlist\", \"ExtensionInstallBlocklist\", or \"ExtensionSettings\" will only inherit 'installation_mode' and 'update_url' from the \"*\" defaults. It will not inherit any other properties. With an update URL, configuration applies to extensions with the exact update URL stated in the extension manifest. If the 'override_update_url' flag is set to true, the extension is installed and updated using the update URL specified in the \"ExtensionInstallForcelist\" policy or in 'update_url' field in this policy. The flag 'override_update_url' is ignored if the 'update_url' is the Edge Add-ons website update URL. For more details, check out the detailed guide to ExtensionSettings policy available at https://go.microsoft.com/fwlink/?linkid=2161555.\n\nTo block extensions from a particular third party store, you only need to block the update_url for that store. For example, if you want to block extensions from Chrome Web Store, you can use the following JSON.\n\n{\"update_url:https://clients2.google.com/service/update2/crx\":{\"installation_mode\":\"blocked\"}}\n\nNote that you can still use \"ExtensionInstallForcelist\" and \"ExtensionInstallAllowlist\" to allow / force install specific extensions even if the store is blocked using the JSON in the previous example.\n\nIf the 'sidebar_auto_open_blocked' flag is set to true in an extension's configuration, the hub-app (sidebar app) corresponding to the specified extension will be prevented from automatically opening.\n\nOn Windows instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be forced installed if the instance is joined to a Microsoft Active Directory domain or joined to Microsoft Azure Active Directory®.\n\nOn macOS instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be force installed if the instance is managed via MDM, joined to a domain via MCX.\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsperformancedetectorenabled","displayName":"Extensions Performance Detector enabled","description":"This policy controls if users can access the Extensions Performance Detector Recommended Action feature in Browser Essentials. This feature alerts extension users if their extensions are causing performance regressions in the browser and allows them to take action to resolve the issue.\n\nIf you enable or don't configure this policy, users receive Extensions Performance Detector notifications from Browser Essentials. When there's an active alert, users are able to view the impact of extensions on their browser's performance and make an informed decision to disable impacting extensions. The detector will exclude browser-managed extensions, such as Google Docs offline, component extensions, and organization-managed extensions (that is, extensions that can't be disabled).\n\nIf you disable this policy, users won't receive notifications or be able to view the Extensions Performance Detector Recommended Action.","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsperformancedetectorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsperformancedetectorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsperformancedetectorenabled_recommended","displayName":"Extensions Performance Detector enabled (users can override)","description":"This policy controls if users can access the Extensions Performance Detector Recommended Action feature in Browser Essentials. This feature alerts extension users if their extensions are causing performance regressions in the browser and allows them to take action to resolve the issue.\n\nIf you enable or don't configure this policy, users receive Extensions Performance Detector notifications from Browser Essentials. When there's an active alert, users are able to view the impact of extensions on their browser's performance and make an informed decision to disable impacting extensions. The detector will exclude browser-managed extensions, such as Google Docs offline, component extensions, and organization-managed extensions (that is, extensions that can't be disabled).\n\nIf you disable this policy, users won't receive notifications or be able to view the Extensions Performance Detector Recommended Action.","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsperformancedetectorenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsperformancedetectorenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.externalprotocoldialogshowalwaysopencheckbox","displayName":"Show an \"Always open\" checkbox in external protocol dialog","description":"This policy controls whether the \"Always allow this site to open links of this type\" checkbox is shown on external protocol launch confirmation prompts. This policy only applies to https:// links.\n\nIf you enable this policy, when an external protocol confirmation prompt is shown, the user can select \"Always allow\" to skip all future confirmation prompts for the protocol on this site.\n\nIf you disable this policy, the \"Always allow\" checkbox isn't displayed. The user is prompted for confirmation every time an external protocol is invoked.\n\nPrior to Microsoft Edge 83, if you don't configure this policy, the \"Always allow\" checkbox isn't displayed. The user is prompted for confirmation every time an external protocol is invoked.\n\nOn Microsoft Edge 83, if you don't configure this policy, the checkbox visibility is controlled by the \"Enable remembering protocol launch prompting preferences\" flag in edge://flags\n\nAs of Microsoft Edge 84, if you don't configure this policy, when an external protocol confirmation prompt is shown, the user can select \"Always allow\" to skip all future confirmation prompts for the protocol on this site.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.externalprotocoldialogshowalwaysopencheckbox_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.externalprotocoldialogshowalwaysopencheckbox_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.familysafetysettingsenabled","displayName":"Allow users to configure Family safety and Kids Mode","description":"This policy disables two family safety-related features in the browser. This hides the Family page inside Settings, and navigation to edge://settings/family is blocked. The family settings page describes what features are available with family groups with Microsoft Family Safety. Learn more about Family Safety here: (https://go.microsoft.com/fwlink/?linkid=2098432). Starting in Microsoft Edge version 90, this policy also disables Kids Mode, a kid-friendly browsing mode with custom themes and allow list browsing that requires the device password to exit. Learn more about Kids Mode here: (https://go.microsoft.com/fwlink/?linkid=2146910)\n\nIf you enable this policy or don't configure it, the family page in Settings is shown and Kids Mode is available.\n\nIf you disable this policy, the family page isn't shown, and Kids Mode is hidden.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.familysafetysettingsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.familysafetysettingsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled","displayName":"Enable favorites bar","description":"Enables or disables the favorites bar.\n\nIf you enable this policy, users will see the favorites bar.\n\nIf you disable this policy, users won't see the favorites bar.\n\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_recommended","displayName":"Enable favorites bar (users can override)","description":"Enables or disables the favorites bar.\n\nIf you enable this policy, users will see the favorites bar.\n\nIf you disable this policy, users won't see the favorites bar.\n\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on shutdown","description":"Controls the duration (in seconds) that keepalive requests are allowed to prevent the browser from completing its shutdown.\n\nIf you configure this policy, the browser blocks completing shutdown while it processes any outstanding keepalive requests (see https://fetch.spec.whatwg.org/#request-keepalive-flag) up to the maximum period of time specified by this policy.\n\nIf you disable or don't configure this policy, the default value of 0 seconds is used, and the outstanding keepalive requests are immediately cancelled during browser shutdown.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.fileordirectorypickerwithoutgestureallowedfororigins","displayName":"Allow file or directory picker APIs to be called without prior user gesture","description":"For security reasons, the showOpenFilePicker(), showSaveFilePicker(), and showDirectoryPicker() web APIs require a prior user gesture (\"transient activation\") to be called; else, they fail.\n\nIf you enable this policy, admins can specify origins on which these APIs can be called without prior user gesture.\n\nFor detailed information on valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.\n\nIf you disable or don't configure this policy, all origins will require a prior user gesture to call these APIs.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.filesystemreadaskforurls","displayName":"Allow read access via the File System API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\n\nLeaving the policy unset means \"DefaultFileSystemReadGuardSetting\" applies for all sites, if set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemReadBlockedForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.filesystemreadblockedforurls","displayName":"Block read access via the File System API on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\n\nIf you don't set this policy, \"DefaultFileSystemReadGuardSetting\" applies for all sites, if set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemReadAskForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.filesystemwriteaskforurls","displayName":"Allow write access to files and directories on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system.\n\nIf you don't set this policy, \"DefaultFileSystemWriteGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemWriteBlockedForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.filesystemwriteblockedforurls","displayName":"Block write access to files and directories on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system.\n\nIf you don't set this policy, \"DefaultFileSystemWriteGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemWriteAskForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcebingsafesearch","displayName":"Enforce Bing SafeSearch","description":"Ensure that queries in Bing web search are done with SafeSearch set to the value specified. Users can't change this setting.\n\nIf you configure this policy to 'BingSafeSearchNoRestrictionsMode', SafeSearch in Bing search falls back to the bing.com value.\n\nIf you configure this policy to 'BingSafeSearchModerateMode', the moderate setting is used in SafeSearch. The moderate setting filters adult videos and images but not text from search results.\n\nIf you configure this policy to 'BingSafeSearchStrictMode', the strict setting in SafeSearch is used. The strict setting filters adult text, images, and videos.\n\nIf you disable this policy or don't configure it, SafeSearch in Bing search isn't enforced, and users can set the value they want on bing.com.\n\nPolicy options mapping:\n\n* BingSafeSearchNoRestrictionsMode (0) = Don't configure search restrictions in Bing\n\n* BingSafeSearchModerateMode (1) = Configure moderate search restrictions in Bing\n\n* BingSafeSearchStrictMode (2) = Configure strict search restrictions in Bing\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcebingsafesearch_bingsafesearchnorestrictionsmode","displayName":"Don't configure search restrictions in Bing","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcebingsafesearch_bingsafesearchmoderatemode","displayName":"Configure moderate search restrictions in Bing","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcebingsafesearch_bingsafesearchstrictmode","displayName":"Configure strict search restrictions in Bing","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceephemeralprofiles","displayName":"Enable use of ephemeral profiles","description":"Controls whether user profiles are switched to ephemeral mode. An ephemeral profile is created when a session begins, is deleted when the session ends, and is associated with the user's original profile.\n\nIf you enable this policy, profiles run in ephemeral mode. This setting lets users work from their own devices without saving browsing data to those devices. If you enable this policy as an OS policy (by using GPO on Windows, for example), it applies to every profile on the system.\n\nIf you disable this policy or don't configure it, users get their regular profiles when they sign in to the browser.\n\nIn ephemeral mode, profile data is saved on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies, and web databases aren't saved after the browser is closed. This setting doesn't prevent a user from manually downloading any data to disk, or from saving pages or printing them. If the user enabled sync, all data is preserved in their sync accounts just like with regular profiles. Users can also use InPrivate browsing in ephemeral mode unless you explicitly disable this setting.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceephemeralprofiles_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceephemeralprofiles_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceforegroundpriorityforurls","displayName":"Force foreground priority for specific URLs","description":"This policy allows you to specify a list of URL patterns for which background web content is forced to run at foreground priority.\n\nIf the ForceForegroundPriorityForAllTabs policy is enabled, this policy is ignored because all tabs are already forced to run at foreground priority.\n\nIf the ForceForegroundPriorityForAllTabs policy is disabled or not configured, only background content that matches the URL patterns in this list is forced to run at foreground priority.\n\nFor more information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nIf you don’t configure this policy or the list is empty, no background content is forced to run at foreground priority.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcegooglesafesearch","displayName":"Enforce Google SafeSearch","description":"Forces queries in Google Web Search to be performed with SafeSearch set to active, and prevents users from changing this setting.\n\nIf you enable this policy, SafeSearch in Google Search is always active.\n\nIf you disable this policy or don't configure it, SafeSearch in Google Search isn't enforced.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcegooglesafesearch_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcegooglesafesearch_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcemajorversiontominorpositioninuseragent","displayName":"Enable or disable freezing the User-Agent string at major version 99 (Obsolete)","description":"This policy was removed in Microsoft Edge 118 and is ignored if configured.\n\nThis policy controls whether the User-Agent string major\nversion should be frozen at 99.\n\nThe User-Agent request header lets websites identify the application,\noperating system, vendor, and/or version of the requesting user agent.\nSome websites make assumptions about how this header is formatted and may\nencounter issues with version strings that include three digits in the\nmajor position (for example, 100.0.0.0).\n\nIf you set this policy to 'Default' or don't configure it, then it defaults to\nbrowser settings for the User-Agent string major version.\nIf you set this policy to 'ForceEnabled', the User-Agent string will always report the\nmajor version as 99 and include the browser's major version in the minor\nposition. For example, browser version 101.0.0.0 would send a User-Agent\nrequest header that reports version 99.101.0.0.\nIf you set this policy to 'ForceDisabled', the User-Agent string won't freeze the\nmajor version.\n\nThis policy is temporary and will be deprecated in the future. If this policy and\nUser-Agent Reduction are\nboth enabled, the User-Agent version string will always be 99.0.0.0.\n\nPolicy options mapping:\n\n* Default (0) = Default to browser settings for User-Agent string version.\n\n* ForceDisabled (1) = The User-Agent string won't freeze the major version.\n\n* ForceEnabled (2) = The User-Agent string will freeze the major version as 99 and include the browser's major version in the minor position.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcemajorversiontominorpositioninuseragent_default","displayName":"Default to browser settings for User-Agent string version.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcemajorversiontominorpositioninuseragent_forcedisabled","displayName":"The User-Agent string won't freeze the major version.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcemajorversiontominorpositioninuseragent_forceenabled","displayName":"The User-Agent string will freeze the major version as 99 and include the browser's major version in the minor position.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcesync","displayName":"Force synchronization of browser data and do not show the sync consent prompt","description":"Forces data synchronization in Microsoft Edge. This policy also prevents the user from turning off sync.\n\nIf you don't configure this policy, users can turn on or turn off sync. If you enable this policy, users can't turn off sync.\n\nFor this policy to work as intended,\n\"BrowserSignin\" policy must not be configured, or must be set to enabled. If \"BrowserSignin\" is set to disabled, then \"ForceSync\" doesn't take affect.\n\n\"SyncDisabled\" must not be configured or must be set to False. If this policy is set to True, \"ForceSync\" doesn't take affect. If you wish to ensure specific datatypes sync or don't sync, use the \"ForceSyncTypes\" policy and \"SyncTypesListDisabled\" policy, respectively.\n\n0 = Do not automatically start sync and show the sync consent (default)\n1 = Force sync to turn on for Azure AD/Azure AD-Degraded user profile and do not show the sync consent prompt","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcesync_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcesync_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcesynctypes","displayName":"Configure the list of types that are included for synchronization","description":"If you enable this policy, all the specified data types are included for synchronization for Azure AD/Azure AD-Degraded user profiles. This policy can be used to ensure the type of data uploaded to the Microsoft Edge synchronization service.\n\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", \"history\", \"openTabs\", \"edgeWallet\", \"collections\", \"apps\", and \"edgeFeatureUsage\". The \"edgeFeatureUsage\" data type is supported starting in Microsoft Edge version 134. Note that these data type names are case sensitive.\n\nUsers can't override the enabled data types.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode","description":"Enforces a minimum Restricted Mode on YouTube and prevents users from picking a less restricted mode.\n\nSet to 'Strict' to enforce Strict Restricted Mode on YouTube.\n\nSet to 'Moderate' to enforce the user to only use Moderate Restricted Mode and Strict Restricted Mode on YouTube. They can't disable Restricted Mode.\n\nSet to 'Off' or don't configure this policy to not enforce Restricted Mode on YouTube. External policies such as YouTube policies might still enforce Restricted Mode.\n\nPolicy options mapping:\n\n* Off (0) = Do not enforce Restricted Mode on YouTube\n\n* Moderate (1) = Enforce at least Moderate Restricted Mode on YouTube\n\n* Strict (2) = Enforce Strict Restricted Mode for YouTube\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceyoutuberestrict_off","displayName":"Do not enforce Restricted Mode on YouTube","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceyoutuberestrict_moderate","displayName":"Enforce at least Moderate Restricted Mode on YouTube","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceyoutuberestrict_strict","displayName":"Enforce Strict Restricted Mode for YouTube","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.fullscreenallowed","displayName":"Allow full screen mode","description":"Set the availability of full screen mode - all Microsoft Edge UI is hidden and only web content is visible.\n\nIf you enable this policy or don't configure it, the user, apps, and extensions with appropriate permissions can enter full screen mode.\n\nIf you disable this policy, users, apps, and extensions can't enter full screen mode.\n\nOpening Microsoft Edge in kiosk mode using the command line is unavailable when full screen mode is disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.fullscreenallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.fullscreenallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled","displayName":"Enable Gamer Mode (Obsolete)","description":"Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more.\n\nIf you enable or don't configure this policy, users can opt into Gamer Mode.\nIf you disable this policy, Gamer Mode is disabled.\nNote: With Microsoft Edge version 141, this policy is obsolete because the Gamer Mode feature is removed.","helpText":null,"infoUrls":[],"categoryId":"81c518f1-522e-4957-b850-e8a66d2ab215","categoryName":"Games settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_recommended","displayName":"Enable Gamer Mode (Obsolete) (users can override)","description":"Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more.\n\nIf you enable or don't configure this policy, users can opt into Gamer Mode.\nIf you disable this policy, Gamer Mode is disabled.\nNote: With Microsoft Edge version 141, this policy is obsolete because the Gamer Mode feature is removed.","helpText":null,"infoUrls":[],"categoryId":"81c518f1-522e-4957-b850-e8a66d2ab215","categoryName":"Games settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.geolocationblockedforurls","displayName":"Block geolocation on these sites","description":"Use this policy to define a list of URL patterns for sites that are blocked from accessing the user's geolocation. These sites also can't prompt the user for location permissions.\n\nIf you enable this policy, the list you provide determines which sites are blocked from requesting or accessing geolocation.\n\nIf you disable or don't configure this policy, DefaultGeolocationSetting applies to all sites, if configured. If it's not configured, the user’s personal browser setting is used.\n\nFor detailed information on valid url patterns, see the documentation on pattern formats: https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\n\nIf you disable or don't set this policy, the browser uses the default behavior of cross-site auth. This behavior is to scope HTTP server authentication credentials by top-level site. So, if two sites use resources from the same authenticating domain, credentials need to be provided independently in the context of both sites. Cached proxy credentials are reused across sites.\n\nIf you enable this policy, HTTP auth credentials entered in the context of one site is automatically used in the context of another site.\n\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\n\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures and will be removed in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.globallyscopehttpauthcacheenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.globallyscopehttpauthcacheenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.guidedswitchenabled","displayName":"Guided Switch Enabled","description":"Allows Microsoft Edge to prompt the user to switch to the appropriate profile when Microsoft Edge detects that a link is a personal or work link.\n\nIf you enable this policy, you're prompted to switch to another account if the current profile doesn't work for the requesting link.\n\nIf you disable this policy, you aren't prompted to switch to another account when there's a profile and link mismatch.\n\nIf this policy isn't configured, guided switch is turned on by default. A user can override this value in the browser settings.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.guidedswitchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.guidedswitchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepageisnewtabpage","displayName":"Set the new tab page as the home page","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\n\nIf you enable this policy, the Home button is set to the new tab page as configured by the user or with the policy \"NewTabPageLocation\" and the URL set with the policy \"HomepageLocation\" is not taken into consideration.\n\nIf you disable this policy, the Home button is the set URL as configured by the user or as configured in the policy \"HomepageLocation\".\n\nIf you don't configure this policy, users can choose whether the set URL or the new tab page is their home page.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepageisnewtabpage_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepageisnewtabpage_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepageisnewtabpage_recommended","displayName":"Set the new tab page as the home page (users can override)","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\n\nIf you enable this policy, the Home button is set to the new tab page as configured by the user or with the policy \"NewTabPageLocation\" and the URL set with the policy \"HomepageLocation\" is not taken into consideration.\n\nIf you disable this policy, the Home button is the set URL as configured by the user or as configured in the policy \"HomepageLocation\".\n\nIf you don't configure this policy, users can choose whether the set URL or the new tab page is their home page.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepageisnewtabpage_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepageisnewtabpage_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepagelocation","displayName":"Configure the home page URL","description":"Configures the default home page URL in Microsoft Edge.\n\nThe home page is the page opened by the Home button. \"RestoreOnStartup\" policies control the pages that open on startup.\n\nYou can either set a URL here or set the home page to open the new tab page 'edge://newtab'. By default, the Home button opens the new tab page (as configured by the user or with the policy \"NewTabPageLocation\"), and the user is able to choose between the URL configured by this policy and the new tab page.\n\nIf you enable this policy, users can't change their home page URL, but they can choose the behavior for the Home button to open either the set URL or the new tab page. If you wish to enforce the usage of the set URL, you must also configure \"HomepageIsNewTabPage\"=Disabled.\n\nIf you disable or don't configure this policy, users can choose their own home page, as long as the \"HomepageIsNewTabPage\" policy isn't enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepagelocation_recommended","displayName":"Configure the home page URL (users can override)","description":"Configures the default home page URL in Microsoft Edge.\n\nThe home page is the page opened by the Home button. \"RestoreOnStartup\" policies control the pages that open on startup.\n\nYou can either set a URL here or set the home page to open the new tab page 'edge://newtab'. By default, the Home button opens the new tab page (as configured by the user or with the policy \"NewTabPageLocation\"), and the user is able to choose between the URL configured by this policy and the new tab page.\n\nIf you enable this policy, users can't change their home page URL, but they can choose the behavior for the Home button to open either the set URL or the new tab page. If you wish to enforce the usage of the set URL, you must also configure \"HomepageIsNewTabPage\"=Disabled.\n\nIf you disable or don't configure this policy, users can choose their own home page, as long as the \"HomepageIsNewTabPage\" policy isn't enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.hstspolicybypasslist","displayName":"Configure the list of names that will bypass the HSTS policy check","description":"Setting the policy specifies a list of hostnames that bypass preloaded HSTS (HTTP Strict Transport Security) upgrades from http to https.\n\nOnly single-label hostnames are allowed in this policy, and this policy only applies to static HSTS-preloaded entries (for example, \"app\", \"new\", \"search\", and \"play\"). This policy doesn't prevent HSTS upgrades for servers that have dynamically requested HSTS upgrades using a Strict-Transport-Security response header.\n\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific single-label hostnames specified and not to subdomains of those names.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpallowlist","displayName":"HTTP Allowlist","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that won't be upgraded to HTTPS. Organizations can use this policy to maintain access to servers that don't support HTTPS, without needing to disable \"HttpsUpgradesEnabled\".\n\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase.\n\nBlanket host wildcards (that is, \"*\" or \"[*]\") aren't allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies.\n\nNote: This policy doesn't apply to HSTS upgrades.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled","description":"This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigation to HTTPS.\n\nIf this setting isn't set or is set to Allowed, users are able to enable HTTPS-Only Mode.\nIf this setting is set to Disallowed, HTTPS-Only Mode will be disabled.\nIf this setting is set to Force Enabled, HTTPS-Only Mode is enabled in Strict mode.\nIf this setting is set to Force Balance Enabled, HTTPS-Only Mode is enabled in Balanced mode.\n\nThe settings Force Enabled and Force Enabled can be recommended to users. HTTPS-Only Mode will be set to Strict or Balanced initially, but users are allowed to change it.\n\nIf you set this policy to a value that isn't supported by the version of Microsoft Edge that receives the policy, Microsoft Edge defaults to the Allowed setting.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nPolicy options mapping:\n\n* allowed (allowed) = Don't restrict users' HTTPS-Only Mode setting\n\n* disallowed (disallowed) = Disable HTTPS-Only Mode\n\n* force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode\n\n* force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_allowed","displayName":"Don't restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_disallowed","displayName":"Disable HTTPS-Only Mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_force_enabled","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_force_balanced_enabled","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended","displayName":"Allow HTTPS-Only Mode to be enabled (users can override)","description":"This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigation to HTTPS.\n\nIf this setting isn't set or is set to Allowed, users are able to enable HTTPS-Only Mode.\nIf this setting is set to Disallowed, HTTPS-Only Mode will be disabled.\nIf this setting is set to Force Enabled, HTTPS-Only Mode is enabled in Strict mode.\nIf this setting is set to Force Balance Enabled, HTTPS-Only Mode is enabled in Balanced mode.\n\nThe settings Force Enabled and Force Enabled can be recommended to users. HTTPS-Only Mode will be set to Strict or Balanced initially, but users are allowed to change it.\n\nIf you set this policy to a value that isn't supported by the version of Microsoft Edge that receives the policy, Microsoft Edge defaults to the Allowed setting.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nPolicy options mapping:\n\n* allowed (allowed) = Don't restrict users' HTTPS-Only Mode setting\n\n* disallowed (disallowed) = Disable HTTPS-Only Mode\n\n* force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode\n\n* force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_allowed","displayName":"Don't restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_disallowed","displayName":"Disable HTTPS-Only Mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_force_enabled","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_force_balanced_enabled","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsupgradesenabled","displayName":"Enable automatic HTTPS upgrades","description":"As of Microsoft Edge version 120, Microsoft Edge tries to upgrade HTTP navigations to HTTPS, whenever possible, to improve security. Navigations to captive portals, IP addresses, and nonunique hostnames are excluded from automatic upgrades.\n\nIf this policy is enabled or not configured, automatic HTTPS upgrades are turned on by default.\n\nIf this policy is disabled, Microsoft Edge doesn't attempt to upgrade HTTP connections to HTTPS.\n\nTo exempt specific hostnames or hostname patterns from being upgraded, use the HttpAllowlist policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsupgradesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsupgradesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.hubssidebarenabled","displayName":"Show Hubs Sidebar","description":"The Sidebar is a launcher bar located on the right side of Microsoft Edge.\n\nIf you enable this policy, the Sidebar is always visible.\n\nIf you disable this policy, the Sidebar is never shown.\n\nIf you don't configure this policy, the Sidebar's visibility follows the user's Microsoft Edge settings.\n\nAs of Microsoft Edge version 141, the \"Microsoft365CopilotChatIconEnabled\" policy is the only means of controlling the display of Copilot in the toolbar.\n\nNote: The recommended version of this policy-also known as the \"Default Settings (users can override)\" policy-is obsolete. This policy has never supported the recommended capability.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.hubssidebarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.hubssidebarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.hubssidebarenabled_recommended","displayName":"Show Hubs Sidebar (users can override)","description":"The Sidebar is a launcher bar located on the right side of Microsoft Edge.\n\nIf you enable this policy, the Sidebar is always visible.\n\nIf you disable this policy, the Sidebar is never shown.\n\nIf you don't configure this policy, the Sidebar's visibility follows the user's Microsoft Edge settings.\n\nAs of Microsoft Edge version 141, the \"Microsoft365CopilotChatIconEnabled\" policy is the only means of controlling the display of Copilot in the toolbar.\n\nNote: The recommended version of this policy-also known as the \"Default Settings (users can override)\" policy-is obsolete. This policy has never supported the recommended capability.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.hubssidebarenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.hubssidebarenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idledetectionallowedforurls","displayName":"Allow idle detection on these sites","description":"Allows you to specify a list of URL patterns for sites that are allowed to use the Idle Detection API.\n\nIf you don't configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise.\n\nOnly the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported. For detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=209532.\n\nURL patterns specified in the blocklist take precedence over this allowlist. This allowlist takes precedence over the DefaultIdleDetectionSetting policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idledetectionblockedforurls","displayName":"Block idle detection on these sites","description":"Allows you to specify a list of URL patterns for sites that are not allowed to use the Idle Detection API.\n\nOnly the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported.\n\nFor detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nIf you do not configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeout","displayName":"Delay before running idle actions","description":"Triggers an action when the computer is idle.\n\nIf you set this policy, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy.\n\nIf you don't set this policy, the browser doesn't run any action.\n\nThe minimum threshold is 1 minute.\n\n\"User input\" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.","helpText":null,"infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions","displayName":"Actions to run when the computer is idle","description":"When the timeout from the IdleTimeout policy is reached, the browser runs the actions configured in this policy.\n\nIf you don't configure the IdleTimeout policy, this policy has no effect.\n\nIf you don't configure this policy or no actions are selected, the IdleTimeout policy has no effect.\n\nSupported actions are:\n\n'close_browsers': close all browser windows and Progressive Web Apps (PWAs) for this profile.\n\n'reload_pages': reload all webpages. For some pages, the user might be prompted for confirmation first.\n\n'sign_out': sign out of browser. (This action only applies to iOS.)\n\n'close_tabs': close all open tabs and create an NTP (New Tab Page). Supported in Android and iOS.\n\n'clear_browsing_history', 'clear_download_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', 'clear_autofill', 'clear_site_settings': clear the corresponding browsing data. Deleting cookies using this policy doesn't sign the user out of their profile, the user stays signed in.\n\nSetting 'clear_browsing_history', 'clear_password_signing', 'clear_autofill', and 'clear_site_settings' disables sync for the respective data types if sync isn't already disabled by setting either the SyncDisabled policy or BrowserSignin to disabled.\n\nPolicy options mapping:\n\n* close_browsers (close_browsers) = Close Browsers\n\n* clear_browsing_history (clear_browsing_history) = Clear Browsing History\n\n* clear_download_history (clear_download_history) = Clear Download History\n\n* clear_cookies_and_other_site_data (clear_cookies_and_other_site_data) = Clear Cookies and Other Site Data\n\n* clear_cached_images_and_files (clear_cached_images_and_files) = Clear Cached Images and Files\n\n* clear_password_signin (clear_password_signin) = Clear Password sign in\n\n* clear_autofill (clear_autofill) = Clear Autofill\n\n* clear_site_settings (clear_site_settings) = Clear Site Settings\n\n* reload_pages (reload_pages) = Reload Pages\n\n* sign_out (sign_out) = Sign Out\n\n* close_tabs (close_tabs) = Close Tabs\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_close_browsers","displayName":"Close Browsers","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_browsing_history","displayName":"Clear Browsing History","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_download_history","displayName":"Clear Download History","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_cookies_and_other_site_data","displayName":"Clear Cookies and Other Site Data","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_cached_images_and_files","displayName":"Clear Cached Images and Files","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_password_signin","displayName":"Clear Password sign in","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_autofill","displayName":"Clear Autofill","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_site_settings","displayName":"Clear Site Settings","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_reload_pages","displayName":"Reload Pages","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_sign_out","displayName":"Sign Out","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_close_tabs","displayName":"Close Tabs","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.imagesallowedforurls","displayName":"Allow images on these sites","description":"Define a list of sites, based on URL patterns, that can display images.\n\nIf you don't configure this policy, the global default value is used for all sites either from the \"DefaultImagesSetting\" policy (if set) or the user's personal configuration.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.imagesblockedforurls","displayName":"Block images on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to display images.\n\nIf you don't configure this policy, the global default value from the \"DefaultImagesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.immersivereadergrammartoolsenabled","displayName":"Enable Grammar Tools feature within Immersive Reader in Microsoft Edge (Obsolete)","description":"This policy is obsoleted because Grammar Tools is deprecated from Microsoft Edge. This policy can't work in Microsoft Edge version 126. Enables the Grammar Tools feature within Immersive Reader in Microsoft Edge.\nThis helps improve reading comprehension by splitting words into syllables and highlighting nouns, verbs, adverbs, and adjectives.\n\nIf you enable this policy or don't configure it, the Grammar Tools option shows up within Immersive Reader.\nIf you disable this policy, users can't access the Grammar Tools feature within Immersive Reader.","helpText":null,"infoUrls":[],"categoryId":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","categoryName":"Immersive Reader settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.immersivereadergrammartoolsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.immersivereadergrammartoolsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.immersivereaderpicturedictionaryenabled","displayName":"Enable Picture Dictionary feature within Immersive Reader in Microsoft Edge (Obsolete)","description":"This Policy is obsoleted because Picture Dictionary is deprecated from Edge as of Sept, 2023. This policy won't work in Microsoft Edge Version 127. Enables the Picture Dictionary feature within Immersive Reader in Microsoft Edge.\nThis feature helps in reading comprehension by letting a user to click on any single word and see an illustration related to the meaning.\n\nIf you enable this policy or don't configure it, the Picture Dictionary option shows up within Immersive Reader.\nIf you disable this policy, users can't access the Picture Dictionary feature within Immersive Reader.","helpText":null,"infoUrls":[],"categoryId":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","categoryName":"Immersive Reader settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.immersivereaderpicturedictionaryenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.immersivereaderpicturedictionaryenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata","displayName":"Allow importing of autofill form data","description":"Allows users to import autofill form data from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import autofill data is automatically selected.\n\nIf you disable this policy, autofill form data isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports autofill data on first run, but users can select or clear autofill data option during manual import.\n\nNote: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS) and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_recommended","displayName":"Allow importing of autofill form data (users can override)","description":"Allows users to import autofill form data from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import autofill data is automatically selected.\n\nIf you disable this policy, autofill form data isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports autofill data on first run, but users can select or clear autofill data option during manual import.\n\nNote: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS) and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importbrowsersettings","displayName":"Allow importing of browser settings","description":"Allows users to import browser settings from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, browser settings aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This option means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\n\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importbrowsersettings_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importbrowsersettings_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importbrowsersettings_recommended","displayName":"Allow importing of browser settings (users can override)","description":"Allows users to import browser settings from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, browser settings aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This option means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\n\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importbrowsersettings_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importbrowsersettings_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies","displayName":"Allow importing of Cookies","description":"Allows users to import Cookies from another browser into Microsoft Edge.\n\nIf you disable this policy, Cookies aren't imported on first run.\n\nIf you don't configure this policy, Cookies are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\n\nNote: This policy currently manages Google Chrome import (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_recommended","displayName":"Allow importing of Cookies (users can override)","description":"Allows users to import Cookies from another browser into Microsoft Edge.\n\nIf you disable this policy, Cookies aren't imported on first run.\n\nIf you don't configure this policy, Cookies are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\n\nNote: This policy currently manages Google Chrome import (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importextensions","displayName":"Allow importing of extensions","description":"Allows users to import extensions from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importextensions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importextensions_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importextensions_recommended","displayName":"Allow importing of extensions (users can override)","description":"Allows users to import extensions from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importextensions_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importextensions_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites","displayName":"Allow importing of favorites","description":"Allows users to import favorites from another browser into Microsoft Edge.\n\nIf you enable this policy, the Favorites check box is automatically selected in the Import browser data dialog box.\n\nIf you disable this policy, favorites aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_recommended","displayName":"Allow importing of favorites (users can override)","description":"Allows users to import favorites from another browser into Microsoft Edge.\n\nIf you enable this policy, the Favorites check box is automatically selected in the Import browser data dialog box.\n\nIf you disable this policy, favorites aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory","displayName":"Allow importing of browsing history","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\n\nIf you enable this policy, the Browsing history check box is automatically selected in the Import browser data dialog box.\n\nIf you disable this policy, browsing history data isn't imported at first run, and users can't import this data manually.\n\nIf you don't configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_recommended","displayName":"Allow importing of browsing history (users can override)","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\n\nIf you enable this policy, the Browsing history check box is automatically selected in the Import browser data dialog box.\n\nIf you disable this policy, browsing history data isn't imported at first run, and users can't import this data manually.\n\nIf you don't configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhomepage","displayName":"Allow importing of home page settings","description":"Allows users to import their home page setting from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import the home page setting is automatically selected.\n\nIf you disable this policy, the home page setting isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, the home page setting is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This option means that Microsoft Edge imports the home page setting on first run, but users can select or clear the **home page** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhomepage_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhomepage_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importoneachlaunch","displayName":"Allow import of data from other browsers on each Microsoft Edge launch","description":"If you enable this policy, users will see a prompt to import their browsing data from other browsers on each Microsoft Edge launch.\n\nIf you disable this policy, users will never see a prompt to import their browsing data from other browsers on each Microsoft Edge launch.\n\nIf the policy is left unconfigured, users can activate this feature from a Microsoft Edge prompt or from the Settings page.\n\nNote: A similar policy named \"AutoImportAtFirstRun\" exists. This policy should be used if you want to import supported data from other browsers only once while setting up your device.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importoneachlaunch_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importoneachlaunch_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importopentabs","displayName":"Allow importing of open tabs","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importopentabs_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importopentabs_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importopentabs_recommended","displayName":"Allow importing of open tabs (users can override)","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importopentabs_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importopentabs_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo","displayName":"Allow importing of payment info","description":"Allows users to import payment info from another browser into Microsoft Edge.\n\nIf you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, payment info isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This option means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import.\n\n**Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_recommended","displayName":"Allow importing of payment info (users can override)","description":"Allows users to import payment info from another browser into Microsoft Edge.\n\nIf you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, payment info isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This option means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import.\n\n**Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords","displayName":"Allow importing of saved passwords","description":"Allows users to import saved passwords from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import saved passwords is automatically selected.\n\nIf you disable this policy, saved passwords aren't imported on first run, and users can't import them manually.\n\nIf you don't configure this policy, no passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_recommended","displayName":"Allow importing of saved passwords (users can override)","description":"Allows users to import saved passwords from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import saved passwords is automatically selected.\n\nIf you disable this policy, saved passwords aren't imported on first run, and users can't import them manually.\n\nIf you don't configure this policy, no passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine","displayName":"Allow importing of search engine settings","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\n\nIf you enable, this policy, the option to import search engine settings is automatically selected.\n\nIf you disable this policy, search engine settings aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This option means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_recommended","displayName":"Allow importing of search engine settings (users can override)","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\n\nIf you enable, this policy, the option to import search engine settings is automatically selected.\n\nIf you disable this policy, search engine settings aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This option means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importshortcuts","displayName":"Allow importing of shortcuts","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\n\nIf you disable this policy, Shortcuts aren't imported on first run.\n\nIf you don't configure this policy, Shortcuts are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\n\nNote: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importshortcuts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importshortcuts_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importshortcuts_recommended","displayName":"Allow importing of shortcuts (users can override)","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\n\nIf you disable this policy, Shortcuts aren't imported on first run.\n\nIf you don't configure this policy, Shortcuts are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\n\nNote: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importshortcuts_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importshortcuts_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importstartuppagesettings","displayName":"Allow importing of startup page settings","description":"Allows users to import Startup settings from another browser into Microsoft Edge.\n\nIf you enable this policy, the Startup settings are always imported.\n\nIf you disable this policy, startup settings aren't imported at first run or at manual import.\n\nIf you don't configure this policy, startup settings are imported at first run, and users can choose whether to import this data manually by selecting browser settings option during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge will import startup settings on first run, but users can select or clear **browser settings** option during manual import.\n\n**Note**: This policy currently manages importing from Microsoft Edge Legacy and Google Chrome (on Windows 7, 8, and 10) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importstartuppagesettings_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importstartuppagesettings_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importstartuppagesettings_recommended","displayName":"Allow importing of startup page settings (users can override)","description":"Allows users to import Startup settings from another browser into Microsoft Edge.\n\nIf you enable this policy, the Startup settings are always imported.\n\nIf you disable this policy, startup settings aren't imported at first run or at manual import.\n\nIf you don't configure this policy, startup settings are imported at first run, and users can choose whether to import this data manually by selecting browser settings option during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge will import startup settings on first run, but users can select or clear **browser settings** option during manual import.\n\n**Note**: This policy currently manages importing from Microsoft Edge Legacy and Google Chrome (on Windows 7, 8, and 10) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importstartuppagesettings_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importstartuppagesettings_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeavailability","displayName":"Configure InPrivate mode availability","description":"Specifies whether the user can open pages in InPrivate mode in Microsoft Edge.\n\nIf you don't configure this policy or set it to 'Enabled', users can open pages in InPrivate mode.\n\nSet this policy to 'Disabled' to stop users from using InPrivate mode.\n\nSet this policy to 'Forced' to always use InPrivate mode.\n\nThe \"InPrivateModeUrlAllowlist\" policy takes precedence over this policy and can allow specific URLs to open in InPrivate mode.\n\nIf this policy disables InPrivate mode and an allowlist is configured, InPrivate mode is permitted only for URLs that match entries in the allowlist. All other URLs are blocked from opening in InPrivate mode.\n\nPolicy options mapping:\n\n* Enabled (0) = InPrivate mode available\n\n* Disabled (1) = InPrivate mode disabled\n\n* Forced (2) = InPrivate mode forced\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeavailability_enabled","displayName":"InPrivate mode available","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeavailability_disabled","displayName":"InPrivate mode disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeavailability_forced","displayName":"InPrivate mode forced","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeurlallowlist","displayName":"Allow access to a list of URLs in InPrivate mode.","description":"This policy allows administrators to specify a list of URL patterns that are permitted to open in InPrivate mode. It can be used to create exceptions for URL patterns defined in \"InPrivateModeUrlBlocklist\". See how to format a URL pattern (https://go.microsoft.com/fwlink/?linkid=2095322).\n\nIf both this policy and \"InPrivateModeUrlBlocklist\" are configured, the allowlist takes precedence. URLs that match a pattern on this allowlist are allowed. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither list fall back to \"URLBlocklist\" and \"URLAllowlist\".\n\nIf this policy is configured and \"InPrivateModeUrlBlocklist\" is not configured, only the URLs specified in this allowlist can be opened in InPrivate mode. All other URLs are blocked.\n\nIf \"InPrivateModeAvailability\" is set to disallow (value 1) but this policy is configured, InPrivate mode is available only for URLs that match the allowlist.\n\nIf this policy is not configured, no exceptions are applied to \"InPrivateModeUrlBlocklist\" or \"InPrivateModeAvailability\".\n\nThis policy applies only to InPrivate mode. To allow URLs across all browsing modes and profiles, use the \"URLAllowlist\" policy.\n\nThis policy supports up to 1000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeurlblocklist","displayName":"Block access to a list of URLs in InPrivate mode.","description":"This policy controls which URLs are blocked from loading in InPrivate mode in Microsoft Edge.\n\nAdministrators can specify a list of URL patterns that are blocked when users browse in InPrivate mode. For information about the supported URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nIf both \"InPrivateModeUrlBlocklist\" and \"InPrivateModeUrlAllowlist\" are configured, the allowlist takes precedence.\n- URLs that match the allowlist are allowed.\n- URLs that match the blocklist but not the allowlist are blocked.\n- URLs that match neither list follow the behavior defined by the general \"URLBlocklist\" and \"URLAllowlist\" policies.\n\nIf \"InPrivateModeUrlAllowlist\" is configured and this policy is not configured, only URLs on the allowlist can be opened in InPrivate mode.\n\nIf \"InPrivateModeAvailability\" is set to disallow (value 1) and \"InPrivateModeUrlAllowlist\" is configured, InPrivate mode is available only for URLs that match the allowlist.\n\nThis policy applies only to InPrivate mode. To block URLs across all browsing modes, use \"URLBlocklist\".\n\nThis policy supports up to 1000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecurecontentallowedforurls","displayName":"Allow insecure content on specified sites","description":"Create a list of URL patterns to specify sites that can display or, as of version 94, download insecure mixed content (that is, HTTP content on HTTPS sites).\n\nIf you don't configure this policy, blockable mixed content is blocked and optionally blockable mixed content is upgraded. However, users are allowed to set exceptions to allow insecure mixed content for specific sites.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecurecontentblockedforurls","displayName":"Block insecure content on specified sites","description":"Creates a list of URL patterns to specify sites that aren't allowed to display blockable (that is, active) mixed content (that is, HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades are disabled.\n\nIf you don't configure this policy, blockable mixed content is blocked, and optionally blockable mixed content is upgraded. However, users are allowed to set exceptions to allow insecure mixed content for specific sites.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureformswarningsenabled","displayName":"Enable warnings for insecure forms (Deprecated)","description":"This policy controls the handling of insecure forms (forms submitted over HTTP) embedded in secure (HTTPS) sites in the browser.\nIf you enable this policy or don't set it, a full page warning is shown when an insecure form is submitted. Additionally, a warning bubble is shown next to the form fields when they're focused, and autofill will be disabled for those forms.\nIf you disable this policy, warnings won't be shown for insecure forms, and autofill works normally.\n\nThis policy may be removed as soon as Edge 132. The feature is enabled by default since Edge 131.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureformswarningsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureformswarningsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowed","displayName":"Specifies whether to allow websites to make requests to any network endpoint in an insecure manner. (Obsolete)","description":"Controls whether websites are allowed to make requests to more-private network endpoints.\n\nWhen this policy is enabled, all Private Network Access checks are disabled for all origins. This may allow attackers to perform cross-site request forgery (CSRF) attacks on private network servers.\n\nWhen this policy is disabled or not configured, the default behavior for requests to more-private network endpoints depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests, PrivateNetworkAccessSendPreflights, and PrivateNetworkAccessRespectPreflightResults feature flags. These flags may be controlled by experimentation or set via the command line.\n\nThis policy relates to the Private Network Access specification. See https://wicg.github.io/private-network-access/ for more details.\n\nA network endpoint is more private than another if:\n1) Its IP address is localhost and the other isn't.\n2) Its IP address is private and the other is public.\nIn the future, depending on spec evolution, this policy might apply to all cross-origin requests directed at private IPs or localhost.\n\nWhen this policy enabled, websites are allowed to make requests to any network endpoint, subject to other cross-origin checks.\n\nThis policy is obsolete. The previous blanket override has been replaced by the permission-based Local Network Access model, which blocks cross-space requests until users grant explicit consent.","helpText":null,"infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from in an insecure manner (Obsolete)","description":"List of URL patterns. Requests initiated from websites served by matching origins aren't subject to Private Network Access checks.\n\nIf this policy isn't set, this policy behaves as if set to the empty list.\n\nFor origins not covered by the patterns specified here, the global default value is used either from the \"InsecurePrivateNetworkRequestsAllowed\" policy, if it's set, or the user's personal configuration otherwise.\n\nFor detailed information on valid URL patterns, see [Filter format for URL list-based policies](/DeployEdge/edge-learnmmore-url-list-filter%20format).\n\nThis policy is obsolete. The previous blanket override has been replaced by the permission-based Local Network Access model, which blocks cross-space requests until users grant explicit consent.","helpText":null,"infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationalwaysuseoscapture","displayName":"Always use the OS capture engine to avoid issues with capturing Internet Explorer mode tabs","description":"Configure this policy to control whether Microsoft Edge will use the \"OS capture engine\" or the \"Browser capture engine\" when capturing browser windows in the same process using the screen-share APIs.\n\nYou should configure this policy if you want to capture the contents of Internet Explorer mode tabs. However, enabling this policy may negatively impact performance when capturing browser windows in the same process.\n\nThis policy only affects window capture, not tab capture. The contents of Internet Explorer mode tabs won't be captured when you choose to capture only a single tab, even if you configure this policy.\n\nIf you enable this policy, Microsoft Edge always uses the OS capture engine for window capture. Internet Explorer mode tabs will have their contents captured.\n\nIf you disable or don't configure this policy, Microsoft Edge uses the Browser capture engine for browser windows in the same process. Internet Explorer mode tabs in these windows won't have their contents captured.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2174004","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationalwaysuseoscapture_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationalwaysuseoscapture_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationalwayswaitforunload","displayName":"Wait for Internet Explorer mode tabs to completely unload before ending the browser session","description":"This policy causes Microsoft Edge to continue running until all Internet Explorer tabs have completely finished unloading. This allows Internet Explorer plugins like ActiveX controls to perform other critical work even after the browser has been closed. However, this can cause stability and performance issues, and Microsoft Edge processes may remain active in the background with no visible windows if the webpage or plugin prevents Internet Explorer from unloading. This policy should only be used if your organization depends on a plugin that requires this behavior.\n\nIf you enable this policy, Microsoft Edge always waits for Internet Explorer mode tabs to fully unload before ending the browser session.\n\nIf you disable or don't configure this policy, Microsoft Edge won't always wait for Internet Explorer mode tabs to fully unload before ending the browser session.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2174004","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationalwayswaitforunload_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationalwayswaitforunload_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcloudneutralsitesreporting","displayName":"Configure reporting of potentially misconfigured neutral site URLs to the M365 Admin Center Site Lists app","description":"This setting lets you enable reporting of sites that need to be configured as a neutral site on the Enterprise Mode Site List. The user must be signed in to Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant specified by the policy.\n\nIf you configure this policy, Microsoft Edge sends a report to the Microsoft 365 Admin Center Site Lists app when a navigation appears stuck redirecting back and forth between the Microsoft Edge and Internet Explorer (IE) engines several times. This indicates that redirection to an authentication server is switching engines, which repeatedly fails in a loop. The report shows the URL of the site that's the redirect target, minus any query string or fragment. The user's identity isn't reported.\n\nFor this reporting to work correctly, you must have successfully visited the Microsoft Edge Site Lists app in the Microsoft 365 Admin Center at least once. This activates a per-tenant storage account used to store these reports. Microsoft Edge still attempts to send reports if this step hasn't been completed. However, the reports aren't stored in the Site Lists app.\n\nIf you enable this policy, you must specify your Office 365 tenant ID. To learn more about finding your Office 365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668.\n\nIf you disable or don't configure this policy, Microsoft Edge never sends reports about misconfigured neutral sites to the Site Lists app.\n\nTo learn more about IE mode, see https://go.microsoft.com/fwlink/?linkid=2165707.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcloudsitelist","displayName":"Configure the Enterprise Mode Cloud Site List","description":"The Microsoft Edge Site Lists setting in the Microsoft 365 Admin Center allows you to host your site list(s) in a compliant cloud location and manage the contents of your site list(s) through the built-in experience. This setting allows you to specify which site list within the Microsoft 365 Admin Center is to be deploy to your users. The user must be signed in to Microsoft Edge with a valid work or school account. Otherwise, Microsoft Edge doesn't download the site list from the cloud location.\n\nThis setting is applicable only when the \"InternetExplorerIntegrationLevel\" setting is configured.\n\nIf you configure this policy, Microsoft Edge uses the specified site list. When enabled, you can enter the identifier of the site list that you created and published to the cloud in M365 Admin Center.\n\nThis setting takes precedence over the \"InternetExplorerIntegrationSiteList\" policy of Microsoft Edge as well as Internet Explorer's site list setting (Use the Enterprise mode IE website list). If you disable or don't configure this policy, Microsoft Edge will use the \"InternetExplorerIntegrationSiteList\" policy instead.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcloudusersitesreporting","displayName":"Configure reporting of IE Mode user list entries to the M365 Admin Center Site Lists app","description":"This setting lets you enable reporting of sites that Microsoft Edge users add to their local IE Mode site list. The user must be signed in to Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant that the policy specifies.\n\nIf you configure this policy, Microsoft Edge sends a report to the Microsoft 365 Admin Center Site Lists app when a user adds a site to their local IE mode site list. The report shows the URL of the site the user added, minus any query string or fragment. The user's identity isn't reported.\n\nFor this reporting to work correctly, you must successfully visit the Microsoft Edge Site Lists app in the Microsoft 365 Admin Center at least once. This visit activates a per-tenant storage account used to store these reports. Microsoft Edge still attempts to send reports if this step isn't completed. However, the reports aren't stored in the Site Lists app.\n\nIf you enable this policy, you must specify your O365 tenant ID. To learn more about finding your O365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668.\n\nIf you disable or don't configure this policy, Microsoft Edge never sends reports about URLs added to a user's local site list to the Site Lists app.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes","displayName":"Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode","description":"From Microsoft Edge version 96, navigations that switch between Internet Explorer mode and Microsoft Edge include form data.\n\nIf you enable this policy, you specify which data types are included in navigations between Microsoft Edge and Internet Explorer mode.\n\nIf you disable or don't configure this policy, Microsoft Edge uses the new behavior of including form data in navigations that change modes.\n\nTo learn more, see https://go.microsoft.com/fwlink/?linkid=2174004.\n\nPolicy options mapping:\n\n* IncludeNone (0) = Do not send form data or headers\n\n* IncludeFormDataOnly (1) = Send form data only\n\n* IncludeHeadersOnly (2) = Send additional headers only\n\n* IncludeFormDataAndHeaders (3) = Send form data and additional headers\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includenone","displayName":"Do not send form data or headers","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includeformdataonly","displayName":"Send form data only","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includeheadersonly","displayName":"Send additional headers only","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includeformdataandheaders","displayName":"Send form data and additional headers","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationenhancedhangdetection","displayName":"Configure enhanced hang detection for Internet Explorer mode","description":"Enhanced hang detection is a more granular approach to detecting hung webpages in Internet Explorer mode than what standalone Internet Explorer uses. When a hung webpage is detected, the browser applies a mitigation to prevent the rest of the browser from hanging.\n\nThis setting allows you to configure the use of enhanced hang detection in case you run into incompatible issues with any of your websites. We recommend disabling this policy only if you see notifications such as \"(website) is not responding\" in Internet Explorer mode but not in standalone Internet Explorer.\n\nThis setting works in conjunction with:\n\"InternetExplorerIntegrationLevel\" is set to 'IEMode'\nand\n\"InternetExplorerIntegrationSiteList\" policy where the list has at least one entry.\n\nIf you set this policy to 'Enabled' or don't configure it, websites running in Internet Explorer mode use enhanced hang detection.\n\nIf you set this policy to 'Disabled', enhanced hang detection is disabled, and users get the basic Internet Explorer hang detection behavior.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210\n\nPolicy options mapping:\n\n* Disabled (0) = Enhanced hang detection disabled\n\n* Enabled (1) = Enhanced hang detection enabled\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationenhancedhangdetection_disabled","displayName":"Enhanced hang detection disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationenhancedhangdetection_enabled","displayName":"Enhanced hang detection enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlevel","displayName":"Configure Internet Explorer integration","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210\n\nPolicy options mapping:\n\n* None (0) = None\n\n* IEMode (1) = Internet Explorer mode\n\n* NeedIE (2) = Internet Explorer 11\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlevel_none","displayName":"None","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlevel_iemode","displayName":"Internet Explorer mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlevel_needie","displayName":"Internet Explorer 11","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileallowed","displayName":"Allow launching of local files in Internet Explorer mode","description":"This policy controls the availability of the --ie-mode-file-url command line argument used to launch Microsoft Edge with a local file specified on the command line into Internet Explorer mode.\n\nThis setting works in conjunction with \"InternetExplorerIntegrationLevel\" (which is set to 'IEMode').\n\nIf this policy is set to \"true\", or don't configure it, the user is allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\n\nIf this policy is set to \"false\", the user isn't allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\n\nFor more information about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileextensionallowlist","displayName":"Open local files in Internet Explorer mode file extension allow list","description":"This policy limits which file:// URLs are allowed to launch into Internet Explorer mode based on file extension.\n\nThis setting works when \"InternetExplorerIntegrationLevel\" is set to 'IEMode'.\n\nWhen a file:// URL is requested to launch in Internet Explorer mode, the file extension of the URL must be present in this list for the URL to be allowed to launch in Internet Explorer mode. A URL that's blocked from opening in Internet Explorer mode is instead opened in Microsoft Edge mode.\n\nIf you set this policy to the special value \"*\" or don't configure it, all file extensions are allowed.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileshowcontextmenu","displayName":"Show context menu to open a file:// link in Internet Explorer mode","description":"This policy controls the visibility of the 'Open link in new Internet Explorer mode tab' option on the context menu for file:// links.\n\nThis setting works in conjunction with:\n\"InternetExplorerIntegrationLevel\", which is set to 'IEMode'.\n\nIf you enable this policy, the 'Open link in new Internet Explorer mode tab' context menu item is available for file:// links.\n\nIf you disable or don't configure this policy, the context menu item won't be added.\n\nIf the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy allows users to reload sites in Internet Explorer mode, then the 'Open link in new Internet Explorer mode tab' context menu item is available for all links, except links to sites explicitly configured by the site list to use Microsoft Edge mode. In this case, if you enable this policy, the context menu item is available for file:// links even for sites configured to use Microsoft Edge mode. If you disable or don't configure this policy, the policy has no effect.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileshowcontextmenu_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileshowcontextmenu_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalmhtfileallowed","displayName":"Allow local MHTML files to open automatically in Internet Explorer mode","description":"This policy controls whether local mht or mhtml files launched from the command line open automatically in Internet Explorer mode based on the file content without specifying the --ie-mode-file-url command line.\n\nThis setting works when \"InternetExplorerIntegrationLevel\" is set to 'IEMode' and \"InternetExplorerIntegrationLocalFileAllowed\" is enabled or not configured.\n\nIf you enable or don't configure this policy, local mht or mhtml files launch in Microsoft Edge or Internet Explorer mode. Then, you can view these files in the best way.\n\nIf you disable this policy, local mht or mhtml files launch in Microsoft Edge.\n\nIf you use the --ie-mode-file-url command line argument for launching local mht or mhtml files, it takes precedence over how you configured this policy.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalmhtfileallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalmhtfileallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationreloadiniemodeallowed","displayName":"Allow unconfigured sites to be reloaded in Internet Explorer mode","description":"This policy allows users to reload unconfigured sites (ones that aren't configured in the Enterprise Mode Site List) in Internet Explorer mode when browsing in Microsoft Edge, and a site requires Internet Explorer for compatibility.\n\nAfter a site is reloaded in Internet Explorer mode, \"in-page\" navigation stays in Internet Explorer mode (for example, a link, script, or form on the page, or a server-side redirect from another \"in-page\" navigation). Users can choose to exit from Internet Explorer mode, or Microsoft Edge automatically exits from Internet Explorer mode when a navigation that isn't \"in-page\" occurs (for example, using the address bar, the back button, or a favorite link).\n\nUsers can also optionally tell Microsoft Edge to use Internet Explorer mode for the site in the future. This choice is remembered for a length of time managed by the \"InternetExplorerIntegrationLocalSiteListExpirationDays\" policy.\n\nIf the \"InternetExplorerIntegrationLevel\" policy is set to 'IEMode', then sites explicitly configured by the \"InternetExplorerIntegrationSiteList\" policy's site list to use Microsoft Edge aren't reloaded in Internet Explorer mode, and sites configured by the site list or by the \"SendIntranetToInternetExplorer\" policy to use Internet Explorer mode can't exit from Internet Explorer mode.\n\nIf you enable this policy, users are allowed to reload unconfigured sites in Internet Explorer mode.\n\nIf you disable this policy, users aren't allowed to reload unconfigured sites in Internet Explorer mode.\n\nIf you enable this policy, it takes precedence over how you configured the \"InternetExplorerIntegrationTestingAllowed\" policy, and that policy is disabled.\n\nFor more information about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationreloadiniemodeallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationreloadiniemodeallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationreloadiniemodeallowed_recommended","displayName":"Allow unconfigured sites to be reloaded in Internet Explorer mode (users can override)","description":"This policy allows users to reload unconfigured sites (ones that aren't configured in the Enterprise Mode Site List) in Internet Explorer mode when browsing in Microsoft Edge, and a site requires Internet Explorer for compatibility.\n\nAfter a site is reloaded in Internet Explorer mode, \"in-page\" navigation stays in Internet Explorer mode (for example, a link, script, or form on the page, or a server-side redirect from another \"in-page\" navigation). Users can choose to exit from Internet Explorer mode, or Microsoft Edge automatically exits from Internet Explorer mode when a navigation that isn't \"in-page\" occurs (for example, using the address bar, the back button, or a favorite link).\n\nUsers can also optionally tell Microsoft Edge to use Internet Explorer mode for the site in the future. This choice is remembered for a length of time managed by the \"InternetExplorerIntegrationLocalSiteListExpirationDays\" policy.\n\nIf the \"InternetExplorerIntegrationLevel\" policy is set to 'IEMode', then sites explicitly configured by the \"InternetExplorerIntegrationSiteList\" policy's site list to use Microsoft Edge aren't reloaded in Internet Explorer mode, and sites configured by the site list or by the \"SendIntranetToInternetExplorer\" policy to use Internet Explorer mode can't exit from Internet Explorer mode.\n\nIf you enable this policy, users are allowed to reload unconfigured sites in Internet Explorer mode.\n\nIf you disable this policy, users aren't allowed to reload unconfigured sites in Internet Explorer mode.\n\nIf you enable this policy, it takes precedence over how you configured the \"InternetExplorerIntegrationTestingAllowed\" policy, and that policy is disabled.\n\nFor more information about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationreloadiniemodeallowed_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationreloadiniemodeallowed_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsitelist","displayName":"Configure the Enterprise Mode Site List","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsitelistrefreshinterval","displayName":"Configure how frequently the Enterprise Mode Site List is refreshed","description":"This setting lets you specify a custom refresh interval for the Enterprise Mode Site List. The refresh interval is specified in minutes. The minimum refresh interval is 30 minutes.\n\nThis setting is applicable only when the \"InternetExplorerIntegrationSiteList\" or \"InternetExplorerIntegrationCloudSiteList\" setting is configured.\n\nIf you configure this policy, Microsoft Edge attempts to retrieve an updated version of the configured Enterprise Mode Site List using the specified refresh interval.\n\nIf you disable or don't configure this policy, Microsoft Edge uses a default refresh interval, it's 10080 minutes (7 days) starting from version 110 or later, 120 minutes from version 93 to 110, and 30 minutes before version 93.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect","displayName":"Specify how \"in-page\" navigations to unconfigured sites behave when started from Internet Explorer mode pages","description":"An \"in-page\" navigation is started from a link, a script, or a form on the current page. It can also be a server-side redirect of a previous \"in-page\" navigation attempt. Conversely, a user can start a navigation that isn't \"in-page\" and that's independent of the current page in several ways by using the browser controls, for example, using the address bar, the back button, or a favorite link.\n\nThis setting lets you specify whether navigations from pages loaded in Internet Explorer mode to unconfigured sites (that aren't configured in the Enterprise Mode Site List) switch back to Microsoft Edge or remain in Internet Explorer mode.\n\nThis setting works in conjunction with \"InternetExplorerIntegrationLevel\" policy that's set to 'IEMode', and with \"InternetExplorerIntegrationSiteList\" policy where the list has at least one entry.\n\nIf you disable or don't configure this policy, only sites configured to open in Internet Explorer mode open in that mode. Any site not configured to open in Internet Explorer mode is redirected back to Microsoft Edge.\n\nIf you set this policy to 'Default', only sites configured to open in Internet Explorer mode open in that mode. Any site not configured to open in Internet Explorer mode is redirected back to Microsoft Edge.\n\nIf you set this policy to 'AutomaticNavigationsOnly', you get the default experience except that all automatic navigations (such as 302 redirects) to unconfigured sites are kept in Internet Explorer mode.\n\nIf you set this policy to 'AllInPageNavigations', all navigations from pages loaded in IE mode to unconfigured sites are kept in Internet Explorer mode (Least Recommended).\n\nIf the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy allows users to reload sites in Internet Explorer mode, then all in-page navigations from unconfigured sites that users have chosen to reload in Internet Explorer mode are kept in Internet Explorer mode, regardless of how this policy is configured.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2105106.\n\nPolicy options mapping:\n\n* Default (0) = Default\n\n* AutomaticNavigationsOnly (1) = Keep only automatic navigations in Internet Explorer mode\n\n* AllInPageNavigations (2) = Keep all in-page navigations in Internet Explorer mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect_default","displayName":"Default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect_automaticnavigationsonly","displayName":"Keep only automatic navigations in Internet Explorer mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect_allinpagenavigations","displayName":"Keep all in-page navigations in Internet Explorer mode","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationtestingallowed","displayName":"Allow Internet Explorer mode testing (Obsolete)","description":"This policy is obsolete because it has been superseded by an improved feature. It doesn't work in Microsoft Edge after version 94. To allow users to open applications in Internet Explorer mode, use the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy instead. Alternatively, users can still use the --ie-mode-test flag.\n\nThis policy allows users to test applications in Internet Explorer mode by opening an Internet Explorer mode tab in Microsoft Edge.\n\nUsers can do so from within the \"More tools\" menu by selecting 'Open sites in Internet Explorer mode'.\n\nAdditionally, users can test their applications in a modern browser without removing applications from the site list using the option 'Open sites in Edge mode'.\n\nThis setting works in conjunction with \"InternetExplorerIntegrationLevel\" which is set to 'IEMode'.\n\nIf you enable this policy, the option 'Open sites in Internet Explorer mode' is visible under \"More tools\". Users can view their sites in Internet Explorer mode on this tab. Another option 'Open sites in Edge mode' is also visible under \"More tools\" to help testing sites in a modern browser without removing them from the site list. If the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy is enabled, it takes precedence and these options will not be visible under \"More tools\".\n\nIf you disable or don't configure this policy, users can't see the options 'Open in Internet Explorer mode' and 'Open in Edge mode' under \"More tools\" menu. However, users can configure these options with the --ie-mode-test flag.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationtestingallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationtestingallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationwindowopenheightadjustment","displayName":"Configure the pixel adjustment between window.open heights sourced from IE mode pages vs. Edge mode pages","description":"This setting lets you specify a custom adjustment to the height of popup windows generated via window.open from the Internet Explorer mode site.\n\nIf you configure this policy, Microsoft Edge will add the adjustment value to the height, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 5.\n\nIf you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window height calculations.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationwindowopenwidthadjustment","displayName":"Configure the pixel adjustment between window.open widths sourced from IE mode pages vs. Edge mode pages","description":"This setting lets you specify a custom adjustment to the width of popup windows generated via window.open from the Internet Explorer mode site.\n\nIf you configure this policy, Microsoft Edge will add the adjustment value to the width, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 4.\n\nIf you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window width calculations.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationzoneidentifiermhtfileallowed","displayName":"Automatically open downloaded MHT or MHTML files from the web in Internet Explorer mode","description":"This policy controls whether MHT or MHTML files that are downloaded from the web are automatically opened in Internet Explorer mode.\n\nIf you enable this policy, the MHT or MHTML files that are downloaded from the web can be opened in both Microsoft Edge and Internet Explorer mode to provide the best user experience.\n\nIf you disable or don't configure this policy, MHT or MHTML files that are downloaded from the web won't automatically open in Internet Explorer mode.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationzoneidentifiermhtfileallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationzoneidentifiermhtfileallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodecleardataonexitenabled","displayName":"Clear history for IE and IE mode every time you exit","description":"This policy controls whether browsing history is deleted from Internet Explorer and Internet Explorer mode every time Microsoft Edge is closed.\n\nUsers can configure this setting in the 'Clear browsing data for Internet Explorer' option in the Privacy, search, and services menu of Settings.\n\nIf you enable this policy, Internet Explorer browsing history will be cleared on browser exit.\n\nIf you disable or don't configure this policy, Internet Explorer browsing history won't be cleared on browser exit.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodecleardataonexitenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodecleardataonexitenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodeenablesavepageas","displayName":"Allow Save page as in Internet Explorer mode","description":"This policy enables 'Save page as' functionality in Internet Explorer mode.\nUsers can use this option to save the current page in the browser. When a user reopens a saved page, it's loaded in the default browser.\n\nIf you enable this policy, the \"Save page as\" option is clickable in \"More tools\".\n\nIf you disable or don't configure this policy, users can't select the \"Save page as\" option in \"More tools\".\n\nNote: To make the \"Ctrl+S\" shortcut work, users must enable the Internet Explorer policy, namely 'Enable extended hot key in Internet Explorer mode'.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodeenablesavepageas_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodeenablesavepageas_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetabinedgemodeallowed","displayName":"Allow sites configured for Internet Explorer mode to open in Microsoft Edge","description":"This policy lets sites configured to open in Internet Explorer mode to be opened by Microsoft Edge for testing on a modern browser without removing them from the site list.\n\nUsers can configure this setting in the \"More tools\" menu by selecting 'Open sites in Microsoft Edge'.\n\nIf you enable this policy, the option to 'Open sites in Microsoft Edge' is visible under \"More tools\". Users use this option to test IE mode sites on a modern browser.\n\nIf you disable or don't configure this policy, users can't see the option 'Open in Microsoft Edge' under the \"More tools\" menu. However, users can access this menu option with the --ie-mode-test flag.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetabinedgemodeallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetabinedgemodeallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled","displayName":"Show the Reload in Internet Explorer mode button in the toolbar","description":"Set this policy to show the Reload in Internet Explorer mode button in the toolbar. Users can hide the button in the toolbar through edge://settings/appearance. The button is only shown on the toolbar when the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy is enabled or if the user chose to enable \"Allow sites to be reloaded in Internet Explorer mode\".\n\nIf you enable this policy, the Reload in Internet mode button is pinned to the toolbar.\n\nIf you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default. Users can toggle the Show Internet Explorer mode button in edge://settings/appearance.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_recommended","displayName":"Show the Reload in Internet Explorer mode button in the toolbar (users can override)","description":"Set this policy to show the Reload in Internet Explorer mode button in the toolbar. Users can hide the button in the toolbar through edge://settings/appearance. The button is only shown on the toolbar when the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy is enabled or if the user chose to enable \"Allow sites to be reloaded in Internet Explorer mode\".\n\nIf you enable this policy, the Reload in Internet mode button is pinned to the toolbar.\n\nIf you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default. Users can toggle the Show Internet Explorer mode button in edge://settings/appearance.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorersetforegroundwhenactive","displayName":"Keep the active Microsoft Edge window with an Internet Explorer mode tab always in the foreground.","description":"This policy controls whether to always keep the active Microsoft Edge window with an Internet Explorer mode tab in the foreground.\n\nIf you enable this policy, the active Microsoft Edge window with an Internet Explorer mode tab remains in the foreground.\n\nIf you disable or don't configure this policy, the active Microsoft Edge window with an Internet Explorer mode tab isn't kept in the foreground.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorersetforegroundwhenactive_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorersetforegroundwhenactive_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerzoomdisplay","displayName":"Display zoom in IE Mode tabs with DPI Scale included like it is in Internet Explorer","description":"Lets you display zoom in IE Mode tabs similar to how it was displayed in Internet Explorer, where the DPI scale of the display is factored in.\n\nFor example, if you have a page zoomed to 200% on a 100 DPI scale display and you change the display to 150 DPI, Microsoft Edge would still display the zoom as 200%. However, Internet Explorer factors in the DPI scale and displays 300%.\n\nIf you enable this policy, zoom values will be displayed with the DPI scale included for IE Mode tabs.\n\nIf you disable or don't configure this policy, zoom values will be displayed without DPI scale included for IE Mode tabs","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerzoomdisplay_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerzoomdisplay_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.intranetfilelinksenabled","displayName":"Allow intranet zone file URL links from Microsoft Edge to open in Windows File Explorer","description":"This setting allows file URL links to intranet zone files from intranet zone HTTPS websites to open Windows File Explorer for that file or directory.\n\nIf you enable this policy, intranet zone file URL links originating from intranet zone HTTPS pages open Windows File Explorer to the parent directory of the file and select the file. Intranet zone directory URL links originating from intranet zone HTTPS pages open Windows File Explorer to the directory with no items in the directory selected.\n\nIf you disable or don't configure this policy, file URL links don't open.\n\nMicrosoft Edge uses the definition of intranet zone as configured for Internet Explorer. https://localhost/ is blocked as an exception of allowed intranet zone host, while loopback addresses (127.0.0.*, [::1]) are considered internet zone by default.\n\nUsers may opt out of prompts on a per-protocol/per-site basis unless the \"ExternalProtocolDialogShowAlwaysOpenCheckbox\" policy is disabled.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.intranetfilelinksenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.intranetfilelinksenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptallowedforurls","displayName":"Allow JavaScript on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to run JavaScript.\n\nIf you don't configure this policy, \"DefaultJavaScriptSetting\" applies for all sites, when the setting is enabled. If not, the user's personal setting applies.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptblockedforurls","displayName":"Block JavaScript on specific sites","description":"Defines a list of sites, based on URL patterns, that aren't allowed to run JavaScript.\n\nIf you don't configure this policy, \"DefaultJavaScriptSetting\" applies for all sites, if it's set. If not, the user's personal setting applies.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nThis policy blocks JavaScript based on whether the origin of the top-level document (usually the page URL that's also displayed in the address bar) matches any of the patterns. Therefore, this policy isn't appropriate for mitigating web supply-chain attacks. For example, supplying the pattern `https://[*.]foo.com/` doesn't prevent a page hosted on, say, `https://contoso.com`, from running a script loaded from `https://www.foo.com/example.js`. Furthermore, supplying the pattern `https://contoso.com/` doesn't prevent a document from `https://contoso.com` from running scripts if it isn't the top-level document, but embedded as a subframe into a page hosted on another origin, say, `https://www.fabrikam.com`.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites","description":"Allows you to set a list of site URL patterns that specify sites that are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\n\nFor detailed information on valid site URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com won't correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there's no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top-level origin URL alone; so, for example, if contoso.com is listed in the JavaScriptJitAllowedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT enabled, but fabrikam.com will use the policy from \"DefaultJavaScriptJitSetting\", if set, or default to JavaScript JIT enabled.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptJitSetting\" applies to the site, if set, otherwise Javascript JIT is enabled for the site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptjitblockedforsites","displayName":"Block JavaScript from using JIT on these sites","description":"Allows you to set a list of site URL patterns that specify sites that aren't allowed to run JavaScript JIT (Just In Time) compiler enabled.\n\nDisabling the JavaScript JIT means that Microsoft Edge may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Microsoft Edge to render web content in a more secure configuration.\n\nFor detailed information on valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top-level origin URL alone; so, for example, if contoso.com is listed in the JavaScriptJitBlockedForSites policy but contoso.com loads a frame containing fabrikam.com, then contoso.com has JavaScript JIT disabled, but fabrikam.com uses the policy from \"DefaultJavaScriptJitSetting\", if set, or default to JavaScript JIT enabled.\n\nIf you don't configure this policy for a site, then the policy from \"DefaultJavaScriptJitSetting\" applies to the site, if set; otherwise, JavaScript JIT is enabled for the site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites","description":"Allows you to set a list of site URL patterns that specify sites for which advanced JavaScript optimizations are enabled.\n\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com doesn't correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there's no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top-level origin URL alone; so, for example, if contoso.com is listed in the \"JavaScriptOptimizerAllowedForSites\" policy but contoso.com loads a frame containing fabrikam.com, then contoso.com has JavaScript optimizations enabled, but fabrikam.com uses the policy from \"DefaultJavaScriptOptimizerSetting\", if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\n\nIf you don't configure this policy for a site, then the policy from \"DefaultJavaScriptOptimizerSetting\" applies to the site, if set, otherwise Javascript optimization is enabled for the site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are disabled.\n\nDisabling JavaScript optimizations means that Microsoft Edge may render web content more slowly.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com won't correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there's no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and isn't based on top-level origin url alone; so, for example, if contoso.com is listed in the \"JavaScriptOptimizerBlockedForSites\" policy but contoso.com loads a frame containing fabrikam.com, then contoso.com has JavaScript optimizations disabled, but fabrikam.com will use the policy from \"DefaultJavaScriptOptimizerSetting\", if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\n\nIf you don't configure this policy for a site, then the policy from \"DefaultJavaScriptOptimizerSetting\" applies to the site, if set; otherwise, JavaScript optimization is enabled for the site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.keyboardfocusablescrollersenabled","displayName":"Enable keyboard focusable scrollers (Obsolete)","description":"This policy provides a temporary opt-out for the new keyboard focusable scrollers behavior.\n\nWhen this policy is Enabled or unset, scrollers without focusable children are keyboard focusable by default.\n\nWhen this policy is Disabled, scrollers aren't keyboard focusable by default.\n\nThis policy is a temporary workaround. Starting in Microsoft Edge version 139, this policy is obsolete.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.keyboardfocusablescrollersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.keyboardfocusablescrollersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.legacysamesitecookiebehaviorenabled","displayName":"Enable default legacy SameSite cookie behavior setting (Obsolete)","description":"This policy doesn't work because it was only intended to serve only as a short-term mechanism to give enterprises more time to update their environments if they were found to be incompatible with the SameSite behavior change.\n\nIf you still require legacy cookie behavior, please use \"LegacySameSiteCookieBehaviorEnabledForDomainList\" to configure behavior on a per-domain basis.\n\nLets you revert all cookies to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute, and skips the scheme comparison when evaluating if two sites are same-site.\n\nIf you don't set this policy, the default SameSite behavior for cookies will depend on other configuration sources for the SameSite-by-default feature, the Cookies-without-SameSite-must-be-secure feature, and the Schemeful Same-Site feature. These features can also be configured by a field trial or the same-site-by-default-cookies flag, the cookies-without-same-site-must-be-secure flag, or the schemeful-same-site flag in edge://flags.\n\nPolicy options mapping:\n\n* DefaultToLegacySameSiteCookieBehavior (1) = Revert to legacy SameSite behavior for cookies on all sites\n\n* DefaultToSameSiteByDefaultCookieBehavior (2) = Use SameSite-by-default behavior for cookies on all sites\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.legacysamesitecookiebehaviorenabled_defaulttolegacysamesitecookiebehavior","displayName":"Revert to legacy SameSite behavior for cookies on all sites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.legacysamesitecookiebehaviorenabled_defaulttosamesitebydefaultcookiebehavior","displayName":"Use SameSite-by-default behavior for cookies on all sites","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.legacysamesitecookiebehaviorenabledfordomainlist","displayName":"Revert to legacy SameSite behavior for cookies on specified sites (Obsolete)","description":"Cookies set for domains match specified patterns revert to legacy SameSite behavior.\n\nReverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute, and skips the scheme comparison when evaluating if two sites are same-site.\n\nIf you don't set this policy, the global default value is used. The global default is also used for cookies on domains not covered by the patterns you specify.\n\nThe global default value can be configured using the \"LegacySameSiteCookieBehaviorEnabled\" policy. If \"LegacySameSiteCookieBehaviorEnabled\" is unset, the global default value falls back to other configuration sources.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nPatterns you list in this policy are treated as domains, not URLs, so you shouldn't specify a scheme or port.\n\nThe policy is discontinued from Edge 132.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.linkedaccountenabled","displayName":"Enable the linked account feature (Obsolete)","description":"This policy is obsolete because Microsoft Edge no longer supports the linked account feature.\n\nMicrosoft Edge guides a user to the account management page where they can link a Microsoft Account (MSA) to an Azure Active Directory (Azure AD) account.\n\nIf you enable or don't configure this policy, linked account information is shown on a flyout. When the Azure AD profile doesn't have a linked account, it shows \"Add account\".\n\nIf you disable this policy, linked accounts are turned off and no extra information is shown.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.linkedaccountenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.linkedaccountenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.livecaptionsallowed","displayName":"Live captions allowed","description":"Allow users to turn the Live captions feature on or off.\n\nLive captions is an accessibility feature that converts speech from the audio that plays in Microsoft Edge into text and shows this text in a separate window. The entire process happens on the device and no audio or caption text ever leaves the device.\n\nNote: This feature isn't generally available. Clients that have the \"ExperimentationAndConfigurationServiceControl\" policy set to 'FullMode' receive the feature before broad availability. Broad availability is announced via Microsoft Edge release notes.\n\nIf you enable or don't configure this policy, users can turn on this feature or turn it off at edge://settings/accessibility.\n\nIf you disable this policy, users can't turn on this accessibility feature. If speech recognition files were downloaded previously, they will be deleted from the device in 30 days. We recommend avoiding this option unless it's needed in your environment.\n\nIf users choose to turn on Live captions, speech recognition files (approximately 100 megabytes) are downloaded to the device on first run and then periodically to improve performance and accuracy. These files will be deleted after 30 days.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.livecaptionsallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.livecaptionsallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.livevideotranslationenabled","displayName":"Allows users to translate videos to different languages.","description":"This policy configures the on-device real-time video translation feature in Microsoft Edge.\nWith this feature, users can watch videos translated into their selected language in real time.\n\nWhen a user selects the Translate icon and chooses a source (video language) and target language (translated language),\ntranslation components are downloaded on first use (approximately 200 MB per language pair).\n\nThese components can be updated periodically to improve performance and translation quality.\nTranslation is performed locally on the user’s device and no data is sent outside of the device.\nThe feature is available only for non-DRM videos, on supported high-end devices, with select language pairs, and in select regions.\nFor more information, see https://www.microsoft.com/en-us/edge/features/real-time-video-translation.\n\nIf you enable or don’t configure this policy, the on-device real-time video translation feature is enabled and\nusers will see the Translate button when hovering over videos.\n\nIf you disable this policy, the on-device real-time video translation feature is disabled and the Translate button is not shown.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.livevideotranslationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.livevideotranslationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localbrowserdatashareenabled","displayName":"Enable Windows to search local Microsoft Edge browsing data","description":"Enables Windows to index Microsoft Edge browsing data stored locally on the user's device and allows users to find and launch previously stored browsing data directly from Windows features such as the search box on the taskbar in Windows.\n\nIf you enable this policy or don't configure it, Microsoft Edge publishes local browsing data to the Windows Indexer.\n\nIf you disable this policy, Microsoft Edge won't share data to the Windows Indexer.\n\nNote that if you disable this policy, Microsoft Edge removes the data shared with Windows on the device and stops sharing any new browsing data.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localbrowserdatashareenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localbrowserdatashareenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localbrowserdatashareenabled_recommended","displayName":"Enable Windows to search local Microsoft Edge browsing data (users can override)","description":"Enables Windows to index Microsoft Edge browsing data stored locally on the user's device and allows users to find and launch previously stored browsing data directly from Windows features such as the search box on the taskbar in Windows.\n\nIf you enable this policy or don't configure it, Microsoft Edge publishes local browsing data to the Windows Indexer.\n\nIf you disable this policy, Microsoft Edge won't share data to the Windows Indexer.\n\nNote that if you disable this policy, Microsoft Edge removes the data shared with Windows on the device and stops sharing any new browsing data.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localbrowserdatashareenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localbrowserdatashareenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localfontsallowedforurls","displayName":"Allow Local Fonts permission on these sites","description":"Specifies a list of site URL patterns for which the local fonts permission is automatically granted. Sites in this list can access information about local fonts.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are supported. This policy matches based on origin only; any path in the URL pattern is ignored.\n\nIf a site isn't included in this policy, the \"DefaultLocalFontsSetting\" policy applies if configured. Otherwise, the browser default behavior applies, and users can choose the permission on a per-site basis.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localfontsblockedforurls","displayName":"Block Local Fonts permission on these sites","description":"Specifies a list of site URL patterns for which the local fonts permission is automatically denied. Sites in this list are prevented from accessing information about local fonts.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are supported. This policy matches based on origin only; any path in the URL pattern is ignored.\n\nIf a site isn't included in this policy, the \"DefaultLocalFontsSetting\" policy applies if configured. Otherwise, the browser default behavior applies, and users can choose the permission on a per-site basis.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessallowedforurls","displayName":"Allow sites to make network requests to local devices and local network endpoints.","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions.\n\nNetwork requests initiated from websites served by matching origins are not subject to Local Network Access checks.\n\nFor origins not covered by the patterns specified here, the user's personal configuration and applicable local network access restrictions apply.\n\nThere are multiple policies that control origins impacting requests to local device and local network endpoints. If an origin matches more than one of the following policies, the policies take precedence in the following order:\n\n- LocalNetworkBlockedForUrls\n- LocalNetworkAllowedForUrls\n- LoopbackNetworkAccessBlockedForUrls\n- LoopbackNetworkAccessAllowedForUrls\n- LocalNetworkAccessBlockedForUrls\n- LocalNetworkAccessAllowedForUrls\n\nFor detailed information about valid URL pattern syntax, see:\nhttps://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns\n\nFor more information about Local Network Access, see:\nhttps://wicg.github.io/local-network-access/\n\nNote: This policy enables controlled exceptions to local network access restrictions. It allows specified public websites to access private IP addresses when required for trusted local communication scenarios.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessblockedforurls","displayName":"Block sites from making network requests to local devices and local network endpoints.","description":"Specifies a list of URL patterns for which requests initiated from matching origins are blocked from issuing Local Network Access requests.\n\nNetwork requests initiated from websites served by matching origins are prevented from accessing local device and local network endpoints.\n\nFor origins not covered by the patterns specified here, the user's personal configuration applies.\n\nThere are multiple policies that control origins impacting requests to local device and local network endpoints. If an origin matches more than one of the following policies, the policies take precedence in the following order:\n\n- LocalNetworkBlockedForUrls\n- LocalNetworkAllowedForUrls\n- LoopbackNetworkAccessBlockedForUrls\n- LoopbackNetworkAccessAllowedForUrls\n- LocalNetworkAccessBlockedForUrls\n- LocalNetworkAccessAllowedForUrls\n\nFor detailed information about valid URL pattern syntax, see:\nhttps://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns\n\nFor more information about Local Network Access, see:\nhttps://wicg.github.io/local-network-access/\n\nNote: This policy blocks specified public websites from accessing private IP addresses. It helps reduce exposure of internal network resources unless access is explicitly permitted by policy.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to block requests from public websites to devices on a user's local network. (Obsolete)","description":"Local Network Access restrictions prevent public websites from making\nrequests to devices on a user's local network without explicit user permission.\n\nIf you enable this policy, Microsoft Edge blocks\nany request that would otherwise trigger a DevTools warning\ndue to Local Network Access checks.\nThese requests are denied without prompting the user.\n\nIf you disable or don't configure this policy, Microsoft Edge handles\nthese requests using the default behavior, which may include showing warnings in DevTools\nand allowing the request to proceed depending on the context.\n\nNote: This feature improves local network security by deprecating direct access to private IP addresses from public websites\nunless explicitly granted by the user. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.\n\nStarting in version 140, Microsoft Edge introduces support for policies that manage Local Network Access behavior on a per-URL basis.\n\nYou can configure exceptions to allow specific URLs to bypass Local Network Access restrictions.\n\nYou can also block specific URLs from making Local Network Access requests.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessrestrictionsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessrestrictionsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessrestrictionstemporaryoptout","displayName":"Specifies whether to opt out of Local Network Access restrictions","description":"This policy allows for opting out of restrictions on requests to local network endpoints.\n\nIf you enable this policy, Local Network Access requests will only display warnings in Edge DevTools when Local Network Access checks fail.\n\nIf you disable or don't configure this policy, Local Network Access requests follow the default handling behavior.\n\nFor more information about Local Network Access restrictions, see Local Network Access.\n\nTo allow specific URL patterns that should automatically be granted Local Network Access permission, use the LocalNetworkAccessAllowedForUrls policy.\n\nNote: This opt-out policy is temporary and will be removed after Microsoft Edge version 152.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessrestrictionstemporaryoptout_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessrestrictionstemporaryoptout_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkallowedforurls","displayName":"Allow sites to make network requests to local network endpoints.","description":"Controls which website origins are exempt from Local Network Access checks when accessing local network endpoints.\n\nNetwork requests initiated from websites that match the specified URL patterns are not subject to Local Network Access checks.\n\nFor origins not covered by the patterns specified in this policy, the user's personal configuration applies.\n\nFor detailed information about valid URL patterns, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\n\nFor more information about Local Network Access restrictions, see https://wicg.github.io/local-network-access/.\n\nMultiple policies can list origins that affect requests to local network endpoints. If an origin matches more than one of the following policies, they take precedence in the following order:\n- LocalNetworkBlockedForUrls\n- LocalNetworkAllowedForUrls\n- LoopbackNetworkBlockedForUrls\n- LoopbackNetworkAllowedForUrls\n- LocalNetworkAccessBlockedForUrls\n- LocalNetworkAccessAllowedForUrls\n\nThis policy controls access to local network endpoints (private IP addresses) and can be used to allow specific websites to access local network resources.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkblockedforurls","displayName":"Block sites from making network requests to local network endpoints.","description":"Controls which website origins are blocked from making Local Network Access requests to local network endpoints.\n\nNetwork requests initiated from websites that match the specified URL patterns are blocked from issuing Local Network Access requests.\n\nFor origins not covered by the patterns specified in this policy, the user's personal configuration applies.\n\nFor detailed information about valid URL patterns, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\n\nFor more information about Local Network Access restrictions, see https://wicg.github.io/local-network-access/.\n\nMultiple policies can list origins that affect requests to local network endpoints. If an origin matches more than one of the following policies, they take precedence in the following order:\n- LocalNetworkBlockedForUrls\n- LocalNetworkAllowedForUrls\n- LoopbackNetworkBlockedForUrls\n- LoopbackNetworkAllowedForUrls\n- LocalNetworkAccessBlockedForUrls\n- LocalNetworkAccessAllowedForUrls\n\nThis policy controls access to local network endpoints (private IP addresses) and can be used to block specific websites from accessing local network resources.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled","displayName":"Allow suggestions from local providers","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\n\nIf you enable this policy, suggestions from local providers are used.\n\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions won't appear.\n\nIf you don't configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\n\nSome features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the \"SavingBrowserHistoryDisabled\" policy.\n\nThis policy requires a browser restart to finish applying.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_recommended","displayName":"Allow suggestions from local providers (users can override)","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\n\nIf you enable this policy, suggestions from local providers are used.\n\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions won't appear.\n\nIf you don't configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\n\nSome features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the \"SavingBrowserHistoryDisabled\" policy.\n\nThis policy requires a browser restart to finish applying.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.loopbacknetworkallowedforurls","displayName":"Allow sites to make network requests to the local device.","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions when accessing loopback addresses (127.0.0.1, ::1, localhost).\n\nIf a requesting origin matches a URL pattern specified in this policy, requests to loopback addresses are allowed and are not subject to Local Network Access restrictions.\n\nFor origins not covered by this policy, the user's personal settings and local network access restrictions apply.\n\nIf this policy is disabled or not configured, no additional exemptions are granted beyond the user's existing configuration.\n\nMultiple policies can specify origins that affect requests to the local device. If an origin matches more than one of the following policies, they are applied in the following order of precedence:\n- LoopbackNetworkBlockedForUrls\n- LoopbackNetworkAllowedForUrls\n- LocalNetworkAccessBlockedForUrls\n- LocalNetworkAccessAllowedForUrls\n\nFor guidance on valid URL pattern syntax, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns .","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.loopbacknetworkblockedforurls","displayName":"Block sites from making network requests to the local device.","description":"Specifies a list of URL patterns for which requests initiated from matching origins to loopback addresses (127.0.0.1, ::1, localhost) are blocked from issuing Local Network Access requests.\n\nIf a requesting origin matches a URL pattern specified in this policy, requests to loopback addresses are blocked.\n\nFor origins not covered by this policy, the user's personal settings and local network access restrictions apply.\n\nMultiple policies can specify origins that affect requests to the local device. If an origin matches more than one of the following policies, they are applied in the following order of precedence:\n- LoopbackNetworkBlockedForUrls\n- LoopbackNetworkAllowedForUrls\n- LocalNetworkAccessBlockedForUrls\n- LocalNetworkAccessAllowedForUrls\n\nNote: This policy improves local network security by blocking specified public websites from accessing loopback addresses. It helps prevent unauthorized external sites from reaching local services running on the device unless explicitly permitted.\n\nFor more information about Local Network Access, see https://wicg.github.io/local-network-access/","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365authpopupsinworkenabled","displayName":"Allow M365 authentication popups in work profiles","description":"This policy controls whether Microsoft Edge allows Microsoft 365 authentication pop-ups to bypass the pop-up blocker in work profiles.\n\nWhen users are signed in with a work account, some Microsoft 365 sites (for example, microsoft.com, cloud.microsoft, and visualstudio.com) may open authentication pop-ups to login.microsoftonline.com, login.live.com, or login.microsoft.com. These pop-ups are required to complete sign-in.\n\nIf you enable this policy or don't configure it, Microsoft 365 authentication pop-ups are allowed in work profiles.\n\nIf you disable this policy, Microsoft 365 authentication pop-ups follow the default settings like other pop-ups.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365authpopupsinworkenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365authpopupsinworkenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365linksautoopencopilotenabled","displayName":"Automatically open Copilot side pane with contextual insights for links opened from Outlook","description":"This policy controls whether Microsoft Edge automatically opens the Microsoft Copilot side pane when users open eligible web links from Outlook emails sent from the same tenant.\n\nStarting in Microsoft Edge version 148, eligible links from Outlook emails sent from the same tenant can open with the Copilot side pane. Copilot can use the originating Outlook email as context to surface relevant insights and suggested next steps alongside the web content.\n\nIf you enable this policy or don't configure it, the Copilot side pane opens automatically when users open eligible links from Outlook emails sent from the same tenant.\n\nIf you disable this policy, the Copilot side pane doesn't open automatically for those links.\n\nThis policy is not yet supported. When support becomes available, eligible links from Outlook emails sent from the same tenant can open with the Copilot side pane.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365linksautoopencopilotenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365linksautoopencopilotenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.managedconfigurationperorigin","displayName":"Sets managed configuration values for websites to specific origins","description":"Setting this policy defines the return value of Managed Configuration API for given origin.\n\nManaged Configuration API is a key-value configuration that can be accessed via navigator.device.getManagedConfiguration() javascript call. This API is only available to origins, which correspond to force-installed web applications via \"WebAppInstallForceList\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.managedfavorites","displayName":"Configure favorites","description":"Configures a list of managed favorites.\n\nThe policy creates a list of favorites. Each favorite contains the keys \"name\" and \"url,\" which hold the favorite's name and its target. You can configure a subfolder by defining a favorite without an \"url\" key but with an extra \"children\" key that contains a list of favorites as defined earlier (some of which may be folders again). Microsoft Edge amends incomplete URLs as if they were submitted via the Address Bar, for example \"microsoft.com\" becomes \"https://microsoft.com/\".\n\nThese favorites are placed in a folder that can't be modified by the user (but the user can choose to hide it from the favorites bar). By default the folder name is \"Managed favorites\" but you can change it by adding to the list of favorites a dictionary containing the key \"toplevel_name\" with the desired folder name as the value.\n\nManaged favorites aren't synced to the user account and can't be modified by extensions.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.managedsearchengines","displayName":"Manage Search Engines","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine. With Microsoft Edge version 100, you can configure up to 100 engines.\n\nYou don't need to specify the encoding. With Microsoft Edge version 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge version 80.\n\nWith Microsoft Edge version 83, you can enable search engine discovery with the optional allow_search_engine_discovery parameter. This parameter must be the first item in the list. If allow_search_engine_discovery isn't specified, search engine discovery is disabled by default. With Microsoft Edge version 84, you can set this policy as a recommended policy to allow search provider discovery. You don't need to add the optional allow_search_engine_discovery parameter. With Microsoft Edge version 100, setting this policy as a recommended policy also allows users to manually add new search engines from their Microsoft Edge settings.\n\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\n\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\n\nIf the \"DefaultSearchProviderSearchURL\" policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.managedsearchengines_recommended","displayName":"Manage Search Engines (users can override)","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine. With Microsoft Edge version 100, you can configure up to 100 engines.\n\nYou don't need to specify the encoding. With Microsoft Edge version 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge version 80.\n\nWith Microsoft Edge version 83, you can enable search engine discovery with the optional allow_search_engine_discovery parameter. This parameter must be the first item in the list. If allow_search_engine_discovery isn't specified, search engine discovery is disabled by default. With Microsoft Edge version 84, you can set this policy as a recommended policy to allow search provider discovery. You don't need to add the optional allow_search_engine_discovery parameter. With Microsoft Edge version 100, setting this policy as a recommended policy also allows users to manually add new search engines from their Microsoft Edge settings.\n\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\n\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\n\nIf the \"DefaultSearchProviderSearchURL\" policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.mandatoryextensionsforinprivatenavigation","displayName":"Specify extensions users must allow in order to navigate using InPrivate mode","description":"This policy lets you specify a list of extension IDs that the user must explicitly allow to run in InPrivate mode in order to enable InPrivate browsing.\n\nIf users don't allow all listed extensions to run in InPrivate mode, they're unable to navigate using InPrivate.\n\nIf any extension in the list isn't installed, InPrivate navigation is blocked.\n\nThis policy only applies when InPrivate mode is enabled. If InPrivate mode is disabled using the InPrivateModeAvailability policy, this policy has no effect.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoft365copilotchaticonenabled","displayName":"Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar","description":"For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon is shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users.\n\nThis policy only applies when users are accessing Copilot in the sidepane.\n\nIf the policy is enabled: Copilot appears in the toolbar.\n\nIf the policy is disabled: Copilot doesn't appear in the toolbar.\n\nIf the policy isn't configured: Otherwise, Copilot shows in the toolbar and users can enable or disable Copilot from showing by using the Show Copilot toggle in settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoft365copilotchaticonenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoft365copilotchaticonenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoft365copilotchaticonenabled_recommended","displayName":"Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar (users can override)","description":"For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon is shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users.\n\nThis policy only applies when users are accessing Copilot in the sidepane.\n\nIf the policy is enabled: Copilot appears in the toolbar.\n\nIf the policy is disabled: Copilot doesn't appear in the toolbar.\n\nIf the policy isn't configured: Otherwise, Copilot shows in the toolbar and users can enable or disable Copilot from showing by using the Show Copilot toggle in settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoft365copilotchaticonenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoft365copilotchaticonenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftedgeinsiderpromotionenabled","displayName":"Microsoft Edge Insider Promotion Enabled","description":"Shows content promoting the Microsoft Edge Insider channels on the About Microsoft Edge settings page.\n\nIf you enable or don't configure this policy, the Microsoft Edge Insider promotion content is shown on the About Microsoft Edge page.\n\nIf you disable this policy, the Microsoft Edge Insider promotion content isn't shown on the About Microsoft Edge page.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftedgeinsiderpromotionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftedgeinsiderpromotionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsofteditorproofingenabled","displayName":"Spell checking provided by Microsoft Editor","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages.\n\nIf you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields.\n\nIf you disable this policy, spell check can only be provided by local engines that use platform or Hunspell services. The results from these engines might be less informative than the results Microsoft Editor can provide.\n\nIf the \"SpellcheckEnabled\" policy is set to disabled, or the user disables spell checking in the settings page, this policy will have no effect.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsofteditorproofingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsofteditorproofingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsofteditorsynonymsenabled","displayName":"Synonyms are provided when using Microsoft Editor spell checker","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages, and synonyms can be suggested as an integrated feature.\n\nIf you enable this policy, Microsoft Editor spell checker provides synonyms for suggestions for misspelled words.\n\nIf you disable or don't configure this policy, Microsoft Editor spell checker won't provide synonyms for suggestions for misspelled words.\n\nIf the \"SpellcheckEnabled\" policy or the \"MicrosoftEditorProofingEnabled\" policy are set to disabled, or the user disables spell checking or chooses not to use Microsoft Editor spell checker in the settings page, this policy will have no effect.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsofteditorsynonymsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsofteditorsynonymsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftofficemenuenabled","displayName":"Allow users to access the Microsoft Office menu (Deprecated)","description":"This policy is deprecated because the Microsoft Edge sidebar replaced it. Microsoft Office applications are now available in the sidebar, which are managed by HubsSidebarEnabled policy.\n\nWhen users can access the Microsoft Office menu, they can get access to Office applications such as Microsoft Word and Microsoft Excel.\n\nIf you enable or don't configure this policy, users can open the Microsoft Office menu.\n\nIf you disable this policy, users can't access the Microsoft Office menu.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftofficemenuenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftofficemenuenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.mousegestureenabled","displayName":"Mouse Gesture Enabled","description":"This policy lets you configure the Mouse Gesture feature in Microsoft Edge.\n\nThis feature provides an easy way for users to complete tasks like scroll forward or backward, open new tab, refresh page, etc. They can finish a task by pressing and holding the mouse right button to draw certain patterns on a webpage, instead of clicking the buttons or using keyboard shortcuts.\n\nIf you enable or don't configure this policy, you can use the Mouse Gesture feature on Microsoft Edge to start using this feature.\n\nIf you disable this policy, you can't use the Mouse Gesture feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.mousegestureenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.mousegestureenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.mutationeventsenabled","displayName":"Enable deprecated/removed Mutation Events (Obsolete)","description":"This policy provides a temporary opt-in back to a deprecated and removed set of platform events named Mutation Events.\n\nIf you enable this policy, mutation events continue to be fired, even if they've been disabled by default for normal web users.\n\nIf you disable or don't configure this policy, these events won't be fired.\n\nNote:\nThis policy is a temporary workaround and will be obsolete starting with Microsoft Edge version 137.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.mutationeventsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.mutationeventsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativehostsexecutableslaunchdirectly","displayName":"Force Windows executable Native Messaging hosts to launch directly","description":"This policy controls whether native host executables launch directly on Windows.\n\nIf you enable this policy, Microsoft Edge is forced to launch native messaging hosts implemented as executables directly.\n\nIf you disable this policy, Microsoft Edge launches hosts using cmd.exe as an intermediary process.\n\nIf you don't configure this policy, Microsoft Edge decides which approach to use based on a progressive rollout from the legacy behavior to the Launch Directly behavior, guided by ecosystem compatibility.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativehostsexecutableslaunchdirectly_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativehostsexecutableslaunchdirectly_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessagingallowlist","displayName":"Control which native messaging hosts users can use","description":"Setting the policy specifies which native messaging hosts aren't subject to the deny list. A deny list value of * means all native messaging hosts are denied unless they're explicitly allowed.\n\nAll native messaging hosts are allowed by default. However, if a native messaging host is denied by policy, the admin can use the allow list to change that policy.","helpText":null,"infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessagingblocklist","displayName":"Configure native messaging block list","description":"Setting this policy specifies which native messaging hosts shouldn't be loaded. A deny list value of * means all native messaging hosts are denied unless they're explicitly allowed.\n\nIf you leave this policy unset, Microsoft Edge loads all installed native messaging hosts.","helpText":null,"infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessaginguserlevelhosts","displayName":"Allow user-level native messaging hosts (installed without admin permissions)","description":"If you set this policy to Enabled or leave it unset, Microsoft Edge can use native messaging hosts installed at the user level.\n\nIf you set this policy to Disabled, Microsoft Edge can only use these hosts if they're installed at the system level.","helpText":null,"infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessaginguserlevelhosts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessaginguserlevelhosts_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.navigationdelayforinitialsitelistdownloadtimeout","displayName":"Set a timeout for delay of tab navigation for the Enterprise Mode Site List","description":"Allows you to set a timeout, in seconds, for Microsoft Edge tabs waiting to navigate until the browser has downloaded the initial Enterprise Mode Site List.\n\nThis setting works in conjunction with: \"InternetExplorerIntegrationLevel\" is set to 'IEMode' and \"InternetExplorerIntegrationSiteList\" policy where the list has at least one entry and \"DelayNavigationsForInitialSiteListDownload\" is set to \"All eligible navigations\" (1).\n\nTabs won't wait longer than this timeout for the Enterprise Mode Site List to download. If the browser hasn't finished downloading the Enterprise Mode Site List when the timeout expires, Microsoft Edge tabs continue navigating anyway. The value of the timeout should be no greater than 20 seconds and no fewer than 1 second.\n\nIf you set the timeout in this policy to a value greater than 2 seconds, an information bar is shown to the user after 2 seconds. The information bar contains a button that allows the user to quit waiting for the Enterprise Mode Site List download to complete.\n\nIf you don't configure this policy, the default timeout of 4 seconds is used. This default is subject to change in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions","displayName":"Enable network prediction","description":"Enables network prediction and prevents users from changing this setting.\n\nThis controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages.\n\nIf you don't configure this policy, network prediction is enabled but the user can change it.\n\nPolicy options mapping:\n\n* NetworkPredictionAlways (0) = Predict network actions on any network connection\n\n* NetworkPredictionWifiOnly (1) = Not supported, if this value is used it will be treated as if 'Predict network actions on any network connection' (0) was set\n\n* NetworkPredictionNever (2) = Don't predict network actions on any network connection\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_networkpredictionalways","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_networkpredictionwifionly","displayName":"Not supported, if this value is used it will be treated as if 'Predict network actions on any network connection' (0) was set","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_networkpredictionnever","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_recommended","displayName":"Enable network prediction (users can override)","description":"Enables network prediction and prevents users from changing this setting.\n\nThis controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages.\n\nIf you don't configure this policy, network prediction is enabled but the user can change it.\n\nPolicy options mapping:\n\n* NetworkPredictionAlways (0) = Predict network actions on any network connection\n\n* NetworkPredictionWifiOnly (1) = Not supported, if this value is used it will be treated as if 'Predict network actions on any network connection' (0) was set\n\n* NetworkPredictionNever (2) = Don't predict network actions on any network connection\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_recommended_networkpredictionalways","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_recommended_networkpredictionwifionly","displayName":"Not supported, if this value is used it will be treated as if 'Predict network actions on any network connection' (0) was set","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_recommended_networkpredictionnever","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\n\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\n\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_recommended","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled (users can override)","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\n\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\n\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageallowedbackgroundtypes","displayName":"Configure the background types allowed for the new tab page layout","description":"You can configure which types of background image that are allowed on the new tab page layout in Microsoft Edge.\n\nIf you don't configure this policy, all background image types on the new tab page are enabled.\n\nPolicy options mapping:\n\n* DisableImageOfTheDay (1) = Disable daily background image type\n\n* DisableCustomImage (2) = Disable custom background image type\n\n* DisableAll (3) = Disable all background image types\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageallowedbackgroundtypes_disableimageoftheday","displayName":"Disable daily background image type","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageallowedbackgroundtypes_disablecustomimage","displayName":"Disable custom background image type","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageallowedbackgroundtypes_disableall","displayName":"Disable all background image types","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageapplauncherenabled","displayName":"Hide App Launcher on Microsoft Edge new tab page","description":"By default, the App Launcher is shown every time a user opens a new tab page.\n\nIf you enable or don't configure this policy, there's no change on the Microsoft Edge new tab page and App Launcher is there for users.\n\nIf you disable this policy, App Launcher doesn't appear and users can't launch Microsoft 365 apps from Microsoft Edge new tab page via the App Launcher.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageapplauncherenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageapplauncherenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagebingchatenabled","displayName":"Disable Bing chat entry-points on Microsoft Edge Enterprise new tab page","description":"By default, the Microsoft Edge new tab page includes three Bing Chat entry points: one inside the search box, one in the Bing autosuggest dropdown when users select or begin typing in the box, and one as a suggested prompt below the box.\n\nIf you enable or don't configure this policy, these Bing Chat entry points continue to appear on the new tab page.\n\nIf you disable this policy, all Bing Chat entry points are removed from the new tab page.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagebingchatenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagebingchatenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogo","displayName":"Set new tab page company logo (Obsolete)","description":"This policy didn't work as expected due to changes in operational requirements. Therefore, it's obsolete and shouldn't be used.\n\nSpecifies the company logo that's to be used on the new tab page in Microsoft Edge.\n\nThe policy should be configured as a string that expresses the logo(s) in JSON format. For example: { \"default_logo\": { \"url\": \"https://www.contoso.com/logo.png\", \"hash\": \"cd0aa9856147b6c5b4ff2b7dfee5da20aa38253099ef1b4a64aced233c9afe29\" }, \"light_logo\": { \"url\": \"https://www.contoso.com/light_logo.png\", \"hash\": \"517d286edb416bb2625ccfcba9de78296e90da8e32330d4c9c8275c4c1c33737\" } }\n\nYou configure this policy by specifying the URL from which Microsoft Edge can download the logo and its cryptographic hash (SHA-256), which is used to verify the integrity of the download. The logo must be in PNG or SVG format, and its file size must not exceed 16 MB. The logo is downloaded and cached, and it will be redownloaded whenever the URL or the hash changes. The URL must be accessible without any authentication.\n\nThe 'default_logo' is required and used when there's no background image. If 'light_logo' is provided, it's used when the user's new tab page has a background image. We recommend a horizontal logo with a transparent background that's left-aligned and vertically centered. The logo should have a minimum height of 32 pixels and an aspect ratio from 1:1 to 4:1. The 'default_logo' should have proper contrast against a white/black background, while the 'light_logo' should have proper contrast against a background image.\n\nIf you enable this policy, Microsoft Edge downloads and shows the specified logo(s) on the new tab page. Users can't override or hide the logo(s).\n\nIf you disable or don't configure this policy, Microsoft Edge shows no company logo or a Microsoft logo on the new tab page.\n\nFor help with determining the SHA-256 hash, see [Get-FileHash](/powershell/module/microsoft.powershell.utility/get-filehash).","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogobackplatecolor","displayName":"Set the company logo backplate color on the new tab page.","description":"By default, the new tab page sets the company logo backplate color to the neutralStrokeActive (#cecece) constant.\n\nYou can configure this policy with a color hex code to change the company logo backplate color on the new tab page.\n\nIf this policy isn't configured, the default neutralStrokeActive (#cecece) color is used as the backplate color.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogoenabled","displayName":"Hide the company logo on the Microsoft Edge new tab page","description":"By default, the company logo is shown on the new tab page if the company logo is configured in Admin Portal.\n\nIf you enable or don't configure this policy, there's no change on the Microsoft Edge new tab page and the company logo is there for users.\n\nIf you disable this policy, the company logo doesn't appear on Microsoft Edge new tab page.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogoenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogoenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecontentenabled","displayName":"Allow Microsoft content on the new tab page","description":"This policy applies for Microsoft Edge to all profile types, namely unsigned local user profiles, profiles signed in using a Microsoft Account, profiles signed in using Active Directory, and profiles signed in using Microsoft Entra ID. The Enterprise new tab page for profiles signed in using Microsoft Entra ID can be configured in the Microsoft 365 admin portal, but this policy setting takes precedence; therefore, any Microsoft 365 admin portal configurations are ignored.\n\nIf you enable or don't configure this policy, Microsoft Edge displays Microsoft content on the new tab page. The user can choose different display options for the content. These options include, but aren't limited to: \"Content off\", \"Content visible on scroll\", \"Headings only\", and \"Content visible\". Enabling this policy doesn't force content to be visible - the users can keep setting their own preferred content position.\n\nIf you disable this policy, Microsoft Edge doesn't display Microsoft content on the new tab page. The Content control in the NTP settings flyout is disabled and set to \"Content off\", and the Layout control in the NTP settings flyout is disabled and set to \"Custom\".\n\nRelated policies: \"NewTabPageAllowedBackgroundTypes\", \"NewTabPageQuickLinksEnabled\"","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecontentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecontentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagehidedefaulttopsites","displayName":"Hide the default top sites from the new tab page","description":"Hides the default top sites from the new tab page in Microsoft Edge.\n\nIf you set this policy to true, the default top site tiles are hidden.\n\nIf you set this policy to false or don't configure it, the default top site tiles remain visible.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagehidedefaulttopsites_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagehidedefaulttopsites_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagelocation","displayName":"Configure the new tab page URL","description":"Configures the default URL for the new tab page.\n\nThe recommended version of this policy doesn't currently work and functions exactly like the mandatory version.\n\nThis policy determines the page that opens when new tabs are created (including when new windows are opened). It also affects the startup page if this page opens to the new tab page.\n\nThis policy doesn't determine which page opens on startup; that factor is controlled by the \"RestoreOnStartup\" policy. It also doesn't affect the home page if this home page opens to the new tab page.\n\nIf you don't configure this policy, the default new tab page is used.\n\nIf you configure this policy *and* the \"NewTabPageSetFeedType\" policy, this policy takes precedence.\n\nIf a blank tab is preferred, \"about:blank\" is the correct URL to use, not \"about://blank\".\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or joined to instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagelocation_recommended","displayName":"Configure the new tab page URL (users can override)","description":"Configures the default URL for the new tab page.\n\nThe recommended version of this policy doesn't currently work and functions exactly like the mandatory version.\n\nThis policy determines the page that opens when new tabs are created (including when new windows are opened). It also affects the startup page if this page opens to the new tab page.\n\nThis policy doesn't determine which page opens on startup; that factor is controlled by the \"RestoreOnStartup\" policy. It also doesn't affect the home page if this home page opens to the new tab page.\n\nIf you don't configure this policy, the default new tab page is used.\n\nIf you configure this policy *and* the \"NewTabPageSetFeedType\" policy, this policy takes precedence.\n\nIf a blank tab is preferred, \"about:blank\" is the correct URL to use, not \"about://blank\".\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or joined to instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagemanagedquicklinks","displayName":"Set new tab page quick links","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\n\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\n\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' isn't provided, the URL is used as the default title. If 'pinned' isn't provided, the default value is false.\n\nMicrosoft Edge presents these tiles in the order listed, from left to right, with all pinned tiles displayed ahead of nonpinned tiles.\n\nIf you set this policy as mandatory, the 'pinned' field is ignored and all tiles are pinned. The tiles can't be deleted by the user and always appear at the front of the quick links list.\n\nIf you set this policy as recommended, pinned tiles remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying nonpinned links via this policy to an existing browser profile, the links don't appear at all, depending on how they rank compared to the user's browsing history.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagemanagedquicklinks_recommended","displayName":"Set new tab page quick links (users can override)","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\n\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\n\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' isn't provided, the URL is used as the default title. If 'pinned' isn't provided, the default value is false.\n\nMicrosoft Edge presents these tiles in the order listed, from left to right, with all pinned tiles displayed ahead of nonpinned tiles.\n\nIf you set this policy as mandatory, the 'pinned' field is ignored and all tiles are pinned. The tiles can't be deleted by the user and always appear at the front of the quick links list.\n\nIf you set this policy as recommended, pinned tiles remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying nonpinned links via this policy to an existing browser profile, the links don't appear at all, depending on how they rank compared to the user's browsing history.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled","displayName":"Enable preload of the new tab page for faster rendering","description":"If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_recommended","displayName":"Enable preload of the new tab page for faster rendering (users can override)","description":"If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagequicklinksenabled","displayName":"Allow quick links on the new tab page","description":"If you enable or don't configure this policy, Microsoft Edge displays quick links on the new tab page, and the user can interact with the control, turning quick links on and off. Enabling this policy doesn't force quick links to be visible - the user can continue to turn quick links on and off.\n\nIf you disable this policy, Microsoft Edge hides quick links on the new tab page and disables the quick links control in the NTP settings flyout.\n\nThis policy only applies for Microsoft Edge local user profiles, profiles signed in using a Microsoft Account, and profiles signed in using Active Directory. To configure the Enterprise new tab page for profiles signed in using Azure Active Directory, use the M365 admin portal.\n\nRelated policies: \"NewTabPageAllowedBackgroundTypes\", \"NewTabPageContentEnabled\"","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagequicklinksenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagequicklinksenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox","displayName":"Configure the new tab page search box experience","description":"You can configure the new tab page search box to use \"Search box (Recommended)\" or \"Address bar\" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\".\n\n If you disable or don't configure this policy and:\n\n- If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.\n- If the address bar default search engine isn't Bing, users are offered an additional choice (use \"Address bar\") when searching on new tabs.\n\n\nIf you enable this policy and set it to:\n\n- \"Search box (Recommended)\" ('bing'), the new tab page uses the search box to search on new tabs.\n- \"Address bar\" ('redirect'), the new tab page search box uses the address bar to search on new tabs.\n\nPolicy options mapping:\n\n* bing (bing) = Search box (Recommended)\n\n* redirect (redirect) = Address bar\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_bing","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_redirect","displayName":"Address bar","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_recommended","displayName":"Configure the new tab page search box experience (users can override)","description":"You can configure the new tab page search box to use \"Search box (Recommended)\" or \"Address bar\" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\".\n\n If you disable or don't configure this policy and:\n\n- If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.\n- If the address bar default search engine isn't Bing, users are offered an additional choice (use \"Address bar\") when searching on new tabs.\n\n\nIf you enable this policy and set it to:\n\n- \"Search box (Recommended)\" ('bing'), the new tab page uses the search box to search on new tabs.\n- \"Address bar\" ('redirect'), the new tab page search box uses the address bar to search on new tabs.\n\nPolicy options mapping:\n\n* bing (bing) = Search box (Recommended)\n\n* redirect (redirect) = Address bar\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_recommended_bing","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_recommended_redirect","displayName":"Address bar","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype","displayName":"Configure the Microsoft Edge new tab page experience (Obsolete)","description":"This policy is obsolete because the new version of the enterprise new tab page no longer requires choosing between different content types. Instead, the content that's presented to the user can be controlled via the Microsoft 365 admin center. To get to the Microsoft 365 admin center, sign in at https://admin.microsoft.com with your admin account.\n\nLets you choose either the Microsoft News or Office 365 feed experience for the new tab page.\n\nIf you set this policy to 'News', users see the Microsoft News feed experience on the new tab page.\n\nIf you set this policy to 'Office', users with an Azure Active Directory browser sign-in see the Office 365 feed experience on the new tab page.\n\nIf you disable or don't configure this policy, users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, and the standard new tab page feed experience. Users without an Azure Active Directory browser sign-in to see the standard new tab page experience.\n\nIf you enable this policy *and* the \"NewTabPageLocation\" policy, \"NewTabPageLocation\" has precedence.\n\nPolicy options mapping:\n\n* News (0) = Microsoft News feed experience\n\n* Office (1) = Office 365 feed experience\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_news","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_office","displayName":"Office 365 feed experience","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_recommended","displayName":"Configure the Microsoft Edge new tab page experience (Obsolete) (users can override)","description":"This policy is obsolete because the new version of the enterprise new tab page no longer requires choosing between different content types. Instead, the content that's presented to the user can be controlled via the Microsoft 365 admin center. To get to the Microsoft 365 admin center, sign in at https://admin.microsoft.com with your admin account.\n\nLets you choose either the Microsoft News or Office 365 feed experience for the new tab page.\n\nIf you set this policy to 'News', users see the Microsoft News feed experience on the new tab page.\n\nIf you set this policy to 'Office', users with an Azure Active Directory browser sign-in see the Office 365 feed experience on the new tab page.\n\nIf you disable or don't configure this policy, users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, and the standard new tab page feed experience. Users without an Azure Active Directory browser sign-in to see the standard new tab page experience.\n\nIf you enable this policy *and* the \"NewTabPageLocation\" policy, \"NewTabPageLocation\" has precedence.\n\nPolicy options mapping:\n\n* News (0) = Microsoft News feed experience\n\n* Office (1) = Office 365 feed experience\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_recommended_news","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_recommended_office","displayName":"Office 365 feed experience","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.notificationsallowedforurls","displayName":"Allow notifications on specific sites","description":"Allows you to create a list of URL patterns to specify sites that are allowed to display notifications.\n\nIf you don't set this policy, the global default value is used for all sites. This default value is from the \"DefaultNotificationsSetting\" policy if set, or from the user's personal configuration. For detailed information on valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.notificationsblockedforurls","displayName":"Block notifications on specific sites","description":"Allows you to create a list of url patterns to specify sites that aren't allowed to display notifications.\n\nIf you don't set this policy, the global default value is used for all sites. This default value is from the \"DefaultNotificationsSetting\" policy if it's set, or from the user's personal configuration. For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.onbulkdataentryenterpriseconnector","displayName":"Configuration policy for bulk data entry for Microsoft Edge for Business Data Loss Prevention Connectors","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when data is entered in Microsoft Edge from the clipboard or by drag and dropping web content.\n\nConnector Fields\n\n1. url_list,\ntags,\nenable,\ndisable\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\nAnalysis is triggered if at least one tag is included in the request.\n\n2. service_provider\nIdentifies the analysis service provider the configuration applies to.\n\n3. block_until_verdict\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\nAny other integer value allows the page to access the data immediately.\n\n4. default_action\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\nAny other value permits the page to access the data.\n\n5. minimum_data_size\nSpecifies the minimum size (in bytes) that the entered data must meet or exceed to be scanned.\nDefault: 100 bytes if the field isn't set.\n\nThis policy requires further setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.onfileattachedenterpriseconnector","displayName":"Configuration policy for files attached for Microsoft Edge for Business Data Loss Prevention Connectors","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when a file is attached to Microsoft Edge.\n\nConnector Fields\n\n1. url_list,\ntags,\nenable,\ndisable\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\nAnalysis is triggered if at least one tag is included in the request.\n\n2. service_provider\nIdentifies the analysis service provider the configuration applies to.\n\n3. block_until_verdict\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\nAny other integer value allows the page to access the data immediately.\n\n4. default_action\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\nAny other value permits the page to access the data.\n\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.onprintenterpriseconnector","displayName":"Configuration policy for print for Microsoft Edge for Business Data Loss Prevention Connectors","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when a page or file is printed from Microsoft Edge.\n\nConnector Fields\n\n1. url_list,\ntags,\nenable,\ndisable\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\nAnalysis is triggered if at least one tag is included in the request.\n\n2. service_provider\nIdentifies the analysis service provider the configuration applies to.\n\n3. block_until_verdict\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\nAny other integer value allows the page to access the data immediately.\n\n4. default_action\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\nAny other value permits the page to access the data.\n\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.onsecurityevententerpriseconnector","displayName":"Configuration policy for Microsoft Edge for Business Reporting Connectors","description":"Defines the Microsoft Edge for Business Reporting Connectors service settings that apply when a security event occurs in Microsoft Edge. These events include negative verdicts from Data Loss Prevention Connectors, password reuse, navigation to unsafe pages, and other security-sensitive actions.\n\nThe service_provider field specifies the reporting service provider. The enabled_event_names field lists the security events enabled for that provider.\n\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2325446.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.organizationalbrandingonworkprofileuienabled_recommended","displayName":"Allow the use of your organization's branding assets from Microsoft Entra on the profile-related UI of a work or school profile (users can override)","description":"Allow the use of your organization's branding assets from Entra, if any, on the profile-related UI of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect.\n\nIf you enable this policy, your organization's branding assets from Entra are used.\n\nIf you disable or don't configure this policy, your organization's branding assets from Entra aren't used.\n\nFor more information about configuring your organization's branding assets on Entra, visit https://go.microsoft.com/fwlink/?linkid=2254514.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.organizationalbrandingonworkprofileuienabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.organizationalbrandingonworkprofileuienabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.organizationlogooverlayonappiconenabled_recommended","displayName":"Allow your organization's logo from Microsoft Entra to be overlaid on the Microsoft Edge app icon of a work or school profile (users can override)","description":"Allows your organization's logo from Entra, if any, to be overlaid on the Microsoft Edge app icon of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect.\n\nIf you enable this policy, your organization's logo from Entra is used.\n\nIf you disable or don't configure this policy, your organization's logo from Entra won't be used.\n\nFor more information about configuring your organization's logo on Entra, visit https://go.microsoft.com/fwlink/?linkid=2254514.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.organizationlogooverlayonappiconenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.organizationlogooverlayonappiconenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.originagentclusterdefaultenabled","displayName":"Origin-keyed agent clustering enabled by default","description":"The Origin-Agent-Cluster: HTTP header controls whether a document is isolated in an origin-keyed agent cluster or in a site-keyed agent cluster. This functionality has security implications because an origin-keyed agent cluster allows isolating documents by origin. The consequence of this for developers is that the document.domain accessor can no longer be set when origin-keyed agent clustering is enabled.\n\nIf you enable or don't configure this policy, documents without the Origin-Agent-Cluster: header are assigned to origin-keyed agent clustering by default. On these documents, the document.domain accessor isn't settable.\n\nIf you disable this policy, documents without the Origin-Agent-Cluster: header are assigned to site-keyed agent clusters by default. On these documents, the document.domain accessor is settable.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2191896.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.originagentclusterdefaultenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.originagentclusterdefaultenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.outlookhubmenuenabled","displayName":"Allow users to access the Outlook menu (Obsolete)","description":"This policy doesn't work because the Outlook menu is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy.\n\nThis policy is used to manage access to the Outlook menu from Microsoft Edge.\n\nIf you enable or don't configure this policy, users can access the Outlook menu.\nIf you disable this policy, users can't access the Outlook menu.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.outlookhubmenuenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.outlookhubmenuenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.outlookhubmenuenabled_recommended","displayName":"Allow users to access the Outlook menu (Obsolete) (users can override)","description":"This policy doesn't work because the Outlook menu is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy.\n\nThis policy is used to manage access to the Outlook menu from Microsoft Edge.\n\nIf you enable or don't configure this policy, users can access the Outlook menu.\nIf you disable this policy, users can't access the Outlook menu.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.outlookhubmenuenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.outlookhubmenuenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.partitionedbloburlusage","displayName":"Manage Blob URL Partitioning During Fetching and Navigation","description":"The \"PartitionedBlobUrlUsage\" policy controls whether Blob URLs are partitioned during fetching and navigation.\nIf this policy is set to Enabled or not set, Blob URLs are partitioned.\nIf this policy is set to Disabled, Blob URLs can't be partitioned. This represents the Blob URL behavior before Microsoft Edge version 135.\n\nThe policy is scheduled to be available through Microsoft Edge version 146. After this version, the policy will be removed, and Microsoft Edge will no longer support unpartitioned blob storage.\n\nFor detailed information on third-party storage partitioning, see https://github.com/privacycg/storage-partitioning.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.partitionedbloburlusage_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.partitionedbloburlusage_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when the \"ClearBrowsingDataOnExit\" policy is enabled.\n\nIf you enable this policy, passwords aren't cleared when the browser closes.\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_recommended","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes (users can override)","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when the \"ClearBrowsingDataOnExit\" policy is enabled.\n\nIf you enable this policy, passwords aren't cleared when the browser closes.\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordexportenabled","displayName":"Enable exporting saved passwords from Password Manager","description":"This policy controls whether the Export Password button in edge://wallet/passwords is enabled.\n\nIf enabled or not configured, users can export saved passwords.\nIf disabled, the Export Password button is unavailable, preventing password exports.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordexportenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordexportenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordgeneratorenabled","displayName":"Allow users to get a strong password suggestion whenever they are creating an account online","description":"Configures the Password Generator Settings toggle that enables/disables the feature for users.\n\nIf you enable or don't configure this policy, then Password Generator offers users a strong and unique password suggestion (via a dropdown) on Signup and Change Password pages.\n\nIf you disable this policy, users no longer see strong password suggestions on Signup or Change Password pages.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordgeneratorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordgeneratorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerblocklist","displayName":"Configure the list of domains for which the password manager UI (Save and Fill) will be disabled","description":"Configure the list of domains where Microsoft Edge should disable the password manager. This means that Save and Fill workflows are disabled, ensuring that passwords for those websites can't be saved or auto filled into web forms.\n\nIf you enable this policy, the password manager is disabled for the specified set of domains.\n\nIf you disable or don't configure this policy, password manager works as usual for all domains.\n\nIf you configure this policy, that is, add domains for which password manager is blocked, users can't change or override the behavior in Microsoft Edge. In addition, users can't use password manager for those URLs.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerenabled","displayName":"Enable saving passwords to the password manager","description":"Enable Microsoft Edge to save user passwords. The next time a user visits a site with a saved password, Microsoft Edge will enter the password automatically.\n\nIf you enable or don't configure this policy, users can save and add their passwords in Microsoft Edge.\n\nIf you disable this policy, users can't save and add new passwords, but they can still use previously saved passwords.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerenabled_recommended","displayName":"Enable saving passwords to the password manager (users can override)","description":"Enable Microsoft Edge to save user passwords. The next time a user visits a site with a saved password, Microsoft Edge will enter the password automatically.\n\nIf you enable or don't configure this policy, users can save and add their passwords in Microsoft Edge.\n\nIf you disable this policy, users can't save and add new passwords, but they can still use previously saved passwords.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerpasskeysenabled","displayName":"Enable saving passkeys to the password manager","description":"This policy controls whether users can save passkeys in the built-in password manager. It does not limit access to, or change the contents of, passkeys already saved in the password manager.\n\nIf the PasswordManagerEnabled policy is Disabled, saving to the built-in password manager is disabled in general, including passkeys. In this case, this policy has no effect.\n\nIf this policy is enabled or not configured, users can save passkeys in the built-in password manager when signed in to Microsoft Edge.\n\nIf this policy is disabled, users cannot save new passkeys to the built-in password manager. Previously saved passkeys continue to work.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerpasskeysenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerpasskeysenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerrestrictlengthenabled","displayName":"Restrict the length of passwords that can be saved in the Password Manager","description":"Make Microsoft Edge restrict the length of usernames and/or passwords that can be saved in the Password Manager.\n\nIf you enable this policy, Microsoft Edge doesn't let the user save credentials with usernames and/or passwords longer than 256 characters.\n\nIf you disable or don't configure this policy, Microsoft Edge lets the user save credentials with arbitrarily long usernames and/or passwords.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerrestrictlengthenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerrestrictlengthenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmonitorallowed","displayName":"Allow users to be alerted if their passwords are found to be unsafe","description":"Allow Microsoft Edge to monitor user passwords.\n\nIf you enable this policy, the user gets alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\n\nIf you disable this policy, users aren't asked for permission to enable this feature. Their passwords aren't scanned, and they aren't alerted either.\n\nIf you don't configure the policy, users can turn this feature on or off.\n\nTo learn more about how Microsoft Edge finds unsafe passwords see https://go.microsoft.com/fwlink/?linkid=2133833\n\nAdditional guidance:\n\nThis policy can be set as both Recommended and Mandatory, however with an important callout.\n\nMandatory enabled: If the policy is set to Mandatory enabled, the UI in Settings will be disabled but remain in 'On' state, and a briefcase icon will be made visible next to it with this description displayed on hover - \"This setting is managed by your organization.\"\n\nRecommended enabled: If the policy is set to Recommended enabled, the UI in Settings will remain in 'Off' state, but a briefcase icon will be made visible next to it with this description displayed on hover - \"Your organization recommends a specific value for this setting and you have chosen a different value\"\n\nMandatory and Recommended disabled: Both these states will work the normal way, with the usual captions being shown to users.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmonitorallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmonitorallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmonitorallowed_recommended","displayName":"Allow users to be alerted if their passwords are found to be unsafe (users can override)","description":"Allow Microsoft Edge to monitor user passwords.\n\nIf you enable this policy, the user gets alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\n\nIf you disable this policy, users aren't asked for permission to enable this feature. Their passwords aren't scanned, and they aren't alerted either.\n\nIf you don't configure the policy, users can turn this feature on or off.\n\nTo learn more about how Microsoft Edge finds unsafe passwords see https://go.microsoft.com/fwlink/?linkid=2133833\n\nAdditional guidance:\n\nThis policy can be set as both Recommended and Mandatory, however with an important callout.\n\nMandatory enabled: If the policy is set to Mandatory enabled, the UI in Settings will be disabled but remain in 'On' state, and a briefcase icon will be made visible next to it with this description displayed on hover - \"This setting is managed by your organization.\"\n\nRecommended enabled: If the policy is set to Recommended enabled, the UI in Settings will remain in 'Off' state, but a briefcase icon will be made visible next to it with this description displayed on hover - \"Your organization recommends a specific value for this setting and you have chosen a different value\"\n\nMandatory and Recommended disabled: Both these states will work the normal way, with the usual captions being shown to users.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmonitorallowed_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmonitorallowed_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordprotectionchangepasswordurl","displayName":"Configure the change password URL","description":"Configures the change password URL (HTTP and HTTPS schemes only).\n\nPassword protection service will send users to this URL to change their password after seeing a warning in the browser.\n\nIf you enable this policy, then password protection service sends users to this URL to change their password.\n\nIf you disable this policy or don't configure it, then password protection service can't redirect users to a change password URL.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordprotectionloginurls","displayName":"Configure the list of enterprise login URLs where the password protection service should capture salted hashes of a password","description":"Configure the list of enterprise login URLs (HTTP and HTTPS schemes only) where Microsoft Edge should capture the salted hashes of passwords and use it for password reuse detection.\n\nIf you enable this policy, the password protection service captures fingerprints of passwords on the defined URLs.\n\nIf you disable this policy or don't configure it, no password fingerprints are captured.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordprotectionwarningtrigger","displayName":"Configure password protection warning trigger","description":"Allows you to control when to trigger password protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites.\n\nYou can use the \"PasswordProtectionLoginURLs\" and \"PasswordProtectionChangePasswordURL\" policies to configure which passwords to protect.\n\nExemptions: Passwords for the sites listed in \"PasswordProtectionLoginURLs\" and \"PasswordProtectionChangePasswordURL\", and for the sites listed in \"SmartScreenAllowListDomains\", don't trigger a password-protection warning.\n\nSet to PasswordProtectionWarningOff to not show password protection warnings.\n\nSet to PasswordProtectionWarningOnPasswordReuse to show password protection warnings when the users reuse their protected password on a non-allowlisted site.\n\nIf you disable or don't configure this policy, then the warning trigger isn't shown.\n\nPolicy options mapping:\n\n* PasswordProtectionWarningOff (0) = Password protection warning is off\n\n* PasswordProtectionWarningOnPasswordReuse (1) = Password protection warning is triggered by password reuse\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordprotectionwarningtrigger_passwordprotectionwarningoff","displayName":"Password protection warning is off","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordprotectionwarningtrigger_passwordprotectionwarningonpasswordreuse","displayName":"Password protection warning is triggered by password reuse","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordrevealenabled","displayName":"Enable Password reveal button","description":"Lets you configure the default display of the browser password reveal button for password input fields on websites.\n\nIf you enable or don't configure this policy, the browser user setting defaults to displaying the password reveal button.\n\nIf you disable this policy, the browser user setting won't display the password reveal button.\n\nFor accessibility, users can change the browser setting from the default policy.\n\nThis policy only affects the browser password reveal button, it doesn't affect websites' custom reveal buttons.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordrevealenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordrevealenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordrevealenabled_recommended","displayName":"Enable Password reveal button (users can override)","description":"Lets you configure the default display of the browser password reveal button for password input fields on websites.\n\nIf you enable or don't configure this policy, the browser user setting defaults to displaying the password reveal button.\n\nIf you disable this policy, the browser user setting can't display the password reveal button.\n\nFor accessibility, users can change the browser setting from the default policy.\n\nThis policy only affects the browser password reveal button but doesn't affect websites' custom reveal buttons.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordrevealenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordrevealenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.paymentmethodqueryenabled","displayName":"Allow websites to query for available payment methods","description":"Allows you to set whether websites can check if the user has payment methods saved.\n\nIf you disable this policy, websites that use PaymentRequest.canMakePayment or PaymentRequest.hasEnrolledInstrument API will be informed that no payment methods are available.\n\nIf you enable this policy or don't set this policy, websites can check if the user has payment methods saved.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.paymentmethodqueryenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.paymentmethodqueryenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdflocalfileaccessallowedfordomains","displayName":"Allow specified sites to access file:// URLs in the PDF Viewer","description":"Controls which sites can access file:// URLs in the PDF Viewer.\n\nIf you enable this policy, sites in the list can access file:// URLs in the PDF Viewer.\n\nIf you disable or don't configure this policy, sites cannot access file:// URLs in the PDF Viewer.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfsecuremode","displayName":"Secure mode and Certificate-based Digital Signature validation in native PDF reader","description":"The policy enables Digital Signature validation for PDF files in a secure environment, which shows the correct validation status of the signatures.\n\nIf you enable this policy, PDF files with Certificate-based digital signatures are opened with an option to view and verify the validity of the signatures with high security.\n\nIf you disable or don't configure this policy, the capability to view and verify the signature isn't available.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfsecuremode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfsecuremode_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfvieweroutofprocessiframeenabled","displayName":"Use out-of-process iframe PDF Viewer","description":"Determines whether the PDF viewer in Microsoft Edge uses an out-of-process iframe (OOPIF).\nThis is the new PDF viewer architecture going forward, as it's simpler in design and makes adding new features easier. The current GuestView PDF viewer, which relies on an outdated and overly complex architecture, is being deprecated.\n\nIf you enable this policy or don't configure it, Microsoft Edge uses the OOPIF PDF viewer architecture. The default behavior will be decided by Microsoft Edge.\n\nIf you disable this policy, Microsoft Edge strictly uses the existing GuestView PDF viewer. This approach embeds a web page with its own separate frame tree into another web page.\n\nThis policy will be removed in the future, after the OOPIF PDF viewer feature has fully rolled out.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfvieweroutofprocessiframeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfvieweroutofprocessiframeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfxfaenabled","displayName":"XFA support in native PDF reader enabled","description":"Lets the Microsoft Edge browser enable XFA (XML Forms Architecture) support in the native PDF reader and allows users to open XFA PDF files in the browser.\n\nIf you enable this policy, XFA support in the native PDF reader is enabled.\n\nIf you disable or don't configure this policy, Microsoft Edge won't enable XFA support in the native PDF reader.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfxfaenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfxfaenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled","displayName":"Performance Detector Enabled","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\n\nIf you enable or don't configure this policy, performance detector is turned on.\n\nIf you disable this policy, performance detector is turned off.\n\nThe user can configure its behavior in edge://settings/system.\n\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_recommended","displayName":"Performance Detector Enabled (users can override)","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\n\nIf you enable or don't configure this policy, performance detector is turned on.\n\nIf you disable this policy, performance detector is turned off.\n\nThe user can configure its behavior in edge://settings/system.\n\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.personalizationreportingenabled","displayName":"Allow personalization of ads, Microsoft Edge, search, news and other Microsoft services by sending browsing history, favorites and collections, usage and other browsing data to Microsoft","description":"This policy prevents Microsoft from collecting a user's Microsoft Edge browsing history, favorites and collections, usage, and other browsing data to be used for personalizing advertising, search, news, Microsoft Edge, and other Microsoft services.\n\nThis setting isn't available for child accounts or enterprise accounts.\n\nIf you disable this policy, users can't change or override the setting. If this policy is enabled or not configured, Microsoft Edge defaults to the user's preference.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.personalizationreportingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.personalizationreportingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.personalizetopsitesincustomizesidebarenabled","displayName":"Personalize my top sites in Customize Sidebar enabled by default","description":"This policy controls whether Microsoft Edge browser be allowed to use the browsing history to personalize the top sites in the customize sidebar page.\n\nIf you enable this policy, Microsoft Edge uses the browsing history to personalize the top sites in the customize sidebar page.\n\nIf you disable this policy, Microsoft Edge doesn't use the browsing history to personalize the top sites in the customize sidebar page.\n\nIf you don't configure this policy, the default behavior is to use the browsing history to personalize the top sites in the customize sidebar page.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.personalizetopsitesincustomizesidebarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.personalizetopsitesincustomizesidebarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\n\nThe Picture in Picture floating overlay button lets the user watch videos in a floating window on top of other windows.\n\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\n\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pictureinpictureoverlayenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pictureinpictureoverlayenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pinbrowseressentialstoolbarbutton","displayName":"Pin browser essentials toolbar button","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\n\nWhen the button is pinned, it always appears on the toolbar.\n\nWhen the button isn't pinned, it only appears when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\n\nIf you enable or don't configure this policy, the Browser essentials button is pinned on the toolbar.\n\nIf you disable this policy, the Browser essentials button isn't pinned on the toolbar.\n\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pinbrowseressentialstoolbarbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pinbrowseressentialstoolbarbutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pinbrowseressentialstoolbarbutton_recommended","displayName":"Pin browser essentials toolbar button (users can override)","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\n\nWhen the button is pinned, it always appears on the toolbar.\n\nWhen the button isn't pinned, it only appears when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\n\nIf you enable or don't configure this policy, the Browser essentials button is pinned on the toolbar.\n\nIf you disable this policy, the Browser essentials button isn't pinned on the toolbar.\n\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pinbrowseressentialstoolbarbutton_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pinbrowseressentialstoolbarbutton_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pluginsallowedforurls","displayName":"Allow the Adobe Flash plug-in on specific sites (Obsolete)","description":"This policy doesn't work because Flash is no longer supported by Microsoft Edge.\n\nDefine a list of sites, based on URL patterns, that can run the Adobe Flash plug-in.\n\nIf you don't configure this policy, the global default value from the \"DefaultPluginsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. However, starting in M85, patterns with '*' and '[*.]' wildcards in the host are no longer supported for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pluginsblockedforurls","displayName":"Block the Adobe Flash plug-in on specific sites (Obsolete)","description":"This policy doesn't work because Flash is no longer supported by Microsoft Edge.\n\nDefine a list of sites, based on URL patterns, that are blocked from running Adobe Flash.\n\nIf you don't configure this policy, the global default value from the \"DefaultPluginsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. However, starting in M85, patterns with '*' and '[*.]' wildcards in the host are no longer supported for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.popupsallowedforurls","displayName":"Allow pop-up windows on specific sites","description":"Define a list of sites, based on URL patterns, that can open pop-up windows. Wildcards (*) are allowed.\n\nIf you don't configure this policy, the global default value from the \"DefaultPopupsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.popupsblockedforurls","displayName":"Block pop-up windows on specific sites","description":"Define a list of sites, based on URL patterns, that are blocked from opening pop-up windows. Wildcards (*) are allowed.\n\nIf you don't configure this policy, the global default value from the \"DefaultPopupsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.precisegeolocationallowedforurls","displayName":"Allow precise geolocation on these sites","description":"This policy lets you specify a list of URL patterns for sites that are allowed to access the user's high-accuracy geolocation without prompting for permission.\n\nIf you leave this policy unset, DefaultGeolocationSetting applies to all sites (if configured). Otherwise, the user's personal setting is used.\n\nFor information about valid url patterns, see https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format. Wildcards (*) are supported.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.prefetchwithserviceworkerenabled","displayName":"Allow SpeculationRules prefetch for ServiceWorker-controlled URLs","description":"Controls whether SpeculationRules prefetch requests are allowed for\nServiceWorker-controlled URLs.\n\nWith Microsoft Edge version 138,\nprefetch requests to ServiceWorker-controlled URLs are allowed by default when\nthe PrefetchServiceWorker feature is enabled.\n\nIf this policy is enabled or not configured, that default behavior is used.\n\nTo restore the legacy behavior from versions before 138, where prefetch requests\nto ServiceWorker-controlled URLs were blocked, set this policy to disabled.\n\nThis policy is intended to be temporary and will be removed in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.prefetchwithserviceworkerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.prefetchwithserviceworkerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventsmartscreenpromptoverride","displayName":"Prevent bypassing Microsoft Defender SmartScreen prompts for sites","description":"This policy setting lets you decide whether users can override the Microsoft Defender SmartScreen warnings about potentially malicious websites.\n\nIf you enable this setting, users can't ignore Microsoft Defender SmartScreen warnings and they're blocked from continuing to the site.\n\nIf you disable or don't configure this setting, users can ignore Microsoft Defender SmartScreen warnings and continue to the site.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventsmartscreenpromptoverride_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventsmartscreenpromptoverride_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventsmartscreenpromptoverrideforfiles","displayName":"Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads","description":"This policy lets you determine whether users can override Microsoft Defender SmartScreen warnings about unverified downloads.\n\nIf you enable this policy, users in your organization can't ignore Microsoft Defender SmartScreen warnings, and they're prevented from completing the unverified downloads.\n\nIf you disable or don't configure this policy, users can ignore Microsoft Defender SmartScreen warnings and complete unverified downloads.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventsmartscreenpromptoverrideforfiles_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventsmartscreenpromptoverrideforfiles_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventtyposquattingpromptoverride","displayName":"Prevent bypassing Edge Website Typo Protection prompts for sites","description":"This policy setting lets you decide whether users can override the Edge Website Typo Protection warnings about potential typosquatting websites.\n\nIf you enable this setting, users can't ignore Edge Website Typo Protection warnings, and they're blocked from continuing to the site.\n\nIf you disable or don't configure this setting, users can ignore Edge Website Typo Protection warnings and continue to the site.\n\nThis only takes effect when TyposquattingCheckerEnabled policy isn't set or is set to enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventtyposquattingpromptoverride_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventtyposquattingpromptoverride_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill","description":"This feature helps users add an additional layer of privacy to their online accounts by requiring device authentication (as a way of confirming the user's identity) before the saved password is autofilled into a web form. This layer ensures that non-authorized persons can't use saved passwords for autofill. This feature doesn't protect against locally running malware.\n\nThis group policy configures the radio button selector that enables this feature for users. It also has a frequency control where users can specify how often they would like to be prompted for authentication.\n\nIf you set this policy to 'Automatically', disable this policy, or don't configure this policy, autofill won't have any authentication flow.\n\nIf you set this policy to 'WithDevicePassword', users have to enter their device password (or preferred mode of authentication under Windows) to prove their identity before their password is autofilled. Authentication modes include Windows Hello, PIN, face recognition, or fingerprint. The frequency for authentication prompt is set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\n\nIf you set this policy to 'WithCustomPrimaryPassword', users are asked to create their custom password and to be redirected to Settings. After the custom password is set, users can authenticate themselves using the custom password and their passwords get autofilled after successful authentication. The frequency for authentication prompt is set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\n\nIf you set this policy to 'AutofillOff', saved passwords are no longer suggested for autofill.\n\nThe Custom Primary Password feature will be removed with Edge 149. From this version onward, the Custom Primary Password option will no longer be available. Users who currently have this setting enabled will be automatically migrated to the \"Prompt for the device sign-in options\" authentication method. Any associated group policies for Custom Primary Password will also be marked as obsolete.\n\nPolicy options mapping:\n\n* Automatically (0) = Automatically\n\n* WithDevicePassword (1) = With device password\n\n* WithCustomPrimaryPassword (2) = With custom primary password\n\n* AutofillOff (3) = Autofill off\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.primarypasswordsetting_automatically","displayName":"Automatically","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.primarypasswordsetting_withdevicepassword","displayName":"With device password","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.primarypasswordsetting_withcustomprimarypassword","displayName":"With custom primary password","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.primarypasswordsetting_autofilloff","displayName":"Autofill off","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printertypedenylist","displayName":"Disable printer types on the deny list","description":"The printer types on the deny list aren't discovered or have their capabilities fetched.\n\nPlacing all printer types on the deny list effectively disables printing because there's no print destination for documents.\n\nIf you don't configure this policy, or the printer list is empty, all printer types are discoverable.\n\nPrinter destinations include extension printers and local printers. Extension printers are also known as print provider destinations, and include any destination that belongs to a Microsoft Edge extension.\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\n\nIn Microsoft version 93 or later, if you set this policy to 'pdf' it also disables the 'save as Pdf' option from the right click context menu.\n\nIn Microsoft version 103 or later, if you set this policy to 'onedrive' it also disables the 'save as Pdf (OneDrive)' option from print preview.\n\nPolicy options mapping:\n\n* privet (privet) = Zeroconf-based (mDNS + DNS-SD) protocol destinations\n\n* extension (extension) = Extension-based destinations\n\n* pdf (pdf) = The 'Save as PDF' destination. (93 or later, also disables from context menu)\n\n* local (local) = Local printer destinations\n\n* onedrive (onedrive) = Save as PDF (OneDrive) printer destinations. (103 or later)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printertypedenylist_privet","displayName":"Zeroconf-based (mDNS + DNS-SD) protocol destinations","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printertypedenylist_extension","displayName":"Extension-based destinations","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printertypedenylist_pdf","displayName":"The 'Save as PDF' destination. (93 or later, also disables from context menu)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printertypedenylist_local","displayName":"Local printer destinations","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printertypedenylist_onedrive","displayName":"Save as PDF (OneDrive) printer destinations. (103 or later)","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode","description":"Restricts background graphics printing mode. If this policy isn't set there's no restriction on printing background graphics.\n\nPolicy options mapping:\n\n* any (any) = Allow printing with and without background graphics\n\n* enabled (enabled) = Allow printing only with background graphics\n\n* disabled (disabled) = Allow printing only without background graphics\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes_any","displayName":"Allow printing with and without background graphics","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes_enabled","displayName":"Allow printing only with background graphics","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes_disabled","displayName":"Allow printing only without background graphics","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode","description":"Overrides the last used setting for printing background graphics.\nIf you enable this setting, background graphics printing is enabled.\nIf you disable this setting, background graphics printing is disabled.\n\nPolicy options mapping:\n\n* enabled (enabled) = Enable background graphics printing mode by default\n\n* disabled (disabled) = Disable background graphics printing mode by default\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingbackgroundgraphicsdefault_enabled","displayName":"Enable background graphics printing mode by default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingbackgroundgraphicsdefault_disabled","displayName":"Disable background graphics printing mode by default","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingenabled","displayName":"Enable printing","description":"Enables printing in Microsoft Edge and prevents users from changing this setting.\n\nIf you enable this policy or don't configure it, users can print.\n\nIf you disable this policy, users can't print from Microsoft Edge. Printing is disabled in the wrench menu, extensions, JavaScript applications, and so on. Users can still print from plug-ins that bypass Microsoft Edge while printing. For example, certain Adobe Flash applications have the print option in their context menu, which isn't covered by this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingpapersizedefault","displayName":"Default printing page size","description":"Overrides default printing page size.\n\nName should contain one of the listed formats or 'custom' if required paper size isn't in the list. If 'custom' value is provided custom_size property should be specified. It describes the desired height and width in micrometers. Otherwise custom_size property shouldn't be specified. Policy that violates these rules is ignored.\n\nIf the page size is unavailable on the printer chosen by the user, this policy is ignored.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout","displayName":"Sets layout for printing","description":"Configuring this policy sets the layout for printing webpages.\n\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\n\nIf you enable this policy, the selected option is set as the layout option.\n\nPolicy options mapping:\n\n* portrait (0) = Sets layout option as portrait\n\n* landscape (1) = Sets layout option as landscape\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_portrait","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_landscape","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_recommended","displayName":"Sets layout for printing (users can override)","description":"Configuring this policy sets the layout for printing webpages.\n\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\n\nIf you enable this policy, the selected option is set as the layout option.\n\nPolicy options mapping:\n\n* portrait (0) = Sets layout option as portrait\n\n* landscape (1) = Sets layout option as landscape\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_recommended_portrait","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_recommended_landscape","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpdfasimagedefault","displayName":"Print PDF as Image Default","description":"Controls if Microsoft Edge makes the Print as image option the default when printing PDFs.\n\nIf you enable this policy, Microsoft Edge defaults to setting the Print as image option in the Print Preview when printing a PDF.\n\nIf you disable or don't configure this policy, Microsoft Edge won't default to setting the Print as image option in the Print Preview when printing a PDF.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpdfasimagedefault_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpdfasimagedefault_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpostscriptmode","displayName":"Print PostScript Mode","description":"Controls how Microsoft Edge prints on Microsoft Windows.\n\nPrinting to a PostScript printer on Microsoft Windows different PostScript generation methods can affect printing performance.\n\nIf you set this policy to Default, Microsoft Edge uses a set of default options when generating PostScript. Text in particular, is always rendered using Type 3 fonts.\n\nIf you set this policy to Type42, Microsoft Edge renders text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\n\nIf you don't configure this policy, Microsoft Edge remains in Default mode.\n\nPolicy options mapping:\n\n* Default (0) = Default\n\n* Type42 (1) = Type42\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpostscriptmode_default","displayName":"Default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpostscriptmode_type42","displayName":"Type42","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewstickysettings","displayName":"Configure the sticky print preview settings","description":"Configuring this policy sets the print preview settings as the most recent choice in Print Preview instead of the default print preview settings.\n\nEach item of this policy expects a boolean:\n\nLayout specifies if the webpage layout should be kept sticky or not in print preview settings. If you set this to True, the webpage layout uses the recent choice; otherwise, it sets to default value.\n\nSize specifies if the page size should be kept sticky or not in print preview settings. If you set this to True, the page size uses the recent choice; otherwise, it sets to default value.\n\nScale Type specifies if the scaling percentage and scale type should be kept sticky or not in print preview settings. If you set this to True, the scale percentage and scale type both use the recent choice; otherwise, it will set to default value.\n\nMargins specifies if the page margin should be kept sticky or not in print preview settings. If you set this to True, the page margins use the recent choice; otherwise, it sets to default value.\n\nIf you enable this policy, the selected values use the most recent choice in Print Preview.\n\nIf you disable or don't configure this policy, print preview settings aren't impacted.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewstickysettings_recommended","displayName":"Configure the sticky print preview settings (users can override)","description":"Configuring this policy sets the print preview settings as the most recent choice in Print Preview instead of the default print preview settings.\n\nEach item of this policy expects a boolean:\n\nLayout specifies if the webpage layout should be kept sticky or not in print preview settings. If you set this to True, the webpage layout uses the recent choice; otherwise, it sets to default value.\n\nSize specifies if the page size should be kept sticky or not in print preview settings. If you set this to True, the page size uses the recent choice; otherwise, it sets to default value.\n\nScale Type specifies if the scaling percentage and scale type should be kept sticky or not in print preview settings. If you set this to True, the scale percentage and scale type both use the recent choice; otherwise, it will set to default value.\n\nMargins specifies if the page margin should be kept sticky or not in print preview settings. If you set this to True, the page margins use the recent choice; otherwise, it sets to default value.\n\nIf you enable this policy, the selected values use the most recent choice in Print Preview.\n\nIf you disable or don't configure this policy, print preview settings aren't impacted.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewusesystemdefaultprinter","displayName":"Set the system default printer as the default printer","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\n\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\n\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewusesystemdefaultprinter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewusesystemdefaultprinter_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewusesystemdefaultprinter_recommended","displayName":"Set the system default printer as the default printer (users can override)","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\n\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\n\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewusesystemdefaultprinter_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewusesystemdefaultprinter_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printrasterizationmode","displayName":"Print Rasterization Mode","description":"Controls how Microsoft Edge prints on Windows. When printing to a non-PostScript printer on Windows, some print jobs need to be rasterized to print correctly.\n\nIf you set this policy to 'Full' or don't configure it, Microsoft Edge performs full page rasterization if necessary.\n\nIf you set this policy to 'Fast', Microsoft Edge reduces the amount of rasterization, which can decrease print job sizes and increase printing speed.\n\nPolicy options mapping:\n\n* Full (0) = Full page rasterization\n\n* Fast (1) = Avoid rasterization if possible\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printrasterizationmode_full","displayName":"Full page rasterization","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printrasterizationmode_fast","displayName":"Avoid rasterization if possible","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI","description":"Controls print image resolution when Microsoft Edge prints PDFs with rasterization.\n\nWhen printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution significantly increases the processing and printing time while a low resolution can lead to poor imaging quality.\n\nIf you set this policy, it allows a particular resolution to be specified for use when rasterizing PDFs for printing.\n\nIf you set this policy to zero or don't configure it, the system default resolution is used during rasterization of page images.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings","displayName":"Print preview sticky settings","description":"Specifies whether print preview should apply last used settings for Microsoft Edge PDF and webpages.\n\nIf you set this policy to 'EnableAll' or don't configure it, Microsoft Edge applies the last used print preview settings for both PDF and webpages.\n\nIf you set this policy to 'DisableAll', Microsoft Edge doesn't apply the last used print preview settings for both PDF and webpages.\n\nIf you set this policy to 'DisablePdf', Microsoft Edge doesn't apply the last used print preview settings for PDF printing and retains it for webpages.\n\nIf you set this policy to 'DisableWebpage', Microsoft Edge doesn't apply the last used print preview settings for webpage printing and retain it for PDF.\n\nThis policy is only available if you enable or don't configure the \"PrintingEnabled\" policy.\n\nPolicy options mapping:\n\n* EnableAll (0) = Enable sticky settings for PDF and Webpages\n\n* DisableAll (1) = Disable sticky settings for PDF and Webpages\n\n* DisablePdf (2) = Disable sticky settings for PDF\n\n* DisableWebpage (3) = Disable sticky settings for Webpages\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_enableall","displayName":"Enable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_disableall","displayName":"Disable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_disablepdf","displayName":"Disable sticky settings for PDF","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_disablewebpage","displayName":"Disable sticky settings for Webpages","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthenabled","displayName":"Enable Proactive Authentication (Obsolete)","description":"This policy is obsolete because it doesn't work independently of browser sign in. It doesn't work in Microsoft Edge after version 90. If you want to configure browser sign in, use the \"BrowserSignin\" policy.\n\nLets you configure whether to turn on Proactive Authentication in Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge tries to seamlessly authenticate to websites and services using the account which is signed-in to the browser.\n\nIf you disable this policy, Microsoft Edge doesn't try to authenticate with websites or services using single sign-on (SSO). Authenticated experiences like the Enterprise New Tab Page won't work (for example, recent and recommended Office documents will not be available).\n\nIf you don't configure this policy, Proactive Authentication is turned on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthworkflowenabled","displayName":"Enable proactive authentication","description":"This policy controls the proactive authentication in Microsoft Edge, that connects the signed-in user identity with Microsoft Bing, MSN and Copilot services for a smooth and consistent sign-in experience.\n\nIf you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser.\n\nIf you disable this policy, Microsoft Edge doesn't send authentications requests to these services, and users need to manually sign-in.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthworkflowenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthworkflowenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.promptfordownloadlocation","displayName":"Ask where to save downloaded files","description":"Set whether to ask where to save a file before downloading it.\n\nIf you enable this policy, the user is asked where to save each file before downloading; if you don't configure it, files are saved automatically to the default location, without asking the user.\n\nIf you don't configure this policy, the user can change this setting.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.promptfordownloadlocation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.promptfordownloadlocation_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.promptonmultiplematchingcertificates","displayName":"Prompt the user to select a certificate when multiple certificates match","description":"This policy controls whether the user is prompted to select a client certificate when more than one certificate matches \"AutoSelectCertificateForUrls\".\nIf this policy is set to True, the user is prompted to select a client certificate whenever the auto-selection policy matches multiple certificates.\nIf this policy is set to False or not set, the user may only be prompted when no certificate matches the auto-selection.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.promptonmultiplematchingcertificates_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.promptonmultiplematchingcertificates_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.protectedcontentidentifiersallowed","displayName":"Allows web pages to use identifiers for the purpose of protected content playback","description":"This policy controls whether sites can use hardware-specific device identifiers to enable hardware-secure DRM (for example, Widevine L1 or PlayReady SL3000), which may be required for high-resolution protected content playback.\n\nIf you enable this policy or do not configure it, sites are allowed to use protected content identifiers.\n\nIf you disable this policy, sites are not allowed to use protected content identifiers.","helpText":null,"infoUrls":[],"categoryId":"2af24920-f611-4f03-99a6-205773869ae6","categoryName":"Protected Content","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.protectedcontentidentifiersallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.protectedcontentidentifiersallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxybypasslist","displayName":"Configure proxy bypass rules (Deprecated)","description":"This policy is deprecated, use \"ProxySettings\" instead. It doesn't work in Microsoft Edge version 91.\n\nDefines a list of hosts for which Microsoft Edge bypasses any proxy.\n\nThis policy is applied only if the \"ProxySettings\" policy isn't specified and you selected either fixed_servers or pac_script in the \"ProxyMode\" policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, you can create a list of hosts for which Microsoft Edge doesn't use a proxy.\n\nIf you don't configure this policy, no list of hosts is created for which Microsoft Edge bypasses a proxy. Leave this policy unconfigured if you specified any other method for setting proxy policies.\n\nFor more detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode","displayName":"Configure proxy server settings (Deprecated)","description":"This policy is deprecated and doesn't work in Microsoft Edge version 91. Use \"ProxySettings\" instead.\n\nIf you set this policy to Enabled, you can specify the proxy server Microsoft Edge uses and prevents users from changing proxy settings. Microsoft Edge ignores all proxy-related options specified from the command line. The policy is only applied if the \"ProxySettings\" policy isn't specified.\n\nOther options are ignored if you choose one of the following options:\n * direct = Never use a proxy server and always connect directly\n * system = Use system proxy settings\n * auto_detect = Auto detect the proxy server\n\nIf you choose to use:\n * fixed_servers = Fixed proxy servers. You can specify further options with \"ProxyServer\" and \"ProxyBypassList\".\n * pac_script = A .pac proxy script. Use \"ProxyPacUrl\" to set the URL to a proxy .pac file.\n\nFor detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.\n\nIf you don't configure this policy, users can choose their own proxy settings.\n\nPolicy options mapping:\n\n* ProxyDisabled (direct) = Never use a proxy\n\n* ProxyAutoDetect (auto_detect) = Auto detect proxy settings\n\n* ProxyPacScript (pac_script) = Use a .pac proxy script\n\n* ProxyFixedServers (fixed_servers) = Use fixed proxy servers\n\n* ProxyUseSystem (system) = Use system proxy settings\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxydisabled","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxyautodetect","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxypacscript","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxyfixedservers","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxyusesystem","displayName":"Use system proxy settings","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxyoverriderules","displayName":"Proxy override rules","description":"This policy enables rule-based proxy selection that determines which proxy Microsoft Edge uses based on the destination URL and any other conditions you define.\n\nWhen this policy is configured, it takes precedence over proxy settings configured by the ProxySettings policy, the Edge.proxy extension API, and any manual user settings.\n\nIf this policy is disabled or not configured, existing proxy policies and user-defined settings continue to apply.\n\nWhen Edge selects a proxy, it evaluates entries in the ProxyOverrideRules policy in order. A rule is considered a match when all the following conditions are met:\n* At least one URL pattern in DestinationMatchers is matched.\n* No URL pattern in ExcludeDestinationMatchers is matched.\n* If Conditions is specified and non-empty, all conditions are satisfied.\n\nFor a matching rule, the value specified in ProxyList is used as the proxy. If no rule matches, proxy selection falls back to the settings defined by the ProxySettings policy.\n\nThe URL patterns supported by DestinationMatchers and ExcludeDestinationMatchers are documented at https://review.learn.microsoft.com/en-us/DeployEdge/configure-microsoft-edge-proxy-support?branch=pr-en-us-6681#proxy-config-url-patterns .\nEntries in ProxyList correspond to PAC-style proxy strings, such as:\n* DIRECT\n* PROXY host:port\n* HTTPS host:port\n* SOCKS4 host:port\n* SOCKS5 host:port\n\nAlternatively, URL-form proxy specifiers can be used, for example:\n* http://host :port\n* https://host :port\n* socks4://host:port\n* socks5://host:port\n\nThe first reachable proxy in the list is used. Invalid entries are ignored.\n\nThe Conditions field specifies conditions that must all be met for an override rule to be applied when selecting a proxy. If this field is not set, the rule is applied when at least one host in DestinationMatchers matches.\n\nThe DnsProbe condition checks whether the specified DNS Host can be resolved to an IP address. The host must include a hostname (for example, example.com) and can optionally include a scheme or port (for example, https://example.com, example.com:123, or https://example.com:123). When a secure scheme (for example, https) is specified, the DNS lookup may also request the HTTPS record (see RFC 9460).\n\nIf Result is set to resolved, the condition is met when resolution succeeds. If set to not_found, the condition is met only when resolution fails.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxypacurl","displayName":"Set the proxy .pac file URL (Deprecated)","description":"This policy is deprecated; use \"ProxySettings\" instead. It doesn't work in Microsoft Edge version 91.\n\nSpecifies the URL for a proxy auto-config (PAC) file.\n\nThis policy is applied only if the \"ProxySettings\" policy isn't specified, and if you've selected pac_script in the \"ProxyMode\" policy. If you've selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, specify the URL for a PAC file, which defines how the browser automatically chooses the appropriate proxy server for fetching a particular website.\n\nIf you disable or don't configure this policy, no PAC file is specified. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\n\nFor detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxyserver","displayName":"Configure address or URL of proxy server (Deprecated)","description":"This policy is deprecated, use \"ProxySettings\" instead. It doesn't work in Microsoft Edge version 91.\n\nSpecifies the URL of the proxy server.\n\nThis policy is applied only if the \"ProxySettings\" policy isn't specified and you selected fixed_servers in the \"ProxyMode\" policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, the proxy server configured by this policy is used for all URLs.\n\nIf you disable or don't configure this policy, users can choose their own proxy settings while in this proxy mode. Leave this policy unconfigured if you specified any other method for setting proxy policies.\n\nFor more options and detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxysettings","displayName":"Proxy settings","description":"Configures the proxy settings for Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge ignores all proxy-related options specified from the command line.\n\nIf you don't configure this policy, users can choose their own proxy settings.\n\nThis policy overrides the following individual policies:\n\n\"ProxyMode\"\n\n\"ProxyPacUrl\"\n\n\"ProxyServer\"\n\n\"ProxyBypassList\"\n\nSetting the \"ProxySettings\" policy accepts the following fields:\n\n* ProxyMode, which lets you specify the proxy server used by Microsoft Edge and prevents users from changing proxy settings\n\n* ProxyPacUrl, a URL to a proxy .pac file or a PAC script encoded as a data URL with MIME type application/x-ns-proxy-autoconfig\n\n* ProxyPacMandatory, a boolean flag that prevents the network stack from falling back to direct connections with invalid or unavailable PAC script\n\n* ProxyServer, a URL for the proxy server\n\n* ProxyBypassList, a list of proxy hosts that Microsoft Edge bypasses\n\nFor ProxyMode, the following values when chosen lead to the following results:\n\n* direct, a proxy is never used and all other fields are ignored.\n\n* system, the systems's proxy is used and all other fields are ignored.\n\n* auto_detect, all other fields are ignored.\n\n* fixed_servers, the ProxyServer and ProxyBypassList fields are used.\n\n* pac_script, the ProxyPacUrl, ProxyPacMandatory and ProxyBypassList fields are used.\n\nFor more detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu","displayName":"Enables Microsoft Edge mini menu","description":"Enables the Microsoft Edge mini menu on websites and PDFs. The mini menu appears when users select text and provides basic actions like Copy and smart actions such as Definitions.\n\nIf you enable or don't configure this policy, selecting text on websites or PDFs shows the mini menu.\n\nIf you disable this policy, the mini menu doesn't appear when users select text on websites or PDFs.\n\nNote: Starting in Microsoft Edge for Mac version 143, this policy is obsolete because the mini menu feature is removed on Mac.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_recommended","displayName":"Enables Microsoft Edge mini menu (users can override)","description":"Enables the Microsoft Edge mini menu on websites and PDFs. The mini menu appears when users select text and provides basic actions like Copy and smart actions such as Definitions.\n\nIf you enable or don't configure this policy, selecting text on websites or PDFs shows the mini menu.\n\nIf you disable this policy, the mini menu doesn't appear when users select text on websites or PDFs.\n\nNote: Starting in Microsoft Edge for Mac version 143, this policy is obsolete because the mini menu feature is removed on Mac.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quickviewofficefilesenabled","displayName":"Manage QuickView Office files capability in Microsoft Edge","description":"Allows you to set whether users can view publicly accessible Office files on the web that aren't on OneDrive or SharePoint. (For example: Word documents, PowerPoint presentations, and Excel spreadsheets)\n\nIf you enable or don't configure this policy, these files can be viewed in Microsoft Edge using Office Viewer instead of downloading the files.\n\nIf you disable this policy, these files are downloaded to be viewed.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.quickviewofficefilesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quickviewofficefilesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.readaloudenabled","displayName":"Enable Read Aloud feature in Microsoft Edge","description":"Enables the Read Aloud feature within Microsoft Edge.\nWith this feature, users can listen to the content on the web page. This feature enables users to multi-task or improve their reading comprehension by hearing content at their own pace.\n\nIf you enable this policy or don't configure it, the Read Aloud option shows up in the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.\nIf you disable this policy, users can't access the Read Aloud feature from the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.readaloudenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.readaloudenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.registeredprotocolhandlers","displayName":"Register protocol handlers","description":"Set this policy (recommended only) to register a list of protocol handlers. This list is merged with ones registered by the user and both are available to use.\n\nTo register a protocol handler:\n\n- Set the protocol property to the scheme (for example, \"mailto\")\n- Set the URL property to the URL property of the application that handlers the scheme specified in the \"protocol\" field. The pattern can include a \"%s\" placeholder, which the handled URL replaces.\n\nUsers can't remove a protocol handler registered by this policy. However, they can install a new default protocol handler to override the existing protocol handlers.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.registeredprotocolhandlers_recommended","displayName":"Register protocol handlers (users can override)","description":"Set this policy (recommended only) to register a list of protocol handlers. This list is merged with ones registered by the user and both are available to use.\n\nTo register a protocol handler:\n\n- Set the protocol property to the scheme (for example, \"mailto\")\n- Set the URL property to the URL property of the application that handlers the scheme specified in the \"protocol\" field. The pattern can include a \"%s\" placeholder, which the handled URL replaces.\n\nUsers can't remove a protocol handler registered by this policy. However, they can install a new default protocol handler to override the existing protocol handlers.\n\nIn the examples in this section, the URL points to the Outlook on the Web (OWA) endpoint used in Exchange Online. If you're targeting Exchange Server (on-premises), use the following URL and replace mail.contoso.com with your organization's OWA endpoint:\n\nhttps://mail.contoso.com/?path=/mail/action/compose&mailtouri=%s","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedmatchescloudserviceenabled","displayName":"Configure Related Matches in Find on Page (Obsolete)","description":"Specifies how the user receives related matches in Find on Page, which provides spellcheck, synonyms, and Q&A results in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can receive related matches in Find on Page on all sites. The results are processed through a cloud service.\n\nIf you disable this policy, users can receive related matches in Find on Page on a limited set of sites. In this case, results are processed locally on the user's device.\n\nNote: This policy is obsolete. The associated cloud service is discontinued, so the feature and policy aren't supported on any versions of Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedmatchescloudserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedmatchescloudserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedwebsitesetsenabled","displayName":"Enable Related Website Sets (Deprecated)","description":"This policy lets you control the enablement of the Related Website Sets feature. Related Website Sets (RWS) is a way for an organisation to declare relationships among sites, so that Microsoft Edge allows limited third-party cookie access for specific purposes across those sites.\n\nIf this policy set to True or unset, the Related Website Sets feature is enabled.\n\nIf this policy is set to False, the Related Website Sets feature is disabled.\n\nThis policy is deprecated as of Microsoft Edge version 144 with the deprecation of Related Website Sets.","helpText":null,"infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedwebsitesetsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedwebsitesetsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (Deprecated)","description":"This policy provides a way to override the list of sets Microsoft Edge uses for Related Website Sets\n\nEach set in the browser's list of Related Website Sets must meet the requirements of a Related Website Set. A Related Website Set must contain a primary site and one or more member sites.\nA set can also contain a list of service sites that it owns, and a map from a site to all its ccTLD variants. For more information on how Microsoft Edge uses Related Website Sets, see https://github.com/WICG/first-party-sets.\n\n\nAll sites in a Related Website Set must be a registrable domain served over HTTPS. Each site in a Related Website Set must also be unique, which means a site can't be listed more than once in a Related Website Set.\n\nWhen this policy is given an empty dictionary, Microsoft Edge uses the public list of Related Website Sets.\n\nFor all sites in a Related Website Set from the replacements list, if a site is also present on a Related Website Set in the browser's list, then that site will be removed from the browser's Related Website Set. After this step, the policy's Related Website Set is added to the Microsoft Edge's list of Related Website Sets.\n\nFor all sites in a Related Website Set from the additions list, if a site is also present on a Related Website Set in Microsoft Edge's list, then the browser's Related Website Set is updated so that the new Related Website Set can be added to the browser's list. After the browser's list has been updated, the policy's Related Website Set is added to the browser's list of Related Website Sets.\n\nThe browser's list of Related Website Sets requires that for all sites in its list, no site is in\nmore than one set. This requirement is also required for both the replacements list\nand the additions list. Similarly, a site can't be in both the\nreplacements list and the additions list.\n\nWildcards (*) aren't supported as a policy value, or as a value within any Related Website Set in these lists.\n\nThis policy is deprecated as of Microsoft Edge version 144 with the deprecation of Related Website Sets.","helpText":null,"infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.resolvenavigationerrorsusewebservice","displayName":"Enable resolution of navigation errors using a web service","description":"Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi.\n\nIf you enable this policy, a web service is used for network connectivity tests.\n\nIf you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues.\n\n**Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues.\n\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\nSpecifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.resolvenavigationerrorsusewebservice_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.resolvenavigationerrorsusewebservice_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.resolvenavigationerrorsusewebservice_recommended","displayName":"Enable resolution of navigation errors using a web service (users can override)","description":"Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi.\n\nIf you enable this policy, a web service is used for network connectivity tests.\n\nIf you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues.\n\n**Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues.\n\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\nSpecifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.resolvenavigationerrorsusewebservice_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.resolvenavigationerrorsusewebservice_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup","displayName":"Action to take on Microsoft Edge startup","description":"Specify how Microsoft Edge behaves when it starts.\n\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\n\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session is restored as it was. This option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\n\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\n\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\n\nDisabling this setting is the same as leaving it not configured. Users can change it in Microsoft Edge.\n\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\n\nPolicy options mapping:\n\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\n\n* RestoreOnStartupIsLastSession (1) = Restore the last session\n\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\n\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupisnewtabpage","displayName":"Open a new tab","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupislastsession","displayName":"Restore the last session","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupisurls","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupislastsessionandurls","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_recommended","displayName":"Action to take on Microsoft Edge startup (users can override)","description":"Specify how Microsoft Edge behaves when it starts.\n\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\n\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session is restored as it was. This option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\n\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\n\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\n\nDisabling this setting is the same as leaving it not configured. Users can change it in Microsoft Edge.\n\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\n\nPolicy options mapping:\n\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\n\n* RestoreOnStartupIsLastSession (1) = Restore the last session\n\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\n\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_recommended_restoreonstartupisnewtabpage","displayName":"Open a new tab","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_recommended_restoreonstartupislastsession","displayName":"Restore the last session","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_recommended_restoreonstartupisurls","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_recommended_restoreonstartupislastsessionandurls","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartupurls","displayName":"Sites to open when the browser starts","description":"Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup.\n\nThis policy only works if you also set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4).\n\nThis policy is available only on specific Windows instances. These instances include devices that are joined to a Microsoft Active Directory domain, devices joined to Microsoft Azure Active Directory`, or devices enrolled for device management.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartupurls_recommended","displayName":"Sites to open when the browser starts (users can override)","description":"Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup.\n\nThis policy only works if you also set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4).\n\nThis policy is available only on specific Windows instances. These instances include devices that are joined to a Microsoft Active Directory domain, devices joined to Microsoft Azure Active Directory`, or devices enrolled for device management.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartupuserurlsenabled","displayName":"Allow users to add and remove their own sites during startup when the RestoreOnStartupURLs policy is configured.","description":"This policy only works if you set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4) and the RestoreOnStartupURLs policy as mandatory.\nIf you enable this policy, users are allowed to add and remove their own URLs to open when starting Microsoft Edge while maintaining the admin specified mandatory list of sites specified by setting \"RestoreOnStartup\" policy to open a list of URLS and providing the list of sites in the RestoreOnStartupURLs policy.\n\nIf you disable or don't configure this policy, there's no change to how the \"RestoreOnStartup\" and RestoreOnStartupURLs policies work.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartupuserurlsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartupuserurlsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restorepdfview","displayName":"Restore PDF view","description":"Enables PDF View Recovery in Microsoft Edge.\n\nIf you enable or don't configure this policy, Microsoft Edge recovers the last state of PDF view and lands users to the section where they ended reading in the last session.\n\nIf you disable this policy, Microsoft Edge recovers the last state of PDF view and lands users at the start of the PDF file.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.restorepdfview_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restorepdfview_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.runallflashinallowmode","displayName":"Extend Adobe Flash content setting to all content (Obsolete)","description":"This policy doesn't work because Flash is no longer supported by Microsoft Edge.\n\nIf you enable this policy, all Adobe Flash content embedded in websites that are set to allow Adobe Flash in the content settings, either by the user or by enterprise policy, run. This includes content from other origins and/or small content.\n\nTo control which websites are allowed to run Adobe Flash, see the specifications in the \"DefaultPluginsSetting\", \"PluginsAllowedForUrls\", and \"PluginsBlockedForUrls\" policies.\n\nIf you disable this policy or don't configure it, Adobe Flash content from other origins (sites that aren't specified in the preceding three policies) or small content might be blocked.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.runallflashinallowmode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.runallflashinallowmode_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sameorigintabcaptureallowedbyorigins","displayName":"Allow Same Origin Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin.\n\nLeaving the policy unset means that sites won't be considered for an override at this scope of capture.\n\nIf a site matches a URL pattern in this policy, the following policies won't be considered: \"TabCaptureAllowedByOrigins\", \"WindowCaptureAllowedByOrigins\", \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sandboxexternalprotocolblocked","displayName":"Allow Microsoft Edge to block navigations to external protocols in a sandboxed iframe","description":"Microsoft Edge blocks navigations to external protocols inside a sandboxed iframe.\n\nIf you enable or don't configure this policy, Microsoft Edge blocks those navigations.\n\nIf you disable this policy, Microsoft Edge doesn't block those navigations.\n\nThis policy can be used by administrators who need more time to update their internal website affected by this new restriction. This Enterprise policy is temporary; it's intended to be removed after Microsoft Edge version 117.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sandboxexternalprotocolblocked_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sandboxexternalprotocolblocked_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.savecookiesonexit","displayName":"Save cookies when Microsoft Edge closes","description":"When this policy is enabled, the specified set of cookies is exempt from deletion when the browser closes. This policy is only effective when:\n- The 'Cookies and other site data' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\n- The policy \"ClearBrowsingDataOnExit\" is enabled or\n- The policy \"DefaultCookiesSetting\" is set to 'Keep cookies for the duration of the session'.\n\nYou can define a list of sites, based on URL patterns, that have their cookies preserved across sessions.\n\nNote: Users can still edit the cookie site list to add or remove URLs. However, they can't remove URLs that are added by an Admin.\n\nIf you enable this policy, the list of cookies aren't cleared when the browser closes.\n\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.savingbrowserhistorydisabled","displayName":"Disable saving browser history","description":"Disables saving browser history and prevents users from changing this setting.\n\nIf you enable this policy, browsing history isn't saved. This also disables tab syncing.\n\nIf you disable this policy or don't configure it, browsing history is saved.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.savingbrowserhistorydisabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.savingbrowserhistorydisabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.scarewareblockerallowlistdomains","displayName":"Configure the list of domains where Microsoft Edge Scareware blockers don't run","description":"This policy configures the list of trusted domains for Microsoft Edge Scareware blocker. When a website's source URL matches any domain in this list, Microsoft Edge Scareware blocker doesn't analyze that site.\n\nThis policy takes effect only if the ScarewareBlockerProtectionEnabled policy is enabled.\n\nIf you enable this policy, Microsoft Edge Scareware blocker trusts the specified domains.\n\nIf you disable or don't configure this policy, Microsoft Edge Scareware blocker analyzes all sites.","helpText":null,"infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowed","displayName":"Allow or deny screen capture","description":"If you enable this policy, or don't configure this policy, a webpage uses screen-share APIs (for example, getDisplayMedia() or the Desktop Capture extension API) for a screen capture.\nIf you disable this policy, calls to screen-share APIs fail. For example, if you're using a web-based online meeting, video or screen sharing won't work. However, this policy isn't considered.\n(and a site will be allowed to use screen-share APIs) if the site matches an origin pattern in any of the following policies:\n\"ScreenCaptureAllowedByOrigins\",\n\"WindowCaptureAllowedByOrigins\",\n\"TabCaptureAllowedByOrigins\",\n\"SameOriginTabCaptureAllowedByOrigins\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowedbyorigins","displayName":"Allow Desktop, Window, and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture.\n\nLeaving the policy unset means that sites won't be considered for an override at this scope of Capture.\n\nThis policy isn't considered if a site matches a URL pattern in any of the following policies: \"WindowCaptureAllowedByOrigins\", \"TabCaptureAllowedByOrigins\", \"SameOriginTabCaptureAllowedByOrigins\".\n\nIf a site matches a URL pattern in this policy, the \"ScreenCaptureAllowed\" isn't considered.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencapturewithoutgestureallowedfororigins","displayName":"Allow screen capture without prior user gesture","description":"For security reasons, the\ngetDisplayMedia() web API requires\na prior user gesture (\"transient activation\") to be called or the API\nfails.\n\nWhen this policy is configured, admins can specify origins on which this API\ncan be called without prior user gesture.\n\nFor detailed information on valid url patterns, see\nhttps://go.microsoft.com/fwlink/?linkid=2095322. Note: * isn't an accepted\nvalue for this policy.\n\nIf this policy isn't configured, all origins require a prior user gesture to\ncall this API.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\n\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL is enabled.\n\nIf you disable this policy, web page scrolling to specific text fragments via a URL is disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.scrolltotextfragmentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.scrolltotextfragmentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled","displayName":"Search Filters Enabled","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions are shown.\n\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\n\nIf you disable this policy, the autosuggestion dropdown can't display the ribbon of available filters.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_recommended","displayName":"Search Filters Enabled (users can override)","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions are shown.\n\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\n\nIf you disable this policy, the autosuggestion dropdown can't display the ribbon of available filters.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchforimageenabled","displayName":"Search for image enabled","description":"This policy lets you configure the Image Search feature in the right-click context menu.\n\nIf you enable or don't configure this policy, then the \"Search the web for image\" option is visible in the context menu.\n\nIf you disable this policy, then the \"Search the web for image\" won't be visible in the context menu.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchforimageenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchforimageenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchinsidebarenabled","displayName":"Search in Sidebar enabled","description":"Search in Sidebar allows users to open search result in sidebar (including sidebar search for Progressive Web Apps).\n\nIf you configure this policy to 'EnableSearchInSidebar' or don't configure it, Search in sidebar is enabled.\n\nIf you configure this policy to 'DisableSearchInSidebarForKidsMode', Search in sidebar is disabled when in Kids mode. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\n\nIf you configure this policy to 'DisableSearchInSidebar', Search in sidebar is disabled. Some methods that would invoke sidebar search invoke a traditional search instead.\n\nPolicy options mapping:\n\n* EnableSearchInSidebar (0) = Enable search in sidebar\n\n* DisableSearchInSidebarForKidsMode (1) = Disable search in sidebar for Kids Mode\n\n* DisableSearchInSidebar (2) = Disable search in sidebar\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchinsidebarenabled_enablesearchinsidebar","displayName":"Enable search in sidebar","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchinsidebarenabled_disablesearchinsidebarforkidsmode","displayName":"Disable search in sidebar for Kids Mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchinsidebarenabled_disablesearchinsidebar","displayName":"Disable search in sidebar","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled","displayName":"Enable search suggestions","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\n\nIf you enable this policy, web search suggestions are used.\n\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\n\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_recommended","displayName":"Enable search suggestions (users can override)","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\n\nIf you enable this policy, web search suggestions are used.\n\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\n\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.securitykeypermitattestation","displayName":"Websites or domains that don't need permission to use direct Security Key attestation","description":"Specifies the WebAuthn RP IDs that don't need explicit user permission when attestation certificates from security keys are requested. Additionally, a signal is sent to the security key indicating that it can use enterprise attestation. Without this policy, users are prompted each time a site requests attestation of security keys.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.selectparserrelaxationenabled","displayName":"Controls whether the new HTML parser behavior for the element. This policy supports the old HTML parser behavior through Microsoft Edge version 138.\n\nIf this policy is enabled or unset, the HTML parser allows additional tags inside the element.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.selectparserrelaxationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.selectparserrelaxationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sendintranettointernetexplorer","displayName":"Send all intranet sites to Internet Explorer","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sendintranettointernetexplorer_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sendintranettointernetexplorer_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sendmouseeventsdisabledformcontrolsenabled","displayName":"Control the new behavior for event dispatching on disabled form controls (Obsolete)","description":"Event dispatching on disabled form controls is being changed in Microsoft Edge to improve compatibility with other browsers and to improve the developer experience.\n\nWith this change, MouseEvents get dispatched on disabled form control elements. Exceptions for this behavior are click, mouseup, and mousedown. Some examples of the new events are mousemove, mouseenter, and mouseleave.\n\nThis change also truncates the event path of click, mouseup, and mousedown when they’re dispatched on children of disabled form controls. These events aren’t dispatched on the disabled form control or on any of its ancestors.\n\nNote: This new behavior might break some websites.\n\nIf you enable or don't configure this policy, the new behavior is used.\n\nIf you disable this policy, the old behavior is used.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sendmouseeventsdisabledformcontrolsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sendmouseeventsdisabledformcontrolsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sensorsallowedforurls","displayName":"Allow access to sensors on specific sites","description":"Define a list of sites, based on URL patterns, that can access and use sensors such as motion and light sensors.\n\nIf you don't configure this policy, the global default value from the \"DefaultSensorsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor URL patterns that don't match this policy, the following order of precedence is used: The \"SensorsBlockedForUrls\" policy (if there's a match), the \"DefaultSensorsSetting\" policy (if set), or the user's personal settings.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"SensorsBlockedForUrls\" policy. You can't allow and block a URL.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sensorsblockedforurls","displayName":"Block access to sensors on specific sites","description":"Define a list of sites, based on URL patterns, that can't access sensors such as motion and light sensors.\n\nIf you don't configure this policy, the global default value from the \"DefaultSensorsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor URL patterns that don't match this policy, the following order of precedence is used: The \"SensorsAllowedForUrls\" policy (if there's a match), the \"DefaultSensorsSetting\" policy (if set), or the user's personal settings.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"SensorsAllowedForUrls\" policy. You can't allow and block a URL.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serialaskforurls","displayName":"Allow the Serial API on specific sites","description":"Specifies URL patterns for sites that are allowed to request access to a serial port.\n\nIf not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings.\n\nFor unmatched sites, the following order applies:\n\n1. \"SerialBlockedForUrls\" (if matched).\n\n2. DefaultSerialGuardSetting (if set).\n\n3. User's settings.\n\nIf URL patterns in this policy conflict with those in \"SerialBlockedForUrls\", they're ignored.\n\nFor detailed information about valid URL patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serialblockedforurls","displayName":"Block the Serial API on specific sites","description":"Specifies URL patterns for sites that aren't allowed to request access to a serial port.\n\nIf not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings.\n\nFor unmatched sites, the following order applies:\n\n1. SerialAskForUrls (if matched).\n\n2. DefaultSerialGuardSetting (if set).\n\n3. User's settings.\n\nURL patterns in this policy must not conflict with those in SerialAskForUrls. This policy takes precedence.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup","description":"This policy controls whether Microsoft Edge enables the ServiceWorkerAutoPreload feature.\n\nIf you enable or don't configure this policy, Microsoft Edge can initiate the main resource network request concurrently with the Service Worker bootstrap process. This can improve performance in scenarios where the Service Worker isn't already running.\n\nIf you disable this policy, Microsoft Edge will wait to dispatch the navigation request until after the Service Worker starts.\n\nThis is a temporary policy and is removed in version 144 of Microsoft Edge.\n\nFor more information on the feature, see https://github.com/WICG/service-worker-auto-preload.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkerautopreloadenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkerautopreloadenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkertocontrolsrcdociframeenabled","displayName":"Allow ServiceWorker to control srcdoc iframes","description":"https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with the \"allow-same-origin\" sandbox attribute to be under ServiceWorker control.\n\nBy default (if left unset) or when set to Enabled, Microsoft Edge makes srcdoc iframes with \"allow-same-origin\" sandbox attributes to be under ServiceWorker control.\n\nSetting the policy to Disabled prevents ServiceWorker control over srcdoc iframes.\n\nThis policy is temporary and planned for deprecation in 2026.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkertocontrolsrcdociframeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkertocontrolsrcdociframeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover","description":"This policy sets the default feed tab on the New Tab Page to Work or Discover.\n\nIf you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work.\n\nIf you set this policy to 'Discover' (1), Microsoft Edge sets the default feed tab to Discover.\n\nThis policy only takes effect when \"ConfigureNTPFeedTabVisibility\" is set to 'EnableBothWorkDiscover' (0) or is not configured. If only one tab is visible, this policy has no effect.\n\nPolicy options mapping:\n\n* NTPDefaultFeedTabWork (0) = Work\n\n* NTPDefaultFeedTabDiscover (1) = Discover\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_ntpdefaultfeedtabwork","displayName":"Work","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_ntpdefaultfeedtabdiscover","displayName":"Discover","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_recommended","displayName":"Set the default New Tab Page feed tab to Work or Discover (users can override)","description":"This policy sets the default feed tab on the New Tab Page to Work or Discover.\n\nIf you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work.\n\nIf you set this policy to 'Discover' (1), Microsoft Edge sets the default feed tab to Discover.\n\nThis policy only takes effect when \"ConfigureNTPFeedTabVisibility\" is set to 'EnableBothWorkDiscover' (0) or is not configured. If only one tab is visible, this policy has no effect.\n\nPolicy options mapping:\n\n* NTPDefaultFeedTabWork (0) = Work\n\n* NTPDefaultFeedTabDiscover (1) = Discover\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_recommended_ntpdefaultfeedtabwork","displayName":"Work","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_recommended_ntpdefaultfeedtabdiscover","displayName":"Discover","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.settimeoutwithout1msclampenabled","displayName":"Control Javascript setTimeout() function minimum timeout (Obsolete)","description":"This policy is obsolete and doesn't work in Microsoft Edge after version 109.\nThis policy was only provided temporarily to allow Enterprises to adapt to the new clamping behavior.\n\n If you enable this policy, the JavaScript setTimeout() with a timeout of 0 ms is no longer fixed to 1 ms to schedule timer-based callbacks.\n If you disable this policy, the JavaScript setTimeout() with a timeout of 0 ms is fixed to 1 ms to schedule timer-based callbacks.\n If you don't configure this policy, use the browser's default behavior for setTimeout() function.\n\n This is a web standards compliancy feature; however, it may change task ordering on a webpage, leading to unexpected behavior on sites that are dependent on a certain ordering.\n It also affects sites with many setTimeout()s with a timeout of 0-ms usage, for example, increasing CPU load.\n\n For users where this policy is unset, Microsoft Edge Stable rolls out the change gradually on the stable channel.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.settimeoutwithout1msclampenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.settimeoutwithout1msclampenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharebrowsinghistorywithcopilotsearchallowed","displayName":"Allow sharing tenant-approved browsing history with Microsoft 365 Copilot Search","description":"This policy controls whether browsing history in Microsoft Edge is shared with Microsoft 365 Copilot Search to provide more relevant search results. Only tenant-approved, work-related sites are shared.\n\nThis feature is available only to users who are signed in to Microsoft Edge with an Entra ID account and have an eligible Microsoft 365 Copilot license.\n\nIf you enable or don't configure this policy, browsing history will be shared with Microsoft 365 Copilot Search by default, and users can turn off sharing using the toggle in Microsoft Edge settings.\n\nIf you disable this policy, browsing history won't be shared with Microsoft 365 Copilot Search.\n\nLearn more about how Copilot uses data and consent at https://go.microsoft.com/fwlink/?linkid=2333202","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharebrowsinghistorywithcopilotsearchallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharebrowsinghistorywithcopilotsearchallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedarraybufferunrestrictedaccessallowed","displayName":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context","description":"Specifies whether SharedArrayBuffers can be used in a non-cross-origin-isolated context. A SharedArrayBuffer is a binary data buffer that's used to create views on shared memory. SharedArrayBuffers have a memory access vulnerability in several popular CPUs.\n\nIf you enable this policy, sites are allowed to use SharedArrayBuffers with no restrictions.\n\nIf you disable or don't configure this policy, sites are allowed to use SharedArrayBuffers only when cross-origin isolated.\n\nMicrosoft Edge requires cross-origin isolation when using SharedArrayBuffers from Microsoft Edge version 91 onward for Web Compatibility reasons.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedarraybufferunrestrictedaccessallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedarraybufferunrestrictedaccessallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedworkerbloburlfixenabled","displayName":"Make SharedWorker blob URL behavior aligned with the specification","description":"According to Service Worker specification\nhttps://w3c.github.io/ServiceWorker/#control-and-use-worker-client, workers\nshould inherit controllers for blob URLs. Currently, only DedicatedWorkers\ninherit the controller, while SharedWorkers do not.\n\nEnabled/Unset: Microsoft Edge inherits\nthe controller for SharedWorker blob URLs, aligning with the specification.\n\nDisabled: Behavior remains unchanged, not aligning with the specification.\n\nThis policy is temporary and will be removed in a future update.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedworkerbloburlfixenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedworkerbloburlfixenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedworkerextendedlifetimeenabled","displayName":"Enable the extended lifetime option for SharedWorkers","description":"Controls whether Microsoft Edge allows SharedWorkers to use the extendedLifetime option.\n\nIf you enable or don't configure this policy, SharedWorkers can use the extended lifetime option in the SharedWorker constructor.\n\nIf you disable this policy, the extended lifetime option is ignored, even if it is requested by the page.\n\nThis policy is temporary and will be removed in a future release.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedworkerextendedlifetimeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedworkerextendedlifetimeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showacrobatsubscriptionbutton","displayName":"Shows button on native PDF viewer in Microsoft Edge that allows users to sign up for Adobe Acrobat subscription","description":"This policy lets the native PDF viewer in Microsoft Edge show a button that lets a user looking for advanced digital document features to discover and subscribe to premium offerings. This is done via the Acrobat extension.\n\nIf you enable or don't configure this policy, the button shows up on the native PDF viewer in Microsoft Edge. A user can buy Adobe subscription to access their premium offerings.\n\nIf you disable this policy, the button isn't visible on the native PDF viewer in Microsoft Edge. A user can't discover Adobe's advanced PDF tools or buy their subscriptions.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showacrobatsubscriptionbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showacrobatsubscriptionbutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showcasticonintoolbar","displayName":"Show the cast icon in the toolbar","description":"Set this policy to true to show the Cast toolbar icon on the toolbar or the overflow menu. Users won't be able to remove it.\n\nIf you don't configure this policy or if you disable it, users can pin or remove the icon by using its contextual menu.\n\nIf you've also set the \"EnableMediaRouter\" policy to false, then this policy is ignored, and the toolbar icon isn't shown.","helpText":null,"infoUrls":[],"categoryId":"fddc444c-3591-4a50-865b-d8993b798e12","categoryName":"Cast","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showcasticonintoolbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showcasticonintoolbar_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadsinsecurewarningsenabled","displayName":"Enable insecure download warnings","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\n\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user receives a UI warning, such as \"Insecure download blocked\". The user can still download the item.\n\nIf you disable this policy, the warnings for insecure downloads are suppressed.","helpText":null,"infoUrls":[],"categoryId":"5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","categoryName":"Downloads","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadsinsecurewarningsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadsinsecurewarningsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadsinsecurewarningsenabled_recommended","displayName":"Enable insecure download warnings (users can override)","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\n\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user receives a UI warning, such as \"Insecure download blocked\". The user can still download the item.\n\nIf you disable this policy, the warnings for insecure downloads are suppressed.","helpText":null,"infoUrls":[],"categoryId":"5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","categoryName":"Downloads","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadsinsecurewarningsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadsinsecurewarningsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadstoolbarbutton","displayName":"Show Downloads button on the toolbar","description":"Set this policy to always show the Downloads button on the toolbar.\n\nIf you enable this policy, the Downloads button is pinned to the toolbar.\n\nIf you disable or don't configure the policy, the Downloads button isn't shown on the toolbar by default. Users can toggle the Downloads button in edge://settings/appearance.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadstoolbarbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadstoolbarbutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhistorythumbnails","displayName":"Show thumbnail images for browsing history","description":"This policy lets you configure whether the history thumbnail feature collects and saves images for the sites you visit. When enabled, this feature makes it easier to identify sites when you hover over your history results.\nIf you don't configure this policy, the thumbnail feature is turned on after a user visits the history hub twice in the past seven days.\nIf you enable this policy, the history thumbnail collects and saves images for visited sites.\nIf you disable this policy, the history thumbnail doesn't collect and save images for visited sites.\nWhen the feature is disabled, existing images are deleted on a per user basis, and the feature no longer collects or saves images when a site is visited.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhistorythumbnails_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhistorythumbnails_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton","displayName":"Show Home button on toolbar","description":"Shows the Home button on Microsoft Edge's toolbar.\n\nEnable this policy to always show the Home button. Disable it to never show the button.\n\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_recommended","displayName":"Show Home button on toolbar (users can override)","description":"Shows the Home button on Microsoft Edge's toolbar.\n\nEnable this policy to always show the Home button. Disable it to never show the button.\n\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards","displayName":"Show Microsoft Rewards experiences","description":"Show Microsoft Rewards experience and notifications.\nIf you enable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.\n\nIf you disable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets won't see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is disabled and toggled off.\n\nIf you don't configure this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_recommended","displayName":"Show Microsoft Rewards experiences (users can override)","description":"Show Microsoft Rewards experience and notifications.\nIf you enable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.\n\nIf you disable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets won't see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is disabled and toggled off.\n\nIf you don't configure this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showofficeshortcutinfavoritesbar","displayName":"Show Microsoft Office shortcut in favorites bar (Deprecated)","description":"This policy didn't work as expected due to changes in operational requirements. Therefore, the policy is deprecated and shouldn't be used.\n\nSpecifies whether to include a shortcut to Office.com in the favorites bar. For users signed into Microsoft Edge, the shortcut takes users to their Microsoft Office apps and docs.\n If you enable or don't configure this policy, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu.\n If you disable this policy, the shortcut isn't shown.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showofficeshortcutinfavoritesbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showofficeshortcutinfavoritesbar_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showpdfdefaultrecommendationsenabled","displayName":"Allow notifications to set Microsoft Edge as default PDF reader","description":"This policy setting lets you decide whether employees should receive recommendations to set Microsoft Edge as PDF handler.\n\nIf you enable or don't configure this setting, employees receive recommendations from Microsoft Edge to set itself as the default PDF handler.\n\nIf you disable this setting, employees can't receive any notifications from Microsoft Edge to set itself as the default PDF handler.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showpdfdefaultrecommendationsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showpdfdefaultrecommendationsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showrecommendationsenabled","displayName":"Allow feature recommendations and browser assistance notifications from Microsoft Edge","description":"This setting controls the in-browser assistance notifications that are intended to help users get the most out of Microsoft Edge. This is done by recommending features and by helping them use browser features. These notifications take the form of dialog boxes, flyouts, coach marks and banners in the browser. An example of an assistance notification would be when a user has many tabs opened in the browser. In this instance, Microsoft Edge may prompt the user to try out the vertical tabs feature which is designed to give better browser tab management.\n\nDisabling this policy stops this message from appearing again even if the user has too many tabs open.\nAny features that have been disabled by a management policy aren't suggested to users.\nIf you enable or don't configure this setting, users receive recommendations or notifications from Microsoft Edge.\nIf you disable this setting, users won't receive any recommendations or notifications from Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showrecommendationsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showrecommendationsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled","displayName":"Enable tab preview on hover","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\n\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\n\nIf you disable this policy, tab previews aren't shown on hover.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_recommended","displayName":"Enable tab preview on hover (users can override)","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\n\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\n\nIf you disable this policy, tab previews aren't shown on hover.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support","description":"Enable support for Signed HTTP Exchange (SXG).\n\nIf this policy isn't set or enabled, Microsoft Edge accepts web contents served as Signed HTTP Exchanges.\n\nIf this policy is set to disabled, Signed HTTP Exchanges can't be loaded.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.signedhttpexchangeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.signedhttpexchangeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsblockedforurls","displayName":"Block sleeping tabs on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to be put to sleep by sleeping tabs. Sites in this list are also excluded from other performance optimizations like efficiency mode and tab discard.\n\nIf the policy \"SleepingTabsEnabled\" is disabled, this list isn't used and no sites are put to sleep automatically.\n\nIf you don't configure this policy, all sites are eligible to be put to sleep unless the user's personal configuration blocks them.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsblockedforurls_recommended","displayName":"Block sleeping tabs on specific sites (users can override)","description":"Define a list of sites, based on URL patterns, that aren't allowed to be put to sleep by sleeping tabs. Sites in this list are also excluded from other performance optimizations like efficiency mode and tab discard.\n\nIf the policy \"SleepingTabsEnabled\" is disabled, this list isn't used and no sites are put to sleep automatically.\n\nIf you don't configure this policy, all sites are eligible to be put to sleep unless the user's personal configuration blocks them.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled","displayName":"Configure sleeping tabs","description":"This policy setting lets you configure whether to turn on sleeping tabs. Sleeping tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, sleeping tabs is turned on.\n\nIndividual sites may be blocked from being put to sleep by configuring the policy \"SleepingTabsBlockedForUrls\".\n\nIf this policy is enabled, sleeping tabs are turned on.\n\nIf this policy is disabled, sleeping tabs are turned off. However, during moderate memory pressure, the system may freeze (sleep) tabs before discarding them.\n\nIf this policy is not configured, users can choose whether to enable sleeping tabs.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_recommended","displayName":"Configure sleeping tabs (users can override)","description":"This policy setting lets you configure whether to turn on sleeping tabs. Sleeping tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, sleeping tabs is turned on.\n\nIndividual sites may be blocked from being put to sleep by configuring the policy \"SleepingTabsBlockedForUrls\".\n\nIf this policy is enabled, sleeping tabs are turned on.\n\nIf this policy is disabled, sleeping tabs are turned off. However, during moderate memory pressure, the system may freeze (sleep) tabs before discarding them.\n\nIf this policy is not configured, users can choose whether to enable sleeping tabs.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs are automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\n\nTabs are only put to sleep automatically when the policy \"SleepingTabsEnabled\" is enabled or isn't configured, and the user has enabled the sleeping tabs setting.\n\nIf you don't configure this policy, users can choose the timeout value.\n\nPolicy options mapping:\n\n* 30Seconds (30) = 30 seconds of inactivity\n\n* 5Minutes (300) = 5 minutes of inactivity\n\n* 15Minutes (900) = 15 minutes of inactivity\n\n* 30Minutes (1800) = 30 minutes of inactivity\n\n* 1Hour (3600) = 1 hour of inactivity\n\n* 2Hours (7200) = 2 hours of inactivity\n\n* 3Hours (10800) = 3 hours of inactivity\n\n* 6Hours (21600) = 6 hours of inactivity\n\n* 12Hours (43200) = 12 hours of inactivity\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_30seconds","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_5minutes","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_15minutes","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_30minutes","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_1hour","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_2hours","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_3hours","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_6hours","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_12hours","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended","displayName":"Set the background tab inactivity timeout for sleeping tabs (users can override)","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs are automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\n\nTabs are only put to sleep automatically when the policy \"SleepingTabsEnabled\" is enabled or isn't configured, and the user has enabled the sleeping tabs setting.\n\nIf you don't configure this policy, users can choose the timeout value.\n\nPolicy options mapping:\n\n* 30Seconds (30) = 30 seconds of inactivity\n\n* 5Minutes (300) = 5 minutes of inactivity\n\n* 15Minutes (900) = 15 minutes of inactivity\n\n* 30Minutes (1800) = 30 minutes of inactivity\n\n* 1Hour (3600) = 1 hour of inactivity\n\n* 2Hours (7200) = 2 hours of inactivity\n\n* 3Hours (10800) = 3 hours of inactivity\n\n* 6Hours (21600) = 6 hours of inactivity\n\n* 12Hours (43200) = 12 hours of inactivity\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_30seconds","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_5minutes","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_15minutes","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_30minutes","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_1hour","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_2hours","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_3hours","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_6hours","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_12hours","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist","displayName":"Block smart actions for a list of services","description":"List specific services, such as PDFs, and websites that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\n\nIf you enable the policy:\n - The smart action in the mini and full context menu is disabled for all profiles for services that match the given list.\n - Users won't see the smart action in the mini and full context menu on text selection for services that match the given list.\n - In Microsoft Edge settings, the smart action in the mini and full context menu is disabled for services that match the given list.\n\nIf you disable or don't configure this policy:\n - The smart action in the mini and full context menu is enabled for all profiles.\n - Users will see the smart action in the mini and full context menu on text selection.\n - In Microsoft Edge settings, the smart action in the mini and full context menu is enabled.\n\nPolicy options mapping:\n\n* smart_actions (smart_actions) = Smart actions in pdfs and on websites\n\n* smart_actions_website (smart_actions_website) = Smart actions on websites\n\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_smart_actions","displayName":"Smart actions in pdfs and on websites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_smart_actions_website","displayName":"Smart actions on websites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_smart_actions_pdf","displayName":"Smart actions in PDF","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_recommended","displayName":"Block smart actions for a list of services (users can override)","description":"List specific services, such as PDFs, and websites that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\n\nIf you enable the policy:\n - The smart action in the mini and full context menu is disabled for all profiles for services that match the given list.\n - Users won't see the smart action in the mini and full context menu on text selection for services that match the given list.\n - In Microsoft Edge settings, the smart action in the mini and full context menu is disabled for services that match the given list.\n\nIf you disable or don't configure this policy:\n - The smart action in the mini and full context menu is enabled for all profiles.\n - Users will see the smart action in the mini and full context menu on text selection.\n - In Microsoft Edge settings, the smart action in the mini and full context menu is enabled.\n\nPolicy options mapping:\n\n* smart_actions (smart_actions) = Smart actions in pdfs and on websites\n\n* smart_actions_website (smart_actions_website) = Smart actions on websites\n\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_recommended_smart_actions","displayName":"Smart actions in pdfs and on websites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_recommended_smart_actions_website","displayName":"Smart actions on websites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_recommended_smart_actions_pdf","displayName":"Smart actions in PDF","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenallowlistdomains","displayName":"Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings","description":"Configures the list of Microsoft Defender SmartScreen trusted domains. This means:\n\n- Microsoft Defender SmartScreen won't check for potentially malicious resources like phishing software and other malware if the source URLs match these domains.\n- The Microsoft Defender SmartScreen download protection service won't check downloads hosted on these domains.\n\nIf you enable this policy, Microsoft Defender SmartScreen trusts these domains.\nIf you disable or don't set this policy, default Microsoft Defender SmartScreen protection is applied to all resources.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10/11 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via mobile device management (MDM) or joined to a domain via MCX.\nNote: If your organization has enabled Microsoft Defender for Endpoint, this policy and any allowlists created with the policy are ignored. You must configure your allowlists and blocklists in Microsoft 365 Defender portal using \"Indicators\" (Settings > Endpoints > Indicators).","helpText":null,"infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenfortrusteddownloadsenabled","displayName":"Force Microsoft Defender SmartScreen checks on downloads from trusted sources","description":"This policy setting lets you configure whether Microsoft Defender SmartScreen checks download reputation from a trusted source.\n\nIn Windows, the policy determines a trusted source by checking its Internet zone. If the source comes from the local system, intranet, or trusted sites zone, then the download is considered trusted and safe.\n\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download's reputation regardless of source.\n\nIf you disable this setting, Microsoft Defender SmartScreen doesn't check the download's reputation when downloading from a trusted source.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.","helpText":null,"infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenfortrusteddownloadsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenfortrusteddownloadsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenfortrusteddownloadsenabled_recommended","displayName":"Force Microsoft Defender SmartScreen checks on downloads from trusted sources (users can override)","description":"This policy setting lets you configure whether Microsoft Defender SmartScreen checks download reputation from a trusted source.\n\nIn Windows, the policy determines a trusted source by checking its Internet zone. If the source comes from the local system, intranet, or trusted sites zone, then the download is considered trusted and safe.\n\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download's reputation regardless of source.\n\nIf you disable this setting, Microsoft Defender SmartScreen doesn't check the download's reputation when downloading from a trusted source.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.","helpText":null,"infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenfortrusteddownloadsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenfortrusteddownloadsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.speechrecognitionenabled","displayName":"Configure Speech Recognition","description":"Set whether websites can use the W3C Web Speech API to recognize speech from the user. The Microsoft Edge implementation of the Web Speech API uses Azure Cognitive Services, so voice data leaves the machine.\n\nIf you enable or don't configure this policy, web-based applications that use the Web Speech API can use Speech Recognition.\n\nIf you disable this policy, Speech Recognition isn't available through the Web Speech API.\n\nRead more about this feature here:\nSpeechRecognition API: https://go.microsoft.com/fwlink/?linkid=2143388\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2143680","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.speechrecognitionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.speechrecognitionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellcheckenabled","displayName":"Enable spellcheck","description":"If you enable or don't configure this policy, the user can use spellcheck.\n\nIf you disable this policy, the user can't use spellcheck and the \"SpellcheckLanguage\" and \"SpellcheckLanguageBlocklist\" policies are also disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellcheckenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellcheckenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellchecklanguage","displayName":"Enable specific spellcheck languages","description":"Enables different languages for spellcheck. Any language that you specify that isn't recognized is ignored.\n\nIf you enable this policy, spellcheck is enabled for the languages specified, and any languages the user enabled.\n\nIf you don't configure or disable this policy, there's no change to the user's spellcheck preferences.\n\nIf the \"SpellcheckEnabled\" policy is disabled, this policy has no effect.\n\nIf a language is included in both the 'SpellcheckLanguage' and the \"SpellcheckLanguageBlocklist\" policy, the spellcheck language is enabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellchecklanguageblocklist","displayName":"Force disable spellcheck languages","description":"Force-disables spellcheck languages. Unrecognized languages in that list will be ignored.\n\nIf you enable this policy, spellcheck will be disabled for the languages specified. The user can still enable or disable spellcheck for languages not in the list.\n\nIf you don't set this policy, or disable it, there is no change to the user's spellcheck preferences.\n\nIf the \"SpellcheckEnabled\" policy is set to disabled, this policy has no effect.\n\nIf a language is included in both the \"SpellcheckLanguage\" and the 'SpellcheckLanguageBlocklist' policy, the spellcheck language is enabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowed","displayName":"Allow users to proceed from the HTTPS warning page","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure (default) this policy, users can click through these warning pages.\n\nIf you disable this policy, users are blocked from clicking through any warning page.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowedfororigins","displayName":"Allow users to proceed from the HTTPS warning page for specific origins","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure the \"SSLErrorOverrideAllowed\" policy, this policy does nothing.\n\nIf you disable the \"SSLErrorOverrideAllowed\" policy, configuring this policy lets you configure a list of origin patterns for sites where users can continue to click through SSL error pages. Users can't click through SSL error pages on origins that are not on this list.\n\nIf you don't configure this policy, the \"SSLErrorOverrideAllowed\" policy applies for all sites.\n\nFor detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy. This policy only matches based on origin, so any path or query in the URL pattern is ignored.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.standardizedbrowserzoomenabled","displayName":"Enable Standardized Browser Zoom Behavior","description":"Configures whether the CSS \"zoom\" property follows the current CSS specification or legacy behavior.\n\nWhen this policy is enabled or not configured, the CSS \"zoom\" property follows the current specification defined by the CSS Working Group:\nhttps://drafts.csswg.org/css-viewport/#zoom-property\n\nWhen this policy is disabled, the CSS \"zoom\" property uses its legacy, pre-standardized behavior.\n\nThis policy is temporary and is intended to provide time for organizations to migrate web content to the updated behavior. In a future Microsoft Edge release, this policy will be removed and the standardized behavior will be enforced by default.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.standardizedbrowserzoomenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.standardizedbrowserzoomenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.staticstoragequotaenabled","displayName":"Control whether storage quota APIs will return static values","description":"Controls how the Storage Quota APIs report the available quota to websites.\n\nWhen enabled, the Storage Quota APIs return a static quota value equal to the current usage plus the smaller of 10 GiB or the device's total storage rounded up to the nearest 1 GiB.\n\nWhen disabled, the Storage Quota APIs return a dynamic quota value that reflects the actual available device storage.\n\nWhen unset, the browser uses the default platform behavior.\n\nThis policy does not affect sites with unlimited storage permissions or enforced quota settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.staticstoragequotaenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.staticstoragequotaenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.strictermixedcontenttreatmentenabled","displayName":"Enable stricter treatment for mixed content (Obsolete)","description":"This policy doesn't work because it was only intended to be a short-term mechanism to give enterprises more time to update their web content if it was found to be incompatible with stricter mixed content treatment.\n\nThis policy controls the treatment for mixed content (HTTP content in HTTPS sites) in the browser.\n\nIf you set this policy to true or not set, audio and video mixed content is automatically upgraded to HTTPS (that is, the URL will be rewritten as HTTPS, without a fallback if the resource isn't available over HTTPS), and a 'Not Secure' warning is shown in the URL bar for image mixed content.\n\nIf you set the policy to false, auto upgrades are disabled for audio and video, and no warning is shown for images.\n\nThis policy doesn't affect other types of mixed content other than audio, video, and images.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.strictermixedcontenttreatmentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.strictermixedcontenttreatmentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.superdragdropenabled","displayName":"Super Drag Drop Enabled","description":"This policy lets you configure the Super Drag Drop feature in Microsoft Edge.\n\nWith this feature, users can drag a link or text from a webpage and drop it onto the same page. They can then either open the URL in a new tab or search the text using the default search engine.\n\nIf you enable or don't configure this policy, you can use the Super Drag Drop feature on Microsoft Edge.\n\nIf you disable this policy, you can't use the Super Drag Drop feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.superdragdropenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.superdragdropenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.syncdisabled","displayName":"Disable synchronization of data using Microsoft sync services","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\n\nThis policy disables cloud synchronization only and has no impact on the \"RoamingProfileSupportEnabled\" policy.\n\nIf you don't set this policy or apply it as recommended, users can turn on or turn off sync. If you apply this policy as mandatory, users won't be able to turn on sync.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.syncdisabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.syncdisabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.syncdisabled_recommended","displayName":"Disable synchronization of data using Microsoft sync services (users can override)","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\n\nThis policy disables cloud synchronization only and has no impact on the \"RoamingProfileSupportEnabled\" policy.\n\nIf you don't set this policy or apply it as recommended, users can turn on or turn off sync. If you apply this policy as mandatory, users won't be able to turn on sync.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.syncdisabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.syncdisabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.synctypeslistdisabled","displayName":"Configure the list of types that are excluded from synchronization","description":"If you enable this policy, all the specified data types are excluded from synchronization. This policy can be used to limit the type of data uploaded to the Microsoft Edge synchronization service.\n\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", \"history\", \"openTabs\", \"edgeWallet\", \"collections\", \"apps\", and \"edgeFeatureUsage\". The \"edgeFeatureUsage\" data type are supported starting in Microsoft Edge version 134. These data type names are case sensitive.\n\nUsers can't override the disabled data types.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.tabcaptureallowedbyorigins","displayName":"Allow Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Tab Capture.\n\nLeaving the policy unset means that sites aren't considered for an override at this scope of capture.\n\nThis policy is not considered if a site matches a URL pattern in the \"SameOriginTabCaptureAllowedByOrigins\" policy.\n\nIf a site matches a URL pattern in this policy, the following policies aren't considered: \"WindowCaptureAllowedByOrigins\", \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.tabservicesenabled","displayName":"Enable tab organization suggestions","description":"This policy controls whether Microsoft Edge can use its tab organization service to help name or suggest tab groups to increase productivity.\n\nIf you enable or don't configure this policy, when a user creates a tab group or activates certain \"Group Similar Tabs\" features Microsoft Edge sends tab data to its tab organization service. This data includes URLs, page titles, and existing group information. The service uses this data to return suggestions for better groupings and group names.\n\nIf you disable this policy, no data is sent to the tab organization service. Microsoft Edge can't suggest group names when a group is created and certain \"Group Similar Tabs\" features that rely on the service aren't available.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.tabservicesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.tabservicesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.textpredictionenabled","displayName":"Text prediction enabled by default","description":"The Microsoft Turing service uses natural language processing to generate predictions for long-form editable text fields on web pages.\n\nIf you enable or don't configure this policy, text predictions are provided for eligible text fields.\n\nIf you disable this policy, text predictions aren't provided in eligible text fields. Sites may still provide their own text predictions.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.textpredictionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.textpredictionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.thirdpartystoragepartitioningblockedfororigins","displayName":"Disable third-party storage partitioning for specific top-level origins (Obsolete)","description":"This policy lets you set a list of URL patterns that specify top-level origins for which third-party storage partitioning (partitioning of cross-origin iframe storage) should be disabled.\n\nIf this policy isn't set or a top-level origin doesn't match one of the URL patterns, then the value from \"DefaultThirdPartyStoragePartitioningSetting\" will be used.\n\nNote that the patterns you list are treated as origins, not URLs, so you shouldn't specify a path. For detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nThis feature has been removed starting in Microsoft Edge version 146. To ensure compatibility, use the requestStorageAccess method instead. For more information, see https://developer.mozilla.org/en-US/docs/Web/API/Document/requestStorageAccess.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors (Obsolete)","description":"This policy doesn't work because it was only intended to be a short-term mechanism to give enterprises more time to upgrade affected proxies.\n\nThis policy controls a security feature in TLS 1.3 that protects connections against downgrade attacks. It's backwards-compatible and doesn't affect connections to compliant TLS 1.2 servers or proxies. However, older versions of some TLS-intercepting proxies have an implementation flaw which causes them to be incompatible.\n\nIf you enable or don't configure this policy, Microsoft Edge enables these security protections for all connections.\n\nIf you disable this policy, Microsoft Edge disables these security protections for connections authenticated with locally-installed CA certificates. These protections are always enabled for connections authenticated with publicly-trusted CA certificates.\n\nThis policy can be used to test for any affected proxies and upgrade them. Affected proxies are expected to fail connections with an error code of ERR_TLS13_DOWNGRADE_DETECTED.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.tls13hardeningforlocalanchorsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.tls13hardeningforlocalanchorsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention","displayName":"Block tracking of users' web-browsing activity","description":"Lets you decide whether to block websites from tracking users' web-browsing activity.\n\nIf you disable this policy or don't configure it, users set their own level of tracking prevention.\n\nPolicy options mapping:\n\n* TrackingPreventionOff (0) = Off (no tracking prevention)\n\n* TrackingPreventionBasic (1) = Basic (blocks harmful trackers, content and ads will be personalized)\n\n* TrackingPreventionBalanced (2) = Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)\n\n* TrackingPreventionStrict (3) = Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionoff","displayName":"Off (no tracking prevention)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionbasic","displayName":"Basic (blocks harmful trackers, content and ads will be personalized)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionbalanced","displayName":"Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionstrict","displayName":"Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.translateenabled","displayName":"Enable Translate","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge offers to translate a webpage by showing an integrated translate flyout when the language detected on a webpage isn't listed under preferred languages. A translate option is available on the right-click context menu.\n\nUsers can also translate selected text on a webpage via the right-click context menu, or on a PDF via the PDF toolbar and the right-click context menu.\n\nIf you don't configure this policy, the policy is enabled by default. Users can choose whether to use the translation functionality or not.\n\nYou can disable this policy to disable all built-in translate features.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.translateenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.translateenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.translateenabled_recommended","displayName":"Enable Translate (users can override)","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge offers to translate a webpage by showing an integrated translate flyout when the language detected on a webpage isn't listed under preferred languages. A translate option is available on the right-click context menu.\n\nUsers can also translate selected text on a webpage via the right-click context menu, or on a PDF via the PDF toolbar and the right-click context menu.\n\nIf you don't configure this policy, the policy is enabled by default. Users can choose whether to use the translation functionality or not.\n\nYou can disable this policy to disable all built-in translate features.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.translateenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.translateenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.travelassistanceenabled","displayName":"Enable travel assistance (Obsolete)","description":"This policy is obsolete as the feature is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy. It doesn't work in Microsoft Edge after version 105.\nConfigure this policy to allow/disallow travel assistance.\n\nThe travel assistance feature gives helpful and relevant information to a user who performs a travel-related task within the browser. This feature provides trusted and validated suggestions/information to the users from across sources gathered by Microsoft.\n\nIf you enable or don't configure this setting, travel assistance is enabled for the users when they are performing travel-related tasks.\n\nIf you disable this setting, travel assistance will be disabled, and users won't be able to see any travel-related recommendations.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.travelassistanceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.travelassistanceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.travelassistanceenabled_recommended","displayName":"Enable travel assistance (Obsolete) (users can override)","description":"This policy is obsolete as the feature is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy. It doesn't work in Microsoft Edge after version 105.\nConfigure this policy to allow/disallow travel assistance.\n\nThe travel assistance feature gives helpful and relevant information to a user who performs a travel-related task within the browser. This feature provides trusted and validated suggestions/information to the users from across sources gathered by Microsoft.\n\nIf you enable or don't configure this setting, travel assistance is enabled for the users when they are performing travel-related tasks.\n\nIf you disable this setting, travel assistance will be disabled, and users won't be able to see any travel-related recommendations.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.travelassistanceenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.travelassistanceenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.typosquattingallowlistdomains","displayName":"Configure the list of domains for which Microsoft Edge Website Typo Protection won't trigger warnings","description":"Configures the list of Microsoft Edge Website Typo Protection trusted domains. This means:\nMicrosoft Edge Website Typo Protection won't check for potentially malicious typosquatting websites.\n\nIf you enable this policy, Microsoft Edge Website Typo Protection trusts these domains.\nIf you disable or don't set this policy, default Microsoft Edge Website Typo Protection protection is applied to all resources.\n\nThis only takes effect when TyposquattingCheckerEnabled policy isn't set or is set to enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10/11 Pro; or Enterprise instances that enrolled for device management; or macOS instances that are that are managed via MDM or joined to a domain via MCX.\nThis policy doesn't apply if your organization has enabled Microsoft Defender for Endpoint. You must configure your allowlists and blocklists in Microsoft 365 Defender portal using Indicators (Settings > Endpoints > Indicators).","helpText":null,"infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.u2fsecuritykeyapienabled","displayName":"Allow using the deprecated U2F Security Key API (Obsolete)","description":"This policy is obsolete because it was intended to be a short-term mechanism to give enterprises more time to update their web content that's incompatible with the change to remove the U2F Security Key API. It doesn't work in Microsoft Edge after version 103.\n\nIf you enable this policy, the deprecated U2F Security Key API can be used and the deprecation reminder prompt shown for U2F API requests is suppressed.\n\nIf you disable this policy or don't configure it, the U2F Security Key API is disabled by default and can only be used by sites that register for and use the U2FSecurityKeyAPI origin trial, which ended after Microsoft Edge version 103.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.u2fsecuritykeyapienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.u2fsecuritykeyapienabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.unthrottlednestedtimeoutenabled","displayName":"JavaScript setTimeout will not be clamped until a higher nesting threshold is set (Deprecated)","description":"This policy is deprecated because it's a temporary policy for web standards compliance. It doesn't work in Microsoft Edge version 107 onward.\nIf you enable this policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4 ms, aren't clamped. This improves short horizon performance; however, websites abusing the API still have their setTimeout usages clamped.\nIf you disable or don't configure this policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4 ms, are clamped.\n\nThis is a web standards compliancy feature that changes task ordering on a webpage, leading to unexpected behavior on sites that are dependent on a certain ordering.\nIt also affects sites with a lot of usage of a timeout of 0 ms for setTimeout, for example, increasing CPU load.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.unthrottlednestedtimeoutenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.unthrottlednestedtimeoutenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.uploadfromphoneenabled","displayName":"Enable upload files from mobile in Microsoft Edge desktop","description":"This policy lets you configure the \"Upload from mobile\" feature in Microsoft Edge.\n\nUpload from mobile lets users select file from mobile devices to desktop when user upload file in a webpage in Microsoft Edge.\n\nIf you enable or don't configure this policy, you can use the Upload from mobile feature in Microsoft Edge.\n\nIf you disable this policy, you can't use the Upload from mobile feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.uploadfromphoneenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.uploadfromphoneenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.urlallowlist","displayName":"Define a list of allowed URLs","description":"Setting the policy provides access to the listed URLs as exceptions to \"URLBlocklist\".\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can use this policy to open exceptions to restrictive blocklists. For example, you can include '*' in the blocklist to block all requests, and then use this policy to allow access to a limited list of URLs. You can use this policy to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths.\n\nThe most specific filter determines if a URL is blocked or allowed. The allowed list takes precedence over the blocked list.\n\nThis policy is limited to 1000 entries; subsequent entries are ignored.\n\nThis policy also allows the browser to automatically invoke external applications registered as protocol handlers for protocols like \"tel:\" or \"ssh:\".\n\nIf you don't configure this policy, there are no exceptions to the blocklist in the \"URLBlocklist\" policy.\n\nThis policy doesn't work as expected with file://* wildcards.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.urlblocklist","displayName":"Block access to a list of URLs","description":"Defines a list of sites, based on URL patterns, that are blocked (your users can't load them).\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can define exceptions in the \"URLAllowlist\" policy. These policies are limited to 1000 entries; subsequent entries are ignored.\n\nBlocking internal 'edge://*' URLs isn't recommended - this may lead to unexpected errors.\n\nThis policy doesn't prevent the page from updating dynamically through JavaScript. For example, if you block 'contoso.com/abc', users can visit 'contoso.com' and select on a link to visit 'contoso.com/abc', as long as the page doesn't refresh.\n\nIf you don't configure this policy, no URLs are blocked.\n\nThis policy doesn't work as expected with file://* wildcards.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction","displayName":"Enable or disable the User-Agent Reduction (Obsolete)","description":"The User-Agent HTTP request header has been reduced by default since Microsoft Edge version 119. To continue receiving detailed platform information, migrate to User-Agent Client Hints, which replace the deprecated detailed User-Agent header. For more information, visit: https://web.dev/articles/migrate-to-ua-ch\n\nIf you don't configure this policy or set it to Default, the User-Agent header will be reduced and controlled by experimentation.\n\nSet this policy to 'ForceEnabled' to force the reduced version of the User-Agent request header for all origins.\n\nSet this policy to 'ForceDisabled' to always use the full (legacy) User-Agent header.\n\nTo learn more about the User-Agent string, read here:\n\nhttps://go.microsoft.com/fwlink/?linkid=2186267\n\nPolicy options mapping:\n\n* Default (0) = Reduced User Agent, or controlled by experimentation.\n\n* ForceDisabled (1) = Full (legacy) User Agent.\n\n* ForceEnabled (2) = Reduced User Agent.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction_default","displayName":"Reduced User Agent, or controlled by experimentation.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction_forcedisabled","displayName":"Full (legacy) User Agent.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction_forceenabled","displayName":"Reduced User Agent.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.usesystemprintdialog","displayName":"Print using system print dialog","description":"Shows the system print dialog instead of print preview.\n\nIf you enable this policy, Microsoft Edge opens the system print dialog instead of the built-in print preview when a user prints a page.\n\nIf you don't configure or disable this policy, print commands trigger the Microsoft Edge print preview screen.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.usesystemprintdialog_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.usesystemprintdialog_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.verticaltabsallowed","displayName":"Configures availability of a vertical layout for tabs on the side of the browser","description":"Configures whether a user can access an alternative layout where tabs are vertically aligned on the side of the browser instead of at the top.\nWhen there are several tabs open, this layout provides better tab viewing and management. There's better visibility of the site titles,\nit's easier to scan aligned icons, and there's more space to manage and close tabs.\n\nIf you disable this policy, then the vertical tab layout isn't available as an option for users.\n\nIf you enable or don't configure this policy, the tab layout remains at the top, but a user has the option to turn on vertical tabs on the side.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.verticaltabsallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.verticaltabsallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.videocaptureallowed","displayName":"Allow or block video capture","description":"Control whether sites can capture video.\n\nIf enabled or not configured (default), the user is asked about video capture access for all sites except sites with URLs configured in the \"VideoCaptureAllowedUrls\" policy list, which is granted without prompting.\n\nIf you disable this policy, the user isn't prompted, and video capture is only available to URLs configured in \"VideoCaptureAllowedUrls\" policy.\n\nThis policy affects all types of video inputs, not only the built-in camera.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.videocaptureallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.videocaptureallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.videocaptureallowedurls","displayName":"Sites that can access video capture devices without requesting permission","description":"Specify websites, based on URL patterns, that can use video capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to video capture devices. However, the pattern \"*\", which matches any URL, isn't supported by this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.viewxfapdfiniemodeallowedfilehash","displayName":"View XFA-based PDF files using IE Mode for allowed file hash.","description":"XFA is a legacy technology that's deprecated by its original creators. It's not an ISO standard and as such, it doesn't align with the modern web architecture. Continued use poses potential risks and vulnerabilities. For more information, see \"ViewXFAPDFInIEModeAllowedOrigins\".\n\nIf you enable this policy, you can configure the list of base64 encoded SHA256 file hashes for which XFA PDF files automatically open in Microsoft Edge using IE Mode.\n\nIf you disable or don't configure this policy, XFA PDFs won't be considered for opening via IE mode except the files from file origin mentioned in Policy \"ViewXFAPDFInIEModeAllowedOrigins\"\n\nFor more information, see - [Get-FileHash](https://go.microsoft.com/fwlink/?linkid=2294823), [Dot Net Convert API](https://go.microsoft.com/fwlink/?linkid=2294913).","helpText":null,"infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.viewxfapdfiniemodeallowedorigins","displayName":"View XFA-based PDF files using IE Mode for allowed file origin.","description":"Internet Explorer (IE) mode uses the Adobe Acrobat Active-X PDF Plugin to open XFA-based PDF files. This policy works only if the Active-X plugin is already on the user's device, it's not installed as part of this policy.\n\nIt's important to note that XFA is a legacy technology that's deprecated by its original creators. It's not an ISO standard and as such doesn't align with the modern web architecture. Continued use poses potential risks and vulnerabilities.\n\nGiven the deprecated status of XFA technology and the lack of any investment by its creators, we strongly recommend that you start planning your transition to more advanced HTML\\PDF form-based solutions.\n\nIn the interim, this policy provides a workaround for users to view XFA PDF in Microsoft Edge.\n\nIf you enable this policy, you can configure the list of origins from which XFA PDF files will be automatically opened in Microsoft Edge using IE Mode.\n\nIf you disable or don't configure the policy, XFA PDFs won't be considered for opening via Internet Explorer mode.\n\nFor detailed information on valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322\n\nAlternatively, \"ViewXFAPDFInIEModeAllowedFileHash\" can also be used to configure list of file hashes instead of URL origins, which enables those files to be automatically opened in Microsoft Edge using IE Mode.","helpText":null,"infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled","displayName":"Visual search enabled","description":"Visual search lets you quickly explore more related content about entities in an image.\n\nIf you enable or don't configure this policy, visual search is enabled via image hover, context menu, and search in sidebar.\n\nIf you disable this policy, visual search is disabled and you can't get more info about images via hover, context menu, and search in sidebar.\n\nNote: Visual Search in Web Capture is still managed by \"WebCaptureEnabled\" policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_recommended","displayName":"Visual search enabled (users can override)","description":"Visual search lets you quickly explore more related content about entities in an image.\n\nIf you enable or don't configure this policy, visual search is enabled via image hover, context menu, and search in sidebar.\n\nIf you disable this policy, visual search is disabled and you can't get more info about images via hover, context menu, and search in sidebar.\n\nNote: Visual Search in Web Capture is still managed by \"WebCaptureEnabled\" policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled","displayName":"Wallet Donation Enabled (Deprecated)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\n\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\n\nIf you disable this policy, users can't use the Wallet Donation feature.\n\nThis policy is deprecated because the Wallet Donation feature has been removed from Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_recommended","displayName":"Wallet Donation Enabled (Deprecated) (users can override)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\n\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\n\nIf you disable this policy, users can't use the Wallet Donation feature.\n\nThis policy is deprecated because the Wallet Donation feature has been removed from Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webappinstallbyuserenabled","displayName":"Enable User Web App Install From Browser","description":"This policy controls whether users can install web apps through Microsoft Edge.\nIf you enable or don’t configure this policy, users can install web apps through the browser.\nIf you disable this policy, users can’t install web apps through the browser, and the \"apps\" data type is excluded from synchronization.\nThis policy doesn't support dynamic refresh. Changes to this policy, whether enabled, disabled, or not configured, take effect only after the browser is restarted.\nThis policy doesn't affect the 'WebAppInstallForceList' policy. Web apps specified by that policy are installed regardless of this policy setting.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webappinstallbyuserenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webappinstallbyuserenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webappinstallforcelist","displayName":"Configure list of force-installed Web Apps","description":"Setting the policy specifies a list of web apps that install silently, without user interaction. Users can't turn off the policy or uninstall these web apps.\n\nEach list item of the policy is an object with a mandatory member:\nurl (the URL of the web app to install)\n\nand 6 optional members:\n- default_launch_container\n(for how the web app opens—a new tab is the default)\n\n- create_desktop_shortcut\n(True if you want to create Linux and\nMicrosoft Windows desktop shortcuts).\n\n- fallback_app_name\n(Starting with Microsoft Edge version 90,\nyou can permanently override the app name if it's not a Progressive Web App (PWA)\nor you can temporarily override the app name if authentication is required before\ninstallation can be completed. If both\ncustom_name and\nfallback_app_name are provided,\nthe latter is ignored.)\n\n- custom_name\n(Starting with Microsoft Edge version 112\non all desktop platforms, you can permanently override the app name for all\nweb apps and PWAs.)\n\n- custom_icon\n(Starting with Microsoft Edge version 112\non all desktop platforms, you can override the app icon of installed apps.\nThe icons have to be square, maximal 1 MB in size, and in one of the following formats:\njpeg, png, gif, webp, ico. The hash value has to be the SHA256 hash of the icon file.\nThe url should be accessible without authentication to\nensure that the icon can be used upon app installation.)\n\n- install_as_shortcut\n(Starting with Microsoft Edge\nversion 107). If enabled, the given url is installed as a shortcut,\nas if done via the \"Create Shortcut...\" option in the desktop browser GUI.\nWhen installed as a shortcut, it won't be updated if the manifest in url changes.\nIf disabled or unset, the web app at the given url is installed normally.\n(This isn't currently supported in Microsoft Edge.)\n\nThe 'WebAppInstallByUserEnabled' policy doesn't affect this policy. Web apps specified by this policy are installed regardless of the 'WebAppInstallByUserEnabled' policy setting.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webappsettings","displayName":"Web App management settings","description":"This policy allows an admin to specify settings for installed web apps. This policy maps a Web App ID to its specific setting. A default configuration can be set using the special ID *, which applies to all web apps without a custom configuration in this policy.\n\n- The manifest_id field is the Manifest ID for the Web App.\nSee https://developer.chrome.com/blog/pwa-manifest-id/\nfor instructions on how to determine the Manifest ID for an installed web app.\n- The run_on_os_login field specifies if a web app can be run during OS sign in.\nIf you set this field to blocked, the web app doesn't run during OS sign in, and the user can't enable this later.\nIf you set this field to run_windowed, the web app runs during OS sign in, and the user can't disable this later.\nIf you set this field to allowed, the user configures the web app to run at OS sign in.\nThe default policy configuration only allows the allowed and blocked values.\n- (Starting with Microsoft Edge version 120) The prevent_close_after_run_on_os_login field specifies if a web app can be prevented from closing in any way.\nFor example, by the user, by task manager, or by web APIs. This behavior can only be enabled if run_on_os_login is set to run_windowed.\nIf the app is already running, this setting will only take effect after the app is restarted.\nIf this field isn't defined, users can close the app.\n(This is currently not supported in Microsoft Edge.)\n- (Since version 118) The force_unregister_os_integration field specifies if all OS integration for a web app, that is, shortcuts, file handlers, protocol handlers and so on, will be removed or not.\nIf an app is already running, this property comes into effect after the app restarts.\nThis should be used with caution, since it can override any OS integration that is set automatically during the startup of the web applications system. This currently only works on Windows, Mac and Linux platforms.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webaudiooutputbufferingenabled","displayName":"Enable adaptive buffering for Web Audio","description":"This policy determines whether the browser enables adaptive buffering\nfor Web Audio. Adaptive buffering can reduce audio glitches but can\nincrease latency to varying degrees.\n\nIf this policy is enabled, the browser uses adaptive buffering.\nIf this policy is disabled or not configured, the browser automatically decides during the\n feature launch process whether to use adaptive buffering.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webaudiooutputbufferingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webaudiooutputbufferingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webauthenticationremotedesktopallowedorigins","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications.","description":"This policy defines a list of allowed HTTPS origins for remote desktop client applications that initiate WebAuthn API requests from a browsing session on a remote host.\n\nOrigins specified in this policy can request WebAuthn authentication for Relying Party IDs (RP IDs) they wouldn't typically be authorized to claim.\n\nOnly HTTPS origins are supported. Wildcards aren't permitted. Entries that don't\nmeet these requirements will be ignored.\n\nFor more information about the WebAuthn Remote Desktop Support feature, see https://github.com/w3c/webauthn/wiki/Explainer:-Remote-Desktop-Support/a4e158c569f456c759d0ddd294a9015bd4d4eb9a.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84 (Obsolete)","description":"This policy doesn't work because this policy allowed these features to be selectively re-enabled until Microsoft Edge version 85. The Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and are disabled by default starting in Microsoft Edge version 80.\n\nIf you set this policy to True, the Web Components v0 features are enabled for all sites.\n\nIf you set this policy to False or don't set this policy, the Web Components v0 features are disabled by default, starting in Microsoft Edge version 80.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webcomponentsv0enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webcomponentsv0enabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webhidaskforurls","displayName":"Allow the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\n\nLeaving the policy unset means \"DefaultWebHidGuardSetting\" applies for all sites, if set. If not, users' personal settings apply.\n\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\n\n * \"WebHidBlockedForUrls\" (if there's a match),\n\n * \"DefaultWebHidGuardSetting\" (if set), or\n\n * Users' personal settings.\n\nURL patterns must not conflict with \"WebHidBlockedForUrls\". Neither policy takes precedence if a URL matches both patterns.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webhidblockedforurls","displayName":"Block the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a HID device.\n\nLeaving the policy unset means \"DefaultWebHidGuardSetting\" applies for all sites, if set. If not, users' personal settings apply.\n\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\n\n * \"WebHidAskForUrls\" (if there's a match),\n\n * \"DefaultWebHidGuardSetting\" (if set), or\n\n * Users' personal settings.\n\nURL patterns can't conflict with \"WebHidAskForUrls\". Neither policy takes precedence if a URL matches both patterns.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtciphandlingurl","displayName":"WebRTC IP Handling Policy for URL Patterns","description":"Controls which IP addresses and network interfaces WebRTC can use\nwhen establishing connections for specific URL patterns.\n\nHow It Works:\nAccepts a list of URL patterns, each paired with a handling type.\nWebRTC evaluates patterns sequentially; the first match determines the handling type.\nIf no match is found, WebRTC defaults to the WebRtcLocalhostIpHandling WebRtcLocalhostIpHandling. policy.\nThis policy applies only to origins—URL path components are ignored.\nWildcards (*) are supported in URL patterns.\n\nSupported Handling Values:\ndefault – Uses all available network interfaces.\ndefault_public_and_private_interfaces – WebRTC uses all public and private interfaces.\ndefault_public_interface_only – WebRTC uses only public interfaces.\ndisable_non_proxied_udp – WebRTC uses UDP SOCKS proxying or falls back to TCP proxying.\n\nMore Information:\nValid input patterns: https://go.microsoft.com/fwlink/?linkid=2095322\nHandling types: https://tools.ietf.org/html/rfc8828.html#section-5.2","helpText":null,"infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtclocalhostiphandling","displayName":"Restrict exposure of local IP address by WebRTC","description":"Allows you to set whether or not WebRTC exposes the user's local IP address.\n\nIf you set this policy to \"AllowAllInterfaces\" or \"AllowPublicAndPrivateInterfaces\", WebRTC exposes the local IP address.\n\nIf you set this policy to \"AllowPublicInterfaceOnly\" or \"DisableNonProxiedUdp\", WebRTC doesn't expose the local IP address.\n\nIf you don't set this policy, or if you disable it, WebRTC exposes the local IP address.\n\nNote that this policy doesn't provide an option to exclude specific domains.\n\nPolicy options mapping:\n\n* AllowAllInterfaces (default) = Allow all interfaces. This exposes the local IP address\n\n* AllowPublicAndPrivateInterfaces (default_public_and_private_interfaces) = Allow public and private interfaces over http default route. This exposes the local IP address\n\n* AllowPublicInterfaceOnly (default_public_interface_only) = Allow public interface over http default route. This doesn't expose the local IP address\n\n* DisableNonProxiedUdp (disable_non_proxied_udp) = Use TCP unless proxy server supports UDP. This doesn't expose the local IP address\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtclocalhostiphandling_allowallinterfaces","displayName":"Allow all interfaces. This exposes the local IP address","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtclocalhostiphandling_allowpublicandprivateinterfaces","displayName":"Allow public and private interfaces over http default route. This exposes the local IP address","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtclocalhostiphandling_allowpublicinterfaceonly","displayName":"Allow public interface over http default route. This doesn't expose the local IP address","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtclocalhostiphandling_disablenonproxiedudp","displayName":"Use TCP unless proxy server supports UDP. This doesn't expose the local IP address","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtclocalipsallowedurls","displayName":"Manage exposure of local IP addressess by WebRTC","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*contoso.com*\") for which local IP address should be exposed by WebRTC.\n\nIf you enable this policy and set a list of origins (URLs) or hostname patterns, when edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will expose the local IP address for cases that match patterns in the list.\n\nIf you disable or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will not expose local IP addresses. The local IP address is concealed with an mDNS hostname.\n\nIf you enable, disable, or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, WebRTC will expose local IP addresses.\n\nPlease note that this policy weakens the protection of local IP addresses that might be needed by administrators.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC","description":"This policy controls the use of post-quantum key agreement for WebRTC in Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge will offer post-quantum key agreement for WebRTC.\n\nIf you disable this policy, post-quantum key agreement won't be offered for WebRTC.\n\nIf you don't configure this policy, post-quantum key agreement won't be offered for WebRTC. A future version of Microsoft Edge may enable this feature by default.\n\nOffering a post-quantum key agreement is backwards compatible. Existing datagram transport layer security (DTLS) peers and networking middleware are expected to ignore the new option and continue using previous options.\n\nHowever, devices that don't correctly implement DTLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or larger message sizes. Such devices aren’t post-quantum-ready and may interfere with an organization's post-quantum transition. If this issue occurs, administrators should contact the device vendor for a fix.\n\nThis policy is temporary and will be removed in a future release.","helpText":null,"infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtcpostquantumkeyagreement_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtcpostquantumkeyagreement_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC","description":"Restricts the UDP port range used by WebRTC to a specified port interval (endpoints included).\n\nBy configuring this policy, you specify the range of local UDP ports that WebRTC can use.\n\nIf you don't configure this policy, or if you set it to an empty string or invalid port range, WebRTC can use any available local UDP port.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webselectenabled","displayName":"Web Select Enabled (Obsolete)","description":"This policy is obsoleted because Web Select is part of Web Capture and can be controlled by \"WebCaptureEnabled\". This policy doesn't work in Microsoft Edge version 117. If Web Capture is disabled by \"WebCaptureEnabled\", Web select won't be available in Web Capture.\n\nWeb select lets users select and copy web content while preserving its formatting when pasted in most cases. It also allows more targeted selection on some web elements, such as copying a single column in a table.\n\nIf you enable or don't configure this policy, Web select is available in Web Capture and can be accessed directly using the CTRL+SHIFT+X keyboard shortcut.\n\nIf you disable this policy, Web select won't be available in Web Capture and the CTRL+SHIFT+X keyboard shortcut will also not work.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webselectenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webselectenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlaccess","displayName":"Force WebSQL to be enabled (Obsolete)","description":"This policy was removed in Microsoft Edge 124 and is ignored if set.\n\nWebSQL is on by default as of Microsoft Edge version 101, but can be disabled via a Microsoft Edge flag.\nIf you enable this policy, WebSQL cannot be disabled.\nIf you disable or don't configure this policy, WebSQL can be disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlaccess_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlaccess_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlnonsecurecontextenabled","displayName":"Force WebSQL in non-secure contexts to be enabled (Obsolete)","description":"This policy doesn't work because WebSQL in nonsecure contexts is on by default as of Microsoft Edge 105.\nIf you enable this policy, WebSQL in nonsecure contexts is enabled.\nIf you disable or don't configure this policy, WebSQL in nonsecure contexts follows the default settings of the browser.\n\nThis policy was removed in Microsoft Edge 113, and it's ignored if configured.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlnonsecurecontextenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlnonsecurecontextenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webusballowdevicesforurls","displayName":"Grant access to specific sites to connect to specific USB devices","description":"Allows you to set a list of URLs that specify which sites will automatically be granted permission to access a USB device with the given vendor and product IDs. Each item in the list must contain both devices and URLs for the policy to be valid. Each item in devices can contain a vendor ID and product ID field. Any ID that is omitted is treated as a wildcard with one exception, and that exception is that a product ID can't be specified without a vendor ID also being specified. Otherwise, the policy isn't valid and is ignored.\n\nThe USB permission model uses the URL of the requesting site (\"requesting URL\") and the URL of the top-level frame site (\"embedding URL\") to grant permission to the requesting URL to access the USB device. The requesting URL may be different than the embedding URL when the requesting site is loaded in an iframe. Therefore, the \"urls\" field can contain up to two URL strings delimited by a comma to specify the requesting and embedding URL respectively. If only one URL is specified, then access to the corresponding USB devices is granted when the requesting site's URL matches this URL regardless of embedding status. The URLs in \"urls\" must be valid URLs; otherwise, the policy is ignored.\n\nThis is deprecated and only supported for backwards compatibility in the following manner. If both a requesting and embedding URL are specified, then the embedding URL is granted the permission as top-level origin, and the requesting URL is ignored entirely.\n\nIf you don't configure this policy, the global default value is used for all sites either from the \"DefaultWebUsbGuardSetting\" policy if it is set, or the user's personal configuration otherwise.\n\nURL patterns in this policy shouldn't clash with the ones configured via \"WebUsbBlockedForUrls\". If there's a clash, this policy takes precedence over \"WebUsbBlockedForUrls\" and \"WebUsbAskForUrls\".","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webusbaskforurls","displayName":"Allow WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can ask the user for access to a USB device.\n\nIf you don't configure this policy, the global default value from the \"DefaultWebUsbGuardSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"WebUsbBlockedForUrls\" policy - you can't both allow and block a URL. For detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webusbblockedforurls","displayName":"Block WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can't ask the user to grant them access to a USB device.\n\nIf you don't configure this policy, the global default value from the \"DefaultWebUsbGuardSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nURL patterns in this policy can't conflict with those configured in the \"WebUsbAskForUrls\" policy. You can't both allow and block a URL. For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.whatsnewpageforentraprofilesenabled","displayName":"Control whether an informational webpage for Edge for Business is shown in the new tab after major browser updates","description":"Starting in Microsoft Edge version 145, users with Microsoft Entra ID profiles will see an informational page about new Edge for Business features after major browser updates. This page highlights recent enhancements designed to promote secure and productive browsing.\n\nThis policy controls whether users with Microsoft Entra ID profiles see this informational page. This policy applies only to Microsoft Entra ID profiles and does not apply to Microsoft account (MSA) profiles.\n\nThis policy is available starting in Microsoft Edge version 144 to allow configuration ahead of the changes introduced in version 145.\n\nIf you enable this policy or do not configure it, Microsoft Edge shows the informational page by default.\nIf you disable this policy, Microsoft Edge does not show the informational page to users.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.whatsnewpageforentraprofilesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.whatsnewpageforentraprofilesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.windowcaptureallowedbyorigins","displayName":"Allow Window and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Window and Tab Capture.\n\nLeaving the policy unset means that sites won't be considered for an override at this scope of Capture.\n\nThis policy isn't considered if a site matches a URL pattern in any of the following policies: \"TabCaptureAllowedByOrigins\", \"SameOriginTabCaptureAllowedByOrigins\".\n\nIf a site matches a URL pattern in this policy, the following policies aren't considered: \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin; so, any path in the URL pattern is ignored.","helpText":null,"infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.windowmanagementallowedforurls","displayName":"Allow Window Management permission on specified sites","description":"Lets you configure a list of site URL patterns that specify sites, which automatically grant the window management permission. This extends the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\n\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\n\nIf this policy isn't configured for a site, then the policy from \"DefaultWindowManagementSetting\" applies to the site, if configured. Otherwise the permission follows the browser's defaults and lets users choose this permission per site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.windowmanagementblockedforurls","displayName":"Block Window Management permission on specified sites","description":"Lets you configure a list of site URL patterns that specify sites which can automatically deny the window management permission. This limits the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\n\nFor detailed information on valid site URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\n\nIf this policy isn't configured for a site, then the policy from \"DefaultWindowManagementSetting\" applies to the site, if configured. Otherwise the permission follows the browser's defaults and lets users choose this permission per site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.workspacesnavigationsettings","displayName":"Configure navigation settings per groups of URLs in Microsoft Edge Workspaces","description":"This setting lets you define groups of URLs, and apply specific Microsoft Edge Workspaces navigation settings to each group.\n\nIf you configure this policy, Microsoft Edge Workspaces use the configured settings when deciding whether and how to share navigations among collaborators in a Microsoft Edge Workspace.\n\nIf you don't configure this policy, Microsoft Edge Workspaces use only default and internally configured navigation settings.\n\nFor more information about configuration options, see https://go.microsoft.com/fwlink/?linkid=2218655\n\nNote, format url_patterns according to https://go.microsoft.com/fwlink/?linkid=2095322. You can configure the url_regex_patterns in this policy to match multiple URLs using a Perl style regular expression for the pattern. Note that pattern matches are case sensitive. For more information about the regular expression rules that are used, refer to https://go.microsoft.com/fwlink/p/?linkid=2133903.","helpText":null,"infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.xsltenabled","displayName":"Control the availability of the XSLT feature","description":"Controls whether the XSLT feature (the XSLTProcessor JavaScript API and the XSL processing instruction) is available in Microsoft Edge.\n\nIf you enable this policy, XSLT is available regardless of the browser's default configuration.\n\nIf you disable this policy, XSLT is unavailable regardless of the browser's default configuration.\n\nIf you don't configure this policy, XSLT availability is determined by the browser's default configuration and any applicable field trials.\n\nThis policy is temporary and will be removed in a future version of Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.xsltenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.xsltenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.intune.mam.managedbrowser.appproxyredirection","displayName":"Application proxy redirection","description":"Enable App proxy redirection to give users access to corporate links and on-premise web apps.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.intune.mam.managedbrowser.appproxyredirection_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.intune.mam.managedbrowser.appproxyredirection_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"command_remotedesktop","displayName":"Remote Desktop","description":"","helpText":null,"infoUrls":[],"categoryId":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","categoryName":"Remote Desktop","options":null},{"id":"command_remotedesktop_remotedesktop","displayName":"Remote Desktop","description":"Enable/Disable Remote Desktop on the device","helpText":null,"infoUrls":[],"categoryId":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","categoryName":"Remote Desktop","options":[{"id":"command_remotedesktop_remotedesktop_true","displayName":"Enable","description":null,"helpText":null},{"id":"command_remotedesktop_remotedesktop_false","displayName":"Disable","description":null,"helpText":null}]},{"id":"ddm-latestsoftwareupdate_ddm-latestsoftwareupdate","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"15be55d8-7477-4274-9b09-b775bce68416","categoryName":"Software Update Enforce Latest","options":null},{"id":"ddm-latestsoftwareupdate_delayindays","displayName":"Delay In Days","description":"Specify the number of days that should pass before a deadline is enforced after a new update is released by Apple.","helpText":null,"infoUrls":[],"categoryId":"15be55d8-7477-4274-9b09-b775bce68416","categoryName":"Software Update Enforce Latest","options":null},{"id":"ddm-latestsoftwareupdate_enforcelatestsoftwareupdateversion","displayName":"Enforce Latest Software Update Version","description":"If true, devices will upgrade to the latest OS version that is available for that device model. This uses the Software Update Enforcement configuration and will force devices to restart and install the update after the deadline passes.","helpText":null,"infoUrls":[],"categoryId":"15be55d8-7477-4274-9b09-b775bce68416","categoryName":"Software Update Enforce Latest","options":{"id":"ddm-latestsoftwareupdate_enforcelatestsoftwareupdateversion_0","displayName":"True","description":null,"helpText":null}},{"id":"ddm-latestsoftwareupdate_installtime","displayName":"Install Time","description":"Specify the local device time for when updates are enforced. This setting uses the 24-hour clock format where midnight is 00:00 and 11:59pm is 23:59. Ensure that you include the leading 0 on single digit hours. For example, 01:00, 02:00, 03:00.","helpText":null,"infoUrls":[],"categoryId":"15be55d8-7477-4274-9b09-b775bce68416","categoryName":"Software Update Enforce Latest","options":null},{"id":"defender_disableprivacymode","displayName":"Allow users to view the full History results","description":"Disable the privacy mode","helpText":null,"infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"defender_disableprivacymode_0","displayName":"No","description":null,"helpText":null},{"id":"defender_disableprivacymode_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"defender_disablerestorepoint","displayName":"Create a system restore point before computers are cleaned","description":"Disables restore point","helpText":null,"infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"defender_disablerestorepoint_0","displayName":"No","description":null,"helpText":null},{"id":"defender_disablerestorepoint_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"defender_randomizescheduletasktimes","displayName":"Randomize scheduled scan and security intelligence update start times","description":"This setting allows you to enable or disable randomization of the scheduled scan start time and the scheduled definition update start time. This setting is used to distribute the resource impact of scanning. For example, it could be used in guest virtual machines sharing a host, to prevent multiple guest virtual machines from undertaking a disk-intensive operation at the same time.","helpText":null,"infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"defender_randomizescheduletasktimes_0","displayName":"No","description":null,"helpText":null},{"id":"defender_randomizescheduletasktimes_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_deletionpolicy","displayName":"Deletion Policy","description":"Configures when profiles will be deleted. Allowed values: 0 (delete immediately upon device returning to a state with no currently active users); 1 (delete at storage capacity threshold); 2 (delete at both storage capacity threshold and profile inactivity threshold).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":[{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_deletionpolicy_0","displayName":"Delete immediately upon device returning to a state with no currently active users)","description":"Delete immediately upon device returning to a state with no currently active users)","helpText":null},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_deletionpolicy_1","displayName":"Delete at storage capacity threshold","description":"Delete at storage capacity threshold","helpText":null},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_deletionpolicy_2","displayName":"Delete at both storage capacity threshold and profile inactivity threshold","description":"Delete at both storage capacity threshold and profile inactivity threshold","helpText":null}]},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_enableprofilemanager","displayName":"Enable Profile Manager","description":"Enable profile lifetime mangement for shared or communal device scenarios.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":[{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_enableprofilemanager_false","displayName":"False","description":"False","helpText":null},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_enableprofilemanager_true","displayName":"True","description":"True","helpText":null}]},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_profileinactivitythreshold","displayName":"Profile Inactivity Threshold","description":"Start deleting profiles when they have not been logged on during the specified period, given as number of days.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":null},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_storagecapacitystartdeletion","displayName":"Storage Capacity Start Deletion","description":"Start deleting profiles when available storage capacity falls below this threshold, given as percent of total storage available for profiles. Profiles that have been inactive the longest will be deleted first.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":null},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_storagecapacitystopdeletion","displayName":"Storage Capacity Stop Deletion","description":"Stop deleting profiles when available storage capacity is brought up to this threshold, given as percent of total storage available for profiles.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":null},{"id":"device_vendor_msft_bitlocker_allowstandarduserencryption","displayName":"Allow Standard User Encryption","description":"Allows Admin to enforce \"RequireDeviceEncryption\" policy for scenarios where policy is pushed while current logged on user is non-admin/standard user.\n \"AllowStandardUserEncryption\" policy is tied to \"AllowWarningForOtherDiskEncryption\" policy being set to \"0\", i.e, Silent encryption is enforced.\n If \"AllowWarningForOtherDiskEncryption\" is not set, or is set to \"1\", \"RequireDeviceEncryption\" policy will not try to encrypt drive(s) if a standard user\n is the current logged on user in the system.\n\n The expected values for this policy are: \n\n 1 = \"RequireDeviceEncryption\" policy will try to enable encryption on all fixed drives even if a current logged in user is standard user.\n 0 = This is the default, when the policy is not set. If current logged on user is a standard user, \"RequireDeviceEncryption\" policy\n will not try to enable encryption on any drive.\n\n If you want to disable this policy use the following SyncML:\n 111./Device/Vendor/MSFT/BitLocker/AllowStandardUserEncryptionint0","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":[{"id":"device_vendor_msft_bitlocker_allowstandarduserencryption_0","displayName":"Disabled","description":"This is the default, when the policy is not set. If current logged on user is a standard user, \"RequireDeviceEncryption\" policy will not try to enable encryption on any drive.","helpText":null},{"id":"device_vendor_msft_bitlocker_allowstandarduserencryption_1","displayName":"Enabled","description":"\"RequireDeviceEncryption\" policy will try to enable encryption on all fixed drives even if a current logged in user is standard user.","helpText":null}]},{"id":"device_vendor_msft_bitlocker_allowwarningforotherdiskencryption","displayName":"Allow Warning For Other Disk Encryption","description":"Allows Admin to disable all UI (notification for encryption and warning prompt for other disk encryption)\n and turn on encryption on the user machines silently.\n Warning: When you enable BitLocker on a device with third party encryption, it may render the device unusable and will\n require reinstallation of Windows.\n Note: This policy takes effect only if \"RequireDeviceEncryption\" policy is set to 1.\n The format is integer.\n The expected values for this policy are: \n\n 1 = This is the default, when the policy is not set. Warning prompt and encryption notification is allowed.\n 0 = Disables the warning prompt and encryption notification. Starting in Windows 10, next major update, \n the value 0 only takes affect on Entra ID joined devices. \n Windows will attempt to silently enable BitLocker for value 0.\n\n If you want to disable this policy use the following SyncML:\n 110./Device/Vendor/MSFT/BitLocker/AllowWarningForOtherDiskEncryptionint0","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#allowwarningforotherdiskencryption"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":[{"id":"device_vendor_msft_bitlocker_allowwarningforotherdiskencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_allowwarningforotherdiskencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation","displayName":"Configure Recovery Password Rotation","description":" Allows Admin to configure Numeric Recovery Password Rotation upon use for OS and fixed drives on Entra ID and Hybrid domain joined devices.\n When not configured, Rotation is turned on by default for Entra ID only and off on Hybrid. The Policy will be effective only when \n Active Directory back up for recovery password is configured to required.\n For OS drive: Turn on \"Do not enable Bitlocker until recovery information is stored to AD DS for operating system drives\"\n For Fixed drives: Turn on \"Do not enable Bitlocker until recovery information is stored to AD DS for fixed data drives\"\n \n Supported Values: 0 - Numeric Recovery Passwords rotation OFF.\n 1 - Numeric Recovery Passwords Rotation upon use ON for Entra ID joined devices. Default value\n 2 - Numeric Recovery Passwords Rotation upon use ON for both Entra ID and Hybrid devices\n \n If you want to disable this policy use the following SyncML:\n \n 112./Device/Vendor/MSFT/BitLocker/ConfigureRecoveryPasswordRotationint0","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":[{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation_0","displayName":"Refresh off (default)","description":"Refresh off (default)","helpText":null},{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation_1","displayName":"Refresh on for Entra ID-joined devices","description":"Refresh on for Entra ID-joined devices","helpText":null},{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation_2","displayName":"Refresh on for both Entra ID-joined and hybrid-joined devices","description":"Refresh on for both Entra ID-joined and hybrid-joined devices","helpText":null}]},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype","displayName":"Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)","description":"This policy setting allows you to configure the algorithm and cipher strength used by BitLocker Drive Encryption. This policy setting is applied when you turn on BitLocker. Changing the encryption method has no effect if the drive is already encrypted, or if encryption is in progress.\n\nIf you enable this policy setting you will be able to configure an encryption algorithm and key cipher strength for fixed data drives, operating system drives, and removable data drives individually. For fixed and operating system drives, we recommend that you use the XTS-AES algorithm. For removable drives, you should use AES-CBC 128-bit or AES-CBC 256-bit if the drive will be used in other devices that are not running Windows 10 (Version 1511).\n\nIf you disable or do not configure this policy setting, BitLocker will use AES with the same bit strength (128-bit or 256-bit) as the \"Choose drive encryption method and cipher strength (Windows Vista, Windows Server 2008, Windows 7)\" and \"Choose drive encryption method and cipher strength\" policy settings (in that order), if they are set. If none of the policies are set, BitLocker will use the default encryption method of XTS-AES 128-bit or the encryption method specified by the setup script.”\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#encryptionmethodbydrivetype"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsfdvdropdown_name","displayName":"Select the encryption method for fixed data drives:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#encryptionmethodbydrivetype"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsfdvdropdown_name_3","displayName":"AES-CBC 128-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsfdvdropdown_name_4","displayName":"AES-CBC 256-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsfdvdropdown_name_6","displayName":"XTS-AES 128-bit (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsfdvdropdown_name_7","displayName":"XTS-AES 256-bit","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsosdropdown_name","displayName":"Select the encryption method for operating system drives:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#encryptionmethodbydrivetype"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsosdropdown_name_3","displayName":"AES-CBC 128-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsosdropdown_name_4","displayName":"AES-CBC 256-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsosdropdown_name_6","displayName":"XTS-AES 128-bit (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsosdropdown_name_7","displayName":"XTS-AES 256-bit","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name","displayName":"Select the encryption method for removable data drives:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#encryptionmethodbydrivetype"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_3","displayName":"AES-CBC 128-bit (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_4","displayName":"AES-CBC 256-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_6","displayName":"XTS-AES 128-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_7","displayName":"XTS-AES 256-bit","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype","displayName":"Enforce drive encryption type on fixed data drives","description":"This policy setting allows you to configure the encryption type used by BitLocker Drive Encryption. This policy setting is applied when you turn on BitLocker. Changing the encryption type has no effect if the drive is already encrypted or if encryption is in progress. Choose full encryption to require that the entire drive be encrypted when BitLocker is turned on. Choose used space only encryption to require that only the portion of the drive used to store data is encrypted when BitLocker is turned on.\r\n\r\nIf you enable this policy setting the encryption type that BitLocker will use to encrypt drives is defined by this policy and the encryption type option will not be presented in the BitLocker setup wizard.\r\n\r\nIf you disable or do not configure this policy setting, the BitLocker setup wizard will ask the user to select the encryption type before turning on BitLocker.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name","displayName":"Select the encryption type:","description":"","helpText":"","infoUrls":[],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name_0","displayName":"Allow user to choose (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name_1","displayName":"Full encryption","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name_2","displayName":"Used Space Only encryption","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions","displayName":"Choose how BitLocker-protected fixed drives can be recovered","description":"This policy setting allows you to control how BitLocker-protected fixed data drives are recovered in the absence of the required credentials. This policy setting is applied when you turn on BitLocker.\n\nThe \"Allow data recovery agent\" check box is used to specify whether a data recovery agent can be used with BitLocker-protected fixed data drives. Before a data recovery agent can be used it must be added from the Public Key Policies item in either the Group Policy Management Console or the Local Group Policy Editor. Consult the BitLocker Drive Encryption Deployment Guide on Microsoft TechNet for more information about adding data recovery agents.\n\nIn \"Configure user storage of BitLocker recovery information\" select whether users are allowed, required, or not allowed to generate a 48-digit recovery password or a 256-bit recovery key.\n\nSelect \"Omit recovery options from the BitLocker setup wizard\" to prevent users from specifying recovery options when they turn on BitLocker on a drive. This means that you will not be able to specify which recovery option to use when you turn on BitLocker, instead BitLocker recovery options for the drive are determined by the policy setting.\n\nIn \"Save BitLocker recovery information to Active Directory Domain Services\" choose which BitLocker recovery information to store in AD DS for fixed data drives. If you select \"Backup recovery password and key package\", both the BitLocker recovery password and key package are stored in AD DS. Storing the key package supports recovering data from a drive that has been physically corrupted. If you select \"Backup recovery password only,\" only the recovery password is stored in AD DS.\n\nSelect the \"Do not enable BitLocker until recovery information is stored in AD DS for fixed data drives\" check box if you want to prevent users from enabling BitLocker unless the computer is connected to the domain and the backup of BitLocker recovery information to AD DS succeeds.\n\nNote: If the \"Do not enable BitLocker until recovery information is stored in AD DS for fixed data drives\" check box is selected, a recovery password is automatically generated.\n\nIf you enable this policy setting, you can control the methods available to users to recover data from BitLocker-protected fixed data drives.\n\nIf this policy setting is not configured or disabled, the default recovery options are supported for BitLocker recovery. By default a DRA is allowed, the recovery options can be specified by the user including the recovery password and recovery key, and recovery information is not backed up to AD DS\n\n","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackup_name","displayName":"Save BitLocker recovery information to AD DS for fixed data drives","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackup_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackup_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackupdropdown_name","displayName":"Configure storage of BitLocker recovery information to AD DS:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackupdropdown_name_1","displayName":"Backup recovery passwords and key packages","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackupdropdown_name_2","displayName":"Backup recovery passwords only","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvallowdra_name","displayName":"Allow data recovery agent","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvallowdra_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvallowdra_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvhiderecoverypage_name","displayName":"Omit recovery options from the BitLocker setup wizard","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvhiderecoverypage_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvhiderecoverypage_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name","displayName":"FDVRecoveryKeyUsageDropDown_Name","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name_2","displayName":"Allow 256-bit recovery key","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name_1","displayName":"Require 256-bit recovery key","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name_0","displayName":"Do not allow 256-bit recovery key","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverypasswordusagedropdown_name","displayName":"Configure user storage of BitLocker recovery information:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverypasswordusagedropdown_name_2","displayName":"Allow 48-digit recovery password","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverypasswordusagedropdown_name_1","displayName":"Require 48-digit recovery password","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverypasswordusagedropdown_name_0","displayName":"Do not allow 48-digit recovery password","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrequireactivedirectorybackup_name","displayName":"Do not enable BitLocker until recovery information is stored to AD DS for fixed data drives","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrequireactivedirectorybackup_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrequireactivedirectorybackup_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrequireencryption","displayName":"Deny write access to fixed drives not protected by BitLocker","description":"This policy setting determines whether BitLocker protection is required for fixed data drives to be writable on a computer.\n\nIf you enable this policy setting, all fixed data drives that are not BitLocker-protected will be mounted as read-only. If the drive is protected by BitLocker, it will be mounted with read and write access.\n\nIf you disable or do not configure this policy setting, all fixed data drives on the computer will be mounted with read and write access.\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrequireencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrequireencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_identificationfield","displayName":"Provide the unique identifiers for your organization","description":"This policy setting allows you to associate unique organizational identifiers to a new drive that is enabled with BitLocker. These identifiers are stored as the identification field and allowed identification field. The identification field allows you to associate a unique organizational identifier to BitLocker-protected drives. This identifier is automatically added to new BitLocker-protected drives and can be updated on existing BitLocker-protected drives using the manage-bde command-line tool. An identification field is required for management of certificate-based data recovery agents on BitLocker-protected drives and for potential updates to the BitLocker To Go Reader. BitLocker will only manage and update data recovery agents when the identification field on the drive matches the value configured in the identification field. In a similar manner, BitLocker will only update the BitLocker To Go Reader when the identification field on the drive matches the value configured for the identification field.\r\n\r\nThe allowed identification field is used in combination with the \"Deny write access to removable drives not protected by BitLocker\" policy setting to help control the use of removable drives in your organization. It is a comma separated list of identification fields from your organization or other external organizations.\r\n\r\nYou can configure the identification fields on existing drives by using manage-bde.exe.\r\n\r\nIf you enable this policy setting, you can configure the identification field on the BitLocker-protected drive and any allowed identification field used by your organization.\r\n\r\nWhen a BitLocker-protected drive is mounted on another BitLocker-enabled computer the identification field and allowed identification field will be used to determine whether the drive is from an outside organization.\r\n\r\nIf you disable or do not configure this policy setting, the identification field is not required.\r\n\r\nNote: Identification fields are required for management of certificate-based data recovery agents on BitLocker-protected drives. BitLocker will only manage and update certificate-based data recovery agents when the identification field is present on a drive and is identical to the value configured on the computer. The identification field can be any value of 260 characters or fewer.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_identificationfield_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_identificationfield_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_identificationfield_identificationfield","displayName":"BitLocker identification field:","description":"","helpText":"","infoUrls":[],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":null},{"id":"device_vendor_msft_bitlocker_identificationfield_secidentificationfield","displayName":"Allowed BitLocker identification field:","description":"","helpText":"","infoUrls":[],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":null},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde","displayName":"Control use of BitLocker on removable drives","description":"This policy setting controls the use of BitLocker on removable data drives. This policy setting is applied when you turn on BitLocker.\r\n\r\nWhen this policy setting is enabled you can select property settings that control how users can configure BitLocker. Choose \"Allow users to apply BitLocker protection on removable data drives\" to permit the user to run the BitLocker setup wizard on a removable data drive. Choose \"Allow users to suspend and decrypt BitLocker on removable data drives\" to permit the user to remove BitLocker Drive encryption from the drive or suspend the encryption while maintenance is performed. Consult the BitLocker Drive Encryption Deployment Guide on Microsoft TechNet for more information on suspending BitLocker protection.\r\n\r\nIf you do not configure this policy setting, users can use BitLocker on removable disk drives.\r\n\r\nIf you disable this policy setting, users cannot use BitLocker on removable disk drives.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvallowbde_name","displayName":"Allow users to apply BitLocker protection on removable data drives","description":"","helpText":"","infoUrls":[],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvallowbde_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvallowbde_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvdisablebde_name","displayName":"Allow users to suspend and decrypt BitLocker protection on removable data drives","description":"","helpText":"","infoUrls":[],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvdisablebde_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvdisablebde_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype","displayName":"Enforce drive encryption type on removable data drives","description":"This policy setting allows you to configure the encryption type used by BitLocker Drive Encryption. This policy setting is applied when you turn on BitLocker. Changing the encryption type has no effect if the drive is already encrypted or if encryption is in progress. Choose full encryption to require that the entire drive be encrypted when BitLocker is turned on. Choose used space only encryption to require that only the portion of the drive used to store data is encrypted when BitLocker is turned on.\r\n\r\nIf you enable this policy setting the encryption type that BitLocker will use to encrypt drives is defined by this policy and the encryption type option will not be presented in the BitLocker setup wizard.\r\n\r\nIf you disable or do not configure this policy setting, the BitLocker setup wizard will ask the user to select the encryption type before turning on BitLocker.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_rdvencryptiontypedropdown_name","displayName":"Select the encryption type:","description":"","helpText":"","infoUrls":[],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_rdvencryptiontypedropdown_name_0","displayName":"Allow user to choose (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_rdvencryptiontypedropdown_name_1","displayName":"Full encryption","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_rdvencryptiontypedropdown_name_2","displayName":"Used Space Only encryption","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_removabledrivesexcludedfromencryption","displayName":"Removable Drives Excluded From Encryption","description":"When enabled, allows you to exclude removable drives and devices connected over USB interface from BitLocker Device Encryption. Excluded devices cannot be encrypted, even manually. Additionally, if \"Deny write access to removable drives not protected by BitLocker\" is configured, user will not be prompted for encryption and drive will be mounted in read/write mode. Provide a comma separated list of excluded removable drives\\devices, using the Hardware ID of the disk device. Example USBSTOR\\SEAGATE_ST39102LW_______0004.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":null},{"id":"device_vendor_msft_bitlocker_removabledrivesrequireencryption","displayName":"Deny write access to removable drives not protected by BitLocker","description":"This policy setting configures whether BitLocker protection is required for a computer to be able to write data to a removable data drive.\n\nIf you enable this policy setting, all removable data drives that are not BitLocker-protected will be mounted as read-only. If the drive is protected by BitLocker, it will be mounted with read and write access.\n\nIf the \"Deny write access to devices configured in another organization\" option is selected, only drives with identification fields matching the computer's identification fields will be given write access. When a removable data drive is accessed it will be checked for valid identification field and allowed identification fields. These fields are defined by the \"Provide the unique identifiers for your organization\" policy setting.\n\nIf you disable or do not configure this policy setting, all removable data drives on the computer will be mounted with read and write access.\n\nNote: This policy setting can be overridden by the policy settings under User Configuration\\Administrative Templates\\System\\Removable Storage Access. If the \"Removable Disks: Deny write access\" policy setting is enabled this policy setting will be ignored.\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesrequireencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesrequireencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_removabledrivesrequireencryption_rdvcrossorg","displayName":"Do not allow write access to devices configured in another organization","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesrequireencryption_rdvcrossorg_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesrequireencryption_rdvcrossorg_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_requiredeviceencryption","displayName":"Require Device Encryption","description":"Allows the Admin to require encryption to be turned on using BitLocker\\Device Encryption.\n The format is integer.\n Sample value for this node to enable this policy:\n 1\n\n Disabling the policy will not turn off the encryption on the system drive. But will stop prompting the user to turn it on.\n If you want to disable this policy use the following SyncML:\n 101./Device/Vendor/MSFT/BitLocker/RequireDeviceEncryptionint0","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":[{"id":"device_vendor_msft_bitlocker_requiredeviceencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_requiredeviceencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesdisallowstandarduserscanchangepin","displayName":"Disallow standard users from changing the PIN or password","description":"This policy setting allows you to configure whether or not standard users are allowed to change BitLocker volume PINs, provided they are able to provide the existing PIN first.\r\n\r\nThis policy setting is applied when you turn on BitLocker.\r\n\r\nIf you enable this policy setting, standard users will not be allowed to change BitLocker PINs or passwords.\r\n\r\nIf you disable or do not configure this policy setting, standard users will be permitted to change BitLocker PINs and passwords.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesdisallowstandarduserscanchangepin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesdisallowstandarduserscanchangepin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesenableprebootinputprotectorsonslates","displayName":"Enable use of BitLocker authentication requiring preboot keyboard input on slates","description":"This policy setting allows users to turn on authentication options that require user input from the pre-boot environment, even if the platform lacks pre-boot input capability.\r\n\r\nThe Windows touch keyboard (such as that used by tablets) isn't available in the pre-boot environment where BitLocker requires additional information such as a PIN or Password.\r\n\r\nIf you enable this policy setting, devices must have an alternative means of pre-boot input (such as an attached USB keyboard).\r\n\r\nIf this policy is not enabled, the Windows Recovery Environment must be enabled on tablets to support the entry of the BitLocker recovery password. When the Windows Recovery Environment is not enabled and this policy is not enabled, you cannot turn on BitLocker on a device that uses the Windows touch keyboard.\r\n\r\nNote that if you do not enable this policy setting, options in the \"Require additional authentication at startup\" policy might not be available on such devices. These options include:\r\n- Configure TPM startup PIN: Required/Allowed\r\n- Configure TPM startup key and PIN: Required/Allowed\r\n- Configure use of passwords for operating system drives.\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesenableprebootinputprotectorsonslates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesenableprebootinputprotectorsonslates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesenableprebootpinexceptionondecapabledevice","displayName":"Allow devices compliant with InstantGo or HSTI to opt out of pre-boot PIN.","description":"This policy setting allows users on devices that are compliant with InstantGo or Microsoft Hardware Security Test Interface (HSTI) to not have a PIN for pre-boot authentication. This overrides the \"Require startup PIN with TPM\" and \"Require startup key and PIN with TPM\" options of the \"Require additional authentication at startup\" policy on compliant hardware.\r\n\r\nIf you enable this policy setting, users on InstantGo and HSTI compliant devices will have the choice to turn on BitLocker without pre-boot authentication.\r\n\r\nIf this policy is not enabled, the options of \"Require additional authentication at startup\" policy apply.\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesenableprebootpinexceptionondecapabledevice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesenableprebootpinexceptionondecapabledevice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype","displayName":"Enforce drive encryption type on operating system drives","description":"This policy setting allows you to configure the encryption type used by BitLocker Drive Encryption. This policy setting is applied when you turn on BitLocker. Changing the encryption type has no effect if the drive is already encrypted or if encryption is in progress. Choose full encryption to require that the entire drive be encrypted when BitLocker is turned on. Choose used space only encryption to require that only the portion of the drive used to store data is encrypted when BitLocker is turned on.\r\n\r\nIf you enable this policy setting the encryption type that BitLocker will use to encrypt drives is defined by this policy and the encryption type option will not be presented in the BitLocker setup wizard.\r\n\r\nIf you disable or do not configure this policy setting, the BitLocker setup wizard will ask the user to select the encryption type before turning on BitLocker.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype_osencryptiontypedropdown_name","displayName":"Select the encryption type:","description":"","helpText":"","infoUrls":[],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype_osencryptiontypedropdown_name_0","displayName":"Allow user to choose (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype_osencryptiontypedropdown_name_1","displayName":"Full encryption","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype_osencryptiontypedropdown_name_2","displayName":"Used Space Only encryption","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesenhancedpin","displayName":"Allow enhanced PINs for startup","description":"This policy setting allows you to configure whether or not enhanced startup PINs are used with BitLocker.\r\n\r\nEnhanced startup PINs permit the use of characters including uppercase and lowercase letters, symbols, numbers, and spaces. This policy setting is applied when you turn on BitLocker.\r\n\r\nIf you enable this policy setting, all new BitLocker startup PINs set will be enhanced PINs.\r\n\r\nNote: Not all computers may support enhanced PINs in the pre-boot environment. It is strongly recommended that users perform a system check during BitLocker setup.\r\n\r\nIf you disable or do not configure this policy setting, enhanced PINs will not be used.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesenhancedpin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesenhancedpin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength","displayName":"Configure minimum PIN length for startup","description":"\n This policy setting allows you to configure a minimum length for a Trusted Platform Module (TPM) startup PIN. This policy setting is applied when you turn on BitLocker. The startup PIN must have a minimum length of 4 digits and can have a maximum length of 20 digits.\n\n If you enable this policy setting, you can require a minimum number of digits to be used when setting the startup PIN.\n\n If you disable or do not configure this policy setting, users can configure a startup PIN of any length between 6 and 20 digits.\n\n NOTE: If minimum PIN length is set below 6 digits, Windows will attempt to update the TPM 2.0 lockout period to be greater than the default when a PIN is changed. If successful, Windows will only reset the TPM lockout period back to default if the TPM is reset.\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength_minpinlength","displayName":"Minimum characters:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage","displayName":"Configure pre-boot recovery message and URL","description":"This policy setting lets you configure the entire recovery message or replace the existing URL that are displayed on the pre-boot key recovery screen when the OS drive is locked.\n\nIf you select the \"Use default recovery message and URL\" option, the default BitLocker recovery message and URL will be displayed in the pre-boot key recovery screen. If you have previously configured a custom recovery message or URL and want to revert to the default message, you must keep the policy enabled and select the \"Use default recovery message and URL\" option.\n\nIf you select the \"Use custom recovery message\" option, the message you type in the \"Custom recovery message option\" text box will be displayed in the pre-boot key recovery screen. If a recovery URL is available, include it in the message.\n\nIf you select the \"Use custom recovery URL\" option, the URL you type in the \"Custom recovery URL option\" text box will replace the default URL in the default recovery message, which will be displayed in the pre-boot key recovery screen.\n\nNote: Not all characters and languages are supported in pre-boot. It is strongly recommended that you test that the characters you use for the custom message or URL appear correctly on the pre-boot recovery screen.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_prebootrecoveryinfodropdown_name","displayName":"Select an option for the pre-boot recovery message:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_prebootrecoveryinfodropdown_name_0","displayName":"","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_prebootrecoveryinfodropdown_name_1","displayName":"Use default recovery message and URL","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_prebootrecoveryinfodropdown_name_2","displayName":"Use custom recovery message","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_prebootrecoveryinfodropdown_name_3","displayName":"Use custom recovery URL","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_recoverymessage_input","displayName":"Custom recovery message option:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_recoveryurl_input","displayName":"Custom recovery URL option:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions","displayName":"Choose how BitLocker-protected operating system drives can be recovered","description":"This policy setting allows you to control how BitLocker-protected operating system drives are recovered in the absence of the required startup key information. This policy setting is applied when you turn on BitLocker.\n\nThe \"Allow certificate-based data recovery agent\" check box is used to specify whether a data recovery agent can be used with BitLocker-protected operating system drives. Before a data recovery agent can be used it must be added from the Public Key Policies item in either the Group Policy Management Console or the Local Group Policy Editor. Consult the BitLocker Drive Encryption Deployment Guide on Microsoft TechNet for more information about adding data recovery agents.\n\nIn \"Configure user storage of BitLocker recovery information\" select whether users are allowed, required, or not allowed to generate a 48-digit recovery password or a 256-bit recovery key.\n\nSelect \"Omit recovery options from the BitLocker setup wizard\" to prevent users from specifying recovery options when they turn on BitLocker on a drive. This means that you will not be able to specify which recovery option to use when you turn on BitLocker, instead BitLocker recovery options for the drive are determined by the policy setting.\n\nIn \"Save BitLocker recovery information to Active Directory Domain Services\", choose which BitLocker recovery information to store in AD DS for operating system drives. If you select \"Backup recovery password and key package\", both the BitLocker recovery password and key package are stored in AD DS. Storing the key package supports recovering data from a drive that has been physically corrupted. If you select \"Backup recovery password only,\" only the recovery password is stored in AD DS.\n\nSelect the \"Do not enable BitLocker until recovery information is stored in AD DS for operating system drives\" check box if you want to prevent users from enabling BitLocker unless the computer is connected to the domain and the backup of BitLocker recovery information to AD DS succeeds.\n\nNote: If the \"Do not enable BitLocker until recovery information is stored in AD DS for operating system drives\" check box is selected, a recovery password is automatically generated.\n\nIf you enable this policy setting, you can control the methods available to users to recover data from BitLocker-protected operating system drives.\n\nIf this policy setting is disabled or not configured, the default recovery options are supported for BitLocker recovery. By default a DRA is allowed, the recovery options can be specified by the user including the recovery password and recovery key, and recovery information is not backed up to AD DS.\n\n","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackup_name","displayName":"Save BitLocker recovery information to AD DS for operating system drives","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackup_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackup_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackupdropdown_name","displayName":"Configure storage of BitLocker recovery information to AD DS:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackupdropdown_name_1","displayName":"Store recovery passwords and key packages","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackupdropdown_name_2","displayName":"Store recovery passwords only","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osallowdra_name","displayName":"Allow data recovery agent","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osallowdra_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osallowdra_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_oshiderecoverypage_name","displayName":"Omit recovery options from the BitLocker setup wizard","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_oshiderecoverypage_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_oshiderecoverypage_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverykeyusagedropdown_name","displayName":"OSRecoveryKeyUsageDropDown_Name","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverykeyusagedropdown_name_2","displayName":"Allow 256-bit recovery key","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverykeyusagedropdown_name_1","displayName":"Require 256-bit recovery key","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverykeyusagedropdown_name_0","displayName":"Do not allow 256-bit recovery key","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverypasswordusagedropdown_name","displayName":"Configure user storage of BitLocker recovery information:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverypasswordusagedropdown_name_2","displayName":"Allow 48-digit recovery password","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverypasswordusagedropdown_name_1","displayName":"Require 48-digit recovery password","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverypasswordusagedropdown_name_0","displayName":"Do not allow 48-digit recovery password","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrequireactivedirectorybackup_name","displayName":"Do not enable BitLocker until recovery information is stored to AD DS for operating system drives","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrequireactivedirectorybackup_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrequireactivedirectorybackup_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication","displayName":"Require additional authentication at startup","description":"This policy setting allows you to configure whether BitLocker requires additional authentication each time the computer starts and whether you are using BitLocker with or without a Trusted Platform Module (TPM). This policy setting is applied when you turn on BitLocker.\n\nNote: Only one of the additional authentication options can be required at startup, otherwise a policy error occurs.\n\nIf you want to use BitLocker on a computer without a TPM, select the \"Allow BitLocker without a compatible TPM\" check box. In this mode either a password or a USB drive is required for start-up. When using a startup key, the key information used to encrypt the drive is stored on the USB drive, creating a USB key. When the USB key is inserted the access to the drive is authenticated and the drive is accessible. If the USB key is lost or unavailable or if you have forgotten the password then you will need to use one of the BitLocker recovery options to access the drive.\n\nOn a computer with a compatible TPM, four types of authentication methods can be used at startup to provide added protection for encrypted data. When the computer starts, it can use only the TPM for authentication, or it can also require insertion of a USB flash drive containing a startup key, the entry of a 6-digit to 20-digit personal identification number (PIN), or both.\n\nIf you enable this policy setting, users can configure advanced startup options in the BitLocker setup wizard.\n\nIf you disable or do not configure this policy setting, users can configure only basic options on computers with a TPM.\n\nNote: If you want to require the use of a startup PIN and a USB flash drive, you must configure BitLocker settings using the command-line tool manage-bde instead of the BitLocker Drive Encryption setup wizard.\n\n","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurenontpmstartupkeyusage_name","displayName":"Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurenontpmstartupkeyusage_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurenontpmstartupkeyusage_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurepinusagedropdown_name","displayName":"Configure TPM startup PIN:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurepinusagedropdown_name_2","displayName":"Allow startup PIN with TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurepinusagedropdown_name_1","displayName":"Require startup PIN with TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurepinusagedropdown_name_0","displayName":"Do not allow startup PIN with TPM","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmpinkeyusagedropdown_name","displayName":"Configure TPM startup key and PIN:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmpinkeyusagedropdown_name_2","displayName":"Allow startup key and PIN with TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmpinkeyusagedropdown_name_1","displayName":"Require startup key and PIN with TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmpinkeyusagedropdown_name_0","displayName":"Do not allow startup key and PIN with TPM","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmstartupkeyusagedropdown_name","displayName":"Configure TPM startup key:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmstartupkeyusagedropdown_name_2","displayName":"Allow startup key with TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmstartupkeyusagedropdown_name_1","displayName":"Require startup key with TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmstartupkeyusagedropdown_name_0","displayName":"Do not allow startup key with TPM","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name","displayName":"Configure TPM startup:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name_2","displayName":"Allow TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name_1","displayName":"Require TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name_0","displayName":"Do not allow TPM","description":null,"helpText":null}]},{"id":"device_vendor_msft_clouddesktop_boottocloudpcenhanced","displayName":"Boot To Cloud PC Enhanced","description":"This node allows to configure different kinds of Boot to Cloud mode. Boot to cloud mode enables users to seamlessly sign-in to a Cloud PC. For using this feature, Cloud Provider application must be installed on the PC and the user must have a Cloud PC provisioned. This node supports the below options: 0. Not Configured. 1. Enable Boot to Cloud Shared PC Mode: Boot to Cloud Shared PC mode allows multiple users to sign-in on the device and use for shared purpose. 2. Enable Boot to Cloud Dedicated Mode (Cloud only): Dedicated mode allows user to sign-in on the device using various authentication mechanism configured by their organization (For ex. PIN, Biometrics etc). This mode preserves user personalization, including their profile picture and username in local machine, and facilitates fast account switching.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/CloudDesktop-csp/"],"categoryId":"39e4c352-be9c-4e75-8111-8236279c7f1e","categoryName":"Cloud Desktop","options":[{"id":"device_vendor_msft_clouddesktop_boottocloudpcenhanced_0","displayName":"Not Configured","description":"Not Configured","helpText":null},{"id":"device_vendor_msft_clouddesktop_boottocloudpcenhanced_1","displayName":"Enable Boot to Cloud Shared PC Mode","description":"Enable Boot to Cloud Shared PC Mode","helpText":null},{"id":"device_vendor_msft_clouddesktop_boottocloudpcenhanced_2","displayName":"Enable Boot to Cloud Dedicated Mode (Cloud only)","description":"Enable Boot to Cloud Dedicated Mode (Cloud only)","helpText":null}]},{"id":"device_vendor_msft_clouddesktop_enableboottocloudsharedpcmode","displayName":"[Deprecated] Enable Boot To Cloud Shared PC Mode","description":"Setting this node to \"true\" configures boot to cloud for Shared PC mode. Boot to cloud mode enables users to seamlessly sign-in to a Cloud PC. Shared PC mode allows multiple users to sign-in on the device and use for shared purpose. For enabling boot to cloud shared pc feature, Cloud Provider application must be installed on the PC and the user must have a Cloud PC provisioned.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/CloudDesktop-csp/"],"categoryId":"39e4c352-be9c-4e75-8111-8236279c7f1e","categoryName":"Cloud Desktop","options":[{"id":"device_vendor_msft_clouddesktop_enableboottocloudsharedpcmode_false","displayName":"Not configured","description":"Not configured","helpText":null},{"id":"device_vendor_msft_clouddesktop_enableboottocloudsharedpcmode_true","displayName":"Boot to cloud shared pc mode enabled","description":"Boot to cloud shared pc mode enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_aiagentnetworkinspection","displayName":"Ai Agent Network Inspection","description":"This setting controls Defender's runtime AI Agent network protection that scans network traffic originated from AI Agents. When enabled, Defender inspects the network traffic of agent processes and blocks any traffic that matches a detection for malware/abuse signals before the agent executes it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_aiagentnetworkinspection_0","displayName":"AI Agent protection is disabled (default).","description":"AI Agent protection is disabled (default).","helpText":null},{"id":"device_vendor_msft_defender_configuration_aiagentnetworkinspection_1","displayName":"AI Agent protection is enabled in block mode - prompts that match a detection are blocked.","description":"AI Agent protection is enabled in block mode - prompts that match a detection are blocked.","helpText":null},{"id":"device_vendor_msft_defender_configuration_aiagentnetworkinspection_2","displayName":"AI Agent protection is enabled in audit mode - prompts that match a detection are logged but not blocked.","description":"AI Agent protection is enabled in audit mode - prompts that match a detection are logged but not blocked.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_aiagentprotection","displayName":"Ai Agent Protection","description":"This setting controls Defender's runtime AI Agent protection that scans prompts submitted to managed AI coding agents (e.g., Claude Code, GitHub Copilot CLI). When enabled, Defender invokes a bridge process from the agent's hook framework to scan each prompt for malware/abuse signals before the agent executes it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_aiagentprotection_0","displayName":"AI Agent protection is disabled (default).","description":"AI Agent protection is disabled (default).","helpText":null},{"id":"device_vendor_msft_defender_configuration_aiagentprotection_1","displayName":"AI Agent protection is enabled in block mode - prompts that match a detection are blocked.","description":"AI Agent protection is enabled in block mode - prompts that match a detection are blocked.","helpText":null},{"id":"device_vendor_msft_defender_configuration_aiagentprotection_2","displayName":"AI Agent protection is enabled in audit mode - prompts that match a detection are logged but not blocked.","description":"AI Agent protection is enabled in audit mode - prompts that match a detection are logged but not blocked.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_allowdatagramprocessingonwinserver","displayName":"Allow Datagram Processing On Win Server","description":"This settings controls whether Network Protection is allowed to enable datagram processing on Windows Server. If false, the value of DisableDatagramProcessing will be ignored and default to disabling Datagram inspection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_allowdatagramprocessingonwinserver_1","displayName":"Datagram processing on Windows Server is enabled.","description":"Datagram processing on Windows Server is enabled.","helpText":null},{"id":"device_vendor_msft_defender_configuration_allowdatagramprocessingonwinserver_0","displayName":"Datagram processing on Windows Server is disabled.","description":"Datagram processing on Windows Server is disabled.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_allownetworkprotectiondownlevel","displayName":"Allow Network Protection Down Level","description":"This settings controls whether Network Protection is allowed to be configured into block or audit mode on windows downlevel of RS3. If false, the value of EnableNetworkProtection will be ignored.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_allownetworkprotectiondownlevel_1","displayName":"Network protection will be enabled downlevel.","description":"Network protection will be enabled downlevel.","helpText":null},{"id":"device_vendor_msft_defender_configuration_allownetworkprotectiondownlevel_0","displayName":"Network protection will be disabled downlevel.","description":"Network protection will be disabled downlevel.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_allownetworkprotectiononwinserver","displayName":"Allow Network Protection On Win Server","description":"This settings controls whether Network Protection is allowed to be configured into block or audit mode on Windows Server. If false, the value of EnableNetworkProtection will be ignored.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_allownetworkprotectiononwinserver_1","displayName":"Allow","description":"Allow","helpText":null},{"id":"device_vendor_msft_defender_configuration_allownetworkprotectiononwinserver_0","displayName":"Disallow","description":"Disallow","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_allowswitchtoasyncinspection","displayName":"Allow Switch To Async Inspection","description":"Control whether network protection can improve performance by switching from real-time inspection to asynchronous inspection","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_allowswitchtoasyncinspection_1","displayName":"Allow switching to asynchronous inspection","description":"Allow switching to asynchronous inspection","helpText":null},{"id":"device_vendor_msft_defender_configuration_allowswitchtoasyncinspection_0","displayName":"Don’t allow asynchronous inspection","description":"Don’t allow asynchronous inspection","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_archivemaxdepth","displayName":"Archive Max Depth","description":"Specify the maximum folder depth to extract from archive files for scanning. If this configuration is off or not set, the default value (0) is applied, and all archives are extracted up to the deepest folder for scanning.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_archivemaxsize","displayName":"Archive Max Size","description":"Specify the maximum size, in KB, of archive files to be extracted and scanned. If this configuration is off or not set, the default value (0) is applied, and all archives are extracted and scanned regardless of size.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_asronlyperruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionaggressiveness","displayName":"Remote Encryption Protection Aggressiveness","description":"Set the criteria for when Remote Encryption Protection blocks IP addresses.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionaggressiveness_0","displayName":"Low: Block only when confidence level is 100% (Default)","description":"Low: Block only when confidence level is 100% (Default)","helpText":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionaggressiveness_1","displayName":"Medium: Use cloud aggregation and block when confidence level is above 99%","description":"Medium: Use cloud aggregation and block when confidence level is above 99%","helpText":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionaggressiveness_2","displayName":"High: Use cloud intel and context, and block when confidence level is above 90%","description":"High: Use cloud intel and context, and block when confidence level is above 90%","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionconfiguredstate","displayName":"Remote Encryption Protection Configured State","description":"Remote Encryption Protection in Microsoft Defender Antivirus detects and blocks attempts to replace local files with encrypted versions from another device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionconfiguredstate_0","displayName":"Not configured: Apply defaults set for the antivirus engine and platform","description":"Not configured: Apply defaults set for the antivirus engine and platform","helpText":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionconfiguredstate_1","displayName":"Block: Prevent suspicious and malicious behaviors","description":"Block: Prevent suspicious and malicious behaviors","helpText":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionconfiguredstate_2","displayName":"Audit: Generate EDR detections without blocking","description":"Audit: Generate EDR detections without blocking","helpText":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionconfiguredstate_4","displayName":"Off: Feature is off with no performance impact","description":"Off: Feature is off with no performance impact","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionexclusions","displayName":"Remote Encryption Protection Exclusions","description":"Specify IP addresses, subnets, or workstation names to exclude from being blocked by Remote Encryption Protection. Note that attackers can spoof excluded addresses and names to bypass protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionmaxblocktime","displayName":"Remote Encryption Protection Max Block Time","description":"Set the maximum time an IP address is blocked by Remote Encryption Protection. After this time, blocked IP addresses will be able to reinitiate connections. If set to 0, internal feature logic will determine blocking time.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_dataduplicationdirectory","displayName":"Data Duplication Directory","description":"Define data duplication directory for device control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_dataduplicationlocalretentionperiod","displayName":"Data Duplication Local Retention Period","description":"Define the retention period in days of how much time the evidence data will be kept on the client machine should any transfer to the remote locations would occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_dataduplicationmaximumquota","displayName":"Data Duplication Maximum Quota","description":"Defines the maximum data duplication quota in MB that can be collected. When the quota is reached the filter will stop duplicating any data until the service manages to dispatch the existing collected data, thus decreasing the quota again below the maximum. The valid interval is [5-5000] MB. By default, the maximum quota will be 500 MB.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_dataduplicationremotelocation","displayName":"Data Duplication Remote Location","description":"Define data duplication remote location for Device Control. When configuring this setting, ensure that Device Control is Enabled and that the provided path is a remote path the user can access.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_daysuntilaggressivecatchupquickscan","displayName":"Days Until Aggressive Catchup Quick Scan","description":"Configure how many days can pass before an aggressive catchup quick scan is triggered. Valid values are 0 and [7-60]. Configuring this setting to 0 will disable aggressive catchup quick scans. By default, these scans will run every 30 days when enabled. These scans are only enabled if catchup scans (quick and full) are disabled, and Microsoft Defender Antivirus is not in Passive mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_defaultenforcement","displayName":"Default Enforcement","description":"Control Device Control default enforcement. This is the enforcement applied if there are no policy rules present or at the end of the policy rules evaluation none were matched.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_defaultenforcement_1","displayName":"Default Allow Enforcement","description":"Default Allow Enforcement","helpText":null},{"id":"device_vendor_msft_defender_configuration_defaultenforcement_2","displayName":"Default Deny Enforcement","description":"Default Deny Enforcement","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_deploymentchannel","displayName":"Deployment Channel","description":"Enable this policy to specify when devices receive Microsoft Defender binary updates based on the chosen deployment channel rollout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_deploymentchannel_0","displayName":"Not Configured (Default). If you don't configure this policy, devices are added to the release channel. Microsoft determines whether devices receive updates earlier or later within the release channel.","description":"Not Configured (Default). If you don't configure this policy, devices are added to the release channel. Microsoft determines whether devices receive updates earlier or later within the release channel.","helpText":null},{"id":"device_vendor_msft_defender_configuration_deploymentchannel_10","displayName":"Validation Channel: Devices set to this channel are the first to receive new monthly binary (platform and engine) updates. The likelihood of new issues occurring is higher, so add only devices with the highest risk tolerance to this channel (recommended for 1% or less of devices in your environment).","description":"Validation Channel: Devices set to this channel are the first to receive new monthly binary (platform and engine) updates. The likelihood of new issues occurring is higher, so add only devices with the highest risk tolerance to this channel (recommended for 1% or less of devices in your environment).","helpText":null},{"id":"device_vendor_msft_defender_configuration_deploymentchannel_20","displayName":"Release Channel - Early: The release channel is appropriate for most of your production environment. Devices set to this channel are offered updates earliest in the release channel. Distribute devices across early, fast and broad depending on their risk tolerance. Add devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment.","description":"Release Channel - Early: The release channel is appropriate for most of your production environment. Devices set to this channel are offered updates earliest in the release channel. Distribute devices across early, fast and broad depending on their risk tolerance. Add devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment.","helpText":null},{"id":"device_vendor_msft_defender_configuration_deploymentchannel_30","displayName":"Release Channel - Fast: The release channel is appropriate for most of your production environment. Devices are offered updates later during the gradual release cycle. Distribute devices across early, fast and broad depending on their risk tolerance. Use devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment.","description":"Release Channel - Fast: The release channel is appropriate for most of your production environment. Devices are offered updates later during the gradual release cycle. Distribute devices across early, fast and broad depending on their risk tolerance. Use devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment.","helpText":null},{"id":"device_vendor_msft_defender_configuration_deploymentchannel_40","displayName":"Release Channel - Broad: The release channel is appropriate for most of your production environment. Devices in this channel receive updates at the end of the gradual release cycle. Distribute devices across early, fast and broad depending on their risk tolerance. Use devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment.","description":"Release Channel - Broad: The release channel is appropriate for most of your production environment. Devices in this channel receive updates at the end of the gradual release cycle. Distribute devices across early, fast and broad depending on their risk tolerance. Use devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment.","helpText":null},{"id":"device_vendor_msft_defender_configuration_deploymentchannel_50","displayName":"Delayed Channel: Devices in this channel are offered updates approximately 48 hours after the devices in the release channel (broad). Use this channel for critical infrastructure and high value assets (~1% or less of devices).","description":"Delayed Channel: Devices in this channel are offered updates approximately 48 hours after the devices in the release channel (broad). Use this channel for critical infrastructure and high value assets (~1% or less of devices).","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}","displayName":"ID","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata","displayName":"Policy rule","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry","displayName":"Access","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask","displayName":"Access mask","description":"Defines the access.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":[{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_1","displayName":"Read","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_2","displayName":"Write","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_4","displayName":"Execute","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_8","displayName":"File read","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_16","displayName":"File write","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_32","displayName":"File execute","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_64","displayName":"Print","description":"","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_computersid","displayName":"Computer Sid","description":"Local computer Sid or computer Sid group or the Sid of the AD object, defines whether to apply this policy over a specific machine or machine group; one entry can have a maximum of one ComputerSid and an entry without any ComputerSid means applying the policy over the machine. If you want to apply an Entry to a specific user and specific machine, add both Sid and ComputerSid into the same Entry.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_id","displayName":"ID","description":"One PolicyRule can have multiple entries; each entry with a unique GUID tells Device Control one restriction.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_options","displayName":"Options","description":"Defines whether to display notification or not.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":[{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_options_0","displayName":"None","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_options_1","displayName":"Show notification","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_options_2","displayName":"Send event","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_options_3","displayName":"Send notification and event","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_options_4","displayName":"Disable","description":"","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_sid","displayName":"Sid","description":"Local user Sid or user Sid group or the Sid of the AD object, defines whether to apply this policy over a specific user or user group; one entry can have a maximum of one Sid and an entry without any Sid means applying the policy over the machine.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type","displayName":"Type","description":"Defines the action for the removable storage groups in IncludedIDList\nEnforcement: Allow or Deny\nAudit: AuditAllowed or AuditDenied","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":[{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_allow","displayName":"Allow","description":null,"helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_deny","displayName":"Deny","description":null,"helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_auditallowed","displayName":"Audit Allowed","description":null,"helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_auditdenied","displayName":"Audit Denied","description":null,"helpText":null}]},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_excludedidlist","displayName":"Excluded Devices","description":"The group(s) that the policy will not be applied to.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_excludedidlist_groupid","displayName":"Excluded Devices","description":"The group(s) that the policy will not be applied to.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_id","displayName":"ID","description":"GUID, a unique ID, represents the policy and will be used in the reporting and troubleshooting.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_includedidlist","displayName":"Included Devices","description":"The group(s) that the policy will be applied to. If multiple groups are added, the policy will be applied to any media in all those groups.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_includedidlist_groupid","displayName":"Included Devices","description":"The group(s) that the policy will be applied to. If multiple groups are added, the policy will be applied to any media in all those groups.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_name","displayName":"Name","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrolenabled","displayName":"Device Control Enabled","description":"Control Device Control feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_devicecontrolenabled_1","displayName":"Device Control is enabled","description":"Device Control is enabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrolenabled_0","displayName":"Device Control is disabled","description":"Device Control is disabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablecachemaintenance","displayName":"Disable Cache Maintenance","description":"Defines whether the cache maintenance idle task will perform the cache maintenance or not.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablecachemaintenance_1","displayName":"Cache maintenance is disabled","description":"Cache maintenance is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablecachemaintenance_0","displayName":"Cache maintenance is enabled (default)","description":"Cache maintenance is enabled (default)","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablecoreserviceecsintegration","displayName":"Disable Core Service ECS Integration","description":"Turn off ECS integration for Defender core service","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablecoreserviceecsintegration_0","displayName":"The Defender core service will use the Experimentation and Configuration Service (ECS) to rapidly deliver critical, org-specific fixes.","description":"The Defender core service will use the Experimentation and Configuration Service (ECS) to rapidly deliver critical, org-specific fixes.","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablecoreserviceecsintegration_1","displayName":"The Defender core service stops using the Experimentation and Configuration Service (ECS). Fixes will continue to be delivered through security intelligence updates.","description":"The Defender core service stops using the Experimentation and Configuration Service (ECS). Fixes will continue to be delivered through security intelligence updates.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablecoreservicetelemetry","displayName":"Disable Core Service Telemetry","description":"Turn off OneDsCollector telemetry for Defender core service","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablecoreservicetelemetry_0","displayName":"The Defender core service will use the OneDsCollector framework to rapidly collect telemetry.","description":"The Defender core service will use the OneDsCollector framework to rapidly collect telemetry.","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablecoreservicetelemetry_1","displayName":"The Defender core service stops using the OneDsCollector framework to rapidly collect telemetry, impacting Microsoft's ability to quickly recognize and address poor performance, false positives, and other problems.","description":"The Defender core service stops using the OneDsCollector framework to rapidly collect telemetry, impacting Microsoft's ability to quickly recognize and address poor performance, false positives, and other problems.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablecputhrottleonidlescans","displayName":"Disable Cpu Throttle On Idle Scans","description":"Indicates whether the CPU will be throttled for scheduled scans while the device is idle. This feature is enabled by default and will not throttle the CPU for scheduled scans performed when the device is otherwise idle, regardless of what ScanAvgCPULoadFactor is set to. For all other scheduled scans this flag will have no impact and normal throttling will occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablecputhrottleonidlescans_1","displayName":"Disable CPU Throttle on idle scans","description":"Disable CPU Throttle on idle scans","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablecputhrottleonidlescans_0","displayName":"Enable CPU Throttle on idle scans","description":"Enable CPU Throttle on idle scans","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disabledatagramprocessing","displayName":"Disable Datagram Processing","description":"Control whether network protection inspects User Datagram Protocol (UDP) traffic","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disabledatagramprocessing_1","displayName":"UDP inspection is off","description":"UDP inspection is off","helpText":null},{"id":"device_vendor_msft_defender_configuration_disabledatagramprocessing_0","displayName":"UDP inspection is on","description":"UDP inspection is on","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablednsovertcpparsing","displayName":"Disable Dns Over Tcp Parsing","description":"This setting disables DNS over TCP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablednsovertcpparsing_1","displayName":"DNS over TCP parsing is disabled","description":"DNS over TCP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablednsovertcpparsing_0","displayName":"DNS over TCP parsing is enabled","description":"DNS over TCP parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablednsparsing","displayName":"Disable Dns Parsing","description":"This setting disables DNS Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablednsparsing_1","displayName":"DNS parsing is disabled","description":"DNS parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablednsparsing_0","displayName":"DNS parsing is enabled","description":"DNS parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disableftpparsing","displayName":"Disable Ftp Parsing","description":"This setting disables FTP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disableftpparsing_1","displayName":"FTP parsing is disabled","description":"FTP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disableftpparsing_0","displayName":"FTP parsing is enabled","description":"FTP parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablegradualrelease","displayName":"Disable Gradual Release","description":"Enable this policy to disable gradual rollout of Defender updates.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablegradualrelease_1","displayName":"Gradual release is disabled","description":"Gradual release is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablegradualrelease_0","displayName":"Gradual release is enabled","description":"Gradual release is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablehttpparsing","displayName":"Disable Http Parsing","description":"This setting disables HTTP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablehttpparsing_1","displayName":"HTTP parsing is disabled","description":"HTTP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablehttpparsing_0","displayName":"HTTP parsing is enabled","description":"HTTP parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disableinboundconnectionfiltering","displayName":"Disable Inbound Connection Filtering","description":"This setting disables Inbound connection filtering for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disableinboundconnectionfiltering_1","displayName":"Inbound connection filtering is disabled","description":"Inbound connection filtering is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disableinboundconnectionfiltering_0","displayName":"Inbound connection filtering is enabled","description":"Inbound connection filtering is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablelocaladminmerge","displayName":"Disable Local Admin Merge","description":"When this value is set to false, it allows a local admin the ability to specify some settings for complex list type that will then merge /override the Preference settings with the Policy settings","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablelocaladminmerge_0","displayName":"Enable Local Admin Merge","description":"Enable Local Admin Merge","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablelocaladminmerge_1","displayName":"Disable Local Admin Merge","description":"Disable Local Admin Merge","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablenetworkprotectionperftelemetry","displayName":"Disable Network Protection Perf Telemetry","description":"This setting disables the gathering and send of performance telemetry from Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablenetworkprotectionperftelemetry_1","displayName":"Network protection telemetry is disabled","description":"Network protection telemetry is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablenetworkprotectionperftelemetry_0","displayName":"Network protection telemetry is enabled","description":"Network protection telemetry is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablequicparsing","displayName":"Disable Quic Parsing","description":"This setting disables QUIC Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablequicparsing_1","displayName":"QUIC parsing is disabled","description":"QUIC parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablequicparsing_0","displayName":"QUIC parsing is enabled","description":"QUIC parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablerdpparsing","displayName":"Disable Rdp Parsing","description":"This setting disables RDP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablerdpparsing_1","displayName":"RDP Parsing is disabled","description":"RDP Parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablerdpparsing_0","displayName":"RDP Parsing is enabled","description":"RDP Parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablesmtpparsing","displayName":"Disable Smtp Parsing","description":"This setting disables SMTP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablesmtpparsing_1","displayName":"SMTP parsing is disabled","description":"SMTP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablesmtpparsing_0","displayName":"SMTP parsing is enabled","description":"SMTP parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablesshparsing","displayName":"Disable Ssh Parsing","description":"This setting disables SSH Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablesshparsing_1","displayName":"SSH parsing is disabled","description":"SSH parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablesshparsing_0","displayName":"SSH parsing is enabled","description":"SSH parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disabletlsparsing","displayName":"Disable Tls Parsing","description":"This setting disables TLS Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disabletlsparsing_1","displayName":"TLS parsing is disabled","description":"TLS parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disabletlsparsing_0","displayName":"TLS parsing is enabled","description":"TLS parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_enableconvertwarntoblock","displayName":"Enable Convert Warn To Block","description":"This setting controls whether network protection blocks network traffic instead of displaying a warning","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_enableconvertwarntoblock_1","displayName":"Warn verdicts are converted to block","description":"Warn verdicts are converted to block","helpText":null},{"id":"device_vendor_msft_defender_configuration_enableconvertwarntoblock_0","displayName":"Warn verdicts are not converted to block","description":"Warn verdicts are not converted to block","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_enablednssinkhole","displayName":"[Deprecated] Enable Dns Sinkhole","description":"This setting is deprecated and no longer has impact on devices. This setting enables the DNS Sinkhole feature for Network Protection, respecting the value of EnableNetworkProtection for block vs audit, does nothing in inspect mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_enablednssinkhole_0","displayName":"DNS Sinkhole is disabled","description":"DNS Sinkhole is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_enablednssinkhole_1","displayName":"DNS Sinkhole is enabled","description":"DNS Sinkhole is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_enablefilehashcomputation","displayName":"Enable File Hash Computation","description":"Enables or disables file hash computation feature. When this feature is enabled Windows defender will compute hashes for files it scans.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_enablefilehashcomputation_0","displayName":"Disable","description":"Disable","helpText":null},{"id":"device_vendor_msft_defender_configuration_enablefilehashcomputation_1","displayName":"Enable","description":"Enable","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_enableudpreceiveoffload","displayName":"Enable Udp Receive Offload","description":"This setting enables Udp Receive Offload Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_enableudpreceiveoffload_0","displayName":"Udp Receive Offload is disabled","description":"Udp Receive Offload is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_enableudpreceiveoffload_1","displayName":"Udp Receive Offload is enabled","description":"Udp Receive Offload is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_enableudpsegmentationoffload","displayName":"Enable Udp Segmentation Offload","description":"This setting enables Udp Segmentation Offload Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_enableudpsegmentationoffload_0","displayName":"Udp Segmentation Offload is disabled","description":"Udp Segmentation Offload is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_enableudpsegmentationoffload_1","displayName":"Udp Segmentation Offload is enabled","description":"Udp Segmentation Offload is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_engineupdateschannel","displayName":"Engine Updates Channel","description":"[to be deprecated] Enable this policy to specify when devices receive Microsoft Defender engine updates during the monthly gradual rollout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_engineupdateschannel_0","displayName":"Not configured (Default). The device will stay up to date automatically during the gradual release cycle. Suitable for most devices.","description":"Not configured (Default). The device will stay up to date automatically during the gradual release cycle. Suitable for most devices.","helpText":null},{"id":"device_vendor_msft_defender_configuration_engineupdateschannel_2","displayName":"Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.","description":"Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.","helpText":null},{"id":"device_vendor_msft_defender_configuration_engineupdateschannel_3","displayName":"Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.","description":"Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.","helpText":null},{"id":"device_vendor_msft_defender_configuration_engineupdateschannel_4","displayName":"Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).","description":"Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).","helpText":null},{"id":"device_vendor_msft_defender_configuration_engineupdateschannel_5","displayName":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).","description":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).","helpText":null},{"id":"device_vendor_msft_defender_configuration_engineupdateschannel_6","displayName":"Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.","description":"Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_excludedipaddresses","displayName":"Excluded Ip Addresses","description":"Allows an administrator to explicitly disable network packet inspection made by wdnisdrv on a particular set of IP addresses.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocaladmins","displayName":"Hide Exclusions From Local Admins","description":"This policy setting controls whether or not exclusions are visible to local admins. To control local users exlcusions visibility use HideExclusionsFromLocalUsers. If HideExclusionsFromLocalAdmins is set then HideExclusionsFromLocalUsers will be implicitly set.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocaladmins_1","displayName":"If you enable this setting, local admins will no longer be able to see the exclusion list in Windows Security App or via PowerShell.","description":"If you enable this setting, local admins will no longer be able to see the exclusion list in Windows Security App or via PowerShell.","helpText":null},{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocaladmins_0","displayName":"If you disable or do not configure this setting, local admins will be able to see exclusions in the Windows Security App and via PowerShell.","description":"If you disable or do not configure this setting, local admins will be able to see exclusions in the Windows Security App and via PowerShell.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocalusers","displayName":"Hide Exclusions From Local Users","description":"This policy setting controls whether or not exclusions are visible to local users. If HideExclusionsFromLocalAdmins is set then this policy will be implicitly set.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocalusers_1","displayName":"If you enable this setting, local users will no longer be able to see the exclusion list in Windows Security App or via PowerShell.","description":"If you enable this setting, local users will no longer be able to see the exclusion list in Windows Security App or via PowerShell.","helpText":null},{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocalusers_0","displayName":"If you disable or do not configure this setting, local users will be able to see exclusions in the Windows Security App and via PowerShell.","description":"If you disable or do not configure this setting, local users will be able to see exclusions in the Windows Security App and via PowerShell.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_inteltdtenabled","displayName":"Intel TDT Enabled","description":"This policy setting configures the Intel TDT integration level for Intel TDT-capable devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_inteltdtenabled_0","displayName":"If you do not configure this setting, the default value will be applied. The default value is controlled by Microsoft security intelligence updates. Microsoft will enable Intel TDT if there is a known threat.","description":"If you do not configure this setting, the default value will be applied. The default value is controlled by Microsoft security intelligence updates. Microsoft will enable Intel TDT if there is a known threat.","helpText":null},{"id":"device_vendor_msft_defender_configuration_inteltdtenabled_1","displayName":"If you configure this setting to enabled, Intel TDT integration will turn on.","description":"If you configure this setting to enabled, Intel TDT integration will turn on.","helpText":null},{"id":"device_vendor_msft_defender_configuration_inteltdtenabled_2","displayName":"If you configure this setting to disabled, Intel TDT integration will turn off.","description":"If you configure this setting to disabled, Intel TDT integration will turn off.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_meteredconnectionupdates","displayName":"Metered Connection Updates","description":"Allow managed devices to update through metered connections. Default is 0 - not allowed, 1 - allowed","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_meteredconnectionupdates_1","displayName":"Allowed","description":"Allowed","helpText":null},{"id":"device_vendor_msft_defender_configuration_meteredconnectionupdates_0","displayName":"Not Allowed","description":"Not Allowed","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_networkprotectionreputationmode","displayName":"Network Protection Reputation Mode","description":"This sets the reputation mode engine for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_networkprotectionreputationmode_0","displayName":"Use standard reputation engine","description":"Use standard reputation engine","helpText":null},{"id":"device_vendor_msft_defender_configuration_networkprotectionreputationmode_1","displayName":"Use ESP reputation engine","description":"Use ESP reputation engine","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_oobeenablertpandsigupdate","displayName":"Oobe Enable Rtp And Sig Update","description":"This setting allows you to configure whether real-time protection and Security Intelligence Updates are enabled during OOBE (Out of Box experience).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_oobeenablertpandsigupdate_1","displayName":"If you enable this setting, real-time protection and Security Intelligence Updates are enabled during OOBE.","description":"If you enable this setting, real-time protection and Security Intelligence Updates are enabled during OOBE.","helpText":null},{"id":"device_vendor_msft_defender_configuration_oobeenablertpandsigupdate_0","displayName":"If you either disable or do not configure this setting, real-time protection and Security Intelligence Updates during OOBE is not enabled.","description":"If you either disable or do not configure this setting, real-time protection and Security Intelligence Updates during OOBE is not enabled.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_passiveremediation","displayName":"Passive Remediation","description":"Setting to control automatic remediation for Sense scans.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_passiveremediation_0","displayName":"Passive Remediation is turned off (default)","description":"Passive Remediation is turned off (default)","helpText":null},{"id":"device_vendor_msft_defender_configuration_passiveremediation_1","displayName":"PASSIVEREMEDIATIONFLAGSENSEAUTOREMEDIATION: Passive Remediation Sense AutoRemediation","description":"PASSIVE_REMEDIATION_FLAG_SENSE_AUTO_REMEDIATION: Passive Remediation Sense AutoRemediation","helpText":null},{"id":"device_vendor_msft_defender_configuration_passiveremediation_2","displayName":"PASSIVEREMEDIATIONFLAGRTPAUDIT: Passive Remediation Realtime Protection Audit","description":"PASSIVE_REMEDIATION_FLAG_RTP_AUDIT: Passive Remediation Realtime Protection Audit","helpText":null},{"id":"device_vendor_msft_defender_configuration_passiveremediation_4","displayName":"PASSIVEREMEDIATIONFLAGRTPREMEDIATION: Passive Remediation Realtime Protection Remediation","description":"PASSIVE_REMEDIATION_FLAG_RTP_REMEDIATION: Passive Remediation Realtime Protection Remediation","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_performancemodestatus","displayName":"Performance Mode Status","description":"This setting allows IT admins to configure performance mode in either enabled or disabled mode for managed devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_performancemodestatus_0","displayName":"Performance mode is enabled (default). A service restart is required after changing this value.","description":"Performance mode is enabled (default). A service restart is required after changing this value.","helpText":null},{"id":"device_vendor_msft_defender_configuration_performancemodestatus_1","displayName":"Performance mode is disabled. A service restart is required after changing this value.","description":"Performance mode is disabled. A service restart is required after changing this value.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_platformupdateschannel","displayName":"Platform Updates Channel","description":"[to be deprecated] Enable this policy to specify when devices receive Microsoft Defender platform updates during the monthly gradual rollout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_platformupdateschannel_0","displayName":"Not configured (Default). The device will stay up to date automatically during the gradual release cycle. Suitable for most devices.","description":"Not configured (Default). The device will stay up to date automatically during the gradual release cycle. Suitable for most devices.","helpText":null},{"id":"device_vendor_msft_defender_configuration_platformupdateschannel_2","displayName":"Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.","description":"Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.","helpText":null},{"id":"device_vendor_msft_defender_configuration_platformupdateschannel_3","displayName":"Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.","description":"Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.","helpText":null},{"id":"device_vendor_msft_defender_configuration_platformupdateschannel_4","displayName":"Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).","description":"Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).","helpText":null},{"id":"device_vendor_msft_defender_configuration_platformupdateschannel_5","displayName":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).","description":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).","helpText":null},{"id":"device_vendor_msft_defender_configuration_platformupdateschannel_6","displayName":"Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.","description":"Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_quickscanincludeexclusions","displayName":"Quick Scan Include Exclusions","description":"This setting allows you to scan excluded files and directories during quick scans.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_quickscanincludeexclusions_0","displayName":"If you set this setting to 0 or do not configure it, exclusions are not scanned during quick scans.","description":"If you set this setting to 0 or do not configure it, exclusions are not scanned during quick scans.","helpText":null},{"id":"device_vendor_msft_defender_configuration_quickscanincludeexclusions_1","displayName":"If you set this setting to 1, all files and directories that are excluded from real-time protection using contextual exclusions are scanned during a quick scan.","description":"If you set this setting to 1, all files and directories that are excluded from real-time protection using contextual exclusions are scanned during a quick scan.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_randomizescheduletasktimes","displayName":"Randomize Schedule Task Times","description":"In Microsoft Defender Antivirus, randomize the start time of the scan to any interval from 0 to 23 hours. This can be useful in virtual machines or VDI deployments.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_randomizescheduletasktimes_1","displayName":"Widen or narrow the randomization period for scheduled scans. Specify a randomization window of between 1 and 23 hours by using the setting SchedulerRandomizationTime.","description":"Widen or narrow the randomization period for scheduled scans. Specify a randomization window of between 1 and 23 hours by using the setting SchedulerRandomizationTime.","helpText":null},{"id":"device_vendor_msft_defender_configuration_randomizescheduletasktimes_0","displayName":"Scheduled tasks will not be randomized.","description":"Scheduled tasks will not be randomized.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_reporting_enabledynamicsignaturedroppedeventreporting","displayName":"Enable Dynamic Signature Dropped Event Reporting","description":"This setting controls whether to report a Dynamic Security Intelligence Update dropped event. By default, such events are not reported.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_reporting_enabledynamicsignaturedroppedeventreporting_0","displayName":"Dynamic Security intelligence update dropped events will not be reported.","description":"Dynamic Security intelligence update dropped events will not be reported.","helpText":null},{"id":"device_vendor_msft_defender_configuration_reporting_enabledynamicsignaturedroppedeventreporting_1","displayName":"Dynamic Security intelligence update events will be reported.","description":"Dynamic Security intelligence update events will be reported.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_scanonlyifidleenabled","displayName":"Scan Only If Idle Enabled","description":"In Microsoft Defender Antivirus, this setting will run scheduled scans only if the system is idle.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_scanonlyifidleenabled_1","displayName":"Runs scheduled scans only if the system is idle.","description":"Runs scheduled scans only if the system is idle.","helpText":null},{"id":"device_vendor_msft_defender_configuration_scanonlyifidleenabled_0","displayName":"Runs scheduled scans regardless of whether the system is idle.","description":"Runs scheduled scans regardless of whether the system is idle.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_schedulerrandomizationtime","displayName":"Scheduler Randomization Time","description":"This setting allows you to configure the scheduler randomization in hours. The randomization interval is [1 - 23] hours. For more information on the randomization effect please check the RandomizeScheduleTaskTimes setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday","displayName":"Schedule Security Intelligence Update Day","description":"This setting allows you to specify the day of the week on which to check for security intelligence updates. By default, this setting is configured to never check for security intelligence updates.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_0","displayName":"Daily","description":"Daily","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_1","displayName":"Sunday","description":"Sunday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_2","displayName":"Monday","description":"Monday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_3","displayName":"Tuesday","description":"Tuesday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_4","displayName":"Wednesday","description":"Wednesday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_5","displayName":"Thursday","description":"Thursday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_6","displayName":"Friday","description":"Friday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_7","displayName":"Saturday","description":"Saturday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_8","displayName":"Never","description":"Never","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdatetime","displayName":"Schedule Security Intelligence Update Time","description":"This setting allows you to specify the time of day at which to check for security intelligence updates. The time value is represented as the number of minutes past midnight (00:00). For example, 120 is equivalent to 02:00 AM. By default, this setting is configured to check for security intelligence updates 15 minutes before the scheduled scan time. The schedule is based on local time on the computer where the check is occurring.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_secureddevicesconfiguration","displayName":"Secured Devices Configuration","description":"Defines which device's primary ids should be secured by Defender Device Control. The primary id values should be pipe (|) separated. Example: RemovableMediaDevices|CdRomDevices. If this configuration is not set the default value will be applied, meaning all supported devices will be secured. Currently supported primary ids are: RemovableMediaDevices, CdRomDevices, WpdDevices, PrinterDevices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_secureddevicesconfiguration_removablemediadevices","displayName":"Removable Media Devices","description":"RemovableMediaDevices","helpText":null},{"id":"device_vendor_msft_defender_configuration_secureddevicesconfiguration_cdromdevices","displayName":"Cd Rom Devices","description":"CdRomDevices","helpText":null},{"id":"device_vendor_msft_defender_configuration_secureddevicesconfiguration_wpddevices","displayName":"Wpd Devices","description":"WpdDevices","helpText":null},{"id":"device_vendor_msft_defender_configuration_secureddevicesconfiguration_printerdevices","displayName":"Printer Devices","description":"PrinterDevices","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_securityintelligencelocationupdateatscheduledtimeonly","displayName":"Security Intelligence Location Update At Scheduled Time Only","description":"This setting allows you to configure security intelligence updates according to the scheduler for VDI-configured computers. It is used together with the shared security intelligence location (SecurityIntelligenceLocation).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_securityintelligencelocationupdateatscheduledtimeonly_1","displayName":"If you enable this setting and configure SecurityIntelligenceLocation, updates from the configured location occur only at the previously configured scheduled update time.","description":"If you enable this setting and configure SecurityIntelligenceLocation, updates from the configured location occur only at the previously configured scheduled update time.","helpText":null},{"id":"device_vendor_msft_defender_configuration_securityintelligencelocationupdateatscheduledtimeonly_0","displayName":"If you either disable or do not configure this setting, updates occur whenever a new security intelligence update is detected at the location that is specified by SecurityIntelligenceLocation.","description":"If you either disable or do not configure this setting, updates occur whenever a new security intelligence update is detected at the location that is specified by SecurityIntelligenceLocation.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel","displayName":"Security Intelligence Updates Channel","description":"Enable this policy to specify when devices receive Microsoft Defender security intelligence updates during the daily gradual rollout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel_0","displayName":"Not configured (Default). Microsoft will either assign the device to Current Channel (Broad) or a beta channel early in the gradual release cycle. The channel selected by Microsoft might be one that receives updates early during the gradual release cycle, which may not be suitable for devices in a production or critical environment","description":"Not configured (Default). Microsoft will either assign the device to Current Channel (Broad) or a beta channel early in the gradual release cycle. The channel selected by Microsoft might be one that receives updates early during the gradual release cycle, which may not be suitable for devices in a production or critical environment","helpText":null},{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel_4","displayName":"Current Channel (Staged): Same as Current Channel (Broad).","description":"Current Channel (Staged): Same as Current Channel (Broad).","helpText":null},{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel_5","displayName":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in all populations, including production.","description":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in all populations, including production.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_supportloglocation","displayName":"Support Log Location","description":"The support log location setting allows the administrator to specify where the Microsoft Defender Antivirus diagnostic data collection tool (MpCmdRun.exe) will save the resulting log files. This setting is configured with an MDM solution, such as Intune, and is available for Windows 10 Enterprise.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_throttleforscheduledscanonly","displayName":"Throttle For Scheduled Scan Only","description":"A CPU usage limit can be applied to scheduled scans only, or to scheduled and custom scans. The default value applies a CPU usage limit to scheduled scans only.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_throttleforscheduledscanonly_1","displayName":"If you enable this setting, CPU throttling will apply only to scheduled scans.","description":"If you enable this setting, CPU throttling will apply only to scheduled scans.","helpText":null},{"id":"device_vendor_msft_defender_configuration_throttleforscheduledscanonly_0","displayName":"If you disable this setting, CPU throttling will apply to scheduled and custom scans.","description":"If you disable this setting, CPU throttling will apply to scheduled and custom scans.","helpText":null}]},{"id":"device_vendor_msft_dmclient_provider_{providerid}","displayName":" Provider ID","description":"This node contains the URI-encoded value of the bootstrapped device management account’s Provider ID. Scope is dynamic. This value is set and controlled by the MDM server. As a best practice, use text that doesn’t require XML/URI escaping.","helpText":"","infoUrls":[],"categoryId":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","categoryName":"Config Refresh","options":null},{"id":"device_vendor_msft_dmclient_provider_{providerid}_configrefresh_cadence","displayName":"Refresh cadence","description":"This node determines the number of minutes between refreshes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/DMClient-csp/"],"categoryId":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","categoryName":"Config Refresh","options":null},{"id":"device_vendor_msft_dmclient_provider_{providerid}_configrefresh_enabled","displayName":"Config refresh","description":"This node determines whether or not a periodic settings refresh for MDM policies will occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/DMClient-csp/"],"categoryId":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","categoryName":"Config Refresh","options":[{"id":"device_vendor_msft_dmclient_provider_{providerid}_configrefresh_enabled_false","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_dmclient_provider_{providerid}_configrefresh_enabled_true","displayName":"Enabled.","description":"Enabled.","helpText":null}]},{"id":"device_vendor_msft_email_accountname","displayName":"Account Name","description":"Exchange ActiveSync account name, displayed to user as name of EAS profile.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/email2-csp"],"categoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","categoryName":"Email","options":null},{"id":"device_vendor_msft_email_emailaddressattributeaad","displayName":"Email address attribute from AAD","description":"The attribute Intune gets from Azure AD to dynamically generate the email address that will be used by this profile e.g. MyName@contoso.com (UPN).","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/email2-csp"],"categoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","categoryName":"Email","options":null},{"id":"device_vendor_msft_email_emailserver","displayName":"Email Server","description":"The Exchange location (URL) of the email server to which the app you specified connects to get email.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/email2-csp"],"categoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","categoryName":"Email","options":null},{"id":"device_vendor_msft_email_usernameattributeaad","displayName":"Username attribute from AAD","description":"The attribute Intune gets from Azure AD to dynamically generate the username that will be used by this profile e.g. MyName@contoso.com (UPN) or MyName (username).","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/email2-csp"],"categoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","categoryName":"Email","options":null},{"id":"device_vendor_msft_euiccs_{euicc}","displayName":"eSIM","description":"Represents information associated with an eUICC. There is one subtree for each known eUICC, created by the Local Profile Assistant (LPA) when the eUICC is first seen. The node name is the eUICC ID (EID). The node name \"Default\" represents the currently active eUICC.","helpText":"","infoUrls":[],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}","displayName":"Download Servers","description":"Node representing the discovery operation for a server name. The node name is the fully qualified domain name of the SM-DP+ server that will be used for profile discovery. Creation of this subtree triggers a discovery request.","helpText":"","infoUrls":[],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_autoenable","displayName":"Auto Enable","description":"Indicates whether the discovered profile must be enabled automatically after install. This must be set by the MDM when the ServerName subtree is created.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":[{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_autoenable_false","displayName":"Disable","description":"Disable","helpText":null},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_autoenable_true","displayName":"Enable","description":"Enable","helpText":null}]},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_isdiscoveryserver","displayName":"Is Discovery Server","description":"Indicates whether the server is a discovery server or if it is used for bulk download. A discovery server is used every time a user requests a profile discovery operation. Optional, default value is false.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":[{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_isdiscoveryserver_false","displayName":"Is Not Discovery Server","description":"Is Not Discovery Server","helpText":null},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_isdiscoveryserver_true","displayName":"Is Discovery Server","description":"Is Discovery Server","helpText":null}]},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_maximumattempts","displayName":"Maximum Attempts (Windows Insiders only)","description":"How many times profile download should be attempted before giving up. A value of 0 indicates unlimited retry attempts. When a value is not specified, it defaults to 50, which is equivalent to about a month of retry attempts.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_servername","displayName":"Server Name","description":null,"helpText":null,"infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_euiccs_{euicc}_policies_localuienabled","displayName":"Display Local UI","description":"Determines whether the local user interface of the LUI is available (true if available, false otherwise). Initially populated by the LPA when the eUICC tree is created, can be queried and changed by the MDM server.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":[{"id":"device_vendor_msft_euiccs_{euicc}_policies_localuienabled_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_euiccs_{euicc}_policies_localuienabled_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}","displayName":"ICCID","description":"Node representing an enterprise-owned eUICC profile. The node name is the ICCID of the profile (which is a unique identifier). Creation of this subtree triggers an AddProfile request by the LPA (which installs the profile on the eUICC). Removal of this subtree triggers the LPA to delete the profile (if resident on the eUICC).","helpText":"","infoUrls":[],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}_isenabled","displayName":"Is Enabled","description":"Indicates whether this eSIM profile is enabled. Can be set by both the MDM and the CSP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":[{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}_isenabled_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}_isenabled_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}_matchingid","displayName":"Matching ID","description":"Matching ID (activation code token) for profile download. Must be set by the MDM when the ICCID subtree is created.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}_servername","displayName":"Server Name","description":"Fully qualified domain name of the SM-DP+ that can download this profile. Must be set by the MDM when the ICCID subtree is created.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_keyboardfilter_blockedkeys","displayName":"Blocked Keys (Windows Insiders only)","description":"Get operations return a comma-delimited string of keys and key combinations that are currently blocked. Returned list does not include scancodes that have been blocked. Use BlockedScancodes to retrieve blocked scancodes and modifier+scancode combinations.\nReplace operations expect a comma-delimited string of keys or modifier(s)+key values and sets them as blocked keys. Invalid keys result in an error. All keys are case-insensitive; to block upper-case letters, specify shift+letter. To block comma, space, tab, or other special characters, specify the key name. Examples of valid key names and modifier names can be found here: https://learn.microsoft.com/en-us/windows/configuration/keyboard-filter/keyboardfilter-key-names \n\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":null},{"id":"device_vendor_msft_keyboardfilter_blockedscancodes","displayName":"Blocked Scancodes (Windows Insiders only)","description":"Get operations return a comma-delimited string of scancodes and modifier+scancode combinations that are currently blocked in hexadecimal format without the \"0x\" prefix. Returned list does not include keys that have been blocked. Use GetBlockedKeys to retrieve blocked keys and key combinations.\nReplace operations expect a comma-delimited string of scancodes or modifier(s)+scancode values in hexadecimal and sets them as blocked scancodes. When specifying hexadecimal values, do not include the \"0x\" prefix. Invalid inputs result in an error. Examples of modifier names can be found here: https://learn.microsoft.com/en-us/windows/configuration/keyboard-filter/keyboardfilter-key-names. Valid scancodes can be found here: https://learn.microsoft.com/en-us/windows/win32/inputdev/about-keyboard-input#scan-codes\n\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":null},{"id":"device_vendor_msft_keyboardfilter_breakoutkeyscancode","displayName":"Breakout Key Scancode (Windows Insiders only)","description":"Get or set the scancode that forces the device to the login screen when pressed five times consecutively. The value is the string representation of the hexadecimal scancode (without the \"0x\" prefix). Defaults to \"5b\", the scancode for the \"left windows key\". Only set a single scancode; scancode combinations are not supported. After setting this value, a reboot is required for the change to take effect.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":null},{"id":"device_vendor_msft_keyboardfilter_disableaccessibilitysettings","displayName":"Disable Accessibility Settings (Windows Insiders only)","description":"Determines if Accessibility settings (e.g. Ease of Access) are disabled. Defaults to false.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":[{"id":"device_vendor_msft_keyboardfilter_disableaccessibilitysettings_false","displayName":"Accessibility settings are honored","description":"Accessibility settings are honored","helpText":null},{"id":"device_vendor_msft_keyboardfilter_disableaccessibilitysettings_true","displayName":"Accessibility settings are disabled","description":"Accessibility settings are disabled","helpText":null}]},{"id":"device_vendor_msft_keyboardfilter_disablekeyboardfilterforadministrators","displayName":"Disable Keyboard Filter For Administrators (Windows Insiders only)","description":"Determines if Keyboard Filter should be disabled for administrators. Defaults to false. If an admin is currently signed in when this value is set, it will take effect on the next sign-in. \r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":[{"id":"device_vendor_msft_keyboardfilter_disablekeyboardfilterforadministrators_false","displayName":"Blocked keys and scancodes are blocked for Administrators","description":"Blocked keys and scancodes are blocked for Administrators","helpText":null},{"id":"device_vendor_msft_keyboardfilter_disablekeyboardfilterforadministrators_true","displayName":"Blocked keys and scancodes are not blocked for Administrators","description":"Blocked keys and scancodes are not blocked for Administrators","helpText":null}]},{"id":"device_vendor_msft_laps_policies_adencryptedpasswordhistorysize","displayName":"AD Encrypted Password History Size ","description":"Use this setting to configure how many previous encrypted passwords will be remembered in Active Directory.\n\nIf not specified, this setting will default to 0 passwords (disabled).\n\nThis setting has a minimum allowed value of 0 passwords.\n\nThis setting has a maximum allowed value of 12 passwords.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_administratoraccountname","displayName":"Administrator Account Name ","description":"Use this setting to configure the name of the managed local administrator account.\n\nIf not specified, the default built-in local administrator account will be located by well-known SID (even if renamed).\n\nIf specified, the specified account's password will be managed.\n\nNote: if a custom managed local administrator account name is specified in this setting, that account must be created via other means. Specifying a name in this setting will not cause the account to be created.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_adpasswordencryptionenabled","displayName":"AD Password Encryption Enabled ","description":"Use this setting to configure whether the password is encrypted before being stored in Active Directory.\n\nThis setting is ignored if the password is currently being stored in Azure.\n\nThis setting is only honored when the Active Directory domain is at Windows Server 2016 Domain Functional Level or higher.\n\nIf this setting is enabled, and the Active Directory domain meets the DFL prerequisite, the password will be encrypted before before being stored in Active Directory.\n\nIf this setting is disabled, or the Active Directory domain does not meet the DFL prerequisite, the password will be stored as clear-text in Active Directory.\n\nIf not specified, this setting defaults to True.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_adpasswordencryptionenabled_false","displayName":"Store the password in clear-text form in Active Directory","description":"Store the password in clear-text form in Active Directory","helpText":null},{"id":"device_vendor_msft_laps_policies_adpasswordencryptionenabled_true","displayName":"Store the password in encrypted form in Active Directory","description":"Store the password in encrypted form in Active Directory","helpText":null}]},{"id":"device_vendor_msft_laps_policies_adpasswordencryptionprincipal","displayName":"AD Password Encryption Principal ","description":"Use this setting to configure the name or SID of a user or group that can decrypt the password stored in Active Directory.\n\nThis setting is ignored if the password is currently being stored in Azure.\n\nIf not specified, the password will be decryptable by the Domain Admins group in the device's domain.\n\nIf specified, the specified user or group will be able to decrypt the password stored in Active Directory.\n\nIf the specified user or group account is invalid the device will fallback to using the Domain Admins group in the device's domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementenableaccount","displayName":"Automatic Account Management Enable Account","description":"Use this setting to configure whether the automatically managed account is enabled or disabled.\n\nIf this setting is enabled, the target account will be enabled.\n\nIf this setting is disabled, the target account will be disabled.\n\nIf not specified, this setting defaults to False.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementenableaccount_false","displayName":"The target account will be disabled","description":"The target account will be disabled","helpText":null},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementenableaccount_true","displayName":"The target account will be enabled","description":"The target account will be enabled","helpText":null}]},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementenabled","displayName":"Automatic Account Management Enabled","description":"Use this setting to specify whether automatic account management is enabled.\n\nIf this setting is enabled, the target account will be automatically managed.\n\nIf this setting is disabled, the target account will not be automatically managed.\n\nIf not specified, this setting defaults to False.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementenabled_false","displayName":"The target account will not be automatically managed","description":"The target account will not be automatically managed","helpText":null},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementenabled_true","displayName":"The target account will be automatically managed","description":"The target account will be automatically managed","helpText":null}]},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementnameorprefix","displayName":"Automatic Account Management Name Or Prefix","description":"Use this setting to configure the name or prefix of the managed local administrator account.\n\nIf specified, the value will be used as the name or name prefix of the managed account.\n\nIf not specified, this setting will default to \"WLapsAdmin\".","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementrandomizename","displayName":"Automatic Account Management Randomize Name","description":"Use this setting to configure whether the name of the automatically managed account uses a random numeric suffix each time the password is rotated.\n\nIf this setting is enabled, the name of the target account will use a random numeric suffix.\n\nIf this setting is disbled, the name of the target account will not use a random numeric suffix..\n\nIf not specified, this setting defaults to False.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementrandomizename_false","displayName":"The name of the target account will not use a random numeric suffix.","description":"The name of the target account will not use a random numeric suffix.","helpText":null},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementrandomizename_true","displayName":"The name of the target account will use a random numeric suffix.","description":"The name of the target account will use a random numeric suffix.","helpText":null}]},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementtarget","displayName":"Automatic Account Management Target","description":"Use this setting to configure which account is automatically managed.\n\nThe allowable settings are:\n\n0=The builtin administrator account will be managed.\n1=A new account created by Windows LAPS will be managed.\n\nIf not specified, this setting will default to 1.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementtarget_0","displayName":"Manage the built-in administrator account","description":"Manage the built-in administrator account","helpText":null},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementtarget_1","displayName":"Manage a new custom administrator account","description":"Manage a new custom administrator account","helpText":null}]},{"id":"device_vendor_msft_laps_policies_backupdirectory","displayName":"Backup Directory ","description":"Use this setting to configure which directory the local admin account password is backed up to.\n\nThe allowable settings are:\n\n0=Disabled (password will not be backed up)\n1=Backup the password to Microsoft Entra ID only\n2=Backup the password to Active Directory only\n\nIf not specified, this setting will default to 0.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_backupdirectory_0","displayName":"Disabled (password will not be backed up)","description":"Disabled (password will not be backed up)","helpText":null},{"id":"device_vendor_msft_laps_policies_backupdirectory_1","displayName":"Backup the password to Microsoft Entra ID only","description":"Backup the password to Microsoft Entra ID only","helpText":null},{"id":"device_vendor_msft_laps_policies_backupdirectory_2","displayName":"Backup the password to Active Directory only","description":"Backup the password to Active Directory only","helpText":null}]},{"id":"device_vendor_msft_laps_policies_passphraselength","displayName":"Passphrase Length","description":"Use this setting to configure the number of passphrase words.\n\nIf not specified, this setting will default to 6 words\n\nThis setting has a minimum allowed value of 3 words.\n\nThis setting has a maximum allowed value of 10 words.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_passwordagedays","displayName":"Password Age Days ","description":"Use this policy to configure the maximum password age of the managed local administrator account.\n\nIf not specified, this setting will default to 30 days\n\nThis setting has a minimum allowed value of 1 day when backing the password to onpremises Active Directory, and 7 days when backing the password to Microsoft Entra ID..\n\nThis setting has a maximum allowed value of 365 days.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_passwordagedays_aad","displayName":"Password Age Days","description":"Use this policy to configure the maximum password age of the managed local administrator account.\n\nIf not specified, this setting will default to 30 days\n\nThis setting has a minimum allowed value of 1 day when backing the password to onpremises Active Directory, and 7 days when backing the password to Azure AD.\n\nThis setting has a maximum allowed value of 365 days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity","displayName":"Password Complexity ","description":"Use this setting to configure password complexity of the managed local administrator account.\n\nThe allowable settings are:\n\n1=Large letters\n2=Large letters + small letters\n3=Large letters + small letters + numbers\n4=Large letters + small letters + numbers + special characters\n\nIf not specified, this setting will default to 4.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_passwordcomplexity_1","displayName":"Large letters","description":"Large letters","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_2","displayName":"Large letters + small letters","description":"Large letters + small letters","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_3","displayName":"Large letters + small letters + numbers","description":"Large letters + small letters + numbers","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_4","displayName":"Large letters + small letters + numbers + special characters","description":"Large letters + small letters + numbers + special characters","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_5","displayName":"Large letters + small letters + numbers + special characters (improved readability)","description":"Large letters + small letters + numbers + special characters (improved readability)","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_6","displayName":"Passphrase (long words)","description":"Passphrase (long words)","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_7","displayName":"Passphrase (short words)","description":"Passphrase (short words)","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_8","displayName":"Passphrase (short words with unique prefixes)","description":"Passphrase (short words with unique prefixes)","helpText":null}]},{"id":"device_vendor_msft_laps_policies_passwordexpirationprotectionenabled","displayName":"Password Expiration Protection Enabled ","description":"Use this setting to configure additional enforcement of maximum password age for the managed local administrator account.\n\nWhen this setting is enabled, planned password expiration that would result in a password age greater than that dictated by \"PasswordAgeDays\" policy is NOT allowed. When such expiration is detected, the password is changed immediately and the new password expiration date is set according to policy.\n\nIf not specified, this setting defaults to True.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_passwordexpirationprotectionenabled_false","displayName":"Allow configured password expiriration timestamp to exceed maximum password age","description":"Allow configured password expiriration timestamp to exceed maximum password age","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordexpirationprotectionenabled_true","displayName":"Do not allow configured password expiriration timestamp to exceed maximum password age","description":"Do not allow configured password expiriration timestamp to exceed maximum password age","helpText":null}]},{"id":"device_vendor_msft_laps_policies_passwordlength","displayName":"Password Length ","description":"Use this setting to configure the length of the password of the managed local administrator account.\n\nIf not specified, this setting will default to 14 characters.\n\nThis setting has a minimum allowed value of 8 characters.\n\nThis setting has a maximum allowed value of 64 characters.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_postauthenticationactions","displayName":"Post Authentication Actions ","description":"Use this setting to specify the actions to take upon expiration of the configured grace period.\n\nIf not specified, this setting will default to 3 (Reset the password and logoff the managed account).\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_postauthenticationactions_1","displayName":"Reset password: upon expiry of the grace period, the managed account password will be reset.","description":"Reset password: upon expiry of the grace period, the managed account password will be reset.","helpText":null},{"id":"device_vendor_msft_laps_policies_postauthenticationactions_3","displayName":"Reset the password and logoff the managed account: upon expiry of the grace period, the managed account password will be reset and any interactive logon sessions using the managed account will terminated.","description":"Reset the password and logoff the managed account: upon expiry of the grace period, the managed account password will be reset and any interactive logon sessions using the managed account will terminated.","helpText":null},{"id":"device_vendor_msft_laps_policies_postauthenticationactions_5","displayName":"Reset the password and reboot: upon expiry of the grace period, the managed account password will be reset and the managed device will be immediately rebooted.","description":"Reset the password and reboot: upon expiry of the grace period, the managed account password will be reset and the managed device will be immediately rebooted.","helpText":null},{"id":"device_vendor_msft_laps_policies_postauthenticationactions_11","displayName":"Reset the password, logoff the managed account, and terminate any remaining processes: upon expiration of the grace period, the managed account password is reset, any interactive logon sessions using the managed account are logged off, and any remaining processes are terminated.","description":"Reset the password, logoff the managed account, and terminate any remaining processes: upon expiration of the grace period, the managed account password is reset, any interactive logon sessions using the managed account are logged off, and any remaining processes are terminated.","helpText":null}]},{"id":"device_vendor_msft_laps_policies_postauthenticationresetdelay","displayName":"Post Authentication Reset Delay ","description":"Use this setting to specify the amount of time (in hours) to wait after an authentication before executing the specified post-authentication actions.\n\n If not specified, this setting will default to 24 hours.\n\n This setting has a minimum allowed value of 0 hours (this disables all post-authentication actions).\n\n This setting has a maximum allowed value of 24 hours.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_multisim_{modemid}","displayName":"Modem ID","description":"Node representing a Mobile Broadband Modem. The node name is the Modem ID. Modem ID is a GUID without curly braces, with exception of \"Embedded\" which represents the embedded Modem.","helpText":"","infoUrls":[],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":null},{"id":"device_vendor_msft_multisim_{modemid}_policies_slotselectionenabled","displayName":"Slot Selection Enabled","description":"Determines whether the user is allowed to change slots in the Cellular settings UI. Default is true.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/MultiSIM-csp/"],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":[{"id":"device_vendor_msft_multisim_{modemid}_policies_slotselectionenabled_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_policies_slotselectionenabled_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}","displayName":" Slot ID","description":"Node representing a SIM Slot. The node name is the Slot ID. SIM Slot ID format is \"0\", \"1\", etc., with exception of \"Embedded\" which represents the embedded Slot.","helpText":"","infoUrls":[],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier","displayName":"Slot ID","description":"Node representing a SIM Slot. The node name is the Slot ID. SIM Slot ID format is \"0\", \"1\", etc., with exception of \"Embedded\" which represents the embedded Slot.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/MultiSIM-csp/"],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":[{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier_embedded","displayName":"Embedded","description":"Embedded","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier_0","displayName":"SIM Slot Id 0","description":"0","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier_1","displayName":"SIM Slot Id 1","description":"1","helpText":null}]},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_isselected","displayName":"Is Selected","description":"Indicates whether this Slot is selected or not.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/MultiSIM-csp/"],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":[{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_isselected_false","displayName":"Not selected","description":"Not selected","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_isselected_true","displayName":"Selected","description":"Selected","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}","displayName":"Device-scoped settings","description":"This policy specifies the Tenant ID in the format of a Globally Unique Identifier (GUID) without curly braces ( { , } ), which will be used as part of Windows Hello for Business provisioning and management.","helpText":"","infoUrls":[],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_enablepinrecovery","displayName":"Enable Pin Recovery","description":"If the user forgets their PIN, it can be changed to a new PIN using the Windows Hello for Business PIN recovery service. This cloud service encrypts a recovery secret which is stored locally on the client, but which can only be decrypted by the cloud service.\n\nIf you enable this policy setting, the PIN recovery secret will be stored on the device and the user will be able to change to a new PIN in case their PIN is forgotten.\n\nIf you disable or do not configure this policy setting, the PIN recovery secret will not be created or stored. If the user's PIN is forgotten, the only way to get a new PIN is by deleting the existing PIN and creating a new one, which will require the user to re-register with any services the old PIN provided access to.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_enablepinrecovery_false","displayName":"false","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_enablepinrecovery_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_excludesecuritydevices_tpm12","displayName":"Restrict use of TPM 1.2","description":"Some Trusted Platform Modules (TPMs) are only compliant with the older 1.2 revision of the TPM specification defined by the Trusted Computing Group (TCG).\n\nIf you enable this policy setting, TPM revision 1.2 modules will be disallowed from being used with Windows Hello for Business.\n\nIf you disable or do not configure this policy setting, TPM revision 1.2 modules will be allowed to be used with Windows Hello for Business.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_excludesecuritydevices_tpm12_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_excludesecuritydevices_tpm12_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_digits","displayName":"Digits","description":"Use this policy setting to configure the use of digits in the Windows Hello for Business PIN.\n\nA value of 1 corresponds to “Required.” If you configure this policy setting to 1, Windows Hello for Business requires users to include at least one digit in their PIN.\n\nA value of 2 corresponds to “Disallow.” If you configure this policy setting to 2, Windows Hello for Business prevents users from using digits in their PIN.\n\nIf you do not configure this policy setting, Windows Hello for Business requires users to use digits in their PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_digits_0","displayName":"Allows the use of digits in PIN.","description":"Allows the use of digits in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_digits_1","displayName":"Requires the use of at least one digits in PIN.","description":"Requires the use of at least one digits in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_digits_2","displayName":"Does not allow the use of digits in PIN.","description":"Does not allow the use of digits in PIN.","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_expiration","displayName":"Expiration","description":"This policy specifies when the PIN expires (in days). Valid values are 0 to 730 inclusive. If this policy is set to 0, then PINs do not expire.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_history","displayName":"PIN History","description":"This policy specifies the number of past PINs that can be stored in the history that can’t be used. Valid values are 0 to 50 inclusive. If this policy is set to 0, then storage of previous PINs is not required. PIN history is not preserved through PIN reset.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_lowercaseletters","displayName":"Lowercase Letters","description":"Use this policy setting to configure the use of lowercase letters in the Windows Hello for Business PIN.\n\nA value of 1 corresponds to “Required.” If you configure this policy setting to 1, Windows Hello for Business requires users to include at least one lowercase letter in their PIN.\n\nA value of 2 corresponds to “Disallow.” If you configure this policy setting to 2, Windows Hello for Business prevents users from using lowercase letters in their PIN.\n\nIf you do not configure this policy setting, Windows Hello for Business does not allow users to use lowercase letters in their PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_lowercaseletters_0","displayName":"Allowed","description":"Allows the use of lowercase letters in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_lowercaseletters_1","displayName":"Required","description":"Requires the use of at least one lowercase letters in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_lowercaseletters_2","displayName":"Blocked","description":"Does not allow the use of lowercase letters in PIN.","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_maximumpinlength","displayName":"Maximum PIN Length","description":"Maximum PIN length configures the maximum number of characters allowed for the PIN. The largest number you can configure for this policy setting is 127. The lowest number you can configure must be larger than the number configured in the Minimum PIN length policy setting or the number 4, whichever is greater.\n\nIf you configure this policy setting, the PIN length must be less than or equal to this number.\n\nIf you do not configure this policy setting, the PIN length must be less than or equal to 127.\n\nNOTE: If the above specified conditions for the maximum PIN length are not met, default values will be used for both the maximum and minimum PIN lengths.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_minimumpinlength","displayName":"Minimum PIN Length","description":"Minimum PIN length configures the minimum number of characters required for the PIN. The lowest number you can configure for this policy setting is 4. The largest number you can configure must be less than the number configured in the Maximum PIN length policy setting or the number 127, whichever is the lowest.\n\nIf you configure this policy setting, the PIN length must be greater than or equal to this number.\n\nIf you do not configure this policy setting, the PIN length must be greater than or equal to 4.\n\nNOTE: If the above specified conditions for the minimum PIN length are not met, default values will be used for both the maximum and minimum PIN lengths.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters","displayName":"Special Characters","description":"Use this policy setting to configure the use of special characters in the Windows Hello for Business PIN gesture. Valid special characters for Windows Hello for Business PIN gestures include: ! \" # $ % & ' ( ) * + , - . / : ; < = > ? @ [ \\ ] ^ _ ` { | } ~ .\n\nA value of 1 corresponds to “Required.” If you configure this policy setting to 1, Windows Hello for Business requires users to include at least one special character in their PIN.\n\nA value of 2 corresponds to “Disallow.” If you configure this policy setting to 2, Windows Hello for Business prevents users from using special characters in their PIN.\n\nIf you do not configure this policy setting, Windows Hello for Business does not allow users to use special characters in their PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters_0","displayName":"Allows the use of special characters in PIN.","description":"Allows the use of special characters in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters_1","displayName":"Requires the use of at least one special characters in PIN.","description":"Requires the use of at least one special characters in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters_2","displayName":"Does not allow the use of special characters in PIN.","description":"Does not allow the use of special characters in PIN.","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters","displayName":"Uppercase Letters","description":"Use this policy setting to configure the use of uppercase letters in the Windows Hello for Business PIN.\n\nA value of 1 corresponds to “Required.” If you configure this policy setting to 1, Windows Hello for Business requires users to include at least one uppercase letter in their PIN.\n\nA value of 2 corresponds to “Disallow.” If you configure this policy setting to 2, Windows Hello for Business prevents users from using uppercase letters in their PIN.\n\nIf you do not configure this policy setting, Windows Hello for Business does not allow users to use uppercase letters in their PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters_0","displayName":"Allowed","description":"Allows the use of uppercase letters in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters_1","displayName":"Required","description":"Requires the use of at least one uppercase letters in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters_2","displayName":"Blocked","description":"Does not allow the use of uppercase letters in PIN.","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_remote_useremotepassport","displayName":"Use Remote Passport","description":"Boolean that specifies if phone sign-in can be used with a device. Phone sign-in provides the ability for a portable, registered device to be usable as a companion device for desktop authentication.\n\nDefault value is false. If you enable this setting, a desktop device will allow a registered, companion device to be used as an authentication factor. If you disable this setting, a companion device cannot be used in desktop authentication scenarios.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_remote_useremotepassport_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_remote_useremotepassport_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_requiresecuritydevice","displayName":"Require Security Device","description":"A Trusted Platform Module (TPM) provides additional security benefits over software because data stored within it cannot be used on other devices.\n\nIf you enable this policy setting, only devices with a usable TPM provision Windows Hello for Business.\n\nIf you disable or do not configure this policy setting, the TPM is still preferred, but all devices provision Windows Hello for Business using software if the TPM is non-functional or unavailable.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_requiresecuritydevice_false","displayName":"false","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_requiresecuritydevice_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usecertificateforonpremauth","displayName":"Use Certificate For On Prem Auth","description":"Windows Hello for Business can use certificates to authenticate to on-premise resources. \n\nIf you enable this policy setting, Windows Hello for Business will wait until the device has received a certificate payload from the mobile device management server before provisioning a PIN.\n\nIf you disable or do not configure this policy setting, the PIN will be provisioned when the user logs in, without waiting for a certificate payload.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usecertificateforonpremauth_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usecertificateforonpremauth_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usecloudtrustforonpremauth","displayName":"Use Cloud Trust For On Prem Auth","description":"Windows Hello for Business to use Azure AD Kerberos to authenticate to on-premises resources. \n\nIf you enable this policy setting, Windows Hello for Business will use an Azure AD Kerberos ticket to authenticate to on-premises resources.\n\nIf you disable or do not configure this policy setting, Windows Hello for Business will use a key or certificate to authenticate to on-premises resources.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usecloudtrustforonpremauth_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usecloudtrustforonpremauth_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usehellocertificatesassmartcardcertificates","displayName":"Use Hello Certificates As Smart Card Certificates","description":"If you enable this policy setting, applications use Windows Hello for Business certificates as smart card certificates. Biometric factors are unavailable when a user is asked to authorize the use of the certificate's private key. This policy setting is designed to allow compatibility with applications that rely exclusively on smart card certificates.\n\nIf you disable or do not configure this policy setting, applications do not use Windows Hello for Business certificates as smart card certificates, and biometric factors are available when a user is asked to authorize the use of the certificate's private key.\n\nWindows requires a user to lock and unlock their session after changing this setting if the user is currently signed in.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usehellocertificatesassmartcardcertificates_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usehellocertificatesassmartcardcertificates_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usepassportforwork","displayName":"Use Windows Hello For Business (Device)","description":"Windows Hello for Business is an alternative method for signing into Windows using your Active Directory or Azure Active Directory account that can replace passwords, Smart Cards, and Virtual Smart Cards.\n\nIf you enable or do not configure this policy setting, the device provisions Windows Hello for Business for all users.\n\nIf you disable this policy setting, the device does not provision Windows Hello for Business for any user.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usepassportforwork_false","displayName":"false","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usepassportforwork_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_biometrics_enableesswithsupportedperipherals","displayName":"Enable ESS with Supported Peripherals","description":"Enhanced Sign-in Security (ESS) isolates both biometric template data and matching operations to trusted hardware or specified memory regions, meaning the rest of the operating system cannot access or tamper with them. Because the channel of communication between the sensors and the algorithm is also secured, it is impossible for malware to inject or replay data in order to simulate a user signing in or to lock a user out of their machine.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_biometrics_enableesswithsupportedperipherals_0","displayName":"Enhanced sign-in security will be disabled on all systems. If a user already has a secure Windows Hello enrollment, they will lose their enrollment and must reset PIN, and they will have the option to re-enroll in normal face and fingerprint. Peripheral usage will be enabled by disabling Enhanced sign-in security. OS will not attempt to start secure components, even if the secure hardware and software components are present. (not recommended)","description":"Enhanced sign-in security will be disabled on all systems. If a user already has a secure Windows Hello enrollment, they will lose their enrollment and must reset PIN, and they will have the option to re-enroll in normal face and fingerprint. Peripheral usage will be enabled by disabling Enhanced sign-in security. OS will not attempt to start secure components, even if the secure hardware and software components are present. (not recommended)","helpText":null},{"id":"device_vendor_msft_passportforwork_biometrics_enableesswithsupportedperipherals_1","displayName":"Enhanced sign-in security will be enabled on systems with capable software and hardware, following the existing default behavior in Windows. For systems with one secure modality (face or fingerprint) and one insecure modality (fingerprint or face), only the secure sensor can be used for sign-in and the insecure sensor(s) will be blocked. This includes peripheral devices, which are unsupported and will be unusable. (default and recommended for highest security)","description":"Enhanced sign-in security will be enabled on systems with capable software and hardware, following the existing default behavior in Windows. For systems with one secure modality (face or fingerprint) and one insecure modality (fingerprint or face), only the secure sensor can be used for sign-in and the insecure sensor(s) will be blocked. This includes peripheral devices, which are unsupported and will be unusable. (default and recommended for highest security)","helpText":null}]},{"id":"device_vendor_msft_passportforwork_biometrics_facialfeaturesuseenhancedantispoofing","displayName":"Facial Features Use Enhanced Anti Spoofing","description":"This setting determines whether enhanced anti-spoofing is required for Windows Hello face authentication.\n\nIf you enable this setting, Windows requires all users on managed devices to use enhanced anti-spoofing for Windows Hello face authentication. This disables Windows Hello face authentication on devices that do not support enhanced anti-spoofing.\n\nIf you disable or do not configure this setting, Windows doesn't require enhanced anti-spoofing for Windows Hello face authentication.\n\nNote that enhanced anti-spoofing for Windows Hello face authentication is not required on unmanaged devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_biometrics_facialfeaturesuseenhancedantispoofing_false","displayName":"false","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_biometrics_facialfeaturesuseenhancedantispoofing_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_biometrics_usebiometrics","displayName":"Allow Use of Biometrics","description":"Windows Hello for Business enables users to use biometric gestures, such as face and fingerprints, as an alternative to the PIN gesture. However, users must still configure a PIN to use in case of failures.\n\nIf you enable or do not configure this policy setting, Windows Hello for Business allows the use of biometric gestures.\n\nIf you disable this policy setting, Windows Hello for Business prevents the use of biometric gestures.\n\nNOTE: Disabling this policy prevents the use of biometric gestures on the device for all account types.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_biometrics_usebiometrics_false","displayName":"False","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_biometrics_usebiometrics_true","displayName":"True","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_deviceunlock_groupa","displayName":"Group A","description":"Contains a list of providers by GUID that are to be considered for the first step of authentication","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_deviceunlock_groupb","displayName":"Group B","description":"Contains a list of providers by GUID that are to be considered for the second step of authentication","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_deviceunlock_plugins","displayName":"Device Unlock Plugins","description":"List of plugins that the passive provider monitors to detect user presence","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_dynamiclock_dynamiclock","displayName":"Dynamic Lock","description":"Enables/Disables Dyanamic Lock","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_dynamiclock_dynamiclock_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_dynamiclock_dynamiclock_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_dynamiclock_plugins","displayName":"Dynamic Lock Plugins","description":"List of plugins that the passive provider monitors to detect user absence","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_securitykey_usesecuritykeyforsignin","displayName":"Use Security Key For Signin","description":"Use security key for signin. 0 is disabled. 1 is enable. If you do not configure this policy setting, the default is disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_securitykey_usesecuritykeyforsignin_0","displayName":"Disabled","description":"disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_securitykey_usesecuritykeyforsignin_1","displayName":"Enabled","description":"enabled","helpText":null}]},{"id":"device_vendor_msft_pkcscertificate_certificatevalidityperiod","displayName":"Certificate validity period","description":"The amount of time remaining before the certificate expires. Enter a value that is equal to or lower than the validity period shown in the certificate template. Default is set at one year.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},{"id":"device_vendor_msft_pkcscertificate_certificationauthority","displayName":"Certification Authority","description":"The fully qualified domain name of the server that hosts the Certification Authority role and issues certificates.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},{"id":"device_vendor_msft_pkcscertificate_keystorageprovider","displayName":"Key storage provider (KSP)","description":"Select where you want to store the certificate’s key.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},{"id":"device_vendor_msft_pkcscertificate_renewalthreshold","displayName":"Renewal threshold (%)","description":"Enter the percentage (between 1 and 99 percent) of remaining certificate lifetime that is allowed before a device can request renewal of the certificate. The recommended amount in Intune is 20%. (1-99)","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},{"id":"device_vendor_msft_pkcscertificate_subjectnameformat","displayName":"Subject name format","description":"CN={{UserName}},E={{EmailAddress}},OU=EnterpriseUsers,O=Contoso Corporation,L=Redmond,ST=WA,C=US\\nor\\nCN={{AAD_Device_ID}},E={{EmailAddress}},OU=EnterpriseUsers,O=Contoso Corporation,L=Redmond,ST=WA,C=US","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},{"id":"device_vendor_msft_pkcsimportedcertificate_intendedpurpose","displayName":"Intended Purpose","description":null,"helpText":"","infoUrls":[],"categoryId":"b2b85670-5475-4148-ab3d-c4c86b4d5af0","categoryName":"PKCS imported certificate","options":null},{"id":"device_vendor_msft_pkcsimportedcertificate_keystorageprovider","displayName":"Key storage provider (KSP)","description":"Select where you want to store the certificate’s key.","helpText":"","infoUrls":[],"categoryId":"b2b85670-5475-4148-ab3d-c4c86b4d5af0","categoryName":"PKCS imported certificate","options":null},{"id":"device_vendor_msft_policy_config_abovelock_allowcortanaabovelock","displayName":"Allow Cortana Above Lock","description":"Added in Windows 10, version 1607. Specifies whether or not the user can interact with Cortana using speech while the system is locked. If you allow or don’t configure this setting, the user can interact with Cortana using speech while the system is locked. If you block this setting, the system will need to be unlocked for the user to interact with Cortana using speech.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-abovelock#allowcortanaabovelock"],"categoryId":"ef8b8f2d-7791-4c44-a4f2-e39051f2e715","categoryName":"Above Lock","options":[{"id":"device_vendor_msft_policy_config_abovelock_allowcortanaabovelock_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_abovelock_allowcortanaabovelock_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_abovelock_allowtoasts","displayName":"Allow Toasts","description":"Specifies whether to allow toast notifications above the device lock screen. Most restrictive value is \"Block\".","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-abovelock#allowtoasts"],"categoryId":"ef8b8f2d-7791-4c44-a4f2-e39051f2e715","categoryName":"Above Lock","options":[{"id":"device_vendor_msft_policy_config_abovelock_allowtoasts_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_abovelock_allowtoasts_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_accounts_allowaddingnonmicrosoftaccountsmanually","displayName":"Allow Adding Non Microsoft Accounts Manually","description":"Specifies whether user is allowed to add non-MSA email accounts. Most restricted value is 0. Note This policy will only block UI/UX-based methods for adding non-Microsoft accounts. Even if this policy is enforced, you can still provision non-MSA accounts using the EMAIL2 CSP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Accounts#AllowAddingNonMicrosoftAccountsManually"],"categoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","categoryName":"Accounts","options":[{"id":"device_vendor_msft_policy_config_accounts_allowaddingnonmicrosoftaccountsmanually_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_accounts_allowaddingnonmicrosoftaccountsmanually_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountconnection","displayName":"Allow Microsoft Account Connection","description":"Specifies whether the user is allowed to use an MSA account for non-email related connection authentication and services. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Accounts#AllowMicrosoftAccountConnection"],"categoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","categoryName":"Accounts","options":[{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountconnection_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountconnection_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountsigninassistant","displayName":"Allow Microsoft Account Sign In Assistant","description":"Allows IT Admins the ability to disable the Microsoft Account Sign-In Assistant (wlidsvc) NT service. Note If the MSA service is disabled, Windows Update will no longer offer feature updates to devices running Windows 10 1709 or higher. See Feature updates are not being offered while other updates are. Note: If the MSA service is disabled, the Subscription Activation feature will not work properly and your users will not be able to “step-up” from Windows 10 Pro to Windows 10 Enterprise, because the MSA ticket for license authentication cannot be generated. The machine will remain on Windows 10 Pro and no error will be displayed in the Activation Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Accounts#AllowMicrosoftAccountSignInAssistant"],"categoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","categoryName":"Accounts","options":[{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountsigninassistant_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountsigninassistant_1","displayName":"Manual start","description":"Manual start","helpText":null}]},{"id":"device_vendor_msft_policy_config_accounts_domainnamesforemailsync","displayName":"Domain Names For Email Sync","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Accounts#domainnamesforemailsync"],"categoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","categoryName":"Accounts","options":null},{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites","displayName":"Approved Installation Sites for ActiveX Controls","description":"This policy setting determines which ActiveX installation sites standard users in your organization can use to install ActiveX controls on their computers. When this setting is enabled, the administrator can create a list of approved Activex Install sites specified by host URL. \n\nIf you enable this setting, the administrator can create a list of approved ActiveX Install sites specified by host URL. \n \nIf you disable or do not configure this policy setting, ActiveX controls prompt the user for administrative credentials before installation. \n\nNote: Wild card characters cannot be used when specifying the host URLs.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-activexcontrols#activexcontrols-approvedinstallationsites"],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites_approvedactivexinstallsiteslist","displayName":"Host URLs","description":"","helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":null},{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites_approvedactivexinstallsiteslist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":null},{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites_approvedactivexinstallsiteslist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies","displayName":"Establish ActiveX installation policy for sites in Trusted zones","description":"This policy setting controls the installation of ActiveX controls for sites in Trusted zone. \r\n\r\nIf you enable this policy setting, ActiveX controls are installed according to the settings defined by this policy setting. \r\n \r\nIf you disable or do not configure this policy setting, ActiveX controls prompt the user before installation. \r\n\r\nIf the trusted site uses the HTTPS protocol, this policy setting can also control how ActiveX Installer Service responds to certificate errors. By default all HTTPS connections must supply a server certificate that passes all validation criteria. If you are aware that a trusted site has a certificate error but you want to trust it anyway you can select the certificate errors that you want to ignore. \r\n \r\nNote: This policy setting applies to all sites in Trusted zones.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-activexinstallservice#admx-activexinstallservice-axisurlzonepolicies"],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcertdate","displayName":"Expired certificate validation date","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcertdate_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcertdate_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcn","displayName":"Invalid certificate name (CN)","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcn_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcn_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreunknownca","displayName":"Unknown certifcation authority (CA)","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreunknownca_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreunknownca_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignorewrongcertusage","displayName":"Wrong certificate usage","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignorewrongcertusage_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignorewrongcertusage_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installsignedocx","displayName":"Installation Policy for signed ActiveX control","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installsignedocx_0","displayName":"Don't install","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installsignedocx_1","displayName":"Prompt the user","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installsignedocx_2","displayName":"Silently install","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installtrustedocx","displayName":"Installation Policy for ActiveX control signed by trusted publisher","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installtrustedocx_0","displayName":"Don't install","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installtrustedocx_1","displayName":"Prompt the user","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installtrustedocx_2","displayName":"Silently install","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installunsignedocx","displayName":"Installation Policy for unsigned ActiveX control","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installunsignedocx_0","displayName":"Don't install","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installunsignedocx_1","displayName":"Prompt the user","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd","displayName":"Password Settings","description":"\nConfigures password parameters\n\nPassword complexity: which characters are used when generating a new password\n Default: Large letters + small letters + numbers + special characters\n\nPassword length\n Minimum: 8 characters\n Maximum: 64 characters\n Default: 14 characters\n\nPassword age in days\n Minimum: 1 day\n Maximum: 365 days\n Default: 30 days\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-admpwd#admx-admpwd-pol-admpwd"],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":[{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname","displayName":"Name of administrator account to manage","description":"\nAdministrator account name: name of the local account you want to manage password for.\n DO NOT configure when you use built-in admin account. Built-in admin account is auto-detected by well-known SID, even when renamed\n\n DO configure when you use custom local admin account\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-admpwd#admx-admpwd-pol-admpwd-adminname"],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":[{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname_txt_adminaccountname","displayName":"Administrator account name","description":"","helpText":"","infoUrls":[],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_dontallowpwdexpirationbehindpolicy","displayName":"Do not allow password expiration time longer than required by policy","description":"\nWhen you enable this setting, planned password expiration longer than password age dictated by \"Password Settings\" policy is NOT allowed. When such expiration is detected, password is changed immediately and password expiration is set according to policy.\n\nWhen you disable or not configure this setting, password expiration time may be longer than required by \"Password Settings\" policy.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-admpwd#admx-admpwd-pol-admpwd-dontallowpwdexpirationbehindpolicy"],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":[{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_dontallowpwdexpirationbehindpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_dontallowpwdexpirationbehindpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordagedays","displayName":"Password Age (Days)","description":"","helpText":"","infoUrls":[],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordcomplexity","displayName":"Password Complexity","description":"","helpText":"","infoUrls":[],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":[{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordcomplexity_1","displayName":"Large letters","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordcomplexity_2","displayName":"Large letters + small letters","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordcomplexity_3","displayName":"Large letters + small letters + numbers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordcomplexity_4","displayName":"Large letters + small letters + numbers + specials","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordlength","displayName":"Password Length","description":"","helpText":"","infoUrls":[],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_enabled","displayName":"Enable local admin password management","description":"\nEnables management of password for local administrator account\n\nIf you enable this setting, local administrator password is managed\n\nIf you disable or not configure this setting, local administrator password is NOT managed\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-admpwd#admx-admpwd-pol-admpwd-enabled"],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":[{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatprevent16bitmach","displayName":"Prevent access to 16-bit applications","description":"Specifies whether to prevent the MS-DOS subsystem (ntvdm.exe) from running on this computer. This setting affects the launching of 16-bit applications in the operating system.\r\n\r\nYou can use this setting to turn off the MS-DOS subsystem, which will reduce resource usage and prevent users from running 16-bit applications. To run any 16-bit application or any application with 16-bit components, ntvdm.exe must be allowed to run. The MS-DOS subsystem starts when the first 16-bit application is launched. While the MS-DOS subsystem is running, any subsequent 16-bit applications launch faster, but overall resource usage on the system is increased.\r\n\r\nIf the status is set to Enabled, the MS-DOS subsystem is prevented from running, which then prevents any 16-bit applications from running. In addition, any 32-bit applications with 16-bit installers or other 16-bit components cannot run.\r\n\r\nIf the status is set to Disabled, the MS-DOS subsystem runs for all users on this computer.\r\n\r\nIf the status is set to Not Configured, the OS falls back on a local policy set by the registry DWORD value HKLM\\System\\CurrentControlSet\\Control\\WOW\\DisallowedPolicyDefault. If that value is non-0, this prevents all 16-bit applications from running. If that value is 0, 16-bit applications are allowed to run. If that value is also not present, on Windows 10 and above the OS will launch the 16-bit application support control panel to allow an elevated administrator to make the decision; on windows 7 and downlevel, the OS will allow 16-bit applications to run.\r\n\r\nNote: This setting appears in only Computer Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatprevent16bitmach"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatprevent16bitmach_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatprevent16bitmach_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatremoveprogramcompatproppage","displayName":"Remove Program Compatibility Property Page","description":"This policy controls the visibility of the Program Compatibility property page shell extension. This shell extension is visible on the property context-menu of any program shortcut or executable file.\r\n\r\nThe compatibility property page displays a list of options that can be selected and applied to the application to resolve the most common issues affecting legacy applications. Enabling this policy setting removes the property page from the context-menus, but does not affect previous compatibility settings applied to application using this interface.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatremoveprogramcompatproppage"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatremoveprogramcompatproppage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatremoveprogramcompatproppage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffapplicationimpacttelemetry","displayName":"Turn off Application Telemetry","description":"The policy controls the state of the Application Telemetry engine in the system.\r\n\r\nApplication Telemetry is a mechanism that tracks anonymous usage of specific Windows system components by applications.\r\n\r\nTurning Application Telemetry off by selecting \"enable\" will stop the collection of usage data.\r\n\r\nIf the customer Experience Improvement program is turned off, Application Telemetry will be turned off regardless of how this policy is set.\r\n\r\nDisabling telemetry will take effect on any newly launched applications. To ensure that telemetry collection has stopped for all applications, please reboot your machine.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffapplicationimpacttelemetry"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffapplicationimpacttelemetry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffapplicationimpacttelemetry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffengine","displayName":"Turn off Application Compatibility Engine","description":" This policy controls the state of the application compatibility engine in the system.\r\n\r\nThe engine is part of the loader and looks through a compatibility database every time an application is started on the system. If a match for the application is found it provides either run-time solutions or compatibility fixes, or displays an Application Help message if the application has a know problem.\r\n\r\nTurning off the application compatibility engine will boost system performance. However, this will degrade the compatibility of many popular legacy applications, and will not block known incompatible applications from installing. (For Instance: This may result in a blue screen if an old anti-virus application is installed.)\r\n\r\nThe Windows Resource Protection and User Account Control features of Windows use the application compatibility engine to provide mitigations for application problems. If the engine is turned off, these mitigations will not be applied to applications and their installers and these applications may fail to install or run properly.\r\n\r\nThis option is useful to server administrators who require faster performance and are aware of the compatibility of the applications they are using. It is particularly useful for a web server where applications may be launched several hundred times a second, and the performance of the loader is essential.\r\n\r\nNOTE: Many system processes cache the value of this setting for performance reasons. If you make changes to this setting, please reboot to ensure that your system accurately reflects those changes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffengine"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffengine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffengine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffprogramcompatibilityassistant_2","displayName":"Turn off Program Compatibility Assistant","description":"This policy setting controls the state of the Program Compatibility Assistant (PCA).\r\n \r\nThe PCA monitors applications run by the user. When a potential compatibility issue with an application is detected, the PCA will prompt the user with recommended solutions. To configure the diagnostic settings for the PCA, go to System->Troubleshooting and Diagnostics->Application Compatibility Diagnostics. \r\n\r\nIf you enable this policy setting, the PCA will be turned off. The user will not be presented with solutions to known compatibility issues when running applications. Turning off the PCA can be useful for system administrators who require better performance and are already aware of application compatibility issues. \r\n\r\nIf you disable or do not configure this policy setting, the PCA will be turned on. To configure the diagnostic settings for the PCA, go to System->Troubleshooting and Diagnostics->Application Compatibility Diagnostics.\r\n\r\nNote: The Diagnostic Policy Service (DPS) and Program Compatibility Assistant Service must be running for the PCA to run. These services can be configured by using the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffprogramcompatibilityassistant-2"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffprogramcompatibilityassistant_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffprogramcompatibilityassistant_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffprograminventory","displayName":"Turn off Inventory Collector","description":"This policy setting controls the state of the Inventory Collector. \r\n\r\nThe Inventory Collector inventories applications, files, devices, and drivers on the system and sends the information to Microsoft. This information is used to help diagnose compatibility problems.\r\n\r\nIf you enable this policy setting, the Inventory Collector will be turned off and data will not be sent to Microsoft. Collection of installation data through the Program Compatibility Assistant is also disabled.\r\n\r\nIf you disable or do not configure this policy setting, the Inventory Collector will be turned on.\r\n\r\nNote: This policy setting has no effect if the Customer Experience Improvement Program is turned off. The Inventory Collector will be off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffprograminventory"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffprograminventory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffprograminventory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffswitchback","displayName":"Turn off SwitchBack Compatibility Engine","description":"The policy controls the state of the Switchback compatibility engine in the system. \r\n\r\nSwitchback is a mechanism that provides generic compatibility mitigations to older applications by providing older behavior to old applications and new behavior to new applications. \r\n\r\nSwitchback is on by default.\r\n\r\nIf you enable this policy setting, Switchback will be turned off. Turning Switchback off may degrade the compatibility of older applications. This option is useful for server administrators who require performance and are aware of compatibility of the applications they are using. \r\n\r\nIf you disable or do not configure this policy setting, the Switchback will be turned on.\r\n\r\nPlease reboot the system after changing the setting to ensure that your system accurately reflects those changes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffswitchback"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffswitchback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffswitchback_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffuseractionrecord","displayName":"Turn off Steps Recorder","description":"This policy setting controls the state of Steps Recorder.\r\n\r\nSteps Recorder keeps a record of steps taken by the user. The data generated by Steps Recorder can be used in feedback systems such as Windows Error Reporting to help developers understand and fix problems. The data includes user actions such as keyboard input and mouse input, user interface data, and screen shots. Steps Recorder includes an option to turn on and off data collection.\r\n\r\nIf you enable this policy setting, Steps Recorder will be disabled.\r\n\r\nIf you disable or do not configure this policy setting, Steps Recorder will be enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffuseractionrecord"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffuseractionrecord_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffuseractionrecord_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appxpackagemanager_allowdeploymentinspecialprofiles","displayName":"Allow deployment operations in special profiles","description":"This policy setting allows you to manage the deployment of Windows Store apps when the user is signed in using a special profile. Special profiles are the following user profiles, where changes are discarded after the user signs off:\r\n\r\nRoaming user profiles to which the \"Delete cached copies of roaming profiles\" Group Policy setting applies\r\n\r\nMandatory user profiles and super-mandatory profiles, which are created by an administrator\r\n\r\nTemporary user profiles, which are created when an error prevents the correct profile from loading\r\n\r\nUser profiles for the Guest account and members of the Guests group\r\n\r\n\r\nIf you enable this policy setting, Group Policy allows deployment operations (adding, registering, staging, updating, or removing an app package) of Windows Store apps when using a special profile.\r\n\r\nIf you disable or do not configure this policy setting, Group Policy blocks deployment operations of Windows Store apps when using a special profile.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appxpackagemanager#admx-appxpackagemanager-allowdeploymentinspecialprofiles"],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_admx_appxpackagemanager_allowdeploymentinspecialprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appxpackagemanager_allowdeploymentinspecialprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeapplicationcontenturirules","displayName":"Turn on dynamic Content URI Rules for packaged Microsoft Store apps","description":"This policy setting lets you turn on Content URI Rules to supplement the static Content URI Rules that were defined as part of the app manifest and apply to all Windows Store apps that use the enterpriseAuthentication capability on a computer.\r\n\r\nIf you enable this policy setting, you can define additional Content URI Rules that all Windows Store apps that use the enterpriseAuthentication capability on a computer can use.\r\n\r\nIf you disable or don't set this policy setting, Windows Store apps will only use the static Content URI Rules.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appxruntime#admx-appxruntime-appxruntimeapplicationcontenturirules"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeapplicationcontenturirules_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeapplicationcontenturirules_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeapplicationcontenturirules_listbox_contenturirules","displayName":"Content URI Rules:","description":null,"helpText":"","infoUrls":[],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":null},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockfileelevation","displayName":"Block launching desktop apps associated with a file.","description":"This policy setting lets you control whether Windows Store apps can open files using the default desktop app for a file type. Because desktop apps run at a higher integrity level than Windows Store apps, there is a risk that a Windows Store app might compromise the system by opening a file in the default desktop app for a file type.\r\n\r\nIf you enable this policy setting, Windows Store apps cannot open files in the default desktop app for a file type; they can open files only in other Windows Store apps.\r\n\r\nIf you disable or do not configure this policy setting, Windows Store apps can open files in the default desktop app for a file type.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appxruntime#admx-appxruntime-appxruntimeblockfileelevation"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockfileelevation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockfileelevation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockhostedappaccesswinrt","displayName":"Block launching Universal Windows apps with Windows Runtime API access from hosted content.","description":"\r\n This policy setting controls whether Universal Windows apps with Windows Runtime API access directly from web content can be launched.\r\n\r\n If you enable this policy setting, Universal Windows apps which declare Windows Runtime API access in ApplicationContentUriRules section of the manifest cannot be launched; Universal Windows apps which have not declared Windows Runtime API access in the manifest are not affected.\r\n\r\n If you disable or do not configure this policy setting, all Universal Windows apps can be launched.\r\n\r\n This policy should not be enabled unless recommended by Microsoft as a security response because it can cause severe app compatibility issues.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appxruntime#admx-appxruntime-appxruntimeblockhostedappaccesswinrt"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockhostedappaccesswinrt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockhostedappaccesswinrt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockprotocolelevation","displayName":"Block launching desktop apps associated with a URI scheme","description":"This policy setting lets you control whether Windows Store apps can open URIs using the default desktop app for a URI scheme. Because desktop apps run at a higher integrity level than Windows Store apps, there is a risk that a URI scheme launched by a Windows Store app might compromise the system by launching a desktop app.\r\n\r\nIf you enable this policy setting, Windows Store apps cannot open URIs in the default desktop app for a URI scheme; they can open URIs only in other Windows Store apps.\r\n\r\nIf you disable or do not configure this policy setting, Windows Store apps can open URIs in the default desktop app for a URI scheme.\r\n\r\nNote: Enabling this policy setting does not block Windows Store apps from opening the default desktop app for the http, https, and mailto URI schemes. The handlers for these URI schemes are hardened against URI-based vulnerabilities from untrusted sources, reducing the associated risk.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appxruntime#admx-appxruntime-appxruntimeblockprotocolelevation"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockprotocolelevation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockprotocolelevation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_auditsettings_includecmdline","displayName":"Include command line in process creation events","description":"This policy setting determines what information is logged in security audit events when a new process has been created.\r\n\r\nThis setting only applies when the Audit Process Creation policy is enabled. If you enable this policy setting the command line information for every process will be logged in plain text in the security event log as part of the Audit Process Creation event 4688, \"a new process has been created,\" on the workstations and servers on which this policy setting is applied.\r\n\r\nIf you disable or do not configure this policy setting, the process's command line information will not be included in Audit Process Creation events.\r\n\r\nDefault: Not configured\r\n\r\nNote: When this policy setting is enabled, any user with access to read the security events will be able to read the command line arguments for any successfully created process. Command line arguments can contain sensitive or private information such as passwords or user data.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-auditsettings#admx-auditsettings-includecmdline"],"categoryId":"76bbc368-9d0b-4aa7-b8e2-2dcfd864b9ee","categoryName":"Audit Process Creation","options":[{"id":"device_vendor_msft_policy_config_admx_auditsettings_includecmdline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_auditsettings_includecmdline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablebranchcache","displayName":"Do not allow the BITS client to use Windows Branch Cache","description":"This setting affects whether the BITS client is allowed to use Windows Branch Cache. If the Windows Branch Cache component is installed and enabled on a computer, BITS jobs on that computer can use Windows Branch Cache by default.\r\n\r\n If you enable this policy setting, the BITS client does not use Windows Branch Cache.\r\n\r\n If you disable or do not configure this policy setting, the BITS client uses Windows Branch Cache.\r\n\r\n Note: This policy setting does not affect the use of Windows Branch Cache by applications other than BITS. This policy setting does not apply to BITS transfers over SMB. This setting has no effect if the computer's administrative settings for Windows Branch Cache disable its use entirely.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-disablebranchcache"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablebranchcache_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablebranchcache_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablepeercachingclient","displayName":"Do not allow the computer to act as a BITS Peercaching client","description":"This policy setting specifies whether the computer will act as a BITS peer caching client. By default, when BITS peer caching is enabled, the computer acts as both a peer caching server (offering files to its peers) and a peer caching client (downloading files from its peers).\r\n\r\n If you enable this policy setting, the computer will no longer use the BITS peer caching feature to download files; files will be downloaded only from the origin server. However, the computer will still make files available to its peers.\r\n\r\n If you disable or do not configure this policy setting, the computer attempts to download peer-enabled BITS jobs from peer computers before reverting to the origin server.\r\n\r\n Note: This policy setting has no effect if the \"Allow BITS peer caching\" policy setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-disablepeercachingclient"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablepeercachingclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablepeercachingclient_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablepeercachingserver","displayName":"Do not allow the computer to act as a BITS Peercaching server","description":"This policy setting specifies whether the computer will act as a BITS peer caching server. By default, when BITS peer caching is enabled, the computer acts as both a peer caching server (offering files to its peers) and a peer caching client (downloading files from its peers).\r\n\r\n If you enable this policy setting, the computer will no longer cache downloaded files and offer them to its peers. However, the computer will still download files from peers.\r\n\r\n If you disable or do not configure this policy setting, the computer will offer downloaded and cached files to its peers.\r\n\r\n Note: This setting has no effect if the \"Allow BITS peer caching\" setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-disablepeercachingserver"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablepeercachingserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablepeercachingserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_enablepeercaching","displayName":"Allow BITS Peercaching","description":"This policy setting determines if the Background Intelligent Transfer Service (BITS) peer caching feature is enabled on a specific computer. By default, the files in a BITS job are downloaded only from the origin server specified by the job's owner.\r\n\r\n If BITS peer caching is enabled, BITS caches downloaded files and makes them available to other BITS peers. When transferring a download job, BITS first requests the files for the job from its peers in the same IP subnet. If none of the peers in the subnet have the requested files, BITS downloads them from the origin server.\r\n\r\n If you enable this policy setting, BITS downloads files from peers, caches the files, and responds to content requests from peers. Using the \"Do not allow the computer to act as a BITS peer caching server\" and \"Do not allow the computer to act as a BITS peer caching client\" policy settings, it is possible to control BITS peer caching functionality at a more detailed level. However, it should be noted that the \"Allow BITS peer caching\" policy setting must be enabled for the other two policy settings to have any effect.\r\n\r\n If you disable or do not configure this policy setting, the BITS peer caching feature will be disabled, and BITS will download files directly from the origin server.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-enablepeercaching"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_enablepeercaching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_enablepeercaching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthservedforpeers","displayName":"Limit the maximum network bandwidth used for Peercaching","description":"This policy setting limits the network bandwidth that BITS uses for peer cache transfers (this setting does not affect transfers from the origin server).\r\n To prevent any negative impact to a computer caused by serving other peers, by default BITS will use up to 30 percent of the bandwidth of the slowest active network interface. For example, if a computer has both a 100 Mbps network card and a 56 Kbps modem, and both are active, BITS will use a maximum of 30 percent of 56 Kbps. \r\n You can change the default behavior of BITS, and specify a fixed maximum bandwidth that BITS will use for peer caching.\r\n\r\n If you enable this policy setting, you can enter a value in bits per second (bps) between 1048576 and 4294967200 to use as the maximum network bandwidth used for peer caching.\r\n\r\n If you disable this policy setting or do not configure it, the default value of 30 percent of the slowest active network interface will be used.\r\n\r\n Note: This setting has no effect if the \"Allow BITS peer caching\" policy setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxbandwidthservedforpeers"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthservedforpeers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthservedforpeers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthservedforpeers_bits_maxbandwidthservedforpeerslist","displayName":"Maximum network bandwidth used for Peercaching (bps):","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance","displayName":"Set up a maintenance schedule to limit the maximum network bandwidth used for BITS background transfers","description":"This policy setting limits the network bandwidth that Background Intelligent Transfer Service (BITS) uses for background transfers during the maintenance days and hours. Maintenance schedules further limit the network bandwidth that is used for background transfers.\r\n\r\n If you enable this policy setting, you can define a separate set of network bandwidth limits and set up a schedule for the maintenance period.\r\n\r\n You can specify a limit to use for background jobs during a maintenance schedule. For example, if normal priority jobs are currently limited to 256 Kbps on a work schedule, you can further limit the network bandwidth of normal priority jobs to 0 Kbps from 8:00 A.M. to 10:00 A.M. on a maintenance schedule.\r\n\r\n If you disable or do not configure this policy setting, the limits defined for work or nonwork schedules will be used.\r\n\r\n Note: The bandwidth limits that are set for the maintenance period supersede any limits defined for work and other schedules.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxbandwidthv2-maintenance"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_6","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_6","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehighprioritylimit","displayName":"High Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehighpriorityunit","displayName":"High Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehighpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehighpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehighpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_23","displayName":"11 PM","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_23","displayName":"11 PM","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancelowprioritylimit","displayName":"Low Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancelowpriorityunit","displayName":"Low Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancelowpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancelowpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancelowpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalprioritylimit","displayName":"Normal Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit","displayName":"Normal Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work","displayName":"Set up a work schedule to limit the maximum network bandwidth used for BITS background transfers","description":"This policy setting limits the network bandwidth that Background Intelligent Transfer Service (BITS) uses for background transfers during the work and nonwork days and hours. The work schedule is defined using a weekly calendar, which consists of days of the week and hours of the day. All hours and days that are not defined in a work schedule are considered non-work hours.\r\n\r\n If you enable this policy setting, you can set up a schedule for limiting network bandwidth during both work and nonwork hours. After the work schedule is defined, you can set the bandwidth usage limits for each of the three BITS background priority levels: high, normal, and low.\r\n\r\n You can specify a limit to use for background jobs during a work schedule. For example, you can limit the network bandwidth of low priority jobs to 128 Kbps from 8:00 A.M. to 5:00 P.M. on Monday through Friday, and then set the limit to 512 Kbps for nonwork hours.\r\n\r\n If you disable or do not configure this policy setting, BITS uses all available unused bandwidth for background job transfers.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxbandwidthv2-work"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_ignorelimitsonlan","displayName":"Ignore bandwidth limits if the source and the destination are on the same subnet.","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_ignorelimitsonlan_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_ignorelimitsonlan_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworkhighprioritylimit","displayName":"High Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworkhighpriorityunit","displayName":"High Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworkhighpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworkhighpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworkhighpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworklowprioritylimit","displayName":"Low Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworklowpriorityunit","displayName":"Low Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworklowpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworklowpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworklowpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalprioritylimit","displayName":"Normal Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit","displayName":"Normal Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_6","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_6","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhighprioritylimit","displayName":"High Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhighpriorityunit","displayName":"High Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhighpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhighpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhighpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_23","displayName":"11 PM","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_23","displayName":"11 PM","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worklowprioritylimit","displayName":"Low Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worklowpriorityunit","displayName":"Low Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worklowpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worklowpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worklowpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worknormalprioritylimit","displayName":"Normal Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worknormalpriorityunit","displayName":"Normal Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worknormalpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worknormalpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worknormalpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcachesize","displayName":"Limit the BITS Peercache size","description":"This policy setting limits the maximum amount of disk space that can be used for the BITS peer cache, as a percentage of the total system disk size. BITS will add files to the peer cache and make those files available to peers until the cache content reaches the specified cache size. By default, BITS will use 1 percent of the total system disk for the peercache.\r\n\r\n If you enable this policy setting, you can enter the percentage of disk space to be used for the BITS peer cache. You can enter a value between 1 percent and 80 percent.\r\n\r\n If you disable or do not configure this policy setting, the default size of the BITS peer cache is 1 percent of the total system disk size.\r\n\r\n Note: This policy setting has no effect if the \"Allow BITS peer caching\" setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxcachesize"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcachesize_bits_maxsize","displayName":"Percentage of disk space to be used for the BITS peercache:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcontentage","displayName":"Limit the age of files in the BITS Peercache","description":"This policy setting limits the maximum age of files in the Background Intelligent Transfer Service (BITS) peer cache. In order to make the most efficient use of disk space, by default BITS removes any files in the peer cache that have not been accessed in the past 90 days.\r\n\r\n If you enable this policy setting, you can specify in days the maximum age of files in the cache. You can enter a value between 1 and 120 days.\r\n\r\n If you disable or do not configure this policy setting, files that have not been accessed for the past 90 days will be removed from the peer cache.\r\n\r\n Note: This policy setting has no effect if the \"Allow BITS Peercaching\" policy setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxcontentage"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcontentage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcontentage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcontentage_bits_maxcontentagelist","displayName":"Number of days:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxdownloadtime","displayName":"Limit the maximum BITS job download time","description":"This policy setting limits the amount of time that Background Intelligent Transfer Service (BITS) will take to download the files in a BITS job.\r\n\r\n The time limit applies only to the time that BITS is actively downloading files. When the cumulative download time exceeds this limit, the job is placed in the error state.\r\n\r\n By default BITS uses a maximum download time of 90 days (7,776,000 seconds).\r\n\r\n If you enable this policy setting, you can set the maximum job download time to a specified number of seconds.\r\n\r\n If you disable or do not configure this policy setting, the default value of 90 days (7,776,000 seconds) will be used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxdownloadtime"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxdownloadtime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxdownloadtime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxdownloadtime_bits_maxdownloadseconds","displayName":"Active Job Timeout in seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxfilesperjob","displayName":"Limit the maximum number of files allowed in a BITS job","description":"This policy setting limits the number of files that a BITS job can contain. By default, a BITS job is limited to 200 files. You can use this setting to raise or lower the maximum number of files a BITS jobs can contain.\r\n\r\n If you enable this policy setting, BITS will limit the maximum number of files a job can contain to the specified number.\r\n\r\n If you disable or do not configure this policy setting, BITS will use the default value of 200 for the maximum number of files a job can contain.\r\n\r\n Note: BITS Jobs created by services and the local administrator account do not count toward this limit.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxfilesperjob"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxfilesperjob_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxfilesperjob_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxfilesperjob_bits_maxfilesperjoblist","displayName":"Maximum number of files allowed in a BITS job:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobspermachine","displayName":"Limit the maximum number of BITS jobs for this computer","description":"This policy setting limits the number of BITS jobs that can be created for all users of the computer. By default, BITS limits the total number of jobs that can be created on the computer to 300 jobs. You can use this policy setting to raise or lower the maximum number of user BITS jobs.\r\n\r\n If you enable this policy setting, BITS will limit the maximum number of BITS jobs to the specified number.\r\n\r\n If you disable or do not configure this policy setting, BITS will use the default BITS job limit of 300 jobs.\r\n\r\n Note: BITS jobs created by services and the local administrator account do not count toward this limit.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxjobspermachine"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobspermachine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobspermachine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobspermachine_bits_maxjobspermachinelist","displayName":"Maximum number of BITS jobs for this computer:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser","displayName":"Limit the maximum number of BITS jobs for each user","description":"This policy setting limits the number of BITS jobs that can be created by a user. By default, BITS limits the total number of jobs that can be created by a user to 60 jobs. You can use this setting to raise or lower the maximum number of BITS jobs a user can create.\r\n\r\n If you enable this policy setting, BITS will limit the maximum number of BITS jobs a user can create to the specified number.\r\n\r\n If you disable or do not configure this policy setting, BITS will use the default user BITS job limit of 300 jobs.\r\n\r\n Note: This limit must be lower than the setting specified in the \"Maximum number of BITS jobs for this computer\" policy setting, or 300 if the \"Maximum number of BITS jobs for this computer\" policy setting is not configured. BITS jobs created by services and the local administrator account do not count toward this limit.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxjobsperuser"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser_bits_maxjobsperuserlist","displayName":"Maximum number of BITS jobs for each user:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxrangesperfile","displayName":"Limit the maximum number of ranges that can be added to the file in a BITS job","description":"This policy setting limits the number of ranges that can be added to a file in a BITS job. By default, files in a BITS job are limited to 500 ranges per file. You can use this setting to raise or lower the maximum number ranges per file.\r\n\r\n If you enable this policy setting, BITS will limit the maximum number of ranges that can be added to a file to the specified number.\r\n\r\n If you disable or do not configure this policy setting, BITS will limit ranges to 500 ranges per file.\r\n\r\n Note: BITS Jobs created by services and the local administrator account do not count toward this limit.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxrangesperfile"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxrangesperfile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxrangesperfile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxrangesperfile_bits_maxrangesperfilelist","displayName":"Maximum number of ranges that can be added to the file in a BITS job:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslciphersuiteorder","displayName":"SSL Cipher Suite Order","description":"This policy setting determines the cipher suites used by the Secure Socket Layer (SSL).\r\n\r\nIf you enable this policy setting, SSL cipher suites are prioritized in the order specified.\r\n\r\nIf you disable or do not configure this policy setting, default cipher suite order is used.\r\n\r\nLink for all the cipherSuites: http://go.microsoft.com/fwlink/?LinkId=517265\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ciphersuiteorder#admx-ciphersuiteorder-sslciphersuiteorder"],"categoryId":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","categoryName":"SSL Configuration Settings","options":[{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslciphersuiteorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslciphersuiteorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslciphersuiteorder_pol_sslciphersuiteorder","displayName":"SSL Cipher Suites","description":null,"helpText":"","infoUrls":[],"categoryId":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","categoryName":"SSL Configuration Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder","displayName":"ECC Curve Order","description":"This policy setting determines the priority order of ECC curves used with ECDHE cipher suites.\r\n\r\nIf you enable this policy setting, ECC curves are prioritized in the order specified.(Enter one Curve name per line)\r\n\r\nIf you disable or do not configure this policy setting, the default ECC curve order is used.\r\n\r\nDefault Curve Order\r\n============\r\ncurve25519\r\nNistP256\r\nNistP384\r\n\r\nTo See all the curves supported on the system, Use the following command:\r\n\r\nCertUtil.exe -DisplayEccCurve\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ciphersuiteorder#admx-ciphersuiteorder-sslcurveorder"],"categoryId":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","categoryName":"SSL Configuration Settings","options":[{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder_sslcurveorderlist","displayName":"ECC Curve Order:","description":null,"helpText":"","infoUrls":[],"categoryId":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","categoryName":"SSL Configuration Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_com_appmgmt_com_searchforclsid_2","displayName":"Download missing COM components","description":"This policy setting directs the system to search Active Directory for missing Component Object Model (COM) components that a program requires.\r\n\r\nMany Windows programs, such as the MMC snap-ins, use the interfaces provided by the COM components. These programs cannot perform all their functions unless Windows has internally registered the required components.\r\n\r\nIf you enable this policy setting and a component registration is missing, the system searches for it in Active Directory and, if it is found, downloads it. The resulting searches might make some programs start or run slowly.\r\n\r\nIf you disable or do not configure this policy setting, the program continues without the registration. As a result, the program might not perform all its functions, or it might stop.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-com#admx-com-appmgmt-com-searchforclsid-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_com_appmgmt_com_searchforclsid_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_com_appmgmt_com_searchforclsid_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen","displayName":"Force a specific default lock screen and logon image","description":"This setting allows you to force a specific default lock screen and logon image by entering the path (location) of the image file. The same image will be used for both the lock and logon screens.\r\n\r\nThis setting lets you specify the default lock screen and logon image shown when no user is signed in, and also sets the specified image as the default for all users (it replaces the inbox default image).\r\n\r\nTo use this setting, type the fully qualified path and name of the file that stores the default lock screen and logon image. You can type a local path, such as C:\\Windows\\Web\\Screen\\img104.jpg or a UNC path, such as \\\\Server\\Share\\Corp.jpg.\r\n\r\nThis can be used in conjunction with the \"Prevent changing lock screen and logon image\" setting to always force the specified lock screen and logon image to be shown.\r\n\r\nNote: This setting only applies to Enterprise, Education, and Server SKUs.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-forcedefaultlockscreen"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_lockscreenimage","displayName":"Path to lock screen image:","description":null,"helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_lockscreenoverlaysdisabled","displayName":"Turn off fun facts, tips, tricks, and more on lock screen","description":null,"helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_lockscreenoverlaysdisabled_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_lockscreenoverlaysdisabled_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nochanginglockscreen","displayName":"Prevent changing lock screen and logon image","description":"Prevents users from changing the background image shown when the machine is locked or when on the logon screen.\r\n\r\nBy default, users can change the background image shown when the machine is locked or displaying the logon screen.\r\n\r\nIf you enable this setting, the user will not be able to change their lock screen and logon image, and they will instead see the default image.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-nochanginglockscreen"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nochanginglockscreen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nochanginglockscreen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nochangingstartmenubackground","displayName":"Prevent changing start menu background","description":"Prevents users from changing the look of their start menu background, such as its color or accent.\r\n\r\nBy default, users can change the look of their start menu background, such as its color or accent.\r\n\r\nIf you enable this setting, the user will be assigned the default start menu background and colors and will not be allowed to change them.\r\n\r\nIf the \"Force a specific background and accent color\" policy is also set on a supported version of Windows, then those colors take precedence over this policy.\r\n\r\nIf the \"Force a specific Start background\" policy is also set on a supported version of Windows, then that background takes precedence over this policy.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-nochangingstartmenubackground"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nochangingstartmenubackground_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nochangingstartmenubackground_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nolockscreen","displayName":"Do not display the lock screen","description":"This policy setting controls whether the lock screen appears for users.\r\n\r\nIf you enable this policy setting, users that are not required to press CTRL + ALT + DEL before signing in will see their selected tile after locking their PC.\r\n\r\nIf you disable or do not configure this policy setting, users that are not required to press CTRL + ALT + DEL before signing in will see a lock screen after locking their PC. They must dismiss the lock screen using touch, the keyboard, or by dragging it with the mouse.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-nolockscreen"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nolockscreen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nolockscreen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_personalcolors","displayName":"Force a specific background and accent color","description":"Forces Windows to use the specified colors for the background and accent. The color values are specified in hex as #RGB.\r\n\r\nBy default, users can change the background and accent colors.\r\n\r\nIf this setting is enabled, the background and accent colors of Windows will be set to the specified colors and users cannot change those colors. This setting will not be applied if the specified colors do not meet a contrast ratio of 2:1 with white text.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-personalcolors"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_personalcolors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_personalcolors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_personalcolors_personalcolors_accent","displayName":"Accent color:","description":null,"helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_personalcolors_personalcolors_background","displayName":"Start background color:","description":null,"helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme","displayName":"Load a specific theme","description":"Specifies which theme file is applied to the computer the first time a user logs on.\n\nIf you enable this setting, the theme that you specify will be applied when a new user logs on for the first time. This policy does not prevent the user from changing the theme or any of the theme elements such as the desktop background, color, sounds, or screen saver after the first logon.\n\nIf you disable or do not configure this setting, the default theme will be applied at the first logon.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-settheme"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_themefilename","displayName":"Path to theme file:","description":"","helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_startbackground","displayName":"Force a specific Start background","description":"Forces the Start screen to use one of the available backgrounds, 1 through 20, and prevents the user from changing it.\r\n\r\nIf this setting is set to zero or not configured, then Start uses the default background, and users can change it.\r\n\r\nIf this setting is set to a nonzero value, then Start uses the specified background, and users cannot change it. If the specified background is not supported, the default background is used.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-startbackground"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_startbackground_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_startbackground_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_startbackground_startbackgroundspin","displayName":"Background ID:","description":null,"helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":null},{"id":"device_vendor_msft_policy_config_admx_cpls_usedefaulttile","displayName":"Apply the default account picture to all users","description":"This policy setting allows an administrator to standardize the account pictures for all users on a system to the default account picture. One application for this policy setting is to standardize the account pictures to a company logo.\r\n\r\nNote: The default account picture is stored at %PROGRAMDATA%\\Microsoft\\User Account Pictures\\user.jpg. The default guest picture is stored at %PROGRAMDATA%\\Microsoft\\User Account Pictures\\guest.jpg. If the default pictures do not exist, an empty frame is displayed.\r\n\r\nIf you enable this policy setting, the default user account picture will display for all users on the system with no customization allowed.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to customize their account pictures.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-cpls#admx-cpls-usedefaulttile"],"categoryId":"6b87c5da-cfd9-44bc-be05-ed08eb2144c7","categoryName":"User Accounts","options":[{"id":"device_vendor_msft_policy_config_admx_cpls_usedefaulttile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_cpls_usedefaulttile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_allowdomaindelaylock","displayName":"Allow users to select when a password is required when resuming from connected standby","description":"This policy setting allows you to control whether a user can change the time before a password is required when a Connected Standby device screen turns off.\r\n\r\nIf you enable this policy setting, a user on a Connected Standby device can change the amount of time after the device's screen turns off before a password is required when waking the device. The time is limited by any EAS settings or Group Policies that affect the maximum idle time before a device locks. Additionally, if a password is required when a screensaver turns on, the screensaver timeout will limit the options the user may choose.\r\n\r\nIf you disable this policy setting, a user cannot change the amount of time after the device's screen turns off before a password is required when waking the device. Instead, a password is required immediately after the screen turns off.\r\n\r\nIf you don't configure this policy setting on a domain-joined device, a user cannot change the amount of time after the device's screen turns off before a password is required when waking the device. Instead, a password is required immediately after the screen turns off.\r\n\r\nIf you don't configure this policy setting on a workgroup device, a user on a Connected Standby device can change the amount of time after the device's screen turns off before a password is required when waking the device. The time is limited by any EAS settings or Group Policies that affect the maximum idle time before a device locks. Additionally, if a password is required when a screensaver turns on, the screensaver timeout will limit the options the user may choose.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credentialproviders#admx-credentialproviders-allowdomaindelaylock"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_credentialproviders_allowdomaindelaylock_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_allowdomaindelaylock_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider","displayName":"Assign a default credential provider","description":"This policy setting allows the administrator to assign a specified credential provider as the default credential provider.\r\n\r\nIf you enable this policy setting, the specified credential provider is selected on other user tile.\r\n\r\nIf you disable or do not configure this policy setting, the system picks the default credential provider on other user tile.\r\n\r\nNote: A list of registered credential providers and their GUIDs can be found in the registry at HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Authentication\\Credential Providers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credentialproviders#admx-credentialproviders-defaultcredentialprovider"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider_defaultcredentialprovider_message","displayName":"Assign the following credential provider as the default credential provider:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_excludedcredentialproviders","displayName":"Exclude credential providers","description":"This policy setting allows the administrator to exclude the specified\r\ncredential providers from use during authentication.\r\n\r\nNote: credential providers are used to process and validate user\r\ncredentials during logon or when authentication is required.\r\nWindows Vista provides two default credential providers:\r\nPassword and Smart Card. An administrator can install additional\r\ncredential providers for different sets of credentials\r\n(for example, to support biometric authentication).\r\n\r\nIf you enable this policy, an administrator can specify the CLSIDs\r\nof the credential providers to exclude from the set of installed\r\ncredential providers available for authentication purposes.\r\n\r\nIf you disable or do not configure this policy, all installed and otherwise enabled credential providers are available for authentication purposes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credentialproviders#admx-credentialproviders-excludedcredentialproviders"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_credentialproviders_excludedcredentialproviders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_excludedcredentialproviders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_excludedcredentialproviders_excludedcredentialproviders_message","displayName":"Exclude the following credential providers:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials","displayName":"Allow delegating default credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved by using a trusted X509 certificate or Kerberos.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's default credentials can be delegated (default credentials are those that you use when first logging on to Windows).\r\n\r\nThe policy becomes effective the next time the user signs on to a computer running Windows.\r\n\r\nIf you disable or do not configure (by default) this policy setting, delegation of default credentials is not permitted to any computer. Applications depending upon this delegation behavior might fail authentication. For more information, see KB.\r\n\r\nFWlink for KB:\r\nhttp://go.microsoft.com/fwlink/?LinkId=301508\r\n\r\nNote: The \"Allow delegating default credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowdefaultcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials_allowdefaultcredentials_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials_concatenatedefaults_adc","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials_concatenatedefaults_adc_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials_concatenatedefaults_adc_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly","displayName":"Allow delegating default credentials with NTLM-only server authentication","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via NTLM.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's default credentials can be delegated (default credentials are those that you use when first logging on to Windows).\r\n\r\nIf you disable or do not configure (by default) this policy setting, delegation of default credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating default credentials with NTLM-only server authentication\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowdefcredentialswhenntlmonly"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_allowdefcredentialswhenntlmonly_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_concatenatedefaults_adcn","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_concatenatedefaults_adcn_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_concatenatedefaults_adcn_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle","displayName":"Encryption Oracle Remediation","description":"Encryption Oracle Remediation\r\n\r\nThis policy setting applies to applications using the CredSSP component (for example: Remote Desktop Connection).\r\n\r\nSome versions of the CredSSP protocol are vulnerable to an encryption oracle attack against the client. This policy controls compatibility with vulnerable clients and servers. This policy allows you to set the level of protection desired for the encryption oracle vulnerability.\r\n\r\nIf you enable this policy setting, CredSSP version support will be selected based on the following options:\r\n\r\nForce Updated Clients: Client applications which use CredSSP will not be able to fall back to the insecure versions and services using CredSSP will not accept unpatched clients. Note: this setting should not be deployed until all remote hosts support the newest version.\r\n\r\nMitigated: Client applications which use CredSSP will not be able to fall back to the insecure version but services using CredSSP will accept unpatched clients. See the link below for important information about the risk posed by remaining unpatched clients.\r\n\r\nVulnerable: Client applications which use CredSSP will expose the remote servers to attacks by supporting fall back to the insecure versions and services using CredSSP will accept unpatched clients.\r\n\r\nFor more information about the vulnerability and servicing requirements for protection, see https://go.microsoft.com/fwlink/?linkid=866660\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowencryptionoracle"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle_allowencryptionoracledrop","displayName":"Protection Level:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle_allowencryptionoracledrop_0","displayName":"Force Updated Clients","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle_allowencryptionoracledrop_1","displayName":"Mitigated","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle_allowencryptionoracledrop_2","displayName":"Vulnerable","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials","displayName":"Allow delegating fresh credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via a trusted X509 certificate or Kerberos.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's fresh credentials can be delegated (fresh credentials are those that you are prompted for when executing the application).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of fresh credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*).\r\n\r\nIf you disable this policy setting, delegation of fresh credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating fresh credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com\r\nRemote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowfreshcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_allowfreshcredentials_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_concatenatedefaults_afc","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_concatenatedefaults_afc_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_concatenatedefaults_afc_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly","displayName":"Allow delegating fresh credentials with NTLM-only server authentication","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via NTLM.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's fresh credentials can be delegated (fresh credentials are those that you are prompted for when executing the application).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of fresh credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*).\r\n\r\nIf you disable this policy setting, delegation of fresh credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating fresh credentials with NTLM-only server authentication\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowfreshcredentialswhenntlmonly"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_allowfreshcredentialswhenntlmonly_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_concatenatedefaults_afcn","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_concatenatedefaults_afcn_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_concatenatedefaults_afcn_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials","displayName":"Allow delegating saved credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via a trusted X509 certificate or Kerberos.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's saved credentials can be delegated (saved credentials are those that you elect to save/remember using the Windows credential manager).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of saved credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*).\r\n\r\nIf you disable this policy setting, delegation of saved credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating saved credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowsavedcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_allowsavedcredentials_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_concatenatedefaults_asc","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_concatenatedefaults_asc_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_concatenatedefaults_asc_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly","displayName":"Allow delegating saved credentials with NTLM-only server authentication","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via NTLM.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's saved credentials can be delegated (saved credentials are those that you elect to save/remember using the Windows credential manager).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of saved credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*) if the client machine is not a member of any domain. If the client is domain-joined, by default the delegation of saved credentials is not permitted to any machine.\r\n\r\nIf you disable this policy setting, delegation of saved credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating saved credentials with NTLM-only server authentication\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowsavedcredentialswhenntlmonly"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_allowsavedcredentialswhenntlmonly_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_concatenatedefaults_ascn","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_concatenatedefaults_ascn_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_concatenatedefaults_ascn_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials","displayName":"Deny delegating default credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's default credentials cannot be delegated (default credentials are those that you use when first logging on to Windows).\r\n\r\nIf you disable or do not configure (by default) this policy setting, this policy setting does not specify any server.\r\n\r\nNote: The \"Deny delegating default credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials cannot be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n\r\nThis policy setting can be used in combination with the \"Allow delegating default credentials\" policy setting to define exceptions for specific servers that are otherwise permitted when using wildcard characters in the \"Allow delegating default credentials\" server list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-denydefaultcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_concatenatedefaults_ddc","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_concatenatedefaults_ddc_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_concatenatedefaults_ddc_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_denydefaultcredentials_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials","displayName":"Deny delegating fresh credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's fresh credentials cannot be delegated (fresh credentials are those that you are prompted for when executing the application).\r\n\r\nIf you disable or do not configure (by default) this policy setting, this policy setting does not specify any server.\r\n\r\nNote: The \"Deny delegating fresh credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials cannot be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n\r\nThis policy setting can be used in combination with the \"Allow delegating fresh credentials\" policy setting to define exceptions for specific servers that are otherwise permitted when using wildcard characters in the \"Allow delegating fresh credentials\" server list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-denyfreshcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials_concatenatedefaults_dfc","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials_concatenatedefaults_dfc_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials_concatenatedefaults_dfc_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials_denyfreshcredentials_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials","displayName":"Deny delegating saved credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's saved credentials cannot be delegated (saved credentials are those that you elect to save/remember using the Windows credential manager).\r\n\r\nIf you disable or do not configure (by default) this policy setting, this policy setting does not specify any server.\r\n\r\nNote: The \"Deny delegating saved credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials cannot be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n\r\nThis policy setting can be used in combination with the \"Allow delegating saved credentials\" policy setting to define exceptions for specific servers that are otherwise permitted when using wildcard characters in the \"Allow delegating saved credentials\" server list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-denysavedcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials_concatenatedefaults_dsc","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials_concatenatedefaults_dsc_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials_concatenatedefaults_dsc_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials_denysavedcredentials_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration","displayName":"Restrict delegation of credentials to remote servers","description":"When running in Restricted Admin or Remote Credential Guard mode, participating apps do not expose signed in or supplied credentials to a remote host. Restricted Admin limits access to resources located on other servers or networks from the remote host because credentials are not delegated. Remote Credential Guard does not limit access to resources because it redirects all requests back to the client device.\r\n\r\nParticipating apps:\r\nRemote Desktop Client\r\n\r\nIf you enable this policy setting, the following options are supported:\r\n \r\nRestrict credential delegation: Participating applications must use Restricted Admin or Remote Credential Guard to connect to remote hosts.\r\n \r\nRequire Remote Credential Guard: Participating applications must use Remote Credential Guard to connect to remote hosts.\r\n \r\nRequire Restricted Admin: Participating applications must use Restricted Admin to connect to remote hosts.\r\n\r\nIf you disable or do not configure this policy setting, Restricted Admin and Remote Credential Guard mode are not enforced and participating apps can delegate credentials to remote devices.\r\n\r\nNote: To disable most credential delegation, it may be sufficient to deny delegation in Credential Security Support Provider (CredSSP) by modifying Administrative template settings (located at Computer Configuration\\Administrative Templates\\System\\Credentials Delegation).\r\n\r\nNote: On Windows 8.1 and Windows Server 2012 R2, enabling this policy will enforce Restricted Administration mode, regardless of the mode chosen. These versions do not support Remote Credential Guard.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-restrictedremoteadministration"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop","displayName":"Use the following restricted mode:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop_3","displayName":"Restrict Credential Delegation","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop_2","displayName":"Require Remote Credential Guard","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop_1","displayName":"Require Restricted Admin","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credui_enablesecurecredentialprompting","displayName":"Require trusted path for credential entry","description":"This policy setting requires the user to enter Microsoft Windows credentials using a trusted path, to prevent a Trojan horse or other types of malicious code from stealing the user’s Windows credentials.\r\n\r\nNote: This policy affects nonlogon authentication tasks only. As a security best practice, this policy should be enabled.\r\n\r\nIf you enable this policy setting, users will be required to enter Windows credentials on the Secure Desktop by means of the trusted path mechanism.\r\n\r\nIf you disable or do not configure this policy setting, users will enter Windows credentials within the user’s desktop session, potentially allowing malicious code access to the user’s Windows credentials.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credui#admx-credui-enablesecurecredentialprompting"],"categoryId":"58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","categoryName":"Credential User Interface","options":[{"id":"device_vendor_msft_policy_config_admx_credui_enablesecurecredentialprompting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credui_enablesecurecredentialprompting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credui_nolocalpasswordresetquestions","displayName":"Prevent the use of security questions for local accounts","description":"If you turn this policy setting on, local users won’t be able to set up and use security questions to reset their passwords.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credui#admx-credui-nolocalpasswordresetquestions"],"categoryId":"58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","categoryName":"Credential User Interface","options":[{"id":"device_vendor_msft_policy_config_admx_credui_nolocalpasswordresetquestions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credui_nolocalpasswordresetquestions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_datacollection_commercialidpolicy","displayName":"Configure the Commercial ID","description":"This policy setting defines the identifier used to uniquely associate this device’s telemetry data as belonging to a given organization. If your organization is participating in a program that requires this device to be identified as belonging to your organization then use this setting to provide that identification. The value for this setting will be provided by Microsoft as part of the onboarding process for the program. \r\n\r\nIf you disable or do not configure this policy setting, then Microsoft will not be able to use this identifier to associate this machine and its telemetry data with your organization.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-datacollection#admx-datacollection-commercialidpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_datacollection_commercialidpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_datacollection_commercialidpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_datacollection_commercialidpolicy_commercialidvalue","displayName":"Commercial Id:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckallowlocallist","displayName":"Allow local activation security check exemptions","description":"Allows you to specify that local computer administrators can supplement the \"Define Activation Security Check exemptions\" list.\r\n\r\nIf you enable this policy setting, and DCOM does not find an explicit entry for a DCOM server application id (appid) in the \"Define Activation Security Check exemptions\" policy (if enabled), DCOM will look for an entry in the locally configured list.\r\n\r\nIf you disable this policy setting, DCOM will not look in the locally configured DCOM activation security check exemption list.\r\n\r\nIf you do not configure this policy setting, DCOM will only look in the locally configured exemption list if the \"Define Activation Security Check exemptions\" policy is not configured.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dcom#admx-dcom-dcomactivationsecuritycheckallowlocallist"],"categoryId":"a57b27b6-48e0-42b2-812a-2be86c113a0c","categoryName":"Application Compatibility Settings","options":[{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckallowlocallist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckallowlocallist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckexemptionlist","displayName":"Define Activation Security Check exemptions","description":"Allows you to view and change a list of DCOM server application ids (appids) which are exempted from the DCOM Activation security check. DCOM uses two such lists, one configured via Group Policy through this policy setting, and the other via the actions of local computer administrators. DCOM ignores the second list when this policy setting is configured, unless the \"Allow local activation security check exemptions\" policy is enabled.\r\n\r\nDCOM server appids added to this policy must be listed in curly-brace format. For example: {b5dcb061-cefb-42e0-a1be-e6a6438133fe}. If you enter a non-existent or improperly formatted appid DCOM will add it to the list without checking for errors.\r\n\r\nIf you enable this policy setting, you can view and change the list of DCOM activation security check exemptions defined by Group Policy settings. If you add an appid to this list and set its value to 1, DCOM will not enforce the Activation security check for that DCOM server. If you add an appid to this list and set its value to 0 DCOM will always enforce the Activation security check for that DCOM server regardless of local settings.\r\n\r\nIf you disable this policy setting, the appid exemption list defined by Group Policy is deleted, and the one defined by local computer administrators is used.\r\n\r\nIf you do not configure this policy setting, the appid exemption list defined by local computer administrators is used.\r\n\r\nNotes:\r\n\r\nThe DCOM Activation security check is done after a DCOM server process is started, but before an object activation request is dispatched to the server process. This access check is done against the DCOM server's custom launch permission security descriptor if it exists, or otherwise against the configured defaults.\r\n\r\nIf the DCOM server's custom launch permission contains explicit DENY entries this may mean that object activations that would have previously succeeded for such specified users, once the DCOM server process was up and running, might now fail instead. The proper action in this situation is to re-configure the DCOM server's custom launch permission settings for correct security settings, but this policy setting may be used in the short-term as an application compatibility deployment aid.\r\n\r\nDCOM servers added to this exemption list are only exempted if their custom launch permissions do not contain specific LocalLaunch, RemoteLaunch, LocalActivate, or RemoteActivate grant or deny entries for any users or groups. Also note, exemptions for DCOM Server Appids added to this list will apply to both 32-bit and 64-bit versions of the server if present.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dcom#admx-dcom-dcomactivationsecuritycheckexemptionlist"],"categoryId":"a57b27b6-48e0-42b2-812a-2be86c113a0c","categoryName":"Application Compatibility Settings","options":[{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckexemptionlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckexemptionlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckexemptionlist_dcom_lbl_actseccheckexemptionlist","displayName":"Add\\remove DCOM servers to the exemption list:","description":null,"helpText":"","infoUrls":[],"categoryId":"a57b27b6-48e0-42b2-812a-2be86c113a0c","categoryName":"Application Compatibility Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckexemptionlist_dcom_lbl_actseccheckexemptionlist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"a57b27b6-48e0-42b2-812a-2be86c113a0c","categoryName":"Application Compatibility Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckexemptionlist_dcom_lbl_actseccheckexemptionlist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"a57b27b6-48e0-42b2-812a-2be86c113a0c","categoryName":"Application Compatibility Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_desktop_nodesktop","displayName":"Hide and disable all items on the desktop","description":"Removes icons, shortcuts, and other default and user-defined items from the desktop, including Briefcase, Recycle Bin, Computer, and Network Locations.\n\nRemoving icons and shortcuts does not prevent the user from using another method to start the programs or opening the items they represent.\n\nAlso, see \"Items displayed in Places Bar\" in User Configuration\\Administrative Templates\\Windows Components\\Common Open File Dialog to remove the Desktop icon from the Places Bar. This will help prevent users from saving data to the Desktop.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-nodesktop"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_desktop_nodesktop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_desktop_nodesktop_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_devicecompat_deviceflags","displayName":"Device compatibility settings","description":"Changes behavior of Microsoft bus drivers to work with specific devices.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-devicecompat#admx-devicecompat-deviceflags"],"categoryId":"27087ae6-d02f-4b54-a143-6cde89c04989","categoryName":"Device and Driver Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_devicecompat_deviceflags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicecompat_deviceflags_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_devicecompat_drivershims","displayName":"Driver compatibility settings","description":"Changes behavior of 3rd-party drivers to work around incompatibilities introduced between OS versions.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-devicecompat#admx-devicecompat-drivershims"],"categoryId":"27087ae6-d02f-4b54-a143-6cde89c04989","categoryName":"Device and Driver Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_devicecompat_drivershims_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicecompat_drivershims_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceguard_configcipolicy","displayName":"Deploy App Control for Business","description":"Deploy Windows Defender Application Control\r\n\r\nThis policy setting lets you deploy a Code Integrity Policy to a machine to control what is allowed to run on that machine.\r\n\r\nIf you deploy a Code Integrity Policy, Windows will restrict what can run in both kernel mode and on the Windows Desktop based on the policy. To enable this policy the machine must be rebooted. \r\n\r\nThe file path must be either a UNC path (for example, \\\\ServerName\\ShareName\\SIPolicy.p7b), or a locally valid path (for example, C:\\FolderName\\SIPolicy.p7b). The local machine account (LOCAL SYSTEM) must have access permission to the policy file.\r\n \r\nIf using a signed and protected policy then disabling this policy setting doesn't remove the feature from the computer. Instead, you must either:\r\n\r\n 1) first update the policy to a non-protected policy and then disable the setting, or\r\n 2) disable the setting and then remove the policy from each computer, with a physically present user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceguard#admx-deviceguard-configcipolicy"],"categoryId":"909339a5-8f04-4fa2-8807-5d38c83ef547","categoryName":"Device Guard","options":[{"id":"device_vendor_msft_policy_config_admx_deviceguard_configcipolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceguard_configcipolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceguard_configcipolicy_configcipolicyfilepathtext","displayName":"Code Integrity Policy file path:","description":null,"helpText":"","infoUrls":[],"categoryId":"909339a5-8f04-4fa2-8807-5d38c83ef547","categoryName":"Device Guard","options":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_allowadmininstall","displayName":"Allow administrators to override Device Installation Restriction policies","description":"This policy setting allows you to determine whether members of the Administrators group can install and update the drivers for any device, regardless of other policy settings.\r\n\r\nIf you enable this policy setting, members of the Administrators group can use the Add Hardware wizard or the Update Driver wizard to install and update the drivers for any device. If you enable this policy setting on a remote desktop server, the policy setting affects redirection of the specified devices from a remote desktop client to the remote desktop server.\r\n\r\nIf you disable or do not configure this policy setting, members of the Administrators group are subject to all policy settings that restrict device installation.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-allowadmininstall"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_allowadmininstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_allowadmininstall_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext","displayName":"Display a custom message when installation is prevented by a policy setting","description":"This policy setting allows you to display a custom message to users in a notification when a device installation is attempted and a policy setting prevents the installation.\r\n\r\nIf you enable this policy setting, Windows displays the text you type in the Detail Text box when a policy setting prevents device installation.\r\n\r\nIf you disable or do not configure this policy setting, Windows displays a default message when a policy setting prevents device installation.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-deniedpolicy-detailtext"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext_deviceinstall_deniedpolicy_detailtext_text","displayName":"Detail Text","description":null,"helpText":"","infoUrls":[],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext","displayName":"Display a custom message title when device installation is prevented by a policy setting","description":"This policy setting allows you to display a custom message title in a notification when a device installation is attempted and a policy setting prevents the installation.\r\n\r\nIf you enable this policy setting, Windows displays the text you type in the Main Text box as the title text of a notification when a policy setting prevents device installation.\r\n\r\nIf you disable or do not configure this policy setting, Windows displays a default title in a notification when a policy setting prevents device installation.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-deniedpolicy-simpletext"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext_deviceinstall_deniedpolicy_simpletext_text","displayName":"Main Text","description":null,"helpText":"","infoUrls":[],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_installtimeout","displayName":"Configure device installation time-out","description":"This policy setting allows you to configure the number of seconds Windows waits for a device installation task to complete. \r\n\r\nIf you enable this policy setting, Windows waits for the number of seconds you specify before terminating the installation.\r\n\r\nIf you disable or do not configure this policy setting, Windows waits 240 seconds for a device installation task to complete before terminating the installation.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-installtimeout"],"categoryId":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","categoryName":"Device Installation","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_installtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_installtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_installtimeout_deviceinstall_installtimeout_time","displayName":"Device Installation Timeout (in seconds)","description":null,"helpText":"","infoUrls":[],"categoryId":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","categoryName":"Device Installation","options":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime","displayName":"Time (in seconds) to force reboot when required for policy changes to take effect","description":"This policy setting establishes the amount of time (in seconds) that the system will wait to reboot in order to enforce a change in device installation restriction policies.\r\n\r\nIf you enable this policy setting, set the amount of seconds you want the system to wait until a reboot.\r\n\r\nIf you disable or do not configure this policy setting, the system does not force a reboot.\r\n\r\nNote: If no reboot is forced, the device installation restriction right will not take effect until the system is restarted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-policy-reboottime"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime_deviceinstall_policy_reboottime_time","displayName":"Reboot Timeout (in seconds)","description":null,"helpText":"","infoUrls":[],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_removable_deny","displayName":"Prevent installation of removable devices","description":"This policy setting allows you to prevent Windows from installing removable devices. A device is considered removable when the driver for the device to which it is connected indicates that the device is removable. For example, a Universal Serial Bus (USB) device is reported to be removable by the drivers for the USB hub to which the device is connected. This policy setting takes precedence over any other policy setting that allows Windows to install a device.\r\n\r\nIf you enable this policy setting, Windows is prevented from installing removable devices and existing removable devices cannot have their drivers updated. If you enable this policy setting on a remote desktop server, the policy setting affects redirection of removable devices from a remote desktop client to the remote desktop server.\r\n\r\nIf you disable or do not configure this policy setting, Windows can install and update device drivers for removable devices as allowed or prevented by other policy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-removable-deny"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_removable_deny_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_removable_deny_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_systemrestore","displayName":"Prevent creation of a system restore point during device activity that would normally prompt creation of a restore point","description":"This policy setting allows you to prevent Windows from creating a system restore point during device activity that would normally prompt Windows to create a system restore point. Windows normally creates restore points for certain driver activity, such as the installation of an unsigned driver. A system restore point enables you to more easily restore your system to its state before the activity. \r\n\r\nIf you enable this policy setting, Windows does not create a system restore point when one would normally be created.\r\n\r\nIf you disable or do not configure this policy setting, Windows creates a system restore point as it normally would.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-systemrestore"],"categoryId":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","categoryName":"Device Installation","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_systemrestore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_systemrestore_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser","displayName":"Allow non-administrators to install drivers for these device setup classes","description":"This policy setting specifies a list of device setup class GUIDs describing driver packages that non-administrator members of the built-in Users group may install on the system.\n\nIf you enable this policy setting, members of the Users group may install new drivers for the specified device setup classes. The drivers must be signed according to Windows Driver Signing Policy, or be signed by publishers already in the TrustedPublisher store.\n\nIf you disable or do not configure this policy setting, only members of the Administrators group are allowed to install new driver packages on the system.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-driverinstall-classes-allowuser"],"categoryId":"1943deba-33f7-4c3d-98c8-6b5319ec98ab","categoryName":"Driver Installation","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser_driverinstall_classes_allowuser_list","displayName":"Allow Users to install driver packages for these classes:","description":"","helpText":"","infoUrls":[],"categoryId":"1943deba-33f7-4c3d-98c8-6b5319ec98ab","categoryName":"Driver Installation","options":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_deviceinstall_balloontips","displayName":"Turn off \"Found New Hardware\" balloons during device installation","description":"This policy setting allows you to turn off \"Found New Hardware\" balloons during device installation.\r\n\r\nIf you enable this policy setting, \"Found New Hardware\" balloons do not appear while a device is being installed.\r\n\r\nIf you disable or do not configure this policy setting, \"Found New Hardware\" balloons appear while a device is being installed, unless the driver for the device suppresses the balloons.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-devicesetup#admx-devicesetup-deviceinstall-balloontips"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_devicesetup_deviceinstall_balloontips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_deviceinstall_balloontips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration","displayName":"Specify search order for device driver source locations","description":"This policy setting allows you to specify the order in which Windows searches source locations for device drivers. \r\n\r\nIf you enable this policy setting, you can select whether Windows searches for drivers on Windows Update unconditionally, only if necessary, or not at all.\r\n\r\nNote that searching always implies that Windows will attempt to search Windows Update exactly one time. With this setting, Windows will not continually search for updates. This setting is used to ensure that the best software will be found for the device, even if the network is temporarily available.\r\n\r\nIf the setting for searching only if needed is specified, then Windows will search for a driver only if a driver is not locally available on the system.\r\n\r\nIf you disable or do not configure this policy setting, members of the Administrators group can determine the priority order in which Windows searches source locations for device drivers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-devicesetup#admx-devicesetup-driversearchplaces-searchorderconfiguration"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown","displayName":"Select search order:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown_1","displayName":"Always search Windows Update","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown_2","displayName":"Search Windows Update only if needed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown_0","displayName":"Do not search Windows Update","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dfs_dfsdiscoverdc","displayName":"Configure how often a DFS client discovers domain controllers","description":"This policy setting allows you to configure how often a Distributed File System (DFS) client attempts to discover domain controllers on a network. By default, a DFS client attempts to discover domain controllers every 15 minutes.\r\n\r\nIf you enable this policy setting, you can configure how often a DFS client attempts to discover domain controllers. This value is specified in minutes.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 15 minutes applies.\r\n\r\nNote: The minimum value you can select is 15 minutes. If you try to set this setting to a value less than 15 minutes, the default value of 15 minutes is applied.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dfs#admx-dfs-dfsdiscoverdc"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_dfs_dfsdiscoverdc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dfs_dfsdiscoverdc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dfs_dfsdiscoverdc_dfsdiscoverdialog","displayName":"Time in minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_digitallocker_digitalx_diableapplication_titletext_2","displayName":"Do not allow Digital Locker to run","description":"Specifies whether Digital Locker can run.\r\n\r\nDigital Locker is a dedicated download manager associated with Windows Marketplace and a feature of Windows that can be used to manage and download products acquired and stored in the user's Windows Marketplace Digital Locker.\r\n\r\nIf you enable this setting, Digital Locker will not run.\r\n\r\nIf you disable or do not configure this setting, Digital Locker can be run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-digitallocker#admx-digitallocker-digitalx-diableapplication-titletext-2"],"categoryId":"1dabc7da-bdf8-4c60-95de-427a4b2cb6bf","categoryName":"Digital Locker","options":[{"id":"device_vendor_msft_policy_config_admx_digitallocker_digitalx_diableapplication_titletext_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_digitallocker_digitalx_diableapplication_titletext_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy","displayName":"Disk Diagnostic: Configure custom alert text","description":"This policy setting substitutes custom alert text in the disk diagnostic message shown to users when a disk reports a S.M.A.R.T. fault. \r\n\r\nIf you enable this policy setting, Windows displays custom alert text in the disk diagnostic message. The custom text may not exceed 512 characters. \r\n\r\nIf you disable or do not configure this policy setting, Windows displays the default alert text in the disk diagnostic message. \r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately. \r\n\r\nThis policy setting only takes effect if the Disk Diagnostic scenario policy setting is enabled or not configured and the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console. \r\n\r\nNote: For Windows Server systems, this policy setting applies only if the Desktop Experience optional component is installed and the Remote Desktop Services role is not installed. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskdiagnostic#admx-diskdiagnostic-dfdalertpolicy"],"categoryId":"e3ca94a7-e506-4133-8fae-41931dc863a5","categoryName":"Disk Diagnostic","options":[{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy_dfdalertpolicytitle","displayName":"Custom alert text","description":null,"helpText":"","infoUrls":[],"categoryId":"e3ca94a7-e506-4133-8fae-41931dc863a5","categoryName":"Disk Diagnostic","options":null},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_wdiscenarioexecutionpolicy","displayName":"Disk Diagnostic: Configure execution level","description":"This policy setting determines the execution level for S.M.A.R.T.-based disk diagnostics. \r\n\r\nSelf-Monitoring And Reporting Technology (S.M.A.R.T.) is a standard mechanism for storage devices to report faults to Windows. A disk that reports a S.M.A.R.T. fault may need to be repaired or replaced. The Diagnostic Policy Service (DPS) detects and logs S.M.A.R.T. faults to the event log when they occur. \r\n\r\nIf you enable this policy setting, the DPS also warns users of S.M.A.R.T. faults and guides them through backup and recovery to minimize potential data loss. \r\n\r\nIf you disable this policy, S.M.A.R.T. faults are still detected and logged, but no corrective action is taken. \r\n\r\nIf you do not configure this policy setting, the DPS enables S.M.A.R.T. fault resolution by default. \r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured. \r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately. \r\n\r\nThis policy setting takes effect only when the DPS is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console. \r\n\r\nNote: For Windows Server systems, this policy setting applies only if the Desktop Experience optional component is installed and the Remote Desktop Services role is not installed. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskdiagnostic#admx-diskdiagnostic-wdiscenarioexecutionpolicy"],"categoryId":"e3ca94a7-e506-4133-8fae-41931dc863a5","categoryName":"Disk Diagnostic","options":[{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_disknvcache_bootresumepolicy","displayName":"Turn off boot and resume optimizations","description":"This policy setting turns off the boot and resume optimizations for the hybrid hard disks in the system.\r\n\r\nIf you enable this policy setting, the system does not use the non-volatile (NV) cache to optimize boot and resume.\r\n\r\nIf you disable this policy setting, the system uses the NV cache to achieve faster boot and resume. The system determines the data that will be stored in the NV cache to optimize boot and resume. The required data is stored in the NV cache during shutdown and hibernate, respectively. This might cause a slight increase in the time taken for shutdown and hibernate.\r\n\r\nIf you do not configure this policy setting, the default behavior is observed and the NV cache is used for boot and resume optimizations.\r\n\r\nNote: This policy setting is applicable only if the NV cache feature is on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-disknvcache#admx-disknvcache-bootresumepolicy"],"categoryId":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","categoryName":"Disk NV Cache","options":[{"id":"device_vendor_msft_policy_config_admx_disknvcache_bootresumepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_disknvcache_bootresumepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_disknvcache_cachepowermodepolicy","displayName":"Turn off cache power mode","description":"This policy setting turns off power save mode on the hybrid hard disks in the system.\r\n\r\nIf you enable this policy setting, the hard disks are not put into NV cache power save mode and no power savings are achieved.\r\n\r\nIf you disable this policy setting, the hard disks are put into an NV cache power saving mode. In this mode, the system tries to save power by aggressively spinning down the disk.\r\n\r\nIf you do not configure this policy setting, the default behavior is to allow the hybrid hard disks to be in power save mode.\r\n\r\nNote: This policy setting is applicable only if the NV cache feature is on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-disknvcache#admx-disknvcache-cachepowermodepolicy"],"categoryId":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","categoryName":"Disk NV Cache","options":[{"id":"device_vendor_msft_policy_config_admx_disknvcache_cachepowermodepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_disknvcache_cachepowermodepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_disknvcache_featureoffpolicy","displayName":"Turn off non-volatile cache feature","description":"This policy setting turns off all support for the non-volatile (NV) cache on all hybrid hard disks in the system. To check if you have hybrid hard disks in the system, from Device Manager, right-click the disk drive and select Properties. The NV cache can be used to optimize boot and resume by reading data from the cache while the disks are spinning up. The NV cache can also be used to reduce the power consumption of the system by keeping the disks spun down while satisfying reads and writes from the cache.\r\n\r\nIf you enable this policy setting, the system will not manage the NV cache and will not enable NV cache power saving mode.\r\n\r\nIf you disable this policy setting, the system will manage the NV cache on the disks if the other policy settings for the NV cache are appropriately configured.\r\n\r\nNote: This policy setting will take effect on next boot.\r\n\r\nIf you do not configure this policy setting, the default behavior is to turn on support for the NV cache.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-disknvcache#admx-disknvcache-featureoffpolicy"],"categoryId":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","categoryName":"Disk NV Cache","options":[{"id":"device_vendor_msft_policy_config_admx_disknvcache_featureoffpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_disknvcache_featureoffpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_disknvcache_solidstatepolicy","displayName":"Turn off solid state mode","description":"This policy setting turns off the solid state mode for the hybrid hard disks. \r\n\r\nIf you enable this policy setting, frequently written files such as the file system metadata and registry may not be stored in the NV cache.\r\n\r\nIf you disable this policy setting, the system will store frequently written data into the non-volatile (NV) cache. This allows the system to exclusively run out of the NV cache and power down the disk for longer periods to save power. Note that this can cause increased wear of the NV cache.\r\n\r\nIf you do not configure this policy setting, the default behavior of the system is observed and frequently written files will be stored in the NV cache.\r\n\r\nNote: This policy setting is applicable only if the NV cache feature is on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-disknvcache#admx-disknvcache-solidstatepolicy"],"categoryId":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","categoryName":"Disk NV Cache","options":[{"id":"device_vendor_msft_policy_config_admx_disknvcache_solidstatepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_disknvcache_solidstatepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_enable","displayName":"Enable disk quotas","description":"This policy setting turns on and turns off disk quota management on all NTFS volumes of the computer, and prevents users from changing the setting.\r\n\r\nIf you enable this policy setting, disk quota management is turned on, and users cannot turn it off.\r\n\r\nIf you disable the policy setting, disk quota management is turned off, and users cannot turn it on.\r\n\r\nIf this policy setting is not configured, disk quota management is turned off by default, but administrators can turn it on.\r\n\r\nTo prevent users from changing the setting while a setting is in effect, the system disables the \"Enable quota management\" option on the Quota tab of NTFS volumes.\r\n\r\nNote: This policy setting turns on disk quota management but does not establish or enforce a particular disk quota limit. To specify a disk quota limit, use the \"Default quota limit and warning level\" policy setting. Otherwise, the system uses the physical space on the volume as the quota limit.\r\n\r\nNote: To turn on or turn off disk quota management without specifying a setting, in My Computer, right-click the name of an NTFS volume, click Properties, click the Quota tab, and then click \"Enable quota management.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskquota#admx-diskquota-dq-enable"],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_enable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_enable_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_enforce","displayName":"Enforce disk quota limit","description":"This policy setting determines whether disk quota limits are enforced and prevents users from changing the setting.\r\n\r\nIf you enable this policy setting, disk quota limits are enforced. If you disable this policy setting, disk quota limits are not enforced. When you enable or disable this policy setting, the system disables the \"Deny disk space to users exceeding quota limit\" option on the Quota tab so administrators cannot make changes while the setting is in effect.\r\n\r\nIf you do not configure this policy setting, the disk quota limit is not enforced by default, but administrators can change the setting.\r\n\r\nEnforcement is optional. When users reach an enforced disk quota limit, the system responds as though the physical space on the volume were exhausted. When users reach an unenforced limit, their status in the Quota Entries window changes, but they can continue to write to the volume as long as physical space is available.\r\n\r\nNote: This policy setting overrides user settings that enable or disable quota enforcement on their volumes.\r\n\r\nNote: To specify a disk quota limit, use the \"Default quota limit and warning level\" policy setting. Otherwise, the system uses the physical space on the volume as the quota limit.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskquota#admx-diskquota-dq-enforce"],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_enforce_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_enforce_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit","displayName":"Specify default quota limit and warning level","description":"This policy setting specifies the default disk quota limit and warning level for new users of the volume.\r\n\r\nThis policy setting determines how much disk space can be used by each user on each of the NTFS file system volumes on a computer. It also specifies the warning level, the point at which the user's status in the Quota Entries window changes to indicate that the user is approaching the disk quota limit.\r\n\r\nThis setting overrides new users’ settings for the disk quota limit and warning level on their volumes, and it disables the corresponding options in the \"Select the default quota limit for new users of this volume\" section on the Quota tab.\r\n\r\nThis policy setting applies to all new users as soon as they write to the volume. It does not affect disk quota limits for current users, or affect customized limits and warning levels set for particular users (on the Quota tab in Volume Properties).\r\n\r\nIf you disable or do not configure this policy setting, the disk space available to users is not limited. The disk quota management feature uses the physical space on each volume as its quota limit and warning level.\r\n\r\nWhen you select a limit, remember that the same limit applies to all users on all volumes, regardless of actual volume size. Be sure to set the limit and warning level so that it is reasonable for the range of volumes in the group.\r\n\r\nThis policy setting is effective only when disk quota management is enabled on the volume. Also, if disk quotas are not enforced, users can exceed the quota limit you set. When users reach the quota limit, their status in the Quota Entries window changes, but users can continue to write to the volume.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskquota#admx-diskquota-dq-limit"],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits","displayName":"Units","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_1","displayName":"KB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_2","displayName":"MB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_3","displayName":"GB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_4","displayName":"TB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_5","displayName":"PB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_6","displayName":"EB","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitvalue","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits","displayName":"Units","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits_1","displayName":"KB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits_2","displayName":"MB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits_3","displayName":"GB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits_4","displayName":"TB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits_5","displayName":"PB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits_6","displayName":"EB","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdvalue","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_logeventoverlimit","displayName":"Log event when quota limit is exceeded","description":"This policy setting determines whether the system records an event in the local Application log when users reach their disk quota limit on a volume, and prevents users from changing the logging setting.\r\n\r\nIf you enable this policy setting, the system records an event when the user reaches their limit. If you disable this policy setting, no event is recorded. Also, when you enable or disable this policy setting, the system disables the \"Log event when a user exceeds their quota limit\" option on the Quota tab, so administrators cannot change the setting while a setting is in effect.\r\n\r\nIf you do not configure this policy setting, no events are recorded, but administrators can use the Quota tab option to change the setting.\r\n\r\nThis policy setting is independent of the enforcement policy settings for disk quotas. As a result, you can direct the system to log an event, regardless of whether or not you choose to enforce the disk quota limit.\r\n\r\nAlso, this policy setting does not affect the Quota Entries window on the Quota tab. Even without the logged event, users can detect that they have reached their limit, because their status in the Quota Entries window changes.\r\n\r\nNote: To find the logging option, in My Computer, right-click the name of an NTFS file system volume, click Properties, and then click the Quota tab.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskquota#admx-diskquota-dq-logeventoverlimit"],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_logeventoverlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_logeventoverlimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_logeventoverthreshold","displayName":"Log event when quota warning level is exceeded","description":"This policy setting determines whether the system records an event in the Application log when users reach their disk quota warning level on a volume.\r\n\r\nIf you enable this policy setting, the system records an event. If you disable this policy setting, no event is recorded. When you enable or disable this policy setting, the system disables the corresponding \"Log event when a user exceeds their warning level\" option on the Quota tab so that administrators cannot change logging while a policy setting is in effect.\r\n\r\nIf you do not configure this policy setting, no event is recorded, but administrators can use the Quota tab option to change the logging setting.\r\n\r\nThis policy setting does not affect the Quota Entries window on the Quota tab. Even without the logged event, users can detect that they have reached their warning level because their status in the Quota Entries window changes.\r\n\r\nNote: To find the logging option, in My Computer, right-click the name of an NTFS file system volume, click Properties, and then click the Quota tab.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskquota#admx-diskquota-dq-logeventoverthreshold"],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_logeventoverthreshold_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_logeventoverthreshold_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_removablemedia","displayName":"Apply policy to removable media","description":"This policy setting extends the disk quota policies in this folder to NTFS file system volumes on removable media.\r\n\r\nIf you disable or do not configure this policy setting, the disk quota policies established in this folder apply to fixed-media NTFS volumes only. Note: When this policy setting is applied, the computer will apply the disk quota to both fixed and removable media.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskquota#admx-diskquota-dq-removablemedia"],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_removablemedia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_removablemedia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_distributedlinktracking_dlt_allowdomainmode","displayName":"Allow Distributed Link Tracking clients to use domain resources","description":"Specifies that Distributed Link Tracking clients in this domain may use the Distributed Link Tracking (DLT) server, which runs on domain controllers. The DLT client enables programs to track linked files that are moved within an NTFS volume, to another NTFS volume on the same computer, or to an NTFS volume on another computer. The DLT client can more reliably track links when allowed to use the DLT server. This policy should not be set unless the DLT server is running on all domain controllers in the domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-distributedlinktracking#admx-distributedlinktracking-dlt-allowdomainmode"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_distributedlinktracking_dlt_allowdomainmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_distributedlinktracking_dlt_allowdomainmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_allowfqdnnetbiosqueries","displayName":"Allow NetBT queries for fully qualified domain names","description":"Specifies that NetBIOS over TCP/IP (NetBT) queries are issued for fully qualified domain names. \r\n\r\nIf you enable this policy setting, NetBT queries will be issued for multi-label and fully qualified domain names such as \"www.example.com\" in addition to single-label names. \r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, NetBT queries will only be issued for single-label names such as \"example\" and not for multi-label and fully qualified domain names.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-allowfqdnnetbiosqueries"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_allowfqdnnetbiosqueries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_allowfqdnnetbiosqueries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_appendtomultilabelname","displayName":"Allow DNS suffix appending to unqualified multi-label name queries","description":"Specifies that computers may attach suffixes to an unqualified multi-label name before sending subsequent DNS queries if the original name query fails.\r\n\r\nA name containing dots, but not dot-terminated, is called an unqualified multi-label name, for example \"server.corp\" is an unqualified multi-label name. The name \"server.corp.contoso.com.\" is an example of a fully qualified name because it contains a terminating dot.\r\n\r\nFor example, if attaching suffixes is allowed, an unqualified multi-label name query for \"server.corp\" will be queried by the DNS client first. If the query succeeds, the response is returned to the client. If the query fails, the unqualified multi-label name is appended with DNS suffixes. These suffixes can be derived from a combination of the local DNS client's primary domain suffix, a connection-specific domain suffix, and a DNS suffix search list.\r\n\r\nIf attaching suffixes is allowed, and a DNS client with a primary domain suffix of \"contoso.com\" performs a query for \"server.corp\" the DNS client will send a query for \"server.corp\" first, and then a query for \"server.corp.contoso.com.\" second if the first query fails.\r\n\r\nIf you enable this policy setting, suffixes are allowed to be appended to an unqualified multi-label name if the original name query fails.\r\n\r\nIf you disable this policy setting, no suffixes are appended to unqualified multi-label name queries if the original name query fails.\r\n\r\nIf you do not configure this policy setting, computers will use their local DNS client settings to determine the query behavior for unqualified multi-label names.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-appendtomultilabelname"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_appendtomultilabelname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_appendtomultilabelname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domain","displayName":"Connection-specific DNS suffix","description":"Specifies a connection-specific DNS suffix. This policy setting supersedes local connection-specific DNS suffixes, and those configured using DHCP.\r\n\r\nTo use this policy setting, click Enabled, and then enter a string value representing the DNS suffix.\r\n\r\nIf you enable this policy setting, the DNS suffix that you enter will be applied to all network connections used by computers that receive this policy setting.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers will use the local or DHCP supplied connection specific DNS suffix, if configured.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-domain"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domain_dns_domainlabel","displayName":"DNS suffix:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel","displayName":"Primary DNS suffix devolution level","description":"Specifies if the devolution level that DNS clients will use if they perform primary DNS suffix devolution during the name resolution process.\r\n\r\nWith devolution, a DNS client creates queries by appending a single-label, unqualified domain name with the parent suffix of the primary DNS suffix name, and the parent of that suffix, and so on, stopping if the name is successfully resolved or at a level determined by devolution settings. Devolution can be used when a user or application submits a query for a single-label domain name.\r\n\r\nThe DNS client appends DNS suffixes to the single-label, unqualified domain name based on the state of the Append primary and connection specific DNS suffixes radio button and Append parent suffixes of the primary DNS suffix check box on the DNS tab in Advanced TCP/IP Settings for the Internet Protocol (TCP/IP) Properties dialog box.\r\n\r\nDevolution is not enabled if a global suffix search list is configured using Group Policy.\r\n\r\nIf a global suffix search list is not configured, and the Append primary and connection specific DNS suffixes radio button is selected, the DNS client appends the following names to a single-label name when it sends DNS queries:\r\n\r\nThe primary DNS suffix, as specified on the Computer Name tab of the System control panel.\r\n\r\nEach connection-specific DNS suffix, assigned either through DHCP or specified in the DNS suffix for this connection box on the DNS tab in the Advanced TCP/IP Settings dialog box for each connection.\r\n\r\nFor example, when a user submits a query for a single-label name such as \"example,\" the DNS client attaches a suffix such as \"microsoft.com\" resulting in the query \"example.microsoft.com,\" before sending the query to a DNS server.\r\n\r\nIf a DNS suffix search list is not specified, the DNS client attaches the primary DNS suffix to a single-label name. If this query fails, the connection-specific DNS suffix is attached for a new query. If none of these queries are resolved, the client devolves the primary DNS suffix of the computer (drops the leftmost label of the primary DNS suffix), attaches this devolved primary DNS suffix to the single-label name, and submits this new query to a DNS server.\r\n\r\nFor example, if the primary DNS suffix ooo.aaa.microsoft.com is attached to the non-dot-terminated single-label name \"example,\" and the DNS query for example.ooo.aaa.microsoft.com fails, the DNS client devolves the primary DNS suffix (drops the leftmost label) till the specified devolution level, and submits a query for example.aaa.microsoft.com. If this query fails, the primary DNS suffix is devolved further if it is under specified devolution level and the query example.microsoft.com is submitted. If this query fails, devolution continues if it is under specified devolution level and the query example.microsoft.com is submitted, corresponding to a devolution level of two. The primary DNS suffix cannot be devolved beyond a devolution level of two. The devolution level can be configured using this policy setting. The default devolution level is two.\r\n\r\nIf you enable this policy setting and DNS devolution is also enabled, DNS clients use the DNS devolution level that you specify.\r\n\r\nIf this policy setting is disabled, or if this policy setting is not configured, DNS clients use the default devolution level of two provided that DNS devolution is enabled.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-domainnamedevolutionlevel"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel_dns_domainnamedevolutionlevellabel","displayName":"Set the primary DNS suffix devolution level","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnencoding","displayName":"Turn off IDN encoding","description":"Specifies whether the DNS client should convert internationalized domain names (IDNs) to Punycode when the computer is on non-domain networks with no WINS servers configured.\r\n\r\nIf this policy setting is enabled, IDNs are not converted to Punycode.\r\n\r\nIf this policy setting is disabled, or if this policy setting is not configured, IDNs are converted to Punycode when the computer is on non-domain networks with no WINS servers configured.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-idnencoding"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnencoding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnencoding_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnmapping","displayName":"IDN mapping","description":"Specifies whether the DNS client should convert internationalized domain names (IDNs) to the Nameprep form, a canonical Unicode representation of the string.\r\n\r\nIf this policy setting is enabled, IDNs are converted to the Nameprep form.\r\n\r\nIf this policy setting is disabled, or if this policy setting is not configured, IDNs are not converted to the Nameprep form.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-idnmapping"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnmapping_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnmapping_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_nameserver","displayName":"DNS servers","description":"Defines the DNS servers to which a computer sends queries when it attempts to resolve names. This policy setting supersedes the list of DNS servers configured locally and those configured using DHCP. \r\n\r\nTo use this policy setting, click Enabled, and then enter a space-delimited list of IP addresses in the available field. To use this policy setting, you must enter at least one IP address.\r\n\r\nIf you enable this policy setting, the list of DNS servers is applied to all network connections used by computers that receive this policy setting. \r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers will use the local or DHCP supplied list of DNS servers, if configured.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-nameserver"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_nameserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_nameserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_nameserver_dns_nameserverlabel","displayName":"IP addresses:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_preferlocalresponsesoverlowerorderdns","displayName":"Prefer link local responses over DNS when received over a network with higher precedence","description":"Specifies that responses from link local name resolution protocols received over a network interface that is higher in the binding order are preferred over DNS responses from network interfaces lower in the binding order. Examples of link local name resolution protocols include link local multicast name resolution (LLMNR) and NetBIOS over TCP/IP (NetBT).\r\n\r\nIf you enable this policy setting, responses from link local protocols will be preferred over DNS responses if the local responses are from a network with a higher binding order.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, then DNS responses from networks lower in the binding order will be preferred over responses from link local protocols received from networks higher in the binding order.\r\n\r\nNote: This policy setting is applicable only if the turn off smart multi-homed name resolution policy setting is disabled or not configured.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-preferlocalresponsesoverlowerorderdns"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_preferlocalresponsesoverlowerorderdns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_preferlocalresponsesoverlowerorderdns_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_primarydnssuffix","displayName":"Primary DNS suffix","description":"Specifies the primary DNS suffix used by computers in DNS name registration and DNS name resolution.\r\n\r\nTo use this policy setting, click Enabled and enter the entire primary DNS suffix you want to assign. For example: microsoft.com.\r\n\r\nImportant: In order for changes to this policy setting to be applied on computers that receive it, you must restart Windows.\r\n\r\nIf you enable this policy setting, it supersedes the primary DNS suffix configured in the DNS Suffix and NetBIOS Computer Name dialog box using the System control panel.\r\n\r\nYou can use this policy setting to prevent users, including local administrators, from changing the primary DNS suffix.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, each computer uses its local primary DNS suffix, which is usually the DNS name of Active Directory domain to which it is joined.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-primarydnssuffix"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_primarydnssuffix_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_primarydnssuffix_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_primarydnssuffix_dns_primarydnssuffixbox","displayName":"Enter a primary DNS suffix:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registeradaptername","displayName":"Register DNS records with connection-specific DNS suffix","description":"Specifies if a computer performing dynamic DNS registration will register A and PTR resource records with a concatenation of its computer name and a connection-specific DNS suffix, in addition to registering these records with a concatenation of its computer name and the primary DNS suffix.\r\n\r\nBy default, a DNS client performing dynamic DNS registration registers A and PTR resource records with a concatenation of its computer name and the primary DNS suffix. For example, a computer name of mycomputer and a primary DNS suffix of microsoft.com will be registered as: mycomputer.microsoft.com.\r\n\r\nIf you enable this policy setting, a computer will register A and PTR resource records with its connection-specific DNS suffix, in addition to the primary DNS suffix. This applies to all network connections used by computers that receive this policy setting.\r\n\r\nFor example, with a computer name of mycomputer, a primary DNS suffix of microsoft.com, and a connection specific DNS suffix of VPNconnection, a computer will register A and PTR resource records for mycomputer.VPNconnection and mycomputer.microsoft.com when this policy setting is enabled.\r\n\r\nImportant: This policy setting is ignored on a DNS client computer if dynamic DNS registration is disabled.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, a DNS client computer will not register any A and PTR resource records using a connection-specific DNS suffix.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registeradaptername"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registeradaptername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registeradaptername_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup","displayName":"Register PTR records","description":"Specifies if DNS client computers will register PTR resource records.\r\n\r\nBy default, DNS clients configured to perform dynamic DNS registration will attempt to register PTR resource record only if they successfully registered the corresponding A resource record.\r\n\r\nIf you enable this policy setting, registration of PTR records will be determined by the option that you choose under Register PTR records.\r\n\r\nTo use this policy setting, click Enabled, and then select one of the following options from the drop-down list:\r\n\r\nDo not register: Computers will not attempt to register PTR resource records.\r\n\r\nRegister: Computers will attempt to register PTR resource records even if registration of the corresponding A records was not successful.\r\n\r\nRegister only if A record registration succeeds: Computers will attempt to register PTR resource records only if registration of the corresponding A records was successful.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers will use locally configured settings.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registerreverselookup"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup_dns_registerreverselookup_box","displayName":"Register PTR records:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup_dns_registerreverselookup_box_2","displayName":"Register only if A record registration succeeds","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup_dns_registerreverselookup_box_1","displayName":"Register","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup_dns_registerreverselookup_box_0","displayName":"Do not register","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationenabled","displayName":"Dynamic update","description":"Specifies if DNS dynamic update is enabled. Computers configured for DNS dynamic update automatically register and update their DNS resource records with a DNS server.\r\n\r\nIf you enable this policy setting, or you do not configure this policy setting, computers will attempt to use dynamic DNS registration on all network connections that have connection-specific dynamic DNS registration enabled. For a dynamic DNS registration to be enabled on a network connection, the connection-specific configuration must allow dynamic DNS registration, and this policy setting must not be disabled.\r\n\r\nIf you disable this policy setting, computers may not use dynamic DNS registration for any of their network connections, regardless of the configuration for individual network connections.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registrationenabled"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationoverwritesinconflict","displayName":"Replace addresses in conflicts","description":"Specifies whether dynamic updates should overwrite existing resource records that contain conflicting IP addresses.\r\n\r\nThis policy setting is designed for computers that register address (A) resource records in DNS zones that do not use Secure Dynamic Updates. Secure Dynamic Update preserves ownership of resource records and does not allow a DNS client to overwrite records that are registered by other computers.\r\n\r\nDuring dynamic update of resource records in a zone that does not use Secure Dynamic Updates, an A resource record might exist that associates the client's host name with an IP address different than the one currently in use by the client. By default, the DNS client attempts to replace the existing A resource record with an A resource record that has the client's current IP address.\r\n\r\nIf you enable this policy setting or if you do not configure this policy setting, DNS clients maintain their default behavior and will attempt to replace conflicting A resource records during dynamic update.\r\n\r\nIf you disable this policy setting, existing A resource records that contain conflicting IP addresses will not be replaced during a dynamic update, and an error will be recorded in Event Viewer.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registrationoverwritesinconflict"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationoverwritesinconflict_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationoverwritesinconflict_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationrefreshinterval","displayName":"Registration refresh interval","description":"Specifies the interval used by DNS clients to refresh registration of A and PTR resource. This policy setting only applies to computers performing dynamic DNS updates.\r\n\r\nComputers configured to perform dynamic DNS registration of A and PTR resource records periodically reregister their records with DNS servers, even if the record has not changed. This reregistration is required to indicate to DNS servers that records are current and should not be automatically removed (scavenged) when a DNS server is configured to delete stale records.\r\n\r\nWarning: If record scavenging is enabled on the zone, the value of this policy setting should never be longer than the value of the DNS zone refresh interval. Configuring the registration refresh interval to be longer than the refresh interval of the DNS zone might result in the undesired deletion of A and PTR resource records.\r\n\r\nTo specify the registration refresh interval, click Enabled and then enter a value of 1800 or greater. The value that you specify is the number of seconds to use for the registration refresh interval. For example, 1800 seconds is 30 minutes.\r\n\r\nIf you enable this policy setting, registration refresh interval that you specify will be applied to all network connections used by computers that receive this policy setting.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers will use the local or DHCP supplied setting. By default, client computers configured with a static IP address attempt to update their DNS resource records once every 24 hours and DHCP clients will attempt to update their DNS resource records when a DHCP lease is granted or renewed.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registrationrefreshinterval"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationrefreshinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationrefreshinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationrefreshinterval_dns_registrationrefreshintervallabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationttl","displayName":"TTL value for A and PTR records","description":"\r\nSpecifies the value of the time to live (TTL) field in A and PTR resource records that are registered by computers to which this policy setting is applied.\r\n\r\nTo specify the TTL, click Enabled and then enter a value in seconds (for example, 900 is 15 minutes).\r\n\r\nIf you enable this policy setting, the TTL value that you specify will be applied to DNS resource records registered for all network connections used by computers that receive this policy setting.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers will use the TTL settings specified in DNS. By default, the TTL is 1200 seconds (20 minutes).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registrationttl"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationttl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationttl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationttl_dns_registrationttllabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_searchlist","displayName":"DNS suffix search list","description":"Specifies the DNS suffixes to attach to an unqualified single-label name before submission of a DNS query for that name.\r\n\r\nAn unqualified single-label name contains no dots. The name \"example\" is a single-label name. This is different from a fully qualified domain name such as \"example.microsoft.com.\"\r\n\r\nClient computers that receive this policy setting will attach one or more suffixes to DNS queries for a single-label name. For example, a DNS query for the single-label name \"example\" will be modified to \"example.microsoft.com\" before sending the query to a DNS server if this policy setting is enabled with a suffix of \"microsoft.com.\"\r\n\r\nTo use this policy setting, click Enabled, and then enter a string value representing the DNS suffixes that should be appended to single-label names. You must specify at least one suffix. Use a comma-delimited string, such as \"microsoft.com,serverua.microsoft.com,office.microsoft.com\" to specify multiple suffixes.\r\n\r\nIf you enable this policy setting, one DNS suffix is attached at a time for each query. If a query is unsuccessful, a new DNS suffix is added in place of the failed suffix, and this new query is submitted. The values are used in the order they appear in the string, starting with the leftmost value and proceeding to the right until a query is successful or all suffixes are tried.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, the primary DNS suffix and network connection-specific DNS suffixes are appended to the unqualified queries.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-searchlist"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_searchlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_searchlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_searchlist_dns_searchlistlabel","displayName":"DNS Suffixes:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartmultihomednameresolution","displayName":"Turn off smart multi-homed name resolution","description":"Specifies that a multi-homed DNS client should optimize name resolution across networks. The setting improves performance by issuing parallel DNS, link local multicast name resolution (LLMNR) and NetBIOS over TCP/IP (NetBT) queries across all networks. In the event that multiple positive responses are received, the network binding order is used to determine which response to accept.\r\n\r\nIf you enable this policy setting, the DNS client will not perform any optimizations. DNS queries will be issued across all networks first. LLMNR queries will be issued if the DNS queries fail, followed by NetBT queries if LLMNR queries fail.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, name resolution will be optimized when issuing DNS, LLMNR and NetBT queries.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-smartmultihomednameresolution"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartmultihomednameresolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartmultihomednameresolution_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartprotocolreorder","displayName":"Turn off smart protocol reordering","description":"Specifies that the DNS client should prefer responses from link local name resolution protocols on non-domain networks over DNS responses when issuing queries for flat names. Examples of link local name resolution protocols include link local multicast name resolution (LLMNR) and NetBIOS over TCP/IP (NetBT).\r\n\r\nIf you enable this policy setting, the DNS client will prefer DNS responses, followed by LLMNR, followed by NetBT for all networks. \r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, the DNS client will prefer link local responses for flat name queries on non-domain networks. \r\n\r\nNote: This policy setting is applicable only if the turn off smart multi-homed name resolution policy setting is disabled or not configured.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-smartprotocolreorder"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartprotocolreorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartprotocolreorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel","displayName":"Update security level","description":"Specifies the security level for dynamic DNS updates.\r\n\r\nTo use this policy setting, click Enabled and then select one of the following values:\r\n\r\nUnsecure followed by secure - computers send secure dynamic updates only when nonsecure dynamic updates are refused.\r\n\r\nOnly unsecure - computers send only nonsecure dynamic updates.\r\n\r\nOnly secure - computers send only secure dynamic updates.\r\n\r\nIf you enable this policy setting, computers that attempt to send dynamic DNS updates will use the security level that you specify in this policy setting.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers will use local settings. By default, DNS clients attempt to use unsecured dynamic update first. If an unsecured update is refused, clients try to use secure update.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-updatesecuritylevel"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box","displayName":"Update security level:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box_256","displayName":"Only secure","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box_16","displayName":"Only unsecure","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box_0","displayName":"Unsecure followed by secure","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatetopleveldomainzones","displayName":"Update top level domain zones","description":"Specifies if computers may send dynamic updates to zones with a single label name. These zones are also known as top-level domain zones, for example: \"com.\"\r\n\r\nBy default, a DNS client that is configured to perform dynamic DNS update will update the DNS zone that is authoritative for its DNS resource records unless the authoritative zone is a top-level domain or root zone.\r\n\r\nIf you enable this policy setting, computers send dynamic updates to any zone that is authoritative for the resource records that the computer needs to update, except the root zone.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers do not send dynamic updates to the root zone or top-level domain zones that are authoritative for the resource records that the computer needs to update.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-updatetopleveldomainzones"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatetopleveldomainzones_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatetopleveldomainzones_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_usedomainnamedevolution","displayName":"Primary DNS suffix devolution","description":"Specifies if the DNS client performs primary DNS suffix devolution during the name resolution process.\r\n\r\nWith devolution, a DNS client creates queries by appending a single-label, unqualified domain name with the parent suffix of the primary DNS suffix name, and the parent of that suffix, and so on, stopping if the name is successfully resolved or at a level determined by devolution settings. Devolution can be used when a user or application submits a query for a single-label domain name.\r\n\r\nThe DNS client appends DNS suffixes to the single-label, unqualified domain name based on the state of the Append primary and connection specific DNS suffixes radio button and Append parent suffixes of the primary DNS suffix check box on the DNS tab in Advanced TCP/IP Settings for the Internet Protocol (TCP/IP) Properties dialog box.\r\n\r\nDevolution is not enabled if a global suffix search list is configured using Group Policy.\r\n\r\nIf a global suffix search list is not configured, and the Append primary and connection specific DNS suffixes radio button is selected, the DNS client appends the following names to a single-label name when it sends DNS queries:\r\n\r\nThe primary DNS suffix, as specified on the Computer Name tab of the System control panel.\r\n\r\nEach connection-specific DNS suffix, assigned either through DHCP or specified in the DNS suffix for this connection box on the DNS tab in the Advanced TCP/IP Settings dialog box for each connection.\r\n\r\nFor example, when a user submits a query for a single-label name such as \"example,\" the DNS client attaches a suffix such as \"microsoft.com\" resulting in the query \"example.microsoft.com,\" before sending the query to a DNS server.\r\n\r\nIf a DNS suffix search list is not specified, the DNS client attaches the primary DNS suffix to a single-label name. If this query fails, the connection-specific DNS suffix is attached for a new query. If none of these queries are resolved, the client devolves the primary DNS suffix of the computer (drops the leftmost label of the primary DNS suffix), attaches this devolved primary DNS suffix to the single-label name, and submits this new query to a DNS server.\r\n\r\nFor example, if the primary DNS suffix ooo.aaa.microsoft.com is attached to the non-dot-terminated single-label name \"example,\" and the DNS query for example.ooo.aaa.microsoft.com fails, the DNS client devolves the primary DNS suffix (drops the leftmost label) till the specified devolution level, and submits a query for example.aaa.microsoft.com. If this query fails, the primary DNS suffix is devolved further if it is under specified devolution level and the query example.microsoft.com is submitted. If this query fails, devolution continues if it is under specified devolution level and the query example.microsoft.com is submitted, corresponding to a devolution level of two. The primary DNS suffix cannot be devolved beyond a devolution level of two. The devolution level can be configured using the primary DNS suffix devolution level policy setting. The default devolution level is two.\r\n\r\nIf you enable this policy setting, or if you do not configure this policy setting, DNS clients attempt to resolve single-label names using concatenations of the single-label name to be resolved and the devolved primary DNS suffix.\r\n\r\nIf you disable this policy setting, DNS clients do not attempt to resolve names that are concatenations of the single-label name to be resolved and the devolved primary DNS suffix.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-usedomainnamedevolution"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_usedomainnamedevolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_usedomainnamedevolution_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_turn_off_multicast","displayName":"Turn off multicast name resolution","description":"Specifies that link local multicast name resolution (LLMNR) is disabled on client computers.\r\n\r\nLLMNR is a secondary name resolution protocol. With LLMNR, queries are sent using multicast over a local network link on a single subnet from a client computer to another client computer on the same subnet that also has LLMNR enabled. LLMNR does not require a DNS server or DNS client configuration, and provides name resolution in scenarios in which conventional DNS name resolution is not possible.\r\n\r\nIf you enable this policy setting, LLMNR will be disabled on all available network adapters on the client computer.\r\n\r\nIf you disable this policy setting, or you do not configure this policy setting, LLMNR will be enabled on all available network adapters.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-turn-off-multicast"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_turn_off_multicast_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_turn_off_multicast_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2","displayName":"Specify a default color","description":"This policy setting controls the default color for window frames when the user does not specify a color. \r\n\r\nIf you enable this policy setting and specify a default color, this color is used in glass window frames, if the user does not specify a color. \r\n\r\nIf you disable or do not configure this policy setting, the default internal color is used, if the user does not specify a color. \r\n\r\nNote: This policy setting can be used in conjunction with the \"Prevent color changes of window frames\" setting, to enforce a specific color for window frames that cannot be changed by users.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dwm#admx-dwm-dwmdefaultcolorizationcolor-2"],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":[{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_dwmdefaultcolorizationcoloralpha","displayName":"Alpha","description":null,"helpText":"","infoUrls":[],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_dwmdefaultcolorizationcolorblue","displayName":"Blue","description":null,"helpText":"","infoUrls":[],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_dwmdefaultcolorizationcolorgreen","displayName":"Green","description":null,"helpText":"","infoUrls":[],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_dwmdefaultcolorizationcolorred","displayName":"Red","description":null,"helpText":"","infoUrls":[],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdisallowanimations_2","displayName":"Do not allow window animations","description":"This policy setting controls the appearance of window animations such as those found when restoring, minimizing, and maximizing windows. \r\n\r\nIf you enable this policy setting, window animations are turned off. \r\n\r\nIf you disable or do not configure this policy setting, window animations are turned on. \r\n\r\nChanging this policy setting requires a logoff for it to be applied.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dwm#admx-dwm-dwmdisallowanimations-2"],"categoryId":"d52dd970-febb-4891-8eb7-1c8616cfb6cb","categoryName":"Desktop Window Manager","options":[{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdisallowanimations_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdisallowanimations_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdisallowcolorizationcolorchanges_2","displayName":"Do not allow color changes","description":"This policy setting controls the ability to change the color of window frames. \r\n\r\nIf you enable this policy setting, you prevent users from changing the default window frame color. \r\n\r\nIf you disable or do not configure this policy setting, you allow users to change the default window frame color. \r\n\r\nNote: This policy setting can be used in conjunction with the \"Specify a default color for window frames\" policy setting, to enforce a specific color for window frames that cannot be changed by users.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dwm#admx-dwm-dwmdisallowcolorizationcolorchanges-2"],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":[{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdisallowcolorizationcolorchanges_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdisallowcolorizationcolorchanges_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_encryptfilesonmove_noencryptonmove","displayName":"Do not automatically encrypt files moved to encrypted folders","description":"This policy setting prevents File Explorer from encrypting files that are moved to an encrypted folder.\r\n\r\nIf you enable this policy setting, File Explorer will not automatically encrypt files that are moved to an encrypted folder.\r\n\r\nIf you disable or do not configure this policy setting, File Explorer automatically encrypts files that are moved to an encrypted folder.\r\n\r\nThis setting applies only to files moved within a volume. When files are moved to other volumes, or if you create a new file in an encrypted folder, File Explorer encrypts those files automatically.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-encryptfilesonmove#admx-encryptfilesonmove-noencryptonmove"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_encryptfilesonmove_noencryptonmove_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_encryptfilesonmove_noencryptonmove_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedenstordevices","displayName":"Configure list of Enhanced Storage devices usable on your computer","description":"This policy setting allows you to configure a list of Enhanced Storage devices by manufacturer and product ID that are usable on your computer.\r\n\r\nIf you enable this policy setting, only Enhanced Storage devices that contain a manufacturer and product ID specified in this policy are usable on your computer.\r\n\r\nIf you disable or do not configure this policy setting, all Enhanced Storage devices are usable on your computer.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-enhancedstorage#admx-enhancedstorage-approvedenstordevices"],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedenstordevices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedenstordevices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedenstordevices_approvedenstordevices_list","displayName":"Usable Enhanced Storage Devices:","description":null,"helpText":"","infoUrls":[],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedsilos","displayName":"Configure list of IEEE 1667 silos usable on your computer","description":"This policy setting allows you to create a list of IEEE 1667 silos, compliant with the Institute of Electrical and Electronics Engineers, Inc. (IEEE) 1667 specification, that are usable on your computer.\r\n\r\nIf you enable this policy setting, only IEEE 1667 silos that match a silo type identifier specified in this policy are usable on your computer.\r\n\r\nIf you disable or do not configure this policy setting, all IEEE 1667 silos on Enhanced Storage devices are usable on your computer.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-enhancedstorage#admx-enhancedstorage-approvedsilos"],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedsilos_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedsilos_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedsilos_approvedsilos_list","displayName":"Usable IEEE 1667 Silo Type Identifiers:","description":null,"helpText":"","infoUrls":[],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_disablepasswordauthentication","displayName":"Do not allow password authentication of Enhanced Storage devices","description":"This policy setting configures whether or not a password can be used to unlock an Enhanced Storage device.\r\n\r\nIf you enable this policy setting, a password cannot be used to unlock an Enhanced Storage device.\r\n\r\nIf you disable or do not configure this policy setting, a password can be used to unlock an Enhanced Storage device.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-enhancedstorage#admx-enhancedstorage-disablepasswordauthentication"],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_disablepasswordauthentication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_disablepasswordauthentication_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_disallowlegacydiskdevices","displayName":"Do not allow non-Enhanced Storage removable devices","description":"This policy setting configures whether or not non-Enhanced Storage removable devices are allowed on your computer.\r\n\r\nIf you enable this policy setting, non-Enhanced Storage removable devices are not allowed on your computer.\r\n\r\nIf you disable or do not configure this policy setting, non-Enhanced Storage removable devices are allowed on your computer.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-enhancedstorage#admx-enhancedstorage-disallowlegacydiskdevices"],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_disallowlegacydiskdevices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_disallowlegacydiskdevices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_lockdeviceonmachinelock","displayName":"Lock Enhanced Storage when the computer is locked","description":"This policy setting locks Enhanced Storage devices when the computer is locked.\r\n\r\nThis policy setting is supported in Windows Server SKUs only.\r\n\r\nIf you enable this policy setting, the Enhanced Storage device remains locked when the computer is locked.\r\n\r\nIf you disable or do not configure this policy setting, the Enhanced Storage device state is not changed when the computer is locked.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-enhancedstorage#admx-enhancedstorage-lockdeviceonmachinelock"],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_lockdeviceonmachinelock_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_lockdeviceonmachinelock_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_roothubconnectedenstordevices","displayName":"Allow only USB root hub connected Enhanced Storage devices","description":"This policy setting configures whether or not only USB root hub connected Enhanced Storage devices are allowed. Allowing only root hub connected Enhanced Storage devices minimizes the risk of an unauthorized USB device reading data on an Enhanced Storage device.\r\n\r\nIf you enable this policy setting, only USB root hub connected Enhanced Storage devices are allowed.\r\n\r\nIf you disable or do not configure this policy setting, USB Enhanced Storage devices connected to both USB root hubs and non-root hubs will be allowed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-enhancedstorage#admx-enhancedstorage-roothubconnectedenstordevices"],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_roothubconnectedenstordevices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_roothubconnectedenstordevices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef","displayName":"Default application reporting settings","description":"This policy setting controls whether errors in general applications are included in reports when Windows Error Reporting is enabled.\r\n\r\nIf you enable this policy setting, you can instruct Windows Error Reporting in the Default pull-down menu to report either all application errors (the default setting), or no application errors.\r\n\r\nIf the Report all errors in Microsoft applications check box is filled, all errors in Microsoft applications are reported, regardless of the setting in the Default pull-down menu. When the Report all errors in Windows check box is filled, all errors in Windows applications are reported, regardless of the setting in the Default dropdown list. The Windows applications category is a subset of Microsoft applications.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable Windows Error Reporting in Control Panel. The default setting in Control Panel is Upload all applications.\r\n\r\nThis policy setting is ignored if the Configure Error Reporting policy setting is disabled or not configured.\r\n\r\nFor related information, see the Configure Error Reporting and Report Operating System Errors policy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-allornonedef"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonedef_list","displayName":"Default:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonedef_list_1","displayName":"Report all application errors","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonedef_list_0","displayName":"Do not report any application errors","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornoneincms_chk","displayName":"Report all errors in Microsoft applications.","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornoneincms_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornoneincms_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonewincomp_chk","displayName":"Report all errors in Windows components.","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonewincomp_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonewincomp_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex","displayName":"List of applications to never report errors for","description":"This policy setting controls Windows Error Reporting behavior for errors in general applications when Windows Error Reporting is turned on.\r\n\r\nIf you enable this policy setting, you can create a list of applications that are never included in error reports. To create a list of applications for which Windows Error Reporting never reports errors, click Show under the Exclude errors for applications on this list setting, and then add or remove applications from the list of application file names in the Show Contents dialog box (example: notepad.exe). File names must always include the .exe file name extension. Errors that are generated by applications in this list are not reported, even if the Default Application Reporting Settings policy setting is configured to report all application errors.\r\n\r\nIf this policy setting is enabled, the Exclude errors for applications on this list setting takes precedence. If an application is listed both in the List of applications to always report errors for policy setting, and in the exclusion list in this policy setting, the application is excluded from error reporting. You can also use the exclusion list in this policy setting to exclude specific Microsoft applications or parts of Windows if the check boxes for these categories are filled in the Default application reporting settings policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Default application reporting settings policy setting takes precedence.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-allornoneex"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex_pch_allornoneex_list","displayName":"Exclude errors for applications on this list:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc","displayName":"List of applications to always report errors for","description":"This policy setting specifies applications for which Windows Error Reporting should always report errors.\r\n\r\nTo create a list of applications for which Windows Error Reporting never reports errors, click Show under the Exclude errors for applications on this list setting, and then add or remove applications from the list of application file names in the Show Contents dialog box (example: notepad.exe). Errors that are generated by applications in this list are not reported, even if the Default Application Reporting Settings policy setting is configured to report all application errors.\r\n\r\nIf you enable this policy setting, you can create a list of applications that are always included in error reporting. To add applications to the list, click Show under the Report errors for applications on this list setting, and edit the list of application file names in the Show Contents dialog box. The file names must include the .exe file name extension (for example, notepad.exe). Errors that are generated by applications on this list are always reported, even if the Default dropdown in the Default application reporting policy setting is set to report no application errors.\r\n\r\nIf the Report all errors in Microsoft applications or Report all errors in Windows components check boxes in the Default Application Reporting policy setting are filled, Windows Error Reporting reports errors as if all applications in these categories were added to the list in this policy setting. (Note: The Microsoft applications category includes the Windows components category.)\r\n\r\nIf you disable this policy setting or do not configure it, the Default application reporting settings policy setting takes precedence.\r\n\r\nAlso see the \"Default Application Reporting\" and \"Application Exclusion List\" policies.\r\n\r\nThis setting will be ignored if the 'Configure Error Reporting' setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-allornoneinc"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc_pch_allornoneinc_list","displayName":"Report errors for applications on this list:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport","displayName":"Configure Error Reporting","description":"This policy setting configures how errors are reported to Microsoft, and what information is sent when Windows Error Reporting is enabled.\r\n\r\nThis policy setting does not enable or disable Windows Error Reporting. To turn Windows Error Reporting on or off, see the Turn off Windows Error Reporting policy setting in Computer Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings.\r\n\r\nImportant: If the Turn off Windows Error Reporting policy setting is not configured, then Control Panel settings for Windows Error Reporting override this policy setting.\r\n\r\nIf you enable this policy setting, the setting overrides any user changes made to Windows Error Reporting settings in Control Panel, and default values are applied for any Windows Error Reporting policy settings that are not configured (even if users have changed settings by using Control Panel). If you enable this policy setting, you can configure the following settings in the policy setting:\r\n\r\n- \"Do not display links to any Microsoft ‘More information’ websites\": Select this option if you do not want error dialog boxes to display links to Microsoft websites.\r\n\r\n- \"Do not collect additional files\": Select this option if you do not want additional files to be collected and included in error reports.\r\n\r\n- \"Do not collect additional computer data\": Select this if you do not want additional information about the computer to be collected and included in error reports.\r\n\r\n- \"Force queue mode for application errors\": Select this option if you do not want users to report errors. When this option is selected, errors are stored in a queue directory, and the next administrator to log on to the computer can send the error reports to Microsoft.\r\n\r\n- \"Corporate file path\": Type a UNC path to enable Corporate Error Reporting. All errors are stored at the specified location instead of being sent directly to Microsoft, and the next administrator to log onto the computer can send the error reports to Microsoft.\r\n\r\n- \"Replace instances of the word ‘Microsoft’ with\": You can specify text with which to customize your error report dialog boxes. The word \"Microsoft\" is replaced with the specified text.\r\n\r\nIf you do not configure this policy setting, users can change Windows Error Reporting settings in Control Panel. By default, these settings are Enable Reporting on computers that are running Windows XP, and Report to Queue on computers that are running Windows Server 2003.\r\n\r\nIf you disable this policy setting, configuration settings in the policy setting are left blank.\r\n\r\nSee related policy settings Display Error Notification (same folder as this policy setting), and Turn off Windows Error Reporting in Computer Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-configurereport"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_companytext_edit","displayName":"Replace instances of the word 'Microsoft' with:","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_dumppath_edit","displayName":"Corporate upload file path:","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_forceq_chk","displayName":"Force queue mode for application errors","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_forceq_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_forceq_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_noexternalurl_chk","displayName":"Do not display links to any Microsoft provided 'more information' web sites.","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_noexternalurl_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_noexternalurl_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_nofilecollect_chk","displayName":"Do not collect additional files","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_nofilecollect_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_nofilecollect_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_noleveltwo_chk","displayName":"Do not collect additional machine data","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_noleveltwo_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_noleveltwo_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_reportoperatingsystemfaults","displayName":"Report operating system errors","description":"This policy setting controls whether errors in the operating system are included Windows Error Reporting is enabled.\r\n\r\nIf you enable this policy setting, Windows Error Reporting includes operating system errors.\r\n\r\nIf you disable this policy setting, operating system errors are not included in error reports.\r\n\r\nIf you do not configure this policy setting, users can change this setting in Control Panel. By default, Windows Error Reporting settings in Control Panel are set to upload operating system errors.\r\n\r\nSee also the Configure Error Reporting policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-reportoperatingsystemfaults"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_reportoperatingsystemfaults_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_reportoperatingsystemfaults_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2","displayName":"Configure Report Archive","description":"This policy setting controls the behavior of the Windows Error Reporting archive.\r\n\r\nIf you enable this policy setting, you can configure Windows Error Reporting archiving behavior. If Archive behavior is set to Store all, all data collected for each error report is stored in the appropriate location. If Archive behavior is set to Store parameters only, only the minimum information required to check for an existing solution is stored. The Maximum number of reports to store setting determines how many reports are stored before older reports are automatically deleted.\r\n\r\nIf you disable or do not configure this policy setting, no Windows Error Reporting information is stored.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werarchive-2"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2_werarchivebehavior","displayName":"Archive behavior:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2_werarchivebehavior_2","displayName":"Store all","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2_werarchivebehavior_1","displayName":"Store parameters only","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2_wermaxarchivecount","displayName":"Maximum number of reports to store:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werautoapproveosdumps_2","displayName":"Automatically send memory dumps for OS-generated error reports","description":"This policy setting controls whether memory dumps in support of OS-generated error reports can be sent to Microsoft automatically. This policy does not apply to error reports generated by 3rd-party products, or additional data other than memory dumps.\r\n\r\nIf you enable or do not configure this policy setting, any memory dumps generated for error reports by Microsoft Windows are automatically uploaded, without notification to the user.\r\n\r\nIf you disable this policy setting, then all memory dumps are uploaded according to the default consent and notification settings.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werautoapproveosdumps-2"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werautoapproveosdumps_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werautoapproveosdumps_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_2","displayName":"Do not throttle additional data","description":"This policy setting determines whether Windows Error Reporting (WER) sends additional, second-level report data even if a CAB file containing data about the same event types has already been uploaded to the server.\r\n\r\nIf you enable this policy setting, WER does not throttle data; that is, WER uploads additional CAB files that can contain data about the same event types as an earlier uploaded report.\r\n\r\nIf you disable or do not configure this policy setting, WER throttles data by default; that is, WER does not upload more than one CAB file for a report that contains data about the same event types.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypassdatathrottling-2"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassnetworkcostthrottling_2","displayName":"Send data when on connected to a restricted/costed network","description":"This policy setting determines whether Windows Error Reporting (WER) checks for a network cost policy that restricts the amount of data that is sent over the network.\r\n\r\nIf you enable this policy setting, WER does not check for network cost policy restrictions, and transmits data even if network cost is restricted.\r\n\r\nIf you disable or do not configure this policy setting, WER does not send data, but will check the network cost policy again if the network profile is changed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypassnetworkcostthrottling-2"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassnetworkcostthrottling_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassnetworkcostthrottling_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypasspowerthrottling_2","displayName":"Send additional data when on battery power","description":"This policy setting determines whether Windows Error Reporting (WER) checks if the computer is running on battery power. By default, when a computer is running on battery power, WER only checks for solutions, but does not upload additional report data until the computer is connected to a more permanent power source.\r\n\r\nIf you enable this policy setting, WER does not determine whether the computer is running on battery power, but checks for solutions and uploads report data normally.\r\n\r\nIf you disable or do not configure this policy setting, WER checks for solutions while a computer is running on battery power, but does not upload report data until the computer is connected to a more permanent power source.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypasspowerthrottling-2"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypasspowerthrottling_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypasspowerthrottling_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer","displayName":"Configure Corporate Windows Error Reporting","description":"This policy setting specifies a corporate server to which Windows Error Reporting sends reports (if you do not want to send error reports to Microsoft).\r\n\r\nIf you enable this policy setting, you can specify the name or IP address of an error report destination server on your organization’s network. You can also select Connect using SSL to transmit error reports over a Secure Sockets Layer (SSL) connection, and specify a port number on the destination server for transmission.\r\n\r\nIf you disable or do not configure this policy setting, Windows Error Reporting sends error reports to Microsoft.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-wercer"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercercorporateportnumber","displayName":"Server port:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerserver","displayName":"Corporate server name:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_werceruploadonfreenetworksonly","displayName":"Only upload on free networks","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_werceruploadonfreenetworksonly_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_werceruploadonfreenetworksonly_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerusessl","displayName":"Connect using SSL","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerusessl_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerusessl_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werconsentoverride_2","displayName":"Ignore custom consent settings","description":"This policy setting determines the behavior of the Configure Default Consent setting in relation to custom consent settings.\r\n\r\nIf you enable this policy setting, the default consent levels of Windows Error Reporting always override any other consent policy setting.\r\n\r\nIf you disable or do not configure this policy setting, custom consent policy settings for error reporting determine the consent level for specified event types, and the default consent setting determines only the consent level of any other error reports.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werconsentoverride-2"],"categoryId":"184981d4-712b-425e-b0a3-93eac7fbd3ee","categoryName":"Consent","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werconsentoverride_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werconsentoverride_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2","displayName":"Configure Default consent","description":"This policy setting determines the default consent behavior of Windows Error Reporting.\r\n\r\nIf you enable this policy setting, you can set the default consent handling for error reports. The following list describes the Consent level settings that are available in the pull-down menu in this policy setting:\r\n\r\n- Always ask before sending data: Windows prompts users for consent to send reports.\r\n\r\n- Send parameters: Only the minimum data that is required to check for an existing solution is sent automatically, and Windows prompts users for consent to send any additional data that is requested by Microsoft.\r\n\r\n- Send parameters and safe additional data: the minimum data that is required to check for an existing solution, along with data which Windows has determined (within a high probability) does not contain personally-identifiable information is sent automatically, and Windows prompts the user for consent to send any additional data that is requested by Microsoft.\r\n\r\n- Send all data: any error reporting data requested by Microsoft is sent automatically.\r\n\r\nIf this policy setting is disabled or not configured, then the consent level defaults to the highest-privacy setting: Always ask before sending data.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werdefaultconsent-2"],"categoryId":"184981d4-712b-425e-b0a3-93eac7fbd3ee","categoryName":"Consent","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_werconsent","displayName":"Consent level","description":null,"helpText":"","infoUrls":[],"categoryId":"184981d4-712b-425e-b0a3-93eac7fbd3ee","categoryName":"Consent","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_werconsent_1","displayName":"Always ask before sending data","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_werconsent_2","displayName":"Send parameters","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_werconsent_3","displayName":"Send parameters and safe additional data","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_werconsent_4","displayName":"Send all data","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werexlusion_2","displayName":"List of applications to be excluded","description":"This policy setting limits Windows Error Reporting behavior for errors in general applications when Windows Error Reporting is turned on.\r\n\r\nIf you enable this policy setting, you can create a list of applications that are never included in error reports. To create a list of applications for which Windows Error Reporting never reports errors, click Show, and then add or remove applications from the list of application file names in the Show Contents dialog box (example: notepad.exe). File names must always include the .exe file name extension. To remove an application from the list, click the name, and then press DELETE. If this policy setting is enabled, the Exclude errors for applications on this list setting takes precedence.\r\n\r\nIf you disable or do not configure this policy setting, errors are reported on all Microsoft and Windows applications by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werexlusion-2"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werexlusion_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werexlusion_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werexlusion_2_werexlusionlist","displayName":"List of applications to be excluded","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wernologging_2","displayName":"Disable logging","description":"This policy setting controls whether Windows Error Reporting saves its own events and error messages to the system event log.\r\n\r\nIf you enable this policy setting, Windows Error Reporting events are not recorded in the system event log.\r\n\r\nIf you disable or do not configure this policy setting, Windows Error Reporting events and errors are logged to the system event log, as with other Windows-based programs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-wernologging-2"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_wernologging_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wernologging_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2","displayName":"Configure Report Queue","description":"This policy setting determines the behavior of the Windows Error Reporting report queue.\r\n\r\nIf you enable this policy setting, you can configure report queue behavior by using the controls in the policy setting. When the Queuing behavior pull-down list is set to Default, Windows determines, when a problem occurs, whether the report should be placed in the reporting queue, or the user should be prompted to send it immediately. When Queuing behavior is set to Always queue, all reports are added to the queue until the user is prompted to send the reports, or until the user sends problem reports by using the Solutions to Problems page in Control Panel. If Queuing behavior is set to Always queue for administrator, reports are queued until an administrator is prompted to send them, or until the administrator sends them by using the Solutions to Problems page in Control Panel.\r\n\r\nThe Maximum number of reports to queue setting determines how many reports can be queued before older reports are automatically deleted. The setting for Number of days between solution check reminders determines the interval time between the display of system notifications that remind the user to check for solutions to problems. A value of 0 disables the reminder.\r\n\r\nIf you disable or do not configure this policy setting, Windows Error Reporting reports are not queued, and users can only send reports at the time that a problem occurs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werqueue-2"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_wermaxqueuecount","displayName":"Maximum number of reports to queue:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_wermaxqueuesize","displayName":"Maximum size of the queue (MB):","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werminfreediskspace","displayName":"Minimum free disk space (MB):","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werqueuebehavior","displayName":"Queuing behavior:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werqueuebehavior_0","displayName":"Default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werqueuebehavior_1","displayName":"Always queue","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werqueuebehavior_2","displayName":"Always queue for administrator","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werupdatecheck","displayName":"Number of days between solution check reminders:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_forwarderresourceusage","displayName":"Configure forwarder resource usage","description":"This policy setting controls resource usage for the forwarder (source computer) by controlling the events/per second sent to the Event Collector.\r\n\r\nIf you enable this policy setting, you can control the volume of events sent to the Event Collector by the source computer. This may be required in high volume environments.\r\n\r\nIf you disable or do not configure this policy setting, forwarder resource usage is not specified.\r\n\r\nThis setting applies across all subscriptions for the forwarder (source computer).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventforwarding#admx-eventforwarding-forwarderresourceusage"],"categoryId":"c859dc1a-fdeb-4591-af97-79d078ee715b","categoryName":"Event Forwarding","options":[{"id":"device_vendor_msft_policy_config_admx_eventforwarding_forwarderresourceusage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_forwarderresourceusage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_forwarderresourceusage_maxforwardingrate","displayName":"The maximum forwarding rate ( events/sec ) allowed for the forwarder:","description":null,"helpText":"","infoUrls":[],"categoryId":"c859dc1a-fdeb-4591-af97-79d078ee715b","categoryName":"Event Forwarding","options":null},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager","displayName":"Configure target Subscription Manager","description":"This policy setting allows you to configure the server address, refresh interval, and issuer certificate authority (CA) of a target Subscription Manager.\r\n\r\nIf you enable this policy setting, you can configure the Source Computer to contact a specific FQDN (Fully Qualified Domain Name) or IP Address and request subscription specifics.\r\n\r\nUse the following syntax when using the HTTPS protocol:\r\nServer=https://:5986/wsman/SubscriptionManager/WEC,Refresh=,IssuerCA=. When using the HTTP protocol, use port 5985.\r\n\r\nIf you disable or do not configure this policy setting, the Event Collector computer will not be specified.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventforwarding#admx-eventforwarding-subscriptionmanager"],"categoryId":"c859dc1a-fdeb-4591-af97-79d078ee715b","categoryName":"Event Forwarding","options":[{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager_subscriptionmanager_listbox","displayName":"SubscriptionManagers","description":null,"helpText":"","infoUrls":[],"categoryId":"c859dc1a-fdeb-4591-af97-79d078ee715b","categoryName":"Event Forwarding","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_1","displayName":"Back up log automatically when full","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size and takes effect only if the \"Retain old events\" policy setting is enabled.\r\n\r\nIf you enable this policy setting and the \"Retain old events\" policy setting is enabled, the Event Log file is automatically closed and renamed when it is full. A new file is then started.\r\n\r\nIf you disable this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and old events are retained.\r\n\r\nIf you do not configure this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and the old events are retained.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-autobackup-1"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_2","displayName":"Back up log automatically when full","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size and takes effect only if the \"Retain old events\" policy setting is enabled.\r\n\r\nIf you enable this policy setting and the \"Retain old events\" policy setting is enabled, the Event Log file is automatically closed and renamed when it is full. A new file is then started.\r\n\r\nIf you disable this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and old events are retained.\r\n\r\nIf you do not configure this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and the old events are retained.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-autobackup-2"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_3","displayName":"Back up log automatically when full","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size and takes effect only if the \"Retain old events\" policy setting is enabled.\r\n\r\nIf you enable this policy setting and the \"Retain old events\" policy setting is enabled, the Event Log file is automatically closed and renamed when it is full. A new file is then started.\r\n\r\nIf you disable this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and old events are retained.\r\n\r\nIf you do not configure this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and the old events are retained.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-autobackup-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_4","displayName":"Back up log automatically when full","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size and takes effect only if the \"Retain old events\" policy setting is enabled.\r\n\r\nIf you enable this policy setting and the \"Retain old events\" policy setting is enabled, the Event Log file is automatically closed and renamed when it is full. A new file is then started.\r\n\r\nIf you disable this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and old events are retained.\r\n\r\nIf you do not configure this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and the old events are retained.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-autobackup-4"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1","displayName":"Configure log access","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string.\r\n\r\nIf you enable this policy setting, only those users matching the security descriptor can access the log.\r\n\r\nIf you disable or do not configure this policy setting, all authenticated users and system services can write, read, or clear this log.\r\n\r\nNote: If you enable this policy setting, some tools and APIs may ignore it. The same change should be made to the \"Configure log access (legacy)\" policy setting to enforce this change across all tools and APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-1"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_2","displayName":"Configure log access","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You cannot configure write permissions for this log. You must set both \"configure log access\" policy settings for this log in order to affect the both modern and legacy tools.\r\n\r\nIf you enable this policy setting, only those users whose security descriptor matches the configured specified value can access the log.\r\n\r\nIf you disable or do not configure this policy setting, only system software and administrators can read or clear this log.\r\n\r\nNote: If you enable this policy setting, some tools and APIs may ignore it. The same change should be made to the \"Configure log access (legacy)\" policy setting to enforce this change across all tools and APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-2"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_2_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_3","displayName":"Configure log access","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string.\r\n\r\nIf you enable this policy setting, only those users matching the security descriptor can access the log.\r\n\r\nIf you disable or do not configure this policy setting, all authenticated users and system services can write, read, or clear this log.\r\n\r\nNote: If you enable this policy setting, some tools and APIs may ignore it. The same change should be made to the \"Configure log access (legacy)\" policy setting to enforce this change across all tools and APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_3_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_4","displayName":"Configure log access","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You must set both \"configure log access\" policy settings for this log in order to affect the both modern and legacy tools.\r\n\r\nIf you enable this policy setting, only users whose security descriptor matches the configured value can access the log.\r\n\r\nIf you disable or do not configure this policy setting, only system software and administrators can write or clear this log, and any authenticated user can read events from it.\r\n\r\nNote: If you enable this policy setting, some tools and APIs may ignore it. The same change should be made to the \"Configure log access (legacy)\" policy setting to enforce this change across all tools and APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-4"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_4_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_5","displayName":"Configure log access (legacy)","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You must set both \"configure log access\" policy settings for this log in order to affect the both modern and legacy tools.\r\n\r\nIf you enable this policy setting, only those users matching the security descriptor can access the log.\r\n\r\nIf you disable this policy setting, all authenticated users and system services can write, read, or clear this log.\r\n\r\nIf you do not configure this policy setting, the previous policy setting configuration remains in effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-5"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_5_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_5_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_5_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6","displayName":"Configure log access (legacy)","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You cannot configure write permissions for this log.\r\n\r\nIf you enable this policy setting, only those users whose security descriptor matches the configured specified value can access the log.\r\n\r\nIf you disable this policy setting, only system software and administrators can read or clear this log.\r\n\r\nIf you do not configure this policy setting, the previous policy setting configuration remains in effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-6"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7","displayName":"Configure log access (legacy)","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You must set both \"configure log access\" policy settings for this log in order to affect the both modern and legacy tools.\r\n\r\nIf you enable this policy setting, only those users matching the security descriptor can access the log.\r\n\r\nIf you disable this policy setting, all authenticated users and system services can write, read, or clear this log.\r\n\r\nIf you do not configure this policy setting, the previous policy setting configuration remains in effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-7"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_8","displayName":"Configure log access (legacy)","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string.\r\n\r\nIf you enable this policy setting, only users whose security descriptor matches the configured value can access the log.\r\n\r\nIf you disable this policy setting, only system software and administrators can write or clear this log, and any authenticated user can read events from it.\r\n\r\nIf you do not configure this policy setting, the previous policy setting configuration remains in effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-8"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_8_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_8_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_2","displayName":"Control Event Log behavior when the log file reaches its maximum size","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size.\r\n\r\nIf you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost.\r\n\r\nIf you disable or do not configure this policy setting and a log file reaches its maximum size, new events overwrite old events.\r\n\r\nNote: Old events may or may not be retained according to the \"Backup log automatically when full\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-retention-2"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_3","displayName":"Control Event Log behavior when the log file reaches its maximum size","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size.\r\n\r\nIf you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost.\r\n\r\nIf you disable or do not configure this policy setting and a log file reaches its maximum size, new events overwrite old events.\r\n\r\nNote: Old events may or may not be retained according to the \"Backup log automatically when full\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-retention-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_4","displayName":"Control Event Log behavior when the log file reaches its maximum size","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size.\r\n\r\nIf you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost.\r\n\r\nIf you disable or do not configure this policy setting and a log file reaches its maximum size, new events overwrite old events.\r\n\r\nNote: Old events may or may not be retained according to the \"Backup log automatically when full\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-retention-4"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logenabled","displayName":"Turn on logging","description":"This policy setting turns on logging.\r\n\r\nIf you enable or do not configure this policy setting, then events can be written to this log.\r\n\r\nIf the policy setting is disabled, then no new events can be logged. Events can always be read from the log, regardless of this policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logenabled"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1","displayName":"Control the location of the log file","description":"This policy setting controls the location of the log file. The location of the file must be writable by the Event Log service and should only be accessible to administrators.\r\n\r\nIf you enable this policy setting, the Event Log uses the path specified in this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Event Log uses the folder %SYSTEMROOT%\\System32\\winevt\\Logs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logfilepath-1"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1_channel_logfilepath","displayName":"Log File Path","description":null,"helpText":"","infoUrls":[],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_2","displayName":"Control the location of the log file","description":"This policy setting controls the location of the log file. The location of the file must be writable by the Event Log service and should only be accessible to administrators.\r\n\r\nIf you enable this policy setting, the Event Log uses the path specified in this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Event Log uses the folder %SYSTEMROOT%\\System32\\winevt\\Logs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logfilepath-2"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_2_channel_logfilepath","displayName":"Log File Path","description":null,"helpText":"","infoUrls":[],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3","displayName":"Control the location of the log file","description":"This policy setting controls the location of the log file. The location of the file must be writable by the Event Log service and should only be accessible to administrators.\r\n\r\nIf you enable this policy setting, the Event Log uses the path specified in this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Event Log uses the folder %SYSTEMROOT%\\System32\\winevt\\Logs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logfilepath-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3_channel_logfilepath","displayName":"Log File Path","description":null,"helpText":"","infoUrls":[],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_4","displayName":"Control the location of the log file","description":"This policy setting controls the location of the log file. The location of the file must be writable by the Event Log service and should only be accessible to administrators.\r\n\r\nIf you enable this policy setting, the Event Log uses the path specified in this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Event Log uses the folder %SYSTEMROOT%\\System32\\winevt\\Logs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logfilepath-4"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_4_channel_logfilepath","displayName":"Log File Path","description":null,"helpText":"","infoUrls":[],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3","displayName":"Specify the maximum log file size (KB)","description":"This policy setting specifies the maximum size of the log file in kilobytes.\r\n\r\nIf you enable this policy setting, you can configure the maximum log file size to be between 1 megabyte (1024 kilobytes) and 2 terabytes (2147483647 kilobytes), in kilobyte increments.\r\n\r\nIf you disable or do not configure this policy setting, the maximum size of the log file will be set to the locally configured value. This value can be changed by the local administrator using the Log Properties dialog, and it defaults to 1 megabyte.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logmaxsize-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3_channel_logmaxsize","displayName":"Maximum Log Size (KB)","description":null,"helpText":"","infoUrls":[],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlogging_enableprotectedeventlogging","displayName":"Enable Protected Event Logging","description":"\r\nThis policy setting lets you configure Protected Event Logging.\r\n\r\nIf you enable this policy setting, components that support it will use the certificate you supply to encrypt potentially sensitive event log data before writing it to the event log. Data will be encrypted using the Cryptographic Message Syntax (CMS) standard and the public key you provide. You can use the Unprotect-CmsMessage PowerShell cmdlet to decrypt these encrypted messages, provided that you have access to the private key corresponding to the public key that they were encrypted with.\r\n\r\nIf you disable or do not configure this policy setting, components will not encrypt event log messages before writing them to the event log.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlogging#admx-eventlogging-enableprotectedeventlogging"],"categoryId":"75e080fb-3ed7-4a73-a6e0-eb93f0119d68","categoryName":"Event Logging","options":[{"id":"device_vendor_msft_policy_config_admx_eventlogging_enableprotectedeventlogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlogging_enableprotectedeventlogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlogging_enableprotectedeventlogging_encryptioncertificate","displayName":"Provide an encryption certificate to be used by Protected Event Logging. You may provide either:\n\n - The content of a base-64 encoded X.509 certificate\n - The thumbprint of a certificate that can be found in the Local Machine certificate store (usually deployed by PKI infrastructure)\n - The full path to a certificate (can be local, or a remote share)\n - The path to a directory containing a certificate or certificates (can be local, or a remote share)\n - The subject name of a certificate that can be found in the Local Machine certificate store (usually deployed by PKI infrastructure)\n\nThe resulting certificate must have 'Document Encryption' as an enhanced key usage (1.3.6.1.4.1.311.80.1), as well as either Data Encipherment or Key Encipherment key usages enabled.","description":null,"helpText":"","infoUrls":[],"categoryId":"75e080fb-3ed7-4a73-a6e0-eb93f0119d68","categoryName":"Event Logging","options":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogram","displayName":"Events.asp program","description":"This is the program that will be invoked when the user clicks the events.asp link.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventviewer#admx-eventviewer-eventviewer-redirectionprogram"],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":[{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogram_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogram_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogram_eventviewer_redirectionprogram","displayName":"Events.asp program","description":null,"helpText":"","infoUrls":[],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters","displayName":"Events.asp program command line parameters","description":"This specifies the command line parameters that will be passed to the events.asp program\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventviewer#admx-eventviewer-eventviewer-redirectionprogramcommandlineparameters"],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":[{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters_eventviewer_redirectionprogramcommandlineparameters","displayName":"Events.asp program command line parameters","description":null,"helpText":"","infoUrls":[],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionurl","displayName":"Events.asp URL","description":"This is the URL that will be passed to the Description area in the Event Properties dialog box. Change this value if you want to use a different Web server to handle event information requests.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventviewer#admx-eventviewer-eventviewer-redirectionurl"],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":[{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionurl_eventviewer_redirectionurl","displayName":"Events.asp URL","description":null,"helpText":"","infoUrls":[],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":null},{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl","displayName":"Set a support web page link","description":"Sets the target of the More Information link that will be displayed when the user attempts to run a program that is blocked by policy.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-explorer#admx-explorer-admininfourl"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl_admininfourl_textbox","displayName":"Support Web page URL","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_explorer_disableroamedprofileinit","displayName":"Do not reinitialize a pre-existing roamed user profile when it is loaded on a machine for the first time","description":"This policy setting allows administrators who have configured roaming profile in conjunction with Delete Cached Roaming Profile Group Policy setting to ensure that Explorer will not reinitialize default program associations and other settings to default values. \r\n\r\nIf you enable this policy setting on a machine that does not contain all programs installed in the same manner as it was on the machine on which the user had last logged on, unexpected behavior could occur. \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-explorer#admx-explorer-disableroamedprofileinit"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_explorer_disableroamedprofileinit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_explorer_disableroamedprofileinit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_hibernate","displayName":"Allow hibernate (S4) when starting from a Windows To Go workspace","description":"\r\n\r\nSpecifies whether the PC can use the hibernation sleep state (S4) when started from a Windows To Go workspace.\r\n\r\nIf you enable this setting, Windows, when started from a Windows To Go workspace, can hibernate the PC.\r\n\r\nIf you disable or don't configure this setting, Windows, when started from a Windows To Go workspace, can't hibernate the PC.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-externalboot#admx-externalboot-portableoperatingsystem-hibernate"],"categoryId":"68a3b82d-d1f4-422d-bfee-2168ec260ad7","categoryName":"Portable Operating System","options":[{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_hibernate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_hibernate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_launcher","displayName":"Windows To Go Default Startup Options","description":"\r\n\r\nThis policy setting controls whether the PC will boot to Windows To Go if a USB device containing a Windows To Go workspace is connected, and controls whether users can make changes using the Windows To Go Startup Options Control Panel item.\r\n\r\nIf you enable this setting, booting to Windows To Go when a USB device is connected will be enabled, and users will not be able to make changes using the Windows To Go Startup Options Control Panel item.\r\n\r\nIf you disable this setting, booting to Windows To Go when a USB device is connected will not be enabled unless a user configures the option manually in the BIOS or other boot order configuration.\r\n\r\nIf you do not configure this setting, users who are members of the Administrators group can make changes using the Windows To Go Startup Options Control Panel item.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-externalboot#admx-externalboot-portableoperatingsystem-launcher"],"categoryId":"68a3b82d-d1f4-422d-bfee-2168ec260ad7","categoryName":"Portable Operating System","options":[{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_launcher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_launcher_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_sleep","displayName":"Disallow standby sleep states (S1-S3) when starting from a Windows to Go workspace","description":"\r\n\r\nSpecifies whether the PC can use standby sleep states (S1-S3) when starting from a Windows To Go workspace.\r\n\r\nIf you enable this setting, Windows, when started from a Windows To Go workspace, can't use standby states to make the PC sleep.\r\n\r\nIf you disable or don't configure this setting, Windows, when started from a Windows To Go workspace, can use standby states to make the PC sleep.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-externalboot#admx-externalboot-portableoperatingsystem-sleep"],"categoryId":"68a3b82d-d1f4-422d-bfee-2168ec260ad7","categoryName":"Portable Operating System","options":[{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_sleep_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_sleep_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy","displayName":"Configure Corrupted File Recovery behavior","description":"This policy setting allows you to configure the recovery behavior for corrupted files to one of three states:\r\n\r\nRegular: Detection, troubleshooting, and recovery of corrupted files will automatically start with a minimal UI display. Windows will attempt to present you with a dialog box when a system restart is required. This is the default recovery behavior for corrupted files.\r\n\r\nSilent: Detection, troubleshooting, and recovery of corrupted files will automatically start with no UI. Windows will log an administrator event when a system restart is required. This behavior is recommended for headless operation.\r\n\r\nTroubleshooting Only: Detection and troubleshooting of corrupted files will automatically start with no UI. Recovery is not attempted automatically. Windows will log an administrator event with instructions if manual recovery is possible.\r\n\r\nIf you enable this setting, the recovery behavior for corrupted files will be set to either the regular (default), silent, or troubleshooting only state.\r\n\r\nIf you disable this setting, the recovery behavior for corrupted files will be disabled. No troubleshooting or resolution will be attempted.\r\n\r\nIf you do not configure this setting, the recovery behavior for corrupted files will be set to the regular recovery behavior.\r\n\r\nNo system or service restarts are required for changes to this policy to take immediate effect after a Group Policy refresh.\r\n\r\nNote: This policy setting will take effect only when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, system file recovery will not be attempted. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filerecovery#admx-filerecovery-wdiscenarioexecutionpolicy"],"categoryId":"736134cb-4d82-427a-97b7-d219ac6a22f0","categoryName":"Corrupted File Recovery","options":[{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"736134cb-4d82-427a-97b7-d219ac6a22f0","categoryName":"Corrupted File Recovery","options":[{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_1","displayName":"Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_2","displayName":"Regular","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_3","displayName":"Silent","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_fileservervssprovider_pol_encryptprotocol","displayName":"Allow or Disallow use of encryption to protect the RPC protocol messages between File Share Shadow Copy Provider running on application server and File Share Shadow Copy Agent running on the file servers.","description":"Determines whether the RPC protocol messagese used by VSS for SMB2 File Shares feature is enabled.\r\n\r\nVSS for SMB2 File Shares feature enables VSS aware backup applications to perform application consistent backup and restore of VSS aware applications storing data on SMB2 File Shares.\r\n\r\nBy default, the RPC protocol message between File Server VSS provider and File Server VSS Agent is signed but not encrypted. \r\n\r\nNote: To make changes to this setting effective, you must restart Volume Shadow Copy (VSS) Service .\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-fileservervssprovider#admx-fileservervssprovider-pol-encryptprotocol"],"categoryId":"d9f5ccc9-5180-43b7-9c81-89ac3364ce00","categoryName":"File Share Shadow Copy Provider","options":[{"id":"device_vendor_msft_policy_config_admx_fileservervssprovider_pol_encryptprotocol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_fileservervssprovider_pol_encryptprotocol_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_disablecompression","displayName":"Do not allow compression on all NTFS volumes","description":"Compression can add to the processing overhead of filesystem operations. Enabling this setting will prevent access to and creation of compressed files. \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-disablecompression"],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_disablecompression_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_disablecompression_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_disabledeletenotification","displayName":"Disable delete notifications on all volumes","description":"Delete notification is a feature that notifies the underlying storage device of clusters that are freed due to a file delete operation.\r\n\r\nA value of 0, the default, will enable delete notifications for all volumes. \r\nA value of 1 will disable delete notifications for all volumes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-disabledeletenotification"],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_disabledeletenotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_disabledeletenotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_disableencryption","displayName":"Do not allow encryption on all NTFS volumes","description":"Encryption can add to the processing overhead of filesystem operations. Enabling this setting will prevent access to and creation of encrypted files\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-disableencryption"],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_disableencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_disableencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_enablepagefileencryption","displayName":"Enable NTFS pagefile encryption","description":"Encrypting the page file prevents malicious users from reading data that has been paged to disk, but also adds processing overhead for filesystem operations. Enabling this setting will cause the page files to be encrypted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-enablepagefileencryption"],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_enablepagefileencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_enablepagefileencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_longpathsenabled","displayName":"Enable Win32 long paths","description":"Enabling Win32 long paths will allow manifested win32 applications and Windows Store applications to access paths beyond the normal 260 character limit per node on file systems that support it. Enabling this setting will cause the long paths to be accessible within the process.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-longpathsenabled"],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_longpathsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_longpathsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings","displayName":"Short name creation options","description":"These settings provide control over whether or not short names are generated during file creation. Some applications require short names for compatibility, but short names have a negative performance impact on the system.\r\n\r\nIf you enable short names on all volumes then short names will always be generated. If you disable them on all volumes then they will never be generated. If you set short name creation to be configurable on a per volume basis then an on-disk flag will determine whether or not short names are created on a given volume. If you disable short name creation on all data volumes then short names will only be generated for files created on the system volume.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-shortnamecreationsettings"],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_shortnamecreationsetting_levels","displayName":"Short name creation options","description":null,"helpText":"","infoUrls":[],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_shortnamecreationsetting_levels_0","displayName":"Enable on all volumes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_shortnamecreationsetting_levels_1","displayName":"Disable on all volumes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_shortnamecreationsetting_levels_2","displayName":"Enable / disable on a per volume basis","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_shortnamecreationsetting_levels_3","displayName":"Disable on all data volumes","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation","displayName":"Selectively allow the evaluation of a symbolic link","description":"Symbolic links can introduce vulnerabilities in certain applications. To mitigate this issue, you can selectively enable or disable the evaluation of these types of symbolic links:\r\n\r\nLocal Link to a Local Target\r\nLocal Link to a Remote Target\r\nRemote Link to Remote Target\r\nRemote Link to Local Target\r\n\r\nFor further information please refer to the Windows Help section\r\n\r\nNOTE: If this policy is Disabled or Not Configured, local administrators may select the types of symbolic links to be evaluated.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-symlinkevaluation"],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2l","displayName":"Local Link to Local Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2l_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2l_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2r","displayName":"Local Link to a Remote Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2r_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2r_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2l","displayName":"Remote Link to Local Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2l_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2l_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2r","displayName":"Remote Link to Remote Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2r_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2r_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_txfdeprecatedfunctionality","displayName":"Enable / disable TXF deprecated features","description":"TXF deprecated features included savepoints, secondary RM, miniversion and roll forward. Please enable it if you want to use the APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-txfdeprecatedfunctionality"],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_txfdeprecatedfunctionality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_txfdeprecatedfunctionality_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_folderredirection_localizexprelativepaths_2","displayName":"Use localized subfolder names when redirecting Start Menu and My Documents","description":"This policy setting allows the administrator to define whether Folder Redirection should use localized names for the All Programs, Startup, My Music, My Pictures, and My Videos subfolders when redirecting the parent Start Menu and legacy My Documents folder respectively.\r\n\r\nIf you enable this policy setting, Windows Vista, Windows 7, Windows 8, and Windows Server 2012 will use localized folder names for these subfolders when redirecting the Start Menu or legacy My Documents folder.\r\n\r\nIf you disable or not configure this policy setting, Windows Vista, Windows 7, Windows 8, and Windows Server 2012 will use the standard English names for these subfolders when redirecting the Start Menu or legacy My Documents folder.\r\n\r\nNote: This policy is valid only on Windows Vista, Windows 7, Windows 8, and Windows Server 2012 when it processes a legacy redirection policy already deployed for these folders in your existing localized environment.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-folderredirection#admx-folderredirection-localizexprelativepaths-2"],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_folderredirection_localizexprelativepaths_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_folderredirection_localizexprelativepaths_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_folderredirection_primarycomputer_fr_2","displayName":"Redirect folders on primary computers only","description":"This policy setting controls whether folders are redirected on a user's primary computers only. This policy setting is useful to improve logon performance and to increase security for user data on computers where the user might not want to download private data, such as on a meeting room computer or on a computer in a remote office.\r\n\r\nTo designate a user's primary computers, an administrator must use management software or a script to add primary computer attributes to the user's account in Active Directory Domain Services (AD DS). This policy setting also requires the Windows Server 2012 version of the Active Directory schema to function.\r\n\r\nIf you enable this policy setting and the user has redirected folders, such as the Documents and Pictures folders, the folders are redirected on the user's primary computer only.\r\n\r\nIf you disable or do not configure this policy setting and the user has redirected folders, the folders are redirected on every computer that the user logs on to.\r\n\r\nNote: If you enable this policy setting in Computer Configuration and User Configuration, the Computer Configuration policy setting takes precedence.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-folderredirection#admx-folderredirection-primarycomputer-fr-2"],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_folderredirection_primarycomputer_fr_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_folderredirection_primarycomputer_fr_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_fthsvc_wdiscenarioexecutionpolicy","displayName":"Configure Scenario Execution Level","description":"This policy setting permits or prohibits the Diagnostic Policy Service (DPS) from automatically resolving any heap corruption problems.\r\n\r\nIf you enable this policy setting, the DPS detects, troubleshoots, and attempts to resolve automatically any heap corruption problems.\r\n\r\nIf you disable this policy setting, Windows cannot detect, troubleshoot, and attempt to resolve automatically any heap corruption problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS enables Fault Tolerant Heap for resolution by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nThis policy setting takes effect only when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n\r\nNo system restart or service restart is required for this policy setting to take effect: changes take effect immediately.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-fthsvc#admx-fthsvc-wdiscenarioexecutionpolicy"],"categoryId":"476e0bfc-ddb6-4612-8446-bed86e875141","categoryName":"Fault Tolerant Heap","options":[{"id":"device_vendor_msft_policy_config_admx_fthsvc_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_fthsvc_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_blockuserinputmethodsforsignin","displayName":"Disallow copying of user input methods to the system account for sign-in","description":"\r\n This policy prevents automatic copying of user input methods to the system account for use on the sign-in screen. The user is restricted to the set of input methods that are enabled in the system account.\r\n\r\n Note this does not affect the availability of user input methods on the lock screen or with the UAC prompt.\r\n\r\n If the policy is Enabled, then the user will get input methods enabled for the system account on the sign-in page.\r\n\r\n If the policy is Disabled or Not Configured, then the user will be able to use input methods enabled for their user account on the sign-in page.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-blockuserinputmethodsforsignin"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_blockuserinputmethodsforsignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_blockuserinputmethodsforsignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_customlocalesnoselect_2","displayName":"Disallow selection of Custom Locales","description":"This policy setting prevents a user from selecting a supplemental custom locale as their user locale. The user is restricted to the set of locales that are installed with the operating system.\r\n\r\nThis does not affect the selection of replacement locales. To prevent the selection of replacement locales, adjust the permissions of the %windir%\\Globalization directory to prevent the installation of locales by unauthorized users.\r\n\r\nThe policy setting \"Restrict user locales\" can also be enabled to disallow selection of a custom locale, even if this policy setting is not configured.\r\n\r\nIf you enable this policy setting, the user cannot select a custom locale as their user locale, but they can still select a replacement locale if one is installed.\r\n\r\nIf you disable or do not configure this policy setting, the user can select a custom locale as their user locale.\r\n\r\nIf this policy setting is enabled at the machine level, it cannot be disabled by a per-user policy setting. If this policy setting is disabled at the machine level, the per-user policy setting will be ignored. If this policy setting is not configured at the machine level, restrictions will be based on per-user policy settings.\r\n\r\nTo set this policy setting on a per-user basis, make sure that you do not configure the per-machine policy setting.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-customlocalesnoselect-2"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_customlocalesnoselect_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_customlocalesnoselect_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_implicitdatacollectionoff_2","displayName":"Turn off automatic learning","description":"\r\n This policy setting turns off the automatic learning component of handwriting recognition personalization. \r\n\r\n\t\tAutomatic learning enables the collection and storage of text and ink written by the user in order to help adapt handwriting recognition to the vocabulary and handwriting style of the user. \r\n\r\n\t\tText that is collected includes all outgoing messages in Windows Mail, and MAPI enabled email clients, as well as URLs from the Internet Explorer browser history. The information that is stored includes word frequency and new words not already known to the handwriting recognition engines (for example, proper names and acronyms). Deleting email content or the browser history does not delete the stored personalization data. Ink entered through Input Panel is collected and stored. \r\n\r\n\t\tNote: Automatic learning of both text and ink might not be available for all languages, even when handwriting personalization is available. See Tablet PC Help for more information.\r\n\r\n\t\tIf you enable this policy setting, automatic learning stops and any stored data is deleted. Users cannot configure this setting in Control Panel.\r\n\r\n\t\tIf you disable this policy setting, automatic learning is turned on. Users cannot configure this policy setting in Control Panel. Collected data is only used for handwriting recognition, if handwriting personalization is turned on.\r\n\r\n\t\tIf you do not configure this policy, users can choose to enable or disable automatic learning either from the Handwriting tab in the Tablet Settings in Control Panel or from the opt-in dialog.\r\n\r\n\t\tThis policy setting is related to the \"Turn off handwriting personalization\" policy setting.\r\n\r\n\t\tNote: The amount of stored ink is limited to 50 MB and the amount of text information to approximately 5 MB. When these limits are reached and new data is collected, old data is deleted to make room for more recent data.\r\n\r\n\t\tNote: Handwriting personalization works only for Microsoft handwriting recognizers, and not with third-party recognizers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-implicitdatacollectionoff-2"],"categoryId":"9a79d480-8cb4-47b5-95c7-5da56eea5bb8","categoryName":"Handwriting personalization","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_implicitdatacollectionoff_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_implicitdatacollectionoff_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict","displayName":"Restrict system locales","description":"This policy setting restricts the permitted system locales to the specified list. If the list is empty, it locks the system locale to its current value. This policy setting does not change the existing system locale; however, the next time that an administrator attempts to change the computer's system locale, they will be restricted to the specified list.\r\n\r\nThe locale list is specified using language names, separated by a semicolon (;). For example, en-US is English (United States). Specifying \"en-US;en-CA\" would restrict the system locale to English (United States) and English (Canada).\r\n\r\nIf you enable this policy setting, administrators can select a system locale only from the specified system locale list.\r\n\r\nIf you disable or do not configure this policy setting, administrators can select any system locale shipped with the operating system.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-localesystemrestrict"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict_allowablesystemlocaletaglist","displayName":"System Locales","description":null,"helpText":"","infoUrls":[],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":null},{"id":"device_vendor_msft_policy_config_admx_globalization_localeuserrestrict_2","displayName":"Restrict user locales","description":"This policy setting restricts users on a computer to the specified list of user locales. If the list is empty, it locks all user locales to their current values. This policy setting does not change existing user locale settings; however, the next time a user attempts to change their user locale, their choices will be restricted to locales in this list.\r\n\r\nTo set this policy setting on a per-user basis, make sure that you do not configure the per-computer policy setting.\r\n\r\nThe locale list is specified using language tags, separated by a semicolon (;). For example, en-US is English (United States). Specifying \"en-CA;fr-CA\" would restrict the user locale to English (Canada) and French (Canada).\r\n\r\nIf you enable this policy setting, only locales in the specified locale list can be selected by users.\r\n\r\nIf you disable or do not configure this policy setting, users can select any locale installed on the computer, unless restricted by the \"Disallow selection of Custom Locales\" policy setting.\r\n\r\nIf this policy setting is enabled at the computer level, it cannot be disabled by a per-user policy. If this policy setting is disabled at the computer level, the per-user policy is ignored. If this policy setting is not configured at the computer level, restrictions are based on per-user policies.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-localeuserrestrict-2"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_localeuserrestrict_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_localeuserrestrict_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_localeuserrestrict_2_allowableuserlocaletaglist","displayName":"User Locales","description":null,"helpText":"","infoUrls":[],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage","displayName":"Restricts the UI language Windows uses for all logged users","description":"This policy setting restricts the Windows UI language for all users.\r\n\r\nThis is a policy setting for computers with more than one UI language installed.\r\n\r\nIf you enable this policy setting, the UI language of Windows menus and dialogs for systems with more than one language will follow the language specified by the administrator as the system UI languages. The UI language selected by the user will be ignored if it is different than any of the system UI languages.\r\n\r\nIf you disable or do not configure this policy setting, the user can specify which UI language is used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-lockmachineuilanguage"],"categoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","categoryName":"Regional and Language Options","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect","displayName":"Restrict users to the following language:","description":null,"helpText":"","infoUrls":[],"categoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","categoryName":"Regional and Language Options","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_en-us","displayName":"English","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_ja-jp","displayName":"Japanese","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_ko-kr","displayName":"Korean","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_de-de","displayName":"German","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_zh-cn","displayName":"Simplified Chinese","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_zh-tw","displayName":"Traditional Chinese (Taiwan)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_fr-fr","displayName":"French","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_es-es","displayName":"Spanish","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_it-it","displayName":"Italian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_sv-se","displayName":"Swedish","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_nl-nl","displayName":"Dutch","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_pt-br","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_fi-fi","displayName":"Finnish","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_nb-no","displayName":"Norwegian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_da-dk","displayName":"Danish","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_hu-hu","displayName":"Hungarian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_pl-pl","displayName":"Polish","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_ru-ru","displayName":"Russian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_cs-cz","displayName":"Czech","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_el-gr","displayName":"Greek","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_pt-pt","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_tr-tr","displayName":"Turkish","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_ar-sa","displayName":"Arabic","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_he-il","displayName":"Hebrew","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_sk-sk","displayName":"Slovak","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_sl-si","displayName":"Slovenian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_ro-ro","displayName":"Romanian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_hr-hr","displayName":"Croatian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_bg-bg","displayName":"Bulgarian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_et-ee","displayName":"Estonian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_lt-lt","displayName":"Lithuanian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_lv-lv","displayName":"Latvian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_th-th","displayName":"Thai","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_zh-hk","displayName":"Traditional Chinese (Hong Kong)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_sr-latn-cs","displayName":"Serbian (Latin)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_uk-ua","displayName":"Ukrainian","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_preventgeoidchange_2","displayName":"Disallow changing of geographic location","description":"This policy setting prevents users from changing their user geographical location (GeoID).\r\n\r\nIf you enable this policy setting, users cannot change their GeoID.\r\n\r\nIf you disable or do not configure this policy setting, users may select any GeoID.\r\n\r\nIf you enable this policy setting at the computer level, it cannot be disabled by a per-user policy setting. If you disable this policy setting at the computer level, the per-user policy is ignored. If you do not configure this policy setting at the computer level, restrictions are based on per-user policy settings.\r\n\r\nTo set this policy setting on a per-user basis, make sure that the per-computer policy setting is not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-preventgeoidchange-2"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_preventgeoidchange_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_preventgeoidchange_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_preventuseroverrides_2","displayName":"Disallow user override of locale settings","description":"This policy setting prevents the user from customizing their locale by changing their user overrides.\r\n\r\nAny existing overrides in place when this policy is enabled will be frozen. To remove existing user overrides, first reset the user(s) values to the defaults and then apply this policy.\r\n\r\nWhen this policy setting is enabled, users can still choose alternate locales installed on the system unless prevented by other policies, however, they will be unable to customize those choices. The user cannot customize their user locale with user overrides.\r\n\r\nIf this policy setting is disabled or not configured, then the user can customize their user locale overrides.\r\n\r\nIf this policy is set to Enabled at the computer level, then it cannot be disabled by a per-User policy. If this policy is set to Disabled at the computer level, then the per-User policy will be ignored. If this policy is set to Not Configured at the computer level, then restrictions will be based on per-User policies.\r\n\r\nTo set this policy on a per-user basis, make sure that the per-computer policy is set to Not Configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-preventuseroverrides-2"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_preventuseroverrides_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_preventuseroverrides_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_allowx-forestpolicy-and-rup","displayName":"Allow cross-forest user policy and roaming user profiles","description":"This policy setting allows user-based policy processing, roaming user profiles, and user object logon scripts for interactive logons across forests.\r\n\r\nThis policy setting affects all user accounts that interactively log on to a computer in a different forest when a trust across forests or a two-way forest trust exists.\r\n\r\nIf you do not configure this policy setting:\r\n- No user-based policy settings are applied from the user's forest.\r\n- Users do not receive their roaming profiles; they receive a local profile on the computer from the local forest. A warning message appears to the user, and an event log message (1529) is posted.\r\n- Loopback Group Policy processing is applied, using the Group Policy Objects (GPOs) that are scoped to the computer.\r\n- An event log message (1109) is posted, stating that loopback was invoked in Replace mode.\r\n\r\nIf you enable this policy setting, the behavior is exactly the same as in Windows 2000: user policy is applied, and a roaming user profile is allowed from the trusted forest.\r\n\r\nIf you disable this policy setting, the behavior is the same as if it is not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-allowx-forestpolicy-and-rup"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_allowx-forestpolicy-and-rup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_allowx-forestpolicy-and-rup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_corpconnsyncwaittime","displayName":"Specify workplace connectivity wait time for policy processing","description":"This policy setting specifies how long Group Policy should wait for workplace connectivity notifications during startup policy processing. If the startup policy processing is synchronous, the computer is blocked until workplace connectivity is available or the wait time is reached. If the startup policy processing is asynchronous, the computer is not blocked and policy processing will occur in the background. In either case, configuring this policy setting overrides any system-computed wait times.\r\n\r\nIf you enable this policy setting, Group Policy uses this administratively configured maximum wait time for workplace connectivity, and overrides any default or system-computed wait time.\r\n\r\nIf you disable or do not configure this policy setting, Group Policy will use the default wait time of 60 seconds on computers running Windows operating systems greater than Windows 7 configured for workplace connectivity.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-corpconnsyncwaittime"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_corpconnsyncwaittime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_corpconnsyncwaittime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_corpconnsyncwaittime_corpconnsyncwaittime_seconds","displayName":"Amount of time to wait (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt","displayName":"Configure software Installation policy processing","description":"This policy setting determines when software installation policies are updated.\r\n\r\nThis policy setting affects all policy settings that use the software installation component of Group Policy, such as policy settings in Software Settings\\Software Installation. You can set software installation policy only for Group Policy Objects stored in Active Directory, not for Group Policy Objects on the local computer.\r\n\r\nThis policy setting overrides customized settings that the program implementing the software installation policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy setting implementations specify that they are updated only when changed. However, you might want to update unchanged policy settings, such as reapplying a desired policies in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-appmgmt"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_cse_nochanges1","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_cse_nochanges1_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_cse_nochanges1_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_cse_slowlink1","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_cse_slowlink1_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_cse_slowlink1_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota","displayName":"Configure disk quota policy processing","description":"This policy setting determines when disk quota policies are updated.\r\n\r\nThis policy setting affects all policies that use the disk quota component of Group Policy, such as those in Computer Configuration\\Administrative Templates\\System\\Disk Quotas.\r\n\r\nThis policy setting overrides customized settings that the program implementing the disk quota policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-diskquota"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_nobackground2","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_nobackground2_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_nobackground2_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_nochanges2","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_nochanges2_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_nochanges2_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_slowlink2","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_slowlink2_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_slowlink2_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery","displayName":"Configure EFS recovery policy processing","description":"This policy setting determines when encryption policies are updated.\r\n\r\nThis policy setting affects all policies that use the encryption component of Group Policy, such as policies related to encryption in Windows Settings\\Security Settings.\r\n\r\nIt overrides customized settings that the program implementing the encryption policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-efsrecovery"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nobackground3","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nobackground3_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nobackground3_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nochanges3","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nochanges3_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nochanges3_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_slowlink3","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_slowlink3_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_slowlink3_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection","displayName":"Configure folder redirection policy processing","description":"This policy setting determines when folder redirection policies are updated.\r\n\r\nThis policy setting affects all policies that use the folder redirection component of Group Policy, such as those in WindowsSettings\\Folder Redirection. You can only set folder redirection policy for Group Policy objects, stored in Active Directory, not for Group Policy objects on the local computer.\r\n\r\nThis policy setting overrides customized settings that the program implementing the folder redirection policy setting set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-folderredirection"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_nochanges4","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_nochanges4_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_nochanges4_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_slowlink4","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_slowlink4_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_slowlink4_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem","displayName":"Configure Internet Explorer Maintenance policy processing","description":"This policy setting determines when Internet Explorer Maintenance policies are updated.\r\n\r\nThis policy setting affects all policies that use the Internet Explorer Maintenance component of Group Policy, such as those in Windows Settings\\Internet Explorer Maintenance.\r\n\r\nThis policy setting overrides customized settings that the program implementing the Internet Explorer Maintenance policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-iem"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_nobackground5","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_nobackground5_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_nobackground5_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_nochanges5","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_nochanges5_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_nochanges5_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_slowlink5","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_slowlink5_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_slowlink5_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity","displayName":"Configure IP security policy processing","description":"This policy setting determines when IP security policies are updated.\r\n\r\nThis policy setting affects all policies that use the IP security component of Group Policy, such as policies in Computer Configuration\\Windows Settings\\Security Settings\\IP Security Policies on Local Machine.\r\n\r\nThis policy setting overrides customized settings that the program implementing the IP security policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-ipsecurity"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nobackground6","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nobackground6_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nobackground6_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nochanges6","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nochanges6_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nochanges6_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_slowlink6","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_slowlink6_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_slowlink6_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry","displayName":"Configure registry policy processing","description":"This policy setting determines when registry policies are updated.\r\n\r\nThis policy setting affects all policies in the Administrative Templates folder and any other policies that store values in the registry. It overrides customized settings that the program implementing a registry policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-registry"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nobackground10","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nobackground10_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nobackground10_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nochanges10","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nochanges10_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nochanges10_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts","displayName":"Configure scripts policy processing","description":"This policy setting determines when policies that assign shared scripts are updated.\r\n\r\nThis policy setting affects all policies that use the scripts component of Group Policy, such as those in WindowsSettings\\Scripts. It overrides customized settings that the program implementing the scripts policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-scripts"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nobackground7","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nobackground7_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nobackground7_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nochanges7","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nochanges7_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nochanges7_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_slowlink7","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_slowlink7_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_slowlink7_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security","displayName":"Configure security policy processing","description":"This policy setting determines when security policies are updated.\r\n\r\nThis policy setting affects all policies that use the security component of Group Policy, such as those in Windows Settings\\Security Settings.\r\n\r\nThis policy setting overrides customized settings that the program implementing the security policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they be updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-security"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nobackground11","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nobackground11_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nobackground11_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nochanges11","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nochanges11_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nochanges11_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired","displayName":"Configure wired policy processing","description":"This policy setting determines when policies that assign wired network settings are updated.\r\n\r\nThis policy setting affects all policies that use the wired network component of Group Policy, such as those in Windows Settings\\Wired Network Policies.\r\n\r\nIt overrides customized settings that the program implementing the wired network set when it was installed.\r\n\r\nIf you enable this policy, you can use the check boxes provided to change the options.\r\n\r\nIf you disable this setting or do not configure it, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-wired"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_nobackground8","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_nobackground8_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_nobackground8_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_nochanges8","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_nochanges8_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_nochanges8_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_slowlink8","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_slowlink8_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_slowlink8_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless","displayName":"Configure wireless policy processing","description":"This policy setting determines when policies that assign wireless network settings are updated.\r\n\r\nThis policy setting affects all policies that use the wireless network component of Group Policy, such as those in WindowsSettings\\Wireless Network Policies.\r\n\r\nIt overrides customized settings that the program implementing the wireless network set when it was installed.\r\n\r\nIf you enable this policy, you can use the check boxes provided to change the options.\r\n\r\nIf you disable this setting or do not configure it, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-wireless"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_nobackground9","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_nobackground9_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_nobackground9_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_nochanges9","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_nochanges9_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_nochanges9_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_slowlink9","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_slowlink9_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_slowlink9_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_denyrsoptointeractiveuser_2","displayName":"Determine if interactive users can generate Resultant Set of Policy data","description":"This policy setting controls the ability of users to view their Resultant Set of Policy (RSoP) data.\r\n\r\nBy default, interactively logged on users can view their own Resultant Set of Policy (RSoP) data.\r\n\r\nIf you enable this policy setting, interactive users cannot generate RSoP data.\r\n\r\nIf you disable or do not configure this policy setting, interactive users can generate RSoP.\r\n\r\nNote: This policy setting does not affect administrators. If you enable or disable this policy setting, by default administrators can view RSoP data.\r\n\r\nNote: To view RSoP data on a client computer, use the RSoP snap-in for the Microsoft Management Console. You can launch the RSoP snap-in from the command line by typing RSOP.msc\r\n\r\nNote: This policy setting exists as both a User Configuration and Computer Configuration setting.\r\n\r\nAlso, see the \"Turn off Resultant set of Policy logging\" policy setting in Computer Configuration\\Administrative Templates\\System\\GroupPolicy.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-denyrsoptointeractiveuser-2"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_denyrsoptointeractiveuser_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_denyrsoptointeractiveuser_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disableaoacprocessing","displayName":"Turn off Group Policy Client Service AOAC optimization","description":"This policy setting prevents the Group Policy Client Service from stopping when idle.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-disableaoacprocessing"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disableaoacprocessing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disableaoacprocessing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disablebackgroundpolicy","displayName":"Turn off background refresh of Group Policy","description":"This policy setting prevents Group Policy from being updated while the computer is in use. This policy setting applies to Group Policy for computers, users, and domain controllers.\r\n\r\nIf you enable this policy setting, the system waits until the current user logs off the system before updating the computer and user settings.\r\n\r\nIf you disable or do not configure this policy setting, updates can be applied while users are working. The frequency of updates is determined by the \"Set Group Policy refresh interval for computers\" and \"Set Group Policy refresh interval for users\" policy settings.\r\n\r\nNote: If you make changes to this policy setting, you must restart your computer for it to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-disablebackgroundpolicy"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disablebackgroundpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disablebackgroundpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disablelgpoprocessing","displayName":"Turn off Local Group Policy Objects processing","description":"This policy setting prevents Local Group Policy Objects (Local GPOs) from being applied.\r\n\r\nBy default, the policy settings in Local GPOs are applied before any domain-based GPO policy settings. These policy settings can apply to both users and the local computer. You can disable the processing and application of all Local GPOs to ensure that only domain-based GPOs are applied.\r\n\r\nIf you enable this policy setting, the system does not process and apply any Local GPOs.\r\n\r\nIf you disable or do not configure this policy setting, Local GPOs continue to be applied.\r\n\r\nNote: For computers joined to a domain, it is strongly recommended that you only configure this policy setting in domain-based GPOs. This policy setting will be ignored on computers that are joined to a workgroup.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-disablelgpoprocessing"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disablelgpoprocessing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disablelgpoprocessing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disableusersfrommachgp","displayName":"Remove users' ability to invoke machine policy refresh","description":"This policy setting allows you to control a user's ability to invoke a computer policy refresh.\r\n\r\nIf you enable this policy setting, users are not able to invoke a refresh of computer policy. Computer policy will still be applied at startup or when an official policy refresh occurs.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior applies. By default, computer policy is applied when the computer starts up. It also applies at a specified refresh interval or when manually invoked by the user.\r\n\r\nNote: This policy setting applies only to non-administrators. Administrators can still invoke a refresh of computer policy at any time, no matter how this policy setting is configured.\r\n\r\nAlso, see the \"Set Group Policy refresh interval for computers\" policy setting to change the policy refresh interval.\r\n\r\nNote: If you make changes to this policy setting, you must restart your computer for it to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-disableusersfrommachgp"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disableusersfrommachgp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disableusersfrommachgp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablecdp","displayName":"Continue experiences on this device","description":"\r\nThis policy setting determines whether the Windows device is allowed to participate in cross-device experiences (continue experiences).\r\n\r\nIf you enable this policy setting, the Windows device is discoverable by other Windows devices that belong to the same user, and can participate in cross-device experiences.\r\n\r\nIf you disable this policy setting, the Windows device is not discoverable by other devices, and cannot participate in cross-device experiences.\r\n\r\nIf you do not configure this policy setting, the default behavior depends on the Windows edition. Changes to this policy take effect on reboot.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-enablecdp"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablecdp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablecdp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimization","displayName":"Configure Group Policy Caching","description":"\r\n This policy setting allows you to configure Group Policy caching behavior.\r\n\r\n If you enable or do not configure this policy setting, Group Policy caches policy information after every background processing session. This cache saves applicable GPOs and the settings contained within them. When Group Policy runs in synchronous foreground mode, it refers to this cache, which enables it to run faster. When the cache is read, Group Policy attempts to contact a logon domain controller to determine the link speed. When Group Policy runs in background mode or asynchronous foreground mode, it continues to download the latest version of the policy information, and it uses a bandwidth estimate to determine slow link thresholds. (See the “Configure Group Policy Slow Link Detection” policy setting to configure asynchronous foreground behavior.)\r\n\r\n The slow link value that is defined in this policy setting determines how long Group Policy will wait for a response from the domain controller before reporting the link speed as slow. The default is 500 milliseconds.\r\n\r\n The timeout value that is defined in this policy setting determines how long Group Policy will wait for a response from the domain controller before determining that there is no network connectivity. This stops the current Group Policy processing. Group Policy will run in the background the next time a connection to a domain controller is established. Setting this value too high might result in longer waits for the user at boot or logon. The default is 5000 milliseconds.\r\n\r\n If you disable this policy setting, the Group Policy client will not cache applicable GPOs or settings that are contained within the GPOs. When Group Policy runs synchronously, it downloads the latest version of the policy from the network and uses bandwidth estimates to determine slow link thresholds. (See the “Configure Group Policy Slow Link Detection” policy setting to configure asynchronous foreground behavior.)\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-enablelogonoptimization"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimization_syncmodenodcthreshold1","displayName":"Timeout value: [number field] milliseconds","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimization_syncmodeslowlinkthreshold1","displayName":"Slow link value:[number field] milliseconds","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimizationonserversku","displayName":"Enable Group Policy Caching for Servers","description":"\r\n This policy setting allows you to configure Group Policy caching behavior on Windows Server machines.\r\n If you enable this policy setting, Group Policy caches policy information after every background processing session. This cache saves applicable GPOs and the settings contained within them. When Group Policy runs in synchronous foreground mode, it refers to this cache, which enables it to run faster. When the cache is read, Group Policy attempts to contact a logon domain controller to determine the link speed. When Group Policy runs in background mode or asynchronous foreground mode, it continues to download the latest version of the policy information, and it uses a bandwidth estimate to determine slow link thresholds. (See the “Configure Group Policy Slow Link Detection” policy setting to configure asynchronous foreground behavior.)\r\n The slow link value that is defined in this policy setting determines how long Group Policy will wait for a response from the domain controller before reporting the link speed as slow. The default is 500 milliseconds.\r\n The timeout value that is defined in this policy setting determines how long Group Policy will wait for a response from the domain controller before determining that there is no network connectivity. This stops the current Group Policy processing. Group Policy will run in the background the next time a connection to a domain controller is established. Setting this value too high might result in longer waits for the user at boot or logon. The default is 5000 milliseconds.\r\n If you disable or do not configure this policy setting, the Group Policy client will not cache applicable GPOs or settings that are contained within the GPOs. When Group Policy runs synchronously, it downloads the latest version of the policy from the network and uses bandwidth estimates to determine slow link thresholds. (See the “Configure Group Policy Slow Link Detection” policy setting to configure asynchronous foreground behavior.)\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-enablelogonoptimizationonserversku"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimizationonserversku_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimizationonserversku_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimizationonserversku_syncmodenodcthreshold1","displayName":"Timeout value: [number field] milliseconds","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimizationonserversku_syncmodeslowlinkthreshold1","displayName":"Slow link value:[number field] milliseconds","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablemmx","displayName":"Phone-PC linking on this device","description":"\r\nThis policy allows IT admins to turn off the ability to Link a Phone with a PC to continue reading, emailing and other tasks that requires linking between Phone and PC.\r\n\r\nIf you enable this policy setting, the Windows device will be able to enroll in Phone-PC linking functionality and participate in Continue on PC experiences.\r\n\r\nIf you disable this policy setting, the Windows device is not allowed to be linked to Phones, will remove itself from the device list of any linked Phones, and cannot participate in Continue on PC experiences.\r\n\r\nIf you do not configure this policy setting, the default behavior depends on the Windows edition. Changes to this policy take effect on reboot.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-enablemmx"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablemmx_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablemmx_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation","displayName":"Untrusted Font Blocking","description":"This security feature provides a global setting to prevent programs from loading untrusted fonts. Untrusted fonts are any font installed outside of the %windir%\\Fonts directory. This feature can be configured to be in 3 modes: On, Off, and Audit. By default, it is Off and no fonts are blocked. If you aren't quite ready to deploy this feature into your organization, you can run it in Audit mode to see if blocking untrusted fonts causes any usability or compatibility issues.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-fontmitigation"],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation_fontmitigation_dl","displayName":"Mitigation Options","description":null,"helpText":"","infoUrls":[],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation_fontmitigation_dl_1000000000000","displayName":"Block untrusted fonts and log events","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation_fontmitigation_dl_2000000000000","displayName":"Do not block untrusted fonts","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation_fontmitigation_dl_3000000000000","displayName":"Log events without blocking untrusted fonts","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2","displayName":"Configure Group Policy slow link detection","description":"This policy setting defines a slow connection for purposes of applying and updating Group Policy.\r\n\r\nIf the rate at which data is transferred from the domain controller providing a policy update to the computers in this group is slower than the rate specified by this setting, the system considers the connection to be slow.\r\n\r\nThe system's response to a slow policy connection varies among policies. The program implementing the policy can specify the response to a slow link. Also, the policy processing settings in this folder lets you override the programs' specified responses to slow links.\r\n\r\nIf you enable this setting, you can, in the \"Connection speed\" box, type a decimal number between 0 and 4,294,967,200, indicating a transfer rate in kilobits per second. Any connection slower than this rate is considered to be slow. If you type 0, all connections are considered to be fast.\r\n\r\nIf you disable this setting or do not configure it, the system uses the default value of 500 kilobits per second.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. The setting in Computer Configuration defines a slow link for policies in the Computer Configuration folder. The setting in User Configuration defines a slow link for settings in the User Configuration folder.\r\n\r\nAlso, see the \"Do not detect slow network connections\" and related policies in Computer Configuration\\Administrative Templates\\System\\User Profile. Note: If the profile server has IP connectivity, the connection speed setting is used. If the profile server does not have IP connectivity, the SMB timing is used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-gptransferrate-2"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_cse_3g_default_to_slowlink_computer","displayName":"Always treat WWAN connections as a slow link","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_cse_3g_default_to_slowlink_computer_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_cse_3g_default_to_slowlink_computer_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_transferrateop2","displayName":"Connection speed (Kbps):","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrate","displayName":"Set Group Policy refresh interval for computers","description":"This policy setting specifies how often Group Policy for computers is updated while the computer is in use (in the background). This setting specifies a background update rate only for Group Policies in the Computer Configuration folder.\r\n\r\nIn addition to background updates, Group Policy for the computer is always updated when the system starts.\r\n\r\nBy default, computer Group Policy is updated in the background every 90 minutes, with a random offset of 0 to 30 minutes.\r\n\r\nIf you enable this setting, you can specify an update rate from 0 to 64,800 minutes (45 days). If you select 0 minutes, the computer tries to update Group Policy every 7 seconds. However, because updates might interfere with users' work and increase network traffic, very short update intervals are not appropriate for most installations.\r\n\r\nIf you disable this setting, Group Policy is updated every 90 minutes (the default). To specify that Group Policy should never be updated while the computer is in use, select the \"Turn off background refresh of Group Policy\" policy.\r\n\r\nThe Set Group Policy refresh interval for computers policy also lets you specify how much the actual update interval varies. To prevent clients with the same update interval from requesting updates simultaneously, the system varies the update interval for each client by a random number of minutes. The number you type in the random time box sets the upper limit for the range of variance. For example, if you type 30 minutes, the system selects a variance of 0 to 30 minutes. Typing a large number establishes a broad range and makes it less likely that client requests overlap. However, updates might be delayed significantly.\r\n\r\nThis setting establishes the update rate for computer Group Policy. To set an update rate for user policies, use the \"Set Group Policy refresh interval for users\" setting (located in User Configuration\\Administrative Templates\\System\\Group Policy).\r\n\r\nThis setting is only used when the \"Turn off background refresh of Group Policy\" setting is not enabled.\r\n\r\nNote: Consider notifying users that their policy is updated periodically so that they recognize the signs of a policy update. When Group Policy is updated, the Windows desktop is refreshed; it flickers briefly and closes open menus. Also, restrictions imposed by Group Policies, such as those that limit the programs users can run, might interfere with tasks in progress.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-grouppolicyrefreshrate"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrate_gprefreshrate1","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrate_gprefreshrateoffset1","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc","displayName":"Set Group Policy refresh interval for domain controllers","description":"This policy setting specifies how often Group Policy is updated on domain controllers while they are running (in the background). The updates specified by this setting occur in addition to updates performed when the system starts.\r\n\r\nBy default, Group Policy on the domain controllers is updated every five minutes.\r\n\r\nIf you enable this setting, you can specify an update rate from 0 to 64,800 minutes (45 days). If you select 0 minutes, the domain controller tries to update Group Policy every 7 seconds. However, because updates might interfere with users' work and increase network traffic, very short update intervals are not appropriate for most installations.\r\n\r\nIf you disable or do not configure this setting, the domain controller updates Group Policy every 5 minutes (the default). To specify that Group Policies for users should never be updated while the computer is in use, select the \"Turn off background refresh of Group Policy\" setting.\r\n\r\nThis setting also lets you specify how much the actual update interval varies. To prevent domain controllers with the same update interval from requesting updates simultaneously, the system varies the update interval for each controller by a random number of minutes. The number you type in the random time box sets the upper limit for the range of variance. For example, if you type 30 minutes, the system selects a variance of 0 to 30 minutes. Typing a large number establishes a broad range and makes it less likely that update requests overlap. However, updates might be delayed significantly.\r\n\r\nNote: This setting is used only when you are establishing policy for a domain, site, organizational unit (OU), or customized group. If you are establishing policy for a local computer only, the system ignores this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-grouppolicyrefreshratedc"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_gprefreshrate2","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_gprefreshrateoffset2","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay","displayName":"Configure Logon Script Delay","description":"\r\n Enter “0” to disable Logon Script Delay.\r\n\r\n This policy setting allows you to configure how long the Group Policy client waits after logon before running scripts.\r\n\r\n By default, the Group Policy client waits five minutes before running logon scripts. This helps create a responsive desktop environment by preventing disk contention.\r\n\r\n If you enable this policy setting, Group Policy will wait for the specified amount of time before running logon scripts.\r\n\r\n If you disable this policy setting, Group Policy will run scripts immediately after logon.\r\n\r\n If you do not configure this policy setting, Group Policy will wait five minutes before running logon scripts.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-logonscriptdelay"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay_asyncscriptdelay1","displayName":"minute:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_onlyuselocaladminfiles","displayName":"Always use local ADM files for Group Policy Object Editor","description":"This policy setting lets you always use local ADM files for the Group Policy snap-in.\r\n\r\nBy default, when you edit a Group Policy Object (GPO) using the Group Policy Object Editor snap-in, the ADM files are loaded from that GPO into the Group Policy Object Editor snap-in. This allows you to use the same version of the ADM files that were used to create the GPO while editing this GPO.\r\n\r\nThis leads to the following behavior:\r\n\r\n- If you originally created the GPO with, for example, an English system, the GPO contains English ADM files.\r\n\r\n- If you later edit the GPO from a different-language system, you get the English ADM files as they were in the GPO.\r\n\r\nYou can change this behavior by using this setting.\r\n\r\nIf you enable this setting, the Group Policy Object Editor snap-in always uses local ADM files in your %windir%\\inf directory when editing GPOs.\r\n\r\nThis leads to the following behavior:\r\n\r\n- If you had originally created the GPO with an English system, and then you edit the GPO with a Japanese system, the Group Policy Object Editor snap-in uses the local Japanese ADM files, and you see the text in Japanese under Administrative Templates.\r\n\r\nIf you disable or do not configure this setting, the Group Policy Object Editor snap-in always loads all ADM files from the actual GPO.\r\n\r\nNote: If the ADMs that you require are not all available locally in your %windir%\\inf directory, you might not be able to see all the settings that have been configured in the GPO that you are editing.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-onlyuselocaladminfiles"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_onlyuselocaladminfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_onlyuselocaladminfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions","displayName":"Process Mitigation Options","description":"\r\n This security feature provides a means to override individual process MitigationOptions settings. This can be used to enforce a number of security policies specific to applications. The application name is specified as the Value name, including extension. The Value is specified as a bit field with a series of flags in particular positions. Bits can be set to either 0 (setting is forced off), 1 (setting is forced on), or ? (setting retains its existing value prior to GPO evaluation). The recognized bit locations are:\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_DEP_ENABLE (0x00000001)\r\n Enables data execution prevention (DEP) for the child process\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_DEP_ATL_THUNK_ENABLE (0x00000002)\r\n Enables DEP-ATL thunk emulation for the child process. DEP-ATL thunk emulation causes the system to intercept NX faults that originate from the Active Template Library (ATL) thunk layer.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_SEHOP_ENABLE (0x00000004)\r\n Enables structured exception handler overwrite protection (SEHOP) for the child process. SEHOP blocks exploits that use the structured exception handler (SEH) overwrite technique.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_FORCE_RELOCATE_IMAGES_ALWAYS_ON (0x00000100)\r\n The force Address Space Layout Randomization (ASLR) policy forcibly rebases images that are not dynamic base compatible by acting as though an image base collision happened at load time. If relocations are required, images that do not have a base relocation section will not be loaded.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_ON (0x00010000)\r\n PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_OFF (0x00020000)\r\n The bottom-up randomization policy, which includes stack randomization options, causes a random location to be used as the lowest user address.\r\n\r\n For instance, to enable PROCESS_CREATION_MITIGATION_POLICY_DEP_ENABLE and PROCESS_CREATION_MITIGATION_POLICY_FORCE_RELOCATE_IMAGES_ALWAYS_ON, disable PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_OFF, and to leave all other options at their default values, specify a value of:\r\n ???????????????0???????1???????1\r\n\r\n Setting flags not specified here to any value other than ? results in undefined behavior.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-processmitigationoptions"],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_processmitigationoptionslist","displayName":"Process Mitigation Options","description":null,"helpText":"","infoUrls":[],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_processmitigationoptionslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_processmitigationoptionslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_resetdfsclientinfoduringrefreshpolicy","displayName":"Enable AD/DFS domain controller synchronization during policy refresh","description":"Enabling this setting will cause the Group Policy Client to connect to the same domain controller for DFS shares as is being used for Active Directory.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-resetdfsclientinfoduringrefreshpolicy"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_resetdfsclientinfoduringrefreshpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_resetdfsclientinfoduringrefreshpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_rsoplogging","displayName":"Turn off Resultant Set of Policy logging","description":"This setting allows you to enable or disable Resultant Set of Policy (RSoP) logging on a client computer.\r\n\r\nRSoP logs information on Group Policy settings that have been applied to the client. This information includes details such as which Group Policy Objects (GPO) were applied, where they came from, and the client-side extension settings that were included.\r\n\r\nIf you enable this setting, RSoP logging is turned off.\r\n\r\nIf you disable or do not configure this setting, RSoP logging is turned on. By default, RSoP logging is always on.\r\n\r\nNote: To view the RSoP information logged on a client computer, you can use the RSoP snap-in in the Microsoft Management Console (MMC).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-rsoplogging"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_rsoplogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_rsoplogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaultfordirectaccess","displayName":"Configure Direct Access connections as a fast network connection","description":"This policy setting allows an administrator to define the Direct Access connection to be considered a fast network connection for the purposes of applying and updating Group Policy.\r\n\r\nWhen Group Policy detects the bandwidth speed of a Direct Access connection, the detection can sometimes fail to provide any bandwidth speed information. If Group Policy detects a bandwidth speed, Group Policy will follow the normal rules for evaluating if the Direct Access connection is a fast or slow network connection. If no bandwidth speed is detected, Group Policy will default to a slow network connection. This policy setting allows the administrator the option to override the default to slow network connection and instead default to using a fast network connection in the case that no network bandwidth speed is determined.\r\n\r\nNote: When Group Policy detects a slow network connection, Group Policy will only process those client side extensions configured for processing across a slow link (slow network connection).\r\n\r\nIf you enable this policy, when Group Policy cannot determine the bandwidth speed across Direct Access, Group Policy will evaluate the network connection as a fast link and process all client side extensions.\r\n\r\nIf you disable this setting or do not configure it, Group Policy will evaluate the network connection as a slow link and process only those client side extensions configured to process over a slow link.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-slowlinkdefaultfordirectaccess"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaultfordirectaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaultfordirectaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaulttoasync","displayName":"Change Group Policy processing to run asynchronously when a slow network connection is detected.","description":"This policy directs Group Policy processing to skip processing any client side extension that requires synchronous processing (that is, whether computers wait for the network to be fully initialized during computer startup and user logon) when a slow network connection is detected.\r\n\r\nIf you enable this policy setting, when a slow network connection is detected, Group Policy processing will always run in an asynchronous manner.\r\nClient computers will not wait for the network to be fully initialized at startup and logon. Existing users will be logged on using cached credentials,\r\nwhich will result in shorter logon times. Group Policy will be applied in the background after the network becomes available.\r\nNote that because this is a background refresh, extensions requiring synchronous processing such as Software Installation, Folder Redirection\r\nand Drive Maps preference extension will not be applied.\r\n\r\nNote: There are two conditions that will cause Group Policy to be processed synchronously even if this policy setting is enabled:\r\n1 - At the first computer startup after the client computer has joined the domain.\r\n2 - If the policy setting \"Always wait for the network at computer startup and logon\" is enabled.\r\n\r\nIf you disable or do not configure this policy setting, detecting a slow network connection will not affect whether Group Policy processing will be synchronous or asynchronous.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-slowlinkdefaulttoasync"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaulttoasync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaulttoasync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_syncwaittime","displayName":"Specify startup policy processing wait time","description":"This policy setting specifies how long Group Policy should wait for network availability notifications during startup policy processing. If the startup policy processing is synchronous, the computer is blocked until the network is available or the default wait time is reached. If the startup policy processing is asynchronous, the computer is not blocked and policy processing will occur in the background. In either case, configuring this policy setting overrides any system-computed wait times.\r\n\r\nIf you enable this policy setting, Group Policy will use this administratively configured maximum wait time and override any default or system-computed wait time.\r\n\r\nIf you disable or do not configure this policy setting, Group Policy will use the default wait time of 30 seconds on computers running Windows Vista operating system.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-syncwaittime"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_syncwaittime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_syncwaittime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_syncwaittime_syncwaittime_minutes","displayName":"Amount of time to wait (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode","displayName":"Configure user Group Policy loopback processing mode","description":"This policy setting directs the system to apply the set of Group Policy objects for the computer to any user who logs on to a computer affected by this setting. It is intended for special-use computers, such as those in public places, laboratories, and classrooms, where you must modify the user setting based on the computer that is being used.\r\n\r\nBy default, the user's Group Policy Objects determine which user settings apply. If this setting is enabled, then, when a user logs on to this computer, the computer's Group Policy Objects determine which set of Group Policy Objects applies.\r\n\r\nIf you enable this setting, you can select one of the following modes from the Mode box:\r\n\r\n\"Replace\" indicates that the user settings defined in the computer's Group Policy Objects replace the user settings normally applied to the user.\r\n\r\n\"Merge\" indicates that the user settings defined in the computer's Group Policy Objects and the user settings normally applied to the user are combined. If the settings conflict, the user settings in the computer's Group Policy Objects take precedence over the user's normal settings.\r\n\r\nIf you disable this setting or do not configure it, the user's Group Policy Objects determines which user settings apply.\r\n\r\nNote: This setting is effective only when both the computer account and the user account are in at least Windows 2000 domains.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-userpolicymode"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_userpolicymodeop","displayName":"Mode:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_userpolicymodeop_1","displayName":"Merge","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_userpolicymodeop_2","displayName":"Replace","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_help_disablehhdep","displayName":"Turn off Data Execution Prevention for HTML Help Executible","description":"This policy setting allows you to exclude HTML Help Executable from being monitored by software-enforced Data Execution Prevention.\r\n\r\n Data Execution Prevention (DEP) is designed to block malicious code that takes advantage of exception-handling mechanisms in Windows by monitoring your programs to make sure that they use system memory safely.\r\n\r\n If you enable this policy setting, DEP for HTML Help Executable is turned off. This will allow certain legacy ActiveX controls to function without DEP shutting down HTML Help Executable.\r\n\r\n If you disable or do not configure this policy setting, DEP is turned on for HTML Help Executable. This provides an additional security benefit, but HTLM Help stops if DEP detects system memory abnormalities.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-help#admx-help-disablehhdep"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_help_disablehhdep_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_help_disablehhdep_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp","displayName":"Restrict potentially unsafe HTML Help functions to specified folders","description":"This policy setting allows you to restrict certain HTML Help commands to function only in HTML Help (.chm) files within specified folders and their subfolders. Alternatively, you can disable these commands on the entire system. It is strongly recommended that only folders requiring administrative privileges be added to this policy setting.\r\n\r\n If you enable this policy setting, the commands function only for .chm files in the specified folders and their subfolders.\r\n\r\n To restrict the commands to one or more folders, enable the policy setting and enter the desired folders in the text box on the Settings tab of the Policy Properties dialog box. Use a semicolon to separate folders. For example, to restrict the commands to only .chm files in the %windir%\\help folder and D:\\somefolder, add the following string to the edit box: \"%windir%\\help;D:\\somefolder\".\r\n\r\n Note: An environment variable may be used, (for example, %windir%), as long as it is defined on the system. For example, %programfiles% is not defined on some early versions of Windows.\r\n\r\n The \"Shortcut\" command is used to add a link to a Help topic, and runs executables that are external to the Help file. The \"WinHelp\" command is used to add a link to a Help topic, and runs a WinHLP32.exe Help (.hlp) file.\r\n\r\n To disallow the \"Shortcut\" and \"WinHelp\" commands on the entire local system, enable the policy setting and leave the text box on the Settings tab of the Policy Properties dialog box blank.\r\n\r\n If you disable or do not configure this policy setting, these commands are fully functional for all Help files.\r\n\r\n Note: Only folders on the local computer can be specified in this policy setting. You cannot use this policy setting to enable the \"Shortcut\" and \"WinHelp\" commands for .chm files that are stored on mapped drives or accessed using UNC paths.\r\n\r\n For additional options, see the \"Restrict these programs from being launched from Help\" policy.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-help#admx-help-helpqualifiedrootdir-comp"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp_helpqualifiedrootdir_edit","displayName":"Enter folder names separated by semi-colons:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_help_restrictrunfromhelp_comp","displayName":"Restrict these programs from being launched from Help","description":"\r\n This policy setting allows you to restrict programs from being run from online Help.\r\n \r\n If you enable this policy setting, you can prevent specified programs from being run from Help. When you enable this policy setting, enter the file names names of the programs you want to restrict, separated by commas.\r\n \r\n If you disable or do not configure this policy setting, users can run all applications from online Help.\r\n \r\n Note: You can also restrict users from running applications by using the Software Restriction Policy settings available in Computer Configuration\\Security Settings.\r\n \r\n Note: This policy setting is available under Computer Configuration and User Configuration. If both are settings are used, any programs listed in either of these locations cannot launched from Help\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-help#admx-help-restrictrunfromhelp-comp"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_help_restrictrunfromhelp_comp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_help_restrictrunfromhelp_comp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_help_restrictrunfromhelp_comp_restrictrunfromhelp_edit","displayName":"Enter executables separated by commas:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_helpandsupport_activehelp","displayName":"Turn off Active Help","description":"This policy setting specifies whether active content links in trusted assistance content are rendered. By default, the Help viewer renders trusted assistance content with active elements such as ShellExecute links and Guided Help links.\r\n\r\nIf you enable this policy setting, active content links are not rendered. The text is displayed, but there are no clickable links for these elements.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior applies (Help viewer renders trusted assistance content with active elements).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-helpandsupport#admx-helpandsupport-activehelp"],"categoryId":"5be35eeb-62e9-4317-8804-018a9dd31149","categoryName":"Online Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_helpandsupport_activehelp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_helpandsupport_activehelp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_hotspotauth_hotspotauth_enable","displayName":"Enable Hotspot Authentication","description":"This policy setting defines whether WLAN hotspots are probed for Wireless Internet Service Provider roaming (WISPr) protocol support.\r\n\r\nIf a WLAN hotspot supports the WISPr protocol, users can submit credentials when manually connecting to the network. If authentication is successful, users will be connected automatically on subsequent attempts. Credentials can also be configured by network operators.\r\n\r\nIf you enable this policy setting, or if you do not configure this policy setting, WLAN hotspots are automatically probed for WISPR protocol support.\r\n\r\nIf you disable this policy setting, WLAN hotspots are not probed for WISPr protocol support, and users can only authenticate with WLAN hotspots using a web browser.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-hotspotauth#admx-hotspotauth-hotspotauth-enable"],"categoryId":"6d4184ab-a66c-47f1-b54e-af55f654e2a5","categoryName":"Hotspot Authentication","options":[{"id":"device_vendor_msft_policy_config_admx_hotspotauth_hotspotauth_enable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_hotspotauth_hotspotauth_enable_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_ceipenable","displayName":"Turn off Windows Customer Experience Improvement Program","description":"This policy setting turns off the Windows Customer Experience Improvement Program. The Windows Customer Experience Improvement Program collects information about your hardware configuration and how you use our software and services to identify trends and usage patterns. Microsoft will not collect your name, address, or any other personally identifiable information. There are no surveys to complete, no salesperson will call, and you can continue working without interruption. It is simple and user-friendly.\r\n\r\nIf you enable this policy setting, all users are opted out of the Windows Customer Experience Improvement Program.\r\n\r\nIf you disable this policy setting, all users are opted into the Windows Customer Experience Improvement Program.\r\n\r\nIf you do not configure this policy setting, the administrator can use the Problem Reports and Solutions component in Control Panel to enable Windows Customer Experience Improvement Program for all users.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-ceipenable"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_ceipenable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_ceipenable_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_certmgr_disableautorootupdates","displayName":"Turn off Automatic Root Certificates Update","description":"This policy setting specifies whether to automatically update root certificates using the Windows Update website. \r\n\r\nTypically, a certificate is used when you use a secure website or when you send and receive secure email. Anyone can issue certificates, but to have transactions that are as secure as possible, certificates must be issued by a trusted certificate authority (CA). Microsoft has included a list in Windows XP and other products of companies and organizations that it considers trusted authorities.\r\n\r\nIf you enable this policy setting, when you are presented with a certificate issued by an untrusted root authority, your computer will not contact the Windows Update website to see if Microsoft has added the CA to its list of trusted authorities.\r\n\r\nIf you disable or do not configure this policy setting, your computer will contact the Windows Update website.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-certmgr-disableautorootupdates"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_certmgr_disableautorootupdates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_certmgr_disableautorootupdates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_driversearchplaces_dontsearchwindowsupdate","displayName":"Turn off Windows Update device driver searching","description":"This policy setting specifies whether Windows searches Windows Update for device drivers when no local drivers for a device are present.\r\n\r\nIf you enable this policy setting, Windows Update is not searched when a new device is installed.\r\n\r\nIf you disable this policy setting, Windows Update is always searched for drivers when no local drivers are present.\r\n\r\nIf you do not configure this policy setting, searching Windows Update is optional when installing a device.\r\n\r\nAlso see \"Turn off Windows Update device driver search prompt\" in \"Administrative Templates/System,\" which governs whether an administrator is prompted before searching Windows Update for device drivers if a driver is not found locally.\r\n\r\nNote: This policy setting is replaced by \"Specify Driver Source Search Order\" in \"Administrative Templates/System/Device Installation\" on newer versions of Windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-driversearchplaces-dontsearchwindowsupdate"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_driversearchplaces_dontsearchwindowsupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_driversearchplaces_dontsearchwindowsupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_eventviewer_disablelinks","displayName":"Turn off Event Viewer \"Events.asp\" links","description":"This policy setting specifies whether \"Events.asp\" hyperlinks are available for events within the Event Viewer application.\r\n\r\nThe Event Viewer normally makes all HTTP(S) URLs into hyperlinks that activate the Internet browser when clicked. In addition, \"More Information\" is placed at the end of the description text if the event is created by a Microsoft component. This text contains a link (URL) that, if clicked, sends information about the event to Microsoft, and allows users to learn more about why that event occurred.\r\n\r\nIf you enable this policy setting, event description hyperlinks are not activated and the text \"More Information\" is not displayed at the end of the description.\r\n\r\nIf you disable or do not configure this policy setting, the user can click the hyperlink, which prompts the user and then sends information about the event over the Internet to Microsoft. Also, see \"Events.asp URL\", \"Events.asp program\", and \"Events.asp Program Command Line Parameters\" settings in \"Administrative Templates/Windows Components/Event Viewer\".\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-eventviewer-disablelinks"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_eventviewer_disablelinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_eventviewer_disablelinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_hss_headlinespolicy","displayName":"Turn off Help and Support Center \"Did you know?\" content","description":"This policy setting specifies whether to show the \"Did you know?\" section of Help and Support Center.\r\n\r\nThis content is dynamically updated when users who are connected to the Internet open Help and Support Center, and provides up-to-date information about Windows and the computer.\r\n\r\nIf you enable this policy setting, the Help and Support Center no longer retrieves nor displays \"Did you know?\" content.\r\n\r\nIf you disable or do not configure this policy setting, the Help and Support Center retrieves and displays \"Did you know?\" content.\r\n\r\nYou might want to enable this policy setting for users who do not have Internet access, because the content in the \"Did you know?\" section will remain static indefinitely without an Internet connection.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-hss-headlinespolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_hss_headlinespolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_hss_headlinespolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_hss_kbsearchpolicy","displayName":"Turn off Help and Support Center Microsoft Knowledge Base search","description":"This policy setting specifies whether users can perform a Microsoft Knowledge Base search from the Help and Support Center.\r\n\r\nThe Knowledge Base is an online source of technical support information and self-help tools for Microsoft products, and is searched as part of all Help and Support Center searches with the default search options.\r\n\r\nIf you enable this policy setting, it removes the Knowledge Base section from the Help and Support Center \"Set search options\" page, and only Help content on the local computer is searched. \r\n\r\nIf you disable or do not configure this policy setting, the Knowledge Base is searched if the user has a connection to the Internet and has not disabled the Knowledge Base search from the Search Options page.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-hss-kbsearchpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_hss_kbsearchpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_hss_kbsearchpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_internetmanagement_restrictcommunication_2","displayName":"Restrict Internet communication","description":"This policy setting specifies whether Windows can access the Internet to accomplish tasks that require Internet resources.\r\n\r\nIf you enable this setting, all of the the policy settings listed in the \"Internet Communication settings\" section are set such that their respective features cannot access the Internet.\r\n\r\nIf you disable this policy setting, all of the the policy settings listed in the \"Internet Communication settings\" section are set such that their respective features can access the Internet.\r\n\r\nIf you do not configure this policy setting, all of the the policy settings in the \"Internet Communication settings\" section are set to not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-internetmanagement-restrictcommunication-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_internetmanagement_restrictcommunication_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_internetmanagement_restrictcommunication_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_nc_exitonisp","displayName":"Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com","description":"This policy setting specifies whether the Internet Connection Wizard can connect to Microsoft to download a list of Internet Service Providers (ISPs).\r\n\r\nIf you enable this policy setting, the \"Choose a list of Internet Service Providers\" path in the Internet Connection Wizard causes the wizard to exit. This prevents users from retrieving the list of ISPs, which resides on Microsoft servers.\r\n\r\nIf you disable or do not configure this policy setting, users can connect to Microsoft to download a list of ISPs for their area.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-nc-exitonisp"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_nc_exitonisp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_nc_exitonisp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_nc_noregistration","displayName":"Turn off Registration if URL connection is referring to Microsoft.com","description":"This policy setting specifies whether the Windows Registration Wizard connects to Microsoft.com for online registration.\r\n\r\nIf you enable this policy setting, it blocks users from connecting to Microsoft.com for online registration and users cannot register their copy of Windows online.\r\n\r\nIf you disable or do not configure this policy setting, users can connect to Microsoft.com to complete the online Windows Registration.\r\n\r\nNote that registration is optional and involves submitting some personal information to Microsoft. However, Windows Product Activation is required but does not involve submitting any personal information (except the country/region you live in).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-nc-noregistration"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_nc_noregistration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_nc_noregistration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_pch_donotreport","displayName":"Turn off Windows Error Reporting","description":"This policy setting controls whether or not errors are reported to Microsoft.\r\n\r\nError Reporting is used to report information about a system or application that has failed or has stopped responding and is used to improve the quality of the product.\r\n\r\nIf you enable this policy setting, users are not given the option to report errors.\r\n\r\nIf you disable or do not configure this policy setting, the errors may be reported to Microsoft via the Internet or to a corporate file share.\r\n\r\nThis policy setting overrides any user setting made from the Control Panel for error reporting.\r\n\r\nAlso see the \"Configure Error Reporting\", \"Display Error Notification\" and \"Disable Windows Error Reporting\" policy settings under Computer Configuration/Administrative Templates/Windows Components/Windows Error Reporting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-pch-donotreport"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_pch_donotreport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_pch_donotreport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_removewindowsupdate_icm","displayName":"Turn off access to all Windows Update features","description":"This policy setting allows you to remove access to Windows Update.\r\n\r\nIf you enable this policy setting, all Windows Update features are removed. This includes blocking access to the Windows Update website at http://windowsupdate.microsoft.com, from the Windows Update hyperlink on the Start menu, and also on the Tools menu in Internet Explorer. Windows automatic updating is also disabled; you will neither be notified about nor will you receive critical updates from Windows Update. This policy setting also prevents Device Manager from automatically installing driver updates from the Windows Update website.\r\n\r\nIf you disable or do not configure this policy setting, users can access the Windows Update website and enable automatic updating to receive notifications and critical updates from Windows Update.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-removewindowsupdate-icm"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_removewindowsupdate_icm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_removewindowsupdate_icm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_searchcompanion_disablefileupdates","displayName":"Turn off Search Companion content file updates","description":"This policy setting specifies whether Search Companion should automatically download content updates during local and Internet searches.\r\n\r\nWhen users search the local computer or the Internet, Search Companion occasionally connects to Microsoft to download an updated privacy policy and additional content files used to format and display results.\r\n\r\nIf you enable this policy setting, Search Companion does not download content updates during searches.\r\n\r\nIf you disable or do not configure this policy setting, Search Companion downloads content updates unless the user is using Classic Search.\r\n\r\nNote: Internet searches still send the search text and information about the search to Microsoft and the chosen search provider. Choosing Classic Search turns off the Search Companion feature completely.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-searchcompanion-disablefileupdates"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_searchcompanion_disablefileupdates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_searchcompanion_disablefileupdates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_shellnouseinternetopenwith_2","displayName":"Turn off Internet File Association service","description":"This policy setting specifies whether to use the Microsoft Web service for finding an application to open a file with an unhandled file association.\r\n\r\nWhen a user opens a file that has an extension that is not associated with any applications on the computer, the user is given the choice to select a local application or use the Web service to find an application.\r\n\r\nIf you enable this policy setting, the link and the dialog for using the Web service to open an unhandled file association are removed.\r\n\r\nIf you disable or do not configure this policy setting, the user is allowed to use the Web service.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellnouseinternetopenwith-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_shellnouseinternetopenwith_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_shellnouseinternetopenwith_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_shellnousestoreopenwith_2","displayName":"Turn off access to the Store","description":"This policy setting specifies whether to use the Store service for finding an application to open a file with an unhandled file type or protocol association.\r\n\r\nWhen a user opens a file type or protocol that is not associated with any applications on the computer, the user is given the choice to select a local application or use the Store service to find an application.\r\n\r\nIf you enable this policy setting, the \"Look for an app in the Store\" item in the Open With dialog is removed.\r\n\r\nIf you disable or do not configure this policy setting, the user is allowed to use the Store service and the Store item is available in the Open With dialog.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellnousestoreopenwith-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_shellnousestoreopenwith_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_shellnousestoreopenwith_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_shellremoveorderprints_2","displayName":"Turn off the \"Order Prints\" picture task","description":"This policy setting specifies whether the \"Order Prints Online\" task is available from Picture Tasks in Windows folders.\r\n\r\nThe Order Prints Online Wizard is used to download a list of providers and allow users to order prints online.\r\n\r\nIf you enable this policy setting, the task \"Order Prints Online\" is removed from Picture Tasks in File Explorer folders.\r\n\r\nIf you disable or do not configure this policy setting, the task is displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellremoveorderprints-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_shellremoveorderprints_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_shellremoveorderprints_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_2","displayName":"Turn off the \"Publish to Web\" task for files and folders","description":"This policy setting specifies whether the tasks \"Publish this file to the Web,\" \"Publish this folder to the Web,\" and \"Publish the selected items to the Web\" are available from File and Folder Tasks in Windows folders.\r\n\r\nThe Web Publishing Wizard is used to download a list of providers and allow users to publish content to the web.\r\n\r\nIf you enable this policy setting, these tasks are removed from the File and Folder tasks in Windows folders.\r\n\r\nIf you disable or do not configure this policy setting, the tasks are shown.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellremovepublishtoweb-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_winmsg_noinstrumentation_2","displayName":"Turn off the Windows Messenger Customer Experience Improvement Program","description":"This policy setting specifies whether Windows Messenger collects anonymous information about how Windows Messenger software and service is used.\r\n\r\nWith the Customer Experience Improvement program, users can allow Microsoft to collect anonymous information about how the product is used. This information is used to improve the product in future releases.\r\n\r\nIf you enable this policy setting, Windows Messenger does not collect usage information, and the user settings to enable the collection of usage information are not shown.\r\n\r\nIf you disable this policy setting, Windows Messenger collects anonymous usage information, and the setting is not shown.\r\n\r\nIf you do not configure this policy setting, users have the choice to opt in and allow information to be collected.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-winmsg-noinstrumentation-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_winmsg_noinstrumentation_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_winmsg_noinstrumentation_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iis_preventiisinstall","displayName":"Prevent IIS installation","description":"\"This policy setting prevents installation of Internet Information Services (IIS) on this computer. If you enable this policy setting, Internet Information Services (IIS) cannot be installed, and you will not be able to install Windows components or applications that require IIS. Users installing Windows components or applications that require IIS might not receive a warning that IIS cannot be installed because of this Group Policy setting. Enabling this setting will not have any effect on IIS if IIS is already installed on the computer. If you disable or do not configure this policy setting, IIS can be installed, as well as all the programs and applications that require IIS to run.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iis#admx-iis-preventiisinstall"],"categoryId":"93c28398-faef-4ca5-9667-f5ed004da32c","categoryName":"Internet Information Services","options":[{"id":"device_vendor_msft_policy_config_admx_iis_preventiisinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iis_preventiisinstall_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configureisnsservers","displayName":"Do not allow manual configuration of iSNS servers","description":"If enabled then new iSNS servers may not be added and thus new targets discovered via those iSNS servers; existing iSNS servers may not be removed. If disabled then new iSNS servers may be added and thus new targets discovered via those iSNS servers; existing iSNS servers may be removed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsidiscovery-configureisnsservers"],"categoryId":"60ea8de3-bc6d-4b01-974a-a53860fe4ef6","categoryName":"i SCSI Target Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configureisnsservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configureisnsservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configuretargetportals","displayName":"Do not allow manual configuration of target portals","description":"If enabled then new target portals may not be added and thus new targets discovered on those portals; existing target portals may not be removed. If disabled then new target portals may be added and thus new targets discovered on those portals; existing target portals may be removed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsidiscovery-configuretargetportals"],"categoryId":"60ea8de3-bc6d-4b01-974a-a53860fe4ef6","categoryName":"i SCSI Target Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configuretargetportals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configuretargetportals_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configuretargets","displayName":"Do not allow manual configuration of discovered targets","description":"If enabled then discovered targets may not be manually configured. If disabled then discovered targets may be manually configured. Note: if enabled there may be cases where this will break VDS.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsidiscovery-configuretargets"],"categoryId":"60ea8de3-bc6d-4b01-974a-a53860fe4ef6","categoryName":"i SCSI Target Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configuretargets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configuretargets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_newstatictargets","displayName":"Do not allow adding new targets via manual configuration","description":"If enabled then new targets may not be manually configured by entering the target name and target portal; already discovered targets may be manually configured. If disabled then new and already discovered targets may be manually configured. Note: if enabled there may be cases where this will break VDS.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsidiscovery-newstatictargets"],"categoryId":"60ea8de3-bc6d-4b01-974a-a53860fe4ef6","categoryName":"i SCSI Target Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_newstatictargets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_newstatictargets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsigeneral_changeiqnname","displayName":"Do not allow changes to initiator iqn name","description":" If enabled then do not allow the initiator iqn name to be changed. If disabled then the initiator iqn name may be changed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsigeneral-changeiqnname"],"categoryId":"ca1aedf4-b951-45f5-a77c-dec776a82e21","categoryName":"General i SCSI","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsigeneral_changeiqnname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsigeneral_changeiqnname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsigeneral_restrictadditionallogins","displayName":"Do not allow additional session logins","description":"If enabled then only those sessions that are established via a persistent login will be established and no new persistent logins may be created. If disabled then additional persistent and non persistent logins may be established.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsigeneral-restrictadditionallogins"],"categoryId":"ca1aedf4-b951-45f5-a77c-dec776a82e21","categoryName":"General i SCSI","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsigeneral_restrictadditionallogins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsigeneral_restrictadditionallogins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_changechapsecret","displayName":"Do not allow changes to initiator CHAP secret","description":" If enabled then do not allow the initiator CHAP secret to be changed. If disabled then the initiator CHAP secret may be changed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsisecurity-changechapsecret"],"categoryId":"6c1d9109-e4d1-4718-a537-dd685464fdbe","categoryName":"i SCSI Security","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_changechapsecret_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_changechapsecret_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requireipsec","displayName":"Do not allow connections without IPSec","description":"If enabled then only those connections that are configured for IPSec may be established. If disabled then connections that are configured for IPSec or connections not configured for IPSec may be established.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsisecurity-requireipsec"],"categoryId":"6c1d9109-e4d1-4718-a537-dd685464fdbe","categoryName":"i SCSI Security","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requireipsec_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requireipsec_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requiremutualchap","displayName":"Do not allow sessions without mutual CHAP","description":"If enabled then only those sessions that are configured for mutual CHAP may be established. If disabled then sessions that are configured for mutual CHAP or sessions not configured for mutual CHAP may be established.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsisecurity-requiremutualchap"],"categoryId":"6c1d9109-e4d1-4718-a537-dd685464fdbe","categoryName":"i SCSI Security","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requiremutualchap_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requiremutualchap_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requireonewaychap","displayName":"Do not allow sessions without one way CHAP","description":"If enabled then only those sessions that are configured for one-way CHAP may be established. If disabled then sessions that are configured for one-way CHAP or sessions not configured for one-way CHAP may be established. Note that if the \"Do not allow sessions without mutual CHAP\" setting is enabled then that setting overrides this one.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsisecurity-requireonewaychap"],"categoryId":"6c1d9109-e4d1-4718-a537-dd685464fdbe","categoryName":"i SCSI Security","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requireonewaychap_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requireonewaychap_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor","displayName":"KDC support for claims, compound authentication and Kerberos armoring","description":"This policy setting allows you to configure a domain controller to support claims and compound authentication for Dynamic Access Control and Kerberos armoring using Kerberos authentication.\r\n\r\nIf you enable this policy setting, client computers that support claims and compound authentication for Dynamic Access Control and are Kerberos armor-aware will use this feature for Kerberos authentication messages. This policy should be applied to all domain controllers to ensure consistent application of this policy in the domain. \r\n\r\nIf you disable or do not configure this policy setting, the domain controller does not support claims, compound authentication or armoring.\r\n\r\nIf you configure the \"Not supported\" option, the domain controller does not support claims, compound authentication or armoring which is the default behavior for domain controllers running Windows Server 2008 R2 or earlier operating systems.\r\n\r\nNote: For the following options of this KDC policy to be effective, the Kerberos Group Policy \"Kerberos client support for claims, compound authentication and Kerberos armoring\" must be enabled on supported systems. If the Kerberos policy setting is not enabled, Kerberos authentication messages will not use these features. \r\n\r\nIf you configure \"Supported\", the domain controller supports claims, compound authentication and Kerberos armoring. The domain controller advertises to Kerberos client computers that the domain is capable of claims and compound authentication for Dynamic Access Control and Kerberos armoring. \r\n\r\nDomain functional level requirements\r\nFor the options \"Always provide claims\" and \"Fail unarmored authentication requests\", when the domain functional level is set to Windows Server 2008 R2 or earlier then domain controllers behave as if the \"Supported\" option is selected. \r\n\r\nWhen the domain functional level is set to Windows Server 2012 then the domain controller advertises to Kerberos client computers that the domain is capable of claims and compound authentication for Dynamic Access Control and Kerberos armoring, and:\r\n - If you set the \"Always provide claims\" option, always returns claims for accounts and supports the RFC behavior for advertising the flexible authentication secure tunneling (FAST).\r\n - If you set the \"Fail unarmored authentication requests\" option, rejects unarmored Kerberos messages.\r\n\r\nWarning: When \"Fail unarmored authentication requests\" is set, then client computers which do not support Kerberos armoring will fail to authenticate to the domain controller.\r\n\r\nTo ensure this feature is effective, deploy enough domain controllers that support claims and compound authentication for Dynamic Access Control and are Kerberos armor-aware to handle the authentication requests. Insufficient number of domain controllers that support this policy result in authentication failures whenever Dynamic Access Control or Kerberos armoring is required (that is, the \"Supported\" option is enabled).\r\n\r\nImpact on domain controller performance when this policy setting is enabled:\r\n - Secure Kerberos domain capability discovery is required resulting in additional message exchanges.\r\n - Claims and compound authentication for Dynamic Access Control increases the size and complexity of the data in the message which results in more processing time and greater Kerberos service ticket size.\r\n - Kerberos armoring fully encrypts Kerberos messages and signs Kerberos errors which results in increased processing time, but does not change the service ticket size.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-cbacandarmor"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_cbacandarmor_levels","displayName":"Claims, compound authentication for Dynamic Access Control and Kerberos armoring options:","description":null,"helpText":"","infoUrls":[],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_cbacandarmor_levels_0","displayName":"Not supported","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_cbacandarmor_levels_1","displayName":"Supported","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_cbacandarmor_levels_2","displayName":"Always provide claims","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_cbacandarmor_levels_3","displayName":"Fail unarmored authentication requests","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_emitlili","displayName":"Provide information about previous logons to client computers","description":"This policy setting controls whether the domain controller provides information about previous logons to client computers.\r\n\r\nIf you enable this policy setting, the domain controller provides the information message about previous logons.\r\n\r\nFor Windows Logon to leverage this feature, the \"Display information about previous logons during user logon\" policy setting located in the Windows Logon Options node under Windows Components also needs to be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the domain controller does not provide information about previous logons unless the \"Display information about previous logons during user logon\" policy setting is enabled.\r\n\r\nNote: Information about previous logons is provided only if the domain functional level is Windows Server 2008. In domains with a domain functional level of Windows Server 2003, Windows 2000 native, or Windows 2000 mixed, domain controllers cannot provide information about previous logons, and enabling this policy setting does not affect anything.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-emitlili"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_emitlili_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_emitlili_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_forestsearch","displayName":"Use forest search order","description":"This policy setting defines the list of trusting forests that the Key Distribution Center (KDC) searches when attempting to resolve two-part service principal names (SPNs).\r\n\r\nIf you enable this policy setting, the KDC will search the forests in this list if it is unable to resolve a two-part SPN in the local forest. The forest search is performed by using a global catalog or name suffix hints. If a match is found, the KDC will return a referral ticket to the client for the appropriate domain.\r\n\r\nIf you disable or do not configure this policy setting, the KDC will not search the listed forests to resolve the SPN. If the KDC is unable to resolve the SPN because the name is not found, NTLM authentication might be used.\r\n\r\nTo ensure consistent behavior, this policy setting must be supported and set identically on all domain controllers in the domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-forestsearch"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_forestsearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_forestsearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_forestsearch_forestsearchlist","displayName":"Forests to Search","description":null,"helpText":"","infoUrls":[],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":null},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness","displayName":"KDC support for PKInit Freshness Extension","description":"Support for PKInit Freshness Extension requires Windows Server 2016 domain functional level (DFL). If the domain controller’s domain is not at Windows Server 2016 DFL or higher this policy will not be applied.\r\n\r\nThis policy setting allows you to configure a domain controller (DC) to support the PKInit Freshness Extension.\r\n\r\nIf you enable this policy setting, the following options are supported:\r\n\r\nSupported: PKInit Freshness Extension is supported on request. Kerberos clients successfully authenticating with the PKInit Freshness Extension will get the fresh public key identity SID.\r\n\r\nRequired: PKInit Freshness Extension is required for successful authentication. Kerberos clients which do not support the PKInit Freshness Extension will always fail when using public key credentials.\r\n\r\nIf you disable or not configure this policy setting, then the DC will never offer the PKInit Freshness Extension and accept valid authentication requests without checking for freshness. Users will never receive the fresh public key identity SID.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-pkinitfreshness"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels","displayName":"PKInit Freshness Extension options:","description":null,"helpText":"","infoUrls":[],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels_1","displayName":"Supported","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels_2","displayName":"Required","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_requestcompoundid","displayName":"Request compound authentication","description":"This policy setting allows you to configure a domain controller to request compound authentication.\r\n\r\nNote: For a domain controller to request compound authentication, the policy \"KDC support for claims, compound authentication, and Kerberos armoring\" must be configured and enabled. \r\n\r\nIf you enable this policy setting, domain controllers will request compound authentication. The returned service ticket will contain compound authentication only when the account is explicitly configured. This policy should be applied to all domain controllers to ensure consistent application of this policy in the domain. \r\n\r\nIf you disable or do not configure this policy setting, domain controllers will return service tickets that contain compound authentication any time the client sends a compound authentication request regardless of the account configuration.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-requestcompoundid"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_requestcompoundid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_requestcompoundid_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_ticketsizethreshold","displayName":"Warning for large Kerberos tickets","description":"This policy setting allows you to configure at what size Kerberos tickets will trigger the warning event issued during Kerberos authentication. The ticket size warnings are logged in the System log.\r\n\r\nIf you enable this policy setting, you can set the threshold limit for Kerberos ticket which trigger the warning events. If set too high, then authentication failures might be occurring even though warning events are not being logged. If set too low, then there will be too many ticket warnings in the log to be useful for analysis. This value should be set to the same value as the Kerberos policy \"Set maximum Kerberos SSPI context token buffer size\" or the smallest MaxTokenSize used in your environment if you are not configuring using Group Policy.\r\n \r\nIf you disable or do not configure this policy setting, the threshold value defaults to 12,000 bytes, which is the default Kerberos MaxTokenSize for Windows 7, Windows Server 2008 R2 and prior versions.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-ticketsizethreshold"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_ticketsizethreshold_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_ticketsizethreshold_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_ticketsizethreshold_ticketsizethreshold","displayName":"Ticket Size Threshold","description":null,"helpText":"","infoUrls":[],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_alwayssendcompoundid","displayName":"Always send compound authentication first","description":"This policy setting controls whether a device always sends a compound authentication request when the resource domain requests compound identity.\r\n\r\nNote: For a domain controller to request compound authentication, the policies \"KDC support for claims, compound authentication, and Kerberos armoring\" and \"Request compound authentication\" must be configured and enabled in the resource account domain. \r\n\r\nIf you enable this policy setting and the resource domain requests compound authentication, devices that support compound authentication always send a compound authentication request. \r\n\r\nIf you disable or do not configure this policy setting and the resource domain requests compound authentication, devices will send a non-compounded authentication request first then a compound authentication request when the service requests compound authentication.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-alwayssendcompoundid"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_alwayssendcompoundid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_alwayssendcompoundid_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled","displayName":"Support device authentication using certificate","description":"Support for device authentication using certificate will require connectivity to a DC in the device account domain which supports certificate authentication for computer accounts. \r\n\r\nThis policy setting allows you to set support for Kerberos to attempt authentication using the certificate for the device to the domain.\r\n\r\nIf you enable this policy setting, the device’s credentials will be selected based on the following options:\r\n\r\nAutomatic: Device will attempt to authenticate using its certificate. If the DC does not support computer account authentication using certificates then authentication with password will be attempted.\r\n\r\nForce: Device will always authenticate using its certificate. If a DC cannot be found which support computer account authentication using certificates then authentication will fail.\r\n\r\nIf you disable this policy setting, certificates will never be used.\r\nIf you do not configure this policy setting, Automatic will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-devicepkinitenabled"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_devicepkinitbehavior","displayName":"Device authentication behavior using certificate:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_devicepkinitbehavior_0","displayName":"Automatic","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_devicepkinitbehavior_1","displayName":"Force","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm","displayName":"Define host name-to-Kerberos realm mappings","description":"This policy setting allows you to specify which DNS host names and which DNS suffixes are mapped to a Kerberos realm.\r\n\r\nIf you enable this policy setting, you can view and change the list of DNS host names and DNS suffixes mapped to a Kerberos realm as defined by Group Policy. To view the list of mappings, enable the policy setting and then click the Show button. To add a mapping, enable the policy setting, note the syntax, and then click Show. In the Show Contents dialog box in the Value Name column, type a realm name. In the Value column, type the list of DNS host names and DNS suffixes using the appropriate syntax format. To remove a mapping from the list, click the mapping entry to be removed, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.\r\n\r\nIf you disable this policy setting, the host name-to-Kerberos realm mappings list defined by Group Policy is deleted.\r\n\r\nIf you do not configure this policy setting, the system uses the host name-to-Kerberos realm mappings that are defined in the local registry, if they exist.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-hosttorealm"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm_hosttorealm","displayName":"Define host name-to-realm mappings:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm_hosttorealm_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm_hosttorealm_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxydisableserverrevocationcheck","displayName":"Disable revocation checking for the SSL certificate of KDC proxy servers","description":"This policy setting allows you to disable revocation check for the SSL certificate of the targeted KDC proxy server.\r\n\r\nIf you enable this policy setting, revocation check for the SSL certificate of the KDC proxy server is ignored by the Kerberos client. This policy setting should only be used in troubleshooting KDC proxy connections. \r\nWarning: When revocation check is ignored, the server represented by the certificate is not guaranteed valid. \r\n\r\nIf you disable or do not configure this policy setting, the Kerberos client enforces the revocation check for the SSL certificate. The connection to the KDC proxy server is not established if the revocation check fails.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-kdcproxydisableserverrevocationcheck"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxydisableserverrevocationcheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxydisableserverrevocationcheck_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver","displayName":"Specify KDC proxy servers for Kerberos clients","description":"This policy setting configures the Kerberos client's mapping to KDC proxy servers for domains based on their DNS suffix names.\r\n\r\nIf you enable this policy setting, the Kerberos client will use the KDC proxy server for a domain when a domain controller cannot be located based on the configured mappings. To map a KDC proxy server to a domain, enable the policy setting, click Show, and then map the KDC proxy server name(s) to the DNS name for the domain using the syntax described in the options pane. In the Show Contents dialog box in the Value Name column, type a DNS suffix name. In the Value column, type the list of proxy servers using the appropriate syntax format. To view the list of mappings, enable the policy setting and then click the Show button. To remove a mapping from the list, click the mapping entry to be removed, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.\r\n\r\nIf you disable or do not configure this policy setting, the Kerberos client does not have KDC proxy servers settings defined by Group Policy.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-kdcproxyserver"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_kdcproxyserver","displayName":"Define KDC proxy servers settings:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_kdcproxyserver_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_kdcproxyserver_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms","displayName":"Define interoperable Kerberos V5 realm settings","description":"This policy setting configures the Kerberos client so that it can authenticate with interoperable Kerberos V5 realms, as defined by this policy setting.\r\n \r\nIf you enable this policy setting, you can view and change the list of interoperable Kerberos V5 realms and their settings. To view the list of interoperable Kerberos V5 realms, enable the policy setting and then click the Show button. To add an interoperable Kerberos V5 realm, enable the policy setting, note the syntax, and then click Show. In the Show Contents dialog box in the Value Name column, type the interoperable Kerberos V5 realm name. In the Value column, type the realm flags and host names of the host KDCs using the appropriate syntax format. To remove an interoperable Kerberos V5 realm Value Name or Value entry from the list, click the entry, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.\r\n\r\nIf you disable this policy setting, the interoperable Kerberos V5 realm settings defined by Group Policy are deleted.\r\n\r\nIf you do not configure this policy setting, the system uses the interoperable Kerberos V5 realm settings that are defined in the local registry, if they exist.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-mitrealms"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_mitrealms","displayName":"Define interoperable Kerberos V5 realm settings:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_mitrealms_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_mitrealms_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound","displayName":"Support compound authentication","description":"This policy setting controls configuring the device's Active Directory account for compound authentication.\r\n\r\nSupport for providing compound authentication which is used for access control will require enough domain controllers in the resource account domains to support the requests. The Domain Administrator must configure the policy \"Support Dynamic Access Control and Kerberos armoring\" on all the domain controllers to support this policy.\r\n\r\nIf you enable this policy setting, the device's Active Directory account will be configured for compound authentication by the following options:\r\n\r\nNever: Compound authentication is never provided for this computer account.\r\n\r\nAutomatic: Compound authentication is provided for this computer account when one or more applications are configured for Dynamic Access Control.\r\n\r\nAlways: Compound authentication is always provided for this computer account.\r\n\r\nIf you disable this policy setting, Never will be used.\r\nIf you do not configure this policy setting, Automatic will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-serveracceptscompound"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled","displayName":"Support authorization with client device information:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled_1","displayName":"Automatic","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled_2","displayName":"Always","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_stricttarget","displayName":"Require strict target SPN match on remote procedure calls","description":" This policy setting allows you to configure this server so that Kerberos can decrypt a ticket that contains this system-generated SPN. When an application attempts to make a remote procedure call (RPC) to this server with a NULL value for the service principal name (SPN), computers running Windows 7 or later attempt to use Kerberos by generating an SPN.\r\n \r\nIf you enable this policy setting, only services running as LocalSystem or NetworkService are allowed to accept these connections. Services running as identities different from LocalSystem or NetworkService might fail to authenticate.\r\n\r\nIf you disable or do not configure this policy setting, any service is allowed to accept incoming connections by using this system-generated SPN.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-stricttarget"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_stricttarget_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_stricttarget_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_ciphersuiteorder","displayName":"Cipher suite order","description":"This policy setting determines the cipher suites used by the SMB server.\r\n\r\nIf you enable this policy setting, cipher suites are prioritized in the order specified.\r\n\r\nIf you enable this policy setting and do not specify at least one supported cipher suite, or if you disable or do not configure this policy setting, the default cipher suite order is used.\r\n\r\nSMB 3.11 cipher suites:\r\n\r\nAES_128_GCM\r\nAES_128_CCM\r\n\r\nSMB 3.0 and 3.02 cipher suites:\r\n\r\nAES_128_CCM\r\n\r\nHow to modify this setting:\r\n\r\nArrange the desired cipher suites in the edit box, one cipher suite per line, in order from most to least preferred, with the most preferred cipher suite at the top. Remove any cipher suites you don't want to use.\r\n\r\nNote: When configuring this security setting, changes will not take effect until you restart Windows.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanserver#admx-lanmanserver-pol-ciphersuiteorder"],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_ciphersuiteorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_ciphersuiteorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_ciphersuiteorder_multitext_ciphersuiteorder","displayName":"Cipher suites:","description":null,"helpText":"","infoUrls":[],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication","displayName":"Hash Publication for BranchCache","description":"This policy setting specifies whether a hash generation service generates hashes, also called content information, for data that is stored in shared folders. This policy setting must be applied to server computers that have the File Services role and both the File Server and the BranchCache for Network Files role services installed.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, hash publication settings are not applied to file servers. In the circumstance where file servers are domain members but you do not want to enable BranchCache on all file servers, you can specify Not Configured for this domain Group Policy setting, and then configure local machine policy to enable BranchCache on individual file servers. Because the domain Group Policy setting is not configured, it will not over-write the enabled setting that you use on individual servers where you want to enable BranchCache.\r\n\r\n- Enabled. With this selection, hash publication is turned on for all file servers where Group Policy is applied. For example, if Hash Publication for BranchCache is enabled in domain Group Policy, hash publication is turned on for all domain member file servers to which the policy is applied. The file servers are then able to create content information for all content that is stored in BranchCache-enabled file shares.\r\n\r\n- Disabled. With this selection, hash publication is turned off for all file servers where Group Policy is applied.\r\n\r\nIn circumstances where this policy setting is enabled, you can also select the following configuration options:\r\n\r\n- Allow hash publication for all shared folders. With this option, BranchCache generates content information for all content in all shares on the file server. \r\n\r\n- Allow hash publication only for shared folders on which BranchCache is enabled. With this option, content information is generated only for shared folders on which BranchCache is enabled. If you use this setting, you must enable BranchCache for individual shares in Share and Storage Management on the file server.\r\n\r\n- Disallow hash publication on all shared folders. With this option, BranchCache does not generate content information for any shares on the computer and does not send content information to client computers that request content.\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanserver#admx-lanmanserver-pol-hashpublication"],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo","displayName":"Hash publication actions:","description":null,"helpText":"","infoUrls":[],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo_0","displayName":"Allow hash publication only for shared folders on which BranchCache is enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo_1","displayName":"Disallow hash publication on all shared folders","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo_2","displayName":"Allow hash publication for all shared folders","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion","displayName":"Hash Version support for BranchCache","description":"This policy setting specifies whether the BranchCache hash generation service supports version 1 (V1) hashes, version 2 (V2) hashes, or both V1 and V2 hashes. Hashes, also called content information, are created based on the data in shared folders where BranchCache is enabled. \r\n\r\nIf you specify only one version that is supported, content information for that version is the only type that is generated by BranchCache, and it is the only type of content information that can be retrieved by client computers. For example, if you enable support for V1 hashes, BranchCache generates only V1 hashes and client computers can retrieve only V1 hashes.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy setting. In this circumstance, which is the default, both V1 and V2 hash generation and retrieval are supported.\r\n\r\n- Enabled. With this selection, the policy setting is applied and the hash version(s) that are specified in \"Hash version supported\" are generated and retrieved.\r\n\r\n- Disabled. With this selection, both V1 and V2 hash generation and retrieval are supported.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\nHash version supported:\r\n\r\n- To support V1 content information only, configure \"Hash version supported\" with the value of 1.\r\n\r\n- To support V2 content information only, configure \"Hash version supported\" with the value of 2.\r\n\r\n- To support both V1 and V2 content information, configure \"Hash version supported\" with the value of 3.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanserver#admx-lanmanserver-pol-hashsupportversion"],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion_lbl_hashversionsupportactioncombo","displayName":"Hash version supported:","description":null,"helpText":"","infoUrls":[],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion_lbl_hashversionsupportactioncombo_1","displayName":"Supports V1 hash version only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion_lbl_hashversionsupportactioncombo_2","displayName":"Supports V2 hash version only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion_lbl_hashversionsupportactioncombo_3","displayName":"Supports V1 as well as V2 versions","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_honorciphersuiteorder","displayName":"Honor cipher suite order","description":"This policy setting determines how the SMB server selects a cipher suite when negotiating a new connection with an SMB client.\r\n\r\nIf you enable this policy setting, the SMB server will select the cipher suite it most prefers from the list of client-supported cipher suites, ignoring the client's preferences.\r\n\r\nIf you disable or do not configure this policy setting, the SMB server will select the cipher suite the client most prefers from the list of server-supported cipher suites.\r\n\r\nNote: When configuring this security setting, changes will not take effect until you restart Windows.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanserver#admx-lanmanserver-pol-honorciphersuiteorder"],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_honorciphersuiteorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_honorciphersuiteorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_ciphersuiteorder","displayName":"Cipher suite order","description":"This policy setting determines the cipher suites used by the SMB client.\r\n\r\nIf you enable this policy setting, cipher suites are prioritized in the order specified.\r\n\r\nIf you enable this policy setting and do not specify at least one supported cipher suite, or if you disable or do not configure this policy setting, the default cipher suite order is used.\r\n\r\nSMB 3.11 cipher suites:\r\n\r\nAES_128_GCM\r\nAES_128_CCM\r\n\r\nSMB 3.0 and 3.02 cipher suites:\r\n\r\nAES_128_CCM\r\n\r\nHow to modify this setting:\r\n\r\nArrange the desired cipher suites in the edit box, one cipher suite per line, in order from most to least preferred, with the most preferred cipher suite at the top. Remove any cipher suites you don't want to use.\r\n\r\nNote: When configuring this security setting, changes will not take effect until you restart Windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanworkstation#admx-lanmanworkstation-pol-ciphersuiteorder"],"categoryId":"88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","categoryName":"Lanman Workstation","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_ciphersuiteorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_ciphersuiteorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_ciphersuiteorder_multitext_ciphersuiteorder","displayName":"Cipher suites:","description":null,"helpText":"","infoUrls":[],"categoryId":"88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","categoryName":"Lanman Workstation","options":null},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_enablehandlecachingforcafiles","displayName":"Handle Caching on Continuous Availability Shares","description":"\r\n This policy setting determines the behavior of SMB handle caching for clients connecting to an SMB share where the Continuous Availability (CA) flag is enabled.\r\n\r\n If you enable this policy setting, the SMB client will allow cached handles to files on CA shares. This may lead to better performance when repeatedly accessing a large number of unstructured data files on CA shares running in Microsoft Azure Files.\r\n\r\n If you disable or do not configure this policy setting, Windows will prevent use of cached handles to files opened through CA shares.\r\n\r\n Note: This policy has no effect when connecting Scale-out File Server shares provided by a Windows Server. Microsoft does not recommend enabling this policy for clients that routinely connect to files hosted on a Windows Failover Cluster with the File Server for General Use role, as it can lead to adverse failover times and increased memory and CPU usage.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanworkstation#admx-lanmanworkstation-pol-enablehandlecachingforcafiles"],"categoryId":"88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","categoryName":"Lanman Workstation","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_enablehandlecachingforcafiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_enablehandlecachingforcafiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_enableofflinefilesforcashares","displayName":"Offline Files Availability on Continuous Availability Shares","description":"\r\n This policy setting determines the behavior of Offline Files on clients connecting to an SMB share where the Continuous Availability (CA) flag is enabled.\r\n\r\n If you enable this policy setting, the \"Always Available offline\" option will appear in the File Explorer menu on a Windows computer when connecting to a CA-enabled share. Pinning of files on CA-enabled shares using client-side caching will also be possible.\r\n\r\n If you disable or do not configure this policy setting, Windows will prevent use of Offline Files with CA-enabled shares.\r\n\r\n Note: Microsoft does not recommend enabling this group policy. Use of CA with Offline Files will lead to very long transition times between the online and offline states.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanworkstation#admx-lanmanworkstation-pol-enableofflinefilesforcashares"],"categoryId":"88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","categoryName":"Lanman Workstation","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_enableofflinefilesforcashares_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_enableofflinefilesforcashares_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_leakdiagnostic_wdiscenarioexecutionpolicy","displayName":"Configure Scenario Execution Level","description":"This policy setting determines whether Diagnostic Policy Service (DPS) diagnoses memory leak problems.\r\n\r\nIf you enable or do not configure this policy setting, the DPS enables Windows Memory Leak Diagnosis by default.\r\n\r\nIf you disable this policy setting, the DPS is not able to diagnose memory leak problems.\r\n\r\nThis policy setting takes effect only under the following conditions: \r\n-- If the diagnostics-wide scenario execution policy is not configured. \r\n-- When the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed.\r\n\r\nNote: The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n\r\nNo operating system restart or service restart is required for this policy to take effect. Changes take effect immediately.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-leakdiagnostic#admx-leakdiagnostic-wdiscenarioexecutionpolicy"],"categoryId":"2b54b208-5459-4e40-8db1-002cb90495bc","categoryName":"Windows Memory Leak Diagnosis","options":[{"id":"device_vendor_msft_policy_config_admx_leakdiagnostic_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_leakdiagnostic_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio","displayName":"Turn on Mapper I/O (LLTDIO) driver","description":"This policy setting changes the operational behavior of the Mapper I/O network protocol driver.\r\n\r\nLLTDIO allows a computer to discover the topology of a network it's connected to. It also allows a computer to initiate Quality-of-Service requests such as bandwidth estimation and network health analysis.\r\n\r\nIf you enable this policy setting, additional options are available to fine-tune your selection. You may choose the \"Allow operation while in domain\" option to allow LLTDIO to operate on a network interface that's connected to a managed network. On the other hand, if a network interface is connected to an unmanaged network, you may choose the \"Allow operation while in public network\" and \"Prohibit operation while in private network\" options instead.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior of LLTDIO will apply.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-linklayertopologydiscovery#admx-linklayertopologydiscovery-lltd-enablelltdio"],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowondomain","displayName":"Allow operation while in domain","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowondomain_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowondomain_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowonpublicnet","displayName":"Allow operation while in public network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowonpublicnet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowonpublicnet_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_prohibitonprivatenet","displayName":"Prohibit operation while in private network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_prohibitonprivatenet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_prohibitonprivatenet_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr","displayName":"Turn on Responder (RSPNDR) driver","description":"This policy setting changes the operational behavior of the Responder network protocol driver.\r\n\r\nThe Responder allows a computer to participate in Link Layer Topology Discovery requests so that it can be discovered and located on the network. It also allows a computer to participate in Quality-of-Service activities such as bandwidth estimation and network health analysis.\r\n\r\nIf you enable this policy setting, additional options are available to fine-tune your selection. You may choose the \"Allow operation while in domain\" option to allow the Responder to operate on a network interface that's connected to a managed network. On the other hand, if a network interface is connected to an unmanaged network, you may choose the \"Allow operation while in public network\" and \"Prohibit operation while in private network\" options instead.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior for the Responder will apply.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-linklayertopologydiscovery#admx-linklayertopologydiscovery-lltd-enablerspndr"],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowondomain","displayName":"Allow operation while in domain","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowondomain_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowondomain_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowonpublicnet","displayName":"Allow operation while in public network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowonpublicnet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowonpublicnet_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_prohibitonprivatenet","displayName":"Prohibit operation while in private network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_prohibitonprivatenet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_prohibitonprivatenet_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_locationprovideradm_disablewindowslocationprovider_1","displayName":"Turn off Windows Location Provider","description":"\r\n This policy setting turns off the Windows Location Provider feature for this computer.\r\n\r\n If you enable this policy setting, the Windows Location Provider feature will be turned off, and all programs on this computer will not be able to use the Windows Location Provider feature.\r\n\r\n If you disable or do not configure this policy setting, all programs on this computer can use the Windows Location Provider feature.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-locationprovideradm#admx-locationprovideradm-disablewindowslocationprovider-1"],"categoryId":"3f8986f3-195d-4ee5-ae8d-96a007b20883","categoryName":"Windows Location Provider","options":[{"id":"device_vendor_msft_policy_config_admx_locationprovideradm_disablewindowslocationprovider_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_locationprovideradm_disablewindowslocationprovider_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_blockuserfromshowingaccountdetailsonsignin","displayName":"Block user from showing account details on sign-in","description":"This policy prevents the user from showing account details (email address or user name) on the sign-in screen.\r\n\r\nIf you enable this policy setting, the user cannot choose to show account details on the sign-in screen.\r\n\r\nIf you disable or do not configure this policy setting, the user may choose to show account details on the sign-in screen.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-blockuserfromshowingaccountdetailsonsignin"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_blockuserfromshowingaccountdetailsonsignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_blockuserfromshowingaccountdetailsonsignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_disableacrylicbackgroundonlogon","displayName":"Show clear logon background","description":"This policy setting disables the acrylic blur effect on logon background image.\r\n\r\n If you enable this policy, the logon background image shows without blur.\r\n If you disable or do not configure this policy, the logon background image adopts the acrylic blur effect.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-disableacrylicbackgroundonlogon"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_disableacrylicbackgroundonlogon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_disableacrylicbackgroundonlogon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_disableexplorerrunlegacy_2","displayName":"Do not process the legacy run list","description":"This policy setting ignores the customized run list.\r\n\r\nYou can create a customized list of additional programs and documents that the system starts automatically when it runs on Windows Vista, Windows XP Professional, and Windows 2000 Professional. These programs are added to the standard run list of programs and services that the system starts.\r\n\r\nIf you enable this policy setting, the system ignores the run list for Windows Vista, Windows XP Professional, and Windows 2000 Professional.\r\n\r\nIf you disable or do not configure this policy setting, Windows Vista adds any customized run list configured to its run list.\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy setting in Computer Configuration takes precedence over the policy setting in User Configuration.\r\n\r\nNote: To create a customized run list by using a policy setting, use the \"Run these applications at startup\" policy setting.\r\n\r\nAlso, see the \"Do not process the run once list\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-disableexplorerrunlegacy-2"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_disableexplorerrunlegacy_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_disableexplorerrunlegacy_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_disableexplorerrunoncelegacy_2","displayName":"Do not process the run once list","description":"This policy setting ignores customized run-once lists.\r\n\r\nYou can create a customized list of additional programs and documents that are started automatically the next time the system starts (but not thereafter). These programs are added to the standard list of programs and services that the system starts.\r\n\r\nIf you enable this policy setting, the system ignores the run-once list.\r\n\r\nIf you disable or do not configure this policy setting, the system runs the programs in the run-once list.\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy setting in Computer Configuration takes precedence over the policy setting in User Configuration.\r\n\r\nNote: Customized run-once lists are stored in the registry in HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce.\r\n\r\nAlso, see the \"Do not process the legacy run list\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-disableexplorerrunoncelegacy-2"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_disableexplorerrunoncelegacy_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_disableexplorerrunoncelegacy_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_disablestatusmessages","displayName":"Remove Boot / Shutdown / Logon / Logoff status messages","description":"This policy setting suppresses system status messages.\r\n\r\nIf you enable this setting, the system does not display a message reminding users to wait while their system starts or shuts down, or while users log on or off.\r\n\r\nIf you disable or do not configure this policy setting, the system displays the message reminding users to wait while their system starts or shuts down, or while users log on or off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-disablestatusmessages"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_logon_disablestatusmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_disablestatusmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_dontenumerateconnectedusers","displayName":"Do not enumerate connected users on domain-joined computers","description":"This policy setting prevents connected users from being enumerated on domain-joined computers. \r\n\r\nIf you enable this policy setting, the Logon UI will not enumerate any connected users on domain-joined computers.\r\n\r\nIf you disable or do not configure this policy setting, connected users will be enumerated on domain-joined computers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-dontenumerateconnectedusers"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_dontenumerateconnectedusers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_dontenumerateconnectedusers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_nowelcometips_2","displayName":"Do not display the Getting Started welcome screen at logon","description":"This policy setting hides the welcome screen that is displayed on Windows 2000 Professional each time the user logs on.\r\n\r\nIf you enable this policy setting, the welcome screen is hidden from the user logging on to a computer where this policy is applied.\r\n\r\nUsers can still display the welcome screen by selecting it on the Start menu or by typing \"Welcome\" in the Run dialog box.\r\n\r\nIf you disable or do not configure this policy, the welcome screen is displayed each time a user logs on to the computer.\r\n\r\nThis setting applies only to Windows 2000 Professional. It does not affect the \"Configure Your Server on a Windows 2000 Server\" screen on Windows 2000 Server.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To display the welcome screen, click Start, point to Programs, point to Accessories, point to System Tools, and then click \"Getting Started.\" To suppress the welcome screen without specifying a setting, clear the \"Show this screen at startup\" check box on the welcome screen.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-nowelcometips-2"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_nowelcometips_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_nowelcometips_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_run_2","displayName":"Run these programs at user logon","description":"This policy setting specifies additional programs or documents that Windows starts automatically when a user logs on to the system.\r\n\r\nIf you enable this policy setting, you can specify which programs can run at the time the user logs on to this computer that has this policy applied.\r\n\r\nTo specify values for this policy setting, click Show. In the Show Contents dialog box in the Value column, type the name of the executable program (.exe) file or document file. To specify another name, press ENTER, and type the name. Unless the file is located in the %Systemroot% directory, you must specify the fully qualified path to the file.\r\n\r\nIf you disable or do not configure this policy setting, the user will have to start the appropriate programs after logon.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the system starts the programs specified in the Computer Configuration setting just before it starts the programs specified in the User Configuration setting.\r\n\r\nAlso, see the \"Do not process the legacy run list\" and the \"Do not process the run once list\" settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-run-2"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_run_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_run_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_run_2_runlistbox2","displayName":"Items to run at logon","description":null,"helpText":"","infoUrls":[],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_logon_syncforegroundpolicy","displayName":"Always wait for the network at computer startup and logon","description":"This policy setting determines whether Group Policy processing is synchronous (that is, whether computers wait for the network to be fully initialized during computer startup and user logon). By default, on client computers, Group Policy processing is not synchronous; client computers typically do not wait for the network to be fully initialized at startup and logon. Existing users are logged on using cached credentials, which results in shorter logon times. Group Policy is applied in the background after the network becomes available. \r\n\r\nNote that because this is a background refresh, extensions such as Software Installation and Folder Redirection take two logons to apply changes. To be able to operate safely, these extensions require that no users be logged on. Therefore, they must be processed in the foreground before users are actively using the computer. In addition, changes that are made to the user object, such as adding a roaming profile path, home directory, or user object logon script, may take up to two logons to be detected.\r\n\r\nIf a user with a roaming profile, home directory, or user object logon script logs on to a computer, computers always wait for the network to be initialized before logging the user on. If a user has never logged on to this computer before, computers always wait for the network to be initialized.\r\n\r\nIf you enable this policy setting, computers wait for the network to be fully initialized before users are logged on. Group Policy is applied in the foreground, synchronously. \r\n\r\nOn servers running Windows Server 2008 or later, this policy setting is ignored during Group Policy processing at computer startup and Group Policy processing will be synchronous (these servers wait for the network to be initialized during computer startup). \r\n\r\nIf the server is configured as follows, this policy setting takes effect during Group Policy processing at user logon:\r\n• The server is configured as a terminal server (that is, the Terminal Server role service is installed and configured on the server); and\r\n• The “Allow asynchronous user Group Policy processing when logging on through Terminal Services” policy setting is enabled. This policy setting is located under Computer Configuration\\Policies\\Administrative templates\\System\\Group Policy\\.\r\n\r\nIf this configuration is not implemented on the server, this policy setting is ignored. In this case, Group Policy processing at user logon is synchronous (these servers wait for the network to be initialized during user logon).\r\n\r\nIf you disable or do not configure this policy setting and users log on to a client computer or a server running Windows Server 2008 or later and that is configured as described earlier, the computer typically does not wait for the network to be fully initialized. In this case, users are logged on with cached credentials. Group Policy is applied asynchronously in the background.\r\n\r\nNotes: \r\n-If you want to guarantee the application of Folder Redirection, Software Installation, or roaming user profile settings in just one logon, enable this policy setting to ensure that Windows waits for the network to be available before applying policy. \r\n-If Folder Redirection policy will apply during the next logon, security policies will be applied asynchronously during the next update cycle, if network connectivity is available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-syncforegroundpolicy"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_syncforegroundpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_syncforegroundpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_useoembackground","displayName":"Always use custom logon background","description":"This policy setting ignores Windows Logon Background.\r\n\r\nThis policy setting may be used to make Windows give preference to a custom logon background. \r\n\r\nIf you enable this policy setting, the logon screen always attempts to load a custom background instead of the Windows-branded logon background. \r\n\r\nIf you disable or do not configure this policy setting, Windows uses the default Windows logon background or custom background.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-useoembackground"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_useoembackground_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_useoembackground_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_verbosestatus","displayName":"Display highly detailed status messages","description":"This policy setting directs the system to display highly detailed status messages.\r\n\r\nThis policy setting is designed for advanced users who require this information.\r\n\r\nIf you enable this policy setting, the system displays status messages that reflect each step in the process of starting, shutting down, logging on, or logging off the system.\r\n\r\nIf you disable or do not configure this policy setting, only the default status messages are displayed to the user during these processes.\r\n\r\nNote: This policy setting is ignored if the \"Remove Boot/Shutdown/Logon/Logoff status messages\" policy setting is enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-verbosestatus"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_logon_verbosestatus_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_verbosestatus_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_allowfastservicestartup","displayName":"Allow antimalware service to startup with normal priority","description":"This policy setting controls the load priority for the antimalware service. Increasing the load priority will allow for faster service startup, but may impact performance.\r\n\r\n If you enable or do not configure this setting, the antimalware service will load as a normal priority task.\r\n\r\n If you disable this setting, the antimalware service will load as a low priority task.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-allowfastservicestartup"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_allowfastservicestartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_allowfastservicestartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableantispywaredefender","displayName":"Turn off Microsoft Defender Antivirus","description":"This policy setting turns off Microsoft Defender Antivirus.\r\n \r\n If you enable this policy setting, Microsoft Defender Antivirus does not run, and will not scan computers for malware or other potentially unwanted software.\r\n\r\n If you disable this policy setting, Microsoft Defender Antivirus will run regardless of any other installed antivirus product.\r\n\r\n If you do not configure this policy setting, Windows will internally manage Microsoft Defender Antivirus. If you install another antivirus program, Windows automatically disables Microsoft Defender Antivirus. Otherwise, Microsoft Defender Antivirus will scan your computers for malware and other potentially unwanted software.\r\n\r\n Enabling or disabling this policy may lead to unexpected or unsupported behavior. It is recommended that you leave this policy setting unconfigured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disableantispywaredefender"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableantispywaredefender_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableantispywaredefender_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableautoexclusions","displayName":"Turn off Auto Exclusions","description":"\r\n Allows an administrator to specify if Automatic Exclusions feature for Server SKUs should be turned off.\r\n\r\n Disabled (Default):\r\n Microsoft Defender will exclude pre-defined list of paths from the scan to improve performance.\r\n\r\n Enabled:\r\n Microsoft Defender will not exclude pre-defined list of paths from scans. This can impact machine performance in some scenarios.\r\n\r\n Not configured:\r\n Same as Disabled.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disableautoexclusions"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableautoexclusions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableautoexclusions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableblockatfirstseen","displayName":"Configure the 'Block at First Sight' feature","description":"This feature ensures the device checks in real time with the Microsoft Active Protection Service (MAPS) before allowing certain content to be run or accessed. If this feature is disabled, the check will not occur, which will lower the protection state of the device.\r\n Enabled – The Block at First Sight setting is turned on.\r\n Disabled – The Block at First Sight setting is turned off.\r\n \r\n This feature requires these Group Policy settings to be set as follows:\r\n MAPS -> The “Join Microsoft MAPS” must be enabled or the “Block at First Sight” feature will not function.\r\n MAPS -> The “Send file samples when further analysis is required” should be set to 1 (Send safe samples) or 3 (Send all samples). Setting to 0 (Always Prompt) will lower the protection state of the device. Setting to 2 (Never send) means the “Block at First Sight” feature will not function.\r\n Real-time Protection -> The “Scan all downloaded files and attachments” policy must be enabled or the “Block at First Sight” feature will not function.\r\n Real-time Protection -> Do not enable the “Turn off real-time protection” policy or the “Block at First Sight” feature will not function.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disableblockatfirstseen"],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableblockatfirstseen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableblockatfirstseen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablelocaladminmerge","displayName":"Configure local administrator merge behavior for lists","description":"This policy setting controls whether or not complex list settings configured by a local administrator are merged with Group Policy settings. This setting applies to lists such as threats and Exclusions.\r\n\r\n If you disable or do not configure this setting, unique items defined in Group Policy and in preference settings configured by the local administrator will be merged into the resulting effective policy. In the case of conflicts, Group policy Settings will override preference settings.\r\n\r\n If you enable this setting, only items defined by Group Policy will be used in the resulting effective policy. Group Policy settings will override preference settings configured by the local administrator.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disablelocaladminmerge"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablelocaladminmerge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablelocaladminmerge_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablerealtimemonitoring","displayName":"Turn off real-time protection","description":"This policy setting turns off real-time protection prompts for known malware detection.\r\n\r\n Microsoft Defender Antivirus alerts you when malware or potentially unwanted software attempts to install itself or to run on your computer.\r\n\r\n If you enable this policy setting, Microsoft Defender Antivirus will not prompt users to take actions on malware detections.\r\n\r\n If you disable or do not configure this policy setting, Microsoft Defender Antivirus will prompt users to take actions on malware detections.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disablerealtimemonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablerealtimemonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablerealtimemonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableroutinelytakingaction","displayName":"Turn off routine remediation","description":"\r\n This policy setting allows you to configure whether Microsoft Defender Antivirus automatically takes action on all detected threats. The action to be taken on a particular threat is determined by the combination of the policy-defined action, user-defined action, and the signature-defined action.\r\n\r\n If you enable this policy setting, Microsoft Defender Antivirus does not automatically take action on the detected threats, but prompts users to choose from the actions available for each threat.\r\n\r\n If you disable or do not configure this policy setting, Microsoft Defender Antivirus automatically takes action on all detected threats after a nonconfigurable delay of approximately five seconds.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disableroutinelytakingaction"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableroutinelytakingaction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableroutinelytakingaction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_extensions","displayName":"Extension Exclusions","description":"This policy setting allows you specify a list of file types that should be excluded from scheduled, custom, and real-time scanning. File types should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of the file type extension (such as \"obj\" or \"lib\"). The value is not used and it is recommended that this be set to 0.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exclusions-extensions"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_extensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_extensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_extensions_exclusions_extensionslist","displayName":"Extension Exclusions","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_extensions_exclusions_extensionslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_extensions_exclusions_extensionslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths","displayName":"Path Exclusions","description":"This policy setting allows you to disable scheduled and real-time scanning for files under the paths specified or for the fully qualified resources specified. Paths should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of a path or a fully qualified resource name. As an example, a path might be defined as: \"c:\\Windows\" to exclude all files in this directory. A fully qualified resource name might be defined as: \"C:\\Windows\\App.exe\". The value is not used and it is recommended that this be set to 0.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exclusions-paths"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_exclusions_pathslist","displayName":"Path Exclusions","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_exclusions_pathslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_exclusions_pathslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes","displayName":"Process Exclusions","description":"This policy setting allows you to disable real-time scanning for any file opened by any of the specified processes. This policy does not apply to scheduled scans. The process itself will not be excluded. To exclude the process, use the Path exclusion. Processes should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of the path to the process image. Note that only executables can be excluded. For example, a process might be defined as: \"c:\\windows\\app.exe\". The value is not used and it is recommended that this be set to 0.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exclusions-processes"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_exclusions_processeslist","displayName":"Process Exclusions","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_exclusions_processeslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_exclusions_processeslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_asronlyexclusions","displayName":"Exclude files and paths from Attack Surface Reduction Rules","description":"\r\n Exclude files and paths from Attack Surface Reduction (ASR) rules.\r\n\r\n Enabled:\r\n Specify the folders or files and resources that should be excluded from ASR rules in the Options section.\r\n Enter each rule on a new line as a name-value pair:\r\n - Name column: Enter a folder path or a fully qualified resource name. For example, \"C:\\Windows\" will exclude all files in that directory. \"C:\\Windows\\App.exe\" will exclude only that specific file in that specific folder\r\n - Value column: Enter \"0\" for each item\r\n\r\n Disabled:\r\n No exclusions will be applied to the ASR rules.\r\n\r\n Not configured:\r\n Same as Disabled.\r\n\r\n You can configure ASR rules in the Configure Attack Surface Reduction rules GP setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exploitguard-asr-asronlyexclusions"],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_asronlyexclusions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_asronlyexclusions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_asronlyexclusions_exploitguard_asr_asronlyexclusions","displayName":"Exclusions from ASR rules:","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_asronlyexclusions_exploitguard_asr_asronlyexclusions_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_asronlyexclusions_exploitguard_asr_asronlyexclusions_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules","displayName":"Configure Attack Surface Reduction rules","description":"\r\n Set the state for each Attack Surface Reduction (ASR) rule.\r\n\r\n After enabling this setting, you can set each rule to the following in the Options section:\r\n - Block: the rule will be applied\r\n - Audit Mode: if the rule would normally cause an event, then it will be recorded (although the rule will not actually be applied)\r\n - Off: the rule will not be applied\r\n - Not Configured: the rule is enabled with default values\r\n - Warn: the rule will be applied and the end-user will have the option to bypass the block\r\n\r\n Unless the ASR rule is disabled, a subsample of audit events are collected for ASR rules will the value of not configured.\r\n\r\n Enabled:\r\n Specify the state for each ASR rule under the Options section for this setting.\r\n Enter each rule on a new line as a name-value pair:\r\n - Name column: Enter a valid ASR rule ID\r\n - Value column: Enter the status ID that relates to state you want to specify for the associated rule\r\n\r\n The following status IDs are permitted under the value column:\r\n - 1 (Block)\r\n - 0 (Off)\r\n - 2 (Audit)\r\n - 5 (Not Configured)\r\n - 6 (Warn)\r\n\r\n \r\n Example:\r\n xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx 0\r\n xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx 1\r\n xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx 2\r\n\r\n Disabled:\r\n No ASR rules will be configured.\r\n\r\n Not configured:\r\n Same as Disabled.\r\n\r\n You can exclude folders or files in the \"Exclude files and paths from Attack Surface Reduction Rules\" GP setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exploitguard-asr-rules"],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules_exploitguard_asr_rules","displayName":"Set the state for each ASR rule:","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules_exploitguard_asr_rules_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules_exploitguard_asr_rules_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications","displayName":"Configure allowed applications","description":"\r\n Add additional applications that should be considered \"trusted\" by controlled folder access.\r\n\r\n These applications are allowed to modify or delete files in controlled folder access folders.\r\n\r\n Microsoft Defender Antivirus automatically determines which applications should be trusted. You can configure this setting to add additional applications.\r\n\r\n Enabled: \r\n Specify additional allowed applications in the Options section..\r\n\r\n Disabled:\r\n No additional applications will be added to the trusted list.\r\n\r\n Not configured:\r\n Same as Disabled.\r\n\r\n You can enable controlled folder access in the Configure controlled folder access GP setting.\r\n\r\n Default system folders are automatically guarded, but you can add folders in the configure protected folders GP setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exploitguard-controlledfolderaccess-allowedapplications"],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications_exploitguard_controlledfolderaccess_allowedapplications","displayName":"Enter the applications that should be trusted:","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications_exploitguard_controlledfolderaccess_allowedapplications_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications_exploitguard_controlledfolderaccess_allowedapplications_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders","displayName":"Configure protected folders","description":"\r\n Specify additional folders that should be guarded by the Controlled folder access feature.\r\n\r\n Files in these folders cannot be modified or deleted by untrusted applications.\r\n\r\n Default system folders are automatically protected. You can configure this setting to add additional folders. \r\n The list of default system folders that are protected is shown in Windows Security.\r\n\r\n Enabled:\r\n Specify additional folders that should be protected in the Options section.\r\n\r\n Disabled:\r\n No additional folders will be protected.\r\n\r\n Not configured:\r\n Same as Disabled.\r\n\r\n You can enable controlled folder access in the Configure controlled folder access GP setting.\r\n\r\n Microsoft Defender Antivirus automatically determines which applications can be trusted. You can add additional trusted applications in the Configure allowed applications GP setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exploitguard-controlledfolderaccess-protectedfolders"],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders_exploitguard_controlledfolderaccess_protectedfolders","displayName":"Enter the folders that should be guarded:","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders_exploitguard_controlledfolderaccess_protectedfolders_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders_exploitguard_controlledfolderaccess_protectedfolders_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_mpengine_enablefilehashcomputation","displayName":"Enable file hash computation feature","description":"\r\n Enable or disable file hash computation feature.\r\n\r\n Enabled:\r\n When this feature is enabled Microsoft Defender will compute hash value for files it scans.\r\n\r\n Disabled:\r\n File hash value is not computed\r\n \r\n Not configured:\r\n Same as Disabled.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-mpengine-enablefilehashcomputation"],"categoryId":"adc4eb7f-0f34-4f43-b361-dc42363eccab","categoryName":"Mp Engine","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_mpengine_enablefilehashcomputation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_mpengine_enablefilehashcomputation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_disablesignatureretirement","displayName":"Turn on definition retirement","description":"This policy setting allows you to configure definition retirement for network protection against exploits of known vulnerabilities. Definition retirement checks to see if a computer has the required security updates necessary to protect it against a particular vulnerability. If the system is not vulnerable to the exploit detected by a definition, then that definition is \"retired\". If all security intelligence for a given protocal are retired then that protocol is no longer parsed. Enabling this feature helps to improve performance. On a computer that is up-to-date with all the latest security updates, network protection will have no impact on network performance.\r\n\r\n If you enable or do not configure this setting, definition retirement will be enabled.\r\n\r\n If you disable this setting, definition retirement will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-nis-consumers-ips-disablesignatureretirement"],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_disablesignatureretirement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_disablesignatureretirement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid","displayName":"Specify additional definition sets for network traffic inspection","description":"This policy setting defines additional definition sets to enable for network traffic inspection. Definition set GUIDs should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of a definition set GUID. As an example, the definition set GUID to enable test security intelligence is defined as: “{b54b6ac9-a737-498e-9120-6616ad3bf590}”. The value is not used and it is recommended that this be set to 0.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-nis-consumers-ips-sku-differentiation-signature-set-guid"],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid_nis_consumers_ips_sku_differentiation_signature_set_guidlist","displayName":"Specify additional definition sets for network traffic inspection","description":null,"helpText":"","infoUrls":[],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid_nis_consumers_ips_sku_differentiation_signature_set_guidlist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid_nis_consumers_ips_sku_differentiation_signature_set_guidlist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_disableprotocolrecognition","displayName":"Turn on protocol recognition","description":"This policy setting allows you to configure protocol recognition for network protection against exploits of known vulnerabilities.\r\n\r\n If you enable or do not configure this setting, protocol recognition will be enabled.\r\n\r\n If you disable this setting, protocol recognition will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-nis-disableprotocolrecognition"],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_disableprotocolrecognition_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_disableprotocolrecognition_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass","displayName":"Define addresses to bypass proxy server","description":"This policy, if defined, will prevent antimalware from using the configured proxy server when communicating with the specified IP addresses. The address value should be entered as a valid URL.\r\n\r\n If you enable this setting, the proxy server will be bypassed for the specified addresses.\r\n\r\n If you disable or do not configure this setting, the proxy server will not be bypassed for the specified addresses.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-proxybypass"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass_proxybypass","displayName":"Define addresses to bypass proxy server","description":null,"helpText":"","infoUrls":[],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxypacurl","displayName":"Define proxy auto-config (.pac) for connecting to the network","description":"This policy setting defines the URL of a proxy .pac file that should be used when the client attempts to connect the network for security intelligence updates and MAPS reporting. If the proxy auto-config fails or if there is no proxy auto-config specified, the client will fall back to the alternative options (in order):\r\n 1. Proxy server (if specified)\r\n 2. Proxy .pac URL (if specified)\r\n 3. None\r\n 4. Internet Explorer proxy settings\r\n 5. Autodetect\r\n\r\n If you enable this setting, the proxy setting will be set to use the specified proxy .pac according to the order specified above.\r\n\r\n If you disable or do not configure this setting, the proxy will skip over this fallback step according to the order specified above.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-proxypacurl"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxypacurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxypacurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxypacurl_proxypacurl","displayName":"Define proxy auto-config (.pac) for connecting to the network","description":null,"helpText":"","infoUrls":[],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxyserver","displayName":"Define proxy server for connecting to the network","description":"This policy setting allows you to configure the named proxy that should be used when the client attempts to connect to the network for security intelligence updates and MAPS reporting. If the named proxy fails or if there is no proxy specified, the client will fall back to the alternative options (in order):\r\n 1. Proxy server (if specified)\r\n 2. Proxy .pac URL (if specified)\r\n 3. None\r\n 4. Internet Explorer proxy settings\r\n 5. Autodetect\r\n\r\n If you enable this setting, the proxy will be set to the specified URL according to the order specified above. The URL should be proceeded with either http:// or https://.\r\n\r\n If you disable or do not configure this setting, the proxy will skip over this fallback step according to the order specified above.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-proxyserver"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxyserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxyserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxyserver_proxyserver","displayName":"Define proxy server for connecting to the network","description":null,"helpText":"","infoUrls":[],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_localsettingoverridepurgeitemsafterdelay","displayName":"Configure local setting override for the removal of items from Quarantine folder","description":"This policy setting configures a local override for the configuration of the number of days items should be kept in the Quarantine folder before being removed. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-quarantine-localsettingoverridepurgeitemsafterdelay"],"categoryId":"a004deb8-6f52-4411-8d94-41563a8203fc","categoryName":"Quarantine","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_localsettingoverridepurgeitemsafterdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_localsettingoverridepurgeitemsafterdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_purgeitemsafterdelay","displayName":"Configure removal of items from Quarantine folder","description":"This policy setting defines the number of days items should be kept in the Quarantine folder before being removed.\r\n\r\n If you enable this setting, items will be removed from the Quarantine folder after the number of days specified.\r\n\r\n If you disable or do not configure this setting, items will be kept in the quarantine folder indefinitely and will not be automatically removed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-quarantine-purgeitemsafterdelay"],"categoryId":"a004deb8-6f52-4411-8d94-41563a8203fc","categoryName":"Quarantine","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_purgeitemsafterdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_purgeitemsafterdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_purgeitemsafterdelay_quarantine_purgeitemsafterdelay","displayName":"Configure removal of items from Quarantine folder","description":null,"helpText":"","infoUrls":[],"categoryId":"a004deb8-6f52-4411-8d94-41563a8203fc","categoryName":"Quarantine","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_randomizescheduletasktimes","displayName":"Randomize scheduled task times","description":"This policy setting allows you to enable or disable randomization of the scheduled scan start time and the scheduled security intelligence update start time. This setting is used to distribute the resource impact of scanning. For example, it could be used in guest virtual machines sharing a host, to prevent multiple guest virtual machines from undertaking a disk-intensive operation at the same time.\r\n\r\n If you enable or do not configure this setting, scheduled tasks will begin at a random time within an interval of 4 hours after the specified start time.\r\n\r\n If you disable this setting, scheduled tasks will begin at the specified start time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-randomizescheduletasktimes"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_randomizescheduletasktimes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_randomizescheduletasktimes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablebehaviormonitoring","displayName":"Turn on behavior monitoring","description":"This policy setting allows you to configure behavior monitoring.\r\n\r\n If you enable or do not configure this setting, behavior monitoring will be enabled.\r\n\r\n If you disable this setting, behavior monitoring will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disablebehaviormonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablebehaviormonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablebehaviormonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableioavprotection","displayName":"Scan all downloaded files and attachments","description":"This policy setting allows you to configure scanning for all downloaded files and attachments.\r\n\r\n If you enable or do not configure this setting, scanning for all downloaded files and attachments will be enabled.\r\n\r\n If you disable this setting, scanning for all downloaded files and attachments will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disableioavprotection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableioavprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableioavprotection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableonaccessprotection","displayName":"Monitor file and program activity on your computer","description":"This policy setting allows you to configure monitoring for file and program activity.\r\n\r\n If you enable or do not configure this setting, monitoring for file and program activity will be enabled.\r\n\r\n If you disable this setting, monitoring for file and program activity will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disableonaccessprotection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableonaccessprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableonaccessprotection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablerawwritenotification","displayName":"Turn on raw volume write notifications","description":"This policy setting controls whether raw volume write notifications are sent to behavior monitoring.\r\n\r\n If you enable or do not configure this setting, raw write notifications will be enabled.\r\n\r\n If you disable this setting, raw write notifications be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disablerawwritenotification"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablerawwritenotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablerawwritenotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablescanonrealtimeenable","displayName":"Turn on process scanning whenever real-time protection is enabled","description":"This policy setting allows you to configure process scanning when real-time protection is turned on. This helps to catch malware which could start when real-time protection is turned off.\r\n\r\n If you enable or do not configure this setting, a process scan will be initiated when real-time protection is turned on.\r\n\r\n If you disable this setting, a process scan will not be initiated when real-time protection is turned on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disablescanonrealtimeenable"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablescanonrealtimeenable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablescanonrealtimeenable_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize","displayName":"Define the maximum size of downloaded files and attachments to be scanned","description":"This policy setting defines the maximum size (in kilobytes) of downloaded files and attachments that will be scanned.\r\n\r\n If you enable this setting, downloaded files and attachments smaller than the size specified will be scanned.\r\n\r\n If you disable or do not configure this setting, a default size will be applied.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-ioavmaxsize"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize_realtimeprotection_ioavmaxsize","displayName":"Define the maximum size of downloaded files and attachments to be scanned","description":null,"helpText":"","infoUrls":[],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablebehaviormonitoring","displayName":"Configure local setting override for turn on behavior monitoring","description":"This policy setting configures a local override for the configuration of behavior monitoring. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverridedisablebehaviormonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablebehaviormonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablebehaviormonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableioavprotection","displayName":"Configure local setting override for scanning all downloaded files and attachments","description":"This policy setting configures a local override for the configuration of scanning for all downloaded files and attachments. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverridedisableioavprotection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableioavprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableioavprotection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableonaccessprotection","displayName":"Configure local setting override for monitoring file and program activity on your computer","description":"This policy setting configures a local override for the configuration of monitoring for file and program activity on your computer. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverridedisableonaccessprotection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableonaccessprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableonaccessprotection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablerealtimemonitoring","displayName":"Configure local setting override to turn on real-time protection","description":"This policy setting configures a local override for the configuration to turn on real-time protection. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverridedisablerealtimemonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablerealtimemonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablerealtimemonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverriderealtimescandirection","displayName":"Configure local setting override for monitoring for incoming and outgoing file activity","description":"This policy setting configures a local override for the configuration of monitoring for incoming and outgoing file activity. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverriderealtimescandirection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverriderealtimescandirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverriderealtimescandirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_localsettingoverridescan_scheduletime","displayName":"Configure local setting override for the time of day to run a scheduled full scan to complete remediation","description":"This policy setting configures a local override for the configuration of the time to run a scheduled full scan to complete remediation. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-remediation-localsettingoverridescan-scheduletime"],"categoryId":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","categoryName":"Remediation","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_localsettingoverridescan_scheduletime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_localsettingoverridescan_scheduletime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday","displayName":"Specify the day of the week to run a scheduled full scan to complete remediation","description":"This policy setting allows you to specify the day of the week on which to perform a scheduled full scan in order to complete remediation. The scan can also be configured to run every day or to never run at all.\r\n\r\n This setting can be configured with the following ordinal number values:\r\n (0x0) Every Day\r\n (0x1) Sunday \r\n (0x2) Monday\r\n (0x3) Tuesday\r\n (0x4) Wednesday\r\n (0x5) Thursday\r\n (0x6) Friday\r\n (0x7) Saturday\r\n (0x8) Never (default)\r\n\r\n If you enable this setting, a scheduled full scan to complete remediation will run at the frequency specified.\r\n\r\n If you disable or do not configure this setting, a scheduled full scan to complete remediation will run at a default frequency.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-remediation-scan-scheduleday"],"categoryId":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","categoryName":"Remediation","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday","displayName":"Specify the day of the week to run a scheduled full scan to complete remediation","description":null,"helpText":"","infoUrls":[],"categoryId":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","categoryName":"Remediation","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_8","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_0","displayName":"Every Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_1","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_2","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_3","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_4","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_5","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_6","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_7","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduletime","displayName":"Specify the time of day to run a scheduled full scan to complete remediation","description":"This policy setting allows you to specify the time of day at which to perform a scheduled full scan in order to complete remediation. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. The schedule is based on local time on the computer where the scan is executing.\r\n\r\n If you enable this setting, a scheduled full scan to complete remediation will run at the time of day specified.\r\n\r\n If you disable or do not configure this setting, a scheduled full scan to complete remediation will run at a default time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-remediation-scan-scheduletime"],"categoryId":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","categoryName":"Remediation","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduletime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduletime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduletime_remediation_scan_scheduletime","displayName":"Specify the time of day to run a scheduled full scan to complete remediation","description":null,"helpText":"","infoUrls":[],"categoryId":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","categoryName":"Remediation","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_additionalactiontimeout","displayName":"Configure time out for detections requiring additional action","description":"This policy setting configures the time in minutes before a detection in the \"additional action\" state moves to the \"cleared\" state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-additionalactiontimeout"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_additionalactiontimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_additionalactiontimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_additionalactiontimeout_reporting_additionalactiontimeout","displayName":"Configure time out for detections requiring additional action","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_criticalfailuretimeout","displayName":"Configure time out for detections in critically failed state","description":"This policy setting configures the time in minutes before a detection in the “critically failed” state to moves to either the “additional action” state or the “cleared” state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-criticalfailuretimeout"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_criticalfailuretimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_criticalfailuretimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_criticalfailuretimeout_reporting_criticalfailuretimeout","displayName":"Configure time out for detections in critically failed state","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disableenhancednotifications","displayName":"Turn off enhanced notifications","description":"\r\n Use this policy setting to specify if you want Microsoft Defender Antivirus enhanced notifications to display on clients.\r\n \r\n If you disable or do not configure this setting, Microsoft Defender Antivirus enhanced notifications will display on clients.\r\n \r\n If you enable this setting, Microsoft Defender Antivirus enhanced notifications will not display on clients.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-disableenhancednotifications"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disableenhancednotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disableenhancednotifications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disablegenericreports","displayName":"Configure Watson events","description":"This policy setting allows you to configure whether or not Watson events are sent.\r\n\r\n If you enable or do not configure this setting, Watson events will be sent.\r\n\r\n If you disable this setting, Watson events will not be sent.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-disablegenericreports"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disablegenericreports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disablegenericreports_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_noncriticaltimeout","displayName":"Configure time out for detections in non-critical failed state","description":"This policy setting configures the time in minutes before a detection in the \"non-critically failed\" state moves to the \"cleared\" state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-noncriticaltimeout"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_noncriticaltimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_noncriticaltimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_noncriticaltimeout_reporting_noncriticaltimeout","displayName":"Configure time out for detections in non-critical failed state","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_recentlycleanedtimeout","displayName":"Configure time out for detections in recently remediated state","description":"This policy setting configures the time in minutes before a detection in the \"completed\" state moves to the \"cleared\" state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-recentlycleanedtimeout"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_recentlycleanedtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_recentlycleanedtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_recentlycleanedtimeout_reporting_recentlycleanedtimeout","displayName":"Configure time out for detections in recently remediated state","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracingcomponents","displayName":"Configure Windows software trace preprocessor components","description":"This policy configures Windows software trace preprocessor (WPP Software Tracing) components.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-wpptracingcomponents"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracingcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracingcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracingcomponents_reporting_wpptracingcomponents","displayName":"Configure Windows software trace preprocessor components","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracinglevel","displayName":"Configure WPP tracing level","description":"This policy allows you to configure tracing levels for Windows software trace preprocessor (WPP Software Tracing). \r\n Tracing levels are defined as:\r\n 1 - Error\r\n 2 - Warning\r\n 3 - Info\r\n 4 - Debug\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-wpptracinglevel"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracinglevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracinglevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracinglevel_reporting_wpptracinglevel","displayName":"Configure WPP tracing level","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_allowpause","displayName":"Allow users to pause scan","description":"This policy setting allows you to manage whether or not end users can pause a scan in progress.\r\n\r\n If you enable or do not configure this setting, a new context menu will be added to the task tray icon to allow the user to pause a scan.\r\n\r\n If you disable this setting, users will not be able to pause scans.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-allowpause"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_allowpause_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_allowpause_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxdepth","displayName":"Specify the maximum depth to scan archive files","description":"This policy setting allows you to configure the maximum directory depth level into which archive files such as .ZIP or .CAB are unpacked during scanning. The default directory depth level is 0.\r\n\r\n If you enable this setting, archive files will be scanned to the directory depth level specified.\r\n\r\n If you disable or do not configure this setting, archive files will be scanned to the default directory depth level.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-archivemaxdepth"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxdepth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxdepth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxdepth_scan_archivemaxdepth","displayName":"Specify the maximum depth to scan archive files","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize","displayName":"Specify the maximum size of archive files to be scanned","description":"This policy setting allows you to configure the maximum size of archive files such as .ZIP or .CAB that will be scanned. The value represents file size in kilobytes (KB). The default value is 0 and represents no limit to archive size for scanning.\r\n\r\n If you enable this setting, archive files less than or equal to the size specified will be scanned.\r\n\r\n If you disable or do not configure this setting, archive files will be scanned according to the default value.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-archivemaxsize"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize_scan_archivemaxsize","displayName":"Specify the maximum size of archive files to be scanned","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablearchivescanning","displayName":"Scan archive files","description":"This policy setting allows you to configure scans for malicious software and unwanted software in archive files such as .ZIP or .CAB files.\r\n\r\n If you enable or do not configure this setting, archive files will be scanned.\r\n\r\n If you disable this setting, archive files will not be scanned.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablearchivescanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablearchivescanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablearchivescanning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableemailscanning","displayName":"Turn on e-mail scanning","description":"This policy setting allows you to configure e-mail scanning. When e-mail scanning is enabled, the engine will parse the mailbox and mail files, according to their specific format, in order to analyze the mail bodies and attachments. Several e-mail formats are currently supported, for example: pst (Outlook), dbx, mbx, mime (Outlook Express), binhex (Mac).\r\n\r\n If you enable this setting, e-mail scanning will be enabled.\r\n\r\n If you disable or do not configure this setting, e-mail scanning will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disableemailscanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableemailscanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableemailscanning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableheuristics","displayName":"Turn on heuristics","description":"This policy setting allows you to configure heuristics. Suspicious detections will be suppressed right before reporting to the engine client. Turning off heuristics will reduce the capability to flag new threats. It is recommended that you do not turn off heuristics.\r\n\r\n If you enable or do not configure this setting, heuristics will be enabled.\r\n\r\n If you disable this setting, heuristics will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disableheuristics"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableheuristics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableheuristics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablepackedexescanning","displayName":"Scan packed executables","description":"This policy setting allows you to configure scanning for packed executables. It is recommended that this type of scanning remain enabled.\r\n\r\n If you enable or do not configure this setting, packed executables will be scanned.\r\n\r\n If you disable this setting, packed executables will not be scanned.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablepackedexescanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablepackedexescanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablepackedexescanning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableremovabledrivescanning","displayName":"Scan removable drives","description":"This policy setting allows you to manage whether or not to scan for malicious software and unwanted software in the contents of removable drives, such as USB flash drives, when running a full scan.\r\n\r\n If you enable this setting, removable drives will be scanned during any type of scan.\r\n\r\n If you disable or do not configure this setting, removable drives will not be scanned during a full scan. Removable drives may still be scanned during quick scan and custom scan.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disableremovabledrivescanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableremovabledrivescanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableremovabledrivescanning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablereparsepointscanning","displayName":"Turn on reparse point scanning","description":"This policy setting allows you to configure reparse point scanning. If you allow reparse points to be scanned, there is a possible risk of recursion. However, the engine supports following reparse points to a maximum depth so at worst scanning could be slowed. Reparse point scanning is disabled by default and this is the recommended state for this functionality. \r\n\r\n If you enable this setting, reparse point scanning will be enabled.\r\n\r\n If you disable or do not configure this setting, reparse point scanning will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablereparsepointscanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablereparsepointscanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablereparsepointscanning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablerestorepoint","displayName":"Create a system restore point","description":"This policy setting allows you to create a system restore point on the computer on a daily basis prior to cleaning. \r\n\r\n If you enable this setting, a system restore point will be created.\r\n\r\n If you disable or do not configure this setting, a system restore point will not be created.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablerestorepoint"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablerestorepoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablerestorepoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablescanningmappednetworkdrivesforfullscan","displayName":"Run full scan on mapped network drives","description":"This policy setting allows you to configure scanning mapped network drives.\r\n\r\n If you enable this setting, mapped network drives will be scanned.\r\n\r\n If you disable or do not configure this setting, mapped network drives will not be scanned.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablescanningmappednetworkdrivesforfullscan"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablescanningmappednetworkdrivesforfullscan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablescanningmappednetworkdrivesforfullscan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablescanningnetworkfiles","displayName":"Configure scanning of network files","description":"This policy setting allows you to configure scanning for network files. It is recommended that you do not enable this setting.\r\n\r\n If you enable this setting, network files will be scanned.\r\n\r\n If you disable or do not configure this setting, network files will not be scanned.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablescanningnetworkfiles"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablescanningnetworkfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablescanningnetworkfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideavgcpuloadfactor","displayName":"Configure local setting override for maximum percentage of CPU utilization","description":"This policy setting configures a local override for the configuration of maximum percentage of CPU utilization during scan. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverrideavgcpuloadfactor"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideavgcpuloadfactor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideavgcpuloadfactor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescanparameters","displayName":"Configure local setting override for the scan type to use for a scheduled scan","description":"This policy setting configures a local override for the configuration of the scan type to use during a scheduled scan. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverridescanparameters"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescanparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescanparameters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduleday","displayName":"Configure local setting override for schedule scan day","description":"This policy setting configures a local override for the configuration of scheduled scan day. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverridescheduleday"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduleday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduleday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideschedulequickscantime","displayName":"Configure local setting override for scheduled quick scan time","description":"This policy setting configures a local override for the configuration of scheduled quick scan time. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverrideschedulequickscantime"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideschedulequickscantime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideschedulequickscantime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduletime","displayName":"Configure local setting override for scheduled scan time","description":"This policy setting configures a local override for the configuration of scheduled scan time. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverridescheduletime"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduletime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduletime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_lowcpupriority","displayName":"Configure low CPU priority for scheduled scans","description":"\r\n This policy setting allows you to enable or disable low CPU priority for scheduled scans.\r\n\r\n If you enable this setting, low CPU priority will be used during scheduled scans.\r\n\r\n If you disable or do not configure this setting, not changes will be made to CPU priority for scheduled scans.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-lowcpupriority"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_lowcpupriority_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_lowcpupriority_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_missedscheduledscancountbeforecatchup","displayName":"Define the number of days after which a catch-up scan is forced","description":"\r\n This policy setting allows you to define the number of consecutive scheduled scans that can be missed after which a catch-up scan will be forced. By default, the value of this setting is 2 consecutive scheduled scans.\r\n\r\n If you enable this setting, a catch-up scan will occur after the specified number consecutive missed scheduled scans.\r\n\r\n If you disable or do not configure this setting, a catch-up scan will occur after the 2 consecutive missed scheduled scans.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-missedscheduledscancountbeforecatchup"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_missedscheduledscancountbeforecatchup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_missedscheduledscancountbeforecatchup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_missedscheduledscancountbeforecatchup_scan_missedscheduledscancountbeforecatchup","displayName":"Define the number of scheduled scans that can be missed after which a catch-up scan is forced","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_purgeitemsafterdelay","displayName":"Turn on removal of items from scan history folder","description":"This policy setting defines the number of days items should be kept in the scan history folder before being permanently removed. The value represents the number of days to keep items in the folder. If set to zero, items will be kept forever and will not be automatically removed. By default, the value is set to 30 days.\r\n\r\n If you enable this setting, items will be removed from the scan history folder after the number of days specified.\r\n\r\n If you disable or do not configure this setting, items will be kept in the scan history folder for the default number of days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-purgeitemsafterdelay"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_purgeitemsafterdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_purgeitemsafterdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_purgeitemsafterdelay_scan_purgeitemsafterdelay","displayName":"Turn on removal of items from scan history folder","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_quickscaninterval","displayName":"Specify the interval to run quick scans per day","description":"This policy setting allows you to specify an interval at which to perform a quick scan. The time value is represented as the number of hours between quick scans. Valid values range from 1 (every hour) to 24 (once per day). If set to zero, interval quick scans will not occur. By default, this setting is set to 0.\r\n\r\n If you enable this setting, a quick scan will run at the interval specified.\r\n\r\n If you disable or do not configure this setting, a quick scan will run at a default time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-quickscaninterval"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_quickscaninterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_quickscaninterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_quickscaninterval_scan_quickscaninterval","displayName":"Specify the interval to run quick scans per day","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scanonlyifidle","displayName":"Start the scheduled scan only when computer is on but not in use","description":"This policy setting allows you to configure scheduled scans to start only when your computer is on but not in use.\r\n\r\n If you enable or do not configure this setting, scheduled scans will only run when the computer is on but not in use.\r\n\r\n If you disable this setting, scheduled scans will run at the scheduled time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-scanonlyifidle"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scanonlyifidle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scanonlyifidle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday","displayName":"Specify the day of the week to run a scheduled scan","description":"This policy setting allows you to specify the day of the week on which to perform a scheduled scan. The scan can also be configured to run every day or to never run at all.\r\n\r\n This setting can be configured with the following ordinal number values:\r\n (0x0) Every Day\r\n (0x1) Sunday \r\n (0x2) Monday\r\n (0x3) Tuesday\r\n (0x4) Wednesday\r\n (0x5) Thursday\r\n (0x6) Friday\r\n (0x7) Saturday\r\n (0x8) Never (default)\r\n\r\n If you enable this setting, a scheduled scan will run at the frequency specified.\r\n\r\n If you disable or do not configure this setting, a scheduled scan will run at a default frequency.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-scheduleday"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday","displayName":"Specify the day of the week to run a scheduled scan","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_8","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_0","displayName":"Every Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_1","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_2","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_3","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_4","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_5","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_6","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_7","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduletime","displayName":"Specify the time of day to run a scheduled scan","description":"This policy setting allows you to specify the time of day at which to perform a scheduled scan. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. By default, this setting is set to a time value of 2:00 AM. The schedule is based on local time on the computer where the scan is executing.\r\n\r\n If you enable this setting, a scheduled scan will run at the time of day specified.\r\n\r\n If you disable or do not configure this setting, a scheduled scan will run at a default time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-scheduletime"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduletime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduletime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduletime_scan_scheduletime","displayName":"Specify the time of day to run a scheduled scan","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_servicekeepalive","displayName":"Allow antimalware service to remain running always","description":"This policy setting allows you to configure whether or not the antimalware service remains running when antivirus and antispyware security intelligence is disabled. It is recommended that this setting remain disabled.\r\n\r\n If you enable this setting, the antimalware service will always remain running even if both antivirus and antispyware security intelligence is disabled.\r\n\r\n If you disable or do not configure this setting, the antimalware service will be stopped when both antivirus and antispyware security intelligence is disabled. If the computer is restarted, the service will be started if it is set to Automatic startup. After the service has started, there will be a check to see if antivirus and antispyware security intelligence is enabled. If at least one is enabled, the service will remain running. If both are disabled, the service will be stopped.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-servicekeepalive"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_servicekeepalive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_servicekeepalive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_assignaturedue","displayName":"Define the number of days before spyware security intelligence is considered out of date","description":"This policy setting allows you to define the number of days that must pass before spyware security intelligence is considered out of date. If security intelligence is determined to be out of date, this state may trigger several additional actions, including falling back to an alternative update source or displaying a warning icon in the user interface. By default, this value is set to 7 days.\r\n\r\n If you enable this setting, spyware security intelligence will be considered out of date after the number of days specified have passed without an update.\r\n\r\n If you disable or do not configure this setting, spyware security intelligence will be considered out of date after the default number of days have passed without an update.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-assignaturedue"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_assignaturedue_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_assignaturedue_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_assignaturedue_signatureupdate_assignaturedue","displayName":"Define the number of days before spyware security intelligence is considered out of date","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_avsignaturedue","displayName":"Define the number of days before virus security intelligence is considered out of date","description":"This policy setting allows you to define the number of days that must pass before virus security intelligence is considered out of date. If security intelligence is determined to be out of date, this state may trigger several additional actions, including falling back to an alternative update source or displaying a warning icon in the user interface. By default, this value is set to 7 days.\r\n\r\n If you enable this setting, virus security intelligence will be considered out of date after the number of days specified have passed without an update.\r\n\r\n If you disable or do not configure this setting, virus security intelligence will be considered out of date after the default number of days have passed without an update.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-avsignaturedue"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_avsignaturedue_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_avsignaturedue_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_avsignaturedue_signatureupdate_avsignaturedue","displayName":"Define the number of days before virus security intelligence is considered out of date","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_definitionupdatefilesharessources","displayName":"Define file shares for downloading security intelligence updates","description":"This policy setting allows you to configure UNC file share sources for downloading security intelligence updates. Sources will be contacted in the order specified. The value of this setting should be entered as a pipe-separated string enumerating the security intelligence update sources. For example: \"{\\\\unc1 | \\\\unc2 }\". The list is empty by default.\r\n\r\n If you enable this setting, the specified sources will be contacted for security intelligence updates. Once security intelligence updates have been successfully downloaded from one specified source, the remaining sources in the list will not be contacted.\r\n\r\n If you disable or do not configure this setting, the list will remain empty by default and no sources will be contacted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-definitionupdatefilesharessources"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_definitionupdatefilesharessources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_definitionupdatefilesharessources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_definitionupdatefilesharessources_signatureupdate_definitionupdatefilesharessources","displayName":"Define file shares for downloading security intelligence updates","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescanonupdate","displayName":"Turn on scan after security intelligence update","description":"This policy setting allows you to configure the automatic scan which starts after a security intelligence update has occurred.\r\n\r\n If you enable or do not configure this setting, a scan will start following a security intelligence update.\r\n\r\n If you disable this setting, a scan will not start following a security intelligence update.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-disablescanonupdate"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescanonupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescanonupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescheduledsignatureupdateonbattery","displayName":"Allow security intelligence updates when running on battery power","description":"This policy setting allows you to configure security intelligence updates when the computer is running on battery power.\r\n\r\n If you enable or do not configure this setting, security intelligence updates will occur as usual regardless of power state.\r\n\r\n If you disable this setting, security intelligence updates will be turned off while the computer is running on battery power.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-disablescheduledsignatureupdateonbattery"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescheduledsignatureupdateonbattery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescheduledsignatureupdateonbattery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disableupdateonstartupwithoutengine","displayName":"Initiate security intelligence update on startup","description":"This policy setting allows you to configure security intelligence updates on startup when there is no antimalware engine present.\r\n\r\n If you enable or do not configure this setting, security intelligence updates will be initiated on startup when there is no antimalware engine present.\r\n\r\n If you disable this setting, security intelligence updates will not be initiated on startup when there is no antimalware engine present.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-disableupdateonstartupwithoutengine"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disableupdateonstartupwithoutengine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disableupdateonstartupwithoutengine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder","displayName":"Define the order of sources for downloading security intelligence updates","description":"This policy setting allows you to define the order in which different security intelligence update sources should be contacted. The value of this setting should be entered as a pipe-separated string enumerating the security intelligence update sources in order. Possible values are: “InternalDefinitionUpdateServer”, “MicrosoftUpdateServer”, “MMPC”, and “FileShares”\r\n\r\n For example: { InternalDefinitionUpdateServer | MicrosoftUpdateServer | MMPC }\r\n\r\n If you enable this setting, security intelligence update sources will be contacted in the order specified. Once security intelligence updates have been successfully downloaded from one specified source, the remaining sources in the list will not be contacted.\r\n\r\n If you disable or do not configure this setting, security intelligence update sources will be contacted in a default order.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-fallbackorder"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder_signatureupdate_fallbackorder","displayName":"Define the order of sources for downloading security intelligence updates","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_forceupdatefrommu","displayName":"Allow security intelligence updates from Microsoft Update","description":"This policy setting allows you to enable download of security intelligence updates from Microsoft Update even if the Automatic Updates default server is configured to another download source such as Windows Update.\r\n\r\n If you enable this setting, security intelligence updates will be downloaded from Microsoft Update.\r\n\r\n If you disable or do not configure this setting, security intelligence updates will be downloaded from the configured download source.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-forceupdatefrommu"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_forceupdatefrommu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_forceupdatefrommu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_realtimesignaturedelivery","displayName":"Allow real-time security intelligence updates based on reports to Microsoft MAPS","description":"This policy setting allows you to enable real-time security intelligence updates in response to reports sent to Microsoft MAPS. If the service reports a file as an unknown and Microsoft MAPS finds that the latest security intelligence update has security intelligence for a threat involving that file, the service will receive all of the latest security intelligence for that threat immediately. You must have configured your computer to join Microsoft MAPS for this functionality to work.\r\n\r\n If you enable or do not configure this setting, real-time security intelligence updates will be enabled.\r\n\r\n If you disable this setting, real-time security intelligence updates will disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-realtimesignaturedelivery"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_realtimesignaturedelivery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_realtimesignaturedelivery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday","displayName":"Specify the day of the week to check for security intelligence updates","description":"This policy setting allows you to specify the day of the week on which to check for security intelligence updates. The check can also be configured to run every day or to never run at all.\r\n\r\n This setting can be configured with the following ordinal number values:\r\n (0x0) Every Day (default)\r\n (0x1) Sunday \r\n (0x2) Monday\r\n (0x3) Tuesday\r\n (0x4) Wednesday\r\n (0x5) Thursday\r\n (0x6) Friday\r\n (0x7) Saturday\r\n (0x8) Never\r\n\r\n If you enable this setting, the check for security intelligence updates will occur at the frequency specified.\r\n\r\n If you disable or do not configure this setting, the check for security intelligence updates will occur at a default frequency.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-scheduleday"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday","displayName":"Specify the day of the week to check for security intelligence updates","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_8","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_0","displayName":"Every Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_1","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_2","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_3","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_4","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_5","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_6","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_7","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduletime","displayName":"Specify the time to check for security intelligence updates","description":"This policy setting allows you to specify the time of day at which to check for security intelligence updates. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. By default this setting is configured to check for security intelligence updates 15 minutes before the scheduled scan time. The schedule is based on local time on the computer where the check is occurring.\r\n\r\n If you enable this setting, the check for security intelligence updates will occur at the time of day specified.\r\n\r\n If you disable or do not configure this setting, the check for security intelligence updates will occur at the default time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-scheduletime"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduletime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduletime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduletime_signatureupdate_scheduletime","displayName":"Specify the time to check for security intelligence updates","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation","displayName":"Define security intelligence location for VDI clients.","description":"This policy setting allows you to define the security intelligence location for VDI-configured computers. \r\n\r\n If you disable or do not configure this setting, security intelligence will be referred from the default local source.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-sharedsignatureslocation"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation_signatureupdate_sharedsignatureslocation","displayName":"Define file share for downloading security intelligence updates in virtual environments","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signaturedisablenotification","displayName":"Allow notifications to disable security intelligence based reports to Microsoft MAPS","description":"This policy setting allows you to configure the antimalware service to receive notifications to disable individual security intelligence in response to reports it sends to Microsoft MAPS. Microsoft MAPS uses these notifications to disable security intelligence that are causing false positive reports. You must have configured your computer to join Microsoft MAPS for this functionality to work.\r\n\r\n If you enable this setting or do not configure, the antimalware service will receive notifications to disable security intelligence.\r\n\r\n If you disable this setting, the antimalware service will not receive notifications to disable security intelligence.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-signaturedisablenotification"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signaturedisablenotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signaturedisablenotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signatureupdatecatchupinterval","displayName":"Define the number of days after which a catch-up security intelligence update is required","description":"This policy setting allows you to define the number of days after which a catch-up security intelligence update will be required. By default, the value of this setting is 1 day.\r\n\r\n If you enable this setting, a catch-up security intelligence update will occur after the specified number of days.\r\n\r\n If you disable or do not configure this setting, a catch-up security intelligence update will be required after the default number of days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-signatureupdatecatchupinterval"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signatureupdatecatchupinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signatureupdatecatchupinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signatureupdatecatchupinterval_signatureupdate_signatureupdatecatchupinterval","displayName":"Define the number of days after which a catch-up security intelligence update is required","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_updateonstartup","displayName":"Check for the latest virus and spyware security intelligence on startup","description":"This policy setting allows you to manage whether a check for new virus and spyware security intelligence will occur immediately after service startup.\r\n\r\n If you enable this setting, a check for new security intelligence will occur after service startup.\r\n\r\n If you disable this setting or do not configure this setting, a check for new security intelligence will not occur after service startup.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-updateonstartup"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_updateonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_updateonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynet_localsettingoverridespynetreporting","displayName":"Configure local setting override for reporting to Microsoft MAPS","description":"This policy setting configures a local override for the configuration to join Microsoft MAPS. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-spynet-localsettingoverridespynetreporting"],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynet_localsettingoverridespynetreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynet_localsettingoverridespynetreporting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting","displayName":"Join Microsoft MAPS","description":"This policy setting allows you to join Microsoft MAPS. Microsoft MAPS is the online community that helps you choose how to respond to potential threats. The community also helps stop the spread of new malicious software infections.\r\n\r\n You can choose to send basic or additional information about detected software. Additional information helps Microsoft create new security intelligence and help it to protect your computer. This information can include things like location of detected items on your computer if harmful software was removed. The information will be automatically collected and sent. In some instances, personal information might unintentionally be sent to Microsoft. However, Microsoft will not use this information to identify you or contact you.\r\n\r\n Possible options are:\r\n (0x0) Disabled (default)\r\n (0x1) Basic membership\r\n (0x2) Advanced membership\r\n\r\n Basic membership will send basic information to Microsoft about software that has been detected, including where the software came from, the actions that you apply or that are applied automatically, and whether the actions were successful.\r\n\r\n Advanced membership, in addition to basic information, will send more information to Microsoft about malicious software, spyware, and potentially unwanted software, including the location of the software, file names, how the software operates, and how it has impacted your computer.\r\n\r\n If you enable this setting, you will join Microsoft MAPS with the membership specified.\r\n\r\n If you disable or do not configure this setting, you will not join Microsoft MAPS.\r\n \r\n In Windows 10, Basic membership is no longer available, so setting the value to 1 or 2 enrolls the device into Advanced membership.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-spynetreporting"],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting","displayName":"Join Microsoft MAPS","description":null,"helpText":"","infoUrls":[],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting_1","displayName":"Basic MAPS","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting_2","displayName":"Advanced MAPS","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction","displayName":"Specify threats upon which default action should not be taken when detected","description":"This policy setting customize which remediation action will be taken for each listed Threat ID when it is detected during a scan. Threats should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defines a valid Threat ID, while the value contains the action ID for the remediation action that should be taken.\r\n\r\n Valid remediation action values are:\r\n 2 = Quarantine\r\n 3 = Remove\r\n 6 = Ignore\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-threats-threatiddefaultaction"],"categoryId":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","categoryName":"Threats","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction_threats_threatiddefaultactionlist","displayName":"Specify threats upon which default action should not be taken when detected","description":null,"helpText":"","infoUrls":[],"categoryId":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","categoryName":"Threats","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction_threats_threatiddefaultactionlist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","categoryName":"Threats","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction_threats_threatiddefaultactionlist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","categoryName":"Threats","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_customdefaultactiontoaststring","displayName":"Display additional text to clients when they need to perform an action","description":"This policy setting allows you to configure whether or not to display additional text to clients when they need to perform an action. The text displayed is a custom administrator-defined string. For example, the phone number to call the company help desk. The client interface will only display a maximum of 1024 characters. Longer strings will be truncated before display.\r\n\r\n If you enable this setting, the additional text specified will be displayed.\r\n\r\n If you disable or do not configure this setting, there will be no additional text displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-ux-configuration-customdefaultactiontoaststring"],"categoryId":"a5060182-4d22-412b-bd0e-3a1e009b36c6","categoryName":"Client Interface","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_customdefaultactiontoaststring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_customdefaultactiontoaststring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_customdefaultactiontoaststring_ux_configuration_customdefaultactiontoaststring","displayName":"Display additional text to clients when they need to perform an action","description":null,"helpText":"","infoUrls":[],"categoryId":"a5060182-4d22-412b-bd0e-3a1e009b36c6","categoryName":"Client Interface","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_notification_suppress","displayName":"Suppress all notifications","description":"Use this policy setting to specify if you want Microsoft Defender Antivirus notifications to display on clients.\r\n If you disable or do not configure this setting, Microsoft Defender Antivirus notifications will display on clients.\r\n\r\n If you enable this setting, Microsoft Defender Antivirus notifications will not display on clients.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-ux-configuration-notification-suppress"],"categoryId":"a5060182-4d22-412b-bd0e-3a1e009b36c6","categoryName":"Client Interface","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_notification_suppress_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_notification_suppress_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_suppressrebootnotification","displayName":"Suppresses reboot notifications","description":"\r\n This policy setting allows user to supress reboot notifications in UI only mode (for cases where UI can't be in lockdown mode).\r\n\r\n If you enable this setting AM UI won't show reboot notifications.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-ux-configuration-suppressrebootnotification"],"categoryId":"a5060182-4d22-412b-bd0e-3a1e009b36c6","categoryName":"Client Interface","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_suppressrebootnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_suppressrebootnotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_uilockdown","displayName":"Enable headless UI mode","description":"\r\n This policy setting allows you to configure whether or not to display AM UI to the users.\r\n If you enable this setting AM UI won't be available to users.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-ux-configuration-uilockdown"],"categoryId":"a5060182-4d22-412b-bd0e-3a1e009b36c6","categoryName":"Client Interface","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_uilockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_uilockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mobilepcmobilitycenter_mobilitycenterenable_2","displayName":"Turn off Windows Mobility Center","description":"This policy setting turns off Windows Mobility Center.\r\n\r\nIf you enable this policy setting, the user is unable to invoke Windows Mobility Center. The Windows Mobility Center UI is removed from all shell entry points and the .exe file does not launch it.\r\n\r\nIf you disable this policy setting, the user is able to invoke Windows Mobility Center and the .exe file launches it.\r\n\r\nIf you do not configure this policy setting, Windows Mobility Center is on by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mobilepcmobilitycenter#admx-mobilepcmobilitycenter-mobilitycenterenable-2"],"categoryId":"1ed9f90e-d8b6-413f-bfc2-face955141bc","categoryName":"Windows Mobility Center","options":[{"id":"device_vendor_msft_policy_config_admx_mobilepcmobilitycenter_mobilitycenterenable_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mobilepcmobilitycenter_mobilitycenterenable_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mobilepcpresentationsettings_presentationsettingsenable_2","displayName":"Turn off Windows presentation settings","description":"This policy setting turns off Windows presentation settings.\r\n\r\nIf you enable this policy setting, Windows presentation settings cannot be invoked.\r\n\r\nIf you disable this policy setting, Windows presentation settings can be invoked. The presentation settings icon will be displayed in the notification area. This will give users a quick and easy way to configure their system settings before a presentation to block system notifications and screen blanking, adjust speaker volume, and apply a custom background image.\r\n\r\nNote: Users will be able to customize their system settings for presentations in Windows Mobility Center.\r\n\r\nIf you do not configure this policy setting, Windows presentation settings can be invoked.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mobilepcpresentationsettings#admx-mobilepcpresentationsettings-presentationsettingsenable-2"],"categoryId":"751cf9ec-7214-4b38-a09e-24922684bd8f","categoryName":"Presentation Settings","options":[{"id":"device_vendor_msft_policy_config_admx_mobilepcpresentationsettings_presentationsettingsenable_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mobilepcpresentationsettings_presentationsettingsenable_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msapolicy_microsoftaccount_disableuserauth","displayName":"Block all consumer Microsoft account user authentication","description":"This setting controls whether users can provide Microsoft accounts for authentication for applications or services. If this setting is enabled, all applications and services on the device are prevented from using Microsoft accounts for authentication. \r\nThis applies both to existing users of a device and new users who may be added. However, any application or service that has already authenticated a user will not be affected by enabling this setting until the authentication cache expires. \r\nIt is recommended to enable this setting before any user signs in to a device to prevent cached tokens from being present. If this setting is disabled or not configured, applications and services can use Microsoft accounts for authentication. \r\nBy default, this setting is Disabled. This setting does not affect whether users can sign in to devices by using Microsoft accounts, or the ability for users to provide Microsoft accounts via the browser for authentication with web-based applications. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msapolicy#admx-msapolicy-microsoftaccount-disableuserauth"],"categoryId":"60b898a9-0490-4599-b7f1-3cd451236266","categoryName":"Microsoft account","options":[{"id":"device_vendor_msft_policy_config_admx_msapolicy_microsoftaccount_disableuserauth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msapolicy_microsoftaccount_disableuserauth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy","displayName":"Automatic Maintenance Activation Boundary","description":"\r\n This policy setting allows you to configure Automatic Maintenance activation boundary.\r\n\r\n The maintenance activation boundary is the daily schduled time at which Automatic Maintenance starts\r\n\r\n If you enable this policy setting, this will override the default daily scheduled time as specified in Security and Maintenance/Automatic Maintenance Control Panel.\r\n\r\n If you disable or do not configure this policy setting, the daily scheduled time as specified in Security and Maintenance/Automatic Maintenance Control Panel will apply.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msched#admx-msched-activationboundarypolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy_activationboundary","displayName":"Regular maintenance activation boundary","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_msched_randomdelaypolicy","displayName":"Automatic Maintenance Random Delay","description":"\r\n This policy setting allows you to configure Automatic Maintenance activation random delay.\r\n\r\n The maintenance random delay is the amount of time up to which Automatic Maintenance will delay starting from its Activation Boundary.\r\n\r\n If you enable this policy setting, Automatic Maintenance will delay starting from its Activation Boundary, by upto this time.\r\n\r\n If you do not configure this policy setting, 4 hour random delay will be applied to Automatic Maintenance.\r\n\r\n If you disable this policy setting, no random delay will be applied to Automatic Maintenance.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msched#admx-msched-randomdelaypolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_msched_randomdelaypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msched_randomdelaypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msched_randomdelaypolicy_randomdelay","displayName":"Regular maintenance random delay","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdtsupportprovider","displayName":"Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider","description":"This policy setting configures Microsoft Support Diagnostic Tool (MSDT) interactive communication with the support provider. MSDT gathers diagnostic data for analysis by support professionals.\r\n\r\nIf you enable this policy setting, users can use MSDT to collect and send diagnostic data to a support professional to resolve a problem.\r\n\r\nBy default, the support provider is set to Microsoft Corporation.\r\n\r\nIf you disable this policy setting, MSDT cannot run in support mode, and no data can be collected or sent to the support provider.\r\n\r\nIf you do not configure this policy setting, MSDT support mode is enabled by default.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect. Changes take effect immediately.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msdt#admx-msdt-msdtsupportprovider"],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_msdtsupportprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdtsupportprovider_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy","displayName":"Microsoft Support Diagnostic Tool: Restrict tool download","description":"This policy setting restricts the tool download policy for Microsoft Support Diagnostic Tool.\r\n\r\nMicrosoft Support Diagnostic Tool (MSDT) gathers diagnostic data for analysis by support professionals. For some problems, MSDT may prompt the user to download additional tools for troubleshooting.\r\n\r\nThese tools are required to completely troubleshoot the problem. If tool download is restricted, it may not be possible to find the root cause of the problem.\r\n\r\nIf you enable this policy setting for remote troubleshooting, MSDT prompts the user to download additional tools to diagnose problems on remote computers only. If you enable this policy setting for local and remote troubleshooting, MSDT always prompts for additional tool downloading.\r\n\r\nIf you disable this policy setting, MSDT never downloads tools, and is unable to diagnose problems on remote computers.\r\n\r\nIf you do not configure this policy setting, MSDT prompts the user before downloading any additional tools.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect. Changes take effect immediately.\r\n\r\nThis policy setting will take effect only when MSDT is enabled.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msdt#admx-msdt-msdttooldownloadpolicy"],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_msdttooldownloadpolicylevel","displayName":"Tool downloads allowed","description":null,"helpText":"","infoUrls":[],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_msdttooldownloadpolicylevel_1","displayName":"Remote troubleshooting only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_msdttooldownloadpolicylevel_2","displayName":"Local and remote troubleshooting","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msdt_wdiscenarioexecutionpolicy","displayName":"Microsoft Support Diagnostic Tool: Configure execution level","description":"This policy setting determines the execution level for Microsoft Support Diagnostic Tool.\r\n\r\nMicrosoft Support Diagnostic Tool (MSDT) gathers diagnostic data for analysis by support professionals.\r\n\r\nIf you enable this policy setting, administrators can use MSDT to collect and send diagnostic data to a support professional to resolve a problem.\r\n\r\nIf you disable this policy setting, MSDT cannot gather diagnostic data.\r\n\r\nIf you do not configure this policy setting, MSDT is turned on by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect. Changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msdt#admx-msdt-wdiscenarioexecutionpolicy"],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownbrowse","displayName":"Allow users to browse for source while elevated","description":"This policy setting allows users to search for installation files during privileged installations.\r\n\r\nIf you enable this policy setting, the Browse button in the \"Use feature from\" dialog box is enabled. As a result, users can search for installation files even when the installation program is running with elevated system privileges.\r\n\r\nBecause the installation is running with elevated system privileges, users can browse through directories that their own permissions would not allow.\r\n\r\nThis policy setting does not affect installations that run in the user's security context. Also, see the \"Remove browse dialog box for new source\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, by default, only system administrators can browse during installations with elevated privileges, such as installations offered on the desktop or displayed in Add or Remove Programs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-allowlockdownbrowse"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownbrowse_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownbrowse_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownmedia","displayName":"Allow users to use media source while elevated","description":"This policy setting allows users to install programs from removable media during privileged installations.\r\n\r\nIf you enable this policy setting, all users are permitted to install programs from removable media, such as floppy disks and CD-ROMs, even when the installation program is running with elevated system privileges.\r\n\r\nThis policy setting does not affect installations that run in the user's security context. By default, users can install from removable media when the installation runs in their own security context.\r\n\r\nIf you disable or do not configure this policy setting, by default, users can install programs from removable media only when the installation runs in the user's security context. During privileged installations, such as those offered on the desktop or displayed in Add or Remove Programs, only system administrators can install from removable media.\r\n\r\nAlso, see the \"Prevent removable media source for any install\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-allowlockdownmedia"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownmedia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownmedia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownpatch","displayName":"Allow users to patch elevated products","description":"This policy setting allows users to patch elevated products.\r\n\r\nIf you enable this policy setting, all users are permitted to install patches, even when the installation program is running with elevated system privileges. Patches are updates or upgrades that replace only those program files that have changed. Because patches can easily be vehicles for malicious programs, some installations prohibit their use.\r\n\r\nIf you disable or do not configure this policy setting, by default, only system administrators can apply patches during installations with elevated privileges, such as installations offered on the desktop or displayed in Add or Remove Programs.\r\n\r\nThis policy setting does not affect installations that run in the user's security context. By default, users can install patches to programs that run in their own security context. Also, see the \"Prohibit patching\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-allowlockdownpatch"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownpatch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownpatch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown","displayName":"Prohibit use of Restart Manager","description":"This policy setting controls Windows Installer's interaction with the Restart Manager. The Restart Manager API can eliminate or reduce the number of system restarts that are required to complete an installation or update.\r\n\r\nIf you enable this policy setting, you can use the options in the Prohibit Use of Restart Manager box to control file in use detection behavior.\r\n\r\n-- The \"Restart Manager On\" option instructs Windows Installer to use Restart Manager to detect files in use and mitigate a system restart, when possible.\r\n\r\n-- The \"Restart Manager Off\" option turns off Restart Manager for file in use detection and the legacy file in use behavior is used.\r\n\r\n-- The \"Restart Manager Off for Legacy App Setup\" option applies to packages that were created for Windows Installer versions lesser than 4.0. This option lets those packages display the legacy files in use UI while still using Restart Manager for detection.\r\n\r\nIf you disable or do not configure this policy setting, Windows Installer will use Restart Manager to detect files in use and mitigate a system restart, when possible.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disableautomaticapplicationshutdown"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_disableautomaticapplicationshutdown","displayName":"Prohibit Usage of Restart Manager","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_disableautomaticapplicationshutdown_0","displayName":"Restart Manager On","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_disableautomaticapplicationshutdown_1","displayName":"Restart Manager Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_disableautomaticapplicationshutdown_2","displayName":"Restart Manager Off for Legacy App Setup","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disablebrowse","displayName":"Remove browse dialog box for new source","description":"\r\n This policy setting prevents users from searching for installation files when they add features or components to an installed program.\r\n\r\n If you enable this policy setting, the Browse button beside the \"Use feature from\" list in the Windows Installer dialog box is disabled. As a result, users must select an installation file source from the \"Use features from\" list that the system administrator configures.\r\n\r\n This policy setting applies even when the installation is running in the user's security context.\r\n\r\n If you disable or do not configure this policy setting, the Browse button is enabled when an installation is running in the user's security context. But only system administrators can browse when an installation is running with elevated system privileges, such as installations offered on the desktop or in Add or Remove Programs.\r\n\r\n This policy setting affects Windows Installer only. It does not prevent users from selecting other browsers, such as File Explorer or Network Locations, to search for installation files.\r\n\r\n Also, see the \"Enable user to browse for source while elevated\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablebrowse"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablebrowse_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablebrowse_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disableflyweightpatching","displayName":"Prohibit flyweight patching","description":"This policy setting controls the ability to turn off all patch optimizations.\r\n\r\nIf you enable this policy setting, all Patch Optimization options are turned off during the installation.\r\n\r\nIf you disable or do not configure this policy setting, it enables faster application of patches by removing execution of unnecessary actions. The flyweight patching mode is primarily designed for patches that just update a few files or registry values. The Installer will analyze the patch for specific changes to determine if optimization is possible. If so, the patch will be applied using a minimal set of processing.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disableflyweightpatching"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableflyweightpatching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableflyweightpatching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disableflyweightpatching_disableflyweightpatching","displayName":"Prohibit Flyweight Patching","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableflyweightpatching_disableflyweightpatching_1","displayName":"Patch Optimization Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableflyweightpatching_disableflyweightpatching_0","displayName":"Patch Optimization On","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage","displayName":"Turn off logging via package settings","description":"This policy setting controls Windows Installer's processing of the MsiLogging property. The MsiLogging property in an installation package can be used to enable automatic logging of all install operations for the package.\r\n\r\nIf you enable this policy setting, you can use the options in the Disable logging via package settings box to control automatic logging via package settings behavior.\r\n\r\n-- The \"Logging via package settings on\" option instructs Windows Installer to automatically generate log files for packages that include the MsiLogging property.\r\n\r\n-- The \"Logging via package settings off\" option turns off the automatic logging behavior when specified via the MsiLogging policy. Log files can still be generated using the logging command line switch or the Logging policy.\r\n\r\nIf you disable or do not configure this policy setting, Windows Installer will automatically generate log files for those packages that include the MsiLogging property.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disableloggingfrompackage"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_disableloggingfrompackage","displayName":"Disable logging via package settings","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_disableloggingfrompackage_1","displayName":"Disable logging via package settings off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_disableloggingfrompackage_0","displayName":"Disable logging via package settings on","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi","displayName":"Turn off Windows Installer","description":"This policy setting restricts the use of Windows Installer.\r\n\r\nIf you enable this policy setting, you can prevent users from installing software on their systems or permit users to install only those programs offered by a system administrator. You can use the options in the Disable Windows Installer box to establish an installation setting.\r\n\r\n-- The \"Never\" option indicates Windows Installer is fully enabled. Users can install and upgrade software. This is the default behavior for Windows Installer on Windows 2000 Professional, Windows XP Professional and Windows Vista when the policy is not configured.\r\n\r\n-- The \"For non-managed applications only\" option permits users to install only those programs that a system administrator assigns (offers on the desktop) or publishes (adds them to Add or Remove Programs). This is the default behavior of Windows Installer on Windows Server 2003 family when the policy is not configured.\r\n\r\n-- The \"Always\" option indicates that Windows Installer is disabled.\r\n\r\nThis policy setting affects Windows Installer only. It does not prevent users from using other methods to install and upgrade programs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablemsi"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_disablemsi","displayName":"Disable Windows Installer","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_disablemsi_2","displayName":"Always","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_disablemsi_1","displayName":"For non-managed applications only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_disablemsi_0","displayName":"Never","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disablepatch","displayName":"Prevent users from using Windows Installer to install updates and upgrades","description":"This policy setting prevents users from using Windows Installer to install patches.\r\n\r\nIf you enable this policy setting, users are prevented from using Windows Installer to install patches. Patches are updates or upgrades that replace only those program files that have changed. Because patches can be easy vehicles for malicious programs, some installations prohibit their use.\r\n\r\nNote: This policy setting applies only to installations that run in the user's security context.\r\n\r\nIf you disable or do not configure this policy setting, by default, users who are not system administrators cannot apply patches to installations that run with elevated system privileges, such as those offered on the desktop or in Add or Remove Programs.\r\n\r\nAlso, see the \"Enable user to patch elevated products\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablepatch"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablepatch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablepatch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disablerollback_2","displayName":"Prohibit rollback","description":"This policy setting prohibits Windows Installer from generating and saving the files it needs to reverse an interrupted or unsuccessful installation.\r\n\r\nIf you enable this policy setting, Windows Installer is prevented from recording the original state of the system and sequence of changes it makes during installation. It also prevents Windows Installer from retaining files it intends to delete later. As a result, Windows Installer cannot restore the computer to its original state if the installation does not complete.\r\n\r\nThis policy setting is designed to reduce the amount of temporary disk space required to install programs. Also, it prevents malicious users from interrupting an installation to gather data about the internal state of the computer or to search secure system files. However, because an incomplete installation can render the system or a program inoperable, do not use this policy setting unless it is essential.\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If the policy setting is enabled in either folder, it is considered be enabled, even if it is explicitly disabled in the other folder.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablerollback-2"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablerollback_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablerollback_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disablesharedcomponent","displayName":"Turn off shared components","description":"This policy setting controls the ability to turn off shared components.\r\n\r\nIf you enable this policy setting, no packages on the system get the shared component functionality enabled by the msidbComponentAttributesShared attribute in the Component Table.\r\n\r\nIf you disable or do not configure this policy setting, by default, the shared component functionality is allowed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablesharedcomponent"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablesharedcomponent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablesharedcomponent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableluapatching","displayName":"Prohibit non-administrators from applying vendor signed updates","description":"This policy setting controls the ability of non-administrators to install updates that have been digitally signed by the application vendor.\r\n\r\nNon-administrator updates provide a mechanism for the author of an application to create digitally signed updates that can be applied by non-privileged users.\r\n\r\nIf you enable this policy setting, only administrators or users with administrative privileges can apply updates to Windows Installer based applications.\r\n\r\nIf you disable or do not configure this policy setting, users without administrative privileges can install non-administrator updates.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-disableluapatching"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableluapatching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableluapatching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablepatchuninstall","displayName":"Prohibit removal of updates","description":"This policy setting controls the ability for users or administrators to remove Windows Installer based updates.\r\n\r\nThis policy setting should be used if you need to maintain a tight control over updates. One example is a lockdown environment where you want to ensure that updates once installed cannot be removed by users or administrators.\r\n\r\nIf you enable this policy setting, updates cannot be removed from the computer by a user or an administrator. The Windows Installer can still remove an update that is no longer applicable to the product.\r\n\r\nIf you disable or do not configure this policy setting, a user can remove an update from the computer only if the user has been granted privileges to remove the update. This can depend on whether the user is an administrator, whether \"Disable Windows Installer\" and \"Always install with elevated privileges\" policy settings are set, and whether the update was installed in a per-user managed, per-user unmanaged, or per-machine context.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-disablepatchuninstall"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablepatchuninstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablepatchuninstall_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablesrcheckpoints","displayName":"Turn off creation of System Restore checkpoints","description":"This policy setting prevents Windows Installer from creating a System Restore checkpoint each time an application is installed. System Restore enables users, in the event of a problem, to restore their computers to a previous state without losing personal data files.\r\n\r\nIf you enable this policy setting, the Windows Installer does not generate System Restore checkpoints when installing applications.\r\n\r\nIf you disable or do not configure this policy setting, by default, the Windows Installer automatically creates a System Restore checkpoint each time an application is installed, so that users can restore their computer to the state it was in before installing the application.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-disablesrcheckpoints"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablesrcheckpoints_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablesrcheckpoints_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls","displayName":"Prohibit User Installs","description":"This policy setting allows you to configure user installs. To configure this policy setting, set it to enabled and use the drop-down list to select the behavior you want.\r\n\r\nIf you do not configure this policy setting, or if the policy setting is enabled and \"Allow User Installs\" is selected, the installer allows and makes use of products that are installed per user, and products that are installed per computer. If the installer finds a per-user install of an application, this hides a per-computer installation of that same product.\r\n\r\nIf you enable this policy setting and \"Hide User Installs\" is selected, the installer ignores per-user applications. This causes a per-computer installed application to be visible to users, even if those users have a per-user install of the product registered in their user profile.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-disableuserinstalls"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_msi_disableuserinstallsbox","displayName":"User Install Behavior:","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_msi_disableuserinstallsbox_0","displayName":"Allow User Installs","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_msi_disableuserinstallsbox_1","displayName":"Hide User Installs","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_enforceupgradecomponentrules","displayName":"Enforce upgrade component rules","description":"This policy setting causes the Windows Installer to enforce strict rules for component upgrades.\r\n\r\nIf you enable this policy setting, strict upgrade rules will be enforced by the Windows Installer which may cause some upgrades to fail. Upgrades can fail if they attempt to do one of the following:\r\n\r\n(1) Remove a component from a feature.\r\nThis can also occur if you change the GUID of a component. The component identified by the original GUID appears to be removed and the component as identified by the new GUID appears as a new component.\r\n\r\n(2) Add a new feature to the top or middle of an existing feature tree.\r\nThe new feature must be added as a new leaf feature to an existing feature tree.\r\n\r\nIf you disable or do not configure this policy setting, the Windows Installer will use less restrictive rules for component upgrades.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-enforceupgradecomponentrules"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_enforceupgradecomponentrules_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_enforceupgradecomponentrules_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize","displayName":"Control maximum size of baseline file cache","description":"\r\n This policy controls the percentage of disk space available to the Windows Installer baseline file cache.\r\n\r\n The Windows Installer uses the baseline file cache to save baseline files modified by binary delta difference updates. The cache is used to retrieve the baseline file for future updates. The cache eliminates user prompts for source media when new updates are applied.\r\n\r\n If you enable this policy setting you can modify the maximum size of the Windows Installer baseline file cache.\r\n\r\n If you set the baseline cache size to 0, the Windows Installer will stop populating the baseline cache for new updates. The existing cached files will remain on disk and will be deleted when the product is removed.\r\n\r\n If you set the baseline cache to 100, the Windows Installer will use available free space for the baseline file cache.\r\n\r\n If you disable or do not configure this policy setting, the Windows Installer will uses a default value of 10 percent for the baseline file cache maximum size.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-maxpatchcachesize"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize_msi_maxpatchcachesize","displayName":"Baseline file cache maximum size","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":null},{"id":"device_vendor_msft_policy_config_admx_msi_msidisableembeddedui","displayName":"Prevent embedded UI","description":"This policy setting controls the ability to prevent embedded UI.\r\n\r\nIf you enable this policy setting, no packages on the system can run embedded UI.\r\n\r\nIf you disable or do not configure this policy setting, embedded UI is allowed to run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msidisableembeddedui"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msidisableembeddedui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msidisableembeddedui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msilogging","displayName":"Specify the types of events Windows Installer records in its transaction log","description":"\r\n Specifies the types of events that Windows Installer records in its transaction log for each installation. The log, Msi.log, appears in the Temp directory of the system volume.\r\n\r\n When you enable this policy setting, you can specify the types of events you want Windows Installer to record. To indicate that an event type is recorded, type the letter representing the event type. You can type the letters in any order and list as many or as few event types as you want.\r\n\r\n To disable logging, delete all of the letters from the box.\r\n\r\n If you disable or do not configure this policy setting, Windows Installer logs the default event types, represented by the letters \"iweap.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msilogging"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msilogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msilogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msilogging_msilogging","displayName":"Logging","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":null},{"id":"device_vendor_msft_policy_config_admx_msi_safeforscripting","displayName":"Prevent Internet Explorer security prompt for Windows Installer scripts","description":"This policy setting allows Web-based programs to install software on the computer without notifying the user.\r\n\r\nIf you disable or do not configure this policy setting, by default, when a script hosted by an Internet browser tries to install a program on the system, the system warns users and allows them to select or refuse the installation.\r\n\r\nIf you enable this policy setting, the warning is suppressed and allows the installation to proceed.\r\n\r\nThis policy setting is designed for enterprises that use Web-based tools to distribute programs to their employees. However, because this policy setting can pose a security risk, it should be applied cautiously.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-safeforscripting"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_safeforscripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_safeforscripting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_transformssecure","displayName":"Save copies of transform files in a secure location on workstation","description":"This policy setting saves copies of transform files in a secure location on the local computer.\r\n\r\nTransform files consist of instructions to modify or customize a program during installation.\r\n\r\nIf you enable this policy setting, the transform file is saved in a secure location on the user's computer.\r\n\r\nIf you do not configure this policy setting on Windows Server 2003, Windows Installer requires the transform file in order to repeat an installation in which the transform file was used, therefore, the user must be using the same computer or be connected to the original or identical media to reinstall, remove, or repair the installation.\r\n\r\nThis policy setting is designed for enterprises to prevent unauthorized or malicious editing of transform files.\r\n\r\nIf you disable this policy setting, Windows Installer stores transform files in the Application Data directory in the user's profile.\r\n\r\nIf you do not configure this policy setting on Windows 2000 Professional, Windows XP Professional and Windows Vista, when a user reinstalls, removes, or repairs an installation, the transform file is available, even if the user is on a different computer or is not connected to the network.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-transformssecure"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_transformssecure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_transformssecure_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy","displayName":"Configure MSI Corrupted File Recovery behavior","description":"This policy setting allows you to configure the recovery behavior for corrupted MSI files to one of three states:\r\n\r\nPrompt for Resolution: Detection, troubleshooting, and recovery of corrupted MSI applications will be turned on. Windows will prompt the user with a dialog box when application reinstallation is required. This is the default recovery behavior on Windows client.\r\n\r\nSilent: Detection, troubleshooting, and notification of MSI application to reinstall will occur with no UI. Windows will log an event when corruption is determined and will suggest the application that should be re-installed. This behavior is recommended for headless operation and is the default recovery behavior on Windows server.\r\n\r\nTroubleshooting Only: Detection and verification of file corruption will be performed without UI. Recovery is not attempted.\r\n\r\nIf you enable this policy setting, the recovery behavior for corrupted files is set to either the Prompt For Resolution (default on Windows client), Silent (default on Windows server), or Troubleshooting Only. \r\n\r\nIf you disable this policy setting, the troubleshooting and recovery behavior for corrupted files will be disabled. No troubleshooting or resolution will be attempted.\r\n\r\nIf you do not configure this policy setting, the recovery behavior for corrupted files will be set to the default recovery behavior.\r\n\r\nNo system or service restarts are required for changes to this policy setting to take immediate effect after a Group Policy refresh.\r\n\r\nNote: This policy setting will take effect only when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, system file recovery will not be attempted. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msifilerecovery#admx-msifilerecovery-wdiscenarioexecutionpolicy"],"categoryId":"e50acc0f-d177-4803-aa31-fc97eeb60ff2","categoryName":"MSI Corrupted File Recovery","options":[{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"e50acc0f-d177-4803-aa31-fc97eeb60ff2","categoryName":"MSI Corrupted File Recovery","options":[{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_1","displayName":"Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_2","displayName":"Prompt for Resolution","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_3","displayName":"Silent","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoadminlogon","displayName":"MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)","description":"MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autoadminlogon"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoadminlogon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoadminlogon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoreboot","displayName":"MSS: (AutoReboot) Allow Windows to automatically restart after a system crash (recommended except for highly secure environments)","description":"MSS: (AutoReboot) Allow Windows to automatically restart after a system crash (recommended except for highly secure environments)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autoreboot"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoreboot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoreboot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoshareserver","displayName":"MSS: (AutoShareServer) Enable Administrative Shares (recommended except for highly secure environments)","description":"MSS: (AutoShareServer) Enable Administrative Shares (recommended except for highly secure environments)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autoshareserver"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoshareserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoshareserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autosharewks","displayName":"MSS: (AutoShareWks) Enable Administrative Shares (recommended except for highly secure environments)","description":"MSS: (AutoShareWks) Enable Administrative Shares (recommended except for highly secure environments)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autosharewks"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autosharewks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autosharewks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_disablesavepassword","displayName":"MSS: (DisableSavePassword) Prevent the dial-up passsword from being saved (recommended)","description":"MSS: (DisableSavePassword) Prevent the dial-up passsword from being saved (recommended)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-disablesavepassword"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_disablesavepassword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_disablesavepassword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_enabledeadgwdetect","displayName":"MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)","description":"MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-enabledeadgwdetect"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_enabledeadgwdetect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_enabledeadgwdetect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_hidefrombrowselist","displayName":"MSS: (Hidden) Hide Computer From the Browse List (not recommended except for highly secure environments)","description":"MSS: (Hidden) Hide Computer From the Browse List (not recommended except for highly secure environments)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-hidefrombrowselist"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_hidefrombrowselist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_hidefrombrowselist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime","displayName":"MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds","description":"MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-keepalivetime"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime","displayName":"KeepAliveTime","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_150000","displayName":"150000 or 2.5 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_300000","displayName":"300000 or 5 minutes (recommended) ","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_600000","displayName":"600000 or 10 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_1200000","displayName":"1200000 or 20 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_2400000","displayName":"2400000 or 40 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_3600000","displayName":"3600000 or 1 hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_7200000","displayName":"7200000 or 2 hours (default value)","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt","displayName":"MSS: (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic. ","description":"MSS: (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic. \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-nodefaultexempt"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt","displayName":"NoDefaultExempt","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_0","displayName":"Allow all exemptions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_1","displayName":"Multicast, broadcast, & ISAKMP exempt.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_2","displayName":"RSVP, Kerberos, and ISAKMP are exempt.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_3","displayName":"Only ISAKMP is exempt.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation","displayName":"MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames","description":"MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-ntfsdisable8dot3namecreation"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation","displayName":"NtfsDisable8dot3NameCreation","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_0","displayName":"Enable 8Dot3 Creation on all Volumes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_1","displayName":"Disable 8Dot3 Creation on all Volumes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_2","displayName":"Set 8dot3 name creation per volume using FSUTIL","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_3","displayName":"Disable 8Dot3 name creation on all volumes except system volume","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_performrouterdiscovery","displayName":"MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)","description":"MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-performrouterdiscovery"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_performrouterdiscovery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_performrouterdiscovery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_safedllsearchmode","displayName":"MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)","description":"MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-safedllsearchmode"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_safedllsearchmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_safedllsearchmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_screensavergraceperiod","displayName":"MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)","description":"MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-screensavergraceperiod"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_screensavergraceperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_screensavergraceperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_screensavergraceperiod_screensavergraceperiod","displayName":"ScreenSaverGracePeriod","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect","displayName":"MSS: (SynAttackProtect) Syn attack protection level (protects against DoS)","description":"MSS: (SynAttackProtect) Syn attack protection level (protects against DoS)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-synattackprotect"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_synattackprotect","displayName":"SynAttackProtect","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_synattackprotect_0","displayName":"No additional protection, use default settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_synattackprotect_1","displayName":"Connections time out sooner if a SYN attack is detected","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions","displayName":"MSS: (TcpMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged","description":"MSS: (TcpMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-tcpmaxconnectresponseretransmissions"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_tcpmaxconnectresponseretransmissions","displayName":"TcpMaxConnectResponseRetransmissions","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_tcpmaxconnectresponseretransmissions_0","displayName":"No retransmission, half-open connections dropped after 3 seconds","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_tcpmaxconnectresponseretransmissions_1","displayName":"3 seconds, half-open connections dropped after 9 seconds","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_tcpmaxconnectresponseretransmissions_2","displayName":"3 & 6 seconds, half-open connections dropped after 21 seconds","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_tcpmaxconnectresponseretransmissions_3","displayName":"3, 6, & 9 seconds, half-open connections dropped after 45 seconds","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions","displayName":"MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)","description":"MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-tcpmaxdataretransmissions"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions_tcpmaxdataretransmissions","displayName":"TcpMaxDataRetransmissions","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6","displayName":"MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)","description":"MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-tcpmaxdataretransmissionsipv6"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6_tcpmaxdataretransmissions","displayName":"TcpMaxDataRetransmissions","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel","displayName":"MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning","description":"MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-warninglevel"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_warninglevel","displayName":"WarningLevel","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_warninglevel_50","displayName":"50%","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_warninglevel_60","displayName":"60%","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_warninglevel_70","displayName":"70%","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_warninglevel_80","displayName":"80%","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_warninglevel_90","displayName":"90%","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_corporateresources","displayName":"Corporate Resources","description":"Specifies resources on your intranet that are normally accessible to DirectAccess clients. Each entry is a string that identifies the type of resource and the location of the resource. \r\n\r\nEach string can be one of the following types:\r\n\t \r\n- A DNS name or IPv6 address that NCA pings. The syntax is “PING:” followed by a fully qualified domain name (FQDN) that resolves to an IPv6 address, or an IPv6 address. Examples: PING:myserver.corp.contoso.com or PING:2002:836b:1::1. \r\n \r\nNote \r\n\r\nWe recommend that you use FQDNs instead of IPv6 addresses wherever possible.\r\n\r\nImportant \r\n\r\nAt least one of the entries must be a PING: resource.\r\n\r\n-\tA Uniform Resource Locator (URL) that NCA queries with a Hypertext Transfer Protocol (HTTP) request. The contents of the web page do not matter. The syntax is “HTTP:” followed by a URL. The host portion of the URL must resolve to an IPv6 address of a Web server or contain an IPv6 address. Examples: HTTP:http://myserver.corp.contoso.com/ or HTTP:http://2002:836b:1::1/.\r\n\r\n-\tA Universal Naming Convention (UNC) path to a file that NCA checks for existence. The contents of the file do not matter. The syntax is “FILE:” followed by a UNC path. The ComputerName portion of the UNC path must resolve to an IPv6 address or contain an IPv6 address. Examples: FILE:\\\\myserver\\myshare\\test.txt or FILE:\\\\2002:836b:1::1\\myshare\\test.txt.\r\n\r\nYou must configure this setting to have complete NCA functionality.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-corporateresources"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_corporateresources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_corporateresources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_corporateresources_corporateresources_control","displayName":"Corporate Resources","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_nca_customcommands","displayName":"Custom Commands","description":"Specifies commands configured by the administrator for custom logging. These commands will run in addition to default log commands.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-customcommands"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_customcommands_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_customcommands_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_customcommands_customcommands_control","displayName":"CustomCommands","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_nca_dtes","displayName":"IPsec Tunnel Endpoints","description":"Specifies the IPv6 addresses of the endpoints of the Internet Protocol security (IPsec) tunnels that enable DirectAccess. NCA attempts to access the resources that are specified in the Corporate Resources setting through these configured tunnel endpoints. \r\n\r\nBy default, NCA uses the same DirectAccess server that the DirectAccess client computer connection is using. In default configurations of DirectAccess, there are typically two IPsec tunnel endpoints: one for the infrastructure tunnel and one for the intranet tunnel. You should configure one endpoint for each tunnel. \r\n\t \r\nEach entry consists of the text PING: followed by the IPv6 address of an IPsec tunnel endpoint. Example: PING:2002:836b:1::836b:1.\r\n\r\nYou must configure this setting to have complete NCA functionality.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-dtes"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_dtes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_dtes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_dtes_dtes_control","displayName":"DTEs","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname","displayName":"Friendly Name","description":"Specifies the string that appears for DirectAccess connectivity when the user clicks the Networking notification area icon. For example, you can specify “Contoso Intranet Access” for the DirectAccess clients of the Contoso Corporation.\r\n\r\nIf this setting is not configured, the string that appears for DirectAccess connectivity is “Corporate Connection”.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-friendlyname"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname_friendlyname_control","displayName":"Friendly Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_nca_localnameson","displayName":"Prefer Local Names Allowed","description":"Specifies whether the user has Connect and Disconnect options for the DirectAccess entry when the user clicks the Networking notification area icon.\r\n\r\nIf the user clicks the Disconnect option, NCA removes the DirectAccess rules from the Name Resolution Policy Table (NRPT) and the DirectAccess client computer uses whatever normal name resolution is available to the client computer in its current network configuration, including sending all DNS queries to the local intranet or Internet DNS servers. Note that NCA does not remove the existing IPsec tunnels and users can still access intranet resources across the DirectAccess server by specifying IPv6 addresses rather than names.\r\n\r\nThe ability to disconnect allows users to specify single-label, unqualified names (such as “PRINTSVR”) for local resources when connected to a different intranet and for temporary access to intranet resources when network location detection has not correctly determined that the DirectAccess client computer is connected to its own intranet.\r\n\r\nTo restore the DirectAccess rules to the NRPT and resume normal DirectAccess functionality, the user clicks Connect.\r\n\r\nNote \r\nIf the DirectAccess client computer is on the intranet and has correctly determined its network location, the Disconnect option has no effect because the rules for DirectAccess are already removed from the NRPT.\r\n\r\nIf this setting is not configured, users do not have Connect or Disconnect options.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-localnameson"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_localnameson_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_localnameson_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_passivemode","displayName":"DirectAccess Passive Mode","description":"Specifies whether NCA service runs in Passive Mode or not.\r\n\r\nSet this to Disabled to keep NCA probing actively all the time. If this setting is not configured, NCA probing is in active mode by default.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-passivemode"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_passivemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_passivemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_showui","displayName":"User Interface","description":"Specifies whether an entry for DirectAccess connectivity appears when the user clicks the Networking notification area icon.\r\n\r\nSet this to Disabled to prevent user confusion when you are just using DirectAccess to remotely manage DirectAccess client computers from your intranet and not providing seamless intranet access. \r\n\r\nIf this setting is not configured, the entry for DirectAccess connectivity appears.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-showui"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_showui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_showui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_supportemail","displayName":"Support Email Address","description":"Specifies the e-mail address to be used when sending the log files that are generated by NCA to the network administrator. \r\n\r\nWhen the user sends the log files to the Administrator, NCA uses the default e-mail client to open a new message with the support email address in the To: field of the message, then attaches the generated log files as a .html file. The user can review the message and add additional information before sending the message.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-supportemail"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_supportemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_supportemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_supportemail_supportemail_control","displayName":"Support Email","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobecontent","displayName":"Specify corporate DNS probe host address","description":"This policy setting enables you to specify the expected address of the host name used for the DNS probe. Successful resolution of the host name to this address indicates corporate connectivity.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-corpdnsprobecontent"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobecontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobecontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobecontent_ncsi_corpdnsprobecontentbox","displayName":"Corporate DNS Probe Address:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobehost","displayName":"Specify corporate DNS probe host name","description":"This policy setting enables you to specify the host name of a computer known to be on the corporate network. Successful resolution of this host name to the expected address indicates corporate connectivity.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-corpdnsprobehost"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobehost_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobehost_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobehost_ncsi_corpdnsprobehostbox","displayName":"Corporate DNS Probe Hostname:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpsiteprefixes","displayName":"Specify corporate site prefix list","description":"This policy setting enables you to specify the list of IPv6 corporate site prefixes to monitor for corporate connectivity. Reachability of addresses with any of these prefixes indicates corporate connectivity.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-corpsiteprefixes"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpsiteprefixes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpsiteprefixes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpsiteprefixes_ncsi_corpsiteprefixesbox","displayName":"Corporate Site Prefix List:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpwebprobeurl","displayName":"Specify corporate Website probe URL","description":"This policy setting enables you to specify the URL of the corporate website, against which an active probe is performed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-corpwebprobeurl"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpwebprobeurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpwebprobeurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpwebprobeurl_ncsi_corpwebprobeurlbox","displayName":"Corporate Website Probe URL:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_domainlocationdeterminationurl","displayName":"Specify domain location determination URL","description":"This policy setting enables you to specify the HTTPS URL of the corporate website that clients use to determine the current domain location (i.e. whether the computer is inside or outside the corporate network). Reachability of the URL destination indicates that the client location is inside corporate network; otherwise it is outside the network.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-domainlocationdeterminationurl"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_domainlocationdeterminationurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_domainlocationdeterminationurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_domainlocationdeterminationurl_ncsi_domainlocationdeterminationurlbox","displayName":"Corporate Domain Location Determination URL:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_globaldns","displayName":"Specify global DNS","description":"This policy setting enables you to specify DNS binding behavior. NCSI by default will restrict DNS lookups to the interface it is currently probing on. If you enable this setting, NCSI will allow the DNS lookups to happen on any interface.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-globaldns"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_globaldns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_globaldns_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_globaldns_ncsi_useglobaldns_checkbox","displayName":"Use global DNS","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_globaldns_ncsi_useglobaldns_checkbox_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_globaldns_ncsi_useglobaldns_checkbox_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling","displayName":"Specify passive polling","description":"This Policy setting enables you to specify passive polling behavior. NCSI polls various measurements throughout the network stack on a frequent interval to determine if network connectivity has been lost. Use the options to control the passive polling behavior.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-passivepolling"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_ncsi_disablepassivepolling_checkbox","displayName":"Disable passive polling","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_ncsi_disablepassivepolling_checkbox_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_ncsi_disablepassivepolling_checkbox_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresslookuponpingbehavior","displayName":"Specify address lookup behavior for DC locator ping","description":"This policy setting configures how a domain controller (DC) behaves when responding to a client whose IP address does not map to any configured site.\r\n\r\nDomain controllers use the client IP address during a DC locator ping request to compute which Active Directory site the client belongs to. If no site mapping can be computed, the DC may do an address lookup on the client network name to discover other IP addresses which may then be used to compute a matching site for the client. \r\n\r\nThe allowable values for this setting result in the following behaviors:\r\n\r\n0 - DCs will never perform address lookups.\r\n1 - DCs will perform an exhaustive address lookup to discover additional client IP addresses.\r\n2 - DCs will perform a fast, DNS-only address lookup to discover additional client IP addresses.\r\n\r\nTo specify this behavior in the DC Locator DNS SRV records, click Enabled, and then enter a value. The range of values is from 0 to 2.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-addresslookuponpingbehavior"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresslookuponpingbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresslookuponpingbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresslookuponpingbehavior_netlogon_addresslookuponpingbehaviorlabel","displayName":"Address lookup behavior:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresstypereturned","displayName":"Return domain controller address type","description":"This policy setting detremines the type of IP address that is returned for a domain controller. The DC Locator APIs return the IP address of the DC with the other parts of information. Before the support of IPv6, the returned DC IP address was IPv4. But with the support of IPv6, the DC Locator APIs can return IPv6 DC address. The returned IPv6 DC address may not be correctly handled by some of the existing applications. So this policy is provided to support such scenarios.\r\n\r\nBy default, DC Locator APIs can return IPv4/IPv6 DC address. But if some applications are broken due to the returned IPv6 DC address, this policy can be used to disable the default behavior and enforce to return only IPv4 DC address. Once applications are fixed, this policy can be used to enable the default behavior.\r\n\r\nIf you enable this policy setting, DC Locator APIs can return IPv4/IPv6 DC address. This is the default behavior of the DC Locator.\r\n\r\nIf you disable this policy setting, DC Locator APIs will ONLY return IPv4 DC address if any. So if the domain controller supports both IPv4 and IPv6 addresses, DC Locator APIs will return IPv4 address. But if the domain controller supports only IPv6 address, then DC Locator APIs will fail.\r\n\r\nIf you do not configure this policy setting, DC Locator APIs can return IPv4/IPv6 DC address. This is the default behavior of the DC Locator.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-addresstypereturned"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresstypereturned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresstypereturned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowdnssuffixsearch","displayName":"Use DNS name resolution when a single-label domain name is used, by appending different registered DNS suffixes, if the AllowSingleLabelDnsDomain setting is not enabled.","description":"This policy setting specifies whether the computers to which this setting is applied attemps DNS name resolution of single-lablel domain names, by appending different registered DNS suffixes, and uses NetBIOS name resolution only if DNS name resolution fails. This policy, including the specified default behavior, is not used if the AllowSingleLabelDnsDomain policy setting is enabled.\r\n\r\nBy default, when no setting is specified for this policy, the behavior is the same as explicitly enabling this policy, unless the AllowSingleLabelDnsDomain policy setting is enabled.\r\n\r\nIf you enable this policy setting, when the AllowSingleLabelDnsDomain policy is not enabled, computers to which this policy is applied, will locate a domain controller hosting an Active Directory domain specified with a single-label name, by appending different registered DNS suffixes to perform DNS name resolution. The single-label name is not used without appending DNS suffixes unless the computer is joined to a domain that has a single-label DNS name in the Active Directory forest. NetBIOS name resolution is performed on the single-label name only, in the event that DNS resolution fails.\r\n\r\nIf you disable this policy setting, when the AllowSingleLabelDnsDomain policy is not enabled, computers to which this policy is applied, will only use NetBIOS name resolution to attempt to locate a domain controller hosting an Active Directory domain specified with a single-label name. The computers will not attempt DNS name resolution in this case, unless the computer is searching for a domain with a single label DNS name to which this computer is joined, in the Active Directory forest.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-allowdnssuffixsearch"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowdnssuffixsearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowdnssuffixsearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allownt4crypto","displayName":"Allow cryptography algorithms compatible with Windows NT 4.0","description":"This policy setting controls whether the Net Logon service will allow the use of older cryptography algorithms that are used in Windows NT 4.0. The cryptography algorithms used in Windows NT 4.0 and earlier are not as secure as newer algorithms used in Windows 2000 or later, including this version of Windows.\r\n\r\nBy default, Net Logon will not allow the older cryptography algorithms to be used and will not include them in the negotiation of cryptography algorithms. Therefore, computers running Windows NT 4.0 will not be able to establish a connection to this domain controller.\r\n \r\nIf you enable this policy setting, Net Logon will allow the negotiation and use of older cryptography algorithms compatible with Windows NT 4.0. However, using the older algorithms represents a potential security risk.\r\n\r\nIf you disable this policy setting, Net Logon will not allow the negotiation and use of older cryptography algorithms. \r\n\r\nIf you do not configure this policy setting, Net Logon will not allow the negotiation and use of older cryptography algorithms.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-allownt4crypto"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allownt4crypto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allownt4crypto_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowsinglelabeldnsdomain","displayName":"Use DNS name resolution with a single-label domain name instead of NetBIOS name resolution to locate the DC","description":"This policy setting specifies whether the computers to which this setting is applied attempt DNS name resolution of a single-label domain names.\r\n\r\nBy default, the behavior specified in the AllowDnsSuffixSearch is used. If the AllowDnsSuffixSearch policy is disabled, then NetBIOS name resolution is used exclusively, to locate a domain controller hosting an Active Directory domain specified with a single-label name.\r\n\r\nIf you enable this policy setting, computers to which this policy is applied will attempt to locate a domain controller hosting an Active Directory domain specified with a single-label name using DNS name resolution.\r\n\r\nIf you disable this policy setting, computers to which this setting is applied will use the AllowDnsSuffixSearch policy, if it is not disabled or perform NetBIOS name resolution otherwise, to attempt to locate a domain controller that hosts an Active Directory domain specified with a single-label name. the computers will not the DNS name resolution in this case, unless the computer is searching for a domain with a single label DNS name that exists in the Active Directory forest to which this computer is joined.\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-allowsinglelabeldnsdomain"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowsinglelabeldnsdomain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowsinglelabeldnsdomain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_autositecoverage","displayName":"Use automated site coverage by the DC Locator DNS SRV Records","description":"This policy setting determines whether domain controllers (DC) will dynamically register DC Locator site-specific SRV records for the closest sites where no DC for the same domain exists (or no Global Catalog for the same forest exists). These DNS records are dynamically registered by the Net Logon service, and they are used to locate the DC.\r\n\r\nIf you enable this policy setting, the DCs to which this setting is applied dynamically register DC Locator site-specific DNS SRV records for the closest sites where no DC for the same domain, or no Global Catalog for the same forest, exists.\r\n\r\nIf you disable this policy setting, the DCs will not register site-specific DC Locator DNS SRV records for any other sites but their own.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-autositecoverage"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_autositecoverage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_autositecoverage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_avoidfallbacknetbiosdiscovery","displayName":"Do not use NetBIOS-based discovery for domain controller location when DNS-based discovery fails","description":"This policy setting allows you to control the domain controller (DC) location algorithm. By default, the DC location algorithm prefers DNS-based discovery if the DNS domain name is known. If DNS-based discovery fails and the NetBIOS domain name is known, the algorithm then uses NetBIOS-based discovery as a fallback mechanism.\r\n\r\nNetBIOS-based discovery uses a WINS server and mailslot messages but does not use site information. Hence it does not ensure that clients will discover the closest DC. It also allows a hub-site client to discover a branch-site DC even if the branch-site DC only registers site-specific DNS records (as recommended). For these reasons, NetBIOS-based discovery is not recommended.\r\n\r\nNote that this policy setting does not affect NetBIOS-based discovery for DC location if only the NetBIOS domain name is known.\r\n\r\nIf you enable or do not configure this policy setting, the DC location algorithm does not use NetBIOS-based discovery as a fallback mechanism when DNS-based discovery fails. This is the default behavior.\r\n\r\nIf you disable this policy setting, the DC location algorithm can use NetBIOS-based discovery as a fallback mechanism when DNS based discovery fails.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-avoidfallbacknetbiosdiscovery"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_avoidfallbacknetbiosdiscovery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_avoidfallbacknetbiosdiscovery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_avoidpdconwan","displayName":"Contact PDC on logon failure","description":"This policy setting defines whether a domain controller (DC) should attempt to verify the password provided by a client with the PDC emulator if the DC failed to validate the password.\r\n\r\nContacting the PDC emulator is useful in case the client’s password was recently changed and did not propagate to the DC yet. Users may want to disable this feature if the PDC emulator is located over a slow WAN connection.\r\n\r\nIf you enable this policy setting, the DCs to which this policy setting applies will attempt to verify a password with the PDC emulator if the DC fails to validate the password.\r\n\r\nIf you disable this policy setting, the DCs will not attempt to verify any passwords with the PDC emulator. \r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-avoidpdconwan"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_avoidpdconwan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_avoidpdconwan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod","displayName":"Use initial DC discovery retry setting for background callers","description":"This policy setting determines the amount of time (in seconds) to wait before the first retry for applications that perform periodic searches for domain controllers (DC) that are unable to find a DC.\r\n\r\nThe default value for this setting is 10 minutes (10*60). The maximum value for this setting is 49 days (0x49*24*60*60=4233600). The minimum value for this setting is 0.\r\n\r\nThis setting is relevant only to those callers of DsGetDcName that have specified the DS_BACKGROUND_ONLY flag.\r\n\r\nIf the value of this setting is less than the value specified in the NegativeCachePeriod subkey, the value in the NegativeCachePeriod subkey is used.\r\n\r\nWarning: If the value for this setting is too large, a client will not attempt to find any DCs that were initially unavailable. If the value set in this setting is very small and the DC is not available, the traffic caused by periodic DC discoveries may be excessive.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-backgroundretryinitialperiod"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod_netlogon_backgroundretryinitialperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretrymaximumperiod","displayName":"Use maximum DC discovery retry interval setting for background callers","description":"This policy setting determines the maximum retry interval allowed when applications performing periodic searches for Domain Controllers (DCs) are unable to find a DC.\r\n\r\nFor example, the retry intervals may be set at 10 minutes, then 20 minutes and then 40 minutes, but when the interval reaches the value set in this setting, that value becomes the retry interval for all subsequent retries until the value set in Final DC Discovery Retry Setting is reached.\r\n\r\nThe default value for this setting is 60 minutes (60*60). The maximum value for this setting is 49 days (0x49*24*60*60=4233600). The minimum value for this setting is 0.\r\n\r\nIf the value for this setting is smaller than the value specified for the Initial DC Discovery Retry Setting, the Initial DC Discovery Retry Setting is used.\r\n\r\nWarning: If the value for this setting is too large, a client may take very long periods to try to find a DC.\r\n\r\nIf the value for this setting is too small and the DC is not available, the frequent retries may produce excessive network traffic.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-backgroundretrymaximumperiod"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretrymaximumperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretrymaximumperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretrymaximumperiod_netlogon_backgroundretrymaximumperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryquittime","displayName":"Use final DC discovery retry setting for background callers","description":"This policy setting determines when retries are no longer allowed for applications that perform periodic searches for domain controllers (DC) are unable to find a DC. For example, retires may be set to occur according to the Use maximum DC discovery retry interval policy setting, but when the value set in this policy setting is reached, no more retries occur. If a value for this policy setting is smaller than the value in the Use maximum DC discovery retry interval policy setting, the value for Use maximum DC discovery retry interval policy setting is used.\r\n\r\nThe default value for this setting is to not quit retrying (0). The maximum value for this setting is 49 days (0x49*24*60*60=4233600). The minimum value for this setting is 0.\r\n\r\nWarning: If the value for this setting is too small, a client will stop trying to find a DC too soon.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-backgroundretryquittime"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryquittime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryquittime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryquittime_netlogon_backgroundretryquittimelabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundsuccessfulrefreshperiod","displayName":"Use positive periodic DC cache refresh for background callers","description":"This policy setting determines when a successful DC cache entry is refreshed. This policy setting is applied to caller programs that periodically attempt to locate DCs, and it is applied before returning the DC information to the caller program. The default value for this setting is infinite (4294967200). The maximum value for this setting is (4294967200), while the maximum that is not treated as infinity is 49 days (49*24*60*60=4233600). Any larger value is treated as infinity. The minimum value for this setting is to always refresh (0).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-backgroundsuccessfulrefreshperiod"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundsuccessfulrefreshperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundsuccessfulrefreshperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundsuccessfulrefreshperiod_netlogon_backgroundsuccessfulrefreshperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_debugflag","displayName":"Specify log file debug output level","description":"This policy setting specifies the level of debug output for the Net Logon service.\r\n\r\nThe Net Logon service outputs debug information to the log file netlogon.log in the directory %windir%\\debug. By default, no debug information is logged.\r\n\r\nIf you enable this policy setting and specify a non-zero value, debug information will be logged to the file. Higher values result in more verbose logging; the value of 536936447 is commonly used as an optimal setting.\r\n\r\nIf you specify zero for this policy setting, the default behavior occurs as described above.\r\n\r\nIf you disable this policy setting or do not configure it, the default behavior occurs as described above.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-debugflag"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_debugflag_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_debugflag_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_debugflag_netlogon_debugflaglabel","displayName":"Level:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords","displayName":"Specify DC Locator DNS records not registered by the DCs","description":"This policy setting determines which DC Locator DNS records are not registered by the Net Logon service.\r\n\r\nIf you enable this policy setting, select Enabled and specify a list of space-delimited mnemonics (instructions) for the DC Locator DNS records that will not be registered by the DCs to which this setting is applied.\r\n\r\nSelect the mnemonics from the following list:\r\n\r\nMnemonic Type DNS Record\r\n\r\nLdapIpAddress A \r\nLdap SRV _ldap._tcp.\r\nLdapAtSite SRV _ldap._tcp.._sites.\r\nPdc SRV _ldap._tcp.pdc._msdcs.\r\nGc SRV _ldap._tcp.gc._msdcs.\r\nGcAtSite SRV _ldap._tcp.._sites.gc._msdcs.\r\nDcByGuid SRV _ldap._tcp..domains._msdcs.\r\nGcIpAddress A gc._msdcs.\r\nDsaCname CNAME ._msdcs.\r\nKdc SRV _kerberos._tcp.dc._msdcs.\r\nKdcAtSite SRV _kerberos._tcp.._sites.dc._msdcs.\r\nDc SRV _ldap._tcp.dc._msdcs.\r\nDcAtSite SRV _ldap._tcp.._sites.dc._msdcs.\r\nRfc1510Kdc SRV _kerberos._tcp.\r\nRfc1510KdcAtSite SRV _kerberos._tcp.._sites.\r\nGenericGc SRV _gc._tcp.\r\nGenericGcAtSite SRV _gc._tcp.._sites.\r\nRfc1510UdpKdc SRV _kerberos._udp.\r\nRfc1510Kpwd SRV _kpasswd._tcp.\r\nRfc1510UdpKpwd SRV _kpasswd._udp.\r\n\r\nIf you disable this policy setting, DCs configured to perform dynamic registration of DC Locator DNS records register all DC Locator DNS resource records.\r\n\r\nIf you do not configure this policy setting, DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-dnsavoidregisterrecords"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords_netlogon_dnsavoidregisterrecordslabel","displayName":"Mnemonics:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsrefreshinterval","displayName":"Specify Refresh Interval of the DC Locator DNS records","description":"This policy setting specifies the Refresh Interval of the DC Locator DNS resource records for DCs to which this setting is applied. These DNS records are dynamically registered by the Net Logon service and are used by the DC Locator algorithm to locate the DC. This setting may be applied only to DCs using dynamic update.\r\n\r\nDCs configured to perform dynamic registration of the DC Locator DNS resource records periodically reregister their records with DNS servers, even if their records’ data has not changed. If authoritative DNS servers are configured to perform scavenging of the stale records, this reregistration is required to instruct the DNS servers configured to automatically remove (scavenge) stale records that these records are current and should be preserved in the database.\r\n\r\nWarning: If the DNS resource records are registered in zones with scavenging enabled, the value of this setting should never be longer than the Refresh Interval configured for these zones. Setting the Refresh Interval of the DC Locator DNS records to longer than the Refresh Interval of the DNS zones may result in the undesired deletion of DNS resource records.\r\n\r\nTo specify the Refresh Interval of the DC records, click Enabled, and then enter a value larger than 1800. This value specifies the Refresh Interval of the DC records in seconds (for example, the value 3600 is 60 minutes).\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-dnsrefreshinterval"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsrefreshinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsrefreshinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsrefreshinterval_netlogon_dnsrefreshintervallabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnssrvrecorduselowercasehostnames","displayName":"Use lowercase DNS host names when registering domain controller SRV records","description":"This policy setting configures whether the domain controllers to which this setting is applied will lowercase their DNS host name when registering SRV records.\r\n\r\nIf enabled, domain controllers will lowercase their DNS host name when registering domain controller SRV records. A best-effort attempt will be made to delete any previously registered SRV records that contain mixed-case DNS host names. For more information and potential manual cleanup procedures, see the link below.\r\n\r\nIf disabled, domain controllers will use their configured DNS host name as-is when registering domain controller SRV records.\r\n\r\nIf not configured, domain controllers will default to using their local configuration.\r\n\r\nThe default local configuration is enabled.\r\n\r\nA reboot is not required for changes to this setting to take effect.\r\n\r\nMore information is available at https://aka.ms/lowercasehostnamesrvrecord\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-dnssrvrecorduselowercasehostnames"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnssrvrecorduselowercasehostnames_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnssrvrecorduselowercasehostnames_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl","displayName":"Set TTL in the DC Locator DNS Records","description":"This policy setting specifies the value for the Time-To-Live (TTL) field in SRV resource records that are registered by the Net Logon service. These DNS records are dynamically registered, and they are used to locate the domain controller (DC).\r\n\r\nTo specify the TTL for DC Locator DNS records, click Enabled, and then enter a value in seconds (for example, the value \"900\" is 15 minutes).\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-dnsttl"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl_netlogon_dnsttllabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay","displayName":"Specify expected dial-up delay on logon","description":"This policy setting specifies the additional time for the computer to wait for the domain controller’s (DC) response when logging on to the network.\r\n\r\nTo specify the expected dial-up delay at logon, click Enabled, and then enter the desired value in seconds (for example, the value \"60\" is 1 minute).\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-expecteddialupdelay"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay_netlogon_expecteddialupdelaylabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_forcerediscoveryinterval","displayName":"Force Rediscovery Interval","description":"This policy setting determines the interval for when a Force Rediscovery is carried out by DC Locator.\r\n\r\nThe Domain Controller Locator (DC Locator) service is used by clients to find domain controllers for their Active Directory domain. When DC Locator finds a domain controller, it caches domain controllers to improve the efficiency of the location algorithm. As long as the cached domain controller meets the requirements and is running, DC Locator will continue to return it. If a new domain controller is introduced, existing clients will only discover it when a Force Rediscovery is carried out by DC Locator. To adapt to changes in network conditions DC Locator will by default carry out a Force Rediscovery according to a specific time interval and maintain efficient load-balancing of clients across all available domain controllers in all domains or forests. The default time interval for Force Rediscovery by DC Locator is 12 hours. Force Rediscovery can also be triggered if a call to DC Locator uses the DS_FORCE_REDISCOVERY flag. Rediscovery resets the timer on the cached domain controller entries.\r\n\r\nIf you enable this policy setting, DC Locator on the machine will carry out Force Rediscovery periodically according to the configured time interval. The minimum time interval is 3600 seconds (1 hour) to avoid excessive network traffic from rediscovery. The maximum allowed time interval is 4294967200 seconds, while any value greater than 4294967 seconds (~49 days) will be treated as infinity.\r\n\r\nIf you disable this policy setting, Force Rediscovery will be used by default for the machine at every 12 hour interval.\r\n\r\nIf you do not configure this policy setting, Force Rediscovery will be used by default for the machine at every 12 hour interval, unless the local machine setting in the registry is a different value.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-forcerediscoveryinterval"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_forcerediscoveryinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_forcerediscoveryinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_forcerediscoveryinterval_netlogon_forcerediscoveryintervallabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage","displayName":"Specify sites covered by the GC Locator DNS SRV Records","description":"This policy setting specifies the sites for which the global catalogs (GC) should register site-specific GC locator DNS SRV resource records. These records are registered in addition to the site-specific SRV records registered for the site where the GC resides, and records registered by a GC configured to register GC Locator DNS SRV records for those sites without a GC that are closest to it. \r\n\r\nThe GC Locator DNS records and the site-specific SRV records are dynamically registered by the Net Logon service, and they are used to locate the GC. An Active Directory site is one or more well-connected TCP/IP subnets that allow administrators to configure Active Directory access and replication. A GC is a domain controller that contains a partial replica of every domain in Active Directory.\r\n\r\nTo specify the sites covered by the GC Locator DNS SRV records, click Enabled, and enter the sites' names in a space-delimited format.\r\n\r\nIf you do not configure this policy setting, it is not applied to any GCs, and GCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-gcsitecoverage"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage_netlogon_gcsitecoveragelabel","displayName":"Sites:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ignoreincomingmailslotmessages","displayName":"Do not process incoming mailslot messages used for domain controller location based on NetBIOS domain names","description":"This policy setting allows you to control the processing of incoming mailslot messages by a local domain controller (DC).\r\n\r\nNote: To locate a remote DC based on its NetBIOS (single-label) domain name, DC Locator first gets the list of DCs from a WINS server that is configured in its local client settings. DC Locator then sends a mailslot message to each remote DC to get more information. DC location succeeds only if a remote DC responds to the mailslot message.\r\n\r\nThis policy setting is recommended to reduce the attack surface on a DC, and can be used in an environment without WINS, in an IPv6-only environment, and whenever DC location based on a NetBIOS domain name is not required. This policy setting does not affect DC location based on DNS names.\r\n\r\nIf you enable this policy setting, this DC does not process incoming mailslot messages that are used for NetBIOS domain name based DC location.\r\n\r\nIf you disable or do not configure this policy setting, this DC processes incoming mailslot messages. This is the default behavior of DC Locator.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-ignoreincomingmailslotmessages"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ignoreincomingmailslotmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ignoreincomingmailslotmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvpriority","displayName":"Set Priority in the DC Locator DNS SRV records","description":"This policy setting specifies the Priority field in the SRV resource records registered by domain controllers (DC) to which this setting is applied. These DNS records are dynamically registered by the Net Logon service and are used to locate the DC.\r\n\r\nThe Priority field in the SRV record sets the preference for target hosts (specified in the SRV record’s Target field). DNS clients that query for SRV resource records attempt to contact the first reachable host with the lowest priority number listed.\r\n\r\nTo specify the Priority in the DC Locator DNS SRV resource records, click Enabled, and then enter a value. The range of values is from 0 to 65535.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-ldapsrvpriority"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvpriority_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvpriority_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvpriority_netlogon_ldapsrvprioritylabel","displayName":"Priority:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvweight","displayName":"Set Weight in the DC Locator DNS SRV records","description":"This policy setting specifies the Weight field in the SRV resource records registered by the domain controllers (DC) to which this setting is applied. These DNS records are dynamically registered by the Net Logon service, and they are used to locate the DC.\r\n\r\nThe Weight field in the SRV record can be used in addition to the Priority value to provide a load-balancing mechanism where multiple servers are specified in the SRV records Target field and are all set to the same priority. The probability with which the DNS client randomly selects the target host to be contacted is proportional to the Weight field value in the SRV record.\r\n\r\nTo specify the Weight in the DC Locator DNS SRV records, click Enabled, and then enter a value. The range of values is from 0 to 65535.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-ldapsrvweight"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvweight_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvweight_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvweight_netlogon_ldapsrvweightlabel","displayName":"Weight:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_maximumlogfilesize","displayName":"Specify maximum log file size","description":"This policy setting specifies the maximum size in bytes of the log file netlogon.log in the directory %windir%\\debug when logging is enabled.\r\n\r\nBy default, the maximum size of the log file is 20MB. If you enable this policy setting, the maximum size of the log file is set to the specified size. Once this size is reached the log file is saved to netlogon.bak and netlogon.log is truncated. A reasonable value based on available storage should be specified.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior occurs as indicated above.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-maximumlogfilesize"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_maximumlogfilesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_maximumlogfilesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_maximumlogfilesize_netlogon_maximumlogfilesizelabel","displayName":"Bytes:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ndncsitecoverage","displayName":"Specify sites covered by the application directory partition DC Locator DNS SRV records","description":"This policy setting specifies the sites for which the domain controllers (DC) that host the application directory partition should register the site-specific, application directory partition-specific DC Locator DNS SRV resource records. These records are registered in addition to the site-specific SRV records registered for the site where the DC resides, and records registered by a DC configured to register DC Locator DNS SRV records for those sites without a DC that are closest to it. \r\n\r\nThe application directory partition DC Locator DNS records and the site-specific SRV records are dynamically registered by the Net Logon service, and they are used to locate the application directory partition-specific DC. An Active Directory site is one or more well-connected TCP/IP subnets that allow administrators to configure Active Directory access and replication.\r\n\r\nTo specify the sites covered by the DC Locator application directory partition-specific DNS SRV records, click Enabled, and then enter the site names in a space-delimited format.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-ndncsitecoverage"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ndncsitecoverage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ndncsitecoverage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ndncsitecoverage_netlogon_ndncsitecoveragelabel","displayName":"Sites:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_negativecacheperiod","displayName":"Specify negative DC Discovery cache setting","description":"This policy setting specifies the amount of time (in seconds) the DC locator remembers that a domain controller (DC) could not be found in a domain. When a subsequent attempt to locate the DC occurs within the time set in this setting, DC Discovery immediately fails, without attempting to find the DC.\r\n\r\nThe default value for this setting is 45 seconds. The maximum value for this setting is 7 days (7*24*60*60). The minimum value for this setting is 0.\r\n\r\nWarning: If the value for this setting is too large, a client will not attempt to find any DCs that were initially unavailable. If the value for this setting is too small, clients will attempt to find DCs even when none are available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-negativecacheperiod"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_negativecacheperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_negativecacheperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_negativecacheperiod_netlogon_negativecacheperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_netlogonsharecompatibilitymode","displayName":"Set Netlogon share compatibility","description":"This policy setting controls whether or not the Netlogon share created by the Net Logon service on a domain controller (DC) should support compatibility in file sharing semantics with earlier applications.\r\n\r\nIf you enable this policy setting, the Netlogon share will honor file sharing semantics that grant requests for exclusive read access to files on the share even when the caller has only read permission.\r\n\r\nIf you disable or do not configure this policy setting, the Netlogon share will grant shared read access to files on the share when exclusive access is requested and the caller has only read permission.\r\n\r\nBy default, the Netlogon share will grant shared read access to files on the share when exclusive access is requested.\r\n\r\nNote: The Netlogon share is a share created by the Net Logon service for use by client machines in the domain. The default behavior of the Netlogon share ensures that no application with only read permission to files on the Netlogon share can lock the files by requesting exclusive read access, which might prevent Group Policy settings from being updated on clients in the domain. When this setting is enabled, an application that relies on the ability to lock files on the Netlogon share with only read permission will be able to deny Group Policy clients from reading the files, and in general the availability of the Netlogon share on the domain will be decreased.\r\n\r\nIf you enable this policy setting, domain administrators should ensure that the only applications using the exclusive read capability in the domain are those approved by the administrator.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-netlogonsharecompatibilitymode"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_netlogonsharecompatibilitymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_netlogonsharecompatibilitymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_nonbackgroundsuccessfulrefreshperiod","displayName":"Specify positive periodic DC Cache refresh for non-background callers","description":"This policy setting determines when a successful DC cache entry is refreshed. This policy setting is applied to caller programs that do not periodically attempt to locate DCs, and it is applied before the returning the DC information to the caller program. This policy setting is relevant to only those callers of DsGetDcName that have not specified the DS_BACKGROUND_ONLY flag.\r\n\r\nThe default value for this setting is 30 minutes (1800). The maximum value for this setting is (4294967200), while the maximum that is not treated as infinity is 49 days (49*24*60*60=4233600). Any larger value will be treated as infinity. The minimum value for this setting is to always refresh (0).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-nonbackgroundsuccessfulrefreshperiod"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_nonbackgroundsuccessfulrefreshperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_nonbackgroundsuccessfulrefreshperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_nonbackgroundsuccessfulrefreshperiod_netlogon_nonbackgroundsuccessfulrefreshperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode","displayName":"Use urgent mode when pinging domain controllers","description":"This policy setting configures whether the computers to which this setting is applied are more aggressive when trying to locate a domain controller (DC).\r\n\r\nWhen an environment has a large number of DCs running both old and new operating systems, the default DC locator discovery behavior may be insufficient to find DCs running a newer operating system. This policy setting can be enabled to configure DC locator to be more aggressive about trying to locate a DC in such an environment, by pinging DCs at a higher frequency. Enabling this setting may result in additional network traffic and increased load on DCs. You should disable this setting once all DCs are running the same OS version.\r\n\r\nThe allowable values for this setting result in the following behaviors:\r\n\r\n1 - Computers will ping DCs at the normal frequency.\r\n2 - Computers will ping DCs at the higher frequency.\r\n\r\nTo specify this behavior, click Enabled and then enter a value. The range of values is from 1 to 2.\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-pingurgencymode"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode_netlogon_pingurgencymodelabel","displayName":"Ping urgency mode:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_scavengeinterval","displayName":"Set scavenge interval","description":"This policy setting determines the interval at which Netlogon performs the following scavenging operations:\r\n\r\n- Checks if a password on a secure channel needs to be modified, and modifies it if necessary.\r\n\r\n- On the domain controllers (DC), discovers a DC that has not been discovered.\r\n\r\n- On the PDC, attempts to add the [1B] NetBIOS name if it hasn’t already been successfully added.\r\n\r\nNone of these operations are critical. 15 minutes is optimal in all but extreme cases. For instance, if a DC is separated from a trusted domain by an expensive (e.g., ISDN) line, this parameter might be adjusted upward to avoid frequent automatic discovery of DCs in a trusted domain.\r\n\r\nTo enable the setting, click Enabled, and then specify the interval in seconds.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-scavengeinterval"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_scavengeinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_scavengeinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_scavengeinterval_netlogon_scavengeintervallabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitecoverage","displayName":"Specify sites covered by the DC Locator DNS SRV records","description":"This policy setting specifies the sites for which the domain controllers (DC) register the site-specific DC Locator DNS SRV resource records. These records are registered in addition to the site-specific SRV records registered for the site where the DC resides, and records registered by a DC configured to register DC Locator DNS SRV records for those sites without a DC that are closest to it. \r\n\r\nThe DC Locator DNS records are dynamically registered by the Net Logon service, and they are used to locate the DC. An Active Directory site is one or more well-connected TCP/IP subnets that allow administrators to configure Active Directory access and replication.\r\n\r\nTo specify the sites covered by the DC Locator DNS SRV records, click Enabled, and then enter the sites names in a space-delimited format.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-sitecoverage"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitecoverage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitecoverage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitecoverage_netlogon_sitecoveragelabel","displayName":"Sites:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename","displayName":"Specify site name","description":"This policy setting specifies the Active Directory site to which computers belong.\r\n\r\nAn Active Directory site is one or more well-connected TCP/IP subnets that allow administrators to configure Active Directory access and replication.\r\n\r\nTo specify the site name for this setting, click Enabled, and then enter the site name. When the site to which a computer belongs is not specified, the computer automatically discovers its site from Active Directory.\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-sitename"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename_netlogon_sitenamelabel","displayName":"Site:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sysvolsharecompatibilitymode","displayName":"Set SYSVOL share compatibility","description":"This policy setting controls whether or not the SYSVOL share created by the Net Logon service on a domain controller (DC) should support compatibility in file sharing semantics with earlier applications.\r\n\r\nWhen this setting is enabled, the SYSVOL share will honor file sharing semantics that grant requests for exclusive read access to files on the share even when the caller has only read permission.\r\n\r\nWhen this setting is disabled or not configured, the SYSVOL share will grant shared read access to files on the share when exclusive access is requested and the caller has only read permission.\r\n\r\nBy default, the SYSVOL share will grant shared read access to files on the share when exclusive access is requested.\r\n\r\nNote: The SYSVOL share is a share created by the Net Logon service for use by Group Policy clients in the domain. The default behavior of the SYSVOL share ensures that no application with only read permission to files on the sysvol share can lock the files by requesting exclusive read access, which might prevent Group Policy settings from being updated on clients in the domain. When this setting is enabled, an application that relies on the ability to lock files on the SYSVOL share with only read permission will be able to deny Group Policy clients from reading the files, and in general the availability of the SYSVOL share on the domain will be decreased.\r\n\r\nIf you enable this policy setting, domain administrators should ensure that the only applications using the exclusive read capability in the domain are those approved by the administrator.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-sysvolsharecompatibilitymode"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sysvolsharecompatibilitymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sysvolsharecompatibilitymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_trynextclosestsite","displayName":"Try Next Closest Site","description":"This policy setting enables DC Locator to attempt to locate a DC in the nearest site based on the site link cost if a DC in same the site is not found. In scenarios with multiple sites, failing over to the try next closest site during DC Location streamlines network traffic more effectively.\r\n\r\nThe DC Locator service is used by clients to find domain controllers for their Active Directory domain. The default behavior for DC Locator is to find a DC in the same site. If none are found in the same site, a DC in another site, which might be several site-hops away, could be returned by DC Locator. Site proximity between two sites is determined by the total site-link cost between them. A site is closer if it has a lower site link cost than another site with a higher site link cost. \r\n\r\nIf you enable this policy setting, Try Next Closest Site DC Location will be turned on for the computer.\r\n\r\nIf you disable this policy setting, Try Next Closest Site DC Location will not be used by default for the computer. However, if a DC Locator call is made using the DS_TRY_NEXTCLOSEST_SITE flag explicitly, the Try Next Closest Site behavior is honored.\r\n\r\nIf you do not configure this policy setting, Try Next Closest Site DC Location will not be used by default for the machine. If the DS_TRY_NEXTCLOSEST_SITE flag is used explicitly, the Next Closest Site behavior will be used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-trynextclosestsite"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_trynextclosestsite_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_trynextclosestsite_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_usedynamicdns","displayName":"Specify dynamic registration of the DC Locator DNS Records","description":"This policy setting determines if dynamic registration of the domain controller (DC) locator DNS resource records is enabled. These DNS records are dynamically registered by the Net Logon service and are used by the Locator algorithm to locate the DC.\r\n\r\nIf you enable this policy setting, DCs to which this setting is applied dynamically register DC Locator DNS resource records through dynamic DNS update-enabled network connections.\r\n\r\nIf you disable this policy setting, DCs will not register DC Locator DNS resource records.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-usedynamicdns"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_usedynamicdns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_usedynamicdns_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_donotshowlocalonlyicon","displayName":"Do not show the \"local access only\" network icon","description":"Specifies whether or not the \"local access only\" network icon will be shown.\r\n\r\nWhen enabled, the icon for Internet access will be shown in the system tray even when a user is connected to a network with local access only.\r\n\r\nIf you disable this setting or do not configure it, the \"local access only\" icon will be used when a user is connected to a network with local access only.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-donotshowlocalonlyicon"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_donotshowlocalonlyicon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_donotshowlocalonlyicon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_forcetunneling","displayName":"Route all traffic through the internal network","description":"This policy setting determines whether a remote client computer routes Internet traffic through the internal network or whether the client accesses the Internet directly.\r\n\r\nWhen a remote client computer connects to an internal network using DirectAccess, it can access the Internet in two ways: through the secure tunnel that DirectAccess establishes between the computer and the internal network, or directly through the local default gateway.\r\n\r\nIf you enable this policy setting, all traffic between a remote client computer running DirectAccess and the Internet is routed through the internal network.\r\n\r\nIf you disable this policy setting, traffic between remote client computers running DirectAccess and the Internet is not routed through the internal network.\r\n\r\nIf you do not configure this policy setting, traffic between remote client computers running DirectAccess and the Internet is not routed through the internal network.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-forcetunneling"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_forcetunneling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_forcetunneling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_forcetunneling_stateselect","displayName":"Select from the following states:","description":null,"helpText":"","infoUrls":[],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_forcetunneling_stateselect_enabled","displayName":"Enabled State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_forcetunneling_stateselect_disabled","displayName":"Disabled State","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_personalfirewallconfig","displayName":"Prohibit use of Internet Connection Firewall on your DNS domain network","description":"Prohibits use of Internet Connection Firewall on your DNS domain network.\r\n\r\nDetermines whether users can enable the Internet Connection Firewall feature on a connection, and if the Internet Connection Firewall service can run on a computer.\r\n\r\nImportant: This setting is location aware. It only applies when a computer is connected to the same DNS domain network it was connected to when the setting was refreshed on that computer. If a computer is connected to a DNS domain network other than the one it was connected to when the setting was refreshed, this setting does not apply.\r\n\r\nThe Internet Connection Firewall is a stateful packet filter for home and small office users to protect them from Internet network security threats.\r\n\r\nIf you enable this setting, Internet Connection Firewall cannot be enabled or configured by users (including administrators), and the Internet Connection Firewall service cannot run on the computer. The option to enable the Internet Connection Firewall through the Advanced tab is removed. In addition, the Internet Connection Firewall is not enabled for remote access connections created through the Make New Connection Wizard. The Network Setup Wizard is disabled.\r\n\r\nNote: If you enable the \"Windows Firewall: Protect all network connections\" policy setting, the \"Prohibit use of Internet Connection Firewall on your DNS domain network\" policy setting has no effect on computers that are running Windows Firewall, which replaces Internet Connection Firewall when you install Windows XP Service Pack 2.\r\n\r\nIf you disable this setting or do not configure it, the Internet Connection Firewall is disabled when a LAN Connection or VPN connection is created, but users can use the Advanced tab in the connection properties to enable it. The Internet Connection Firewall is enabled by default on the connection for which Internet Connection Sharing is enabled. In addition, remote access connections created through the Make New Connection Wizard have the Internet Connection Firewall enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-personalfirewallconfig"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_personalfirewallconfig_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_personalfirewallconfig_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_showsharedaccessui","displayName":"Prohibit use of Internet Connection Sharing on your DNS domain network","description":"Determines whether administrators can enable and configure the Internet Connection Sharing (ICS) feature of an Internet connection and if the ICS service can run on the computer.\r\n\r\nICS lets administrators configure their system as an Internet gateway for a small network and provides network services, such as name resolution and addressing through DHCP, to the local private network.\r\n\r\nIf you enable this setting, ICS cannot be enabled or configured by administrators, and the ICS service cannot run on the computer. The Advanced tab in the Properties dialog box for a LAN or remote access connection is removed. The Internet Connection Sharing page is removed from the New Connection Wizard. The Network Setup Wizard is disabled.\r\n\r\nIf you disable this setting or do not configure it and have two or more connections, administrators can enable ICS. The Advanced tab in the properties dialog box for a LAN or remote access connection is available. In addition, the user is presented with the option to enable Internet Connection Sharing in the Network Setup Wizard and Make New Connection Wizard. (The Network Setup Wizard is available only in Windows XP Professional.)\r\n\r\nBy default, ICS is disabled when you create a remote access connection, but administrators can use the Advanced tab to enable it. When running the New Connection Wizard or Network Setup Wizard, administrators can choose to enable ICS.\r\n\r\nNote: Internet Connection Sharing is only available when two or more network connections are present.\r\n\r\nNote: When the \"Prohibit access to properties of a LAN connection,\" \"Ability to change properties of an all user remote access connection,\" or \"Prohibit changing properties of a private remote access connection\" settings are set to deny access to the Connection Properties dialog box, the Advanced tab for the connection is blocked.\r\n\r\nNote: Nonadministrators are already prohibited from configuring Internet Connection Sharing, regardless of this setting.\r\n\r\nNote: Disabling this setting does not prevent Wireless Hosted Networking from using the ICS service for DHCP services. To prevent the ICS service from running, on the Network Permissions tab in the network's policy properties, select the \"Don't use hosted networks\" check box.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-showsharedaccessui"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_showsharedaccessui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_showsharedaccessui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_stddomainusersetlocation","displayName":"Require domain users to elevate when setting a network's location","description":"This policy setting determines whether to require domain users to elevate when setting a network's location.\r\n\r\nIf you enable this policy setting, domain users must elevate when setting a network's location.\r\n\r\nIf you disable or do not configure this policy setting, domain users can set a network's location without elevating.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-stddomainusersetlocation"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_stddomainusersetlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_stddomainusersetlocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_alwayspinsubfolders","displayName":"Subfolders always available offline","description":"Makes subfolders available offline whenever their parent folder is made available offline.\r\n\r\nThis setting automatically extends the \"make available offline\" setting to all new and existing subfolders of a folder. Users do not have the option of excluding subfolders.\r\n\r\nIf you enable this setting, when you make a folder available offline, all folders within that folder are also made available offline. Also, new folders that you create within a folder that is available offline are made available offline when the parent folder is synchronized.\r\n\r\nIf you disable this setting or do not configure it, the system asks users whether they want subfolders to be made available offline when they make a parent folder available offline.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-alwayspinsubfolders"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_alwayspinsubfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_alwayspinsubfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2","displayName":"Specify administratively assigned Offline Files","description":"This policy setting lists network files and folders that are always available for offline use. This ensures that the specified files and folders are available offline to users of the computer.\r\n\r\nIf you enable this policy setting, the files you enter are always available offline to users of the computer. To specify a file or folder, click Show. In the Show Contents dialog box in the Value Name column, type the fully qualified UNC path to the file or folder. Leave the Value column field blank.\r\n\r\nIf you disable this policy setting, the list of files or folders made always available offline (including those inherited from lower precedence GPOs) is deleted and no files or folders are made available for offline use by Group Policy (though users can still specify their own files and folders for offline use).\r\n\r\nIf you do not configure this policy setting, no files or folders are made available for offline use by Group Policy.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy settings will be combined and all specified files will be available for offline use.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-assignedofflinefiles-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_lbl_assignedofflinefileslist","displayName":"Files and Folders:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_lbl_assignedofflinefileslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_lbl_assignedofflinefileslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings","displayName":"Configure Background Sync","description":"This policy setting controls when background synchronization occurs while operating in slow-link mode, and applies to any user who logs onto the specified machine while this policy is in effect. To control slow-link mode, use the \"Configure slow-link mode\" policy setting.\r\n\r\nIf you enable this policy setting, you can control when Windows synchronizes in the background while operating in slow-link mode. Use the 'Sync Interval' and 'Sync Variance' values to override the default sync interval and variance settings. Use 'Blockout Start Time' and 'Blockout Duration' to set a period of time where background sync is disabled. Use the 'Maximum Allowed Time Without A Sync' value to ensure that all network folders on the machine are synchronized with the server on a regular basis.\r\n\r\nYou can also configure Background Sync for network shares that are in user selected Work Offline mode. This mode is in effect when a user selects the Work Offline button for a specific share. When selected, all configured settings will apply to shares in user selected Work Offline mode as well.\r\n\r\nIf you disable or do not configure this policy setting, Windows performs a background sync of offline folders in the slow-link mode at a default interval with the start of the sync varying between 0 and 60 additional minutes. In Windows 7 and Windows Server 2008 R2, the default sync interval is 360 minutes. In Windows 8 and Windows Server 2012, the default sync interval is 120 minutes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-backgroundsyncsettings"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncblockoutperiodduration","displayName":"Blockout Duration (minutes)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncblockoutperiodstarttime","displayName":"Blockout Start Time (HHMM)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncdefaultsynctime","displayName":"Sync Interval (minutes)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncignoreblockouttime","displayName":"Maximum Allowed Time Without A Sync (minutes)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncinforcedoffline","displayName":"Enable Background Sync for shares in user selected \"Work Offline\" mode","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncinforcedoffline_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncinforcedoffline_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncvariance","displayName":"Sync Variance (minutes)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize","displayName":"Limit disk space used by Offline Files","description":"This policy setting limits the amount of disk space that can be used to store offline files. This includes the space used by automatically cached files and files that are specifically made available offline. Files can be automatically cached if the user accesses a file on an automatic caching network share.\r\n\r\nThis setting also disables the ability to adjust, through the Offline Files control panel applet, the disk space limits on the Offline Files cache. This prevents users from trying to change the option while a policy setting controls it.\r\n\r\nIf you enable this policy setting, you can specify the disk space limit (in megabytes) for offline files and also specify how much of that disk space can be used by automatically cached files.\r\n\r\nIf you disable this policy setting, the system limits the space that offline files occupy to 25 percent of the total space on the drive where the Offline Files cache is located. The limit for automatically cached files is 100 percent of the total disk space limit.\r\n\r\nIf you do not configure this policy setting, the system limits the space that offline files occupy to 25 percent of the total space on the drive where the Offline Files cache is located. The limit for automatically cached files is 100 percent of the total disk space limit. However, the users can change these values using the Offline Files control applet.\r\n\r\nIf you enable this setting and specify a total size limit greater than the size of the drive hosting the Offline Files cache, and that drive is the system drive, the total size limit is automatically adjusted downward to 75 percent of the size of the drive. If the cache is located on a drive other than the system drive, the limit is automatically adjusted downward to 100 percent of the size of the drive.\r\n\r\nIf you enable this setting and specify a total size limit less than the amount of space currently used by the Offline Files cache, the total size limit is automatically adjusted upward to the amount of space currently used by offline files. The cache is then considered full.\r\n\r\nIf you enable this setting and specify an auto-cached space limit greater than the total size limit, the auto-cached limit is automatically adjusted downward to equal the total size limit.\r\n\r\nThis setting replaces the Default Cache Size setting used by pre-Windows Vista systems.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-cachesize"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize_lbl_autocachesizespin","displayName":"Size of auto-cached files:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize_lbl_totalcachesizespin","displayName":"Total size of offline files:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_2","displayName":"Non-default server disconnect actions","description":"Determines how computers respond when they are disconnected from particular offline file servers. This setting overrides the default response, a user-specified response, and the response specified in the \"Action on server disconnect\" setting.\r\n\r\nTo use this setting, click Show. In the Show Contents dialog box in the Value Name column box, type the server's computer name. Then, in the Value column box, type \"0\" if users can work offline when they are disconnected from this server, or type \"1\" if they cannot.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured for a particular server, the setting in Computer Configuration takes precedence over the setting in User Configuration. Both Computer and User configuration take precedence over a user's setting. This setting does not prevent users from setting custom actions through the Offline Files tab. However, users are unable to change any custom actions established via this setting.\r\n\r\nTip: To configure this setting without establishing a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then click Advanced. This setting corresponds to the settings in the \"Exception list\" section.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-customgoofflineactions-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_2_lbl_customgoofflineactionslist","displayName":"Customize actions:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_2_lbl_customgoofflineactionslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_2_lbl_customgoofflineactionslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize","displayName":"Default cache size","description":"Limits the percentage of the computer's disk space that can be used to store automatically cached offline files.\r\n\r\nThis setting also disables the \"Amount of disk space to use for temporary offline files\" option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.\r\n\r\nAutomatic caching can be set on any network share. When a user opens a file on the share, the system automatically stores a copy of the file on the user's computer.\r\n\r\nThis setting does not limit the disk space available for files that user's make available offline manually.\r\n\r\nIf you enable this setting, you can specify an automatic-cache disk space limit.\r\n\r\nIf you disable this setting, the system limits the space that automatically cached files occupy to 10 percent of the space on the system drive.\r\n\r\nIf you do not configure this setting, disk space for automatically cached files is limited to 10 percent of the system drive by default, but users can change it.\r\n\r\nTip: To change the amount of disk space used for automatic caching without specifying a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then use the slider bar associated with the \"Amount of disk space to use for temporary offline files\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-defcachesize"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize_lbl_defcachesizespin","displayName":"Default cache size:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_enabled","displayName":"Allow or Disallow use of the Offline Files feature","description":"This policy setting determines whether the Offline Files feature is enabled. Offline Files saves a copy of network files on the user's computer for use when the computer is not connected to the network.\r\n\r\nIf you enable this policy setting, Offline Files is enabled and users cannot disable it.\r\n\r\nIf you disable this policy setting, Offline Files is disabled and users cannot enable it.\r\n\r\nIf you do not configure this policy setting, Offline Files is enabled on Windows client computers, and disabled on computers running Windows Server, unless changed by the user.\r\n\r\nNote: Changes to this policy setting do not take effect until the affected computer is restarted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-enabled"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_encryptofflinefiles","displayName":"Encrypt the Offline Files cache","description":"This policy setting determines whether offline files are encrypted.\r\n\r\nOffline files are locally cached copies of files from a network share. Encrypting this cache reduces the likelihood that a user could access files from the Offline Files cache without proper permissions.\r\n\r\nIf you enable this policy setting, all files in the Offline Files cache are encrypted. This includes existing files as well as files added later. The cached copy on the local computer is affected, but the associated network copy is not. The user cannot unencrypt Offline Files through the user interface.\r\n\r\nIf you disable this policy setting, all files in the Offline Files cache are unencrypted. This includes existing files as well as files added later, even if the files were stored using NTFS encryption or BitLocker Drive Encryption while on the server. The cached copy on the local computer is affected, but the associated network copy is not. The user cannot encrypt Offline Files through the user interface.\r\n\r\nIf you do not configure this policy setting, encryption of the Offline Files cache is controlled by the user through the user interface. The current cache state is retained, and if the cache is only partially encrypted, the operation completes so that it is fully encrypted. The cache does not return to the unencrypted state. The user must be an administrator on the local computer to encrypt or decrypt the Offline Files cache.\r\n\r\nNote: By default, this cache is protected on NTFS partitions by ACLs.\r\n\r\nThis setting is applied at user logon. If this setting is changed after user logon then user logoff and logon is required for this setting to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-encryptofflinefiles"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_encryptofflinefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_encryptofflinefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_eventlogginglevel_2","displayName":"Event logging level","description":"Determines which events the Offline Files feature records in the event log.\r\n\r\nOffline Files records events in the Application log in Event Viewer when it detects errors. By default, Offline Files records an event only when the offline files storage cache is corrupted. However, you can use this setting to specify additional events you want Offline Files to record.\r\n\r\nTo use this setting, in the \"Enter\" box, select the number corresponding to the events you want the system to log. The levels are cumulative; that is, each level includes the events in all preceding levels.\r\n\r\n\"0\" records an error when the offline storage cache is corrupted.\r\n\r\n\"1\" also records an event when the server hosting the offline file is disconnected from the network.\r\n\r\n\"2\" also records events when the local computer is connected and disconnected from the network.\r\n\r\n\"3\" also records an event when the server hosting the offline file is reconnected to the network.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-eventlogginglevel-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_eventlogginglevel_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_eventlogginglevel_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_eventlogginglevel_2_lbl_eventlogginglevelspin","displayName":"Enter [0-3]:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings","displayName":"Enable file screens","description":"This policy setting enables administrators to block certain file types from being created in the folders that have been made available offline.\r\n\r\nIf you enable this policy setting, a user will be unable to create files with the specified file extensions in any of the folders that have been made available offline.\r\n\r\nIf you disable or do not configure this policy setting, a user can create a file of any type in the folders that have been made available offline.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-exclusionlistsettings"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings_lbl_exclusionlistsettingslist","displayName":"Extensions: ","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_extexclusionlist","displayName":"Files not cached","description":"Lists types of files that cannot be used offline.\r\n\r\nThis setting lets you exclude certain types of files from automatic and manual caching for offline use. The system does not cache files of the type specified in this setting even when they reside on a network share configured for automatic caching. Also, if users try to make a file of this type available offline, the operation will fail and the following message will be displayed in the Synchronization Manager progress dialog box: \"Files of this type cannot be made available offline.\"\r\n\r\nThis setting is designed to protect files that cannot be separated, such as database components.\r\n\r\nTo use this setting, type the file name extension in the \"Extensions\" box. To type more than one extension, separate the extensions with a semicolon (;).\r\n\r\nNote: To make changes to this setting effective, you must log off and log on again.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-extexclusionlist"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_extexclusionlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_extexclusionlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_extexclusionlist_lbl_extexclusionlistedit","displayName":"Extensions: ","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2","displayName":"Action on server disconnect","description":"Determines whether network files remain available if the computer is suddenly disconnected from the server hosting the files.\r\n\r\nThis setting also disables the \"When a network connection is lost\" option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.\r\n\r\nIf you enable this setting, you can use the \"Action\" box to specify how computers in the group respond.\r\n\r\n-- \"Work offline\" indicates that the computer can use local copies of network files while the server is inaccessible.\r\n\r\n-- \"Never go offline\" indicates that network files are not available while the server is inaccessible.\r\n\r\nIf you disable this setting or select the \"Work offline\" option, users can work offline if disconnected.\r\n\r\nIf you do not configure this setting, users can work offline by default, but they can change this option.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To configure this setting without establishing a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, click Advanced, and then select an option in the \"When a network connection is lost\" section.\r\n\r\nAlso, see the \"Non-default server disconnect actions\" setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-goofflineaction-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_lbl_goofflineactioncombo","displayName":"Action:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_lbl_goofflineactioncombo_0","displayName":"Work offline","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_lbl_goofflineactioncombo_1","displayName":"Never go offline","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nocacheviewer_2","displayName":"Prevent use of Offline Files folder","description":"Disables the Offline Files folder.\r\n\r\nThis setting disables the \"View Files\" button on the Offline Files tab. As a result, users cannot use the Offline Files folder to view or open copies of network files stored on their computer. Also, they cannot use the folder to view characteristics of offline files, such as their server status, type, or location.\r\n\r\nThis setting does not prevent users from working offline or from saving local copies of files available offline. Also, it does not prevent them from using other programs, such as Windows Explorer, to view their offline files.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To view the Offline Files Folder, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then click \"View Files.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-nocacheviewer-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nocacheviewer_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nocacheviewer_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noconfigcache_2","displayName":"Prohibit user configuration of Offline Files","description":"Prevents users from enabling, disabling, or changing the configuration of Offline Files.\r\n\r\nThis setting removes the Offline Files tab from the Folder Options dialog box. It also removes the Settings item from the Offline Files context menu and disables the Settings button on the Offline Files Status dialog box. As a result, users cannot view or change the options on the Offline Files tab or Offline Files dialog box.\r\n\r\nThis is a comprehensive setting that locks down the configuration you establish by using other settings in this folder.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: This setting provides a quick method for locking down the default settings for Offline Files. To accept the defaults, just enable this setting. You do not have to disable any other settings in this folder.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-noconfigcache-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noconfigcache_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noconfigcache_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nomakeavailableoffline_2","displayName":"Remove \"Make Available Offline\" command","description":"This policy setting prevents users from making network files and folders available offline.\r\n\r\nIf you enable this policy setting, users cannot designate files to be saved on their computer for offline use. However, Windows will still cache local copies of files that reside on network shares designated for automatic caching.\r\n\r\nIf you disable or do not configure this policy setting, users can manually specify files and folders that they want to make available offline.\r\n\r\nNotes:\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy setting in Computer Configuration takes precedence.\r\n\r\nThe \"Make Available Offline\" command is called \"Always available offline\" on computers running Windows Server 2012, Windows Server 2008 R2, Windows Server 2008, Windows 8, Windows 7, or Windows Vista.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-nomakeavailableoffline-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nomakeavailableoffline_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nomakeavailableoffline_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2","displayName":"Remove \"Make Available Offline\" for these files and folders","description":"This policy setting allows you to manage a list of files and folders for which you want to block the \"Make Available Offline\" command.\r\n\r\nIf you enable this policy setting, the \"Make Available Offline\" command is not available for the files and folders that you list. To specify these files and folders, click Show. In the Show Contents dialog box, in the Value Name column box, type the fully qualified UNC path to the file or folder. Leave the Value column field blank.\r\n\r\nIf you disable this policy setting, the list of files and folders is deleted, including any lists inherited from lower precedence GPOs, and the \"Make Available Offline\" command is displayed for all files and folders.\r\n\r\nIf you do not configure this policy setting, the \"Make Available Offline\" command is available for all files and folders.\r\n\r\nNotes:\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy settings are combined, and the \"Make Available Offline\" command is unavailable for all specified files and folders.\r\n\r\nThe \"Make Available Offline\" command is called \"Always available offline\" on computers running Windows Server 2012, Windows Server 2008 R2, Windows Server 2008, Windows 8, Windows 7, or Windows Vista.\r\n\r\nThis policy setting does not prevent files from being automatically cached if the network share is configured for \"Automatic Caching.\" It only affects the display of the \"Make Available Offline\" command in File Explorer.\r\n\r\nIf the \"Remove 'Make Available Offline' command\" policy setting is enabled, this setting has no effect.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-nopinfiles-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_lbl_nopinfileslist","displayName":"Files and Folders:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_lbl_nopinfileslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_lbl_nopinfileslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noreminders_2","displayName":"Turn off reminder balloons","description":"Hides or displays reminder balloons, and prevents users from changing the setting.\r\n\r\nReminder balloons appear above the Offline Files icon in the notification area to notify users when they have lost the connection to a networked file and are working on a local copy of the file. Users can then decide how to proceed.\r\n\r\nIf you enable this setting, the system hides the reminder balloons, and prevents users from displaying them.\r\n\r\nIf you disable the setting, the system displays the reminder balloons and prevents users from hiding them.\r\n\r\nIf this setting is not configured, reminder balloons are displayed by default when you enable offline files, but users can change the setting.\r\n\r\nTo prevent users from changing the setting while a setting is in effect, the system disables the \"Enable reminders\" option on the Offline Files tab\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To display or hide reminder balloons without establishing a setting, in Windows Explorer, on the Tools menu, click Folder Options, and then click the Offline Files tab. This setting corresponds to the \"Enable reminders\" check box.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-noreminders-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noreminders_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noreminders_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings","displayName":"Enable Transparent Caching","description":"This policy setting controls whether files read from file shares over a slow network are transparently cached in the Offline Files cache for future reads. When a user tries to access a file that has been transparently cached, Windows reads from the cached copy after verifying its integrity. This improves end-user response times and decreases bandwidth consumption over WAN links.\r\n\r\nThe cached files are temporary and are not available to the user when offline. The cached files are not kept in sync with the version on the server, and the most current version from the server is always available for subsequent reads.\r\n\r\nThis policy setting is triggered by the configured round trip network latency value. We recommend using this policy setting when the network connection to the server is slow. For example, you can configure a value of 60 ms as the round trip latency of the network above which files should be transparently cached in the Offline Files cache. If the round trip latency of the network is less than 60ms, reads to remote files will not be cached.\r\n\r\nIf you enable this policy setting, transparent caching is enabled and configurable.\r\n\r\nIf you disable or do not configure this policy setting, remote files will be not be transparently cached on client computers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-onlinecachingsettings"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings_lbl_onlinecachingsettingslist","displayName":"Enter network latency value in milliseconds","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_purgeatlogoff","displayName":"At logoff, delete local copy of user’s offline files","description":"Deletes local copies of the user's offline files when the user logs off.\r\n\r\nThis setting specifies that automatically and manually cached offline files are retained only while the user is logged on to the computer. When the user logs off, the system deletes all local copies of offline files.\r\n\r\nIf you disable this setting or do not configure it, automatically and manually cached copies are retained on the user's computer for later offline use.\r\n\r\nCaution: Files are not synchronized before they are deleted. Any changes to local files since the last synchronization are lost.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-purgeatlogoff"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_purgeatlogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_purgeatlogoff_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_purgeatlogoff_lbl_purgeonlyautocachedfiles","displayName":"Delete only the temporary offline files.","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_purgeatlogoff_lbl_purgeonlyautocachedfiles_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_purgeatlogoff_lbl_purgeonlyautocachedfiles_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_quickadimpin","displayName":"Turn on economical application of administratively assigned Offline Files","description":"This policy setting allows you to turn on economical application of administratively assigned Offline Files.\r\n\r\nIf you enable or do not configure this policy setting, only new files and folders in administratively assigned folders are synchronized at logon. Files and folders that are already available offline are skipped and are synchronized later.\r\n\r\nIf you disable this policy setting, all administratively assigned folders are synchronized at logon.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-quickadimpin"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_quickadimpin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_quickadimpin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2","displayName":"Reminder balloon frequency","description":"Determines how often reminder balloon updates appear.\r\n\r\nIf you enable this setting, you can select how often reminder balloons updates appear and also prevent users from changing this setting.\r\n\r\nReminder balloons appear when the user's connection to a network file is lost or reconnected, and they are updated periodically. By default, the first reminder for an event is displayed for 30 seconds. Then, updates appear every 60 minutes and are displayed for 15 seconds. You can use this setting to change the update interval.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To set reminder balloon frequency without establishing a setting, in Windows Explorer, on the Tools menu, click Folder Options, and then click the Offline Files tab. This setting corresponds to the \"Display reminder balloons every ... minutes\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-reminderfreq-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2_lbl_reminderfreqspin","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_2","displayName":"Initial reminder balloon lifetime","description":"Determines how long the first reminder balloon for a network status change is displayed.\r\n\r\nReminder balloons appear when the user's connection to a network file is lost or reconnected, and they are updated periodically. By default, the first reminder for an event is displayed for 30 seconds. Then, updates appear every 60 minutes and are displayed for 15 seconds. You can use this setting to change the duration of the first reminder.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-reminderinittimeout-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_2_lbl_reminderinittimeoutspin","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_remindertimeout_2","displayName":"Reminder balloon lifetime","description":"Determines how long updated reminder balloons are displayed.\r\n\r\nReminder balloons appear when the user's connection to a network file is lost or reconnected, and they are updated periodically. By default, the first reminder for an event is displayed for 30 seconds. Then, updates appear every 60 minutes and are displayed for 15 seconds. You can use this setting to change the duration of the update reminder.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-remindertimeout-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_remindertimeout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_remindertimeout_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_remindertimeout_2_lbl_remindertimeoutspin","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings","displayName":"Configure slow-link mode","description":"This policy setting controls the network latency and throughput thresholds that will cause a client computers to transition files and folders that are already available offline to the slow-link mode so that the user's access to this data is not degraded due to network slowness. When Offline Files is operating in the slow-link mode, all network file requests are satisfied from the Offline Files cache. This is similar to a user working offline.\r\n\r\nIf you enable this policy setting, Offline Files uses the slow-link mode if the network throughput between the client and the server is below (slower than) the Throughput threshold parameter, or if the round-trip network latency is above (slower than) the Latency threshold parameter.\r\n\r\nYou can configure the slow-link mode by specifying threshold values for Throughput (in bits per second) and/or Latency (in milliseconds) for specific UNC paths. We recommend that you always specify a value for Latency, since the round-trip network latency detection is faster. You can use wildcard characters (*) for specifying UNC paths. If you do not specify a Latency or Throughput value, computers running Windows Vista or Windows Server 2008 will not use the slow-link mode.\r\n\r\nIf you do not configure this policy setting, computers running Windows Vista or Windows Server 2008 will not transition a shared folder to the slow-link mode. Computers running Windows 7 or Windows Server 2008 R2 will use the default latency value of 80 milliseconds when transitioning a folder to the slow-link mode. Computers running Windows 8 or Windows Server 2012 will use the default latency value of 35 milliseconds when transitioning a folder to the slow-link mode. To avoid extra charges on cell phone or broadband plans, it may be necessary to configure the latency threshold to be lower than the round-trip network latency.\r\n\r\nIn Windows Vista or Windows Server 2008, once transitioned to slow-link mode, users will continue to operate in slow-link mode until the user clicks the Work Online button on the toolbar in Windows Explorer. Data will only be synchronized to the server if the user manually initiates synchronization by using Sync Center.\r\n\r\nIn Windows 7, Windows Server 2008 R2, Windows 8 or Windows Server 2012, when operating in slow-link mode Offline Files synchronizes the user's files in the background at regular intervals, or as configured by the \"Configure Background Sync\" policy. While in slow-link mode, Windows periodically checks the connection to the folder and brings the folder back online if network speeds improve.\r\n\r\nIn Windows 8 or Windows Server 2012, set the Latency threshold to 1ms to keep users always working offline in slow-link mode.\r\n\r\nIf you disable this policy setting, computers will not use the slow-link mode.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-slowlinksettings"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_lbl_slowlinksettingslist","displayName":"UNC Paths:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_lbl_slowlinksettingslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_lbl_slowlinksettingslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinkspeed","displayName":"Configure Slow link speed","description":"Configures the threshold value at which Offline Files considers a network connection to be \"slow\". Any network speed below this value is considered to be slow.\r\n\r\nWhen a connection is considered slow, Offline Files automatically adjust its behavior to avoid excessive synchronization traffic and will not automatically reconnect to a server when the presence of a server is detected.\r\n\r\nIf you enable this setting, you can configure the threshold value that will be used to determine a slow network connection.\r\n\r\nIf this setting is disabled or not configured, the default threshold value of 64,000 bps is used to determine if a network connection is considered to be slow.\r\n\r\nNote: Use the following formula when entering the slow link value: [ bps / 100]. For example, if you want to set a threshold value of 128,000 bps, enter a value of 1280.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-slowlinkspeed"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinkspeed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinkspeed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinkspeed_lbl_slowlinkspeedspin","displayName":"Value:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogoff_2","displayName":"Synchronize all offline files before logging off","description":"Determines whether offline files are fully synchronized when users log off.\r\n\r\nThis setting also disables the \"Synchronize all offline files before logging off\" option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.\r\n\r\nIf you enable this setting, offline files are fully synchronized. Full synchronization ensures that offline files are complete and current.\r\n\r\nIf you disable this setting, the system only performs a quick synchronization. Quick synchronization ensures that files are complete, but does not ensure that they are current.\r\n\r\nIf you do not configure this setting, the system performs a quick synchronization by default, but users can change this option.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To change the synchronization method without changing a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then select the \"Synchronize all offline files before logging off\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-syncatlogoff-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogoff_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogoff_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogon_2","displayName":"Synchronize all offline files when logging on","description":"Determines whether offline files are fully synchronized when users log on.\r\n\r\nThis setting also disables the \"Synchronize all offline files before logging on\" option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.\r\n\r\nIf you enable this setting, offline files are fully synchronized at logon. Full synchronization ensures that offline files are complete and current. Enabling this setting automatically enables logon synchronization in Synchronization Manager.\r\n\r\nIf this setting is disabled and Synchronization Manager is configured for logon synchronization, the system performs only a quick synchronization. Quick synchronization ensures that files are complete but does not ensure that they are current.\r\n\r\nIf you do not configure this setting and Synchronization Manager is configured for logon synchronization, the system performs a quick synchronization by default, but users can change this option.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To change the synchronization method without setting a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then select the \"Synchronize all offline files before logging on\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-syncatlogon-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogon_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogon_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_2","displayName":"Synchronize offline files before suspend","description":"Determines whether offline files are synchonized before a computer is suspended.\r\n\r\nIf you enable this setting, offline files are synchronized whenever the computer is suspended. Setting the synchronization action to \"Quick\" ensures only that all files in the cache are complete. Setting the synchronization action to \"Full\" ensures that all cached files and folders are up-to-date with the most current version.\r\n\r\nIf you disable or do not configuring this setting, files are not synchronized when the computer is suspended.\r\n\r\nNote: If the computer is suspended by closing the display on a portable computer, files are not synchronized. If multiple users are logged on to the computer at the time the computer is suspended, a synchronization is not performed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-syncatsuspend-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_2_lbl_syncatsuspendcombo","displayName":"Action:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_2_lbl_syncatsuspendcombo_0","displayName":"Quick","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_2_lbl_syncatsuspendcombo_1","displayName":"Full","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_synconcostednetwork","displayName":"Enable file synchronization on costed networks","description":"This policy setting determines whether offline files are synchronized in the background when it could result in extra charges on cell phone or broadband plans.\r\n\r\nIf you enable this setting, synchronization can occur in the background when the user's network is roaming, near, or over the plan's data limit. This may result in extra charges on cell phone or broadband plans.\r\n\r\nIf this setting is disabled or not configured, synchronization will not run in the background on network folders when the user's network is roaming, near, or over the plan's data limit. The network folder must also be in \"slow-link\" mode, as specified by the \"Configure slow-link mode\" policy to avoid network usage.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-synconcostednetwork"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_synconcostednetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_synconcostednetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_workofflinedisabled_2","displayName":"Remove \"Work offline\" command","description":"This policy setting removes the \"Work offline\" command from Explorer, preventing users from manually changing whether Offline Files is in online mode or offline mode.\r\n\r\nIf you enable this policy setting, the \"Work offline\" command is not displayed in File Explorer.\r\n\r\nIf you disable or do not configure this policy setting, the \"Work offline\" command is displayed in File Explorer.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-workofflinedisabled-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_workofflinedisabled_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_workofflinedisabled_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectblockeddriverspolicy","displayName":"Notify blocked drivers","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectblockeddriverspolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectblockeddriverspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectblockeddriverspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomcomponentfailurespolicy","displayName":"Detect application failures caused by deprecated COM objects","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectdeprecatedcomcomponentfailurespolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomcomponentfailurespolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomcomponentfailurespolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomcomponentfailurespolicy_detectdeprecatedcomcomponentfailureslevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomcomponentfailurespolicy_detectdeprecatedcomcomponentfailureslevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomcomponentfailurespolicy_detectdeprecatedcomcomponentfailureslevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy","displayName":"Detect application failures caused by deprecated Windows DLLs","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectdeprecatedcomponentfailurespolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_detectdeprecatedcomponentfailureslevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_detectdeprecatedcomponentfailureslevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_detectdeprecatedcomponentfailureslevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectinstallfailurespolicy","displayName":"Detect application install failures","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectinstallfailurespolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectinstallfailurespolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectinstallfailurespolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectundetectedinstallerspolicy","displayName":"Detect application installers that need to be run as administrator","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectundetectedinstallerspolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectundetectedinstallerspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectundetectedinstallerspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectundetectedinstallerspolicy_detectundetectedinstallerslevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectundetectedinstallerspolicy_detectundetectedinstallerslevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectundetectedinstallerspolicy_detectundetectedinstallerslevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy","displayName":"Detect applications unable to launch installers under UAC","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectupdatefailurespolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_detectupdatefailureslevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_detectupdatefailureslevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_detectupdatefailureslevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_disablepcauipolicy","displayName":"Detect compatibility issues for applications and drivers","description":"This policy setting configures the Program Compatibility Assistant (PCA) to diagnose failures with application and driver compatibility. \r\n\r\nIf you enable this policy setting, the PCA is configured to detect failures during application installation, failures during application runtime, and drivers blocked due to compatibility issues. When failures are detected, the PCA will provide options to run the application in a compatibility mode or get help online through a Microsoft website.\r\n\r\nIf you disable this policy setting, the PCA does not detect compatibility issues for applications and drivers.\r\n\r\nIf you do not configure this policy setting, the PCA is configured to detect failures during application installation, failures during application runtime, and drivers blocked due to compatibility issues.\r\n\r\nNote: This policy setting has no effect if the \"Turn off Program Compatibility Assistant\" policy setting is enabled. The Diagnostic Policy Service (DPS) and Program Compatibility Assistant Service must be running for the PCA to run. These services can be configured by using the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-disablepcauipolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_disablepcauipolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_disablepcauipolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache","displayName":"Turn on BranchCache","description":"This policy setting specifies whether BranchCache is enabled on client computers to which this policy is applied. In addition to this policy setting, you must specify whether the client computers are hosted cache mode or distributed cache mode clients. To do so, configure one of the following the policy settings: \r\n\r\n- Set BranchCache Distributed Cache mode\r\n\r\n- Set BranchCache Hosted Cache mode\r\n\r\n- Configure Hosted Cache Servers\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to enable BranchCache on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the enabled setting that you use on individual client computers where you want to enable BranchCache.\r\n\r\n- Enabled. With this selection, BranchCache is turned on for all client computers where the policy is applied. For example, if this policy is enabled in domain Group Policy, BranchCache is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache is turned off for all client computers where the policy is applied.\r\n\r\n* This policy setting is supported on computers that are running Windows Vista Business, Enterprise, and Ultimate editions with Background Intelligent Transfer Service (BITS) 4.0 installed.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-enablewindowsbranchcache"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_distributed","displayName":"Set BranchCache Distributed Cache mode","description":"This policy setting specifies whether BranchCache distributed cache mode is enabled on client computers to which this policy is applied. In addition to this policy, you must use the policy \"Turn on BranchCache\" to enable BranchCache on client computers.\r\n\r\nIn distributed cache mode, client computers download content from BranchCache-enabled main office content servers, cache the content locally, and serve the content to other BranchCache distributed cache mode clients in the branch office.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to enable BranchCache on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the enabled setting that you use on individual client computers where you want to enable BranchCache.\r\n\r\n- Enabled. With this selection, BranchCache distributed cache mode is enabled for all client computers where the policy is applied. For example, if this policy is enabled in domain Group Policy, BranchCache distributed cache mode is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache distributed cache mode is turned off for all client computers where the policy is applied.\r\n\r\n* This policy setting is supported on computers that are running Windows Vista Business, Enterprise, and Ultimate editions with Background Intelligent Transfer Service (BITS) 4.0 installed.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-enablewindowsbranchcache-distributed"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_distributed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_distributed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hosted","displayName":"Set BranchCache Hosted Cache mode","description":"This policy setting specifies whether BranchCache hosted cache mode is enabled on client computers to which this policy is applied. In addition to this policy, you must use the policy \"Turn on BranchCache\" to enable BranchCache on client computers.\r\n\r\nWhen a client computer is configured as a hosted cache mode client, it is able to download cached content from a hosted cache server that is located at the branch office. In addition, when the hosted cache client obtains content from a content server, the client can upload the content to the hosted cache server for access by other hosted cache clients at the branch office.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to enable BranchCache on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the enabled setting that you use on individual client computers where you want to enable BranchCache.\r\n\r\n- Enabled. With this selection, BranchCache hosted cache mode is enabled for all client computers where the policy is applied. For example, if this policy is enabled in domain Group Policy, BranchCache hosted cache mode is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache hosted cache mode is turned off for all client computers where the policy is applied.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\n- Type the name of the hosted cache server. Specifies the computer name of the hosted cache server. Because the hosted cache server name is also specified in the certificate enrolled to the hosted cache server, the name that you enter here must match the name of the hosted cache server that is specified in the server certificate. \r\n\r\nHosted cache clients must trust the server certificate that is issued to the hosted cache server. Ensure that the issuing CA certificate is installed in the Trusted Root Certification Authorities certificate store on all hosted cache client computers.\r\n\r\n* This policy setting is supported on computers that are running Windows Vista Business, Enterprise, and Ultimate editions with Background Intelligent Transfer Service (BITS) 4.0 installed.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-enablewindowsbranchcache-hosted"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hosted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hosted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hosted_wbc_cache_textbox","displayName":"Type the name of the hosted cache server","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedcachediscovery","displayName":"Enable Automatic Hosted Cache Discovery by Service Connection Point","description":"This policy setting specifies whether client computers should attempt the automatic configuration of hosted cache mode by searching for hosted cache servers publishing service connection points that are associated with the client's current Active Directory site. If you enable this policy setting, client computers to which the policy setting is applied search for hosted cache servers using Active Directory, and will prefer both these servers and hosted cache mode rather than manual BranchCache configuration or BranchCache configuration by other group policies.\r\n\r\nIf you enable this policy setting in addition to the \"Turn on BranchCache\" policy setting, BranchCache clients attempt to discover hosted cache servers in the local branch office. If client computers detect hosted cache servers, hosted cache mode is turned on. If they do not detect hosted cache servers, hosted cache mode is not turned on, and the client uses any other configuration that is specified manually or by Group Policy.\r\n\r\nWhen this policy setting is applied, the client computer performs or does not perform automatic hosted cache server discovery under the following circumstances:\r\n\r\nIf no other BranchCache mode-based policy settings are applied, the client computer performs automatic hosted cache server discovery. If one or more hosted cache servers is found, the client computer self-configures for hosted cache mode.\r\n\r\nIf the policy setting \"Set BranchCache Distributed Cache Mode\" is applied in addition to this policy, the client computer performs automatic hosted cache server discovery. If one or more hosted cache servers are found, the client computer self-configures for hosted cache mode only.\r\n\r\nIf the policy setting \"Set BranchCache Hosted Cache Mode\" is applied, the client computer does not perform automatic hosted cache discovery. This is also true in cases where the policy setting \"Configure Hosted Cache Servers\" is applied.\r\n\r\nThis policy setting can only be applied to client computers that are running at least Windows 8. This policy has no effect on computers that are running Windows 7 or Windows Vista. \r\n\r\nIf you disable, or do not configure this setting, a client will not attempt to discover hosted cache servers by service connection point.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy setting, and client computers do not perform hosted cache server discovery.\r\n\r\n- Enabled. With this selection, the policy setting is applied to client computers, which perform automatic hosted cache server discovery and which are configured as hosted cache mode clients.\r\n\r\n- Disabled. With this selection, this policy is not applied to client computers.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-enablewindowsbranchcache-hostedcachediscovery"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedcachediscovery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedcachediscovery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedmultipleservers","displayName":"Configure Hosted Cache Servers","description":"This policy setting specifies whether client computers are configured to use hosted cache mode and provides the computer name of the hosted cache servers that are available to the client computers. Hosted cache mode enables client computers in branch offices to retrieve content from one or more hosted cache servers that are installed in the same office location. You can use this setting to automatically configure client computers that are configured for hosted cache mode with the computer names of the hosted cache servers in the branch office.\r\n\r\nIf you enable this policy setting and specify valid computer names of hosted cache servers, hosted cache mode is enabled for all client computers to which the policy setting is applied. For this policy setting to take effect, you must also enable the \"Turn on BranchCache\" policy setting.\r\n\r\nThis policy setting can only be applied to client computers that are running at least Windows 8. This policy has no effect on computers that are running Windows 7 or Windows Vista. Client computers to which this policy setting is applied, in addition to the \"Set BranchCache Hosted Cache mode\" policy setting, use the hosted cache servers that are specified in this policy setting and do not use the hosted cache server that is configured in the policy setting \"Set BranchCache Hosted Cache Mode.\"\r\n\r\nIf you do not configure this policy setting, or if you disable this policy setting, client computers that are configured with hosted cache mode still function correctly.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy setting.\r\n\r\n- Enabled. With this selection, the policy setting is applied to client computers, which are configured as hosted cache mode clients that use the hosted cache servers that you specify in \"Hosted cache servers.\"\r\n\r\n- Disabled. With this selection, this policy is not applied to client computers.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\n- Hosted cache servers. To add hosted cache server computer names to this policy setting, click Enabled, and then click Show. The Show Contents dialog box opens. Click Value, and then type the computer names of the hosted cache servers.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-enablewindowsbranchcache-hostedmultipleservers"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedmultipleservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedmultipleservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedmultipleservers_wbc_multipleservers_listbox","displayName":"Hosted cache servers","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_smb","displayName":"Configure BranchCache for network files","description":"This policy setting is used only when you have deployed one or more BranchCache-enabled file servers at your main office. This policy setting specifies when client computers in branch offices start caching content from file servers based on the network latency - or delay - that occurs when the clients download content from the main office over a Wide Area Network (WAN) link. When you configure a value for this setting, which is the maximum round trip network latency allowed before caching begins, clients do not cache content until the network latency reaches the specified value; when network latency is greater than the value, clients begin caching content after they receive it from the file servers.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache latency settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to configure a BranchCache latency setting on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache latency settings on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the latency setting that you use on individual client computers.\r\n\r\n- Enabled. With this selection, the BranchCache maximum round trip latency setting is enabled for all client computers where the policy is applied. For example, if Configure BranchCache for network files is enabled in domain Group Policy, the BranchCache latency setting that you specify in the policy is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache client computers use the default latency setting of 80 milliseconds.\r\n\r\nIn circumstances where this policy setting is enabled, you can also select and configure the following option:\r\n\r\n- Type the maximum round trip network latency (milliseconds) after which caching begins. Specifies the amount of time, in milliseconds, after which BranchCache client computers begin to cache content locally.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-enablewindowsbranchcache-smb"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_smb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_smb_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_smb_wbc_smblatency_decimaltextbox","displayName":"Type the maximum round trip network latency (milliseconds) after which caching begins","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent","displayName":"Set percentage of disk space used for client computer cache","description":"This policy setting specifies the default percentage of total disk space that is allocated for the BranchCache disk cache on client computers.\r\n\r\nIf you enable this policy setting, you can configure the percentage of total disk space to allocate for the cache.\r\n\r\nIf you disable or do not configure this policy setting, the cache is set to 5 percent of the total disk space on the client computer.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache client computer cache settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to configure a BranchCache client computer cache setting on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache client computer cache settings on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the client computer cache setting that you use on individual client computers.\r\n\r\n- Enabled. With this selection, the BranchCache client computer cache setting is enabled for all client computers where the policy is applied. For example, if Set percentage of disk space used for client computer cache is enabled in domain Group Policy, the BranchCache client computer cache setting that you specify in the policy is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache client computers use the default client computer cache setting of five percent of the total disk space on the client computer.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\n- Specify the percentage of total disk space allocated for the cache. Specifies an integer that is the percentage of total client computer disk space to use for the BranchCache client computer cache.\r\n\r\n* This policy setting is supported on computers that are running Windows Vista Business, Enterprise, and Ultimate editions with Background Intelligent Transfer Service (BITS) 4.0 installed.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-setcachepercent"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent_wbc_cache_size_percent_dctxtbox","displayName":"Specify the percentage of total disk space allocated for the cache","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdatacacheentrymaxage","displayName":"Set age for segments in the data cache","description":"This policy setting specifies the default age in days for which segments are valid in the BranchCache data cache on client computers.\r\n\r\nIf you enable this policy setting, you can configure the age for segments in the data cache.\r\n\r\nIf you disable or do not configure this policy setting, the age is set to 28 days.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache client computer cache age settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to configure a BranchCache client computer cache age setting on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache client computer cache age settings on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the client computer cache age setting that you use on individual client computers.\r\n\r\n- Enabled. With this selection, the BranchCache client computer cache age setting is enabled for all client computers where the policy is applied. For example, if this policy setting is enabled in domain Group Policy, the BranchCache client computer cache age that you specify in the policy is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache client computers use the default client computer cache age setting of 28 days on the client computer.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\n- Specify the age in days for which segments in the data cache are valid.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-setdatacacheentrymaxage"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdatacacheentrymaxage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdatacacheentrymaxage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdatacacheentrymaxage_wbc_cache_maxage_dctxtbox","displayName":"Specify the age in days for which segments in the data cache are valid","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading","displayName":"Configure Client BranchCache Version Support","description":"This policy setting specifies whether BranchCache-capable client computers operate in a downgraded mode in order to maintain compatibility with previous versions of BranchCache. If client computers do not use the same BranchCache version, cache efficiency might be reduced because client computers that are using different versions of BranchCache might store cache data in incompatible formats.\r\n\r\nIf you enable this policy setting, all clients use the version of BranchCache that you specify in \"Select from the following versions.\"\r\n\r\nIf you do not configure this setting, all clients will use the version of BranchCache that matches their operating system.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, this policy setting is not applied to client computers, and the clients run the version of BranchCache that is included with their operating system.\r\n\r\n- Enabled. With this selection, this policy setting is applied to client computers based on the value of the option setting \"Select from the following versions\" that you specify.\r\n\r\n- Disabled. With this selection, this policy setting is not applied to client computers, and the clients run the version of BranchCache that is included with their operating system.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\nSelect from the following versions\r\n\r\n- Windows Vista with BITS 4.0 installed, Windows 7, or Windows Server 2008 R2. If you select this version, later versions of Windows run the version of BranchCache that is included in these operating systems rather than later versions of BranchCache.\r\n\r\n- Windows 8. If you select this version, Windows 8 will run the version of BranchCache that is included in the operating system.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-setdowngrading"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_downgrading_version","displayName":"Select from the following versions:","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_downgrading_version_1","displayName":"Windows Vista with BITS 4.0 installed, Windows 7, or Windows Server 2008 R2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_downgrading_version_2","displayName":"Windows 8","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pentraining_pentrainingoff_2","displayName":"Turn off Tablet PC Pen Training","description":"Turns off Tablet PC Pen Training.\r\n\r\nIf you enable this policy setting, users cannot open Tablet PC Pen Training.\r\n\r\nIf you disable or do not configure this policy setting, users can open Tablet PC Pen Training.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pentraining#admx-pentraining-pentrainingoff-2"],"categoryId":"fe65603b-1980-446b-ae17-516eb885c6be","categoryName":"Tablet PC Pen Training","options":[{"id":"device_vendor_msft_policy_config_admx_pentraining_pentrainingoff_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pentraining_pentrainingoff_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1","displayName":"Configure Scenario Execution Level","description":"Determines the execution level for Windows Boot Performance Diagnostics.\r\n\r\nIf you enable this policy setting, you must select an execution level from the dropdown menu. If you select problem detection and troubleshooting only, the Diagnostic Policy Service (DPS) will detect Windows Boot Performance problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will detect Windows Boot Performance problems and indicate to the user that assisted resolution is available.\r\n\r\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve any Windows Boot Performance problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS will enable Windows Boot Performance for resolution by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo system restart or service restart is required for this policy to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-performancediagnostics#admx-performancediagnostics-wdiscenarioexecutionpolicy-1"],"categoryId":"18b972fd-74f2-4345-9449-087c80dd38a3","categoryName":"Windows Boot Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"18b972fd-74f2-4345-9449-087c80dd38a3","categoryName":"Windows Boot Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_wdiscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_wdiscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_2","displayName":"Configure Scenario Execution Level","description":"Determines the execution level for Windows System Responsiveness Diagnostics.\r\n\r\nIf you enable this policy setting, you must select an execution level from the dropdown menu. If you select problem detection and troubleshooting only, the Diagnostic Policy Service (DPS) will detect Windows System Responsiveness problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will detect Windows System Responsiveness problems and indicate to the user that assisted resolution is available.\r\n\r\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve any Windows System Responsiveness problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS will enable Windows System Responsiveness for resolution by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo system restart or service restart is required for this policy to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-performancediagnostics#admx-performancediagnostics-wdiscenarioexecutionpolicy-2"],"categoryId":"32b20540-8fe9-4730-a4b0-ff41f6b13a97","categoryName":"Windows System Responsiveness Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_2_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"32b20540-8fe9-4730-a4b0-ff41f6b13a97","categoryName":"Windows System Responsiveness Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_2_wdiscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_2_wdiscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3","displayName":"Configure Scenario Execution Level","description":"Determines the execution level for Windows Shutdown Performance Diagnostics.\r\n\r\nIf you enable this policy setting, you must select an execution level from the dropdown menu. If you select problem detection and troubleshooting only, the Diagnostic Policy Service (DPS) will detect Windows Shutdown Performance problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will detect Windows Shutdown Performance problems and indicate to the user that assisted resolution is available.\r\n\r\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve any Windows Shutdown Performance problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS will enable Windows Shutdown Performance for resolution by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo system restart or service restart is required for this policy to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-performancediagnostics#admx-performancediagnostics-wdiscenarioexecutionpolicy-3"],"categoryId":"cebd5934-9dfe-4278-966d-b9d880cb30e7","categoryName":"Windows Shutdown Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"cebd5934-9dfe-4278-966d-b9d880cb30e7","categoryName":"Windows Shutdown Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_wdiscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_wdiscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_4","displayName":"Configure Scenario Execution Level","description":"Determines the execution level for Windows Standby/Resume Performance Diagnostics.\n\nIf you enable this policy setting, you must select an execution level from the dropdown menu. If you select problem detection and troubleshooting only, the Diagnostic Policy Service (DPS) will detect Windows Standby/Resume Performance problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will detect Windows Standby/Resume Performance problems and indicate to the user that assisted resolution is available.\n\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve any Windows Standby/Resume Performance problems that are handled by the DPS.\n\nIf you do not configure this policy setting, the DPS will enable Windows Standby/Resume Performance for resolution by default.\n\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\n\nNo system restart or service restart is required for this policy to take effect: changes take effect immediately.\n\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-performancediagnostics#admx-performancediagnostics-wdiscenarioexecutionpolicy-4"],"categoryId":"a7e7529f-1030-41da-8b4d-024e1c08bbac","categoryName":"Windows Standby Resume Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_4_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":"","helpText":"","infoUrls":[],"categoryId":"a7e7529f-1030-41da-8b4d-024e1c08bbac","categoryName":"Windows Standby Resume Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_4_wdiscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_4_wdiscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_acconnectivityinstandby_2","displayName":"Allow network connectivity during connected-standby (plugged in)","description":"This policy setting allows you to control the network connectivity state in standby on modern standby-capable systems.\r\n\r\nIf you enable this policy setting, network connectivity will be maintained in standby.\r\n\r\nIf you disable this policy setting, network connectivity in standby is not guaranteed. This connectivity restriction currently applies to WLAN networks only, and is subject to change.\r\n\r\nIf you do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-acconnectivityinstandby-2"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_acconnectivityinstandby_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_acconnectivityinstandby_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_accriticalsleeptransitionsdisable_2","displayName":"Turn on the ability for applications to prevent sleep transitions (plugged in)","description":"This policy setting allows you to turn on the ability for applications and services to prevent the system from sleeping.\r\n\r\nIf you enable this policy setting, an application or service may prevent the system from sleeping (Hybrid Sleep, Stand By, or Hibernate).\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-accriticalsleeptransitionsdisable-2"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_accriticalsleeptransitionsdisable_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_accriticalsleeptransitionsdisable_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2","displayName":"Select the Start menu Power button action (plugged in)","description":"This policy setting specifies the action that Windows takes when a user presses the Start menu Power button.\r\n\r\nIf you enable this policy setting, select one of the following actions:\r\n-Sleep\r\n-Hibernate\r\n-Shut down\r\n\r\nIf you disable this policy or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-acstartmenubuttonaction-2"],"categoryId":"5d03766c-9480-43f2-9e85-461a44c821d4","categoryName":"Button Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2_selectacstartmenubuttonaction","displayName":"User Interface Sleep Button Action","description":null,"helpText":"","infoUrls":[],"categoryId":"5d03766c-9480-43f2-9e85-461a44c821d4","categoryName":"Button Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2_selectacstartmenubuttonaction_0","displayName":"Sleep","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2_selectacstartmenubuttonaction_1","displayName":"Hibernate","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2_selectacstartmenubuttonaction_2","displayName":"Shut down","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestac","displayName":"Allow applications to prevent automatic sleep (plugged in)","description":"This policy setting allows applications and services to prevent automatic sleep.\r\n\r\nIf you enable this policy setting, any application, service, or device driver prevents Windows from automatically transitioning to sleep after a period of user inactivity.\r\n\r\nIf you disable or do not configure this policy setting, applications, services, or drivers do not prevent Windows from automatically transitioning to sleep. Only user input is used to determine if Windows should automatically sleep.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystempowerrequestac"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestac_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestac_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestdc","displayName":"Allow applications to prevent automatic sleep (on battery)","description":"This policy setting allows applications and services to prevent automatic sleep.\r\n\r\nIf you enable this policy setting, any application, service, or device driver prevents Windows from automatically transitioning to sleep after a period of user inactivity.\r\n\r\nIf you disable or do not configure this policy setting, applications, services, or drivers do not prevent Windows from automatically transitioning to sleep. Only user input is used to determine if Windows should automatically sleep.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystempowerrequestdc"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestdc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestdc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopenac","displayName":"Allow automatic sleep with Open Network Files (plugged in)","description":"This policy setting allows you to manage automatic sleep with open network files.\r\n\r\nIf you enable this policy setting, the computer automatically sleeps when network files are open.\r\n\r\nIf you disable or do not configure this policy setting, the computer does not automatically sleep when network files are open.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystemsleepwithremotefilesopenac"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopenac_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopenac_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopendc","displayName":"Allow automatic sleep with Open Network Files (on battery)","description":"This policy setting allows you to manage automatic sleep with open network files.\r\n\r\nIf you enable this policy setting, the computer automatically sleeps when network files are open.\r\n\r\nIf you disable or do not configure this policy setting, the computer does not automatically sleep when network files are open.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystemsleepwithremotefilesopendc"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopendc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopendc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2","displayName":"Specify a custom active power plan","description":"This policy setting specifies the active power plan from a specified power plan’s GUID. The GUID for a custom power plan GUID can be retrieved by using powercfg, the power configuration command line tool. \r\n\r\nIf you enable this policy setting, you must specify a power plan, specified as a GUID using the following format: XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX (For example, 103eea6e-9fcd-4544-a713-c282d8e50083), indicating the power plan to be active.\r\n\r\nIf you disable or do not configure this policy setting, users can see and change this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-customactiveschemeoverride-2"],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":[{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2_customactiveschemeoverrideenter","displayName":"Custom Active Power Plan (GUID):","description":null,"helpText":"","infoUrls":[],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2","displayName":"Critical battery notification action","description":"This policy setting specifies the action that Windows takes when battery capacity reaches the critical battery notification level.\r\n\r\nIf you enable this policy setting, select one of the following actions:\r\n-Take no action\r\n-Sleep\r\n-Hibernate\r\n-Shut down\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargeaction0-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0","displayName":"Critical Battery Notification Action","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_0","displayName":"Take no action","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_1","displayName":"Sleep","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_2","displayName":"Hibernate","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_3","displayName":"Shut down","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2","displayName":"Low battery notification action","description":"This policy setting specifies the action that Windows takes when battery capacity reaches the low battery notification level.\r\n\r\nIf you enable this policy setting, select one of the following actions:\r\n-Take no action\r\n-Sleep\r\n-Hibernate\r\n-Shut down\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargeaction1-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_selectdcbatterydischargeaction1","displayName":"Low Battery Notification Action","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_selectdcbatterydischargeaction1_0","displayName":"Take no action","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_selectdcbatterydischargeaction1_1","displayName":"Sleep","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_selectdcbatterydischargeaction1_2","displayName":"Hibernate","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_selectdcbatterydischargeaction1_3","displayName":"Shut down","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel0_2","displayName":"Critical battery notification level","description":"This policy setting specifies the percentage of battery capacity remaining that triggers the critical battery notification action.\r\n\r\nIf you enable this policy setting, you must enter a numeric value (percentage) to set the battery level that triggers the critical notification.\r\n\r\nTo set the action that is triggered, see the \"Critical Battery Notification Action\" policy setting.\r\n\r\nIf you disable this policy setting or do not configure it, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargelevel0-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel0_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel0_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel0_2_enterdcbatterydischargelevel0","displayName":"Critical Battery Notification Level","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2","displayName":"Low battery notification level","description":"This policy setting specifies the percentage of battery capacity remaining that triggers the low battery notification action.\r\n\r\nIf you enable this policy setting, you must enter a numeric value (percentage) to set the battery level that triggers the low notification.\r\n\r\nTo set the action that is triggered, see the \"Low Battery Notification Action\" policy setting.\r\n\r\nIf you disable this policy setting or do not configure it, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargelevel1-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2_enterdcbatterydischargelevel1","displayName":"Low Battery Notification Level","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1uinotification_2","displayName":"Turn off low battery user notification","description":"This policy setting turns off the user notification when the battery capacity remaining equals the low battery notification level.\r\n\r\nIf you enable this policy setting, Windows shows a notification when the battery capacity remaining equals the low battery notification level. To configure the low battery notification level, see the \"Low Battery Notification Level\" policy setting.\r\n\r\nThe notification will only be shown if the \"Low Battery Notification Action\" policy setting is configured to \"No Action\".\r\n\r\nIf you disable or do not configure this policy setting, users can control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargelevel1uinotification-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1uinotification_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1uinotification_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcconnectivityinstandby_2","displayName":"Allow network connectivity during connected-standby (on battery)","description":"This policy setting allows you to control the network connectivity state in standby on modern standby-capable systems.\r\n\r\nIf you enable this policy setting, network connectivity will be maintained in standby.\r\n\r\nIf you disable this policy setting, network connectivity in standby is not guaranteed. This connectivity restriction currently applies to WLAN networks only, and is subject to change.\r\n\r\nIf you do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcconnectivityinstandby-2"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcconnectivityinstandby_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcconnectivityinstandby_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dccriticalsleeptransitionsdisable_2","displayName":"Turn on the ability for applications to prevent sleep transitions (on battery)","description":"This policy setting allows you to turn on the ability for applications and services to prevent the system from sleeping.\r\n\r\nIf you enable this policy setting, an application or service may prevent the system from sleeping (Hybrid Sleep, Stand By, or Hibernate).\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dccriticalsleeptransitionsdisable-2"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dccriticalsleeptransitionsdisable_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dccriticalsleeptransitionsdisable_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2","displayName":"Select the Start menu Power button action (on battery)","description":"This policy setting specifies the action that Windows takes when a user presses the Start menu Power button.\r\n\r\nIf you enable this policy setting, select one of the following actions:\r\n-Sleep\r\n-Hibernate\r\n-Shut down\r\n\r\nIf you disable this policy or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcstartmenubuttonaction-2"],"categoryId":"5d03766c-9480-43f2-9e85-461a44c821d4","categoryName":"Button Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2_selectdcstartmenubuttonaction","displayName":"User Interface Sleep Button Action","description":null,"helpText":"","infoUrls":[],"categoryId":"5d03766c-9480-43f2-9e85-461a44c821d4","categoryName":"Button Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2_selectdcstartmenubuttonaction_0","displayName":"Sleep","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2_selectdcstartmenubuttonaction_1","displayName":"Hibernate","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2_selectdcstartmenubuttonaction_2","displayName":"Shut down","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2","displayName":"Turn Off the hard disk (plugged in)","description":"This policy setting specifies the period of inactivity before Windows turns off the hard disk.\r\n\r\nIf you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows turns off the hard disk.\r\n\r\nIf you disable or do not configure this policy setting, users can see and change this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-diskacpowerdowntimeout-2"],"categoryId":"91c02e14-8848-485d-8844-b9933fa888ec","categoryName":"Hard Disk Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2_enterdiskacpowerdowntimeout","displayName":"Turn Off the Hard Disk (seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"91c02e14-8848-485d-8844-b9933fa888ec","categoryName":"Hard Disk Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_power_diskdcpowerdowntimeout_2","displayName":"Turn Off the hard disk (on battery)","description":"This policy setting specifies the period of inactivity before Windows turns off the hard disk.\r\n\r\nIf you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows turns off the hard disk.\r\n\r\nIf you disable or do not configure this policy setting, users can see and change this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-diskdcpowerdowntimeout-2"],"categoryId":"91c02e14-8848-485d-8844-b9933fa888ec","categoryName":"Hard Disk Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_diskdcpowerdowntimeout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_diskdcpowerdowntimeout_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_diskdcpowerdowntimeout_2_enterdiskdcpowerdowntimeout","displayName":"Turn Off the Hard Disk (seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"91c02e14-8848-485d-8844-b9933fa888ec","categoryName":"Hard Disk Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_power_dont_poweroff_aftershutdown","displayName":"Do not turn off system power after a Windows system shutdown has occurred.","description":"This policy setting allows you to configure whether power is automatically turned off when Windows shutdown completes. This setting does not affect Windows shutdown behavior when shutdown is manually selected using the Start menu or Task Manager user interfaces. Applications such as UPS software may rely on Windows shutdown behavior.\r\n\r\nThis setting is only applicable when Windows shutdown is initiated by software programs invoking the Windows programming interfaces ExitWindowsEx() or InitiateSystemShutdown().\r\n\r\nIf you enable this policy setting, the computer system safely shuts down and remains in a powered state, ready for power to be safely removed.\r\n\r\nIf you disable or do not configure this policy setting, the computer system safely shuts down to a fully powered-off state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dont-poweroff-aftershutdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_power_dont_poweroff_aftershutdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dont_poweroff_aftershutdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_enabledesktopslideshowac","displayName":"Turn on desktop background slideshow (plugged in)","description":"This policy setting allows you to specify if Windows should enable the desktop background slideshow.\n\nIf you enable this policy setting, desktop background slideshow is enabled.\n\nIf you disable this policy setting, the desktop background slideshow is disabled.\n\nIf you disable or do not configure this policy setting, users control this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-enabledesktopslideshowac"],"categoryId":"01da0c26-af30-4eb2-a899-7d5e7ecb9738","categoryName":"Video and Display Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_enabledesktopslideshowac_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_enabledesktopslideshowac_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_enabledesktopslideshowdc","displayName":"Turn on desktop background slideshow (on battery)","description":"This policy setting allows you to specify if Windows should enable the desktop background slideshow.\n\nIf you enable this policy setting, desktop background slideshow is enabled.\n\nIf you disable this policy setting, the desktop background slideshow is disabled.\n\nIf you disable or do not configure this policy setting, users control this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-enabledesktopslideshowdc"],"categoryId":"01da0c26-af30-4eb2-a899-7d5e7ecb9738","categoryName":"Video and Display Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_enabledesktopslideshowdc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_enabledesktopslideshowdc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2","displayName":"Select an active power plan","description":"This policy setting specifies the active power plan from a list of default Windows power plans. To specify a custom power plan, use the Custom Active Power Plan setting.\r\n\r\nIf you enable this policy setting, specify a power plan from the Active Power Plan list.\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-inboxactiveschemeoverride-2"],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":[{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter","displayName":"Active Power Plan:","description":null,"helpText":"","infoUrls":[],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":[{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter_381b4222-f694-41f0-9685-ff5bb260df2e","displayName":"Automatic (recommended)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter_a1841308-3541-4fab-bc81-f71556f20b4a","displayName":"Power Saver","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter_8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c","displayName":"High Performance","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_powerthrottlingturnoff","displayName":"Turn off Power Throttling","description":"This policy setting allows you to turn off Power Throttling.\r\n\r\nIf you enable this policy setting, Power Throttling will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-powerthrottlingturnoff"],"categoryId":"86b4fa22-f6f1-4ca5-8fe4-8788f9b3fd89","categoryName":"Power Throttling Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_powerthrottlingturnoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_powerthrottlingturnoff_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_reservebatterynotificationlevel","displayName":"Reserve battery notification level","description":"This policy setting specifies the percentage of battery capacity remaining that triggers the reserve power mode.\r\n\r\nIf you enable this policy setting, you must enter a numeric value (percentage) to set the battery level that triggers the reserve power notification.\r\n\r\nIf you disable or do not configure this policy setting, users can see and change this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-reservebatterynotificationlevel"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_reservebatterynotificationlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_reservebatterynotificationlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_reservebatterynotificationlevel_enterreservebatterynotificationlevel","displayName":"Reserve Battery Notification Level (percent):","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging","displayName":"Turn on Module Logging","description":"\r\n This policy setting allows you to turn on logging for Windows PowerShell modules.\r\n\r\n If you enable this policy setting, pipeline execution events for members of the specified modules are recorded in the Windows PowerShell log in Event Viewer. Enabling this policy setting for a module is equivalent to setting the LogPipelineExecutionDetails property of the module to True.\r\n\r\n If you disable this policy setting, logging of execution events is disabled for all Windows PowerShell modules. Disabling this policy setting for a module is equivalent to setting the LogPipelineExecutionDetails property of the module to False.\r\n\r\n If this policy setting is not configured, the LogPipelineExecutionDetails property of a module or snap-in determines whether the execution events of a module or snap-in are logged. By default, the LogPipelineExecutionDetails property of all modules and snap-ins is set to False.\r\n\r\n To add modules and snap-ins to the policy setting list, click Show, and then type the module names in the list. The modules and snap-ins in the list must be installed on the computer.\r\n\r\n Note: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enablemodulelogging"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging_listbox_modulenames","displayName":"Module Names","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts","displayName":"Turn on Script Execution","description":"This policy setting lets you configure the script execution policy, controlling which scripts are allowed to run.\r\n\r\nIf you enable this policy setting, the scripts selected in the drop-down list are allowed to run.\r\n\r\nThe \"Allow only signed scripts\" policy setting allows scripts to execute only if they are signed by a trusted publisher.\r\n\r\nThe \"Allow local scripts and remote signed scripts\" policy setting allows any local scrips to run; scripts that originate from the Internet must be signed by a trusted publisher.\r\n\r\nThe \"Allow all scripts\" policy setting allows all scripts to run.\r\n\r\nIf you disable this policy setting, no scripts are allowed to run.\r\n\r\nNote: This policy setting exists under both \"Computer Configuration\" and \"User Configuration\" in the Local Group Policy Editor. The \"Computer Configuration\" has precedence over \"User Configuration.\"\r\n\r\nIf you disable or do not configure this policy setting, it reverts to a per-machine preference setting; the default if that is not configured is \"No scripts allowed.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enablescripts"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_executionpolicy","displayName":"Execution Policy","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_executionpolicy_allsigned","displayName":"Allow only signed scripts","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_executionpolicy_remotesigned","displayName":"Allow local scripts and remote signed scripts","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_executionpolicy_unrestricted","displayName":"Allow all scripts","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting","displayName":"Turn on PowerShell Transcription","description":"\r\n This policy setting lets you capture the input and output of Windows PowerShell commands into text-based transcripts.\r\n\r\n If you enable this policy setting, Windows PowerShell will enable transcripting for Windows PowerShell, the Windows PowerShell ISE, and any other\r\n applications that leverage the Windows PowerShell engine. By default, Windows PowerShell will record transcript output to each users' My Documents\r\n directory, with a file name that includes 'PowerShell_transcript', along with the computer name and time started. Enabling this policy is equivalent\r\n to calling the Start-Transcript cmdlet on each Windows PowerShell session.\r\n\r\n If you disable this policy setting, transcripting of PowerShell-based applications is disabled by default, although transcripting can still be enabled\r\n through the Start-Transcript cmdlet.\r\n \r\n If you use the OutputDirectory setting to enable transcript logging to a shared location, be sure to limit access to that directory to prevent users\r\n from viewing the transcripts of other users or computers.\r\n\r\n Note: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enabletranscripting"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_enableinvocationheader","displayName":"Include invocation headers:","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_enableinvocationheader_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_enableinvocationheader_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_outputdirectory","displayName":"Transcript output directory","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath","displayName":"Set the default source path for Update-Help","description":"This policy setting allows you to set the default value of the SourcePath parameter on the Update-Help cmdlet.\r\n\r\nIf you enable this policy setting, the Update-Help cmdlet will use the specified value as the default value for the SourcePath parameter. This default value can be overridden by specifying a different value with the SourcePath parameter on the Update-Help cmdlet.\r\n\r\nIf this policy setting is disabled or not configured, this policy setting does not set a default value for the SourcePath parameter of the Update-Help cmdlet.\r\n\r\nNote: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enableupdatehelpdefaultsourcepath"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath_sourcepathforupdatehelp","displayName":"Default Source Path","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablebackuprestore_2","displayName":"Prevent restoring previous versions from backups","description":"This policy setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a local file, in which the previous version is stored on a backup.\r\n\r\nIf you enable this policy setting, the Restore button is disabled when the user selects a previous version corresponding to a backup.\r\n\r\nIf you disable this policy setting, the Restore button remains active for a previous version corresponding to a backup. If the Restore button is clicked, Windows attempts to restore the file from the backup media.\r\n\r\nIf you do not configure this policy setting, it is disabled by default. The Restore button is active when the previous version is of a local file and stored on the backup.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disablebackuprestore-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_disablebackuprestore_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablebackuprestore_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalpage_2","displayName":"Hide previous versions list for local files","description":"This policy setting lets you hide the list of previous versions of files that are on local disks. The previous versions could come from the on-disk restore points or from backup media.\r\n\r\nIf you enable this policy setting, users cannot list or restore previous versions of files on local disks.\r\n\r\nIf you disable this policy setting, users cannot list and restore previous versions of files on local disks.\r\n\r\nIf you do not configure this policy setting, it defaults to disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disablelocalpage-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalpage_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalpage_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_2","displayName":"Prevent restoring local previous versions","description":"This policy setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a local file.\r\n\r\nIf you enable this policy setting, the Restore button is disabled when the user selects a previous version corresponding to a local file.\r\n\r\nIf you disable this policy setting, the Restore button remains active for a previous version corresponding to a local file. If the user clicks the Restore button, Windows attempts to restore the file from the local disk.\r\n\r\nIf you do not configure this policy setting, it is disabled by default. The Restore button is active when the previous version is of a local file.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disablelocalrestore-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_previousversions_disableremotepage_2","displayName":"Hide previous versions list for remote files","description":"This policy setting lets you hide the list of previous versions of files that are on file shares. The previous versions come from the on-disk restore points on the file share.\r\n\r\nIf you enable this policy setting, users cannot list or restore previous versions of files on file shares.\r\n\r\nIf you disable this policy setting, users can list and restore previous versions of files on file shares.\r\n\r\nIf you do not configure this policy setting, it is disabled by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disableremotepage-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_disableremotepage_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disableremotepage_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_previousversions_disableremoterestore_2","displayName":"Prevent restoring remote previous versions","description":"This setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a file on a file share.\r\n\r\nIf you enable this policy setting, the Restore button is disabled when the user selects a previous version corresponding to a file on a file share.\r\n\r\nIf you disable this policy setting, the Restore button remains active for a previous version corresponding to a file on a file share. If the user clicks the Restore button, Windows attempts to restore the file from the file share.\r\n\r\nIf you do not configure this policy setting, it is disabled by default. The Restore button is active when the previous version is of a file on a file share.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disableremoterestore-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_disableremoterestore_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disableremoterestore_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_previousversions_hidebackupentries_2","displayName":"Hide previous versions of files on backup location","description":"This policy setting lets you hide entries in the list of previous versions of a file in which the previous version is located on backup media. Previous versions can come from the on-disk restore points or the backup media.\r\n\r\nIf you enable this policy setting, users cannot see any previous versions corresponding to backup copies, and can see only previous versions corresponding to on-disk restore points.\r\n\r\nIf you disable this policy setting, users can see previous versions corresponding to backup copies as well as previous versions corresponding to on-disk restore points.\r\n\r\nIf you do not configure this policy setting, it is disabled by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-hidebackupentries-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_hidebackupentries_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_hidebackupentries_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_allowwebprinting","displayName":"Activate Internet printing","description":"Internet printing lets you display printers on Web pages so that printers can be viewed, managed, and used across the Internet or an intranet.\r\n\r\n If you enable this policy setting, Internet printing is activated on this server.\r\n\r\n If you disable this policy setting or do not configure it, Internet printing is not activated.\r\n\r\n Internet printing is an extension of Internet Information Services (IIS). To use Internet printing, IIS must be installed, and printing support and this setting must be enabled.\r\n\r\n Note: This setting affects the server side of Internet printing only. It does not prevent the print client on the computer from printing across the Internet.\r\n\r\n Also, see the \"Custom support URL in the Printers folder's left pane\" setting in this folder and the \"Browse a common Web site to find printers\" setting in User Configuration\\Administrative Templates\\Control Panel\\Printers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-allowwebprinting"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_allowwebprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_allowwebprinting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_applicationdriverisolation","displayName":"Isolate print drivers from applications","description":"Determines if print driver components are isolated from applications instead of normally loading them into applications. Isolating print drivers greatly reduces the risk of a print driver failure causing an application crash.\r\n\r\nNot all applications support driver isolation. By default, Microsoft Excel 2007, Excel 2010, Word 2007, Word 2010 and certain other applications are configured to support it. Other applications may also be capable of isolating print drivers, depending on whether they are configured for it.\r\n\r\nIf you enable or do not configure this policy setting, then applications that are configured to support driver isolation will be isolated.\r\n\r\nIf you disable this policy setting, then print drivers will be loaded within all associated application processes.\r\n\r\nNotes:\r\n-This policy setting applies only to applications opted into isolation.\r\n-This policy setting applies only to print drivers loaded by applications. Print drivers loaded by the print spooler are not affected.\r\n-This policy setting is only checked once during the lifetime of a process. After changing the policy, a running application must be relaunched before settings take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-applicationdriverisolation"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_applicationdriverisolation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_applicationdriverisolation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_customizedsupporturl","displayName":"Custom support URL in the Printers folder's left pane","description":"By default, the Printers folder includes a link to the Microsoft Support Web page called \"Get help with printing\". It can also include a link to a Web page supplied by the vendor of the currently selected printer.\r\n\r\n If you enable this policy setting, you replace the \"Get help with printing\" default link with a link to a Web page customized for your enterprise.\r\n\r\n If you disable this setting or do not configure it, or if you do not enter an alternate Internet address, the default link will appear in the Printers folder.\r\n\r\n Note: Web pages links only appear in the Printers folder when Web view is enabled. If Web view is disabled, the setting has no effect. (To enable Web view, open the Printers folder, and, on the Tools menu, click Folder Options, click the General tab, and then click \"Enable Web content in folders.\")\r\n\r\n Also, see the \"Activate Internet printing\" setting in this setting folder and the \"Browse a common web site to find printers\" setting in User Configuration\\Administrative Templates\\Control Panel\\Printers.\r\n\r\n Web view is affected by the \"Turn on Classic Shell\" and \"Do not allow Folder Options to be opened from the Options button on the View tab of the ribbon\" settings in User Configuration\\Administrative Templates\\Windows Components\\Windows Explorer, and by the \"Enable Active Desktop\" setting in User Configuration\\Administrative Templates\\Desktop\\Active Desktop.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-customizedsupporturl"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_customizedsupporturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_customizedsupporturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_customizedsupporturl_customizedsupporturl_link","displayName":"URL","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters","displayName":"Add Printer wizard - Network scan page (Managed network)","description":"If you enable this policy setting, it sets the maximum number of printers (of each type) that the Add Printer wizard will display on a computer on a managed network (when the computer is able to reach a domain controller, e.g. a domain-joined laptop on a corporate network.)\r\n\r\n If this policy setting is disabled, the network scan page will not be displayed.\r\n\r\n If this policy setting is not configured, the Add Printer wizard will display the default number of printers of each type:\r\n Directory printers: 20\r\n TCP/IP printers: 0\r\n Web Services printers: 0\r\n Bluetooth printers: 10\r\n Shared printers: 0\r\n\r\n In order to view available Web Services printers on your network, ensure that network discovery is turned on. To turn on network discovery, click \"Start\", click \"Control Panel\", and then click \"Network and Internet\". On the \"Network and Internet\" page, click \"Network and Sharing Center\". On the Network and Sharing Center page, click \"Change advanced sharing settings\". On the Advanced sharing settings page, click the arrow next to \"Domain\" arrow, click \"turn on network discovery\", and then click \"Save changes\".\r\n\r\n If you would like to not display printers of a certain type, enable this policy and set the number of printers to display to 0.\r\n\r\n In Windows 10 and later, only TCP/IP printers can be shown in the wizard. If you enable this policy setting, only TCP/IP printer limits are applicable. On Windows 10 only, if you disable or do not configure this policy setting, the default limit is applied.\r\n \r\n In Windows 8 and later, Bluetooth printers are not shown so its limit does not apply to those versions of Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-domainprinters"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_adprinters","displayName":"Number of directory printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_bluetoothprinters","displayName":"Number of Bluetooth printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_ipprinters","displayName":"Number of TCP/IP printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_shareprinters","displayName":"Number of shared printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_wsdprinters","displayName":"Number of Web Services Printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_donotinstallcompatibledriverfromwindowsupdate","displayName":"Extend Point and Print connection to search Windows Update","description":"This policy setting allows you to manage where client computers search for Point and Printer drivers.\r\n\r\nIf you enable this policy setting, the client computer will continue to search for compatible Point and Print drivers from Windows Update after it fails to find the compatible driver from the local driver store and the server driver cache.\r\n\r\nIf you disable this policy setting, the client computer will only search the local driver store and server driver cache for compatible Point and Print drivers. If it is unable to find a compatible driver, then the Point and Print connection will fail.\r\n\r\nThis policy setting is not configured by default, and the behavior depends on the version of Windows that you are using.\r\nBy default, Windows Ultimate, Professional and Home SKUs will continue to search for compatible Point and Print drivers from Windows Update, if needed. However, you must explicitly enable this policy setting for other versions of Windows (for example Windows Enterprise, and all versions of Windows Server 2008 R2 and later) to have the same behavior.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-donotinstallcompatibledriverfromwindowsupdate"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_donotinstallcompatibledriverfromwindowsupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_donotinstallcompatibledriverfromwindowsupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_emfdespooling","displayName":"Always render print jobs on the server","description":"When printing through a print server, determines whether the print spooler on the client will process print jobs itself, or pass them on to the server to do the work.\r\n\r\nThis policy setting only effects printing to a Windows print server.\r\n\r\nIf you enable this policy setting on a client machine, the client spooler will not process print jobs before sending them to the print server. This decreases the workload on the client at the expense of increasing the load on the server.\r\n\r\nIf you disable this policy setting on a client machine, the client itself will process print jobs into printer device commands. These commands will then be sent to the print server, and the server will simply pass the commands to the printer. This increases the workload of the client while decreasing the load on the server.\r\n\r\nIf you do not enable this policy setting, the behavior is the same as disabling it.\r\n\r\nNote: This policy does not determine whether offline printing will be available to the client. The client print spooler can always queue print jobs when not connected to the print server. Upon reconnecting to the server, the client will submit any pending print jobs.\r\n\r\nNote: Some printer drivers require a custom print processor. In some cases the custom print processor may not be installed on the client machine, such as when the print server does not support transferring print processors during point-and-print. In the case of a print processor mismatch, the client spooler will always send jobs to the print server for rendering. Disabling the above policy setting does not override this behavior.\r\n\r\nNote: In cases where the client print driver does not match the server print driver (mismatched connection), the client will always process the print job, regardless of the setting of this policy.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-emfdespooling"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_emfdespooling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_emfdespooling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_forcesoftwarerasterization","displayName":"Always rasterize content to be printed using a software rasterizer","description":"Determines whether the XPS Rasterization Service or the XPS-to-GDI conversion (XGC) is forced to use a software rasterizer instead of a Graphics Processing Unit (GPU) to rasterize pages.\r\n\r\nThis setting may improve the performance of the XPS Rasterization Service or the XPS-to-GDI conversion (XGC) on machines that have a relatively powerful CPU as compared to the machine’s GPU.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-forcesoftwarerasterization"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_forcesoftwarerasterization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_forcesoftwarerasterization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_kmprintersareblocked","displayName":"Disallow installation of printers using kernel-mode drivers","description":"Determines whether printers using kernel-mode drivers may be installed on the local computer. Kernel-mode drivers have access to system-wide memory, and therefore poorly-written kernel-mode drivers can cause stop errors.\r\n\r\nIf you disable this setting, or do not configure it, then printers using a kernel-mode drivers may be installed on the local computer running Windows XP Home Edition and Windows XP Professional.\r\n\r\nIf you do not configure this setting on Windows Server 2003 family products, the installation of kernel-mode printer drivers will be blocked.\r\n\r\nIf you enable this setting, installation of a printer using a kernel-mode driver will not be allowed.\r\n\r\nNote: By applying this policy, existing kernel-mode drivers will be disabled upon installation of service packs or reinstallation of the Windows XP operating system. This policy does not apply to 64-bit kernel-mode printer drivers as they cannot be installed and associated with a print queue.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-kmprintersareblocked"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_kmprintersareblocked_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_kmprintersareblocked_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_mxdwuselegacyoutputformatmsxps","displayName":"Change Microsoft XPS Document Writer (MXDW) default output format to the legacy Microsoft XPS format (*.xps)","description":"Microsoft XPS Document Writer (MXDW) generates OpenXPS (*.oxps) files by default in %WINDOWS_CLIENT_CURRENT_VERSION%, %WINDOWS_ARM_CURRENT_VERSION% and %WINDOWS_SERVER_CURRENT_VERSION%.\r\n\r\n If you enable this group policy setting, the default MXDW output format is the legacy Microsoft XPS (*.xps).\r\n\r\n If you disable or do not configure this policy setting, the default MXDW output format is OpenXPS (*.oxps).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-mxdwuselegacyoutputformatmsxps"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_mxdwuselegacyoutputformatmsxps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_mxdwuselegacyoutputformatmsxps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters","displayName":"Add Printer wizard - Network scan page (Unmanaged network)","description":"This policy sets the maximum number of printers (of each type) that the Add Printer wizard will display on a computer on an unmanaged network (when the computer is not able to reach a domain controller, e.g. a domain-joined laptop on a home network.)\r\n\r\nIf this setting is disabled, the network scan page will not be displayed.\r\n\r\nIf this setting is not configured, the Add Printer wizard will display the default number of printers of each type:\r\nTCP/IP printers: 50\r\nWeb Services printers: 50\r\nBluetooth printers: 10\r\nShared printers: 50\r\n\r\nIf you would like to not display printers of a certain type, enable this policy and set the number of printers to display to 0.\r\n\r\nIn Windows 10 and later, only TCP/IP printers can be shown in the wizard. If you enable this policy setting, only TCP/IP printer limits are applicable. On Windows 10 only, if you disable or do not configure this policy setting, the default limit is applied.\r\n \r\nIn Windows 8 and later, Bluetooth printers are not shown so its limit does not apply to those versions of Windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-nondomainprinters"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_bluetoothprinters","displayName":"Number of Bluetooth printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_ipprinters","displayName":"Number of TCP/IP printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_shareprinters","displayName":"Number of shared printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_wsdprinters","displayName":"Number of Web Services Printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintonly_win7","displayName":"Only use Package Point and print","description":"This policy restricts clients computers to use package point and print only.\r\n\r\nIf this setting is enabled, users will only be able to point and print to printers that use package-aware drivers. When using package point and print, client computers will check the driver signature of all drivers that are downloaded from print servers.\r\n\r\nIf this setting is disabled, or not configured, users will not be restricted to package-aware point and print only.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-packagepointandprintonly-win7"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintonly_win7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintonly_win7_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintserverlist_win7","displayName":"Package Point and print - Approved servers","description":"Restricts package point and print to approved servers.\r\n\r\nThis policy setting restricts package point and print connections to approved servers. This setting only applies to Package Point and Print connections, and is completely independent from the \"Point and Print Restrictions\" policy that governs the behavior of non-package point and print connections.\r\n\r\nWindows Vista and later clients will attempt to make a non-package point and print connection anytime a package point and print connection fails, including attempts that are blocked by this policy. Administrators may need to set both policies to block all print connections to a specific print server.\r\n\r\nIf this setting is enabled, users will only be able to package point and print to print servers approved by the network administrator. When using package point and print, client computers will check the driver signature of all drivers that are downloaded from print servers.\r\n\r\nIf this setting is disabled, or not configured, package point and print will not be restricted to specific print servers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-packagepointandprintserverlist-win7"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintserverlist_win7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintserverlist_win7_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintserverlist_win7_packagepointandprintserverlist_edit","displayName":"Enter fully qualified server names","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_physicallocation","displayName":"Computer location","description":"If this policy setting is enabled, it specifies the default location criteria used when searching for printers.\r\n\r\n This setting is a component of the Location Tracking feature of Windows printers. To use this setting, enable Location Tracking by enabling the \"Pre-populate printer search location text\" setting.\r\n\r\n When Location Tracking is enabled, the system uses the specified location as a criterion when users search for printers. The value you type here overrides the actual location of the computer conducting the search.\r\n\r\n Type the location of the user's computer. When users search for printers, the system uses the specified location (and other search criteria) to find a printer nearby. You can also use this setting to direct users to a particular printer or group of printers that you want them to use.\r\n\r\n If you disable this setting or do not configure it, and the user does not type a location as a search criterion, the system searches for a nearby printer based on the IP address and subnet mask of the user's computer.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-physicallocation"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_physicallocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_physicallocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_physicallocation_physicallocation_name","displayName":"Location","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_physicallocationsupport","displayName":"Pre-populate printer search location text","description":"Enables the physical Location Tracking setting for Windows printers.\r\n\r\nUse Location Tracking to design a location scheme for your enterprise and assign computers and printers to locations in the scheme. Location Tracking overrides the standard method used to locate and associate computers and printers. The standard method uses a printer's IP address and subnet mask to estimate its physical location and proximity to computers.\r\n\r\nIf you enable this setting, users can browse for printers by location without knowing the printer's location or location naming scheme. Enabling Location Tracking adds a Browse button in the Add Printer wizard's Printer Name and Sharing Location screen and to the General tab in the Printer Properties dialog box. If you enable the Group Policy Computer location setting, the default location you entered appears in the Location field by default.\r\n\r\nIf you disable this setting or do not configure it, Location Tracking is disabled. Printer proximity is estimated using the standard method (that is, based on IP address and subnet mask).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-physicallocationsupport"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_physicallocationsupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_physicallocationsupport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationexecutionpolicy","displayName":"Execute print drivers in isolated processes","description":"This policy setting determines whether the print spooler will execute print drivers in an isolated or separate process. When print drivers are loaded in an isolated process (or isolated processes), a print driver failure will not cause the print spooler service to fail.\r\n\r\nIf you enable or do not configure this policy setting, the print spooler will execute print drivers in an isolated process by default.\r\n\r\nIf you disable this policy setting, the print spooler will execute print drivers in the print spooler process.\r\n\r\n\r\nNotes:\r\n-Other system or driver policy settings may alter the process in which a print driver is executed.\r\n-This policy setting applies only to print drivers loaded by the print spooler. Print drivers loaded by applications are not affected.\r\n-This policy setting takes effect without restarting the print spooler service.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-printdriverisolationexecutionpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationoverridecompat","displayName":"Override print driver execution compatibility setting reported by print driver","description":"This policy setting determines whether the print spooler will override the Driver Isolation compatibility reported by the print driver. This enables executing print drivers in an isolated process, even if the driver does not report compatibility.\r\n\r\nIf you enable this policy setting, the print spooler isolates all print drivers that do not explicitly opt out of Driver Isolation.\r\n\r\nIf you disable or do not configure this policy setting, the print spooler uses the Driver Isolation compatibility flag value reported by the print driver.\r\n\r\nNotes:\r\n-Other system or driver policy settings may alter the process in which a print driver is executed.\r\n-This policy setting applies only to print drivers loaded by the print spooler. Print drivers loaded by applications are not affected.\r\n-This policy setting takes effect without restarting the print spooler service.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-printdriverisolationoverridecompat"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationoverridecompat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationoverridecompat_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_printerserverthread","displayName":"Printer browsing","description":"Announces the presence of shared printers to print browse master servers for the domain.\r\n\r\nOn domains with Active Directory, shared printer resources are available in Active Directory and are not announced.\r\n\r\nIf you enable this setting, the print spooler announces shared printers to the print browse master servers.\r\n\r\nIf you disable this setting, shared printers are not announced to print browse master servers, even if Active Directory is not available.\r\n\r\nIf you do not configure this setting, shared printers are announced to browse master servers only when Active Directory is not available.\r\n\r\nNote: A client license is used each time a client computer announces a printer to a print browse master on the domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-printerserverthread"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_printerserverthread_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_printerserverthread_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_showjobtitleineventlogs","displayName":"Allow job name in event logs","description":"\r\n This policy controls whether the print job name will be included in print event logs.\r\n\r\n If you disable or do not configure this policy setting, the print job name will not be included.\r\n\r\n If you enable this policy setting, the print job name will be included in new log entries.\r\n\r\n Note: This setting does not apply to Branch Office Direct Printing jobs.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-showjobtitleineventlogs"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_showjobtitleineventlogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_showjobtitleineventlogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_v4driverdisallowprinterextension","displayName":"Do not allow v4 printer drivers to show printer extensions","description":"This policy determines if v4 printer drivers are allowed to run printer extensions.\r\n\r\n V4 printer drivers may include an optional, customized user interface known as a printer extension. These extensions may provide access to more device features, but this may not be appropriate for all enterprises.\r\n\r\n If you enable this policy setting, then all printer extensions will not be allowed to run.\r\n\r\n If you disable this policy setting or do not configure it, then all printer extensions that have been installed will be allowed to run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-v4driverdisallowprinterextension"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_v4driverdisallowprinterextension_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_v4driverdisallowprinterextension_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_autopublishing","displayName":"Automatically publish new printers in Active Directory","description":"Determines whether the Add Printer Wizard automatically publishes the computer's shared printers in Active Directory.\r\n\r\n If you enable this setting or do not configure it, the Add Printer Wizard automatically publishes all shared printers.\r\n\r\n If you disable this setting, the Add Printer Wizard does not automatically publish printers. However, you can publish shared printers manually.\r\n\r\n The default behavior is to automatically publish shared printers in Active Directory.\r\n\r\n Note: This setting is ignored if the \"Allow printers to be published\" setting is disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-autopublishing"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_autopublishing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_autopublishing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_immortalprintqueue","displayName":"Allow pruning of published printers","description":"Determines whether the domain controller can prune (delete from Active Directory) the printers published by this computer.\r\n\r\n By default, the pruning service on the domain controller prunes printer objects from Active Directory if the computer that published them does not respond to contact requests. When the computer that published the printers restarts, it republishes any deleted printer objects.\r\n\r\n If you enable this setting or do not configure it, the domain controller prunes this computer's printers when the computer does not respond.\r\n\r\n If you disable this setting, the domain controller does not prune this computer's printers. This setting is designed to prevent printers from being pruned when the computer is temporarily disconnected from the network.\r\n\r\n Note: You can use the \"Directory Pruning Interval\" and \"Directory Pruning Retry\" settings to adjust the contact interval and number of contact attempts.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-immortalprintqueue"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_immortalprintqueue_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_immortalprintqueue_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel","displayName":"Prune printers that are not automatically republished","description":"Determines whether the pruning service on a domain controller prunes printer objects that are not automatically republished whenever the host computer does not respond,just as it does with Windows 2000 printers. This setting applies to printers running operating systems other than Windows 2000 and to Windows 2000 printers published outside their forest.\r\n\r\n The Windows pruning service prunes printer objects from Active Directory when the computer that published them does not respond to contact requests. Computers running Windows 2000 Professional detect and republish deleted printer objects when they rejoin the network. However, because non-Windows 2000 computers and computers in other domains cannot republish printers in Active Directory automatically, by default, the system never prunes their printer objects.\r\n\r\n You can enable this setting to change the default behavior. To use this setting, select one of the following options from the \"Prune non-republishing printers\" box:\r\n\r\n -- \"Never\" specifies that printer objects that are not automatically republished are never pruned. \"Never\" is the default.\r\n\r\n -- \"Only if Print Server is found\" prunes printer objects that are not automatically republished only when the print server responds, but the printer is unavailable.\r\n\r\n -- \"Whenever printer is not found\" prunes printer objects that are not automatically republished whenever the host computer does not respond, just as it does with Windows 2000 printers.\r\n\r\n Note: This setting applies to printers published by using Active Directory Users and Computers or Pubprn.vbs. It does not apply to printers published by using Printers in Control Panel.\r\n\r\n Tip: If you disable automatic pruning, remember to delete printer objects manually whenever you remove a printer or print server.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-prunedownlevel"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle","displayName":"Prune non-republishing printers:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle_1","displayName":"Only if Print Server is found","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle_2","displayName":"Whenever printer is not found","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval","displayName":"Directory pruning interval","description":"Specifies how often the pruning service on a domain controller contacts computers to verify that their printers are operational.\r\n\r\n The pruning service periodically contacts computers that have published printers. If a computer does not respond to the contact message (optionally, after repeated attempts), the pruning service \"prunes\" (deletes from Active Directory) printer objects the computer has published.\r\n\r\n By default, the pruning service contacts computers every eight hours and allows two repeated contact attempts before deleting printers from Active Directory.\r\n\r\n If you enable this setting, you can change the interval between contact attempts.\r\n\r\n If you do not configure or disable this setting the default values will be used.\r\n\r\n Note: This setting is used only on domain controllers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-pruninginterval"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle","displayName":"Interval:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_0","displayName":"Continuous","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_10","displayName":"10 Minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_30","displayName":"30 Minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_60","displayName":"1 Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_240","displayName":"4 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_480","displayName":"8 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_720","displayName":"12 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_1440","displayName":"1 Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_2880","displayName":"2 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_4320","displayName":"3 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_5760","displayName":"4 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_7200","displayName":"5 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_8640","displayName":"6 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_10080","displayName":"1 Week","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_20160","displayName":"2 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_30240","displayName":"3 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_40320","displayName":"4 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_50400","displayName":"5 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_60480","displayName":"6 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_70560","displayName":"7 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_4294967295","displayName":"Infinite","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority","displayName":"Directory pruning priority","description":"Sets the priority of the pruning thread.\r\n\r\n The pruning thread, which runs only on domain controllers, deletes printer objects from Active Directory if the printer that published the object does not respond to contact attempts. This process keeps printer information in Active Directory current.\r\n\r\n The thread priority influences the order in which the thread receives processor time and determines how likely it is to be preempted by higher priority threads.\r\n\r\n By default, the pruning thread runs at normal priority. However, you can adjust the priority to improve the performance of this service.\r\n\r\n Note: This setting is used only on domain controllers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-pruningpriority"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_prioritylevel","displayName":"Priority level:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_prioritylevel_4294967294","displayName":"Lowest","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_prioritylevel_4294967295","displayName":"Below Normal","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_prioritylevel_0","displayName":"Normal","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_prioritylevel_1","displayName":"Above Normal","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_prioritylevel_2","displayName":"Highest","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries","displayName":"Directory pruning retry","description":"Specifies how many times the pruning service on a domain controller repeats its attempt to contact a computer before pruning the computer's printers.\r\n\r\n The pruning service periodically contacts computers that have published printers to verify that the printers are still available for use. If a computer does not respond to the contact message, the message is repeated for the specified number of times. If the computer still fails to respond, then the pruning service \"prunes\" (deletes from Active Directory) printer objects the computer has published.\r\n\r\n By default, the pruning service contacts computers every eight hours and allows two retries before deleting printers from Active Directory. You can use this setting to change the number of retries.\r\n\r\n If you enable this setting, you can change the interval between attempts.\r\n\r\n If you do not configure or disable this setting, the default values are used.\r\n\r\n Note: This setting is used only on domain controllers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-pruningretries"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle","displayName":"Retries:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_0","displayName":"No Retry","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_1","displayName":"1 Retry","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_2","displayName":"2 Retries","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_3","displayName":"3 Retries","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_4","displayName":"4 Retries","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_5","displayName":"5 Retries","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_6","displayName":"6 Retries","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretrylog","displayName":"Log directory pruning retry events","description":"Specifies whether or not to log events when the pruning service on a domain controller attempts to contact a computer before pruning the computer's printers.\r\n\r\n The pruning service periodically contacts computers that have published printers to verify that the printers are still available for use. If a computer does not respond to the contact attempt, the attempt is retried a specified number of times, at a specified interval. The \"Directory pruning retry\" setting determines the number of times the attempt is retried; the default value is two retries. The \"Directory Pruning Interval\" setting determines the time interval between retries; the default value is every eight hours. If the computer has not responded by the last contact attempt, its printers are pruned from the directory.\r\n\r\n If you enable this policy setting, the contact events are recorded in the event log.\r\n\r\n If you disable or do not configure this policy setting, the contact events are not recorded in the event log.\r\n\r\n Note: This setting does not affect the logging of pruning events; the actual pruning of a printer is always logged.\r\n\r\n Note: This setting is used only on domain controllers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-pruningretrylog"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretrylog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretrylog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_registerspoolerremoterpcendpoint","displayName":"Allow Print Spooler to accept client connections","description":"This policy controls whether the print spooler will accept client connections.\r\n\r\nWhen the policy is unconfigured or enabled, the spooler will always accept client connections.\r\n\r\nWhen the policy is disabled, the spooler will not accept client connections nor allow users to share printers. All printers currently shared will continue to be shared.\r\n\r\nThe spooler must be restarted for changes to this policy to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-registerspoolerremoterpcendpoint"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_registerspoolerremoterpcendpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_registerspoolerremoterpcendpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate","displayName":"Check published state","description":"Directs the system to periodically verify that the printers published by this computer still appear in Active Directory. This setting also specifies how often the system repeats the verification.\r\n\r\n By default, the system only verifies published printers at startup. This setting allows for periodic verification while the computer is operating.\r\n\r\n To enable this additional verification, enable this setting, and then select a verification interval.\r\n\r\n To disable verification, disable this setting, or enable this setting and select \"Never\" for the verification interval.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-verifypublishedstate"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle","displayName":"Published State Check Interval:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_30","displayName":"30 Minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_60","displayName":"1 Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_240","displayName":"4 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_480","displayName":"8 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_720","displayName":"12 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_1440","displayName":"1 Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_4294967295","displayName":"Never","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pushtoinstall_disablepushtoinstall","displayName":"Turn off Push To Install service","description":"If you enable this setting, users will not be able to push Apps to this device from the Microsoft Store running on other devices or the web.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pushtoinstall#admx-pushtoinstall-disablepushtoinstall"],"categoryId":"05305a87-0b19-41bb-bf1e-0bd92bfcdc16","categoryName":"Push To Install","options":[{"id":"device_vendor_msft_policy_config_admx_pushtoinstall_disablepushtoinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pushtoinstall_disablepushtoinstall_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosmaxoutstandingsends","displayName":"Limit outstanding packets","description":"Specifies the maximum number of outstanding packets permitted on the system. When the number of outstanding packets reaches this limit, the Packet Scheduler postpones all submissions to network adapters until the number falls below this limit.\r\n\r\n\"Outstanding packets\" are packets that the Packet Scheduler has submitted to a network adapter for transmission, but which have not yet been sent.\r\n\r\nIf you enable this setting, you can limit the number of outstanding packets.\r\n\r\nIf you disable this setting or do not configure it, then the setting has no effect on the system.\r\n\r\nImportant: If the maximum number of outstanding packets is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosmaxoutstandingsends"],"categoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","categoryName":"Qo S Packet Scheduler","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosmaxoutstandingsends_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosmaxoutstandingsends_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosmaxoutstandingsends_qosmaxoutstandingsends_box","displayName":"Number of packets:","description":null,"helpText":"","infoUrls":[],"categoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","categoryName":"Qo S Packet Scheduler","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosnonbesteffortlimit","displayName":"Limit reservable bandwidth","description":"Determines the percentage of connection bandwidth that the system can reserve. This value limits the combined bandwidth reservations of all programs running on the system.\r\n\r\nBy default, the Packet Scheduler limits the system to 80 percent of the bandwidth of a connection, but you can use this setting to override the default.\r\n\r\nIf you enable this setting, you can use the \"Bandwidth limit\" box to adjust the amount of bandwidth the system can reserve.\r\n\r\nIf you disable this setting or do not configure it, the system uses the default value of 80 percent of the connection.\r\n\r\nImportant: If a bandwidth limit is set for a particular network adapter in the registry, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosnonbesteffortlimit"],"categoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","categoryName":"Qo S Packet Scheduler","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosnonbesteffortlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosnonbesteffortlimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosnonbesteffortlimit_qosnonbesteffortlimit_box","displayName":"Bandwidth limit (%):","description":null,"helpText":"","infoUrls":[],"categoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","categoryName":"Qo S Packet Scheduler","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c","displayName":"Best effort service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Best Effort service type (ServiceTypeBestEffort). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Best Effort service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypebesteffort-c"],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_nc","displayName":"Best effort service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Best Effort service type (ServiceTypeBestEffort). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that do not conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Best Effort service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypebesteffort-nc"],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_nc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_nc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv","displayName":"Best effort service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Best Effort service type (ServiceTypeBestEffort). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Best Effort service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypebesteffort-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_c","displayName":"Controlled load service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Controlled Load service type (ServiceTypeControlledLoad). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Controlled Load service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 24 (0x18).\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypecontrolledload-c"],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_c_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_c_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_nc","displayName":"Controlled load service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Controlled Load service type (ServiceTypeControlledLoad). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that do not conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Controlled Load service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypecontrolledload-nc"],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_nc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_nc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_pv","displayName":"Controlled load service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Controlled Load service type (ServiceTypeControlledLoad). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Controlled Load service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypecontrolledload-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_pv_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_c","displayName":"Guaranteed service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Guaranteed service type (ServiceTypeGuaranteed). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Guaranteed service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 40 (0x28).\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypeguaranteed-c"],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_c_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_c_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc","displayName":"Guaranteed service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Guaranteed service type (ServiceTypeGuaranteed). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that do not conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Guaranteed service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypeguaranteed-nc"],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv","displayName":"Guaranteed service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Guaranteed service type (ServiceTypeGuaranteed). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Guaranteed service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypeguaranteed-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_c","displayName":"Network control service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Network Control service type (ServiceTypeNetworkControl). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Network Control service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 48 (0x30).\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypenetworkcontrol-c"],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_c_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_c_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_nc","displayName":"Network control service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Network Control service type (ServiceTypeNetworkControl). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that do not conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Network Control service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypenetworkcontrol-nc"],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_nc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_nc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_pv","displayName":"Network control service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Network Control service type (ServiceTypeNetworkControl). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Network Control service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypenetworkcontrol-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_pv_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenonconforming","displayName":"Non-conforming packets","description":"Specifies an alternate link layer (Layer-2) priority value for packets that do not conform to the flow specification. The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with nonconforming packets.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for nonconforming packets is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypenonconforming"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenonconforming_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenonconforming_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenonconforming_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_c","displayName":"Qualitative service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Qualitative service type (ServiceTypeQualitative). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Qualitative service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypequalitative-c"],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_c_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_c_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_nc","displayName":"Qualitative service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Qualitative service type (ServiceTypeQualitative). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that do not conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Qualitative service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypequalitative-nc"],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_nc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_nc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv","displayName":"Qualitative service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Qualitative service type (ServiceTypeQualitative). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Qualitative service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypequalitative-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qostimerresolution","displayName":"Set timer resolution","description":"Determines the smallest unit of time that the Packet Scheduler uses when scheduling packets for transmission. The Packet Scheduler cannot schedule packets for transmission more frequently than permitted by the value of this entry.\r\n\r\nIf you enable this setting, you can override the default timer resolution established for the system, usually units of 10 microseconds.\r\n\r\nIf you disable this setting or do not configure it, the setting has no effect on the system.\r\n\r\nImportant: If a timer resolution is specified in the registry for a particular network adapter, then this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qostimerresolution"],"categoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","categoryName":"Qo S Packet Scheduler","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qostimerresolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qostimerresolution_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qostimerresolution_qostimerresolution_box","displayName":"Timer units (in microseconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","categoryName":"Qo S Packet Scheduler","options":null},{"id":"device_vendor_msft_policy_config_admx_radar_wdiscenarioexecutionpolicy","displayName":"Configure Scenario Execution Level","description":"Determines the execution level for Windows Resource Exhaustion Detection and Resolution.\r\n\r\nIf you enable this policy setting, you must select an execution level from the dropdown menu. If you select problem detection and troubleshooting only, the Diagnostic Policy Service (DPS) will detect Windows Resource Exhaustion problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will detect Windows Resource Exhaustion problems and indicate to the user that assisted resolution is available.\r\n\r\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve any Windows Resource Exhaustion problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS will enable Windows Resource Exhaustion for resolution by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo system restart or service restart is required for this policy to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-radar#admx-radar-wdiscenarioexecutionpolicy"],"categoryId":"ffd1a98f-0fac-47fe-813f-7510d0dacbc3","categoryName":"Windows Resource Exhaustion Detection and Resolution","options":[{"id":"device_vendor_msft_policy_config_admx_radar_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_radar_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_radar_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"ffd1a98f-0fac-47fe-813f-7510d0dacbc3","categoryName":"Windows Resource Exhaustion Detection and Resolution","options":[{"id":"device_vendor_msft_policy_config_admx_radar_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_radar_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_reliability_ee_enablepersistenttimestamp","displayName":"Enable Persistent Time Stamp","description":"This policy setting allows the system to detect the time of unexpected shutdowns by writing the current time to disk on a schedule controlled by the Timestamp Interval.\r\n\r\nIf you enable this policy setting, you are able to specify how often the Persistent System Timestamp is refreshed and subsequently written to the disk. You can specify the Timestamp Interval in seconds.\r\n\r\nIf you disable this policy setting, the Persistent System Timestamp is turned off and the timing of unexpected shutdowns is not recorded.\r\n\r\nIf you do not configure this policy setting, the Persistent System Timestamp is refreshed according the default, which is every 60 seconds beginning with Windows Server 2003.\r\n\r\nNote: This feature might interfere with power configuration settings that turn off hard disks after a period of inactivity. These power settings may be accessed in the Power Options Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-reliability#admx-reliability-ee-enablepersistenttimestamp"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_reliability_ee_enablepersistenttimestamp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_reliability_ee_enablepersistenttimestamp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_reliability_ee_enablepersistenttimestamp_ee_enablepersistenttimestamp_desc4","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_reliability_pch_reportshutdownevents","displayName":"Report unplanned shutdown events","description":"This policy setting controls whether or not unplanned shutdown events can be reported when error reporting is enabled.\r\n\r\nIf you enable this policy setting, error reporting includes unplanned shutdown events.\r\n\r\nIf you disable this policy setting, unplanned shutdown events are not included in error reporting.\r\n\r\nIf you do not configure this policy setting, users can adjust this setting using the control panel, which is set to \"Upload unplanned shutdown events\" by default.\r\n\r\nAlso see the \"Configure Error Reporting\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-reliability#admx-reliability-pch-reportshutdownevents"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_reliability_pch_reportshutdownevents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_reliability_pch_reportshutdownevents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdowneventtrackerstatefile","displayName":"Activate Shutdown Event Tracker System State Data feature","description":"This policy setting defines when the Shutdown Event Tracker System State Data feature is activated.\r\n\r\nThe system state data file contains information about the basic system state as well as the state of all running processes.\r\n\r\nIf you enable this policy setting, the System State Data feature is activated when the user indicates that the shutdown or restart is unplanned.\r\n\r\nIf you disable this policy setting, the System State Data feature is never activated.\r\n\r\nIf you do not configure this policy setting, the default behavior for the System State Data feature occurs.\r\n\r\nNote: By default, the System State Data feature is always enabled on Windows Server 2003. See \"Supported on\" for all supported versions.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-reliability#admx-reliability-shutdowneventtrackerstatefile"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_reliability_shutdowneventtrackerstatefile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdowneventtrackerstatefile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason","displayName":"Display Shutdown Event Tracker","description":"The Shutdown Event Tracker can be displayed when you shut down a workstation or server. This is an extra set of questions that is displayed when you invoke a shutdown to collect information related to why you are shutting down the computer.\r\n\r\nIf you enable this setting and choose \"Always\" from the drop-down menu list, the Shutdown Event Tracker is displayed when the computer shuts down.\r\n\r\nIf you enable this policy setting and choose \"Server Only\" from the drop-down menu list, the Shutdown Event Tracker is displayed when you shut down a computer running Windows Server. (See \"Supported on\" for supported versions.)\r\n\r\nIf you enable this policy setting and choose \"Workstation Only\" from the drop-down menu list, the Shutdown Event Tracker is displayed when you shut down a computer running a client version of Windows. (See \"Supported on\" for supported versions.)\r\n\r\nIf you disable this policy setting, the Shutdown Event Tracker is not displayed when you shut down the computer.\r\n\r\nIf you do not configure this policy setting, the default behavior for the Shutdown Event Tracker occurs.\r\n\r\nNote: By default, the Shutdown Event Tracker is only displayed on computers running Windows Server.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-reliability#admx-reliability-shutdownreason"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason_shutdownreason_box","displayName":"Shutdown Event Tracker should be displayed:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason_shutdownreason_box_1","displayName":"Always","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason_shutdownreason_box_2","displayName":"Workstation Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason_shutdownreason_box_3","displayName":"Server Only","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_encryptedticketonly","displayName":"Allow only Windows Vista or later connections","description":"This policy setting enables Remote Assistance invitations to be generated with improved encryption so that only computers running this version (or later versions) of the operating system can connect. This policy setting does not affect Remote Assistance connections that are initiated by instant messaging contacts or the unsolicited Offer Remote Assistance.\r\n\r\nIf you enable this policy setting, only computers running this version (or later versions) of the operating system can connect to this computer.\r\n\r\nIf you disable this policy setting, computers running this version and a previous version of the operating system can connect to this computer.\r\n\r\nIf you do not configure this policy setting, users can configure the setting in System Properties in the Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-remoteassistance#admx-remoteassistance-ra-encryptedticketonly"],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_encryptedticketonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_encryptedticketonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth","displayName":"Turn on bandwidth optimization","description":"This policy setting allows you to improve performance in low bandwidth scenarios.\r\n\r\nThis setting is incrementally scaled from \"No optimization\" to \"Full optimization\". Each incremental setting includes the previous optimization setting.\r\n\r\nFor example:\r\n\r\n\"Turn off background\" will include the following optimizations:\r\n-No full window drag\r\n-Turn off background\r\n\r\n\"Full optimization\" will include the following optimizations:\r\n-Use 16-bit color (8-bit color in Windows Vista)\r\n-Turn off font smoothing (not supported in Windows Vista)\r\n-No full window drag\r\n-Turn off background\r\n\r\nIf you enable this policy setting, bandwidth optimization occurs at the level specified.\r\n\r\nIf you disable this policy setting, application-based settings are used.\r\n\r\nIf you do not configure this policy setting, application-based settings are used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-remoteassistance#admx-remoteassistance-ra-optimize-bandwidth"],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_ra_optimize_bandwidth_list","displayName":"Optimize settings for reduced bandwidth:","description":null,"helpText":"","infoUrls":[],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_ra_optimize_bandwidth_list_14","displayName":"No optimization","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_ra_optimize_bandwidth_list_12","displayName":"No full window drag","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_ra_optimize_bandwidth_list_8","displayName":"Turn off background","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_ra_optimize_bandwidth_list_0","displayName":"Full optimization","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_accessrights_reboottime_2","displayName":"Set time (in seconds) to force reboot","description":"This policy setting configures the amount of time (in seconds) that the operating system waits to reboot in order to enforce a change in access rights to removable storage devices.\r\n\r\nIf you enable this policy setting, you can set the number of seconds you want the system to wait until a reboot.\r\n\r\nIf you disable or do not configure this setting, the operating system does not force a reboot.\r\n\r\nNote: If no reboot is forced, the access right does not take effect until the operating system is restarted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-accessrights-reboottime-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_accessrights_reboottime_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_accessrights_reboottime_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_accessrights_reboottime_2_accessrights_reboottime_seconds","displayName":"Time (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyexecute_access_2","displayName":"CD and DVD: Deny execute access","description":"This policy setting denies execute access to the CD and DVD removable storage class.\r\n\r\nIf you enable this policy setting, execute access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, execute access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-cdanddvd-denyexecute-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyexecute_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyexecute_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyread_access_2","displayName":"CD and DVD: Deny read access","description":"This policy setting denies read access to the CD and DVD removable storage class.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-cdanddvd-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denywrite_access_2","displayName":"CD and DVD: Deny write access","description":"This policy setting denies write access to the CD and DVD removable storage class.\r\n\r\nIf you enable this policy setting, write access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-cdanddvd-denywrite-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denywrite_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denywrite_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_2","displayName":"Custom Classes: Deny read access","description":"This policy setting denies read access to custom removable storage classes.\r\n\r\nIf you enable this policy setting, read access is denied to these removable storage classes.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to these removable storage classes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-customclasses-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_2_customclasses_list","displayName":"GUID for custom removable storage class:","description":null,"helpText":"","infoUrls":[],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_2","displayName":"Custom Classes: Deny write access","description":"This policy setting denies write access to custom removable storage classes.\r\n\r\nIf you enable this policy setting, write access is denied to these removable storage classes.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to these removable storage classes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-customclasses-denywrite-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_2_customclasses_list","displayName":"GUID for custom removable storage class:","description":null,"helpText":"","infoUrls":[],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyexecute_access_2","displayName":"Floppy Drives: Deny execute access","description":"This policy setting denies execute access to the Floppy Drives removable storage class, including USB Floppy Drives.\r\n\r\nIf you enable this policy setting, execute access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, execute access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-floppydrives-denyexecute-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyexecute_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyexecute_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_2","displayName":"Floppy Drives: Deny read access","description":"This policy setting denies read access to the Floppy Drives removable storage class, including USB Floppy Drives.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-floppydrives-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denywrite_access_2","displayName":"Floppy Drives: Deny write access","description":"This policy setting denies write access to the Floppy Drives removable storage class, including USB Floppy Drives.\r\n\r\nIf you enable this policy setting, write access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-floppydrives-denywrite-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denywrite_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denywrite_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removable_remote_allow_access","displayName":"All Removable Storage: Allow direct access in remote sessions","description":"This policy setting grants normal users direct access to removable storage devices in remote sessions.\r\n\r\nIf you enable this policy setting, remote users can open direct handles to removable storage devices in remote sessions.\r\n\r\nIf you disable or do not configure this policy setting, remote users cannot open direct handles to removable storage devices in remote sessions.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-removable-remote-allow-access"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_removable_remote_allow_access_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removable_remote_allow_access_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyexecute_access_2","displayName":"Removable Disks: Deny execute access","description":"This policy setting denies execute access to removable disks.\r\n\r\nIf you enable this policy setting, execute access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, execute access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-removabledisks-denyexecute-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyexecute_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyexecute_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyread_access_2","displayName":"Removable Disks: Deny read access","description":"This policy setting denies read access to removable disks.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-removabledisks-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removablestorageclasses_denyall_access_2","displayName":"All Removable Storage classes: Deny all access","description":"Configure access to all removable storage classes.\r\n\r\nThis policy setting takes precedence over any individual removable storage policy settings. To manage individual classes, use the policy settings available for each class.\r\n\r\nIf you enable this policy setting, no access is allowed to any removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write and read accesses are allowed to all removable storage classes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-removablestorageclasses-denyall-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_removablestorageclasses_denyall_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removablestorageclasses_denyall_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denyexecute_access_2","displayName":"Tape Drives: Deny execute access","description":"This policy setting denies execute access to the Tape Drive removable storage class.\r\n\r\nIf you enable this policy setting, execute access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, execute access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-tapedrives-denyexecute-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denyexecute_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denyexecute_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denyread_access_2","displayName":"Tape Drives: Deny read access","description":"This policy setting denies read access to the Tape Drive removable storage class.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-tapedrives-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_2","displayName":"Tape Drives: Deny write access","description":"This policy setting denies write access to the Tape Drive removable storage class.\r\n\r\nIf you enable this policy setting, write access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-tapedrives-denywrite-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_wpddevices_denyread_access_2","displayName":"WPD Devices: Deny read access","description":"This policy setting denies read access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-wpddevices-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_wpddevices_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_wpddevices_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_wpddevices_denywrite_access_2","displayName":"WPD Devices: Deny write access","description":"This policy setting denies write access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices.\r\n\r\nIf you enable this policy setting, write access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-wpddevices-denywrite-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_wpddevices_denywrite_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_wpddevices_denywrite_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation","displayName":"Propagate extended error information","description":"This policy setting controls whether the RPC runtime generates extended error information when an error occurs.\r\n\r\nExtended error information includes the local time that the error occurred, the RPC version, and the name of the computer on which the error occurred, or from which it was propagated. Programs can retrieve the extended error information by using standard Windows application programming interfaces (APIs).\r\n\r\nIf you disable this policy setting, the RPC Runtime only generates a status code to indicate an error condition.\r\n\r\nIf you do not configure this policy setting, it remains disabled. It will only generate a status code to indicate an error condition.\r\n\r\nIf you enable this policy setting, the RPC runtime will generate extended error information. You must select an error response type in the drop-down box.\r\n\r\n-- \"Off\" disables all extended error information for all processes. RPC only generates an error code.\r\n\r\n-- \"On with Exceptions\" enables extended error information, but lets you disable it for selected processes. To disable extended error information for a process while this policy setting is in effect, the command that starts the process must begin with one of the strings in the Extended Error Information Exception field.\r\n\r\n-- \"Off with Exceptions\" disables extended error information, but lets you enable it for selected processes. To enable extended error information for a process while this policy setting is in effect, the command that starts the process must begin with one of the strings in the Extended Error Information Exception field.\r\n\r\n-- \"On\" enables extended error information for all processes.\r\n\r\nNote: For information about the Extended Error Information Exception field, see the Windows Software Development Kit (SDK).\r\n\r\nNote: Extended error information is formatted to be compatible with other operating systems and older Microsoft operating systems, but only newer Microsoft operating systems can read and respond to the information.\r\n\r\nNote: The default policy setting, \"Off,\" is designed for systems where extended error information is considered to be sensitive, and it should not be made available remotely.\r\n\r\nNote: This policy setting will not be applied until the system is rebooted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-rpc#admx-rpc-rpcextendederrorinformation"],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_rpcextendederrorinformationlist","displayName":"Propagation of extended error information:","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_rpcextendederrorinformationlist_0","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_rpcextendederrorinformationlist_1","displayName":"On with Exceptions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_rpcextendederrorinformationlist_2","displayName":"Off with Exceptions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_rpcextendederrorinformationlist_3","displayName":"On","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_rpcexterrorexceptions","displayName":"Extended Error Information Exceptions:","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure","displayName":"Ignore Delegation Failure","description":"This policy setting controls whether the RPC Runtime ignores delegation failures when delegation is requested.\r\n\r\nThe constrained delegation model, introduced in Windows Server 2003, does not report that delegation was enabled on a security context when a client connects to a server. Callers of RPC and COM are encouraged to use the RPC_C_QOS_CAPABILITIES_IGNORE_DELEGATE_FAILURE flag, but some applications written for the traditional delegation model prior to Windows Server 2003 may not use this flag and will encounter RPC_S_SEC_PKG_ERROR when connecting to a server that uses constrained delegation.\r\n\r\nIf you disable this policy setting, the RPC Runtime will generate RPC_S_SEC_PKG_ERROR errors to applications that ask for delegation and connect to servers using constrained delegation. \r\n\r\nIf you do not configure this policy setting, it remains disabled and will generate RPC_S_SEC_PKG_ERROR errors to applications that ask for delegation and connect to servers using constrained delegation. \r\n\r\nIf you enable this policy setting, then:\r\n\r\n-- \"Off\" directs the RPC Runtime to generate RPC_S_SEC_PKG_ERROR if the client asks for delegation, but the created security context does not support delegation.\r\n\r\n-- \"On\" directs the RPC Runtime to accept security contexts that do not support delegation even if delegation was asked for.\r\n\r\nNote: This policy setting will not be applied until the system is rebooted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-rpc#admx-rpc-rpcignoredelegationfailure"],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_rpcignoredelegationfailurelist","displayName":"Ignoring Delegation Failure:","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_rpcignoredelegationfailurelist_0","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_rpcignoredelegationfailurelist_1","displayName":"On","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcminimumhttpconnectiontimeout","displayName":"Set Minimum Idle Connection Timeout for RPC/HTTP connections","description":"This policy setting controls the idle connection timeout for RPC/HTTP connections. \r\n\r\nThis policy setting is useful in cases where a network agent like an HTTP proxy or a router uses a lower idle connection timeout than the IIS server running the RPC/HTTP proxy. In such cases, RPC/HTTP clients may encounter errors because connections will be timed out faster than expected. Using this policy setting you can force the RPC Runtime and the RPC/HTTP Proxy to use a lower connection timeout.\r\n\r\nThis policy setting is only applicable when the RPC Client, the RPC Server and the RPC HTTP Proxy are all running Windows Server 2003 family/Windows XP SP1 or higher versions. If either the RPC Client or the RPC Server or the RPC HTTP Proxy run on an older version of Windows, this policy setting will be ignored.\r\n\r\nThe minimum allowed value for this policy setting is 90 seconds. The maximum is 7200 seconds (2 hours).\r\n\r\nIf you disable this policy setting, the idle connection timeout on the IIS server running the RPC HTTP proxy will be used.\r\n\r\nIf you do not configure this policy setting, it will remain disabled. The idle connection timeout on the IIS server running the RPC HTTP proxy will be used.\r\n\r\nIf you enable this policy setting, and the IIS server running the RPC HTTP proxy is configured with a lower idle connection timeout, the timeout on the IIS server is used. Otherwise, the provided timeout value is used. The timeout is given in seconds.\r\n\r\nNote: This policy setting will not be applied until the system is rebooted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-rpc#admx-rpc-rpcminimumhttpconnectiontimeout"],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcminimumhttpconnectiontimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcminimumhttpconnectiontimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcminimumhttpconnectiontimeout_rpcminimumhttpconnectiontimeoutvalue","displayName":"Minimum Idle Connection Timeout (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation","displayName":"Maintain RPC Troubleshooting State Information","description":"This policy setting determines whether the RPC Runtime maintains RPC state information for the system, and how much information it maintains. Basic state information, which consists only of the most commonly needed state data, is required for troubleshooting RPC problems.\r\n\r\nIf you disable this policy setting, the RPC runtime defaults to \"Auto2\" level.\r\n\r\nIf you do not configure this policy setting, the RPC defaults to \"Auto2\" level. \r\n\r\nIf you enable this policy setting, you can use the drop-down box to determine which systems maintain RPC state information.\r\n\r\n-- \"None\" indicates that the system does not maintain any RPC state information. Note: Because the basic state information required for troubleshooting has a negligible effect on performance and uses only about 4K of memory, this setting is not recommended for most installations.\r\n\r\n-- \"Auto1\" directs RPC to maintain basic state information only if the computer has at least 64 MB of memory.\r\n\r\n-- \"Auto2\" directs RPC to maintain basic state information only if the computer has at least 128 MB of memory and is running Windows 2000 Server, Windows 2000 Advanced Server, or Windows 2000 Datacenter Server. \r\n\r\n-- \"Server\" directs RPC to maintain basic state information on the computer, regardless of its capacity.\r\n\r\n-- \"Full\" directs RPC to maintain complete RPC state information on the system, regardless of its capacity. Because this level can degrade performance, it is recommended for use only while you are investigating an RPC problem.\r\n\r\nNote: To retrieve the RPC state information from a system that maintains it, you must use a debugging tool.\r\n\r\nNote: This policy setting will not be applied until the system is rebooted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-rpc#admx-rpc-rpcstateinformation"],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist","displayName":"RPC Runtime state information to maintain:","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_0","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_1","displayName":"Auto1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_2","displayName":"Auto2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_3","displayName":"Server","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_4","displayName":"Full","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation","displayName":"Configure validation of ROCA-vulnerable WHfB keys during authentication","description":"This policy setting allows you to configure how domain controllers handle Windows Hello for Business (WHfB) keys that are vulnerable to the \"Return of Coppersmith's attack\" (ROCA) vulnerability.\n\nFor more information on the ROCA vulnerability, please see:\n\nhttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15361\n\nhttps://en.wikipedia.org/wiki/ROCA_vulnerability\n\nIf you enable this policy setting the following options are supported:\n\nIgnore: during authentication the domain controller will not probe any WHfB keys for the ROCA vulnerability.\n\nAudit: during authentication the domain controller will emit audit events for WHfB keys that are subject to the ROCA vulnerability (authentications will still succeed).\n\nBlock: during authentication the domain controller will block the use of WHfB keys that are subject to the ROCA vulnerability (authentications will fail).\n\nThis setting only takes effect on domain controllers.\n\nIf not configured, domain controllers will default to using their local configuration. The default local configuration is Audit.\n\nA reboot is not required for changes to this setting to take effect.\n\nNote: to avoid unexpected disruptions this setting should not be set to Block until appropriate mitigations have been performed, for example patching of vulnerable TPMs.\n\nMore information is available at https://go.microsoft.com/fwlink/?linkid=2116430.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sam#admx-sam-samngckeyrocavalidation"],"categoryId":"03a966f7-8f8e-4ecb-aab3-055fe907f5ab","categoryName":"Security Account Manager","options":[{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings","displayName":"Options for handling ROCA-vulnerable WHfB keys:","description":"","helpText":"","infoUrls":[],"categoryId":"03a966f7-8f8e-4ecb-aab3-055fe907f5ab","categoryName":"Security Account Manager","options":[{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings_0","displayName":"Ignore ROCA-vulnerable WHfB keys","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings_1","displayName":"Audit ROCA-vulnerable WHfB keys on use","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings_2","displayName":"Block ROCA-vulnerable WHfB keys on use","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_allow_logon_script_netbiosdisabled","displayName":"Allow logon scripts when NetBIOS or WINS is disabled","description":"This policy setting allows user logon scripts to run when the logon cross-forest, DNS suffixes are not configured, and NetBIOS or WINS is disabled. This policy setting affects all user accounts interactively logging on to the computer.\r\n\r\nIf you enable this policy setting, user logon scripts run if NetBIOS or WINS is disabled during cross-forest logons without the DNS suffixes being configured.\r\n\r\nIf you disable or do not configure this policy setting, user account cross-forest, interactive logging cannot run logon scripts if NetBIOS or WINS is disabled, and the DNS suffixes are not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-allow-logon-script-netbiosdisabled"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_allow_logon_script_netbiosdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_allow_logon_script_netbiosdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_maxgposcriptwaitpolicy","displayName":"Specify maximum wait time for Group Policy scripts","description":"This policy setting determines how long the system waits for scripts applied by Group Policy to run. \r\n\r\nThis setting limits the total time allowed for all logon, logoff, startup, and shutdown scripts applied by Group Policy to finish running. If the scripts have not finished running when the specified time expires, the system stops script processing and records an error event.\r\n\r\nIf you enable this setting, then, in the Seconds box, you can type a number from 1 to 32,000 for the number of seconds you want the system to wait for the set of scripts to finish. To direct the system to wait until the scripts have finished, no matter how long they take, type 0. \r\n\r\nThis interval is particularly important when other system tasks must wait while the scripts complete. By default, each startup script must complete before the next one runs. Also, you can use the \"Run logon scripts synchronously\" setting to direct the system to wait for the logon scripts to complete before loading the desktop. \r\n\r\nAn excessively long interval can delay the system and inconvenience users. However, if the interval is too short, prerequisite tasks might not be done, and the system can appear to be ready prematurely.\r\n\r\nIf you disable or do not configure this setting the system lets the combined set of scripts run for up to 600 seconds (10 minutes). This is the default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-maxgposcriptwaitpolicy"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_maxgposcriptwaitpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_maxgposcriptwaitpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_maxgposcriptwaitpolicy_maxgposcriptwait","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_computer_ps_scripts_first","displayName":"Run Windows PowerShell scripts first at computer startup, shutdown","description":"This policy setting determines whether Windows PowerShell scripts are run before non-Windows PowerShell scripts during computer startup and shutdown. By default, Windows PowerShell scripts run after non-Windows PowerShell scripts. \r\n \r\nIf you enable this policy setting, within each applicable Group Policy Object (GPO), Windows PowerShell scripts are run before non-Windows PowerShell scripts during computer startup and shutdown. \r\n\r\nFor example, assume the following scenario: \r\n\r\nThere are three GPOs (GPO A, GPO B, and GPO C). This policy setting is enabled in GPO A. \r\n\r\nGPO B and GPO C include the following computer startup scripts:\r\n\r\nGPO B: B.cmd, B.ps1\r\nGPO C: C.cmd, C.ps1\r\n\r\nAssume also that there are two computers, DesktopIT and DesktopSales. \r\nFor DesktopIT, GPOs A, B, and C are applied. Therefore, the scripts for GPOs B and C run in the following order for DesktopIT:\r\n\r\nWithin GPO B: B.ps1, B.cmd\r\nWithin GPO C: C.ps1, C.cmd\r\n \r\nFor DesktopSales, GPOs B and C are applied, but not GPO A. Therefore, the scripts for GPOs B and C run in the following order for DesktopSales:\r\n\r\nWithin GPO B: B.cmd, B.ps1\r\nWithin GPO C: C.cmd, C.ps1\r\n\r\nNote: This policy setting determines the order in which computer startup and shutdown scripts are run within all applicable GPOs. You can override this policy setting for specific script types within a specific GPO by configuring the following policy settings for the GPO:\r\n \r\nComputer Configuration\\Policies\\Windows Settings\\Scripts (Startup/Shutdown)\\Startup\r\nComputer Configuration\\Policies\\Windows Settings\\Scripts (Startup/Shutdown)\\Shutdown\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-computer-ps-scripts-first"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_run_computer_ps_scripts_first_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_computer_ps_scripts_first_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_run_logon_script_sync_2","displayName":"Run logon scripts synchronously","description":"This policy setting directs the system to wait for logon scripts to finish running before it starts the File Explorer interface program and creates the desktop.\r\n\r\nIf you enable this policy setting, File Explorer does not start until the logon scripts have finished running. This policy setting ensures that logon script processing is complete before the user starts working, but it can delay the appearance of the desktop.\r\n\r\nIf you disable or do not configure this policy setting, the logon scripts and File Explorer are not synchronized and can run simultaneously.\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. The policy setting set in Computer Configuration takes precedence over the policy setting set in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-logon-script-sync-2"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_run_logon_script_sync_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_logon_script_sync_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_run_shutdown_script_visible","displayName":"Display instructions in shutdown scripts as they run","description":"This policy setting displays the instructions in shutdown scripts as they run.\r\n\r\nShutdown scripts are batch files of instructions that run when the user restarts the system or shuts it down. By default, the system does not display the instructions in the shutdown script.\r\n\r\nIf you enable this policy setting, the system displays each instruction in the shutdown script as it runs. The instructions appear in a command window.\r\n\r\nIf you disable or do not configure this policy setting, the instructions are suppressed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-shutdown-script-visible"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_run_shutdown_script_visible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_shutdown_script_visible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_run_startup_script_sync","displayName":"Run startup scripts asynchronously","description":"This policy setting lets the system run startup scripts simultaneously.\r\n\r\nStartup scripts are batch files that run before the user is invited to log on. By default, the system waits for each startup script to complete before it runs the next startup script.\r\n\r\nIf you enable this policy setting, the system does not coordinate the running of startup scripts. As a result, startup scripts can run simultaneously.\r\n\r\nIf you disable or do not configure this policy setting, a startup cannot run until the previous script is complete.\r\n\r\nNote: Starting with Windows Vista operating system, scripts that are configured to run asynchronously are no longer visible on startup, whether the \"Run startup scripts visible\" policy setting is enabled or not.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-startup-script-sync"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_run_startup_script_sync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_startup_script_sync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_run_startup_script_visible","displayName":"Display instructions in startup scripts as they run","description":"This policy setting displays the instructions in startup scripts as they run.\r\n\r\nStartup scripts are batch files of instructions that run before the user is invited to log on. By default, the system does not display the instructions in the startup script.\r\n\r\nIf you enable this policy setting, the system displays each instruction in the startup script as it runs. Instructions appear in a command window. This policy setting is designed for advanced users.\r\n\r\nIf you disable or do not configure this policy setting, the instructions are suppressed.\r\n\r\nNote: Starting with Windows Vista operating system, scripts that are configured to run asynchronously are no longer visible on startup, whether this policy setting is enabled or not.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-startup-script-visible"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_run_startup_script_visible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_startup_script_visible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_run_user_ps_scripts_first","displayName":"Run Windows PowerShell scripts first at user logon, logoff","description":"This policy setting determines whether Windows PowerShell scripts are run before non-Windows PowerShell scripts during user logon and logoff. By default, Windows PowerShell scripts run after non-Windows PowerShell scripts. \r\n \r\nIf you enable this policy setting, within each applicable Group Policy Object (GPO), PowerShell scripts are run before non-PowerShell scripts during user logon and logoff. \r\n\r\nFor example, assume the following scenario: \r\n\r\nThere are three GPOs (GPO A, GPO B, and GPO C). This policy setting is enabled in GPO A. \r\n\r\nGPO B and GPO C include the following user logon scripts:\r\n\r\nGPO B: B.cmd, B.ps1\r\nGPO C: C.cmd, C.ps1\r\n\r\nAssume also that there are two users, Qin Hong and Tamara Johnston. \r\nFor Qin, GPOs A, B, and C are applied. Therefore, the scripts for GPOs B and C run in the following order for Qin:\r\n\r\nWithin GPO B: B.ps1, B.cmd\r\nWithin GPO C: C.ps1, C.cmd\r\n \r\nFor Tamara, GPOs B and C are applied, but not GPO A. Therefore, the scripts for GPOs B and C run in the following order for Tamara:\r\n\r\nWithin GPO B: B.cmd, B.ps1\r\nWithin GPO C: C.cmd, C.ps1\r\n\r\nNote: This policy setting determines the order in which user logon and logoff scripts are run within all applicable GPOs. You can override this policy setting for specific script types within a specific GPO by configuring the following policy settings for the GPO:\r\n \r\nUser Configuration\\Policies\\Windows Settings\\Scripts (Logon/Logoff)\\Logon\r\nUser Configuration\\Policies\\Windows Settings\\Scripts (Logon/Logoff)\\Logoff\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. The policy setting set in Computer Configuration takes precedence over the setting set in User Configuration.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-user-ps-scripts-first"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_run_user_ps_scripts_first_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_user_ps_scripts_first_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sdiageng_betterwhenconnected","displayName":"Troubleshooting: Allow users to access online troubleshooting content on Microsoft servers from the Troubleshooting Control Panel (via the Windows Online Troubleshooting Service - WOTS)","description":"This policy setting allows users who are connected to the Internet to access and search troubleshooting content that is hosted on Microsoft content servers. Users can access online troubleshooting content from within the Troubleshooting Control Panel UI by clicking \"Yes\" when they are prompted by a message that states, \"Do you want the most up-to-date troubleshooting content?\"\r\n\r\nIf you enable or do not configure this policy setting, users who are connected to the Internet can access and search troubleshooting content that is hosted on Microsoft content servers from within the Troubleshooting Control Panel user interface.\r\n\r\nIf you disable this policy setting, users can only access and search troubleshooting content that is available locally on their computers, even if they are connected to the Internet. They are prevented from connecting to the Microsoft servers that host the Windows Online Troubleshooting Service.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sdiageng#admx-sdiageng-betterwhenconnected"],"categoryId":"b6bb653a-73f0-42f4-b097-1ce556310904","categoryName":"Scripted Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_sdiageng_betterwhenconnected_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sdiageng_betterwhenconnected_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticsexecutionpolicy","displayName":"Troubleshooting: Allow users to access and run Troubleshooting Wizards","description":"This policy setting allows users to access and run the troubleshooting tools that are available in the Troubleshooting Control Panel and to run the troubleshooting wizard to troubleshoot problems on their computers.\r\n\r\nIf you enable or do not configure this policy setting, users can access and run the troubleshooting tools from the Troubleshooting Control Panel.\r\n\r\nIf you disable this policy setting, users cannot access or run the troubleshooting tools from the Control Panel.\r\n\r\nNote that this setting also controls a user's ability to launch standalone troubleshooting packs such as those found in .diagcab files.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sdiageng#admx-sdiageng-scripteddiagnosticsexecutionpolicy"],"categoryId":"b6bb653a-73f0-42f4-b097-1ce556310904","categoryName":"Scripted Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticsexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticsexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticssecuritypolicy","displayName":"Configure Security Policy for Scripted Diagnostics","description":"This policy setting determines whether scripted diagnostics will execute diagnostic packages that are signed by untrusted publishers.\r\n\r\nIf you enable this policy setting, the scripted diagnostics execution engine validates the signer of any diagnostic package and runs only those signed by trusted publishers.\r\n\r\nIf you disable or do not configure this policy setting, the scripted diagnostics execution engine runs all digitally signed packages.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sdiageng#admx-sdiageng-scripteddiagnosticssecuritypolicy"],"categoryId":"b6bb653a-73f0-42f4-b097-1ce556310904","categoryName":"Scripted Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticssecuritypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticssecuritypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sdiagschd_scheduleddiagnosticsexecutionpolicy","displayName":"Configure Scheduled Maintenance Behavior","description":"Determines whether scheduled diagnostics will run to proactively detect and resolve system problems.\r\n\r\nIf you enable this policy setting, you must choose an execution level. If you choose detection and troubleshooting only, Windows will periodically detect and troubleshoot problems. The user will be notified of the problem for interactive resolution. \r\n\r\nIf you choose detection, troubleshooting and resolution, Windows will resolve some of these problems silently without requiring user input.\r\n\r\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve problems on a scheduled basis.\r\n\r\nIf you do not configure this policy setting, local troubleshooting preferences will take precedence, as configured in the control panel. If no local troubleshooting preference is configured, scheduled diagnostics are enabled for detection, troubleshooting and resolution by default.\r\n\r\nNo reboots or service restarts are required for this policy to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Task Scheduler service is in the running state. When the service is stopped or disabled, scheduled diagnostics will not be executed. The Task Scheduler service can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sdiagschd#admx-sdiagschd-scheduleddiagnosticsexecutionpolicy"],"categoryId":"fe3cb879-8869-4163-91d7-e432abd75da8","categoryName":"Scheduled Maintenance","options":[{"id":"device_vendor_msft_policy_config_admx_sdiagschd_scheduleddiagnosticsexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sdiagschd_scheduleddiagnosticsexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sdiagschd_scheduleddiagnosticsexecutionpolicy_scheduleddiagnosticsexecutionpolicylevel","displayName":"Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"fe3cb879-8869-4163-91d7-e432abd75da8","categoryName":"Scheduled Maintenance","options":[{"id":"device_vendor_msft_policy_config_admx_sdiagschd_scheduleddiagnosticsexecutionpolicy_scheduleddiagnosticsexecutionpolicylevel_1","displayName":"Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sdiagschd_scheduleddiagnosticsexecutionpolicy_scheduleddiagnosticsexecutionpolicylevel_2","displayName":"Regular","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_securitycenter_securitycenter_securitycenterindomain","displayName":"Turn on Security Center (Domain PCs only)","description":"This policy setting specifies whether Security Center is turned on or off for computers that are joined to an Active Directory domain. When Security Center is turned on, it monitors essential security settings and notifies the user when the computer might be at risk. The Security Center Control Panel category view also contains a status section, where the user can get recommendations to help increase the computer's security. When Security Center is not enabled on the domain, neither the notifications nor the Security Center status section are displayed. \r\n\r\nNote that Security Center can only be turned off for computers that are joined to a Windows domain. When a computer is not joined to a Windows domain, the policy setting will have no effect.\r\n\r\nIf you do not congifure this policy setting, the Security Center is turned off for domain members. \r\n\r\nIf you enable this policy setting, Security Center is turned on for all users. \r\n\r\nIf you disable this policy setting, Security Center is turned off for domain members.\r\n\r\nWindows XP SP2\r\n----------------------\r\nIn Windows XP SP2, the essential security settings that are monitored by Security Center include firewall, antivirus, and Automatic Updates. Note that Security Center might not be available following a change to this policy setting until after the computer is restarted for Windows XP SP2 computers. \r\n\r\nWindows Vista\r\n---------------------\r\nIn Windows Vista, this policy setting monitors essential security settings to include firewall, antivirus, antispyware, Internet security settings, User Account Control, and Automatic Updates. Windows Vista computers do not require a reboot for this policy setting to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-securitycenter#admx-securitycenter-securitycenter-securitycenterindomain"],"categoryId":"31d3b4c4-767e-403a-834c-51f3691bbf2b","categoryName":"Security Center","options":[{"id":"device_vendor_msft_policy_config_admx_securitycenter_securitycenter_securitycenterindomain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_securitycenter_securitycenter_securitycenterindomain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sensors_disablelocationscripting_2","displayName":"Turn off location scripting","description":"\r\n This policy setting turns off scripting for the location feature.\r\n\r\n If you enable this policy setting, scripts for the location feature will not run.\r\n\r\n If you disable or do not configure this policy setting, all location scripts will run.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sensors#admx-sensors-disablelocationscripting-2"],"categoryId":"b40cfb22-8f17-4317-bcbb-c1c871497446","categoryName":"Location and Sensors","options":[{"id":"device_vendor_msft_policy_config_admx_sensors_disablelocationscripting_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sensors_disablelocationscripting_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sensors_disablesensors_2","displayName":"Turn off sensors","description":"\r\n This policy setting turns off the sensor feature for this computer.\r\n\r\n If you enable this policy setting, the sensor feature is turned off, and all programs on this computer cannot use the sensor feature.\r\n\r\n If you disable or do not configure this policy setting, all programs on this computer can use the sensor feature.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sensors#admx-sensors-disablesensors-2"],"categoryId":"b40cfb22-8f17-4317-bcbb-c1c871497446","categoryName":"Location and Sensors","options":[{"id":"device_vendor_msft_policy_config_admx_sensors_disablesensors_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sensors_disablesensors_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servermanager_do_not_display_manage_your_server_page","displayName":"Do not display Manage Your Server page at logon","description":"This policy setting allows you to turn off the automatic display of the Manage Your Server page. \r\n\r\nIf you enable this policy setting, the Manage Your Server page is not displayed each time an administrator logs on to the server. \r\n\r\nIf you disable or do not configure this policy setting, the Manage Your Server page is displayed each time an administrator logs on to the server. However, if the administrator has selected the \"Don’t display this page at logon\" option at the bottom of the Manage Your Server page, the page is not displayed.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servermanager#admx-servermanager-do-not-display-manage-your-server-page"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_servermanager_do_not_display_manage_your_server_page_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servermanager_do_not_display_manage_your_server_page_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servermanager_donotlaunchinitialconfigurationtasks","displayName":"Do not display Initial Configuration Tasks window automatically at logon","description":"This policy setting allows you to turn off the automatic display of the Initial Configuration Tasks window at logon on Windows Server 2008 and Windows Server 2008 R2. \r\n\r\nIf you enable this policy setting, the Initial Configuration Tasks window is not displayed when an administrator logs on to the server. \r\n\r\nIf you disable this policy setting, the Initial Configuration Tasks window is displayed when an administrator logs on to the server.\r\n\r\nIf you do not configure this policy setting, the Initial Configuration Tasks window is displayed when an administrator logs on to the server. However, if an administrator selects the \"Do not show this window at logon\" option, the window is not displayed on subsequent logons.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servermanager#admx-servermanager-donotlaunchinitialconfigurationtasks"],"categoryId":"e042b102-b12c-48d1-86ef-f6d296da5b95","categoryName":"Server Manager","options":[{"id":"device_vendor_msft_policy_config_admx_servermanager_donotlaunchinitialconfigurationtasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servermanager_donotlaunchinitialconfigurationtasks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servermanager_donotlaunchservermanager","displayName":"Do not display Server Manager automatically at logon","description":"This policy setting allows you to turn off the automatic display of Server Manager at logon.\r\n\r\nIf you enable this policy setting, Server Manager is not displayed automatically when a user logs on to the server.\r\n\r\nIf you disable this policy setting, Server Manager is displayed automatically when a user logs on to the server.\r\n\r\nIf you do not configure this policy setting, Server Manager is displayed when a user logs on to the server. However, if the \"Do not show me this console at logon\" (Windows Server 2008 and Windows Server 2008 R2) or “Do not start Server Manager automatically at logon” (Windows Server 2012) option is selected, the console is not displayed automatically at logon.\r\n\r\nNote: Regardless of the status of this policy setting, Server Manager is available from the Start menu or the Windows taskbar.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servermanager#admx-servermanager-donotlaunchservermanager"],"categoryId":"e042b102-b12c-48d1-86ef-f6d296da5b95","categoryName":"Server Manager","options":[{"id":"device_vendor_msft_policy_config_admx_servermanager_donotlaunchservermanager_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servermanager_donotlaunchservermanager_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate","displayName":"Configure the refresh interval for Server Manager","description":"This policy setting allows you to set the refresh interval for Server Manager. Each refresh provides Server Manager with updated information about which roles and features are installed on servers that you are managing by using Server Manager. Server Manager also monitors the status of roles and features installed on managed servers.\r\n\r\nIf you enable this policy setting, Server Manager uses the refresh interval specified in the policy setting instead of the “Configure Refresh Interval” setting (in Windows Server 2008 and Windows Server 2008 R2), or the “Refresh the data shown in Server Manager every [x] [minutes/hours/days]” setting (in Windows Server 2012) that is configured in the Server Manager console.\r\n\r\nIf you disable this policy setting, Server Manager does not refresh automatically. If you do not configure this policy setting, Server Manager uses the refresh interval settings that are specified in the Server Manager console.\r\n\r\nNote: The default refresh interval for Server Manager is two minutes in Windows Server 2008 and Windows Server 2008 R2, or 10 minutes in Windows Server 2012.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servermanager#admx-servermanager-servermanagerautorefreshrate"],"categoryId":"e042b102-b12c-48d1-86ef-f6d296da5b95","categoryName":"Server Manager","options":[{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate_refreshrate","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"e042b102-b12c-48d1-86ef-f6d296da5b95","categoryName":"Server Manager","options":null},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing","displayName":"Specify settings for optional component installation and component repair","description":"\r\nThis policy setting specifies the network locations that will be used for the repair of operating system corruption and for enabling optional features that have had their payload files removed.\r\n\r\nIf you enable this policy setting and specify the new location, the files in that location will be used to repair operating system corruption and for enabling optional features that have had their payload files removed. You must enter the fully qualified path to the new location in the \"Alternate source file path\" text box. Multiple locations can be specified when each path is separated by a semicolon. \r\n\r\nThe network location can be either a folder, or a WIM file. If it is a WIM file, the location should be specified by prefixing the path with “wim:” and include the index of the image to use in the WIM file. For example “wim:\\\\server\\share\\install.wim:3”.\r\n\r\nIf you disable or do not configure this policy setting, or if the required files cannot be found at the locations specified in this policy setting, the files will be downloaded from Windows Update, if that is allowed by the policy settings for the computer.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servicing#admx-servicing-servicing"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_checkbox_neverusewu","displayName":"Never attempt to download payload from Windows Update","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_checkbox_neverusewu_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_checkbox_neverusewu_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_checkbox_sidestepwsus","displayName":"Download repair content and optional features directly from Windows Update instead of Windows Server Update Services (WSUS)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_checkbox_sidestepwsus_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_checkbox_sidestepwsus_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_localsourcepath_textbox","displayName":"Alternate source file path","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableapplicationsettingsync","displayName":"Do not sync app settings","description":"Prevent the \"app settings\" group from syncing to and from this PC. This turns off and disables the \"app settings\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"app settings\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn app settings syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"app settings\" group is on by default and configurable by the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disableapplicationsettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disableapplicationsettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableapplicationsettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableapplicationsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"app settings\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disableapplicationsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableapplicationsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync","displayName":"Do not sync Apps","description":"\r\n Prevent the \"AppSync\" group from syncing to and from this PC. This turns off and disables the \"AppSync\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"AppSync\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn app syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"AppSync\" group is on by default and configurable by the user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disableappsyncsettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"AppSync\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablecredentialssettingsync","displayName":"Do not sync passwords","description":"Prevent the \"passwords\" group from syncing to and from this PC. This turns off and disables the \"passwords\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"passwords\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn passwords syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"passwords\" group is on by default and configurable by the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablecredentialssettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablecredentialssettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablecredentialssettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablecredentialssettingsync_checkbox_useroverride","displayName":"Allow users to turn \"passwords\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablecredentialssettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablecredentialssettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync","displayName":"Do not sync desktop personalization","description":"Prevent the \"desktop personalization\" group from syncing to and from this PC. This turns off and disables the \"desktop personalization\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"desktop personalization\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn desktop personalization syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"desktop personalization\" group is on by default and configurable by the user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disabledesktopthemesettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_checkbox_useroverride","displayName":"Allow users to turn \"desktop personalization\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync","displayName":"Do not sync personalize","description":"Prevent the \"personalize\" group from syncing to and from this PC. This turns off and disables the \"personalize\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"personalize\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn personalize syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"personalize\" group is on by default and configurable by the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablepersonalizationsettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"personalize\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync","displayName":"Do not sync","description":"Prevent syncing to and from this PC. This turns off and disables the \"sync your settings\" switch on the \"sync your settings\" page in PC Settings.\r\n\r\nIf you enable this policy setting, \"sync your settings\" will be turned off, and none of the \"sync your setting\" groups will be synced on this PC.\r\n\r\nUse the option \"Allow users to turn syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, \"sync your settings\" is on by default and configurable by the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablesettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_checkbox_useroverride","displayName":"Allow users to turn syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync","displayName":"Do not sync start settings","description":"\r\n Prevent the \"Start layout\" group from syncing to and from this PC. This turns off and disables the \"Start layout\" group on the \"sync your settings\" page in PC settings.\r\n\r\n If you enable this policy setting, the \"Start layout\" group will not be synced.\r\n\r\n Use the option \"Allow users to turn start syncing on\" so that syncing is turned off by default but not disabled.\r\n\r\n If you do not set or disable this setting, syncing of the \"Start layout\" group is on by default and configurable by the user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablestartlayoutsettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"start layout\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesynconpaidnetwork","displayName":"Do not sync on metered connections","description":"Prevent syncing to and from this PC when on metered Internet connections. This turns off and disables \"sync your settings on metered connections\" switch on the \"sync your settings\" page in PC Settings.\r\n\r\nIf you enable this policy setting, syncing on metered connections will be turned off, and no syncing will take place when this PC is on a metered connection.\r\n\r\nIf you do not set or disable this setting, syncing on metered connections is configurable by the user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablesynconpaidnetwork"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesynconpaidnetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesynconpaidnetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablewindowssettingsync","displayName":"Do not sync other Windows settings","description":"Prevent the \"Other Windows settings\" group from syncing to and from this PC. This turns off and disables the \"Other Windows settings\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"Other Windows settings\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn other Windows settings syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"Other Windows settings\" group is on by default and configurable by the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablewindowssettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablewindowssettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablewindowssettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablewindowssettingsync_checkbox_useroverride","displayName":"Allow users to turn \"other Windows settings\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablewindowssettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablewindowssettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sharing_disablehomegroup","displayName":"Prevent the computer from joining a homegroup","description":"This policy setting specifies whether users can add computers to a homegroup. By default, users can add their computer to a homegroup on a private network.\r\n\r\nIf you enable this policy setting, users cannot add computers to a homegroup. This policy setting does not affect other network sharing features.\r\n\r\nIf you disable or do not configure this policy setting, users can add computers to a homegroup. However, data on a domain-joined computer is not shared with the homegroup.\r\n\r\nThis policy setting is not configured by default.\r\n\r\nYou must restart the computer for this policy setting to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sharing#admx-sharing-disablehomegroup"],"categoryId":"d0e46713-238c-42b7-a996-653cf952c367","categoryName":"Home Group","options":[{"id":"device_vendor_msft_policy_config_admx_sharing_disablehomegroup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sharing_disablehomegroup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowcertificateswithnoeku","displayName":"Allow certificates with no extended key usage certificate attribute","description":"This policy setting lets you allow certificates without an Extended Key Usage (EKU) set to be used for logon.\r\n\r\nIn versions of Windows prior to Windows Vista, smart card certificates that are used for logon require an enhanced key usage (EKU) extension with a smart card logon object identifier. This policy setting can be used to modify that restriction.\r\n\r\nIf you enable this policy setting, certificates with the following attributes can also be used to log on with a smart card:\r\n- Certificates with no EKU\r\n- Certificates with an All Purpose EKU\r\n- Certificates with a Client Authentication EKU\r\n\r\nIf you disable or do not configure this policy setting, only certificates that contain the smart card logon object identifier can be used to log on with a smart card.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowcertificateswithnoeku"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowcertificateswithnoeku_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowcertificateswithnoeku_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowintegratedunblock","displayName":"Allow Integrated Unblock screen to be displayed at the time of logon","description":"This policy setting lets you determine whether the integrated unblock feature will be available in the logon User Interface (UI).\r\n\r\nIn order to use the integrated unblock feature your smart card must support this feature. Please check with your hardware manufacturer to see if your smart card supports this feature.\r\n\r\nIf you enable this policy setting, the integrated unblock feature will be available.\r\n\r\nIf you disable or do not configure this policy setting then the integrated unblock feature will not be available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowintegratedunblock"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowintegratedunblock_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowintegratedunblock_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowsignatureonlykeys","displayName":"Allow signature keys valid for Logon","description":"This policy setting lets you allow signature key-based certificates to be enumerated and available for logon.\r\n\r\nIf you enable this policy setting then any certificates available on the smart card with a signature only key will be listed on the logon screen.\r\n\r\nIf you disable or do not configure this policy setting, any available smart card signature key-based certificates will not be listed on the logon screen.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowsignatureonlykeys"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowsignatureonlykeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowsignatureonlykeys_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowtimeinvalidcertificates","displayName":"Allow time invalid certificates","description":"This policy setting permits those certificates to be displayed for logon that are either expired or not yet valid.\r\n\r\nUnder previous versions of Microsoft Windows, certificates were required to contain a valid time and not be expired. The certificate must still be accepted by the domain controller in order to be used. This setting only controls the displaying of the certificate on the client machine. \r\n\r\nIf you enable this policy setting certificates will be listed on the logon screen regardless of whether they have an invalid time or their time validity has expired.\r\n\r\nIf you disable or do not configure this policy setting, certificates which are expired or not yet valid will not be listed on the logon screen.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowtimeinvalidcertificates"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowtimeinvalidcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowtimeinvalidcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_certpropenabledstring","displayName":"Turn on certificate propagation from smart card","description":"This policy setting allows you to manage the certificate propagation that occurs when a smart card is inserted.\r\n\r\nIf you enable or do not configure this policy setting then certificate propagation will occur when you insert your smart card.\r\n\r\nIf you disable this policy setting, certificate propagation will not occur and the certificates will not be made available to applications such as Outlook.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-certpropenabledstring"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_certpropenabledstring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certpropenabledstring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring","displayName":"Configure root certificate clean up","description":"This policy setting allows you to manage the clean up behavior of root certificates. If you enable this policy setting then root certificate cleanup will occur according to the option selected. If you disable or do not configure this setting then root certificate clean up will occur on log off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-certproprootcleanupstring"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels","displayName":"Root certificate clean up options","description":null,"helpText":"","infoUrls":[],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels_0","displayName":"No cleanup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels_1","displayName":"Clean up certificates on smart card removal","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels_2","displayName":"Clean up certificates on log off","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootenabledstring","displayName":"Turn on root certificate propagation from smart card","description":"This policy setting allows you to manage the root certificate propagation that occurs when a smart card is inserted.\r\n\r\nIf you enable or do not configure this policy setting then root certificate propagation will occur when you insert your smart card. Note: For this policy setting to work the following policy setting must also be enabled: Turn on certificate propagation from smart card.\r\n\r\nIf you disable this policy setting then root certificates will not be propagated from the smart card.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-certproprootenabledstring"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootenabledstring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootenabledstring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_disallowplaintextpin","displayName":"Prevent plaintext PINs from being returned by Credential Manager","description":"This policy setting prevents plaintext PINs from being returned by Credential Manager. \r\n\r\nIf you enable this policy setting, Credential Manager does not return a plaintext PIN. \r\n\r\nIf you disable or do not configure this policy setting, plaintext PINs can be returned by Credential Manager.\r\n\r\nNote: Enabling this policy setting could prevent certain smart cards from working on Windows. Please consult your smart card manufacturer to find out whether you will be affected by this policy setting.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-disallowplaintextpin"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_disallowplaintextpin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_disallowplaintextpin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_enumerateecccerts","displayName":"Allow ECC certificates to be used for logon and authentication","description":"This policy setting allows you to control whether elliptic curve cryptography (ECC) certificates on a smart card can be used to log on to a domain.\r\n\r\nIf you enable this policy setting, ECC certificates on a smart card can be used to log on to a domain.\r\n\r\nIf you disable or do not configure this policy setting, ECC certificates on a smart card cannot be used to log on to a domain. \r\n\r\nNote: This policy setting only affects a user's ability to log on to a domain. ECC certificates on a smart card that are used for other applications, such as document signing, are not affected by this policy setting. \r\nNote: If you use an ECDSA key to log on, you must also have an associated ECDH key to permit logons when you are not connected to the network.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-enumerateecccerts"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_enumerateecccerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_enumerateecccerts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_filterduplicatecerts","displayName":"Filter duplicate logon certificates","description":"This policy settings lets you configure if all your valid logon certificates are displayed.\r\n\r\nDuring the certificate renewal period, a user can have multiple valid logon certificates issued from the same certificate template. This can cause confusion as to which certificate to select for logon. The common case for this behavior is when a certificate is renewed and the old one has not yet expired. Two certificates are determined to be the same if they are issued from the same template with the same major version and they are for the same user (determined by their UPN). \r\n \r\nIf there are two or more of the \"same\" certificate on a smart card and this policy is enabled then the certificate that is used for logon on Windows 2000, Windows XP, and Windows 2003 Server will be shown, otherwise the the certificate with the expiration time furthest in the future will be shown. Note: This setting will be applied after the following policy: \"Allow time invalid certificates\"\r\n\r\nIf you enable or do not configure this policy setting, filtering will take place.\r\n\r\nIf you disable this policy setting, no filtering will take place.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-filterduplicatecerts"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_filterduplicatecerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_filterduplicatecerts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_forcereadingallcertificates","displayName":"Force the reading of all certificates from the smart card","description":"This policy setting allows you to manage the reading of all certificates from the smart card for logon.\r\n\r\nDuring logon Windows will by default only read the default certificate from the smart card unless it supports retrieval of all certificates in a single call. This setting forces Windows to read all the certificates from the card. This can introduce a significant performance decrease in certain situations. Please contact your smart card vendor to determine if your smart card and associated CSP supports the required behavior.\r\n\r\nIf you enable this setting, then Windows will attempt to read all certificates from the smart card regardless of the feature set of the CSP.\r\n\r\nIf you disable or do not configure this setting, Windows will only attempt to read the default certificate from those cards that do not support retrieval of all certificates in a single call. Certificates other than the default will not be available for logon.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-forcereadingallcertificates"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_forcereadingallcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_forcereadingallcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_integratedunblockpromptstring","displayName":"Display string when smart card is blocked","description":"This policy setting allows you to manage the displayed message when a smart card is blocked.\r\n\r\nIf you enable this policy setting, the specified message will be displayed to the user when the smart card is blocked. Note: The following policy setting must be enabled - Allow Integrated Unblock screen to be displayed at the time of logon.\r\n\r\nIf you disable or do not configure this policy setting, the default message will be displayed to the user when the smart card is blocked, if the integrated unblock feature is enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-integratedunblockpromptstring"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_integratedunblockpromptstring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_integratedunblockpromptstring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_integratedunblockpromptstring_integratedunblockpromptstring","displayName":"Display string when smart card is blocked","description":null,"helpText":"","infoUrls":[],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_reversesubject","displayName":"Reverse the subject name stored in a certificate when displaying","description":"This policy setting lets you reverse the subject name from how it is stored in the certificate when displaying it during logon. \r\n \r\nBy default the user principal name (UPN) is displayed in addition to the common name to help users distinguish one certificate from another. For example, if the certificate subject was CN=User1, OU=Users, DN=example, DN=com and had an UPN of user1@example.com then \"User1\" will be displayed along with \"user1@example.com.\" If the UPN is not present then the entire subject name will be displayed. This setting controls the appearance of that subject name and might need to be adjusted per organization.\r\n\r\nIf you enable this policy setting or do not configure this setting, then the subject name will be reversed. \r\n\r\nIf you disable , the subject name will be displayed as it appears in the certificate.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-reversesubject"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_reversesubject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_reversesubject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_scpnpenabled","displayName":"Turn on Smart Card Plug and Play service","description":"This policy setting allows you to control whether Smart Card Plug and Play is enabled.\r\n\r\nIf you enable or do not configure this policy setting, Smart Card Plug and Play will be enabled and the system will attempt to install a Smart Card device driver when a card is inserted in a Smart Card Reader for the first time.\r\n\r\nIf you disable this policy setting, Smart Card Plug and Play will be disabled and a device driver will not be installed when a card is inserted in a Smart Card Reader.\r\n\r\nNote: This policy setting is applied only for smart cards that have passed the Windows Hardware Quality Labs (WHQL) testing process.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-scpnpenabled"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_scpnpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_scpnpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_scpnpnotification","displayName":"Notify user of successful smart card driver installation","description":"This policy setting allows you to control whether a confirmation message is displayed when a smart card device driver is installed.\r\n\r\nIf you enable or do not configure this policy setting, a confirmation message will be displayed when a smart card device driver is installed.\r\n\r\nIf you disable this policy setting, a confirmation message will not be displayed when a smart card device driver is installed.\r\n\r\nNote: This policy setting is applied only for smart cards that have passed the Windows Hardware Quality Labs (WHQL) testing process.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-scpnpnotification"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_scpnpnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_scpnpnotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_x509hintsneeded","displayName":"Allow user name hint","description":"This policy setting lets you determine whether an optional field will be displayed during logon and elevation that allows a user to enter his or her user name or user name and domain, thereby associating a certificate with that user.\r\n\r\nIf you enable this policy setting then an optional field that allows a user to enter their user name or user name and domain will be displayed.\r\n\r\nIf you disable or do not configure this policy setting, an optional field that allows users to enter their user name or user name and domain will not be displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-x509hintsneeded"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_x509hintsneeded_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_x509hintsneeded_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_communities","displayName":"Specify communities","description":"This policy setting configures a list of the communities defined to the Simple Network Management Protocol (SNMP) service.\r\n\r\nSNMP is a protocol designed to give a user the capability to remotely manage a computer network, by polling and setting terminal values and monitoring network events.\r\n\r\nA valid community is a community recognized by the SNMP service, while a community is a group of hosts (servers, workstations, hubs, and routers) that are administered together by SNMP. The SNMP service is a managed network node that receives SNMP packets from the network.\r\n\r\nIf you enable this policy setting, the SNMP agent only accepts requests from management systems within the communities it recognizes, and only SNMP Read operation is allowed for the community.\r\n\r\nIf you disable or do not configure this policy setting, the SNMP service takes the Valid Communities configured on the local computer instead.\r\n\r\nBest practice: For security purposes, it is recommended to restrict the HKLM\\SOFTWARE\\Policies\\SNMP\\Parameters\\ValidCommunities key to allow only the local admin group full control.\r\n\r\nNote: It is good practice to use a cryptic community name.\r\n\r\nNote: This policy setting has no effect if the SNMP agent is not installed on the client computer.\r\n\r\nAlso, see the other two SNMP settings: \"Specify permitted managers\" and \"Specify trap configuration\".\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-snmp#admx-snmp-snmp-communities"],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":[{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_communities_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_communities_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_communities_snmp_communitieslistbox","displayName":"Communities","description":null,"helpText":"","infoUrls":[],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":null},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers","displayName":"Specify permitted managers","description":"This policy setting determines the permitted list of hosts that can submit a query to the Simple Network Management (SNMP) agent running on the client computer.\r\n\r\nSimple Network Management Protocol is a protocol designed to give a user the capability to remotely manage a computer network by polling and setting terminal values and monitoring network events.\r\n\r\nThe manager is located on the host computer on the network. The manager's role is to poll the agents for certain requested information.\r\n\r\nIf you enable this policy setting, the SNMP agent only accepts requests from the list of permitted managers that you configure using this setting.\r\n\r\nIf you disable or do not configure this policy setting, SNMP service takes the permitted managers configured on the local computer instead.\r\n\r\nBest practice: For security purposes, it is recommended to restrict the HKLM\\SOFTWARE\\Policies\\SNMP\\Parameters\\PermittedManagers key to allow only the local admin group full control.\r\n\r\nNote: This policy setting has no effect if the SNMP agent is not installed on the client computer.\r\n\r\nAlso, see the other two SNMP policy settings: \"Specify trap configuration\" and \"Specify Community Name\".\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-snmp#admx-snmp-snmp-permittedmanagers"],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":[{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers_snmp_permittedmanagerslistbox","displayName":"Permitted managers","description":null,"helpText":"","infoUrls":[],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":null},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_traps_public","displayName":"Specify traps for public community","description":"This policy setting allows trap configuration for the Simple Network Management Protocol (SNMP) agent.\r\n\r\nSimple Network Management Protocol is a protocol designed to give a user the capability to remotely manage a computer network by polling and setting terminal values and monitoring network events.\r\n\r\nThis policy setting allows you to configure the name of the hosts that receive trap messages for the community sent by the SNMP service. A trap message is an alert or significant event that allows the SNMP agent to notify management systems asynchronously.\r\n\r\nIf you enable this policy setting, the SNMP service sends trap messages to the hosts within the \"public\" community.\r\n\r\nIf you disable or do not configure this policy setting, the SNMP service takes the trap configuration configured on the local computer instead.\r\n\r\nNote: This setting has no effect if the SNMP agent is not installed on the client computer.\r\n\r\nAlso, see the other two SNMP settings: \"Specify permitted managers\" and \"Specify Community Name\".\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-snmp#admx-snmp-snmp-traps-public"],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":[{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_traps_public_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_traps_public_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_traps_public_snmp_traps_publiclistbox","displayName":"Trap configuration","description":null,"helpText":"","infoUrls":[],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":null},{"id":"device_vendor_msft_policy_config_admx_soundrec_soundrec_diableapplication_titletext_2","displayName":"Do not allow Sound Recorder to run","description":"Specifies whether Sound Recorder can run.\r\n\r\nSound Recorder is a feature of Microsoft Windows Vista that can be used to record sound from an audio input device where the recorded sound is encoded and saved as an audio file.\r\n\r\nIf you enable this policy setting, Sound Recorder will not run.\r\n\r\nIf you disable or do not configure this policy setting, Sound Recorder can be run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-soundrec#admx-soundrec-soundrec-diableapplication-titletext-2"],"categoryId":"088b8d8d-5f3f-4979-aa18-b3c4b2616a24","categoryName":"Sound Recorder","options":[{"id":"device_vendor_msft_policy_config_admx_soundrec_soundrec_diableapplication_titletext_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_soundrec_soundrec_diableapplication_titletext_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration","displayName":"Customize message for Access Denied errors","description":"This policy setting specifies the message that users see when they are denied access to a file or folder. You can customize the Access Denied message to include additional text and links. You can also provide users with the ability to send an email to request access to the file or folder to which they were denied access.\r\n\r\nIf you enable this policy setting, users receive a customized Access Denied message from the file servers on which this policy setting is applied. \r\n\r\nIf you disable this policy setting, users see a standard Access Denied message that doesn't provide any of the functionality controlled by this policy setting, regardless of the file server configuration.\r\n\r\nIf you do not configure this policy setting, users see a standard Access Denied message unless the file server is configured to display the customized Access Denied message. By default, users see the standard Access Denied message.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-srmfci#admx-srmfci-accessdeniedconfiguration"],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_additonalemailtotext","displayName":"Additional recipients:","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_allowemailrequestscheck","displayName":"Enable users to request assistance","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_allowemailrequestscheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_allowemailrequestscheck_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_emailmessagetext","displayName":"Add the following text to the end of the email:","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_errormessagetext","displayName":"Display the following message to users who are denied access:","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_generatelogcheck","displayName":"Log emails in Application and Services event log","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_generatelogcheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_generatelogcheck_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includedeviceclaimscheck","displayName":"Include device claims","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includedeviceclaimscheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includedeviceclaimscheck_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includeuserclaimscheck","displayName":"Include user claims","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includeuserclaimscheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includeuserclaimscheck_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_putadminontocheck","displayName":"File server administrator","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_putadminontocheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_putadminontocheck_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_putdataownerontocheck","displayName":"Folder owner","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_putdataownerontocheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_putdataownerontocheck_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist","displayName":"File Classification Infrastructure: Specify classification properties list","description":"This policy setting controls which set of properties is available for classifying files on affected computers.\r\n\r\nAdministrators can define the properties for the organization by using Active Directory Domain Services (AD DS), and then group these properties into lists. Administrators can supplement these properties on individual file servers by using File Classification Infrastructure, which is part of the File Server Resource Manager role service.\r\n\r\nIf you enable this policy setting, you can select which list of properties is available for classification on the affected computers. \r\n\r\nIf you disable or do not configure this policy setting, the Global Resource Property List in AD DS provides the default set of properties.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-srmfci#admx-srmfci-centralclassificationlist"],"categoryId":"dd9a3dad-5851-4899-a5c1-c23318986846","categoryName":"File Classification Infrastructure","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist_centralclassificationlisttextelement","displayName":"Classification properties list:","description":null,"helpText":"","infoUrls":[],"categoryId":"dd9a3dad-5851-4899-a5c1-c23318986846","categoryName":"File Classification Infrastructure","options":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_enablemanualux","displayName":"File Classification Infrastructure: Display Classification tab in File Explorer","description":"This policy setting controls whether the Classification tab is displayed in the Properties dialog box in File Explorer.\r\n\r\nThe Classification tab enables users to manually classify files by selecting properties from a list. Administrators can define the properties for the organization by using Group Policy, and supplement these with properties defined on individual file servers by using File Classification Infrastructure, which is part of the File Server Resource Manager role service.\r\n\r\nIf you enable this policy setting, the Classification tab is displayed.\r\n\r\nIf you disable or do not configure this policy setting, the Classification tab is hidden.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-srmfci#admx-srmfci-enablemanualux"],"categoryId":"dd9a3dad-5851-4899-a5c1-c23318986846","categoryName":"File Classification Infrastructure","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_enablemanualux_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_enablemanualux_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_enableshellaccesscheck","displayName":"Enable access-denied assistance on client for all file types","description":"This Group Policy Setting should be set on Windows clients to enable access-denied assistance for all file types\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-srmfci#admx-srmfci-enableshellaccesscheck"],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_enableshellaccesscheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_enableshellaccesscheck_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_hidepoweroptions","displayName":"Remove and prevent access to the Shut Down, Restart, Sleep, and Hibernate commands","description":"This policy setting prevents users from performing the following commands from the Windows security screen, the logon screen, and the Start menu: Shut Down, Restart, Sleep, and Hibernate. This policy setting does not prevent users from running Windows-based programs that perform these functions.\r\n\r\nIf you enable this policy setting, the shutdown, restart, sleep, and hibernate commands are removed from the Start menu. The Power button is also removed from the Windows Security screen, which appears when you press CTRL+ALT+DELETE, and from the logon screen.\r\n\r\nIf you disable or do not configure this policy setting, the Power button and the Shut Down, Restart, Sleep, and Hibernate commands are available on the Start menu. The Power button on the Windows Security and logon screens is also available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-hidepoweroptions"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_hidepoweroptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_hidepoweroptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_nochangestartmenu","displayName":"Prevent users from customizing their Start Screen","description":"This policy setting allows you to prevent users from changing their Start screen layout.\n\nIf you enable this setting, you will prevent a user from selecting an app, resizing a tile, pinning/unpinning a tile or a secondary tile, entering the customize mode and rearranging tiles within Start and Apps.\n\nIf you disable or do not configure this setting, you will allow a user to select an app, resize a tile, pin/unpin a tile or a secondary tile, enter the customize mode and rearrange tiles within Start and Apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nochangestartmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nochangestartmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nochangestartmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist","displayName":"Remove All Programs list from the Start menu","description":"If you enable this setting, the Start Menu will either collapse or remove the all apps list from the Start menu.\r\n\r\nSelecting \"Collapse\" will not display the app list next to the pinned tiles in Start. An \"All apps\" button will be displayed on Start to open the all apps list. This is equivalent to setting the \"Show app list in Start\" in Settings to Off.\r\n\r\nSelecting \"Collapse and disable setting\" will do the same as the collapse option and disable the \"Show app list in Start menu\" in Settings, so users cannot turn it to On.\r\n\r\nSelecting \"Remove and disable setting\" will remove the all apps list from Start and disable the \"Show app list in Start menu\" in Settings, so users cannot turn it to On. Select this option for compatibility with earlier versions of Windows.\r\n\r\nIf you disable or do not configure this setting, the all apps list will be visible by default, and the user can change \"Show app list in Start\" in Settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nomoreprogramslist"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown","displayName":"Choose one of the following actions","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_0","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_3","displayName":"Collapse","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_2","displayName":"Collapse and disable setting","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_1","displayName":"Remove and disable setting","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_norun","displayName":"Remove Run menu from Start Menu","description":"Allows you to remove the Run command from the Start menu, Internet Explorer, and Task Manager.\n\nIf you enable this setting, the following changes occur:\n\n(1) The Run command is removed from the Start menu.\n\n(2) The New Task (Run) command is removed from Task Manager.\n\n(3) The user will be blocked from entering the following into the Internet Explorer Address Bar:\n\n--- A UNC path: \\\\\\\n\n---Accessing local drives: e.g., C:\n\n--- Accessing local folders: e.g., \\temp>\n\nAlso, users with extended keyboards will no longer be able to display the Run dialog box by pressing the Application key (the key with the Windows logo) + R.\n\nIf you disable or do not configure this setting, users will be able to access the Run command in the Start menu and in Task Manager and use the Internet Explorer Address Bar.\n\n\n\nNote:This setting affects the specified interface only. It does not prevent users from using other methods to run programs.\n\nNote: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-norun"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_norun_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_norun_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_nosettaskbar","displayName":"Prevent changes to Taskbar and Start Menu Settings","description":"This policy setting allows you to prevent changes to Taskbar and Start Menu Settings.\n\nIf you enable this policy setting, The user will be prevented from opening the Taskbar Properties dialog box.\n\nIf the user right-clicks the taskbar and then clicks Properties, a message appears explaining that a setting prevents the action.\n\nIf you disable or do not configure this policy setting, the Taskbar and Start Menu items are available from Settings on the Start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosettaskbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nosettaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nosettaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_notraycontextmenu","displayName":"Remove access to the context menus for the taskbar","description":"This policy setting allows you to remove access to the context menus for the taskbar.\n\nIf you enable this policy setting, the menus that appear when you right-click the taskbar and items on the taskbar are hidden, such as the Start button, the clock, and the taskbar buttons.\n\nIf you disable or do not configure this policy setting, the context menus for the taskbar are available.\n\nThis policy setting does not prevent users from using other methods to issue the commands that appear on these menus.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-notraycontextmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_notraycontextmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_notraycontextmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart","displayName":"Prevent users from uninstalling applications from Start","description":"If you enable this setting, users cannot uninstall apps from Start.\n\nIf you disable this setting or do not configure it, users can access the uninstall command from Start","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nouninstallfromstart"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled","displayName":"Pin Apps to Start when installed","description":"This policy setting allows pinning apps to Start by default, when they are included by AppID on the list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-startpinappswheninstalled"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_startpinappswheninstalled_name","displayName":"Add AppIDs to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_systemrestore_sr_disableconfig","displayName":"Turn off Configuration","description":"Allows you to disable System Restore configuration through System Protection.\r\n\r\nThis policy setting allows you to turn off System Restore configuration through System Protection.\r\n\r\nSystem Restore enables users, in the event of a problem, to restore their computers to a previous state without losing personal data files. The behavior of this policy setting depends on the \"Turn off System Restore\" policy setting.\r\n\r\nIf you enable this policy setting, the option to configure System Restore through System Protection is disabled.\r\n\r\nIf you disable or do not configure this policy setting, users can change the System Restore settings through System Protection. \r\n\r\nAlso, see the \"Turn off System Restore\" policy setting. If the \"Turn off System Restore\" policy setting is enabled, the \"Turn off System Restore configuration\" policy setting is overwritten.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-systemrestore#admx-systemrestore-sr-disableconfig"],"categoryId":"5c9a2f21-d3a8-4295-a803-e0535aa29489","categoryName":"System Restore","options":[{"id":"device_vendor_msft_policy_config_admx_systemrestore_sr_disableconfig_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_systemrestore_sr_disableconfig_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_autocomplete_2","displayName":"Turn off AutoComplete integration with Input Panel","description":"Turns off the integration of application auto complete lists with Tablet PC Input Panel in applications where this behavior is available.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, application auto complete lists will never appear next to Input Panel. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, application auto complete lists will appear next to Input Panel in applications where the functionality is available. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, application auto complete lists will appear next to Input Panel in applications where the functionality is available. Users will be able to configure this setting on the Text completion tab in Input Panel Options.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-autocomplete-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_autocomplete_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_autocomplete_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_edgetarget_2","displayName":"Prevent Input Panel tab from appearing","description":"Prevents Input Panel tab from appearing on the edge of the Tablet PC screen.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel tab will not appear on the edge of the Tablet PC screen. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel tab will appear on the edge of the Tablet PC screen. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel tab will appear on the edge of the Tablet PC screen. Users will be able to configure this setting on the Opening tab in Input Panel Options.\r\n\r\nCaution: If you enable both the “Prevent Input Panel from appearing next to text entry areas” policy and the “Prevent Input Panel tab from appearing” policy, and disable the “Show Input Panel taskbar icon” policy, the user will then have no way to access Input Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-edgetarget-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_edgetarget_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_edgetarget_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_2","displayName":"For tablet pen input, don’t show the Input Panel icon","description":"Prevents the Tablet PC Input Panel icon from appearing next to any text entry area in applications where this behavior is available. This policy applies only when using a tablet pen as an input device.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel will never appear next to text entry areas when using a tablet pen as an input device. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel will appear next to any text entry area in applications where this behavior is available. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel will appear next to text entry areas in applications where this behavior is available. Users will be able to configure this setting on the Opening tab in Input Panel Options.\r\n\r\nCaution: If you enable both the “Prevent Input Panel from appearing next to text entry areas” policy and the “Prevent Input Panel tab from appearing” policy, and disable the “Show Input Panel taskbar icon” policy, the user will then have no way to access Input Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-iptiptarget-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptouchtarget_2","displayName":"For touch input, don’t show the Input Panel icon","description":"Prevents the Tablet PC Input Panel icon from appearing next to any text entry area in applications where this behavior is available. This policy applies only when a user is using touch input.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel will never appear next to any text entry area when a user is using touch input. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel will appear next to text entry areas in applications where this behavior is available. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel will appear next to text entry areas in applications where this behavior is available. Users will be able to configure this setting on the Opening tab in Input Panel Options.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-iptiptouchtarget-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptouchtarget_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptouchtarget_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2","displayName":"Turn off password security in Input Panel","description":"Adjusts password security settings in Touch Keyboard and Handwriting panel (a.k.a. Tablet PC Input Panel in Windows 7 and Windows Vista). These settings include using the on-screen keyboard by default, preventing users from switching to another Input Panel skin (the writing pad or character pad), and not showing what keys are tapped when entering a password.\r\n\r\nTouch Keyboard and Handwriting panel enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy and choose “Low” from the drop-down box, password security is set to “Low.” At this setting, all password security settings are turned off. Users will not be able to configure this setting in the Input Panel Options dialog box. \r\n\r\nIf you enable this policy and choose “Medium-Low” from the drop-down box, password security is set to “Medium-Low.” At this setting, when users enter passwords from Input Panel they use the on-screen keyboard by default, skin switching is allowed, and Input Panel displays the cursor and which keys are tapped. Users will not be able to configure this setting in the Input Panel Options dialog box. \r\n\r\nIf you enable this policy and choose “Medium” from the drop-down box, password security is set to “Medium.” At this setting, when users enter passwords from Input Panel they use the on-screen keyboard by default, skin switching is not allowed, and Input Panel displays the cursor and which keys are tapped. Users will not be able to configure this setting in the Input Panel Options dialog box. \r\n\r\nIf you enable this policy and choose to “Medium-High” from the drop-down box, password security is set to “Medium-High.” At this setting, when users enter passwords from Input Panel they use the on-screen keyboard by default, skin switching is allowed, and Input Panel does not display the cursor or which keys are tapped. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you enable this policy and choose “High” from the drop-down box, password security is set to “High.” At this setting, when users enter passwords from Input Panel they use the on-screen keyboard by default, skin switching is not allowed, and Input Panel does not display the cursor or which keys are tapped. Users will not be able to configure this setting in the Input Panel Options dialog box. \r\n\r\nIf you disable this policy, password security is set to “Medium-High.” At this setting, when users enter passwords from Input Panel they use the on-screen keyboard by default, skin switching is allowed, and Input Panel does not display the cursor or which keys are tapped. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n \r\nIf you do not configure this policy, password security is set to “Medium-High” by default. At this setting, when users enter passwords from Input Panel they use the on-screen keyboard by default, skin switching is allowed, and Input Panel does not display the cursor or which keys are tapped. Users will be able to configure this setting on the Advanced tab in Input Panel Options in Windows 7 and Windows Vista.\r\n\r\nCaution: If you lower password security settings, people who can see the user’s screen might be able to see their passwords.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-passwordsecurity-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity","displayName":"Turn off password security in Input Panel","description":null,"helpText":"","infoUrls":[],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_1","displayName":"Low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_3","displayName":"Medium","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_4","displayName":"Medium High","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_5","displayName":"High","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_prediction_2","displayName":"Disable text prediction","description":"Prevents the Touch Keyboard and Handwriting panel (a.k.a. Tablet PC Input Panel in Windows 7 and Windows Vista) from providing text prediction suggestions. This policy applies for both the on-screen keyboard and the handwriting tab when the feature is available for the current input area and input language.\r\n\r\nTouch Keyboard and Handwriting panel enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel will not provide text prediction suggestions. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel will provide text prediction suggestions. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel will provide text prediction suggestions. Users will be able to configure this setting on the Text Completion tab in Input Panel Options in Windows 7 and Windows Vista.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-prediction-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_prediction_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_prediction_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_rarechar_2","displayName":"Include rarely used Chinese, Kanji, or Hanja characters","description":"Includes rarely used Chinese, Kanji, and Hanja characters when handwriting is converted to typed text. This policy applies only to the use of the Microsoft recognizers for Chinese (Simplified), Chinese (Traditional), Japanese, and Korean. This setting appears in Input Panel Options (in Windows 7 and Windows Vista only) only when these input languages or keyboards are installed. \r\n\r\nTouch Keyboard and Handwriting panel (a.k.a. Tablet PC Input Panel in Windows 7 and Windows Vista) enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, rarely used Chinese, Kanji, and Hanja characters will be included in recognition results when handwriting is converted to typed text. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, rarely used Chinese, Kanji, and Hanja characters will not be included in recognition results when handwriting is converted to typed text. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, rarely used Chinese, Kanji, and Hanja characters will not be included in recognition results when handwriting is converted to typed text. Users will be able to configure this setting on the Ink to text conversion tab in Input Panel Options (in Windows 7 and Windows Vista).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-rarechar-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_rarechar_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_rarechar_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2","displayName":"Turn off tolerant and Z-shaped scratch-out gestures","description":"\r\n Turns off both the more tolerant scratch-out gestures that were added in Windows Vista and the Z-shaped scratch-out gesture that was available in Microsoft Windows XP Tablet PC Edition.\r\n\r\n The tolerant gestures let users scratch out ink in Input Panel by using strikethrough and other scratch-out gesture shapes.\r\n\r\n Tablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\n If you enable this policy and choose “All” from the drop-down menu, no scratch-out gestures will be available in Input Panel. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\n If you enable this policy and choose “Tolerant,\" users will be able to use the Z-shaped scratch-out gesture that was available in Microsoft Windows XP Tablet PC Edition. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\n If you enable this policy and choose “None,” users will be able to use both the tolerant scratch-out gestures and the Z-shaped scratch-out gesture. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\n If you disable this policy, users will be able to use both the tolerant scratch-out gestures and the Z-shaped scratch-out gesture. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\n If you do not configure this policy, users will be able to use both the tolerant scratch-out gestures and the Z-shaped scratch-out gesture. Users will be able to configure this setting on the Gestures tab in Input Panel Options.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-scratchout-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout","displayName":"Turn off tolerant and Z-shaped scratch-out gestures","description":null,"helpText":"","infoUrls":[],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout_1","displayName":"All","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout_2","displayName":"Tolerant","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout_3","displayName":"None","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disableinkball_2","displayName":"Do not allow Inkball to run","description":"Prevents start of InkBall game.\r\n\r\nIf you enable this policy, the InkBall game will not run.\r\n\r\nIf you disable this policy, the InkBall game will run.\r\n\r\nIf you do not configure this policy, the InkBall game will run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-disableinkball-2"],"categoryId":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","categoryName":"Accessories","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_disableinkball_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disableinkball_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablejournal_2","displayName":"Do not allow Windows Journal to be run","description":"Prevents start of Windows Journal.\r\n\r\nIf you enable this policy, the Windows Journal accessory will not run.\r\n\r\nIf you disable this policy, the Windows Journal accessory will run.\r\n\r\nIf you do not configure this policy, the Windows Journal accessory will run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-disablejournal-2"],"categoryId":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","categoryName":"Accessories","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablejournal_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablejournal_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablenotewriterprinting_2","displayName":"Do not allow printing to Journal Note Writer","description":"Prevents printing to Journal Note Writer.\r\n\r\nIf you enable this policy, the Journal Note Writer printer driver will not allow printing to it. It will remain displayed in the list of available printers, but attempts to print to it will fail.\r\n\r\nIf you disable this policy, you will be able to use this feature to print to a Journal Note.\r\n\r\nIf you do not configure this policy, users will be able to use this feature to print to a Journal Note.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-disablenotewriterprinting-2"],"categoryId":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","categoryName":"Accessories","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablenotewriterprinting_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablenotewriterprinting_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablesnippingtool_2","displayName":"Do not allow Snipping Tool to run","description":"Prevents the snipping tool from running.\r\n\r\nIf you enable this policy setting, the Snipping Tool will not run.\r\n\r\nIf you disable this policy setting, the Snipping Tool will run.\r\n\r\nIf you do not configure this policy setting, the Snipping Tool will run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-disablesnippingtool-2"],"categoryId":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","categoryName":"Accessories","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablesnippingtool_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablesnippingtool_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventbackescmapping_2","displayName":"Prevent Back-ESC mapping","description":"Removes the Back->ESC mapping that normally occurs when menus are visible, and for applications that subscribe to this behavior.\r\n\r\nIf you enable this policy, a button assigned to Back will not map to ESC.\r\n\r\nIf you disable this policy, Back->ESC mapping will occur.\r\n\r\nIf you do not configure this policy, Back->ESC mapping will occur.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventbackescmapping-2"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventbackescmapping_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventbackescmapping_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflicks_2","displayName":"Prevent flicks","description":"Makes pen flicks and all related features unavailable.\r\n\r\nIf you enable this policy, pen flicks and all related features are unavailable. This includes: pen flicks themselves, pen flicks training, pen flicks training triggers in Internet Explorer, the pen flicks notification and the pen flicks tray icon.\r\n\r\nIf you disable or do not configure this policy, pen flicks and related features are available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventflicks-2"],"categoryId":"b524d6e2-75bc-4409-ae3d-07605707d7ee","categoryName":"Pen UX Behaviors","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflicks_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflicks_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflickslearningmode_2","displayName":"Prevent Flicks Learning Mode","description":"Makes pen flicks learning mode unavailable.\r\n\r\nIf you enable this policy, pen flicks are still available but learning mode is not. Pen flicks are off by default and can be turned on system-wide, but cannot be restricted to learning mode applications. This means that the pen flicks training triggers in Internet Explorer are disabled and that the pen flicks notification will never be displayed. However, pen flicks, the pen flicks tray icon and pen flicks training (that can be accessed through CPL) are still available. Conceptually this policy is a subset of the Disable pen flicks policy.\r\n\r\nIf you disable or do not configure this policy, all the features described above will be available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventflickslearningmode-2"],"categoryId":"6f0e6df6-8654-4b57-b1d5-2160c5a0a54e","categoryName":"Pen Flicks Learning","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflickslearningmode_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflickslearningmode_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_2","displayName":"Prevent launch an application","description":"Prevents the user from launching an application from a Tablet PC hardware button.\r\n\r\nIf you enable this policy, applications cannot be launched from a hardware button, and \"Launch an application\" is removed from the drop down menu for configuring button actions (in the Tablet PC Control Panel buttons tab).\r\n\r\nIf you disable this policy, applications can be launched from a hardware button.\r\n\r\nIf you do not configure this policy, applications can be launched from a hardware button.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventlaunchapp-2"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventpressandhold_2","displayName":"Prevent press and hold","description":"Prevents press and hold actions on hardware buttons, so that only one action is available per button.\r\n\r\nIf you enable this policy, press and hold actions are unavailable, and the button configuration dialog will display the following text: \"Some settings are controlled by Group Policy. If a setting is unavailable, contact your system administrator.\"\r\n\r\nIf you disable this policy, press and hold actions for buttons will be available.\r\n\r\nIf you do not configure this policy, press and hold actions will be available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventpressandhold-2"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventpressandhold_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventpressandhold_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnoffbuttons_2","displayName":"Turn off hardware buttons","description":"Turns off Tablet PC hardware buttons.\r\n\r\nIf you enable this policy, no actions will occur when the buttons are pressed, and the buttons tab in Tablet PC Control Panel will be removed.\r\n\r\nIf you disable this policy, user and OEM defined button actions will occur when the buttons are pressed.\r\n\r\nIf you do not configure this policy, user and OEM defined button actions will occur when the buttons are pressed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-turnoffbuttons-2"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnoffbuttons_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnoffbuttons_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnofffeedback_2","displayName":"Turn off pen feedback","description":"Disables visual pen action feedback, except for press and hold feedback.\r\n\r\nIf you enable this policy, all visual pen action feedback is disabled except for press and hold feedback. Additionally, the mouse cursors are shown instead of the pen cursors.\r\n\r\nIf you disable or do not configure this policy, visual feedback and pen cursors will be shown unless the user disables them in Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-turnofffeedback-2"],"categoryId":"9b894b32-3697-4a83-9731-3db2a35455ad","categoryName":"Cursors","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnofffeedback_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnofffeedback_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_taskbar_disablenotificationcenter","displayName":"Remove Notifications and Action Center","description":"This policy setting removes Notifications and Action Center from the notification area on the taskbar.\n\nThe notification area is located at the far right end of the taskbar and includes icons for current notifications and the system clock.\n\nIf this setting is enabled, Notifications and Action Center is not displayed in the notification area. The user will be able to read notifications when they appear, but they won’t be able to review any notifications they miss.\n\nIf you disable or do not configure this policy setting, Notification and Security and Maintenance will be displayed on the taskbar.\n\nA reboot is required for this policy setting to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-disablenotificationcenter"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_taskbar_disablenotificationcenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_taskbar_disablenotificationcenter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_taskbar_taskbarnopinnedlist","displayName":"Remove pinned programs from the Taskbar","description":"This policy setting allows you to remove pinned programs from the taskbar.\n\nIf you enable this policy setting, pinned programs are prevented from being shown on the Taskbar. Users cannot pin programs to the Taskbar.\n\nIf you disable or do not configure this policy setting, users can pin programs so that the program shortcuts stay on the Taskbar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-taskbarnopinnedlist"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_taskbar_taskbarnopinnedlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_taskbar_taskbarnopinnedlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name","displayName":"Set 6to4 Relay Name","description":"This policy setting allows you to specify a 6to4 relay name for a 6to4 host. A 6to4 relay is used as a default gateway for IPv6 network traffic sent by the 6to4 host. The 6to4 relay name setting has no effect if 6to4 connectivity is not available on the host.\r\n\r\nIf you enable this policy setting, you can specify a relay name for a 6to4 host.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used, and you cannot specify a relay name for a 6to4 host.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-6to4-router-name"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval","displayName":"Set 6to4 Relay Name Resolution Interval","description":"This policy setting allows you to specify the interval at which the relay name is resolved. The 6to4 relay name resolution interval setting has no effect if 6to4 connectivity is not available on the host.\r\n\r\nIf you enable this policy setting, you can specify the value for the duration at which the relay name is resolved periodically.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-6to4-router-name-resolution-interval"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval_routernameresolutionintervalbox","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_routernamebox","displayName":"Enter a router or relay name:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state","displayName":"Set 6to4 State","description":"This policy setting allows you to configure 6to4, an address assignment and router-to-router automatic tunneling technology that is used to provide unicast IPv6 connectivity between IPv6 sites and hosts across the IPv4 Internet. 6to4 uses the global address prefix: 2002:WWXX:YYZZ::/48 in which the letters are a hexadecimal representation of the global IPv4 address (w.x.y.z) assigned to a site.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\nIf you enable this policy setting, you can configure 6to4 with one of the following settings:\r\n\r\nPolicy Default State: 6to4 is enabled if the host has only link-local IPv6 connectivity and a public IPv4 address. If no global IPv6 address is present and no global IPv4 address is present, the host will not have a 6to4 interface. If no global IPv6 address is present and a global IPv4 address is present, the host will have a 6to4 interface.\r\n\r\nPolicy Enabled State: If a global IPv4 address is present, the host will have a 6to4 interface. If no global IPv4 address is present, the host will not have a 6to4 interface.\r\n\r\nPolicy Disabled State: 6to4 is turned off and connectivity with 6to4 will not be available.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-6to4-state"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state_stateselect","displayName":"Select from the following states:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state_stateselect_default","displayName":"Default State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state_stateselect_enabled","displayName":"Enabled State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state_stateselect_disabled","displayName":"Disabled State","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_ip_stateless_autoconfiguration_limits_state","displayName":"Set IP Stateless Autoconfiguration Limits State","description":"This policy setting allows you to configure IP Stateless Autoconfiguration Limits.\r\n\r\nIf you enable or do not configure this policy setting, IP Stateless Autoconfiguration Limits will be enabled and system will limit the number of autoconfigured addresses and routes.\r\n\r\nIf you disable this policy setting, IP Stateless Autoconfiguration Limits will be disabled and system will not limit the number of autoconfigured addresses and routes.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-ip-stateless-autoconfiguration-limits-state"],"categoryId":"91789113-6339-4e96-8e1d-73a4dec4967f","categoryName":"Parameters","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_ip_stateless_autoconfiguration_limits_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_ip_stateless_autoconfiguration_limits_state_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate","displayName":"Set IP-HTTPS State","description":"This policy setting allows you to configure IP-HTTPS, a tunneling technology that uses the HTTPS protocol to provide IP connectivity to a remote network.\r\n\r\nIf you disable or do not configure this policy setting, the local host settings are used.\r\n\r\nIf you enable this policy setting, you can specify an IP-HTTPS server URL. You will be able to configure IP-HTTPS with one of the following settings:\r\n\r\nPolicy Default State: The IP-HTTPS interface is used when there are no other connectivity options.\r\n\r\nPolicy Enabled State: The IP-HTTPS interface is always present, even if the host has other connectivity options.\r\n\r\nPolicy Disabled State: No IP-HTTPS interfaces are present on the host.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-iphttps-clientstate"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_iphttpsclienturlbox","displayName":"Enter the IPHTTPS Url:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_stateselect","displayName":"Select Interface state from the following options:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_stateselect_0","displayName":"Default State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_stateselect_2","displayName":"Enabled State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_stateselect_3","displayName":"Disabled State","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_router_name","displayName":"Set ISATAP Router Name","description":"This policy setting allows you to specify a router name or Internet Protocol version 4 (IPv4) address for an ISATAP router.\r\n\r\nIf you enable this policy setting, you can specify a router name or IPv4 address for an ISATAP router. If you enter an IPv4 address of the ISATAP router in the text box, DNS services are not required.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-isatap-router-name"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_router_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_router_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_router_name_routernamebox","displayName":"Enter a router or relay name:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state","displayName":"Set ISATAP State","description":"This policy setting allows you to configure Intra-Site Automatic Tunnel Addressing Protocol (ISATAP), an address-to-router and host-to-host, host-to-router and router-to-host automatic tunneling technology that is used to provide unicast IPv6 connectivity between IPv6 hosts across an IPv4 intranet.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\nIf you enable this policy setting, you can configure ISATAP with one of the following settings:\r\n\r\nPolicy Default State: If the ISATAP router name is resolved successfully, the host will have ISATAP configured with a link-local address and an address for each prefix received from the ISATAP router through stateless address auto-configuration. If the ISATAP router name is not resolved successfully, ISATAP connectivity is not available on the host using the corresponding IPv4 address.\r\n\r\nPolicy Enabled State: If the ISATAP name is resolved successfully, the host will have ISATAP configured with a link-local address and an address for each prefix received from the ISATAP router through stateless address auto-configuration. If the ISATAP name is not resolved successfully, the host will have an ISATAP interface configured with a link-local address.\r\n\r\nPolicy Disabled State: No ISATAP interfaces are present on the host.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-isatap-state"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_stateselect","displayName":"Select from the following states:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_stateselect_default","displayName":"Default State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_stateselect_enabled","displayName":"Enabled State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_stateselect_disabled","displayName":"Disabled State","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_client_port","displayName":"Set Teredo Client Port","description":"This policy setting allows you to select the UDP port the Teredo client will use to send packets. If you leave the default of 0, the operating system will select a port (recommended). If you select a UDP port that is already in use by a system, the Teredo client will fail to initialize.\r\n\r\nIf you enable this policy setting, you can customize a UDP port for the Teredo client.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-client-port"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_client_port_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_client_port_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_client_port_teredoclientportbox","displayName":"The range is 0 to 65535. Default (recommended) is 0 which is to let the local system pick the port.","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_default_qualified","displayName":"Set Teredo Default Qualified","description":"This policy setting allows you to set Teredo to be ready to communicate, a process referred to as qualification. By default, Teredo enters a dormant state when not in use. The qualification process brings it out of a dormant state.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\nThis policy setting contains only one state:\r\n\r\nPolicy Enabled State: If Default Qualified is enabled, Teredo will attempt qualification immediately and remain qualified if the qualification process succeeds.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-default-qualified"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_default_qualified_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_default_qualified_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_default_qualified_stateselect","displayName":"Select from the following states:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_default_qualified_stateselect_enabled","displayName":"Enabled State","description":null,"helpText":null}},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate","displayName":"Set Teredo Refresh Rate","description":"This policy setting allows you to configure the Teredo refresh rate.\r\n\r\nNote: On a periodic basis (by default, every 30 seconds), Teredo clients send a single Router Solicitation packet to the Teredo server. The Teredo server sends a Router Advertisement Packet in response. This periodic packet refreshes the IP address and UDP port mapping in the translation table of the Teredo client's NAT device.\r\n\r\nIf you enable this policy setting, you can specify the refresh rate. If you choose a refresh rate longer than the port mapping in the Teredo client's NAT device, Teredo might stop working or connectivity might be intermittent.\r\n\r\nIf you disable or do not configure this policy setting, the refresh rate is configured using the local settings on the computer. The default refresh rate is 30 seconds.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-refresh-rate"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate_teredorefreshratebox","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name","displayName":"Set Teredo Server Name","description":"This policy setting allows you to specify the name of the Teredo server. This server name will be used on the Teredo client computer where this policy setting is applied.\r\n\r\nIf you enable this policy setting, you can specify a Teredo server name that applies to a Teredo client.\r\n\r\nIf you disable or do not configure this policy setting, the local settings on the computer are used to determine the Teredo server name.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-server-name"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name_teredoservernamebox","displayName":"Enter a Teredo server name:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state","displayName":"Set Teredo State","description":"This policy setting allows you to configure Teredo, an address assignment and automatic tunneling technology that provides unicast IPv6 connectivity across the IPv4 Internet.\r\n\r\nIf you disable or do not configure this policy setting, the local host settings are used.\r\n\r\nIf you enable this policy setting, you can configure Teredo with one of the following settings:\r\n\r\nDefault: The default state is \"Client.\"\r\n\r\nDisabled: No Teredo interfaces are present on the host.\r\n\r\nClient: The Teredo interface is present only when the host is not on a network that includes a domain controller.\r\n\r\nEnterprise Client: The Teredo interface is always present, even if the host is on a network that includes a domain controller.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-state"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect","displayName":"Select from the following states:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_default","displayName":"Default State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_disabled","displayName":"Disabled State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_client","displayName":"Client","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_enterprise client","displayName":"Enterprise Client","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_windows_scaling_heuristics_state","displayName":"Set Window Scaling Heuristics State","description":"This policy setting allows you to configure Window Scaling Heuristics. Window Scaling Heuristics is an algorithm to identify connectivity and throughput problems caused by many Firewalls and other middle boxes that don't interpret Window Scaling option correctly.\r\n\r\nIf you do not configure this policy setting, the local host settings are used.\r\n\r\nIf you enable this policy setting, Window Scaling Heuristics will be enabled and system will try to identify connectivity and throughput problems and take appropriate measures.\r\n\r\nIf you disable this policy setting, Window Scaling Heuristics will be disabled and system will not try to identify connectivity and throughput problems casued by Firewalls or other middle boxes.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-windows-scaling-heuristics-state"],"categoryId":"91789113-6339-4e96-8e1d-73a4dec4967f","categoryName":"Parameters","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_windows_scaling_heuristics_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_windows_scaling_heuristics_state_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_auto_reconnect","displayName":"Automatic reconnection","description":"Specifies whether to allow Remote Desktop Connection clients to automatically reconnect to sessions on an RD Session Host server if their network link is temporarily lost. By default, a maximum of twenty reconnection attempts are made at five second intervals.\r\n\r\nIf the status is set to Enabled, automatic reconnection is attempted for all clients running Remote Desktop Connection whenever their network connection is lost.\r\n\r\nIf the status is set to Disabled, automatic reconnection of clients is prohibited.\r\n\r\nIf the status is set to Not Configured, automatic reconnection is not specified at the Group Policy level. However, users can configure automatic reconnection using the \"Reconnect if connection is dropped\" checkbox on the Experience tab in Remote Desktop Connection.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-auto-reconnect"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_auto_reconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_auto_reconnect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_camera_redirection","displayName":"Do not allow video capture redirection","description":"This policy setting lets you control the redirection of video capture devices to the remote computer in a Remote Desktop Services session. \r\n\r\nBy default, Remote Desktop Services allows redirection of video capture devices.\r\n\r\nIf you enable this policy setting, users cannot redirect their video capture devices to the remote computer. \r\n\r\nIf you disable or do not configure this policy setting, users can redirect their video capture devices to the remote computer. Users can use the More option on the Local Resources tab of Remote Desktop Connection to choose the video capture devices to redirect to the remote computer.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-camera-redirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_camera_redirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_camera_redirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy","displayName":"Server authentication certificate template","description":"This policy setting allows you to specify the name of the certificate template that determines which certificate is automatically selected to authenticate an RD Session Host server.\r\n\r\nA certificate is needed to authenticate an RD Session Host server when TLS 1.0, 1.1 or 1.2 is used to secure communication between a client and an RD Session Host server during RDP connections.\r\n\r\nIf you enable this policy setting, you need to specify a certificate template name. Only certificates created by using the specified certificate template will be considered when a certificate to authenticate the RD Session Host server is automatically selected. Automatic certificate selection only occurs when a specific certificate has not been selected.\r\n\r\nIf no certificate can be found that was created with the specified certificate template, the RD Session Host server will issue a certificate enrollment request and will use the current certificate until the request is completed. If more than one certificate is found that was created with the specified certificate template, the certificate that will expire latest and that matches the current name of the RD Session Host server will be selected.\r\n\r\nIf you disable or do not configure this policy, the certificate template name is not specified at the Group Policy level. By default, a self-signed certificate is used to authenticate the RD Session Host server. \r\n\r\nNote: If you select a specific certificate to be used to authenticate the RD Session Host server, that certificate will take precedence over this policy setting.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-certificate-template-policy"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy_ts_certificate_template_name","displayName":"Certificate Template Name","description":null,"helpText":"","infoUrls":[],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_signed_files_2","displayName":"Allow .rdp files from valid publishers and user's default .rdp settings","description":"This policy setting allows you to specify whether users can run Remote Desktop Protocol (.rdp) files from a publisher that signed the file with a valid certificate. A valid certificate is one that is issued by an authority recognized by the client, such as the issuers in the client's Third-Party Root Certification Authorities certificate store. This policy setting also controls whether the user can start an RDP session by using default .rdp settings (for example, when a user directly opens the Remote Desktop Connection [RDC] client without specifying an .rdp file).\r\n\r\nIf you enable or do not configure this policy setting, users can run .rdp files that are signed with a valid certificate. Users can also start an RDP session with default .rdp settings by directly opening the RDC client. When a user starts an RDP session, the user is asked to confirm whether they want to connect.\r\n\r\nIf you disable this policy setting, users cannot run .rdp files that are signed with a valid certificate. Additionally, users cannot start an RDP session by directly opening the RDC client and specifying the remote computer name. When a user tries to start an RDP session, the user receives a message that the publisher has been blocked.\r\n\r\nNote: You can define this policy setting in the Computer Configuration node or in the User Configuration node. If you configure this policy setting for the computer, all users on the computer are affected.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-allow-signed-files-2"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_signed_files_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_signed_files_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_2","displayName":"Allow .rdp files from unknown publishers","description":"This policy setting allows you to specify whether users can run unsigned Remote Desktop Protocol (.rdp) files and .rdp files from unknown publishers on the client computer.\r\n\r\nIf you enable or do not configure this policy setting, users can run unsigned .rdp files and .rdp files from unknown publishers on the client computer. Before a user starts an RDP session, the user receives a warning message and is asked to confirm whether they want to connect.\r\n\r\nIf you disable this policy setting, users cannot run unsigned .rdp files and .rdp files from unknown publishers on the client computer. If the user tries to start an RDP session, the user receives a message that the publisher has been blocked.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-allow-unsigned-files-2"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio","displayName":"Allow audio and video playback redirection","description":"This policy setting allows you to specify whether users can redirect the remote computer's audio and video output in a Remote Desktop Services session.\r\nUsers can specify where to play the remote computer's audio output by configuring the remote audio settings on the Local Resources tab in Remote Desktop Connection (RDC). Users can choose to play the remote audio on the remote computer or on the local computer. Users can also choose to not play the audio. Video playback can be configured by using the videoplayback setting in a Remote Desktop Protocol (.rdp) file. By default, video playback is enabled.\r\n\r\nBy default, audio and video playback redirection is not allowed when connecting to a computer running Windows Server 2008 R2, Windows Server 2008, or Windows Server 2003. Audio and video playback redirection is allowed by default when connecting to a computer running Windows 8, Windows Server 2012, Windows 7, Windows Vista, or Windows XP Professional.\r\n\r\nIf you enable this policy setting, audio and video playback redirection is allowed.\r\n\r\nIf you disable this policy setting, audio and video playback redirection is not allowed, even if audio playback redirection is specified in RDC, or video playback is specified in the .rdp file.\r\n\r\nIf you do not configure this policy setting audio and video playback redirection is not specified at the Group Policy level. \r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-audio"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_capture","displayName":"Allow audio recording redirection","description":"This policy setting allows you to specify whether users can record audio to the remote computer in a Remote Desktop Services session.\r\nUsers can specify whether to record audio to the remote computer by configuring the remote audio settings on the Local Resources tab in Remote Desktop Connection (RDC). Users can record audio by using an audio input device on the local computer, such as a built-in microphone.\r\n\r\nBy default, audio recording redirection is not allowed when connecting to a computer running Windows Server 2008 R2. Audio recording redirection is allowed by default when connecting to a computer running at least Windows 7, or Windows Server 2008 R2. \r\n\r\nIf you enable this policy setting, audio recording redirection is allowed.\r\n\r\nIf you disable this policy setting, audio recording redirection is not allowed, even if audio recording redirection is specified in RDC.\r\n\r\nIf you do not configure this policy setting, Audio recording redirection is not specified at the Group Policy level.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-audio-capture"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_capture_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_capture_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality","displayName":"Limit audio playback quality","description":"This policy setting allows you to limit the audio playback quality for a Remote Desktop Services session. Limiting the quality of audio playback can improve connection performance, particularly over slow links.\r\n\r\nIf you enable this policy setting, you must select one of the following: High, Medium, or Dynamic. If you select High, the audio will be sent without any compression and with minimum latency. This requires a large amount of bandwidth. If you select Medium, the audio will be sent with some compression and with minimum latency as determined by the codec that is being used. If you select Dynamic, the audio will be sent with a level of compression that is determined by the bandwidth of the remote connection.\r\n\r\nThe audio playback quality that you specify on the remote computer by using this policy setting is the maximum quality that can be used for a Remote Desktop Services session, regardless of the audio playback quality configured on the client computer. For example, if the audio playback quality configured on the client computer is higher than the audio playback quality configured on the remote computer, the lower level of audio playback quality will be used.\r\n\r\nAudio playback quality can be configured on the client computer by using the audioqualitymode setting in a Remote Desktop Protocol (.rdp) file. By default, audio playback quality is set to Dynamic.\r\n\r\nIf you disable or do not configure this policy setting, audio playback quality will be set to Dynamic.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-audio-quality"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level","displayName":"Audio Quality","description":null,"helpText":"","infoUrls":[],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level_1","displayName":"Dynamic","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level_3","displayName":"Medium","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level_7","displayName":"High","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_clipboard","displayName":"Do not allow Clipboard redirection","description":"This policy setting specifies whether to prevent the sharing of Clipboard contents (Clipboard redirection) between a remote computer and a client computer during a Remote Desktop Services session.\r\n\r\nYou can use this setting to prevent users from redirecting Clipboard data to and from the remote computer and the local computer. By default, Remote Desktop Services allows Clipboard redirection.\r\n\r\nIf you enable this policy setting, users cannot redirect Clipboard data.\r\n\r\nIf you disable this policy setting, Remote Desktop Services always allows Clipboard redirection.\r\n\r\nIf you do not configure this policy setting, Clipboard redirection is not specified at the Group Policy level. \r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-clipboard"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_clipboard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_clipboard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_com","displayName":"Do not allow COM port redirection","description":"This policy setting specifies whether to prevent the redirection of data to client COM ports from the remote computer in a Remote Desktop Services session.\r\n\r\nYou can use this setting to prevent users from redirecting data to COM port peripherals or mapping local COM ports while they are logged on to a Remote Desktop Services session. By default, Remote Desktop Services allows this COM port redirection.\r\n\r\nIf you enable this policy setting, users cannot redirect server data to the local COM port.\r\n\r\nIf you disable this policy setting, Remote Desktop Services always allows COM port redirection.\r\n\r\nIf you do not configure this policy setting, COM port redirection is not specified at the Group Policy level. \r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-com"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_com_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_com_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_default_m","displayName":"Do not set default client printer to be default printer in a session","description":"This policy setting allows you to specify whether the client default printer is automatically set as the default printer in a session on an RD Session Host server.\r\n\r\nBy default, Remote Desktop Services automatically designates the client default printer as the default printer in a session on an RD Session Host server. You can use this policy setting to override this behavior.\r\n\r\nIf you enable this policy setting, the default printer is the printer specified on the remote computer.\r\n\r\nIf you disable this policy setting, the RD Session Host server automatically maps the client default printer and sets it as the default printer upon connection.\r\n\r\nIf you do not configure this policy setting, the default printer is not specified at the Group Policy level.\r\n\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-default-m"],"categoryId":"f1455024-7de9-448f-8d8f-a42db2af0a35","categoryName":"Printer Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_default_m_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_default_m_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_hardware_mode","displayName":"Do not allow hardware accelerated decoding","description":"This policy setting specifies whether the Remote Desktop Connection can use hardware acceleration if supported hardware is available. If you use this setting, the Remote Desktop Client will use only software decoding. For example, if you have a problem that you suspect may be related to hardware acceleration, use this setting to disable the acceleration; then, if the problem still occurs, you will know that there are additional issues to investigate. If you disable this setting or leave it not configured, the Remote Desktop client will use hardware accelerated decoding if supported hardware is available.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-disable-hardware-mode"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_hardware_mode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_hardware_mode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_lpt","displayName":"Do not allow LPT port redirection","description":"This policy setting specifies whether to prevent the redirection of data to client LPT ports during a Remote Desktop Services session.\r\n\r\nYou can use this setting to prevent users from mapping local LPT ports and redirecting data from the remote computer to local LPT port peripherals. By default, Remote Desktop Services allows LPT port redirection.\r\n\r\nIf you enable this policy setting, users in a Remote Desktop Services session cannot redirect server data to the local LPT port.\r\n\r\nIf you disable this policy setting, LPT port redirection is always allowed.\r\n\r\nIf you do not configure this policy setting, LPT port redirection is not specified at the Group Policy level. \r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-lpt"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_lpt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_lpt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_pnp","displayName":"Do not allow supported Plug and Play device redirection","description":"This policy setting lets you control the redirection of supported Plug and Play and RemoteFX USB devices, such as Windows Portable Devices, to the remote computer in a Remote Desktop Services session. \r\n\r\nBy default, Remote Desktop Services does not allow redirection of supported Plug and Play and RemoteFX USB devices.\r\n\r\nIf you disable this policy setting, users can redirect their supported Plug and Play devices to the remote computer. Users can use the More option on the Local Resources tab of Remote Desktop Connection to choose the supported Plug and Play devices to redirect to the remote computer.\r\n\r\nIf you enable this policy setting, users cannot redirect their supported Plug and Play devices to the remote computer.If you do not configure this policy setting, users can redirect their supported Plug and Play devices to the remote computer only if it is running Windows Server 2012 R2 and earlier versions.\r\n\r\nNote: You can disable redirection of specific types of supported Plug and Play devices by using Computer Configuration\\Administrative Templates\\System\\Device Installation\\Device Installation Restrictions policy settings.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-pnp"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_pnp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_pnp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_printer","displayName":"Do not allow client printer redirection","description":"This policy setting allows you to specify whether to prevent the mapping of client printers in Remote Desktop Services sessions.\r\n\r\nYou can use this policy setting to prevent users from redirecting print jobs from the remote computer to a printer attached to their local (client) computer. By default, Remote Desktop Services allows this client printer mapping.\r\n\r\nIf you enable this policy setting, users cannot redirect print jobs from the remote computer to a local client printer in Remote Desktop Services sessions.\r\n\r\nIf you disable this policy setting, users can redirect print jobs with client printer mapping.\r\n\r\nIf you do not configure this policy setting, client printer mapping is not specified at the Group Policy level.\r\n\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-printer"],"categoryId":"f1455024-7de9-448f-8d8f-a42db2af0a35","categoryName":"Printer Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_printer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_printer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_trusted_certificate_thumbprints_1","displayName":"Specify SHA1 thumbprints of certificates representing trusted .rdp publishers","description":"This policy setting allows you to specify a list of Secure Hash Algorithm 1 (SHA1) certificate thumbprints that represent trusted Remote Desktop Protocol (.rdp) file publishers.\r\n\r\nIf you enable this policy setting, any certificate with an SHA1 thumbprint that matches a thumbprint on the list is trusted. If a user tries to start an .rdp file that is signed by a trusted certificate, the user does not receive any warning messages when they start the file. To obtain the thumbprint, view the certificate details, and then click the Thumbprint field.\r\n\r\nIf you disable or do not configure this policy setting, no publisher is treated as a trusted .rdp publisher.\r\n\r\nNotes:\r\n\r\nYou can define this policy setting in the Computer Configuration node or in the User Configuration node. If you configure this policy setting for the computer, the list of certificate thumbprints trusted for a user is a combination of the list defined for the computer and the list defined for the user.\r\n\r\nThis policy setting overrides the behavior of the \"Allow .rdp files from valid publishers and user's default .rdp settings\" policy setting.\r\n\r\nIf the list contains a string that is not a certificate thumbprint, it is ignored.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-trusted-certificate-thumbprints-1"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_trusted_certificate_thumbprints_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_trusted_certificate_thumbprints_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_trusted_certificate_thumbprints_1_trusted_certificate_thumbprints","displayName":"Comma-separated list of SHA1 trusted certificate thumbprints:","description":null,"helpText":"","infoUrls":[],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_turn_off_udp","displayName":"Turn Off UDP On Client","description":"This policy setting specifies whether the UDP protocol will be used to access servers via Remote Desktop Protocol. \r\n\r\nIf you enable this policy setting, Remote Desktop Protocol traffic will only use the TCP protocol.\r\n\r\nIf you disable or do not configure this policy setting, Remote Desktop Protocol traffic will attempt to use both TCP and UDP protocols.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-turn-off-udp"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_turn_off_udp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_turn_off_udp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth","displayName":"Limit maximum color depth","description":"This policy setting allows you to specify the maximum color resolution (color depth) for Remote Desktop Services connections.\r\n\r\nYou can use this policy setting to set a limit on the color depth of any connection that uses RDP. Limiting the color depth can improve connection performance, particularly over slow links, and reduce server load.\r\n\r\nIf you enable this policy setting, the color depth that you specify is the maximum color depth allowed for a user's RDP connection. The actual color depth for the connection is determined by the color support available on the client computer. If you select Client Compatible, the highest color depth supported by the client will be used.\r\n\r\nIf you disable or do not configure this policy setting, the color depth for connections is not specified at the Group Policy level.\r\n\r\nNote:\r\n1.\tSetting the color depth to 24 bits is only supported on Windows Server 2003 and Windows XP Professional.\r\n2.\tThe value specified in this policy setting is not applied to connections from client computers that are using at least Remote Desktop Protocol 8.0 (computers running at least Windows 8 or Windows Server 2012). The 32-bit color depth format is always used for these connections.\r\n3.\tFor connections from client computers that are using Remote Desktop Protocol 7.1 or earlier versions that are connecting to computers running at least Windows 8 or Windows Server 2012, the minimum of the following values is used as the color depth format:\r\na.\tValue specified by this policy setting\r\nb.\tMaximum color depth supported by the client\r\nc.\tValue requested by the client\r\n\r\nIf the client does not support at least 16 bits, the connection is terminated.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-colordepth"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_ts_color_depth","displayName":"Color Depth","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_ts_color_depth_999","displayName":"Client Compatible","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_ts_color_depth_2","displayName":"15 bit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_ts_color_depth_3","displayName":"16 bit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_ts_color_depth_4","displayName":"24 bit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_ts_color_depth_5","displayName":"32 bit","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_delete_roaming_user_profiles","displayName":"Limit the size of the entire roaming user profile cache","description":"This policy setting allows you to limit the size of the entire roaming user profile cache on the local drive. This policy setting only applies to a computer on which the Remote Desktop Session Host role service is installed.\r\n\r\nNote: If you want to limit the size of an individual user profile, use the \"Limit profile size\" policy setting located in User Configuration\\Policies\\Administrative Templates\\System\\User Profiles.\r\n\r\nIf you enable this policy setting, you must specify a monitoring interval (in minutes) and a maximum size (in gigabytes) for the entire roaming user profile cache. The monitoring interval determines how often the size of the entire roaming user profile cache is checked. When the size of the entire roaming user profile cache exceeds the maximum size that you have specified, the oldest (least recently used) roaming user profiles will be deleted until the size of the entire roaming user profile cache is less than the maximum size specified.\r\n\r\nIf you disable or do not configure this policy setting, no restriction is placed on the size of the entire roaming user profile cache on the local drive.\r\n\r\nNote: This policy setting is ignored if the \"Prevent Roaming Profile changes from propagating to the server\" policy setting located in Computer Configuration\\Policies\\Administrative Templates\\System\\User Profiles is enabled.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-delete-roaming-user-profiles"],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_delete_roaming_user_profiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_delete_roaming_user_profiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_delete_roaming_user_profiles_ts_profile_directory_monitoring_interval","displayName":"Monitoring interval (minutes):","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_delete_roaming_user_profiles_ts_profile_directory_quota","displayName":"Maximum cache size (GBs):","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_disable_remote_desktop_wallpaper","displayName":"Enforce Removal of Remote Desktop Wallpaper","description":"Specifies whether desktop wallpaper is displayed to remote clients connecting via Remote Desktop Services.\r\n\r\nYou can use this setting to enforce the removal of wallpaper during a Remote Desktop Services session. By default, Windows XP Professional displays wallpaper to remote clients connecting through Remote Desktop, depending on the client configuration (see the Experience tab in the Remote Desktop Connection options for more information). Servers running Windows Server 2003 do not display wallpaper by default to Remote Desktop Services sessions.\r\n\r\nIf the status is set to Enabled, wallpaper never appears in a Remote Desktop Services session.\r\n\r\nIf the status is set to Disabled, wallpaper might appear in a Remote Desktop Services session, depending on the client configuration.\r\n\r\nIf the status is set to Not Configured, the default behavior applies.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-disable-remote-desktop-wallpaper"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_disable_remote_desktop_wallpaper_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_disable_remote_desktop_wallpaper_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_dx_use_full_hwgpu","displayName":"Use hardware graphics adapters for all Remote Desktop Services sessions","description":"This policy setting enables system administrators to change the graphics rendering for all Remote Desktop Services sessions.\r\n\r\nIf you enable this policy setting, all Remote Desktop Services sessions use the hardware graphics renderer instead of the Microsoft Basic Render Driver as the default adapter.\r\n\r\nIf you disable this policy setting, all Remote Desktop Services sessions use the Microsoft Basic Render Driver as the default adapter.\r\n\r\nIf you do not configure this policy setting, Remote Desktop Services sessions on the RD Session Host server use the Microsoft Basic Render Driver as the default adapter. In all other cases, Remote Desktop Services sessions use the hardware graphics renderer by default.\r\n\r\nNOTE: The policy setting enables load-balancing of graphics processing units (GPU) on a computer with more than one GPU installed. The GPU configuration of the local session is not affected by this policy setting.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-dx-use-full-hwgpu"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_dx_use_full_hwgpu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_dx_use_full_hwgpu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_easy_print","displayName":"Use Remote Desktop Easy Print printer driver first","description":"This policy setting allows you to specify whether the Remote Desktop Easy Print printer driver is used first to install all client printers. \r\n\r\nIf you enable or do not configure this policy setting, the RD Session Host server first tries to use the Remote Desktop Easy Print printer driver to install all client printers. If for any reason the Remote Desktop Easy Print printer driver cannot be used, a printer driver on the RD Session Host server that matches the client printer is used. If the RD Session Host server does not have a printer driver that matches the client printer, the client printer is not available for the Remote Desktop session.\r\n\r\nIf you disable this policy setting, the RD Session Host server tries to find a suitable printer driver to install the client printer. If the RD Session Host server does not have a printer driver that matches the client printer, the server tries to use the Remote Desktop Easy Print driver to install the client printer. If for any reason the Remote Desktop Easy Print printer driver cannot be used, the client printer is not available for the Remote Desktop Services session.\r\n\r\nNote: If the \"Do not allow client printer redirection\" policy setting is enabled, the \"Use Remote Desktop Easy Print printer driver first\" policy setting is ignored.\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-easy-print"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_easy_print_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_easy_print_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_enablevirtualgraphics","displayName":"Configure RemoteFX","description":"This policy setting allows you to control the availability of RemoteFX on both a Remote Desktop Virtualization Host (RD Virtualization Host) server and a Remote Desktop Session Host (RD Session Host) server.\r\n\r\nWhen deployed on an RD Virtualization Host server, RemoteFX delivers a rich user experience by rendering content on the server by using graphics processing units (GPUs). By default, RemoteFX for RD Virtualization Host uses server-side GPUs to deliver a rich user experience over LAN connections and RDP 7.1.\r\n\r\nWhen deployed on an RD Session Host server, RemoteFX delivers a rich user experience by using a hardware-accelerated compression scheme.\r\n\r\nIf you enable this policy setting, RemoteFX will be used to deliver a rich user experience over LAN connections and RDP 7.1.\r\n\r\nIf you disable this policy setting, RemoteFX will be disabled.\r\n\r\nIf you do not configure this policy setting, the default behavior will be used. By default, RemoteFX for RD Virtualization Host is enabled and RemoteFX for RD Session Host is disabled.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-enablevirtualgraphics"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_enablevirtualgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_enablevirtualgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype","displayName":"Specify RD Session Host server fallback printer driver behavior","description":"This policy setting allows you to specify the RD Session Host server fallback printer driver behavior.\r\n\r\nBy default, the RD Session Host server fallback printer driver is disabled. If the RD Session Host server does not have a printer driver that matches the client's printer, no printer will be available for the Remote Desktop Services session.\r\n\r\nIf you enable this policy setting, the fallback printer driver is enabled, and the default behavior is for the RD Session Host server to find a suitable printer driver. If one is not found, the client's printer is not available. You can choose to change this default behavior. The available options are:\r\n\r\n\"Do nothing if one is not found\" - If there is a printer driver mismatch, the server will attempt to find a suitable driver. If one is not found, the client's printer is not available. This is the default behavior.\r\n\r\n\"Default to PCL if one is not found\" - If no suitable printer driver can be found, default to the Printer Control Language (PCL) fallback printer driver.\r\n\r\n\"Default to PS if one is not found\" - If no suitable printer driver can be found, default to the PostScript (PS) fallback printer driver.\r\n\r\n\"Show both PCL and PS if one is not found\" - If no suitable driver can be found, show both PS and PCL-based fallback printer drivers.\r\n\r\nIf you disable this policy setting, the RD Session Host server fallback driver is disabled and the RD Session Host server will not attempt to use the fallback printer driver.\r\n\r\nIf you do not configure this policy setting, the fallback printer driver behavior is off by default.\r\n\r\nNote: If the \"Do not allow client printer redirection\" setting is enabled, this policy setting is ignored and the fallback printer driver is disabled.\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-fallbackprintdrivertype"],"categoryId":"f1455024-7de9-448f-8d8f-a42db2af0a35","categoryName":"Printer Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_ts_fallback_options","displayName":"When attempting to find a suitable driver:","description":"\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":[],"categoryId":"f1455024-7de9-448f-8d8f-a42db2af0a35","categoryName":"Printer Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_ts_fallback_options_1","displayName":"Do nothing if one is not found.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_ts_fallback_options_2","displayName":"Default to PCL if one is not found.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_ts_fallback_options_3","displayName":"Default to PS if one is not found.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_ts_fallback_options_4","displayName":"Show both PCL and PS if one is not found.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_forcible_logoff","displayName":"Deny logoff of an administrator logged in to the console session","description":"This policy setting determines whether an administrator attempting to connect remotely to the console of a server can log off an administrator currently logged on to the console.\r\n\r\nThis policy is useful when the currently connected administrator does not want to be logged off by another administrator. If the connected administrator is logged off, any data not previously saved is lost.\r\n\r\nIf you enable this policy setting, logging off the connected administrator is not allowed.\r\n\r\nIf you disable or do not configure this policy setting, logging off the connected administrator is allowed.\r\n\r\nNote: The console session is also known as Session 0. Console access can be obtained by using the /console switch from Remote Desktop Connection in the computer field name or from the command line.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-forcible-logoff"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_forcible_logoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_forcible_logoff_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_join_session_directory","displayName":"Join RD Connection Broker","description":"This policy setting allows you to specify whether the RD Session Host server should join a farm in RD Connection Broker. RD Connection Broker tracks user sessions and allows a user to reconnect to their existing session in a load-balanced RD Session Host server farm. To participate in RD Connection Broker, the Remote Desktop Session Host role service must be installed on the server.\r\n\r\nIf the policy setting is enabled, the RD Session Host server joins the farm that is specified in the RD Connection Broker farm name policy setting. The farm exists on the RD Connection Broker server that is specified in the Configure RD Connection Broker server name policy setting.\r\n\r\nIf you disable this policy setting, the server does not join a farm in RD Connection Broker, and user session tracking is not performed. If the policy setting is disabled, you cannot use either the Remote Desktop Session Host Configuration tool or the Remote Desktop Services WMI Provider to join the server to RD Connection Broker.\r\n\r\nIf the policy setting is not configured, the policy setting is not specified at the Group Policy level. \r\n\r\nNotes:\r\n\r\n 1. If you enable this policy setting, you must also enable the Configure RD Connection Broker farm name and Configure RD Connection Broker server name policy settings.\r\n\r\n 2. For Windows Server 2008, this policy setting is supported on at least Windows Server 2008 Standard.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-join-session-directory"],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_join_session_directory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_join_session_directory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive","displayName":"Configure keep-alive connection interval","description":"This policy setting allows you to enter a keep-alive interval to ensure that the session state on the RD Session Host server is consistent with the client state.\r\n\r\nAfter an RD Session Host server client loses the connection to an RD Session Host server, the session on the RD Session Host server might remain active instead of changing to a disconnected state, even if the client is physically disconnected from the RD Session Host server. If the client logs on to the same RD Session Host server again, a new session might be established (if the RD Session Host server is configured to allow multiple sessions), and the original session might still be active.\r\n\r\nIf you enable this policy setting, you must enter a keep-alive interval. The keep-alive interval determines how often, in minutes, the server checks the session state. The range of values you can enter is 1 to 999,999.\r\n\r\nIf you disable or do not configure this policy setting, a keep-alive interval is not set and the server will not check the session state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-keep-alive"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive_ts_keep_alive_interval","displayName":"Keep-Alive interval:","description":null,"helpText":"","infoUrls":[],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_secgroup","displayName":"License server security group","description":"This policy setting allows you to specify the RD Session Host servers to which a Remote Desktop license server will offer Remote Desktop Services client access licenses (RDS CALs).\r\n\r\nYou can use this policy setting to control which RD Session Host servers are issued RDS CALs by the Remote Desktop license server. By default, a license server issues an RDS CAL to any RD Session Host server that requests one.\r\n\r\nIf you enable this policy setting and this policy setting is applied to a Remote Desktop license server, the license server will only respond to RDS CAL requests from RD Session Host servers whose computer accounts are a member of the RDS Endpoint Servers group on the license server.\r\n\r\nBy default, the RDS Endpoint Servers group is empty.\r\n\r\nIf you disable or do not configure this policy setting, the Remote Desktop license server issues an RDS CAL to any RD Session Host server that requests one. The RDS Endpoint Servers group is not deleted or changed in any way by disabling or not configuring this policy setting.\r\n\r\nNote: You should only enable this policy setting when the license server is a member of a domain. You can only add computer accounts for RD Session Host servers to the RDS Endpoint Servers group when the license server is a member of a domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-license-secgroup"],"categoryId":"0456dcd5-c003-4a8b-80e6-61bacf854330","categoryName":"RD Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_secgroup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_secgroup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers","displayName":"Use the specified Remote Desktop license servers","description":"This policy setting allows you to specify the order in which an RD Session Host server attempts to locate Remote Desktop license servers.\r\n\r\nIf you enable this policy setting, an RD Session Host server first attempts to locate the specified license servers. If the specified license servers cannot be located, the RD Session Host server will attempt automatic license server discovery. In the automatic license server discovery process, an RD Session Host server in a Windows Server-based domain attempts to contact a license server in the following order:\r\n\r\n 1. Remote Desktop license servers that are published in Active Directory Domain Services.\r\n\r\n 2. Remote Desktop license servers that are installed on domain controllers in the same domain as the RD Session Host server.\r\n\r\nIf you disable or do not configure this policy setting, the RD Session Host server does not specify a license server at the Group Policy level.\r\n\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-license-servers"],"categoryId":"4b540860-0858-48f4-8830-18383bb1766f","categoryName":"Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers_ts_license_edit","displayName":"License servers to use:","description":"\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":[],"categoryId":"4b540860-0858-48f4-8830-18383bb1766f","categoryName":"Licensing","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_tooltip","displayName":"Hide notifications about RD Licensing problems that affect the RD Session Host server","description":"This policy setting determines whether notifications are displayed on an RD Session Host server when there are problems with RD Licensing that affect the RD Session Host server.\r\n\r\nBy default, notifications are displayed on an RD Session Host server after you log on as a local administrator, if there are problems with RD Licensing that affect the RD Session Host server. If applicable, a notification will also be displayed that notes the number of days until the licensing grace period for the RD Session Host server will expire.\r\n\r\nIf you enable this policy setting, these notifications will not be displayed on the RD Session Host server.\r\n\r\nIf you disable or do not configure this policy setting, these notifications will be displayed on the RD Session Host server after you log on as a local administrator.\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-license-tooltip"],"categoryId":"4b540860-0858-48f4-8830-18383bb1766f","categoryName":"Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_tooltip_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_tooltip_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode","displayName":"Set the Remote Desktop licensing mode","description":"\r\n This policy setting allows you to specify the type of Remote Desktop Services client access license (RDS CAL) that is required to connect to this RD Session Host server.\r\n\r\n You can use this policy setting to select one of three licensing modes: Per User , Per Device and AAD Per User .\r\n\r\n Per User licensing mode requires that each user account connecting to this RD Session Host server have an RDS Per User CAL issued from an RD Licensing server.\r\n\r\n Per Device licensing mode requires that each device connecting to this RD Session Host server have an RDS Per Device CAL issued from an RD Licensing server.\r\n\r\n AAD Per User licensing mode requires that each user account connecting to this RD Session Host server have a service plan that supports RDS licenses assigned in AAD.\r\n \r\n If you enable this policy setting, the Remote Desktop licensing mode that you specify is honored by the Remote Desktop license server and RD Session Host.\r\n\r\n If you disable or do not configure this policy setting, the licensing mode is not specified at the Group Policy level.\r\n \r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-licensing-mode"],"categoryId":"4b540860-0858-48f4-8830-18383bb1766f","categoryName":"Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode_ts_licensing_name","displayName":"Specify the licensing mode for the RD Session Host server.","description":"\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":[],"categoryId":"4b540860-0858-48f4-8830-18383bb1766f","categoryName":"Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode_ts_licensing_name_2","displayName":"Per Device","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode_ts_licensing_name_4","displayName":"Per User","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode_ts_licensing_name_6","displayName":"AAD Per User","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_max_con_policy","displayName":"Limit number of connections","description":"Specifies whether Remote Desktop Services limits the number of simultaneous connections to the server.\r\n\r\nYou can use this setting to restrict the number of Remote Desktop Services sessions that can be active on a server. If this number is exceeded, addtional users who try to connect receive an error message telling them that the server is busy and to try again later. Restricting the number of sessions improves performance because fewer sessions are demanding system resources. By default, RD Session Host servers allow an unlimited number of Remote Desktop Services sessions, and Remote Desktop for Administration allows two Remote Desktop Services sessions.\r\n\r\nTo use this setting, enter the number of connections you want to specify as the maximum for the server. To specify an unlimited number of connections, type 999999.\r\n\r\nIf the status is set to Enabled, the maximum number of connections is limited to the specified number consistent with the version of Windows and the mode of Remote Desktop Services running on the server.\r\n\r\nIf the status is set to Disabled or Not Configured, limits to the number of connections are not enforced at the Group Policy level.\r\n\r\nNote: This setting is designed to be used on RD Session Host servers (that is, on servers running Windows with Remote Desktop Session Host role service installed).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-max-con-policy"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_max_con_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_max_con_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_max_con_policy_ts_maximum_connections_allowed","displayName":"RD Maximum Connections allowed","description":null,"helpText":"","infoUrls":[],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxdisplayres","displayName":"Limit maximum display resolution","description":"This policy setting allows you to specify the maximum display resolution that can be used by each monitor used to display a Remote Desktop Services session. Limiting the resolution used to display a remote session can improve connection performance, particularly over slow links, and reduce server load.\r\n\r\nIf you enable this policy setting, you must specify a resolution width and height. The resolution specified will be the maximum resolution that can be used by each monitor used to display a Remote Desktop Services session.\r\n\r\nIf you disable or do not configure this policy setting, the maximum resolution that can be used by each monitor to display a Remote Desktop Services session will be determined by the values specified on the Display Settings tab in the Remote Desktop Session Host Configuration tool.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-maxdisplayres"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxdisplayres_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxdisplayres_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxdisplayres_ts_displayres_height","displayName":"Height","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxdisplayres_ts_displayres_width","displayName":"Width","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxmonitor","displayName":"Limit number of monitors","description":"This policy setting allows you to limit the number of monitors that a user can use to display a Remote Desktop Services session. Limiting the number of monitors to display a Remote Desktop Services session can improve connection performance, particularly over slow links, and reduce server load.\r\n\r\nIf you enable this policy setting, you can specify the number of monitors that can be used to display a Remote Desktop Services session. You can specify a number from 1 to 16.\r\n\r\nIf you disable or do not configure this policy setting, the number of monitors that can be used to display a Remote Desktop Services session is not specified at the Group Policy level.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-maxmonitor"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxmonitor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxmonitor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxmonitor_ts_max_monitor","displayName":"Maximum Monitors","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_nodisconnectmenu","displayName":"Remove \"Disconnect\" option from Shut Down dialog","description":"This policy setting allows you to remove the \"Disconnect\" option from the Shut Down Windows dialog box in Remote Desktop Services sessions.\r\n\r\nYou can use this policy setting to prevent users from using this familiar method to disconnect their client from an RD Session Host server.\r\n\r\nIf you enable this policy setting, \"Disconnect\" does not appear as an option in the drop-down list in the Shut Down Windows dialog box.\r\n\r\nIf you disable or do not configure this policy setting, \"Disconnect\" is not removed from the list in the Shut Down Windows dialog box.\r\n\r\nNote: This policy setting affects only the Shut Down Windows dialog box. It does not prevent users from using other methods to disconnect from a Remote Desktop Services session. This policy setting also does not prevent disconnected sessions at the server. You can control how long a disconnected session remains active on the server by configuring the \"Computer Configuration\\Administrative Templates\\Windows Components\\Remote Desktop Services\\RD Session Host\\Session Time Limits\\Set time limit for disconnected sessions\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-nodisconnectmenu"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_nodisconnectmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_nodisconnectmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_nosecuritymenu","displayName":"Remove Windows Security item from Start menu","description":"Specifies whether to remove the Windows Security item from the Settings menu on Remote Desktop clients. You can use this setting to prevent inexperienced users from logging off from Remote Desktop Services inadvertently.\r\n\r\nIf the status is set to Enabled, Windows Security does not appear in Settings on the Start menu. As a result, users must type a security attention sequence, such as CTRL+ALT+END, to open the Windows Security dialog box on the client computer.\r\n\r\nIf the status is set to Disabled or Not Configured, Windows Security remains in the Settings menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-nosecuritymenu"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_nosecuritymenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_nosecuritymenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_preventlicenseupgrade","displayName":"Prevent license upgrade","description":"This policy setting allows you to specify which version of Remote Desktop Services client access license (RDS CAL) a Remote Desktop Services license server will issue to clients connecting to RD Session Host servers running other Windows-based operating systems.\r\n\r\nA license server attempts to provide the most appropriate RDS or TS CAL for a connection. For example, a Windows Server 2008 license server will try to issue a Windows Server 2008 TS CAL for clients connecting to a terminal server running Windows Server 2008, and will try to issue a Windows Server 2003 TS CAL for clients connecting to a terminal server running Windows Server 2003.\r\n\r\nBy default, if the most appropriate RDS CAL is not available for a connection, a Windows Server 2008 license server will issue a Windows Server 2008 TS CAL, if available, to the following:\r\n\r\n* A client connecting to a Windows Server 2003 terminal server\r\n* A client connecting to a Windows 2000 terminal server\r\n\r\nIf you enable this policy setting, the license server will only issue a temporary RDS CAL to the client if an appropriate RDS CAL for the RD Session Host server is not available. If the client has already been issued a temporary RDS CAL and the temporary RDS CAL has expired, the client will not be able to connect to the RD Session Host server unless the RD Licensing grace period for the RD Session Host server has not expired.\r\n\r\nIf you disable or do not configure this policy setting, the license server will exhibit the default behavior noted earlier.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-preventlicenseupgrade"],"categoryId":"0456dcd5-c003-4a8b-80e6-61bacf854330","categoryName":"RD Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_preventlicenseupgrade_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_preventlicenseupgrade_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_promt_creds_client_comp","displayName":"Prompt for credentials on the client computer","description":"This policy setting determines whether a user will be prompted on the client computer to provide credentials for a remote connection to an RD Session Host server.\r\n\r\nIf you enable this policy setting, a user will be prompted on the client computer instead of on the RD Session Host server to provide credentials for a remote connection to an RD Session Host server. If saved credentials for the user are available on the client computer, the user will not be prompted to provide credentials.\r\n\r\nNote: If you enable this policy setting in releases of Windows Server 2008 R2 with SP1 or Windows Server 2008 R2, and a user is prompted on both the client computer and on the RD Session Host server to provide credentials, clear the Always prompt for password check box on the Log on Settings tab in Remote Desktop Session Host Configuration.\r\n\r\nIf you disable or do not configure this policy setting, the version of the operating system on the RD Session Host server will determine when a user is prompted to provide credentials for a remote connection to an RD Session Host server. For Windows Server 2003 and Windows 2000 Server a user will be prompted on the terminal server to provide credentials for a remote connection. For Windows Server 2008 and Windows Server 2008 R2, a user will be prompted on the client computer to provide credentials for a remote connection.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-promt-creds-client-comp"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_promt_creds_client_comp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_promt_creds_client_comp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_rdsappx_waitforregistration","displayName":"Suspend user sign-in to complete app registration","description":"This policy setting allows you to specify whether the app registration is completed before showing the Start screen to the user. \r\n\r\nBy default, when a new user signs in to a computer, the Start screen is shown and apps are registered in the background. However, some apps may not work until app registration is complete.\r\n\r\nIf you enable this policy setting, user sign-in is blocked for up to 6 minutes to complete the app registration. You can use this policy setting when customizing the Start screen on Remote Desktop Session Host servers. \r\n\r\nIf you disable or do not configure this policy setting, the Start screen is shown and apps are registered in the background.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-rdsappx-waitforregistration"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_rdsappx_waitforregistration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_rdsappx_waitforregistration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2","displayName":"Set rules for remote control of Remote Desktop Services user sessions","description":"If you enable this policy setting, administrators can interact with a user's Remote Desktop Services session based on the option selected. Select the desired level of control and permission from the options list:\r\n\r\n1. No remote control allowed: Disallows an administrator to use remote control or view a remote user session.\r\n2. Full Control with user's permission: Allows the administrator to interact with the session, with the user's consent.\r\n3. Full Control without user's permission: Allows the administrator to interact with the session, without the user's consent.\r\n4. View Session with user's permission: Allows the administrator to watch the session of a remote user with the user's consent. \r\n5. View Session without user's permission: Allows the administrator to watch the session of a remote user without the user's consent.\r\n\r\nIf you disable this policy setting, administrators can interact with a user's Remote Desktop Services session, with the user's consent.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-remotecontrol-2"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels","displayName":"Options:","description":null,"helpText":"","infoUrls":[],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_0","displayName":"No remote control allowed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_1","displayName":"Full Control with user's permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_2","displayName":"Full Control without user's permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_3","displayName":"View Session with user's permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_4","displayName":"View Session without user's permission","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics","displayName":"Optimize visual experience when using RemoteFX","description":"This policy setting allows you to specify the visual experience that remote users will have in Remote Desktop Connection (RDC) connections that use RemoteFX. You can use this policy to balance the network bandwidth usage with the type of graphics experience that is delivered.\r\n\r\nDepending on the requirements of your users, you can reduce network bandwidth usage by reducing the screen capture rate. You can also reduce network bandwidth usage by reducing the image quality (increasing the amount of image compression that is performed).\r\n\r\nIf you have a higher than average bandwidth network, you can maximize the utilization of bandwidth by selecting the highest setting for screen capture rate and the highest setting for image quality.\r\n\r\nBy default, Remote Desktop Connection sessions that use RemoteFX are optimized for a balanced experience over LAN conditions. If you disable or do not configure this policy setting, Remote Desktop Connection sessions that use RemoteFX will be the same as if the medium screen capture rate and the medium image compression settings were selected (the default behavior). \r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-remotedesktopvirtualgraphics"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screencapturerate","displayName":"Screen capture rate (frames per second):","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screencapturerate_1","displayName":"Highest (best quality)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screencapturerate_2","displayName":"Medium (default)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screencapturerate_3","displayName":"Lowest","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screenimagequality","displayName":"Screen Image Quality:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screenimagequality_1","displayName":"Highest (best quality)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screenimagequality_2","displayName":"Medium (default)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screenimagequality_3","displayName":"Lowest","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_clustname","displayName":"Configure RD Connection Broker farm name","description":"This policy setting allows you to specify the name of a farm to join in RD Connection Broker. RD Connection Broker uses the farm name to determine which RD Session Host servers are in the same RD Session Host server farm. Therefore, you must use the same farm name for all RD Session Host servers in the same load-balanced farm. The farm name does not have to correspond to a name in Active Directory Domain Services.\r\n\r\nIf you specify a new farm name, a new farm is created in RD Connection Broker. If you specify an existing farm name, the server joins that farm in RD Connection Broker.\r\n\r\nIf you enable this policy setting, you must specify the name of a farm in RD Connection Broker.\r\n\r\nIf you disable or do not configure this policy setting, the farm name is not specified at the Group Policy level. \r\n\r\nNotes:\r\n\r\n 1. This policy setting is not effective unless both the Join RD Connection Broker and the Configure RD Connection Broker server name policy settings are enabled and configured by using Group Policy.\r\n\r\n 2. For Windows Server 2008, this policy setting is supported on at least Windows Server 2008 Standard.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sd-clustname"],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_clustname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_clustname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_clustname_ts_sd_clustname","displayName":"Configure RD Connection Broker farm name:","description":null,"helpText":"","infoUrls":[],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_expose_address","displayName":"Use IP Address Redirection","description":"This policy setting allows you to specify the redirection method to use when a client device reconnects to an existing Remote Desktop Services session in a load-balanced RD Session Host server farm. This setting applies to an RD Session Host server that is configured to use RD Connection Broker and not to the RD Connection Broker server.\r\n\r\nIf you enable this policy setting, a Remote Desktop Services client queries the RD Connection Broker server and is redirected to their existing session by using the IP address of the RD Session Host server where their session exists. To use this redirection method, client computers must be able to connect directly by IP address to RD Session Host servers in the farm.\r\n\r\nIf you disable this policy setting, the IP address of the RD Session Host server is not sent to the client. Instead, the IP address is embedded in a token. When a client reconnects to the load balancer, the routing token is used to redirect the client to their existing session on the correct RD Session Host server in the farm. Only disable this setting when your network load-balancing solution supports the use of RD Connection Broker routing tokens and you do not want clients to directly connect by IP address to RD Session Host servers in the load-balanced farm.\r\n\r\nIf you do not configure this policy setting, the Use IP address redirection policy setting is not enforced at the group Group policy Policy level and the default will be used. This setting is enabled by default.\r\n\r\nNotes:\r\n\r\n 1. For Windows Server 2008, this policy setting is supported on at least Windows Server 2008 Standard.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sd-expose-address"],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_expose_address_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_expose_address_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_loc","displayName":"Configure RD Connection Broker server name","description":"This policy setting allows you to specify the RD Connection Broker server that the RD Session Host server uses to track and redirect user sessions for a load-balanced RD Session Host server farm. The specified server must be running the Remote Desktop Connection Broker service. All RD Session Host servers in a load-balanced farm should use the same RD Connection Broker server.\r\n\r\nIf you enable this policy setting, you must specify the RD Connection Broker server by using its fully qualified domain name (FQDN). In Windows Server 2012, for a high availability setup with multiple RD Connection Broker servers, you must provide a semi-colon separated list of the FQDNs of all the RD Connection Broker servers.\r\n\r\nIf you disable or do not configure this policy setting, the policy setting is not specified at the Group Policy level.\r\n\r\nNotes:\r\n\r\n 1. For Windows Server 2008, this policy setting is supported on at least Windows Server 2008 Standard.\r\n\r\n 2. This policy setting is not effective unless the Join RD Connection Broker policy setting is enabled.\r\n\r\n 3. To be an active member of an RD Session Host server farm, the computer account for each RD Session Host server in the farm must be a member of one of the following local groups on the RD Connection Broker server: Session Directory Computers, Session Broker Computers, or RDS Endpoint Servers.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sd-loc"],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_loc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_loc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_loc_ts_sd_loc","displayName":"Configure RD Connection Broker server name:","description":null,"helpText":"","infoUrls":[],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy","displayName":"Require use of specific security layer for remote (RDP) connections","description":"This policy setting specifies whether to require the use of a specific security layer to secure communications between clients and RD Session Host servers during Remote Desktop Protocol (RDP) connections.\r\n\r\nIf you enable this policy setting, all communications between clients and RD Session Host servers during remote connections must use the security method specified in this setting. The following security methods are available:\r\n\r\n* Negotiate: The Negotiate method enforces the most secure method that is supported by the client. If Transport Layer Security (TLS) version 1.0 is supported, it is used to authenticate the RD Session Host server. If TLS is not supported, native Remote Desktop Protocol (RDP) encryption is used to secure communications, but the RD Session Host server is not authenticated. Native RDP encryption (as opposed to SSL encryption) is not recommended.\r\n\r\n* RDP: The RDP method uses native RDP encryption to secure communications between the client and RD Session Host server. If you select this setting, the RD Session Host server is not authenticated. Native RDP encryption (as opposed to SSL encryption) is not recommended.\r\n\r\n* SSL (TLS 1.0): The SSL method requires the use of TLS 1.0 to authenticate the RD Session Host server. If TLS is not supported, the connection fails. This is the recommended setting for this policy.\r\n\r\nIf you disable or do not configure this policy setting, the security method to be used for remote connections to RD Session Host servers is not specified at the Group Policy level.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-security-layer-policy"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_ts_security_layer","displayName":"Security Layer","description":null,"helpText":"","infoUrls":[],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_ts_security_layer_0","displayName":"RDP","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_ts_security_layer_1","displayName":"Negotiate","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_ts_security_layer_2","displayName":"SSL","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect","displayName":"Select network detection on the server","description":"This policy setting allows you to specify how the Remote Desktop Protocol will try to detect the network quality (bandwidth and latency).\r\n\r\nYou can choose to disable Connect Time Detect, Continuous Network Detect, or both Connect Time Detect and Continuous Network Detect. \r\n\r\nIf you disable Connect Time Detect, Remote Desktop Protocol will not determine the network quality at the connect time, and it will assume that all traffic to this server originates from a low-speed connection.\r\n\r\nIf you disable Continuous Network Detect, Remote Desktop Protocol will not try to adapt the remote user experience to varying network quality. \r\n\r\nIf you disable Connect Time Detect and Continuous Network Detect, Remote Desktop Protocol will not try to determine the network quality at the connect time; instead it will assume that all traffic to this server originates from a low-speed connection, and it will not try to adapt the user experience to varying network quality.\r\n\r\nIf you disable or do not configure this policy setting, Remote Desktop Protocol will spend up to a few seconds trying to determine the network quality prior to the connection, and it will continuously try to adapt the user experience to varying network quality.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-select-network-detect"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_ts_select_network_detect_level","displayName":"Select Network Detect Level","description":null,"helpText":"","infoUrls":[],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_ts_select_network_detect_level_0","displayName":"Use both Connect Time Detect and Continuous Network Detect","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_ts_select_network_detect_level_1","displayName":"Turn off Connect Time Detect","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_ts_select_network_detect_level_2","displayName":"Turn off Continuous Network Detect","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_ts_select_network_detect_level_3","displayName":"Turn off Connect Time Detect and Continuous Network Detect","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport","displayName":"Select RDP transport protocols","description":"This policy setting allows you to specify which protocols can be used for Remote Desktop Protocol (RDP) access to this server.\r\n\r\nIf you enable this policy setting, you must specify if you would like RDP to use UDP.\r\n\r\nYou can select one of the following options: \"Use both UDP and TCP\", \"Use only TCP\" or \"Use either UDP or TCP (default)\" \r\n\r\nIf you select \"Use either UDP or TCP\" and the UDP connection is successful, most of the RDP traffic will use UDP.\r\n\r\nIf the UDP connection is not successful or if you select \"Use only TCP,\" all of the RDP traffic will use TCP.\r\n\r\nIf you disable or do not configure this policy setting, RDP will choose the optimal protocols for delivering the best user experience.\r\n\t \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-select-transport"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport_ts_select_transport_type","displayName":"Select Transport Type","description":null,"helpText":"","infoUrls":[],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport_ts_select_transport_type_0","displayName":"Use both UDP and TCP","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport_ts_select_transport_type_1","displayName":"Use only TCP","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport_ts_select_transport_type_2","displayName":"Use either UDP or TCP","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_advanced_remotefx_remoteapp","displayName":"Use advanced RemoteFX graphics for RemoteApp","description":"This policy setting allows you to enable RemoteApp programs to use advanced graphics, including support for transparency, live thumbnails, and seamless application moves. This policy setting applies only to RemoteApp programs and does not apply to remote desktop sessions.\r\n\r\nIf you enable or do not configure this policy setting, RemoteApp programs published from this RD Session Host server will use these advanced graphics.\r\n\r\nIf you disable this policy setting, RemoteApp programs published from this RD Session Host server will not use these advanced graphics. You may want to choose this option if you discover that applications published as RemoteApp programs do not support these advanced graphics. \r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-advanced-remotefx-remoteapp"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_advanced_remotefx_remoteapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_advanced_remotefx_remoteapp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth","displayName":"Configure server authentication for client","description":"This policy setting allows you to specify whether the client will establish a connection to the RD Session Host server when the client cannot authenticate the RD Session Host server.\r\n\r\nIf you enable this policy setting, you must specify one of the following settings:\r\n\r\nAlways connect, even if authentication fails: The client connects to the RD Session Host server even if the client cannot authenticate the RD Session Host server.\r\n\r\nWarn me if authentication fails: The client attempts to authenticate the RD Session Host server. If the RD Session Host server can be authenticated, the client establishes a connection to the RD Session Host server. If the RD Session Host server cannot be authenticated, the user is prompted to choose whether to connect to the RD Session Host server without authenticating the RD Session Host server.\r\n\r\nDo not connect if authentication fails: The client establishes a connection to the RD Session Host server only if the RD Session Host server can be authenticated.\r\n\r\nIf you disable or do not configure this policy setting, the authentication setting that is specified in Remote Desktop Connection or in the .rdp file determines whether the client establishes a connection to the RD Session Host server when the client cannot authenticate the RD Session Host server.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-auth"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_ts_server_auth_level","displayName":"Authentication setting:","description":null,"helpText":"","infoUrls":[],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_ts_server_auth_level_0","displayName":"Always connect, even if authentication fails","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_ts_server_auth_level_2","displayName":"Warn me if authentication fails","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_ts_server_auth_level_1","displayName":"Do not connect if authentication fails","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc_hw_encode_preferred","displayName":"Configure H.264/AVC hardware encoding for Remote Desktop Connections","description":"This policy setting lets you enable H.264/AVC hardware encoding support for Remote Desktop Connections. When you enable hardware encoding, if an error occurs, we will attempt to use software encoding. If you disable or do not configure this policy, we will always use software encoding.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-avc-hw-encode-preferred"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc_hw_encode_preferred_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc_hw_encode_preferred_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc444_mode_preferred","displayName":"Prioritize H.264/AVC 444 graphics mode for Remote Desktop Connections","description":"This policy setting prioritizes the H.264/AVC 444 graphics mode for non-RemoteFX vGPU scenarios. When you use this setting on the RDP server, the server will use H.264/AVC 444 as the codec in an RDP 10 connection where both the client and server can use H.264/AVC 444.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-avc444-mode-preferred"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc444_mode_preferred_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc444_mode_preferred_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor","displayName":"Configure compression for RemoteFX data","description":"This policy setting allows you to specify which Remote Desktop Protocol (RDP) compression algorithm to use.\r\n\r\nBy default, servers use an RDP compression algorithm that is based on the server's hardware configuration.\r\n\r\nIf you enable this policy setting, you can specify which RDP compression algorithm to use. If you select the algorithm that is optimized to use less memory, this option is less memory-intensive, but uses more network bandwidth. If you select the algorithm that is optimized to use less network bandwidth, this option uses less network bandwidth, but is more memory-intensive. Additionally, a third option is available that balances memory usage and network bandwidth. In Windows 8 only the compression algorithm that balances memory usage and bandwidth is used.\r\n\r\nYou can also choose not to use an RDP compression algorithm. Choosing not to use an RDP compression algorithm will use more network bandwidth and is only recommended if you are using a hardware device that is designed to optimize network traffic. Even if you choose not to use an RDP compression algorithm, some graphics data will still be compressed.\r\n\r\nIf you disable or do not configure this policy setting, the default RDP compression algorithm will be used.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-compressor"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_ts_compressor_levels","displayName":"RDP compression algorithm:","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_ts_compressor_levels_1","displayName":"Optimized to use less memory","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_ts_compressor_levels_3","displayName":"Optimized to use less network bandwidth","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_ts_compressor_levels_2","displayName":"Balances memory and network bandwidth","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_ts_compressor_levels_0","displayName":"Do not use an RDP compression algorithm","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality","displayName":"Configure image quality for RemoteFX Adaptive Graphics","description":"This policy setting allows you to specify the visual quality for remote users when connecting to this computer by using Remote Desktop Connection. You can use this policy setting to balance the network bandwidth usage with the visual quality that is delivered.\r\n If you enable this policy setting and set quality to Low, RemoteFX Adaptive Graphics uses an encoding mechanism that results in low quality images. This mode consumes the lowest amount of network bandwidth of the quality modes.\r\n If you enable this policy setting and set quality to Medium, RemoteFX Adaptive Graphics uses an encoding mechanism that results in medium quality images. This mode provides better graphics quality than low quality and uses less bandwidth than high quality.\r\n If you enable this policy setting and set quality to High, RemoteFX Adaptive Graphics uses an encoding mechanism that results in high quality images and consumes moderate network bandwidth.\r\n If you enable this policy setting and set quality to Lossless, RemoteFX Adaptive Graphics uses lossless encoding. In this mode, the color integrity of the graphics data is not impacted. However, this setting results in a significant increase in network bandwidth consumption. We recommend that you set this for very specific cases only.\r\n If you disable or do not configure this policy setting, RemoteFX Adaptive Graphics uses an encoding mechanism that results in medium quality images.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-image-quality"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_ts_server_image_quality_levels","displayName":"Image quality:","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_ts_server_image_quality_levels_1","displayName":"Lossless","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_ts_server_image_quality_levels_2","displayName":"High","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_ts_server_image_quality_levels_3","displayName":"Medium","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_ts_server_image_quality_levels_4","displayName":"Low","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_legacy_rfx","displayName":"Enable RemoteFX encoding for RemoteFX clients designed for Windows Server 2008 R2 SP1","description":"This policy setting allows you to configure graphics encoding to use the RemoteFX Codec on the Remote Desktop Session Host server so that the sessions are compatible with non-Windows thin client devices designed for Windows Server 2008 R2 SP1. These clients only support the Windows Server 2008 R2 SP1 RemoteFX Codec.If you enable this policy setting, users' sessions on this server will only use the Windows Server 2008 R2 SP1 RemoteFX Codec for encoding. This mode is compatible with thin client devices that only support the Windows Server 2008 R2 SP1 RemoteFX Codec.If you disable or do not configure this policy setting, non-Windows thin clients that only support the Windows Server 2008 R2 SP1 RemoteFX Codec will not be able to connect to this server. This policy setting applies only to clients that are using Remote Desktop Protocol (RDP) 7.1, and does not affect clients that are using other RDP versions.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-legacy-rfx"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_legacy_rfx_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_legacy_rfx_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile","displayName":"Configure RemoteFX Adaptive Graphics","description":"This policy setting allows the administrator to configure the RemoteFX experience for Remote Desktop Session Host or Remote Desktop Virtualization Host servers. By default, the system will choose the best experience based on available nework bandwidth.\r\n\r\nIf you enable this policy setting, the RemoteFX experience could be set to one of the following options:\r\n1. Let the system choose the experience for the network condition\r\n2. Optimize for server scalability\r\n3. Optimize for minimum bandwidth usage\r\n\r\nIf you disable or do not configure this policy setting, the RemoteFX experience will change dynamically based on the network condition.\"\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-profile"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile_ts_server_profile_levels","displayName":"RDP experience:","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile_ts_server_profile_levels_2","displayName":"Let the system choose experience for network condition","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile_ts_server_profile_levels_1","displayName":"Optimize for server scalability","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile_ts_server_profile_levels_3","displayName":"Optimize for minimum bandwidth usage","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp","displayName":"Optimize visual experience for Remote Desktop Service Sessions","description":"This policy setting allows you to specify the visual experience that remote users receive in Remote Desktop Services sessions. Remote sessions on the remote computer are then optimized to support this visual experience.\r\n\r\nBy default, Remote Desktop Services sessions are optimized for rich multimedia, such as applications that use Silverlight or Windows Presentation Foundation.\r\n\r\nIf you enable this policy setting, you must select the visual experience for which you want to optimize Remote Desktop Services sessions. You can select either Rich multimedia or Text.\r\n\r\nIf you disable or do not configure this policy setting, Remote Desktop Services sessions are optimized for rich multimedia.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-visexp"],"categoryId":"b7bde490-eac6-4f57-8808-e0786b8191a1","categoryName":"Remote FX for Windows Server 2008 R2","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_ts_visexp_settings","displayName":"Visual experience:","description":null,"helpText":"","infoUrls":[],"categoryId":"b7bde490-eac6-4f57-8808-e0786b8191a1","categoryName":"Remote FX for Windows Server 2008 R2","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_ts_visexp_settings_1","displayName":"Rich multimedia","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_ts_visexp_settings_2","displayName":"Text","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_wddm_graphics_driver","displayName":"Use WDDM graphics display driver for Remote Desktop Connections","description":"This policy setting lets you enable WDDM graphics display driver for Remote Desktop Connections.\r\n\r\nIf you enable or do not configure this policy setting, Remote Desktop Connections will use WDDM graphics display driver.\r\n\r\nIf you disable this policy setting, Remote Desktop Connections will NOT use WDDM graphics display driver. In this case, the Remote Desktop Connections will use XDDM graphics display driver.\r\n\r\nFor this change to take effect, you must restart Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-wddm-graphics-driver"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_wddm_graphics_driver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_wddm_graphics_driver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_session_end_on_limit_2","displayName":"End session when time limits are reached","description":"This policy setting specifies whether to end a Remote Desktop Services session that has timed out instead of disconnecting it.\r\n\r\nYou can use this setting to direct Remote Desktop Services to end a session (that is, the user is logged off and the session is deleted from the server) after time limits for active or idle sessions are reached. By default, Remote Desktop Services disconnects sessions that reach their time limits.\r\n\r\nTime limits are set locally by the server administrator or by using Group Policy. See the policy settings Set time limit for active Remote Desktop Services sessions and Set time limit for active but idle Remote Desktop Services sessions policy settings.\r\n\r\nIf you enable this policy setting, Remote Desktop Services ends any session that reaches its time-out limit.\r\n\r\nIf you disable this policy setting, Remote Desktop Services always disconnects a timed-out session, even if specified otherwise by the server administrator.\r\n\r\nIf you do not configure this policy setting, Remote Desktop Services disconnects a timed-out session, unless specified otherwise in local settings.\r\n\r\nNote: This policy setting only applies to time-out limits that are explicitly set by the administrator. This policy setting does not apply to time-out events that occur due to connectivity or network conditions. This setting appears in both Computer Configuration and User Configuration. If both settings are configured, the Computer Configuration setting takes precedence.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-session-end-on-limit-2"],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_session_end_on_limit_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_session_end_on_limit_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2","displayName":"Set time limit for disconnected sessions","description":"This policy setting allows you to configure a time limit for disconnected Remote Desktop Services sessions.\r\n\r\nYou can use this policy setting to specify the maximum amount of time that a disconnected session remains active on the server. By default, Remote Desktop Services allows users to disconnect from a Remote Desktop Services session without logging off and ending the session.\r\n\r\nWhen a session is in a disconnected state, running programs are kept active even though the user is no longer actively connected. By default, these disconnected sessions are maintained for an unlimited time on the server.\r\n\r\nIf you enable this policy setting, disconnected sessions are deleted from the server after the specified amount of time. To enforce the default behavior that disconnected sessions are maintained for an unlimited time, select Never. If you have a console session, disconnected session time limits do not apply.\r\n\r\n\r\nIf you disable or do not configure this policy setting, this policy setting is not specified at the Group Policy level. Be y default, Remote Desktop Services disconnected sessions are maintained for an unlimited amount of time. \r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the Computer Configuration policy setting takes precedence.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sessions-disconnected-timeout-2"],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected","displayName":"End a disconnected session","description":null,"helpText":"","infoUrls":[],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_60000","displayName":"1 minute","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_300000","displayName":"5 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_600000","displayName":"10 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_900000","displayName":"15 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_1800000","displayName":"30 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_3600000","displayName":"1 hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_7200000","displayName":"2 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_10800000","displayName":"3 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_21600000","displayName":"6 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_28800000","displayName":"8 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_43200000","displayName":"12 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_57600000","displayName":"16 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_64800000","displayName":"18 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_86400000","displayName":"1 day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_172800000","displayName":"2 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_259200000","displayName":"3 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_345600000","displayName":"4 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_432000000","displayName":"5 days","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2","displayName":"Set time limit for active but idle Remote Desktop Services sessions","description":"This policy setting allows you to specify the maximum amount of time that an active Remote Desktop Services session can be idle (without user input) before it is automatically disconnected.\r\n\r\nIf you enable this policy setting, you must select the desired time limit in the Idle session limit list. Remote Desktop Services will automatically disconnect active but idle sessions after the specified amount of time. The user receives a warning two minutes before the session disconnects, which allows the user to press a key or move the mouse to keep the session active. If you have a console session, idle session time limits do not apply.\r\n\r\nIf you disable or do not configure this policy setting, the time limit is not specified at the Group Policy level. By default, Remote Desktop Services allows sessions to remain active but idle for an unlimited amount of time. \r\n\r\nIf you want Remote Desktop Services to end instead of disconnect a session when the time limit is reached, you can configure the policy setting Computer Configuration\\Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Session Time Limits\\End session when time limits are reached.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the Computer Configuration policy setting takes precedence.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sessions-idle-limit-2"],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext","displayName":"Idle session limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_60000","displayName":"1 minute","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_300000","displayName":"5 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_600000","displayName":"10 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_900000","displayName":"15 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_1800000","displayName":"30 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_3600000","displayName":"1 hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_7200000","displayName":"2 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_10800000","displayName":"3 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_21600000","displayName":"6 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_28800000","displayName":"8 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_43200000","displayName":"12 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_57600000","displayName":"16 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_64800000","displayName":"18 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_86400000","displayName":"1 day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_172800000","displayName":"2 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_259200000","displayName":"3 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_345600000","displayName":"4 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_432000000","displayName":"5 days","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2","displayName":"Set time limit for active Remote Desktop Services sessions","description":"This policy setting allows you to specify the maximum amount of time that a Remote Desktop Services session can be active before it is automatically disconnected.\r\n\r\nIf you enable this policy setting, you must select the desired time limit in the Active session limit list. Remote Desktop Services will automatically disconnect active sessions after the specified amount of time. The user receives a warning two minutes before the Remote Desktop Services session disconnects, which allows the user to save open files and close programs. If you have a console session, active session time limits do not apply.\r\n\r\nIf you disable or do not configure this policy setting, this policy setting is not specified at the Group Policy level. By default, Remote Desktop Services allows sessions to remain active for an unlimited amount of time. \r\n\r\nIf you want Remote Desktop Services to end instead of disconnect a session when the time limit is reached, you can configure the policy setting Computer Configuration\\Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Session Time Limits\\End session when time limits are reached.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the Computer Configuration policy setting takes precedence.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sessions-limits-2"],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit","displayName":"Active session limit :","description":null,"helpText":"","infoUrls":[],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_60000","displayName":"1 minute","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_300000","displayName":"5 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_600000","displayName":"10 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_900000","displayName":"15 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_1800000","displayName":"30 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_3600000","displayName":"1 hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_7200000","displayName":"2 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_10800000","displayName":"3 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_21600000","displayName":"6 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_28800000","displayName":"8 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_43200000","displayName":"12 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_57600000","displayName":"16 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_64800000","displayName":"18 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_86400000","displayName":"1 day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_172800000","displayName":"2 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_259200000","displayName":"3 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_345600000","displayName":"4 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_432000000","displayName":"5 days","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_single_session","displayName":"Restrict Remote Desktop Services users to a single Remote Desktop Services session","description":"This policy setting allows you to restrict users to a single Remote Desktop Services session.\r\n\r\nIf you enable this policy setting, users who log on remotely by using Remote Desktop Services will be restricted to a single session (either active or disconnected) on that server. If the user leaves the session in a disconnected state, the user automatically reconnects to that session at the next logon.\r\n\r\nIf you disable this policy setting, users are allowed to make unlimited simultaneous remote connections by using Remote Desktop Services.\r\n\r\nIf you do not configure this policy setting, this policy setting is not specified at the Group Policy level.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-single-session"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_single_session_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_single_session_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_smart_card","displayName":"Do not allow smart card device redirection","description":"This policy setting allows you to control the redirection of smart card devices in a Remote Desktop Services session.\r\n\r\nIf you enable this policy setting, Remote Desktop Services users cannot use a smart card to log on to a Remote Desktop Services session.\r\n\r\nIf you disable or do not configure this policy setting, smart card device redirection is allowed. By default, Remote Desktop Services automatically redirects smart card devices on connection.\r\n\r\nNote: The client computer must be running at least Microsoft Windows 2000 Server or at least Microsoft Windows XP Professional and the target server must be joined to a domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-smart-card"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_smart_card_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_smart_card_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2","displayName":"Start a program on connection","description":"Configures Remote Desktop Services to run a specified program automatically upon connection.\r\n\r\nYou can use this setting to specify a program to run automatically when a user logs on to a remote computer.\r\n\r\nBy default, Remote Desktop Services sessions provide access to the full Windows desktop, unless otherwise specified with this setting, by the server administrator, or by the user in configuring the client connection. Enabling this setting overrides the \"Start Program\" settings set by the server administrator or user. The Start menu and Windows Desktop are not displayed, and when the user exits the program the session is automatically logged off.\r\n\r\nTo use this setting, in Program path and file name, type the fully qualified path and file name of the executable file to be run when the user logs on. If necessary, in Working Directory, type the fully qualified path to the starting directory for the program. If you leave Working Directory blank, the program runs with its default working directory. If the specified program path, file name, or working directory is not the name of a valid directory, the RD Session Host server connection fails with an error message.\r\n\r\nIf the status is set to Enabled, Remote Desktop Services sessions automatically run the specified program and use the specified Working Directory (or the program default directory, if Working Directory is not specified) as the working directory for the program.\r\n\r\nIf the status is set to Disabled or Not Configured, Remote Desktop Services sessions start with the full desktop, unless the server administrator or user specify otherwise. (See \"Computer Configuration\\Administrative Templates\\System\\Logon\\Run these programs at user logon\" setting.)\r\n\r\nNote: This setting appears in both Computer Configuration and User Configuration. If both settings are configured, the Computer Configuration setting overrides.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-start-program-2"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_ts_program_name","displayName":"Program path and file name","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_ts_workdir","displayName":"Working Directory","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_delete","displayName":"Do not delete temp folders upon exit","description":"This policy setting specifies whether Remote Desktop Services retains a user's per-session temporary folders at logoff.\r\n\r\nYou can use this setting to maintain a user's session-specific temporary folders on a remote computer, even if the user logs off from a session. By default, Remote Desktop Services deletes a user's temporary folders when the user logs off.\r\n\r\nIf you enable this policy setting, a user's per-session temporary folders are retained when the user logs off from a session.\r\n\r\nIf you disable this policy setting, temporary folders are deleted when a user logs off, even if the server administrator specifies otherwise.\r\n\r\nIf you do not configure this policy setting, Remote Desktop Services deletes the temporary folders from the remote computer at logoff, unless specified otherwise by the server administrator.\r\n\r\nNote: This setting only takes effect if per-session temporary folders are in use on the server. If you enable the Do not use temporary folders per session policy setting, this policy setting has no effect.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-temp-delete"],"categoryId":"b40b8f80-c0e6-4494-8085-f90cadc167a9","categoryName":"Temporary folders","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_delete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_delete_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_per_session","displayName":"Do not use temporary folders per session","description":"This policy setting allows you to prevent Remote Desktop Services from creating session-specific temporary folders.\r\n\r\nYou can use this policy setting to disable the creation of separate temporary folders on a remote computer for each session. By default, Remote Desktop Services creates a separate temporary folder for each active session that a user maintains on a remote computer. These temporary folders are created on the remote computer in a Temp folder under the user's profile folder and are named with the sessionid.\r\n\r\nIf you enable this policy setting, per-session temporary folders are not created. Instead, a user's temporary files for all sessions on the remote computer are stored in a common Temp folder under the user's profile folder on the remote computer.\r\n\r\nIf you disable this policy setting, per-session temporary folders are always created, even if the server administrator specifies otherwise.\r\n\r\nIf you do not configure this policy setting, per-session temporary folders are created unless the server administrator specifies otherwise.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-temp-per-session"],"categoryId":"b40b8f80-c0e6-4494-8085-f90cadc167a9","categoryName":"Temporary folders","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_per_session_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_per_session_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_time_zone","displayName":"Allow time zone redirection","description":"This policy setting determines whether the client computer redirects its time zone settings to the Remote Desktop Services session.\r\n\r\nIf you enable this policy setting, clients that are capable of time zone redirection send their time zone information to the server. The server base time is then used to calculate the current session time (current session time = server base time + client time zone).\r\n\r\nIf you disable or do not configure this policy setting, the client computer does not redirect its time zone information and the session time zone is the same as the server time zone.\r\n\r\nNote: Time zone redirection is possible only when connecting to at least a Microsoft Windows Server 2003 terminal server with a client using RDP 5.1 and later.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-time-zone"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_time_zone_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_time_zone_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_tscc_permissions_policy","displayName":"Do not allow local administrators to customize permissions","description":"This policy setting specifies whether to disable the administrator rights to customize security permissions for the Remote Desktop Session Host server. \r\n\r\nYou can use this setting to prevent administrators from making changes to the user groups allowed to connect remotely to the RD Session Host server. By default, administrators are able to make such changes.\r\n\r\nIf you enable this policy setting the default security descriptors for existing groups on the RD Session Host server cannot be changed. All the security descriptors are read-only.\r\n\r\nIf you disable or do not configure this policy setting, server administrators have full read/write permissions to the user security descriptors by using the Remote Desktop Session WMI Provider.\r\n\r\nNote: The preferred method of managing user access is by adding a user to the Remote Desktop Users group.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-tscc-permissions-policy"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_tscc_permissions_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_tscc_permissions_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_turnoff_singleapp","displayName":"Always show desktop on connection","description":"This policy setting determines whether the desktop is always displayed after a client connects to a remote computer or an initial program can run. It can be used to require that the desktop be displayed after a client connects to a remote computer, even if an initial program is already specified in the default user profile, Remote Desktop Connection, Remote Desktop Services client, or through Group Policy.\r\n\r\nIf you enable this policy setting, the desktop is always displayed when a client connects to a remote computer. This policy setting overrides any initial program policy settings.\r\n\r\nIf you disable or do not configure this policy setting, an initial program can be specified that runs on the remote computer after the client connects to the remote computer. If an initial program is not specified, the desktop is always displayed on the remote computer after the client connects to the remote computer.\r\n\r\nNote: If this policy setting is enabled, then the \"Start a program on connection\" policy setting is ignored.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-turnoff-singleapp"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_turnoff_singleapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_turnoff_singleapp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable","displayName":"Allow RDP redirection of other supported RemoteFX USB devices from this computer","description":"This policy setting allows you to permit RDP redirection of other supported RemoteFX USB devices from this computer. Redirected RemoteFX USB devices will not be available for local usage on this computer.\r\n\r\nIf you enable this policy setting, you can choose to give the ability to redirect other supported RemoteFX USB devices over RDP to all users or only to users who are in the Administrators group on the computer.\r\n\r\nIf you disable or do not configure this policy setting, other supported RemoteFX USB devices are not available for RDP redirection by using any user account.\r\n\r\nFor this change to take effect, you must restart Windows.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-usb-redirection-disable"],"categoryId":"e6b767af-2ce1-4c91-9360-15abbb0bf3bc","categoryName":"Remote FX USB Device Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_usbaccessright","displayName":"RemoteFX USB Redirection Access Rights","description":null,"helpText":"","infoUrls":[],"categoryId":"e6b767af-2ce1-4c91-9360-15abbb0bf3bc","categoryName":"Remote FX USB Device Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_usbaccessright_1","displayName":"Adminstrators Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_usbaccessright_2","displayName":"Adminstrators and Users","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_authentication_policy","displayName":"Require user authentication for remote connections by using Network Level Authentication","description":"This policy setting allows you to specify whether to require user authentication for remote connections to the RD Session Host server by using Network Level Authentication. This policy setting enhances security by requiring that user authentication occur earlier in the remote connection process.\r\n\r\nIf you enable this policy setting, only client computers that support Network Level Authentication can connect to the RD Session Host server.\r\n\r\nTo determine whether a client computer supports Network Level Authentication, start Remote Desktop Connection on the client computer, click the icon in the upper-left corner of the Remote Desktop Connection dialog box, and then click About. In the About Remote Desktop Connection dialog box, look for the phrase Network Level Authentication supported.\r\n\r\nIf you disable this policy setting, Network Level Authentication is not required for user authentication before allowing remote connections to the RD Session Host server.\r\n\r\nIf you do not configure this policy setting, the local setting on the target computer will be enforced. On Windows Server 2012 and Windows 8, Network Level Authentication is enforced by default.\r\n\r\nImportant: Disabling this policy setting provides less security because user authentication will occur later in the remote connection process.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-user-authentication-policy"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_authentication_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_authentication_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home","displayName":"Set Remote Desktop Services User Home Directory","description":"Specifies whether Remote Desktop Services uses the specified network share or local directory path as the root of the user's home directory for a Remote Desktop Services session.\r\n\r\nTo use this setting, select the location for the home directory (network or local) from the Location drop-down list. If you choose to place the directory on a network share, type the Home Dir Root Path in the form \\\\Computername\\Sharename, and then select the drive letter to which you want the network share to be mapped.\r\n\r\nIf you choose to keep the home directory on the local computer, type the Home Dir Root Path in the form \"Drive:\\Path\" (without quotes), without environment variables or ellipses. Do not specify a placeholder for user alias, because Remote Desktop Services automatically appends this at logon.\r\n\r\nNote: The Drive Letter field is ignored if you choose to specify a local path. If you choose to specify a local path but then type the name of a network share in Home Dir Root Path, Remote Desktop Services places user home directories in the network location.\r\n\r\nIf the status is set to Enabled, Remote Desktop Services creates the user's home directory in the specified location on the local computer or the network. The home directory path for each user is the specified Home Dir Root Path and the user's alias.\r\n\r\nIf the status is set to Disabled or Not Configured, the user's home directory is as specified at the server.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-user-home"],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter","displayName":"Drive Letter","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_g:","displayName":"G:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_h:","displayName":"H:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_i:","displayName":"I:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_j:","displayName":"J:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_k:","displayName":"K:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_l:","displayName":"L:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_m:","displayName":"M:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_n:","displayName":"N:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_o:","displayName":"O:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_p:","displayName":"P:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_q:","displayName":"Q:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_r:","displayName":"R:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_s:","displayName":"S:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_t:","displayName":"T:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_u:","displayName":"U:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_v:","displayName":"V:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_w:","displayName":"W:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_x:","displayName":"X:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_y:","displayName":"Y:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_z:","displayName":"Z:","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_home_dir","displayName":"Home Dir Root Path:","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_user_home_location","displayName":"Location:","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_user_home_location_1","displayName":"On the Network","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_user_home_location_0","displayName":"On the Local machine","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_mandatory_profiles","displayName":"Use mandatory profiles on the RD Session Host server","description":"This policy setting allows you to specify whether Remote Desktop Services uses a mandatory profile for all users connecting remotely to the RD Session Host server.\r\n\r\nIf you enable this policy setting, Remote Desktop Services uses the path specified in the \"Set path for Remote Desktop Services Roaming User Profile\" policy setting as the root folder for the mandatory user profile. All users connecting remotely to the RD Session Host server use the same user profile.\r\n\r\nIf you disable or do not configure this policy setting, mandatory user profiles are not used by users connecting remotely to the RD Session Host server.\r\n\r\nNote:\r\n\r\nFor this policy setting to take effect, you must also enable and configure the \"Set path for Remote Desktop Services Roaming User Profile\" policy setting.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-user-mandatory-profiles"],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_mandatory_profiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_mandatory_profiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_profiles","displayName":"Set path for Remote Desktop Services Roaming User Profile","description":"This policy setting allows you to specify the network path that Remote Desktop Services uses for roaming user profiles.\r\n\r\nBy default, Remote Desktop Services stores all user profiles locally on the RD Session Host server. You can use this policy setting to specify a network share where user profiles can be centrally stored, allowing a user to access the same profile for sessions on all RD Session Host servers that are configured to use the network share for user profiles.\r\n\r\nIf you enable this policy setting, Remote Desktop Services uses the specified path as the root directory for all user profiles. The profiles are contained in subfolders named for the account name of each user.\r\n\r\nTo configure this policy setting, type the path to the network share in the form of \\\\Computername\\Sharename. Do not specify a placeholder for the user account name, because Remote Desktop Services automatically adds this when the user logs on and the profile is created. If the specified network share does not exist, Remote Desktop Services displays an error message on the RD Session Host server and will store the user profiles locally on the RD Session Host server.\r\n\r\nIf you disable or do not configure this policy setting, user profiles are stored locally on the RD Session Host server. You can configure a user's profile path on the Remote Desktop Services Profile tab on the user's account Properties dialog box.\r\n\r\nNotes:\r\n1. The roaming user profiles enabled by the policy setting apply only to Remote Desktop Services connections. A user might also have a Windows roaming user profile configured. The Remote Desktop Services roaming user profile always takes precedence in a Remote Desktop Services session.\r\n2. To configure a mandatory Remote Desktop Services roaming user profile for all users connecting remotely to the RD Session Host server, use this policy setting together with the \"Use mandatory profiles on the RD Session Host server\" policy setting located in Computer Configuration\\Administrative Templates\\Windows Components\\Remote Desktop Services\\RD Session Host\\Profiles. The path set in the \"Set path for Remote Desktop Services Roaming User Profile\" policy setting should contain the mandatory profile.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-user-profiles"],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_profiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_profiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_profiles_ts_profile_path","displayName":"Profile path","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_touchinput_panningeverywhereoff_2","displayName":"Turn off Touch Panning","description":"Turn off Panning \r\nTurns off touch panning, which allows users pan inside windows by touch. On a compatible PC with a touch digitizer, by default users are able to scroll or pan inside a scrolling area by dragging up or down directly on the scrolling content.\r\n\r\nIf you enable this setting, the user will not be able to pan windows by touch. \r\n\r\nIf you disable this setting, the user can pan windows by touch.\r\n\r\nIf you do not configure this setting, Touch Panning is on by default.\r\n\r\nNote: Changes to this setting will not take effect until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-touchinput#admx-touchinput-panningeverywhereoff-2"],"categoryId":"abf781d7-1179-4f24-8d01-5611db14eddc","categoryName":"Touch Input","options":[{"id":"device_vendor_msft_policy_config_admx_touchinput_panningeverywhereoff_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_touchinput_panningeverywhereoff_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_touchinput_touchinputoff_2","displayName":"Turn off Tablet PC touch input","description":"Turn off Tablet PC touch input\r\n\r\nTurns off touch input, which allows the user to interact with their computer using their finger.\r\n\r\nIf you enable this setting, the user will not be able to produce input with touch. They will not be able to use touch input or touch gestures such as tap and double tap, the touch pointer, and other touch-specific features.\r\n\r\nIf you disable this setting, the user can produce input with touch, by using gestures, the touch pointer, and other-touch specific features.\r\n\r\nIf you do not configure this setting, touch input is on by default.\r\n\r\nNote: Changes to this setting will not take effect until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-touchinput#admx-touchinput-touchinputoff-2"],"categoryId":"abf781d7-1179-4f24-8d01-5611db14eddc","categoryName":"Touch Input","options":[{"id":"device_vendor_msft_policy_config_admx_touchinput_touchinputoff_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_touchinput_touchinputoff_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_blockedcommandslist_name","displayName":"Configure the list of blocked TPM commands","description":"This policy setting allows you to manage the Group Policy list of Trusted Platform Module (TPM) commands blocked by Windows.\r\n\r\nIf you enable this policy setting, Windows will block the specified commands from being sent to the TPM on the computer. TPM commands are referenced by a command number. For example, command number 129 is TPM_OwnerReadInternalPub, and command number 170 is TPM_FieldUpgrade. To find the command number associated with each TPM command with TPM 1.2, run \"tpm.msc\" and navigate to the \"Command Management\" section.\r\n\r\nIf you disable or do not configure this policy setting, only those TPM commands specified through the default or local lists may be blocked by Windows. The default list of blocked TPM commands is pre-configured by Windows. You can view the default list by running \"tpm.msc\", navigating to the \"Command Management\" section, and making visible the \"On Default Block List\" column. The local list of blocked TPM commands is configured outside of Group Policy by running \"tpm.msc\" or through scripting against the Win32_Tpm interface. See related policy settings to enforce or ignore the default and local lists of blocked TPM commands.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-blockedcommandslist-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_blockedcommandslist_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_blockedcommandslist_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_blockedcommandslist_name_blockedcommandslist_ordinals2","displayName":"The list of blocked TPM commands:","description":null,"helpText":"","infoUrls":[],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":null},{"id":"device_vendor_msft_policy_config_admx_tpm_cleartpmifnotready_name","displayName":"Configure the system to clear the TPM if it is not in a ready state.","description":"This policy setting configures the system to prompt the user to clear the TPM if the TPM is detected to be in any state other than Ready. This policy will take effect only if the system’s TPM is in a state other than Ready, including if the TPM is “Ready, with reduced functionality”. The prompt to clear the TPM will start occurring after the next reboot, upon user login only if the logged in user is part of the Administrators group for the system. The prompt can be dismissed, but will reappear after every reboot and login until the policy is disabled or until the TPM is in a Ready state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-cleartpmifnotready-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_cleartpmifnotready_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_cleartpmifnotready_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_ignoredefaultlist_name","displayName":"Ignore the default list of blocked TPM commands","description":"This policy setting allows you to enforce or ignore the computer's default list of blocked Trusted Platform Module (TPM) commands.\r\n\r\nIf you enable this policy setting, Windows will ignore the computer's default list of blocked TPM commands and will only block those TPM commands specified by Group Policy or the local list.\r\n\r\nThe default list of blocked TPM commands is pre-configured by Windows. You can view the default list by running \"tpm.msc\", navigating to the \"Command Management\" section, and making visible the \"On Default Block List\" column. The local list of blocked TPM commands is configured outside of Group Policy by running \"tpm.msc\" or through scripting against the Win32_Tpm interface. See the related policy setting to configure the Group Policy list of blocked TPM commands.\r\n\r\nIf you disable or do not configure this policy setting, Windows will block the TPM commands in the default list, in addition to commands in the Group Policy and local lists of blocked TPM commands. \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-ignoredefaultlist-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_ignoredefaultlist_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_ignoredefaultlist_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_ignorelocallist_name","displayName":"Ignore the local list of blocked TPM commands","description":"This policy setting allows you to enforce or ignore the computer's local list of blocked Trusted Platform Module (TPM) commands.\r\n\r\nIf you enable this policy setting, Windows will ignore the computer's local list of blocked TPM commands and will only block those TPM commands specified by Group Policy or the default list.\r\n\r\nThe local list of blocked TPM commands is configured outside of Group Policy by running \"tpm.msc\" or through scripting against the Win32_Tpm interface. The default list of blocked TPM commands is pre-configured by Windows. See the related policy setting to configure the Group Policy list of blocked TPM commands.\r\n\r\nIf you disable or do not configure this policy setting, Windows will block the TPM commands found in the local list, in addition to commands in the Group Policy and default lists of blocked TPM commands.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-ignorelocallist-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_ignorelocallist_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_ignorelocallist_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_optintodsha_name","displayName":"Enable Device Health Attestation Monitoring and Reporting","description":"This group policy enables Device Health Attestation reporting (DHA-report) on supported devices. It enables supported devices to send Device Health Attestation related information (device boot logs, PCR values, TPM certificate, etc.) to Device Health Attestation Service (DHA-Service) every time a device starts. Device Health Attestation Service validates the security state and health of the devices, and makes the findings accessible to enterprise administrators via a cloud based reporting portal. This policy is independent of DHA reports that are initiated by device manageability solutions (like MDM or SCCM), and will not interfere with their workflows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-optintodsha-name"],"categoryId":"99b4ac32-50b5-4659-a7a1-94bc708ae71a","categoryName":"Device Health Attestation Service","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_optintodsha_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_optintodsha_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name","displayName":"Configure the level of TPM owner authorization information available to the operating system","description":"This policy setting configures how much of the TPM owner authorization information is stored in the registry of the local computer. Depending on the amount of TPM owner authorization information stored locally, the operating system and TPM-based applications can perform certain TPM actions which require TPM owner authorization without requiring the user to enter the TPM owner password.\r\n\r\nYou can choose to have the operating system store either the full TPM owner authorization value, the TPM administrative delegation blob plus the TPM user delegation blob, or none.\r\n\r\nIf you enable this policy setting, Windows will store the TPM owner authorization in the registry of the local computer according to the operating system managed TPM authentication setting you choose.\r\n\r\nChoose the operating system managed TPM authentication setting of \"Full\" to store the full TPM owner authorization, the TPM administrative delegation blob and the TPM user delegation blob in the local registry. This setting allows use of the TPM without requiring remote or external storage of the TPM owner authorization value. This setting is appropriate for scenarios which do not depend on preventing reset of the TPM anti-hammering logic or changing the TPM owner authorization value. Some TPM-based applications may require this setting be changed before features which depend on the TPM anti-hammering logic can be used.\r\n\r\nChoose the operating system managed TPM authentication setting of \"Delegated\" to store only the TPM administrative delegation blob and the TPM user delegation blob in the local registry. This setting is appropriate for use with TPM-based applications that depend on the TPM anti-hammering logic.\r\n\r\nChoose the operating system managed TPM authentication setting of \"None\" for compatibility with previous operating systems and applications or for use with scenarios that require TPM owner authorization not be stored locally. Using this setting might cause issues with some TPM-based applications.\r\n\r\nNote: If the operating system managed TPM authentication setting is changed from \"Full\" to \"Delegated\", the full TPM owner authorization value will be regenerated and any copies of the original TPM owner authorization value will be invalid.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-osmanagedauth-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name_selectosmanagedauthlevel","displayName":"Operating system managed TPM authentication level:","description":null,"helpText":"","infoUrls":[],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name_selectosmanagedauthlevel_4","displayName":"Full","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name_selectosmanagedauthlevel_2","displayName":"Delegated","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name_selectosmanagedauthlevel_0","displayName":"None","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureduration_name","displayName":"Standard User Lockout Duration","description":"This policy setting allows you to manage the duration in minutes for counting standard user authorization failures for Trusted Platform Module (TPM) commands requiring authorization. If the number of TPM commands with an authorization failure within the duration equals a threshold, a standard user is prevented from sending commands requiring authorization to the TPM.\r\n\r\nThis setting helps administrators prevent the TPM hardware from entering a lockout mode because it slows the speed standard users can send commands requiring authorization to the TPM.\r\n\r\nAn authorization failure occurs each time a standard user sends a command to the TPM and receives an error response indicating an authorization failure occurred. Authorization failures older than this duration are ignored.\r\n\r\nFor each standard user two thresholds apply. Exceeding either threshold will prevent the standard user from sending a command to the TPM that requires authorization.\r\n\r\nThe Standard User Lockout Threshold Individual value is the maximum number of authorization failures each standard user may have before the user is not allowed to send commands requiring authorization to the TPM.\r\n\r\nThe Standard User Lockout Total Threshold value is the maximum total number of authorization failures all standard users may have before all standard users are not allowed to send commands requiring authorization to the TPM.\r\n\r\nThe TPM is designed to protect itself against password guessing attacks by entering a hardware lockout mode when it receives too many commands with an incorrect authorization value. When the TPM enters a lockout mode it is global for all users including administrators and Windows features like BitLocker Drive Encryption. The number of authorization failures a TPM allows and how long it stays locked out vary by TPM manufacturer. Some TPMs may enter lockout mode for successively longer periods of time with fewer authorization failures depending on past failures. Some TPMs may require a system restart to exit the lockout mode. Other TPMs may require the system to be on so enough clock cycles elapse before the TPM exits the lockout mode.\r\n\r\nAn administrator with the TPM owner password may fully reset the TPM's hardware lockout logic using the TPM Management Console (tpm.msc). Each time an administrator resets the TPM's hardware lockout logic all prior standard user TPM authorization failures are ignored; allowing standard users to use the TPM normally again immediately.\r\n\r\nIf this value is not configured, a default value of 480 minutes (8 hours) is used.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-standarduserauthorizationfailureduration-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureduration_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureduration_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureduration_name_dxt_standarduserauthorizationfailureduration_name","displayName":"Duration for counting TPM authorization failures (minutes):","description":null,"helpText":"","infoUrls":[],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":null},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureindividualthreshold_name","displayName":"Standard User Individual Lockout Threshold","description":"This policy setting allows you to manage the maximum number of authorization failures for each standard user for the Trusted Platform Module (TPM). If the number of authorization failures for the user within the duration for Standard User Lockout Duration equals this value, the standard user is prevented from sending commands to the Trusted Platform Module (TPM) that require authorization.\r\n\r\nThis setting helps administrators prevent the TPM hardware from entering a lockout mode because it slows the speed standard users can send commands requiring authorization to the TPM.\r\n\r\nAn authorization failure occurs each time a standard user sends a command to the TPM and receives an error response indicating an authorization failure occurred. Authorization failures older than the duration are ignored.\r\n\r\nFor each standard user two thresholds apply. Exceeding either threshold will prevent the standard user from sending a command to the TPM that requires authorization.\r\n\r\nThis value is the maximum number of authorization failures each standard user may have before the user is not allowed to send commands requiring authorization to the TPM.\r\n\r\nThe Standard User Lockout Total Threshold value is the maximum total number of authorization failures all standard users may have before all standard users are not allowed to send commands requiring authorization to the TPM.\r\n\r\nThe TPM is designed to protect itself against password guessing attacks by entering a hardware lockout mode when it receives too many commands with an incorrect authorization value. When the TPM enters a lockout mode it is global for all users including administrators and Windows features like BitLocker Drive Encryption. The number of authorization failures a TPM allows and how long it stays locked out vary by TPM manufacturer. Some TPMs may enter lockout mode for successively longer periods of time with fewer authorization failures depending on past failures. Some TPMs may require a system restart to exit the lockout mode. Other TPMs may require the system to be on so enough clock cycles elapse before the TPM exits the lockout mode.\r\n\r\nAn administrator with the TPM owner password may fully reset the TPM's hardware lockout logic using the TPM Management Console (tpm.msc). Each time an administrator resets the TPM's hardware lockout logic all prior standard user TPM authorization failures are ignored; allowing standard users to use the TPM normally again immediately.\r\n\r\nIf this value is not configured, a default value of 4 is used.\r\n\r\nA value of zero means the OS will not allow standard users to send commands to the TPM which may cause an authorization failure.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-standarduserauthorizationfailureindividualthreshold-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureindividualthreshold_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureindividualthreshold_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureindividualthreshold_name_dxt_standarduserauthorizationfailureindividualthreshold_name","displayName":"Maximum number of authorization failures per duration:","description":null,"helpText":"","infoUrls":[],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":null},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailuretotalthreshold_name","displayName":"Standard User Total Lockout Threshold","description":"This policy setting allows you to manage the maximum number of authorization failures for all standard users for the Trusted Platform Module (TPM). If the total number of authorization failures for all standard users within the duration for Standard User Lockout Duration equals this value, all standard users are prevented from sending commands to the Trusted Platform Module (TPM) that require authorization.\r\n\r\nThis setting helps administrators prevent the TPM hardware from entering a lockout mode because it slows the speed standard users can send commands requiring authorization to the TPM.\r\n\r\nAn authorization failure occurs each time a standard user sends a command to the TPM and receives an error response indicating an authorization failure occurred. Authorization failures older than the duration are ignored.\r\n\r\nFor each standard user two thresholds apply. Exceeding either threshold will prevent the standard user from sending a command to the TPM that requires authorization.\r\n\r\nThe Standard User Individual Lockout value is the maximum number of authorization failures each standard user may have before the user is not allowed to send commands requiring authorization to the TPM.\r\n\r\nThis value is the maximum total number of authorization failures all standard users may have before all standard users are not allowed to send commands requiring authorization to the TPM.\r\n\r\nThe TPM is designed to protect itself against password guessing attacks by entering a hardware lockout mode when it receives too many commands with an incorrect authorization value. When the TPM enters a lockout mode it is global for all users including administrators and Windows features like BitLocker Drive Encryption. The number of authorization failures a TPM allows and how long it stays locked out vary by TPM manufacturer. Some TPMs may enter lockout mode for successively longer periods of time with fewer authorization failures depending on past failures. Some TPMs may require a system restart to exit the lockout mode. Other TPMs may require the system to be on so enough clock cycles elapse before the TPM exits the lockout mode.\r\n\r\nAn administrator with the TPM owner password may fully reset the TPM's hardware lockout logic using the TPM Management Console (tpm.msc). Each time an administrator resets the TPM's hardware lockout logic all prior standard user TPM authorization failures are ignored; allowing standard users to use the TPM normally again immediately.\r\n\r\nIf this value is not configured, a default value of 9 is used.\r\n\r\nA value of zero means the OS will not allow standard users to send commands to the TPM which may cause an authorization failure.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-standarduserauthorizationfailuretotalthreshold-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailuretotalthreshold_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailuretotalthreshold_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailuretotalthreshold_name_dxt_standarduserauthorizationfailuretotalthreshold_name","displayName":"Maximum number of authorization failures per duration:","description":null,"helpText":"","infoUrls":[],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":null},{"id":"device_vendor_msft_policy_config_admx_tpm_uselegacydap_name","displayName":"Configure the system to use legacy Dictionary Attack Prevention Parameters setting for TPM 2.0.","description":"This policy setting configures the TPM to use the Dictionary Attack Prevention Parameters (lockout threshold and recovery time) to the values that were used for Windows 10 Version 1607 and below. Setting this policy will take effect only if a) the TPM was originally prepared using a version of Windows after Windows 10 Version 1607 and b) the System has a TPM 2.0. Note that enabling this policy will only take effect after the TPM maintenance task runs (which typically happens after a system restart). Once this policy has been enabled on a system and has taken effect (after a system restart), disabling it will have no impact and the system's TPM will remain configured using the legacy Dictionary Attack Prevention parameters, regardless of the value of this group policy. The only way for the disabled setting of this policy to take effect on a system where it was once enabled is to a) disable it from group policy and b)clear the TPM on the system.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-uselegacydap-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_uselegacydap_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_uselegacydap_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_calculator","displayName":"Calculator","description":"This policy setting configures the synchronization of user settings of Calculator.\r\nBy default, the user settings of Calculator synchronize between computers. Use the policy setting to prevent the user settings of Calculator from synchronization between computers. \r\nIf you enable this policy setting, the Calculator user settings continue to synchronize. \r\nIf you disable this policy setting, Calculator user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-calculator"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_calculator_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_calculator_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod","displayName":"Configure Sync Method","description":"This policy setting configures the sync provider used by User Experience Virtualization (UE-V) to sync settings between users’ computers. With Sync Method set to ”SyncProvider,” the UE-V Agent uses a built-in sync provider to keep user settings synchronized between the computer and the settings storage location. This is the default value. You can disable the sync provider on computers that never go offline and are always connected to the settings storage location.\r\nWhen SyncMethod is set to “None,” the UE-V Agent uses no sync provider. Settings are written directly to the settings storage location rather than being cached to sync later. \r\nSet SyncMethod to “External” when an external synchronization engine is being deployed for settings sync. This could use OneDrive, Work Folders, SharePoint or any other engine that uses a local folder to synchronize data between users’ computers. In this mode, UE-V writes settings data to the local folder specified in the settings storage path. These settings are then synchronized to other computers by an external synchronization engine. UE-V has no control over this synchronization. It only reads and writes the settings data when the normal UE-V triggers take place.\r\nWith notifications enabled, UE-V users receive a message when the settings sync is delayed. The notification delay policy setting defines the delay before a notification appears.\r\nIf you disable this policy setting, the sync provider is used to synchronize settings between computers and the settings storage location.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-configuresyncmethod"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_delay","displayName":"Notification delay (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_enable","displayName":"Enable notification","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_enable_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_enable_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_syncmethodconfiguration_list","displayName":"Sync Method:","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_syncmethodconfiguration_list_syncprovider","displayName":"SyncProvider","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_syncmethodconfiguration_list_none","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_syncmethodconfiguration_list_external","displayName":"External","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi","displayName":"VDI Configuration","description":"This policy setting configures the synchronization of User Experience Virtualization (UE-V) rollback information for computers running in a non-persistent, pooled VDI environment. UE-V settings rollback data and checkpoints are normally stored only on the local computer. With this policy setting enabled, the rollback information is copied to the settings storage location when the user logs off or shuts down their VDI session. Enable this setting to register a VDI-specific settings location template and restore data on computers in pooled VDI environments that reset to a clean state on logout. With this policy enabled you can roll settings back to the state when UE-V was installed or to “last-known-good” configurations. Only enable this policy setting on computers running in a non-persistent VDI environment. The VDI Collection Name defines the name of the virtual desktop collection containing the virtual computers. \r\nIf you enable this policy setting, the UE-V rollback state is copied to the settings storage location on logout and restored on login.\r\nIf you disable this policy setting, no UE-V rollback state is copied to the settings storage location.\r\nIf you do not configure this policy, no UE-V rollback state is copied to the settings storage location.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-configurevdi"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi_vdicollectionname","displayName":"VDI Collection Name:","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactitdescription","displayName":"Contact IT Link Text","description":"This policy setting specifies the text of the Contact IT URL hyperlink in the Company Settings Center.\r\nIf you enable this policy setting, the Company Settings Center displays the specified text in the link to the Contact IT URL.\r\nIf you disable this policy setting, the Company Settings Center does not display an IT Contact link.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-contactitdescription"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactitdescription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactitdescription_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactitdescription_contactitdescription","displayName":"Contact IT Link Text","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactiturl","displayName":"Contact IT URL","description":"This policy setting specifies the URL for the Contact IT link in the Company Settings Center.\r\nIf you enable this policy setting, the Company Settings Center Contact IT text links to the specified URL. The link can be of any standard protocol such as http or mailto. \r\nIf you disable this policy setting, the Company Settings Center does not display an IT Contact link.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-contactiturl"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactiturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactiturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactiturl_contactiturl","displayName":"Contact IT URL","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewin8sync","displayName":"Do not synchronize Windows Apps","description":"This policy setting defines whether the User Experience Virtualization (UE-V) Agent synchronizes settings for Windows apps.\r\nBy default, the UE-V Agent synchronizes settings for Windows apps between the computer and the settings storage location. \r\nIf you enable this policy setting, the UE-V Agent will not synchronize settings for Windows apps.\r\nIf you disable this policy setting, the UE-V Agent will synchronize settings for Windows apps. \r\nIf you do not configure this policy setting, any defined values are deleted.\r\nNote: If the user connects their Microsoft account for their computer then the UE-V Agent will not synchronize Windows apps. The Windows apps will default to whatever settings are configured in the Sync your settings configuration in Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-disablewin8sync"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewin8sync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewin8sync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings","displayName":"Synchronize Windows settings","description":"\r\nThis policy setting configures the synchronization of Windows settings between computers.\r\nCertain Windows settings will synchronize between computers by default. These settings include Windows themes, Windows desktop settings, Ease of Access settings, and network printers. Use this policy setting to specify which Windows settings synchronize between computers. You can also use these settings to enable synchronization of users' sign-in information for certain apps, networks, and certificates.\r\nIf you enable this policy setting, only the selected Windows settings synchronize. Unselected Windows settings are excluded from settings synchronization.\r\nIf you disable this policy setting, all Windows Settings are excluded from the settings synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-disablewindowsossettings"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_desktopsettings","displayName":"Desktop settings","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_desktopsettings_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_desktopsettings_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_easeofaccesssettings","displayName":"Ease of access","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_easeofaccesssettings_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_easeofaccesssettings_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_networkprinters","displayName":"Network Printers","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_networkprinters_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_networkprinters_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings","displayName":"Roaming Credentials","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_themesettings","displayName":"Themes","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_themesettings_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_themesettings_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_enableuev","displayName":"Enable UEV","description":"This policy setting allows you to enable or disable User Experience Virtualization (UE-V) feature. Reboot is needed for enable to take effect. With Auto-register inbox templates enabled, the UE-V inbox templates such as Office 2016 will be automatically registered when the UE-V Service is enabled. If this option is changed, it will only take effect when UE-V service is re-enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-enableuev"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_enableuev_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_enableuev_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_enableuev_registerinboxtemplates","displayName":"Auto-register inbox templates","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_enableuev_registerinboxtemplates_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_enableuev_registerinboxtemplates_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_finance","displayName":"Finance","description":"This policy setting configures the synchronization of user settings for the Finance app.\r\nBy default, the user settings of Finance sync between computers. Use the policy setting to prevent the user settings of Finance from synchronizing between computers.\r\nIf you enable this policy setting, Finance user settings continue to sync.\r\nIf you disable this policy setting, Finance user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-finance"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_finance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_finance_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_firstusenotificationenabled","displayName":"First Use Notification","description":"This policy setting enables a notification in the system tray that appears when the User Experience Virtualization (UE-V) Agent runs for the first time.\r\nBy default, a notification informs users that Company Settings Center, the user-facing name for the UE-V Agent, now helps to synchronize settings between their work computers.\r\nWith this setting enabled, the notification appears the first time that the UE-V Agent runs.\r\nWith this setting disabled, no notification appears.\r\nIf you do not configure this policy setting, any defined values are deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-firstusenotificationenabled"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_firstusenotificationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_firstusenotificationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_games","displayName":"Games","description":"This policy setting configures the synchronization of user settings for the Games app.\r\nBy default, the user settings of Games sync between computers. Use the policy setting to prevent the user settings of Games from synchronizing between computers.\r\nIf you enable this policy setting, Games user settings continue to sync.\r\nIf you disable this policy setting, Games user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-games"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_games_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_games_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10","displayName":"Internet Explorer 10","description":"This policy setting configures the synchronization of user settings of Internet Explorer 10.\r\nBy default, the user settings of Internet Explorer 10 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 10 from synchronization between computers. \r\nIf you enable this policy setting, the Internet Explorer 10 user settings continue to synchronize. \r\nIf you disable this policy setting, Internet Explorer 10 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer10"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer11","displayName":"Internet Explorer 11","description":"This policy setting configures the synchronization of user settings of Internet Explorer 11.\r\nBy default, the user settings of Internet Explorer 11 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 11 from synchronization between computers.\r\nIf you enable this policy setting, the Internet Explorer 11 user settings continue to synchronize.\r\nIf you disable this policy setting, Internet Explorer 11 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer11"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer8","displayName":"Internet Explorer 8","description":"This policy setting configures the synchronization of user settings for Internet Explorer 8.\r\nBy default, the user settings of Internet Explorer 8 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 8 from synchronization between computers. \r\nIf you enable this policy setting, the Internet Explorer 8 user settings continue to synchronize. \r\nIf you disable this policy setting, Internet Explorer 8 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer8"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer8_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer9","displayName":"Internet Explorer 9","description":"This policy setting configures the synchronization of user settings for Internet Explorer 9.\r\nBy default, the user settings of Internet Explorer 9 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 9 from synchronization between computers. \r\nIf you enable this policy setting, the Internet Explorer 9 user settings continue to synchronize. \r\nIf you disable this policy setting, Internet Explorer 9 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer9"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer9_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer9_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorercommon","displayName":"Internet Explorer Common Settings","description":"This policy setting configures the synchronization of user settings which are common between the versions of Internet Explorer.\r\nBy default, the user settings which are common between the versions of Internet Explorer synchronize between computers. Use the policy setting to prevent the user settings of Internet Explorer from synchronization between computers. \r\nIf you enable this policy setting, the user settings which are common between the versions of Internet Explorer continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the versions of Internet Explorer are excluded from settings synchronization. If any version of the Internet Explorer settings are enabled this policy setting should not be disabled.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorercommon"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorercommon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorercommon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maps","displayName":"Maps","description":"This policy setting configures the synchronization of user settings for the Maps app.\r\nBy default, the user settings of Maps sync between computers. Use the policy setting to prevent the user settings of Maps from synchronizing between computers.\r\nIf you enable this policy setting, Maps user settings continue to sync.\r\nIf you disable this policy setting, Maps user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-maps"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maxpackagesizeinbytes","displayName":"Settings package size warning threshold","description":"This policy setting allows you to configure the UE-V Agent to write a warning event to the event log when a settings package file size reaches a defined threshold. By default the UE-V Agent does not report information about package file size. \r\nIf you enable this policy setting, specify the threshold file size in bytes. When the settings package file exceeds this threshold the UE-V Agent will write a warning event to the event log.\r\nIf you disable or do not configure this policy setting, no event is written to the event log to report settings package size.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-maxpackagesizeinbytes"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maxpackagesizeinbytes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maxpackagesizeinbytes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maxpackagesizeinbytes_maxpackagesizeinbytes","displayName":"Package size threshold (in bytes):","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010access","displayName":"Microsoft Access 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Access 2010.\r\nBy default, the user settings of Microsoft Access 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Access 2010 from synchronization between computers. \r\nIf you enable this policy setting, Microsoft Access 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Access 2010 user settings are excluded from the synchronization settings. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010access"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010access_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010access_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010common","displayName":"Microsoft Office 2010 Common Settings","description":"This policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2010 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2010 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2010 applications from synchronization between computers. \r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2010 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2010 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2010 applications are enabled, this policy setting should not be disabled \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010common_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010excel","displayName":"Microsoft Excel 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Excel 2010.\r\nBy default, the user settings of Microsoft Excel 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Excel 2010 from synchronization between computers. \r\nIf you enable this policy setting, Microsoft Excel 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Excel 2010 user settings are excluded from the synchronization settings. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010excel"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010excel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010excel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010infopath","displayName":"Microsoft InfoPath 2010","description":"This policy setting configures the synchronization of user settings for Microsoft InfoPath 2010.\r\nBy default, the user settings of Microsoft InfoPath 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft InfoPath 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft InfoPath 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft InfoPath 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010infopath"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010infopath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010infopath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010lync","displayName":"Microsoft Lync 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Lync 2010.\r\nBy default, the user settings of Microsoft Lync 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Lync 2010 from synchronization between computers. \r\nIf you enable this policy setting, Microsoft Lync 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Lync 2010 user settings are excluded from the synchronization settings. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010lync"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010lync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010lync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010onenote","displayName":"Microsoft OneNote 2010","description":"This policy setting configures the synchronization of user settings for Microsoft OneNote 2010.\r\nBy default, the user settings of Microsoft OneNote 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010onenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010outlook","displayName":"Microsoft Outlook 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Outlook 2010.\r\nBy default, the user settings of Microsoft Outlook 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Outlook 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Outlook 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Outlook 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010outlook"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010outlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010outlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010powerpoint","displayName":"Microsoft PowerPoint 2010","description":"This policy setting configures the synchronization of user settings for Microsoft PowerPoint 2010.\r\nBy default, the user settings of Microsoft PowerPoint 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft PowerPoint 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft PowerPoint 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft PowerPoint 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010powerpoint"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010powerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010powerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010project","displayName":"Microsoft Project 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Project 2010.\r\nBy default, the user settings of Microsoft Project 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Project 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Project 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Project 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010project"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010project_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010project_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010publisher","displayName":"Microsoft Publisher 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Publisher 2010.\r\nBy default, the user settings of Microsoft Publisher 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Publisher 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Publisher 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Publisher 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010publisher"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010publisher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010publisher_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointdesigner","displayName":"Microsoft SharePoint Designer 2010","description":"This policy setting configures the synchronization of user settings for Microsoft SharePoint Designer 2010.\r\nBy default, the user settings of Microsoft SharePoint Designer 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Designer 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Designer 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Designer 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010sharepointdesigner"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointdesigner_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointdesigner_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace","displayName":"Microsoft SharePoint Workspace 2010","description":"This policy setting configures the synchronization of user settings for Microsoft SharePoint Workspace 2010.\r\nBy default, the user settings of Microsoft SharePoint Workspace 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Workspace 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Workspace 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Workspace 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010sharepointworkspace"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010visio","displayName":"Microsoft Visio 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Visio 2010.\r\nBy default, the user settings of Microsoft Visio 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Visio 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Visio 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Visio 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010visio"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010visio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010visio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010word","displayName":"Microsoft Word 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Word 2010.\r\nBy default, the user settings of Microsoft Word 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Word 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Word 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Word 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010word"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010word_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010word_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013access","displayName":"Microsoft Access 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Access 2013.\r\nBy default, the user settings of Microsoft Access 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Access 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Access 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Access 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013access"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013access_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013access_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013accessbackup","displayName":"Access 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Access 2013.\r\nMicrosoft Access 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Access 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Access 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Access 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013accessbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013accessbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013accessbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013common","displayName":"Microsoft Office 2013 Common Settings","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2013 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2013 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2013 applications from synchronization between computers.\r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2013 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2013 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2013 applications are enabled, this policy setting should not be disabled.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013common_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013commonbackup","displayName":"Common 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings which are common between the Microsoft Office Suite 2013 applications.\r\nMicrosoft Office Suite 2013 has user settings which are common between applications and are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific common Microsoft Office Suite 2013 applications.\r\nIf you enable this policy setting, certain user settings which are common between the Microsoft Office Suite 2013 applications will continue to be backed up.\r\nIf you disable this policy setting, certain user settings which are common between the Microsoft Office Suite 2013 applications will not be backed up. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013commonbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013commonbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013commonbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excel","displayName":"Microsoft Excel 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Excel 2013.\r\nBy default, the user settings of Microsoft Excel 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Excel 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Excel 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Excel 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013excel"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excelbackup","displayName":"Excel 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Excel 2013.\r\nMicrosoft Excel 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Excel 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Excel 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Excel 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013excelbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excelbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excelbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopath","displayName":"Microsoft InfoPath 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft InfoPath 2013.\r\nBy default, the user settings of Microsoft InfoPath 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft InfoPath 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft InfoPath 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft InfoPath 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013infopath"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup","displayName":"InfoPath 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft InfoPath 2013.\r\nMicrosoft InfoPath 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft InfoPath 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft InfoPath 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft InfoPath 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013infopathbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lync","displayName":"Microsoft Lync 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Lync 2013.\r\nBy default, the user settings of Microsoft Lync 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Lync 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Lync 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Lync 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013lync"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lyncbackup","displayName":"Lync 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Lync 2013.\r\nMicrosoft Lync 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Lync 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Lync 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Lync 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013lyncbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lyncbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lyncbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onedriveforbusiness","displayName":"Microsoft OneDrive for Business 2013","description":"\r\nThis policy setting configures the synchronization of user settings for OneDrive for Business 2013.\r\nBy default, the user settings of OneDrive for Business 2013 synchronize between computers. Use the policy setting to prevent the user settings of OneDrive for Business 2013 from synchronization between computers.\r\nIf you enable this policy setting, OneDrive for Business 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, OneDrive for Business 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013onedriveforbusiness"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onedriveforbusiness_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onedriveforbusiness_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenote","displayName":"Microsoft OneNote 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft OneNote 2013.\r\nBy default, the user settings of Microsoft OneNote 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenotebackup","displayName":"OneNote 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft OneNote 2013.\r\nMicrosoft OneNote 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft OneNote 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft OneNote 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft OneNote 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013onenotebackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenotebackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenotebackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlook","displayName":"Microsoft Outlook 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Outlook 2013.\r\nBy default, the user settings of Microsoft Outlook 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Outlook 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Outlook 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Outlook 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013outlook"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlookbackup","displayName":"Outlook 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Outlook 2013.\r\nMicrosoft Outlook 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Outlook 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Outlook 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Outlook 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013outlookbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlookbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlookbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpoint","displayName":"Microsoft PowerPoint 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft PowerPoint 2013.\r\nBy default, the user settings of Microsoft PowerPoint 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft PowerPoint 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft PowerPoint 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft PowerPoint 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013powerpoint"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpointbackup","displayName":"PowerPoint 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft PowerPoint 2013.\r\nMicrosoft PowerPoint 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft PowerPoint 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft PowerPoint 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft PowerPoint 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013powerpointbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpointbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpointbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013project","displayName":"Microsoft Project 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Project 2013.\r\nBy default, the user settings of Microsoft Project 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Project 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Project 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Project 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013project"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013project_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013project_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013projectbackup","displayName":"Project 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Project 2013.\r\nMicrosoft Project 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Project 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Project 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Project 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013projectbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013projectbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013projectbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisher","displayName":"Microsoft Publisher 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Publisher 2013.\r\nBy default, the user settings of Microsoft Publisher 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Publisher 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Publisher 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Publisher 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013publisher"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisher_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisherbackup","displayName":"Publisher 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Publisher 2013.\r\nMicrosoft Publisher 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Publisher 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Publisher 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Publisher 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013publisherbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisherbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisherbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesigner","displayName":"Microsoft SharePoint Designer 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft SharePoint Designer 2013.\r\nBy default, the user settings of Microsoft SharePoint Designer 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Designer 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Designer 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Designer 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013sharepointdesigner"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesigner_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesigner_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesignerbackup","displayName":"SharePoint Designer 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft SharePoint Designer 2013.\r\nMicrosoft SharePoint Designer 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft SharePoint Designer 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft SharePoint Designer 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft SharePoint Designer 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013sharepointdesignerbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesignerbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesignerbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013uploadcenter","displayName":"Microsoft Office 2013 Upload Center","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 2013 Upload Center.\r\nBy default, the user settings of Microsoft Office 2013 Upload Center synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Office 2013 Upload Center from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Office 2013 Upload Center user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Office 2013 Upload Center user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013uploadcenter"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013uploadcenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013uploadcenter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visio","displayName":"Microsoft Visio 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Visio 2013.\r\nBy default, the user settings of Microsoft Visio 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Visio 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Visio 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Visio 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013visio"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visiobackup","displayName":"Visio 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Visio 2013.\r\nMicrosoft Visio 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Visio 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Visio 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Visio 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013visiobackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visiobackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visiobackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013word","displayName":"Microsoft Word 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Word 2013.\r\nBy default, the user settings of Microsoft Word 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Word 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Word 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Word 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013word"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013word_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013word_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013wordbackup","displayName":"Word 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Word 2013.\r\nMicrosoft Word 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Word 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Word 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Word 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013wordbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013wordbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013wordbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016access","displayName":"Microsoft Access 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Access 2016.\r\nBy default, the user settings of Microsoft Access 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Access 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Access 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Access 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016access"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016access_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016access_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016accessbackup","displayName":"Access 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Access 2016.\r\nMicrosoft Access 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Access 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Access 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Access 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016accessbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016accessbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016accessbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common","displayName":"Microsoft Office 2016 Common Settings","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2016 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2016 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2016 applications from synchronization between computers.\r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2016 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2016 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2016 applications are enabled, this policy setting should not be disabled.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016commonbackup","displayName":"Common 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings which are common between the Microsoft Office Suite 2016 applications.\r\nMicrosoft Office Suite 2016 has user settings which are common between applications and are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific common Microsoft Office Suite 2016 applications.\r\nIf you enable this policy setting, certain user settings which are common between the Microsoft Office Suite 2016 applications will continue to be backed up.\r\nIf you disable this policy setting, certain user settings which are common between the Microsoft Office Suite 2016 applications will not be backed up. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016commonbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016commonbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016commonbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excel","displayName":"Microsoft Excel 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Excel 2016.\r\nBy default, the user settings of Microsoft Excel 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Excel 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Excel 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Excel 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016excel"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excelbackup","displayName":"Excel 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Excel 2016.\r\nMicrosoft Excel 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Excel 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Excel 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Excel 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016excelbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excelbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excelbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lync","displayName":"Microsoft Lync 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Lync 2016.\r\nBy default, the user settings of Microsoft Lync 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Lync 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Lync 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Lync 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016lync"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lyncbackup","displayName":"Lync 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Lync 2016.\r\nMicrosoft Lync 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Lync 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Lync 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Lync 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016lyncbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lyncbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lyncbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onedriveforbusiness","displayName":"Microsoft OneDrive for Business 2016","description":"\r\nThis policy setting configures the synchronization of user settings for OneDrive for Business 2016.\r\nBy default, the user settings of OneDrive for Business 2016 synchronize between computers. Use the policy setting to prevent the user settings of OneDrive for Business 2016 from synchronization between computers.\r\nIf you enable this policy setting, OneDrive for Business 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, OneDrive for Business 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016onedriveforbusiness"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onedriveforbusiness_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onedriveforbusiness_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote","displayName":"Microsoft OneNote 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft OneNote 2016.\r\nBy default, the user settings of Microsoft OneNote 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenotebackup","displayName":"OneNote 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft OneNote 2016.\r\nMicrosoft OneNote 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft OneNote 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft OneNote 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft OneNote 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016onenotebackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenotebackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenotebackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlook","displayName":"Microsoft Outlook 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Outlook 2016.\r\nBy default, the user settings of Microsoft Outlook 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Outlook 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Outlook 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Outlook 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016outlook"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup","displayName":"Outlook 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Outlook 2016.\r\nMicrosoft Outlook 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Outlook 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Outlook 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Outlook 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016outlookbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016powerpoint","displayName":"Microsoft PowerPoint 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft PowerPoint 2016.\r\nBy default, the user settings of Microsoft PowerPoint 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft PowerPoint 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft PowerPoint 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft PowerPoint 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016powerpoint"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016powerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016powerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016powerpointbackup","displayName":"PowerPoint 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft PowerPoint 2016.\r\nMicrosoft PowerPoint 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft PowerPoint 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft PowerPoint 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft PowerPoint 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016powerpointbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016powerpointbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016powerpointbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016project","displayName":"Microsoft Project 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Project 2016.\r\nBy default, the user settings of Microsoft Project 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Project 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Project 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Project 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016project"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016project_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016project_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016projectbackup","displayName":"Project 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Project 2016.\r\nMicrosoft Project 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Project 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Project 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Project 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016projectbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016projectbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016projectbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisher","displayName":"Microsoft Publisher 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Publisher 2016.\r\nBy default, the user settings of Microsoft Publisher 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Publisher 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Publisher 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Publisher 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016publisher"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisher_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisherbackup","displayName":"Publisher 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Publisher 2016.\r\nMicrosoft Publisher 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Publisher 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Publisher 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Publisher 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016publisherbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisherbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisherbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016uploadcenter","displayName":"Microsoft Office 2016 Upload Center","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 2016 Upload Center.\r\nBy default, the user settings of Microsoft Office 2016 Upload Center synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Office 2016 Upload Center from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Office 2016 Upload Center user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Office 2016 Upload Center user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016uploadcenter"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016uploadcenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016uploadcenter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visio","displayName":"Microsoft Visio 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Visio 2016.\r\nBy default, the user settings of Microsoft Visio 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Visio 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Visio 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Visio 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016visio"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visiobackup","displayName":"Visio 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Visio 2016.\r\nMicrosoft Visio 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Visio 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Visio 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Visio 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016visiobackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visiobackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visiobackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016word","displayName":"Microsoft Word 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Word 2016.\r\nBy default, the user settings of Microsoft Word 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Word 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Word 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Word 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016word"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016word_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016word_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016wordbackup","displayName":"Word 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Word 2016.\r\nMicrosoft Word 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Word 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Word 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Word 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016wordbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016wordbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016wordbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2013","displayName":"Microsoft Office 365 Access 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Access 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Access 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Access 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Access 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Access 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365access2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2016","displayName":"Microsoft Office 365 Access 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Access 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Access 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Access 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Access 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Access 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365access2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2013","displayName":"Microsoft Office 365 Common 2013","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2013 applications.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings which are common between the Microsoft Office Suite 2013 applications will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings which are common between the Microsoft Office Suite 2013 applications from synchronization between computers with UE-V.\r\nIf you enable this policy setting, user settings which are common between the Microsoft Office Suite 2013 applications continue to synchronize with UE-V.\r\nIf you disable this policy setting, user settings which are common between the Microsoft Office Suite 2013 applications are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365common2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2016","displayName":"Microsoft Office 365 Common 2016","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2016 applications.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings which are common between the Microsoft Office Suite 2016 applications will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings which are common between the Microsoft Office Suite 2016 applications from synchronization between computers with UE-V.\r\nIf you enable this policy setting, user settings which are common between the Microsoft Office Suite 2016 applications continue to synchronize with UE-V.\r\nIf you disable this policy setting, user settings which are common between the Microsoft Office Suite 2016 applications are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365common2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2013","displayName":"Microsoft Office 365 Excel 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Excel 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Excel 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Excel 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Excel 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Excel 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365excel2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2016","displayName":"Microsoft Office 365 Excel 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Excel 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Excel 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Excel 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Excel 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Excel 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365excel2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365infopath2013","displayName":"Microsoft Office 365 InfoPath 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 InfoPath 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 InfoPath 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 InfoPath 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 InfoPath 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 InfoPath 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365infopath2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365infopath2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365infopath2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013","displayName":"Microsoft Office 365 Lync 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Lync 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Lync 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Lync 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Lync 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Lync 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365lync2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016","displayName":"Microsoft Office 365 Lync 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Lync 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Lync 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Lync 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Lync 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Lync 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365lync2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2013","displayName":"Microsoft Office 365 OneNote 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 OneNote 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 OneNote 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 OneNote 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 OneNote 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 OneNote 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365onenote2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2016","displayName":"Microsoft Office 365 OneNote 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 OneNote 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 OneNote 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 OneNote 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 OneNote 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 OneNote 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365onenote2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013","displayName":"Microsoft Office 365 Outlook 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Outlook 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Outlook 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Outlook 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Outlook 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Outlook 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365outlook2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2016","displayName":"Microsoft Office 365 Outlook 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Outlook 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Outlook 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Outlook 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Outlook 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Outlook 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365outlook2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013","displayName":"Microsoft Office 365 PowerPoint 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 PowerPoint 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 PowerPoint 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 PowerPoint 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 PowerPoint 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 PowerPoint 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365powerpoint2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2016","displayName":"Microsoft Office 365 PowerPoint 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 PowerPoint 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 PowerPoint 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 PowerPoint 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 PowerPoint 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 PowerPoint 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365powerpoint2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2013","displayName":"Microsoft Office 365 Project 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Project 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Project 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Project 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Project 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Project 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365project2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016","displayName":"Microsoft Office 365 Project 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Project 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Project 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Project 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Project 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Project 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365project2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2013","displayName":"Microsoft Office 365 Publisher 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Publisher 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Publisher 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Publisher 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Publisher 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Publisher 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365publisher2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2016","displayName":"Microsoft Office 365 Publisher 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Publisher 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Publisher 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Publisher 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Publisher 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Publisher 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365publisher2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365sharepointdesigner2013","displayName":"Microsoft Office 365 SharePoint Designer 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 SharePoint Designer 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 SharePoint Designer 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 SharePoint Designer 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 SharePoint Designer 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 SharePoint Designer 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365sharepointdesigner2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365sharepointdesigner2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365sharepointdesigner2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2013","displayName":"Microsoft Office 365 Visio 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Visio 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Visio 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Visio 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Visio 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Visio 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365visio2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016","displayName":"Microsoft Office 365 Visio 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Visio 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Visio 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Visio 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Visio 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Visio 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365visio2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365word2013","displayName":"Microsoft Office 365 Word 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Word 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Word 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Word 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Word 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Word 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365word2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365word2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365word2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365word2016","displayName":"Microsoft Office 365 Word 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Word 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Word 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Word 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Word 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Word 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365word2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365word2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365word2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_music","displayName":"Music","description":"This policy setting configures the synchronization of user settings for the Music app.\r\nBy default, the user settings of Music sync between computers. Use the policy setting to prevent the user settings of Music from synchronizing between computers.\r\nIf you enable this policy setting, Music user settings continue to sync.\r\nIf you disable this policy setting, Music user settings are excluded from the synchronizing settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-music"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_music_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_music_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_news","displayName":"News","description":"This policy setting configures the synchronization of user settings for the News app.\r\nBy default, the user settings of News sync between computers. Use the policy setting to prevent the user settings of News from synchronizing between computers.\r\nIf you enable this policy setting, News user settings continue to sync.\r\nIf you disable this policy setting, News user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-news"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_news_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_news_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_notepad","displayName":"Notepad","description":"This policy setting configures the synchronization of user settings of Notepad.\r\nBy default, the user settings of Notepad synchronize between computers. Use the policy setting to prevent the user settings of Notepad from synchronization between computers. \r\nIf you enable this policy setting, the Notepad user settings continue to synchronize. \r\nIf you disable this policy setting, Notepad user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-notepad"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_notepad_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_notepad_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_reader","displayName":"Reader","description":"This policy setting configures the synchronization of user settings for the Reader app.\r\nBy default, the user settings of Reader sync between computers. Use the policy setting to prevent the user settings of Reader from synchronizing between computers.\r\nIf you enable this policy setting, Reader user settings continue to sync.\r\nIf you disable this policy setting, Reader user settings are excluded from the synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-reader"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_reader_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_reader_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_repositorytimeout","displayName":"Synchronization timeout","description":"This policy setting configures the number of milliseconds that the computer waits when retrieving user settings from the settings storage location. \r\nYou can use this setting to override the default value of 2000 milliseconds. \r\nIf you enable this policy setting, set the number of milliseconds that the system waits to retrieve settings. \r\nIf you disable or do not configure this policy setting, the default value of 2000 milliseconds is used.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-repositorytimeout"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_repositorytimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_repositorytimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_repositorytimeout_repositorytimeout","displayName":"Synchronization timeout (in milliseconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingsstoragepath","displayName":"Settings storage path","description":"This policy setting configures where the settings package files that contain user settings are stored. \r\nIf you enable this policy setting, the user settings are stored in the specified location. \r\nIf you disable or do not configure this policy setting, the user settings are stored in the user’s home directory if configured for your environment. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-settingsstoragepath"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingsstoragepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingsstoragepath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingsstoragepath_settingsstoragepath","displayName":"Settings storage path","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath","displayName":"Settings template catalog path","description":"This policy setting configures where custom settings location templates are stored and if the catalog will be used to replace the default Microsoft templates installed with the UE-V Agent.\r\nIf you enable this policy setting, the UE-V Agent checks the specified location once each day and updates its synchronization behavior based on the templates in this location. Settings location templates added or updated since the last check are registered by the UE-V Agent. The UE-V Agent deregisters templates that were removed from this location.\r\nIf you specify a UNC path and leave the option to replace the default Microsoft templates unchecked, the UE-V Agent will use the default Microsoft templates installed by the UE-V Agent and custom templates in the settings template catalog. If there are custom templates in the settings template catalog which use the same ID as the default Microsoft templates, they will be ignored.\r\nIf you specify a UNC path and check the option to replace the default Microsoft templates, all of the default Microsoft templates installed by the UE-V Agent will be deleted from the computer and only the templates located in the settings template catalog will be used.\r\nIf you disable this policy setting, the UE-V Agent will not use the custom settings location templates. If you disable this policy setting after it has been enabled, the UE-V Agent will not restore the default Microsoft templates. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-settingstemplatecatalogpath"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_overridemstemplates","displayName":"Replace the default Microsoft templates","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_overridemstemplates_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_overridemstemplates_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_settingstemplatecatalogpath","displayName":"Settings template catalog path","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_sports","displayName":"Sports","description":"This policy setting configures the synchronization of user settings for the Sports app.\r\nBy default, the user settings of Sports sync between computers. Use the policy setting to prevent the user settings of Sports from synchronizing between computers.\r\nIf you enable this policy setting, Sports user settings continue to sync.\r\nIf you disable this policy setting, Sports user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-sports"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_sports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_sports_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncenabled","displayName":"Use User Experience Virtualization (UE-V)","description":"This policy setting allows you to enable or disable User Experience Virtualization (UE-V). Only applies to Windows 10 or earlier.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncenabled"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetwork","displayName":"Sync settings over metered connections","description":"This policy setting defines whether the User Experience Virtualization (UE-V) Agent synchronizes settings over metered connections.\r\nBy default, the UE-V Agent does not synchronize settings over a metered connection.\r\nWith this setting enabled, the UE-V Agent synchronizes settings over a metered connection.\r\nWith this setting disabled, the UE-V Agent does not synchronize settings over a metered connection.\r\nIf you do not configure this policy setting, any defined values are deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncovermeterednetwork"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetworkwhenroaming","displayName":"Sync settings over metered connections even when roaming","description":"This policy setting defines whether the User Experience Virtualization (UE-V) Agent synchronizes settings over metered connections outside of the home provider network, for example when connected via a roaming connection.\r\nBy default, the UE-V Agent does not synchronize settings over a metered connection that is roaming.\r\nWith this setting enabled, the UE-V Agent synchronizes settings over a metered connection that is roaming.\r\nWith this setting disabled, the UE-V Agent will not synchronize settings over a metered connection that is roaming.\r\nIf you do not configure this policy setting, any defined values are deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncovermeterednetworkwhenroaming"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetworkwhenroaming_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetworkwhenroaming_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncproviderpingenabled","displayName":"Ping the settings storage location before sync","description":"This policy setting allows you to configure the User Experience Virtualization (UE-V) sync provider to ping the settings storage path before attempting to sync settings. If the ping is successful then the sync provider attempts to synchronize the settings packages. If the ping is unsuccessful then the sync provider doesn’t attempt the synchronization. \r\nIf you enable this policy setting, the sync provider pings the settings storage location before synchronizing settings packages.\r\nIf you disable this policy setting, the sync provider doesn’t ping the settings storage location before synchronizing settings packages. \r\nIf you do not configure this policy, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncproviderpingenabled"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncproviderpingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncproviderpingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncunlistedwindows8apps","displayName":"Sync Unlisted Windows Apps","description":"This policy setting defines the default settings sync behavior of the User Experience Virtualization (UE-V) Agent for Windows apps that are not explicitly listed in Windows App List.\r\nBy default, the UE-V Agent only synchronizes settings of those Windows apps included in the Windows App List.\r\nWith this setting enabled, the settings of all Windows apps not expressly disable in the Windows App List are synchronized.\r\nWith this setting disabled, only the settings of the Windows apps set to synchronize in the Windows App List are synchronized.\r\nIf you do not configure this policy setting, any defined values are deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncunlistedwindows8apps"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncunlistedwindows8apps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncunlistedwindows8apps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_travel","displayName":"Travel","description":"This policy setting configures the synchronization of user settings for the Travel app.\r\nBy default, the user settings of Travel sync between computers. Use the policy setting to prevent the user settings of Travel from synchronizing between computers.\r\nIf you enable this policy setting, Travel user settings continue to sync.\r\nIf you disable this policy setting, Travel user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-travel"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_travel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_travel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_trayiconenabled","displayName":"Tray Icon","description":"This policy setting enables the User Experience Virtualization (UE-V) tray icon. By default, an icon appears in the system tray that displays notifications for UE-V. This icon also provides a link to the UE-V Agent application, Company Settings Center. Users can open the Company Settings Center by right-clicking the icon and selecting Open or by double-clicking the icon. When this group policy setting is enabled, the UE-V tray icon is visible, the UE-V notifications display, and the Company Settings Center is accessible from the tray icon.\r\nWith this setting disabled, the tray icon does not appear in the system tray, UE-V never displays notifications, and the user cannot access Company Settings Center from the system tray. The Company Settings Center remains accessible through the Control Panel and the Start menu or Start screen.\r\nIf you do not configure this policy setting, any defined values are deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-trayiconenabled"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_trayiconenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_trayiconenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_video","displayName":"Video","description":"This policy setting configures the synchronization of user settings for the Video app.\r\nBy default, the user settings of Video sync between computers. Use the policy setting to prevent the user settings of Video from synchronizing between computers.\r\nIf you enable this policy setting, Video user settings continue to sync.\r\nIf you disable this policy setting, Video user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-video"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_video_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_video_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_weather","displayName":"Weather","description":"This policy setting configures the synchronization of user settings for the Weather app.\r\nBy default, the user settings of Weather sync between computers. Use the policy setting to prevent the user settings of Weather from synchronizing between computers.\r\nIf you enable this policy setting, Weather user settings continue to sync.\r\nIf you disable this policy setting, Weather user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-weather"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_weather_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_weather_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_wordpad","displayName":"WordPad","description":"This policy setting configures the synchronization of user settings of WordPad.\r\nBy default, the user settings of WordPad synchronize between computers. Use the policy setting to prevent the user settings of WordPad from synchronization between computers. \r\nIf you enable this policy setting, the WordPad user settings continue to synchronize. \r\nIf you disable this policy setting, WordPad user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-wordpad"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_wordpad_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_wordpad_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles","displayName":"Delete user profiles older than a specified number of days on system restart","description":"This policy setting allows an administrator to automatically delete user profiles on system restart that have not been used within a specified number of days. Note: One day is interpreted as 24 hours after a specific user profile was accessed.\r\n\r\nIf you enable this policy setting, the User Profile Service will automatically delete on the next system restart all user profiles on the computer that have not been used within the specified number of days. \r\n\r\nIf you disable or do not configure this policy setting, User Profile Service will not automatically delete any profiles on the next system restart.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-cleanupprofiles"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles_cleanupprofiles_days","displayName":"Delete user profiles older than (days)","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_dontforceunloadhive","displayName":"Do not forcefully unload the users registry at user logoff","description":"This policy setting controls whether Windows forcefully unloads the user's registry at logoff, even if there are open handles to the per-user registry keys. \r\n\r\nNote: This policy setting should only be used for cases where you may be running into application compatibility issues due to this specific Windows behavior. It is not recommended to enable this policy by default as it may prevent users from getting an updated version of their roaming user profile.\r\n\r\nIf you enable this policy setting, Windows will not forcefully unload the users registry at logoff, but will unload the registry when all open handles to the per-user registry keys are closed.\r\n\r\nIf you disable or do not configure this policy setting, Windows will always unload the users registry at logoff, even if there are any open handles to the per-user registry keys at user logoff.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-dontforceunloadhive"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_dontforceunloadhive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_dontforceunloadhive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_leaveappmgmtdata","displayName":"Leave Windows Installer and Group Policy Software Installation Data","description":"This policy setting determines whether the system retains a roaming user's Windows Installer and Group Policy based software installation data on their profile deletion.\r\n\r\nBy default Windows deletes all information related to a roaming user (which includes the user's settings, data, Windows Installer related data, and the like) when their profile is deleted. As a result, the next time a roaming user whose profile was previously deleted on that client logs on, they will need to reinstall all apps published via policy at logon increasing logon time. You can use this policy setting to change this behavior.\r\n\r\nIf you enable this policy setting, Windows will not delete Windows Installer or Group Policy software installation data for roaming users when profiles are deleted from the machine. This will improve the performance of Group Policy based Software Installation during user logon when a user profile is deleted and that user subsequently logs on to the machine.\r\n\r\nIf you disable or do not configure this policy setting, Windows will delete the entire profile for roaming users, including the Windows Installer and Group Policy software installation data when those profiles are deleted.\r\n\r\nNote: If this policy setting is enabled for a machine, local administrator action is required to remove the Windows Installer or Group Policy software installation data stored in the registry and file system of roaming users' profiles on the machine.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-leaveappmgmtdata"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_leaveappmgmtdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_leaveappmgmtdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_profileerroraction","displayName":"Do not log users on with temporary profiles","description":"This policy setting will automatically log off a user when Windows cannot load their profile. \r\n\r\nIf Windows cannot access the user profile folder or the profile contains errors that prevent it from loading, Windows logs on the user with a temporary profile. This policy setting allows the administrator to disable this behavior, preventing Windows from loggin on the user with a temporary profile.\r\n\r\nIf you enable this policy setting, Windows will not log on a user with a temporary profile. Windows logs the user off if their profile cannot be loaded.\r\n\r\nIf you disable this policy setting or do not configure it, Windows logs on the user with a temporary profile when Windows cannot load their user profile.\r\n\r\nAlso, see the \"Delete cached copies of roaming profiles\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-profileerroraction"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_profileerroraction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_profileerroraction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout","displayName":"Control slow network connection timeout for user profiles","description":"This policy setting defines a slow connection for roaming user profiles and establishes thresholds for two tests of network speed. \r\n\r\nTo determine the network performance characteristics, a connection is made to the file share storing the user's profile and 64 kilobytes of data is transfered. From that connection and data transfer, the network's latency and connection speed are determined.\r\n\r\nThis policy setting and related policy settings in this folder together define the system's response when roaming user profiles are slow to load.\r\n\r\nIf you enable this policy setting, you can change how long Windows waits for a response from the server before considering the connection to be slow.\r\n\r\nIf you disable or do not configure this policy setting, Windows considers the network connection to be slow if the server returns less than 500 kilobits of data per second or take 120 milliseconds to respond.Consider increasing this value for clients using DHCP Service-assigned addresses or for computers accessing profiles across dial-up connections.Important: If the \"Do not detect slow network connections\" policy setting is enabled, this policy setting is ignored. Also, if the \"Delete cached copies of roaming profiles\" policy setting is enabled, there is no local copy of the roaming profile to load when the system detects a slow connection.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-slowlinktimeout"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout_slowlinkwaitinterval","displayName":"Time (milliseconds)","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout_transferrateop","displayName":"Connection speed (Kbps):","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home","displayName":"Set user home folder","description":"This policy setting allows you to specify the location and root (file share or local path) of a user's home folder for a logon session.\r\n\r\nIf you enable this policy setting, the user's home folder is configured to the specified local or network location, creating a new folder for each user name.\r\n\r\nTo use this policy setting, in the Location list, choose the location for the home folder. If you choose “On the network,” enter the path to a file share in the Path box (for example, \\\\ComputerName\\ShareName), and then choose the drive letter to assign to the file share. If you choose “On the local computer,” enter a local path (for example, C:\\HomeFolder) in the Path box.\r\n\r\nDo not specify environment variables or ellipses in the path. Also, do not specify a placeholder for the user name because the user name will be appended at logon.\r\n\r\nNote: The Drive letter box is ignored if you choose “On the local computer” from the Location list. If you choose “On the local computer” and enter a file share, the user's home folder will be placed in the network location without mapping the file share to a drive letter.\r\n\r\nIf you disable or do not configure this policy setting, the user's home folder is configured as specified in the user's Active Directory Domain Services account.\r\n\r\nIf the \"Set Remote Desktop Services User Home Directory\" policy setting is enabled, the “Set user home folder” policy setting has no effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-user-home"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter","displayName":"Drive letter","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_g:","displayName":"G:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_h:","displayName":"H:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_i:","displayName":"I:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_j:","displayName":"J:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_k:","displayName":"K:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_l:","displayName":"L:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_m:","displayName":"M:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_n:","displayName":"N:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_o:","displayName":"O:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_p:","displayName":"P:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_q:","displayName":"Q:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_r:","displayName":"R:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_s:","displayName":"S:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_t:","displayName":"T:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_u:","displayName":"U:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_v:","displayName":"V:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_w:","displayName":"W:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_x:","displayName":"X:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_y:","displayName":"Y:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_z:","displayName":"Z:","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_home_path","displayName":"Path:","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_user_home_location","displayName":"Location:","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_user_home_location_1","displayName":"On the network","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_user_home_location_0","displayName":"On the local computer","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction","displayName":"User management of sharing user name, account picture, and domain information with apps (not desktop apps)","description":"This setting prevents users from managing the ability to allow apps to access the user name, account picture, and domain information.\r\n\r\nIf you enable this policy setting, sharing of user name, picture and domain information may be controlled by setting one of the following options:\r\n\r\n\"Always on\" - users will not be able to change this setting and the user's name and account picture will be shared with apps (not desktop apps). In addition apps (not desktop apps) that have the enterprise authentication capability will also be able to retrieve the user's UPN, SIP/URI, and DNS.\r\n\r\n\"Always off\" - users will not be able to change this setting and the user's name and account picture will not be shared with apps (not desktop apps). In addition apps (not desktop apps) that have the enterprise authentication capability will not be able to retrieve the user's UPN, SIP/URI, and DNS. Selecting this option may have a negative impact on certain enterprise software and/or line of business apps that depend on the domain information protected by this setting to connect with network resources.\r\n\r\nIf you do not configure or disable this policy the user will have full control over this setting and can turn it off and on. Selecting this option may have a negative impact on certain enterprise software and/or line of business apps that depend on the domain information protected by this setting to connect with network resources if users choose to turn the setting off.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-userinfoaccessaction"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_allowuserinfoaccess","displayName":"Action:","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_allowuserinfoaccess_1","displayName":"Always on","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_allowuserinfoaccess_2","displayName":"Always off","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config","displayName":"Global Configuration Settings","description":"This policy setting allows you to specify Clock discipline and General values for the Windows Time service (W32time) for domain controllers including RODCs.\r\n\r\nIf this policy setting is enabled, W32time Service on target machines use the settings provided here. Otherwise, the service on target machines use locally configured settings values.\r\n\r\nFor more details on individual parameters, combinations of parameter values as well as definitions of flags, see https://go.microsoft.com/fwlink/?linkid=847809.\r\n\r\n FrequencyCorrectRate\r\nThis parameter controls the rate at which the W32time corrects the local clock's frequency. Lower values cause slower corrections; larger values cause more frequent corrections. Default: 4 (scalar).\r\n\r\n HoldPeriod\r\nThis parameter indicates how many consistent time samples the client computer must receive in a series before subsequent time samples are evaluated as potential spikes. Default: 5\r\n\r\n LargePhaseOffset\r\nIf a time sample differs from the client computer's local clock by more than LargePhaseOffset, the local clock is deemed to have drifted considerably, or in other words, spiked. Default: 50,000,000 100-nanosecond units (ns) or 5 seconds.\r\n\r\n MaxAllowedPhaseOffset\r\nIf a response is received that has a time variation that is larger than this parameter value, W32time sets the client computer's local clock immediately to the time that is accepted as accurate from the Network Time Protocol (NTP) server. If the time variation is less than this value, the client computer's local clock is corrected gradually. Default: 300 seconds.\r\n\r\n MaxNegPhaseCorrection\r\nIf a time sample is received that indicates a time in the past (as compared to the client computer's local clock) that has a time difference that is greater than the MaxNegPhaseCorrection value, the time sample is discarded. Default: 172,800 seconds.\r\n\r\n MaxPosPhaseCorrection\r\nIf a time sample is received that indicates a time in the future (as compared to the client computer's local clock) that has a time difference greater than the MaxPosPhaseCorrection value, the time sample is discarded. Default: 172,800 seconds.\r\n\r\n PhaseCorrectRate\r\nThis parameter controls how quickly W32time corrects the client computer's local clock difference to match time samples that are accepted as accurate from the NTP server. Lower values cause the clock to correct more slowly; larger values cause the clock to correct more quickly. Default: 7 (scalar).\r\n\r\n PollAdjustFactor\r\nThis parameter controls how quickly W32time changes polling intervals. When responses are considered to be accurate, the polling interval lengthens automatically. When responses are considered to be inaccurate, the polling interval shortens automatically. Default: 5 (scalar).\r\n\r\n SpikeWatchPeriod\r\nThis parameter specifies the amount of time that samples with time offset larger than LargePhaseOffset are received before these samples are accepted as accurate. SpikeWatchPeriod is used in conjunction with HoldPeriod to help eliminate sporadic, inaccurate time samples that are returned from a peer. Default: 900 seconds.\r\n\r\n UpdateInterval\r\nThis parameter specifies the amount of time that W32time waits between corrections when the clock is being corrected gradually. When it makes a gradual correction, the service adjusts the clock slightly, waits this amount of time, and then checks to see if another adjustment is needed, until the correction is finished. Default: 100 1/100th second units, or 1 second.\r\n\r\n General parameters:\r\n\r\n AnnounceFlags\r\nThis parameter is a bitmask value that controls how time service availability is advertised through NetLogon. Default: 0x0a hexadecimal\r\n\r\n EventLogFlags\r\nThis parameter controls special events that may be logged to the Event Viewer System log. Default: 0x02 hexadecimal bitmask.\r\n\r\n LocalClockDispersion\r\nThis parameter indicates the maximum error in seconds that is reported by the NTP server to clients that are requesting a time sample. (Applies only when the NTP server is using the time of the local CMOS clock.) Default: 10 seconds.\r\n\r\n MaxPollInterval\r\nThis parameter controls the maximum polling interval, which defines the maximum amount of time between polls of a peer. Default: 10 in log base-2, or 1024 seconds. (Should not be set higher than 15.)\r\n\r\n MinPollInterval\r\nThis parameter controls the minimum polling interval that defines the minimum amount of time between polls of a peer. Default: 6 in log base-2, or 64 seconds.\r\n\r\n ClockHoldoverPeriod\r\nThis parameter indicates the maximum number of seconds a system clock can nominally hold its accuracy without synchronizing with a time source. If this period of time passes without W32time obtaining new samples from any of its input providers, W32time initiates a rediscovery of time sources. Default: 7800 seconds.\r\n\r\n RequireSecureTimeSyncRequests\r\nThis parameter controls whether or not the DC will respond to time sync requests that use older authentication protocols. If enabled (set to 1), the DC will not respond to requests using such protocols. Default: 0 Boolean.\r\n\r\n UtilizeSslTimeData\r\nThis parameter controls whether W32time will use time data computed from SSL traffic on the machine as an additional input for correcting the local clock. Default: 1 (enabled) Boolean\r\n\r\n ClockAdjustmentAuditLimit\r\nThis parameter specifies the smallest local clock adjustments that may be logged to the W32time service event log on the target machine. Default: 800 Parts per million (PPM).\r\n\r\n RODC parameters:\r\n\r\n ChainEntryTimeout\r\nThis parameter specifies the maximum amount of time that an entry can remain in the chaining table before the entry is considered to be expired. Expired entries may be removed when the next request or response is processed. Default: 16 seconds.\r\n\r\n ChainMaxEntries\r\nThis parameter controls the maximum number of entries that are allowed in the chaining table. If the chaining table is full and no expired entries can be removed, any incoming requests are discarded. Default: 128 entries.\r\n\r\n ChainMaxHostEntries\r\nThis parameter controls the maximum number of entries that are allowed in the chaining table for a particular host. Default: 4 entries.\r\n\r\n ChainDisable\r\nThis parameter controls whether or not the chaining mechanism is disabled. If chaining is disabled (set to 0), the RODC can synchronize with any domain controller, but hosts that do not have their passwords cached on the RODC will not be able to synchronize with the RODC. Default: 0 Boolean.\r\n\r\n ChainLoggingRate\r\nThis parameter controls the frequency at which an event that indicates the number of successful and unsuccessful chaining attempts is logged to the System log in Event Viewer. Default: 30 minutes.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-w32time#admx-w32time-w32time-policy-config"],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":[{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_announceflags","displayName":"AnnounceFlags","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chaindisable","displayName":"ChainDisable","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chainentrytimeout","displayName":"ChainEntryTimeout","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chainloggingrate","displayName":"ChainLoggingRate","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chainmaxentries","displayName":"ChainMaxEntries","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chainmaxhostentries","displayName":"ChainMaxHostEntries","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_clockadjustmentauditlimit","displayName":"ClockAdjustmentAuditLimit","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_clockholdoverperiod","displayName":"ClockHoldoverPeriod","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_eventlogflags","displayName":"EventLogFlags","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_frequencycorrectrate","displayName":"FrequencyCorrectRate","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_holdperiod","displayName":"HoldPeriod","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_largephaseoffset","displayName":"LargePhaseOffset","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_localclockdispersion","displayName":"LocalClockDispersion","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_maxallowedphaseoffset","displayName":"MaxAllowedPhaseOffset","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_maxnegphasecorrection","displayName":"MaxNegPhaseCorrection","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_maxpollinterval","displayName":"MaxPollInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_maxposphasecorrection","displayName":"MaxPosPhaseCorrection","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_minpollinterval","displayName":"MinPollInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_phasecorrectrate","displayName":"PhaseCorrectRate","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_polladjustfactor","displayName":"PollAdjustFactor","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_requiresecuretimesyncrequests","displayName":"RequireSecureTimeSyncRequests","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_spikewatchperiod","displayName":"SpikeWatchPeriod","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_updateinterval","displayName":"UpdateInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_utilizessltimedata","displayName":"UtilizeSslTimeData","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient","displayName":"Configure Windows NTP Client","description":"This policy setting specifies a set of parameters for controlling the Windows NTP Client.\r\n\r\nIf you enable this policy setting, you can specify the following parameters for the Windows NTP Client.\r\n\r\nIf you disable or do not configure this policy setting, the WIndows NTP Client uses the defaults of each of the following parameters.\r\n\r\nNtpServer\r\nThe Domain Name System (DNS) name or IP address of an NTP time source. This value is in the form of \"dnsName,flags\" where \"flags\" is a hexadecimal bitmask of the flags for that host. For more information, see the NTP Client Group Policy Settings Associated with Windows Time section of the Windows Time Service Group Policy Settings. The default value is \"time.windows.com,0x09\". \r\n\r\nType\r\nThis value controls the authentication that W32time uses. The default value is NT5DS.\r\n\r\nCrossSiteSyncFlags\r\nThis value, expressed as a bitmask, controls how W32time chooses time sources outside its own site. The possible values are 0, 1, and 2. Setting this value to 0 (None) indicates that the time client should not attempt to synchronize time outside its site. Setting this value to 1 (PdcOnly) indicates that only the computers that function as primary domain controller (PDC) emulator operations masters in other domains can be used as synchronization partners when the client has to synchronize time with a partner outside its own site. Setting a value of 2 (All) indicates that any synchronization partner can be used. This value is ignored if the NT5DS value is not set. The default value is 2 decimal (0x02 hexadecimal).\r\n\r\nResolvePeerBackoffMinutes\r\nThis value, expressed in minutes, controls how long W32time waits before it attempts to resolve a DNS name when a previous attempt failed. The default value is 15 minutes.\r\n\r\nResolvePeerBackoffMaxTimes\r\nThis value controls how many times W32time attempts to resolve a DNS name before the discovery process is restarted. Each time DNS name resolution fails, the amount of time to wait before the next attempt will be twice the previous amount. The default value is seven attempts.\r\n\r\nSpecialPollInterval\r\nThis NTP client value, expressed in seconds, controls how often a manually configured time source is polled when the time source is configured to use a special polling interval. If the SpecialInterval flag is enabled on the NTPServer setting, the client uses the value that is set as the SpecialPollInterval, instead of a variable interval between MinPollInterval and MaxPollInterval values, to determine how frequently to poll the time source. SpecialPollInterval must be in the range of [MinPollInterval, MaxPollInterval], else the nearest value of the range is picked. Default: 1024 seconds.\r\n\r\nEventLogFlags\r\nThis value is a bitmask that controls events that may be logged to the System log in Event Viewer. Setting this value to 0x1 indicates that W32time will create an event whenever a time jump is detected. Setting this value to 0x2 indicates that W32time will create an event whenever a time source change is made. Because it is a bitmask value, setting 0x3 (the addition of 0x1 and 0x2) indicates that both time jumps and time source changes will be logged.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-w32time#admx-w32time-w32time-policy-configure-ntpclient"],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":[{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_crosssitesyncflags","displayName":"CrossSiteSyncFlags","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_ntpclienteventlogflags","displayName":"EventLogFlags","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_ntpserver","displayName":"NtpServer","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_resolvepeerbackoffmaxtimes","displayName":"ResolvePeerBackoffMaxTimes","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_resolvepeerbackoffminutes","displayName":"ResolvePeerBackoffMinutes","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_specialpollinterval","displayName":"SpecialPollInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_type","displayName":"Type","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":[{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_type_nosync","displayName":"NoSync","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_type_ntp","displayName":"NTP","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_type_nt5ds","displayName":"NT5DS","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_type_allsync","displayName":"AllSync","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpclient","displayName":"Enable Windows NTP Client","description":"This policy setting specifies whether the Windows NTP Client is enabled.\r\n\r\nEnabling the Windows NTP Client allows your computer to synchronize its computer clock with other NTP servers. You might want to disable this service if you decide to use a third-party time provider.\r\n\r\nIf you enable this policy setting, you can set the local computer clock to synchronize time with NTP servers.\r\n\r\nIf you disable or do not configure this policy setting, the local computer clock does not synchronize time with NTP servers.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-w32time#admx-w32time-w32time-policy-enable-ntpclient"],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":[{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpclient_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpserver","displayName":"Enable Windows NTP Server","description":"This policy setting allows you to specify whether the Windows NTP Server is enabled.\r\n\r\nIf you enable this policy setting for the Windows NTP Server, your computer can service NTP requests from other computers.\r\n\r\n\r\nIf you disable or do not configure this policy setting, your computer cannot service NTP requests from other computers.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-w32time#admx-w32time-w32time-policy-enable-ntpserver"],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":[{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_disablepowermanagement","displayName":"Disable power management in connected standby mode","description":"This policy setting specifies that power management is disabled when the machine enters connected standby mode. \r\n\r\nIf this policy setting is enabled, Windows Connection Manager does not manage adapter radios to reduce power consumption when the machine enters connected standby mode.\r\n\r\nIf this policy setting is not configured or is disabled, power management is enabled when the machine enters connected standby mode.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wcm#admx-wcm-wcm-disablepowermanagement"],"categoryId":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","categoryName":"Windows Connection Manager","options":[{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_disablepowermanagement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_disablepowermanagement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_enablesoftdisconnect","displayName":"Enable Windows to soft-disconnect a computer from a network","description":"This policy setting determines whether Windows will soft-disconnect a computer from a network.\r\n\r\nIf this policy setting is enabled or not configured, Windows will soft-disconnect a computer from a network when it determines that the computer should no longer be connected to a network.\r\n\r\nIf this policy setting is disabled, Windows will disconnect a computer from a network immediately when it determines that the computer should no longer be connected to a network.\r\n\r\nWhen soft disconnect is enabled:\r\n- When Windows decides that the computer should no longer be connected to a network, it waits for traffic to settle on that network. The existing TCP session will continue uninterrupted.\r\n- Windows then checks the traffic level on the network periodically. If the traffic level is above a certain threshold, no further action is taken. The computer stays connected to the network and continues to use it. For example, if the network connection is currently being used to download files from the Internet, the files will continue to be downloaded using that network connection.\r\n- When the network traffic drops below this threshold, the computer will be disconnected from the network. Apps that keep a network connection active even when they’re not actively using it (for example, email apps) might lose their connection. If this happens, these apps should re-establish their connection over a different network. \r\n\r\nThis policy setting depends on other group policy settings. For example, if 'Minimize the number of simultaneous connections to the Internet or a Windows Domain' is disabled, Windows will not disconnect from any networks.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wcm#admx-wcm-wcm-enablesoftdisconnect"],"categoryId":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","categoryName":"Windows Connection Manager","options":[{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_enablesoftdisconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_enablesoftdisconnect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections","displayName":"Minimize the number of simultaneous connections to the Internet or a Windows Domain","description":"\r\n This policy setting determines if a computer can have multiple connections to the internet or to a Windows domain. If multiple connections are allowed, it then determines how network traffic will be routed.\r\n\r\n If this policy setting is set to 0, a computer can have simultaneous connections to the internet, to a Windows domain, or to both. Internet traffic can be routed over any connection - including a cellular connection and any metered network. This was previously the Disabled state for this policy setting. This option was first available in Windows 8.\r\n\r\n If this policy setting is set to 1, any new automatic internet connection is blocked when the computer has at least one active internet connection to a preferred type of network. Here's the order of preference (from most preferred to least preferred): Ethernet, WLAN, then cellular. Ethernet is always preferred when connected. Users can still manually connect to any network. This was previously the Enabled state for this policy setting. This option was first available in Windows 8.\r\n\r\n If this policy setting is set to 2, the behavior is similar to 1. However, if a cellular data connection is available, it will always stay connected for services that require a cellular connection. When the user is connected to a WLAN or Ethernet connection, no internet traffic will be routed over the cellular connection. This option was first available in Windows 10 (Version 1703).\r\n\r\n If this policy setting is set to 3, the behavior is similar to 2. However, if there's an Ethernet connection, Windows won't allow users to connect to a WLAN manually. A WLAN can only be connected (automatically or manually) when there's no Ethernet connection.\r\n\r\n This policy setting is related to the \"Enable Windows to soft-disconnect a computer from a network\" policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wcm#admx-wcm-wcm-minimizeconnections"],"categoryId":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","categoryName":"Windows Connection Manager","options":[{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_wcm_minimizeconnections_options","displayName":"Minimize Policy Options","description":null,"helpText":"","infoUrls":[],"categoryId":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","categoryName":"Windows Connection Manager","options":[{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_wcm_minimizeconnections_options_0","displayName":"0 = Allow simultaneous connections","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_wcm_minimizeconnections_options_1","displayName":"1 = Minimize simultaneous connections","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_wcm_minimizeconnections_options_2","displayName":"2 = Stay connected to cellular","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_wcm_minimizeconnections_options_3","displayName":"3 = Prevent Wi-Fi when on Ethernet","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy","displayName":"Diagnostics: Configure scenario retention","description":"This policy setting determines the data retention limit for Diagnostic Policy Service (DPS) scenario data.\r\n\r\nIf you enable this policy setting, you must enter the maximum size of scenario data that should be retained in megabytes. Detailed troubleshooting data related to scenarios will be retained until this limit is reached.\r\n\r\nIf you disable or do not configure this policy setting, the DPS deletes scenario data once it exceeds 128 megabytes in size.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenario data will not be deleted. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wdi#admx-wdi-wdidpsscenariodatasizelimitpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy_wdidpsscenariodatasizelimitpolicyvalue","displayName":"Scenario data size limit (in MB)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy","displayName":"Diagnostics: Configure scenario execution level","description":"This policy setting determines the execution level for Diagnostic Policy Service (DPS) scenarios.\r\n\r\nIf you enable this policy setting, you must select an execution level from the drop-down menu. If you select problem detection and troubleshooting only, the DPS will detect problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will attempt to automatically fix problems it detects or indicate to the user that assisted resolution is available.\r\n\r\nIf you disable this policy setting, Windows cannot detect, troubleshoot, or resolve any problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS enables all scenarios for resolution by default, unless you configure separate scenario-specific policy settings.\r\n\r\nThis policy setting takes precedence over any scenario-specific policy settings when it is enabled or disabled. Scenario-specific policy settings only take effect if this policy setting is not configured.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wdi#admx-wdi-wdidpsscenarioexecutionpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_wdidpsscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_wdidpsscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_wdidpsscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wincal_turnoffwincal_2","displayName":"Turn off Windows Calendar","description":"Windows Calendar is a feature that allows users to manage appointments and tasks by creating personal calendars, publishing them, and subscribing to other users calendars.\r\n\r\nIf you enable this setting, Windows Calendar will be turned off.\r\n\r\nIf you disable or do not configure this setting, Windows Calendar will be turned on.\r\n\r\nThe default is for Windows Calendar to be turned on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wincal#admx-wincal-turnoffwincal-2"],"categoryId":"fff51673-04b8-4277-98ef-4baffbd8d192","categoryName":"Windows Calendar","options":[{"id":"device_vendor_msft_policy_config_admx_wincal_turnoffwincal_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wincal_turnoffwincal_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_2","displayName":"Prohibit installing or uninstalling color profiles","description":"This policy setting affects the ability of users to install or uninstall color profiles.\r\n\r\nIf you enable this policy setting, users cannot install new color profiles or uninstall previously installed color profiles.\r\n\r\nIf you disable or do not configure this policy setting, all users can install new color profiles. Standard users can uninstall color profiles that they previously installed. Administrators will be able to uninstall all color profiles.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowscolorsystem#admx-windowscolorsystem-prohibitchanginginstalledprofilelist-2"],"categoryId":"444409a4-8b03-402d-91d0-1cd9565fb0fb","categoryName":"Windows Color System","options":[{"id":"device_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_2","displayName":"Prohibit access of the Windows Connect Now wizards","description":"This policy setting prohibits access to Windows Connect Now (WCN) wizards. \r\n\r\nIf you enable this policy setting, the wizards are turned off and users have no access to any of the wizard tasks. All the configuration related tasks, including \"Set up a wireless router or access point\" and \"Add a wireless device\" are disabled. \r\n\r\nIf you disable or do not configure this policy setting, users can access the wizard tasks, including \"Set up a wireless router or access point\" and \"Add a wireless device.\" The default for this policy setting allows users to access all WCN wizards.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsconnectnow#admx-windowsconnectnow-wcn-disablewcnui-2"],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar","displayName":"Configuration of wireless settings using Windows Connect Now","description":"This policy setting allows the configuration of wireless settings using Windows Connect Now (WCN). The WCN Registrar enables the discovery and configuration of devices over Ethernet (UPnP), over In-band 802.11 WLAN, through the Windows Portable Device API (WPD), and via USB Flash drives.\r\n\r\nAdditional options are available to allow discovery and configuration over a specific medium. \r\n\r\nIf you enable this policy setting, additional choices are available to turn off the operations over a specific medium. \r\n\r\nIf you disable this policy setting, operations are disabled over all media. \r\n\r\nIf you do not configure this policy setting, operations are enabled over all media. \r\n\r\nThe default for this policy setting allows operations over all media.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsconnectnow#admx-windowsconnectnow-wcn-enableregistrar"],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableflashconfig","displayName":"Turn off ability to configure using a USB Flash Drive","description":null,"helpText":"","infoUrls":[],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableflashconfig_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableflashconfig_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableinband802dot11","displayName":"Turn off ability to configure using WCN over In-band 802.11 WLAN","description":null,"helpText":"","infoUrls":[],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableinband802dot11_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableinband802dot11_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableupnp","displayName":"Turn off ability to configure using WCN over Ethernet (UPnP)","description":null,"helpText":"","infoUrls":[],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableupnp_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableupnp_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disablewpd","displayName":"Turn off ability to configure Windows Portable Device (WPD)","description":null,"helpText":"","infoUrls":[],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disablewpd_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disablewpd_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_maxwcndevicenumber","displayName":"Maximum number of WCN devices allowed:","description":null,"helpText":"","infoUrls":[],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_higher_precedence_registrar","displayName":"Higher precedence medium for devices discovered by multiple media:","description":null,"helpText":"","infoUrls":[],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_higher_precedence_registrar_1","displayName":"WCN over Ethernet (UPnP)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_higher_precedence_registrar_2","displayName":"WCN over In-band 802.11 WLAN","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_checksamesourceandtargetforfranddfs","displayName":"Verify old and new Folder Redirection targets point to the same share before redirecting","description":"This policy setting allows you to prevent data loss when you change the target location for Folder Redirection, and the new and old targets point to the same network share, but have different network paths.\r\n\r\nIf you enable this policy setting, Folder Redirection creates a temporary file in the old location in order to verify that new and old locations point to the same network share. If both new and old locations point to the same share, the target path is updated and files are not copied or deleted. The temporary file is deleted.\r\n\r\nIf you disable or do not configure this policy setting, Folder Redirection does not create a temporary file and functions as if both new and old locations point to different shares when their network paths are different.\r\n\r\nNote: If the paths point to different network shares, this policy setting is not required. If the paths point to the same network share, any data contained in the redirected folders is deleted if this policy setting is not enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-checksamesourceandtargetforfranddfs"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_checksamesourceandtargetforfranddfs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_checksamesourceandtargetforfranddfs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_defaultlibrarieslocation","displayName":"Location where all default Library definition files for users/machines reside.","description":"\r\nThis policy setting allows you to specify a location where all default Library definition files for users/machines reside.\r\n\r\nIf you enable this policy setting, administrators can specify a path where all default Library definition files for users reside. The user will not be allowed to make changes to these Libraries from the UI. On every logon, the policy settings are verified and Libraries for the user are updated or changed according to the path defined.\r\n\r\nIf you disable or do not configure this policy setting, no changes are made to the location of the default Library definition files.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-defaultlibrarieslocation"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_defaultlibrarieslocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_defaultlibrarieslocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_defaultlibrarieslocation_defaultlibrarieslocation","displayName":"Default Libraries definition location","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_disablebinddirectlytopropertysetstorage","displayName":"Disable binding directly to IPropertySetStorage without intermediate layers.","description":"\r\nChanges the behavior of IShellFolder::BindToObject for IID_IPropertySetStorage to not bind directly to the IPropertySetStorage implementation, and to include the intermediate layers provided by the Property System. This behavior is consistent with Windows Vista's behavior in this scenario.\r\n\r\nThis disables access to user-defined properties, and properties stored in NTFS secondary streams.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-disablebinddirectlytopropertysetstorage"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_disablebinddirectlytopropertysetstorage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_disablebinddirectlytopropertysetstorage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_disablemotwoninsecurepathcopy","displayName":"Do not apply the Mark of the Web tag to files copied from insecure sources","description":"This policy setting determines the application of the Mark of the Web tag to files sourced from insecure locations.\n\nIf you enable this policy setting, files copied from unsecure sources will not be tagged with the Mark of the Web.\n\nIf you disable or do not configure this policy setting, files copied from unsecure sources will be tagged with the appropriate Mark of the Web.\n\nNote: Failure to tag files from unsecure sources with the Mark of the Web can expose users’ computers to security risks.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-disablemotwoninsecurepathcopy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_disablemotwoninsecurepathcopy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_disablemotwoninsecurepathcopy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enableshellshortcuticonremotepath","displayName":"Allow the use of remote paths in file shortcut icons","description":"This policy setting determines whether remote paths can be used for file shortcut (.lnk file) icons.\r\n\r\nIf you enable this policy setting, file shortcut icons are allowed to be obtained from remote paths.\r\n\r\nIf you disable or do not configure this policy setting, file shortcut icons that use remote paths are prevented from being displayed.\r\n\r\nNote: Allowing the use of remote paths in file shortcut icons can expose users’ computers to security risks.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-enableshellshortcuticonremotepath"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enableshellshortcuticonremotepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enableshellshortcuticonremotepath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen","displayName":"Configure Windows Defender SmartScreen","description":"This policy allows you to turn Windows Defender SmartScreen on or off. SmartScreen helps protect PCs by warning users before running potentially malicious programs downloaded from the Internet. This warning is presented as an interstitial dialog shown before running an app that has been downloaded from the Internet and is unrecognized or known to be malicious. No dialog is shown for apps that do not appear to be suspicious.\r\n\r\nSome information is sent to Microsoft about files and programs run on PCs with this feature enabled.\r\n\r\nIf you enable this policy, SmartScreen will be turned on for all users. Its behavior can be controlled by the following options:\r\n\r\n• Warn and prevent bypass\r\n• Warn\r\n\r\nIf you enable this policy with the \"Warn and prevent bypass\" option, SmartScreen's dialogs will not present the user with the option to disregard the warning and run the app. SmartScreen will continue to show the warning on subsequent attempts to run the app.\r\n\r\nIf you enable this policy with the \"Warn\" option, SmartScreen's dialogs will warn the user that the app appears suspicious, but will permit the user to disregard the warning and run the app anyway. SmartScreen will not warn the user again for that app if the user tells SmartScreen to run the app.\r\n\r\nIf you disable this policy, SmartScreen will be turned off for all users. Users will not be warned if they try to run suspicious apps from the Internet.\r\n\r\nIf you do not configure this policy, SmartScreen will be enabled by default, but users may change their settings.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-enablesmartscreen"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_enablesmartscreendropdown","displayName":"Pick one of the following settings:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_enablesmartscreendropdown_block","displayName":"Warn and prevent bypass","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_enablesmartscreendropdown_warn","displayName":"Warn","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized","displayName":"Start File Explorer with ribbon minimized","description":"This policy setting allows you to specify whether the ribbon appears minimized or in full when new File Explorer windows are opened. If you enable this policy setting, you can set how the ribbon appears the first time users open File Explorer and whenever they open new windows. If you disable or do not configure this policy setting, users can choose how the ribbon appears when they open new windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-explorerribbonstartsminimized"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_explorerribbonstartsminimizeddropdown","displayName":"Pick one of the following settings","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_explorerribbonstartsminimizeddropdown_1","displayName":"Always open new File Explorer windows with the ribbon minimized.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_explorerribbonstartsminimizeddropdown_2","displayName":"Never open new File Explorer windows with the ribbon minimized.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_explorerribbonstartsminimizeddropdown_3","displayName":"Minimize the ribbon when File Explorer is opened the first time.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_explorerribbonstartsminimizeddropdown_4","displayName":"Display the full ribbon when File Explorer is opened the first time.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internet","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-internet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internetlockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-internetlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internetlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internetlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranet","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-intranet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranetlockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-intranetlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranetlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranetlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachine","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-localmachine"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-localmachinelockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restricted","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users cannot preview items or get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-restricted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restricted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restricted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restrictedlockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users cannot preview items or get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-restrictedlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restrictedlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restrictedlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trusted","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-trusted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trusted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trusted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trustedlockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-trustedlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trustedlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trustedlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internet","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-internet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internetlockdown","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-internetlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internetlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internetlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranet","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-intranet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranetlockdown","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-intranetlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranetlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranetlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_localmachine","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-localmachine"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_localmachine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_localmachine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_localmachinelockdown","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-localmachinelockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_localmachinelockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_localmachinelockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_restricted","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users cannot perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-restricted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_restricted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_restricted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_restrictedlockdown","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users cannot perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-restrictedlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_restrictedlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_restrictedlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trusted","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-trusted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trusted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trusted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trustedlockdown","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-trustedlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trustedlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trustedlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_nonewappalert","displayName":"Do not show the 'new application installed' notification","description":"This policy removes the end-user notification for new application associations. These associations are based on file types (e.g. *.txt) or protocols (e.g. http:)\r\n\r\nIf this group policy is enabled, no notifications will be shown. If the group policy is not configured or disabled, notifications will be shown to the end user if a new application has been installed that can handle the file type or protocol association that was invoked.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nonewappalert"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_nonewappalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_nonewappalert_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_nostrcmplogical","displayName":"Turn off numerical sorting in File Explorer","description":"\r\nThis policy setting allows you to have file names sorted literally (as in Windows 2000 and earlier) rather than in numerical order.\r\nIf you enable this policy setting, File Explorer will sort file names by each digit in a file name (for example, 111 < 22 < 3).\r\nIf you disable or do not configure this policy setting, File Explorer will sort file names by increasing number value (for example, 3 < 22 < 111).\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nostrcmplogical"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_nostrcmplogical_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_nostrcmplogical_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_shellprotocolprotectedmodetitle_2","displayName":"Turn off shell protocol protected mode","description":"This policy setting allows you to configure the amount of functionality that the shell protocol can have. When using the full functionality of this protocol, applications can open folders and launch files. The protected mode reduces the functionality of this protocol allowing applications to only open a limited set of folders. Applications are not able to open files with this protocol when it is in the protected mode. It is recommended to leave this protocol in the protected mode to increase the security of Windows.\r\n\r\nIf you enable this policy setting the protocol is fully enabled, allowing the opening of folders and files.\r\n\r\nIf you disable this policy setting the protocol is in the protected mode, allowing applications to only open a limited set of folders.\r\n\r\nIf you do not configure this policy setting the protocol is in the protected mode, allowing applications to only open a limited set of folders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-shellprotocolprotectedmodetitle-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_shellprotocolprotectedmodetitle_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_shellprotocolprotectedmodetitle_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showhibernateoption","displayName":"Show hibernate in the power options menu","description":"Shows or hides hibernate from the power options menu.\r\n\r\nIf you enable this policy setting, the hibernate option will be shown in the Power Options menu (as long as it is supported by the machine's hardware).\r\n\r\nIf you disable this policy setting, the hibernate option will never be shown in the Power Options menu.\r\n\r\nIf you do not configure this policy setting, users will be able to choose whether they want hibernate to show through the Power Options Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-showhibernateoption"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showhibernateoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showhibernateoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showsleepoption","displayName":"Show sleep in the power options menu","description":"Shows or hides sleep from the power options menu.\r\n\r\nIf you enable this policy setting, the sleep option will be shown in the Power Options menu (as long as it is supported by the machine's hardware).\r\n\r\nIf you disable this policy setting, the sleep option will never be shown in the Power Options menu.\r\n\r\nIf you do not configure this policy setting, users will be able to choose whether they want sleep to show through the Power Options Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-showsleepoption"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showsleepoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showsleepoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpdllcachedir","displayName":"Specify Windows File Protection cache location (Windows Insiders only)","description":"This policy setting specifies an alternate location for the Windows File Protection cache.\r\n\r\nIf you enable this policy setting, enter the fully qualified local path to the new location in the \"Cache file path\" box.\r\n\r\nIf you disable this setting or do not configure it, the Windows File Protection cache is located in the %Systemroot%\\System32\\Dllcache directory.\r\n\r\nNote: Do not put the cache on a network shared directory.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsfileprotection#admx-windowsfileprotection-wfpdllcachedir"],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":[{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpdllcachedir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpdllcachedir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpdllcachedir_wfpdllcachedirbox","displayName":"Cache file path: (Device)","description":"\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":[],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpquota","displayName":"Limit Windows File Protection cache size (Windows Insiders only)","description":"This policy setting specifies the maximum amount of disk space that can be used for the Windows File Protection file cache.\r\n\r\nWindows File Protection adds protected files to the cache until the cache content reaches the quota. If the quota is greater than 50 MB, Windows File Protection adds other important Windows XP files to the cache until the cache size reaches the quota.\r\n\r\nIf you enable this policy setting, enter the maximum amount of disk space to be used (in MB). To indicate that the cache size is unlimited, select \"4294967295\" as the maximum amount of disk space.\r\n\r\nIf you disable this policy setting or do not configure it, the default value is set to 50 MB on Windows XP Professional and is unlimited (4294967295 MB) on Windows Server 2003.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsfileprotection#admx-windowsfileprotection-wfpquota"],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":[{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpquota_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpquota_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpquota_wfpquota_size","displayName":"Cache size (in MB) (Device)","description":"\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":[],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpscan","displayName":"Set Windows File Protection scanning (Windows Insiders only)","description":"This policy setting allows you to set when Windows File Protection scans protected files. This policy setting directs Windows File Protection to enumerate and scan all system files for changes.\r\n\r\nIf you enable this policy setting, select a rate from the \"Scanning Frequency\" box. You can use this setting to direct Windows File Protection to scan files more often.\r\n\r\n-- \"Do not scan during startup,\" the default, scans files only during setup.\r\n\r\n-- \"Scan during startup\" also scans files each time you start Windows XP. This setting delays each startup.\r\n\r\nIf you disable or do not configure this policy setting, by default, files are scanned only during setup.\r\n\r\nNote: This policy setting affects file scanning only. It does not affect the standard background file change detection that Windows File Protection provides.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsfileprotection#admx-windowsfileprotection-wfpscan"],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":[{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpscan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpscan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpscan_wfpscanlist","displayName":"Scanning frequency: (Device)","description":"\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":[],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":[{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpscan_wfpscanlist_0","displayName":"Do not scan during startup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpscan_wfpscanlist_1","displayName":"Scan during startup","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpshowprogress","displayName":"Hide the file scan progress window (Windows Insiders only)","description":"This policy setting hides the file scan progress window. This window provides status information to sophisticated users, but it might confuse novices.\r\n\r\nIf you enable this policy setting, the file scan window does not appear during file scanning.\r\n\r\nIf you disable or do not configure this policy setting, the file scan progress window appears.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsfileprotection#admx-windowsfileprotection-wfpshowprogress"],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":[{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpshowprogress_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpshowprogress_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediadrm_disableonline","displayName":"Prevent Windows Media DRM Internet Access","description":"Prevents Windows Media Digital Rights Management (DRM) from accessing the Internet (or intranet).\r\n\r\nWhen enabled, Windows Media DRM is prevented from accessing the Internet (or intranet) for license acquisition and security upgrades.\r\n\r\nWhen this policy is enabled, programs are not able to acquire licenses for secure content, upgrade Windows Media DRM security components, or restore backed up content licenses. Secure content that is already licensed to the local computer will continue to play. Users are also able to protect music that they copy from a CD and play this protected content on their computer, since the license is generated locally in this scenario.\r\n\r\nWhen this policy is either disabled or not configured, Windows Media DRM functions normally and will connect to the Internet (or intranet) to acquire licenses, download security upgrades, and perform license restoration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediadrm#admx-windowsmediadrm-disableonline"],"categoryId":"19ab385f-14f5-47cd-87b2-f4784eedcdd9","categoryName":"Windows Media Digital Rights Management","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediadrm_disableonline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediadrm_disableonline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disableautoupdate","displayName":"Prevent Automatic Updates","description":"This policy setting allows you to turn off do not show first use dialog boxes.\r\n\r\nIf you enable this policy setting, the Privacy Options and Installation Options dialog boxes are prevented from being displayed the first time a user starts Windows Media Player.\r\n\r\nThis policy setting prevents the dialog boxes which allow users to select privacy, file types, and other desktop options from being displayed when the Player is first started. Some of the options can be configured by using other Windows Media Player group policies.\r\n\r\nIf you disable or do not configure this policy setting, the dialog boxes are displayed when the user starts the Player for the first time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-disableautoupdate"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disableautoupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disableautoupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disablesetupfirstuseconfiguration","displayName":"Do Not Show First Use Dialog Boxes","description":"This policy setting allows you to prevent the anchor window from being displayed when Windows Media Player is in skin mode.\r\n\r\nIf you enable this policy setting, the anchor window is hidden when the Player is in skin mode. In addition, the option on the Player tab in the Player that enables users to choose whether the anchor window displays is not available.\r\n\r\nIf you disable or do not configure this policy setting, users can show or hide the anchor window when the Player is in skin mode by using the Player tab in the Player.\r\n\r\nIf you do not configure this policy setting, and the \"Set and lock skin\" policy setting is enabled, some options in the anchor window are not available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-disablesetupfirstuseconfiguration"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disablesetupfirstuseconfiguration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disablesetupfirstuseconfiguration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_dontuseframeinterpolation","displayName":"Prevent Video Smoothing","description":"This policy setting allows you to prevent video smoothing from occurring.\r\n\r\nIf you enable this policy setting, video smoothing is prevented, which can improve video playback on computers with limited resources. In addition, the Use Video Smoothing check box in the Video Acceleration Settings dialog box in the Player is cleared and is not available.\r\n\r\nIf you disable this policy setting, video smoothing occurs if necessary, and the Use Video Smoothing check box is selected and is not available.\r\n\r\nIf you do not configure this policy setting, video smoothing occurs if necessary. Users can change the setting for the Use Video Smoothing check box.\r\n\r\nVideo smoothing is available only on the Windows XP Home Edition and Windows XP Professional operating systems.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-dontuseframeinterpolation"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_dontuseframeinterpolation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_dontuseframeinterpolation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventlibrarysharing","displayName":"Prevent Media Sharing","description":"This policy setting allows you to prevent media sharing from Windows Media Player.\r\n\r\nIf you enable this policy setting, any user on this computer is prevented from sharing digital media content from Windows Media Player with other computers and devices that are on the same network. Media sharing is disabled from Windows Media Player or from programs that depend on the Player's media sharing feature.\r\n\r\nIf you disable or do not configure this policy setting, anyone using Windows Media Player can turn media sharing on or off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-preventlibrarysharing"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventlibrarysharing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventlibrarysharing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventquicklaunchshortcut","displayName":"Prevent Quick Launch Toolbar Shortcut Creation","description":"This policy setting allows you to prevent a shortcut for the Player from being added to the Quick Launch bar.\r\n\r\nIf you enable this policy setting, the user cannot add the shortcut for the Player to the Quick Launch bar.\r\n\r\nIf you disable or do not configure this policy setting, the user can choose whether to add the shortcut for the Player to the Quick Launch bar.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-preventquicklaunchshortcut"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventquicklaunchshortcut_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventquicklaunchshortcut_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventwmpdesktopshortcut","displayName":"Prevent Desktop Shortcut Creation","description":"This policy setting allows you to prevent a shortcut icon for the Player from being added to the user's desktop.\r\n\r\nIf you enable this policy setting, users cannot add the Player shortcut icon to their desktops.\r\n\r\nIf you disable or do not configure this policy setting, users can choose whether to add the Player shortcut icon to their desktops.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-preventwmpdesktopshortcut"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventwmpdesktopshortcut_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventwmpdesktopshortcut_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsremotemanagement_disallowkerberos_1","displayName":"Disallow Kerberos authentication","description":"This policy setting allows you to manage whether the Windows Remote Management (WinRM) service accepts Kerberos credentials over the network.\r\n\r\n If you enable this policy setting, the WinRM service does not accept Kerberos credentials over the network.\r\n\r\n If you disable or do not configure this policy setting, the WinRM service accepts Kerberos authentication from a remote client.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsremotemanagement#admx-windowsremotemanagement-disallowkerberos-1"],"categoryId":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","categoryName":"Win RM Service","options":[{"id":"device_vendor_msft_policy_config_admx_windowsremotemanagement_disallowkerberos_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsremotemanagement_disallowkerberos_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsremotemanagement_disallowkerberos_2","displayName":"Disallow Kerberos authentication","description":"This policy setting allows you to manage whether the Windows Remote Management (WinRM) client uses Kerberos authentication directly.\r\n\r\nIf you enable this policy setting, the Windows Remote Management (WinRM) client does not use Kerberos authentication directly. Kerberos can still be used if the WinRM client is using the Negotiate authentication and Kerberos is selected.\r\n\r\nIf you disable or do not configure this policy setting, the WinRM client uses the Kerberos authentication directly.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsremotemanagement#admx-windowsremotemanagement-disallowkerberos-2"],"categoryId":"0f6d725e-2c2d-4926-8e78-3d2d5867eef5","categoryName":"Win RM Client","options":[{"id":"device_vendor_msft_policy_config_admx_windowsremotemanagement_disallowkerberos_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsremotemanagement_disallowkerberos_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableautodownloadwin8","displayName":"Turn off Automatic Download of updates on Win8 machines","description":"Enables or disables the automatic download of app updates on PCs running Windows 8.\r\n\r\nIf you enable this setting, the automatic download of app updates is turned off.\r\n\r\nIf you disable this setting, the automatic download of app updates is turned on.\r\n\r\nIf you don't configure this setting, the automatic download of app updates is determined by a registry setting that the user can change using Settings in the Microsoft Store.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsstore#admx-windowsstore-disableautodownloadwin8"],"categoryId":"be9bdbec-b52e-4174-9c5b-cf765dee855b","categoryName":"Store","options":[{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableautodownloadwin8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableautodownloadwin8_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableosupgrade_2","displayName":"Turn off the offer to update to the latest version of Windows","description":"Enables or disables the Store offer to update to the latest version of Windows.\r\n\r\nIf you enable this setting, the Store application will not offer updates to the latest version of Windows.\r\n\r\nIf you disable or do not configure this setting the Store application will offer updates to the latest version of Windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsstore#admx-windowsstore-disableosupgrade-2"],"categoryId":"be9bdbec-b52e-4174-9c5b-cf765dee855b","categoryName":"Store","options":[{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableosupgrade_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableosupgrade_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsstore_removewindowsstore_2","displayName":"Turn off the Store application","description":"Denies or allows access to the Store application.\r\n\r\nIf you enable this setting, access to the Store application is denied. Access to the Store is required for installing app updates.\r\n\r\nIf you disable or don't configure this setting, access to the Store application is allowed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsstore#admx-windowsstore-removewindowsstore-2"],"categoryId":"be9bdbec-b52e-4174-9c5b-cf765dee855b","categoryName":"Store","options":[{"id":"device_vendor_msft_policy_config_admx_windowsstore_removewindowsstore_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsstore_removewindowsstore_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wininit_disablenamedpipeshutdownpolicydescription","displayName":"Turn off legacy remote shutdown interface","description":"This policy setting controls the legacy remote shutdown interface (named pipe). The named pipe remote shutdown interface is needed in order to shutdown this system from a remote Windows XP or Windows Server 2003 system.\r\n\r\nIf you enable this policy setting, the system does not create the named pipe remote shutdown interface.\r\n\r\nIf you disable or do not configure this policy setting, the system creates the named pipe remote shutdown interface.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wininit#admx-wininit-disablenamedpipeshutdownpolicydescription"],"categoryId":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","categoryName":"Shutdown Options","options":[{"id":"device_vendor_msft_policy_config_admx_wininit_disablenamedpipeshutdownpolicydescription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wininit_disablenamedpipeshutdownpolicydescription_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wininit_hiberboot","displayName":"Require use of fast startup","description":"This policy setting controls the use of fast startup. \r\n\r\nIf you enable this policy setting, the system requires hibernate to be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the local setting is used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wininit#admx-wininit-hiberboot"],"categoryId":"60b55db1-53fc-45ea-93d3-e4372b1e19a5","categoryName":"Shutdown","options":[{"id":"device_vendor_msft_policy_config_admx_wininit_hiberboot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wininit_hiberboot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription","displayName":"Timeout for hung logon sessions during shutdown","description":"This policy setting configures the number of minutes the system waits for the hung logon sessions before proceeding with the system shutdown.\r\n\r\nIf you enable this policy setting, the system waits for the hung logon sessions for the number of minutes specified.\r\n\r\nIf you disable or do not configure this policy setting, the default timeout value is 3 minutes for workstations and 15 minutes for servers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wininit#admx-wininit-shutdowntimeouthungsessionsdescription"],"categoryId":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","categoryName":"Shutdown Options","options":[{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription_shutdownsessiontimeout_time","displayName":"Hung session timeout in Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","categoryName":"Shutdown Options","options":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_displaylastlogoninfodescription","displayName":"Display information about previous logons during user logon","description":"This policy setting controls whether or not the system displays information about previous logons and logon failures to the user.\r\n\r\nFor local user accounts and domain user accounts in domains of at least a Windows Server 2008 functional level, if you enable this setting, a message appears after the user logs on that displays the date and time of the last successful logon by that user, the date and time of the last unsuccessful logon attempted with that user name, and the number of unsuccessful logons since the last successful logon by that user. This message must be acknowledged by the user before the user is presented with the Microsoft Windows desktop.\r\n\r\nFor domain user accounts in Windows Server 2003, Windows 2000 native, or Windows 2000 mixed functional level domains, if you enable this setting, a warning message will appear that Windows could not retrieve the information and the user will not be able to log on. Therefore, you should not enable this policy setting if the domain is not at the Windows Server 2008 domain functional level.\r\n\r\nIf you disable or do not configure this setting, messages about the previous logon or logon failures are not displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-winlogon#admx-winlogon-displaylastlogoninfodescription"],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_admx_winlogon_displaylastlogoninfodescription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_displaylastlogoninfodescription_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_winlogon_reportcachedlogonpolicydescription","displayName":"Report when logon server was not available during user logon","description":"This policy controls whether the logged on user should be notified if the logon server could not be contacted during logon and he has been logged on using previously stored account information.\r\n\r\nIf enabled, a notification popup will be displayed to the user when the user logs on with cached credentials.\r\n\r\nIf disabled or not configured, no popup will be displayed to the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-winlogon#admx-winlogon-reportcachedlogonpolicydescription"],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_admx_winlogon_reportcachedlogonpolicydescription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_reportcachedlogonpolicydescription_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration","displayName":"Disable or enable software Secure Attention Sequence","description":"This policy setting controls whether or not software can simulate the Secure Attention Sequence (SAS).\r\n\r\nIf you enable this policy setting, you have one of four options:\r\n\r\nIf you set this policy setting to \"None,\" user mode software cannot simulate the SAS.\r\nIf you set this policy setting to \"Services,\" services can simulate the SAS.\r\nIf you set this policy setting to \"Ease of Access applications,\" Ease of Access applications can simulate the SAS.\r\nIf you set this policy setting to \"Services and Ease of Access applications,\" both services and Ease of Access applications can simulate the SAS.\r\n\r\nIf you disable or do not configure this setting, only Ease of Access applications running on the secure desktop can simulate the SAS.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-winlogon#admx-winlogon-softwaresasgeneration"],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_softwaresasgenerationdescription","displayName":"Set which software is allowed to generate the Secure Attention Sequence","description":null,"helpText":"","infoUrls":[],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_softwaresasgenerationdescription_0","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_softwaresasgenerationdescription_1","displayName":"Services","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_softwaresasgenerationdescription_2","displayName":"Ease of Access applications","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_softwaresasgenerationdescription_3","displayName":"Services and Ease of Access applications","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_winsrv_allowblockingappsatshutdown","displayName":"Turn off automatic termination of applications that block or cancel shutdown","description":"This policy setting specifies whether Windows will allow console applications and GUI applications without visible top-level windows to block or cancel shutdown. By default, such applications are automatically terminated if they attempt to cancel shutdown or block it indefinitely.\r\n\r\nIf you enable this setting, console applications or GUI applications without visible top-level windows that block or cancel shutdown will not be automatically terminated during shutdown.\r\n\r\nIf you disable or do not configure this setting, these applications will be automatically terminated during shutdown, helping to ensure that Windows can shut down faster and more smoothly.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-winsrv#admx-winsrv-allowblockingappsatshutdown"],"categoryId":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","categoryName":"Shutdown Options","options":[{"id":"device_vendor_msft_policy_config_admx_winsrv_allowblockingappsatshutdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winsrv_allowblockingappsatshutdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost","displayName":"Set Cost","description":"This policy setting configures the cost of Wireless LAN (WLAN) connections on the local machine.\r\n\r\nIf this policy setting is enabled, a drop-down list box presenting possible cost values will be active. Selecting one of the following values from the list will set the cost of all WLAN connections on the local machine:\r\n\r\n- Unrestricted: Use of this connection is unlimited and not restricted by usage charges and capacity constraints. \r\n\r\n- Fixed: Use of this connection is not restricted by usage charges and capacity constraints up to a certain data limit. \r\n\r\n- Variable: This connection is costed on a per byte basis.\r\n\r\nIf this policy setting is disabled or is not configured, the cost of Wireless LAN connections is Unrestricted by default.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wlansvc#admx-wlansvc-setcost"],"categoryId":"6cd02266-a42f-4675-b83e-37360dbf3c68","categoryName":"WLAN Media Cost","options":[{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost_cost_dropdownlist","displayName":"Please select a wlan connection cost value to set:","description":null,"helpText":"","infoUrls":[],"categoryId":"6cd02266-a42f-4675-b83e-37360dbf3c68","categoryName":"WLAN Media Cost","options":[{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost_cost_dropdownlist_1","displayName":"Unrestricted","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost_cost_dropdownlist_2","displayName":"Fixed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost_cost_dropdownlist_3","displayName":"Variable","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinenforced","displayName":"Require PIN pairing","description":"This policy applies to Wireless Display connections. This policy means that the use of a PIN for pairing to Wireless Display devices is required rather than optional.\r\n\r\nConversely it means that Push Button is NOT allowed.\r\n\r\nIf this policy setting is disabled or is not configured, by default Push Button pairing is allowed (but not necessarily preferred).\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wlansvc#admx-wlansvc-setpinenforced"],"categoryId":"4dd8280d-6c01-4a06-bfd1-e1cb4c529494","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinenforced_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinenforced_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinpreferred","displayName":"Prefer PIN pairing","description":"This policy applies to Wireless Display connections. This policy changes the preference order of the pairing methods.\r\n\r\nWhen enabled, it makes the connections to prefer a PIN for pairing to Wireless Display devices over the Push Button pairing method.\r\n\r\nIf this policy setting is disabled or is not configured, by default Push Button pairing is preferred (if allowed by other policies).\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wlansvc#admx-wlansvc-setpinpreferred"],"categoryId":"4dd8280d-6c01-4a06-bfd1-e1cb4c529494","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinpreferred_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinpreferred_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_workfoldersclient_pol_machineenableworkfolders","displayName":"Force automatic setup for all users","description":"This policy setting specifies whether Work Folders should be set up automatically for all users of the affected computer.\r\n \r\nIf you enable this policy setting, Work Folders will be set up automatically for all users of the affected computer. This prevents users from choosing not to use Work Folders on the computer; it also prevents them from manually specifying the local folder in which Work Folders stores files. Work Folders will use the settings specified in the \"Specify Work Folders settings\" policy setting in User Configuration\\Administrative Templates\\Windows Components\\WorkFolders. If the \"Specify Work Folders settings\" policy setting does not apply to a user, Work Folders is not automatically set up.\r\n \r\nIf you disable or do not configure this policy setting, Work Folders uses the \"Force automatic setup\" option of the \"Specify Work Folders settings\" policy setting to determine whether to automatically set up Work Folders for a given user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-workfoldersclient#admx-workfoldersclient-pol-machineenableworkfolders"],"categoryId":"87667b72-85ce-48c2-8023-e6db7f5fe739","categoryName":"Work Folders","options":[{"id":"device_vendor_msft_policy_config_admx_workfoldersclient_pol_machineenableworkfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_workfoldersclient_pol_machineenableworkfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wpn_notoastnotification","displayName":"Turn off toast notifications","description":"\n This policy setting turns off toast notifications for applications.\n\n If you enable this policy setting, applications will not be able to raise toast notifications.\n\n Note that this policy does not affect taskbar notification balloons.\n\n Note that Windows system features are not affected by this policy. You must enable/disable system features individually to stop their ability to raise toast notifications.\n\n If you disable or do not configure this policy setting, toast notifications are enabled and can be turned off by the administrator or user.\n\n No reboots or service restarts are required for this policy setting to take effect.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wpn#admx-wpn-notoastnotification"],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":[{"id":"device_vendor_msft_policy_config_admx_wpn_notoastnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wpn_notoastnotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls","displayName":"App Control for Business Built In Controls","description":"App Control for Business Built In Controls","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_enable_app_control","displayName":"Enable App Control for Business policy to trust Windows components and Store apps","description":"Select Audit only to log all events in local client logs but not block any apps from running or select Enforce to actively block apps from running in a deployed App Control for Business base policy. App Control for Business policies created in either Audit only or Enforce mode will be deployed as rebootless base policies to all devices targeted./nBy default, any devices targeted with this App Control for Business policy will have the setting to Trust Windows components and Store apps enabled, in either audit or enforce mode based on your selection.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_enable_app_control_0","displayName":"Enforce","description":"Enforce","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_enable_app_control_1","displayName":"Audit only","description":"Audit only","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_trust_apps","displayName":"Select additional rules for trusting apps","description":"By default, any devices targeted with this App Control for Business policy will have the setting to Trust Windows components and Store apps enabled, in either audit or enforce mode based on your selection./nFurther, you can optionally add some additional rules to your policy, such as selecting Trust apps with good reputation to allow reputable apps as defined by the Microsoft Intelligent Security Graph to run./nSelect Trust apps from managed installers to allow apps deployed via authorized sources of application deployment (managed installers). The Intune management extension will be considered a managed installer if it has been set as such within your organization. Any apps not marked as coming from a managed installer will not be allowed to run./nAll other apps and files not specified by the rules in this App Control for Business policy will be audited only in local client logs (if Audit only is selected), or blocked (if Enforce is selected) from running on devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_trust_apps_0","displayName":"Trust apps with good reputation","description":"Trust app with good reputation","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_trust_apps_1","displayName":"Trust apps from managed installers","description":"Trust apps from managed installers","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrol_policies_{policyguid}_policiesoptions","displayName":"Configuration settings format","description":"Select Enter XML data to type or paste an XML property list that contains your App Control for Business policy. Select Use built-in controls to choose from toggles exposed in this App Control for Business policy. Setting this to Not Configured will result in default behaviour on the device with no added options from the ApplicationControl CSP on the device.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_applicationcontrol_configure_xml_selected","displayName":"Enter xml data","description":"Enter xml data","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_selected","displayName":"Use built-in controls","description":"Use built-in controls","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrol_policies_{policyguid}_xml","displayName":"App Control for Business policy","description":"The format of the XML property list varies depending on the settings you are configuring for the ApplicationControl CSP. Microsoft Endpoint Manager will validate the XML format; but not validate the settings behaviour, the settings applicability nor sign the policy binary. ApplicationControl CSP supports base and supplemental policies for devices running the Windows 1903 build and later. Supplemental policies are required to loosen a base policy; and are always less restrictive. A supplemental policy needs to support a specific base policy that has been deployed to the same client. If not, there is no effect on assigned Windows devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_auditmode","displayName":"Audit mode","description":"Turning audit mode on will not enforce the policy. We recommend first running the poliy with audit mode turned on prior to enforcement to determine the impacts of the policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_auditmode_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_auditmode_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_buildoptions","displayName":"Policy creation type","description":"Select Enter XML data to type or paste an XML property list that contains your Application Control policy. Select Use built-in controls to choose from toggles exposed in this Application Control policy. Setting this to Not Configured will result in default behaviour on the device with no added options from the ApplicationControl CSP on the device.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_buildoptions_upload_xml_selected","displayName":"XML upload","description":"XML upload","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_buildoptions_built_in_controls_selected","displayName":"Built-in controls","description":"Built-in controls","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions","displayName":"Configuration settings format","description":"Select Enter XML data to type or paste an XML property list that contains your Application Control policy. Select Use built-in controls to choose from toggles exposed in this Application Control policy. Setting this to Not Configured will result in default behaviour on the device with no added options from the ApplicationControl CSP on the device.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_uploadxml","displayName":"Enter xml data","description":"Enter xml data","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_builtincontrols","displayName":"Use built-in controls","description":"Use built-in controls","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}","displayName":"Policy rules","description":"","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/defender-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_action","displayName":"Action","description":"Sets a rule to allow or deny the configured settings.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_action_allow","displayName":"Allow","description":null,"helpText":null}},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_id","displayName":"Rule Id","description":"The Id of the rule, leave this field blank, it will be filled in automatically.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_name","displayName":"Rule Name","description":"The name of the rule","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type","displayName":"Rule Type","description":"Rule Type","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisher","displayName":"Publisher","description":"Creates a rule for a file that is signed by the software publisher. Upload the output generated by the binary file information extractor for your selected reference file.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filehash","displayName":"File Hash","description":"Creates a rule for a file based on its corresponding hash values. Upload a CSV file containing a list of hash values you want to include in this rule or directly type your hash values in the text area below.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filepath","displayName":"File Path","description":"Creates a rule for a specific file path or folder. Selecting folder will affect all files in a folder.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes","displayName":"File Attributes","description":"Creates a rule for a file based on one of its attributes. Select a file to use as reference for your rule.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_filedescriptiondetails","displayName":"File description","description":"The description of the selected file as stated in the file attributes.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_filenamedetails","displayName":"Original file name","description":"The original name of the applications executable as stated in the file attributes.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_internalnamedetails","displayName":"Internal name","description":"The Internal name of the selected file as stated in the file attributes.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_productnamedetails","displayName":"Product name","description":"The product name of the selected file as stated in the file attributes.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributesdetails","displayName":"File Attributes","description":"Creates a rule for attributes of a selected file.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_filename","displayName":"Original file name","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_filedescription","displayName":"File description","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_productname","displayName":"Minimum version","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_internalname","displayName":"Internal name","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filehashdetails","displayName":"File hash","description":"A set of coma separated hashes for use of the application of this rule.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filepathdetails","displayName":"File Path","description":"The path of the directory or file for application of this rule.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails","displayName":"Publisher","description":"Creates a rule for a file that is signed by the software publisher. Upload the output generated by the binary file information extractor for your selected reference file.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_issuingca","displayName":"Issuing certificate authority","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_publishername","displayName":"Publisher","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_minimumversion","displayName":"Minimum version","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherfilename","displayName":"File name","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_issuingcadetails","displayName":"Issuing certificate authority","description":"The name of the issuing certificate authority","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_minimumversiondetails","displayName":"Minimum Version","description":"The application's minimum version","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_publishernamedetails","displayName":"Publisher","description":"The name of the application publisher","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherfilenamedetails","displayName":"File name","description":"The name of the applications executable file name.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_basepolicyid","displayName":"Base policy id","description":"The id of the base policy for which this supplemental policy applies.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_disableruntimefilepathrules","displayName":"Disable runtime file path rules","description":"Turning this off will disable FilePath rule protection of enforcing user-writeability and onlu allowing admin-writable locations.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_disableruntimefilepathrules_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_disableruntimefilepathrules_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_hypervisorprotectedcodeintegrity","displayName":"Hypervisor protected Code Integrity","description":"When enabled, code integrity runs in a hypervisor-protected container.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_hypervisorprotectedcodeintegrity_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_hypervisorprotectedcodeintegrity_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappsfrommanagedinstaller","displayName":"Trust apps from managed installer","description":"Turning Trust apps from managed installer on will not enforce the policy. We recommend first running the poliy with Trust apps from managed installer turned on prior to enforcement to determine the impacts of the policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappsfrommanagedinstaller_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappsfrommanagedinstaller_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappswithgoodreputation","displayName":"Trust apps with good reputation","description":"When enabled, applications with known good reputation as defined by the Microsoft's Intelligent Security Graph (ISG) are white listed.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappswithgoodreputation_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappswithgoodreputation_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_uploadxmldetails","displayName":"XML Upload","description":"The format of the XML property list varies depending on the settings you are configuring for the ApplicationControl CSP. Microsoft Endpoint Manager will validate the XML format; but not validate the settings behaviour, the settings applicability nor sign the policy binary. ApplicationControl CSP supports base and supplemental policies for devices running the Windows 1903 build and later. Supplemental policies are required to loosen a base policy; and are always less restrictive. A supplemental policy needs to support a specific base policy that has been deployed to the same client. If not, there is no effect on assigned Windows devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappsfrommanagedinstaller","displayName":"Trust apps from managed installer","description":"Turning Trust apps from managed installer on will not enforce the policy. We recommend first running the poliy with Trust apps from managed installer turned on prior to enforcement to determine the impacts of the policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappsfrommanagedinstaller_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappsfrommanagedinstaller_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappswithgoodreputation","displayName":"Trust apps with good reputation","description":"When enabled, applications with known good reputation as defined by the Microsoft's Intelligent Security Graph (ISG) are white listed.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappswithgoodreputation_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappswithgoodreputation_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_xmlupload","displayName":"XML upload","description":"The format of the XML property list varies depending on the settings you are configuring for the ApplicationControl CSP. Microsoft Endpoint Manager will validate the XML format; but not validate the settings behaviour, the settings applicability nor sign the policy binary. ApplicationControl CSP supports base and supplemental policies for devices running the Windows 1903 build and later. Supplemental policies are required to loosen a base policy; and are always less restrictive. A supplemental policy needs to support a specific base policy that has been deployed to the same client. If not, there is no effect on assigned Windows devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationdefaults_defaultassociationsconfiguration","displayName":"Default Associations Configuration","description":"This policy allows an administrator to set default file type and protocol associations. When set, default associations will be applied on sign-in to the PC. The association file can be created using the DISM tool (dism /online /export-defaultappassociations:appassoc. xml), and then needs to be base64 encoded before being added to SyncML. If policy is enabled and the client machine is Azure Active Directory joined, the associations assigned in SyncML will be processed and default associations will be applied.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationDefaults#defaultassociationsconfiguration"],"categoryId":"ddcc8634-edc3-40ef-a444-45f806439c18","categoryName":"Application Defaults","options":null},{"id":"device_vendor_msft_policy_config_applicationdefaults_enableappurihandlers","displayName":"Enable App Uri Handlers","description":"Enables web-to-app linking, which allows apps to be launched with a http(s) URI","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationDefaults#enableappurihandlers"],"categoryId":"ddcc8634-edc3-40ef-a444-45f806439c18","categoryName":"Application Defaults","options":[{"id":"device_vendor_msft_policy_config_applicationdefaults_enableappurihandlers_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationdefaults_enableappurihandlers_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowalltrustedapps","displayName":"Allow All Trusted Apps","description":"Specifies whether non Microsoft Store apps are allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowalltrustedapps"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowalltrustedapps_0","displayName":"Explicit deny.","description":"Explicit deny.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowalltrustedapps_1","displayName":"Explicit allow unlock.","description":"Explicit allow unlock.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowalltrustedapps_65535","displayName":"Not configured.","description":"Not configured.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowappstoreautoupdate","displayName":"Allow apps from the Microsoft app store to auto update","description":"Specifies whether automatic update of apps from Microsoft Store are allowed. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowappstoreautoupdate"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowappstoreautoupdate_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowappstoreautoupdate_1","displayName":"Allowed.","description":"Allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowappstoreautoupdate_2","displayName":"Not configured.","description":"Not configured.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock","displayName":"Allow Developer Unlock","description":"Specifies whether developer unlock is allowed. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowdeveloperunlock"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock_0","displayName":"Explicit deny.","description":"Explicit deny.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock_1","displayName":"Explicit allow unlock.","description":"Explicit allow unlock.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock_65535","displayName":"Not configured.","description":"Not configured.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowgamedvr","displayName":"Allow Game DVR","description":"Note The policy is only enforced in Windows 10 for desktop. Specifies whether DVR and broadcasting is allowed. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowgamedvr"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowgamedvr_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowgamedvr_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowshareduserappdata","displayName":"Allow Shared User App Data","description":"With this policy, you can configure Windows 10 to share application data among multiple users on the system and with other instances of that app. Data shared through the SharedLocal folder is available through the Windows. Storage API. If you previously enabled this policy and now want to disable it, any shared app data remains in the SharedLocal folder.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowshareduserappdata"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowshareduserappdata_0","displayName":"Block","description":"Prevented/not allowed, but Microsoft Edge downloads book files to a per-user folder for each user.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowshareduserappdata_1","displayName":"Allow","description":"Allowed. Microsoft Edge downloads book files into a shared folder. For this policy to work correctly, you must also enable the Allow a Windows app to share application data between users group policy. Also, the users must be signed in with a school or work account.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_blocknonadminuserinstall","displayName":"Block Non Admin User Install","description":"Manages non-administrator users' ability to install Windows app packages. If you enable this policy, non-administrators will be unable to initiate installation of Windows app packages. Administrators who wish to install an app will need to do so from an Administrator context (for example, an Administrator PowerShell window). All users will still be able to install Windows app packages via the Microsoft Store, if permitted by other policies. If you disable or do not configure this policy, all users will be able to initiate installation of Windows app packages.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#blocknonadminuserinstall"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_blocknonadminuserinstall_0","displayName":"Block","description":"Disabled. All users will be able to initiate installation of Windows app packages.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_blocknonadminuserinstall_1","displayName":"Allow","description":"Enabled. Non-administrator users will not be able to initiate installation of Windows app packages.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_disablestoreoriginatedapps","displayName":"Disable Store Originated Apps","description":"Boolean value that disables the launch of all apps from Microsoft Store that came pre-installed or were downloaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#disablestoreoriginatedapps"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_disablestoreoriginatedapps_0","displayName":"Disabled","description":"Enable launch of apps.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_disablestoreoriginatedapps_1","displayName":"Enabled","description":"Disable launch of apps.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_launchappafterlogon","displayName":"Launch App After Log On","description":"List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are to be launched after logon.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#launchappafterlogon"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_msiallowusercontroloverinstall","displayName":"MSI Allow User Control Over Install","description":"This policy setting permits users to change installation options that typically are available only to system administrators. If you enable this policy setting, some of the security features of Windows Installer are bypassed. It permits installations to complete that otherwise would be halted due to a security violation. If you disable or do not configure this policy setting, the security features of Windows Installer prevent users from changing installation options typically reserved for system administrators, such as specifying the directory to which files are installed. If Windows Installer detects that an installation package has permitted the user to change a protected option, it stops the installation and displays a message. These security features operate only when the installation program is running in a privileged security context in which it has access to directories denied to the user. This policy setting is designed for less restrictive environments. It can be used to circumvent errors in an installation program that prevents software from being installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#msiallowusercontroloverinstall"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_msiallowusercontroloverinstall_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_msiallowusercontroloverinstall_1","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_msialwaysinstallwithelevatedprivileges","displayName":"MSI Always Install With Elevated Privileges","description":"This policy setting directs Windows Installer to use elevated permissions when it installs any program on the system. If you enable this policy setting, privileges are extended to all programs. These privileges are usually reserved for programs that have been assigned to the user (offered on the desktop), assigned to the computer (installed automatically), or made available in Add or Remove Programs in Control Panel. This profile setting lets users install programs that require access to directories that the user might not have permission to view or change, including directories on highly restricted computers. If you disable or do not configure this policy setting, the system applies the current user's permissions when it installs programs that a system administrator does not distribute or offer. Note: This policy setting appears both in the Computer Configuration and User Configuration folders. To make this policy setting effective, you must enable it in both folders. Caution: Skilled users can take advantage of the permissions this policy setting grants to change their privileges and gain permanent access to restricted files and folders. Note that the User Configuration version of this policy setting is not guaranteed to be secure.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#msialwaysinstallwithelevatedprivileges"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_msialwaysinstallwithelevatedprivileges_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_msialwaysinstallwithelevatedprivileges_1","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages","displayName":"Remove Default Microsoft Store packages from the system.","description":"Removes Default Microsoft Store packages from the system.\n\nIf you enable this policy, the selected Microsoft Store apps in the provided list will be uninstalled from the system. You can make adjustments to the default settings.\n\nUnselected apps in the list will not be removed.\n\nDefault is 'disabled' (key not present).\n\nIf the policy is disabled or not configured, no Default Microsoft Store packages will be removed from the system.\n\n* This is a headless app (no UI)\n\n** This app is the default handler for a common file type or protocol. Removing this app might result in a degraded user experience. We do not recommend removing this app.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-applicationmanagement#applicationmanagement-removedefaultmicrosoftstorepackages"],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2","displayName":"Remove Microsoft Store apps with dynamic list","description":"Removes Default Microsoft Store packages from the system.\r\n\r\nIf you enable this policy, the selected Microsoft Store apps in the provided list will be uninstalled from the system. You can make adjustments to the default settings.\r\n\r\nUnselected apps in the list will not be removed.\r\n\r\n* This is a headless app (no UI)\r\n\r\n** This app is the default handler for a common file type or protocol. Removing this app might result in a degraded user experience. We do not recommend removing this app.\r\n\r\nIf you enable this policy, you can also remove an app by entering the app's package family name(e.g., Microsoft.WindowsCalculator_8wekyb3d8bbwe) in the dynamic list under \"Specify additional package family names to remove.\".\r\n\r\nIf this policy is enabled, reinstallation of a previously removed app requires de-selecting the app from the provided list or removing the app's package family name from the dynamic list.\r\n\r\nYou cannot remove Windows System components via the dynamic app removal list.\r\n\r\nValidation of package family names in the dynamic app removal list occurs upon user login, not at policy configuration time.\r\n\r\nDefault is 'disabled' (key not present).\r\n\r\nIf the policy is disabled or not configured, no Default apps will be removed from the system.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-applicationmanagement#applicationmanagement-removedefaultmicrosoftstorepackages-2"],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingnews","displayName":"Microsoft News (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingnews_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingnews_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingweather","displayName":"MSN Weather (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingweather_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingweather_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_clipchamp","displayName":"Microsoft Clipchamp (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_clipchamp_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_clipchamp_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_copilot","displayName":"Microsoft Copilot (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_copilot_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_copilot_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_dynamicremovallist","displayName":"Specify additional package family names to remove (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_gamingapp","displayName":"Xbox Gaming App (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_gamingapp_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_gamingapp_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_mediaplayer","displayName":"Windows Media Player ** (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_mediaplayer_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_mediaplayer_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftofficehub","displayName":"Microsoft 365 Copilot (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftofficehub_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftofficehub_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftsolitairecollection","displayName":"Microsoft Solitaire Collection (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftsolitairecollection_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftsolitairecollection_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftstickynotes","displayName":"Microsoft Sticky Notes (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftstickynotes_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftstickynotes_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_msteams","displayName":"Microsoft Teams (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_msteams_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_msteams_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_outlookforwindows","displayName":"Outlook for Windows (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_outlookforwindows_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_outlookforwindows_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_paint","displayName":"Paint (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_paint_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_paint_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_photos","displayName":"Microsoft Photos ** (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_photos_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_photos_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_quickassist","displayName":"Quick Assist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_quickassist_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_quickassist_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_screensketch","displayName":"Snipping Tool (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_screensketch_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_screensketch_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_todo","displayName":"Microsoft To Do (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_todo_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_todo_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscalculator","displayName":"Windows Calculator (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscalculator_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscalculator_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscamera","displayName":"Windows Camera ** (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscamera_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscamera_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsfeedbackhub","displayName":"Feedback Hub (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsfeedbackhub_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsfeedbackhub_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsnotepad","displayName":"Windows Notepad ** (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsnotepad_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsnotepad_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowssoundrecorder","displayName":"Windows Sound Recorder (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowssoundrecorder_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowssoundrecorder_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsterminal","displayName":"Windows Terminal (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsterminal_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsterminal_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxidentityprovider","displayName":"Xbox Identity Provider * (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxidentityprovider_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxidentityprovider_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxspeechtotextoverlay","displayName":"Xbox Speech To Text Overlay * (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxspeechtotextoverlay_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxspeechtotextoverlay_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxtcui","displayName":"Xbox TCUI * (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxtcui_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxtcui_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_bingnews","displayName":"Microsoft News","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_bingnews_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_bingnews_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_bingweather","displayName":"MSN Weather","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_bingweather_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_bingweather_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_clipchamp","displayName":"Microsoft Clipchamp","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_clipchamp_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_clipchamp_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_copilot","displayName":"Microsoft Copilot","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_copilot_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_copilot_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_gamingapp","displayName":"Xbox Gaming App","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_gamingapp_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_gamingapp_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_mediaplayer","displayName":"Windows Media Player **","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_mediaplayer_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_mediaplayer_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftofficehub","displayName":"Microsoft 365 Copilot","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftofficehub_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftofficehub_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftsolitairecollection","displayName":"Microsoft Solitaire Collection","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftsolitairecollection_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftsolitairecollection_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftstickynotes","displayName":"Microsoft Sticky Notes","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftstickynotes_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftstickynotes_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_msteams","displayName":"Microsoft Teams","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_msteams_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_msteams_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_outlookforwindows","displayName":"Outlook for Windows","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_outlookforwindows_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_outlookforwindows_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_paint","displayName":"Paint","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_paint_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_paint_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_photos","displayName":"Microsoft Photos **","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_photos_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_photos_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_quickassist","displayName":"Quick Assist","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_quickassist_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_quickassist_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_screensketch","displayName":"Snipping Tool","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_screensketch_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_screensketch_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_todo","displayName":"Microsoft To Do","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_todo_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_todo_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowscalculator","displayName":"Windows Calculator","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowscalculator_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowscalculator_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowscamera","displayName":"Windows Camera **","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowscamera_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowscamera_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsfeedbackhub","displayName":"Feedback Hub","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsfeedbackhub_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsfeedbackhub_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsnotepad","displayName":"Windows Notepad **","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsnotepad_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsnotepad_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowssoundrecorder","displayName":"Windows Sound Recorder","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowssoundrecorder_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowssoundrecorder_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsterminal","displayName":"Windows Terminal","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsterminal_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsterminal_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxidentityprovider","displayName":"Xbox Identity Provider *","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxidentityprovider_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxidentityprovider_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxspeechtotextoverlay","displayName":"Xbox Speech To Text Overlay *","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxspeechtotextoverlay_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxspeechtotextoverlay_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxtcui","displayName":"Xbox TCUI *","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxtcui_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxtcui_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_requireprivatestoreonly","displayName":"Require Private Store Only","description":"Allows disabling of the retail catalog and only enables the Private store. Most restricted value is 1.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#requireprivatestoreonly"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_requireprivatestoreonly_0","displayName":"Allow both public and Private store.","description":"Allow both public and Private store.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_requireprivatestoreonly_1","displayName":"Only Private store is enabled.","description":"Only Private store is enabled.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_restrictappdatatosystemvolume","displayName":"Restrict App Data To System Volume","description":"Specifies whether application data is restricted to the system drive. Most restricted value is 1.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#restrictappdatatosystemvolume"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_restrictappdatatosystemvolume_0","displayName":"Disabled","description":"Not restricted.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_restrictappdatatosystemvolume_1","displayName":"Enabled","description":"Restricted.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_restrictapptosystemvolume","displayName":"Restrict App To System Volume","description":"Specifies whether the installation of applications is restricted to the system drive. Most restricted value is 1.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#restrictapptosystemvolume"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_restrictapptosystemvolume_0","displayName":"Disabled","description":"Not restricted.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_restrictapptosystemvolume_1","displayName":"Enabled","description":"Restricted.","helpText":null}]},{"id":"device_vendor_msft_policy_config_appruntime_allowmicrosoftaccountstobeoptional","displayName":"Allow Microsoft accounts to be optional","description":"This policy setting lets you control whether Microsoft accounts are optional for packaged Microsoft Store apps that require an account to sign in. This policy only affects packaged Microsoft Store apps that support it.\n\nIf you enable this policy setting, packaged Microsoft Store apps that typically require a Microsoft account to sign in will allow users to sign in with an enterprise account instead.\n\nIf you disable or do not configure this policy setting, users will need to sign in with a Microsoft account.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-appruntime#appruntime-allowmicrosoftaccountstobeoptional"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"device_vendor_msft_policy_config_appruntime_allowmicrosoftaccountstobeoptional_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appruntime_allowmicrosoftaccountstobeoptional_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowappvclient","displayName":"Enable App-V Client","description":"This policy setting allows you to enable or disable Microsoft Application Virtualization (App-V) feature. Reboot is needed for disable to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowappvclient"],"categoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","categoryName":"App-V","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowappvclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowappvclient_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowdynamicvirtualization","displayName":"Enable Dynamic Virtualization","description":"Enables Dynamic Virtualization of supported shell extensions, browser helper objects, and ActiveX controls.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowdynamicvirtualization"],"categoryId":"10835ce3-31c8-4ec6-aa00-c5af48e550a8","categoryName":"Virtualization","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowdynamicvirtualization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowdynamicvirtualization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagecleanup","displayName":"Enable automatic cleanup of unused appv packages","description":"Enables automatic cleanup of appv packages that were added after Windows10 anniversary release.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowpackagecleanup"],"categoryId":"f125d7cd-a333-4f24-a5f4-99fc289c6d22","categoryName":"Package Management","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagecleanup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagecleanup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagescripts","displayName":"Enable Package Scripts","description":"Enables scripts defined in the package manifest of configuration files that should run.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowpackagescripts"],"categoryId":"efabaf11-42e4-48ab-81ca-4514199d239b","categoryName":"Scripting","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagescripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagescripts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpublishingrefreshux","displayName":"Enable Publishing Refresh UX","description":"Enables a UX to display to the user when a publishing refresh is performed on the client.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowpublishingrefreshux"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowpublishingrefreshux_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpublishingrefreshux_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver","displayName":"Reporting Server","description":"Reporting Server URL: Displays the URL of reporting server.\n\n Reporting Time: When the client data should be reported to the server. Acceptable range is 0~23, corresponding to the 24 hours in a day. A good practice is, don't set this time to a busy hour, e.g. 9AM.\n \n Delay reporting for the random minutes: The maximum minutes of random delay on top of the reporting time. For a busy system, the random delay will help reduce the server load.\n \n Repeat reporting for every (days): The periodical interval in days for sending the reporting data.\n \n Data Cache Limit: This value specifies the maximum size in megabytes (MB) of the XML cache for storing reporting information. The default value is 20 MB. The size applies to the cache in memory. When the limit is reached, the log file will roll over. When a new record is to be added (bottom of the list), one or more of the oldest records (top of the list) will be deleted to make room. A warning will be logged to the Client log and the event log the first time this occurs, and will not be logged again until after the cache has been successfully cleared on transmission and the log has filled up again.\n\n Data Block Size: This value specifies the maximum size in bytes to transmit to the server at once on a reporting upload, to avoid permanent transmission failures when the log has reached a significant size. The default value is 65536. When transmitting report data to the server, one block at a time of application records that is less than or equal to the block size in bytes of XML data will be removed from the cache and sent to the server. Each block will have the general Client data and global package list data prepended, and these will not factor into the block size calculations; the potential exists for an extremely large package list to result in transmission failures over low bandwidth or unreliable connections.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowreportingserver"],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_data_block_size","displayName":"Data Block Size","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_data_cache_limit","displayName":"Data Cache Limit","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_interval","displayName":"Repeat reporting for every (days)","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_random_delay","displayName":"Delay reporting for the random minutes","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_reporting_server_url_prompt","displayName":"Reporting Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_start_time","displayName":"Reporting Time","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingfileexclusions","displayName":"Roaming File Exclusions","description":"Specifies the file paths relative to %userprofile% that do not roam with a user's profile. Example usage: /FILEEXCLUSIONLIST='desktop;my pictures'.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowroamingfileexclusions"],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingfileexclusions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingfileexclusions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingfileexclusions_integration_roaming_file_exclusions_prompt","displayName":"Roaming Registry Exclusions","description":"","helpText":"","infoUrls":[],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingregistryexclusions","displayName":"Roaming Registry Exclusions","description":"Specifies the registry paths that do not roam with a user profile. Example usage: /REGISTRYEXCLUSIONLIST=software\\classes;software\\clients.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowroamingregistryexclusions"],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingregistryexclusions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingregistryexclusions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingregistryexclusions_integration_roaming_registry_exclusions_prompt","displayName":"Roaming File Exclusions","description":"","helpText":"","infoUrls":[],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload","displayName":"Specify what to load in background (aka AutoLoad)","description":"Specifies how new packages should be loaded automatically by App-V on a specific computer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowstreamingautoload"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload_steaming_autoload_options","displayName":"Autoload Options","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload_steaming_autoload_options_0","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload_steaming_autoload_options_1","displayName":"Previously Used","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload_steaming_autoload_options_2","displayName":"All","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_clientcoexistenceallowmigrationmode","displayName":"Enable Migration Mode","description":"Migration mode allows the App-V client to modify shortcuts and FTA's for packages created using a previous version of App-V.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-clientcoexistenceallowmigrationmode"],"categoryId":"b9201072-3681-4e95-ad90-869e6166b129","categoryName":"Client Coexistence","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_clientcoexistenceallowmigrationmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_clientcoexistenceallowmigrationmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootglobal","displayName":"Integration Root User","description":"Specifies the location where symbolic links are created to the current version of a per-user published package. Shortcuts, file type associations, etc. are created pointing to this path. If empty, symbolic links are not used during publishing. Example: %localappdata%\\Microsoft\\AppV\\Client\\Integration.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-integrationallowrootglobal"],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootglobal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootglobal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootglobal_integration_root_user_prompt","displayName":"Integration Root User","description":"","helpText":"","infoUrls":[],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootuser","displayName":"Integration Root Global","description":"Specifies the location where symbolic links are created to the current version of a globally published package. Shortcuts, file type associations, etc. are created pointing to this path. If empty, symbolic links are not used during publishing. Example: %allusersprofile%\\Microsoft\\AppV\\Client\\Integration.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-integrationallowrootuser"],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootuser_integration_root_global_prompt","displayName":"Integration Root Global","description":"","helpText":"","infoUrls":[],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1","displayName":"Publishing Server 1 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver1"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_publishing_refresh_options","displayName":"Global Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_interval_prompt","displayName":"Global Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_onlogon_options","displayName":"Global Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_unit_options","displayName":"Global Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_publishing_server1_name_prompt","displayName":"Publishing Server Display Name","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_onlogon_options","displayName":"User Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_unit_options","displayName":"User Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2","displayName":"Publishing Server 2 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver2"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_publishing_refresh_options","displayName":"Global Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_interval_prompt","displayName":"Global Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_onlogon_options","displayName":"Global Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_unit_options","displayName":"Global Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_publishing_server2_name_prompt","displayName":"Publishing Server Display Name","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_onlogon_options","displayName":"User Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_unit_options","displayName":"User Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3","displayName":"Publishing Server 3 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver3"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_publishing_refresh_options","displayName":"Global Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_interval_prompt","displayName":"Global Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_onlogon_options","displayName":"Global Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_unit_options","displayName":"Global Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_publishing_server3_name_prompt","displayName":"Publishing Server Display Name","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_onlogon_options","displayName":"User Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_unit_options","displayName":"User Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4","displayName":"Publishing Server 4 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver4"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_publishing_refresh_options","displayName":"Global Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_interval_prompt","displayName":"Global Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_onlogon_options","displayName":"Global Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_unit_options","displayName":"Global Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_publishing_server4_name_prompt","displayName":"Publishing Server Display Name","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_onlogon_options","displayName":"User Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_unit_options","displayName":"User Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5","displayName":"Publishing Server 5 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver5"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_publishing_refresh_options","displayName":"Global Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_interval_prompt","displayName":"Global Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_onlogon_options","displayName":"Global Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_unit_options","displayName":"Global Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_publishing_server5_name_prompt","displayName":"Publishing Server Display Name","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_onlogon_options","displayName":"User Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_unit_options","displayName":"User Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl","displayName":"Certificate Filter For Client SSL","description":"Specifies the path to a valid certificate in the certificate store.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowcertificatefilterforclient-ssl"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl_streaming_certificate_filter_for_client_ssl_prompt","displayName":"Certificate Filter For Client SSL","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowhighcostlaunch","displayName":"Allow First Time Application Launches if on a High Cost Windows 8 Metered Connection","description":"This setting controls whether virtualized applications are launched on Windows 8 machines connected via a metered network connection (e.g. 4G).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowhighcostlaunch"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowhighcostlaunch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowhighcostlaunch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowlocationprovider","displayName":"Location Provider","description":"Specifies the CLSID for a compatible implementation of the IAppvPackageLocationProvider interface.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowlocationprovider"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowlocationprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowlocationprovider_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowlocationprovider_streaming_location_provider_prompt","displayName":"Location Provider","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackageinstallationroot","displayName":"Package Installation Root","description":"Specifies directory where all new applications and updates will be installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowpackageinstallationroot"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackageinstallationroot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackageinstallationroot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackageinstallationroot_streaming_package_installation_root_prompt","displayName":"Package Installation Root","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackagesourceroot","displayName":"Package Source Root","description":"Overrides source location for downloading package content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowpackagesourceroot"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackagesourceroot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackagesourceroot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackagesourceroot_package_source_root_prompt","displayName":"Package Source Root","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentinterval","displayName":"Reestablishment Interval","description":"Specifies the number of seconds between attempts to reestablish a dropped session.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowreestablishmentinterval"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentinterval_streaming_reestablishment_interval_prompt","displayName":"Reestablishment Interval:","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries","displayName":"Reestablishment Retries","description":"Specifies the number of times to retry a dropped session.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowreestablishmentretries"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries_streaming_reestablishment_retries_prompt","displayName":"Reestablishment Retries:","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingsharedcontentstoremode","displayName":"Shared Content Store (SCS) mode","description":"Specifies that streamed package contents will be not be saved to the local hard disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingsharedcontentstoremode"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingsharedcontentstoremode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingsharedcontentstoremode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingsupportbranchcache","displayName":"Enable Support for BranchCache","description":"If enabled, the App-V client will support BrancheCache compatible HTTP streaming. If BranchCache support is not desired, this should be disabled. The client can then apply HTTP optimizations which are incompatible with BranchCache","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingsupportbranchcache"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingsupportbranchcache_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingsupportbranchcache_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingverifycertificaterevocationlist","displayName":"Verify certificate revocation list","description":"Verifies Server certificate revocation status before streaming using HTTPS.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingverifycertificaterevocationlist"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingverifycertificaterevocationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingverifycertificaterevocationlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_virtualcomponentsallowlist","displayName":"Virtual Component Process Allow List","description":"Specifies a list of process paths (may contain wildcards) which are candidates for using virtual components (shell extensions, browser helper objects, etc). Only processes whose full path matches one of these items can use virtual components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-virtualcomponentsallowlist"],"categoryId":"10835ce3-31c8-4ec6-aa00-c5af48e550a8","categoryName":"Virtualization","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_virtualcomponentsallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_virtualcomponentsallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_virtualcomponentsallowlist_virtualization_jitvallowlist_prompt","displayName":"Virtual Component Process Allow List","description":"","helpText":"","infoUrls":[],"categoryId":"10835ce3-31c8-4ec6-aa00-c5af48e550a8","categoryName":"Virtualization","options":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation","displayName":"Account Logon Audit Credential Validation","description":"This policy setting allows you to audit events generated by validation tests on user account logon credentials. Events in this subcategory occur only on the computer that is authoritative for those credentials. For domain accounts, the domain controller is authoritative. For local accounts, the local computer is authoritative.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogon_auditcredentialvalidation"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosauthenticationservice","displayName":"Account Logon Audit Kerberos Authentication Service","description":"This policy setting allows you to audit events generated by Kerberos authentication ticket-granting ticket (TGT) requests. If you configure this policy setting, an audit event is generated after a Kerberos authentication TGT request. Success audits record successful requests and Failure audits record unsuccessful requests. If you do not configure this policy setting, no audit event is generated after a Kerberos authentication TGT request.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogon_auditkerberosauthenticationservice"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosauthenticationservice_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosauthenticationservice_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosauthenticationservice_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosauthenticationservice_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosserviceticketoperations","displayName":"Account Logon Audit Kerberos Service Ticket Operations","description":"This policy setting allows you to audit events generated by Kerberos authentication ticket-granting ticket (TGT) requests submitted for user accounts. If you configure this policy setting, an audit event is generated after a Kerberos authentication TGT is requested for a user account. Success audits record successful requests and Failure audits record unsuccessful requests. If you do not configure this policy setting, no audit event is generated after a Kerberos authentication TGT is request for a user account.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogon_auditkerberosserviceticketoperations"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosserviceticketoperations_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosserviceticketoperations_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosserviceticketoperations_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosserviceticketoperations_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditotheraccountlogonevents","displayName":"Account Logon Audit Other Account Logon Events","description":"This policy setting allows you to audit events generated by responses to credential requests submitted for a user account logon that are not credential validation or Kerberos tickets. Currently, there are no events in this subcategory.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogon_auditotheraccountlogonevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditotheraccountlogonevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditotheraccountlogonevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditotheraccountlogonevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditotheraccountlogonevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout","displayName":"Account Logon Logoff Audit Account Lockout","description":"This policy setting allows you to audit events generated by a failed attempt to log on to an account that is locked out. If you configure this policy setting, an audit event is generated when an account cannot log on to a computer because the account is locked out. Success audits record successful attempts and Failure audits record unsuccessful attempts. Logon events are essential for understanding user activity and to detect potential attacks.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditaccountlockout"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership","displayName":"Account Logon Logoff Audit Group Membership","description":"This policy allows you to audit the group memberhsip information in the user's logon token. Events in this subcategory are generated on the computer on which a logon session is created. For an interactive logon, the security audit event is generated on the computer that the user logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the computer hosting the resource. When this setting is configured, one or more security audit events are generated for each successful logon. You must also enable the Audit Logon setting under Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff. Multiple events are generated if the group memberhsip information cannot fit in a single security audit event.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditgroupmembership"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecextendedmode","displayName":"Account Logon Logoff Audit I Psec Extended Mode","description":"This policy setting allows you to audit events generated by Internet Key Exchange protocol (IKE) and Authenticated Internet Protocol (AuthIP) during Extended Mode negotiations. If you configure this policy setting, an audit event is generated during an IPsec Extended Mode negotiation. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated during an IPsec Extended Mode negotiation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditipsecextendedmode"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecextendedmode_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecextendedmode_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecextendedmode_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecextendedmode_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecmainmode","displayName":"Account Logon Logoff Audit I Psec Main Mode","description":"This policy setting allows you to audit events generated by Internet Key Exchange protocol (IKE) and Authenticated Internet Protocol (AuthIP) during Main Mode negotiations. If you configure this policy setting, an audit event is generated during an IPsec Main Mode negotiation. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated during an IPsec Main Mode negotiation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditipsecmainmode"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecmainmode_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecmainmode_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecmainmode_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecmainmode_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode","displayName":"Account Logon Logoff Audit I Psec Quick Mode","description":"This policy setting allows you to audit events generated by Internet Key Exchange protocol (IKE) and Authenticated Internet Protocol (AuthIP) during Quick Mode negotiations. If you configure this policy setting, an audit event is generated during an IPsec Quick Mode negotiation. Success audits record successful attempts and Failure audits record unsuccessful attempts.If you do not configure this policy setting, no audit event is generated during an IPsec Quick Mode negotiation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditipsecquickmode"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogoff","displayName":"Account Logon Logoff Audit Logoff","description":"This policy setting allows you to audit events generated by the closing of a logon session. These events occur on the computer that was accessed. For an interactive logoff the security audit event is generated on the computer that the user account logged on to. If you configure this policy setting, an audit event is generated when a logon session is closed. Success audits record successful attempts to close sessions and Failure audits record unsuccessful attempts to close sessions. If you do not configure this policy setting, no audit event is generated when a logon session is closed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditlogoff"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogoff_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogoff_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogoff_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogoff_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogon","displayName":"Account Logon Logoff Audit Logon","description":"This policy setting allows you to audit events generated by user account logon attempts on the computer. Events in this subcategory are related to the creation of logon sessions and occur on the computer which was accessed. For an interactive logon, the security audit event is generated on the computer that the user account logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the computer hosting the resource. The following events are included: Successful logon attempts. Failed logon attempts. Logon attempts using explicit credentials. This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch logon configurations, such as scheduled tasks or when using the RUNAS command. Security identifiers (SIDs) were filtered and not allowed to log on.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditlogon"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogon_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogon_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogon_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogon_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditnetworkpolicyserver","displayName":"Account Logon Logoff Audit Network Policy Server","description":"This policy setting allows you to audit events generated by RADIUS (IAS) and Network Access Protection (NAP) user access requests. These requests can be Grant, Deny, Discard, Quarantine, Lock, and Unlock. If you configure this policy setting, an audit event is generated for each IAS and NAP user access request. Success audits record successful user access requests and Failure audits record unsuccessful attempts. If you do not configure this policy settings, IAS and NAP user access requests are not audited.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditnetworkpolicyserver"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditnetworkpolicyserver_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditnetworkpolicyserver_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditnetworkpolicyserver_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditnetworkpolicyserver_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditotherlogonlogoffevents","displayName":"Audit Other Logon Logoff Events","description":"This policy setting allows you to audit other logon/logoff-related events that are not covered in the “Logon/Logoff” policy setting such as the following: Terminal Services session disconnections. New Terminal Services sessions. Locking and unlocking a workstation. Invoking a screen saver. Dismissal of a screen saver. Detection of a Kerberos replay attack, in which a Kerberos request was received twice with identical information. This condition could be caused by network misconfiguration. Access to a wireless network granted to a user or computer account. Access to a wired 802.1x network granted to a user or computer account.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditotherlogonlogoffevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditotherlogonlogoffevents_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditotherlogonlogoffevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditotherlogonlogoffevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditotherlogonlogoffevents_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon","displayName":"Audit Special Logon","description":"This policy setting allows you to audit events generated by special logons such as the following : The use of a special logon, which is a logon that has administrator-equivalent privileges and can be used to elevate a process to a higher level. A logon by a member of a Special Group. Special Groups enable you to audit events generated when a member of a certain group has logged on to your network. You can configure a list of group security identifiers (SIDs) in the registry. If any of those SIDs are added to a token during logon and the subcategory is enabled, an event is logged. For more information about this feature, see article 947223 in the Microsoft Knowledge Base (https://go.microsoft.com/fwlink/?LinkId=121697).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditspeciallogon"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_audituserdeviceclaims","displayName":"Account Logon Logoff Audit User Device Claims","description":"This policy allows you to audit user and device claims information in the user's logon token. Events in this subcategory are generated on the computer on which a logon session is created. For an interactive logon, the security audit event is generated on the computer that the user logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the computer hosting the resource. User claims are added to a logon token when claims are included with a user's account attributes in Active Directory. Device claims are added to the logon token when claims are included with a device's computer account attributes in Active Directory. In addition, compound identity must be enabled for the domain and on the computer where the user logged on. When this setting is configured, one or more security audit events are generated for each successful logon. You must also enable the Audit Logon setting under Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff. Multiple events are generated if the user and device claims information cannot fit in a single security audit event.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_audituserdeviceclaims"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_audituserdeviceclaims_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_audituserdeviceclaims_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_audituserdeviceclaims_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_audituserdeviceclaims_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditapplicationgroupmanagement","displayName":"Account Management Audit Application Group Management","description":"This policy setting allows you to audit events generated by changes to application groups such as the following: Application group is created, changed, or deleted. Member is added or removed from an application group. If you configure this policy setting, an audit event is generated when an attempt to change an application group is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an application group changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountmanagement_auditapplicationgroupmanagement"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditapplicationgroupmanagement_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditapplicationgroupmanagement_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditapplicationgroupmanagement_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditapplicationgroupmanagement_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditcomputeraccountmanagement","displayName":"Account Management Audit Computer Account Management","description":"This policy setting allows you to audit events generated by changes to computer accounts such as when a computer account is created, changed, or deleted. If you configure this policy setting, an audit event is generated when an attempt to change a computer account is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a computer account changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountmanagement_auditcomputeraccountmanagement"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditcomputeraccountmanagement_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditcomputeraccountmanagement_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditcomputeraccountmanagement_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditcomputeraccountmanagement_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditdistributiongroupmanagement","displayName":"Account Management Audit Distribution Group Management","description":"This policy setting allows you to audit events generated by changes to distribution groups such as the following: Distribution group is created, changed, or deleted. Member is added or removed from a distribution group. Distribution group type is changed. If you configure this policy setting, an audit event is generated when an attempt to change a distribution group is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a distribution group changes. Note: Events in this subcategory are logged only on domain controllers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountmanagement_auditdistributiongroupmanagement"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditdistributiongroupmanagement_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditdistributiongroupmanagement_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditdistributiongroupmanagement_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditdistributiongroupmanagement_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditotheraccountmanagementevents","displayName":"Account Management Audit Other Account Management Events","description":"This policy setting allows you to audit events generated by other user account changes that are not covered in this category, such as the following: The password hash of a user account was accessed. This typically happens during an Active Directory Management Tool password migration. The Password Policy Checking API was called. Calls to this function can be part of an attack when a malicious application tests the policy to reduce the number of attempts during a password dictionary attack. Changes to the Default Domain Group Policy under the following Group Policy paths: Computer Configuration\\Windows Settings\\Security Settings\\Account Policies\\Password Policy Computer Configuration\\Windows Settings\\Security Settings\\Account Policies\\Account Lockout Policy","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountmanagement_auditotheraccountmanagementevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditotheraccountmanagementevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditotheraccountmanagementevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditotheraccountmanagementevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditotheraccountmanagementevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditsecuritygroupmanagement","displayName":"Audit Security Group Management","description":"This policy setting allows you to audit events generated by changes to security groups such as the following: Security group is created, changed, or deleted. Member is added or removed from a security group. Group type is changed. If you configure this policy setting, an audit event is generated when an attempt to change a security group is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a security group changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountmanagement_auditsecuritygroupmanagement"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditsecuritygroupmanagement_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditsecuritygroupmanagement_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditsecuritygroupmanagement_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditsecuritygroupmanagement_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_audituseraccountmanagement","displayName":"Audit User Account Management","description":"This policy setting allows you to audit changes to user accounts. Events include the following: A user account is created, changed, deleted; renamed, disabled, enabled, locked out, or unlocked. A user account’s password is set or changed. A security identifier (SID) is added to the SID History of a user account. The Directory Services Restore Mode password is configured. Permissions on administrative user accounts are changed. Credential Manager credentials are backed up or restored. If you configure this policy setting, an audit event is generated when an attempt to change a user account is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a user account changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountmanagement_audituseraccountmanagement"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountmanagement_audituseraccountmanagement_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_audituseraccountmanagement_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_audituseraccountmanagement_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_audituseraccountmanagement_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity","displayName":"Detailed Tracking Audit DPAPI Activity","description":"This policy setting allows you to audit events generated when encryption or decryption requests are made to the Data Protection application interface (DPAPI). DPAPI is used to protect secret information such as stored password and key information. For more information about DPAPI, see https://go.microsoft.com/fwlink/?LinkId=121720. If you configure this policy setting, an audit event is generated when an encryption or decryption request is made to DPAPI. Success audits record successful requests and Failure audits record unsuccessful requests. If you do not configure this policy setting, no audit event is generated when an encryption or decryption request is made to DPAPI.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditdpapiactivity"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity","displayName":"Detailed Tracking Audit PNP Activity","description":"This policy setting allows you to audit when plug and play detects an external device. If you configure this policy setting, an audit event is generated whenever plug and play detects an external device. Only Success audits are recorded for this category. If you do not configure this policy setting, no audit event is generated when an external device is detected by plug and play.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditpnpactivity"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation","displayName":"Detailed Tracking Audit Process Creation","description":"This policy setting allows you to audit events generated when a process is created or starts. The name of the application or user that created the process is also audited. If you configure this policy setting, an audit event is generated when a process is created. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a process is created.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditprocesscreation"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination","displayName":"Detailed Tracking Audit Process Termination","description":"This policy setting allows you to audit events generated when a process ends. If you configure this policy setting, an audit event is generated when a process ends. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a process ends.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditprocesstermination"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents","displayName":"Detailed Tracking Audit RPC Events","description":"This policy setting allows you to audit inbound remote procedure call (RPC) connections. If you configure this policy setting, an audit event is generated when a remote RPC connection is attempted. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a remote RPC connection is attempted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditrpcevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted","displayName":"Detailed Tracking Audit Token Right Adjusted","description":"This policy setting allows you to audit events generated by adjusting the privileges of a token.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_audittokenrightadjusted"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdetaileddirectoryservicereplication","displayName":"DS Access Audit Detailed Directory Service Replication","description":"This policy setting allows you to audit events generated by detailed Active Directory Domain Services (AD DS) replication between domain controllers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#dsaccess_auditdetaileddirectoryservicereplication"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdetaileddirectoryservicereplication_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdetaileddirectoryservicereplication_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdetaileddirectoryservicereplication_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdetaileddirectoryservicereplication_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryserviceaccess","displayName":"DS Access Audit Directory Service Access","description":"This policy setting allows you to audit events generated when an Active Directory Domain Services (AD DS) object is accessed. Only AD DS objects with a matching system access control list (SACL) are logged. Events in this subcategory are similar to the Directory Service Access events available in previous versions of Windows.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#dsaccess_auditdirectoryserviceaccess"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryserviceaccess_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryserviceaccess_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryserviceaccess_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryserviceaccess_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicechanges","displayName":"Audit Directory Service Changes","description":"This policy setting allows you to audit events generated by changes to objects in Active Directory Domain Services (AD DS). Events are logged when an object is created, deleted, modified, moved, or undeleted. When possible, events logged in this subcategory indicate the old and new values of the object’s properties. Events in this subcategory are logged only on domain controllers, and only objects in AD DS with a matching system access control list (SACL) are logged. Note: Actions on some objects and properties do not cause audit events to be generated due to settings on the object class in the schema. If you configure this policy setting, an audit event is generated when an attempt to change an object in AD DS is made. Success audits record successful attempts, however unsuccessful attempts are NOT recorded. If you do not configure this policy setting, no audit event is generated when an attempt to change an object in AD DS object is made.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#dsaccess_auditdirectoryservicechanges"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicechanges_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicechanges_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicechanges_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicechanges_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicereplication","displayName":"DS Access Audit Directory Service Replication","description":"This policy setting allows you to audit replication between two Active Directory Domain Services (AD DS) domain controllers. If you configure this policy setting, an audit event is generated during AD DS replication. Success audits record successful replication and Failure audits record unsuccessful replication. If you do not configure this policy setting, no audit event is generated during AD DS replication.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#dsaccess_auditdirectoryservicereplication"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicereplication_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicereplication_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicereplication_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicereplication_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditapplicationgenerated","displayName":"Object Access Audit Application Generated","description":"This policy setting allows you to audit applications that generate events using the Windows Auditing application programming interfaces (APIs). Applications designed to use the Windows Auditing API use this subcategory to log auditing events related to their function. Events in this subcategory include: Creation of an application client context. Deletion of an application client context. Initialization of an application client context. Other application operations using the Windows Auditing APIs.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditapplicationgenerated"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditapplicationgenerated_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditapplicationgenerated_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditapplicationgenerated_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditapplicationgenerated_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcentralaccesspolicystaging","displayName":"Object Access Audit Central Access Policy Staging","description":"This policy setting allows you to audit access requests where the permission granted or denied by a proposed policy differs from the current central access policy on an object. If you configure this policy setting, an audit event is generated each time a user accesses an object and the permission granted by the current central access policy on the object differs from that granted by the proposed policy. The resulting audit event will be generated as follows: 1) Success audits, when configured, records access attempts when the current central access policy grants access but the proposed policy denies access. 2) Failure audits when configured records access attempts when: a) The current central access policy does not grant access but the proposed policy grants access. b) A principal requests the maximum access rights they are allowed and the access rights granted by the current central access policy are different than the access rights granted by the proposed policy. Volume: Potentially high on a file server when the proposed policy differs significantly from the current central access policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditcentralaccesspolicystaging"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcentralaccesspolicystaging_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcentralaccesspolicystaging_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcentralaccesspolicystaging_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcentralaccesspolicystaging_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcertificationservices","displayName":"Object Access Audit Certification Services","description":"This policy setting allows you to audit Active Directory Certificate Services (AD CS) operations. AD CS operations include the following: AD CS startup/shutdown/backup/restore. Changes to the certificate revocation list (CRL). New certificate requests. Issuing of a certificate. Revocation of a certificate. Changes to the Certificate Manager settings for AD CS. Changes in the configuration of AD CS. Changes to a Certificate Services template. Importing of a certificate. Publishing of a certification authority certificate is to Active Directory Domain Services. Changes to the security permissions for AD CS. Archival of a key. Importing of a key. Retrieval of a key. Starting of Online Certificate Status Protocol (OCSP) Responder Service. Stopping of Online Certificate Status Protocol (OCSP) Responder Service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditcertificationservices"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcertificationservices_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcertificationservices_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcertificationservices_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcertificationservices_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditdetailedfileshare","displayName":"Object Access Audit Detailed File Share","description":"This policy setting allows you to audit attempts to access files and folders on a shared folder. The Detailed File Share setting logs an event every time a file or folder is accessed, whereas the File Share setting only records one event for any connection established between a client and file share. Detailed File Share audit events include detailed information about the permissions or other criteria used to grant or deny access. If you configure this policy setting, an audit event is generated when an attempt is made to access a file or folder on a share. The administrator can specify whether to audit only successes, only failures, or both successes and failures. Note: There are no system access control lists (SACLs) for shared folders. If this policy setting is enabled, access to all shared files and folders on the system is audited.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditdetailedfileshare"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditdetailedfileshare_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditdetailedfileshare_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditdetailedfileshare_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditdetailedfileshare_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare","displayName":"Audit File Share Access","description":"This policy setting allows you to audit attempts to access a shared folder. If you configure this policy setting, an audit event is generated when an attempt is made to access a shared folder. If this policy setting is defined, the administrator can specify whether to audit only successes, only failures, or both successes and failures. Note: There are no system access control lists (SACLs) for shared folders. If this policy setting is enabled, access to all shared folders on the system is audited.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditfileshare"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilesystem","displayName":"Object Access Audit File System","description":"This policy setting allows you to audit user attempts to access file system objects. A security audit event is generated only for objects that have system access control lists (SACL) specified, and only if the type of access requested, such as Write, Read, or Modify and the account making the request match the settings in the SACL. For more information about enabling object access auditing, see https://go.microsoft.com/fwlink/?LinkId=122083. If you configure this policy setting, an audit event is generated each time an account accesses a file system object with a matching SACL. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an account accesses a file system object with a matching SACL. Note: You can set a SACL on a file system object using the Security tab in that object's Properties dialog box.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditfilesystem"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilesystem_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilesystem_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilesystem_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilesystem_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformconnection","displayName":"Object Access Audit Filtering Platform Connection","description":"This policy setting allows you to audit connections that are allowed or blocked by the Windows Filtering Platform (WFP). The following events are included: The Windows Firewall Service blocks an application from accepting incoming connections on the network. The WFP allows a connection. The WFP blocks a connection. The WFP permits a bind to a local port. The WFP blocks a bind to a local port. The WFP allows a connection. The WFP blocks a connection. The WFP permits an application or service to listen on a port for incoming connections. The WFP blocks an application or service to listen on a port for incoming connections. If you configure this policy setting, an audit event is generated when connections are allowed or blocked by the WFP. Success audits record events generated when connections are allowed and Failure audits record events generated when connections are blocked. If you do not configure this policy setting, no audit event is generated when connected are allowed or blocked by the WFP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditfilteringplatformconnection"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformconnection_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformconnection_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformconnection_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformconnection_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformpacketdrop","displayName":"Object Access Audit Filtering Platform Packet Drop","description":"This policy setting allows you to audit packets that are dropped by Windows Filtering Platform (WFP).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditfilteringplatformpacketdrop"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformpacketdrop_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformpacketdrop_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformpacketdrop_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformpacketdrop_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_audithandlemanipulation","displayName":"Object Access Audit Handle Manipulation","description":"This policy setting allows you to audit events generated when a handle to an object is opened or closed. Only objects with a matching system access control list (SACL) generate security audit events. If you configure this policy setting, an audit event is generated when a handle is manipulated. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a handle is manipulated. Note: Events in this subcategory generate events only for object types where the corresponding Object Access subcategory is enabled. For example, if File system object access is enabled, handle manipulation security audit events are generated. If Registry object access is not enabled, handle manipulation security audit events will not be generated.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_audithandlemanipulation"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_audithandlemanipulation_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_audithandlemanipulation_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_audithandlemanipulation_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_audithandlemanipulation_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject","displayName":"Object Access Audit Kernel Object","description":"This policy setting allows you to audit attempts to access the kernel, which include mutexes and semaphores. Only kernel objects with a matching system access control list (SACL) generate security audit events. Note: The Audit: Audit the access of global system objects policy setting controls the default SACL of kernel objects.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditkernelobject"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents","displayName":"Object Access Audit Other Object Access Events","description":"This policy setting allows you to audit events generated by the management of task scheduler jobs or COM+ objects. For scheduler jobs, the following are audited: Job created. Job deleted. Job enabled. Job disabled. Job updated. For COM+ objects, the following are audited: Catalog object added. Catalog object updated. Catalog object deleted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditotherobjectaccessevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry","displayName":"Object Access Audit Registry","description":"This policy setting allows you to audit attempts to access registry objects. A security audit event is generated only for objects that have system access control lists (SACLs) specified, and only if the type of access requested, such as Read, Write, or Modify, and the account making the request match the settings in the SACL. If you configure this policy setting, an audit event is generated each time an account accesses a registry object with a matching SACL. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an account accesses a registry object with a matching SACL. Note: You can set a SACL on a registry object using the Permissions dialog box.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditregistry"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditremovablestorage","displayName":"Object Access Audit Removable Storage","description":"This policy setting allows you to audit user attempts to access file system objects on a removable storage device. A security audit event is generated only for all objects for all types of access requested. If you configure this policy setting, an audit event is generated each time an account accesses a file system object on a removable storage. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an account accesses a file system object on a removable storage.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditremovablestorage"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditremovablestorage_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditremovablestorage_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditremovablestorage_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditremovablestorage_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam","displayName":"Object Access Audit SAM","description":"This policy setting allows you to audit events generated by attempts to access to Security Accounts Manager (SAM) objects. SAM objects include the following: SAM_ALIAS -- A local group. SAM_GROUP -- A group that is not a local group. SAM_USER – A user account. SAM_DOMAIN – A domain. SAM_SERVER – A computer account. If you configure this policy setting, an audit event is generated when an attempt to access a kernel object is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an attempt to access a kernel object is made. Note: Only the System Access Control List (SACL) for SAM_SERVER can be modified. Volume: High on domain controllers. For information about reducing the amount of events generated in this subcategory, see article 841001 in the Microsoft Knowledge Base (https://go.microsoft.com/fwlink/?LinkId=121698).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditsam"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange","displayName":"Audit Authentication Policy Change","description":"This policy setting allows you to audit events generated by changes to the authentication policy such as the following: Creation of forest and domain trusts. Modification of forest and domain trusts. Removal of forest and domain trusts. Changes to Kerberos policy under Computer Configuration\\Windows Settings\\Security Settings\\Account Policies\\Kerberos Policy. Granting of any of the following user rights to a user or group: Access This Computer From the Network. Allow Logon Locally. Allow Logon Through Terminal Services. Logon as a Batch Job. Logon a Service. Namespace collision. For example, when a new trust has the same name as an existing namespace name. If you configure this policy setting, an audit event is generated when an attempt to change the authentication policy is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when the authentication policy is changed. Note: The security audit event is logged when the group policy is applied. It does not occur at the time when the settings are modified.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditauthenticationpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthorizationpolicychange","displayName":"Audit Authorization Policy Change","description":"This policy setting allows you to audit events generated by changes to the authorization policy such as the following: Assignment of user rights (privileges), such as SeCreateTokenPrivilege, that are not audited through the “Authentication Policy Change” subcategory. Removal of user rights (privileges), such as SeCreateTokenPrivilege, that are not audited through the “Authentication Policy Change” subcategory. Changes in the Encrypted File System (EFS) policy. Changes to the Resource attributes of an object. Changes to the Central Access Policy (CAP) applied to an object. If you configure this policy setting, an audit event is generated when an attempt to change the authorization policy is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when the authorization policy changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditauthorizationpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthorizationpolicychange_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthorizationpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthorizationpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthorizationpolicychange_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_policychange_auditfilteringplatformpolicychange","displayName":"Policy Change Audit Filtering Platform Policy Change","description":"This policy setting allows you to audit events generated by changes to the Windows Filtering Platform (WFP) such as the following: IPsec services status. Changes to IPsec policy settings. Changes to Windows Firewall policy settings. Changes to WFP providers and engine. If you configure this policy setting, an audit event is generated when a change to the WFP is attempted. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a change occurs to the WFP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditfilteringplatformpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditfilteringplatformpolicychange_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditfilteringplatformpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditfilteringplatformpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditfilteringplatformpolicychange_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_policychange_auditmpssvcrulelevelpolicychange","displayName":"Policy Change Audit MPSSVC Rule Level Policy Change","description":"This policy setting allows you to audit events generated by changes in policy rules used by the Microsoft Protection Service (MPSSVC). This service is used by Windows Firewall. Events include the following: Reporting of active policies when Windows Firewall service starts. Changes to Windows Firewall rules. Changes to Windows Firewall exception list. Changes to Windows Firewall settings. Rules ignored or not applied by Windows Firewall Service. Changes to Windows Firewall Group Policy settings. If you configure this policy setting, an audit event is generated by attempts to change policy rules used by the MPSSVC. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated by changes in policy rules used by the MPSSVC.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditmpssvcrulelevelpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditmpssvcrulelevelpolicychange_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditmpssvcrulelevelpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditmpssvcrulelevelpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditmpssvcrulelevelpolicychange_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_policychange_auditotherpolicychangeevents","displayName":"Policy Change Audit Other Policy Change Events","description":"This policy setting allows you to audit events generated by other security policy changes that are not audited in the policy change category, such as the following: Trusted Platform Module (TPM) configuration changes. Kernel-mode cryptographic self tests. Cryptographic provider operations. Cryptographic context operations or modifications. Applied Central Access Policies (CAPs) changes. Boot Configuration Data (BCD) modifications.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditotherpolicychangeevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditotherpolicychangeevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditotherpolicychangeevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditotherpolicychangeevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditotherpolicychangeevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange","displayName":"Audit Changes to Audit Policy","description":"This policy setting allows you to audit changes in the security audit policy settings such as the following: Settings permissions and audit settings on the Audit Policy object. Changes to the system audit policy. Registration of security event sources. De-registration of security event sources. Changes to the per-user audit settings. Changes to the value of CrashOnAuditFail. Changes to the system access control list on a file system or registry object. Changes to the Special Groups list. Note: System access control list (SACL) change auditing is done when a SACL for an object changes and the policy change category is enabled. Discretionary access control list (DACL) and ownership changes are audited when object access auditing is enabled and the object's SACL is configured for auditing of DACL/Owner change.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditnonsensitiveprivilegeuse","displayName":"Privilege Use Audit Non Sensitive Privilege Use","description":"This policy setting allows you to audit events generated by the use of non-sensitive privileges (user rights). The following privileges are non-sensitive: Access Credential Manager as a trusted caller. Access this computer from the network. Add workstations to domain. Adjust memory quotas for a process. Allow log on locally. Allow log on through Terminal Services. Bypass traverse checking. Change the system time. Create a pagefile. Create global objects. Create permanent shared objects. Create symbolic links. Deny access this computer from the network. Deny log on as a batch job. Deny log on as a service. Deny log on locally. Deny log on through Terminal Services. Force shutdown from a remote system. Increase a process working set. Increase scheduling priority. Lock pages in memory. Log on as a batch job. Log on as a service. Modify an object label. Perform volume maintenance tasks. Profile single process. Profile system performance. Remove computer from docking station. Shut down the system. Synchronize directory service data. If you configure this policy setting, an audit event is generated when a non-sensitive privilege is called. Success audits record successful calls and Failure audits record unsuccessful calls. If you do not configure this policy setting, no audit event is generated when a non-sensitive privilege is called.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#privilegeuse_auditnonsensitiveprivilegeuse"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditnonsensitiveprivilegeuse_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditnonsensitiveprivilegeuse_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditnonsensitiveprivilegeuse_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditnonsensitiveprivilegeuse_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditotherprivilegeuseevents","displayName":"Privilege Use Audit Other Privilege Use Events","description":"Not used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#privilegeuse_auditotherprivilegeuseevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditotherprivilegeuseevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditotherprivilegeuseevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditotherprivilegeuseevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditotherprivilegeuseevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse","displayName":"Privilege Use Audit Sensitive Privilege Use","description":"This policy setting allows you to audit events generated when sensitive privileges (user rights) are used such as the following: A privileged service is called. One of the following privileges are called: Act as part of the operating system. Back up files and directories. Create a token object. Debug programs. Enable computer and user accounts to be trusted for delegation. Generate security audits. Impersonate a client after authentication. Load and unload device drivers. Manage auditing and security log. Modify firmware environment values. Replace a process-level token. Restore files and directories. Take ownership of files or other objects. If you configure this policy setting, an audit event is generated when sensitive privilege requests are made. Success audits record successful requests and Failure audits record unsuccessful requests. If you do not configure this policy setting, no audit event is generated when sensitive privilege requests are made. ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#privilegeuse_auditsensitiveprivilegeuse"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver","displayName":"System Audit I Psec Driver","description":"This policy setting allows you to audit events generated by the IPsec filter driver such as the following: Startup and shutdown of the IPsec services. Network packets dropped due to integrity check failure. Network packets dropped due to replay check failure. Network packets dropped due to being in plaintext. Network packets received with incorrect Security Parameter Index (SPI). This may indicate that either the network card is not working correctly or the driver needs to be updated. Inability to process IPsec filters. If you configure this policy setting, an audit event is generated on an IPsec filter driver operation. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated on an IPSec filter driver operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditipsecdriver"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_system_auditothersystemevents","displayName":"System Audit Other System Events","description":"This policy setting allows you to audit any of the following events: Startup and shutdown of the Windows Firewall service and driver. Security policy processing by the Windows Firewall Service. Cryptography key file and migration operations.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditothersystemevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditothersystemevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditothersystemevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditothersystemevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditothersystemevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritystatechange","displayName":"System Audit Security State Change","description":"This policy setting allows you to audit events generated by changes in the security state of the computer such as the following events: Startup and shutdown of the computer. Change of system time. Recovering the system from CrashOnAuditFail, which is logged after a system restarts when the security event log is full and the CrashOnAuditFail registry entry is configured.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditsecuritystatechange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritystatechange_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritystatechange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritystatechange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritystatechange_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension","displayName":"Audit Security System Extension","description":"This policy setting allows you to audit events related to security system extensions or services such as the following: A security system extension, such as an authentication, notification, or security package is loaded and is registered with the Local Security Authority (LSA). It is used to authenticate logon attempts, submit logon requests, and any account or password changes. Examples of security system extensions are Kerberos and NTLM. A service is installed and registered with the Service Control Manager. The audit log contains information about the service name, binary, type, start type, and service account. If you configure this policy setting, an audit event is generated when an attempt is made to load a security system extension. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an attempt is made to load a security system extension.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditsecuritysystemextension"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_system_auditsystemintegrity","displayName":"System Audit System Integrity","description":"This policy setting allows you to audit events that violate the integrity of the security subsystem, such as the following: Events that could not be written to the event log because of a problem with the auditing system. A process that uses a local procedure call (LPC) port that is not valid in an attempt to impersonate a client by replying, reading, or writing to or from a client address space. The detection of a Remote Procedure Call (RPC) that compromises system integrity. The detection of a hash value of an executable file that is not valid as determined by Code Integrity. Cryptographic operations that compromise system integrity.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditsystemintegrity"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditsystemintegrity_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsystemintegrity_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsystemintegrity_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsystemintegrity_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_allowaadpasswordreset","displayName":"Allow Aad Password Reset","description":"Specifies whether password reset is enabled for AAD accounts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#allowaadpasswordreset"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":[{"id":"device_vendor_msft_policy_config_authentication_allowaadpasswordreset_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_allowaadpasswordreset_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_allowfastreconnect","displayName":"Allow Fast Reconnect","description":"Allows EAP Fast Reconnect from being attempted for EAP Method TLS. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#allowfastreconnect"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":[{"id":"device_vendor_msft_policy_config_authentication_allowfastreconnect_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_allowfastreconnect_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_allowsecondaryauthenticationdevice","displayName":"Allow Secondary Authentication Device","description":"Allows secondary authentication devices to work with Windows. The default for this policy must be on for consumer devices (defined as local or Microsoft account connected device) and off for enterprise devices (such as cloud domain-joined, cloud domain-joined in an on-premises only environment, cloud domain-joined in a hybrid environment, and BYOD). In the next major release of Windows 10, the default for this policy for consumer devices will be changed to off. This will only affect users that have not already set up a secondary authentication device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#allowsecondaryauthenticationdevice"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":[{"id":"device_vendor_msft_policy_config_authentication_allowsecondaryauthenticationdevice_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_allowsecondaryauthenticationdevice_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_configurewebcamaccessdomainnames","displayName":"Configure Webcam Access Domain Names","description":"Specifies a list of domains that are allowed to access the webcam in Web Sign-in based authentication scenarios.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#configurewebcamaccessdomainnames"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":null},{"id":"device_vendor_msft_policy_config_authentication_configurewebsigninallowedurls","displayName":"Configure Web Sign In Allowed Urls","description":"Specifies a list of URLs that are navigable in Web Sign-in based authentication scenarios.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#configurewebsigninallowedurls"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":null},{"id":"device_vendor_msft_policy_config_authentication_enablefastfirstsignin","displayName":"Enable Fast First Sign In","description":"Specifies whether new non-admin AAD accounts should auto-connect to pre-created candidate local accounts","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#enablefastfirstsignin"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":[{"id":"device_vendor_msft_policy_config_authentication_enablefastfirstsignin_0","displayName":"The feature defaults to the existing SKU and device capabilities.","description":"The feature defaults to the existing SKU and device capabilities.","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_enablefastfirstsignin_1","displayName":"Enabled. Auto-connect new non-admin Azure AD accounts to pre-configured candidate local accounts","description":"Enabled. Auto-connect new non-admin Azure AD accounts to pre-configured candidate local accounts","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_enablefastfirstsignin_2","displayName":"Disabled. Do not auto-connect new non-admin Azure AD accounts to pre-configured local accounts","description":"Disabled. Do not auto-connect new non-admin Azure AD accounts to pre-configured local accounts","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_enablepasswordlessexperience","displayName":"Enable Passwordless Experience","description":"Specifies whether connected users on AADJ devices receive a Passwordless experience on Windows\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#enablepasswordlessexperience"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":[{"id":"device_vendor_msft_policy_config_authentication_enablepasswordlessexperience_0","displayName":"The feature defaults to the existing edition and device capabilities.","description":"The feature defaults to the existing edition and device capabilities.","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_enablepasswordlessexperience_1","displayName":"Enabled. The Passwordless experience will be enabled on Windows","description":"Enabled. The Passwordless experience will be enabled on Windows","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_enablepasswordlessexperience_2","displayName":"Disabled. The Passwordless experience will not be enabled on Windows","description":"Disabled. The Passwordless experience will not be enabled on Windows","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_enablewebsignin","displayName":"Enable Web Sign In","description":"Specifies whether web-based sign-in is allowed for signing in to Windows","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#enablewebsignin"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":[{"id":"device_vendor_msft_policy_config_authentication_enablewebsignin_0","displayName":"The feature defaults to the existing SKU and device capabilities.","description":"The feature defaults to the existing SKU and device capabilities.","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_enablewebsignin_1","displayName":"Enabled. Web Sign-in will be enabled for signing in to Windows","description":"Enabled. Web Sign-in will be enabled for signing in to Windows","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_enablewebsignin_2","displayName":"Disabled. Web Sign-in will not be enabled for signing in to Windows","description":"Disabled. Web Sign-in will not be enabled for signing in to Windows","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_preferredaadtenantdomainname","displayName":"Preferred Aad Tenant Domain Name","description":"Specifies the preferred domain among available domains in the AAD tenant.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#preferredaadtenantdomainname"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":null},{"id":"device_vendor_msft_policy_config_autoplay_disallowautoplayfornonvolumedevices","displayName":"Disallow Autoplay for non-volume devices","description":"This policy setting disallows AutoPlay for MTP devices like cameras or phones.\n\n If you enable this policy setting, AutoPlay is not allowed for MTP devices like cameras or phones.\n\n If you disable or do not configure this policy setting, AutoPlay is enabled for non-volume devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-autoplay#autoplay-disallowautoplayfornonvolumedevices"],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"device_vendor_msft_policy_config_autoplay_disallowautoplayfornonvolumedevices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_autoplay_disallowautoplayfornonvolumedevices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior","displayName":"Set the default behavior for AutoRun","description":"This policy setting sets the default behavior for Autorun commands.\n\n Autorun commands are generally stored in autorun.inf files. They often launch the installation program or other routines.\n\n Prior to Windows Vista, when media containing an autorun command is inserted, the system will automatically execute the program without user intervention.\n\n This creates a major security concern as code may be executed without user's knowledge. The default behavior starting with Windows Vista is to prompt the user whether autorun command is to be run. The autorun command is represented as a handler in the Autoplay dialog.\n\n If you enable this policy setting, an Administrator can change the default Windows Vista or later behavior for autorun to:\n\n a) Completely disable autorun commands, or\n b) Revert back to pre-Windows Vista behavior of automatically executing the autorun command.\n\n If you disable or not configure this policy setting, Windows Vista or later will prompt the user whether autorun command is to be run.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-autoplay#autoplay-setdefaultautorunbehavior"],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_noautorun_dropdown","displayName":"Default AutoRun Behavior","description":"","helpText":"","infoUrls":[],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_noautorun_dropdown_1","displayName":"Do not execute any autorun commands","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_noautorun_dropdown_2","displayName":"Automatically execute autorun commands","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_autoplay_turnoffautoplay","displayName":"Turn off Autoplay","description":"This policy setting allows you to turn off the Autoplay feature.\n\n Autoplay begins reading from a drive as soon as you insert media in the drive. As a result, the setup file of programs and the music on audio media start immediately.\n\n Prior to Windows XP SP2, Autoplay is disabled by default on removable drives, such as the floppy disk drive (but not the CD-ROM drive), and on network drives.\n\n Starting with Windows XP SP2, Autoplay is enabled for removable drives as well, including Zip drives and some USB mass storage devices.\n\n If you enable this policy setting, Autoplay is disabled on CD-ROM and removable media drives, or disabled on all drives.\n\n This policy setting disables Autoplay on additional types of drives. You cannot use this setting to enable Autoplay on drives on which it is disabled by default.\n\n If you disable or do not configure this policy setting, AutoPlay is enabled.\n\n Note: This policy setting appears in both the Computer Configuration and User Configuration folders. If the policy settings conflict, the policy setting in Computer Configuration takes precedence over the policy setting in User Configuration.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-autoplay#autoplay-turnoffautoplay"],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"device_vendor_msft_policy_config_autoplay_turnoffautoplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_autoplay_turnoffautoplay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_autoplay_turnoffautoplay_autorun_box","displayName":"Turn off Autoplay on:","description":"","helpText":"","infoUrls":[],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"device_vendor_msft_policy_config_autoplay_turnoffautoplay_autorun_box_181","displayName":"CD-ROM and removable media drives","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_autoplay_turnoffautoplay_autorun_box_255","displayName":"All drives","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_bits_bandwidththrottlingendtime","displayName":"Bandwidth Throttling End Time","description":"This policy specifies the bandwidth throttling end time that Background Intelligent Transfer Service (BITS) uses for background transfers. This policy setting does not affect foreground transfers. This policy is based on the 24-hour clock. Value type is integer. Default value is 17 (5 PM). Supported value range: 0 - 23You can specify a limit to use during a specific time interval and at all other times. For example, limit the use of network bandwidth to 10 Kbps from 8:00 A. M. to 5:00 P. M. , and use all available unused bandwidth the rest of the day's hours. Using the three policies together (BandwidthThrottlingStartTime, BandwidthThrottlingEndTime, BandwidthThrottlingTransferRate), BITS will limit its bandwidth usage to the specified values. You can specify the limit in kilobits per second (Kbps). If you specify a value less than 2 kilobits, BITS will continue to use approximately 2 kilobits. To prevent BITS transfers from occurring, specify a limit of 0. If you disable or do not configure this policy setting, BITS uses all available unused bandwidth. Note: You should base the limit on the speed of the network link, not the computer's network interface card (NIC). This policy setting does not affect peer caching transfers between peer computers (it does affect transfers from the origin server); the Limit the maximum network bandwidth used for Peercaching policy setting should be used for that purpose. Consider using this setting to prevent BITS transfers from competing for network bandwidth when the client computer has a fast network card (10Mbs), but is connected to the network via a slow link (56Kbs).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#bandwidththrottlingendtime"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":null},{"id":"device_vendor_msft_policy_config_bits_bandwidththrottlingstarttime","displayName":"Bandwidth Throttling Start Time","description":"This policy specifies the bandwidth throttling start time that Background Intelligent Transfer Service (BITS) uses for background transfers. This policy setting does not affect foreground transfers. This policy is based on the 24-hour clock. Value type is integer. Default value is 8 (8 am). Supported value range: 0 - 23You can specify a limit to use during a specific time interval and at all other times. For example, limit the use of network bandwidth to 10 Kbps from 8:00 A. M. to 5:00 P. M. , and use all available unused bandwidth the rest of the day's hours. Using the three policies together (BandwidthThrottlingStartTime, BandwidthThrottlingEndTime, BandwidthThrottlingTransferRate), BITS will limit its bandwidth usage to the specified values. You can specify the limit in kilobits per second (Kbps). If you specify a value less than 2 kilobits, BITS will continue to use approximately 2 kilobits. To prevent BITS transfers from occurring, specify a limit of 0. If you disable or do not configure this policy setting, BITS uses all available unused bandwidth. Note: You should base the limit on the speed of the network link, not the computer's network interface card (NIC). This policy setting does not affect peer caching transfers between peer computers (it does affect transfers from the origin server); the Limit the maximum network bandwidth used for Peercaching policy setting should be used for that purpose. Consider using this setting to prevent BITS transfers from competing for network bandwidth when the client computer has a fast network card (10Mbs), but is connected to the network via a slow link (56Kbs).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#bandwidththrottlingstarttime"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":null},{"id":"device_vendor_msft_policy_config_bits_bandwidththrottlingtransferrate","displayName":"Bandwidth Throttling Transfer Rate","description":"This policy specifies the bandwidth throttling transfer rate in kilobits per second (Kbps) that Background Intelligent Transfer Service (BITS) uses for background transfers. This policy setting does not affect foreground transfers. Value type is integer. Default value is 1000. Supported value range: 0 - 4294967200. You can specify a limit to use during a specific time interval and at all other times. For example, limit the use of network bandwidth to 10 Kbps from 8:00 A. M. to 5:00 P. M. , and use all available unused bandwidth the rest of the day's hours. Using the three policies together (BandwidthThrottlingStartTime, BandwidthThrottlingEndTime, BandwidthThrottlingTransferRate), BITS will limit its bandwidth usage to the specified values. You can specify the limit in kilobits per second (Kbps). If you specify a value less than 2 kilobits, BITS will continue to use approximately 2 kilobits. To prevent BITS transfers from occurring, specify a limit of 0. If you disable or do not configure this policy setting, BITS uses all available unused bandwidth. Note: You should base the limit on the speed of the network link, not the computer's network interface card (NIC). This policy setting does not affect peer caching transfers between peer computers (it does affect transfers from the origin server); the Limit the maximum network bandwidth used for Peercaching policy setting should be used for that purpose. Consider using this setting to prevent BITS transfers from competing for network bandwidth when the client computer has a fast network card (10Mbs), but is connected to the network via a slow link (56Kbs).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#bandwidththrottlingtransferrate"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority","displayName":"Costed Network Behavior Background Priority","description":"This policy setting defines the default behavior that the Background Intelligent Transfer Service (BITS) uses for background transfers when the system is connected to a costed network (3G, etc. ). Download behavior policies further limit the network usage of background transfers. If you enable this policy setting, you can define a default download policy for each BITS job priority. This setting does not override a download policy explicitly configured by the application that created the BITS job, but does apply to jobs that are created by specifying only a priority. For example, you can specify that background jobs are by default to transfer only when on uncosted network connections, but foreground jobs should proceed only when not roaming. The values that can be assigned are:1 - Always transfer2 - Transfer unless roaming3 - Transfer unless surcharge applies (when not roaming or overcap)4 - Transfer unless nearing limit (when not roaming or nearing cap)5 - Transfer only if unconstrained","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#costednetworkbehaviorbackgroundpriority"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":[{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_1","displayName":"Always transfer","description":"Always transfer","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_2","displayName":"Transfer unless roaming","description":"Transfer unless roaming","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_3","displayName":"Transfer unless surcharge applies (when not roaming or over cap)","description":"Transfer unless surcharge applies (when not roaming or over cap)","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_4","displayName":"Transfer unless nearing limit (when not roaming or nearing cap)","description":"Transfer unless nearing limit (when not roaming or nearing cap)","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_5","displayName":"Transfer only if unconstrained","description":"Transfer only if unconstrained","helpText":null}]},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorforegroundpriority","displayName":"Costed Network Behavior Foreground Priority","description":"This policy setting defines the default behavior that the foreground Intelligent Transfer Service (BITS) uses for foreground transfers when the system is connected to a costed network (3G, etc. ). Download behavior policies further limit the network usage of foreground transfers. If you enable this policy setting, you can define a default download policy for each BITS job priority. This setting does not override a download policy explicitly configured by the application that created the BITS job, but does apply to jobs that are created by specifying only a priority. For example, you can specify that foreground jobs are by default to transfer only when on uncosted network connections, but foreground jobs should proceed only when not roaming. The values that can be assigned are:1 - Always transfer2 - Transfer unless roaming3 - Transfer unless surcharge applies (when not roaming or overcap)4 - Transfer unless nearing limit (when not roaming or nearing cap)5 - Transfer only if unconstrained","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#costednetworkbehaviorforegroundpriority"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":[{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorforegroundpriority_1","displayName":"Always transfer","description":"Always transfer","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorforegroundpriority_2","displayName":"Transfer unless roaming","description":"Transfer unless roaming","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorforegroundpriority_3","displayName":"Transfer unless surcharge applies (when not roaming or over cap)","description":"Transfer unless surcharge applies (when not roaming or over cap)","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorforegroundpriority_4","displayName":"Transfer unless nearing limit (when not roaming or nearing cap)","description":"Transfer unless nearing limit (when not roaming or nearing cap)","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorforegroundpriority_5","displayName":"Transfer only if unconstrained","description":"Transfer only if unconstrained","helpText":null}]},{"id":"device_vendor_msft_policy_config_bits_jobinactivitytimeout","displayName":"Job Inactivity Timeout","description":"This policy setting specifies the number of days a pending BITS job can remain inactive before the job is considered abandoned. By default BITS will wait 90 days before considering an inactive job abandoned. After a job is determined to be abandoned, the job is deleted from BITS and any downloaded files for the job are deleted from the disk. NoteAny property changes to the job or any successful download action will reset this timeout. Value type is integer. Default is 90 days. Supported values range: 0 - 999Consider increasing the timeout value if computers tend to stay offline for a long period of time and still have pending jobs. Consider decreasing this value if you are concerned about orphaned jobs occupying disk space. If you disable or do not configure this policy setting, the default value of 90 (days) will be used for the inactive job timeout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#jobinactivitytimeout"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":null},{"id":"device_vendor_msft_policy_config_bluetooth_allowadvertising","displayName":"Allow Advertising","description":"Specifies whether the device can send out Bluetooth advertisements. If this is not set or it is deleted, the default value of 1 (Allow) is used. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#allowadvertising"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":[{"id":"device_vendor_msft_policy_config_bluetooth_allowadvertising_0","displayName":"Block","description":"Not allowed. When set to 0, the device will not send out advertisements. To verify, use any Bluetooth LE app and enable it to do advertising. Then, verify that the advertisement is not received by the peripheral.","helpText":null},{"id":"device_vendor_msft_policy_config_bluetooth_allowadvertising_1","displayName":"Allow","description":"Allowed. When set to 1, the device will send out advertisements. To verify, use any Bluetooth LE app and enable it to do advertising. Then, verify that the advertisement is received by the peripheral.","helpText":null}]},{"id":"device_vendor_msft_policy_config_bluetooth_allowdiscoverablemode","displayName":"Allow Discoverable Mode","description":"Specifies whether other Bluetooth-enabled devices can discover the device. If this is not set or it is deleted, the default value of 1 (Allow) is used. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#allowdiscoverablemode"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":[{"id":"device_vendor_msft_policy_config_bluetooth_allowdiscoverablemode_0","displayName":"Block","description":"Not allowed. When set to 0, other devices will not be able to detect the device. To verify, open the Bluetooth control panel on the device. Then, go to another Bluetooth-enabled device, open the Bluetooth control panel, and verify that you cannot see the name of the device.","helpText":null},{"id":"device_vendor_msft_policy_config_bluetooth_allowdiscoverablemode_1","displayName":"Allow","description":"Allowed. When set to 1, other devices will be able to detect the device. To verify, open the Bluetooth control panel on the device. Then, go to another Bluetooth-enabled device, open the Bluetooth control panel and verify that you can discover it.","helpText":null}]},{"id":"device_vendor_msft_policy_config_bluetooth_allowprepairing","displayName":"Allow Prepairing","description":"Specifies whether to allow specific bundled Bluetooth peripherals to automatically pair with the host device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#allowprepairing"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":[{"id":"device_vendor_msft_policy_config_bluetooth_allowprepairing_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_bluetooth_allowprepairing_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_bluetooth_allowpromptedproximalconnections","displayName":"Allow Prompted Proximal Connections","description":"This policy allows the IT admin to block users on these managed devices from using Swift Pair and other proximity based scenarios.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#allowpromptedproximalconnections"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":[{"id":"device_vendor_msft_policy_config_bluetooth_allowpromptedproximalconnections_0","displayName":"Block","description":"Disallow. Block users on these managed devices from using Swift Pair and other proximity based scenarios","helpText":null},{"id":"device_vendor_msft_policy_config_bluetooth_allowpromptedproximalconnections_1","displayName":"Allow","description":"Allow. Allow users on these managed devices to use Swift Pair and other proximity based scenarios","helpText":null}]},{"id":"device_vendor_msft_policy_config_bluetooth_localdevicename","displayName":"Local Device Name","description":"Sets the local Bluetooth device name. If this is set, the value that it is set to will be used as the Bluetooth device name. To verify the policy is set, open the Bluetooth control panel on the device. Then, go to another Bluetooth-enabled device, open the Bluetooth control panel, and verify that the value that was specified. If this policy is not set or it is deleted, the default local radio name is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#localdevicename"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":null},{"id":"device_vendor_msft_policy_config_bluetooth_servicesallowedlist","displayName":"Services Allowed List","description":"Set a list of allowable services and profiles. String hex formatted array of Bluetooth service UUIDs in canonical format, delimited by semicolons. For example, {782AFCFC-7CAA-436C-8BF0-78CD0FFBD4AF}. The default value is an empty string. For more information, see ServicesAllowedList usage guide","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#servicesallowedlist"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":null},{"id":"device_vendor_msft_policy_config_bluetooth_setminimumencryptionkeysize","displayName":"Set Minimum Encryption Key Size","description":"There are multiple levels of encryption strength when pairing Bluetooth devices. This policy helps prevent weaker devices cryptographically being used in high security environments.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#setminimumencryptionkeysize"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":null},{"id":"device_vendor_msft_policy_config_browser_allowaddressbardropdown","displayName":"Allow Address Bar Dropdown","description":"This policy setting lets you decide whether the Address bar drop-down functionality is available in Microsoft Edge. We recommend disabling this setting if you want to minimize network connections from Microsoft Edge to Microsoft services.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowaddressbardropdown"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowaddressbardropdown_0","displayName":"Block","description":"Prevented/not allowed. Hide the Address bar drop-down functionality and disable the Show search and site suggestions as I type toggle in Settings.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowaddressbardropdown_1","displayName":"Allow","description":"Allowed. Show the Address bar drop-down list and make it available.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowautofill","displayName":"Allow Autofill","description":"This setting lets you decide whether employees can use Autofill to automatically fill in form fields while using Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowautofill"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowautofill_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowautofill_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowconfigurationupdateforbookslibrary","displayName":"Allow Configuration Update For Books Library","description":"This policy setting lets you decide whether Microsoft Edge can automatically update the configuration data for the Books Library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowconfigurationupdateforbookslibrary"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowconfigurationupdateforbookslibrary_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowconfigurationupdateforbookslibrary_1","displayName":"Allow","description":"Allowed. Microsoft Edge updates the configuration data for the Books Library automatically.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowcookies","displayName":"Allow Cookies","description":"This setting lets you configure how your company deals with cookies.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowcookies"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowcookies_0","displayName":"Block all cookies from all sites","description":"Block all cookies from all sites","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowcookies_1","displayName":"Block only cookies from third party websites","description":"Block only cookies from third party websites","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowcookies_2","displayName":"Allow all cookies from all sites","description":"Allow all cookies from all sites","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowdevelopertools","displayName":"Allow Developer Tools","description":"This setting lets you decide whether employees can use F12 Developer Tools on Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowdevelopertools"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowdevelopertools_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowdevelopertools_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowdonottrack","displayName":"Allow Do Not Track","description":"This setting lets you decide whether employees can send Do Not Track headers to websites that request tracking info.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowdonottrack"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowdonottrack_0","displayName":"Block","description":"Never send tracking information.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowdonottrack_1","displayName":"Allow","description":"Send tracking information.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowextensions","displayName":"Allow Extensions","description":"This setting lets you decide whether employees can load extensions in Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowextensions"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowextensions_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowextensions_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowflash","displayName":"Allow Flash","description":"This setting lets you decide whether employees can run Adobe Flash in Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowflash"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowflash_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowflash_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowflashclicktorun","displayName":"Allow Flash Click To Run","description":"Configure the Adobe Flash Click-to-Run setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowflashclicktorun"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowflashclicktorun_0","displayName":"Block","description":"Load and run Adobe Flash content automatically.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowflashclicktorun_1","displayName":"Allow","description":"Does not load or run Adobe Flash content automatically. Requires action from the user.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowfullscreenmode","displayName":"Allow Full Screen Mode","description":"With this policy, you can specify whether to allow full-screen mode, which shows only the web content and hides the Microsoft Edge UI. If enabled or not configured, full-screen mode is available for use in Microsoft Edge. Your users and extensions must have the proper permissions. If disabled, full-screen mode is unavailable for use in Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowfullscreenmode"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowfullscreenmode_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowfullscreenmode_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowinprivate","displayName":"Allow InPrivate","description":"This setting lets you decide whether employees can browse using InPrivate website browsing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowinprivate"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowinprivate_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowinprivate_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowmicrosoftcompatibilitylist","displayName":"Allow Microsoft Compatibility List","description":"This policy setting lets you decide whether the Microsoft Compatibility List is enabled or disabled in Microsoft Edge. This feature uses a Microsoft-provided list to ensure that any sites with known compatibility issues are displayed correctly when a user navigates to them. By default, the Microsoft Compatibility List is enabled and can be viewed by navigating to about:compat. If you enable or don’t configure this setting, Microsoft Edge will periodically download the latest version of the list from Microsoft and will apply the configurations specified there during browser navigation. If a user visits a site on the Microsoft Compatibility List, he or she will be prompted to open the site in Internet Explorer 11. Once in Internet Explorer, the site will automatically be rendered as if the user is viewing it in the previous version of Internet Explorer it requires to display correctly. If you disable this setting, the Microsoft Compatibility List will not be used during browser navigation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowmicrosoftcompatibilitylist"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowmicrosoftcompatibilitylist_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowmicrosoftcompatibilitylist_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowpasswordmanager","displayName":"Allow Password Manager","description":"This setting lets you decide whether employees can save their passwords locally, using Password Manager.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowpasswordmanager"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowpasswordmanager_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowpasswordmanager_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowpopups","displayName":"Allow Popups","description":"This setting lets you decide whether to turn on Pop-up Blocker and whether to allow pop-ups to appear in secondary windows.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowpopups"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowpopups_0","displayName":"Block","description":"Turn off Pop-up Blocker letting pop-up windows open.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowpopups_1","displayName":"Allow","description":"Turn on Pop-up Blocker stopping pop-up windows from opening.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowprelaunch","displayName":"Allow Prelaunch","description":"Allow Microsoft Edge to pre-launch at Windows startup, when the system is idle, and each time Microsoft Edge is closed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowprelaunch"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowprelaunch_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowprelaunch_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowprinting","displayName":"Allow Printing","description":"With this policy, you can restrict whether printing web content in Microsoft Edge is allowed. If enabled, printing is allowed. If disabled, printing is not allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowprinting"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowprinting_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowprinting_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowsavinghistory","displayName":"Allow Saving History","description":"Microsoft Edge saves your user's browsing history, which is made up of info about the websites they visit, on their devices. If enabled or not configured, the browsing history is saved and visible in the History pane. If disabled, the browsing history stops saving and is not visible in the History pane. If browsing history exists before this policy was disabled, the previous browsing history remains visible in the History pane. This policy, when disabled, does not stop roaming of existing history or history coming from other roamed devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsavinghistory"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsavinghistory_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsavinghistory_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowsearchenginecustomization","displayName":"Allow Search Engine Customization","description":"Allow search engine customization for MDM enrolled devices. Users can change their default search engine. If this setting is turned on or not configured, users can add new search engines and change the default used in the address bar from within Microsoft Edge Settings. If this setting is disabled, users will be unable to add search engines or change the default used in the address bar. This policy will only apply on domain joined machines or when the device is MDM enrolled. For more information, see Microsoft browser extension policy (aka.ms/browserpolicy).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsearchenginecustomization"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsearchenginecustomization_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsearchenginecustomization_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowsearchsuggestionsinaddressbar","displayName":"Allow Search Suggestionsin Address Bar","description":"This setting lets you decide whether search suggestions should appear in the Address bar of Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsearchsuggestionsinaddressbar"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsearchsuggestionsinaddressbar_0","displayName":"Block","description":"Prevented/Not allowed. Hide the search suggestions.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsearchsuggestionsinaddressbar_1","displayName":"Allow","description":"Allowed. Show the search suggestions.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowsideloadingofextensions","displayName":"Allow Sideloading Of Extensions","description":"This setting lets you decide whether employees can sideload extensions in Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsideloadingofextensions"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsideloadingofextensions_0","displayName":"Block","description":"Prevented/Not allowed. Disabling does not prevent sideloading of extensions using Add-AppxPackage via Powershell. To prevent this, set the ApplicationManagement/AllowDeveloperUnlock policy to 1 (enabled).","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsideloadingofextensions_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowsmartscreen","displayName":"Allow Smart Screen","description":"This setting lets you decide whether to turn on Windows Defender SmartScreen.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsmartscreen"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsmartscreen_0","displayName":"Block","description":"Turned off. Do not protect users from potential threats and prevent users from turning it on.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsmartscreen_1","displayName":"Allow","description":"Turned on. Protect users from potential threats and prevent users from turning it off.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowtabpreloading","displayName":"Allow Tab Preloading","description":"Prevent Microsoft Edge from starting and loading the Start and New Tab page at Windows startup and each time Microsoft Edge is closed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowtabpreloading"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowtabpreloading_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowtabpreloading_1","displayName":"Allow","description":"Allowed. Preload Start and New tab pages.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowwebcontentonnewtabpage","displayName":"Allow Web Content On New Tab Page","description":"This policy setting lets you configure what appears when Microsoft Edge opens a new tab. By default, Microsoft Edge opens the New Tab page. If you enable this setting, Microsoft Edge opens a new tab with the New Tab page. If you disable this setting, Microsoft Edge opens a new tab with a blank page. If you use this setting, employees can't change it. If you don't configure this setting, employees can choose how new tabs appears.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowwebcontentonnewtabpage"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowwebcontentonnewtabpage_0","displayName":"Block","description":"Load a blank page instead of the default New tab page and prevent users from changing it.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowwebcontentonnewtabpage_1","displayName":"Allow","description":"Load the default New tab page.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_alwaysenablebookslibrary","displayName":"Always Enable Books Library","description":"Specifies whether the Books Library in Microsoft Edge will always be visible regardless of the country or region setting for the device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#alwaysenablebookslibrary"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_alwaysenablebookslibrary_0","displayName":"Disabled","description":"Show the Books Library only in countries or regions where supported.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_alwaysenablebookslibrary_1","displayName":"Enabled","description":"Show the Books Library, regardless of the device's country or region.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_clearbrowsingdataonexit","displayName":"Clear Browsing Data On Exit","description":"Specifies whether to always clear browsing history on exiting Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#clearbrowsingdataonexit"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_clearbrowsingdataonexit_0","displayName":"Disabled","description":"Prevented/not allowed. Users can configure the 'Clear browsing data' option in Settings.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_clearbrowsingdataonexit_1","displayName":"Enabled","description":"Allowed. Clear the browsing data upon exit automatically.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_configureadditionalsearchengines","displayName":"Configure Additional Search Engines","description":"Allows you to add up to 5 additional search engines for MDM-enrolled devices. If this setting is turned on, you can add up to 5 additional search engines for your employee. For each additional search engine you wish to add, you must specify a link to the OpenSearch XML file that contains, at minimum, the short name and the URL to the search engine. This policy does not affect the default search engine. Employees will not be able to remove these search engines, but they can set any one of these as the default. If this setting is not configured, the search engines are the ones specified in the App settings. If this setting is disabled, the search engines you had added will be deleted from your employee's machine. Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configureadditionalsearchengines"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_configurefavoritesbar","displayName":"Configure Favorites Bar","description":"The favorites bar shows your user's links to sites they have added to it. With this policy, you can specify whether to set the favorites bar to always be visible or hidden on any page. If enabled, favorites bar is always visible on any page, and the favorites bar toggle in Settings sets to On, but disabled preventing your users from making changes. An error message also shows at the top of the Settings pane indicating that your organization manages some settings. The show bar/hide bar option is hidden from the context menu. If disabled, the favorites bar is hidden, and the favorites bar toggle resets to Off, but disabled preventing your users from making changes. An error message also shows at the top of the Settings pane indicating that your organization manages some settings. If not configured, the favorites bar is hidden but is visible on the Start and New Tab pages, and the favorites bar toggle in Settings sets to Off but is enabled allowing the user to make changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configurefavoritesbar"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configurefavoritesbar_0","displayName":"Disabled","description":"Hide the favorites bar on all pages. Also, the favorites bar toggle, in Settings, is set to Off and disabled preventing users from making changes. Microsoft Edge also hides the “show bar/hide bar” option in the context menu.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurefavoritesbar_1","displayName":"Enabled","description":"Show the favorites bar on all pages. Also, the favorites bar toggle, in Settings, is set to On and disabled preventing users from making changes. Microsoft Edge also hides the “show bar/hide bar” option in the context menu.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_configurehomebutton","displayName":"Configure Home Button","description":"The Home button loads either the default Start page, the New tab page, or a URL defined in the Set Home Button URL policy. By default, this policy is disabled or not configured and clicking the home button loads the default Start page. When enabled, the home button is locked down preventing your users from making changes in Microsoft Edge's UI settings. To let your users change the Microsoft Edge UI settings, enable the Unlock Home Button policy. If Enabled AND: - Show home button & set to Start page is selected, clicking the home button loads the Start page. - Show home button & set to New tab page is selected, clicking the home button loads a New tab page. - Show home button & set a specific page is selected, clicking the home button loads the URL specified in the Set Home Button URL policy. - Hide home button is selected, the home button is hidden in Microsoft Edge. Default setting: Disabled or not configured Related policies: - Set Home Button URL - Unlock Home Button","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configurehomebutton"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configurehomebutton_0","displayName":"Show home button and load the Start page","description":"Show home button and load the Start page","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurehomebutton_1","displayName":"Show home button and load the New tab page","description":"Show home button and load the New tab page","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurehomebutton_2","displayName":"Show home button and load the custom URL defined in the Set Home Button URL policy","description":"Show home button and load the custom URL defined in the Set Home Button URL policy","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurehomebutton_3","displayName":"Hide home button","description":"Hide home button","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_configurekioskmode","displayName":"Configure Kiosk Mode","description":"Configure how Microsoft Edge behaves when it’s running in kiosk mode with assigned access, either as a single app or as one of multiple apps running on the kiosk device. You can control whether Microsoft Edge runs InPrivate full screen, InPrivate multi-tab with limited functionality, or normal Microsoft Edge. You need to configure Microsoft Edge in assigned access for this policy to take effect; otherwise, these settings are ignored. To learn more about assigned access and kiosk configuration, see “Configure kiosk and shared devices running Windows desktop editions” (https://aka.ms/E489vw). If enabled and set to 0 (Default or not configured): - If it’s a single app, it runs InPrivate full screen for digital signage or interactive displays. - If it’s one of many apps, Microsoft Edge runs as normal. If enabled and set to 1: - If it’s a single app, it runs a limited multi-tab version of InPrivate and is the only app available for public browsing. Users can’t minimize, close, or open windows or customize Microsoft Edge, but can clear browsing data and downloads and restart by clicking “End session.” You can configure Microsoft Edge to restart after a period of inactivity by using the “Configure kiosk reset after idle timeout” policy. - If it’s one of many apps, it runs in a limited multi-tab version of InPrivate for public browsing with other apps. Users can minimize, close, and open multiple InPrivate windows, but they can’t customize Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configurekioskmode"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configurekioskmode_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurekioskmode_0","displayName":"Disable","description":"Disable","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_configurekioskresetafteridletimeout","displayName":"Configure Kiosk Reset After Idle Timeout","description":"You can configure Microsoft Edge to reset to the configured start experience after a specified amount of idle time. The reset timer begins after the last user interaction. Resetting to the configured start experience deletes the current user’s browsing data. If enabled, you can set the idle time in minutes (0-1440). You must set the Configure kiosk mode policy to 1 and configure Microsoft Edge in assigned access as a single app for this policy to work. Once the idle time meets the time specified, a confirmation message prompts the user to continue, and if no user action, Microsoft Edge resets after 30 seconds. If you set this policy to 0, Microsoft Edge does not use an idle timer. If disabled or not configured, the default value is 5 minutes. If you do not configure Microsoft Edge in assigned access, then this policy does not take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configurekioskresetafteridletimeout"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_configureopenmicrosoftedgewith","displayName":"Configure Open Microsoft Edge With","description":"You can configure Microsoft Edge to lock down the Start page, preventing users from changing or customizing it. If enabled, you can choose one of the following options: - Start page: the Start page loads ignoring the Configure Start Pages policy. - New tab page: the New tab page loads ignoring the Configure Start Pages policy. - Previous pages: all tabs the user had open when Microsoft Edge last closed loads ignoring the Configure Start Pages policy. - A specific page or pages: the URL(s) specified with Configure Start Pages policy load(s). If selected, you must specify at least one URL in Configure Start Pages; otherwise, this policy is ignored. When enabled, and you want to make changes, you must first set the Disable Lockdown of Start Pages to not configured, make the changes to the Configure Open Edge With policy, and then enable the Disable Lockdown of Start Pages policy. If disabled or not configured, and you enable the Disable Lockdown of Start Pages policy, your users can change or customize the Start page. Default setting: A specific page or pages (default) Related policies: -Disable Lockdown of Start Pages -Configure Start Pages","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configureopenmicrosoftedgewith"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configureopenmicrosoftedgewith_0","displayName":"Load the Start page","description":"Load the Start page","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configureopenmicrosoftedgewith_1","displayName":"Load the New tab page","description":"Load the New tab page","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configureopenmicrosoftedgewith_2","displayName":"Load the previous pages","description":"Load the previous pages","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configureopenmicrosoftedgewith_3","displayName":"Load a specific page or pages","description":"Load a specific page or pages","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_configuretelemetryformicrosoft365analytics","displayName":"Configure Telemetry For Microsoft 365 Analytics","description":"Configures what browsing data will be sent to Microsoft 365 Analytics for devices belonging to an organization.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configuretelemetryformicrosoft365analytics"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configuretelemetryformicrosoft365analytics_0","displayName":"No data collected or sent","description":"No data collected or sent","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configuretelemetryformicrosoft365analytics_1","displayName":"Send intranet history only","description":"Send intranet history only","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configuretelemetryformicrosoft365analytics_2","displayName":"Send Internet history only","description":"Send Internet history only","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configuretelemetryformicrosoft365analytics_3","displayName":"Send both intranet and Internet history","description":"Send both intranet and Internet history","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_disablelockdownofstartpages","displayName":"Disable Lockdown Of Start Pages","description":"You can configure Microsoft Edge to disable the lockdown of Start pages allowing users to change or customize their start pages. To do this, you must also enable the Configure Start Pages or Configure Open Microsoft With policy. When enabled, all configured start pages are editable. Any Start page configured using the Configure Start pages policy is not locked down allowing users to edit their Start pages. If disabled or not configured, the Start pages configured in the Configure Start Pages policy cannot be changed and remain locked down. Supported devices: Domain-joined or MDM-enrolled Related policy: - Configure Start Pages - Configure Open Microsoft Edge With","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#disablelockdownofstartpages"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_disablelockdownofstartpages_0","displayName":"Disabled","description":"Lock down Start pages configured in either the ConfigureOpenEdgeWith policy and HomePages policy.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_disablelockdownofstartpages_1","displayName":"Enabled","description":"Unlocked. Users can make changes to all configured start pages.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_enableextendedbookstelemetry","displayName":"Enable Extended Books Telemetry","description":"This setting allows organizations to send extended telemetry on book usage from the Books Library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#enableextendedbookstelemetry"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_enableextendedbookstelemetry_0","displayName":"Disabled","description":"Gather and send only basic diagnostic data, depending on the device configuration.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_enableextendedbookstelemetry_1","displayName":"Enabled","description":"Gather all diagnostic data.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_enterprisemodesitelist","displayName":"Enterprise Mode Site List","description":"This setting lets you configure whether your company uses Enterprise Mode and the Enterprise Mode Site List to address common compatibility problems with legacy websites.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#enterprisemodesitelist"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_enterprisesitelistserviceurl","displayName":"Enterprise Site List Service Url","description":"Important. Discontinued in Windows 10, version 1511. Use the Browser/EnterpriseModeSiteList policy instead.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#enterprisesitelistserviceurl"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_homepages","displayName":"Home Pages","description":"When you enable the Configure Open Microsoft Edge With policy, you can configure one or more Start pages. When you enable this policy, users are not allowed to make changes to their Start pages. If enabled, you must include URLs to the pages, separating multiple pages using angle brackets in the following format: If disabled or not configured, the webpages specified in App settings loads as the default Start pages. Version 1703 or later: If you do not want to send traffic to Microsoft, enable this policy and use the value, which honors domain- and non-domain-joined devices, when it is the only configured URL. Version 1809: If enabled, and you select either Start page, New Tab page, or previous page in the Configure Open Microsoft Edge With policy, Microsoft Edge ignores the Configure Start Pages policy. If not configured or you set the Configure Open Microsoft Edge With policy to a specific page or pages, Microsoft Edge uses the Configure Start Pages policy. Supported devices: Domain-joined or MDM-enrolled Related policy: - Configure Open Microsoft Edge With - Disable Lockdown of Start Pages","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#homepages"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_lockdownfavorites","displayName":"Lockdown Favorites","description":"This policy setting lets you decide whether employees can add, import, sort, or edit the Favorites list on Microsoft Edge. If you enable this setting, employees won't be able to add, import, or change anything in the Favorites list. Also as part of this, Save a Favorite, Import settings, and the context menu items (such as, Create a new folder) are all turned off. Important Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge. If you disable or don't configure this setting (default), employees can add, import and make changes to the Favorites list.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#lockdownfavorites"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_lockdownfavorites_0","displayName":"Disabled","description":"Allowed/not locked down. Users can add, import, and make changes to the favorites.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_lockdownfavorites_1","displayName":"Enabled","description":"Prevented/locked down.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_preventaccesstoaboutflagsinmicrosoftedge","displayName":"Prevent Access To About Flags In Microsoft Edge","description":"Prevent access to the about:flags page in Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventaccesstoaboutflagsinmicrosoftedge"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventaccesstoaboutflagsinmicrosoftedge_0","displayName":"Disabled","description":"Allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventaccesstoaboutflagsinmicrosoftedge_1","displayName":"Enabled","description":"Prevents users from accessing the about:flags page.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_preventcerterroroverrides","displayName":"Prevent Cert Error Overrides","description":"Web security certificates are used to ensure a site your users go to is legitimate, and in some circumstances encrypts the data. With this policy, you can specify whether to prevent users from bypassing the security warning to sites that have SSL errors. If enabled, overriding certificate errors are not allowed. If disabled or not configured, overriding certificate errors are allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventcerterroroverrides"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventcerterroroverrides_0","displayName":"Disabled","description":"Allowed/turned on. Override the security warning to sites that have SSL errors.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventcerterroroverrides_1","displayName":"Enabled","description":"Prevented/turned on.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_preventlivetiledatacollection","displayName":"Prevent Live Tile Data Collection","description":"This policy lets you decide whether Microsoft Edge can gather Live Tile metadata from the ieonline.microsoft.com service to provide a better experience while pinning a Live Tile to the Start menu. Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventlivetiledatacollection"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventlivetiledatacollection_0","displayName":"Disabled","description":"Collect and send Live Tile metadata.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventlivetiledatacollection_1","displayName":"Enabled","description":"No data collected.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverride","displayName":"Prevent Smart Screen Prompt Override","description":"Don't allow Windows Defender SmartScreen warning overrides","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventsmartscreenpromptoverride"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverride_0","displayName":"Disabled","description":"Allowed/turned off. Users can ignore the warning and continue to the site.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverride_1","displayName":"Enabled","description":"Prevented/turned on.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverrideforfiles","displayName":"Prevent Smart Screen Prompt Override For Files","description":"Don't allow Windows Defender SmartScreen warning overrides for unverified files.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventsmartscreenpromptoverrideforfiles"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverrideforfiles_0","displayName":"Disabled","description":"Allowed/turned off. Users can ignore the warning and continue to download the unverified file(s).","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverrideforfiles_1","displayName":"Enabled","description":"Prevented/turned on.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_preventturningoffrequiredextensions","displayName":"Prevent Turning Off Required Extensions","description":"You can define a list of extensions in Microsoft Edge that users cannot turn off. You must deploy extensions through any available enterprise deployment channel, such as Microsoft Intune. When you enable this policy, users cannot uninstall extensions from their computer, but they can configure options for extensions defined in this policy, such as allow for InPrivate browsing. Any additional permissions requested by future updates of the extension gets granted automatically. When you enable this policy, you must provide a semi-colon delimited list of extension package family names (PFNs). For example, adding Microsoft.OneNoteWebClipper_8wekyb3d8bbwe;Microsoft.OfficeOnline_8wekyb3d8bbwe prevents a user from turning off the OneNote Web Clipper and Office Online extension. When enabled, removing extensions from the list does not uninstall the extension from the user’s computer automatically. To uninstall the extension, use any available enterprise deployment channel. If you enable the Allow Developer Tools policy, then this policy does not prevent users from debugging and altering the logic on an extension. If disabled or not configured, extensions defined as part of this policy get ignored. Default setting: Disabled or not configured Related policies: Allow Developer Tools Related Documents: - Find a package family name (PFN) for per-app VPN (https://docs.microsoft.com/en-us/sccm/protect/deploy-use/find-a-pfn-for-per-app-vpn) - How to manage apps you purchased from the Microsoft Store for Business with Microsoft Intune (https://docs.microsoft.com/en-us/intune/windows-store-for-business) - How to assign apps to groups with Microsoft Intune (https://docs.microsoft.com/en-us/intune/apps-deploy) - Manage apps from the Microsoft Store for Business with System Center Configuration Manager (https://docs.microsoft.com/en-us/sccm/apps/deploy-use/manage-apps-from-the-windows-store-for-business) - How to add Windows line-of-business (LOB) apps to Microsoft Intune (https://docs.microsoft.com/en-us/intune/lob-apps-windows)","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventturningoffrequiredextensions"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_preventusinglocalhostipaddressforwebrtc","displayName":"Prevent Using Local Host IP Address For Web RTC","description":"Prevent using localhost IP address for WebRTC","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventusinglocalhostipaddressforwebrtc"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventusinglocalhostipaddressforwebrtc_0","displayName":"Disabled","description":"Allowed. Show localhost IP addresses.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventusinglocalhostipaddressforwebrtc_1","displayName":"Enabled","description":"Prevented/Not allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_provisionfavorites","displayName":"Provision Favorites","description":"This policy setting allows you to configure a default set of favorites, which will appear for employees. Employees cannot modify, sort, move, export or delete these provisioned favorites. If you enable this setting, you can set favorite URL's and favorite folders to appear on top of users' favorites list (either in the Hub or Favorites Bar). The user favorites will appear after these provisioned favorites. Important Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge. If you disable or don't configure this setting, employees will see the favorites they set in the Hub and Favorites Bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#provisionfavorites"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_sendintranettraffictointernetexplorer","displayName":"Send Intranet Trafficto Internet Explorer","description":"Sends all intranet traffic over to Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#sendintranettraffictointernetexplorer"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_sendintranettraffictointernetexplorer_0","displayName":"Disabled","description":"All sites, including intranet sites, open in Microsoft Edge automatically.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_sendintranettraffictointernetexplorer_1","displayName":"Enabled","description":"Only intranet sites open in Internet Explorer 11 automatically.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_setdefaultsearchengine","displayName":"Set Default Search Engine","description":"Sets the default search engine for MDM-enrolled devices. Users can still change their default search engine. If this setting is turned on, you are setting the default search engine that you would like your employees to use. Employees can still change the default search engine, unless you apply the AllowSearchEngineCustomization policy which will disable the ability to change it. You must specify a link to the OpenSearch XML file that contains, at minimum, the short name and the URL to the search engine. If you would like for your employees to use the Edge factory settings for the default search engine for their market, set the string EDGEDEFAULT; if you would like for your employees to use Bing as the default search engine, set the string EDGEBING. If this setting is not configured, the default search engine is set to the one specified in App settings and can be changed by your employees. If this setting is disabled, the policy-set search engine will be removed, and, if it is the current default, the default will be set back to the factory Microsoft Edge search engine for the market. Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#setdefaultsearchengine"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_sethomebuttonurl","displayName":"Set Home Button URL","description":"The home button can be configured to load a custom URL when your user clicks the home button. If enabled, or configured, and the Configure Home Button policy is enabled, and the Show home button & set a specific page is selected, a custom URL loads when your user clicks the home button. Default setting: Blank or not configured Related policy: Configure Home Button","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#sethomebuttonurl"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_setnewtabpageurl","displayName":"Set New Tab Page URL","description":"You can set the default New Tab page URL in Microsoft Edge. Enabling this policy prevents your users from changing the New tab page setting. When enabled and the Allow web content on New Tab page policy is disabled, Microsoft Edge ignores the URL specified in this policy and opens about:blank. If enabled, you can set the default New Tab page URL. If disabled or not configured, the default Microsoft Edge new tab page is used. Default setting: Disabled or not configured Related policy: Allow web content on New Tab page","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#setnewtabpageurl"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer","displayName":"Show Message When Opening Sites In Internet Explorer","description":"You can configure Microsoft Edge to open a site automatically in Internet Explorer 11 and choose to display a notification before the site opens. If you want to display a notification, you must enable Configure the Enterprise Mode Site List or Send all intranets sites to Internet Explorer 11 or both. If enabled, the notification appears on a new page. If you want users to continue in Microsoft Edge, select the Show Keep going in Microsoft Edge option from the drop-down list under Options. If disabled or not configured, the default app behavior occurs and no additional page displays. Default setting: Disabled or not configured Related policies: -Configure the Enterprise Mode Site List -Send all intranet sites to Internet Explorer 11","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#showmessagewhenopeningsitesininternetexplorer"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer_0","displayName":"No additional message displays.","description":"No additional message displays.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer_1","displayName":"Show an additional message stating that a site has opened in IE11.","description":"Show an additional message stating that a site has opened in IE11.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer_2","displayName":"Show an additional message with a \"Keep going in Microsoft Edge\" link.","description":"Show an additional message with a \"Keep going in Microsoft Edge\" link.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_syncfavoritesbetweenieandmicrosoftedge","displayName":"Sync Favorites Between IE And Microsoft Edge","description":"Specifies whether favorites are kept in sync between Internet Explorer and Microsoft Edge. Changes to favorites in one browser are reflected in the other, including: additions, deletions, modifications, and ordering.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#syncfavoritesbetweenieandmicrosoftedge"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_syncfavoritesbetweenieandmicrosoftedge_0","displayName":"Disabled","description":"Turned off/not syncing.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_syncfavoritesbetweenieandmicrosoftedge_1","displayName":"Enabled","description":"Turned on/syncing.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_unlockhomebutton","displayName":"Unlock Home Button","description":"By default, when enabling Configure Home Button or Set Home Button URL, the home button is locked down to prevent your users from changing what page loads when clicking the home button. Use this policy to let users change the home button even when Configure Home Button or Set Home Button URL are enabled. If enabled, the UI settings for the home button are enabled allowing your users to make changes, including hiding and showing the home button as well as configuring a custom URL. If disabled or not configured, the UI settings for the home button are disabled preventing your users from making changes. Default setting: Disabled or not configured Related policy: -Configure Home Button -Set Home Button URL","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#unlockhomebutton"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_unlockhomebutton_0","displayName":"Disabled","description":"Lock down and prevent users from making changes to the settings.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_unlockhomebutton_1","displayName":"Enabled","description":"Let users make changes.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_usesharedfolderforbooks","displayName":"Use Shared Folder For Books","description":"This setting specifies whether organizations should use a folder shared across users to store books from the Books Library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#usesharedfolderforbooks"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_usesharedfolderforbooks_0","displayName":"Disabled","description":"Prevented/not allowed, but Microsoft Edge downloads book files to a per-user folder for each user.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_usesharedfolderforbooks_1","displayName":"Enabled","description":"Allowed. Microsoft Edge downloads book files to a shared folder. For this policy to work correctly, you must also enable the Allow a Windows app to share application data between users group policy. Also, the users must be signed in with a school or work account.","helpText":null}]},{"id":"device_vendor_msft_policy_config_camera_allowcamera","displayName":"Allow Camera","description":"Disables or enables the camera. Most restrictive value is Block","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-camera#allowcamera"],"categoryId":"18893f00-c309-4695-bcaf-b66286ad99c1","categoryName":"Camera","options":[{"id":"device_vendor_msft_policy_config_camera_allowcamera_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_camera_allowcamera_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_camera_configurecameraoptions","displayName":"Configure Camera Options","description":"This policy will allow camera mode to be managed by IT admins and enable camera to run in safe or auto share mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Camera#configurecameraoptions"],"categoryId":"18893f00-c309-4695-bcaf-b66286ad99c1","categoryName":"Camera","options":[{"id":"device_vendor_msft_policy_config_camera_configurecameraoptions_0","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_camera_configurecameraoptions_1","displayName":"AutoShare - Allow camera access by multiple applications simultaneously.","description":"AutoShare - Allow camera access by multiple applications simultaneously.","helpText":null},{"id":"device_vendor_msft_policy_config_camera_configurecameraoptions_2","displayName":"SafeMode - The camera is configured to auto‑share and operate in a non‑accelerated mode, bypassing OEM/IHV‑provided plugins where applicable.","description":"SafeMode - The camera is configured to auto‑share and operate in a non‑accelerated mode, bypassing OEM/IHV‑provided plugins where applicable.","helpText":null}]},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata","displayName":"Let Apps Access Cellular Data","description":"This policy setting specifies whether Windows apps can access cellular data.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":[{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_0","displayName":"User is in control","description":"User is in control","helpText":null},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_1","displayName":"Force Allow","description":"Force Allow","helpText":null},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_2","displayName":"Force Deny","description":"Force Deny","helpText":null}]},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_forceallowtheseapps","displayName":"Let Apps Access Cellular Data Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Windows Store Apps. Listed apps are allowed access to cellular data. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata_forceallowtheseapps"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":null},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_forcedenytheseapps","displayName":"Let Apps Access Cellular Data Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to cellular data. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata_forcedenytheseapps"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":null},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_userincontroloftheseapps","displayName":"Let Apps Access Cellular Data User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the cellular data access setting for the listed apps. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata_userincontroloftheseapps"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":null},{"id":"device_vendor_msft_policy_config_cellular_showappcellularaccessui","displayName":"Set Per-App Cellular Access UI Visibility","description":"This policy setting configures the visibility of the link to the per-application cellular access control page in the cellular setting UX.\n\nIf this policy setting is enabled, a drop-down list box presenting possible values will be active. Select \"Hide\" or \"Show\" to hide or show the link to the per-application cellular access control page.\nIf this policy setting is disabled or is not configured, the link to the per-application cellular access control page is showed by default.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-cellular#cellular-showappcellularaccessui"],"categoryId":"eefc9ae4-b9ae-4d77-8b68-359b9e5ec6f7","categoryName":"WWAN UI Settings","options":[{"id":"device_vendor_msft_policy_config_cellular_showappcellularaccessui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_cellular_showappcellularaccessui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_cellular_showappcellularaccessui_showappcellularaccessui_option","displayName":"Please select one option to set:","description":"","helpText":"","infoUrls":[],"categoryId":"eefc9ae4-b9ae-4d77-8b68-359b9e5ec6f7","categoryName":"WWAN UI Settings","options":[{"id":"device_vendor_msft_policy_config_cellular_showappcellularaccessui_showappcellularaccessui_option_0","displayName":"Hide","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_cellular_showappcellularaccessui_showappcellularaccessui_option_1","displayName":"Show","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_abusiveexperienceinterventionenforce","displayName":"Abusive Experience Intervention Enforce","description":"If SafeBrowsingEnabled is not Disabled, then setting AbusiveExperienceInterventionEnforce to Enabled or leaving it unset prevents sites with abusive experiences from opening new windows or tabs.\r\n\r\nSetting SafeBrowsingEnabled to Disabled or AbusiveExperienceInterventionEnforce to Disabled lets sites with abusive experiences open new windows or tabs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_abusiveexperienceinterventionenforce_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_abusiveexperienceinterventionenforce_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_accessibilityimagelabelsenabled","displayName":"Enable Get Image Descriptions from Google.","description":"The Get Image Descriptions from Google\r\naccessibility feature enables visually-impaired screen reader users to\r\nget descriptions of unlabeled images on the web. Users who choose to enable it\r\nwill have the option of using an anonymous Google service to provide\r\nautomatic descriptions for unlabeled images they encounter on the web.\r\n\r\nIf this feature is enabled, the content of images will be sent to Google\r\nservers in order to generate a description. No cookies or other user\r\ndata is sent, and Google does not save or log any image content.\r\n\r\nIf this policy is set to Enabled, the\r\nGet Image Descriptions from Google\r\nfeature will be enabled, though it will only affect users who are using a\r\nscreen reader or other similar assistive technology.\r\n\r\nIf this policy is set to Disabled, users will not have the option of enabling\r\nthe feature.\r\n\r\nIf this policy is not set, user can choose to use this feature or not.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_accessibilityimagelabelsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_accessibilityimagelabelsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_additionaldnsquerytypesenabled","displayName":"Allow DNS queries for additional DNS record types","description":"This policy controls whether Google Chrome may query additional DNS record types when making insecure DNS requests. This policy has no effect on DNS queries made via Secure DNS, which may always query additional DNS types.\r\n\r\nIf this policy is unset or set to Enabled, additional types such as HTTPS (DNS type 65) may be queried in addition to A (DNS type 1) and AAAA (DNS type 28).\r\n\r\nIf this policy is set to Disabled, DNS will only be queried for A (DNS type 1) and/or AAAA (DNS type 28).\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Google Chrome. After removal of the policy, Google Chrome will always be able to query additional DNS types.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_additionaldnsquerytypesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_additionaldnsquerytypesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads","description":"Unless SafeBrowsingEnabled is set to False, then setting AdsSettingForIntrusiveAdsSites to 1 or leaving it unset allows ads on all sites.\r\n\r\nSetting the policy to 2 blocks ads on sites with intrusive ads.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_adssettingforintrusiveadssites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_adssettingforintrusiveadssites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_adssettingforintrusiveadssites_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_adssettingforintrusiveadssites_adssettingforintrusiveadssites_1","displayName":"Allow ads on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_adssettingforintrusiveadssites_adssettingforintrusiveadssites_2","displayName":"Do not allow ads on sites with intrusive ads","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_advancedprotectionallowed","displayName":"Enable additional protections for users enrolled in the Advanced Protection program","description":"This policy controls whether users enrolled in the Advanced Protection program receive extra protections. Some of these features may involve the sharing of data with Google (for example, Advanced Protection users will be able to send their downloads to Google for malware scanning). If set to True or not set, enrolled users will receive extra protections. If set to False, Advanced Protection users will receive only the standard consumer features.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_advancedprotectionallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_advancedprotectionallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdeletingbrowserhistory","displayName":"Enable deleting browser and download history","description":"Setting the policy to Enabled or leaving it unset means browser history and download history can be deleted in Chrome, and users can't change this setting.\r\n\r\nSetting the policy to Disabled means browser history and download history can't be deleted. Even with this policy off, the browsing and download history are not guaranteed to be retained. Users may be able to edit or delete the history database files directly, and the browser itself may expire or archive any or all history items at any time.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdeletingbrowserhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdeletingbrowserhistory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdinosaureasteregg","displayName":"Allow Dinosaur Easter Egg Game","description":"Setting the policy to True allows users to play the dinosaur game. Setting the policy to False means users can't play the dinosaur easter egg game when device is offline.\r\n\r\nLeaving the policy unset means users can't play the game on enrolled Google Chrome OS, but can under other circumstances.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdinosaureasteregg_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdinosaureasteregg_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace","description":"Setting the policy turns on Chrome's restricted sign-in feature in Google Workspace and prevents users from changing this setting. Users can only access Google tools using accounts from the specified domains (to allow gmail or googlemail accounts, add consumer_accounts to the list of domains). This setting prevents users from signing in and adding a Secondary Account on a managed device that requires Google authentication, if that account doesn't belong to one of the explicitly allowed domains.\r\n\r\nLeaving this setting empty or unset means users can access Google Workspace with any account.\r\n\r\nUsers cannot change or override this setting.\r\n\r\nNote: This policy causes the X-GoogApps-Allowed-Domains header to be appended to all HTTP and HTTPS requests to all google.com domains, as described in https://support.google.com/a/answer/1668854.\r\n\r\nExample value: managedchrome.com,example.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowfileselectiondialogs","displayName":"Allow invocation of file selection dialogs","description":"Setting the policy to Enabled or leaving it unset means Chrome can display, and users can open, file selection dialogs.\r\n\r\nSetting the policy to Disabled means that whenever users perform actions provoking a file selection dialog, such as importing bookmarks, uploading files, and saving links, a message appears instead. The user is assumed to have clicked Cancel on the file selection dialog.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowfileselectiondialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowfileselectiondialogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal","displayName":"Allows a page to perform synchronous XHR requests during page dismissal.","description":"This policy allows an admin to specify that a page may send synchronous XHR requests during page dismissal.\r\n\r\nWhen the policy is set to enabled, pages are allowed to send synchronous XHR requests during page dismissal.\r\n\r\nWhen the policy is set to disabled or not set, pages are not allowed to send synchronous XHR requests during page dismissal.\r\n\r\nThis policy will be removed in Chrome 93.\r\n\r\nSee https://www.chromestatus.com/feature/4664843055398912 .","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alternateerrorpagesenabled","displayName":"Enable alternate error pages","description":"Setting the policy to True means Google Chrome uses alternate error pages built into (such as \"page not found\"). Setting the policy to False means Google Chrome never uses alternate error pages.\r\n\r\nIf you set the policy, users can't change it. If not set, the policy is on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alternateerrorpagesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alternateerrorpagesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alwaysopenpdfexternally","displayName":"Always Open PDF files externally","description":"Setting the policy to Enabled turns the internal PDF viewer off in Google Chrome, treats PDF files as a download, and lets users open PDFs with the default application.\r\n\r\nSetting the policy to Disabled means that unless users turns off the PDF plugin, it will open PDF files.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users can choose whether to open PDF externally or not.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alwaysopenpdfexternally_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alwaysopenpdfexternally_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for profile types.","description":"Configuring this policy will allow/disallow ambient authentication for Incognito and Guest profiles in Google Chrome.\r\n\r\nAmbient Authentication is http authentication with default credentials if explicit credentials are not provided via NTLM/Kerberos/Negotiate challenge/response schemes.\r\n\r\nSetting the RegularOnly (value 0), allows ambient authentication for Regular sessions only. Incognito and Guest sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the IncognitoAndRegular (value 1), allows ambient authentication for Incognito and Regular sessions. Guest sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the GuestAndRegular (value 2), allows ambient authentication for Guest and Regular sessions. Incognito sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the All (value 3), allows ambient authentication for all sessions.\r\n\r\nNote that, ambient authentication is always allowed on regular profiles.\r\n\r\nIn Google Chrome version 81 and later, if the policy is left not set, ambient authentication will be enabled in regular sessions only.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for profile types. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_0","displayName":"Enable ambient authentication in regular sessions only.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_1","displayName":"Enable ambient authentication in incognito and regular sessions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_2","displayName":"Enable ambient authentication in guest and regular sessions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_3","displayName":"Enable ambient authentication in regular, incognito and guest sessions.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_applicationlocalevalue","displayName":"Application locale","description":"Setting the policy specifies the locale Google Chrome uses.\r\n\r\nTurning it off or leaving it unset means the locale will be the first valid locale from:\r\n1) The user specified locale (if configured).\r\n2) The system locale.\r\n3) The fallback locale (en-US).\r\n\r\nExample value: en","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_applicationlocalevalue_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_applicationlocalevalue_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_applicationlocalevalue_applicationlocalevalue","displayName":"Application locale (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowed","displayName":"Allow or deny audio capture","description":"Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the AudioCaptureAllowedUrls list, users get prompted for audio capture access.\r\n\r\nSetting the policy to Disabled turns off prompts, and audio capture is only available to URLs set in the AudioCaptureAllowedUrls list.\r\n\r\nNote: The policy affects all audio input (not just the built-in microphone).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowedurls","displayName":"URLs that will be granted access to audio capture devices without prompt","description":"Setting the policy means you specify the URL list whose patterns get matched to the security origin of the requesting URL. A match grants access to audio capture devices without prompt\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com/\r\nhttps://[*.]example.edu/","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowedurls_audiocaptureallowedurlsdesc","displayName":"URLs that will be granted access to audio capture devices without prompt (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audioprocesshighpriorityenabled","displayName":"Allow the audio process to run with priority above normal on Windows","description":"This policy controls the priority of the audio process on Windows.\r\nIf this policy is enabled, the audio process will run with above normal priority.\r\nIf this policy is disabled, the audio process will run with normal priority.\r\nIf this policy is not set, the default configuration for the audio process will be used.\r\nThis policy is intended as a temporary measure to give enterprises the ability to\r\nrun audio with higher priority to address certain performance issues with audio capture.\r\nThis policy will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audioprocesshighpriorityenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audioprocesshighpriorityenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled","displayName":"Allow the audio sandbox to run","description":"This policy controls the audio process sandbox.\r\nIf this policy is enabled, the audio process will run sandboxed.\r\nIf this policy is disabled, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\r\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\r\nIf this policy is not set, the default configuration for the audio sandbox will be used, which may differ per platform.\r\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofilladdressenabled","displayName":"Enable AutoFill for addresses","description":"Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI.\r\n\r\nSetting the policy to False means Autofill never suggests or fills address information, nor does it save additional address information that users submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofilladdressenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofilladdressenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled","displayName":"Enable AutoFill for credit cards","description":"Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI.\r\n\r\nSetting the policy to False means autofill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user","description":"Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator should not be included when listing the protocol, so list \"skype\" instead of \"skype:\" or \"skype://\".\r\n\r\nIf this policy is set, a protocol will only be permitted to launch an external application without prompting by policy if the protocol is listed, and the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list. If either condition is false the external protocol launch prompt will not be omitted by policy.\r\n\r\nIf this policy is not set, no protocols can launch without a prompt by default. Users may opt out of prompts on a per-protocol/per-site basis unless the ExternalProtocolDialogShowAlwaysOpenCheckbox policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' policy, which are documented at http://www.chromium.org/administrators/url-blocklist-filter-format.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=AutoLaunchProtocolsFromOrigins for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"protocol\": \"spotify\",\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"teams\",\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"outlook\",\r\n \"allowed_origins\": [\r\n \"*\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenallowedforurls","displayName":"URLs where AutoOpenFileTypes can apply","description":"List of URLs specifying which urls AutoOpenFileTypes will apply to. This policy has no impact on automatically open values set by users.\r\n\r\nIf this policy is set, files will only automatically open by policy if the url is part of this set and the file type is listed in AutoOpenFileTypes. If either condition is false the download won't automatically open by policy.\r\n\r\nIf this policy isn't set, all downloads where the file type is in AutoOpenFileTypes will automatically open.\r\n\r\nA URL pattern has to be formatted according to https://www.chromium.org/administrators/url-blocklist-filter-format.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenallowedforurls_autoopenallowedforurlsdesc","displayName":"URLs where AutoOpenFileTypes can apply (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes","displayName":"List of file types that should be automatically opened on download","description":"List of file types that should be automatically opened on download. The leading separator should not be included when listing the file type, so list \"txt\" instead of \".txt\".\r\n\r\nFiles with types that should be automatically opened will still be subject to the enabled safe browsing checks and won't be opened if they fail those checks.\r\n\r\nIf this policy isn't set, only file types that a user has already specified to automatically be opened will do so when downloaded.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nexe\r\ntxt","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes_autoopenfiletypesdesc","displayName":"List of file types that should be automatically opened on download (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowed","displayName":"Allow media autoplay","description":"Setting the policy to True lets Google Chrome autoplay media. Setting the policy to False stops Google Chrome from autoplaying media.\r\n\r\n By default, Google Chrome doesn't autoplay media. But, for certain URL patterns, you can use the AutoplayAllowlist policy to change this setting.\r\n\r\nIf this policy changes while Google Chrome is running, it only applies to newly opened tabs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowlist","displayName":"Allow media autoplay on a allowlist of URL patterns","description":"Setting the policy lets videos play automatically (without user consent) with audio content in Google Chrome. If AutoplayAllowed policy is set to True, then this policy has no effect. If AutoplayAllowed is set to False, then any URL patterns set in this policy can still play. If this policy changes while Google Chrome is running, it only applies to newly opened tabs.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowlist_autoplayallowlistdesc","displayName":"Allow media autoplay on a allowlist of URL patterns (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_backgroundmodeenabled","displayName":"Continue running background apps when Google Chrome is closed","description":"Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there.\r\n\r\nSetting the policy to Disabled turns background mode off.\r\n\r\nIf you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_backgroundmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_backgroundmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_blockthirdpartycookies","displayName":"Block third party cookies","description":"Setting the policy to Enabled prevents webpage elements that aren't from the domain that's in the browser's address bar from setting cookies. Setting the policy to Disabled lets those elements set cookies and prevents users from changing this setting.\r\n\r\nLeaving it unset turns third-party cookies on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_blockthirdpartycookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_blockthirdpartycookies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_bookmarkbarenabled","displayName":"Enable Bookmark Bar","description":"Setting the policy to True displays a bookmark bar in Google Chrome. Setting the policy to False means users never see the bookmark bar.\r\n\r\nIf you set the policy, users can't change it. If not set, users decide whether to use this function.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_bookmarkbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_bookmarkbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browseraddpersonenabled","displayName":"Enable add person in user manager","description":"If this policy is set to true or not configured, Google Chrome will allow Add Person from the user manager.\r\n\r\nIf this policy is set to false, Google Chrome will not allow creation of new profiles from the user manager.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browseraddpersonenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browseraddpersonenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenabled","displayName":"Enable guest mode in browser","description":"If this policy is set to true or not configured, Google Chrome will enable guest logins. Guest logins are Google Chrome profiles where all windows are in incognito mode.\r\n\r\nIf this policy is set to false, Google Chrome will not allow guest profiles to be started.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenforced","displayName":"Enforce browser guest mode","description":"Setting the policy to Enabled means Google Chrome enforces guest sessions and prevents profile sign-ins. Guest sign-ins are Google Chrome profiles where windows are in Incognito mode.\r\n\r\nSetting the policy to Disabled, leaving it unset, or disabling browser Guest mode (through BrowserGuestModeEnabled) allows the use of new and existing profiles.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenforced_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenforced_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlabsenabled","displayName":"Browser experiments icon in toolbar","description":"Setting the policy to Enabled or leaving the policy unset means that users can access browser experimental features through an icon in the toolbar\r\n\r\nSetting the policy to Disabled removes the browser experimental features icon from the toolbar.\r\n\r\nchrome://flags and any other means of turning off and on browser features will still behave as expected regardless of whether this policy is Enabled or Disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlegacyextensionpointsblocked","displayName":"Block Browser Legacy Extension Points","description":"Setting the policy to Enabled or leaving it unset will enable ProcessExtensionPointDisablePolicy to block legacy extension points in the Browser process.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security and stability as unknown and potentially hostile code can load inside Google Chrome's browser process. Only turn off the policy if there are compatibility issues with third-party software that must run inside Google Chrome's browser process.\r\n\r\nNote: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlegacyextensionpointsblocked_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlegacyextensionpointsblocked_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsernetworktimequeriesenabled","displayName":"Allow queries to a Google time service","description":"Setting the policy to Enabled or leaving it unset means Google Chrome send occasional queries to a Google server to retrieve an accurate timestamp.\r\n\r\nSetting the policy to Disabled stops Google Chrome from sending these queries.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsernetworktimequeriesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsernetworktimequeriesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin","displayName":"Browser sign in settings","description":"This policy controls the sign-in behavior of the browser. It allows you to specify if the user can sign in to Google Chrome with their account and use account related services like Google Chrome Sync.\r\n\r\nIf the policy is set to \"Disable browser sign-in\" then the user cannot sign in to the browser and use account-based services. In this case browser-level features like Google Chrome Sync cannot be used and will be unavailable. On iOS, if the user was signed in and the policy is set to \"Disabled\" they will be signed out immediately. On other platforms, they will be signed out the next time they run Google Chrome. On all platforms, their local profile data like bookmarks, passwords etc. will be preserved and still usable. The user will still be able to sign into and use Google web services like Gmail.\r\n\r\nIf the policy is set to \"Enable browser sign-in,\" then the user is allowed to sign in to the browser. On all platforms except iOS, the user is automatically signed in to the browser when signed in to Google web services like Gmail. Being signed in to the browser means the user's account information will be kept by the browser. However, it does not mean that Google Chrome Sync will be turned on by default; the user must separately opt-in to use this feature. Enabling this policy will prevent the user from turning off the setting that allows browser sign-in. To control the availability of Google Chrome Sync, use the SyncDisabled policy.\r\n\r\nIf the policy is set to \"Force browser sign-in\" the user is presented with an account selection dialog and has to choose and sign in to an account to use the browser. This ensures that for managed accounts the policies associated with the account are applied and enforced. The default value of BrowserGuestModeEnabled will be set to disabled. Note that existing unsigned profiles will be locked and inaccessible after enabling this policy. For more information, see help center article: https://support.google.com/chrome/a/answer/7572556 . This option is not supported on Linux, Android or iOS. It will fall back to \"Enable browser sign-in\" if used.\r\n\r\nIf this policy is not set then the user can decide if they want to enable browser sign-in in the Google Chrome settings and use it as they see fit.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin_browsersignin","displayName":"Browser sign in settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin_browsersignin_0","displayName":"Disable browser sign-in","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin_browsersignin_1","displayName":"Enable browser sign-in","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin_browsersignin_2","displayName":"Force users to sign-in to use the browser","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor","displayName":"Configure the color of the browser's theme","description":"This policy allows admins to configure the color of Google Chrome's theme. The input string should be a valid hex color string matching the format \"#RRGGBB\".\r\n\r\nSetting the policy to a valid hex color causes a theme based on that color to be automatically generated and applied to the browser. Users won't be able to change the theme set by the policy.\r\n\r\nLeaving the policy unset lets users change their browser's theme as preferred.\r\n\r\nExample value: #FFFFFF","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor_browserthemecolor","displayName":"Configure the color of the browser's theme (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings","description":"Configures browsing data lifetime settings for Google Chrome. This policy allows admins to configure (per data-type) when data is deleted by the browser. This is useful for customers that work with sensitive customer data. The policy will only take effect if SyncDisabled is set to true.\r\n\r\nThe available data types are 'browsing_history', 'download_history', 'cookies_and_other_site_data', 'cached_images_and_files', 'password_signin', 'autofill', 'site_settings' and 'hosted_app_data'.\r\n\r\nThe browser will automatically remove data of selected types that is older than 'time_to_live_in_hours'. The minimum value that can be set is 1 hour.\r\n\r\nThe deletion of expired data will happen 15 seconds after the browser starts then every hour while the browser is running.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=BrowsingDataLifetime for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"time_to_live_in_hours\": 24,\r\n \"data_types\": [\r\n \"browsing_history\"\r\n ]\r\n },\r\n {\r\n \"time_to_live_in_hours\": 12,\r\n \"data_types\": [\r\n \"password_signin\",\r\n \"autofill\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_builtindnsclientenabled","displayName":"Use built-in DNS client","description":"This policy controls which software stack is used to communicate with the DNS server: the Operating System DNS client, or Google Chrome's built-in DNS client. This policy does not affect which DNS servers are used: if, for example, the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It also does not control if DNS-over-HTTPS is used; Google Chrome will always use the built-in resolver for DNS-over-HTTPS requests. Please see the DnsOverHttpsMode policy for information on controlling DNS-over-HTTPS.\r\n\r\nIf this policy is set to Enabled, the built-in DNS client will be used, if available.\r\n\r\nIf this policy is set to Disabled, the built-in DNS client will only be used when DNS-over-HTTPS is in use.\r\n\r\nIf this policy is left unset, the built-in DNS client will be enabled by default on macOS, Android (when neither Private DNS nor VPN are enabled) and Google Chrome OS.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_builtindnsclientenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_builtindnsclientenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled","displayName":"CECPQ2 post-quantum key-agreement enabled for TLS","description":"If this policy is not configured, or is set to enabled, then Google Chrome will follow the default rollout process for CECPQ2, a post-quantum key-agreement algorithm in TLS.\r\n\r\nCECPQ2 results in larger TLS messages which, in very rare cases, can trigger bugs in some networking hardware. This policy can be set to False to disable CECPQ2 while networking issues are resolved.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Google Chrome.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforcas","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes","description":"Setting the policy turns off enforcement of Certificate Transparency disclosure requirements for a list of subjectPublicKeyInfo hashes. Enterprise hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed). To turn off enforcement, the hash must meet one of these conditions:\r\n\r\n* It's of the server certificate's subjectPublicKeyInfo.\r\n\r\n* It's of a subjectPublicKeyInfo that appears in a Certificate Authority (CA) certificate in the certificate chain. That CA certificate is constrained through the X.509v3 nameConstraints extension, one or more directoryName nameConstraints are present in the permittedSubtrees, and the directoryName has an organizationName attribute.\r\n\r\n* It's of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, the CA certificate has one or more organizationName attributes in the certificate Subject, and the server's certificate has the same number of organizationName attributes, in the same order, and with byte-for-byte identical values.\r\n\r\nSpecify a subjectPublicKeyInfo hash by linking the hash algorithm name, a slash, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. Base64 encoding format matches that of an SPKI Fingerprint. The only recognized hash algorithm is sha256; others are ignored.\r\n\r\nLeaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforcas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforcas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforcas_certificatetransparencyenforcementdisabledforcasdesc","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas","displayName":"Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities","description":"Setting the policy turns off enforcement of Certificate Transparency disclosure requirements for a list of Legacy Certificate Authorities (CA) for certificate chains with a specified subjectPublicKeyInfo hash. Enterprise hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed). To turn off enforcement, the subjectPublicKeyInfo hash must appear in a CA certificate recognized as a Legacy CA. A Legacy CA is publicly trusted by one or more operating systems supported by Google Chrome, but not Android Open Source Project or Google Chrome OS.\r\n\r\nSpecify a subjectPublicKeyInfo hash by linking the hash algorithm name, a slash and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. Base64 encoding format matches that of an SPKI Fingerprint. The only recognized hash algorithm is sha256; others are ignored.\r\n\r\nLeaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_certificatetransparencyenforcementdisabledforlegacycasdesc","displayName":"Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforurls","displayName":"Disable Certificate Transparency enforcement for a list of URLs","description":"Setting the policy turns off Certificate Transparency disclosure requirements for the hostnames in the specified URLs. While making it harder to detect misissued certificates, hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed).\r\n\r\nLeaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.\r\n\r\nA URL pattern follows this format ( https://www.chromium.org/administrators/url-blocklist-filter-format ). However, because the validity of certificates for a given hostname is independent of the scheme, port, or path, Google Chrome only considers the hostname portion of the URL. Wildcard hosts aren't supported.\r\n\r\nExample value:\r\n\r\nexample.com\r\n.example.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforurls_certificatetransparencyenforcementdisabledforurlsdesc","displayName":"Disable Certificate Transparency enforcement for a list of URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromecleanupenabled","displayName":"Enable Chrome Cleanup on Windows","description":"Setting the policy to Enabled or leaving it unset means Chrome Cleanup periodically scans the system for unwanted software and should any be found, will ask the user if they wish to remove it. Manually triggering Chrome Cleanup from chrome://settings is allowed.\r\n\r\nSetting the policy to Disabled means Chrome Cleanup won't periodically scan and manual triggering is disabled.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromecleanupenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromecleanupenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromecleanupreportingenabled","displayName":"Control how Chrome Cleanup reports data to Google","description":"Setting the policy to Enabled means if Chrome Cleanup detects unwanted software, it may, in line with policy set by SafeBrowsingExtendedReportingEnabled, report about the scan to Google. Chrome Cleanup asks users if they want the cleanup. It sends results to Google.\r\n\r\nSetting the policy to Disabled means if Chrome Cleanup detects unwanted software, it won't report about the scan to Google, regardless of the value of SafeBrowsingExtendedReportingEnabled. Chrome Cleanup asks users if they want the cleanup. The results aren't reported to Google.\r\n\r\nLeaving the policy unset means Chrome Cleanup may, in line with policy set by SafeBrowsingExtendedReportingEnabled, report about scans for detecting unwanted software to Google. Chrome Cleanup asks users if they want the cleanup and to share the results with Google to help with future unwanted software detection. These results have file metadata, automatically installed extensions, and registry keys, as described by the Chrome Privacy Whitepaper.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromecleanupreportingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromecleanupreportingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations","displayName":"Determine the availability of variations","description":"Configuring this policy allows to specify which variations are allowed to be applied in Google Chrome.\r\n\r\nVariations provide a means for offering modifications to Google Chrome without shipping a new version of the browser by selectively enabling or disabling already existing features. See https://support.google.com/chrome/a?p=Manage_the_Chrome_variations_framework for more information.\r\n\r\nSetting the VariationsEnabled (value 0), or leaving the policy not set allows all variations to be applied to the browser.\r\n\r\nSetting the CriticalFixesOnly (value 1), allows only variations considered critical security or stability fixes to be applied to Google Chrome.\r\n\r\nSetting the VariationsDisabled (value 2), prevent all variations from being applied to the browser. Please note that this mode can potentially prevent the Google Chrome developers from providing critical security fixes in a timely manner and is thus not recommended.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations","displayName":"Determine the availability of variations (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_0","displayName":"Enable all variations","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_1","displayName":"Enable variations concerning critical fixes only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_2","displayName":"Disable all variations","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist","displayName":"Clear Browsing Data on Exit","description":"Configures a list of browsing data types that should be deleted when the user closes all browser windows. The available data types are browsing history (browsing_history), download history (download_history), cookies (cookies_and_other_site_data), cache(cached_images_and_files), autofill (autofill), passwords (password_signin), site settings (site_settings) and hosted apps data (hosted_app_data). This policy does not take precedence over AllowDeletingBrowserHistory.\r\n\r\nThis policy requires the SyncDisabled policy to be set to true, otherwise it will be ignored. If this policy is set at platform level, Sync should be disabled at platform level. If this policy is set at user level, Sync should be disabled for that user in order for this policy to take effect.\r\n\r\nIf Google Chrome does not exit cleanly (for example, if the browser or the OS crashes), the browsing data will be cleared the next time the profile is loaded.\r\n\r\nExample value:\r\n\r\nbrowsing_history\r\ndownload_history\r\ncookies_and_other_site_data\r\ncached_images_and_files\r\npassword_signin\r\nautofill\r\nsite_settings\r\nhosted_app_data","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist_clearbrowsingdataonexitlistdesc","displayName":"Clear Browsing Data on Exit (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clicktocallenabled","displayName":"Enable the Click to Call Feature","description":"Enable the Click to Call feature which allows users to send phone numbers from Chrome Desktops to an Android device when the user is Signed-in. For more information, see help center article: https://support.google.com/chrome/answer/9430554?hl=en.\r\n\r\nIf this policy is set to enabled, the capability of sending phone numbers to Android devices will be enabled for the Chrome user.\r\n\r\nIf this policy is set to disabled, the capability of sending phone numbers to Android devices will be disabled for the Chrome user.\r\n\r\nIf you set this policy, users cannot change or override it.\r\n\r\nIf this policy is left unset, the Click to Call feature is enabled by default.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clicktocallenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clicktocallenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmentmandatory","displayName":"Enable mandatory cloud management enrollment","description":"Setting the policy to Enabled mandates Chrome Browser Cloud Management enrollment and blocks Google Chrome launch process if failed.\r\n\r\nSetting the policy to Disabled or leaving it unset renders Chrome Browser Cloud Management optional and doesn't block Google Chrome launch process if failed.\r\n\r\nMachine scope cloud policy enrollment on desktop uses this policy. See https://support.google.com/chrome/a/answer/9301891?ref_topic=9301744 for details.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmentmandatory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmentmandatory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmenttoken","displayName":"The enrollment token of cloud policy on desktop","description":"Setting the policy means Google Chrome tries to register itself with Chrome Browser Cloud Management. The value of this policy is an enrollment token you can retrieve from the Google Admin console.\r\n\r\nSee https://support.google.com/chrome/a/answer/9301891?ref_topic=9301744 for details.\r\n\r\nExample value: 37185d02-e055-11e7-80c1-9a214cf093ae","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmenttoken_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmenttoken_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmenttoken_cloudmanagementenrollmenttoken","displayName":"The enrollment token of cloud policy on desktop (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudpolicyoverridesplatformpolicy","displayName":"Google Chrome cloud policy overrides Platform policy.","description":"Setting the policy to Enabled means cloud policy takes precedence if it conflicts with platform policy.\r\n\r\nSetting the policy to Disabled or leaving it unset means platform policy takes precedence if it conflicts with cloud policy.\r\n\r\nThis mandatory policy affects machine scope cloud policies.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudpolicyoverridesplatformpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudpolicyoverridesplatformpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clouduserpolicymerge","displayName":"Enables merging of user cloud policies into machine-level policies","description":"Setting the policy to Enabled allows policies associated with a Google Workspace account to be merged into machine-level policies.\r\n\r\nOnly policies originating from secure users can be merged. A secure user is affiliated with the organization that manages their browser using Chrome Browser Cloud Management. All other user-level policies will always be ignored.\r\n\r\nPolicies that need to be merged also need to be set in either PolicyListMultipleSourceMergeList or PolicyDictionaryMultipleSourceMergeList. This policy will be ignored if neither of the two aforementioned policies is configured.\r\n\r\nLeaving the policy unset or setting it to Disabled prevents user-level cloud policies from being merged with policies from any other sources.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clouduserpolicymerge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clouduserpolicymerge_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clouduserpolicyoverridescloudmachinepolicy","displayName":"Allow user cloud policies to override Chrome Browser Cloud Management policies.","description":"Setting the policy to Enabled allows policies associated with a Google Workspace account to take precedence if they conflict with Chrome Browser Cloud Management policies.\r\n\r\nOnly policies originating from secure users can be merged. A secure user is affiliated with the organization that manages their browser using Chrome Browser Cloud Management. All other user-level policies will have default precedence.\r\n\r\nThe policy can be combined with CloudPolicyOverridesPlatformPolicy. If both policies are enabled, user cloud policies will also take precedence over conflicting platform policies.\r\n\r\nLeaving the policy unset or setting it to disabled causes user-level cloud policies to have default priority.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clouduserpolicyoverridescloudmachinepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clouduserpolicyoverridescloudmachinepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_commandlineflagsecuritywarningsenabled","displayName":"Enable security warnings for command-line flags","description":"Setting the policy to Enabled or leaving it unset means security warnings appear when potentially dangerous command-line flags are used to launch Chrome.\r\n\r\nSetting the policy to Disabled prevents security warnings from appearing when Chrome is launched with potentially dangerous command-line flags.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_commandlineflagsecuritywarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_commandlineflagsecuritywarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_componentupdatesenabled","displayName":"Enable component updates in Google Chrome","description":"Enables component updates for all components in Google Chrome when not set or set to enabled.\r\n\r\nIf set to disabled, updates to components are disabled. However, some components are exempt from this policy: updates to any component that does not contain executable code, or does not significantly alter the behavior of the browser, or is critical for its security will not be disabled.\r\nExamples of such components include the certificate revocation lists and Safe Browsing data.\r\nSee https://developers.google.com/safe-browsing for more info on Safe Browsing.\r\nPlease note that setting this policy to disabled can potentially prevent the Google Chrome developers from providing critical security fixes in a timely manner and is thus not recommended.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_componentupdatesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_componentupdatesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request headers support","description":"Configures support of CORS non-wildcard request headers.\r\n\r\nGoogle Chrome version 97 introduces support for CORS non-wildcard request headers. When scripts make a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header must be explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. See https://www.chromest atus.com/feature/5768642492891136 for more detail.\r\n\r\nIf this policy is not set, or set to True, Google Chrome will support the CORS non-wildcard request headers and behave as described above.\r\n\r\nWhen this policy is set to False, chrome will allow the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\r\n\r\nThis Enterprise policy is temporary; it's intended to be removed after Google Chrome version 103.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_corsnonwildcardrequestheaderssupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_corsnonwildcardrequestheaderssupport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled","displayName":"Specifies whether WebAssembly modules can be sent cross-origin","description":"\r\nSpecifies whether WebAssembly modules can be sent to another window or worker cross-origin. Cross-origin WebAssembly module sharing will be deprecated as part of the efforts to deprecate document.domain, see https://github.com/mikewest/deprecating-document-domain. This policy allows to re-enable cross-origin WebAssembly module sharing to offer a longer transition period in the deprecation process.\r\n\r\nWhen set to True, sites can send WebAssembly modules also cross-origin without restrictions.\r\n\r\nWhen set to False or not set, sites can only send WebAssembly modules to windows and workers in the same origin.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultbrowsersettingenabled","displayName":"Set Google Chrome as Default Browser","description":"Setting the policy to True has Google Chrome always check whether it's the default browser on startup and, if possible, automatically register itself. Setting the policy to False stops Google Chrome from ever checking if it's the default and turns user controls off for this option.\r\n\r\nLeaving the policy unset means Google Chrome lets users control whether it's the default and, if not, whether user notifications should appear.\r\n\r\nNote: For Microsoft®Windows® administrators, turning this setting on only works for machines running Windows 7. For later versions, you must deploy a \"default application associations\" file that makes Google Chrome the handler for the https and http protocols (and, optionally, the ftp protocol and other file formats). See Chrome Help ( https://support.google.com/chrome?p=make_chrome_default_win ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultbrowsersettingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultbrowsersettingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultsearchprovidercontextmenuaccessallowed","displayName":"Allow default search provider context menu search access","description":"Enables the use of a default search provider on the context menu.\r\n\r\nIf you set this policy to disabled the search context menu item that relies on your default search provider will not be available.\r\n\r\nIf this policy is set to enabled or not set, the context menu item for your default search provider will be available.\r\n\r\nThe policy value is only appled when the DefaultSearchProviderEnabled policy is enabled, and is not applicable otherwise.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultsearchprovidercontextmenuaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultsearchprovidercontextmenuaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_desktopsharinghubenabled","displayName":"Enable desktop sharing in the omnibox and 3-dot menu","description":"Setting the policy to True or leaving it unset lets users share or save the current webpage using actions provided by the desktop sharing hub. The sharing hub is accessed through either an omnibox icon or the 3-dot menu.\r\n\r\nSetting the policy to False removes the sharing icon from the omnibox and the entry from the 3-dot menu.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_desktopsharinghubenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_desktopsharinghubenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability","displayName":"Control where Developer Tools can be used","description":"Setting the policy to 0 (the default) means you can access the developer tools and the JavaScript console, but not in the context of extensions installed by enterprise policy. Setting the policy to 1 means you can access the developer tools and the JavaScript console in all contexts, including that of extensions installed by enterprise policy. Setting the policy to 2 means you can't acess developer tools, and you can't inspect website elements.\r\n\r\nThis setting also turns off keyboard shortcuts and menu or context menu entries to open developer tools or the JavaScript console.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability","displayName":"Control where Developer Tools can be used (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability_0","displayName":"Disallow usage of the Developer Tools on extensions installed by enterprise policy, allow usage of the Developer Tools in other contexts","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability_1","displayName":"Allow usage of the Developer Tools","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability_2","displayName":"Disallow usage of the Developer Tools","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disable3dapis","displayName":"Disable support for 3D graphics APIs","description":"Setting the policy to True (or setting HardwareAccelerationModeEnabled to False) prevents webpages from accessing the WebGL API, and plugins can't use the Pepper 3D API.\r\n\r\nSetting the policy to False or leaving it unset lets webpages use the WebGL API and plugins use the Pepper 3D API, but the browser's default settings might still require command line arguments to use these APIs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disable3dapis_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disable3dapis_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablesafebrowsingproceedanyway","displayName":"Disable proceeding from the Safe Browsing warning page","description":"Setting the policy to Enabled prevents users from proceeding past the warning page the Safe Browsing service shows to the malicious site. This policy only prevents users from proceeding on Safe Browsing warnings such as malware and phishing, not for SSL certificate-related issues such as invalid or expired certificates.\r\n\r\nSetting the policy to Disabled or leaving it unset means users can choose to proceed to the flagged site after the warning appears.\r\n\r\nSee more about Safe Browsing ( https://developers.google.com/safe-browsing ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablesafebrowsingproceedanyway_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablesafebrowsingproceedanyway_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablescreenshots","displayName":"Disable taking screenshots","description":"Setting the policy to True disallows screenshots taken with keyboard shortcuts or extension APIs. Setting the policy to False allows screenshots.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablescreenshots_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablescreenshots_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir","displayName":"Set disk cache directory","description":"Setting the policy has Google Chrome use the directory you provide for storing cached files on the disk—whether or not users specify the --disk-cache-dir flag.\r\n\r\nIf not set, Google Chrome uses the default cache directory, but users can change that setting with the --disk-cache-dir command line flag.\r\n\r\nGoogle Chrome manages the contents of a volume's root directory. So to avoid data loss or other errors, do not set this policy to the root directory or any directory used for other purposes. See the variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: ${user_home}/Chrome_cache","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir_diskcachedir","displayName":"Set disk cache directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachesize","displayName":"Set disk cache size in bytes","description":"Setting the policy to None has Google Chrome use the default cache size for storing cached files on the disk. Users can't change it.\r\n\r\nIf you set the policy, Google Chrome uses the cache size you provide—whether or not users specify the --disk-cache-size flag. (Values below a few megabytes are rounded up.)\r\n\r\nIf not set, Google Chrome uses the default size. Users can change that setting using the --disk-cache-size flag.\r\n\r\nNote: The value specified in this policy is used as a hint to various cache subsystems in the browser. Therefore the actual total disk consumption of all caches will be higher but within the same order of magnitude as the value specified.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachesize_diskcachesize","displayName":"Set disk cache size: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_displaycapturepermissionspolicyenabled","displayName":"Specifies whether the display-capture permissions-policy is checked or skipped.","description":"\r\nThe display-capture permissions-policy gates access to getDisplayMedia(), as per this spec: https://www.w3.org/TR/screen-capture/#feature-policy-integration. However, if this policy is Disabled, this requirement is not enforced, and getDisplayMedia() is allowed from contexts that would otherwise be forbidden. This Enterprise policy is temporary; it's intended to be removed after Google Chrome version 100. It is intended to unblock Enterprise users whose application is non-spec compliant, but needs time to be fixed.\r\n\r\nWhen enabled or not set, sites can only call getDisplayMedia() from contexts which are allowlisted by the display-capture permissions-policy.\r\n\r\nWhen disabled, sites can call getDisplayMedia() even from contexts which are not allowlisted by the display-capture permissions policy. Note that other restrictions may still apply.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_displaycapturepermissionspolicyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_displaycapturepermissionspolicyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsinterceptionchecksenabled","displayName":"DNS interception checks enabled","description":"This policy configures a local switch that can be used to disable DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\r\n\r\nThis detection may not be necessary in an enterprise environment where the network configuration is known, since it causes some amount of DNS and HTTP traffic on start-up and each DNS configuration change.\r\n\r\nWhen this policy is not set, or is enabled, the DNS interception checks are performed. When explicitly disabled, they're not.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsinterceptionchecksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsinterceptionchecksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode","displayName":"Controls the mode of DNS-over-HTTPS","description":"Controls the mode of the DNS-over-HTTPS resolver. Please note that this policy will only set the default mode for each query. The mode may be overridden for special types of queries such as requests to resolve a DNS-over-HTTPS server hostname.\r\n\r\nThe \"off\" mode will disable DNS-over-HTTPS.\r\n\r\nThe \"automatic\" mode will send DNS-over-HTTPS queries first if a DNS-over-HTTPS server is available and may fallback to sending insecure queries on error.\r\n\r\nThe \"secure\" mode will only send DNS-over-HTTPS queries and will fail to resolve on error.\r\n\r\nOn Android Pie and above, if DNS-over-TLS is active, Google Chrome will not send insecure DNS requests.\r\n\r\nIf this policy is unset the browser may send DNS-over-HTTPS requests to a resolver associated with the user's configured system resolver.\r\n\r\nExample value: off","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode","displayName":"Controls the mode of DNS-over-HTTPS (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_off","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_automatic","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_secure","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver","description":"The URI template of the desired DNS-over-HTTPS resolver. To specify multiple DNS-over-HTTPS resolvers, separate the corresponding URI templates with spaces.\r\n\r\nIf the DnsOverHttpsMode is set to \"secure\" then this policy must be set and not empty.\r\n\r\nIf the DnsOverHttpsMode is set to \"automatic\" and this policy is set then the URI templates specified will be used; if this policy is unset then hardcoded mappings will be used to attempt to upgrade the user's current DNS resolver to a DoH resolver operated by the same provider.\r\n\r\nIf the URI template contains a dns variable, requests to the resolver will use GET; otherwise requests will use POST.\r\n\r\nIncorrectly formatted templates will be ignored.\r\n\r\nExample value: https://dns.example.net/dns-query{?dns}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloaddirectory","displayName":"Set download directory","description":"Setting the policy sets up the directory Chrome uses for downloading files. It uses the provided directory, whether or not users specify one or turned on the flag to be prompted for download location every time.\r\n\r\nLeaving the policy unset means Chrome uses the default download directory, and users can change it.\r\n\r\nNote: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloaddirectory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloaddirectory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloaddirectory_downloaddirectory","displayName":"Set download directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions","displayName":"Allow download restrictions","description":"Setting the policy means users can't bypass download security decisions.\r\n\r\nThere are many types of download warnings within Chrome, which roughly break down into these categories (learn more about Safe Browsing verdicts https://support.google.com/chrome/?p=ib_download_blocked):\r\n\r\n* Malicious, as flagged by the Safe Browsing server\r\n* Uncommon or unwanted, as flagged by the Safe Browsing server\r\n* A dangerous file type (e.g. all SWF downloads and many EXE downloads)\r\n\r\nSetting the policy blocks different subsets of these, depending on it's value:\r\n\r\n0: No special restrictions. Default.\r\n\r\n1: Blocks malicious files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n2: Blocks malicious files flagged by the Safe Browsing server AND Blocks uncommon or unwanted files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n3: Blocks all downloads. Not recommended, except for special use cases.\r\n\r\n4: Blocks malicious files flagged by the Safe Browsing server, does not block dangerous file types. Recommended.\r\n\r\nNote: These restrictions apply to downloads triggered from webpage content, as well as the Download link... menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options. Read more about Safe Browsing ( https://developers.google.com/safe-browsing ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_downloadrestrictions","displayName":"Download restrictions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_downloadrestrictions_0","displayName":"No special restrictions. Default.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_downloadrestrictions_2","displayName":"Block malicious downloads, uncommon or unwanted downloads and dangerous file types.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_downloadrestrictions_3","displayName":"Block all downloads.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_downloadrestrictions_4","displayName":"Block malicious downloads. Recommended.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_editbookmarksenabled","displayName":"Enable or disable bookmark editing","description":"Setting the policy to True or leaving it unset lets users add, remove, or modify bookmarks.\r\n\r\nSetting the policy to False means users can't add, remove, or modify bookmarks. They can still use existing bookmarks.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_editbookmarksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_editbookmarksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies","displayName":"Enables experimental policies","description":"Allows Google Chrome to load experimental policies.\r\n\r\nWARNING: Experimental policies are unsupported and subject to change or be removed without notice in future version of the browser!\r\n\r\nAn experimental policy may not be finished or still have known or unknown defects. It may be changed or even removed without any notification. By enabling experimental policies, you could lose browser data or compromise your security or privacy.\r\n\r\nIf a policy is not in the list and it's not officially released, its value will be ignored on Beta and Stable channel.\r\n\r\nIf a policy is in the list and it's not officially released, its value will be applied.\r\n\r\nThis policy has no effect on already released policies.\r\n\r\nExample value:\r\n\r\nExtensionInstallAllowlist\r\nExtensionInstallBlocklist","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies_enableexperimentalpoliciesdesc","displayName":"Enables experimental policies (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableonlinerevocationchecks","displayName":"Enable online OCSP/CRL checks","description":"Setting the policy to True means online OCSP/CRL checks are performed.\r\n\r\nSetting the policy to False or leaving it unset means Google Chrome won't perform online revocation checks in Google Chrome 19 and later.\r\n\r\nNote: OCSP/CRL checks provide no effective security benefit.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableonlinerevocationchecks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableonlinerevocationchecks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled","displayName":"Enables managed extensions to use the Enterprise Hardware Platform API","description":"Setting the policy to True lets extensions installed by enterprise policy use the Enterprise Hardware Platform API.\r\n\r\nSetting the policy to False or leaving it unset prevents extensions from using this API.\r\n\r\nNote: This policy also applies to component extensions, such as the Hangout Services extension.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_explicitlyallowednetworkports","displayName":"Explicitly allowed network ports","description":"There is a list of restricted ports built into Google Chrome. Connections to these ports will fail. This setting permits bypassing that list. The value is a comma-separated list of zero or more ports that outgoing connections will be permitted on.\r\n\r\nPorts are restricted to prevent Google Chrome being used as a vector to exploit various network vulnerabilities. Setting this policy may expose your network to attacks. This policy is intended as a temporary workaround for errors with code \"ERR_UNSAFE_PORT\" while migrating a service running on a blocked port to a standard port (ie. port 80 or 443).\r\n\r\nMalicious websites can easily detect that this policy is set, and for what ports, and use that information to target attacks.\r\n\r\nEach port here is labelled with a date that it can be unblocked until. After that date the port will be restricted regardless of this setting.\r\n\r\nLeaving the value empty or unset means that all restricted ports will be blocked. If there is a mixture of valid and invalid values, the valid ones will be applied.\r\n\r\nThis policy overrides the \"--explicitly-allowed-ports\" command-line option.\r\n\r\nExample value:\r\n\r\n10080","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_explicitlyallowednetworkports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_explicitlyallowednetworkports_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_explicitlyallowednetworkports_explicitlyallowednetworkportsdesc","displayName":"Explicitly allowed network ports (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_externalprotocoldialogshowalwaysopencheckbox","displayName":"Show an \"Always open\" checkbox in external protocol dialog.","description":"This policy controls whether or not the \"Always open\" checkbox is shown on external protocol launch confirmation prompts.\r\n\r\n If this policy is set to True or not set, when an external protocol confirmation is shown, the user can select \"Always allow\" to skip all future confirmation prompts for the protocol on this site.\r\n\r\n If this policy is set to False, the \"Always allow\" checkbox is not displayed and the user will be prompted each time an external protocol is invoked.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_externalprotocoldialogshowalwaysopencheckbox_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_externalprotocoldialogshowalwaysopencheckbox_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on Shutdown","description":"Controls the duration (in seconds) allowed for keepalive requests on browser shutdown.\r\n\r\nWhen specified, browser shutdown can be blocked up to the specified seconds,\r\nto process keepalive (https://fetch.spec.whatwg.org/#request-keepalive-flag) requests.\r\n\r\nThe default value (0) means this feature is disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fetchkeepalivedurationsecondsonshutdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fetchkeepalivedurationsecondsonshutdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fetchkeepalivedurationsecondsonshutdown_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on Shutdown: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages","displayName":"Configure the content and order of preferred languages","description":"This policy allows admins to configure the order of the preferred languages in Google Chrome's settings.\r\n\r\nThe order of the list will appear in the same order under the \"Order languages based on your preference\" section in chrome://settings/languages. Users won't be able to remove or reorder languages set by the policy, but will be able to add languages underneath those set by the policy. Users will also have full control over the browser's UI language and translation/spell check settings, unless enforced by other policies.\r\n\r\nLeaving the policy unset lets users manipulate the entire list of preferred languages.\r\n\r\nExample value:\r\n\r\nen-US","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages_forcedlanguagesdesc","displayName":"Configure the content and order of preferred languages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceephemeralprofiles","displayName":"Ephemeral profile","description":"If set to enabled this policy forces the profile to be switched to ephemeral mode. If this policy is specified as an OS policy (e.g. GPO on Windows) it will apply to every profile on the system; if the policy is set as a Cloud policy it will apply only to a profile signed in with a managed account.\r\n\r\nIn this mode the profile data is persisted on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies and web databases are not preserved after the browser is closed. However this does not prevent the user from downloading any data to disk manually, save pages or print them.\r\n\r\nIf the user has enabled sync all this data is preserved in their sync profile just like with regular profiles. Incognito mode is also available if not explicitly disabled by policy.\r\n\r\nIf the policy is set to disabled or left not set signing in leads to regular profiles.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceephemeralprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceephemeralprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcegooglesafesearch","displayName":"Force Google SafeSearch","description":"Setting the policy to Enabled means SafeSearch in Google Search is always active, and users can't change this setting.\r\n\r\nSetting the policy to Disabled or leaving it unset means SafeSearch in Google Search is not enforced.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcegooglesafesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcegooglesafesearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode","description":"Setting the policy enforces a minimum Restricted mode on YouTube and prevents users from picking a less restricted mode. If you set it to:\r\n\r\n* Strict, Strict Restricted mode on YouTube is always active.\r\n\r\n* Moderate, the user may only pick Moderate Restricted mode and Strict Restricted mode on YouTube, but can't turn off Restricted mode.\r\n\r\n* Off or if no value is set, Restricted mode on YouTube isn't enforced by Chrome. External policies such as YouTube policies might still enforce Restricted mode.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict_forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict_forceyoutuberestrict_0","displayName":"Do not enforce Restricted Mode on YouTube","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict_forceyoutuberestrict_1","displayName":"Enforce at least Moderate Restricted Mode on YouTube","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict_forceyoutuberestrict_2","displayName":"Enforce Strict Restricted Mode for YouTube","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fullscreenallowed","displayName":"Allow fullscreen mode","description":"Setting the policy to True or leaving it unset means that, with appropriate permissions, users, apps, and extensions can enter Fullscreen mode (in which only web content appears).\r\n\r\nSetting the policy to False means users, apps, and extensions can't enter Fullscreen mode.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fullscreenallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fullscreenallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\r\n\r\nIf this policy is unset or disabled, the browser will use the default behavior of cross-site auth, which as of version 80, will be to scope HTTP server authentication credentials by top-level site, so if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites.\r\n\r\nIf the policy is enabled, HTTP auth credentials entered in the context of one site will automatically be used in the context of another.\r\n\r\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\r\n\r\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures, and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_globallyscopehttpauthcacheenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_globallyscopehttpauthcacheenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hardwareaccelerationmodeenabled","displayName":"Use hardware acceleration when available","description":"Setting the policy to Enabled or leaving it unset turns on hardware acceleration, if available.\r\n\r\nSetting the policy to Disabled turns off hardware acceleration.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hardwareaccelerationmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hardwareaccelerationmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode","displayName":"Control use of the Headless Mode","description":"Setting this policy to Enabled or leaving the policy unset allows use of the headless mode. Setting this policy to Disabled denies use of the headless mode.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_headlessmode","displayName":"Control use of the Headless Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_headlessmode_1","displayName":"Allow use of the Headless Mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_headlessmode_2","displayName":"Do not allow use of the Headless Mode","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hidewebstoreicon","displayName":"Hide the web store from the New Tab Page and app launcher","description":"Hide the Chrome Web Store app and footer link from the New Tab Page and Google Chrome OS app launcher.\r\n\r\nWhen this policy is set to true, the icons are hidden.\r\n\r\nWhen this policy is set to false or is not configured, the icons are visible.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hidewebstoreicon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hidewebstoreicon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_historyclustersvisible","displayName":"Show history clusters on the Chrome history page","description":"This policy controls the visibility of history clusters on the Chrome history page.\r\n\r\nIf the policy is set to Enabled, history clusters will be visible at chrome://history/journeys.\r\n\r\nIf the policy is set to Disabled, history clusters will not be visible at chrome://history/journeys.\r\n\r\nIf the policy is left unset, history clusters will be visible at chrome://history/journeys by default and users can change the visibility of history clusters.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_historyclustersvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_historyclustersvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hstspolicybypasslist","displayName":"List of names that will bypass the HSTS policy check","description":"Setting the policy specifies a list of hostnames that bypass preloaded HSTS upgrades from http to https.\r\n\r\nOnly single-label hostnames are allowed in this policy, and this policy only applies to \"static\" HSTS-preloaded entries (for instance, \"app\", \"new\", \"search\", \"play\"). This policy does not prevent HSTS upgrades for servers that have \"dynamically\" requested HSTS upgrades using a Strict-Transport-Security response header.\r\n\r\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific single-label hostnames specified, not to subdomains of those names.\r\n\r\nExample value:\r\n\r\nmeet","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hstspolicybypasslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hstspolicybypasslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hstspolicybypasslist_hstspolicybypasslistdesc","displayName":"List of names that will bypass the HSTS policy check (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled","description":"This policy controls whether users can enable HTTPS-Only Mode in Settings. HTTPS-Only Mode upgrades all navigations to HTTPS.\r\nIf this setting is not set or set to allowed, users will be allowed to enable HTTPS-Only Mode.\r\nIf this setting is set to disallowed, users will not be allowed to enable HTTPS-Only Mode.\r\nForce enabling HTTPS-Only Mode is not currently supported.\r\n\r\nExample value: disallowed","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode_allowed","displayName":"Allow users to enable HTTPS-Only Mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode_disallowed","displayName":"Do not allow users to enable HTTPS-Only Mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode_force_enabled","displayName":"Force enable HTTPS-Only Mode (not supported yet)","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importautofillformdata","displayName":"Import autofill form data from default browser on first run","description":"Setting the policy to Enabled imports autofill form data from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run.\r\n\r\nUsers can trigger an import dialog and the autofill form data checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importautofillformdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importautofillformdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importbookmarks","displayName":"Import bookmarks from default browser on first run","description":"Setting the policy to Enabled imports bookmarks from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run.\r\n\r\nUsers can trigger an import dialog and the bookmarks checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importbookmarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importbookmarks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhistory","displayName":"Import browsing history from default browser on first run","description":"Setting the policy to Enabled imports browsing history from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run.\r\n\r\nUsers can trigger an import dialog and the browsing history checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhistory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhomepage","displayName":"Import of homepage from default browser on first run","description":"Setting the policy to Enabled imports the homepage from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the homepage isn't imported on first run.\r\n\r\nUsers can trigger an import dialog and the homepage checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsavedpasswords","displayName":"Import saved passwords from default browser on first run","description":"Setting the policy to Enabled imports saved passwords from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no saved passwords are imported on first run.\r\n\r\nUsers can trigger an import dialog and the saved passwords checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsavedpasswords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsavedpasswords_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsearchengine","displayName":"Import search engines from default browser on first run","description":"Setting the policy to Enabled imports the default search engine from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run.\r\n\r\nUsers can trigger an import dialog and the default search engine checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsearchengine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsearchengine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability","displayName":"Incognito mode availability","description":"Specifies whether the user may open pages in Incognito mode in Google Chrome.\r\n\r\nIf 'Enabled' is selected or the policy is left unset, pages may be opened in Incognito mode.\r\n\r\nIf 'Disabled' is selected, pages may not be opened in Incognito mode.\r\n\r\nIf 'Forced' is selected, pages may be opened ONLY in Incognito mode. Note that 'Forced' does not work for Android-on-Chrome\r\n\r\nNote: On iOS, if the policy is changed during a session, it will only take effect on relaunch.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability","displayName":"Incognito mode availability (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability_0","displayName":"Incognito mode available","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability_1","displayName":"Incognito mode disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability_2","displayName":"Incognito mode forced","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureformswarningsenabled","displayName":"Enable warnings for insecure forms","description":"This policy controls the treatment for insecure forms (forms that submit over HTTP) embedded in secure (HTTPS) sites in the browser.\r\nIf the policy is enabled or unset, a full page warning will be shown when an insecure form is submitted. Additionally, a warning bubble will be shown next to the form fields when they are focused, and autofill will be disabled for those forms.\r\nIf the policy is disabled, warnings will not be shown for insecure forms, and autofill will work normally.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureformswarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureformswarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowed","displayName":"Specifies whether to allow insecure websites to make requests to more-private network endpoints","description":"Controls whether insecure websites are allowed to make requests to more-private network endpoints.\r\n\r\nThis policy relates to the Private Network Access specification. See https://wicg.github.io/private-network-access/ for more details.\r\n\r\nA network endpoint is more private than another if:\r\n1) Its IP address is localhost and the other is not.\r\n2) Its IP address is private and the other is public.\r\nIn the future, depending on spec evolution, this policy might apply to all cross-origin requests directed at private IPs or localhost.\r\n\r\nA website is deemed secure if it meets the definition of a secure context in https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts. Otherwise, it will be treated as an insecure context.\r\n\r\nWhen this policy is either not set or set to false, the default behavior for requests from insecure contexts to more-private network endpoints will depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests feature, which may be set by a field trial or on the command line.\r\n\r\nWhen this policy is set to true, insecure websites are allowed to make requests to any network endpoint, subject to other cross-origin checks.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts.","description":"List of URL patterns. Private network requests initiated from insecure websites served by matching origins are allowed.\r\n\r\nIf unset, this policy behaves as if set to the empty list.\r\n\r\nFor origins not covered by the patterns specified here, the global default value will be used either from the InsecurePrivateNetworkRequestsAllowed policy, if it is set, or the user's personal configuration otherwise.\r\n\r\nNote that this policy only affects insecure origins, so secure origins (e.g. https://example.com) included in this list will be ignored.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls_insecureprivatenetworkrequestsallowedforurlsdesc","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intensivewakeupthrottlingenabled","displayName":"Control the IntensiveWakeUpThrottling feature.","description":"When enabled the IntensiveWakeUpThrottling feature causes Javascript timers in background tabs to be aggressively throttled and coalesced, running no more than once per minute after a page has been backgrounded for 5 minutes or more.\r\n\r\nThis is a web standards compliant feature, but it may break functionality\r\non some websites by causing certain actions to be delayed by up to a\r\nminute. However, it results in significant CPU and battery savings when\r\nenabled. See https://bit.ly/30b1XR4 for more details.\r\n\r\nIf this policy is set to enabled then the feature will be force enabled, and\r\nusers will not be able to override this.\r\n\r\nIf this policy is set to disabled then the feature will be force disabled, and\r\nusers will not be able to override this.\r\n\r\nIf this policy is left unset then the feature will be controlled by its\r\nown internal logic, which can be manually configured by users.\r\n\r\nNote that the policy is applied per renderer process, with the most recent\r\nvalue of the policy setting in force when a renderer process starts. A full\r\nrestart is required to ensure that all loaded tabs receive a consistent\r\npolicy setting. It is harmless for processes to be running with different\r\nvalues of this policy.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intensivewakeupthrottlingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intensivewakeupthrottlingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior","displayName":"Intranet Redirection Behavior","description":"This policy configures behavior for intranet redirection via DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\r\n\r\nIf this policy is not set, the browser will use the default behavior of DNS interception checks and intranet redirect suggestions. In M88, they are enabled by default but will be disabled by default in the future release.\r\n\r\nDNSInterceptionChecksEnabled is a related policy that may also disable DNS interception checks; this policy is a more flexible version which may separately control intranet redirection infobars and may be expanded in the future.\r\nIf either DNSInterceptionChecksEnabled or this policy requests to disable interception checks, the checks will be disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_intranetredirectbehavior","displayName":"Intranet Redirection Behavior (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_intranetredirectbehavior_0","displayName":"Use default browser behavior.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_intranetredirectbehavior_1","displayName":"Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_intranetredirectbehavior_2","displayName":"Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_intranetredirectbehavior_3","displayName":"Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_isolateorigins","displayName":"Enable Site Isolation for specified origins","description":"Setting the policy means each of the named origins in a comma-separated list runs in a dedicated process. Each named origin's process will only be allowed to contain documents from that origin and its subdomains. For example, specifying https://a1.example.com/ allows https://a2.a1.example.com/ in the same process, but not https://example.com or https://b.example.com.\r\n\r\nSince Google Chrome 77, you can also specify a range of origins to isolate using a wildcard. For example, specifying https://[*.]corp.example.com will give every origin underneath https://corp.example.com its own dedicated process, including https://corp.example.com itself, https://a1.corp.example.com, and https://a2.a1.corp.example.com.\r\n\r\nNote that all sites (i.e., scheme plus eTLD+1, such as https://example.com) are already isolated by default on Desktop platforms, as noted in the SitePerProcess policy. This IsolateOrigins policy is useful to isolate specific origins at a finer granularity (e.g., https://a.example.com).\r\n\r\nAlso note that origins isolated by this policy will be unable to script other origins in the same site, which is otherwise possible if two same-site documents modify their document.domain values to match. Administrators should confirm this uncommon behavior is not used on an origin before isolating it.\r\n\r\nSetting the policy to off or leaving it unset lets users change this setting.\r\n\r\nNote: For Android, use the IsolateOriginsAndroid policy instead.\r\n\r\nExample value: https://a.example.com/,https://othersite.org/,https://[*.]corp.example.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_isolateorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_isolateorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_isolateorigins_isolateorigins","displayName":"Enable Site Isolation for specified origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lensregionsearchenabled","displayName":"Allow Google Lens region search menu item to be shown in context menu if supported.","description":"Leaving the policy unset or setting it to Enabled allows users to view and use the Google Lens region search menu item in the context menu. Setting the policy to Disabled means users will not see the Google Lens region search menu item in the context menu when Google Lens region search is supported.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lensregionsearchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lensregionsearchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lockiconinaddressbarenabled","displayName":"Enable lock icon in the omnibox for secure connections","description":"This policy controls the treatment for lock icon in the omnibox.\r\nFrom Chrome M93, there is a new omnibox icon for secure connections.\r\nIf the policy is Enabled, Chrome will use the existing lock icon for secure connections.\r\nIf the policy is Disabled or not set, Chrome will use the default icon for secure connections.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lockiconinaddressbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lockiconinaddressbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains","displayName":"Suppress lookalike domain warnings on domains","description":"This policy prevents the display of lookalike URL warnings on the sites listed. These warnings are typically shown on sites that Google Chrome believes might be trying to spoof another site the user is familiar with.\r\n\r\nIf the policy is enabled and set to one or more domains, no lookalike warnings pages will be shown when the user visits pages on that domain.\r\n\r\nIf the policy is not set, or set to an empty list, warnings may appear on any site the user visits.\r\n\r\nA hostname can be allowed with a complete host match, or any domain match. For example, a URL like \"https://foo.example.com/bar\" may have warnings suppressed if this list includes either \"foo.example.com\" or \"example.com\".\r\n\r\nExample value:\r\n\r\nfoo.example.com\r\nexample.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_lookalikewarningallowlistdomainsdesc","displayName":"Suppress lookalike domain warnings on domains (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction","displayName":"Add restrictions on managed accounts","description":"\r\n This policy requires SigninInterceptionEnabled to be set to True to take effect.\r\n\r\n If this policy is set to 'primary_account' at the machine level, all managed accounts will be forced to be primary.\r\n If this policy is set to 'primary_account' on an account, that account will always be a primary account, but may have secondary accounts in its profile.\r\n\r\n If this policy is set to 'primary_account_strict' at the machine level, all managed accounts will be forced to be primary.\r\n If this policy is set to 'primary_account_strict' on an account, that account will always be a primary account and will not have any secondary accounts in its profile.\r\n\r\n If this policy is set to 'none' or not set, managed accounts have no restrictions. This may result in a managed account being a secondary account, which disables its ability to receive policies set on the account by the admin.\r\n\r\n\r\nExample value: primary_account","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction_managedaccountssigninrestriction","displayName":"Add restrictions on managed accounts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction_managedaccountssigninrestriction_primary_account","displayName":"A Managed account must be a primary account","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction_managedaccountssigninrestriction_primary_account_strict","displayName":"A Managed account must be a primary account and have no secondary accounts","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction_managedaccountssigninrestriction_none","displayName":"No restrictions on managed accounts","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedbookmarks","displayName":"Managed Bookmarks","description":"Setting the policy sets up a list of bookmarks where each one is a dictionary with the keys \"name\" and \"url\". These keys hold the bookmark's name and target. Admins can set up a subfolder by defining a bookmark without a \"url\" key, but with an additional \"children\" key. This key also has a list of bookmarks, some of which can also be folders. Chrome amends incomplete URLs as if they were submitted through the address bar. For example, \"google.com\" becomes \"https://google.com/\".\r\n\r\nUsers can't change the folders the bookmarks are placed in (though they can hide it from the bookmark bar). The default folder name for managed bookmarks is \"Managed bookmarks\" but it can be changed by adding a new sub-dictionary to the policy with a single key named \"toplevel_name\" with the desired folder name as its value. Managed bookmarks are not synced to the user account and extensions can't modify them.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ManagedBookmarks for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"toplevel_name\": \"My managed bookmarks folder\"\r\n },\r\n {\r\n \"name\": \"Google\",\r\n \"url\": \"google.com\"\r\n },\r\n {\r\n \"name\": \"Youtube\",\r\n \"url\": \"youtube.com\"\r\n },\r\n {\r\n \"name\": \"Chrome links\",\r\n \"children\": [\r\n {\r\n \"name\": \"Chromium\",\r\n \"url\": \"chromium.org\"\r\n },\r\n {\r\n \"name\": \"Chromium Developers\",\r\n \"url\": \"dev.chromium.org\"\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedbookmarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedbookmarks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedbookmarks_managedbookmarks","displayName":"Managed Bookmarks (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedconfigurationperorigin","displayName":"Sets managed configuration values to websites to specific origins","description":"Setting the policy defines the return value of Managed Configuration API for given origin.\r\n\r\n Managed configuration API is a key-value configuration that can be accessed via navigator.managed.getManagedConfiguration() javascript call. This API is only available to origins which correspond to force-installed web applications via WebAppInstallForceList.\r\n\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ManagedConfigurationPerOrigin for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"origin\": \"https://www.google.com\",\r\n \"managed_configuration_url\": \"https://gstatic.google.com/configuration.json\",\r\n \"managed_configuration_hash\": \"asd891jedasd12ue9h\"\r\n },\r\n {\r\n \"origin\": \"https://www.example.com\",\r\n \"managed_configuration_url\": \"https://gstatic.google.com/configuration2.json\",\r\n \"managed_configuration_hash\": \"djio12easd89u12aws\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedconfigurationperorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedconfigurationperorigin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedconfigurationperorigin_managedconfigurationperorigin","displayName":"Sets managed configuration values to websites to specific origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxconnectionsperproxy","displayName":"Maximal number of concurrent connections to the proxy server","description":"Setting the policy specifies the maximal number of simultaneous connections to the proxy server. Some proxy servers can't handle a high number of concurrent connections per client, which is solved by setting this policy to a lower value. The value should be lower than 100 and higher than 6. Some web apps are known to consume many connections with hanging GETs, so setting a value below 32 may lead to browser networking hangs if there are too many web apps with hanging connections open. Lower below the default at your own risk.\r\n\r\nLeaving the policy unset means a default of 32 is used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxconnectionsperproxy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxconnectionsperproxy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxconnectionsperproxy_maxconnectionsperproxy","displayName":"Maximal number of concurrent connections to the proxy server: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay","displayName":"Maximum fetch delay after a policy invalidation","description":"Setting the policy specifies the maximum delay in milliseconds between receiving a policy invalidation and fetching the new policy from the device management service. Valid values range from 1,000 (1 second) to 300,000 (5 minutes). Values outside this range will be clamped to the respective boundary.\r\n\r\nLeaving the policy unset means Google Chrome uses the default value of 10 seconds.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay_maxinvalidationfetchdelay","displayName":"Maximum fetch delay after a policy invalidation: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled","displayName":"Enable Media Recommendations","description":"By default the browser will show media recommendations that are personalized to the user. Setting this policy to Disabled will result in these recommendations being hidden from the user. Setting this policy to Enabled or leaving it unset will result in the media recommendations being shown to the user.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediaroutercastallowallips","displayName":"Allow Google Cast to connect to Cast devices on all IP addresses.","description":"Unless EnableMediaRouter is set to Disabled, setting MediaRouterCastAllowAllIPs to Enabled connects Google Cast to Cast devices on all IP addresses, not just RFC1918/RFC4193 private addresses.\r\n\r\nSetting the policy to Disabled connects Google Cast to Cast devices only on RFC1918/RFC4193.\r\n\r\nLeaving the policy unset connects Google Cast to Cast devices only on RFC1918/RFC4193, unless the CastAllowAllIPs feature is turned on.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediaroutercastallowallips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediaroutercastallowallips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_metricsreportingenabled","displayName":"Enable reporting of usage and crash-related data","description":"When this policy is enabled, anonymous reporting of usage and crash-related data about Chrome to Google is enabled by default. Users will still be able to change this setting in the Chrome settings.\r\n\r\nWhen this policy is disabled, anonymous reporting is disabled and no usage or crash data is sent to Google. Users won't be able to change this setting.\r\n\r\nWhen this policy isn't set, users can choose the anonymous reporting behavior at installation or first run, and can later change the setting in the Chrome settings.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain or Windows 10 Pro or Enterprise instances that are enrolled for device management, and macOS instances that are managed via MDM or joined to a domain via MCX.\r\n\r\n(For Chrome OS, see DeviceMetricsReportingEnabled.)","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_metricsreportingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_metricsreportingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions","displayName":"Enable network prediction","description":"This policy controls network prediction in Google Chrome. It controls DNS prefetching, TCP, and SSL preconnection and prerendering of webpages.\r\n\r\nIf you set the policy, users can't change it. Leaving it unset turns on network prediction, but the user can change it.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions","displayName":"Enable network prediction (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_2","displayName":"Do not predict network actions on any network connection","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkservicesandboxenabled","displayName":"Enable the network service sandbox","description":"This policy controls whether or not the network service process runs sandboxed.\r\nIf this policy is enabled, the network service process will run sandboxed.\r\nIf this policy is disabled, the network service process will run unsandboxed. This leaves users open to additional security risks related to running the network service unsandboxed.\r\nIf this policy is not set, the default configuration for the network sandbox will be used. This may vary depending on Google Chrome release, currently running field trials, and platform.\r\nThis policy is intended to give enterprises flexibility to disable the network sandbox if they use third party software that interferes with the network service sandbox.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkservicesandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkservicesandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcardsvisible","displayName":"Show cards on the New Tab Page","description":"This policy controls the visibility of cards on the New Tab Page. Cards surface entry points to launch common user journeys based on the user's browsing behavior.\r\n\r\nIf the policy is set to Enabled, the New Tab Page will show cards if content is available.\r\n\r\nIf the policy is set to Disabled, the New Tab Page won't show cards.\r\n\r\nIf the policy is not set, the user can control the card visibility. The default is visible.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcardsvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcardsvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled","displayName":"Allow users to customize the background on the New Tab page","description":"If the policy is set to false, the New Tab page won't allow users to customize the background. Any existing custom background will be permanently removed even if the policy is set to true later.\r\n\r\nIf the policy is set to true or unset, users can customize the background on the New Tab page.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply","description":"Setting the policy specifies a list of origins (URLs) or hostname patterns (such as *.example.com) for which security restrictions on insecure origins won't apply. Organizations can specify origins for legacy applications that can't deploy TLS or set up a staging server for internal web development, so developers can test out features requiring secure contexts without having to deploy TLS on the staging server. This policy also prevents the origin from being labeled \"Not Secure\" in the address bar.\r\n\r\nSetting a list of URLs in this policy amounts to setting the command-line flag --unsafely-treat-insecure-origin-as-secure to a comma-separated list of the same URLs. The policy overrides the command-line flag and UnsafelyTreatInsecureOriginAsSecure, if present.\r\n\r\nFor more information on secure contexts, see Secure Contexts ( https://www.w3.org/TR/secure-contexts ).\r\n\r\nExample value:\r\n\r\nhttp://testserver.example.com/\r\n*.example.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin_overridesecurityrestrictionsoninsecureorigindesc","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_paymentmethodqueryenabled","displayName":"Allow websites to query for available payment methods.","description":"Allows you to set whether websites are allowed to check if the user has payment methods saved.\r\n\r\nIf this policy is set to disabled, websites that use PaymentRequest.canMakePayment or PaymentRequest.hasEnrolledInstrument API will be informed that no payment methods are available.\r\n\r\nIf the setting is enabled or not set then websites are allowed to check if the user has payment methods saved.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_paymentmethodqueryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_paymentmethodqueryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled","displayName":"Enables the concept of policy atomic groups","description":"Setting the policy to Enabled means policies coming from an atomic group that don't share the source with the highest priority from that group get ignored.\r\n\r\nSetting the policy to Disabled means no policy is ignored because of its source. Policies are ignored only if there's a conflict, and the policy doesn't have the highest priority.\r\n\r\nIf this policy is set from a cloud source, it can't target a specific user.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policydictionarymultiplesourcemergelist","displayName":"Allow merging dictionary policies from different sources","description":"Setting the policy allows merging of selected policies when they come from different sources, with the same scopes and level. This merging is in the first level keys of the dictionary from each source. The key coming from the highest priority source takes precedence.\r\n\r\nIf a policy is in the list and there's conflict between sources with:\r\n\r\n* The same scopes and level: The values merge into a new policy dictionary.\r\n\r\n* Different scopes or level: The policy with the highest priority applies.\r\n\r\nIf a policy isn't in the list and there's conflict between sources, scopes, or level, the policy with the highest priority applies.\r\n\r\nExample value:\r\n\r\nExtensionSettings","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policydictionarymultiplesourcemergelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policydictionarymultiplesourcemergelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policydictionarymultiplesourcemergelist_policydictionarymultiplesourcemergelistdesc","displayName":"Allow merging dictionary policies from different sources (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policylistmultiplesourcemergelist","displayName":"Allow merging list policies from different sources","description":"Setting the policy allows merging of selected policies when they come from different sources, with the same scopes and level.\r\n\r\nIf a policy is in the list and there's conflict between sources with:\r\n\r\n* The same scopes and level: The values merge into a new policy list.\r\n\r\n* Different scopes or level: The policy with the highest priority applies.\r\n\r\nIf a policy isn't in the list and there's conflict between sources, scopes, or level, the policy with the highest priority applies.\r\n\r\nExample value:\r\n\r\nExtensionInstallAllowlist\r\nExtensionInstallBlocklist","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policylistmultiplesourcemergelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policylistmultiplesourcemergelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policylistmultiplesourcemergelist_policylistmultiplesourcemergelistdesc","displayName":"Allow merging list policies from different sources (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyrefreshrate","displayName":"Refresh rate for user policy","description":"Setting the policy specifies the period in milliseconds at which the device management service is queried for user policy information. Valid values range from 1,800,000 (30 minutes) to 86,400,000 (1 day). Values outside this range will be clamped to the respective boundary.\r\n\r\nLeaving the policy unset uses the default value of 3 hours.\r\n\r\nNote: Policy notifications force a refresh when the policy changes, making frequent refreshes unnecessary. So, if the platform supports these notifications, the refresh delay is 24 hours (ignoring defaults and the value of this policy).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyrefreshrate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyrefreshrate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyrefreshrate_policyrefreshrate","displayName":"Refresh rate for user policy: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability","displayName":"Profile picker availability on startup","description":"Specifies whether the profile picker is enabled, disabled or forced at the browser startup.\r\n\r\nBy default the profile picker is not shown if the browser starts in guest or incognito mode, a profile directory and/or urls are specified by command line, an app is explicitly requested to open, the browser was launched by a native notification, there is only one profile available or the policy ForceBrowserSignin is set to true.\r\n\r\nIf 'Enabled' (0) is selected or the policy is left unset, the profile picker will be shown at startup by default, but users will be able to enable/disable it.\r\n\r\nIf 'Disabled' (1) is selected, the profile picker will never be shown, and users will not be able to change the setting.\r\n\r\nIf 'Forced' (2) is selected, the profile picker cannot be suppressed by the user. The profile picker will be shown even if there is only one profile available.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability","displayName":"Profile picker availability on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_0","displayName":"Profile picker available at startup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_1","displayName":"Profile picker disabled at startup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_2","displayName":"Profile picker forced at startup","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promotionaltabsenabled","displayName":"Enable showing full-tab promotional content","description":"Setting the policy to True or leaving it unset lets Google Chrome show users product information as full-tab content.\r\n\r\nSetting the policy to False prevents Google Chrome from showing product information as full-tab content.\r\n\r\nSetting the policy controls the presentation of the welcome pages that help users sign in to Google Chrome, set Google Chrome as users' default browser, or otherwise inform them of product features.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promotionaltabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promotionaltabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promptfordownloadlocation","displayName":"Ask where to save each file before downloading","description":"Setting the policy to Enabled means users are asked where to save each file before downloading. Setting the policy to Disabled has downloads start immediately, and users aren't asked where to save the file.\r\n\r\nLeaving the policy unset lets users change this setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promptfordownloadlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promptfordownloadlocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings","displayName":"Proxy settings","description":"Setting the policy configures the proxy settings for Chrome and ARC-apps, which ignore all proxy-related options specified from the command line.\r\n\r\n Leaving the policy unset lets users choose their proxy settings.\r\n\r\n Setting the ProxySettings policy accepts the following fields:\r\n * ProxyMode, which lets you specify the proxy server Chrome uses and prevents users from changing proxy settings\r\n * ProxyPacUrl, a URL to a proxy .pac file\r\n * ProxyPacMandatory, which prevents the network stack from falling back to direct connections with invalid or unavailable PAC script\r\n * ProxyServer, a URL of the proxy server\r\n * ProxyBypassList, a list of hosts for which the proxy will be bypassed\r\n\r\n The ProxyServerMode field is deprecated in favor of the ProxyMode field.\r\n\r\n For ProxyMode, if you choose the value:\r\n * direct, a proxy is never used and all other fields are ignored.\r\n * system, the systems's proxy is used and all other fields are ignored.\r\n * auto_detect, all other fields are ignored.\r\n * fixed_servers, the ProxyServer and ProxyBypassList fields are used.\r\n * pac_script, the ProxyPacUrl, ProxyPacMandatory and ProxyBypassList fields are used.\r\n\r\nNote: For more detailed examples, visit The Chromium Projects ( https://www.chromium.org/developers/design-documents/network-settings#TOC-Command-line-options-for-proxy-sett ).\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ProxySettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"ProxyMode\": \"fixed_servers\",\r\n \"ProxyServer\": \"123.123.123.123:8080\",\r\n \"ProxyBypassList\": \"https://www.example1.com,https://www.example2.com,https://internalsite/\"\r\n}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings_proxysettings","displayName":"Proxy settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed","displayName":"Allow QUIC protocol","description":"Setting the policy to Enabled or leaving it unset allows the use of QUIC protocol in Google Chrome.\r\n\r\nSetting the policy to Disabled disallows the use of QUIC protocol.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alternateerrorpagesenabled_recommended","displayName":"Enable alternate error pages","description":"Setting the policy to True means Google Chrome uses alternate error pages built into (such as \"page not found\"). Setting the policy to False means Google Chrome never uses alternate error pages.\r\n\r\nIf you set the policy, users can't change it. If not set, the policy is on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alternateerrorpagesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alternateerrorpagesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alwaysopenpdfexternally_recommended","displayName":"Always Open PDF files externally","description":"Setting the policy to Enabled turns the internal PDF viewer off in Google Chrome, treats PDF files as a download, and lets users open PDFs with the default application.\r\n\r\nSetting the policy to Disabled means that unless users turns off the PDF plugin, it will open PDF files.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users can choose whether to open PDF externally or not.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alwaysopenpdfexternally_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alwaysopenpdfexternally_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended","displayName":"Application locale","description":"Setting the policy specifies the locale Google Chrome uses.\r\n\r\nTurning it off or leaving it unset means the locale will be the first valid locale from:\r\n1) The user specified locale (if configured).\r\n2) The system locale.\r\n3) The fallback locale (en-US).\r\n\r\nExample value: en","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended_applicationlocalevalue","displayName":"Application locale (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofilladdressenabled_recommended","displayName":"Enable AutoFill for addresses","description":"Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI.\r\n\r\nSetting the policy to False means Autofill never suggests or fills address information, nor does it save additional address information that users submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofilladdressenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofilladdressenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofillcreditcardenabled_recommended","displayName":"Enable AutoFill for credit cards","description":"Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI.\r\n\r\nSetting the policy to False means autofill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofillcreditcardenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofillcreditcardenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended","displayName":"Continue running background apps when Google Chrome is closed","description":"Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there.\r\n\r\nSetting the policy to Disabled turns background mode off.\r\n\r\nIf you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_blockthirdpartycookies_recommended","displayName":"Block third party cookies","description":"Setting the policy to Enabled prevents webpage elements that aren't from the domain that's in the browser's address bar from setting cookies. Setting the policy to Disabled lets those elements set cookies and prevents users from changing this setting.\r\n\r\nLeaving it unset turns third-party cookies on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_blockthirdpartycookies_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_blockthirdpartycookies_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_bookmarkbarenabled_recommended","displayName":"Enable Bookmark Bar","description":"Setting the policy to True displays a bookmark bar in Google Chrome. Setting the policy to False means users never see the bookmark bar.\r\n\r\nIf you set the policy, users can't change it. If not set, users decide whether to use this function.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_bookmarkbarenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_bookmarkbarenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended","displayName":"Set default download directory","description":"Setting the policy changes the default directory that Chrome downloads files to, but users can change the directory.\r\n\r\nLeaving the policy unset means Chrome uses its platform-specific default directory.\r\n\r\nNote: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_defaultdownloaddirectory","displayName":"Set default download directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultsearchprovidercontextmenuaccessallowed_recommended","displayName":"Allow default search provider context menu search access","description":"Enables the use of a default search provider on the context menu.\r\n\r\nIf you set this policy to disabled the search context menu item that relies on your default search provider will not be available.\r\n\r\nIf this policy is set to enabled or not set, the context menu item for your default search provider will be available.\r\n\r\nThe policy value is only appled when the DefaultSearchProviderEnabled policy is enabled, and is not applicable otherwise.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultsearchprovidercontextmenuaccessallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultsearchprovidercontextmenuaccessallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloaddirectory_recommended","displayName":"Set download directory","description":"Setting the policy sets up the directory Chrome uses for downloading files. It uses the provided directory, whether or not users specify one or turned on the flag to be prompted for download location every time.\r\n\r\nLeaving the policy unset means Chrome uses the default download directory, and users can change it.\r\n\r\nNote: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloaddirectory_recommended_downloaddirectory","displayName":"Set download directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended","displayName":"Allow download restrictions","description":"Setting the policy means users can't bypass download security decisions.\r\n\r\nThere are many types of download warnings within Chrome, which roughly break down into these categories (learn more about Safe Browsing verdicts https://support.google.com/chrome/?p=ib_download_blocked):\r\n\r\n* Malicious, as flagged by the Safe Browsing server\r\n* Uncommon or unwanted, as flagged by the Safe Browsing server\r\n* A dangerous file type (e.g. all SWF downloads and many EXE downloads)\r\n\r\nSetting the policy blocks different subsets of these, depending on it's value:\r\n\r\n0: No special restrictions. Default.\r\n\r\n1: Blocks malicious files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n2: Blocks malicious files flagged by the Safe Browsing server AND Blocks uncommon or unwanted files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n3: Blocks all downloads. Not recommended, except for special use cases.\r\n\r\n4: Blocks malicious files flagged by the Safe Browsing server, does not block dangerous file types. Recommended.\r\n\r\nNote: These restrictions apply to downloads triggered from webpage content, as well as the Download link... menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options. Read more about Safe Browsing ( https://developers.google.com/safe-browsing ).","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions","displayName":"Download restrictions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_0","displayName":"No special restrictions. Default.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_2","displayName":"Block malicious downloads, uncommon or unwanted downloads and dangerous file types.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_3","displayName":"Block all downloads.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_4","displayName":"Block malicious downloads. Recommended.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importautofillformdata_recommended","displayName":"Import autofill form data from default browser on first run","description":"Setting the policy to Enabled imports autofill form data from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run.\r\n\r\nUsers can trigger an import dialog and the autofill form data checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importautofillformdata_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importautofillformdata_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importbookmarks_recommended","displayName":"Import bookmarks from default browser on first run","description":"Setting the policy to Enabled imports bookmarks from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run.\r\n\r\nUsers can trigger an import dialog and the bookmarks checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importbookmarks_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importbookmarks_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importhistory_recommended","displayName":"Import browsing history from default browser on first run","description":"Setting the policy to Enabled imports browsing history from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run.\r\n\r\nUsers can trigger an import dialog and the browsing history checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importhistory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importhistory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsavedpasswords_recommended","displayName":"Import saved passwords from default browser on first run","description":"Setting the policy to Enabled imports saved passwords from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no saved passwords are imported on first run.\r\n\r\nUsers can trigger an import dialog and the saved passwords checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsavedpasswords_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsavedpasswords_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended","displayName":"Import search engines from default browser on first run","description":"Setting the policy to Enabled imports the default search engine from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run.\r\n\r\nUsers can trigger an import dialog and the default search engine checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_metricsreportingenabled_recommended","displayName":"Enable reporting of usage and crash-related data","description":"When this policy is enabled, anonymous reporting of usage and crash-related data about Chrome to Google is enabled by default. Users will still be able to change this setting in the Chrome settings.\r\n\r\nWhen this policy is disabled, anonymous reporting is disabled and no usage or crash data is sent to Google. Users won't be able to change this setting.\r\n\r\nWhen this policy isn't set, users can choose the anonymous reporting behavior at installation or first run, and can later change the setting in the Chrome settings.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain or Windows 10 Pro or Enterprise instances that are enrolled for device management, and macOS instances that are managed via MDM or joined to a domain via MCX.\r\n\r\n(For Chrome OS, see DeviceMetricsReportingEnabled.)","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_metricsreportingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_metricsreportingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended","displayName":"Enable network prediction","description":"This policy controls network prediction in Google Chrome. It controls DNS prefetching, TCP, and SSL preconnection and prerendering of webpages.\r\n\r\nIf you set the policy, users can't change it. Leaving it unset turns on network prediction, but the user can change it.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions","displayName":"Enable network prediction (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions_2","displayName":"Do not predict network actions on any network connection","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_safebrowsingfortrustedsourcesenabled_recommended","displayName":"Enable Safe Browsing for trusted sources","description":"Setting the policy to Enabled or leaving it unset means downloaded files are sent to be analyzed by Safe Browsing, even when it's from a trusted source.\r\n\r\nSetting the policy to Disabled means downloaded files won't be sent to be analyzed by Safe Browsing when it's from a trusted source.\r\n\r\nThese restrictions apply to downloads triggered from webpage content, as well as the Download link menu option. These restrictions don't apply to the save or download of the currently displayed page or to saving as PDF from the printing options.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_safebrowsingfortrustedsourcesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_safebrowsingfortrustedsourcesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_searchsuggestenabled_recommended","displayName":"Enable search suggestions","description":"Setting the policy to True turns on search suggestions in Google Chrome's address bar. Setting the policy to False turns off these search suggestions.\r\n\r\nIf you set the policy, users can't change it. If not set, search suggestions are on at first, but users can turn them off any time.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_searchsuggestenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_searchsuggestenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_showfullurlsinaddressbar_recommended","displayName":"Show Full URLs","description":"This feature enables display of the full URL in the address bar.\r\nIf this policy is set to True, then the full URL will be shown in the address bar, including schemes and subdomains.\r\nIf this policy is set to False, then the default URL display will apply.\r\nIf this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.\r\n","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_showfullurlsinaddressbar_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_showfullurlsinaddressbar_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_spellcheckserviceenabled_recommended","displayName":"Enable or disable spell checking web service","description":"Setting the policy to Enabled puts a Google web service in use to help resolve spelling errors. This policy only controls the use of the online service. Setting the policy to Disabled means this service is never used.\r\n\r\nLeaving the policy unset lets users choose whether to use the spellcheck service.\r\n\r\nThe spell check can always use a downloaded dictionary locally unless the feature is disabled by SpellcheckEnabled in which case this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_spellcheckserviceenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_spellcheckserviceenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_translateenabled_recommended","displayName":"Enable Translate","description":"Setting the policy to True provides translation functionality when it's appropriate for users by showing an integrated translate toolbar in Google Chrome and a translate option on the right-click context menu. Setting the policy to False shuts off all built-in translate features.\r\n\r\nIf you set the policy, users can't change this function. Leaving it unset lets them change the setting.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_translateenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_translateenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended","displayName":"Register protocol handlers","description":"Setting the policy (as recommended only) lets you register a list of protocol handlers, which merge with the ones that the user registers, putting both sets in use. Set the property \"protocol\" to the scheme, such as \"mailto\", and set the property \"URL\" to the URL pattern of the application that handles the scheme specified in the \"protocol\" field. The pattern can include a \"%s\" placeholder, which the handled URL replaces.\r\n\r\nUsers can't remove a protocol handler registered by policy. However, by installing a new default handler, they can change the protocol handlers installed by policy.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=RegisteredProtocolHandlers for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"protocol\": \"mailto\",\r\n \"url\": \"https://mail.google.com/mail/?extsrc=mailto&url=%s\",\r\n \"default\": true\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"962a2377-ad9a-4654-a526-a77c14152fd7","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_registeredprotocolhandlers","displayName":"Register protocol handlers (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"962a2377-ad9a-4654-a526-a77c14152fd7","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended","displayName":"List of alternate URLs for the default search provider","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderAlternateURLs specifies a list of alternate URLs for extracting search terms from the search engine. The URLs should include the string '{searchTerms}'.\r\n\r\nLeaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms.\r\n\r\nExample value:\r\n\r\nhttps://search.my.company/suggest#q={searchTerms}\r\nhttps://search.my.company/suggest/search#q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended_defaultsearchprovideralternateurlsdesc","displayName":"List of alternate URLs for the default search provider (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended","displayName":"Enable the default search provider","description":"Setting the policy to Enabled means a default search is performed when a user enters non-URL text in the address bar. To specify the default search provider, set the rest of the default search policies. If you leave those policies empty, the user can choose the default provider. Setting the policy to Disabled means there's no search when the user enters non-URL text in the address bar.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, the default search provider is on, and users can set the search provider list.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended","displayName":"Default search provider encodings","description":"If DefaultSearchProviderEnabled is on, setting DefaultSearchProviderEncodings specifies the character encodings supported by the search provider. Encodings are code page names such as UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided.\r\n\r\nLeaving DefaultSearchProviderEncodings unset puts UTF-8 in use.\r\n\r\nExample value:\r\n\r\nUTF-8\r\nUTF-16\r\nGB2312\r\nISO-8859-1","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidericonurl_recommended","displayName":"Default search provider icon","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderIconURL specifies the default search provider's favorite icon URL.\r\n\r\nLeaving DefaultSearchProviderIconURL unset means there's no icon for the search provider.\r\n\r\nExample value: https://search.my.company/favicon.ico","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidericonurl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidericonurl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidericonurl_recommended_defaultsearchprovidericonurl","displayName":"Default search provider icon (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended","displayName":"Parameter providing search-by-image feature for the default search provider","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURL specifies the URL of the search engine used for image search. (If DefaultSearchProviderImageURLPostParams is set, then image search requests use the POST method instead.)\r\n\r\nLeaving DefaultSearchProviderImageURL unset means no image search is used.\r\n\r\nExample value: https://search.my.company/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_defaultsearchproviderimageurl","displayName":"Parameter providing search-by-image feature for the default search provider (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended","displayName":"Parameters for image URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURLPostParams specifies the parameters during image search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as {imageThumbnail}, real image thumbnail data replaces it.\r\n\r\nLeaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_defaultsearchproviderimageurlpostparams","displayName":"Parameters for image URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended","displayName":"Default search provider keyword","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider.\r\n\r\nLeaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_defaultsearchproviderkeyword","displayName":"Default search provider keyword (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended","displayName":"Default search provider name","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name.\r\n\r\nLeaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_defaultsearchprovidername","displayName":"Default search provider name (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended","displayName":"Default search provider new tab page URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderNewTabURL specifies the URL of the search engine used to provide a New Tab page.\r\n\r\nLeaving DefaultSearchProviderNewTabURL unset means no new tab page is provided.\r\n\r\nExample value: https://search.my.company/newtab","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended_defaultsearchprovidernewtaburl","displayName":"Default search provider new tab page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended","displayName":"Default search provider search URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURL specifies the URL of the search engine used during a default search. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms.\r\n\r\nYou can specify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\r\n\r\nExample value: https://search.my.company/search?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended","displayName":"Parameters for search URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended_defaultsearchprovidersearchurlpostparams","displayName":"Parameters for search URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended","displayName":"Default search provider suggest URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURL specifies the URL of the search engine to provide search suggestions. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms.\r\n\r\nYou can specify Google's search URL as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nExample value: https://search.my.company/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturlpostparams_recommended","displayName":"Parameters for suggest URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURLPostParams specifies the parameters during suggestion search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSuggestURLPostParams unset unset means suggest search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturlpostparams_recommended_defaultsearchprovidersuggesturlpostparams","displayName":"Parameters for suggest URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_autofillenabled_recommended","displayName":"Enable AutoFill","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"de643352-007f-4a47-8c83-d75a79516b39","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_autofillenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_autofillenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_safebrowsingenabled_recommended","displayName":"Enable Safe Browsing","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"de643352-007f-4a47-8c83-d75a79516b39","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_safebrowsingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_safebrowsingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordleakdetectionenabled_recommended","displayName":"Enable leak detection for entered credentials","description":"Setting the policy to Enabled lets users have Google Chrome check whether usernames and passwords entered were part of a leak.\r\n\r\nIf the policy is set, users can't change it in Google Chrome. If not set, credential leak checking is allowed, but the user can turn it off.\r\n\r\nThis behavior will not trigger if Safe Browsing is disabled (either by policy or by the user). In order to force Safe Browsing on, use the SafeBrowsingEnabled policy or the SafeBrowsingProtectionLevel policy.","helpText":"","infoUrls":[],"categoryId":"6d6b289c-c1e9-4004-b5ab-3123920cf10d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordleakdetectionenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordleakdetectionenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordmanagerenabled_recommended","displayName":"Enable saving passwords to the password manager","description":"Setting the policy to Enabled means users have Google Chrome remember passwords and provide them the next time they sign in to a site.\r\n\r\nSetting the policy to Disabled means users can't save new passwords, but previously saved passwords will still work.\r\n\r\nIf the policy is set, users can't change it in Google Chrome. If not set, the user can turn off password saving.","helpText":"","infoUrls":[],"categoryId":"6d6b289c-c1e9-4004-b5ab-3123920cf10d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordmanagerenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordmanagerenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printheaderfooter_recommended","displayName":"Print Headers and Footers","description":"Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview.\r\n\r\nIf you set the policy, users can't change it. If unset, users decides whether headers and footers appear.","helpText":"","infoUrls":[],"categoryId":"20ceae56-e189-46ec-a440-791ce7454017","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printheaderfooter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printheaderfooter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpdfasimagedefault_recommended","displayName":"Print PDF as Image Default","description":"Controls if Google Chrome makes the Print as image option default to set when printing PDFs.\r\n\r\nWhen this policy is set to Enabled, Google Chrome will default to setting the Print as image option in the Print Preview when printing a PDF.\r\n\r\nWhen this policy is set to Disabled or not set Google Chrome then the user selection for Print as image option will be initially unset. The user will be allowed to select it for each individual PDFs print job, if the option is available.\r\n\r\nFor Microsoft® Windows® or macOS this policy only has an effect if PrintPdfAsImageAvailability is also enabled.","helpText":"","infoUrls":[],"categoryId":"20ceae56-e189-46ec-a440-791ce7454017","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpdfasimagedefault_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpdfasimagedefault_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended","displayName":"Use System Default Printer as Default","description":"Setting the policy to Enabled means Google Chrome uses the OS default printer as the default destination for print preview.\r\n\r\nSetting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.","helpText":"","infoUrls":[],"categoryId":"20ceae56-e189-46ec-a440-791ce7454017","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_clearsitedataonexit_recommended","displayName":"Clear site data on browser shutdown (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_clearsitedataonexit_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_clearsitedataonexit_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturl_recommended","displayName":"Default search provider instant URL","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturl_recommended_defaultsearchproviderinstanturl","displayName":"Default search provider instant URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended","displayName":"Parameters for instant URL which uses POST","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended_defaultsearchproviderinstanturlpostparams","displayName":"Parameters for instant URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchprovidersearchtermsreplacementkey_recommended","displayName":"Parameter controlling search term placement for the default search provider","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchprovidersearchtermsreplacementkey_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchprovidersearchtermsreplacementkey_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchprovidersearchtermsreplacementkey_recommended_defaultsearchprovidersearchtermsreplacementkey","displayName":"Parameter controlling search term placement for the default search provider (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended","displayName":"Enable network prediction","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_instantenabled_recommended","displayName":"Enable Instant","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_instantenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_instantenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended","displayName":"Safe Browsing Protection Level","description":"Allows you to control whether Google Chrome's Safe Browsing feature is enabled and the mode it operates in.\r\n\r\nIf this policy is set to 'NoProtection' (value 0), Safe Browsing is never active.\r\n\r\nIf this policy is set to 'StandardProtection' (value 1, which is the default), Safe Browsing is always active in the standard mode.\r\n\r\nIf this policy is set to 'EnhancedProtection' (value 2), Safe Browsing is always active in the enhanced mode, which provides better security, but requires sharing more browsing information with Google.\r\n\r\nIf you set this policy as mandatory, users cannot change or override the Safe Browsing setting in Google Chrome.\r\n\r\nIf this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting.\r\n\r\nSee https://developers.google.com/safe-browsing for more info on Safe Browsing.","helpText":"","infoUrls":[],"categoryId":"af351b0c-3d9e-4b18-957b-8179e4eaba15","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_safebrowsingprotectionlevel","displayName":"Safe Browsing Protection Level (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"af351b0c-3d9e-4b18-957b-8179e4eaba15","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_safebrowsingprotectionlevel_0","displayName":"Safe Browsing is never active.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_safebrowsingprotectionlevel_1","displayName":"Safe Browsing is active in the standard mode.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_safebrowsingprotectionlevel_2","displayName":"Safe Browsing is active in the enhanced mode. This mode provides better security, but requires sharing more browsing information with Google.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepageisnewtabpage_recommended","displayName":"Use New Tab Page as homepage","description":"Setting the policy to Enabled makes the New Tab page the user's homepage, ignoring any homepage URL location. Setting the policy to Disabled means that their homepage is never the New Tab page, unless the user's homepage URL is set to chrome://newtab.\r\n\r\nIf you set the policy, users can't change their homepage type in Google Chrome. If not set, the user decides whether or not the New Tab page is their homepage.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepageisnewtabpage_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepageisnewtabpage_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepagelocation_recommended","displayName":"Configure the home page URL","description":"Setting the policy sets the default homepage URL in Google Chrome. You open the homepage using the Home button. On desktop, the RestoreOnStartup policies control the pages that open on startup.\r\n\r\nIf the homepage is set to the New Tab Page, by the user or HomepageIsNewTabPage, this policy has no effect.\r\n\r\n The URL needs a standard scheme, such as http://example.com or https://example.com. When this policy is set, users can't change their homepage URL in Google Chrome.\r\n\r\nLeaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepagelocation_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepagelocation_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepagelocation_recommended_homepagelocation","displayName":"Home page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended","displayName":"Action on startup","description":"Setting the policy lets you specify system behavior on startup. Turning this setting off amounts to leaving it unset as Google Chrome must have specified start up behavior.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users can change it.\r\n\r\nSetting this policy to RestoreOnStartupIsLastSession turns off some settings that rely on sessions or that perform actions on exit, such as clearing browsing data on exit or session-only cookies.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup","displayName":"Action on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_5","displayName":"Open New Tab Page","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended","displayName":"URLs to open on startup","description":"If RestoreOnStartup is set to RestoreOnStartupIsURLs, then setting RestoreOnStartupURLs to a list of URLs specify which URLs open.\r\n\r\nIf not set, the New Tab page opens on start up.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nhttps://example.com\r\nhttps://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_restoreonstartupurlsdesc","displayName":"URLs to open on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_showhomebutton_recommended","displayName":"Show Home button on toolbar","description":"Setting the policy to Enabled shows the Home button on Google Chrome's toolbar. Setting the policy to Disabled keeps the Home button from appearing.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users chooses whether to show the Home button.","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_showhomebutton_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_showhomebutton_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification","displayName":"Notify a user that a browser relaunch or device restart is recommended or required","description":"Notify users that Google Chrome must be relaunched or Google Chrome OS must be restarted to apply a pending update.\r\n\r\nThis policy setting enables notifications to inform the user that a browser relaunch or device restart is recommended or required. If not set, Google Chrome indicates to the user that a relaunch is needed via subtle changes to its menu, while Google Chrome OS indicates such via a notification in the system tray. If set to 'Recommended', a recurring warning will be shown to the user that a relaunch is recommended. The user can dismiss this warning to defer the relaunch. If set to 'Required', a recurring warning will be shown to the user indicating that a browser relaunch will be forced once the notification period passes. The default period is seven days for Google Chrome and four days for Google Chrome OS, and may be configured via the RelaunchNotificationPeriod policy setting.\r\n\r\nThe user's session is restored following the relaunch/restart.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_relaunchnotification","displayName":"Notify a user that a browser relaunch or device restart is recommended or required (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_relaunchnotification_1","displayName":"Show a recurring prompt to the user indicating that a relaunch is recommended","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_relaunchnotification_2","displayName":"Show a recurring prompt to the user indicating that a relaunch is required","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod","displayName":"Set the time period for update notifications","description":"Allows you to set the time period, in milliseconds, over which users are notified that Google Chrome must be relaunched or that a Google Chrome OS device must be restarted to apply a pending update.\r\n\r\nOver this time period, the user will be repeatedly informed of the need for an update. For Google Chrome OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Google Chrome browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the RelaunchNotification policy follow this same schedule.\r\n\r\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod_relaunchnotificationperiod","displayName":"Time period (milliseconds): (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow","displayName":"Set the time interval for relaunch","description":"Specify a target time window for the end of the relaunch notification period.\r\n\r\nUsers are notified of the need for a browser relaunch or device restart based on the RelaunchNotification and RelaunchNotificationPeriod policy settings. Browsers and devices are forcibly restarted at the end of the notification period when the RelaunchNotification policy is set to 'Required'. This RelaunchWindow policy can be used to defer the end of the notification period so that it falls within a specific time window.\r\n\r\nIf this policy is not set, the default target time window for Google Chrome OS is between 2 AM and 4 AM. The default target time window for Google Chrome is the whole day (i.e., the end of the notification period is never deferred).\r\n\r\nNote: Though the policy can accept multiple items in entries, all but the first item are ignored.\r\nWarning: Setting this policy may delay application of software updates.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=RelaunchWindow for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"entries\": [\r\n {\r\n \"start\": {\r\n \"hour\": 2,\r\n \"minute\": 15\r\n },\r\n \"duration_mins\": 240\r\n }\r\n ]\r\n}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow_relaunchwindow","displayName":"Relaunch time window (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_remotedebuggingallowed","displayName":"Allow remote debugging","description":"Controls whether users may use remote debugging.\r\n\r\nIf this policy is set to Enabled or not set, users may use remote debugging by specifying --remote-debugging-port and --remote-debugging-pipe command line switches.\r\n\r\nIf this policy is set to Disabled, users are not allowed to use remote debugging.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_remotedebuggingallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_remotedebuggingallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_renderercodeintegrityenabled","displayName":"Enable Renderer Code Integrity","description":"Setting the policy to Enabled or leaving it unset turns Renderer Code Integrity on.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security and stability as unknown and potentially hostile code can load inside Google Chrome's renderer processes. Only turn off the policy if there are compatibility issues with third-party software that must run inside Google Chrome's renderer processes.\r\n\r\nNote: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_renderercodeintegrityenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_renderercodeintegrityenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_requireonlinerevocationchecksforlocalanchors","displayName":"Require online OCSP/CRL checks for local trust anchors","description":"Setting the policy to True means Google Chrome always performs revocation checking for successfully validated server certificates signed by locally installed CA certificates. If Google Chrome can't get revocation status information, Google Chrome treats these certificates as revoked (hard-fail).\r\n\r\nSetting the policy to False or leaving it unset means Google Chrome uses existing online revocation-checking settings.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_requireonlinerevocationchecksforlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_requireonlinerevocationchecksforlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_restrictsignintopattern","displayName":"Restrict which Google accounts are allowed to be set as browser primary accounts in Google Chrome","description":"Contains a regular expression which is used to determine which Google accounts can be set as browser primary accounts in Google Chrome (i.e. the account that is chosen during the Sync opt-in flow).\r\n\r\nAn appropriate error is displayed if a user tries to set a browser primary account with a username that does not match this pattern.\r\n\r\nIf this policy is left not set or blank, then the user can set any Google account as a browser primary account in Google Chrome.\r\n\r\nExample value: .*@example\\.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_restrictsignintopattern_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_restrictsignintopattern_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_restrictsignintopattern_restrictsignintopattern","displayName":"Restrict which Google accounts are allowed to be set as browser primary accounts in Google Chrome (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation","displayName":"Set the roaming profile directory","description":"Configures the directory that Google Chrome will use for storing the roaming copy of the profiles.\r\n\r\nIf you set this policy, Google Chrome will use the provided directory to store the roaming copy of the profiles if the RoamingProfileSupportEnabled policy has been enabled. If the RoamingProfileSupportEnabled policy is disabled or left unset the value stored in this policy is not used.\r\n\r\nSee https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used.\r\n\r\nOn non-Windows platforms, this policy must be set for roaming profiles to work.\r\n\r\nOn Windows, if this policy is left unset, the default roaming profile path will be used.\r\n\r\nExample value: ${roaming_app_data}\\chrome-profile","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_roamingprofilelocation","displayName":"Set the roaming profile directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilesupportenabled","displayName":"Enable the creation of roaming copies for Google Chrome profile data","description":"If you enable this setting, the settings stored in Google Chrome profiles like bookmarks, autofill data, passwords, etc. will also be written to a file stored in the Roaming user profile folder or a location specified by the Administrator through the RoamingProfileLocation policy. Enabling this policy disables cloud sync.\r\n\r\nIf this policy is disabled or left not set only the regular local profiles will be used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilesupportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilesupportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safebrowsingfortrustedsourcesenabled","displayName":"Enable Safe Browsing for trusted sources","description":"Setting the policy to Enabled or leaving it unset means downloaded files are sent to be analyzed by Safe Browsing, even when it's from a trusted source.\r\n\r\nSetting the policy to Disabled means downloaded files won't be sent to be analyzed by Safe Browsing when it's from a trusted source.\r\n\r\nThese restrictions apply to downloads triggered from webpage content, as well as the Download link menu option. These restrictions don't apply to the save or download of the currently displayed page or to saving as PDF from the printing options.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safebrowsingfortrustedsourcesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safebrowsingfortrustedsourcesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safesitesfilterbehavior","displayName":"Control SafeSites adult content filtering.","description":"Setting the policy controls the SafeSites URL filter, which uses the Google Safe Search API to classify URLs as pornographic or not.\r\n\r\nWhen this policy is set to:\r\n\r\n* Do not filter sites for adult content, or not set, sites aren't filtered\r\n\r\n* Filter top level sites for adult content, pornographic sites are filtered","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safesitesfilterbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safesitesfilterbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safesitesfilterbehavior_safesitesfilterbehavior","displayName":"Control SafeSites adult content filtering. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safesitesfilterbehavior_safesitesfilterbehavior_0","displayName":"Do not filter sites for adult content","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safesitesfilterbehavior_safesitesfilterbehavior_1","displayName":"Filter top level sites (but not embedded iframes) for adult content","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sandboxexternalprotocolblocked","displayName":"Allow Chrome to block navigations toward external protocols in sandboxed iframes","description":"Chrome will block navigations toward external protocols inside\r\nsandboxed iframe. See https://chromestatus.com/features/5680742077038592.\r\n\r\nWhen True, this lets Chrome blocks those navigations.\r\n\r\nWhen False, this prevents Chrome from blocking those navigations.\r\n\r\nThis defaults to True: security feature enabled.\r\n\r\nThis can be used by administrators who need more time to update their internal website affected by this new restriction. This Enterprise policy is temporary; it's intended to be removed after Google Chrome version 104.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sandboxexternalprotocolblocked_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sandboxexternalprotocolblocked_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_savingbrowserhistorydisabled","displayName":"Disable saving browser history","description":"Setting the policy to Enabled means browsing history is not saved, tab syncing is off and users can't change this setting.\r\n\r\nSetting the policy to Disabled or leaving it unset saves browsing history.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_savingbrowserhistorydisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_savingbrowserhistorydisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature allows for hyperlinks and address bar URL navigations to target specific text within a web page, which will be scrolled to once the loading of the web page is complete.\r\n\r\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via URL will be enabled.\r\n\r\nIf you disable this policy, web page scrolling to specific text fragments via URL will be disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_searchsuggestenabled","displayName":"Enable search suggestions","description":"Setting the policy to True turns on search suggestions in Google Chrome's address bar. Setting the policy to False turns off these search suggestions.\r\n\r\nIf you set the policy, users can't change it. If not set, search suggestions are on at first, but users can turn them off any time.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_searchsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_searchsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation","displayName":"URLs/domains automatically permitted direct Security Key attestation","description":"Setting the policy specifies URLs and domains for which no prompt appears when attestation certificates from Security Keys are requested. A signal is also sent to the Security Key indicating that individual attestation may be used. Without this, when sites request attestation of Security Keys, users are prompted in Google Chrome version 65 and later.\r\n\r\nURLs will only match as U2F appIDs. Domains only match as webauthn RP IDs. So to cover both U2F and webauthn APIs, list the appID URL and domain for a given site.\r\n\r\nExample value:\r\n\r\nhttps://example.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation_securitykeypermitattestationdesc","displayName":"URLs/domains automatically permitted direct Security Key attestation (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedarraybufferunrestrictedaccessallowed","displayName":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context","description":"\r\nSpecifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context. Google Chrome will require cross-origin isolation when using SharedArrayBuffers from Google Chrome 91 onward (2021-05-25) for Web Compatibility reasons. Additional details can be found on: https://developer.chrome.com/blog/enabling-shared-array-buffer/.\r\n\r\nWhen set to Enabled, sites can use SharedArrayBuffer with no restrictions.\r\n\r\nWhen set to Disabled or not set, sites can only use SharedArrayBuffers when cross-origin isolated.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedarraybufferunrestrictedaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedarraybufferunrestrictedaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedclipboardenabled","displayName":"Enable the Shared Clipboard Feature","description":"Enable the Shared Clipboard feature which allows users to send text between Chrome Desktops and an Android device when Sync is enabled and the user is Signed-in.\r\n\r\nIf this policy is set to true, the capability of sending text, cross device, for chrome user is enabled.\r\n\r\nIf this policy is set to false, the capability of sending text, cross device, for chrome user is disabled.\r\n\r\nIf you set this policy, users cannot change or override it.\r\n\r\nIf this policy is left unset, the shared clipboard feature is enabled by default.\r\n\r\nIt is up to the admins to set policies in all platforms they care about. It's recommended to set this policy to one value in all platforms.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedclipboardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedclipboardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_showappsshortcutinbookmarkbar","displayName":"Show the apps shortcut in the bookmark bar","description":"Setting the policy to True displays the apps shortcut. Setting the policy to False means this shortcut never appears.\r\n\r\nIf you set the policy, users can't change it. If not set, users decide to show or hide the apps shortcut from the bookmark bar context menu.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_showappsshortcutinbookmarkbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_showappsshortcutinbookmarkbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_showfullurlsinaddressbar","displayName":"Show Full URLs","description":"This feature enables display of the full URL in the address bar.\r\nIf this policy is set to True, then the full URL will be shown in the address bar, including schemes and subdomains.\r\nIf this policy is set to False, then the default URL display will apply.\r\nIf this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_showfullurlsinaddressbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_showfullurlsinaddressbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support","description":"Setting the policy to True or leaving it unset means Google Chrome will accept web contents served as Signed HTTP Exchanges.\r\n\r\nSetting the policy to False prevents Signed HTTP Exchanges from loading.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signedhttpexchangeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signedhttpexchangeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signininterceptionenabled","displayName":"Enable signin interception","description":"This settings enables or disables signin interception.\r\n\r\nWhen this policy not set or is set to True, the signin interception dialog triggers when a Google account is added on the web, and the user may benefit from moving this account to another (new or existing) profile.\r\n\r\nWhen this is set to False, the signin interception dialog does not trigger.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signininterceptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signininterceptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_siteperprocess","displayName":"Require Site Isolation for every site","description":"Since Google Chrome 67, site isolation has been enabled by default on all Desktop platforms, causing every site to run in its own process. A site is a scheme plus eTLD+1 (e.g., https://example.com). Setting this policy to Enabled does not change that behavior; it only prevents users from opting out (for example, using Disable site isolation in chrome://flags). Since Google Chrome 76, setting the policy to Disabled or leaving it unset doesn't turn off site isolation, but instead allows users to opt out.\r\n\r\nIsolateOrigins might also be useful for isolating specific origins at a finer granularity than site (e.g., https://a.example.com).\r\n\r\nOn Google Chrome OS version 76 and earlier, set the DeviceLoginScreenSitePerProcess device policy to the same value. (If the values don't match, a delay can occur when entering a user session.)\r\n\r\nNote: For Android, use the SitePerProcessAndroid policy instead.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_siteperprocess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_siteperprocess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckenabled","displayName":"Enable spellcheck","description":"Setting the policy to Enabled turns spellcheck on, and users can't turn it off. On Microsoft® Windows®, Google Chrome OS and Linux®, spellcheck languages can be switched on or off individually, so users can still turn spellcheck off by switching off every spellcheck language. To avoid that, use the SpellcheckLanguage to force-enable specific spellcheck languages.\r\n\r\nSetting the policy to Disabled turns off spellcheck from all sources, and users can't turn it on. The SpellCheckServiceEnabled, SpellcheckLanguage and SpellcheckLanguageBlocklist policies have no effect when this policy is set to False.\r\n\r\nLeaving the policy unset lets users turn spellcheck on or off in the language settings.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguage","displayName":"Force enable spellcheck languages","description":"Force-enables spellcheck languages. Unrecognized languages in the list will be ignored.\r\n\r\nIf you enable this policy, spellcheck will be enabled for the languages specified, in addition to the languages for which the user has enabled spellcheck.\r\n\r\nIf you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences.\r\n\r\nIf the SpellcheckEnabled policy is set to false, this policy will have no effect.\r\n\r\nIf a language is included in both this policy and the SpellcheckLanguageBlocklist policy, this policy is prioritized and the spellcheck language is enabled.\r\n\r\nThe currently supported languages are: af, bg, ca, cs, da, de, el, en-AU, en-CA, en-GB, en-US, es, es-419, es-AR, es-ES, es-MX, es-US, et, fa, fo, fr, he, hi, hr, hu, id, it, ko, lt, lv, nb, nl, pl, pt-BR, pt-PT, ro, ru, sh, sk, sl, sq, sr, sv, ta, tg, tr, uk, vi.\r\n\r\nExample value:\r\n\r\nfr\r\nes","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguage_spellchecklanguagedesc","displayName":"Force enable spellcheck languages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguageblocklist","displayName":"Force disable spellcheck languages","description":"Force-disables spellcheck languages. Unrecognized languages in that list will be ignored.\r\n\r\nIf you enable this policy, spellcheck will be disabled for the languages specified. The user can still enable or disable spellcheck for languages not in the list.\r\n\r\nIf you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences.\r\n\r\nIf the SpellcheckEnabled policy is set to false, this policy will have no effect.\r\n\r\nIf a language is included in both this policy and the SpellcheckLanguage policy, the latter is prioritized and the spellcheck language will be enabled.\r\n\r\nThe currently supported languages are: af, bg, ca, cs, da, de, el, en-AU, en-CA, en-GB, en-US, es, es-419, es-AR, es-ES, es-MX, es-US, et, fa, fo, fr, he, hi, hr, hu, id, it, ko, lt, lv, nb, nl, pl, pt-BR, pt-PT, ro, ru, sh, sk, sl, sq, sr, sv, ta, tg, tr, uk, vi.\r\n\r\nExample value:\r\n\r\nfr\r\nes","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguageblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguageblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguageblocklist_spellchecklanguageblocklistdesc","displayName":"Force disable spellcheck languages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckserviceenabled","displayName":"Enable or disable spell checking web service","description":"Setting the policy to Enabled puts a Google web service in use to help resolve spelling errors. This policy only controls the use of the online service. Setting the policy to Disabled means this service is never used.\r\n\r\nLeaving the policy unset lets users choose whether to use the spellcheck service.\r\n\r\nThe spell check can always use a downloaded dictionary locally unless the feature is disabled by SpellcheckEnabled in which case this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckserviceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckserviceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowed","displayName":"Allow proceeding from the SSL warning page","description":"Setting the policy to Enabled or leaving it unset lets users click through warning pages Google Chrome shows when users navigate to sites that have SSL errors.\r\n\r\nSetting the policy to Disabled prevent users from clicking through any warning pages.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowedfororigins","displayName":"Allow proceeding from the SSL warning page on specific origins","description":"If SSLErrorOverrideAllowed is Disabled, setting the policy lets you set a list of origin patterns that specify the sites where a user can click through warning pages Google Chrome shows when users navigate to sites that have SSL errors. Users will not be able to click through SSL warning pages on origins that are not on this list.\r\n\r\nIf SSLErrorOverrideAllowed is Enabled or unset, this policy does nothing.\r\n\r\nLeaving the policy unset means SSLErrorOverrideAllowed applies for all sites.\r\n\r\nFor detailed information on valid input patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowedfororigins_sslerroroverrideallowedfororiginsdesc","displayName":"Allow proceeding from the SSL warning page on specific origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin","displayName":"Minimum SSL version enabled","description":"Setting the policy to a valid value means Google Chrome won't use SSL/TLS versions less than the specified version. Unrecognized values are ignored.\r\n\r\nIf this policy is not set, then Google Chrome will show an error for TLS 1.0 and TLS 1.1, but the user will be able to bypass it.\r\n\r\nIf this policy is set to \"tls1.2\", the user will not be able to bypass this error.\r\n\r\nSupport for setting this policy to \"tls1\" or \"tls1.1\" was removed in version 91. Suppressing the TLS 1.0/1.1 warning is no longer supported.\r\n\r\nExample value: tls1.2","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin","displayName":"Minimum SSL version enabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1","displayName":"TLS 1.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1.1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs","displayName":"Suppress JavaScript Dialogs triggered from different origin subframes","description":"As described in https://www.chromestatus.com/feature/5148698084376576 , JavaScript modal dialogs, triggered by window.alert, window.confirm, and window.prompt, will be blocked in Google Chrome if triggered from a subframe whose origin is different from the main frame origin.\r\nThis policy allows overriding that change.\r\nIf the policy is set to enabled or unset, JavaScript dialogs triggered from a different origin subframe will be blocked.\r\nIf the policy is set to disabled, JavaScript dialogs triggered from a different origin subframe will not be blocked.\r\n\r\nThis policy will be removed in Google Chrome version 95.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressunsupportedoswarning","displayName":"Suppress the unsupported OS warning","description":"Setting the policy to Enabled suppresses the warning that appears when Google Chrome is running on an unsupported computer or operating system.\r\n\r\nSetting the policy to Disabled or leaving it unset means the warnings appear on unsupported systems.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressunsupportedoswarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressunsupportedoswarning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_syncdisabled","displayName":"Disable synchronization of data with Google","description":"Setting the policy to Enabled turns off data synchronization in Google Chrome using Google-hosted synchronization services.\r\nTo fully turn off Chrome Sync services, we recommend that you turn off the service in the Google Admin console.\r\n\r\nIf the policy is set to Disabled or not set, users are allowed to choose whether to use Chrome Sync.\r\n\r\nNote: Do not turn on this policy when RoamingProfileSupportEnabled is Enabled, because that feature shares the same client-side functionality. The Google-hosted synchronization is off completely in this case.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_syncdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_syncdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled","displayName":"List of types that should be excluded from synchronization","description":"If this policy is set all specified data types will be excluded from synchronization both for Chrome Sync as well as for roaming profile synchronization. This can be beneficial to reduce the size of the roaming profile or limit the type of data uploaded to the Chrome Sync Servers.\r\n\r\nThe current data types for this policy are: \"bookmarks\", \"readingList\", \"preferences\", \"passwords\", \"autofill\", \"themes\", \"typedUrls\", \"extensions\", \"apps\", \"tabs\", \"wifiConfigurations\". Those names are case sensitive!\r\n\r\nExample value:\r\n\r\nbookmarks","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled_synctypeslistdisableddesc","displayName":"List of types that should be excluded from synchronization (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank","description":"Setting the policy to Disabled allows popups targeting _blank to access (via JavaScript) the page that requested to open the popup.\r\n\r\nSetting the policy to Enabled or leaving it unset causes the window.opener property to be set to null unless the anchor specifies rel=\"opener\".\r\n\r\nThis policy will be removed in Google Chrome version 95.\r\n\r\nSee https://chromestatus.com/feature/6140064063029248.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_taskmanagerendprocessenabled","displayName":"Enable ending processes in Task Manager","description":"Setting the policy to Disabled prevents users from ending processes in the Task Manager.\r\n\r\nSetting the policy to Enabled or leaving it unset lets users end processes in the Task Manager.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_taskmanagerendprocessenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_taskmanagerendprocessenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_thirdpartyblockingenabled","displayName":"Enable third party software injection blocking","description":"Setting the policy to Enabled or leaving it unset prevents third-party software from injecting executable code into Google Chrome's processes.\r\n\r\nSetting the policy to Disabled allows this software to inject such code into Google Chrome's processes.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_thirdpartyblockingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_thirdpartyblockingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_totalmemorylimitmb","displayName":"Set limit on megabytes of memory a single Chrome instance can use.","description":"Configures the amount of memory that a single Google Chrome instance can use before tabs start being discarded (I.E. the memory used by the tab will be freed and the tab will have to be reloaded when switched to) to save memory.\r\n\r\nIf the policy is set, browser will begin to discard tabs to save memory once the limitation is exceeded. However, there is no guarantee that the browser is always running under the limit. Any value under 1024 will be rounded up to 1024.\r\n\r\nIf this policy is not set, the browser will only begin attempts to save memory once it has detected that the amount of physical memory on its machine is low.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_totalmemorylimitmb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_totalmemorylimitmb_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_totalmemorylimitmb_totalmemorylimitmb","displayName":"Set memory limit for Chrome instances: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled","displayName":"Enable Translate","description":"Setting the policy to True provides translation functionality when it's appropriate for users by showing an integrated translate toolbar in Google Chrome and a translate option on the right-click context menu. Setting the policy to False shuts off all built-in translate features.\r\n\r\nIf you set the policy, users can't change this function. Leaving it unset lets them change the setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_u2fsecuritykeyapienabled","displayName":"Allow using the deprecated U2F Security Key API","description":"If set to Enabled, the deprecated U2F Security Key API can be used and the deprecation reminder prompt shown for U2F API requests is suppressed.\r\n\r\nIf the policy is set to Disabled or left unset, the default behavior will apply.\r\n\r\nThe U2F Security Key API is deprecated and it will be disabled by default in Chrome 98.\r\n\r\nThis is a temporary opt-out mechanism. The U2F API will be removed from Chrome in Chrome 104, at which point this policy will cease to be supported.\r\n\r\nFor more information about the deprecation of the U2F Security Key API, please refer to https://groups.google.com/a/chromium.org/g/blink-dev/c/xHC3AtU_65A.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_u2fsecuritykeyapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_u2fsecuritykeyapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist","displayName":"Allow access to a list of URLs","description":"Setting the policy provides access to the listed URLs, as exceptions to URLBlocklist. See that policy's description for the format of entries of this list. For example, setting URLBlocklist to * will block all requests, and you can use this policy to allow access to a limited list of URLs. Use it to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths, using the format specified at ( https://www.chromium.org/administrators/url-blocklist-filter-format ). The most specific filter determines if a URL is blocked or allowed. The URLAllowlist policy takes precedence over URLBlocklist. This policy is limited to 1,000 entries.\r\n\r\nThis policy also allows enabling the automatic invocation by the browser of external application registered as protocol handlers for the listed protocols like \"tel:\" or \"ssh:\".\r\n\r\nLeaving the policy unset allows no exceptions to URLBlocklist.\r\n\r\nFrom Google Chrome version 92, this policy is also supported in the headless mode.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist_urlallowlistdesc","displayName":"Allow access to a list of URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlblocklist","displayName":"Block access to a list of URLs","description":"Setting the policy prevents webpages with prohibited URLs from loading. It provides a list of URL patterns that specify forbidden URLs. Leaving the policy unset means no URLs are prohibited in the browser. Format the URL pattern according to this format ( https://www.chromium.org/administrators/url-blocklist-filter-format ). Up to 1,000 exceptions can be defined in URLAllowlist.\r\n\r\nFrom Google Chrome version 73, you can block javascript://* URLs. However, it affects only JavaScript entered in the address bar (or, for example, bookmarklets). In-page JavaScript URLs with dynamically loaded data aren't subject to this policy. For example, if you block example.com/abc, then example.com can still load example.com/abc using XMLHTTPRequest.\r\n\r\nFrom Google Chrome version 92, this policy is also supported in the headless mode.\r\n\r\nNote: Blocking internal chrome://* URLs can lead to unexpected errors.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlblocklist_urlblocklistdesc","displayName":"Block access to a list of URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlkeyedanonymizeddatacollectionenabled","displayName":"Enable URL-keyed anonymized data collection","description":"Setting the policy to Enabled means URL-keyed anonymized data collection, which sends URLs of pages the user visits to Google to make searches and browsing better, is always active.\r\n\r\nSetting the policy to Disabled results in no URL-keyed anonymized data collection.\r\n\r\nIf you set the policy, users can't change. If not set, then URL-keyed anonymized data collection at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlkeyedanonymizeddatacollectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlkeyedanonymizeddatacollectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir","displayName":"Set user data directory","description":"Configures the directory that Google Chrome will use for storing user data.\r\n\r\nIf you set this policy, Google Chrome will use the provided directory regardless whether the user has specified the '--user-data-dir' flag or not. To avoid data loss or other unexpected errors this policy should not be set to a directory used for other purposes, because Google Chrome manages its contents.\r\n\r\nSee https://support.google.com/chrome/a?p=Supported_directory_variables for a list of variables that can be used.\r\n\r\nIf this policy is left not set the default profile path will be used and the user will be able to override it with the '--user-data-dir' command line flag.\r\n\r\nExample value: ${users}/${user_name}/Chrome","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir_userdatadir","displayName":"Set user data directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit","displayName":"Limits the number of user data snapshots retained for use in case of emergency rollback.","description":"Following each major version update, Chrome will create a snapshot of certain portions of the user's browsing data for use in case of a later emergency version rollback. If an emergency rollback is performed to a version for which a user has a corresponding snapshot, the data in the snapshot is restored. This allows users to retain such settings as bookmarks and autofill data.\r\n\r\nIf this policy is not set, the default value of 3 is used\r\n\r\nIf the policy is set, old snapshots are deleted as needed to respect the limit. If the policy is set to 0, no snapshots will be taken","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit_userdatasnapshotretentionlimit","displayName":"Limits the number of user data snapshots retained for use in case of emergency rollback.: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userfeedbackallowed","displayName":"Allow user feedback","description":"Setting the policy to Enabled or leaving it unset lets users send feedback to Google through Menu > Help > Report an Issue or key combination.\r\n\r\nSetting the policy to Disabled means users can't send feedback to Google.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userfeedbackallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userfeedbackallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowed","displayName":"Allow or deny video capture","description":"Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the VideoCaptureAllowedUrls list, users get prompted for video capture access.\r\n\r\nSetting the policy to Disabled turns off prompts, and video capture is only available to URLs set in the VideoCaptureAllowedUrls list.\r\n\r\nNote: The policy affects all video input (not just the built-in camera).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowedurls","displayName":"URLs that will be granted access to video capture devices without prompt","description":"Setting the policy means you specify the URL list whose patterns get matched to the security origin of the requesting URL. A match grants access to video capture devices without prompt\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com/\r\nhttps://[*.]example.edu/","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowedurls_videocaptureallowedurlsdesc","displayName":"URLs that will be granted access to video capture devices without prompt (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist","displayName":"Configure list of force-installed Web Apps","description":"Setting the policy specifies a list of web apps that install silently, without user interaction, and which users can't uninstall or turn off.\r\n\r\nEach list item of the policy is an object with a mandatory member:\r\nurl (the URL of the web app to install)\r\n\r\nand 5 optional members:\r\n- default_launch_container\r\n(for how the web app opens—a new tab is the default)\r\n\r\n- create_desktop_shortcut\r\n(True if you want to create Linux and\r\nMicrosoft® Windows® desktop shortcuts).\r\n\r\n- fallback_app_name\r\n(Starting with Google Chrome version 90,\r\nallows you to override the app name if it is not a\r\nProgressive Web App (PWA), or the app name that is temporarily\r\ninstalled if it is a PWA but authentication is required before the\r\ninstallation can be completed. If both\r\ncustom_name and\r\nfallback_app_name are provided,\r\nthe latter will be ignored.)\r\n\r\n- custom_name\r\n(Starting with Google Chrome\r\nversion 96, allows you to permanently override the app name for all web\r\napps and PWAs. Currently only supported on\r\nGoogle Chrome OS.)\r\n\r\n- custom_icon\r\n(Starting with Google Chrome\r\nversion 96, allows you to override the app icon of installed apps. The\r\nicons have to be square, maximal 1 MB in size, and in one of the following\r\nformats: jpeg, png, gif, webp, ico. The hash value has to be the SHA256\r\nhash of the icon file. Currently only supported on\r\nGoogle Chrome OS.)\r\n\r\nSee PinnedLauncherApps for pinning apps to the Google Chrome OS shelf.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebAppInstallForceList for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.google.com/maps\",\r\n \"default_launch_container\": \"window\",\r\n \"create_desktop_shortcut\": true\r\n },\r\n {\r\n \"url\": \"https://docs.google.com\",\r\n \"default_launch_container\": \"tab\"\r\n },\r\n {\r\n \"url\": \"https://docs.google.com/editor\",\r\n \"default_launch_container\": \"window\",\r\n \"fallback_app_name\": \"Editor\"\r\n },\r\n {\r\n \"url\": \"https://docs.google.com/sheets\",\r\n \"default_launch_container\": \"window\",\r\n \"custom_name\": \"Spreadsheets\"\r\n },\r\n {\r\n \"url\": \"https://weather.example.com\",\r\n \"custom_icon\": {\r\n \"url\": \"https://mydomain.example.com/sunny_icon.png\",\r\n \"hash\": \"c28f469c450e9ab2b86ea47038d2b324c6ad3b1e9a4bd8960da13214afd0ca38\"\r\n }\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_webappinstallforcelist","displayName":"URLs for Web Apps to be silently installed. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcallowlegacytlsprotocols","displayName":"Allow legacy TLS/DTLS downgrade in WebRTC","description":"If enabled, WebRTC peer connections can downgrade to obsolete\r\nversions of the TLS/DTLS (DTLS 1.0, TLS 1.0 and TLS 1.1) protocols.\r\nWhen this policy is disabled or not set, these TLS/DTLS versions are\r\ndisabled.\r\n\r\nThis policy is temporary and will be removed in a future version\r\nof Google Chrome.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcallowlegacytlsprotocols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcallowlegacytlsprotocols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtceventlogcollectionallowed","displayName":"Allow collection of WebRTC event logs from Google services","description":"Setting the policy to Enabled means Google Chrome can collect WebRTC event logs from Google services such as Hangouts Meet and upload them to Google. These logs have diagnostic information for debugging issues with audio or video meetings in Google Chrome, such as the time and size of RTP packets, feedback about congestion on the network, and metadata about time and quality of audio and video frames. These logs have no audio or video content from the meeting. To make debugging easier, Google might associate these logs, by means of a session ID, with other logs collected by the Google service itself.\r\n\r\nSetting the policy to Disabled results in no collection or uploading of such logs.\r\n\r\nLeaving the policy unset on versions up to and including M76 means Google Chrome defaults to not being able to collect and upload these logs. Starting at M77, Google Chrome defaults to being able to collect and upload these logs from most profiles affected by cloud-based, user-level enterprise policies. From M77 up to and including M80, Google Chrome can also collect and upload these logs by default from profiles affected by Google Chrome on-premise management.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtceventlogcollectionallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtceventlogcollectionallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling","displayName":"The IP handling policy of WebRTC","description":"This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection. See RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2). When unset, defaults to using all available interfaces.\r\n\r\nExample value: default","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling","displayName":"The IP handling policy of WebRTC (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_default","displayName":"WebRTC will use all available interfaces when searching for the best path.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_default_public_and_private_interfaces","displayName":"WebRTC will only use the interface connecting to the public Internet, but may connect using private IP addresses.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_default_public_interface_only","displayName":"WebRTC will only use the interface connecting to the public Internet, and will not connect using private IP addresses.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_disable_non_proxied_udp","displayName":"WebRTC will use TCP on the public-facing interface, and will only use UDP if supported by a configured proxy.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtclocalipsallowedurls","displayName":"URLs for which local IPs are exposed in WebRTC ICE candidates","description":"Patterns in this list will be matched against the security origin of the requesting URL.\r\nIf a match is found or chrome://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, the local IP addresses are shown in WebRTC ICE candidates.\r\nOtherwise, local IP addresses are concealed with mDNS hostnames.\r\nPlease note that this policy weakens the protection of local IPs if needed by administrators.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n*example.com*","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtclocalipsallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtclocalipsallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtclocalipsallowedurls_webrtclocalipsallowedurlsdesc","displayName":"URLs for which local IPs are exposed in WebRTC ICE candidates (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC","description":"If the policy is set, the UDP port range used by WebRTC is restricted to the specified port interval (endpoints included).\r\n\r\nIf the policy is not set, or if it is set to the empty string or an invalid port range, WebRTC is allowed to use any available local UDP port.\r\n\r\nExample value: 10000-11999","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcudpportrange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcudpportrange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcudpportrange_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_websqlinthirdpartycontextenabled","displayName":"Force WebSQL in third-party contexts to be re-enabled.","description":"WebSQL in third-party contexts (e.g., cross-site iframes) is off by default as of M97 and will be fully removed in M101.\r\nIf this policy is set to false or unset, WebSQL in third party contexts will remain off.\r\nIf this policy is set to true, WebSQL in third-party contexts will be re-enabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_websqlinthirdpartycontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_websqlinthirdpartycontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_windowocclusionenabled","displayName":"Enable Window Occlusion","description":"Enables window occlusion in Google Chrome.\r\n\r\nIf you enable this setting, to reduce CPU and power consumption Google Chrome will detect when a window is covered by other windows, and will suspend work painting pixels.\r\n\r\nIf you disable this setting Google Chrome will not detect when a window is covered by other windows.\r\n\r\nIf this policy is left not set, occlusion detection will be enabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_windowocclusionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_windowocclusionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_wpadquickcheckenabled","displayName":"Enable WPAD optimization","description":"Setting the policy to Enabled or leaving it unset turns on WPAD (Web Proxy Auto-Discovery) optimization in Google Chrome.\r\n\r\nSetting the policy to Disabled turns off WPAD optimization, causing Google Chrome to wait longer for DNS-based WPAD servers.\r\n\r\nWhether or not this policy is set, users can't change the WPAD optimization setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_wpadquickcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_wpadquickcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserparameters","displayName":"Command-line parameters for the alternative browser.","description":"Setting the policy to a list of strings means each string is passed to the alternative browser as separate command-line parameters. On Microsoft® Windows®, the parameters are joined with spaces. On macOS and Linux®, a parameter can have spaces and still be treated as a single parameter.\r\n\r\nIf an parameter contains ${url}, ${url} is replaced with the URL of the page to open. If no parameter contains ${url}, the URL is appended at the end of the command line.\r\n\r\nEnvironment variables are expanded. On Microsoft® Windows®, %ABC% is replaced with the value of the ABC environment variable. On macOS and Linux®, ${ABC} is replaced with the value of the ABC environment variable.\r\n\r\nLeaving the policy unset means only the URL is passed as a command-line parameter.\r\n\r\nExample value:\r\n\r\n-foreground\r\n-new-window\r\n${url}\r\n-profile\r\n%HOME%\\browser_profile","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserparameters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserparameters_alternativebrowserparametersdesc","displayName":"Command-line parameters for the alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserpath","displayName":"Alternative browser to launch for configured websites.","description":"Setting the policy controls which command to use to open URLs in an alternative browser. The policy can be set to one of ${ie}, ${firefox}, ${safari}, ${opera}, ${edge} or a file path. When this policy is set to a file path, that file is used as an executable file. ${ie} is only available on Microsoft® Windows®. ${safari} and ${edge} are only available on Microsoft® Windows® and macOS.\r\n\r\nLeaving the policy unset puts a platform-specific default in use: Internet Explorer® for Microsoft® Windows®, or Safari® for macOS. On Linux®, launching an alternative browser will fail.\r\n\r\nExample value: ${ie}","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserpath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserpath_alternativebrowserpath","displayName":"Alternative browser to launch for configured websites. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters","displayName":"Command-line parameters for switching from the alternative browser.","description":"Setting the policy to a list of strings means the strings are joined with spaces and passed from Internet Explorer® to Google Chrome as command-line parameters. If an parameter contains ${url}, ${url} is replaced with the URL of the page to open. If no parameter contains ${url}, the URL is appended at the end of the command line.\r\n\r\nEnvironment variables are expanded. On Microsoft® Windows®, %ABC% is replaced with the value of the ABC environment variable.\r\n\r\nLeaving the policy unset means Internet Explorer® only passes the URL to Google Chrome as a command-line parameter.\r\n\r\nNote: If the Legacy Browser Support add-in for Internet Explorer® isn't installed, this policy has no effect.\r\n\r\nExample value:\r\n\r\n--force-dark-mode","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_browserswitcherchromeparametersdesc","displayName":"Command-line parameters for switching from the alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromepath","displayName":"Path to Chrome for switching from the alternative browser.","description":"This policy controls the command to use to open URLs in Google Chrome when switching from Internet Explorer®. This policy can be set to an executable file path or ${chrome} to autodetect the location of Google Chrome.\r\n\r\nLeaving the policy unset means Internet Explorer® autodetects Google Chrome's own executable path when launching Google Chrome from Internet Explorer.\r\n\r\nNote: If the Legacy Browser Support add-in for Internet Explorer® isn't installed, this policy has no effect.\r\n\r\nExample value: ${chrome}","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromepath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromepath_browserswitcherchromepath","displayName":"Path to Chrome for switching from the alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay","displayName":"Delay before launching alternative browser (milliseconds)","description":"Setting the policy to a number has Google Chrome show a message for that number of milliseconds, then it opens an alternative browser.\r\n\r\nLeaving the policy unset or set to 0 means navigating to a designated URL immediately opens it in an alternative browser.","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay_browserswitcherdelay","displayName":"Delay before launching alternative browser (milliseconds): (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherenabled","displayName":"Enable the Legacy Browser Support feature.","description":"Setting the policy to Enabled means Google Chrome will try to launch some URLs in an alternate browser, such as Internet Explorer®. This feature is set using the policies in the Legacy Browser support group.\r\n\r\nSetting the policy to Disabled or leaving it unset means Google Chrome won't try to launch designated URLs in an alternate browser.","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalgreylisturl","displayName":"URL of an XML file that contains URLs that should never trigger a browser switch.","description":"Setting the policy to a valid URL has Google Chrome download the site list from that URL and apply the rules as if they were set up with the BrowserSwitcherUrlGreylist policy. These policies prevent Google Chrome and the alternative browser from opening one another.\r\n\r\nLeaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for not switching browsers.\r\n\r\nNote: This policy points to an XML file in the same format as Internet Explorer®'s SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer®. Read more on Internet Explorer®'s SiteList policy ( https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode )\r\n\r\nExample value: http://example.com/greylist.xml","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalgreylisturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalgreylisturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalgreylisturl_browserswitcherexternalgreylisturl","displayName":"URL of an XML file that contains URLs that should never trigger a browser switch. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl","displayName":"URL of an XML file that contains URLs to load in an alternative browser.","description":"Setting the policy to a valid URL has Google Chrome download the site list from that URL and apply the rules as if they were set up with the BrowserSwitcherUrlList policy.\r\n\r\nLeaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for switching browsers.\r\n\r\nNote: This policy points to an XML file in the same format as Internet Explorer®'s SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer®. Read more on Internet Explorer®'s SiteList policy ( https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode)\r\n\r\nExample value: http://example.com/sitelist.xml","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl_browserswitcherexternalsitelisturl","displayName":"URL of an XML file that contains URLs to load in an alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherkeeplastchrometab","displayName":"Keep last tab open in Chrome.","description":"Setting the policy to Enabled or leaving it unset has Google Chrome keep at least one tab open, after switching to an alternate browser.\r\n\r\nSetting the policy to Disabled has Google Chrome close the tab after switching to an alternate browser, even if it was the last tab. This causes Google Chrome to exit completely.","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherkeeplastchrometab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherkeeplastchrometab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode","displayName":"Sitelist parsing mode","description":"This policy controls how Google Chrome interprets sitelist/greylist policies for the Legacy Browser Support feature. It affects the following policies: BrowserSwitcherUrlList, BrowserSwitcherUrlGreylist, BrowserSwitcherUseIeSitelist, BrowserSwitcherExternalSitelistUrl, and BrowserSwitcherExternalGreylistUrl.\r\n\r\nIf 'Default' (0) or unset, URL matching is less strict. Rules that do not contain \"/\" look for a substring anywhere in the URL's hostname. Matching the path component of a URL is case-sensitive.\r\n\r\nIf 'IESiteListMode' (1), URL matching is more strict. Rules that do not contain \"/\" only match at the end of the hostname. They must also be at a domain name boundary. Matching the path component of a URL is case-insensitive. This is more compatible with Microsoft® Internet Explorer® and Microsoft® Edge®.\r\n\r\nFor example, with the rules \"example.com\" and \"acme.com/abc\":\r\n\r\n\"http://example.com/\", \"http://subdomain.example.com/\" and \"http://acme.com/abc\" match regardless of parsing mode.\r\n\r\n\"http://notexample.com/\", \"http://example.com.invalid.com/\", \"http://example.comabc/\" only match in 'Default' mode.\r\n\r\n\"http://acme.com/ABC\" only matches in 'IESiteListMode'.","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_browserswitcherparsingmode","displayName":"Sitelist parsing mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_browserswitcherparsingmode_0","displayName":"Default behavior for LBS.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_browserswitcherparsingmode_1","displayName":"More compatible with Microsoft IE/Edge enterprise mode sitelists.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurlgreylist","displayName":"Websites that should never trigger a browser switch.","description":"Setting the policy controls the list of websites that will never cause a browser switch. Each item is treated as a rule. Those rules that match won't open an alternative browser. Unlike the BrowserSwitcherUrlList policy, rules apply to both directions. When the Internet Explorer® add-in is on, it also controls whether Internet Explorer® should open these URLs in Google Chrome.\r\n\r\nLeaving the policy unset adds no websites to the list.\r\n\r\nNote: Elements can also be added to this list through the BrowserSwitcherExternalGreylistUrl policy.\r\n\r\nExample value:\r\n\r\nie.com\r\n!open-in-chrome.ie.com\r\nfoobar.com/ie-only/","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurlgreylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurlgreylist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurlgreylist_browserswitcherurlgreylistdesc","displayName":"Websites that should never trigger a browser switch. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist","displayName":"Websites to open in alternative browser","description":"Setting the policy controls the list of websites to open in an alternative browser. Each item is treated as a rule for something to open in an alternative browser. Google Chrome uses those rules when choosing if a URL should open in an alternative browser. When the Internet Explorer® add-in is on, Internet Explorer® switches back to Google Chrome when the rules don't match. If rules contradict each other, Google Chrome uses the most specific rule.\r\n\r\nLeaving the policy unset adds no websites to the list.\r\n\r\nNote: Elements can also be added to this list through the BrowserSwitcherUseIeSitelist and BrowserSwitcherExternalSitelistUrl policies.\r\n\r\nExample value:\r\n\r\nie.com\r\n!open-in-chrome.ie.com\r\nfoobar.com/ie-only/","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist_browserswitcherurllistdesc","displayName":"Websites to open in alternative browser (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcheruseiesitelist","displayName":"Use Internet Explorer's SiteList policy for Legacy Browser Support.","description":"This policy controls whether to load rules from Internet Explorer®'s SiteList policy.\r\n\r\nWhen this policy is set to true, Google Chrome reads Internet Explorer®'s SiteList to obtain the site list's URL. Google Chrome then downloads the site list from that URL, and applies the rules as if they had been configured with the BrowserSwitcherUrlList policy.\r\n\r\nWhen this policy is false or unset, Google Chrome does not use Internet Explorer®'s SiteList policy as a source of rules for switching browsers.\r\n\r\nFor more information on Internet Explorer's SiteList policy: https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcheruseiesitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcheruseiesitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_autoselectcertificateforurls","displayName":"Automatically select client certificates for these sites","description":"Setting the policy lets you make a list of URL patterns that specify sites for which Chrome can automatically select a client certificate. The value is an array of stringified JSON dictionaries, each with the form { \"pattern\": \"$URL_PATTERN\", \"filter\" : $FILTER }, where $URL_PATTERN is a content setting pattern. $FILTER restricts the client certificates the browser automatically selects from. Independent of the filter, only certificates that match the server's certificate request are selected.\r\n\r\nExamples for the usage of the $FILTER section:\r\n\r\n* When $FILTER is set to { \"ISSUER\": { \"CN\": \"$ISSUER_CN\" } }, only client certificates issued by a certificate with the CommonName $ISSUER_CN are selected.\r\n\r\n* When $FILTER contains both the \"ISSUER\" and the \"SUBJECT\" sections, only client certificates that satisfy both conditions are selected.\r\n\r\n* When $FILTER contains a \"SUBJECT\" section with the \"O\" value, a certificate needs at least one organization matching the specified value to be selected.\r\n\r\n* When $FILTER contains a \"SUBJECT\" section with a \"OU\" value, a certificate needs at least one organizational unit matching the specified value to be selected.\r\n\r\n* When $FILTER is set to {}, the selection of client certificates is not additionally restricted. Note that filters provided by the web server still apply.\r\n\r\nLeaving the policy unset means there's no autoselection for any site.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=AutoSelectCertificateForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\"pattern\":\"https://www.example.com\",\"filter\":{\"ISSUER\":{\"CN\":\"certificate issuer name\", \"L\": \"certificate issuer location\", \"O\": \"certificate issuer org\", \"OU\": \"certificate issuer org unit\"}, \"SUBJECT\":{\"CN\":\"certificate subject name\", \"L\": \"certificate subject location\", \"O\": \"certificate subject org\", \"OU\": \"certificate subject org unit\"}}}","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_autoselectcertificateforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_autoselectcertificateforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_autoselectcertificateforurls_autoselectcertificateforurlsdesc","displayName":"Automatically select client certificates for these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls","displayName":"Allow cookies on these sites","description":"Allows you to set a list of url patterns that specify sites which are allowed to set cookies.\r\n\r\nIf this policy is left not set the global default value will be used for all sites either from the DefaultCookiesSetting policy if it is set, or the user's personal configuration otherwise.\r\n\r\nSee also policies CookiesBlockedForUrls and CookiesSessionOnlyForUrls. Note that there must be no conflicting URL patterns between these three policies - it is unspecified which policy takes precedence.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls_cookiesallowedforurlsdesc","displayName":"Allow cookies on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls","displayName":"Block cookies on these sites","description":"Setting the policy lets you make a list of URL patterns that specify sites that can't set cookies.\r\n\r\nLeaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nWhile no specific policy takes precedence, see CookiesAllowedForUrls and CookiesSessionOnlyForUrls. URL patterns among these 3 policies must not conflict.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls_cookiesblockedforurlsdesc","displayName":"Block cookies on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls","displayName":"Limit cookies from matching URLs to the current session","description":"Unless the RestoreOnStartup policy is set to permanently restore URLs from previous sessions, then setting CookiesSessionOnlyForUrls lets you make a list of URL patterns that specify sites that can and can't set cookies for one session.\r\n\r\nLeaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. URLs not covered by the patterns specified also result in the use of defaults.\r\n\r\nWhile no specific policy takes precedence, see CookiesBlockedForUrls and CookiesAllowedForUrls. URL patterns among these 3 policies must not conflict.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls_cookiessessiononlyforurlsdesc","displayName":"Limit cookies from matching URLs to the current session (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting","displayName":"Default cookies setting","description":"Unless the RestoreOnStartup policy is set to permanently restore URLs from previous sessions, then setting CookiesSessionOnlyForUrls lets you make a list of URL patterns that specify sites that can and can't set cookies for one session.\r\n\r\nLeaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. URLs not covered by the patterns specified also result in the use of defaults.\r\n\r\nWhile no specific policy takes precedence, see CookiesBlockedForUrls and CookiesAllowedForUrls. URL patterns among these 3 policies must not conflict.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_defaultcookiessetting","displayName":"Default cookies setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_defaultcookiessetting_1","displayName":"Allow all sites to set local data","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_defaultcookiessetting_2","displayName":"Do not allow any site to set local data","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_defaultcookiessetting_4","displayName":"Keep cookies for the duration of the session","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading","description":"Setting the policy to 3 lets websites ask for read access to files and directories in the host operating system's file system via the File System API. Setting the policy to 2 denies access.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_2","displayName":"Do not allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_3","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing","description":"Setting the policy to 3 lets websites ask for write access to files and directories in the host operating system's file system. Setting the policy to 2 denies access.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemwriteguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemwriteguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting_2","displayName":"Do not allow any site to request write access to files and directories","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting_3","displayName":"Allow sites to ask the user to grant write access to files and directories","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting","displayName":"Default geolocation setting","description":"Setting the policy to 1 lets sites track the users' physical location as the default state. Setting the policy to 2 denies this tracking by default. You can set the policy to ask whenever a site wants to track the users' physical location.\r\n\r\nLeaving the policy unset means the AskGeolocation policy applies, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting","displayName":"Default geolocation setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting_1","displayName":"Allow sites to track the users' physical location","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting_2","displayName":"Do not allow any site to track the users' physical location","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting_3","displayName":"Ask whenever a site wants to track the users' physical location","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting","displayName":"Default images setting","description":"Setting the policy to 1 lets all websites display images. Setting the policy to 2 denies image display.\r\n\r\nLeaving it unset allows images, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_defaultimagessetting","displayName":"Default images setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_defaultimagessetting_1","displayName":"Allow all sites to show all images","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_defaultimagessetting_2","displayName":"Do not allow any site to show images","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions","description":"Allows you to set whether users can add exceptions to allow mixed content for specific sites.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'InsecureContentAllowedForUrls' and 'InsecureContentBlockedForUrls' policies.\r\n\r\nIf this policy is left not set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_2","displayName":"Do not allow any site to load mixed content","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_3","displayName":"Allow users to add exceptions to allow mixed content","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT","description":"Allows you to set whether Google Chrome will run the v8 JavaScript engine with JIT (Just In Time) compiler enabled or not.\r\n\r\nDisabling the JavaScript JIT will mean that Google Chrome may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Google Chrome to render web content in a more secure configuration.\r\n\r\nThis policy can be overridden for specific URL patterns using the JavaScriptJitAllowedForSites and JavaScriptJitBlockedForSites policies.\r\n\r\nIf this policy is left not set, JavaScript JIT is enabled.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_1","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_2","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting","displayName":"Default JavaScript setting","description":"Setting the policy to 1 lets websites run JavaScript. Setting the policy to 2 denies JavaScript.\r\n\r\nLeaving it unset allows JavaScript, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting","displayName":"Default JavaScript setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_1","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_2","displayName":"Do not allow any site to run JavaScript","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting","displayName":"Default notification setting","description":"Setting the policy to 1 lets websites display desktop notifications. Setting the policy to 2 denies desktop notifications.\r\n\r\nLeaving it unset means AskNotifications applies, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting","displayName":"Default notification setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting_1","displayName":"Allow sites to show desktop notifications","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting_2","displayName":"Do not allow any site to show desktop notifications","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting_3","displayName":"Ask every time a site wants to show desktop notifications","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting","displayName":"Default popups setting","description":"Setting the policy to 1 lets websites display pop-ups. Setting the policy to 2 denies pop-ups.\r\n\r\nLeaving it unset means BlockPopups applies, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_defaultpopupssetting","displayName":"Default popups setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_defaultpopupssetting_1","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_defaultpopupssetting_2","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultsensorssetting","displayName":"Default sensors setting","description":"Setting the policy to 1 lets websites access and use sensors such as motion and light. Setting the policy to 2 denies acess to sensors.\r\n\r\nLeaving it unset means AllowSensors applies, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultsensorssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultsensorssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultsensorssetting_defaultsensorssetting","displayName":"Default sensors setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultsensorssetting_defaultsensorssetting_1","displayName":"Allow sites to access sensors","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultsensorssetting_defaultsensorssetting_2","displayName":"Do not allow any site to access sensors","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultserialguardsetting","displayName":"Control use of the Serial API","description":"Setting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultserialguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultserialguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultserialguardsetting_defaultserialguardsetting","displayName":"Control use of the Serial API (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultserialguardsetting_defaultserialguardsetting_2","displayName":"Do not allow any site to request access to serial ports via the Serial API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultserialguardsetting_defaultserialguardsetting_3","displayName":"Allow sites to ask the user to grant access to a serial port","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API","description":"Setting the policy to 3 lets websites ask for access to nearby Bluetooth devices. Setting the policy to 2 denies access to nearby Bluetooth devices.\r\n\r\nLeaving the policy unset lets sites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_2","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_3","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API","description":"Setting the policy to 3 lets websites ask for access to connected USB devices. Setting the policy to 2 denies access to connected USB devices.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting_2","displayName":"Do not allow any site to request access to USB devices via the WebUSB API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting_3","displayName":"Allow sites to ask the user to grant access to a connected USB device","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadaskforurls","displayName":"Allow read access via the File System API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\r\n\r\nLeaving the policy unset means DefaultFileSystemReadGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns must not conflict with FileSystemReadBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadaskforurls_filesystemreadaskforurlsdesc","displayName":"Allow read access via the File System API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadblockedforurls","displayName":"Block read access via the File System API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\r\n\r\nLeaving the policy unset means DefaultFileSystemReadGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with FileSystemReadAskForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadblockedforurls_filesystemreadblockedforurlsdesc","displayName":"Block read access via the File System API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls","displayName":"Allow write access to files and directories on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nLeaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns must not conflict with FileSystemWriteBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls_filesystemwriteaskforurlsdesc","displayName":"Allow write access to files and directories on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteblockedforurls","displayName":"Block write access to files and directories on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nLeaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with FileSystemWriteAskForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteblockedforurls_filesystemwriteblockedforurlsdesc","displayName":"Block write access to files and directories on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls","displayName":"Allow images on these sites","description":"Setting the policy lets you set a list of URL patterns that specify sites that may display images.\r\n\r\nLeaving the policy unset means DefaultImagesSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nNote that previously this policy was erroneously enabled on Android, but this functionality has never been fully supported on Android.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_imagesallowedforurlsdesc","displayName":"Allow images on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesblockedforurls","displayName":"Block images on these sites","description":"Setting the policy lets you set a list of URL patterns that specify sites that can't display images.\r\n\r\nLeaving the policy unset means DefaultImagesSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\n For detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\n Note that previously this policy was erroneously enabled on Android, but this functionality has never been fully supported on Android.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesblockedforurls_imagesblockedforurlsdesc","displayName":"Block images on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls","displayName":"Allow insecure content on these sites","description":"Allows you to set a list of url patterns that specify sites which are allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled.\r\n\r\nIf this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, and users will be allowed to set exceptions to allow it for specific sites.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls_insecurecontentallowedforurlsdesc","displayName":"Allow insecure content on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls","displayName":"Block insecure content on these sites","description":"Allows you to set a list of url patterns that specify sites which are not allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites), and for which optionally blockable (i.e. passive) mixed content will be upgraded.\r\n\r\nIf this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, but users will be allowed to set exceptions to allow it for specific sites.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_insecurecontentblockedforurlsdesc","displayName":"Block insecure content on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls","displayName":"Allow JavaScript on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can run JavaScript.\r\n\r\nLeaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls_javascriptallowedforurlsdesc","displayName":"Allow JavaScript on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptblockedforurls","displayName":"Block JavaScript on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can't run JavaScript.\r\n\r\nLeaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptblockedforurls_javascriptblockedforurlsdesc","displayName":"Block JavaScript on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT enabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise Javascript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_javascriptjitallowedforsitesdesc","displayName":"Allow JavaScript to use JIT on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites","displayName":"Block JavaScript from using JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are not allowed to run JavaScript JIT (Just In Time) compiler enabled.\r\n\r\nDisabling the JavaScript JIT will mean that Google Chrome may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Google Chrome to render web content in a more secure configuration.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitBlockedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT disabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise JavaScript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites_javascriptjitblockedforsitesdesc","displayName":"Block JavaScript from using JIT on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist","displayName":"Revert to legacy SameSite behavior for cookies on these sites","description":"Cookies set for domains matching these patterns will revert to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute, and skips the scheme comparison when evaluating if two sites are same-site. See https://www.chromium.org/administrators/policy-list-3/cookie-legacy-samesite-policies for full description.\r\n\r\nFor cookies on domains not covered by the patterns specified here, or for all cookies if this policy is not set, the global default value will be the user's personal configuration.\r\n\r\nFor detailed information on valid patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nNote that patterns you list here are treated as domains, not URLs, so you should not specify a scheme or port.\r\n\r\nExample value:\r\n\r\nwww.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_legacysamesitecookiebehaviorenabledfordomainlistdesc","displayName":"Revert to legacy SameSite behavior for cookies on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsallowedforurls","displayName":"Allow notifications on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can display notifications.\r\n\r\nLeaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsallowedforurls_notificationsallowedforurlsdesc","displayName":"Allow notifications on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls","displayName":"Block notifications on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can't display notifications.\r\n\r\nLeaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls_notificationsblockedforurlsdesc","displayName":"Block notifications on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls","displayName":"Allow popups on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can open pop-ups.\r\n\r\nLeaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls_popupsallowedforurlsdesc","displayName":"Allow popups on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsblockedforurls","displayName":"Block popups on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can't open pop-ups.\r\n\r\nLeaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsblockedforurls_popupsblockedforurlsdesc","displayName":"Block popups on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls","displayName":"Allow access to sensors on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can access sensors like motion and light sensors.\r\n\r\nLeaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nIf the same URL pattern exists in both this policy and the SensorsBlockedForUrls policy, the latter is prioritized and access to motion or light sensors will be blocked.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls_sensorsallowedforurlsdesc","displayName":"Allow access to sensors on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls","displayName":"Block access to sensors on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can't access sensors like motion and light sensors.\r\n\r\nLeaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nIf the same URL pattern exists in both this policy and the SensorsAllowedForUrls policy, this policy is prioritized and access to motion or light sensors will be blocked.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls_sensorsblockedforurlsdesc","displayName":"Block access to sensors on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowallportsforurls","displayName":"Automatically grant permission to sites to connect all serial ports.","description":"Setting the policy allows you to list sites which are automatically granted permission to access all available serial ports.\r\n\r\nThe URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered.\r\n\r\nOn Chrome OS, this policy only applies to affiliated users.\r\n\r\nThis policy overrides DefaultSerialGuardSetting, SerialAskForUrls, SerialBlockedForUrls and the user's preferences.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowallportsforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowallportsforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowallportsforurls_serialallowallportsforurlsdesc","displayName":"Automatically grant permission to sites to connect all serial ports. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowusbdevicesforurls","displayName":"Automatically grant permission to sites to connect to USB serial devices.","description":"Setting the policy allows you to list sites which are automatically granted permission to access USB serial devices with vendor and product IDs matching the vendor_id and product_id fields. Omitting the product_id field allows the given sites permission to access devices with a vendor ID matching the vendor_id field and any product ID.\r\n\r\nThe URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered.\r\n\r\nOn Chrome OS, this policy only applies to affiliated users.\r\n\r\nThis policy overrides DefaultSerialGuardSetting, SerialAskForUrls, SerialBlockedForUrls and the user's preferences.\r\n\r\nThis policy only affects access to USB devices through the Web Serial API. To grant access to USB devices through the WebUSB API see the WebUsbAllowDevicesForUrls policy.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=SerialAllowUsbDevicesForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234,\r\n \"product_id\": 5678\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://specific-device.example.com\"\r\n ]\r\n },\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://all-vendor-devices.example.com\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowusbdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowusbdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowusbdevicesforurls_serialallowusbdevicesforurls","displayName":"Automatically grant permission to sites to connect to USB serial devices. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialaskforurls","displayName":"Allow the Serial API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a serial port.\r\n\r\nLeaving the policy unset means DefaultSerialGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns which do not match the policy SerialBlockedForUrls (if there is a match), DefaultSerialGuardSetting (if set), or the users' personal settings take precedence, in that order.\r\n\r\nURL patterns must not conflict with SerialBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialaskforurls_serialaskforurlsdesc","displayName":"Allow the Serial API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialblockedforurls","displayName":"Block the Serial API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a serial port.\r\n\r\nLeaving the policy unset means DefaultSerialGuardSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor URL patterns which do not match the policy SerialAskForUrls (if there is a match), DefaultSerialGuardSetting (if set), or the users' personal settings take precedence, in that order.\r\n\r\nURL patterns can't conflict with SerialAskForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialblockedforurls_serialblockedforurlsdesc","displayName":"Block the Serial API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to USB devices with the given vendor and product IDs.","description":"Setting the policy lets you list the URL patterns that specify which sites are automatically granted permission to access a USB device with the given vendor and product IDs. Each item in the list requires both devices and urls fields for the policy to be valid. Each item in the devices field can have a vendor_id and product_id field. Omitting the vendor_id field will create a policy matching any device. Omitting the product_id field will create a policy matching any device with the given vendor ID. A policy which has a product_id field without a vendor_id field is invalid.\r\n\r\nThe USB permission model will grant the specified URL permission to access the USB device as a top-level origin. If embedded frames need to access USB devices, the 'usb' feature-policy header should be used to grant access. The URL must be valid, otherwise the policy is ignored.\r\n\r\nDeprecated: The USB permission model used to support specifying both the requesting and embedding URLs. This is deprecated and only supported for backwards compatiblity in this manner: if both a requesting and embedding URL is specified, then the embedding URL will be granted the permission as top-level origin and the requsting URL will be ignored entirely.\r\n\r\nThis policy overrides DefaultWebUsbGuardSetting, WebUsbAskForUrls, WebUsbBlockedForUrls and the user's preferences.\r\n\r\nThis policy only affects access to USB devices through the WebUSB API. To grant access to USB devices through the Web Serial API see the SerialAllowUsbDevicesForUrls policy.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebUsbAllowDevicesForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234,\r\n \"product_id\": 5678\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://google.com\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls_webusballowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to USB devices with the given vendor and product IDs. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbaskforurls","displayName":"Allow WebUSB on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a USB device.\r\n\r\nLeaving the policy unset means DefaultWebUsbGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns must not conflict with WebUsbAskForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbaskforurls_webusbaskforurlsdesc","displayName":"Allow WebUSB on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbblockedforurls","displayName":"Block WebUSB on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a USB device.\r\n\r\nLeaving the policy unset means DefaultWebUsbGuardSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nURL patterns can't conflict with WebUsbAskForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbblockedforurls_webusbblockedforurlsdesc","displayName":"Block WebUSB on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls","displayName":"List of alternate URLs for the default search provider","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderAlternateURLs specifies a list of alternate URLs for extracting search terms from the search engine. The URLs should include the string '{searchTerms}'.\r\n\r\nLeaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms.\r\n\r\nExample value:\r\n\r\nhttps://search.my.company/suggest#q={searchTerms}\r\nhttps://search.my.company/suggest/search#q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls_defaultsearchprovideralternateurlsdesc","displayName":"List of alternate URLs for the default search provider (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderenabled","displayName":"Enable the default search provider","description":"Setting the policy to Enabled means a default search is performed when a user enters non-URL text in the address bar. To specify the default search provider, set the rest of the default search policies. If you leave those policies empty, the user can choose the default provider. Setting the policy to Disabled means there's no search when the user enters non-URL text in the address bar.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, the default search provider is on, and users can set the search provider list.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings","displayName":"Default search provider encodings","description":"If DefaultSearchProviderEnabled is on, setting DefaultSearchProviderEncodings specifies the character encodings supported by the search provider. Encodings are code page names such as UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided.\r\n\r\nLeaving DefaultSearchProviderEncodings unset puts UTF-8 in use.\r\n\r\nExample value:\r\n\r\nUTF-8\r\nUTF-16\r\nGB2312\r\nISO-8859-1","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl","displayName":"Default search provider icon","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderIconURL specifies the default search provider's favorite icon URL.\r\n\r\nLeaving DefaultSearchProviderIconURL unset means there's no icon for the search provider.\r\n\r\nExample value: https://search.my.company/favicon.ico","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_defaultsearchprovidericonurl","displayName":"Default search provider icon (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurl","displayName":"Parameter providing search-by-image feature for the default search provider","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURL specifies the URL of the search engine used for image search. (If DefaultSearchProviderImageURLPostParams is set, then image search requests use the POST method instead.)\r\n\r\nLeaving DefaultSearchProviderImageURL unset means no image search is used.\r\n\r\nExample value: https://search.my.company/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurl_defaultsearchproviderimageurl","displayName":"Parameter providing search-by-image feature for the default search provider (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurlpostparams","displayName":"Parameters for image URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURLPostParams specifies the parameters during image search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as {imageThumbnail}, real image thumbnail data replaces it.\r\n\r\nLeaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurlpostparams_defaultsearchproviderimageurlpostparams","displayName":"Parameters for image URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword","displayName":"Default search provider keyword","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider.\r\n\r\nLeaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword_defaultsearchproviderkeyword","displayName":"Default search provider keyword (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername","displayName":"Default search provider name","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name.\r\n\r\nLeaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_defaultsearchprovidername","displayName":"Default search provider name (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl","displayName":"Default search provider new tab page URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderNewTabURL specifies the URL of the search engine used to provide a New Tab page.\r\n\r\nLeaving DefaultSearchProviderNewTabURL unset means no new tab page is provided.\r\n\r\nExample value: https://search.my.company/newtab","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl_defaultsearchprovidernewtaburl","displayName":"Default search provider new tab page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurl","displayName":"Default search provider search URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURL specifies the URL of the search engine used during a default search. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms.\r\n\r\nYou can specify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\r\n\r\nExample value: https://search.my.company/search?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurl_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams","displayName":"Parameters for search URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_defaultsearchprovidersearchurlpostparams","displayName":"Parameters for search URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURL specifies the URL of the search engine to provide search suggestions. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms.\r\n\r\nYou can specify Google's search URL as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nExample value: https://search.my.company/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturlpostparams","displayName":"Parameters for suggest URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURLPostParams specifies the parameters during suggestion search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSuggestURLPostParams unset unset means suggest search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturlpostparams_defaultsearchprovidersuggesturlpostparams","displayName":"Parameters for suggest URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authnegotiatedelegatewhitelist","displayName":"Kerberos delegation server whitelist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: foobar.example.com","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authnegotiatedelegatewhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authnegotiatedelegatewhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authnegotiatedelegatewhitelist_authnegotiatedelegatewhitelist","displayName":"Kerberos delegation server whitelist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authserverwhitelist","displayName":"Authentication server whitelist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: *.example.com,example.com","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authserverwhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authserverwhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authserverwhitelist_authserverwhitelist","displayName":"Authentication server whitelist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autofillenabled","displayName":"Enable AutoFill","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autofillenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autofillenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autoplaywhitelist","displayName":"Allow media autoplay on a whitelist of URL patterns","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autoplaywhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autoplaywhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autoplaywhitelist_autoplaywhitelistdesc","displayName":"Allow media autoplay on a whitelist of URL patterns (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting","displayName":"Default mediastream setting","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_defaultmediastreamsetting","displayName":"Default mediastream setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_defaultmediastreamsetting_2","displayName":"Do not allow any site to access the camera and microphone","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_defaultmediastreamsetting_3","displayName":"Ask every time a site wants to access the camera and/or microphone","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_developertoolsdisabled","displayName":"Disable Developer Tools","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_developertoolsdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_developertoolsdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_disabledschemes","displayName":"Disable URL protocol schemes","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nfile\r\nhttps","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_disabledschemes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_disabledschemes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_disabledschemes_disabledschemesdesc","displayName":"List of disabled protocol schemes (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallblacklist","displayName":"Configure extension installation blacklist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallblacklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallblacklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallblacklist_extensioninstallblacklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist","displayName":"Configure extension installation whitelist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist_extensioninstallwhitelistdesc","displayName":"Extension IDs to exempt from the blacklist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcebrowsersignin","displayName":"Enable force sign in for Google Chrome","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcebrowsersignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcebrowsersignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcesafesearch","displayName":"Force SafeSearch","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcesafesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcesafesearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forceyoutubesafetymode","displayName":"Force YouTube Safety Mode","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forceyoutubesafetymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forceyoutubesafetymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_incognitoenabled","displayName":"Enable Incognito mode","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_incognitoenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_incognitoenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_javascriptenabled","displayName":"Enable JavaScript","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_javascriptenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_javascriptenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist","displayName":"Configure native messaging blocklist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist_nativemessagingblacklistdesc","displayName":"Names of the forbidden native messaging hosts (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingwhitelist","displayName":"Configure native messaging whitelist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingwhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingwhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingwhitelist_nativemessagingwhitelistdesc","displayName":"Names of the native messaging hosts to exempt from the blocklist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativewindowocclusionenabled","displayName":"Enable Native Window Occlusion","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativewindowocclusionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativewindowocclusionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxybypasslist","displayName":"Proxy bypass rules","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: https://www.example1.com,https://www.example2.com,https://internalsite/","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxybypasslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxybypasslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxybypasslist_proxybypasslist","displayName":"Comma-separated list of proxy bypass rules (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode","displayName":"Choose how to specify proxy server settings","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: direct","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode","displayName":"Choose how to specify proxy server settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_direct","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_auto_detect","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_pac_script","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_fixed_servers","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_system","displayName":"Use system proxy settings","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxypacurl","displayName":"URL to a proxy .pac file","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: https://internal.site/example.pac","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxypacurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxypacurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxypacurl_proxypacurl","displayName":"URL to a proxy .pac file (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyserver","displayName":"Address or URL of proxy server","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: 123.123.123.123:8080","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyserver_proxyserver","displayName":"Address or URL of proxy server (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode","displayName":"Choose how to specify proxy server settings","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_proxyservermode","displayName":"Choose how to specify proxy server settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_proxyservermode_0","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_proxyservermode_1","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_proxyservermode_2","displayName":"Manually specify proxy settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_proxyservermode_3","displayName":"Use system proxy settings","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostclientdomain","displayName":"Configure the required domain name for remote access clients","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: my-awesome-domain.com","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostclientdomain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostclientdomain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostclientdomain_remoteaccesshostclientdomain","displayName":"Configure the required domain name for remote access clients (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostdomain","displayName":"Configure the required domain name for remote access hosts","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: my-awesome-domain.com","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostdomain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostdomain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostdomain_remoteaccesshostdomain","displayName":"Configure the required domain name for remote access hosts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled","displayName":"Enable Safe Browsing","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingwhitelistdomains","displayName":"Configure the list of domains on which Safe Browsing will not trigger warnings.","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingwhitelistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingwhitelistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingwhitelistdomains_safebrowsingwhitelistdomainsdesc","displayName":"Configure the list of domains on which Safe Browsing will not trigger warnings. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_signinallowed","displayName":"Allow sign in to Google Chrome","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_signinallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_signinallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_spellchecklanguageblacklist","displayName":"Force disable spellcheck languages","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nfr\r\nes","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_spellchecklanguageblacklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_spellchecklanguageblacklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_spellchecklanguageblacklist_spellchecklanguageblacklistdesc","displayName":"Force disable spellcheck languages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_strictermixedcontenttreatmentenabled","displayName":"Enable stricter treatment for mixed content","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_strictermixedcontenttreatmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_strictermixedcontenttreatmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttp://testserver.example.com/\r\n*.example.org","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_unsafelytreatinsecureoriginassecuredesc","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlblacklist","displayName":"Block access to a list of URLs","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlblacklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlblacklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlblacklist_urlblacklistdesc","displayName":"Block access to a list of URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist","displayName":"Allow access to a list of URLs","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist_urlwhitelistdesc","displayName":"Allow access to a list of URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_blockexternalextensions","displayName":"Blocks external extensions from being installed","description":"Controls external extensions installation.\r\n\r\nEnabling this setting blocks external extensions from being installed.\r\n\r\nDisabling this setting or leaving it unset allows external extensions to be installed.\r\n\r\nExternal extensions and their installation are documented at https://developer.chrome.com/apps/external_extensions.\r\n","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_blockexternalextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_blockexternalextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionallowedtypes","displayName":"Configure allowed app/extension types","description":"Setting the policy controls which apps and extensions may be installed in Google Chrome, which hosts they can interact with, and limits runtime access.\r\n\r\nLeaving the policy unset results in no restrictions on the acceptable extension and app types.\r\n\r\nExtensions and apps which have a type that's not on the list won't be installed. Each value should be one of these strings:\r\n\r\n* \"extension\"\r\n\r\n* \"theme\"\r\n\r\n* \"user_script\"\r\n\r\n* \"hosted_app\"\r\n\r\n* \"legacy_packaged_app\"\r\n\r\n* \"platform_app\"\r\n\r\nSee the Google Chrome extensions documentation for more information on these types.\r\n\r\nVersions earlier than 75 that use multiple comma separated extension IDs aren't supported and are skipped. The rest of the policy applies.\r\n\r\nNote: This policy also affects extensions and apps to be force-installed using ExtensionInstallForcelist.\r\n\r\nExample value:\r\n\r\nhosted_app","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionallowedtypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionallowedtypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionallowedtypes_extensionallowedtypesdesc","displayName":"Types of extensions/apps that are allowed to be installed (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist","displayName":"Configure extension installation allow list","description":"Setting the policy specifies which extensions are not subject to the blocklist.\r\n\r\nA blocklist value of * means all extensions are blocked and users can only install extensions listed in the allow list.\r\n\r\nBy default, all extensions are allowed. But, if you prohibited extensions by policy, use the list of allowed extensions to change that policy.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_extensioninstallallowlistdesc","displayName":"Extension IDs to exempt from the blocklist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallblocklist","displayName":"Configure extension installation blocklist","description":"Allows you to specify which extensions the users can NOT install. Extensions already installed will be disabled if blocked, without a way for the user to enable them. Once an extension disabled due to the blocklist is removed from it, it will automatically get re-enabled.\r\n\r\nA blocklist value of '*' means all extensions are blocked unless they are explicitly listed in the allowlist.\r\n\r\nIf this policy is left not set the user can install any extension in Google Chrome.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallblocklist_extensioninstallblocklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist","displayName":"Configure the list of force-installed apps and extensions","description":"Setting the policy specifies a list of apps and extensions that install silently, without user interaction, and which users can't uninstall or turn off. Permissions are granted implicitly, including for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These 2 APIs aren't available to apps and extensions that aren't force-installed.)\r\n\r\nLeaving the policy unset means no apps or extensions are autoinstalled, and users can uninstall any app or extension in Google Chrome.\r\n\r\nThis policy superseeds ExtensionInstallBlocklist policy. If a previously force-installed app or extension is removed from this list, Google Chrome automatically uninstalls it.\r\n\r\nOn Microsoft® Windows® instances, apps and extensions from outside the Chrome Web Store can only be forced installed if the instance is joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management.\r\n\r\nOn macOS instances, apps and extensions from outside the Chrome Web Store can only be force installed if the instance is managed via MDM, or joined to a domain via MCX.\r\n\r\nThe source code of any extension may be altered by users through developer tools, potentially rendering the extension dysfunctional. If this is a concern, set the DeveloperToolsDisabled policy.\r\n\r\nEach list item of the policy is a string that contains an extension ID and, optionally, an \"update\" URL separated by a semicolon (;). The extension ID is the 32-letter string found, for example, on chrome://extensions when in Developer mode. If specified, the \"update\" URL should point to an Update Manifest XML document ( https://developer.chrome.com/extensions/autoupdate ). By default, the Chrome Web Store's update URL is used. The \"update\" URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL in the extension's manifest.\r\n\r\n Note: This policy doesn't apply to Incognito mode. Read about hosting extensions ( https://developer.chrome.com/extensions/hosting ).\r\n\r\nExample value:\r\n\r\naaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa;https://clients2.google.com/service/update2/crx\r\nabcdefghijklmnopabcdefghijklmnop","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist_extensioninstallforcelistdesc","displayName":"Extension/App IDs and update URLs to be silently installed (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources","displayName":"Configure extension, app, and user script install sources","description":"Setting the policy specifies which URLs may install extensions, apps, and themes. Before Google Chrome 21, users could click on a link to a *.crx file, and Google Chrome would offer to install the file after a few warnings. Afterwards, such files must be downloaded and dragged to the Google Chrome settings page. This setting allows specific URLs to have the old, easier installation flow.\r\n\r\nEach item in this list is an extension-style match pattern (see https://developer.chrome.com/extensions/match_patterns). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (the referrer) must be allowed by these patterns.\r\n\r\nExtensionInstallBlocklist takes precedence over this policy. That is, an extension on the blocklist won't be installed, even if it happens from a site on this list.\r\n\r\nExample value:\r\n\r\nhttps://corp.mycompany.com/*","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_extensioninstallsourcesdesc","displayName":"URL patterns to allow extension, app, and user script installs from (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings","displayName":"Extension management settings","description":"Setting the policy controls extension management settings for Google Chrome, including any controlled by existing extension-related policies. The policy supersedes any legacy policies that might be set.\r\n\r\nThis policy maps an extension ID or an update URL to its specific setting only. A default configuration can be set for the special ID \"*\", which applies to all extensions without a custom configuration in this policy. With an update URL, configuration applies to extensions with the exact update URL stated in the extension manifest ( http://support.google.com/chrome/a?p=Configure_ExtensionSettings_policy ). If the 'override_update_url' flag is set to true, the extension is installed and updated using the \"update\" URL specified in the ExtensionInstallForcelist policy or in 'update_url' field in this policy. The flag 'override_update_url' is ignored if the 'update_url' is a Chrome Web Store url.\r\n\r\nNote: For Windows® instances not joined to a Microsoft® Active Directory® domain, forced installation is limited to apps and extensions listed in the Chrome Web Store.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ExtensionSettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"abcdefghijklmnopabcdefghijklmnop\": {\r\n \"installation_mode\": \"allowed\",\r\n \"blocked_permissions\": [\r\n \"history\"\r\n ],\r\n \"minimum_version_required\": \"1.0.1\",\r\n \"toolbar_pin\": \"force_pinned\"\r\n },\r\n \"bcdefghijklmnopabcdefghijklmnopa\": {\r\n \"installation_mode\": \"force_installed\",\r\n \"update_url\": \"https://example.com/update_url\",\r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ],\r\n \"runtime_blocked_hosts\": [\r\n \"*://*.example.com\"\r\n ],\r\n \"runtime_allowed_hosts\": [\r\n \"*://good.example.com\"\r\n ]\r\n },\r\n \"cdefghijklmnopabcdefghijklmnopab\": {\r\n \"installation_mode\": \"blocked\",\r\n \"blocked_install_message\": \"Custom error message.\"\r\n },\r\n \"defghijklmnopabcdefghijklmnopabc,efghijklmnopabcdefghijklmnopabcd\": {\r\n \"installation_mode\": \"blocked\",\r\n \"blocked_install_message\": \"Custom error message.\"\r\n },\r\n \"update_url:https://www.example.com/update.xml\": {\r\n \"blocked_permissions\": [\r\n \"wallpaper\"\r\n ],\r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ],\r\n \"installation_mode\": \"allowed\"\r\n },\r\n \"fghijklmnopabcdefghijklmnopabcde\": {\r\n \"installation_mode\": \"removed\",\r\n \"blocked_install_message\": \"Custom removal message.\"\r\n },\r\n \"ghijklmnopabcdefghijklmnopabcdef\": {\r\n \"installation_mode\": \"force_installed\",\r\n \"update_url\": \"https://example.com/update_url\",\r\n \"override_update_url\": true\r\n },\r\n \"*\": {\r\n \"installation_mode\": \"blocked\",\r\n \"blocked_permissions\": [\r\n \"downloads\",\r\n \"bookmarks\"\r\n ],\r\n \"install_sources\": [\r\n \"https://company-intranet/chromeapps\"\r\n ],\r\n \"allowed_types\": [\r\n \"hosted_app\"\r\n ],\r\n \"runtime_blocked_hosts\": [\r\n \"*://*.example.com\"\r\n ],\r\n \"runtime_allowed_hosts\": [\r\n \"*://good.example.com\"\r\n ],\r\n \"blocked_install_message\": \"Custom error message.\"\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings_extensionsettings","displayName":"Extension management settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_enablemediarouter","displayName":"Enable Google Cast","description":"Setting the policy to Enabled or leaving it unset turns on Google Cast, which users can launch from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.\r\n\r\nSetting the policy to Disabled turns off Google Cast.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_enablemediarouter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_enablemediarouter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_showcasticonintoolbar","displayName":"Show the Google Cast toolbar icon","description":"Setting the policy to Enabled displays the Cast toolbar icon on the toolbar or the overflow menu, and users can't remove it.\r\n\r\nSetting the policy to Disabled or leaving it unset lets users pin or remove the icon through its contextual menu.\r\n\r\nIf the policy EnableMediaRouter is set to Disabled, then this policy's value has no effect, and the toolbar icon doesn't appear.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_showcasticonintoolbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_showcasticonintoolbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_allowcrossoriginauthprompt","displayName":"Cross-origin HTTP Authentication prompts","description":"Setting the policy to Enabled allows third-party images on a page to show an authentication prompt.\r\n\r\n Setting the policy to Disabled or leaving it unset renders third-party images unable to show an authentication prompt.\r\n\r\nTypically, this policy is Disabled as a phishing defense.","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_allowcrossoriginauthprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_allowcrossoriginauthprompt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authnegotiatedelegateallowlist","displayName":"Kerberos delegation server allowlist","description":"Setting the policy assigns servers that Google Chrome may delegate to. Separate multiple server names with commas. Wildcards, *, are allowed.\r\n\r\nLeaving the policy unset means Google Chrome won't delegate user credentials, even if a server is detected as intranet.\r\n\r\nExample value: foobar.example.com","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authnegotiatedelegateallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authnegotiatedelegateallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authnegotiatedelegateallowlist_authnegotiatedelegateallowlist","displayName":"Kerberos delegation server allowlist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes","displayName":"Supported authentication schemes","description":"Setting the policy specifies which HTTP authentication schemes Google Chrome supports.\r\n\r\nLeaving the policy unset employs all 4 schemes.\r\n\r\nValid values:\r\n\r\n* basic\r\n\r\n* digest\r\n\r\n* ntlm\r\n\r\n* negotiate\r\n\r\nNote: Separate multiple values with commas.\r\n\r\nExample value: basic,digest,ntlm,negotiate","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes_authschemes","displayName":"Supported authentication schemes (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist","displayName":"Authentication server allowlist","description":"Setting the policy specifies which servers should be allowed for integrated authentication. Integrated authentication is only on when Google Chrome gets an authentication challenge from a proxy or from a server in this permitted list.\r\n\r\nLeaving the policy unset means Google Chrome tries to detect if a server is on the intranet. Only then will it respond to IWA requests. If a server is detected as internet, then Google Chrome ignores IWA requests from it.\r\n\r\nNote: Separate multiple server names with commas. Wildcards, *, are allowed.\r\n\r\nExample value: *.example.com,example.com","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist_authserverallowlist","displayName":"Authentication server allowlist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_basicauthoverhttpenabled","displayName":"Allow Basic authentication for HTTP","description":"Setting the policy to Enabled or leaving it unset will allow Basic authentication challenges received over non-secure HTTP.\r\n\r\nSetting the policy to Disabled forbids non-secure HTTP requests from using the Basic authentication scheme; only secure HTTPS is allowed.\r\n\r\nThis policy setting is ignored (and Basic is always forbidden) if the AuthSchemes policy is set and does not include Basic.","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_basicauthoverhttpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_basicauthoverhttpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_disableauthnegotiatecnamelookup","displayName":"Disable CNAME lookup when negotiating Kerberos authentication","description":"Setting the policy to Enabled skips CNAME lookup. The server name is used as entered when generating the Kerberos SPN.\r\n\r\nSetting the policy to Disabled or leaving it unset means CNAME lookup determines the canonical name of the server when generating the Kerberos SPN.","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_disableauthnegotiatecnamelookup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_disableauthnegotiatecnamelookup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_enableauthnegotiateport","displayName":"Include non-standard port in Kerberos SPN","description":"Setting the policy to Enabled and entering a nonstandard port (in other words, a port other than 80 or 443) includes it in the generated Kerberos SPN.\r\n\r\nSetting the policy to Disabled or leaving it unset means the generated Kerberos SPN won't include a port.","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_enableauthnegotiateport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_enableauthnegotiateport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingallowlist","displayName":"Configure native messaging allowlist","description":"Setting the policy specifies which native messaging hosts aren't subject to the deny list. A deny list value of * means all native messaging hosts are denied, unless they're explicitly allowed.\r\n\r\nAll native messaging hosts are allowed by default. But, if all native messaging hosts are denied by policy, the admin can use the allow list to change that policy.\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingallowlist_nativemessagingallowlistdesc","displayName":"Names of the native messaging hosts to exempt from the blocklist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingblocklist","displayName":"Configure native messaging blocklist","description":"Setting the policy specifies which native messaging hosts shouldn't be loaded. A deny list value of * means all native messaging hosts are denied, unless they're explicitly allowed.\r\n\r\nLeaving the policy unset means Google Chrome loads all installed native messaging hosts.\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingblocklist_nativemessagingblocklistdesc","displayName":"Names of the forbidden native messaging hosts (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessaginguserlevelhosts","displayName":"Allow user-level Native Messaging hosts (installed without admin permissions)","description":"Setting the policy to Enabled or leaving it unset means Google Chrome can use native messaging hosts installed at the user level.\r\n\r\nSetting the policy to Disabled means Google Chrome can only use these hosts if installed at the system level.","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessaginguserlevelhosts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessaginguserlevelhosts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~other_promptonmultiplematchingcertificates","displayName":"Prompt for the client certificate when multiple certificates match.","description":"This policy controls whether the user is prompted to select a client certificate when more than one certificate matches AutoSelectCertificateForUrls.\r\nIf this policy is set to Enabled, the user is prompted to select a client certificate whenever the auto-selection policy matches multiple certificates.\r\nIf this policy is set to Disabled or not set, the user may only be prompted when no certificate matches the auto-selection.","helpText":"","infoUrls":[],"categoryId":"b46f4e70-d3d1-4177-8e22-62f806d4568c","categoryName":"Other","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~other_promptonmultiplematchingcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~other_promptonmultiplematchingcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordleakdetectionenabled","displayName":"Enable leak detection for entered credentials","description":"Setting the policy to Enabled lets users have Google Chrome check whether usernames and passwords entered were part of a leak.\r\n\r\nIf the policy is set, users can't change it in Google Chrome. If not set, credential leak checking is allowed, but the user can turn it off.\r\n\r\nThis behavior will not trigger if Safe Browsing is disabled (either by policy or by the user). In order to force Safe Browsing on, use the SafeBrowsingEnabled policy or the SafeBrowsingProtectionLevel policy.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordleakdetectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordleakdetectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordmanagerenabled","displayName":"Enable saving passwords to the password manager","description":"Setting the policy to Enabled means users have Google Chrome remember passwords and provide them the next time they sign in to a site.\r\n\r\nSetting the policy to Disabled means users can't save new passwords, but previously saved passwords will still work.\r\n\r\nIf the policy is set, users can't change it in Google Chrome. If not set, the user can turn off password saving.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordmanagerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordmanagerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled","displayName":"Enable Google Cloud Print proxy","description":"Setting the policy to Enabled or leaving it unset lets Google Chrome act as a proxy between Google Cloud Print and legacy printers connected to the machine. Using their Google Account, users may turn on the cloud print proxy by authentication.\r\n\r\nSetting the policy to Disabled means users can't turn on the proxy, and the machine can't share its printers with Google Cloud Print.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintsubmitenabled","displayName":"Enable submission of documents to Google Cloud Print","description":"Setting the policy to Enabled or leaving it unset lets users print to Google Cloud Print from the Google Chrome print dialog. Google Chrome can submit documents to Google Cloud Print for printing. This doesn't prevent users from submitting print jobs on websites.\r\n\r\nSetting the policy to Disabled means users can't print to Google Cloud Print from the Google Chrome print dialog.\r\n\r\nIn order to keep Google Cloud Print destinations discoverable, this policy must be set to Enabled and cloud must not be included in the PrinterTypeDenyList policy.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintsubmitenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintsubmitenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection","displayName":"Default printer selection rules","description":"Setting the policy sets the rules for selecting the default printer in Google Chrome, overriding the default rules. Printer selection occurs the first time users try to print, when Google Chrome seeks a printer matching the specified attributes. In case of a less than perfect match, Google Chrome can be set to select any matching printer, depending on the order printers are discovered.\r\n\r\nLeaving the policy unset or set to attributes for which there's no match means the built-in PDF printer is the default. If there's no PDF printer, Google Chrome defaults to none.\r\n\r\nPrinters connected to Google Cloud Print are considered \"cloud\", the rest of the printers are classified as \"local\".\r\n\r\nNote: Omitting a field means all values match. For example, not specifying connectivity causes Print Preview to start discovery of all kinds of printers, \"local\" and \"cloud\". Regular expression patterns must follow the JavaScript RegExp syntax, and matches are case sensistive.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=DefaultPrinterSelection for more information about schema and formatting.\r\n\r\n\r\nExample value: { \"kind\": \"cloud\", \"idPattern\": \".*public\", \"namePattern\": \".*Color\" }","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection_defaultprinterselection","displayName":"Default printer selection rules (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_disableprintpreview","displayName":"Disable Print Preview","description":"Setting the policy to Enabled has Google Chrome open the system print dialog instead of the built-in print preview when users request a printout.\r\n\r\nSetting the policy to Disabled or leaving it unset has print commands trigger the print preview screen.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_disableprintpreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_disableprintpreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist","displayName":"Disable printer types on the deny list","description":"The printers of types placed on the deny list will be disabled from being discovered or having their capabilities fetched.\r\n\r\nPlacing all printer types on the deny list effectively disables printing, as there would be no available destinations to send a document for printing.\r\n\r\nIncluding cloud on the deny list has the same effect as setting the CloudPrintSubmitEnabled policy to false. In order to keep Google Cloud Print destinations discoverable, the CloudPrintSubmitEnabled policy must be set to true and cloud must not be on the deny list.\r\n\r\nIf the policy is not set, or is set to an empty list, all printer types will be available for discovery.\r\n\r\nExtension printers are also known as print provider destinations, and include any destination that belongs to a Google Chrome extension.\r\n\r\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\r\n\r\nExample value:\r\n\r\ncloud\r\nprivet","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist_printertypedenylistdesc","displayName":"Disable printer types on the deny list (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter","displayName":"Print Headers and Footers","description":"Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview.\r\n\r\nIf you set the policy, users can't change it. If unset, users decides whether headers and footers appear.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode","description":"Restricts background graphics printing mode. Unset policy is treated as no restriction.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_any","displayName":"Allow printing both with and without background graphics","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_enabled","displayName":"Allow printing only with background graphics","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_disabled","displayName":"Allow printing only without background graphics","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode","description":"Overrides default background graphics printing mode.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_enabled","displayName":"Enable background graphics printing mode by default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_disabled","displayName":"Disable background graphics printing mode by default","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingenabled","displayName":"Enable printing","description":"Setting the policy to Enabled or leaving it unset lets users print in Google Chrome, and users can't change this setting.\r\n\r\nSetting the policy to Disabled means users can't print from Google Chrome. Printing is off in the three dots menu, extensions, and JavaScript applications.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault","displayName":"Default printing page size","description":"Overrides default printing page size.\r\n\r\nname should contain one of the listed formats or 'custom' if required paper size is not in the list. If 'custom' value is provided custom_size property should be specified. It describes the desired height and width in micrometers. Otherwise custom_size property shouldn't be specified. Policy that violates these rules is ignored.\r\n\r\nIf the page size is unavailable on the printer chosen by the user this policy is ignored.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=PrintingPaperSizeDefault for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"name\": \"custom\",\r\n \"custom_size\": {\r\n \"width\": 210000,\r\n \"height\": 297000\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault_printingpapersizedefault","displayName":"Default printing page size (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpdfasimageavailability","displayName":"Print PDF as Image Available","description":"Controls how Google Chrome makes the Print as image option available on Microsoft® Windows® and macOS when printing PDFs.\r\n\r\nWhen printing a PDF on Microsoft® Windows® or macOS, sometimes print jobs need to be rasterized to an image for certain printers to get correct looking output.\r\n\r\nWhen this policy is set to Enabled, Google Chrome will make the Print as image option available in the Print Preview when printing a PDF.\r\n\r\nWhen this policy is set to Disabled or not set Google Chrome the Print as image option will not be available to users in Print Preview and PDFs will be printed as usual without being rasterized to an image before being sent to the destination.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpdfasimageavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpdfasimageavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode","displayName":"Print PostScript Mode","description":"Controls how Google Chrome prints on Microsoft® Windows®.\r\n\r\nWhen printing to a PostScript printer on Microsoft® Windows® different PostScript generation methods can affect printing performance.\r\n\r\nWhen this policy is set to Default, Google Chrome will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts.\r\n\r\nWhen this policy is set to Type42, Google Chrome will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\r\n\r\nWhen this policy is not set, Google Chrome will be in Default mode.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode","displayName":"Print PostScript Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode_0","displayName":"Default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode_1","displayName":"Type42","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpreviewusesystemdefaultprinter","displayName":"Use System Default Printer as Default","description":"Setting the policy to Enabled means Google Chrome uses the OS default printer as the default destination for print preview.\r\n\r\nSetting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpreviewusesystemdefaultprinter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpreviewusesystemdefaultprinter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode","displayName":"Print Rasterization Mode","description":"Controls how Google Chrome prints on Microsoft® Windows®.\r\n\r\nWhen printing to a non-PostScript printer on Microsoft® Windows®, sometimes print jobs need to be rasterized to print correctly.\r\n\r\nWhen this policy is set to Full, Google Chrome will do full page rasterization if necessary.\r\n\r\nWhen this policy is set to Fast, Google Chrome will avoid rasterization if possible, reducing the amount of rasterization can help reduce print job sizes and increase printing speed.\r\n\r\nWhen this policy is not set, Google Chrome will be in Full mode.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_printrasterizationmode","displayName":"Print Rasterization Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_printrasterizationmode_0","displayName":"Full","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_printrasterizationmode_1","displayName":"Fast","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI","description":"Controls print image resolution when Google Chrome prints PDFs with rasterization.\r\n\r\nWhen printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution will significantly increase the processing and printing time while a low resolution can lead to poor imaging quality.\r\n\r\nThis policy allows a particular resolution to be specified for use when rasterizing PDFs for printing.\r\n\r\nIf this policy is set to zero or not set at all then the system default resolution will be used during rasterization of page images.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizepdfdpi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizepdfdpi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizepdfdpi_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowclientpairing","displayName":"Enable or disable PIN-less authentication for remote access hosts","description":"Setting the policy to Enabled or leaving it unset lets users pair clients and hosts at connection time, eliminating the need to enter a PIN every time.\r\n\r\nSetting the policy to Disabled makes this feature unavailable.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowclientpairing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowclientpairing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer","displayName":"Allow remote access users to transfer files to/from the host","description":"Setting the policy to Enabled or leaving it unset allows users connected to a remote access host to transfer files between the client and the host. This doesn't apply to remote assistance connections, which don't support file transfer.\r\n\r\nSetting the policy to Disabled disallows file transfer.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowrelayedconnection","displayName":"Enable the use of relay servers by the remote access host","description":"If RemoteAccessHostFirewallTraversal is set to Enabled, setting RemoteAccessHostAllowRelayedConnection to Enabled or leaving it unset allows the use of remote clients to use relay servers to connect to this machine when a direct connection is not available, for example, because of firewall restrictions.\r\n\r\nSetting the policy to Disabled doesn't turn remote access off, but only allows connections from the same network (not NAT traversal or relay).","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowrelayedconnection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowrelayedconnection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowremoteaccessconnections","displayName":"Allow remote access connections to this machine","description":"If this policy is Disabled, the remote access host service cannot be started or configured to accept incoming connections. This policy does not affect remote support scenarios.\r\n\r\nThis policy has no effect if it is set to Enabled, left empty, or is not set.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowremoteaccessconnections_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowremoteaccessconnections_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowremotesupportconnections","displayName":"Allow remote support connections to this machine","description":"If this policy is disabled, the remote support host cannot be started or configured to accept incoming connections.\r\n\r\nThis policy does not affect remote access scenarios.\r\n\r\nThis policy does not prevent enterprise admins from connecting to managed Chrome OS devices.\r\n\r\nThis policy has no effect if enabled, left empty, or is not set.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowremotesupportconnections_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowremotesupportconnections_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowuiaccessforremoteassistance","displayName":"Allow remote users to interact with elevated windows in remote assistance sessions","description":"Setting the policy to Enabled means the remote assistance host runs in a process with uiAccess permissions. This lets remote users interact with elevated windows on the local user's desktop.\r\n\r\nSetting the policy to Disabled or leaving it unset means the remote assistance host runs in the user's context, and remote users can't interact with elevated windows on the desktop.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowuiaccessforremoteassistance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowuiaccessforremoteassistance_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist","displayName":"Configure the required domain names for remote access clients","description":"Setting the policy specifies the client domain names that are imposed on remote access clients, and users can't change them. Only clients from one of the specified domains can connect to the host.\r\n\r\nSetting the policy to an empty list or leaving it unset applies the default policy for the connection type. For remote assistance, this allows clients from any domain to connect to the host. For anytime remote access, only the host owner can connect.\r\n\r\nSee also RemoteAccessHostDomainList.\r\n\r\nNote: This setting overrides RemoteAccessHostClientDomain, if present.\r\n\r\nExample value:\r\n\r\nmy-awesome-domain.com\r\nmy-auxiliary-domain.com","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist_remoteaccesshostclientdomainlistdesc","displayName":"Configure the required domain names for remote access clients (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes","displayName":"The maximum size, in bytes, that can be transferred between client and host via clipboard synchronization","description":"If this policy is set, clipboard data sent to and from the host will be truncated to the limit set by this policy.\r\n\r\nIf a value of 0 is set, then clipboard sync is disabled.\r\n\r\nThis policy affects both remote access and remote support scenarios.\r\n\r\nThis policy has no effect if it is not set.\r\n\r\nSetting the policy to a value that is not within the min/max range may prevent the host from starting.\r\n\r\nPlease note that the actual upper bound for the clipboard size is based on the maximum WebRTC data channel message size which this policy does not control.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes_remoteaccesshostclipboardsizebytes","displayName":"The maximum size, in bytes, that can be transferred between client and host via clipboard synchronization: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostdomainlist","displayName":"Configure the required domain names for remote access hosts","description":"Setting the policy specifies the host domain names that are imposed on remote access hosts, and users can't change them. Hosts can be shared only using accounts registered on one of the specified domain names.\r\n\r\nSetting the policy to an empty list or leaving it unset means hosts can be shared using any account.\r\n\r\nSee also RemoteAccessHostClientDomainList.\r\n\r\nNote: This setting will override RemoteAccessHostDomain, if present.\r\n\r\nExample value:\r\n\r\nmy-awesome-domain.com\r\nmy-auxiliary-domain.com","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostdomainlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostdomainlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostdomainlist_remoteaccesshostdomainlistdesc","displayName":"Configure the required domain names for remote access hosts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostfirewalltraversal","displayName":"Enable firewall traversal from remote access host","description":"Setting the policy to Enabled or leaving it unset allows the usage of STUN servers, letting remote clients discover and connect to this machine, even if separated by a firewall.\r\n\r\nSetting the policy to Disabled when outgoing UDP connections are filtered by the firewall means the machine only allows connections from client machines within the local network.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostfirewalltraversal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostfirewalltraversal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes","displayName":"Maximum session duration allowed for remote access connections","description":"If this policy is set, remote access connections will automatically disconnect after the number of minutes defined in the policy have elapsed. This does not prevent the client from reconnecting after the maximum session duration has been reached. Setting the policy to a value that is not within the min/max range may prevent the host from starting. This policy does not affect remote support scenarios.\r\n\r\nThis policy has no effect if it is not set. In this case, remote access connections will have no maximum duration on this machine.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes_remoteaccesshostmaximumsessiondurationminutes","displayName":"Maximum session duration allowed for remote access connections: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostrequirecurtain","displayName":"Enable curtaining of remote access hosts","description":"Setting the policy to Enabled turns off remote access hosts' physical input and output devices during a remote connection.\r\n\r\nSetting the policy to Disabled or leaving it unset lets both local and remote users interact with the host while it's shared.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostrequirecurtain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostrequirecurtain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostudpportrange","displayName":"Restrict the UDP port range used by the remote access host","description":"Setting the policy restricts the UDP port range used by the remote access host in this machine.\r\n\r\nLeaving the policy unset or set to an empty string means the remote access host can use any available port.\r\n\r\nNote: If RemoteAccessHostFirewallTraversal is Disabled, the remote access host will use UDP ports in the 12400-12409 range.\r\n\r\nExample value: 12400-12409","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostudpportrange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostudpportrange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostudpportrange_remoteaccesshostudpportrange","displayName":"Restrict the UDP port range used by the remote access host (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_additionallaunchparameters","displayName":"Additional command line parameters for Google Chrome","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_additionallaunchparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_additionallaunchparameters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_additionallaunchparameters_additionallaunchparameters","displayName":"Additional command line parameters for Google Chrome (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled","displayName":"Enable sending downloads to Google for deep scanning for users enrolled in the Advanced Protection program","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowoutdatedplugins","displayName":"Allow running plugins that are outdated","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowoutdatedplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowoutdatedplugins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowpopupsduringpageunload","displayName":"Allows a page to show popups during its unloading","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowpopupsduringpageunload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowpopupsduringpageunload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_alwaysauthorizeplugins","displayName":"Always runs plugins that require authorization (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_alwaysauthorizeplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_alwaysauthorizeplugins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_appcacheforceenabled","displayName":"Allows the AppCache feature to be re-enabled even if it is off by default.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_appcacheforceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_appcacheforceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframecontenttypes","displayName":"Allow Google Chrome Frame to handle the listed content types","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframecontenttypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframecontenttypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframecontenttypes_chromeframecontenttypesdesc","displayName":"Allow Google Chrome Frame to handle the listed content types (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings","displayName":"Default HTML renderer for Google Chrome Frame","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_chromeframerenderersettings","displayName":"Default HTML renderer for Google Chrome Frame (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_chromeframerenderersettings_0","displayName":"Use the host browser by default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_chromeframerenderersettings_1","displayName":"Use Google Chrome Frame by default","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_clearsitedataonexit","displayName":"Clear site data on browser shutdown (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_clearsitedataonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_clearsitedataonexit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_cloudprintwarningssuppressed","displayName":"Suppress Google Cloud Print deprecation messages","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_cloudprintwarningssuppressed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_cloudprintwarningssuppressed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corslegacymodeenabled","displayName":"Use the legacy CORS implementation rather than new CORS","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corslegacymodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corslegacymodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist","displayName":"Enable CORS check mitigations in the new CORS implementation","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_corsmitigationlistdesc","displayName":"Enable CORS check mitigations in the new CORS implementation (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting","displayName":"Control use of the File Handling API","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_defaultfilehandlingguardsetting","displayName":"Control use of the File Handling API (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_defaultfilehandlingguardsetting_2","displayName":"Do not allow any web app to access file types via the File Handling API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_defaultfilehandlingguardsetting_3","displayName":"Allow web apps to ask the user to grant access to file types via the File Handling API","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting","displayName":"Default key generation setting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_defaultkeygensetting","displayName":"Default key generation setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_defaultkeygensetting_1","displayName":"Allow all sites to use key generation","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_defaultkeygensetting_2","displayName":"Do not allow any site to use key generation","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting","displayName":"Default Flash setting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting","displayName":"Default Flash setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting_1","displayName":"Allow all sites to automatically run the Flash plugin","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting_2","displayName":"Block the Flash plugin","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting_3","displayName":"Click to play","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl","displayName":"Default search provider instant URL","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_defaultsearchproviderinstanturl","displayName":"Default search provider instant URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturlpostparams","displayName":"Parameters for instant URL which uses POST","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturlpostparams_defaultsearchproviderinstanturlpostparams","displayName":"Parameters for instant URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey","displayName":"Parameter controlling search term placement for the default search provider","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_defaultsearchprovidersearchtermsreplacementkey","displayName":"Parameter controlling search term placement for the default search provider (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_dheenabled","displayName":"Enable DHE cipher suites in TLS","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_dheenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_dheenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins","displayName":"Specify a list of disabled plugins","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins_disabledpluginsdesc","displayName":"List of disabled plugins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledpluginsexceptions","displayName":"Specify a list of plugins that the user can enable or disable","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledpluginsexceptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledpluginsexceptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledpluginsexceptions_disabledpluginsexceptionsdesc","displayName":"List of exceptions to the list of disabled plugins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablepluginfinder","displayName":"Specify whether the plugin finder should be disabled (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablepluginfinder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablepluginfinder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablespdy","displayName":"Disable SPDY protocol","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablespdy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablespdy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablesslrecordsplitting","displayName":"Disable TLS False Start","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablesslrecordsplitting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablesslrecordsplitting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_dnsprefetchingenabled","displayName":"Enable network prediction","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_dnsprefetchingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_dnsprefetchingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablecommonnamefallbackforlocalanchors","displayName":"Allow certificates issued by local trust anchors without subjectAlternativeName extension","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablecommonnamefallbackforlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablecommonnamefallbackforlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedprivetprinting","displayName":"Enable deprecated privet printing","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedprivetprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedprivetprinting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebbasedsignin","displayName":"Enable the old web-based signin flow","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebbasedsignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebbasedsignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebplatformfeatures","displayName":"Enable deprecated web platform features for a limited time","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebplatformfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebplatformfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebplatformfeatures_enabledeprecatedwebplatformfeaturesdesc","displayName":"Enable deprecated web platform features for a limited time (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledplugins","displayName":"Specify a list of enabled plugins","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledplugins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledplugins_enabledpluginsdesc","displayName":"List of enabled plugins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesha1forlocalanchors","displayName":"Allow SHA-1 signed certificates issued by local trust anchors","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesha1forlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesha1forlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesymanteclegacyinfrastructure","displayName":"Enable trust in Symantec Corporation's Legacy PKI Infrastructure","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesymanteclegacyinfrastructure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesymanteclegacyinfrastructure_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename","displayName":"Enterprise web store name (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_enterprisewebstorename","displayName":"Enterprise web store name (deprecated) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl","displayName":"Enterprise web store URL (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl_enterprisewebstoreurl","displayName":"Enterprise web store URL (deprecated) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_extensionallowinsecureupdates","displayName":"Allow insecure algorithms in integrity checks on extension updates and installs","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_extensionallowinsecureupdates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_extensionallowinsecureupdates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls","displayName":"Allow the File Handling API on these web apps","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_filehandlingallowedforurlsdesc","displayName":"Allow the File Handling API on these web apps (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingblockedforurls","displayName":"Block the File Handling API on these web apps","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingblockedforurls_filehandlingblockedforurlsdesc","displayName":"Block the File Handling API on these web apps (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcelegacydefaultreferrerpolicy","displayName":"Use a default referrer policy of no-referrer-when-downgrade.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcelegacydefaultreferrerpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcelegacydefaultreferrerpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcenetworkinprocess","displayName":"Force networking code to run in the browser process","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcenetworkinprocess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcenetworkinprocess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_gcfuserdatadir","displayName":"Set Google Chrome Frame user data directory","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_gcfuserdatadir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_gcfuserdatadir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_gcfuserdatadir_gcfuserdatadir","displayName":"Set user data directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_hidewebstorepromo","displayName":"Prevent app promotions from appearing on the new tab page","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_hidewebstorepromo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_hidewebstorepromo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_http09onnondefaultportsenabled","displayName":"Enable HTTP/0.9 support on non-default ports","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_http09onnondefaultportsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_http09onnondefaultportsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_instantenabled","displayName":"Enable Instant","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_instantenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_instantenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenallowedforurls","displayName":"Allow key generation on these sites","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenallowedforurls_keygenallowedforurlsdesc","displayName":"Allow key generation on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls","displayName":"Block key generation on these sites","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_keygenblockedforurlsdesc","displayName":"Block key generation on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled","displayName":"Default legacy SameSite cookie behavior setting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled","displayName":"Default legacy SameSite cookie behavior setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_1","displayName":"Revert to legacy SameSite behavior for cookies on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_2","displayName":"Use SameSite-by-default behavior for cookies on all sites","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_localdiscoveryenabled","displayName":"Enable chrome://devices","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_localdiscoveryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_localdiscoveryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_machinelevelusercloudpolicyenrollmenttoken","displayName":"The enrollment token of cloud policy on desktop","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_machinelevelusercloudpolicyenrollmenttoken_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_machinelevelusercloudpolicyenrollmenttoken_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_machinelevelusercloudpolicyenrollmenttoken_machinelevelusercloudpolicyenrollmenttoken","displayName":"The enrollment token of cloud policy on desktop (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize","displayName":"Set media disk cache size in bytes","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_mediacachesize","displayName":"Set media disk cache size: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pachttpsurlstrippingenabled","displayName":"Enable PAC URL stripping (for https://)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pachttpsurlstrippingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pachttpsurlstrippingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_passwordmanagerallowshowpasswords","displayName":"Allow users to show passwords in Password Manager (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_passwordmanagerallowshowpasswords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_passwordmanagerallowshowpasswords_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls","displayName":"Allow the Flash plugin on these sites","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls_pluginsallowedforurlsdesc","displayName":"Allow the Flash plugin on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsblockedforurls","displayName":"Block the Flash plugin on these sites","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsblockedforurls_pluginsblockedforurlsdesc","displayName":"Block the Flash plugin on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled","displayName":"Enable RC4 cipher suites in TLS","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccessclientfirewalltraversal","displayName":"Enable firewall traversal from remote access client","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccessclientfirewalltraversal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccessclientfirewalltraversal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies","displayName":"Policy overrides for Debug builds of the remote access host","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies_remoteaccesshostdebugoverridepolicies","displayName":"Policy overrides for Debug builds of the remote access host (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostrequiretwofactor","displayName":"Enable two-factor authentication for remote access hosts","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostrequiretwofactor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostrequiretwofactor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshosttalkgadgetprefix","displayName":"Configure the TalkGadget prefix for remote access hosts","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshosttalkgadgetprefix_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshosttalkgadgetprefix_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshosttalkgadgetprefix_remoteaccesshosttalkgadgetprefix","displayName":"Configure the TalkGadget prefix for remote access hosts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinchromeframelist","displayName":"Always render the following URL patterns in Google Chrome Frame","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinchromeframelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinchromeframelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinchromeframelist_renderinchromeframelistdesc","displayName":"Always render the following URL patterns in Google Chrome Frame (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist","displayName":"Always render the following URL patterns in the host browser","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist_renderinhostlistdesc","displayName":"Always render the following URL patterns in the host browser (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_runallflashinallowmode","displayName":"Extend Flash content setting to all content (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_runallflashinallowmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_runallflashinallowmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_safebrowsingextendedreportingoptinallowed","displayName":"Allow users to opt in to Safe Browsing extended reporting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_safebrowsingextendedreportingoptinallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_safebrowsingextendedreportingoptinallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_skipmetadatacheck","displayName":"Skip the meta tag check in Google Chrome Frame","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_skipmetadatacheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_skipmetadatacheck_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin","displayName":"Minimum TLS version to fallback to","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_sslversionfallbackmin","displayName":"Minimum TLS version to fallback to (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_sslversionfallbackmin_tls1.1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_sslversionfallbackmin_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax","displayName":"Maximum SSL version enabled","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_sslversionmax","displayName":"Maximum SSL version enabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_sslversionmax_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_sslversionmax_tls1.3","displayName":"TLS 1.3","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_supervisedusercreationenabled","displayName":"Enable creation of supervised users","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_supervisedusercreationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_supervisedusercreationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_suppresschromeframeturndownprompt","displayName":"Suppress the Google Chrome Frame turndown prompt","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_suppresschromeframeturndownprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_suppresschromeframeturndownprompt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled","displayName":"Allow background tabs freeze","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabunderallowed","displayName":"Allow sites to simultaneously navigate and open pop-ups","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabunderallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabunderallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tls13hardeningforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tls13hardeningforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tripledesenabled","displayName":"Enable 3DES cipher suites in TLS","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tripledesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tripledesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_uselegacyformcontrols","displayName":"Use Legacy Form Controls until M84.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_uselegacyformcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_uselegacyformcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_useragentclienthintsenabled","displayName":"Control the User-Agent Client Hints feature.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_useragentclienthintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_useragentclienthintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webdriveroverridesincompatiblepolicies","displayName":"Allow WebDriver to Override Incompatible Policies","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webdriveroverridesincompatiblepolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webdriveroverridesincompatiblepolicies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_welcomepageonosupgradeenabled","displayName":"Enable showing the welcome page on the first browser launch following OS upgrade","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_welcomepageonosupgradeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_welcomepageonosupgradeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL.","description":"Setting the policy sets the URL for users to change their password after seeing a warning in the browser. The password protection service sends users to the URL (HTTP and HTTPS protocols only) you designate through this policy. For Google Chrome to correctly capture the salted hash of the new password on this change password page, make sure your change password page follows these guidelines ( https://www.chromium.org/developers/design-documents/create-amazing-password-forms ).\r\n\r\nTurning the policy off or leaving it unset means the service sends users to https://myaccount.google.com to change their password.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://mydomain.com/change_password.html","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionchangepasswordurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionchangepasswordurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionchangepasswordurl_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls","displayName":"Configure the list of enterprise login URLs where password protection service should capture salted hashes of passwords.","description":"Setting the policy sets the list of enterprise login URLs (HTTP and HTTPS protocols only). Password protection service will capture salted hashes of passwords on these URLs and use them for password reuse detection. For Google Chrome to correctly capture password salted hashes, ensure your sign-in pages follow these guidelines ( https://www.chromium.org/developers/design-documents/create-amazing-password-forms ).\r\n\r\nTurning this setting off or leaving it unset means the password protection service only captures the password salted hashes on https://accounts.google.com.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nhttps://mydomain.com/login.html\r\nhttps://login.mydomain.com","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls_passwordprotectionloginurlsdesc","displayName":"Configure the list of enterprise login URLs where password protection service should capture salted hashes of passwords. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger","displayName":"Password protection warning trigger","description":"Setting the policy lets you control the triggering of password protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites.\r\n\r\nUse PasswordProtectionLoginURLs and PasswordProtectionChangePasswordURL to set which password to protect.\r\n\r\nIf this policy is set to:\r\n\r\n* PasswordProtectionWarningOff, no password protection warning will be shown.\r\n\r\n* PasswordProtectionWarningOnPasswordReuse, password protection warning will be shown when the user reuses their protected password on a non-allowed site.\r\n\r\n* PasswordProtectionWarningOnPhishingReuse, password protection warning will be shown when the user reuses their protected password on a phishing site.\r\n\r\nLeaving the policy unset has the password protection service only protect Google passwords, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger","displayName":"Password protection warning trigger (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger_0","displayName":"Password protection warning is off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger_1","displayName":"Password protection warning is triggered by password reuse","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger_2","displayName":"Password protection warning is triggered by password reuse on phishing page","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains","displayName":"Configure the list of domains on which Safe Browsing will not trigger warnings.","description":"Setting the policy to Enabled means Safe Browsing will trust the domains you designate. It won't check them for dangerous resources such as phishing, malware, or unwanted software. Safe Browsing's download protection service won't check downloads hosted on these domains. Its password protection service won't check for password reuse.\r\n\r\nLeaving the policy unset means default Safe Browsing protection applies to all resources.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains_safebrowsingallowlistdomainsdesc","displayName":"Configure the list of domains on which Safe Browsing will not trigger warnings. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingextendedreportingenabled","displayName":"Enable Safe Browsing Extended Reporting","description":"Setting the policy to Enabled turns on Google Chrome's Safe Browsing Extended Reporting, which sends some system information and page content to Google servers to help detect dangerous apps and sites.\r\n\r\nSetting the policy to Disabled means reports are never sent.\r\n\r\nIf you set this policy, users can't change it. If not set, users can decide whether to send reports or not.\r\n\r\nSee more about Safe Browsing ( https://developers.google.com/safe-browsing ).","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingextendedreportingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingextendedreportingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel","displayName":"Safe Browsing Protection Level","description":"Allows you to control whether Google Chrome's Safe Browsing feature is enabled and the mode it operates in.\r\n\r\nIf this policy is set to 'NoProtection' (value 0), Safe Browsing is never active.\r\n\r\nIf this policy is set to 'StandardProtection' (value 1, which is the default), Safe Browsing is always active in the standard mode.\r\n\r\nIf this policy is set to 'EnhancedProtection' (value 2), Safe Browsing is always active in the enhanced mode, which provides better security, but requires sharing more browsing information with Google.\r\n\r\nIf you set this policy as mandatory, users cannot change or override the Safe Browsing setting in Google Chrome.\r\n\r\nIf this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting.\r\n\r\nSee https://developers.google.com/safe-browsing for more info on Safe Browsing.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel_safebrowsingprotectionlevel","displayName":"Safe Browsing Protection Level (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel_safebrowsingprotectionlevel_0","displayName":"Safe Browsing is never active.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel_safebrowsingprotectionlevel_1","displayName":"Safe Browsing is active in the standard mode.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel_safebrowsingprotectionlevel_2","displayName":"Safe Browsing is active in the enhanced mode. This mode provides better security, but requires sharing more browsing information with Google.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins","displayName":"Allow Same Origin Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this level of capture.\r\n\r\nNote that windowed Chrome Apps with the same origin as this site will still be allowed to be captured.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: TabCaptureAllowedByOrigins, WindowCaptureAllowedByOrigins, ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins_sameorigintabcaptureallowedbyoriginsdesc","displayName":"Allow Same Origin Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowed","displayName":"Allow or deny screen capture","description":"If enabled or not configured (default), a Web page can use\r\nscreen-share APIs (e.g., getDisplayMedia() or the Desktop Capture extension API)\r\nto prompt the user to select a tab, window or desktop to capture.\r\n\r\nWhen this policy is disabled, any calls to screen-share APIs will fail\r\nwith an error; however this policy is not considered (and a site will be\r\nallowed to use screen-share APIs) if the site matches an origin pattern in\r\nany of the following policies:\r\nScreenCaptureAllowedByOrigins,\r\nWindowCaptureAllowedByOrigins,\r\nTabCaptureAllowedByOrigins,\r\nSameOriginTabCaptureAllowedByOrigins.\r\n","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowedbyorigins","displayName":"Allow Desktop, Window, and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this level of Capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in any of the following policies: WindowCaptureAllowedByOrigins, TabCaptureAllowedByOrigins, SameOriginTabCaptureAllowedByOrigins.\r\n\r\nIf a site matches a URL pattern in this policy, the ScreenCaptureAllowed will not be considered.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowedbyorigins_screencaptureallowedbyoriginsdesc","displayName":"Allow Desktop, Window, and Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_tabcaptureallowedbyorigins","displayName":"Allow Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this level of capture.\r\n\r\nNote that windowed Chrome Apps will still be allowed to be captured.\r\n\r\nThis policy is not considered if a site matches a URL pattern in the SameOriginTabCaptureAllowedByOrigins policy.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: WindowCaptureAllowedByOrigins, ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_tabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_tabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_tabcaptureallowedbyorigins_tabcaptureallowedbyoriginsdesc","displayName":"Allow Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_windowcaptureallowedbyorigins","displayName":"Allow Window and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Window and Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this level of Capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in any of the following policies: TabCaptureAllowedByOrigins, SameOriginTabCaptureAllowedByOrigins.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_windowcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_windowcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_windowcaptureallowedbyorigins_windowcaptureallowedbyoriginsdesc","displayName":"Allow Window and Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepageisnewtabpage","displayName":"Use New Tab Page as homepage","description":"Setting the policy to Enabled makes the New Tab page the user's homepage, ignoring any homepage URL location. Setting the policy to Disabled means that their homepage is never the New Tab page, unless the user's homepage URL is set to chrome://newtab.\r\n\r\nIf you set the policy, users can't change their homepage type in Google Chrome. If not set, the user decides whether or not the New Tab page is their homepage.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepageisnewtabpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepageisnewtabpage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation","displayName":"Configure the home page URL","description":"Setting the policy sets the default homepage URL in Google Chrome. You open the homepage using the Home button. On desktop, the RestoreOnStartup policies control the pages that open on startup.\r\n\r\nIf the homepage is set to the New Tab Page, by the user or HomepageIsNewTabPage, this policy has no effect.\r\n\r\n The URL needs a standard scheme, such as http://example.com or https://example.com. When this policy is set, users can't change their homepage URL in Google Chrome.\r\n\r\nLeaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_homepagelocation","displayName":"Home page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation","displayName":"Configure the New Tab page URL","description":"Setting the policy configures the default New Tab page URL and prevents users from changing it.\r\n\r\nThe New Tab page opens with new tabs and windows.\r\n\r\nThis policy doesn't decide which pages open on start up. Those are controlled by the RestoreOnStartup policies. This policy does affect the homepage, if that's set to open the New Tab page, as well as the startup page if it's set to open the New Tab page.\r\n\r\nIt is a best practice to provide fully canonicalized URL, if the URL is not fully canonicalized Google Chrome will default to https://.\r\n\r\nLeaving the policy unset or empty puts the default New Tab page in use.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation_newtabpagelocation","displayName":"New Tab page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup","displayName":"Action on startup","description":"Setting the policy lets you specify system behavior on startup. Turning this setting off amounts to leaving it unset as Google Chrome must have specified start up behavior.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users can change it.\r\n\r\nSetting this policy to RestoreOnStartupIsLastSession turns off some settings that rely on sessions or that perform actions on exit, such as clearing browsing data on exit or session-only cookies.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup","displayName":"Action on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup_5","displayName":"Open New Tab Page","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartupurls","displayName":"URLs to open on startup","description":"If RestoreOnStartup is set to RestoreOnStartupIsURLs, then setting RestoreOnStartupURLs to a list of URLs specify which URLs open.\r\n\r\nIf not set, the New Tab page opens on start up.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nhttps://example.com\r\nhttps://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartupurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartupurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartupurls_restoreonstartupurlsdesc","displayName":"URLs to open on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_showhomebutton","displayName":"Show Home button on toolbar","description":"Setting the policy to Enabled shows the Home button on Google Chrome's toolbar. Setting the policy to Disabled keeps the Home button from appearing.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users chooses whether to show the Home button.","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_showhomebutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_showhomebutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowbackforwardcacheforcachecontrolnostorepageenabled","displayName":"Allow pages with Cache-Control: no-store header to enter back/forward cache","description":"This policy controls if a page with Cache-Control: no-store header can be stored in back/forward cache. The website setting this header may not expect the page to be restored from back/forward cache since some sensitive information could still be displayed after the restoration even if it is no longer accessible.\r\n\r\nIf the policy is enabled or unset, the page with Cache-Control: no-store header might be restored from back/forward cache unless the cache eviction is triggered (e.g. when there is HTTP-only cookie change to the site).\r\n\r\nIf the policy is disabled, the page with Cache-Control: no-store header will not be stored in back/forward cache.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowbackforwardcacheforcachecontrolnostorepageenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowbackforwardcacheforcachecontrolnostorepageenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowwebauthnwithbrokentlscerts","displayName":"Allow Web Authentication requests on sites with broken TLS certificates.","description":"If set to Enabled, Google Chrome will\r\nallow Web Authentication requests on websites that have TLS certificates with\r\nerrors (i.e. websites considered not secure).\r\n\r\nIf the policy is set to Disabled or left unset, the default behavior of\r\nblocking such requests will apply.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowwebauthnwithbrokentlscerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowwebauthnwithbrokentlscerts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_applicationboundencryptionenabled","displayName":"Enable Application Bound Encryption","description":"Setting the policy to Enabled or leaving it unset binds encryption keys used for local data storage to Google Chrome whenever that is possible.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security as unknown and potentially hostile apps can retrieve encryption keys used to secure data.\r\n\r\nOnly turn off the policy if there are compatibility issues, such as other applications that need legitimate access to Google Chrome's data, encrypted user data is expected to be fully portable between different computers or the integrity and location of Google Chrome's executable files is not consistent.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_applicationboundencryptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_applicationboundencryptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability","displayName":"Enable Battery Saver Mode","description":"This policy enables or disables the Battery Saver Mode setting.\r\nOn Chrome, this setting makes it so that frame rate is throttled to lower power consumption. If this policy is unset, the end user can control this setting in chrome://settings/performance.\r\nOn ChromeOS, this setting makes it so that frame rate and CPU frequency are throttled, backlights are dimmed, and Android is put in Battery Saver Mode. On devices with multiple CPUs, some CPUs will be turned off.\r\nThe different levels are:\r\nDisabled (0): Battery Saver Mode will be disabled.\r\nEnabledBelowThreshold (1): Battery Saver Mode will be enabled when the device is on battery power and battery level is low.\r\nEnabledOnBattery (2): This value is deprecated as of M121. From M121 onwards, values will be treated as EnabledBelowThreshold.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability_batterysavermodeavailability","displayName":"Enable Battery Saver Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability_batterysavermodeavailability_0","displayName":"Battery Saver Mode will be disabled.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability_batterysavermodeavailability_1","displayName":"Battery Saver Mode will be enabled when the device is on battery power and battery level is low.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability_batterysavermodeavailability_2","displayName":"This value is deprecated as of M121. In M121 and after, values will be treated as EnabledBelowThreshold.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_builtinaiapisenabled","displayName":"Allow pages to use the built-in AI APIs.","description":"This policy controls if a page can use the built-in AI APIs (such as LanguageModel API, Summarization API, Writer API, and Rewriter API).\r\n\r\nIf the policy is enabled or unset, the APIs are enabled to be used.\r\n\r\nIf the policy is disabled, attempting using the APIs will result in an error.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_builtinaiapisenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_builtinaiapisenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_chromefortestingallowed","displayName":"Allow Chrome for Testing","description":"Controls whether users may use Chrome for Testing.\r\n\r\nIf this policy is set to Enabled or not set, users may install and run Chrome for Testing.\r\n\r\nIf this policy is set to Disabled, users are not allowed to run Chrome for Testing. Users will still be able to install Chrome for Testing, however it will not run with the profiles where this policy is set to Disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_chromefortestingallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_chromefortestingallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_domainreliabilityallowed","displayName":"Allow reporting of domain reliability related data","description":"If this policy is set false, domain reliability diagnostic data reporting is disabled and no data is sent to Google.\r\nIf this policy is set true or not set, domain reliability diagnostic data reporting will follow the behavior of MetricsReportingEnabled for Google Chrome or DeviceMetricsReportingEnabled for Google ChromeOS.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_domainreliabilityallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_domainreliabilityallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings","displayName":"Dynamic Code Settings","description":"This policy controls the dynamic code settings for Google Chrome.\r\n\r\nDisabling dynamic code improves the security of Google Chrome by preventing potentially hostile dynamic code and third-party code from making changes to Google Chrome's behavior, but might cause compatibility issues with third-party software (e.g. certain printer drivers) that must run inside the browser process.\r\n\r\nIf the policy is set to 0 - Default or left unset then Google Chrome will use the default settings.\r\n\r\nIf the policy is set to 1 - DisabledForBrowser then the Google Chrome browser process will be prevented from creating dynamic code.\r\n\r\nNote: Read more about process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_dynamiccodesettings","displayName":"Dynamic Code Settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_dynamiccodesettings_0","displayName":"Default dynamic code settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_dynamiccodesettings_1","displayName":"Prevent the browser process from creating dynamic code","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enableunsafeswiftshader","displayName":"Allow software WebGL fallback using SwiftShader","description":"A policy that controls if SwiftShader will be used as a WebGL fallback when hardware GPU acceleration is not available.\r\n\r\nSwiftShader has been used to support WebGL on systems without GPU acceleration such as headless systems or virtual machines but has been deprecated due to security issues. Starting in M139, WebGL context creation will fail when it would have otherwise used SwiftShader. This policy allows the browser or administrator to temporarily defer the deprecation.\r\n\r\nSetting the policy to Enabled, SwiftShader will be used as a software WebGL fallback.\r\n\r\nSetting the policy to Disabled or not set, WebGL context creation may fail if hardware GPU acceleration is not available. Web pages may misbehave if they do not gracefully handle WebGL context creation failure.\r\n\r\nThis is a temporary policy which will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enableunsafeswiftshader_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enableunsafeswiftshader_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_encryptedclienthelloenabled","displayName":"Enable TLS Encrypted ClientHello","description":"Encrypted ClientHello (ECH) is an extension to TLS to encrypt sensitive fields of the ClientHello and improve privacy.\r\n\r\nIf this policy is not configured, or is set to enabled, Google Chrome will follow the default rollout process for ECH. If it is disabled, Google Chrome will not enable ECH.\r\n\r\nWhen the feature is enabled, Google Chrome may or may not use ECH depending on server support, availability of the HTTPS DNS record, or rollout status.\r\n\r\nECH is an evolving protocol, so Google Chrome's implementation is subject to change. As such, this policy is a temporary measure to control the initial experimental implementation. It will be replaced with final controls as the protocol finalizes.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_encryptedclienthelloenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_encryptedclienthelloenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel","displayName":"Set a custom enterprise label for a managed profile","description":"This policy controls a custom label used to identify managed profiles. For managed profiles, this label will be shown next to the avatar in the toolbar. The custom label will not be translated.\r\n\r\nWhen this policy is applied, any strings that surpass 16 characters will be truncated with a “...” Please refrain from using extended names.\r\n\r\nThis policy can only be set as a user policy.\r\n\r\nNote that this policy has no effect if the EnterpriseProfileBadgeToolbarSettings policy is set to hide_expanded_enterprise_toolbar_badge (value 1).\r\n\r\nExample value: Chromium","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel_enterprisecustomlabel","displayName":"Set a custom enterprise label for a managed profile (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabelforbrowser","displayName":"Set a custom enterprise label for a managed browser","description":"This policy controls a custom label used to indicate a managed browser. For managed browsers, this label will be shown in a management disclaimer on a footer on the New Tab page. The custom label will not be translated.\r\n\r\nNote that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\n\r\nExample value: Chromium","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabelforbrowser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabelforbrowser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabelforbrowser_enterprisecustomlabelforbrowser","displayName":"Set a custom enterprise label for a managed browser (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourl","displayName":"Enterprise Logo URL for a managed profile","description":"A URL to an image that will be used as an enterprise badge for a managed profile. The URL must point to an image.\r\n\r\nThis policy can only be set as a user policy.\r\n\r\nIt is recommended to use the favicon (example https://www.google.com/favicon.ico) or an icon no smaller than 48 x 48 px.\r\n\r\nExample value: https://example.com/image.png","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourl_enterpriselogourl","displayName":"Enterprise Logo URL for a managed profile (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser","displayName":"Enterprise Logo URL for a managed browser","description":"A URL to an image that will be used as an enterprise badge for a managed browser. The URL must point to an image.\r\n\r\nIt is recommended to use the favicon (example https://www.google.com/favicon.ico) or an icon no smaller than 48 x 48 px.\r\n\r\nNote that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\n\r\nExample value: https://example.com/image.png","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser_enterpriselogourlforbrowser","displayName":"Enterprise Logo URL for a managed browser (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings","displayName":"Controls visibility of enterprise profile badge in the toolbar","description":"For work and school profiles, the toolbar will show a \"Work\" or \"School\" label by default next to the toolbar avatar. The label will only be shown if the signed in account is managed.\r\n\r\nSetting this policy to hide_expanded_enterprise_toolbar_badge (value 1) will hide the enterprise badge for a managed profile in the toolbar.\r\n\r\nLeaving this policy unset or setting it to show_expanded_enterprise_toolbar_badge (value 0) will show the enterprise badge.\r\n\r\nThe label is customizable via the EnterpriseCustomLabel policy.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings","displayName":"Controls visibility of enterprise profile badge in the toolbar (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings_0","displayName":"Show expanded enterprise toolbar badge","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings_1","displayName":"Hide expanded enterprise toolbar badge","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilecreationkeepbrowsingdata","displayName":"Keep browsing data when creating enterprise profile by default","description":"If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default.\r\n\r\nIf this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.\r\n\r\nRegardless of the value, the user will be able to decide whether or not to keep any existing browsing data when creating an enterprise profile.\r\n\r\nThis policy has no effect if the option to keep existing browsing data is not available; this happens if enterprise profile separation is strictly enforced, or if the data would be from an already managed profile.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilecreationkeepbrowsingdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilecreationkeepbrowsingdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings","displayName":"Enterprise search aggregator settings","description":"This policy allows administrators to set a designated enterprise search aggregator that will provide search recommendations and results within the omnibox (address bar) and the search box on the New Tab page.\r\n\r\nBy default, enterprise search suggestions will be blended and shown alongside regular Google Chrome recommendations. Users can explicitly scope their search to just the enterprise search aggregator by typing the keyword specified in the shortcut field with or without the @ prefix (e.g. @work) followed by Space or Tab in the omnibox. Scoped enterprise searches (triggered by a keyword) are currently only supported in the omnibox and not in the search box on the New Tab page.\r\n\r\nThe following fields are required: name, shortcut, search_url, suggest_url.\r\n\r\nThe name field corresponds to the search engine name shown to the user in the address bar.\r\n\r\nThe shortcut field corresponds to the keyword that the user enters to trigger the search. The shortcut can include plain words and characters, but cannot include spaces or start with the @ symbol. Shortcuts must be unique.\r\n\r\nThe search_url field specifies the URL on which to search. Enter the web address for the search engine's results page, and use '{searchTerms}' in place of the query.\r\n\r\nThe suggest_url field specifies the URL that provides search suggestions. A POST request will be made and the user's query will be passed in the POST params under key 'query'.\r\n\r\nThe icon_url field specifies the URL to an image that will be used on the search suggestions. A default icon will be used when this field is not set. It's recommended to use a favicon (example https://www.google.com/favicon.ico). Supported image file formats: JPEG, PNG, and ICO.\r\n\r\nThe require_shortcut field specifies whether the address bar shortcut is required to see search recommendations. If required, suggestions will not be shown in the search box on the New Tab page, but will continue to be shown in the omnibox (address bar) in scoped search mode. If this field is not set, the address bar shortcut is not required.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=EnterpriseSearchAggregatorSettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"name\": \"My Search Aggregator\",\r\n \"shortcut\": \"work\",\r\n \"search_url\": \"https://www.aggregator.com/search?q={searchTerms}\",\r\n \"suggest_url\": \"https://www.aggregator.com/suggest\",\r\n \"icon_url\": \"https://www.google.com/favicon.ico\",\r\n \"require_shortcut\": true\r\n}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings_enterprisesearchaggregatorsettings","displayName":"Enterprise search aggregator settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users would not see a warning when downloading \"jnlp\" files from \"website1.com\", but see a download warning when downloading \"jnlp\" files from \"website2.com\".\r\n\r\nFiles with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Safe Browsing warnings.\r\n\r\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.\r\n\r\nIf you enable this policy:\r\n\r\n* The URL pattern should be formatted according to https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list \"jnlp\" should be used instead of \".jnlp\".\r\n\r\nExample:\r\n\r\nThe following example value would prevent file type extension-based download warnings on \"exe\" and \"jnlp\" extensions for *.example.com domains, and on \"swf\" extensions for all domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\r\n\r\n[\r\n{ \"file_extension\": \"jnlp\", \"domains\": [\"example.com\"] },\r\n{ \"file_extension\": \"exe\", \"domains\": [\"example.com\"] },\r\n{ \"file_extension\": \"swf\", \"domains\": [\"*\"] }\r\n]\r\n\r\nNote that while the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.\r\n\r\nIf this policy is enabled alongside DownloadRestrictions, then the exemptions to file type extension-based warnings specified by this policy take precedence over a DownloadRestrictions setting that would block dangerous file types. The exemptions specified by this policy only apply to the \"block dangerous file types\" behavior specified by values 1 and 2 of DownloadRestrictions.\r\n\r\nFor example, if this policy specifies an exemption for \"exe\" downloads from \"website1.com\", and DownloadRestrictions is set to block malicious downloads and dangerous file types (value 1), then \"exe\" downloads from \"website1.com\" will be exempt from file type extension-based blocking but will still be blocked if they are malicious.\r\n\r\nMore information about DownloadRestrictions can be found at https://chromeenterprise.google/policies/?policy=DownloadRestrictions.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ExemptDomainFileTypePairsFromFileTypeDownloadWarnings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"domains\": [\r\n \"https://example.com\",\r\n \"example2.com\"\r\n ],\r\n \"file_extension\": \"jnlp\"\r\n },\r\n {\r\n \"domains\": [\r\n \"*\"\r\n ],\r\n \"file_extension\": \"swf\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings_exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_feedbacksurveysenabled","displayName":"Specifies whether in-product Google Chrome surveys are shown to users.","description":"Google Chrome in-product surveys collect user feedback for the browser. Survey responses are not associated with user accounts.\r\nWhen this policy is Enabled or not set, in-product surveys may be shown to users.\r\nWhen this policy is Disabled, in-product surveys are not shown to users.\r\n\r\nThis policy has no effect if MetricsReportingEnabled is set to Disabled, which disables in-product surveys as well.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_feedbacksurveysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_feedbacksurveysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_fileordirectorypickerwithoutgestureallowedfororigins","displayName":"Allow file or directory picker APIs to be called without prior user gesture","description":"For security reasons, the\r\nshowOpenFilePicker(),\r\nshowSaveFilePicker() and\r\nshowDirectoryPicker() web APIs\r\nrequire a prior user gesture (\"transient activation\") to be called or will\r\notherwise fail.\r\n\r\nWith this policy set, admins can specify origins on which these APIs can be\r\ncalled without prior user gesture.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is\r\nnot an accepted value for this policy.\r\n\r\nIf this policy is unset, all origins will require a prior user gesture to call\r\nthese APIs.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_fileordirectorypickerwithoutgestureallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_fileordirectorypickerwithoutgestureallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_fileordirectorypickerwithoutgestureallowedfororigins_fileordirectorypickerwithoutgestureallowedfororiginsdesc","displayName":"Allow file or directory picker APIs to be called without prior user gesture (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled.","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy. Currently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers. This enterprise policy can be used to opt out of this gradual deprecation by forcing the default to remain as enabled.\r\n\r\nPages may depend on unload event handlers to save data or signal the end of a user session to the server. This is not recommended as it is unreliable and impacts performance by blocking use of BackForwardCache. Recommended alternatives exist, however the unload event has been used for a long time. Some applications may still rely on them.\r\n\r\nIf this policy is set to false or not set, then unload events handlers will be gradually deprecated in-line with the deprecation rollout and sites which do not set Permissions-Policy header will stop firing `unload` events.\r\n\r\nIf this policy is set to true then unload event handlers will continue to work by default.\r\n\r\nNOTE: This policy had an incorrectly documented default of `true` in M117. The unload event did and will not change in M117, so this policy has no effect in that version.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_forcepermissionpolicyunloaddefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_forcepermissionpolicyunloaddefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_googlesearchsidepanelenabled","displayName":"Enable Google Search Side Panel","description":"If set to Enabled or not set, Google Search Side Panel is allowed on all web pages.\r\n\r\nIf set to Disabled, Google Search Side Panel is not available on any webpage.\r\n\r\nGenAI capabilities that are part of this feature are not available for Educational or Enterprise accounts.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_googlesearchsidepanelenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_googlesearchsidepanelenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_highefficiencymodeenabled","displayName":"Enable High Efficiency Mode","description":"This policy enables or disables the High Efficiency Mode setting. This setting makes it so that tabs are discarded after some period of time in the background to reclaim memory.\r\nIf this policy is unset, the end user can control this setting in chrome://settings/performance.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_highefficiencymodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_highefficiencymodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist","displayName":"HTTP Allowlist","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as\r\n'[*.]example.com') that will not be upgraded to HTTPS and will not show an\r\nerror interstitial if HTTPS-First Mode is enabled. Organizations can use this\r\npolicy to maintain access to servers that do not support HTTPS, without\r\nneeding to disable HTTPS Upgrades and/or HTTPS-First Mode.\r\n\r\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their\r\nA-label format, and all ASCII letters must be lowercase.\r\n\r\nBlanket host wildcards (i.e., \"*\" or \"[*]\") are not allowed. Instead,\r\nHTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their\r\nspecific policies.\r\n\r\nNote: This policy does not apply to HSTS upgrades.\r\n\r\nExample value:\r\n\r\ntestserver.example.com\r\n[*.]example.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist_httpallowlistdesc","displayName":"HTTP Allowlist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpsupgradesenabled","displayName":"Enable automatic HTTPS upgrades","description":"Google Chrome attempts to upgrade some\r\nnavigations from HTTP to HTTPS, when possible. This policy can be used to\r\ndisable this behavior. If set to \"true\" or left unset, this feature will be\r\nenabled by default.\r\n\r\nThe separate HttpAllowlist policy\r\ncan be used to exempt specific hostnames or hostname patterns from being\r\nupgraded to HTTPS by this feature.\r\n\r\nSee also the HttpsOnlyMode policy.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpsupgradesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpsupgradesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensdesktopntpsearchenabled","displayName":"Allow Google Lens button to be shown in the search box on the New Tab page if supported.","description":"Leaving the policy unset or setting it to Enabled allows users to view and use the Google Lens button in the search box on the New Tab page. Setting the policy to Disabled means users will not see the Google Lens button in the search box on the New Tab page.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensdesktopntpsearchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensdesktopntpsearchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings","displayName":"Settings for the Lens Overlay feature","description":"Lens Overlay lets users perform contextual Google searches either via a screenshot or by asking a question about the current page's contents. This feature requires the end user to opt-in.\r\n\r\nThis feature is available to all users with Google as their default search engine, unless it is disabled by this policy.\r\n\r\nWhen policy is set to 0 - Allow or not set, the feature will be available to users.\r\n\r\nWhen policy is set to 1 - Do not allow, the feature will not be available.\r\n\r\nStarting in Google Chrome 140, if the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_lensoverlaysettings","displayName":"Settings for the Lens Overlay feature (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_lensoverlaysettings_0","displayName":"Allow","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_lensoverlaysettings_1","displayName":"Do not allow","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings","displayName":"Change Memory Saver Mode Savings","description":"This policy changes the savings level of Memory Saver.\r\n\r\nThis only takes effect when Memory Saver is enabled through settings or through the HighEfficiencyModeEnabled policy, and will affect how heuristics are used to determine when to discard tabs. For example, reducing the lifetime of an inactive tab before discarding it can save memory, but it also means that tabs will be reloaded more frequently which can lead to bad user experience and cost more network traffic.\r\n\r\nSetting the policy to 0 - Memory Saver will get moderate memory savings. Tabs become inactive after a longer period of time\r\n\r\nSetting the policy to 1 - Memory Saver will get balanced memory savings. Tabs become inactive after an optimal period of time.\r\n\r\nSetting the policy to 2 - Memory Saver will get maximum memory savings. Tabs become inactive after a shorter period of time.\r\n\r\nIf this policy is unset, the end user can control this setting in chrome://settings/performance.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings","displayName":"Change Memory Saver Mode Savings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings_0","displayName":"Moderate memory savings.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings_1","displayName":"Balanced memory savings.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings_2","displayName":"Maximum memory savings.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_nativehostsexecutableslaunchdirectly","displayName":"Force Windows executable Native Messaging hosts to launch directly","description":"This policy controls whether native host executables launch directly on Windows.\r\n\r\nSetting the policy to Enabled forces Google Chrome to launch native messaging hosts implemented as executables directly.\r\n\r\nSetting the policy to Disabled will result in Google Chrome launching hosts using cmd.exe as an intermediary process.\r\n\r\nLeaving the policy unset allows Google Chrome to decide which approach to use.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_nativehostsexecutableslaunchdirectly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_nativehostsexecutableslaunchdirectly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpfooterextensionattributionenabled","displayName":"Control the visibility of the extension attribution on the New Tab page","description":"This policy determines whether an attribution to the extension modifying the New Tab Page (NTP) is displayed in the NTP's footer.\r\n\r\nBy default, if an extension has overridden the standard NTP, a message attributing this change to the specific extension will appear in the footer. This attribution typically includes a link to the relevant extension in the Chrome Web Store.\r\n\r\nIf this policy is left unset or set to true, the extension attribution will be visible on the NTP footer when an extension is controlling the NTP.\r\n\r\nIf this policy is set to false, the attribution to the extension in the NTP footer will be suppressed.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpfooterextensionattributionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpfooterextensionattributionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpfootermanagementnoticeenabled","displayName":"Control the visibility of the management notice on the New Tab Page for managed browsers","description":"This policy controls the visibility of the management notice within the footer of the New Tab Page (NTP). By default, the NTP footer displays information when the browser is managed by an organization (indicated by a building icon and \"Managed by [domain name]\"). This can be customized using the EnterpriseCustomLabelForBrowser and EnterpriseLogoUrlForBrowser policies.\r\n\r\nIf this policy is left unset or set to true, managed browsers will display a “Managed by…” notice with an icon.\r\n\r\nIf this policy is set to false, the management notice will be hidden.\r\n\r\nNote that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpfootermanagementnoticeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpfootermanagementnoticeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpmiddleslotannouncementvisible","displayName":"Show the middle slot announcement on the New Tab Page","description":"This policy controls the visibility of the middle slot announcement on the New Tab Page.\r\n\r\nIf the policy is set to Enabled, the New Tab Page will show the middle slot announcement if it is available.\r\n\r\nIf the policy is set to Disabled, the New Tab Page will not show the middle slot announcement even if it is available.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpmiddleslotannouncementvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpmiddleslotannouncementvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpoutlookcardvisible","displayName":"Show Outlook Calendar card on the New Tab Page","description":"This policy controls the visibility of the Outlook Card on the New Tab Page. The card will only be displayed on the New Tab Page if the policy is enabled and your organization authorized the usage of the Outlook Calendar data in the browser.\r\n\r\nOutlook data will not be stored by the browser.\r\n\r\nThe Outlook card shows the next calendar event, along with a glanceable look at the rest of the day's meetings. It aims to address the issue of context switching and enhance productivity by giving users a shortcut to their next meeting.\r\n\r\nThe Microsoft Outlook card will require additional admin configuration. For detailed information on connecting the Chrome New Tab Page Card to Outlook, please see https://support.google.com/chrome/a?p=chrome_ntp_microsoft_cards.\r\n\r\nIf the NTPCardsVisible is disabled, the Outlook Card will not be shown. If NTPCardsVisible is enabled, the Outlook card will be shown if this policy is also enabled and there is data to be shown. If NTPCardsVisible is unset, the Outlook card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpoutlookcardvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpoutlookcardvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpsharepointcardvisible","displayName":"Show SharePoint and OneDrive File Card on the New Tab Page","description":"This policy controls the visibility of the SharePoint and OneDrive File Card on the New Tab Page. The card will only be displayed on the New Tab Page if the policy is enabled and your organization authorized the usage of the SharePoint and OneDrive File data in the browser.\r\n\r\nSharePoint and OneDrive data will not be stored by the browser.\r\n\r\nThe SharePoint and OneDrive Files recommendation card shows a list of recommended files. It aims to address the issue of context switching and enhance productivity by giving users a shortcut to their most important documents.\r\n\r\nThe Microsoft SharePoint and OneDrive card will require additional admin configuration. For detailed information on connecting the Chrome New Tab Page Card to Sharepoint, please see https://support.google.com/chrome/a?p=chrome_ntp_microsoft_cards.\r\n\r\nIf the NTPCardsVisible is disabled, the SharePoint and OneDrive Card will not be shown. If NTPCardsVisible is enabled, the SharePoint and OneDrive card will be shown if this policy is also enabled and there is data to be shown. If NTPCardsVisible is unset, the SharePoint and OneDrive card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpsharepointcardvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpsharepointcardvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts","displayName":"Setting shortcuts on the New Tab Page (Beta)","description":"In development: for early preview only.\r\n\r\nSetting the policy pre-configures up to 10 custom shortcuts on the Google Chrome New Tab page.\r\n\r\nIf set, users will see these shortcuts by default and users can toggle between “My shortcuts,\" \"Most visited sites\" or \"My organization's shortcuts\" on the \"Customize Chrome\" panel. If empty or unset, the user will only be able to toggle between “My shortcuts\" or \"Most visited sites\" on the \"Customize Chrome\" panel.\r\n\r\nShortcut URLs must be unique.\r\n\r\nIf allow_user_edit is set to true, users can change the name of the shortcut. If set to false or unset, users cannot edit the name.\r\n\r\nIf allow_user_delete is set to true, users can remove the shortcut. If set to false or unset, users cannot remove the shortcut.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=NTPShortcuts for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"name\": \"Google\",\r\n \"url\": \"https://www.google.com\"\r\n },\r\n {\r\n \"name\": \"YouTube\",\r\n \"url\": \"https://www.youtube.com\"\r\n },\r\n {\r\n \"name\": \"Google Drive\",\r\n \"url\": \"https://www.drive.google.com\",\r\n \"allow_user_edit\": true,\r\n \"allow_user_delete\": true\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts_ntpshortcuts","displayName":"Setting shortcuts on the New Tab Page (Beta) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_originagentclusterdefaultenabled","displayName":"Allows origin-keyed agent clustering by default.","description":"This policy allows origin-keyed agent clustering by default.\r\n\r\nThe Origin-Agent-Cluster HTTP header controls whether a document is\r\nisolated in an origin-keyed agent cluster, or in a site-keyed agent\r\ncluster. This has security implications since an origin-keyed agent\r\ncluster allows isolating documents by origin. The developer-visible\r\nconsequence of this is that the document.domain accessor can no longer\r\nbe set.\r\n\r\nThe default behaviour - when no Origin-Agent-Cluster header has been set -\r\nchanges in M111 from site-keyed to origin-keyed.\r\n\r\nIf this policy is enabled or not set, the browser will follow this\r\nnew default from that version on.\r\n\r\nIf this policy is disabled this change is reversed and\r\ndocuments without Origin-Agent-Cluster headers will be assigned to\r\nsite-keyed agent clusters. As a consequence, the document.domain accessor\r\nremains settable by default. This matches the legacy behaviour.\r\n\r\nSee https://developer.chrome.com/blog/immutable-document-domain/ for\r\nadditional details.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_originagentclusterdefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_originagentclusterdefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfannotationsenabled","displayName":"Enable PDF Annotations","description":"Controls if the PDF viewer in Google Chrome can annotate PDFs.\r\n\r\nWhen this policy is not set, or is set to true, then the PDF viewer will be able to annotate PDFs.\r\n\r\nWhen this policy is set to false, then the PDF viewer will not be able to annotate PDFs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfannotationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfannotationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfuseskiarendererenabled","displayName":"Use Skia renderer for PDF rendering","description":"Controls whether the PDF viewer in Google Chrome uses Skia renderer.\r\n\r\nWhen this policy is enabled, the PDF viewer uses Skia renderer.\r\n\r\nWhen this policy is disabled, the PDF viewer uses its current AGG renderer.\r\n\r\nWhen this policy is not set, the PDF renderer will be chosen by the browser.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfuseskiarendererenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfuseskiarendererenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfvieweroutofprocessiframeenabled","displayName":"Use out-of-process iframe PDF Viewer","description":"Controls whether the PDF viewer in Google Chrome uses an out-of-process iframe (OOPIF). This will be the new PDF viewer architecture in the future, as it is simpler and makes adding new features easier. The existing GuestView PDF viewer is an outdated, complex architecture that is being deprecated.\r\n\r\nWhen this policy is set to Enabled or not set, Google Chrome will be able to use the OOPIF PDF viewer architecture. Once Enabled or not set, the default behavior will be decided by Google Chrome.\r\n\r\nWhen this policy is set to Disabled, Google Chrome will strictly use the existing GuestView PDF viewer. It embeds a web page with a separate frame tree into another web page.\r\n\r\nThis policy will be removed in the future, after the OOPIF PDF viewer feature has fully rolled out.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfvieweroutofprocessiframeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfvieweroutofprocessiframeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_postquantumkeyagreementenabled","displayName":"Enable post-quantum key agreement for TLS","description":"This policy configures whether Google Chrome will offer a post-quantum key agreement algorithm in TLS, using the ML-KEM NIST standard. Prior to Google Chrome 131, the algorithm was Kyber, an earlier draft iteration of the standard. This allows supporting servers to protect user traffic from being later decrypted by quantum computers.\r\n\r\nIf this policy is Enabled or not set, Google Chrome will offer a post-quantum key agreement in TLS connections. User traffic will then be protected from quantum computers when communicating with compatible servers.\r\n\r\nIf this policy is Disabled, Google Chrome will not offer a post-quantum key agreement in TLS connections. User traffic will then be unprotected from quantum computers.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing TLS servers and networking middleware are expected to ignore the new option and continue selecting previous options.\r\n\r\nHowever, devices that do not correctly implement TLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or the resulting larger messages. Such devices are not post-quantum-ready and will interfere with an enterprise's post-quantum transition. If encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed sometime after Google Chrome version 145. It may be Enabled to allow you to test for issues, and may be Disabled while issues are being resolved.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_postquantumkeyagreementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_postquantumkeyagreementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled","displayName":"Allow SpeculationRules prefetch to ServiceWorker-controlled URLs","description":"SpeculationRules prefetch can be issued to URLs that are controlled by\r\nServiceWorker. However, legacy code did not allow it and canceled the prefetch\r\nrequests. This policy enables to control the behavior.\r\n\r\nSetting this policy to Enabled or not set allows SpeculationRules prefetch to\r\nServiceWorker-controlled URLs (if the PrefetchServiceWorker feature flag is\r\nenabled). This is the current default behavior and is aligned with the\r\nspecifications.\r\n\r\nSetting this policy to Disabled disallows SpeculationRules prefetch to\r\nServiceWorker-controlled URLs. This is the legacy behavior.\r\n\r\nThis policy is intended to be temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt","displayName":"Prompt users to re-authenticate to the profile","description":"When set to DoNotPrompt or left unset, Google Chrome does not automatically prompt the user to re-authenticate to the browser.\r\n\r\nWhen set to PromptInTab, when the user's authentication expires, immediately open a new tab with the Google login page. This only happens if using Chrome Sync.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_profilereauthprompt","displayName":"Prompt users to re-authenticate to the profile (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_profilereauthprompt_0","displayName":"Do not prompt for reauth","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_profilereauthprompt_1","displayName":"Prompt for reauth in a tab","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_promotionsenabled","displayName":"Enable showing promotional content","description":"Setting the policy to True or leaving it unset lets Google Chrome show users product promotional content.\r\n\r\nSetting the policy to False prevents Google Chrome from showing product promotional content.\r\n\r\nSetting the policy controls the presentation of promotional content, including the welcome pages that help users sign in to Google Chrome, set Google Chrome as users' default browser, or otherwise inform them of product features.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_promotionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_promotionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_qrcodegeneratorenabled","displayName":"Enable QR Code Generator","description":"This policy enables the QR Code generator feature in Google Chrome.\r\n\r\nIf you enable this policy or don't configure it, the QR Code Generator feature is enabled.\r\n\r\nIf you disable this policy, the QR Code Generator feature is disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_qrcodegeneratorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_qrcodegeneratorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended","displayName":"Enable Battery Saver Mode","description":"This policy enables or disables the Battery Saver Mode setting.\r\nOn Chrome, this setting makes it so that frame rate is throttled to lower power consumption. If this policy is unset, the end user can control this setting in chrome://settings/performance.\r\nOn ChromeOS, this setting makes it so that frame rate and CPU frequency are throttled, backlights are dimmed, and Android is put in Battery Saver Mode. On devices with multiple CPUs, some CPUs will be turned off.\r\nThe different levels are:\r\nDisabled (0): Battery Saver Mode will be disabled.\r\nEnabledBelowThreshold (1): Battery Saver Mode will be enabled when the device is on battery power and battery level is low.\r\nEnabledOnBattery (2): This value is deprecated as of M121. From M121 onwards, values will be treated as EnabledBelowThreshold.\r\n","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability","displayName":"Enable Battery Saver Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability_0","displayName":"Battery Saver Mode will be disabled.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability_1","displayName":"Battery Saver Mode will be enabled when the device is on battery power and battery level is low.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability_2","displayName":"This value is deprecated as of M121. In M121 and after, values will be treated as EnabledBelowThreshold.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_domainreliabilityallowed_recommended","displayName":"Allow reporting of domain reliability related data","description":"If this policy is set false, domain reliability diagnostic data reporting is disabled and no data is sent to Google.\r\nIf this policy is set true or not set, domain reliability diagnostic data reporting will follow the behavior of MetricsReportingEnabled for Google Chrome or DeviceMetricsReportingEnabled for Google ChromeOS.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_domainreliabilityallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_domainreliabilityallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_enterpriseprofilecreationkeepbrowsingdata_recommended","displayName":"Keep browsing data when creating enterprise profile by default","description":"If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default.\r\n\r\nIf this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.\r\n\r\nRegardless of the value, the user will be able to decide whether or not to keep any existing browsing data when creating an enterprise profile.\r\n\r\nThis policy has no effect if the option to keep existing browsing data is not available; this happens if enterprise profile separation is strictly enforced, or if the data would be from an already managed profile.\r\n","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_enterpriseprofilecreationkeepbrowsingdata_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_enterpriseprofilecreationkeepbrowsingdata_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_originkeyedprocessesenabled_recommended","displayName":"Enable origin-keyed process isolation by default.","description":"Enables origin-keyed process isolation for most pages (i.e., those assigned to an origin-keyed agent cluster by default). This improves security but also increases the number of processes created. Users are allowed to override the set policy value via the command-line flags or chrome://flags (both to turn this feature on or off).\r\n\r\nSetting the policy to Enabled results in most origins being isolated, even from other origins in the same site. See also the IsolateOrigins and SitePerProcess policies.\r\n\r\nSetting the policy to Disabled results in no origins being isolated from the rest of their site unless an origin explicitly asks to.\r\n\r\nNot setting the policy results in the browser determining which origins to isolate and when to isolate them.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_originkeyedprocessesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_originkeyedprocessesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livecaptionenabled_recommended","displayName":"Enable Live Caption","description":"Enable the Live Caption feature.\r\n\r\nIf this policy is set to Enabled, Live Caption will always be turned on.\r\n\r\nIf this policy is set to Disabled, Live Caption will always be turned off.\r\n\r\nIf you set this policy as mandatory, users cannot change or override it.\r\n\r\nIf this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.","helpText":"","infoUrls":[],"categoryId":"12142994-4b30-486c-bab1-9206528b2b96","categoryName":"Accessibility settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livecaptionenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livecaptionenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livetranslateenabled_recommended","displayName":"Enable Live Translate","description":"Enable translation of live captions. Captions will be sent to Google for translation.\r\n\r\nIf this policy is set to Enabled, Live Translate will always be turned on.\r\n\r\nIf this policy is set to Disabled, Live Translate will always be turned off.\r\n\r\nIf you set this policy as mandatory, users cannot change or override it.\r\n\r\nIf this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime.\r\n\r\nIn LiveCaptionEnabled is set to Disabled, Live Translate will be disabled regardless of this policy setting.","helpText":"","infoUrls":[],"categoryId":"12142994-4b30-486c-bab1-9206528b2b96","categoryName":"Accessibility settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livetranslateenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livetranslateenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_reduceacceptlanguageenabled","displayName":"Control Accept-Language Reduction","description":"The Accept-Language HTTP request header and the JavaScript navigator.languages getter are planned for reduction for privacy reasons.\r\nTo facilitate testing and ensure compatibility, this policy allows you to enable or disable the Accept-Language Reduction feature.\r\n\r\nIf this policy is set to enabled or left unset, Accept-Language Reduction will be applied through field trials.\r\nIf this policy is set to disabled, field trials will not be able to activate Accept-Language Reduction.\r\n\r\nFor more information about this feature, please visit: https://github.com/explainers-by-googlers/reduce-accept-language.\r\n\r\nNOTE: Only newly-started renderer processes will reflect changes to this policy while the browser is running.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_reduceacceptlanguageenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_reduceacceptlanguageenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_relaunchfastifoutdated","displayName":"Relaunch fast if outdated","description":"Specifies the minimum release age beyond which relaunch notifications are more aggressive. The age is calculated from the time the currently-running version was last served to clients.\r\n\r\nIf a browser relaunch or device restart is needed to finalize a pending update and the current version has been outdated for more than the number of days specified by this setting, the RelaunchNotificationPeriod policy is overridden to 2 hours. If the RelaunchNotification policy is set to 1 ('Required'), users will be forced to relaunch or restart at the end of the period.\r\n\r\nIf not set, or if the release age cannot be determined, the RelaunchNotificationPeriod policy will be used for all updates.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_relaunchfastifoutdated_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_relaunchfastifoutdated_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_relaunchfastifoutdated_relaunchfastifoutdated","displayName":"Time period (days): (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_rendererappcontainerenabled","displayName":"Enable Renderer App Container","description":"Setting the policy to Enabled or leaving it unset means Renderer App Container configuration will be enabled on supported platforms.\r\n\r\nSetting the policy to Disabled has a detrimental effect on the security and stability of Google Chrome as it will weaken the sandbox that renderer processes use. Only turn off the policy if there are compatibility issues with third-party software that must run inside renderer processes.\r\n\r\nNote: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_rendererappcontainerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_rendererappcontainerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer","displayName":"Restrict CPU core sharing for renderer process","description":"This policy mitigates side-channel cross process memory attacks by isolating the renderer process on the CPU core and preventing other processes from sharing the same core. The mitigation is supported on Microsoft® Windows® 11 24H2 and above. If the OS does not have the required scheduling support, this policy will have no effect. This policy may slow down performance in some demanding scenarios similar to disabling hyperthreading. For more information refer https://learn.microsoft.com/en-us/windows/win32/api/winnt/ns-winnt-process_mitigation_side_channel_isolation_policy\r\nIf this policy is enabled, all other processes will not be scheduled on the same CPU core when the renderer process is running.\r\nIf this policy is disabled, all other processes can be scheduled on the same CPU core if a renderer process is running on it.\r\nIf this policy is not set, all other processes can be scheduled on the same CPU core if a renderer process is running on the core. This may vary depending on Google Chrome release, currently running field trials, and platform.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_screencapturewithoutgestureallowedfororigins","displayName":"Allow screen capture without prior user gesture","description":"For security reasons, the\r\ngetDisplayMedia() web API requires\r\na prior user gesture (\"transient activation\") to be called or will otherwise\r\nfail.\r\n\r\nWith this policy set, admins can specify origins on which this API can be\r\ncalled without prior user gesture.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is\r\nnot an accepted value for this policy.\r\n\r\nIf this policy is unset, all origins will require a prior user gesture to call\r\nthis API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_screencapturewithoutgestureallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_screencapturewithoutgestureallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_screencapturewithoutgestureallowedfororigins_screencapturewithoutgestureallowedfororiginsdesc","displayName":"Allow screen capture without prior user gesture (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup","description":"https://github.com/WICG/service-worker-auto-preload\r\nThe ServiceWorkerAutoPreload feature dispatches a network request for a main resource at the same time it begins the ServiceWorker bootstrap process.\r\n\r\nSetting the policy to Enabled or leaving it unset means\r\nGoogle Chrome enables ServiceWorkerAutoPreload. The navigation request is automatically dispatched while starting the ServiceWorker in some scenarios, e.g. ServiceWorker is not running,\r\n\r\nIf it is disabled, Google Chrome will not enable ServiceWorkerAutoPreload. The navigation request is dispatched always after starting the ServiceWorker.\r\n\r\nThis policy is a temporary measure to control the feature and will be removed in M144.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkerautopreloadenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkerautopreloadenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled","displayName":"Allow ServiceWorker to control srcdoc iframes","description":"https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with\r\nthe \"allow-same-origin\" sandbox attribute to be under ServiceWorker control.\r\n\r\nSetting the policy to Enabled or leaving it unset means\r\nGoogle Chrome makes srcdoc iframes\r\nwith \"allow-same-origin\" sandbox attributes to be under ServiceWorker control.\r\n\r\nSetting the policy to Disabled leaves the srcdoc iframe not controlled by\r\nServiceWorker.\r\n\r\nThis policy is intended to be temporary and will be removed in 2026.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sharedworkerbloburlfixenabled","displayName":"Make SharedWorker blob URL behavior aligned with the specification","description":"Upon https://w3c.github.io/ServiceWorker/#control-and-use-worker-client,\r\nworkers should inherit controllers for the blob URL. However, existing code\r\nallows only DedicatedWorkers to inherit the controller, and SharedWorkers do\r\nnot inherit the controller.\r\n\r\nSetting the policy to Enabled or leaving it unset means\r\nGoogle Chrome inherit the controller\r\nif a blob URL is used as a SharedWorker URL.\r\n\r\nSetting the policy to Disabled leaves the behavior not aligned with the\r\nspecification as-is.\r\n\r\nThis policy is intended to be temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sharedworkerbloburlfixenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sharedworkerbloburlfixenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_shoppinglistenabled","displayName":"Allow the shopping list feature to be enabled","description":"This policy controls the availability of the shopping list feature.\r\nIf enabled, users will be presented with UI to track the price of the product displayed on the current page. The tracked product will be shown in the bookmarks side panel.\r\nIf this policy is set to Enabled or not set, the shopping list feature will be available to users.\r\nIf this policy is set to Disabled, the shopping list feature will be unavailable.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_shoppinglistenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_shoppinglistenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sidesearchenabled","displayName":"Allow showing the most recent default search engine results page in a Browser side panel","description":"Setting the policy to Enabled or leaving the policy unset means that users can bring up their most recent default search engine results page in a side panel via toggling an icon in the toolbar.\r\n\r\nSetting the policy to Disabled removes the icon from the toolbar that opens the side panel with the default search engine results page.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sidesearchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sidesearchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sitesearchsettings","displayName":"Site search settings","description":"This policy provides a list of sites that users can quickly search using shortcuts in the address bar. Users can initiate a search by typing the shortcut or @shortcut (e.g. @work), followed by Space or Tab, in the address bar.\r\n\r\nThe following fields are required for each site: name, shortcut, url.\r\n\r\nThe name field corresponds to the site or search engine name to be shown to the user in the address bar.\r\n\r\nThe shortcut can include plain words and characters, but cannot include spaces or start with the @ symbol. Shortcuts must also be unique.\r\n\r\nFor each entry, the url field specifies the URL of the search engine used during a search with the corresponding keyword. The URL must include the string '{searchTerms}', replaced in the query by the user's search terms. Invalid entries and entries with duplicate shortcuts are ignored.\r\n\r\nSite search entries configured as featured are displayed in the address bar when the user types \"@\". Up to three entries can be selected as featured.\r\n\r\nFor a site search entry where allow_user_override is true, users have the ability to edit or disable that entry. However, featured engines (beginning with \"@\") can only be disabled. If a user modifies an entry that was initially created by this policy, it will no longer be managed by policy and will be treated like a user-created shortcut. When allow_user_override is false or unspecified for a site search entry, users cannot edit or disable that entry. The setting to allow user override is only supported on M139 and later; earlier versions will default to disabling user override.\r\n\r\nUsers cannot create new site search entries with a shortcut previously created via this policy unless allow_user_override is set to true for the site search entry.\r\n\r\nIn case of a conflict with a shortcut previously created by the user, the user setting takes precedence. However, users can still trigger the option created by the policy by typing \"@\" in the search bar. For example, if the user already defined \"work\" as a shortcut to URL1 and the policy defines \"work\" as a shortcut to URL2, then typing \"work\" in the search bar will trigger a search to URL1, but typing \"@work\" in the search bar will trigger a search to URL2.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=SiteSearchSettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"featured\": true,\r\n \"name\": \"Google Wikipedia\",\r\n \"shortcut\": \"wikipedia\",\r\n \"url\": \"https://www.google.com/search?q=site%3Awikipedia.com+%s\"\r\n },\r\n {\r\n \"name\": \"YouTube\",\r\n \"shortcut\": \"youtube\",\r\n \"url\": \"https://www.youtube.com/results?search_query=%s\"\r\n },\r\n {\r\n \"name\": \"Google Drive\",\r\n \"shortcut\": \"drive\",\r\n \"url\": \"https://drive.google.com/?q=%s\",\r\n \"allow_user_override\": true\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sitesearchsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sitesearchsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sitesearchsettings_sitesearchsettings","displayName":"Site search settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_standardizedbrowserzoomenabled","displayName":"Enable Standardized Browser Zoom Behavior","description":"This policy enables conformance to the newly-adopted specification of CSS zoom.\r\n\r\nWhen this policy is Enabled or unset, the CSS \"zoom\" property will adhere to the specification:\r\n\r\nhttps://drafts.csswg.org/css-viewport/#zoom-property\r\n\r\nWhen Disabled, the CSS \"zoom\" property will fall back to its legacy pre-standardized behavior.\r\n\r\nThis policy is a temporary reprieve to allow time to migrate web content to the new behavior. There is also an origin trial (\"DisableStandardizedBrowserZoom\") that corresponds to the behavior when this policy is Disabled. This policy will be removed and the \"Enabled\" behavior made permanent in milestone 134.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_standardizedbrowserzoomenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_standardizedbrowserzoomenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_strictmimetypecheckforworkerscriptsenabled","displayName":"Enable strict MIME type checking for worker scripts","description":"This policy enables strict MIME type checking for worker scripts.\r\n\r\nWhen enabled or unset, then worker scripts will use strict MIME type checking for JavaScript, which is the new default behaviour. Worker scripts with legacy MIME types will be rejected.\r\n\r\nWhen disabled, then worker scripts will use lax MIME type checking, so that worker scripts with legacy MIME types, e.g. text/ascii, will continue to be loaded and executed.\r\n\r\nBrowsers traditionally used lax MIME type checking, so that resources with a number of legacy MIME types were supported. E.g. for JavaScript resources, text/ascii is a legacy supported MIME type. This may cause security issues, by allowing to load resources as scripts that were never intended to be used as such. Chrome will transition to use strict MIME type checking in the near future. The enabled policy will track the default behaviour. Disabling this policy allows administrators to retain the legacy behaviour, if desired.\r\n\r\nSee https://html.spec.whatwg.org/multipage/scripting.html#scriptingLanguage for details about JavaScript / ECMAScript media types.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_strictmimetypecheckforworkerscriptsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_strictmimetypecheckforworkerscriptsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions","displayName":"URL pattern Exceptions to tab discarding","description":"This policy makes it so that any URL matching one or more of the patterns it specifies (using the URLBlocklist filter format) will never be discarded by the browser.\r\nThis applies to memory pressure and high efficiency mode discarding.\r\nA discarded page is unloaded and its resources fully reclaimed. The tab its associated with remains in the tabstrip, but making it visible will trigger a full reload.\r\n\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://*\r\n*","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_tabdiscardingexceptionsdesc","displayName":"URL pattern Exceptions to tab discarding (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tls13earlydataenabled","displayName":"Enable TLS 1.3 Early Data","description":"TLS 1.3 Early Data is an extension to TLS 1.3 to send an HTTP request simultaneously with the TLS handshake.\r\n\r\nIf this policy is not configured, Google Chrome will follow the default rollout process for TLS 1.3 Early Data.\r\n\r\nIf it is enabled, Google Chrome will enable TLS 1.3 Early Data.\r\n\r\nIf it is disabled, Google Chrome will not enable TLS 1.3 Early Data.\r\n\r\nWhen the feature is enabled, Google Chrome may or may not use TLS 1.3 Early Data depending on server support.\r\n\r\nTLS 1.3 Early Data is an established protocol. Existing TLS servers, middleboxes, and security software are expected to either handle or reject TLS 1.3 Early Data without dropping the connection.\r\n\r\nHowever, devices that do not correctly implement TLS may malfunction and disconnect when TLS 1.3 Early Data is in use. If this occurs, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure to control the feature and will be removed afterwards. The policy may be enabled to allow you to test for issues and disabled while issues are being resolved.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tls13earlydataenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tls13earlydataenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_translatorapiallowed","displayName":"Allow Translator API","description":"Setting the policy to Enabled or leaving it unset allows the use of Translator API in Google Chrome.\r\n\r\nSetting the policy to Disabled disallows the use of Translator API.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_translatorapiallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_translatorapiallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webappsettings","displayName":"Web App management settings","description":"This policy allows an admin to specify settings for installed web apps. This policy maps a Web App ID to its specific setting. A default configuration can be set using the special ID *, which applies to all web apps without a custom configuration in this policy.\r\n\r\nThe manifest_id field is the Manifest ID for the Web App. See https://developer.chrome.com/blog/pwa-manifest-id/ for instructions on how to determine the Manifest ID for an installed web app.\r\nThe run_on_os_login field specifies if a web app can be run during OS login. If this field is set to blocked, the web app will not run during OS login and the user will not be able to enable this later. If this field is set to run_windowed, the web app will run during OS login and the user will not be able to disable this later. If this field is set to allowed, the user will be able to configure the web app to run at OS login. The default configuration only allows the allowed and blocked values.\r\n(Since version 117) The prevent_close_after_run_on_os_login field specifies if a web app shall be prevented from closing in any way (e.g. by the user, task manager, web APIs). This behavior can only be enabled if run_on_os_login is set to run_windowed. If the app were already running, this property will only come into effect after the app is restarted. If this field is not defined, apps will be closable by users.\r\n(Since version 118) The force_unregister_os_integration field specifies if all OS integration for a web app, i.e. shortcuts, file handlers, protocol handlers etc will be removed or not. If an app is already running, this property will come into effect after the app has restarted. This should be used with caution, since this can override any OS integration that is set automatically during the startup of the web applications system. Currently only works on Windows, Mac and Linux platforms.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebAppSettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"manifest_id\": \"https://foo.example/index.html\",\r\n \"run_on_os_login\": \"allowed\"\r\n },\r\n {\r\n \"manifest_id\": \"https://bar.example/index.html\",\r\n \"run_on_os_login\": \"allowed\"\r\n },\r\n {\r\n \"manifest_id\": \"https://foobar.example/index.html\",\r\n \"run_on_os_login\": \"run_windowed\",\r\n \"prevent_close_after_run_on_os_login\": true\r\n },\r\n {\r\n \"manifest_id\": \"*\",\r\n \"run_on_os_login\": \"blocked\"\r\n },\r\n {\r\n \"manifest_id\": \"https://foo.example/index.html\",\r\n \"force_unregister_os_integration\": true\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webappsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webappsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webappsettings_webappsettings","displayName":"Web App management settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webaudiooutputbufferingenabled","displayName":"Enable adaptive buffering for Web Audio","description":"This policy controls whether the browser uses adaptive buffering for\r\nWeb Audio, which may decrease audio glitches but may increase\r\nlatency by a variable amount.\r\n\r\nSetting the policy to Enabled will always use adaptive buffering.\r\n\r\nSetting the policy to Disabled or not set will allow the browser\r\nfeature launch process to decide if adaptive buffering is used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webaudiooutputbufferingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webaudiooutputbufferingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webauthenticationremotedesktopallowedorigins","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications.","description":"A list of origins of remote desktop client apps that may execute WebAuthn API\r\nrequests that originate from a browsing session on a remote host.\r\n\r\nAny origin configured in this policy can make WebAuthn requests for Relying\r\nParty IDs (RP IDs) that it would normally not allowed to be able to claim.\r\n\r\nOnly valid HTTPS origins are allowed. Wildcards are not supported.\r\nAny invalid entries are ignored.\r\n\r\nExample value:\r\n\r\nhttps://remotedesktop.google.com\r\nhttps://vdi.corp.example\r\nhttps://server:8080/","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webauthenticationremotedesktopallowedorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webauthenticationremotedesktopallowedorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webauthenticationremotedesktopallowedorigins_webauthenticationremotedesktopallowedoriginsdesc","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webrtctextlogcollectionallowed","displayName":"Allow WebRTC text logs collection from Google Services","description":"Setting the policy to enabled means Google Chrome can collect WebRTC text logs from Google services such as Google Meet and upload them to Google. These logs have diagnostic information for debugging issues with audio or video meetings in Google Chrome, such as textual metadata describing incoming and outgoing WebRTC streams, WebRTC specific log entries and additional system information. These logs have no audio or video content from the meeting.\r\nSetting the policy to disabled results in no uploading of such logs to Google. Logs would still accumulate locally on the user's device.\r\nLeaving the policy unset means Google Chrome defaults to being able to collect and upload these logs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webrtctextlogcollectionallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webrtctextlogcollectionallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livecaptionenabled","displayName":"Enable Live Caption","description":"Enable the Live Caption feature.\r\n\r\nIf this policy is set to Enabled, Live Caption will always be turned on.\r\n\r\nIf this policy is set to Disabled, Live Caption will always be turned off.\r\n\r\nIf you set this policy as mandatory, users cannot change or override it.\r\n\r\nIf this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.","helpText":"","infoUrls":[],"categoryId":"d9432f48-3072-4171-9031-4ebead394151","categoryName":"Accessibility settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livecaptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livecaptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livetranslateenabled","displayName":"Enable Live Translate","description":"Enable translation of live captions. Captions will be sent to Google for translation.\r\n\r\nIf this policy is set to Enabled, Live Translate will always be turned on.\r\n\r\nIf this policy is set to Disabled, Live Translate will always be turned off.\r\n\r\nIf you set this policy as mandatory, users cannot change or override it.\r\n\r\nIf this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime.\r\n\r\nIn LiveCaptionEnabled is set to Disabled, Live Translate will be disabled regardless of this policy setting.","helpText":"","infoUrls":[],"categoryId":"d9432f48-3072-4171-9031-4ebead394151","categoryName":"Accessibility settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livetranslateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livetranslateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_uiautomationproviderenabled","displayName":"Enable the browser's UI Automation accessibility framework provider on Windows","description":"Enables the UI Automation accessibility framework\r\nprovider in Google Chrome for use by\r\naccessibility tools.\r\n\r\nThis policy is supported in\r\nGoogle Chrome for a one-year\r\ntransition period to allow enterprise administrators to control the deployment\r\nof the browser's UI Automation accessibility\r\nframework provider. Accessibility and other tools that use the\r\nUI Automation accessibility framework to interoperate\r\nwith the browser may require updates to function properly with the browser's\r\nUI Automation provider. Administrators can use this\r\npolicy to temporarily disable the browser's\r\nUI Automation provider (thereby reverting to the old\r\nbehavior) while they work with vendors to provide updates to impacted tools.\r\n\r\nWhen set to false, Google Chrome only\r\nenables its Microsoft Active Accessibility\r\nprovider. Accessibility and other tools that use the newer\r\nUI Automation accessibility framework to interoperate\r\nwith the browser will communicate with it by way of a compatibility shim in\r\nMicrosoft® Windows®.\r\n\r\nWhen set to true, Google Chrome\r\nenables its UI Automation provider in addition to its\r\nMicrosoft Active Accessibility provider.\r\nAccessibility and other tools that use the newer\r\nUI Automation accessibility framework to interoperate\r\nwith the browser will communicate directly with it.\r\n\r\nWhen left unset, the variations framework in Google Chrome is used to enable or disable\r\nthe provider.\r\n\r\nSupport for this policy setting will end in Google Chrome 146.","helpText":"","infoUrls":[],"categoryId":"d9432f48-3072-4171-9031-4ebead394151","categoryName":"Accessibility settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_uiautomationproviderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_uiautomationproviderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled","displayName":"Allow automatic sign-in to Microsoft® cloud identity providers","description":"Configures automatic user sign-in for accounts backed by a Microsoft® cloud identity provider.\r\n\r\nBy setting this policy to 1 (Enabled), users who sign into their computer with an account backed by a Microsoft® cloud identity provider (i.e., Microsoft® Azure® Active Directory® or the consumer Microsoft® account identity provider) or who have added a work or school account to Microsoft® Windows® can be signed into web properties using that identity automatically. Information pertaining to the user's device and account is transmitted to the user's cloud identity provider for each authentication event.\r\n\r\nBy setting this policy to 0 (Disabled) or leaving it unset, automatic sign-in as described above is disabled.\r\n\r\nThis feature is available starting in Microsoft® Windows® 10.\r\n\r\nNote: This policy doesn't apply to Incognito or Guest modes.","helpText":"","infoUrls":[],"categoryId":"463e6791-7d54-4964-a36b-63bbedb7d0cd","categoryName":"Microsoft Active Directory management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_cloudapauthenabled","displayName":"Allow automatic sign-in to Microsoft® cloud identity providers (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"463e6791-7d54-4964-a36b-63bbedb7d0cd","categoryName":"Microsoft Active Directory management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_cloudapauthenabled_0","displayName":"Disable Microsoft® cloud authentication","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_cloudapauthenabled_1","displayName":"Enable Microsoft® cloud authentication","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout","displayName":"Delay before running idle actions","description":"Triggers an action when the computer is idle.\r\n\r\nIf this policy is set, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy.\r\n\r\nIf this policy is not set, no action will be ran.\r\n\r\nThe minimum threshold is 1 minute.\r\n\r\n\"User input\" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.","helpText":"","infoUrls":[],"categoryId":"8c35f124-e249-43e3-9044-ecc0b0a5855a","categoryName":"Idle Browser Actions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout_idletimeout","displayName":"Delay before running idle actions: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8c35f124-e249-43e3-9044-ecc0b0a5855a","categoryName":"Idle Browser Actions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions","displayName":"Actions to run when the computer is idle","description":"List of actions to run when the timeout from the IdleTimeout policy is reached.\r\n\r\nWarning: Setting this policy can impact and permanently remove local personal data. It is recommended to test your settings before deploying to prevent accidental deletion of personal data.\r\n\r\nIf the IdleTimeout policy is unset, this policy has no effect.\r\n\r\nWhen the timeout from the IdleTimeout policy is reached, the browser runs the actions configured in this policy.\r\n\r\nIf this policy is empty or left unset, the IdleTimeout policy has no effect.\r\n\r\nSupported actions are:\r\n\r\n'close_browsers': close all browser windows and PWAs for this profile. Not supported on Android and iOS.\r\n\r\n'close_tabs': close all open tabs in open windows. Only supported on iOS.\r\n\r\n'show_profile_picker': show the Profile Picker window. Not supported on Android and iOS.\r\n\r\n'sign_out': Signs out the current signed in user. Only supported on iOS.\r\n\r\n'clear_browsing_history', 'clear_download_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', 'clear_autofill', 'clear_site_settings', 'clear_hosted_app_data': clear the corresponding browsing data. See the ClearBrowsingDataOnExitList policy for more details. The types supported on iOS are 'clear_browsing_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', and 'clear_autofill'\r\n\r\n'reload_pages': reload all webpages. For some pages, the user may be prompted for confirmation first. Not supported on iOS.\r\n\r\nThe user will stay signed into their Google account when deleting cookies using 'clear_cookies_and_other_site_data'.\r\n\r\nSetting 'clear_browsing_history', 'clear_password_signing', 'clear_autofill', and 'clear_site_settings' will disable sync for the respective data types if neither `Chrome Sync` is disabled by setting the SyncDisabled policy nor BrowserSignin is disabled.\r\n\r\nExample value:\r\n\r\nclose_browsers\r\nshow_profile_picker","helpText":"","infoUrls":[],"categoryId":"8c35f124-e249-43e3-9044-ecc0b0a5855a","categoryName":"Idle Browser Actions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions_idletimeoutactionsdesc","displayName":"Actions to run when the computer is idle (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8c35f124-e249-43e3-9044-ecc0b0a5855a","categoryName":"Idle Browser Actions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates.","description":"Setting the policy to All (0) or leaving it unset lets users edit trust settings for all CA certificates, remove user-imported certificates, and import certificates using Certificate Manager. Setting the policy to UserOnly (1) lets users manage only user-imported certificates, but not change trust settings of built-in certificates. Setting it to None (2) lets users view (not manage) CA certificates.","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed_0","displayName":"Allow users to manage all certificates","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed_1","displayName":"Allow users to manage user certificates","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed_2","displayName":"Disallow users from managing certificates","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication","description":"A list of TLS certificates that should be trusted by Google Chrome for server authentication.\r\nCertificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_cacertificatesdesc","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication with constraints","description":"A list of TLS certificates that should be trusted by Google Chrome for server authentication, with constraints added outside the certificate. If no constraint of a certain type is present, then any name of that type is allowed.\r\nCertificates should be base64-encoded. At least one constraint must be specified for each certificate.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=CACertificatesWithConstraints for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"certificate\": \"MIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X\",\r\n \"constraints\": {\r\n \"permitted_dns_names\": [\r\n \"example.org\"\r\n ],\r\n \"permitted_cidrs\": [\r\n \"10.1.1.0/24\"\r\n ]\r\n }\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication with constraints (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cadistrustedcertificates","displayName":"TLS certificates that should be distrusted by Google Chrome for server authentication","description":"A list of certificate public keys that should be distrusted by Google Chrome for TLS server\r\nauthentication.\r\n\r\nThe policy value is a list of base64-encoded X.509 certificates. Any\r\ncertificate with a matching SPKI (SubjectPublicKeyInfo) will be distrusted.\r\n\r\nExample value:\r\n\r\nMIIB/TCCAaOgAwIBAgIUQthnWVsd1jWpUCNBf/uILjXC+t4wCgYIKoZIzj0EAwIwVDELMAkGA1UEBhMCVVMxETAPBgNVBAgMCFZpcmdpbmlhMQ8wDQYDVQQHDAZSZXN0b24xITAfBgNVBAoMGEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDAeFw0yMzEyMDcxNjE5NTVaFw0yMzEyMjExNjE5NTVaMFQxCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhWaXJnaW5pYTEPMA0GA1UEBwwGUmVzdG9uMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQ9Akav/KB0aVA9FM1QK4J1CEHn5rFOyY/nxcr5HG3+Fom0Kwu5zTR/kz9eOYgtG/1NmCzbiEKaULDfzA8V9aJ7o1MwUTAdBgNVHQ4EFgQUq37bLKiuw8Y/G+rurMf46hw7EekwHwYDVR0jBBgwFoAUq37bLKiuw8Y/G+rurMf46hw7EekwDwYDVR0TAQH/BAUwAwEB/zAKBggqhkjOPQQDAgNIADBFAiEA/JhtLSgtVOcXkgFJ9V5Vb6lhGdiKQFfzO9wTxPeCxCECIFePYPucys2n/r9MOBMHiX/8068ssv+uceqokzUg0mAb","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cadistrustedcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cadistrustedcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cadistrustedcertificates_cadistrustedcertificatesdesc","displayName":"TLS certificates that should be distrusted by Google Chrome for server authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication","description":"A list of certificates that are not trusted or distrusted in Google Chrome\r\nbut can be used as hints for path-building. Certificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIIFljCCA36gAwIBAgINAgO8U1lrNMcY9QFQZjANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjEwHhcNMjAwODEzMDAwMDQyWhcNMjcwOTMwMDAwMDQyWjBGMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzETMBEGA1UEAxMKR1RTIENBIDFDMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPWI3+dijB43+DdCkH9sh9D7ZYIl/ejLa6T/belaI+KZ9hzpkgOZE3wJCor6QtZeViSqejOEH9Hpabu5dOxXTGZok3c3VVP+ORBNtzS7XyV3NzsXlOo85Z3VvMO0Q+sup0fvsEQRY9i0QYXdQTBIkxu/t/bgRQIh4JZCF8/ZK2VWNAcmBA2o/X3KLu/qSHw3TT8An4Pf73WELnlXXPxXbhqW//yMmqaZviXZf5YsBvcRKgKAgOtjGDxQSYflispfGStZloEAoPtR28p3CwvJlk/vcEnHXG0g/Zm0tOLKLnf9LdwLtmsTDIwZKxeWmLnwi/agJ7u2441Rj72ux5uxiZ0CAwEAAaOCAYAwggF8MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQUinR/r4XN7pXNPZzQ4kYU83E1HScwHwYDVR0jBBgwFoAU5K8rJnEaK0gnhS9SZizv8IkTcT4waAYIKwYBBQUHAQEEXDBaMCYGCCsGAQUFBzABhhpodHRwOi8vb2NzcC5wa2kuZ29vZy9ndHNyMTAwBggrBgEFBQcwAoYkaHR0cDovL3BraS5nb29nL3JlcG8vY2VydHMvZ3RzcjEuZGVyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6Ly9jcmwucGtpLmdvb2cvZ3RzcjEvZ3RzcjEuY3JsMFcGA1UdIARQME4wOAYKKwYBBAHWeQIFAzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3BraS5nb29nL3JlcG9zaXRvcnkvMAgGBmeBDAECATAIBgZngQwBAgIwDQYJKoZIhvcNAQELBQADggIBAIl9rCBcDDy+mqhXlRu0rvqrpXJxtDaV/d9AEQNMwkYUuxQkq/BQcSLbrcRuf8/xam/IgxvYzolfh2yHuKkMo5uhYpSTld9brmYZCwKWnvy15xBpPnrLRklfRuFBsdeYTWU0AIAaP0+fbH9JAIFTQaSSIYKCGvGjRFsqUBITTcFTNvNCCK9U+o53UxtkOCcXCb1YyRt8OS1b887U7ZfbFAO/CVMkH8IMBHmYJvJh8VNS/UKMG2YrPxWhu//2m+OBmgEGcYk1KCTd4b3rGS3hSMs9WYNRtHTGnXzGsYZbr8w0xNPM1IERlQCh9BIiAfq0g3GvjLeMcySsN1PCAJA/Ef5c7TaUEDu9Ka7ixzpiO2xj2YC/WXGsYye5TBeg2vZzFb8q3o/zpWwygTMD0IZRcZk0upONXbVRWPeyk+gB9lm+cZv9TSjOz23HFtz30dZGm6fKa+l3D/2gthsjgx0QGtkJAITgRNOidSOzNIb2ILCkXhAd4FJGAJ2xDx8hcFH1mt0G/FX0Kw4zd8NLQsLxdxP8c4CU6x+7Nz/OAipmsHMdMqUybDKwjuDEI/9bfU1lcKwrmz3O2+BtjjKAvpafkmO8l7tdufThcV4q5O8DIrGKZTqPwJNl1IXNDw9bg1kWRxYtnCQ6yICmJhSFm/Y3m6xv+cXDBlHz4n/FsRC6UfTd","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_cahintcertificatesdesc","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled","displayName":"Use user-added TLS certificates from platform trust stores for server authentication","description":"If enabled(or not set), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.\r\n\r\nIf disabled, user-added TLS certificates from platform trust stores will not be used in path-building for TLS server authentication.","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls","displayName":"Allow automatic fullscreen on these sites","description":"For security reasons, the\r\nrequestFullscreen() web API\r\nrequires a prior user gesture (\"transient activation\") to be called or will\r\notherwise fail. Users' personal settings may allow certain origins to call\r\nthis API without a prior user gesture, as described in\r\nhttps://chromestatus.com/feature/6218822004768768.\r\n\r\nThis policy supersedes users' personal settings and allows matching origins to\r\ncall the API without a prior user gesture.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nOrigins matching both blocked and allowed policy patterns will be blocked.\r\nOrigins not specified by policy nor user settings will require a prior user\r\ngesture to call this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls_automaticfullscreenallowedforurlsdesc","displayName":"Allow automatic fullscreen on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenblockedforurls","displayName":"Block automatic fullscreen on these sites","description":"For security reasons, the\r\nrequestFullscreen() web API\r\nrequires a prior user gesture (\"transient activation\") to be called or will\r\notherwise fail. Users' personal settings may allow certain origins to call\r\nthis API without a prior user gesture, as described in\r\nhttps://chromestatus.com/feature/6218822004768768.\r\n\r\nThis policy supersedes users' personal settings and blocks matching origins\r\nfrom calling the API without a prior user gesture.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nOrigins matching both blocked and allowed policy patterns will be blocked.\r\nOrigins not specified by policy nor user settings will require a prior user\r\ngesture to call this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenblockedforurls_automaticfullscreenblockedforurlsdesc","displayName":"Block automatic fullscreen on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardallowedforurls","displayName":"Allow clipboard on these sites","description":"Setting the policy lets you set a list of URL patterns that specify sites that can use the clipboard site permission. This does not include all clipboard operations on origins matching the patterns. For instance, users will still be able to paste using keyboard shortcuts as this isn't gated by the clipboard site permission.\r\n\r\n\r\nLeaving the policy unset means DefaultClipboardSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardallowedforurls_clipboardallowedforurlsdesc","displayName":"Allow clipboard on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardblockedforurls","displayName":"Block clipboard on these sites","description":"Setting the policy lets you set a list of URL patterns that specify sites that can't use the clipboard site permission. This does not include all clipboard operations on origins matching the patterns. For instance, users will still be able to paste using keyboard shortcuts as this isn't gated by the clipboard site permission.\r\n\r\nLeaving the policy unset means DefaultClipboardSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardblockedforurls_clipboardblockedforurlsdesc","displayName":"Block clipboard on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_dataurlinsvguseenabled","displayName":"Data URL support for SVGUseElement.","description":"This policy enables Data URL support for SVGUseElement, which will be disabled\r\nby default starting in M119.\r\nIf this policy is set to Enabled, Data URLs will continue to work in SVGUseElement.\r\nIf this policy is set to Disabled or not set, Data URLs won't work in SVGUseElement.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_dataurlinsvguseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_dataurlinsvguseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultclipboardsetting","displayName":"Default clipboard setting","description":"Setting the policy to 2 blocks sites from using the clipboard site permission. Setting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use one.\r\n\r\nThis policy can be overridden for specific URL patterns using the ClipboardAllowedForUrls and ClipboardBlockedForUrls policies.\r\n\r\nThis policy only affects clipboard operations controlled by the clipboard site permission, and does not affect sanitized clipboard writes or trusted copy and paste operations.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultclipboardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultclipboardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultclipboardsetting_defaultclipboardsetting","displayName":"Default clipboard setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultclipboardsetting_defaultclipboardsetting_2","displayName":"Do not allow any site to use the clipboard site permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultclipboardsetting_defaultclipboardsetting_3","displayName":"Allow sites to ask the user to grant the clipboard site permission","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers","description":"Allows you to set whether Google Chrome\r\nwill run the v8 JavaScript engine with more advanced JavaScript optimizations enabled.\r\n\r\nDisabling JavaScript optimizations (by setting this policy's value to 2) will\r\nmean that Google Chrome may render web\r\ncontent more slowly.\r\n\r\nThis policy can be overridden for specific URL patterns using the JavaScriptOptimizerAllowedForSites and JavaScriptOptimizerBlockedForSites policies.\r\n\r\nIf this policy is left not set, JavaScript optimizations are enabled.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting_1","displayName":"Enable advanced JavaScript optimizations on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting_2","displayName":"Disable advanced JavaScript optimizations on all sites","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting","description":"Setting the policy to BlockLocalFonts (value 2) automatically denies the local fonts permission to sites by default. This will limit the ability of sites to see information about local fonts.\r\n\r\nSetting the policy to AskLocalFonts (value 3) will prompt the user when the local fonts permission is requested by default. If users allow the permission, it will extend the ability of sites to see information about local fonts.\r\n\r\nLeaving the policy unset means the default behavior applies which is to prompt the user, but users can change this setting","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_2","displayName":"Denies the Local Fonts permission on all sites by default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_3","displayName":"Ask every time a site wants obtain the Local Fonts permission","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting","displayName":"Control use of the WebHID API","description":"Setting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.\r\n\r\nThis policy can be overridden for specific url patterns using the WebHidAskForUrls and WebHidBlockedForUrls policies.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_defaultwebhidguardsetting","displayName":"Control use of the WebHID API (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_defaultwebhidguardsetting_2","displayName":"Do not allow any site to request access to HID devices via the WebHID API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_defaultwebhidguardsetting_3","displayName":"Allow sites to ask the user to grant access to a HID device","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting","description":"Setting the policy to BlockWindowManagement (value 2) automatically denies the window management permission to sites by default. This will limit the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nSetting the policy to AskWindowManagement (value 3) will prompt the user when the window management permission is requested by default. If users allow the permission, it will extend the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nLeaving the policy unset means the AskWindowManagement policy applies, but users can change this setting.\r\n\r\nThis replaces the deprecated DefaultWindowPlacementSetting policy.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_defaultwindowmanagementsetting_2","displayName":"Denies the Window Management permission on all sites by default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_defaultwindowmanagementsetting_3","displayName":"Ask every time a site wants obtain the Window Management permission","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites","description":"Allows you to set a list of site url patterns that specify sites for which\r\nadvanced JavaScript optimizations are enabled.\r\n\r\nFor detailed information on valid site url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site\r\ngranularity (eTLD+1). A policy set for only subdomain.site.com will not\r\ncorrectly apply to site.com or subdomain.site.com since they both resolve to\r\nthe same eTLD+1 (site.com) for which there is no policy. In this case, policy\r\nmust be set on site.com to apply correctly for both site.com and\r\nsubdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level\r\norigin url alone, so e.g. if site-one.com is listed in the JavaScriptOptimizerAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript optimizations\r\nenabled, but site-two.com will use the policy from DefaultJavaScriptOptimizerSetting, if set, or default to JavaScript\r\noptimizations enabled. Blocklist entries have higher priority than allowlist\r\nentries, which in turn have higher priority than the configured default value.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise\r\nJavascript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites_javascriptoptimizerallowedforsitesdesc","displayName":"Allow JavaScript optimization on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites","description":"Allows you to set a list of site url patterns that specify sites for which\r\nadvanced JavaScript optimizations are disabled.\r\n\r\nDisabling JavaScript optimizations will mean that Google Chrome may render web content more slowly.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site\r\ngranularity (eTLD+1). A policy set for only subdomain.site.com will not\r\ncorrectly apply to site.com or subdomain.site.com since they both resolve to\r\nthe same eTLD+1 (site.com) for which there is no policy. In this case, policy\r\nmust be set on site.com to apply correctly for both site.com and\r\nsubdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level\r\norigin url alone, so e.g. if site-one.com is listed in the JavaScriptOptimizerBlockedForSites policy but site-one.com loads a frame\r\ncontaining site-two.com then site-one.com will have JavaScript optimizations\r\ndisabled, but site-two.com will use the policy from DefaultJavaScriptOptimizerSetting, if set, or default to JavaScript\r\noptimizations enabled. Blocklist entries have higher priority than allowlist\r\nentries, which in turn have higher priority than the configured default value.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise\r\nJavaScript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites_javascriptoptimizerblockedforsitesdesc","displayName":"Block JavaScript optimizations on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls","displayName":"Allow Local Fonts permission on these sites","description":"Sets a list of site url patterns that specify sites which will automatically grant the local fonts permission. This will extend the ability of sites to see information about local fonts.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls_localfontsallowedforurlsdesc","displayName":"Allow Local Fonts permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsblockedforurls","displayName":"Block Local Fonts permission on these sites","description":"Sets a list of site url patterns that specify sites which will automatically deny the local fonts permission. This will limit the ability of sites to see information about local fonts.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsblockedforurls_localfontsblockedforurlsdesc","displayName":"Block Local Fonts permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_partitionedbloburlusage","displayName":"Choose whether Blob URLs are partitioned during fetching and navigations","description":"This policy controls whether Blob URLs are partitioned during fetching and navigation.\r\nIf this policy is set to Enabled or not set, Blob URLs will be partitioned.\r\nIf this policy is set to Disabled, Blob URLs won't be partitioned.\r\n\r\nIf storage partitioning is disabled for a given top-level origin by either\r\nThirdPartyStoragePartitioningBlockedForOrigins\r\nor DefaultThirdPartyStoragePartitioningSetting,\r\nthen Blob URLs will also not be partitioned.\r\n\r\nIf you must use the policy, please file a bug at\r\nGoogle Chrome\r\nexplaining your use case. The policy is scheduled to be offered through\r\nGoogle Chrome version 143, after which\r\nthe old implementation will be removed.\r\n\r\nNOTE: Only newly-started renderer processes will reflect changes to this\r\npolicy while the browser is running.\r\n\r\nFor detailed information on third-party storage partitioning, please see\r\nhttps://developers.google.com/privacy-sandbox/cookies/storage-partitioning.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_partitionedbloburlusage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_partitionedbloburlusage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_pdflocalfileaccessallowedfordomains","displayName":"Allow local file access to file:// URLs on these sites in the PDF Viewer","description":"Setting this policy allows the domains listed to access file:// URLs in the PDF Viewer.\r\nAdding to the policy allows the domain to access file:// URLs in the PDF Viewer.\r\nRemoving from the policy disallows the domain from accessing file:// URLs in the PDF Viewer.\r\nLeaving the policy unset disallows all domains from accessing file:// URLs in the PDF Viewer.\r\n\r\nExample value:\r\n\r\nexample.com\r\ngoogle.com","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_pdflocalfileaccessallowedfordomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_pdflocalfileaccessallowedfordomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_pdflocalfileaccessallowedfordomains_pdflocalfileaccessallowedfordomainsdesc","displayName":"Allow local file access to file:// URLs on these sites in the PDF Viewer (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls","displayName":"Automatically grant permission to sites to connect to any HID device.","description":"Setting the policy allows you to list sites which are automatically granted permission to access all available devices.\r\n\r\nThe URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered.\r\n\r\nOn ChromeOS, this policy only applies to affiliated users.\r\n\r\nThis policy overrides DefaultWebHidGuardSetting, WebHidAskForUrls, WebHidBlockedForUrls and the user's preferences.\r\n\r\nExample value:\r\n\r\nhttps://google.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_webhidallowalldevicesforurlsdesc","displayName":"Automatically grant permission to sites to connect to any HID device. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices with the given vendor and product IDs.","description":"Setting the policy lets you list the URLs that specify which sites are automatically granted permission to access a HID device with the given vendor and product IDs. Each item in the list requires both devices and urls fields for the item to be valid, otherwise the item is ignored. Each item in the devices field must have a vendor_id and may have a product_id field. Omitting the product_id field will create a policy matching any device with the specified vendor ID. An item which has a product_id field without a vendor_id field is invalid and is ignored.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies, if it's set. If not, the user's personal setting applies.\r\n\r\nURLs in this policy shouldn't conflict with those configured through WebHidBlockedForUrls. If they do, this policy takes precedence over WebHidBlockedForUrls.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebHidAllowDevicesForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"product_id\": 5678,\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://google.com\",\r\n \"https://chromium.org\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls_webhidallowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices with the given vendor and product IDs. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage.","description":"Setting the policy lets you list the URLs that specify which sites are automatically granted permission to access a HID device containing a top-level collection with the given HID usage. Each item in the list requires both usages and urls fields for the policy to be valid. Each item in the usages field must have a usage_page and may have a usage field. Omitting the usage field will create a policy matching any device containing a top-level collection with a usage from the specified usage page. An item which has a usage field without a usage_page field is invalid and is ignored.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies, if it's set. If not, the user's personal setting applies.\r\n\r\nURLs in this policy shouldn't conflict with those configured through WebHidBlockedForUrls. If they do, this policy takes precedence over WebHidBlockedForUrls.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebHidAllowDevicesWithHidUsagesForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"urls\": [\r\n \"https://google.com\",\r\n \"https://chromium.org\"\r\n ],\r\n \"usages\": [\r\n {\r\n \"usage\": 5678,\r\n \"usage_page\": 1234\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdeviceswithhidusagesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdeviceswithhidusagesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdeviceswithhidusagesforurls_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls","displayName":"Allow the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns which do not match the policy, the following take precedence, in this order:\r\n\r\n * WebHidBlockedForUrls (if there is a match),\r\n\r\n * DefaultWebHidGuardSetting (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns must not conflict with WebHidBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://google.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_webhidaskforurlsdesc","displayName":"Allow the WebHID API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidblockedforurls","displayName":"Block the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns which do not match the policy, the following take precedence, in this order:\r\n\r\n * WebHidAskForUrls (if there is a match),\r\n\r\n * DefaultWebHidGuardSetting (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns can't conflict with WebHidAskForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://google.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidblockedforurls_webhidblockedforurlsdesc","displayName":"Block the WebHID API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls","displayName":"Allow Window Management permission on these sites","description":"Allows you to set a list of site url patterns that specify sites which will automatically grant the window management permission. This will extend the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nThis replaces the deprecated WindowPlacementAllowedForUrls policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls_windowmanagementallowedforurlsdesc","displayName":"Allow Window Management permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls","displayName":"Block Window Management permission on these sites","description":"Allows you to set a list of site url patterns that specify sites which will automatically deny the window management permission. This will limit the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nThis replaces the deprecated WindowPlacementBlockedForUrls policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_windowmanagementblockedforurlsdesc","displayName":"Block Window Management permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultthirdpartystoragepartitioningsetting","displayName":"Default third-party storage partitioning setting","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultthirdpartystoragepartitioningsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultthirdpartystoragepartitioningsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting","displayName":"Default third-party storage partitioning setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting_1","displayName":"Allow third-party storage partitioning by default.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting_2","displayName":"Disable third-party storage partitioning.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultwindowplacementsetting","displayName":"Default Window Placement permission setting","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultwindowplacementsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultwindowplacementsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultwindowplacementsetting_defaultwindowplacementsetting","displayName":"Default Window Placement permission setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultwindowplacementsetting_defaultwindowplacementsetting_2","displayName":"Denies the Window Placement permission on all sites by default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultwindowplacementsetting_defaultwindowplacementsetting_3","displayName":"Ask every time a site wants obtain the Window Placement permission","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins","displayName":"Disable third-party storage partitioning for specific top-level origins","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nwww.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins_thirdpartystoragepartitioningblockedfororiginsdesc","displayName":"Disable third-party storage partitioning for specific top-level origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction","displayName":"Enable or disable the User-Agent Reduction.","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_useragentreduction","displayName":"Enable or disable the User-Agent Reduction. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_useragentreduction_0","displayName":"Reduced User Agent.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_useragentreduction_1","displayName":"Full (legacy) User Agent.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_useragentreduction_2","displayName":"Reduced User Agent.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls","displayName":"Allow Window Placement permission on these sites","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls_windowplacementallowedforurlsdesc","displayName":"Allow Window Placement permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls","displayName":"Block Window Placement permission on these sites","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls_windowplacementblockedforurlsdesc","displayName":"Block Window Placement permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page","description":"Control if users can turn on Developer Mode on chrome://extensions.\r\n\r\nIf the policy is not set, users can turn on developer mode on extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\r\nIf the policy is set to Allow (0), users can turn on developer mode on extensions page.\r\nIf the policy is set to Disallow (1), users can not turn on developer mode on extensions page.\r\n\r\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings_0","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings_1","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant extended background lifetime to the connecting extensions.","description":"Extensions that connect to one of these origins will be be kept running as long as the port is connected.\r\n\r\nIf unset, the policy's default values will be used. These are app origins that offer SDKs that are known to not offer the possibility to restart a closed connection to a previous state:\r\n- Smart Card Connector\r\n- Citrix Receiver (stable, beta, back-up)\r\n- VMware Horizon (stable, beta)\r\n\r\nIf set, the default value list is extended with the newly configured values. Both defaults and the policy-provided entries will grant the exception to the connecting extensions, as long as the port is connected.\r\n\r\nExample value:\r\n\r\nchrome-extension://abcdefghijklmnopabcdefghijklmnop/\r\nchrome-extension://bcdefghijklmnopabcdefghijklmnopa/","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_extensionextendedbackgroundlifetimeforportconnectionstourlsdesc","displayName":"Configure a list of origins that grant extended background lifetime to the connecting extensions. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist","displayName":"Blocklist for install types of extensions","description":"The blocklist controls which extensions install types are disallowed.\r\n\r\nSetting \"command_line\" will block extension from being loaded from\r\ncommand line.\r\n\r\nExample value:\r\n\r\ncommand_line","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_extensioninstalltypeblocklistdesc","displayName":"Blocklist for install types of extensions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability","displayName":"Control availability of extensions unpublished on the Chrome Web Store.","description":"If this policy is enabled, extensions that are unpublished on the Chrome Web\r\nStore will be disabled in Google Chrome.\r\nThis policy only applies to extensions that are installed and updated from the\r\nChrome Web Store.\r\n\r\nOff-store extensions such as unpacked extensions installed using developer\r\nmode and extensions installed using the command-line switch are ignored.\r\nForce-installed extensions that are self-hosted are ignored. All\r\nversion-pinned extensions are also ignored.\r\n\r\nIf the policy is set to AllowUnpublished (0) or not set, extensions that are unpublished on the Chrome Web Store are allowed.\r\nIf the policy is set to DisableUnpublished (1), extensions that are unpublished on the Chrome Web Store are disabled.","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_extensionunpublishedavailability","displayName":"Control availability of extensions unpublished on the Chrome Web Store. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_extensionunpublishedavailability_0","displayName":"Allow unpublished extensions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_extensionunpublishedavailability_1","displayName":"Disable unpublished extensions","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsenabled","displayName":"Enable First-Party Sets.","description":"This policy is provided as a way to opt-out of the First-Party Sets feature.\r\n\r\nWhen this policy is unset or set to Enabled, the First-Party Sets feature is enabled.\r\n\r\nWhen this policy is set to Disabled, the First-Party Sets feature is disabled.\r\n\r\nIt controls whether Chrome supports First-Party Sets related integrations.\r\n\r\nThis is the equivalent of the RelatedWebsiteSetsEnabled policy.\r\nEither policy may be used, but this one will be deprecated soon so the RelatedWebsiteSetsEnabled policy is preferred.\r\nThey both have the same effect on the browser's behavior.","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides","displayName":"Override First-Party Sets.","description":"This policy provides a way to override the list of sets the browser uses for First-Party Sets features.\r\n\r\nEach set in the browser's list of First-Party Sets must meet the requirements of a First-Party Set.\r\nA First-Party Set must contain a primary site and one or more member sites.\r\nA set can also contain a list of service sites that it owns, as well as a map from a site to all of its ccTLD variants.\r\nSee https://github.com/WICG/first-party-sets for more information on First-Party Sets are used by Google Chrome.\r\n\r\nAll sites in a First-Party Set must be a registrable domain served over HTTPS. Each site in a First-Party Set must also be unique,\r\nmeaning a site cannot be listed more than once in a First-Party Set.\r\n\r\nWhen this policy is given an empty dictionary, the browser uses the public list of First-Party Sets.\r\n\r\nFor all sites in a First-Party Set from the replacements list, if a site is also present\r\non a First-Party Set in the browser's list, then that site will be removed from the browser's First-Party Set.\r\nAfter this, the policy's First-Party Set will be added to the browser's list of First-Party Sets.\r\n\r\nFor all sites in a First-Party Set from the additions list, if a site is also present\r\non a First-Party Set in the browser's list, then the browser's First-Party Set will be updated so that the\r\nnew First-Party Set can be added to the browser's list. After the browser's list has been updated,\r\nthe policy's First-Party Set will be added to the browser's list of First-Party Sets.\r\n\r\nThe browser's list of First-Party Sets requires that for all sites in its list, no site is in\r\nmore than one set. This is also required for both the replacements list\r\nand the additions list. Similarly, a site cannot be in both the\r\nreplacements list and the additions list.\r\n\r\nWildcards (*) are not supported as a policy value, nor within any First-Party Set in these lists.\r\n\r\nAll sets provided by the policy must be valid First-Party Sets, if they aren't then an\r\nappropriate error will be outputted.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\n\r\nThis is the equivalent of the RelatedWebsiteSetsOverrides policy.\r\nEither policy may be used, but this one will be deprecated soon so the RelatedWebsiteSetsOverrides policy is preferred.\r\nThey both have the same effect on the browser's behavior.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=FirstPartySetsOverrides for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"additions\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate2.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate2.test\": [\r\n \"https://associate2.com\"\r\n ]\r\n },\r\n \"primary\": \"https://primary2.test\",\r\n \"serviceSites\": [\r\n \"https://associate2-content.test\"\r\n ]\r\n }\r\n ],\r\n \"replacements\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate1.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate1.test\": [\r\n \"https://associate1.co.uk\"\r\n ]\r\n },\r\n \"primary\": \"https://primary1.test\",\r\n \"serviceSites\": [\r\n \"https://associate1-content.test\"\r\n ]\r\n }\r\n ]\r\n}","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_firstpartysetsoverrides","displayName":"Override First-Party Sets. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings","displayName":"Settings for Google's AI Mode integrations in the address bar and New Tab page search box.","description":"This policy controls Google's AI Mode integrations in the address bar and the New Tab page search box.\r\n\r\nTo access this feature, Google must be set as the user's default search engine.\r\n\r\n0/unset = The feature will be available to users.\r\n\r\n1 = The feature will not be available to users.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_aimodesettings","displayName":"Settings for Google's AI Mode integrations in the address bar and New Tab page search box. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_aimodesettings_0","displayName":"Allow AI Mode integrations.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_aimodesettings_1","displayName":"Do not allow AI Mode integrations.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings","displayName":"Settings for enhanced autofill","description":"Specifies whether users can let Google Chrome use Generative AI to better understand forms and help them fill more fields.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings_autofillpredictionsettings","displayName":"Settings for enhanced autofill (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings_autofillpredictionsettings_0","displayName":"Allow enhanced autofill and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings_autofillpredictionsettings_1","displayName":"Allow enhanced autofill without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings_autofillpredictionsettings_2","displayName":"Do not allow enhanced autofill.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings","displayName":"Settings for Create Themes with AI","description":"Create Themes with AI lets users create custom themes/wallpapers by preselecting from a list of options.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings_createthemessettings","displayName":"Settings for Create Themes with AI (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings_createthemessettings_0","displayName":"Allow Create Themes and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings_createthemessettings_1","displayName":"Allow Create Themes without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings_createthemessettings_2","displayName":"Do not allow Create Themes.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings","displayName":"Settings for DevTools Generative AI Features","description":"These features in Google Chrome's DevTools employ generative AI models to provide additional debugging information. To use these features, Google Chrome has to collect data such as error messages, stack traces, code snippets, and network requests and send them to a server owned by Google, which runs a generative AI model. Response body or authentication and cookie headers in network requests are not included in the data sent to the server.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nDevTools Generative AI features include:\r\n\r\n- Console Insights: explains console messages and offers suggestions on how to fix console errors.\r\n\r\n- AI assistance: get help with understanding CSS styles (since version 131), network requests, performance, and files (all since version 132).\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings_devtoolsgenaisettings","displayName":"Settings for DevTools Generative AI Features (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings_devtoolsgenaisettings_0","displayName":"Allow DevTools Generative AI Features and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings_devtoolsgenaisettings_1","displayName":"Allow DevTools Generative AI Features without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings_devtoolsgenaisettings_2","displayName":"Do not allow DevTools Generative AI Features.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings","displayName":"Settings for Gemini integration","description":"This setting allows Gemini app integrations.\r\n\r\n0/unset = Gemini integration will be available for users.\r\n\r\n1 = Gemini integration will not be available for users.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information, please check the Help Center article https://support.google.com/chrome/a?p=gemini_in_chrome.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_geminisettings","displayName":"Settings for Gemini integration (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_geminisettings_0","displayName":"Allow Gemini integrations.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_geminisettings_1","displayName":"Do not allow Gemini integrations.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings","displayName":"Settings for GenAI local foundational model","description":"Configure how Google Chrome downloads the foundational GenAI model and uses for inference locally.\r\n\r\nWhen the policy is set to Allowed (0) or not set, the model is downloaded automatically, and used for inference.\r\n\r\nWhen the policy is set to Disabled (1), the model will not be downloaded.\r\n\r\nModel downloading can also be disabled by ComponentUpdatesEnabled.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings","displayName":"Settings for GenAI local foundational model (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings_0","displayName":"Downloads model automatically","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings_1","displayName":"Do not download model","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings","displayName":"Settings for Help Me Write","description":"Help Me Write is an AI-based writing assistant for short-form content on the web. Suggested content is based on prompts entered by the user and the content of the web page.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings","displayName":"Settings for Help Me Write (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_0","displayName":"Allow Help Me Write and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_1","displayName":"Allow Help Me Write without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_2","displayName":"Do not allow Help Me Write.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings","displayName":"Settings for AI-powered History Search","description":"AI History Search is a feature that allows users to search their browsing history and receive generated answers based on page contents and not just the page title and URL.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings","displayName":"Settings for AI-powered History Search (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings_0","displayName":"Allow AI History Search and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings_1","displayName":"Allow AI History Search without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings_2","displayName":"Do not allow AI History Search.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings","displayName":"Tab Compare settings","description":"Tab Compare is an AI-powered tool for comparing information across a user's tabs. As an example, the feature can be offered to the user when multiple tabs with products in a similar category are open.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_tabcomparesettings","displayName":"Tab Compare settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_tabcomparesettings_0","displayName":"Allow Tab Compare and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_tabcomparesettings_1","displayName":"Allow Tab Compare without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_tabcomparesettings_2","displayName":"Do not allow Tab Compare.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration","displayName":"Specifies how long (in seconds) a cast device selected with an access code or QR code stays in the Google Cast menu's list of cast devices.","description":"This policy specifies how long (in seconds) a cast device that was previously selected via an access code or QR code can be seen within the Google Cast menu of cast devices.\r\nThe lifetime of an entry starts at the time the access code was first entered or the QR code was first scanned.\r\nDuring this period the cast device will appear in the Google Cast menu's list of cast devices.\r\nAfter this period, in order to use the cast device again the access code must be reentered or the QR code must be rescanned.\r\nBy default, the period is zero seconds, so cast devices will not stay in the Google Cast menu, and so the access code must be reentered, or the QR code rescanned, in order to initiate a new casting session.\r\nNote that this policy only affects how long a cast devices appears in the Google Cast menu, and has no effect on any ongoing cast session which will continue even if the period expires.\r\nThis policy has no effect unless the AccessCodeCastEnabled policy is Enabled.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration_accesscodecastdeviceduration","displayName":"Specifies how long (in seconds) a cast device selected with an access code or QR code stays in the Google Cast menu's list of cast devices.: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastenabled","displayName":"Allow users to select cast devices with an access code or QR code from within the Google Cast menu.","description":"This policy controls whether a user will be presented with an option, within the Google Cast menu which allows them to cast to cast devices that do not appear in the Google Cast menu, using either the access code or QR code displayed on the cast devices's screen.\r\nBy default, a user must reenter the access code or rescan the QR code in order to initiate a subsequent casting session, but if the AccessCodeCastDeviceDuration policy has been set to a non-zero value (the default is zero), then the cast device will remain in the list of available cast devices until the specified period of time has expired.\r\nWhen this policy is set to Enabled, users will be presented with the option to select cast devices by using an access code or by scanning a QR code.\r\nWhen this policy is set to Disabled or not set, users will not be given the option to select cast devices by using an access code or by scanning a QR code.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_showcastsessionsstartedbyotherdevices","displayName":"Show media controls for Google Cast sessions started by other devices on the local network","description":"When this policy is enabled, media playback controls UI is available for Google Cast sessions started by other devices on the local network.\r\n\r\nWhen this policy is unset for enterprise users or is disabled, media playback controls UI is unavailable for Google Cast sessions started by other devices on the local network.\r\n\r\nIf the policy EnableMediaRouter is disabled, then this policy's value has no effect, as the entire Google Cast functionality is disabled.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_showcastsessionsstartedbyotherdevices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_showcastsessionsstartedbyotherdevices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins","displayName":"List of origins allowing all HTTP authentication","description":"Setting the policy specifies for which origins to allow all the HTTP authentication schemes Google Chrome supports regardless of the AuthSchemes policy.\r\n\r\nFormat the origin pattern according to this format (https://support.google.com/chrome/a?p=url_blocklist_filter_format). Up to 1,000 exceptions can be defined in AllHttpAuthSchemesAllowedForOrigins.\r\nWildcards are allowed for the whole origin or parts of the origin, either the scheme, host, port.\r\n\r\nExample value:\r\n\r\n*.example.com","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins_allhttpauthschemesallowedfororiginsdesc","displayName":"List of origins allowing all HTTP authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls","displayName":"Allow sites to make requests to local network endpoints.","description":"List of URL patterns. Requests initiated from websites served by matching origins are not subject to Local Network Access checks.\r\n\r\nIf an origin is covered by both this policy and by LocalNetworkAccessBlockedForUrls, LocalNetworkAccessBlockedForUrls takes precedence.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_localnetworkaccessallowedforurlsdesc","displayName":"Allow sites to make requests to local network endpoints. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls","displayName":"Block sites from making requests to local network endpoints.","description":"List of URL patterns. Requests initiated from websites served by matching origins are blocked from issuing Local Network Access requests.\r\n\r\nIf an origin is covered by both this policy and by LocalNetworkAccessAllowedForUrls, this policy takes precedence.\r\n\r\nDepending on the stage of the rollout of Local Network Access, LocalNetworkAccessRestrictionsEnabled may also need to be enabled for this policy to block Local Network Access requests.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls_localnetworkaccessblockedforurlsdesc","displayName":"Block sites from making requests to local network endpoints. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to apply restrictions to requests to local network endpoints","description":"When this policy is set to Enabled, any time when a warning is supposed to be\r\ndisplayed in the DevTools due to Local Network Access checks failing, the\r\nmain request will be blocked instead.\r\n\r\nWhen this policy is set to Disabled or unset, Local Network Access requests will use the\r\ndefault handling of these requests.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessrestrictionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessrestrictionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_accesscontrolallowmethodsincorspreflightspecconformant","displayName":"Make Access-Control-Allow-Methods matching in CORS preflight spec conformant","description":"This policy controls whether request methods are uppercased when matching with Access-Control-Allow-Methods response headers in CORS preflight.\r\n\r\nIf the policy is Disabled, request methods are uppercased.\r\nThis is the behavior on or before Google Chrome 108.\r\n\r\nIf the policy is Enabled or not set, request methods are not uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT.\r\nThis would reject fetch(url, {method: 'Foo'}) + \"Access-Control-Allow-Methods: FOO\" response header,\r\nand would accept fetch(url, {method: 'Foo'}) + \"Access-Control-Allow-Methods: Foo\" response header.\r\n\r\nNote: request methods \"post\" and \"put\" are not affected, while \"patch\" is affected.\r\n\r\nThis policy is intended to be temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"fa2722a8-dcfd-4e14-a429-2b0041642c77","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_accesscontrolallowmethodsincorspreflightspecconformant_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_accesscontrolallowmethodsincorspreflightspecconformant_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_compressiondictionarytransportenabled","displayName":"Enable compression dictionary transport support","description":"This feature enables the use of dictionary-specific content encodings in the Accept-Encoding request header (\"sbr\" and \"zst-d\") when dictionaries are available for use.\r\n\r\nSetting the policy to Enabled or leaving it unset means Google Chrome will accept web contents using the compression dictionary transport feature.\r\nSetting the policy to Disabled turns off the compression dictionary transport feature.","helpText":"","infoUrls":[],"categoryId":"fa2722a8-dcfd-4e14-a429-2b0041642c77","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_compressiondictionarytransportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_compressiondictionarytransportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_dataurlwhitespacepreservationenabled","displayName":"DataURL Whitespace Preservation for all media types","description":"This policy provides a temporary opt-out for changes to how Chrome handles whitepsace in data URLS.\r\nPreviously, whitespace would be kept only if the top level media type was text or contained the media type string xml.\r\nNow, whitespace will be preserved in all data URLs, regardless of media type.\r\n\r\nIf this policy is left unset or is set to True, the new behavior is enabled.\r\n\r\nWhen this policy is set to False, the old behavior is enabled.","helpText":"","infoUrls":[],"categoryId":"fa2722a8-dcfd-4e14-a429-2b0041642c77","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_dataurlwhitespacepreservationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_dataurlwhitespacepreservationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_happyeyeballsv3enabled","displayName":"Use the Happy Eyeballs V3 algorithm","description":"This feature enables the Happy Eyeballs V3 algorithm to make connection attempts. See https://datatracker.ietf.org/doc/draft-pauly-happy-happyeyeballs-v3 for details.\r\n\r\nSetting the policy to Enabled means Google Chrome will use the Happy Eyeballs V3 algorithm for connection attempts.\r\n\r\nSetting the policy to Disabled turns off the Happy Eyeballs V3 algorithm.\r\n\r\nNot setting the policy, Google Chrome will turn on or off the Happy Eyeballs V3 algorithm based on chrome://flags/#happy-eyeballs-v3.\r\n\r\nThis policy supports dynamic refresh.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Google Chrome.","helpText":"","infoUrls":[],"categoryId":"fa2722a8-dcfd-4e14-a429-2b0041642c77","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_happyeyeballsv3enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_happyeyeballsv3enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_ipv6reachabilityoverrideenabled","displayName":"Enable IPv6 reachability check override","description":"Setting the policy to true overrides the IPv6 reachability check. This means that the\r\nsystem will always query AAAA records when resolving host names. It applies to\r\nall users and interfaces on the device.\r\n\r\nSetting the policy to false or leaving it unset does not overrides the IPv6 reachability check.\r\nThe system only queries AAAA records when it is reachable to a global IPv6 host.","helpText":"","infoUrls":[],"categoryId":"fa2722a8-dcfd-4e14-a429-2b0041642c77","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_ipv6reachabilityoverrideenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_ipv6reachabilityoverrideenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings","displayName":"Enable automated password change","description":"This policy controls the availability of Google Chrome's automated password change feature.\r\n\r\nIf enabled, a user can trigger a process where the browser attempts to change their password on a website automatically. This process is managed by Generative AI. The new password is saved in the browser's password manager.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings","displayName":"Enable automated password change (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_0","displayName":"Allow feature use and improving AI models","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_1","displayName":"Allow feature use without improving AI models","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_2","displayName":"Do not allow feature","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own and, if fixing them is possible, it usually requires complex user actions.\r\n\r\nSetting the policy to Enabled or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched.\r\n\r\nSetting the policy to Disabled means users will leave their password manager data untouched, but will experience a broken password manager functionality.\r\n\r\nIf the policy is set, users can't change it in Google Chrome.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passworddismisscompromisedalertenabled","displayName":"Enable dismissing compromised password alerts for entered credentials","description":"Setting the policy to Enabled or leaving it unset gives the user the option to dismiss/restore compromised password alerts.\r\n\r\nIf you disable this setting, users will not be able to dismiss alerts about compromised passwords. If enabled, users will be able to dismiss alerts about compromised passwords.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passworddismisscompromisedalertenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passworddismisscompromisedalertenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist","displayName":"Configure the list of domains for which the Password Manager (Save and Fill) will be disabled","description":"Configure the list of domains where Google Chrome should disable the Password Manager. This means that Save and Fill workflows will be disabled, ensuring that passwords for those websites can't be saved or auto filled into web forms.\r\n\r\nIf a domain is present in the list, the Password Manager will be disabled for it.\r\n\r\nIf a domain is not present in the list, the Password Manager will be available for it.\r\n\r\nIf the policy is unset, the Password Manager will be available for all domains.\r\n\r\nExample value:\r\n\r\nexample.com\r\nlogin.example.com","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_passwordmanagerblocklistdesc","displayName":"Configure the list of domains for which the Password Manager (Save and Fill) will be disabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerpasskeysenabled","displayName":"Enable saving passkeys to the password manager","description":"This policy controls the browser's ability to save passkeys in the built-in password manager. It does not limit access to, or change the contents of, passkeys already saved in the password manager. If the PasswordManagerEnabled policy is set to Disabled then saving in the built-in password manager is disabled in general, including passkeys and passwords, and thus this policy is not applicable.\r\n\r\nSetting the policy to Enabled or leaving unset means that users can save passkeys in the built-in password manager if signed into Google Chrome.\r\n\r\nSetting the policy to Disabled means users can't save passkeys to the built-in password manager, but previously saved passkeys will still work.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerpasskeysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerpasskeysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordsharingenabled","displayName":"Enable sharing user credentials with other users","description":"Setting the policy to Enabled lets users send to and receive from family members (according to Family Service) their passwords.\r\nWhen the policy is Enabled or not set, there is a button in the Password Manager allowing to send a password.\r\nThe received passwords are stored into user's account and are available in the Password Manager.\r\n\r\nSetting the policy to Disabled means users can't send passwords from Password Manager to other users, and can't receive passwords from other users.\r\n\r\nThe feature is not available if synchronization of Passwords is turned off (either via user settings or SyncDisabled policy is Enabled).\r\n\r\nManaged accounts aren't eligible to join or create a family group and therefore cannot share passwords.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordsharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordsharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed","displayName":"Out-of-process print drivers allowed","description":"Controls if Google Chrome interacts with printer drivers from a separate service process. Platform printing calls to query available printers, get print driver settings, and submit documents for printing to local printers are made from a service process. Moving such calls out of the browser process helps improve stability and reduce frozen UI behavior in Print Preview.\r\n\r\nWhen this policy is set to Enabled or not set, Google Chrome will use a separate service process for platform printing tasks.\r\n\r\nWhen this policy is set to Disabled, Google Chrome will use the browser process for platform printing tasks.\r\n\r\nThis policy will be removed in the future, after the out-of-process print drivers feature has fully rolled out.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printinglpacsandboxenabled","displayName":"Enable Printing LPAC Sandbox","description":"Setting the policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services whenever the system configuration supports it.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security as services used for printing might run in a weaker sandbox configuration.\r\n\r\nOnly turn off the policy if there are compatibility issues with third party software that prevent printing services from operating correctly inside the LPAC Sandbox.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printinglpacsandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printinglpacsandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printpdfasimagedefault","displayName":"Print PDF as Image Default","description":"Controls if Google Chrome makes the Print as image option default to set when printing PDFs.\r\n\r\nWhen this policy is set to Enabled, Google Chrome will default to setting the Print as image option in the Print Preview when printing a PDF.\r\n\r\nWhen this policy is set to Disabled or not set Google Chrome then the user selection for Print as image option will be initially unset. The user will be allowed to select it for each individual PDFs print job, if the option is available.\r\n\r\nFor Microsoft® Windows® or macOS this policy only has an effect if PrintPdfAsImageAvailability is also enabled.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printpdfasimagedefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printpdfasimagedefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadmeasurementenabled","displayName":"Choose whether the Privacy Sandbox ad measurement setting can be disabled","description":"A policy to control whether the Privacy Sandbox Ad measurement setting can be disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Ad measurement setting will be turned off for your users.\r\nIf you set this policy to Enabled or keep it unset, your users will be able to turn on or off the Privacy Sandbox Ad measurement setting on their device.\r\n\r\nSetting this policy requires setting the PrivacySandboxPromptEnabled policy to Disabled.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadmeasurementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadmeasurementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadtopicsenabled","displayName":"Choose whether the Privacy Sandbox Ad topics setting can be disabled","description":"A policy to control whether the Privacy Sandbox Ad topics setting can be disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Ad topics setting will be turned off for your users.\r\nIf you set this policy to Enabled or keep it unset, your users will be able to turn on or off the Privacy Sandbox Ad topics setting on their device.\r\n\r\nSetting this policy requires setting the PrivacySandboxPromptEnabled policy to Disabled.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadtopicsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadtopicsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxfingerprintingprotectionenabled","displayName":"Choose whether the Privacy Sandbox Fingerprinting Protection feature is to be enabled in Incognito mode.","description":"A policy to control whether the Privacy Sandbox Fingerprinting Protection setting is to be enabled in Incognito mode or disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Fingerprinting Protection feature setting will be turned off for your users.\r\nIf you set this policy to Enabled, your users will have the Fingerprinting Protection feature setting turned on in Incognito mode.\r\nIf the policy is not set, users will be able to turn on or off the Fingerprinting Protection feature for Incognito mode in their UI settings. The default state will be false or disabled, meaning the Fingerprinting Protection feature will be turned off.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxfingerprintingprotectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxfingerprintingprotectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxipprotectionenabled","displayName":"Choose whether the Privacy Sandbox IP Protection feature should be enabled.","description":"A policy to control whether the Privacy Sandbox IP Protection feature should be enabled.\r\n\r\nIP Protection is a feature that limits availability of a user's original IP address for certain third-party network requests made while browsing in Incognito mode, enhancing protections against cross-site tracking during Incognito browsing sessions.\r\n\r\nIf the policy is set to Disabled, then IP Protection will be disabled and users won't be able to enable the feature via UI settings.\r\nIf the policy is set to Enabled, then IP Protection will be enabled and users won't be able to disable the feature via UI settings.\r\nIf the policy is not set, IP Protection will be enabled by default and users will be able to control the feature on their device via UI settings.\r\n\r\nSome considerations regarding whether enterprises should disable IP Protection include:\r\n\r\n- DNS lookups won't be performed for requests that are proxied, which may impact DNS-based monitoring or filtering.\r\n\r\n- Enterprise applications may experience breakage when used in Incognito mode if they rely on requests to domains (or subdomains of those domains) on the Masked Domain List (Google Chrome) and require those requests to come from specific IP address ranges.\r\n\r\n- Traffic might not be proxied in Incognito mode under certain conditions, for example when users launch Incognito mode from a Chrome profile they aren't signed in to. In general the feature requires the user to have been signed in to Chrome with a personal Google account when launching Incognito mode.\r\n\r\n- The list of domains on the Masked Domain List may change over time, with new versions being pushed to users automatically. For more information on the Masked Domain List, see: Google Chrome.\r\n\r\nFor more information on IP Protection, see: Google Chrome.\r\n\r\nIP Protection will be launched no sooner than M139.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxipprotectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxipprotectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxpromptenabled","displayName":"Choose whether the Privacy Sandbox prompt can be shown to your users","description":"A policy to control whether your users see the Privacy Sandbox prompt.\r\nThe prompt is a user-blocking flow which informs your users of the Privacy Sandbox settings. See https://privacysandbox.com for details about Chrome’s effort to deprecate third-party cookies.\r\n\r\nIf you set this policy to Disabled, then Google Chrome won’t show the Privacy Sandbox prompt.\r\nIf you set this policy to Enabled or keep it unset, then Google Chrome determines whether the Privacy Sandbox prompt can be shown or not and then show it if possible.\r\n\r\nIf any of the following policies are set, it’s required to set this policy to Disabled:\r\nPrivacySandboxAdTopicsEnabled\r\nPrivacySandboxSiteEnabledAdsEnabled\r\nPrivacySandboxAdMeasurementEnabled","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxpromptenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxpromptenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxsiteenabledadsenabled","displayName":"Choose whether the Privacy Sandbox Site-suggested ads setting can be disabled","description":"A policy to control whether the Privacy Sandbox Site-suggested ads setting can be disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Site-suggested ads setting will be turned off for your users.\r\nIf you set this policy to Enabled or keep it unset, your users will be able to turn on or off the Privacy Sandbox Site-suggested ads setting on their device.\r\n\r\nSetting this policy requires setting the PrivacySandboxPromptEnabled policy to Disabled.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxsiteenabledadsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxsiteenabledadsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~protectedcontent_protectedcontentidentifiersallowed","displayName":"Allows web pages to use identifiers for the purpose of protected content playback","description":"If the policy is set to true or unset, the use of protected content identifiers is allowed, which can help enable higher quality of protected content playback.\r\n\r\nIf the policy is set to false, protected content identifiers are not allowed to be used.","helpText":"","infoUrls":[],"categoryId":"4cd10f38-02cf-40f2-aa87-ad70a2190a1a","categoryName":"Protected Content","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~protectedcontent_protectedcontentidentifiersallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~protectedcontent_protectedcontentidentifiersallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsenabled","displayName":"Enable Related Website Sets","description":"This policy allows to control the Related Website Sets feature enablement.\r\n\r\nThis policy overrides the FirstPartySetsEnabled policy.\r\n\r\nWhen this policy is unset or set to True, the Related Website Sets feature is enabled.\r\n\r\nWhen this policy is set to False, the Related Website Sets feature is disabled.","helpText":"","infoUrls":[],"categoryId":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","categoryName":"Related Website Sets Settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets.","description":"This policy provides a way to override the list of sets the browser uses for Related Website Sets features.\r\n\r\nThis policy overrides the FirstPartySetsOverrides policy.\r\n\r\nEach set in the browser's list of Related Website Sets must meet the requirements of a Related Website Set.\r\nA Related Website Set must contain a primary site and one or more member sites.\r\nA set can also contain a list of service sites that it owns, as well as a map from a site to all of its ccTLD variants.\r\nSee https://github.com/WICG/first-party-sets for more information on how Google Chrome uses Related Website Sets.\r\n\r\n\r\nAll sites in a Related Website Set must be a registrable domain served over HTTPS. Each site in a Related Website Set must also be unique,\r\nmeaning a site cannot be listed more than once in a Related Website Set.\r\n\r\nWhen this policy is given an empty dictionary, the browser uses the public list of Related Website Sets.\r\n\r\nFor all sites in a Related Website Set from the replacements list, if a site is also present\r\non a Related Website Set in the browser's list, then that site will be removed from the browser's Related Website Set.\r\nAfter this, the policy's Related Website Set will be added to the browser's list of Related Website Sets.\r\n\r\nFor all sites in a Related Website Set from the additions list, if a site is also present\r\non a Related Website Set in the browser's list, then the browser's Related Website Set will be updated so that the\r\nnew Related Website Set can be added to the browser's list. After the browser's list has been updated,\r\nthe policy's Related Website Set will be added to the browser's list of Related Website Sets.\r\n\r\nThe browser's list of Related Website Sets requires that for all sites in its list, no site is in\r\nmore than one set. This is also required for both the replacements list\r\nand the additions list. Similarly, a site cannot be in both the\r\nreplacements list and the additions list.\r\n\r\nWildcards (*) are not supported as a policy value, nor within any Related Website Set in these lists.\r\n\r\nAll sets provided by the policy must be valid Related Website Sets, if they aren't then an\r\nappropriate error will be outputted.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=RelatedWebsiteSetsOverrides for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"additions\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate2.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate2.test\": [\r\n \"https://associate2.com\"\r\n ]\r\n },\r\n \"primary\": \"https://primary2.test\",\r\n \"serviceSites\": [\r\n \"https://associate2-content.test\"\r\n ]\r\n }\r\n ],\r\n \"replacements\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate1.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate1.test\": [\r\n \"https://associate1.co.uk\"\r\n ]\r\n },\r\n \"primary\": \"https://primary1.test\",\r\n \"serviceSites\": [\r\n \"https://associate1-content.test\"\r\n ]\r\n }\r\n ]\r\n}","helpText":"","infoUrls":[],"categoryId":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","categoryName":"Related Website Sets Settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsoverrides_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","categoryName":"Related Website Sets Settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~remoteaccess_remoteaccesshostallowpinauthentication","displayName":"Allow PIN and pairing authentication methods for remote access hosts","description":"Setting the policy to Enabled allows the remote access host to use PIN and pairing authentications when accepting client connections.\r\n\r\nSetting the policy to Disabled disallows PIN or pairing authentications.\r\n\r\nLeaving it unset lets the host decide whether PIN and/or pairing authentications can be used.\r\n\r\nNote: If the setting results in no mutually supported authentication methods by both the host and the client, then the connection will be rejected.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~remoteaccess_remoteaccesshostallowpinauthentication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~remoteaccess_remoteaccesshostallowpinauthentication_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~remoteaccess_remoteaccesshostallowurlforwarding","displayName":"Allow remote access users to open host-side URLs in their local client browser","description":"Setting the policy to Enabled or leaving it unset may allow users connected to a remote access host to open host-side URLs in their local client browser.\r\n\r\nSetting the policy to Disabled will prevent the remote access host from sending URLs to the client.\r\n\r\nThis setting doesn't apply to remote assistance connections as the feature is not supported for that connection mode.\r\n\r\nNote: This feature is not yet generally available so enabling it does not mean that the feature will be visible in the client UI.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~remoteaccess_remoteaccesshostallowurlforwarding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~remoteaccess_remoteaccesshostallowurlforwarding_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_assistantwebenabled","displayName":"Allow using Google Assistant on the web, e.g. to enable changing passwords automatically","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_assistantwebenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_assistantwebenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_beforeunloadeventcancelbypreventdefaultenabled","displayName":"Control new behavior for the cancel dialog produced by the beforeunload event","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_beforeunloadeventcancelbypreventdefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_beforeunloadeventcancelbypreventdefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_blocktruncatedcookies","displayName":"Block truncated cookies","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_blocktruncatedcookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_blocktruncatedcookies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappsenabled","displayName":"Extend support for Chrome Apps on Microsoft® Windows®, macOS, and Linux.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappswebviewpermissivebehaviorallowed","displayName":"Restore permissive Chrome Apps behavior","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappswebviewpermissivebehaviorallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappswebviewpermissivebehaviorallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromerootstoreenabled","displayName":"Determines whether the Chrome Root Store and built-in certificate verifier will be used to verify server certificates","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromerootstoreenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromerootstoreenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_csscustomstatedeprecatedsyntaxenabled","displayName":"Controls whether the deprecated :--foo syntax for CSS custom state is enabled","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_csscustomstatedeprecatedsyntaxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_csscustomstatedeprecatedsyntaxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_downloadbubbleenabled","displayName":"Enable download bubble UI","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_downloadbubbleenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_downloadbubbleenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_enforcelocalanchorconstraintsenabled","displayName":"Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_enforcelocalanchorconstraintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_enforcelocalanchorconstraintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_eventpathenabled","displayName":"Re-enable the Event.path API until M115.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_eventpathenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_eventpathenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_0","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_1","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_2","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_3","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled","displayName":"Re-enable the deprecated async interface for FileSystemSyncAccessHandle in File System Access API","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forceenablepeppervideodecoderdevapi","displayName":"Enable support for the PPB_VideoDecoder(Dev) API.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forceenablepeppervideodecoderdevapi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forceenablepeppervideodecoderdevapi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent","displayName":"Freeze User-Agent string major version at 99","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_forcemajorversiontominorpositioninuseragent","displayName":"Freeze User-Agent string major version at 99 (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_forcemajorversiontominorpositioninuseragent_0","displayName":"Default to browser settings for User-Agent string version.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_forcemajorversiontominorpositioninuseragent_1","displayName":"The User-Agent string will not freeze the major version.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_forcemajorversiontominorpositioninuseragent_2","displayName":"The User-Agent string will freeze the major version as 99 and include the browser's major version in the minor position.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_insecurehashesintlshandshakesenabled","displayName":"Insecure Hashes in TLS Handshakes Enabled","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_insecurehashesintlshandshakesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_insecurehashesintlshandshakesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_keyboardfocusablescrollersenabled","displayName":"Enable keyboard focusable scrollers","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_keyboardfocusablescrollersenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_keyboardfocusablescrollersenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_loadcryptotokenextension","displayName":"Load the CryptoToken component extension at startup","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_loadcryptotokenextension_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_loadcryptotokenextension_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled","displayName":"Re-enable deprecated/removed Mutation Events","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_nativeclientforceallowed","displayName":"Forces Native Client (NaCl) to be allowed to run.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_nativeclientforceallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_nativeclientforceallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_newbaseurlinheritancebehaviorallowed","displayName":"Allows enabling the feature NewBaseUrlInheritanceBehavior","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_newbaseurlinheritancebehaviorallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_newbaseurlinheritancebehaviorallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled","displayName":"Control the new behavior of HTMLElement.offsetParent","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_optimizationguidefetchingenabled","displayName":"Enable Optimization Guide Fetching","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_optimizationguidefetchingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_optimizationguidefetchingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_persistentquotaenabled","displayName":"Force persistent quota to be enabled","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_persistentquotaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_persistentquotaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_ppapisharedimagesswapchainallowed","displayName":"Allow modern buffer allocation for Graphics3D APIs PPAPI plugin.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_ppapisharedimagesswapchainallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_ppapisharedimagesswapchainallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedstorageinfoenabled","displayName":"Re-enable the deprecated window.webkitStorageInfo API","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedstorageinfoenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedstorageinfoenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability","displayName":"Manage the deprecated prefixed video fullscreen API's availability","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability","displayName":"Manage the deprecated prefixed video fullscreen API's availability (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability_runtime-enabled","displayName":"Follows regular deprecation timelines for the PrefixedVideoFullscreen API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability_disabled","displayName":"Disables prefixed video fullscreen APIs","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability_enabled","displayName":"Enables prefixed video fullscreen APIs","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_privatenetworkaccessrestrictionsenabled","displayName":"Specifies whether to apply restrictions to requests to more-private network endpoints","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_privatenetworkaccessrestrictionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_privatenetworkaccessrestrictionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_rsakeyusageforlocalanchorsenabled","displayName":"Check RSA key usage for server certificates issued by local trust anchors","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_rsakeyusageforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_rsakeyusageforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_selectparserrelaxationenabled","displayName":"Controls whether the new HTML parser behavior for the element is enabled","description":"The HTML parser is being changed to allow additional HTML tags inside the element.\r\n\r\nIf this policy is disabled, then the HTML parser will restrict which tags can be put in the element is enabled (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_selectparserrelaxationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_selectparserrelaxationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_sendmouseeventsdisabledformcontrolsenabled","displayName":"Control the new behavior for event dispatching on disabled form controls (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_sendmouseeventsdisabledformcontrolsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_sendmouseeventsdisabledformcontrolsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_settimeoutwithout1msclampenabled","displayName":"Control Javascript setTimeout() function minimum timeout. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_settimeoutwithout1msclampenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_settimeoutwithout1msclampenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings","displayName":"Settings for Tab Organizer (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings","displayName":"Settings for Tab Organizer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings_0","displayName":"Allow Tab Organizer and improve AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings_1","displayName":"Allow Tab Organizer without improving AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings_2","displayName":"Do not allow Tab Organizer.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_throttlenonvisiblecrossoriginiframesallowed","displayName":"Allows enabling throttling of non-visible, cross-origin iframes (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_throttlenonvisiblecrossoriginiframesallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_throttlenonvisiblecrossoriginiframesallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings","displayName":"Managed toolbar avatar label setting (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_toolbaravatarlabelsettings","displayName":"Managed toolbar avatar label setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_toolbaravatarlabelsettings_0","displayName":"Always display management label","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_toolbaravatarlabelsettings_1","displayName":"Display management labels for 30s","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_unthrottlednestedtimeoutenabled","displayName":"Control the nesting threshold before which Javascript setTimeout() function start being clamped (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_unthrottlednestedtimeoutenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_unthrottlednestedtimeoutenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled","displayName":"Control the URL parameter filter feature (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_usemojovideodecoderforpepperallowed","displayName":"Allow Pepper to use a new decoder for hardware accelerated video decoding. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_usemojovideodecoderforpepperallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_usemojovideodecoderforpepperallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_useragentclienthintsgreaseupdateenabled","displayName":"Control the User-Agent Client Hints GREASE Update feature. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_useragentclienthintsgreaseupdateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_useragentclienthintsgreaseupdateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlaccess","displayName":"Force WebSQL to be enabled. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlnonsecurecontextenabled","displayName":"Force WebSQL in non-secure contexts to be enabled. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlnonsecurecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlnonsecurecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled","displayName":"Enable zstd content-encoding support (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled","displayName":"Allow download deep scanning for Safe Browsing-enabled users (User)","description":"When this policy is enabled or left unset, Google Chrome can send suspicious downloads from Safe Browsing-enabled users to Google to scan for malware, or prompt users to provide a password for encrypted archives.\r\nWhen this policy is disabled, this scanning will not be performed.\r\nThis policy does not impact download content analysis configured by Chrome Enterprise Connectors.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingproxiedrealtimechecksallowed","displayName":"Allow Safe Browsing Proxied Real Time Checks (User)","description":"This controls whether Safe Browsing's standard protection mode is allowed to\r\nsend partial hashes of URLs to Google through a proxy via Oblivious HTTP\r\nin order to determine whether they are safe to visit.\r\n\r\nThe proxy allows browsers to upload partial hashes of URLs to Google\r\nwithout them being linked to the user's IP address. The policy also allows\r\nbrowsers to upload the partial hashes of URLs with higher frequency for\r\nbetter Safe Browsing protection quality.\r\n\r\nThis policy will be ignored if Safe Browsing is disabled or set to enhanced\r\nprotection mode.\r\n\r\nSetting the policy to Enabled or leaving it unset allows the\r\nhigher-protection proxied lookups.\r\n\r\nSetting the policy to Disabled disallows the higher-protection proxied\r\nlookups. Partial hashes of URLs will be uploaded to Google directly with much\r\nlower frequency, which will degrade protection.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingproxiedrealtimechecksallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingproxiedrealtimechecksallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingsurveysenabled","displayName":"Allow Safe Browsing Surveys (User)","description":"When this policy is enabled or left unset, the user may receive surveys related to Safe Browsing.\r\nWhen this policy is disabled, the user will not receive surveys related to Safe Browsing.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingsurveysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingsurveysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_boundsessioncredentialsenabled","displayName":"Bind Google credentials to a device (User)","description":"Controls the state of the Device Bound Session Credentials feature.\r\n\r\nDevice Bound Session Credentials protects Google authentication cookies against cookie theft by regularly providing a cryptographic proof of device possession to Google servers.\r\n\r\nIf this policy is set to false, Device Bound Session Credentials feature will be disabled.\r\n\r\nIf this policy is set to true, Device Bound Session Credentials feature will be enabled.\r\n\r\nIf this policy is unset, Google Chrome will follow the default rollout process for the Device Bound Session Credentials feature, which means that the feature will be gradually rolled out to an increasing number of users.","helpText":"","infoUrls":[],"categoryId":"f00e9baf-9bbf-48e4-aaac-57410730f016","categoryName":"Sign-in settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_boundsessioncredentialsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_boundsessioncredentialsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist","displayName":"Enterprise profile separation secondary domain allowlist (User)","description":"If this policy is unset, account logins will not be required to create a new separate profile.\r\n\r\nIf this policy is set, account logins from the listed domains will not be required to create a new separate profile.\r\n\r\nThis policy can be set to an empty string so that all account logins are required to create a new separate profile.\r\n\r\nExample value:\r\n\r\ndomain.com\r\notherdomain.com","helpText":"","infoUrls":[],"categoryId":"f00e9baf-9bbf-48e4-aaac-57410730f016","categoryName":"Sign-in settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist_profileseparationdomainexceptionlistdesc","displayName":"Enterprise profile separation secondary domain allowlist (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f00e9baf-9bbf-48e4-aaac-57410730f016","categoryName":"Sign-in settings","options":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl","displayName":"WebRTC per URL IP Handling (User)","description":"This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection for each specific URL pattern.\r\n\r\nIt accepts a list of URL patterns and handling type pairs. The URL patterns are checked in order and the first match will configure which handling is used by WebRTC for the domain. When the URL of the current document is not matched against any entry, it uses the configuration set by the policy WebRtcIPHandling.\r\n\r\nFor detailed information on valid input patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nValid handling values:\r\n\r\n* default - WebRTC uses all network interfaces.\r\n\r\n* default_public_and_private_interfaces - WebRTC uses all public and private interfaces.\r\n\r\n* default_public_interface_only - WebRTC uses all public interfaces, but not private ones.\r\n\r\n* disable_non_proxied_udp - WebRTC uses either UDP SOCKS proxying or will fallback to TCP proxying.\r\n\r\nSee RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2) for a detailed description of all the handling values.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebRtcIPHandlingUrl for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.example.com\",\r\n \"handling\": \"default_public_and_private_interfaces\"\r\n },\r\n {\r\n \"url\": \"https://[*.]example.edu\",\r\n \"handling\": \"default_public_interface_only\"\r\n },\r\n {\r\n \"url\": \"*\",\r\n \"handling\": \"disable_non_proxied_udp\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","categoryName":"Web Rtc settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl_webrtciphandlingurl","displayName":"WebRTC per URL IP Handling (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","categoryName":"Web Rtc settings","options":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC (User)","description":"This policy allows controlling post-quantum key agreement for WebRTC.\r\n\r\nIf this policy is set to Enabled, post-quantum key agreement would be offered for\r\nWebRTC.\r\n\r\nIf this policy is set to Disabled, post-quantum key agreement would not be offered\r\nfor WebRTC.\r\n\r\nIf this policy is not set, the value would be set by the default rollout process\r\nfor post-quantum key agreement offered for WebRTC.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing DTLS\r\npeers and networking middleware are expected to ignore the new option and\r\ncontinue selecting previous options.\r\n\r\nHowever, devices that do not correctly implement DTLS may malfunction when\r\noffered the new option. For example, they may disconnect in response to\r\nunrecognized options or the resulting larger messages. Such devices are not\r\npost-quantum-ready and will interfere with an enterprise's post-quantum\r\ntransition. If encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed after some milestones.","helpText":"","infoUrls":[],"categoryId":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","categoryName":"Web Rtc settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_connectivity_disablecrossdeviceresume","displayName":"Disable Cross Device Resume (User)","description":"This policy allows IT admins to turn off CrossDeviceResume feature to continue tasks, such as browsing file, continue using 1P/ 3P apps that require linking between Phone and PC. If you enable this policy setting, the Windows device will not receive any CrossDeviceResume notification. If you disable this policy setting, the Windows device will receive notification to resume activity from linked phone. If you do not configure this policy setting, the default behavior is that the CrossDeviceResume feature is turned 'ON'. Changes to this policy take effect on reboot.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Connectivity#disablecrossdeviceresume"],"categoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","categoryName":"Connectivity","options":[{"id":"user_vendor_msft_policy_config_connectivity_disablecrossdeviceresume_0","displayName":"CrossDeviceResume is Enabled","description":"CrossDeviceResume is Enabled","helpText":null},{"id":"user_vendor_msft_policy_config_connectivity_disablecrossdeviceresume_1","displayName":"CrossDeviceResume is Disabled","description":"CrossDeviceResume is Disabled","helpText":null}]},{"id":"user_vendor_msft_policy_config_credentialsui_disablepasswordreveal","displayName":"Do not display the password reveal button (User)","description":"This policy setting allows you to configure the display of the password reveal button in password entry user experiences.\n\nIf you enable this policy setting, the password reveal button will not be displayed after a user types a password in the password entry text box.\n\nIf you disable or do not configure this policy setting, the password reveal button will be displayed after a user types a password in the password entry text box.\n\nBy default, the password reveal button is displayed after a user types a password in the password entry text box. To display the password, click the password reveal button.\n\nThe policy applies to all Windows components and applications that use the Windows system controls, including Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-credentialsui#credentialsui-disablepasswordreveal"],"categoryId":"58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","categoryName":"Credential User Interface","options":[{"id":"user_vendor_msft_policy_config_credentialsui_disablepasswordreveal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_credentialsui_disablepasswordreveal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_desktop_preventuserredirectionofprofilefolders","displayName":"Prohibit User from manually redirecting Profile Folders (User)","description":"Prevents users from changing the path to their profile folders.\n\nBy default, a user can change the location of their individual profile folders like Documents, Music etc. by typing a new path in the Locations tab of the folder's Properties dialog box.\n\nIf you enable this setting, users are unable to type a new location in the Target box.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-desktop#desktop-preventuserredirectionofprofilefolders"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_desktop_preventuserredirectionofprofilefolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_desktop_preventuserredirectionofprofilefolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_display_configuremultipledisplaymode","displayName":"Configure Multiple Display Mode (User)","description":"Set the default display arrangement as clone, extend, internalOnly, externalOnly or default Windows Settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Display#configuremultipledisplaymode"],"categoryId":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_display_configuremultipledisplaymode_0","displayName":"Default.","description":"Default.","helpText":null},{"id":"user_vendor_msft_policy_config_display_configuremultipledisplaymode_1","displayName":"Internal Only.","description":"Internal Only.","helpText":null},{"id":"user_vendor_msft_policy_config_display_configuremultipledisplaymode_2","displayName":"External Only.","description":"External Only.","helpText":null},{"id":"user_vendor_msft_policy_config_display_configuremultipledisplaymode_3","displayName":"Clone.","description":"Clone.","helpText":null},{"id":"user_vendor_msft_policy_config_display_configuremultipledisplaymode_4","displayName":"Extend.","description":"Extend.","helpText":null}]},{"id":"user_vendor_msft_policy_config_display_enableperprocessdpi","displayName":"Enable Per Process Dpi (User)","description":"Enable or disable Per-Process System DPI for all applications.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Display#enableperprocessdpi"],"categoryId":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_display_enableperprocessdpi_0","displayName":"Disabled","description":"Disable.","helpText":null},{"id":"user_vendor_msft_policy_config_display_enableperprocessdpi_1","displayName":"Enabled","description":"Enable.","helpText":null}]},{"id":"user_vendor_msft_policy_config_display_setclonepreferredresolutionsource","displayName":"Set Clone Preferred Resolution Source (User)","description":"Set the cloned monitor preferred resolution source as internal or external monitor or set to default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Display#setclonepreferredresolutionsource"],"categoryId":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_display_setclonepreferredresolutionsource_0","displayName":"Default.","description":"Default.","helpText":null},{"id":"user_vendor_msft_policy_config_display_setclonepreferredresolutionsource_1","displayName":"Internal.","description":"Internal.","helpText":null},{"id":"user_vendor_msft_policy_config_display_setclonepreferredresolutionsource_2","displayName":"External.","description":"External.","helpText":null}]},{"id":"user_vendor_msft_policy_config_education_allowgraphingcalculator","displayName":"Allow Graphing Calculator (User)","description":"This policy setting allows you to control whether graphing functionality is available in the Windows Calculator app. If you disable this policy setting, graphing functionality will not be accessible in the Windows Calculator app. If you enable or don't configure this policy setting, users will be able to access graphing functionality.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Education#allowgraphingcalculator"],"categoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","categoryName":"Education","options":[{"id":"user_vendor_msft_policy_config_education_allowgraphingcalculator_0","displayName":"Block","description":"Disabled.","helpText":null},{"id":"user_vendor_msft_policy_config_education_allowgraphingcalculator_1","displayName":"Allow","description":"Enabled.","helpText":null}]},{"id":"user_vendor_msft_policy_config_education_defaultprintername","displayName":"Default Printer Name (User)","description":"This policy sets user's default printer","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Education#defaultprintername"],"categoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","categoryName":"Education","options":null},{"id":"user_vendor_msft_policy_config_education_preventaddingnewprinters","displayName":"Prevent Adding New Printers (User)","description":"Boolean that specifies whether or not to prevent user to install new printers","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Education#preventaddingnewprinters"],"categoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","categoryName":"Education","options":[{"id":"user_vendor_msft_policy_config_education_preventaddingnewprinters_0","displayName":"Disabled","description":"Allow user installation.","helpText":null},{"id":"user_vendor_msft_policy_config_education_preventaddingnewprinters_1","displayName":"Enabled","description":"Prevent user installation.","helpText":null}]},{"id":"user_vendor_msft_policy_config_education_printernames","displayName":"Printer Names (User)","description":"This policy provisions per-user network printers","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Education#printernames"],"categoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","categoryName":"Education","options":null},{"id":"user_vendor_msft_policy_config_enterprisecloudprint_cloudprinterdiscoveryendpoint","displayName":"Cloud Printer Discovery End Point (User)","description":"This policy provisions per-user discovery end point to discover cloud printers","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-EnterpriseCloudPrint#cloudprinterdiscoveryendpoint"],"categoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","categoryName":"Enterprise Cloud Print","options":null},{"id":"user_vendor_msft_policy_config_enterprisecloudprint_cloudprintoauthauthority","displayName":"Cloud Print OAuth Authority (User)","description":"Authentication endpoint for acquiring OAuth tokens","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-EnterpriseCloudPrint#cloudprintoauthauthority"],"categoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","categoryName":"Enterprise Cloud Print","options":null},{"id":"user_vendor_msft_policy_config_enterprisecloudprint_cloudprintoauthclientid","displayName":"Cloud Print OAuth Client Id (User)","description":"A GUID identifying the client application authorized to retrieve OAuth tokens from the OAuthAuthority","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-EnterpriseCloudPrint#cloudprintoauthclientid"],"categoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","categoryName":"Enterprise Cloud Print","options":null},{"id":"user_vendor_msft_policy_config_enterprisecloudprint_cloudprintresourceid","displayName":"Cloud Print Resource Id (User)","description":"Resource URI for which access is being requested by the Enterprise Cloud Print client during OAuth authentication","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-EnterpriseCloudPrint#cloudprintresourceid"],"categoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","categoryName":"Enterprise Cloud Print","options":null},{"id":"user_vendor_msft_policy_config_enterprisecloudprint_mopriadiscoveryresourceid","displayName":"Mopria Discovery Resource Id (User)","description":"Resource URI for which access is being requested by the Mopria discovery client during OAuth authentication","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-EnterpriseCloudPrint#mopriadiscoveryresourceid"],"categoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","categoryName":"Enterprise Cloud Print","options":null},{"id":"user_vendor_msft_policy_config_excel16~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_blockinsecureprotocolsinexcelworksheetfunctions","displayName":"Block Insecure Protocols in Excel Worksheet Functions (User)","description":"\n\t\t This policy controls whether the following Excel functions can access the web via insecure protocols: WEBSERVICE, IMPORTCSV, IMPORTTEXT\n\n\t\t If you enable this policy setting, WEBSERVICE, IMPORTCSV, and IMPORTTEXT functions will be blocked from accessing the web via insecure protocols.\n\n\t\t If you disable or don't configure this policy setting, WEBSERVICE, IMPORTCSV, and IMPORTTEXT functions will be allowed to access the web via insecure protocols.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_blockinsecureprotocolsinexcelworksheetfunctions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_blockinsecureprotocolsinexcelworksheetfunctions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v10~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_excelforcesupportforunicodesurrogates","displayName":"Force support for Unicode surrogates in Excel 2021 and Excel 2024 (User)","description":"Warning: this setting alters how your app calculates LEN, MID, SEARCH, FIND and REPLACE and forces files to Compatibility Version 2. When these workbooks are shared, users may see different calculation results. This setting only applies to non-subscription Excel 2021 and Excel 2024.\r\n \r\nIf you enable this policy setting, when any workbook is opened in non-subscription Excel 2021 or Excel 2024, it will automatically be set to Compatibility Version 2. This will cause LEN, MID, SEARCH, FIND and REPLACE functions to calculate differently in those workbooks.\r\n \r\nIf you disable or do not configure this policy setting, the Compatibility Version will not be automatically set when a file is opened in any version of non-subscription Excel 2021 and Excel 2024 (this setting never affects other versions).","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v10~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_excelforcesupportforunicodesurrogates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v10~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_excelforcesupportforunicodesurrogates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Enter error ID for Value Name and custom button text for Value","helpText":"","infoUrls":[],"categoryId":"5b832259-c30b-43bb-b249-9d3ea4d5b028","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize87","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5b832259-c30b-43bb-b249-9d3ea4d5b028","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize87_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"5b832259-c30b-43bb-b249-9d3ea4d5b028","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize87_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5b832259-c30b-43bb-b249-9d3ea4d5b028","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_datarecovery_l_donotshowdataextractionoptionswhenopeningcorruptworkbooks","displayName":"Do not show data extraction options when opening corrupt workbooks (User)","description":"This policy setting controls whether Excel presents users with a list of data extraction options before beginning an Open and Repair operation when users choose to open a corrupt workbook in repair or extract mode.\r\n \r\nIf you enable this policy setting, Excel opens the file using the Safe Load process and does not prompt users to choose between repairing or extracting data.\r\n \r\nIf you disable or do not configure this policy setting, Excel prompts the user to select either to repair or to extract data, and to select either to convert to values or to recover formulas.","helpText":"","infoUrls":[],"categoryId":"28831364-ca54-4f31-acca-1aa0c7a7d3d2","categoryName":"Data Recovery","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_datarecovery_l_donotshowdataextractionoptionswhenopeningcorruptworkbooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_datarecovery_l_donotshowdataextractionoptionswhenopeningcorruptworkbooks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems165","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"3b7e16e7-171f-4169-8904-c8483b06700d","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems165_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems165_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems165_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b7e16e7-171f-4169-8904-c8483b06700d","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys166","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"3b7e16e7-171f-4169-8904-c8483b06700d","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys166_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys166_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys166_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b7e16e7-171f-4169-8904-c8483b06700d","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable specific command bar buttons and menu items in the specified applications.\r\n \r\n If you enable this policy setting you can disable specific command bar buttons and menu items in the user interface for the selected application. The predefined list of command bar buttons and menu items you can disable becomes available to you when you enable this policy setting.\r\n \r\n If you disable or do not configure this policy setting, the predefined list of command bar buttons and menu items are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodemacros","displayName":"Developer tab | Code | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodemacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodemacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodemacrosecurity","displayName":"Developer tab | Code | Macro Security (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodemacrosecurity_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodemacrosecurity_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercoderecordmacro","displayName":"Developer tab | Code | Record Macro (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercoderecordmacro_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercoderecordmacro_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodevisualbasic","displayName":"Developer tab | Code | Visual Basic (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodevisualbasic_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodevisualbasic_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_insertlinkshyperlink","displayName":"Insert tab | Links | Hyperlink (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_insertlinkshyperlink_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_insertlinkshyperlink_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizationmailrecipient","displayName":"File tab | Share | Email (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizationmailrecipient_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizationmailrecipient_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizedocumentlocation","displayName":"File tab | Options | Customize Ribbon | All Commands | Document Location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizedocumentlocation_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizedocumentlocation_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonxceloptionscustomizationcombinedpreviewwebpagepreview","displayName":"File tab | Options | Customize Ribbon | All Commands | Web Page Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonxceloptionscustomizationcombinedpreviewwebpagepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonxceloptionscustomizationcombinedpreviewwebpagepreview_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectsharing","displayName":"Review tab | Changes | Protect and Share Workbook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectsharing_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectsharing_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectsheet","displayName":"Review tab | Changes | Protect Sheet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectsheet_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectsheet_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectworkbook","displayName":"Review tab | Changes | Protect Workbook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectworkbook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectworkbook_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_viewmacrosmacros","displayName":"View tab | Macros | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_viewmacrosmacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_viewmacrosmacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable specific shortcut key combinations in the specified applications.\r\n \r\n If you enable this policy setting you can disable specific shortcut keys for the selected application. The predefined list of shortcut keys you can disable becomes available to you when you enable this policy setting.\r\n \r\n If you disable or do not configure this policy setting, the predefined list of shortcut keys are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros","displayName":"Alt+F8 (Developer | Code | Macros) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altlvdevelopercodevisualbasic","displayName":"Alt+F11 (Developer | Code | Visual Basic) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altlvdevelopercodevisualbasic_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altlvdevelopercodevisualbasic_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlfhomeeditingfind","displayName":"Ctrl+F (Home | Editing | Find & Select | Find) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlfhomeeditingfind_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlfhomeeditingfind_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinsertlinkshyperlinks","displayName":"Ctrl+K (Insert | Links | Hyperlink) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinsertlinkshyperlinks_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinsertlinkshyperlinks_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alertbeforeoverwritingcells","displayName":"Alert before overwriting cells (User)","description":"This policy setting sets the \"Alert before overwriting cells\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will give a warning if cells are about to be overwritten. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will suppress the warning that cells are about to be overwritten.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alertbeforeoverwritingcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alertbeforeoverwritingcells_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation","displayName":"Alternate startup file location (User)","description":"This policy setting allows you to specify the folder where files will be opened by Excel at startup.\r\n\r\nIf you enable this policy setting, you may specify the folder where files will be opened by Excel at startup. Files will be opened from this folder in addition to the XLSTART folder in the Microsoft Office installation directory (default C:\\Program Files\\Microsoft Office\\Office14\\XLSTART).\r\n\r\nIf you disable or do not configure this policy setting, files will only be opened from the XLSTART folder.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation_l_alternatestartupfilelocation86","displayName":"Alternate startup file location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_asktoupdateautomaticlinks","displayName":"Ask to update automatic links (User)","description":"This policy setting controls whether Excel prompts users to update automatic links, or whether the updates occur in the background with no prompt.\r\n \r\nIf you enable or do not configure this policy setting, Excel will prompt users to update automatic links. In addition, the \"Ask to update automatic links\" user interface option under File tab | Advanced | General is selected.\r\n \r\nIf you disable this policy setting, Excel updates automatic links without prompting or informing users, which could compromise the integrity of some of the information in the workbook.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_asktoupdateautomaticlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_asktoupdateautomaticlinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyflashfill","displayName":"Automatically Flash Fill (User)","description":"This policy setting controls the \"Automatically Flash Fill\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will enable automatic Flash Fill. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will turn off the Automatic Flash Fill feature.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyflashfill_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyflashfill_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyinsertadecimalpoint","displayName":"Automatically insert a decimal point (User)","description":"This policy setting allows you to configure the \"Automatically insert a decimal point\" option.\r\n\r\nIf you enable this policy setting, the \"Automatically insert a decimal point\" option will be checked and the Places option is set to 2.\r\n\r\nIf you disable or do not configure this policy setting, the \"Automatically insert a decimal point\" option will not be checked.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyinsertadecimalpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyinsertadecimalpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_chartreftrackingenabled","displayName":"Allow formatting and labels to track data points (User)","description":"This policy setting governs how custom formatting and data labels react to data changes in a chart.\r\n\r\nIf you enable or do not configure this policy setting, when the user creates a new workbook, custom formatting and data labels follow data points as they move or change in any chart in the workbook.\r\n\r\nIf you disable this policy setting, custom formatting and data labels do not follow data points, but instead follow data point indices.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_chartreftrackingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_chartreftrackingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments","displayName":"Comments (User)","description":"Determines how comments are displayed on the worksheet.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_l_comments85","displayName":"Comments (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_l_comments85_0","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_l_comments85_1","displayName":"Comment indicator only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_l_comments85_2","displayName":"Comment & indicator","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement","displayName":"Cursor movement (User)","description":"Determines how the insertion point moves through bi-directional text. Possible values are Logical or Visual and the default is Logical.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_l_cursormovement82","displayName":"Cursor movement (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_l_cursormovement82_0","displayName":"Logical","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_l_cursormovement82_1","displayName":"Visual","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cutandcopyobjectswithcells","displayName":"Cut and copy objects with cells (User)","description":"This policy setting sets the \"Cut, copy, and sort inserted objects with their parent cells\" option found under File tab | Options | Advanced | Cut, copy, and paste Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will cut, copy, and sort inserted objects with their parent cells.\r\n\r\nIf you disable this policy setting, Excel will not cut and copy inserted objects with their parent cells.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cutandcopyobjectswithcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cutandcopyobjectswithcells_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection","displayName":"Default sheet direction (User)","description":"This setting controls the default sheet direction, which is either \"Left to Right\" or \"Right to Left\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_l_defaultdirection81","displayName":"Default sheet direction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_l_defaultdirection81_1","displayName":"Right-to-Left","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_l_defaultdirection81_0","displayName":"Left-to-Right","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_editdirectlyincell","displayName":"Edit directly in cell (User)","description":"This policy setting sets the \"Edit directly in cell\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will allow editing directly in the cell This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will not allow editing to be done directly in the cell.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_editdirectlyincell_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_editdirectlyincell_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enableautocompleteforcellvalues","displayName":"Enable AutoComplete for cell values (User)","description":"This policy setting sets the \"Enable AutoComplete for cell values\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will allow AutoComplete for cell values. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will turn off the AutoComplete feature.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enableautocompleteforcellvalues_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enableautocompleteforcellvalues_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enableautomaticpercententry","displayName":"Enable automatic percent entry (User)","description":"Enabling this policy selects the Advanced (Editing options) user option to \"Enable automatic percent entry\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enableautomaticpercententry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enableautomaticpercententry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enablefillhandleandcelldraganddrop","displayName":"Enable fill handle and cell drag-and-drop (User)","description":"This policy setting sets the \"Enable fill handle and cell drag-and-drop\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will enable the fill handle and allow drag-and-drop. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will disable the fill handle and drag-and-drop will not be allowed.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enablefillhandleandcelldraganddrop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enablefillhandleandcelldraganddrop_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_extenddatarangeformatsandformulas","displayName":"Extend data range formats and formulas (User)","description":"This policy setting sets the \"Extend data range formats and formulas\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will allow the user to automatically format new items added to the end of a list to match the format of the rest of the list. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will not automatically format new items added to the end of a list.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_extenddatarangeformatsandformulas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_extenddatarangeformatsandformulas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_functiontooltips","displayName":"Function tooltips (User)","description":"Enabling this setting selects the Advanced (Display) user option to \"Show function ScreenTips\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_functiontooltips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_functiontooltips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_ignoreotherapplications","displayName":"Ignore other applications (User)","description":"This policy setting controls whether Excel can exchange data with other applications that use Dynamic Data Exchange (DDE).\r\n \r\n If you enable this policy setting, Excel does not allow the exchange of data with other applications that use DDE. In addition, the \"Ignore other applications that use Dynamic Data Exchange (DDE)\" user interface option under Excel Options | General is selected and users cannot change it. Enabling this policy setting can cause disruptions for users who rely on the DDE functionality in Excel to update information in workbooks. These users will have to use some other method to update information provided by other applications.\r\n \r\n If you disable or do not configure this policy setting, Excel can use the Dynamic Data Exchange (DDE) protocol to exchange messages and data with other applications. For example, a cell in an Excel workbook can be dynamically linked to a value provided by another application, such as weather or stock price information. When the value provided by the other application changes, Excel can automatically update the value in the workbook. Note: users can change this behavior by selecting the \"Ignore other applications that use Dynamic Data Exchange (DDE)\" user interface option under Excel Options | General.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_ignoreotherapplications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_ignoreotherapplications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_microsoftexcelmenuorhelpkey","displayName":"Microsoft Excel menu or Help key (User)","description":"This policy setting allows you to set the ASCII value for the key of choice (e.g. '/'=47).","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_microsoftexcelmenuorhelpkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_microsoftexcelmenuorhelpkey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_microsoftexcelmenuorhelpkey_l_helpkey","displayName":"Enter ASCII value (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenter","displayName":"Move selection after Enter (User)","description":"Enabling this policy selects the Advanced (Editing Options) user option to \"After pressing Enter, move selection\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection","displayName":"Move selection after Enter direction (User)","description":"Specifies the direction that the selection is moved after the Enter key is pressed.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_l_moveselectionafterenterdirection84","displayName":"Move selection after Enter direction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_l_moveselectionafterenterdirection84_0","displayName":"Down","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_l_moveselectionafterenterdirection84_1","displayName":"Right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_l_moveselectionafterenterdirection84_2","displayName":"Up","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_l_moveselectionafterenterdirection84_3","displayName":"Left","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_recentlyusedfilelist","displayName":"Number of workbooks in the Recent Workbooks list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Workbooks list that appears when users click Open on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Workbooks list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Workbooks list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_recentlyusedfilelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_recentlyusedfilelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_recentlyusedfilelist_l_entriesonrecentlyusedfilelist","displayName":"Entries on recently used file list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showalertifnotdefault","displayName":"Show Alert if Excel is not the default for its associated file types (User)","description":"This policy setting controls the \"Tell me if Microsoft Excel isn't the default progam for viewing and editing spreadsheets\" option found under File tab | Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will show an alert if it isn't the default progam for viewing and editing spreadsheets. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will turn off the alert.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showalertifnotdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showalertifnotdefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showcontrolcharacters","displayName":"Show control characters (User)","description":"Enabling this policy selects the user option to \"Show control characters\". This option appears in the Advanced category when certain languages have been enabled.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showcontrolcharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showcontrolcharacters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinfullview","displayName":"Show Formula bar in Full View (User)","description":"Checked: Displays the Formula bar when the Full Screen command in the View menu is set. | Unchecked: Does not dispaly the Formula bar when the Full Screen command in the View menu is set.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinfullview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinfullview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinnormalview","displayName":"Show Formula bar in Normal View (User)","description":"Enabling this setting selects the Advanced (Display) user option to \"Show formula bar\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinnormalview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinnormalview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showinsertoptionsbuttons","displayName":"Show Insert Options buttons (User)","description":"This policy setting sets the \"Show Insert Options buttons\" option found under File tab | Options | Advanced | Cut, copy, and paste options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will show the Insert Options button after inserting cells, rows, or columns that contain formatting. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will not display the Insert Options buttons on insert.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showinsertoptionsbuttons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showinsertoptionsbuttons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_shownames","displayName":"Show names (User)","description":"Enabling this setting selects the Advanced (Display) user option to \"Show chart element names on hover\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_shownames_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_shownames_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showpasteoptionsbuttonwhencontentispasted","displayName":"Show Paste Options button when content is pasted (User)","description":"This policy setting sets the \"Show Paste Options button when content is pasted\" option found under File tab | Options | Advanced | Cut, copy, and paste options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will show the Paste Options button after inserting cells, rows, or columns that contain formatting. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will not display the Paste Options buttons on paste.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showpasteoptionsbuttonwhencontentispasted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showpasteoptionsbuttonwhencontentispasted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showvalues","displayName":"Show values (User)","description":"Enabling this setting selects the Advanced (Display) user option to \"Show data point values on hover\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showvalues_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showvalues_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_transitionnavigationkeys","displayName":"Transition navigation keys (User)","description":"Enabling this policy checks the Advanced (Lotus compatibility) user option named \"Transition navigation keys\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_transitionnavigationkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_transitionnavigationkeys_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_zoomonrollwithintellimouse","displayName":"Zoom on roll with IntelliMouse (User)","description":"This policy setting sets the \"Zoom on roll with IntelliMouse'\" option found under File tab | Options | Advanced | Editing options\r\n\r\nIf you enable this policy setting, rolling the mouse wheel will change the zoom level of the worksheet.\r\n\r\nIf you disable or do not configure this policy setting, rolling the mouse wheel will scroll the worksheet. This is the default behavior.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_zoomonrollwithintellimouse_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_zoomonrollwithintellimouse_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced~l_weboptions~l_general_l_loadpicturesfromwebpagesnotcreatedinexcel","displayName":"Load pictures from Web pages not created in Excel (User)","description":"This policy setting controls whether Excel loads graphics when opening Web pages that were not created in Excel. It configures the \"Load pictures from Web pages not created in Excel\" option under the File tab | Options | Advanced | General | Web Options... | General tab.\r\n \r\nIf you enable or do not configure this policy setting, Excel loads any graphics that are included in the pages, regardless of whether they were originally created in Excel.\r\n \r\nIf you disable this policy setting, Excel will not load any pictures from Web pages that were not created in Excel.","helpText":"","infoUrls":[],"categoryId":"b90fb0dc-b8c1-4fc3-b9f9-dfbda4b3f03d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced~l_weboptions~l_general_l_loadpicturesfromwebpagesnotcreatedinexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced~l_weboptions~l_general_l_loadpicturesfromwebpagesnotcreatedinexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_formulas_l_r1c1referencestyle","displayName":"R1C1 reference style (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"9215e382-4e7b-4554-8c80-80277136b544","categoryName":"Formulas","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_formulas_l_r1c1referencestyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_formulas_l_r1c1referencestyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"d1e2bb0d-6c0e-4f40-9f2e-52055edc14b5","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_allowquickanalysis","displayName":"Show Quick Analysis options on selection (User)","description":"This policy setting controls the \"Show Quick Analysis options on selection\" option found under File tab | Options | General | User Interface Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will show Quick Analysis options when data is selected. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will not show these options on selection.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_allowquickanalysis_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_allowquickanalysis_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_allowselectionfloaties","displayName":"Show Mini Toolbar on selection (User)","description":"Disabling this policy setting will result in Mini Toolbar not being displayed on text selection. By default, Mini Toolbar on selection is enabled and its visibility can be changed via a setting in the Excel Options dialog box.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_allowselectionfloaties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_allowselectionfloaties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_defaultsheets","displayName":"Default Sheets (User)","description":"Specifies the initial number of worksheets to create in a new workbook.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_defaultsheets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_defaultsheets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_defaultsheets_l_sheetsinnewworkbook","displayName":"Sheets in new workbook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_disablelivepreview","displayName":"Enable Live Preview (User)","description":"Shows or hides the Live Previews that appear when using Galleries that support previews. Live Preview shows how a command would be applied without actually applying it to the document.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_disablelivepreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_disablelivepreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_font","displayName":"Font (User)","description":"Specifies the \"Standard font\" font name and size.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_font_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_font_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_font_l_namesize","displayName":"Name, Size (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_windowsintaskbar","displayName":"Show all windows in the Taskbar (User)","description":"When multiple workbooks are open simultaneously, this determines whether the user will see a single entry for Excel in the taskbar or a separate entry in the taskbar for each open workbook.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_windowsintaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_windowsintaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_includenewrowsandcolumnsinlist","displayName":"Include new rows and columns in table (User)","description":"When working in cells adjacent to a table (known as a \"list\" in previous versions of Excel), enabling this setting causes the adjacent row or column to become part of the table.","helpText":"","infoUrls":[],"categoryId":"67eb1dab-7805-41bb-af5a-798dc7e29f23","categoryName":"Autocorrect Options","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_includenewrowsandcolumnsinlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_includenewrowsandcolumnsinlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_internetandnetworkpathsashyperlinks","displayName":"Internet and network paths as hyperlinks (User)","description":"This policy setting determines whether Excel automatically creates hyperlinks when users enter URL or UNC path information.\r\n \r\nIf you enable this policy setting, when users type a string of characters that Excel recognizes as a Uniform Resource Locator (URL) or Uniform Naming Convention (UNC) path to a resource on the Internet or a local network, Excel will automatically transform it into a hyperlink. Clicking the hyperlink opens it in the configured default Web browser or the appropriate application.\r\n \r\nIf you disable this policy setting, Excel will not transform URLs and UNC paths to hyperlinks.\r\n \r\nIf you do not configure this policy setting, Excel will automatically transform URLs and UNC paths to hyperlinks and users can change the behavior by selecting or deselecting the \"Internet and network paths as hyperlinks\" check box under File tab | Help | Options | Proofing | AutoCorrect Options... | AutoFormat as You Type tab | Replace as you type.","helpText":"","infoUrls":[],"categoryId":"67eb1dab-7805-41bb-af5a-798dc7e29f23","categoryName":"Autocorrect Options","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_internetandnetworkpathsashyperlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_internetandnetworkpathsashyperlinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoverdelay","displayName":"AutoRecover delay (User)","description":"This policy specifies how long (in seconds) the user must be idle before AutoRecover information will be saved.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoverdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoverdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoverdelay_l_secondsofidletimebeforeautorecoverstarts","displayName":"Seconds of idle time before AutoRecover starts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoversavelocation","displayName":"AutoRecover save location (User)","description":"This policy setting allows you to specify the location where AutoRecover information is to be saved. Directing the location to a network drive may allow you to back up these files along with other network files.\r\n\r\nIf you enable this policy setting, you may specify the location where AutoRecover information is to be saved.\r\n\r\nIf you disable or you do not configure this policy setting, the default location is %userprofile%\\Application Data\\Microsoft\\Excel.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoversavelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoversavelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoversavelocation_l_autorecoversavelocation2","displayName":"AutoRecover save location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecovertime","displayName":"AutoRecover time (User)","description":"This policy determines the interval (in minutes) at which AutoRecover information will be saved.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecovertime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecovertime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecovertime_l_saveautorecoverinfoevery","displayName":"Save AutoRecover info every (minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_defaultfilelocation","displayName":"Default file location (User)","description":"This policy setting allows you to specify the folder that Excel uses when opening or saving a file. This setting can be found under File tab | Options | Save | Save workbook Options.\r\n\r\nIf you enable this policy setting, you may specify this folder.\r\n\r\nIf you disable or do not configure this policy setting, the default folder will be used.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_defaultfilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_defaultfilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_defaultfilelocation_l_defaultfilelocation0","displayName":"Default file location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_disableautorepublish","displayName":"Disable AutoRepublish (User)","description":"This policy setting allows administrators to disable the AutoRepublish feature in Excel. If users choose to publish Excel data to a static Web page and enable the AutoRepublish feature, Excel saves a copy of the data to the Web page every time the user saves the workbook. By default, a message dialog displays every time the user saves a published workbook when AutoRepublish is enabled. From this dialog, the user can disable AutoRepublish temporarily or permanently, or select \"Do not show this message again\" to prevent the dialog from appearing after every save. If the user selects \"Do not show this message again\", Excel will continue to automatically republish the data after every save without informing the user.\r\n \r\n If you enable this policy setting, the AutoRepublish feature is turned off and Excel users will need to publish data to the Web manually.\r\n \r\n If you disable or do not configure this policy setting, users can enable the AutoRepublish feature to automatically republish workbooks saved as type Web Page.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_disableautorepublish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_disableautorepublish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_donotshowautorepublishwarningalert","displayName":"Do not show AutoRepublish warning alert (User)","description":"This policy setting controls whether Excel displays an alert before republishing a workbook to the World Wide Web.\r\n\r\nIf you enable this policy setting, no warning appears when the user saves a published workbook when AutoRepublish is enabled.\r\n \r\nIf you disable or do not configure this policy setting, a message dialog appears every time the user saves a published workbook when AutoRepublish is enabled. From this dialog, the user can disable AutoRepublish temporarily or permanently, or select \"Do not show this message again\" to prevent the dialog from appearing after every save. If the user selects \"Do not show this message again\", Excel will continue to automatically republish the data after every save without informing the user.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_donotshowautorepublishwarningalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_donotshowautorepublishwarningalert_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_keeplastautosavedversions","displayName":"Keep the last AutoSaved versions of files for the next session (User)","description":"This policy setting determines whether Excel keeps the last AutoSaved version of a file if a user closes a file without saving it. (Note: AutoSave applies only when AutoRecover is enabled.)\r\n\r\nIf you enable or do not configure this policy setting, Excel keeps the last AutoSaved version of the file and makes it available to the user the next time the file is opened if the user closes a file without saving it.\r\n\r\nIf you disable this policy setting, Excel does not keep the last AutoSaved version of the file if the user closes a file without saving it.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_keeplastautosavedversions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_keeplastautosavedversions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_promptforworkbookproperties","displayName":"Prompt for workbook properties (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_promptforworkbookproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_promptforworkbookproperties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveautorecoverinfo","displayName":"Save AutoRecover info (User)","description":"Enabling this policy selects the user option to \"Save AutoRecover information every N minutes\".","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveautorecoverinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveautorecoverinfo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas","displayName":"Default file format (User)","description":"This policy setting controls the default file format for saving workbooks in Excel.\r\n\r\nIf you enable this policy setting, you can set the default file format for Excel from among the following options:\r\n\r\n- Excel Workbook (.xlsx).This option is the default configuration in Excel 2016.\r\n- Excel Macro-Enabled Workbook (.xlsm)\r\n- Excel Binary Workbook (.xlsb)\r\n- Web Page (.htm; .html)\r\n- Excel 97-2003 Workbook (.xls)\r\n- Excel 5.0/95 Workbook (.xls)\r\n- OpenDocument Spreadsheet (*.ods)\r\n\r\nUsers can choose to save workbooks in a different file format than the default.\r\n\r\nIf you disable or you do not configure this policy setting, Excel saves new workbooks in the Office Open XML format with an .xlsx extension.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1","displayName":"Save Excel files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_51","displayName":"Excel Workbook (*.xlsx)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_52","displayName":"Excel Macro-Enabled Workbook (*.xlsm)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_50","displayName":"Excel Binary Workbook (*.xlsb)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_44","displayName":"Web Page (*.htm; *.html)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_56","displayName":"Excel 97-2003 Workbook (*.xls)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_39","displayName":"Excel 5.0/95 Workbook (*.xls)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_60","displayName":"OpenDocument Spreadsheet (*.ods)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_turnofffileformatcompatiblitydialogforods","displayName":"Suppress file format compatibility dialog box for OpenDocument Spreadsheet format (User)","description":"This policy setting allows you to configure the file format compatibility dialog box when saving a file as an OpenDocument Spreadsheet file in Microsoft Excel.\r\n\r\nIf you enable this policy setting, the file format compatibility dialog is not displayed whenever you save as an OpenDocument Spreadsheet file in Excel.\r\n\r\nIf you disable or do not configure this policy setting, the file format compatibility dialog is displayed when you save as an OpenDocument Spreadsheet file in Excel.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_turnofffileformatcompatiblitydialogforods_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_turnofffileformatcompatiblitydialogforods_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel","displayName":"Scan encrypted macros in Excel Open XML workbooks (User)","description":"This policy setting controls whether encrypted macros in Open XML workbooks be are required to be scanned with anti-virus software before being opened.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n- Scan encrypted macros: encrypted macros are disabled unless anti-virus software is installed. Encrypted macros are scanned by your anti-virus software when you attempt to open an encrypted workbook that contains macros.\r\n- Scan if anti-virus software available: if anti-virus software is installed, scan the encrypted macros first before allowing them to load. If anti-virus software is not available, allow encrypted macros to load.\r\n- Load macros without scanning: do not check for anti-virus software and allow macros to be loaded in an encrypted file.\r\n\r\nIf you disable or do not configure this policy setting, the behavior will be similar to the \"Scan encrypted macros\" option.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid_0","displayName":"Scan encrypted macros (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid_1","displayName":"Scan if anti-virus software available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid_2","displayName":"Load macros without scanning","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch","displayName":"Force file extension to match file type (User)","description":"This policy setting controls how Excel loads file types that do not match their extension. Excel can load files with extensions that do not match the files' type. For example, if a comma-separated values (CSV) file named example.csv is renamed example.xls (or any other file extension supported by Excel 2003 and earlier only), Excel can properly load it as a CSV file.\r\n\r\nIf you enable this policy setting, you can choose from three options for working with files that have non-matching extensions:\r\n\r\n- Allow different - Excel opens the files properly without warning users that the files have non-matching extensions. If users subsequently edit and save the files, Excel preserves both the true, underlying file format and the incorrect file extension.\r\n\r\n- Allow different, but warn - Excel opens the files properly, but warns users about the file type mismatch. This option is the default configuration in Excel.\r\n\r\n- Always match file type - Excel does not open any files that have non-matching extensions.\r\n\r\nIf you disable or do not configure this policy setting, if users attempt to open files with the wrong extension, Excel opens the file and displays a warning that the file type is not what Excel expected.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_l_empty_0","displayName":"Allow different","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_l_empty_1","displayName":"Allow different, but warn","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_l_empty_2","displayName":"Always match file type","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches","displayName":"Perform file validation on pivot caches (User)","description":"This policy key configures whether or not pivot caches should go through file validation and get scanned for security problems when documents in Excel 97-2003 format are opened.\r\n\r\nIf you enable this policy setting, you may select one of these options:\r\n\r\n- No file validation: Never perform file validation on pivot caches for all Excel files (not recommended).\r\n- Web and email sources: Perform file validation on pivot caches for documents that come from the web and email, in addition to all documents that trigger pivot caches on load (default).\r\n- Always perform validation: Always perform file validation on pivot caches for all Excel files.\r\n\r\nThis setting can be overridden by the Object Model property Application.FileValidationPivot.\r\n\r\nIf you disable or do not configure this policy setting, the \"Web and email source\" setting will apply.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches_l_performfilevalidationonpivotcachesdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches_l_performfilevalidationonpivotcachesdropid_0","displayName":"No file validation","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches_l_performfilevalidationonpivotcachesdropid_1","displayName":"Web and email sources","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches_l_performfilevalidationonpivotcachesdropid_2","displayName":"Always perform validation","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_turnofffilevalidation","displayName":"Turn off file validation (User)","description":"This policy setting allows you turn off the file validation feature.\r\n\r\nIf you enable this policy setting, file validation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, file validation will be turned on. Office Binary Documents (97-2003) are checked to see if they conform against the file format schema before they are opened.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_turnofffilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_turnofffilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel","displayName":"WEBSERVICE Function Notification Settings (User)","description":"This policy setting controls how Excel will warn users when WEBSERVICE functions are present.\r\n\r\nIf you enable this policy setting, you can choose from three options for determining how the specified applications will warn the user about WEBSERVICE functions:\r\n\r\n- Disable all with notification: The application displays the Trust Bar for all WEBSERVICE functions. This option enforces the default configuration in Office.\r\n- Disable all without notification: The application disables all WEBSERVICE functions and does not notify users.\r\n- Enable all WEBSERVICE functions (not recommended): The application enables all WEBSERVICE functions and does not notify users. This option can significantly reduce security by allowing information disclosure to third party web services.\r\n\r\nIf you disable this policy setting, the “Disable all with notification” will be the default setting.\r\nIf you do not configure this policy setting, when users open workbooks that contain WEBSERVICE functions, Excel will open the files with the WEBSERVICE functions disabled and display the Trust Bar with a warning that WEBSERVICE functions are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content,\" then the document is added as a trusted document.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel_l_webcontentwarninglevelvalue","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel_l_webcontentwarninglevelvalue_0","displayName":"Enable all WEBSERVICE functions (not recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel_l_webcontentwarninglevelvalue_1","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel_l_webcontentwarninglevelvalue_2","displayName":"Disable all without notification","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setparametersforcngcontext","displayName":"Set parameters for CNG context (User)","description":"This policy setting allows you to specify the encryption parameters that should be used for the CNG context. \r\n\r\nIf you enable this policy setting, the parameters specified will be passed to the CNG context.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG values will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setparametersforcngcontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setparametersforcngcontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm","displayName":"Specify CNG random number generator algorithm (User)","description":"This policy setting allows you to configure the CNG random number generator to use.\r\n\r\nIf you enable this policy setting, the random number generator specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default random number generator will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_l_specifycngrandomnumbergeneratoralgorithmid","displayName":"Random number generator: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngsaltlength","displayName":"Specify CNG salt length (User)","description":"This policy setting allows you to specific the number of bytes of salt that should be used.\r\n\r\nIf you enable this policy setting, the bytes specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default length or 16 will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngsaltlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngsaltlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility","displayName":"Specify encryption compatibility (User)","description":"This policy setting allows you to specify the encrypted database compatibility.\r\n\r\nIf you enable this policy setting, the compatibility format specified will be applied during encryption for new files\r\n- Use legacy format\r\n- Use next generation format\r\n- All files save with next generation format\r\n\r\nIf you disable or do not configure this policy setting, the default setting, \"Use next generation format,\" will be applied.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_0","displayName":"Use legacy format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_1","displayName":"Use next generation format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_2","displayName":"All files save with next generation format","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_usenewkeyonpasswordchange","displayName":"Use new key on password change (User)","description":"This policy setting allows you to specify if a new encryption key is used when the password is changed.\r\n\r\nIf you enable or do not configure this policy setting, a new intermediate key is generated when the password is changed. This causes any extra key encryptors to be removed when the file is saved.\r\n\r\nIf you disable this policy setting, a new intermediate key is not generated when the password is changed.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_usenewkeyonpasswordchange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_usenewkeyonpasswordchange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users, except if application add-ins are required to be signed by Trusted Publishers.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User) (Deprecated)","description":"This policy setting controls whether the specified Office 2016 applications notify users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the ''Require that application add-ins are signed by Trusted Publisher'' policy setting, which prevents users from changing this policy setting. \r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if an application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the ''Add-ins'' category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User)","description":"This policy setting controls whether the specified Office 2016 applications notify users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the ''Require that application add-ins are signed by Trusted Publisher'' policy setting, which prevents users from changing this policy setting. \r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if an application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the ''Add-ins'' category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for the specified Office 2016 applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, Office 2016 applications do not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.\r\n","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve","displayName":"Set maximum number of trust records to preserve (User)","description":"This policy setting allows you to specify the maximum number of trust records to preserve when the purge task detects that this application has trusted more than the number of trusted documents set by the \"Set maximum number of trusted documents\" policy setting.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of trust records to preserve, with an upper limit of 20000. Due to performance reasons, it is not recommended to set it to the upper limit.\r\n\r\nIf you disable or you do not configure this policy setting, the default value for of 400 is used.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_l_setmaximumnumberoftrustrecordstopreservespinid","displayName":"Maximum to preserve: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_storemacroinpersonalmacroworkbookbydefault","displayName":"Store macro in Personal Macro Workbook by default (User)","description":"This policy setting controls the default location for storing macros in Excel.\r\n \r\n If this policy setting is enabled, Excel stores macros in users' personal macro workbook.\r\n \r\n If you disable or do not configure this policy setting, Excel stores macros in the active workbook from which they are created.\r\n \r\n Note: In the user interface (UI), the \"Store macro in\" drop down list box in the Record Macro dialog box (Macros | Record Macro) allows users to choose whether to store the new macro in the current workbook, a new workbook, or their personal macro workbook (Personal.xlsb), a hidden workbook that opens every time Excel starts.\r\n \r\n By default, Excel displays the \"Store macro in\" box with \"This Workbook\" already selected in the drop-down list. If a user saves a macro in the active workbook and then distributes the workbook to others, the macro is distributed along with the workbook. If you enable this policy setting, Excel displays the \"Store macro in\" box with \"Personal Macro Workbook\" already selected. Users can still select one of the other two options in the drop-down menu.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_storemacroinpersonalmacroworkbookbydefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_storemacroinpersonalmacroworkbookbydefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject","displayName":"Trust access to Visual Basic Project (User)","description":"This policy setting controls whether automation clients such as Microsoft Visual Studio 2005 Tools for Microsoft Office (VSTO) can access the Visual Basic for Applications project system in the specified applications. VSTO projects require access to the Visual Basic for Applications project system in Excel, PowerPoint, and Word, even though the projects do not use Visual Basic for Applications. Design-time support of controls in both Visual Basic and C# projects depends on the Visual Basic for Applications project system in Word and Excel.\r\n\r\nIf you enable this policy setting, VSTO and other automation clients can access the Visual Basic for Applications project system in the specified applications. Users will not be able to change this behavior through the \"Trust access to the VBA project object model\" user interface option under the Macro Settings section of the Trust Center.\r\n\r\nIf you disable this policy setting, VSTO does not have programmatic access to VBA projects. In addition, the \"Trust access to the VBA project object model\" check box is cleared and users cannot change it. Note: Disabling this policy setting prevents VSTO projects from interacting properly with the VBA project system in the selected application.\r\n\r\nIf you do not configure this policy setting, automation clients do not have programmatic access to VBA projects. Users can enable this by selecting the \"Trust access to the VBA project object model\" in the \"Macro Settings\" section of the Trust Center. However, doing so allows macros in any documents the user opens to access the core Visual Basic objects, methods, and properties, which represents a potential security hazard.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_turnofftrusteddocuments","displayName":"Turn off trusted documents (User)","description":"This policy setting allows you to turn off the trusted documents feature. The trusted documents feature allows users to always enable active content in documents such as macros, ActiveX controls, data connections, etc. so that they are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.\r\n\r\nIf you enable this policy setting, you will turn off the trusted documents feature. Users will receive a security prompt every time a document containing active content is opened.\r\n\r\nIf you disable or do not configure this policy setting, documents will be trusted when users enable content for a document, and users will not receive a security prompt.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_turnofftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_turnofftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork","displayName":"Turn off Trusted Documents on the network (User)","description":"This policy setting allows you to turn off the trusted documents feature for documents opened from the network.\r\n\r\nIf you enable this policy setting, users will always see security notifications for active content such as macros, ActiveX controls, data connections, etc. for documents opened from the network.\r\n\r\nIf you disable or do not configure this policy setting, the trusted documents feature allows users to always allow active content in documents such as macros, ActiveX controls, data connections, etc. so that users are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty4","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty4_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty4_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty4_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty4_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles","displayName":"dBase III / IV files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_l_dbaseiiiandivfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_l_dbaseiiiandivfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_l_dbaseiiiandivfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles","displayName":"Dif and Sylk files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles_l_difandsylkfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles_l_difandsylkfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles_l_difandsylkfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles_l_difandsylkfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles","displayName":"Excel 2007 and later add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles_l_excel2007andlateraddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles_l_excel2007andlateraddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles_l_excel2007andlateraddinfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles_l_excel2007andlateraddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks","displayName":"Excel 2007 and later binary workbooks (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates","displayName":"Excel 2007 and later macro-enabled workbooks and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates","displayName":"Excel 2007 and later workbooks and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles","displayName":"Excel 2 macrosheets and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_l_excel2macrosheetsandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_l_excel2macrosheetsandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_l_excel2macrosheetsandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_l_excel2macrosheetsandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_l_excel2macrosheetsandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_l_excel2macrosheetsandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets","displayName":"Excel 2 worksheets (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_l_excel2worksheetsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_l_excel2worksheetsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_l_excel2worksheetsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_l_excel2worksheetsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_l_excel2worksheetsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_l_excel2worksheetsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles","displayName":"Excel 3 macrosheets and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_l_excel3macrosheetsandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_l_excel3macrosheetsandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_l_excel3macrosheetsandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_l_excel3macrosheetsandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_l_excel3macrosheetsandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_l_excel3macrosheetsandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets","displayName":"Excel 3 worksheets (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_l_excel3worksheetsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_l_excel3worksheetsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_l_excel3worksheetsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_l_excel3worksheetsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_l_excel3worksheetsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_l_excel3worksheetsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles","displayName":"Excel 4 macrosheets and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_l_excel4macrosheetsandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_l_excel4macrosheetsandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_l_excel4macrosheetsandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_l_excel4macrosheetsandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_l_excel4macrosheetsandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_l_excel4macrosheetsandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks","displayName":"Excel 4 workbooks (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets","displayName":"Excel 4 worksheets (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates","displayName":"Excel 95-97 workbooks and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks","displayName":"Excel 95 workbooks (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles","displayName":"Excel 97-2003 add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles_l_excel972003addinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles_l_excel972003addinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles_l_excel972003addinfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles_l_excel972003addinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates","displayName":"Excel 97-2003 workbooks and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles","displayName":"Excel add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_l_exceladdinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_l_exceladdinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_l_exceladdinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel","displayName":"Legacy converters for Excel (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_l_legacyconvertersforexceldropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_l_legacyconvertersforexceldropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_l_legacyconvertersforexceldropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_l_legacyconvertersforexceldropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_l_legacyconvertersforexceldropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_l_legacyconvertersforexceldropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel","displayName":"Microsoft Office Open XML converters for Excel (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles","displayName":"Microsoft Office query files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles","displayName":"Microsoft Office data connection files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_l_officedataconnectionfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_l_officedataconnectionfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_l_officedataconnectionfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_offlinecubefiles","displayName":"Offline cube files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_offlinecubefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_offlinecubefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_offlinecubefiles_l_offlinecubefilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_offlinecubefiles_l_offlinecubefilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_offlinecubefiles_l_offlinecubefilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles","displayName":"OpenDocument Spreadsheet files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_otherdatasourcefiles","displayName":"Other data source files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_otherdatasourcefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_otherdatasourcefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_otherdatasourcefiles_l_otherdatasourcefilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_otherdatasourcefiles_l_otherdatasourcefilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_otherdatasourcefiles_l_otherdatasourcefilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior","displayName":"Set default file block behavior (User)","description":"This policy setting allows you to determine if users can open, view, or edit Excel files.\r\n\r\nIf you enable this policy setting, you can set one of these options:\r\n- Blocked files are not opened\r\n- Blocked files open in Protected View and can not be edited\r\n- Blocked files open in Protected View and can be edited\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the same as the \"Blocked files are not opened\" setting. Users will not be able to open blocked files.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_0","displayName":"Blocked files are not opened","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_1","displayName":"Blocked files open in Protected View and can not be edited","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_2","displayName":"Blocked files open in Protected View and can be edited","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles","displayName":"Text files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles_l_textfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles_l_textfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles_l_textfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles_l_textfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets","displayName":"Web pages and Excel 2003 XML spreadsheets (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles","displayName":"XML files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles_l_xmlfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles_l_xmlfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles_l_xmlfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles_l_xmlfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview","displayName":"Do not open files from the Internet zone in Protected View (User)","description":"This policy setting allows you to determine if files downloaded from the Internet zone open in Protected View.\r\n\r\nIf you enable this policy setting, files downloaded from the Internet zone do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files downloaded from the Internet zone open in Protected View.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview","displayName":"Do not open files in unsafe locations in Protected View (User)","description":"This policy setting lets you determine if files located in unsafe locations will open in Protected View. If you have not specified unsafe locations, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders are considered unsafe locations.\r\n\r\nIf you enable this policy setting, files located in unsafe locations do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files located in unsafe locations open in Protected View.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview","displayName":"Open files on local Intranet UNC in Protected View (User)","description":"This policy setting lets you determine if files on local Intranet UNC file shares open in Protected View.\r\n\r\nIf you enable this policy setting, files on local Intranet UNC file shares open in Protected View if their UNC paths appear to be within the Internet zone.\r\n\r\nIf you disable or do not configure this policy setting, files on Intranet UNC file shares do not open in Protected View if their UNC paths appear to be within the Internet zone.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails","displayName":"Set document behavior if file validation fails (User)","description":"This policy setting controls how Office handles documents when they fail file validation. \r\n\r\nIf you enable this policy setting, you can configure the following options for files that fail file validation:\r\n\r\n- Block files completely. Users cannot open the files.\r\n- Open files in Protected View and disallow edit. Users cannot edit the files. This is also how Office handles the files if you disable this policy setting.\r\n- Open files in Protected View and allow edit. Users can edit the files. This is also how Office handles the files if you do not configure this policy setting.\r\n\r\nIf you disable this policy setting, Office follows the \"Open files in Protected View and disallow edit\" behavior.\r\n\r\nIf you do not configure this policy setting, Office follows the \"Open files in Protected View and allow edit\" behavior.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_0","displayName":"Block files","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_1","displayName":"Open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3","displayName":"Checked: Allow edit. Unchecked: Do not allow edit. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook","displayName":"Turn off Protected View for attachments opened from Outlook (User)","description":"This policy setting allows you to determine if Excel files in Outlook attachments open in Protected View.\r\n\r\nIf you enable this policy setting, Outlook attachments do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, Outlook attachments open in Protected View.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork","displayName":"Allow Trusted Locations on the network (User)","description":"This policy setting controls whether trusted locations on the network can be used.\r\n\r\nIf you enable this policy setting, users can specify trusted locations on network shares or in other remote locations that are not under their direct control by clicking the \"Add new location\" button in the Trusted Locations section of the Trust Center. Content, code, and add-ins are allowed to load from trusted locations with minimal security and without prompting the user for permission.\r\n\r\nIf you disable this policy setting, the selected application ignores any network locations listed in the Trusted Locations section of the Trust Center. \r\n\r\nIf you also deploy Trusted Locations via Group Policy, you should verify whether any of them are remote locations. If any of them are remote locations and you do not allow remote locations via this policy setting, those policy keys that point to remote locations will be ignored on client computers.\r\n\r\nDisabling this policy setting does not delete any network locations from the Trusted Locations list, but causes disruption for users who add network locations to the Trusted Locations list. Users are also prevented from adding new network locations to the Trusted Locations list in the Trust Center. We recommended that you do not enable this policy setting (as the \"Allow Trusted Locations on my network (not recommended)\" check box also states). Therefore, in practice, it should be possible to disable this policy setting in most situations without causing significant usability issues for most users.\r\n\r\nIf you do not enable this policy setting, users can select the \"Allow Trusted Locations on my network (not recommended)\" check box if desired and then specify trusted locations by clicking the \"Add new location\" button.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders8","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders8_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders8_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_datecolon6","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_descriptioncolon7","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_pathcolon5","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders12","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders12_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders12_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_datecolon10","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_descriptioncolon11","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_pathcolon9","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders16","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders16_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders16_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_datecolon14","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_descriptioncolon15","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_pathcolon13","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders20","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders20_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders20_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_datecolon18","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_descriptioncolon19","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_pathcolon17","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders24","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders24_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders24_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon22","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_descriptioncolon23","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_pathcolon21","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders28","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders28_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders28_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_datecolon26","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_descriptioncolon27","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_pathcolon25","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders32","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders32_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders32_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_datecolon30","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_descriptioncolon31","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_pathcolon29","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders36","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders36_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders36_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_datecolon34","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_descriptioncolon35","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_pathcolon33","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders40","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders40_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders40_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_datecolon38","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_descriptioncolon39","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_pathcolon37","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11","displayName":"Trusted Location #11 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders44","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders44_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders44_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_datecolon42","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_descriptioncolon43","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_pathcolon41","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders48","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders48_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders48_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_datecolon46","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_descriptioncolon47","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_pathcolon45","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders52","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders52_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders52_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_datecolon50","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_descriptioncolon51","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_pathcolon49","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders56","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders56_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders56_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_datecolon54","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_descriptioncolon55","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_pathcolon53","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders60","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders60_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders60_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_datecolon58","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_descriptioncolon59","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_pathcolon57","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders64","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders64_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders64_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_datecolon62","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_descriptioncolon63","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_pathcolon61","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders68","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders68_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders68_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_datecolon66","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_descriptioncolon67","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_pathcolon65","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders72","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders72_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders72_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_datecolon70","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_descriptioncolon71","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_pathcolon69","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders76","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders76_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders76_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_datecolon74","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_descriptioncolon75","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_pathcolon73","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders80","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders80_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders80_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_datecolon78","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_descriptioncolon79","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_pathcolon77","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation","displayName":"Check for accessibility issues while editing (User)","description":"This policy setting controls whether accessibility issues are checked for automatically while the user is editing a workbook. By default, accessibility issues aren’t checked for automatically.\r\n\r\nIf you enable this policy setting, accessibility issues are checked for automatically and users won’t be able to turn it off. The status bar will indicate if accessibility recommendations are available to make the workbook more usable by people with disabilities.\r\n\r\nIf you disable or don’t configure this policy setting, accessibility issues won’t be checked for automatically while editing a workbook. Users can turn on automatic checking by going to File > Options > Ease of Access.\r\n","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation","displayName":"Stop checking for alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that objects such as images and shapes contain alternative text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that objects such as images and shapes contain alternative text.\r\n\r\nIf you disable or do not configure this policy setting, objects will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsusedasformatting","displayName":"Stop checking for blank table rows used as formatting (User)","description":"This policy setting allows you to configure Accessibility Checker and whether it checks for blank table rows used as formatting.\r\n\r\nIf you enable this policy setting, no check for blank table rows used as formatting will be done.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for blank rows and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsusedasformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsusedasformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingformergedcells","displayName":"Stop checking for merged cells (User)","description":"This policy setting allows you to configure whether Accessibility Checker will verify that tables do not have merged cells.\r\n\r\nIf you enable this policy setting, no check will be made.\r\n\r\nIf you disable or do not configure this policy setting, worksheets will be checked for merged cells and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingformergedcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingformergedcells_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation","displayName":"Stop checking for table header accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables have a header row specified.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables have a header row specified.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for header rows and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful","displayName":"Stop checking to ensure hyperlink text is meaningful (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensurenondefaultsheetnames","displayName":"Stop checking to ensure non-default sheet names (User)","description":"This policy setting prevents the Accessibility Checker from verifying that worksheets with content have non-default names.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that worksheets with content have non-default names.\r\n\r\nIf you disable or do not configure this policy setting, worksheet names will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensurenondefaultsheetnames_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensurenondefaultsheetnames_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensureworkbooksallowprogrammaticaccess","displayName":"Stop checking to ensure workbooks allow programmatic access (User)","description":"This policy setting allows you to configure Accessibility Checker and whether it checks to ensure that workbooks have not blocked programmatic access through DRM.\r\n\r\nIf you enable this policy setting, no check will be made.\r\n\r\nIf you disable or do not configure this policy setting, workbooks will be checked for programmatic access and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensureworkbooksallowprogrammaticaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensureworkbooksallowprogrammaticaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_intelligentservices_l_insights","displayName":"Remove Ideas button from the Ribbon (User)","description":"\r\nThis policy setting allows you to prevent users from accessing Ideas in Excel, an intelligent service providing suggestions and analyses based on your data. By default, a button for Ideas appears in the “Ideas” group on the “Home” tab on the ribbon.\r\n\r\nIf you enable this policy setting, the button for Ideas is removed from the ribbon and users can’t add the button to the ribbon manually. Users won’t be able to access Ideas.\r\n\r\nIf you disable or don’t configure this policy setting, the button for Ideas appears on the ribbon and users can access Ideas.\r\n\t\t","helpText":"","infoUrls":[],"categoryId":"9a2bfe77-7e03-4a24-a9fa-c42a225a28b8","categoryName":"Intelligent Services","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_intelligentservices_l_insights_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_intelligentservices_l_insights_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_defaultcustomtab","displayName":"Show custom templates tab by default in Excel on the Office Start screen and in File | New (User)","description":"This policy setting controls whether custom templates (when they exist) show as the default tab in Excel on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, users will the see custom templates tab as the default tab in Excel on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Excel on the Office Start screen and in File | New, unless all Office-provided templates have been disabled.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_defaultcustomtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_defaultcustomtab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_disableofficestartexcel","displayName":"Disable the Office Start screen for Excel (User)","description":"This policy setting controls whether the Office Start screen appears on boot for Excel.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot Excel.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot Excel.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_disableofficestartexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_disableofficestartexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_donotcachenetworkfileslocally","displayName":"Do not cache network files locally (User)","description":"This policy setting allows you to configure whether network files are locally cached when editing spreadsheets stored on network shares.\r\n\r\nIf you enable this policy setting, a file located on a network share may not be saved if the network connection was lost at any time while editing the file and the file contains a pivot table, VBE code or an embedded OLE object. \r\n\r\nIf you disable or do not configure this policy setting, network files are locally cached when editing spreadsheets stored on network shares. This may help prevent data loss during network failures.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_donotcachenetworkfileslocally_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_donotcachenetworkfileslocally_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_enablefourdigityeardisplay","displayName":"Enable four-digit year display (User)","description":"When this setting is not enabled, Excel follows the Short date style setting under Regional Settings in Control Panel. When this setting is enabled, Excel always displays four digits when you type a date that includes a four-digit year, which may override the Short date style setting under Regional Settings in Control Panel.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_enablefourdigityeardisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_enablefourdigityeardisplay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_graphgallerypath","displayName":"Graph gallery path (User)","description":"Sets the path where user defined graph templates are stored.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_graphgallerypath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_graphgallerypath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_graphgallerypath_l_graphgallerypath169","displayName":"Graph gallery path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins, Excel Automation add-ins, and RTD add-ins, or specify the file name of Excel XLL add-ins and Excel add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\Excel\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\Excel\\Addins.\r\n\r\nTo obtain the file name of an add-in, click the File menu in the application where the add-in is installed. Click Options, click Add-ins, and then use the Location column to determine the file name of the add-in.\r\n\r\nYou can also obtain the ProgID or the file name of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting","displayName":"OLAP PivotTable User Defined Function (UDF) security setting (User)","description":"PivotTable reports can contain OLAP queries with references to User Defined Functions (UDFs). UDFs can be compiled executables, therefore posing a potential security threat. With this setting you can either (1) allow all UDFs in OLAP queries to execute with no IObjectSafety check, (2) allow only UDFs where the developer has used IObjectSafety to mark the UDF as a safe executable, or (3) disable all UDFs from executing in OLAP queries. The effect of setting this key is for Excel to pass the selected value to the OLAP provider.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting_l_olappivottableuserdefinedfunctionudfsecuritysetting171","displayName":"OLAP PivotTable User Defined Function (UDF) security setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting_l_olappivottableuserdefinedfunctionudfsecuritysetting171_1","displayName":"Allow ALL UDFs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting_l_olappivottableuserdefinedfunctionudfsecuritysetting171_2","displayName":"Allow safe UDFs only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting_l_olappivottableuserdefinedfunctionudfsecuritysetting171_3","displayName":"Allow NO UDFs","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_personaltemplatespath","displayName":"Personal templates path for Excel (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp","displayName":"Turn off file synchronization via SOAP over HTTP (User)","description":"This policy setting controls file synchronization via SOAP over HTTP for Excel.\r\n\r\nIf you enable this policy setting, file synchronization via SOAP over HTTP is turned off for Excel.\r\n\r\nIf you disable or do not configure this policy setting this policy setting, file synchronization via SOAP over HTTP is turned on for Excel.\r\n\r\nNote: Turning off file synchronization via SOAP over HTTP will adversely affect the behavior of SharePoint Workspaces.","helpText":"","infoUrls":[],"categoryId":"183628a3-d0a5-47de-b444-e132d634ca38","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlaunch","displayName":"Don’t allow Dynamic Data Exchange (DDE) server launch in Excel (User)","description":"This policy setting allows you to control whether Dynamic Data Exchange (DDE) server launch is allowed.\r\n\r\nBy default, DDE server launch is turned off, but users can turn on DDE server launch by going to File > Options > Trust Center > Trust Center Settings > External Content.\r\n\r\nFor security reasons, turning on DDE server launch is not recommended.\r\n\r\nNote: For DDE server launch to work, Dynamic Data Exchange (DDE) server lookup must be turned on. Be sure that the “Don’t allow Dynamic Data Exchange (DDE) server lookup” policy setting isn’t enabled, because enabling that policy setting turns off DDE server lookup.\r\n\r\nIf you enable this policy setting, DDE server launch isn’t allowed, and users can’t turn on DDE server launch in the Trust Center.\r\n\r\nIf you disable this policy setting, DDE server launch is allowed, and users cannot turn off DDE server launch in the Trust Center. For security reasons, this is not recommended.\r\n\r\nIf you don’t configure this policy setting, DDE server launch is turned off, but users can turn on DDE server launch in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"e36863b6-3232-4a29-be02-32ee67cc48b9","categoryName":"External Content","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlaunch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlaunch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlookup","displayName":"Don’t allow Dynamic Data Exchange (DDE) server lookup in Excel (User)","description":"This policy setting allows you to control whether Dynamic Data Exchange (DDE) server lookup is allowed.\r\n\r\nBy default, DDE server lookup is turned on, but users can turn off DDE server lookup by going to File > Options > Trust Center > Trust Center Settings > External Content.\r\n\r\nIf you enable this policy setting, DDE server lookup isn’t allowed, and users can’t turn on DDE server lookup in the Trust Center.\r\n\r\nNote: If you’re using Dynamic Data Exchange (DDE) server launch, which isn’t recommended, don’t enable this policy setting, because DDE server launch requires DDE server lookup to be on.\r\n\r\nIf you disable or don’t configure this policy setting, DDE server lookup is turned on, but users can turn off DDE server lookup in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"e36863b6-3232-4a29-be02-32ee67cc48b9","categoryName":"External Content","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlookup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlookup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_enableblockunsecurequeryfiles","displayName":"Always prevent untrusted Microsoft Query files from opening (User)","description":"This policy setting controls whether Microsoft Query files (.iqy, oqy, .dqy, and .rqy) in an untrusted location are prevented from opening.\r\n\r\nIf you enable this policy setting, Microsoft Query files in an untrusted location are prevented from opening. Users will not be able to change this setting under File > Options > Trust Center > Trust Center Settings > External Content.\r\n\r\nIf you disable or don’t configure this policy setting, Microsoft Query files in an untrusted location are not prevented from opening, unless users have changed this setting in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"e36863b6-3232-4a29-be02-32ee67cc48b9","categoryName":"External Content","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_enableblockunsecurequeryfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_enableblockunsecurequeryfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_enabledatabasefileprotectedview","displayName":"Always open untrusted database files in Protected View (User)","description":"This policy setting controls whether database files (.dbf) opened from an untrusted location are always opened in Protected View.\r\n\r\nIf you enable this policy setting, database files opened from an untrusted location are always opened in Protected View. Users will not be able to change this setting under File > Options > Trust Center > Trust Center Settings > Protected View.\r\n\r\nIf you disable or don’t configure this policy setting, database files opened from an untrusted location are not opened in Protected View, unless users have changed this setting in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_enabledatabasefileprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_enabledatabasefileprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_enableforeigntextfileprotectedview","displayName":"Always open untrusted text-based files in Protected View (User)","description":"This policy setting controls whether text-based files (.csv, .dif, and .sylk) opened from an untrusted location are always opened in Protected View.\r\n\r\nIf you enable this policy setting, text-based files opened from an untrusted location are always opened in Protected View. Users will not be able to change this setting under File > Options > Trust Center > Trust Center Settings > Protected View.\r\n\r\nIf you disable or don’t configure this policy setting, text-based files opened from an untrusted location are not opened in Protected View, unless users have changed this setting in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_enableforeigntextfileprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_enableforeigntextfileprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v4~policy~l_microsoftofficeexcel~l_powerbi_l_disablefrompowerbidatasetorganizationname","displayName":"Disable displaying organization name in the buttons to create PivotTables from Power BI datasets (User)","description":"\r\n This policy setting allows you to prevent the organization name from being displayed in the buttons in the Excel ribbon used to create PivotTables from Power BI datasets. By default, the organization name will be shown in the ribbon if it is available from Graph.\r\n\r\n If you enable this policy setting, the organization name will not be shown.\r\n\r\n If you disable or don’t configure this policy setting, the organization name will be shown.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"b473c6fa-a971-4e5d-ad15-2c27c17c5d3e","categoryName":"Power BI","options":[{"id":"user_vendor_msft_policy_config_excel16v4~policy~l_microsoftofficeexcel~l_powerbi_l_disablefrompowerbidatasetorganizationname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v4~policy~l_microsoftofficeexcel~l_powerbi_l_disablefrompowerbidatasetorganizationname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v5~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation","displayName":"Stop checking for table alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables contain alternative text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables contain alternative text.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v5~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v5~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v6~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_xl4killswitchpolicy","displayName":"Prevent Excel from running XLM macros (User)","description":"This policy setting will prevent Excel from running Excel 4.0 (XLM) macros.\r\n\r\nIf you enable this policy setting, XLM macros cannot be run in Excel.\r\n\r\nIf you disable or don’t configure this policy setting, XLM macros can be run in Excel.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v6~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_xl4killswitchpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v6~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_xl4killswitchpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v7~policy~l_microsoftofficeexcel~l_miscellaneous168_l_exceldisableofficescripts","displayName":"Disable Office Scripts in Excel for Windows Desktop (User)","description":"This policy setting controls whether Office Scripts (including the relevant commands on the Automate tab) are available for use.\r\n\r\nIf you enable this policy setting, Office Scripts will not be available for use on the installed Excel app on a desktop.\r\n\r\nIf you disable or don't configure this policy setting, Office Scripts will be available for use provided all other prerequisites are met, including the applicable Microsoft 365 subscription license.\r\n\r\nNote: This policy setting is independent of Office Scripts settings available to administrators in the Microsoft 365 Admin Center. Admin Center settings are always honored by the Excel app regardless of the state of this policy; however, turning on this policy will also hide Office Scripts-related entry points.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v7~policy~l_microsoftofficeexcel~l_miscellaneous168_l_exceldisableofficescripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v7~policy~l_microsoftofficeexcel~l_miscellaneous168_l_exceldisableofficescripts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet","displayName":"Block Excel XLL Add-ins that come from an untrusted source (User)","description":"\r\n This policy setting allows you to block Excel XLL Add-ins that come from an untrusted source.\r\n\r\n If you enable this policy setting, you can set one of these options:\r\n - Block: XLL add-ins from untrusted sources are blocked. Users will receive a notification that the add-in was blocked.\r\n - Show Additional Warning: Show an additional warning prompt after the user chooses to enable an XLL add-in from an untrusted source.\r\n - Allow: XLL add-ins from an untrusted source are allowed.\r\n\r\n The exceptions when Excel XLL Add-ins will be allowed to run are:\r\n - The XLL is stored in a Trusted Location.\r\n - The XLL is digitally signed and the matching Trusted Publisher certificate is installed on the device.\r\n\r\n If you disable this policy setting, the settings configured in the Macro and Add-in Settings sections of the Trust Center determine whether Excel XLL Add-ins that come from an untrusted source will be allowed.\r\n\r\n If you disable or do not configure this policy setting, users will be able to override default behavior by modifying the registry.\r\n\r\n For more information, see https://support.microsoft.com/topic/1e3752e2-1177-4444-a807-7b700266a6fb.\r\n ","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet_l_blockxllfrominternetenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet_l_blockxllfrominternetenum_1","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet_l_blockxllfrominternetenum_0","displayName":"Show Additional Warning","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet_l_blockxllfrominternetenum_2","displayName":"Allow","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v9~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excelfileblockexternallinks","displayName":"File Block includes external link files (User)","description":"This setting determines whether Trust Center settings for blocking load of potentially unsecure workbooks applies to those accessed by external links.\r\n\r\nIf you enable this policy setting, external links to workbooks that are blocked by File Block settings in Trust Center will not refresh. Attempts to create new links or refresh data from blocked workbooks may result in errors.\r\n\r\nIf you disable this policy setting, attempts to access external links data will not be subject to File Block settings in Trust Center.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v9~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excelfileblockexternallinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v9~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excelfileblockexternallinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_allowspotlightcollection","displayName":"Allow Spotlight Collection (User)","description":"Specifies whether Spotlight collection is allowed as a Personalization->Background Setting. If you enable this policy setting, Spotlight collection will show as an option in the user's Personalization Settings, and the user will be able to get daily images from Microsoft displayed on their desktop. If you disable this policy setting, Spotlight collection will not show as an option in Personliazation Settings, and the user will not have the choice of getting Microsoft daily images shown on their desktop.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowspotlightcollection"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":null},{"id":"user_vendor_msft_policy_config_experience_allowtailoredexperienceswithdiagnosticdata","displayName":"Allow Tailored Experiences With Diagnostic Data (User)","description":"This policy allows you to prevent Windows from using diagnostic data to provide customized experiences to the user. If you enable this policy setting, Windows will not use diagnostic data from this device to customize content shown on the lock screen, Windows tips, Microsoft consumer features, or other related features. If these features are enabled, users will still see recommendations, tips and offers, but they may be less relevant. If you disable or do not configure this policy setting, Microsoft will use diagnostic data to provide personalized recommendations, tips, and offers to tailor Windows for the user's needs and make it work better for them. Diagnostic data can include browser, app and feature usage, depending on the Diagnostic and usage data setting value. Note This setting does not control Cortana cutomized experiences because there are separate policies to configure it. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowtailoredexperienceswithdiagnosticdata"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowtailoredexperienceswithdiagnosticdata_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowtailoredexperienceswithdiagnosticdata_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_allowthirdpartysuggestionsinwindowsspotlight","displayName":"Allow Third Party Suggestions In Windows Spotlight (User)","description":"Specifies whether to allow app and content suggestions from third-party software publishers in Windows spotlight features like lock screen spotlight, suggested apps in the Start menu, and Windows tips. Users may still see suggestions for Microsoft features, apps, and services.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowthirdpartysuggestionsinwindowsspotlight"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowthirdpartysuggestionsinwindowsspotlight_0","displayName":"Block","description":"Third-party suggestions not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowthirdpartysuggestionsinwindowsspotlight_1","displayName":"Allow","description":"Third-party suggestions allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlight","displayName":"Allow Windows Spotlight (User)","description":"Specifies whether to turn off all Windows spotlight features at once. If you enable this policy setting, Windows spotlight on lock screen, Windows Tips, Microsoft consumer features and other related features will be turned off. You should enable this policy setting if your goal is to minimize network traffic from target devices. If you disable or do not configure this policy setting, Windows spotlight features are allowed and may be controlled individually using their corresponding policy settings. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlight"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlight_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlight_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonactioncenter","displayName":"Allow Windows Spotlight On Action Center (User)","description":"This policy allows administrators to prevent Windows spotlight notifications from being displayed in the Action Center. If you enable this policy, Windows spotlight notifications will no longer be displayed in the Action Center. If you disable or do not configure this policy, Microsoft may display notifications in the Action Center that will suggest apps or features to help users be more productive on Windows. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlightonactioncenter"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonactioncenter_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonactioncenter_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonsettings","displayName":"Allow Windows Spotlight On Settings (User)","description":"This policy allows IT admins to turn off Suggestions in Settings app. These suggestions from Microsoft may show after each OS clean install, upgrade or an on-going basis to help users discover apps/features on Windows or across devices, to make their experience productive. User setting is under Settings -> Privacy -> General -> Show me suggested content in Settings app. User Setting is changeable on a per user basis. If the Group policy is set to off, no suggestions will be shown to the user in Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlightonsettings"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonsettings_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonsettings_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightwindowswelcomeexperience","displayName":"Allow Windows Spotlight Windows Welcome Experience (User)","description":"This policy setting lets you turn off the Windows spotlight Windows welcome experience feature. The Windows welcome experience feature introduces onboard users to Windows; for example, launching Microsoft Edge with a webpage that highlights new features. If you enable this policy, the Windows welcome experience will no longer be displayed when there are updates and changes to Windows and its apps. If you disable or do not configure this policy, the Windows welcome experience will be launched to inform onboard users about what's new, changed, and suggested. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlightwindowswelcomeexperience"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightwindowswelcomeexperience_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightwindowswelcomeexperience_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_configurewindowsspotlightonlockscreen","displayName":"Configure Windows Spotlight On Lock Screen (User)","description":"Allows IT admins to specify whether spotlight should be used on the user's lock screen. If your organization does not have an Enterprise spotlight content service, then this policy will behave the same as a setting of 1.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#configurewindowsspotlightonlockscreen"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_configurewindowsspotlightonlockscreen_0","displayName":"Windows spotlight disabled.","description":"Windows spotlight disabled.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_configurewindowsspotlightonlockscreen_1","displayName":"Windows spotlight enabled.","description":"Windows spotlight enabled.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_configurewindowsspotlightonlockscreen_2","displayName":"Windows spotlight is always enabled, the user cannot disable it","description":"Windows spotlight is always enabled, the user cannot disable it","helpText":null},{"id":"user_vendor_msft_policy_config_experience_configurewindowsspotlightonlockscreen_3","displayName":"Windows spotlight is always enabled, the user cannot disable it. For special configurations only","description":"Windows spotlight is always enabled, the user cannot disable it. For special configurations only","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_enableorganizationalmessages","displayName":"Enable delivery of organizational messages (User)","description":"Organizational messages allow Administrators to deliver messages to their end users on selected Windows 11 experiences. Organizational messages are available to Administrators via services like Microsoft Endpoint Manager. By default, this policy is disabled. If you enable this policy, these experiences will show content booked by Administrators. Enabling this policy will have no impact on existing MDM policy settings governing delivery of content from Microsoft on Windows experiences.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#enableorganizationalmessages"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_enableorganizationalmessages_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"user_vendor_msft_policy_config_experience_enableorganizationalmessages_1","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork","displayName":"Allow Option To Show Network (User)","description":"When the Network folder is restricted, give the user the option to enumerate and navigate into it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#allowoptiontoshownetwork"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork_0","displayName":"Not Allowed.","description":"Not Allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc","displayName":"Allow Option To Show This PC (User)","description":"When This PC location is restricted, give the user the option to enumerate and navigate into it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#allowoptiontoshowthispc"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc_0","displayName":"Not Allowed.","description":"Not Allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations","displayName":"Set Allowed Folder Locations (User)","description":"A value that can represent one or more folder locations in File Explorer. If not specified, the default is access to all folder locations.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#setallowedfolderlocations"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations_0","displayName":"Access to all folder locations.","description":"Access to all folder locations.","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations_13","displayName":"Documents, Pictures, Downloads","description":"Documents, Pictures, Downloads","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations_15","displayName":"Desktop, Documents, Pictures, Downloads","description":"Desktop, Documents, Pictures, Downloads","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations_31","displayName":"Desktop, Documents, Pictures, Downloads, Network","description":"Desktop, Documents, Pictures, Downloads, Network","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations_47","displayName":"This PC, Desktop, Documents, Pictures, Downloads","description":"This PC, Desktop, Documents, Pictures, Downloads","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations_63","displayName":"This PC, Desktop, Documents, Pictures, Downloads, Network","description":"This PC, Desktop, Documents, Pictures, Downloads, Network","helpText":null}]},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations","displayName":"Set Allowed Storage Locations (User)","description":"A value that can represent one or more storage locations in File Explorer. If not specified, the default is access to all storage locations.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#setallowedstoragelocations"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_0","displayName":"Access to all storage locations.","description":"Access to all storage locations.","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_1","displayName":"Removable Drives","description":"Removable Drives","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_2","displayName":"Sync roots","description":"Sync roots","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_3","displayName":"Removable Drives, Sync roots","description":"Removable Drives, Sync roots","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_4","displayName":"Local Drives","description":"Local Drives","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_5","displayName":"Removable Drives, Local Drives","description":"Removable Drives, Local Drives","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_6","displayName":"Sync Roots, Local Drives","description":"Sync Roots, Local Drives","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_7","displayName":"Removable Drives, Sync Roots, Local Drives","description":"Removable Drives, Sync Roots, Local Drives","helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_addsearchprovider","displayName":"Add a specific list of search providers to the user's list of search providers (User)","description":"This policy setting allows you to add a specific list of search providers to the user's default list of search providers. Normally, search providers can be added from third-party toolbars or in Setup. The user can also add a search provider from the provider's website.\n\nIf you enable this policy setting, the user can add and remove search providers, but only from the set of search providers specified in the list of policy keys for search providers (found under [HKCU or HKLM\\Software\\policies\\Microsoft\\Internet Explorer\\SearchScopes]). Note: This list can be created from a custom administrative template file. For information about creating this custom administrative template file, see the Internet Explorer documentation on search providers.\n\nIf you disable or do not configure this policy setting, the user can configure their list of search providers unless another policy setting restricts such configuration.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-addsearchprovider"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_addsearchprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_addsearchprovider_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowactivexfiltering","displayName":"Turn on ActiveX Filtering (User)","description":"This policy setting controls the ActiveX Filtering feature for websites that are running ActiveX controls. The user can choose to turn off ActiveX Filtering for specific websites so that ActiveX controls can run properly.\n\nIf you enable this policy setting, ActiveX Filtering is enabled by default for the user. The user cannot turn off ActiveX Filtering, although they may add per-site exceptions.\n\nIf you disable or do not configure this policy setting, ActiveX Filtering is not enabled by default for the user. The user can turn ActiveX Filtering on or off.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowactivexfiltering"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowactivexfiltering_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowactivexfiltering_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowaddonlist","displayName":"Add-on List (User)","description":"This policy setting allows you to manage a list of add-ons to be allowed or denied by Internet Explorer. Add-ons in this case are controls like ActiveX Controls, Toolbars, and Browser Helper Objects (BHOs) which are specifically written to extend or enhance the functionality of the browser or web pages.\n\nThis list can be used with the 'Deny all add-ons unless specifically allowed in the Add-on List' policy setting, which defines whether add-ons not listed here are assumed to be denied.\n\nIf you enable this policy setting, you can enter a list of add-ons to be allowed or denied by Internet Explorer. For each entry that you add to the list, enter the following information:\n\nName of the Value - the CLSID (class identifier) for the add-on you wish to add to the list. The CLSID should be in brackets for example, ‘{000000000-0000-0000-0000-0000000000000}'. The CLSID for an add-on can be obtained by reading the OBJECT tag from a Web page on which the add-on is referenced.\n\nValue - A number indicating whether Internet Explorer should deny or allow the add-on to be loaded. To specify that an add-on should be denied enter a 0 (zero) into this field. To specify that an add-on should be allowed, enter a 1 (one) into this field. To specify that an add-on should be allowed and also permit the user to manage the add-on through Add-on Manager, enter a 2 (two) into this field.\n\nIf you disable this policy setting, the list is deleted. The 'Deny all add-ons unless specifically allowed in the Add-on List' policy setting will still determine whether add-ons not in this list are assumed to be denied.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowaddonlist"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowaddonlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowaddonlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowaddonlist_addonlist","displayName":"Add-on List (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowaddonlist_addonlist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowaddonlist_addonlist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete","displayName":"Turn on the auto-complete feature for user names and passwords on forms (User)","description":"This AutoComplete feature can remember and suggest User names and passwords on Forms.\n\nIf you enable this setting, the user cannot change \"User name and passwords on forms\" or \"prompt me to save passwords\". The Auto Complete feature for User names and passwords on Forms will be turned on. You have to decide whether to select \"prompt me to save passwords\".\n\nIf you disable this setting the user cannot change \"User name and passwords on forms\" or \"prompt me to save passwords\". The Auto Complete feature for User names and passwords on Forms is turned off. The user also cannot opt to be prompted to save passwords.\n\nIf you do not configure this setting, the user has the freedom of turning on Auto complete for User name and passwords on forms and the option of prompting to save passwords. To display this option, the users open the Internet Options dialog box, click the Contents Tab and click the Settings button.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowautocomplete"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_chkbox_passwordask","displayName":"Prompt me to save passwords (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_chkbox_passwordask_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_chkbox_passwordask_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowcertificateaddressmismatchwarning","displayName":"Turn on certificate address mismatch warning (User)","description":"This policy setting allows you to turn on the certificate address mismatch security warning. When this policy setting is turned on, the user is warned when visiting Secure HTTP (HTTPS) websites that present certificates issued for a different website address. This warning helps prevent spoofing attacks.\n\nIf you enable this policy setting, the certificate address mismatch warning always appears.\n\nIf you disable or do not configure this policy setting, the user can choose whether the certificate address mismatch warning appears (by using the Advanced page in the Internet Control panel).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowcertificateaddressmismatchwarning"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowcertificateaddressmismatchwarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowcertificateaddressmismatchwarning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowdeletingbrowsinghistoryonexit","displayName":"Allow deleting browsing history on exit (User)","description":"This policy setting allows the automatic deletion of specified items when the last browser window closes. The preferences selected in the Delete Browsing History dialog box (such as deleting temporary Internet files, cookies, history, form data, and passwords) are applied, and those items are deleted.\n\nIf you enable this policy setting, deleting browsing history on exit is turned on.\n\nIf you disable this policy setting, deleting browsing history on exit is turned off.\n\nIf you do not configure this policy setting, it can be configured on the General tab in Internet Options.\n\nIf the \"Prevent access to Delete Browsing History\" policy setting is enabled, this policy setting has no effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowdeletingbrowsinghistoryonexit"],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowdeletingbrowsinghistoryonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowdeletingbrowsinghistoryonexit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedprotectedmode","displayName":"Turn on Enhanced Protected Mode (User)","description":"Enhanced Protected Mode provides additional protection against malicious websites by using 64-bit processes on 64-bit versions of Windows. For computers running at least Windows 8, Enhanced Protected Mode also limits the locations Internet Explorer can read from in the registry and the file system.\n\nIf you enable this policy setting, Enhanced Protected Mode will be turned on. Any zone that has Protected Mode enabled will use Enhanced Protected Mode. Users will not be able to disable Enhanced Protected Mode.\n\nIf you disable this policy setting, Enhanced Protected Mode will be turned off. Any zone that has Protected Mode enabled will use the version of Protected Mode introduced in Internet Explorer 7 for Windows Vista.\n\nIf you do not configure this policy, users will be able to turn on or turn off Enhanced Protected Mode on the Advanced tab of the Internet Options dialog.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenhancedprotectedmode"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar","displayName":"Allow Microsoft services to provide enhanced suggestions as the user types in the Address bar (User)","description":"This policy setting allows Internet Explorer to provide enhanced suggestions as the user types in the Address bar. To provide enhanced suggestions, the user's keystrokes are sent to Microsoft through Microsoft services.\n\nIf you enable this policy setting, users receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.\n\nIf you disable this policy setting, users won't receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.\n\nIf you don't configure this policy setting, users can change the Suggestions setting on the Settings charm.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenhancedsuggestionsinaddressbar"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu","displayName":"Let users turn on and use Enterprise Mode from the Tools menu (User)","description":"This policy setting lets you decide whether users can turn on Enterprise Mode for websites with compatibility issues. Optionally, this policy also lets you specify where to get reports (through post messages) about the websites for which users turn on Enterprise Mode using the Tools menu.\n\nIf you turn this setting on, users can see and use the Enterprise Mode option from the Tools menu. If you turn this setting on, but don't specify a report location, Enterprise Mode will still be available to your users, but you won't get any reports.\n\nIf you disable or don't configure this policy setting, the menu option won't appear and users won't be able to run websites in Enterprise Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenterprisemodefromtoolsmenu"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu_enterreportbackprompt","displayName":"Type the location (URL) of where to receive reports about the websites for which users turn on and use Enterprise Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodesitelist","displayName":"Use the Enterprise Mode IE website list (User)","description":"This policy setting lets you specify where to find the list of websites you want opened using Enterprise Mode IE, instead of Standard mode, because of compatibility issues. Users can't edit this list.\n\nIf you enable this policy setting, Internet Explorer downloads the website list from your location (HKCU or HKLM\\Software\\policies\\Microsoft\\Internet Explorer\\Main\\EnterpriseMode), opening all listed websites using Enterprise Mode IE.\n\nIf you disable or don't configure this policy setting, Internet Explorer opens all websites using Standards mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenterprisemodesitelist"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodesitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodesitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodesitelist_entersitelistprompt","displayName":"Type the location (URL) of your Enterprise Mode IE website list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorer7policylist","displayName":"Use Policy List of Internet Explorer 7 sites (User)","description":"This policy setting allows you to add specific sites that must be viewed in Internet Explorer 7 Compatibility View.\n\nIf you enable this policy setting, the user can add and remove sites from the list, but the user cannot remove the entries that you specify.\n\nIf you disable or do not configure this policy setting, the user can add and remove sites from the list.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowinternetexplorer7policylist"],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorer7policylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorer7policylist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorer7policylist_compatview_sitelist","displayName":"List of sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorerstandardsmode","displayName":"Turn on Internet Explorer Standards Mode for local intranet (User)","description":"This policy setting controls how Internet Explorer displays local intranet content. Intranet content is defined as any webpage that belongs to the local intranet security zone.\n\nIf you enable this policy setting, Internet Explorer uses the current user agent string for local intranet content. Additionally, all local intranet Standards Mode pages appear in the Standards Mode available with the latest version of Internet Explorer. The user cannot change this behavior through the Compatibility View Settings dialog box.\n\nIf you disable this policy setting, Internet Explorer uses an Internet Explorer 7 user agent string (with an additional string appended) for local intranet content. Additionally, all local intranet Standards Mode pages appear in Internet Explorer 7 Standards Mode. The user cannot change this behavior through the Compatibility View Settings dialog box.\n\nIf you do not configure this policy setting, Internet Explorer uses an Internet Explorer 7 user agent string (with an additional string appended) for local intranet content. Additionally, all local intranet Standards Mode pages appear in Internet Explorer 7 Standards Mode. This option results in the greatest compatibility with existing webpages, but newer content written to common Internet standards may be displayed incorrectly. This option matches the default behavior of Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowinternetexplorerstandardsmode"],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorerstandardsmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorerstandardsmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate","displayName":"Internet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowinternetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_iz_partnameinternetzonetemplate","displayName":"Internet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_iz_partnameinternetzonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_iz_partnameinternetzonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_iz_partnameinternetzonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_iz_partnameinternetzonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_iz_partnameinternetzonetemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate","displayName":"Intranet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowintranetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate","displayName":"Intranet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate","displayName":"Local Machine Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlocalmachinezonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate","displayName":"Local Machine Zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate","displayName":"Locked-Down Internet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddowninternetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_iz_partnameinternetzonelockdowntemplate","displayName":"Locked-Down Internet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_iz_partnameinternetzonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_iz_partnameinternetzonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_iz_partnameinternetzonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_iz_partnameinternetzonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_iz_partnameinternetzonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate","displayName":"Locked-Down Intranet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownintranetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_iz_partnameintranetzonelockdowntemplate","displayName":"Locked-Down Intranet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_iz_partnameintranetzonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_iz_partnameintranetzonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_iz_partnameintranetzonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_iz_partnameintranetzonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_iz_partnameintranetzonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate","displayName":"Locked-Down Local Machine Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownlocalmachinezonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_iz_partnamelocalmachinezonelockdowntemplate","displayName":"Locked-Down Local Machine Zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_iz_partnamelocalmachinezonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_iz_partnamelocalmachinezonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_iz_partnamelocalmachinezonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_iz_partnamelocalmachinezonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_iz_partnamelocalmachinezonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate","displayName":"Locked-Down Restricted Sites Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownrestrictedsiteszonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate","displayName":"Locked-Down Restricted Sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowonewordentry","displayName":"Go to an intranet site for a one-word entry in the Address bar (User)","description":"This policy allows the user to go directly to an intranet site for a one-word entry in the Address bar.\n\nIf you enable this policy setting, Internet Explorer goes directly to an intranet site for a one-word entry in the Address bar, if it is available.\n\nIf you disable or do not configure this policy setting, Internet Explorer does not go directly to an intranet site for a one-word entry in the Address bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowonewordentry"],"categoryId":"a1fbe395-3b60-475f-8a34-3710d6b2e09f","categoryName":"Browsing","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowonewordentry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowonewordentry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsavetargetasiniemode","displayName":"Allow \"Save Target As\" in Internet Explorer mode (User)","description":"This policy setting allows admins to enable \"Save Target As\" context menu in Internet Explorer mode.\n\nIf you enable this policy, \"Save Target As\" will show up in the Internet Explorer mode context menu and work the same as Internet Explorer.\n\nIf you disable or do not configure this policy setting, \"Save Target As\" will not show up in the Internet Explorer mode context menu.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2102115","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsavetargetasiniemode"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsavetargetasiniemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsavetargetasiniemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist","displayName":"Site to Zone Assignment List (User)","description":"This policy setting allows you to manage a list of sites that you want to associate with a particular security zone. These zone numbers have associated security settings that apply to all of the sites in the zone.\n\nInternet Explorer has 4 security zones, numbered 1-4, and these are used by this policy setting to associate sites to zones. They are: (1) Intranet zone, (2) Trusted Sites zone, (3) Internet zone, and (4) Restricted Sites zone. Security settings can be set for each of these zones through other policy settings, and their default settings are: Trusted Sites zone (Low template), Intranet zone (Medium-Low template), Internet zone (Medium template), and Restricted Sites zone (High template). (The Local Machine zone and its locked down equivalent have special security settings that protect your local computer.)\n\nIf you enable this policy setting, you can enter a list of sites and their related zone numbers. The association of a site with a zone will ensure that the security settings for the specified zone are applied to the site.  For each entry that you add to the list, enter the following information:\n\nValuename – A host for an intranet site, or a fully qualified domain name for other sites. The valuename may also include a specific protocol. For example, if you enter http://www.contoso.com as the valuename, other protocols are not affected. If you enter just www.contoso.com, then all protocols are affected for that site, including http, https, ftp, and so on. The site may also be expressed as an IP address (e.g., 127.0.0.1) or range (e.g., 127.0.0.1-10). To avoid creating conflicting policies, do not include additional characters after the domain such as trailing slashes or URL path. For example, policy settings for www.contoso.com and www.contoso.com/mail would be treated as the same policy setting by Internet Explorer, and would therefore be in conflict.\n\nValue - A number indicating the zone with which this site should be associated for security settings. The Internet Explorer zones described above are 1-4.\n\nIf you disable or do not configure this policy, users may choose their own site-to-zone assignments.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsitetozoneassignmentlist"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_iz_zonemapprompt","displayName":"Enter the zone assignments here. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_iz_zonemapprompt_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_iz_zonemapprompt_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate","displayName":"Locked-Down Trusted Sites Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowslockeddowntrustedsiteszonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate","displayName":"Locked-Down Trusted Sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid","displayName":"Allow software to run or install even if the signature is invalid (User)","description":"This policy setting allows you to manage whether software, such as ActiveX controls and file downloads, can be installed or run by the user even though the signature is invalid. An invalid signature might indicate that someone has tampered with the file.\n\nIf you enable this policy setting, users will be prompted to install or run files with an invalid signature.\n\nIf you disable this policy setting, users cannot run or install files with an invalid signature.\n\nIf you do not configure this policy, users can choose to run or install files with an invalid signature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsoftwarewhensignatureisinvalid"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate","displayName":"Restricted Sites Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsrestrictedsiteszonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonetemplate","displayName":"Restricted Sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonetemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsuggestedsites","displayName":"Turn on Suggested Sites (User)","description":"This policy setting controls the Suggested Sites feature, which recommends websites based on the user’s browsing activity. Suggested Sites reports a user’s browsing history to Microsoft to suggest sites that the user might want to visit.\n\nIf you enable this policy setting, the user is not prompted to enable Suggested Sites. The user’s browsing history is sent to Microsoft to produce suggestions.\n\nIf you disable this policy setting, the entry points and functionality associated with this feature are turned off.\n\nIf you do not configure this policy setting, the user can turn on and turn off the Suggested Sites feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsuggestedsites"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsuggestedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsuggestedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate","displayName":"Trusted Sites Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowtrustedsiteszonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate","displayName":"Trusted Sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_autodetectintranet","displayName":"Turn on automatic detection of intranet (User)","description":"This policy setting enables intranet mapping rules to be applied automatically if the computer belongs to a domain.\n\nIf you enable this policy setting, automatic detection of the intranet is turned on, and intranet mapping rules are applied automatically if the computer belongs to a domain.\n\nIf you disable this policy setting, automatic detection of the intranet is turned off, and intranet mapping rules are applied however they are configured.\n\nIf this policy setting is not configured, the user can choose whether or not to automatically detect the intranet through the intranet settings dialog in Control Panel.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-autodetectintranet"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_autodetectintranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_autodetectintranet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation","displayName":"Check for server certificate revocation (User)","description":"This policy setting allows you to manage whether Internet Explorer will check revocation status of servers' certificates. Certificates are revoked when they have been compromised or are no longer valid, and this option protects users from submitting confidential data to a site that may be fraudulent or not secure.\n\nIf you enable this policy setting, Internet Explorer will check to see if server certificates have been revoked.\n\nIf you disable this policy setting, Internet Explorer will not check server certificates to see if they have been revoked.\n\nIf you do not configure this policy setting, Internet Explorer will not check server certificates to see if they have been revoked.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-checkservercertificaterevocation"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms","displayName":"Check for signatures on downloaded programs (User)","description":"This policy setting allows you to manage whether Internet Explorer checks for digital signatures (which identifies the publisher of signed software and verifies it hasn't been modified or tampered with) on user computers before downloading executable programs.\n\nIf you enable this policy setting, Internet Explorer will check the digital signatures of executable programs and display their identities before downloading them to user computers.\n\nIf you disable this policy setting, Internet Explorer will not check the digital signatures of executable programs or display their identities before downloading them to user computers.\n\nIf you do not configure this policy, Internet Explorer will not check the digital signatures of executable programs or display their identities before downloading them to user computers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-checksignaturesondownloadedprograms"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel","displayName":"Configure which channel of Microsoft Edge to use for opening redirected sites (User)","description":"Enables you to configure up to three versions of Microsoft Edge to open a redirected site (in order of preference). Use this policy if your environment is configured to redirect sites from Internet Explorer 11 to Microsoft Edge. If any of the chosen versions are not installed on the device, that preference will be bypassed.\n\nIf both the Windows Update for the next version of Microsoft Edge* and Microsoft Edge Stable channel are installed, the following behaviors occur:\n- If you disable or don't configure this policy, Microsoft Edge Stable channel is used. This is the default behavior.\n- If you enable this policy, you can configure redirected sites to open in up to three of the following channels where:\n 1 = Microsoft Edge Stable\n 2 = Microsoft Edge Beta version 77 or later\n 3 = Microsoft Edge Dev version 77 or later\n 4 = Microsoft Edge Canary version 77 or later\n\nIf the Windows Update for the next version of Microsoft Edge* or Microsoft Edge Stable channel are not installed, the following behaviors occur:\n- If you disable or don't configure this policy, Microsoft Edge version 45 or earlier is automatically used. This is the default behavior.\n- If you enable this policy, you can configure redirected sites to open in up to three of the following channels where:\n 0 = Microsoft Edge version 45 or earlier\n 1 = Microsoft Edge Stable\n 2 = Microsoft Edge Beta version 77 or later\n 3 = Microsoft Edge Dev version 77 or later\n 4 = Microsoft Edge Canary version 77 or later\n\n*For more information about the Windows update for the next version of Microsoft Edge including how to disable it, see https://go.microsoft.com/fwlink/?linkid=2102115. This update applies only to Windows 10 version 1709 and higher.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-configureedgeredirectchannel"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser","displayName":"First choice (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_","displayName":"","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_1","displayName":"Microsoft Edge Stable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_2","displayName":"Microsoft Edge Beta version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_3","displayName":"Microsoft Edge Dev version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_4","displayName":"Microsoft Edge Canary version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_0","displayName":"Microsoft Edge version 45 or earlier","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2","displayName":"Second choice (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_","displayName":"","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_1","displayName":"Microsoft Edge Stable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_2","displayName":"Microsoft Edge Beta version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_3","displayName":"Microsoft Edge Dev version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_4","displayName":"Microsoft Edge Canary version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_0","displayName":"Microsoft Edge version 45 or earlier","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3","displayName":"Third choice (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3_","displayName":"","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3_1","displayName":"Microsoft Edge Stable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3_2","displayName":"Microsoft Edge Beta version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3_3","displayName":"Microsoft Edge Dev version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3_4","displayName":"Microsoft Edge Canary version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3_0","displayName":"Microsoft Edge version 45 or earlier","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"Internet Explorer uses Multipurpose Internet Mail Extensions (MIME) data to determine file handling procedures for files received through a Web server.\n\nThis policy setting determines whether Internet Explorer requires that all file-type information provided by Web servers be consistent. For example, if the MIME type of a file is text/plain but the MIME sniff indicates that the file is really an executable file, Internet Explorer renames the file by saving it in the Internet Explorer cache and changing its extension.\n\nIf you enable this policy setting, Internet Explorer requires consistent MIME data for all received files.\n\nIf you disable this policy setting, Internet Explorer will not require consistent MIME data for all received files.\n\nIf you do not configure this policy setting, Internet Explorer requires consistent MIME data for all received files.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-consistentmimehandlinginternetexplorerprocesses"],"categoryId":"ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","categoryName":"Consistent Mime Handling","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableactivexversionlistautodownload","displayName":"Turn off automatic download of the ActiveX VersionList (User)","description":"This setting determines whether IE automatically downloads updated versions of Microsoft’s VersionList.XML. IE uses this file to determine whether an ActiveX control should be stopped from loading.\n\nIf you enable this setting, IE stops downloading updated versions of VersionList.XML. Turning off this automatic download breaks the out-of-date ActiveX control blocking feature by not letting the version list update with newly outdated controls, potentially compromising the security of your computer.\n\nIf you disable or don't configure this setting, IE continues to download updated versions of VersionList.XML.\n\nFor more information, see \"Out-of-date ActiveX control blocking\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableactivexversionlistautodownload"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableactivexversionlistautodownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableactivexversionlistautodownload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableadobeflash","displayName":"Turn off Adobe Flash in Internet Explorer and prevent applications from using Internet Explorer technology to instantiate Flash objects (User)","description":"This policy setting turns off Adobe Flash in Internet Explorer and prevents applications from using Internet Explorer technology to instantiate Flash objects.\r\n\r\nIf you enable this policy setting, Flash is turned off for Internet Explorer, and applications cannot use Internet Explorer technology to instantiate Flash objects. In the Manage Add-ons dialog box, the Flash status will be 'Disabled', and users cannot enable Flash. If you enable this policy setting, Internet Explorer will ignore settings made for Adobe Flash through the \"Add-on List\" and \"Deny all add-ons unless specifically allowed in the Add-on List\" policy settings.\r\n\r\nIf you disable, or do not configure this policy setting, Flash is turned on for Internet Explorer, and applications can use Internet Explorer technology to instantiate Flash objects. Users can enable or disable Flash in the Manage Add-ons dialog box.\r\n\r\nNote that Adobe Flash can still be disabled through the \"Add-on List\" and \"Deny all add-ons unless specifically allowed in the Add-on List\" policy settings, even if this policy setting is disabled, or not configured. However, if Adobe Flash is disabled through the \"Add-on List\" and \"Deny all add-ons unless specifically allowed in the Add-on List\" policy settings and not through this policy setting, all applications that use Internet Explorer technology to instantiate Flash object can still do so. For more information, see \"Group Policy Settings in Internet Explorer 10\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-InternetExplorer#internetexplorer-disableadobeflash"],"categoryId":"89c0381d-3b9b-4be5-8077-ffb18d47e910","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableadobeflash_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableadobeflash_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarnings","displayName":"Prevent bypassing SmartScreen Filter warnings (User)","description":"This policy setting determines whether the user can bypass warnings from SmartScreen Filter. SmartScreen Filter prevents the user from browsing to or downloading from sites that are known to host malicious content. SmartScreen Filter also prevents the execution of files that are known to be malicious.\n\nIf you enable this policy setting, SmartScreen Filter warnings block the user.\n\nIf you disable or do not configure this policy setting, the user can bypass SmartScreen Filter warnings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablebypassofsmartscreenwarnings"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarningsaboutuncommonfiles","displayName":"Prevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the Internet (User)","description":"This policy setting determines whether the user can bypass warnings from SmartScreen Filter. SmartScreen Filter warns the user about executable files that Internet Explorer users do not commonly download from the Internet.\n\nIf you enable this policy setting, SmartScreen Filter warnings block the user.\n\nIf you disable or do not configure this policy setting, the user can bypass SmartScreen Filter warnings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablebypassofsmartscreenwarningsaboutuncommonfiles"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarningsaboutuncommonfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarningsaboutuncommonfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecompatview","displayName":"Turn off Compatibility View (User)","description":"This policy setting controls the Compatibility View feature, which allows the user to fix website display problems that he or she may encounter while browsing.\n\nIf you enable this policy setting, the user cannot use the Compatibility View button or manage the Compatibility View sites list.\n\nIf you disable or do not configure this policy setting, the user can use the Compatibility View button and manage the Compatibility View sites list.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecompatview"],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablecompatview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecompatview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableconfiguringhistory","displayName":"Disable \"Configuring History\" (User)","description":"This setting specifies the number of days that Internet Explorer tracks views of pages in the History List. To access the Temporary Internet Files and History Settings dialog box, from the Menu bar, on the Tools menu, click Internet Options, click the General tab, and then click Settings under Browsing history.\n\nIf you enable this policy setting, a user cannot set the number of days that Internet Explorer tracks views of the pages in the History List. You must specify the number of days that Internet Explorer tracks views of pages in the History List. Users can not delete browsing history.\n\nIf you disable or do not configure this policy setting, a user can set the number of days that Internet Explorer tracks views of pages in the History list. Users can delete browsing history.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableconfiguringhistory"],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableconfiguringhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableconfiguringhistory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableconfiguringhistory_daystokeep_prompt","displayName":"Days to keep pages in History (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecrashdetection","displayName":"Turn off Crash Detection (User)","description":"This policy setting allows you to manage the crash detection feature of add-on Management.\n\nIf you enable this policy setting, a crash in Internet Explorer will exhibit behavior found in Windows XP Professional Service Pack 1 and earlier, namely to invoke Windows Error Reporting. All policy settings for Windows Error Reporting continue to apply.\n\nIf you disable or do not configure this policy setting, the crash detection feature for add-on management will be functional.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecrashdetection"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablecrashdetection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecrashdetection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation","displayName":"Prevent participation in the Customer Experience Improvement Program (User)","description":"This policy setting prevents the user from participating in the Customer Experience Improvement Program (CEIP).\n\nIf you enable this policy setting, the user cannot participate in the CEIP, and the Customer Feedback Options command does not appear on the Help menu.\n\nIf you disable this policy setting, the user must participate in the CEIP, and the Customer Feedback Options command does not appear on the Help menu.\n\nIf you do not configure this policy setting, the user can choose to participate in the CEIP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecustomerexperienceimprovementprogramparticipation"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disabledeletinguservisitedwebsites","displayName":"Prevent deleting websites that the user has visited (User)","description":"This policy setting prevents the user from deleting the history of websites that he or she has visited. This feature is available in the Delete Browsing History dialog box.\n\nIf you enable this policy setting, websites that the user has visited are preserved when he or she clicks Delete.\n\nIf you disable this policy setting, websites that the user has visited are deleted when he or she clicks Delete.\n\nIf you do not configure this policy setting, the user can choose whether to delete or preserve visited websites when he or she clicks Delete.\n\nIf the \"Prevent access to Delete Browsing History\" policy setting is enabled, this policy setting is enabled by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disabledeletinguservisitedwebsites"],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disabledeletinguservisitedwebsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disabledeletinguservisitedwebsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableenclosuredownloading","displayName":"Prevent downloading of enclosures (User)","description":"This policy setting prevents the user from having enclosures (file attachments) downloaded from a feed to the user's computer.\n\nIf you enable this policy setting, the user cannot set the Feed Sync Engine to download an enclosure through the Feed property page. A developer cannot change the download setting through the Feed APIs.\n\nIf you disable or do not configure this policy setting, the user can set the Feed Sync Engine to download an enclosure through the Feed property page. A developer can change the download setting through the Feed APIs.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableenclosuredownloading"],"categoryId":"9aaa7ee2-727d-426f-8a2b-6b10a4cd084f","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableenclosuredownloading_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableenclosuredownloading_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport","displayName":"Turn off encryption support (User)","description":"This policy setting allows you to turn off support for Transport Layer Security (TLS) 1.0, TLS 1.1, TLS 1.2, Secure Sockets Layer (SSL) 2.0, or SSL 3.0 in the browser. TLS and SSL are protocols that help protect communication between the browser and the target server. When the browser attempts to set up a protected communication with the target server, the browser and server negotiate which protocol and version to use. The browser and server attempt to match each other’s list of supported protocols and versions, and they select the most preferred match.\n\nIf you enable this policy setting, the browser negotiates or does not negotiate an encryption tunnel by using the encryption methods that you select from the drop-down list.\n\nIf you disable or do not configure this policy setting, the user can select which encryption method the browser supports.\n\nNote: SSL 2.0 is off by default and is no longer supported starting with Windows 10 Version 1607. SSL 2.0 is an outdated security protocol, and enabling SSL 2.0 impairs the performance and functionality of TLS 1.0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableencryptionsupport"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions","displayName":"Secure Protocol combinations (User)","description":"","helpText":"","infoUrls":[],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_0","displayName":"Use no secure protocols","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_8","displayName":"[Obsolete] Only use SSL 2.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_32","displayName":"Only use SSL 3.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_40","displayName":"[Obsolete] Use SSL 2.0 and SSL 3.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_128","displayName":"Only use TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_136","displayName":"[Obsolete] Use SSL 2.0 and TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_160","displayName":"Use SSL 3.0 and TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_168","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, and TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_512","displayName":"Only use TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_520","displayName":"[Obsolete] Use SSL 2.0 and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_544","displayName":"Use SSL 3.0 and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_552","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_640","displayName":"Use TLS 1.0 and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_648","displayName":"[Obsolete] Use SSL 2.0, TLS 1.0, and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_672","displayName":"Use SSL 3.0, TLS 1.0, and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_680","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, TLS 1.0, and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2048","displayName":"Only use TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2056","displayName":"[Obsolete] Use SSL 2.0 and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2080","displayName":"Use SSL 3.0 and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2088","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2176","displayName":"Use TLS 1.0 and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2184","displayName":"[Obsolete] Use SSL 2.0, TLS 1.0, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2208","displayName":"Use SSL 3.0, TLS 1.0, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2216","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, TLS 1.0, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2560","displayName":"Use TLS 1.1 and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2568","displayName":"[Obsolete] Use SSL 2.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2592","displayName":"Use SSL 3.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2600","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2688","displayName":"Use TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2696","displayName":"[Obsolete] Use SSL 2.0, TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2720","displayName":"Use SSL 3.0, TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2728","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_8192","displayName":"Only use TLS 1.3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10240","displayName":"Use TLS 1.2 and TLS 1.3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10752","displayName":"Use TLS 1.1, TLS 1.2, and TLS 1.3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10880","displayName":"Use TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10912","displayName":"Use SSL 3.0, TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefeedsbackgroundsync","displayName":"Turn off background synchronization for feeds and Web Slices (User)","description":"This policy setting controls whether to have background synchronization for feeds and Web Slices.\n\nIf you enable this policy setting, the ability to synchronize feeds and Web Slices in the background is turned off.\n\nIf you disable or do not configure this policy setting, the user can synchronize feeds and Web Slices in the background.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablefeedsbackgroundsync"],"categoryId":"9aaa7ee2-727d-426f-8a2b-6b10a4cd084f","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablefeedsbackgroundsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefeedsbackgroundsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard","displayName":"Prevent running First Run wizard (User)","description":"This policy setting prevents Internet Explorer from running the First Run wizard the first time a user starts the browser after installing Internet Explorer or Windows.\n\nIf you enable this policy setting, you must make one of the following choices:\n • Skip the First Run wizard, and go directly to the user's home page.\n • Skip the First Run wizard, and go directly to the \"Welcome to Internet Explorer\" webpage.\n\nStarting with Windows 8, the \"Welcome to Internet Explorer\" webpage is not available. The user's home page will display regardless of which option is chosen.\n\nIf you disable or do not configure this policy setting, Internet Explorer may run the First Run wizard the first time the browser is started after installation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablefirstrunwizard"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_firstrunoptions","displayName":"Select your choice (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_firstrunoptions_1","displayName":"Go directly to home page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_firstrunoptions_2","displayName":"Go directly to \"Welcome To IE\" page","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature","displayName":"Turn off the flip ahead with page prediction feature (User)","description":"This policy setting determines whether a user can swipe across a screen or click Forward to go to the next pre-loaded page of a website.\n\nMicrosoft collects your browsing history to improve how flip ahead with page prediction works. This feature isn't available for Internet Explorer for the desktop.\n\nIf you enable this policy setting, flip ahead with page prediction is turned off and the next webpage isn't loaded into the background.\n\nIf you disable this policy setting, flip ahead with page prediction is turned on and the next webpage is loaded into the background.\n\nIf you don't configure this setting, users can turn this behavior on or off, using the Settings charm.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableflipaheadfeature"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablegeolocation","displayName":"Turn off browser geolocation (User)","description":"This policy setting allows you to disable browser geolocation support. This will prevent websites from requesting location data about the user.\n\nIf you enable this policy setting, browser geolocation support is turned off.\n\nIf you disable this policy setting, browser geolocation support is turned on.\n\nIf you do not configure this policy setting, browser geolocation support can be turned on or off in Internet Options on the Privacy tab.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablegeolocation"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablegeolocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablegeolocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablehomepagechange","displayName":"Disable changing home page settings (User)","description":"The Home page specified on the General tab of the Internet Options dialog box is the default Web page that Internet Explorer loads whenever it is run.\n\nIf you enable this policy setting, a user cannot set a custom default home page. You must specify which default home page should load on the user machine. For machines with at least Internet Explorer 7, the home page can be set within this policy to override other home page policies.\n\nIf you disable or do not configure this policy setting, the Home page box is enabled and users can choose their own home page.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablehomepagechange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablehomepagechange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablehomepagechange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablehomepagechange_enterhomepageprompt","displayName":"Home Page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablehtmlapplication","displayName":"Disable HTML Application (User)","description":"This policy setting specifies if running the HTML Application (HTA file) is blocked or allowed.\n\nIf you enable this policy setting, running the HTML Application (HTA file) will be blocked.\n\nIf you disable or do not configure this policy setting, running the HTML Application (HTA file) is allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablehtmlapplication"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablehtmlapplication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablehtmlapplication_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableignoringcertificateerrors","displayName":"Prevent ignoring certificate errors (User)","description":"This policy setting prevents the user from ignoring Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificate errors that interrupt browsing (such as \"expired\", \"revoked\", or \"name mismatch\" errors) in Internet Explorer.\n\nIf you enable this policy setting, the user cannot continue browsing.\n\nIf you disable or do not configure this policy setting, the user can choose to ignore certificate errors and continue browsing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableignoringcertificateerrors"],"categoryId":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","categoryName":"Internet Control Panel","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableignoringcertificateerrors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableignoringcertificateerrors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinprivatebrowsing","displayName":"Turn off InPrivate Browsing (User)","description":"This policy setting allows you to turn off the InPrivate Browsing feature.\n\nInPrivate Browsing prevents Internet Explorer from storing data about a user's browsing session. This includes cookies, temporary Internet files, history, and other data.\n\nIf you enable this policy setting, InPrivate Browsing is turned off.\n\nIf you disable this policy setting, InPrivate Browsing is available for use.\n\nIf you do not configure this policy setting, InPrivate Browsing can be turned on or off through the registry.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinprivatebrowsing"],"categoryId":"f26fe4c2-d073-4e51-90bf-61c4bbdeb4f2","categoryName":"Privacy","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableinprivatebrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinprivatebrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp","displayName":"[Deprecated] Disable Internet Explorer 11 as a standalone browser (User)","description":"This policy lets you restrict launching of Internet Explorer as a standalone browser.\r\n\r\nIf you enable this policy, it:\r\n- Prevents Internet Explorer 11 from launching as a standalone browser.\r\n- Restricts Internet Explorer's usage to Microsoft Edge's native 'Internet Explorer mode'.\r\n- Redirects all attempts at launching Internet Explorer 11 to Microsoft Edge Stable Channel browser.\r\n- Overrides any other policies that redirect to Internet Explorer 11.\r\n\r\nIf you disable, or don’t configure this policy, all sites are opened using the current active browser settings. Note: Microsoft Edge Stable Channel must be installed for this policy to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinternetexplorerapp"],"categoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2","displayName":"Disable Internet Explorer 11 as a standalone browser (User)","description":"This policy lets you restrict launching of Internet Explorer as a standalone browser.\n\nIf you enable this policy, it:\n- Prevents Internet Explorer 11 from launching as a standalone browser.\n- Restricts Internet Explorer's usage to Microsoft Edge's native 'Internet Explorer mode'.\n- Redirects attempts at launching Internet Explorer 11 to Microsoft Edge Stable Channel browser.\n- Overrides any other policies that redirect to Internet Explorer 11.\n\nEven with this policy enabled launching Internet Explorer 11 using COM automation will still be allowed. To disable COM automation launches of Internet Explorer 11 use the \"Disable Internet Explorer 11 COM Automation\" group policy.\n\nIf you disable, or don’t configure this policy, all sites are opened using the current active browser settings. Note: Microsoft Edge Stable Channel must be installed for this policy to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinternetexplorerapp"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_notifydisableieoptions","displayName":"Notify that Internet Explorer 11 browser is disabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_notifydisableieoptions_0","displayName":"Never","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_notifydisableieoptions_1","displayName":"Always","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_notifydisableieoptions_2","displayName":"Once per user","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerlaunchviacom","displayName":"Disable Internet Explorer 11 Launch Via COM Automation (User)","description":"This policy lets you restrict launching of Internet Explorer using COM automation.\n\nIf you enable this policy, it prevents Internet Explorer 11 from being launched using COM automation.\n\nIf you disable, or don’t configure this policy, Internet Explorer 11 COM automation launches are allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinternetexplorerlaunchviacom"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerlaunchviacom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerlaunchviacom_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableprocessesinenhancedprotectedmode","displayName":"Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows (User)","description":"This policy setting determines whether Internet Explorer 11 uses 64-bit processes (for greater security) or 32-bit processes (for greater compatibility) when running in Enhanced Protected Mode on 64-bit versions of Windows.\n\nImportant: Some ActiveX controls and toolbars may not be available when 64-bit processes are used.\n\nIf you enable this policy setting, Internet Explorer 11 will use 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows.\n\nIf you disable this policy setting, Internet Explorer 11 will use 32-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows.\n\nIf you don't configure this policy setting, users can turn this feature on or off using Internet Explorer settings. This feature is turned off by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableprocessesinenhancedprotectedmode"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableprocessesinenhancedprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableprocessesinenhancedprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableproxychange","displayName":"Prevent changing proxy settings (User)","description":"This policy setting specifies if a user can change proxy settings.\n\nIf you enable this policy setting, the user will not be able to configure proxy settings.\n\nIf you disable or do not configure this policy setting, the user can configure proxy settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableproxychange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableproxychange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableproxychange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesearchproviderchange","displayName":"Prevent changing the default search provider (User)","description":"This policy setting prevents the user from changing the default search provider for the Address bar and the toolbar Search box.\n\nIf you enable this policy setting, the user cannot change the default search provider.\n\nIf you disable or do not configure this policy setting, the user can change the default search provider.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablesearchproviderchange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablesearchproviderchange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesearchproviderchange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange","displayName":"Disable changing secondary home page settings (User)","description":"Secondary home pages are the default Web pages that Internet Explorer loads in separate tabs from the home page whenever the browser is run. This policy setting allows you to set default secondary home pages.\n\nIf you enable this policy setting, you can specify which default home pages should load as secondary home pages. The user cannot set custom default secondary home pages.\n\nIf you disable or do not configure this policy setting, the user can add secondary home pages.\n\nNote: If the “Disable Changing Home Page Settings” policy is enabled, the user cannot add secondary home pages.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablesecondaryhomepagechange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_secondaryhomepageslist","displayName":"Secondary home pages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecuritysettingscheck","displayName":"Turn off the Security Settings Check feature (User)","description":"This policy setting turns off the Security Settings Check feature, which checks Internet Explorer security settings to determine when the settings put Internet Explorer at risk.\n\nIf you enable this policy setting, the feature is turned off.\n\nIf you disable or do not configure this policy setting, the feature is turned on.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablesecuritysettingscheck"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecuritysettingscheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecuritysettingscheck_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablewebaddressautocomplete","displayName":"Turn off the auto-complete feature for web addresses (User)","description":"This AutoComplete feature suggests possible matches when users are entering Web addresses in the browser address bar.\n\nIf you enable this policy setting, user will not be suggested matches when entering Web addresses. The user cannot change the auto-complete for web-address setting.\n\nIf you disable this policy setting, user will be suggested matches when entering Web addresses. The user cannot change the auto-complete for web-address setting.\n\nIf you do not configure this policy setting, a user will have the freedom to choose to turn the auto-complete setting for web-addresses on or off.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablewebaddressautocomplete"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablewebaddressautocomplete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablewebaddressautocomplete_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_donotallowactivexcontrolsinprotectedmode","displayName":"Do not allow ActiveX controls to run in Protected Mode when Enhanced Protected Mode is enabled (User)","description":"This policy setting prevents ActiveX controls from running in Protected Mode when Enhanced Protected Mode is enabled. When a user has an ActiveX control installed that is not compatible with Enhanced Protected Mode and a website attempts to load the control, Internet Explorer notifies the user and gives the option to run the website in regular Protected Mode. This policy setting disables this notification and forces all websites to run in Enhanced Protected Mode.\n\nEnhanced Protected Mode provides additional protection against malicious websites by using 64-bit processes on 64-bit versions of Windows. For computers running at least Windows 8, Enhanced Protected Mode also limits the locations Internet Explorer can read from in the registry and the file system.\n\nWhen Enhanced Protected Mode is enabled, and a user encounters a website that attempts to load an ActiveX control that is not compatible with Enhanced Protected Mode, Internet Explorer notifies the user and gives the option to disable Enhanced Protected Mode for that particular website.\n\nIf you enable this policy setting, Internet Explorer will not give the user the option to disable Enhanced Protected Mode. All Protected Mode websites will run in Enhanced Protected Mode.\n\nIf you disable or do not configure this policy setting, Internet Explorer notifies users and provides an option to run websites with incompatible ActiveX controls in regular Protected Mode. This is the default behavior.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-donotallowactivexcontrolsinprotectedmode"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_donotallowactivexcontrolsinprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_donotallowactivexcontrolsinprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrols","displayName":"Turn off blocking of outdated ActiveX controls for Internet Explorer (User)","description":"This policy setting determines whether Internet Explorer blocks specific outdated ActiveX controls. Outdated ActiveX controls are never blocked in the Intranet Zone.\n\nIf you enable this policy setting, Internet Explorer stops blocking outdated ActiveX controls.\n\nIf you disable or don't configure this policy setting, Internet Explorer continues to block specific outdated ActiveX controls.\n\nFor more information, see \"Outdated ActiveX Controls\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-donotblockoutdatedactivexcontrols"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrolsonspecificdomains","displayName":"Turn off blocking of outdated ActiveX controls for Internet Explorer on specific domains (User)","description":"This policy setting allows you to manage a list of domains on which Internet Explorer will stop blocking outdated ActiveX controls. Outdated ActiveX controls are never blocked in the Intranet Zone.\n\nIf you enable this policy setting, you can enter a custom list of domains for which outdated ActiveX controls won't be blocked in Internet Explorer. Each domain entry must be formatted like one of the following:\n\n1. \"domain.name.TLD\". For example, if you want to include *.contoso.com/*, use \"contoso.com\"\n2. \"hostname\". For example, if you want to include http://example, use \"example\"\n3. \"file:///path/filename.htm\". For example, use \"file:///C:/Users/contoso/Desktop/index.htm\"\n\nIf you disable or don't configure this policy setting, the list is deleted and Internet Explorer continues to block specific outdated ActiveX controls on all domains in the Internet Zone.\n\nFor more information, see \"Outdated ActiveX Controls\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-donotblockoutdatedactivexcontrolsonspecificdomains"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrolsonspecificdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrolsonspecificdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrolsonspecificdomains_domainlist","displayName":"Domain allow list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_enableextendediemodehotkeys","displayName":"Enable extended hot keys in Internet Explorer mode (User)","description":"This policy setting lets admins enable extended Microsoft Edge Internet Explorer mode hotkeys, such as \"Ctrl+S\" to have \"Save as\" functionality.\n\nIf you enable this policy, extended hotkey functionality is enabled in Internet Explorer mode and work the same as Internet Explorer.\n\nIf you disable, or don't configure this policy, extended hotkeys will not work in Internet Explorer mode.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2102115","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-enableextendediemodehotkeys"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_enableextendediemodehotkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_enableextendediemodehotkeys_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_enableglobalwindowlistiniemode","displayName":"Enable global window list in Internet Explorer mode (User)","description":"This setting allows Internet Explorer mode to use the global window list that enables sharing state with other applications.\nThe setting will take effect only when Internet Explorer 11 is disabled as a standalone browser.\n\nIf you enable this policy, Internet Explorer mode will use the global window list.\n\nIf you disable or don’t configure this policy, Internet Explorer mode will continue to maintain a separate window list.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2102921\nTo learn more about disabling Internet Explorer 11 as a standalone browser, see https://go.microsoft.com/fwlink/?linkid=2168340","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-enableglobalwindowlistiniemode"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_enableglobalwindowlistiniemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_enableglobalwindowlistiniemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_includealllocalsites","displayName":"Intranet Sites: Include all local (intranet) sites not listed in other zones (User)","description":"This policy setting controls whether local sites which are not explicitly mapped into any Security Zone are forced into the local Intranet security zone.\n\nIf you enable this policy setting, local sites which are not explicitly mapped into a zone are considered to be in the Intranet Zone.\n\nIf you disable this policy setting, local sites which are not explicitly mapped into a zone will not be considered to be in the Intranet Zone (so would typically be in the Internet Zone).\n\nIf you do not configure this policy setting, users choose whether to force local sites into the Intranet Zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-includealllocalsites"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_includealllocalsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_includealllocalsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths","displayName":"Intranet Sites: Include all network paths (UNCs) (User)","description":"This policy setting controls whether URLs representing UNCs are mapped into the local Intranet security zone.\n\nIf you enable this policy setting, all network paths are mapped into the Intranet Zone.\n\nIf you disable this policy setting, network paths are not necessarily mapped into the Intranet Zone (other rules might map one there).\n\nIf you do not configure this policy setting, users choose whether network paths are mapped into the Intranet Zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-includeallnetworkpaths"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_includeallproxybypasssites","displayName":"Intranet Sites: Include all sites that bypass the proxy server (User)","description":"This policy setting controls whether sites which bypass the proxy server are mapped into the local Intranet security zone.\n\nIf you enable this policy setting, sites which bypass the proxy server are mapped into the Intranet Zone.\n\nIf you disable this policy setting, sites which bypass the proxy server aren't necessarily mapped into the Intranet Zone (other rules might map one there).\n\nIf you do not configure this policy setting, users choose whether sites which bypass the proxy server are mapped into the Intranet Zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-includeallproxybypasssites"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_includeallproxybypasssites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_includeallproxybypasssites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowaccesstodatasources"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowautomaticpromptingforactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript","displayName":"Allow cut, copy or paste operations from the clipboard via script (User)","description":"This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region.\n\nIf you enable this policy setting, a script can perform a clipboard operation.\n\nIf you select Prompt in the drop-down box, users are queried as to whether to perform clipboard operations.\n\nIf you disable this policy setting, a script cannot perform a clipboard operation.\n\nIf you do not configure this policy setting, a script can perform a clipboard operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowcopypasteviascript"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407","displayName":"Allow paste operations via script (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles","displayName":"Allow drag and drop or copy and paste files (User)","description":"This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone.\n\nIf you enable this policy setting, users can drag files or copy and paste files from this zone automatically. If you select Prompt in the drop-down box, users are queried to choose whether to drag or copy files from this zone.\n\nIf you disable this policy setting, users are prevented from dragging files or copying and pasting files from this zone.\n\nIf you do not configure this policy setting, users can drag files or copy and paste files from this zone automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowdraganddropcopyandpastefiles"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles_iz_partname1802","displayName":"Allow drag and drop or copy and paste files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles_iz_partname1802_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles_iz_partname1802_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles_iz_partname1802_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowfontdownloads"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowlessprivilegedsites"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles","displayName":"Allow loading of XAML files (User)","description":"This policy setting allows you to manage the loading of Extensible Application Markup Language (XAML) files. XAML is an XML-based declarative markup language commonly used for creating rich user interfaces and graphics that take advantage of the Windows Presentation Foundation.\n\nIf you enable this policy setting and set the drop-down box to Enable, XAML files are automatically loaded inside Internet Explorer. The user cannot change this behavior. If you set the drop-down box to Prompt, the user is prompted for loading XAML files.\n\nIf you disable this policy setting, XAML files are not loaded inside Internet Explorer. The user cannot change this behavior.\n\nIf you do not configure this policy setting, the user can decide whether to load XAML files inside Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowloadingofxamlfiles"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402","displayName":"XAML Files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallownetframeworkreliantcomponents"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstouseactivexcontrols","displayName":"Allow only approved domains to use ActiveX controls without prompt (User)","description":"This policy setting controls whether or not the user is prompted to allow ActiveX controls to run on websites other than the website that installed the ActiveX control.\n\nIf you enable this policy setting, the user is prompted before ActiveX controls can run from websites in this zone. The user can choose to allow the control to run from the current site or from all sites.\n\nIf you disable this policy setting, the user does not see the per-site ActiveX prompt, and ActiveX controls can run from all sites in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowonlyapproveddomainstouseactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstouseactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstouseactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b","displayName":"Only allow approved domains to use ActiveX controls without prompt (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol","displayName":"Allow only approved domains to use the TDC ActiveX control (User)","description":"This policy setting controls whether or not the user is allowed to run the TDC ActiveX control on websites.\n\nIf you enable this policy setting, the TDC ActiveX control will not run from websites in this zone.\n\nIf you disable this policy setting, the TDC Active X control will run from all sites in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowonlyapproveddomainstousetdcactivexcontrol"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c","displayName":"Only allow approved domains to use the TDC ActiveX control (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols","displayName":"Allow scripting of Internet Explorer WebBrowser controls (User)","description":"This policy setting determines whether a page can control embedded WebBrowser controls via script.\n\nIf you enable this policy setting, script access to the WebBrowser control is allowed.\n\nIf you disable this policy setting, script access to the WebBrowser control is not allowed.\n\nIf you do not configure this policy setting, the user can enable or disable script access to the WebBrowser control. By default, script access to the WebBrowser control is allowed only in the Local Machine and Intranet zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowscriptingofinternetexplorerwebbrowsercontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206","displayName":"Internet Explorer web browser control (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows","displayName":"Allow script-initiated windows without size or position constraints (User)","description":"This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars.\n\nIf you enable this policy setting, Windows Restrictions security will not apply in this zone. The security zone runs without the added layer of security provided by this feature.\n\nIf you disable this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.\n\nIf you do not configure this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowscriptinitiatedwindows"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102","displayName":"Allow script-initiated windows without size or position constraints (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowscriptlets"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowsmartscreenie"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowupdatestostatusbarviascript","displayName":"Allow updates to status bar via script (User)","description":"This policy setting allows you to manage whether script is allowed to update the status bar within the zone.\n\nIf you enable this policy setting, script is allowed to update the status bar.\n\nIf you disable or do not configure this policy setting, script is not allowed to update the status bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowupdatestostatusbarviascript"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowupdatestostatusbarviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowupdatestostatusbarviascript_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowupdatestostatusbarviascript_iz_partname2103","displayName":"Status bar updates via script (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowupdatestostatusbarviascript_iz_partname2103_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowupdatestostatusbarviascript_iz_partname2103_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowuserdatapersistence"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer","displayName":"Allow VBScript to run in Internet Explorer (User)","description":"This policy setting allows you to manage whether VBScript can be run on pages from the specified zone in Internet Explorer.\n\nIf you selected Enable in the drop-down box, VBScript can run without user intervention.\n\nIf you selected Prompt in the drop-down box, users are asked to choose whether to allow VBScript to run.\n\nIf you selected Disable in the drop-down box, VBScript is prevented from running.\n\nIf you do not configure or disable this policy setting, VBScript is prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowvbscripttorunininternetexplorer"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c","displayName":"Allow VBScript to run in Internet Explorer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols","displayName":"Download signed ActiveX controls (User)","description":"This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone.\n\nIf you enable this policy, users can download signed controls without user intervention. If you select Prompt in the drop-down box, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.\n\nIf you disable the policy setting, signed controls cannot be downloaded.\n\nIf you do not configure this policy setting, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedownloadsignedactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_iz_partname1001","displayName":"Download signed ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_iz_partname1001_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_iz_partname1001_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_iz_partname1001_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols","displayName":"Download unsigned ActiveX controls (User)","description":"This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone. Such code is potentially harmful, especially when coming from an untrusted zone.\n\nIf you enable this policy setting, users can run unsigned controls without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to allow the unsigned control to run.\n\nIf you disable this policy setting, users cannot run unsigned controls.\n\nIf you do not configure this policy setting, users cannot run unsigned controls.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedownloadunsignedactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004","displayName":"Download unsigned ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter","displayName":"Turn on Cross-Site Scripting Filter (User)","description":"This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into websites in this zone.\n\nIf you enable this policy setting, the XSS Filter is turned on for sites in this zone, and the XSS Filter attempts to block cross-site script injections.\n\nIf you disable this policy setting, the XSS Filter is turned off for sites in this zone, and Internet Explorer permits cross-site script injections.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenablecrosssitescriptingfilter"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_iz_partname1409","displayName":"Turn on Cross-Site Scripting (XSS) Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_iz_partname1409_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_iz_partname1409_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows","displayName":"Enable dragging of content from different domains across windows (User)","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in different windows.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when both the source and destination are in different windows. Users cannot change this setting.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in different windows. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy or do not configure it, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709","displayName":"Enable dragging of content from different domains across windows (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows","displayName":"Enable dragging of content from different domains within a window (User)","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in the same window.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting in the Internet Options dialog.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in the same window. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy setting or do not configure it, users can drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting in the Internet Options dialog.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708","displayName":"Enable dragging of content from different domains within a window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing","displayName":"Enable MIME Sniffing (User)","description":"This policy setting allows you to manage MIME sniffing for file promotion from one type to another based on a MIME sniff. A MIME sniff is the recognition by Internet Explorer of the file type based on a bit signature.\n\nIf you enable this policy setting, the MIME Sniffing Safety Feature will not apply in this zone. The security zone will run without the added layer of security provided by this feature.\n\nIf you disable this policy setting, the actions that may be harmful cannot run; this Internet Explorer security feature will be turned on in this zone, as dictated by the feature control setting for the process.\n\nIf you do not configure this policy setting, the MIME Sniffing Safety Feature will not apply in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenablemimesniffing"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100","displayName":"Enable MIME Sniffing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenableprotectedmode"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver","displayName":"Include local path when user is uploading files to a server (User)","description":"This policy setting controls whether or not local path information is sent when the user is uploading a file via an HTML form. If the local path information is sent, some information may be unintentionally revealed to the server. For instance, files sent from the user's desktop may contain the user name as a part of the path.\n\nIf you enable this policy setting, path information is sent when the user is uploading a file via an HTML form.\n\nIf you disable this policy setting, path information is removed when the user is uploading a file via an HTML form.\n\nIf you do not configure this policy setting, the user can choose whether path information is sent when he or she is uploading a file via an HTML form. By default, path information is sent.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneincludelocalpathwhenuploadingfilestoserver"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a","displayName":"Include local directory path when uploading files to a server (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneinitializeandscriptactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, the permission is set to High Safety.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonejavapermissions"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe","displayName":"Launching applications and files in an IFRAME (User)","description":"This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone.\n\nIf you enable this policy setting, users can run applications and download files from IFRAMEs on the pages in this zone without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.\n\nIf you disable this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.\n\nIf you do not configure this policy setting, users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonelaunchingapplicationsandfilesiniframe"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804","displayName":"Launching applications and files in an IFRAME (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions","displayName":"Logon options (User)","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon only in Intranet zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonelogonoptions"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonenavigatewindowsandframes"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode","displayName":"Run .NET Framework-reliant components signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute signed managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute signed managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute signed managed components.\n\nIf you do not configure this policy setting, Internet Explorer will execute signed managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonerunnetframeworkreliantcomponentssignedwithauthenticode"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001","displayName":"Run .NET Framework-reliant components signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles","displayName":"Show security warning for potentially unsafe files (User)","description":"This policy setting controls whether or not the \"Open File - Security Warning\" message appears when the user tries to open executable files or other potentially unsafe files (from an intranet file share by using File Explorer, for example).\n\nIf you enable this policy setting and set the drop-down box to Enable, these files open without a security warning. If you set the drop-down box to Prompt, a security warning appears before the files open.\n\nIf you disable this policy setting, these files do not open.\n\nIf you do not configure this policy setting, the user can configure how the computer handles these files. By default, these files are blocked in the Restricted zone, enabled in the Intranet and Local Computer zones, and set to prompt in the Internet and Trusted zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneshowsecuritywarningforpotentiallyunsafefiles"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806","displayName":"Launching programs and unsafe files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker","displayName":"Use Pop-up Blocker (User)","description":"This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link are not blocked.\n\nIf you enable this policy setting, most unwanted pop-up windows are prevented from appearing.\n\nIf you disable this policy setting, pop-up windows are not prevented from appearing.\n\nIf you do not configure this policy setting, most unwanted pop-up windows are prevented from appearing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneusepopupblocker"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_iz_partname1809","displayName":"Use Pop-up Blocker (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_iz_partname1809_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_iz_partname1809_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowaccesstodatasources"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowautomaticpromptingforactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, users will receive a file download dialog for automatic download attempts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowfontdownloads"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowlessprivilegedsites"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallownetframeworkreliantcomponents"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowscriptlets"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowsmartscreenie"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowuserdatapersistence"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://learn.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneenableprotectedmode"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneinitializeandscriptactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, the permission is set to Medium Safety.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonejavapermissions"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions","displayName":"Logon options (User)","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon only in Intranet zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonelogonoptions"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonenavigatewindowsandframes"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_jscriptreplacement","displayName":"Replace JScript by loading JScript9Legacy in place of JScript. (User)","description":"This policy setting specifies whether JScript or JScript9Legacy is loaded.\n \nIf you enable this policy setting or not configured, JScript9Legacy will be loaded in situations where JScript is instantiated.\n\nIf you disable this policy, then JScript will be utilized.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-jscriptreplacement"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_jscriptreplacement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_jscriptreplacement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_keepintranetsitesininternetexplorer","displayName":"Keep all intranet sites in Internet Explorer (User)","description":"Prevents intranet sites from being opened in any browser except Internet Explorer. But note that If the ‘Send all sites not included in the Enterprise Mode Site List to Microsoft Edge’ (‘RestrictIE’) policy isn’t enabled, this policy has no effect.\n\nIf you enable this policy, all intranet sites are opened in Internet Explorer 11. The only exceptions are sites listed in your Enterprise Mode Site List.\n\nIf you disable or don’t configure this policy, all intranet sites are automatically opened in Microsoft Edge.\n\nWe strongly recommend keeping this policy in sync with the ‘Send all intranet sites to Internet Explorer’ (‘SendIntranetToInternetExplorer’) policy. Additionally, it’s best to enable this policy only if your intranet sites have known compatibility problems with Microsoft Edge.\n\nRelated policies:\n- Send all intranet sites to Internet Explorer (‘SendIntranetToInternetExplorer’)\n- Send all sites not included in the Enterprise Mode Site List to Microsoft Edge (‘RestrictIE’)\n\nFor more info about how to use this policy together with other related policies to create the optimal configuration for your organization, see https://go.microsoft.com/fwlink/?linkid=2094210.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-keepintranetsitesininternetexplorer"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_keepintranetsitesininternetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_keepintranetsitesininternetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowaccesstodatasources"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowautomaticpromptingforactivexcontrols"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, users will receive a file download dialog for automatic download attempts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowautomaticpromptingforfiledownloads"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowfontdownloads"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowlessprivilegedsites"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallownetframeworkreliantcomponents"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowscriptlets"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowsmartscreenie"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowuserdatapersistence"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://learn.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneenableprotectedmode"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, users are queried whether to allow the control to be loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneinitializeandscriptactivexcontrols"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, the permission is set to Medium Safety.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezonejavapermissions"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions","displayName":"Logon options (User)","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon with current username and password.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezonelogonoptions"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezonenavigatewindowsandframes"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowaccesstodatasources"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowautomaticpromptingforactivexcontrols"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowfontdownloads"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowlessprivilegedsites"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallownetframeworkreliantcomponents"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowscriptlets"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowsmartscreenie"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowuserdatapersistence"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneinitializeandscriptactivexcontrols"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzonejavapermissions"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzonenavigatewindowsandframes"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetjavapermissions"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowaccesstodatasources"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowautomaticpromptingforactivexcontrols"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowfontdownloads"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowlessprivilegedsites"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallownetframeworkreliantcomponents"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowscriptlets"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowsmartscreenie"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowuserdatapersistence"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneinitializeandscriptactivexcontrols"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzonenavigatewindowsandframes"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowaccesstodatasources"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowfontdownloads"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowlessprivilegedsites"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallownetframeworkreliantcomponents"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowscriptlets"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowsmartscreenie"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowuserdatapersistence"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneinitializeandscriptactivexcontrols"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezonejavapermissions"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezonenavigatewindowsandframes"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowaccesstodatasources"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, users are queried whether to allow HTML fonts to download.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowfontdownloads"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowlessprivilegedsites"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowscriptlets"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowsmartscreenie"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowuserdatapersistence"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszonejavapermissions"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open additional windows and frames from other domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow additional windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open other windows and frames from other domains or access applications from different domains.\n\nIf you do not configure this policy setting, users cannot open other windows and frames from different domains or access applications from different domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszonenavigatewindowsandframes"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowaccesstodatasources"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowfontdownloads"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowlessprivilegedsites"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallownetframeworkreliantcomponents"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowscriptlets"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowsmartscreenie"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowuserdatapersistence"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszonejavapermissions"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszonenavigatewindowsandframes"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_mimesniffingsafetyfeatureinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"This policy setting determines whether Internet Explorer MIME sniffing will prevent promotion of a file of one type to a more dangerous file type.\n\nIf you enable this policy setting, MIME sniffing will never promote a file of one type to a more dangerous file type.\n\nIf you disable this policy setting, Internet Explorer processes will allow a MIME sniff promoting a file of one type to a more dangerous file type.\n\nIf you do not configure this policy setting, MIME sniffing will never promote a file of one type to a more dangerous file type.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-mimesniffingsafetyfeatureinternetexplorerprocesses"],"categoryId":"b03bfdc7-f42a-400e-935b-2b07fc71a7f1","categoryName":"Mime Sniffing Safety Feature","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_mimesniffingsafetyfeatureinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_mimesniffingsafetyfeatureinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_mkprotocolsecurityrestrictioninternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"The MK Protocol Security Restriction policy setting reduces attack surface area by preventing the MK protocol. Resources hosted on the MK protocol will fail.\n\nIf you enable this policy setting, the MK Protocol is prevented for File Explorer and Internet Explorer, and resources hosted on the MK protocol will fail.\n\nIf you disable this policy setting, applications can use the MK protocol API. Resources hosted on the MK protocol will work for the File Explorer and Internet Explorer processes.\n\nIf you do not configure this policy setting, the MK Protocol is prevented for File Explorer and Internet Explorer, and resources hosted on the MK protocol will fail.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-mkprotocolsecurityrestrictioninternetexplorerprocesses"],"categoryId":"853d5a82-91e4-4c53-8338-fd1a3d9b542c","categoryName":"MK Protocol Security Restriction","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_mkprotocolsecurityrestrictioninternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_mkprotocolsecurityrestrictioninternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage","displayName":"Specify default behavior for a new tab (User)","description":"This policy setting allows you to specify what is displayed when the user opens a new tab.\n\nIf you enable this policy setting, you can choose which page to display when the user opens a new tab: blank page (about:blank), the first home page, the new tab page or the new tab page with my news feed.\n\nIf you disable or do not configure this policy setting, the user can select his or her preference for this behavior.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-newtabdefaultpage"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_newtabactionoptions","displayName":"New tab behavior (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_newtabactionoptions_3","displayName":"New tab page with my news feed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_newtabactionoptions_0","displayName":"about:blank","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_newtabactionoptions_2","displayName":"New tab page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_newtabactionoptions_1","displayName":"Home page","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_notificationbarinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"This policy setting allows you to manage whether the Notification bar is displayed for Internet Explorer processes when file or code installs are restricted. By default, the Notification bar is displayed for Internet Explorer processes.\n\nIf you enable this policy setting, the Notification bar will be displayed for Internet Explorer Processes.\n\nIf you disable this policy setting, the Notification bar will not be displayed for Internet Explorer processes.\n\nIf you do not configure this policy setting, the Notification bar will be displayed for Internet Explorer Processes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-notificationbarinternetexplorerprocesses"],"categoryId":"18296501-4825-47ea-835d-66a01aba9384","categoryName":"Notification bar","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_notificationbarinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_notificationbarinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter","displayName":"Prevent managing SmartScreen Filter (User)","description":"This policy setting prevents the user from managing SmartScreen Filter, which warns the user if the website being visited is known for fraudulent attempts to gather personal information through \"phishing,\" or is known to host malware.\n\nIf you enable this policy setting, the user is not prompted to turn on SmartScreen Filter. All website addresses that are not on the filter's allow list are sent automatically to Microsoft without prompting the user.\n\nIf you disable or do not configure this policy setting, the user is prompted to decide whether to turn on SmartScreen Filter during the first-run experience.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-preventmanagingsmartscreenfilter"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_ie9safetyfilteroptions","displayName":"Select SmartScreen Filter mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_ie9safetyfilteroptions_0","displayName":"Off","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_ie9safetyfilteroptions_1","displayName":"On","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_preventperuserinstallationofactivexcontrols","displayName":"Prevent per-user installation of ActiveX controls (User)","description":"This policy setting allows you to prevent the installation of ActiveX controls on a per-user basis.\n\nIf you enable this policy setting, ActiveX controls cannot be installed on a per-user basis.\n\nIf you disable or do not configure this policy setting, ActiveX controls can be installed on a per-user basis.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-preventperuserinstallationofactivexcontrols"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_preventperuserinstallationofactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_preventperuserinstallationofactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_protectionfromzoneelevationinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"Internet Explorer places restrictions on each Web page it opens. The restrictions are dependent upon the location of the Web page (Internet, Intranet, Local Machine zone, etc.). Web pages on the local computer have the fewest security restrictions and reside in the Local Machine zone, making the Local Machine security zone a prime target for malicious users. Zone Elevation also disables JavaScript navigation if there is no security context.\n\nIf you enable this policy setting, any zone can be protected from zone elevation by Internet Explorer processes.\n\nIf you disable this policy setting, no zone receives such protection for Internet Explorer processes.\n\nIf you do not configure this policy setting, any zone can be protected from zone elevation by Internet Explorer processes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-protectionfromzoneelevationinternetexplorerprocesses"],"categoryId":"3bbaff1b-7d59-4b9c-ab53-c235d72b2fb0","categoryName":"Protection From Zone Elevation","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_protectionfromzoneelevationinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_protectionfromzoneelevationinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols","displayName":"Remove \"Run this time\" button for outdated ActiveX controls in Internet Explorer (User)","description":"This policy setting allows you to stop users from seeing the \"Run this time\" button and from running specific outdated ActiveX controls in Internet Explorer.\n\nIf you enable this policy setting, users won't see the \"Run this time\" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control.\n\nIf you disable or don't configure this policy setting, users will see the \"Run this time\" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control. Clicking this button lets the user run the outdated ActiveX control once.\n\nFor more information, see \"Outdated ActiveX Controls\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-removerunthistimebuttonforoutdatedactivexcontrols"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_resetzoomfordialoginiemode","displayName":"Reset zoom to default for HTML dialogs in Internet Explorer mode (User)","description":"This policy setting lets admins reset zoom to default for HTML dialogs in Internet Explorer mode.\n\nIf you enable this policy, the zoom of an HTML dialog in Internet Explorer mode will not get propagated from its parent page.\n\nIf you disable, or don't configure this policy, the zoom of an HTML dialog in Internet Explorer mode will be set based on the zoom of it's parent page.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2220107","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-resetzoomfordialoginiemode"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_resetzoomfordialoginiemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_resetzoomfordialoginiemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictactivexinstallinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"This policy setting enables blocking of ActiveX control installation prompts for Internet Explorer processes.\n\nIf you enable this policy setting, prompting for ActiveX control installations will be blocked for Internet Explorer processes.\n\nIf you disable this policy setting, prompting for ActiveX control installations will not be blocked for Internet Explorer processes.\n\nIf you do not configure this policy setting, the user's preference will be used to determine whether to block ActiveX control installations for Internet Explorer processes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictactivexinstallinternetexplorerprocesses"],"categoryId":"e6911a08-946f-4b70-99cb-2a8b92c461e0","categoryName":"Restrict ActiveX Install","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictactivexinstallinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictactivexinstallinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowaccesstodatasources"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting","displayName":"Allow active scripting (User)","description":"This policy setting allows you to manage whether script code on pages in the zone is run.\n\nIf you enable this policy setting, script code on pages in the zone can run automatically. If you select Prompt in the drop-down box, users are queried to choose whether to allow script code on pages in the zone to run.\n\nIf you disable this policy setting, script code on pages in the zone is prevented from running.\n\nIf you do not configure this policy setting, script code on pages in the zone is prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowactivescripting"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400","displayName":"Allow active scripting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowautomaticpromptingforactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors","displayName":"Allow binary and script behaviors (User)","description":"This policy setting allows you to manage dynamic binary and script behaviors: components that encapsulate specific functionality for HTML elements to which they were attached.\n\nIf you enable this policy setting, binary and script behaviors are available. If you select Administrator approved in the drop-down box, only behaviors listed in the Admin-approved Behaviors under Binary Behaviors Security Restriction policy are available.\n\nIf you disable this policy setting, binary and script behaviors are not available unless applications have implemented a custom security manager.\n\nIf you do not configure this policy setting, binary and script behaviors are not available unless applications have implemented a custom security manager.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowbinaryandscriptbehaviors"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000","displayName":"Allow Binary and Script Behaviors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000_65536","displayName":"Administrator approved","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript","displayName":"Allow cut, copy or paste operations from the clipboard via script (User)","description":"This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region.\n\nIf you enable this policy setting, a script can perform a clipboard operation.\n\nIf you select Prompt in the drop-down box, users are queried as to whether to perform clipboard operations.\n\nIf you disable this policy setting, a script cannot perform a clipboard operation.\n\nIf you do not configure this policy setting, a script cannot perform a clipboard operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowcopypasteviascript"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407","displayName":"Allow paste operations via script (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles","displayName":"Allow drag and drop or copy and paste files (User)","description":"This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone.\n\nIf you enable this policy setting, users can drag files or copy and paste files from this zone automatically. If you select Prompt in the drop-down box, users are queried to choose whether to drag or copy files from this zone.\n\nIf you disable this policy setting, users are prevented from dragging files or copying and pasting files from this zone.\n\nIf you do not configure this policy setting, users are queried to choose whether to drag or copy files from this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowdraganddropcopyandpastefiles"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_iz_partname1802","displayName":"Allow drag and drop or copy and paste files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_iz_partname1802_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_iz_partname1802_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_iz_partname1802_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads","displayName":"Allow file downloads (User)","description":"This policy setting allows you to manage whether file downloads are permitted from the zone. This option is determined by the zone of the page with the link causing the download, not the zone from which the file is delivered.\n\nIf you enable this policy setting, files can be downloaded from the zone.\n\nIf you disable this policy setting, files are prevented from being downloaded from the zone.\n\n If you do not configure this policy setting, files are prevented from being downloaded from the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowfiledownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_iz_partname1803","displayName":"Allow file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_iz_partname1803_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_iz_partname1803_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, users are queried whether to allow HTML fonts to download.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowfontdownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowlessprivilegedsites"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles","displayName":"Allow loading of XAML files (User)","description":"This policy setting allows you to manage the loading of Extensible Application Markup Language (XAML) files. XAML is an XML-based declarative markup language commonly used for creating rich user interfaces and graphics that take advantage of the Windows Presentation Foundation.\n\nIf you enable this policy setting and set the drop-down box to Enable, XAML files are automatically loaded inside Internet Explorer. The user cannot change this behavior. If you set the drop-down box to Prompt, the user is prompted for loading XAML files.\n\nIf you disable this policy setting, XAML files are not loaded inside Internet Explorer. The user cannot change this behavior.\n\nIf you do not configure this policy setting, the user can decide whether to load XAML files inside Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowloadingofxamlfiles"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402","displayName":"XAML Files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowmetarefresh","displayName":"Allow META REFRESH (User)","description":"This policy setting allows you to manage whether a user's browser can be redirected to another Web page if the author of the Web page uses the Meta Refresh setting (tag) to redirect browsers to another Web page.\n\nIf you enable this policy setting, a user's browser that loads a page containing an active Meta Refresh setting can be redirected to another Web page.\n\nIf you disable this policy setting, a user's browser that loads a page containing an active Meta Refresh setting cannot be redirected to another Web page.\n\nIf you do not configure this policy setting, a user's browser that loads a page containing an active Meta Refresh setting cannot be redirected to another Web page.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowmetarefresh"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowmetarefresh_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowmetarefresh_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowmetarefresh_iz_partname1608","displayName":"Allow META REFRESH (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowmetarefresh_iz_partname1608_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowmetarefresh_iz_partname1608_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallownetframeworkreliantcomponents"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols","displayName":"Allow only approved domains to use ActiveX controls without prompt (User)","description":"This policy setting controls whether or not the user is prompted to allow ActiveX controls to run on websites other than the website that installed the ActiveX control.\n\nIf you enable this policy setting, the user is prompted before ActiveX controls can run from websites in this zone. The user can choose to allow the control to run from the current site or from all sites.\n\nIf you disable this policy setting, the user does not see the per-site ActiveX prompt, and ActiveX controls can run from all sites in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b","displayName":"Only allow approved domains to use ActiveX controls without prompt (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol","displayName":"Allow only approved domains to use the TDC ActiveX control (User)","description":"This policy setting controls whether or not the user is allowed to run the TDC ActiveX control on websites.\n\nIf you enable this policy setting, the TDC ActiveX control will not run from websites in this zone.\n\nIf you disable this policy setting, the TDC Active X control will run from all sites in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c","displayName":"Only allow approved domains to use the TDC ActiveX control (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols","displayName":"Allow scripting of Internet Explorer WebBrowser controls (User)","description":"This policy setting determines whether a page can control embedded WebBrowser controls via script.\n\nIf you enable this policy setting, script access to the WebBrowser control is allowed.\n\nIf you disable this policy setting, script access to the WebBrowser control is not allowed.\n\nIf you do not configure this policy setting, the user can enable or disable script access to the WebBrowser control. By default, script access to the WebBrowser control is allowed only in the Local Machine and Intranet zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206","displayName":"Internet Explorer web browser control (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows","displayName":"Allow script-initiated windows without size or position constraints (User)","description":"This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars.\n\nIf you enable this policy setting, Windows Restrictions security will not apply in this zone. The security zone runs without the added layer of security provided by this feature.\n\nIf you disable this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.\n\nIf you do not configure this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowscriptinitiatedwindows"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_iz_partname2102","displayName":"Allow script-initiated windows without size or position constraints (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_iz_partname2102_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_iz_partname2102_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowscriptlets"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowsmartscreenie"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript","displayName":"Allow updates to status bar via script (User)","description":"This policy setting allows you to manage whether script is allowed to update the status bar within the zone.\n\nIf you enable this policy setting, script is allowed to update the status bar.\n\nIf you disable or do not configure this policy setting, script is not allowed to update the status bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowupdatestostatusbarviascript"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_iz_partname2103","displayName":"Status bar updates via script (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_iz_partname2103_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_iz_partname2103_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowuserdatapersistence"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer","displayName":"Allow VBScript to run in Internet Explorer (User)","description":"This policy setting allows you to manage whether VBScript can be run on pages from the specified zone in Internet Explorer.\n\nIf you selected Enable in the drop-down box, VBScript can run without user intervention.\n\nIf you selected Prompt in the drop-down box, users are asked to choose whether to allow VBScript to run.\n\nIf you selected Disable in the drop-down box, VBScript is prevented from running.\n\nIf you do not configure or disable this policy setting, VBScript is prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowvbscripttorunininternetexplorer"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_iz_partname140c","displayName":"Allow VBScript to run in Internet Explorer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_iz_partname140c_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_iz_partname140c_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_iz_partname140c_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols","displayName":"Download signed ActiveX controls (User)","description":"This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone.\n\nIf you enable this policy, users can download signed controls without user intervention. If you select Prompt in the drop-down box, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.\n\nIf you disable the policy setting, signed controls cannot be downloaded.\n\nIf you do not configure this policy setting, signed controls cannot be downloaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonedownloadsignedactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001","displayName":"Download signed ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols","displayName":"Download unsigned ActiveX controls (User)","description":"This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone. Such code is potentially harmful, especially when coming from an untrusted zone.\n\nIf you enable this policy setting, users can run unsigned controls without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to allow the unsigned control to run.\n\nIf you disable this policy setting, users cannot run unsigned controls.\n\nIf you do not configure this policy setting, users cannot run unsigned controls.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonedownloadunsignedactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004","displayName":"Download unsigned ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter","displayName":"Turn on Cross-Site Scripting Filter (User)","description":"This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into websites in this zone.\n\nIf you enable this policy setting, the XSS Filter is turned on for sites in this zone, and the XSS Filter attempts to block cross-site script injections.\n\nIf you disable this policy setting, the XSS Filter is turned off for sites in this zone, and Internet Explorer permits cross-site script injections.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenablecrosssitescriptingfilter"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_iz_partname1409","displayName":"Turn on Cross-Site Scripting (XSS) Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_iz_partname1409_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_iz_partname1409_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows","displayName":"Enable dragging of content from different domains across windows (User)","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in different windows.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when both the source and destination are in different windows. Users cannot change this setting.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in different windows. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy or do not configure it, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709","displayName":"Enable dragging of content from different domains across windows (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows","displayName":"Enable dragging of content from different domains within a window (User)","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in the same window.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting in the Internet Options dialog.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in the same window. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy setting or do not configure it, users can drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting in the Internet Options dialog.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708","displayName":"Enable dragging of content from different domains within a window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing","displayName":"Enable MIME Sniffing (User)","description":"This policy setting allows you to manage MIME sniffing for file promotion from one type to another based on a MIME sniff. A MIME sniff is the recognition by Internet Explorer of the file type based on a bit signature.\n\nIf you enable this policy setting, the MIME Sniffing Safety Feature will not apply in this zone. The security zone will run without the added layer of security provided by this feature.\n\nIf you disable this policy setting, the actions that may be harmful cannot run; this Internet Explorer security feature will be turned on in this zone, as dictated by the feature control setting for the process.\n\nIf you do not configure this policy setting, the actions that may be harmful cannot run; this Internet Explorer security feature will be turned on in this zone, as dictated by the feature control setting for the process.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenablemimesniffing"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_iz_partname2100","displayName":"Enable MIME Sniffing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_iz_partname2100_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_iz_partname2100_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver","displayName":"Include local path when user is uploading files to a server (User)","description":"This policy setting controls whether or not local path information is sent when the user is uploading a file via an HTML form. If the local path information is sent, some information may be unintentionally revealed to the server. For instance, files sent from the user's desktop may contain the user name as a part of the path.\n\nIf you enable this policy setting, path information is sent when the user is uploading a file via an HTML form.\n\nIf you disable this policy setting, path information is removed when the user is uploading a file via an HTML form.\n\nIf you do not configure this policy setting, the user can choose whether path information is sent when he or she is uploading a file via an HTML form. By default, path information is sent.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a","displayName":"Include local directory path when uploading files to a server (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonejavapermissions"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe","displayName":"Launching applications and files in an IFRAME (User)","description":"This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone.\n\nIf you enable this policy setting, users can run applications and download files from IFRAMEs on the pages in this zone without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.\n\nIf you disable this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.\n\nIf you do not configure this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonelaunchingapplicationsandfilesiniframe"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804","displayName":"Launching applications and files in an IFRAME (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions","displayName":"Logon options (User)","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Prompt for username and password.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonelogonoptions"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open additional windows and frames from other domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow additional windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open other windows and frames from other domains or access applications from different domains.\n\nIf you do not configure this policy setting, users cannot open other windows and frames from different domains or access applications from different domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonenavigatewindowsandframes"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins","displayName":"Run ActiveX controls and plugins (User)","description":"This policy setting allows you to manage whether ActiveX controls and plug-ins can be run on pages from the specified zone.\n\nIf you enable this policy setting, controls and plug-ins can run without user intervention.\n\nIf you selected Prompt in the drop-down box, users are asked to choose whether to allow the controls or plug-in to run.\n\nIf you disable this policy setting, controls and plug-ins are prevented from running.\n\nIf you do not configure this policy setting, controls and plug-ins are prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonerunactivexcontrolsandplugins"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200","displayName":"Run ActiveX controls and plugins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_65536","displayName":"Administrator approved","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode","displayName":"Run .NET Framework-reliant components signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute signed managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute signed managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute signed managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute signed managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001","displayName":"Run .NET Framework-reliant components signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting","displayName":"Script ActiveX controls marked safe for scripting (User)","description":"This policy setting allows you to manage whether an ActiveX control marked safe for scripting can interact with a script.\n\nIf you enable this policy setting, script interaction can occur automatically without user intervention.\n\nIf you select Prompt in the drop-down box, users are queried to choose whether to allow script interaction.\n\nIf you disable this policy setting, script interaction is prevented from occurring.\n\nIf you do not configure this policy setting, script interaction is prevented from occurring.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_iz_partname1405","displayName":"Script ActiveX controls marked safe for scripting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_iz_partname1405_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_iz_partname1405_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_iz_partname1405_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets","displayName":"Scripting of Java applets (User)","description":"This policy setting allows you to manage whether applets are exposed to scripts within the zone.\n\nIf you enable this policy setting, scripts can access applets automatically without user intervention.\n\nIf you select Prompt in the drop-down box, users are queried to choose whether to allow scripts to access applets.\n\nIf you disable this policy setting, scripts are prevented from accessing applets.\n\nIf you do not configure this policy setting, scripts are prevented from accessing applets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonescriptingofjavaapplets"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402","displayName":"Scripting of Java applets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles","displayName":"Show security warning for potentially unsafe files (User)","description":"This policy setting controls whether or not the \"Open File - Security Warning\" message appears when the user tries to open executable files or other potentially unsafe files (from an intranet file share by using File Explorer, for example).\n\nIf you enable this policy setting and set the drop-down box to Enable, these files open without a security warning. If you set the drop-down box to Prompt, a security warning appears before the files open.\n\nIf you disable this policy setting, these files do not open.\n\nIf you do not configure this policy setting, the user can configure how the computer handles these files. By default, these files are blocked in the Restricted zone, enabled in the Intranet and Local Computer zones, and set to prompt in the Internet and Trusted zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806","displayName":"Launching programs and unsafe files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneturnonprotectedmode"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker","displayName":"Use Pop-up Blocker (User)","description":"This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link are not blocked.\n\nIf you enable this policy setting, most unwanted pop-up windows are prevented from appearing.\n\nIf you disable this policy setting, pop-up windows are not prevented from appearing.\n\nIf you do not configure this policy setting, most unwanted pop-up windows are prevented from appearing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneusepopupblocker"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_iz_partname1809","displayName":"Use Pop-up Blocker (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_iz_partname1809_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_iz_partname1809_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictfiledownloadinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"This policy setting enables blocking of file download prompts that are not user initiated.\n\nIf you enable this policy setting, file download prompts that are not user initiated will be blocked for Internet Explorer processes.\n\nIf you disable this policy setting, prompting will occur for file downloads that are not user initiated for Internet Explorer processes.\n\nIf you do not configure this policy setting, the user's preference determines whether to prompt for file downloads that are not user initiated for Internet Explorer processes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictfiledownloadinternetexplorerprocesses"],"categoryId":"17bc9899-d157-4eac-a949-810b4a841e28","categoryName":"Restrict File Download","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictfiledownloadinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictfiledownloadinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_scriptedwindowsecurityrestrictionsinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"Internet Explorer allows scripts to programmatically open, resize, and reposition windows of various types. The Window Restrictions security feature restricts popup windows and prohibits scripts from displaying windows in which the title and status bars are not visible to the user or obfuscate other Windows' title and status bars.\n\nIf you enable this policy setting, popup windows and other restrictions apply for File Explorer and Internet Explorer processes.\n\nIf you disable this policy setting, scripts can continue to create popup windows and windows that obfuscate other windows.\n\nIf you do not configure this policy setting, popup windows and other restrictions apply for File Explorer and Internet Explorer processes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-scriptedwindowsecurityrestrictionsinternetexplorerprocesses"],"categoryId":"622c83ff-f780-47e6-8b9c-bf82552e3f04","categoryName":"Scripted Window Security Restrictions","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_scriptedwindowsecurityrestrictionsinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_scriptedwindowsecurityrestrictionsinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_searchproviderlist","displayName":"Restrict search providers to a specific list (User)","description":"This policy setting allows you to restrict the search providers that appear in the Search box in Internet Explorer to those defined in the list of policy keys for search providers (found under [HKCU or HKLM\\Software\\policies\\Microsoft\\Internet Explorer\\SearchScopes]). Normally, search providers can be added from third-party toolbars or in Setup, but the user can also add them from a search provider's website.\n\nIf you enable this policy setting, the user cannot configure the list of search providers on his or her computer, and any default providers installed do not appear (including providers installed from other applications). The only providers that appear are those in the list of policy keys for search providers. Note: This list can be created through a custom administrative template file. For information about creating this custom administrative template file, see the Internet Explorer documentation on search providers.\n\nIf you disable or do not configure this policy setting, the user can configure his or her list of search providers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-searchproviderlist"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_searchproviderlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_searchproviderlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_sendsitesnotinenterprisesitelisttoedge","displayName":"Send all sites not included in the Enterprise Mode Site List to Microsoft Edge. (User)","description":"This setting lets you decide whether to open all sites not included in the Enterprise Mode Site List in Microsoft Edge. If you use this setting, you must also turn on the Administrative Templates\\Windows Components\\Internet Explorer\\Use the Enterprise Mode IE website list policy setting and you must include at least one site in the Enterprise Mode Site List.\n\nEnabling this setting automatically opens all sites not included in the Enterprise Mode Site List in Microsoft Edge.\n\nDisabling, or not configuring this setting, opens all sites based on the currently active browser.\n\nNote: If you've also enabled the Administrative Templates\\Windows Components\\Microsoft Edge\\Send all intranet sites to Internet Explorer 11 policy setting, then all intranet sites will continue to open in Internet Explorer 11.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-sendsitesnotinenterprisesitelisttoedge"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_sendsitesnotinenterprisesitelisttoedge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_sendsitesnotinenterprisesitelisttoedge_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_specifyuseofactivexinstallerservice","displayName":"Specify use of ActiveX Installer Service for installation of ActiveX controls (User)","description":"This policy setting allows you to specify how ActiveX controls are installed.\n\nIf you enable this policy setting, ActiveX controls are installed only if the ActiveX Installer Service is present and has been configured to allow the installation of ActiveX controls.\n\nIf you disable or do not configure this policy setting, ActiveX controls, including per-user controls, are installed through the standard installation process.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-specifyuseofactivexinstallerservice"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_specifyuseofactivexinstallerservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_specifyuseofactivexinstallerservice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowaccesstodatasources"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowautomaticpromptingforactivexcontrols"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, users will receive a file download dialog for automatic download attempts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowfontdownloads"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, a warning is issued to the user that potentially risky navigation is about to occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowlessprivilegedsites"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallownetframeworkreliantcomponents"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowscriptlets"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowsmartscreenie"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowuserdatapersistence"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://learn.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneenableprotectedmode"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, users are queried whether to allow the control to be loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, the permission is set to Low Safety.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszonejavapermissions"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions","displayName":"Logon options (User)","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon with current username and password.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszonelogonoptions"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszonenavigatewindowsandframes"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_kioskbrowser_blockedurlexceptions","displayName":"Blocked Url Exceptions (User)","description":"List of exceptions to the blocked website URLs (with wildcard support). This is used to configure URLs kiosk browsers are allowed to navigate to, which are a subset of the blocked URLs.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#blockedurlexceptions"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_blockedurls","displayName":"Blocked Urls (User)","description":"List of blocked website URLs (with wildcard support). This is used to configure blocked URLs kiosk browsers can not navigate to.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#blockedurls"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_defaulturl","displayName":"Default URL (User)","description":"Configures the default URL kiosk browsers to navigate on launch and restart.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#defaulturl"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton","displayName":"Enable End Session Button (User)","description":"Enable/disable kiosk browser's end session button.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enableendsessionbutton"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"user_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton_0","displayName":"Disable","description":"Disable","helpText":null}]},{"id":"user_vendor_msft_policy_config_kioskbrowser_enablehomebutton","displayName":"Enable Home Button (User)","description":"Enable/disable kiosk browser's home button.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enablehomebutton"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"user_vendor_msft_policy_config_kioskbrowser_enablehomebutton_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_enablehomebutton_0","displayName":"Disable","description":"Disable","helpText":null}]},{"id":"user_vendor_msft_policy_config_kioskbrowser_enablenavigationbuttons","displayName":"Enable Navigation Buttons (User)","description":"Enable/disable kiosk browser's navigation buttons (forward/back).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enablenavigationbuttons"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"user_vendor_msft_policy_config_kioskbrowser_enablenavigationbuttons_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_enablenavigationbuttons_0","displayName":"Disable","description":"Disable","helpText":null}]},{"id":"user_vendor_msft_policy_config_kioskbrowser_restartonidletime","displayName":"Restart On Idle Time (User)","description":"Amount of time in minutes the session is idle until the kiosk browser restarts in a fresh state.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#restartonidletime"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfigurationmode_1","displayName":"Specify server (User)","description":"\r\nSpecifies how Microsoft Lync identifies the server.\r\n\r\nIf you enable this policy setting, you must specify the server name that Microsoft Lync uses.\r\n\r\nIf you disable this policy setting, Microsoft Lync uses a DNS lookup to identify the server.\r\n\r\nIf you do not configure this policy setting, the user can choose automatic configuration, or the user can specify the name of the server in Microsoft Lync user preferences. To set the user preferences, from the Microsoft Lync Tools menu, click Options, click the Personal tab, within the SIP Communications My Account area click Advanced, select Configure Settings, type the server name in the Server name field.\r\n\r\nNote: You can configure this policy setting under both Computer Configuration and User Configuration, but the policy setting under Computer Configuration takes precedence.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfigurationmode_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfigurationmode_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfigurationmode_1_l_serveraddressexternal_value","displayName":"DNS name of the external server (User)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfigurationmode_1_l_serveraddressinternal_value","displayName":"DNS name of the internal server (User)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1","displayName":"Additional server versions supported (User)","description":"\r\nSpecify a semicolon separated list of server version names, e.g. RTC/2.9;RTC/3.0;RTC/4.0, to which Microsoft Lync allows logon in addition to the server versions that are supported by default. Space character is treated as part of the version string.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1_l_configuredservercheckvalues_value","displayName":"Server version names (semicolon separated list): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1","displayName":"Disable automatic upload of sign-in failure logs (User)","description":"\r\nUploads the sign-in failure logs to the Microsoft Lync Server automatically for analysis. No logs will be automatically uploaded if sign-in is successful.\r\n\r\nIf this policy is not configured, then the following happens: \r\nFor Lync Online Users: Sign-in failure logs are automatically uploaded.\r\nFor Lync On-Premise Users: A confirmation seeking consent from the user is shown before upload.\r\n\r\nWhen this is disabled, sign-in logs would be uploaded to the Microsoft Lync Server for both Lync On-Premise and Online users automatically.\r\n\r\nWhen this is enabled, sign-in logs will never be uploaded automatically.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1","displayName":"Disable HTTP fallback for SIP connection (User)","description":"Prevents from HTTP being used for SIP connection in case TLS or TCP fail.","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablentcredentials_1","displayName":"Require logon credentials (User)","description":"\r\nRequires the user to provide logon credentials for Microsoft Lync rather than automatically using the Windows credentials when Microsoft Lync authenticates the user using NTLM or Kerberos.\r\n\r\nIf you enable this policy setting, Microsoft Lync requires the user to provide logon credentials.\r\n\r\nIf you disable or do not configure this policy setting, Microsoft Lync authenticates the user based on the logon credentials for Windows.\r\n\r\nNote: You can configure this policy setting under both Computer Configuration and User Configuration, but the policy setting under Computer Configuration takes precedence.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablentcredentials_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablentcredentials_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableservercheck_1","displayName":"Disable server version check (User)","description":"Prevents Microsoft Lync from checking the server version before signing in.","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableservercheck_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableservercheck_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablebitsforgaldownload_1","displayName":"Enable using BITS to download Address Book Service files (User)","description":"This policy allows Microsoft Lync to use BITS (Background Intelligent Transfer Service) to download the Address Book Services files.","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablebitsforgaldownload_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablebitsforgaldownload_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablesiphighsecuritymode_1","displayName":"Configure SIP security mode (User)","description":"\r\nWhen Lync connects to the server, it supports various authentication mechanisms. This policy allows the user to specify whether Digest and Basic authentication are supported.\r\n\r\nDisabled (default): NTLM/Kerberos/TLS-DSK/Digest/Basic\r\nEnabled:\r\n Authentication mechanisms: NTLM/Kerberos/TLS-DSK\r\n Gal Download: Requires HTTPS if user is not logged in as an internal user.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablesiphighsecuritymode_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablesiphighsecuritymode_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policygaldownloadinitialdelay_1","displayName":"Global Address Book Download Initial Delay (User)","description":"\r\nWhen set, this will delay the initial download of the Global Address Book by a random number between 0 and the number of minutes specified after sign-in. When the value is 0, the download will begin immediately after sign-in. By default, the value is 60. This means that there will be a random delay between 0 and 60 minutes after sign-in before Lync begins to download the address book.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policygaldownloadinitialdelay_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policygaldownloadinitialdelay_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policygaldownloadinitialdelay_1_l_galdownloadinitialdelay_value","displayName":"Maximum possible number of minutes to delay download: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policypreventrun_1","displayName":"Prevent users from running Microsoft Lync (User)","description":"\r\nPrevents users from running Microsoft Lync.\r\n\r\nIf you enable this policy setting, users cannot run Microsoft Lync.\r\n\r\nIf you disable or do not configure this policy setting, users can run Microsoft Lync.\r\n\r\nNote: You can configure this policy setting under both Computer Configuration and User Configuration, but the policy setting under Computer Configuration takes precedence.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policypreventrun_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policypreventrun_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysavepassword_1","displayName":"Allow storage of user passwords (User)","description":"\r\nAllows Microsoft Lync to store user passwords.\r\n\r\nIf you enable this policy setting, Microsoft Lync can store a password on request from the user.\r\n\r\nIf you disable this policy setting, Microsoft Lync cannot store a password.\r\n\r\nIf you do not configure this policy setting and the user logs on to a domain, Microsoft Lync does not store the password. If you do not configure this policy setting and the user does not log on to a domain (for example, if the user logs on to a workgroup), Microsoft Lync can store the password.\r\n\r\nNote: You can configure this policy setting under both Computer Configuration and User Configuration, but the policy setting under Computer Configuration takes precedence.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysavepassword_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysavepassword_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1","displayName":"Configure SIP compression mode (User)","description":"\r\nDefines when to turn on SIP compression. Default: Based on adaptor speed.\r\n\r\nSetting this policy may cause an increase in sign-in time.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_l_policysipcompression","displayName":"Configure SIP compression mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_l_policysipcompression_0","displayName":"Always disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_l_policysipcompression_1","displayName":"Always enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_l_policysipcompression_2","displayName":"Based on adaptor speed (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_l_policysipcompression_3","displayName":"Based on ping round-trip time","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_1","displayName":"Trusted Domain List (User)","description":"\r\nWhen Lync connects to an unknown domain, it needs explicit user consent. A dialog is shown asking the user for confirmation on whether it should continue.\r\n\r\nThis policy gives administrators the ability to provide trusted domain names. If a domain name is added to this list, Lync will trust that domain and will not show the dialog requesting permission. Multiple domain addresses as comma separated values can be provided.\r\n\r\nBy setting this policy, Lync will not explicitly trust the default domains specified below. It will exclusively trust the domain specified by the policy.\r\n\r\nSupported values:\r\n Not Configured (Default)/Disabled: By default the following domains will be trusted: \"lync.com, outlook.com, lync.glbdns.microsoft.com, and microsoftonline.com.\"\r\n Enabled: The list of domains to be trusted. For example: \"contoso.com, contoso.co.in\"\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_1_l_trustmodeldata_value","displayName":"Trusted Domains (comma separated list): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder","displayName":"Configure the location of the browser executable folder (User)","description":"This policy configures WebView2 applications to use the WebView2 Runtime in the specified path. The folder should contain the following files: msedgewebview2.exe, msedge.dll, and so on.\r\n\r\nTo set the value for the folder path, provide a Value name and Value pair. Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications.\r\n\r\nExample value:\r\n\r\nName: *, Value: C:\\Program Files\\Microsoft Edge WebView2 Runtime Redistributable 85.0.541.0 x64","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc","displayName":"Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference","displayName":"Set the release channel search order preference (User)","description":"The default channel search order is WebView2 Runtime, Beta, Dev, and Canary.\r\n\r\nTo reverse the default search order, set this policy to 1.\r\n\r\nTo set the value for the release channel preference, provide a Value name and Value pair. Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications.\r\n\r\nExample value:\r\n\r\nName: *, Value: 1","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference_releasechannelpreferencedesc","displayName":"Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference_releasechannelpreferencedesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference_releasechannelpreferencedesc_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service (User)","description":"The Experimentation and Configuration Service is used to deploy Experimentation and Configuration payloads to the client.\r\n\r\nExperimentation payload consists of a list of early in development features that Microsoft is enabling for testing and feedback.\r\n\r\nConfiguration payload consists of a list of recommended settings that Microsoft wants to deploy to optimize the user experience.\r\n\r\nConfiguration payload may also contain a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\r\n\r\nIf you set this policy to 'FullMode', the full payload is downloaded from the Experimentation and Configuration Service. This includes both the experimentation and configuration payloads.\r\n\r\nIf you set this policy to 'ConfigurationsOnlyMode', only the configuration payload is downloaded.\r\n\r\nIf you set this policy to 'RestrictedMode', the communication with the Experimentation and Configuration Service is stopped completely. Microsoft does not recommend this setting.\r\n\r\nIf you don't configure this policy on a managed device, the behavior on Beta and Stable channels is the same as the 'ConfigurationsOnlyMode'. On Canary and Dev channels the behavior is the same as 'FullMode'.\r\n\r\nIf you don't configure this policy on an unmanaged device, the behavior is the same as the 'FullMode'.\r\n\r\nPolicy options mapping:\r\n\r\n* FullMode (2) = Retrieve configurations and experiments\r\n\r\n* ConfigurationsOnlyMode (1) = Retrieve configurations only\r\n\r\n* RestrictedMode (0) = Disable communication with the Experimentation and Configuration Service\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol_2","displayName":"Retrieve configurations and experiments","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol_1","displayName":"Retrieve configurations only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol_0","displayName":"Disable communication with the Experimentation and Configuration Service","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled. (User)","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy.\r\nCurrently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers.\r\nThis enterprise policy can be used to opt out of this gradual deprecation by forcing the default to stay enabled.\r\n\r\nPages might depend on unload event handlers to save data or signal the end of a user session to the server.\r\nThis is not recommended because it's unreliable and impacts performance by blocking use of BackForwardCache.\r\nRecommended alternatives exist, but the unload event has been used for a long time. Some applications might still rely on them.\r\n\r\nIf you disable this policy or don't configure it, unload event handlers will gradually be deprecated in-line with the deprecation rollout and sites which don't set Permissions-Policy header will stop firing `unload` events.\r\n\r\nIf you enable this policy then unload event handlers will continue to work by default.","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_forcepermissionpolicyunloaddefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_forcepermissionpolicyunloaddefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist","displayName":"HTTP Allowlist (User)","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that will not be upgraded to HTTPS and will not show an error interstitial if HTTPS-First Mode is enabled. Organizations can use this policy to maintain access to servers that do not support HTTPS, without needing to disable \"AutomaticHttpsDefault\".\r\n\r\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase.\r\n\r\nBlanket host wildcards (i.e., \"*\" or \"[*]\") are not allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies.\r\n\r\nNote: This policy does not apply to HSTS upgrades.\r\n\r\nExample value:\r\n\r\ntestserver.example.com\r\n[*.]example.org","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_httpallowlistdesc","displayName":"HTTP Allowlist (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_httpallowlistdesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_httpallowlistdesc_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newbaseurlinheritancebehaviorallowed","displayName":"Allows enabling the feature NewBaseUrlInheritanceBehavior (User)","description":"NewBaseUrlInheritanceBehavior is a Microsoft Edge feature that causes about:blank and about:srcdoc frames to consistently inherit their base url values via snapshots of their initiator's base url.\r\n\r\nIf you disable this policy, it prevents users or Microsoft Edge variations from enabling NewBaseUrlInheritanceBehavior, in case compatibility issues are discovered.\r\n\r\nIf you enable or don't configure this policy, it allows enabling NewBaseUrlInheritanceBehavior.","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newbaseurlinheritancebehaviorallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newbaseurlinheritancebehaviorallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newpdfreaderwebview2list","displayName":"Enable built-in PDF reader powered by Adobe Acrobat for WebView2 (User)","description":"This policy configures WebView2 applications to launch the new version of the PDF reader that's powered by Adobe Acrobat's PDF reader. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF file handling, and greater accessibility.\r\n\r\nIf this policy is specified for an application, it is possible that it may impact other related applications as well. The policy is applied to all WebView2s sharing the same WebView2 user data folder. These WebView2s could potentially belong to multiple applications if those applications, which are likely from the same product family, are designed to share the same user data folder.\r\n\r\nUse a name-value pair to enable the new PDF reader for the application. Set the name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications. Set the Value to true to enable the new reader or set it to false to use the existing one.\r\n\r\nIf you enable this policy for the specified WebView2 applications, they will use the new Adobe Acrobat powered PDF reader to open all PDF files.\r\n\r\nIf you disable the policy for the specified WebView2 applications or don't configure it, they will use the existing PDF reader to open all PDF files.\r\n\r\nExample value:\r\n\r\n{\"name\": \"app1.exe\", \"value\": true}\r\n{\"name\": \"app_id_for_app2\", \"value\": true}\r\n{\"name\": \"*\", \"value\": false}","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newpdfreaderwebview2list_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newpdfreaderwebview2list_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newpdfreaderwebview2list_newpdfreaderwebview2listdesc","displayName":"Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newpdfreaderwebview2list_newpdfreaderwebview2listdesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newpdfreaderwebview2list_newpdfreaderwebview2listdesc_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_rsakeyusageforlocalanchorsenabled","displayName":"Check RSA key usage for server certificates issued by local trust anchors (User)","description":"The X.509 key usage extension declares how the key in a certificate can be\r\nused. These instructions ensure certificates aren't used in an unintended\r\ncontext, which protects against a class of cross-protocol attacks on HTTPS and\r\nother protocols. HTTPS clients must verify that server certificates match the\r\nconnection's TLS parameters.\r\n\r\nIf this policy is enabled,\r\nMicrosoft Edge will perform this key\r\ncheck. This helps prevent attacks where an attacker manipulates the browser into\r\ninterpreting a key in ways that the certificate owner did not intend.\r\n\r\nIf this policy is set to disabled or not configured,\r\nMicrosoft Edge will skip this key check in\r\nHTTPS connections that negotiate TLS 1.2 and use an RSA certificate that\r\nchains to a local trust anchor. Examples of local trust anchors include\r\npolicy-provided or user-installed root certificates. In all other cases, the\r\ncheck is performed independent of this policy's setting.\r\n\r\nThis policy is available for administrators to preview the behavior of a\r\nfuture release, which will enable this check by default. At that point, this\r\npolicy will remain temporarily available for administrators that need more\r\ntime to update their certificates to meet the new RSA key usage requirements.\r\n\r\nConnections that fail this check will fail with the error\r\nERR_SSL_KEY_USAGE_INCOMPATIBLE. Sites that fail with this error likely have a\r\nmisconfigured certificate. Modern ECDHE_RSA cipher suites use the\r\n\"digitalSignature\" key usage option, while legacy RSA decryption cipher suites\r\nuse the \"keyEncipherment\" key usage option. If uncertain, administrators should\r\ninclude both in RSA certificates meant for HTTPS.","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_rsakeyusageforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_rsakeyusageforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowdeletingbrowserhistory","displayName":"Enable deleting browser and download history (User)","description":"Enables deleting browser history and download history and prevents users from changing this setting.\r\n\r\nNote that even with this policy is disabled, the browsing and download history aren't guaranteed to be retained: users can edit or delete the history database files directly, and the browser itself may remove (based on expiration period) or archive any or all history items at any time.\r\n\r\nIf you enable this policy or don't configure it, users can delete the browsing and download history.\r\n\r\nIf you disable this policy, users can't delete browsing and download history.\r\n\r\nIf you enable this policy, don't enable the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) policy, because they both deal with deleting data. If you enable both, the 'ClearBrowsingDataOnExit' policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how this policy is configured.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowdeletingbrowserhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowdeletingbrowserhistory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowfileselectiondialogs","displayName":"Allow file selection dialogs (User)","description":"Allow access to local files by letting Microsoft Edge display file selection dialogs.\r\n\r\nIf you enable or don't configure this policy, users can open file selection dialogs as normal.\r\n\r\nIf you disable this policy, whenever the user performs an action that triggers a file selection dialog (like importing favorites, uploading files, or saving links), a message is displayed instead, and the user is assumed to have clicked Cancel on the file selection dialog.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowfileselectiondialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowfileselectiondialogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowsocketpoolsizerandomizationforproxies","displayName":"Allow socket pool size randomization for proxies (User)","description":"Controls whether Microsoft Edge randomizes socket pool sizes for proxy connections.\n\nSocket pool size randomization is a security mechanism that helps prevent attackers from using deterministic connection limits to infer cross-site information. For example, if the configured proxy socket pool limit is 128, Microsoft Edge can randomly set the effective limit between 128 and 256. This can allow up to twice as many proxy connections, though the expected increase is closer to 1.2x in practice.\n\nThis policy affects the limits configured by the 'MaxConnectionsPerProxy' (Maximum number of concurrent connections to the proxy server for non-WebSocket requests) and 'MaxConnectionsPerProxyForWebSocket' (Maximum number of concurrent connections to the proxy server for WebSocket requests) policies. When this policy is enabled, the effective upper limit can be randomized up to 2x the values configured by those policies.\n\nIf you enable this policy or don't configure it, Microsoft Edge enables socket pool size randomization for proxy connections.\n\nIf you disable this policy, Microsoft Edge disables socket pool size randomization for proxy connections. The values configured by 'MaxConnectionsPerProxy' and 'MaxConnectionsPerProxyForWebSocket' are used as the upper limits without randomization.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowsocketpoolsizerandomizationforproxies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowsocketpoolsizerandomizationforproxies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_alwaysopenpdfexternally","displayName":"Always open PDF files externally (User)","description":"Disables the internal PDF viewer in Microsoft Edge.\r\n\r\nIf you enable this policy Microsoft Edge treats PDF files as downloads and lets users open them with the default application.\r\n\r\nIf you don't configure this policy or disable it, Microsoft Edge will open PDF files (unless the user disables it).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_alwaysopenpdfexternally_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_alwaysopenpdfexternally_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_applicationlocalevalue","displayName":"Set application locale (User)","description":"Configures the application locale in Microsoft Edge and prevents users from changing the locale.\r\n\r\nIf you enable this policy, Microsoft Edge uses the specified locale. If the configured locale isn't supported, 'en-US' is used instead.\r\n\r\nIf you disable or don't configure this setting, Microsoft Edge uses either the user-specified preferred locale (if configured) or the fallback locale 'en-US'.\r\n\r\nExample value: en","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_applicationlocalevalue_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_applicationlocalevalue_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_applicationlocalevalue_applicationlocalevalue","displayName":"Application locale (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowed","displayName":"Allow or block audio capture (User)","description":"Allows you to set whether a user is prompted to grant a website access to their audio capture device. This policy applies to all URLs except for those configured in the 'AudioCaptureAllowedUrls' (Sites that can access audio capture devices without requesting permission) list.\r\n\r\nIf you enable this policy or don't configure it (the default setting), the user is prompted for audio capture access except from the URLs in the 'AudioCaptureAllowedUrls' list. These listed URLs are granted access without prompting.\r\n\r\nIf you disable this policy, the user is not prompted, and audio capture is accessible only to the URLs configured in 'AudioCaptureAllowedUrls'.\r\n\r\nThis policy affects all types of audio inputs, not only the built-in microphone.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls","displayName":"Sites that can access audio capture devices without requesting permission (User)","description":"Specify websites, based on URL patterns, that can use audio capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to audio capture devices. Note, however, that the pattern \"*\", which matches any URL, is not supported by this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com/\r\nhttps://[*.]contoso.edu/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls_audiocaptureallowedurlsdesc","displayName":"Sites that can access audio capture devices without requesting permission (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofilladdressenabled","displayName":"Enable AutoFill for addresses (User)","description":"Enables the AutoFill feature and allows users to auto-complete address information in web forms using previously stored information.\r\n\r\nIf you disable this policy, AutoFill never suggests or fills in address information, nor does it save additional address information that the user might submit while browsing the web.\r\n\r\nIf you enable this policy or don't configure it, users can control AutoFill for addresses in the user interface.\r\n\r\nNote that if you disable this policy you also stop all activity for all web forms, except payment and password forms. No further entries are saved, and Microsoft Edge won't suggest or AutoFill any previous entries.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofilladdressenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofilladdressenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofillcreditcardenabled","displayName":"Enable AutoFill for payment instruments (User)","description":"Enables Microsoft Edge's AutoFill feature and lets users auto complete payment instruments like credit or debit cards in web forms using previously stored information. This includes suggesting new payment instruments like Buy Now Pay Later (BNPL) in web forms and Express Checkout.\r\n\r\nIf you enable this policy or don't configure it, users can control AutoFill for payment instruments.\r\n\r\nIf you disable this policy, AutoFill never suggests, fills, or recommends new payment Instruments. Additionally, it won't save any payment instrument information that users submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofillcreditcardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofillcreditcardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun","displayName":"Automatically import another browser's data and settings at first run (User)","description":"If you enable this policy, all supported datatypes and settings from the specified browser will be silently and automatically imported at first run. During the First Run Experience, the import section will also be skipped.\r\n\r\nThe browser data from Microsoft Edge Legacy will always be silently migrated at the first run, irrespective of the value of this policy. You can use the following values for this policy:\r\n\r\n* 0 = Automatically imports all supported datatypes and settings from the default browser\r\n\r\n* 1 = Automatically imports all supported datatypes and settings from Internet Explorer\r\n\r\n* 2 = Automatically imports all supported datatypes and settings from Google Chrome\r\n\r\n* 3 = Automatically imports all supported datatypes and settings from Safari\r\n\r\n* 4 = Disables automatic import, and the import section of the first-run experience is skipped\r\n\r\n* 5 = Automatically imports all supported datatypes and settings from Mozilla Firefox\r\n\r\nIf this policy is set to the default value (0), then the datatypes corresponding to the default browser on the managed device will be imported.\r\n\r\nIf the browser specified as the value of this policy is not present in the managed device, Microsoft Edge will simply skip the import without any notification to the user.\r\n\r\nIf you set this policy to 'DisabledAutoImport' (4), the import section of the first-run experience is skipped entirely and Microsoft Edge doesn't import browser data and settings automatically.\r\n\r\nIf this policy is set to the value of Internet Explorer (1), the following datatypes will be imported from Internet Explorer:\r\n1. Favorites or bookmarks\r\n2. Saved passwords\r\n3. Search engines\r\n4. Browsing history\r\n5. Home page\r\n\r\nIf this policy is set to the value of Google Chrome (2), the following datatypes will be imported from Google Chrome:\r\n1. Favorites\r\n2. Saved passwords\r\n3. Addresses and more\r\n4. Payment info\r\n5. Browsing history\r\n6. Settings\r\n7. Pinned and Open tabs\r\n8. Extensions\r\n9. Cookies\r\n\r\nNote: For more details on what is imported from Google Chrome, please see https://go.microsoft.com/fwlink/?linkid=2120835\r\n\r\nIf this policy is set to the value of Safari (3), the following datatypes will be imported from Safari:\r\n1. Favorites or bookmarks\r\n2. Browsing history\r\n\r\nStarting with Microsoft Edge version 83, if this policy is set to the value of Mozilla Firefox (5), the following datatypes will be imported from Mozilla Firefox:\r\n1. Favorites or bookmarks\r\n2. Saved passwords\r\n3. Addresses and more\r\n4. Browsing History\r\n\r\nIf you want to restrict specific datatypes from getting imported on the managed devices, you can use this policy with other policies such as 'ImportAutofillFormData' (Allow importing of autofill form data), 'ImportBrowserSettings' (Allow importing of browser settings), 'ImportFavorites' (Allow importing of favorites), and etc.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun","displayName":"Automatically import another browser's data and settings at first run (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_0","displayName":"Automatically imports all supported datatypes and settings from the default browser","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_1","displayName":"Automatically imports all supported datatypes and settings from Internet Explorer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_2","displayName":"Automatically imports all supported datatypes and settings from Google Chrome","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_3","displayName":"Automatically imports all supported datatypes and settings from Safari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_4","displayName":"Disables automatic import, and the import section of the first-run experience is skipped","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_backgroundmodeenabled","displayName":"Continue running background apps after Microsoft Edge closes (User)","description":"Allows Microsoft Edge processes to start at OS sign-in and keep running after the last browser window is closed. In this scenario, background apps and the current browsing session remain active, including any session cookies. An open background process displays an icon in the system tray and can always be closed from there.\r\n\r\nIf you enable this policy, background mode is turned on.\r\n\r\nIf you disable this policy, background mode is turned off.\r\n\r\nIf you don't configure this policy, background mode is initially turned off, and the user can configure its behavior in edge://settings/system.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_backgroundmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_backgroundmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies","displayName":"Block third party cookies (User)","description":"Block web page elements that aren't from the domain that's in the address bar from setting cookies.\r\n\r\nIf you enable this policy, web page elements that are not from the domain that is in the address bar can't set cookies\r\n\r\nIf you disable this policy, web page elements from domains other than in the address bar can set cookies.\r\n\r\nIf you don't configure this policy, third-party cookies are enabled but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browseraddprofileenabled","displayName":"Enable profile creation from the Identity flyout menu or the Settings page (User)","description":"Allows users to create new profiles, using the **Add profile** option.\r\nIf you enable this policy or don't configure it, Microsoft Edge allows users to use **Add profile** on the Identity flyout menu or the Settings page to create new profiles.\r\n\r\nIf you disable this policy, users cannot add new profiles from the Identity flyout menu or the Settings page.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browseraddprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browseraddprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browserguestmodeenabled","displayName":"Enable guest mode (User)","description":"Enable the option to allow the use of guest profiles in Microsoft Edge. In a guest profile, the browser doesn't import browsing data from existing profiles, and it deletes browsing data when all guest profiles are closed.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge lets users browse in guest profiles.\r\n\r\nIf you disable this policy, Microsoft Edge doesn't let users browse in guest profiles.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browserguestmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browserguestmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsernetworktimequeriesenabled","displayName":"Allow queries to a Browser Network Time service (User)","description":"Prevents Microsoft Edge from occasionally sending queries to a browser network time service to retrieve an accurate timestamp.\r\n\r\nIf you disable this policy, Microsoft Edge will stop sending queries to a browser network time service.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will occasionally send queries to a browser network time service.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsernetworktimequeriesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsernetworktimequeriesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin","displayName":"Browser sign-in settings (User)","description":"Specify whether a user can sign into Microsoft Edge with their account and use account-related services like sync and single sign on. To control the availability of sync, use the 'SyncDisabled' (Disable synchronization of data using Microsoft sync services) policy instead.\r\n\r\nIf you set this policy to 'Disable browser sign-in', make sure that you also set the 'NonRemovableProfileEnabled' (Configure whether a user always has a default profile automatically signed in with their work or school account) policy to disabled because 'NonRemovableProfileEnabled' disables the creation of an automatically signed in browser profile. If both policies are set, Microsoft Edge will use the 'Disable browser sign-in' policy and behave as if 'NonRemovableProfileEnabled' is set to disabled.\r\n\r\nIf you set this policy to 'Enable browser sign-in' (1), users can sign into the browser. Signing into the browser doesn't mean that sync is turned on by default; the user must separately opt-in to use this feature.\r\n\r\nIf you set this policy to 'Force browser sign-in' (2) users must sign into a profile to use the browser. By default, this will allow the user to choose whether they want to sync to their account, unless sync is disabled by the domain admin or with the 'SyncDisabled' policy. The default value of 'BrowserGuestModeEnabled' (Enable guest mode) policy is set to false.\r\n\r\nIf you don't configure this policy users can decide if they want to enable the browser sign-in option and use it as they see fit.\r\n\r\n* 0 = Disable browser sign-in\r\n\r\n* 1 = Enable browser sign-in\r\n\r\n* 2 = Force users to sign-in to use the browser","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin_browsersignin","displayName":"Browser sign-in settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin_browsersignin_0","displayName":"Disable browser sign-in","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin_browsersignin_1","displayName":"Enable browser sign-in","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin_browsersignin_2","displayName":"Force users to sign-in to use the browser","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled","displayName":"Use built-in DNS client (User)","description":"Controls whether to use the built-in DNS client.\r\n\r\nThis does not affect which DNS servers are used; just the software stack which is used to communicate with them. For example if the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It is however possible that the built-in DNS client will address servers in different ways by using more modern DNS-related protocols such as DNS-over-TLS.\r\n\r\nIf you enable this policy, the built-in DNS client is used, if it's available.\r\n\r\nIf you disable this policy, the client is never used.\r\n\r\nIf you don't configure this policy, the built-in DNS client is enabled by default on MacOS, and users can change whether to use the built-in DNS client by editing edge://flags or by specifying a command-line flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes (User)","description":"Disables enforcement of Certificate Transparency requirements for a list of subjectPublicKeyInfo hashes.\r\n\r\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This allows certificates that would otherwise be untrusted because they were not properly publicly disclosed to still be used for Enterprise hosts.\r\n\r\nTo disable Certificate Transparency enforcement when this policy is set, one of the following sets of conditions must be met:\r\n1. The hash is of the server certificate's subjectPublicKeyInfo.\r\n2. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, that CA certificate is constrained via the X.509v3 nameConstraints extension, one or more directoryName nameConstraints are present in the permittedSubtrees, and the directoryName contains an organizationName attribute.\r\n3. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, the CA certificate has one or more organizationName attributes in the certificate Subject, and the server's certificate contains the same number of organizationName attributes, in the same order, and with byte-for-byte identical values.\r\n\r\nA subjectPublicKeyInfo hash is specified by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\r\n\r\nIf you disable this policy or don't configure it, any certificate that's required to be disclosed via Certificate Transparency will be treated as untrusted if it's not disclosed according to the Certificate Transparency policy.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas_certificatetransparencyenforcementdisabledforcasdesc","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforlegacycas","displayName":"Disable Certificate Transparency enforcement for a list of legacy certificate authorities (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 131.\r\n\r\nDisables enforcing Certificate Transparency requirements for a list of legacy certificate authorities (Cas).\r\n\r\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This allows certificates that would otherwise be untrusted because they were not properly publicly disclosed, continue to be used for enterprise hosts.\r\n\r\nIn order for Certificate Transparency enforcement to be disabled, you must set the hash to a subjectPublicKeyInfo appearing in a CA certificate that is recognized as a legacy certificate authority (CA). A legacy CA is a CA that has been publicly trusted by default by one or more operating systems supported by Microsoft Edge.\r\n\r\nYou specify a subjectPublicKeyInfo hash by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\r\n\r\nIf you don't configure this policy, any certificate that's required to be disclosed via Certificate Transparency will be treated as untrusted if it isn't disclosed according to the Certificate Transparency policy.\r\n\r\nThis policy is obsolete because the feature to disable Certificate Transparency enforcement for legacy certificates has been removed.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforlegacycas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforlegacycas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforlegacycas_certificatetransparencyenforcementdisabledforlegacycasdesc","displayName":"Disable Certificate Transparency enforcement for a list of legacy certificate authorities (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforurls","displayName":"Disable Certificate Transparency enforcement for specific URLs (User)","description":"Disables enforcing Certificate Transparency requirements for the listed URLs.\r\n\r\nThis policy lets you not disclose certificates for the hostnames in the specified URLs via Certificate Transparency. This lets you use certificates that would otherwise be untrusted, because they weren't properly publicly disclosed, but it makes it harder to detect mis-issued certificates for those hosts.\r\n\r\nForm your URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322. Because certificates are valid for a given hostname, independent of the scheme, port, or path, only the hostname part of the URL is considered. Wildcard hosts are not supported.\r\n\r\nIf you don't configure this policy, any certificate that should be disclosed via Certificate Transparency is treated as untrusted if it's not disclosed.\r\n\r\nExample value:\r\n\r\ncontoso.com\r\n.contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforurls_certificatetransparencyenforcementdisabledforurlsdesc","displayName":"Disable Certificate Transparency enforcement for specific URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_componentupdatesenabled","displayName":"Enable component updates in Microsoft Edge (User)","description":"If you enable or don't configure this policy, component updates are enabled in Microsoft Edge.\r\n\r\nIf you disable this policy or set it to false, component updates are disabled for all components in Microsoft Edge.\r\n\r\nHowever, some components are exempt from this policy. This includes any component that doesn't contain executable code, that doesn't significantly alter the behavior of the browser, or that's critical for security. That is, updates that are deemed \"critical for security\" are still applied even if you disable this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_componentupdatesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_componentupdatesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_configuredonottrack","displayName":"Configure Do Not Track (User)","description":"Specify whether to send Do Not Track requests to websites that ask for tracking info. Do Not Track requests let the websites you visit know that you don't want your browsing activity to be tracked. By default, Microsoft Edge doesn't send Do Not Track requests, but users can turn on this feature to send them.\r\n\r\nIf you enable this policy, Do Not Track requests are always sent to websites asking for tracking info.\r\n\r\nIf you disable this policy, requests are never sent.\r\n\r\nIf you don't configure this policy, users can choose whether to send these requests.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_configuredonottrack_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_configuredonottrack_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_configureonlinetexttospeech","displayName":"Configure Online Text To Speech (User)","description":"Set whether the browser can leverage Online Text to Speech voice fonts, part of Azure Cognitive Services. These voice fonts are higher quality than the pre-installed system voice fonts.\r\n\r\nIf you enable or don't configure this policy, web-based applications that use the SpeechSynthesis API can use Online Text to Speech voice fonts.\r\n\r\nIf you disable this policy, the voice fonts aren't available.\r\n\r\nRead more about this feature here:\r\nSpeechSynthesis API: https://go.microsoft.com/fwlink/?linkid=2110038\r\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2110141","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_configureonlinetexttospeech_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_configureonlinetexttospeech_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_copilotaddressbarsuggestionsenabled","displayName":"Enable Copilot address bar suggestions (User)","description":"This policy controls whether Copilot chat suggestions appear in the address bar of Microsoft Edge.\n\nIf you enable this policy or don't configure it, Copilot chat suggestions appear in the address bar.\n\nIf you disable this policy, Copilot chat suggestions don't appear in the address bar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_copilotaddressbarsuggestionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_copilotaddressbarsuggestionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride","displayName":"Override for the CPU performance tier (User)","description":"This policy allows you to override the value returned by the CPU Performance API (that is, navigator.cpuPerformance).\n\nIf you enable this policy, the value of navigator.cpuPerformance is overridden with the specified value.\n\nIf you don’t configure this policy, the default performance tier calculation is used.\n\nYou can specify a value from 0 through 4.\n\nFor more information, see https://github.com/WICG/cpu-performance.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride_cpuperformancetieroverride","displayName":"Override for the CPU performance tier: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_dataurlinwebworkeropaqueoriginenabled","displayName":"Enable opaque origins for data URLs in Web Workers (User)","description":"This policy controls whether Web Workers created from data URLs are assigned\na unique opaque origin.\n\nWeb Workers can be created using a data URL that contains the worker script.\nPreviously, these workers inherited the origin of the page that created them,\nwhich allowed them to access the same origin-bound data, such as local\nstorage and cookies.\n\nStarting in Microsoft Edge version\n149, Web Workers created from data URLs are assigned a unique opaque origin\nby default. This behavior improves security and aligns with the HTML\nspecification by isolating these workers from the page that created them.\n\nIf you enable this policy or don't configure it, Web Workers created from\ndata URLs are assigned a unique opaque origin.\n\nIf you disable this policy, Web Workers created from data URLs inherit the\norigin of the page that created them. Use this setting only as a temporary\nmitigation for compatibility issues with internal applications that depend\non the legacy behavior.\n\nThis policy is temporary and will be removed in Microsoft Edge\nversion 157.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_dataurlinwebworkeropaqueoriginenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_dataurlinwebworkeropaqueoriginenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability","displayName":"Control where developer tools can be used (User)","description":"Control where developer tools can be used.\r\n\r\nIf you set this policy to 'DeveloperToolsDisallowedForForceInstalledExtensions' (0, the default), users can access the developer tools and the JavaScript console in general, but not in the context of extensions installed by enterprise policy.\r\n\r\nIf you set this policy to 'DeveloperToolsAllowed' (1), users can access the developer tools and the JavaScript console in all contexts, including extensions installed by enterprise policy.\r\n\r\nIf you set this policy to 'DeveloperToolsDisallowed' (2), users can't access the developer tools or inspect website elements. Keyboard shortcuts and menu or context menu entries that open the developer tools or the JavaScript Console are disabled.\r\n\r\n* 0 = Block the developer tools on extensions installed by enterprise policy, allow in other contexts\r\n\r\n* 1 = Allow using the developer tools\r\n\r\n* 2 = Don't allow using the developer tools","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability","displayName":"Control where developer tools can be used (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability_0","displayName":"Block the developer tools on extensions installed by enterprise policy, allow in other contexts","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability_1","displayName":"Allow using the developer tools","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability_2","displayName":"Don't allow using the developer tools","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disable3dapis","displayName":"Disable support for 3D graphics APIs (User)","description":"Prevent web pages from accessing the graphics processing unit (GPU). Specifically, web pages can't access the WebGL API and plug-ins can't use the Pepper 3D API.\r\n\r\nIf you don't configure or disable this policy, it potentially allows web pages to use the WebGL API and plug-ins to use the Pepper 3D API. Microsoft Edge might, by default, still require command line arguments to be passed in order to use these APIs.\r\n\r\nIf 'HardwareAccelerationModeEnabled' (Use hardware acceleration when available) policy is set to false, the setting for 'Disable3DAPIs' policy is ignored - it's the equivalent of setting 'Disable3DAPIs' policy to true.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disable3dapis_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disable3dapis_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disablescreenshots","displayName":"Disable taking screenshots (User)","description":"Controls if users can take screenshots of the browser page.\r\n\r\nIf enabled, user can't take screenshots by using keyboard shortcuts or extension APIs.\r\n\r\nIf disabled or don't configure this policy, users can take screenshots.\r\n\r\nPlease note this policy controls screenshots taken from within the browser itself. Even if you enable this policy, users might still be able to take screenshots using some method outside of the browser (like using an operating system feature or another application).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disablescreenshots_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disablescreenshots_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir","displayName":"Set disk cache directory (User)","description":"Configures the directory to use to store cached files.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified the '--disk-cache-dir' flag. To avoid data loss or other unexpected errors, don't configure this policy to a volume's root directory or to a directory used for other purposes, because Microsoft Edge manages its contents.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables you can use when specifying directories and paths.\r\n\r\nIf you don't configure this policy, the default cache directory is used, and users can override that default with the '--disk-cache-dir' command line flag.\r\n\r\nExample value: ${user_home}/Edge_cache","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir_diskcachedir","displayName":"Set disk cache directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize","displayName":"Set disk cache size, in bytes (User)","description":"Configures the size of the cache, in bytes, used to store files on the disk.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided cache size regardless of whether the user has specified the '--disk-cache-size' flag. The value specified in this policy isn't a hard boundary but rather a suggestion to the caching system; any value below a few megabytes is too small and will be rounded up to a reasonable minimum.\r\n\r\nIf you set the value of this policy to 0, the default cache size is used, and users can't change it.\r\n\r\nIf you don't configure this policy, the default size is used, but users can override it with the '--disk-cache-size' flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize_diskcachesize","displayName":"Set disk cache size: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory","displayName":"Set download directory (User)","description":"Configures the directory to use when downloading files.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified one or chosen to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\r\n\r\nIf you disable or don't configure this policy, the default download directory is used, and the user can change it.\r\n\r\nIf you set an invalid path, Microsoft Edge will default to the user's default download directory.\r\n\r\nIf the folder specified by the path doesn't exist, the download will trigger a prompt that asks the user where they want to save their download.\r\n\r\nExample value: \r\n Linux-based OSes (including Mac): /home/${user_name}/Downloads\r\n Windows: C:\\Users\\${user_name}\\Downloads","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory_downloaddirectory","displayName":"Set download directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions","displayName":"Allow download restrictions (User)","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'Block dangerous downloads' (1) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings.\r\n\r\nSet 'Block potentially dangerous downloads' (2) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous downloads.\r\n\r\nSet 'Block all downloads' (3) to block all downloads.\r\n\r\nIf you don't configure this policy or set the 'No special restrictions' (0) option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\n* 0 = No special restrictions\r\n\r\n* 1 = Block dangerous downloads\r\n\r\n* 2 = Block potentially dangerous downloads\r\n\r\n* 3 = Block all downloads","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions","displayName":"Download restrictions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_1","displayName":"Block dangerous downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_2","displayName":"Block potentially dangerous downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled","displayName":"Allows users to edit favorites (User)","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\r\n\r\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledeprecatedwebplatformfeatures","displayName":"Re-enable deprecated web platform features for a limited time (User)","description":"Specify a list of deprecated web platform features to temporarily re-enable.\r\n\r\nThis policy lets you re-enable deprecated web platform features for a limited time. Features are identified by a string tag.\r\n\r\nIf you don't configure this policy, if the list is empty, or if a feature doesn't match one of the supported string tags, all deprecated web platform features remain disabled.\r\n\r\nWhile the policy itself is supported on the above platforms, the feature it's enabling might not be available on all of those platforms. Not all deprecated Web Platform features can be re-enabled. Only those explicitly listed below can be re-enabled, and only for a limited period of time, which differs per feature. You can review the intent behind the Web Platform feature changes at https://bit.ly/blinkintents.\r\n\r\nThe general format of the string tag is [DeprecatedFeatureName]_EffectiveUntil[yyyymmdd].\r\n\r\n* \"ExampleDeprecatedFeature_EffectiveUntil20080902\" = Enable ExampleDeprecatedFeature API through 2008/09/02\r\n\r\nExample value:\r\n\r\nExampleDeprecatedFeature_EffectiveUntil20080902","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledeprecatedwebplatformfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledeprecatedwebplatformfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledeprecatedwebplatformfeatures_enabledeprecatedwebplatformfeaturesdesc","displayName":"Re-enable deprecated web platform features for a limited time (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledomainactionsdownload","displayName":"Enable Domain Actions Download from Microsoft (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nAlthough this policy is used to enable/disable download of the domain actions list, it doesn't always achieve the desired state. The Experimentation and Configuration Service, which handles the download, has its own group policy to configure what is downloaded from the service. To avoid conflicting states, this policy is being deprecated and will be obsolete in milestone 85 onward. Please use the 'ExperimentationAndConfigurationServiceControl' (Control communication with the Experimentation and Configuration Service) policy instead.\r\n\r\nIn Microsoft Edge, Domain Actions represent a series of compatibility features that help the browser work correctly on the web.\r\n\r\nMicrosoft keeps a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken due to the new User Agent string on Microsoft Edge. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\r\n\r\nWhen the browser starts up and then periodically afterwards, the browser will contact the Experimentation and Configuration Service that contains the most up to date list of compatibility actions to perform. This list is saved locally after it is first retrieved so that subsequent requests will only update the list if the server's copy has changed.\r\n\r\nIf you enable this policy, the list of Domain Actions will continue to be downloaded from the Experimentation and Configuration Service.\r\n\r\nIf you disable this policy, the list of Domain Actions will no longer be downloaded from the Experimentation and Configuration Service.\r\n\r\nIf you don't configure this policy, the list of Domain Actions will continue to be downloaded from the Experimentation and Configuration Service.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledomainactionsdownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledomainactionsdownload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enableonlinerevocationchecks","displayName":"Enable online OCSP/CRL checks (User)","description":"Online revocation checks don't provide a significant security benefit and are disabled by default.\r\n\r\nIf you enable this policy, Microsoft Edge will perform soft-fail, online OCSP/CRL checks. \"Soft fail\" means that if the revocation server can't be reached, the certificate will be considered valid.\r\n\r\nIf you disable the policy or don't configure it, Microsoft Edge won't perform online revocation checks.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enableonlinerevocationchecks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enableonlinerevocationchecks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service (User)","description":"In Microsoft Edge, the Experimentation and Configuration Service is used to deploy Experimentation and Configuration payload.\r\n\r\nExperimentation payload consists of a list of early in development features that Microsoft is enabling for testing and feedback.\r\n\r\nConfiguration payload consists of a list of settings that Microsoft wants to deploy to Microsoft Edge to optimize user experience. For example, configuration payload may specify how often Microsoft Edge sends requests to the Experimentation and Configuration Service to retrieve the newest payload.\r\n\r\nAdditionaly, configuration payload may also contain a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken due to the new User Agent string on Microsoft Edge. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\r\n\r\nIf you set this policy to \"Retrieve configurations and experiments\" mode, the full payload is downloaded from the Experimentation and Configuration Service. This includes both the experimentation and configuration payloads.\r\n\r\nIf you set this policy to \"Retrieve configurations only\" mode, only the configuration payload is delivered.\r\n\r\nIf you set this policy to \"Disable communication with the Experimentation and Configuration Service\" mode, the communication with the Experimentation and Configuration Service is stopped completely.\r\n\r\nIf you don't configure this policy, on a managed device on Stable and Beta channels the behavior is the same as the \"Retrieve configurations only\" mode.\r\n\r\nIf you don't configure this policy, on an unmanaged device the behavior is the same as the \"Retrieve configurations and experiments\" mode.\r\n\r\n* 0 = Disable communication with the Experimentation and Configuration Service\r\n\r\n* 1 = Retrieve configurations only\r\n\r\n* 2 = Retrieve configurations and experiments","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol_2","displayName":"Retrieve configurations and experiments","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol_1","displayName":"Retrieve configurations only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol_0","displayName":"Disable communication with the Experimentation and Configuration Service","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled","displayName":"Enable favorites bar (User)","description":"Enables or disables the favorites bar.\r\n\r\nIf you enable this policy, users will see the favorites bar.\r\n\r\nIf you disable this policy, users won't see the favorites bar.\r\n\r\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch","displayName":"Enforce Bing SafeSearch (User)","description":"Ensure that queries in Bing web search are done with SafeSearch set to the value specified. Users can't change this setting.\r\n\r\nIf you configure this policy to \"Off\", SafeSearch in Bing search falls back to the bing.com value.\r\n\r\nIf you configure this policy to \"Moderate\", the moderate setting is used in SafeSearch. The moderate setting filters adult videos and images but not text from search results.\r\n\r\nIf you configure this policy to \"Strict\", the strict setting in SafeSearch is used. The strict setting filters adult text, images, and videos.\r\n\r\nIf you disable this policy or don't configure it, SafeSearch in Bing search isn't enforced, and users can set the value they want on bing.com.\r\n\r\n* 0 = Don't configure search restrictions in Bing\r\n\r\n* 1 = Configure moderate search restrictions in Bing\r\n\r\n* 2 = Configure strict search restrictions in Bing","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch","displayName":"Enforce Bing SafeSearch (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch_0","displayName":"Don't configure search restrictions in Bing","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch_1","displayName":"Configure moderate search restrictions in Bing","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch_2","displayName":"Configure strict search restrictions in Bing","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceephemeralprofiles","displayName":"Enable use of ephemeral profiles (User)","description":"Controls whether user profiles are switched to ephemeral mode. An ephemeral profile is created when a session begins, is deleted when the session ends, and is associated with the user's original profile.\r\n\r\nIf you enable this policy, profiles run in ephemeral mode. This lets users work from their own devices without saving browsing data to those devices. If you enable this policy as an OS policy (by using GPO on Windows, for example), it applies to every profile on the system.\r\n\r\nIf you disable this policy or don't configure it, users get their regular profiles when they sign in to the browser.\r\n\r\nIn ephemeral mode, profile data is saved on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies, and web databases aren't saved after the browser is closed. This doesn't prevent a user from manually downloading any data to disk, or from saving pages or printing them. If the user has enabled sync, all data is preserved in their sync accounts just like with regular profiles. Users can also use InPrivate browsing in ephemeral mode unless you explicitly disable this.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceephemeralprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceephemeralprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcegooglesafesearch","displayName":"Enforce Google SafeSearch (User)","description":"Forces queries in Google Web Search to be performed with SafeSearch set to active, and prevents users from changing this setting.\r\n\r\nIf you enable this policy, SafeSearch in Google Search is always active.\r\n\r\nIf you disable this policy or don't configure it, SafeSearch in Google Search isn't enforced.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcegooglesafesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcegooglesafesearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode (User)","description":"Enforces a minimum Restricted Mode on YouTube and prevents users from picking a less restricted mode.\r\n\r\nSet to Strict (2) to enforce Strict Restricted Mode on YouTube.\r\n\r\nSet to Moderate (1) to enforce the user to only use Moderate Restricted Mode and Strict Restricted Mode on YouTube. They can't disable Restricted Mode.\r\n\r\nSet to Off (0) or don't configure this policy to not enforce Restricted Mode on YouTube. External policies such as YouTube policies might still enforce Restricted Mode.\r\n\r\n* 0 = Do not enforce Restricted Mode on YouTube\r\n\r\n* 1 = Enforce at least Moderate Restricted Mode on YouTube\r\n\r\n* 2 = Enforce Strict Restricted Mode for YouTube","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_forceyoutuberestrict_0","displayName":"Do not enforce Restricted Mode on YouTube","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_forceyoutuberestrict_1","displayName":"Enforce at least Moderate Restricted Mode on YouTube","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_forceyoutuberestrict_2","displayName":"Enforce Strict Restricted Mode for YouTube","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_fullscreenallowed","displayName":"Allow full screen mode (User)","description":"Set the availability of full screen mode - all Microsoft Edge UI is hidden and only web content is visible.\r\n\r\nIf you enable this policy or don't configure it, the user, apps, and extensions with appropriate permissions can enter full screen mode.\r\n\r\nIf you disable this policy, users, apps, and extensions can't enter full screen mode.\r\n\r\nOpening Microsoft Edge in kiosk mode using the command line is unavailable when full screen mode is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_fullscreenallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_fullscreenallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_hardwareaccelerationmodeenabled","displayName":"Use hardware acceleration when available (User)","description":"Specify to use hardware acceleration, if it's available. If you enable this policy or don't configure it, hardware acceleration is enabled unless a GPU feature is explicitly blocked.\r\n\r\nIf you disable this policy, hardware acceleration is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_hardwareaccelerationmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_hardwareaccelerationmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importautofillformdata","displayName":"Allow importing of autofill form data (User)","description":"Allows users to import autofill form data from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the option to manually import autofill data is automatically selected.\r\n\r\nIf you disable this policy, autofill form data isn't imported at first run, and users can't import it manually.\r\n\r\nIf you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge will import autofill data on first run, but users can select or clear **autofill data** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS) and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importautofillformdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importautofillformdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importfavorites","displayName":"Allow importing of favorites (User)","description":"Allows users to import favorites from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Favorites** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, favorites aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importfavorites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importfavorites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importhistory","displayName":"Allow importing of browsing history (User)","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browsing history** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browsing history data isn't imported at first run, and users can’t import this data manually.\r\n\r\nIf you don’t configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importhistory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importhomepage","displayName":"Allow importing of home page settings (User)","description":"Allows users to import their home page setting from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the option to manually import the home page setting is automatically selected.\r\n\r\nIf you disable this policy, the home page setting isn’t imported at first run, and users can’t import it manually.\r\n\r\nIf you don’t configure this policy, the home page setting is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports the home page setting on first run, but users can select or clear the **home page** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importpaymentinfo","displayName":"Allow importing of payment info (User)","description":"Allows users to import payment info from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, payment info isn’t imported at first run, and users can’t import it manually.\r\n\r\nIf you don’t configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import.\r\n\r\n**Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importpaymentinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importpaymentinfo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsavedpasswords","displayName":"Allow importing of saved passwords (User)","description":"Allows users to import saved passwords from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the option to manually import saved passwords is automatically selected.\r\n\r\nIf you disable this policy, saved passwords aren't imported on first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsavedpasswords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsavedpasswords_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsearchengine","displayName":"Allow importing of search engine settings (User)","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\r\n\r\nIf you enable, this policy, the option to import search engine settings is automatically selected.\r\n\r\nIf you disable this policy, search engine settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsearchengine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsearchengine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability","displayName":"Configure InPrivate mode availability (User)","description":"Specifies whether the user can open pages in InPrivate mode in Microsoft Edge.\r\n\r\nIf you don't configure this policy or set it to 'Enabled' (0), users can open pages in InPrivate mode.\r\n\r\nSet this policy to 'Disable' (1) to stop users from using InPrivate mode.\r\n\r\nSet this policy to 'Forced' (2) to always use InPrivate mode.\r\n\r\n* 0 = InPrivate mode available\r\n\r\n* 1 = InPrivate mode disabled\r\n\r\n* 2 = InPrivate mode forced","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_inprivatemodeavailability","displayName":"Configure InPrivate mode availability (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_inprivatemodeavailability_0","displayName":"InPrivate mode available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_inprivatemodeavailability_1","displayName":"InPrivate mode disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_inprivatemodeavailability_2","displayName":"InPrivate mode forced","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel","displayName":"Configure Internet Explorer integration (User)","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210\r\n\r\n* 0 = None\r\n\r\n* 1 = Internet Explorer mode\r\n\r\n* 2 = Internet Explorer 11","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_internetexplorerintegrationlevel","displayName":"Configure Internet Explorer integration (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_internetexplorerintegrationlevel_1","displayName":"Internet Explorer mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_internetexplorerintegrationlevel_2","displayName":"Internet Explorer 11","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins","displayName":"Enable site isolation for specific origins (User)","description":"Specify origins to run in isolation, in their own process.\r\nThis policy also isolates origins named by subdomains - for example, specifying https://contoso.com/ will cause https://foo.contoso.com/ to be isolated as part of the https://contoso.com/ site.\r\nIf the policy is enabled, each of the named origins in a comma-separated list will run in its own process.\r\nIf you disable this policy, then both the 'IsolateOrigins' and 'SitePerProcess' features are disabled. Users can still enable 'IsolateOrigins' policy manually, via command line flags.\r\nIf you don't configure the policy, the user can change this setting.\r\n\r\nExample value: https://contoso.com/,https://fabrikam.com/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins_isolateorigins","displayName":"Enable site isolation for specific origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites","displayName":"Configure favorites (User)","description":"Configures a list of managed favorites.\r\n\r\nThe policy creates a list of favorites. Each favorite contains the keys \"name\" and \"url,\" which hold the favorite's name and its target. You can configure a subfolder by defining a favorites without an \"url\" key but with an additional \"children\" key that contains a list of favorites as defined above (some of which may be folders again). Microsoft Edge amends incomplete URLs as if they were submitted via the Address Bar, for example \"microsoft.com\" becomes \"https://microsoft.com/\".\r\n\r\nThese favorites are placed in a folder that can't be modified by the user (but the user can choose to hide it from the favorites bar). By default the folder name is \"Managed favorites\" but you can change it by adding to the list of favorites a dictionary containing the key \"toplevel_name\" with the desired folder name as the value.\r\n\r\nManaged favorites are not synced to the user account and can't be modified by extensions.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"toplevel_name\": \"My managed favorites folder\"\r\n }, \r\n {\r\n \"url\": \"microsoft.com\", \r\n \"name\": \"Microsoft\"\r\n }, \r\n {\r\n \"url\": \"bing.com\", \r\n \"name\": \"Bing\"\r\n }, \r\n {\r\n \"name\": \"Microsoft Edge links\", \r\n \"children\": [\r\n {\r\n \"url\": \"www.microsoftedgeinsider.com\", \r\n \"name\": \"Microsoft Edge Insiders\"\r\n }, \r\n {\r\n \"url\": \"www.microsoft.com/windows/microsoft-edge\", \r\n \"name\": \"Microsoft Edge\"\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites_managedfavorites","displayName":"Configure favorites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines","displayName":"Manage Search Engines (User)","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine.\r\nYou do not need to specify the encoding. Starting in Microsoft Edge 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge 80.\r\n\r\nStarting in Microsoft Edge 83, you can enable search engine discovery with the allow_search_engine_discovery optional parameter. This parameter must be the first item in the list. If allow_search_engine_discovery is not specified, search engine discovery will be disabled by default.\r\n\r\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\r\n\r\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\r\n\r\nIf the 'DefaultSearchProviderSearchURL' (Default search provider search URL) policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allow_search_engine_discovery\": true\r\n }, \r\n {\r\n \"is_default\": true, \r\n \"suggest_url\": \"https://www.example1.com/qbox?query={searchTerms}\", \r\n \"search_url\": \"https://www.example1.com/search?q={searchTerms}\", \r\n \"name\": \"Example1\", \r\n \"keyword\": \"example1.com\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example2.com/qbox?query={searchTerms}\", \r\n \"image_search_url\": \"https://www.example2.com/images/detail/search?iss=sbiupload\", \r\n \"name\": \"Example2\", \r\n \"keyword\": \"example2.com\", \r\n \"image_search_post_params\": \"content={imageThumbnail},url={imageURL},sbisrc={SearchSource}\", \r\n \"search_url\": \"https://www.example2.com/search?q={searchTerms}\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example3.com/qbox?query={searchTerms}\", \r\n \"image_search_url\": \"https://www.example3.com/images/detail/search?iss=sbiupload\", \r\n \"name\": \"Example3\", \r\n \"keyword\": \"example3.com\", \r\n \"encoding\": \"UTF-8\", \r\n \"search_url\": \"https://www.example3.com/search?q={searchTerms}\"\r\n }, \r\n {\r\n \"search_url\": \"https://www.example4.com/search?q={searchTerms}\", \r\n \"name\": \"Example4\", \r\n \"keyword\": \"example4.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines_managedsearchengines","displayName":"Manage Search Engines (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_maxconnectionsperproxy","displayName":"Maximum number of concurrent connections to the proxy server (User)","description":"Specifies the maximum number of simultaneous connections to the proxy server.\r\n\r\nSome proxy servers can't handle a high number of concurrent connections per client - you can solve this by setting this policy to a lower value.\r\n\r\nThe value of this policy should be lower than 100 and higher than 6. The default value is 32.\r\n\r\nSome web apps are known to consume many connections with hanging GETs - lowering the maximum connections below 32 may lead to browser networking hangs if too many of these kind of web apps are open.\r\n\r\nIf you don't configure this policy, the default value (32) is used.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_maxconnectionsperproxy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_maxconnectionsperproxy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_maxconnectionsperproxy_maxconnectionsperproxy","displayName":"Maximum number of concurrent connections to the proxy server: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_mediaroutercastallowallips","displayName":"Allow Google Cast to connect to Cast devices on all IP addresses (User)","description":"Enable this policy to let Google Cast connect to Cast devices on all IP addresses, not just RFC1918/RFC4193 private addresses.\r\n\r\nDisable this policy to restrict Google Cast to Cast devices on RFC1918/RFC4193 private addresses.\r\n\r\nIf you don't configure this policy, Google Cast connects to Cast devices on RFC1918/RFC4193 private addresses only, unless you enable the CastAllowAllIPs feature.\r\n\r\nIf the 'EnableMediaRouter' (Enable Google Cast) policy is disabled, then this policy has no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_mediaroutercastallowallips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_mediaroutercastallowallips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_metricsreportingenabled","displayName":"Enable usage and crash-related data reporting (User)","description":"This policy enables reporting of usage and crash-related data about Microsoft Edge to Microsoft.\r\n\r\nEnable this policy to send reporting of usage and crash-related data to Microsoft. Disable this policy to not send the data to Microsoft. In both cases, users can't change or override the setting.\r\n\r\nOn Windows 10, Beta and Stable channels, if you don’t configure this policy, Microsoft Edge will default to the Windows diagnostic data setting. If you enable this policy, Microsoft Edge will only send usage data if the Windows Diagnostic data setting is set to Enhanced or Full. If you disable this policy, Microsoft Edge will not send usage data. Crash-related data is sent based on the Windows Diagnostic data setting. Learn more about Windows Diagnostic data settings at https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nOn Windows 10, Canary and Dev channels, this policy controls sending usage data. If this policy is not configured, Microsoft Edge will default to the user's preference. Crash-related data is sent based on the Windows Diagnostic data setting. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nOn Windows 7, 8, and macOS, this policy controls sending usage and crash-related data. If you don’t configure this policy, Microsoft Edge will default to the user's preference.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_metricsreportingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_metricsreportingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions","displayName":"Enable network prediction (User)","description":"Enables network prediction and prevents users from changing this setting.\r\n\r\nThis controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages.\r\n\r\nIf you don't configure this policy, network prediction is enabled but the user can change it.\r\n\r\n* 0 = Predict network actions on any network connection\r\n\r\n* 2 = Don't predict network actions on any network connection","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions","displayName":"Enable network prediction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions_2","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin","displayName":"Control where security restrictions on insecure origins apply (User)","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*.contoso.com\") for which security restrictions on insecure origins don't apply.\r\n\r\nThis policy lets you specify allowed origins for legacy applications that can't deploy TLS or set up a staging server for internal web development so that developers can test out features requiring secure contexts without having to deploy TLS on the staging server. This policy also prevents the origin from being labeled \"Not Secure\" in the omnibox.\r\n\r\nSetting a list of URLs in this policy has the same effect as setting the command-line flag '--unsafely-treat-insecure-origin-as-secure' to a comma-separated list of the same URLs. If you enable this policy, it overrides the command-line flag.\r\n\r\nFor more information on secure contexts, see https://www.w3.org/TR/secure-contexts/.\r\n\r\nExample value:\r\n\r\nhttp://testserver.contoso.com/\r\n*.contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin_overridesecurityrestrictionsoninsecureorigindesc","displayName":"Control where security restrictions on insecure origins apply (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_proactiveauthenabled","displayName":"Enable Proactive Authentication (User)","description":"Lets you configure whether to turn on Proactive Authentication.\r\n\r\nIf you enable this policy, Microsoft Edge tries to proactively authenticate the signed-in user with Microsoft services. At regular intervals, Microsoft Edge checks with an online service for an updated manifest that contains the configuration that governs how to do this.\r\n\r\nIf you disable this policy, Microsoft Edge doesn't try to proactively authenticate the signed-in user with Microsoft services. Microsoft Edge no longer checks with an online service for an updated manifest that contains the configuration for doing this.\r\n\r\nIf you don't configure this policy, Proactive Authentication is turned on.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_proactiveauthenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_proactiveauthenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_promotionaltabsenabled","displayName":"Enable full-tab promotional content (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nControl the presentation of full-tab promotional or educational content. This setting controls the presentation of welcome pages that help users sign into Microsoft Edge, choose their default browser, or learn about product features.\r\n\r\nIf you enable this policy (set it true) or don't configure it, Microsoft Edge can show full-tab content to users to provide product information.\r\n\r\nIf you disable (set to false) this policy, Microsoft Edge can't show full-tab content to users.\r\n\r\nThis is deprecated - use ShowRecommendationsEnabled instead.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_promotionaltabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_promotionaltabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_promptfordownloadlocation","displayName":"Ask where to save downloaded files (User)","description":"Set whether to ask where to save a file before downloading it.\r\n\r\nIf you enable this policy, the user is asked where to save each file before downloading; if you don't configure it, files are saved automatically to the default location, without asking the user.\r\n\r\nIf you don't configure this policy, the user will be able to change this setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_promptfordownloadlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_promptfordownloadlocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_quicallowed","displayName":"Allow QUIC protocol (User)","description":"Allows use of the QUIC protocol in Microsoft Edge.\r\n\r\nIf you enable this policy or don't configure it, the QUIC protocol is allowed.\r\n\r\nIf you disable this policy, the QUIC protocol is blocked.\r\n\r\nQUIC is a transport layer network protocol that can improve performance of web applications that currently use TCP.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_quicallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_quicallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended","displayName":"Set application locale (User)","description":"Configures the application locale in Microsoft Edge and prevents users from changing the locale.\r\n\r\nIf you enable this policy, Microsoft Edge uses the specified locale. If the configured locale isn't supported, 'en-US' is used instead.\r\n\r\nIf you disable or don't configure this setting, Microsoft Edge uses either the user-specified preferred locale (if configured) or the fallback locale 'en-US'.\r\n\r\nExample value: en","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended_applicationlocalevalue","displayName":"Application locale (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_autofilladdressenabled_recommended","displayName":"Enable AutoFill for addresses (User)","description":"Enables the AutoFill feature and allows users to auto-complete address information in web forms using previously stored information.\r\n\r\nIf you disable this policy, AutoFill never suggests or fills in address information, nor does it save additional address information that the user might submit while browsing the web.\r\n\r\nIf you enable this policy or don't configure it, users can control AutoFill for addresses in the user interface.\r\n\r\nNote that if you disable this policy you also stop all activity for all web forms, except payment and password forms. No further entries are saved, and Microsoft Edge won't suggest or AutoFill any previous entries.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_autofilladdressenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_autofilladdressenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_autofillcreditcardenabled_recommended","displayName":"Enable AutoFill for credit cards (User)","description":"Enables Microsoft Edge's AutoFill feature and lets users auto complete credit card information in web forms using previously stored information.\r\n\r\nIf you disable this policy, AutoFill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.\r\n\r\nIf you enable this policy or don't configure it, users can control AutoFill for credit cards.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_autofillcreditcardenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_autofillcreditcardenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_backgroundmodeenabled_recommended","displayName":"Continue running background apps after Microsoft Edge closes (User)","description":"Allows Microsoft Edge processes to start at OS sign-in and keep running after the last browser window is closed. In this scenario, background apps and the current browsing session remain active, including any session cookies. An open background process displays an icon in the system tray and can always be closed from there.\r\n\r\nIf you enable this policy, background mode is turned on.\r\n\r\nIf you disable this policy, background mode is turned off.\r\n\r\nIf you don't configure this policy, background mode is initially turned off, and the user can configure its behavior in edge://settings/system.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_backgroundmodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_backgroundmodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_blockthirdpartycookies_recommended","displayName":"Block third party cookies (User)","description":"Block web page elements that aren't from the domain that's in the address bar from setting cookies.\r\n\r\nIf you enable this policy, web page elements that are not from the domain that is in the address bar can't set cookies\r\n\r\nIf you disable this policy, web page elements from domains other than in the address bar can set cookies.\r\n\r\nIf you don't configure this policy, third-party cookies are enabled but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_blockthirdpartycookies_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_blockthirdpartycookies_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloaddirectory_recommended","displayName":"Set download directory (User)","description":"Configures the directory to use when downloading files.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified one or chosen to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\r\n\r\nIf you disable or don't configure this policy, the default download directory is used, and the user can change it.\r\n\r\nIf you set an invalid path, Microsoft Edge will default to the user's default download directory.\r\n\r\nIf the folder specified by the path doesn't exist, the download will trigger a prompt that asks the user where they want to save their download.\r\n\r\nExample value: \r\n Linux-based OSes (including Mac): /home/${user_name}/Downloads\r\n Windows: C:\\Users\\${user_name}\\Downloads","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloaddirectory_recommended_downloaddirectory","displayName":"Set download directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended","displayName":"Allow download restrictions (User)","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'Block dangerous downloads' (1) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings.\r\n\r\nSet 'Block potentially dangerous downloads' (2) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous downloads.\r\n\r\nSet 'Block all downloads' (3) to block all downloads.\r\n\r\nIf you don't configure this policy or set the 'No special restrictions' (0) option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\n* 0 = No special restrictions\r\n\r\n* 1 = Block dangerous downloads\r\n\r\n* 2 = Block potentially dangerous downloads\r\n\r\n* 3 = Block all downloads","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions","displayName":"Download restrictions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_1","displayName":"Block dangerous downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_2","displayName":"Block potentially dangerous downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_favoritesbarenabled_recommended","displayName":"Enable favorites bar (User)","description":"Enables or disables the favorites bar.\r\n\r\nIf you enable this policy, users will see the favorites bar.\r\n\r\nIf you disable this policy, users won't see the favorites bar.\r\n\r\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_favoritesbarenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_favoritesbarenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importautofillformdata_recommended","displayName":"Allow importing of autofill form data (User)","description":"Allows users to import autofill form data from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the option to manually import autofill data is automatically selected.\r\n\r\nIf you disable this policy, autofill form data isn't imported at first run, and users can't import it manually.\r\n\r\nIf you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge will import autofill data on first run, but users can select or clear **autofill data** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS) and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importautofillformdata_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importautofillformdata_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended","displayName":"Allow importing of favorites (User)","description":"Allows users to import favorites from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Favorites** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, favorites aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importhistory_recommended","displayName":"Allow importing of browsing history (User)","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browsing history** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browsing history data isn't imported at first run, and users can’t import this data manually.\r\n\r\nIf you don’t configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importhistory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importhistory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importpaymentinfo_recommended","displayName":"Allow importing of payment info (User)","description":"Allows users to import payment info from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, payment info isn’t imported at first run, and users can’t import it manually.\r\n\r\nIf you don’t configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import.\r\n\r\n**Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importpaymentinfo_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importpaymentinfo_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsavedpasswords_recommended","displayName":"Allow importing of saved passwords (User)","description":"Allows users to import saved passwords from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the option to manually import saved passwords is automatically selected.\r\n\r\nIf you disable this policy, saved passwords aren't imported on first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsavedpasswords_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsavedpasswords_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsearchengine_recommended","displayName":"Allow importing of search engine settings (User)","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\r\n\r\nIf you enable, this policy, the option to import search engine settings is automatically selected.\r\n\r\nIf you disable this policy, search engine settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsearchengine_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsearchengine_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended","displayName":"Enable network prediction (User)","description":"Enables network prediction and prevents users from changing this setting.\r\n\r\nThis controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages.\r\n\r\nIf you don't configure this policy, network prediction is enabled but the user can change it.\r\n\r\n* 0 = Predict network actions on any network connection\r\n\r\n* 2 = Don't predict network actions on any network connection","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended_networkpredictionoptions","displayName":"Enable network prediction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended_networkpredictionoptions_2","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_resolvenavigationerrorsusewebservice_recommended","displayName":"Enable resolution of navigation errors using a web service (User)","description":"Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi.\r\n\r\nIf you enable this policy, a web service is used for network connectivity tests.\r\n\r\nIf you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues.\r\n\r\n**Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_resolvenavigationerrorsusewebservice_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_resolvenavigationerrorsusewebservice_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_searchsuggestenabled_recommended","displayName":"Enable search suggestions (User)","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\r\n\r\nIf you enable this policy, web search suggestions are used.\r\n\r\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\r\n\r\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_searchsuggestenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_searchsuggestenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended","displayName":"Disable synchronization of data using Microsoft sync services (User)","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\r\n\r\nIf you don't set this policy or apply it as recommended, users will be able to turn sync on or off. If you apply this policy as mandatory, users will not be able to turn sync on.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_translateenabled_recommended","displayName":"Enable Translate (User)","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\r\n\r\nIf you enable this policy, Microsoft Edge offers translation functionality to the user by showing an integrated translate flyout when appropriate, and a translate option on the right-click context menu.\r\n\r\nDisable this policy to disable all built-in translate features.\r\n\r\nIf you don't configure the policy, users can choose whether to use the translation functionality or not.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_translateenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_translateenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended","displayName":"Register protocol handlers (User)","description":"Register a list of protocol handlers. Set the protocol property to the scheme (like 'mailto') and the url property to the URL pattern of the application that handles the scheme. The pattern can include a '%s', which will be replaced by the handled URL.\r\n\r\nYou can recommend a specific value for this policy, but you can't require that your users use it.\r\n\r\nThe protocol handlers registered by policy are merged with any handlers registered by the user, and both are available for use. The user can override the protocol handlers installed by policy by installing a new default handler, but they can't remove a protocol handler registered by policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://mail.contoso.com/mail/?extsrc=mailto&url=%s\", \r\n \"default\": true, \r\n \"protocol\": \"mailto\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"0d4cf1d9-d8ad-4628-bd71-fa0de6598f28","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_registeredprotocolhandlers","displayName":"Register protocol handlers (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0d4cf1d9-d8ad-4628-bd71-fa0de6598f28","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmanagerenabled_recommended","displayName":"Enable saving passwords to the password manager (User)","description":"Enable Microsoft Edge to save user passwords.\r\n\r\nIf you enable this policy, users can save their passwords in Microsoft Edge. The next time they visit the site, Microsoft Edge will enter the password automatically.\r\n\r\nIf you disable this policy, users can't save new passwords, but they can still use previously saved passwords.\r\n\r\nIf you enable or disable this policy, users can't change or override it in Microsoft Edge. If you don't configure it, users can save passwords, as well as turn this feature off.","helpText":"","infoUrls":[],"categoryId":"a877a2ff-f144-421f-814c-593e972a8a20","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmanagerenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmanagerenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printheaderfooter_recommended","displayName":"Print headers and footers (User)","description":"Force 'headers and footers' to be on or off in the printing dialog.\r\n\r\nIf you don't configure this policy, users can decide whether to print headers and footers.\r\n\r\nIf you disable this policy, users can't print headers and footers.\r\n\r\nIf you enable this policy, users always print headers and footers.","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printheaderfooter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printheaderfooter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended","displayName":"Set the system default printer as the default printer (User)","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\r\n\r\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\r\n\r\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenenabled_recommended","displayName":"Configure Microsoft Defender SmartScreen (User)","description":"This policy setting lets you configure whether to turn on Microsoft Defender SmartScreen. Microsoft Defender SmartScreen provides warning messages to help protect your users from potential phishing scams and malicious software. By default, Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you enable this setting, Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepageisnewtabpage_recommended","displayName":"Set the new tab page as the home page (User)","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\r\n\r\nIf you enable this policy, the new tab page is always used for the home page, and the home page URL location is ignored.\r\n\r\nIf you disable this policy, the user's home page can't be the new tab page, unless the URL is set to 'edge://newtab'.\r\n\r\nIf not configured users can choose whether the new tab page is their home page.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepageisnewtabpage_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepageisnewtabpage_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepagelocation_recommended","displayName":"Configure the home page URL (User)","description":"Configures the default home page URL in Microsoft Edge.\r\n\r\nThe home page is the page opened by the Home button. The pages that open on startup are controlled by the 'RestoreOnStartup' (Action to take on startup) policies.\r\n\r\nYou can either set a URL here or set the home page to open the new tab page. If you select to open the new tab page, then this policy doesn't take effect.\r\n\r\nIf you enable this policy, users can't change their home page URL, but they can choose to use the new tab page as their home page.\r\n\r\nIf you disable or don't configure this policy, users can choose their own home page, as long as the 'HomepageIsNewTabPage' (Set the new tab page as the home page) policy isn't enabled.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\nExample value: https://www.contoso.com","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepagelocation_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepagelocation_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepagelocation_recommended_homepagelocation","displayName":"Home page URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended","displayName":"Configure the new tab page URL (User)","description":"Configures the default URL for the new tab page.\r\n\r\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\r\n\r\nThis policy doesn't determine which page opens on startup; that's controlled by the 'RestoreOnStartup' (Action to take on startup) policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\r\n\r\nIf you don't configure this policy, the default new tab page is used.\r\n\r\nIf you configure this policy *and* the 'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) policy, this policy has precedence.\r\n\r\nIf an invalid URL is provided, new tabs will open about://blank.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_newtabpagelocation","displayName":"New tab page URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'Open new tab' (5).\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'Restore the last session' (1). The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'Open a list of URLs' (4).\r\n\r\nDisabling this setting is equivalent to leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\n* 1 = Restore the last session\r\n\r\n* 4 = Open a list of URLs\r\n\r\n* 5 = Open a new tab","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup","displayName":"Action to take on startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartupurls_recommended","displayName":"Sites to open when the browser starts (User)","description":"Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup.\r\n\r\nThis policy only works if you also set the 'RestoreOnStartup' (Action to take on startup) policy to 'Open a list of URLs' (4).\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com\r\nhttps://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartupurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartupurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartupurls_recommended_restoreonstartupurlsdesc","displayName":"Sites to open when the browser starts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_showhomebutton_recommended","displayName":"Show Home button on toolbar (User)","description":"Shows the Home button on Microsoft Edge's toolbar.\r\n\r\nEnable this policy to always show the Home button. Disable it to never show the button.\r\n\r\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_showhomebutton_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_showhomebutton_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification","displayName":"Notify a user that a browser restart is recommended or required for pending updates (User)","description":"Notify users that they need to restart Microsoft Edge to apply a pending update.\r\n\r\nIf you don't configure this policy, Microsoft Edge adds a recycle icon at the far right of the top menu bar to prompt users to restart the browser to apply the update.\r\n\r\nIf you enable this policy and set it to 'Recommended' (1), a recurring warning prompts users that a restart is recommended. Users can dismiss this warning and defer the restart.\r\n\r\nIf you set the policy to 'Required' (2), a recurring warning prompts users that the browser will be restarted automatically as soon as a notification period passes. The default period is seven days. You can configure this period with the 'RelaunchNotificationPeriod' (Set the time period for update notifications) policy.\r\n\r\nThe user's session is restored when the browser restarts.\r\n\r\n* 1 = Recommended - Show a recurring prompt to the user indicating that a restart is recommended\r\n\r\n* 2 = Required - Show a recurring prompt to the user indicating that a restart is required","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_relaunchnotification","displayName":"Notify a user that a browser restart is recommended or required for pending updates (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_relaunchnotification_1","displayName":"Recommended - Show a recurring prompt to the user indicating that a restart is recommended","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_relaunchnotification_2","displayName":"Required - Show a recurring prompt to the user indicating that a restart is required","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod","displayName":"Set the time period for update notifications (User)","description":"Allows you to set the time period, in milliseconds, over which users are notified that Microsoft Edge must be relaunched or that a Microsoft Edge OS device must be restarted to apply a pending update.\r\n\r\nOver this time period, the user will be repeatedly informed of the need for an update. For Microsoft Edge OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Microsoft Edge browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the 'RelaunchNotification' (Notify a user that a browser restart is recommended or required for pending updates) policy follow this same schedule.\r\n\r\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_relaunchnotificationperiod","displayName":"Set the time period for update notifications: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_requireonlinerevocationchecksforlocalanchors","displayName":"Specify if online OCSP/CRL checks are required for local trust anchors (User)","description":"Control whether online revocation checks (OCSP/CRL checks) are required. If Microsoft Edge can't get revocation status information, these certificates are treated as revoked (\"hard-fail\").\r\n\r\nIf you enable this policy, Microsoft Edge always performs revocation checking for server certificates that successfully validate and are signed by locally-installed CA certificates.\r\n\r\nIf you don't configure or disable this policy, then Microsoft Edge uses the existing online revocation checking settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_requireonlinerevocationchecksforlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_requireonlinerevocationchecksforlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_resolvenavigationerrorsusewebservice","displayName":"Enable resolution of navigation errors using a web service (User)","description":"Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi.\r\n\r\nIf you enable this policy, a web service is used for network connectivity tests.\r\n\r\nIf you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues.\r\n\r\n**Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_resolvenavigationerrorsusewebservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_resolvenavigationerrorsusewebservice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictbackgroundfetchfromserviceworkerenabled","displayName":"Restrict Background Fetch API when called from a Service Worker (User)","description":"This policy controls whether background fetch requests from Service Workers are restricted. If a feature that downloads files in the background is affected, this policy may be relevant.\n\nIf you enable this policy or don't configure it, the restriction is active, and background fetch requests from Service Worker contexts may be blocked.\n\nIf you disable this policy, the restriction is bypassed, allowing Service Workers to make background fetch requests.\n\nThis policy is temporary and will be removed after Microsoft Edge version 152.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictbackgroundfetchfromserviceworkerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictbackgroundfetchfromserviceworkerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictsignintopattern","displayName":"Restrict which accounts can be used to sign in to Microsoft Edge (User)","description":"Determines which accounts can be used to sign in to the Microsoft Edge account that's chosen during the Sync opt-in flow.\r\n\r\nYou can configure this policy to match multiple accounts using a Perl style regular expression for the pattern. If a user tries to sign in to the browser with an account whose username doesn't match this pattern, they are blocked and will get the appropriate error message. Note that pattern matches are case sensitive. For more information about the regular expression rules that are used, refer to https://go.microsoft.com/fwlink/p/?linkid=2133903.\r\n\r\nIf you don't configure this policy or leave it blank, users can use any account to sign in to Microsoft Edge.\r\n\r\nNote that signed-in profiles with a username that doesn't match this pattern will be signed out after this policy is enabled.\r\n\r\nExample value: .*@contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictsignintopattern_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictsignintopattern_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictsignintopattern_restrictsignintopattern","displayName":"Restrict which accounts can be used as Microsoft Edge primary accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_runallflashinallowmode","displayName":"Extend Adobe Flash content setting to all content (User)","description":"If you enable this policy, all Adobe Flash content embedded in websites that are set to allow Adobe Flash in the content settings -- either by the user or by enterprise policy -- will run. This includes content from other origins and/or small content.\r\n\r\nTo control which websites are allowed to run Adobe Flash, see the specifications in the 'DefaultPluginsSetting' (Default Adobe Flash setting), 'PluginsAllowedForUrls' (Allow the Adobe Flash plug-in on specific sites), and 'PluginsBlockedForUrls' (Block the Adobe Flash plug-in on specific sites) policies.\r\n\r\nIf you disable this policy or don't configure it, Adobe Flash content from other origins (from sites that aren't specified in the three policies mentioned immediately above) or small content might be blocked.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_runallflashinallowmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_runallflashinallowmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_savingbrowserhistorydisabled","displayName":"Disable saving browser history (User)","description":"Disables saving browser history and prevents users from changing this setting.\r\n\r\nIf you enable this policy, browsing history isn't saved. This also disables tab syncing.\r\n\r\nIf you disable this policy or don't configure it, browsing history is saved.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_savingbrowserhistorydisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_savingbrowserhistorydisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_searchsuggestenabled","displayName":"Enable search suggestions (User)","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\r\n\r\nIf you enable this policy, web search suggestions are used.\r\n\r\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\r\n\r\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_searchsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_searchsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_securitykeypermitattestation","displayName":"Websites or domains that don't need permission to use direct Security Key attestation (User)","description":"Specifies websites and domains that don't need explicit user permission when attestation certificates from security keys are requested. Additionally, a signal is sent to the security key indicating that it can use individual attestation. Without this, users are prompted each time a site requests attestation of security keys.\r\n\r\nSites (like https://contoso.com/some/path) only match as U2F appIDs. Domains (like contoso.com) only match as webauthn RP IDs. To cover both U2F and webauthn APIs for a given site, you need to list both the appID URL and domain.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_securitykeypermitattestation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_securitykeypermitattestation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_securitykeypermitattestation_securitykeypermitattestationdesc","displayName":"Websites or domains that don't need permission to use direct Security Key attestation (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer","displayName":"Send all intranet sites to Internet Explorer (User)","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices","displayName":"Send site information to improve Microsoft services (User)","description":"This policy enables sending info about websites visited in Microsoft Edge to Microsoft to improve services like search.\r\n\r\nEnable this policy to send info about websites visited in Microsoft Edge to Microsoft. Disable this policy to not send info about websites visited in Microsoft Edge to Microsoft. In both cases, users can't change or override the setting.\r\n\r\nOn Windows 10, Beta and Stable if this policy is not configured, Microsoft Edge will default to the Windows diagnostic data setting. If this policy is enabled Microsoft Edge will only send info about websites visited in Microsoft Edge if the Windows Diagnostic data setting is set to Full. If this policy is disabled Microsoft Edge will not send info about websites visited. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nOn Windows 10, Canary and Dev channels, this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.\r\n\r\nOn Windows 7, 8, and Mac this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_showofficeshortcutinfavoritesbar","displayName":"Show Microsoft Office shortcut in favorites bar (User)","description":"Specifies whether to include a shortcut to Office.com in the favorites bar. For users signed into Microsoft Edge the shortcut takes users to their Microsoft Office apps and docs.\r\n\r\nIf this policy is enabled or not configure, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu.\r\n\r\nIf the policy is disabled, the shortcut won't be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_showofficeshortcutinfavoritesbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_showofficeshortcutinfavoritesbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_siteperprocess","displayName":"Enable site isolation for every site (User)","description":"\r\nThe 'SitePerProcess' policy can be used to prevent users from opting out of the default behavior of isolating all sites. Note that you can also use the 'IsolateOrigins' (Enable site isolation for specific origins) policy to isolate additional, finer-grained origins.\r\nIf you enable this policy, users can't opt out of the default behavior where each site runs in its own process.\r\nIf you disable or don’t configure this policy, a user can opt out of site isolation. (For example, by using \"Disable site isolation\" entry in edge://flags.) Disabling the policy or not configuring the policy doesn't turn off Site Isolation.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_siteperprocess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_siteperprocess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellcheckenabled","displayName":"Enable spellcheck (User)","description":"If you enable or don't configure this policy, the user can use spellcheck.\r\n\r\nIf you disable this policy, the user can't use spellcheck and the 'SpellcheckLanguage' (Enable specific spellcheck languages) and 'SpellcheckLanguageBlocklist' (Force disable spellcheck languages) policies are also disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellchecklanguage","displayName":"Enable specific spellcheck languages (User)","description":"Enables different languages for spellcheck. Any language that you specify that isn't recognized is ignored.\r\n\r\nIf you enable this policy, spellcheck is enabled for the languages specified, as well as any languages the user has enabled.\r\n\r\nIf you don't configure or disable this policy, there's no change to the user's spellcheck preferences.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy is disabled, this policy will have no effect.\r\n\r\nIf a language is included in both the 'SpellcheckLanguage' and the 'SpellcheckLanguageBlocklist' (Force disable spellcheck languages) policy, the spellcheck language is enabled.\r\n\r\nThe supported languages are: af, bg, ca, cs, cy, da, de, el, en-AU, en-CA, en-GB, en-US, es, es-419, es-AR, es-ES, es-MX, es-US, et, fa, fo, fr, he, hi, hr, hu, id, it, ko, lt, lv, nb, nl, pl, pt-BR, pt-PT, ro, ru, sh, sk, sl, sq, sr, sv, ta, tg, tr, uk, vi.\r\n\r\nExample value:\r\n\r\nfr\r\nes","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellchecklanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellchecklanguage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellchecklanguage_spellchecklanguagedesc","displayName":"Enable specific spellcheck languages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslerroroverrideallowed","displayName":"Allow users to proceed from the HTTPS warning page (User)","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\r\n\r\nIf you enable or don't configure (default) this policy, users can click through these warning pages.\r\n\r\nIf you disable this policy, users are blocked from clicking through any warning page.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslerroroverrideallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslerroroverrideallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin","displayName":"Minimum TLS version enabled (User)","description":"Sets the minimum supported version of SSL. If you don't configure this policy, Microsoft Edge uses a default minimum version, TLS 1.0.\r\n\r\nIf you enable this policy, you can set the minimum version to one of the following values: \"tls1\", \"tls1.1\" or \"tls1.2\". When set, Microsoft Edge won't use any version of SSL/TLS lower than the specified version. Any unrecognized value is ignored.\r\n\r\n* \"tls1\" = TLS 1.0\r\n\r\n* \"tls1.1\" = TLS 1.1\r\n\r\n* \"tls1.2\" = TLS 1.2\r\n\r\nExample value: tls1","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin","displayName":"Minimum SSL version enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin_tls1","displayName":"TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin_tls1.1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_strictmimetypecheckforworkerscriptsenabled","displayName":"Enable strict MIME type checking for worker scripts (User)","description":"This policy controls whether strict MIME type checking is used for worker scripts.\n\nIf you enable or don't configure this policy, worker scripts use strict MIME type checking for JavaScript. Worker scripts that use legacy MIME types are rejected.\n\nIf you disable this policy, worker scripts use lax MIME type checking. This allows worker scripts that use legacy MIME types, such as text/ascii, to continue to load and run.\n\nBrowsers traditionally used lax MIME type checking, which allowed JavaScript resources to load with several legacy MIME types. This behavior can create security risks by allowing resources to load as scripts when they weren't intended to be used that way.\n\nMicrosoft Edge uses strict MIME type checking by default. Enabling this policy follows the default behavior. Disabling this policy lets admins temporarily retain the legacy behavior for compatibility.\n\nFor more information about JavaScript and ECMAScript media types, see https://html.spec.whatwg.org/multipage/scripting.html#scriptingLanguage.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_strictmimetypecheckforworkerscriptsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_strictmimetypecheckforworkerscriptsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_suppressunsupportedoswarning","displayName":"Suppress the unsupported OS warning (User)","description":"Suppresses the warning that appears when Microsoft Edge is running on a computer or operating system that is no longer supported.\r\n\r\nIf this policy is false or unset, the warnings will appear on such unsupported computers or operating systems.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_suppressunsupportedoswarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_suppressunsupportedoswarning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_syncdisabled","displayName":"Disable synchronization of data using Microsoft sync services (User)","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\r\n\r\nIf you don't set this policy or apply it as recommended, users will be able to turn sync on or off. If you apply this policy as mandatory, users will not be able to turn sync on.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_syncdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_syncdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled","displayName":"Configure tab lifecycles (User)","description":"The tab lifecycles feature reclaims CPU and memory associated with running tabs that haven't been used in a long time, by first throttling, then freezing, and finally discarding them.\r\n\r\nIf you disable this policy, the tab lifecycles feature is disabled, and all tabs are left running normally.\r\n\r\nIf you enable or don't configure this policy, the tab lifecycles feature is enabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_taskmanagerendprocessenabled","displayName":"Enable ending processes in the Browser task manager (User)","description":"If you enable or don't configure this policy, users can end processes in the Browser task manager. If you disable it, users can't end processes, and the End process button is disabled in the Browser task manager.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_taskmanagerendprocessenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_taskmanagerendprocessenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_translateenabled","displayName":"Enable Translate (User)","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\r\n\r\nIf you enable this policy, Microsoft Edge offers translation functionality to the user by showing an integrated translate flyout when appropriate, and a translate option on the right-click context menu.\r\n\r\nDisable this policy to disable all built-in translate features.\r\n\r\nIf you don't configure the policy, users can choose whether to use the translation functionality or not.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_translateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_translateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist","displayName":"Define a list of allowed URLs (User)","description":"Allow access to the listed URLs, as exceptions to the URL block list.\r\n\r\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nYou can use this policy to open exceptions to restrictive block lists. For example, you can include '*' in the block list to block all requests, and then use this policy to allow access to a limited list of URLs. You can use this policy to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths.\r\n\r\nThe most specific filter determines if a URL is blocked or allowed. The allowed list takes precedence over the block list.\r\n\r\nThis policy is limited to 1000 entries; subsequent entries are ignored.\r\n\r\nIf you don't configure this policy, there are no exceptions to the block list in the 'URLBlocklist' (Block access to a list of URLs) policy.\r\n\r\nExample value:\r\n\r\ncontoso.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist_urlallowlistdesc","displayName":"Define a list of allowed URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlblocklist","displayName":"Block access to a list of URLs (User)","description":"Define a list of sites, based on URL patterns, that are blocked (your users can't load them).\r\n\r\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nYou can define exceptions in the 'URLAllowlist' (Define a list of allowed URLs) policy. These policies are limited to 1000 entries; subsequent entries are ignored.\r\n\r\nNote that blocking internal 'edge://*' URLs isn't recommended - this may lead to unexpected errors.\r\n\r\nThis policy doesn't prevent the page from updating dynamically through JavaScript. For example, if you block 'contoso.com/abc', users might still be able to visit 'contoso.com' and click on a link to visit 'contoso.com/abc', as long as the page doesn't refresh.\r\n\r\nIf you don't configure this policy, no URLs are blocked.\r\n\r\nExample value:\r\n\r\ncontoso.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlblocklist_urlblocklistdesc","displayName":"Block access to a list of URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir","displayName":"Set the user data directory (User)","description":"Set the directory to use for storing user data.\r\n\r\nIf you enable this policy, Microsoft Edge uses the specified directory regardless of whether the user has set the '--user-data-dir' command-line flag.\r\n\r\nIf you don't enable this policy, the default profile path is used, but the user can override it by using the '--user-data-dir' flag. Users can find the directory for the profile at edge://version/ under profile path.\r\n\r\nTo avoid data loss or other errors, don't configure this policy to a volume's root directory or to a directory that's used for other purposes, because Microsoft Edge manages its contents.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\r\n\r\nExample value: ${users}/${user_name}/Edge","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir_userdatadir","displayName":"Set the user data directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userfeedbackallowed","displayName":"Allow user feedback (User)","description":"Microsoft Edge uses the Edge Feedback feature (enabled by default) to allow users to send feedback, suggestions or customer surveys and to report any issues with the browser. Also, by default, users can't disable (turn off) the Edge Feedback feature.\r\n\r\nIf you enable this policy or don't configure it, users can invoke Edge Feedback.\r\n\r\nIf you disable this policy, users can't invoke Edge Feedback.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userfeedbackallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userfeedbackallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowed","displayName":"Allow or block video capture (User)","description":"Control whether sites can capture video.\r\n\r\nIf enabled or not configured (default), the user will be asked about video capture access for all sites except those with URLs configured in the 'VideoCaptureAllowedUrls' (Sites that can access video capture devices without requesting permission) policy list, which will be granted access without prompting.\r\n\r\nIf you disable this policy, the user isn't prompted, and video capture is only available to URLs configured in 'VideoCaptureAllowedUrls' policy.\r\n\r\nThis policy affects all types of video inputs, not only the built-in camera.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls","displayName":"Sites that can access video capture devices without requesting permission (User)","description":"Specify websites, based on URL patterns, that can use video capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to video capture devices. Note, however, that the pattern \"*\", which matches any URL, is not supported by this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com/\r\nhttps://[*.]contoso.edu/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls_videocaptureallowedurlsdesc","displayName":"Sites that can access video capture devices without requesting permission (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webdriveroverridesincompatiblepolicies","displayName":"Allow WebDriver to Override Incompatible Policies (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\n\r\nThis policy was removed in M83, because it is not necessary anymore as\r\nWebDriver is now compatible with all existing policies.\r\n\r\nThis policy allows users of the WebDriver feature to override\r\npolicies which can interfere with its operation.\r\n\r\nCurrently this policy disables 'SitePerProcess' (Enable site isolation for every site) and 'IsolateOrigins' (Enable site isolation for specific origins) policies.\r\n\r\nIf the policy is enabled, WebDriver will be able to override incomaptible\r\npolicies.\r\nIf the policy is disabled or not configured, WebDriver will not be allowed\r\nto override incompatible policies.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webdriveroverridesincompatiblepolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webdriveroverridesincompatiblepolicies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling","displayName":"Restrict exposure of local IP address by WebRTC (User)","description":"Allows you to set whether or not WebRTC exposes the user's local IP address.\r\n\r\nIf you set this policy to \"AllowAllInterfaces\" ('default') or \"AllowPublicAndPrivateInterfaces\" ('default_public_and_private_interfaces'), WebRTC exposes the local IP address.\r\n\r\nIf you set this policy to \"AllowPublicInterfaceOnly\" ('default_public_interface_only') or \"DisableNonProxiedUdp\" ('disable_non_proxied_udp'), WebRTC doesn't expose the local IP address.\r\n\r\nIf you don't set this policy, or if you disable it, WebRTC exposes the local IP address.\r\n\r\n * 'default' = Allow all interfaces. This exposes the local IP address.\r\n * 'default_public_and_private_interfaces' = Allow public and private interfaces over http default route. This exposes the local IP address.\r\n * 'default_public_interface_only' = Allow public interface over http default route. This doesn't expose the local IP address.\r\n * 'disable_non_proxied_udp' = Use TCP unless proxy server supports UDP. This doesn't expose the local IP address.\r\n\r\nExample value: default","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling","displayName":"Restrict exposure of localhost IP address by WebRTC (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_default","displayName":"Allow all interfaces. This exposes the local IP address","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_default_public_and_private_interfaces","displayName":"Allow public and private interfaces over http default route. This exposes the local IP address","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_default_public_interface_only","displayName":"Allow public interface over http default route. This doesn't expose the local IP address","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_disable_non_proxied_udp","displayName":"Use TCP unless proxy server supports UDP. This doesn't expose the local IP address","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC (User)","description":"Restricts the UDP port range used by WebRTC to a specified port interval (endpoints included).\r\n\r\nBy configuring this policy, you specify the range of local UDP ports that WebRTC can use.\r\n\r\nIf you don't configure this policy, or if you set it to an empty string or invalid port range, WebRTC can use any available local UDP port.\r\n\r\nExample value: 10000-11999","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_wpadquickcheckenabled","displayName":"Set WPAD optimization (User)","description":"Allows you to turn off WPAD (Web Proxy Auto-Discovery) optimization in Microsoft Edge.\r\n\r\nIf you disable this policy, WPAD optimization is disabled, which makes the browser wait longer for DNS-based WPAD servers.\r\n\r\nIf you enable or don't configure the policy, WPAD optimization is enabled.\r\n\r\nIndependent of whether or how this policy is enabled, the WPAD optimization setting cannot be changed by users.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_wpadquickcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_wpadquickcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls","displayName":"Automatically select client certificates for these sites (User)","description":"Specify a list of sites, based on URL patterns, for which Microsoft Edge should automatically select a client certificate, if the site requests one.\r\n\r\nThe value must be an array of stringified JSON dictionaries. Each dictionary must have the form { \"pattern\": \"$URL_PATTERN\", \"filter\" : $FILTER }, where $URL_PATTERN is a content setting pattern. $FILTER restricts from which client certificates the browser will automatically select. Independent of the filter, only certificates will be selected that match the server's certificate request. For example, if $FILTER has the form { \"ISSUER\": { \"CN\": \"$ISSUER_CN\" } }, additionally only client certificates are selected that are issued by a certificate with the CommonName $ISSUER_CN. If $FILTER contains an \"ISSUER\" and a \"SUBJECT\" section, a client certificate must satisfy both conditions to be selected. If $FILTER specifies an organization (\"O\"), a certificate must have at least one organization which matches the specified value to be selected. If $FILTER specifies an organization unit (\"OU\"), a certificate must have at least one organization unit which matches the specified value to be selected. If $FILTER is the empty dictionary {}, the selection of client certificates is not additionally restricted.\r\n\r\nIf you don't configure this policy, auto-selection isn't done for any site.\r\n\r\nExample value:\r\n\r\n{\"pattern\":\"https://www.contoso.com\",\"filter\":{\"ISSUER\":{\"CN\":\"certificate issuer name\", \"L\": \"certificate issuer location\", \"O\": \"certificate issuer org\", \"OU\": \"certificate issuer org unit\"}, \"SUBJECT\":{\"CN\":\"certificate subject name\", \"L\": \"certificate subject location\", \"O\": \"certificate subject org\", \"OU\": \"certificate subject org unit\"}}}","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls_autoselectcertificateforurlsdesc","displayName":"Automatically select client certificates for these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls","displayName":"Allow cookies on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are allowed to set cookies.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nSee the 'CookiesBlockedForUrls' (Block cookies on specific sites) and 'CookiesSessionOnlyForUrls' (Limit cookies from specific websites to the current session) policies for more information.\r\n\r\nNote there cannot be conflicting URL patterns set between these three policies:\r\n\r\n- 'CookiesBlockedForUrls'\r\n\r\n- CookiesAllowedForUrls\r\n\r\n- 'CookiesSessionOnlyForUrls'\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls_cookiesallowedforurlsdesc","displayName":"Allow cookies on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls","displayName":"Block cookies on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can't set cookies.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nSee the 'CookiesAllowedForUrls' (Allow cookies on specific sites) and 'CookiesSessionOnlyForUrls' (Limit cookies from specific websites to the current session) policies for more information.\r\n\r\nNote there cannot be conflicting URL patterns set between these three policies:\r\n\r\n- CookiesBlockedForUrls\r\n\r\n- 'CookiesAllowedForUrls'\r\n\r\n- 'CookiesSessionOnlyForUrls'\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls_cookiesblockedforurlsdesc","displayName":"Block cookies on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiessessiononlyforurls","displayName":"Limit cookies from specific websites to the current session (User)","description":"Cookies created by websites that match a URL pattern you define are deleted when the session ends (when the window closes).\r\n\r\nCookies created by websites that don't match the pattern are controlled by the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or by the user's personal configuration. This is also the default behavior if you don't configure this policy.\r\n\r\nIf Microsoft Edge is running in background mode, the session might not close when the last window is closed, meaning the cookies won't be cleared when the window closes. See the 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about configuring what happens when Microsoft Edge runs in background mode.\r\n\r\nYou can also use the 'CookiesAllowedForUrls' (Allow cookies on specific sites) and 'CookiesBlockedForUrls' (Block cookies on specific sites) policies to control which websites can create cookies.\r\n\r\nNote there cannot be conflicting URL patterns set between these three policies:\r\n\r\n- 'CookiesBlockedForUrls'\r\n\r\n- 'CookiesAllowedForUrls'\r\n\r\n- CookiesSessionOnlyForUrls\r\n\r\nIf you set the 'RestoreOnStartup' (Action to take on startup) policy to restore URLs from previous sessions, this policy is ignored, and cookies are stored permanently for those sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiessessiononlyforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiessessiononlyforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiessessiononlyforurls_cookiessessiononlyforurlsdesc","displayName":"Limit cookies from specific websites to the current session (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting","displayName":"Configure cookies (User)","description":"Control whether websites can create cookies on the user's device. This policy is all or nothing - you can let all websites create cookies, or no websites create cookies. You can't use this policy to enable cookies from specific websites.\r\n\r\nSet the policy to 'SessionOnly' (4) to clear cookies when the session closes. If Microsoft Edge is running in background mode, the session might not close when the last window is closed, meaning the cookies won't be cleared when the window closes. See 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about configuring what happens when Microsoft Edge runs in background mode.\r\n\r\nIf you don't configure this policy, the default 'AllowCookies' (1) is used, and users can change this setting in Microsoft Edge Settings. (If you don't want users to be able to change this setting, set the policy.)\r\n\r\n* 1 = Let all sites create cookies\r\n\r\n* 2 = Don't let any site create cookies\r\n\r\n* 4 = Keep cookies for the duration of the session","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting","displayName":"Configure cookies (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting_1","displayName":"Let all sites create cookies","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting_2","displayName":"Don't let any site create cookies","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting_4","displayName":"Keep cookies for the duration of the session","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting","displayName":"Default geolocation setting (User)","description":"Set whether websites can track users' physical locations. You can allow tracking by default (1), deny it by default (2), or ask the user each time a website requests their location (3).\r\n\r\nIf you don't configure this policy, 'AskGeolocation' policy is used and the user can change it.\r\n\r\n* 1 = Allow sites to track users' physical location\r\n\r\n* 2 = Don't allow any site to track users' physical location\r\n\r\n* 3 = Ask whenever a site wants to track users' physical location","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting","displayName":"Default geolocation setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting_1","displayName":"Allow sites to track users' physical location","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting_2","displayName":"Don't allow any site to track users' physical location","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting_3","displayName":"Ask whenever a site wants to track users' physical location","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting","displayName":"Default images setting (User)","description":"Set whether websites can display images. You can allow images on all sites (1) or block them on all sites (2).\r\n\r\nIf you don't configure this policy, images are allowed by default, and the user can change this setting.\r\n\r\n* 1 = Allow all sites to show all images\r\n\r\n* 2 = Don't allow any site to show images","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_defaultimagessetting","displayName":"Default images setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_defaultimagessetting_1","displayName":"Allow all sites to show all images","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_defaultimagessetting_2","displayName":"Don't allow any site to show images","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting","displayName":"Default JavaScript setting (User)","description":"Set whether websites can run JavaScript. You can allow it for all sites (1) or block it for all sites (2).\r\n\r\nIf you don't configure this policy, all sites can run JavaScript by default, and the user can change this setting.\r\n\r\n* 1 = Allow all sites to run JavaScript\r\n\r\n* 2 = Don't allow any site to run JavaScript","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting","displayName":"Default JavaScript setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_1","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_2","displayName":"Don't allow any site to run JavaScript","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting (User)","description":"Setting this policy controls the default behavior for the local fonts permission.\n\nIf you set the policy to BlockLocalFonts (value 2), access to local fonts is denied by default. Sites are prevented from accessing information about local fonts.\n\nIf you set the policy to AskLocalFonts (value 3), users are prompted when a site requests access to local fonts. If permission is granted, the site can access information about local fonts.\n\nIf a site is included in 'LocalFontsAllowedForUrls' (Allow Local Fonts permission on these sites) or 'LocalFontsBlockedForUrls' (Block Local Fonts permission on these sites), then that setting overrides the value set for this policy.\n\nIf you don't configure this policy, users are prompted by default and can change this setting.\n\nPolicy options mapping:\n\n* BlockLocalFonts (2) = Denies the Local Fonts permission on all sites by default\n\n* AskLocalFonts (3) = Ask every time a site wants to obtain the Local Fonts permission\n\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_2","displayName":"Denies the Local Fonts permission on all sites by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_3","displayName":"Ask every time a site wants to obtain the Local Fonts permission","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting","displayName":"Default notification setting (User)","description":"Set whether websites can display desktop notifications. You can allow them by default (1), deny them by default (2), or have the user be asked each time a website wants to show a notification (3).\r\n\r\nIf you don't configure this policy, notifications are allowed by default, and the user can change this setting.\r\n\r\n* 1 = Allow sites to show desktop notifications\r\n\r\n* 2 = Don't allow any site to show desktop notifications\r\n\r\n* 3 = Ask every time a site wants to show desktop notifications","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting","displayName":"Default notification setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting_1","displayName":"Allow sites to show desktop notifications","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting_2","displayName":"Don't allow any site to show desktop notifications","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting_3","displayName":"Ask every time a site wants to show desktop notifications","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting","displayName":"Default Adobe Flash setting (User)","description":"Determines whether websites that aren't covered by 'PluginsAllowedForUrls' (Allow the Adobe Flash plug-in on specific sites) or 'PluginsBlockedForUrls' (Block the Adobe Flash plug-in on specific sites) can automatically run the Adobe Flash plug-in. You can select 'BlockPlugins' (2) to block Adobe Flash on all sites, or you can select 'ClickToPlay' (3) to let Adobe Flash run but require the user to click the placeholder to start it. In any case, the 'PluginsAllowedForUrls' and 'PluginsBlockedForUrls' policies take precedence over 'DefaultPluginsSetting'.\r\n\r\nAutomatic playback is only allowed for domains explicitly listed in the 'PluginsAllowedForUrls' policy. If you want to enable automatic playback for all sites, consider adding http://* and https://* to this list.\r\n\r\nIf you don't configure this policy, the user can change this setting manually.\r\n\r\n* 2 = Block the Adobe Flash plug-in\r\n\r\n* 3 = Click to play\r\n\r\nThe former '1' option set allow-all, but this functionality is now only handled by the 'PluginsAllowedForUrls' policy. Existing policies using '1' will operate in Click-to-play mode.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_defaultpluginssetting","displayName":"Default Adobe Flash setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_defaultpluginssetting_2","displayName":"Block the Adobe Flash plugin","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_defaultpluginssetting_3","displayName":"Click to play","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting","displayName":"Default pop-up window setting (User)","description":"Set whether websites can show pop-up windows. You can allow them on all websites (1) or block them on all sites (2).\r\n\r\nIf you don't configure this policy, pop-up windows are blocked by default, and users can change this setting.\r\n\r\n* 1 = Allow all sites to show pop-ups\r\n\r\n* 2 = Don't allow any site to show pop-up windows","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting","displayName":"Default pop-up window setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting_1","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting_2","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API (User)","description":"Control whether websites can access nearby Bluetooth devices. You can completely block access or require the site to ask the user each time it wants to access a Bluetooth device.\r\n\r\nIf you don't configure this policy, the default value (3, meaning users are asked each time) is used and users can change it.\r\n\r\n* 2 = Don't allow any site to request access to Bluetooth devices by using the Web Bluetooth API\r\n\r\n* 3 = Allow sites to ask the user to grant access to a nearby Bluetooth device","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_2","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_3","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API (User)","description":"Set whether websites can access connected USB devices. You can completely block access or ask the user each time a website wants to get access to connected USB devices.\r\n\r\nYou can override this policy for specific URL patterns by using the 'WebUsbAskForUrls' (Allow WebUSB on specific sites) and 'WebUsbBlockedForUrls' (Block WebUSB on specific sites) policies.\r\n\r\nIf you don't configure this policy, sites can ask users whether they can access the connected USB devices (3) by default, and users can change this setting.\r\n\r\n* 2 = Don't allow any site to request access to USB devices via the WebUSB API\r\n\r\n* 3 = Allow sites to ask the user to grant access to a connected USB device","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebusbguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebusbguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting_2","displayName":"Do not allow any site to request access to USB devices via the WebUSB API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting_3","displayName":"Allow sites to ask the user to grant access to a connected USB device","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesallowedforurls","displayName":"Allow images on these sites (User)","description":"Define a list of sites, based on URL patterns, that can display images.\r\n\r\nIf you don't configure this policy, the global default value is used for all sites either from the 'DefaultImagesSetting' (Default images setting) policy (if set) or the user's personal configuration.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesallowedforurls_imagesallowedforurlsdesc","displayName":"Allow images on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls","displayName":"Block images on specific sites (User)","description":"Define a list of sites, based on URL patterns, that aren't allowed to display images.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultImagesSetting' (Default images setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_imagesblockedforurlsdesc","displayName":"Block images on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptallowedforurls","displayName":"Allow JavaScript on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are allowed to run JavaScript.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultJavaScriptSetting' (Default JavaScript setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptallowedforurls_javascriptallowedforurlsdesc","displayName":"Allow JavaScript on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls","displayName":"Block JavaScript on specific sites (User)","description":"Define a list of sites, based on URL patterns, that aren't allowed to run JavaScript.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultJavaScriptSetting' (Default JavaScript setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls_javascriptblockedforurlsdesc","displayName":"Block JavaScript on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsallowedforurls","displayName":"Allow Local Fonts permission on these sites (User)","description":"Specifies a list of site URL patterns for which the local fonts permission is automatically granted. Sites in this list can access information about local fonts.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are supported. This policy matches based on origin only; any path in the URL pattern is ignored.\n\nIf a site isn't included in this policy, the 'DefaultLocalFontsSetting' (Default Local Fonts permission setting) policy applies if configured. Otherwise, the browser default behavior applies, and users can choose the permission on a per-site basis.\n\nExample value:\n\nhttps://www.example.com\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsallowedforurls_localfontsallowedforurlsdesc","displayName":"Allow Local Fonts permission on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsblockedforurls","displayName":"Block Local Fonts permission on these sites (User)","description":"Specifies a list of site URL patterns for which the local fonts permission is automatically denied. Sites in this list are prevented from accessing information about local fonts.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are supported. This policy matches based on origin only; any path in the URL pattern is ignored.\n\nIf a site isn't included in this policy, the 'DefaultLocalFontsSetting' (Default Local Fonts permission setting) policy applies if configured. Otherwise, the browser default behavior applies, and users can choose the permission on a per-site basis.\n\nExample value:\n\nhttps://www.example.com\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsblockedforurls_localfontsblockedforurlsdesc","displayName":"Block Local Fonts permission on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsallowedforurls","displayName":"Allow notifications on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can display notifications.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultNotificationsSetting' (Default notification setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsallowedforurls_notificationsallowedforurlsdesc","displayName":"Allow notifications on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls","displayName":"Block notifications on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are blocked from displaying notifications.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultNotificationsSetting' (Default notification setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_notificationsblockedforurlsdesc","displayName":"Block notifications on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsallowedforurls","displayName":"Allow the Adobe Flash plug-in on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can run the Adobe Flash plug-in.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultPluginsSetting' (Default Adobe Flash setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsallowedforurls_pluginsallowedforurlsdesc","displayName":"Allow the Adobe Flash plug-in on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls","displayName":"Block the Adobe Flash plug-in on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are blocked from running Adobe Flash.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultPluginsSetting' (Default Adobe Flash setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls_pluginsblockedforurlsdesc","displayName":"Block the Adobe Flash plug-in on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls","displayName":"Allow pop-up windows on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can open pop-up windows.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultPopupsSetting' (Default pop-up window setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls_popupsallowedforurlsdesc","displayName":"Allow pop-up windows on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsblockedforurls","displayName":"Block pop-up windows on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are blocked from opening pop-up windows.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultPopupsSetting' (Default pop-up window setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsblockedforurls_popupsblockedforurlsdesc","displayName":"Block pop-up windows on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls","displayName":"Grant access to specific sites to connect to specific USB devices (User)","description":"Allows you to set a list of urls that specify which sites will automatically be granted permission to access a USB device with the given vendor and product IDs. Each item in the list must contain both devices and urls in order for the policy to be valid. Each item in devices can contain a vendor ID and product ID field. Any ID that is omitted is treated as a wildcard with one exception, and that exception is that a product ID cannot be specified without a vendor ID also being specified. Otherwise, the policy will not be valid and will be ignored.\r\n\r\nThe USB permission model uses the URL of the requesting site (\"requesting URL\") and the URL of the top-level frame site (\"embedding URL\") to grant permission to the requesting URL to access the USB device. The requesting URL may be different than the embedding URL when the requesting site is loaded in an iframe. Therefore, the \"urls\" field can contain up to two URL strings delimited by a comma to specify the requesting and embedding URL respectively. If only one URL is specified, then access to the corresponding USB devices will be granted when the requesting site's URL matches this URL regardless of embedding status. The URLs in \"urls\" must be valid URLs, otherwise the policy will be ignored.\r\n\r\nIf this policy is left not set, the global default value will be used for all sites either from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy if it is set, or the user's personal configuration otherwise.\r\n\r\nURL patterns in this policy should not clash with the ones configured via 'WebUsbBlockedForUrls' (Block WebUSB on specific sites). If there is a clash, this policy will take precedence over 'WebUsbBlockedForUrls' and 'WebUsbAskForUrls' (Allow WebUSB on specific sites).\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"urls\": [\r\n \"https://contoso.com\", \r\n \"https://fabrikam.com\"\r\n ], \r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234, \r\n \"product_id\": 5678\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_webusballowdevicesforurls","displayName":"Grant access to specific sites to connect to specific USB devices (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls","displayName":"Allow WebUSB on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can ask the user for access to a USB device.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nThe URL patterns defined in this policy can't conflict with those configured in the 'WebUsbBlockedForUrls' (Block WebUSB on specific sites) policy - you can't both allow and block a URL.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls_webusbaskforurlsdesc","displayName":"Allow WebUSB on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls","displayName":"Block WebUSB on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can't ask the user to grant them access to a USB device.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nURL patterns in this policy can't conflict with those configured in the 'WebUsbAskForUrls' (Allow WebUSB on specific sites) policy. You can't both allow and block a URL.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls_webusbblockedforurlsdesc","displayName":"Block WebUSB on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderenabled","displayName":"Enable the default search provider (User)","description":"Enables the ability to use a default search provider.\r\n\r\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\r\n\r\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider.\r\n\r\nIf you disable this policy, the user can't search from the address bar.\r\n\r\nIf you enable or disable this policy, users can't change or override it.\r\n\r\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderencodings","displayName":"Default search provider encodings (User)","description":"Specify the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They are tried in the order provided.\r\n\r\nThis policy is optional. If not configured, the default, UTF-8, is used.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value:\r\n\r\nUTF-8\r\nUTF-16\r\nGB2312\r\nISO-8859-1","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderencodings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderencodings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderencodings_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider (User)","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\r\n\r\nThis policy is optional. If you don't configure it, image search isn't available.\r\n\r\nSpecify Bing's Image Search URL as:\r\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\r\n\r\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\r\n\r\nSee 'DefaultSearchProviderImageURLPostParams' (Parameters for an image URL that uses POST) policy to finish configuring image search.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: https://search.contoso.com/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST (User)","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it’s replaced with real image thumbnail data. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nSpecify Bing's Image Search URL Post Params as:\r\n'imageBin={google:imageThumbnailBase64}'.\r\n\r\nSpecify Google's Image Search URL Post Params as:\r\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\r\n\r\nIf you don’t set this policy, image search requests are sent using the GET method.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderkeyword","displayName":"Default search provider keyword (User)","description":"Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider.\r\n\r\nThis policy is optional. If you don't configure it, no keyword activates the search provider.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderkeyword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderkeyword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderkeyword_defaultsearchproviderkeyword","displayName":"Default search provider keyword (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"Specifies the name of the default search provider.\r\n\r\nIf you enable this policy, you set the name of the default search provider.\r\n\r\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\r\n\r\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidername_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidername_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (User)","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\r\n\r\nSpecify Bing's search URL as:\r\n\r\n'{bing:baseURL}search?q={searchTerms}'.\r\n\r\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\r\n\r\nThis policy is required when you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) policy; if you don't enable the latter policy, this policy is ignored.\r\n\r\nExample value: https://search.contoso.com/search?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersearchurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersearchurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersearchurl_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions (User)","description":"Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user has entered so far.\r\n\r\nThis policy is optional. If you don't configure it, users won't see search suggestions; they will see suggestions from their browsing history and favorites.\r\n\r\nBing's suggest URL can be specified as:\r\n\r\n'{bing:baseURL}qbox?query={searchTerms}'.\r\n\r\nGoogle's suggest URL can be specified as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: https://search.contoso.com/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl_defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes","displayName":"Configure allowed extension types (User)","description":"Controls which extension types can be installed and limits runtime access.\r\n\r\nThis setting defines the allowed types of extensions and which hosts they can interact with. The value is a list of strings, each of which should be one of the following: \"extension\", \"theme\", \"user_script\", and \"hosted_app\". See the Microsoft Edge extensions documentation for more information on these types.\r\n\r\nNote that this policy also affects extensions to be force-installed by using 'ExtensionInstallForcelist' (Control which extensions are installed silently) policy.\r\n\r\nIf you enable this policy, only extensions that match a type in the list are installed.\r\n\r\nIf you don't configure this policy, no restrictions on the acceptable extension types are enforced.\r\n\r\nExample value:\r\n\r\nhosted_app","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes_extensionallowedtypesdesc","displayName":"Types of extensions/apps that are allowed to be installed (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist","displayName":"Allow specific extensions to be installed (User)","description":"By default, all extensions are allowed. However, if you block all extensions by setting the 'ExtensionInstallBlockList' policy to \"*,\" users can only install extensions defined in this policy.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist_extensioninstallallowlistdesc","displayName":"Extension IDs to exempt from the block list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallblocklist","displayName":"Control which extensions cannot be installed (User)","description":"List specific extensions that users can NOT install in Microsoft Edge. When you deploy this policy, any extensions on this list that were previously installed will be disabled, and the user won't be able to enable them. If you remove an item from the list of blocked extensions, that extension is automatically re-enabled anywhere it was previously installed.\r\n\r\nUse \"*\" to block all extensions that aren't explicitly listed in the allow list.\r\n\r\nIf you don't configure this policy, users can install any extension in Microsoft Edge.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallblocklist_extensioninstallblocklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallforcelist","displayName":"Control which extensions are installed silently (User)","description":"Specifies extensions that are installed silently, without user interaction, and that the users can't uninstall or disable (\"force-installed\"). All permissions requested by the extensions are granted implicitly, without user interaction, including any additional permissions requested by future versions of the extension. Furthermore, permissions are granted for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These two APIs are only available to extensions that are force-installed.)\r\n\r\nThis policy takes precedence over a potentially conflicting 'ExtensionInstallBlocklist' (Control which extensions cannot be installed) policy. When you take an extension off of the force-installed list it's automatically uninstalled by Microsoft Edge.\r\n\r\nFor Windows devices that aren't joined to a Microsoft Active Directory domain, forced installation is limited to extensions available in the Microsoft Store.\r\n\r\nNote that users can modify the source code of any extension by using Developer Tools, potentially rendering the extension dysfunctional. If this is a concern, set the 'DeveloperToolsAvailability' (Control where developer tools can be used) policy.\r\n\r\nUse the following format to add an extension to the list:\r\n\r\n[extensionID];[updateURL]\r\n\r\n- extensionID - the 32-letter string found on edge://extensions when in developer mode.\r\n\r\n- updateURL (optional) is the address of the Update Manifest XML document for the app or extension, as described at https://go.microsoft.com/fwlink/?linkid=2095043. If you don't set the updateURL, the Microsoft Store update URL is used (currently https://edge.microsoft.com/extensionwebstorebase/v1/crx). Note that the update URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL indicated in the extension's manifest.\r\n\r\nFor example, gggmmkjegpiggikcnhidnjjhmicpibll;https://edge.microsoft.com/extensionwebstorebase/v1/crx installs the Microsoft Online app from the Microsoft Store \"update\" URL. For more information about hosting extensions, see: https://go.microsoft.com/fwlink/?linkid=2095044.\r\n\r\nIf you don't configure this policy, no extensions are installed automatically, and users can uninstall any extension in Microsoft Edge.\r\n\r\nNote that this policy doesn't apply to InPrivate mode.\r\n\r\nExample value:\r\n\r\ngbchcmhmhahfdphkhkmpfmihenigjmpp;https://edge.microsoft.com/extensionwebstorebase/v1/crx\r\nabcdefghijklmnopabcdefghijklmnop","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallforcelist_extensioninstallforcelistdesc","displayName":"Extension/App IDs and update URLs to be silently installed (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallsources","displayName":"Configure extension and user script install sources (User)","description":"Define URLs that can install extensions and themes.\r\n\r\nBy default, users have to download a *.crx file for each extension or script they want to install, and then drag it onto the Microsoft Edge settings page. This policy lets specific URLs use install the extension or script for the user.\r\n\r\nEach item in this list is an extension-style match pattern (see https://go.microsoft.com/fwlink/?linkid=2095039). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (in other words, the referrer) must be allowed by these patterns.\r\n\r\nThe 'ExtensionInstallBlocklist' (Control which extensions cannot be installed) policy takes precedence over this policy. Any extensions that's on the block list won't be installed, even if it comes from a site on this list.\r\n\r\nExample value:\r\n\r\nhttps://corp.contoso.com/*","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallsources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallsources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallsources_extensioninstallsourcesdesc","displayName":"URL patterns to allow extension, app, and user script installs from (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings","displayName":"Configure extension management settings (User)","description":"Configures extension management settings for Microsoft Edge.\r\n\r\nThis policy controls multiple settings, including settings controlled by any existing extension-related policies. This policy overrides any legacy policies if both are set.\r\n\r\nThis policy maps an extension ID or an update URL to its configuration. With an extension ID, the configuration is applied only to the specified extension. Set a default configuration for the special ID \"*\", to apply to all extensions that aren't specifically listed in this policy. With an update URL, the configuration is applied to all extensions with the exact update URL stated in manifest of this extension, as described at https://go.microsoft.com/fwlink/?linkid=2095043.\r\n\r\nExample value:\r\n\r\n{\r\n \"abcdefghijklmnopabcdefghijklmnop\": {\r\n \"blocked_permissions\": [\r\n \"history\"\r\n ], \r\n \"installation_mode\": \"allowed\", \r\n \"minimum_version_required\": \"1.0.1\"\r\n }, \r\n \"bcdefghijklmnopabcdefghijklmnopa\": {\r\n \"runtime_blocked_hosts\": [\r\n \"*://*.contoso.com\"\r\n ], \r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ], \r\n \"update_url\": \"https://contoso.com/update_url\", \r\n \"runtime_allowed_hosts\": [\r\n \"*://good.contoso.com\"\r\n ], \r\n \"installation_mode\": \"force_installed\"\r\n }, \r\n \"cdefghijklmnopabcdefghijklmnopab\": {\r\n \"blocked_install_message\": \"Custom error message.\", \r\n \"installation_mode\": \"blocked\"\r\n }, \r\n \"*\": {\r\n \"blocked_permissions\": [\r\n \"downloads\", \r\n \"bookmarks\"\r\n ], \r\n \"installation_mode\": \"blocked\", \r\n \"runtime_blocked_hosts\": [\r\n \"*://*.contoso.com\"\r\n ], \r\n \"blocked_install_message\": \"Custom error message.\", \r\n \"allowed_types\": [\r\n \"hosted_app\"\r\n ], \r\n \"runtime_allowed_hosts\": [\r\n \"*://good.contoso.com\"\r\n ], \r\n \"install_sources\": [\r\n \"https://company-intranet/apps\"\r\n ]\r\n }, \r\n \"defghijklmnopabcdefghijklmnopabc,efghijklmnopabcdefghijklmnopabcd\": {\r\n \"blocked_install_message\": \"Custom error message.\", \r\n \"installation_mode\": \"blocked\"\r\n }, \r\n \"fghijklmnopabcdefghijklmnopabcde\": {\r\n \"blocked_install_message\": \"Custom removal message.\", \r\n \"installation_mode\": \"removed\"\r\n }, \r\n \"update_url:https://www.contoso.com/update.xml\": {\r\n \"blocked_permissions\": [\r\n \"wallpaper\"\r\n ], \r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ], \r\n \"installation_mode\": \"allowed\"\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings_extensionsettings","displayName":"Configure extension management settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_enablemediarouter","displayName":"Enable Google Cast (User)","description":"Enable this policy to enable Google Cast. Users will be able to launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.\r\n\r\nDisable this policy to disable Google Cast.\r\n\r\nBy default, Google Cast is enabled.","helpText":"","infoUrls":[],"categoryId":"fddc444c-3591-4a50-865b-d8993b798e12","categoryName":"Cast","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_enablemediarouter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_enablemediarouter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_showcasticonintoolbar","displayName":"Show the cast icon in the toolbar (User)","description":"Set this policy to true to show the Cast toolbar icon on the toolbar or the overflow menu. Users won't be able to remove it.\r\n\r\nIf you don't configure this policy or if you disable it, users can pin or remove the icon by using its contextual menu.\r\n\r\nIf you've also set the 'EnableMediaRouter' (Enable Google Cast) policy to false, then this policy is ignored, and the toolbar icon isn't shown.","helpText":"","infoUrls":[],"categoryId":"fddc444c-3591-4a50-865b-d8993b798e12","categoryName":"Cast","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_showcasticonintoolbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_showcasticonintoolbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_allowcrossoriginauthprompt","displayName":"Allow cross-origin HTTP Basic Auth prompts (User)","description":"Controls whether third-party sub-content on a page can open an HTTP Basic Auth dialog box.\r\n\r\nTypically, this is disabled as a phishing defense. If you don't configure this policy, it's disabled and third-party sub-content can't open a HTTP Basic Auth dialog box.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_allowcrossoriginauthprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_allowcrossoriginauthprompt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authnegotiatedelegateallowlist","displayName":"Specifies a list of servers that Microsoft Edge can delegate user credentials to (User)","description":"Configure the list of servers that Microsoft Edge can delegate to.\r\n\r\nSeparate multiple server names with commas. Wildcards (*) are allowed.\r\n\r\nIf you don't configure this policy Microsoft Edge won't delegate user credentials even if a server is detected as Intranet.\r\n\r\nExample value: contoso.com","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authnegotiatedelegateallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authnegotiatedelegateallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authnegotiatedelegateallowlist_authnegotiatedelegateallowlist","displayName":"Specifies a list of servers that Microsoft Edge can delegate user credentials to (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authschemes","displayName":"Supported authentication schemes (User)","description":"Specifies which HTTP authentication schemes are supported.\r\n\r\nYou can configure the policy by using these values: 'basic', 'digest', 'ntlm', and 'negotiate'. Separate multiple values with commas.\r\n\r\nIf you don't configure this policy, all four schemes are used.\r\n\r\nExample value: basic,digest,ntlm,negotiate","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authschemes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authschemes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authschemes_authschemes","displayName":"Supported authentication schemes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authserverallowlist","displayName":"Configure list of allowed authentication servers (User)","description":"Specifies which servers to enable for integrated authentication. Integrated authentication is only enabled when Microsoft Edge receives an authentication challenge from a proxy or from a server in this list.\r\n\r\nSeparate multiple server names with commas. Wildcards (*) are allowed.\r\n\r\nIf you don't configure this policy, Microsoft Edge tries to detect if a server is on the intranet - only then will it respond to IWA requests. If the server is on the internet, IWA requests from it are ignored by Microsoft Edge.\r\n\r\nExample value: *contoso.com,contoso.com","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authserverallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authserverallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authserverallowlist_authserverallowlist","displayName":"Configure list of allowed authentication servers (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_disableauthnegotiatecnamelookup","displayName":"Disable CNAME lookup when negotiating Kerberos authentication (User)","description":"Determines whether the generated Kerberos SPN is based on the canonical DNS name (CNAME) or on the original name entered.\r\n\r\nIf you enable this policy, CNAME lookup is skipped and the server name (as entered) is used.\r\n\r\nIf you disable this policy or don't configure it, the canonical name of the server is used. This is determined through CNAME lookup.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_disableauthnegotiatecnamelookup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_disableauthnegotiatecnamelookup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_enableauthnegotiateport","displayName":"Include non-standard port in Kerberos SPN (User)","description":"Specifies whether the generated Kerberos SPN should include a non-standard port.\r\n\r\nIf you enable this policy, and a user includes a non-standard port (a port other than 80 or 443) in a URL, that port is included in the generated Kerberos SPN.\r\n\r\nIf you don't configure or disable this policy, the generated Kerberos SPN won't include a port in any case.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_enableauthnegotiateport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_enableauthnegotiateport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~identity_nonmicrosoftaccountsigninenabled","displayName":"Enable sign-in to Microsoft Edge using non-Microsoft accounts (User)","description":"This policy controls whether users can sign in to Microsoft Edge using non-Microsoft accounts, such as Google or Apple accounts.\n\nIf you enable this policy or don't configure it, users can sign in to Microsoft Edge with non-Microsoft accounts when the feature is available. Related sign-in entry points, such as Google or Apple sign-in buttons in the profile flyout and unified sign-in experience, are shown when available.\n\nIf you disable this policy, users can't sign in to Microsoft Edge with non-Microsoft accounts. Related sign-in entry points and code paths are hidden and disabled, regardless of related feature flag settings.\n\nUsers can still sign in with Microsoft accounts.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~identity_nonmicrosoftaccountsigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~identity_nonmicrosoftaccountsigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist","displayName":"Control which native messaging hosts users can use (User)","description":"List specific native messaging hosts that users can use in Microsoft Edge.\r\n\r\nBy default, all native messaging hosts are allowed. If you set the 'NativeMessagingBlocklist' (Configure native messaging block list) policy to *, all native messaging hosts are blocked, and only native messaging hosts listed in here are loaded.\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist_nativemessagingallowlistdesc","displayName":"Names of the native messaging hosts to exempt from the block list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingblocklist","displayName":"Configure native messaging block list (User)","description":"Specifies which native messaging hosts that shouldn't be used.\r\n\r\nUse '*' to block all native messaging hosts unless they are explicitly listed in the allow list.\r\n\r\nIf you don't configure this policy, Microsoft Edge will load all installed native messaging hosts.\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingblocklist_nativemessagingblocklistdesc","displayName":"Names of the forbidden native messaging hosts (or * for all) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts","displayName":"Allow user-level native messaging hosts (installed without admin permissions) (User)","description":"Enables user-level installation of native messaging hosts.\r\n\r\nIf you disable this policy, Microsoft Edge will only use native messaging hosts installed on the system level.\r\n\r\nBy default, if you don't configure this policy, Microsoft Edge will allow usage of user-level native messaging hosts.","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordmanagerenabled","displayName":"Enable saving passwords to the password manager (User)","description":"Enable Microsoft Edge to save user passwords.\r\n\r\nIf you enable this policy, users can save their passwords in Microsoft Edge. The next time they visit the site, Microsoft Edge will enter the password automatically.\r\n\r\nIf you disable this policy, users can't save new passwords, but they can still use previously saved passwords.\r\n\r\nIf you enable or disable this policy, users can't change or override it in Microsoft Edge. If you don't configure it, users can save passwords, as well as turn this feature off.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordmanagerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordmanagerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL (User)","description":"Configures the change password URL (HTTP and HTTPS schemes only).\r\n\r\nPassword protection service will send users to this URL to change their password after seeing a warning in the browser.\r\n\r\nIf you enable this policy, then password protection service sends users to this URL to change their password.\r\n\r\nIf you disable this policy or don't configure it, then password protection service will not redirect users to a change password URL.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://contoso.com/change_password.html","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls","displayName":"Configure the list of enterprise login URLs where password protection service should capture fingerprint of password (User)","description":"Configure the list of enterprise login URLs (HTTP and HTTPS schemes only) where Microsoft Edge should capture the fingerprint of passwords and use it for password reuse detection.\r\n\r\nIf you enable this policy, the password protection service captures fingerprints of passwords on the defined URLs.\r\n\r\nIf you disable this policy or don't configure it, no password fingerprints are captured.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com/login.html\r\nhttps://login.contoso.com","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls_passwordprotectionloginurlsdesc","displayName":"Configure the list of enterprise login URLs where password protection service should capture fingerprint of password (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionwarningtrigger","displayName":"Configure password protection warning trigger (User)","description":"Allows you to control when to trigger password protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites.\r\n\r\nYou can use the 'PasswordProtectionLoginURLs' (Configure the list of enterprise login URLs where password protection service should capture fingerprint of password) and 'PasswordProtectionChangePasswordURL' (Configure the change password URL) policies to configure which passwords to protect.\r\n\r\nExemptions: Passwords for the sites listed in 'PasswordProtectionLoginURLs' and 'PasswordProtectionChangePasswordURL', as well as for the sites listed in 'SmartScreenAllowListDomains' (Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings), will not trigger a password-protection warning.\r\n\r\nSet to 'PasswordProtectionWarningOff' (0) to not show password protection warningss.\r\n\r\nSet to 'PasswordProtectionWarningOnPasswordReuse' (1) to show password protection warnings when the user reuses their protected password on a non-allowlisted site.\r\n\r\nIf you disable or don't configure this policy, then the warning trigger is not shown.\r\n\r\n* 0 = Password protection warning is off.\r\n\r\n* 1 = Password protection warning is triggered by password reuse.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionwarningtrigger_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionwarningtrigger_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger","displayName":"Configure password protection warning trigger (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger_0","displayName":"Password protection warning is off","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger_1","displayName":"Password protection warning is triggered by password reuse","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_defaultprinterselection","displayName":"Default printer selection rules (User)","description":"Overrides Microsoft Edge default printer selection rules. This policy determines the rules for selecting the default printer in Microsoft Edge, which happens the first time a user tries to print a page.\r\n\r\nWhen this policy is set, Microsoft Edge tries to find a printer that matches all of the specified attributes and uses it as default printer. If there are multiple printers that meet the criteria, the first printer that matches is used.\r\n\r\nIf you don't configure this policy or no matching printers are found within the timeout, the printer defaults to the built-in PDF printer or no printer, if the PDF printer isn't available.\r\n\r\nThe value is parsed as a JSON object, conforming to the following schema: { \"type\": \"object\", \"properties\": { \"idPattern\": { \"description\": \"Regular expression to match printer id.\", \"type\": \"string\" }, \"namePattern\": { \"description\": \"Regular expression to match printer display name.\", \"type\": \"string\" } } }\r\n\r\nOmitting a field means all values match; for example, if you don't specify connectivity Print Preview starts discovering all kinds of local printers. Regular expression patterns must follow the JavaScript RegExp syntax and matches are case sensitive.\r\n\r\nExample value: { \"idPattern\": \".*public\", \"namePattern\": \".*Color\" }","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_defaultprinterselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_defaultprinterselection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_defaultprinterselection_defaultprinterselection","displayName":"Default printer selection rules (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printheaderfooter","displayName":"Print headers and footers (User)","description":"Force 'headers and footers' to be on or off in the printing dialog.\r\n\r\nIf you don't configure this policy, users can decide whether to print headers and footers.\r\n\r\nIf you disable this policy, users can't print headers and footers.\r\n\r\nIf you enable this policy, users always print headers and footers.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printheaderfooter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printheaderfooter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printingenabled","displayName":"Enable printing (User)","description":"Enables printing in Microsoft Edge and prevents users from changing this setting.\r\n\r\nIf you enable this policy or don't configure it, users can print.\r\n\r\nIf you disable this policy, users can't print from Microsoft Edge. Printing is disabled in the wrench menu, extensions, JavaScript applications, and so on. Users can still print from plug-ins that bypass Microsoft Edge while printing. For example, certain Adobe Flash applications have the print option in their context menu, which isn't covered by this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printpreviewusesystemdefaultprinter","displayName":"Set the system default printer as the default printer (User)","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\r\n\r\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\r\n\r\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printpreviewusesystemdefaultprinter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printpreviewusesystemdefaultprinter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_usesystemprintdialog","displayName":"Print using system print dialog (User)","description":"Shows the system print dialog instead of print preview.\r\n\r\nIf you enable this policy, Microsoft Edge opens the system print dialog instead of the built-in print preview when a user prints a page.\r\n\r\nIf you don't configure or disable this policy, print commands trigger the Microsoft Edge print preview screen.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_usesystemprintdialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_usesystemprintdialog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxybypasslist","displayName":"Configure proxy bypass rules (User)","description":"Defines a list of hosts for which Microsoft Edge bypasses any proxy.\r\n\r\nThis policy is applied only if you have selected 'Use fixed proxy servers' in the 'ProxyMode' (Configure proxy server settings) policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\r\n\r\nIf you enable this policy, you can create a list of hosts for which Microsoft Edge doesn't use a proxy.\r\n\r\nIf you don't configure this policy, no list of hosts is created for which Microsoft Edge bypasses a proxy. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\r\n\r\nFor more detailed examples go to https://go.microsoft.com/fwlink/?linkid=2094936.\r\n\r\nExample value: https://www.contoso.com, https://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxybypasslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxybypasslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxybypasslist_proxybypasslist","displayName":"Comma-separated list of proxy bypass rules (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode","displayName":"Configure proxy server settings (User)","description":"Specify the proxy server settings used by Microsoft Edge. If you enable this policy, users can't change the proxy settings.\r\n\r\nIf you choose to never use a proxy server and to always connect directly, all other options are ignored.\r\n\r\nIf you choose to use system proxy settings, all other options are ignored.\r\n\r\nIf you choose to auto detect the proxy server, all other options are ignored.\r\n\r\nIf you choose fixed server proxy mode, you can specify further options in 'ProxyServer' (Configure address or URL of proxy server) and 'Comma-separated list of proxy bypass rules'.\r\n\r\nIf you choose to use a .pac proxy script, you must specify the URL to the script in 'URL to a proxy .pac file'.\r\n\r\nFor detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.\r\n\r\nIf you enable this policy, Microsoft Edge will ignore all proxy-related options specified from the command line.\r\n\r\nIf you don't configure this policy users can choose their own proxy settings.\r\n\r\n* \"direct\" = Never use a proxy\r\n\r\n* \"auto_detect\" = Auto detect proxy settings\r\n\r\n* \"pac_script\" = Use a .pac proxy script\r\n\r\n* \"fixed_servers\" = Use fixed proxy servers\r\n\r\n* \"system\" = Use system proxy settings\r\n\r\nExample value: direct","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_proxymode","displayName":"Configure proxy server settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_proxymode_direct","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_proxymode_auto_detect","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_proxymode_pac_script","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_proxymode_fixed_servers","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_proxymode_system","displayName":"Use system proxy settings","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxypacurl","displayName":"Set the proxy .pac file URL (User)","description":"Specifies the URL for a proxy auto-config (PAC) file.\r\n\r\nThis policy is applied only if you selected 'Use a .pac proxy script' in the 'ProxyMode' (Configure proxy server settings) policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\r\n\r\nIf you enable this policy, you can specify the URL for a PAC file, which defines how the browser automatically chooses the appropriate proxy server for fetching a particular website.\r\n\r\nIf you disable or don't configure this policy, no PAC file is specified. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\r\n\r\nFor detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.\r\n\r\nExample value: https://internal.contoso.com/example.pac","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxypacurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxypacurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxypacurl_proxypacurl","displayName":"Set the proxy .pac file URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxyserver","displayName":"Configure address or URL of proxy server (User)","description":"Specifies the URL of the proxy server.\r\n\r\nThis policy is applied only if you have selected 'Use fixed proxy servers' in the 'ProxyMode' (Configure proxy server settings) policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\r\n\r\nIf you enable this policy, the proxy server configured by this policy will be used for all URLs.\r\n\r\nIf you disable or don't configure this policy, users can choose their own proxy settings while in this proxy mode. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\r\n\r\nFor more options and detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.\r\n\r\nExample value: 123.123.123.123:8080","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxyserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxyserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxyserver_proxyserver","displayName":"Configure address or URL of proxy server (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxysettings","displayName":"Proxy settings (User)","description":"Configures the proxy settings for Microsoft Edge.\r\n\r\nIf you enable this policy, Microsoft Edge ignores all proxy-related options specified from the command line.\r\n\r\nIf you don't configure this policy, users can choose their own proxy settings.\r\n\r\nThis policy overrides the following individual policies:\r\n\r\n'ProxyMode' (Configure proxy server settings)\r\n'ProxyPacUrl' (Set the proxy .pac file URL)\r\n'ProxyServer' (Configure address or URL of proxy server)\r\n'ProxyBypassList' (Configure proxy bypass rules)\r\n\r\nThe ProxyMode field lets you specify the proxy server used by Microsoft Edge and prevents users from changing proxy settings.\r\n\r\nThe ProxyPacUrl field is a URL to a proxy .pac file.\r\n\r\nThe ProxyServer field is a URL for the proxy server.\r\n\r\nThe ProxyBypassList field is a list of proxy hosts that Microsoft Edge bypasses.\r\n\r\nIf you choose the 'direct' value as 'ProxyMode', a proxy is never used and all other fields are ignored.\r\n\r\nIf you choose the 'system' value as 'ProxyMode', the systems's proxy is used and all other fields are ignored.\r\n\r\nIf you choose the 'auto_detect' value as 'ProxyMode', all other fields are ignored.\r\n\r\nIf you choose the 'fixed_server' value as 'ProxyMode', the 'ProxyServer' and 'ProxyBypassList' fields are used.\r\n\r\nIf you choose the 'pac_script' value as 'ProxyMode', the 'ProxyPacUrl' and 'ProxyBypassList' fields are used.\r\n\r\nExample value:\r\n\r\n{\r\n \"ProxyMode\": \"direct\", \r\n \"ProxyPacUrl\": \"https://internal.site/example.pac\", \r\n \"ProxyServer\": \"123.123.123.123:8080\", \r\n \"ProxyBypassList\": \"https://www.example1.com,https://www.example2.com,https://internalsite/\"\r\n}","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxysettings_proxysettings","displayName":"Proxy settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverride","displayName":"Prevent bypassing Microsoft Defender SmartScreen prompts for sites (User)","description":"This policy setting lets you decide whether users can override the Microsoft Defender SmartScreen warnings about potentially malicious websites.\r\n\r\nIf you enable this setting, users can't ignore Microsoft Defender SmartScreen warnings and they are blocked from continuing to the site.\r\n\r\nIf you disable or don't configure this setting, users can ignore Microsoft Defender SmartScreen warnings and continue to the site.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverride_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverride_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverrideforfiles","displayName":"Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads (User)","description":"This policy lets you determine whether users can override Microsoft Defender SmartScreen warnings about unverified downloads.\r\n\r\nIf you enable this policy, users in your organization can't ignore Microsoft Defender SmartScreen warnings, and they're prevented from completing the unverified downloads.\r\n\r\nIf you disable or don't configure this policy, users can ignore Microsoft Defender SmartScreen warnings and complete unverified downloads.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverrideforfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverrideforfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains","displayName":"Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings (User)","description":"Configure the list of Microsoft Defender SmartScreen trusted domains. This means:\r\nMicrosoft Defender SmartScreen won't check for potentially malicious resources like phishing software and other malware if the source URLs match these domains.\r\nThe Microsoft Defender SmartScreen download protection service won't check downloads hosted on these domains.\r\n\r\nIf you enable this policy, Microsoft Defender SmartScreen trusts these domains.\r\nIf you disable or don't set this policy, default Microsoft Defender SmartScreen protection is applied to all resources.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender Advanced Threat Protection. You must configure your allow and block lists in Microsoft Defender Security Center instead.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains_smartscreenallowlistdomainsdesc","displayName":"Configure the list of domains for which SmartScreen won't trigger warnings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenenabled","displayName":"Configure Microsoft Defender SmartScreen (User)","description":"This policy setting lets you configure whether to turn on Microsoft Defender SmartScreen. Microsoft Defender SmartScreen provides warning messages to help protect your users from potential phishing scams and malicious software. By default, Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you enable this setting, Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepageisnewtabpage","displayName":"Set the new tab page as the home page (User)","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\r\n\r\nIf you enable this policy, the new tab page is always used for the home page, and the home page URL location is ignored.\r\n\r\nIf you disable this policy, the user's home page can't be the new tab page, unless the URL is set to 'edge://newtab'.\r\n\r\nIf not configured users can choose whether the new tab page is their home page.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepageisnewtabpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepageisnewtabpage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation","displayName":"Configure the home page URL (User)","description":"Configures the default home page URL in Microsoft Edge.\r\n\r\nThe home page is the page opened by the Home button. The pages that open on startup are controlled by the 'RestoreOnStartup' (Action to take on startup) policies.\r\n\r\nYou can either set a URL here or set the home page to open the new tab page. If you select to open the new tab page, then this policy doesn't take effect.\r\n\r\nIf you enable this policy, users can't change their home page URL, but they can choose to use the new tab page as their home page.\r\n\r\nIf you disable or don't configure this policy, users can choose their own home page, as long as the 'HomepageIsNewTabPage' (Set the new tab page as the home page) policy isn't enabled.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\nExample value: https://www.contoso.com","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation_homepagelocation","displayName":"Home page URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagehidedefaulttopsites","displayName":"Hide the default top sites from the new tab page (User)","description":"Hides the default top sites from the new tab page in Microsoft Edge.\r\n\r\nIf you set this policy to true, the default top site tiles are hidden.\r\n\r\nIf you set this policy to false or don't configure it, the default top site tiles remain visible.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagehidedefaulttopsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagehidedefaulttopsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation","displayName":"Configure the new tab page URL (User)","description":"Configures the default URL for the new tab page.\r\n\r\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\r\n\r\nThis policy doesn't determine which page opens on startup; that's controlled by the 'RestoreOnStartup' (Action to take on startup) policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\r\n\r\nIf you don't configure this policy, the default new tab page is used.\r\n\r\nIf you configure this policy *and* the 'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) policy, this policy has precedence.\r\n\r\nIf an invalid URL is provided, new tabs will open about://blank.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation_newtabpagelocation","displayName":"New tab page URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'Open new tab' (5).\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'Restore the last session' (1). The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'Open a list of URLs' (4).\r\n\r\nDisabling this setting is equivalent to leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\n* 1 = Restore the last session\r\n\r\n* 4 = Open a list of URLs\r\n\r\n* 5 = Open a new tab","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup","displayName":"Action to take on startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartupurls","displayName":"Sites to open when the browser starts (User)","description":"Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup.\r\n\r\nThis policy only works if you also set the 'RestoreOnStartup' (Action to take on startup) policy to 'Open a list of URLs' (4).\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com\r\nhttps://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartupurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartupurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartupurls_restoreonstartupurlsdesc","displayName":"Sites to open when the browser starts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_showhomebutton","displayName":"Show Home button on toolbar (User)","description":"Shows the Home button on Microsoft Edge's toolbar.\r\n\r\nEnable this policy to always show the Home button. Disable it to never show the button.\r\n\r\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_showhomebutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_showhomebutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions","displayName":"Allow download restrictions (User)","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'BlockDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known or potentially dangerous downloads or that have dangerous file type extensions.\r\n\r\nSet 'BlockPotentiallyDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous or unwanted downloads or that have dangerous file type extensions.\r\n\r\nSet 'BlockAllDownloads' to block all downloads.\r\n\r\nSet 'BlockMaliciousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known malicious downloads.\r\n\r\nIf you don't configure this policy or set the 'DefaultDownloadSecurity' option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\nPolicy options mapping:\r\n\r\n* DefaultDownloadSecurity (0) = No special restrictions\r\n\r\n* BlockDangerousDownloads (1) = Block malicious downloads and dangerous file types\r\n\r\n* BlockPotentiallyDangerousDownloads (2) = Block potentially dangerous or unwanted downloads and dangerous file types\r\n\r\n* BlockAllDownloads (3) = Block all downloads\r\n\r\n* BlockMaliciousDownloads (4) = Block malicious downloads\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions","displayName":"Download restrictions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_2","displayName":"Block potentially dangerous or unwanted downloads and dangerous file types","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_4","displayName":"Block malicious downloads","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended","displayName":"Allow download restrictions (User)","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'BlockDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known or potentially dangerous downloads or that have dangerous file type extensions.\r\n\r\nSet 'BlockPotentiallyDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous or unwanted downloads or that have dangerous file type extensions.\r\n\r\nSet 'BlockAllDownloads' to block all downloads.\r\n\r\nSet 'BlockMaliciousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known malicious downloads.\r\n\r\nIf you don't configure this policy or set the 'DefaultDownloadSecurity' option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\nPolicy options mapping:\r\n\r\n* DefaultDownloadSecurity (0) = No special restrictions\r\n\r\n* BlockDangerousDownloads (1) = Block malicious downloads and dangerous file types\r\n\r\n* BlockPotentiallyDangerousDownloads (2) = Block potentially dangerous or unwanted downloads and dangerous file types\r\n\r\n* BlockAllDownloads (3) = Block all downloads\r\n\r\n* BlockMaliciousDownloads (4) = Block malicious downloads\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions","displayName":"Download restrictions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_2","displayName":"Block potentially dangerous or unwanted downloads and dangerous file types","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_4","displayName":"Block malicious downloads","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_adstransparencyenabled","displayName":"Configure if the ads transparency feature is enabled (User)","description":"Lets you decide whether the ads transparency feature is enabled. This behavior only applies to the \"balanced\" mode of tracking prevention, and does not impact \"basic\" or \"strict\" modes. Your users' tracking prevention level can be configured using the 'TrackingPrevention' (Block tracking of users' web-browsing activity) policy. AdsTransparencyEnabled will only have an effect if 'TrackingPrevention' is set to TrackingPreventionBalanced or is not configured.\r\n\r\nIf you enable or don't configure this policy, transparency metadata provided by ads will be available to the user when the feature is active.\r\n\r\nWhen the feature is enabled, Tracking Prevention will enable exceptions for the associated ad providers that have met Microsoft's privacy standards.\r\n\r\nIf you disable this policy, Tracking Prevention will not adjust its behavior even when transparency metadata is provided by ads.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_adstransparencyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_adstransparencyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_hiderestoredialogenabled","displayName":"Hide restore pages dialog after browser crash (User)","description":"This policy gives an option to hide the \"Restore pages\" dialog after Microsoft Edge has crashed. The \"Restore pages\" dialog gives users the option to restore the pages that were previously open before Microsoft Edge crashed.\r\n\r\nIf you enable this policy, the \"Restore pages\" dialog will not be shown. In the event of a crash, Microsoft Edge will not restore previous tabs and will start the session with a new tab page.\r\n\r\nIf you disable or don't set this policy, the \"Restore pages\" dialog will be shown.\r\n\r\nIf you set this policy, do not set the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) or 'SavingBrowserHistoryDisabled' (Disable saving browser history) policy since that prevents history from being saved which also disables the dialog.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_hiderestoredialogenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_hiderestoredialogenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_pdfsecuremode","displayName":"Secure mode and Certificate-based Digital Signature validation in native PDF reader (User)","description":"The policy enables Digital Signature validation for PDF files in a secure environment, which shows the correct validation status of the signatures.\r\n\r\nIf you enable this policy, PDF files with Certificate-based digital signatures are opened with an option to view and verify the validity of the signatures with high security.\r\n\r\nIf you disable or don't configure this policy, the capability to view and verify the signature will not be available.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_pdfsecuremode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_pdfsecuremode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_promptonmultiplematchingcertificates","displayName":"Prompt the user to select a certificate when multiple certificates match (User)","description":"This policy controls whether the user is prompted to select a client certificate when more than one certificate matches 'AutoSelectCertificateForUrls' (Automatically select client certificates for these sites).\r\nIf this policy is set to True, the user is prompted to select a client certificate whenever the auto-selection policy matches multiple certificates.\r\nIf this policy is set to False or not set, the user may only be prompted when no certificate matches the auto-selection.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_promptonmultiplematchingcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_promptonmultiplematchingcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting","displayName":"Control use of the WebHID API (User)","description":"Setting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.\r\n\r\nThis policy can be overridden for specific url patterns using the 'WebHidAskForUrls' (Allow the WebHID API on these sites) and 'WebHidBlockedForUrls' (Block the WebHID API on these sites) policies.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockWebHid (2) = Do not allow any site to request access to HID devices via the WebHID API\r\n\r\n* AskWebHid (3) = Allow sites to ask the user to grant access to a HID device\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_defaultwebhidguardsetting","displayName":"Control use of the WebHID API (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_defaultwebhidguardsetting_2","displayName":"Do not allow any site to request access to HID devices via the WebHID API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_defaultwebhidguardsetting_3","displayName":"Allow sites to ask the user to grant access to a HID device","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls","displayName":"Allow the WebHID API on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\r\n\r\n * 'WebHidBlockedForUrls' (Block the WebHID API on these sites) (if there is a match),\r\n\r\n * 'DefaultWebHidGuardSetting' (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns must not conflict with 'WebHidBlockedForUrls'. Neither policy takes precedence if a URL matches both patterns.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://microsoft.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_webhidaskforurlsdesc","displayName":"Allow the WebHID API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidblockedforurls","displayName":"Block the WebHID API on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\r\n\r\n * 'WebHidAskForUrls' (Allow the WebHID API on these sites) (if there is a match),\r\n\r\n * 'DefaultWebHidGuardSetting' (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns can't conflict with 'WebHidAskForUrls'. Neither policy takes precedence if a URL matches both patterns.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://microsoft.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidblockedforurls_webhidblockedforurlsdesc","displayName":"Block the WebHID API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts","displayName":"Configure the list of commands for which to disable keyboard shortcuts (User)","description":"Configure the list of Microsoft Edge commands for which to disable keyboard shortcuts.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2186950 for a list of possible commands to disable.\r\n\r\nIf you enable this policy, commands in the 'disabled' list will no longer be activated by keyboard shortcuts.\r\n\r\nIf you disable this policy, all keyboard shortcuts behave as usual.\r\n\r\nNote: Disabling a command will only remove its shortcut mapping. Commands in the 'disabled' list will still function if accessed via browser UI.\r\n\r\nExample value:\r\n\r\n{\r\n \"disabled\": [\r\n \"new_tab\",\r\n \"fullscreen\"\r\n ]\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"disabled\": [\"new_tab\", \"fullscreen\"]}","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts_configurekeyboardshortcuts","displayName":"Configure the list of commands for which to disable keyboard shortcuts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_edgeassetdeliveryserviceenabled","displayName":"Allow features to download assets from the Asset Delivery Service (User)","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\r\nThese assets can be config files or Machine Learning models that power the features that use this service.\r\n\r\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\r\n\r\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_edgeassetdeliveryserviceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_edgeassetdeliveryserviceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_internetexplorermodeenablesavepageas","displayName":"Allow Save page as in Internet Explorer mode (User)","description":"This policy enables 'Save page as' functionality in Internet Explorer mode.\r\nUsers can use this option to save the current page in the browser. When a user re-opens a saved page, it will be loaded in the default browser.\r\n\r\nIf you enable this policy, the \"Save page as\" option will be clickable in \"More tools\".\r\n\r\nIf you disable or don't configure this policy, users can't select the \"Save page as\" option in \"More tools\".\r\n\r\nNote: To make the \"Ctrl+S\" shortcut work, users must enable the Internet Explorer policy, 'Enable extended hot key in Internet Explorer mode'.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_internetexplorermodeenablesavepageas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_internetexplorermodeenablesavepageas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_edgeassetdeliveryserviceenabled_recommended","displayName":"Allow features to download assets from the Asset Delivery Service (User)","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\r\nThese assets can be config files or Machine Learning models that power the features that use this service.\r\n\r\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\r\n\r\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_edgeassetdeliveryserviceenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_edgeassetdeliveryserviceenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_sitesafetyservicesenabled_recommended","displayName":"Allow users to configure Site safety services (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nThis policy is obselete as the feature is being removed after Microsoft Edge version 127.\r\n\r\nThis policy disables site safety services from showing top site info in the page info dialog.\r\n\r\nIf you enable this policy or don't configure it, the top site info will be shown.\r\n\r\nIf you disable this policy, the top site info will not be shown.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_sitesafetyservicesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_sitesafetyservicesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended~extensions_recommended_controldefaultstateofallowextensionfromotherstoressettingenabled_recommended","displayName":"Configure default state of Allow extensions from other stores setting (User)","description":"This policy allows you to control the default state of the Allow extensions from other stores setting.\r\nThis policy can't be used to stop installation of extensions from other stores such as Chrome Web Store.\r\nTo stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098.\r\n\r\nWhen enabled, Allow extensions from other stores will be turned on. So, users won't have to turn on the flag manually\r\nwhile installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting.\r\nIf the user has already turned on the setting and then turned it off, this setting may not work.\r\nIf the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it will have no impact on\r\nuser settings and the setting will remain as it is.\r\n\r\nWhen disabled or not configured, the user can manage the Allow extensions from other store setting.","helpText":"","infoUrls":[],"categoryId":"b96b63eb-0292-4a73-85d7-c68d330c109e","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended~extensions_recommended_controldefaultstateofallowextensionfromotherstoressettingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended~extensions_recommended_controldefaultstateofallowextensionfromotherstoressettingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_sitesafetyservicesenabled","displayName":"Allow users to configure Site safety services (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nThis policy is obselete as the feature is being removed after Microsoft Edge version 127.\r\n\r\nThis policy disables site safety services from showing top site info in the page info dialog.\r\n\r\nIf you enable this policy or don't configure it, the top site info will be shown.\r\n\r\nIf you disable this policy, the top site info will not be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_sitesafetyservicesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_sitesafetyservicesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled","displayName":"Default Profile Setting Enabled (User)","description":"Configuring this policy will let you set a default profile in Microsoft Edge to be used when opening the browser rather than the last profile used. This policy won't affect when \"--profile-directory\" parameter has been specified. Set the value to \"Default\" to refer to the default profile. The value is case sensitive.\r\nThe value of the policy is the name of the profile (case sensitive) and can be configured with string that is the name of a specific profile.\r\nThe value \"Edge Kids Mode\" and \"Guest Profile\" are considered not useful values because they not supposed to be a default profile.\r\nThis policy won't impact the following scenarios:\r\n 1) Settings specified in \"Profile preferences for sites\" in \"Profile preferences\"\r\n 2) Links opening from Outlook and Teams.\r\n\r\nThe following statements are under the condition of not specify the \"--profile-directory\" and configured value is not \"Edge Kids Mode\" or \"Guest Profile\":\r\nIf you enable this policy and configure it with a specific profile name and the specified profile can be found, Microsoft Edge will use the specified profile when launching and the setting of \"Default profile for external link\" is changed to the specified profile name and greyed out.\r\nIf you enable this policy and configure it with a specific profile name but it can't be found, the policy will behave like it's never been set before.\r\nIf you enable this policy, but don't configure or disable it, the policy will behave like it's never been set before.\r\n\r\nExample value: Default","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled_edgedefaultprofileenabled","displayName":"Default Profile Setting Enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~kioskmode_kioskswipegesturesenabled","displayName":"Swipe gestures in Microsoft Edge kiosk mode enabled (User)","description":"This policy only applies to Microsoft Edge kiosk mode.\r\n\r\nIf you enable this policy or don't configure it, swipe gestures will behave as expected.\r\n\r\nIf you disable this policy, the user will not be able to use swipe gestures (for example navigate forwards and backwards, refresh page).\r\n\r\nFor detailed information on configuring kiosk mode, see https://go.microsoft.com/fwlink/?linkid=2137578.","helpText":"","infoUrls":[],"categoryId":"d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","categoryName":"Kiosk Mode settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~kioskmode_kioskswipegesturesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~kioskmode_kioskswipegesturesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_networkservicesandboxenabled","displayName":"Enable the network service sandbox (User)","description":"This policy controls whether or not the network service process runs sandboxed.\r\nIf this policy is enabled, the network service process will run sandboxed.\r\nIf this policy is disabled, the network service process will run unsandboxed. This leaves users open to additional security risks related to running the network service unsandboxed.\r\nIf this policy is not set, the default configuration for the network sandbox will be used. This may vary depending on Microsoft Edge release, currently running field trials, and platform.\r\nThis policy is intended to give enterprises flexibility to disable the network sandbox if they use third party software that interferes with the network service sandbox.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_networkservicesandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_networkservicesandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_outlookhubmenuenabled","displayName":"Allow users to access the Outlook menu (User)","description":"This policy is used to manage access to the Outlook menu from Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, users can access the Outlook menu.\r\nIf you disable this policy, users can't access the Outlook menu.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_outlookhubmenuenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_outlookhubmenuenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_recommended_outlookhubmenuenabled_recommended","displayName":"Allow users to access the Outlook menu (User)","description":"This policy is used to manage access to the Outlook menu from Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, users can access the Outlook menu.\r\nIf you disable this policy, users can't access the Outlook menu.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_recommended_outlookhubmenuenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_recommended_outlookhubmenuenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_settimeoutwithout1msclampenabled","displayName":"Control Javascript setTimeout() function minimum timeout (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nWhen the policy is set to Enabled, the Javascript setTimeout() with a timeout of 0ms will no longer be fixed to 1ms to schedule timer-based callbacks.\r\nWhen the policy is set to Disabled, the Javascript setTimeout() with a timeout of 0ms will be fixed to 1ms to schedule timer-based callbacks.\r\nWhen the policy is unset, use the browser's default behavior for setTimeout() function.\r\n\r\nThis is a web standards compliancy feature, but it may change task ordering on a web page, leading to unexpected behavior on sites that are dependent on a certain ordering.\r\nIt also may affect sites with a lot of setTimeout()s with a timeout of 0ms usage. For example, increasing CPU load.\r\n\r\nFor users where this policy is unset, Microsoft Edge Stable will roll out the change gradually on the stable channel.\r\n\r\nThis is a temporary policy that is planned to be removed in Microsoft Edge Stable 105.\r\nThis deadline may be extended if there is a need for enterprises.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_settimeoutwithout1msclampenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_settimeoutwithout1msclampenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_useragentclienthintsgreaseupdateenabled","displayName":"Control the User-Agent Client Hints GREASE Update feature (User)","description":"The User-Agent GREASE specification recommends the inclusion of additional GREASE characters beyond the current semicolon and space, and recommends that the arbitrary version number be varied over time.\r\n\r\nWhen enabled, the User-Agent Client Hints GREASE Update feature aligns the User-Agent GREASE algorithm with the latest version from the specification. The updated specification may break some websites that restrict the characters that requests may contain. For more information, see the following specification: https://wicg.github.io/ua-client-hints/#grease\r\n\r\nIf this policy is enabled or not configured, the User-Agent GREASE algorithm from the specification will be used. If the policy is disabled, the prior User-Agent GREASE algorithm will be used.\r\n\r\nThis policy is a temporary measure and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_useragentclienthintsgreaseupdateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_useragentclienthintsgreaseupdateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge~httpauthentication_allhttpauthschemesallowedfororigins","displayName":"List of origins that allow all HTTP authentication (User)","description":"Set this policy to specify which origins allow all the HTTP authentication schemes Microsoft Edge supports regardless of the 'AuthSchemes' (Supported authentication schemes) policy.\r\n\r\nFormat the origin pattern according to this format (https://support.google.com/chrome/a?p=url_blocklist_filter_format). Up to 1,000 exceptions can be defined in 'AllHttpAuthSchemesAllowedForOrigins' (List of origins that allow all HTTP authentication).\r\nWildcards are allowed for the whole origin or parts of the origin. Parts include the scheme, host, or port.\r\n\r\nExample value:\r\n\r\n*.example.com","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge~httpauthentication_allhttpauthschemesallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge~httpauthentication_allhttpauthschemesallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge~httpauthentication_allhttpauthschemesallowedfororigins_allhttpauthschemesallowedfororiginsdesc","displayName":"List of origins that allow all HTTP authentication (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_internetexplorerzoomdisplay","displayName":"Display zoom in IE Mode tabs with DPI Scale included like it is in Internet Explorer (User)","description":"Lets you display zoom in IE Mode tabs similar to how it was displayed in Internet Explorer, where the DPI scale of the display is factored in.\r\n\r\nFor example, if you have a page zoomed to 200% on a 100 DPI scale display and you change the display to 150 DPI, Microsoft Edge would still display the zoom as 200%. However, Internet Explorer factors in the DPI scale and displays 300%.\r\n\r\nIf you enable this policy, zoom values will be displayed with the DPI scale included for IE Mode tabs.\r\n\r\nIf you disable or don't configure this policy, zoom values will be displayed without DPI scale included for IE Mode tabs","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_internetexplorerzoomdisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_internetexplorerzoomdisplay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_livecaptionsallowed","displayName":"Live captions allowed (User)","description":"Allow users to turn the Live captions feature on or off.\r\n\r\nLive captions is an accessibility feature that converts speech from the audio that plays in Microsoft Edge in to text and shows this text in a separate window. The entire process happens on the device and no audio or caption text ever leaves the device.\r\n\r\nNote: This feature is not generally available. Clients that have the 'ExperimentationAndConfigurationServiceControl' (Control communication with the Experimentation and Configuration Service) policy set to 'FullMode' may receive the feature before broad availability. Broad availability will be announced via Microsoft Edge release notes.\r\n\r\nIf you enable or don't configure this policy, users can turn this feature on or off at edge://settings/accessibility.\r\n\r\nIf you disable this policy, users will not be able to turn this accessibility feature on. If speech recognition files have been downloaded previously, they will be deleted from the device in 30 days. We recommend avoiding this option unless it's needed in your environment.\r\n\r\nIf users choose to turn on Live captions, speech recognition files (approximately 100 megabytes) will be downloaded to the device on first run and then periodically to improve performance and accuracy. These files will be deleted after 30 days.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_livecaptionsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_livecaptionsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_originagentclusterdefaultenabled","displayName":"Origin-keyed agent clustering enabled by default (User)","description":"The Origin-Agent-Cluster: HTTP header controls whether a document is isolated in an origin-keyed agent cluster or in a site-keyed agent cluster. This has security implications because an origin-keyed agent cluster allows isolating documents by origin. The consequence of this for developers is that the document.domain accessor can no longer be set when origin-keyed agent clustering is enabled.\r\n\r\nIf you enable or don't configure this policy, documents without the Origin-Agent-Cluster: header will be assigned to origin-keyed agent clustering by default. On these documents, the document.domain accessor will not be settable.\r\n\r\nIf you disable this policy, documents without the Origin-Agent-Cluster: header will be assigned to site-keyed agent clusters by default. On these documents, the document.domain accessor will be settable.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2191896 for additional details.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_originagentclusterdefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_originagentclusterdefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled","displayName":"Guided Switch Enabled (User)","description":"Allows Microsoft Edge to prompt the user to switch to the appropriate profile when Microsoft Edge detects that a link is a personal or work link.\r\n\r\nIf you enable this policy, you'll be prompted to switch to another account if the current profile doesn't work for the requesting link.\r\n\r\nIf you disable this policy, you won't be prompted to switch to another account when there's a profile and link mismatch.\r\n\r\nIf this policy isn't configured, guided switch is turned on by default. A user can override this value in the browser settings.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace (User)","description":"Setting the policy on Microsoft Edge turns on the restricted sign-in feature in Google Workspace and prevents users from changing this setting. Users can only access Google tools using accounts from the specified domains. To allow gmail or googlemail accounts, add consumer_accounts to the list of domains. This policy is based on the Chrome policy of the same name.\r\n\r\nIf you don't provide a domain name or leave this policy unset, users can access Google Workspace with any account.\r\n\r\nUsers cannot change or override this setting.\r\n\r\nNote: This policy causes the X-GoogApps-Allowed-Domains header to be appended to all HTTP and HTTPS requests to all google.com domains, as described in https://go.microsoft.com/fwlink/?linkid=2197973.\r\n\r\nExample value: example.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_alloweddomainsforapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_alloweddomainsforapps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_alloweddomainsforapps_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_askbeforecloseenabled","displayName":"Get user confirmation before closing a browser window with multiple tabs (User)","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\r\n\r\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\r\n\r\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_askbeforecloseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_askbeforecloseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting","displayName":"Configure browser process code integrity guard setting (User)","description":"This policy controls the use of code integrity guard in the browser process, which only allows Microsoft signed binaries to load.\r\n\r\nSetting this policy to Enabled will enable code integrity guard in the browser process.\r\n\r\nSetting this policy to Disabled, or if the policy is not set, will prevent the browser from enabling code integrity guard in the browser process.\r\n\r\nThe policy value Audit (1) is obsolete as of version 110. Setting this value is equivalent to the Disabled value.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro or Enterprise instances that enrolled for device management.\r\n\r\nThis policy will only take effect on Windows 10 RS2 and above.\r\n\r\nPolicy options mapping:\r\n\r\n* Disabled (0) = Do not enable code integrity guard in the browser process.\r\n\r\n* Audit (1) = Enable code integrity guard audit mode in the browser process.\r\n\r\n* Enabled (2) = Enable code integrity guard enforcement in the browser process.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_browsercodeintegritysetting","displayName":"Configure browser process code integrity guard setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_browsercodeintegritysetting_0","displayName":"Do not enable code integrity guard in the browser process.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_browsercodeintegritysetting_1","displayName":"Enable code integrity guard audit mode in the browser process.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_browsercodeintegritysetting_2","displayName":"Enable code integrity guard enforcement in the browser process.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_doubleclickclosetabenabled","displayName":"Double Click feature in Microsoft Edge enabled (only available in China) (User)","description":"This policy lets you configure the double click feature in Microsoft Edge.\r\n\r\nDouble Click lets users close a tab by double clicking the left mouse button.\r\n\r\nIf you enable or don't configure this policy, you can use the double click feature to close a tab on Microsoft Edge to start using this feature.\r\n\r\nIf you disable this policy, you can't use the double click feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_doubleclickclosetabenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_doubleclickclosetabenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_edgeedropenabled","displayName":"Enable Drop feature in Microsoft Edge (User)","description":"This policy lets you configure the Drop feature in Microsoft Edge.\r\n\r\nDrop lets users send messages or files to themselves.\r\n\r\nIf you enable or don't configure this policy, you can use the Drop feature in Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Drop feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_edgeedropenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_edgeedropenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_importoneachlaunch","displayName":"Allow import of data from other browsers on each Microsoft Edge launch (User)","description":"If you enable this policy, users will see a prompt to import their browsing data from other browsers on each Microsoft Edge launch.\r\n\r\nIf you disable this policy, users will never see a prompt to import their browsing data from other browsers on each Microsoft Edge launch.\r\n\r\nIf the policy is left unconfigured, users can activate this feature from a Microsoft Edge prompt or from the Settings page.\r\n\r\nNote: A similar policy named 'AutoImportAtFirstRun' (Automatically import another browser's data and settings at first run) exists. This policy should be used if you want to import supported data from other browsers only once while setting up your device.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_importoneachlaunch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_importoneachlaunch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_pdfxfaenabled","displayName":"XFA support in native PDF reader enabled (User)","description":"Lets the Microsoft Edge browser enable XFA (XML Forms Architecture) support in the native PDF reader and allows users to open XFA PDF files in the browser.\r\n\r\nIf you enable this policy, XFA support in the native PDF reader will be enabled.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not enable XFA support in the native PDF reader.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_pdfxfaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_pdfxfaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_quicksearchshowminimenu","displayName":"Enables Microsoft Edge mini menu (User)","description":"Enables Microsoft Edge mini menu on websites and PDFs. The mini menu is triggered on text selection and has basic actions like copy and smart actions like definitions.\r\n\r\nIf you enable or don't config this policy, selecting text on websites and PDFs will show the Microsoft Edge mini menu.\r\n\r\nIf you disable this policy, the Microsoft Edge mini menu will not be shown when text on websites and PDFs is selected.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_quicksearchshowminimenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_quicksearchshowminimenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_askbeforecloseenabled_recommended","displayName":"Get user confirmation before closing a browser window with multiple tabs (User)","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\r\n\r\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\r\n\r\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_askbeforecloseenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_askbeforecloseenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_quicksearchshowminimenu_recommended","displayName":"Enables Microsoft Edge mini menu (User)","description":"Enables Microsoft Edge mini menu on websites and PDFs. The mini menu is triggered on text selection and has basic actions like copy and smart actions like definitions.\r\n\r\nIf you enable or don't config this policy, selecting text on websites and PDFs will show the Microsoft Edge mini menu.\r\n\r\nIf you disable this policy, the Microsoft Edge mini menu will not be shown when text on websites and PDFs is selected.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_quicksearchshowminimenu_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_quicksearchshowminimenu_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_textpredictionenabled","displayName":"Text prediction enabled by default (User)","description":"The Microsoft Turing service uses natural language processing to generate predictions for long-form editable text fields on web pages.\r\n\r\nIf you enable or don't configure this policy, text predictions will be provided for eligible text fields.\r\n\r\nIf you disable this policy, text predictions will not be provided in eligible text fields. Sites may still provide their own text predictions.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_textpredictionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_textpredictionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge~passwordmanager_passwordmanagerrestrictlengthenabled","displayName":"Restrict the length of passwords that can be saved in the Password Manager (User)","description":"Make Microsoft Edge restrict the length of usernames and/or passwords that can be saved in the Password Manager.\r\n\r\nIf you enable this policy, Microsoft Edge will not let the user save credentials with usernames and/or passwords longer than 256 characters.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will let the user save credentials with arbitrarily long usernames and/or passwords.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge~passwordmanager_passwordmanagerrestrictlengthenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge~passwordmanager_passwordmanagerrestrictlengthenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_exemptfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (User)","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users would not see a warning when downloading \"jnlp\" files from \"website1.com\", but see a download warning when downloading \"jnlp\" files from \"website2.com\".\r\n\r\nFiles with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\r\n\r\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.\r\n\r\nIf you enable this policy:\r\n\r\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list \"jnlp\" should be used instead of \".jnlp\".\r\n\r\nExample:\r\n\r\nThe following example value would prevent file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\r\n\r\n[\r\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\r\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\r\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\r\n]\r\n\r\nNote that while the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"domains\": [\r\n \"https://contoso.com\",\r\n \"contoso2.com\"\r\n ],\r\n \"file_extension\": \"jnlp\"\r\n },\r\n {\r\n \"domains\": [\r\n \"*\"\r\n ],\r\n \"file_extension\": \"swf\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_exemptfiletypedownloadwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_exemptfiletypedownloadwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_exemptfiletypedownloadwarnings_exemptfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_internetexplorerintegrationalwayswaitforunload","displayName":"Wait for Internet Explorer mode tabs to completely unload before ending the browser session (User)","description":"This policy causes Microsoft Edge to continue running until all Internet Explorer tabs have completely finished unloading. This allows Internet Explorer plugins like ActiveX controls to perform additional critical work even after the browser has been closed. However, this can cause stability and performance issues, and Microsoft Edge processes may remain active in the background with no visible windows if the webpage or plugin prevents Internet Explorer from unloading. This policy should only be used if your organization depends on a plugin that requires this behavior.\r\n\r\nIf you enable this policy, Microsoft Edge will always wait for Internet Explorer mode tabs to fully unload before ending the browser session.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not always wait for Internet Explorer mode tabs to fully unload before ending the browser session.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2174004","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_internetexplorerintegrationalwayswaitforunload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_internetexplorerintegrationalwayswaitforunload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled","displayName":"Spell checking provided by Microsoft Editor (User)","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages.\r\n\r\nIf you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields.\r\n\r\nIf you disable this policy, spell check can only be provided by local engines that use platform or Hunspell services. The results from these engines might be less informative than the results Microsoft Editor can provide.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy is set to disabled, or the user disables spell checking in the settings page, this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorsynonymsenabled","displayName":"Synonyms are provided when using Microsoft Editor spell checker (User)","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages, and synonyms can be suggested as an integrated feature.\r\n\r\nIf you enable this policy, Microsoft Editor spell checker will provide synonyms for suggestions for misspelled words.\r\n\r\nIf you disable or don't configure this policy, Microsoft Editor spell checker will not provide synonyms for suggestions for misspelled words.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy or the 'MicrosoftEditorProofingEnabled' (Spell checking provided by Microsoft Editor) policy are set to disabled, or the user disables spell checking or chooses not to use Microsoft Editor spell checker in the settings page, this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorsynonymsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorsynonymsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (User)","description":"If FriendlyURLs are enabled, Microsoft Edge will compute additional representations of the URL and place them on the clipboard.\r\n\r\nThis policy configures what format will be pasted when the user pastes in external applications, or inside Microsoft Edge without the 'Paste as' context menu item.\r\n\r\nIf configured, this policy makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu will not be available.\r\n\r\n* Not configured = The user will be able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\r\n\r\n* 1 = No additional formats will be stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature will be disabled.\r\n\r\n* 3 = The user will get a friendly URL whenever they paste into surfaces that accept rich text. The plain URL will still be available for non-rich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\r\n\r\n* 4 = (Not currently used)\r\n\r\nThe richer formats may not be well-supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy.\r\n\r\nThe recommended policy is available in Microsoft Edge 105 or later.\r\n\r\nPolicy options mapping:\r\n\r\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\r\n\r\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.\r\n\r\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_configurefriendlyurlformat_1","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_configurefriendlyurlformat_3","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_configurefriendlyurlformat_4","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_unthrottlednestedtimeoutenabled","displayName":"JavaScript setTimeout will not be clamped until a higher nesting threshold is set (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because it is a temporary policy for web standards compliance. It won't work in Microsoft Edge as soon as version 107.\r\nIf you enable this policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4ms, will not be clamped. This improves short horizon performance, but websites abusing the API will still eventually have their setTimeout usages clamped.\r\nIf you disable or don't configure policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4ms, will be clamped.\r\n\r\nThis is a web standards compliancy feature that may change task ordering on a web page, leading to unexpected behavior on sites that are dependent on a certain ordering.\r\nIt also may affect sites with a lot of usage of a timeout of 0ms for setTimeout. For example, increasing CPU load.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_unthrottlednestedtimeoutenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_unthrottlednestedtimeoutenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_internetexplorerintegrationalwaysuseoscapture","displayName":"Always use the OS capture engine to avoid issues with capturing Internet Explorer mode tabs (User)","description":"Configure this policy to control whether Microsoft Edge will use the \"OS capture engine\" or the \"Browser capture engine\" when capturing browser windows in the same process using the screen-share APIs.\r\n\r\nYou should configure this policy if you want to capture the contents of Internet Explorer mode tabs. However, enabling this policy may negatively impact performance when capturing browser windows in the same process.\r\n\r\nThis policy only affects window capture, not tab capture. The contents of Internet Explorer mode tabs will not be captured when you choose to capture only a single tab, even if you configure this policy.\r\n\r\nIf you enable this policy, Microsoft Edge will always use the OS capture engine for window capture. Internet Explorer mode tabs will have their contents captured.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use the Browser capture engine for browser windows in the same process. Internet Explorer mode tabs in these windows will not have their contents captured.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2174004","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_internetexplorerintegrationalwaysuseoscapture_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_internetexplorerintegrationalwaysuseoscapture_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeenabled_recommended","displayName":"Efficiency mode enabled (User)","description":"Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and disabled otherwise.\r\n\r\nIf you enable this policy, efficiency mode will become active according to the setting chosen by the user. You can configure the efficiency mode setting using the 'EfficiencyMode' (Configure when efficiency mode should become active) policy. If the device does not have a battery, efficiency mode will always be active.\r\n\r\nIf you disable this policy, efficiency mode will never become active. The 'EfficiencyMode' and 'EfficiencyModeOnPowerEnabled' (Enable efficiency mode when the device is connected to a power source) policies will have no effect.\r\n\r\nIf you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeonpowerenabled_recommended","displayName":"Enable efficiency mode when the device is connected to a power source (User)","description":"Allows efficiency mode to become active when the device is connected to a power source. On devices with no battery, this policy has no effect.\r\n\r\nIf you enable this policy, efficiency mode will become active when the device is connected to a power source.\r\n\r\nIf you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeonpowerenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeonpowerenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeenabled","displayName":"Efficiency mode enabled (User)","description":"Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and disabled otherwise.\r\n\r\nIf you enable this policy, efficiency mode will become active according to the setting chosen by the user. You can configure the efficiency mode setting using the 'EfficiencyMode' (Configure when efficiency mode should become active) policy. If the device does not have a battery, efficiency mode will always be active.\r\n\r\nIf you disable this policy, efficiency mode will never become active. The 'EfficiencyMode' and 'EfficiencyModeOnPowerEnabled' (Enable efficiency mode when the device is connected to a power source) policies will have no effect.\r\n\r\nIf you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeonpowerenabled","displayName":"Enable efficiency mode when the device is connected to a power source (User)","description":"Allows efficiency mode to become active when the device is connected to a power source. On devices with no battery, this policy has no effect.\r\n\r\nIf you enable this policy, efficiency mode will become active when the device is connected to a power source.\r\n\r\nIf you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeonpowerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeonpowerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~printing_printpdfasimagedefault","displayName":"Print PDF as Image Default (User)","description":"Controls if Microsoft Edge makes the Print as image option the default when printing PDFs.\r\n\r\nIf you enable this policy, Microsoft Edge will default to setting the Print as image option in the Print Preview when printing a PDF.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not default to setting the Print as image option in the Print Preview when printing a PDF.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~printing_printpdfasimagedefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~printing_printpdfasimagedefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_enhancesecuritymodebypassintranet","displayName":"Enhanced Security Mode configuration for Intranet zone sites (User)","description":"Microsoft Edge will apply Enhanced Security Mode on Intranet zone sites by default. This may lead to Intranet zone sites acting in an unexpected manner.\r\n\r\nIf you enable this policy, Microsoft Edge won't apply Enhanced Security Mode on Intranet zone sites.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will apply Enhanced Security Mode on Intranet zone sites.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_enhancesecuritymodebypassintranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_enhancesecuritymodebypassintranet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_eventpathenabled","displayName":"Re-enable the Event.path API until Microsoft Edge version 115 (User)","description":"Starting in Microsoft Edge version 109, the non-standard API Event.path will be removed to improve web compatibility. This policy re-enables the API until version 115.\r\n\r\nIf you enable this policy, the Event.path API will be available.\r\n\r\nIf you disable this policy, the Event.path API will be unavailable.\r\n\r\nIf this policy is not set, the Event.path API will be in the following default states: available before version 109, and unavailable in version 109 to version 114.\r\n\r\nThis policy will be made obsolete after Microsoft Edge version 115.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_eventpathenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_eventpathenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_internetexplorerintegrationlocalmhtfileallowed","displayName":"Allow local MHTML files to open automatically in Internet Explorer mode (User)","description":"This policy controls whether local mht or mhtml files launched from the command line can open automatically in Internet Explorer mode based on the file content without specifying the --ie-mode-file-url command line.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'\r\nand\r\n'InternetExplorerIntegrationLocalFileAllowed' (Allow launching of local files in Internet Explorer mode) is enabled or not configured.\r\n\r\nIf you enable or don't configure this policy, local mht or mhtml files can launch in Microsoft Edge or Internet Explorer mode to best view the file.\r\n\r\nIf you disable this policy, local mht or mhtml files will launch in Microsoft Edge.\r\n\r\nNote that if you use the --ie-mode-file-url command line argument for launching local mht or mhtml files, it takes precedence over how you configured this policy.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_internetexplorerintegrationlocalmhtfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_internetexplorerintegrationlocalmhtfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended","displayName":"Performance Detector Enabled (User)","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\r\n\r\nIf you enable or don't configure this policy, performance detector is turned on.\r\n\r\nIf you disable this policy, performance detector is turned off.\r\n\r\nThe user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled","displayName":"Web Select Enabled (User)","description":"Web select lets users select and copy web content while preserving its formatting when pasted in most cases. It also allows more targeted selection on some web elements, such as copying a single column in a table.\r\n\r\nIf you enable or don't configure this policy, Web select is available through the right click context menu and the CTRL+SHIFT+X keyboard shortcut.\r\n\r\nIf you disable this policy, Web select won't be available.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlaccess","displayName":"Force WebSQL to be enabled (User)","description":"WebSQL is on by default as of Microsoft Edge version 101, but can be disabled via a Microsoft Edge flag.\r\nIf you enable this policy, WebSQL cannot be disabled.\r\nIf you disable or don't configure this policy, WebSQL can be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled","displayName":"Force WebSQL in non-secure contexts to be enabled (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because it is a temporary policy to support WebSQL in non-secure contexts. It won't work in Microsoft Edge as soon as version 110.\r\nIf you enable this policy, WebSQL in non-secure contexts will be enabled.\r\nIf you disable or don't configure this policy, WebSQL in non-secure contexts will follow the default settings of the broser.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~edgeworkspaces_edgeworkspacesenabled","displayName":"Enable Workspaces (User)","description":"Microsoft Edge Workspaces helps improve productivity for users in your organization.\r\n\r\nIf you enable this policy, users will be able to access the Microsoft Edge Workspaces feature.\r\nIf you disable or don't configure this policy, users will not be able to access the Microsoft Edge Workspaces feature.\r\n\r\nTo learn more about the feature, see https://go.microsoft.com/fwlink/?linkid=2209950","helpText":"","infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~edgeworkspaces_edgeworkspacesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~edgeworkspaces_edgeworkspacesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~identity_linkedaccountenabled","displayName":"Enable the linked account feature (User)","description":"Microsoft Edge guides a user to the account management page where they can link a Microsoft Account (MSA) to an Azure Active Directory (Azure AD) account.\r\n\r\nIf you enable or don't configure this policy, linked account information will be shown on a flyout. When the Azure AD profile doesn't have a linked account it will show \"Add account\".\r\n\r\nIf you disable this policy, linked accounts will be turned off and no extra information will be shown.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~identity_linkedaccountenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~identity_linkedaccountenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~performance_performancedetectorenabled","displayName":"Performance Detector Enabled (User)","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\r\n\r\nIf you enable or don't configure this policy, performance detector is turned on.\r\n\r\nIf you disable this policy, performance detector is turned off.\r\n\r\nThe user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~performance_performancedetectorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~performance_performancedetectorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~startup_restoreonstartupuserurlsenabled","displayName":"Allow users to add and remove their own sites during startup when the RestoreOnStartupURLs policy is configured (User)","description":"If you enable this policy, users are allowed to add and remove their own URLs to open when starting Edge while maintaining the admin specified mandatory list of sites specified by setting 'RestoreOnStartup' (Action to take on startup) policy to open a list of URLS and providing the list of sites in the 'RestoreOnStartupURLs' (Sites to open when the browser starts) policy.\r\n\r\nIf you disable or don't configure this policy, there is no change to how the 'RestoreOnStartup' and 'RestoreOnStartupURLs' policies work.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~startup_restoreonstartupuserurlsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~startup_restoreonstartupuserurlsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting","displayName":"Set the default \"share additional operating system region\" setting (User)","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\r\n\r\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting will be shared with the web through the default JavaScript locale. If shared, websites will be able to query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\r\n\r\nIf you set this policy to \"Limited\", the OS Regional format will only be shared if its language part matches the Microsoft Edge display language.\r\n\r\nIf you set this policy to \"Always\", the OS Regional format will always be shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months can be displayed in one language while the surrounding text is displayed in another language.\r\n\r\nIf you set this policy to \"Never\", the OS Regional format will never be shared.\r\n\r\nExample 1: In this example the OS Regional format is set to \"en-GB\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Limited\", or \"Always\".\r\n\r\nExample 2: In this example the OS Regional format is set to \"es-MX\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Always\" but will not if the policy is set to \"Limited\".\r\n\r\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282\r\n\r\nPolicy options mapping:\r\n\r\n* Limited (0) = Limited\r\n\r\n* Always (1) = Always share the OS Regional format\r\n\r\n* Never (2) = Never share the OS Regional format\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting_defaultshareadditionalosregionsetting","displayName":"'Set the default \"share additional operating system region\" setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting_defaultshareadditionalosregionsetting_0","displayName":"Limited","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting_defaultshareadditionalosregionsetting_1","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting_defaultshareadditionalosregionsetting_2","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_encryptedclienthelloenabled","displayName":"TLS Encrypted ClientHello Enabled (User)","description":"Encrypted ClientHello (ECH) is an extension to TLS that encrypts the sensitive fields of ClientHello to improve privacy.\r\n\r\nIf ECH is enabled, Microsoft Edge might or might not use ECH depending on server support, the availability of the HTTPS DNS record, or the rollout status.\r\n\r\nIf you enable or do not configure this policy, Microsoft Edge will follow the default rollout process for ECH.\r\n\r\nIf this policy is disabled, Microsoft Edge will not enable ECH.\r\n\r\nBecause ECH is an evolving protocol, Microsoft Edge's implementation is subject to change.\r\n\r\nAs such, this policy is a temporary measure to control the initial experimental implementation. It will be replaced with final controls as the protocol finalizes.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_encryptedclienthelloenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_encryptedclienthelloenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended","displayName":"Set the default \"share additional operating system region\" setting (User)","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\r\n\r\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting will be shared with the web through the default JavaScript locale. If shared, websites will be able to query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\r\n\r\nIf you set this policy to \"Limited\", the OS Regional format will only be shared if its language part matches the Microsoft Edge display language.\r\n\r\nIf you set this policy to \"Always\", the OS Regional format will always be shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months can be displayed in one language while the surrounding text is displayed in another language.\r\n\r\nIf you set this policy to \"Never\", the OS Regional format will never be shared.\r\n\r\nExample 1: In this example the OS Regional format is set to \"en-GB\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Limited\", or \"Always\".\r\n\r\nExample 2: In this example the OS Regional format is set to \"es-MX\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Always\" but will not if the policy is set to \"Limited\".\r\n\r\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282\r\n\r\nPolicy options mapping:\r\n\r\n* Limited (0) = Limited\r\n\r\n* Always (1) = Always share the OS Regional format\r\n\r\n* Never (2) = Never share the OS Regional format\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting","displayName":"'Set the default \"share additional operating system region\" setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting_0","displayName":"Limited","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting_1","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting_2","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge~startup_newtabpageapplauncherenabled","displayName":"Hide App Launcher on Microsoft Edge new tab page (User)","description":"By default, the App Launcher is shown every time a user opens a new tab page.\r\n\r\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge new tab page and App Launcher is there for users.\r\n\r\nIf you disable this policy, App Launcher doesn't appear and users won't be able to launch M365 apps from Microsoft Edge new tab page via the App Launcher.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge~startup_newtabpageapplauncherenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge~startup_newtabpageapplauncherenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls","displayName":"Allow clipboard use on specific sites (User)","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\r\n\r\nSetting the policy lets you create a list of URL patterns that specify which sites can use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\r\n\r\nLeaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set. If it isn't set, the user's personal setting applies.\r\n\r\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls_clipboardallowedforurlsdesc","displayName":"Allow clipboard use on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls","displayName":"Block clipboard use on specific sites (User)","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\r\n\r\nSetting the policy lets you create a list of URL patterns that specify sites that can't use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\r\n\r\nLeaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set. If it isn't set, the user's personal setting applies.\r\n\r\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_clipboardblockedforurlsdesc","displayName":"Block clipboard use on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting","displayName":"Default clipboard site permission (User)","description":"This policy controls the default value for the clipboard site permission.\r\n\r\nSetting the policy to 2 blocks sites from using the clipboard site permission.\r\n\r\nSetting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use an API.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'ClipboardAllowedForUrls' (Allow clipboard use on specific sites) and 'ClipboardBlockedForUrls' (Block clipboard use on specific sites) policies.\r\n\r\nThis policy only affects clipboard operations controlled by the clipboard site permission and doesn't affect sanitized clipboard writes or trusted copy and paste operations.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockClipboard (2) = Do not allow any site to use the clipboard site permission\r\n\r\n* AskClipboard (3) = Allow sites to ask the user to grant the clipboard site permission\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_defaultclipboardsetting","displayName":"Default clipboard site permission (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_defaultclipboardsetting_2","displayName":"Do not allow any site to use the clipboard site permission","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_defaultclipboardsetting_3","displayName":"Allow sites to ask the user to grant the clipboard site permission","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled","displayName":"Determines whether the Microsoft Root Store and built-in certificate verifier will be used to verify server certificates (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 114.\r\n\r\nWhen this policy is set to enabled, Microsoft Edge will perform verification of server certificates using the built-in certificate verifier with the Microsoft Root Store as the source of public trust.\r\n\r\nWhen this policy is set to disabled, Microsoft Edge will use the system certificate verifier and system root certificates.\r\n\r\nWhen this policy is not set, the Microsoft Root Store or system provided roots may be used.\r\n\r\nThis policy is planned to be removed in Microsoft Edge version\r\n121 for Android devices when support for using the platform supplied roots is planned to be removed.\r\n\r\nThis policy was removed in Microsoft Edge version 115 for\r\nMicrosoft Windows and macOS,\r\nMicrosoft Edge version 120 for\r\nLinux, and\r\nMicrosoft Edge version 121 for\r\nAndroid\r\nwhen support for using the platform supplied certificate verifier and roots was removed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowalldevicesforurls","displayName":"Allow listed sites to connect to any HID device (User)","description":"This setting allows you to list sites which are automatically granted permission to access all available devices.\r\n\r\nThe URLs must be valid or the policy is ignored. Only the origin (scheme, host and port) of the URL is evaluated.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nThis policy overrides 'DefaultWebHidGuardSetting' (Control use of the WebHID API), 'WebHidAskForUrls' (Allow the WebHID API on these sites), 'WebHidBlockedForUrls' (Block the WebHID API on these sites) and the user's preferences.\r\n\r\nExample value:\r\n\r\nhttps://microsoft.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowalldevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowalldevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowalldevicesforurls_webhidallowalldevicesforurlsdesc","displayName":"Allow listed sites to connect to any HID device (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdevicesforurls","displayName":"Allow listed sites connect to specific HID devices (User)","description":"This setting lets you list the URLs that specify which sites are automatically granted permission to access a HID device with the given vendor and product IDs.\r\n\r\nSetting the policy Each item in the list requires both devices and urls fields for the item to be valid, otherwise the item is ignored.\r\n\r\n * Each item in the devices field must have a vendor_id and may have a product_id field.\r\n\r\n * Omitting the product_id field will create a policy matching any device with the specified vendor ID.\r\n\r\n * An item which has a product_id field without a vendor_id field is invalid and is ignored.\r\n\r\nIf you don't set this policy, that means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nURLs in this policy shouldn't conflict with those configured through 'WebHidBlockedForUrls' (Block the WebHID API on these sites). If they do, this policy takes precedence over 'WebHidBlockedForUrls'.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"product_id\": 5678,\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://microsoft.com\",\r\n \"https://chromium.org\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdevicesforurls_webhidallowdevicesforurls","displayName":"Allow listed sites connect to specific HID devices (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage (User)","description":"This setting allows you to list the URLs that specify which sites are automatically granted permission to access a HID device containing a top-level collection with the given HID usage.\r\n\r\nEach item in the list requires both usages and urls fields for the policy to be valid.\r\n\r\n * Each item in the usages field must have a usage_page and may have a usage field.\r\n\r\n * Omitting the usage field will create a policy matching any device containing a top-level collection with a usage from the specified usage page.\r\n\r\n * An item which has a usage field without a usage_page field is invalid and is ignored.\r\n\r\nIf you don't set this policy, that means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nURLs in this policy shouldn't conflict with those configured through 'WebHidBlockedForUrls' (Block the WebHID API on these sites). If they do, this policy takes precedence over 'WebHidBlockedForUrls'.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"urls\": [\r\n \"https://microsoft.com\",\r\n \"https://chromium.org\"\r\n ],\r\n \"usages\": [\r\n {\r\n \"usage\": 5678,\r\n \"usage_page\": 1234\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_autofillmembershipsenabled","displayName":"Save and fill memberships (User)","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\r\n\r\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\r\n\r\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\r\n\r\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_autofillmembershipsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_autofillmembershipsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended_autofillmembershipsenabled_recommended","displayName":"Save and fill memberships (User)","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\r\n\r\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\r\n\r\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\r\n\r\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended_autofillmembershipsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended_autofillmembershipsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended_searchfiltersenabled_recommended","displayName":"Search Filters Enabled (User)","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions will be shown.\r\n\r\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\r\n\r\nIf you disable this policy, the autosuggestion dropdown won't display the ribbon of available filters.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended_searchfiltersenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended_searchfiltersenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended~printing_recommended_printpreviewstickysettings_recommended","displayName":"Configure the sticky print preview settings (User)","description":"Configuring this policy sets the print preview settings as the most recent choice in Print Preview instead of the default print preview settings.\r\n\r\nEach item of this policy expects a boolean:\r\n\r\nLayout specifies if the webpage layout should be kept sticky or not in print preview settings. If we set this to True the webpage layout uses the recent choice otherwise it will set to default value.\r\n\r\nSize specifies if the page size should be kept sticky or not in print preview settings. If we set this to True the page size uses the recent choice otherwise it will set to default value.\r\n\r\nScale Type specifies if the scaling percentage and scale type should be kept sticky or not in print preview settings. If we set this to True the scale percentage and scale type both uses the recent choice oherwise it will set to default value.\r\n\r\nMargins specifies if the page margin should be kept sticky or not in print preview settings. If we set this to True the page margins uses the recent choice otherwise it will set to default value.\r\n\r\nIf you enable this policy, the selected values will use the most recent choice in Print Preview.\r\n\r\nIf you disable or don't configure this policy, print preview settings will not be impacted.\r\n\r\nExample value:\r\n\r\n{\r\n \"layout\": false,\r\n \"margins\": true,\r\n \"scaleType\": false,\r\n \"size\": true\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"layout\": false, \"margins\": true, \"scaleType\": false, \"size\": true}","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended~printing_recommended_printpreviewstickysettings_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended~printing_recommended_printpreviewstickysettings_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended~printing_recommended_printpreviewstickysettings_recommended_printpreviewstickysettings","displayName":"Configure the sticky print preview settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchfiltersenabled","displayName":"Search Filters Enabled (User)","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions will be shown.\r\n\r\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\r\n\r\nIf you disable this policy, the autosuggestion dropdown won't display the ribbon of available filters.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchfiltersenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchfiltersenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled","displayName":"Search in Sidebar enabled (User)","description":"Search in Sidebar allows users to open search result in sidebar (including sidebar search for Progressive Web Apps).\r\n\r\nIf you configure this policy to 'EnableSearchInSidebar' or don't configure it, Search in sidebar will be enabled.\r\n\r\nIf you configure this policy to 'DisableSearchInSidebarForKidsMode', Search in sidebar will be disabled when in Kids mode. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\r\n\r\nIf you configure this policy to 'DisableSearchInSidebar', Search in sidebar will be disabled. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\r\n\r\nPolicy options mapping:\r\n\r\n* EnableSearchInSidebar (0) = Enable search in sidebar\r\n\r\n* DisableSearchInSidebarForKidsMode (1) = Disable search in sidebar for Kids Mode\r\n\r\n* DisableSearchInSidebar (2) = Disable search in sidebar\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled","displayName":"Search in Sidebar enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled_0","displayName":"Enable search in sidebar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled_1","displayName":"Disable search in sidebar for Kids Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled_2","displayName":"Disable search in sidebar","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsallowedforurls","displayName":"Allow multiple automatic downloads in quick succession on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are allowed to perform multiple successive automatic downloads.\r\nIf you don't configure this policy, 'DefaultAutomaticDownloadsSetting' (Default automatic downloads setting) applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\r\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsallowedforurls_automaticdownloadsallowedforurlsdesc","displayName":"Allow multiple automatic downloads in quick succession on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls","displayName":"Block multiple automatic downloads in quick succession on specific sites (User)","description":"Define a list of sites, based on URL patterns, where multiple successive automatic downloads aren't allowed.\r\nIf you don't configure this policy, 'DefaultAutomaticDownloadsSetting' (Default automatic downloads setting) applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\r\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com\r\n[*.]contoso.com","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls_automaticdownloadsblockedforurlsdesc","displayName":"Block multiple automatic downloads in quick succession on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting","displayName":"Default automatic downloads setting (User)","description":"Administrators can use this policy to control whether websites can perform multiple downloads successively. Individual site behavior can be managed using the AutomaticDownloadsAllowedForUrls and AutomaticDownloadsBlockedForUrls policies.\r\n\r\nDefault behavior:\r\n\r\n- A user gesture is required for each additional download.\r\n\r\n- Users can modify their browser settings to disable successive downloads.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowAutomaticDownloads (1) = Allow all websites to perform multiple downloads without requiring a user gesture between each download.\r\n\r\n* BlockAutomaticDownloads (2) = Prevent all websites from performing multiple downloads, even after a user gesture.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting","displayName":"Default automatic downloads setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting_1","displayName":"Allow all websites to perform automatic downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting_2","displayName":"Don't allow any website to perform automatic downloads","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings","displayName":"Configure navigation settings per groups of URLs in Microsoft Edge Workspaces (User)","description":"This setting lets you to define groups of URLs, and apply specific Microsoft Edge Workspaces navigation settings to each group.\r\n\r\nIf this policy is configured, Microsoft Edge Workspaces will use the configured settings when deciding whether and how to share navigations among collaborators in a Microsoft Edge Workspace.\r\n\r\nIf this policy is not configured, Microsoft Edge Workspaces will use only default and internally configured navigation settings.\r\n\r\nFor more information about configuration options, see https://go.microsoft.com/fwlink/?linkid=2218655\r\n\r\nNote, format url_patterns according to https://go.microsoft.com/fwlink/?linkid=2095322. You can configure the url_regex_patterns in this policy to match multiple URLs using a Perl style regular expression for the pattern. Note that pattern matches are case sensitive. For more information about the regular expression rules that are used, refer to https://go.microsoft.com/fwlink/p/?linkid=2133903.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"navigation_options\": {\r\n \"do_not_send_to\": true,\r\n \"remove_all_query_parameters\": true\r\n },\r\n \"url_patterns\": [\r\n \"https://contoso.com\",\r\n \"https://www.fabrikam.com\",\r\n \".exact.hostname.com\"\r\n ]\r\n },\r\n {\r\n \"navigation_options\": {\r\n \"query_parameters_to_remove\": [\r\n \"username\",\r\n \"login_hint\"\r\n ]\r\n },\r\n \"url_patterns\": [\r\n \"https://adatum.com\"\r\n ]\r\n },\r\n {\r\n \"navigation_options\": {\r\n \"do_not_send_from\": true,\r\n \"prefer_initial_url\": true\r\n },\r\n \"url_regex_patterns\": [\r\n \"\\\\Ahttps://.*?tafe\\\\..*?trs.*?\\\\.fabrikam.com/Sts\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings_workspacesnavigationsettings","displayName":"Configure navigation settings per groups of URLs in Microsoft Edge Workspaces (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereadergrammartoolsenabled","displayName":"Enable Grammar Tools feature within Immersive Reader in Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 125.\r\n\r\nThis policy is obsoleted because Grammar Tools is deprecated from Edge. This policy won't work in Microsoft Edge version 126. Enables the Grammar Tools feature within Immersive Reader in Microsoft Edge.\r\nThis helps improve reading comprehension by splitting words into syllables and highlighting nouns, verbs, adverbs, and adjectives.\r\n\r\nIf you enable this policy or don't configure it, the Grammar Tools option shows up within Immersive Reader.\r\nIf you disable this policy, users can't access the Grammar Tools feature within Immersive Reader.","helpText":"","infoUrls":[],"categoryId":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","categoryName":"Immersive Reader settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereadergrammartoolsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereadergrammartoolsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereaderpicturedictionaryenabled","displayName":"Enable Picture Dictionary feature within Immersive Reader in Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 126.\r\n\r\nThis Policy is obsoleted because Picture Dictionary is deprecated from Edge as of Sept, 2023. This policy won't work in Microsoft Edge Version 127. Enables the Picture Dictionary feature within Immersive Reader in Microsoft Edge.\r\nThis feature helps in reading comprehension by letting a user to click on any single word and see an illustration related to the meaning.\r\n\r\nIf you enable this policy or don't configure it, the Picture Dictionary option shows up within Immersive Reader.\r\nIf you disable this policy, users can't access the Picture Dictionary feature within Immersive Reader.","helpText":"","infoUrls":[],"categoryId":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","categoryName":"Immersive Reader settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereaderpicturedictionaryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereaderpicturedictionaryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~printing_printpreviewstickysettings","displayName":"Configure the sticky print preview settings (User)","description":"Configuring this policy sets the print preview settings as the most recent choice in Print Preview instead of the default print preview settings.\r\n\r\nEach item of this policy expects a boolean:\r\n\r\nLayout specifies if the webpage layout should be kept sticky or not in print preview settings. If we set this to True the webpage layout uses the recent choice otherwise it will set to default value.\r\n\r\nSize specifies if the page size should be kept sticky or not in print preview settings. If we set this to True the page size uses the recent choice otherwise it will set to default value.\r\n\r\nScale Type specifies if the scaling percentage and scale type should be kept sticky or not in print preview settings. If we set this to True the scale percentage and scale type both uses the recent choice oherwise it will set to default value.\r\n\r\nMargins specifies if the page margin should be kept sticky or not in print preview settings. If we set this to True the page margins uses the recent choice otherwise it will set to default value.\r\n\r\nIf you enable this policy, the selected values will use the most recent choice in Print Preview.\r\n\r\nIf you disable or don't configure this policy, print preview settings will not be impacted.\r\n\r\nExample value:\r\n\r\n{\r\n \"layout\": false,\r\n \"margins\": true,\r\n \"scaleType\": false,\r\n \"size\": true\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"layout\": false, \"margins\": true, \"scaleType\": false, \"size\": true}","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~printing_printpreviewstickysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~printing_printpreviewstickysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~printing_printpreviewstickysettings_printpreviewstickysettings","displayName":"Configure the sticky print preview settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_internetexplorermodecleardataonexitenabled","displayName":"Clear history for IE and IE mode every time you exit (User)","description":"This policy controls whether browsing history is deleted from Internet Explorer and Internet Explorer mode every time Microsoft Edge is closed.\r\n\r\nUsers can configure this setting in the 'Clear browsing data for Internet Explorer' option in the Privacy, search, and services menu of Settings.\r\n\r\nIf you enable this policy, on browser exit Internet Explorer browsing history will be cleared.\r\n\r\nIf you disable or do not configure this policy, Internet Explorer browsing history will not be cleared on browser exit.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_internetexplorermodecleardataonexitenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_internetexplorermodecleardataonexitenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_newpdfreaderenabled","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled (User)","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\r\n\r\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_newpdfreaderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_newpdfreaderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_recommended_newpdfreaderenabled_recommended","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled (User)","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\r\n\r\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_recommended_newpdfreaderenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_recommended_newpdfreaderenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed","displayName":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context (User)","description":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context. A SharedArrayBuffer is a binary data buffer that can be used to create views on shared memory. SharedArrayBuffers have a memory access vulnerability in several popular CPUs.\r\n\r\nIf you enable this policy, sites are allowed to use SharedArrayBuffers with no restrictions.\r\n\r\nIf you disable or don't configure this policy, sites are allowed to use SharedArrayBuffers only when cross-origin isolated.\r\n\r\nMicrosoft Edge will require cross-origin isolation when using SharedArrayBuffers from Microsoft Edge 91 onward for Web Compatibility reasons.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_showacrobatsubscriptionbutton","displayName":"Shows button on native PDF viewer in Microsoft Edge that allows users to sign up for Adobe Acrobat subscription (User)","description":"This policy lets the native PDF viewer in Microsoft Edge show a button that lets a user looking for advanced digital document features to discover and subscribe to premium offerings. This is done via the Acrobat extension.\r\n\r\nIf you enable or don't configure this policy, the button will show up on the native PDF viewer in Microsoft Edge. A user will be able to buy Adobe subscription to access their premium offerings.\r\n\r\nIf you disable this policy, the button won't be visible on the native PDF viewer in Microsoft Edge. A user won't be able to discover Adobe's advanced PDF tools or buy their subscriptions.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_showacrobatsubscriptionbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_showacrobatsubscriptionbutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_cryptowalletenabled","displayName":"Enable CryptoWallet feature (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 128.\r\n\r\nThis policy is obsoleted because this feature will no longer be supported, starting in Microsoft Edge 128. There is no replacement for this policy.\r\n Enables CryptoWallet feature in Microsoft Edge.\r\n\r\n If you enable this policy or don't configure it, users can use CryptoWallet feature which allows users to securely store, manage and transact digital assets such as Bitcoin, Ethereum and other cryptocurrencies. Therefore, Microsoft Edge may access Microsoft servers to communicate with the web3 world during the use of the CryptoWallet feature.\r\n\r\n If you disable this policy, users can't use CryptoWallet feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_cryptowalletenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_cryptowalletenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_mousegestureenabled","displayName":"Mouse Gesture Enabled (User)","description":"This policy lets you configure the Mouse Gesture feature in Microsoft Edge.\r\n\r\nThis feature provides an easy way for users to complete tasks like scroll forward or backward, open new tab, refresh page, etc. They can finish a task by pressing and holding the mouse right button to draw certain patterns on a webpage, instead of clicking the buttons or using keyboard shortcuts.\r\n\r\nIf you enable or don't configure this policy, you can use the Mouse Gesture feature on Microsoft Edge to start using this feature.\r\n\r\nIf you disable this policy, you can't use the Mouse Gesture feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_mousegestureenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_mousegestureenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_readaloudenabled","displayName":"Enable Read Aloud feature in Microsoft Edge (User)","description":"Enables the Read Aloud feature within Microsoft Edge.\r\nUsing this feature, users can listen to the content on the web page. This enables users to multi-task or improve their reading comprehension by hearing content at their own pace.\r\n\r\nIf you enable this policy or don't configure it, the Read Aloud option shows up in the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.\r\nIf you disable this policy, users can't access the Read Aloud feature from the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_readaloudenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_readaloudenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_restorepdfview","displayName":"Restore PDF view (User)","description":"Enables PDF View Recovery in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy Microsoft Edge will recover the last state of PDF view and land users to the section where they ended reading in the last session.\r\n\r\nIf you disable this policy Microsoft Edge will recover the last state of PDF view and land users at the start of the PDF file.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_restorepdfview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_restorepdfview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_tabservicesenabled","displayName":"Enable tab organization suggestions (User)","description":"This policy controls whether Microsoft Edge can use its tab organization service to help name or suggest tab groups to increase productivity.\r\n\r\nIf you enable or don't configure this policy, when a user creates a tab group or activates certain \"Group Similar Tabs\" features Microsoft Edge sends tab data to its tab organization service. This data includes URLs, page titles, and existing group information. The service uses this data to return suggestions for better groupings and group names.\r\n\r\nIf you disable this policy, no data will be sent to the tab organization service. Microsoft Edge won't suggest group names when a group is created and certain \"Group Similar Tabs\" features that rely on the service won't be available.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_tabservicesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_tabservicesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_defaultbrowsersettingscampaignenabled","displayName":"Enables default browser settings campaigns (User)","description":"This policy enables the default browser settings campaign. If a user clicks to accept the campaign, their default browser and/or default search engine will be changed to Microsoft Edge and Microsoft Bing, respectively. If the user dismisses the campaign, the user's browser settings will remain unchanged.\r\n\r\nIf you enable or don't configure this policy, users will be prompted to set Microsoft Edge as the default browser and Microsoft Bing as the default search engine, if they do not have those browser settings.\r\n\r\nIf you disable this policy, users will not be prompted to set Microsoft Edge as the default browser, or to set Microsoft Bing as the default search engine.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_defaultbrowsersettingscampaignenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_defaultbrowsersettingscampaignenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_discoverpagecontextenabled","displayName":"Enable Discover access to page contents for AAD profiles (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nThis policy has been obsoleted as of Edge 127. Two new Edge Policies have taken its place. Those policies are CopilotPageContext (Control Copilot access to page contents for AAD profiles), and CopilotCDPPageContext (Control Copilot with Commercial Data Protection access to page contents for AAD profiles).\r\n\r\nThis policy did not allow for separate control of Copilot and Copilot with Commercial Data Protection. The new policies allow separate control of these versions of Copilot. The new policies also allow admins to force-enable Copilot access to Edge page contents by enabling the policy, whereas DiscoverPageContextEnabled only allowed force-disabling of Copilot page access.\r\n\r\nThis policy controls Discover access to page contents for AAD profiles. Discover is an extension that hosts Bing Chat. In order to summarize pages and interact with text selections, it needs to be able to access the page contents. When enabled, page contents will be sent to Bing. This policy does not affect MSA profiles.\r\n\r\nIf you enable or don't configure this policy, Discover will have access to page contents.\r\n\r\nIf you disable this policy, Discover will not be able to access page contents.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_discoverpagecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_discoverpagecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_enforcelocalanchorconstraintsenabled","displayName":"Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nX.509 certificates may encode constraints, such as Name Constraints, in extensions in the certificate. RFC 5280 specifies that enforcing such constraints on trust anchor certificates is optional.\r\n\r\nStarting in Microsoft Edge 112, such constraints in certificates loaded from the platform certificate store will now be enforced.\r\n\r\nThis policy exists as a temporary opt-out in case an enterprise encounters issues with the constraints encoded in their private roots. In that case this policy may be used to temporarily disable enforcement of the constraints while correcting the certificate issues.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will enforce constraints encoded into trust anchors loaded from the platform trust store.\r\n\r\nIf you disable this policy, Microsoft Edge will not enforce constraints encoded into trust anchors loaded from the platform trust store.\r\n\r\nThis policy has no effect if the 'MicrosoftRootStoreEnabled' (Determines whether the Microsoft Root Store and built-in certificate verifier will be used to verify server certificates) policy is disabled.\r\n\r\nThis policy was removed in Microsoft Edge version 128. Starting with that version, constraints in trust anchors are always enforced.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_enforcelocalanchorconstraintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_enforcelocalanchorconstraintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_showdownloadstoolbarbutton","displayName":"Show Downloads button on the toolbar (User)","description":"Set this policy to always show the Downloads button on the toolbar.\r\n\r\nIf you enable this policy, the Downloads button is pinned to the toolbar.\r\n\r\nIf you disable or don't configure the policy, the Downloads button isn't shown on the toolbar by default. Users can toggle the Downloads button in edge://settings/appearance.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_showdownloadstoolbarbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_showdownloadstoolbarbutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_standalonehubssidebarenabled","displayName":"Standalone Sidebar Enabled (User)","description":"Standalone Sidebar is an optional mode for the Sidebar in Microsoft Edge. When this mode is activated by a user, the Sidebar appears in a fixed position on the Microsoft Windows desktop, and is hidden from the browser application frame.\r\n\r\nIf you enable or don't configure this policy, users will have the ability to activate the Standalone Sidebar.\r\nIf you disable this policy, options to activate Standalone Sidebar will be hidden or made unavailable. Note that blocking 'HubsSidebarEnabled' (Show Hubs Sidebar) will also prevent users from accessing Standalone Sidebar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_standalonehubssidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_standalonehubssidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_composeinlineenabled","displayName":"Compose is enabled for writing on the web (User)","description":"This policy lets you configure Compose in Microsoft Edge. Compose provides help for writing with AI-generated text, which lets the user get ideas for writing. This includes elaborating on text, re-writing, changing tone, formatting the text, and more.\r\n\r\nIf you enable or don't configure this policy, Compose can provide text generation for eligible fields, which are text editable and don't have an autocomplete attribute.\r\n\r\nIf you disable this policy, Compose will not be able to provide text generation for eligible fields. Compose will still be available for prompt-based text generation through the sidebar and must be managed with either 'EdgeDiscoverEnabled' (Discover feature In Microsoft Edge) policy or 'HubsSidebarEnabled' (Show Hubs Sidebar) policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_composeinlineenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_composeinlineenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeindicatoruienabled","displayName":"Manage the indicator UI of the Enhanced Security Mode (ESM) feature in Microsoft Edge (User)","description":"This policy lets you manage whether the indicator User Interface (UI) for enhanced security mode is shown or not when ESM is turned on.\r\n\r\nIf you enable or don't configure this policy, the indicator UI is on.\r\n\r\nIf you disable this policy, the indicator UI is off.\r\n\r\nNote: If this policy is used, only the indicator User Interface experience is supressed - ESM is still turned on. For more information, see the 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) policy.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeindicatoruienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeindicatoruienabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeoptoutuxenabled","displayName":"Manage opt-out user experience for Enhanced Security Mode (ESM) in Microsoft Edge (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy lets you manage whether the opt-out user experience for enhanced security mode is presented when ESM is turned on for Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, the UI for the opt-out user experience is on.\r\n\r\nIf you disable this policy, the UI for the opt-out user experience is off.\r\n\r\nNote: If this policy is used, only the User Interface for the opt-out experience is supressed - ESM is still turned on. For more information, see the 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) policy.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.\r\n\r\nAfter careful evaluation, we have determined that this experimental opt-out UX is not required. As a result, this policy will be deprecated and stop working after Edge version 130.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeoptoutuxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeoptoutuxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_recommended_walletdonationenabled_recommended","displayName":"Wallet Donation Enabled (User)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\r\n\r\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\r\n\r\nIf you disable this policy, users can't use the Wallet Donation feature.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_recommended_walletdonationenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_recommended_walletdonationenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_searchforimageenabled","displayName":"Search for image enabled (User)","description":"This policy lets you configure the Image Search feature in the right-click context menu.\r\n\r\nIf you enable or don't configure this policy, then the \"Search the web for image\" option will be visible in the context menu.\r\n\r\nIf you disable this policy, then the \"Search the web for image\" will not be visible in the context menu.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_searchforimageenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_searchforimageenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_walletdonationenabled","displayName":"Wallet Donation Enabled (User)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\r\n\r\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\r\n\r\nIf you disable this policy, users can't use the Wallet Donation feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_walletdonationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_walletdonationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenabled","displayName":"Microsoft Edge management enabled (User)","description":"Microsoft Edge management service in Microsoft 365 Admin Center lets you set policy and manage users through a Microsoft Edge focused cloud-based management experience. This policy lets you control whether Microsoft Edge management is enabled.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will attempt to connect to the Microsoft Edge management service to download and apply policy assigned to the Azure AD account of the user.\r\n\r\nIf you disable this policy, Microsoft Edge will not attempt to connect to the Microsoft Edge management service.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken","displayName":"Microsoft Edge management enrollment token (User)","description":"Microsoft Edge management service in Microsoft 365 Admin Center lets you set policy and manage users through a Microsoft Edge focused cloud-based management experience. This policy lets you specify an enrollment token that's used to register with Microsoft Edge management service and deploy the associated policies. The user must be signed into Microsoft Edge with a valid work or school account otherwise Microsoft Edge will not download the policy.\r\n\r\nIf you enable this policy, Microsoft Edge will attempt to use the specified enrollment token to register with the Microsoft Edge management service and download the published policy.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not attempt to connect to the Microsoft Edge management service.\r\n\r\nExample value: RgAAAACBbzoQDmUrRfq3WeKUoFeEBwBOqK2QPYsBT5V3lQFoKND-AAAAAAEVAAAOqK2QPYvBT5V4lQFoKMD-AAADTXvzAAAA0","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_edgemanagementenrollmenttoken","displayName":"Microsoft Edge management enrollment token (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementextensionsfeedbackenabled","displayName":"Microsoft Edge management extensions feedback enabled (User)","description":"This setting controls whether Microsoft Edge sends data about blocked extensions to the Microsoft Edge management service.\r\n\r\nThe 'EdgeManagementEnabled' policy must also be enabled for this setting to take effect.\r\n\r\nIf you enable this policy, Microsoft Edge will send data to the Microsoft Edge service when a user tries to install a blocked extension.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge won't send any data to the Microsoft Edge service about blocked extensions.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementextensionsfeedbackenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementextensionsfeedbackenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_recommended~performance_recommended_pinbrowseressentialstoolbarbutton_recommended","displayName":"Pin browser essentials toolbar button (User)","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\r\n\r\nWhen the button is pinned, it will always appear on the toolbar.\r\n\r\nWhen the button isn't pinned, it will only appear when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\r\n\r\nIf you enable or don't configure this policy, the Browser essentials button will be pinned on the toolbar.\r\n\r\nIf you disable this policy, the Browser essentials button won't be pinned on the toolbar.\r\n\r\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_recommended~performance_recommended_pinbrowseressentialstoolbarbutton_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_recommended~performance_recommended_pinbrowseressentialstoolbarbutton_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_throttlenonvisiblecrossoriginiframesallowed","displayName":"Allows enabling throttling of non-visible, cross-origin iframes (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 123.\r\n\r\nThrottling of cross-origin frames that are display:none and non-visible is a feature designed to make cross-process and same-process cross-origin iframes consistent in their rendering behavior. For more details on cross-process vs. same-process throttling, refer to https://go.microsoft.com/fwlink/?linkid=2239564.\r\n\r\nThis enterprise policy exists to allow administrators to control whether their users are able to turn the additional throttling on or not.\r\n\r\nIf you enable or don't configure this policy, users can opt-in to throttling.\r\n\r\nIf you disable this policy, users can't enable throttling.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_throttlenonvisiblecrossoriginiframesallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_throttlenonvisiblecrossoriginiframesallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting","displayName":"Default setting for third-party storage partitioning (User)","description":"This policy controls whether third-party storage partitioning is allowed by default.\r\n\r\nIf this policy is set to 1 - AllowPartitioning, or unset, third-party storage partitioning will be allowed by default. This default may be overridden for specific top-level origins by other means.\r\n\r\nIf this policy is set to 2 - BlockPartitioning, third-party storage partitioning will be disabled for all contexts.\r\n\r\nUse ThirdPartyStoragePartitioningBlockedForOrigins to disable third-party storage partitioning for specific top-level origins.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowPartitioning (1) = Allow third-party storage partitioning by default.\r\n\r\n* BlockPartitioning (2) = Disable third-party storage partitioning.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting","displayName":"Default setting for third-party storage partitioning (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting_1","displayName":"Let third-party storage partitioning to be enabled.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting_2","displayName":"Block third-party storage partitioning from being enabled.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_thirdpartystoragepartitioningblockedfororigins","displayName":"Disable third-party storage partitioning for specific top-level origins (User)","description":"This policy lets you set a list of URL patterns that specify top-level origins for which third-party storage partitioning (partitioning of cross-origin iframe storage) should be disabled.\r\n\r\nIf this policy isn't set or a top-level origin doesn't match one of the URL patterns, then the value from 'DefaultThirdPartyStoragePartitioningSetting' (Default setting for third-party storage partitioning) will be used.\r\n\r\nNote that the patterns you list are treated as origins, not URLs, so you shouldn't specify a path. For detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nwww.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_thirdpartystoragepartitioningblockedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_thirdpartystoragepartitioningblockedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_thirdpartystoragepartitioningblockedfororigins_thirdpartystoragepartitioningblockedfororiginsdesc","displayName":"Block third-party storage partitioning for these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton","displayName":"Pin browser essentials toolbar button (User)","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\r\n\r\nWhen the button is pinned, it will always appear on the toolbar.\r\n\r\nWhen the button isn't pinned, it will only appear when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\r\n\r\nIf you enable or don't configure this policy, the Browser essentials button will be pinned on the toolbar.\r\n\r\nIf you disable this policy, the Browser essentials button won't be pinned on the toolbar.\r\n\r\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_allowsystemnotifications","displayName":"Allows system notifications (User)","description":"Lets you use system notifications instead of Microsoft Edge's embedded Message Center on Windows and Linux.\r\n\r\nIf set to True or not set, Microsoft Edge is allowed to use system notifications.\r\n\r\nIf set to False, Microsoft Edge will not use system notifications. Microsoft Edge's embedded Message Center will be used as a fallback.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_allowsystemnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_allowsystemnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_edgewalletetreeenabled","displayName":"Edge Wallet E-Tree Enabled (User)","description":"The Edge Wallet E-Tree feature in Microsoft Edge allows users to plant a E-Tree for their own.\r\n\r\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\r\n\r\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_edgewalletetreeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_edgewalletetreeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_internetexplorerintegrationzoneidentifiermhtfileallowed","displayName":"Automatically open downloaded MHT or MHTML files from the web in Internet Explorer mode (User)","description":"This policy controls whether MHT or MHTML files that are downloaded from the web are automatically opened in Internet Explorer mode.\r\n\r\nIf you enable this policy, the MHT or MHTML files that are downloaded from the web can be opened in both Microsoft Edge and Internet Explorer mode to provide the best user experience.\r\n\r\nIf you disable or don't configure this policy, MHT or MHTML files that are downloaded from the web won't automatically open in Internet Explorer mode.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_internetexplorerintegrationzoneidentifiermhtfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_internetexplorerintegrationzoneidentifiermhtfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended_edgewalletetreeenabled_recommended","displayName":"Edge Wallet E-Tree Enabled (User)","description":"The Edge Wallet E-Tree feature in Microsoft Edge allows users to plant a E-Tree for their own.\r\n\r\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\r\n\r\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended_edgewalletetreeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended_edgewalletetreeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended~edgegames_recommended_gamermodeenabled_recommended","displayName":"Enable Gamer Mode (User)","description":"Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more.\r\n\r\nIf you enable or don't configure this policy, users can opt into Gamer Mode.\r\nIf you disable this policy, Gamer Mode will be disabled.","helpText":"","infoUrls":[],"categoryId":"48965ad9-3011-4722-855b-7179fef89954","categoryName":"Games settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended~edgegames_recommended_gamermodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended~edgegames_recommended_gamermodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_searchbarallowed","displayName":"Enable the Search bar (User)","description":"Enables the search bar. When enabled, users can use the search bar to search the web from their desktop or from an application. The search bar provides a search box, powered by Edge default search engine, that shows web suggestions and opens all web searches in Microsoft Edge. The search bar can be launched from the \"More tools\" menu or jump list in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy:\r\nThe search bar will be automatically enabled for all profiles.\r\nThe option to enable the search bar at startup will be toggled on if the 'SearchbarIsEnabledOnStartup' (Allow the Search bar at Windows startup) policy is enabled.\r\nIf the 'SearchbarIsEnabledOnStartup' is disabled or not configured, the option to enable the search bar at startup will be toggled off.\r\nUsers will see the menu item to launch the search bar from the Microsoft Edge \"More tools\" menu. Users can launch the search bar from \"More tools\".\r\nUsers will see the menu item to launch the search bar from the Microsoft Edge jump list menu. Users can launch the search bar from the Microsoft Edge jump list menu.\r\nThe search bar can be turned off by the \"Quit\" option in the System tray or by closing the search bar from the 3 dot menu. The search bar will be restarted on system reboot if auto-start is enabled.\r\n\r\n\r\nIf you disable this policy:\r\nThe search bar will be disabled for all profiles.\r\nThe option to launch the search bar from Microsoft Edge \"More tools\" menu will be disabled.\r\nThe option to launch the search bar from Microsoft Edge jump list menu will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_searchbarallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_searchbarallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_searchbarisenabledonstartup","displayName":"Allow the Search bar at Windows startup (User)","description":"Allows the Search bar to start running at Windows startup.\r\n\r\nIf you enable:\r\n The Search bar will start running at Windows startup by default.\r\n If the Search bar is disabled via 'SearchbarAllowed' (Enable the Search bar) policy, this policy will not start the Search bar on Windows startup.\r\n\r\nIf you disable this policy:\r\n The Search bar will not start at Windows startup for all profiles.\r\n The option to start the search bar at Windows startup will be disabled and toggled off in search bar settings.\r\n\r\nIf you don't configure the policy:\r\n The Search bar will not start at Windows startup for all profiles.\r\n The option to start the search bar at Windows startup will be toggled off in search bar settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_searchbarisenabledonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_searchbarisenabledonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_showhistorythumbnails","displayName":"Show thumbnail images for browsing history (User)","description":"This policy lets you configure whether the history thumbnail feature collects and saves images for the sites you visit. When enabled, this feature makes it easier to identify sites when you hover over your history results.\r\nIf you don't configure this policy, the thumbnail feature is turned on after a user visits the history hub twice in the past 7 days.\r\nIf you enable this policy, the history thumbnail collects and saves images for visited sites.\r\nIf you disable this policy, the history thumbnail doesn't collect and save images for visited sites.\r\nWhen the feature is disabled, existing images are deleted on a per user basis, and the feature no longer collects or saves images when a site is visited.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_showhistorythumbnails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_showhistorythumbnails_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_splitscreenenabled","displayName":"Enable split screen feature in Microsoft Edge (User)","description":"This policy lets you configure the split screen feature in Microsoft Edge. This feature lets a user open two web pages in one tab.\r\n\r\nIf you enable or don't configure this policy, users can use the split screen feature in Microsoft Edge.\r\n\r\nIf you disable this policy, users can't use the split screen feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_splitscreenenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_splitscreenenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_uploadfromphoneenabled","displayName":"Enable upload files from mobile in Microsoft Edge desktop (User)","description":"This policy lets you configure the \"Upload from mobile\" feature in Microsoft Edge.\r\n\r\nUpload from mobile lets users select file from mobile devices to desktop when user upload file in a webpage in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, you can use the Upload from mobile feature in Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Upload from mobile feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_uploadfromphoneenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_uploadfromphoneenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge~edgegames_gamermodeenabled","displayName":"Enable Gamer Mode (User)","description":"Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more.\r\n\r\nIf you enable or don't configure this policy, users can opt into Gamer Mode.\r\nIf you disable this policy, Gamer Mode will be disabled.","helpText":"","infoUrls":[],"categoryId":"81c518f1-522e-4957-b850-e8a66d2ab215","categoryName":"Games settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge~edgegames_gamermodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge~edgegames_gamermodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_beforeunloadeventcancelbypreventdefaultenabled","displayName":"Control the behavior for the cancel dialog produced by the beforeunload event (User)","description":"This policy provides a temporary opt-out for two related fixes to the behavior of the confirmation dialog that’s shown by the beforeunload event.\r\n\r\nWhen this policy is Enabled, the new (correct) behavior will be used.\r\nWhen this policy is Disabled, the old (legacy) behavior will be used.\r\nWhen this policy is left not set, the default behavior will be used.\r\nNote: This policy is a temporary workaround and will be removed in a future release.\r\n\r\nNew and correct behavior: In `beforeunload`, calling `event.preventDefault()` will trigger the confirmation dialog. Setting `event.returnValue` to the empty string won’t trigger the confirmation dialog.\r\n\r\nOld and legacy behavior: In `beforeunload`, calling `event.preventDefault()` won’t trigger the confirmation dialog. Setting `event.returnValue` to the empty string will trigger the confirmation dialog.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_beforeunloadeventcancelbypreventdefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_beforeunloadeventcancelbypreventdefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcebuiltinpushmessagingclient","displayName":"Forces Microsoft Edge to use its built-in WNS push client to connect to the Windows Push Notification Service. (User)","description":"In some environments, the Windows OS client can't connect to the Windows Push Notification Service (WNS). For these environments, you can use the Microsoft Edge built-in WNS push client, which may be able to connect successfully.\r\n\r\nIf enabled, Microsoft Edge will use its built-in WNS push client to connect to WNS.\r\n\r\nIf disabled or not configured, Microsoft Edge will use the Windows OS client to connect to the Windows Push Notification Service. This is the default setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcebuiltinpushmessagingclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcebuiltinpushmessagingclient_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled. (User)","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy.\r\nCurrently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers.\r\nThis enterprise policy can be used to opt out of this gradual deprecation by forcing the default to stay enabled.\r\n\r\nPages might depend on unload event handlers to save data or signal the end of a user session to the server.\r\nThis is not recommended because it's unreliable and impacts performance by blocking use of BackForwardCache.\r\nRecommended alternatives exist, but the unload event has been used for a long time. Some applications might still rely on them.\r\n\r\nIf you disable this policy or don't configure it, unload event handlers will gradually be deprecated in-line with the deprecation rollout and sites which don't set Permissions-Policy header will stop firing `unload` events.\r\n\r\nIf you enable this policy then unload event handlers will continue to work by default.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcepermissionpolicyunloaddefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcepermissionpolicyunloaddefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge (User)","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\r\n\r\nThe Picture in Picture floating overlay button lets user to watch videos in a floating window on top of other windows.\r\n\r\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_recommended~passwordmanager_recommended_passworddeleteonbrowsercloseenabled_recommended","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes (User)","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when:\r\n- The 'Passwords' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\r\n- The policy ClearBrowsingDataOnExit is enabled\r\n\r\nIf you enable this policy, passwords won't be cleared when the browser closes.\r\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":"","infoUrls":[],"categoryId":"a877a2ff-f144-421f-814c-593e972a8a20","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_recommended~passwordmanager_recommended_passworddeleteonbrowsercloseenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_recommended~passwordmanager_recommended_passworddeleteonbrowsercloseenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_sendmouseeventsdisabledformcontrolsenabled","displayName":"Control the new behavior for event dispatching on disabled form controls (User)","description":"Event dispatching on disabled form controls is being changed in Edge to improve compatibility with other browsers and to improve the developer experience.\r\n\r\nWith this change, MouseEvents get dispatched on disabled form control elements. Exceptions for this behavior are click, mouseup, and mousedown. Some examples of the new events are mousemove, mouseenter, and mouseleave.\r\n\r\nThis change also truncates the event path of click, mouseup, and mousedown when they’re dispatched on children of disabled form controls. These events aren’t dispatched on the disabled form control or any of its ancestors.\r\n\r\nNote: This new behavior might break some websites.\r\n\r\nIf this policy is enabled or left not set, the new behavior will be used.\r\n\r\nIf this policy is disabled, the old behavior will be used.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_sendmouseeventsdisabledformcontrolsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_sendmouseeventsdisabledformcontrolsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~contentsettings_dataurlinsvguseenabled","displayName":"Data URL support for SVGUseElement (User)","description":"This policy enables Data URL support for SVGUseElement, which will be disabled\r\nby default starting in Edge stable version 119.\r\nIf this policy is Enabled, Data URLs will keep working in SVGUseElement.\r\nIf this policy is Disabled or left not set, Data URLs won't work in SVGUseElement.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~contentsettings_dataurlinsvguseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~contentsettings_dataurlinsvguseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~network_compressiondictionarytransportenabled","displayName":"Enable compression dictionary transport support (User)","description":"This feature enables the use of dictionary-specific content encodings in the Accept-Encoding request header (\"sbr\" and \"zst-d\") when dictionaries are available for use.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will accept web contents using the compression dictionary transport feature.\r\n\r\nIf you disable this policy, Microsoft Edge will turn off the compression dictionary transport feature.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~network_compressiondictionarytransportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~network_compressiondictionarytransportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes (User)","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when:\r\n- The 'Passwords' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\r\n- The policy ClearBrowsingDataOnExit is enabled\r\n\r\nIf you enable this policy, passwords won't be cleared when the browser closes.\r\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~smartscreen_exemptsmartscreendownloadwarnings","displayName":"Disable SmartScreen AppRep based warnings for specified file types on specified domains (User)","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from SmartScreen AppRep warnings. For example, if the \"vbe\" extension is associated with \"website1.com\", users would not see a SmartScreen AppRep warning when downloading \"vbe\" files from \"website1.com\", but may see a download warning when downloading \"vbe\" files from \"website2.com\".\r\n\r\nFiles with file type extensions specified for domains identified by this policy will still be subject to file type extension-based security warnings and mixed-content download warnings.\r\n\r\nIf you disable this policy or don't configure it, files that trigger SmartScreen AppRep download warnings will show warnings to the user.\r\n\r\nIf you enable this policy:\r\n\r\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so \"vbe\" should be used instead of \".vbe\".\r\n\r\nExample:\r\n\r\nThe following example value would prevent SmartScreen AppRep warnings on msi, exe, and vbe extensions for *.contoso.com domains. It may show the user a SmartScreen AppRep warning on any other domain for exe and msi files, but not for vbe files.\r\n\r\n[\r\n { \"file_extension\": \"msi\", \"domains\": [\"contoso.com\"] },\r\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\r\n { \"file_extension\": \"vbe\", \"domains\": [\"*\"] }\r\n]\r\n\r\nNote that while the preceding example shows the suppression of SmartScreen AppRep download warnings for \"vbe\" files for all domains, applying suppression of such warnings for all domains is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"domains\": [\r\n \"https://contoso.com\",\r\n \"contoso2.com\"\r\n ],\r\n \"file_extension\": \"msi\"\r\n },\r\n {\r\n \"domains\": [\r\n \"*\"\r\n ],\r\n \"file_extension\": \"vbe\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~smartscreen_exemptsmartscreendownloadwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~smartscreen_exemptsmartscreendownloadwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~smartscreen_exemptsmartscreendownloadwarnings_exemptsmartscreendownloadwarnings","displayName":"Disable SmartScreen AppRep based warnings for specified file types on specified domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagebingchatenabled","displayName":"Disable Bing chat entry-points on Microsoft Edge Enterprise new tab page (User)","description":"By default, there are two Bing chat entry-points on new tab page. One is inside the new tab page search box, and one is in the Bing Autosuggest drawer on-click.\r\n\r\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge Enterprise new tab page and the Bing chat entry-points are there for users.\r\n\r\nIf you disable this policy, Bing chat entry-points don't appear on the new tab page.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagebingchatenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagebingchatenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagecompanylogoenabled","displayName":"Hide the company logo on the Microsoft Edge new tab page (User)","description":"By default, the company logo is shown on the new tab page if the company logo is configured in Admin Portal.\r\n\r\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge new tab page and the company logo is there for users.\r\n\r\nIf you disable this policy, the company logo doesn't appear on Microsoft Edge new tab page.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagecompanylogoenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagecompanylogoenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge_recommended_organizationalbrandingonworkprofileuienabled_recommended","displayName":"Allow the use of your organization's branding assets from Microsoft Entra on the profile-related UI of a work profile (User)","description":"Allow the use of your organization's branding assets from Entra, if any, on the profile-related UI of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect.\r\n\r\nIf you enable this policy, your organization's branding assets from Entra will be used.\r\n\r\nIf you disable or don't configure this policy, your organization's branding assets from Entra won't be used.\r\n\r\nFor more information about configuring your organization's branding assets on Entra, please visit https://go.microsoft.com/fwlink/?linkid=2254514.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge_recommended_organizationalbrandingonworkprofileuienabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge_recommended_organizationalbrandingonworkprofileuienabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile","displayName":"Switch intranet sites to a work profile (User)","description":"Allows Microsoft Edge to switch to the appropriate profile when Microsoft Edge detects that a URL is the intranet.\r\n\r\nIf you enable or don't configure this policy, navigations to intranet URLs will switch to the most recently used work profile if one exists.\r\n\r\nIf you disable this policy, navigations to intranet URLs will remain in the current browser profile.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchsitesoniemodesitelisttoworkprofile","displayName":"Switch sites on the IE mode site list to a work profile (User)","description":"Allows Microsoft Edge to switch to the appropriate profile when navigating to a site that matches an entry on the IE mode site list. Only sites that specify IE mode or Edge mode will be switched to the work profile.\r\n\r\nIf you enable or don't configure this policy, navigations to URLs matching a site on the IE mode site list will switch to the most recently used work profile if one exists.\r\n\r\nIf you disable this policy, navigations to URLs matching a site on the IE mode site list will remain in the current browser profile.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchsitesoniemodesitelisttoworkprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchsitesoniemodesitelisttoworkprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementpolicyoverridesplatformpolicy","displayName":"Microsoft Edge management service policy overrides platform policy. (User)","description":"If you enable this policy, the cloud-based Microsoft Edge management service policy takes precedence if it conflicts with platform policy.\r\n\r\nIf you disable or don't configure this policy, platform policy takes precedence if it conflicts with the cloud-based Microsoft Edge management service policy.\r\n\r\nThis mandatory policy affects machine scope cloud-based Microsoft Edge management policies.\r\n\r\nMachine policies apply to all edge browser instances regardless of the user who is logged in.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementpolicyoverridesplatformpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementpolicyoverridesplatformpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementuserpolicyoverridescloudmachinepolicy","displayName":"Allow cloud-based Microsoft Edge management service user policies to override local user policies. (User)","description":"If you enable this policy, cloud-based Microsoft Edge management service user policies takes precedence if it conflicts with local user policy.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge management service user policies will take precedence.\r\n\r\nThe policy can be combined with 'EdgeManagementPolicyOverridesPlatformPolicy' (Microsoft Edge management service policy overrides platform policy.). If both policies are enabled, all cloud-based Microsoft Edge management service policies will take precedence over conflicting local service policies.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementuserpolicyoverridescloudmachinepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementuserpolicyoverridescloudmachinepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_edge3pserptelemetryenabled","displayName":"Edge 3P SERP Telemetry Enabled (User)","description":"Edge3P Telemetry in Microsoft Edge captures the searches user does on third party search providers without identifying the person or the device and captures only if the user has consented to this collection of data. User can turn off the collection at any time in the browser settings.\r\n\r\nIf you enable or don't configure this policy, Edge 3P SERP Telemetry feature will be enabled.\r\n\r\nIf you disable this policy, Edge 3P SERP Telemetry feature will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_edge3pserptelemetryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_edge3pserptelemetryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_edge3pserptelemetryenabled_recommended","displayName":"Edge 3P SERP Telemetry Enabled (User)","description":"Edge3P Telemetry in Microsoft Edge captures the searches user does on third party search providers without identifying the person or the device and captures only if the user has consented to this collection of data. User can turn off the collection at any time in the browser settings.\r\n\r\nIf you enable or don't configure this policy, Edge 3P SERP Telemetry feature will be enabled.\r\n\r\nIf you disable this policy, Edge 3P SERP Telemetry feature will be disabled.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_edge3pserptelemetryenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_edge3pserptelemetryenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_organizationlogooverlayonappiconenabled_recommended","displayName":"Allow your organization's logo from Microsoft Entra to be overlaid on the Microsoft Edge app icon of a work profile (User)","description":"Allow your organization's logo from Entra, if any, to be overlaid on the Microsoft Edge app icon of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect.\r\n\r\nIf you enable this policy, your organization's logo from Entra will be used.\r\n\r\nIf you disable or don't configure this policy, your organization's logo from Entra won't be used.\r\n\r\nFor more information about configuring your organization's logo on Entra, please visit https://go.microsoft.com/fwlink/?linkid=2254514.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_organizationlogooverlayonappiconenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_organizationlogooverlayonappiconenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~identity_recommended_automaticprofileswitchingsitelist_recommended","displayName":"Configure the automatic profile switching site list (User)","description":"Set this policy to control which profiles Microsoft Edge will use to open sites in. Switching configurations for sites listed in this policy take precedence over other heuristics Microsoft Edge uses for switching sites but note that sites not listed on this policy are still subject to switching by those heuristics. If this policy is not configured, Microsoft Edge will continue using its heuristics to automatically switch sites.\r\n\r\nThis policy maps a URL hostname to a profile that it should be opened in.\r\n\r\nThe 'site' field should take the form of a URL hostname.\r\n\r\nThe 'profile' field can take one of the following values:\r\n- 'Work': The most recently used Microsoft Entra signed-in profile will be used to open 'site'.\r\n- 'Personal': The most recently used MSA signed-in profile will be used to open 'site'.\r\n- 'No preference': The currently used profile will be used to open 'site'.\r\n- Wildcard email address: This takes the form of '*@contoso.com'. A profile whose username ends with the contents following the '*' will be used to open 'site'.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"site\": \"work.com\",\r\n \"profile\": \"Work\"\r\n },\r\n {\r\n \"site\": \"personal.com\",\r\n \"profile\": \"Personal\"\r\n },\r\n {\r\n \"site\": \"nopreference.com\",\r\n \"profile\": \"No preference\"\r\n },\r\n {\r\n \"site\": \"contoso.com\",\r\n \"profile\": \"*@contoso.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"04b46099-4ee5-4def-8e04-569c988057a9","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~identity_recommended_automaticprofileswitchingsitelist_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~identity_recommended_automaticprofileswitchingsitelist_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~identity_recommended_automaticprofileswitchingsitelist_recommended_automaticprofileswitchingsitelist","displayName":"Configure the automatic profile switching site list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"04b46099-4ee5-4def-8e04-569c988057a9","categoryName":"Identity and sign-in","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~sleepingtabs_recommended_autodiscardsleepingtabsenabled_recommended","displayName":"Configure auto discard sleeping tabs (User)","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab will need to be reloaded.\r\n\r\nIf the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature will be enabled by default.\r\n\r\nIf the 'SleepingTabsEnabled' is disabled, then this feature will be disabled by default and cannot be enabled.\r\n\r\nIf enabled, idle background tabs will be discarded after 1.5 days.\r\n\r\nIf disabled, idle background tab will not be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~sleepingtabs_recommended_autodiscardsleepingtabsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~sleepingtabs_recommended_autodiscardsleepingtabsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_webappsettings","displayName":"Web App management settings (User)","description":"This policy allows an admin to specify settings for installed web apps. This policy maps a Web App ID to its specific setting. A default configuration can be set using the special ID *, which applies to all web apps without a custom configuration in this policy.\r\n\r\n- The manifest_id field is the Manifest ID for the Web App.\r\nSee https://developer.chrome.com/blog/pwa-manifest-id/\r\nfor instructions on how to determine the Manifest ID for an installed web app.\r\n- The run_on_os_login field specifies if a web app can be run during OS login.\r\nIf this field is set to blocked, the web app will not run during OS login and the user will not be able to enable this later.\r\nIf this field is set to run_windowed, the web app will run during OS login and the user won't be able to disable this later.\r\nIf this field is set to allowed, the user will be able to configure the web app to run at OS login.\r\nThe default policy configuration only allows the allowed and blocked values.\r\n- (Starting with Microsoft Edge version 120) The prevent_close_after_run_on_os_login field specifies if a web app can be prevented from closing in any way.\r\nFor example, by the user, by task manager, or by web APIs. This behavior can only be enabled if run_on_os_login is set to run_windowed.\r\nIf the app is already running, this setting will only take effect after the app is restarted.\r\nIf this field isn't defined, users can close the app.\r\n(This is currently not supported in Microsoft Edge.)\r\n- (Since version 118) The force_unregister_os_integration field specifies if all OS integration for a web app, that is, shortcuts, file handlers, protocol handlers and so on will be removed or not.\r\nIf an app is already running, this property will come into effect after the app restarts.\r\nThis should be used with caution, since it can override any OS integration that is set automatically during the startup of the web applications system. This currently only works on Windows, Mac and Linux platforms.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"manifest_id\": \"https://foo.example/index.html\",\r\n \"run_on_os_login\": \"allowed\"\r\n },\r\n {\r\n \"manifest_id\": \"https://bar.example/index.html\",\r\n \"run_on_os_login\": \"allowed\"\r\n },\r\n {\r\n \"manifest_id\": \"https://foobar.example/index.html\",\r\n \"run_on_os_login\": \"run_windowed\",\r\n \"prevent_close_after_run_on_os_login\": true\r\n },\r\n {\r\n \"manifest_id\": \"*\",\r\n \"run_on_os_login\": \"blocked\"\r\n },\r\n {\r\n \"manifest_id\": \"https://foo.example/index.html\",\r\n \"force_unregister_os_integration\": true\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_webappsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_webappsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_webappsettings_webappsettings","displayName":"Web App management settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist","displayName":"Configure the automatic profile switching site list (User)","description":"Set this policy to control which profiles Microsoft Edge will use to open sites in. Switching configurations for sites listed in this policy take precedence over other heuristics Microsoft Edge uses for switching sites but note that sites not listed on this policy are still subject to switching by those heuristics. If this policy is not configured, Microsoft Edge will continue using its heuristics to automatically switch sites.\r\n\r\nThis policy maps a URL hostname to a profile that it should be opened in.\r\n\r\nThe 'site' field should take the form of a URL hostname.\r\n\r\nThe 'profile' field can take one of the following values:\r\n- 'Work': The most recently used Microsoft Entra signed-in profile will be used to open 'site'.\r\n- 'Personal': The most recently used MSA signed-in profile will be used to open 'site'.\r\n- 'No preference': The currently used profile will be used to open 'site'.\r\n- Wildcard email address: This takes the form of '*@contoso.com'. A profile whose username ends with the contents following the '*' will be used to open 'site'.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"site\": \"work.com\",\r\n \"profile\": \"Work\"\r\n },\r\n {\r\n \"site\": \"personal.com\",\r\n \"profile\": \"Personal\"\r\n },\r\n {\r\n \"site\": \"nopreference.com\",\r\n \"profile\": \"No preference\"\r\n },\r\n {\r\n \"site\": \"contoso.com\",\r\n \"profile\": \"*@contoso.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist_automaticprofileswitchingsitelist","displayName":"Configure the automatic profile switching site list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled","displayName":"Configure auto discard sleeping tabs (User)","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab will need to be reloaded.\r\n\r\nIf the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature will be enabled by default.\r\n\r\nIf the 'SleepingTabsEnabled' is disabled, then this feature will be disabled by default and cannot be enabled.\r\n\r\nIf enabled, idle background tabs will be discarded after 1.5 days.\r\n\r\nIf disabled, idle background tab will not be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly","displayName":"Force Windows executable Native Messaging hosts to launch directly (User)","description":"This policy controls whether native host executables launch directly on Windows.\r\n\r\nIf you enable this policy, Microsoft Edge is forced to launch native messaging hosts implemented as executables directly.\r\n\r\nIf you disable this policy, Microsoft Edge will launch hosts using cmd.exe as an intermediary process.\r\n\r\nIf you don't configure this policy, Microsoft Edge will decide which approach to use based on a progressive rollout from the legacy behavior to the Launch Directly behavior, guided by ecosystem compatibility.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_postquantumkeyagreementenabled","displayName":"Enable post-quantum key agreement for TLS (User)","description":"This policy configures whether Microsoft Edge will offer a post-quantum key agreement algorithm in TLS. This lets supporting servers protect user traffic from being decrypted by quantum computers.\r\n\r\nIf you enable this policy, Microsoft Edge will offer a post-quantum key agreement in TLS connections. TLS connections will be protected from quantum computers when communicating with compatible servers.\r\n\r\nIf you disable this policy, Microsoft Edge will not offer a post-quantum key agreement in TLS connections. User traffic will be unprotected from decryption by quantum computers.\r\n\r\nIf you don't configure this policy, Microsoft Edge will follow the default rollout process for offering a post-quantum key agreement.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing TLS servers and networking middleware are expected to ignore the new option and continue selecting previous options.\r\n\r\nHowever, devices that don't implement TLS correctly may malfunction when offered the new option. For example, they might disconnect in response to unrecognized options or the resulting larger messages. These devices are not post-quantum-ready and will interfere with an enterprise's post-quantum transition. If this issue is encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Microsoft Edge. You can enable it to test for issues and you can disable it while you resolve issues.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_postquantumkeyagreementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_postquantumkeyagreementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~googlecast_edgedisabledialprotocolforcastdiscovery","displayName":"Disable DIAL protocol for cast device discovery (User)","description":"Enable this policy to disable the DIAL (Discovery And Launch) protocol for cast device discovery. (If EnableMediaRouter is disabled, this policy will have no effect).\r\n\r\nEnable this policy to disable DIAL protocol.\r\n\r\nBy default, Cast device discovery will use DIAL protocol.","helpText":"","infoUrls":[],"categoryId":"fddc444c-3591-4a50-865b-d8993b798e12","categoryName":"Cast","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~googlecast_edgedisabledialprotocolforcastdiscovery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~googlecast_edgedisabledialprotocolforcastdiscovery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsenabled","displayName":"Enable Related Website Sets (User)","description":"This policy lets you control the enablement of the Related Website Sets feature. Related Website Sets (RWS) is a way for an organisation to declare relationships among sites, so that Microsoft Edge allows limited third-party cookie access for specific purposes across those sites.\r\n\r\nIf this policy set to True or unset, the Related Website Sets feature is enabled.\r\n\r\nIf this policy is set to False, the Related Website Sets feature is disabled.","helpText":"","infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (User)","description":"This policy provides a way to override the list of sets Microsoft Edge uses for Related Website Sets\r\n\r\nEach set in the browser's list of Related Website Sets must meet the requirements of a Related Website Set. A Related Website Set must contain a primary site and one or more member sites.\r\nA set can also contain a list of service sites that it owns, as well as a map from a site to all its ccTLD variants. See https://github.com/WICG/first-party-sets for more information on how Microsoft Edge uses Related Website Sets.\r\n\r\n\r\nAll sites in a Related Website Set must be a registrable domain served over HTTPS. Each site in a Related Website Set must also be unique, which means a site can't be listed more than once in a Related Website Set.\r\n\r\nWhen this policy is given an empty dictionary, Microsoft Edge uses the public list of Related Website Sets.\r\n\r\nFor all sites in a Related Website Set from the replacements list, if a site is also present on a Related Website Set in the browser's list, then that site will be removed from the browser's Related Website Set. After this, the policy's Related Website Set will be added to the Microsoft Edge's list of Related Website Sets.\r\n\r\nFor all sites in a Related Website Set from the additions list, if a site is also present on a Related Website Set in Microsoft Edge's list, then the browser's Related Website Set will be updated so that the new Related Website Set can be added to the browser's list. After the browser's list has been updated, the policy's Related Website Set will be added to the browser's list of Related Website Sets.\r\n\r\nThe browser's list of Related Website Sets requires that for all sites in its list, no site is in\r\nmore than one set. This is also required for both the replacements list\r\nand the additions list. Similarly, a site can't be in both the\r\nreplacements list and the additions list.\r\n\r\nWildcards (*) aren't supported as a policy value, or as a value within any Related Website Set in these lists.\r\n\r\nExample value:\r\n\r\n{\r\n \"additions\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate2.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate2.test\": [\r\n \"https://associate2.com\"\r\n ]\r\n },\r\n \"primary\": \"https://primary2.test\",\r\n \"serviceSites\": [\r\n \"https://associate2-content.test\"\r\n ]\r\n }\r\n ],\r\n \"replacements\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate1.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate1.test\": [\r\n \"https://associate1.co.uk\"\r\n ]\r\n },\r\n \"primary\": \"https://primary1.test\",\r\n \"serviceSites\": [\r\n \"https://associate1-content.test\"\r\n ]\r\n }\r\n ]\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"additions\": [{\"associatedSites\": [\"https://associate2.test\"], \"ccTLDs\": {\"https://associate2.test\": [\"https://associate2.com\"]}, \"primary\": \"https://primary2.test\", \"serviceSites\": [\"https://associate2-content.test\"]}], \"replacements\": [{\"associatedSites\": [\"https://associate1.test\"], \"ccTLDs\": {\"https://associate1.test\": [\"https://associate1.co.uk\"]}, \"primary\": \"https://primary1.test\", \"serviceSites\": [\"https://associate1-content.test\"]}]}","helpText":"","infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_preventtyposquattingpromptoverride","displayName":"Prevent bypassing Edge Website Typo Protection prompts for sites (User)","description":"This policy setting lets you decide whether users can override the Edge Website Typo Protection warnings about potential typosquatting websites.\r\n\r\nIf you enable this setting, users can't ignore Edge Website Typo Protection warnings and they are blocked from continuing to the site.\r\n\r\nIf you disable or don't configure this setting, users can ignore Edge Website Typo Protection warnings and continue to the site.\r\n\r\nThis will only take effect when TyposquattingCheckerEnabled policy is not set or set to enabled.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_preventtyposquattingpromptoverride_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_preventtyposquattingpromptoverride_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains","displayName":"Configure the list of domains for which Edge Website Typo Protection won't trigger warnings (User)","description":"Configure the list of Edge Website Typo Protection trusted domains. This means:\r\nEdge Website Typo Protection won't check for potentially malicious typosquatting websites.\r\n\r\nIf you enable this policy, Edge Website Typo Protection trusts these domains.\r\nIf you disable or don't set this policy, default Edge Website Typo Protection protection is applied to all resources.\r\n\r\nThis will only take effect when TyposquattingCheckerEnabled policy is not set or set to enabled.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10/11 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.\r\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender for Endpoint. You must configure your allow and block lists in Microsoft 365 Defender portal using Indicators (Settings > Endpoints > Indicators).\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_typosquattingallowlistdomainsdesc","displayName":"Configure the list of domains for which Edge Website Typo Protection won't trigger warnings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled","displayName":"Enables DALL-E themes generation (User)","description":"This policy lets you generate browser themes using DALL-E and apply them to Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, the AI generated themes will be enabled.\r\n\r\nIf you disable this policy, the AI generated themes will be disabled for your organization.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_enhancesecuritymodeallowuserbypass","displayName":"Allow users to bypass Enhanced Security Mode (User)","description":"Microsoft Edge will let users bypass Enhanced Security Mode on a site via Settings page or PageInfo flyout. This policy lets you configure whether users can bypass Enhanced Security Mode.\r\n\r\nIf you disable this policy, Microsoft Edge won't allow users to bypass Enhanced Security Mode.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will allow users to bypass Enhanced Security Mode.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_enhancesecuritymodeallowuserbypass_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_enhancesecuritymodeallowuserbypass_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_superdragdropenabled","displayName":"Super Drag Drop Enabled (User)","description":"This policy lets you configure the Super Drag Drop feature in Microsoft Edge.\r\n\r\nWith this feature, users can drag a link or text from a webpage and drop it onto the same page. They can then either open the URL in a new tab or search the text using the default search engine.\r\n\r\nIf you enable or don't configure this policy, you can use the Super Drag Drop feature on Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Super Drag Drop feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_superdragdropenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_superdragdropenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_urldiagnosticdataenabled","displayName":"URL reporting in Edge diagnostic data enabled (User)","description":"Controls sending URLs of pages visited and per-page usage in the Microsoft Edge optional diagnostics data to Microsoft to help make browsing and search better. This also includes identifiers and usage diagnostics of other browser components that can modify or provide content, such as extensions.\r\n\r\nThis policy is applicable only if the 'DiagnosticData' (Send required and optional diagnostic data about browser usage) setting is set to 'OptionalData'. See the description of 'DiagnosticData' for more information on how Microsoft Edge diagnostic data levels are set.\r\n\r\nIf you enable or don't configure this setting, URLs are provided in optional diagnostic data.\r\n\r\nIf you disable this setting, URLs are not reported in optional diagnostic data.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_urldiagnosticdataenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_urldiagnosticdataenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_rsakeyusageforlocalanchorsenabled","displayName":"Check RSA key usage for server certificates issued by local trust anchors (User)","description":"The X.509 key usage extension declares how the key in a certificate can be\r\nused. These instructions ensure certificates aren't used in an unintended\r\ncontext, which protects against a class of cross-protocol attacks on HTTPS and\r\nother protocols. HTTPS clients must verify that server certificates match the\r\nconnection's TLS parameters.\r\n\r\nIf this policy is enabled,\r\nMicrosoft Edge will perform this key\r\ncheck. This helps prevent attacks where an attacker manipulates the browser into\r\ninterpreting a key in ways that the certificate owner did not intend.\r\n\r\nIf this policy is set to disabled or not configured,\r\nMicrosoft Edge will skip this key check in\r\nHTTPS connections that negotiate TLS 1.2 and use an RSA certificate that\r\nchains to a local trust anchor. Examples of local trust anchors include\r\npolicy-provided or user-installed root certificates. In all other cases, the\r\ncheck is performed independent of this policy's setting.\r\n\r\nThis policy is available for administrators to preview the behavior of a\r\nfuture release, which will enable this check by default. At that point, this\r\npolicy will remain temporarily available for administrators that need more\r\ntime to update their certificates to meet the new RSA key usage requirements.\r\n\r\nConnections that fail this check will fail with the error\r\nERR_SSL_KEY_USAGE_INCOMPATIBLE. Sites that fail with this error likely have a\r\nmisconfigured certificate. Modern ECDHE_RSA cipher suites use the\r\n\"digitalSignature\" key usage option, while legacy RSA decryption cipher suites\r\nuse the \"keyEncipherment\" key usage option. If uncertain, administrators should\r\ninclude both in RSA certificates meant for HTTPS.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_rsakeyusageforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_rsakeyusageforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_screencapturewithoutgestureallowedfororigins","displayName":"Allow screen capture without prior user gesture (User)","description":"For security reasons, the\r\ngetDisplayMedia() web API requires\r\na prior user gesture (\"transient activation\") to be called or the API will\r\nfail.\r\n\r\nWhen this policy is configured, admins can specify origins on which this API\r\ncan be called without prior user gesture.\r\n\r\nFor detailed information on valid url patterns, see\r\nhttps://go.microsoft.com/fwlink/?linkid=2095322. Note: * is not an accepted\r\nvalue for this policy.\r\n\r\nIf this policy is not configured, all origins require a prior user gesture to\r\ncall this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_screencapturewithoutgestureallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_screencapturewithoutgestureallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_screencapturewithoutgestureallowedfororigins_screencapturewithoutgestureallowedfororiginsdesc","displayName":"Allow screen capture without prior user gesture (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting (User)","description":"Setting the policy to \"BlockWindowManagement\" (value 2) automatically denies the window management permission to sites by default. This limits the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nSetting the policy to \"AskWindowManagement\" (value 3) by default prompts the user when the window management permission is requested. If users allow the permission, it extends the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nNot configuring the policy means the \"AskWindowManagement\" policy applies, but users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockWindowManagement (2) = Denies the Window Management permission on all sites by default\r\n\r\n* AskWindowManagement (3) = Ask every time a site wants obtain the Window Management permission\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_defaultwindowmanagementsetting_2","displayName":"Denies the Window Management permission on all sites by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_defaultwindowmanagementsetting_3","displayName":"Ask every time a site wants obtain the Window Management permission","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementallowedforurls","displayName":"Allow Window Management permission on specified sites (User)","description":"Lets you configure a list of site url patterns that specify sites which will automatically grant the window management permission. This extends the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy isn't configured for a site, then the policy from 'DefaultWindowManagementSetting' (Default Window Management permission setting) applies to the site, if configured. Otherwise the permission will follow the browser's defaults and let users choose this permission per site.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementallowedforurls_windowmanagementallowedforurlsdesc","displayName":"Allow Window Management permission on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls","displayName":"Block Window Management permission on specified sites (User)","description":"Lets you configure a list of site url patterns that specify sites which will automatically deny the window management permission. This limits the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy isn't configured for a site, then the policy from 'DefaultWindowManagementSetting' (Default Window Management permission setting) applies to the site, if configured. Otherwise the permission will follow the browser's defaults and let users choose this permission per site.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls_windowmanagementblockedforurlsdesc","displayName":"Block Window Management permission on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensioninstalltypeblocklist","displayName":"Blocklist for extension install types (User)","description":"The blocklist controls which extension install types are disallowed.\r\n\r\nSetting the \"command_line\" will block an extension from being loaded from command line.\r\n\r\nPolicy options mapping:\r\n\r\n* command_line (command_line) = Blocks extensions from being loaded from command line\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\ncommand_line","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensioninstalltypeblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensioninstalltypeblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensioninstalltypeblocklist_extensioninstalltypeblocklistdesc","displayName":"Blocklist for extension install types (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability (User)","description":"Control if Manifest v2 extensions can be used by browser.\r\n\r\nManifest v2 extensions support will be deprecated and all extensions need to be migrated to v3 in the future. More information about, and the timeline of the migration has not been established.\r\n\r\nIf the policy is set to Default or not set, v2 extension loading is decided by browser. This will follow the preceding timeline when it's established.\r\n\r\nIf the policy is set to Disable, v2 extensions installation are blocked, and existing ones are disabled. This option is going to be treated the same as if the policy is unset after v2 support is turned off by default.\r\n\r\nIf the policy is set to Enable, v2 extensions are allowed. The option is going to be treated the same as if the policy isn't set before v2 support is turned off by default.\r\n\r\nIf the policy is set to EnableForForcedExtensions, force installed v2 extensions are allowed. This includes extensions that are listed by 'ExtensionInstallForcelist' (Control which extensions are installed silently) or 'ExtensionSettings' (Configure extension management settings) with installation_mode \"force_installed\" or \"normal_installed\". All other v2 extensions are disabled. The option is always available regardless of the manifest migration state.\r\n\r\nExtensions availabilities are still controlled by other policies.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default browser behavior\r\n\r\n* Disable (1) = Manifest v2 is disabled\r\n\r\n* Enable (2) = Manifest v2 is enabled\r\n\r\n* EnableForForcedExtensions (3) = Manifest v2 is enabled for forced extensions only\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_0","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_1","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_2","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_3","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotcdppagecontext","displayName":"Control Copilot with Commercial Data Protection access to page context for Microsoft Entra ID profiles (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 132.\r\n\r\nThis policy has been obsoleted as of Edge 133. Instead of this obsolete policy, we recommend using 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane).\r\n\r\nThis policy controls access to page contents for Copilot with Commercial Data Protection in the Edge sidebar. This policy applies only to Microsoft Entra ID profiles. To summarize pages and interact with text selections, it needs to be able to access the page contents. This policy does not apply to MSA profiles. This policy doesn't control access for Copilot without Commercial Data Protection. Access for Copilot without Commercial Data Protection is controlled by the policy CopilotPageContext.\r\n\r\nIf you enable this policy, Copilot with Commercial Data Protection will have access to page context.\r\n\r\nIf you don't configure this policy, a user can enable access to page context for Copilot with Commercial Data Protection using the setting toggle in Edge.\r\n\r\nIf you disable this policy, Copilot with Commercial Data Protection will not be able to access page context.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotcdppagecontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotcdppagecontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotpagecontext","displayName":"Control Copilot access to page context for Microsoft Entra ID profiles (User)","description":"This policy controls access to page contents for Copilot in the Microsoft Edge sidebar when users are logged into their MSA Copilot account. This policy applies only to Microsoft Entra ID Microsoft Edge profiles. To summarize pages and interact with text selections, it needs to be able to access the page contents. This policy does not apply to MSA Microsoft Edge profiles. This policy doesn't control access for Copilot with enterprise data protection (EDP). Access for Copilot with enterprise data protection (EDP) is controlled by the 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane) policy.\r\n\r\nIf you enable this policy, Copilot will have access to page content when logged in with Entra ID.\r\n\r\nIf this policy is not configured, the default behavior for non-EU countries is that access is initially enabled. For EU countries, the default behavior is that access is initially disabled. In both cases, if the policy is not configured, users can enable or disable Copilot's access to page content using the setting toggle in Microsoft Edge.\r\n\r\nIf you disable this policy, Copilot will not be able to access page context.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotpagecontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotpagecontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled","displayName":"Enable deprecated/removed Mutation Events (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy provides a temporary opt-in back to a deprecated and removed set of platform events named Mutation Events.\r\n\r\nIf you enable this policy, mutation events will continue to be fired, even if they've been disabled by default for normal web users.\r\n\r\nIf you disable or don't configure this policy, these events will not be fired.\r\n\r\nThis policy is a temporary workaround, and enterprises should still work to remove their dependencies on these mutation events.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_imageeditorserviceenabled","displayName":"Enable the Designer for Image Editor feature (User)","description":"Lets users access and use the Designer for Image Editor feature to edit an image they select.\r\n\r\nIf you enable or don't configure this policy, users can access and use the Designer for Image Editor feature in Microsoft Edge.\r\n\r\nIf you disable this policy, users can't access and use the Designer for Image Editor feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_imageeditorserviceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_imageeditorserviceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_qrcodegeneratorenabled","displayName":"Enable QR Code Generator (User)","description":"This policy enables the QR Code generator feature in Microsoft Edge.\r\n\r\nIf you enable this policy or don't configure it, the QR Code Generator feature is enabled.\r\n\r\nIf you disable this policy, the QR Code Generator feature is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_qrcodegeneratorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_qrcodegeneratorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge~network_zstdcontentencodingenabled","displayName":"Enable zstd content encoding support (User)","description":"This feature enables advertising \"zstd\" support in the Accept-Encoding request header and support for decompressing zstd web content.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will accept server responses compressed with zstd.\r\n\r\nIf you disable this policy, the zstd content encoding feature will not be advertised or supported when processing server responses.\r\n\r\nThis policy is temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge~network_zstdcontentencodingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge~network_zstdcontentencodingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge_internetexplorersetforegroundwhenactive","displayName":"Keep the active Microsoft Edge window with an Internet Explorer mode tab always in the foreground. (User)","description":"This policy controls whether to always keep the active Microsoft Edge window with an Internet Explorer mode tab in the foreground.\r\n\r\nIf you enable this policy, the active Microsoft Edge window with an Internet Explorer mode tab will always be in the foreground.\r\n\r\nIf you disable or don't configure this policy, the active Microsoft Edge window with an Internet Explorer mode tab will not be kept in the foreground.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge_internetexplorersetforegroundwhenactive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge_internetexplorersetforegroundwhenactive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge~identity_proactiveauthworkflowenabled","displayName":"Enable proactive authentication (User)","description":"This policy controls the proactive authentication in Microsoft Edge, that connects the signed-in user identity with Microsoft Bing, MSN and Copilot services for a smooth and consistent sign-in experience.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser.\r\n\r\nIf you disable this policy, Microsoft Edge does not send authentications requests to these services and users will need to manually sign-in.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge~identity_proactiveauthworkflowenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge~identity_proactiveauthworkflowenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_csscustomstatedeprecatedsyntaxenabled","displayName":"Controls whether the deprecated :--foo syntax for CSS custom state is enabled (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 132.\r\n\r\nThe :--foo syntax for the CSS custom state feature is being changed to :state(foo) in Microsoft Edge in order to comply with changes that have been made in Firefox and Safari. This policy lets the deprecated syntax to be used until Stable 132.\r\n\r\nThis deprecation might break some Microsoft Edge-only websites that use the deprecated :--foo syntax.\r\n\r\nIf you enable this policy, the deprecated syntax will be enabled.\r\n\r\nIf you disable this policy or don't set it, the deprecated syntax will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_csscustomstatedeprecatedsyntaxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_csscustomstatedeprecatedsyntaxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist","displayName":"Control which apps cannot be opened in Microsoft Edge sidebar (User)","description":"Define a list of sites, based on URL patterns, that cannot be opened in sidebar.\r\n\r\nIf you don't configure this policy, a user can open any app in sidebar.\r\n\r\nIf the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used and no sidebar can be opened.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nNote: A blocklist value of '*' means all apps are blocked unless they are explicitly listed in the 'EdgeSidebarAppUrlHostAllowList' (Allow specific apps to be opened in Microsoft Edge sidebar) policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_edgesidebarappurlhostblocklistdesc","displayName":"Control which apps cannot be opened in Microsoft Edge sidebar (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128.1~policy~microsoft_edge_applicationboundencryptionenabled","displayName":"Enable Application Bound Encryption (User)","description":"Enabling this policy or leaving it unset binds the encryption keys used for local data storage to Microsoft Edge whenever possible.\r\n\r\nDisabling this policy has a detrimental effect on Microsoft Edge's security because unknown and potentially hostile apps can retrieve the encryption keys used to secure data.\r\n\r\nOnly turn off this policy if there are compatibility issues, such as scenarios where other applications need legitimate access to Microsoft Edge's data. Encrypted user data is expected to be fully portable between different computers or the integrity and location of Microsoft Edge's executable files isn’t consistent.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128.1~policy~microsoft_edge_applicationboundencryptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128.1~policy~microsoft_edge_applicationboundencryptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings","displayName":"Dynamic Code Settings (User)","description":"This policy controls the dynamic code settings for Microsoft Edge.\r\n\r\nDisabling dynamic code improves the security of Microsoft Edge by preventing potentially hostile dynamic code and third-party code from making changes to Microsoft Edge's behavior. However this might cause compatibility issues with third-party software that must run in the browser process.\r\n\r\nIf you set this policy to 0 (the default) or leave unset, then Microsoft Edge will use the default settings.\r\n\r\nIf you set this policy to 1 – (EnabledForBrowser) then the Microsoft Edge browser process is prevented from creating dynamic code.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default dynamic code settings\r\n\r\n* EnabledForBrowser (1) = Prevent the browser process from creating dynamic code\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_dynamiccodesettings","displayName":"Dynamic Code Settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_dynamiccodesettings_0","displayName":"Default dynamic code settings","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_dynamiccodesettings_1","displayName":"Prevent the browser process from creating dynamic code","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgeopeninsidebarenabled","displayName":"Enable open in sidebar (User)","description":"Allow/Disallow user open a website or an app to the sidebar.\r\n\r\nIf you enable or don't configure this policy, users will be able to access the feature.\r\nIf you disable this policy, users will not be able to access the feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgeopeninsidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgeopeninsidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgesidebarcustomizeenabled","displayName":"Enable sidebar customize (User)","description":"Allow/Disallow to use sidebar customize.\r\n\r\nIf you enable or don't configure this policy, users will be able to access sidebar customize.\r\nIf you disable this policy, users will not be able to access the sidebar customize.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgesidebarcustomizeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgesidebarcustomizeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_keyboardfocusablescrollersenabled","displayName":"Enable keyboard focusable scrollers (User)","description":"This policy provides a temporary opt-out for the new keyboard focusable scrollers behavior.\r\n\r\nWhen this policy is Enabled or unset, scrollers without focusable children are keyboard focusable by default.\r\n\r\nWhen this policy is Disabled, scrollers are not keyboard focusable by default.\r\n\r\nThis policy is a temporary workaround and will be removed in Edge Stable 135.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_keyboardfocusablescrollersenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_keyboardfocusablescrollersenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_recommended~downloads_recommended_showdownloadsinsecurewarningsenabled_recommended","displayName":"Enable insecure download warnings (User)","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\r\n\r\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user will receive a UI warning, such as \"Insecure download blocked.\" The user will still have an option to proceed and download the item.\r\n\r\nIf you disable this policy, the warnings for insecure downloads will be suppressed.","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_recommended~downloads_recommended_showdownloadsinsecurewarningsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_recommended~downloads_recommended_showdownloadsinsecurewarningsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~downloads_showdownloadsinsecurewarningsenabled","displayName":"Enable insecure download warnings (User)","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\r\n\r\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user will receive a UI warning, such as \"Insecure download blocked.\" The user will still have an option to proceed and download the item.\r\n\r\nIf you disable this policy, the warnings for insecure downloads will be suppressed.","helpText":"","infoUrls":[],"categoryId":"5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","categoryName":"Downloads","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~downloads_showdownloadsinsecurewarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~downloads_showdownloadsinsecurewarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page (User)","description":"Control if users can turn on Developer Mode on edge://extensions.\r\n\r\nIf the policy isn't set, users can turn on developer mode on the extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\r\nIf the policy is set to Allow (0), users can turn on developer mode on the extensions page.\r\nIf the policy is set to Disallow (1), users cannot turn on developer mode on the extensions page.\r\n\r\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.\r\n\r\nPolicy options mapping:\r\n\r\n* Allow (0) = Allow the usage of developer mode on extensions page\r\n\r\n* Disallow (1) = Do not allow the usage of developer mode on extensions page\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensiondevelopermodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensiondevelopermodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings_0","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings_1","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant an extended background lifetime to connecting extensions. (User)","description":"Extensions that connect to one of these origins will keep running as long as the port is connected.\r\nIf unset, the policy's default values are used. These are the app origins that offer SDKs that are known to not offer the possibility to restart a closed connection to a previous state:\r\n- Smart Card Connector\r\n- Citrix Receiver (stable, beta, back-up)\r\n- VMware Horizon (stable, beta)\r\n\r\nIf set, the default value list is extended with the newly configured values. The defaults and policy-provided entries will grant the exception to the connecting extensions, as long as the port is connected.\r\n\r\nExample value:\r\n\r\nchrome-extension://abcdefghijklmnopabcdefghijklmnop/\r\nchrome-extension://bcdefghijklmnopabcdefghijklmnopa/","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_extensionextendedbackgroundlifetimeforportconnectionstourlsdesc","displayName":"Configure a list of origins that grant an extended background lifetime to connecting extensions. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled","displayName":"Enable Printing LPAC Sandbox (User)","description":"Setting this policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services when the system configuration supports it.\r\n\r\nSetting this policy to Disabled has a detrimental effect on Microsoft Edge's security because services used for printing might run in a weaker sandbox configuration.\r\n\r\nOnly turn this policy off if there are compatibility issues with third party software that prevent printing services from operating correctly inside the LPAC Sandbox.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge_edgeentracopilotpagecontext","displayName":"Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane (User)","description":"This policy controls whether Copilot in the Microsoft Edge sidepane can access Microsoft Edge page content. This includes page summarization and similar contextual queries sent to Copilot.\r\n\r\nThis policy only applies to users who are signed in to Microsoft Edge with their Entra account and are using Copilot in the sidepane. This policy applies to all Copilot products in the Microsoft Edge sidepane - namely, Microsoft 365 Copilot Business Chat and Microsoft Copilot with enterprise data protection (EDP).\r\n\r\nIf you enable this policy, Copilot will be able to access Microsoft Edge page content when users ask a contextual query to Copilot in the Microsoft Edge sidepane.\r\n\r\nIf you disable this policy, Copilot will not be able to access Microsoft Edge page content.\r\n\r\nIf you don't configure this policy, the default behavior is as follows:\r\n\r\n- For non-EU countries, access is enabled by default.\r\n\r\n- For EU countries, access is disabled by default.\r\n\r\n- In both cases, if the policy is not configured, users can enable or disable Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings.\r\n\r\nExceptions to the preceding behavior include when a page is protected using data loss prevention (DLP) measures. In that case, Copilot will not be able to access Microsoft Edge page content even when this policy is enabled. This behavior is to ensure the integrity of DLP.\r\n\r\nLearn more about Copilot's data usage and consent at https://go.microsoft.com/fwlink/?linkid=2288056","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge_edgeentracopilotpagecontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge_edgeentracopilotpagecontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge~performance_extensionsperformancedetectorenabled","displayName":"Extensions Performance Detector enabled (User)","description":"This policy controls if users can access the Extensions Performance Detector Recommended Action feature in Browser Essentials. This feature alerts extension users if their extensions are causing performance regressions in the browser and allows them to take action to resolve the issue.\r\n\r\nIf you enable or don't configure this policy, users will receive Extensions Performance Detector notifications from Browser Essentials. When there is an active alert, users will be able to view the impact of extensions on their browser's performance and make an informed decision to disable impacting extensions. The detector will exclude browser-managed extensions, such as Google Docs offline, component extensions, and organization-managed extensions (ie. extensions that cannot be disabled).\r\n\r\nIf you disable this policy, users will not receive notifications or be able to view the Extensions Performance Detector Recommended Action.","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge~performance_extensionsperformancedetectorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge~performance_extensionsperformancedetectorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist","displayName":"Allow specific apps to be opened in Microsoft Edge sidebar (User)","description":"Define a list of sites, based on URL patterns, that are not subject to the 'EdgeSidebarAppUrlHostBlockList' (Control which apps cannot be opened in Microsoft Edge sidebar).\r\n\r\nIf you don't configure this policy, a user can open any app in sidebar except the urls listed in 'EdgeSidebarAppUrlHostBlockList'.\r\n\r\nIf you configure this policy, the apps listed in the allow list could be opened in sidebar even if they are listed in the block list.\r\n\r\nBy default, all apps are allowed. However, if you prohibited apps by policy, you can use the list of allowed apps to change that policy.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist_edgesidebarappurlhostallowlistdesc","displayName":"Allow specific apps to be opened in Microsoft Edge sidebar (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_edgeautofillmlenabled","displayName":"Machine learning powered autofill suggestions (User)","description":"Allows ML technology to predict and fill in forms and text fields for better browsing. Your personal data is secure and will not be used elsewhere.\r\n\r\nIf you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data.\r\n\r\nIf you disable this policy, machine learning powered autofill suggestions will not be shown, and autofill will no longer use cloud-based machine learning models to enhance form filling with smarter, context aware suggestions. Instead, autofill will rely on basic form data without the benefits of machine learning.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_edgeautofillmlenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_edgeautofillmlenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_livetranslationallowed","displayName":"Live translation allowed (User)","description":"Allow users to turn the Realtime Video Translation feature on or off.\r\n\r\nThis feature allows videos being watched to be translated to the selected language in real time or live. Users need to click the translate icon that appears when they hover over a video to get started.\r\n\r\nThis is the on-device feature and none of the audio, data or even translated audio leave the device.\r\n\r\nIf you enable or don't configure this policy, users can turn this feature on or off in edge://settings/languages.\r\nIf you disable this policy, users will not be able to turn this feature on. If user has been using the feature already and policy gets disabled, the feature related files downloaded previously, will be deleted from the device after 30 days. We recommend not to disable the policy, unless it is needed in your environment.\r\n\r\nIf users enable this feature, the feature related files (approximately 200 megabytes) will be downloaded to the device on the first run and periodically thereafter to enhance performance and accuracy. These files will be deleted 30 days after their last use.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_livetranslationallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_livetranslationallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_personalizetopsitesincustomizesidebarenabled","displayName":"Personalize my top sites in Customize Sidebar enabled by default (User)","description":"This policy controls whether Microsoft Edge browser be allowed to use the browsing history to personalize the top sites in the customize sidebar page.\r\n\r\nIf you enable this policy, Microsoft Edge will use the browsing history to personalize the top sites in the customize sidebar page.\r\n\r\nIf you disable this policy, Microsoft Edge will not use the browsing history to personalize the top sites in the customize sidebar page.\r\n\r\nIf you don't configure this policy, the default behavior is to use the browsing history to personalize the top sites in the customize sidebar page.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_personalizetopsitesincustomizesidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_personalizetopsitesincustomizesidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_recommended_edgeautofillmlenabled_recommended","displayName":"Machine learning powered autofill suggestions (User)","description":"Allows ML technology to predict and fill in forms and text fields for better browsing. Your personal data is secure and will not be used elsewhere.\r\n\r\nIf you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data.\r\n\r\nIf you disable this policy, machine learning powered autofill suggestions will not be shown, and autofill will no longer use cloud-based machine learning models to enhance form filling with smarter, context aware suggestions. Instead, autofill will rely on basic form data without the benefits of machine learning.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_recommended_edgeautofillmlenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_recommended_edgeautofillmlenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_selectparserrelaxationenabled","displayName":"Controls whether the new HTML parser behavior for the element. This policy supports the old HTML parser behavior until M136.\r\n\r\nIf this policy is enabled or unset, the HTML parser will allow additional tags inside the element.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_selectparserrelaxationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_selectparserrelaxationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenallowedforurls","displayName":"Allow automatic full screen on specified sites (User)","description":"For security reasons, the\r\nrequestFullscreen() web API\r\nrequires a prior user gesture (\"transient activation\") to be called or it will\r\nfail. Users' personal settings may allow certain origins to call this API\r\nwithout a prior user gesture.\r\n\r\nThis policy supersedes users' personal settings and allows matching origins to\r\ncall the API without a prior user gesture.\r\n\r\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\nWildcards (*) are allowed.\r\n\r\nOrigins matching both blocked and allowed policy patterns will be blocked.\r\nOrigins not specified by policy or user settings will require a prior user\r\ngesture to call this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenallowedforurls_automaticfullscreenallowedforurlsdesc","displayName":"Allow automatic full screen on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls","displayName":"Block automatic full screen on specified sites (User)","description":"For security reasons, the\r\nrequestFullscreen() web API\r\nrequires a prior user gesture (\"transient activation\") to be called or it will\r\nfail. Users' personal settings may allow certain origins to call this API\r\nwithout a prior user gesture.\r\n\r\nThis policy supersedes users' personal settings and blocks matching origins\r\nfrom calling the API without a prior user gesture.\r\n\r\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\nWildcards (*) are allowed.\r\n\r\nOrigins matching both blocked and allowed policy patterns will be blocked.\r\nOrigins not specified by policy or user settings will require a prior user\r\ngesture to call this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls_automaticfullscreenblockedforurlsdesc","displayName":"Block automatic full screen on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~generativeai_genailocalfoundationalmodelsettings","displayName":"Settings for GenAI local foundational model (User)","description":"Configure how Microsoft Edge downloads the foundational GenAI model and uses it for inference locally.\r\n\r\nWhen the policy is set to Allowed (0) or not set, the model is downloaded automatically, and used for inference.\r\n\r\nWhen the policy is set to Disabled (1), the model will not be downloaded.\r\n\r\nModel downloading can also be disabled by ComponentUpdatesEnabled.\r\n\r\nPolicy options mapping:\r\n\r\n* Allowed (0) = Downloads model automatically\r\n\r\n* Disabled (1) = Do not download model\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"76e34834-6d47-4e06-b14c-aa2888cdce27","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~generativeai_genailocalfoundationalmodelsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~generativeai_genailocalfoundationalmodelsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings","displayName":"Settings for GenAI local foundational model (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76e34834-6d47-4e06-b14c-aa2888cdce27","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings_0","displayName":"Downloads model automatically","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings_1","displayName":"Do not download model","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled","displayName":"Enable IPv6 reachability check override (User)","description":"This policy enables an override of the IPv6 reachability check. When overridden, the\r\nsystem will always query AAAA records when resolving host names. It applies to\r\nall users and interfaces on the device.\r\n\r\nIf you enable this policy, the IPv6 reachability check will be overridden.\r\n\r\nIf you disable or don't configure this policy, the IPv6 reachability check will not be overridden.\r\nThe system only queries AAAA records when it is reachable to a global IPv6 host.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~passwordmanager_deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords (User)","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own.\r\n\r\nIf fixing them is possible, it usually requires complex user actions.\r\n\r\nEnabling this policy or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched.\r\n\r\nDisabling this policy means users will have their password manager data untouched, but will experience a broken password manager functionality.\r\n\r\nIf the policy is set, users can't override it in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~passwordmanager_deletingundecryptablepasswordsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~passwordmanager_deletingundecryptablepasswordsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedfilehash","displayName":"View XFA-based PDF files using IE Mode for allowed file hash. (User)","description":"XFA is a legacy technology that is deprecated by its original creators. It is not an ISO standard and as such, doesn't align with the modern web architecture. Continued use poses potential risks and vulnerabilities. For more information, see - 'ViewXFAPDFInIEModeAllowedOrigins' (View XFA-based PDF files using IE Mode for allowed file origin.).\r\n\r\nIf you enable this policy, you can configure the list of base64 encoded SHA256 file hashes for which XFA PDF files will automatically open in Microsoft Edge using IE Mode.\r\n\r\nIf you disable or don't configure this policy, XFA PDFs won't be considered for opening via IE mode except the files from file origin mentioned in Policy 'ViewXFAPDFInIEModeAllowedOrigins'\r\n\r\nFor more information, see - [Get-FileHash](https://go.microsoft.com/fwlink/?linkid=2294823), [Dot Net Convert API](https://go.microsoft.com/fwlink/?linkid=2294913).\r\n\r\nExample value:\r\n\r\npZGm1Av0IEBKARczz7exkNYsZb8LzaMrV7J32a2fFG4=\r\nnFeL0Q+9HX7WFI3RsmSDFTlUtrbclXH67MTdXDwWuu4=","helpText":"","infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedfilehash_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedfilehash_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedfilehash_viewxfapdfiniemodeallowedfilehashdesc","displayName":"View XFA-based PDF files using IE Mode for allowed file hash. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins","displayName":"View XFA-based PDF files using IE Mode for allowed file origin. (User)","description":"Internet Explorer (IE) mode uses the Adobe Acrobat Active-X PDF Plugin to open XFA-based PDF files. This policy will only work if the Active-X plugin is already on the user's device, it's not installed as part of this policy.\r\n\r\nIt's important to note that XFA is a legacy technology that is deprecated by its original creators. It is not an ISO standard and as such, doesn't align with the modern web architecture. Continued use poses potential risks and vulnerabilities.\r\n\r\nGiven the deprecated status of XFA technology and the lack of any investment by its creators, we strongly recommend that you start planning your transition to a more advanced HTML\\PDF form-based solutions.\r\n\r\nIn the interim, this policy provides a workaround for users to view XFA PDF in Microsoft Edge.\r\n\r\nIf you enable this policy, you can configure the list of origins from which XFA PDF files will be automatically opened in Microsoft Edge using IE Mode.\r\n\r\nIf you disable or don't configure the policy, XFA PDFs won't be considered for opening via Internet Explorer mode.\r\n\r\nFor detailed information on valid URL patterns, see - https://go.microsoft.com/fwlink/?linkid=2095322\r\n\r\nAlternatively, 'ViewXFAPDFInIEModeAllowedFileHash' (View XFA-based PDF files using IE Mode for allowed file hash.) can also be used to configure list of file hashes instead of URL origins, which will enable those files to be automatically opened in Microsoft Edge using IE Mode.\r\n\r\nExample value:\r\n\r\nhttps://contesso.sharepoint.com/accounts/\r\nhttps://contesso.sharepoint.com/transport/\r\nfile://account_forms/","helpText":"","infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins_viewxfapdfiniemodeallowedoriginsdesc","displayName":"View XFA-based PDF files using IE Mode for allowed file origin. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled","displayName":"Enable additional search box in browser (User)","description":"A search box is an additional text input field located next to the address bar in a web browser. It allows users to perform web searches directly from the browser interface.\r\n\r\nIf you enable or don't configure this policy, the search box will be visible and available for use.\r\nUsers can toggle the search box in Edge Settings page edge://settings/appearance#SearchBoxInToolbar.\r\n\r\nIf you disable this policy, search box will not be visible, and users will have to use the address bar or navigate to a search engine to perform web searches.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_allowwebauthnwithbrokentlscerts","displayName":"Allow Web Authentication requests on sites with broken TLS certificates. (User)","description":"If you enable this policy, Microsoft Edge will allow Web Authentication requests on websites that have TLS certificates with errors (i.e. websites considered not secure).\r\n\r\nIf you disable or don't configure this policy, the default behavior of blocking such requests will apply.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_allowwebauthnwithbrokentlscerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_allowwebauthnwithbrokentlscerts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar (User)","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\r\n\r\nIf you don't configure this policy, no app is forced to be shown in sidebar.\r\n\r\nIf the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used and no sidebar can be shown.\r\n\r\nFor detailed information about valid url, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nNote: URL patterns are not supported in this policy. You should provide the exact URL of the app.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_edgesidebarappurlhostforcelistdesc","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist","displayName":"HTTP Allowlist (User)","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that will not be upgraded to HTTPS and will not show an error interstitial if HTTPS-First Mode is enabled. Organizations can use this policy to maintain access to servers that do not support HTTPS, without needing to disable 'AutomaticHttpsDefault' (Configure Automatic HTTPS).\r\n\r\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase.\r\n\r\nBlanket host wildcards (i.e., \"*\" or \"[*]\") are not allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies.\r\n\r\nNote: This policy does not apply to HSTS upgrades.\r\n\r\nExample value:\r\n\r\ntestserver.example.com\r\n[*.]example.org","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist_httpallowlistdesc","displayName":"HTTP Allowlist (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_pdfvieweroutofprocessiframeenabled","displayName":"Use out-of-process iframe PDF Viewer (User)","description":"Determines whether the PDF viewer in Microsoft Edge uses an out-of-process iframe (OOPIF).\r\nThis will be the new PDF viewer architecture going forward, as it is simpler in design and makes adding new features easier. The current GuestView PDF viewer, which relies on an outdated and overly complex architecture, is being deprecated.\r\n\r\nWhen this policy is set to Enabled or not set, Microsoft Edge will use the OOPIF PDF viewer architecture. Once Enabled or not set, the default behavior will be decided by Microsoft Edge.\r\n\r\nWhen this policy is set to Disabled, Microsoft Edge will strictly use the existing GuestView PDF viewer. This approach embeds a web page with its own separate frame tree into another web page.\r\n\r\nThis policy will be removed in the future, after the OOPIF PDF viewer feature has fully rolled out.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_pdfvieweroutofprocessiframeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_pdfvieweroutofprocessiframeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates. (User)","description":"Setting the policy to All (0) or leaving it unset lets users edit trust settings for all CA certificates, remove user-imported certificates, and import certificates using Certificate Manager. Setting the policy to UserOnly (1) lets users manage only user-imported certificates, but not change trust settings of built-in certificates. Setting it to None (2) lets users view (not manage) CA certificates.\r\n\r\nPolicy options mapping:\r\n\r\n* All (0) = Allow users to manage all certificates\r\n\r\n* UserOnly (1) = Allow users to manage user certificates\r\n\r\n* None (2) = Disallow users from managing certificates\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed_0","displayName":"Allow users to manage all certificates","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed_1","displayName":"Allow users to manage user certificates","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed_2","displayName":"Disallow users from managing certificates","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates","displayName":"TLS server certificates that should be trusted by Microsoft Edge (User)","description":"This policy enables a list of TLS certificates that should be trusted by Microsoft Edge for server authentication.\r\nCertificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_cacertificatesdesc","displayName":"TLS server certificates that should be trusted by Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Microsoft Edge for server authentication with constraints (User)","description":"This policy enables a list of TLS certificates that should be trusted by Microsoft Edge for server authentication, with constraints added outside the certificate. If no constraint of a certain type is present, then any name of that type is allowed.\r\nCertificates should be base64-encoded. At least one constraint must be specified for each certificate.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"certificate\": \"MIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X\",\r\n \"constraints\": {\r\n \"permitted_dns_names\": [\r\n \"example.org\"\r\n ],\r\n \"permitted_cidrs\": [\r\n \"10.1.1.0/24\"\r\n ]\r\n }\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificateswithconstraints_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificateswithconstraints_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificateswithconstraints_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Microsoft Edge for server authentication with constraints (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cadistrustedcertificates","displayName":"TLS certificates that should be distrusted by Microsoft Edge for server authentication (User)","description":"This policy enables defining a list of certificate public keys that should be distrusted by Microsoft Edge for TLS server\r\nauthentication.\r\n\r\nThe policy value is a list of base64-encoded X.509 certificates. Any\r\ncertificate with a matching SPKI (SubjectPublicKeyInfo) will be distrusted.\r\n\r\nExample value:\r\n\r\nMIIB/TCCAaOgAwIBAgIUQthnWVsd1jWpUCNBf/uILjXC+t4wCgYIKoZIzj0EAwIwVDELMAkGA1UEBhMCVVMxETAPBgNVBAgMCFZpcmdpbmlhMQ8wDQYDVQQHDAZSZXN0b24xITAfBgNVBAoMGEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDAeFw0yMzEyMDcxNjE5NTVaFw0yMzEyMjExNjE5NTVaMFQxCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhWaXJnaW5pYTEPMA0GA1UEBwwGUmVzdG9uMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQ9Akav/KB0aVA9FM1QK4J1CEHn5rFOyY/nxcr5HG3+Fom0Kwu5zTR/kz9eOYgtG/1NmCzbiEKaULDfzA8V9aJ7o1MwUTAdBgNVHQ4EFgQUq37bLKiuw8Y/G+rurMf46hw7EekwHwYDVR0jBBgwFoAUq37bLKiuw8Y/G+rurMf46hw7EekwDwYDVR0TAQH/BAUwAwEB/zAKBggqhkjOPQQDAgNIADBFAiEA/JhtLSgtVOcXkgFJ9V5Vb6lhGdiKQFfzO9wTxPeCxCECIFePYPucys2n/r9MOBMHiX/8068ssv+uceqokzUg0mAb","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cadistrustedcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cadistrustedcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cadistrustedcertificates_cadistrustedcertificatesdesc","displayName":"TLS certificates that should be distrusted by Microsoft Edge for server authentication (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication (User)","description":"This policy enables defining a list of certificates that are not trusted or distrusted in Microsoft Edge\r\nbut can be used as hints for path-building. Certificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIIFljCCA36gAwIBAgINAgO8U1lrNMcY9QFQZjANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjEwHhcNMjAwODEzMDAwMDQyWhcNMjcwOTMwMDAwMDQyWjBGMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzETMBEGA1UEAxMKR1RTIENBIDFDMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPWI3+dijB43+DdCkH9sh9D7ZYIl/ejLa6T/belaI+KZ9hzpkgOZE3wJCor6QtZeViSqejOEH9Hpabu5dOxXTGZok3c3VVP+ORBNtzS7XyV3NzsXlOo85Z3VvMO0Q+sup0fvsEQRY9i0QYXdQTBIkxu/t/bgRQIh4JZCF8/ZK2VWNAcmBA2o/X3KLu/qSHw3TT8An4Pf73WELnlXXPxXbhqW//yMmqaZviXZf5YsBvcRKgKAgOtjGDxQSYflispfGStZloEAoPtR28p3CwvJlk/vcEnHXG0g/Zm0tOLKLnf9LdwLtmsTDIwZKxeWmLnwi/agJ7u2441Rj72ux5uxiZ0CAwEAAaOCAYAwggF8MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQUinR/r4XN7pXNPZzQ4kYU83E1HScwHwYDVR0jBBgwFoAU5K8rJnEaK0gnhS9SZizv8IkTcT4waAYIKwYBBQUHAQEEXDBaMCYGCCsGAQUFBzABhhpodHRwOi8vb2NzcC5wa2kuZ29vZy9ndHNyMTAwBggrBgEFBQcwAoYkaHR0cDovL3BraS5nb29nL3JlcG8vY2VydHMvZ3RzcjEuZGVyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6Ly9jcmwucGtpLmdvb2cvZ3RzcjEvZ3RzcjEuY3JsMFcGA1UdIARQME4wOAYKKwYBBAHWeQIFAzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3BraS5nb29nL3JlcG9zaXRvcnkvMAgGBmeBDAECATAIBgZngQwBAgIwDQYJKoZIhvcNAQELBQADggIBAIl9rCBcDDy+mqhXlRu0rvqrpXJxtDaV/d9AEQNMwkYUuxQkq/BQcSLbrcRuf8/xam/IgxvYzolfh2yHuKkMo5uhYpSTld9brmYZCwKWnvy15xBpPnrLRklfRuFBsdeYTWU0AIAaP0+fbH9JAIFTQaSSIYKCGvGjRFsqUBITTcFTNvNCCK9U+o53UxtkOCcXCb1YyRt8OS1b887U7ZfbFAO/CVMkH8IMBHmYJvJh8VNS/UKMG2YrPxWhu//2m+OBmgEGcYk1KCTd4b3rGS3hSMs9WYNRtHTGnXzGsYZbr8w0xNPM1IERlQCh9BIiAfq0g3GvjLeMcySsN1PCAJA/Ef5c7TaUEDu9Ka7ixzpiO2xj2YC/WXGsYye5TBeg2vZzFb8q3o/zpWwygTMD0IZRcZk0upONXbVRWPeyk+gB9lm+cZv9TSjOz23HFtz30dZGm6fKa+l3D/2gthsjgx0QGtkJAITgRNOidSOzNIb2ILCkXhAd4FJGAJ2xDx8hcFH1mt0G/FX0Kw4zd8NLQsLxdxP8c4CU6x+7Nz/OAipmsHMdMqUybDKwjuDEI/9bfU1lcKwrmz3O2+BtjjKAvpafkmO8l7tdufThcV4q5O8DIrGKZTqPwJNl1IXNDw9bg1kWRxYtnCQ6yICmJhSFm/Y3m6xv+cXDBlHz4n/FsRC6UfTd","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cahintcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cahintcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cahintcertificates_cahintcertificatesdesc","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_caplatformintegrationenabled","displayName":"Use user-added TLS certificates from platform trust stores for server authentication (User)","description":"If enabled (or unset), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.\r\n\r\nIf disabled, user-added TLS certificates from platform trust stores will not be used in path-building for TLS server authentication.","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_caplatformintegrationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_caplatformintegrationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_seamlesswebtobrowsersigninenabled","displayName":"Seamless Web To Browser Sign-in Enabled (User)","description":"This policy only takes effect when the 'WebToBrowserSignInEnabled' (Web To Browser Sign-in Enabled) is enabled.\r\nIf you enable this policy and set this policy to True, users cannot turn off Seamless Web to Browser Sign-in feature from \"Automatic sign in on Microsoft Edge\" setting on Microsoft Edge profile settings page and that toggle will be greyed out.\r\nIf you enable this policy and set this policy to False, users cannot turn on Seamless Web to Browser Sign-in feature from \"Automatic sign in on Microsoft Edge\" setting on Microsoft Edge profile settings page and that toggle will be greyed out.\r\nIf you enable this policy but not configured or disabled, users can turn on/off Seamless Web to Browser Sign-in feature from settings by themselves.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_seamlesswebtobrowsersigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_seamlesswebtobrowsersigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_webtobrowsersigninenabled","displayName":"Web To Browser Sign-in Enabled (User)","description":"Allow user to sign in to the same account in Microsoft Edge when a user signs in to a Microsoft website.\r\nIf this policy is enabled or not configured, user are able to get sign in CTA or seamless sign in experience(if 'SeamlessWebToBrowserSignInEnabled' (Seamless Web To Browser Sign-in Enabled) is enabled) when user sign in on Microsoft website.\r\nIf this policy is disabled, user will not get sign in CTA or seamless sign in experience when user sign in on Microsoft website.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_webtobrowsersigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_webtobrowsersigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~network_dataurlwhitespacepreservationenabled","displayName":"DataURL Whitespace Preservation for all media types (User)","description":"This policy provides a temporary opt-out for changes to how Edge handles whitepsace in data URLS.\r\nPreviously, whitespace would be kept only if the top level media type was text or contained the media type string xml.\r\nNow, whitespace will be preserved in all data URLs, regardless of media type.\r\n\r\nIf this policy is left unset or is set to True, the new behavior is enabled.\r\n\r\nWhen this policy is set to False, the old behavior is enabled.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~network_dataurlwhitespacepreservationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~network_dataurlwhitespacepreservationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_addressbarworksearchresultsenabled","displayName":"Enable Work Search suggestions in the address bar (User)","description":"Enables the display of relevant workplace suggestions in the address bar’s suggestion dropdown when users type a query in the address bar.\r\n\r\nIf this policy is enabled or not configured, users can view internal work-related suggestions, such as bookmarks, files, and people results powered by Microsoft 365, in the Microsoft Edge address bar suggestion dropdown. To access these results, users must be signed into Microsoft Edge with their Entra ID account associated with that organization.\r\n\r\nIf this policy is disabled, users will not see internal workplace results in the Microsoft Edge address bar suggestion dropdown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_addressbarworksearchresultsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_addressbarworksearchresultsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerprotectionenabled_recommended","displayName":"Configure Edge Scareware Blocker Protection (User)","description":"This policy setting allows administrators to control whether Microsoft Edge enables the Scareware Blocker, an AI-powered feature that provides warning messages to help protect users from potential tech scams.\r\n\r\nIf this policy is enabled, Edge Scareware Blocker will warn users of potential tech scams.\r\n\r\nIf this policy is disabled, Edge Scareware Blocker will not warn users of potential tech scams.\r\n\r\nIf this policy is not configured, Edge Scareware Blocker will not warn users of potential tech scams, but users can choose warnings in settings.\r\n\r\nBy configuring this policy, administrators determine whether users receive proactive scam warnings or must manually enable them.","helpText":"","infoUrls":[],"categoryId":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerprotectionenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerprotectionenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_serviceworkertocontrolsrcdociframeenabled","displayName":"Allow ServiceWorker to control srcdoc iframes (User)","description":"https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with the \"allow-same-origin\" sandbox attribute to be under ServiceWorker control.\r\n\r\nBy default (if left unset) or when set to Enabled, Microsoft Edge makes srcdoc iframes with \"allow-same-origin\" sandbox attributes to be under ServiceWorker control.\r\n\r\nSetting the policy to Disabled prevents ServiceWorker control over srcdoc iframes.\r\n\r\nThis policy is temporary and planned for deprecation in 2026.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_serviceworkertocontrolsrcdociframeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_serviceworkertocontrolsrcdociframeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_sharedworkerbloburlfixenabled","displayName":"Make SharedWorker blob URL behavior aligned with the specification (User)","description":"According to Service Worker specification\r\nhttps://w3c.github.io/ServiceWorker/#control-and-use-worker-client, workers\r\nshould inherit controllers for blob URLs. Currently, only DedicatedWorkers\r\ninherit the controller, while SharedWorkers do not.\r\n\r\nEnabled/Unset: Microsoft Edge inherits\r\nthe controller for SharedWorker blob URLs, aligning with the specification.\r\n\r\nDisabled: Behavior remains unchanged, not aligning with the specification.\r\n\r\nThis policy is temporary and will be removed in a future update.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_sharedworkerbloburlfixenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_sharedworkerbloburlfixenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_webaudiooutputbufferingenabled","displayName":"Enable adaptive buffering for Web Audio (User)","description":"This policy determines whether the browser enables adaptive buffering\r\nfor Web Audio. Adaptive buffering can reduce audio glitches but may\r\nincrease latency to varying degrees.\r\n\r\nEnabled: The browser will always use adaptive buffering.\r\nDisabled or Not Set: The browser will automatically decide during the\r\n feature launch process whether to use adaptive buffering.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_webaudiooutputbufferingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_webaudiooutputbufferingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout","displayName":"Delay before running idle actions (User)","description":"Triggers an action when the computer is idle.\r\n\r\nIf you set this policy, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy.\r\n\r\nIf you not set this policy, no action will be ran.\r\n\r\nThe minimum threshold is 1 minute.\r\n\r\n\"User input\" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_idletimeout","displayName":"Delay before running idle actions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeoutactions","displayName":"Actions to run when the computer is idle (User)","description":"List of actions to run when the timeout from the IdleTimeout policy is reached.\r\n\r\nIf the IdleTimeout policy is unset, this policy has no effect.\r\n\r\nWhen the timeout from the IdleTimeout policy is reached, the browser runs the actions configured in this policy.\r\n\r\nIf you do not set this policy or no actions are selected, the IdleTimeout policy has no effect.\r\n\r\nSupported actions are:\r\n\r\n'close_browsers': close all browser windows and PWAs for this profile.\r\n\r\n'reload_pages': reload all webpages. For some pages, the user may be prompted for confirmation first.\r\n\r\n'clear_browsing_history', 'clear_download_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', 'clear_autofill', 'clear_site_settings': clear the corresponding browsing data.\r\n\r\nSetting 'clear_browsing_history', 'clear_password_signing', 'clear_autofill', and 'clear_site_settings' will disable sync for the respective data types if neither `Chrome Sync` is disabled by setting the SyncDisabled policy nor BrowserSignin is disabled.\r\n\r\nPolicy options mapping:\r\n\r\n* close_browsers (close_browsers) = Close Browsers\r\n\r\n* clear_browsing_history (clear_browsing_history) = Clear Browsing History\r\n\r\n* clear_download_history (clear_download_history) = Clear Download History\r\n\r\n* clear_cookies_and_other_site_data (clear_cookies_and_other_site_data) = Clear Cookies and Other Site Data\r\n\r\n* clear_cached_images_and_files (clear_cached_images_and_files) = Clear Cached Images and Files\r\n\r\n* clear_password_signin (clear_password_signin) = Clear Password Signin\r\n\r\n* clear_autofill (clear_autofill) = Clear Autofill\r\n\r\n* clear_site_settings (clear_site_settings) = Clear Site Settings\r\n\r\n* reload_pages (reload_pages) = Reload Pages\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\nclose_browsers","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeoutactions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeoutactions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeoutactions_idletimeoutactionsdesc","displayName":"Actions to run when the computer is idle (User)","description":"","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers (User)","description":"Allows you to set whether Microsoft Edge will run the v8 JavaScript engine with more advanced JavaScript optimizations enabled.\r\n\r\nDisabling JavaScript optimizations (by setting this policy's value to 2) will mean that Microsoft Edge may render web content more slowly.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'JavaScriptOptimizerAllowedForSites' (Allow JavaScript optimization on these sites) and 'JavaScriptOptimizerBlockedForSites' (Block JavaScript optimizations on these sites) policies.\r\n\r\nIf you don't configure this policy, JavaScript optimizations are enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowJavaScriptOptimizer (1) = Enable advanced JavaScript optimizations on all sites\r\n\r\n* BlockJavaScriptOptimizer (2) = Disable advanced JavaScript optimizations on all sites\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting_1","displayName":"Enable advanced JavaScript optimizations on all sites","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting_2","displayName":"Disable advanced JavaScript optimizations on all sites","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the 'JavaScriptOptimizerAllowedForSites' (Allow JavaScript optimization on these sites) policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations enabled, but fabrikam.com will use the policy from 'DefaultJavaScriptOptimizerSetting' (Control use of JavaScript optimizers), if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set, otherwise Javascript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites_javascriptoptimizerallowedforsitesdesc","displayName":"Allow JavaScript optimization on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are disabled.\r\n\r\nDisabling JavaScript optimizations will mean that Microsoft Edge may render web content more slowly.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the 'JavaScriptOptimizerBlockedForSites' (Block JavaScript optimizations on these sites) policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations disabled, but fabrikam.com will use the policy from 'DefaultJavaScriptOptimizerSetting' (Control use of JavaScript optimizers), if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set, otherwise JavaScript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_javascriptoptimizerblockedforsitesdesc","displayName":"Block JavaScript optimizations on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~printing_oopprintdriversallowed","displayName":"Out-of-process print drivers allowed (User)","description":"This policy determines whether Microsoft Edge handles interactions with printer drivers through a separate service process.\r\n\r\nUsing a service process for tasks like querying available printers, retrieving print driver settings, and submitting documents to local printers improves browser stability and prevents UI freezing during Print Preview.\r\n\r\nEnabled or Not Set: Microsoft Edge will use a separate service process for these printing tasks.\r\n\r\nDisabled: Microsoft Edge will perform these printing tasks within the browser process.\r\n\r\nNote: This policy will be deprecated in the future once the transition to out-of-process print drivers is fully implemented.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~printing_oopprintdriversallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~printing_oopprintdriversallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~scarewareblocker_scarewareblockerprotectionenabled","displayName":"Configure Edge Scareware Blocker Protection (User)","description":"This policy setting allows administrators to control whether Microsoft Edge enables the Scareware Blocker, an AI-powered feature that provides warning messages to help protect users from potential tech scams.\r\n\r\nIf this policy is enabled, Edge Scareware Blocker will warn users of potential tech scams.\r\n\r\nIf this policy is disabled, Edge Scareware Blocker will not warn users of potential tech scams.\r\n\r\nIf this policy is not configured, Edge Scareware Blocker will not warn users of potential tech scams, but users can choose warnings in settings.\r\n\r\nBy configuring this policy, administrators determine whether users receive proactive scam warnings or must manually enable them.","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~scarewareblocker_scarewareblockerprotectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~scarewareblocker_scarewareblockerprotectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_addressbartrendingsuggestenabled","displayName":"Enable Microsoft Bing trending suggestions in the address bar (User)","description":"This policy controls whether Microsoft Bing trending suggestions appear in the address bar’s suggestion dropdown when users click the address bar while on a New Tab Page.\r\n\r\nIf this policy is enabled or not configured, Microsoft Bing trending suggestions will appear in the address bar suggestion dropdown.\r\n\r\nIf this policy is disabled, Microsoft Edge will not display Microsoft Bing trending suggestions when users click the address bar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_addressbartrendingsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_addressbartrendingsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_webcontentfilteringblockedcategories","displayName":"Configure Web Content Filtering (User)","description":"You can configure this policy to block certain categories of URLs. Blocking a category prevents users in specified device groups from accessing URLs associated with the category.\r\n\r\nThe list of possible categories, their Category String, and their description are detailed at https://go.microsoft.com/fwlink/?linkid=2249965\r\n\r\nTo block a category, add the Category String of the category to the following List of blocked categories If you leave this policy unset or disable the policy, no URLs will be blocked.\r\n\r\nIf you want to block a specific URL without blocking an entire category, add the URL to the list of blocked URLs using the 'URLBlocklist' (Block access to a list of URLs) policy.\r\n\r\nIf you want a specific URL in a blocked category to be accessible, add the URL to the list of allowed URLs using the 'URLAllowlist' (Define a list of allowed URLs) policy.\r\n\r\nThis Web Content Filtering policy only works on Microsoft Edge on Windows 10 devices or above.\r\n\r\nPolicy options mapping:\r\n\r\n* chat (chat) = Chat\r\n\r\n* child_abuse_images (child_abuse_images) = Child Abuse Images\r\n\r\n* criminal_activity (criminal_activity) = Criminal Activity\r\n\r\n* download_sites (download_sites) = Download Sites\r\n\r\n* gambling (gambling) = Gambling\r\n\r\n* games (games) = Games\r\n\r\n* hacking (hacking) = Hacking\r\n\r\n* hate_and_intolerance (hate_and_intolerance) = Hate and Intolerance\r\n\r\n* illegal_drug (illegal_drug) = Illegal Drug\r\n\r\n* illegal_software (illegal_software) = Illegal Software\r\n\r\n* image_sharing (image_sharing) = Image Sharing\r\n\r\n* instant_messaging (instant_messaging) = Instant Messaging\r\n\r\n* nudity (nudity) = Nudity\r\n\r\n* peer_to_peer (peer_to_peer) = Peer to Peer\r\n\r\n* pornography_or_sexually_explicit (pornography_or_sexually_explicit) = Pornography or Sexually Explicit\r\n\r\n* professional_networking (professional_networking) = Professional Networking\r\n\r\n* self_harm (self_harm) = Self Harm\r\n\r\n* sex_education (sex_education) = Sex Education\r\n\r\n* social_networking (social_networking) = Social Networking\r\n\r\n* streaming_and_downloads (streaming_and_downloads) = Streaming Media and Downloads\r\n\r\n* tasteless (tasteless) = Tasteless\r\n\r\n* violence (violence) = Violence\r\n\r\n* weapons (weapons) = Weapons\r\n\r\n* web_based_email (web_based_email) = Web Based Email\r\n\r\n* none (none) = None\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\ngambling\r\nstreaming_and_downloads\r\ngames","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_webcontentfilteringblockedcategories_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_webcontentfilteringblockedcategories_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_webcontentfilteringblockedcategories_webcontentfilteringblockedcategoriesdesc","displayName":"List of blocked categories (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~contentsettings_partitionedbloburlusage","displayName":"Manage Blob URL Partitioning During Fetching and Navigation (User)","description":"This policy controls whether Blob URLs are partitioned during fetching and navigation.\r\nIf this policy is set to Enabled or not set, Blob URLs will be partitioned.\r\nIf this policy is set to Disabled, Blob URLs won't be partitioned. This is the Blob URL behavior prior to\r\nMicrosoft Edge version 135.\r\n\r\nIf storage partitioning is disabled for a given top-level origin by either\r\nThirdPartyStoragePartitioningBlockedForOrigins\r\nor DefaultThirdPartyStoragePartitioningSetting,\r\nthen Blob URLs will also not be partitioned.\r\n\r\nThe policy is scheduled to be available through Microsoft Edge version 140. After this\r\nversion, the policy will be removed, and Microsoft Edge will no longer support unpartitioned\r\nblob storage.\r\n\r\nFor detailed information on third-party storage partitioning, please see https://github.com/privacycg/storage-partitioning.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~contentsettings_partitionedbloburlusage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~contentsettings_partitionedbloburlusage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor","displayName":"Set the company logo backplate color on the new tab page. (User)","description":"By default, the new tab page sets the company logo backplate color to the neutralStrokeActive (#cecece) constant.\r\n\r\nYou can configure this policy with a color hex code to change the company logo backplate color on the new tab page.\r\n\r\nIf this policy is not configured, the default neutralStrokeActive (#cecece) color will be used as the backplate color.\r\n\r\nExample value: #cecece","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor_newtabpagecompanylogobackplatecolor","displayName":"Set the company logo backplate color on the new tab page. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~webrtc_webrtciphandlingurl","displayName":"WebRTC IP Handling Policy for URL Patterns (User)","description":"Controls which IP addresses and network interfaces WebRTC can use\r\nwhen establishing connections for specific URL patterns.\r\n\r\nHow It Works:\r\nAccepts a list of URL patterns, each paired with a handling type.\r\nWebRTC evaluates patterns sequentially; the first match determines the handling type.\r\nIf no match is found, WebRTC defaults to the WebRtcLocalhostIpHandling WebRtcLocalhostIpHandling. policy.\r\nThis policy applies only to origins—URL path components are ignored.\r\nWildcards (*) are supported in URL patterns.\r\n\r\nSupported Handling Values:\r\ndefault – Uses all available network interfaces.\r\ndefault_public_and_private_interfaces – WebRTC uses all public and private interfaces.\r\ndefault_public_interface_only – WebRTC uses only public interfaces.\r\ndisable_non_proxied_udp – WebRTC uses UDP SOCKS proxying or falls back to TCP proxying.\r\n\r\nMore Information:\r\nValid input patterns: https://go.microsoft.com/fwlink/?linkid=2095322\r\nHandling types: https://tools.ietf.org/html/rfc8828.html#section-5.2\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.example.com\",\r\n \"handling\": \"default_public_and_private_interfaces\"\r\n },\r\n {\r\n \"url\": \"https://[*.]example.edu\",\r\n \"handling\": \"default_public_interface_only\"\r\n },\r\n {\r\n \"url\": \"*\",\r\n \"handling\": \"disable_non_proxied_udp\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~webrtc_webrtciphandlingurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~webrtc_webrtciphandlingurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~webrtc_webrtciphandlingurl_webrtciphandlingurl","displayName":"WebRTC IP Handling Policy for URL Patterns (User)","description":"","helpText":"","infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge_httpsupgradesenabled","displayName":"Enable automatic HTTPS upgrades (User)","description":"As of Microsoft Edge version 120, Microsoft Edge tries to upgrade HTTP navigations to HTTPS whenever possible to improve security. Navigations to captive portals, IP addresses, and non-unique hostnames are excluded from automatic upgrades.\r\n\r\nIf this policy is enabled or not configured, automatic HTTPS upgrades are turned on by default.\r\n\r\nIf this policy is disabled, Microsoft Edge won't attempt to upgrade HTTP connections to HTTPS.\r\n\r\nTo exempt specific hostnames or hostname patterns from being upgraded, use the HttpAllowlist policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge_httpsupgradesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge_httpsupgradesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~passwordmanager_passwordexportenabled","displayName":"Enable exporting saved passwords from Password Manager (User)","description":"This policy controls whether the Export Password button in edge://wallet/passwords is enabled.\r\n\r\nIf enabled or not configured, users can export saved passwords.\r\nIf disabled, the Export Password button is unavailable, preventing password exports.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~passwordmanager_passwordexportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~passwordmanager_passwordexportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~profile_profiletypeinprofilebuttonenabled","displayName":"Controls the display of the profile button label for the work or school profile (User)","description":"Controls whether the label for the work or school profile type is shown in the profile button.\r\n\r\nThis policy does not apply when the OrganizationalBrandingOnWorkProfileUIEnabled policy is enabled.\r\n\r\nIf you enable this policy, the label for the work or school profile type appears in the profile button.\r\n\r\nIf you disable this policy or leave it not configured, the label is not shown.","helpText":"","infoUrls":[],"categoryId":"1043e7ed-8651-44b2-b918-7230c0b75a6c","categoryName":"Profile settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~profile_profiletypeinprofilebuttonenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~profile_profiletypeinprofilebuttonenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onbulkdataentryenterpriseconnector","displayName":"Configuration policy for bulk data entry for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when data is entered in Microsoft Edge from the clipboard or by drag and dropping web content.\r\n\r\nConnector Fields\r\n\r\n1. url_list,\r\ntags,\r\nenable,\r\ndisable\r\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\r\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\r\nAnalysis is triggered if at least one tag is included in the request.\r\n\r\n2. service_provider\r\nIdentifies the analysis service provider the configuration applies to.\r\n\r\n3. block_until_verdict\r\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\r\nAny other integer value allows the page to access the data immediately.\r\n\r\n4. default_action\r\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\r\nAny other value permits the page to access the data.\r\n\r\n5. minimum_data_size\r\nSpecifies the minimum size (in bytes) that the entered data must meet or exceed to be scanned.\r\nDefault: 100 bytes if the field is not set.\r\n\r\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"block_until_verdict\": 0,\r\n \"default_action\": \"allow\",\r\n \"disable\": [\r\n {\r\n \"tags\": [\r\n \"malware\"\r\n ],\r\n \"url_list\": [\r\n \"*.us.com\"\r\n ]\r\n }\r\n ],\r\n \"enable\": [\r\n {\r\n \"tags\": [\r\n \"malware\"\r\n ],\r\n \"url_list\": [\r\n \"*\"\r\n ]\r\n },\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.them.com\",\r\n \"*.others.com\"\r\n ]\r\n }\r\n ],\r\n \"minimum_data_size\": 100,\r\n \"service_provider\": \"local_system_agent\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onbulkdataentryenterpriseconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onbulkdataentryenterpriseconnector_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onbulkdataentryenterpriseconnector_onbulkdataentryenterpriseconnector","displayName":"Configuration policy for bulk data entry for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector","displayName":"Configuration policy for files attached for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when a file is attached to Microsoft Edge.\r\n\r\nConnector Fields\r\n\r\n1. url_list,\r\ntags,\r\nenable,\r\ndisable\r\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\r\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\r\nAnalysis is triggered if at least one tag is included in the request.\r\n\r\n2. service_provider\r\nIdentifies the analysis service provider the configuration applies to.\r\n\r\n3. block_until_verdict\r\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\r\nAny other integer value allows the page to access the data immediately.\r\n\r\n4. default_action\r\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\r\nAny other value permits the page to access the data.\r\n\r\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"block_until_verdict\": 0,\r\n \"default_action\": \"allow\",\r\n \"disable\": [\r\n {\r\n \"tags\": [\r\n \"malware\"\r\n ],\r\n \"url_list\": [\r\n \"*.us.com\"\r\n ]\r\n }\r\n ],\r\n \"enable\": [\r\n {\r\n \"tags\": [\r\n \"malware\"\r\n ],\r\n \"url_list\": [\r\n \"*\"\r\n ]\r\n },\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.them.com\",\r\n \"*.others.com\"\r\n ]\r\n }\r\n ],\r\n \"service_provider\": \"local_system_agent\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector_onfileattachedenterpriseconnector","displayName":"Configuration policy for files attached for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector","displayName":"Configuration policy for print for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when a page or file is printed from Microsoft Edge.\r\n\r\nConnector Fields\r\n\r\n1. url_list,\r\ntags,\r\nenable,\r\ndisable\r\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\r\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\r\nAnalysis is triggered if at least one tag is included in the request.\r\n\r\n2. service_provider\r\nIdentifies the analysis service provider the configuration applies to.\r\n\r\n3. block_until_verdict\r\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\r\nAny other integer value allows the page to access the data immediately.\r\n\r\n4. default_action\r\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\r\nAny other value permits the page to access the data.\r\n\r\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"block_until_verdict\": 0,\r\n \"default_action\": \"allow\",\r\n \"disable\": [\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.us.com\"\r\n ]\r\n }\r\n ],\r\n \"enable\": [\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.them.com\",\r\n \"*.others.com\"\r\n ]\r\n }\r\n ],\r\n \"service_provider\": \"local_system_agent\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector_onprintenterpriseconnector","displayName":"Configuration policy for print for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_webauthenticationremotedesktopallowedorigins","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications. (User)","description":"This policy defines a list of allowed HTTPS origins for remote desktop client applications that initiate WebAuthn API requests from a browsing session on a remote host.\r\n\r\nOrigins specified in this policy can request WebAuthn authentication for Relying Party IDs (RP IDs) they would not typically be authorized to claim.\r\n\r\nOnly HTTPS origins are supported. Wildcards are not permitted. Entries that do not\r\nmeet these requirements will be ignored.\r\n\r\nFor more information about the WebAuthn Remote Desktop Support feature, please see https://github.com/w3c/webauthn/wiki/Explainer:-Remote-Desktop-Support/a4e158c569f456c759d0ddd294a9015bd4d4eb9a.\r\n\r\nExample value:\r\n\r\nhttps://server:8080/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_webauthenticationremotedesktopallowedorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_webauthenticationremotedesktopallowedorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_webauthenticationremotedesktopallowedorigins_webauthenticationremotedesktopallowedoriginsdesc","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge~network_happyeyeballsv3enabled","displayName":"Use the Happy Eyeballs V3 algorithm for connection attempts (User)","description":"Controls whether Microsoft Edge uses the Happy Eyeballs V3 algorithm to optimize connection attempts. This algorithm improves reliability and performance in dual-stack (IPv4/IPv6) networks by racing connection attempts across IP versions and HTTP protocols (e.g., HTTP/3 vs. others). For more details, see https://datatracker.ietf.org/doc/draft-pauly-happy-happyeyeballs-v3.\r\n\r\nEnabled or not configured: Uses the algorithm for connection attempts.\r\n\r\nDisabled: Disables the algorithm.\r\n\r\nNote: This policy supports dynamic refresh.\r\n\r\nImportant: This policy is temporary and will be removed in a future version.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge~network_happyeyeballsv3enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge~network_happyeyeballsv3enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_builtinaiapisenabled","displayName":"Allow pages to use the built-in AI APIs. (User)","description":"Use this policy to control whether websites can access the built-in AI APIs, including the LanguageModel API, Summarization API, Writer API, and Rewriter API.\r\n\r\nEnable this policy to allow pages to use the APIs. If you don’t configure this policy, the APIs are still allowed.\r\n\r\nDisable this policy to block access to the APIs. The APIs will return an error when used.\r\n\r\nFor more information, see https://github.com/webmachinelearning/writing-assistance-apis/blob/main/README.md.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_builtinaiapisenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_builtinaiapisenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_edgehistoryaisearchenabled","displayName":"Control access to AI-enhanced search in History (User)","description":"This policy controls whether users can use AI-enhanced search in their browsing history in Microsoft Edge.\r\n\r\nWhen enabled or not configured, users can search using synonyms, natural language phrases, and minor spelling errors to find previously visited pages.\r\n\r\nWhen disabled, users can only perform exact match (verbatim) searches in their history.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_edgehistoryaisearchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_edgehistoryaisearchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_prefetchwithserviceworkerenabled","displayName":"Allow SpeculationRules prefetch for ServiceWorker-controlled URLs (User)","description":"Controls whether SpeculationRules prefetch requests are allowed for\r\nServiceWorker-controlled URLs.\r\n\r\nStarting with Microsoft Edge version 138,\r\nprefetch requests to ServiceWorker-controlled URLs are allowed by default when\r\nthe PrefetchServiceWorker feature is enabled.\r\n\r\nIf this policy is enabled or not configured, that default behavior is used.\r\n\r\nTo restore the legacy behavior from versions prior to 138, where prefetch requests\r\nto ServiceWorker-controlled URLs were blocked, set this policy to disabled.\r\n\r\nThis policy is intended to be temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_prefetchwithserviceworkerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_prefetchwithserviceworkerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_recommended~identity_recommended_edgeopenexternallinkswithprimaryworkprofileenabled_recommended","displayName":"Use Primary Work Profile as default to open external links (User)","description":"This policy controls whether Microsoft Edge uses the Primary Work Profile as the default profile when opening external links.\r\n1. On Windows, the Primary Work Profile refers to the profile signed in with the Entra ID account used to enroll the device.\r\n2. On macOS and Linux, the Primary Work Profile is the only profile signed in with an Entra ID account. If multiple profiles are signed in with Entra ID accounts, the Primary Work Profile setting does not apply.\r\n\r\nPolicy behavior:\r\n1. If enabled or not configured, Microsoft Edge will use the Primary Work Profile as the default for opening external links.\r\n2. If disabled, the last used profile becomes the default for opening external links.\r\n\r\nNote: This policy does not override the following scenarios:\r\n1. If the EdgeDefaultProfileEnabled policy is set, it takes precedence over this policy.\r\n2. External links opened from Outlook or Microsoft Teams may be configured to launch in a specific profile, which can override the Primary Work Profile setting.\r\n3. If the user sets a preference for \"Default profile for external links\" in Profile preferences, that setting will take effect.","helpText":"","infoUrls":[],"categoryId":"04b46099-4ee5-4def-8e04-569c988057a9","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_recommended~identity_recommended_edgeopenexternallinkswithprimaryworkprofileenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_recommended~identity_recommended_edgeopenexternallinkswithprimaryworkprofileenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_tls13earlydataenabled","displayName":"Control whether TLS 1.3 Early Data is enabled in Microsoft Edge (User)","description":"This policy controls whether TLS 1.3 Early Data is enabled in Microsoft Edge.\r\n\r\nTLS 1.3 Early Data is an extension that allows an HTTP request to be sent in parallel with the TLS handshake. When enabled and supported by the server, this can improve page load performance.\r\n\r\nEnabled – Microsoft Edge enables TLS 1.3 Early Data.\r\n\r\nDisabled – Microsoft Edge disables TLS 1.3 Early Data.\r\n\r\nNot configured – Microsoft Edge follows the default rollout process for TLS 1.3 Early Data.\r\n\r\nNOTE: When this feature is enabled, whether TLS 1.3 Early Data is used depends on server support. Most modern TLS servers and middleware can handle or reject Early Data without interrupting the connection. However, improperly implemented TLS stacks may cause connection failures. If such issues occur, contact the device or software vendor for a resolution.\r\n\r\nThis policy is temporary and intended to help test for compatibility issues. It may be removed in a future release once the feature is fully rolled out.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_tls13earlydataenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_tls13earlydataenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to block requests from public websites to devices on a user's local network. (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nLocal Network Access restrictions prevent public websites from making\r\nrequests to devices on a user's local network without explicit user permission.\r\n\r\nIf you enable this policy, Microsoft Edge will\r\nblock any request that would otherwise trigger a DevTools warning\r\ndue to Local Network Access checks.\r\nThese requests will be denied without prompting the user.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will handle\r\nthese requests using the default behavior, which may include showing warnings in DevTools\r\nand allowing the request to proceed depending on the context.\r\n\r\nNote: This feature improves local network security by deprecating direct access to private IP addresses from public websites\r\nunless explicitly granted by the user.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_enableunsafeswiftshader","displayName":"Allow software WebGL fallback using SwiftShader (User)","description":"Controls whether SwiftShader is used as a fallback for WebGL when hardware GPU acceleration is not available.\r\n\r\nWhen enabled, Microsoft Edge will use SwiftShader to support WebGL on systems without GPU acceleration, such as headless environments or virtual machines.\r\n\r\nStarting in Microsoft Edge version 139, SwiftShader has been deprecated due to security concerns. As a result, WebGL context creation will fail in scenarios where SwiftShader would have been used. Enabling this policy allows organizations to temporarily defer the deprecation and continue using SwiftShader.\r\n\r\nIf you disable or do not configure this policy, WebGL context creation may fail on systems without hardware acceleration. This could cause web content relying on WebGL to function incorrectly if it does not handle context creation failures.\r\n\r\nNote: This is a temporary policy and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_enableunsafeswiftshader_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_enableunsafeswiftshader_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_microsoft365copilotchaticonenabled","displayName":"Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar (User)","description":"For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon will be shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users.\r\n\r\nThis policy only applies when users are accessing Copilot in the sidepane.\r\n\r\nIf the policy is enabled: Copilot will appear in the toolbar.\r\n\r\nIf the policy is disabled: Copilot will not appear in the toolbar.\r\n\r\nIf the policy is not configured: Otherwise, Copilot will show in the toolbar and users may enable or disable Copilot from showing by using the Show Copilot toggle in settings.\r\n\r\nWhen both this policy and 'HubsSidebarEnabled' (Show Hubs Sidebar) are configured, this policy takes precedence in determining whether Copilot appears in the toolbar. If this policy is not configured and 'HubsSidebarEnabled' is disabled, Copilot will remain hidden. In a future release, this policy will be the sole control for managing Copilot's visibility in the toolbar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_microsoft365copilotchaticonenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_microsoft365copilotchaticonenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_onsecurityevententerpriseconnector","displayName":"Configuration policy for Microsoft Edge for Business Reporting Connectors (User)","description":"Defines the Microsoft Edge for Business Reporting Connectors service settings that apply when a security event occurs in Microsoft Edge. These events include negative verdicts from Data Loss Prevention Connectors, password reuse, navigation to unsafe pages, and other security-sensitive actions.\r\n\r\nThe service_provider field specifies the reporting service provider. The enabled_event_names field lists the security events enabled for that provider.\r\n\r\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2325446.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"enabled_event_names\": [\r\n \"passwordChangedEvent\",\r\n \"sensitiveDataEvent\"\r\n ],\r\n \"enabled_opt_in_events\": [\r\n {\r\n \"name\": \"loginEvent\",\r\n \"url_patterns\": [\r\n \"*\"\r\n ]\r\n },\r\n {\r\n \"name\": \"passwordBreachEvent\",\r\n \"url_patterns\": [\r\n \"example.com\",\r\n \"other.example.com\"\r\n ]\r\n }\r\n ],\r\n \"service_provider\": \"microsoft\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_onsecurityevententerpriseconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_onsecurityevententerpriseconnector_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_onsecurityevententerpriseconnector_onsecurityevententerpriseconnector","displayName":"Configuration policy for Microsoft Edge for Business Reporting Connectors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_recommended_microsoft365copilotchaticonenabled_recommended","displayName":"Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar (User)","description":"For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon will be shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users.\r\n\r\nThis policy only applies when users are accessing Copilot in the sidepane.\r\n\r\nIf the policy is enabled: Copilot will appear in the toolbar.\r\n\r\nIf the policy is disabled: Copilot will not appear in the toolbar.\r\n\r\nIf the policy is not configured: Otherwise, Copilot will show in the toolbar and users may enable or disable Copilot from showing by using the Show Copilot toggle in settings.\r\n\r\nWhen both this policy and 'HubsSidebarEnabled' (Show Hubs Sidebar) are configured, this policy takes precedence in determining whether Copilot appears in the toolbar. If this policy is not configured and 'HubsSidebarEnabled' is disabled, Copilot will remain hidden. In a future release, this policy will be the sole control for managing Copilot's visibility in the toolbar.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_recommended_microsoft365copilotchaticonenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_recommended_microsoft365copilotchaticonenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~extensions_mandatoryextensionsforinprivatenavigation","displayName":"Specify extensions users must allow in order to navigate using InPrivate mode (User)","description":"This policy lets you specify a list of extension IDs that must be explicitly allowed by the user to run in InPrivate mode in order to enable InPrivate browsing.\r\n\r\nIf users do not allow all listed extensions to run in InPrivate mode, they will be unable to navigate using InPrivate.\r\n\r\nIf any extension in the list is not installed, InPrivate navigation is blocked.\r\n\r\nThis policy only applies when InPrivate mode is enabled. If InPrivate mode is disabled using the InPrivateModeAvailability policy, this policy has no effect.\r\n\r\nExample value:\r\n\r\nabcdefghijklmnopabcdefghijklmnop","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~extensions_mandatoryextensionsforinprivatenavigation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~extensions_mandatoryextensionsforinprivatenavigation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~extensions_mandatoryextensionsforinprivatenavigation_mandatoryextensionsforinprivatenavigationdesc","displayName":"Specify extensions users must allow in order to navigate using InPrivate mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~identity_edgeopenexternallinkswithappspecifiedprofile","displayName":"Prioritize App specified profile to open external links (User)","description":"This policy controls whether the profile specified by an app (such as Microsoft Teams or Outlook) is given priority when opening external links, instead of the profile selected in the Default profile for external links setting.\r\n\r\nPolicy behavior:\r\n1. Enabled or not configured: The app-specified profile is prioritized for opening external links. This behavior overrides the profile selected in settings, and the behavior defined by the EdgeDefaultProfileEnabled and EdgeOpenExternalLinksWithPrimaryWorkProfileEnabled policies. If the app doesn't specify a profile, this policy has no effect.\r\n2. Disabled: The profile selected in settings—along with the EdgeDefaultProfileEnabled and EdgeOpenExternalLinksWithPrimaryWorkProfileEnabled policies—will be used to determine which profile opens external links.\r\n\r\nNOTE:\r\nThis policy doesn't override user-defined preferences set through Automatic profile switching, including the Custom site switch setting located within it. If a user has configured specific sites to open in designated profiles, those preferences take precedence.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~identity_edgeopenexternallinkswithappspecifiedprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~identity_edgeopenexternallinkswithappspecifiedprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_additionaldnsquerytypesenabled","displayName":"Allow DNS queries for more DNS record types (User)","description":"This policy controls whether Microsoft Edge can query more DNS record types when making insecure (non-Secure DNS) requests.\r\n\r\nIf this policy is unset or set to Enabled, more record types such as HTTPS (DNS type 65) may be queried in addition to A (DNS type 1) and AAAA (DNS type 28).\r\n\r\nIf this policy is set to Disabled, Microsoft Edge will only query A and AAAA record types for insecure DNS requests.\r\n\r\nThis setting doesn't affect DNS queries made via Secure DNS, which may always use more record types.\r\n\r\nNote: This is a temporary policy and is planned for removal in a future version of Microsoft Edge. After removal, Microsoft Edge will always be able to query more DNS types during insecure requests.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_additionaldnsquerytypesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_additionaldnsquerytypesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled (User)","description":"This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigations to HTTPS.\r\n\r\nIf this setting is not set or is set to allowed, users will be able to enable HTTPS-Only Mode.\r\nIf this setting is set to disallowed, users will not be able to enable HTTPS-Only Mode.\r\nIf this setting is set to force_enabled, HTTPS-Only Mode will be enabled in Strict mode and users will not be able to disable it.\r\nIf this setting is set to force_balanced_enabled, HTTPS-Only Mode will be enabled in Balanced mode and users will not be able to disable it.\r\n\r\nIf you set this policy to a value that is not supported by the version of Microsoft Edge that receives the policy, Microsoft Edge will default to the allowed setting.\r\n\r\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\r\n\r\nPolicy options mapping:\r\n\r\n* allowed (allowed) = Do not restrict users' HTTPS-Only Mode setting\r\n\r\n* disallowed (disallowed) = Do not allow users to enable any HTTPS-Only Mode\r\n\r\n* force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode\r\n\r\n* force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: disallowed","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_allowed","displayName":"Do not restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_disallowed","displayName":"Do not allow users to enable any HTTPS-Only Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_force_enabled","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_force_balanced_enabled","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_restrictcoresharingonrenderer","displayName":"Restrict CPU core sharing for renderer process (User)","description":"This policy helps mitigate side-channel cross-process memory attacks by isolating the renderer process to a dedicated CPU core, preventing other processes from being scheduled on the same core. This mitigation is supported on Microsoft® Windows® 11 24H2 and later. If the operating system does not support the necessary scheduling features, this policy has no effect. Enabling this policy may reduce performance in demanding workloads, similar to the impact of disabling hyperthreading. For more information refer https://learn.microsoft.com/windows/win32/api/winnt/ns-winnt-process_mitigation_side_channel_isolation_policy\r\nIf you enable this policy, other processes can not be scheduled on the same CPU core as a renderer process.\r\nIf you disable this policy, other processes can be scheduled on the same CPU core as a renderer process.\r\nIf you don't configure this policy, other processes may be scheduled on the same core as the renderer process. Behavior may vary depending on Microsoft Edge version and platform.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_restrictcoresharingonrenderer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_restrictcoresharingonrenderer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup (User)","description":"This policy controls whether Microsoft Edge enables the ServiceWorkerAutoPreload feature.\r\n\r\nWhen enabled or not configured, Microsoft Edge may initiate the main resource network request concurrently with the Service Worker bootstrap process. This can improve performance in scenarios where the Service Worker is not already running.\r\n\r\nIf you disable this policy, Microsoft Edge will wait to dispatch the navigation request until after the Service Worker has started.\r\n\r\nThis is a temporary policy and will be removed in version 144 of Microsoft Edge.\r\n\r\nFor more details on the feature, see https://github.com/WICG/service-worker-auto-preload.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_serviceworkerautopreloadenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_serviceworkerautopreloadenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls","displayName":"Allow sites to make requests to local network endpoints. (User)","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions.\r\n\r\nIf an origin is specified by both this policy and the 'LocalNetworkAccessBlockedForUrls' (Block sites from making requests to local network endpoints.) policy, the blocked list takes precedence.\r\n\r\nFor origins not covered by this policy, the user's personal settings and local network access restrictions will apply.\r\n\r\nFor guidance on valid URL pattern syntax, see:\r\nhttps://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns\r\n\r\nNote: This policy enables controlled exceptions to local network access restrictions. It allows specific public websites to access private IP addresses when necessary for trusted local communication scenarios. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls_localnetworkaccessallowedforurlsdesc","displayName":"Allow sites to make requests to local network endpoints. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls","displayName":"Block sites from making requests to local network endpoints. (User)","description":"List of URL patterns. Requests initiated from websites served by matching origins are blocked from issuing Local Network Access requests.\r\n\r\nIf an origin is covered by both this policy and by 'LocalNetworkAccessAllowedForUrls' (Allow sites to make requests to local network endpoints.), this policy takes precedence.\r\n\r\nDepending on the stage of the rollout of Local Network Access, LocalNetworkAccessRestrictionsEnabled may also need to be enabled for this policy to block Local Network Access requests.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\r\n\r\nNote: This policy improves local network security by blocking specified public websites from accessing private IP addresses. It helps prevent unauthorized external sites from reaching internal resources unless explicitly permitted. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls_localnetworkaccessblockedforurlsdesc","displayName":"Block sites from making requests to local network endpoints. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled","displayName":"Allows users to translate videos to different languages. (User)","description":"This policy configures the on-device real-time video translation feature in Microsoft Edge.\r\nWith this feature, users can watch videos translated into their selected language in real time.\r\n\r\nWhen a user selects the Translate icon and chooses a source (video language) and target language (translated language),\r\ntranslation components are downloaded on first use (approximately 200 MB per language pair).\r\n\r\nThese components may be updated periodically to improve performance and translation quality.\r\nTranslation is performed locally on the user’s device and no data is sent outside of the device.\r\nThe feature is available only for non-DRM videos, on supported high-end devices, with select language pairs, and in select regions.\r\nFor more details, see https://www.microsoft.com/en-us/edge/features/real-time-video-translation.\r\n\r\nIf you enable or don’t configure this policy, the on-device real-time video translation feature is enabled and\r\nusers will see the Translate button when hovering over videos.\r\n\r\nIf you disable this policy, the on-device real-time video translation feature is disabled and the Translate button won’t be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_originkeyedprocessesenabled_recommended","displayName":"Enable origin-keyed process isolation for improved security (User)","description":"This policy enables origin-keyed process isolation for most pages, which improves security by separating content from different origins into distinct processes. This may increase the number of processes created. Users can override this setting by using command-line flags or edge://flags to turn the feature on or off.\r\n\r\nIf you enable this policy, most origins will be isolated, even from other origins within the same site. For related configuration, see the IsolateOrigins and SitePerProcess policies.\r\n\r\nIf you disable this policy, origins will not be isolated from the rest of their site unless the origin explicitly requests isolation.\r\n\r\nIf you don’t configure this policy, the browser will decide which origins to isolate and when. By default, this feature is disabled. The default state may change in the future.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_originkeyedprocessesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_originkeyedprocessesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_showtabpreviewenabled_recommended","displayName":"Enable tab preview on hover (User)","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\r\n\r\nIf you disable this policy, tab previews will not be shown on hover.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_showtabpreviewenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_showtabpreviewenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_relaunchfastifoutdated","displayName":"Relaunch browser quickly when the current version is outdated (User)","description":"This policy specifies the minimum release age after which relaunch notifications become more aggressive. The release age is calculated from the time the currently running version was last served to clients.\r\n\r\nIf a browser relaunch is needed to finalize a pending update and the current version has been outdated for more than the number of days specified by this setting, the RelaunchNotificationPeriod policy is overridden to 2 hours. If the RelaunchNotification policy is set to 1 ('Required'), a browser relaunch will be forced at the end of the period.\r\n\r\nIf not set, or if the release age cannot be determined, the RelaunchNotificationPeriod policy will be used for all updates.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_relaunchfastifoutdated_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_relaunchfastifoutdated_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_relaunchfastifoutdated_relaunchfastifoutdated","displayName":"Time period (days): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_showtabpreviewenabled","displayName":"Enable tab preview on hover (User)","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\r\n\r\nIf you disable this policy, tab previews will not be shown on hover.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_showtabpreviewenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_showtabpreviewenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge~webrtc_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC (User)","description":"This policy controls the use of post-quantum key agreement for WebRTC in Microsoft Edge.\r\n\r\nIf you enable this policy, Microsoft Edge will offer post-quantum key agreement for WebRTC.\r\n\r\nIf you disable this policy, post-quantum key agreement will not be offered for WebRTC.\r\n\r\nIf you don't configure this policy, post-quantum key agreement will not be offered for WebRTC. A future version of Microsoft Edge may enable this feature by default.\r\n\r\nOffering a post-quantum key agreement is backwards compatible. Existing datagram transport layer security (DTLS) peers and networking middleware are expected to ignore the new option and continue using previous options.\r\n\r\nHowever, devices that don't correctly implement DTLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or larger message sizes. Such devices aren’t post-quantum-ready and may interfere with an organization's post-quantum transition. If this issue occurs, administrators should contact the device vendor for a fix.\r\n\r\nThis policy is temporary and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge~webrtc_webrtcpostquantumkeyagreement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge~webrtc_webrtcpostquantumkeyagreement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerblocksdetectedsitesenabled_recommended","displayName":"Configure Edge scareware blocker to block sites detected as potential tech scams (User)","description":"This policy controls whether Microsoft Edge blocks sites that are detected as potential tech scams.\r\n\r\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will block sites detected as potential tech scams.\r\n\r\nIf you disable this policy, Microsoft Edge will not block sites detected as potential tech scams.","helpText":"","infoUrls":[],"categoryId":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerblocksdetectedsitesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerblocksdetectedsitesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockersenddetectedsitestosmartscreenenabled_recommended","displayName":"Configure Edge scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen (User)","description":"This policy controls whether Microsoft Edge shares URLs of sites that are detected as potential tech scams with Microsoft Defender SmartScreen.\r\n\r\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\r\n\r\nIf you enable this policy, Microsoft Edge will share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.","helpText":"","infoUrls":[],"categoryId":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockersenddetectedsitestosmartscreenenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockersenddetectedsitestosmartscreenenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerallowlistdomains","displayName":"Configure the list of domains where Microsoft Edge scareware blocker won't run (User)","description":"This policy configures the list of trusted domains for Microsoft Edge scareware blocker. When a website's source URL matches any domain in this list, Edge scareware blocker won’t analyze that site.\r\n\r\nThis policy takes effect only if the ScarewareBlockerProtectionEnabled policy is enabled.\r\n\r\nIf you enable this policy, Microsoft Edge scareware blocker will trust the specified domains.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge scareware blocker will analyze all sites.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerallowlistdomains_scarewareblockerallowlistdomainsdesc","displayName":"Configure the list of domains where Microsoft Edge scareware blocker won't run (User)","description":"","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerblocksdetectedsitesenabled","displayName":"Configure Edge scareware blocker to block sites detected as potential tech scams (User)","description":"This policy controls whether Microsoft Edge blocks sites that are detected as potential tech scams.\r\n\r\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will block sites detected as potential tech scams.\r\n\r\nIf you disable this policy, Microsoft Edge will not block sites detected as potential tech scams.","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerblocksdetectedsitesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerblocksdetectedsitesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockersenddetectedsitestosmartscreenenabled","displayName":"Configure Edge scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen (User)","description":"This policy controls whether Microsoft Edge shares URLs of sites that are detected as potential tech scams with Microsoft Defender SmartScreen.\r\n\r\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\r\n\r\nIf you enable this policy, Microsoft Edge will share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockersenddetectedsitestosmartscreenenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockersenddetectedsitestosmartscreenenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge_sharebrowsinghistorywithcopilotsearchallowed","displayName":"Allow sharing tenant-approved browsing history with Microsoft 365 Copilot Search (User)","description":"This policy controls whether browsing history in Microsoft Edge is shared with Microsoft 365 Copilot Search to provide more relevant search results. Only tenant-approved, work-related sites are shared.\r\n\r\nThis feature is available only to users who are signed in to Microsoft Edge with an Entra ID account and have an eligible Microsoft 365 Copilot license.\r\n\r\nIf you enable or don't configure this policy, browsing history will be shared with Microsoft 365 Copilot Search by default, and users can turn off sharing using the toggle in Microsoft Edge settings.\r\n\r\nIf you disable this policy, browsing history won't be shared with Microsoft 365 Copilot Search.\r\n\r\nLearn more about how Copilot uses data and consent at https://go.microsoft.com/fwlink/?linkid=2333202","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge_sharebrowsinghistorywithcopilotsearchallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge_sharebrowsinghistorywithcopilotsearchallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge~network_localnetworkaccessrestrictionstemporaryoptout","displayName":"Specifies whether to opt out of Local Network Access restrictions (User)","description":"This policy allows for opting out of restrictions on requests to local network endpoints.\r\n\r\nIf you enable this policy, Local Network Access requests will only display warnings in Edge DevTools when Local Network Access checks fail.\r\n\r\nIf you disable or don't configure this policy, Local Network Access requests will follow the default handling behavior.\r\n\r\nFor more information about Local Network Access restrictions, see Local Network Access .\r\n\r\nThis enterprise policy is temporary and will be removed after Microsoft Edge version 146.\r\n\r\nTo allow specific URL patterns that should automatically be granted Local Network Access permission, use the LocalNetworkAccessAllowedForUrls policy.\r\n\r\nNote: If the LocalNetworkAccessRestrictionsEnabled policy is enabled, it takes precedence over this policy.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge~network_localnetworkaccessrestrictionstemporaryoptout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge~network_localnetworkaccessrestrictionstemporaryoptout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge~performance_ramresourcecontrolsenabled","displayName":"Enable RAM (memory) resource controls (User)","description":"This policy controls whether users can access the RAM (memory) resource control feature. This feature lets users set an individual limit on how much RAM (memory) the browser can use.\r\n\r\nTo set a specific memory limit, use the 'TotalMemoryLimitMb' (Set limit on megabytes of memory a single Microsoft Edge instance can use) policy.\r\n\r\nIf you enable or don't configure this policy, users can enable resource control and set the amount of RAM that Microsoft Edge can use. Browser performance may be affected by low limits.\r\n\r\nIf you disable this policy, users can't use resource control.","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge~performance_ramresourcecontrolsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge~performance_ramresourcecontrolsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled","displayName":"Enable Silent Printing (User)","description":"This policy controls whether Microsoft Edge uses silent printing.\r\n\r\nIf you enable this policy, Edge automatically closes the print preview window and prints to the default printer using its default settings. If the default printer is Save as PDF, the file is saved to the user's Downloads folder.\r\n\r\nIf you disable or don't configure this policy, silent printing is disabled. The print preview window stays open and the user must choose print settings as usual.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_whatsnewpageforentraprofilesenabled","displayName":"Control whether an informational webpage for Edge for Business is shown in the new tab after major browser updates (User)","description":"Starting in Microsoft Edge version 145, users with Microsoft Entra ID profiles will see an informational page about new Edge for Business features after major browser updates. This page highlights recent enhancements designed to promote secure and productive browsing.\r\n\r\nThis policy controls whether users with Microsoft Entra ID profiles see this informational page. This policy applies only to Microsoft Entra ID profiles and does not apply to Microsoft account (MSA) profiles.\r\n\r\nThis policy is available starting in Microsoft Edge version 144 to allow configuration ahead of the changes introduced in version 145.\r\n\r\nIf you enable this policy or do not configure it, Microsoft Edge shows the informational page by default.\r\nIf you disable this policy, Microsoft Edge does not show the informational page to users.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_whatsnewpageforentraprofilesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_whatsnewpageforentraprofilesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls","displayName":"Block geolocation on these sites (User)","description":"Use this policy to define a list of URL patterns for sites that are blocked from accessing the user's geolocation. These sites also can't prompt the user for location permissions.\r\n\r\nIf you enable this policy, the list you provide determines which sites are blocked from requesting or accessing geolocation.\r\n\r\nIf you disable or don't configure this policy, DefaultGeolocationSetting applies to all sites, if configured. If it's not configured, the user’s personal browser setting is used.\r\n\r\nFor detailed information on valid url patterns, see the documentation on pattern formats: https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls_geolocationblockedforurlsdesc","displayName":"Block geolocation on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_precisegeolocationallowedforurls","displayName":"Allow precise geolocation on these sites (User)","description":"This policy lets you specify a list of URL patterns for sites that are allowed to access the user's high-accuracy geolocation without prompting for permission.\r\n\r\nIf you leave this policy unset, DefaultGeolocationSetting applies to all sites (if configured). Otherwise, the user's personal setting is used.\r\n\r\nFor information about valid url patterns, see https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format. Wildcards (*) are supported.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_precisegeolocationallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_precisegeolocationallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_precisegeolocationallowedforurls_precisegeolocationallowedforurlsdesc","displayName":"Allow precise geolocation on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended","displayName":"Allow HTTPS-Only Mode to be enabled (User)","description":"This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigations to HTTPS.\r\n\r\nIf this setting isn't set or is set to `allowed`, users are able to enable HTTPS-Only Mode.\r\nIf this setting is set to `disallowed`, HTTPS-Only Mode will be disabled.\r\nIf this setting is set to `force_enabled`, HTTPS-Only Mode is enabled in Strict mode.\r\nIf this setting is set to `force_balanced_enabled`, HTTPS-Only Mode is enabled in Balanced mode.\r\n\r\nThe settings `force_enabled` and `force_balanced_enabled` can be recommended to users. HTTPS-Only Mode will be set to Strict or Balanced initially, but users are allowed to change it.\r\n\r\nIf you set this policy to a value that isn't supported by the version of Microsoft Edge that receives the policy, Microsoft Edge defaults to the `allowed` setting.\r\n\r\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\r\n\r\nPolicy options mapping:\r\n\r\n* allowed (allowed) = Don't restrict users' HTTPS-Only Mode setting\r\n\r\n* disallowed (disallowed) = Disable HTTPS-Only Mode\r\n\r\n* force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode\r\n\r\n* force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: disallowed","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_httpsonlymode_allowed","displayName":"Don't restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_httpsonlymode_disallowed","displayName":"Disable HTTPS-Only Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_httpsonlymode_force_enabled","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_httpsonlymode_force_balanced_enabled","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_staticstoragequotaenabled","displayName":"Control whether storage quota APIs will return static values (User)","description":"Controls how the Storage Quota APIs report the available quota to websites.\r\n\r\nWhen enabled, the Storage Quota APIs return a static quota value equal to the current usage plus the smaller of 10 GiB or the device's total storage rounded up to the nearest 1 GiB.\r\n\r\nWhen disabled, the Storage Quota APIs return a dynamic quota value that reflects the actual available device storage.\r\n\r\nWhen unset, the browser uses the default platform behavior.\r\n\r\nThis policy does not affect sites with unlimited storage permissions or enforced quota settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_staticstoragequotaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_staticstoragequotaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_webappinstallbyuserenabled","displayName":"Enable User Web App Install From Browser (User)","description":"This policy controls whether users can install web apps through Microsoft Edge.\r\nIf you enable or don’t configure this policy, users can install web apps through the browser.\r\nIf you disable this policy, users can’t install web apps through the browser, and the \"apps\" data type is excluded from synchronization.\r\nThis policy doesn't support dynamic refresh. Changes to this policy, whether enabled, disabled, or not configured, take effect only after the browser is restarted.\r\nThis policy doesn't affect the 'WebAppInstallForceList' policy. Web apps specified by that policy are installed regardless of this policy setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_webappinstallbyuserenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_webappinstallbyuserenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting","displayName":"Default idle detection setting (User)","description":"Setting this policy to 1 - AllowIdleDetection allows websites to use the Idle Detection API without requesting user permission.\r\n\r\nSetting this policy to 2 - BlockIdleDetection prevents websites from using the Idle Detection API.\r\n\r\nSetting this policy to 3 - AskIdleDetection requires websites to request user permission each time before using the Idle Detection API.\r\n\r\nIf you do not configure this policy, users can decide whether to allow the Idle Detection API and can change this setting themselves.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowIdleDetection (1) = Allow sites to detect idle state without asking the user\r\n\r\n* BlockIdleDetection (2) = Do not allow any site to detect the user's idle state\r\n\r\n* AskIdleDetection (3) = Ask every time a site wants to detect the user's idle state\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting","displayName":"Idle detection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting_1","displayName":"Allow sites to detect idle state without asking the user","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting_2","displayName":"Do not allow any site to detect the user's idle state","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting_3","displayName":"Ask every time a site wants to detect the user's idle state","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls","displayName":"Allow idle detection on these sites (User)","description":"Allows you to specify a list of URL patterns for sites that are allowed to use the Idle Detection API.\r\n\r\nIf you do not configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise.\r\n\r\nOnly the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported. For detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=209532.\r\n\r\nURL patterns specified in the blocklist take precedence over this allowlist. This allowlist takes precedence over the DefaultIdleDetectionSetting policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls_idledetectionallowedforurlsdesc","displayName":"Allowed sites for idle detection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls","displayName":"Block idle detection on these sites (User)","description":"Allows you to specify a list of URL patterns for sites that are not allowed to use the Idle Detection API.\r\n\r\nOnly the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported.\r\n\r\nFor detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nIf you do not configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls_idledetectionblockedforurlsdesc","displayName":"Blocked sites for idle detection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~extensions_edgesafehostingextensionenabled","displayName":"Control Microsoft Edge Safe Hosting Extension (User)","description":"This policy controls whether the Microsoft Edge Safe Hosting component extension is installed automatically when users visit supported Microsoft services, such as Microsoft 365 Copilot app.\r\n\r\nThe Microsoft Edge Safe Hosting extension provides additional security capabilities for these services. When a user accesses a supported service, the extension installs automatically to enable those protections.\r\n\r\nIf you enable or don't configure this policy, the extension installs automatically and remains installed for 90 days after the user's last visit, then is removed if no further activity occurs.\r\n\r\nIf you disable this policy, the extension won't install automatically. If it’s already installed, it will be removed.\r\n\r\nNote: This policy controls only automatic installation. It doesn’t prevent users from manually installing other extensions from the Microsoft Edge Add-ons website.","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~extensions_edgesafehostingextensionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~extensions_edgesafehostingextensionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled","displayName":"Enable editing profile in settings (User)","description":"This policy controls whether users can modify profile properties (such as profile avatar) from the profile settings page.\r\n\r\nIf you enable or don't configure this policy, users can edit profile properties. The edit button is available on the profile settings page.\r\n\r\nIf you disable this policy, users can't edit profile properties. The edit button is disabled on the profile settings page.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled","displayName":"Enable saving passkeys to the password manager (User)","description":"This policy controls whether users can save passkeys in the built-in password manager. It does not limit access to, or change the contents of, passkeys already saved in the password manager.\r\n\r\nIf the PasswordManagerEnabled policy is Disabled, saving to the built-in password manager is disabled in general, including passkeys. In this case, this policy has no effect.\r\n\r\nIf this policy is enabled or not configured, users can save passkeys in the built-in password manager when signed in to Microsoft Edge.\r\n\r\nIf this policy is disabled, users cannot save new passkeys to the built-in password manager. Previously saved passkeys continue to work.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge_standardizedbrowserzoomenabled","displayName":"Enable Standardized Browser Zoom Behavior (User)","description":"Configures whether the CSS \"zoom\" property follows the current CSS specification or legacy behavior.\r\n\r\nWhen this policy is enabled or not configured, the CSS \"zoom\" property follows the current specification defined by the CSS Working Group:\r\nhttps://drafts.csswg.org/css-viewport/#zoom-property\r\n\r\nWhen this policy is disabled, the CSS \"zoom\" property uses its legacy, pre-standardized behavior.\r\n\r\nThis policy is temporary and is intended to provide time for organizations to migrate web content to the updated behavior. In a future Microsoft Edge release, this policy will be removed and the standardized behavior will be enforced by default.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge_standardizedbrowserzoomenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge_standardizedbrowserzoomenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowciphers","displayName":"Prefer specific encryption cipher algorithms for TLS (User)","description":"This policy configures Microsoft Edge to order its preferred encryption ciphers in TLS 1.3 based on algorithms approved by a specific compliance regime.\r\n\r\nSetting this policy does not guarantee that any specific algorithms will be negotiated.\r\n\r\nThis policy allows server operators who support both compliant and non-compliant clients to differentiate between them, and use certain non-default algorithms with increased cryptographic strength only for clients explicitly configured to prefer them.\r\n\r\nSetting the policy to 'cnsa' configures Microsoft Edge to prefer ciphers required for compliance with the Commercial National Security Algorithm Suite versions 1.0 and 2.0 (CNSA 1.0 and 2.0).\r\n\r\nNot setting the policy, or setting it to 'default', configures Microsoft Edge to use its default ciphers.\r\n\r\nSetting this policy isn't required for security. The default cryptography used by Microsoft Edge is strong enough to withstand a brute-force attack using the entire power of the Sun.\r\n\r\nSetting this policy will cause Microsoft Edge to be slower when accessing websites.\r\n\r\nThis policy only affects TLS 1.3 and QUIC. It doesn't affect earlier versions of TLS.\r\n\r\nPolicy options mapping:\r\n\r\n* CNSA (cnsa) = Prefer ciphers satisfying the requirements of CNSA 1.0 and 2.0\r\n\r\n* Default (default) = Use Microsoft Edge's default cipher order\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: cnsa","helpText":"","infoUrls":[],"categoryId":"120b24dd-c04a-4291-8f24-9c48fcdc1434","categoryName":"Cryptography compliance policies","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowciphers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowciphers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowciphers_preferslowciphers","displayName":"Prefer specific encryption cipher algorithms for TLS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"120b24dd-c04a-4291-8f24-9c48fcdc1434","categoryName":"Cryptography compliance policies","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowciphers_preferslowciphers_cnsa","displayName":"Prefer ciphers satisfying the requirements of CNSA 1.0 and 2.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowciphers_preferslowciphers_default","displayName":"Use Microsoft Edge's default cipher order","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowkexalgorithms","displayName":"Prefer specific key exchange algorithms for TLS (User)","description":"This policy configures Microsoft Edge to prioritize certain key agreement algorithms (supported groups) in TLS 1.3 based on compliance requirements.\r\n\r\nIf you set this policy to 'cnsa2', Microsoft Edge prefers the algorithms required for the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0). If you leave this policy unset or set it to 'default', the browser uses its standard key exchange order.\r\n\r\nThis policy does not guarantee negotiation of a specific algorithm. It is designed to help server operators distinguish clients with compliance requirements and apply higher-strength, non-default algorithms only when appropriate.\r\n\r\nIf this policy would prefer a post-quantum key agreement algorithm but PostQuantumKeyAgreementEnabled is Disabled, the post-quantum setting takes precedence.\r\n\r\nThis policy applies only to TLS 1.3 and QUIC. The default cryptography used by Microsoft Edge already provides strong security, but enabling this policy may reduce performance when accessing websites.\r\n\r\nPolicy options mapping:\r\n\r\n* CNSA2.0 (cnsa2) = Prefer key exchange methods satisfying the requirements of CNSA 2.0\r\n\r\n* Default (default) = Use Microsoft Edge's default supported groups\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: cnsa2","helpText":"","infoUrls":[],"categoryId":"120b24dd-c04a-4291-8f24-9c48fcdc1434","categoryName":"Cryptography compliance policies","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowkexalgorithms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowkexalgorithms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowkexalgorithms_preferslowkexalgorithms","displayName":"Prefer specific key exchange algorithms for TLS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"120b24dd-c04a-4291-8f24-9c48fcdc1434","categoryName":"Cryptography compliance policies","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowkexalgorithms_preferslowkexalgorithms_cnsa2","displayName":"Prefer key exchange methods satisfying the requirements of CNSA 2.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowkexalgorithms_preferslowkexalgorithms_default","displayName":"Use Microsoft Edge's default supported groups","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides","displayName":"Override IP address space mappings (User)","description":"Specifies IP address space overrides for Local Network Access restrictions. This policy allows administrators to treat specific IP address ranges as public (exempt from Local Network Access restrictions) or as local (subject to Local Network Access restrictions).\r\n\r\nIP address space overrides can be specified using one of the following formats:\r\n\r\n• [cidr]=[public|local|loopback]\r\nwhere [cidr] is an IP address range in CIDR notation. CIDR overrides apply to all ports.\r\n\r\n• [ip-address]:[port]=[public|local|loopback]\r\n\r\nIPv6 addresses must be specified in URL-safe (bracketed) format.\r\n\r\nFor more information about Local Network Access, see https://wicg.github.io/local-network-access/.\r\n\r\nExample value:\r\n\r\n100.64.0.0/10=public\r\n[2001:db8::]/32=local\r\n192.168.0.1:8000=public\r\n[2001:DB8::8:800:200C:417A]:8080=local","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides_localnetworkaccessipaddressspaceoverridesdesc","displayName":"Override IP address space mappings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccesspermissionspolicydefaultenabled","displayName":"Allow Local Network Access (LNA) requests in subframes without explicit delegation (User)","description":"Controls whether Local Network Access (LNA) permissions are inherited by cross-origin subframes.\r\n\r\nBy default, Local Network Access permissions can be requested in cross-origin subframes only if they are explicitly delegated.\r\n\r\nIf you enable this policy, subframes inherit all LNA Permissions Policy features by default and can make local network requests, which trigger the permission prompt.\r\n\r\nIf you disable or don't configure this policy, subframes must be explicitly delegated the Permissions Policy feature to make local network requests and trigger the permission prompt.\r\n\r\nThis policy applies to the Permissions Policy features \"local-network-access\", \"loopback-network\", and \"local-network\".\r\n\r\nFor more information about Local Network Access, see https://learn.microsoft.com/deployedge/ms-edge-local-network-access.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccesspermissionspolicydefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccesspermissionspolicydefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkallowedforurls","displayName":"Allow sites to make network requests to local network endpoints. (User)","description":"Controls which website origins are exempt from Local Network Access checks when accessing local network endpoints.\r\n\r\nNetwork requests initiated from websites that match the specified URL patterns are not subject to Local Network Access checks.\r\n\r\nFor origins not covered by the patterns specified in this policy, the user's personal configuration applies.\r\n\r\nFor detailed information about valid URL patterns, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\r\n\r\nFor more information about Local Network Access restrictions, see https://wicg.github.io/local-network-access/.\r\n\r\nMultiple policies can list origins that affect requests to local network endpoints. If an origin matches more than one of the following policies, they take precedence in the following order:\r\n- LocalNetworkBlockedForUrls\r\n- LocalNetworkAllowedForUrls\r\n- LoopbackNetworkBlockedForUrls\r\n- LoopbackNetworkAllowedForUrls\r\n- LocalNetworkAccessBlockedForUrls\r\n- LocalNetworkAccessAllowedForUrls\r\n\r\nThis policy controls access to local network endpoints (private IP addresses) and can be used to allow specific websites to access local network resources.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkallowedforurls_localnetworkallowedforurlsdesc","displayName":"Allow sites to make network requests to local network endpoints. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkblockedforurls","displayName":"Block sites from making network requests to local network endpoints. (User)","description":"Controls which website origins are blocked from making Local Network Access requests to local network endpoints.\r\n\r\nNetwork requests initiated from websites that match the specified URL patterns are blocked from issuing Local Network Access requests.\r\n\r\nFor origins not covered by the patterns specified in this policy, the user's personal configuration applies.\r\n\r\nFor detailed information about valid URL patterns, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\r\n\r\nFor more information about Local Network Access restrictions, see https://wicg.github.io/local-network-access/.\r\n\r\nMultiple policies can list origins that affect requests to local network endpoints. If an origin matches more than one of the following policies, they take precedence in the following order:\r\n- LocalNetworkBlockedForUrls\r\n- LocalNetworkAllowedForUrls\r\n- LoopbackNetworkBlockedForUrls\r\n- LoopbackNetworkAllowedForUrls\r\n- LocalNetworkAccessBlockedForUrls\r\n- LocalNetworkAccessAllowedForUrls\r\n\r\nThis policy controls access to local network endpoints (private IP addresses) and can be used to block specific websites from accessing local network resources.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkblockedforurls_localnetworkblockedforurlsdesc","displayName":"Block sites from making network requests to local network endpoints. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls","displayName":"Allow sites to make network requests to the local device. (User)","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions when accessing loopback addresses (127.0.0.1, ::1, localhost).\r\n\r\nIf a requesting origin matches a URL pattern specified in this policy, requests to loopback addresses are allowed and are not subject to Local Network Access restrictions.\r\n\r\nFor origins not covered by this policy, the user's personal settings and local network access restrictions apply.\r\n\r\nIf this policy is disabled or not configured, no additional exemptions are granted beyond the user's existing configuration.\r\n\r\nMultiple policies can specify origins that affect requests to the local device. If an origin matches more than one of the following policies, they are applied in the following order of precedence:\r\n- LoopbackNetworkBlockedForUrls\r\n- LoopbackNetworkAllowedForUrls\r\n- LocalNetworkAccessBlockedForUrls\r\n- LocalNetworkAccessAllowedForUrls\r\n\r\nFor guidance on valid URL pattern syntax, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns .\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls_loopbacknetworkallowedforurlsdesc","displayName":"Allow sites to make network requests to the local device. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkblockedforurls","displayName":"Block sites from making network requests to the local device. (User)","description":"Specifies a list of URL patterns for which requests initiated from matching origins to loopback addresses (127.0.0.1, ::1, localhost) are blocked from issuing Local Network Access requests.\r\n\r\nIf a requesting origin matches a URL pattern specified in this policy, requests to loopback addresses are blocked.\r\n\r\nFor origins not covered by this policy, the user's personal settings and local network access restrictions apply.\r\n\r\nMultiple policies can specify origins that affect requests to the local device. If an origin matches more than one of the following policies, they are applied in the following order of precedence:\r\n- LoopbackNetworkBlockedForUrls\r\n- LoopbackNetworkAllowedForUrls\r\n- LocalNetworkAccessBlockedForUrls\r\n- LocalNetworkAccessAllowedForUrls\r\n\r\nNote: This policy improves local network security by blocking specified public websites from accessing loopback addresses. It helps prevent unauthorized external sites from reaching local services running on the device unless explicitly permitted.\r\n\r\nFor more information about Local Network Access, see https://wicg.github.io/local-network-access/\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkblockedforurls_loopbacknetworkblockedforurlsdesc","displayName":"Block sites from making network requests to the local device. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_browserguestmodeenforced","displayName":"Enforce Edge guest mode (User)","description":"Controls whether Microsoft Edge enforces Guest-only browsing.\r\n\r\nIf you enable this policy, Microsoft Edge enforces Guest sessions and prevents profile sign-in. Guest sessions run in InPrivate mode.\r\n\r\nIf you disable or don't configure this policy, users can create and use profiles. Guest mode can also be controlled separately using the BrowserGuestModeEnabled policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_browserguestmodeenforced_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_browserguestmodeenforced_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_forceforegroundpriorityforalltabs","displayName":"Force foreground priority for all tabs (User)","description":"This policy controls whether background web content runs at foreground priority.\r\n\r\nBy default, the browser optimizes resource usage by lowering the scheduling\r\npriority of content in background tabs. This helps improve overall system\r\nresponsiveness and performance for the active tab.\r\n\r\nIf you enable this policy, background web content runs at the same foreground\r\npriority as the active tab, regardless of visibility state.\r\n\r\nIf you disable or don't configure this policy, the browser determines the\r\npriority of web content based on standard heuristics. For example, content\r\nthat is not visible, not playing audio, and not participating in video calls\r\nmay be deprioritized.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_forceforegroundpriorityforalltabs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_forceforegroundpriorityforalltabs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist","displayName":"Allow access to a list of URLs in InPrivate mode. (User)","description":"This policy allows administrators to specify a list of URL patterns that are permitted to open in InPrivate mode. It can be used to create exceptions for URL patterns defined in 'InPrivateModeUrlBlocklist' (Block access to a list of URLs in InPrivate mode.). See how to format a URL pattern (https://go.microsoft.com/fwlink/?linkid=2095322).\r\n\r\nIf both this policy and 'InPrivateModeUrlBlocklist' are configured, the allowlist takes precedence. URLs that match a pattern on this allowlist are allowed. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither list fall back to 'URLBlocklist' (Block access to a list of URLs) and 'URLAllowlist' (Define a list of allowed URLs).\r\n\r\nIf this policy is configured and 'InPrivateModeUrlBlocklist' is not configured, only the URLs specified in this allowlist can be opened in InPrivate mode. All other URLs are blocked.\r\n\r\nIf 'InPrivateModeAvailability' (Configure InPrivate mode availability) is set to disallow (value 1) but this policy is configured, InPrivate mode is available only for URLs that match the allowlist.\r\n\r\nIf this policy is not configured, no exceptions are applied to 'InPrivateModeUrlBlocklist' or 'InPrivateModeAvailability'.\r\n\r\nThis policy applies only to InPrivate mode. To allow URLs across all browsing modes and profiles, use the 'URLAllowlist' policy.\r\n\r\nThis policy supports up to 1000 entries.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist_inprivatemodeurlallowlistdesc","displayName":"Allow access to a list of URLs in InPrivate mode. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist","displayName":"Block access to a list of URLs in InPrivate mode. (User)","description":"This policy controls which URLs are blocked from loading in InPrivate mode in Microsoft Edge.\r\n\r\nAdministrators can specify a list of URL patterns that are blocked when users browse in InPrivate mode. For information about the supported URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nIf both 'InPrivateModeUrlBlocklist' (Block access to a list of URLs in InPrivate mode.) and 'InPrivateModeUrlAllowlist' (Allow access to a list of URLs in InPrivate mode.) are configured, the allowlist takes precedence.\r\n- URLs that match the allowlist are allowed.\r\n- URLs that match the blocklist but not the allowlist are blocked.\r\n- URLs that match neither list follow the behavior defined by the general 'URLBlocklist' (Block access to a list of URLs) and 'URLAllowlist' (Define a list of allowed URLs) policies.\r\n\r\nIf 'InPrivateModeUrlAllowlist' is configured and this policy is not configured, only URLs on the allowlist can be opened in InPrivate mode.\r\n\r\nIf 'InPrivateModeAvailability' (Configure InPrivate mode availability) is set to disallow (value 1) and 'InPrivateModeUrlAllowlist' is configured, InPrivate mode is available only for URLs that match the allowlist.\r\n\r\nThis policy applies only to InPrivate mode. To block URLs across all browsing modes, use 'URLBlocklist'.\r\n\r\nThis policy supports up to 1000 entries.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist_inprivatemodeurlblocklistdesc","displayName":"Block access to a list of URLs in InPrivate mode. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended","displayName":"Set default download directory (User)","description":"This policy sets the default directory that Microsoft Edge uses to download files. Users can change the directory through browser settings.\r\n\r\nIf you don't configure this policy, Microsoft Edge uses the platform-specific default download directory.\r\n\r\nThis policy has no effect if the DownloadDirectory policy is set.\r\n\r\nFor a list of supported variables, see https://learn.microsoft.com/en-us/deployedge/edge-learnmore-create-user-directory-vars .\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_defaultdownloaddirectory","displayName":"Set default download directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_xsltenabled","displayName":"Control the availability of the XSLT feature (User)","description":"Controls whether the XSLT feature (the XSLTProcessor JavaScript API and the XSL processing instruction) is available in Microsoft Edge.\r\n\r\nIf you enable this policy, XSLT is available regardless of the browser's default configuration.\r\n\r\nIf you disable this policy, XSLT is unavailable regardless of the browser's default configuration.\r\n\r\nIf you don't configure this policy, XSLT availability is determined by the browser's default configuration and any applicable field trials.\r\n\r\nThis policy is temporary and will be removed in a future version of Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_xsltenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_xsltenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains","displayName":"Allow specified sites to access file:// URLs in the PDF Viewer (User)","description":"Controls which sites can access file:// URLs in the PDF Viewer.\r\n\r\nIf you enable this policy, sites in the list can access file:// URLs in the PDF Viewer.\r\n\r\nIf you disable or don't configure this policy, sites cannot access file:// URLs in the PDF Viewer.\r\n\r\nExample value:\r\n\r\nexample.com\r\ncontoso.com","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains_pdflocalfileaccessallowedfordomainsdesc","displayName":"Allow specified sites to access file:// URLs in the PDF Viewer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~protectedcontent_protectedcontentidentifiersallowed","displayName":"Allows web pages to use identifiers for the purpose of protected content playback (User)","description":"This policy controls whether sites can use hardware-specific device identifiers to enable hardware-secure DRM (for example, Widevine L1 or PlayReady SL3000), which may be required for high-resolution protected content playback.\r\n\r\nIf you enable this policy or do not configure it, sites are allowed to use protected content identifiers.\r\n\r\nIf you disable this policy, sites are not allowed to use protected content identifiers.","helpText":"","infoUrls":[],"categoryId":"2af24920-f611-4f03-99a6-205773869ae6","categoryName":"Protected Content","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~protectedcontent_protectedcontentidentifiersallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~protectedcontent_protectedcontentidentifiersallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge. (User)","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\r\n\r\nBrowsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\r\n\r\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\r\n\r\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?linkid=2346300.\r\n\r\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\r\n\r\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\r\n\r\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist","displayName":"Browsing with Copilot Allowed URLs (User)","description":"Allows you to define a list of URLs where browsing with Copilot is available. Users cannot modify this list.\r\n\r\nIf you enable this policy, browsing with Copilot is available only on the sites specified in the list. To allow a broader set of sites while blocking specific exceptions, configure this policy together with the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. For example, you can include '*' to allow all sites, and then use the block list to restrict access to specific URLs.\r\n\r\nYou can define exceptions based on schemes, subdomains, ports, or origins. When multiple filters apply, the most specific match determines whether a URL is allowed or blocked. The block list takes precedence over the allow list.\r\n\r\nIf you disable or do not configure this policy, browsing with Copilot is unavailable on all sites, even if the 'AllowBrowsingWithCopilot' (Controls the availability of browsing with Copilot in Microsoft Edge.) policy is enabled.\r\n\r\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. This policy applies only to the site origin; any path specified in the URL pattern is ignored. For guidance on formatting URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu\r\ncontoso.net\r\nlogin.contoso.us","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_browsingwithcopilotallowlistdesc","displayName":"Browsing with Copilot Allowed URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist","displayName":"Browsing with Copilot Blocked URLs (User)","description":"Controls the list of URLs where browsing with Copilot is blocked. Users can't modify this list.\r\n\r\nUse this policy to define exceptions to broader allowlists. For example, you can set 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) to '*' to allow all sites, and then use this policy to block access to specific URLs.\r\n\r\nThis policy supports blocking by scheme, subdomain, or port. When multiple URL patterns apply, the most specific match determines whether access is allowed or blocked. Blocklist entries take precedence over allowlist entries.\r\n\r\nIf you don't configure this policy, no exceptions are applied to 'BrowsingWithCopilotAllowList'.\r\n\r\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. URL matching is based on the site origin only; any path specified in the pattern is ignored.\r\n\r\nFor information about URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu\r\ncontoso.net\r\nlogin.contoso.us","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist_browsingwithcopilotblocklistdesc","displayName":"Browsing with Copilot Blocked URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_copilotnewtabpageenabled","displayName":"Enable the Copilot new tab page (User)","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\r\n\r\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\r\n\r\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\r\n\r\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\r\n\r\nIf you enable this policy, the Copilot new tab page is turned on.\r\n\r\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_copilotnewtabpageenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_copilotnewtabpageenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityallowlist","displayName":"List of URL patterns for which developer tools are allowed to be opened (User)","description":"This policy controls where developer tools can be used in Microsoft Edge by specifying an allowlist of URL patterns.\r\n\r\nURL patterns are matched against the URL of every frame on the page being inspected.\r\n\r\nIf you configure this policy and do not configure the 'DeveloperToolsAvailabilityBlocklist' (List of URL patterns for which developer tools are blocked) policy, developer tools are available only when every frame on the page matches a pattern in this allowlist. If any frame does not match, developer tools are blocked for the entire page. For information on the URL format, see https://go.microsoft.com/fwlink/?linkid=2095322 .\r\n\r\nIf you configure both this policy and the 'DeveloperToolsAvailabilityBlocklist' policy, this allowlist takes precedence. URLs that match this allowlist are allowed even if they also match the blocklist. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither are governed by the 'DeveloperToolsAvailability' (Control where developer tools can be used) policy.\r\n\r\nIf you disable or do not configure this policy, developer tools availability is determined by the 'DeveloperToolsAvailabilityBlocklist' and 'DeveloperToolsAvailability' policies.\r\n\r\nThis policy applies to developer tools opened for websites, extensions, and web applications.\r\n\r\nThis policy supports up to 1,000 entries.\r\n\r\nExample value:\r\n\r\ncontoso.com\r\nhttps://ssl.server.com\r\ncontoso.com/good_path\r\nhttps://server.contoso.com:8080/path\r\n.exact.hostname.com\r\nfile://*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityallowlist_developertoolsavailabilityallowlistdesc","displayName":"List of URL patterns for which developer tools are allowed to be opened (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityblocklist","displayName":"List of URL patterns for which developer tools are blocked (User)","description":"This policy specifies URL patterns where developer tools are blocked. For information on the URL format, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nURL patterns are evaluated against the URL of every frame on the page being inspected. If any frame matches a pattern in this policy, developer tools are blocked for the entire page.\r\n\r\nIf you configure this policy and do not configure the 'DeveloperToolsAvailabilityAllowlist' (List of URL patterns for which developer tools are allowed to be opened) policy, developer tools are blocked when any frame matches a pattern in this policy. If no frames match, availability is determined by the 'DeveloperToolsAvailability' (Control where developer tools can be used) policy.\r\n\r\nIf you configure both this policy and the 'DeveloperToolsAvailabilityAllowlist' policy, the allowlist takes precedence. URLs that match the allowlist are allowed, even if they also match this policy. URLs that match this policy (but not the allowlist) are blocked. If a URL matches neither, the 'DeveloperToolsAvailability' policy determines availability.\r\n\r\nIf you disable or do not configure this policy, developer tools availability is determined by the 'DeveloperToolsAvailabilityAllowlist' and 'DeveloperToolsAvailability' policies.\r\n\r\nThis policy supports up to 1,000 entries.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com\r\ncontoso.com\r\nhttps://ssl.server.com\r\ncontoso.com/bad_path\r\nhttps://server.contoso.com:8080/path\r\n.exact.hostname.com\r\n*\r\nfile://*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityblocklist_developertoolsavailabilityblocklistdesc","displayName":"List of URL patterns for which developer tools are blocked (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_m365linksautoopencopilotenabled","displayName":"Automatically open Copilot side pane with contextual insights for links opened from Outlook (User)","description":"This policy controls whether Microsoft Edge automatically opens the Microsoft Copilot side pane when users open web links from Outlook emails sent from the same tenant.\r\n\r\nStarting in Microsoft Edge version 148, when users open eligible links from Outlook emails sent from the same tenant, Microsoft Edge automatically opens the Copilot side pane with contextual insights. Copilot can use the originating Outlook email as context to surface relevant insights and suggested next steps alongside the web content.\r\n\r\nIf you enable this policy or don't configure it, the Copilot side pane opens automatically when users open links from Outlook emails sent from the same tenant.\r\n\r\nIf you disable this policy, the Copilot side pane doesn't open automatically when users open links from Outlook emails sent from the same tenant.\r\n\r\nThis feature applies only to links opened from Outlook emails sent from the same tenant and requires Microsoft Copilot to be available for the user in Microsoft Edge.\r\n\r\nThis feature is disabled if the 'CopilotPageContext' (Control Copilot access to page context for Microsoft Entra ID profiles) policy or the 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane) policy is disabled, regardless of this policy's configuration. Copilot requires access to page content to provide contextual insights.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_m365linksautoopencopilotenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_m365linksautoopencopilotenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket","displayName":"Maximum number of concurrent connections to the proxy server for WebSocket requests (User)","description":"Specifies the maximum number of simultaneous connections to a proxy server for WebSocket requests.\r\n\r\nTo configure limits for non-WebSocket requests, see the 'MaxConnectionsPerProxy' (Maximum number of concurrent connections to the proxy server) policy.\r\n\r\nIf you don't configure this policy, the default value of 32 is used.\r\n\r\nSome web applications maintain multiple concurrent connections (for example, long-lived or hanging requests). Setting a value lower than the default may cause networking delays when many such applications are open.\r\n\r\nSome proxy servers cannot handle a high number of concurrent connections per client. In these cases, reducing the value of this policy may improve reliability.\r\n\r\nThe supported range is 6 to 256:\r\n- Values less than 6 are treated as 6.\r\n- Values greater than 256 are treated as 256.\r\n\r\nWe recommend modifying this value only if required by your proxy server configuration or network environment.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket_maxconnectionsperproxyforwebsocket","displayName":"Maximum number of concurrent connections to the proxy server for WebSocket requests: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge. (User)","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\r\n\r\nBrowsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\r\n\r\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\r\n\r\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?linkid=2346300.\r\n\r\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\r\n\r\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\r\n\r\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended","displayName":"Enable the Copilot new tab page (User)","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\r\n\r\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\r\n\r\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\r\n\r\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\r\n\r\nIf you enable this policy, the Copilot new tab page is turned on.\r\n\r\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended","displayName":"Set the default New Tab Page feed tab to Work or Discover (User)","description":"This policy sets the default feed tab on the New Tab Page to Work or Discover.\r\n\r\nIf you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work.\r\n\r\nIf you set this policy to 'Discover' (1), Microsoft Edge sets the default feed tab to Discover.\r\n\r\nThis policy only takes effect when 'ConfigureNTPFeedTabVisibility' (Configure whether the Discover or Work feed tabs are shown on the New Tab Page.) is set to 'EnableBothWorkDiscover' (0) or is not configured. If only one tab is visible, this policy has no effect.\r\n\r\nPolicy options mapping:\r\n\r\n* NTPDefaultFeedTabWork (0) = Work\r\n\r\n* NTPDefaultFeedTabDiscover (1) = Discover\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab_0","displayName":"Work","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab_1","displayName":"Discover","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_sharedworkerextendedlifetimeenabled","displayName":"Enable the extended lifetime option for SharedWorkers (User)","description":"Controls whether Microsoft Edge allows SharedWorkers to use the extendedLifetime option.\r\n\r\nIf you enable or don't configure this policy, SharedWorkers can use the extended lifetime option in the SharedWorker constructor.\r\n\r\nIf you disable this policy, the extended lifetime option is ignored, even if it is requested by the page.\r\n\r\nThis policy is temporary and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_sharedworkerextendedlifetimeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_sharedworkerextendedlifetimeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~identity_m365authpopupsinworkenabled","displayName":"Allow M365 authentication popups in work profiles (User)","description":"This policy controls whether Microsoft Edge allows Microsoft 365 authentication pop-ups to bypass the pop-up blocker in work profiles.\r\n\r\nWhen users are signed in with a work account, some Microsoft 365 sites (for example, microsoft.com, cloud.microsoft, and visualstudio.com) may open authentication pop-ups to login.microsoftonline.com, login.live.com, or login.microsoft.com. These pop-ups are required to complete sign-in.\r\n\r\nIf you enable this policy or don't configure it, Microsoft 365 authentication pop-ups are allowed in work profiles.\r\n\r\nIf you disable this policy, Microsoft 365 authentication pop-ups follow the default settings like other pop-ups.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~identity_m365authpopupsinworkenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~identity_m365authpopupsinworkenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~manageability_mamwithdevicedlpenabled","displayName":"Allow MAM enrollment when managed device has Purview DLP policy configured (User)","description":"Controls whether Microsoft Edge allows Mobile Application Management (MAM) enrollment on managed devices when Microsoft Purview Data Loss Prevention (DLP) is configured.\r\n\r\nIf you enable this policy, MAM enrollment is allowed even when Purview DLP is detected on the device.\r\n\r\nIf you disable or don't configure this policy, MAM enrollment is blocked when Purview DLP is detected on the device.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~manageability_mamwithdevicedlpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~manageability_mamwithdevicedlpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility","displayName":"Configure whether the Discover or Work feed tabs are shown on the New Tab Page. (User)","description":"This policy configures whether the Discover or Work feed tabs are shown on the New Tab Page. By default, both Work and Discover tabs are enabled.\r\n\r\nIf you set this policy to 'EnableBothWorkDiscover' (0) or do not configure this policy, Microsoft Edge shows both the Work and Discover feed tabs on the new tab page.\r\n\r\nIf you set this policy to 'EnableOnlyWork' (1), Microsoft Edge shows only the Work feed tab on the new tab page.\r\n\r\nIf you set this policy to 'EnableOnlyDiscover' (2), Microsoft Edge shows only the Discover feed tab on the new tab page.\r\n\r\nThis policy works with the SetNTPDefaultFeedTab policy, which controls which feed tab is selected by default when both tabs are available.\r\n\r\nPolicy options mapping:\r\n\r\n* EnableBothWorkDiscover (0) = Enable both Work and Discover tabs\r\n\r\n* EnableOnlyWork (1) = Enable only Work tab\r\n\r\n* EnableOnlyDiscover (2) = Enable only Discover tab\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility","displayName":"Configure whether the Discover or Work feed tabs are shown on the New Tab Page. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility_0","displayName":"Enable both Work and Discover tabs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility_1","displayName":"Enable only Work tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility_2","displayName":"Enable only Discover tab","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (User)","description":"This policy sets the default feed tab on the New Tab Page to Work or Discover.\r\n\r\nIf you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work.\r\n\r\nIf you set this policy to 'Discover' (1), Microsoft Edge sets the default feed tab to Discover.\r\n\r\nThis policy only takes effect when 'ConfigureNTPFeedTabVisibility' (Configure whether the Discover or Work feed tabs are shown on the New Tab Page.) is set to 'EnableBothWorkDiscover' (0) or is not configured. If only one tab is visible, this policy has no effect.\r\n\r\nPolicy options mapping:\r\n\r\n* NTPDefaultFeedTabWork (0) = Work\r\n\r\n* NTPDefaultFeedTabDiscover (1) = Discover\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab_0","displayName":"Work","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab_1","displayName":"Discover","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\r\n\r\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\r\n\r\nDisabling this setting is the same as leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\r\n\r\nPolicy options mapping:\r\n\r\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\r\n\r\n* RestoreOnStartupIsLastSession (1) = Restore the last session\r\n\r\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\r\n\r\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_6","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\r\n\r\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\r\n\r\nDisabling this setting is the same as leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\r\n\r\nPolicy options mapping:\r\n\r\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\r\n\r\n* RestoreOnStartupIsLastSession (1) = Restore the last session\r\n\r\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\r\n\r\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_6","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads (User)","description":"Controls whether ads are blocked on sites with intrusive ads. You can set this policy to one of the following options:\r\n\r\n* 1 = Allow ads on all sites.\r\n\r\n* 2 = Block ads on sites with intrusive ads (Default value).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_adssettingforintrusiveadssites_1","displayName":"Allow ads on all sites","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_adssettingforintrusiveadssites_2","displayName":"Block ads on sites with intrusive ads. (Default value)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowpopupsduringpageunload","displayName":"Allows a page to show popups during its unloading (User)","description":"This policy allows an admin to specify that a page can show popups during its unloading.\r\n\r\nWhen the policy is set to enabled, pages are allowed to show popups while they're being unloaded.\r\n\r\nWhen the policy is set to disabled or unset, pages aren't allowed to show popups while they're being unloaded. This is as per the spec: (https://html.spec.whatwg.org/#apis-for-creating-and-navigating-browsing-contexts-by-name).\r\n\r\nThis policy will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowpopupsduringpageunload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowpopupsduringpageunload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls","displayName":"Configure tracking prevention exceptions for specific sites (User)","description":"Configure the list of URL patterns that are excluded from tracking prevention.\r\n\r\nIf you configure this policy, the list of configured URL patterns is excluded from tracking prevention.\r\n\r\nIf you don't configure this policy, the global default value from the \"Block tracking of users' web-browsing activity\" policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_allowtrackingforurlsdesc","displayName":"Configure tracking prevention exceptions for specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_autoplayallowed","displayName":"Allow media autoplay for websites (User)","description":"This policy sets the media autoplay policy for websites.\r\n\r\nThe default setting, \"Not configured\" respects the current media autoplay settings and lets users configure their autoplay settings.\r\n\r\nSetting to \"Enabled\" sets media autoplay to \"Allow\". All websites are allowed to autoplay media. Users can’t override this policy.\r\n\r\nSetting to \"Disabled\" sets media autoplay to \"Block\". No websites are allowed to autoplay media. Users can’t override this policy.\r\n\r\nA tab will need to be closed and re-opened for this policy to take effect.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_autoplayallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_autoplayallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clearbrowsingdataonexit","displayName":"Clear browsing data when Microsoft Edge closes (User)","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\r\n\r\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured 'DefaultCookiesSetting' (Configure cookies)\r\n\r\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\r\n\r\nIf you enable this policy, don't configure the 'AllowDeletingBrowserHistory' (Enable deleting browser and download history) or the 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes) policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured 'AllowDeletingBrowserHistory' or 'ClearCachedImagesAndFilesOnExit'.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clearbrowsingdataonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clearbrowsingdataonexit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clickonceenabled","displayName":"Allow users to open files using the ClickOnce protocol (User)","description":"Allow users to open files using the ClickOnce protocol. The ClickOnce protocol allows websites to request that the browser open files from a specific URL using the ClickOnce file handler on the user's computer or device.\r\n\r\nIf you enable this policy, users can open files using the ClickOnce protocol. This policy overrides the user's ClickOnce setting in the edge://flags/ page.\r\n\r\nIf you disable this policy, users can't open files using the ClickOnce protocol. Instead, the file will be saved to the file system using the browser. This policy overrides the user's ClickOnce setting in the edge://flags/ page.\r\n\r\nIf you don't configure this policy, users can't open files using the ClickOnce protocol. Users have the option to enable the use of the ClickOnce protocol with the edge://flags/ page.\r\n\r\nDisabling ClickOnce may prevent ClickOnce applications (.application files) from launching properly.\r\n\r\nFor more information about ClickOnce, see https://go.microsoft.com/fwlink/?linkid=2103872 and https://go.microsoft.com/fwlink/?linkid=2099880.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clickonceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clickonceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_commandlineflagsecuritywarningsenabled","displayName":"Enable security warnings for command-line flags (User)","description":"If disabled, this policy prevents security warnings from appearing when Microsoft Edge is launched with potentially dangerous command-line flags.\r\n\r\nIf enabled or unset, security warnings are displayed when these command-line flags are used to launch Microsoft Edge.\r\n\r\nFor example, the --disable-gpu-sandbox flag generates this warning: You're using an unsupported command-line flag: --disable-gpu-sandbox. This poses stability and security risks.\r\n\r\nOn Windows, this policy is only available on instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro (or Enterprise) instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_commandlineflagsecuritywarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_commandlineflagsecuritywarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_directinvokeenabled","displayName":"Allow users to open files using the DirectInvoke protocol (User)","description":"Allow users to open files using the DirectInvoke protocol. The DirectInvoke protocol allows websites to request that the browser open files from a specific URL using a specific file handler on the user's computer or device.\r\n\r\nIf you enable or don't configure this policy, users can open files using the DirectInvoke protocol.\r\n\r\nIf you disable this policy, users can't open files using the DirectInvoke protocol. Instead, the file will be saved to the file system.\r\n\r\nNote: Disabling DirectInvoke may prevent certain Microsoft SharePoint Online features from working as expected.\r\n\r\nFor more information about DirectInvoke, see https://go.microsoft.com/fwlink/?linkid=2103872 and https://go.microsoft.com/fwlink/?linkid=2099871.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_directinvokeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_directinvokeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_edgecollectionsenabled","displayName":"Enable the Collections feature (User)","description":"Lets you allow users to access the Collections feature, where they can collect, organize, share, and export content more efficiently and with Office integration.\r\n\r\nIf you enable or don't configure this policy, users can access and use the Collections feature in Microsoft Edge.\r\n\r\nIf you disable this policy, users can't access and use Collections in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_edgecollectionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_edgecollectionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_enterprisehardwareplatformapienabled","displayName":"Allow managed extensions to use the Enterprise Hardware Platform API (User)","description":"When this policy is set to enabled, extensions installed by enterprise policy are allowed to use the Enterprise Hardware Platform API.\r\nWhen this policy is set to disabled or isn't set, no extensions are allowed to use the Enterprise Hardware Platform API.\r\nThis policy also applies to component extensions.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_enterprisehardwareplatformapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_enterprisehardwareplatformapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_forcenetworkinprocess","displayName":"Force networking code to run in the browser process (User)","description":"This policy forces networking code to run in the browser process.\r\n\r\nThis policy is disabled by default. If enabled, users are open to security issues when the networking process is sandboxed.\r\n\r\nThis policy is intended to give enterprises a chance to migrate to 3rd party software that doesn't depend on hooking networking APIs. Proxy servers are recommended over LSPs and Win32 API patching.\r\n\r\nIf this policy isn't set, networking code may run out of the browser process depending on field trials of the NetworkService experiment.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_forcenetworkinprocess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_forcenetworkinprocess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_gotointranetsiteforsinglewordentryinaddressbar","displayName":"Force direct intranet site navigation instead of searching on single word entries in the Address Bar (User)","description":"If you enable this policy, the top auto-suggest result in the address bar suggestion list will navigate to intranet sites if the text entered in the address bar is a single word without punctuation.\r\n\r\nDefault navigation when typing a single word without punctuation will conduct a navigation to an intranet site matching the entered text.\r\n\r\nIf you enable this policy, the second auto-suggest result in the address bar suggestion list will conduct a web search exactly as it was entered, provided that this text is a single word without punctuation. The default search provider will be used unless a policy to prevent web search is also enabled.\r\n\r\nTwo effects of enabling this policy are:\r\n\r\nNavigation to sites in response to single word queries that would typically resolve to a history item will no longer happen. Instead, the browser will attempt navigate to internal sites that may not exist in an organization’s intranet. This will result in a 404 error.\r\n\r\nPopular, single-word search terms will require manual selection of search suggestions to properly conduct a search.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_gotointranetsiteforsinglewordentryinaddressbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_gotointranetsiteforsinglewordentryinaddressbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_importbrowsersettings","displayName":"Allow importing of browser settings (User)","description":"Allows users to import browser settings from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browser settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_importbrowsersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_importbrowsersettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist","displayName":"Configure the Enterprise Mode Site List (User)","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210\r\n\r\nExample value: https://internal.contoso.com/sitelist.xml","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist_internetexplorerintegrationsitelist","displayName":"Configure the Enterprise Mode Site List (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled","displayName":"Configure whether a user always has a default profile automatically signed in with their work or school account (User)","description":"This policy determines if a user can remove the Microsoft Edge profile automatically signed in with a user's work or school account.\r\n\r\nIf you enable this policy, a non-removable profile will be created with the user's work or school account on Windows. This profile can't be signed out or removed.\r\n\r\nIf you disable or don't configure this policy, the profile automatically signed in with a user's work or school account on Windows can be signed out or removed by the user.\r\n\r\nIf you want to configure browser sign in, use the 'BrowserSignin' (Browser sign-in settings) policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_clearbrowsingdataonexit_recommended","displayName":"Clear browsing data when Microsoft Edge closes (User)","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\r\n\r\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured 'DefaultCookiesSetting' (Configure cookies)\r\n\r\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\r\n\r\nIf you enable this policy, don't configure the 'AllowDeletingBrowserHistory' (Enable deleting browser and download history) or the 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes) policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured 'AllowDeletingBrowserHistory' or 'ClearCachedImagesAndFilesOnExit'.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_clearbrowsingdataonexit_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_clearbrowsingdataonexit_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_importbrowsersettings_recommended","displayName":"Allow importing of browser settings (User)","description":"Allows users to import browser settings from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browser settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_importbrowsersettings_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_importbrowsersettings_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenfortrusteddownloadsenabled_recommended","displayName":"Force Microsoft Defender SmartScreen checks on downloads from trusted sources (User)","description":"This policy setting lets you configure whether Microsoft Defender SmartScreen checks download reputation from a trusted source.\r\n\r\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download’s reputation regardless of source.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen doesn’t check the download’s reputation when downloading from a trusted source.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenfortrusteddownloadsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenfortrusteddownloadsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_renderercodeintegrityenabled","displayName":"Enable renderer code integrity (deprecated) (User)","description":"If this policy is enabled or left unset, then Renderer Code Integrity is enabled. This policy should only be disabled if compatibility issues are encountered with third party software that must run inside Microsoft Edge's renderer processes.\r\n\r\nDisabling this policy has a detrimental effect on Microsoft Edge's security and stability because unknown and potentially hostile code will be allowed to load inside Microsoft Edge's renderer processes.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_renderercodeintegrityenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_renderercodeintegrityenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support (User)","description":"Enable support for Signed HTTP Exchange (SXG).\r\n\r\nIf this policy isn't set or enabled, Microsoft Edge will accept web contents served as Signed HTTP Exchanges.\r\n\r\nIf this policy is set to disabled, Signed HTTP Exchanges can't be loaded.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_spellchecklanguageblocklist","displayName":"Force disable spellcheck languages (User)","description":"Force-disables spellcheck languages. Unrecognized languages in that list will be ignored.\r\n\r\nIf you enable this policy, spellcheck will be disabled for the languages specified. The user can still enable or disable spellcheck for languages not in the list.\r\n\r\nIf you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy is set to disabled, this policy will have no effect.\r\n\r\nIf a language is included in both the 'SpellcheckLanguage' (Enable specific spellcheck languages) and the 'SpellcheckLanguageBlocklist' policy, the spellcheck language is enabled.\r\n\r\nThe currently supported languages are: af, bg, ca, cs, da, de, el, en-AU, en-CA, en-GB, en-US, es, es-419, es-AR, es-ES, es-MX, es-US, et, fa, fo, fr, he, hi, hr, hu, id, it, ko, lt, lv, nb, nl, pl, pt-BR, pt-PT, ro, ru, sh, sk, sl, sq, sr, sv, ta, tg, tr, uk, vi.\r\n\r\nExample value:\r\n\r\nfr\r\nes","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_spellchecklanguageblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_spellchecklanguageblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_spellchecklanguageblocklist_spellchecklanguageblocklistdesc","displayName":"Force disable spellcheck languages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention","displayName":"Block tracking of users' web-browsing activity (User)","description":"Lets you decide whether to block websites from tracking users' web-browsing activity.\r\n\r\nIf you enable this policy, you have the following options for setting the level of tracking prevention:\r\n\r\n* 0 = Off (no tracking prevention)\r\n\r\n* 1 = Basic (blocks harmful trackers, content and ads will be personalized)\r\n\r\n* 2 = Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)\r\n\r\n* 3 = Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)\r\n\r\nIf you disable this policy or don't configure it, users can set their own level of tracking prevention.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_trackingprevention","displayName":"Block tracking of users' web-browsing activity (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_trackingprevention_0","displayName":"Off (no tracking prevention)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_trackingprevention_1","displayName":"Basic (blocks harmful trackers, content and ads will be personalized)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_trackingprevention_2","displayName":"Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_trackingprevention_3","displayName":"Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge~smartscreen_smartscreenfortrusteddownloadsenabled","displayName":"Force Microsoft Defender SmartScreen checks on downloads from trusted sources (User)","description":"This policy setting lets you configure whether Microsoft Defender SmartScreen checks download reputation from a trusted source.\r\n\r\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download’s reputation regardless of source.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen doesn’t check the download’s reputation when downloading from a trusted source.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge~smartscreen_smartscreenfortrusteddownloadsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge~smartscreen_smartscreenfortrusteddownloadsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_allowsyncxhrinpagedismissal","displayName":"Allow pages to send synchronous XHR requests during page dismissal (User)","description":"This policy lets you specify that a page can send synchronous XHR requests during page dismissal.\r\n\r\nIf you enable this policy, pages can send synchronous XHR requests during page dismissal.\r\n\r\nIf you disable this policy or don't configure this policy, pages aren't allowed to send synchronous XHR requests during page dismissal.\r\n\r\nThis policy is temporary and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_allowsyncxhrinpagedismissal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_allowsyncxhrinpagedismissal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_backgroundtemplatelistupdatesenabled","displayName":"Enables background updates to the list of available templates for Collections and other features that use templates (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because we are moving to a new policy. It won't work in Microsoft Edge as soon as version 104. The new policy to use is 'EdgeAssetDeliveryServiceEnabled' (Allow features to download assets from the Asset Delivery Service).\r\n\r\nLets you enable or disable background updates to the list of available templates for Collections and other features that use templates. Templates are used to extract rich metadata from a webpage when the page is saved to a collection.\r\n\r\nIf you enable this setting or the setting is unconfigured, the list of available templates will be downloaded in the background from a Microsoft service every 24 hours.\r\n\r\nIf you disable this setting the list of available templates will be downloaded on demand. This type of download might result in small performance penalties for Collections and other features.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_backgroundtemplatelistupdatesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_backgroundtemplatelistupdatesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_customhelplink","displayName":"Specify custom help link (User)","description":"Specify a link for the Help menu or the F1 key.\r\n\r\nIf you enable this policy, an admin can specify a link for the Help menu or the F1 key.\r\n\r\nIf you disable or don't configure this policy, the default link for the Help menu or the F1 key is used.\r\n\r\nExample value: https://go.microsoft.com/fwlink/?linkid=2080734","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_customhelplink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_customhelplink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_customhelplink_customhelplink","displayName":"Specify custom help link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_externalprotocoldialogshowalwaysopencheckbox","displayName":"Show an \"Always open\" checkbox in external protocol dialog (User)","description":"This policy controls whether the \"Always allow this site to open links of this type\" checkbox is shown on external protocol launch confirmation prompts.\r\n\r\nIf you set this policy to True, when an external protocol confirmation prompt is shown, the user can select \"Always allow\" to skip all future confirmation prompts for the protocol on this site.\r\n\r\nIf you set this policy to False, the \"Always allow\" checkbox isn't displayed. The user will be prompted for confirmation every time an external protocol is invoked.\r\n\r\nIf this policy is unset, the checkbox visibility is controlled by the \"Enable remembering protocol launch prompting preferences\" flag in edge://flags","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_externalprotocoldialogshowalwaysopencheckbox_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_externalprotocoldialogshowalwaysopencheckbox_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist","displayName":"Configure the list of names that will bypass the HSTS policy check (User)","description":"Hostnames specified in this list will be exempt from the HSTS policy check that could potentially upgrade requests from \"http://\" to \"https://\". Only single-label hostnames are allowed in this policy. Hostnames must be canonicalized. Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific hostnames specified; it doesn't apply to subdomains of the names in the list.\r\n\r\nExample value:\r\n\r\nmeet","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist_hstspolicybypasslistdesc","displayName":"Configure the list of names that will bypass the HSTS policy check (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_importopentabs","displayName":"Allow importing of open tabs (User)","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_importopentabs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_importopentabs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended","displayName":"Allow importing of open tabs (User)","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagemanagedquicklinks_recommended","displayName":"Set new tab page quick links (User)","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\r\n\r\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\r\n\r\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' is not provided, the URL is used as the default title. If 'pinned' is not provided, the default value is false.\r\n\r\nMicrosoft Edge presents these in the order listed, from left to right, with all pinned tiles displayed ahead of non-pinned tiles.\r\n\r\nIf the policy is set as mandatory, the 'pinned' field will be ignored and all tiles will be pinned. The tiles can't be deleted by the user and will always appear at the front of the quick links list.\r\n\r\nIf the policy is set as recommended, pinned tiles will remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying non-pinned links via this policy to an existing browser profile, the links may not appear at all, depending on how they rank compared to the user's browsing history.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"pinned\": true,\r\n \"title\": \"Contoso Portal\",\r\n \"url\": \"https://contoso.com\"\r\n },\r\n {\r\n \"title\": \"Fabrikam\",\r\n \"url\": \"https://fabrikam.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagemanagedquicklinks_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagemanagedquicklinks_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagemanagedquicklinks_recommended_newtabpagemanagedquicklinks","displayName":"Set new tab page quick links (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagesetfeedtype_recommended","displayName":"Configure the Microsoft Edge new tab page experience (User)","description":"Lets you choose either the Microsoft News or Office 365 feed experience for the new tab page.\r\n\r\nWhen you set this policy to Microsoft News feed experience (0), users will see the Microsoft News feed experience on the new tab page.\r\n\r\nWhen you set this policy to Office 365 feed experience (1), users with an Azure Active Directory browser sign-in will see the Office 365 feed experience on the new tab page.\r\n\r\nIf you disable or don't configure this policy:\r\n\r\n- Users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, as well as the standard new tab page feed experience.\r\n\r\n- Users without an Azure Active Directory browser sign-in will see the standard new tab page experience.\r\n\r\nIf you configure this policy *and* the 'NewTabPageLocation' (Configure the new tab page URL) policy, 'NewTabPageLocation' has precedence.\r\n\r\nDefault setting: Disabled or not configured.\r\n\r\n* 0 = Microsoft News feed experience\r\n\r\n* 1 = Office 365 feed experience","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagesetfeedtype_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagesetfeedtype_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagesetfeedtype_recommended_newtabpagesetfeedtype","displayName":"New tab page experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagesetfeedtype_recommended_newtabpagesetfeedtype_0","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagesetfeedtype_recommended_newtabpagesetfeedtype_1","displayName":"Office 365 feed experience","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_tabfreezingenabled","displayName":"Allow freezing of background tabs (User)","description":"Controls whether Microsoft Edge can freeze tabs that are in the background for at least 5 minutes.\r\n\r\nTab freezing reduces CPU, battery, and memory usage. Microsoft Edge uses heuristics to avoid freezing tabs that do useful work in the background, such as display notifications, play sound, and stream video.\r\n\r\nIf you enable or don't configure this policy, tabs that have been in the background for at least 5 minutes might be frozen.\r\n\r\nIf you disable this policy, no tabs will be frozen.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_tabfreezingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_tabfreezingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagecompanylogo","displayName":"Set new tab page company logo (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nWe are deprecating this policy because it doesn't work as expected and recommend that it not be used.\r\n\r\nSpecifies the company logo to use on the new tab page in Microsoft Edge.\r\n\r\nThe policy should be configured as a string that expresses the logo(s) in JSON format. For example: { \"default_logo\": { \"url\": \"https://www.contoso.com/logo.png\", \"hash\": \"cd0aa9856147b6c5b4ff2b7dfee5da20aa38253099ef1b4a64aced233c9afe29\" }, \"light_logo\": { \"url\": \"https://www.contoso.com/light_logo.png\", \"hash\": \"517d286edb416bb2625ccfcba9de78296e90da8e32330d4c9c8275c4c1c33737\" } }\r\n\r\nYou configure this policy by specifying the URL from which Microsoft Edge can download the logo and its cryptographic hash (SHA-256), which is used to verify the integrity of the download. The logo must be in PNG or SVG format, and its file size must not exceed 16 MB. The logo is downloaded and cached, and it will be redownloaded whenever the URL or the hash changes. The URL must be accessible without any authentication.\r\n\r\nThe 'default_logo' is required and will be used when there's no background image. If 'light_logo' is provided, it will be used when the user's new tab page has a background image. We recommend a horizontal logo with a transparent background that is left-aligned and vertically centered. The logo should have a minimum height of 32 pixels and an aspect ratio from 1:1 to 4:1. The 'default_logo' should have proper contrast against a white/black background while the 'light_logo' should have proper contrast against a background image.\r\n\r\nIf you enable this policy, Microsoft Edge downloads and shows the specified logo(s) on the new tab page. Users can't override or hide the logo(s).\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will show no company logo or a Microsoft logo on the new tab page.\r\n\r\nFor help with determining the SHA-256 hash, see https://docs.microsoft.com/powershell/module/microsoft.powershell.utility/get-filehash.\r\n\r\nExample value:\r\n\r\n{\r\n \"light_logo\": {\r\n \"url\": \"https://www.contoso.com/light_logo.png\", \r\n \"hash\": \"517d286edb416bb2625ccfcba9de78296e90da8e32330d4c9c8275c4c1c33737\"\r\n }, \r\n \"default_logo\": {\r\n \"url\": \"https://www.contoso.com/logo.png\", \r\n \"hash\": \"cd0aa9856147b6c5b4ff2b7dfee5da20aa38253099ef1b4a64aced233c9afe29\"\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagecompanylogo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagecompanylogo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagecompanylogo_newtabpagecompanylogo","displayName":"New tab page company logo (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks","displayName":"Set new tab page quick links (User)","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\r\n\r\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\r\n\r\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' is not provided, the URL is used as the default title. If 'pinned' is not provided, the default value is false.\r\n\r\nMicrosoft Edge presents these in the order listed, from left to right, with all pinned tiles displayed ahead of non-pinned tiles.\r\n\r\nIf the policy is set as mandatory, the 'pinned' field will be ignored and all tiles will be pinned. The tiles can't be deleted by the user and will always appear at the front of the quick links list.\r\n\r\nIf the policy is set as recommended, pinned tiles will remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying non-pinned links via this policy to an existing browser profile, the links may not appear at all, depending on how they rank compared to the user's browsing history.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"pinned\": true,\r\n \"title\": \"Contoso Portal\",\r\n \"url\": \"https://contoso.com\"\r\n },\r\n {\r\n \"title\": \"Fabrikam\",\r\n \"url\": \"https://fabrikam.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks_newtabpagemanagedquicklinks","displayName":"Set new tab page quick links (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype","displayName":"Configure the Microsoft Edge new tab page experience (User)","description":"Lets you choose either the Microsoft News or Office 365 feed experience for the new tab page.\r\n\r\nWhen you set this policy to Microsoft News feed experience (0), users will see the Microsoft News feed experience on the new tab page.\r\n\r\nWhen you set this policy to Office 365 feed experience (1), users with an Azure Active Directory browser sign-in will see the Office 365 feed experience on the new tab page.\r\n\r\nIf you disable or don't configure this policy:\r\n\r\n- Users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, as well as the standard new tab page feed experience.\r\n\r\n- Users without an Azure Active Directory browser sign-in will see the standard new tab page experience.\r\n\r\nIf you configure this policy *and* the 'NewTabPageLocation' (Configure the new tab page URL) policy, 'NewTabPageLocation' has precedence.\r\n\r\nDefault setting: Disabled or not configured.\r\n\r\n* 0 = Microsoft News feed experience\r\n\r\n* 1 = Office 365 feed experience","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype","displayName":"New tab page experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype_0","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype_1","displayName":"Office 365 feed experience","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_alternateerrorpagesenabled","displayName":"Suggest similar pages when a webpage can’t be found (User)","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\r\n\r\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\r\n\r\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Suggest similar pages when a webpage can’t be found** toggle, which the user can switch on or off. Note that if you have enable this policy (AlternateErrorPagesEnabled), the Suggest similar pages when a webpage can’t be found setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the Suggest similar pages when a webpage can’t be found setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_alternateerrorpagesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_alternateerrorpagesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_dnsinterceptionchecksenabled","displayName":"DNS interception checks enabled (User)","description":"This policy configures a local switch that can be used to disable DNS interception checks. These checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\r\n\r\nThis detection might not be necessary in an enterprise environment where the network configuration is known. It can be disabled to avoid additional DNS and HTTP traffic on start-up and each DNS configuration change.\r\n\r\nIf you enable or don’t set this policy, the DNS interception checks are performed.\r\n\r\nIf you disable this policy, DNS interception checks aren’t performed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_dnsinterceptionchecksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_dnsinterceptionchecksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_hidefirstrunexperience","displayName":"Hide the First-run experience and splash screen (User)","description":"If you enable this policy, the First-run experience and the splash screen will not be shown to users when they run Microsoft Edge for the first time.\r\n\r\nFor the configuration options shown in the First Run Experience, the browser will default to the following:\r\n\r\n-On the New Tab Page, the feed type will be set to MSN News and the layout to Inspirational.\r\n\r\n-The user will still be automatically signed into Microsoft Edge if the Windows account is of Azure AD or MSA type.\r\n\r\n-Sync will not be enabled by default and users will be able to turn on sync from the sync settings.\r\n\r\nIf you disable or don't configure this policy, the First-run experience and the Splash screen will be shown.\r\n\r\nNote: The specific configuration options shown to the user in the First Run Experience, can also be managed by using other specific policies. You can use the HideFirstRunExperience policy in combination with these policies to configure a specific browser experience on your managed devices. Some of these other policies are:\r\n\r\n-'AutoImportAtFirstRun' (Automatically import another browser's data and settings at first run)\r\n\r\n-'NewTabPageLocation' (Configure the new tab page URL)\r\n\r\n-'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience)\r\n\r\n-'SyncDisabled' (Disable synchronization of data using Microsoft sync services)\r\n\r\n-'BrowserSignin' (Browser sign-in settings)\r\n\r\n-'NonRemovableProfileEnabled' (Configure whether a user always has a default profile automatically signed in with their work or school account)","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_hidefirstrunexperience_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_hidefirstrunexperience_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_paymentmethodqueryenabled","displayName":"Allow websites to query for available payment methods (User)","description":"Allows you to set whether websites can check if the user has payment methods saved.\r\n\r\nIf you disable this policy, websites that use PaymentRequest.canMakePayment or PaymentRequest.hasEnrolledInstrument API will be informed that no payment methods are available.\r\n\r\nIf you enable this policy or don't set this policy, websites can check if the user has payment methods saved.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_paymentmethodqueryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_paymentmethodqueryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_personalizationreportingenabled","displayName":"Allow personalization of ads, search and news by sending browsing history to Microsoft (User)","description":"This policy prevents Microsoft from collecting a user's Microsoft Edge browsing history to be used for personalizing advertising, search, news and other Microsoft services.\r\n\r\nThis setting is only available for users with a Microsoft account. This setting is not available for child accounts or enterprise accounts.\r\n\r\nIf you disable this policy, users can't change or override the setting. If this policy is enabled or not configured, Microsoft Edge will default to the user’s preference.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_personalizationreportingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_personalizationreportingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_pinningwizardallowed","displayName":"Allow Pin to taskbar wizard (User)","description":"Microsoft Edge uses the Pin to taskbar wizard to help users pin suggested sites to the taskbar. The Pin to taskbar wizard feature is enabled by default and accessible to the user through the Settings and more menu.\r\n\r\nIf you enable this policy or don't configure it, users can call the Pin to taskbar wizard from the Settings and More menu. The wizard can also be called via a protocol launch.\r\n\r\nIf you disable this policy, the Pin to taskbar wizard is disabled in the menu and cannot be called via a protocol launch.\r\n\r\nUser settings to enable or disable the Pin to taskbar wizard aren't available.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_pinningwizardallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_pinningwizardallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended","displayName":"Suggest similar pages when a webpage can’t be found (User)","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\r\n\r\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\r\n\r\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Suggest similar pages when a webpage can’t be found** toggle, which the user can switch on or off. Note that if you have enable this policy (AlternateErrorPagesEnabled), the Suggest similar pages when a webpage can’t be found setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the Suggest similar pages when a webpage can’t be found setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenpuaenabled_recommended","displayName":"Configure Microsoft Defender SmartScreen to block potentially unwanted apps (User)","description":"This policy setting lets you configure whether to turn on blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default.\r\n\r\nIf you enable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenpuaenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenpuaenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb","displayName":"Set limit on megabytes of memory a single Microsoft Edge instance can use. (User)","description":"Configures the amount of memory that a single Microsoft Edge instance can use before tabs start getting discarded to save memory. The memory used by the tab will be freed and the tab will have to be reloaded when switched to.\r\n\r\nIf you enable this policy, the browser will start to discard tabs to save memory once the limitation is exceeded. However, there is no guarantee that the browser is always running under the limit. Any value under 1024 will be rounded up to 1024.\r\n\r\nIf you don't set this policy, the browser will only attempt to save memory when it has detected that the amount of physical memory on its machine is low.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb_totalmemorylimitmb","displayName":"Set memory limit for Microsoft Edge instances: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist","displayName":"Configure list of force-installed Web Apps (User)","description":"Specifies a list of websites that are installed silently, without user interaction, and which can't be uninstalled or disabled by the user.\r\n\r\nEach list item of the policy is an object with the following members:\r\n - \"url\", which is mandatory. \"url\" should be the URL of the web app to install.\r\n\r\nValues for the optional members are:\r\n - \"launch_container\" should be either \"window\" or \"tab\" to indicate how the Web App will be opened after it's installed.\r\n - \"create_desktop_shortcut\" should be true if a desktop shortcut should be created on Windows.\r\n\r\nIf \"default_launch_container\" is omitted, the app will open in a tab by default. Regardless of the value of \"default_launch_container\", users can change which container the app will open in. If \"create_desktop_shortcuts\" is omitted, no desktop shortcuts will be created.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.contoso.com/maps\", \r\n \"create_desktop_shortcut\": true, \r\n \"default_launch_container\": \"window\"\r\n }, \r\n {\r\n \"url\": \"https://app.contoso.edu\", \r\n \"default_launch_container\": \"tab\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist_webappinstallforcelist","displayName":"URLs for Web Apps to be silently installed. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84. (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThe Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and have been disabled by default starting in M80. This policy allows these features to be selectively re-enabled until M84.\r\n\r\n If you set this policy is set to True, the Web Components v0 features will be enabled for all sites.\r\n\r\n If you set this policy to False or don't set this policy, the Web Components v0 features will be disabled by default, starting in M80.\r\n\r\n This policy will be removed after Microsoft Edge 84.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webcomponentsv0enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webcomponentsv0enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webrtclocalipsallowedurls","displayName":"Manage exposure of local IP addressess by WebRTC (User)","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*contoso.com*\") for which local IP address should be exposed by WebRTC.\r\n\r\nIf you enable this policy and set a list of origins (URLs) or hostname patterns, when edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will expose the local IP address for cases that match patterns in the list.\r\n\r\nIf you disable or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will not expose local IP addresses. The local IP address is concealed with an mDNS hostname.\r\n\r\nIf you enable, disable, or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, WebRTC will expose local IP addresses.\r\n\r\nPlease note that this policy weakens the protection of local IP addresses that might be needed by administrators.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n*contoso.com*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webrtclocalipsallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webrtclocalipsallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webrtclocalipsallowedurls_webrtclocalipsallowedurlsdesc","displayName":"Manage exposure of local IP addressess by WebRTC (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (User)","description":"Allows you to set whether users can add exceptions to allow mixed content for specific sites.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'InsecureContentAllowedForUrls' (Allow insecure content on specified sites) and 'InsecureContentBlockedForUrls' (Block insecure content on specified sites) policies.\r\n\r\nIf this policy isn't set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.\r\n\r\n* 2 = Do not allow any site to load blockable mixed content\r\n\r\n* 3 = Allow users to add exceptions to allow blockable mixed content","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_2","displayName":"Do not allow any site to load blockable mixed content","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_3","displayName":"Allow users to add exceptions to allow blockable mixed content","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentallowedforurls","displayName":"Allow insecure content on specified sites (User)","description":"Create a list of URL patterns to specify sites that can display insecure mixed content (that is, HTTP content on HTTPS sites).\r\n\r\nIf you don't configure this policy, blockable mixed content will be blocked and optionally blockable mixed content will be upgraded. However, users will be allowed to set exceptions to allow insecure mixed content for specific sites.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentallowedforurls_insecurecontentallowedforurlsdesc","displayName":"Allow insecure content on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls","displayName":"Block insecure content on specified sites (User)","description":"Create a list of URL patterns to specify sites that aren't allowed to display blockable (i.e. active) mixed content (that is, HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled.\r\n\r\nIf you don't configure this policy, blockable mixed content will be blocked and optionally blockable mixed content will be upgraded. However, users will be allowed to set exceptions to allow insecure mixed content for specific sites.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls_insecurecontentblockedforurlsdesc","displayName":"Block insecure content on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled","displayName":"Enable default legacy SameSite cookie behavior setting (obsolete) (User)","description":"Lets you revert all cookies to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", and removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute.\r\n\r\nYou can set the following values for this policy:\r\n\r\n* 1 = Revert to legacy SameSite behavior for cookies on all sites\r\n\r\n* 2 = Use SameSite-by-default behavior for cookies on all sites\r\n\r\nIf you don't set this policy, the default behavior for cookies that don't specify a SameSite attribute will depend on other configuration sources for the SameSite-by-default feature. This feature might be set by a field trial or by enabling the same-site-by-default-cookies flag in edge://flags.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled","displayName":"Enable default legacy SameSite cookie behavior setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_1","displayName":"Revert to legacy SameSite behavior for cookies on all sites","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_2","displayName":"Use SameSite-by-default behavior for cookies on all sites","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist","displayName":"Revert to legacy SameSite behavior for cookies on specified sites (obsolete) (User)","description":"Cookies set for domains match specified patterns will revert to legacy SameSite behavior.\r\n\r\nReverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", and removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute.\r\n\r\nIf you don't set this policy, the global default value will be used. The global default will also be used for cookies on domains not covered by the patterns you specify.\r\n\r\nThe global default value can be configured using the 'LegacySameSiteCookieBehaviorEnabled' (Enable default legacy SameSite cookie behavior setting) policy. If 'LegacySameSiteCookieBehaviorEnabled' is unset, the global default value falls back to other configuration sources.\r\n\r\nNote that patterns you list in this policy are treated as domains, not URLs, so you should not specify a scheme or port.\r\n\r\nExample value:\r\n\r\nwww.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_legacysamesitecookiebehaviorenabledfordomainlistdesc","displayName":"Revert to legacy SameSite behavior for cookies on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled","displayName":"Configure Microsoft Defender SmartScreen to block potentially unwanted apps (User)","description":"This policy setting lets you configure whether to turn on blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default.\r\n\r\nIf you enable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_addressbarmicrosoftsearchinbingproviderenabled","displayName":"Enable Microsoft Search in Bing suggestions in the address bar (User)","description":"Enables the display of relevant Microsoft Search in Bing suggestions in the address bar's suggestion list when the user types a search string in the address bar. If you enable or don't configure this policy, users can see internal results powered by Microsoft Search in Bing in the Microsoft Edge address bar suggestion list. To see the Microsoft Search in Bing results, the user must be signed into Microsoft Edge with their Azure AD account for that organization.\r\nIf you disable this policy, users can't see internal results in the Microsoft Edge address bar suggestion list.\r\nIf you have enabled the set of policies which forces a default search provider ('DefaultSearchProviderEnabled' (Enable the default search provider), 'DefaultSearchProviderName' (Default search provider name) and 'DefaultSearchProviderSearchURL' (Default search provider search URL)), and the search provider specified is not Bing, then this policy is not applicable and there will be no Microsoft Search in Bing suggestions in the address bar's suggestion list.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_addressbarmicrosoftsearchinbingproviderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_addressbarmicrosoftsearchinbingproviderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for InPrivate and Guest profiles (User)","description":"Configure this policy to allow/disallow ambient authentication for InPrivate and Guest profiles in Microsoft Edge.\r\n\r\nAmbient Authentication is http authentication with default credentials when explicit credentials aren't provided via NTLM/Kerberos/Negotiate challenge/response schemes.\r\n\r\nIf you set the policy to RegularOnly (value 0), it allows ambient authentication for Regular sessions only. InPrivate and Guest sessions won't be allowed to ambiently authenticate.\r\n\r\nIf you set the policy to InPrivateAndRegular (value 1), it allows ambient authentication for InPrivate and Regular sessions. Guest sessions won't be allowed to ambiently authenticate.\r\n\r\nIf you set the policy to GuestAndRegular (value 2), it allows ambient authentication for Guest and Regular sessions. InPrivate sessions won't be allowed to ambiently authenticate\r\n\r\nIf you set the policy to All (value 3), it allows ambient authentication for all sessions.\r\n\r\nNote that ambient authentication is always allowed on regular profiles.\r\n\r\nIn Microsoft Edge version 81 and later, if the policy is left not set, ambient authentication will be enabled in regular sessions only.\r\n\r\n* 0 = Enable ambient authentication in regular sessions only\r\n\r\n* 1 = Enable ambient authentication in InPrivate and regular sessions\r\n\r\n* 2 = Enable ambient authentication in guest and regular sessions\r\n\r\n* 3 = Enable ambient authentication in regular, InPrivate and guest sessions","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for InPrivate and Guest profiles (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_0","displayName":"Enable ambient authentication in regular sessions only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_1","displayName":"Enable ambient authentication in InPrivate and regular sessions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_2","displayName":"Enable ambient authentication in guest and regular sessions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_3","displayName":"Enable ambient authentication in regular, InPrivate and guest sessions","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_audiosandboxenabled","displayName":"Allow the audio sandbox to run (User)","description":"This policy controls the audio process sandbox.\r\n\r\nIf you enable this policy, the audio process will run sandboxed.\r\n\r\nIf you disable this policy, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\r\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\r\n\r\nIf you don't configure this policy, the default configuration for the audio sandbox will be used, which might differ based on the platform.\r\n\r\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_audiosandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_audiosandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin","displayName":"Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account (User)","description":"Enable the use of Active Directory accounts for automatic sign in if your users' machines are Domain Joined and your environment is not hybrid joined. If you want users automatically signed in with their Azure Active Directory accounts instead, please Azure AD join (See https://go.microsoft.com/fwlink/?linkid=2118197 for more information) or hybrid join (See https://go.microsoft.com/fwlink/?linkid=2118365 for more information) your environment.\r\n\r\nIf you have configured the 'BrowserSignin' (Browser sign-in settings) policy to disabled, this policy will not take any effect.\r\n\r\nIf you enable this policy and set it to \"Sign in and make domain account non-removable\", Microsoft Edge will automatically sign in users that are on domain joined machines using their Active Directory accounts.\r\n\r\nIf you set this policy to \"Disabled\" or don't set it, Microsoft Edge will not automatically sign in users that are on domain joined machines with Active Directory accounts.\r\n\r\n* 0 = Disabled\r\n\r\n* 1 = Sign in and make domain account non-removable","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_configureonpremisesaccountautosignin","displayName":"Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_configureonpremisesaccountautosignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_configureonpremisesaccountautosignin_1","displayName":"Sign in and make domain account non-removable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_forcelegacydefaultreferrerpolicy","displayName":"Use a default referrer policy of no-referrer-when-downgrade. (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis enterprise policy is for short-term adaptation and will be removed in M83.\r\n\r\nMicrosoft Edge’s default referrer policy is being strengthened from its current value of no-referrer-when-downgrade to the more secure strict-origin-when-cross-origin through a gradual rollout targeting M80 stable.\r\n\r\nBefore the rollout, this enterprise policy will have no effect. After the rollout, when this enterprise policy is enabled, Microsoft Edge’s default referrer policy will be set to its pre-M80 value of no-referrer-when-downgrade.\r\n\r\nThis enterprise policy is disabled by default","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_forcelegacydefaultreferrerpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_forcelegacydefaultreferrerpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache (User)","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\r\n\r\nIf you disable or don’t set this policy, the browser will use the default behavior of cross-site auth, which as of version 80, will be to scope HTTP server authentication credentials by top-level site. So, if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites.\r\n\r\nIf you enable this policy HTTP auth credentials entered in the context of one site will automatically be used in the context of another site.\r\n\r\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\r\n\r\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_globallyscopehttpauthcacheenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_globallyscopehttpauthcacheenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importcookies","displayName":"Allow importing of Cookies (User)","description":"Allows users to import Cookies from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Cookies aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Cookies are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importcookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importcookies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importextensions","displayName":"Allow importing of extensions (User)","description":"Allows users to import extensions from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts","displayName":"Allow importing of shortcuts (User)","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Shortcuts aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Shortcuts are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect","displayName":"Specify how \"in-page\" navigations to unconfigured sites behave when started from Internet Explorer mode pages (User)","description":"An \"in-page\" navigation is started from a link, a script, or a form on the current page. It can also be a server-side redirect of a previous \"in-page\" navigation attempt. Conversely, a user can start a navigation that isn't \"in-page\" that's independent of the current page in several ways by using the browser controls. For example, using the address bar, the back button, or a favorite link.\r\n\r\nThis setting lets you specify whether navigations from pages loaded in Internet Explorer mode to unconfigured sites (that are not configured in the Enterprise Mode Site List) switch back to Microsoft Edge or remain in Internet Explorer mode.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to \"Internet Explorer mode\" (1)\r\nand\r\n'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry.\r\n\r\nIf you disable or don’t configure this policy, only sites configured to open in Internet Explorer mode will open in that mode. Any site not configured to open in Internet Explorer mode will be redirected back to Microsoft Edge.\r\n\r\nIf you set this policy to Default (value 0), only sites configured to open in Internet Explorer mode will open in that mode. Any site not configured to open in Internet Explorer mode will be redirected back to Microsoft Edge.\r\n\r\nIf you set this policy to AutomaticNavigationsOnly (value 1), you get the default experience except that all automatic navigations (such as 302 redirects) to unconfigured sites will be kept in Internet Explorer mode.\r\n\r\nIf you set this policy to AllInPageNavigations (value 2), all navigations from pages loaded in IE mode to unconfigured sites are kept in Internet Explorer mode (Least Recommended).\r\n\r\nIf you enable this policy, you can choose one of the following navigation options:\r\n\r\n* 0 = Default\r\n\r\n* 1 = Keep only automatic navigations in Internet Explorer mode\r\n\r\n* 2 = Keep all in-page navigations in Internet Explorer mode\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2105106","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect","displayName":"Specify how \"in-page\" navigations to unconfigured sites behave when started from Internet Explorer mode pages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect_1","displayName":"Keep only automatic navigations in Internet Explorer mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect_2","displayName":"Keep all in-page navigations in Internet Explorer mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importcookies_recommended","displayName":"Allow importing of Cookies (User)","description":"Allows users to import Cookies from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Cookies aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Cookies are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importcookies_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importcookies_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importextensions_recommended","displayName":"Allow importing of extensions (User)","description":"Allows users to import extensions from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importextensions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importextensions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importshortcuts_recommended","displayName":"Allow importing of shortcuts (User)","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Shortcuts aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Shortcuts are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importshortcuts_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importshortcuts_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_strictermixedcontenttreatmentenabled","displayName":"Enable stricter treatment for mixed content (User)","description":"This policy controls the treatment for mixed content (HTTP content in HTTPS sites) in the browser.\r\n\r\nIf you set this policy to true or not set, audio and video mixed content will be automatically upgraded to HTTPS (that is, the URL will be rewritten as HTTPS, without a fallback if the resource isn’t available over HTTPS) and a 'Not Secure' warning will be shown in the URL bar for image mixed content.\r\n\r\nIf you set the policy to false, auto upgrades will be disabled for audio and video, and no warning will be shown for images.\r\n\r\nThis policy does not affect other types of mixed content other than audio, video, and images.\r\n\r\nThis policy will no longer take effect starting in Microsoft Edge 84.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_strictermixedcontenttreatmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_strictermixedcontenttreatmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors. (User)","description":"This policy controls a security feature in TLS 1.3 that protects connections against downgrade attacks. It is backwards-compatible and will not affect connections to compliant TLS 1.2 servers or proxies. However, older versions of some TLS-intercepting proxies have an implementation flaw which causes them to be incompatible.\r\n\r\nIf you enable this policy or don't set it, Microsoft Edge will enable these security protections for all connections.\r\n\r\nIf you disable this policy, Microsoft Edge will disable these security protections for connections authenticated with locally-installed CA certificates. These protections are always enabled for connections authenticated with publicly-trusted CA certificates.\r\n\r\nThis policy may be used to test for any affected proxies and upgrade them. Affected proxies are expected to fail connections with an error code of ERR_TLS13_DOWNGRADE_DETECTED. A later version of Microsoft Edge will enable this option by default.\r\n\r\nAfter it is enabled by default, administrators who need more time to upgrade affected proxies may use this policy to temporarily disable this security feature. This policy will be removed after version 85.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81identitydiff~policy~microsoft_edge_forcecertificatepromptsonmultiplematches","displayName":"Configure whether Microsoft Edge should automatically select a certificate when there are multiple certificate matches for a site configured with \"AutoSelectCertificateForUrls\" (User)","description":"Toggles whether users are prompted to select a certificate if there are multiple certificates available and a site is configured with 'AutoSelectCertificateForUrls' (Automatically select client certificates for these sites). If you don't configure 'AutoSelectCertificateForUrls' for a site, the user will always be prompted to select a certificate.\r\n\r\nIf you set this policy to True, Microsoft Edge will prompt a user to select a certificate for sites on the list defined in 'AutoSelectCertificateForUrls' if and only if there is more than one certificate.\r\n\r\nIf you set this policy to False or don't configure it, Microsoft Edge will automatically select a certificate even if there are multiple matches for a certificate. The user will not be prompted to select a certificate for sites on the list defined in 'AutoSelectCertificateForUrls'.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81identitydiff~policy~microsoft_edge_forcecertificatepromptsonmultiplematches_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81identitydiff~policy~microsoft_edge_forcecertificatepromptsonmultiplematches_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowsurfgame","displayName":"Allow surf game (User)","description":"If you disable this policy, users won't be able to play the surf game when the device is offline or if the user navigates to edge://surf.\r\n\r\nIf you enable or don't configure this policy, users can play the surf game.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowsurfgame_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowsurfgame_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls","displayName":"Configure the list of sites for which Microsoft Edge will attempt to establish a Token Binding with. (User)","description":"Configure the list of URL patterns for sites that the browser will attempt to perform the Token Binding protocol with.\r\nFor the domains on this list, the browser will send the Token Binding ClientHello in the TLS handshake (See https://tools.ietf.org/html/rfc8472).\r\nIf the server responds with a valid ServerHello response, the browser will create and send Token Binding messages on subsequent https requests. See https://tools.ietf.org/html/rfc8471 for more info.\r\n\r\nIf this list is empty, Token Binding will be disabled.\r\n\r\nThis policy is only available on Windows 10 devices with Virtual Secure Mode capability.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\n[*.]mydomain2.com\r\n[*.].mydomain2.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_allowtokenbindingforurlsdesc","displayName":"Configure the list of sites for which Microsoft Edge will attempt to establish a Token Binding with. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_bingadssuppression","displayName":"Block all ads on Bing search results (User)","description":"Enables an ad-free search experience on Bing.com\r\n\r\nIf you enable this policy, then a user can search on bing.com and have an ad-free search experience. At the same time, the SafeSearch setting will be set to 'Strict' and can't be changed by the user.\r\n\r\nIf you don't configure this policy, then the default experience will have ads in the search results on bing.com. SafeSearch will be set to 'Moderate' by default and can be changed by the user.\r\n\r\nThis policy is only available for K-12 SKUs that are identified as EDU tenants by Microsoft.\r\n\r\nPlease refer to https://go.microsoft.com/fwlink/?linkid=2119711 to learn more about this policy or if the following scenarios apply to you:\r\n\r\n* You have an EDU tenant, but the policy doesn't work.\r\n\r\n* You had your IP whitelisted for having an ad free search experience.\r\n\r\n* You were experiencing an ad-free search experience on Microsoft Edge Legacy and want to upgrade to the new version of Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_bingadssuppression_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_bingadssuppression_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_clearcachedimagesandfilesonexit","displayName":"Clear cached images and files when Microsoft Edge closes (User)","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\r\n\r\nIf you enable this policy, cached images and files will be deleted each time Microsoft Edge closes.\r\n\r\nIf you disable this policy, users cannot configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\r\n\r\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\r\n\r\nIf you disable this policy, don't enable the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) policy, because they both deal with deleting data. If you configure both, the 'ClearBrowsingDataOnExit' policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_clearcachedimagesandfilesonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_clearcachedimagesandfilesonexit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare","displayName":"Configure the Share experience (User)","description":"If you set this policy to 'ShareAllowed' (0, the default), users will be able to access the Windows 10 Share experience from the Settings and More Menu in Microsoft Edge to share with other apps on the system.\r\n\r\nIf you set this policy to 'ShareDisallowed' (1), users won't be able to access the Windows 10 Share experience. If the Share button is on the toolbar, it will also be hidden.\r\n\r\n* 0 = Allow using the Share experience\r\n\r\n* 1 = Don't allow using the Share experience\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_configureshare","displayName":"Configure the Share experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_configureshare_0","displayName":"Allow using the Share experience","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_configureshare_1","displayName":"Don't allow using the Share experience","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_deletedataonmigration","displayName":"Delete old browser data on migration (User)","description":"This policy determines whether user browsing data from Microsoft Edge Legacy will be deleted after migrating to the Microsoft Edge version 81 or later.\r\n\r\nIf you set this policy to \"Enabled\", all browsing data from Microsoft Edge Legacy after migrating to the Microsoft Edge version 81 or later will be deleted. This policy must be set before migrating to the Microsoft Edge version 81 or later to have any effect on existing browsing data.\r\n\r\nIf you set this policy to \"Disabled\", or the policy is not configured, user browsing data isn't deleted after migrating to the Microsoft Edge version 83 or later.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_deletedataonmigration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_deletedataonmigration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode","displayName":"Control the mode of DNS-over-HTTPS (User)","description":"Control the mode of the DNS-over-HTTPS resolver. Note that this policy will only set the default mode for each query. The mode can be overridden for special types of queries such as requests to resolve a DNS-over-HTTPS server hostname.\r\n\r\nThe \"off\" mode will disable DNS-over-HTTPS.\r\n\r\nThe \"automatic\" mode will send DNS-over-HTTPS queries first if a DNS-over-HTTPS server is available and may fallback to sending insecure queries on error.\r\n\r\nThe \"secure\" mode will only send DNS-over-HTTPS queries and will fail to resolve on error.\r\n\r\nIf you don't configure this policy, the browser might send DNS-over-HTTPS requests to a resolver associated with the user's configured system resolver.\r\n\r\nExample value: off","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode","displayName":"Control the mode of DNS-over-HTTPS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_off","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_automatic","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_secure","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver (User)","description":"The URI template of the desired DNS-over-HTTPS resolver. To specify multiple DNS-over-HTTPS resolvers, separate the corresponding URI templates with spaces.\r\n\r\nIf you set 'DnsOverHttpsMode' (Control the mode of DNS-over-HTTPS) to \"secure\" then this policy must be set and cannot be empty.\r\n\r\nIf you set 'DnsOverHttpsMode' to \"automatic\" and this policy is set then the URI templates specified will be used. If you don't set this policy, then hardcoded mappings will be used to attempt to upgrade the user's current DNS resolver to a DoH resolver operated by the same provider.\r\n\r\nIf the URI template contains a dns variable, requests to the resolver will use GET; otherwise requests will use POST.\r\n\r\nIncorrectly formatted templates will be ignored.\r\n\r\nExample value: https://dns.example.net/dns-query{?dns}","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpstemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpstemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpstemplates_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_familysafetysettingsenabled","displayName":"Allow users to configure Family safety (User)","description":"This policy disables and completely hides the Family safety page in Settings. Navigation to edge://settings/familysafety will also be blocked. The Family safety page describes what features are available for family groups and how to join a family group. Learn more about family safety here: (https://go.microsoft.com/fwlink/?linkid=2098432).\r\n\r\nIf you enable this policy or don't configure it, the Family safety page will be shown.\r\n\r\nIf you disable this policy, the Family safety page will not be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_familysafetysettingsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_familysafetysettingsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_localprovidersenabled","displayName":"Allow suggestions from local providers (User)","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\r\n\r\nIf you enable this policy, suggestions from local providers are used.\r\n\r\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions will not appear.\r\n\r\nIf you do not configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\r\n\r\nNote that some features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the 'SavingBrowserHistoryDisabled' (Disable saving browser history) policy.\r\n\r\nThis policy requires a browser restart to finish applying.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_localprovidersenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_localprovidersenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_recommended_clearcachedimagesandfilesonexit_recommended","displayName":"Clear cached images and files when Microsoft Edge closes (User)","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\r\n\r\nIf you enable this policy, cached images and files will be deleted each time Microsoft Edge closes.\r\n\r\nIf you disable this policy, users cannot configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\r\n\r\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\r\n\r\nIf you disable this policy, don't enable the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) policy, because they both deal with deleting data. If you configure both, the 'ClearBrowsingDataOnExit' policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_recommended_clearcachedimagesandfilesonexit_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_recommended_clearcachedimagesandfilesonexit_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_recommended_localprovidersenabled_recommended","displayName":"Allow suggestions from local providers (User)","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\r\n\r\nIf you enable this policy, suggestions from local providers are used.\r\n\r\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions will not appear.\r\n\r\nIf you do not configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\r\n\r\nNote that some features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the 'SavingBrowserHistoryDisabled' (Disable saving browser history) policy.\r\n\r\nThis policy requires a browser restart to finish applying.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_recommended_localprovidersenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_recommended_localprovidersenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_screencaptureallowed","displayName":"Allow or deny screen capture (User)","description":"If you enable this policy, or don't configure this policy, a web page can use screen-share APIs (for example, getDisplayMedia() or the Desktop Capture extension API) for a screen capture.\r\nIf you disable this policy, calls to screen-share APIs will fail. For example, if you're using a web-based online meeting, video or screen sharing will not work. However, this policy is not considered\r\n(and a site will be allowed to use screen-share APIs) if the site matches an origin pattern in any of the following policies:\r\n'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins),\r\n'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins),\r\n'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins),\r\n'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_screencaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_screencaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments (User)","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\r\n​\r\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL will be enabled.​\r\n\r\nIf you disable this policy, web page scrolling to specific text fragments via a URL will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_synctypeslistdisabled","displayName":"Configure the list of types that are excluded from synchronization (User)","description":"If you enable this policy all the specified data types will be excluded from synchronization. This policy can be used to limit the type of data uploaded to the Microsoft Edge synchronization service.\r\n\r\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", and “collections”. Note that these data type names are case sensitive.\r\n\r\nUsers will not be able to override the disabled data types.\r\n\r\nExample value:\r\n\r\nfavorites","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_synctypeslistdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_synctypeslistdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_synctypeslistdisabled_synctypeslistdisableddesc","displayName":"Configure the list of types that are excluded from synchronization (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_appcacheforceenabled","displayName":"Allows the AppCache feature to be re-enabled, even if it's turned off by default (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 96.\r\n\r\nSupport for AppCache and this policy was removed from Microsoft Edge starting in version 97.\r\n\r\nIf you set this policy to true, the AppCache is enabled, even when AppCache in Microsoft Edge is not available by default.\r\n\r\nIf you set this policy to false, or don't set it, AppCache will follow Microsoft Edge's defaults.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_appcacheforceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_appcacheforceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload","displayName":"Require that the Enterprise Mode Site List is available before tab navigation (User)","description":"Lets you specify whether Microsoft Edge tabs wait to navigate until the browser has downloaded the initial Enterprise Mode Site List. This setting is intended for the scenario where the browser home page should load in Internet Explorer mode, and it is important that is does so on browser first run after IE mode is enabled. If this scenario does not exist, we recommend not enabling this setting because it can negatively impact the performance of loading the home page. The setting only applies when Microsoft Edge does not have a cached Enterprise Mode Site List, such as on browser first run after IE mode is enabled.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to \"Internet Explorer mode\" (1)\r\nand\r\n'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry.\r\n\r\nThe timeout behavior of this policy can be configured with the 'NavigationDelayForInitialSiteListDownloadTimeout' (Set a timeout for delay of tab navigation for the Enterprise Mode Site List) policy.\r\n\r\nIf you set this policy to 1, when Microsoft Edge does not have a cached version of the Enterprise Mode Site List, tabs delay navigating until the browser has downloaded the site list. Sites configured to open in Internet Explorer mode by the site list will load in Internet Explorer mode, even during the initial navigation of the browser. Sites that cannot possibly be configured to open in Internet Explorer, such as any site with a scheme other than http:, https:, file:, or ftp: do not delay navigating and load immediately in Edge mode.\r\n\r\nIf you set this policy to 0 or don't configure it, when Microsoft Edge does not have a cached version of the Enterprise Mode Site List, tabs will navigate immediately, and not wait for the browser to download the Enterprise Mode Site List. Sites configured to open in Internet Explorer mode by the site list will open in Microsoft Edge mode until the browser has finished downloading the Enterprise Mode Site List.\r\n\r\n* 0 = None\r\n\r\n* 1 = All eligible navigations","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload","displayName":"Require that the Enterprise Mode Site List is available before tab navigation (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload_0","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload_1","displayName":"All eligible navigations","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection","displayName":"Configure enhanced hang detection for Internet Explorer mode (User)","description":"Enhanced hang detection is a more granular approach to detecting hung webpages in Internet Explorer mode than what standalone Internet Explorer uses. When a hung webpage is detected, the browser will apply a mitigation to prevent the rest of the browser from hanging.\r\n\r\nThis setting allows you to configure the use of enhanced hang detection in case you run into incompatible issues with any of your websites. We recommend disabling this policy only if you see notifications such as \"(website) is not responding\" in Internet Explorer mode but not in standalone Internet Explorer.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to \"Internet Explorer mode\" (1)\r\nand\r\n'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry.\r\n\r\nIf you set this policy to 'Enabled' (1) or don’t configure it, websites running in Internet Explorer mode will use enhanced hang detection.\r\n\r\nIf you set this policy to 'Disabled' (0), enhanced hang detection is disabled, and users will get the basic Internet Explorer hang detection behavior.\r\n\r\n* 0 = Enhanced hang detection disabled\r\n\r\n* 1 = Enhanced hang detection enabled\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_internetexplorerintegrationenhancedhangdetection","displayName":"Configure enhanced hang detection for Internet Explorer mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_internetexplorerintegrationenhancedhangdetection_0","displayName":"Enhanced hang detection disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_internetexplorerintegrationenhancedhangdetection_1","displayName":"Enhanced hang detection enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_nativewindowocclusionenabled","displayName":"Enable Hiding of Native Windows (User)","description":"Enables hiding of native windows in Microsoft Edge.\r\n\r\nIf you enable this setting, to reduce CPU and power consumption Microsoft Edge will detect when a window is covered by other windows, and will suspend work painting pixels.\r\n\r\nIf you disable this setting Microsoft Edge will not detect when a window is covered by other windows.\r\n\r\nIf this policy is left not set, window hiding detection will be enabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_nativewindowocclusionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_nativewindowocclusionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_navigationdelayforinitialsitelistdownloadtimeout","displayName":"Set a timeout for delay of tab navigation for the Enterprise Mode Site List (User)","description":"Allows you to set a timeout, in seconds, for Microsoft Edge tabs waiting to navigate until the browser has downloaded the initial Enterprise Mode Site List.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to \"Internet Explorer mode\" (1)\r\nand\r\n'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry\r\nand\r\n'DelayNavigationsForInitialSiteListDownload' (Require that the Enterprise Mode Site List is available before tab navigation) is set to \"All eligible navigations\" (1).\r\n\r\nTabs will not wait longer than this timeout for the Enterprise Mode Site List to download. If the browser has not finished downloading the Enterprise Mode Site List when the timeout expires, Microsoft Edge tabs will continue navigating anyway. The value of the timeout should be no greater than 20 seconds and no fewer than 1 second.\r\n\r\nIf you set the timeout in this policy to a value greater than the default of 2 seconds, an information bar is shown to the user after 2 seconds. The information bar contains a button that allows the user to quit waiting for the Enterprise Mode Site List download to complete.\r\n\r\nIf you don't configure this policy, the default timeout of 2 seconds is used. This default is subject to change in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_navigationdelayforinitialsitelistdownloadtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_navigationdelayforinitialsitelistdownloadtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_navigationdelayforinitialsitelistdownloadtimeout_navigationdelayforinitialsitelistdownloadtimeout","displayName":"Set a timeout for delay of tab navigation for the Enterprise Mode Site List: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended","displayName":"Manage Search Engines (User)","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine.\r\nYou do not need to specify the encoding. Starting in Microsoft Edge 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge 80.\r\n\r\nStarting in Microsoft Edge 83, you can enable search engine discovery with the allow_search_engine_discovery optional parameter. This parameter must be the first item in the list. If allow_search_engine_discovery is not specified, search engine discovery will be disabled by default. Starting in Microsoft Edge 84, you can set this policy as a recommended policy to allow search provider discovery. You do not need to add the allow_search_engine_discovery optional parameter.\r\n\r\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\r\n\r\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\r\n\r\nIf the 'DefaultSearchProviderSearchURL' (Default search provider search URL) policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allow_search_engine_discovery\": true\r\n }, \r\n {\r\n \"is_default\": true, \r\n \"suggest_url\": \"https://www.example1.com/qbox?query={searchTerms}\", \r\n \"search_url\": \"https://www.example1.com/search?q={searchTerms}\", \r\n \"name\": \"Example1\", \r\n \"keyword\": \"example1.com\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example2.com/qbox?query={searchTerms}\", \r\n \"image_search_url\": \"https://www.example2.com/images/detail/search?iss=sbiupload\", \r\n \"name\": \"Example2\", \r\n \"keyword\": \"example2.com\", \r\n \"image_search_post_params\": \"content={imageThumbnail},url={imageURL},sbisrc={SearchSource}\", \r\n \"search_url\": \"https://www.example2.com/search?q={searchTerms}\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example3.com/qbox?query={searchTerms}\", \r\n \"search_url\": \"https://www.example3.com/search?q={searchTerms}\", \r\n \"name\": \"Example3\", \r\n \"keyword\": \"example3.com\", \r\n \"encoding\": \"UTF-8\", \r\n \"image_search_url\": \"https://www.example3.com/images/detail/search?iss=sbiupload\"\r\n }, \r\n {\r\n \"search_url\": \"https://www.example4.com/search?q={searchTerms}\", \r\n \"name\": \"Example4\", \r\n \"keyword\": \"example4.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended_managedsearchengines","displayName":"Manage Search Engines (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended","displayName":"Enable the default search provider (User)","description":"Enables the ability to use a default search provider.\r\n\r\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\r\n\r\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider.\r\n\r\nIf you disable this policy, the user can't search from the address bar.\r\n\r\nIf you enable or disable this policy, users can't change or override it.\r\n\r\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy.","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended","displayName":"Default search provider encodings (User)","description":"Specify the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They are tried in the order provided.\r\n\r\nThis policy is optional. If not configured, the default, UTF-8, is used.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value:\r\n\r\nUTF-8\r\nUTF-16\r\nGB2312\r\nISO-8859-1","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended","displayName":"Specifies the search-by-image feature for the default search provider (User)","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\r\n\r\nThis policy is optional. If you don't configure it, image search isn't available.\r\n\r\nSpecify Bing's Image Search URL as:\r\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\r\n\r\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\r\n\r\nSee 'DefaultSearchProviderImageURLPostParams' (Parameters for an image URL that uses POST) policy to finish configuring image search.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value: https://search.contoso.com/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended","displayName":"Parameters for an image URL that uses POST (User)","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it's replaced with real image thumbnail data. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nSpecify Bing's Image Search URL Post Params as:\r\n'imageBin={google:imageThumbnailBase64}'.\r\n\r\nSpecify Google's Image Search URL Post Params as:\r\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\r\n\r\nIf you don't set this policy, image search requests are sent using the GET method.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended","displayName":"Default search provider keyword (User)","description":"Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider.\r\n\r\nThis policy is optional. If you don't configure it, no keyword activates the search provider.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_defaultsearchproviderkeyword","displayName":"Default search provider keyword (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended","displayName":"Default search provider name (User)","description":"Specifies the name of the default search provider.\r\n\r\nIf you enable this policy, you set the name of the default search provider.\r\n\r\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\r\n\r\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended","displayName":"Default search provider search URL (User)","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\r\n\r\nSpecify Bing's search URL as:\r\n\r\n'{bing:baseURL}search?q={searchTerms}'.\r\n\r\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\r\n\r\nThis policy is required when you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) policy; if you don't enable the latter policy, this policy is ignored.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value: https://search.contoso.com/search?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended","displayName":"Default search provider URL for suggestions (User)","description":"Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user has entered so far.\r\n\r\nThis policy is optional. If you don't configure it, users won't see search suggestions; they will see suggestions from their browsing history and favorites.\r\n\r\nBing's suggest URL can be specified as:\r\n\r\n'{bing:baseURL}qbox?query={searchTerms}'.\r\n\r\nGoogle's suggest URL can be specified as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value: https://search.contoso.com/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_winhttpproxyresolverenabled","displayName":"Use Windows proxy resolver (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nUse Windows to resolve proxies for all browser networking instead of the proxy resolver built into Microsoft Edge. The Windows proxy resolver enables Windows proxy features such as DirectAccess/NRPT.\r\n\r\nThis policy comes with the problems described by https://crbug.com/644030. It causes PAC files to be fetched and executed by Windows code, including PAC files set via the 'ProxyPacUrl' (Set the proxy .pac file URL) policy. Since Network Fetches for the PAC file happen via Windows instead of Microsoft Edge code, network policies such as 'DnsOverHttpsMode' (Control the mode of DNS-over-HTTPS) will not apply to network fetches for a PAC file.\r\n\r\nThis policy is deprecated. It will be superseded by a similar feature in a future release, see https://crbug.com/1032820.\r\n\r\nIf you enable this policy, the Windows proxy resolver will be used.\r\n\r\nIf you disable or don't configure this policy, the Microsoft Edge proxy resolver will be used.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_winhttpproxyresolverenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_winhttpproxyresolverenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge~applicationguard_applicationguardcontainerproxy","displayName":"Application Guard Container Proxy (User)","description":"Configures the proxy settings for Microsoft Edge Application Guard.\r\nIf you enable this policy, Microsoft Edge Application Guard ignores other sources of proxy configurations.\r\n\r\nIf you don't configure this policy, Microsoft Edge Application Guard uses the proxy configuration of the host.\r\n\r\nThis policy does not affect the proxy configuration of Microsoft Edge outside of Application Guard (on the host).\r\n\r\nThe ProxyMode field lets you specify the proxy server used by Microsoft Edge Application Guard.\r\n\r\nThe ProxyPacUrl field is a URL to a proxy .pac file.\r\n\r\nThe ProxyServer field is a URL for the proxy server.\r\n\r\nIf you choose the 'direct' value as 'ProxyMode', all other fields are ignored.\r\n\r\nIf you choose the 'auto_detect' value as 'ProxyMode', all other fields are ignored.\r\n\r\nIf you choose the 'fixed_servers' value as 'ProxyMode', the 'ProxyServer' field is used.\r\n\r\nIf you choose the 'pac_script' value as 'ProxyMode', the 'ProxyPacUrl' field is used.\r\n\r\nExample value:\r\n\r\n{\r\n \"ProxyMode\": \"direct\", \r\n \"ProxyPacUrl\": \"https://internal.site/example.pac\", \r\n \"ProxyServer\": \"123.123.123.123:8080\"\r\n}","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge~applicationguard_applicationguardcontainerproxy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge~applicationguard_applicationguardcontainerproxy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge~applicationguard_applicationguardcontainerproxy_applicationguardcontainerproxy","displayName":"Application Guard Container Proxy (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user (User)","description":"Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator should not be included when listing the protocol and the protocol should be all lower case. For example, list \"skype\" instead of \"skype:\", \"skype://\" or \"Skype\".\r\n\r\nIf you configure this policy, a protocol will only be permitted to launch an external application without prompting by policy if:\r\n\r\n- the protocol is listed\r\n\r\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\r\n\r\nIf either condition is false, the external protocol launch prompt will not be omitted by policy.\r\n\r\nIf you don't configure this policy, no protocols can launch without a prompt. Users can opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an \"Always open\" checkbox in external protocol dialog) policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' (Block access to a list of URLs) policy, which are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\n\r\nThis policy does not work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ],\r\n \"protocol\": \"spotify\"\r\n },\r\n {\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ],\r\n \"protocol\": \"msteams\"\r\n },\r\n {\r\n \"allowed_origins\": [\r\n \"*\"\r\n ],\r\n \"protocol\": \"msoutlook\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls","displayName":"URLs where AutoOpenFileTypes can apply (User)","description":"A list of URLs to which 'AutoOpenFileTypes' (List of file types that should be automatically opened on download) will apply to. This policy has no impact on automatically open values set by users via the download shelf ... > \"Always open files of this type\" menu entry.\r\n\r\nIf you set URLs in this policy, files will only automatically open by policy if the URL is part of this set and the file type is listed in 'AutoOpenFileTypes'. If either condition is false, the download won't automatically open by policy.\r\n\r\nIf you don't set this policy, all downloads where the file type is in 'AutoOpenFileTypes' will automatically open.\r\n\r\nA URL pattern has to be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nThis policy does not work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls_autoopenallowedforurlsdesc","displayName":"URLs where AutoOpenFileTypes can apply (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenfiletypes","displayName":"List of file types that should be automatically opened on download (User)","description":"This policy sets a list of file types that should be automatically opened on download. Note: The leading separator should not be included when listing the file type, so list \"txt\" instead of \".txt\".\r\n\r\nBy default, these file types will be automatically opened on all URLs. You can use the 'AutoOpenAllowedForURLs' (URLs where AutoOpenFileTypes can apply) policy to restrict the URLs for which these file types will be automatically opened on.\r\n\r\nFiles with types that should be automatically opened will still be subject to the enabled Microsoft Defender SmartScreen checks and won't be opened if they fail those checks.\r\n\r\nFile types that a user has already specified to automatically be opened will continue to do so when downloaded. The user will continue to be able to specify other file types to be automatically opened.\r\n\r\nIf you don't set this policy, only file types that a user has already specified to automatically be opened will do so when downloaded.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory or instances that enrolled for device management.\r\n\r\nExample value:\r\n\r\nexe\r\ntxt","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenfiletypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenfiletypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenfiletypes_autoopenfiletypesdesc","displayName":"List of file types that should be automatically opened on download (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_defaultsearchprovidercontextmenuaccessallowed","displayName":"Allow default search provider context menu search access (User)","description":"Enables the use of a default search provider on the context menu.\r\n\r\nIf you set this policy to disabled the search context menu item that relies on your default search provider and sidebar search will not be available.\r\n\r\nIf this policy is set to enabled or not set, the context menu item for your default search provider and sidebar search will be available.\r\n\r\nThe policy value is only applied when the 'DefaultSearchProviderEnabled' (Enable the default search provider) policy is enabled, and is not applicable otherwise.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_defaultsearchprovidercontextmenuaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_defaultsearchprovidercontextmenuaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_enablesha1forlocalanchors","displayName":"Allow certificates signed using SHA-1 when issued by local trust anchors (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nWhen this setting is enabled, Microsoft Edge allows connections secured by SHA-1 signed certificates so long as the the certificate chains to a locally-installed root certificate and is otherwise valid.\r\n\r\nNote that this policy depends on the operating system (OS) certificate verification stack allowing SHA-1 signatures. If an OS update changes the OS handling of SHA-1 certificates, this policy might no longer have effect. Further, this policy is intended as a temporary workaround to give enterprises more time to move away from SHA-1. This policy will be removed in Microsoft Edge 92 releasing in mid 2021.\r\n\r\nIf you don't set this policy or set it to false, or the SHA-1 certificate chains to a publicly trusted certificate root, then Microsoft Edge won't allow certificates signed by SHA-1.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_enablesha1forlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_enablesha1forlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109.\r\n\r\nThis policy has been obsoleted in favor of 'ExemptFileTypeDownloadWarnings' (Disable download file type extension-based warnings for specified file types on domains) because of a type mismatch that caused errors in Mac.\r\n\r\nYou can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users would not see a warning when downloading \"jnlp\" files from \"website1.com\", but see a download warning when downloading \"jnlp\" files from \"website2.com\".\r\n\r\nFiles with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\r\n\r\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.\r\n\r\nIf you enable this policy:\r\n\r\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list \"jnlp\" should be used instead of \".jnlp\".\r\n\r\nExample:\r\n\r\nThe following example value would prevent file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\r\n\r\n[\r\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\r\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\r\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\r\n]\r\n\r\nNote that while the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.\r\n\r\nExample value:\r\n\r\n{\"domains\": [\"https://contoso.com\", \"contoso2.com\"], \"file_extension\": \"jnlp\"}\r\n{\"domains\": [\"*\"], \"file_extension\": \"swf\"}","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_exemptdomainfiletypepairsfromfiletypedownloadwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_exemptdomainfiletypepairsfromfiletypedownloadwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_exemptdomainfiletypepairsfromfiletypedownloadwarnings_exemptdomainfiletypepairsfromfiletypedownloadwarningsdesc","displayName":"Disable download file type extension-based warnings for specified file types on domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_intensivewakeupthrottlingenabled","displayName":"Control the IntensiveWakeUpThrottling feature (User)","description":"When enabled the IntensiveWakeUpThrottling feature causes Javascript timers in background tabs to be aggressively throttled and coalesced, running no more than once per minute after a page has been backgrounded for 5 minutes or more.\r\n\r\nThis is a web standards compliant feature, but it may break functionality on some websites by causing certain actions to be delayed by up to a minute. However, it results in significant CPU and battery savings when enabled. See https://bit.ly/30b1XR4 for more details.\r\n\r\nIf you enable this policy, the feature will be force enabled, and users will not be able to override this setting.\r\nIf you disable this policy, the feature will be force disabled, and users will not be able to override this setting.\r\nIf you don't configure this policy, the feature will be controlled by its own internal logic. Users can manually configure this setting.\r\n\r\nNote that the policy is applied per renderer process, with the most recent value of the policy setting in force when a renderer process starts. A full restart is required to ensure that all the loaded tabs receive a consistent policy setting. It is harmless for processes to be running with different values of this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_intensivewakeupthrottlingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_intensivewakeupthrottlingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_newtabpagesearchbox_recommended","displayName":"Configure the new tab page search box experience (User)","description":"You can configure the new tab page search box to use \"Search box (Recommended)\" or \"Address bar\" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL).\r\n\r\n If you disable or don't configure this policy and:\r\n\r\n- If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.\r\n- If the address bar default search engine is not Bing, users are offered an additional choice (use \"Address bar\") when searching on new tabs.\r\n\r\n\r\nIf you enable this policy and set it to:\r\n\r\n- \"Search box (Recommended)\" ('bing'), the new tab page uses the search box to search on new tabs.\r\n- \"Address bar\" ('redirect'), the new tab page search box uses the address bar to search on new tabs.\r\n\r\nPolicy options mapping:\r\n\r\n* bing (bing) = Search box (Recommended)\r\n\r\n* redirect (redirect) = Address bar\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: bing","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_newtabpagesearchbox_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_newtabpagesearchbox_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_newtabpagesearchbox_recommended_newtabpagesearchbox","displayName":"New tab page search box experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_newtabpagesearchbox_recommended_newtabpagesearchbox_bing","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_newtabpagesearchbox_recommended_newtabpagesearchbox_redirect","displayName":"Address bar","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmonitorallowed_recommended","displayName":"Allow users to be alerted if their passwords are found to be unsafe (User)","description":"Allow Microsoft Edge to monitor user passwords.\r\n\r\nIf you enable this policy, the user will get alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\r\n\r\nIf you disable this policy, users will not be asked for permission to enable this feature. Their passwords will not be scanned and they will not be alerted either.\r\n\r\nIf you don't configure the policy, users can turn this feature on or off.\r\n\r\nTo learn more about how Microsoft Edge finds unsafe passwords see https://go.microsoft.com/fwlink/?linkid=2133833\r\n\r\nAdditional guidance:\r\n\r\nThis policy can be set as both Recommended as well as Mandatory, however with an important callout.\r\n\r\nMandatory enabled: If the policy is set to Mandatory enabled, the UI in Settings will be disabled but remain in 'On' state, and a briefcase icon will be made visible next to it with this description displayed on hover - \"This setting is managed by your organization.\"\r\n\r\nRecommended enabled: If the policy is set to Recommended enabled, the UI in Settings will remain in 'Off' state, but a briefcase icon will be made visible next to it with this description displayed on hover - \"Your organization recommends a specific value for this setting and you have chosen a different value\"\r\n\r\nMandatory and Recommended disabled: Both these states will work the normal way, with the usual captions being shown to users.","helpText":"","infoUrls":[],"categoryId":"a877a2ff-f144-421f-814c-593e972a8a20","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmonitorallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmonitorallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~startup_recommended_newtabpageprerenderenabled_recommended","displayName":"Enable preload of the new tab page for faster rendering (User)","description":"If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~startup_recommended_newtabpageprerenderenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~startup_recommended_newtabpageprerenderenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation","displayName":"Set the roaming profile directory (User)","description":"Configures the directory to use to store the roaming copy of profiles.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory to store a roaming copy of the profiles, as long as you've also enabled the 'RoamingProfileSupportEnabled' (Enable using roaming copies for Microsoft Edge profile data) policy. If you disable the 'RoamingProfileSupportEnabled' policy or don't configure it, the value stored in this policy isn't used.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables you can use.\r\n\r\nIf you don't configure this policy, the default roaming profile path is used.\r\n\r\nExample value: ${roaming_app_data}\\edge-profile","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation_roamingprofilelocation","displayName":"Set the roaming profile directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilesupportenabled","displayName":"Enable using roaming copies for Microsoft Edge profile data (User)","description":"Enable this policy to use roaming profiles on Windows. The settings stored in Microsoft Edge profiles (favorites and preferences) are also saved to a file stored in the Roaming user profile folder (or the location specified by the administrator through the 'RoamingProfileLocation' (Set the roaming profile directory) policy).\r\n\r\nIf you disable this policy or don't configure it, only the regular local profiles are used.\r\n\r\nThe 'SyncDisabled' (Disable synchronization of data using Microsoft sync services) policy disables all data synchronization, overriding policy.\r\n\r\nSee https://docs.microsoft.com/windows-server/storage/folder-redirection/deploy-roaming-user-profiles for more information on using roaming user profiles.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilesupportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilesupportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_tlsciphersuitedenylist","displayName":"Specify the TLS cipher suites to disable (User)","description":"Configure the list of cipher suites that are disabled for TLS connections.\r\n\r\nIf you configure this policy, the list of configured cipher suites will not be used when establishing TLS connections.\r\n\r\nIf you don't configure this policy, the browser will choose which TLS cipher suites to use.\r\n\r\nCipher suite values to be disabled are specified as 16-bit hexadecimal values. The values are assigned by the Internet Assigned Numbers Authority (IANA) registry.\r\n\r\nThe TLS 1.3 cipher suite TLS_AES_128_GCM_SHA256 (0x1301) is required for TLS 1.3 and can't be disabled by this policy.\r\n\r\nThis policy does not affect QUIC-based connections. QUIC can be turned off via the 'QuicAllowed' (Allow QUIC protocol) policy.\r\n\r\nExample value:\r\n\r\n0x1303\r\n0xcca8\r\n0xcca9","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_tlsciphersuitedenylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_tlsciphersuitedenylist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_tlsciphersuitedenylist_tlsciphersuitedenylistdesc","displayName":"Specify the TLS cipher suites to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox","displayName":"Configure the new tab page search box experience (User)","description":"You can configure the new tab page search box to use \"Search box (Recommended)\" or \"Address bar\" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL).\r\n\r\n If you disable or don't configure this policy and:\r\n\r\n- If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.\r\n- If the address bar default search engine is not Bing, users are offered an additional choice (use \"Address bar\") when searching on new tabs.\r\n\r\n\r\nIf you enable this policy and set it to:\r\n\r\n- \"Search box (Recommended)\" ('bing'), the new tab page uses the search box to search on new tabs.\r\n- \"Address bar\" ('redirect'), the new tab page search box uses the address bar to search on new tabs.\r\n\r\nPolicy options mapping:\r\n\r\n* bing (bing) = Search box (Recommended)\r\n\r\n* redirect (redirect) = Address bar\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: bing","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_newtabpagesearchbox","displayName":"New tab page search box experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_newtabpagesearchbox_bing","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_newtabpagesearchbox_redirect","displayName":"Address bar","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~passwordmanager_passwordmonitorallowed","displayName":"Allow users to be alerted if their passwords are found to be unsafe (User)","description":"Allow Microsoft Edge to monitor user passwords.\r\n\r\nIf you enable this policy, the user will get alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\r\n\r\nIf you disable this policy, users will not be asked for permission to enable this feature. Their passwords will not be scanned and they will not be alerted either.\r\n\r\nIf you don't configure the policy, users can turn this feature on or off.\r\n\r\nTo learn more about how Microsoft Edge finds unsafe passwords see https://go.microsoft.com/fwlink/?linkid=2133833\r\n\r\nAdditional guidance:\r\n\r\nThis policy can be set as both Recommended as well as Mandatory, however with an important callout.\r\n\r\nMandatory enabled: If the policy is set to Mandatory enabled, the UI in Settings will be disabled but remain in 'On' state, and a briefcase icon will be made visible next to it with this description displayed on hover - \"This setting is managed by your organization.\"\r\n\r\nRecommended enabled: If the policy is set to Recommended enabled, the UI in Settings will remain in 'Off' state, but a briefcase icon will be made visible next to it with this description displayed on hover - \"Your organization recommends a specific value for this setting and you have chosen a different value\"\r\n\r\nMandatory and Recommended disabled: Both these states will work the normal way, with the usual captions being shown to users.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~passwordmanager_passwordmonitorallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~passwordmanager_passwordmonitorallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~startup_newtabpageprerenderenabled","displayName":"Enable preload of the new tab page for faster rendering (User)","description":"If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~startup_newtabpageprerenderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~startup_newtabpageprerenderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage (User)","description":"This policy controls sending required and optional diagnostic data about browser usage to Microsoft.\r\n\r\nRequired diagnostic data is collected to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\nOptional diagnostic data includes data about how you use the browser, websites you visit and crash reports to Microsoft for product and service improvement.\r\n\r\nUp to version 121, this policy is not supported on Windows 10 devices. To control this data collection on Windows 10 for 121 and previous, IT admins must use the Windows diagnostic data group policy. This policy will either be 'Allow Telemetry' or 'Allow Diagnostic Data', depending on the version of Windows. Learn more about Windows 10 diagnostic data collection: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nFor version 122 and later, this policy is supported on Windows 10 devices to allow controlling Microsoft Edge data collection separately from Windows 10 diagnostics data collection.\r\n\r\nUse one of the following settings to configure this policy:\r\n\r\n'Off' turns off required and optional diagnostic data collection. This option is not recommended.\r\n\r\n'RequiredData' sends required diagnostic data but turns off optional diagnostic data collection. Microsoft Edge will send required diagnostic data to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\n'OptionalData' sends optional diagnostic data includes data about browser usage, websites that are visited, crash reports sent to Microsoft for product and service improvement.\r\n\r\nOn Windows 7/macOS, this policy controls sending required and optional data to Microsoft.\r\n\r\nIf you don't configure this policy or disable it, Microsoft Edge will default to the user's preference.\r\n\r\nPolicy options mapping:\r\n\r\n* Off (0) = Off (Not recommended)\r\n\r\n* RequiredData (1) = Required data\r\n\r\n* OptionalData (2) = Optional data\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_diagnosticdata_0","displayName":"Off (Not recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_diagnosticdata_1","displayName":"Required data","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_diagnosticdata_2","displayName":"Optional data","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist","displayName":"Block access to a specified list of services and export targets in Collections (User)","description":"List specific services and export targets that users can't access in the Collections feature in Microsoft Edge. This includes displaying additional data from Bing and exporting collections to Microsoft products or external partners.\r\n\r\nIf you enable this policy, services and export targets that match the given list are blocked.\r\n\r\nIf you don't configure this policy, no restrictions on the acceptable services and export targets are enforced.\r\n\r\nPolicy options mapping:\r\n\r\n* pinterest_suggestions (pinterest_suggestions) = Pinterest suggestions\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\npinterest_suggestions","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_collectionsservicesandexportsblocklistdesc","displayName":"Block access to a specified list of services and export targets in Collections (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting","displayName":"Default sensors setting (User)","description":"Set whether websites can access and use sensors such as motion and light sensors. You can completely block or allow websites to get access to sensors.\r\n\r\nSetting the policy to 1 lets websites access and use sensors. Setting the policy to 2 denies access to sensors.\r\n\r\nYou can override this policy for specific URL patterns by using the 'SensorsAllowedForUrls' (Allow access to sensors on specific sites) and 'SensorsBlockedForUrls' (Block access to sensors on specific sites) policies.\r\n\r\nIf you don't configure this policy, websites can access and use sensors, and users can change this setting. This is the global default for 'SensorsAllowedForUrls' and 'SensorsBlockedForUrls'.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowSensors (1) = Allow sites to access sensors\r\n\r\n* BlockSensors (2) = Do not allow any site to access sensors\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_defaultsensorssetting","displayName":"Default sensors setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_defaultsensorssetting_1","displayName":"Allow sites to access sensors","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_defaultsensorssetting_2","displayName":"Do not allow any site to access sensors","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting","displayName":"Control use of the Serial API (User)","description":"\r\nSet whether websites can access serial ports. You can completely block access or ask the user each time a website wants to get access to a serial port.\r\n\r\nSetting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\r\n\r\nYou can override this policy for specific URL patterns by using the 'SerialAskForUrls' (Allow the Serial API on specific sites) and 'SerialBlockedForUrls' (Block the Serial API on specific sites) policies.\r\n\r\nIf you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockSerial (2) = Do not allow any site to request access to serial ports via the Serial API\r\n\r\n* AskSerial (3) = Allow sites to ask for user permission to access a serial port\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_defaultserialguardsetting","displayName":"Control use of the Serial API (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_defaultserialguardsetting_2","displayName":"Do not allow any site to request access to serial ports via the Serial API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_defaultserialguardsetting_3","displayName":"Allow sites to ask for user permission to access a serial port","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage (User)","description":"This policy controls sending required and optional diagnostic data about browser usage to Microsoft.\r\n\r\nRequired diagnostic data is collected to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\nOptional diagnostic data includes data about how you use the browser, websites you visit and crash reports to Microsoft for product and service improvement.\r\n\r\nUp to version 121, this policy is not supported on Windows 10 devices. To control this data collection on Windows 10 for 121 and previous, IT admins must use the Windows diagnostic data group policy. This policy will either be 'Allow Telemetry' or 'Allow Diagnostic Data', depending on the version of Windows. Learn more about Windows 10 diagnostic data collection: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nFor version 122 and later, this policy is supported on Windows 10 devices to allow controlling Microsoft Edge data collection separately from Windows 10 diagnostics data collection.\r\n\r\nUse one of the following settings to configure this policy:\r\n\r\n'Off' turns off required and optional diagnostic data collection. This option is not recommended.\r\n\r\n'RequiredData' sends required diagnostic data but turns off optional diagnostic data collection. Microsoft Edge will send required diagnostic data to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\n'OptionalData' sends optional diagnostic data includes data about browser usage, websites that are visited, crash reports sent to Microsoft for product and service improvement.\r\n\r\nOn Windows 7/macOS, this policy controls sending required and optional data to Microsoft.\r\n\r\nIf you don't configure this policy or disable it, Microsoft Edge will default to the user's preference.\r\n\r\nPolicy options mapping:\r\n\r\n* Off (0) = Off (Not recommended)\r\n\r\n* RequiredData (1) = Required data\r\n\r\n* OptionalData (2) = Optional data\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata_0","displayName":"Off (Not recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata_1","displayName":"Required data","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata_2","displayName":"Optional data","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_enterprisemodesitelistmanagerallowed","displayName":"Allow access to the Enterprise Mode Site List Manager tool (User)","description":"Allows you to set whether Enterprise Mode Site List Manager is available to users.\r\n\r\nIf you enable this policy, users can see the Enterprise Mode Site List Manager nav button on edge://compat page, navigate to the tool and use it.\r\n\r\nIf you disable or don't configure this policy, users won't see the Enterprise Mode Site List Manager nav button and won't be able to use it.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_enterprisemodesitelistmanagerallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_enterprisemodesitelistmanagerallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_forcesync","displayName":"Force synchronization of browser data and do not show the sync consent prompt (User)","description":"Forces data synchronization in Microsoft Edge. This policy also prevents the user from turning sync off.\r\n\r\nIf you don't configure this policy, users will be able to turn sync on or off. If you enable this policy, users will not be able to turn sync off.\r\n\r\nFor this policy to work as intended,\r\n'BrowserSignin' (Browser sign-in settings) policy must not be configured, or must be set to enabled. If 'ForceSync' (Force synchronization of browser data and do not show the sync consent prompt) is set to disabled, then 'BrowserSignin' will not take affect.\r\n\r\n'SyncDisabled' (Disable synchronization of data using Microsoft sync services) must not be configured or must be set to False. If this is set to True, 'ForceSync' will not take affect.\r\n\r\n0 = Do not automatically start sync and show the sync consent (default)\r\n1 = Force sync to be turned on for Azure AD/Azure AD-Degraded user profile and do not show the sync consent prompt","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_forcesync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_forcesync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled","displayName":"Enable warnings for insecure forms (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy controls the handling of insecure forms (forms submitted over HTTP) embedded in secure (HTTPS) sites in the browser.\r\nIf you enable this policy or don't set it, a full page warning will be shown when an insecure form is submitted. Additionally, a warning bubble will be shown next to the form fields when they are focused, and autofill will be disabled for those forms.\r\nIf you disable this policy, warnings will not be shown for insecure forms, and autofill will work normally.\r\n\r\nThis policy may be removed as soon as Edge 132. The feature is enabled by default since Edge 131.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_internetexplorerintegrationtestingallowed","displayName":"Allow Internet Explorer mode testing (User)","description":"This policy is a replacement for the ie-mode-test flag policy. It lets users open an IE mode tab from the UI menu option.\r\n\r\n This setting works in conjunction with:\r\n 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'\r\n and\r\n 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry.\r\n\r\n If you enable this policy, users can open IE mode tab from the UI option and navigate current site to an IE mode site.\r\n\r\n If you disable this policy, users can't see the UI option in the menu directly.\r\n\r\n If you don't configure this policy, you can set up the ie-mode-test flag manually.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_internetexplorerintegrationtestingallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_internetexplorerintegrationtestingallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit","displayName":"Save cookies when Microsoft Edge closes (User)","description":"When this policy is enabled, the specified set of cookies is exempt from deletion when the browser closes. This policy is only effective when:\r\n- The 'Cookies and other site data' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\r\n- The policy 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) is enabled or\r\n- The policy 'DefaultCookiesSetting' (Configure cookies) is set to 'Keep cookies for the duration of the session'.\r\n\r\nYou can define a list of sites, based on URL patterns, that will have their cookies preserved across sessions.\r\n\r\nNote: Users can still edit the cookie site list to add or remove URLs. However, they can't remove URLs that have been added by an Admin.\r\n\r\nIf you enable this policy, the list of cookies won't be cleared when the browser closes.\r\n\r\nIf you disable or don't configure this policy, the user's personal configuration is used.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit_savecookiesonexitdesc","displayName":"Save cookies when Microsoft Edge closes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls","displayName":"Allow access to sensors on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can access and use sensors such as motion and light sensors.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultSensorsSetting' (Default sensors setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor URL patterns that don't match this policy, the following order of precedence is used: The 'SensorsBlockedForUrls' (Block access to sensors on specific sites) policy (if there is a match), the 'DefaultSensorsSetting' policy (if set), or the user's personal settings.\r\n\r\nThe URL patterns defined in this policy can't conflict with those configured in the 'SensorsBlockedForUrls' policy. You can't allow and block a URL.\r\n\r\nFor detailed information about valid URL patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_sensorsallowedforurlsdesc","displayName":"Allow access to sensors on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsblockedforurls","displayName":"Block access to sensors on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can't access sensors such as motion and light sensors.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultSensorsSetting' (Default sensors setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor URL patterns that don't match this policy, the following order of precedence is used: The 'SensorsAllowedForUrls' (Allow access to sensors on specific sites) policy (if there is a match), the 'DefaultSensorsSetting' policy (if set), or the user's personal settings.\r\n\r\nThe URL patterns defined in this policy can't conflict with those configured in the 'SensorsAllowedForUrls' policy. You can't allow and block a URL.\r\n\r\nFor detailed information about valid URL patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsblockedforurls_sensorsblockedforurlsdesc","displayName":"Block access to sensors on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialaskforurls","displayName":"Allow the Serial API on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can ask the user for access to a serial port.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultSerialGuardSetting' (Control use of the Serial API) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor URL patterns that don't match this policy, the following order of precedence is used: The 'SerialBlockedForUrls' (Block the Serial API on specific sites) policy (if there is a match), the 'DefaultSerialGuardSetting' policy (if set), or the user's personal settings.\r\n\r\nThe URL patterns defined in this policy can't conflict with those configured in the 'SerialBlockedForUrls' policy. You can't allow and block a URL.\r\n\r\nFor detailed information about valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialaskforurls_serialaskforurlsdesc","displayName":"Allow the Serial API on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialblockedforurls","displayName":"Block the Serial API on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can't ask the user to grant them access to a serial port.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultSerialGuardSetting' (Control use of the Serial API) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor URL patterns that don't match this policy, the following order of precedence is used: The 'SerialAskForUrls' (Allow the Serial API on specific sites) policy (if there is a match), the 'DefaultSerialGuardSetting' policy (if set), or the user's personal settings.\r\n\r\nThe URL patterns in this policy can't conflict with those configured in the 'SerialAskForUrls' policy. You can't allow and block a URL.\r\n\r\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialblockedforurls_serialblockedforurlsdesc","displayName":"Block the Serial API on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_useragentclienthintsenabled","displayName":"Enable the User-Agent Client Hints feature (obsolete) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because it's only intended to be a short-term mechanism to give enterprises more time to update their web content if and when it's found to be incompatible with the User-Agent Client Hints feature. It won't work in Microsoft Edge version 89.\r\n\r\nWhen enabled the User-Agent Client Hints feature sends granular request headers that provide information about the user browser (for example, the browser version) and environment (for example, the system architecture).\r\n\r\nThis is an additive feature, but the new headers may break some websites that restrict the characters that requests may contain.\r\n\r\nIf you enable or don't configure this policy, the User-Agent Client Hints feature is enabled. If you disable this policy, this feature is unavailable.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_useragentclienthintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_useragentclienthintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit","displayName":"Limits the number of user data snapshots retained for use in case of emergency rollback (User)","description":"Following each major version update, Microsoft Edge will create a snapshot of parts of the user's browsing data to use in case of a later emergency that requires a temporary version rollback. If a temporary rollback is performed to a version for which a user has a corresponding snapshot, the data in the snapshot is restored. This lets users keep settings such as bookmarks and autofill data.\r\n\r\nIf you don't set this policy, the default value of 3 snapshots is used.\r\n\r\nIf you set this policy, old snapshots are deleted as needed to respect the limit you set. If you set this policy to 0, no snapshots are taken.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit_userdatasnapshotretentionlimit","displayName":"Limits the number of user data snapshots retained for use in case of emergency rollback: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading (User)","description":"If you set this policy to 3, websites can ask for read access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\r\n\r\nIf you don't set this policy, websites can ask for access. Users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockFileSystemRead (2) = Don't allow any site to request read access to files and directories via the File System API\r\n\r\n* AskFileSystemRead (3) = Allow sites to ask the user to grant read access to files and directories via the File System API\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_2","displayName":"Don't allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_3","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing (User)","description":"If you set this policy to 3, websites can ask for write access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\r\n\r\nIf you don't set this policy, websites can ask for access. Users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockFileSystemWrite (2) = Don't allow any site to request write access to files and directories\r\n\r\n* AskFileSystemWrite (3) = Allow sites to ask the user to grant write access to files and directories\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting_2","displayName":"Don't allow any site to request write access to files and directories","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting_3","displayName":"Allow sites to ask the user to grant write access to files and directories","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls","displayName":"Allow read access via the File System API on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\r\n\r\nLeaving the policy unset means 'DefaultFileSystemReadGuardSetting' (Control use of the File System API for reading) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemReadBlockedForUrls' (Block read access via the File System API on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_filesystemreadaskforurlsdesc","displayName":"Allow read access via the File System API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadblockedforurls","displayName":"Block read access via the File System API on these sites (User)","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\r\n\r\nIf you don't set this policy, 'DefaultFileSystemReadGuardSetting' (Control use of the File System API for reading) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemReadAskForUrls' (Allow read access via the File System API on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadblockedforurls_filesystemreadblockedforurlsdesc","displayName":"Block read access via the File System API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls","displayName":"Allow write access to files and directories on these sites (User)","description":"If you set this policy, you can list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nIf you don't set this policy, 'DefaultFileSystemWriteGuardSetting' (Control use of the File System API for writing) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemWriteBlockedForUrls' (Block write access to files and directories on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls_filesystemwriteaskforurlsdesc","displayName":"Allow write access to files and directories on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls","displayName":"Block write access to files and directories on these sites (User)","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nIf you don't set this policy, 'DefaultFileSystemWriteGuardSetting' (Control use of the File System API for writing) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemWriteAskForUrls' (Allow write access to files and directories on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls_filesystemwriteblockedforurlsdesc","displayName":"Block write access to files and directories on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_spotlightexperiencesandrecommendationsenabled","displayName":"Choose whether users can receive customized background images and text, suggestions, notifications,\r\nand tips for Microsoft services (User)","description":"Choose whether users can receive customized background images and text, suggestions, notifications, and tips for Microsoft services.\r\n\r\nIf you enable or don't configure this setting, spotlight experiences and recommendations are turned on.\r\n\r\nIf you disable this setting, spotlight experiences and recommendations are turned off.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_spotlightexperiencesandrecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_spotlightexperiencesandrecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes","displayName":"Configure the background types allowed for the new tab page layout (User)","description":"You can configure which types of background image that are allowed on the new tab page layout in Microsoft Edge.\r\n\r\nIf you don't configure this policy, all background image types on the new tab page are enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* DisableImageOfTheDay (1) = Disable daily background image type\r\n\r\n* DisableCustomImage (2) = Disable custom background image type\r\n\r\n* DisableAll (3) = Disable all background image types\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes","displayName":"New tab page experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes_1","displayName":"Disable daily background image type","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes_2","displayName":"Disable custom background image type","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes_3","displayName":"Disable all background image types","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (User)","description":"If FriendlyURLs are enabled, Microsoft Edge will compute additional representations of the URL and place them on the clipboard.\r\n\r\nThis policy configures what format will be pasted when the user pastes in external applications, or inside Microsoft Edge without the 'Paste as' context menu item.\r\n\r\nIf configured, this policy makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu will not be available.\r\n\r\n* Not configured = The user will be able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\r\n\r\n* 1 = No additional formats will be stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature will be disabled.\r\n\r\n* 3 = The user will get a friendly URL whenever they paste into surfaces that accept rich text. The plain URL will still be available for non-rich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\r\n\r\n* 4 = (Not currently used)\r\n\r\nThe richer formats may not be well-supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy.\r\n\r\nThe recommended policy is available in Microsoft Edge 105 or later.\r\n\r\nPolicy options mapping:\r\n\r\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\r\n\r\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.\r\n\r\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat_1","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat_3","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat_4","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled","displayName":"Shopping in Microsoft Edge Enabled (User)","description":"This policy lets users compare the prices of a product they are looking at, get coupons from the website they're on, or auto-apply coupons during checkout.\r\n\r\nIf you enable or don't configure this policy, shopping features such as price comparison and coupons will be automatically applied for retail domains. Coupons for the current retailer and prices from other retailers will be fetched from a server.\r\n\r\nIf you disable this policy shopping features such as price comparison and coupons will not be automatically found for retail domains.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_hideinternetexplorerredirectuxforincompatiblesitesenabled","displayName":"Hide the one-time redirection dialog and the banner on Microsoft Edge (User)","description":"This policy gives an option to disable one-time redirection dialog and the banner. When this policy is enabled, users will not see both the one-time dialog and the banner.\r\nUsers will continue to be redirected to Microsoft Edge when they encounter an incompatible website on Internet Explorer, but their browsing data will not be imported.\r\n\r\n- If you enable this policy the one-time redirection dialog and banner will never be shown to users. Users' browsing data will not be imported when a redirection happens.\r\n\r\n- If you disable or don't set this policy, the redirection dialog will be shown on the first redirection and the persistent redirection banner will be shown to users on sessions that begin with a redirection. Users' browsing data will be imported every time user encounters such redirection (ONLY IF user consents to it on the one-time dialog).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_hideinternetexplorerredirectuxforincompatiblesitesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_hideinternetexplorerredirectuxforincompatiblesitesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_edgeshoppingassistantenabled_recommended","displayName":"Shopping in Microsoft Edge Enabled (User)","description":"This policy lets users compare the prices of a product they are looking at, get coupons from the website they're on, or auto-apply coupons during checkout.\r\n\r\nIf you enable or don't configure this policy, shopping features such as price comparison and coupons will be automatically applied for retail domains. Coupons for the current retailer and prices from other retailers will be fetched from a server.\r\n\r\nIf you disable this policy shopping features such as price comparison and coupons will not be automatically found for retail domains.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_edgeshoppingassistantenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_edgeshoppingassistantenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"This setting lets you specify whether Internet Explorer will redirect navigations to sites that require a modern browser to Microsoft Edge.\r\n\r\nIf you don't configure this policy or set it to 'Sitelist', beginning in M87, Internet Explorer will redirect sites that require a modern browser to Microsoft Edge.\r\n\r\nMicrosoft provides a list of public sites that require such redirection, such as https://mail.yahoo.com.\r\n\r\nWhen a site is redirected from Internet Explorer to Microsoft Edge, the Internet Explorer tab that began loading that site is closed if it had no prior content. Otherwise, it is navigated to a Microsoft help page explaining why the site was redirected to Microsoft Edge.\r\n\r\nWhen Microsoft Edge is launched to load a site from IE, an information bar is shown to the user explaining that the site works best in a modern browser.\r\n\r\nIf you set this policy to 'Disable', Internet Explorer will not redirect any traffic to Microsoft Edge.\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715\r\n\r\nPolicy options mapping:\r\n\r\n* Disable (0) = Disable\r\n\r\n* Sitelist (1) = Redirect sites based on the incompatible sites sitelist\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode_0","displayName":"Prevent redirection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode_1","displayName":"Redirect sites based on the incompatible sites sitelist","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordrevealenabled_recommended","displayName":"Enable Password reveal button (User)","description":"Lets you configure the default display of the browser password reveal button for password input fields on websites.\r\n\r\nIf you enable or don't configure this policy, the browser user setting defaults to displaying the password reveal button.\r\n\r\nIf you disable this policy, the browser user setting won't display the password reveal button.\r\n\r\nFor accessibility, users can change the browser setting from the default policy.\r\n\r\nThis policy only affects the browser password reveal button, it doesn't affect websites' custom reveal buttons.","helpText":"","infoUrls":[],"categoryId":"a877a2ff-f144-421f-814c-593e972a8a20","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordrevealenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordrevealenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall","displayName":"Prevent install of the BHO to redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"This setting lets you specify whether to block the install of the Browser Helper Object (BHO) that enables redirecting incompatible sites from Internet Explorer to Microsoft Edge for sites that require a modern browser.\r\n\r\nIf you enable this policy, the BHO will not be installed. If it is already installed it will be uninstalled on the next Microsoft Edge update.\r\n\r\nIf this policy is not configured or is disabled, the BHO will be installed.\r\n\r\nThe BHO is required for incompatible site redirection to occur, however whether redirection occurs or not is also controlled by 'RedirectSitesFromInternetExplorerRedirectMode' (Redirect incompatible sites from Internet Explorer to Microsoft Edge).\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"This setting lets you specify whether Internet Explorer will redirect navigations to sites that require a modern browser to Microsoft Edge.\r\n\r\nIf you don't configure this policy or set it to 'Sitelist', beginning in M87, Internet Explorer will redirect sites that require a modern browser to Microsoft Edge.\r\n\r\nMicrosoft provides a list of public sites that require such redirection, such as https://mail.yahoo.com.\r\n\r\nWhen a site is redirected from Internet Explorer to Microsoft Edge, the Internet Explorer tab that began loading that site is closed if it had no prior content. Otherwise, it is navigated to a Microsoft help page explaining why the site was redirected to Microsoft Edge.\r\n\r\nWhen Microsoft Edge is launched to load a site from IE, an information bar is shown to the user explaining that the site works best in a modern browser.\r\n\r\nIf you set this policy to 'Disable', Internet Explorer will not redirect any traffic to Microsoft Edge.\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715\r\n\r\nPolicy options mapping:\r\n\r\n* Disable (0) = Disable\r\n\r\n* Sitelist (1) = Redirect sites based on the incompatible sites sitelist\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_redirectsitesfrominternetexplorerredirectmode","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_redirectsitesfrominternetexplorerredirectmode_0","displayName":"Prevent redirection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_redirectsitesfrominternetexplorerredirectmode_1","displayName":"Redirect sites based on the incompatible sites sitelist","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_speechrecognitionenabled","displayName":"Configure Speech Recognition (User)","description":"Set whether websites can use the W3C Web Speech API to recognize speech from the user. The Microsoft Edge implementation of the Web Speech API uses Azure Cognitive Services, so voice data will leave the machine.\r\n\r\nIf you enable or don't configure this policy, web-based applications that use the Web Speech API can use Speech Recognition.\r\n\r\nIf you disable this policy, Speech Recognition is not available through the Web Speech API.\r\n\r\nRead more about this feature here:\r\nSpeechRecognition API: https://go.microsoft.com/fwlink/?linkid=2143388\r\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2143680","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_speechrecognitionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_speechrecognitionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_webcaptureenabled","displayName":"Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge (User)","description":"Note: The web capture feature is rebranded to \"Screenshot\".\r\n\r\nEnables the Screenshot feature in Microsoft Edge. This feature lets users capture web and PDF content, and annotate captures using inking tools. Users can also do a visual image search based on the captured content.\r\n\r\nIf you enable or don't configure this policy, the Screenshot option appears in the context menu, the Settings and more menu, and by using the keyboard shortcut, CTRL+SHIFT+S.\r\n\r\nIf you disable this policy, users can't access this feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_webcaptureenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_webcaptureenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskaddressbareditingenabled","displayName":"Configure address bar editing for kiosk mode public browsing experience (User)","description":"This policy only applies to Microsoft Edge kiosk mode while using the public browsing experience.\r\n\r\nIf you enable or don't configure this policy, users can change the URL in the address bar.\r\n\r\nIf you disable this policy, it prevents users from changing the URL in the address bar.\r\n\r\nFor detailed information on configuring kiosk Mode, see https://go.microsoft.com/fwlink/?linkid=2137578.","helpText":"","infoUrls":[],"categoryId":"d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","categoryName":"Kiosk Mode settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskaddressbareditingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskaddressbareditingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskdeletedownloadsonexit","displayName":"Delete files downloaded as part of kiosk session when Microsoft Edge closes (User)","description":"This policy only applies to Microsoft Edge kiosk mode.\r\n\r\nIf you enable this policy, files downloaded as part of the kiosk session are deleted each time Microsoft Edge closes.\r\n\r\nIf you disable this policy or don't configure it, files downloaded as part of the kiosk session are not deleted when Microsoft Edge closes.\r\n\r\nFor detailed information on configuring kiosk Mode, see https://go.microsoft.com/fwlink/?linkid=2137578.","helpText":"","infoUrls":[],"categoryId":"d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","categoryName":"Kiosk Mode settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskdeletedownloadsonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskdeletedownloadsonexit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~printing_printingpapersizedefault","displayName":"Default printing page size (User)","description":"Overrides default printing page size.\r\n\r\nname should contain one of the listed formats or 'custom' if required paper size is not in the list. If 'custom' value is provided custom_size property should be specified. It describes the desired height and width in micrometers. Otherwise custom_size property shouldn't be specified. Policy that violates these rules is ignored.\r\n\r\nIf the page size is unavailable on the printer chosen by the user this policy is ignored.\r\n\r\nExample value:\r\n\r\n{\r\n \"custom_size\": {\r\n \"height\": 297000,\r\n \"width\": 210000\r\n },\r\n \"name\": \"custom\"\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"custom_size\": {\"height\": 297000, \"width\": 210000}, \"name\": \"custom\"}","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~printing_printingpapersizedefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~printing_printingpapersizedefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~printing_printingpapersizedefault_printingpapersizedefault","displayName":"Default printing page size (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended","displayName":"Set the background tab inactivity timeout for sleeping tabs (User)","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure sleeping tabs) is enabled or is not configured and the user has enabled the sleeping tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 30Seconds (30) = 30 seconds of inactivity\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_30","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs (User)","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure sleeping tabs) is enabled or is not configured and the user has enabled the sleeping tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 30Seconds (30) = 30 seconds of inactivity\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_30","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed","displayName":"Allow launching of local files in Internet Explorer mode (User)","description":"This policy controls the availability of the --ie-mode-file-url command line argument which is used to launch Microsoft Edge with a local file specified on the command line into Internet Explorer mode.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nIf you set this policy to true, or don't configure it, the user is allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\r\n\r\nIf you set this policy to false, the user isn't allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist","displayName":"Open local files in Internet Explorer mode file extension allow list (User)","description":"This policy limits which file:// URLs are allowed to be launched into Internet Explorer mode based on file extension.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nWhen a file:// URL is requested to launch in Internet Explorer mode, the file extension of the URL must be present in this list in order for the URL to be allowed to launch in Internet Explorer mode. A URL which is blocked from opening in Internet Explorer mode will instead open in Edge mode.\r\n\r\nIf you set this policy to the special value \"*\" or don't configure it, all file extensions are allowed.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210\r\n\r\nExample value:\r\n\r\n.mht\r\n.pdf\r\n.vsdx","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist_internetexplorerintegrationlocalfileextensionallowlistdesc","displayName":"Open local files in Internet Explorer mode file extension allow list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileshowcontextmenu","displayName":"Show context menu to open a link in Internet Explorer mode (User)","description":"This policy controls the visibility of the 'Open link in new Internet Explorer mode tab' option on the context menu for file:// links.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nIf you set this policy to true, the 'Open link in new Internet Explorer mode tab' context menu item will be available for file:// links.\r\n\r\nIf you set this policy to false or don't configure it, the context menu item will not be added.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileshowcontextmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileshowcontextmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior","displayName":"Intranet Redirection Behavior (User)","description":"This policy configures behavior for intranet redirection via DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\r\n\r\nIf this policy isn't configured, the browser will use the default behavior of DNS interception checks and intranet redirect suggestions. In M88, they are enabled by default but will be disabled by default in the future release.\r\n\r\n'DNSInterceptionChecksEnabled' (DNS interception checks enabled) is a related policy that might also disable DNS interception checks. However, this policy is a more flexible version which might separately control intranet redirection infobars and might be expanded in the future.\r\nIf either 'DNSInterceptionChecksEnabled' or this policy make a request to disable interception checks, the checks will be disabled.\r\nIf DNS interception checks are disabled by this policy but 'GoToIntranetSiteForSingleWordEntryInAddressBar' (Force direct intranet site navigation instead of searching on single word entries in the Address Bar) is enabled, single word queries will still result in intranet navigations.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Use default browser behavior.\r\n\r\n* DisableInterceptionChecksDisableInfobar (1) = Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.\r\n\r\n* DisableInterceptionChecksEnableInfobar (2) = Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.\r\n\r\n* EnableInterceptionChecksEnableInfobar (3) = Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_intranetredirectbehavior","displayName":"Intranet Redirection Behavior (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_intranetredirectbehavior_0","displayName":"Use default browser behavior.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_intranetredirectbehavior_1","displayName":"Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_intranetredirectbehavior_2","displayName":"Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_intranetredirectbehavior_3","displayName":"Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended_showmicrosoftrewards_recommended","displayName":"Show Microsoft Rewards experiences (User)","description":"Show Microsoft Rewards experience and notifications.\r\nIf you enable this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\r\n - The setting to enable Give mode will be enabled and respect the user's setting.\r\n\r\nIf you disable this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will not see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be disabled and toggled off.\r\n\r\nIf you don't configure this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\r\n - The setting to enable Give mode will be enabled and respect the user's setting.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended_showmicrosoftrewards_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended_showmicrosoftrewards_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~performance_recommended_startupboostenabled_recommended","displayName":"Enable startup boost (User)","description":"Allows Microsoft Edge processes to start at OS sign-in and restart in background after the last browser window is closed.\r\n\r\nIf Microsoft Edge is running in background mode, the browser might not close when the last window is closed and the browser won't be restarted in background when the window closes. See the 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about what happens after configuring Microsoft Edge background mode behavior.\r\n\r\nIf you enable this policy, startup boost is turned on.\r\n\r\nIf you disable this policy, startup boost is turned off.\r\n\r\nIf you don't configure this policy, startup boost may initially be off or on. The user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about startup boost: https://go.microsoft.com/fwlink/?linkid=2147018","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~performance_recommended_startupboostenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~performance_recommended_startupboostenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended","displayName":"Block Sleeping Tabs on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are not allowed to be put to sleep by Sleeping Tabs.\r\n\r\nIf the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is disabled, this list is not used and no sites will be put to sleep automatically.\r\n\r\nIf you don't configure this policy, all sites will be eligible to be put to sleep unless the user's personal configuration blocks them.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended_sleepingtabsblockedforurlsdesc","displayName":"Block Sleeping Tabs on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsenabled_recommended","displayName":"Configure Sleeping Tabs (User)","description":"This policy setting lets you configure whether to turn on Sleeping Tabs. Sleeping Tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, Sleeping Tabs is turned on.\r\n\r\nIndividual sites may be blocked from being put to sleep by configuring the policy 'SleepingTabsBlockedForUrls' (Block Sleeping Tabs on specific sites).\r\n\r\nIf you enable this setting, Sleeping Tabs is turned on.\r\n\r\nIf you disable this setting, Sleeping Tabs is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use Sleeping Tabs.","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended","displayName":"Set the background tab inactivity timeout for Sleeping Tabs (User)","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if Sleeping Tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is enabled or is not configured and the user has enabled the Sleeping Tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_showmicrosoftrewards","displayName":"Show Microsoft Rewards experiences (User)","description":"Show Microsoft Rewards experience and notifications.\r\nIf you enable this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\r\n - The setting to enable Give mode will be enabled and respect the user's setting.\r\n\r\nIf you disable this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will not see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be disabled and toggled off.\r\n\r\nIf you don't configure this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\r\n - The setting to enable Give mode will be enabled and respect the user's setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_showmicrosoftrewards_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_showmicrosoftrewards_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed","displayName":"Configures availability of a vertical layout for tabs on the side of the browser (User)","description":"Configures whether a user can access an alternative layout where tabs are vertically aligned on the side of the browser instead of at the top.\r\nWhen there are several tabs open, this layout provides better tab viewing and management. There's better visibility of the site titles,\r\nit's easier to scan aligned icons, and there's more space to manage and close tabs.\r\n\r\nIf you disable this policy, then the vertical tab layout will not be available as an option for users.\r\n\r\nIf you enable or don't configure this policy, the tab layout will still be at the top, but a user has the option to turn on vertical tabs on the side.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols","displayName":"Allow legacy TLS/DTLS downgrade in WebRTC (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 120.\r\n\r\nIf you enable this policy, WebRTC peer connections can downgrade to obsolete\r\nversions of the TLS/DTLS (DTLS 1.0, TLS 1.0 and TLS 1.1) protocols.\r\nIf you disable or don't set this policy, these TLS/DTLS versions are\r\ndisabled.\r\n\r\nThis policy was removed in Microsoft Edge 121 and is ignored if set.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetallowed","displayName":"Enable the Search bar (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nEnables the search bar. When enabled, users can use the search bar to search the web from their desktop or from an application. The search bar provides a search box that shows web suggestions and opens all web searches in Microsoft Edge. The search box provides search (powered by Bing) and URL suggestions. The search bar can be launched from the \"More tools\" menu or jump list in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy:\r\nThe search bar will be automatically enabled for all profiles.\r\nThe option to enable the search bar at startup will be toggled on if the 'WebWidgetIsEnabledOnStartup' (Allow the Search bar at Windows startup) policy is enabled.\r\nIf the 'WebWidgetIsEnabledOnStartup' is disabled or not configured, the option to enable the search bar at startup will be toggled off.\r\nUsers will see the menu item to launch the search bar from the Microsoft Edge \"More tools\" menu. Users can launch the search bar from \"More tools\".\r\nUsers will see the menu item to launch the search bar from the Microsoft Edge jump list menu. Users can launch the search bar from the Microsoft Edge jump list menu.\r\nThe search bar can be turned off by the \"Quit\" option in the System tray or by closing the search bar from the 3 dot menu. The search bar will be restarted on system reboot if auto-start is enabled.\r\n\r\n\r\nIf you disable this policy:\r\nThe search bar will be disabled for all profiles.\r\nThe option to launch the search bar from Microsoft Edge \"More tools\" menu will be disabled.\r\nThe option to launch the search bar from Microsoft Edge jump list menu will be disabled.\r\n\r\nThis policy is deprecated due to the deprecation of the Web widget's vertical layout. This policy will be made obsolete in 119 release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetisenabledonstartup","displayName":"Allow the Search bar at Windows startup (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 119.\r\n\r\nThis policy is obsolete due to the deprecation of the Web widget, which is now known as Edge search bar. Admins should use SearchbarIsEnabledOnStartup for Edge search bar instead. Allows the Search bar to start running at Windows startup.\r\n\r\nIf you enable this policy the Search bar will start running at Windows startup by default. If the Search bar is disabled via 'WebWidgetAllowed' (Enable the Search bar) policy, this policy will not start the Search bar on Windows startup.\r\n\r\nIf you disable this policy, the Search bar will not start at Windows startup for all profiles. The option to start the Edge search bar at Windows startup will be disabled and toggled off in Microsoft Edge settings.\r\n\r\nIf you don't configure this policy, the Search bar will not start at Windows startup for all profiles. The option to start the Edge search bar at Windows startup will be toggled off in Microsoft Edge settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetisenabledonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetisenabledonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~extensions_blockexternalextensions","displayName":"Blocks external extensions from being installed (User)","description":"Control the installation of external extensions.\r\n\r\nIf you enable this setting, external extensions are blocked from being installed.\r\n\r\nIf you disable this setting or leave it unset, external extensions are allowed to be installed.\r\n\r\nExternal extensions and their installation are documented at [Alternate extension distribution methods](/microsoft-edge/extensions-chromium/developer-guide/alternate-distribution-options).","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~extensions_blockexternalextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~extensions_blockexternalextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~performance_startupboostenabled","displayName":"Enable startup boost (User)","description":"Allows Microsoft Edge processes to start at OS sign-in and restart in background after the last browser window is closed.\r\n\r\nIf Microsoft Edge is running in background mode, the browser might not close when the last window is closed and the browser won't be restarted in background when the window closes. See the 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about what happens after configuring Microsoft Edge background mode behavior.\r\n\r\nIf you enable this policy, startup boost is turned on.\r\n\r\nIf you disable this policy, startup boost is turned off.\r\n\r\nIf you don't configure this policy, startup boost may initially be off or on. The user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about startup boost: https://go.microsoft.com/fwlink/?linkid=2147018","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~performance_startupboostenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~performance_startupboostenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist","displayName":"Disable printer types on the deny list (User)","description":"The printer types on the deny list won't be discovered or have their capabilities fetched.\r\n\r\nPlacing all printer types on the deny list effectively disables printing, because there's no print destination for documents.\r\n\r\nIf you don't configure this policy, or the printer list is empty, all printer types are discoverable.\r\n\r\nPrinter destinations include extension printers and local printers. Extension printers are also known as print provider destinations, and include any destination that belongs to a Microsoft Edge extension.\r\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\r\n\r\nIn Microsoft version 93 or later, if you set this policy to 'pdf' it also disables the 'save as Pdf' option from the right click context menu.\r\n\r\nIn Microsoft version 103 or later, if you set this policy to 'onedrive' it also disables the 'save as Pdf (OneDrive)' option from print preview.\r\n\r\nPolicy options mapping:\r\n\r\n* privet (privet) = Zeroconf-based (mDNS + DNS-SD) protocol destinations\r\n\r\n* extension (extension) = Extension-based destinations\r\n\r\n* pdf (pdf) = The 'Save as PDF' destination. (93 or later, also disables from context menu)\r\n\r\n* local (local) = Local printer destinations\r\n\r\n* onedrive (onedrive) = Save as PDF (OneDrive) printer destinations. (103 or later)\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\nlocal\r\nprivet","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist_printertypedenylistdesc","displayName":"Disable printer types on the deny list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsblockedforurls","displayName":"Block Sleeping Tabs on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are not allowed to be put to sleep by Sleeping Tabs.\r\n\r\nIf the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is disabled, this list is not used and no sites will be put to sleep automatically.\r\n\r\nIf you don't configure this policy, all sites will be eligible to be put to sleep unless the user's personal configuration blocks them.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsblockedforurls_sleepingtabsblockedforurlsdesc","displayName":"Block Sleeping Tabs on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsenabled","displayName":"Configure Sleeping Tabs (User)","description":"This policy setting lets you configure whether to turn on Sleeping Tabs. Sleeping Tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, Sleeping Tabs is turned on.\r\n\r\nIndividual sites may be blocked from being put to sleep by configuring the policy 'SleepingTabsBlockedForUrls' (Block Sleeping Tabs on specific sites).\r\n\r\nIf you enable this setting, Sleeping Tabs is turned on.\r\n\r\nIf you disable this setting, Sleeping Tabs is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use Sleeping Tabs.","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs (User)","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if Sleeping Tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is enabled or is not configured and the user has enabled the Sleeping Tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings (User)","description":"Configures browsing data lifetime settings for Microsoft Edge.\r\nThis policy controls the lifetime of selected browsing data. This policy has no effect if Sync is enabled.\r\nThe available data types are the 'browsing_history', 'download_history', 'cookies_and_other_site_data', 'cached_images_and_files', 'password_signin', 'autofill', 'site_settings' and 'hosted_app_data'.\r\nMicrosoft Edge will regularly remove data of selected types that is older than 'time_to_live_in_hours'. Because data deletion only happens at certain intervals, some data might be kept slightly longer but never more than twice its expected 'time_to_live_in_hours'.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"data_types\": [\r\n \"browsing_history\"\r\n ], \r\n \"time_to_live_in_hours\": 24\r\n }, \r\n {\r\n \"data_types\": [\r\n \"password_signin\", \r\n \"autofill\"\r\n ], \r\n \"time_to_live_in_hours\": 12\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages","displayName":"Define an ordered list of preferred languages that websites should display in if the site supports the language (User)","description":"Configures the language variants that Microsoft Edge sends to websites as part of the Accept-Language request HTTP header and prevents users from adding, removing, or changing the order of preferred languages in Microsoft Edge settings. Users who want to change the languages Microsoft Edge displays in or offers to translate pages to will be limited to the languages configured in this policy.\r\n\r\nIf you enable this policy, websites will appear in the first language in the list that they support unless other site-specific logic is used to determine the display language. The language variants defined in this policy override the languages configured as part of the 'SpellcheckLanguage' (Enable specific spellcheck languages) policy.\r\n\r\nIf you don't configure or disable this policy, Microsoft Edge sends websites the user-specified preferred languages as part of the Accept-Language request HTTP header.\r\n\r\nFor detailed information on valid language variants, see https://go.microsoft.com/fwlink/?linkid=2148854.\r\n\r\nExample value: en-US,fr,es","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages_definepreferredlanguages","displayName":"Define an ordered list of preferred languages that websites should display in if the site supports the language (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended","displayName":"Block smart actions for a list of services (User)","description":"List specific services, such as PDFs, that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\r\n\r\nIf you enable the policy: :\r\n - The smart action in the mini and full context menu will be disabled for all profiles for services that match the given list.\r\n - Users will not see the smart action in the mini and full context menu on text selection for services that match the given list.\r\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be disabled for services that match the given list.\r\n\r\nIf you disable or don't configure this policy:\r\n - The smart action in the mini and full context menu will be enabled for all profiles.\r\n - Users will see the smart action in the mini and full context menu on text selection.\r\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\nsmart_actions_pdf","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended_smartactionsblocklistdesc","displayName":"Block smart actions for a list of services (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_showrecommendationsenabled","displayName":"Allow feature recommendations and browser assistance notifications from Microsoft Edge (User)","description":"This setting controls the in-browser assistance notifications which are intended to help users get the most out of Microsoft Edge. This is done by recommending features and by helping them use browser features. These notifications take the form of dialog boxes, flyouts, coach marks and banners in the browser. An example of an assistance notification would be when a user has many tabs opened in the browser. In this instance Microsoft Edge may prompt the user to try out the vertical tabs feature which is designed to give better browser tab management.\r\n\r\nDisabling this policy will stop this message from appearing again even if the user has too many tabs open.\r\n Any features that have been disabled by a management policy are not suggested to users.\r\nIf you enable or don't configure this setting, users will receive recommendations or notifications from Microsoft Edge.\r\n If you disable this setting, users will not receive any recommendations or notifications from Microsoft Edge","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_showrecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_showrecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_smartactionsblocklist","displayName":"Block smart actions for a list of services (User)","description":"List specific services, such as PDFs, that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\r\n\r\nIf you enable the policy: :\r\n - The smart action in the mini and full context menu will be disabled for all profiles for services that match the given list.\r\n - Users will not see the smart action in the mini and full context menu on text selection for services that match the given list.\r\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be disabled for services that match the given list.\r\n\r\nIf you disable or don't configure this policy:\r\n - The smart action in the mini and full context menu will be enabled for all profiles.\r\n - Users will see the smart action in the mini and full context menu on text selection.\r\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\nsmart_actions_pdf","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_smartactionsblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_smartactionsblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_smartactionsblocklist_smartactionsblocklistdesc","displayName":"Block smart actions for a list of services (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~manageability_mamenabled","displayName":"Mobile App Management Enabled (User)","description":"Allows the Microsoft Edge browser to retrieve policies from the Intune application management services and apply them to users' profiles.\r\n\r\nIf you enable this policy or don't configure it, Mobile App Management (MAM) Policies can be applied.\r\n\r\nIf you disable this policy, Microsoft Edge will not communicate with Intune to request MAM Policies.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~manageability_mamenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~manageability_mamenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode (User)","description":"Restricts background graphics printing mode. If this policy isn't set there's no restriction on printing background graphics.\r\n\r\nPolicy options mapping:\r\n\r\n* any (any) = Allow printing with and without background graphics\r\n\r\n* enabled (enabled) = Allow printing only with background graphics\r\n\r\n* disabled (disabled) = Allow printing only without background graphics\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_any","displayName":"Allow printing with and without background graphics","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_enabled","displayName":"Allow printing only with background graphics","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_disabled","displayName":"Allow printing only without background graphics","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode (User)","description":"Overrides the last used setting for printing background graphics.\r\nIf you enable this setting, background graphics printing is enabled.\r\nIf you disable this setting, background graphics printing is disabled.\r\n\r\nPolicy options mapping:\r\n\r\n* enabled (enabled) = Enable background graphics printing mode by default\r\n\r\n* disabled (disabled) = Disable background graphics printing mode by default\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingbackgroundgraphicsdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingbackgroundgraphicsdefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_enabled","displayName":"Enable background graphics printing mode by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_disabled","displayName":"Disable background graphics printing mode by default","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on shutdown (User)","description":"Controls the duration (in seconds) that keepalive requests are allowed to prevent the browser from completing its shutdown.\r\n\r\nIf you configure this policy, the browser will block completing shutdown while it processes any outstanding keepalive requests (see https://fetch.spec.whatwg.org/#request-keepalive-flag) up to the maximum period of time specified by this policy.\r\n\r\nIf you disable or don't configure this policy, the default value of 0 seconds is used and outstanding keepalive requests will be immediately cancelled during browser shutdown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_fetchkeepalivedurationsecondsonshutdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_fetchkeepalivedurationsecondsonshutdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_fetchkeepalivedurationsecondsonshutdown_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on shutdown: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin","displayName":"Sets managed configuration values for websites to specific origins (User)","description":"Setting this policy defines the return value of Managed Configuration API for given origin.\r\n\r\nManaged Configuration API is a key-value configuration that can be accessed via navigator.device.getManagedConfiguration() javascript call. This API is only available to origins which correspond to force-installed web applications via 'WebAppInstallForceList' (Configure list of force-installed Web Apps).\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"managed_configuration_hash\": \"asd891jedasd12ue9h\",\r\n \"managed_configuration_url\": \"https://static.contoso.com/configuration.json\",\r\n \"origin\": \"https://www.contoso.com\"\r\n },\r\n {\r\n \"managed_configuration_hash\": \"djio12easd89u12aws\",\r\n \"managed_configuration_url\": \"https://static.contoso.com/configuration2.json\",\r\n \"origin\": \"https://www.example.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_managedconfigurationperorigin","displayName":"Sets managed configuration values for websites to specific origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_quickviewofficefilesenabled","displayName":"Manage QuickView Office files capability in Microsoft Edge (User)","description":"Allows you to set whether users can view publicly accessible Office files on the web that aren't on OneDrive or SharePoint. (For example: Word documents, PowerPoint presentations, and Excel spreadsheets)\r\n\r\nIf you enable or don't configure this policy, these files can be viewed in Microsoft Edge using Office Viewer instead of downloading the files.\r\n\r\nIf you disable this policy, these files will be downloaded to be viewed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_quickviewofficefilesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_quickviewofficefilesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_recommended~httpauthentication_recommended_windowshelloforhttpauthenabled_recommended","displayName":"Windows Hello For HTTP Auth Enabled (User)","description":"Indicates if Windows Credential UI should be used to respond to NTLM and Negotiate authentication challenges.\r\n\r\nIf you disable this policy, a basic username and password prompt will be used to respond to NTLM and Negotiate challenges. If you enable or don't configure this policy, Windows Credential UI will be used.","helpText":"","infoUrls":[],"categoryId":"6fafeb5c-65ce-4993-b421-46e60da69131","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_recommended~httpauthentication_recommended_windowshelloforhttpauthenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_recommended~httpauthentication_recommended_windowshelloforhttpauthenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_sslerroroverrideallowedfororigins","displayName":"Allow users to proceed from the HTTPS warning page for specific origins (User)","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\r\n\r\nIf you enable or don't configure the 'SSLErrorOverrideAllowed' (Allow users to proceed from the HTTPS warning page) policy, this policy does nothing.\r\n\r\nIf you disable the 'SSLErrorOverrideAllowed' policy, configuring this policy lets you configure a list of origin patterns for sites where users can continue to click through SSL error pages. Users can't click through SSL error pages on origins that are not on this list.\r\n\r\nIf you don't configure this policy, the 'SSLErrorOverrideAllowed' policy applies for all sites.\r\n\r\nFor detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy. This policy only matches based on origin, so any path or query in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_sslerroroverrideallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_sslerroroverrideallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_sslerroroverrideallowedfororigins_sslerroroverrideallowedfororiginsdesc","displayName":"Allow users to proceed from the HTTPS warning page for specific origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~applicationguard_applicationguardfavoritessyncenabled","displayName":"Application Guard Favorites Sync Enabled (User)","description":"This policy allows Microsoft Edge computers/devices that have application guard enabled to sync favorites from the host to the container so the favorites match.\r\n\r\nIf 'ManagedFavorites' (Configure favorites) are configured, those favorites will also be synced to the container.\r\n\r\nIf you enable this policy, editing favorites in the container is disabled. So, the add favorites and add favorites folder buttons will be blurred out in the UI of the container browser.\r\n\r\nIf you disable or don't configure this policy, favorites on the host will not be shared to the container.","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~applicationguard_applicationguardfavoritessyncenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~applicationguard_applicationguardfavoritessyncenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~httpauthentication_windowshelloforhttpauthenabled","displayName":"Windows Hello For HTTP Auth Enabled (User)","description":"Indicates if Windows Credential UI should be used to respond to NTLM and Negotiate authentication challenges.\r\n\r\nIf you disable this policy, a basic username and password prompt will be used to respond to NTLM and Negotiate challenges. If you enable or don't configure this policy, Windows Credential UI will be used.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~httpauthentication_windowshelloforhttpauthenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~httpauthentication_windowshelloforhttpauthenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode","displayName":"Print Rasterization Mode (User)","description":"Controls how Microsoft Edge prints on Windows.\r\n\r\nWhen printing to a non-PostScript printer on Windows, sometimes print jobs need to be rasterized to print correctly.\r\n\r\nIf you set this policy to 'Full' or don't configure it, Microsoft Edge will do full page rasterization if necessary.\r\n\r\nIf you set this policy to 'Fast', Microsoft Edge will reduce the amount of rasterization which can help reduce print job sizes and increase printing speed.\r\n\r\nPolicy options mapping:\r\n\r\n* Full (0) = Full page rasterization\r\n\r\n* Fast (1) = Avoid rasterization if possible\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_printrasterizationmode","displayName":"Print Rasterization Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_printrasterizationmode_0","displayName":"Full page rasterization","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_printrasterizationmode_1","displayName":"Avoid rasterization if possible","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports","displayName":"Explicitly allowed network ports (User)","description":"There is a list of restricted ports built into Microsoft Edge. Connections to these ports will fail. This policy allows bypassing that list. The set of ports is defined as a comma-separated list that outgoing connections should be permitted on.\r\n\r\nPorts are restricted to prevent Microsoft Edge from being used as a vector to exploit various network vulnerabilities. Setting this policy may expose your network to attacks. This policy is intended as a temporary workaround for error code \"ERR_UNSAFE_PORT\" while migrating a service running on a blocked port to a standard port (for example port 80 or 443).\r\n\r\nMalicious websites can easily detect that this policy is set, and for which ports, then use that information to target attacks.\r\n\r\nEach port listed in this policy is labeled with a date that it can be unblocked until. After that date the port will be restricted regardless of if it's specified by the value of this policy.\r\n\r\nLeaving the value empty or unset means that all restricted ports will be blocked. Invalid port values set through this policy will be ignored while valid ones will still be applied.\r\n\r\nThis policy overrides the \"--explicitly-allowed-ports\" command-line option.\r\n\r\nPolicy options mapping:\r\n\r\n* 554 (554) = port 554 (can be unblocked until 2021/10/15)\r\n\r\n* 10080 (10080) = port 10080 (can be unblocked until 2022/04/01)\r\n\r\n* 6566 (6566) = port 6566 (can be unblocked until 2021/10/15)\r\n\r\n* 989 (989) = port 989 (can be unblocked until 2022/02/01)\r\n\r\n* 990 (990) = port 990 (can be unblocked until 2022/02/01)\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\n10080","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports_explicitlyallowednetworkportsdesc","displayName":"Explicitly allowed network ports (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_importstartuppagesettings","displayName":"Allow importing of startup page settings (User)","description":"Allows users to import Startup settings from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the Startup settings are always imported.\r\n\r\nIf you disable this policy, startup settings are not imported at first run or at manual import.\r\n\r\nIf you don't configure this policy, startup settings are imported at first run, and users can choose whether to import this data manually by selecting browser settings option during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge will import startup settings on first run, but users can select or clear **browser settings** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Microsoft Edge Legacy and Google Chrome (on Windows 7, 8, and 10) browsers.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_importstartuppagesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_importstartuppagesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_mathsolverenabled","displayName":"Let users snip a Math problem and get the solution with a step-by-step explanation in Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 125.\r\n\r\nThis policy is obsoleted because Math Solver is deprecated from Edge. This policy won't work in Microsoft Edge version 126. This policy lets you manage whether users can use the Math Solver tool in Microsoft Edge or not.\r\n\r\nIf you enable or don't configure the policy, then a user can take a snip of the Math problem and get the solution including a step-by-step explanation of the solution in a Microsoft Edge side pane.\r\n\r\nIf you disable the policy, then the Math Solver tool will be disabled and users will not be able to use it.\r\n\r\nNote: Setting the 'ComponentUpdatesEnabled' (Enable component updates in Microsoft Edge) policy to disabled will also disable the Math Solver component.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_mathsolverenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_mathsolverenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_recommended_importstartuppagesettings_recommended","displayName":"Allow importing of startup page settings (User)","description":"Allows users to import Startup settings from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the Startup settings are always imported.\r\n\r\nIf you disable this policy, startup settings are not imported at first run or at manual import.\r\n\r\nIf you don't configure this policy, startup settings are imported at first run, and users can choose whether to import this data manually by selecting browser settings option during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge will import startup settings on first run, but users can select or clear **browser settings** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Microsoft Edge Legacy and Google Chrome (on Windows 7, 8, and 10) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_recommended_importstartuppagesettings_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_recommended_importstartuppagesettings_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~applicationguard_applicationguardtrafficidentificationenabled","displayName":"Application Guard Traffic Identification (User)","description":"If you enable or don't configure this policy, Application Guard will add an extra HTTP header (X-MS-ApplicationGuard-Initiated) to all outbound HTTP requests made from the Application Guard container.\r\n\r\nIf you disable this policy, the extra header is not added to the traffic.","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~applicationguard_applicationguardtrafficidentificationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~applicationguard_applicationguardtrafficidentificationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~startup_newtabpagecontentenabled","displayName":"Allow Microsoft content on the new tab page (User)","description":"This policy applies for Microsoft Edge to all profile types, namely unsigned local user profiles, profiles signed in using a Microsoft Account, profiles signed in using Active Directory and profiles signed in using Microsoft Entra ID. The Enterprise new tab page for profiles signed in using Microsoft Entra ID can be configured in the M365 admin portal, but this policy setting takes precedence, so any M365 admin portal configurations will be ignored.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge displays Microsoft content on the new tab page. The user can choose different display options for the content. These options include, but aren't limited to: Content off, Content visible on scroll, Headings only, and Content visible. Enabling this policy doesn't force content to be visible - the user can keep setting their own preferred content position.\r\n\r\nIf you disable this policy, Microsoft Edge doesn't display Microsoft content on the new tab page, the Content control in the NTP settings flyout is disabled and set to \"Content off\", and the Layout control in the NTP settings flyout is disabled and set to \"Custom\".\r\n\r\nRelated policies: 'NewTabPageAllowedBackgroundTypes' (Configure the background types allowed for the new tab page layout), 'NewTabPageQuickLinksEnabled' (Allow quick links on the new tab page)","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~startup_newtabpagecontentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~startup_newtabpagecontentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~startup_newtabpagequicklinksenabled","displayName":"Allow quick links on the new tab page (User)","description":"If you enable or don't configure this policy, Microsoft Edge displays quick links on the new tab page, and the user can interact with the control, turning quick links on and off. Enabling this policy does not force quick links to be visible - the user can continue to turn quick links on and off.\r\n\r\nIf you disable this policy, Microsoft Edge hides quick links on the new tab page and disables the quick links control in the NTP settings flyout.\r\n\r\nThis policy only applies for Microsoft Edge local user profiles, profiles signed in using a Microsoft Account, and profiles signed in using Active Directory. To configure the Enterprise new tab page for profiles signed in using Azure Active Directory, use the M365 admin portal.\r\n\r\nRelated policies: 'NewTabPageAllowedBackgroundTypes' (Configure the background types allowed for the new tab page layout), 'NewTabPageContentEnabled' (Allow Microsoft content on the new tab page)","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~startup_newtabpagequicklinksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~startup_newtabpagequicklinksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled","displayName":"Single sign-on for work or school sites using this profile enabled (User)","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\r\n\r\nIf you disable this policy, non-AAD profiles will not be able to use SSO using other credentials present on the machine. This will also ensure that 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' is turned off.\r\n\r\nIf you enable this policy or don't configure it, non-AAD profiles will be able to use SSO using other credentials present on the machine and 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will continue working.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault","displayName":"Configure Automatic HTTPS (User)","description":"This policy lets you manage settings for 'AutomaticHttpsDefault' (Configure Automatic HTTPS), which switches connections from HTTP to HTTPS.\r\n\r\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\r\n\r\nNote: The 'UpgradeCapableDomains' configuration requires a component list, and will not upgrade these connections if 'ComponentUpdatesEnabled' (Enable component updates in Microsoft Edge) is set to 'Disabled'.\r\n\r\nIf you don't configure this policy, 'AutomaticHttpsDefault' will be enabled, and will only upgrade connections on domains likely to support HTTPS.\r\n\r\nPolicy options mapping:\r\n\r\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\r\n\r\n* UpgradeCapableDomains (1) = Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\r\n\r\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_automatichttpsdefault","displayName":"Configure Automatic HTTPS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_automatichttpsdefault_0","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_automatichttpsdefault_1","displayName":"Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_automatichttpsdefault_2","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_headlessmodeenabled","displayName":"Control use of the Headless Mode (User)","description":"This policy setting lets you decide whether users can launch Microsoft Edge in headless mode.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge allows use of the headless mode.\r\n\r\nIf you disable this policy, Microsoft Edge denies use of the headless mode.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_headlessmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_headlessmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationlocalsitelistexpirationdays","displayName":"Specify the number of days that a site remains on the local IE mode site list (User)","description":"If the 'InternetExplorerIntegrationReloadInIEModeAllowed' (Allow unconfigured sites to be reloaded in Internet Explorer mode) policy is enabled or not configured, users will be able to tell Microsoft Edge to load specific pages in Internet Explorer mode for a limited number of days.\r\n\r\nYou can use this setting to determine how many days that configuration is remembered in the browser. After this period has elapsed, the individual page will no longer automatically load in IE mode.\r\n\r\nIf you disable the 'InternetExplorerIntegrationReloadInIEModeAllowed' policy, this policy has no effect.\r\n\r\nIf you disable or don't configure this policy, the default value of 30 days is used.\r\n\r\nIf you enable this policy, you must enter the number of days for which the sites are retained on the user's local site list in Microsoft Edge. The value can be from 0 to 90 days.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationlocalsitelistexpirationdays_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationlocalsitelistexpirationdays_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationlocalsitelistexpirationdays_internetexplorerintegrationlocalsitelistexpirationdays","displayName":"Specify the number of days that a site remains on the local IE mode site list: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationreloadiniemodeallowed","displayName":"Allow unconfigured sites to be reloaded in Internet Explorer mode (User)","description":"This policy allows users to reload unconfigured sites (that are not configured in the Enterprise Mode Site List) in Internet Explorer mode when browsing in Microsoft Edge and a site requires Internet Explorer for compatibility.\r\n\r\nAfter a site has been reloaded in Internet Explorer mode, \"in-page\" navigations will stay in Internet Explorer mode (for example, a link, script, or form on the page, or a server-side redirect from another \"in-page\" navigation). Users can choose to exit from Internet Explorer mode, or Microsoft Edge will automatically exit from Internet Explorer mode when a navigation that isn't \"in-page\" occurs (for example, using the address bar, the back button, or a favorite link).\r\n\r\nUsers can also optionally tell Microsoft Edge to use Internet Explorer mode for the site in the future. This choice will be remembered for a length of time managed by the 'InternetExplorerIntegrationLocalSiteListExpirationDays' (Specify the number of days that a site remains on the local IE mode site list) policy.\r\n\r\nIf the 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) policy is set to 'IEMode', then sites explicitly configured by the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy's site list to use Microsoft Edge can't be reloaded in Internet Explorer mode, and sites configured by the site list or by the 'SendIntranetToInternetExplorer' (Send all intranet sites to Internet Explorer) policy to use Internet Explorer mode can't exit from Internet Explorer mode.\r\n\r\nIf you enable this policy, users are allowed to reload unconfigured sites in Internet Explorer mode.\r\n\r\nIf you disable this policy, users aren't allowed to reload unconfigured sites in Internet Explorer mode.\r\n\r\nNote that if you enable this policy, it takes precedence over how you configured the 'InternetExplorerIntegrationTestingAllowed' (Allow Internet Explorer mode testing) policy, and that policy will be disabled.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationreloadiniemodeallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationreloadiniemodeallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_aadwebsitessousingthisprofileenabled_recommended","displayName":"Single sign-on for work or school sites using this profile enabled (User)","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\r\n\r\nIf you disable this policy, non-AAD profiles will not be able to use SSO using other credentials present on the machine. This will also ensure that 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' is turned off.\r\n\r\nIf you enable this policy or don't configure it, non-AAD profiles will be able to use SSO using other credentials present on the machine and 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will continue working.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_aadwebsitessousingthisprofileenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_aadwebsitessousingthisprofileenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended","displayName":"Configure Automatic HTTPS (User)","description":"This policy lets you manage settings for 'AutomaticHttpsDefault' (Configure Automatic HTTPS), which switches connections from HTTP to HTTPS.\r\n\r\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\r\n\r\nNote: The 'UpgradeCapableDomains' configuration requires a component list, and will not upgrade these connections if 'ComponentUpdatesEnabled' (Enable component updates in Microsoft Edge) is set to 'Disabled'.\r\n\r\nIf you don't configure this policy, 'AutomaticHttpsDefault' will be enabled, and will only upgrade connections on domains likely to support HTTPS.\r\n\r\nPolicy options mapping:\r\n\r\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\r\n\r\n* UpgradeCapableDomains (1) = Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\r\n\r\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault","displayName":"Configure Automatic HTTPS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault_0","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault_1","displayName":"Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault_2","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_internetexplorerintegrationreloadiniemodeallowed_recommended","displayName":"Allow unconfigured sites to be reloaded in Internet Explorer mode (User)","description":"This policy allows users to reload unconfigured sites (that are not configured in the Enterprise Mode Site List) in Internet Explorer mode when browsing in Microsoft Edge and a site requires Internet Explorer for compatibility.\r\n\r\nAfter a site has been reloaded in Internet Explorer mode, \"in-page\" navigations will stay in Internet Explorer mode (for example, a link, script, or form on the page, or a server-side redirect from another \"in-page\" navigation). Users can choose to exit from Internet Explorer mode, or Microsoft Edge will automatically exit from Internet Explorer mode when a navigation that isn't \"in-page\" occurs (for example, using the address bar, the back button, or a favorite link).\r\n\r\nUsers can also optionally tell Microsoft Edge to use Internet Explorer mode for the site in the future. This choice will be remembered for a length of time managed by the 'InternetExplorerIntegrationLocalSiteListExpirationDays' (Specify the number of days that a site remains on the local IE mode site list) policy.\r\n\r\nIf the 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) policy is set to 'IEMode', then sites explicitly configured by the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy's site list to use Microsoft Edge can't be reloaded in Internet Explorer mode, and sites configured by the site list or by the 'SendIntranetToInternetExplorer' (Send all intranet sites to Internet Explorer) policy to use Internet Explorer mode can't exit from Internet Explorer mode.\r\n\r\nIf you enable this policy, users are allowed to reload unconfigured sites in Internet Explorer mode.\r\n\r\nIf you disable this policy, users aren't allowed to reload unconfigured sites in Internet Explorer mode.\r\n\r\nNote that if you enable this policy, it takes precedence over how you configured the 'InternetExplorerIntegrationTestingAllowed' (Allow Internet Explorer mode testing) policy, and that policy will be disabled.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_internetexplorerintegrationreloadiniemodeallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_internetexplorerintegrationreloadiniemodeallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowed","displayName":"Specifies whether to allow insecure websites to make requests to more-private network endpoints (User)","description":"Controls whether insecure websites are allowed to make requests to more-private network endpoints.\r\n\r\nThis policy relates to the CORS-RFC1918 specification. See https://wicg.github.io/cors-rfc1918 for more details.\r\n\r\nA network endpoint is more private than another if:\r\n1) Its IP address is localhost and the other is not.\r\n2) Its IP address is private and the other is public.\r\nIn the future, depending on spec evolution, this policy might apply to all cross-origin requests directed at private IPs or localhost.\r\n\r\nA website is deemed secure if it meets the definition of a secure context in https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts. Otherwise, it will be treated as an insecure context.\r\n\r\nWhen this policy is either not set or set to false, the default behavior for requests from insecure contexts to more-private network endpoints will depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests feature, which may be set by a field trial or on the command line.\r\n\r\nWhen this policy is set to true, insecure websites are allowed to make requests to any network endpoint, subject to other cross-origin checks.","helpText":"","infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts (User)","description":"List of URL patterns. Private network requests initiated from insecure websites served by matching origins are allowed.\r\n\r\nIf this policy is not set, this policy behaves as if set to the empty list.\r\n\r\nFor origins not covered by the patterns specified here, the global default value will be used either from the 'InsecurePrivateNetworkRequestsAllowed' (Specifies whether to allow insecure websites to make requests to more-private network endpoints) policy, if it is set, or the user's personal configuration otherwise.\r\n\r\nNote that this policy only affects insecure origins, so secure origins (e.g. https://example.com) included in this list will be ignored.\r\n\r\nFor detailed information on valid URL patterns, please see https://docs.microsoft.com/en-us/DeployEdge/edge-learnmmore-url-list-filter%20format.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_insecureprivatenetworkrequestsallowedforurlsdesc","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill (User)","description":"The feature helps users add an additional layer of privacy to their online accounts by requiring device authentication (as a way of confirming the user's identity) before the saved password is auto-filled into a web form. This ensures that non-authorized persons can't use saved passwords for autofill.\r\n\r\nThis group policy configures the radio button selector that enables this feature for users. It also has a frequency control where users can specify how often they would like to be prompted for authentication.\r\n\r\nIf you set this policy to 'Automatically', disable this policy, or don't configure this policy, autofill will not have any authentication flow.\r\n\r\nIf you set this policy to 'WithDevicePassword', users will have to enter their device password (or preferred mode of authentication under Windows) to prove their identity before their password is auto filled. Authentication modes include Windows Hello, PIN, face recognition, or fingerprint. The frequency for authentication prompt will be set to 'Always' by default. However, users can change it to the other option, which is 'Once every browsing session'.\r\n\r\nIf you set this policy to 'WithCustomPrimaryPassword', users will be asked to create their custom password and then to be redirected to Settings. After the custom password is set, users can authenticate themselves using the custom password and their passwords will get auto-filled after successful authentication. The frequency for authentication prompt will be set to 'Always' by default. However, users can change it to the other option, which is 'Once every browsing session'.\r\n\r\nIf you set this policy to 'AutofillOff', saved passwords will no longer be suggested for autofill.\r\n\r\nPolicy options mapping:\r\n\r\n* Automatically (0) = Automatically\r\n\r\n* WithDevicePassword (1) = With device password\r\n\r\n* WithCustomPrimaryPassword (2) = With custom primary password\r\n\r\n* AutofillOff (3) = Autofill off\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_0","displayName":"Automatically","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_1","displayName":"With device password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_2","displayName":"With custom primary password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_3","displayName":"Autofill off","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist","displayName":"Allow media autoplay on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are allowed to autoplay media.\r\n\r\nIf you don't configure this policy, the global default value from the 'AutoplayAllowed' (Allow media autoplay for websites) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nNote: * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist_autoplayallowlistdesc","displayName":"Allow media autoplay on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_cecpq2enabled","displayName":"CECPQ2 post-quantum key-agreement enabled for TLS (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 113.\r\n\r\nThis policy was removed in Microsoft Edge 114 and is ignored if set. It served to disable CECPQ2, but CECPQ2 has been disabled by default. A separate policy will be introduced to control the rollout of the replacement of CECPQ2. That replacement will be a combination of the standard key-agreement X25519 with NIST's chosen post-quantum KEM, called \"Kyber\".\r\n\r\nIf this policy is not configured, or is set to enabled, then Microsoft Edge will follow the default rollout process for CECPQ2, a post-quantum key-agreement algorithm in TLS.\r\n\r\nCECPQ2 results in larger TLS messages which, in very rare cases, can trigger bugs in some networking hardware. This policy can be set to False to disable CECPQ2 while networking issues are resolved.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_cecpq2enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_cecpq2enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_configureviewinfileexplorer","displayName":"Configure the View in File Explorer feature for SharePoint pages in Microsoft Edge (User)","description":"This setting allows you to configure the View in File Explorer capability for file management in SharePoint Online while using Microsoft Edge.\r\n\r\nYou will need to list the specific domains where this is allowed and list cookies needed for SharePoint authentication (rtFa and FedAuth).\r\n\r\nBehind the scenes, the policy allows URLs with the viewinfileexplorer: scheme to open WebDAV URLs in Windows File Explorer on pages matching the list of domains and uses the cookies you specified for WebDAV authentication.\r\n\r\nIf you enable this policy, you can use the \"View in File Explorer\" feature on the SharePoint document libraries you list. You will need to specify the SharePoint domain and authentication cookies. See example value below.\r\n\r\nIf you disable or don't configure this policy, you cannot use the \"View in File Explorer\" feature on SharePoint document libraries.\r\n\r\nNote that while this is an available option through Microsoft Edge, rather than use the View in File Explorer option, the recommended approach to managing files and folders outside of SharePoint is to sync your SharePoint files or move or copy files in SharePoint.\r\nSync your SharePoint files: https://go.microsoft.com/fwlink/p/?linkid=2166983\r\nMove or copy files in SharePoint: https://go.microsoft.com/fwlink/p/?linkid=2167123\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"cookies\": [\r\n \"rtFa\",\r\n \"FedAuth\"\r\n ],\r\n \"domain\": \"contoso.sharepoint.com\"\r\n },\r\n {\r\n \"cookies\": [\r\n \"rtFa\",\r\n \"FedAuth\"\r\n ],\r\n \"domain\": \"contoso2.sharepoint.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_configureviewinfileexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_configureviewinfileexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_configureviewinfileexplorer_configureviewinfileexplorer","displayName":"Configure the View in File Explorer feature for SharePoint pages in Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationcloudsitelist","displayName":"Configure the Enterprise Mode Cloud Site List (User)","description":"The Microsoft Edge Site Lists setting in the M365 Admin Center allows you to host your site list(s) in a compliant cloud location and manage the contents of your site list(s) through the built-in experience. This setting allows you to specify which site list within the M365 Admin Center to deploy to your users. The user must be signed into Microsoft Edge with a valid work or school account. Otherwise, Microsoft Edge will not download the site list from the cloud location.\r\n\r\nThis setting is applicable only when the 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) setting is configured.\r\n\r\nIf you configure this policy, Microsoft Edge will use the specified site list. When enabled, you can enter the identifier of the site list that you created and published to the cloud in M365 Admin Center.\r\n\r\nThis setting takes precedence over Microsoft Edge's 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy as well as Internet Explorer's site list setting (Use the Enterprise mode IE website list). If you disable or don't configure this policy, Microsoft Edge will use the 'InternetExplorerIntegrationSiteList' policy instead.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707\r\n\r\nExample value: aba95e58-070f-4784-8dcd-e5fd46c2c6d6","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationcloudsitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationcloudsitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationcloudsitelist_internetexplorerintegrationcloudsitelist","displayName":"Configure the Enterprise Mode Cloud Site List (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval","displayName":"Configure how frequently the Enterprise Mode Site List is refreshed (User)","description":"This setting lets you specify a custom refresh interval for the Enterprise Mode Site List. The refresh interval is specified in minutes. The minimum refresh interval is 30 minutes.\r\n\r\nThis setting is applicable only when the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) or 'InternetExplorerIntegrationCloudSiteList' (Configure the Enterprise Mode Cloud Site List) setting is configured.\r\n\r\nIf you configure this policy, Microsoft Edge will attempt to retrieve an updated version of the configured Enterprise Mode Site List using the specified refresh interval.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use a default refresh interval, it is 10080 minutes (7 days) starting from version 110 or later, 120 minutes from version 93 to 110, and 30 minutes before version 93.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval_internetexplorerintegrationsitelistrefreshinterval","displayName":"Configure how frequently the Enterprise Mode Site List is refreshed: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_localbrowserdatashareenabled","displayName":"Enable Windows to search local Microsoft Edge browsing data (User)","description":"Enables Windows to index Microsoft Edge browsing data stored locally on the user's device and allows users to find and launch previously stored browsing data directly from Windows features such as the search box on the taskbar in Windows.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will publish local browsing data to the Windows Indexer.\r\n\r\nIf you disable this policy, Microsoft Edge will not share data to the Windows Indexer.\r\n\r\nNote that if you disable this policy, Microsoft Edge will remove the data shared with Windows on the device and stop sharing any new browsing data.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_localbrowserdatashareenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_localbrowserdatashareenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_msawebsitessousingthisprofileallowed","displayName":"Allow single sign-on for Microsoft personal sites using this profile (User)","description":"'Allow single sign-on for Microsoft personal sites using this profile' option allows non-MSA profiles to be able to use single sign-on for Microsoft sites using MSA credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-MSA profiles only.\r\n\r\nIf you disable this policy, non-MSA profiles will not be able to use single sign-on for Microsoft sites using MSA credentials present on the machine.\r\n\r\nIf you enable this policy or don't configure it, users will be able to use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_msawebsitessousingthisprofileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_msawebsitessousingthisprofileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_localbrowserdatashareenabled_recommended","displayName":"Enable Windows to search local Microsoft Edge browsing data (User)","description":"Enables Windows to index Microsoft Edge browsing data stored locally on the user's device and allows users to find and launch previously stored browsing data directly from Windows features such as the search box on the taskbar in Windows.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will publish local browsing data to the Windows Indexer.\r\n\r\nIf you disable this policy, Microsoft Edge will not share data to the Windows Indexer.\r\n\r\nNote that if you disable this policy, Microsoft Edge will remove the data shared with Windows on the device and stop sharing any new browsing data.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_localbrowserdatashareenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_localbrowserdatashareenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_msawebsitessousingthisprofileallowed_recommended","displayName":"Allow single sign-on for Microsoft personal sites using this profile (User)","description":"'Allow single sign-on for Microsoft personal sites using this profile' option allows non-MSA profiles to be able to use single sign-on for Microsoft sites using MSA credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-MSA profiles only.\r\n\r\nIf you disable this policy, non-MSA profiles will not be able to use single sign-on for Microsoft sites using MSA credentials present on the machine.\r\n\r\nIf you enable this policy or don't configure it, users will be able to use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_msawebsitessousingthisprofileallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_msawebsitessousingthisprofileallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_travelassistanceenabled_recommended","displayName":"Enable travel assistance (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105.\r\n\r\nThis policy is obsolete as the feature is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy. It doesn't work in Microsoft Edge after version 105.\r\nConfigure this policy to allow/disallow travel assistance.\r\n\r\nThe travel assistance feature gives helpful and relevant information to a user who performs Travel related task within the browser. This feature provides trusted and validated suggestions / information to the users from across sources gathered by Microsoft.\r\n\r\nIf you enable or don't configure this setting, travel assistance will be enabled for the users when they are performing travel related tasks.\r\n\r\nIf you disable this setting, travel assistance will be disabled and users will not be able to see any travel related recommendations.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_travelassistanceenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_travelassistanceenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended","displayName":"Sets layout for printing (User)","description":"Configuring this policy sets the layout for printing webpages.\r\n\r\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\r\n\r\nIf you enable this policy, the selected option is set as the layout option.\r\n\r\nPolicy options mapping:\r\n\r\n* portrait (0) = Sets layout option as portrait\r\n\r\n* landscape (1) = Sets layout option as landscape\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_printingwebpagelayout","displayName":"Sets layout for printing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_printingwebpagelayout_0","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_printingwebpagelayout_1","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_relaunchwindow","displayName":"Set the time interval for relaunch (User)","description":"Specifies a target time window for the end of the relaunch notification period.\r\n\r\nUsers are notified of the need for a browser relaunch or device restart based on the 'RelaunchNotification' (Notify a user that a browser restart is recommended or required for pending updates) and 'RelaunchNotificationPeriod' (Set the time period for update notifications) policy settings. Browsers and devices are forcibly restarted at the end of the notification period when the 'RelaunchNotification' policy is set to 'Required'. This RelaunchWindow policy can be used to defer the end of the notification period so that it falls within a specific time window.\r\n\r\nIf you don't configure this policy, the default target time window is the whole day (i.e., the end of the notification period is never deferred).\r\n\r\nNote: Though the policy can accept multiple items in entries, all but the first item are ignored.\r\nWarning: Setting this policy may delay application of software updates.\r\n\r\nExample value:\r\n\r\n{\r\n \"entries\": [\r\n {\r\n \"duration_mins\": 240,\r\n \"start\": {\r\n \"hour\": 2,\r\n \"minute\": 15\r\n }\r\n }\r\n ]\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"entries\": [{\"duration_mins\": 240, \"start\": {\"hour\": 2, \"minute\": 15}}]}","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_relaunchwindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_relaunchwindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_relaunchwindow_relaunchwindow","displayName":"Relaunch time window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_remotedebuggingallowed","displayName":"Allow remote debugging (User)","description":"Controls whether users may use remote debugging.\r\n\r\nIf you enable or don't configure this policy, users may use remote debugging by specifying --remote-debug-port and --remote-debugging-pipe command line switches.\r\n\r\nIf you disable this policy, users are not allowed to use remote debugging.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_remotedebuggingallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_remotedebuggingallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_travelassistanceenabled","displayName":"Enable travel assistance (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105.\r\n\r\nThis policy is obsolete as the feature is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy. It doesn't work in Microsoft Edge after version 105.\r\nConfigure this policy to allow/disallow travel assistance.\r\n\r\nThe travel assistance feature gives helpful and relevant information to a user who performs Travel related task within the browser. This feature provides trusted and validated suggestions / information to the users from across sources gathered by Microsoft.\r\n\r\nIf you enable or don't configure this setting, travel assistance will be enabled for the users when they are performing travel related tasks.\r\n\r\nIf you disable this setting, travel assistance will be disabled and users will not be able to see any travel related recommendations.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_travelassistanceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_travelassistanceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_tripledesenabled","displayName":"Enable 3DES cipher suites in TLS (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 96.\r\n\r\n'This policy was removed in version 97 after 3DES was removed from Microsoft Edge.\r\n\r\nIf the policy is set to true, then 3DES cipher suites in TLS will be enabled. If it is set to false, they will be disabled. If the policy is unset, 3DES cipher suites are disabled by default. This policy may be used to temporarily retain compatibility with an outdated server. This is a stopgap measure and the server should be reconfigured.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_tripledesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_tripledesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (User)","description":"Allows you to set whether Microsoft Edge will run the v8 JavaScript engine with JIT (Just In Time) compiler enabled or not.\r\n\r\nDisabling the JavaScript JIT will mean that Microsoft Edge may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Microsoft Edge to render web content in a more secure configuration.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'JavaScriptJitAllowedForSites' (Allow JavaScript to use JIT on these sites) and 'JavaScriptJitBlockedForSites' (Block JavaScript from using JIT on these sites) policies.\r\n\r\nIf you don't configure this policy, JavaScript JIT is enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowJavaScriptJit (1) = Allow any site to run JavaScript JIT\r\n\r\n* BlockJavaScriptJit (2) = Do not allow any site to run JavaScript JIT\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_1","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_2","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitAllowedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT enabled, but fabrikam.com will use the policy from 'DefaultJavaScriptJitSetting' (Control use of JavaScript JIT), if set, or default to JavaScript JIT enabled.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set, otherwise Javascript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_javascriptjitallowedforsitesdesc","displayName":"Allow JavaScript to use JIT on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites","displayName":"Block JavaScript from using JIT on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites which are not allowed to run JavaScript JIT (Just In Time) compiler enabled.\r\n\r\nDisabling the JavaScript JIT will mean that Microsoft Edge may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Microsoft Edge to render web content in a more secure configuration.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitBlockedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT disabled, but fabrikam.com will use the policy from 'DefaultJavaScriptJitSetting' (Control use of JavaScript JIT), if set, or default to JavaScript JIT enabled.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set, otherwise JavaScript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites_javascriptjitblockedforsitesdesc","displayName":"Block JavaScript from using JIT on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_showpdfdefaultrecommendationsenabled","displayName":"Allow notifications to set Microsoft Edge as default PDF reader (User)","description":"This policy setting lets you decide whether employees should receive recommendations to set Microsoft Edge as PDF handler.\r\n\r\nIf you enable or don't configure this setting, employees receive recommendations from Microsoft Edge to set itself as the default PDF handler.\r\n\r\nIf you disable this setting, employees will not receive any notifications from Microsoft Edge to set itself as the default PDF handler.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_showpdfdefaultrecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_showpdfdefaultrecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol","displayName":"Configure users ability to override feature flags (User)","description":"Configures users ability to override state of feature flags.\r\nIf you set this policy to 'CommandLineOverridesEnabled', users can override state of feature flags using command line arguments but not edge://flags page.\r\n\r\nIf you set this policy to 'OverridesEnabled', users can override state of feature flags using command line arguments or edge://flags page.\r\n\r\nIf you set this policy to 'OverridesDisabled', users can't override state of feature flags using command line arguments or edge://flags page.\r\n\r\nIf you don't configure this policy, the behavior is the same as the 'OverridesEnabled'.\r\n\r\nPolicy options mapping:\r\n\r\n* CommandLineOverridesEnabled (2) = Allow users to override feature flags using command line arguments only\r\n\r\n* OverridesEnabled (1) = Allow users to override feature flags\r\n\r\n* OverridesDisabled (0) = Prevent users from overriding feature flags\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"eb6409fc-fb52-413d-ae4b-eff017b52b30","categoryName":"Experimentation","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol","displayName":"Configure users ability to override feature flags (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb6409fc-fb52-413d-ae4b-eff017b52b30","categoryName":"Experimentation","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol_2","displayName":"Allow users to override feature flags using command line arguments only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol_1","displayName":"Allow users to override feature flags","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol_0","displayName":"Prevent users from overriding feature flags","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_implicitsigninenabled","displayName":"Enable implicit sign-in (User)","description":"Configure this policy to allow/disallow implicit sign-in.\r\n\r\nIf you have configured the 'BrowserSignin' (Browser sign-in settings) policy to 'Disable browser sign-in', this policy will not take any effect.\r\n\r\nIf you enable or don't configure this setting, implicit sign-in will be enabled, Edge will attempt to sign the user into their profile based on what and how they sign in to their OS.\r\n\r\nIf you disable this setting, implicit sign-in will be disabled.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_implicitsigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_implicitsigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_oneauthauthenticationenforced","displayName":"OneAuth Authentication Flow Enforced for signin (User)","description":"This policy allows users to decide whether to use the OneAuth library for sign-in and token fetch in Microsoft Edge on Windows 10 RS3 and above.\r\n\r\nIf you disable or don't configure this policy, signin process will use Windows Account Manager. Microsoft Edge would be able to use accounts you logged in to Windows, Microsoft Office, or other Microsoft applications for login, without the needing of password. Or you can provide valid account and password to sign in, which will be stored in Windows Account Manager for future usage. You will be able to investigate all accounts stored in Windows Account Manager through Windows Settings -> Accounts -> Email and accounts page.\r\n\r\nIf you enable this policy, OneAuth authentication flow will be used for account signin. The OneAuth authentication flow has fewer dependencies and can work without Windows shell. The account you use would not be stored in the Email and accounts page.\r\n\r\nThis policy will only take effect on Windows 10 RS3 and above. On Windows 10 below RS3, OneAuth is used for authentication in Microsoft Edge by default.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_oneauthauthenticationenforced_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_oneauthauthenticationenforced_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_passwordgeneratorenabled","displayName":"Allow users to get a strong password suggestion whenever they are creating an account online (User)","description":"Configures the Password Generator Settings toggle that enables/disables the feature for users.\r\n\r\nIf you enable or don't configure this policy, then Password Generator will offer users a strong and unique password suggestion (via a dropdown) on Signup and Change Password pages.\r\n\r\nIf you disable this policy, users will no longer see strong password suggestions on Signup or Change Password pages.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_passwordgeneratorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_passwordgeneratorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill (User)","description":"The feature helps users add an additional layer of privacy to their online accounts by requiring device authentication (as a way of confirming the user's identity) before the saved password is auto-filled into a web form. This ensures that non-authorized persons can't use saved passwords for autofill. Note that this feature does not protect against locally-running malware.\r\n\r\nThis group policy configures the radio button selector that enables this feature for users. It also has a frequency control where users can specify how often they would like to be prompted for authentication.\r\n\r\nIf you set this policy to 'Automatically', disable this policy, or don't configure this policy, autofill will not have any authentication flow.\r\n\r\nIf you set this policy to 'WithDevicePassword', users will have to enter their device password (or preferred mode of authentication under Windows) to prove their identity before their password is auto filled. Authentication modes include Windows Hello, PIN, face recognition, or fingerprint. The frequency for authentication prompt will be set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\r\n\r\nIf you set this policy to 'WithCustomPrimaryPassword', users will be asked to create their custom password and then to be redirected to Settings. After the custom password is set, users can authenticate themselves using the custom password and their passwords will get auto-filled after successful authentication. The frequency for authentication prompt will be set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\r\n\r\nIf you set this policy to 'AutofillOff', saved passwords will no longer be suggested for autofill.\r\n\r\nPolicy options mapping:\r\n\r\n* Automatically (0) = Automatically\r\n\r\n* WithDevicePassword (1) = With device password\r\n\r\n* WithCustomPrimaryPassword (2) = With custom primary password\r\n\r\n* AutofillOff (3) = Autofill off\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_0","displayName":"Automatically","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_1","displayName":"With device password","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout","displayName":"Sets layout for printing (User)","description":"Configuring this policy sets the layout for printing webpages.\r\n\r\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\r\n\r\nIf you enable this policy, the selected option is set as the layout option.\r\n\r\nPolicy options mapping:\r\n\r\n* portrait (0) = Sets layout option as portrait\r\n\r\n* landscape (1) = Sets layout option as landscape\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_printingwebpagelayout","displayName":"Sets layout for printing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_printingwebpagelayout_0","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_printingwebpagelayout_1","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge_webrtcrespectosroutingtableenabled","displayName":"Enable support for Windows OS routing table rules when making peer to peer connections via WebRTC (User)","description":"Controls whether WebRTC will respect the Windows OS routing table rules when making peer to peer connections, thus enabling split tunnel VPNs.\r\n\r\nIf you disable this policy or don't configure it, WebRTC will not consider the routing table and may make peer to peer connections over any available network.\r\n\r\nIf you enable this policy, WebRTC will prefer to make peer to peer connections using the indicated network interface for the remote address as indicated in the routing table.\r\n\r\nThis policy is only available on Windows.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge_webrtcrespectosroutingtableenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge_webrtcrespectosroutingtableenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~applicationguard_applicationguardpassivemodeenabled","displayName":"Ignore Application Guard site list configuration and browse Edge normally (User)","description":"Set whether Edge should ignore the Application Guard site list configuration for trusted and untrusted sites.\r\n\r\nIf you enable this policy, all navigations from Edge, including navigations to untrusted sites, will be accessed normally within Edge without redirecting to the Application Guard container. Note: this policy ONLY impacts Edge, so navigations from other browsers might get redirected to the Application Guard Container if you have the corresponding extensions enabled.\r\n\r\nIf you disable or don't configure this policy, Edge does not ignore the Application Guard site list. If users try to navigate to an untrusted site in the host, the site will open in the container.","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~applicationguard_applicationguardpassivemodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~applicationguard_applicationguardpassivemodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~identity_onlyonpremisesimplicitsigninenabled","displayName":"Only on-premises account enabled for implicit sign-in (User)","description":"Configure this policy to decide whether only on-premises accounts are enabled for implicit sign-in.\r\n\r\nIf you enable this policy, only on-premises accounts will be enabled for implicit sign-in. Microsoft Edge won't attempt to implicitly sign in to MSA or AAD accounts. Upgrade from on-premises accounts to AAD accounts will be stopped as well.\r\n\r\nIf you disable or don't configure this policy, all accounts will be enabled for implicit sign-in.\r\n\r\nThis policy will only take effect when policy 'ConfigureOnPremisesAccountAutoSignIn' (Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account) is enabled and set to 'SignInAndMakeDomainAccountNonRemovable'.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~identity_onlyonpremisesimplicitsigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~identity_onlyonpremisesimplicitsigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_browserlegacyextensionpointsblockingenabled","displayName":"Enable browser legacy extension point blocking (User)","description":"Sets the ProcessExtensionPointDisablePolicy on Microsoft Edge's browser process to block code injection from legacy third party applications.\r\n\r\nIf you enable or don't configure this policy, the ProcessExtensionPointDisablePolicy is applied to block legacy extension points in the browser process.\r\n\r\nIf you disable this policy, the ProcessExtensionPointDisablePolicy is not applied to block legacy extension points in the browser process. This has a detrimental effect on Microsoft Edge's security and stability as unknown and potentially hostile code can load inside Microsoft Edge's browser process. Only turn off the policy if there are compatibility issues with third-party software that must run inside Microsoft Edge's browser process.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_browserlegacyextensionpointsblockingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_browserlegacyextensionpointsblockingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_crossoriginwebassemblymodulesharingenabled","displayName":"Specifies whether WebAssembly modules can be sent cross-origin (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 98.\r\n\r\nSpecifies whether WebAssembly modules can be sent to another window or worker cross-origin. Cross-origin WebAssembly module sharing was deprecated as part of the efforts to deprecate document.domain, see https://github.com/mikewest/deprecating-document-domain. This policy allowed re-enabling of cross-origin WebAssembly module sharing. This policy is obsolete because it was intended to offer a longer transition period in the deprecation process.\r\n\r\nIf you enable this policy, sites can send WebAssembly modules cross-origin\r\nwithout restrictions.\r\n\r\nIf you disable or don't configure this policy, sites can only send\r\nWebAssembly modules to windows and workers in the same origin.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_crossoriginwebassemblymodulesharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_crossoriginwebassemblymodulesharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_displaycapturepermissionspolicyenabled","displayName":"Specifies whether the display-capture permissions-policy is checked or skipped (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109.\r\n\r\nThis policy is obsolete. The policy was a temporary workaround for non-spec-compliant enterprise applications.\r\n\r\nThis policy stopped working in Microsoft Edge 107 and was obsoleted in Microsoft Edge 110.\r\n\r\nThe display-capture permissions-policy gates access to getDisplayMedia(),\r\nas per this spec:\r\nhttps://www.w3.org/TR/screen-capture/#feature-policy-integration\r\nHowever, if this policy is Disabled, this requirement is not enforced,\r\nand getDisplayMedia() is allowed from contexts that would otherwise be\r\nforbidden.\r\n\r\nIf you enable or don't configure this policy, sites can only call getDisplayMedia() from\r\ncontexts which are allowlisted by the display-capture permissions-policy.\r\n\r\nIf you disable this policy, sites can call getDisplayMedia() even from contexts\r\nwhich are not allowlisted by the display-capture permissions policy.\r\nNote that other restrictions may still apply.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_displaycapturepermissionspolicyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_displaycapturepermissionspolicyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenheightadjustment","displayName":"Configure the pixel adjustment between window.open heights sourced from IE mode pages vs. Edge mode pages (User)","description":"This setting lets you specify a custom adjustment to the height of popup windows generated via window.open from the Internet Explorer mode site.\r\n\r\nIf you configure this policy, Microsoft Edge will add the adjustment value to the height, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 5.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window height calculations.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenheightadjustment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenheightadjustment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenheightadjustment_internetexplorerintegrationwindowopenheightadjustment","displayName":"Configure the pixel adjustment between window.open heights sourced from IE mode pages vs. Edge mode pages: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment","displayName":"Configure the pixel adjustment between window.open widths sourced from IE mode pages vs. Edge mode pages (User)","description":"This setting lets you specify a custom adjustment to the width of popup windows generated via window.open from the Internet Explorer mode site.\r\n\r\nIf you configure this policy, Microsoft Edge will add the adjustment value to the width, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 4.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window width calculations.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_internetexplorerintegrationwindowopenwidthadjustment","displayName":"Configure the pixel adjustment between window.open widths sourced from IE mode pages vs. Edge mode pages: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended_visualsearchenabled_recommended","displayName":"Visual search enabled (User)","description":"Visual search lets you quickly explore more related content about entities in an image.\r\n\r\nIf you enable or don't configure this policy, visual search will be enabled via image hover, context menu, and search in sidebar.\r\n\r\nIf you disable this policy, visual search will be disabled and you won't be able to get more info about images via hover, context menu, and search in sidebar.\r\n\r\nNote: Visual Search in Web Capture is still managed by 'WebCaptureEnabled' (Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge) policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended_visualsearchenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended_visualsearchenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended~smartscreen_recommended_newsmartscreenlibraryenabled_recommended","displayName":"Enable new SmartScreen library (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 107.\r\n\r\nThis policy doesn't work because it was only intended to be a short-term mechanism to support the update to a new SmartScreen client.\r\n\r\nAllows the Microsoft Edge browser to load the new SmartScreen library (libSmartScreenN) for any SmartScreen checks on site URLs or application downloads.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will use the new SmartScreen library (libSmartScreenN).\r\n\r\nIf you disable this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nBefore Microsoft Edge version 103, if you don't configure this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.\r\nThis also includes macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended~smartscreen_recommended_newsmartscreenlibraryenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended~smartscreen_recommended_newsmartscreenlibraryenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior","displayName":"Configure ShadowStack crash rollback behavior (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109.\r\n\r\nThis policy is deprecated because it's intended to serve only as a short-term mechanism to give enterprises more time to update their environments and report issues if they are found to be incompatible with Hardware-enforced Stack Protection. It won't work in Microsoft Edge as soon as version 109.\r\n\r\nMicrosoft Edge includes a Hardware-enforced Stack Protection security feature. This feature may result in the browser crashing unexpectedly in cases that do not represent an attempt to compromise the browser's security.\r\n\r\nUsing this policy, you may control the behavior of the Hardware-enforced Stack Protection feature after a crash triggered by this feature is encountered.\r\n\r\nSet this policy to 'Disable' to disable the feature.\r\n\r\nSet this policy to 'DisableUntilUpdate' to disable the feature until Microsoft Edge updates next time.\r\n\r\nSet this policy to 'Enable' to keep the feature enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* Disable (0) = Disable Hardware-enforced Stack Protection\r\n\r\n* DisableUntilUpdate (1) = Disable Hardware-enforced Stack Protection until the next Microsoft Edge update\r\n\r\n* Enable (2) = Enable Hardware-enforced Stack Protection\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_shadowstackcrashrollbackbehavior","displayName":"Configure ShadowStack crash rollback behavior (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_shadowstackcrashrollbackbehavior_0","displayName":"Disable Hardware-enforced Stack Protection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_shadowstackcrashrollbackbehavior_1","displayName":"Disable Hardware-enforced Stack Protection until the next Microsoft Edge update","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_shadowstackcrashrollbackbehavior_2","displayName":"Enable Hardware-enforced Stack Protection","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_visualsearchenabled","displayName":"Visual search enabled (User)","description":"Visual search lets you quickly explore more related content about entities in an image.\r\n\r\nIf you enable or don't configure this policy, visual search will be enabled via image hover, context menu, and search in sidebar.\r\n\r\nIf you disable this policy, visual search will be disabled and you won't be able to get more info about images via hover, context menu, and search in sidebar.\r\n\r\nNote: Visual Search in Web Capture is still managed by 'WebCaptureEnabled' (Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge) policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_visualsearchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_visualsearchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled","displayName":"Allow intranet zone file URL links from Microsoft Edge to open in Windows File Explorer (User)","description":"This setting allows file URL links to intranet zone files from intranet zone HTTPS websites to open Windows File Explorer for that file or directory.\r\n\r\nIf you enable this policy, intranet zone file URL links originating from intranet zone HTTPS pages will open Windows File Explorer to the parent directory of the file and select the file. Intranet zone directory URL links originating from intranet zone HTTPS pages will open Windows File Explorer to the directory with no items in the directory selected.\r\n\r\nIf you disable or don't configure this policy, file URL links will not open.\r\n\r\nMicrosoft Edge uses the definition of intranet zone as configured for Internet Explorer. Note that https://localhost/ is specifically blocked as an exception of allowed intranet zone host, while loopback addresses (127.0.0.*, [::1]) are considered internet zone by default.\r\n\r\nUsers may opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an \"Always open\" checkbox in external protocol dialog) policy is disabled.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~smartscreen_newsmartscreenlibraryenabled","displayName":"Enable new SmartScreen library (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 107.\r\n\r\nThis policy doesn't work because it was only intended to be a short-term mechanism to support the update to a new SmartScreen client.\r\n\r\nAllows the Microsoft Edge browser to load the new SmartScreen library (libSmartScreenN) for any SmartScreen checks on site URLs or application downloads.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will use the new SmartScreen library (libSmartScreenN).\r\n\r\nIf you disable this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nBefore Microsoft Edge version 103, if you don't configure this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.\r\nThis also includes macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~smartscreen_newsmartscreenlibraryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~smartscreen_newsmartscreenlibraryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended","displayName":"Configure when efficiency mode should become active (User)","description":"This policy setting lets you configure when efficiency mode will become active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, the default is for efficiency mode to never become active.\r\n\r\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites).\r\n\r\nSet this policy to 'AlwaysActive' and efficiency mode will always be active.\r\n\r\nSet this policy to 'NeverActive' and efficiency mode will never become active.\r\n\r\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode will become active when the device is unplugged.\r\n\r\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode will become active when the device is unplugged and the battery is low.\r\n\r\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode will take moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode will take additional steps to save battery.\r\n\r\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nIf the device does not have a battery, efficiency mode will never become active in any mode other than 'AlwaysActive' unless the setting or 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is enabled.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\r\n\r\nPolicy options mapping:\r\n\r\n* AlwaysActive (0) = Efficiency mode is always active\r\n\r\n* NeverActive (1) = Efficiency mode is never active\r\n\r\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\r\n\r\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\r\n\r\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_4","displayName":"When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_5","displayName":"When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"This policy setting lets you configure when efficiency mode will become active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, the default is for efficiency mode to never become active.\r\n\r\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites).\r\n\r\nSet this policy to 'AlwaysActive' and efficiency mode will always be active.\r\n\r\nSet this policy to 'NeverActive' and efficiency mode will never become active.\r\n\r\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode will become active when the device is unplugged.\r\n\r\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode will become active when the device is unplugged and the battery is low.\r\n\r\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode will take moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode will take additional steps to save battery.\r\n\r\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nIf the device does not have a battery, efficiency mode will never become active in any mode other than 'AlwaysActive' unless the setting or 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is enabled.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\r\n\r\nPolicy options mapping:\r\n\r\n* AlwaysActive (0) = Efficiency mode is always active\r\n\r\n* NeverActive (1) = Efficiency mode is never active\r\n\r\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\r\n\r\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\r\n\r\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_4","displayName":"When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_5","displayName":"When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_audioprocesshighpriorityenabled","displayName":"Allow the audio process to run with priority above normal on Windows (User)","description":"This policy controls the priority of the audio process on Windows.\r\nIf this policy is enabled, the audio process will run with above normal priority.\r\nIf this policy is disabled, the audio process will run with normal priority.\r\nIf this policy is not configured, the default configuration for the audio process will be used.\r\nThis policy is intended as a temporary measure to give enterprises the ability to\r\nrun audio with higher priority to address certain performance issues with audio capture.\r\nThis policy will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_audioprocesshighpriorityenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_audioprocesshighpriorityenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_autolaunchprotocolscomponentenabled","displayName":"AutoLaunch Protocols Component Enabled (User)","description":"Specifies whether the AutoLaunch Protocols component should be enabled. This component allows Microsoft to provide a list similar to that of the 'AutoLaunchProtocolsFromOrigins' (Define a list of protocols that can launch an external application from listed origins without prompting the user) policy, allowing certain external protocols to launch without prompt or blocking certain protocols (on specified origins). By default, this component is enabled.\r\n\r\nIf you enable or don't configure this policy, the AutoLaunch Protocols component is enabled.\r\n\r\nIf you disable this policy, the AutoLaunch Protocols component is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_autolaunchprotocolscomponentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_autolaunchprotocolscomponentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_forcesynctypes","displayName":"Configure the list of types that are included for synchronization (User)","description":"If you enable this policy all the specified data types will be included for synchronization for Azure AD/Azure AD-Degraded user profiles. This policy can be used to ensure the type of data uploaded to the Microsoft Edge synchronization service.\r\n\r\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", \"history\", \"openTabs\", \"edgeWallet\", \"collections\", \"apps\", and \"edgeFeatureUsage\". The \"edgeFeatureUsage\" data type will be supported starting in Microsoft Edge version 134. Note that these data type names are case sensitive.\r\n\r\nUsers will not be able to override the enabled data types.\r\n\r\nExample value:\r\n\r\nfavorites","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_forcesynctypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_forcesynctypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_forcesynctypes_forcesynctypesdesc","displayName":"Configure the list of types that are included for synchronization (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes","displayName":"Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode (User)","description":"Starting with Microsoft Edge version 96, navigations that switch between Internet Explorer mode and Microsoft Edge will include form data.\r\n\r\nIf you enable this policy, you can specify which data types should be included in navigations between Microsoft Edge and Internet Explorer mode.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use the new behavior of including form data in navigations that change modes.\r\n\r\nTo learn more, see https://go.microsoft.com/fwlink/?linkid=2174004\r\n\r\nPolicy options mapping:\r\n\r\n* IncludeNone (0) = Do not send form data or headers\r\n\r\n* IncludeFormDataOnly (1) = Send form data only\r\n\r\n* IncludeHeadersOnly (2) = Send additional headers only\r\n\r\n* IncludeFormDataAndHeaders (3) = Send form data and additional headers\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes","displayName":"Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_0","displayName":"Do not send form data or headers","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_1","displayName":"Send form data only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_2","displayName":"Send additional headers only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_3","displayName":"Send form data and additional headers","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorermodetoolbarbuttonenabled","displayName":"Show the Reload in Internet Explorer mode button in the toolbar (User)","description":"Set this policy to show the Reload in Internet Explorer mode button in the toolbar. Users can hide the button in the toolbar through edge://settings/appearance. The button will only be shown on the toolbar when the 'InternetExplorerIntegrationReloadInIEModeAllowed' (Allow unconfigured sites to be reloaded in Internet Explorer mode) policy is enabled or if the user has chosen to enable \"Allow sites to be reloaded in Internet Explorer mode\".\r\n\r\nIf you enable this policy, the Reload in Internet mode button is pinned to the toolbar.\r\n\r\nIf you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default. Users can toggle the Show Internet Explorer mode button in edge://settings/appearance.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorermodetoolbarbuttonenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorermodetoolbarbuttonenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended_internetexplorermodetoolbarbuttonenabled_recommended","displayName":"Show the Reload in Internet Explorer mode button in the toolbar (User)","description":"Set this policy to show the Reload in Internet Explorer mode button in the toolbar. Users can hide the button in the toolbar through edge://settings/appearance. The button will only be shown on the toolbar when the 'InternetExplorerIntegrationReloadInIEModeAllowed' (Allow unconfigured sites to be reloaded in Internet Explorer mode) policy is enabled or if the user has chosen to enable \"Allow sites to be reloaded in Internet Explorer mode\".\r\n\r\nIf you enable this policy, the Reload in Internet mode button is pinned to the toolbar.\r\n\r\nIf you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default. Users can toggle the Show Internet Explorer mode button in edge://settings/appearance.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended_internetexplorermodetoolbarbuttonenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended_internetexplorermodetoolbarbuttonenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended","displayName":"Configure when efficiency mode should become active (User)","description":"This policy setting lets you configure when efficiency mode will become active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, the default is for efficiency mode to never become active.\r\n\r\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites).\r\n\r\nSet this policy to 'AlwaysActive' and efficiency mode will always be active.\r\n\r\nSet this policy to 'NeverActive' and efficiency mode will never become active.\r\n\r\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode will become active when the device is unplugged.\r\n\r\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode will become active when the device is unplugged and the battery is low.\r\n\r\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode will take moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode will take additional steps to save battery.\r\n\r\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nIf the device does not have a battery, efficiency mode will never become active in any mode other than 'AlwaysActive' unless the setting or 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is enabled.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\r\n\r\nPolicy options mapping:\r\n\r\n* AlwaysActive (0) = Efficiency mode is always active\r\n\r\n* NeverActive (1) = Efficiency mode is never active\r\n\r\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\r\n\r\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\r\n\r\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended","displayName":"Configure Edge Website Typo Protection (User)","description":"This policy setting lets you configure whether to turn on Edge Website Typo Protection. Edge Website Typo Protection provides warning messages to help protect your users from potential typosquatting sites. By default, Edge Website Typo Protection is turned on.\r\n\r\nIf you enable this policy, Edge Website Typo Protection is turned on.\r\n\r\nIf you disable this policy, Edge Website Typo Protection is turned off.\r\n\r\nIf you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.","helpText":"","infoUrls":[],"categoryId":"1ccd3115-55e7-464f-9bb9-d38a92191306","categoryName":"Edge Website Typo Protection settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_rendererappcontainerenabled","displayName":"Enable renderer in app container (User)","description":"Launches Renderer processes into an App Container for\r\nadditional security benefits.\r\n\r\nIf you don't configure this policy, Microsoft Edge will launch the renderer process in an app\r\ncontainer in a future update.\r\n\r\nIf you enable this policy, Microsoft Edge will launch the renderer process in an app container.\r\n\r\nIf you disable this policy, Microsoft Edge will not launch the renderer process in an app container.\r\n\r\nOnly turn off the policy if there are compatibility issues with\r\nthird-party software that must run inside Microsoft Edge's renderer processes.\r\n\r\nThis policy will only take effect on Windows 10 RS5 and above.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_rendererappcontainerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_rendererappcontainerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_sharedlinksenabled","displayName":"Show links shared from Microsoft 365 apps in History (User)","description":"Allows Microsoft Edge to display links recently shared by or shared with the user from Microsoft 365 apps in History.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge displays links recently shared by or shared with the user from Microsoft 365 apps in History.\r\n\r\nIf you disable this policy, Microsoft Edge does not display links recently shared by or shared with the user from Microsoft 365 apps in History. The control in Microsoft Edge settings is disabled and set to off.\r\n\r\nThis policy only applies for Microsoft Edge local user profiles and profiles signed in using Azure Active Directory.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_sharedlinksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_sharedlinksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~applicationguard_applicationguarduploadblockingenabled","displayName":"Prevents files from being uploaded while in Application Guard (User)","description":"Sets whether files can be uploaded while in Application Guard.\r\n\r\nIf you enable this policy, users will not be able to upload files in Application Guard.\r\n\r\nIf you disable or don't configure this policy, users will be able to upload files while in Application Guard.","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~applicationguard_applicationguarduploadblockingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~applicationguard_applicationguarduploadblockingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"This policy setting lets you configure when efficiency mode will become active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, the default is for efficiency mode to never become active.\r\n\r\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites).\r\n\r\nSet this policy to 'AlwaysActive' and efficiency mode will always be active.\r\n\r\nSet this policy to 'NeverActive' and efficiency mode will never become active.\r\n\r\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode will become active when the device is unplugged.\r\n\r\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode will become active when the device is unplugged and the battery is low.\r\n\r\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode will take moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode will take additional steps to save battery.\r\n\r\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nIf the device does not have a battery, efficiency mode will never become active in any mode other than 'AlwaysActive' unless the setting or 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is enabled.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\r\n\r\nPolicy options mapping:\r\n\r\n* AlwaysActive (0) = Efficiency mode is always active\r\n\r\n* NeverActive (1) = Efficiency mode is never active\r\n\r\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\r\n\r\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\r\n\r\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode","displayName":"Print PostScript Mode (User)","description":"Controls how Microsoft Edge prints on Microsoft Windows.\r\n\r\nPrinting to a PostScript printer on Microsoft Windows different PostScript generation methods can affect printing performance.\r\n\r\nIf you set this policy to Default, Microsoft Edge will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts.\r\n\r\nIf you set this policy to Type42, Microsoft Edge will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\r\n\r\nIf you don't configure this policy, Microsoft Edge will be in Default mode.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default\r\n\r\n* Type42 (1) = Type42\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_printpostscriptmode","displayName":"Print PostScript Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_printpostscriptmode_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_printpostscriptmode_1","displayName":"Type42","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI (User)","description":"Controls print image resolution when Microsoft Edge prints PDFs with rasterization.\r\n\r\nWhen printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution will significantly increase the processing and printing time while a low resolution can lead to poor imaging quality.\r\n\r\nIf you set this policy, it allows a particular resolution to be specified for use when rasterizing PDFs for printing.\r\n\r\nIf you set this policy to zero or don't configure it, the system default resolution will be used during rasterization of page images.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~typosquattingchecker_typosquattingcheckerenabled","displayName":"Configure Edge Website Typo Protection (User)","description":"This policy setting lets you configure whether to turn on Edge Website Typo Protection. Edge Website Typo Protection provides warning messages to help protect your users from potential typosquatting sites. By default, Edge Website Typo Protection is turned on.\r\n\r\nIf you enable this policy, Edge Website Typo Protection is turned on.\r\n\r\nIf you disable this policy, Edge Website Typo Protection is turned off.\r\n\r\nIf you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~typosquattingchecker_typosquattingcheckerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~typosquattingchecker_typosquattingcheckerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_accessibilityimagelabelsenabled","displayName":"Let screen reader users get image descriptions from Microsoft (User)","description":"Lets screen reader users get descriptions of unlabeled images on the web.\r\n\r\nIf you enable or don't configure this policy, users have the option of using an anonymous Microsoft service. This service provides automatic descriptions for unlabeled images users encounter on the web when they're using a screen reader.\r\n\r\nIf you disable this policy, users can't enable the Get Image Descriptions from Microsoft feature.\r\n\r\nWhen this feature is enabled, the content of images that need a generated description is sent to Microsoft servers to generate a description.\r\n\r\nNo cookies or other user data is sent to Microsoft, and Microsoft doesn't save or log any image content.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_accessibilityimagelabelsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_accessibilityimagelabelsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request header support enabled (User)","description":"This policy lets you configure support of CORS non-wildcard request headers.\r\n\r\nMicrosoft Edge version 97 introduces support for CORS non-wildcard request headers. When a script makes a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header must be explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. See https://go.microsoft.com/fwlink/?linkid=2180022 for more detail.\r\n\r\nIf you enable or don't configure the policy, Microsoft Edge will support the CORS non-wildcard request headers and behave as previously described.\r\n\r\nIf you disable this policy, Microsoft Edge will allow the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\r\n\r\nThis policy is a temporary workaround for the new CORS non-wildcard request header feature. It's intended to be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_corsnonwildcardrequestheaderssupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_corsnonwildcardrequestheaderssupport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgediscoverenabled","displayName":"Discover feature In Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105.\r\n\r\nThis policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy.\r\n\r\nThis policy lets you configure the Discover feature in Microsoft Edge.\r\n\r\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\r\n\r\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\r\n\r\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgediscoverenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgediscoverenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgeenhanceimagesenabled","displayName":"Enhance images enabled (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 121.\r\n\r\nThe enhance images feature is deprecated and starting in 122 this policy will be removed. Set whether Microsoft Edge can automatically enhance images to show you sharper images with better color, lighting, and contrast.\r\n\r\nIf you enable this policy or don't configure the policy, Microsoft Edge will automatically enhance images on specific web applications.\r\n\r\nIf you disable this policy, Microsoft Edge will not enhance images.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgeenhanceimagesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgeenhanceimagesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_internetexplorermodetabinedgemodeallowed","displayName":"Allow sites configured for Internet Explorer mode to open in Microsoft Edge (User)","description":"This policy lets sites configured to open in Internet Explorer mode to be opened by Microsoft Edge for testing on a modern browser without removing them from the site list.\r\n\r\nUsers can configure this setting in the \"More tools\" menu by selecting 'Open sites in Microsoft Edge'.\r\n\r\nIf you enable this policy, the option to 'Open sites in Microsoft Edge' will be visible under \"More tools\". Users use this option to test IE mode sites on a modern browser.\r\n\r\nIf you disable or don't configure this policy, users can't see the option 'Open in Microsoft Edge' under the \"More tools\" menu. However, users can access this menu option with the --ie-mode-test flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_internetexplorermodetabinedgemodeallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_internetexplorermodetabinedgemodeallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_openmicrosoftlinksinedgeenabled","displayName":"Always open links from certain Microsoft apps in Microsoft Edge (User)","description":"Make Microsoft Edge open links from other supported Microsoft Apps, such as Microsoft Outlook and Microsoft Teams on Windows 10 and above, so that web links can be opened using the correct profile in Microsoft Edge. This does not change the browser set as the default in Windows settings.\r\n\r\nIf you do not configure this policy, the end user will see a prompt to manage this policy the first time Microsoft Edge opens a link from supported Microsoft apps. Users can manage this policy in Microsoft Edge settings at any time. The default browser setting in Windows will not be changed based on the Microsoft Edge setting.\r\n\r\nIf this policy is Enabled, Microsoft Edge will open web links from these apps, and will use the correct profile where possible, even when Microsoft Edge is not set as the default in Windows settings. This policy does not change the browser set as the default in Windows settings.\r\n\r\nIf this policy is disabled, the browser set as the default in Windows settings will be used to open web links from these apps.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_openmicrosoftlinksinedgeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_openmicrosoftlinksinedgeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended_edgediscoverenabled_recommended","displayName":"Discover feature In Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105.\r\n\r\nThis policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy.\r\n\r\nThis policy lets you configure the Discover feature in Microsoft Edge.\r\n\r\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\r\n\r\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\r\n\r\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended_edgediscoverenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended_edgediscoverenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreendnsrequestsenabled_recommended","displayName":"Enable Microsoft Defender SmartScreen DNS requests (User)","description":"This policy lets you configure whether to enable DNS requests made by Microsoft Defender SmartScreen. Note: Disabling DNS requests will prevent Microsoft Defender SmartScreen from getting IP addresses, and potentially impact the IP-based protections provided.\r\n\r\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen will make DNS requests.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen will not make any DNS requests.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreendnsrequestsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreendnsrequestsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_websqlinthirdpartycontextenabled","displayName":"Force WebSQL in third-party contexts to be re-enabled (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 100.\r\n\r\nThis policy is obsolete because it was intended to be a short-term mechanism to give enterprises more time to update their web content when it's found to be incompatible with the change to disable WebSQL in third-party contexts. It doesn't work in Microsoft Edge after version 100.\r\n\r\nWebSQL in third-party contexts (for example, cross-site iframes) is off by default as of Microsoft Edge version 97 and was fully removed in version 101.\r\n\r\nIf you enable this policy, WebSQL in third-party contexts will be re-enabled.\r\n\r\nIf you disable this policy or don't configure it, WebSQL in third-party contexts will stay off.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_websqlinthirdpartycontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_websqlinthirdpartycontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls","displayName":"Automatically grant sites permission to connect all serial ports (User)","description":"Setting the policy allows you to list sites which are automatically granted permission to access all available serial ports.\r\n\r\nThe URLs must be valid, or the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered.\r\n\r\nThis policy overrides 'DefaultSerialGuardSetting' (Control use of the Serial API), 'SerialAskForUrls' (Allow the Serial API on specific sites), 'SerialBlockedForUrls' (Block the Serial API on specific sites) and the user's preferences.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls_serialallowallportsforurlsdesc","displayName":"Automatically grant sites permission to connect all serial ports (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls","displayName":"Automatically grant sites permission to connect to USB serial devices (User)","description":"Setting the policy lets you list sites that are automatically granted permission to access USB serial devices with vendor and product IDs that match the vendor_id and product_id fields.\r\n\r\nOptionally you can omit the product_id field. This enables site access to all the vendor's devices. When you provide a product ID, then you give the site access to a specific device from the vendor but not all devices.\r\n\r\nThe URLs must be valid, or the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered.\r\n\r\nThis policy overrides 'DefaultSerialGuardSetting' (Control use of the Serial API), 'SerialAskForUrls' (Allow the Serial API on specific sites), 'SerialBlockedForUrls' (Block the Serial API on specific sites) and the user's preferences.\r\n\r\nThis policy only affects access to USB devices through the Web Serial API. To grant access to USB devices through the WebUSB API see the 'WebUsbAllowDevicesForUrls' (Grant access to specific sites to connect to specific USB devices) policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"product_id\": 5678,\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://specific-device.example.com\"\r\n ]\r\n },\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://all-vendor-devices.example.com\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_serialallowusbdevicesforurls","displayName":"Automatically grant sites permission to connect to USB serial devices (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins","displayName":"Allow Same Origin Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'ScreenCaptureAllowed' (Allow or deny screen capture).\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins_sameorigintabcaptureallowedbyoriginsdesc","displayName":"Allow Same Origin Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins","displayName":"Allow Desktop, Window, and Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of Capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in any of the following policies: 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins).\r\n\r\nIf a site matches a URL pattern in this policy, the 'ScreenCaptureAllowed' (Allow or deny screen capture) will not be considered.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins_screencaptureallowedbyoriginsdesc","displayName":"Allow Desktop, Window, and Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins","displayName":"Allow Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can use Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in the 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins) policy.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'ScreenCaptureAllowed' (Allow or deny screen capture).\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins_tabcaptureallowedbyoriginsdesc","displayName":"Allow Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_windowcaptureallowedbyorigins","displayName":"Allow Window and Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can use Window and Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of Capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in any of the following policies: 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins).\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'ScreenCaptureAllowed' (Allow or deny screen capture).\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_windowcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_windowcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_windowcaptureallowedbyorigins_windowcaptureallowedbyoriginsdesc","displayName":"Allow Window and Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~smartscreen_smartscreendnsrequestsenabled","displayName":"Enable Microsoft Defender SmartScreen DNS requests (User)","description":"This policy lets you configure whether to enable DNS requests made by Microsoft Defender SmartScreen. Note: Disabling DNS requests will prevent Microsoft Defender SmartScreen from getting IP addresses, and potentially impact the IP-based protections provided.\r\n\r\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen will make DNS requests.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen will not make any DNS requests.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~smartscreen_smartscreendnsrequestsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~smartscreen_smartscreendnsrequestsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge (User)","description":"This policy lets you enhance the security state in Microsoft Edge.\r\n\r\nIf you set this policy to 'StandardMode', the enhanced mode will be turned off and Microsoft Edge will fallback to its standard security mode.\r\n\r\nIf you set this policy to 'BalancedMode', the security state will be in balanced mode.\r\n\r\nIf you set this policy to 'StrictMode', the security state will be in strict mode.\r\n\r\nIf you set this policy to 'BasicMode', the security state will be in basic mode.\r\n\r\nNote: Sites that use WebAssembly (WASM) are not currently supported when 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2195852\r\n\r\nPolicy options mapping:\r\n\r\n* StandardMode (0) = Standard mode\r\n\r\n* BalancedMode (1) = Balanced mode\r\n\r\n* StrictMode (2) = Strict mode\r\n\r\n* BasicMode (2) = Basic mode\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_0","displayName":"Standard mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_1","displayName":"Balanced mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_2","displayName":"Strict mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_3","displayName":"Basic mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_edgefollowenabled","displayName":"Enable Follow service in Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 126.\r\n\r\nLets Microsoft Edge browser enable Follow service and apply it to users.\r\n\r\nUsers can use the Follow feature for an influencer, site, or topic in Microsoft Edge..\r\n\r\nIf you enable or don't configure this policy, Follow in Microsoft Edge can be applied.\r\n\r\nIf you disable this policy, Microsoft Edge will not communicate with Follow service to provide the follow feature.\r\n\r\nThis policy is obsolete after version 126.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_edgefollowenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_edgefollowenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge (User) (obsolete)","description":"This policy lets you enhance the security state in Microsoft Edge.\r\n\r\nIf you set this policy to 'StandardMode', the enhanced mode will be turned off and Microsoft Edge will fallback to its standard security mode.\r\n\r\nIf you set this policy to 'BalancedMode', the security state will be in balanced mode.\r\n\r\nIf you set this policy to 'StrictMode', the security state will be in strict mode.\r\n\r\nIf you set this policy to 'BasicMode', the security state will be in basic mode.\r\n\r\nNote: Sites that use WebAssembly (WASM) are not supported on 32-bit systems when 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\r\n\r\nStarting in Microsoft Edge 113, 'BasicMode' is deprecated and is treated the same as 'BalancedMode'. It won't work in Microsoft Edge version 116.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895\r\n\r\nPolicy options mapping:\r\n\r\n* StandardMode (0) = Standard mode\r\n\r\n* BalancedMode (1) = Balanced mode\r\n\r\n* StrictMode (2) = Strict mode\r\n\r\n* BasicMode (3) = (Deprecated) Basic mode\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge (User) (obsolete)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_0","displayName":"Standard mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_1","displayName":"Balanced mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_2","displayName":"Strict mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodebypasslistdomains","displayName":"Configure the list of domains for which enhance security mode will not be enforced (User)","description":"Configure the list of enhance security trusted domains. This means that\r\nenhance security mode will not be enforced when loading the sites in trusted domains.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodebypasslistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodebypasslistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodebypasslistdomains_enhancesecuritymodebypasslistdomainsdesc","displayName":"Configure the list of domains for which enhance security mode will not be enforced (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodeenforcelistdomains","displayName":"Configure the list of domains for which enhance security mode will always be enforced (User)","description":"Configure the list of enhance security untrusted domains. This means that\r\nenhance security mode will always be enforced when loading the sites in untrusted domains.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodeenforcelistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodeenforcelistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodeenforcelistdomains_enhancesecuritymodeenforcelistdomainsdesc","displayName":"Configure the list of domains for which enhance security mode will always be enforced (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_inappsupportenabled","displayName":"In-app support Enabled (User)","description":"Microsoft Edge uses the in-app support feature (enabled by default) to allow users to contact our support agents directly from the browser. Also, by default, users can't disable (turn off) the in-app support feature.\r\n\r\nIf you enable this policy or don't configure it, users can invoke in-app support.\r\n\r\nIf you disable this policy, users can't invoke in-app support.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_inappsupportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_inappsupportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_microsoftedgeinsiderpromotionenabled","displayName":"Microsoft Edge Insider Promotion Enabled (User)","description":"Shows content promoting the Microsoft Edge Insider channels on the About Microsoft Edge settings page.\r\n\r\nIf you enable or don't configure this policy, the Microsoft Edge Insider promotion content will be shown on the About Microsoft Edge page.\r\n\r\nIf you disable this policy, the Microsoft Edge Insider promotion content will not be shown on the About Microsoft Edge page.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_microsoftedgeinsiderpromotionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_microsoftedgeinsiderpromotionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_u2fsecuritykeyapienabled","displayName":"Allow using the deprecated U2F Security Key API (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 103.\r\n\r\nThis policy is obsolete because it was intended to be a short-term mechanism to give enterprises more time to update their web content when it's found to be incompatible with the change to remove the U2F Security Key API. It doesn't work in Microsoft Edge after version 103.\r\n\r\nIf you enable this policy, the deprecated U2F Security Key API can be used and the deprecation reminder prompt shown for U2F API requests is suppressed.\r\n\r\nIf you disable this policy or don't configure it, the U2F Security Key API is disabled by default and can only be used by sites that register for and use the U2FSecurityKeyAPI origin trial which ended after Microsoft Edge version 103.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_u2fsecuritykeyapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_u2fsecuritykeyapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings","displayName":"Print preview sticky settings (User)","description":"Specifies whether print preview should apply last used settings for Microsoft Edge PDF and webpages.\r\n\r\nIf you set this policy to 'EnableAll' or don't configure it, Microsoft Edge applies the last used print preview settings for both PDF and webpages.\r\n\r\nIf you set this policy to 'DisableAll', Microsoft Edge doesn't apply the last used print preview settings for both PDF and webpages.\r\n\r\nIf you set this policy to 'DisablePdf', Microsoft Edge doesn't apply the last used print preview settings for PDF printing and retains it for webpages.\r\n\r\nIf you set this policy to 'DisableWebpage', Microsoft Edge doesn't apply the last used print preview settings for webpage printing and retain it for PDF.\r\n\r\nThis policy is only available if you enable or don't configure the 'PrintingEnabled' (Enable printing) policy.\r\n\r\nPolicy options mapping:\r\n\r\n* EnableAll (0) = Enable sticky settings for PDF and Webpages\r\n\r\n* DisableAll (1) = Disable sticky settings for PDF and Webpages\r\n\r\n* DisablePdf (2) = Disable sticky settings for PDF\r\n\r\n* DisableWebpage (3) = Disable sticky settings for Webpages\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_printstickysettings","displayName":"Print preview sticky settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_printstickysettings_0","displayName":"Enable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_printstickysettings_1","displayName":"Disable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_printstickysettings_2","displayName":"Disable sticky settings for PDF","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_printstickysettings_3","displayName":"Disable sticky settings for Webpages","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_addressbareditingenabled","displayName":"Configure address bar editing (User)","description":"If you enable or don't configure this policy, users can change the URL in the address bar.\r\n\r\nIf you disable this policy, it prevents users from changing the URL in the address bar.\r\n\r\nNote: This policy doesn't prevent the browser from navigating to any URL. Users can still navigate to any URL by using the search option in the default New Tab Page, or using any link that leads to a web search engine. To ensure that users can only go to sites you expect, consider configuring the following policies in addition to this policy:\r\n\r\n- 'NewTabPageLocation' (Configure the new tab page URL)\r\n\r\n- 'HomepageLocation' (Configure the home page URL)\r\n\r\n- 'HomepageIsNewTabPage' (Set the new tab page as the home page)\r\n\r\n- 'URLBlocklist' (Block access to a list of URLs) and 'URLAllowlist' (Define a list of allowed URLs) to scope the pages that browser can navigate to.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_addressbareditingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_addressbareditingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_allowgamesmenu","displayName":"Allow users to access the games menu (User)","description":"If you enable or don't configure this policy, users can access the games menu.\r\n\r\nIf you disable this policy, users won't be able to access the games menu.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_allowgamesmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_allowgamesmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins","displayName":"Define a list of protocols that can not be silently blocked by anti-flood protection (User)","description":"Allows you to create a list of protocols, and for each protocol an associated list of allowed origin patterns. These origins won't be silently blocked from launching an external application by anti-flood protection. The trailing separator shouldn't be included when listing the protocol. For example, list \"skype\" instead of \"skype:\" or \"skype://\".\r\n\r\nIf you configure this policy, a protocol will only be permitted to bypass being silently blocked by anti-flood protection if:\r\n\r\n- the protocol is listed\r\n\r\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\r\n\r\nIf either condition is false, the external protocol launch may be blocked by anti-flood protection.\r\n\r\nIf you don't configure this policy, no protocols can bypass being silently blocked.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' (Block access to a list of URLs) policy, that are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\n\r\nThis policy doesn't work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"protocol\": \"spotify\",\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"msteams\",\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"msoutlook\",\r\n \"allowed_origins\": [\r\n \"*\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_donotsilentlyblockprotocolsfromorigins","displayName":"Define a list of protocols that can not be silently blocked by anti-flood protection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_hubssidebarenabled","displayName":"Show Hubs Sidebar (User)","description":"Shows a launcher bar on the right side of Microsoft Edge's screen.\r\n\r\nEnable this policy to always show the Sidebar.\r\nDisable this policy to never show the Sidebar.\r\n\r\nIf you don't configure the policy, users can choose whether to show the Sidebar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_hubssidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_hubssidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting","displayName":"Configure reporting of potentially misconfigured neutral site URLs to the M365 Admin Center Site Lists app (User)","description":"This setting lets you enable reporting of sites that might need to be configured as a neutral site on the Enterprise Mode Site List. The user must be signed into Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant specified by the policy.\r\n\r\nIf you configure this policy, Microsoft Edge will send a report to the M365 Admin Center Site Lists app when a navigation appears stuck redirecting back and forth between the Microsoft Edge and Internet Explorer engines several times. This usually indicates that redirection to an authentication server is switching engines, which repeatedly fails in a loop. The report will show the URL of the site that is the redirect target, minus any query string or fragment. The user's identity isn't reported.\r\n\r\nFor this reporting to work correctly, you must have successfully visited the Microsoft Edge Site Lists app in the M365 Admin Center at least once. This activates a per-tenant storage account used to store these reports. Microsoft Edge will still attempt to send reports if this step hasn't been completed. However, the reports will not be stored in the Site Lists app.\r\n\r\nWhen enabling this policy, you must specify your O365 tenant ID. To learn more about finding your O365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will never send reports about potentially misconfigured neutral sites to the Site Lists app.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707\r\n\r\nExample value: aba95e58-070f-4784-8dcd-e5fd46c2c6d6","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting_internetexplorerintegrationcloudneutralsitesreporting","displayName":"Configure reporting of potentially misconfigured neutral site URLs to the M365 Admin Center Site Lists app (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting","displayName":"Configure reporting of IE Mode user list entries to the M365 Admin Center Site Lists app (User)","description":"This setting lets you enable reporting of sites that Microsoft Edge users add to their local IE Mode site list. The user must be signed into Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant specified by the policy.\r\n\r\nIf you configure this policy, Microsoft Edge will send a report to the M365 Admin Center Site Lists app when a user adds a site to their local IE mode site list. The report will show the URL of the site the user added, minus any query string or fragment. The user's identity isn't reported.\r\n\r\nFor this reporting to work correctly, you must have successfully visited the Microsoft Edge Site Lists app in the M365 Admin Center at least once. This activates a per-tenant storage account used to store these reports. Microsoft Edge will still attempt to send reports if this step hasn't been completed. However, the reports will not be stored in the Site Lists app.\r\n\r\nWhen enabling this policy, you must specify your O365 tenant ID. To learn more about finding your O365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will never send reports about URLs added to a user's local site list to the Site Lists app.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707\r\n\r\nExample value: aba95e58-070f-4784-8dcd-e5fd46c2c6d6","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting_internetexplorerintegrationcloudusersitesreporting","displayName":"Configure reporting of IE Mode user list entries to the M365 Admin Center Site Lists app (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended","displayName":"Show Hubs Sidebar (User)","description":"Shows a launcher bar on the right side of Microsoft Edge's screen.\r\n\r\nEnable this policy to always show the Sidebar.\r\nDisable this policy to never show the Sidebar.\r\n\r\nIf you don't configure the policy, users can choose whether to show the Sidebar.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended~identity_recommended_signinctaonntpenabled_recommended","displayName":"Enable sign in click to action dialog (User)","description":"Configure this policy to show sign in click to action dialog on New tab page.\r\n\r\nIf you enable or don't configure this policy, sign in click to action dialog is shown on New tab page.\r\n\r\nIf you disable this policy, sign in click to action dialog isn't shown on the New tab page.","helpText":"","infoUrls":[],"categoryId":"04b46099-4ee5-4def-8e04-569c988057a9","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended~identity_recommended_signinctaonntpenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended~identity_recommended_signinctaonntpenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_relatedmatchescloudserviceenabled","displayName":"Configure Related Matches in Find on Page (User)","description":"Specifies how the user receives related matches in Find on Page, which provides spellcheck, synonyms, and Q&A results in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, users can receive related matches in Find on Page on all sites. The results are processed in a cloud service.\r\n\r\nIf you disable this policy, users can receive related matches in Find on Page on limited sites. The results are processed on the user's device.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_relatedmatchescloudserviceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_relatedmatchescloudserviceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_sandboxexternalprotocolblocked","displayName":"Allow Microsoft Edge to block navigations to external protocols in a sandboxed iframe (User)","description":"Microsoft Edge will block navigations to external protocols inside a\r\nsandboxed iframe.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will block those navigations.\r\n\r\nIf you disable this policy, Microsoft Edge will not block those navigations.\r\n\r\nThis can be used by administrators who need more time to update their internal website affected by this new restriction. This Enterprise policy is temporary; it's intended to be removed after Microsoft Edge version 104.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_sandboxexternalprotocolblocked_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_sandboxexternalprotocolblocked_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction","displayName":"Enable or disable the User-Agent Reduction (User)","description":"The User-Agent HTTP request header is scheduled to be reduced. To facilitate testing and compatibility, this policy can enable the reduction feature for all websites, or disable the ability for origin trials, or field trials to enable the feature.\r\n\r\nIf you don't configure this policy or set it to Default, User-Agent will be controlled by experimentation.\r\n\r\nSet this policy to 'ForceEnabled' to force the reduced version of the User-Agent request header.\r\n\r\nSet this policy to 'ForceDisabled' to force the full version of the User-Agent request header.\r\n\r\nTo learn more about the User-Agent string, read here:\r\n\r\nhttps://docs.microsoft.com/en-us/microsoft-edge/web-platform/user-agent-guidance.\r\n\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = User-Agent reduction will be controllable via Experimentation\r\n\r\n* ForceDisabled (1) = User-Agent reduction diabled, and not enabled by Experimentation\r\n\r\n* ForceEnabled (2) = User-Agent reduction will be enabled for all origins\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_useragentreduction","displayName":"Enable or disable the User-Agent Reduction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_useragentreduction_0","displayName":"User-Agent reduction will be controllable via Experimentation","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_useragentreduction_1","displayName":"User-Agent reduction diabled, and not enabled by Experimentation","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_useragentreduction_2","displayName":"User-Agent reduction will be enabled for all origins","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist","displayName":"Configure the list of domains for which the password manager UI (Save and Fill) will be disabled (User)","description":"Configure the list of domains where Microsoft Edge should disable the password manager. This means that Save and Fill workflows will be disabled, ensuring that passwords for those websites can't be saved or auto filled into web forms.\r\n\r\nIf you enable this policy, the password manager will be disabled for the specified set of domains.\r\n\r\nIf you disable or don't configure this policy, password manager will work as usual for all domains.\r\n\r\nIf you configure this policy, that is, add domains for which password manager is blocked, users can't change or override the behavior in Microsoft Edge. In addition, users can't use password manager for those URLs.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com/\r\nhttps://login.contoso.com","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist_passwordmanagerblocklistdesc","displayName":"Configure the list of domains for which the password manager UI (Save and Fill) will be disabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":null},{"id":"user_vendor_msft_policy_config_notifications_disallownotificationmirroring","displayName":"Disallow Notification Mirroring (User)","description":"Boolean value that turns off notification mirroring. For each user logged into the device, if you enable this policy (set value to 1) the app and system notifications received by this user on this device will not get mirrored to other devices of the same logged in user. If you disable or do not configure this policy (set value to 0) the notifications received by this user on this device will be mirrored to other devices of the same logged in user. This feature can be turned off by apps that do not want to participate in Notification Mirroring. This feature can also be turned off by the user in the Cortana setting page. No reboot or service restart is required for this policy to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Notifications#disallownotificationmirroring"],"categoryId":"cb1e177e-8f06-4a69-8215-ec1e91c19e30","categoryName":"Notifications","options":[{"id":"user_vendor_msft_policy_config_notifications_disallownotificationmirroring_0","displayName":"Block","description":"Enable notification mirroring.","helpText":null},{"id":"user_vendor_msft_policy_config_notifications_disallownotificationmirroring_1","displayName":"Allow","description":"Disable notification mirroring.","helpText":null}]},{"id":"user_vendor_msft_policy_config_notifications_disallowtilenotification","displayName":"Disallow Tile Notification (User)","description":"This policy setting turns off tile notifications. If you enable this policy setting, applications and system features will not be able to update their tiles and tile badges in the Start screen. If you disable or do not configure this policy setting, tile and badge notifications are enabled and can be turned off by the administrator or user. No reboots or service restarts are required for this policy setting to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Notifications#disallowtilenotification"],"categoryId":"cb1e177e-8f06-4a69-8215-ec1e91c19e30","categoryName":"Notifications","options":[{"id":"user_vendor_msft_policy_config_notifications_disallowtilenotification_0","displayName":"Block","description":"Disabled.","helpText":null},{"id":"user_vendor_msft_policy_config_notifications_disallowtilenotification_1","displayName":"Allow","description":"Enabled.","helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicy","displayName":"Age out documents older than n days (User)","description":"This policy controls when locally cached Office documents are aged out of the Office Document Cache","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicy_l_ageoutpolicydecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_evictserverversionspolicy","displayName":"Age out the locally cached copies of server document versions that are more than n days old. (User)","description":"\r\n This policy controls when locally cached Office version documents from the server are aged out of the local cache.\r\n\r\n If you enable this policy setting, Office document versions from the server that have been locally cached for more than n days, will be deleted from the local cache.\r\n\r\n If you disable or do not configure this policy setting, Office document versions from the server that have been locally cached, will be deleted from the local cache if older than the default of one day.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_evictserverversionspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_evictserverversionspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_evictserverversionspolicy_l_evictserverversionspolicydecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_maximplicitcachesize","displayName":"Set the max size of the Office Document Cache (User)","description":"This policy controls how large the user's Office Document Cache can be. It does not apply to explicitly cached files on \"OneDrive for Business Client\" and \"OneDrive (consumer) Client\".","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_maximplicitcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_maximplicitcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_maximplicitcachesize_l_maximplicitcachesizedecimal","displayName":"Percent of disk space (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_opendirectlyinapp","displayName":"Open Directly in Office Client Application (User)","description":"This policy allows the admin to choose whether Office documents located on web servers open up directly in the App or go via the web browser","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_opendirectlyinapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_opendirectlyinapp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps","displayName":"Apps blocked by Writing Assistance admin policy (User)","description":"This policy setting allows administrators to specify a list of applications where Writing Assistance will be blocked.\nIf you enable this policy setting, enter one application executable name per line (e.g., notepad.exe). Writing Assistance will be disabled in those applications.\nIf you disable or do not configure this policy setting, Writing Assistance will not be blocked by this policy in any application.\n ","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps_l_writingassistantadminblockedappslistid","displayName":"Blocked application names (e.g., notepad.exe) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedurls","displayName":"Web pages blocked by Writing Assistance admin policy (User)","description":"This policy setting allows administrators to specify a list of web page URL patterns where Writing Assistance will be blocked.\nIf you enable this policy setting, enter one URL pattern per line (e.g., example.com). Writing Assistance will be disabled on pages matching those patterns.\nIf you disable or do not configure this policy setting, Writing Assistance will not be blocked by this policy on any web page.\n ","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedurls_l_writingassistantadminblockedurlslistid","displayName":"Blocked URL patterns (e.g., example.com) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblocklistlocked","displayName":"Lock Writing Assistance admin blocklist (User)","description":"This policy setting controls whether users can modify the admin-managed Writing Assistance blocklist.\nIf you enable this policy setting (or do not configure it), the admin blocklist is locked and users cannot remove entries from it.\nIf you disable this policy setting, users can remove individual entries from the admin-provided blocklist.\n ","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblocklistlocked_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblocklistlocked_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice","displayName":"Writing Assistance First Run Experience Mode (User)","description":"This policy setting controls the Writing Assistance first run experience (FRE).If you enable this policy setting, choose one of the following options:Skip FRE entirely - Writing Assistance marks the first run experience as completed without showing it.Informational only - Writing Assistance shows the first run experience once without requiring user approval or sign-in. The experience is marked completed immediately, uses Next on page 1 and Okay on page 2, removes No Thanks, and is still completed if the user dismisses it.Approval required - Writing Assistance keeps the existing approval-required first run experience behavior.If you disable or don’t configure this policy setting, Writing Assistance uses the existing default first run experience behavior.Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for Enterprise.","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice_l_writingassistantfirstrunexperienceadminchoicedropid","displayName":"Configure Writing Assistance First Run Experience Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice_l_writingassistantfirstrunexperienceadminchoicedropid_0","displayName":"Skip FRE entirely","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice_l_writingassistantfirstrunexperienceadminchoicedropid_1","displayName":"Informational only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice_l_writingassistantfirstrunexperienceadminchoicedropid_2","displayName":"Approval required","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice","displayName":"Configure Writing Assistance installation and startup (User)","description":"This policy setting controls whether Writing Assistance is not installed, installed without launching automatically at startup and locked off, installed without launching automatically at startup but still user-controllable, installed and allowed to launch automatically at startup and locked on, or installed with startup on by default but still user-controllable.\n\nIf you enable this policy setting, choose one of the following options:\n- Not installed: Writing Assistance is removed and should not appear in Start.\n- Installed, don't launch at startup: Writing Assistance remains installed, but automatic startup launches are blocked and users cannot turn startup back on.\n- Installed, don't launch at startup by default (users can enable): Writing Assistance remains installed, automatic startup launches are off by default, and users can turn startup on later.\n- Installed, launch at startup: Writing Assistance remains installed, automatic startup launches are allowed, and users cannot turn startup off.\n- Installed, launch at startup by default (users can disable): Writing Assistance remains installed, automatic startup launches are on by default, and users can turn startup off later.\n\nIf you disable or don't configure this policy setting, Writing Assistance follows its default install and startup behavior, and users can control startup themselves.\n\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for Enterprise.\n ","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_l_writingassistantinstallandstartupadminchoiceenum","displayName":"Configure Writing Assistance Install and Startup Behavior (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_l_writingassistantinstallandstartupadminchoiceenum_0","displayName":"Not installed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_l_writingassistantinstallandstartupadminchoiceenum_1","displayName":"Installed, don't launch at startup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_l_writingassistantinstallandstartupadminchoiceenum_3","displayName":"Installed, don't launch at startup by default (users can enable)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_l_writingassistantinstallandstartupadminchoiceenum_2","displayName":"Installed, launch at startup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_l_writingassistantinstallandstartupadminchoiceenum_4","displayName":"Installed, launch at startup by default (users can disable)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v10~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_allownonadminuserinstalllaps","displayName":"Allow users who aren’t admins to install language accessory packs (User)","description":"This policy setting controls whether users can install language accessory packs for Office even if they don’t have local administrator permissions on their devices. By default, users must have local administrator permissions on their devices to install language accessory packs.\r\n\r\nIf you enable this policy setting, users will be able to install language accessory packs for Office even if they don’t have local administrator permissions on their devices. They can install those language accessory packs by going to File > Options > Language in the app, such as Word.\r\n\r\nIf you disable or don’t configure this policy setting, users who don’t have local administrator permissions on their devices won’t be able to install language accessory packs. Someone with local administrator permissions on the device will need to install the language accessory packs for the user.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2161939.\r\n ","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v10~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_allownonadminuserinstalllaps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v10~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_allownonadminuserinstalllaps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_miscellaneous437_l_officerecommendeddocuments","displayName":"Show recommended files on the File tab or start page (User)","description":"This policy setting allows you to control whether users see a list of recommended files on the File tab or start page in Word, Excel, and PowerPoint, on devices running Windows.\r\n\r\nIf you enable this policy setting, users will see a list of recommended files on the File tab or start page.\r\n\r\nIf you disable this policy setting, users won't see a list of recommended files on the File tab or start page.\r\n\r\nIf you don't configure this policy setting, users will see a list of recommended files on the File tab or start page.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2146780.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_miscellaneous437_l_officerecommendeddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_miscellaneous437_l_officerecommendeddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_services_l_officeenableautoalttext","displayName":"Automatically generate alternative text (alt text) for pictures (User)","description":"This policy setting controls whether alternative text (alt text) is generated automatically for pictures in Word, PowerPoint, and Outlook.\r\n\r\nThis policy setting is related to the \"Automatically generate alt text for me\" check box under File > Options > Ease of Access > Automatic Alt Text.\r\n\r\nIf you enable this policy setting, alt text will be generated automatically for pictures. The \"Automatically generate alt text for me\" check box will be selected and users won't be able to clear the check box.\r\n\r\nIf you disable this policy setting, alt text won't be generated automatically for pictures. The \"Automatically generate alt text for me\" check box won't be selected and users won't be able to select the check box.\r\n\r\nIf you don't configure this policy setting, alt text will be generated automatically for pictures. But, users will be able to clear the \"Automatically generate alt text for me\" check box.\r\n ","helpText":"","infoUrls":[],"categoryId":"478ed057-8ee7-4dd2-8276-06dad8f85397","categoryName":"Services","options":[{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_services_l_officeenableautoalttext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_services_l_officeenableautoalttext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicylocalversioning","displayName":"Number of days to keep local document versions in the local cache (User)","description":"This policy controls how long local document versions are kept in the local cache. The default setting is 30 days and applies to Word, Excel, and PowerPoint. \r\n\r\nIf you enable this policy setting, local document versions will be kept for the number of days specified, after which they’ll be deleted from the local cache. You can configure the setting with a value from 1 to 30.\r\n\r\nIf you disable or don’t configure this policy setting, local document versions will be kept for 30 days, after which they’ll be deleted from the local cache.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicylocalversioning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicylocalversioning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicylocalversioning_l_ageoutpolicylocalversioningdecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains","displayName":"Turn off roaming of file names and metadata by server domain. (User)","description":"\r\nThis policy setting controls whether file names and metadata for Office files are roamed and appear in the list of recently opened files in an Office app, such as Word, on different devices.\r\n\r\nRoaming, which relies on a web-based Microsoft service, occurs when a user signs into Office with the same work or school account on different devices.\r\n\r\nNote: This policy is applied to any Office files stored on a specified list of server domains. The set of disallowed domains is a semicolon separated list: \"*.contoso.com;service.microsoft.com\".\r\n\r\nIf you enable this policy setting, file names and metadata won't roam and won’t appear in the list of recently opened files in Office apps on other devices, unless the file has been opened on that device.\r\n\r\nIf you disable or don't configure this policy setting, file names and metadata will roam and will appear in the list of recently opened files in Office apps on other devices, even if the file hasn’t been opened on that device.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains_l_disalloweddomainlist","displayName":"Disallowed Domains: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthpromptbehavior","displayName":"Allow specified hosts to show Basic Authentication prompts to Office apps (User)","description":"This policy setting allows you to specify which hosts can show Basic Authentication sign-in prompts to Office apps.\r\n\r\nBy default, all Basic Authentication sign-in prompts are blocked, and the user is shown a message that the sign-in method isn’t allowed.\r\n\r\nIf you enable this policy setting, you need to enter the hosts by name, separating the host names with a semi-colon. For example: server1.contoso.com; server2.fabrikam.com.\r\n\r\nWarning: Allowing Basic Authentication sign-in prompts isn’t recommended because it’s a security risk.\r\n\r\nBasic Authentication sign-in prompts from all other hosts will be blocked and the user will be shown a message that the sign-in method isn’t allowed.\r\n\r\nIf you disable or don’t configure this policy setting, all Basic Authentication sign-in prompts will be blocked, and the user will be shown a message that the sign-in method isn’t allowed.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2199001.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthpromptbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthpromptbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthpromptbehavior_l_authenticationbasicauthenabledhostsid","displayName":"Host names: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthproxybehavior","displayName":"Allow Basic Authentication prompts from network proxies (User)","description":"This policy setting controls whether network proxies are allowed to show Basic Authentication prompts.\r\n\r\nBy default, all Basic Authentication sign-in prompts are blocked, and the user is shown a message that the sign-in method isn’t allowed.\r\n\r\nIf you enable this policy setting, then network proxies will be allowed to show Basic Authentication prompts.\r\n\r\nWarning: Allowing Basic Authentication sign-in prompts isn’t recommended because it’s a security risk.\r\n\r\nIf you disable or don’t configure this policy setting, all Basic Authentication sign-in prompts from network proxes will be blocked, and the user will be shown a message that the sign-in method isn’t allowed.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2199001.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthproxybehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthproxybehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_pdfandxps_l_pdfprotectionfromoffice","displayName":"Use the Sensitivity feature in Office to apply sensitivity labels to PDFs (User)","description":"This policy setting controls whether sensitivity labels powered by Microsoft Purview Information Protection are applied to PDFs created in Word, Excel, and PowerPoint.​\r\n\r\nIf you enable this policy setting or don’t configure it, PDFs will inherit the sensitivity label and encryption from the source Word, Excel, and PowerPoint document.\r\n\r\nIf you disable this policy setting, PDFs created in Word, Excel, and PowerPoint do not inherit their source file’s sensitivity labels and encryption. When the source file is encrypted, users who do not have the rights to remove protection cannot export to PDF.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise. For more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2220953.","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_pdfandxps_l_pdfprotectionfromoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_pdfandxps_l_pdfprotectionfromoffice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_securitysettings_l_aipexception","displayName":"Use the Azure Information Protection add-in for sensitivity labeling (User)","description":"This policy setting controls whether the Microsoft Azure Information Protection add-in can be used rather than the default of built-in labeling to view and apply sensitivity labels in Office apps. It applies only to subscription versions of Office, such as Microsoft 365 Apps for enterprise.​\r\n\r\nIf you enable this policy setting and the Microsoft Azure Information Protection unified labeling client is installed, the add-in from that client replaces the default labeling built into Office apps.\r\n\r\nIf you disable this policy setting or don’t configure it, the default labeling experience that’s built-in for Office apps is used to view and apply sensitivity labels.​\r\n\r\nFor more information about this setting, see https://go.microsoft.com/fwlink/p/?linkid=2207430.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_securitysettings_l_aipexception_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_securitysettings_l_aipexception_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice","displayName":"Choose which browser opens web links (User)","description":"This policy controls which browser will open web links from within supported Microsoft 365 apps. By default, web links will open in Microsoft Edge.\r\n\r\nNote: This policy doesn’t override any user settings or policies that specify that document links should open in the desktop apps instead of their web app counterparts.\r\n\r\nIf you enable this policy, you can choose either “System default browser” or a specific browser, such as “Microsoft Edge.” “System default browser” refers to the browser setting specified on the user’s Windows device.\r\n\r\nIf you disable or don’t configure this policy, web links will open in Microsoft Edge. The user can set their preferred browser from the settings for the specific Microsoft 365 app.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2224834.","helpText":"","infoUrls":[],"categoryId":"94ce8206-be22-496c-aa72-f3560e2a5c8d","categoryName":"Links","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_l_browserchoiceenum","displayName":"Browser: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"94ce8206-be22-496c-aa72-f3560e2a5c8d","categoryName":"Links","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_l_browserchoiceenum_0","displayName":"System default browser","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_l_browserchoiceenum_1","displayName":"Microsoft Edge","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm","displayName":"Encryption mode for Information Rights Management (IRM) (User)","description":"If you enable this policy setting, you can choose from two options for controlling the encryption mode that Excel, PowerPoint, Word, Visio, and Outlook applications use to protect content with Information Rights Management (IRM):\r\n\r\n- Electronic Codebook (ECB) – ECB mode is always used when applying IRM encryption.\r\n- Cipher Block Chaining (CBC) – CBC mode is always used when applying IRM encryption.\r\n\r\nIf you disable or don't configure this policy setting:\r\n\r\n- For Microsoft 365 Apps (Version 2304 or later): Cipher Block Chaining (CBC) mode is used.\r\n- For earlier Microsoft 365 Apps and Office LTSC 2021, 2019, and 2016: Electronic Codebook (ECB) mode is used.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_l_encryptiontypeforirmcolon","displayName":"IRM Encryption Mode: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_l_encryptiontypeforirmcolon_1","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_l_encryptiontypeforirmcolon_2","displayName":"Electronic Codebook (ECB)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v15~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableresourceidnamemapping","displayName":"Disable caching when opening server-only files. (User)","description":"This policy setting controls disabling caching when opening server-only files.\r\n\r\nCaching files helps Office speed up server-only file opens but could cause conflicts for organizations that rename files or change file contents directly on SharePoint.\r\n\r\nThe cache is meant to improve performance so disabling it is expected to hurt performance.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v15~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableresourceidnamemapping_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v15~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableresourceidnamemapping_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatieuser","displayName":"Disable local training of the Adaptive Floatie feature for the user. (User)","description":"\r\nThis policy setting disables local training of the Adaptive Floatie feature for the user.\r\n\r\nFor local training policy, feature-specific settings are prioritized over general settings and computer settings are prioritized over user settings.\r\n\r\nIf a higher priority policy setting is not configured, then:\r\n- If this policy setting is enabled, local training of the Adaptive Floatie feature is disabled for the user.\r\n- If this policy setting is disabled, local training of the Adaptive Floatie feature is enabled for the user.\r\n- If this policy setting is not configured, local training of the Adaptive Floatie feature is determined by lower priority policy settings.\r\n- If this policy setting is not configured and lower priority policy settings are also not configured, local training of the Adaptive Floatie feature is enabled for the user.\r\n\r\nFor this policy setting, the order of priority is:\r\n1. Disable local training of the Adaptive Floatie feature for the computer.\r\n2. Disable local training of all features for the computer.\r\n3. Disable local training of the Adaptive Floatie feature for the user.\r\n4. Disable local training of all features for the user.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatieuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatieuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletraininguser","displayName":"Disable local training of all features for the user. (User)","description":"\r\nThis policy setting disables local training of all features for the user.\r\n\r\nFor local training policy, feature-specific settings are prioritized over general settings and computer settings are prioritized over user settings.\r\n\r\nIf a higher priority policy setting is not configured, then:\r\n- If this policy setting is enabled, local training of all features is disabled for the user.\r\n- If this policy setting is disabled, local training of all features is enabled for the user.\r\n- If this policy setting is not configured, local training of all features is enabled for the user.\r\n\r\nFor this policy setting, the order of priority is:\r\n1. Disable local training of [a specific feature] for the computer.\r\n2. Disable local training of all features for the computer.\r\n3. Disable local training of [a specific feature] for the user.\r\n4. Disable local training of all features for the user.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletraininguser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletraininguser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowuserdefinedfilesharecatalogs","displayName":"Allow users to control the Trusted Shared Folder Catalogs (User)","description":"\r\nThis policy setting allows users to control all the Trusted Shared Folder Catalogs when other policy settings in the Trusted Catalogs folder are set by policy. \r\n\r\nNote: This setting only applies to Version 2308 or later of Office.\r\n\r\nIf you enable this policy setting, users can set their own Trusted Shared Folder Catalogs including the Default Shared Folder location. Shared Folder Catalogs defined by policy will not be used.\r\n\r\nIf you disable this policy setting, then all Trusted Shared Folders Catalogs are policy controlled.\r\n\r\nIf you do not configure this policy setting but do configure other policy settings in the Trusted Catalogs folder, the Trusted Shared Folder Catalogs are policy controlled. If you do not configure this policy setting or any other policy setting in the Trusted Catalogs folder, users can set their own Trusted Shared Folder locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowuserdefinedfilesharecatalogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowuserdefinedfilesharecatalogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics","displayName":"Configure Get Diagnostics feature's visibility in the Help Ribbon in Office applications and control the feature's mode of operation. (User)","description":"This policy setting allows you to enable or disable Get Diagnostics in Office applications and specifies the mode in which the feature operates.\r\n\r\nIf you enable this policy setting, you must choose one of the following options:\r\nDisabled\r\nEnable upload of diagnostics logs to Microsoft\r\nEnable the collection of diagnostic logs in an archive\r\n\r\nIf you select \"Disabled\", Office applications will not display a visible Get Diagnostics button in the Help Ribbon.\r\n\r\nIf you select \"Enable upload of diagnostics logs to Microsoft\", Office applications will have a visible Get Diagnostics button in the Help Ribbon. Clicking this button will upload the application’s diagnostic logs to Microsoft for support purposes.\r\n\r\nIf you select \"Enable the collection of diagnostic logs in an archive\", Office applications will have a visible Get Diagnostics button in the Help Ribbon. Clicking this button will capture the application’s diagnostic logs in a file archive on the device where the application is currently running. These logs will not be uploaded to Microsoft.\r\n\r\nPlease note that the option “Enable the collection of diagnostic logs in an archive” may not be applicable in certain Office applications. When the application does not support local log collection, setting the policy to this option will completely disable the feature, removing the \"Get Diagnostics\" button.\r\n\r\nIf you don’t set this policy, the feature will operate in the default mode, which is “Enable upload of diagnostics logs to Microsoft.”\r\n ","helpText":"","infoUrls":[],"categoryId":"e86f24d3-8531-4298-b064-692ea795b1d9","categoryName":"Diagnostics","options":[{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum","displayName":"Configure Get Diagnostics: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e86f24d3-8531-4298-b064-692ea795b1d9","categoryName":"Diagnostics","options":[{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum_1","displayName":"Upload diagnostic logs to Microsoft","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum_2","displayName":"Capture diagnostic logs in a local archive, dont upload logs to Microsoft","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v18~policy~l_microsoftofficesystem~l_miscellaneous437_l_linksopenrightdefaultsettingisnative","displayName":"File links open preference default selection as Desktop App (User)","description":"This policy setting controls which file links open preference is set as the default for users’ who has not make their selection. For more information about file links handling and open preference in Office, see https://go.microsoft.com/fwlink/?linkid=2277074. User can manually change the default selection anytime.\r\n\r\nIf you enabled this policy setting, file open preference in Word, Excel, PowerPoint, and Outlook will be defaulted to open in Desktop App.\r\n\r\nIf you disable this policy setting, file open preference in Word, Excel, PowerPoint, and Outlook will be defaulted to open in web browser.\r\n\r\nNote: This policy setting only applies to subscription version of Office.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v18~policy~l_microsoftofficesystem~l_miscellaneous437_l_linksopenrightdefaultsettingisnative_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v18~policy~l_microsoftofficesystem~l_miscellaneous437_l_linksopenrightdefaultsettingisnative_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v19~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_acceptalleulas","displayName":"Accept all EULAs (User)","description":"By default, users are required to accept a EULA upon activating an Office license. By setting this policy, all EULAs will be automatically accepted machine-wide and no prompts will be shown.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v19~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_acceptalleulas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v19~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_acceptalleulas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter","displayName":"Hide Microsoft cloud-based file locations in the Backstage view (User)","description":"This policy setting allows you to hide Microsoft cloud-based file locations in the Backstage view in Office. This helps prevent users from opening, saving, or sharing cloud-based files to locations such as: OneDrive, SharePoint, or Third Party Services.\r\n\r\nThis policy setting only applies to Word, PowerPoint, and Excel.\r\n\r\nTo filter specific services, add the values for all services to be disabled:\r\n 1 - OneDrive Personal\r\n 4 - ThisPC\r\n 8 - SharePoint OnPrem\r\n 16 - Recent Places\r\n 32 - SharePoint\r\n 64 - OneDrive for Business\r\n 128 - Third Party Services\r\n\r\nSpecial Values:\r\n 0 - (Default) All services enabled.\r\n 2 - (Legacy Value) Disable SharePoint and OneDrive for Business.\r\n\t4294967295 - All optional services disabled.\r\n\r\nFor example, OneDrive Personal (1), This PC (4) and Third Party Services (128) can all be disabled with a value of 133.\r\n\r\nThis value is calculated as follows: 1 + 4 + 128 = 133\r\n\r\nCommon Setting Values:\r\n 1 - Disable OneDrive Personal\r\n 2 - Disable SharePoint Online and OneDrive for Business\r\n 3 - Disable SharePoint Online, OneDrive for Business, and OneDrive Personal\r\n\r\nIf you disable or don’t configure this policy setting, users can use any configured Microsoft cloud-based file location to open, save, and share files.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid","displayName":"Online Storage Filter Value: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences","displayName":"Allow the use of connected experiences in Office (User)","description":"This policy setting allows you to control whether connected experiences are available to your users when they're using Office.\r\n\r\nConnected experiences include experiences that analyze content, such as Editor in Word, experiences that download online content, such as PowerPoint QuickStarter, and other connected experiences, such as document co-authoring and online file storage. It also includes additional optional connected experiences, such as inserting an online video into a PowerPoint presentation or the 3D Maps feature in Excel, which uses Bing. See the Note at the end for more information about other policy settings that you can use to control these connected experiences.\r\n\r\nIf you enable this policy setting, these connected experiences will be available to your users.\r\n\r\nIf you disable this policy setting, these connected experiences won't be available to your users.\r\n\r\nNote: If you disable this policy setting, nearly all connected experiences will be turned off. However, limited Office functionality will remain available, such as synching a mailbox in Outlook. Essential services, such as the licensing service that confirms that you’re properly licensed to use Office, will also remain available.\r\n\r\nIf you don't configure this policy setting, these connected experiences will be available to your users.\r\n\r\nNote: You can use these other policy settings if you want to disable just a certain group of connected experiences: \"Allow the use of connected experiences in Office that analyze content\", \"Allow the use of connected experiences in Office that download online content\", and \"Allow the use of additional optional connected experiences in Office\".\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2085689","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent","displayName":"Allow the use of connected experiences in Office that analyze content (User)","description":"This policy setting allows you to control whether connected experiences that analyze content are available to your users when they're using Office.\r\n\r\nPowerPoint Designer and Editor in Word are examples of connected experiences that analyze content.\r\n\r\nIf you enable this policy setting, connected experiences that analyze content will be available to your users.\r\n\r\nIf you disable this policy setting, connected experiences that analyze content won't be available to your users.\r\n\r\nIf you don't configure this policy setting, connected experiences that analyze content will be available to your users.\r\n\r\nNote: If you disable the \"Allow the use of connected experiences in Office\" policy setting, connected experiences that analyze content won't be available to your users.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2085794\r\n\r\nNote: For information about how this policy setting affects Microsoft 365 Copilot, see https://go.microsoft.com/fwlink/p/?linkid=2248397.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent","displayName":"Allow the use of connected experiences in Office that download online content (User)","description":"This policy setting allows you to control whether connected experiences that download online content are available to your users when they’re using Office.\r\n\r\nOffice templates and PowerPoint QuickStarter are examples of connected experiences that download online content.\r\n\r\nIf you enable this policy setting, connected experiences that download online content will be available to your users.\r\n\r\nIf you disable this policy setting, connected experiences that download online content won’t be available to your users.\r\n\r\nIf you don’t configure this policy setting, connected experiences that download online content will be available to your users.\r\n\r\nNote: If you disable the “Allow the use of connected experiences in Office” policy setting, connected experiences that download online content won’t be available to your users.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2085688","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences","displayName":"Allow the use of additional optional connected experiences in Office (User)","description":"This policy setting allows you to control whether additional optional connected experiences are available to your users when they’re using Office.\r\n\r\nAdditional optional connected experiences are offered by Microsoft directly to your users and are governed by terms other than your organization’s commercial agreement with Microsoft.\r\n\r\nInserting an online video into a PowerPoint presentation or the 3D Maps feature in Excel, which uses Bing, are examples of additional optional connected experiences.\r\n\r\nNote: Even if you choose to make these additional optional connected experiences available to your users, your users will have the option to turn these additional optional connected experiences off as a group by going to File > Account > Account Privacy > Manage Settings.\r\n\r\nIf you enable this policy setting, additional optional connected experiences will be available to your users.\r\n\r\nIf you disable this policy setting, additional optional connected experiences won’t be available to your users.\r\n\r\nNote: Some additional optional connected experiences may be controlled by other policy settings instead of this policy setting. For more information, see the link below.\r\n\r\nIf you don’t configure this policy setting, additional optional connected experiences will be available to your users.\r\n\r\nNote: If you disable the “Allow the use of connected experiences in Office” policy setting, additional optional connected experiences won’t be available to your users.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2085690\r\n\r\nNote: For information about how this policy setting affects Microsoft 365 Copilot, see https://go.microsoft.com/fwlink/p/?linkid=2248196.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel","displayName":"Turn off AutoSave by default in Excel (User)","description":"This policy setting allows you to turn off AutoSave by default in Excel. AutoSave automatically saves all changes a user makes to files that are stored in OneDrive, OneDrive for Business, or SharePoint Online.\r\n\r\nIf you enable this policy setting, AutoSave is off by default in Excel. But, the user can enable AutoSave for Excel by going to File > Options > Save. Or, the user can enable AutoSave for a specific Excel file by using the AutoSave toggle in the title bar.\r\n\r\nIf you disable or don’t configure this policy setting, AutoSave is on by default, but the user can disable AutoSave by going to File > Options > Save or by using the AutoSave toggle.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum_0","displayName":"Use AutoSave Default Setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum_1","displayName":"AutoSave Is On By Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum_2","displayName":"AutoSave Is Off By Default","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint","displayName":"Turn off AutoSave by default in PowerPoint (User)","description":"This policy setting allows you to turn off AutoSave by default in PowerPoint. AutoSave automatically saves all changes a user makes to files that are stored in OneDrive, OneDrive for Business, or SharePoint Online.\r\n\r\nIf you enable this policy setting, AutoSave is off by default in PowerPoint. But, the user can enable AutoSave for PowerPoint by going to File > Options > Save. Or, the user can enable AutoSave for a specific PowerPoint file by using the AutoSave toggle in the title bar.\r\n \r\nIf you disable or don’t configure this policy setting, AutoSave is on by default, but the user can disable AutoSave by going to File > Options > Save or by using the AutoSave toggle.\r\n \r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum_0","displayName":"Use AutoSave Default Setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum_1","displayName":"AutoSave Is On By Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum_2","displayName":"AutoSave Is Off By Default","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword","displayName":"Turn off AutoSave by default in Word (User)","description":"This policy setting allows you to turn off AutoSave by default in PowerPoint. AutoSave automatically saves all changes a user makes to files that are stored in OneDrive, OneDrive for Business, or SharePoint Online.\r\n\r\nIf you enable this policy setting, AutoSave is off by default in PowerPoint. But, the user can enable AutoSave for PowerPoint by going to File > Options > Save. Or, the user can enable AutoSave for a specific PowerPoint file by using the AutoSave toggle in the title bar.\r\n \r\nIf you disable or don’t configure this policy setting, AutoSave is on by default, but the user can disable AutoSave by going to File > Options > Save or by using the AutoSave toggle.\r\n \r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum_0","displayName":"Use AutoSave Default Setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum_1","displayName":"AutoSave Is On By Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum_2","displayName":"AutoSave Is Off By Default","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationexcel","displayName":"[Deprecated] Don’t AutoSave files in Excel (User)","description":"Important: This policy setting will be removed in a future release and will no longer be supported. Please use the \"Turn off AutoSave by default in Excel\" policy setting instead.\r\n \r\nThis policy setting controls whether files can be AutoSaved in the desktop version of Excel after Excel has been updated with new features. By default, Auto Saving files is Enabled.\r\n\r\nIf you enable this policy setting files will not be able to be AutoSaved.\r\n\r\nIf you disable or don’t configure this policy setting files will be able to be AutoSaved.\r\n\r\nNote: There are separate policy settings for Word, Excel, and PowerPoint.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationpowerpoint","displayName":"[Deprecated] Don’t AutoSave files in PowerPoint (User)","description":"Important: This policy setting will be removed in a future release and will no longer be supported. Please use the \"Turn off AutoSave by default in PowerPoint\" policy setting instead.\r\n \r\nThis policy setting controls whether files can be AutoSaved in the desktop version of PowerPoint after PowerPoint has been updated with new features. By default, Auto Saving files is Enabled.\r\n\r\nIf you enable this policy setting files will not be able to be AutoSaved.\r\n\r\nIf you disable or don’t configure this policy setting files will be able to be AutoSaved.\r\n\r\nNote: There are separate policy settings for Word, Excel, and PowerPoint.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationword","displayName":"[Deprecated] Don’t AutoSave files in Word (User)","description":"Important: This policy setting will be removed in a future release and will no longer be supported. Please use the \"Turn off AutoSave by default in Word\" policy setting instead.\r\n \r\nThis policy setting controls whether files can be AutoSaved in the desktop version of Word after Word has been updated with new features. By default, Auto Saving files is Enabled.\r\n\r\nIf you enable this policy setting files will not be able to be AutoSaved.\r\n\r\nIf you disable or don’t configure this policy setting files will be able to be AutoSaved.\r\n\r\nNote: There are separate policy settings for Word, Excel, and PowerPoint.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_disabledefaultservice","displayName":"Remove Office Presentation Service from the list of online presentation services in PowerPoint and Word (User)","description":"This policy setting allows you to remove Office Presentation Service from the list of online presentation services in PowerPoint and Word. This list appears when a user selects Present Online from the Share tab in Backstage view and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, Office Presentation Service is not shown as an option for presenting online. \r\n\r\nIf you disable or do not configure this policy setting, users can select Office Presentation Service to present their PowerPoint or Word file to other users online.","helpText":"","infoUrls":[],"categoryId":"5bf4c2ba-be08-4cda-bf33-d10707580d78","categoryName":"Present Online","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_disabledefaultservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_disabledefaultservice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_disableprogrammaticaccess","displayName":"Restrict programmatic access for creating online presentations in PowerPoint and Word (User)","description":"This policy setting allows you to restrict the ability to create an online presentation programmatically in PowerPoint and Word.\r\n\r\nIf you enable this policy setting, an online presentation cannot be created programmatically.\r\n\r\nIf you disable or do not configure this policy setting, an online presentation can be created programmatically.","helpText":"","infoUrls":[],"categoryId":"5bf4c2ba-be08-4cda-bf33-d10707580d78","categoryName":"Present Online","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_disableprogrammaticaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_disableprogrammaticaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_preventaccesstouserspecifiedservices","displayName":"Prevent users from adding online presentation services in PowerPoint and Word (User)","description":"This policy setting allows you to prevent users from adding new or previously created presentation services to the list of online presentation services in PowerPoint and Word. These services appear when a user selects the More services link under Present Online on the Share tab in Backstage view.\r\n\r\nIf you enable or do not configure this policy setting, the More services link does not allow users to add a new presentation service. In addition, all services previously added by users are removed from the list.\r\n\r\nIf you disable this policy setting, the More Services link provides an option for users to add a new presentation service. In addition, the list of services previously added by users appears in the list of services.","helpText":"","infoUrls":[],"categoryId":"5bf4c2ba-be08-4cda-bf33-d10707580d78","categoryName":"Present Online","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_preventaccesstouserspecifiedservices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_preventaccesstouserspecifiedservices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00","displayName":"Configure presentation service in PowerPoint and Word 1 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicecreatesharednotes0","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicecreatesharednotes0_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicecreatesharednotes0_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicemajorversion0","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceminorversion0","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicenotesdefaulturl0","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceservercapabilities0","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceserverdescription0","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceserverinfo0","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceservername0","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceserverterms0","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceserverurl0","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicesharednotescustomurl0","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01","displayName":"Configure presentation service in PowerPoint and Word 2 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicecreatesharednotes1","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicecreatesharednotes1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicecreatesharednotes1_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicemajorversion1","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceminorversion1","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicenotesdefaulturl1","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceservercapabilities1","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceserverdescription1","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceserverinfo1","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceservername1","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceserverterms1","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceserverurl1","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicesharednotescustomurl1","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02","displayName":"Configure presentation service in PowerPoint and Word 3 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicecreatesharednotes2","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicecreatesharednotes2_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicecreatesharednotes2_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicemajorversion2","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceminorversion2","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicenotesdefaulturl2","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceservercapabilities2","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceserverdescription2","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceserverinfo2","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceservername2","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceserverterms2","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceserverurl2","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicesharednotescustomurl2","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03","displayName":"Configure presentation service in PowerPoint and Word 4 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastservicecreatesharednotes3","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastservicecreatesharednotes3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastservicecreatesharednotes3_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastservicemajorversion3","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceminorversion3","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastservicenotesdefaulturl3","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceservercapabilities3","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverdescription3","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverinfo3","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceservername3","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverterms3","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverurl3","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastservicesharednotescustomurl3","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04","displayName":"Configure presentation service in PowerPoint and Word 5 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicecreatesharednotes4","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicecreatesharednotes4_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicecreatesharednotes4_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicemajorversion4","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceminorversion4","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicenotesdefaulturl4","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceservercapabilities4","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverdescription4","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverinfo4","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceservername4","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverterms4","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverurl4","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicesharednotescustomurl4","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05","displayName":"Configure presentation service in PowerPoint and Word 6 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicecreatesharednotes5","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicecreatesharednotes5_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicecreatesharednotes5_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicemajorversion5","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceminorversion5","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicenotesdefaulturl5","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceservercapabilities5","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceserverdescription5","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceserverinfo5","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceservername5","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceserverterms5","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceserverurl5","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicesharednotescustomurl5","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06","displayName":"Configure presentation service in PowerPoint and Word 7 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastservicecreatesharednotes6","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastservicecreatesharednotes6_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastservicecreatesharednotes6_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastservicemajorversion6","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceminorversion6","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastservicenotesdefaulturl6","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceservercapabilities6","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceserverdescription6","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceserverinfo6","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceservername6","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceserverterms6","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceserverurl6","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastservicesharednotescustomurl6","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07","displayName":"Configure presentation service in PowerPoint and Word 8 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicecreatesharednotes7","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicecreatesharednotes7_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicecreatesharednotes7_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicemajorversion7","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceminorversion7","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicenotesdefaulturl7","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceservercapabilities7","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceserverdescription7","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceserverinfo7","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceservername7","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceserverterms7","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceserverurl7","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicesharednotescustomurl7","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08","displayName":"Configure presentation service in PowerPoint and Word 9 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicecreatesharednotes8","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicecreatesharednotes8_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicecreatesharednotes8_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicemajorversion8","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceminorversion8","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicenotesdefaulturl8","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceservercapabilities8","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceserverdescription8","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceserverinfo8","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceservername8","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceserverterms8","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceserverurl8","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicesharednotescustomurl8","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09","displayName":"Configure presentation service in PowerPoint and Word 10 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicecreatesharednotes9","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicecreatesharednotes9_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicecreatesharednotes9_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicemajorversion9","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceminorversion9","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicenotesdefaulturl9","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceservercapabilities9","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceserverdescription9","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceserverinfo9","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceservername9","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceserverterms9","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceserverurl9","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicesharednotescustomurl9","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaultinstanceslimit","displayName":"Set the database default instances limit (User)","description":"This policy setting allows you to specify the default limit of how many instances per page the database shim can return. The application is allowed to specify a larger timeout programmatically. This is a default value to be used by the database shim to restrict the number of results that can be returned per page. The application can specify a larger limit via execution context.\r\n\r\nIf you enable this policy setting, you may specify the default limit of how many instances the database shim can return.\r\n\r\nIf you disable or do not configure this policy setting, a default value of 200 instances per page will be used.","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaultinstanceslimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaultinstanceslimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaultinstanceslimit_l_databasedefaultinstanceslimitdecimal","displayName":"Default number of instances returned (User)","description":"","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaulttimeout","displayName":"Set the database default timeout (User)","description":"This policy setting allows you to specify the default timeout in milliseconds used by the database shim. The application can specify a larger limit via the execution context.\r\n \r\nIf you enable this policy setting, you may specify the default timeout in milliseconds used by the database shim.\r\n\r\nIf you disable or do not configure this policy setting, a default of 7000 milliseconds will be used.","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaulttimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaulttimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaulttimeout_l_databasedefaulttimeoutdecimal","displayName":"Database default timeout (milliseconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit","displayName":"Set maximum database instances limit (User)","description":"This policy setting allows you to specify the maximum limit of how many instances per page the database shim can return. This policy setting enforces the allowed maximum for applications including those that do not respect the default.\r\n \r\nIf you enable this policy setting, you may specify the maximum limit of how many instances the database shim can return.\r\n\r\nIf you disable or do not configure this policy setting, there will be no limit of how many instances the database shim can return.","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit_l_databasemaxinstanceslimitdecimal","displayName":"Maximum number of instances returned (User)","description":"","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout","displayName":"Set maximum database timeout limit (User)","description":"This policy setting allows you to specify the maximum timeout in milliseconds used by the database shim. This maximum value is enforced for applications including those that do not respect the default.\r\n\r\nIf you enable this policy setting, you may specify the maximum timeout in milliseconds used by the database shim.\r\n\r\nIf you disable or do not configure this policy setting, no maximum timeout value will be enforced.","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout_l_databasemaxtimeoutdecimal","displayName":"Database maximum timeout (milliseconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_cleanupinterval","displayName":"Set the cleanup interval (User)","description":"This policy setting allows you to specify the interval (in minutes) for how long successfully completed operations and other data that is no longer needed will remain in the cache before they can be deleted. The synchronization process leads to data in the cache that will no longer be needed. However, the data may be useful for troubleshooting purposes. To prevent the cache from growing too large, the cache contents should periodically be deleted.\r\n\r\nIf you enable this policy setting, you may specify the interval (in minutes) for the times the contents in the cache are deleted.\r\n\r\nIf you disable or do not configure this policy setting, a default value of 1440 minutes (1 day) will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_cleanupinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_cleanupinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_cleanupinterval_l_cleanupintervaldecimal","displayName":"Cleanup interval (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval","displayName":"Set errors cleanup interval (User)","description":"This policy setting allows you to specify the interval for how long failed operations and other error data will remain in the cache before they can be deleted. Synchronization can fail for any reason. The failed operations and related instances are marked as \"in error,\" and this data will eventually need to be removed from the cache. It is recommended that this interval be larger than the regular cleanup interval to give the user opportunities to troubleshoot errors.\r\n\r\nIf you enable this policy setting, you may specify the interval (in minutes) for the times the failed operations and error data in the cache are deleted. \r\n\r\nIf you disable or do not configure this policy setting, a default value of 10080 minutes (1 week) will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval_l_errorscleanupintervaldecimal","displayName":"Errors cleanup interval (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries","displayName":"Set maximum number of retries when synchronization fails (User)","description":"This policy setting allows you to specify the maximum number of times a failed synchronization operation can be retried.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of times a failed synchronization operation can be retried.\r\n\r\nIf you disable or do not configure this policy setting, then a default value of 50 times will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries_l_maxretriesdecimal","displayName":"Maximum number of retries (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_queryinstanceslimit","displayName":"Set query items limit (User)","description":"This policy setting allows you to specify the maximum number of items that will be added to the client’s cache as the result of executing a query. Several bulk operations (especially queries) can return a large number of items to be added to the cache. This increases the size of the cache, potentially exceeding the 4GB limit imposed by Microsoft SQL Server CE. It also increases the amount of work required to keep the cache synchronized and increases the load on the LOB server. In order to protect the system, a limit is used – any results processed before reaching the limit are still committed, but the operation is marked as failed and will be retried later.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of items that will be added to the client’s cache as the result of executing a query.\r\n\r\nIf you disable or do not configure this policy setting, a default value of 2000 items will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_queryinstanceslimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_queryinstanceslimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_queryinstanceslimit_l_queryinstanceslimitdecimal","displayName":"Query instances limit (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_querytimeout","displayName":"Set query processing timeout limit (User)","description":"This policy setting allows you to specify the maximum number of minutes the system will spend processing an individual query. When the interval is exceeded, the processing is aborted and the query is marked as failed. The query will then be retried later. Several bulk operations (especially queries) can take a significant amount of time before all results are retrieved and processed. During this time no other operation can be processed.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of minutes the system will spend processing an individual query.\r\n\r\nIf you disable or do not configure this policy setting, a default value of 20 minutes will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_querytimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_querytimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_querytimeout_l_querytimeoutdecimal","displayName":"Time before query timeout (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_refreshfrequencylimit","displayName":"Set refresh frequency limit (User)","description":"This policy setting allows you to enforce a lower limit in minutes for the refresh interval. Refreshing subscriptions too frequently can overload the LOB systems or the network with too many requests.\r\n\r\nIf you enable this policy setting, you may specify the number of minutes for the refresh interval. This limit prevents cache subscriptions from being refreshed more frequently, reducing the number of requests issued against the line-of-business (LOB) system.\r\n\r\nIf you disable or do not configure this policy setting, a default limit of 10 minutes will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_refreshfrequencylimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_refreshfrequencylimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_refreshfrequencylimit_l_refreshfrequencylimitdecimal","displayName":"Refresh frequency limit (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_retryintervallimit","displayName":"Set subscription refresh retry interval (User)","description":"This policy setting allows you to specify the maximum number of minutes the system must wait before retrying the operation execution of a failed operation.\r\n\r\nIf you enable this policy setting, you may specify the maximum interval in minutes before a retrying the operation execution of a failed operation.\r\n\r\nIf you disable or do not configure this policy setting, then a default value of 360 minutes will be used.\r\n","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_retryintervallimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_retryintervallimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_retryintervallimit_l_retryintervallimitdecimal","displayName":"Maximum retry interval (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_sleepinterval","displayName":"Set maximum sleep interval (User)","description":"This policy setting allows you to set an upper limit on the sleep interval used by the cache. The sleep is automatically interrupted when any application made changes in the cache or if there is an action scheduled to be performed.\r\n \r\nIf you enable this policy setting, you may specify how long (in minutes) the synchronization should wait before resuming when there is no pending work to do.\r\n\r\nIf you disable or do not configure this policy setting, then a default value of 20 minutes will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_sleepinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_sleepinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_sleepinterval_l_sleepintervaldecimal","displayName":"Sleep interval upper limit (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaultsizelimit","displayName":"Set web service default return size limit (User)","description":"This policy setting allows you to specify the default limit of how much data in kilobytes (KB) the web service shim can return per call. The application is allowed to specify a larger limit programmatically.\r\n\r\nIf you enable this policy setting, you may specify the default limit of data in kilobytes the web service shim can return per call.\r\n\r\nIf you disable or do not configure this policy setting, a default limit of 3000 KB will be used.","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaultsizelimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaultsizelimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaultsizelimit_l_webservicedefaultsizelimitdecimal","displayName":"Web service default size limit (KB) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaulttimeout","displayName":"Set web service default timeout (User)","description":"This policy setting allows you to specify the default timeout in milliseconds for the web service shim. The application is allowed to specify a larger timeout programmatically.\r\n\r\nIf you enable this policy setting, you may specify the default timeout in milliseconds for the web service shim.\r\n\r\nIf you disable or do not configure this policy setting, a default of 7000 milliseconds will be used.","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaulttimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaulttimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaulttimeout_l_webservicedefaulttimeoutdecimal","displayName":"Web service default timeout limit (milliseconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxsizelimit","displayName":"Set maximum web service return size limit (User)","description":"This policy setting allows you to specify the maximum limit of how much data in kilobytes (KB) the web service shim can return per call. This maximum value is enforced for applications including those that do not respect the default. \r\n\r\nIf you enable this policy setting, you may specify the maximum limit of data in kilobytes the web service shim can return per call.\r\n\r\nIf you disable or do not configure this policy setting, no maximum limit will be enforced.","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxsizelimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxsizelimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxsizelimit_l_webservicemaxsizelimitdecimal","displayName":"Web service maximum size limit (KB) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxtimeout","displayName":"Set maximum web service default timeout (User)","description":"This policy setting allows you to specify the maximum timeout in milliseconds for the web service shim. This maximum value is enforced for applications that do not respect the default.\r\n\r\nIf you enable this policy setting, you may specify the maximum timeout in milliseconds for the web service shim.\r\n\r\nIf you disable or do not configure this policy setting, no maximum limit will be enforced.","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxtimeout_l_webservicemaxtimeoutdecimal","displayName":"Web service maximum timeout limit (milliseconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest","displayName":"Default subject for a review request (User)","description":"Defines the default subject text for a review request.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest_l_defaultsubjectforareviewrequest393","displayName":"Default subject for a review request (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_donotpromptuserstoshareexcelworkbookswhensendingforreview","displayName":"Do not prompt users to share Excel workbooks when sending for review (User)","description":"Checked: Do not prompt the user to share Excel workbooks when sending them for review. | Unchecked: Prompt the user to share Excel workbooks when sending them for review.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_donotpromptuserstoshareexcelworkbookswhensendingforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_donotpromptuserstoshareexcelworkbookswhensendingforreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingadhocreview","displayName":"Max number of documents being reviewed using ad hoc review (User)","description":"Sets the total number of documents that can be sent for review by a user using ad-hoc review before reusing registry entries from previous review cycles.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingadhocreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingadhocreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingadhocreview_l_empty388","displayName":"\r\nMax number of documents being reviewed using ad hoc review\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview","displayName":"Max number of documents being reviewed using 'send for review' (User)","description":"Sets the total number of documents that can be sent for review by a user before reusing registry entries from previous review cycles.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview_l_empty385","displayName":"\r\nMax number of documents being reviewed using 'send for review'\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing","displayName":"Outlook: Ad hoc reviewing (User)","description":"\"Enable ad hoc reviewing\": Enables the ad-hoc review feature. | \"Exclude author's e-mail in documents\": Enables the ad-hoc review feature, but the authors e-mail is not recorded on the sent document. | \"Disable ad hoc reviewing\": Disables the ad-hoc review feature.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_l_empty400","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_l_empty400_0","displayName":"Enable ad hoc reviewing","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_l_empty400_2","displayName":"Exclude author's e-mail in documents","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_l_empty400_1","displayName":"Disable ad hoc reviewing","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview","displayName":"Outlook: 'send for review' (User)","description":"\"Enable 'send for review\"': Enables the Send For Review feature. | \"Exclude author's e-mail in documents\": Enables the Send For Review feature, but the authors e-mail is not recorded on the sent document. | \"Disable 'send for review\"': Disables the Send For Review feature.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399_0","displayName":"Enable 'send for review'","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399_2","displayName":"Exclude author's e-mail in documents","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399_1","displayName":"Disable 'send for review'","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor","displayName":"Prompt for sending reviewed document to author (User)","description":"\"Never ask user\": Do not ask users if they want to send back changes to the author. | \"Prompt for 'send for review\"': Ask users if they want to send back changes to the author only if the document was sent using Send For Review and not with ad-hoc review. | \"Always prompt\": Ask users if they want to send back changes to the author for documents sent using either Send For Review or ad-hoc review.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_l_empty395","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_l_empty395_2","displayName":"Never ask user","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_l_empty395_1","displayName":"Prompt for 'send for review'","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_l_empty395_0","displayName":"Always prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview","displayName":"When choosing 'Send for Review...' (User)","description":"\"Send link and attachment\": When choosing Send for Review for a document on a server, send both a link and an attachment. | \"Only send link\": When choosing Send for Review for a document on a server, send only a link. | \"Prompt user\": When choosing Send for Review for a document on a server, prompt the user for what to send.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_l_empty392","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_l_empty392_2","displayName":"Send link and attachment","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_l_empty392_1","displayName":"Only send link","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_l_empty392_0","displayName":"Prompt user","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_coauthoring_l_setdocumentsynchronizationtimeout","displayName":"Set document synchronization timeout (User)","description":"This policy setting specifies the server timeout value in milliseconds for document synchronization. This policy setting does not apply when synchronizing documents on SharePoint servers. \r\n\r\nIf you enable this policy setting, you may specify the server timeout value in milliseconds for document synchronization.\r\n\r\nIf you disable or do not configure this policy setting, the server timeout will default to the Windows timeout value.\r\n","helpText":"","infoUrls":[],"categoryId":"a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_coauthoring_l_setdocumentsynchronizationtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_coauthoring_l_setdocumentsynchronizationtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_coauthoring_l_setdocumentsynchronizationtimeout_l_setdocumentsynchronizationtimeoutspinid","displayName":"in milliseconds: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","categoryName":"Co-authoring","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withasimplewebdiscussionslink373","displayName":"With a simple Web discussions link (User)","description":"Defines the default message body text used in a reply to an email request for review when the reply contains a simple Web discussions link. ","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withasimplewebdiscussionslink373_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withasimplewebdiscussionslink373_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withasimplewebdiscussionslink373_l_withasimplewebdiscussionslink374","displayName":"With a simple Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withawebdiscussionslink380","displayName":"With a Web discussions link (User)","description":"Defines the default message body text used in a reply to an email request for review when the reply contains a simple Web discussions link. ","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withawebdiscussionslink380_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withawebdiscussionslink380_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withawebdiscussionslink380_l_withawebdiscussionslink381","displayName":"With a Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustanattachment","displayName":"With just an attachment (User)","description":"Defines the default message body text used in a reply to an email request for review when the reply contains a simple Web discussions link. ","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustanattachment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustanattachment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustanattachment_l_withjustanattachment379","displayName":"With just an attachment (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink","displayName":"With just a simple Web discussions link (User)","description":"Defines the default message body text used in a reply to an email request for review when the reply contains a simple Web discussions link. ","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink_l_withjustasimplewebdiscussionslink377","displayName":"With just a simple Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontainingalink","displayName":"Only containing a link (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontainingalink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontainingalink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontainingalink_l_onlycontainingalink357","displayName":"Only containing a link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontaininganattachment","displayName":"Only containing an attachment (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontaininganattachment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontaininganattachment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontaininganattachment_l_onlycontaininganattachment356","displayName":"Only containing an attachment (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withalinkandanattachment","displayName":"With a link and an attachment (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withalinkandanattachment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withalinkandanattachment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withalinkandanattachment_l_withalinkandanattachment359","displayName":"With a link and an attachment (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink","displayName":"With a simple Web discussions link (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink_l_withasimplewebdiscussionslink362","displayName":"With a simple Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment","displayName":"With a simple Web discussions link and an attachment (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment_l_withasimplewebdiscussionslinkandanattachment364","displayName":"With a simple Web discussions link and an attachment (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslink","displayName":"With a Web discussions link (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslink_l_withawebdiscussionslink367","displayName":"With a Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslinkandanattachment","displayName":"With a Web discussions link and an attachment (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslinkandanattachment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslinkandanattachment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslinkandanattachment_l_withawebdiscussionslinkandanattachment370","displayName":"With a Web discussions link and an attachment (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons","displayName":"Configure presence icons (User)","description":"This policy setting allows you to specify whether Microsoft Office applications display presence icons in the user interface (UI).\r\n\r\nIf you enable this policy setting, you may specify when applications display presence icons:\r\n\r\n- Display all: Presence icons are displayed in the UI.\r\n- Display some: Presence icons are displayed only in the Contact Card, Quick Contacts and SharePoint.\r\n- Display none: Presence icons are not displayed in the UI.\r\n\r\nIf you disable or you do not configure this policy setting, presence icons are displayed in the UI.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid_0","displayName":"Display all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid_1","displayName":"Display some","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid_2","displayName":"Display none","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_displaylegacygaldialog","displayName":"Display legacy GAL dialog (User)","description":"This policy setting allows you to specify the way contact information is displayed.\r\n\r\nIf you enable this policy setting the global address list (GAL) dialog is displayed instead of the Contact Card when users double click a contact in Outlook. \r\n\r\nIf you disable or do not configure this policy setting the Contact Card is displayed when users double click a contact in Outlook.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_displaylegacygaldialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_displaylegacygaldialog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayhovermenu","displayName":"Do not display Hover Menu (User)","description":"This policy setting allows you to stop the Hover Menu from displaying when a user hovers over a contact’s presence icon or display name with the mouse cursor.\r\n\r\nIf you enable this policy setting, when a user hovers over a contact’s presence icon or display name with the mouse cursor, the Hover Menu will not be displayed.\r\n\r\nIf you disable or do not configure this policy setting, the Hover Menu appears when a user hovers over a contact’s presence icon or display name with the mouse cursor.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayhovermenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayhovermenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayphotograph","displayName":"Do not display photograph (User)","description":"This policy setting lets you specify if the photograph is shown on the contact card, e-mail header, reading pane, fast search results, global address list (GAL) dialog, Backstage, and quick contacts. \r\n\r\nIf you enable this policy setting, photographs are not displayed in the locations listed above.\r\n\r\nIf you disable or do not configure this policy setting, photographs appear in the locations listed above.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayphotograph_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayphotograph_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removememberoftab","displayName":"Remove Member Of tab (User)","description":"This policy setting allows you to remove the Member Of tab from the Contact Card.\r\n\r\nIf you enable this policy setting the Member Of tab is removed from the Contact Card.\r\n\r\nIf you disable or do not configure this policy setting the Member Of tab appears on the Contact Card.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removememberoftab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removememberoftab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removeorganizationtab","displayName":"Remove Organization tab (User)","description":"This policy setting allows you to remove the Organization tab from the Contact Card.\r\n\r\nIf you enable this policy setting, the Organization tab is removed from the Contact Card.\r\n\r\nIf you disable or do not configure this policy setting, the Organization tab appears on the Contact Card.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removeorganizationtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removeorganizationtab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffclicktoimoption","displayName":"Turn off click to IM option (User)","description":"This policy setting allows you to remove the Instant Messaging (IM) option from the Contact Card and Outlook Ribbon.\r\n\r\nIf you enable this policy setting the Instant Messaging icon does not appear on the Contact Card and Outlook Ribbon.\r\n\r\nIf you disable or do not configure this policy setting the Instant Messaging icon appears on the Contact Card and Outlook Ribbon.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffclicktoimoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffclicktoimoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffclicktotelephone","displayName":"Turn off click to telephone (User)","description":"This policy setting allows you to remove the telephone option from the Contact Card and Outlook Ribbon.\r\n\r\nIf you enable this policy setting, the telephone option does not appear in the Contact Card. Telephone links do not appear in the Contact Card. Telephone options do not appear in the Outlook Ribbon.\r\n\r\nIf you disable or do not configure this policy setting telephone options appear in the Contact Card and Outlook Ribbon.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffclicktotelephone_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffclicktotelephone_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffpresenceintegration","displayName":"Turn off presence integration (User)","description":"This policy setting allows you to turn off instant messaging (IM) presence integration for Microsoft Office applications. \r\n\r\nIf you enable this policy, setting IM presence icons will not be displayed and presence integration will be turned off for Office applications.\r\n\r\nIf you disable or do not configure this policy setting, IM presence icons will be displayed and presence integration will be turned on for Office applications.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffpresenceintegration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffpresenceintegration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttabcalendar","displayName":"Remove Calendar Line (User)","description":"\r\nThis policy setting enables you to remove the Calendar line on the Contact Tab, which is on the Contact Card.\r\n\r\nIf you enable this policy setting, you can remove the Calendar line.\r\n\r\nIf you disable or do not configure this policy setting, the Calendar line appears on the Contact Tab.\r\n","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttabcalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttabcalendar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttablocation","displayName":"Remove Location Line (User)","description":"\r\nThis policy setting enables you to remove the Location line on the Contact Tab, which is on the Contact Card.\r\n\r\nIf you enable this policy setting, you can remove the Location line.\r\n\r\nIf you disable or do not configure this policy setting, the Location line appears on the Contact Tab.\r\n","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttablocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttablocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacebirthday","displayName":"Replace AD - Birthday (User)","description":"This policy setting allows you to customize the 16th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"birthday\" of line 16.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 16 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacebirthday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacebirthday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacebirthday_l_birthdayadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacecompany","displayName":"Replace AD - Company (User)","description":"This policy setting allows you to customize the 12th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"company\" of line 12.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 12 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacecompany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacecompany_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacecompany_l_companyadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail","displayName":"Replace AD - E-mail (User)","description":"This policy setting allows you to customize the 1st value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"email address\" of line 1.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 1 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail_l_emailadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome","displayName":"Replace AD - Home (User)","description":"This policy setting allows you to customize the 6th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"home phone\" of line 6.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 6 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome_l_homeadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome2","displayName":"Replace AD - Home2 (User)","description":"This policy setting allows you to customize the 7th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"home phone 2\" of line 7.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 7 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome2_l_home2adreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehomeadd","displayName":"Replace AD - Home Address (User)","description":"This policy setting allows you to customize the 14th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"home address\" of line 14.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 14 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehomeadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehomeadd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehomeadd_l_homeaddadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceim","displayName":"Replace AD - IM (User)","description":"This policy setting allows you to customize the 9th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"IM address\" of line 9.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 9 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceim_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceim_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceim_l_imadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacemobile","displayName":"Replace AD - Mobile (User)","description":"This policy setting allows you to customize the 5th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"mobile phone\" of line 5.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 5 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacemobile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacemobile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacemobile_l_mobileadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceoffice","displayName":"Replace AD - Office (User)","description":"This policy setting allows you to customize the 11th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"office location\" of line 11.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 11 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceoffice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceoffice_l_officeadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceother","displayName":"Replace AD - Other (User)","description":"This policy setting allows you to customize the 8th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"other phone\" of line 8.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 8 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceother_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceother_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceother_l_otheradreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceotheradd","displayName":"Replace AD - Other Address (User)","description":"This policy setting allows you to customize the 15th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"other address\" of line 15.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 15 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceotheradd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceotheradd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceotheradd_l_otheraddadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceprofile","displayName":"Replace AD - Profile (User)","description":"This policy setting allows you to customize the 10th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"profile\" of line 10.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 10 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceprofile_l_profileadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework","displayName":"Replace AD - Work (User)","description":"This policy setting allows you to customize the 2nd value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"work phone\" of line 2.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 2 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework_l_workadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2","displayName":"Replace AD - Work2 (User)","description":"This policy setting allows you to customize the 3rd value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"work phone 2\" of line 3.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 3 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2_l_work2adreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkadd","displayName":"Replace AD - Work Address (User)","description":"This policy setting allows you to customize the 13th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"work address\" of line 13.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 13 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkadd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkadd_l_workaddadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkfax","displayName":"Replace AD - WorkFax (User)","description":"This policy setting allows you to customize the 4th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"work fax\" of line 4.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 4 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkfax_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkfax_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkfax_l_workfaxadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacebirthday","displayName":"Replace Label - Birthday (User)","description":"This policy setting allows you to change or remove the 16th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacebirthday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacebirthday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacebirthday_l_birthdaylabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany","displayName":"Replace Label - Company (User)","description":"This policy setting allows you to change or remove the 12th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany_l_companylabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail","displayName":"Replace Label - E-mail (User)","description":"This policy setting allows you to change or remove the 1st label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail_l_emaillabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome","displayName":"Replace Label - Home (User)","description":"This policy setting allows you to change or remove the 6th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome_l_homelabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome2","displayName":"Replace Label - Home2 (User)","description":"This policy setting allows you to change or remove the 7th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome2_l_home2labelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehomeadd","displayName":"Replace Label - Home Address (User)","description":"This policy setting allows you to change or remove the 14th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehomeadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehomeadd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehomeadd_l_homeaddlabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceim","displayName":"Replace Label - IM (User)","description":"This policy setting allows you to change or remove the 9th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceim_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceim_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceim_l_imlabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile","displayName":"Replace Label - Mobile (User)","description":"This policy setting allows you to change or remove the 5th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile_l_mobilelabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceoffice","displayName":"Replace Label - Office (User)","description":"This policy setting allows you to change or remove the 11th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceoffice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceoffice_l_officelabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother","displayName":"Replace Label - Other (User)","description":"This policy setting allows you to change or remove the 8th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother_l_otherlabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceotheradd","displayName":"Replace Label - Other Address (User)","description":"This policy setting allows you to change or remove the 15th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceotheradd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceotheradd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceotheradd_l_otheraddlabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceprofile","displayName":"Replace Label - Profile (User)","description":"This policy setting allows you to change or remove the 10th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceprofile_l_profilelabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework","displayName":"Replace Label - Work (User)","description":"This policy setting allows you to change or remove the 2nd label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework_l_worklabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework2","displayName":"Replace Label - Work2 (User)","description":"This policy setting allows you to change or remove the 3rd label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework2_l_work2labelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd","displayName":"Replace Label - Work Address (User)","description":"This policy setting allows you to change or remove the 13th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd_l_workaddlabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkfax","displayName":"Replace Label - WorkFax (User)","description":"This policy setting allows you to change or remove the 4th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkfax_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkfax_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkfax_l_workfaxlabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacebirthday","displayName":"Replace MAPI - Birthday (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"birthday\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"birthday\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacebirthday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacebirthday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacebirthday_l_birthdaymapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany","displayName":"Replace MAPI - Company (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"company\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"company\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany_l_companymapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceemail","displayName":"Replace MAPI - E-mail (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"email address\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"email address\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceemail_l_emailmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome","displayName":"Replace MAPI - Home (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"home phone\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"home phone\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome_l_homemapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome2","displayName":"Replace MAPI - Home2 (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"home phone 2\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"home phone 2\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome2_l_home2mapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehomeadd","displayName":"Replace MAPI - Home Address (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"home address\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"home address\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehomeadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehomeadd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehomeadd_l_homeaddmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceim","displayName":"Replace MAPI - IM (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"IM address\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"IM address\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceim_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceim_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceim_l_immapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacemobile","displayName":"Replace MAPI - Mobile (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"mobile phone\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"mobile phone\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacemobile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacemobile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacemobile_l_mobilemapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceoffice","displayName":"Replace MAPI - Office (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"office location\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"office location\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceoffice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceoffice_l_officemapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceother","displayName":"Replace MAPI - Other (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"other phone\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"other phone\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceother_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceother_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceother_l_othermapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceotheradd","displayName":"Replace MAPI - Other Address (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"other address\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"other address\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceotheradd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceotheradd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceotheradd_l_otheraddmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceprofile","displayName":"Replace MAPI - Profile (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"profile\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"profile\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceprofile_l_profilemapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework","displayName":"Replace MAPI - Work (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"work phone\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"work phone\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework_l_workmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework2","displayName":"Replace MAPI - Work2 (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"work phone 2\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"work phone 2\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework2_l_work2mapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkadd","displayName":"Replace MAPI - Work Address (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"work address\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"work address\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkadd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkadd_l_workaddmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkfax","displayName":"Replace MAPI - WorkFax (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"work fax\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"work fax\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkfax_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkfax_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkfax_l_workfaxmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_baseurl","displayName":"Base URL (User)","description":"Sets the URL for the location of customized error messages.","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_baseurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_baseurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_baseurl_l_baseurl349","displayName":"Base URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext","displayName":"Default button text (User)","description":"Sets the custom button text that appears on the error dialog box.","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext_l_defaultbuttontext350","displayName":"Default button text (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext","displayName":"Default save prompt text (User)","description":"Sets the text displayed when the user saves a document in any format other than the default.","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext_l_defaultsaveprompttext352","displayName":"Default save prompt text (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize351","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize351_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize351_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_hidebuiltinshapepresetstyles","displayName":"Hide built-in shape style presets (User)","description":"This policy setting allows you to specify whether or not to show the the built-in shape preset styles.","helpText":"","infoUrls":[],"categoryId":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","categoryName":"Disable Items in User Interface","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_hidebuiltinshapepresetstyles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_hidebuiltinshapepresetstyles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_tooltipfordisabledtoolbarbuttonsandmenuitems","displayName":"Tooltip for disabled toolbar buttons and menu items (User)","description":"Defines the text to be used in tooltips for disabled toolbar buttons and menu items.","helpText":"","infoUrls":[],"categoryId":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","categoryName":"Disable Items in User Interface","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_tooltipfordisabledtoolbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_tooltipfordisabledtoolbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_tooltipfordisabledtoolbarbuttonsandmenuitems_l_tooltipfordisabledtoolbarbuttonsandmenuitems353","displayName":"Tooltip for disabled toolbar buttons and menu items (User)","description":"","helpText":"","infoUrls":[],"categoryId":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","categoryName":"Disable Items in User Interface","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_turnoffscreenclipping","displayName":"Turn off screen clipping (User)","description":"This policy setting allows you to turn off the Insert Screenshot feature.\r\n\r\nIf you enable this policy setting, you will turn off the Insert Screenshot feature found in Microsoft Excel, PowerPoint, Outlook, and Word. This setting does not affect the screen clipping feature found in Microsoft OneNote or the Print Screen key on your keyboard.\r\n\r\nIf you disable or do not configure this policy setting, the Insert Screenshot feature in Microsoft Excel, PowerPoint, Outlook, and Word will be available. This feature allows users to insert both screen clippings and the contents of an entire active window. ","helpText":"","infoUrls":[],"categoryId":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","categoryName":"Disable Items in User Interface","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_turnoffscreenclipping_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_turnoffscreenclipping_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_dlp_l_policytipsenabled","displayName":"Enable DLP on application boot (User)","description":"This policy setting determines whether DLP executes on application boot.\r\n\r\nIf you enable this policy setting, DLP runs on application boot.\r\n\r\nIf you disable or do not configure this policy setting, DLP does not run on application boot.","helpText":"","infoUrls":[],"categoryId":"b94cbc54-e565-44f2-a27a-a63b2514d8bf","categoryName":"DLP","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_dlp_l_policytipsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_dlp_l_policytipsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_disabledocumentinformationpanel","displayName":"Disable Document Information Panel (User)","description":"This policy setting controls whether Excel, PowerPoint, and Word users can view document information in the Document Information Panel.The Document Information Panel replaces the modal Properties dialog box in earlier versions of Excel, PowerPoint, and Word, and allows users to view and edit metadata that is associated with the document. Office 2016 developers can create custom Document Information Panels to record a variety of information relevant to the document or the organization. \r\n\r\nIf you enable this policy setting, forms and controls do not display in the Document Information Panel. The panel itself will display when users open it, but it will be blank. \r\n\r\nIf you disable or do not configure this policy setting, users can view the Document Information Panel.","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_disabledocumentinformationpanel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_disabledocumentinformationpanel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui","displayName":"Document Information Panel Beaconing UI (User)","description":"This policy setting controls whether users see a security warning when they open custom Document Information Panels that contain a Web beaconing threat. InfoPath can be used to create custom Document Information Panels that can be attached to Excel workbooks, PowerPoint presentations, and Word documents. \r\n\r\nIf you enable this policy setting, you can choose from three options for controlling when users are prompted about Web beaconing threats: \r\n\r\n- Never show UI \r\n\r\n- Always show UI \r\n\r\n- Show UI if XSN is in Internet Zone \r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled -- Never show UI.","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui_l_empty423","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui_l_empty423_0","displayName":"Never show UI","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui_l_empty423_1","displayName":"Always show UI","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui_l_empty423_2","displayName":"Show UI if XSN is in Internet Zone","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel","displayName":"Offline Mode for Document Information Panel (User)","description":"Specify if Offline Mode is disabled/enabled for custom Document Information Panel templates and if the Document Information Panel is currently in Offline Mode.","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel_l_empty422","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel_l_empty422_0","displayName":"Disable Offline Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel_l_empty422_1","displayName":"Enable Offline Mode, work offline now","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel_l_empty422_2","displayName":"Enable Offline Mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution","displayName":"Trust Local Solution (User)","description":"Suppresses prompt that asks to load a locally installed full-trust solution of a Document Information Panel in the background. This is normally shown if a full-trust solution is deployed and there are bound properties in the document (e.g. lookups) that must load the Document Information Panel in the background to retrieve the contents of the property. \r\n\r\nEnter pairs corresponding to the Document Information Panel solution path and a value of 1 to disable. If the value is set, the user will not be prompted when loading the full-trust solution in the background. The solution will load normally (and any non-related warnings that exist).","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_l_empty421","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_l_empty421_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_l_empty421_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_hidemissingcomponentdownloadhyperlinks","displayName":"Hide missing component download hyperlinks (User)","description":"Don't allow the download of missing components but not showing the download hyperlinks for the missing components. Possible missing components are the Microsoft .NET 2.0 framework and Workflow component.","helpText":"","infoUrls":[],"categoryId":"bc633a5a-c712-49a6-9f56-775ca9321df4","categoryName":"Downloading Framework Components","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_hidemissingcomponentdownloadhyperlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_hidemissingcomponentdownloadhyperlinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20framework","displayName":"Set download location for Microsoft .NET Framework 2.0 (User)","description":"Set a custom path to where users can access the missing component.","helpText":"","infoUrls":[],"categoryId":"bc633a5a-c712-49a6-9f56-775ca9321df4","categoryName":"Downloading Framework Components","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20framework_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20framework_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20framework_l_empty434","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"bc633a5a-c712-49a6-9f56-775ca9321df4","categoryName":"Downloading Framework Components","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20frameworklp","displayName":"Set download location for Microsoft .NET Framework 2.0 Language Pack (User)","description":"Set a custom path to where users can access the missing component.","helpText":"","infoUrls":[],"categoryId":"bc633a5a-c712-49a6-9f56-775ca9321df4","categoryName":"Downloading Framework Components","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20frameworklp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20frameworklp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20frameworklp_l_empty435","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"bc633a5a-c712-49a6-9f56-775ca9321df4","categoryName":"Downloading Framework Components","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy1","displayName":"Places Bar Location 1 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy1_l_placesbarname","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy1_l_placesbarpath","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy10","displayName":"Places Bar Location 10 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy10_l_placesbarname227","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy10_l_placesbarpath228","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy2","displayName":"Places Bar Location 2 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy2_l_placesbarname211","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy2_l_placesbarpath212","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy3","displayName":"Places Bar Location 3 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy3_l_placesbarname213","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy3_l_placesbarpath214","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy4","displayName":"Places Bar Location 4 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy4_l_placesbarname215","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy4_l_placesbarpath216","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5","displayName":"Places Bar Location 5 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_l_placesbarname217","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_l_placesbarpath218","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6","displayName":"Places Bar Location 6 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_l_placesbarname219","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_l_placesbarpath220","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7","displayName":"Places Bar Location 7 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_l_placesbarname221","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_l_placesbarpath222","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8","displayName":"Places Bar Location 8 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8_l_placesbarname223","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8_l_placesbarpath224","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy9","displayName":"Places Bar Location 9 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy9_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy9_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy9_l_placesbarname225","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy9_l_placesbarpath226","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing","displayName":"Activate Restricted Browsing (User)","description":"When Restricted Browsing is activated the save as dialog box will be restricted such that the user will only be able to navigate to those locations and the children of those locations specified in the \"Restricted Browsing\\Approve Locations\" policy setting. If you want to enable the \"Approve Locations\" policy setting, you must first enable the \"Approve Locations\" policy setting first.","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_access","displayName":"Microsoft Access (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_access_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_access_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_excel","displayName":"Microsoft Excel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_excel_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_excel_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_infopath","displayName":"Microsoft InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_infopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_infopath_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_onenote","displayName":"Microsoft OneNote (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_onenote_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_onenote_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_outlook","displayName":"Microsoft Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_outlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_outlook_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_powerpoint","displayName":"Microsoft PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_powerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_powerpoint_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_project","displayName":"Microsoft Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_project_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_project_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_publisher","displayName":"Microsoft Publisher (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_publisher_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_publisher_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_sharepoint","displayName":"Microsoft SharePoint Designer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_sharepoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_sharepoint_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_visio","displayName":"Microsoft Visio (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_visio_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_visio_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_word","displayName":"Microsoft Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_word_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_word_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy","displayName":"Approve Locations (User)","description":"Adds locations, such as c:\\Windows or \\\\server\\share, to the list of approved locations for use with Restricted Browsing. When Restricted Browsing is active, the Save As dialog box is restricted such that the user can navigate only to the locations and the children of the locations specified in this list. \r\n\r\nTo allow easier access to these approved locations, consider adding them to the Places bar by using the Places Bar Locations setting for the File Open/Save dialog box. If there are no approved locations in the Places bar, the dialog box may not be able to open.\r\n\r\nTo activate Restricted Browsing, use the Restricted Browsing/Activate Restricted Browsing setting. Note: You must set this policy setting first before the \"Activate Restricted Browsing.\"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_l_listofapprovedlocations","displayName":"List of Approved Locations: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_l_listofapprovedlocations_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_l_listofapprovedlocations_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_firstrun_l_disablemovie","displayName":"Disable First Run Movie (User)","description":"This policy setting determines whether a video about signing-in to Office is played when Office first runs.\r\n\r\nIf you enable this policy setting, the video does not run during Office First Run.\r\n\r\nIf you disable or do not configure this policy setting, a video about signing-in to Office plays when Office first runs.","helpText":"","infoUrls":[],"categoryId":"72a7524b-11c5-4695-9fcf-6cf30c8ba2b9","categoryName":"First Run","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_firstrun_l_disablemovie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_firstrun_l_disablemovie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_firstrun_l_disableofficefirstrun","displayName":"Disable Office First Run on application boot (User)","description":"This policy setting determines whether the Office First Run comes up on first application boot if not previously viewed.\r\n\r\nIf you enable this policy setting, the Office First Run does not run on first application boot.\r\n\r\nIf you disable or do not configure this policy setting, the Office First Run about signing-in to Office comes up on first application boot if not previously viewed.","helpText":"","infoUrls":[],"categoryId":"72a7524b-11c5-4695-9fcf-6cf30c8ba2b9","categoryName":"First Run","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_firstrun_l_disableofficefirstrun_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_firstrun_l_disableofficefirstrun_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_allowroamingquickaccesstoolbarribboncustomizations","displayName":"Allow roaming of all user customizations (User)","description":"This policy setting allows roaming of both the Quick Access Toolbar and Ribbon customizations. \r\n\r\nIf you enable this policy setting, users' Quick Access Toolbar and Ribbon customizations will be available to them on any computer on their network when they log on. \r\n\r\nIf you disable or do not configure this policy setting, users' Quick Access Toolbar and Ribbon customizations will only be available to them on the computer on which they made the customizations.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_allowroamingquickaccesstoolbarribboncustomizations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_allowroamingquickaccesstoolbarribboncustomizations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy","displayName":"Turn off user customizations via UI (User)","description":"This policy setting can prevent users from customizing both the Quick Access Toolbar and Ribbon through the user interface (UI).\r\n\r\nIf you enable this policy setting, the following UI entry points are turned off: the Quick Access Toolbar and Ribbon tabs in the application's Office Center dialog box, and the Quick Access Toolbar and Ribbon customization options on the right-click menu on the Ribbon.\r\n\r\nIf you disable or do not configure this policy setting, users can customize the Quick Access Toolbar and Ribbon through both the application’s Office Center dialog box, and the right-click menu on the Ribbon.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiaccess","displayName":"Disallow in Access (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiaccess_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiaccess_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiexcel","displayName":"Disallow in Excel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiexcel_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiexcel_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiinfopath","displayName":"Disallow in InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiinfopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiinfopath_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuionenote","displayName":"Disallow in OneNote (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuionenote_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuionenote_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuioutlook","displayName":"Disallow in Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuioutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuioutlook_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipowerpoint","displayName":"Disallow in PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipowerpoint_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiproject","displayName":"Disallow in Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiproject_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipublisher","displayName":"Disallow in Publisher (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipublisher_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipublisher_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispd","displayName":"Disallow in SharePoint Designer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispw","displayName":"Disallow in SharePoint Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispw_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispw_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuivisio","displayName":"Disallow in Visio (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuivisio_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuivisio_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiword","displayName":"Disallow in Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiword_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_donotshowscreentipsontoolbars","displayName":"Do not show ScreenTips on toolbars (User)","description":"This policy setting allows you to configure the \"Show ScreenTips on Toolbars\" option.\r\n\r\nIf you enable this policy setting, ScreenTips will not be shown on toolbars.\r\n\r\nIf you disable or do not configure this policy setting, ScreenTips will be shown on toolbars.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_donotshowscreentipsontoolbars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_donotshowscreentipsontoolbars_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_largeicons","displayName":"Large icons (User)","description":"Checks/Unchecks the corresponding UI option. This option only applies to CommandBars UI.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_largeicons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_largeicons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_listfontnamesintheirfont","displayName":"List font names in their font (User)","description":"Checks/Unchecks the corresponding UI option. This option only applies to CommandBars UI.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_listfontnamesintheirfont_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_listfontnamesintheirfont_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations","displayName":"Menu animations (User)","description":"Checks/Unchecks the corresponding UI option. This option only applies to CommandBars UI.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_l_menuanimations209","displayName":"Menu animations (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_l_menuanimations209_0","displayName":"(System Default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_l_menuanimations209_1","displayName":"Random","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_l_menuanimations209_2","displayName":"Unfold","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_l_menuanimations209_3","displayName":"Slide","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_l_menuanimations209_4","displayName":"Fade","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy","displayName":"Disable UI extending from documents and templates (User)","description":"This policy setting controls whether Office 2016 applications load any custom user interface (UI) code included with a document or template. Office 2016 allows developers to extend the UI with customization code that is included in a document or template. \r\n\r\nIf you enable this policy setting, Office 2016 applications cannot load any UI customization code included with documents and templates. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 applications load any UI customization code included with a document or template when opening it.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyaccess","displayName":"Disallow in Access (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyaccess_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyaccess_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyexcel","displayName":"Disallow in Excel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyexcel_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyexcel_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyinfopath","displayName":"Disallow in InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyinfopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyinfopath_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyoutlook","displayName":"Disallow in Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyoutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyoutlook_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypowerpoint","displayName":"Disallow in PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypowerpoint_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyproject","displayName":"Disallow in Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyproject_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypublisher","displayName":"Disallow in Publisher (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypublisher_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypublisher_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyvisio","displayName":"Disallow in Visio (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyvisio_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyvisio_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyword","displayName":"Disallow in Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyword_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy","displayName":"Turn off all user customizations (User)","description":"This policy setting can prevent users from making any Quick Access Toolbar and the Ribbon customizations. This includes customizations made through user interface (UI) entry points, or loaded from documents or templates.\r\n\r\nIf you enable this policy setting, users will not be able to customize the Quick Access Toolbar and Ribbon through either the Quick Access Toolbar and Ribbon tabs in the application's Office Center dialog box, or the right-click menu on the Ribbon. In addition, Quick Access Toolbar and Ribbon customizations originating from documents or templates will not be loaded when these documents are opened.\r\n\r\nIf you disable or do not configure this policy setting, users can make Quick Access Toolbar and Ribbon customizations through the UI, as well as load them from documents and templates.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyaccess","displayName":"Disallow in Access (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyaccess_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyaccess_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyexcel","displayName":"Disallow in Excel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyexcel_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyexcel_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyinfopath","displayName":"Disallow in InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyinfopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyinfopath_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyonenote","displayName":"Disallow in OneNote (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyonenote_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyonenote_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyoutlook","displayName":"Disallow in Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyoutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyoutlook_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypowerpoint","displayName":"Disallow in PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypowerpoint_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyproject","displayName":"Disallow in Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyproject_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypublisher","displayName":"Disallow in Publisher (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypublisher_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypublisher_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspd","displayName":"Disallow in SharePoint Designer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspw","displayName":"Disallow in SharePoint Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspw_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspw_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyvisio","displayName":"Disallow in Visio (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyvisio_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyvisio_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyword","displayName":"Disallow in Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyword_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_showshortcutkeysinscreentips","displayName":"Show shortcut keys in ScreenTips (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_showshortcutkeysinscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_showshortcutkeysinscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_automaticdiscovery","displayName":"Automatic Discovery (User)","description":"Enables/Disables the Automatic Discovery feature.","helpText":"","infoUrls":[],"categoryId":"13123148-c522-437f-b316-d78f5cc0d28d","categoryName":"Shared Workspace","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_automaticdiscovery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_automaticdiscovery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_automaticdiscovery_l_automaticdiscovery210","displayName":"Automatic Discovery (User)","description":"","helpText":"","infoUrls":[],"categoryId":"13123148-c522-437f-b316-d78f5cc0d28d","categoryName":"Shared Workspace","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_automaticdiscovery_l_automaticdiscovery210_on","displayName":"On","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_automaticdiscovery_l_automaticdiscovery210_off","displayName":"Off","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_disableuserfromsettingpersonalsiteasdefaultlocation","displayName":"Disable user from setting personal site as default location (User)","description":"Checked: User is not able to define the default location to the personal site. | Unchecked: Default location is not restricted.","helpText":"","infoUrls":[],"categoryId":"13123148-c522-437f-b316-d78f5cc0d28d","categoryName":"Shared Workspace","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_disableuserfromsettingpersonalsiteasdefaultlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_disableuserfromsettingpersonalsiteasdefaultlocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace~l_definesharedworkspaceurls_l_site1","displayName":"Site 1: (User)","description":"Specifies the name and URL of a shared workspace. The name and URL appear in the Document Management pane.","helpText":"","infoUrls":[],"categoryId":"725adbdf-1eb8-45c4-8eb1-44747bd1615d","categoryName":"Define Shared Workspace URL's","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace~l_definesharedworkspaceurls_l_site1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace~l_definesharedworkspaceurls_l_site1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace~l_definesharedworkspaceurls_l_site1_l_name","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"725adbdf-1eb8-45c4-8eb1-44747bd1615d","categoryName":"Define Shared Workspace URL's","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace~l_definesharedworkspaceurls_l_site1_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"725adbdf-1eb8-45c4-8eb1-44747bd1615d","categoryName":"Define Shared Workspace URL's","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_charttemplatesserverlocation","displayName":"Chart Templates Server Location (User)","description":"Specifies the location [URL or UNC] for server-based chart templates.","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_charttemplatesserverlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_charttemplatesserverlocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_charttemplatesserverlocation_l_location","displayName":"Location: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_enablemsgraphasdefaultchart","displayName":"Enable MS Graph as Default Chart Tool in PowerPoint and Word (User)","description":"Enables administrators to set the default chart creation tool to MS Graph instead of the default Excel Chart in PowerPoint and Word. Also blocks conversion of Graph charts to Office charts.","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_enablemsgraphasdefaultchart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_enablemsgraphasdefaultchart_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_graphgallerypath","displayName":"Graph gallery path (User)","description":"Sets the path to store user-defined custom charts.","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_graphgallerypath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_graphgallerypath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_graphgallerypath_l_graphgallerypath354","displayName":"Graph gallery path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_help_l_federatedsearchforhelp","displayName":"Federated search for help (User)","description":"\r\n This policy setting allows you to determine the sources of content that Office users in your organization can access through Office Help (F1).\r\n\r\n If you enable or do not configure this policy setting, users who utilize Office Help see content from both Office and the Internet.\r\n\r\n If you disable this setting, Office users’ search results through Help are limited to Office content.\r\n ","helpText":"","infoUrls":[],"categoryId":"1942922a-cba9-44c8-871f-3d915c62bd06","categoryName":"Help","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_help_l_federatedsearchforhelp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_help_l_federatedsearchforhelp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltincolorvariations","displayName":"Disable built-in color variations (User)","description":"Specify whether or not to show the built-in color variations.","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltincolorvariations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltincolorvariations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltinigxgraphics","displayName":"Disable built-in graphics (User)","description":"Specify whether or not to show the built-in SmartArt Graphics.","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltinigxgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltinigxgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltinquickstyles","displayName":"Disable Built-in Quick Styles (User)","description":"Specify whether or not to show the built-in Quick Styles.","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltinquickstyles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltinquickstyles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel","displayName":"Error Severity Level (User)","description":"Specify the severity level of errors included in the log file created when loading layouts for SmartArt graphic layouts. Choosing Errors only will result in the smallest possible log file and choosing All will result in the largest log file.","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419","displayName":"Error Severity Level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_0","displayName":"Errors only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_1","displayName":"Level 1 warnings and below","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_2","displayName":"Level 2 warnings and below","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_3","displayName":"Level 3 warnings and below","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_4","displayName":"All","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber","displayName":"Log File Entries Number (User)","description":"Specify the number of log entries to be removed from the log file when the maximum size limit is exceeded. (1-1000)","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber_l_empty420","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfilemaximumsize","displayName":"Log File Maximum Size (User)","description":"Specify the maximum size in bytes for the log file created when loading custom layouts. (Maximum = 100000)","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfilemaximumsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfilemaximumsize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfilemaximumsize_l_logfilemaximumsizepart","displayName":"Bytes: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookcontactsdictionary","displayName":"Set comment fields for Outlook Contacts Dictionary (User)","description":"This policy setting allows you to specify the fields to display in the comments in the Outlook Contacts Dictionary. This policy setting applies to Japanese Microsoft IME only.\r\n\r\nIf you enable this policy setting, you can specify the fields to display by setting strings, which are represented by the following identification letter IDs. You must also use any IDs/strings in the following sequence.\r\n\r\nID for each field is as follows:\r\na = Full Name\r\nc = Phonetic Name\r\ne = Company Name\r\nf = Department Name\r\ng = Title\r\nh = Office Location\r\nj = Email Address\r\nk = Business Telephone Number\r\nl = Business Address\r\n\r\nFor example, if you want to display Full Name, Phonetic Name and Company Name, specify 'ace'.\r\n\r\nIf you do not configure this policy setting, Full Name, Phonetic Name, Company Name, Department Name, and Job Title are displayed in the comments in this order.","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookcontactsdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookcontactsdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookcontactsdictionary_l_setcommentfieldsforoutlookcontactsdictionaryid","displayName":"Field identification letters: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookglobaladdresslistdictionary","displayName":"Set comment fields for Outlook Global Address List Dictionary (User)","description":"This policy setting allows you to specify the fields to display in the comments in the Outlook Global Address List Dictionary. This policy setting applies to Japanese Microsoft IME only.\r\n\r\nIf you enable this policy setting, you can specify the fields to display by setting strings, which are represented by the following identification letter IDs. You must also use any IDs/strings in the following sequence.\r\n\r\nThe ID for each field is as follows:\r\na = Full Name\r\nc = Phonetic Name\r\ne = Company Name\r\nf = Department Name\r\ng = Title\r\nh = Office Location\r\nj = Email Address\r\nk = Business Telephone Number\r\nl = Business Address\r\n\r\nFor example, if you want to display Full Name, Phonetic Name and Company Name, specify 'ace'.\r\n\r\nIf you do not configure this policy setting, Full Name, Phonetic Name, Department Name, Job Title and Office Location are displayed in the comments, in this order.","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookglobaladdresslistdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookglobaladdresslistdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookglobaladdresslistdictionary_l_setcommentfieldsforoutlookglobaladdresslistdictionaryid","displayName":"Field identification letters: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookcontactsdictionary","displayName":"Set update interval for Outlook Contacts Dictionary (User)","description":"This policy setting allows you to specify the update interval for the Outlook Contacts Dictionary. This policy setting applies to Japanese Microsoft IME only.\r\n\r\nIf you enable this policy setting, you can specify the update interval. For example, if you specify \"720,\" the Outlook Contacts Dictionary is updated every 720 minutes.\r\n\r\nIf you do not configure this policy setting, the Outlook Contacts Dictionary is updated every 1440 minutes (24 hours).","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookcontactsdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookcontactsdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookcontactsdictionary_l_setupdateintervalforoutlookcontactsdictionaryspinid","displayName":"(in minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary","displayName":"Set update interval for Outlook Global Address List Dictionary (User)","description":"This policy setting allows you to specify the update interval for the Outlook Global Address List Dictionary. This policy setting applies to Japanese Microsoft IME only.\r\n\r\n\r\nIf you enable this policy setting, you can specify the update interval in minutes. For example, if you specify \"720,\" the Outlook Global Address List Dictionary is updated every 720 minutes.\r\n\r\nIf you do not configure this policy setting, the Outlook Global Address List Dictionary is updated every 1440 minutes (24 hours).","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary_l_setupdateintervalforoutlookglobaladdresslistdictionaryspinid","displayName":"(in minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffoutlooknamedictionaries","displayName":"Turn off Outlook name dictionaries update (User)","description":"This policy setting allows you to turn off updating for Outlook name dictionaries of Microsoft IME (Input Method Editor). This policy setting applies to Japanese Microsoft IME only.\r\n\r\nIf you enable this policy setting, all Outlook name dictionaries are not updated.\r\nOutlook name dictionaries that were added before enabling this policy setting are used for conversion.\r\n\r\nIf you disable or do not configure this policy setting, Outlook name dictionaries are generated, updated and used for conversion.","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffoutlooknamedictionaries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffoutlooknamedictionaries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffsharepointdictionary","displayName":"Turn off SharePoint dictionary update (User)","description":"This policy setting allows you to turn off updating for SharePoint dictionary of Microsoft IME (Input Method Editor). This policy setting applies to Japanese Microsoft IME only.\r\n\r\nIf you enable this policy setting, SharePoint dictionary is not updated, and you cannot add a new SharePoint dictionary.\r\nA SharePoint dictionary that was added before enabling this policy setting is used for conversion.\r\n\r\nIf you disable or do not configure this policy setting, SharePoint dictionary can be updated and added.","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffsharepointdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffsharepointdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingerrormessages","displayName":"Stop reporting error messages (User)","description":"This policy setting controls whether the application reports error messages.\r\n\r\nIf you enable this policy, error messages will not be reported.\r\n\r\nIf you disable or do not configure this policy setting, error messages will be reported.","helpText":"","infoUrls":[],"categoryId":"33fb4f49-5c7f-472c-a0f3-e05646a55902","categoryName":"Improved Error Reporting","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingerrormessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingerrormessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingnoncriticalerrors","displayName":"Stop reporting non-critical errors (User)","description":"This policy setting controls whether the application reports non-critical errors.\r\n\r\nIf you enable this policy, non-critical errors will not be reported.\r\n\r\nIf you disable or do not configure this policy setting, non-critical errors will be reported.","helpText":"","infoUrls":[],"categoryId":"33fb4f49-5c7f-472c-a0f3-e05646a55902","categoryName":"Improved Error Reporting","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingnoncriticalerrors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingnoncriticalerrors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings_l_disableproofingtoolsadvertisement","displayName":"Notify users if they do not have proofing tools for a language they use (User)","description":"This policy setting allows you to turn on or turn off notifications that are displayed to users when they use a language in their document but do not have proofing tools installed for that language.\r\n\r\nIf you enable this policy setting, users see a message bar when they use a language in their document but do not have proofing tools installed for that language. Users cannot disable this notification because the \"Never show again\" button is not shown, and the checkbox to disable proofing notifications is removed from the Options dialog box.\r\n\r\nIf you disable this policy setting, users do not see this message bar.\r\n\r\nIf you do not configure this policy setting, users see this message bar. They can disable the notification by clicking the \"Never show again\" button or by clearing a check box in the Options dialog box.","helpText":"","infoUrls":[],"categoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","categoryName":"Language Preferences","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings_l_disableproofingtoolsadvertisement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings_l_disableproofingtoolsadvertisement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktolanguagepackdownloadsite","displayName":"Change or delete link to language pack download site (User)","description":"This policy setting affects the language download link under the display and help language section.\r\n\r\nIf you enable this policy setting you, you may enter the URL to another location where language packs may be downloaded.\r\n\r\nIf you disable this policy setting the URL will be removed.\r\n\r\nIf you do not configure this policy setting, the URL will remain available and point to the language pack download site on Office.com.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktolanguagepackdownloadsite_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktolanguagepackdownloadsite_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktolanguagepackdownloadsite_l_changeordeletelinktolanguagepackdownloadsiteid","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite","displayName":"Change or delete link to the proofing tools download site (User)","description":"This policy setting affects the proofing tools link under the Editing language section.\r\n\r\nIf you enable this policy setting you, you may enter the URL to another location where proofing tools may be downloaded.\r\n\r\nIf you disable this policy setting the URL will be removed.\r\n\r\nIf you do not configure this policy setting, the URL will remain available and point to the proofing tools site on Office.com.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite_l_changeordeletelinktoproofingtoolsdownloadsiteid","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin","displayName":"Display help in (User)","description":"Sets the default language of online Help. In addition to configuring this setting, consider enabling the same language in the 'Enabled Editing Languages' policy node.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336","displayName":"Display help in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_0","displayName":"(same as menus and dialog boxes)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1078","displayName":"Afrikaans","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1052","displayName":"Albanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1118","displayName":"Amharic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1025","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1067","displayName":"Armenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1101","displayName":"Assamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1068","displayName":"Azerbaijani (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2117","displayName":"Bangla (Bangladesh)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1093","displayName":"Bangla (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1069","displayName":"Basque","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1059","displayName":"Belarusian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_5146","displayName":"Bosnian (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1026","displayName":"Bulgarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1027","displayName":"Catalan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1170","displayName":"Central Kurdish (Iraq)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1116","displayName":"Cherokee","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2052","displayName":"Chinese (Simplified)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1028","displayName":"Chinese (Traditional)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1050","displayName":"Croatian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1029","displayName":"Czech","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1030","displayName":"Danish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1164","displayName":"Dari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1043","displayName":"Dutch","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1033","displayName":"English","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1061","displayName":"Estonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1124","displayName":"Filipino","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1035","displayName":"Finnish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1036","displayName":"French","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1110","displayName":"Galician","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1079","displayName":"Georgian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1031","displayName":"German","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1032","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1095","displayName":"Gujarati","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1128","displayName":"Hausa (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1037","displayName":"Hebrew","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1081","displayName":"Hindi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1038","displayName":"Hungarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1039","displayName":"Icelandic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1136","displayName":"Igbo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1057","displayName":"Indonesian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2141","displayName":"Inuktitut (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2108","displayName":"Irish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1076","displayName":"isiXhosa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1077","displayName":"isiZulu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1040","displayName":"Italian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1041","displayName":"Japanese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1099","displayName":"Kannada","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1087","displayName":"Kazakh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1107","displayName":"Khmer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1158","displayName":"K'iche","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1159","displayName":"Kinyarwanda","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1089","displayName":"Swahili","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1111","displayName":"Konkani","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1042","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1088","displayName":"Kyrgyz","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1062","displayName":"Latvian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1063","displayName":"Lithuanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1134","displayName":"Luxembourgish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1086","displayName":"Malay (Malaysia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1100","displayName":"Malayalam","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1082","displayName":"Maltese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1153","displayName":"Maori","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1102","displayName":"Marathi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1104","displayName":"Mongolian (Cyrillic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1071","displayName":"Macedonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1121","displayName":"Nepali","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1044","displayName":"Norwegian (Bokmal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2068","displayName":"Norwegian (Nynorsk)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1096","displayName":"Odia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1065","displayName":"Persian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1045","displayName":"Polish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1046","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2070","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1094","displayName":"Punjabi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2118","displayName":"Punjabi (Pakistan)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_3179","displayName":"Quechua (Peru)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1048","displayName":"Romanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1049","displayName":"Russian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1169","displayName":"Scottish Gaelic (United Kingdom)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_3098","displayName":"Serbian (Cyrillic, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_7194","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2074","displayName":"Serbian (Latin, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1132","displayName":"Sesotho sa Leboa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1074","displayName":"Setswana","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2137","displayName":"Sindhi (Arabic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1115","displayName":"Sinhala","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1051","displayName":"Slovak","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1060","displayName":"Slovenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_3082","displayName":"Spanish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1053","displayName":"Swedish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1064","displayName":"Tajik","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1097","displayName":"Tamil","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1092","displayName":"Tatar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1098","displayName":"Telugu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1054","displayName":"Thai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1139","displayName":"Tigrinya (Ethiopia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1055","displayName":"Turkish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1090","displayName":"Turkmen","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1058","displayName":"Ukrainian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1056","displayName":"Urdu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1152","displayName":"Uyghur (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1091","displayName":"Uzbek (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2051","displayName":"Valencian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1066","displayName":"Vietnamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1106","displayName":"Welsh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1160","displayName":"Wolof","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1130","displayName":"Yoruba","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin","displayName":"Display menus and dialog boxes in (User)","description":"Sets the display language of the user interface for all Office 2016 programs. In addition to configuring this setting, consider enabling the same language in the 'Enabled Editing Languages' policy node.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334","displayName":"Display menus and dialog boxes in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_0","displayName":"(same as the system)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1078","displayName":"Afrikaans","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1052","displayName":"Albanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1118","displayName":"Amharic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1025","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1067","displayName":"Armenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1101","displayName":"Assamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1068","displayName":"Azerbaijani (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2117","displayName":"Bangla (Bangladesh)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1093","displayName":"Bangla (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1069","displayName":"Basque","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1059","displayName":"Belarusian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_5146","displayName":"Bosnian (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1026","displayName":"Bulgarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1027","displayName":"Catalan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1170","displayName":"Central Kurdish (Iraq)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1116","displayName":"Cherokee","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2052","displayName":"Chinese (Simplified)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1028","displayName":"Chinese (Traditional)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1050","displayName":"Croatian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1029","displayName":"Czech","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1030","displayName":"Danish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1164","displayName":"Dari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1043","displayName":"Dutch","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1033","displayName":"English","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1061","displayName":"Estonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1124","displayName":"Filipino","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1035","displayName":"Finnish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1036","displayName":"French","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1110","displayName":"Galician","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1079","displayName":"Georgian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1031","displayName":"German","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1032","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1095","displayName":"Gujarati","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1128","displayName":"Hausa (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1037","displayName":"Hebrew","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1081","displayName":"Hindi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1038","displayName":"Hungarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1039","displayName":"Icelandic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1136","displayName":"Igbo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1057","displayName":"Indonesian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2141","displayName":"Inuktitut (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2108","displayName":"Irish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1076","displayName":"isiXhosa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1077","displayName":"isiZulu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1040","displayName":"Italian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1041","displayName":"Japanese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1099","displayName":"Kannada","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1087","displayName":"Kazakh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1107","displayName":"Khmer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1158","displayName":"K'iche","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1159","displayName":"Kinyarwanda","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1088","displayName":"Kyrgyz","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1089","displayName":"Swahili","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1111","displayName":"Konkani","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1042","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1062","displayName":"Latvian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1063","displayName":"Lithuanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1134","displayName":"Luxembourgish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1086","displayName":"Malay (Malaysia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1100","displayName":"Malayalam","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1082","displayName":"Maltese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1153","displayName":"Maori","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1102","displayName":"Marathi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1071","displayName":"Macedonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1104","displayName":"Mongolian (Cyrillic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1121","displayName":"Nepali","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1044","displayName":"Norwegian (Bokmal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2068","displayName":"Norwegian (Nynorsk)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1096","displayName":"Odia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1065","displayName":"Persian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1045","displayName":"Polish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1046","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2070","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1094","displayName":"Punjabi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2118","displayName":"Punjabi (Pakistan)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_3179","displayName":"Quechua (Peru)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1048","displayName":"Romanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1049","displayName":"Russian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1169","displayName":"Scottish Gaelic (United Kingdom)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_3098","displayName":"Serbian (Cyrillic, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_7194","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2074","displayName":"Serbian (Latin, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1132","displayName":"Sesotho sa Leboa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1074","displayName":"Setswana","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2137","displayName":"Sindhi (Arabic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1115","displayName":"Sinhala","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1051","displayName":"Slovak","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1060","displayName":"Slovenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_3082","displayName":"Spanish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1053","displayName":"Swedish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1064","displayName":"Tajik","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1097","displayName":"Tamil","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1092","displayName":"Tatar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1098","displayName":"Telugu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1054","displayName":"Thai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1139","displayName":"Tigrinya (Ethiopia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1055","displayName":"Turkish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1090","displayName":"Turkmen","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1058","displayName":"Ukrainian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1056","displayName":"Urdu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1152","displayName":"Uyghur (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1091","displayName":"Uzbek (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2051","displayName":"Valencian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1066","displayName":"Vietnamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1106","displayName":"Welsh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1160","displayName":"Wolof","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1130","displayName":"Yoruba","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage","displayName":"Primary Editing Language (User)","description":"Defines the editing options for Office 2016 programs. In addition to configuring this setting, consider enabling the same language in the 'Enabled Editing Languages' policy node. Please refer to the Office Resource Kit documentation for important information on setting the installed version of Microsoft Office.","helpText":"","infoUrls":[],"categoryId":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","categoryName":"Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341","displayName":"Primary Editing Language (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","categoryName":"Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1078","displayName":"Afrikaans","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1052","displayName":"Albanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1156","displayName":"Alsatian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1118","displayName":"Amharic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5121","displayName":"Arabic (Algeria)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_15361","displayName":"Arabic (Bahrain)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3073","displayName":"Arabic (Egypt)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2049","displayName":"Arabic (Iraq)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_11265","displayName":"Arabic (Jordan)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_13313","displayName":"Arabic (Kuwait)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_12289","displayName":"Arabic (Lebanon)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4097","displayName":"Arabic (Libya)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_6145","displayName":"Arabic (Morocco)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_8193","displayName":"Arabic (Oman)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_16385","displayName":"Arabic (Qatar)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1025","displayName":"Arabic (Saudi Arabia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_10241","displayName":"Arabic (Syria)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_7169","displayName":"Arabic (Tunisia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_14337","displayName":"Arabic (U.A.E.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_9217","displayName":"Arabic (Yemen)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1067","displayName":"Armenian (Armenia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1101","displayName":"Assamese (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2092","displayName":"Azerbaijani (Cyrillic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1068","displayName":"Azerbaijani (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2117","displayName":"Bangla (Bangladesh)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1093","displayName":"Bangla (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1133","displayName":"Bashkir","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1069","displayName":"Basque","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1059","displayName":"Belarusian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_8218","displayName":"Bosnian (Cyrillic, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5146","displayName":"Bosnian (Latin, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1150","displayName":"Breton","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1026","displayName":"Bulgarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1109","displayName":"Burmese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1027","displayName":"Catalan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1170","displayName":"Central Kurdish (Iraq)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1116","displayName":"Cherokee","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2052","displayName":"Chinese (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3076","displayName":"Chinese (Hong Kong S.A.R.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5124","displayName":"Chinese (Macao S.A.R.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4100","displayName":"Chinese (Singapore)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1028","displayName":"Chinese (Taiwan)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1155","displayName":"Corsican","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4122","displayName":"Croatian (Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1050","displayName":"Croatian (Croatia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1029","displayName":"Czech","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1030","displayName":"Danish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1164","displayName":"Dari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1125","displayName":"Divehi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2067","displayName":"Dutch (Belgium)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1043","displayName":"Dutch (Netherlands)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1126","displayName":"Edo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3081","displayName":"English (Australia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_10249","displayName":"English (Belize)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4105","displayName":"English (Canada)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_9225","displayName":"English (Caribbean)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_15369","displayName":"English (Hong Kong S.A.R.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_16393","displayName":"English (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_14345","displayName":"English (Indonesia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_6153","displayName":"English (Ireland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_8201","displayName":"English (Jamaica)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_17417","displayName":"English (Malaysia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5129","displayName":"English (New Zealand)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_13321","displayName":"English (Philippines)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_18441","displayName":"English (Singapore)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_7177","displayName":"English (South Africa)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_11273","displayName":"English (Trinidad and Tobago)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2057","displayName":"English (U.K.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1033","displayName":"English (U.S.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_12297","displayName":"English (Zimbabwe)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1061","displayName":"Estonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1080","displayName":"Faeroese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1124","displayName":"Filipino","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1035","displayName":"Finnish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2060","displayName":"French (Belgium)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_11276","displayName":"French (Cameroon)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3084","displayName":"French (Canada)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_7180","displayName":"French (Caribbean)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_9228","displayName":"French (Congo (DRC))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_12300","displayName":"French (Côte d'Ivoire)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1036","displayName":"French (France)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_15372","displayName":"French (Haiti)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5132","displayName":"French (Luxembourg)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_13324","displayName":"French (Mali)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_6156","displayName":"French (Monaco)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_14348","displayName":"French (Morocco)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_8204","displayName":"French (Reunion)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_10252","displayName":"French (Senegal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4108","displayName":"French (Switzerland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1122","displayName":"Frisian (Netherlands)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1127","displayName":"Fulfulde","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1169","displayName":"Scottish Gaelic (United Kingdom)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1110","displayName":"Galician","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1079","displayName":"Georgian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3079","displayName":"German (Austria)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1031","displayName":"German (Germany)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5127","displayName":"German (Liechtenstein)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4103","displayName":"German (Luxembourg)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2055","displayName":"German (Switzerland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1032","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1135","displayName":"Greenlandic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1140","displayName":"Guarani","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1095","displayName":"Gujarati","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1128","displayName":"Hausa (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1141","displayName":"Hawaiian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1037","displayName":"Hebrew (Israel)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1081","displayName":"Hindi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1038","displayName":"Hungarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1129","displayName":"Ibibio","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1039","displayName":"Icelandic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1136","displayName":"Igbo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1057","displayName":"Indonesian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2141","displayName":"Inuktitut (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1117","displayName":"Inuktitut (Syllabics)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2108","displayName":"Irish (Ireland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1077","displayName":"isiZulu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1076","displayName":"isiXhosa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1040","displayName":"Italian (Italy)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2064","displayName":"Italian (Switzerland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1041","displayName":"Japanese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1099","displayName":"Kannada","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1137","displayName":"Kanuri","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1120","displayName":"Kashmiri (Arabic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2144","displayName":"Kashmiri (Devanagari)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1087","displayName":"Kazakh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1107","displayName":"Khmer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1158","displayName":"K'iche","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1159","displayName":"Kinyarwanda","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1111","displayName":"Konkani","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1042","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1088","displayName":"Kyrgyz","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1108","displayName":"Lao","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1142","displayName":"Latin","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1062","displayName":"Latvian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1063","displayName":"Lithuanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1134","displayName":"Luxembourgish (Luxembourg)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1071","displayName":"Macedonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2110","displayName":"Malay (Brunei)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1086","displayName":"Malay (Malaysia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1100","displayName":"Malayalam","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1082","displayName":"Maltese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1112","displayName":"Manipuri","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1153","displayName":"Maori","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1146","displayName":"Mapudungun","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1102","displayName":"Marathi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1148","displayName":"Mohawk","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1104","displayName":"Mongolian (Cyrillic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2128","displayName":"Mongolian (Traditional Mongolian)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2145","displayName":"Nepali (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1121","displayName":"Nepali (Nepal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1044","displayName":"Norwegian (Bokmål)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2068","displayName":"Norwegian (Nynorsk)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1154","displayName":"Occitan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1138","displayName":"Oromo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1096","displayName":"Odia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1145","displayName":"Papiamentu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1123","displayName":"Pashto","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1065","displayName":"Persian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1045","displayName":"Polish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1046","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2070","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1094","displayName":"Punjabi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2118","displayName":"Punjabi (Pakistan)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1131","displayName":"Quechua (Bolivia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2155","displayName":"Quechua (Ecuador)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3179","displayName":"Quechua (Peru)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1047","displayName":"Romansh (Switzerland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2072","displayName":"Romanian (Moldova)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1048","displayName":"Romanian (Romania)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2073","displayName":"Russian (Moldova)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1049","displayName":"Russian (Russia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_9275","displayName":"Sami, Inari (Finland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4155","displayName":"Sami, Lule (Norway)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5179","displayName":"Sami, Lule (Sweden)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3131","displayName":"Sami, Northern (Finland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1083","displayName":"Sami, Northern (Norway)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2107","displayName":"Sami, Northern (Sweden)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_8251","displayName":"Sami, Skolt (Finland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_6203","displayName":"Sami, Southern (Norway)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_7227","displayName":"Sami, Southern (Sweden)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1103","displayName":"Sanskrit","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_7194","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_6170","displayName":"Serbian (Latin, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3098","displayName":"Serbian (Cyrillic, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_10266","displayName":"Serbian (Cyrillic, Serbia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_12314","displayName":"Serbian (Cyrillic, Montenegro)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2074","displayName":"Serbian (Latin, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_11290","displayName":"Serbian (Latin, Montenegro)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_9242","displayName":"Serbian (Latin, Serbia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1072","displayName":"Sesotho","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1132","displayName":"Sesotho sa Leboa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1074","displayName":"Setswana","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1113","displayName":"Sindhi (Devanagari)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2137","displayName":"Sindhi (Arabic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1115","displayName":"Sinhala","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1051","displayName":"Slovak","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1060","displayName":"Slovenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1143","displayName":"Somali","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2094","displayName":"Lower Sorbian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1070","displayName":"Upper Sorbian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_11274","displayName":"Spanish (Argentina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_16394","displayName":"Spanish (Bolivia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_13322","displayName":"Spanish (Chile)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_9226","displayName":"Spanish (Colombia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5130","displayName":"Spanish (Costa Rica)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_7178","displayName":"Spanish (Dominican Republic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_12298","displayName":"Spanish (Ecuador)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_17418","displayName":"Spanish (El Salvador)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4106","displayName":"Spanish (Guatemala)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_18442","displayName":"Spanish (Honduras)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2058","displayName":"Spanish (Mexico)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_19466","displayName":"Spanish (Nicaragua)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_6154","displayName":"Spanish (Panama)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_15370","displayName":"Spanish (Paraguay)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_10250","displayName":"Spanish (Peru)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_20490","displayName":"Spanish (Puerto Rico)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3082","displayName":"Spanish (Spain)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_21514","displayName":"Spanish (United States)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_14346","displayName":"Spanish (Uruguay)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_8202","displayName":"Spanish (Venezuela)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1089","displayName":"Swahili","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2077","displayName":"Swedish (Finland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1053","displayName":"Swedish (Sweden)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1114","displayName":"Syriac","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2143","displayName":"Tamazight (Latin, Algeria)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1119","displayName":"Tamazight (Arabic, Morocco)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1097","displayName":"Tamil","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1092","displayName":"Tatar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1098","displayName":"Telugu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1064","displayName":"Tajik","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1054","displayName":"Thai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1105","displayName":"Tibetan (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2163","displayName":"Tigrinya (Eritrea)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1139","displayName":"Tigrinya (Ethiopia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1055","displayName":"Turkish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1090","displayName":"Turkmen","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1152","displayName":"Uyghur (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1058","displayName":"Ukrainian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1056","displayName":"Urdu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2115","displayName":"Uzbek (Cyrillic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1091","displayName":"Uzbek (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2051","displayName":"Valencian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1075","displayName":"Venda","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1066","displayName":"Vietnamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1106","displayName":"Welsh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1160","displayName":"Wolof","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1073","displayName":"Xitsonga","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1157","displayName":"Sakha","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1144","displayName":"Yi (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1085","displayName":"Yiddish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1130","displayName":"Yoruba","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_afrikaans","displayName":"Afrikaans (User)","description":"Enables the editing language Afrikaans","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_afrikaans_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_afrikaans_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_albanian","displayName":"Albanian (User)","description":"Enables the editing language Albanian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_albanian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_albanian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_alsatian","displayName":"Alsatian (User)","description":"Enables the editing language Alsatian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_alsatian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_alsatian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_amharic","displayName":"Amharic (User)","description":"Enables the editing language Amharic","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_amharic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_amharic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicalgeria","displayName":"Arabic (Algeria) (User)","description":"Enables the editing language Arabic (Algeria)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicalgeria_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicalgeria_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicbahrain","displayName":"Arabic (Bahrain) (User)","description":"Enables the editing language Arabic (Bahrain)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicbahrain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicbahrain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicegypt","displayName":"Arabic (Egypt) (User)","description":"Enables the editing language Arabic (Egypt)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicegypt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicegypt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiciraq","displayName":"Arabic (Iraq) (User)","description":"Enables the editing language Arabic (Iraq)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiciraq_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiciraq_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicjordan","displayName":"Arabic (Jordan) (User)","description":"Enables the editing language Arabic (Jordan)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicjordan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicjordan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabickuwait","displayName":"Arabic (Kuwait) (User)","description":"Enables the editing language Arabic (Kuwait)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabickuwait_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabickuwait_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclebanon","displayName":"Arabic (Lebanon) (User)","description":"Enables the editing language Arabic (Lebanon)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclebanon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclebanon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclibya","displayName":"Arabic (Libya) (User)","description":"Enables the editing language Arabic (Libya)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclibya_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclibya_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicmorocco","displayName":"Arabic (Morocco) (User)","description":"Enables the editing language Arabic (Morocco)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicmorocco_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicmorocco_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicoman","displayName":"Arabic (Oman) (User)","description":"Enables the editing language Arabic (Oman)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicoman_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicoman_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicqatar","displayName":"Arabic (Qatar) (User)","description":"Enables the editing language Arabic (Qatar)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicqatar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicqatar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicsaudiarabia","displayName":"Arabic (Saudi Arabia) (User)","description":"Enables the editing language Arabic (Saudi Arabia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicsaudiarabia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicsaudiarabia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicsyria","displayName":"Arabic (Syria) (User)","description":"Enables the editing language Arabic (Syria)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicsyria_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicsyria_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabictunisia","displayName":"Arabic (Tunisia) (User)","description":"Enables the editing language Arabic (Tunisia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabictunisia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabictunisia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicuae","displayName":"Arabic (U.A.E.) (User)","description":"Enables the editing language Arabic (U.A.E.)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicuae_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicuae_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicyemen","displayName":"Arabic (Yemen) (User)","description":"Enables the editing language Arabic (Yemen)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicyemen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicyemen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_armenianarmenia","displayName":"Armenian (Armenia) (User)","description":"Enables the editing language Armenian (Armenia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_armenianarmenia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_armenianarmenia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_assameseindia","displayName":"Assamese (India) (User)","description":"Enables the editing language Assamese (India)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_assameseindia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_assameseindia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_azerbaijanicyrillic","displayName":"Azerbaijani (Cyrillic) (User)","description":"Enables the editing language Azerbaijani (Cyrillic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_azerbaijanicyrillic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_azerbaijanicyrillic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_azerbaijanilatin","displayName":"Azerbaijani (Latin) (User)","description":"Enables the editing language Azerbaijani (Latin)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_azerbaijanilatin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_azerbaijanilatin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglabangladesh","displayName":"Bangla (Bangladesh) (User)","description":"Enables the editing language Bangla (Bangladesh)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglabangladesh_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglabangladesh_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglaindia","displayName":"Bangla (India) (User)","description":"Enables the editing language Bangla (India)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglaindia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglaindia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bashkir","displayName":"Bashkir (User)","description":"Enables the editing language Bashkir","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bashkir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bashkir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_basque","displayName":"Basque (User)","description":"Enables the editing language Basque","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_basque_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_basque_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_belarusian","displayName":"Belarusian (User)","description":"Enables the editing language Belarusian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_belarusian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_belarusian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosniancyrillicbosniaandherzegovina","displayName":"Bosnian (Cyrillic, Bosnia and Herzegovina) (User)","description":"Enables the editing language \"Bosnian (Cyrillic, Bosnia and Herzegovina)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosniancyrillicbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosniancyrillicbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosnianlatinbosniaandherzegovina","displayName":"Bosnian (Latin, Bosnia and Herzegovina) (User)","description":"Enables the editing language \"Bosnian (Latin, Bosnia and Herzegovina)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosnianlatinbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosnianlatinbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_breton","displayName":"Breton (User)","description":"Enables the editing language Breton","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_breton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_breton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bulgarian","displayName":"Bulgarian (User)","description":"Enables the editing language Bulgarian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bulgarian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bulgarian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_burmese","displayName":"Burmese (User)","description":"Enables the editing language Burmese","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_burmese_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_burmese_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_catalan","displayName":"Catalan (User)","description":"Enables the editing language Catalan","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_catalan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_catalan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_centralkurdishiraq","displayName":"Central Kurdish (Iraq) (User)","description":"Enables the editing language Central Kurdish (Iraq)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_centralkurdishiraq_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_centralkurdishiraq_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_cherokee","displayName":"Cherokee (User)","description":"Enables the editing language Cherokee","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_cherokee_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_cherokee_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesehongkongsar","displayName":"Chinese (Hong Kong S.A.R.) (User)","description":"Enables the editing language Chinese (Hong Kong S.A.R.)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesehongkongsar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesehongkongsar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesemacaosar","displayName":"Chinese (Macao S.A.R.) (User)","description":"Enables the editing language Chinese (Macao S.A.R.)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesemacaosar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesemacaosar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chineseprc","displayName":"Chinese (PRC) (User)","description":"Enables the editing language Chinese (PRC)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chineseprc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chineseprc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesesingapore","displayName":"Chinese (Singapore) (User)","description":"Enables the editing language Chinese (Singapore)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesesingapore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesesingapore_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesetaiwan","displayName":"Chinese (Taiwan) (User)","description":"Enables the editing language Chinese (Taiwan)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesetaiwan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesetaiwan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_corsican","displayName":"Corsican (User)","description":"Enables the editing language Corsican","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_corsican_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_corsican_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatianbosniaandherzegovina","displayName":"Croatian (Bosnia and Herzegovina) (User)","description":"Enables the editing language Croatian (Bosnia and Herzegovina)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatianbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatianbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatiancroatia","displayName":"Croatian (Croatia) (User)","description":"Enables the editing language Croatian (Croatia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatiancroatia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatiancroatia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_czech","displayName":"Czech (User)","description":"Enables the editing language Czech","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_czech_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_czech_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_danish","displayName":"Danish (User)","description":"Enables the editing language Danish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_danish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_danish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dari","displayName":"Dari (User)","description":"Enables the editing language Dari","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dari_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dari_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_divehi","displayName":"Divehi (User)","description":"Enables the editing language Divehi","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_divehi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_divehi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dutchbelgium","displayName":"Dutch (Belgium) (User)","description":"Enables the editing language Dutch (Belgium)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dutchbelgium_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dutchbelgium_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dutchnetherlands","displayName":"Dutch (Netherlands) (User)","description":"Enables the editing language Dutch (Netherlands)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dutchnetherlands_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dutchnetherlands_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_edo","displayName":"Edo (User)","description":"Enables the editing language Edo","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_edo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_edo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishaustralia","displayName":"English (Australia) (User)","description":"Enables the editing language English (Australia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishaustralia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishaustralia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishbelize","displayName":"English (Belize) (User)","description":"Enables the editing language English (Belize)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishbelize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishbelize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcanada","displayName":"English (Canada) (User)","description":"Enables the editing language English (Canada)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcanada_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcanada_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcaribbean","displayName":"English (Caribbean) (User)","description":"Enables the editing language English (Caribbean)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcaribbean_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcaribbean_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishhongkongsar","displayName":"English (Hong Kong S.A.R.) (User)","description":"Enables the editing language English (Hong Kong S.A.R.)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishhongkongsar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishhongkongsar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishindia","displayName":"English (India) (User)","description":"Enables the editing language English (India)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishindia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishindia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishindonesia","displayName":"English (Indonesia) (User)","description":"Enables the editing language English (Indonesia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishindonesia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishindonesia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishireland","displayName":"English (Ireland) (User)","description":"Enables the editing language English (Ireland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishireland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishireland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishjamaica","displayName":"English (Jamaica) (User)","description":"Enables the editing language English (Jamaica)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishjamaica_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishjamaica_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishmalaysia","displayName":"English (Malaysia) (User)","description":"Enables the editing language English (Malaysia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishmalaysia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishmalaysia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishnewzealand","displayName":"English (New Zealand) (User)","description":"Enables the editing language English (New Zealand)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishnewzealand_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishnewzealand_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishphilippines","displayName":"English (Philippines) (User)","description":"Enables the editing language English (Philippines)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishphilippines_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishphilippines_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishsingapore","displayName":"English (Singapore) (User)","description":"Enables the editing language English (Singapore)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishsingapore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishsingapore_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishsouthafrica","displayName":"English (South Africa) (User)","description":"Enables the editing language English (South Africa)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishsouthafrica_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishsouthafrica_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishtrinidadandtobago","displayName":"English (Trinidad and Tobago) (User)","description":"Enables the editing language English (Trinidad and Tobago)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishtrinidadandtobago_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishtrinidadandtobago_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishuk","displayName":"English (U.K.) (User)","description":"Enables the editing language English (U.K.)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishuk_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishuk_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishus","displayName":"English (U.S.) (User)","description":"Enables the editing language English (U.S.)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishus_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishus_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishzimbabwe","displayName":"English (Zimbabwe) (User)","description":"Enables the editing language English (Zimbabwe)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishzimbabwe_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishzimbabwe_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_estonian","displayName":"Estonian (User)","description":"Enables the editing language Estonian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_estonian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_estonian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_faeroese","displayName":"Faeroese (User)","description":"Enables the editing language Faeroese","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_faeroese_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_faeroese_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_filipino","displayName":"Filipino (User)","description":"Enables the editing language Filipino","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_filipino_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_filipino_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_finnish","displayName":"Finnish (User)","description":"Enables the editing language Finnish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_finnish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_finnish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchbelgium","displayName":"French (Belgium) (User)","description":"Enables the editing language French (Belgium)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchbelgium_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchbelgium_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcameroon","displayName":"French (Cameroon) (User)","description":"Enables the editing language French (Cameroon)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcameroon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcameroon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcanada","displayName":"French (Canada) (User)","description":"Enables the editing language French (Canada)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcanada_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcanada_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcaribbean","displayName":"French (Caribbean) (User)","description":"Enables the editing language French (Caribbean)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcaribbean_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcaribbean_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcongodrc","displayName":"French (Congo (DRC)) (User)","description":"Enables the editing language French (Congo (DRC))","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcongodrc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcongodrc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcotedivoire","displayName":"French (Côte d'Ivoire) (User)","description":"Enables the editing language French (Côte d'Ivoire)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcotedivoire_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcotedivoire_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchfrance","displayName":"French (France) (User)","description":"Enables the editing language French (France)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchfrance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchfrance_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchhaiti","displayName":"French (Haiti) (User)","description":"Enables the editing language French (Haiti)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchhaiti_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchhaiti_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchluxembourg","displayName":"French (Luxembourg) (User)","description":"Enables the editing language French (Luxembourg)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchluxembourg_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchluxembourg_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmali","displayName":"French (Mali) (User)","description":"Enables the editing language French (Mali)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmali_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmali_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmonaco","displayName":"French (Monaco) (User)","description":"Enables the editing language French (Monaco)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmonaco_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmonaco_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmorocco","displayName":"French (Morocco) (User)","description":"Enables the editing language French (Morocco)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmorocco_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmorocco_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchreunion","displayName":"French (Reunion) (User)","description":"Enables the editing language French (Reunion)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchreunion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchreunion_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchsenegal","displayName":"French (Senegal) (User)","description":"Enables the editing language French (Senegal)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchsenegal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchsenegal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchswitzerland","displayName":"French (Switzerland) (User)","description":"Enables the editing language French (Switzerland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchswitzerland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchswitzerland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frisiannetherlands","displayName":"Frisian (Netherlands) (User)","description":"Enables the editing language Frisian (Netherlands)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frisiannetherlands_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frisiannetherlands_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_fulfulde","displayName":"Fulfulde (User)","description":"Enables the editing language Fulfulde","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_fulfulde_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_fulfulde_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_galician","displayName":"Galician (User)","description":"Enables the editing language Galician","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_galician_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_galician_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_georgian","displayName":"Georgian (User)","description":"Enables the editing language Georgian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_georgian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_georgian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanaustria","displayName":"German (Austria) (User)","description":"Enables the editing language German (Austria)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanaustria_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanaustria_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germangermany","displayName":"German (Germany) (User)","description":"Enables the editing language German (Germany)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germangermany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germangermany_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanliechtenstein","displayName":"German (Liechtenstein) (User)","description":"Enables the editing language German (Liechtenstein)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanliechtenstein_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanliechtenstein_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanluxembourg","displayName":"German (Luxembourg) (User)","description":"Enables the editing language German (Luxembourg)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanluxembourg_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanluxembourg_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanswitzerland","displayName":"German (Switzerland) (User)","description":"Enables the editing language German (Switzerland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanswitzerland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanswitzerland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greek","displayName":"Greek (User)","description":"Enables the editing language Greek","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greek_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greek_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greenlandic","displayName":"Greenlandic (User)","description":"Enables the editing language Greenlandic","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greenlandic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greenlandic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_guarani","displayName":"Guarani (User)","description":"Enables the editing language Guarani","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_guarani_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_guarani_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_gujarati","displayName":"Gujarati (User)","description":"Enables the editing language Gujarati","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_gujarati_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_gujarati_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hausa","displayName":"Hausa (Latin) (User)","description":"Enables the editing language Hausa (Latin)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hausa_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hausa_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hawaiian","displayName":"Hawaiian (User)","description":"Enables the editing language Hawaiian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hawaiian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hawaiian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hebrewisrael","displayName":"Hebrew (Israel) (User)","description":"Enables the editing language Hebrew (Israel)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hebrewisrael_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hebrewisrael_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hindi","displayName":"Hindi (User)","description":"Enables the editing language Hindi","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hindi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hindi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hungarian","displayName":"Hungarian (User)","description":"Enables the editing language Hungarian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hungarian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hungarian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_ibibio","displayName":"Ibibio (User)","description":"Enables the editing language Ibibio","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_ibibio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_ibibio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_icelandic","displayName":"Icelandic (User)","description":"Enables the editing language Icelandic","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_icelandic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_icelandic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_igbo","displayName":"Igbo (User)","description":"Enables the editing language Igbo","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_igbo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_igbo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_indonesian","displayName":"Indonesian (User)","description":"Enables the editing language Indonesian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_indonesian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_indonesian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutlatin","displayName":"Inuktitut (Latin) (User)","description":"Enables the editing language Inuktitut (Latin)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutlatin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutlatin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutsyllabics","displayName":"Inuktitut (Syllabics) (User)","description":"Enables the editing language Inuktitut (Syllabics)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutsyllabics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutsyllabics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_irishireland","displayName":"Irish (Ireland) (User)","description":"Enables the editing language Irish (Ireland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_irishireland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_irishireland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isixhosa","displayName":"isiXhosa (User)","description":"Enables the editing language isiXhosa","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isixhosa_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isixhosa_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isizulu","displayName":"isiZulu (User)","description":"Enables the editing language isiZulu","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isizulu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isizulu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianitaly","displayName":"Italian (Italy) (User)","description":"Enables the editing language Italian (Italy)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianitaly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianitaly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianswitzerland","displayName":"Italian (Switzerland) (User)","description":"Enables the editing language Italian (Switzerland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianswitzerland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianswitzerland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_japanese","displayName":"Japanese (User)","description":"Enables the editing language Japanese","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_japanese_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_japanese_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kannada","displayName":"Kannada (User)","description":"Enables the editing language Kannada","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kannada_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kannada_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kanuri","displayName":"Kanuri (User)","description":"Enables the editing language Kanuri","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kanuri_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kanuri_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiriarabic","displayName":"Kashmiri (Arabic) (User)","description":"Enables the editing language Kashmiri (Arabic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiriarabic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiriarabic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiridevanagari","displayName":"Kashmiri (Devanagari) (User)","description":"Enables the editing language Kashmiri (Devanagari)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiridevanagari_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiridevanagari_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kazakh","displayName":"Kazakh (User)","description":"Enables the editing language Kazakh","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kazakh_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kazakh_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_khmer","displayName":"Khmer (User)","description":"Enables the editing language Khmer","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_khmer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_khmer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kiche","displayName":"K'iche (User)","description":"Enables the editing language K'iche","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kiche_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kiche_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kinyarwanda","displayName":"Kinyarwanda (User)","description":"Enables the editing language Kinyarwanda","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kinyarwanda_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kinyarwanda_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_konkani","displayName":"Konkani (User)","description":"Enables the editing language Konkani","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_konkani_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_konkani_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_korean","displayName":"Korean (User)","description":"Enables the editing language Korean","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_korean_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_korean_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kyrgyz","displayName":"Kyrgyz (User)","description":"Enables the editing language Kyrgyz","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kyrgyz_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kyrgyz_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lao","displayName":"Lao (User)","description":"Enables the editing language Lao","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lao_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lao_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latin","displayName":"Latin (User)","description":"Enables the editing language Latin","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latvian","displayName":"Latvian (User)","description":"Enables the editing language Latvian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latvian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latvian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lithuanian","displayName":"Lithuanian (User)","description":"Enables the editing language Lithuanian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lithuanian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lithuanian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lowersorbian","displayName":"Lower Sorbian (User)","description":"Enables the editing language Lower Sorbian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lowersorbian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lowersorbian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_luxembourgishluxembourg","displayName":"Luxembourgish (Luxembourg) (User)","description":"Enables the editing language Luxembourgish (Luxembourg)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_luxembourgishluxembourg_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_luxembourgishluxembourg_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_macedonian","displayName":"Macedonian (User)","description":"Enables the editing language Macedonian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_macedonian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_macedonian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malayalam","displayName":"Malayalam (User)","description":"Enables the editing language Malayalam","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malayalam_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malayalam_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malaybrunei","displayName":"Malay (Brunei) (User)","description":"Enables the editing language Malay (Brunei)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malaybrunei_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malaybrunei_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malaymalaysia","displayName":"Malay (Malaysia) (User)","description":"Enables the editing language Malay (Malaysia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malaymalaysia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malaymalaysia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_maltese","displayName":"Maltese (User)","description":"Enables the editing language Maltese","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_maltese_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_maltese_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_manipuri","displayName":"Manipuri (User)","description":"Enables the editing language Manipuri","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_manipuri_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_manipuri_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_maori","displayName":"Maori (User)","description":"Enables the editing language Maori","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_maori_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_maori_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mapudungun","displayName":"Mapudungun (User)","description":"Enables the editing language Mapudungun","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mapudungun_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mapudungun_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_marathi","displayName":"Marathi (User)","description":"Enables the editing language Marathi","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_marathi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_marathi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mohawk","displayName":"Mohawk (User)","description":"Enables the editing language Mohawk","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mohawk_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mohawk_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliancyrillic","displayName":"Mongolian (Cyrillic) (User)","description":"Enables the editing language Mongolian (Cyrillic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliancyrillic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliancyrillic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliantraditionalmongolian","displayName":"Mongolian (Traditional Mongolian) (User)","description":"Enables the editing language Mongolian (Traditional Mongolian)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliantraditionalmongolian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliantraditionalmongolian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepaliindia","displayName":"Nepali (India) (User)","description":"Enables the editing language Nepali (India)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepaliindia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepaliindia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepalinepal","displayName":"Nepali (Nepal) (User)","description":"Enables the editing language Nepali (Nepal)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepalinepal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepalinepal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_norwegianbokml","displayName":"Norwegian (Bokmål) (User)","description":"Enables the editing language Norwegian (Bokm†l)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_norwegianbokml_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_norwegianbokml_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_norwegiannynorsk","displayName":"Norwegian (Nynorsk) (User)","description":"Enables the editing language Norwegian (Nynorsk)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_norwegiannynorsk_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_norwegiannynorsk_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_occitan","displayName":"Occitan (User)","description":"Enables the editing language Occitan","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_occitan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_occitan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_odia","displayName":"Odia (User)","description":"Enables the editing language Odia","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_odia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_odia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_oromo","displayName":"Oromo (User)","description":"Enables the editing language Oromo","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_oromo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_oromo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_papiamentu","displayName":"Papiamentu (User)","description":"Enables the editing language Papiamentu","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_papiamentu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_papiamentu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_pashto","displayName":"Pashto (User)","description":"Enables the editing language Pashto","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_pashto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_pashto_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_persian","displayName":"Persian (User)","description":"Enables the editing language Persian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_persian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_persian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_polish","displayName":"Polish (User)","description":"Enables the editing language Polish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_polish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_polish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portuguesebrazil","displayName":"Portuguese (Brazil) (User)","description":"Enables the editing language Portuguese (Brazil)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portuguesebrazil_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portuguesebrazil_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portugueseportugal","displayName":"Portuguese (Portugal) (User)","description":"Enables the editing language Portuguese (Portugal)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portugueseportugal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portugueseportugal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabi","displayName":"Punjabi (User)","description":"Enables the editing language Punjabi","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabipakistan","displayName":"Punjabi (Pakistan) (User)","description":"Enables the editing language Punjabi (Pakistan)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabipakistan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabipakistan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuabolivia","displayName":"Quechua (Bolivia) (User)","description":"Enables the editing language Quechua (Bolivia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuabolivia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuabolivia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaecuador","displayName":"Quechua (Ecuador) (User)","description":"Enables the editing language Quechua (Ecuador)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaecuador_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaecuador_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaperu","displayName":"Quechua (Peru) (User)","description":"Enables the editing language Quechua (Peru)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaperu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaperu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanianmoldova","displayName":"Romanian (Moldova) (User)","description":"Enables the editing language Romanian (Moldova)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanianmoldova_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanianmoldova_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanianromania","displayName":"Romanian (Romania) (User)","description":"Enables the editing language Romanian (Romania)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanianromania_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanianromania_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanshswitzerland","displayName":"Romansh (Switzerland) (User)","description":"Enables the editing language Romansh (Switzerland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanshswitzerland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanshswitzerland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_russianmoldova","displayName":"Russian (Moldova) (User)","description":"Enables the editing language Russian (Moldova)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_russianmoldova_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_russianmoldova_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_russianrussia","displayName":"Russian (Russia) (User)","description":"Enables the editing language Russian (Russia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_russianrussia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_russianrussia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sakha","displayName":"Sakha (User)","description":"Enables the editing language Sakha","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sakha_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sakha_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiinarifinland","displayName":"Sami, Inari (Finland) (User)","description":"Enables the editing language \"Sami, Inari (Finland)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiinarifinland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiinarifinland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samilulenorway","displayName":"Sami, Lule (Norway) (User)","description":"Enables the editing language \"Sami, Lule (Norway)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samilulenorway_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samilulenorway_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samilulesweden","displayName":"Sami, Lule (Sweden) (User)","description":"Enables the editing language \"Sami, Lule (Sweden)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samilulesweden_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samilulesweden_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernfinland","displayName":"Sami, Northern (Finland) (User)","description":"Enables the editing language \"Sami, Northern (Finland)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernfinland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernfinland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernnorway","displayName":"Sami, Northern (Norway) (User)","description":"Enables the editing language \"Sami, Northern (Norway)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernnorway_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernnorway_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernsweden","displayName":"Sami, Northern (Sweden) (User)","description":"Enables the editing language \"Sami, Northern (Sweden)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernsweden_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernsweden_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiskoltfinland","displayName":"Sami, Skolt (Finland) (User)","description":"Enables the editing language \"Sami, Skolt (Finland)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiskoltfinland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiskoltfinland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samisouthernnorway","displayName":"Sami, Southern (Norway) (User)","description":"Enables the editing language \"Sami, Southern (Norway)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samisouthernnorway_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samisouthernnorway_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samisouthernsweden","displayName":"Sami, Southern (Sweden) (User)","description":"Enables the editing language \"Sami, Southern (Sweden)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samisouthernsweden_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samisouthernsweden_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sanskrit","displayName":"Sanskrit (User)","description":"Enables the editing language Sanskrit","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sanskrit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sanskrit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_scottishgaelicunitedkingdom","displayName":"Scottish Gaelic (United Kingdom) (User)","description":"Enables the editing language Scottish Gaelic (United Kingdom)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_scottishgaelicunitedkingdom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_scottishgaelicunitedkingdom_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicbosniaandherzegovina","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina) (User)","description":"Enables the editing language \"Serbian (Cyrillic, Bosnia and Herzegovina)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicmontenegro","displayName":"Serbian (Cyrillic, Montenegro) (User)","description":"Enables the editing language \"Serbian (Cyrillic, Montenegro)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicmontenegro_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicmontenegro_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicserbia","displayName":"Serbian (Cyrillic, Serbia) (User)","description":"Enables the editing language \"Serbian (Cyrillic, Serbia)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicserbia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicserbia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicserbiaandmontenegro","displayName":"Serbian (Cyrillic, Serbia and Montenegro (Former)) (User)","description":"Enables the editing language \"Serbian (Cyrillic, Serbia and Montenegro (Former))\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicserbiaandmontenegro_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicserbiaandmontenegro_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinbosniaandherzegovina","displayName":"Serbian (Latin, Bosnia and Herzegovina) (User)","description":"Enables the editing language \"Serbian (Latin, Bosnia and Herzegovina)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinmontenegro","displayName":"Serbian (Latin, Montenegro) (User)","description":"Enables the editing language \"Serbian (Latin, Montenegro)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinmontenegro_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinmontenegro_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinserbia","displayName":"Serbian (Latin, Serbia) (User)","description":"Enables the editing language \"Serbian (Latin, Serbia)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinserbia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinserbia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinserbiaandmontenegro","displayName":"Serbian (Latin, Serbia and Montenegro (Former)) (User)","description":"Enables the editing language \"Serbian (Latin, Serbia and Montenegro (Former))\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinserbiaandmontenegro_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinserbiaandmontenegro_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sesotho","displayName":"Sesotho (User)","description":"Enables the editing language Sesotho","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sesotho_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sesotho_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sesothosaleboa","displayName":"Sesotho sa Leboa (User)","description":"Enables the editing language Sesotho sa Leboa","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sesothosaleboa_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sesothosaleboa_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_setswana","displayName":"Setswana (User)","description":"Enables the editing language Setswana","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_setswana_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_setswana_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhiarabic","displayName":"Sindhi (Arabic) (User)","description":"Enables the editing language Sindhi (Arabic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhiarabic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhiarabic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhidevanagari","displayName":"Sindhi (Devanagari) (User)","description":"Enables the editing language Sindhi (Devanagari)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhidevanagari_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhidevanagari_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sinhala","displayName":"Sinhala (User)","description":"Enables the editing language Sinhala","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sinhala_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sinhala_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_slovak","displayName":"Slovak (User)","description":"Enables the editing language Slovak","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_slovak_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_slovak_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_slovenian","displayName":"Slovenian (User)","description":"Enables the editing language Slovenian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_slovenian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_slovenian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_somali","displayName":"Somali (User)","description":"Enables the editing language Somali","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_somali_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_somali_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishargentina","displayName":"Spanish (Argentina) (User)","description":"Enables the editing language Spanish (Argentina)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishargentina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishargentina_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishbolivia","displayName":"Spanish (Bolivia) (User)","description":"Enables the editing language Spanish (Bolivia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishbolivia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishbolivia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishchile","displayName":"Spanish (Chile) (User)","description":"Enables the editing language Spanish (Chile)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishchile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishchile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishcolombia","displayName":"Spanish (Colombia) (User)","description":"Enables the editing language Spanish (Colombia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishcolombia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishcolombia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishcostarica","displayName":"Spanish (Costa Rica) (User)","description":"Enables the editing language Spanish (Costa Rica)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishcostarica_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishcostarica_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishdominicanrepublic","displayName":"Spanish (Dominican Republic) (User)","description":"Enables the editing language Spanish (Dominican Republic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishdominicanrepublic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishdominicanrepublic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishecuador","displayName":"Spanish (Ecuador) (User)","description":"Enables the editing language Spanish (Ecuador)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishecuador_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishecuador_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishelsalvador","displayName":"Spanish (El Salvador) (User)","description":"Enables the editing language Spanish (El Salvador)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishelsalvador_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishelsalvador_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishguatemala","displayName":"Spanish (Guatemala) (User)","description":"Enables the editing language Spanish (Guatemala)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishguatemala_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishguatemala_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishhonduras","displayName":"Spanish (Honduras) (User)","description":"Enables the editing language Spanish (Honduras)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishhonduras_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishhonduras_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishmexico","displayName":"Spanish (Mexico) (User)","description":"Enables the editing language Spanish (Mexico)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishmexico_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishmexico_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishnicaragua","displayName":"Spanish (Nicaragua) (User)","description":"Enables the editing language Spanish (Nicaragua)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishnicaragua_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishnicaragua_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpanama","displayName":"Spanish (Panama) (User)","description":"Enables the editing language Spanish (Panama)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpanama_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpanama_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishparaguay","displayName":"Spanish (Paraguay) (User)","description":"Enables the editing language Spanish (Paraguay)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishparaguay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishparaguay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishperu","displayName":"Spanish (Peru) (User)","description":"Enables the editing language Spanish (Peru)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishperu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishperu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpuertorico","displayName":"Spanish (Puerto Rico) (User)","description":"Enables the editing language Spanish (Puerto Rico)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpuertorico_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpuertorico_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishspain","displayName":"Spanish (Spain) (User)","description":"Enables the editing language Spanish (Spain)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishspain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishspain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishunitedstates","displayName":"Spanish (United States) (User)","description":"Enables the editing language Spanish (United States)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishunitedstates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishunitedstates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishuruguay","displayName":"Spanish (Uruguay) (User)","description":"Enables the editing language Spanish (Uruguay)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishuruguay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishuruguay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishvenezuela","displayName":"Spanish (Venezuela) (User)","description":"Enables the editing language Spanish (Venezuela)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishvenezuela_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishvenezuela_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swahili","displayName":"Swahili (User)","description":"Enables the editing language Swahili","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swahili_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swahili_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swedishfinland","displayName":"Swedish (Finland) (User)","description":"Enables the editing language Swedish (Finland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swedishfinland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swedishfinland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swedishsweden","displayName":"Swedish (Sweden) (User)","description":"Enables the editing language Swedish (Sweden)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swedishsweden_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swedishsweden_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_syriac","displayName":"Syriac (User)","description":"Enables the editing language Syriac","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_syriac_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_syriac_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tajik","displayName":"Tajik (User)","description":"Enables the editing language Tajik","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tajik_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tajik_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightarabicmorocco","displayName":"Tamazight (Arabic, Morocco) (User)","description":"Enables the editing language \"Tamazight (Arabic, Morocco)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightarabicmorocco_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightarabicmorocco_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightlatinalgeria","displayName":"Tamazight (Latin, Algeria) (User)","description":"Enables the editing language \"Tamazight (Latin, Algeria)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightlatinalgeria_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightlatinalgeria_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamil","displayName":"Tamil (User)","description":"Enables the editing language Tamil","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamil_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamil_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tatar","displayName":"Tatar (User)","description":"Enables the editing language Tatar","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tatar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tatar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_telugu","displayName":"Telugu (User)","description":"Enables the editing language Telugu","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_telugu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_telugu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_thai","displayName":"Thai (User)","description":"Enables the editing language Thai","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_thai_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_thai_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tibetanprc","displayName":"Tibetan (PRC) (User)","description":"Enables the editing language Tibetan (PRC)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tibetanprc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tibetanprc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaeritrea","displayName":"Tigrinya (Eritrea) (User)","description":"Enables the editing language Tigrinya (Eritrea)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaeritrea_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaeritrea_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaethiopia","displayName":"Tigrinya (Ethiopia) (User)","description":"Enables the editing language Tigrinya (Ethiopia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaethiopia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaethiopia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkish","displayName":"Turkish (User)","description":"Enables the editing language Turkish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkmen","displayName":"Turkmen (User)","description":"Enables the editing language Turkmen","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkmen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkmen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_ukrainian","displayName":"Ukrainian (User)","description":"Enables the editing language Ukrainian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_ukrainian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_ukrainian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uppersorbian","displayName":"Upper Sorbian (User)","description":"Enables the editing language Upper Sorbian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uppersorbian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uppersorbian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_urdu","displayName":"Urdu (User)","description":"Enables the editing language Urdu","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_urdu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_urdu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uyghurprc","displayName":"Uyghur (PRC) (User)","description":"Enables the editing language Uyghur (PRC)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uyghurprc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uyghurprc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbekcyrillic","displayName":"Uzbek (Cyrillic) (User)","description":"Enables the editing language Uzbek (Cyrillic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbekcyrillic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbekcyrillic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbeklatin","displayName":"Uzbek (Latin) (User)","description":"Enables the editing language Uzbek (Latin)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbeklatin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbeklatin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_valencian","displayName":"Valencian (User)","description":"Enables the editing language Valencian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_valencian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_valencian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_venda","displayName":"Venda (User)","description":"Enables the editing language Venda","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_venda_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_venda_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_vietnamese","displayName":"Vietnamese (User)","description":"Enables the editing language Vietnamese","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_vietnamese_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_vietnamese_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_welsh","displayName":"Welsh (User)","description":"Enables the editing language Welsh","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_welsh_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_welsh_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_wolof","displayName":"Wolof (User)","description":"Enables the editing language Wolof","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_wolof_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_wolof_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_xitsonga","displayName":"Xitsonga (User)","description":"Enables the editing language Xitsonga","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_xitsonga_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_xitsonga_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yiddish","displayName":"Yiddish (User)","description":"Enables the editing language Yiddish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yiddish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yiddish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yiprc","displayName":"Yi (PRC) (User)","description":"Enables the editing language Yi (PRC)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yiprc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yiprc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yoruba","displayName":"Yoruba (User)","description":"Enables the editing language Yoruba","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yoruba_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yoruba_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_other_l_disablecomingsoon","displayName":"Turn off Coming Soon (User)","description":"\r\n This policy setting controls whether Coming Soon is available to users. Coming Soon provides information in an Office app, such as Word or Excel, about upcoming feature changes to that app and lets users try out those changes ahead of time. By default, Coming Soon is available to users.\r\n\r\n If you enable this policy setting, Coming Soon is turned off and isn't available to users.\r\n\r\n If you disable or don't configure this policy setting, Coming Soon is available to users.\r\n ","helpText":"","infoUrls":[],"categoryId":"e0dfe97e-348d-4d30-a6a1-e0de1989236e","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_other_l_disablecomingsoon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_other_l_disablecomingsoon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion","displayName":"Active Directory timeout for querying one entry for group expansion (User)","description":"Specifies the timeout value for querying one Active Directory entry for group expansion.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion_l_entertimeoutinseconds","displayName":"Enter timeout in seconds: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl","displayName":"Additional permissions request URL (User)","description":"Specifies a location where a user can obtain more information about getting access to IRM content.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_l_checktospecifyacustomurloremailaddress","displayName":"Check to specify a custom URL or e-mail address (User)","description":"","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_l_checktospecifyacustomurloremailaddress_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_l_checktospecifyacustomurloremailaddress_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_l_specifyurlemailaddress","displayName":"Specify URL/Email address: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_allowuserswithearlierversionsofofficetoreadwithbrowsers","displayName":"Allow users with earlier versions of Office to read with browsers... (User)","description":"This policy setting will allow users with earlier versions of Office to read documents with browsers supporting Information Rights Management.\r\n\r\nIf you enable this policy setting, users with earlier versions of Office can read documents with browsers supporting Information Rights Management. Note that this will make all documents with restricted permissions larger.\r\n\r\nIf you disable or do not configure this policy setting, users with earlier versions of Office cannot read documents with browsers supporting Information Rights Management.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_allowuserswithearlierversionsofofficetoreadwithbrowsers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_allowuserswithearlierversionsofofficetoreadwithbrowsers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_alwaysexpandgroupsinofficewhenrestrictingpermissionfordocume","displayName":"Always expand groups in Office when restricting permission for documents (User)","description":"This policy setting controls whether group names automatically expand to display all the members of the group when selected in the Permissions dialog box. \r\n\r\nIf you enable this policy setting, when users select a group name while applying Information Rights Management (IRM) permissions to Excel workbooks, InfoPath templates, Outlook e-mail messages, PowerPoint presentations, or Word documents in the Permissions dialog box, it will automatically expand to display all the members of the group. \r\n\r\nIf you disable or do not configure this policy setting, when users select a group name in the Permissions dialog box, the members of the group are not displayed.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_alwaysexpandgroupsinofficewhenrestrictingpermissionfordocume_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_alwaysexpandgroupsinofficewhenrestrictingpermissionfordocume_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_alwaysrequireuserstoconnecttoverifypermission","displayName":"Always require users to connect to verify permission (User)","description":"This policy setting controls whether users are required to connect to the Internet or a local network to have their licenses confirmed every time they attempt to open Excel workbooks, InfoPath forms or templates, Outlook e-mail messages, PowerPoint presentations, or Word documents that are protected by Information Rights Management (IRM). This policy is useful if you want to log the usage of files with restricted permissions on the server.\r\n\r\nIf you enable this policy setting, users are required to connect to verify permissions. This policy setting will only affect protected files created on machines where the policy is enabled.\r\n\r\nIf you disable or do not configure this policy setting, users are not required to connect to the network to verify permissions.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_alwaysrequireuserstoconnecttoverifypermission_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_alwaysrequireuserstoconnecttoverifypermission_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_disableinformationrightsmanagementuserinterface","displayName":"Turn off Information Rights Management user interface (User)","description":"This policy setting controls Information Rights Management (IRM).\r\n\r\nIf you enable this policy setting, IRM will be turned off for users.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to use IRM.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_disableinformationrightsmanagementuserinterface_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_disableinformationrightsmanagementuserinterface_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_neverallowuserstospecifygroupswhenrestrictingpermissionfordo","displayName":"Never allow users to specify groups when restricting permission for documents (User)","description":"This policy setting controls whether Office 2016 users can assign permissions to distribution lists when using Information Rights Management. \r\n\r\nIf you enable this policy setting, Office 2016 users cannot specify a distribution list as an authorized party in the Permission dialog box. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 users can specify distribution lists when using Information Rights Management (IRM) to restrict access to Excel workbooks, InfoPath templates, Outlook e-mail messages, PowerPoint presentations, or Word documents.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_neverallowuserstospecifygroupswhenrestrictingpermissionfordo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_neverallowuserstospecifygroupswhenrestrictingpermissionfordo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_preventusersfromchangingpermissions","displayName":"Prevent users from changing permissions on rights managed content (User)","description":"This policy setting controls whether Office 2016 users can change permissions for content that is protected with Information Rights Management (IRM). \r\n\r\nThe Information Rights Management feature of Office 2016 allows individuals and administrators to specify access permissions to Word documents, Excel workbooks, PowerPoint presentations, InfoPath templates and forms, and Outlook e-mail messages. This functionality helps prevent sensitive information from being printed, forwarded, or copied by unauthorized people. \r\n\r\nIf you enable this policy setting, users can open and edit documents for which they have the appropriate permissions, but they cannot create new rights-managed content, add IRM to existing documents, change existing IRM permissions, or remove IRM from documents. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 users can add, remove, or change IRM permissions for documents if they are authorized to do so.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_preventusersfromchangingpermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_preventusersfromchangingpermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_specifydefaultpermissionserver","displayName":"Specify Permission Policy Default Server for Quick Access Toolbar (User)","description":"This policy setting specifies the RMS server Office uses by default.\r\n\r\nIf you enable this policy setting, Office uses the server you specify as the default RMS server.\r\n\r\nIf you disable or do not configure this policy setting, Office chooses the default RMS server.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_specifydefaultpermissionserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_specifydefaultpermissionserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_specifydefaultpermissionserver_l_empty407","displayName":"\r\nEnter Permission Policy Default Server for Quick Access Toolbar\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_urlforlocationofdocumenttemplatespolicy","displayName":"URL for location of document templates displayed when applications do not recognize rights-managed documents (User)","description":"Provide the path to a folder with document, spreadsheet, and presentation files to be used as templates for a unencrypted wrapper for files with rights-managed content received by users with older versions of Office. Office includes plain-text wrapper documents that notify users about a rights-managed document in certain circumstances. If the user's application cannot recognize a document that includes rights-management, the user receives the wrapper document with information such as instructions for downloading a Rights Management Add-on for Windows Internet Explorer. You can provide a folder with customized templates for Office to use for these plain-text wrappers by using this setting to specify a URL to a folder.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_urlforlocationofdocumenttemplatespolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_urlforlocationofdocumenttemplatespolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_urlforlocationofdocumenttemplatespolicy_l_enteraurl","displayName":"Enter a URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_checkouttolocaldisk","displayName":"Check-out to local disk (User)","description":"This policy turns on the check-out to local disk feature.\r\n\r\nIf you enable this policy setting, documents that are checked-out will be stored in the Local Drafts folder on the local disk.\r\n\r\nIf you disable or do not configure this policy setting, documents that are checked out will be checked-out on SharePoint and no local copy will be created.","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_checkouttolocaldisk_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_checkouttolocaldisk_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_deletefilesfromofficedocumentcache","displayName":"Delete files from Office Document Cache (User)","description":"This policy setting determines whether or not documents opened in Office are deleted from the Office Document Cache when they are closed.\r\n\r\nIf you enable this policy setting documents are deleted from the Office Document Cache when they are closed. \r\n\r\nIf you disable or do not configure this policy setting, documents are not deleted from the Office Document Cache when they are closed.\r\n\r\nNote: This policy setting does not apply to documents in SharePoint Workspace. Documents in SharePoint Workspace will not be deleted from the Office Document cache when they are closed. Sharepoint Workspace will not work correctly if this Group Policy is enabled.","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_deletefilesfromofficedocumentcache_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_deletefilesfromofficedocumentcache_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_enablecheckouttodrafts","displayName":"Save checked-out files to a local folder (User)","description":"This policy setting allows users to save files checked out from SharePoint, or other document management server products, to a local folder when editing the files. \r\n\r\nBy default, checked-out files are stored in the Office Document Cache. The Office Document Cache allows the same offline editing capabilities as a local folder, but automatically syncs the files when there is Internet connectivity.\r\n\r\nNote: It’s not recommended to enable this policy setting unless needed to support existing document management processes.\r\n\r\nIf you enable this policy setting, users can specify a local folder to save checked-out files to by going to File > Options > Save > Offline editing options.\r\n\r\nIf you disable or don’t configure this policy setting, checked-out files are stored in the Office Document Cache.\r\n ","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_enablecheckouttodrafts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_enablecheckouttodrafts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_officedocumentcachelocation","displayName":"Office document cache location (User)","description":"This policy setting determines the location where Office maintains the Office Document Cache.\r\n\r\nIf you enable this policy setting, you can specify the location where Office maintains the Office Document Cache.\r\n\r\nIf you disable or do not configure this policy setting, the Office Document Cache will be stored in the following location: %LocalAppData%\\Microsoft\\Office\\16.0\\OfficeFileCache","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_officedocumentcachelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_officedocumentcachelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_officedocumentcachelocation_l_officedocumentcachelocationid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_opendocumentsfromofficedocumentcachefirst","displayName":"Open documents from Office Document Cache first (User)","description":"This policy setting allows the client application to open a document directly from the Office Document Cache if it is aware that the server the document resides on is not reachable. It may be useful in situations where you would like to wait to contact the server every time, time out and then fallback to the cache. \r\n\r\nIf you enable or do not configure this policy setting, documents will be opened directly from the Office Document Cache when the server the document resides on is not reachable. \r\n\r\nIf you disable this policy setting, Office will always attempt to first reach the server the document resides on before opening it from the Office Document Cache.","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_opendocumentsfromofficedocumentcachefirst_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_opendocumentsfromofficedocumentcachefirst_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_allowlinkedinfeatures","displayName":"Show LinkedIn features in Office applications (User)","description":"This policy setting will prevent LinkedIn features from appearing in the Office applications.\r\n\r\nIf you enable or do not configure this policy, users will be able to leverage LinkedIn data and resources from a variety of locations within the Office applications.\r\n\r\nIf you disable this policy setting, LinkedIn features will not be available.\r\n\r\nImportant: This policy setting only applies to Office 365 clients that are installed by using Click-to-Run, including Office 365 ProPlus, Office 365 Business, Visio Pro for Office 365 and Project Pro for Office 365. It doesn't apply to Office products that use Windows Installer (MSI).\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_allowlinkedinfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_allowlinkedinfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_alwaysshowfilesharemoreoptions","displayName":"Show additional sharing choices under the File tab (User)","description":"This policy settings controls what is displayed when the user goes to File > Share in Word, Excel, or PowerPoint.\r\n\r\nBy default, choosing File > Share takes the user to the Share dialog, which provides various choices for sharing. These choices used to appear under File > Share, but no longer appear there by default. There are some additional choices that used to appear under File > Share, but don’t appear in the Share dialog.\r\n\r\nIf you enable this policy setting, the user isn’t taken to the Share dialog and the user sees all the sharing choices under File > Share. For example, several options to share by email or an option to share by instant message.\r\n\r\nIf you disable or don’t configure this policy setting, choosing File > Share takes the user to the Share dialog, which doesn’t have all the sharing choices.\r\n\r\nNote: The user can also add buttons for these additional sharing choices to the ribbon or to the quick access toolbar, regardless of how this policy setting is configured.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_alwaysshowfilesharemoreoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_alwaysshowfilesharemoreoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changedestinationurlforsharepointhyperlink","displayName":"Change destination URL for SharePoint hyperlink (User)","description":"This policy setting changes the destination URL of the Learn more about SharePoint hyperlink located on the Save to SharePoint form in the Backstage view for Word, PowerPoint, Excel, Visio, and Project.\r\n\r\nIf you enable this policy setting, the hyperlink destination you provide will be used.\r\n\r\nIf you disable or do not configure this policy setting, then the default destination URL to Learn more about SharePoint will be used.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changedestinationurlforsharepointhyperlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changedestinationurlforsharepointhyperlink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changedestinationurlforsharepointhyperlink_l_changedestinationurlforsharepointhyperlinkid","displayName":"Destination URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changelabelofsavetosharepoint","displayName":"SharePoint Product Name (User)","description":"This policy setting allows you to customize the label that is used for your company's SharePoint deployment. This will update the label that is used in the Open and Save As places in all Office applications.\r\n\r\nYou can use this option to make it more clear to users where they should be saving company documents.\r\n\r\nIf you enable this policy setting, the new string you provide will be used to refer to your company's SharePoint deployment. We recommend setting this to the name of your company.\r\n\r\nIf you disable or do not configure this policy setting then the default string, \"SharePoint,\" will be displayed in the Open and Save As UI in all Office applications.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changelabelofsavetosharepoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changelabelofsavetosharepoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changelabelofsavetosharepoint_l_changelabelofsavetosharepointid","displayName":"Custom string to be displayed: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging","displayName":"Control Blogging (User)","description":"This policy setting controls whether users can compose and post blog entries from Word.\r\n\r\nIf you enable this policy setting, you can choose from three options for controlling blogging: \r\n\r\n* Enabled - Users may compose and post blog entries from Word to any available blog provider. This is the default configuration in Word. \r\n\r\n* Only SharePoint blogs allowed - Users can only post blog entries to SharePoint sites. \r\n\r\n* Disabled - The blogging feature in Word is disabled entirely. \r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled-Enabled.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging_l_empty503","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging_l_empty503_0","displayName":"Enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging_l_empty503_1","displayName":"Only SharePoint blogs allowed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging_l_empty503_2","displayName":"All blogging disabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableanimations","displayName":"Disable Office animations (User)","description":"This setting will disable all unnecessary Office animations. By default, animation effects, such as fading between views, are enabled.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableanimations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableanimations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablebackgrounds","displayName":"Disable Office Backgrounds (User)","description":"This policy setting turns on and off the ability of users to select an Office background.\r\n\r\nIf you enable this policy setting, users won’t see the Office Backgrounds setting in either the Account place or the Options dialog. They also won’t have an Office Background applied to the upper right of their Office applications.\r\n\r\nIf you disable or don’t configure this policy setting, users will see the Office Backgrounds setting in the Account place and in the Options dialog, and they will have an Office Background applied to the upper right of their Office applications.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablebackgrounds_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablebackgrounds_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableclipboardtoolbartriggers","displayName":"Disable Clipboard Toolbar triggers (User)","description":"Checked: Prevents the Office Clipboard from automatically appearing when multiple Copy commands are performed in any of the Office programs. | Unchecked: Permits the Office Clipboard to appear automatically when multiple Copy commands are performed in Office programs.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableclipboardtoolbartriggers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableclipboardtoolbartriggers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelinksopenright","displayName":"Open Office file links in Office Online (User)","description":"\r\n This policy setting controls which version of Office opens when a hyperlink to an Office file stored on OneDrive, OneDrive for Business, or a SharePoint Online team site is selected.\r\n\r\n By default, a hyperlink to a file stored in one of these locations opens the file in the Office client version of Word, Excel, or PowerPoint. This is the version of Office that is installed on the user’s computer. If Office isn’t installed on the user’s computer, the file is opened in the Office Online version of the program in the user’s web browser.\r\n\r\n If you enable this policy setting, a hyperlink to an Office file stored in one of these locations opens the file in the Office Online version of Word, Excel, or PowerPoint. This opens the file in the user’s web browser.\r\n\r\n If you disable or don’t configure this policy setting, a hyperlink to an Office file stored in one of these locations opens the file in the Office client version of Word, Excel, or PowerPoint, if Office is installed on the user’s computer.\r\n\r\n Note: This policy setting only applies to subscription versions of the Office client, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelinksopenright_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelinksopenright_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableofficestartglobal","displayName":"Disable the Office Start screen for all Office applications (User)","description":"This policy setting controls whether the Office Start screen appears on boot for all Office applications.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot any Office application.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot their Office applications.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableofficestartglobal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableofficestartglobal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablescreenshotautohyperlink","displayName":"Do not automatically hyperlink screenshots (User)","description":"This policy setting allows you to specify whether or not Word, PowerPoint, Excel or Outlook automatically binds hyperlink to a screenshot inserted through the Insert Screenshot tool, if the screenshot is of an Internet Explorer browser window.\r\n\r\nIf you enable this policy setting, Word, PowerPoint, Excel and Outlook does not automatically bind hyperlinks to screenshot of Internet Explorer browser windows.\r\n\r\nIf you disable or do not configure this policy setting, Word, PowerPoint, Excel and Outlook automatically binds a hyperlink to screenshots of Internet Explorer browser windows.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablescreenshotautohyperlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablescreenshotautohyperlink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablewebviewintheofficefiledialogs","displayName":"Disable web view in the Office file dialog boxes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablewebviewintheofficefiledialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablewebviewintheofficefiledialogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disalowconvertdocumentpolicy","displayName":"Disallow Convert Document (Excel, PowerPoint, Word) (User)","description":"Disallow users to convert files that are in compatibility mode via the \"Convert\" command for Excel, PowerPoint, and Word.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disalowconvertdocumentpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disalowconvertdocumentpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotdisplaypathsinalerts","displayName":"Do not display paths in alerts (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotdisplaypathsinalerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotdisplaypathsinalerts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotemulatetabswithspaceswhenexportinghtml","displayName":"Emulate tabs with spaces when exporting HTML (User)","description":"Enabled: Tabs are emulated by replacing them with spaces when exporting HTML. | Disabled: Tab characters are not replaced with spaces when exporting HTML format.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotemulatetabswithspaceswhenexportinghtml_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotemulatetabswithspaceswhenexportinghtml_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donottrackdocumenteditingtime","displayName":"Do not track document editing time (User)","description":"Checked: Do not calculate the total editing time while a document is open. | Unchecked: Track the editing time while a document is open.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donottrackdocumenteditingtime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donottrackdocumenteditingtime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotuploadmediafiles","displayName":"Do not upload media files (User)","description":"Disables/Enables uploading of media files.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotuploadmediafiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotuploadmediafiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotusehardwareacceleration","displayName":"Do not use hardware graphics acceleration (User)","description":"This policy setting allows you to not use hardware graphics acceleration.\r\n\r\nIf you enable this policy setting, hardware graphics acceleration will not be used.\r\n\r\nIf you disable or do not configure this policy setting hardware graphics acceleration may be used.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotusehardwareacceleration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotusehardwareacceleration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotvalidateprintersbeforeusingthem","displayName":"Do not validate printers before using them (User)","description":"This policy setting allows you to determine whether Word, PowerPoint, or Excel validates its connection with a printer before attempting to use it in the Print tab in Backstage View.\r\n\r\nIf you enable this policy setting, Word, PowerPoint, and Excel do not validate printers before using them. If invalid data is returned from the printer, then Word, PowerPoint, and Excel still attempt to use the data, which can result in the application failing.\r\n\r\nIf you disable or do not configure this policy setting, Word, PowerPoint, and Excel validate printers before using them in the Print tab in Backstage View. If validation fails, the printer is disabled.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotvalidateprintersbeforeusingthem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotvalidateprintersbeforeusingthem_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_enableworkflowsonmysite","displayName":"Enable Workflows on My Site (User)","description":"Allows workflows on My Site to be started from within the workflow enabled Office applications.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_enableworkflowsonmysite_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_enableworkflowsonmysite_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_freezedry","displayName":"Enable Smart Resume (User)","description":"If Outlook, Word, Excel, or PowerPoint shuts down unexpectedly and is restarted automatically (for example, by Document Recovery), the user is returned to a visual state similar to the state at shutdown. By default, this setting is enabled.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_freezedry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_freezedry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_graphicfilterlegacymode","displayName":"Graphic filter legacy mode (User)","description":"Controls code path used by legacy GIF/PNG/JPEG filters. The default is to use the GDI+ codecs for these image types. For a compatibility mode to previous versions of Office which will use the legacy filter code, enable this policy.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_graphicfilterlegacymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_graphicfilterlegacymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_hidethelearnmoreaboutsharepointhyperlink","displayName":"Hide the Learn more about SharePoint Hyperlink (User)","description":"This policy setting allows you to remove the Learn more about SharePoint hyperlink from the Save to SharePoint form in the Backstage view for Word, PowerPoint, Excel, Visio, and Project.\r\n\r\nIf you enable this policy setting, the hyperlink will not be displayed.\r\n\r\nIf you disable or do not configure this policy setting, the hyperlink will appear for the Save to SharePoint form in the Backstage view when there are no locations listed.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_hidethelearnmoreaboutsharepointhyperlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_hidethelearnmoreaboutsharepointhyperlink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_homeworkflowlibrary","displayName":"Home Workflow Library (User)","description":"Allows administrators to make workflows from a specified list or library available within the workflow enabled Office applications. The value of this key should be the URL to the list or library where the workflows have been made available.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_homeworkflowlibrary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_homeworkflowlibrary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_homeworkflowlibrary_l_path2504","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations","displayName":"Increase the visibility of Accessibility Checker violations (User)","description":"This policy setting controls whether a document, workbook, or spreadsheet with accessibility errors will cause a loud warning or error slab in the user interface.\r\n\r\nIf you enable this policy setting, you may specify what happens when a document, workbook, or spreadsheet has accessibility errors:\r\n\r\n- Accessibility violations do not change Prepare for Distribution loudness (default)\r\n- Accessibility errors cause the Prepare for Distribution slab to be loud\r\n- Accessibility errors or warnings cause the Prepare for Distribution slab to be loud\r\n\r\nIf you disable or do not configure this policy setting, the Accessibility Checker UI will be presented in its normal state.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid_0","displayName":"Accessibility violations do not change loudness (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid_1","displayName":"Accessibility errors cause slab to be loud","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid_2","displayName":"Accessibility errors or warnings cause slab to be loud","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_iscustomaddintabdefaultbackstageplace","displayName":"Take users to a custom File menu tab (User)","description":"\r\nThis policy setting controls whether users are taken to a custom menu tab when they choose the File menu in an Office app, such as Word or PowerPoint. A custom menu tab can be provided by an installed add-in.\r\n\r\nBy default, when users choose the File menu, they are taken to one of the File menu tabs provided by Office, such as Home or Info.\r\n\r\nIf you enable this policy setting, and an installed add-in provides a custom File menu tab, users will be taken to that custom tab when they choose the File menu.\r\n\r\nIf you disable or don’t configure this policy setting, when users choose the File menu, users will be taken to one of the File menu tabs provided by Office, such as Home or Info.\r\n\r\nNote: This policy setting only applies to Office clients, such as Office 365 ProPlus, that come with an Office 365 plan.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_iscustomaddintabdefaultbackstageplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_iscustomaddintabdefaultbackstageplace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_iscustomtabdefaultinnewplace","displayName":"Show the Custom tab as the default tab when creating a new file (User)","description":"\r\nThis policy settings controls whether the Custom tab shows as the default tab under File > New in Word, Excel, and PowerPoint.\r\n\r\nThe Custom tab shows the custom templates that are available. If there aren’t any custom templates, the Custom tab can’t be shown.\r\n\r\nIf you enable this policy setting, users will see the Custom tab as the default tab when creating a new file by going to File > New.\r\n\r\nIf you disable or don’t configure this policy setting, users will see the Featured tab as the default tab when creating a new file by going to File > New, unless access to Office-provided templates has been disabled.\r\n\r\nNote: This policy setting only applies to Office clients, such as Office 365 ProPlus, that come with an Office 365 plan.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_iscustomtabdefaultinnewplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_iscustomtabdefaultinnewplace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcode","displayName":"Disable Microsoft Office shared drawing code for blip caching (User)","description":"Disables blip (an image representation) caching in the shared drawing code GEL. Caching can speed up certain operations. Disabling blip caching can be used to prevent caching during file open operations.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcodeformeta","displayName":"Disable Microsoft Office shared drawing code for metafile rendering (User)","description":"Disables nearly all EMF's and WMF's will no longer be converted at runtime to be anti-aliased. Examples of EMF/WMF's that would remain \"aliased\" are: clipart, OLE object placeholders, any user inserted EMF/WMF image, etc. Any EMF/WMF containing text would be an exception to this and would be still getting anti-aliased.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcodeformeta_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcodeformeta_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_mrutemplatelistlength","displayName":"Most Recently Used Template List Length (User)","description":"This setting determines the length of the recently used templates list in the New Document dialog box. The maximum value is 25 and the minimum value is 0. This setting applies to Word, Powerpoint, and Excel.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_mrutemplatelistlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_mrutemplatelistlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_mrutemplatelistlength_l_mrutemplatelistlength505","displayName":"Most Recently Used Template List Length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter","displayName":"Hide file locations when opening or saving files (User)","description":"\r\nThis policy setting allows you to hide specific file locations when the user opens or saves a file. This helps prevent users from using either the local PC, SharePointServer, or Microsoft Office 365 cloud-based file locations such as OneDrive or SharePoint Online, to open, save, or share files.\r\n\r\nNote: This policy setting only applies to Word, PowerPoint, and Excel.\r\n\r\nIf you enable this policy setting, you can specify which file locations are hidden when the user opens or saves a file.\r\n\r\nIf you disable or don’t configure this policy setting, users can use the local PC, SharePoint Server or any configured Microsoft cloud-based file location to open, save, and share files.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid_1","displayName":"Hide OneDrive Personal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid_2","displayName":"Hide SharePoint Online and OneDrive for Business","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid_3","displayName":"Hide OneDrive Personal, SharePoint Online and OneDrive for Business","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid_4","displayName":"Hide Local PC","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid_8","displayName":"Hide SharePoint Server","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_printticketsafemode","displayName":"Print ticket safe mode (User)","description":"This policy setting allows you to determine whether Word, PowerPoint, or Excel turns off print ticket features the next time it attempts to use print ticket features after the application fails. Print ticket features include duplexing and stapling.\r\n\r\nIf you enable or do not configure this policy setting, print ticket features are turned off if Word, PowerPoint, and Excel fail while attempting to use a printer's print ticket functionality. When the printer is next used, its print ticket features are turned off until the user requests to use them again.\r\n\r\nIf you disable this policy setting, Word, PowerPoint, or Excel does not turn off print ticket features due to a previous application failure. This might result in repeated instances of the printer not responding.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_printticketsafemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_printticketsafemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_providefeedbackwithsound","displayName":"Provide feedback with sound (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_providefeedbackwithsound_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_providefeedbackwithsound_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showpasteoptionsbuttons","displayName":"Show Paste Options button when content is pasted (User)","description":"This policy setting configures the Paste Options button.\r\n\r\nIf you enable this policy setting, the Paste Options button is displayed after content is pasted.\r\n\r\nIf you disable or do not configure this policy setting, the Paste Options button is not displayed.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showpasteoptionsbuttons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showpasteoptionsbuttons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips","displayName":"Show Screen Tips (User)","description":"This policy setting allows you to determine whether Office applications display screen tips when users hover on commands on the Office Ribbon, and whether the screen tips display feature names and descriptions, or just feature names. \r\n\r\nIf you enable this policy setting, you can select any of the following options:\r\n- Show feature descriptions: Both feature names and descriptions appear when users hover over commands on the Ribbon. \r\n- Don't show feature descriptions: Only feature names appear when users hover over commands on the Ribbon. \r\n- Don't show screen tips: Nothing appears when users hover over commands on the Ribbon.\r\n\r\nIf you disable this policy setting, nothing appears when users hover over commands on the Office Ribbon.\r\n\r\nIf you do not configure this policy setting, both feature names and descriptions appear when users hover over commands on the Office Ribbon.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_l_showscreentipsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_l_showscreentipsdropid_0","displayName":"Show feature descriptions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_l_showscreentipsdropid_1","displayName":"Don't show feature descriptions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_l_showscreentipsdropid_2","displayName":"Don't show screentips","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showskydrivesignin","displayName":"Show OneDrive Sign In (User)","description":"Prompt user to sign in to OneDrive while performing a file save operation.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showskydrivesignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showskydrivesignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions","displayName":"Block signing into Office (User)","description":"This policy setting controls whether users can provide credentials to Office using either their Microsoft Account or the user ID assigned by your organization for accessing Office 365.\r\nIf you enable this policy setting, you can specify one of the following options:\r\n\r\n- If you select \"Both IDs allowed\", users can sign in and access Office content by using either ID\r\n- If you select \"Microsoft Account only\", users can sign in only by using their Microsoft Account.\r\n- If you select \"Organization only\", users can sign in only by using the user ID assigned by your organization for accessing Office 365.\r\n- If you select \"None allowed\", users cannot sign in by using either ID.\r\n\r\nIf you disable or do not configure this policy setting, users can sign in by using either ID.\r\n\r\nNote: This policy does not apply to licensing. A user can license their product using any applicable ID if they have a valid license associated with that account. Providing credentials for licensing purposes when that ID type has been disabled, however, will not affect the signed in state of Office.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5","displayName":"Block signing into Office (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_0","displayName":"Both IDs allowed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_1","displayName":"Microsoft Account only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_2","displayName":"Org ID only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_3","displayName":"None allowed","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_suppressrecommendedsettingsdialog","displayName":"Suppress recommended settings dialog (User)","description":"This policy setting controls the Recommended Settings dialog on first run of Office.\r\n\r\nIf you enable this policy setting, the recommended settings dialog will not be displayed on first run of Office.\r\n\r\nIf you disable or do not configure this policy setting, the recommended settings will provide choices to the user to opt into services such as such as Microsoft Update, new software notifications, Customer Experience Improvement Program, Office Diagnostics (Automatically receive small updates to improve reliability) Online Help (Online content options) and Online Search Relevancy that will help improve their Office experience.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_suppressrecommendedsettingsdialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_suppressrecommendedsettingsdialog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselegacytranslationfeatures","displayName":"Use legacy translation features (User)","description":"\r\nThis policy setting allows you to use legacy translation features in Office apps, such as Word, instead of the Translator feature, which uses the cloud-based Microsoft Translator service.\r\n\r\nLegacy translation features include the following:\r\n- Translation of the entire document, by using the browser-based Bilingual Viewer.\r\n- Translation of selected text, by using the Research pane.\r\n- Translation of an individual word when hovering over the word, by using the Mini Translator.\r\n\r\nYou may need to use legacy translation features in special cases that require extra configurability, such as when using customer translation providers.\r\n\r\nIf you enable this policy setting, translation commands, such as those on the ribbon or in shortcut menus, will use the legacy translation features instead of the Translator feature.\r\n\r\nIf you disable or don’t configure this policy setting, translation commands, such as those on the ribbon or in shortcut menus, will use the Translator feature instead of the legacy translation features.\r\n\r\nNote: This policy setting only applies to apps and subscription versions of Office, such as Office 365 ProPlus, that support the Translator feature.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselegacytranslationfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselegacytranslationfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselocaluserinfo","displayName":"Use local user name and initials values regardless of signed-in user (User)","description":"This policy setting controls whether Office uses the user name and initials of the user currently signed-in, or the user name and initials that are specified in the Options dialog box.\r\n\r\nIf you enable this policy setting, regardless of any user currently signed-in, Office uses the user name and initials specified in the Options dialog box.\r\n\r\nIf you disable or do not configure this policy setting, Office uses the user name and initials from the information provided by the user that is currently signed-in.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselocaluserinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselocaluserinfo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_usesystemfontinsteadoftahoma","displayName":"Use system font instead of the Office default UI font (User)","description":"Use the system font instead of the Office default UI font. | Unchecked: Use the Office default UI font.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_usesystemfontinsteadoftahoma_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_usesystemfontinsteadoftahoma_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders","displayName":"Web Folders: Managing pairs of Web pages and folders (User)","description":"Specifies how a Web page and folder pair is to be displayed and managed by Windows.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders_l_webfoldersmanagingpairsofwebpagesandfolders506","displayName":"Web Folders: Managing pairs of Web pages and folders (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders_l_webfoldersmanagingpairsofwebpagesandfolders506_0","displayName":"Show and manage the pair as a single file","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders_l_webfoldersmanagingpairsofwebpagesandfolders506_2","displayName":"Show both parts and manage them individually","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders_l_webfoldersmanagingpairsofwebpagesandfolders506_1","displayName":"Show both parts but manage as a single file","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1","displayName":"Workflow Cache 1 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowcachename","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowdescrip","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowfriendly","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowpath","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowsig","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowsig_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowsig_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10","displayName":"Workflow Cache 10 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowcachename473","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowdescrip475","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowfriendly476","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowpath474","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowsig477","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowsig477_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowsig477_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11","displayName":"Workflow Cache 11 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowcachename478","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowdescrip480","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowfriendly481","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowpath479","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowsig482","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowsig482_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowsig482_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12","displayName":"Workflow Cache 12 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowcachename483","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowdescrip485","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowfriendly486","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowpath484","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowsig487","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowsig487_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowsig487_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13","displayName":"Workflow Cache 13 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowcachename488","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowdescrip490","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowfriendly491","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowpath489","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowsig492","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowsig492_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowsig492_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14","displayName":"Workflow Cache 14 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowcachename493","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowdescrip495","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowfriendly496","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowpath494","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowsig497","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowsig497_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowsig497_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15","displayName":"Workflow Cache 15 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowcachename498","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowdescrip500","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowfriendly501","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowpath499","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowsig502","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowsig502_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowsig502_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2","displayName":"Workflow Cache 2 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowcachename433","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowdescrip435","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowfriendly436","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowpath434","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowsig437","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowsig437_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowsig437_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3","displayName":"Workflow Cache 3 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowcachename438","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowdescrip440","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowfriendly441","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowpath439","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowsig442","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowsig442_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowsig442_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4","displayName":"Workflow Cache 4 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowcachename443","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowdescrip445","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowfriendly446","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowpath444","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowsig447","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowsig447_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowsig447_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5","displayName":"Workflow Cache 5 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowcachename448","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowdescrip450","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowfriendly451","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowpath449","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowsig452","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowsig452_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowsig452_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6","displayName":"Workflow Cache 6 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowcachename453","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowdescrip455","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowfriendly456","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowpath454","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowsig457","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowsig457_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowsig457_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7","displayName":"Workflow Cache 7 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowcachename458","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowdescrip460","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowfriendly461","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowpath459","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowsig462","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowsig462_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowsig462_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8","displayName":"Workflow Cache 8 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowcachename463","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowdescrip465","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowfriendly466","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowpath464","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowsig467","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowsig467_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowsig467_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9","displayName":"Workflow Cache 9 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowcachename468","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowdescrip470","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowfriendly471","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowpath469","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowsig472","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowsig472_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowsig472_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseexcel","displayName":"Block opening of pre-release versions of file formats new to Excel 2016 through the Compatibility Pack for Office 2016 and Excel 2016 Converter (User)","description":"This policy setting controls whether users with the Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2016 File Formats installed can open Office Open XML files saved with pre-release versions of Excel 2016. Excel Open XML files usually have the following extensions: .xlsx, .xlsm, .xltx, .xltm, .xlam. \r\n\r\nIf you enable this policy setting, users of the Compatibility Pack will not be able to open Office Open XML files created in pre-release versions of Excel 2016.\r\n\r\nIf you disable this policy setting, users with the Compatibility Pack installed can open files saved by some pre-release versions of Excel, but not by others, which can lead to inconsistent file opening functionality.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled. ","helpText":"","infoUrls":[],"categoryId":"8b0e5a63-c309-430b-8521-7bd21e715b90","categoryName":"Office 2016 Converters","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseppt","displayName":"Block opening of pre-release versions of file formats new to PowerPoint 2016 through the Compatibility Pack for Office 2016 and PowerPoint 2016 Converter (User)","description":"This policy setting controls whether users with the Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2016 File Formats installed can open Office Open XML files saved with pre-release versions of PowerPoint 2016. PowerPoint Open XML files usually have the following extensions: .pptx, .pptm, .potx, .potm, .ppsx, .ppsm, .ppam, .thmx, .xml. \r\n\r\nIf you enable this policy setting, users of the Compatibility Pack will not be able to open Office Open XML files created in pre-release versions of PowerPoint 2016. \r\n\r\nIf you disable this policy setting, users with the Compatibility Pack installed can open files saved by some pre-release versions of PowerPoint, but not by others, which can lead to inconsistent file opening functionality.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled","helpText":"","infoUrls":[],"categoryId":"8b0e5a63-c309-430b-8521-7bd21e715b90","categoryName":"Office 2016 Converters","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseppt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseppt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_disableinclusionofdocumentpropertiesinpdfandxpsoutput","displayName":"Disable inclusion of document properties in PDF and XPS output (User)","description":"This policy setting controls whether document metadata can be saved in PDF and XPS documents. \r\n\r\nIf you enable this policy setting, document properties metadata is not exported to PDF and XPS files. \r\n\r\nIf you disable this policy setting, document properties metadata will always be saved with PDF and XPS files, and users will not be able to override this configuration. \r\n\r\nIf you do not configure this policy setting, if the Microsoft Save as PDF or XPS Add-in for Microsoft Office Programs add-in is installed, document properties are saved as metadata when users save files using the PDF or XPS or Publish as PDF or XPS commands in Access, Excel, InfoPath, PowerPoint, and Word, unless the \"Document properties\" option is unchecked in the Options dialog.","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_disableinclusionofdocumentpropertiesinpdfandxpsoutput_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_disableinclusionofdocumentpropertiesinpdfandxpsoutput_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa","displayName":"Enforce PDF compliance with ISO 19005-1 (PDF/A) (User)","description":"Allows enforcement of ISO 19005-1 compliance in PDF output. The values for his setting are as follows:\r\n \r\nDefault: Options UI defaults to not ISO compliant. User may override.\r\n\r\nEncourage: Options UI defaults to ISO compliance. User may override.\r\n\r\nPrevent: Not ISO compliant. No user override.\r\n\r\nEnforce: ISO compliant. No user override.\r\n\r\nSee Office Help for more details on the tradeoffs of choosing ISO 19005 compliance.","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_l_empty417","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_l_empty417_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_l_empty417_1","displayName":"Encourage","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_l_empty417_2","displayName":"Prevent","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_l_empty417_3","displayName":"Enforce","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser","displayName":"Disable Microsoft Save As PDF and XPS add-ins (User)","description":"Allows the user or administrator to specify which of the installed Microsoft PDF and XPS add-ins are available. \r\n\r\nWhen this setting is not configured, installed Microsoft PDF and XPS add-ins are visible to users. \r\n\r\nDefault: same as not configured. \r\n\r\nDisable XPS: Hides and disables the Microsoft Save As XPS add-in. \r\n\r\nDisable PDF: Hides and disables the Microsoft Save As PDF add-in. \r\n\r\nDisable XPS and PDF: Hides and disables both the Microsoft Save As PDF and Save As XPS add-ins.","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_l_empty418","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_l_empty418_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_l_empty418_1","displayName":"Disable XPS","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_l_empty418_2","displayName":"Disable PDF","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_l_empty418_3","displayName":"Disable XPS and PDF","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences","displayName":"[Deprecated] Allow the use of connected experiences in Office (User)","description":"\r\n This policy setting allows you to control whether connected experiences are available to your users when they're using Office.\r\n\r\n Connected experiences include experiences that analyze content, such as Editor in Word, experiences that download online content, such as PowerPoint QuickStarter, and other connected experiences, such as document co-authoring and online file storage. It also includes additional optional connected experiences, such as the LinkedIn features of the Resume Assistant in Word or the 3D Maps feature in Excel, which uses Bing. See the Note at the end for more information about other policy settings that you can use to control these connected experiences.\r\n\r\n If you enable this policy setting, these connected experiences will be available to your users.\r\n\r\n If you disable this policy setting, these connected experiences won't be available to your users.\r\n\r\n Note: If you disable this policy setting, nearly all connected experiences will be turned off. However, limited Office functionality will remain available, such as synching a mailbox in Outlook. Essential services, such as the licensing service that confirms that you’re properly licensed to use Office, will also remain available.\r\n\r\n If you don't configure this policy setting, these connected experiences will be available to your users.\r\n\r\n Note: You can use these other policy settings if you want to disable just a certain group of connected experiences:\"Allow the use of connected experiences in Office that analyze content,\" \"Allow the use of connected experiences in Office that download online content,\" and \"Allow the use of additional optional connected experiences in Office.\"\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2085689\r\n ","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_l_connectedofficeexperiencesdropid","displayName":"[Deprecated] Connected experiences in Office (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_l_connectedofficeexperiencesdropid_1","displayName":"Connected","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_l_connectedofficeexperiencesdropid_2","displayName":"Disconnected","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_disableoptinwizard","displayName":"Disable Opt-in Wizard on first run (User)","description":"This policy setting controls whether users see the Opt-in Wizard the first time they run a Microsoft Office 2016 application. \r\n\r\nIf you enable this policy setting, the Opt-in Wizard does not display the first time users run an Office 2016 application. \r\n\r\nIf you disable or do not configure this policy setting, the Opt-in Wizard displays the first time users run a Microsoft Office 2016 application, which allows them to opt into Internet--based services that will help improve their Office experience, such as Microsoft Update, the Customer Experience Improvement Program, Office Diagnostics, and Online Help.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_disableoptinwizard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_disableoptinwizard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_enablecustomerexperienceimprovementprogram","displayName":"Enable Customer Experience Improvement Program (User)","description":"This policy setting controls whether users can participate in the Microsoft Office Customer Experience Improvement Program to help improve Microsoft Office. When users choose to participate in the Customer Experience Improvement Program (CEIP), Office 2016 applications automatically send information to Microsoft about how the applications are used. This information is combined with other CEIP data to help Microsoft solve problems and to improve the products and features customers use most often. This feature does not collect users' names, addresses, or any other identifying information except the IP address that is used to send the data. \r\n\r\nIf you enable this policy setting, users have the opportunity to opt into participation in the CEIP the first time they run an Office application. If your organization has policies that govern the use of external resources such as the CEIP, allowing users to opt in to the program might cause them to violate these policies. \r\n\r\nIf you disable this policy setting, Office 2016 users cannot participate in the Customer Experience Improvement Program. \r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_enablecustomerexperienceimprovementprogram_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_enablecustomerexperienceimprovementprogram_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent","displayName":"[Deprecated] Allow the use of connected experiences in Office that analyze content (User)","description":"\r\n This policy setting allows you to control whether connected experiences that analyze content are available to your users when they're using Office.\r\n\r\n PowerPoint Designer and Editor in Word are examples of connected experiences that analyze content.\r\n\r\n If you enable this policy setting, connected experiences that analyze content will be available to your users.\r\n\r\n If you disable this policy setting, connected experiences that analyze content won't be available to your users.\r\n\r\n If you don't configure this policy setting, connected experiences that analyze content will be available to your users.\r\n\r\n Note: If you disable the \"Allow the use of connected experiences in Office\" policy setting, conected experiences that analyze content won't be available to your users.\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2085794\r\n ","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_l_officeexperiencesanlayzingcontentdropid","displayName":"[Deprecated] Connected experiences in Office that analyze content (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_l_officeexperiencesanlayzingcontentdropid_1","displayName":"Enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_l_officeexperiencesanlayzingcontentdropid_2","displayName":"Disabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent","displayName":"[Deprecated] Allow the use of connected experiences in Office that download online content (User)","description":"\r\n This policy setting allows you to control whether connected experiences that download online content are available to your users when they’re using Office.\r\n\r\n Office templates and PowerPoint QuickStarter are examples of connected experiences that download online content.\r\n\r\n If you enable this policy setting, connected experiences that download online content will be available to your users.\r\n\r\n If you disable this policy setting, connected experiences that download online content won’t be available to your users.\r\n\r\n If you don’t configure this policy setting, connected experiences that download online content will be available to your users.\r\n\r\n Note: If you disable the “Allow the use of connected experiences in Office” policy setting, connected experiences that download online content won’t be available to your users.\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2085688\r\n ","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_l_officeexperiencesdownloadingcontentdropid","displayName":"[Deprecated] Connected experiences in Office that download online content (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_l_officeexperiencesdownloadingcontentdropid_1","displayName":"Enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_l_officeexperiencesdownloadingcontentdropid_2","displayName":"Disabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences","displayName":"[Deprecated] Allow the use of additional optional connected experiences in Office (User)","description":"\r\n This policy setting allows you to control whether additional optional connected experiences are available to your users when they’re using Office.\r\n\r\n Additional optional connected experiences are offered by Microsoft directly to your users and are governed by terms other than your organization’s commercial agreement with Microsoft.\r\n\r\n The LinkedIn features of the Resume Assistant in Word or the 3D Maps feature in Excel, which uses Bing, are examples of additional optional connected experiences.\r\n\r\n Note: Even if you choose to make these additional optional connected experiences available to your users, your users will have the option to turn these additional optional connected experiences off as a group by going to File > Account > Account Privacy > Manage Settings.\r\n\r\n If you enable this policy setting, additional optional connected experiences will be available to your users.\r\n\r\n If you disable this policy setting, additional optional connected experiences won’t be available to your users.\r\n\r\n Note: Some additional optional connected experiences may be controlled by other policy settings instead of this policy setting. For more information, see the link below.\r\n\r\n If you don’t configure this policy setting, additional optional connected experiences will be available to your users.\r\n\r\n Note: If you disable the “Allow the use of connected experiences in Office” policy setting, additional optional connected experiences won’t be available to your users.\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2085690\r\n ","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_l_optionalconnectedexperiencesdropid","displayName":"[Deprecated] Optional connected experiences in Office (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_l_optionalconnectedexperiencesdropid_1","displayName":"Enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_l_optionalconnectedexperiencesdropid_2","displayName":"Disabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_screenshot","displayName":"Allow including screenshot with Office Feedback (User)","description":"This policy setting manages whether the Office Feedback Tool (a.k.a. Send a Smile) allows the user to send a screenshot of their desktop with their feedback to Microsoft. The Office Feedback Tool allows users to provide Microsoft feedback regarding their positive and negative experiences when using Office.\r\n\r\nIf you enable this policy setting, the Office Feedback Tool will allow the user to send a screenshot of their desktop with their feedback to Microsoft.\r\n\r\nIf you disable this policy setting, the Office Feedback Tool will not allow the user to send a screenshot of their desktop with their feedback to Microsoft.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_screenshot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_screenshot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendcustomerdata","displayName":"Send personal information (User)","description":"This policy setting controls whether users can send personal information to Office. When users choose to send information Office 2016 applications automatically send information to Office.\r\n\r\nIf you enable this policy setting, users will opt into sending personal information to Office. If your organization has policies that govern the use of external resources, opting users into the program might cause them to violate these policies.\r\n\r\nIf you disable this policy setting, Office 2016 users cannot send personal information to Office.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendcustomerdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendcustomerdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendfeedback","displayName":"Send Office Feedback (User)","description":"This policy setting manages the Office Feedback Tool (a.k.a. Send a Smile). The Office Feedback Tool allows users to provide Microsoft feedback regarding their positive and negative experiences when using Office.\r\n\r\nIf you enable this policy setting, the Office Feedback Tool will be turned on in all Office applications in which the tool is available. They can access the tool through the Smile button located in the top right corner of the Office application.\r\n\r\nIf you disable this policy setting, the Office Feedback Tool will be turned off. Users will not see the Smile button in any of the Office applications in which the tool is available.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendfeedback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendfeedback_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry","displayName":"Configure the level of client software diagnostic data sent by Office to Microsoft (User)","description":"\r\n This policy setting allows you to configure the level of client software diagnostic data that is collected and sent to Microsoft about the Office client software running on the user's device.\r\n\r\n Client software diagnostic data is used to keep Office secure and up-to-date, detect, diagnose and remediate problems, and also make product improvements. This data does not include a user's name or email address, the content of the user's files, or information about apps unrelated to Office.\r\n\r\n If you enable this policy setting, you must choose which level of diagnostic data is sent to Microsoft. Your choices are Required, Optional, or Neither.\r\n\r\n If you choose Required, the minimum data needed to keep Office secure, up-to-date, and performing as expected on the device it's installed on is sent to Microsoft.\r\n\r\n If you choose Optional, additional data that helps make product improvements and provides enhanced information to help detect, diagnose, and remediate issues is sent to Microsoft. If you choose to send optional diagnostic data, required diagnostic data is also included.\r\n\r\n If you choose Neither, no diagnostic data about Office client software running on the user's device is sent to Microsoft. This option, however, significantly limits Microsoft's ability to detect, diagnose, and remediate problems that your users may encounter when using Office.\r\n\r\n If you disable or don't configure this policy setting, optional diagnostic data is sent to Microsoft.\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2085687 ","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid","displayName":"Type of diagnostic data: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid_3","displayName":"Neither","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid_2","displayName":"Optional","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid_1","displayName":"Required","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_updatereliabilitypolicy","displayName":"Automatically receive small updates to improve reliability (User)","description":"This policy setting controls whether Microsoft Office Diagnostics is enabled. Office Diagnostics enables Microsoft to diagnose system problems by periodically downloading a small file to the computer. \r\n\r\nIf you enable this policy setting, Office Diagnostics collects information about specific errors and the IP address of the computer. Office Diagnostics does not transmit any personally identifiable information to Microsoft other than the IP address of the computer requesting the update. \r\n\r\nIf you disable this policy setting, users will not receive updates from Office Diagnostics. \r\n\r\nIf you do not configure this policy setting, this policy setting is not enabled, but users have the opportunity to opt into receiving updates from Office Diagnostics the first time they run an Office 2016 application.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_updatereliabilitypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_updatereliabilitypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags","displayName":"Specify custom labels to use with the Readiness Toolkit (User)","description":"This policy setting allows you to specify up to four custom labels to categorize and filter data in reports created by the Readiness Toolkit for Office. Labels are available in reports that are based on scans of the most recently used Office documents and installed add-ins on the user’s computer.\r\n\r\nYou can specify any string for the custom labels. For example, you can use a label to indicate the user’s department, title, or geographic location. When the Readiness Toolkit runs on the user’s computer, the custom labels are collected and are made available in the reports that are created. For example, you can filter the report to show only data from the Finance Department. Assign labels in a consistent manner, such as always using Label 1 for department.\r\n\r\nIf you enable this policy setting, the custom labels that you specify will be available in reports created by the Readiness Toolkit.\r\n\r\nIf you disable or don’t configure this policy setting, custom labels won’t be available in reports created by the Readiness Toolkit.\r\n\r\nNote: If you're using the Office Telemetry Dashboard and have already configured tags (labels), the Readiness Toolkit automatically collects those labels during its scan of the user's computer and will make them available in its reports. You don't need to enable this policy setting unless you want to specify different labels. Labels you specify for the Readiness Toolkit won't appear in the Office Telemetry Dashboard.","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_l_officereadinesstoolkitcustomtagstag1","displayName":"Label 1: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_l_officereadinesstoolkitcustomtagstag2","displayName":"Label 2: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_l_officereadinesstoolkitcustomtagstag3","displayName":"Label 3: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_l_officereadinesstoolkitcustomtagstag4","displayName":"Label 4: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitenableusageagent","displayName":"Allow add-in usage data to be generated and collected by the Readiness Toolkit (User)","description":"This policy setting allows you to configure whether the Readiness Toolkit for Office generates and collects add-in usage data. The data generated and collected includes when the add-in is loaded and used, and if the add-in crashes. This information is available in reports provided by the Readiness Toolkit.\r\n\r\nIf you enable this policy setting, the Readiness Toolkit generates and collects add-in usage data.\r\n\r\nIf you disable or don't configure this policy setting, the Readiness Toolkit doesn't generate or collect add-in usage data.","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitenableusageagent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitenableusageagent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization","displayName":"ActiveX Control Initialization (User)","description":"This policy setting specifies the Microsoft ActiveX® initialization security level for all Microsoft Office applications. ActiveX controls can adversely affect a computer directly. In addition, malicious code can be used to compromise an ActiveX control and attack a computer. To indicate the safety of an ActiveX control, developers can denote them as Safe For Initialization (SFI). SFI indicates that a control is safe to open and run, and that it is not capable of causing a problem for any computer, regardless of whether it has persisted data values or not. If a control is not marked SFI, it is possible that the control could adversely affect a computer--or it could mean that the developers did not test the control in all situations and are not sure whether it might be compromised in the future. \r\n \r\n If you enable this policy setting, you can set the ActiveX security level to a number between 1 and 6. These security levels are as follows: \r\n \r\n 1 - Regardless of how the control is marked, load it and use the persisted values (if any). This setting does not prompt the user. \r\n \r\n 2 - If SFI, load the control in safe mode and use persisted values (if any). If not SFI, load in unsafe mode with persisted values (if any), or use the default (first-time initialization) settings. This level is similar to the default configuration, but does not prompt the user. \r\n \r\n 3 - If SFI, load the control in unsafe mode and use persisted values (if any). If not SFI, prompt the user and advise them that it is marked unsafe. If the user chooses No at the prompt, do not load the control. Otherwise, load it with default (first-time initialization) settings. \r\n \r\n 4 - If SFI, load the control in safe mode and use persisted values (if any). If not SFI, prompt the user and advise them that it is marked unsafe. If the user chooses No at the prompt, do not load the control. Otherwise, load it with default (first-time initialization) settings. \r\n \r\n 5 - If SFI, load the control in unsafe mode and use persisted values (if any). If not SFI, prompt the user and advise them that it is marked unsafe. If the user chooses No at the prompt, do not load the control. Otherwise, load it with persisted values. \r\n \r\n 6 - If SFI, load the control in safe mode and use persisted values (if any). If not SFI, prompt the user and advise them that it is marked unsafe. If the user chooses No at the prompt, do not load the control. Otherwise, load it with persisted values. \r\n \r\n If you disable or do not configure this policy setting, if a control is marked SFI, the application loads the control in safe mode and uses persisted values (if any). If the control is not marked SFI, the application loads the control in unsafe mode with persisted values (if any), or uses the default (first-time initialization) settings. In both situations, the Message Bar informs users that the controls have been disabled and prompts them to respond. \r\n \r\n Important - Some ActiveX controls do not respect the safe mode registry setting, and therefore might load persisted data even though you configure this setting to instruct the control to use safe mode. This setting only increases security for ActiveX controls that are accurately marked as SFI. In situations that involve malicious or poorly designed code, an ActiveX control might be inaccurately marked as SFI.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon","displayName":"ActiveX Control Initialization: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon_2","displayName":"2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon_3","displayName":"3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon_4","displayName":"4","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon_5","displayName":"5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon_6","displayName":"6","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions","displayName":"Allow file extensions for OLE embedding (User)","description":"This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus or Visio Pro for Office 365.\r\n\r\nThis policy setting allows you to specify which file extensions Office won’t block when they are embedded as an OLE package in an Office file by using the Object Packager control.\r\n\r\nBy default, Office blocks certain file extensions. For a list of those file extensions, go to https://go.microsoft.com/fwlink/?linkid=847759.\r\n\r\nImportant: Malicious scripts and executables can be embedded as an OLE package and can cause harm if clicked by the user.\r\n\r\nIf you enable this policy setting, enter the file extensions to allow, separated by semicolons. For example, exe;vbs;js.\r\n\r\nIf you disable or don’t configure this policy setting, the default set of file extensions will be blocked.\r\n\r\nIf you want to block additional file extensions, enable the \"Block additional file extensions for OLE embedding\" policy setting.\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions_l_allowedextensionsole","displayName":"File extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity","displayName":"Automation Security (User)","description":"This policy setting controls whether macros can run in an Office 2016 application that is opened programmatically by another application. \r\n\r\nIf you enable this policy setting, you can choose from three options for controlling macro behavior in Excel, PowerPoint, and Word when the application is opened programmatically: \r\n\r\n- Disable macros by default - All macros are disabled in the programmatically opened application. \r\n\r\n- Macros enabled (default) - Macros can run in the programmatically opened application. This option enforces the default configuration in Excel, PowerPoint, and Word. \r\n\r\n- User application macro security level - Macro functionality is determined by the setting in the \"Macro Settings\" section of the Trust Center. \r\n\r\nIf you disable or do not configure this policy setting, when a separate program is used to launch Microsoft Excel, PowerPoint, or Word programmatically, any macros can run in the programmatically opened application without being blocked.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel","displayName":"Set the Automation Security level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel_3","displayName":"Disable macros by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel_2","displayName":"Use application macro security level","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel_1","displayName":"Macros enabled (default)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions","displayName":"Block additional file extensions for OLE embedding (User)","description":"This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus or Visio Pro for Office 365.\r\n\r\nThis policy setting allows you to specify additional file extensions that Office will block when they are embedded as an OLE package in an Office file by using the Object Packager control.\r\n\r\nBy default, Office blocks certain file extensions. For a list of those file extensions, go to https://go.microsoft.com/fwlink/?linkid=847759.\r\n\r\nImportant: Malicious scripts and executables can be embedded as an OLE package and can cause harm if clicked by the user.\r\n\r\nIf you enable this policy setting, enter the additional file extensions to block, separated by semicolons. For example, py;rb.\r\n\r\nIf you disable or don’t configure this policy setting, the default set of file extensions will be blocked.\r\n\r\nIf you want to allow certain file extensions, enable the \"Allow file extensions for OLE embedding\" policy setting. Extensions added to this policy setting will take precedence over extensions in \"Allow file extensions for OLE embedding\"\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions_l_blockedextensionsole","displayName":"File extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects","displayName":"Check ActiveX objects (User)","description":"This policy setting determines whether Office checks that an ActiveX object is properly categorized before loading it. \r\n\r\nIf you enable this policy setting, you can select one of the following options:\r\n- Do not check: Office loads ActiveX objects without checking if they are properly categorized.\r\n- Override IE kill bit list: Office uses the category list to override IE kill bit checks. (This is also the default behavior for this policy setting). \r\n- Strict allow list: Office only loads properly categorized ActiveX objects.\r\n\r\nIf you disable or do not configure this policy setting, Office uses the category list to override IE kill bit checks.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects_l_checkactivexobjectsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects_l_checkactivexobjectsdropid_0","displayName":"Do not check","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects_l_checkactivexobjectsdropid_1","displayName":"Override IE kill bit list","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects_l_checkactivexobjectsdropid_2","displayName":"Strict allow list","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkexcelrtdservers","displayName":"Check Excel RTD servers (User)","description":"This policy setting determines whether Office checks that a RealTimeData (RTD) is properly categorized before loading it. \r\n\r\nIf you enable this policy setting Office only loads properly categorized RTD servers.\r\n\r\nIf you disable or do not configure this policy setting, Office does not check that an RTD server is properly categorized before loading it.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkexcelrtdservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkexcelrtdservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects","displayName":"Check OLE objects (User)","description":"This policy setting determines whether Office checks that an OLE object is properly categorized before loading it. \r\n\r\nIf you enable this policy setting, you can select one of the following options:\r\n- Do not check: Office loads OLE objects without checking if they are properly categorized.\r\n- Override IE kill bit list: Office uses the category list to override IE kill bit checks. (This is also the default behavior for this policy setting). \r\n- Strict allow list: Office only loads properly categorized OLE objects.\r\n\r\nIf you disable or do not configure this policy setting, Office uses the category list to override IE kill bit checks.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_l_checkoleobjectsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_l_checkoleobjectsdropid_0","displayName":"Do not check","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_l_checkoleobjectsdropid_1","displayName":"Override IE kill bit list","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_l_checkoleobjectsdropid_2","displayName":"Strict allow list","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkowcdatasourceproviders","displayName":"Check OWC data source providers (User)","description":"This policy setting determines whether Office checks that an Office Web Components (OWC) data source provider is properly categorized before loading it.\r\n\r\nIf you enable this policy setting, Office only loads properly categorized data source providers.\r\n\r\nIf you disable or do not configure this policy setting, Office does not check that an OWC data source provider is properly categorized before loading it.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkowcdatasourceproviders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkowcdatasourceproviders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disableallactivex","displayName":"Disable All ActiveX (User)","description":"This policy setting controls whether ActiveX controls are disabled. \r\n\r\nIf you enable this policy setting, Office 2016 applications do not initialize ActiveX controls from non-trusted locations, and do not notify the user that the ActiveX controls are disabled. \r\n\r\nIf you disable or do not configure this policy setting, users can set the trust level for ActiveX controls in the Trust Center in the 2016 versions of Microsoft Access, PowerPoint, Word, and Excel. The default configuration does not load untrusted ActiveX controls, but uses the Message Bar to prompt users about the control, and they can then choose whether to run the control.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disableallactivex_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disableallactivex_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablealltrustbarnotificationsfor","displayName":"Disable all Trust Bar notifications for security issues (User)","description":"This policy setting controls whether Office 2016 applications notify users when potentially unsafe features or content are detected, or whether such features or content are silently disabled without notification. \r\n\r\nThe Message Bar in Office 2016 applications is used to identify security issues, such as unsigned macros or potentially unsafe add-ins. When such issues are detected, the application disables the unsafe feature or content and displays the Message Bar at the top of the active window. The Message Bar informs the users about the nature of the security issue and, in some cases, provides the users with an option to enable the potentially unsafe feature or content, which could harm the user's computer. \r\n\r\nIf you enable this policy setting, Office 2016 applications do not display information in the Message Bar about potentially unsafe content that has been detected or has automatically been blocked. \r\n\r\nIf you disable this policy setting, Office 2016 applications display information in the Message Bar about content that has automatically been blocked. \r\n\r\nIf you do not configure this policy setting, if an Office 2016 application detects a security issue, the Message Bar is displayed. However, this configuration can be modified by users in the Trust Center.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablealltrustbarnotificationsfor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablealltrustbarnotificationsfor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablepasswordtoopenui","displayName":"Disable password to open UI (User)","description":"This policy setting controls whether Office 2016 users can add password encryption to documents. (Users would access this feature in Microsoft Office tab--click Info, click Protect Document, then click Encrypt with Password.)\r\n \r\n If you enable this policy setting, users cannot password protect their 2016 Office documents. \r\n \r\n\r\nIf you disable or do not configure this policy setting, users can encrypt their 2016 Office files with passwords.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablepasswordtoopenui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablepasswordtoopenui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablevbaforofficeapplications319","displayName":"Disable VBA for Office applications (User)","description":"This policy setting allows you to prevent Excel 2016, SharePoint Designer 2016, Outlook 2016, PowerPoint 2016, Publisher 2016, and Word 2016 from using Visual Basic for Applications (VBA), whether or not the VBA feature is installed on user computers. Changing this policy setting will not install or remove the VBA files from the user computers. For more information about configuring security settings, see the 2016 Office Resource Kit.\r\n\r\nIf you enable this policy setting, VBA is disabled on 2016 Office applications on user computers.\r\n\r\nIf you disable or do not configure this policy setting, VBA is enabled for 2016 Office applications on user computers.\r\n","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablevbaforofficeapplications319_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablevbaforofficeapplications319_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_enableminimizevbaresigning","displayName":"Enable Minimizing VBA Project Digital Signature Invalidation (User)","description":"\r\nThis policy setting allows you to reduce the number of actions in Office that will result in a document's VBA digital signature becoming invalidated.\r\n\r\nThe VBA project may be modified in certain ways that change the project storage but that do not invalidate the source code digital signature. With this setting turned off, these actions will lead to the VBA digital signature being invalidated, and the signature dropped on save if the user does not have the private key available to resign.\r\n\r\nWith this setting on, we will only perform a resign of the project if the source code signature has changed, and will keep the existing signature in other cases. If the VBA project storage is changed and saved, but the old signature retained under this feature, this can lead to an invalidation of the saved compiled VBA project state. If this happens, the VBA project will be forced to recompile each time the document is loaded. This may have negative performance impacts for larger VBA projects. Once a document is in this state, the state will persist until the VBA project is resigned.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_enableminimizevbaresigning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_enableminimizevbaresigning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptdocumentproperties","displayName":"Encrypt document properties (User)","description":"This policy setting allows you configure if the document properties are encrypted. This applies to OLE documents (Office 97-2003 compatible) if the application is configured for CAPI RC4.\r\n\r\nIf you enable this policy setting, the document properties will be encrypted.\r\n\r\nIf you disable or do not configure this policy setting, the document properties will not be encrypted.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptdocumentproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptdocumentproperties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003","displayName":"Encryption type for password protected Office 97-2003 files (User)","description":"This policy setting enables you to specify an encryption type for password-protected Office 97-2003 files.\r\n \r\nIf you enable this policy setting, you can specify the type of encryption that Office applications will use to encrypt password-protected files in the older Office 97-2003 file formats. The chosen encryption type must have a corresponding cryptographic service provider (CSP) installed on the computer that encrypts the file. See the HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\ registry key for a list of CSPs installed on the local computer. Specify the encryption type to use by entering it in the provided text box in the following form:\r\n\r\n,,.\r\nFor example, Microsoft Enhanced Cryptographic Provider v1.0,RC4,128\r\n\r\nIf you do not configure this policy setting, Excel, PowerPoint, and Word use Office 97/2000 Compatible encryption, a proprietary encryption method, to encrypt password-protected Office 97-2003 files.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003_l_encryptiontypecolon318","displayName":"Encryption type: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedofficeopen","displayName":"Encryption type for password protected Office Open XML files (User)","description":"This policy setting allows you to specify an encryption type for Office Open XML files.\r\n \r\nIf you enable this policy setting, you can specify the type of encryption that Office applications use to encrypt password-protected files in the Office Open XML file formats used by Excel, PowerPoint, and Word. The chosen encryption type must have a corresponding cryptographic service provider (CSP) installed on the computer that encrypts the file. See the HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\ registry key for a list of CSPs installed on the local computer. Specify the encryption type to use by entering it in the provided text box in the following form:\r\n\r\n,,\r\n\r\nFor example: Microsoft Enhanced Cryptographic Provider v1.0,RC4,128\r\n\r\nIf you disable or do not configure this policy setting, the default CSP is used. The default cryptographic service provider (CSP) is Microsoft Enhanced RSA and AES Cryptographic Provider, AES-128, 128-bit.\r\n\r\nNote: This policy setting does not take effect unless the registry key \r\nHKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\\\Security\\Crypto\\CompatMode is set to 0. By default the CompatMode registry key is set to 1.\r\n","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedofficeopen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedofficeopen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedofficeopen_l_encryptiontypecolon","displayName":"Encryption type: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3","displayName":"Load Controls in Forms3 (User)","description":"This policy setting allows you to control how ActiveX controls in UserForms should be initialized based upon whether they are Safe For Initialization (SFI) or Unsafefor Initialization (UFI). \r\n \r\n ActiveX controls are Component Object Model (COM) objects and have unrestricted access to users' computers. ActiveX controls can access the local file system and change the registry settings of the operating system. If a malicious user repurposes an ActiveX control to take over a user's computer, the effect could be significant. To help improve security, ActiveX developers can mark controls as Safe For Initialization (SFI), which means that the developer states that the controls are safe to open and run and not capable of causing harm to any computers. If a control is not marked SFI, the control could adversely affect a computer--or it's possible the developers did not test the control in all situations and are not sure whether their control might be compromised at some future date.SFI controls run in safe mode, which limits their access to the computer. For example, a worksheet control can both read and write files when it is in unsafe mode, but perhaps only read from files when it is in safe mode. This functionality allows the control to be used in very powerful ways when safety wasn't important, but the control would still be safe for use in a Web page. If a control is not marked as SFI, it is marked Unsafe For Initialization (UFI), which means that it is capable of affecting a user's computer. If UFI ActiveX controls are loaded, they are always loaded in unsafe mode. \r\n \r\n If you enable this policy setting, you can choose from four options for loading controls in UserForms: \r\n \r\n 1- For a UFI or SFI signed control that supports safe and unsafe mode, load the control in unsafe mode. For an SFI signed control that only supports a safe mode configuration, load the control in safe mode. This option enforces the default configuration. \r\n \r\n 2 - Users are prompted to determine how UserForm forms will load. The prompt only displays once per session within an application. When users respond to the prompt, loading continues based on whether the control is UFI or SFI: \r\n \r\n - For a UFI signed control, if users respond Yes to the prompt, load the control in unsafe mode. If users respond No, load the control using the default properties. \r\n \r\n - For an SFI signed control that supports both safe and unsafe modes, if users respond Yes to the prompt, load the control in unsafe mode. If users respond No, load the control using safe mode. If the SFI control can only support safe mode, load the control in safe mode. This option is the default configuration in the Microsoft Office 2016 release. \r\n \r\n 3 - Users are prompted to determine how UserForm forms will load. The prompt only displays once per session within an application. When users respond to the prompt, loading continues based on whether the control is UFI or SFI: \r\n \r\n - For a UFI signed control, if users respond Yes to the prompt, load the control in unsafe mode. If users respond No, load the control with its default properties. \r\n \r\n - For an SFI signed control, load in safe mode. \r\n \r\n 4 - For a UFI signed control, load with the default properties of the control. For an SFI signed control, load in safe mode (considered to be the safest mode). \r\n \r\n If you disable or do not configure this policy setting, the behavior is as if you enable this policy setting and then select option 1. ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon","displayName":"Load Controls in Forms3: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_2","displayName":"2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_3","displayName":"3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_4","displayName":"4","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope","displayName":"Macro Runtime Scan Scope (User)","description":"This policy setting specifies for which documents the VBA Runtime Scan feature is enabled.\r\n\r\nIf the feature is disabled for all documents, no runtime scanning of enabled macros will be performed.\r\n\r\nIf the feature is enabled for low trust documents, the feature will be enabled for all documents for which macros are enabled except:\r\n\r\n - Documents opened while macro security settings are set to \"Enable All Macros\"\r\n\r\n - Documents opened from a Trusted Location\r\n\r\n - Documents that are Trusted Documents\r\n\r\n - Documents that contain VBA that is digitally signed by a Trusted Publisher\r\n\r\nIf the feature is enabled for all documents, then the above class of documents are not excluded from the behavior.\r\n\r\nThis protocol allows the VBA runtime to report to the Anti-Virus system certain high-risk code behaviors it is about to execute and allows the Anti-Virus to report back to the process if the sequence of observed behaviors indicates likely malicious activity so the Office application can take appropriate action.\r\n\r\nWhen this feature is enabled, affected VBA projects' runtime performance may be reduced.\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope_l_macroruntimescanscopeenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope_l_macroruntimescanscopeenum_0","displayName":"Disable for all documents","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope_l_macroruntimescanscopeenum_1","displayName":"Enable for low trust documents","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope_l_macroruntimescanscopeenum_2","displayName":"Enable for all documents","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_preventwordandexcelfromloadingmanagedcodeextensions","displayName":"Prevent Word and Excel from loading managed code extensions (User)","description":"This policy setting allows you to prevent Word 2016 and Excel 2016 from loading managed code extensions.\r\n\r\nIf you enable this policy setting, Word 2016 and Excel 2016 will not load managed code extensions.\r\n\r\nIf you disable or do not configure this policy setting, Word 2016 and Excel 2016 will load managed code extensions automatically.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_preventwordandexcelfromloadingmanagedcodeextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_preventwordandexcelfromloadingmanagedcodeextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforpasswordprotected","displayName":"Protect document metadata for password protected files (User)","description":"This policy setting determines whether metadata is encrypted when an Office Open XML file is password protected.\r\n \r\n If you enable this policy setting, Excel 2016, PowerPoint 2016, and Word 2016 encrypt metadata stored in password-protected Office Open XML files and override any configuration changes on users' computers.\r\n \r\n If you disable this policy setting, Office 2016 applications cannot encrypt metadata in password-protected Office Open XML files, which can reduce security.\r\n \r\n If you do not configure this policy setting, when an Office Open XML document is protected with a password and saved, any metadata associated with the document is encrypted along with the rest of the document's contents. If this configuration is changed, potentially sensitive information such as the document author and hyperlink references could be exposed to unauthorized people.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforpasswordprotected_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforpasswordprotected_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforrightsmanaged","displayName":"Protect document metadata for rights managed Office Open XML Files (User)","description":"This policy setting determines whether metadata is encrypted in Office Open XML files that are protected by Information Rights Management (IRM). \r\n\r\nIf you enable this policy setting, Excel, PowerPoint, and Word encrypt metadata stored in rights-managed Office Open XML files and override any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Office 2016 applications cannot encrypt metadata in rights-managed Office Open XML files, which can reduce security. \r\n\r\nIf you do not configure this policy setting, when Information Rights Management (IRM) is used to restrict access to an Office Open XML document, any metadata associated with the document is not encrypted.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforrightsmanaged_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforrightsmanaged_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength","displayName":"Set minimum password length (User)","description":"This setting will define what the minimum length a password should be when the local policy is enforced.\r\n\r\nIf you enable this policy setting, you may specify the minimum password length. The valid range is between 0 and 255.\r\n\r\nIf you disable or do not configure this policy setting, the default minimum password length is 0 characters.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength_l_setminimumpasswordlengthspinid","displayName":"Minimum password length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordhashformatasisocompliant","displayName":"Set password hash format as ISO-compliant (User)","description":"This policy setting allows you create ISO-compliant modification password records.\r\n\r\nIf you enable this policy setting, then passwords created will be ISO-compliant.\r\n\r\nIf you disable or do not configure this policy setting, the default will be ECMA-style records.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordhashformatasisocompliant_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordhashformatasisocompliant_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordrulesdomaintimeout","displayName":"Set password rules domain timeout (User)","description":"This policy setting will define how long in milliseconds to wait when contacting a domain controller before timing out. This requires the \"Set password rules level\" to be enabled and set to \"Local length, local complexity, and domain policy checks.\"\r\n\r\nIf you enable this policy setting, you may set how long in milliseconds to wait when contacting a domain controller before timing out.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 4000 milliseconds is used.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordrulesdomaintimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordrulesdomaintimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordrulesdomaintimeout_l_setpasswordrulesdomaintimeoutspinid","displayName":"in milliseconds (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel","displayName":"Set password rules level (User)","description":"This policy setting allows you to set the password rules level.\r\n\r\nIf you enable this policy setting, you may specify a password rules level:\r\n\r\n- No password checks: There are no complexity checks\r\n- Local length check: Minimum length checks\r\n- Local length and complexity checks: Minimum length checks plus 3 of 4 character groups checks.\r\n- Local length, local complexity, and domain policy checks: All the previous checks plus Windows domain password rules enforced.\r\n\r\nIf you select \"Local length and complexity checks\" or \"Local length, local complexity, and domain policy checks,\" then the password must contain characters from at least three of four character sets: lowercase a-z, uppercase A-Z, digits 0-9, or non-alphabetic characters. When this complexity is enforced, the minimum password length needs to be at least 6, but can be more depending on the value set in the \"Set minimum password length\" policy setting.\r\n\r\nIf you select \"Local length, local complexity, and domain policy checks,\" then Microsoft Office will use the Windows domain policy as well as all the settings \"Local length and complexity checks.\" This allows a custom password filter that is installed for Windows passwords to be used. If you are offline or a domain controller cannot be contacted, then the Windows password settings are not used, and only the \"Local length and complexity checks\" settings are used. If you don’t have a custom password filter, then \"Local length and complexity checks\" saves a trip across the network and would be the best choice.\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the same as if this policy setting were enabled and \"No password checks\" selected.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_l_setpasswordrulesleveldropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_l_setpasswordrulesleveldropid_0","displayName":"No password checks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_l_setpasswordrulesleveldropid_1","displayName":"Local length check","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_l_setpasswordrulesleveldropid_2","displayName":"Local length and complexity checks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_l_setpasswordrulesleveldropid_3","displayName":"Local length, local complexity, and domain policy checks","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_suppresshyperlinkwarnings","displayName":"Suppress hyperlink warnings (User)","description":"This policy setting controls whether Office 2016 applications notify users about unsafe hyperlinks. Links that Office 2016 considers unsafe include links to executable files, TIFF files, and Microsoft Document Imaging (MDI) files. Other unsafe links are those that use protocols considered to be unsafe such as javascript. \r\n\r\nIf you enable this policy setting, unsafe hyperlink warnings are suppressed for all users. \r\n\r\nIf you disable or do not configure this policy setting, hyperlink warnings cannot be suppressed by any means. Office 2016 users will be notified that links are unsafe and must enable them manually to use them.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_suppresshyperlinkwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_suppresshyperlinkwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnofferrorreportingforfilesthatfailfilevalidation","displayName":"Turn off error reporting for files that fail file validation (User)","description":"This policy determines whether error reports and files that fail file validation should be sent using the Watson dialog.\r\n\r\nIf you enable this policy setting, users will not see the Watson dialog. Files that fail file validation will not be sent by the Watson dialog to Microsoft.\r\n\r\nIf you disable or do not configure this policy setting, the Watson dialog to send files that fail validation will show up once every two weeks.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnofferrorreportingforfilesthatfailfilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnofferrorreportingforfilesthatfailfilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnoffpdfencryptionsettingui","displayName":"Turn off PDF encryption setting UI (User)","description":"This policy setting allows you to turn off the PDF encryption setting UI.\r\n\r\nIf you enable this policy setting, the PDF encryption UI is hidden. If your organization has a higher requirement on encryption than what is supported, the recommendation is to enable this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the PDF encryption UI is shown, and users may choose to encrypt the PDF file or not.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnoffpdfencryptionsettingui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnoffpdfencryptionsettingui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_checkthexadesportionsofadigitalsignature","displayName":"Check the XAdES portions of a digital signature (User)","description":"This policy setting lets you specify whether or not Office 2016 checks the XAdES portions of a digital signature, if present, when validating a digital signature for a document. \r\n\r\nIf you enable this policy setting, Office 2016 checks the XAdES portions of a digital signature when validating it.\r\n\r\nIf you disable or do not configure this policy setting, Office 2016 only validates XML-DSig and XAdES-BES portions of a digital signature.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_checkthexadesportionsofadigitalsignature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_checkthexadesportionsofadigitalsignature_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm","displayName":"Configure time stamping hashing algorithm (User)","description":"This policy setting allows you to configure the time stamping hashing algorithm used by Office 2016 applications to validate a message or document.\r\n \r\nIf you enable this policy setting, you can specify any of the following standard hashing algorithm (SHA) functions:\r\n- SHA1\r\n- SHA256\r\n- SHA384\r\n- SHA512\r\n\r\nIf you disable or do not configure this policy setting, SHA1 will be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_l_configuretimestampinghashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_l_configuretimestampinghashingalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_l_configuretimestampinghashingalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_l_configuretimestampinghashingalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_l_configuretimestampinghashingalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_donotallowexpiredcertificateswhenvalidatingsignatures","displayName":"Do not allow expired certificates when validating signatures (User)","description":"This policy setting allows you to configure Office 2016 applications to accept expired digital certificates during verification of digital signatures.\r\n\r\nIf you enable or do not configure this policy setting, Office 2016 applications display digital signatures created with expired certificates as invalid.\r\n\r\nIf you disable this policy setting, Office 2016 applications treat expired certificates as valid.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_donotallowexpiredcertificateswhenvalidatingsignatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_donotallowexpiredcertificateswhenvalidatingsignatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration","displayName":"Requested XAdES level for signature generation (User)","description":"This policy setting allows you to specify a requested or desired XAdES level in creating a digital signature. \r\n\r\nIf you enable this policy setting, you may specify the XAdES level in creating a digital signature. If the desired XAdES level is not reached, the last highest XAdES level reached is used if the level is higher than the minimum XAdES level (XAdeES-BES).\r\n\r\n- No XAdES: XML-DSig - No XAdES\r\n- XAdES-BES: Minimal XAdES (Default)\r\n- XAdES-T: Will fall back to XAdES-BES if minimum XAdES level < XAdes-T\r\n- XAdES-C: Will fall back to XAdES-T if minimum XAdES level < XAdes-C\r\n- XAdES-X: Will fall back to XAdES-C if minimum XAdES level < XAdes-X\r\n- XAdES-X-L: Will fall back to XAdES-X if minimum XAdES level < XAdes-X-L\r\n\r\nIf you disable or do not configure this policy setting, XAdES-BES will be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_0","displayName":"No XAdES","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_1","displayName":"XAdES-BES","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_2","displayName":"XAdES-T","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_3","displayName":"XAdES-C","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_4","displayName":"XAdES-X","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_5","displayName":"XAdES-X-L","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requireocspatsignaturegenerationtime","displayName":"Require OCSP at signature generation time (User)","description":"This policy setting lets you determine whether Office 2016 requires OCSP (Online Certificate Status Protocol) revocation data for all digital certificates in a chain when digital signatures are generated.\r\n\r\nIf you enable this policy setting, Office 2016 requires OCSP revocation data for all certificates in a chain when digital signatures are generated.\r\n\r\nIf you disable or do not configure this policy setting, Office 2016 does not set any restrictions on what type of revocation data is to be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requireocspatsignaturegenerationtime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requireocspatsignaturegenerationtime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm","displayName":"Select digital signature hashing algorithm (User)","description":"This policy setting allows you to configure the hashing algorithm Office 2016 applications use to confirm digital signatures.\r\n\r\nIf you enable this policy setting, you can specify any of the following SHA standard functions:\r\n- SHA1\r\n- SHA256\r\n- SHA384\r\n- SHA512\r\n\r\nIf you disable or do not configure this policy setting, the default value of SHA1 is used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits","displayName":"Configure invalid DSA public key size (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as invalid because of the number of DSA public key bits used in the digital signature.\r\n\r\nIf you enable this policy setting, you can specify the number of bits that Office treats as invalid in a digital signature. For example: 512, 768, etc.\r\n\r\nIf you don’t configure this policy setting, Office won’t treat any digital signatures as invalid because of the number of bits in the public key.\r\n\r\nEnabling this policy causes the minimum DSA public key size to be the next largest option.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm","displayName":"Configure invalid hashing algorithm (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as invalid when it contains specific hash algorithms.\r\n\r\nIf you enable this policy setting, you can specify the weakest hash algorithm that Office treats as invalid. If you enable this policy setting, you can specify any of the following algorithms:\r\n- MD5\r\n- SHA1\r\n- SHA256\r\n- SHA384\r\n\r\nIf you don’t configure this policy setting, Office won’t treat digital signatures as invalid because of the hashing algorithm.\r\n\r\nFor example, if you set MD5 as the invalid hashing algorithm Office treats MD5 signatures as invalid.\r\n ","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_md5","displayName":"MD5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits","displayName":"Configure invalid RSA public key size (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as invalid because of the number of RSA public key bits used in the digital signature.\r\n\r\nIf you enable this policy setting, you can specify the number of bits that Office treats as invalid in a digital signature. For example: 512, 768, etc.\r\n\r\nIf you don’t configure this policy setting, Office won’t treat any digital signatures as invalid because of the number of bits in the public key.\r\n\r\nEnabling this policy causes the minimum RSA public key size to be the next largest option.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid_1536","displayName":"1536","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid_2048","displayName":"2048","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits","displayName":"Configure legacy DSA public key size (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as legacy because of the number of DSA public key bits used in the digital signature.\r\n\r\nIf you enable this policy setting, you can specify the number of bits that Office treats as legacy in a digital signature. For example: 512, 768, etc.\r\n\r\nIf you don’t configure this policy setting, Office won’t treat any digital signatures as legacy because of the number of bits in the public key.\r\n\r\nEnabling this policy causes the minimum DSA public key size to be the next largest option.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm","displayName":"Configure legacy hashing algorithm (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as legacy when it contains specific hash algorithms.\r\n\r\nIf you enable this policy setting, you can specify the weakest hash algorithm that Office treats as legacy. You can specify any of the following algorithms:\r\n- MD5\r\n- SHA1\r\n- SHA256\r\n- SHA384\r\n\r\nIf you don’t configure this policy setting, Office treats digital signatures containing SHA1 or better as valid.\r\n\r\nFor example, if you set SHA256 as the legacy hashing algorithm, Office treats SHA384 signatures as valid.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_md5","displayName":"MD5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits","displayName":"Configure legacy RSA public key size (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as legacy because of the number of RSA public key bits used in the digital signature.\r\n\r\nIf you enable this policy setting, you can specify the number of bits that Office treats as legacy in a digital signature. For example: 512, 768, etc.\r\n\r\nIf you don’t configure this policy setting, Office won’t treat any digital signatures as legacy because of the number of bits in the public key.\r\n\r\nEnabling this policy causes the minimum RSA public key size to be the next largest option.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid_1536","displayName":"1536","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid_2048","displayName":"2048","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits","displayName":"Configure minimum DSA public key size (User)","description":"This policy setting allows you to configure the minimum number of DSA public key bits Office allows to create digital signatures.\r\n \r\nIf you enable this policy setting, you can specify the minimum number of bits that can be used to create a digital signature. For example: 1024, 2048, etc.\r\n \r\nIf you disable or don’t configure this policy setting, Office allows all DSA keys, unless the legacy or invalid DSA policy settings are configured.\r\n\r\n If the legacy or invalid DSA public key bits policy settings are configured, then the default for this setting will be the next larger value. For example, if the number of DSA public key bits is set to 768, then this setting would default to 1024.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits","displayName":"Configure minimum RSA public key size (User)","description":"This policy setting allows you to configure the minimum number of RSA public key bits Office allows to create digital signatures.\r\n \r\nIf you enable this policy setting, you can specify the minimum number of bits that can be used to create a digital signature. For example: 1024, 2048, etc.\r\n \r\nIf you disable or don’t configure this policy setting, Office allows all RSA keys, unless the legacy or invalid RSA policy settings are configured.\r\n\r\n If the legacy or invalid RSA public key bits policy settings are configured, then the default for this setting will be the next larger value. For example, if the number of RSA public key bits is set to 768, then this setting would default to 1024.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_1536","displayName":"1536","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_2048","displayName":"2048","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_4096","displayName":"4096","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel","displayName":"Set signature verification level (User)","description":"This policy setting allows you to set the verification level used by Office 2016 applications when validating a digital signature.\r\n\r\nNote: Enabling this policy setting is not recommended for subscription versions of Office, such as Office 365 ProPlus, because it will use the legacy registry based rules settings (described below) instead of basing the verification level on the Office version that signed the file.\r\n\r\nIf you enable this policy setting, you can set the verification level to any of the following:\r\n\r\n- No rules: Office 2016 digital signature rules are disabled.\r\n\r\n- Office 2007 rules: Office 2016 uses the Office 2007 digital signature rules.\r\n\r\n- Office 2010 rules: Office 2016 uses the Office 2010 digital signature rules.\r\n\r\n- Office 2013 rules: Office 2016 uses the Office 2013 digital signature rules.\r\n\r\nIf you disable or do not configure this policy setting, subscription versions of Office 2016 use the rules of the Office version that was used to sign the document to validate the digital signature.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_l_setsignatureverificationleveldropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_l_setsignatureverificationleveldropid_0","displayName":"No rules","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_l_setsignatureverificationleveldropid_1","displayName":"Office 2007 rules","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_l_setsignatureverificationleveldropid_2","displayName":"Office 2010 rules","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_l_setsignatureverificationleveldropid_3","displayName":"Office 2013 rules","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_settimestampservertimeout","displayName":"Set timestamp server timeout (User)","description":"This policy setting allows you to configure the number of seconds Office 2016 applications wait for a response from the time stamping server before timing out. If timeout occurs, the Office 2016 application will not open the message or document.\r\n\r\nIf you enable this policy setting, the number of seconds you specify will be the length of time Office 2016 will wait for the time stamping server to return a result.\r\n\r\nIf you disable or do not configure this policy setting, the default of 5 seconds will be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_settimestampservertimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_settimestampservertimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_settimestampservertimeout_l_settimestampservertimeoutspinid","displayName":"In seconds (User)","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter","displayName":"Specify filtering for certificate issuers (User)","description":"This policy setting allows you to configure Office to only allow certificates from a specific issuer when creating a digital signature.\r\n \r\nIf you enable this policy setting, Office only displays certificates that contain the string you set in the policy. This setting is case-sensitive.\r\n\r\nFor example, a setting of \"MyCA\" would match an issuer of \"MyCA 1\"and \"MyCA 2\", but not \"MYCA 3\".\r\n\r\nIf you disable or don’t configure this setting, then signing certificates from any issuer can be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter_l_specifyissuerfilterid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration","displayName":"Specify minimum XAdES level for digital signature generation (User)","description":"This policy setting lets you specify a minimum XAdES level that Office 2016 applications must reach in order to create an XAdES digital signature. If unable to reach the minimum XAdESLevel, the Office application fails to create the signature. \r\n\r\nIf you enable this policy setting, you can set the following minimum XAdES levels that must be met by the Office application before creating the digital signature.\r\n\r\n- No minimum level\r\n- XAdES-BES: Must create at least XAdES-BES or fail\r\n- XAdES-T: Must create at least XAdES-T (timestamp) or fail. \r\n- XAdES-C: Must create at least XAdES-C (certificate and revocation references) or fail. \r\n- XAdES-X: Must create at least XAdES-X (timestamp -C) or fail. \r\n- XAdES-X-L: Must create at least XAdES-X-L (store certificate and revocation values) or fail.\r\n\r\nIf you disable or do not configure this policy setting, Office 2016 does not require a minimum XAdES level and creates the most advanced XAdES signature possible, up to the level specified in the policy setting","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_0","displayName":"No minimum level","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_1","displayName":"XAdES-BES","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_2","displayName":"XAdES-T","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_3","displayName":"XAdES-C","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_4","displayName":"XAdES-X","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_5","displayName":"XAdES-X-L","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifytimestampservername","displayName":"Specify timestamp server name (User)","description":"This policy setting allows you to set the HTTP URL for the timestamp server used by Office 2016 applications in the process of validating messages or documents.\r\n\r\nIf you enable this policy setting, you must provide a valid HTTP URL address for the timestamp server. \r\n\r\nIf you do disable or not configure this policy setting, a timestamp server will not be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifytimestampservername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifytimestampservername_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifytimestampservername_l_specifytimestampservernameid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_suppressnocertdialog","displayName":"Display alternative certificate providers (User)","description":"This policy setting allows you to configure whether Office displays a link to get a certificate from a Microsoft partner when there are no usable signing certificates.\r\n\r\nIf you enable this policy setting, the link won’t be displayed.\r\n\r\nIf you disable or don’t configure this policy setting, the link is displayed.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_suppressnocertdialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_suppressnocertdialog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey01","displayName":"Escrow Key #1 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey01_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey02","displayName":"Escrow Key #2 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey02_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey03","displayName":"Escrow Key #3 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey03_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey04","displayName":"Escrow Key #4 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey04_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey05","displayName":"Escrow Key #5 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey05_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06","displayName":"Escrow Key #6 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey07","displayName":"Escrow Key #7 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey07_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey08","displayName":"Escrow Key #8 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey08_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey09","displayName":"Escrow Key #9 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey09_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey10","displayName":"Escrow Key #10 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey10_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11","displayName":"Escrow Key #11 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12","displayName":"Escrow Key #12 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey13","displayName":"Escrow Key #13 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey13_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey14","displayName":"Escrow Key #14 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey14_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15","displayName":"Escrow Key #15 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16","displayName":"Escrow Key #16 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17","displayName":"Escrow Key #17 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey18","displayName":"Escrow Key #18 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey18_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey19","displayName":"Escrow Key #19 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey19_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey20","displayName":"Escrow Key #20 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey20_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_allowmixofpolicyanduserlocations","displayName":"Allow mix of policy and user locations (User)","description":"This policy setting controls whether trusted locations can be defined by users, the Office Customization Tool (OCT), and Group Policy, or if they must be defined by Group Policy alone.\r\n \r\nIf you enable this policy setting, users can specify any location as a trusted location, and a computer can have a combination of user-created, OCT-created, and Group Policy-created trusted locations.\r\n \r\nIf you disable this policy setting, all trusted locations that are not created by Group Policy are disabled and users cannot create new trusted locations in the Trust Center.\r\n \r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled.\r\n \r\nNote - InfoPath 2016 and Outlook 2016 do not recognize trusted locations, and therefore are unaffected by this policy setting.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_allowmixofpolicyanduserlocations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_allowmixofpolicyanduserlocations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos","displayName":"Set the minimum operating system for verifying agile VBA signatures (User)","description":"This policy setting allows you to set the minimum operating system (OS) on which agile VBA signatures produced by Office can be verified. This ensures the hashing algorithm used to sign is compatible with the specified OS and later versions. \r\n\r\nIf you enable this policy setting, Office uses the OS you specify as the minimum OS to verify agile VBA signatures.\r\n\r\nIf you disable or do not configure this policy setting, Office uses Windows 7 as the minimum OS to verify agile VBA signatures.\r\n\r\nIf you specify a minimum OS version that is higher than the highest OS supported by Office, Office uses the highest supported OS to verify agile VBA signatures.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_0","displayName":"Windows XP","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_1","displayName":"Windows Vista","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_2","displayName":"Windows 7","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_3","displayName":"Windows 8","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_l_allowsubfolders245","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_l_allowsubfolders245_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_l_allowsubfolders245_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_l_datecolon243","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_l_descriptioncolon244","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_l_pathcolon242","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_allowsubfolders249","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_allowsubfolders249_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_allowsubfolders249_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_datecolon247","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_descriptioncolon248","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_pathcolon246","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_allowsubfolders253","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_allowsubfolders253_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_allowsubfolders253_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_datecolon251","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_descriptioncolon252","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_pathcolon250","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_allowsubfolders257","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_allowsubfolders257_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_allowsubfolders257_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_datecolon255","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_descriptioncolon256","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_pathcolon254","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_allowsubfolders261","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_allowsubfolders261_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_allowsubfolders261_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_datecolon259","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_descriptioncolon260","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_pathcolon258","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_allowsubfolders265","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_allowsubfolders265_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_allowsubfolders265_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_datecolon263","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_descriptioncolon264","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_pathcolon262","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_l_allowsubfolders269","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_l_allowsubfolders269_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_l_allowsubfolders269_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_l_datecolon267","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_l_descriptioncolon268","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_l_pathcolon266","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_l_allowsubfolders273","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_l_allowsubfolders273_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_l_allowsubfolders273_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_l_datecolon271","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_l_descriptioncolon272","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_l_pathcolon270","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_allowsubfolders277","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_allowsubfolders277_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_allowsubfolders277_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_datecolon275","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_descriptioncolon276","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_pathcolon274","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11","displayName":"Trusted Location #11 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_l_allowsubfolders281","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_l_allowsubfolders281_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_l_allowsubfolders281_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_l_datecolon279","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_l_descriptioncolon280","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_l_pathcolon278","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_l_allowsubfolders285","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_l_allowsubfolders285_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_l_allowsubfolders285_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_l_datecolon283","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_l_descriptioncolon284","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_l_pathcolon282","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_l_allowsubfolders289","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_l_allowsubfolders289_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_l_allowsubfolders289_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_l_datecolon287","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_l_descriptioncolon288","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_l_pathcolon286","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_allowsubfolders293","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_allowsubfolders293_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_allowsubfolders293_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_datecolon291","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_descriptioncolon292","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_pathcolon290","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_allowsubfolders297","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_allowsubfolders297_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_allowsubfolders297_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_datecolon295","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_descriptioncolon296","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_pathcolon294","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_allowsubfolders301","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_allowsubfolders301_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_allowsubfolders301_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_datecolon299","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_descriptioncolon300","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_pathcolon298","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_allowsubfolders305","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_allowsubfolders305_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_allowsubfolders305_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_datecolon303","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_descriptioncolon304","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_pathcolon302","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_allowsubfolders309","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_allowsubfolders309_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_allowsubfolders309_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_datecolon307","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_descriptioncolon308","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_pathcolon306","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_allowsubfolders313","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_allowsubfolders313_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_allowsubfolders313_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_datecolon311","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_descriptioncolon312","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_pathcolon310","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_allowsubfolders317","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_allowsubfolders317_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_allowsubfolders317_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_datecolon315","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_descriptioncolon316","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_pathcolon314","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustlegacysignature","displayName":"Trust legacy VBA signatures (User)","description":"This policy setting allows you to control how Office loads and verifies legacy Visual Basic for Applications (VBA) signatures.\r\n\r\nIf you enable or do not configure this policy setting, Office applications can load and verify legacy VBA signatures.\r\n\r\nIf you disable this policy setting, Office applications can’t load or verify legacy VBA signatures. They can only load and verify agile VBA signatures.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustlegacysignature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustlegacysignature_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01","displayName":"Unsafe Location #1 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_l_allowsubfolders01","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_l_allowsubfolders01_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_l_allowsubfolders01_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_l_pathcolon01","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02","displayName":"Unsafe Location #2 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_allowsubfolders02","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_allowsubfolders02_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_allowsubfolders02_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_pathcolon02","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03","displayName":"Unsafe Location #3 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03_l_allowsubfolders03","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03_l_allowsubfolders03_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03_l_allowsubfolders03_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03_l_pathcolon03","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04","displayName":"Unsafe Location #4 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_l_allowsubfolders04","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_l_allowsubfolders04_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_l_allowsubfolders04_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_l_pathcolon04","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05","displayName":"Unsafe Location #5 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_l_allowsubfolders05","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_l_allowsubfolders05_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_l_allowsubfolders05_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_l_pathcolon05","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06","displayName":"Unsafe Location #6 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_allowsubfolders06","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_allowsubfolders06_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_allowsubfolders06_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_pathcolon06","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07","displayName":"Unsafe Location #7 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07_l_allowsubfolders07","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07_l_allowsubfolders07_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07_l_allowsubfolders07_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07_l_pathcolon07","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08","displayName":"Unsafe Location #8 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_l_allowsubfolders08","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_l_allowsubfolders08_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_l_allowsubfolders08_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_l_pathcolon08","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09","displayName":"Unsafe Location #9 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_l_allowsubfolders09","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_l_allowsubfolders09_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_l_allowsubfolders09_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_l_pathcolon09","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10","displayName":"Unsafe Location #10 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_allowsubfolders10","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_allowsubfolders10_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_allowsubfolders10_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_pathcolon10","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11","displayName":"Unsafe Location #11 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_l_allowsubfolders11","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_l_allowsubfolders11_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_l_allowsubfolders11_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_l_pathcolon11","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12","displayName":"Unsafe Location #12 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12_l_allowsubfolders12","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12_l_allowsubfolders12_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12_l_allowsubfolders12_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12_l_pathcolon12","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13","displayName":"Unsafe Location #13 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_l_allowsubfolders13","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_l_allowsubfolders13_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_l_allowsubfolders13_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_l_pathcolon13","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14","displayName":"Unsafe Location #14 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_allowsubfolders14","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_allowsubfolders14_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_allowsubfolders14_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_pathcolon14","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15","displayName":"Unsafe Location #15 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_l_allowsubfolders15","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_l_allowsubfolders15_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_l_allowsubfolders15_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_l_pathcolon15","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16","displayName":"Unsafe Location #16 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_l_allowsubfolders16","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_l_allowsubfolders16_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_l_allowsubfolders16_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_l_pathcolon16","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17","displayName":"Unsafe Location #17 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_l_allowsubfolders17","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_l_allowsubfolders17_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_l_allowsubfolders17_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_l_pathcolon17","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18","displayName":"Unsafe Location #18 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_allowsubfolders18","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_allowsubfolders18_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_allowsubfolders18_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_pathcolon18","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19","displayName":"Unsafe Location #19 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19_l_allowsubfolders19","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19_l_allowsubfolders19_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19_l_allowsubfolders19_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19_l_pathcolon19","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20","displayName":"Unsafe Location #20 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20_l_allowsubfolders20","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20_l_allowsubfolders20_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20_l_allowsubfolders20_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20_l_pathcolon20","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowunsecureapps","displayName":"Allow Unsecure web add-ins and Catalogs (User)","description":"This policy setting allows users to run unsecure web add-in, which are add-ins that have web page or catalog locations that are not SSL-secured (https://), and are not in users' Internet zones.\r\n\r\nIf you enable this policy setting, users can run unsecure apps. To enable specific unsecure web add-ins, you must also configure the Trusted Web add-in Catalog policy settings to trust the catalogs that contains those Add-ins.\r\n\r\nIf you disable or do not configure this policy setting, unsecure web add-ins are not allowed.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowunsecureapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowunsecureapps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultfilesharecatalog","displayName":"Default Shared Folder Location (User)","description":"This policy setting sets allows you to set the location of the Shared Folder that is designated as Default.\r\n\r\nIf you enable this policy setting, you can set the URL for the Shared Folder from which users can insert web add-ins into their Office documents.\r\n\r\nIf you disable this policy setting, users cannot insert web add-ins from a Shared Folder.\r\n\r\nIf you do not configure this policy setting, or any other policy settings in the Trusted Catalogs folder, users can set their own Default Shared Folder location.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultfilesharecatalog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultfilesharecatalog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultfilesharecatalog_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultspcatalog","displayName":"Default SharePoint Catalog Location (User)","description":"This policy setting allows you to set the location of the SharePoint Catalog that is designated as Default. The web add-ins contained in the Default Catalog can be inserted into Office documents by users.\r\n\r\nIf you enable this policy setting, you can set the URL for the SharePoint Catalog from which users can insert apps into their Office documents.\r\n\r\nIf you disable this policy setting, users cannot insert web add-ins from a SharePoint catalog.\r\n\r\nIf you do not configure this policy setting or set any other policy settings in the Trusted Catalogs folder, users can set their own Default SharePoint Catalog location.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultspcatalog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultspcatalog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultspcatalog_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableallcatalogs","displayName":"Block Web Add-ins (User)","description":"This policy setting allows you to prevent users from using web add-ins.\r\n\r\nIf you enable this policy setting, web add-ins are blocked and all other policy settings in the Trusted Catalogs folder are ignored.\r\n\r\nIf you disable or do not configure this policy setting, apps are allowed. Other policy settings in the Trusted Catalogs folder determine which specific app sources are allowed.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableallcatalogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableallcatalogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableofficestore","displayName":"Block the Office Store (User)","description":"This policy setting allows you to prevent users from using or inserting web add-ins that come from the Office Store.\r\n\r\nIf you enable this policy setting, apps from the Office Store are blocked.\r\n\r\nIf you disable or do not configure this policy setting, apps from the Office Store are allowed, unless the \"Block Apps for Office\" policy setting is enabled.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableofficestore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableofficestore_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog01","displayName":"Trusted Catalog Location #1 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog01_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog02","displayName":"Trusted Catalog Location #2 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog02_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog03","displayName":"Trusted Catalog Location #3 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog03_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04","displayName":"Trusted Catalog Location #4 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05","displayName":"Trusted Catalog Location #5 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog06","displayName":"Trusted Catalog Location #6 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog06_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog07","displayName":"Trusted Catalog Location #7 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog07_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog08","displayName":"Trusted Catalog Location #8 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog08_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog09","displayName":"Trusted Catalog Location #9 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog09_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog10","displayName":"Trusted Catalog Location #10 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog10_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_adattributecontaingpersonalsiteurl","displayName":"AD attribute containing Personal Site URL (User)","description":"The Office client updates the User object in the Active Directory with the URL of the user's personal site. Please enter the attribute of the user object which Office should update. The default is \"wwwHomePage\".","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_adattributecontaingpersonalsiteurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_adattributecontaingpersonalsiteurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_adattributecontaingpersonalsiteurl_l_empty424","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_allowfilesynchronizationviasoaponlyondomainnetworks","displayName":"Allow file synchronization via SOAP over HTTP only on domain networks (User)","description":"This policy setting controls file synchronization via SOAP over HTTP.\r\n\r\nIf you enable this policy setting, file synchronization via SOAP over HTTP is allowed only on domain networks. \r\n\r\nIf you disable or do not configure this policy setting, file synchronization via SOAP over HTTP functions on all networks.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_allowfilesynchronizationviasoaponlyondomainnetworks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_allowfilesynchronizationviasoaponlyondomainnetworks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod","displayName":"Catalog Refresh Period (User)","description":"This policy setting sets the apps for Office catalog refresh period, which is the amount of time (hours) Office waits between refreshes of the app catalogs. Refreshing the catalogs detects whether entitlements to any apps have expired.\r\n\r\nIf you enable this policy setting, set the number of hours to determine the length of the refresh period. Choose a value between 0 (always refresh) and 10,000.\r\n\r\nIf you disable or do not configure this policy setting, the catalog refresh period is set to the default 72 hours.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod_l_empty601","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_disabletheofficeclientfrompolling","displayName":"Disable the Office client from polling the SharePoint Server for published links (User)","description":"This policy setting controls whether Office 2016 applications can poll Office servers to retrieve lists of published links. \r\n\r\nIf you enable this policy setting, Office 2016 applications cannot poll an Office server for published links. \r\n\r\nIf you disable or do not configure this policy setting, users of Office 2016 applications can see and use links to Microsoft SharePoint Server sites from those applications. You can configure published links to Office applications during initial deployment, and can add or change links as part of regular operations. These links appear on the My SharePoint Sites tab of the Open, Save, and Save As dialog boxes when opening and saving documents from these applications. Links can be targeted so that they only appear to users who are members of particular audiences. \r\n\r\nNote - This policy setting applies to Microsoft SharePoint Server specifically. It does not apply to Microsoft SharePoint Foundation.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_disabletheofficeclientfrompolling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_disabletheofficeclientfrompolling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_disabletheuserfromsettingthepersonalsiteurl","displayName":"Disable the user from setting the Personal Site URL (User)","description":"This setting will disable the Office client applications from setting the personal site URL in the Active Directory.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_disabletheuserfromsettingthepersonalsiteurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_disabletheuserfromsettingthepersonalsiteurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_foldernameforpublishedlinks","displayName":"Folder name for Published Links (User)","description":"The folder name used to store network folder shortcuts published from SharePoint Server. \"My SharePoints\" (localized) by default.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_foldernameforpublishedlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_foldernameforpublishedlinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_foldernameforpublishedlinks_l_empty427","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload","displayName":"Frequency for polling the server to download published links (User)","description":"Minimum time to wait (in seconds) before polling SharePoint Server to download published links.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload_l_empty426","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_lengthadattributecontainingpersonalsiteurl","displayName":"Length AD Attribute containing Personal Site URL (User)","description":"The Office client updates the User object in the Active Directory with the URL of the user's personal site. Please enter the length of URL that the attribute can accept. The default is 2048.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_lengthadattributecontainingpersonalsiteurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_lengthadattributecontainingpersonalsiteurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_lengthadattributecontainingpersonalsiteurl_l_empty425","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_turnonfilesynchronizationviasoapoverhttp","displayName":"Turn on file synchronization via SOAP over HTTP (User)","description":"This policy setting controls file synchronization via SOAP over HTTP.\r\n\r\nIf you enable or do not configure this policy setting, file synchronization via SOAP over HTTP is turned on. Turning file synchronization on here will still allow application-specific file synchronization to be turned off.\r\n\r\nIf you disable this policy setting this policy setting, file synchronization via SOAP over HTTP is turned off. You will turn off file synchronization via SOAP over HTTP for other applications even if the application-specific file synchronization is turned on.\r\n\r\nImportant: If you disable this policy setting, which will turn off file synchronization via SOAP over HTTP, you will also prevent co-authoring for Word and PowerPoint, and it will adversely affect the behavior of SharePoint Workspaces.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_turnonfilesynchronizationviasoapoverhttp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_turnonfilesynchronizationviasoapoverhttp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_enablecolleagueimportoutlookaddintowork","displayName":"Enable Colleague Import Outlook Add-in to work with Microsoft SharePoint Server (User)","description":"This setting will enable the Colleague Import Outlook Add-in.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_enablecolleagueimportoutlookaddintowork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_enablecolleagueimportoutlookaddintowork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofdaystoscanfromtodaytodetermine","displayName":"Maximum number of days to scan from today to determine the user's colleagues for recommendation (User)","description":"The maximum number of days to scan the Outlook mailbox to determine the colleagues the user has. The larger the number, the more accurate the recommendation. The smaller the number, the faster the recommendations are generated.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofdaystoscanfromtodaytodetermine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofdaystoscanfromtodaytodetermine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofdaystoscanfromtodaytodetermine_l_empty429","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofitemstoscanfromtoday","displayName":"Maximum number of items to scan from today to determine the user's colleagues for recommendation (User)","description":"The maximum number of items to scan in the Outlook mailbox to determine the colleagues the user has. The larger the number, the more accurate the recommendation. The smaller the number, the faster the recommendations are generated.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofitemstoscanfromtoday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofitemstoscanfromtoday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofitemstoscanfromtoday_l_empty428","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofreceipientsinanoutlookitem","displayName":"Maximum number of recipients in an Outlook item to scan to determine the user's colleagues for recommendation (User)","description":"The maximum number of recipients in an Outlook item to scan to determine the colleagues the user has. The larger the number, the more accurate the recommendation. The smaller the number, the faster the recommendations are generated.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofreceipientsinanoutlookitem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofreceipientsinanoutlookitem_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofreceipientsinanoutlookitem_l_empty430","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows","displayName":"Maximum number of rows fetched per request while populating a lookup in the SharePoint list control (User)","description":"The maximum number of rows fetched per request while populating a lookup in the SharePoint list control. Based on a standalone server's recommended hardware configuration a good default would be about 5000. The limit helps improve the performance of the SharePoint list control and is a defense in depth measure to prevent loading the server.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_100","displayName":"100","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_450","displayName":"450","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_5000","displayName":"5000","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimebeforestartingcolleague","displayName":"Minimum time before starting Colleague recommendation scan (User)","description":"The minimum idle time (in milliseconds) to wait before the Colleague Import Outlook add-in begins to scan the mailbox.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimebeforestartingcolleague_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimebeforestartingcolleague_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimebeforestartingcolleague_l_empty431","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimetowaitbeforerescanning","displayName":"Minimum time to wait before rescanning the Outlook mailbox for new colleague recommendations (User)","description":"The minimum time (in hours) to wait before rescanning the Outlook mailbox for new colleague recommendations.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimetowaitbeforerescanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimetowaitbeforerescanning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimetowaitbeforerescanning_l_empty432","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services_l_disableofficeuserroamingsettings","displayName":"Disable Roaming Office User Settings (User)","description":"Microsoft Office includes the ability to roam settings for specific Office features amongst devices by storing this data in the cloud. This data includes user activity such as the list of most recently used documents as well as user preferences such as the Office theme. This policy setting controls whether this data is allowed to be stored in the cloud. \r\n\r\nIf you enable this policy setting, roaming settings are only stored locally and not synchronized to the Microsoft Office roaming settings web service. \r\n\r\nIf you disable or do not configure this policy setting, roaming settings are synchronized with the Microsoft Office roaming settings web service and users can access their data from other devices. \r\n\r\nExisting data in the cloud is not affected by this policy.","helpText":"","infoUrls":[],"categoryId":"478ed057-8ee7-4dd2-8276-06dad8f85397","categoryName":"Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services_l_disableofficeuserroamingsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services_l_disableofficeuserroamingsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disablefaxoverinternetfeature","displayName":"Disable Internet Fax feature (User)","description":"This policy setting determines whether users can access the Internet Fax feature in Office 2016 applications. \r\n\r\nIf you enable this policy setting, Office 2016 users cannot send Internet faxes, and the Internet Fax menu item is removed from the Send sub-menu of the Microsoft Office menu. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 users can use the Internet Fax feature.","helpText":"","infoUrls":[],"categoryId":"a5607145-2bd3-4473-a8ee-d7fa5c2f2675","categoryName":"Fax","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disablefaxoverinternetfeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disablefaxoverinternetfeature_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disallowcustomcoversheet","displayName":"Disallow custom cover sheet (User)","description":"Disables the custom fax cover sheet by displaying the message, \"This option has been disabled by administrative policy\" when the user clicks the Custom button in the Fax Service pane of the email message.","helpText":"","infoUrls":[],"categoryId":"a5607145-2bd3-4473-a8ee-d7fa5c2f2675","categoryName":"Fax","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disallowcustomcoversheet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disallowcustomcoversheet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_enterprisetemplatespath","displayName":"Enterprise templates path (User)","description":"Specifies the location of enterprise templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_enterprisetemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_enterprisetemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_enterprisetemplatespath_l_enterprisetemplatespath329","displayName":"Enterprise templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles","displayName":"Set User path for the label page size update files (User)","description":"This policy setting allows you to override the User path for the label page size update files. \r\n\r\nIf you enable this policy setting, you may enter the path to the PSX update files and override the User path.\r\n\r\nIf you disable or do not configure this policy setting, the User path for the label page size update files remains valid.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles_l_setuserpathforthelabelpagesizeupdatefilesid","displayName":"User path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles","displayName":"Set Workgroup path for label page size update files (User)","description":"This policy setting allows you to specify the Workgroup path for the label page size update files. This is useful if the organization has a centralized template depot. \r\n\r\nIf you enable this policy setting, you may enter the path to the PSX update files.\r\n\r\nIf you disable or do not configure this policy setting, there is no Workgroup path for the shared label templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles_l_setworkgrouppathforlabelpagesizeupdatefilesid","displayName":"Workgroup path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_sharedthemespath","displayName":"Shared themes path (User)","description":"Specifies the location of workgroup themes.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_sharedthemespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_sharedthemespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_sharedthemespath_l_sharedthemespath330","displayName":"Shared themes path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_userqueriespath","displayName":"User queries path (User)","description":"Specifies the location of data sources for database queries.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_userqueriespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_userqueriespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_userqueriespath_l_userqueriespath331","displayName":"User queries path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath","displayName":"User templates path (User)","description":"Specifies the location of user templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath_l_usertemplatespath328","displayName":"User templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage","displayName":"Web Query dialog box home page (User)","description":"Specifies the default location of the home page for Web queries.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage_l_webquerydialoghomepage333","displayName":"Web Query dialog box home page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgroupbuildingblockspath","displayName":"Workgroup building blocks path (User)","description":"Specifies the location of workgroup building block templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgroupbuildingblockspath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgroupbuildingblockspath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgroupbuildingblockspath_l_path2","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgrouptemplatespath","displayName":"Workgroup templates path (User)","description":"Specifies the location of workgroup templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgrouptemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgrouptemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgrouptemplatespath_l_workgrouptemplatespath329","displayName":"Workgroup templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_ekufiltering","displayName":"EKU filtering (User)","description":"This policy setting allows you to specify enhanced key usage (EKU) values to be used in filtering a list of digital certificates for signing Excel, PowerPoint, and Word documents. An enhanced key usage (EKU) extension to a digital certificate is a collection of one or more values that indicate how a certificate should be used. Examples of EKU values include Smart Card Logon and Client Authentication. EKU filtering allows you to filter the list of installed certificates that can be used for digitally signing documents. The filtered list will appear when users attempt to select a certificate for digitally signing a document. \r\n\r\nIf you enable this policy setting, you can specify a list of object identifiers (OIDs) that represent acceptable EKUs for certificates used in conjunction with signed documents. For example, for a certificate with the Encrypting File System (1.3.6.1.4.1.311.10.3.4) identifier, the OID is 1.3.6.1.4.1.311.10.3.4. This list of appropriate OIDs will vary according to the specific certificates that the organization uses. For a list of object IDs associated with Microsoft cryptography, see Microsoft Knowledge Base article 287547, \"Object IDs associated with Microsoft cryptography\" at http://officeredir.microsoft.com/r/rlidGPOIDAndCrypt2O14?clid=1033. \r\n\r\nIf you disable or do not configure this policy setting, EKU filtering is not available.","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_ekufiltering_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_ekufiltering_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_ekufiltering_l_empty412","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_legacyformatsignatires","displayName":"Legacy format signatures (User)","description":"This policy setting controls whether users can apply binary format digital signatures to Office 97-2003 documents. \r\n\r\nIf you enable this policy setting, Office 2016 applications use the Office 2003 binary format to apply digital signatures to Office 97-2003 binary documents so that they will be recognized by the Office 2003 release and earlier applications. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 applications use the XML--based XMLDSIG format to attach digital signatures to documents, including Office 97-2003 binary documents. XMLDSIG signatures are not recognized by Office 2003 applications or previous versions. If an Office 2003 user opens an Excel, PowerPoint, or Word binary document with an XMLDSIG signature attached, the signature will be lost.","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_legacyformatsignatires_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_legacyformatsignatires_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_setdefaultimagedirctory","displayName":"Set default image directory (User)","description":"Sets the default directory for signing images (defaults to your pictures otherwise).","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_setdefaultimagedirctory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_setdefaultimagedirctory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_setdefaultimagedirctory_l_setdefaultimagedirctorypart","displayName":"Last-used signature image directory: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressexternalsigningservicesmenuitems","displayName":"Suppress external signature services menu item (User)","description":"This policy setting controls whether Outlook displays the \"Add Signature Services\" menu item. \r\n\r\nIf you enable this policy setting, Outlook does not display the \"Add Signature Services\" menu item on the Signature Line drop-down menu. \r\n\r\nIf you disable or do not configure this policy setting, users can select \"Add Signature Services\" (from the Signature Line drop-down menu on the Insert tab of the Ribbon in Excel, PowerPoint, and Word) to see a list of signature service providers on Office.com.","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressexternalsigningservicesmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressexternalsigningservicesmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders","displayName":"Suppress Office Signing Providers (User)","description":"This policy setting controls whether users can apply a default Microsoft Office signature line to Word documents and Excel workbooks. Digital signatures provide assurances of authenticity, integrity, and non-repudiation to electronic documents. In Excel and Word, users can add visible representations of their signatures to a document at the same time that they add digital signatures. The ability to capture digital signatures by using signature lines in Office 2016 documents makes it possible for organizations to use paperless signing processes for documents such as contracts or other agreements. \r\n\r\nIf you enable this policy setting, you can choose from four options for enabling the default Microsoft Office 2016 signature lines: \r\n\r\n- Enable Western and East Asian - Both Microsoft Office Signature Line and Stamp Signature Line are available from the Signature Line drop-down menu on the Insert tab of the Ribbon. \r\n\r\n- Suppress default Western - Users cannot add the Microsoft Office Signature Line to documents. \r\n\r\n- Suppress default East Asian - Users cannot add the Stamp Signature Line to documents. \r\n\r\n- Suppress both Western and East Asian. Neither of the default signature lines is available. This only takes affect if there is at least one other valid third party signature provider installed. \r\n\r\nIf you disable or do not configure this policy setting, Excel and Word include support for two kinds of signature lines, called Microsoft Office Signature Line and Stamp Signature Lines. The choice(s) available to the user vary according to the editing language(s) that are configured for the application at installation. \r\n\r\n- Microsoft Office Signature Line displays the letter \"X\" followed by a horizontal line, a familiar convention for handwritten signature lines. \r\n\r\n- Stamp Signature Line is only available to users of the Simplified Chinese, Traditional Chinese, Japanese, or Korean language versions of Office 2016, or to users who have installed Office 2016 Multi-Language Pack for one of these languages. This signature line displays a square, a convention in countries where rubber identity stamps (called hanko in Japan and South Korea) are used to sign documents. \r\n\r\nBoth kinds of signature lines allow signers to specify their name, title, and e-mail address. If neither kind of signature line is appropriate, third-party signature products can be added to Office applications to serve different needs. \r\n\r\nIf the correct signature line is not available for users to choose, they might be prevented from digitally signing documents. \r\n\r\nNote - This policy setting only applies to visible signature lines in Excel workbooks and Word documents. It does not affect the ability of users to add invisible digital signatures to Excel workbooks, PowerPoint presentations, and Word documents.","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_l_empty413","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_l_empty413_0","displayName":"Enable Western and East Asian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_l_empty413_1","displayName":"Suppress default Western","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_l_empty413_2","displayName":"Suppress default East Asian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_l_empty413_3","displayName":"Suppress both Western and East Asian","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_smartdocumentswordexcel_l_completelydisablethesmartdocumentsfeatureinwordandexcel","displayName":"Completely disable the Smart Documents feature in Word and Excel (User)","description":"This policy setting allows you to configure the ability to run smart documents in Word or Excel. However, since XML expansion packs can include many types of solutions in addition to smart document solutions, this policy setting cannot be used to disable the ability to run XML expansion packs.\r\n\r\nIf you enable this policy setting, smart document solutions will not run. To fully manage the Smart Documents feature, this policy and the \"Disable Smart Document's use of manifests\" policy should both be configured.\r\n\r\nIf you disable or do not configure this policy setting, smart document solutions will run.","helpText":"","infoUrls":[],"categoryId":"449201b6-5002-42d1-85ed-d288fb6552da","categoryName":"Smart Documents (Word, Excel)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_smartdocumentswordexcel_l_completelydisablethesmartdocumentsfeatureinwordandexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_smartdocumentswordexcel_l_completelydisablethesmartdocumentsfeatureinwordandexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_smartdocumentswordexcel_l_disablesmartdocumentsuseofmanifests","displayName":"Disable Smart Document's use of manifests (User)","description":"This policy setting controls whether Office 2016 applications can load an XML expansion pack manifest file with a Smart Document. \r\n\r\nAn XML expansion pack is the group of files that constitutes a Smart Document in Excel and Word. You package one or more components that provide the logic needed for a Smart Document by using an XML expansion pack. These components can include any type of file, including XML schemas, Extensible Stylesheet Language Transforms (XSLTs), dynamic-link libraries (DLLs), and image files, as well as additional XML files, HTML files, Word files, Excel files, and text files. \r\n\r\nThe key component to building an XML expansion pack is creating an XML expansion pack manifest file. By creating this file, you specify the locations of all files that make up the XML expansion pack, as well as information that instructs Office 2016 how to set up the files for your Smart Document. The XML expansion pack can also contain information about how to set up some files, such as how to install and register a COM object required by the XML expansion pack. \r\n\r\nIf you enable this policy setting, Office 2016 applications cannot load XML expansion packs with Smart Documents. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 applications can load an XML expansion pack manifest file with a Smart Document.","helpText":"","infoUrls":[],"categoryId":"449201b6-5002-42d1-85ed-d288fb6552da","categoryName":"Smart Documents (Word, Excel)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_smartdocumentswordexcel_l_disablesmartdocumentsuseofmanifests_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_smartdocumentswordexcel_l_disablesmartdocumentsuseofmanifests_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_autoorgidgetkey","displayName":"Automatically activate Office with federated organization credentials (User)","description":"This policy setting activates Office on users’ computers without prompting them to sign in to their Office 365 accounts.\r\n\r\nIf you enable or do not configure this policy setting, and a user is already signed in with federated organization credentials, Office automatically activates when the user first starts an Office application. If either multiple or no organization credentials are found, the user is prompted to sign in.\r\n\r\nIf you disable this policy setting, Office might prompt the user to sign in with their organization's credentials if Office is not installed directly by the user from his or her Office 365 account homepage.\r\n","helpText":"","infoUrls":[],"categoryId":"760376f3-6b74-4992-89eb-aa41d6190e94","categoryName":"Subscription Activation","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_autoorgidgetkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_autoorgidgetkey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_hidemanageaccountlink","displayName":"Do not show \"Manage Account\" link for subscription licenses. (User)","description":"This policy setting controls whether a \"Manage Account\" link is exposed in Account tab of the File menu for subscription licenses.\r\n\r\nIf you enable this policy setting, Office does not expose a \"Manage Account\" link for subscription licenses.\r\n\r\nIf you disable or do not configure this policy setting, Office exposes a \"Manage Account\" link for subscription licenses.","helpText":"","infoUrls":[],"categoryId":"760376f3-6b74-4992-89eb-aa41d6190e94","categoryName":"Subscription Activation","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_hidemanageaccountlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_hidemanageaccountlink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_enablelogging","displayName":"Turn on telemetry data collection (User)","description":"This policy setting allows you to turn on the data collection features in Office that are used by Office Telemetry Dashboard and Office Telemetry Log.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent and Office applications will collect telemetry data, which includes Office application usage, most recently used Office documents (including file names) and solutions usage, compatibility issues, and critical errors that occur on the local computers. You can use Office Telemetry Dashboard to view this data remotely, and users can use Office Telemetry Log to view this data on their local computers.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent and Office applications do not generate or collect telemetry data.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_enablelogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_enablelogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentfilemetadataobfuscation","displayName":"Turn on privacy settings in Office Telemetry Agent (User)","description":"This policy setting configures Office Telemetry Agent to disguise, or obfuscate, certain file properties that are reported in telemetry data.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent obfuscates the file name, file path, and title of Office documents before uploading telemetry data to the shared folder.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent uploads telemetry data that shows the full file name, file path, and title of all Office documents.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentfilemetadataobfuscation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentfilemetadataobfuscation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentupload","displayName":"Turn on data uploading for Office Telemetry Agent (User)","description":"This policy setting turns on the data uploading feature in Office Telemetry Agent.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent periodically uploads telemetry data to a shared folder.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent does not upload any data. However, telemetry data is still collected on the local computer and can be viewed by using Office Telemetry Log.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentupload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentupload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcommonfileshare","displayName":"Specify the UNC path to store Office telemetry data (User)","description":"This policy setting allows you to specify the Uniform Naming Convention (UNC) path of a shared folder to which Office Telemetry Agent sends Office telemetry data.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent uploads Office telemetry data to the UNC path that you specify. Use the format \\\\Server_Name\\Share_Name.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent does not send the data, and you cannot see any data in Office Telemetry Dashboard.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcommonfileshare_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcommonfileshare_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcommonfileshare_l_officeosmcommonfilesharefileshare","displayName":"UNC path to store Office telemetry data: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags","displayName":"Specify custom tags for Office telemetry data (User)","description":"This policy setting allows you to add custom tags to the Office telemetry data that is sent by Office Telemetry Agent.\r\n\r\nIf you enable this policy setting, the specified custom tags are shown in Office Telemetry Dashboard, where you can filter the collected data by the tag name. You can specify any string that you want to categorize and filter the collected data (for example, department name, title of user, and so forth).\r\n\r\nIf you disable or do not configure this policy setting, no custom tags are shown in Office Telemetry Dashboard, and you cannot filter the data that is sent by Office Telemetry Agent.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_l_officeosmcustomtagstag1","displayName":"Tag 1: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_l_officeosmcustomtagstag2","displayName":"Tag 2: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_l_officeosmcustomtagstag3","displayName":"Tag 3: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_l_officeosmcustomtagstag4","displayName":"Tag 4: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications","displayName":"Office applications to exclude from Office Telemetry Agent reporting (User)","description":"This policy setting allows you to prevent telemetry data for Office applications from being reported to Office Telemetry Dashboard.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent does not upload telemetry data for the specified Office applications to Office Telemetry Dashboard.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent uploads telemetry data for all Office applications.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsaccess","displayName":"Access-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsaccess_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsaccess_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsexcel","displayName":"Excel-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsexcel_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsexcel_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsonenote","displayName":"OneNote-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsonenote_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsonenote_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsoutlook","displayName":"Outlook-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsoutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsoutlook_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationspowerpoint","displayName":"PowerPoint-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationspowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationspowerpoint_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsproject","displayName":"Project-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsproject_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationspublisher","displayName":"Publisher-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationspublisher_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationspublisher_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsvisio","displayName":"Visio-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsvisio_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsvisio_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsword","displayName":"Word-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsword_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes","displayName":"Office solutions to exclude from Office Telemetry Agent reporting (User)","description":"This policy setting allows you to prevent telemetry data for Office solutions from being reported to Office Telemetry Dashboard.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent does not upload telemetry data for the specified Office solutions to Office Telemetry Dashboard.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent uploads telemetry data for all available solution types.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesagave","displayName":"Web Add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesagave_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesagave_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesappaddins","displayName":"Application-specific add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesappaddins_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesappaddins_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypescomaddins","displayName":"COM add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypescomaddins_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypescomaddins_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesdocumentfiles","displayName":"Office document files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesdocumentfiles_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesdocumentfiles_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypestemplatefiles","displayName":"Office template files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypestemplatefiles_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypestemplatefiles_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_capitalizefirstletterofsentence","displayName":"Capitalize first letter of sentence (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_capitalizefirstletterofsentence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_capitalizefirstletterofsentence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_capitalizenamesofdays","displayName":"Capitalize names of days (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_capitalizenamesofdays_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_capitalizenamesofdays_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_correctaccidentaluseofcapslockkey","displayName":"Correct accidental use of cAPS LOCK key (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_correctaccidentaluseofcapslockkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_correctaccidentaluseofcapslockkey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_correcttwoinitialcapitals","displayName":"Correct TWo INitial CApitals (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_correcttwoinitialcapitals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_correcttwoinitialcapitals_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_replacetextasyoutype","displayName":"Replace text as you type (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_replacetextasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_replacetextasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_showautocorrectoptionsbuttons","displayName":"Show AutoCorrect Options buttons (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_showautocorrectoptionsbuttons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_showautocorrectoptionsbuttons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_checkfornewactionsurl","displayName":"Check for new actions URL (User)","description":"This policy setting allows you to configure the \"Check for New Actions\" menu option.\r\n\r\nIf you enable this policy setting, and when a URL is specified, a new \"Check for New Actions\" menu option will be added to the \"Additional Actions\" context menu.\r\n\r\nIf you disable or do not configure this policy setting, or when it is enabled and a URL is not specified, a \"Check for New Actions\" menu option will not be shown in the \"Additional Actions\" context menu.","helpText":"","infoUrls":[],"categoryId":"69931627-230d-4df9-bbef-e3eac64ea8ef","categoryName":"Additional Actions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_checkfornewactionsurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_checkfornewactionsurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_checkfornewactionsurl_l_checkfornewactionsurl231","displayName":"Check for new actions URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"69931627-230d-4df9-bbef-e3eac64ea8ef","categoryName":"Additional Actions","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_enableadditionalactionsinexcel","displayName":"Enable additional actions in Excel (User)","description":"This policy setting controls whether Excel can provide additional actions for certain words and phrases in a workbook through the right-click menu, and whether users can configure this behavior by checking or unchecking the \"Enable additional actions in the right-click menu\" option under the File tab | Options | Proofing | AutoCorrect Options | Actions tab. If additional actions functionality is turned on, Excel can recognize dates and financial symbols and provide additional actions for them.\r\n\r\nIf you enable or do not configure this policy setting, users can configure Excel to provide additional actions. Note: Excel does not provide additional actions until users check the \"Enable additional actions in the right-click menu\" option in the UI.\r\n\r\nIf you disable this policy setting, users cannot configure Excel to provide additional actions.","helpText":"","infoUrls":[],"categoryId":"69931627-230d-4df9-bbef-e3eac64ea8ef","categoryName":"Additional Actions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_enableadditionalactionsinexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_enableadditionalactionsinexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_moreactionsurl","displayName":"More actions URL (User)","description":"This policy setting allows you to specify what URL to send users to when the More Actions button is clicked. The More Actions button can be found under File tab | Options | Proofing | Autocorrect Options... | Actions | More Actions.\r\n\r\nIf you enable this policy setting and you specify a URL, the More Actions button will send the user to the specified URL. If you enable this policy setting and you do not specify a URL (you leave the field blank), the More Actions button is disabled.\r\n\r\nIf you disable or do not configure this policy setting, the More Actions button will send the user to the default URL.","helpText":"","infoUrls":[],"categoryId":"69931627-230d-4df9-bbef-e3eac64ea8ef","categoryName":"Additional Actions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_moreactionsurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_moreactionsurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_moreactionsurl_l_moreactionsurleditid","displayName":"More Actions URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"69931627-230d-4df9-bbef-e3eac64ea8ef","categoryName":"Additional Actions","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_conversionservices_l_conversionservicesoptions","displayName":"Conversion Service Options (User)","description":"This policy setting controls users' access to the online features of Office 2016.","helpText":"","infoUrls":[],"categoryId":"6c142a01-47fa-422d-8135-29e81bc970cc","categoryName":"Conversion Service","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_conversionservices_l_conversionservicesoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_conversionservices_l_conversionservicesoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_conversionservices_l_conversionservicesoptions_l_conversionservicesoptions236","displayName":"Conversion service options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6c142a01-47fa-422d-8135-29e81bc970cc","categoryName":"Conversion Service","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_conversionservices_l_conversionservicesoptions_l_conversionservicesoptions236_0","displayName":"Do not allow to use Microsoft Conversion Service","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_conversionservices_l_conversionservicesoptions_l_conversionservicesoptions236_2","displayName":"Allow to use Microsoft Conversion Service","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_onlinecontentoptions","displayName":"Online Content Options (User)","description":"This policy setting controls users' access to the online features of Office 2016.\r\n\r\nIf you enable this policy setting, you can choose one of two options for user access to online content and services:\r\n\r\n* Do not allow Office to connect to the Internet – Office applications do not connect to the Internet to access online services, or to download the latest online content from Office.com. Connected features of Office 2016 are disabled.\r\n\r\n* Allow Office to connect to the Internet – Office applications use online services and download the latest online content from Office.com when users’ computers are connected to the Internet. Connected features of Office 2016 are enabled. This option enforces the default configuration.\r\n\r\nIf you disable this policy setting or do not configure this policy setting, Office applications use online services and download the latest online content from Office.com when users’ computers are connected to the Internet. Users can change this behavior by deselecting the \"Allow Office to connect to the Internet\" checkbox in the Privacy Options section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","categoryName":"Online Content","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_onlinecontentoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_onlinecontentoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_onlinecontentoptions_l_onlinecontentoptions236","displayName":"Online content options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","categoryName":"Online Content","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_onlinecontentoptions_l_onlinecontentoptions236_0","displayName":"Do not allow Office to connect to the Internet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_onlinecontentoptions_l_onlinecontentoptions236_2","displayName":"Allow Office to connect to the Internet","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions","displayName":"Service Level Options (User)","description":"This policy setting controls the types of services that can be used by the online features of Office 2016.\r\n \r\nIf you enable this policy setting, you can choose one of three options for gating access to online services based on the owner of the service:\r\n\r\n* Office services only - Office 2016 applications on the computer communicate only with Office-owned services. All other Microsoft or third-party service integration in Office 2016 is disabled on the computer. This is the most restrictive option.\r\n\r\n* Microsoft services only - Office 2016 applications on the computer communicate only with Microsoft-owned services. All third-party service integration in Office 2016 is disabled on the computer.\r\n\r\n* All services - All service integration in Office 2016 is enabled on the computer. This is also the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, Office 2016 client applications allow all service integrations. Individual users can manage the set of services they use through the new My Office place in Office Backstage view.","helpText":"","infoUrls":[],"categoryId":"91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","categoryName":"Online Content","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions_l_serviceleveloptionsdropid","displayName":"Service Level Options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","categoryName":"Online Content","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions_l_serviceleveloptionsdropid_0","displayName":"Office services only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions_l_serviceleveloptionsdropid_1","displayName":"Microsoft services only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions_l_serviceleveloptionsdropid_2","displayName":"All services","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_powerpointdesigner_l_powerpointdesigneroptions","displayName":"PowerPoint Designer Options (User)","description":"This policy setting allows an administrator to enable or disable PowerPoint Designer","helpText":"","infoUrls":[],"categoryId":"5838ed03-2902-4931-92cf-e349ab09c9b8","categoryName":"PowerPoint Designer","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_powerpointdesigner_l_powerpointdesigneroptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_powerpointdesigner_l_powerpointdesigneroptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_powerpointdesigner_l_powerpointdesigneroptions_l_powerpointdesigneroptionsid","displayName":"PowerPoint Designer options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5838ed03-2902-4931-92cf-e349ab09c9b8","categoryName":"PowerPoint Designer","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_powerpointdesigner_l_powerpointdesigneroptions_l_powerpointdesigneroptionsid_0","displayName":"Disable PowerPoint Designer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_powerpointdesigner_l_powerpointdesigneroptions_l_powerpointdesigneroptionsid_73187","displayName":"Enable PowerPoint Designer","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disablehyperlinkstowebtemplatesinfilenewandtaskpanes","displayName":"Disable web templates in File | New and on the Office Start screen (User)","description":"This policy setting controls whether users can download templates from Office.com from within the Office applications.\r\n\r\nIf you enable this policy setting, users will not see featured templates from Office.com in File | New and on the Office Start screen and will not be able to download templates from within Office applications.\r\n\r\nIf you disable or do not configure this policy setting, users will see featured templates from Office.com in File | New and on the Office Start screen and will be able to download templates from within Office applications.\r\n\r\nNote - Enabling this policy setting does not prevent users from downloading templates from Office.com using their Web browsers.","helpText":"","infoUrls":[],"categoryId":"2d5a483f-b408-426d-9234-2883eae20afb","categoryName":"Tools | Options | General | Web Options...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disablehyperlinkstowebtemplatesinfilenewandtaskpanes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disablehyperlinkstowebtemplatesinfilenewandtaskpanes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disableofficetemplates","displayName":"Hide all Office-provided templates on the Office Start screen and in File | New (User)","description":"This policy setting controls whether Office-provided templates (from Office.com and shipped with the Office clients) are hidden on the Office Start screen and in File | New.\r\n\r\nIf you enable this policy setting, users will not see any Office provided templates on the Office Start screen nor in File | New.\r\n\r\nIf you disable or do not configure this policy setting, users will see Office provided templates on the Office Start screen nor in File | New.\r\n\r\nNote - enabling this policy setting does not prevent users from downloading templates from Office.com using their Web browsers and does not prevent users from using Office-provided templates installed on their hard drive using Windows Explorer to launch those templates.","helpText":"","infoUrls":[],"categoryId":"2d5a483f-b408-426d-9234-2883eae20afb","categoryName":"Tools | Options | General | Web Options...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disableofficetemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disableofficetemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disabletargetedmessaging","displayName":"Hide dynamic lifecycle messages (User)","description":"This policy setting controls whether dynamic lifecycle messages are displayed in Office applications.\r\n\r\nA dynamic lifecycle message appears as a notification in an Office application. This message is similar to a default lifecycle message, but provides additional information. For example, a message that reminds users to renew their subscription that also includes information to help them renew. Office periodically connects to the Internet and contacts Microsoft to determine if there are any relevant messages to display.\r\n\r\nIf you enable this policy setting, Office won’t check for these types of messages, but, default lifecycle messages still display in Office applications.\r\n\r\nIf you disable or don’t configure this policy setting, Office checks for these types of messages and displays them.","helpText":"","infoUrls":[],"categoryId":"2d5a483f-b408-426d-9234-2883eae20afb","categoryName":"Tools | Options | General | Web Options...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disabletargetedmessaging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disabletargetedmessaging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_allowpngasanoutputformat","displayName":"Allow PNG as an output format (User)","description":"This policy setting determines whether Office 2016 applications can output graphics in Portable Network Graphics (PNG) format when documents are saved as Web pages.\r\n\r\nIf you enable this policy setting, Office 2016 applications can save graphics in PNG format and users cannot change this configuration.\r\n\r\nIf you disable this policy setting, Office 2016 applications cannot save graphics in PNG format and users cannot change this configuration.\r\n\r\nIf you do not configure this policy setting, Office 2016 applications do not save graphics in the PNG format. Users can change this functionality by opening the application's Options dialog box, clicking Advanced, clicking Web Options, and selecting the Allow PNG as a graphics format check box.","helpText":"","infoUrls":[],"categoryId":"8ee1d8d2-582f-401b-927a-993016f4290d","categoryName":"Browsers","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_allowpngasanoutputformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_allowpngasanoutputformat_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_relyonvmlfordisplayinggraphicsinbrowsers","displayName":"Rely on VML for displaying graphics in browsers (User)","description":"This policy setting controls whether Office 2016 applications save standard raster file format (GIF or PNG) copies of Vector Markup Language (VML) graphics when documents are saved as Web pages.\r\n\r\nIf you enable this policy setting, Office 2016 applications will not generate alternate files for VML graphics when documents are saved as Web pages. In addition, the \"Rely on VML for displaying graphics in browsers\" check box is checked in the Web Options dialog in Excel, PowerPoint, and Word, and users cannot change it.\r\n\r\nIf you disable this policy setting, Office 2016 applications also save copies of the graphics in a standard raster file format (GIF or PNG) for use by browsers that cannot display VML. In addition, the \"Rely on VML for displaying graphics in browsers\" check box is cleared in the Web Options dialog in Excel, PowerPoint, and Word, and users cannot change it.\r\n\r\nIf you do not configure this policy setting, when saving VML graphics, Office 2016 applications also save copies of the graphics in a standard raster file format (GIF or PNG) for use by browsers that cannot display VML. If the \"Rely on VML for displaying graphics in browsers\" check box in the Web Options dialog is selected, applications will not save raster copies of VML graphics, which means those graphics will not display in non-Microsoft browsers.","helpText":"","infoUrls":[],"categoryId":"8ee1d8d2-582f-401b-927a-993016f4290d","categoryName":"Browsers","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_relyonvmlfordisplayinggraphicsinbrowsers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_relyonvmlfordisplayinggraphicsinbrowsers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor","displayName":"Target monitor (User)","description":"Sets the value in the UI.","helpText":"","infoUrls":[],"categoryId":"8ee1d8d2-582f-401b-927a-993016f4290d","categoryName":"Browsers","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_pixelsperinch","displayName":"Pixels per inch (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8ee1d8d2-582f-401b-927a-993016f4290d","categoryName":"Browsers","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_pixelsperinch_72","displayName":"72","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_pixelsperinch_96","displayName":"96","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_pixelsperinch_120","displayName":"120","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize","displayName":"Screen size (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8ee1d8d2-582f-401b-927a-993016f4290d","categoryName":"Browsers","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_544x376","displayName":"544 x 376","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_640x480","displayName":"640 x 480","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_720x512","displayName":"720 x 512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_800x600","displayName":"800 x 600","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1024x768","displayName":"1024 x 768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1152x882","displayName":"1152 x 882","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1152x900","displayName":"1152 x 900","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1280x1024","displayName":"1280 x 1024","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1600x1200","displayName":"1600 x 1200","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1800x1440","displayName":"1800 x 1440","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1920x1200","displayName":"1920 x 1200","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding","displayName":"Default or specific encoding (User)","description":"When enabled, either default encoding or a specified encoding will be used.","helpText":"","infoUrls":[],"categoryId":"025c640e-51e2-4f04-85e3-a13f30b5e08c","categoryName":"Encoding","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_alwayssavewebpagesinthedefaultencoding","displayName":"Always save Web pages in the default encoding. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"025c640e-51e2-4f04-85e3-a13f30b5e08c","categoryName":"Encoding","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_alwayssavewebpagesinthedefaultencoding_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_alwayssavewebpagesinthedefaultencoding_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas","displayName":"Save this document as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"025c640e-51e2-4f04-85e3-a13f30b5e08c","categoryName":"Encoding","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1256","displayName":"Arabic Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_28594","displayName":"Baltic Alphabet (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1257","displayName":"Baltic Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_852","displayName":"Central European (DOS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_28592","displayName":"Central European Alphabet (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1250","displayName":"Central European Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_936","displayName":"Chinese Simplified (GB2312)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_52936","displayName":"Chinese Simplified (HZ)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_950","displayName":"Chinese Traditional (Big 5)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_866","displayName":"Cyrillic Alphabet (DOS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_28595","displayName":"Cyrillic Alphabet (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_20866","displayName":"Cyrillic Alphabet (KOI8-R)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1251","displayName":"Cyrillic Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_28597","displayName":"Greek Alphabet (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1253","displayName":"Greek Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1255","displayName":"Hebrew Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_51932","displayName":"Japanese (EUC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_50220","displayName":"Japanese (JIS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_50222","displayName":"Japanese (JIS-Allow 1 byte Kana - SO/SI)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_50221","displayName":"Japanese (JIS-Allow 1 byte Kana)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_932","displayName":"Japanese (Shift-JIS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_949","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_28593","displayName":"Latin 3 Alphabet (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_874","displayName":"Thai (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1254","displayName":"Turkish Alphabet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_21866","displayName":"Ukrainian Alphabet (KOI8-RU)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1200","displayName":"Universal Alphabet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1201","displayName":"Universal Alphabet (Big-Endian)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_65001","displayName":"Universal Alphabet (UTF-8)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1258","displayName":"Vietnamese Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_28598","displayName":"Visual Hebrew (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1252","displayName":"Western Alphabet (Windows)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_checkifofficeisthedefaulteditorforwebpagescreatedinoffice","displayName":"Check if Office is the default editor for Web pages created in Office (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_checkifofficeisthedefaulteditorforwebpagescreatedinoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_checkifofficeisthedefaulteditorforwebpagescreatedinoffice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentdirectlyinofficeapplication","displayName":"Open Office document directly in Office application (User)","description":"This policy setting allows you to choose whether Office documents located on web servers open directly in the registered application or through the web browser. \r\n\r\nIf you enable this policy setting, files will open directly in the associated Office application, bypassing the web browser.\r\n\r\nIf you disable this policy setting files will open through the web browser.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentdirectlyinofficeapplication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentdirectlyinofficeapplication_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentsasreadwritewhilebrowsing","displayName":"Open Office documents as read/write while browsing (User)","description":"This policy setting controls whether users can edit and save Office 2016 documents on Web servers that they have opened using Internet Explorer.\r\n \r\nIf enable this policy setting, when users browse to an Office 2016 document on a Web server using Internet Explorer the appropriate application opens the file in read/write mode.\r\n\r\nIf you disable or do not configure this policy setting, when users browse to an Office 2016 document on a Web server using Internet Explorer, the appropriate application opens the file in read-only mode.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentsasreadwritewhilebrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentsasreadwritewhilebrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_organizesupportingfilesinafolder","displayName":"Organize supporting files in a folder (User)","description":"This will be forced on if 'Use long file names' is forced off.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_organizesupportingfilesinafolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_organizesupportingfilesinafolder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_updatelinksonsave","displayName":"Update links on save (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_updatelinksonsave_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_updatelinksonsave_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_uselongfilenameswheneverpossible","displayName":"Use long file names whenever possible (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_uselongfilenameswheneverpossible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_uselongfilenameswheneverpossible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting","displayName":"Rely on CSS for font formatting (User)","description":"This policy setting allows you to rely on CSS for font formatting.\r\n\r\nIf you enable this policy setting, you may select configure these options:\r\n- Enforce CSS: If checked, enforce CSS is on. If not checked, enforce CSS is off.\r\n- CSS setting for Word: If checked, the CSS setting for Word as an email editor is used.\r\n\r\nIf you disable or do not configure this policy setting, the options will not be configured.","helpText":"","infoUrls":[],"categoryId":"eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_l_checktoenforcecssonunchecktoenforcecssoff","displayName":"Enforce CSS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_l_checktoenforcecssonunchecktoenforcecssoff_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_l_checktoenforcecssonunchecktoenforcecssoff_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_l_usethecsssettingforwordasanemaileditor","displayName":"CSS setting for Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_l_usethecsssettingforwordasanemaileditor_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_l_usethecsssettingforwordasanemaileditor_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_allowaccenteduppercaseinfrench","displayName":"Allow accented uppercase in French (User)","description":"Checks/Unchecks the option \"Enforce accented uppercase in French\".","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_allowaccenteduppercaseinfrench_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_allowaccenteduppercaseinfrench_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes","displayName":"Arabic modes (User)","description":"Specifies the spelling rules to use for checking spelling of Arabic text. This option is available only if you are using a right-to-left language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for the language, and have enabled support for the language through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_l_empty239","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_l_empty239_0","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_l_empty239_1","displayName":"Strict initial alef hamza","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_l_empty239_2","displayName":"Strict final yaa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_l_empty239_3","displayName":"Both strict","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_combineauxverbadj","displayName":"Combine aux verb/adj. (User)","description":"Checks/Unchecks the corresponding UI option. This option is available only if you are using the Korean language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for Korean, and have enabled support for Korean through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_combineauxverbadj_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_combineauxverbadj_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_flagrepeatedwords","displayName":"Flag Repeated Words (User)","description":"Allows users to flag or ignore repeated words.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_flagrepeatedwords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_flagrepeatedwords_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode","displayName":"Hebrew mode (User)","description":"Specifies the script to use for checking spelling of Hebrew text. This option is available only if you are using a right-to-left language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for that language, and have enabled support for the language through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_l_empty238","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_l_empty238_0","displayName":"Full","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_l_empty238_1","displayName":"Partial","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_l_empty238_2","displayName":"Mixed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_l_empty238_3","displayName":"Mixed authorized","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignoreinternetandfileaddresses","displayName":"Ignore Internet and file addresses (User)","description":"Allow users to ignore URLs and file paths.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignoreinternetandfileaddresses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignoreinternetandfileaddresses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignorewordsinuppercase","displayName":"Ignore words in UPPERCASE (User)","description":"Allow users to ignore words written in UPPERCASE.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignorewordsinuppercase_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignorewordsinuppercase_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignorewordswithnumbers","displayName":"Ignore words with numbers (User)","description":"Allows users to ignore words with numbers.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignorewordswithnumbers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignorewordswithnumbers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_processcompoundnouns","displayName":"Process compound nouns (User)","description":"Checks/Unchecks the corresponding UI option. This option is available only if you are using the Korean language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for Korean, and have enabled support for Korean through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_processcompoundnouns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_processcompoundnouns_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_suggestfrommaindictionaryonly","displayName":"Suggest from main dictionary only (User)","description":"Allows users to select words from main lexicon only.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_suggestfrommaindictionaryonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_suggestfrommaindictionaryonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_useautochangelist","displayName":"Use auto-change list (User)","description":"Checks/Unchecks the option \"Search misused word list\". This option is available only if you are using the Korean language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for Korean, and have enabled support for Korean through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_useautochangelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_useautochangelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_usegermanpostreformruleswhenrunningspellcheck","displayName":"German: Use post-reform rules (User)","description":"Allows users to choose a particular spellchecking style; Pre-reform or post reform.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_usegermanpostreformruleswhenrunningspellcheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_usegermanpostreformruleswhenrunningspellcheck_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling~l_proofingdatacollection_l_improveproofingtools","displayName":"Improve Proofing Tools (User)","description":"This policy setting controls whether the Help Improve Proofing Tools feature sends usage data to Microsoft. The Help Improve Proofing Tools feature collects data about use of the Proofing Tools, such as additions to the custom dictionary, and sends it to Microsoft. After about six months, the feature stops sending data to Microsoft and deletes the data collection file from the user's computer. \r\n\r\nIf you enable this policy setting, this feature is enabled if users choose to participate in the Customer Experience Improvement Program (CEIP). If your organization has policies that govern the use of external resources such as the CEIP, allowing the use of the Help Improve Proofing Tools feature might cause them to violate these policies. \r\n\r\nIf you disable this policy setting, the Help Improve Proofing Tools feature does not collect proofing tool usage information and transmit it to Microsoft. \r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"df357f0c-78fe-4aee-a465-f3da7499077e","categoryName":"Proofing Data Collection","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling~l_proofingdatacollection_l_improveproofingtools_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling~l_proofingdatacollection_l_improveproofingtools_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_allowwebarchivestobesavedinanyhtmlencoding","displayName":"Allow Web Archives to be saved in any HTML encoding (User)","description":"Enabled: Allow the user to save Web Archives in any HTML encoding.\r\n\r\nNot enabled: Always use US-ASCII for Web Archives.\r\n\r\nThis results in smaller files, but is not supported in Windows Internet Explorer 5.0 or earlier.","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_allowwebarchivestobesavedinanyhtmlencoding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_allowwebarchivestobesavedinanyhtmlencoding_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish","displayName":"Default format for 'Publish' (User)","description":"\"Web Archive (*.mht)\": The Publish command creates a Web Archive file. | \"Web Page (*.htm)\": The Publish command creates an HTML file. | \"Default\": The Publish command uses the default Web page format for publishing.","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish_l_defaultformatforpublish405","displayName":"Default format for 'Publish' (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish_l_defaultformatforpublish405_2","displayName":"Web Archive (*.mht)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish_l_defaultformatforpublish405_1","displayName":"Web Page (*.htm)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish_l_defaultformatforpublish405_0","displayName":"Default","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointsaveanadditionalversionofthepresentationforolderbr","displayName":"PowerPoint: Save an additional version of the presentation for older browsers (User)","description":"Checked: PowerPoint publishes Web Archive presentations that contain a version of the presentation that is compatible with older browsers. | Unchecked: PowerPoint publishes Web Archive presentations that contain only the version of the presentation that is compatible with later browsers.","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointsaveanadditionalversionofthepresentationforolderbr_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointsaveanadditionalversionofthepresentationforolderbr_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility","displayName":"PowerPoint: web page format compatibility (User)","description":"\"All browsers\": Save new PowerPoint web pages in a format that is compatible with all browsers. | \"Windows Internet Explorer 4.0 or later\": Save new PowerPoint web pages in a format that requires Windows Internet Explorer 4.0 or later. | \"Based on installed browsers\": Examine the browsers installed on the user's computer and save new PowerPoint web pages in the smallest possible format that is compatible with all of the installed browsers.","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406","displayName":"PowerPoint: web page format compatibility (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406_2","displayName":"All browsers","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406_1","displayName":"Windows Internet Explorer 4.0 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406_0","displayName":"Based on installed browsers","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_savenewwebpagesaswebarchives","displayName":"Save new Web pages as Web archives (User)","description":"Checked: Use Web Archive (*.mht) as the default format for the Save as Web Page command (File menu). | Unchecked: Use Web page (*.htm) as the default format for the Save as Web Page command (File menu).","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_savenewwebpagesaswebarchives_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_savenewwebpagesaswebarchives_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding","displayName":"Web Archive encoding (User)","description":"\"Use 8 bit content-transfer-encoding\": Use a content-transfer-encoding of 8bit for all parts in a Web Archive file. | \"Use 8 bit only for encoding text parts\": Use a content-transfer-encoding of 8bit only for text parts. | \"Use RFC-approved encoding\": Always use RFC-approved encodings.","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding_l_webarchiveencoding402","displayName":"Web Archive encoding (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding_l_webarchiveencoding402_2","displayName":"Use 8 bit content-transfer-encoding","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding_l_webarchiveencoding402_1","displayName":"Use 8 bit only for encoding text parts","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding_l_webarchiveencoding402_0","displayName":"Use RFC-approved encoding","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationexcel","displayName":"Don’t show the What’s New information for Excel (User)","description":"This policy setting controls whether the What’s New information is shown when a user opens the desktop version of Excel for the first time after Excel has been updated with new features. By default, the What’s New information is shown.\r\n\r\nIf you enable this policy setting, the What’s New information isn’t shown. Also, the What’s New button in File > Account is disabled.\r\n\r\nIf you disable or don’t configure this policy setting, the What’s New information is shown.\r\n\r\nNote: There are separate policy settings for Word, Excel, PowerPoint, Outlook, OneNote, and Visio.\r\n ","helpText":"","infoUrls":[],"categoryId":"adf11731-7089-4e2e-8dde-4bd9ef86b067","categoryName":"What's New","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationonenote","displayName":"Don’t show the What’s New information for OneNote (User)","description":"This policy setting controls whether the What’s New information is shown when a user opens the desktop version of OneNote for the first time after OneNote has been updated with new features. By default, the What’s New information is shown.\r\n\r\nIf you enable this policy setting, the What’s New information isn’t shown. Also, the What’s New button in File > Account is disabled.\r\n\r\nIf you disable or don’t configure this policy setting, the What’s New information is shown.\r\n\r\nNote: There are separate policy settings for Word, Excel, PowerPoint, Outlook, OneNote, and Visio.\r\n ","helpText":"","infoUrls":[],"categoryId":"adf11731-7089-4e2e-8dde-4bd9ef86b067","categoryName":"What's New","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationonenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationonenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationoutlook","displayName":"Don’t show the What’s New information for Outlook (User)","description":"This policy setting controls whether the What’s New information is shown when a user opens the desktop version of Outlook for the first time after Outlook has been updated with new features. By default, the What’s New information is shown.\r\n\r\nIf you enable this policy setting, the What’s New information isn’t shown. Also, the What’s New button in File > Office Account is disabled.\r\n\r\nIf you disable or don’t configure this policy setting, the What’s New information is shown.\r\n\r\nNote: There are separate policy settings for Word, Excel, PowerPoint, Outlook, OneNote, and Visio.\r\n ","helpText":"","infoUrls":[],"categoryId":"adf11731-7089-4e2e-8dde-4bd9ef86b067","categoryName":"What's New","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationpowerpoint","displayName":"Don’t show the What’s New information for PowerPoint (User)","description":"This policy setting controls whether the What’s New information is shown when a user opens the desktop version of PowerPoint for the first time after PowerPoint has been updated with new features. By default, the What’s New information is shown.\r\n\r\nIf you enable this policy setting, the What’s New information isn’t shown. Also, the What’s New button in File > Account is disabled.\r\n\r\nIf you disable or don’t configure this policy setting, the What’s New information is shown.\r\n\r\nNote: There are separate policy settings for Word, Excel, PowerPoint, Outlook, OneNote, and Visio.\r\n ","helpText":"","infoUrls":[],"categoryId":"adf11731-7089-4e2e-8dde-4bd9ef86b067","categoryName":"What's New","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationvisio","displayName":"Don’t show the What’s New information for Visio (User)","description":"This policy setting controls whether the What’s New information is shown when a user opens the desktop version of Visio for the first time after Visio has been updated with new features. By default, the What’s New information is shown.\r\n\r\nIf you enable this policy setting, the What’s New information isn’t shown. Also, the What’s New button in File > Account is disabled.\r\n\r\nIf you disable or don’t configure this policy setting, the What’s New information is shown.\r\n\r\nNote: There are separate policy settings for Word, Excel, PowerPoint, Outlook, OneNote, and Visio.\r\n ","helpText":"","infoUrls":[],"categoryId":"adf11731-7089-4e2e-8dde-4bd9ef86b067","categoryName":"What's New","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationvisio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationvisio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationword","displayName":"Don’t show the What’s New information for Word (User)","description":"This policy setting controls whether the What’s New information is shown when a user opens the desktop version of Word for the first time after Word has been updated with new features. By default, the What’s New information is shown.\r\n\r\nIf you enable this policy setting, the What’s New information isn’t shown. Also, the What’s New button in File > Account is disabled.\r\n\r\nIf you disable or don’t configure this policy setting, the What’s New information is shown.\r\n\r\nNote: There are separate policy settings for Word, Excel, PowerPoint, Outlook, OneNote, and Visio.\r\n ","helpText":"","infoUrls":[],"categoryId":"adf11731-7089-4e2e-8dde-4bd9ef86b067","categoryName":"What's New","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_miscellaneous437_l_cloudonlysaving","displayName":"Restrict saving on non-Cloud locations (User)","description":"This policy setting controls whether Word, Excel, and PowerPoint users can use non-cloud locations (local and network) to create new files.\r\n\r\nIf you enable this policy setting, users will only have Cloud Locations available to perform SaveAs and Save new files.\r\n\r\nIf you disable or don’t configure this policy setting, users can use any location (Cloud, Local, and Network) to perform SaveAs and Save new files.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for Enterprise.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_miscellaneous437_l_cloudonlysaving_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_miscellaneous437_l_cloudonlysaving_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_shownfilefmtprompt","displayName":"Show the File Format dialog (User)","description":"This policy setting allows you to control whether the file format dialog has already been shown to the user. If you enable this policy setting, the dialog won't be shown again. If you disable this policy setting, the dialog prompts the user to select a default file format on each boot until one is selected. If you don't configure this policy setting, the dialog prompts the user to select a default file format on each boot until one is selected.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_shownfilefmtprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_shownfilefmtprompt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload","displayName":"Age out documents older than n days Including documents with pending uploads (User)","description":"\r\n This policy controls when locally cached Office documents are aged out of the Office Document Cache including if the file may have pending uploads. This acts as a maximum possible age (in days) for any file to remain in the Office Document Cache.\r\n\r\n If you enable this policy setting, files older than the policy \"Age out documents older than n days\" as well as this setting will get cleaned up regardless of file pending upload status.\r\n\r\n If you disable this policy setting or if you do not configure this policy setting, Office will clean out only files that do not have pending changes per the policy \"Age out documents older than n days\". Configuring this policy with a value of 0 is also considered disabling the policy.\r\n\r\n For more information https://support.microsoft.com/en-us/topic/managing-office-document-cache-size-ea64af72-b597-408e-8ecf-fd55daa02476\r\n\r\n Note: This policy setting only applies to Office builds 19328.20000 and newer\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload_l_ageoutpolicyincludingfilespendinguploaddecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_writingassistantadminchoiceadminchoice","displayName":"Enable Writing Assistant (User)","description":"This policy setting controls whether users can use the Writing Assistant feature.\r\n \r\nIf you enable or don’t configure this policy setting, users will be allowed to use Writing Assistant and it will be enabled by default (unless the users disabled it).\r\n\r\nIf you disable this policy setting, users won't see Writing Assistant by default.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for Enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_writingassistantadminchoiceadminchoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_writingassistantadminchoiceadminchoice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins","displayName":"List of allowed COM/VSTO add-ins registered in HKCU (User)","description":"This policy setting allows you to specify COM/VSTO add-ins registered in HKEY_CURRENT_USER (HKCU) that should be allowed to load, overriding the \"Block loading of COM/VSTO add-ins registered in HKCU\" policy.\r\n\r\nSome legitimate add-ins may be installed in HKCU even when deployed by administrators, due to how the independent software vendor (ISV) designed their installer. This policy provides an administrative override to allow specific add-ins to load despite being registered in HKCU.\r\n\r\nIf you enable this policy setting, you can specify a list of COM/VSTO add-ins that are allowed to load from HKCU. Enter each add-in using its ProgID as the name.\r\n\r\nIf you disable or don't configure this policy setting, the standard HKCU blocking behavior applies when that policy is enabled.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_l_allowedcomaddinslist","displayName":"Allowed COM/VSTO Add-ins: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_l_allowedcomaddinslist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_l_allowedcomaddinslist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockmotwmacrointrustedorsigned","displayName":"Block all internet macros (ignore trusted locations or publishers) (User)","description":"This policy setting removes the trusted location and trusted publisher exceptions for files downloaded from the internet with Mark of the Web (MOTW).\r\n\r\nBy default, Office blocks macros from the internet but allows exceptions for files that are either in trusted locations or signed by trusted publishers.\r\n\r\nIf you enable this policy setting, all macros in files downloaded from the internet will be blocked, including those in trusted locations or signed by trusted publishers. This provides maximum protection against internet-based macro threats.\r\n\r\nIf you disable or don't configure this policy setting, the default behavior applies where macros from the internet are blocked except when the file is in a trusted location or signed by a trusted publisher.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockmotwmacrointrustedorsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockmotwmacrointrustedorsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockvbamacrotrusteddocument","displayName":"Turn off Trusted Documents for VBA macros (User)","description":"This policy setting allows you to turn off the Trusted Documents feature for documents containing VBA macros.\r\n\r\nIf you enable this policy setting, users will always see security notifications for VBA macros in documents. When users click \"Enable Content\" for VBA macros, Office will not create a trust record for the document, ensuring that the user is prompted every time they open the document.\r\n\r\nIf you disable or don't configure this policy setting, the Trusted Documents feature allows users to always allow VBA macros in a document so that the user is not prompted the next time they open that document. Trusted documents are exempt from security notifications.\r\n\r\nNote: Enabling this policy setting does not clear existing trusted documents that were previously trusted.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockvbamacrotrusteddocument_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockvbamacrotrusteddocument_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_enablemacrotrustlevel","displayName":"Enable macro trust levels (User)","description":"This policy setting controls whether macro trust levels are enabled, which classifies VBA macros into four security levels based on file location and digital signature status.\r\n\r\nIf you enable this policy setting, VBA macros will be classified into the following trust levels with corresponding user experiences:\r\n\r\n- Lowest (Most Trusted): Files signed by a trusted publisher, saved to a trusted location, or unsaved files.\r\n - User Experience: No Message Bar displayed, macros load normally.\r\n\r\n- Lower: Files opened from a connected personal or business OneDrive account, connected SharePoint location, or local OneDrive folders.\r\n - User Experience: Yellow Message Bar with Enable Content option.\r\n\r\n- Moderate: Files opened from intranet locations, or signed with an extended validation (EV) certificate but not by a trusted publisher.\r\n - User Experience: Yellow Message Bar with a Learn More option. This encourages security awareness by requiring additional steps before enabling macros.\r\n\r\n- Highest (Least Trusted): All other files.\r\n - User Experience: Red Message Bar with macros blocked.\r\n\r\nWhen enabled, unsaved files containing macros will display a warning dialog when users attempt to save the file to local disk, informing them that saving locally may block macro execution when the file is reopened.\r\n\r\nIf you disable or don't configure this policy setting, macro trust levels are not enabled and the standard macro security behavior applies.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_enablemacrotrustlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_enablemacrotrustlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_requirealwaysonmacrosig","displayName":"Require trusted publisher signatures for macros that are always loaded (User)","description":"This policy setting controls signature requirements for macros that are automatically loaded when Office applications start.\r\n\r\nMacros that are always loaded include VBA add-ins and templates that load automatically: Excel add-ins (xla/xlam), PowerPoint add-ins (ppa/ppam), Access add-ins (accda/mda), and Word templates (dot/dotm).\r\n\r\nIf you enable this policy setting:\r\n- Unsigned macros that are always loaded are silently disabled and don't load.\r\n- Signed but untrusted macros that are always loaded display a red Message Bar with no option for users to enable them for the current session.\r\n- Macros signed by a trusted publisher are allowed to always load.\r\n\r\nIf you disable or don't configure this policy setting, macros that are always on can load without requiring trusted publisher signatures.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_requirealwaysonmacrosig_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_requirealwaysonmacrosig_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_restrictcucomaddin","displayName":"Block loading of COM/VSTO add-ins registered in HKCU (User)","description":"This policy setting controls whether COM/VSTO add-ins registered only in HKEY_CURRENT_USER (HKCU) are blocked from loading.\r\n\r\nStandard users can install add-ins through ClickOnce deployment or the Office Add-ins settings, which typically register add-ins in HKCU rather than HKEY_LOCAL_MACHINE (HKLM).\r\n\r\nIf you enable this policy setting, all COM/VSTO add-ins registered only in HKCU will be blocked from loading, preventing users from running add-ins they have installed without administrator privileges.\r\n\r\nIf you disable or don't configure this policy setting, COM/VSTO add-ins registered in HKCU are allowed to load normally.\r\n\r\nNote: Add-ins registered in HKLM (typically installed by administrators) are not affected by this policy setting.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_restrictcucomaddin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_restrictcucomaddin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_vbadigsigchaintrustedpublishers","displayName":"Allow root or intermediate certificates as VBA trusted publishers (User)","description":"This policy setting controls whether root and intermediate certificates can be added as trusted publishers for VBA macro validation when the VBA Macro Notification Settings policy is set to \"Disable all except digitally signed macros\".\r\n\r\nIf you enable this policy setting, administrators can add root or intermediate certificates to the trusted publishers store. VBA macros signed by any certificate that chains to these trusted root or intermediate certificates will be considered as signed by a trusted publisher and allowed to run.\r\n\r\nIf you disable or don't configure this policy setting, only end (leaf) certificates can be added as trusted publishers.\r\n\r\nNote: This policy setting only takes effect when the VBA Macro Notification Settings policy is set to \"Disable all except digitally signed macros\".","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_vbadigsigchaintrustedpublishers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_vbadigsigchaintrustedpublishers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v22~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelastmileinappmessaging","displayName":"Disable Last-Mile In-App Messages (User)","description":"This policy setting prevents Office from displaying bizbar messages to the user about last-mile (environmental) issues affecting their experience.\r\n\r\nIf you disable or don’t configure this policy setting, Office will display last-mile messages by default as they are encountered.\r\n\r\nIf you enable this policy setting, Office will not display the configured last-mile in-app messages when they are encountered.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v22~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelastmileinappmessaging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v22~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelastmileinappmessaging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockinsecureprotocols","displayName":"Block Insecure Protocols (User)","description":"\r\n\t\t\tThis policy setting allows you to control which protocols can be used when opening documents in Microsoft 365 apps.\r\n\r\n\t\t\tIf you enable this policy setting, non-HTTPS links will be blocked when opening documents in Microsoft 365 apps.\r\n\r\n\t\t\tIf you disable this policy setting, all protocols and links will be allowed when opening documents in Microsoft 365 apps.\r\n\r\n\t\t\tIf you don't configure this policy setting, all protocols and links will be allowed when opening documents in Microsoft 365 apps.\r\n\t\t","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockinsecureprotocols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockinsecureprotocols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockolegraph","displayName":"Block OLE Graph (User)","description":"This policy setting allows you to control whether Object Linking and Embedding (OLE) Graph functionality runs in Microsoft 365 apps.\r\n\r\nIf you enable this policy setting, OLE Graph, including MSGraph.Application and MSGraph.Chart, will not run in any Microsoft 365 app. Instead, a static image will render in its place.\r\n\r\nIf you disable this policy setting, OLE Graph will run in Microsoft 365 apps.\r\n\r\nIf you don't configure this policy setting, OLE Graph will run in Microsoft 365 apps.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockolegraph_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockolegraph_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockorgchart","displayName":"Block OrgChart (User)","description":"This policy setting allows you to control whether Organization Chart (OrgChart) Add-in for Microsoft Office programs runs in Microsoft 365 apps.\r\n\r\nIf you enable this policy setting, OrgChart will not run in any Microsoft 365 app. Instead, a static image will render in its place.\r\n\r\nIf you disable this policy setting, OrgChart will run in Microsoft 365 apps.\r\n\r\nIf you don't configure this policy setting, OrgChart will run in Microsoft 365 apps.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockorgchart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockorgchart_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockwecfallback","displayName":"Restrict Apps from FPRPC Fallback (User)","description":"\r\n\t\t\tThis policy setting allows you to control the fallback behavior of Microsoft 365 apps when using FrontPage Server Extensions Remote Procedure Call Protocol (FPRPC).\r\n\r\n\t\t\tIf you enable this policy setting, Microsoft 365 apps will not use FPRPC.\r\n\r\n\t\t\tIf you disable this policy setting, Microsoft 365 apps will continue to use FPRPC.\r\n\r\n\t\t\tIf you don't configure this policy setting, Microsoft 365 apps will continue to use FPRPC.\r\n\t\t","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockwecfallback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockwecfallback_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3.1~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableroamingmruforonpremservers","displayName":"Turn off roaming of on-premises file names and metadata (User)","description":"\r\nThis policy setting controls whether file names and metadata for Office files are roamed and appear in the list of recently opened files in an Office app, such as Word, on different devices.\r\n\r\nRoaming, which relies on a web-based Microsoft service, occurs when a user signs into Office with the same work or school account on different devices.\r\n\r\nNote: This policy setting only applies to Office files that are saved to on-premises instances of SharePoint Server or OneDrive for Business.\r\n\r\nIf you enable this policy setting, file names and metadata won't roam and won’t appear in the list of recently opened files in Office apps on other devices, unless the file has been opened on that device.\r\n\r\nIf you disable or don't configure this policy setting, file names and metadata will roam and will appear in the list of recently opened files in Office apps on other devices, even if the file hasn’t been opened on that device.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v3.1~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableroamingmruforonpremservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3.1~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableroamingmruforonpremservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_collaborationsettings_l_documentchat","displayName":"Allow co-authors to chat within a document (User)","description":"This policy setting controls whether co-authors can use the chat functionality within an Office application to collaborate with each other when editing a document.\r\n\r\nIf you enable or don’t configure this policy setting, users can chat with each other when co-authoring a document.\r\n\r\nIf you disable this policy setting, users can’t chat with each other when co-authoring a document.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_collaborationsettings_l_documentchat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_collaborationsettings_l_documentchat_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser","displayName":"Default Office theme (User)","description":"This policy setting allows you to select the user interface (UI) theme used by Office, if the user has not already selected an Office theme.\r\n\r\nNote: This setting only applies to Version 1903 or later of Office.\r\n\r\nIf you enable this policy setting, you may choose the Office theme used in cases where the user has not selected an Office theme themselves.\r\n\r\nIf you disable or do not configure this policy setting, Office will use the Colorful theme in cases where the user has not selected an Office theme themselves.\r\n\r\nRegardless of how you configure this policy setting, users can change their Office theme by going to File > Account > Office Theme (or, in Outlook, by going to File > Office Account > Office Theme).\r\n\r\nNote: The “Default Office theme” policy setting located under Computer Configuration takes precedence over this policy setting.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum","displayName":"Theme: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_0","displayName":"Colorful","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_3","displayName":"Dark Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_4","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_5","displayName":"White","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableroamingmruforonpremservers","displayName":"Turn off roaming of on-premises file names and metadata (User)","description":"\r\nThis policy setting controls whether file names and metadata for Office files are roamed and appear in the list of recently opened files in an Office app, such as Word, on different devices.\r\n\r\nRoaming, which relies on a web-based Microsoft service, occurs when a user signs into Office with the same work or school account on different devices.\r\n\r\nNote: This policy setting only applies to Office files that are saved to on-premises instances of SharePoint Server or OneDrive for Business.\r\n\r\nIf you enable this policy setting, file names and metadata won't roam and won’t appear in the list of recently opened files in Office apps on other devices, unless the file has been opened on that device.\r\n\r\nIf you disable or don't configure this policy setting, file names and metadata will roam and will appear in the list of recently opened files in Office apps on other devices, even if the file hasn’t been opened on that device.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableroamingmruforonpremservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableroamingmruforonpremservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_miscellaneous437_l_officeinsideruserexperience","displayName":"Show the option for Office Insider (User)","description":"This policy setting controls whether the option for Office Insider is shown under File > Account in an Office app, such as Word.\r\n\r\nBy showing this option, a user can choose to join or leave the Office Insider program. For more information about the Office Insider program, see https://insider.office.com.\r\n\r\nIf you enable this policy setting, the option for Office Insider is shown under File > Account.\r\n\r\nNote: if you enable this policy setting, you shouldn’t enable and configure the “Update Channel” or the “Update Path” policy setting under Computer Configuration\\Policies\\Administrative Templates\\Microsoft Office 2016 (Machine)\\Updates. If you do, those policy settings will take precedence, even though the option for Office Insider is shown.\r\n\r\nIf you disable this policy setting, the option for Office Insider is not shown under File > Account.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus, and to subscription versions of Project and Visio.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_miscellaneous437_l_officeinsideruserexperience_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_miscellaneous437_l_officeinsideruserexperience_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_forceruntimeavscan","displayName":"Force Runtime AV Scan (User)","description":"This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus or Visio Pro for Office 365. \r\n\r\nThis policy setting controls when Office files are scanned at runtime by an installed Anti-Virus software.\r\n\r\nNote, files will only be scanned if the Anti-Virus software registers as a provider for runtime scanning.\r\n\r\nIf you enable this policy setting, Office applications will submit all files for a runtime scan by Antivirus.\r\n\r\nIf you disable or do not configure this policy setting, Office will selectively submit certain files, for example encrypted files, for a runtime scan by Antivirus.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_forceruntimeavscan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_forceruntimeavscan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_useofficeforlabelling","displayName":"Use the Sensitivity feature in Office to apply and view sensitivity labels (User)","description":"This policy setting controls whether sensitivity labels configured by an admin can be applied and viewed by using the Sensitivity feature in an Office app, such as Word, or by using the Microsoft Azure Information Protection add-in, if the add-in is installed and enabled.\r\n\r\nIf you enable this policy setting, the Sensitivity feature in an Office app can be used to apply and view sensitivity labels. If the Microsoft Azure Information Protection add-in is installed, the add-in is prevented from loading, even if the add-in is enabled, and the add-in can’t be used to apply sensitivity labels.\r\n\r\nIf you disable this policy setting, the Sensitivity feature won’t be available in an Office app and can’t be used to apply or view sensitivity labels. If the Microsoft Azure Information Protection add-in is installed and enabled, the add-in will be allowed to load and can be used to apply sensitivity labels.\r\n\r\nIf you don’t configure this policy setting:\r\n\r\n- If the Microsoft Azure Information Protection add-in is installed and enabled, the add-in will be allowed to load and can be used to apply sensitivity labels. The Sensitivity feature won’t be available in an Office app and can’t be used to apply or view sensitivity labels.\r\n- If the Microsoft Azure Information Protection add-in is not installed, or is installed but is disabled, then the Sensitivity feature in an Office app can be used to apply and view sensitivity labels.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_useofficeforlabelling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_useofficeforlabelling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior","displayName":"Control how Office handles form-based sign-in prompts (User)","description":"This policy setting controls how Office applications handle form-based sign-in prompts.​\r\n\r\nIf you enable this policy setting, you must choose one of the following options:​\r\n\r\nBlock all prompts​\r\nAsk the user what to do for each new host​\r\nShow prompts only from allowed hosts​\r\n\r\nIf you select “Block all prompts” then no form-based sign-in prompts are shown to the user and the user is shown a message that the sign-in method isn’t allowed.​\r\n\r\nIf you select “Ask the user what do for each new host” then the user is asked for each new host whether the user wants to sign-in to the host. If the user has previously signed-in to a host, a form-based sign-in prompt is shown for that host. Also, form-based sign-in prompts are shown for any hosts specified by the “Specify hosts allowed to show form-based sign-in prompts to users” setting.\r\n\r\nIf you select “Show prompts only from allowed hosts” then form-based sign-in prompts are shown only from hosts that have been specified by the additional “Specify hosts allowed to show form-based sign-in prompts to users” setting. Form-based sign-in prompts from all other hosts are blocked and the user is shown a message that the sign-in method isn’t allowed.\r\n\r\nNote: If you don’t configure the “Specify hosts allowed to show form-based sign-in prompts to users” setting or don’t specify any hosts in that setting, then the behavior of the “Show prompts only from allowed hosts” option will be the same as if you selected the “Block all prompts” option.\r\n\r\nIf you disable or don’t configure this policy setting, all form-based sign-in prompts are blocked and the user is shown a message that the sign-in method isn’t allowed. But users are able to change the behavior for form-based sign-in prompts by going to File > Options > Trust Center > Trust Center Settings > Form-based sign-in.\r\n\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus, and to subscription versions of Project and Visio.​","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_l_authenticationfbabehaviorenum","displayName":"Behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_l_authenticationfbabehaviorenum_1","displayName":"Block all prompts","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_l_authenticationfbabehaviorenum_2","displayName":"Ask the user what to do for each new host","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_l_authenticationfbabehaviorenum_3","displayName":"Show prompts only from allowed hosts","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_l_authenticationfbaenabledhostsid","displayName":"Specify hosts allowed to show form-based sign-in prompts to users: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_allowvbaintranetrefs","displayName":"Allow VBA to load typelib references by path from untrusted intranet locations (User)","description":"This policy setting permits VBA to load typelib references by explicit path read from the project data if that path points to an intranet location that is not explicitly in the system trusted sites list.\r\n\r\nBy default, VBA will attempt to load typelibs referenced in a project by searching for the library GUID in the registry. If it is not found in the registry, VBA will attempt to load the typelib or project reference using the path stored in the project for the reference as long as the reference does not point to an internet or intranet location that is not in the trusted sites list.\r\n\r\nIf you enable this policy setting, VBA will treat intranet paths like local machine paths, and therefore VBA will attempt to search for unregistered references in intranet locations that are not local machine or in the system's trusted sites list.\r\n\r\nIf you disable or don’t configure this policy setting, VBA maintains its default behavior and will refuse to load typelibs on intranet paths if it does not find the typelib registered in HKEY_CLASSES_ROOT.\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_allowvbaintranetrefs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_allowvbaintranetrefs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_disablestrictvbarefssecuritypolicy","displayName":"Disable additional security checks on VBA library references that may refer to unsafe locations on the local machine (User)","description":"This policy setting restricts VBA to checking project library references only against the registry and trusted zones. By default VBA performs additional checks against library paths to prevent loading references from potentially unsafe locations on the local machine as well. It is recommended that this setting remain 0 or unset to allow for the more secure default behavior. Only enable this setting if the default behavior is causing compatibility issues with critical solutions, and then, only to provide time to migrate the solutions to address the less secure behavior, at which point the setting should be turned off again.\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_disablestrictvbarefssecuritypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_disablestrictvbarefssecuritypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7.updates~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey","displayName":"Allow users to receive and respond to in-product surveys from Microsoft (User)","description":"This policy setting allows you to control whether your users can receive and respond to in-product surveys in Microsoft 365 products. Microsoft will use this feedback to improve the product experience for users. The ability to receive and respond to in-product surveys is enabled by default.\r\n\r\nIf you enable this policy setting, your users will be able to receive and respond to in-product surveys about their experience using Microsoft 365 products.\r\n\r\nIf you disable this policy setting, Microsoft will not survey your users while they are using Microsoft 365 products.\r\n\r\nIf you don't configure this policy setting, your users will be able to receive and respond to in-product surveys about their experience using Microsoft 365 products.\r\n\r\nComing soon, you will be able to view and manage feedback from your org in the Microsoft 365 admin center.\r\n\r\nNote: This data will be considered \"Feedback\" under your Microsoft 365 agreement, including information that would otherwise be considered \"Customer Data\" or \"Personal Data\".\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2142253","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v7.updates~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7.updates~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_miscellaneous437_l_personalizationhomeuseprogram","displayName":"Show in-product notifications for the Microsoft Home Use Program (User)","description":"This policy setting controls whether notifications about the Microsoft Home Use Program (HUP) are displayed to end-users in Office applications.\r\n\r\nIf you enable this policy setting, Office will occasionally notify end-users if they are eligible to purchase an Office subscription for their personal use at a discount via the Microsoft Home Use Program. End-users can permanently opt-out of these notifications at any time using a button within the notification.\r\n\r\nIf you disable this policy setting, Office will not display any notifications related to the Microsoft Home Use Program.\r\n\r\nIf you don't configure this policy setting, Microsoft will control whether or not these notifications appear. Please check the Message Center in the Microsoft 365 admin center for updates on whether this feature has been enabled by Microsoft yet and the default setting for the notifications.\r\n\r\nFor more information, see https://aka.ms/huplearnmore.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_miscellaneous437_l_personalizationhomeuseprogram_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_miscellaneous437_l_personalizationhomeuseprogram_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_emailcollection","displayName":"Allow Microsoft to follow up on feedback submitted by users (User)","description":"This policy setting controls whether Microsoft can follow up on feedback submitted by users to help understand the feedback, troubleshoot an issue submitted through feedback, or share back how Microsoft used the feedback to improve the product.\r\n\r\nMicrosoft may send transactional emails or request follow-up conversations via email, voice, or other means related to the feedback or survey response. In some circumstances, Microsoft may ask for additional information to assist with troubleshooting.\r\n\r\nIf you enable this policy setting, Microsoft may follow up on feedback submitted. \r\n\r\nIf you disable or don’t configure this policy setting, Microsoft will not follow up on feedback submitted by your users.\r\n\r\nComing soon, you will be able to view and manage feedback from your org in the Microsoft 365 admin center.\r\n\r\nNote: This policy setting has no effect if the \"Allow users to submit feedback to Microsoft\" policy setting or the “Allow users to receive and respond to in-product surveys from Microsoft” policy setting is set to Disabled.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2142253","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_emailcollection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_emailcollection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey","displayName":"[Deprecated] Allow users to receive and respond to in-product surveys from Microsoft (User)","description":"This policy setting allows you to control whether your users can receive and respond to in-product surveys in Microsoft 365 products. Microsoft will use this feedback to improve the product experience for users. The ability to receive and respond to in-product surveys is enabled by default.\r\n\r\nIf you enable this policy setting, your users will be able to receive and respond to in-product surveys about their experience using Microsoft 365 products.\r\n\r\nIf you disable this policy setting, Microsoft will not survey your users while they are using Microsoft 365 products.\r\n\r\nIf you don't configure this policy setting, your users will be able to receive and respond to in-product surveys about their experience using Microsoft 365 products.\r\n\r\nComing soon, you will be able to view and manage feedback from your org in the Microsoft 365 admin center.\r\n\r\nNote: This data will be considered \"Feedback\" under your Microsoft 365 agreement, including information that would otherwise be considered \"Customer Data\" or \"Personal Data\".\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2142253","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions","displayName":"Disable 3D Model File Formats List (User)","description":"This policy setting allows you to specify a list of 3D model file formats that will be blocked from being loaded in Office applications.\r\n\r\nIf you enable this policy setting, you can specify a list of 3D Model file format that Office applications will block on insert or load. You should specify the list of 3D model file formats to block in a list of files extensions. For example, to block the FBX extension, enter the string “FBX”. To block the FBX and OBJ extensions, enter the string “FBX; OBJ”.\r\n\r\nIf you disable or do not configure this policy setting, Office applications do not restrict any 3D model file formats.\r\n","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions_l_model3dblocklist","displayName":"List of file extensions to block: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffcameraandmicrophoneinapplicationguard","displayName":"Turn off camera and microphone access for Office apps using Application Guard. (User)","description":"The policy allows you to control whether Office apps using Application Guard can access the user's camera and microphone if they're enabled on the user's device.\r\n\r\nImportant: A compromised Application Guard container could bypass camera and microphone permissions and access the camera and microphone without the user’s knowledge. To prevent unauthorized access, we recommend that the camera and microphone be turned off on the user’s device when they aren’t needed.\r\n\r\nIf you enable this policy setting, Office apps using Application Guard won't be able to access the camera and microphone on the user’s device. \r\n\r\nIf you disable or don't configure this policy setting, Office apps using Application Guard will be able to access the camera and microphone on the user’s device.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffcameraandmicrophoneinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffcameraandmicrophoneinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffclipboardaccessinapplicationguard","displayName":"Don't allow copy and paste from Office documents opened in Application Guard. (User)","description":"This policy setting allows you to control whether users can copy and paste content from Office to and from documents opened in Application Guard.\r\nNote: Application Guard only allows copying text and images and doesn’t allow copying of rich content.\r\n\r\nIf you enable this policy setting, users can't copy and paste content to and from documents opened in Application Guard to other locations outside Application Guard.\r\n\r\nIf you disable or don't configure this policy setting, users can copy and paste content to and from documents opened in Application Guard to other locations outside Application Guard.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffclipboardaccessinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffclipboardaccessinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffhardwareaccelerationinapplicationguard","displayName":"Disable hardware acceleration for Office in Application Guard. (User)","description":"This policy setting controls whether Office in Application Guard uses hardware or software acceleration to render graphics.\r\n\r\nIf you enable this setting, Application Guard uses software-based (CPU) rendering and won’t load any third-party graphics drivers or interact with any connected graphics hardware.\r\n\r\nImportant: Be aware that disabling or not configuring this policy setting with potentially compromised graphics devices or drivers might pose a risk to the user's device.\r\n\r\nIf you disable or don't configure this setting, Application Guard uses Hyper-V to access supported, high-security rendering graphics hardware (GPUs). These GPUs improve rendering performance and battery life while using Application Guard, particularly for video playback and other graphics-intensive operations. If you disable or don't configure this setting without connecting any high-security rendering graphics hardware, Application Guard will automatically revert to software-based (CPU) rendering.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise. ","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffhardwareaccelerationinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffhardwareaccelerationinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffofficeinapplicationguard","displayName":"Don't use Application Guard with Office. (User)","description":"This policy setting allows you to control whether Office apps use Application Guard to isolate untrusted documents.\r\n\r\nIf you enable this policy setting, Office apps won't use Application Guard to isolate untrusted documents even if the device is configured to use Application Guard. Instead, Office will use Protected View to isolate untrusted documents.\r\n\r\nNote: You should consider enabling this policy setting if you want to stop Office apps from using Application Guard without impacting the use of Application Guard with other applications.\r\n\r\nIf you disable or don't configure this policy settings, Office apps will use Application Guard to isolate untrusted documents. The device must be configured to use Application Guard and the user must be licensed to use Application Guard.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffofficeinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffofficeinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard","displayName":"Restrict printing from Office of documents opened in Application Guard. (User)","description":"This policy setting allows you to control how users can print from Office documents opened in Application Guard. \r\nIf you enable this policy setting, you can choose to selectively retrict one or more of the following printing options.\r\n- Don't allow printing to XPS, prevents users from printing as XPS and saving the resulting file on the host. \r\n- Don't allow printing to PDF, prevents users from printing as PDF and saving the resulting file on the host. \r\n- Don't allow printing to local printers, prevents users from printing to locally attached printers. \r\n- Don't allow printing to existing network printers, prevents users from printing to previously connected network printers. Also, users can't search for additional printers.\r\nNote: if you select all the choices or don’t select any of the choices, then printing isn’t allowed in Application Guard.\r\n\r\nIf you disable or don’t configure this policy setting, users can print to all printers configured on their device.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnofflocalprintinginapplicationguard","displayName":"Disable Local printing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnofflocalprintinginapplicationguard_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnofflocalprintinginapplicationguard_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffnetworkprintinginapplicationguard","displayName":"Disable Network printing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffnetworkprintinginapplicationguard_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffnetworkprintinginapplicationguard_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffpdfprintinginapplicationguard","displayName":"Disable PDF printing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffpdfprintinginapplicationguard_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffpdfprintinginapplicationguard_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffxpsprintinginapplicationguard","displayName":"Disable XPS printing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffxpsprintinginapplicationguard_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffxpsprintinginapplicationguard_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnofftrustpromotionfordocumentsinapplicationguard","displayName":"Prevent users from removing Application Guard protection on files. (User)","description":"This policy setting allows you to control whether users can remove Application Guard protection and open a document with full trust in Office.\r\n\r\nIf you enable this policy setting, users can continue to work with Office documents in Application Guard, however, they cannot remove protection and open a document outside Application Guard.\r\n\r\nIf you disable or do not configure this policy settings, Office will by default allow users to remove protection and open a document with full trust.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnofftrustpromotionfordocumentsinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnofftrustpromotionfordocumentsinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_logcollection","displayName":"Allow users to include log files and content samples when they submit feedback to Microsoft (User)","description":"This policy setting controls whether your users see an option to include log files and content samples when they submit feedback to Microsoft.\r\n\r\nLog files and content samples help Microsoft troubleshoot product issues and Microsoft will use this information to improve product experiences for users. The option to include log files and content samples when submitting feedback to Microsoft is disabled by default.\r\n\r\nIf you enable this policy setting, your users will see an option to include log files and content samples when they submit feedback to Microsoft.\r\n\r\nIf you disable or don’t configure this policy setting, your users will not see an option to include log files and content samples when they submit feedback to Microsoft.\r\n\r\nComing soon, you will be able to view and manage feedback from your org in the Microsoft 365 admin center.\r\n\r\nNote: This policy setting has no effect if the \"Allow users to submit feedback to Microsoft\" policy setting is set to Disabled.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2142253","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_logcollection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_logcollection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_onlytrustvbasignaturev3","displayName":"Only trust VBA macros that use V3 signatures (User)","description":"This policy setting controls whether only VBA macros that use V3 signatures can be trusted and run in the application.\r\n\r\nIf you enable this policy setting, only VBA macros that use V3 signatures can be trusted and run in the application.\r\n\r\nIf you enable this policy setting, we also recommend that you enable the “VBA Macro Notification Settings” policy setting for the application and then select the “Disable all except digitally signed macros” option.\r\n\r\nNote: Before enabling this policy setting, you should upgrade your existing VBA macros to use V3 signatures.\r\n\r\nIf you disable or don’t configure this policy setting, VBA macros signed with legacy signature schemes can be trusted and run in the application.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_onlytrustvbasignaturev3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_onlytrustvbasignaturev3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_configureprecreateinapplicationguard","displayName":"Configure Application Guard container precreation. (User)","description":"This policy setting determines if the Application Guard container, for isolating untrusted files, is pre-created for improved run time performance.\r\n\r\nIf you enable this policy setting, you can specify the number of days to continue pre-creating an Application Guard container if the user has not opened a file with Application Guard. Pre-creating a container when the user logs in will decrease the wait time when opening an untrusted file.\r\n\r\n“65535” will configure Office to always create an Application Guard container when a user logs into Windows.\r\n\"20\" will configure Office to pre-create the container each time a user logs into Windows for up to 20 days after the last time the user opened an untrusted file using Application Guard.\r\n“0” will configure Office to never pre-create the container. Instead the container will only be created when a user opens their first untrusted file after logging into Windows.\r\n\r\nNote: if you configure Office to never pre-create a container then users will experience a longer wait when opening an untrusted file after logging into Windows.\r\n\r\nIf you disable or don’t configure this setting, Office will use a built-in heuristic to pre-create the container.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_configureprecreateinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_configureprecreateinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_configureprecreateinapplicationguard_l_setappguardprewarmwindowvalue","displayName":"Pre-Create Window (days): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser","displayName":"Show the option for the Office Update Channel experience (User)","description":"This policy setting controls whether the option for Update Channel experience is shown under File > Account on an Office app, such as Word.\r\n\r\nBy showing this option, a user can choose to receive Office updates from the Office update channels that the administrator chooses to expose to the users.\r\n\r\nIf you enable this policy setting, the option for Update Channel experience is shown under File > Account.\r\n\r\nNote: This policy supersedes the “Show the option for Office Insider” in cases where both policies are configured.\r\n\r\nNote: If you enable this policy setting, you shouldn’t enable and configure the “Target Version”, “Update Channel” or the “Update Path” policy setting under Computer Configuration\\Policies\\Administrative Templates\\Microsoft Office 2016 (Machine)\\Updates. If you do, those policy settings will take precedence, blocking user access to the Office Update Channel experience.\r\n\r\nIf you disable this policy setting, the option for Office Channel experience is not shown under File > Account.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderfast","displayName":"Beta Channel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderfast_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderfast_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderslow","displayName":"Current Channel (Preview) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderslow_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderslow_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_mec","displayName":"Monthly Enterprise Channel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_mec_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_mec_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_production","displayName":"Current Channel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_production_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_production_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_sae","displayName":"Semi-Annual Enterprise Channel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_sae_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_sae_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_saepreview","displayName":"Semi-Annual Enterprise Channel (Preview) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_saepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_saepreview_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffblockingofunsupportedfiletypesinapplicationguard","displayName":"Turn off protection of unsupported file types in Application Guard for Office. (User)","description":"This policy setting controls whether Application Guard for Office will block unsupported file types from being opened in Office apps or if it will enable the redirection to Protected View.\r\n\r\nIf you enable this setting, Application Guard for Office will redirect unsupported file types to Protected View in Office apps.\r\n\r\nImportant: Be aware that enabling this policy setting might pose a risk to the user's device.\r\n\r\nIf you disable or don't configure this setting, Application Guard for Office will block unsupported file types in Office apps.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffblockingofunsupportedfiletypesinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffblockingofunsupportedfiletypesinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites","displayName":"Configure team site libraries to sync automatically (User)","description":"This setting lets you specify SharePoint team site libraries to sync automatically the next time users sign in to the OneDrive sync app (OneDrive.exe). It may take up to 8 hours after a users signs in before the library begins to sync. To use the setting, you must enable OneDrive Files On-Demand, and the setting applies only for users on computers running Windows 10 (1709) Fall Creators Update or later. Do not enable this setting for the same library to more than 1,000 devices. To ensure a good sync experience, avoid enabling this feature on large libraries sets (For the most up to date guidance see https://docs.microsoft.com/en-us/onedrive/use-group-policy#AutoMountTeamSites). This feature is not enabled for on-premises SharePoint sites.\r\n \r\nIf you enable this setting, the OneDrive sync app will automatically download the contents of the libraries you specified as online-only files the next time the user signs in. The user won't be able to stop syncing the libraries.\r\n \r\nIf you disable this setting, team site libraries that you've specified won't be automatically synced for new users. Existing users can choose to stop syncing the libraries, but the libraries won't stop syncing automatically.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_automountteamsiteslistbox","displayName":"Libraries: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_automountteamsiteslistbox_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_automountteamsiteslistbox_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir","displayName":"Set the default location for the OneDrive folder (User)","description":"This setting lets you set a specific path as the default location of the OneDrive folder on users' computers. By default, the path is under %userprofile%.\r\n\r\nIf you enable this setting, the default location of the OneDrive - {organization name} folder will be the path that you specify in the OneDrive.admx file. To prevent users from changing the location you specify, enable the \"Prevent users from changing the location of their OneDrive folder\" setting.\r\n\r\nIf you disable or do not configure this setting, the default location of the OneDrive - {organization name} folder will be in %userprofile%.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_defaultrootdirlist","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_defaultrootdirlist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_defaultrootdirlist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot","displayName":"Prevent users from changing the location of their OneDrive folder (User)","description":"This setting lets you block users from changing the location of their OneDrive - {organization name} folder during setup of the OneDrive sync app.\r\n\r\nIf you enable this setting, the \"Change location\" link is hidden in OneDrive Setup. The OneDrive folder will be created in the default location, or in the custom location you specified if you enabled the \"Set the default location for the OneDrive folder\" setting.\r\n\r\nIf you disable or do not configure this setting, users can click the \"Change location\" link to change the location of their OneDrive folder in OneDrive Setup.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_disablecustomrootlist","displayName":"Change location setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_disablecustomrootlist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_disablecustomrootlist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablefretutorial","displayName":"Disable the tutorial that appears at the end of OneDrive Setup (User)","description":"This setting lets you prevent the tutorial from launching in a web browser at the end of OneDrive Setup.\r\n\r\nIf you enable this setting, users will not see the tutorial after they complete OneDrive Setup.\r\n\r\nIf you disable or do not configure this setting, the tutorial will appear at the end of OneDrive Setup.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablefretutorial_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablefretutorial_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonbatterysaver","displayName":"Continue syncing when devices have battery saver mode turned on (User)","description":"This setting lets you turn off the auto-pause feature for devices that have battery saver mode turned on.\r\n\r\nIf you enable this setting, syncing will continue when users turn on battery saver mode. OneDrive will not automatically pause syncing.\r\n\r\nIf you disable or do not configure this setting, syncing will pause automatically when battery saver mode is detected and a notification will be displayed. Users can choose not to pause syncing by clicking \"Sync Anyway\" in the notification. When syncing is paused, users can resume syncing by clicking the OneDrive cloud icon in the notification area of the taskbar and then clicking the alert at the top of the activity center.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonbatterysaver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonbatterysaver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonmeterednetwork","displayName":"Continue syncing on metered networks (User)","description":"This setting lets you turn off the auto-pause feature when devices connect to metered networks.\r\n\r\nIf you enable this setting, syncing will continue when devices are on a metered network. OneDrive will not automatically pause syncing.\r\n\r\nIf you disable or do not configure this setting, syncing will pause automatically when a metered network is detected and a notification will be displayed. Users can choose not to pause syncing by clicking \"Sync Anyway\" in the notification. When syncing is paused, uers can resume syncing by clicking the OneDrive cloud icon in the notification area of the taskbar and then clicking the alert at the top of the activity center.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonmeterednetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonmeterednetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepersonalsync","displayName":"Prevent users from syncing personal OneDrive accounts (User)","description":"This setting lets you block users from signing in with a Microsoft account to sync their personal OneDrive files.\r\n\r\nIf you enable this setting, users will be prevented from setting up a sync relationship for their personal OneDrive account. Users who are already syncing their personal OneDrive when you enable this setting won't be able to continue syncing (and will be shown a message that syncing has stopped), but any files synced to the computer will remain on the computer.\r\n\r\nIf you disable or do not configure this setting, users can sync their personal OneDrive accounts.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepersonalsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepersonalsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_downloadbandwidthlimit","displayName":"Limit the sync app download speed to a fixed rate (User)","description":"This setting lets you configure the maximum speed at which the OneDrive sync app (OneDrive.exe) can download files. This rate is a fixed value in kilobytes per second, and applies only to syncing, not to downloading updates. The lower the rate, the slower files will download. The minimum rate that can be set is 1 KB/s and the maximum rate is 100000 KB/s. Any input lower than 50 KB/s will set the limit to 50 KB/s, even if the UI shows the inputted rate.\r\nIf you enable this setting, computers will use the maximum download rate that you specify, and users will not be able to change it.\r\n\r\nIf you disable or do not configure this setting, users can choose to limit the download rate in OneDrive sync app settings.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_downloadbandwidthlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_downloadbandwidthlimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_downloadbandwidthlimit_downloadratevalue","displayName":"Bandwidth: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_enableallocsiclients","displayName":"Coauthor and share in Office desktop apps (User)","description":"This setting lets multiple users use the Office 365 ProPlus, Office 2019, or Office 2016 desktop apps to simultaneously edit an Office file stored in OneDrive. It also lets users share files from the Office desktop apps.\r\n\r\nIf you enable this setting, coauthoring and sharing in the Office desktop apps is enabled. Users can disable these features by opening the OneDrive sync app settings, clicking the Office tab, and clearing the \"Use Office applications to sync Office files that I open\" check box.\r\n\r\nIf you disable this setting, coauthoring and sharing in the Office desktop apps is disabled, and the Office tab is hidden in sync app. The \"Office file conflicts\" setting will also be disabled and when two versions of a file conflict, both copies will be kept.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_enableallocsiclients_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_enableallocsiclients_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_enableholdthefile","displayName":"Allow users to choose how to handle Office file sync conflicts (User)","description":"This setting specifies what happens when there's a conflict between Office file versions during sync. By default, users can decide if they want to merge changes or keep both copies. Users can also change settings in the OneDrive sync app to always keep both copies. (This option is available for Office 2016 or later only. With earlier versions of Office, both copies are always kept.)\r\n\r\nIf you enable this setting or do not configure this setting, users can decide if they want to merge changes or keep both copies. Users can also select in OneDrive sync app settings to keep both copies.\r\n\r\nIf you disable this setting, both copies of the file will be kept when versions of a file conflict. Users won't be able to change the setting and merge changes.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_enableholdthefile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_enableholdthefile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit","displayName":"Limit the sync app upload speed to a fixed rate (User)","description":"This setting lets you configure the maximum speed at which the OneDrive sync app (OneDrive.exe) can upload files. This rate is a fixed value in kilobytes per second. The lower the rate, the slower the computer will upload files. The minimum rate that can be set is 1 KB/s and the maximum rate is 100000 KB/s. Any input lower than 50 KB/s will set the limit to 50 KB/s, even if the UI shows the inputted rate.\r\n\r\nIf you enable this setting, computers will use the maximum upload rate that you specify, and users will not be able to change it in OneDrive settings.\r\n\r\nIf you disable or do not configure this setting, users can choose to limit the upload rate to a fixed value (in KB/second), or set it to \"Adjust automatically\" which will use 70% of upload throughput to respond to increases and decreases in throughput.\r\n\r\nInstead of using this setting to limit the upload rate, we recommend enabling \"Limit the sync app upload rate to a percentage of throughput\" to set a limit that adjusts to changing conditions. You should not enable both settings at the same time.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit_uploadratevalue","displayName":"Bandwidth: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv4~policy~onedrivengsc_kfmforcewindowsdisplaylanguage","displayName":"Always use the user's Windows display language when provisioning known folders in OneDrive (User)","description":"When you move Windows known folders to OneDrive, they will be provisioned in the user's Windows display language by default, unless the user sets a different preferred language. This setting lets you override the user's preferred language setting. It works with both Known Folder Move settings (\"Silently move Windows known folders to OneDrive\" and \"Prompt users to move Windows known folders to OneDrive\").\r\n\r\nIf you enable this setting, known folders will be provisioned using the user's Windows display language, even if the user sets a different preferred language.\r\n\r\nIf you disable or do not configure this setting, and the user set a preferred language, their known folders will be provisioned in OneDrive using that language. The known folders on their PC will appear in their preferred language.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv4~policy~onedrivengsc_kfmforcewindowsdisplaylanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv4~policy~onedrivengsc_kfmforcewindowsdisplaylanguage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_disablefreanimation","displayName":"Disable animation that appears during OneDrive Setup (User)","description":"This setting lets you prevent the animation from showing during OneDrive Setup.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_disablefreanimation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_disablefreanimation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_enableautostart","displayName":"Start OneDrive automatically when signing in to Windows (User)","description":"This setting overrides a user's choice, ensuring OneDrive will automatically start every time they sign in to Windows. \r\n \r\nIf you configure this setting, OneDrive will start automatically when a user signs in to Windows. The OneDrive sync app must be restarted after this setting is enabled for the setting to take effect.\r\n\r\nIf you do not configure this setting or set it to any value other than 1, the user can choose to automatically start OneDrive (default choice) or to disable OneDrive from starting in OneDrive sync app settings.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_enableautostart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_enableautostart_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_disableinstalledonenoteaddins","displayName":"Disable installed OneNote Add-ins (User)","description":"Turns off all of the installed OneNote Add-ins.","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_disableinstalledonenoteaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_disableinstalledonenoteaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_disableonenotecomapi","displayName":"Disable OneNote COM API (User)","description":"Disable OneNote COM API - this disables add-on applications that may use the COM API. Note that it also breaks other features that use this API such as sending information from Outlook to OneNote.","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_disableonenotecomapi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_disableonenotecomapi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\OneNote\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\OneNote\\Addins.\r\n\r\nYou can also obtain the ProgID of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook","displayName":"Choose default codec to be used for Video notebook (User)","description":"This option will set the default codec used by OneNote for video recording that are created in OneNote.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec","displayName":"Choose the Windows Media Video 8 codec: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for color pocket pcs (150 kbps)","displayName":"Color Pocket PCs (150 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for dial-up modems or single-channel isdn (28.8 to 56 kbps)","displayName":"Dial-up Modems or Single-channel ISDN (28.8 to 56 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for lan, cable modem, or xdsl (100 to 768 kbps)","displayName":"LAN, Cable Modem, or xDSL (100 to 768 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for dial-up modems or lan (28.8 to 100 kbps)","displayName":"Dial-up Modems or LAN (28.8 to 100 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for dial-up modems (28.8 kbps)","displayName":"Dial-up Modems (28.8 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for dial-up modems (56 kbps)","displayName":"Dial-up Modems (56 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for local area network (100 kbps)","displayName":"Local Area Network (100 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for local area network (256 kbps)","displayName":"Local Area Network (256 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for local area network (384 kbps)","displayName":"Local Area Network (384 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for broadband (ntsc, 700 kbps)","displayName":"Broadband (NTSC, 700 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for broadband (ntsc, 1400 kbps)","displayName":"Broadband (NTSC, 1400 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for broadband (pal, 384 kbps)","displayName":"Broadband (PAL, 384 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for broadband (pal, 700 kbps)","displayName":"Broadband (PAL, 700 Kbps)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_disableaudosearch","displayName":"Disable audio search (User)","description":"Disables OneNote audio search feature.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_disableaudosearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_disableaudosearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_disablelinkedaudiofeature","displayName":"Disable Linked Audio feature (User)","description":"This policy setting allows you to configure the Record Audio and the Record Video commands on the Insert tab.\r\n\r\nIf you enable this policy setting, the commands will be not be available.\r\n\r\nIf you disable or do not configure this policy, the commands will be available.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_disablelinkedaudiofeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_disablelinkedaudiofeature_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_rewindfromstartofparagraphbythefollowingnumberofseconds","displayName":"Rewind from start of paragraph by the following number of seconds (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_rewindfromstartofparagraphbythefollowingnumberofseconds_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_rewindfromstartofparagraphbythefollowingnumberofseconds_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_rewindfromstartofparagraphbythefollowingnumberofseconds_l_rewindfromstartofparagraphbysec","displayName":"Rewind from start of paragraph by: (sec) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofbitstosamplewhenrecording","displayName":"Specify number of bits to sample when recording (User)","description":"Specifies the default number of bits per sample (value is in kbps) used when recording audio. If the appropriate codec is found, then this is the default bit depth used in the Format setting for Linked Audio, found under File tab | Options | Audio & Video.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofbitstosamplewhenrecording_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofbitstosamplewhenrecording_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofbitstosamplewhenrecording_l_bits","displayName":"Bits: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofchannelstorecord","displayName":"Specify number of channels to record (User)","description":"Specifies whether 1 or 2 channels are used when recording audio. If the appropriate codec is found, then this is the default number of channels used in the Format setting for Linked Audio found under File tab | Options | Audio & Video.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofchannelstorecord_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofchannelstorecord_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofchannelstorecord_l_channels12","displayName":"Channels (1-2): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifyratetosampleaudiobitssecond","displayName":"Specify rate to sample audio (bits/second) (User)","description":"Specifies the default sample rate (value is in kHz) used when recording audio. If the appropriate codec is found, then this is the default sample rate used in the Format setting for Linked Audio found under File tab | Options | Audio & Video.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifyratetosampleaudiobitssecond_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifyratetosampleaudiobitssecond_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifyratetosampleaudiobitssecond_l_bitssecond","displayName":"Bits/Second: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook","displayName":"Automatically back up my notebook... (User)","description":"Checks/Unchecks the option ''Automatically back up my notebook at the following time interval''.","helpText":"","infoUrls":[],"categoryId":"c02141e6-0725-4f6f-9138-83d10c6bc104","categoryName":"Backup","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin","displayName":"Automatically back up at this interval (min): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c02141e6-0725-4f6f-9138-83d10c6bc104","categoryName":"Backup","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_2","displayName":"2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_3","displayName":"3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_4","displayName":"4","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_5","displayName":"5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_10","displayName":"10","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_15","displayName":"15","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_30","displayName":"30","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_60","displayName":"60","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_120","displayName":"120","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_180","displayName":"180","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_240","displayName":"240","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_300","displayName":"300","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_360","displayName":"360","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_480","displayName":"480","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_720","displayName":"720","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_960","displayName":"960","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_1440","displayName":"1440","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_2880","displayName":"2880","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_4320","displayName":"4320","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_5760","displayName":"5760","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_7200","displayName":"7200","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_8640","displayName":"8640","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_10080","displayName":"10080","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_20160","displayName":"20160","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_30240","displayName":"30240","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_40320","displayName":"40320","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_50400","displayName":"50400","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_60480","displayName":"60480","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_checktoenableautomaticbackup","displayName":"Check to enable automatic backup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c02141e6-0725-4f6f-9138-83d10c6bc104","categoryName":"Backup","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_checktoenableautomaticbackup_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_checktoenableautomaticbackup_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_numberofbackupcopiestokeep","displayName":"Number of backup copies to keep (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"c02141e6-0725-4f6f-9138-83d10c6bc104","categoryName":"Backup","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_numberofbackupcopiestokeep_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_numberofbackupcopiestokeep_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_numberofbackupcopiestokeep_l_numberofbackupcopiestokeep2","displayName":"Number of backup copies to keep (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c02141e6-0725-4f6f-9138-83d10c6bc104","categoryName":"Backup","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_navigationbarappearsontheright","displayName":"Navigation bar appears on the right (User)","description":"This option is to specify where the navigation bar appears.","helpText":"","infoUrls":[],"categoryId":"44774d3d-387b-4fa7-8de4-d82b039c06d1","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_navigationbarappearsontheright_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_navigationbarappearsontheright_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_pagetabsappearontheleft","displayName":"Page tabs appear on the left (User)","description":"Right: Unchecks the option ''Page tabs appear on the left''. | Left: Checks the option ''Page tabs appear on the left''.","helpText":"","infoUrls":[],"categoryId":"44774d3d-387b-4fa7-8de4-d82b039c06d1","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_pagetabsappearontheleft_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_pagetabsappearontheleft_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_pagetabsappearontheleft_l_specifylocationofthepagetabcontrol","displayName":"Specify location of the page tab control: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44774d3d-387b-4fa7-8de4-d82b039c06d1","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_pagetabsappearontheleft_l_specifylocationofthepagetabcontrol_0","displayName":"Right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_pagetabsappearontheleft_l_specifylocationofthepagetabcontrol_1","displayName":"Left","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_shownotecontainers","displayName":"Show Note Containers (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"44774d3d-387b-4fa7-8de4-d82b039c06d1","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_shownotecontainers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_shownotecontainers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_verticalscrollbarappearsonleft","displayName":"Vertical scroll bar appears on left (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"44774d3d-387b-4fa7-8de4-d82b039c06d1","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_verticalscrollbarappearsonleft_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_verticalscrollbarappearsonleft_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autobulletrecognition","displayName":"Auto Bullet Recognition (User)","description":"Checks/Unchecks the option ''Apply bullets to lists automatically''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autobulletrecognition_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autobulletrecognition_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autokeyboardswitching","displayName":"Auto Keyboard Switching (User)","description":"Check/Unchecks the option ''Switch keyboards automatically''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autokeyboardswitching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autokeyboardswitching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autonumberingrecognition","displayName":"Auto Numbering Recognition (User)","description":"Checks/Unchecks the option ''Apply numbering to lists automatically''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autonumberingrecognition_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autonumberingrecognition_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontname","displayName":"Default Font Name (User)","description":"Specifies the value in the option ''Font''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontname_l_font","displayName":"Font: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize","displayName":"Default Font Size (User)","description":"Specifies the value in the option ''Size''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize_l_fontsize","displayName":"Font Size: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_includelinktosourcewhenpastingfromtheinternet","displayName":"Include link to source when pasting from the Internet (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_includelinktosourcewhenpastingfromtheinternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_includelinktosourcewhenpastingfromtheinternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_showpasteoptionsbuttons","displayName":"Show Paste Options buttons (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_showpasteoptionsbuttons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_showpasteoptionsbuttons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnoffautocalculator","displayName":"Turn off auto calculator (User)","description":"This option turns on/off the auto calculator functionality.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnoffautocalculator_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnoffautocalculator_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnofflinkcreationwith","displayName":"Turn off link creation with [[ ]] (User)","description":"This policy setting allows you to turn off link creation with [[ ]]. OneNote allows users to automatically create links by putting [[ ]] around a term. OneNote will then automatically create a new page in that section and create a link on that text.\r\n\r\nIf you enable this policy setting, users will not be able to use [[ ]] to create a link and a new page.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will automatically create links when users use [[ ]].","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnofflinkcreationwith_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnofflinkcreationwith_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_addsignaturetoonenoteemailmessages","displayName":"Add signature to OneNote email messages (User)","description":"Checks/Unchecks the option ''Add the following signature to e-mail messages and Web pages created in OneNote''.","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_addsignaturetoonenoteemailmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_addsignaturetoonenoteemailmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_allowonenoteemailattachments","displayName":"Allow OneNote e-mail attachments (User)","description":"Checks/Unchecks the option ''Attach a copy of the original notes as a OneNote file''.","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_allowonenoteemailattachments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_allowonenoteemailattachments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_attachembeddedfilestotheemail","displayName":"Attach embedded files to the email message as separate files (User)","description":"This policy setting allows you to configure the \"Attach embedded files to the email message as separate file\" option found under File tab | Options | Advanced | E-mail sent from OneNote.\r\n\r\nIf you enable or do not configure this policy setting, embedded files are attached to the email message as separate files.\r\n\r\nIf you disable this policy setting, embedded files are not attached to the email message as separate files.","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_attachembeddedfilestotheemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_attachembeddedfilestotheemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_usethissignatureforonenoteemail","displayName":"Use this signature for OneNote email (User)","description":"Sets the value in the option ''Add the following signature to e-mail messages and Web pages created in OneNote''.","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_usethissignatureforonenoteemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_usethissignatureforonenoteemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_usethissignatureforonenoteemail_l_entersignaturetouseforonenoteemail","displayName":"Enter signature to use for OneNote e-mail (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_noteflags_l_copyitemswhenmovingthem","displayName":"Copy items when moving them (User)","description":"This policy setting allows you to configure tagged notes.\r\n\r\nIf you enable or do not configure this policy setting, the option \"Leave original tagged notes unchanged\" will be checked.\r\n\r\nIf you disable this policy setting, the option \"Show original tagged notes as dimmed\" will be checked.","helpText":"","infoUrls":[],"categoryId":"4a7b0e92-ba43-46aa-96e8-c5839dbcb524","categoryName":"Note Flags","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_noteflags_l_copyitemswhenmovingthem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_noteflags_l_copyitemswhenmovingthem_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_noteflags_l_showdimmedtaggednotesinthetagssummarytaskpane","displayName":"Show dimmed tagged notes in the Tags Summary task pane (User)","description":"Checks/unchecks the option \"Show dimmed tagged notes in the Tags Summary task pane.\"","helpText":"","infoUrls":[],"categoryId":"4a7b0e92-ba43-46aa-96e8-c5839dbcb524","categoryName":"Note Flags","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_noteflags_l_showdimmedtaggednotesinthetagssummarytaskpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_noteflags_l_showdimmedtaggednotesinthetagssummarytaskpane_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_addonenoteicontonotificationarea","displayName":"Add OneNote icon to notification area (User)","description":"Checks/Unchecks the option ''Place OneNote icon in the notification area of the taskbar''.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_addonenoteicontonotificationarea_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_addonenoteicontonotificationarea_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote","displayName":"Default unit of measurement used in OneNote (User)","description":"Sets the value in the option ''Measurement units''.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_l_specifydefaultunitofmeasurement","displayName":"Specify default unit of measurement: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_l_specifydefaultunitofmeasurement_0","displayName":"Inch","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_l_specifydefaultunitofmeasurement_1","displayName":"Centimeter","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_l_specifydefaultunitofmeasurement_2","displayName":"Millimeter","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_l_specifydefaultunitofmeasurement_3","displayName":"Point","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_l_specifydefaultunitofmeasurement_4","displayName":"Pica","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableembeddedfiles","displayName":"Disable embedded files (User)","description":"To disable the ability to embed files on a OneNote page, so people cannot transmit files that might not be caught by anti-virus software, etc. Note: This policy will only limit embedded files in the OneNote UI, if a page has an embedded file OneNote will still sync and replicate the embedded files in the file system.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableembeddedfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableembeddedfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableocr","displayName":"Disable OCR (User)","description":"This policy turns off the OneNote image optical character recognition (OCR) feature. The OCR feature allows OneNote to automatically scan through images to find text that will appear in search results.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableocr_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableocr_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableonenotescreenclippingnotifications","displayName":"Disable OneNote screen clipping notifications (User)","description":"Turns off all of the OneNote screen clipping notifications.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableonenotescreenclippingnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableonenotescreenclippingnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableonenotescreenclippings","displayName":"Disable OneNote Screen Clippings (User)","description":"Disables the screen clipping feature in OneNote.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableonenotescreenclippings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableonenotescreenclippings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_embeddedfilesblockedextensions","displayName":"Embedded Files Blocked Extensions (User)","description":"To disable the ability of the users in your organization from being able to open a file attachment of a specific file type from a Microsoft OneNote page, add the extensions you want to disable using this format: \".ext1;.ext2;\" If you want to disable the opening of any attachment from a OneNote page, see the Disable embedded files policy. You cannot block embedded audio and video recordings (WMA & WMV) with this policy instead refer to the Disable embedded files policy.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_embeddedfilesblockedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_embeddedfilesblockedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_embeddedfilesblockedextensions_l_empty12","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot","displayName":"Load a notebook on first boot (User)","description":"Points to a folder containing a notebook that should be loaded on first boot.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot_l_empty13","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_notebookpresence","displayName":"Notebook Presence (User)","description":"This policy setting enables or disables the Notebook Presence feature in OneNote, which broadcasts user presence within a notebook and enables real-time synchronization for users who are editing the same page. Note: Any change to this policy does not take effect until OneNote is restarted.\r\n\r\nIf you enable or do not configure this policy setting, users are notified when they are editing the same page in a notebook as another user. OneNote also enters real-time sync when it discovers multiple users editing the same page. \r\n\r\nIf you disable this policy setting, users are not notified when they are editing the same page in a notebook as another user. OneNote does not enter real-time sync when multiple users are editing the same page.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_notebookpresence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_notebookpresence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_numberofdaysbeforewarningthatserveris","displayName":"Number of days before warning that server is inaccessible (User)","description":"Set the number of days until OneNote warns that the server is inaccessible and prompts for a new location for the affected files.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_numberofdaysbeforewarningthatserveris_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_numberofdaysbeforewarningthatserveris_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_numberofdaysbeforewarningthatserveris_l_empty14","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_setuncintervaltopollforchangesonfileservers","displayName":"Set UNC interval to poll for changes on file servers (User)","description":"This policy setting allows you to change the synchronization interval at which OneNote will poll for changes on the server. When OneNote synchronizes a notebook on UNC, also known as SMB or Windows File shares, OneNote will receive notifications from the file server as well as poll the server looking for new updates on the server.\r\n\r\nBy making the interval faster it will make OneNote synchronize faster, but it also might cause performance issues on the server.\r\n\r\nIf you enable this policy setting, you may specify the number of seconds OneNote will poll.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will automatically poll every 30 seconds.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_setuncintervaltopollforchangesonfileservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_setuncintervaltopollforchangesonfileservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_setuncintervaltopollforchangesonfileservers_l_setuncintervaltopollforchangesonfileserversspinid","displayName":"Interval to poll the server (seconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointsyncinterval","displayName":"SharePoint sync interval for notebooks stored on SharePoint (User)","description":"Limits the number of times OneNote polls a SharePoint site for changes to a section. Enter the sync interval in seconds.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointsyncinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointsyncinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointsyncinterval_l_empty15","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_specifyembeddedfilesizelimit","displayName":"Embedded File Size Limit (User)","description":"This policy setting enables you to specify the maximum embedded file size that users can insert directly into a OneNote notebook on a SharePoint server.\r\n \r\nIf you enable this policy setting, you can increase or decrease the default maximum file size of 50 MB. \r\n\r\nIf you increase this value, users can insert larger files directly into the notebook, but this may reduce server performance. \r\n\r\nIf you decrease this value, users can only insert smaller files directly into the notebook, which may improve server performance if OneNote sync is generating a lot of traffic.\r\n\r\nIf you disable or do not configure this policy setting, users cannot insert a file larger than 50MB inserted into a OneNote notebook. Instead, the file is uploaded to a SharePoint folder and inserted as a hyperlink into the notebook.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_specifyembeddedfilesizelimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_specifyembeddedfilesizelimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_specifyembeddedfilesizelimit_l_embeddedfilesizelimit","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffonenoteautolinkednotetaking","displayName":"Turn off OneNote auto-linked note taking (User)","description":"This policy setting turns off the OneNote auto note taking feature which allows you to take notes on items such as webpages, Word documents, etc. OneNote will automatically record what pages or document you were viewing when you took this note.\r\n\r\nIf you enable this policy setting, OneNote will not automatically link notes when the user tries to turn on this feature.\r\n\r\nIf you disable or do not enable this policy, OneNote will automatically link notes when the user tries to turn on this feature.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffonenoteautolinkednotetaking_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffonenoteautolinkednotetaking_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disablepasswordprotectedsections","displayName":"Disable password protected sections (User)","description":"Disables the ability to create new password protected sections. You can however still unlock and edit existing sections which had a password set.","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disablepasswordprotectedsections_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disablepasswordprotectedsections_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disallowsaddonsaccesstopass","displayName":"Disallows add-ons access to password protected sections (User)","description":"This option disallows extensibility add-ons the ability to access password protected sections if they are unlocked.","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disallowsaddonsaccesstopass_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disallowsaddonsaccesstopass_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime","displayName":"Lock password protected sections after user hasn't worked on them for a time (User)","description":"OneNote supports password protecting sections and they are unlocked once a user types the password and can be locked again by either a timeout period or when you navigate away from the section. This option will lock the section after the user hasn't used the section for the selected amount of time.","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_checktolocksections","displayName":"Check to lock sections (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_checktolocksections_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_checktolocksections_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections","displayName":"Time interval (minutes) to lock password protected sections: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_5","displayName":"5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_10","displayName":"10","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_15","displayName":"15","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_30","displayName":"30","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_60","displayName":"60","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_120","displayName":"120","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_240","displayName":"240","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_480","displayName":"480","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_720","displayName":"720","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_1440","displayName":"1440","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsassoonasinavigateawayfromthem","displayName":"Lock password protected sections as soon as I navigate away from them (User)","description":"OneNote supports password protecting sections and they are unlocked once a user types the password and can be locked again by either a timeout period or when you navigate away from the section. This option will lock the section once you navigate away from the password protected section.","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsassoonasinavigateawayfromthem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsassoonasinavigateawayfromthem_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_automaticallyswitchbetweenpenandselectiontool","displayName":"Automatically switch between Pen and Selection Tool (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"84de2eed-843c-401b-a3fd-e21be88f2365","categoryName":"Pen","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_automaticallyswitchbetweenpenandselectiontool_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_automaticallyswitchbetweenpenandselectiontool_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_createallnewpageswithrulelines","displayName":"Create all new pages with rule lines (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"84de2eed-843c-401b-a3fd-e21be88f2365","categoryName":"Pen","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_createallnewpageswithrulelines_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_createallnewpageswithrulelines_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_disablescratchout","displayName":"Disable scratch out (User)","description":"Disables the scratch out gesture while inking.","helpText":"","infoUrls":[],"categoryId":"84de2eed-843c-401b-a3fd-e21be88f2365","categoryName":"Pen","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_disablescratchout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_disablescratchout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_showtabletpcinputpanelononenotepages","displayName":"Show Tablet PC Input Panel on OneNote pages (User)","description":"Enable this policy to display the Tablet PC Input Panel on OneNote pages.","helpText":"","infoUrls":[],"categoryId":"84de2eed-843c-401b-a3fd-e21be88f2365","categoryName":"Pen","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_showtabletpcinputpanelononenotepages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_showtabletpcinputpanelononenotepages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_usepenpressuresensitivity","displayName":"Use pen pressure sensitivity (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"84de2eed-843c-401b-a3fd-e21be88f2365","categoryName":"Pen","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_usepenpressuresensitivity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_usepenpressuresensitivity_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles","displayName":"Enable ability to optimize OneNote files... (User)","description":"Checks/Unchecks the option ''Optimize sections after OneNote has been inactive for the following number of minutes''.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_l_checktoenableabilitytooptimizeonenotefiles","displayName":"Check to enable ability to optimize OneNote files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_l_checktoenableabilitytooptimizeonenotefiles_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_l_checktoenableabilitytooptimizeonenotefiles_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_l_optimizeonenotefilesatthisintervalmin","displayName":"Optimize OneNote files at this interval (min): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder","displayName":"Location of Backup Folder (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder_l_backupfolder","displayName":"Backup Folder: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofunfilednotessection","displayName":"Location of unfiled notes section (User)","description":"Location where OneNote stores the unfiled notes section.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofunfilednotessection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofunfilednotessection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofunfilednotessection_l_opensidenotesinthissection","displayName":"Open Side Notes in this section: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot","displayName":"Notebook Root (User)","description":"To change to where new notebooks are defaulted, enter a path to a folder relative to your documents.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot_l_empty1","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections","displayName":"Percentage of unused disk space to allow in sections (User)","description":"Sets the value in the option ''Percentage of unused space to allow in sections without optimizing''.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections_l_enterpercentage","displayName":"Enter Percentage: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setparametersforcngcontext","displayName":"Set parameters for CNG context (User)","description":"This policy setting allows you to specify the encryption parameters that should be used for the CNG context. \r\n\r\nIf you enable this policy setting, the parameters specified will be passed to the CNG context.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG values will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setparametersforcngcontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setparametersforcngcontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm","displayName":"Specify CNG random number generator algorithm (User)","description":"This policy setting allows you to configure the CNG random number generator to use.\r\n\r\nIf you enable this policy setting, the random number generator specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default random number generator will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_l_specifycngrandomnumbergeneratoralgorithmid","displayName":"Random number generator: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngsaltlength","displayName":"Specify CNG salt length (User)","description":"This policy setting allows you to specific the number of bytes of salt that should be used.\r\n\r\nIf you enable this policy setting, the bytes specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default length or 16 will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngsaltlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngsaltlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility","displayName":"Specify encryption compatibility (User)","description":"This policy setting allows you to specify the encrypted database compatibility.\r\n\r\nIf you enable this policy setting, the compatibility format specified will be applied during encryption for new files\r\n- Use legacy format\r\n- Use next generation format\r\n- All files save with next generation format\r\n\r\nIf you disable or do not configure this policy setting, the default setting, \"Use next generation format,\" will be applied.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_0","displayName":"Use legacy format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_1","displayName":"Use next generation format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_2","displayName":"All files save with next generation format","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_sendtoonenote_l_disableoutlooksendemailtoonenoteoption","displayName":"Disable Outlook send email to OneNote option (User)","description":"This policy disables the OneNote ''Send to OneNote'' add-in for Microsoft Outlook. By default OneNote installs an add-in on the Outlook toolbar which allows users to send emails to OneNote. The ''Send to OneNote'' button appears on the main mail module in Outlook as well as when viewing an email message. You may disable this feature with this policy.","helpText":"","infoUrls":[],"categoryId":"a87f9d6a-0c84-4cad-839f-e912c6006c12","categoryName":"Send to OneNote","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_sendtoonenote_l_disableoutlooksendemailtoonenoteoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_sendtoonenote_l_disableoutlooksendemailtoonenoteoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions","displayName":"OneNote Spelling Options (User)","description":"These options change the \"When correcting spelling in OneNote\" options that appear in the File tab | Option | Proofing dialog box.","helpText":"","infoUrls":[],"categoryId":"1bfef2c3-a561-4e7a-8f0f-0944bc79c20f","categoryName":"Spelling","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_l_empty11","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"1bfef2c3-a561-4e7a-8f0f-0944bc79c20f","categoryName":"Spelling","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_l_empty11_0","displayName":"no spell checking","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_l_empty11_1","displayName":"check spelling as you type","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_l_empty11_2","displayName":"hide spelling errors","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_l_empty11_3","displayName":"check spelling but hide errors","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepinversionhistory","displayName":"Days back to keep in version history (User)","description":"This policy setting allows you to set the number of days when all version history items created before this value will be deleted. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, you can set the number of days back to delete version history.\r\n\r\nIf you disable or do not configure this policy setting OneNote will default to keeping previous versions for all days in the past. This is the default value of -1.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepinversionhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepinversionhistory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepinversionhistory_l_daysbacktokeepinversionhistoryspinid","displayName":"Days back to keep versions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepitemsinrecyclebin","displayName":"Days back to keep items in recycle bin (User)","description":"This policy setting allows you to set the number of days before which all items added to the Recycle Bin before value will be deleted when the version history is pruned. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, you can set the number of days in the past to keep recycle bin items.\r\n\r\nIf you do not configure this policy setting OneNote will use the default value of 60 days in the past.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepitemsinrecyclebin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepitemsinrecyclebin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepitemsinrecyclebin_l_daysbacktokeepitemsinrecyclebinspinid","displayName":"Days back to keep items in recycle bin (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofallversions","displayName":"Days all Version History items are \"safe\" from pruning (User)","description":"This policy setting allows you to specify a period of time during which OneNote maintains comprehensive version history pages. After the time specified, OneNote maintains more basic version history pages, which uses less storage space.\r\n\r\nIf you enable this policy setting, OneNote maintains comprehensive version history pages for the length of time you specify, and then maintains basic version history pages once the time period expires.\r\n\r\nIf you disable or do not configure this policy setting, OneNote maintains comprehensive version history pages for 2 days, and then maintains basic version history pages once the time period expires.\r\n ","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofallversions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofallversions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofallversions_l_daysofallversionsspinid","displayName":"Days back (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofhourlyversionsnottopruneafterdaysback","displayName":"Days of hourly versions not to prune after Days Back (User)","description":"This policy setting allows you to set the number of hourly versions not to prune after Days Back. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, you may specify the number of days to keep hourly versions after the Days Back setting. This value specifies the number of days past \"DaysOfAllVersions\" to keep hourly version history information. Users will keep one version per hour for this number of days after \"DaysOfAllVersions\".\r\n\r\nIf you disable or do not configure this policy setting, OneNote will keep hourly versions for the past 5 days.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofhourlyversionsnottopruneafterdaysback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofhourlyversionsnottopruneafterdaysback_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofhourlyversionsnottopruneafterdaysback_l_daysofhourlyversionsnottopruneafterdaysbackspinid","displayName":"Days back (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_donotpruneversionsovertime","displayName":"Do not prune versions over time (User)","description":"This policy setting allows you to turn off OneNote's automatic pruning. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, OneNote will not prune previous versions.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will prune previous versions. The default value is to prune versions over time. You should only enable this policy setting if OneNote should not prune previous versions.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_donotpruneversionsovertime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_donotpruneversionsovertime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_maximumnumberofonceperdayversionhistoryitemskept","displayName":"Maximum number of once-per-day version history items kept (User)","description":"This policy setting allows you to set the number of once-per-day history items to be kept for each page. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, you can set the number of versions per day to keep. If you set a value of -1 this will tell OneNote to keep all old once-per-day version history items.\r\n \r\nIf you disable or do not configure this policy setting OneNote will keep a page for the past 10 days every day in the past.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_maximumnumberofonceperdayversionhistoryitemskept_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_maximumnumberofonceperdayversionhistoryitemskept_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_maximumnumberofonceperdayversionhistoryitemskept_l_maximumnumberofonceperdayversionhistoryitemskeptspinid","displayName":"Max number of versions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_turnoffversionsandnotebookrecyclebininsharednotebooks","displayName":"Turn off Versions and Notebook Recycle Bin in shared notebooks (User)","description":"This policy setting allows you to turn off version history which includes versions and the notebook recycle bin. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, it will turn off version history.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will store previous versions by default.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_turnoffversionsandnotebookrecyclebininsharednotebooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_turnoffversionsandnotebookrecyclebininsharednotebooks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointbackgroundsyncintervalmultiplier","displayName":"Multiplier for background sync interval for notebooks stored on SharePoint (User)","description":"This policy setting allows you to increase the interval between background polls of a SharePoint site for changes to notebooks.\r\n\r\nIf you enable this policy setting, OneNote will poll SharePoint less frequently for changes to whole notebooks. Intervals are multiplied by the entered value, a positive integer value from 1 to 10. Larger intervals will slow notebook sync but reduce server load.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will sync notebooks at the default rate (multiplier value of 1).\r\n\r\nNote: This policy setting only applies to volume licensed versions of Office 2016 that use Windows Installer (MSI), such as Office Professional Plus 2016 and Office Standard 2016.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointbackgroundsyncintervalmultiplier_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointbackgroundsyncintervalmultiplier_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointbackgroundsyncintervalmultiplier_l_empty16","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier","displayName":"Multiplier for foreground sync interval for the currently viewed section stored on SharePoint (User)","description":"This policy setting allows you to increase the interval between foreground polls of a SharePoint site for changes to the currently viewed section.\r\n\r\nIf you enable this policy setting, OneNote will poll SharePoint less frequently for changes to the currently viewed section. Intervals are multiplied by the entered value, a positive integer value from 1 to 10. Larger intervals will slow section sync but reduce server load.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will sync the currently viewed section at the default rate (multiplier value of 1).\r\n\r\nNote: This policy setting only applies to volume licensed versions of Office 2016 that use Windows Installer (MSI), such as Office Professional Plus 2016 and Office Standard 2016.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier_l_empty17","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier","displayName":"Multiplier for Presence sync interval for notebooks stored on SharePoint (User)","description":"This policy setting allows you to increase the interval between polls to SharePoint to determine active users of notebooks. OneNote will sync notebooks at a faster rate when other users are interacting with a notebook.\r\n\r\nIf you enable this policy setting, OneNote will poll SharePoint less frequently to determine if there are other users currently interacting with notebooks. Intervals are multiplied by the entered value, a positive integer value from 1 to 10. Larger intervals will slow detection of concurrent users in notebooks but reduce server load.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will poll for active users of notebooks at the default rate (multiplier value of 1).\r\n\r\nNote: This policy setting only applies to volume licensed versions of Office 2016 that use Windows Installer (MSI), such as Office Professional Plus 2016 and Office Standard 2016.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier_l_empty18","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v4~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disablesupportdiagnostics","displayName":"Turn off support diagnostics in OneNote (User)","description":"This policy setting controls whether OneNote sends client information to support services on failure.\r\n\r\nSending client information to support services on failure can help diagnose the issue, provide resolution steps, or show contextual error messaging to the user.\r\n\r\nIf you enable this policy setting, OneNote won’t send client information to support services on failure.\r\n\r\nIf you disable or don’t configure this policy setting, OneNote will send client information to support services on failure.\r\n\r\nNote: This policy setting only applies to Version 2207 and later of OneNote.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v4~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disablesupportdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v4~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disablesupportdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v5~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_onenotetextprediction","displayName":"OneNote text prediction (User)","description":"\r\nThis policy setting controls whether users will see and be able to accept text predictions when writing notes in English in OneNote.\r\n\r\nIf you enable or don't configure this policy setting, users will see and be able to accept predicted text by using the Tab key or right arrow key while writing their notes. Or they can simply keep typing to ignore the predicted text.\r\n\r\nIf you disable this policy setting, users will not be able to see or accept text predictions while writing notes.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v5~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_onenotetextprediction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v5~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_onenotetextprediction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v6.1~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffnewstickynotesinonenote","displayName":"Disable the new Sticky Notes experience (User)","description":"This policy controls the ability of users to access the new Sticky Notes experiences from OneNote.\r\n\r\nIf you enable this policy setting, users will be unable to access the new Sticky Notes experiences from OneNote.\r\n\r\nIf you disable this policy setting, users can access the new Sticky Notes experiences from OneNote.\r\n\r\nIf you do not set this policy setting, users can access the new Sticky Notes experiences from OneNote.\r\n\r\nNote: This policy does not affect the classic Microsoft Sticky Notes app available on the Microsoft Store. Additionally, disabling or not setting this policy does not guarantee access to the new Sticky Notes experiences from OneNote.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v6.1~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffnewstickynotesinonenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v6.1~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffnewstickynotesinonenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v6~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffnewstickynotesinonenote","displayName":"Disable the new Sticky Notes experience (User)","description":"This policy controls the ability of users to access the new Sticky Notes experiences from OneNote.\r\n\r\nIf you enable this policy setting, users will be unable to access the new Sticky Notes experiences from OneNote.\r\n\r\nIf you disable this policy setting, users can access the new Sticky Notes experiences from OneNote.\r\n\r\nIf you do not set this policy setting, users can access the new Sticky Notes experiences from OneNote.\r\n\r\nNote: This policy does not affect the classic Microsoft Sticky Notes app available on the Microsoft Store. Additionally, disabling or not setting this policy does not guarantee access to the new Sticky Notes experiences from OneNote.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v6~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffnewstickynotesinonenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v6~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffnewstickynotesinonenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v7~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_onenotesensitivitylabels","displayName":"Enable OneNote Sensitivity Labels (User)","description":"This policy setting controls whether Purview Sensitivity Label capabilities can be enabled for OneNote Sections.\r\n\r\nIf you enable this policy, users can use supported Purview features, such as manual labeling, label removal, or default labels, to apply sensitivity labels to OneNote sections and help protect sensitive information. At this time, mandatory labels, auto labeling, and dynamic watermarking are not supported.\r\n\r\nIf you disable this policy, users won't be able to apply, change or remove Sensitivity Labels in OneNote Sections.\r\n\r\nIf you do not configure this policy setting, users won't be able to apply, change or remove Sensitivity Labels in OneNote Sections.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v7~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_onenotesensitivitylabels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v7~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_onenotesensitivitylabels_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems290","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems290_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems290_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems290_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_outlk16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace","displayName":"Disable Preview Place. (User)","description":"\r\n This policy setting determines whether the Preview Place feature is allowed. Enabling this setting will block the Preview Place feature from being available.\r\n Users will no longer be able to preview and provide feedback on upcoming changes in Outlook.\r\n\tNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v10~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disablecalendarsearchagendaview","displayName":"Do not allow Calendar search agenda view (User)","description":"This policy setting allows you to prevent agenda view for Calendar search.\r\n\r\nIf you enable this policy setting, Calendar search will default to list view.\r\n\r\nIf you disable or do not configure this policy setting, it will default to agenda view.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v10~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disablecalendarsearchagendaview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v10~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disablecalendarsearchagendaview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifymaxcertlengthallowedtostamp","displayName":"Maximum Size Limit for certificate in Reply to Encrypted Emails cases. (User)","description":"When replying to a digitally signed email using Outlook, Win32 saves the certificate chain of the original sender in Exchange. This allows for encrypted replies without adding the original sender to the contact list. \r\nHowever, there are cases where a sent email may not be delivered or saved in the sent items if the size of the stored certificate on the Exchange server is too large.\r\nTo avoid this issue caused by large certificate sizes of the original email sender in Win32 Outlook, the default upper limit is set at 12921 bytes. However, administrators have the option to configure a higher limit, up to a maximum of 16384 bytes.\t\r\n ","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifymaxcertlengthallowedtostamp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifymaxcertlengthallowedtostamp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifymaxcertlengthallowedtostamp_l_specifymaxcertlengthallowedtostampspinid","displayName":"In bytes: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":null},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifywaitonsendtimeoutfordlpevaluation","displayName":"Specify wait time to evaluate sensitive content (User)","description":"This policy setting is used to define the waiting time for evaluating sensitive content in emails before a user can send them. Customize whether immediate email sending is allowed, sending is permitted after a specific wait time, or complete evaluation is required before sending. Regardless of the setting, the service will continue the evaluation in the background and take appropriate action based on the results, such as blocking delivery if necessary.\r\n\r\nIf you disable or do not configure this policy setting, emails will be sent right away without waiting for the final evaluation of the configured policies.\r\n\r\nIf you enable this policy setting, you can set a specific wait time, measured in seconds (in the range of 0-9999), before the \"Send Anyway\" button appears in the waiting dialog. This allows users to send the mail even before the policy evaluation is complete. \r\n\r\nPlease note that setting the wait time above 9999 indicates that users are not allowed to send the mail without evaluation. In such cases, the \"Send Anyway\" button will never be shown.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifywaitonsendtimeoutfordlpevaluation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifywaitonsendtimeoutfordlpevaluation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifywaitonsendtimeoutfordlpevaluation_l_specifywaitonsendtimeoutfordlpevaluationspinid","displayName":"In seconds: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":null},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hidenewoutlooktoggle","displayName":"Hide the “Try the new Outlook” toggle in Outlook (User)","description":"This policy setting controls whether the “Try the new Outlook” toggle is displayed in Outlook.\r\n\r\nIf you enable this policy setting, the toggle for “Try the new Outlook” will be hidden and users will not have the ability to switch between the existing and new Outlook experiences.\r\n\r\nIf you disable or do not configure this policy setting, the toggle for “Try the new Outlook” will be displayed.\r\n\r\nNote: This policy only applies to subscription-based Microsoft 365 Apps.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hidenewoutlooktoggle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hidenewoutlooktoggle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v12~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablesimplemapisendwithoutoutlook","displayName":"Running Outlook for Simple MAPI Mail Sending (User)","description":"This policy setting determines whether users can send mail through Simple MAPI when Outlook is not active.\r\n\r\nIf you enable this policy setting, users are required to have Outlook running to send mail through Simple MAPI. This will force users to open Outlook to send mail, ensuring that Outlook Add-ins run properly before the mail is sent. \r\n\r\nIf you disable this policy setting, users are allowed to send mail through Simple MAPI regardless of Outlook running.\r\n\r\nWhen this policy setting is not configured, it functions as if it has been disabled, allowing users to send mail through Simple MAPI without having Outlook running.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v12~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablesimplemapisendwithoutoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v12~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablesimplemapisendwithoutoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps","displayName":"Show Outlook Loop components for supported apps. (User)","description":"This policy controls whether Outlook displays Loop components that are supported by installed apps without requiring users to explicitly choose to load them.\r\n\r\nIf you enable this policy setting by selecting \"Always show automatically\" or \"Only show automatically within tenant,\" Outlook will automatically display Loop components in emails. This applies to all messages or specifically to messages that originate within the recipient's local tenant or organization. This might involve contacting servers used by the installed apps to retrieve Loop components.\r\n\r\nIf you do not set this policy setting, Outlook will default to the \"Only show automatically within tenant\" setting. This ensures Loop components are automatically displayed in emails originating from the recipient's local tenant or organization.\r\n\r\nNote: Loop components included in messages located in the Junk Mail folder will not load automatically, regardless of the policy setting specified. Loop components will only be shown for apps that are installed, ensuring security and a tailored experience in Outlook.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid","displayName":"Show Outlook Loop components for supported apps (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid_1","displayName":"Always show automatically.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid_2","displayName":"Only show automatically within tenant.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid_3","displayName":"Don’t show automatically.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals","displayName":"Interval between new Outlook migration attempts (User)","description":"This policy setting controls the interval between new Outlook migration attempts.\r\n\r\nIf you don't set this or set this to 0 (default value), classic Outlook will stop executing \"New Outlook auto migration\" after the user toggles back to classic Outlook for Windows.\r\n\r\nIf you set this to 1, classic Outlook will show a blocking prompt on each app launch, which will attempt to switch the user to the new Outlook app.\r\n\r\nIf you set this to N (2 - 9900) value, \"New Outlook auto migration\" will be re-initiated N days after the user toggles back to classic Outlook.\r\n\r\nNote: This policy only applies to subscription-based Microsoft 365 Apps.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_l_newoutlookautomigrationretryintervalsid","displayName":"New Outlook Auto Migration Retry Interval: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablecomtowebaddinupgrade","displayName":"Disable web add-in installation on migration to new Outlook for Windows (User)","description":"This policy setting allows you to disable installation of web add-in equivalents of COM add-ins on the switch to new Outlook. The add-ins available for migration are listed in https://aka.ms/newoutlooksettings.\r\n\r\nLearn more about Outlook web add-ins at https://learn.microsoft.com/office/dev/add-ins/outlook/outlook-add-ins-overview.\r\n\r\nCOM add-ins do not work in new Outlook for Windows. By default, users in the organization will get the option to install available web add-ins, in place of COM add-ins, when they move from classic Outlook for Windows.\r\n\r\nIf you enable this policy setting, users will not get the option to install web add-ins in place of their COM add-ins. \r\n \r\nIf you disable or do not configure this policy setting, users will get an option to install web add-ins in place of their COM add-ins.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablecomtowebaddinupgrade_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablecomtowebaddinupgrade_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_donewoutlookautomigration","displayName":"Admin-Controlled Migration to New Outlook (User)","description":"\r\nThis policy controls the ability of IT admins to initiate the migration of users from classic Outlook to new Outlook.\r\n\r\nIf you enable this policy setting, IT admins will start the process to switch users from classic Outlook to new Outlook.\r\n\r\nIf you disable this policy setting, the migration process to new Outlook will be stopped, keeping users on their current version of Outlook without transitioning to new Outlook.\r\n\r\nIf you do not set this policy setting, the migration process to new Outlook will not start, and users that have not migrated will remain on classic Outlook.\r\n\r\nNote: IT admins can also define intervals for re-initiating the migration process for users who revert to classic Outlook from new Outlook. This is managed through the NewOutlookAutoMigrationRetryIntervals policy, offering a tailored strategy for transitioning users based on organizational requirements and user feedback.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_donewoutlookautomigration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_donewoutlookautomigration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals","displayName":"Interval between new Outlook migration attempts (User)","description":"This policy setting controls the interval between new Outlook migration attempts.\r\n\r\nIf you don't set this or set this to 0 (default value), classic Outlook will stop executing \"New Outlook auto migration\" after the user toggles back to classic Outlook for Windows.\r\n\r\nIf you set this to 1, classic Outlook will show a blocking prompt on each app launch, which will attempt to switch the user to the new Outlook app.\r\n\r\nIf you set this to N (2 - 9900) value, \"New Outlook auto migration\" will be re-initiated N days after the user toggles back to classic Outlook.\r\n\r\nNote: This policy only applies to subscription-based Microsoft 365 Apps.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_l_newoutlookautomigrationretryintervalsid","displayName":"New Outlook Auto Migration Retry Interval: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption","displayName":"MailTips bar display options (User)","description":"\r\n This policy setting controls MailTips bar display options. If the \"Disable MailTips\" policy is also enabled, this policy takes precedence.\r\n\r\n If you enable this policy setting, you can choose from three options for determining how the MailTips bar will display:\r\n\r\n - Display automatically when MailTips apply\r\n - Display at all times\r\n - Never Display MailTips\r\n\r\n If you disable or do not configure this policy setting, users can choose how the MailTips bar will display.\r\n ","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions_0","displayName":"Display automatically when MailTips apply","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions_1","displayName":"Display at all times","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions_2","displayName":"Never display MailTips","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_smimedisabledataupload","displayName":"Block processing of S/MIME encrypted messages by certain connected experiences (User)","description":"\r\nThis policy controls whether certain connected experiences that analyze your content can process email messages with S/MIME encryption.\r\n\r\nIf you enable this policy setting, certain connected experiences that analyze your content can’t process email messages with S/MIME encryption. This means connected experiences such as the following won’t be available:\r\n\r\n-\tSpelling and grammar check (Editor)\r\n-\tSuggested replies\r\n-\tAutomatically apply or recommend sensitivity labels\r\n-\tMicrosoft Purview Data Loss Prevention policy tips\r\n\r\nFor more information about which connected experiences are affected, see https://go.microsoft.com/fwlink/p/?linkid=2268773.\r\n\r\nIf you disable or don’t configure this policy setting, all connected experiences that analyze your content can process email messages with S/MIME encryption.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_smimedisabledataupload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_smimedisabledataupload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy","displayName":"Manage user setting for new Outlook automatic migration (User)","description":"\r\nThis policy allows you to manage the user setting for enabling or disabling automatic migration to the new Outlook app. Automatic migration could be admin-driven (enabled through 'Admin-Controlled migration to New Outlook' policy), or Microsoft-driven.\r\n\r\nWhen applied, this policy controls whether the user can be switched to the new Outlook app automatically or retains control over the setting.\r\n\r\nIf you set this policy to 1 (Set to 1), the user setting controlling automatic migration is enabled. Automatic migration to the new Outlook app is allowed, and the user cannot change this setting.\r\n\r\nIf you set this policy to 2 (Set to 2), the user setting controlling automatic migration is disabled. Automatic migration to the new Outlook app is not allowed, and the user cannot change this setting.\r\n\r\nIf you set this policy to 0 (Set to 0) or don't configure this policy (default), the user setting for automatic migration is not controlled by the policy, allowing the user to manage it themselves. This user setting for automatic migration is enabled by default.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy_l_newoutlookautomigrationusersettingpolicyid","displayName":"New Outlook Auto Migration User Setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_outlk16v17~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomaticsetupusersetting","displayName":"Manage automatic setup of classic Outlook accounts in new Outlook (User)","description":"\r\nThis policy setting allows you to manage whether classic Outlook automatically sets up user accounts and settings in new Outlook.\r\n\r\nIf you enable this policy setting, automatic setup of user accounts and settings in new Outlook is allowed and cannot be changed by the user.\r\n\r\nIf you disable this policy setting, automatic setup of user accounts and settings in new Outlook is not allowed and cannot be changed by the user.\r\n\r\nIf you don't configure this policy setting, users can manage the setting themselves. Automatic setup is enabled by default.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v17~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomaticsetupusersetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v17~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomaticsetupusersetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges","displayName":"Add properties to attachments to enable Reply with Changes (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_l_addpropertiestoattachmentstoenablereplywithchanges","displayName":"Add properties to attachments to enable Reply with Changes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_l_addpropertiestoattachmentstoenablereplywithchanges_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_l_addpropertiestoattachmentstoenablereplywithchanges_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator","displayName":"Allow commas as address separator (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_l_allowcommasasaddressseparator","displayName":"Allow commas as address separator (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_l_allowcommasasaddressseparator_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_l_allowcommasasaddressseparator_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_automaticnamechecking","displayName":"Automatic name checking (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_automaticnamechecking_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_automaticnamechecking_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_automaticnamechecking_l_automaticnamechecking","displayName":"Automatic name checking (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_automaticnamechecking_l_automaticnamechecking_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_automaticnamechecking_l_automaticnamechecking_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_deletemeetingrequestfrominboxwhenresponding","displayName":"Delete meeting request from Inbox when responding (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_deletemeetingrequestfrominboxwhenresponding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_deletemeetingrequestfrominboxwhenresponding_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_deletemeetingrequestfrominboxwhenresponding_l_deletemeetingrequestfrominboxwhenresponding","displayName":"Delete meeting request from Inbox when responding (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_deletemeetingrequestfrominboxwhenresponding_l_deletemeetingrequestfrominboxwhenresponding_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_deletemeetingrequestfrominboxwhenresponding_l_deletemeetingrequestfrominboxwhenresponding_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_messagesexpireafterdays","displayName":"Messages expire after (days) (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_messagesexpireafterdays_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_messagesexpireafterdays_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_messagesexpireafterdays_l_messagesexpireafterdays","displayName":"Messages expire after (days): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance","displayName":"Set importance (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance","displayName":"Set importance: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance_2","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance_1","displayName":"Normal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance_0","displayName":"Low","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity","displayName":"Set sensitivity (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_l_setsensitivity","displayName":"Set sensitivity: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_l_setsensitivity_0","displayName":"Normal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_l_setsensitivity_1","displayName":"Personal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_l_setsensitivity_2","displayName":"Private","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_l_setsensitivity_3","displayName":"Confidential","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_suggestnameswhilecompletingtoccandbccfields","displayName":"Suggest names while completing To, Cc, and Bcc fields (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_suggestnameswhilecompletingtoccandbccfields_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_suggestnameswhilecompletingtoccandbccfields_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_suggestnameswhilecompletingtoccandbccfields_l_suggestnameswhilecompletingtoccandbccfields","displayName":"Suggest names while completing To, Cc, and Bcc fields (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_suggestnameswhilecompletingtoccandbccfields_l_suggestnameswhilecompletingtoccandbccfields_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_suggestnameswhilecompletingtoccandbccfields_l_suggestnameswhilecompletingtoccandbccfields_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2.updates.4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts","displayName":"Prevent copying or moving items between accounts (User)","description":"This policy setting allows you to prevent items from being copied or moved to other accounts or PSTs.\r\n\r\nIf you enable this policy setting, items will be prevented from being moved or copied to other accounts or PSTs. Enter one of the following details:\r\n\r\n- \"Contoso.com\": prevents copying or moving from the account corresponding to the listed domain\r\n- \"*\": prevents copying from all accounts and PST's\r\n- \"SharePoint\": prevents copies or moves from the SharePoint PST\r\n\r\nIf you disable or do not configure this policy setting, copying or moving items between accounts or PSTs is allowed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2.updates.4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2.updates.4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2.updates.4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts_l_preventcopyingormovingitemsbetweenaccountsid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"ee62e9fc-14c8-4f24-aa7e-89524087a802","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize37","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ee62e9fc-14c8-4f24-aa7e-89524087a802","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize37_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"ee62e9fc-14c8-4f24-aa7e-89524087a802","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize37_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"ee62e9fc-14c8-4f24-aa7e-89524087a802","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disablecommandbar38","displayName":"Disable command bar buttons and menu items (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"8184df77-410e-41a6-b687-88de05769977","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disablecommandbar38_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disablecommandbar38_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disablecommandbar38_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8184df77-410e-41a6-b687-88de05769977","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys39","displayName":"Disable shortcut keys (User)","description":"Specify the virtual key code and modifier for the shortcut key to disable.","helpText":"","infoUrls":[],"categoryId":"8184df77-410e-41a6-b687-88de05769977","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys39_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys39_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys39_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8184df77-410e-41a6-b687-88de05769977","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_predefined_l_hidequickstepsgallery","displayName":"Disable Quick Steps Gallery (User)","description":"This policy setting allows you to hide the Quick Steps Gallery in the Ribbon. By default, the Quick Steps Gallery is included in the Home tab of the Outlook explorer Ribbon. \r\n\r\nIf you enable this policy setting, you will hide the Quick Steps Gallery in the Ribbon.\r\n\r\nIf you disable or do not configure this policy setting, the Quick Steps Gallery will be included in the Home tab of the Outlook explorer Ribbon.","helpText":"","infoUrls":[],"categoryId":"d59dfcc1-6c35-41de-bfb6-de94b8120ca5","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_predefined_l_hidequickstepsgallery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_predefined_l_hidequickstepsgallery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage","displayName":"Calendar Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Calendar Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_showassociatedwebpage42","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_showassociatedwebpage42_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_showassociatedwebpage42_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage44","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage44_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage44_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_urladdressofassociatedwebpage43","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage","displayName":"Contacts Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Contacts Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_showassociatedwebpage45","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_showassociatedwebpage45_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_showassociatedwebpage45_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage47","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage47_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_urladdressofassociatedwebpage46","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage","displayName":"Deleted Items Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Deleted Items Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_showassociatedwebpage48","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_showassociatedwebpage48_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_showassociatedwebpage48_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage50","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage50_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage50_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_urladdressofassociatedwebpage49","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_disablefolderhomepages","displayName":"Do not allow Home Page URL to be set in folder Properties (User)","description":"By default, users can set a URL to be used as the Home Page for a folder by entering the URL on the Home Page tab on the folder's Properties dialog box. By enabling this setting, you can disallow setting Folder Home Pages for all folders.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_disablefolderhomepages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_disablefolderhomepages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage","displayName":"Drafts Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Drafts Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_showassociatedwebpage51","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_showassociatedwebpage51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_showassociatedwebpage51_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage53","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage53_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage53_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_urladdressofassociatedwebpage52","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage","displayName":"Inbox Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Inbox Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_showassociatedwebpage40","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_showassociatedwebpage40_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_showassociatedwebpage40_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_urladdressofassociatedwebpage41","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage","displayName":"Journal Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Journal Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_showassociatedwebpage54","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_showassociatedwebpage54_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_showassociatedwebpage54_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage56","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage56_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage56_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_urladdressofassociatedwebpage55","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage","displayName":"Notes Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Notes Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_showassociatedwebpage57","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_showassociatedwebpage57_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_showassociatedwebpage57_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage59","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage59_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_urladdressofassociatedwebpage58","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage","displayName":"Outbox Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Outbox Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_showassociatedwebpage60","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_showassociatedwebpage60_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_showassociatedwebpage60_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage62","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage62_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage62_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_urladdressofassociatedwebpage61","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage","displayName":"RSS Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the RSS Feeds Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_showassociatedwebpage","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_showassociatedwebpage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_showassociatedwebpage_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_turnoffinternetexplorersecuritychecks","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_turnoffinternetexplorersecuritychecks_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_turnoffinternetexplorersecuritychecks_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_urladdressofassociatedwebpage","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage","displayName":"Sent Items Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Sent Items Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_showassociatedwebpage63","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_showassociatedwebpage63_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_showassociatedwebpage63_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage65","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage65_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage65_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_urladdressofassociatedwebpage64","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage","displayName":"Tasks Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Tasks Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_showassociatedwebpage66","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_showassociatedwebpage66_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_showassociatedwebpage66_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage68","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage68_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage68_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_urladdressofassociatedwebpage67","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions","displayName":"Configure form regions permissions (User)","description":"By default, all form region customizations are permitted to run in Outlook. By using this setting, you can disable all form region customizations, or specify that form regions must be registered on a per-computer basis, rather than a per-user basis.","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart","displayName":"Configure form regions permissions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart_0","displayName":"All form regions are allowed to run","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart_1","displayName":"Allow only those registered in HKLM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart_2","displayName":"No form regions are allowed to run","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions","displayName":"Locked form regions (User)","description":"This policy setting allows you to configure adjoining form regions to be always expanded.\r\n\r\nIf you enable this policy setting, you may enter the adjoining form region name as the Value name and the Value data as \"1\" (without quotes). This ensures that users see the whole adjoining form region and cannot collapse it. This works for both Explorer and Inspector.\r\n\r\nIf you disable or do not configure this policy setting, adjoining form regions are not expanded.","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions_l_empty76","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions_l_empty76_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions_l_empty76_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_infopathintegration_l_disableinfopathpropertiespromotioninoutlook","displayName":"Do not promote InfoPath forms properties into Outlook properties (User)","description":"By default, InfoPath property promotion is enabled. This setting allows you to disable the ability to promote InfoPath forms properties into Outlook properties. This feature allows InfoPath forms to promote properties from the underlying data into named properties in Outlook. These properties are displayed in views on folders, and users can group, filter, and sort by them.","helpText":"","infoUrls":[],"categoryId":"e1a2f289-40d8-4e7c-b0a6-cd36f0ee9111","categoryName":"InfoPath Integration","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_infopathintegration_l_disableinfopathpropertiespromotioninoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_infopathintegration_l_disableinfopathpropertiespromotioninoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces","displayName":"Default servers and data for Meeting Workspaces (User)","description":"Using this policy, you can define default servers and server data for Meeting Workspaces. It is recommended that you draft this policy in a text editor and paste it into the text box in the setting. You can add up to five servers by listing them in the \"Default server:\" text box. Each server is defined by a pipe-delimited list, with a total of six pipes per server record. The OrganizerName field is left blank. For example: http://server1 | Friendly name for server1 | templateLCID | templateID | TemplateName | OrganizerName | http://server2 | ... and so on. For more information, see the Office 2016 Resource Kit on TechNet.","helpText":"","infoUrls":[],"categoryId":"f77040df-7dd2-4916-b6a0-5ef962686d4e","categoryName":"Meeting Workspace","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces_l_defaultserver","displayName":"Default server: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f77040df-7dd2-4916-b6a0-5ef962686d4e","categoryName":"Meeting Workspace","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist","displayName":"Disable user entries to server list (User)","description":"This policy setting controls whether Outlook users can add entries to the list of SharePoint servers when establishing a meeting workspace. \r\n\r\nIf you enable this policy setting, you can choose between two options to determine whether Outlook users can add entries to the published server list: \r\n\r\n- Publish default, allow others. This option is the default configuration in Outlook. \r\n\r\n- Publish default, disallow others. This option prevents users from adding servers to the default published server list. \r\n\r\nIf you disable or do not configure this policy setting, when users create a meeting workspace, they can choose a server from a default list provided by administrators or manually enter the address of a server that is not listed. This is the equivalent of Enabled -- Publish default, allow others.","helpText":"","infoUrls":[],"categoryId":"f77040df-7dd2-4916-b6a0-5ef962686d4e","categoryName":"Meeting Workspace","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_l_checktodisableusersfromaddingentriestoserverlist","displayName":"Check to disable users from adding entries to server list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f77040df-7dd2-4916-b6a0-5ef962686d4e","categoryName":"Meeting Workspace","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_l_checktodisableusersfromaddingentriestoserverlist_1","displayName":"Publish default, allow others","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_l_checktodisableusersfromaddingentriestoserverlist_2","displayName":"Publish default, disallow others","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody","displayName":"Change the limit for the number of MIME body parts (User)","description":"By default, the limit is 250 for the number of MIME body parts when an e-mail message is converted from MIME to MAPI. The number can be set to any positive integer. This helps prevent scenarios in which Outlook hangs while attempting conversion.","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody_l_empty75","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitrecipients","displayName":"Change the limit for the number of recipients (User)","description":"By default, the limit is 12288 recipients included for an e-mail message when the message is converted from MIME to MAPI. The number can be set to any positive integer. This helps prevent scenarios in which Outlook hangs while attempting conversion.","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitrecipients_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitrecipients_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitrecipients_l_empty73","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitforthenumberof","displayName":"Change the limit for the number of nested embedded messages (User)","description":"By default, the limit is 50 embedded messages when an e-mail message is converted from MIME to MAPI. The number can be set to any positive integer. This helps prevent scenarios in which Outlook hangs while attempting conversion.","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitforthenumberof_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitforthenumberof_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitforthenumberof_l_empty71","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitfriendlyname","displayName":"Change the limit for the number of characters in Friendly Name (User)","description":"By default, the limit is 1000 characters for Friendly Name when an e-mail message is converted from MIME to MAPI. The number can be set to any positive integer. This helps prevent scenarios in which Outlook hangs while attempting conversion.","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitfriendlyname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitfriendlyname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitfriendlyname_l_empty72","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitmimeheaders","displayName":"Change the limit for the number of MIME headers (User)","description":"By default, the limit is 20000 for the number of MIME headers when an e-mail message is converted from MIME to MAPI. The number can be set to any positive integer. This helps prevent scenarios in which Outlook hangs while attempting conversion.","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitmimeheaders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitmimeheaders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitmimeheaders_l_empty74","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_addnewcategories","displayName":"Add new categories (User)","description":"This policy setting allows you to add (append) new categories to the user's current list of categories.\r\n\r\nIf you enable this policy setting, you may add (append) new categories to the user's current list of categories (the default list of categories or the list of categories the user has created). A category's length should not exceed 255 characters.\r\n\r\nIf you disable or do not configure this policy setting, the user's current list of categories is not modified.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_addnewcategories_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_addnewcategories_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_addnewcategories_l_enternewcategoriessemicolondelimited","displayName":"Enter new categories (comma or semicolon delimited) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_allowcryptoautosave","displayName":"Extend Outlook Autosave to include encrypted e-mail messages (User)","description":"By default, Outlook does not automatically save copies of unsent e-mail messages that are encrypted. You can enable this setting so that Outlook autosaves unsent encrypted e-mail messages to the user's Drafts folder.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_allowcryptoautosave_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_allowcryptoautosave_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disableaddinlogging","displayName":"Disable Windows event logging for Outlook add-ins (User)","description":"This policy setting governs logging of connected add-ins to the Windows event log.\r\n\r\nIf you enable this policy setting, an inventory of connected Outlook add-ins will not be written to the Windows event log.\r\n\r\nIf you disable or do not configure this policy setting, an inventory of connected Outlook add-ins will be written to the Windows event log.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disableaddinlogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disableaddinlogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disabledistributionlistexpansion","displayName":"Do not expand Contact Groups (User)","description":"This policy setting controls whether Outlook users can expand Contact Groups when addressing e-mail messages. \r\n\r\nIf you enable this policy setting, Outlook users cannot expand Contact Groups. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook users add a Contact Group to the To, CC, or BCC fields of an e-mail message or other item, they can expand the Contact Group to see the e-mail addresses of everyone in the group.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disabledistributionlistexpansion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disabledistributionlistexpansion_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablevlvbrowsingonldapservers","displayName":"Disable VLV Browsing on LDAP servers (User)","description":"When this policy is enabled, Outlook will not use the Virtual List Views (VLV) LDAP extension when querying an LDAP servier. When the policy is not configured or disabled, Outlook will use the Virtual Lst Views (VLV) LDAP extension when querying an LDAP server.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablevlvbrowsingonldapservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablevlvbrowsingonldapservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablewindowsfriendlylogonmailquery","displayName":"Do not show unread message count on Windows Welcome screen (User)","description":"By default, Windows queries Outlook for the unread message count for users and displays the result on the Windows Welcome screen. By enabling this setting, you can change this behavior so that Windows does not provide this feature on the Welcome screen.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablewindowsfriendlylogonmailquery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablewindowsfriendlylogonmailquery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_donotdownloadpermissionlicenseforirmemailduring","displayName":"Do not download rights permission license information for IRM e-mail during Exchange folder sync (User)","description":"By default, IRM license information for e-mail messages is downloaded to the user's local cache when Outlook synchronizes with Exchange. By enabling this setting, you can change this behavior so that licence information is not cached locally and users must connect to the network to retreive license information in order to open rights-managed e-mail messages.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_donotdownloadpermissionlicenseforirmemailduring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_donotdownloadpermissionlicenseforirmemailduring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\Outlook\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\Outlook\\Addins.\r\n\r\nYou can also obtain the ProgID of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.\r\n\r\nAdd-ins that are disabled by this policy will never be disabled by the Outlook add-in disabling feature, which disables add-ins for performance, resiliency, or reliability reasons.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges","displayName":"Managing Categories during e-mail exchanges (User)","description":"By default, categories on incoming e-mail are removed, and categories are removed when replying to or forwarding an e-mail. This setting allows you to control how categories are shared as users exchange e-mail messages. You can specify that categories are not removed for users' incoming e-mail. You can also specify that e-mail messages that users reply to or forward retain the categories on the original message.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_acceptcategoriesassignedtoincomingmailbythesender","displayName":"Accept Categories assigned to incoming mail by the sender (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_acceptcategoriesassignedtoincomingmailbythesender_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_acceptcategoriesassignedtoincomingmailbythesender_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_whenreplyingtoandforwardingmailincludepersonalcategories","displayName":"When replying to and forwarding mail, include personal categories (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_whenreplyingtoandforwardingmailincludepersonalcategories_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_whenreplyingtoandforwardingmailincludepersonalcategories_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventmapiservicesfrombeingadded","displayName":"Prevent MAPI services from being added (User)","description":"By default, any MAPI service can be added to a user profile as an Outlook account. This setting allows you to prevent users from adding a specific MAPI services on the list of services. To prevent adding a MAPI service, append the name of the service to the list of services stored in this setting, separated by from a previous name by a semi-colon (;). For example, if you wanted to prevent adding the Outlook Mobile Service and Live Meeting Transport, you would configure this setting \"MSOMS;LiveMeeting\".","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventmapiservicesfrombeingadded_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventmapiservicesfrombeingadded_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventmapiservicesfrombeingadded_l_preventmapiservicesfrombeingaddedpart","displayName":"Enter MAPI services to disable (semi-colon delimited) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes","displayName":"Prevent users from adding e-mail account types (User)","description":"Disables/Enables the option for adding e-mail account of the associated type in the Server Types page of the E-mail Accounts dialog box.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingeasemailaccounts","displayName":"Prevent users from adding Exchange ActiveSync e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingeasemailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingeasemailaccounts_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingexchangeemailaccounts","displayName":"Prevent users from adding Exchange e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingexchangeemailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingexchangeemailaccounts_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingimapemailaccounts","displayName":"Prevent users from adding IMAP e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingimapemailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingimapemailaccounts_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingothertypesofemailaccounts","displayName":"Prevent users from adding other types of e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingothertypesofemailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingothertypesofemailaccounts_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingpop3emailaccounts","displayName":"Prevent users from adding POP3 e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingpop3emailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingpop3emailaccounts_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfrommakingchangestooutlookprofiles","displayName":"Prevent users from making changes to Outlook profiles (User)","description":"This policy setting allows you to prevent users from accessing profile or account configuration tools through either Account Settings or through the Mail Control Panel Applet.\r\n\r\nIf you enable this policy setting, users will see the error, \"This feature has been disabled by your system administrator\" if they select the Account Settings button under Account Information found by clicking on the File tab. Users will also be unable to access profile configuration the Mail Control Panel Applet.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to access Account Settings and the Mail Control Panel Applet normally.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfrommakingchangestooutlookprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfrommakingchangestooutlookprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest","displayName":"Specify delay before sending people search request (User)","description":"This policy is used to set the delay for sending people search requests from the Find a Contact box in Outlook and the Related People section that appears in the Backstage view (Info tab) of Office applications.\r\n\r\nIf you enable this policy setting, you can specify the delay in milliseconds between when the user stops (or pauses) typing in the search box and when the application sends a search request.\r\n\r\nIf you disable or do not configure this policy setting, the default delay is 200 milliseconds (0.20 seconds).","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest_l_specifydelaybeforesendingpeoplesearchrequestspinid","displayName":"in milliseconds (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout","displayName":"Set the time-out interval for Outlook people search (User)","description":"This policy setting controls the time-out interval of Outlook people search. Outlook returns as many people search results as possible before the time-out interval lapses. If the search results are incomplete, Outlook displays a message at the bottom of the results list.\r\n\r\nIf you enable this policy setting, you can specify the time-out interval in milliseconds.\r\n\r\nIf you disable or do not configure this policy setting, the time-out interval is 60,000 milliseconds (60 seconds).","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout_l_specifyoutlookpeoplesearchtimeoutspinid","displayName":"in milliseconds (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_workflowtasksinoutlook","displayName":"Do not display \"Open this task\" button for workflow tasks (User)","description":"As part of E-mail notification of workflow tasks, users can edit a task by clicking the \"Open this task\" button to display the task dialog box for the workflow task. When this setting is enabled, the \"Open this task\" button is not displayed.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_workflowtasksinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_workflowtasksinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforostfiles","displayName":"Default location for OST files (User)","description":"This policy setting allows you to specify a different folder location for Outlook Data File (OST) files on user computers. \r\n\r\nIf you enable this policy setting, you can specify a location for OST files on user computers.\r\n\r\nIf you disable or do not configure this policy setting, OST files are located in: %LOCALAPPDATA%\\Microsoft\\Outlook on user computers.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforostfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforostfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforostfiles_l_defaultlocationforostfilespart","displayName":"Default location for OST files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforpstfiles","displayName":"Default location for PST files (User)","description":"This policy setting allows you to specify a different folder location for Outlook Data File (PST) files on user computers. \r\n\r\nIf you enable this policy setting, you can specify a location for PST files on user computers.\r\n\r\nIf you disable or do not configure this policy setting, PST files are located in: %USERPROFILE%\\Documents\\Outlook Files\\ on user computers.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforpstfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforpstfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforpstfiles_l_defaultlocationforpstfiles79","displayName":"Default location for PST files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_donotsendmeetingforwardnotifications","displayName":"Do not send meeting forward notifications (User)","description":"This policy setting prevents Outlook from sending meeting forward notifications. This does not affect whether or not Exchange sends meeting forward notifications. \r\n\r\nIf you enable this policy setting, Outlook will not send meeting forward notifications.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will send meeting forward notifications.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_donotsendmeetingforwardnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_donotsendmeetingforwardnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstabsolutemaximumsize","displayName":"Large PST: Absolute maximum size (User)","description":"Specifies the maximum allowable size (in megabytes) for an Outlook Data File.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstabsolutemaximumsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstabsolutemaximumsize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstabsolutemaximumsize_l_enterabsolutemaximumsizeforpstinmegabytes2","displayName":"(0 - 4,294,967,295 MB) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstsizetodisableaddingnewcontent","displayName":"Large PST: Size to disable adding new content (User)","description":"Specifies the size at which Outlook will no longer accept new content into an Outlook Data File.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstsizetodisableaddingnewcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstsizetodisableaddingnewcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstsizetodisableaddingnewcontent_l_entersizetodisableaddingnewcontenttopstinmegabytes2","displayName":"(0 - 4,294,967,295 MB) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize","displayName":"Legacy PST: Absolute maximum size (User)","description":"Specifies the maximum allowable size (in bytes) for an Outlook 97-2002 Data File.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize_l_enterabsolutemaximumsizeforpstinbytes2","displayName":"(0 - 2,075,149,312 bytes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstsizetodisableaddingnewcontent","displayName":"Legacy PST: Size to disable adding new content (User)","description":"Specifies the size at which Outlook will no longer accept new content into an Outlook Data File.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstsizetodisableaddingnewcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstsizetodisableaddingnewcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstsizetodisableaddingnewcontent_l_entersizetodisableaddingnewcontenttopstinbytes2","displayName":"(0 - 2,075,149,312 Bytes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_permanentlyremovealldeleteditems","displayName":"Permanently remove all deleted content from PST and OST files (User)","description":"By default, a small percentage of deleted data is not overwritten in Outlook PST and OST files. By enabling this setting, all deleted data in PST and OST files is overwritten when users exit Outlook.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_permanentlyremovealldeleteditems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_permanentlyremovealldeleteditems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi","displayName":"Preferred PST Mode (Unicode/ANSI) (User)","description":"Specifies whether new PST files created by the user are to be in Unicode or ANSI format, and whether the user is allowed to choose that format.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_l_chooseadefaultformatfornewpsts","displayName":"Choose a default format for new PSTs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_l_chooseadefaultformatfornewpsts_0","displayName":"Prefer Unicode PST","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_l_chooseadefaultformatfornewpsts_1","displayName":"Prefer ANSI PST","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_l_chooseadefaultformatfornewpsts_2","displayName":"Enforce Unicode PST","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_l_chooseadefaultformatfornewpsts_3","displayName":"Enforce ANSI PST","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingnewcontentto","displayName":"Prevent users from adding new content to existing PST files (User)","description":"This setting prevents users from adding any new content to PST files linked to their profiles.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingnewcontentto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingnewcontentto_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts","displayName":"Prevent users from adding PSTs to Outlook profiles and/or prevent using Sharing-Exclusive PSTs (User)","description":"By default, users can add PSTs to their Outlook profiles and can use Sharing-Exclusive PSTs for storing SharePoint Lists and Internet Calendars. You can use this setting to limit users' ability to store mail in a decentralized fashion. You can block the use of PSTs completely, but be aware that blocking all PSTs disables Outlook features such as SharePoint Lists and Internet Calendar. \r\n\r\nIf instead you allow only Sharing-Exclusive PSTs to be added to user profiles, PST usage is still limited but the Outlook features that rely on special PSTs are not disabled. The setting that allows Sharing-Exclusive PSTs to be added blocks users from creating new folders in the Sharing-Exclusive PST; copying existing mail folders from their default store to the PST; and copying individual mail items to the root of the PST.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts_l_empty78","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts_l_empty78_0","displayName":"(default) PSTs can be added","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts_l_empty78_1","displayName":"No PSTs can be added","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts_l_empty78_2","displayName":"Only Sharing-Exclusive PSTs can be added","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_pstnullfreeondelete","displayName":"PST Null Data on Delete (User)","description":"This policy setting allows you to force Outlook to fully nullify deleted data in users’ Personal Folder files (.pst) at the time that the data is deleted. \r\n \r\nIf you enable this policy setting, data is immediately nullified in PST files when deleted. \r\n \r\nIf you disable or do not configure this policy setting, data remains in PST files until it is purged or overwritten by the user.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_pstnullfreeondelete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_pstnullfreeondelete_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_upgradeonlythedefaultstore","displayName":"Upgrade only the default store (User)","description":"This policy setting allows you to specify that only the default data file is upgraded on the first boot of Outlook.\r\n\r\nIf you enable this policy setting, only the data file associated with your delivery mailbox is upgraded.\r\n\r\nIf you disable or do not configure this policy setting, all Outlook Data Files are upgraded.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_upgradeonlythedefaultstore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_upgradeonlythedefaultstore_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior","displayName":"Configure fast shutdown behavior (User)","description":"This policy setting controls Outlook's \"fast shutdown\" behavior. \r\n\r\nIf you enable this policy setting, you may select one of these options:\r\n\r\n- MAPI provider does not support: Outlook should always use Fast Shutdown unless a MAPI provider explicitly does not support it.\r\n- All MAPI providers support: Outlook only uses Fast Shutdown if all MAPI providers do support it.\r\n- Never: Outlook never uses Fast Shutdown\r\n\r\nIf you disable or do not configure this policy setting, the behavior will be the same as the \"MAPI provider does not support\" option.","helpText":"","infoUrls":[],"categoryId":"ffb0a109-2507-42b3-b26f-9f667f2d5029","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior_l_configurefastshutdownbehaviordropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ffb0a109-2507-42b3-b26f-9f667f2d5029","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior_l_configurefastshutdownbehaviordropid_0","displayName":"MAPI provider does not support","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior_l_configurefastshutdownbehaviordropid_1","displayName":"All MAPI providers support","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior_l_configurefastshutdownbehaviordropid_2","displayName":"Never","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehaviorforaddins","displayName":"Configure fast shutdown behavior for add-ins (User)","description":"This policy setting controls Outlook's \"fast shutdown\" behavior for add-ins.\r\n\r\nIf you enable this policy setting, the BeginShutdown and OnDisconnection events should always be called for all add-ins. \r\n\r\nIf you disable or do not configure this policy setting, all Outlook addins should always use the Addin Fast Shutdown behavior and not have the BeginShutdown and OnDisconnection events called.","helpText":"","infoUrls":[],"categoryId":"ffb0a109-2507-42b3-b26f-9f667f2d5029","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehaviorforaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehaviorforaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_preventshutdownifexternalreferencesexist","displayName":"Prevent shutdown if external references exist (User)","description":"This policy setting controls whether Outlook should ignore external references during shutdown.\r\n\r\nIf you enable this policy setting, shutdown will not occur if external references exist.\r\n\r\nIf you disable or do not configure this policy setting, external references will be ignored during shutdown.","helpText":"","infoUrls":[],"categoryId":"ffb0a109-2507-42b3-b26f-9f667f2d5029","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_preventshutdownifexternalreferencesexist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_preventshutdownifexternalreferencesexist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions_l_internetandnetworkpathsintohyperlinks","displayName":"Internet and network paths into hyperlinks (User)","description":"This policy setting specifies whether Outlook automatically turns text that represents Internet and network paths into hyperlinks. This option can also be configured by selecting the “Internet and network paths with hyperlinks” check box that is available on the Outlook | File | Options | Mail | Editor Options.... | Proofing | AutoCorrect Options… | AutoFormat tab on the user interface (UI).\r\n\r\nIf you enable or do not configure this policy setting, text in Outlook that represents internet and network paths are automatically turned into hyperlinks. This is the default behavior of Outlook.\r\n\r\nIf you disable this policy setting, text in Outlook that represents internet and network paths are not automatically turned into hyperlinks.","helpText":"","infoUrls":[],"categoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","categoryName":"Outlook Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions_l_internetandnetworkpathsintohyperlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions_l_internetandnetworkpathsintohyperlinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_cacheothersmail","displayName":"Disable shared mail folder caching (User)","description":"This policy setting allows you to control the caching of shared mail folders.\r\n\r\nIf you enable this policy setting, Outlook will only cache shared non-mail folders.\r\n\r\nIf you disable or do not configure this policy setting, shared mail and non-mail folders you have access to are cached in your .ost file when you add another mailbox to your profile.","helpText":"","infoUrls":[],"categoryId":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","categoryName":"Delegates","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_cacheothersmail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_cacheothersmail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_locationofitemsdeletedbydelegates","displayName":"Store deleted items in owner's mailbox instead of delegate's mailbox (User)","description":"This policy setting allows you to store deleted items in the owner's mailbox instead of the delegate's mailbox.\r\n\r\nIf you enable this policy setting, deleted items are stored in the owner's Deleted Items folder. For this setting to work correctly, the owner must also give the delegate permission to write to the owner's Deleted Items folder.\r\n\r\nIf you disable or do not configure this policy setting, items deleted by a delegate are stored in the delegate's Deleted Items Folder instead of the owner's Deleted Items folder.","helpText":"","infoUrls":[],"categoryId":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","categoryName":"Delegates","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_locationofitemsdeletedbydelegates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_locationofitemsdeletedbydelegates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_disablereadingpanecompose","displayName":"Disable Reading Pane Compose (User)","description":"This policy setting allows you to control whether user’s responses to emails are composed inline on the reading pane or in a new window.\r\n\r\nIf you enable this policy setting, responses to emails are composed in new windows.\r\n\r\nIf you disable or do not configure this policy setting, responses to emails are composed inline in the reading pane.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_disablereadingpanecompose_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_disablereadingpanecompose_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_forceselectionofaccountbeforesending","displayName":"Force selection of account before sending (User)","description":"This policy setting enables you to force users to select an e-mail account from which to send outgoing e-mail.\r\n\r\nIf you enable this policy setting, users must choose an e-mail account before they can send an e-mail.\r\n\r\nIf you disable or do not configure this policy setting, e-mail is sent from the default e-mail account if users do not select a specific e-mail account.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_forceselectionofaccountbeforesending_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_forceselectionofaccountbeforesending_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_outlookprotectionrules","displayName":"Outlook Protection Rules (User)","description":"This policy setting controls whether the Outlook Protection Rules add-in is enabled.\r\n\r\nIf you enable or do not configure this policy setting the add-in automatically downloads Outlook Protection Rules from Exchange and processes them when each Exchange mailbox user composes a new e-mail. \r\n\r\nIf you disable this policy setting the add-in does not download or process Outlook Protection Rules.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_outlookprotectionrules_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_outlookprotectionrules_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat_l_disablesignatures","displayName":"Do not allow signatures for e-mail messages (User)","description":"This policy setting allows you to prevent Outlook users from adding signatures to e-mails they create, reply to, or forward. \r\n\r\nIf you enable this policy setting, Outlook users cannot manually add signatures to e-mails they create, reply to, or forward, nor will they be able to configure automatic signatures.\r\n\r\nIf you disable or do not configure this policy setting, Outlook 2016 users can add signatures to e-mail messages either manually or automatically.","helpText":"","infoUrls":[],"categoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","categoryName":"Mail Format","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat_l_disablesignatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat_l_disablesignatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_autoselectencodingforoutgoingmessages","displayName":"Auto-select encoding for outgoing messages (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_autoselectencodingforoutgoingmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_autoselectencodingforoutgoingmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_disableinternationalizeddomainnamesidninoutlook","displayName":"Disable Internationalized Domain Names (IDN) in Outlook (User)","description":"By default, Outlook supports Internationalized Domain Names (IDN) for SMTP addresses in Outlook if Windows provides the appropriate support for this feature. You can disable IDN support so that Punycode rather than native characters are used for rendering SMTP addresses. \r\n\r\nYou might choose to disable IDN support in Outlook if you do not typically expect non-ASCII characters in SMTP addresses. \r\n\r\nThis setting does not affect the support of IDN in URLs.","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_disableinternationalizeddomainnamesidninoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_disableinternationalizeddomainnamesidninoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages","displayName":"Encoding for outgoing messages (User)","description":"Sets the value in the option \"Preferred encoding for outgoing messages\".","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages","displayName":"Use this encoding for outgoing messages: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28596","displayName":"Arabic (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1256","displayName":"Arabic (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28594","displayName":"Baltic (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1257","displayName":"Baltic (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28592","displayName":"Central European (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1250","displayName":"Central European (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_54936","displayName":"Chinese Simplified (GB18030)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_936","displayName":"Chinese Simplified (GB2312)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_52936","displayName":"Chinese Simplified (HZ)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_950","displayName":"Chinese Traditional (Big5)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28595","displayName":"Cyrillic (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_20866","displayName":"Cyrillic (KOI8-R)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_21866","displayName":"Cyrillic (KOI8-U)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1251","displayName":"Cyrillic (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28597","displayName":"Greek (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1253","displayName":"Greek (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_38598","displayName":"Hebrew (ISO-Logical)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1255","displayName":"Hebrew (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_51932","displayName":"Japanese (EUC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_50220","displayName":"Japanese (JIS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_50221","displayName":"Japanese (JIS-Allow 1 byte Kana)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_932","displayName":"Japanese (Shift-JIS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_949","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_51949","displayName":"Korean (EUC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28593","displayName":"Latin 3 (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28605","displayName":"Latin 9(ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_874","displayName":"Thai (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28599","displayName":"Turkish (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1254","displayName":"Turkish (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_65000","displayName":"Unicode (UTF-7)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_65001","displayName":"Unicode (UTF-8)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_20127","displayName":"US-ASCII","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_50000","displayName":"User Defined","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1258","displayName":"Vietnamese (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28591","displayName":"Western European (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1252","displayName":"Western European (Windows)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags","displayName":"English message headers and flags (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_l_useenglishformessageflags","displayName":"Use English for message flags (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_l_useenglishformessageflags_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_l_useenglishformessageflags_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_l_useenglishformessageheadersonrepliesorforwards","displayName":"Use English for message headers on replies or forwards (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_l_useenglishformessageheadersonrepliesorforwards_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_l_useenglishformessageheadersonrepliesorforwards_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_euroencodingforoutgoingmessages","displayName":"Euro encoding for outgoing messages (User)","description":"This policy setting allows you to choose whether to ignore the euro character when auto-detecting the encoding of an outgoing message and the preferred encoding does not support euro.","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_euroencodingforoutgoingmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_euroencodingforoutgoingmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_euroencodingforoutgoingmessages_l_whenpreferredencodingdoesnotsupporteuro2","displayName":"Auto-select should: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_euroencodingforoutgoingmessages_l_whenpreferredencodingdoesnotsupporteuro2_0","displayName":"Send messages as UTF 8","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_euroencodingforoutgoingmessages_l_whenpreferredencodingdoesnotsupporteuro2_1","displayName":"ignore euro","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions","displayName":"Outlook Rich Text options (User)","description":"This policy setting controls how Outlook sends Rich Text Format (RTF) messages to Internet recipients.\r\n\r\nIf you enable this policy setting, you may choose from the following for handling RTF messages addressed to recipients on the Internet:\r\n* Convert to Plain Text format - Outlook converts the message to plain text format in the default character set. Any message formatting will be lost.\r\n\r\nIf you disable or do not configure this policy setting, Outlook automatically converts RTF formatted messages that are sent over the Internet to HTML format, so that the message formatting is maintained and attachments are received.","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions_l_whensendingoutlookrichtextmessagestointernetrecipients2","displayName":"Use this format: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions_l_whensendingoutlookrichtextmessagestointernetrecipients2_1","displayName":"Convert to Plain Text format","description":null,"helpText":null}},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions","displayName":"Plain text options (User)","description":"This policy setting allows you to control how plain text messages are formatted when they are sent from Outlook. \r\n\r\nIf you enable this policy setting, text is automatically wrapped in Internet e-mail messages and attachments are encoded in UUENCODE format. \r\n\r\nIf you disable this policy setting, Outlook uses the standard MIME format to encode attachments in plain text Outlook messages. Users will not be able to change this configuration. \r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Disabled, but users can modify plain text options in Outlook when required by clicking Tools, clicking Options, clicking the Mail Format tab, clicking Internet Format, and changing the values under \"Plain text options\".","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_automaticallywraptextatxcharacters","displayName":"Automatically wrap text at characters. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_encodeattachmentsinuuencodeformatwhensending1","displayName":"Encode attachments in UUENCODE format (User)","description":"","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_encodeattachmentsinuuencodeformatwhensending1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_encodeattachmentsinuuencodeformatwhensending1_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor","displayName":"Set message format (User)","description":"This policy setting controls the default message format in Outlook. \r\n\r\nIf you do not configure this policy setting, new e-mail messages in Outlook are formatted as HTML. \r\n\r\nIf you enable this policy setting, you can set the default e-mail format in Outlook to HTML, Rich Text, or plain text. Users can choose a format other than the default when composing messages. \r\n\r\nIf you disable this policy setting, Outlook uses HTML as the default e-mail format and users will not be able to change it. \r\n\r\nIf you do not configure this policy setting, Outlook uses HTML as the default e-mail format, but users can choose a format other than the default when composing messages.","helpText":"","infoUrls":[],"categoryId":"25df12bc-5ebd-4db2-8930-5d27690f3e60","categoryName":"Message Format","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor_l_usethefollowingformateditorforemailmessages","displayName":"Use the following format for e-mail messages: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25df12bc-5ebd-4db2-8930-5d27690f3e60","categoryName":"Message Format","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor_l_usethefollowingformateditorforemailmessages_131072","displayName":"HTML","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor_l_usethefollowingformateditorforemailmessages_196608","displayName":"Rich Text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor_l_usethefollowingformateditorforemailmessages_65536","displayName":"Plain Text","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts","displayName":"Stationery Fonts (User)","description":"This policy setting allows you to choose a Stationery font option.\r\n\r\nIf you enable this policy setting, a Stationery font option from the dropdown list will be enforced.\r\n\r\nIf you disable or do not configure this policy setting, the default setting (use theme's font) will be used.","helpText":"","infoUrls":[],"categoryId":"88b16683-81f2-450a-9bf2-42f582e0b748","categoryName":"Stationery and Fonts","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts_l_stationeryfontoptions","displayName":"Stationery font options: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"88b16683-81f2-450a-9bf2-42f582e0b748","categoryName":"Stationery and Fonts","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts_l_stationeryfontoptions_0","displayName":"Use theme's font","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts_l_stationeryfontoptions_1","displayName":"Use user's font on replies and forwards","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts_l_stationeryfontoptions_2","displayName":"Always use user's fonts","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailsetup_l_mailaccountoptions","displayName":"Mail account options (User)","description":"Send messages immediately when connected","helpText":"","infoUrls":[],"categoryId":"114356a4-dfc9-44e9-9a62-f1d601d48445","categoryName":"Mail Setup","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailsetup_l_mailaccountoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailsetup_l_mailaccountoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"fa6bfb01-34f6-4c54-89b9-f7e717e6d394","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_allowselectionfloaties","displayName":"Show Mini Toolbar on selection (User)","description":"Disabling this policy setting will result in Mini Toolbar not being displayed on text selection. By default, Mini Toolbar on selection is enabled and its visibility can be changed via a setting in the Editor Options dialog box.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_allowselectionfloaties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_allowselectionfloaties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableonlinemodeauthdiagnostics","displayName":"Disable online mode for Get Diagnostics. (User)","description":"\r\n This policy setting determines whether online mode for Get Diagnostics is allowed. Enabling this setting will block Get Diagnostics feature from sending authentication and diagnostics logs to our service.\r\n Users will now go through offline mode. We will collect all the logs and store them in the Downloads folder of the user. This user can contact support and decide if they want to send us the logs. \r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableonlinemodeauthdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableonlinemodeauthdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace","displayName":"Disable Preview Place. (User)","description":"\r\n This policy setting determines whether the Preview Place feature is allowed. Enabling this setting will block the Preview Place feature from being available.\r\n Users will no longer be able to preview and provide feedback on upcoming changes in Outlook.\r\n\tNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablereadingpane","displayName":"Do not display the reading pane (User)","description":"By default, the Reading Pane is enabled only in the mail module and located on the right hand side of the window. This setting allows you to disable the reading pane.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablereadingpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablereadingpane_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_donotdownloadphotosfromtheactivedirectory","displayName":"Do not download photos from the Active Directory (User)","description":"This policy setting controls whether user photos will be downloaded from the Active Directory (if available). \r\n\r\nIf you enable this policy setting, photos will not be downloaded.\r\n\r\nIf you disable or do not configure this policy setting, photos will be downloaded.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_donotdownloadphotosfromtheactivedirectory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_donotdownloadphotosfromtheactivedirectory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_emptydeleteditemsfolder","displayName":"Empty the Deleted Items folder when Outlook closes (User)","description":"By default, the Deleted Items folder is not emptied when users exit Outlook. By enabling this setting, you can change this behavior so that the Deleted Items folder is emptied when Outlook closes.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_emptydeleteditemsfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_emptydeleteditemsfolder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hideappsstorebuttoninhometabribbon","displayName":"Hide the Office Store button (User)","description":"The Office Store button allows users to get apps for Outlook from the Home tab in the ribbon.\r\n\r\nIf you enable this policy setting, the Office Store button doesn’t appear on the Home tab in the ribbon.\r\n\r\nIf you disable or don’t configure this policy setting, the Office Store button appears on the Home tab in the ribbon.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hideappsstorebuttoninhometabribbon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hideappsstorebuttoninhometabribbon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hidephotolink","displayName":"Hide photo link (User)","description":"This policy setting configures the link to the user's My Site (when detected) where the user's photo can be uploaded. This link is under the File tab. \r\n\r\nIf you enable this policy setting, the link is not visible.\r\n\r\nIf you disable or do not configure this policy setting, the link is visible.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hidephotolink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hidephotolink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_makeoutlookthedefaultprogramforemailcontactsandcalendar","displayName":"Make Outlook the default program for E-mail, Contacts, and Calendar (User)","description":"This policy setting controls whether Outlook is the default program for e-mail, contacts, and calendar services.\r\n\r\nIf you enable this policy setting, the \"Make Outlook the default program for E-mail, Contacts, and Calendar\" check box on the General tab of the Office Center is selected and users cannot change it.\r\n\r\nIf you disable this policy setting, users cannot make Outlook the default program for these services.\r\n\r\nIf you do not configure this policy setting, Outlook is made the default program for e-mail, contacts, and calendar services when it is installed, although users can designate other programs as the default programs for these services.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_makeoutlookthedefaultprogramforemailcontactsandcalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_makeoutlookthedefaultprogramforemailcontactsandcalendar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane","displayName":"Reading Pane (User)","description":"Checks/Unchecks the option \"Mark items as read when viewed in the Reading Pane\" in the Reading Pane dialog box.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markitemasreadwhenselectionchanges","displayName":"Mark item as read when selection changes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markitemasreadwhenselectionchanges_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markitemasreadwhenselectionchanges_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markmessagesasreadinreadingwindow","displayName":"Mark messages as read in reading window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markmessagesasreadinreadingwindow_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markmessagesasreadinreadingwindow_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_singlekeyreadingusingspacebar","displayName":"Single key reading using spacebar (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_singlekeyreadingusingspacebar_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_singlekeyreadingusingspacebar_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_waitxxxsecondsbeforemarkingitemsasread","displayName":"Wait xxx seconds before marking items as read: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_sortfoldersalphabetically","displayName":"Sort folders alphabetically (User)","description":"This policy setting controls whether users can rearrange their folders in Outlook.\r\n\r\nIf you enable this policy setting, users cannot rearrange their folders. The folders are displayed alphabetically.\r\n\r\nIf you disable this policy setting, users can rearrange their folders, but are not able to turn automatic alphabetical sorting back on from the Ribbon. \r\n\r\nIf you do not configure this policy setting, users can rearrange their folders, and turn automatic alphabetical sorting back on from the Ribbon.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_sortfoldersalphabetically_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_sortfoldersalphabetically_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disablefolderhomepagesforfoldersinnondefaultstores","displayName":"Do not allow folders in non-default stores to be set as folder home pages (User)","description":"By default, creating folder home pages for folders in non-default stores is blocked; you cannot define a folder home page for a folder that is in a non-default store. This setting allows you to unblock folder home pages for folders in non-default stores. Note that other settings might still prevent folder home pages from functioning.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disablefolderhomepagesforfoldersinnondefaultstores_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disablefolderhomepagesforfoldersinnondefaultstores_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts","displayName":"Do not allow Outlook object model scripts to run for shared folders (User) (Deprecated)","description":"This policy setting controls whether Outlook executes scripts associated with custom forms or folder home pages for shared folders. \r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with shared folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for shared folders. \r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_v2","displayName":"Do not allow Outlook object model scripts to run for shared folders (User)","description":"This policy setting controls whether Outlook executes scripts associated with custom forms or folder home pages for shared folders. \r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with shared folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for shared folders. \r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders","displayName":"Do not allow Outlook object model scripts to run for public folders (User) (Deprecated)","description":"This policy setting controls whether Outlook executes scripts that are associated with custom forms or folder home pages for public folders.\r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you do not configure this policy setting, Outlook will not run any scripts associated with public folders by default. Users can configure the setting in the Trust Center by selecting the “Allow script in public folders” check box.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_v2","displayName":"Do not allow Outlook object model scripts to run for public folders (User)","description":"This policy setting controls whether Outlook executes scripts that are associated with custom forms or folder home pages for public folders.\r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you do not configure this policy setting, Outlook will not run any scripts associated with public folders by default. Users can configure the setting in the Trust Center by selecting the “Allow script in public folders” check box.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_enablemailloggingtroubleshooting","displayName":"Enable mail logging (troubleshooting) (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_enablemailloggingtroubleshooting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_enablemailloggingtroubleshooting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_minimizeoutlooktothesystemtray","displayName":"Minimize Outlook to the system tray (User)","description":"Checks/Unchecks the Outlook system tray icon option \"Hide When Minimized\".","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_minimizeoutlooktothesystemtray_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_minimizeoutlooktothesystemtray_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_moreoptions","displayName":"Warn before permanently deleting items (User)","description":"By default, a warning message is displayed before Outlook items are permanently deleted. By disabling this setting, you can change this behavior to not display the warning message.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_moreoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_moreoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_msgunicodeformatwhendraggingtofilesystem","displayName":"Use Unicode format when dragging e-mail message to file system (User) (Deprecated)","description":"This policy setting controls whether e-mail messages dragged from Outlook to the file system are saved in Unicode or ANSI format. \r\n\r\nIf you enable or do not configure this policy setting, when users drag an e-mail message from Outlook to the file system, Outlook uses the Unicode character encoding standard to create the message file, which preserves special characters in the message. \r\n\r\nIf you disable this policy setting, when users drag an e-mail message from Outlook to the file system, the message file created is in ANSI format.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_msgunicodeformatwhendraggingtofilesystem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_msgunicodeformatwhendraggingtofilesystem_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_msgunicodeformatwhendraggingtofilesystem_v2","displayName":"Use Unicode format when dragging e-mail message to file system (User)","description":"This policy setting controls whether e-mail messages dragged from Outlook to the file system are saved in Unicode or ANSI format. \r\n\r\nIf you enable or do not configure this policy setting, when users drag an e-mail message from Outlook to the file system, Outlook uses the Unicode character encoding standard to create the message file, which preserves special characters in the message. \r\n\r\nIf you disable this policy setting, when users drag an e-mail message from Outlook to the file system, the message file created is in ANSI format.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_msgunicodeformatwhendraggingtofilesystem_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_msgunicodeformatwhendraggingtofilesystem_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_preventsavingsyncconflicts","displayName":"Prevent saving sync conflicts (User)","description":"This policy setting allows you to prevent saving of sync conflicts.\r\n\r\nIf you enable this policy setting, Outlook will not save sync conflicts.\r\n\r\nIf you disable or do not configure this policy setting, all conflicts except those related to Calendar and RSS items are saved by default.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_preventsavingsyncconflicts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_preventsavingsyncconflicts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_savecalendarconflicts","displayName":"Save calendar sync conflicts (User)","description":"This policy setting allows you to save calendar sync conflicts.\r\n\r\nIf you enable this policy setting, Outlook will save calendar sync conflicts.\r\n\r\nIf you disable or do not configure this policy setting, calendar sync conflicts are not saved by default.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_savecalendarconflicts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_savecalendarconflicts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_saverssconflicts","displayName":"Save RSS conflicts (User)","description":"This policy setting allows you to save RSS conflicts.\r\n\r\nIf you enable this policy setting, RSS conflicts will be saved. This policy setting takes precedence over the \"Prevent saving sync conflicts\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, RSS conflicts are not saved.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_saverssconflicts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_saverssconflicts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts","displayName":"Turn on logging for all conflicts (User)","description":"This policy setting allows you to create Modification Resolution logs whenever the Outlook conflict resolver runs. \r\n\r\nIf you enable this policy setting, Outlook will create Modification Resolution logs whenever the Outlook conflict resolver runs. By default, Modification Resolution logs are written into the Sync Issues folder whenever Outlook's conflict resolver cannot resolve a conflict.\r\n\r\nYou may select one of these options:\r\n- No conflicts are logged: No Modification Resolution logs are written into the Sync Issues folder whenever Outlook's conflict resolver runs. \r\n- All conflicts logged: Modification Resolution logs are written into the Sync Issues folder whenever Outlook's conflict resolver runs.\r\n- Unresolved conflicts logged only: Modification Resolution logs are written into the Sync Issues folder in Outlook when the Outlook conflict resolver cannot resolve a conflict.\r\n\r\nThis applies to all item types.\r\n\r\nIf you disable or do not configure this policy setting, no Modification Resolution logs are written when the Outlook conflict resolver runs.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid_0","displayName":"No conflicts are logged (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid_1","displayName":"All conflicts logged","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid_2","displayName":"Unresolved conflicts logged only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders","displayName":"Reminders (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"13eb248a-4549-4d23-9ada-23b40edf36bf","categoryName":"Reminder Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_l_displaythereminder","displayName":"Display the reminder (User)","description":"","helpText":"","infoUrls":[],"categoryId":"13eb248a-4549-4d23-9ada-23b40edf36bf","categoryName":"Reminder Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_l_displaythereminder_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_l_displaythereminder_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_l_playremindersound","displayName":"Play reminder sound (User)","description":"","helpText":"","infoUrls":[],"categoryId":"13eb248a-4549-4d23-9ada-23b40edf36bf","categoryName":"Reminder Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_l_playremindersound_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_l_playremindersound_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_archiveignorelastmodifiedtime","displayName":"Change the criteria that Outlook uses to archive different item types (User)","description":"If you enable this policy setting, Outlook ignores the last modified date and archives items based on a date that is specific for the item type, as follows:\r\n\r\n-Email message: The received date.\r\n-Calendar item: The actual date that an appointment, event, or meeting is scheduled for.\r\n-Task: The completion date. Tasks that are not marked as completed are not archived. Tasks that are assigned to other users are archived only if the status is completed. \r\n-Note: The last modified date and time.\r\n-Journal entry: The date when the journal entry is created.\r\n-Contact: Not archived.\r\n\r\nIf you disable or do not configure this policy setting, Outlook archives different items based on the item type, as follows:\r\n\r\n-Email message: The received date or the last modified date and time, whichever is later. \r\n-Calendar item: The last modified date and time or the actual date that an appointment, event, or meeting is scheduled for, whichever is later. \r\n-Task: The completion date or the last modified date and time, whichever is later. Tasks that are not marked as completed are not archived. Tasks that are assigned to other users are archived only if the status is completed. \r\n-Note: The last modified date and time.\r\n-Journal entry: The date when the journal entry is created or the last modified date and time, whichever is later.\r\n-Contact: Not archived.","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_archiveignorelastmodifiedtime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_archiveignorelastmodifiedtime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings","displayName":"AutoArchive Settings (User)","description":"If you enable this policy setting, the options specified in the AutoArchive dialog box are disabled.","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_archiveordeleteolditems","displayName":"Archive or delete old items (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_archiveordeleteolditems_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_archiveordeleteolditems_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_cleanoutitemsolderthan","displayName":"Clean out items older than (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_deleteexpireditemsemailfoldersonly","displayName":"Delete expired items (e-mail folders only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_deleteexpireditemsemailfoldersonly_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_deleteexpireditemsemailfoldersonly_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_empty19","displayName":"\r\nDuring AutoArchive:\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_empty19_0","displayName":"Months","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_empty19_1","displayName":"Weeks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_empty19_2","displayName":"Days","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_permanentlydeleteolditems","displayName":"Permanently delete old items (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_permanentlydeleteolditems_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_permanentlydeleteolditems_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_promptbeforeautoarchiveruns","displayName":"Prompt before AutoArchive runs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_promptbeforeautoarchiveruns_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_promptbeforeautoarchiveruns_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_runautoarchiveeveryxdays","displayName":"Run AutoArchive every days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_showarchivefolderinfolderlist","displayName":"Show archive folder in folder list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_showarchivefolderinfolderlist_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_showarchivefolderinfolderlist_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_turnonautoarchive","displayName":"Turn on AutoArchive (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_turnonautoarchive_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_turnonautoarchive_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_disablefilearchive","displayName":"Disable File|Archive (User)","description":"This setting allows you to disable File|Archive and prevent users from manually archiving items in their mailbox. You might want to set this if you have deployed other messaging records management policies in order to avoid conflicts. You should also consider disabling AutoArchive in the setting named AutoArchive Settings.","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_disablefilearchive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_disablefilearchive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice","displayName":"Polling Out-of-office Web service (User)","description":"By default, the Out Of Office (OOF) Web service is polled every 15 minutes (900000 milliseconds). This setting allows you to set the maximum number of milliseconds that elapse before Outlook polls the OOF Web service for OOF status.","helpText":"","infoUrls":[],"categoryId":"93a20c17-1e34-4778-8c95-91a46980ea75","categoryName":"Out of Office Assistant","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"93a20c17-1e34-4778-8c95-91a46980ea75","categoryName":"Out of Office Assistant","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_300000","displayName":"5 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_600000","displayName":"10 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_900000","displayName":"15 minutes (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_1200000","displayName":"20 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_1500000","displayName":"25 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_1800000","displayName":"30 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_2100000","displayName":"35 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_2400000","displayName":"40 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_2700000","displayName":"45 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_3000000","displayName":"50 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_3600000","displayName":"1 hour","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_7200000","displayName":"2 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_14400000","displayName":"4 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_28800000","displayName":"8 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_86400000","displayName":"24 hours","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_allowattendeestoproposenewtimesformeetingsyouorganize","displayName":"Allow attendees to propose new times for meetings you organize (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_allowattendeestoproposenewtimesformeetingsyouorganize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_allowattendeestoproposenewtimesformeetingsyouorganize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults","displayName":"Calendar item defaults (User)","description":"Sets the value in the option \"Default reminder\".","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults_l_showremindersxminutesbeforetheeventstarts","displayName":"Show reminders minutes before the event starts: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendarweeknumbers","displayName":"Calendar week numbers (User)","description":"By default, week numbers are not shown in the Date Navigator in the Calendar. You can change this behavior to show week numbers in the Date Navigator by enabling this setting.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendarweeknumbers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendarweeknumbers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing","displayName":"Control Calendar Sharing (User)","description":"By default, users can share an entire calendar by saving it in the iCalendar format, or share a snapshot of a calendar by using e-mail. This setting allows you to specify the detail level in the shared versions of calendars, or to disable sharing of calendars.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_l_controlcalendarsharing5","displayName":"Control Calendar Sharing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_l_controlcalendarsharing5_32768","displayName":"Prevent Calendar Sharing","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_l_controlcalendarsharing5_16384","displayName":"Allow calendar sharing with 'Availability Only' detail level","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_l_controlcalendarsharing5_8192","displayName":"Allow calendar sharing with 'Availability Only' and 'Limited Details' detail level","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disablemeetingregeneration","displayName":"Do not regenerate meetings (User)","description":"By default, when a user accepts or tentatively accepts a meeting, Outlook creates a duplicate copy of the meeting with the new response status and a new entry ID. Outlook then deletes the old version of the meeting from the calendar. This setting allows you to roll back to the legacy behavior and prevent meeting regeneration.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disablemeetingregeneration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disablemeetingregeneration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disableweather","displayName":"Disable Weather Bar (User)","description":"This policy setting allows you to turn on or turn off the Weather Bar.\r\n\r\nIf you enable this policy setting, the Weather Bar is turned off.\r\n\r\nIf you disable or do not configure this setting, the Weather Bar is turned on.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disableweather_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disableweather_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enableendearly","displayName":"End appointments and meetings early (User)","description":"\r\n This policy setting allows you to control whether the end time of appointments and meetings are reduced by a specified number of minutes when a user creates an appointment or meeting.\r\n\r\n If you enable this policy setting, the end time of appointments and meetings are reduced by a specified number of minutes when a user creates an appointment or meeting.\r\n\r\n To specify how many minutes to reduce appointments and meetings by, you can use the “Reduce the end time of short appointments and meetings by a specified number of minutes” and “Reduce the end time of long appointments and meetings by a specified number of minutes” policy settings.\r\n\r\n If you don’t enable those policy settings to specify a time in minutes, users will be able to specify a time, in minutes, by going to File > Options > Calendar. If the user hasn’t specified a time, default values of 5 minutes, for short meetings, and 10 minutes, for long meetings, will be used.\r\n\r\n If you disable this policy setting, appointments and meetings can’t be configured to end early and the option will be disabled under File > Options > Calendar and can’t be enabled by the user.\r\n\r\n If you don’t configure this policy setting, appointments and meetings aren’t configured to end early, but the user can enable appointments and meetings to end early by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enableendearly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enableendearly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enablemeetingdownleveltext","displayName":"Enable down-level meeting text (User)","description":"This policy setting controls whether Outlook automatically displays the meeting time and location in the meeting request body.\r\n\r\nIf you enable this policy setting, Outlook automatically displays the meeting time and location in the meeting request body.\r\n\r\nIf you disable or do not configure this policy setting, Outlook does not automatically display the meeting time and location in the meeting request body.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enablemeetingdownleveltext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enablemeetingdownleveltext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong","displayName":"Reduce the end time of long appointments and meetings by a specified number of minutes (User)","description":"\r\n This policy setting allows you to specify how many minutes to reduce the end time of a long appointment or meeting by when a user creates an appointment or meeting. A long appointment or meeting is one that lasts for one hour or longer.\r\n\r\n If you enable this policy setting, you specify the number of minutes to reduce the end time of a long appointment or meeting by when a user creates an appointment or meeting. The user won’t be able to change this value by going to File > Options > Calendar.\r\n\r\n Note: You should also enable the “End appointments and meetings early” policy setting\r\n\r\n If you disable or don’t configure this policy setting, the default value of 10 minutes is used or whatever the user specifies by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong_l_endearlylongspinid","displayName":"Minutes to reduce meetings by: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort","displayName":"Reduce the end time of short appointments and meetings by a specified number of minutes (User)","description":"\r\n This policy setting allows you to specify how many minutes to reduce the end time of a short appointment or meeting by when a user creates an appointment or meeting. A short appointment or meeting is one that lasts for less than one hour.\r\n\r\n If you enable this policy setting, you specify the number of minutes to reduce the end time of a short appointment or meeting by when a user creates an appointment or meeting. The user can’t change this value by going to File > Options > Calendar.\r\n\r\n Note: You should also enable the “End appointments and meetings early” policy setting.\r\n\r\n If you disable or don’t configure this policy setting, the default value of 5 minutes is used or whatever the user specifies by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort_l_endearlyshortspinid","displayName":"Minutes to reduce meetings by: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek","displayName":"First day of the week (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek","displayName":"Choose the first day of the week: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_0","displayName":"Sunday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_1","displayName":"Monday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_4","displayName":"Thursday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_5","displayName":"Friday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_6","displayName":"Saturday","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear","displayName":"First week of year (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_l_choosethefirstweekoftheyear","displayName":"Choose the first week of the year: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_l_choosethefirstweekoftheyear_0","displayName":"Starts on Jan. 1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_l_choosethefirstweekoftheyear_2","displayName":"First full week","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_l_choosethefirstweekoftheyear_1","displayName":"First four-day week","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_hideluckydayswhenusingrokuyoujapanesecalendar","displayName":"Hide lucky days when using Rokuyou (Japanese) calendar (User)","description":"Checked: Does not display lucky days when using a Japanese Rokuyou calendar. | Unchecked: Displays lucky days when using a Japanese Rokuyou calendar.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_hideluckydayswhenusingrokuyoujapanesecalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_hideluckydayswhenusingrokuyoujapanesecalendar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_hidesendlatestversionbutton","displayName":"Hide Send Latest Version button (User)","description":"This policy setting hides the \"Send Latest Version\" button and prevents it from appearing on out-of-date meeting forward notifications and responses.\r\n\r\nIf you enable this policy setting, the \"Send Latest Version\" button be hidden on out-of-date meeting forward notifications and responses. \r\n\r\nIf you disable or do not configure this policy setting, the \"Send Latest Version\" button will be turned on.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_hidesendlatestversionbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_hidesendlatestversionbutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_includeappointmentsonlywithinworkinghours","displayName":"Include appointments only within working hours (User)","description":"By default, all appointments in a calendar are included when that calendar is shared through e-mail or by using the Office.com Sharing Service. This setting allows users to publish only appointments that are within users' working hours.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_includeappointmentsonlywithinworkinghours_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_includeappointmentsonlywithinworkinghours_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_meetingrequestsusingicalendar","displayName":"Send Internet meeting requests using iCalendar format (User)","description":"This policy setting determines whether users' meeting requests sent outside of your organization use the iCalendar format.\r\n\r\nIf you enable or do not configure this policy setting, meeting requests sent outside of your organization use the ICAL format.\r\n\r\nIf you disable this policy setting, meeting requests sent outside your organization use the TNEF format.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_meetingrequestsusingicalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_meetingrequestsusingicalendar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_remindersoncalendaritems","displayName":"Do not display reminders on Calendar items by default (User)","description":"By default, when users create Calendar items, the Reminder: check box in the item is set. By disabling this setting, you can change the default behavior so that the Reminder: check box is cleared by default .","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_remindersoncalendaritems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_remindersoncalendaritems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_restupdatesforcalendar","displayName":"REST updates for calendars (User)","description":"This policy determines if Outlook can use REST to update calendars.\r\n\r\n If you enable this policy, Outlook will use REST to update supported Office 365 and Outlook.com calendars.\r\n\r\n If you disable this policy, Outlook won't use REST to update any calendars.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_restupdatesforcalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_restupdatesforcalendar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes","displayName":"Use this response when you propose new meeting times (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_l_usethisresponsewhenyouproposenewmeetingtimes6","displayName":"Use this response when you propose new meeting times (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_l_usethisresponsewhenyouproposenewmeetingtimes6_2","displayName":"Tentative","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_l_usethisresponsewhenyouproposenewmeetingtimes6_3","displayName":"Accept","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_l_usethisresponsewhenyouproposenewmeetingtimes6_4","displayName":"Decline","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherserviceurl","displayName":"Weather Service URL (User)","description":"This policy setting allows you to configure the weather service URL for Outlook.\r\n\r\nIf you enable this policy setting, you must enter your desired weather service URL.\r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default weather service URL.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherserviceurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherserviceurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherserviceurl_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency","displayName":"Weather Bar Update Frequency (User)","description":"This policy setting allows you to set the update frequency (in minutes) for the Weather Bar. \r\n\r\nIf you enable this policy setting, Outlook sets the update frequency to the specified value. \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default value of 120 minutes.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency_l_weatherupdatefrequencyintervalspinid","displayName":"Update frequency (in minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours","displayName":"Working hours (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime","displayName":"End Time: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1020","displayName":"5:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_0","displayName":"12:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_30","displayName":"12:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_60","displayName":"1:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_90","displayName":"1:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_120","displayName":"2:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_150","displayName":"2:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_180","displayName":"3:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_210","displayName":"3:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_240","displayName":"4:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_270","displayName":"4:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_300","displayName":"5:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_330","displayName":"5:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_360","displayName":"6:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_390","displayName":"6:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_420","displayName":"7:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_450","displayName":"7:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_480","displayName":"8:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_510","displayName":"8:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_540","displayName":"9:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_570","displayName":"9:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_600","displayName":"10:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_630","displayName":"10:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_660","displayName":"11:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_690","displayName":"11:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_720","displayName":"12:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_750","displayName":"12:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_780","displayName":"1:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_810","displayName":"1:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_840","displayName":"2:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_870","displayName":"2:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_900","displayName":"3:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_930","displayName":"3:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_960","displayName":"4:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_990","displayName":"4:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1050","displayName":"5:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1080","displayName":"6:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1110","displayName":"6:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1140","displayName":"7:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1170","displayName":"7:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1200","displayName":"8:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1230","displayName":"8:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1260","displayName":"9:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1290","displayName":"9:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1320","displayName":"10:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1350","displayName":"10:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1380","displayName":"11:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1410","displayName":"11:30 PM","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime","displayName":"Start time: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_480","displayName":"8:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_0","displayName":"12:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_30","displayName":"12:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_60","displayName":"1:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_90","displayName":"1:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_120","displayName":"2:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_150","displayName":"2:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_180","displayName":"3:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_210","displayName":"3:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_240","displayName":"4:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_270","displayName":"4:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_300","displayName":"5:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_330","displayName":"5:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_360","displayName":"6:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_390","displayName":"6:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_420","displayName":"7:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_450","displayName":"7:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_510","displayName":"8:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_540","displayName":"9:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_570","displayName":"9:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_600","displayName":"10:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_630","displayName":"10:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_660","displayName":"11:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_690","displayName":"11:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_720","displayName":"12:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_750","displayName":"12:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_780","displayName":"1:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_810","displayName":"1:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_840","displayName":"2:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_870","displayName":"2:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_900","displayName":"3:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_930","displayName":"3:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_960","displayName":"4:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_990","displayName":"4:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1020","displayName":"5:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1050","displayName":"5:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1080","displayName":"6:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1110","displayName":"6:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1140","displayName":"7:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1170","displayName":"7:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1200","displayName":"8:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1230","displayName":"8:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1260","displayName":"9:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1290","displayName":"9:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1320","displayName":"10:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1350","displayName":"10:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1380","displayName":"11:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1410","displayName":"11:30 PM","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek","displayName":"Work week (User)","description":"Sets the value in the option \"Calendar work week\".","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek","displayName":"Length of work week: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_124","displayName":"Monday to Friday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_120","displayName":"Monday to Thursday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_60","displayName":"Tuesday to Friday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_126","displayName":"Monday to Saturday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_30","displayName":"Wednesday to Saturday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_142","displayName":"Thursday to Sunday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_252","displayName":"Sunday to Friday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_254","displayName":"All seven days","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions","displayName":"Internet Free/Busy Options (User)","description":"Checks/Unchecks the option \"Publish at my location\".","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_l_publishatthisurl","displayName":"Publish at this URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_l_publishfreebusyinformation","displayName":"Publish free/busy information (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_l_publishfreebusyinformation_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_l_publishfreebusyinformation_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_l_searchatthisurl","displayName":"Search at this URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9","displayName":"Options (User)","description":"Sets the value in the option \"Publish [] month(s) of Calendar free/busy information on the server\".","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_freebusyupdatedontheservereveryxxxseconds","displayName":"Free/Busy updated on the server every xxx seconds: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_monthsoffreebusyinformationpublished","displayName":"Months of Free/Busy information published: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_preventusersfromchangingmonthsoffreebusyinformation1","displayName":"Prevent users from changing Months of Free/Busy information being published (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_preventusersfromchangingmonthsoffreebusyinformation1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_preventusersfromchangingmonthsoffreebusyinformation1_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_accesstopublishedcalendars","displayName":"Access to published calendars (User)","description":"This policy setting determines what restrictions apply to users who publish their calendars on Office.com or third-party World Wide Web Distributed Authoring and Versioning (WebDAV) servers. \r\n\r\nIf you enable or disable this policy setting, calendars that are published on Office.com must have restricted access (users other than the calendar owner/publisher who wish to view the calendar can only do so if they receive invitations from the calendar owner), and users cannot publish their calendars to third-party DAV servers. \r\n\r\nIf you do not configure this policy setting, users can share their calendars with others by publishing them to the Office.com Calendar Sharing Services and to a server that supports the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol. Office.com allows users to choose whether to restrict access to their calendars to people they invite, or allow unrestricted access to anyone who knows the URL to reach the calendar. DAV access restrictions can only be achieved through server and folder permissions, and might require the assistance of a server administrator to set up and maintain.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_accesstopublishedcalendars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_accesstopublishedcalendars_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver","displayName":"Path to DAV server (User)","description":"This setting allows you to define the path to a DAV server that should be used when users publish their calendars via DAV.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_preventpublishingtoadavserver","displayName":"Prevent publishing to a DAV server (User)","description":"This policy setting controls whether Outlook users can publish their calendars to a DAV server. \r\n\r\nIf you enable this policy setting, Outlook users cannot publish their calendars to a DAV server. \r\n\r\nIf you disable or do not configure this policy setting, Outlook users can share their calendars with others by publishing them to a server that supports the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_preventpublishingtoadavserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_preventpublishingtoadavserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_preventpublishingtoofficeonline","displayName":"Prevent publishing to Office.com (User)","description":"This policy setting controls whether Outlook users can publish their calendars to the Office.com Calendar Sharing Service. \r\n\r\nIf you enable this policy setting, Outlook users cannot publish their calendars to Office.com. \r\n\r\nIf you disable do not configure this policy setting, Outlook users can share their calendars with selected others by publishing them to the Microsoft Outlook Calendar Sharing Service. Users can control who can view their calendar and at what level of detail.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_preventpublishingtoofficeonline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_preventpublishingtoofficeonline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_publishinterval","displayName":"Publish interval (User)","description":"By default, Outlook does not publish calendars to Office.com more often then the publish interval set by Office.com. This setting allows users to publish calendars more often than the Office.com interval specifies.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_publishinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_publishinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails","displayName":"Restrict level of calendar details users can publish (User)","description":"This policy setting controls the level of calendar details that Outlook users can publish to the Microsoft Outlook Calendar Sharing Service. \r\n\r\nIf you enable this policy setting, you can choose from three levels of detail: \r\n\r\n* All options are available - This level of detail is the default configuration. \r\n* Disables 'Full details' \r\n* Disables 'Full details' and 'Limited details' \r\n\r\nIf you disable or do not configure this policy setting, Outlook users can share their calendars with selected others by publishing them to the Microsoft Outlook Calendar Sharing Service. Users can choose from three levels of detail: \r\n\r\n* Availability only - Authorized visitors will see the user's time marked as Free, Busy, Tentative, or Out of Office, but will not be able to see the subjects or details of calendar items. \r\n* Limited details - Authorized visitors can see the user's availability and the subjects of calendar items only. They will not be able to view the details of calendar items. Optionally, users can allow visitors to see the existence of private items. \r\n* Full details - Authorized visitors can see the full details of calendar items. Optionally, users can allow visitors to see the existence of private items.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails_l_empty4","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails_l_empty4_0","displayName":"All options are available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails_l_empty4_8192","displayName":"Disables 'Full details'","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails_l_empty4_16384","displayName":"Disables 'Full details' and 'Limited details'","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictuploadmethod","displayName":"Restrict upload method (User)","description":"This policy setting controls whether Outlook can automatically upload calendar updates to Office.com. \r\n\r\nIf you enable this policy setting, Outlook enforces the \"Single Upload: Updates will not be uploaded from the Published Calendar Settings dialog\" option, and calendar updates are not uploaded. Users will not be able to change this setting.\r\n\r\nIf you disable this policy setting Outlook automatically publishes calendar updates to Office.com at regular intervals and users will not be able to change this. \r\n\r\nIf you do not configure this policy setting, when users publish their calendar to Office.com using the Microsoft Outlook Calendar Sharing Service, Outlook updates the calendars online at regular intervals unless they click \"Advanced\" and select \"Single Upload: Updates will not be uploaded from the Published Calendar Settings dialog\".","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictuploadmethod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictuploadmethod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner","displayName":"Meeting Planner (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"2592e8ea-5eb0-482b-b41e-eab92f33ac07","categoryName":"Planner Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_l_showcalendardetailsinthegrid","displayName":"Show calendar details in the grid (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2592e8ea-5eb0-482b-b41e-eab92f33ac07","categoryName":"Planner Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_l_showcalendardetailsinthegrid_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_l_showcalendardetailsinthegrid_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_l_showpopupcalendardetails","displayName":"Show popup calendar details (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2592e8ea-5eb0-482b-b41e-eab92f33ac07","categoryName":"Planner Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_l_showpopupcalendardetails_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_l_showpopupcalendardetails_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_defaultrecurrenceduration","displayName":"Specify total number of days in a recurring meeting or appointment (User)","description":"This policy setting allows you to specify the default number of days after which a recurring meeting or appointment (but not a task) ends.\r\n\r\nIf you enable this policy setting, the “End by” setting is the default setting for recurring meetings and appointments, and the “End by” value is set to the specified number of days after today’s date. For example, if you specify a value of 180 and today's date is May 5, 2011, the “End by” value is November 1, 2011 (180 days after today’s date).\r\n\r\nIf you disable or do not configure this policy setting, the “No end date” option is the default setting for recurring meetings and appointments.","helpText":"","infoUrls":[],"categoryId":"826db7fb-889b-4a99-80a6-38347ba37f21","categoryName":"Recurring item configuration","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_defaultrecurrenceduration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_defaultrecurrenceduration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_defaultrecurrenceduration_l_defaultrecurrencedurationspinid","displayName":"End recurrence after x days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"826db7fb-889b-4a99-80a6-38347ba37f21","categoryName":"Recurring item configuration","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_disablenoenddate","displayName":"Disable the \"No end date\" option for recurring items (User)","description":"This policy setting allows you to disable the \"No end date\" option for the recurrence range in appointments, meetings, and tasks.\r\n\r\nIf you enable this policy setting, the “No end date” option is disabled, and the “End after” recurrence setting is selected and set to “10 occurrences” by default. You can change this default setting by configuring the “Specify total number of days in a recurring meeting or appointment” policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the “No end date” option is enabled and is the default setting for recurring meetings, appointments, and tasks.","helpText":"","infoUrls":[],"categoryId":"826db7fb-889b-4a99-80a6-38347ba37f21","categoryName":"Recurring item configuration","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_disablenoenddate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_disablenoenddate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_donotallowhorizontalcalendarview","displayName":"Do not allow horizontal calendar view (User)","description":"This policy setting allows you to prevent horizontal calendar view.\r\n\r\nIf you enable this policy setting, horizontal calendar view is not allowed.\r\n\r\nIf you disable or do not configure this policy setting, horizontal calendar view is allowed.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_donotallowhorizontalcalendarview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_donotallowhorizontalcalendarview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventmydepartmentcalendarfromappearing","displayName":"Prevent My Department Calendar from appearing (User)","description":"This policy setting prevents My Department Calendar from appearing in the navigation pane.\r\n\r\nIf you enable this policy setting, My Department Calendar will not appear in the navigation pane.\r\n\r\nIf you disable or do not configure this policy setting, My Department Calendar will appear in the navigation pane.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventmydepartmentcalendarfromappearing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventmydepartmentcalendarfromappearing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventotherdepartmentcalendarfromappearing","displayName":"Prevent Other Department Calendar from appearing (User)","description":"This policy setting prevents Other Department Calendar from appearing in the navigation pane.\r\n\r\nIf you enable this policy setting, Other Department Calendar will not appear in the navigation pane.\r\n\r\nIf you disable or do not configure this policy setting, Other Department Calendar will appear in the navigation pane.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventotherdepartmentcalendarfromappearing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventotherdepartmentcalendarfromappearing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventreportinglinegroupcalendarfromappearing","displayName":"Prevent Reporting Line Group Calendar from appearing (User)","description":"This policy setting prevents Reporting Line Group Calendar from appearing in the navigation pane.\r\n\r\nIf you enable this policy setting, Reporting Line Group Calendar will not appear in the navigation pane.\r\n\r\nIf you disable or do not configure this policy setting, My Reporting Line Group Calendar will appear in the navigation pane.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventreportinglinegroupcalendarfromappearing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventreportinglinegroupcalendarfromappearing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffautoswitchingfromhorizontaltovertical","displayName":"Turn off auto-switching from horizontal to vertical layout (User)","description":"This policy setting controls auto switching of calendar layouts from horizontal to vertical. \r\n\r\nIf you enable this policy setting, auto-switching is turned off.\r\n\r\nIf you disable or do not configure this policy setting, auto-switching is turned on.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffautoswitchingfromhorizontaltovertical_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffautoswitchingfromhorizontaltovertical_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffautoswitchingfromverticaltohorizontallayout","displayName":"Turn off auto-switching from vertical to horizontal layout (User)","description":"This policy setting controls auto-switching of calendar layouts from vertical to horizontal.\r\n\r\nIf you enable this policy setting, auto-switching is turned off.\r\n\r\nIf you disable or do not configure this policy setting, auto-switching is turned on.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffautoswitchingfromverticaltohorizontallayout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffautoswitchingfromverticaltohorizontallayout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnofflegacygroupcalendarmigration","displayName":"Turn off Legacy Group Calendar migration (User)","description":"This policy setting controls the migration of legacy Group Calendar. \r\n\r\nIf you enable this policy setting, migration will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, migration will be turned on.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnofflegacygroupcalendarmigration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnofflegacygroupcalendarmigration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffsharingrecommendation","displayName":"Turn off sharing recommendation (User)","description":"This policy setting controls the sharing recommendation feature. \r\n\r\nIf you enable this policy setting, the recommendation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, the recommendation will be turned on.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffsharingrecommendation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffsharingrecommendation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_determineorderofsourcesforphotos","displayName":"Determine order of sources for photos (User)","description":"This policy setting controls the order of sources for photos displayed in Outlook. \r\n\r\nIf you enable this policy setting, Outlook will first look at the OAB/AD for the user photo. If this is not available, Outlook will show a Contact photo if the Contact photo is available.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will first look into the Contact Address Books for the user photo. If this is not available, Outlook will look to the OAB/AD if available.","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_determineorderofsourcesforphotos_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_determineorderofsourcesforphotos_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts","displayName":"Select the default setting for how to file new contacts (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex","displayName":"Additional Contacts Index: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_2","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_7","displayName":"Cyrillic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_15","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_16","displayName":"Hebrew","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_28","displayName":"Thai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_30","displayName":"Vietnamese","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_checkforduplicatecontacts","displayName":"Check for duplicate contacts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_checkforduplicatecontacts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_checkforduplicatecontacts_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfileasorder","displayName":"Default File As order: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfileasorder_32791","displayName":"Last First","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfileasorder_32823","displayName":"First Last","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfileasorder_14870","displayName":"Company","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfileasorder_32793","displayName":"Last, First (Company)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfileasorder_32792","displayName":"Company (Last, First)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfullnameorder","displayName":"Default Full Name order: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfullnameorder_e","displayName":"First (Middle) Last","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfullnameorder_h","displayName":"Last First","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfullnameorder_s","displayName":"First Last1 Last2","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_showanadditionalcontactsindex","displayName":"Show an additional Contacts Index (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_showanadditionalcontactsindex_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_showanadditionalcontactsindex_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_showcontactslinkingcontrolsonallforms","displayName":"Show Contacts linking controls on all Forms (User)","description":"By default, Tasks, Appointments, Journal Entries, and Contacts hide the controls in the Outlook user interface used for linking related contacts. When you enable this setting, the linking controls appear in Outlook. You might choose to enable this setting if your users rely on contact linking - for example, to track partners who attend appointments together or to track ways in which contacts are related to each other.","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_showcontactslinkingcontrolsonallforms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_showcontactslinkingcontrolsonallforms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior","displayName":"Change CTRL+ENTER shortcut behavior (User)","description":"This policy setting controls whether CTRL+ENTER can be used as a shortcut to send an email message. You can change this behavior so that CTRL+ENTER does not send an email message.\r\n\r\nIf you enable this policy setting, you may select one of these choices:\r\n- CTRL+Enter is not a shortcut for sending a message\r\n- CTRL+Enter is a shortcut for sending a message\r\n- CTRL+Enter displays a prompt\r\n\r\nIf you disable or do not configure this policy setting, users can use CTRL+ENTER to send an e-mail message. By default, users are prompted the first time they use the shortcut to confirm sending the message.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior_l_changectrlentershortcutbehaviorid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior_l_changectrlentershortcutbehaviorid_0","displayName":"CTRL+Enter is not a shortcut for sending a message","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior_l_changectrlentershortcutbehaviorid_1","displayName":"CTRL+Enter is a shortcut for sending a message","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior_l_changectrlentershortcutbehaviorid_2","displayName":"CTRL+Enter displays a prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_checkforgottenattachments","displayName":"Attachment Reminder Options (User)","description":"This policy setting governs the enabling or disabling of the Attachment Reminder feature in Outlook.\r\n\r\nIf you enable or do not configure this policy setting, when a user sends an email, Outlook looks for any references to attachments in the email, and if no attachments are found, displays a dialog box to alert the user.\r\n\r\nIf you disable this policy setting, Outlook does not check for any references to attachments, and the Attachment Reminder dialog box does not pop up.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_checkforgottenattachments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_checkforgottenattachments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview","displayName":"Configure Cross Folder Content in conversation view (User)","description":"This policy setting controls how conversation view in Outlook is loaded and whether Cross Folder Content is turned on or off.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n- On and cross-store (default): Cross Folder Content is on and cross-store. Data will be pulled from all connected data files whether they are cached or online. \r\n- Off: Cross Folder Content is turned off.\r\n- On and current: Cross Folder Content is on, but data is only pulled from the current data file. \r\n- On and local: Cross Folder Content is on, but data is only pulled from the current data file and any other local data files.\r\n\r\nIf you disable or do not configure this policy setting, Cross Folder Content will be turned on and pulled from all connected data files.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_l_configurecrossfoldercontentinconversationviewdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_l_configurecrossfoldercontentinconversationviewdropid_0","displayName":"On and cross-store (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_l_configurecrossfoldercontentinconversationviewdropid_1","displayName":"Off","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_l_configurecrossfoldercontentinconversationviewdropid_2","displayName":"On and current","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_l_configurecrossfoldercontentinconversationviewdropid_3","displayName":"On and local","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_disableattachmentpreviewing","displayName":"Do not allow attachment previewing in Outlook (User)","description":"This policy setting controls whether Outlook users can preview attachments in e-mail messages. \r\n\r\nIf you enable this policy setting, users cannot preview attachments within Outlook. Users must instead use the appropriate application to view attachments, depending on security settings. This configuration can be used to guard against theoretical future zero-day attacks that target specific file types. \r\n\r\nIf you disable or do not configure this policy setting, Outlook users can preview certain types of e-mail attachments within the message window or Reading Pane by clicking the icon that represents the attachment. Users can preview Outlook items, Word documents, PowerPoint presentations, Excel worksheets, Microsoft Visio® drawings, image files, and text files. To help protect users from malicious code, active content embedded in attachments (including scripts, macros, and ActiveX controls) is disabled during a preview.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_disableattachmentpreviewing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_disableattachmentpreviewing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_disablemailtips","displayName":"Disable Mail Tips (User)","description":"This policy setting determines whether users can view Mail Tips.\r\n\t \r\nIf you enable this policy setting, Mail Tips do not appear in Outlook.\r\n\t\t\t\t\t\r\nIf you disable or do not configure this policy, Mail Tips appear in Outlook.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_disablemailtips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_disablemailtips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_displaysenderpicture","displayName":"Display Sender Picture (User)","description":"This policy setting controls whether Outlook displays pictures in email headers for senders of email messages and meeting requests. \r\n\t \r\nIf you enable or do not configure this policy setting Outlook displays pictures for senders if they are available. \r\n\r\nIf you disable this policy setting, pictures of senders will not be displayed.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_displaysenderpicture_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_displaysenderpicture_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_donotuseconversationalarrangementinviews","displayName":"Do not use Conversation arrangement in Views (User)","description":"This policy setting allows you to prevent the use of Conversation arrangement in Views.\r\n\r\nIf you enable this policy setting, you will prevent Conversational arrangement in Views.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to use Conversation arrangement in Views.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_donotuseconversationalarrangementinviews_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_donotuseconversationalarrangementinviews_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling","displayName":"Message handling (User)","description":"You can use this setting to specify various options for how e-mail messages are handled.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_aftermovingordeletinganopenitem0","displayName":"After moving or deleting an open item: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_aftermovingordeletinganopenitem0_0","displayName":"Open the next item","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_aftermovingordeletinganopenitem0_1","displayName":"Return to the current folder","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_aftermovingordeletinganopenitem0_2","displayName":"Open the previous item","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_automaticallycleanupplaintextmessages","displayName":"Automatically clean up plain text messages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_automaticallycleanupplaintextmessages_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_automaticallycleanupplaintextmessages_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_autosaveunsenteveryxxminutes0noautosave","displayName":"Autosave unsent every xx minutes (0=No AutoSave): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_closeoriginalmessagewhenreplyorforward","displayName":"Close original message when reply or forward (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_closeoriginalmessagewhenreplyorforward_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_closeoriginalmessagewhenreplyorforward_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_savecopiesofmessagesinsentitemsfolder","displayName":"Save copies of messages in Sent Items folder (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_savecopiesofmessagesinsentitemsfolder_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_savecopiesofmessagesinsentitemsfolder_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards","displayName":"On replies and forwards (User)","description":"Sets the values in the corresponding UI options.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_allowuserscommentstobemarked","displayName":"Allow user's comments to be marked (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_allowuserscommentstobemarked_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_allowuserscommentstobemarked_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_prefixeachlinewith","displayName":"Prefix each line with: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenforwardingamessage","displayName":"When forwarding a message: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenforwardingamessage_1","displayName":"Attach orginal message","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenforwardingamessage_2","displayName":"Include original message text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenforwardingamessage_3","displayName":"Include and indent org. message text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenforwardingamessage_1000","displayName":"Prefix each line of the org. message","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenreplyingtoamessage","displayName":"When replying to a message: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenreplyingtoamessage_0","displayName":"Do not include orginal message","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenreplyingtoamessage_1","displayName":"Attach orginal message","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenreplyingtoamessage_2","displayName":"Include original message text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenreplyingtoamessage_3","displayName":"Include and indent org. message text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenreplyingtoamessage_1000","displayName":"Prefix each line of the org. message","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_reademailasplaintext","displayName":"Read e-mail as plain text (User)","description":"This policy setting determines whether Outlook renders all e-mail messages in plain text format for reading.Outlook can display e-mail messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. \r\n\r\nIf you enable this policy setting, the \"Read all standard mail in plain text\" check box option is selected in the \"E-mail Security\" section of the Trust Center and users cannot change it. This option only changes the way e-mail messages are displayed; the original message is not converted to plain text format. \r\n\r\nIf you disable or do not configure this policy setting, Outlook displays e-mail messages in whatever format they were received in.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_reademailasplaintext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_reademailasplaintext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_readsignedemailasplaintext","displayName":"Read signed e-mail as plain text (User)","description":"This policy setting determines whether Outlook renders all digitally signed e-mail in plain text format for reading. Outlook can display e-mail messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. \r\n\r\nIf you enable this policy setting, the \"Read all standard mail in plain text\" check box option is selected in the \"E-mail Security\" section of the Trust Center and users cannot change it. This option only changes the way e-mail messages are displayed; the original message is not converted to plain text format. \r\n\r\nIf you disable or do not configure this policy setting, Outlook displays digitally signed e-mail messages in the format they were received in.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_readsignedemailasplaintext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_readsignedemailasplaintext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_disableautopreview","displayName":"Disable AutoPreview (User)","description":"Enabling this policy permanently disables the item preview. Users cannot turn it back on and the ribbon UI to change it is disabled.","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_disableautopreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_disableautopreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages","displayName":"More save messages (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_l_infoldersotherthantheinboxsavereplieswithoriginalmessage","displayName":"In folders other than the Inbox, save replies with original message (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_l_infoldersotherthantheinboxsavereplieswithoriginalmessage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_l_infoldersotherthantheinboxsavereplieswithoriginalmessage_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_l_saveforwardedmessages","displayName":"Save forwarded messages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_l_saveforwardedmessages_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_l_saveforwardedmessages_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages","displayName":"Save Messages (User)","description":"Specifies the folder in which unsent messages are saved.","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_l_saveunsentitemsinthisfolder","displayName":"Save unsent items in this folder: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_l_saveunsentitemsinthisfolder_4","displayName":"Outbox","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_l_saveunsentitemsinthisfolder_5","displayName":"Sent Items","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_l_saveunsentitemsinthisfolder_6","displayName":"Inbox","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_l_saveunsentitemsinthisfolder_16","displayName":"Drafts","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive","displayName":"When new items arrive (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_brieflychangethemousecursor","displayName":"Briefly change the mouse cursor (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_brieflychangethemousecursor_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_brieflychangethemousecursor_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_playasound","displayName":"Play a sound (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_playasound_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_playasound_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_showanenvelopeiconinthesystemtray","displayName":"Show an envelope icon in the system tray (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_showanenvelopeiconinthesystemtray_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_showanenvelopeiconinthesystemtray_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage","displayName":"When sending a message (User)","description":"Sets the values in the corresponding UI options.","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_addpropertiestoattachmentstoenablereplywithchanges","displayName":"Add properties to attachments to enable Reply with Changes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_addpropertiestoattachmentstoenablereplywithchanges_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_addpropertiestoattachmentstoenablereplywithchanges_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_allowcommasasaddressseparator","displayName":"Allow commas as address separator (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_allowcommasasaddressseparator_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_allowcommasasaddressseparator_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_automaticnamechecking","displayName":"Automatic name checking (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_automaticnamechecking_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_automaticnamechecking_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_deletemeetingrequestfrominboxwhenresponding","displayName":"Delete meeting request from Inbox when responding (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_deletemeetingrequestfrominboxwhenresponding_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_deletemeetingrequestfrominboxwhenresponding_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_messagesexpireafterdays","displayName":"Messages expire after (days): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setimportance","displayName":"Set importance: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setimportance_2","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setimportance_1","displayName":"Normal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setimportance_0","displayName":"Low","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setsensitivity","displayName":"Set sensitivity: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setsensitivity_0","displayName":"Normal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setsensitivity_1","displayName":"Personal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setsensitivity_2","displayName":"Private","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setsensitivity_3","displayName":"Confidential","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_suggestnameswhilecompletingtoccandbccfields","displayName":"Suggest names while completing To, Cc, and Bcc fields (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_suggestnameswhilecompletingtoccandbccfields_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_suggestnameswhilecompletingtoccandbccfields_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_newmaildesktopalert","displayName":"Do not display New Mail alert for users (User)","description":"By default, users receive an alert message on their desktops when new mail arrives. By enabling this setting, the alert is not displayed for new mail.","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_newmaildesktopalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_newmaildesktopalert_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert","displayName":"Specify default location of Desktop Alert (User)","description":"You can change the default location of the Desktop Alert. In the Corner field, select a number corresponding to a quadrant of the user's screen: 0 = upper left, 1 = upper right, 2 = lower left, 3 = lower right (the default). In the XOffset field, enter a number representing the horizontal distance from the corner you've specified (the default is 44). In the YOffset field, enter a number representing the vertical distance from the corner you've specified (the default is 42).","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_l_corner03","displayName":"Corner (0-3) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_l_xoffsetdefault44","displayName":"XOffset (default 44): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_l_yoffsetdefault42","displayName":"YOffset (default 42): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertbeforefadeinmillisec","displayName":"Specify duration of Desktop Alert before fade (in milliseconds) (User)","description":"Specify duration of Desktop Alert before fade (in milliseconds)","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertbeforefadeinmillisec_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertbeforefadeinmillisec_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertbeforefadeinmillisec_l_millisecdefault4000","displayName":"Millisec (Default 4000): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec","displayName":"Specify duration of Desktop Alert on mouse over (in milliseconds) (User)","description":"Specify duration of Desktop Alert on mouse over (in milliseconds)","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec_l_millisec1","displayName":"Millisec: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeininmillisec","displayName":"Specify duration of fade in (in milliseconds) (User)","description":"Specify duration of fade in (in milliseconds)","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeininmillisec_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeininmillisec_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeininmillisec_l_millisec","displayName":"Millisec: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeoutinmillisec","displayName":"Specify duration of fade out (in milliseconds) (User)","description":"Specify duration of fade out (in milliseconds)","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeoutinmillisec_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeoutinmillisec_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeoutinmillisec_l_millisec2","displayName":"Millisec: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityatstartoffadein","displayName":"Specify opacity at start of fade in (User)","description":"Specify opacity at start of fade in","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityatstartoffadein_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityatstartoffadein_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityatstartoffadein_l_specifyopacityatstartoffadein3","displayName":"Specify opacity at start of fade in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityofdesktopalert","displayName":"Specify opacity of Desktop Alert (User)","description":"Specify opacity of Desktop Alert","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityofdesktopalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityofdesktopalert_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityofdesktopalert_l_opacityalphalevel","displayName":"Opacity (Alpha Level): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options","displayName":"Options (User)","description":"You can use these settings to specify how tracking options work for Outlook e-mail messages.","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_deleteblankvotingandmeetingresponsesafterprocessing","displayName":"Delete blank voting and meeting responses after processing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_deleteblankvotingandmeetingresponsesafterprocessing_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_deleteblankvotingandmeetingresponsesafterprocessing_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processreceiptsonarrival","displayName":"Process receipts on arrival (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processreceiptsonarrival_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processreceiptsonarrival_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processrequestsandresponsesonarrival","displayName":"Process requests and responses on arrival (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processrequestsandresponsesonarrival_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processrequestsandresponsesonarrival_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestareadreceiptforallmessagesausersends","displayName":"Request a read receipt for all messages a user sends (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestareadreceiptforallmessagesausersends_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestareadreceiptforallmessagesausersends_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestdeliveryrcptforallmsgsausersendsexchangeonly","displayName":"Request delivery rcpt for all msgs a user sends (Exchange only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestdeliveryrcptforallmsgsausersendsexchangeonly_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestdeliveryrcptforallmsgsausersendsexchangeonly_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_whenoutlookisaskedtorespondtoareadreceiptrequest","displayName":"When Outlook is asked to respond to a read receipt request: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_whenoutlookisaskedtorespondtoareadreceiptrequest_0","displayName":"Always send a response","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_whenoutlookisaskedtorespondtoareadreceiptrequest_1","displayName":"Never send a response","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_whenoutlookisaskedtorespondtoareadreceiptrequest_2","displayName":"Ask before sending a response","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_turnoffsendandtrack","displayName":"Turn off Send and Track feature (User)","description":"By default, users can flag an e-mail that they send to help them remember to follow up on it later. The flag is not sent to the recipient. By enabling this setting, this feature is turned off.","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_turnoffsendandtrack_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_turnoffsendandtrack_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_addpeopleiemailtothesafesenderslist","displayName":"Add e-mail recipients to users' Safe Senders Lists (User)","description":"This policy setting controls whether recipients' e-mail addresses are automatically added to the user's Safe Senders List in Microsoft Outlook. Sometimes users will send e-mail messages to request that they be taken off a mailing list. If the e-mail recipient is then automatically added to the Safe Senders List, future e-mail messages from that address will no longer be sent to the users Junk E-mail folder, even if it would otherwise be considered junk. \r\n\r\nIf you enable this policy setting, all recipients of outgoing messages are automatically added to users' Safe Senders Lists. If users respond to junk e-mail senders while this policy setting is Enabled, all future junk e-mail from the same address will be considered safe. \r\n\r\nIf you disable this policy setting, recipients of outgoing messages are not automatically added to the Safe Senders List. Users must explicitly add addresses to the list. \r\n\r\nIf you do not configure this policy setting, recipients of outgoing messages are not added automatically to individual users' Safe Senders Lists. However, users can change this configuration in the Outlook user interface.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_addpeopleiemailtothesafesenderslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_addpeopleiemailtothesafesenderslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_hidejunkmailui","displayName":"Hide Junk Mail UI (User)","description":"This policy setting controls whether the Junk E-mail Filter is enabled in Outlook. The Junk E-mail Filter in Outlook is designed to intercept the most obvious junk e-mail, or spam, and send it to users' Junk E-mail folders. The filter evaluates each incoming message based on several factors, including the time when the message was sent and the content of the message. The filter does not single out any particular sender or message type, but instead analyzes each message based on its content and structure to discover whether or not it is probably spam.\r\n \r\nIf you enable this policy setting, junk e-mail filtering in Outlook is turned off entirely, in addition to hiding the filtering controls from users. In addition, you can use the \"Junk E-mail Protection level\" policy setting to preset a filtering level and prevent users from changing it. Note - This policy setting does not affect the configuration of the Microsoft Exchange Server Intelligent Message Filter (IMF), which provides server-level junk e-mail filtering. \r\n\r\nIf you disable or do not configure this policy setting, the Junk E-mail Filter in Outlook is enabled.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_hidejunkmailui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_hidejunkmailui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkmailimportlist","displayName":"Trigger to apply junk email list settings (User)","description":"This policy setting allows you to trigger the activation of other junk e-mail policy settings.\r\n\r\nIf you enable this policy setting, you will trigger the activation of other junk e-mail policy settings. For example, if you configure the \"Specify path to Safe Senders list\" policy setting, the specified Safe Senders list is not imported by Outlook unless you also enable the \"Junk Mail Import List\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, you will not trigger the activation of other junk e-mail policies.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkmailimportlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkmailimportlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_overwriteorappendjunkmailimportlist","displayName":"Overwrite or Append Junk Mail Import List (User)","description":"By default, when a new Junk E-mail Filter list is deployed, Outlook appends the new Junk Mail Import List to the existing list. Enable this setting to replace the existing list with the new list, instead of appending to the current list.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_overwriteorappendjunkmailimportlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_overwriteorappendjunkmailimportlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_permanentlydeletejunkemail","displayName":"Permanently delete Junk E-mail (User)","description":"This policy setting determines whether suspected junk e-mail is permanently deleted instead of moved to the Junk E-mail folder.\r\n\r\nIf you enable this policy setting, suspected junk e-mail is immediately deleted and not moved into the Deleted Items folder.\r\n\r\nIf you disable or do not configure this policy setting, suspected junk e-mail is moved into the Junk E-mail folder.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_permanentlydeletejunkemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_permanentlydeletejunkemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtoblockedsenderslist","displayName":"Specify path to Blocked Senders list (User)","description":"Specify a text file containing a list of e-mail addresses to append to or overwrite the Blocked Senders list (depending on the policy \"Overwrite or Append Junk Mail Import List\").","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtoblockedsenderslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtoblockedsenderslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtoblockedsenderslist_l_specifyfullpathandfilenametoblockedsenderslist","displayName":"Specify full path and filename to Blocked Senders list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist","displayName":"Specify path to Safe Recipients list (User)","description":"Specify a text file containing a list of e-mail addresses to append to or overwrite the Safe Recipients list (depending on the policy \"Overwrite or Append Junk Mail Import List\").","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist_l_specifyfullpathandfilenametosaferecipientslist","displayName":"Specify full path and filename to Safe Recipients list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist","displayName":"Specify path to Safe Senders list (User)","description":"Specify a text file containing a list of e-mail addresses to append to or overwrite the Safe Senders list (depending on the policy \"Overwrite or Append Junk Mail Import List\").","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist_l_specifyfullpathandfilenametosafesenderslist","displayName":"Specify full path and filename to Safe Senders list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_spoofyemails","displayName":"Hide warnings about suspicious domain names in e-mail addresses (User)","description":"By default, users are warned about suspicious domain names in the e-mail addresses. Use this setting to hide warnings about suspicious domain names in e-mail addreses.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_spoofyemails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_spoofyemails_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_trustemailfromcontacts","displayName":"Trust e-mail from contacts (User)","description":"This policy setting controls whether Outlook analyzes e-mail from users' Contacts when filtering junk e-mail.\r\n\r\nIf you enable this policy setting, the \"Also trust E-mail from my Contacts\" check box is selected in the Safe Senders tab of the Junk E-mail Options dialog and users cannot change it. E-mail addresses in users' Contacts list are treated as safe senders for purposes of filtering junk e-mail.\r\n\r\nIf you disable this policy setting, e-mail addresses in users' Contacts list are not treated as safe senders for purposes of filtering junk email, and users cannot change this configuration.\r\n\r\nIf you do not configure this policy setting, e-mail messages that are received from people who are listed in Contacts are considered safe by the Junk E-mail Filter, but users can change this configuration.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_trustemailfromcontacts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_trustemailfromcontacts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehithighlighting","displayName":"Do not display hit highlights in search results (User)","description":"By default, hit highlights are included in search results. Enable this setting to turn off search hit highlighting.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehithighlighting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehithighlighting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehybridsearch","displayName":"Disable Hybrid Searching (User)","description":"This policy setting controls whether searches in Cached Exchange Mode can also be run on the Exchange server. This policy does not affect either Online Mode or non-Exchange accounts. \r\n\r\nIf you enable this policy setting, Outlook runs searches locally in Cached Exchange Mode and “hybrid” (on the Exchange Server also) modes. It should be noted that if the sync slider is enabled and all mail is not locally cached, you may not see all available results.\r\n\r\nIf you disable or do not configure this policy setting, Outlook first runs searches locally, but then allows the user to search on the Exchange server by clicking “More” link at the bottom of searches, or uses the equivalent ribbon button.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehybridsearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehybridsearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disableinstallationprompts","displayName":"Prevent installation prompts when Windows Desktop Search component is not present (User)","description":"This policy setting allows you to prevent a dialog box from being shown when the Windows Desktop Search 4.0 or above system component is not present on the user's computer and removes the other links provided in Outlook to allow users to download the component. The new search functionality in Outlook requires Windows Desktop Search 4.0 or above.\r\n\r\nIf you enable this policy setting, the dialog box is not shown.\r\n\r\nIf you disable or do not configure this policy setting, the dialog box is shown when this system component is not present. Users are prompted with a dialog box when Outlook starts that explains how to download the system component to install on their computers. In addition, other links are provided by default in Outlook to allow users to download the system component. \r\n\r\nNote: If the required Windows system component is not available, the buttons in the Outlook Search ribbon tab will be disabled regardless of how this policy setting is configured.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disableinstallationprompts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disableinstallationprompts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_donotincludetheonlinearchiveinallmailitemsearch","displayName":"Do not include the Online Archive in All Mail Item search (User)","description":"This policy sets the default action in All Mail Item search to not include search results from the Online Archive.\r\n\r\nIf you enable this policy setting, search results from the Online Archive will not be included in an All Mail Item search in Outlook.\r\n\r\nIf you disable or do not configure this policy setting, search results from the Online Archive will be included in an All Mail Item search in Outlook.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_donotincludetheonlinearchiveinallmailitemsearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_donotincludetheonlinearchiveinallmailitemsearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor","displayName":"Change color used to highlight search matches (User)","description":"By default, search matches are highlighted in yellow. This setting allows you to change the color used for highlighting matches in search results.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon","displayName":"Background Color: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_000000","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_12632256","displayName":"Silver","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8421504","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16777215","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_65535","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16711808","displayName":"Fuchsia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8453888","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16776960","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8421376","displayName":"Olive","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8388736","displayName":"Purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_32768","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16711680","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8388608","displayName":"Maroon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_128","displayName":"Navy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_32896","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_255","displayName":"Blue","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_preventclearsignedmessageandattachmentindexing","displayName":"Prevent clear signed message and attachment indexing (User)","description":"This policy setting allows you to turn off the indexing of the body and attachments of clear-text signed messages. The sender, subject line, and date will continue to be indexed and searchable. \r\n\r\nIf you enable this policy setting, indexing of clear-text signed messages will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, clear-text signed messages will be indexed and searchable.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_preventclearsignedmessageandattachmentindexing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_preventclearsignedmessageandattachmentindexing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope","displayName":"Set default search scope (User)","description":"This policy allows you to specify the default search scope to be used. Users will not be able to change the default once this policy is set, but they can change the scope while running a search.\r\n \r\nIf you enable this policy, you can specify the folders that Outlook searches by default when the user begins a new search.\r\n \r\nIf you disable or do not configure this policy, Outlook searches all folders in the current mailbox when the search is initiated from the Inbox. If the search is initiated from another folder, the search only includes items from that folder. Users can still change the scope when searching.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_l_setdefaultsearchscopedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_l_setdefaultsearchscopedropid_0","displayName":"Default behavior (see explanation)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_l_setdefaultsearchscopedropid_1","displayName":"\"All Mailboxes\" on all folders","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_l_setdefaultsearchscopedropid_2","displayName":"\"Current Folder\" on all folders","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_l_setdefaultsearchscopedropid_3","displayName":"\"Current Mailbox\" on all folders","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_turnoffautomaticsearchindexreconciliation","displayName":"Turn off automatic search index reconciliation (User)","description":"This policy setting configures the automatic verification of the integrity of Outlook's search index every 72 hours.\r\n\r\nIf you enable this policy setting, automatic reconciliation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will reconcile its index every 72 hours.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_turnoffautomaticsearchindexreconciliation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_turnoffautomaticsearchindexreconciliation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_turnoffwordwheel","displayName":"Do not display search results as the user types (User)","description":"By default, search results are displayed as the user types a search query. This functionality (known as WordWheeling) can be turned off by enabling this setting.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_turnoffwordwheel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_turnoffwordwheel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions","displayName":"Layout Options (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b9ab4d39-9e28-4897-aa34-0201a35ea989","categoryName":"Right-to-left","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setglobaltextdirection","displayName":"Set global text direction: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b9ab4d39-9e28-4897-aa34-0201a35ea989","categoryName":"Right-to-left","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setglobaltextdirection_0","displayName":"Context-based","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setglobaltextdirection_1","displayName":"Left to right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setglobaltextdirection_2","displayName":"Right-to-left","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setlayoutdirection","displayName":"Set layout direction: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b9ab4d39-9e28-4897-aa34-0201a35ea989","categoryName":"Right-to-left","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setlayoutdirection_0","displayName":"Left to Right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setlayoutdirection_1","displayName":"Right to Left","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general","displayName":"General (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","categoryName":"Spelling","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_l_alwayscheckspellingbeforesending","displayName":"Always check spelling before sending (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","categoryName":"Spelling","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_l_alwayscheckspellingbeforesending_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_l_alwayscheckspellingbeforesending_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_l_ignoreoriginalmessagetextinreplyorforward","displayName":"Ignore original message text in reply or forward (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","categoryName":"Spelling","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_l_ignoreoriginalmessagetextinreplyorforward_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_l_ignoreoriginalmessagetextinreplyorforward_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockglobaladdresslistsynchronization","displayName":"Block Global Address List synchronization (User)","description":"This policy setting allows you to block the synchronization of contacts between Outlook and the Global Address List (GAL).\r\n\r\nIf you enable this policy setting, GAL contact synchronization is blocked.\r\n\r\nIf you disable or you do not configure this policy setting, GAL contact synchronization is allowed.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockglobaladdresslistsynchronization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockglobaladdresslistsynchronization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocknetworkactivitysynchronization","displayName":"Block network activity synchronization (User)","description":"This policy setting allows you to block synchronization of status updates between Outlook and social networks.\r\n\r\nIf you enable this policy setting, social network activity synchronization is blocked.\r\n\r\nIf you disable or you do not configure this policy setting, social network activity synchronization is allowed.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocknetworkactivitysynchronization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocknetworkactivitysynchronization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocksocialnetworkcontactsynchronization","displayName":"Block social network contact synchronization (User)","description":"This policy setting allows you to block synchronization of contacts between Outlook and social networks. \r\n\r\nIf you enable this policy setting, social network contact synchronization is blocked.\r\n\r\nIf you disable or you do not configure this policy setting, social network contact synchronization is allowed.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocksocialnetworkcontactsynchronization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocksocialnetworkcontactsynchronization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockspecificsocialnetworkproviders","displayName":"Block specific social network providers (User)","description":"This policy setting allows you to specify the list of social network providers that will never be loaded by the Outlook Social Connector. \r\n\r\nIf you enable this policy setting, social network providers added to the list will never be loaded by the Outlook Social Connector. This list needs to be semi-colon delimited. \r\n\r\nIf you disable or you do not configure this policy setting, the Outlook Social Connector can load any provider specified by the user.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockspecificsocialnetworkproviders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockspecificsocialnetworkproviders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockspecificsocialnetworkproviders_l_blockspecificsocialnetworkprovidersid","displayName":"Separate ProgIDs with semi-colons (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotallowondemandactivitysynchronization","displayName":"Do not allow on-demand activity synchronization (User)","description":"This policy setting allows you to prevent on-demand synchronization of activity information between Outlook and social networks.\r\n\r\nIf you enable this policy setting, on-demand synchronization is blocked. \r\n\r\nIf you disable or you do not configure this policy setting, on-demand synchronization is allowed.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotallowondemandactivitysynchronization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotallowondemandactivitysynchronization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotdownloadphotosfromactivedirectory","displayName":"Do not download photos from Active Directory (User)","description":"This policy setting controls whether contact photos are downloaded from the Active Directory.\r\n\r\nIf you enable this policy setting, contact photos are not downloaded. \r\n\r\nIf you disable or you do not configure this policy setting, contact photos are downloaded.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotdownloadphotosfromactivedirectory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotdownloadphotosfromactivedirectory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotshowsocialnetworkinfobars","displayName":"Do not show social network info-bars (User)","description":"This policy setting controls whether certain info-bar messages that will prompt users to install social network providers are displayed in the social connector. \r\n\r\nIf you enable this policy setting, the info-bars are not shown.\r\n\r\nIf you disable or you do not configure this policy setting, the info-bars are shown.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotshowsocialnetworkinfobars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotshowsocialnetworkinfobars_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_preventsocialnetworkconnectivity","displayName":"Disable Office connections to social networks (User)","description":"This policy setting prevents users from connecting Office to social networks (including SharePoint), and prevents Office from displaying contacts and feeds from their social networks.\r\n\r\nIf you enable this policy setting, users cannot connect Office to social networks.\r\n\r\nIf you disable or you do not configure this policy setting, users can connect Office to social networks.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_preventsocialnetworkconnectivity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_preventsocialnetworkconnectivity_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval","displayName":"Set GAL contact synchronization interval (User)","description":"This policy setting controls how often contact information is synchronized between Outlook and connected social networks (in minutes). \r\n\r\nIf you enable this policy setting, you may specify the specified interval (in minutes) in which contact information is synchronized.\r\n\r\nIf you disable or you do not configure this policy setting, contact information is synchronized at the default interval (once every 4 days, or 5760 minutes).","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval_l_setgalcontactsynchronizationintervalspinid","displayName":"Synchronization interval (in minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifyactivityfeedsynchronizationinterval","displayName":"Specify activity feed synchronization interval (User)","description":"This policy setting specifies the minimum interval that Office waits before requesting activity feed information from social networks for a given contact.\r\n\r\nIf you enable this policy setting, Office waits for at least the specified interval before requesting a new activity feed for each contact.\r\n\r\nIf you disable or do not configure this policy setting, Office waits for at least the default interval (60 minutes) before requesting a new activity feed for each contact.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifyactivityfeedsynchronizationinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifyactivityfeedsynchronizationinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifyactivityfeedsynchronizationinterval_l_specifyactivityfeedsynchronizationintervalspinid","displayName":"Synchronization interval (in minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload","displayName":"Specify list of social network providers to load (User)","description":"This policy setting determines the list of social network providers that are loaded by the Outlook Social Connector.\r\n\r\nIf you enable this policy setting, you may enter a list of provider progIDs of social network providers that will be loaded by the Outlook Social Connector. This list needs to be semi-colon delimited. Note that if you enable this policy setting, only social network providers that are on this list will be loaded by the Outlook Social Connector. No other social network providers will be loaded.\r\n\r\nIf you disable or you do not configure this policy setting, the Outlook Social Connector can load any provider specified by the user.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload_l_specifylistofsocialnetworkproviderstoloadid","displayName":"Separate ProgIDs with semi-colons (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_turnoffoutlooksocialconnector","displayName":"Turn off Outlook Social Connector (User)","description":"This policy setting allows you to turn off the Outlook Social Connector.\r\n\r\nIf you enable this policy setting, the Outlook Social Connector is turned off.\r\n\r\nIf you disable or you do not configure this policy setting, the Outlook Social Connector is turned on.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_turnoffoutlooksocialconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_turnoffoutlooksocialconnector_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_outlooktodayavailability","displayName":"Outlook Today availability (User)","description":"Checked: Displays the customizable Outlook Today page. | Unchecked: Displays a standard folder view in place of Outlook Today.","helpText":"","infoUrls":[],"categoryId":"75ad885f-6118-4508-a2fd-bb26be931c3f","categoryName":"Outlook Today Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_outlooktodayavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_outlooktodayavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_urlforcustomoutlooktoday","displayName":"URL for custom Outlook Today (User)","description":"Specifies the URL of a custom web page to be displayed in place of Outlook Today.","helpText":"","infoUrls":[],"categoryId":"75ad885f-6118-4508-a2fd-bb26be931c3f","categoryName":"Outlook Today Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_urlforcustomoutlooktoday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_urlforcustomoutlooktoday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_urlforcustomoutlooktoday_l_entertheurlofoutlooktodayswebpagemax129chars","displayName":"Enter the URL of Outlook Today's web page (max 129 chars): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75ad885f-6118-4508-a2fd-bb26be931c3f","categoryName":"Outlook Today Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersinexchangeonline","displayName":"Keep Search Folders in Exchange online (User)","description":"This policy setting allows you to specify the number of days to keep a Search Folder active when running in online mode. After a Search Folder has not been accessed for the specified number of days, it becomes dormant and no longer remains up-to-date with current contents of folders (viewing the Search Folder makes it active again and restarts the timer).\r\n\r\nIf you enable this policy setting, you may specify the number of days to keep a Search Folder active when running in online mode.\r\n\r\nIf you disable or do not configure this policy setting, then Search Folders always remain dormant.","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersinexchangeonline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersinexchangeonline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersinexchangeonline_l_specifydaystokeepfoldersaliveinexchangeonlinemode","displayName":"Specify days to keep folders alive in Exchange online mode: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersoffline","displayName":"Keep Search Folders offline (User)","description":"This policy setting allows you to specify the number of days to keep a Search Folder active when running in offline or cached mode. After a Search Folder has not been accessed for the specified number of days, it becomes dormant and no longer remains up-to-date with current contents of folders (viewing the Search Folder makes it active again and restarts the timer).\r\n\r\nIf you enable this policy setting, you may specify the number of days to keep a Search Folder active when running in offline mode.\r\n\r\nIf you disable or do not configure this policy setting, then Search Folders always remain dormant.","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersoffline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersoffline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersoffline_l_specifydaystokeepfoldersaliveinofflineorcachedmode","displayName":"Specify days to keep folders alive in offline or cached mode: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox","displayName":"Maximum Number of Online Search Folders per mailbox (User)","description":"Specifies the maximum number of Search Folders that run on the Exchange server. The number of Search Folders running on the client computer is not affected.","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox_l_specifymaximumnumberofsearchfolders2","displayName":"Maximum number of Search Folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms","displayName":"Allow Active X One Off Forms (User) (Deprecated)","description":"By default, third-party ActiveX controls are not allowed to run in one-off forms in Outlook. You can change this behavior so that Safe Controls (Microsoft Forms 2.0 controls and the Outlook Recipient and Body controls) are allowed in one-off forms, or so that all ActiveX controls are allowed to run.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_l_empty29","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_l_empty29_0","displayName":"Load only Outlook Controls","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_l_empty29_1","displayName":"Allows only Safe Controls","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_l_empty29_2","displayName":"Allows all ActiveX Controls","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2","displayName":"Allow Active X One Off Forms (User)","description":"By default, third-party ActiveX controls are not allowed to run in one-off forms in Outlook. You can change this behavior so that Safe Controls (Microsoft Forms 2.0 controls and the Outlook Recipient and Body controls) are allowed in one-off forms, or so that all ActiveX controls are allowed to run.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29","displayName":"\r\nSets which ActiveX controls to allow.\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29_0","displayName":"Load only Outlook Controls","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29_1","displayName":"Allows only Safe Controls","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29_2","displayName":"Allows all ActiveX Controls","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel","displayName":"Configure Add-In Trust Level (User)","description":"All installed trusted COM addins can be trusted. Exchange Settings for the addins still override if present and this option is selected.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28","displayName":"\r\nSelect Add-In Trust Level:\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28_0","displayName":"Trust all, or use Exchange settings if present","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28_1","displayName":"Trust all loaded and installed COM addins","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28_2","displayName":"Do NOT trust loaded and installed COM addins","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_disablerememberpasswordcheckboxforinternetemailsettingsdialo","displayName":"Disable 'Remember password' for Internet e-mail accounts (User)","description":"Use this option to hide your user's ability to cache passwords locally in the computer's registry. When configured, this policy will hide the 'Remember Password' checkbox and not allow users to have Outlook remember their password. \r\n\r\nNote that POP3, IMAP, and HTTP e-mail accounts are all considered Internet e-mail accounts in Outlook. E-mail account options are listed on the Server Type dialog box when users choose 'New' under Tools | Account Settings.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_disablerememberpasswordcheckboxforinternetemailsettingsdialo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_disablerememberpasswordcheckboxforinternetemailsettingsdialo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_donotautomaticallysignreplies","displayName":"Do not automatically sign replies (User)","description":"This policy setting allows you to specify whether replies will be automatically signed.\r\n\r\nIf you enable this policy setting, the option to respond automatically to a signed message with a signed response will be overridden, and an unsigned response will be the default reply to a signed message.\r\n\r\nIf you disable or do not configure this policy setting, a signed response will be the default reply to a signed message.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_donotautomaticallysignreplies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_donotautomaticallysignreplies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_preventusersfromcustomizingattachmentsecuritysettings","displayName":"Prevent users from customizing attachment security settings (User) (Deprecated)","description":"This policy setting prevents users from overriding the set of attachments blocked by Outlook.\r\n\r\nIf you enable this policy setting users will be prevented from overriding the set of attachments blocked by Outlook. Outlook also checks the \"Level1Remove\" registry key when this setting is specified. \r\n\r\nIf you disable or do not configure this policy setting, users will be allowed to override the set of attachments blocked by Outlook.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_preventusersfromcustomizingattachmentsecuritysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_preventusersfromcustomizingattachmentsecuritysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_preventusersfromcustomizingattachmentsecuritysettings_v2","displayName":"Prevent users from customizing attachment security settings (User)","description":"This policy setting prevents users from overriding the set of attachments blocked by Outlook.\r\n\r\nIf you enable this policy setting users will be prevented from overriding the set of attachments blocked by Outlook. Outlook also checks the \"Level1Remove\" registry key when this setting is specified. \r\n\r\nIf you disable or do not configure this policy setting, users will be allowed to override the set of attachments blocked by Outlook.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_preventusersfromcustomizingattachmentsecuritysettings_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_preventusersfromcustomizingattachmentsecuritysettings_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_promptusertochoosesecuritysettingsifdefaultsettingsfail","displayName":"Prompt user to choose security settings if default settings fail (User)","description":"Check to prompt the user to choose security settings if default settings fail; uncheck to automatically select.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_promptusertochoosesecuritysettingsifdefaultsettingsfail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_promptusertochoosesecuritysettingsifdefaultsettingsfail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_turnoffcontactexport","displayName":"Turn off contact export (User)","description":"This policy setting controls the ability of users to export contact information from the address book.\r\n\r\nIf you enable this policy setting, the \"Add to Contacts\" menu is not configurable in the address book.\r\n\r\nIf you disable or do not configure this policy setting, the \"Add to Contacts\" menu is configurable.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_turnoffcontactexport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_turnoffcontactexport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_useprotectedviewforattachmentsreceivedfrominternalsenders","displayName":"Use Protected View for attachments received from internal senders (User)","description":"This policy setting allows you to determine if attachments received from senders within your organization open in Protected View. This setting only applies to Outlook accounts setup to use an Exchange server.\r\n\r\nIf you enable this policy setting, attachments received from senders within your organization open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, attachments received from senders within your organization do not open in Protected View.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_useprotectedviewforattachmentsreceivedfrominternalsenders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_useprotectedviewforattachmentsreceivedfrominternalsenders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockexternalcontent","displayName":"Display pictures and external content in HTML e-mail (User)","description":"This policy setting setting controls whether Outlook downloads untrusted pictures and external content located in HTML e-mail messages without users explicitly choosing to download them. \r\n\r\nIf you enable this policy setting, Outlook will not automatically download content from external servers unless the sender is included in the Safe Senders list. Recipients can choose to download external content from untrusted senders on a message-by-message basis. \r\n\r\nIf you disable this policy setting, Outlook will display pictures and external content in HTML e-mail automatically.\r\n\r\nIf you do not configure this policy setting, Outlook does not download external content in HTML e-mail and RSS items unless the content is considered safe. Content that Outlook can be configured to consider safe includes: \r\n\r\n- Content in e-mail messages from senders and to recipients defined in the Safe Senders and Safe Recipients lists. \r\n- Content from Web sites in Internet Explorer's Trusted Sites security zone. \r\n- Content in RSS items. \r\n- Content from SharePoint Discussion Boards. Users can control what content is considered safe by changing the options in the \"Automatic Download\" section of the Trust Center. If Outlook's default blocking configuration is overridden, in the Trust Center or by some other method, Outlook will display external content in all HTML e-mail messages, including any that include Web beacons.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockexternalcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockexternalcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockinternet","displayName":"Include Internet in Safe Zones for Automatic Picture Download (User) (Deprecated)","description":"This policy setting controls whether pictures and external content in HTML e-mail messages from untrusted senders on the Internet are downloaded without Outlook users explicitly choosing to do so. \r\n\r\nIf you enable this policy setting, Outlook will automatically download external content in all e-mail messages sent over the Internet and users will not be able to change the setting. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not consider the Internet a safe zone, which means that Outlook will not automatically download content from external servers unless the sender is included in the Safe Senders list. Recipients can choose to download external content from untrusted senders on a message-by-message basis.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockinternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockinternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockinternet_v2","displayName":"Include Internet in Safe Zones for Automatic Picture Download (User)","description":"This policy setting controls whether pictures and external content in HTML e-mail messages from untrusted senders on the Internet are downloaded without Outlook users explicitly choosing to do so. \r\n\r\nIf you enable this policy setting, Outlook will automatically download external content in all e-mail messages sent over the Internet and users will not be able to change the setting. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not consider the Internet a safe zone, which means that Outlook will not automatically download content from external servers unless the sender is included in the Safe Senders list. Recipients can choose to download external content from untrusted senders on a message-by-message basis.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockinternet_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockinternet_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockintranet","displayName":"Include Intranet in Safe Zones for Automatic Picture Download (User)","description":"This policy setting controls whether pictures and external content in HTML e-mail messages from untrusted senders on the local intranet are downloaded without Outlook users explictly choosing to do so. \r\n\r\nIf you enable this policy setting, Outlook will automatically download external content in all e-mail messages sent over the local intranet and users will not be able to change the setting. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not consider the local intranet a safe zone, which means that Outlook will not automatically download content from other servers in the Local Intranet zone unless the sender is included in the Safe Senders list. Recipients can choose to download external content from untrusted senders on a message-by-message basis.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockintranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockintranet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blocktrustedzones","displayName":"Block Trusted Zones (User)","description":"This policy setting controls whether pictures from sites in the Trusted Sites security zone are automatically downloaded in Outlook e-mail messages and other items. \r\n\r\nIf you enable this policy setting, Outlook does not automatically download content from Web sites in the Trusted sites zone in Internet Explorer. Recipients can choose to download external content on a message-by-message basis. \r\n\r\nIf you disable or do not configure this policy setting, Outlook automatically downloads content from Web sites in the Trusted sites zone in Internet Explorer.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blocktrustedzones_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blocktrustedzones_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafesenderandrecipientlists","displayName":"Automatically download content for e-mail from people in Safe Senders and Safe Recipients Lists (User)","description":"This policy setting controls whether Outlook automatically downloads external content in e-mail from senders in the Safe Senders List or Safe Recipients List. \r\n\r\nIf you enable this policy setting, Outlook automatically downloads content for e-mail from people in Safe Senders and Safe Recipients lists. \r\n\r\nIf you disable this policy setting, Outlook will not automatically download content from external servers for messages sent by people listed in users' Safe Senders Lists or Safe Recipients Lists. Recipients can choose to download external content on a message-by-message basis. \r\n\r\nIf you do not configure this policy setting, downloads are permitted when users receive e-mail from people listed in the user's Safe Senders List or Safe Recipients List.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafesenderandrecipientlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafesenderandrecipientlists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafezones","displayName":"Do not permit download of content from safe zones (User)","description":"This policy setting controls whether Outlook automatically downloads content from safe zones when displaying messages. \r\n\r\nIf you enable this policy setting content from safe zones will be downloaded automatically. \r\n\r\nIf you disable this policy Outlook will not automatically download content from safe zones. Recipients can choose to download external content from untrusted senders on a message-by-message basis. \r\n\r\nIf you do not configure this policy setting, Outlook automatically downloads content from sites that are considered \"safe,\" as defined in the Security tab of the Internet Options dialog box in Internet Explorer. \r\n\r\nImportant - Note that this policy setting is \"backward.\" Despite the name, disabling the policy setting prevents the download of content from safe zones and enabling the policy setting allows it.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafezones_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafezones_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablecontinuebuttononallencryptionwarningdialogs","displayName":"Do not provide Continue option on Encryption warning dialog boxes (User)","description":"This setting controls whether Outlook users are allowed to send e-mail messages after they see an encryption warning. \r\n\r\nIf you enable this policy setting, encryption warning dialog boxes do not contain a Continue button, which means that users must cancel the sending operation entirely. \r\n\r\nIf you disable or do not configure this policy setting, if Outlook users see an encryption-related dialog box when attempting to send a message, they can choose to dismiss the warning and send the message anyway.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablecontinuebuttononallencryptionwarningdialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablecontinuebuttononallencryptionwarningdialogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablepublishtogalbutton","displayName":"Do not display 'Publish to GAL' button (User)","description":"This policy setting controls whether Outlook users can publish e-mail certificates to the Global Address List (GAL). \r\n\r\nIf you enable this policy setting, the \"Publish to GAL\" button does not display in the \"E-mail Security\" section of the Trust Center. \r\n\r\nIf you disable or do not configure this policy setting, Outlook users can publish their e-mail certificates to the GAL through the \"E-mail Security\" section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablepublishtogalbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablepublishtogalbutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_donotcheckemailaddressagainstaddressofcertificatesbeingusing","displayName":"Do not check e-mail address against address of certificates being used (User)","description":"This policy setting controls whether Outlook verifies the user's e-mail address with the address associated with the certificate used for signing.\r\n\r\nIf you enable this policy setting, users can send messages signed with certificates that do not match their e-mail addresses.\r\n\r\nIf you disable or do not configure this policy setting, Outlook verifies that the user's e-mail address matches the certificate being used for signing.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_donotcheckemailaddressagainstaddressofcertificatesbeingusing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_donotcheckemailaddressagainstaddressofcertificatesbeingusing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_enableaiacertevaluation","displayName":"Enable Retrieval of Remote Certificate Authority Information (User)","description":"This policy setting controls whether Outlook will use remote certificate authority information in a secure email message to validate that its certificate is trusted. \r\n\r\nIf you enable this setting, you’ll allow the operating system to access remote network locations specified in a certificate for validation.\r\n\r\nIf you disable or don’t configure this setting, retrieval of remote Certificate Authority Information won’t be allowed, and only stored certificates will be used for authentication.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_enableaiacertevaluation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_enableaiacertevaluation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_enablecryptographyicons","displayName":"Enable Cryptography Icons (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_enablecryptographyicons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_enablecryptographyicons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_encryptallemailmessages","displayName":"Encrypt all e-mail messages (User)","description":"This policy setting allows you to require that all e-mail messages be encrypted when sent from Outlook.\r\n\r\nIf you enable this policy setting, the Encrypt button is automatically selected on all outgoing e-mail messages, meeting invitations, and other Outlook items. Users must select an appropriate certificate to encrypt the message for the intended recipient.\r\n\r\nIf you disable or do not configure this policy setting, outgoing e-mail messages are not encrypted. If you disable this policy setting, users will not be able to change the configuration.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_encryptallemailmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_encryptallemailmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_ensureallsmimesignedmessageshavealabel","displayName":"Ensure all S/MIME signed messages have a label (User)","description":"This policy setting controls whether Outlook requires labels on S/MIME signed messages.\r\n\r\nIf you enable this policy setting, labels must be attached to all Outlook S/MIME messages before they are sent. Users can attach labels to messages in the \"Message Options\" dialog box by clicking \"Security Settings,\" ensuring that the \"Add digital signature to this message\" check box is selected, and selecting a label under \"Security Label.\"\r\n\r\nIf you disable all S/MIME signed messages are not required to have a label, and users cannot change this functionality.\r\n\r\nIf you do not configure this policy setting, all S/MIME signed messages are not required to have a label, but users can change this functionality through the \"Message Options\" dialog box.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_ensureallsmimesignedmessageshavealabel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_ensureallsmimesignedmessageshavealabel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_fortezzacertificatepolicies","displayName":"Fortezza certificate policies (User)","description":"This policy setting specifies a list of policies allowed in the policies extension of a certificate that indicate the certificate is a Fortezza certificate. Fortezza is a hardware--based encryption standard created by the National Security Agency (NSA), a division of the United States Department of Defense. To be valid for use with Fortezza, a certificate must include an appropriate policy in the certificate's policies extension. \r\n\r\nIf you enable this policy setting, you can enter a list of policies in the supplied text box that can be used to indicate that a certificate is a Fortezza certificate. The list should be separated by semi-colons. For example: policy1;policy2;policy3. \r\n\r\nIf you disable or so nor configure this policy setting, a list of Fortezza certificate policies are not listed.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_fortezzacertificatepolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_fortezzacertificatepolicies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_fortezzacertificatepolicies_l_enterlistofpoliciesthatcanbeinthepoliciesextension2","displayName":"List of policies to indicate that a certificate is a Fortezza certificate (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats","displayName":"Message Formats (User)","description":"This policy setting controls which message encryption formats Outlook can use. Outlook supports three formats for encrypting and signing messages: S/MIME, Exchange, and Fortezza.\r\n\r\nIf you enable this policy setting, you can specify whether Outlook can use S/MIME (the default), Exchange, or Fortezza encryption, or any combination of any of these options. Users will not be able to change this configuration.\r\n\r\nIf you disable or do not configure this policy setting, Outlook only uses S/MIME to encrypt and sign messages. If you disable this policy setting, users will not be able to change this configuration.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats","displayName":"Support the following message formats: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_1","displayName":"S/MIME","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_2","displayName":"Exchange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_20","displayName":"Fortezza","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_3","displayName":"S/MIME and Exchange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_21","displayName":"S/MIME and Fortezza","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_22","displayName":"Exchange and Fortezza","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_23","displayName":"S/MIME, Exchange, and Fortezza","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messagewhenoutlookcannotfindthedigitalidtodecodeamessage","displayName":"Message when Outlook cannot find the digital ID to decode a message (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messagewhenoutlookcannotfindthedigitalidtodecodeamessage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messagewhenoutlookcannotfindthedigitalidtodecodeamessage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messagewhenoutlookcannotfindthedigitalidtodecodeamessage_l_entererrormessagetextmax255characters","displayName":"Enter error message text (max 255 characters): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings","displayName":"Minimum encryption settings (User) (Deprecated)","description":"This policy setting allows you to set the minimum key length for an encrypted e-mail message.\r\n\r\nIf you enable this policy setting, you may set the minimum key length for an encrypted e-mail message. Outlook will display a warning dialog if the user tries to send a message using an encryption key that is below the minimum encryption key value set. The user can still choose to ignore the warning and send using the encryption key originally chosen.\r\n\r\nIf you disable or do not configure this policy setting, a dialog warning will be shown to the user if the user attempts to send a message using encryption. The user can still choose to ignore the warning and send using the encryption key originally chosen.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_l_minimumkeysizeinbits","displayName":"Minimum key size (in bits): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_v2","displayName":"Minimum encryption settings (User)","description":"This policy setting allows you to set the minimum key length for an encrypted e-mail message.\r\n\r\nIf you enable this policy setting, you may set the minimum key length for an encrypted e-mail message. Outlook will display a warning dialog if the user tries to send a message using an encryption key that is below the minimum encryption key value set. The user can still choose to ignore the warning and send using the encryption key originally chosen.\r\n\r\nIf you disable or do not configure this policy setting, a dialog warning will be shown to the user if the user attempts to send a message using encryption. The user can still choose to ignore the warning and send using the encryption key originally chosen.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_v2_l_minimumkeysizeinbits","displayName":"Minimum key size (in bits): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_outlooktnefinsmimemessages","displayName":"Always use TNEF formatting in S/MIME messages (User)","description":"This policy setting allows you to specify the formatting when sending S/MIME messages.\r\n\r\nIf you enable this policy setting, Outlook always uses TNEF formatting when sending S/MIME messages.\r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the format specified by the user when sending e-mail messages, including when sending S/MIME messages.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_outlooktnefinsmimemessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_outlooktnefinsmimemessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_repliesorforwardstosignedencryptedmessagesaresignedencrypted","displayName":"Replies or forwards to signed/encrypted messages are signed/encrypted (User)","description":"This policy setting controls whether replies and forwards to signed/encrypted mail should also be signed/encrypted. \r\n\r\nIf you enable this policy setting, signing/encryption will be turned on when replying/forwarding a signed or encrypted message, even if the user is not configured for SMIME.\r\n\r\nIf you disable or do not configure this policy setting, signing/encryption is not enforced.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_repliesorforwardstosignedencryptedmessagesaresignedencrypted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_repliesorforwardstosignedencryptedmessagesaresignedencrypted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requestansmimereceiptforallsmimesignedmessages","displayName":"Request an S/MIME receipt for all S/MIME signed messages (User)","description":"This policy setting controls whether Outlook sends S/MIME receipt requests with S/MIME signed messages.\r\n\r\nIf you enable this policy setting, Outlook requests S/MIME receipts whenever it sends S/MIME signed messages and users cannot change this setting.\r\n\r\nIf you disable or do not configure this policy setting, Outlook does not send S/MIME receipt requests with signed messages, but users can still include receipt requests with individual messages. If you disable this policy setting, users cannot change this functionality, but if you do not configure this policy setting, users can enable the option in the \"E-mail Security\" section of the Trust Center or the \"Security Properties\" dialog for individual messages.\r\n\r\nImportant: When the \"Sign all e-mail messages\" policy setting is enabled, enabling this policy setting can place significant stress on the e-mail infrastructure. Consider your needs and capabilities before enabling both settings.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requestansmimereceiptforallsmimesignedmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requestansmimereceiptforallsmimesignedmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority","displayName":"Required Certificate Authority (User)","description":"This policy setting enables you to designate a required certificate authority for Outlook to use for encryption and digital signatures.\r\n\r\nIf you enable this policy setting, you can specify a required certificate authority by entering an X.509 distinguished name in the text field that is provided. The name must conform to the X.509 certificate format exactly. For example:\r\n\r\nCN=WoodgroveBankCA, DC=WoodgroveBank, DC=com\r\n\r\nIf you disable or do not configure this policy setting, Outlook trusts any certificate authorities that are represented by certificates in the Trusted Root Certification Authorities store on users' computers.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority_l_x509issuednthatrestrictschoiceofcertifyingauthorities","displayName":"X.509 issue DN that restricts choice of certifying authorities: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiresuitebalgorithmsforsmimeoperations","displayName":"Require SuiteB algorithms for S/MIME operations (User)","description":"This policy setting determines whether Outlook is required to use NSA Suite B algorithms for S/MIME operations. Outlook implements Suite B, a set of cryptographic algorithms for symmetric encryption, hashing, digital signatures, and key exchange announced in 2005 by the National Security Agency (NSA), a division of the United States Department of Defense. The Suite B protocols can be used to meet U.S. government standards for handling both classified and unclassified information. \r\n\r\nIf you enable this policy setting, Outlook uses only Suite B algorithms for S/MIME operations. The Suite B algorithms are as follows: \r\n\r\n- Symmetric encryption. Advanced Encryption Standard (AES) with key sizes of 128 and 256 bits. \r\n\r\n- Message digest. Secure Hash Algorithm (SHA-256 and SHA-384). \r\n\r\n- Key agreement. Elliptic-Curve Menezes-Qu-Vanstone (ECMQV); Elliptic Curve Diffie-Hellman (ECDH). \r\n\r\n- Digital Signatures. Elliptic-Curve Digital Signature Algorithm (ECDSA). \r\n\r\nIf you disable or do not configure this policy setting, Outlook can use any available algorithm for S/MIME operations, such as encryption, signing, and so on. \r\n\r\nNote - For more information about Suite B, see \"Fact Sheet NSA Suite B Cryptography\" http://www.nsa.gov/ia/industry/crypto_suite_b.cfm.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiresuitebalgorithmsforsmimeoperations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiresuitebalgorithmsforsmimeoperations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_runinfipscompliantmode","displayName":"Run in FIPS compliant mode (User)","description":"This policy setting controls whether Outlook is required to use FIPS-compliant algorithms when signing and encrypting messages. Outlook can run in a mode that complies with Federal Information Processing Standards (FIPS), a set of standards published by the National Institute of Standards and Technology (NIST) for use by non-military United States government agencies and by government contractors.\r\n\r\nIf you enable this policy setting, Outlook runs in a mode that complies with the FIPS 140-1 standard for cryptographic modules. This mode requires the use of the SHA-1 algorithm for signing and 3DES for encryption.\r\n\r\nIf you disable or do not configure this policy setting, Outlook does not run in FIPS-compliant mode. Organizations that do business with the United States government but do not run Outlook in FIPS-compliant mode risk violating the U.S. government's rules regarding the handling of sensitive information.\r\n\r\nFor more information about FIPS, see FIPS - General Information at http://www.itl.nist.gov/fipspubs/geninfo.htm","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_runinfipscompliantmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_runinfipscompliantmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_sendallsignedmessagesasclearsignedmessages","displayName":"Send all signed messages as clear signed messages (User)","description":"This policy setting controls whether Outlook sends signed messages as clear text signed messages.\r\n\r\nIf you enable this policy setting, the \"Send clear text signed message when sending signed messages\" option is selected in the E-mail Security section of the Trust Center.\r\n\r\nIf you disable or do not configure this policy setting, when users sign e-mail messages with their digital signature and send them, Outlook uses the signature's private key to encrypt the digital signature but sends the messages as clear text, unless they are encrypted separately.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_sendallsignedmessagesasclearsignedmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_sendallsignedmessagesasclearsignedmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signallemailmessages","displayName":"Sign all e-mail messages (User)","description":"This policy setting controls whether Outlook requires digital signatures on all outgoing e-mail messages.\r\n\r\nIf you enable this policy setting, Outlook requires all outgoing messages to be digitally signed before being sent.\r\n\r\nIf you disable or do not configure this policy setting, Outlook does not require outgoing messages to have digital signatures.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signallemailmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signallemailmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning","displayName":"Signature Warning (User) (Deprecated)","description":"This policy setting controls how Outlook warns users about messages with invalid digital signatures.\r\n\r\nIf you enable this policy setting, you can choose from three options for controlling how Outlook users are warned about invalid signatures:\r\n\r\n- Let user decide if they want to be warned. This option enforces the default configuration.\r\n- Always warn about invalid signatures.\r\n- Never warn about invalid signatures.\r\n\r\nIf you disable or do not configure this policy setting, if users open e-mail messages that include invalid digital signatures, Outlook displays a warning dialog. Users can decide whether they want to be warned about invalid signatures in the future.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30","displayName":"Signature Warning (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30_0","displayName":"Let user decide if they want to be warned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30_1","displayName":"Always warn about invalid signatures","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30_2","displayName":"Never warn about invalid signatures","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2","displayName":"Signature Warning (User)","description":"This policy setting controls how Outlook warns users about messages with invalid digital signatures.\r\n\r\nIf you enable this policy setting, you can choose from three options for controlling how Outlook users are warned about invalid signatures:\r\n\r\n- Let user decide if they want to be warned. This option enforces the default configuration.\r\n- Always warn about invalid signatures.\r\n- Never warn about invalid signatures.\r\n\r\nIf you disable or do not configure this policy setting, if users open e-mail messages that include invalid digital signatures, Outlook displays a warning dialog. Users can decide whether they want to be warned about invalid signatures in the future.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2_l_signaturewarning30","displayName":"Signature Warning (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2_l_signaturewarning30_0","displayName":"Let user decide if they want to be warned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2_l_signaturewarning30_1","displayName":"Always warn about invalid signatures","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2_l_signaturewarning30_2","displayName":"Never warn about invalid signatures","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients","displayName":"S/MIME interoperability with external clients: (User)","description":"This policy setting controls whether Outlook decodes encrypted messages itself or passes them to an external program for processing.\r\n\r\nIf you enable this policy setting, you can choose from three options for configuring external S/MIME clients:\r\n\r\n- Handle internally. Outlook decrypts all S/MIME messages itself.\r\n- Handle externally. Outlook hands all S/MIME messages off to the configured external program.\r\n- Handle if possible. Outlook attempts to decrypt all S/MIME messages itself. If it cannot decrypt a message, Outlook hands the message off to the configured external program. This option is the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of selecting Enabled – Handle if possible.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients_l_behaviorforhandlingsmimemessages","displayName":"Behavior for handling S/MIME messages: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients_l_behaviorforhandlingsmimemessages_0","displayName":"Handle internally","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients_l_behaviorforhandlingsmimemessages_1","displayName":"Handle externally","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients_l_behaviorforhandlingsmimemessages_2","displayName":"Handle if possible","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests","displayName":"S/MIME receipt requests behavior (User)","description":"This policy setting controls how Outlook handles S/MIME receipt requests.\r\n\r\nIf you enable this policy setting, you can choose from four options for handling S/MIME receipt requests in Outlook:\r\n\r\n- Open message if receipt can't be sent\r\n- Don't open message if receipt can't be sent\r\n- Always prompt before sending receipt\r\n- Never send S/MIME receipts\r\n\r\nIf you disable or do not configure this policy setting, when users open messages with attached receipt requests, Outlook prompts them to decide whether to send a receipt to the sender with information about the identity of the user who opened the message and the time it was opened. If Outlook cannot send the receipt, the user is still allowed to open the message.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_l_handlemessageswithsmimereceiptrequestsinthefollowingmanner","displayName":"Handle messages with S/MIME receipt requests in the following manner: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_l_handlemessageswithsmimereceiptrequestsinthefollowingmanner_0","displayName":"Open message if receipt can't be sent","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_l_handlemessageswithsmimereceiptrequestsinthefollowingmanner_3","displayName":"Don't open message if receipt can't be sent","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_l_handlemessageswithsmimereceiptrequestsinthefollowingmanner_1","displayName":"Always prompt before sending receipt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_l_handlemessageswithsmimereceiptrequestsinthefollowingmanner_2","displayName":"Never send S/MIME receipts","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeuseissuerserialnumber","displayName":"Use UserIssuerSerialNumber (User)","description":"This policy setting determines whether Outlook uses IssuerSerialNumber as the SignerIdentifier, which enables third-party email client software applications to read encrypted Outlook email messages. For more information about Cryptographic Message Syntax, refer to the RFC 5652 specification.\r\n\r\nIf you enable or do not configure this policy setting, Outlook uses the IssuerSerialNumber as the SignerIdentifier.\r\n\r\nIf you disable this policy setting, Outlook uses SubjectKeyIdentifier for the SignerIdentifier, which might prevent third-party email client software applications from reading encrypted Outlook email messages.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeuseissuerserialnumber_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeuseissuerserialnumber_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_urlforsmimecertificates","displayName":"URL for S/MIME certificates (User)","description":"This policy setting provides a URL at which Outlook users can obtain S/MIME certificates. \r\n\r\nIf you enable this policy setting, you can enter a URL from which users can obtain S/MIME certificates. The URL can contain three variables, %1, %2, and %3, which will be replaced by the user's name, e-mail address, and language, respectively. When users click \"Get a Digital ID\", they will be directed to the supplied URL. \r\n\r\nIf you disable or do not configure this policy setting, a URL for S/MIME certificates is not provided.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_urlforsmimecertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_urlforsmimecertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_urlforsmimecertificates_l_enterurl","displayName":"Enter URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_attachmentsecuretemporaryfolder","displayName":"Attachment Secure Temporary Folder (User)","description":"This policy setting allows you to specify a folder path for the Secure Temporary Files folder rather than using the one that is randomly generated by Outlook. \r\n\r\nIf you enable this policy setting, you can specify a folder path for the Security Temporary Files folder rather than using the one that is randomly generated by Outlook. \r\n\r\nIf you disable or do not configure this policy setting, Outlook will assign the Secure Temporary Files folder a different random name for each user. \r\n\r\nImportant - If you must use a specific folder for Outlook attachments, Microsoft recommends that you use a local directory (for best performance), that you place the folder under the Temporary Internet Files folder (to benefit from the enhanced security on that folder), and that the folder name is unique and difficult to guess.","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_attachmentsecuretemporaryfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_attachmentsecuretemporaryfolder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_attachmentsecuretemporaryfolder_l_enterthesecurefolderpath","displayName":"Enter the Secure Folder path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls","displayName":"Missing CRLs (User)","description":"This policy setting controls whether Outlook considers a missing certificate revocation list (CRL) a warning or an error. Digital certificates contain an attribute that shows where the corresponding CRL is located. CRLs contain lists of digital certificates that have been revoked by their controlling certification authorities (CAs), typically because the certificates were issued improperly or their associated private keys were compromised. If a CRL is missing or unavailable, Outlook cannot determine whether a certificate has been revoked. Therefore, an improperly issued certificate or one that has been compromised might be used to gain access to data. \r\n\r\nIf you enable this policy setting, you can choose between two options that determine how Outlook functions when a CRL is missing: \r\n\r\n- Warning. This option is the default configuration in Outlook and ensures that Outlook displays a warning message when a CRL is missing. \r\n\r\n- Error. This option ensures that Outlook displays an error message when a CRL is missing. \r\n\r\nIf you disable or do not configure this policy setting, Outlook displays a warning message when a CRL is not available.","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_l_indicateamissingcrlasan","displayName":"Indicate a missing CRL as a(n): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_l_indicateamissingcrlasan_0","displayName":"Warning","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_l_indicateamissingcrlasan_1","displayName":"Error","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates","displayName":"Missing root certificates (User)","description":"This policy setting controls how Outlook functions when a root certificate is missing. \r\n\r\nIf you enable this policy setting, you can choose from three options that determine how Outlook functions when a root certificate is missing. \r\n\r\n- Neither Error nor Warning. This option displays neither an error nor a warning, and enforces the default configuration in Outlook.\r\n- Warning. This option ensures that Outlook displays a warning message when a root certificate is missing. \r\n- Error. This option ensures that Outlook displays an error message when a root certificate is missing. \r\n\r\nIf you don't configure this policy setting, users will see an error when a root certificate is missing.","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan","displayName":"Indicate a missing root certificate as a(n): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan_0","displayName":"Neither error nor warning","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan_1","displayName":"Warning","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan_2","displayName":"Error","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_promotingerrorsaswarnings","displayName":"Promote Level 2 errors as errors, not warnings (User)","description":"This policy setting allows you to treat Level 2 errors as warnings instead of errors. Level 2 errors occur when the message signature appears to be valid, but there are other issues with the signature. \r\n\r\nIf you enable this policy setting, Level 2 errors will be treated as warnings.\r\n\r\nIf you disable or do not configure this policy setting, Level 2 errors will be treated as errors\r\n\r\nWhen you specify a value for PromoteErrorsAsWarnings, note that potential Level 2 error conditions include the following:\r\n\r\n- Unknown Signature Algorithm\r\n- No Signing Certification Found\r\n- Bad Attribute Sets\r\n- No Issuer Certificate found\r\n- No CRL Found\r\n- Out-of-date CRL\r\n- Root Trust Problem\r\n- Out-of-date CTL","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_promotingerrorsaswarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_promotingerrorsaswarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists","displayName":"Retrieving CRLs (Certificate Revocation Lists) (User) (Deprecated)","description":"This policy setting controls how Outlook retrieves Certificate Revocation Lists to verify the validity of certificates.Certificate revocation lists (CRLs) are lists of digital certificates that have been revoked by their controlling certificate authorities (CAs), typically because the certificates were issued improperly or their associated private keys were compromised. \r\n\r\nIf you enable this policy setting, you can choose from three options to govern how Outlook uses CRLs: \r\n\r\n- Use system Default. Outlook relies on the CRL download schedule that is configured for the operating system. \r\n- When online always retrieve the CRL. This option is the default configuration in Outlook. \r\n- Never retrieve the CRL. Outlook will not attempt to download the CRL for a certificate, even if it is online. This option can reduce security. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook handles a certificate that includes a URL from which a CRL can be downloaded, Outlook will retrieve the CRL from the provided URL if Outlook is online.","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_l_empty31","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_l_empty31_0","displayName":"Use system Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_l_empty31_1","displayName":"When online always retreive the CRL","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_l_empty31_2","displayName":"Never retreive the CRL","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2","displayName":"Retrieving CRLs (Certificate Revocation Lists) (User)","description":"This policy setting controls how Outlook retrieves Certificate Revocation Lists to verify the validity of certificates.Certificate revocation lists (CRLs) are lists of digital certificates that have been revoked by their controlling certificate authorities (CAs), typically because the certificates were issued improperly or their associated private keys were compromised. \r\n\r\nIf you enable this policy setting, you can choose from three options to govern how Outlook uses CRLs: \r\n\r\n- Use system Default. Outlook relies on the CRL download schedule that is configured for the operating system. \r\n- When online always retrieve the CRL. This option is the default configuration in Outlook. \r\n- Never retrieve the CRL. Outlook will not attempt to download the CRL for a certificate, even if it is online. This option can reduce security. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook handles a certificate that includes a URL from which a CRL can be downloaded, Outlook will retrieve the CRL from the provided URL if Outlook is online.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2_l_empty31","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2_l_empty31_0","displayName":"Use system Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2_l_empty31_1","displayName":"When online always retreive the CRL","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2_l_empty31_2","displayName":"Never retreive the CRL","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode","displayName":"Outlook Security Mode (User)","description":"This policy setting controls which set of security settings are enforced in Outlook. \r\n\r\nIf you enable this policy setting, you can choose from four options for enforcing Outlook security settings: \r\n\r\n* Outlook Default Security - This option is the default configuration in Outlook. Users can configure security themselves, and Outlook ignores any security-related settings configured in Group Policy. \r\n\r\n* Use Security Form from 'Outlook Security Settings' Public Folder - Outlook uses the settings from the security form published in the designated public folder. \r\n\r\n* Use Security Form from 'Outlook 10 Security Settings' Public Folder - Outlook uses the settings from the security form published in the designated public folder. \r\n\r\n* Use Outlook Security Group Policy - Outlook uses security settings from Group Policy. \r\n\r\nImportant - You must enable this policy setting if you want to apply the other Outlook security policy settings mentioned in this guide. \r\n\r\nIf you disable or do not configure this policy setting, Outlook users can configure security for themselves, and Outlook ignores any security-related settings that are configured in Group Policy. \r\n\r\nNote - In previous versions of Outlook, when security settings were published in a form in Exchange Server public folders, users who needed these settings required the HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Security\\CheckAdminSettings registry key to be set on their computers for the settings to apply. In Outlook, the CheckAdminSettings registry key is no longer used to determine users' security settings. Instead, the Outlook Security Mode setting can be used to determine whether Outlook security should be controlled directly by Group Policy, by the security form from the Outlook Security Settings Public Folder, or by the settings on users' own computers.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_l_outlooksecuritypolicy","displayName":"Outlook Security Policy: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_l_outlooksecuritypolicy_0","displayName":"Outlook Default Security","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_l_outlooksecuritypolicy_1","displayName":"Use Security Form from 'Outlook Security Settings' Public Folder","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_l_outlooksecuritypolicy_2","displayName":"Use Security Form from 'Outlook 10 Security Settings' Public Folder","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_l_outlooksecuritypolicy_3","displayName":"Use Outlook Security Group Policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments","displayName":"Allow users to demote attachments to Level 2 (User) (Deprecated)","description":"This policy setting controls whether Outlook users can demote attachments to Level 2 by using a registry key, which will allow them to save files to disk and open them from that location. Outlook uses two levels of security to restrict access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, users can create a list of Level 1 file types to demote to Level 2 by adding the file types to the following registry key: HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Security\\Level1Remove. \r\n\r\nIf you disable or do not configure this policy setting, users cannot demote level 1 attachments to level 2, and the HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Security\\Level1Remove registry key has no effect.\r\n","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_v2","displayName":"Allow users to demote attachments to Level 2 (User)","description":"This policy setting controls whether Outlook users can demote attachments to Level 2 by using a registry key, which will allow them to save files to disk and open them from that location. Outlook uses two levels of security to restrict access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, users can create a list of Level 1 file types to demote to Level 2 by adding the file types to the following registry key: HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Security\\Level1Remove. \r\n\r\nIf you disable or do not configure this policy setting, users cannot demote level 1 attachments to level 2, and the HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Security\\Level1Remove registry key has no effect.\r\n","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1addfilepolicy","displayName":"Add file extensions to block as Level 1 (User)","description":"This policy setting controls which types of attachments (determined by file extension) Outlook prevents from being delivered. \r\n\r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify additional file type extensions as Level 1--that is, to be blocked from delivery--by entering them in the text field provided separated by semicolons. \r\n\r\nIf you disable or do not configure this policy setting, Outlook classifies a number of potentially harmful file types (such as those with .exe, .reg, and .vbs extensions) as Level 1 and blocks files with those extensions from being delivered. Important: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1addfilepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1addfilepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1addfilepolicy_l_additionalextensions","displayName":"Additional Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments","displayName":"Display Level 1 attachments (User) (Deprecated)","description":"This policy setting controls whether Outlook blocks potentially dangerous attachments designated Level 1. \r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n \r\nIf you enable this policy setting, Outlook users can gain access to Level 1 file type attachments by first saving the attachments to disk and then opening them, as with Level 2 attachments. \r\n\r\nIf you disable this policy setting, Level 1 attachments do not display under any circumstances. \r\n\r\nIf you do not configure this policy setting, Outlook completely blocks access to Level 1 files, and requires users to save Level 2 files to disk before opening them.","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_v2","displayName":"Display Level 1 attachments (User)","description":"This policy setting controls whether Outlook blocks potentially dangerous attachments designated Level 1. \r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n \r\nIf you enable this policy setting, Outlook users can gain access to Level 1 file type attachments by first saving the attachments to disk and then opening them, as with Level 2 attachments. \r\n\r\nIf you disable this policy setting, Level 1 attachments do not display under any circumstances. \r\n\r\nIf you do not configure this policy setting, Outlook completely blocks access to Level 1 files, and requires users to save Level 2 files to disk before opening them.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy","displayName":"Remove file extensions blocked as Level 1 (User) (Deprecated)","description":"This policy setting controls which types of attachments (determined by file extension) Outlook prevents from being delivered. \r\n\r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify the removal of file type extensions as that Outlook classifies as Level 1--that is, to be blocked from delivery--by entering them in the text field provided separated by semicolons. \r\n\r\nIf you disable or do not configure this policy setting, Outlook classifies a number of potentially harmful file types (such as those with .exe, .reg, and .vbs extensions) as Level 1 and blocks files with those extensions from being delivered. \r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_l_removedextensions","displayName":"Removed Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_v2","displayName":"Remove file extensions blocked as Level 1 (User)","description":"This policy setting controls which types of attachments (determined by file extension) Outlook prevents from being delivered. \r\n\r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify the removal of file type extensions as that Outlook classifies as Level 1--that is, to be blocked from delivery--by entering them in the text field provided separated by semicolons. \r\n\r\nIf you disable or do not configure this policy setting, Outlook classifies a number of potentially harmful file types (such as those with .exe, .reg, and .vbs extensions) as Level 1 and blocks files with those extensions from being delivered. \r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_v2_l_removedextensions","displayName":"Removed Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2addfilepolicy","displayName":"Add file extensions to block as Level 2 (User)","description":"This policy setting controls which types of attachments (determined by file extension) must be saved to disk before users can open them. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify a list of attachment file types to classify as Level 2, which forces users to actively decide to download the attachment to view it. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not classify any file type extensions as Level 2. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2addfilepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2addfilepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2addfilepolicy_l_additionalextensions23","displayName":"Additional Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy","displayName":"Remove file extensions blocked as Level 2 (User) (Deprecated)","description":"This policy setting controls which types of attachments (determined by file extension) must be saved to disk before users can open them. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify a list of attachment file types to classify as Level 2, which forces users to actively decide to download the attachment to view it. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not classify any file type extensions as Level 2. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_l_removedextensions25","displayName":"Removed Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_v2","displayName":"Remove file extensions blocked as Level 2 (User)","description":"This policy setting controls which types of attachments (determined by file extension) must be saved to disk before users can open them. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify a list of attachment file types to classify as Level 2, which forces users to actively decide to download the attachment to view it. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not classify any file type extensions as Level 2. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_v2_l_removedextensions25","displayName":"Removed Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_nopromptlevel1close","displayName":"Do not prompt about Level 1 attachments when closing an item (User)","description":"This policy setting controls whether Outlook displays a warning before closing an item that contains an unsafe attachment that will be blocked when the item is re-opened.To protect users from viruses and other harmful files, Outlook uses two levels of security, designated Level 1 and Level 2, to restrict users' access to files attached to e-mail messages or other items. Outlook completely blocks access to Level 1 files by default, and requires users to save Level 2 files to disk before opening them. Potentially harmful files can be classified into these two levels by file type extension, with all other file types considered safe. \r\n\r\nIf you enable this policy setting, Outlook will not display a warning when users close items with Level 1 attachments, which could cause data loss. \r\n\r\nIf you disable or do not configure this policy setting, when a user closes an item to which a level 1 file has been attached, Outlook warns the user that the message contains a potentially unsafe attachment and that the user might not be able to access the attachment when opening the item later. (Such a sequence of events might occur when a user closes a draft message that they intend to resume editing at some future time.) \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_nopromptlevel1close_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_nopromptlevel1close_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_nopromptlevel1send","displayName":"Do not prompt about Level 1 attachments when sending an item (User)","description":"This policy setting controls whether Outlook displays a warning before sending an item that contains an unsafe attachment that will be blocked when the item is opened by a recipient. To protect users from viruses and other harmful files, Outlook uses two levels of security, designated Level 1 and Level 2, to restrict access to files attached to e-mail messages or other items. Outlook completely blocks access to Level 1 files by default, and requires users to save Level 2 files to disk before opening them. Potentially harmful files can be classified into these two levels by file type extension, with all other file types considered safe. \r\n\r\nIf you enable this policy setting, Outlook will not display a warning when a user sends an item with a Level 1 attachment, which can cause users' data to be at risk.\r\n\r\nIf you disable or do not configure this policy setting, when users attempt to send an item to which a level 1 file has been attached, Outlook warns them that the message contains a potentially unsafe attachment and that the recipient might not be able to access it. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_nopromptlevel1send_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_nopromptlevel1send_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_showolepackageobj","displayName":"Display OLE package objects (User)","description":"By default, OLE package objects are not displayed in e-mail messages. You can change this behavior so that the package appears in the body of the e-mail message as an icon that represents an embedded or linked OLE object. When users double-click the icon representing the package, the program used to create the object either plays the object or opens and displays it. Be aware that the icon for OLE package objects can be easily changed and used to disguise malicious files.\r\n\r\nTo set Exchange Security Form settings by using Group Policy, note that this policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_showolepackageobj_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_showolepackageobj_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms","displayName":"Allow scripts in one-off Outlook forms (User) (Deprecated)","description":"This policy setting controls whether scripts can run in Outlook forms in which the script and layout are contained within the message. \r\n\r\nIf you enable this policy setting, scripts can run in one-off Outlook forms. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not run scripts in forms in which the script and the layout are contained within the message. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"e11f4bd4-9041-49c9-9b8c-163827d606ce","categoryName":"Custom Form Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_v2","displayName":"Allow scripts in one-off Outlook forms (User)","description":"This policy setting controls whether scripts can run in Outlook forms in which the script and layout are contained within the message. \r\n\r\nIf you enable this policy setting, scripts can run in one-off Outlook forms. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not run scripts in forms in which the script and the layout are contained within the message. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom","displayName":"Set Outlook object model custom actions execution prompt (User) (Deprecated)","description":"This policy setting controls whether Outlook prompts users before executing a custom action. Custom actions add functionality to Outlook that can be triggered as part of a rule. Among other possible features, custom actions can be created that reply to messages in ways that circumvent the Outlook model's programmatic send protections. \r\n\r\nIf you enable this policy setting, you can choose from four options to control how Outlook functions when a custom action is executed that uses the Outlook object model: \r\n\r\n* Prompt User \r\n* Automatically Approve \r\n* Automatically Deny \r\n* Prompt user based on computer security. This option enforces the default configuration in Outlook. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook or another program initiates a custom action using the Outlook object model, users are prompted to allow or reject the action. If this configuration is changed, malicious code can use the Outlook object model to compromise sensitive information or otherwise cause data and computing resources to be at risk. This is the equivalent of choosing Enabled -- Prompt user based on computer security.","helpText":"","infoUrls":[],"categoryId":"e11f4bd4-9041-49c9-9b8c-163827d606ce","categoryName":"Custom Form Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_l_onexecutecustomactionoom_setting","displayName":"When executing a custom action: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e11f4bd4-9041-49c9-9b8c-163827d606ce","categoryName":"Custom Form Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_l_onexecutecustomactionoom_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_l_onexecutecustomactionoom_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_l_onexecutecustomactionoom_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_l_onexecutecustomactionoom_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2","displayName":"Set Outlook object model custom actions execution prompt (User)","description":"This policy setting controls whether Outlook prompts users before executing a custom action. Custom actions add functionality to Outlook that can be triggered as part of a rule. Among other possible features, custom actions can be created that reply to messages in ways that circumvent the Outlook model's programmatic send protections. \r\n\r\nIf you enable this policy setting, you can choose from four options to control how Outlook functions when a custom action is executed that uses the Outlook object model: \r\n\r\n* Prompt User \r\n* Automatically Approve \r\n* Automatically Deny \r\n* Prompt user based on computer security. This option enforces the default configuration in Outlook. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook or another program initiates a custom action using the Outlook object model, users are prompted to allow or reject the action. If this configuration is changed, malicious code can use the Outlook object model to compromise sensitive information or otherwise cause data and computing resources to be at risk. This is the equivalent of choosing Enabled -- Prompt user based on computer security.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_l_onexecutecustomactionoom_setting","displayName":"When executing a custom action: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_l_onexecutecustomactionoom_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_l_onexecutecustomactionoom_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_l_onexecutecustomactionoom_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_l_onexecutecustomactionoom_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess","displayName":"Configure Outlook object model prompt when reading address information (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to gain access to a recipient field, such as the ''To:'' field, using the Outlook object model.\r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to access a recipient field using the Outlook object model:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt.\r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended.\r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. This is the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to access recipient fields, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_l_oomaddressaccess_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_l_oomaddressaccess_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_l_oomaddressaccess_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_l_oomaddressaccess_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_l_oomaddressaccess_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2","displayName":"Configure Outlook object model prompt when reading address information (User)","description":"This policy setting controls what happens when an untrusted program attempts to gain access to a recipient field, such as the ''To:'' field, using the Outlook object model.\r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to access a recipient field using the Outlook object model:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt.\r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended.\r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. This is the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to access recipient fields, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook","displayName":"Configure Outlook object model prompt when accessing an address book (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to gain access to an Address Book using the Outlook object model. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to programmatically access an Address Book using the Outlook object model:\r\n\r\n- Prompt user - Users are prompted to approve every access attempt. \r\n- Automatically approve - Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny - Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security - Outlook will rely on the setting in the ''Programmatic Access'' section of the Trust Center. This is the default behavior.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to access the address book programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_l_oomaddressbook_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_l_oomaddressbook_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_l_oomaddressbook_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_l_oomaddressbook_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_l_oomaddressbook_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2","displayName":"Configure Outlook object model prompt when accessing an address book (User)","description":"This policy setting controls what happens when an untrusted program attempts to gain access to an Address Book using the Outlook object model. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to programmatically access an Address Book using the Outlook object model:\r\n\r\n- Prompt user - Users are prompted to approve every access attempt. \r\n- Automatically approve - Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny - Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security - Outlook will rely on the setting in the ''Programmatic Access'' section of the Trust Center. This is the default behavior.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to access the address book programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula","displayName":"Configure Outlook object model prompt When accessing the Formula property of a UserProperty object (User) (Deprecated)","description":"This policy setting controls what happens when a user designs a custom form in Outlook and attempts to bind an Address Information field to a combination or formula custom field.\r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to access address information using the UserProperties. Find method of the Outlook object model: \r\n\r\n- Prompt user. The user will be prompted to approve every access attempt. \r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. \r\n\r\nIf you disable or do not configure this policy setting, when a user tries to bind an address information field to a combination or formula custom field in a custom form, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_l_oomformula_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_l_oomformula_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_l_oomformula_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_l_oomformula_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_l_oomformula_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2","displayName":"Configure Outlook object model prompt When accessing the Formula property of a UserProperty object (User)","description":"This policy setting controls what happens when a user designs a custom form in Outlook and attempts to bind an Address Information field to a combination or formula custom field.\r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to access address information using the UserProperties. Find method of the Outlook object model: \r\n\r\n- Prompt user. The user will be prompted to approve every access attempt. \r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. \r\n\r\nIf you disable or do not configure this policy setting, when a user tries to bind an address information field to a combination or formula custom field in a custom form, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_l_oomformula_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_l_oomformula_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_l_oomformula_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_l_oomformula_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_l_oomformula_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest","displayName":"Configure Outlook object model prompt when responding to meeting and task requests (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to programmatically send e-mail in Outlook using the Response method of a task or meeting request. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to programmatically send e-mail using the Response method of a task or meeting request:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt.\r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended.\r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook only prompts users when antivirus software is out of date or not running. This is the default configuration. \r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to respond to tasks or meeting requests programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_l_oommeetingtaskrequest_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_l_oommeetingtaskrequest_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_l_oommeetingtaskrequest_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_l_oommeetingtaskrequest_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_l_oommeetingtaskrequest_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2","displayName":"Configure Outlook object model prompt when responding to meeting and task requests (User)","description":"This policy setting controls what happens when an untrusted program attempts to programmatically send e-mail in Outlook using the Response method of a task or meeting request. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to programmatically send e-mail using the Response method of a task or meeting request:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt.\r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended.\r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook only prompts users when antivirus software is out of date or not running. This is the default configuration. \r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to respond to tasks or meeting requests programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas","displayName":"Configure Outlook object model prompt when executing Save As (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to use the Save As command to programmatically save an item. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to use the Save As command to programmatically save an item:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt. \r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. This is the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to use the Save As command, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_l_oomsaveas_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_l_oomsaveas_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_l_oomsaveas_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_l_oomsaveas_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_l_oomsaveas_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2","displayName":"Configure Outlook object model prompt when executing Save As (User)","description":"This policy setting controls what happens when an untrusted program attempts to use the Save As command to programmatically save an item. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to use the Save As command to programmatically save an item:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt. \r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. This is the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to use the Save As command, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend","displayName":"Configure Outlook object model prompt when sending mail (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to send e-mail programmatically using the Outlook object model. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to send e-mail programmatically using the Outlook object model: \r\n\r\n- Prompt user - The user will be prompted to approve every access attempt.\r\n- Automatically approve - Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny - Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. \r\n\r\nImportant: This policy setting only applies if the ''Outlook Security Mode'' policy setting under ''Microsoft Outlook 2016\\Security\\Security Form Settings'' is configured to ''Use Outlook Security Group Policy.''\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to send mail programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_l_oomsend_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_l_oomsend_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_l_oomsend_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_l_oomsend_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_l_oomsend_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2","displayName":"Configure Outlook object model prompt when sending mail (User)","description":"This policy setting controls what happens when an untrusted program attempts to send e-mail programmatically using the Outlook object model. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to send e-mail programmatically using the Outlook object model: \r\n\r\n- Prompt user - The user will be prompted to approve every access attempt.\r\n- Automatically approve - Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny - Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. \r\n\r\nImportant: This policy setting only applies if the ''Outlook Security Mode'' policy setting under ''Microsoft Outlook 2016\\Security\\Security Form Settings'' is configured to ''Use Outlook Security Group Policy.''\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to send mail programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_l_oomsend_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_l_oomsend_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_l_oomsend_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_l_oomsend_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_l_oomsend_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve","displayName":"Configure Simple MAPI name resolution prompt (User)","description":"This policy setting allows you to specify what occurs when a program attempts to gain access to an Address Book, using Simple MAPI.\r\n\r\nIf you enable this policy setting, you can choose whether Outlook always allows access to the Address Book, always disallows access to the Address Book, or prompts the user to specify whether to allow or disallow access to the Address Book.\r\n\r\nIf you disable or do not configure this policy setting, Outlook prompts the user to specify whether to allow or disallow access to the Address Book.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_l_simplemapi_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_l_simplemapi_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_l_simplemapi_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_l_simplemapi_setting_0","displayName":"Automatically Deny","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage","displayName":"Configure Simple MAPI message opening prompt (User)","description":"This policy setting allows you to specify what occurs when a program attempts to gain access to a recipient field, such as the “To” field, using Simple MAPI.\r\n\r\nIf you enable this policy setting, you can choose whether Outlook always allows access to the recipient field, always disallows access to the recipient field, or prompt users to specify whether to allow or disallow access to the recipient field.\r\n\r\nIf you disable or do not configure this policy setting, Outlook prompts users to specify whether to allow or disallow access to the Address Book.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting_0","displayName":"Automatically Deny","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend","displayName":"Configure Simple MAPI sending prompt (User)","description":"This policy setting allows you to specify what occurs when a program attempts to send mail programmatically, using Simple MAPI.\r\n\r\nIf you enable this policy setting, you can choose whether Outlook always allows sending mail, always disables sending mail, or prompts users to specify whether to allow or disallow sending mail.\r\n\r\nIf you disable or do not configure this policy setting, Outlook prompts users to specify whether to allow or disallow sending the mail.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend_l_simplemapi_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend_l_simplemapi_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend_l_simplemapi_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend_l_simplemapi_setting_0","displayName":"Automatically Deny","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins","displayName":"Configure trusted add-ins (User)","description":"This policy setting can be used to specify a list of trusted add-ins that can be run without being restricted by the security measures in Outlook.\r\n\r\nIf you enable this policy setting, a list of trusted add-ins and hashes is made available that you can modify by adding and removing entries. The list is empty by default. To create a new entry, enter a DLL file name in the ''Value Name'' column and the hash result in the ''Value'' column. \r\n\r\nIf you disable or do not configure this policy setting, the list of trusted add-ins is empty and unused, so the recommended EC and SSLF settings do not create any usability issues. However, users who rely on add-ins that access the Outlook object model might be repeatedly prompted unless administrators enable this setting and add the add-ins to the list.\r\n\r\nNote - You can also configure Exchange Security Form settings by enabling the ''Outlook Security Mode'' setting in User Configuration\\Administrative Templates\\Microsoft Outlook 2016\\Security\\Security Form Settings\\Microsoft Outlook 2016 Security and selecting ''Use Outlook Security Group Policy'' from the drop-down list.","helpText":"","infoUrls":[],"categoryId":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","categoryName":"Trusted Add-ins","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins_l_listoftrustedaddins","displayName":"List of trusted add-ins and hashes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","categoryName":"Trusted Add-ins","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins_l_listoftrustedaddins_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","categoryName":"Trusted Add-ins","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins_l_listoftrustedaddins_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","categoryName":"Trusted Add-ins","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_applymacrosecuritysettings","displayName":"Apply macro security settings to macros, add-ins and additional actions (User)","description":"This policy setting controls whether Outlook also applies the macro security settings to installed COM add-ins and additional actions. \r\n\r\nIf you enable this policy setting, the macro security settings will also be applied to add-ins and additional actions. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not use the macro security settings to determine whether to run macros, installed COM add-ins, and additional actions.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_applymacrosecuritysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_applymacrosecuritysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_enablelinksinemailmessages","displayName":"Allow hyperlinks in suspected phishing e-mail messages (User) (Deprecated)","description":"This policy setting controls whether hyperlinks in suspected phishing e-mail messages in Outlook are allowed. \r\n\r\nIf you enable this policy setting, Outlook will allow hyperlinks in suspected phishing messages that are not also classified as junk e-mail. \r\n\r\nIf you disable or do not configure this policy setting, Outlook will not allow hyperlinks in suspected phishing messages, even if they are not classified as junk e-mail.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_enablelinksinemailmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_enablelinksinemailmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_enablelinksinemailmessages_v2","displayName":"Allow hyperlinks in suspected phishing e-mail messages (User)","description":"This policy setting controls whether hyperlinks in suspected phishing e-mail messages in Outlook are allowed. \r\n\r\nIf you enable this policy setting, Outlook will allow hyperlinks in suspected phishing messages that are not also classified as junk e-mail. \r\n\r\nIf you disable or do not configure this policy setting, Outlook will not allow hyperlinks in suspected phishing messages, even if they are not classified as junk e-mail.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_enablelinksinemailmessages_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_enablelinksinemailmessages_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_onsendaddinsenabled","displayName":"Disable send when web extensions can’t load. (User)","description":"If you enable this policy setting, Outlook won’t allow email and meeting requests to be sent until web add-ins are loaded from Exchange.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_onsendaddinsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_onsendaddinsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationalertthreshold","displayName":"Specify activation disabling threshold for web extensions (User)","description":"This policy setting allows you to specify the threshold that Outlook refers to before disabling a web extension during activation. \r\n\r\nIf you enable this policy setting, you can specify a threshold (in milliseconds) for the activation manager retry limit during an Outlook session. If the web extension requires more than the specified threshold for the number of occurrences specified by the activation manager retry limit during an Outlook session, Outlook disables the web extension. \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default activation alert threshold of 1000 milliseconds. The maximum activation alert threshold is 10000 milliseconds, and the minimum activation alert threshold is 100 milliseconds.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationalertthreshold_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationalertthreshold_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationalertthreshold_l_outlookactivationalertthresholdspinid","displayName":"(100 - 10000 milliseconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationmanagerretrylimit","displayName":"Specify activation manager retry limit for web extensions (User)","description":"This policy setting allows you to specify the retry limit Outlook uses before disabling a web extension during activation.\r\n\r\nIf you enable this policy setting, you can specify the activation manager retry limit. If the web extension requires more than the specified activation alert threshold for the number of occurrences specified by the activation manager retry limit during an Outlook session, Outlook automatically disables the web extension. \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default activation manager retry limit of 3 occurrences. The maximum activation manager retry limit is 5 occurrences, and the minimum activation manager retry limit is 1 occurrence.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationmanagerretrylimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationmanagerretrylimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationmanagerretrylimit_l_outlookactivationmanagerretrylimitspinid","displayName":"(1 - 5 occurrences) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval","displayName":"Specify alert interval for web extensions (User)","description":"This policy setting allows you to specify the alert interval Outlook uses before disabling a web extension during initialization. The alert interval controls how often Office checks on memory and CPU usage for a running web extension. \r\n\r\nIf you enable this policy setting, you can specify the alert interval for web extensions. If the web extension requires more than the specified memory alert threshold when the memory or CPU check occurs, Outlook disables the web extension. \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default alert interval of 5 seconds. This alert interval overrides the WEF alert interval. The maximum alert interval is 600 seconds, and the minimum alert interval is 5 seconds.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval_l_outlookalertintervalspinid","displayName":"(5 - 600 seconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookmemoryalertthreshold","displayName":"Specify Outlook memory alert threshold for web extensions (User)","description":"This policy setting allows you to specify the memory usage limit Outlook uses before disabling a web extension during initialization. The memory alert threshold controls the maximum amount of virtual memory that can be used by a running web extension.\r\n\r\nIf you enable this policy setting, you can specify the memory alert threshold for web extensions. If the web extension requires more than the specified memory alert threshold when a memory or CPU check occurs, Outlook disables the web extension.\r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default memory usage limit of 1500 MB. This memory alert threshold overrides the WEF memory alert threshold. The maximum memory alert threshold is 1500 MB, and the minimum memory alert threshold is 1 MB.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookmemoryalertthreshold_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookmemoryalertthreshold_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookmemoryalertthreshold_l_outlookmemoryalertthresholdspinid","displayName":"(1 - 1500 MB) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookrestartmanagerretrylimit","displayName":"Specify the number of restarts attempted for a running web extension (User)","description":"This policy setting allows you to specify the number of restarts Outlook attempts for a running web extension.\r\n\r\nIf you enable this policy setting, you can specify the number of restarts Outlook attempts for a running web extension. If the web extension requires more than the specified number of restarts during an Outlook session, Outlook disables the web extension.\r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default restart limit of 3 occurrences. The maximum restart limit is 10 occurrences, and the minimum restart limit is 1 occurrence.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookrestartmanagerretrylimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookrestartmanagerretrylimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookrestartmanagerretrylimit_l_outlookrestartmanagerretrylimitspinid","displayName":"(1 - 10 occurrences) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook","displayName":"Security setting for macros (User) (Deprecated)","description":"This policy setting controls the security level for macros in Outlook. \r\n\r\nIf you enable this policy setting, you can choose from four options for handling macros in Outlook: \r\n\r\n- Always warn. This option corresponds to the \"Warnings for all macros\" option in the \"Macro Security\" section of the Outlook Trust Center. Outlook disables all macros that are not opened from a trusted location, even if the macros are signed by a trusted publisher. For each disabled macro, Outlook displays a security alert dialog box with information about the macro and its digital signature (if present), and allows users to enable the macro or leave it disabled. \r\n\r\n- Never warn, disable all. This option corresponds to the \"No warnings and disable all macros\" option in the Trust Center. Outlook disables all macros that are not opened from trusted locations, and does not notify users. \r\n\r\n- Warning for signed, disable unsigned. This option corresponds to the \"Warnings for signed macros; all unsigned macros are disabled\" option in the Trust Center. Outlook handles macros as follows: \r\n\r\n--If a macro is digitally signed by a trusted publisher, the macro can run if the user has already trusted the publisher. \r\n\r\n--If a macro has a valid signature from a publisher that the user has not trusted, the security alert dialog box for the macro lets the user choose whether to enable the macro for the current session, disable the macro for the current session, or to add the publisher to the Trusted Publishers list so that it will run without prompting the user in the future. \r\n\r\n--If a macro does not have a valid signature, Outlook disables it without prompting the user, unless it is opened from a trusted location. \r\n\r\nThis option is the default configuration in Outlook. \r\n\r\n- No security check. This option corresponds to the \"No security check for macros (Not recommended)\" option in the Trust Center. Outlook runs all macros without prompting users. This configuration makes users' computers vulnerable to potentially malicious code and is not recommended. \r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of Enabled -- Warning for signed, disable unsigned.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel","displayName":"Security Level (User) (Deprecated)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_2","displayName":"Always warn","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_4","displayName":"Never warn, disable all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_3","displayName":"Warn for signed, disable unsigned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_1","displayName":"No security check","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2","displayName":"Security setting for macros (User)","description":"This policy setting controls the security level for macros in Outlook. \r\n\r\nIf you enable this policy setting, you can choose from four options for handling macros in Outlook: \r\n\r\n- Always warn. This option corresponds to the \"Warnings for all macros\" option in the \"Macro Security\" section of the Outlook Trust Center. Outlook disables all macros that are not opened from a trusted location, even if the macros are signed by a trusted publisher. For each disabled macro, Outlook displays a security alert dialog box with information about the macro and its digital signature (if present), and allows users to enable the macro or leave it disabled. \r\n\r\n- Never warn, disable all. This option corresponds to the \"No warnings and disable all macros\" option in the Trust Center. Outlook disables all macros that are not opened from trusted locations, and does not notify users. \r\n\r\n- Warning for signed, disable unsigned. This option corresponds to the \"Warnings for signed macros; all unsigned macros are disabled\" option in the Trust Center. Outlook handles macros as follows: \r\n\r\n--If a macro is digitally signed by a trusted publisher, the macro can run if the user has already trusted the publisher. \r\n\r\n--If a macro has a valid signature from a publisher that the user has not trusted, the security alert dialog box for the macro lets the user choose whether to enable the macro for the current session, disable the macro for the current session, or to add the publisher to the Trusted Publishers list so that it will run without prompting the user in the future. \r\n\r\n--If a macro does not have a valid signature, Outlook disables it without prompting the user, unless it is opened from a trusted location. \r\n\r\nThis option is the default configuration in Outlook. \r\n\r\n- No security check. This option corresponds to the \"No security check for macros (Not recommended)\" option in the Trust Center. Outlook runs all macros without prompting users. This configuration makes users' computers vulnerable to potentially malicious code and is not recommended. \r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of Enabled -- Warning for signed, disable unsigned.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel","displayName":"Security Level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_2","displayName":"Always warn","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_4","displayName":"Never warn, disable all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_3","displayName":"Warn for signed, disable unsigned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_1","displayName":"No security check","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_preventsavingcredentialsforbasicauthenticationpolicy","displayName":"Prevent saving credentials for Basic Authentication policy (User)","description":"This policy setting allows you to prevent Outlook from saving user credentials using Basic Authentication.\r\n\r\nIf you enable this policy setting, Outlook will not save user credentials using Basic Authentication.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will allow the user to save credentials when using Basic Authentication against a server. These credentials are stored as generic and retrievable by any process running with that user's rights on the machine.","helpText":"","infoUrls":[],"categoryId":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_preventsavingcredentialsforbasicauthenticationpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_preventsavingcredentialsforbasicauthenticationpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_specifyofflineaddressbookpath","displayName":"Specify Offline Address Book path (User)","description":"This policy setting allows you to specify a path to save the Offline Address Book. This policy setting will apply to all Microsoft Exchange accounts.\r\n\r\nIf you enable this policy setting, you may specify a path to save the Offline Address Book.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will save the Offline Address Book in %LOCALAPPDATA%\\Microsoft\\Outlook.","helpText":"","infoUrls":[],"categoryId":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_specifyofflineaddressbookpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_specifyofflineaddressbookpath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_specifyofflineaddressbookpath_l_specifyofflineaddressbookpathid","displayName":"Offline Address Book path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","categoryName":"E-mail","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency","displayName":"EAS Sync Frequency (User)","description":"This policy setting allows you to specify the number of minutes that Outlook automatically syncs the users' Exchange ActiveSync (EAS) accounts.\r\n\r\nIf you enable this policy setting, you can specify the number of minutes.\r\n\r\nIf you disable or do not configure this policy setting, Outlook automatically syncs the users’ EAS accounts every 59 minutes.","helpText":"","infoUrls":[],"categoryId":"b161cf66-abfa-4a36-a9ac-c20ca60594e0","categoryName":"Exchange ActiveSync","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency_l_eassyncfrequencyintervalspinid","displayName":"Synchronization interval (in minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b161cf66-abfa-4a36-a9ac-c20ca60594e0","categoryName":"Exchange ActiveSync","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_automaticallyconfigureprofilebasedonactive","displayName":"Automatically configure profile based on Active Directory Primary SMTP address (User)","description":"Automatically configure only the first profile based on Active Directory primary SMTP address\r\n\r\nThis policy setting controls whether users who are joined to a domain in an Active Directory environment can change the primary SMTP address that is used when they set up an account in Outlook.\r\n\r\nIf this policy setting is enabled, users can enter a profile name to create a new profile without using the new account wizard. A user interface does not appear as the profile is created.\r\n\r\nThis key will be ignored after the first profile has been successfully created.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_automaticallyconfigureprofilebasedonactive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_automaticallyconfigureprofilebasedonactive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_automaticallyconfigureprofilebasedonactiveonce","displayName":"Automatically configure only the first profile based on Active Directory primary SMTP address (User)","description":"Automatically configure profile based on Active Directory Primary SMTP address once\r\n\r\nThis policy setting controls whether users who are joined to a domain in an Active Directory environment can change the primary SMTP address that is used when they set up accounts in Outlook.\r\n\r\nIf this policy setting is enabled, users can create a new profile by entering a profile name. The profile is created without using the New Account wizard. No user interface appears as the profile is created. \r\n\r\nThis key will be ignored after the first profile has been successfully created.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_automaticallyconfigureprofilebasedonactiveonce_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_automaticallyconfigureprofilebasedonactiveonce_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold","displayName":"Cached Exchange low bandwidth threshold (User)","description":"Specifies the bit rate threshold value. If the bit rate of the active network connection is below this value, Outlook identifies the network connection as a \"slow\" connection and operates accordingly (for example, downloading headers instead of full messages).","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold_l_enterthebitratekbps128k128thresholdtodetectlowbandwidth2","displayName":"(0 - 1,000,000 kbps) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablechangingfolderpermissions","displayName":"Do not allow users to change permissions on folders (User)","description":"This policy setting prevents users from changing their mail folder permissions. \r\n\r\nIf you enable this policy setting, Outlook users cannot change permissions on folders; the settings on the Permissions tab are disabled. Enabling this policy setting does not affect existing permissions, and users can still change permissions by sending a sharing message.\r\n\r\nIf you disable or do not configure this policy setting, Outlook users can change the permissions for folders under their control by using the Permissions tab of the Properties dialog box for the folder.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablechangingfolderpermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablechangingfolderpermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disableexchangeconsumeraccounts","displayName":"Prevent personal Microsoft accounts from using MAPI (User)","description":"This policy setting governs whether personal Microsoft accounts can be configured to use MAPI in Outlook.\r\n\r\nA personal Microsoft account is an account hosted on Outlook.com, Hotmail.com, Live.com, Msn.com or any variation on those domains.\r\n\r\nIf you enable this policy, users won’t be able to configure a personal Microsoft account to use MAPI in Outlook.\r\n\r\nThis means that in the Add Account dialog box in Outlook, users must choose “Manual setup or additional server types,” then choose Next, and then choose “POP or IMAP.”\r\n\r\nIf you disable or don’t configure this policy setting, users can configure a personal Microsoft account to use MAPI in Outlook. They can do this by choosing “E-mail” account in the Add Account dialog box.\r\n\r\nNote that personal Microsoft accounts that are configured to use MAPI will be automatically configured to use Cached Exchange Mode, and this can’t be changed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disableexchangeconsumeraccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disableexchangeconsumeraccounts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablerpctransportfallback","displayName":"Disable connection fallback between protocols (User)","description":"This policy setting allows you to control the connection transport fallback behavior in Outlook when it attempts to connect to a Microsoft Exchange Server.\r\n \r\nThis policy setting applies if you are using Outlook Anywhere (RPC over HTTP) to connect to a Microsoft Exchange Server. There are two Outlook profile settings on the Microsoft Exchange Proxy Settings dialog box (accessed through the Control Panel or Account Settings), that configure the default connection transport fallback behavior.\r\n \r\n- On fast networks, connect using HTTP first, then connect using TCP/IP\r\n- On slow networks, connect using HTTP first, then connect using TCP/IP\r\n \r\nFor example, if you are on a fast network and you enable the “On fast networks, connect using HTTP first, then connect using TCP/IP” setting in the Microsoft Exchange Proxy Settings dialog box, Outlook first attempts to connect to the Exchange Server using HTTP. If Outlook is unable to connect using HTTP, then it attempts to connect using TCP/IP.\r\n \r\nIf you enable this policy setting, if Outlook connection attempts with Microsoft Exchange Server fail, Outlook does not fallback to the TCP/IP protocol, regardless of what is specified in the Microsoft Exchange Proxy Settings dialog box. \r\n\r\nIf you disable or do not configure this policy setting, Outlook connection attempts with Microsoft Exchange Server can fallback from either TCP/IP to HTTP, or HTTP to TCP/IP, depending on the settings specified in the Microsoft Exchange Proxy Settings dialog box.\r\n","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablerpctransportfallback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablerpctransportfallback_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_donotcreatenewostonupgrade","displayName":"Do not create new OST file on upgrade (User)","description":"This policy setting controls whether Outlook creates a new OST file when you upgrade to Outlook 2016. The new OST file uses less space on the disk. When a new OST file is created, the contents from the previous version of Outlook are downloaded from the Exchange Server.\r\n\r\nIf you enable this policy setting, Outlook continues to use the existing OST file created by the installed earlier version of Outlook. \r\n\r\nIf you disable or do not configure this policy setting, when you upgrade to Outlook 2016, a new OST file is created, and the contents from the installed earlier version of Outlook are downloaded from the Exchange server.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_donotcreatenewostonupgrade_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_donotcreatenewostonupgrade_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface","displayName":"Configure Outlook Anywhere user interface options (User)","description":"This policy setting allows you to determine whether users can view and change user interface (UI) options for Outlook Anywhere.\r\n\r\nIf you enable this policy setting, users can view and change UI options for Outlook Anywhere.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to use the Outlook Anywhere feature, but they will not be able to view or change UI options for it.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_l_chooseuistatewhenoscansupportfeature","displayName":"Choose UI State when OS can support feature: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_l_chooseuistatewhenoscansupportfeature_0","displayName":"Hidden","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_l_chooseuistatewhenoscansupportfeature_1","displayName":"All config UI enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_l_chooseuistatewhenoscansupportfeature_2","displayName":"Enable only On/Off control but not config UI","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_l_chooseuistatewhenoscansupportfeature_3","displayName":"Enable config UI when settings are pre-deployed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_l_chooseuistatewhenoscansupportfeature_4","displayName":"Disable but show all config UI","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption","displayName":"Enable RPC encryption (User) (Deprecated)","description":"This policy setting controls whether Outlook uses remote procedure call (RPC) encryption to communicate with Microsoft Exchange servers. \r\n\r\nIf you enable this policy setting, Outlook uses RPC encryption when communicating with an Exchange server. Note - RPC encryption only encrypts the data from the Outlook client computer to the Exchange server. It does not encrypt the messages themselves as they traverse the Internet. \r\n\r\nIf you disable or do not configure this policy setting, RPC encryption is still used by default. This setting allows you to override the corresponding per-profile setting.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_v2","displayName":"Enable RPC encryption (User)","description":"This policy setting controls whether Outlook uses remote procedure call (RPC) encryption to communicate with Microsoft Exchange servers. \r\n\r\nIf you enable this policy setting, Outlook uses RPC encryption when communicating with an Exchange server. Note - RPC encryption only encrypts the data from the Outlook client computer to the Exchange server. It does not encrypt the messages themselves as they traverse the Internet. \r\n\r\nIf you disable or do not configure this policy setting, RPC encryption is still used by default. This setting allows you to override the corresponding per-profile setting.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat","displayName":"Exchange Unicode Mode - Ignore OST Format (User)","description":"This policy setting allows you to specify whether existing OST format determines the mailbox mode.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n* OST Format determines mode: the format of the user's OST file will be used to determine whether to run in Unicode or ANSI mode.\r\n* Create new OST if format doesn't match mode: create a new OST file if needed.\r\n* Prompt to create new OST if format doesn't match mode\r\n\r\nIf you disable or do not configure this policy setting, you will not be able to specify whether existing OST format determines the mailbox mode.\r\n\r\nThis policy is ignored if PreferANSI is not set and the OST is enabled but either does not exist or is a Unicode OST, because it would be impossible for the user to create an ANSI OST.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_l_choosewhetherexistingostformatdeterminesmailboxmode","displayName":"Choose whether existing OST format determines mailbox mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_l_choosewhetherexistingostformatdeterminesmailboxmode_0","displayName":"OST Format determines mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_l_choosewhetherexistingostformatdeterminesmailboxmode_1","displayName":"Create new OST if format doesn't match mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_l_choosewhetherexistingostformatdeterminesmailboxmode_2","displayName":"Prompt to create new OST if format doesn't match mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodesilentostformatchange","displayName":"Exchange Unicode Mode - Silent OST format change (User)","description":"This policy setting allows .OST files to silently update to Unicode format from ANSI.\r\n\r\nIf you enable this policy setting, it will only have meaning if the related policy setting \"Exchange Unicode Mode - Ignore OST format\" is enabled and set to the options listed below.\r\n\r\nThe behavior is as follows -\r\n\r\n\"Ignore OST Format\" policy setting is enabled and set to \"Create new OST if format doesn't match mode\"; \"Silent OST Format Change\" policy setting is enabled:\r\nIf Outlook detects a mode that is different than the current .OST mode, then a new .OST is created without prompting the user.\r\n\r\n\"Ignore OST Format\" policy setting is enabled and set to \"Prompt to create new OST if format doesn't match mode\"; \"Silent OST Format Change\" policy setting is enabled:\r\nIf Outlook detects a mode that is different than the current .OST mode, the user is prompted to allow a delay in the conversion to the mode set by policy. By clicking Ok, a new OST is created without a prompt for a new .OST name.\r\n\r\nIf you disable or do not configure this policy setting, users will be prompted to enter a new name for the updated .OST file.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodesilentostformatchange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodesilentostformatchange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeturnoffansi","displayName":"Exchange Unicode Mode - Turn off ANSI mode (User)","description":"This policy setting controls the creation of ANSI OST files.\r\n\r\nIf you enable or do not configure this policy setting, new ANSI OST files cannot be created.\r\n\r\nIf you disable this policy setting, all new OST files for an Outlook profile are created in ANSI format.\r\n\r\nProfiles with multiple Exchange accounts will always create Unicode OST files, regardless of this policy setting.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeturnoffansi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeturnoffansi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_foldersizedisplay","displayName":"Do not display Folder Size button on folder properties dialog box (User)","description":"Retains/Removes the \"Folder Size\" button in the General tab of the Properties dialog box.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_foldersizedisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_foldersizedisplay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_ostcreation","displayName":"Do not allow an OST file to be created (User)","description":"Prevents offline folder use at startup. This is equivalent to clicking the Disable Offline Use button in the Offline Folder Settings dialog box.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_ostcreation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_ostcreation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover","displayName":"Disable AutoDiscover (User)","description":"This policy setting allows you to disable AutoDiscover.\r\n\r\nIf you enable this policy setting, you can select one or more of the following options to disable in the AutoDiscover feature.\r\n\r\n\"Exclude the last known good URL” – Outlook does not use the last known good Autodiscover URL.\r\n\r\n\"Exclude the SCP object lookup\" – Outlook does not perform Active Directory queries for Service Connection Point (SCP) objects with Autodiscover information.\r\n\r\n\"Exclude the root domain query based on your primary SMTP address\" - Outlook does not use the root domain of your primary SMTP address to locate the AutoDiscover service. For example, you select this optionOutlook does not use the following URL: https:///autodiscover/autodiscover.xml.\r\n\r\n\"Exclude the query for the AutoDiscover domain\" - Outlook does not use the Autodiscover domain to locate the Autodiscover service. For example, Outlook does not use the following URL: https://autodiscover./autodiscover/autodiscover.xml\r\n\r\n\"Exclude the HTTP redirect method\" - Outlook does not use the HTTP redirect method in the event it is unable to reach the AutoDiscover service via either of the HTTPS URLs: https:///autodiscover/autodiscover.xml or https://autodiscover./autodiscover/autodiscover.xml.\r\n\r\n\"Exclude the SRV record query in DNS\" - Outlook does not use an SRV record lookup in DNS to locate the AutoDiscover service.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverautodiscoversubdomain","displayName":"Exclude the query for the AutoDiscover domain (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverautodiscoversubdomain_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverautodiscoversubdomain_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverhttpredirect","displayName":"Exclude the HTTP redirect method (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverhttpredirect_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverhttpredirect_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverlkgurl","displayName":"Exclude the last known goode URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverlkgurl_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverlkgurl_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverrootdomain","displayName":"Exclude the root domain query based on your primary SMTP address (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverrootdomain_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverrootdomain_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverscplookup","displayName":"Exclude the SCP object lookup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverscplookup_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverscplookup_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoversrvrecord","displayName":"Exclude the SRV record query in DNS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoversrvrecord_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoversrvrecord_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_personaldistributionlistsexchangeonly","displayName":"Do not validate personal Contact Groups when sending e-mail messages (User)","description":"Use only the local cache to obtain current user information when expanding a Personal Contact Group while sending e-mail","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_personaldistributionlistsexchangeonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_personaldistributionlistsexchangeonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts","displayName":"Prevent copying or moving items between accounts (User)","description":"This policy setting allows you to prevent items from being copied or moved to other accounts or PSTs.\r\n\r\nIf you enable this policy setting, items will be prevented from being moved or copied to other accounts or PSTs. Enter one of the following details:\r\n\r\n- \"Contoso.com\": prevents copying or moving from the account corresponding to the listed domain\r\n- \"*\": prevents copying from all accounts and PST's\r\n- \"SharePoint\": prevents copies or moves from the SharePoint PST\r\n\r\nIf you disable or do not configure this policy setting, copying or moving items between accounts or PSTs is allowed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts_l_preventcopyingormovingitemsbetweenaccountsid","displayName":"SMTP address domain (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventnondefaultexchangeaccounts","displayName":"Prevent adding non-default Exchange accounts (User)","description":"This policy allows you to prevent users from adding non-default Exchange accounts to existing Outlook profiles.\r\n\r\nIf you enable this policy setting, you will prevent users from adding non-default Exchange accounts via the Add New E-mail Account wizard.\r\n\r\nIf you disable or do not configure this policy setting, users can add non-default Exchange accounts to existing Outlook profiles.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventnondefaultexchangeaccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventnondefaultexchangeaccounts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags","displayName":"RPC/HTTP Connection Flags (User)","description":"This policy setting configures connection options for Outlook Anywhere. \r\n\r\nIf you enable this policy setting, you can configure multiple connection options by selecting the flag in the drop down menu that contains the combination of settings you need. The following flags are available: \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the settings specified in Autodiscover.\r\n\r\nFlag 1: Enables the 'Connect to Microsoft Exchange using HTTP checkbox' on the Connection tab. \r\n\r\nThe following flags configure options in the Microsoft Exchange Proxy Settings dialog box: \r\n\r\nFlag 2: Enables the 'Connect using SSL only' checkbox \r\nFlag 3: Enables the 'Only connect to proxy servers that have this principal name in their certificate' checkbox \r\nFlag 4: Enables the 'On fast networks, connect using HTTP first, then connect using TCP/IP' checkbox \r\nFlag 5: Enables the 'On slow networks, connect using HTTP first, then connect using TCP/IP' checkbox \r\n","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags","displayName":"Select a combination of RPC/HTTP connection flags (see Explain tab for details): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_0","displayName":"No Flags","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_47","displayName":"Flags: 1 + 2 + 3 + 4 + 5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_39","displayName":"Flags: 1 + 2 + 3 + 5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_43","displayName":"Flags: 1 + 2 + 4 + 5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_35","displayName":"Flags: 1 + 2 + 5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_41","displayName":"Flags: 1 + 4 + 5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_33","displayName":"Flags: 1 + 5","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting","displayName":"RPC Proxy Authentication Setting (User)","description":"This policy setting determines the RPC proxy authentication setting for Outlook Anywhere.\r\n \r\nIf you enable this policy setting, you can specify the proxy authentication setting that Outlook uses, and this overrides any proxy authentication setting specified in Autodiscover.\r\n\r\nIf you do not configure this policy setting Outlook uses the proxy server authentication specified in Autodiscover.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_l_selectrpcproxyauthentication","displayName":"Authentication used to connect with the proxy server: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_l_selectrpcproxyauthentication_1","displayName":"Basic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_l_selectrpcproxyauthentication_2","displayName":"NTLM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_l_selectrpcproxyauthentication_16","displayName":"Negotiate","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_l_selectrpcproxyauthentication_65536","displayName":"Certificate","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyservername","displayName":"RPC Proxy Server Name (User)","description":"This policy setting determines the RPC proxy server that Outlook Anywhere uses when connecting to Exchange.\r\n \r\nIf you enable this policy setting, Outlook uses only the RPC proxy server that you specify when connecting to Exchange. It ignores the proxy server specified in Autodiscover.\r\n\r\nIf you disable or do not configure this policy setting Outlook uses the RPC proxy server that is specified in Autodiscover.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyservername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyservername_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyservername_l_rpcproxyservernametextid","displayName":"Specify the proxy server name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyserverprincipalname","displayName":"Only connect if Proxy Server certificate has this principal name (User)","description":"This policy setting specifies the required certificate principal name for the RPC proxy server for Outlook Anywhere. \r\n\r\nIf you enable this policy setting, you must enter a server principal name. You must precede the server name with \"msstd:\" for this configuration to work. For example, you would enter the following text if the server principal name is mail.fourthcoffee.com: \r\n\r\nmsstd:mail.fourthcoffee.com \r\n\r\nIf you disable or do not configure this setting, Outlook uses the certificate principal name that is specified in Autodiscover.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyserverprincipalname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyserverprincipalname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyserverprincipalname_l_rpcproxyserverprincipalnametextid","displayName":"Specify the proxy server principal name (see Explain tab for details): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_setmaximumnumberofexchangeaccounts","displayName":"Set maximum number of Exchange accounts per profile (User)","description":"This policy setting allows you to set the maximum number of Exchange accounts allowed per Outlook profile.\r\n\r\nIf you enable this policy setting, you will be able to set the maximum number of Exchange accounts allowed per Outlook profile.\r\n\r\nIf you disable or do not configure this policy setting, the default maximum number of Exchange accounts allowed per Outlook profile is 10.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_setmaximumnumberofexchangeaccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_setmaximumnumberofexchangeaccounts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_setmaximumnumberofexchangeaccounts_l_setmaximumnumberofexchangeaccountsspinid","displayName":"Number of Accounts: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders","displayName":"Synchronizing data in shared folders (User)","description":"This setting controls the number of days that elapses without a user accessing an Outlook folder before Outlook stops synchronizing the folder with Exchange. For example, say this option is set to 45. User A opens User B's calendar in Outlook, and then does not click on it again for 45 days. Outlook stops synchronizing the data with Exchange and the calendar is no longer up-to-date. The local copy of the data is removed from the OST file. If User A then clicks on the User B calendar 90 days later, Outlook synchronizes the calendar data and starts the clock again for 45 days.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders_l_numberofdays","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbook","displayName":"Turn off Hierarchical Address Book (User)","description":"This policy setting turns off the Hierarchical Address Book (HAB).\r\n\r\nIf you enable this policy setting, the HAB will be turned off. \r\n\r\nIf you disable or do not configure this policy setting, the HAB will be displayed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbookdepartmentselection","displayName":"Turn off Hierarchical Address Book department selection (User)","description":"This policy setting controls whether departments can be picked as recipients in the Hierarchical Address Book (HAB).\r\n\r\nIf you enable this policy setting, the tree control to pick departments as recipients is turned off in the HAB.\r\n\r\nIf you disable or do not configure this policy setting, the tree control to pick departments as recipients is turned on in the HAB.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbookdepartmentselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbookdepartmentselection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbooksearch","displayName":"Turn off Hierarchical Address Book search (User)","description":"This policy setting controls entry points to search in the Hierarchical Address Book (HAB).\r\n\r\nIf you enable this policy setting, all entry points to search features in the HAB will be turned off. \r\n\r\nIf you disable or do not configure this policy setting, all entry points to search features in the HAB will be enabled.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbooksearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbooksearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_uselegacyoutlookauthenticationdialogs","displayName":"Use legacy Change Password authentication dialog boxes (User)","description":"By default, Outlook displays the Windows authentication dialog box when users are prompted to change their passwords. By enabling this setting, you can change this behavior so that older-style Outlook dialog boxes that include the Change Password button are displayed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_uselegacyoutlookauthenticationdialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_uselegacyoutlookauthenticationdialogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode","displayName":"Cached Exchange Mode (File | Cached Exchange Mode) (User)","description":"Specifies the default Cached Exchange Mode for new profiles and disables the download options in the Cached Exchange Mode command submenu in the File menu.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles","displayName":"Select Cached Exchange Mode for new profiles (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles_1","displayName":"Download Headers","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles_2","displayName":"Download Full Items","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles_3","displayName":"Download Headers and then Full Items","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_configurecachedexchangemode","displayName":"Use Cached Exchange Mode for new and existing Outlook profiles (User)","description":"By default, users can choose to configure Cached Exchange Mode or use Online mode. By enabling this setting, new and existing Outlook profiles are configured to use Cached Exchange Mode. Disabling this setting configures new and existing Outlook profiles to use Online mode.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_configurecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_configurecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadfullitemsfilecachedexchangemode","displayName":"Disallow Download Full Items (User)","description":"This policy setting allows you to turn off the \"Download Full Items\" option.\r\n\r\nIf you enable this policy setting, you will turn off the \"Download Full Items\" option in the Download Preferences menu in the Send/Receive tab.\r\n\r\nIf you disable or do not configure this policy setting, you will allow the \"Download Full Items\" option in the Download Preferences menu in the Send/Receive tab.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadfullitemsfilecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadfullitemsfilecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadheadersfilecachedexchangemode","displayName":"Disallow Download Headers (User)","description":"Disables/Enables the option \"Download Headers\" in the Server group of the Send/Receive tab.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadheadersfilecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadheadersfilecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadheadersthenfullitemsfilecachedexchangemode","displayName":"Disallow Download Headers then Full Items (User)","description":"This policy setting allows you to turn off the \"Download Headers and then Full Items\" option. Microsoft Exchange Server 2003 or later is required.\r\n\r\nIf you enable this policy setting, you will turn off the \"Download Headers and then Full Items\" option in the Download Preferences menu in the Send/Receive tab.\r\n\r\nIf you disable or do not configure this policy setting, you will allow the \"Download Headers and then Full Items\" option in the Download Preferences menu in the Send/Receive tab.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadheadersthenfullitemsfilecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadheadersthenfullitemsfilecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowonslowconnectionsonlydownloadheadersfilecachedexchan","displayName":"Disallow On Slow Connections Only Download Headers (User)","description":"This policy setting allows you to turn off the \"On Slow Connections Download Only Headers\" option.\r\n\r\nIf you enable this policy setting, you will turn off the \"On Slow Connections Download Only Headers\" option in the Download Preferences menu in the Send/Receive tab.\r\n\r\nIf you disable or do not configure this policy setting, you will allow the \"On Slow Connections Download Only Headers\" option in the Download Preferences menu in the Send/Receive tab.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowonslowconnectionsonlydownloadheadersfilecachedexchan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowonslowconnectionsonlydownloadheadersfilecachedexchan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_downloadpublicfolderfavorites","displayName":"Download Public Folder Favorites (User)","description":"Checked: Checks the \"Download Public Folder Favorites\" option in the Advanced tab of the Microsoft Exchange Server dialog box (More Settings button in the E-mail Accounts dialog box) and enables the option. This enables Public Folder Favorites synchronization in Cached Exchange mode. | Unchecked: Unchecks the \"Download Public Folder Favorites\" option in the Advanced tab of the Microsoft Exchange Server dialog box (More Settings button in the E-mail Accounts dialog box) and disables the option. This disables Public Folder Favorites synchronization in Cached Exchange mode.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_downloadpublicfolderfavorites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_downloadpublicfolderfavorites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_downloadshardnonmailfolders","displayName":"Download shared non-mail folders (User)","description":"By default, most shared folders that users access in other mailboxes are automatically downloaded and cached in the users' local OST files when Cached Exchange Mode is enabled. Only shared Mail folders are not cached. You can use this setting to change this behavior so that non-mail folders are not downloaded automatically.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_downloadshardnonmailfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_downloadshardnonmailfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entermaximumsecondstowaittosyncchanges","displayName":"Enter maximum seconds to wait to sync changes (User)","description":"Specifies maximum number of seconds to wait before synchronizing changes with the Exchange server.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entermaximumsecondstowaittosyncchanges_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entermaximumsecondstowaittosyncchanges_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entermaximumsecondstowaittosyncchanges_l_entersecondstowaitbeforesyncdefault60sec","displayName":"Enter seconds to wait before sync(Default 60 sec.) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver","displayName":"Enter seconds to wait to download changes from server (User)","description":"Specifies number of seconds to wait before downloading changes from the Exchange server.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver_l_entersecondstowaitbeforedownloaddefault30sec","displayName":"Enter seconds to wait before download(Default 30 sec.) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittouploadchangestoserver","displayName":"Enter seconds to wait to upload changes to server (User)","description":"Specifies number of seconds to wait before uploading changes to the Exchange server.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittouploadchangestoserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittouploadchangestoserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittouploadchangestoserver_l_entersecondstowaitbeforeuploaddefault15sec","displayName":"Enter seconds to wait before upload(Default 15 sec.) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_hybridmode","displayName":"Disable Exchange Fast Access (User)","description":"This policy setting allows you to disable Exchange Fast Access, which forces user accounts to access data from a local cache.\r\n\r\nIf you enable this policy setting, Exchange Fast Access is not available to any Exchange Accounts on a computer.\r\n\r\nIf you disable or do not configure this policy setting, Exchange Fast Access is turned on by default for Exchange Accounts in Cached Exchange Mode.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_hybridmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_hybridmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_incachedexchangemakesendreceivef9nulloperation","displayName":"Do not sync in Cached Exchange mode when users click Send/Receive or F9 (User)","description":"By default, when users click Send/Receive or press F9 for Cached Exchange Mode accounts, Outlook synchronizes with the Exchange server. When this setting is enabled, clicking Send/Receive and pressing F9 do not synchronize with Exchange unless only one folder is being synchronized. Users can continue to use shift-F9 to synchronize the current folder.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_incachedexchangemakesendreceivef9nulloperation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_incachedexchangemakesendreceivef9nulloperation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_includeonlinemodegalinanr","displayName":"Use the Online Global Address List for Nickname Resolution (User)","description":"This policy setting allows you to force Outlook to use the Online Global Address List for ambiguous name resolution when composing messages in Outlook, instead of using the Offline Address Book when it is available.\r\n\r\nIf you enable this policy setting, addresses are resolved using the Online Global Address List, which may contain additional information (that the Offline Address Book would not have) that allows an address to be resolved.\r\n\r\nIf you disable or do not configure this policy setting, Outlook resolves addresses using the Offline Address Book when it is available.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_includeonlinemodegalinanr_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_includeonlinemodegalinanr_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbookexactaliasmatching","displayName":"Return e-mail alias if it exactly matches the provided e-mail address when searching OAB (User)","description":"By default, when searching the Offline Address Book, Outlook resolves e-mail addresses using Ambiguous Name Resolution. With Ambiguous Name Resolution, Outlook suggests additional possible matches (if they exist) even if there is a name that matches exactly the e-mail alias entered. By enabling this setting, you can change the behavior so that Outlook returns a single e-mail address if it exactly matches an e-mail alias.","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbookexactaliasmatching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbookexactaliasmatching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads","displayName":"Offline Address Book: Limit manual OAB downloads (User)","description":"This policy setting allows you to specify the number of manual downloads of the offline address book (OAB) allowed in a 13 hour period.\r\n\r\nIf you enable this policy setting, you may specify the number of manual downloads of the offline address book (OAB) allowed in a 13 hour period. If you set the value to 0, then no manual OAB downloads are allowed. If you set the value to the maximum of 65535, then that will allow an unlimited number of manual downloads of the OAB.\r\n\r\nIf you disable or do not configure this policy setting, an unlimited number of manual downloads of the OAB will be allowed.","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads_l_allowxxmanualoabdownloadsper13hrperiod","displayName":"Upper limit of number of manual OAB downloads per 13 hour period (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitnumberofincrementaloabdownloads","displayName":"Offline Address Book: Limit number of incremental OAB downloads (User)","description":"This policy setting allows you to specify the number of incremental download attempts of the offline address book (OAB) allowed in a 13 hour period.\r\n\r\nIf you enable this policy setting, you may specify the number of incremental download attempts of the offline address book (OAB) allowed in a 13 hour period. If you set the value to 0, then no incremental download attempts are allowed. If you set the value to the maximum of 65535, then that will allow an unlimited number of incremental OAB download attempts.\r\n\r\nIf you disable or do not configure this policy setting, an unlimited number of incremental OAB download attempts of the OAB will be allowed.","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitnumberofincrementaloabdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitnumberofincrementaloabdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitnumberofincrementaloabdownloads_l_allowxxincrementaloabdownloadsper13hrperiod","displayName":"Allow xx incremental OAB downloads per 13hr period (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbookpromptbeforedownloadingfulloab","displayName":"Offline Address Book: Prompt before Downloading Full OAB (User)","description":"Specifies that the user is asked for permission before initiating a full download of the offline address book.","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbookpromptbeforedownloadingfulloab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbookpromptbeforedownloadingfulloab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_imap_l_turnonpurgewhenswitchingfolders","displayName":"Turn on purge when switching folders (User)","description":"When \"purge on switch\" is enabled, IMAP e-mail messages marked for deletion in the current folder will be permanently removed from the server when the user switches to another folder. This setting will allow you to enable the IMAP \"purge on switch\" feature.","helpText":"","infoUrls":[],"categoryId":"63ca5d8b-829d-42c5-92e8-35f9ca47fb0e","categoryName":"IMAP","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_imap_l_turnonpurgewhenswitchingfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_imap_l_turnonpurgewhenswitchingfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_automaticallydownloadenclosures","displayName":"Automatically download enclosures (User)","description":"This policy setting allows you to control whether Outlook automatically downloads enclosures on RSS items.\r\n\r\nIf you enable this policy setting, Outlook will automatically download enclosures on RSS items.\r\n\r\nIf you disable or do not configure this policy setting, enclosures on RSS items are not downloaded by default.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_automaticallydownloadenclosures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_automaticallydownloadenclosures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_defaultrssfeeds","displayName":"Default RSS Feeds (User)","description":"This policy setting allows you to deploy default RSS Feeds by providing a list of URLs that point to content that is syndicated through RSS. Outlook reads the list when it starts, and the corresponding RSS Feeds are added to each of the user's profiles. By default, users are not subscribed to any RSS Feeds.\r\n\r\nIf you enable this policy setting, you may specify the URLs in the format: feed://, where \"feed://\" replaces \"http://\". This ensures that the URL is parsed as an RSS XML file in Outlook.\r\n\r\nIf you disable or do not configure this policy setting, users are not subscribed to any RSS Feeds.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_defaultrssfeeds_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_defaultrssfeeds_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_defaultrssfeeds_l_defaultrsssubscriptionspart","displayName":"List of default RSS Feeds (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_defaultrssfeeds_l_defaultrsssubscriptionspart_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_defaultrssfeeds_l_defaultrsssubscriptionspart_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_disableroamingofrsssubscriptions","displayName":"Do not roam users' RSS Feeds (User)","description":"This policy setting allows you to change the default delivery location of RSS Feeds to a local PST.\r\n\r\nIf you enable this setting, the default delivery location will be changed to a local PST. When RSS Feeds are delivered to a local PST, they will not roam from client to client and will only be available on the computer where the user originally subscribed to the RSS Feed.\r\n\r\nIf you disable or do not configure this policy setting, subscriptions to RSS Feeds are delivered to the user's mailbox and roam from client to client via Exchange. This setting does not affect RSS Feeds that were subscribed before the policy setting was enabled. This setting also does not prevent the user from manually directing an RSS Feed to deliver to the user's mailbox, which allows the RSS Feed to roam from client to client.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_disableroamingofrsssubscriptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_disableroamingofrsssubscriptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_downloadfulltextofarticles","displayName":"Download full text of articles as HTML attachments (User)","description":"This policy setting controls whether Outlook automatically makes an offline copy of the RSS items as HTML attachments.\r\n\r\nIf you enable this policy setting, Outlook automatically makes an offline copy of RSS items as HTML attachments. \r\n\r\nIf you disable or do not configure this policy setting, Outlook will not automatically make an offline copy of RSS items as HTML attachments.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_downloadfulltextofarticles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_downloadfulltextofarticles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_overridepublishedsyncinterval","displayName":"Override published sync interval (User)","description":"This policy setting allows you to ignore the synchronization interval specified by the RSS publisher. By default, Outlook follows the synchronization interval specified by the RSS publisher and RSS Feeds will not be synchronized more often than allowed by the RSS publisher. If Outlook does not follow the RSS publisher's synchronization interval, the RSS publisher may suspend Outlook from synchronizing the RSS Feed.\r\n\r\nIf you enable this policy setting, Outlook will always ignore the synchronization interval specified by the RSS publisher.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will always follow the synchronization interval specified by the RSS publisher.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_overridepublishedsyncinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_overridepublishedsyncinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_runrulesonrssitems","displayName":"Run rules on RSS items (User)","description":"By default, rules are not run on RSS items. Use this setting to make rules run on RSS items.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_runrulesonrssitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_runrulesonrssitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_synchronizeoutlookrssfeedswithcommonfeedlist","displayName":"Synchronize Outlook RSS Feeds with Common Feed List (User)","description":"This policy setting controls whether Outlook subscribes to the Common Feed List, which is made available to multiple RSS clients. The Common Feed List is a hierarchical set of RSS Feeds to which clients such as Outlook, the Feeds list in Internet Explorer 7, and the Feed Headlines Sidebar gadget in Windows Vista can subscribe. \r\n\r\nIf you enable this policy setting, Outlook automatically subscribes to RSS Feeds added in Internet Explorer, and Outlook RSS Feeds are synchronized with the Common Feed List so they are available in Internet Explorer. Be aware that third-party applications besides Internet Explorer can add RSS Feeds to the Common Feed List, and if you enable this setting Outlook automatically subscribes to those RSS Feeds as well. \r\n\r\nIf you disable or do not configure this policy setting, Outlook maintains its own list of RSS Feeds and does not automatically subscribe to RSS Feeds that are added to the Common Feed List.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_synchronizeoutlookrssfeedswithcommonfeedlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_synchronizeoutlookrssfeedswithcommonfeedlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_turnoffrssfeature","displayName":"Turn off RSS feature (User)","description":"This policy setting controls whether the RSS aggregation feature in Outlook is enabled. \r\n\r\nIf you enable this policy setting, the RSS aggregation feature in Outlook is disabled. \r\n\r\nIf you disable or do not configure this policy setting, users can subscribe to RSS Feeds from within Outlook and read RSS items like e-mail messages.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_turnoffrssfeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_turnoffrssfeature_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists","displayName":"Default SharePoint lists (User)","description":"This policy setting allows you to deploy SharePoint lists.\r\n\r\nIf you enable this policy setting, you can provide a list of SharePoint list URLs in the following format:\r\n\r\nValue name: SPsite1\r\nValue: SPsite1 stssync:// URL. See MS-STSSYN for documentation.\r\n\r\nValue name: SPSite2\r\nValue: SPsite2 stssync:// URL. See MS-STSSYN for documentation.\r\n\r\nThe list of URLs provided is read when Outlook starts up, and the corresponding SharePoint lists are added to each of the user's profiles.\r\n\r\nIf you disable or do not configure this policy setting, users will not have any default SharePoint lists.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists_l_empty35","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists_l_empty35_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists_l_empty35_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_definecustomlabelforsharepointstore","displayName":"Define custom label for SharePoint store (User)","description":"You can use this setting to define a custom label for the SharePoint Lists PST and most other places where the term \"SharePoint\" is used in Outlook. (Setting this value replaces the word \"SharePoint\" in Outlook strings with the value you specify.) A custom label might be particularly useful when deploying a third-party server that supports the same Microsoft SharePoint Foundation Web services Outlook uses for synchronization.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_definecustomlabelforsharepointstore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_definecustomlabelforsharepointstore_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_definecustomlabelforsharepointstore_l_definecustomlabelforsharepointstorepart","displayName":"Enter custom label for SharePoint store: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disableroamingofsharepointlists","displayName":"Do not roam users' SharePoint lists (User)","description":"By default, links to SharePoint lists are available on each client that the users use to connect to their Microsoft Exchange Server mailboxes. This setting allows you to disable roaming links to SharePoint lists. When roaming is disabled, SharePoint lists are available only on the client that originally linked them.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disableroamingofsharepointlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disableroamingofsharepointlists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disablesharepointintegrationinoutlook","displayName":"Do not allow Sharepoint-Outlook integration (User)","description":"This policy setting allows you to prevent access to Microsoft SharePoint Foundation with Outlook.\r\n\r\nIf you enable this policy setting, user profiles will not be able to upload new items or sync changes to the SharePoint list from the server; however, user profiles that have pre-existing SharePoint lists will retain their local data. In addition, new SharePoint lists cannot be connected when this policy setting is enabled. This can be toggled on and off to restore synchronization to existing lists. Note that users will not receive a message if synchronization has been prevented.\r\n\r\nIf you disable or do not configure this policy setting, Microsoft SharePoint Foundation access will be allowed with Outlook.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disablesharepointintegrationinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disablesharepointintegrationinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_logsharepointsyncrequestsandresponses","displayName":"Log SharePoint sync requests and responses (User)","description":"This policy setting allows you to control whether sync requests and responses between Outlook and SharePoint are logged. Log files can help diagnose problems with Outlook and SharePoint interactions. Each log file links to one or more XML files (also in the TEMP directory) containing detailed server response and error information. The XML filename is based on the corresponding log file; you can obtain all related diagnostic files by copying all *-wss-*.* files from the TEMP directory.\r\n\r\nIf you enable this policy setting, Outlook logs most sync requests and responses to a log file stored in the user's TEMP directory. One log file is created per session (up to seven total), using the naming convention: 0-wss-sync-log.HTM, 1-wss-sync-log.HTM, etc. \r\n\r\nIf you disable or do not configure this policy setting, sync requests and responses between Outlook and SharePoint are not logged.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_logsharepointsyncrequestsandresponses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_logsharepointsyncrequestsandresponses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_modifynumberofchangeditemsincluded","displayName":"Modify number of changed items included in SharePoint client page download (User)","description":"By default, the number of changes an Outlook client downloads from a SharePoint server in a single web service request or \"page\" is 250 changed items. If SharePoint servers have reduced capacity or are overwhelmed by the size of requests coming from Outlook clients, you can change this setting to specify a different number of items to download for a SharePoint page. \r\n\r\nYou should test changes in this setting to determine the impact in your specific environment. A page size below 15 or above 1000 is not recommended.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_modifynumberofchangeditemsincluded_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_modifynumberofchangeditemsincluded_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_modifynumberofchangeditemsincluded_l_empty34","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_overridepublishedsyncinteral36","displayName":"Override published sync interval (User)","description":"This policy setting allows you to prevent users from overriding the sync interval published by managed SharePoint lists.\r\n\r\nIf you enable this policy setting, the \"Update Limit\" checkbox found under File tab | Info | Account Settings | SharePoint List | Change… is disabled, and the user's connected SharePoint lists will only sync as defined by the list's administrator.\r\n\r\nIf you disable this policy setting, then individual users will be able to override the sync interval by unchecking the \"Update Limit\" checkbox in the SharePoint List's Options dialog. Defined sync intervals can range from 1 minute to 1440 minutes (a full day).\r\n\r\nIf you do not configure this policy setting, the user's profile will sync the SharePoint list at a default of 20 minutes or as specified by the administrator of the SharePoint list.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_overridepublishedsyncinteral36_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_overridepublishedsyncinteral36_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_automaticallydownloadenclosureswebcal","displayName":"Automatically download attachments (User)","description":"This policy setting controls whether Outlook downloads files attached to Internet Calendar appointments. \r\n\r\nIf you enable this policy setting, Outlook automatically downloads all Internet Calendar appointment attachments \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not download attachments when retrieving Internet Calendar appointments.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_automaticallydownloadenclosureswebcal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_automaticallydownloadenclosureswebcal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions","displayName":"Default Internet Calendar subscriptions (User)","description":"This policy setting allows you to deploy Internet Calendar subscriptions.\r\n\r\nIf you enable this policy setting, the URLs listed here will be read and the corresponding Internet Calendar subscriptions will be added to each of the user's profiles. The name you specify here will not be used as the name of the Internet Calendar subscription.\r\n\r\nIf you disable or do not configure this policy setting users will not have any default Internet Calendar subscriptions.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_l_empty32","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_l_empty32_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_l_empty32_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_disableroamingofinternetcalendars","displayName":"Disable roaming of Internet Calendars (User)","description":"By default, Internet Calendars are available on each client that the users use to connect to their Microsoft Exchange Server mailboxes. This setting allows you to disable roaming Internet Calendars. When roaming is disabled, Internet Calendars are available only on the client that originally linked them.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_disableroamingofinternetcalendars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_disableroamingofinternetcalendars_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_disablewebcalintegration","displayName":"Do not include Internet Calendar integration in Outlook (User)","description":"This policy setting allows you to determine whether or not you want to include Internet Calendar integration in Outlook. The Internet Calendar feature in Outlook enables users to publish calendars online (using the webcal:// protocol) and subscribe to calendars that others have published. When users subscribe to an Internet calendar, Outlook queries the calendar at regular intervals and downloads any changes as they are posted. \r\n\r\nIf you enable this policy setting, all Internet calendar functionality in Outlook is disabled. \r\n\r\nIf you disable or do not configure this policy setting, Outlook allows users to subscribe to Internet calendars.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_disablewebcalintegration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_disablewebcalintegration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_overridepublishedsyncinteral","displayName":"Override published sync interval (User)","description":"By default, Outlook follows the sync interval specified by the Internet Calendar publisher and Internet Calendar subscriptions will not be sync'd more often than allowed by the Internet Calendar publisher. This setting allows you to prevent users from overriding the sync interval published by Internet Calendar publishers.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_overridepublishedsyncinteral_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_overridepublishedsyncinteral_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v3~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preferprovidedemailinautodiscoverauthprompts","displayName":"Prefer the provided account email in AutoDiscover auth prompts. (User)","description":"If set, this policy setting governs the displayed email in auth prompts related to AutoDiscover.\r\n\r\n Default (0): Prefers the account UPN, when available.\r\n\r\n If you enable this setting, then AutoDiscover auth prompts will prefer the provided account email (can be either SMTP or UPN depending on which was configured).","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v3~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preferprovidedemailinautodiscoverauthprompts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v3~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preferprovidedemailinautodiscoverauthprompts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions_l_disableguesssmart","displayName":"Disable GuessSmart in Outlook. (User)","description":"This policy setting determines whether GuessSmart will be used to configure an account.\r\n\r\nIf you enable this policy setting, GuessSmart will not be used to configure an account.","helpText":"","infoUrls":[],"categoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","categoryName":"Outlook Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions_l_disableguesssmart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions_l_disableguesssmart_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions_l_disableroamingsettings","displayName":"Disable roaming settings in Outlook. (User)","description":"This policy setting determines whether roaming settings will be used to store accounts and their settings.\r\n\r\nIf you enable this policy setting, roaming settings will not store Outlook accounts or their settings in the cloud.","helpText":"","infoUrls":[],"categoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","categoryName":"Outlook Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions_l_disableroamingsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions_l_disableroamingsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookfeedbackfeatures","displayName":"Disable Outlook features in the Feedback tab under the File menu in Outlook (User)","description":"This policy setting determines whether Outlook features will be displayed in the Feedback tab under the File menu in Outlook.\r\n\r\nIf you enable this policy setting, then Outlook features will not be displayed in the Feedback tab under the File menu in Outlook.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookfeedbackfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookfeedbackfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookmobilehyperlink","displayName":"Disable Outlook Mobile Hyperlink (User)","description":"This policy setting determines if the Outlook Mobile Hyperlink is shown in Account Settings.\r\n\r\nIf you enable this policy setting, users will be unable to view the Outlook Mobile Hyperlink in Account Settings.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookmobilehyperlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookmobilehyperlink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportbackstage","displayName":"Disable the Support tab under the File menu in Outlook (User)","description":"This policy setting determines whether the Support tab will be displayed under the File menu in Outlook.\r\n\r\nIf you enable this policy setting, then the Support tab will not be displayed under the File menu in Outlook.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportbackstage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportbackstage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportdiagnostics","displayName":"Disable support diagnostics in Outlook (User)","description":"This policy setting determines if Outlook can communicate client information on failure to support services with the intent of diagnosing the issue or making the information available to support to help with the diagnosis/resolution of the issue and/or provide contextual error messaging to the user.\r\n\r\nIf you enable this policy setting, then Outlook will not communicate client information on failure to support services.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportticketcreationinoutlook","displayName":"Disable support ticket creation in Outlook (User)","description":"This policy setting determines if an Outlook support ticket can be created in Outlook.\r\n\r\nIf you enable this policy setting, users will be unable to create a support ticket in Outlook.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportticketcreationinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportticketcreationinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_disableaccountsettingsdetectionservice","displayName":"Prevent Outlook from interacting with the account settings detection service (User)","description":"This policy setting determines whether Outlook can interact with the account settings detection service to gather information about a user's account settings.\r\n\r\nIf you enable this policy setting, users will need to manually configure their account settings.","helpText":"","infoUrls":[],"categoryId":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_disableaccountsettingsdetectionservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_disableaccountsettingsdetectionservice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_disableoffice365simplifiedaccountcreation","displayName":"Prevent Office 365 E-mail accounts from being configured within a simplified Interface (User)","description":"This policy setting determines whether an Office 365 E-mail account when being configured in Outlook, can use a simplified dialog that can greatly accelerate the initial account creation.\r\n\r\nIf you enable this policy setting, users will configure their Office 365 accounts using the Account Wizard, as they do, for all other account types.","helpText":"","infoUrls":[],"categoryId":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_disableoffice365simplifiedaccountcreation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_disableoffice365simplifiedaccountcreation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_enableeasaccountcreation","displayName":"Enable Exchange ActiveSync account creation in the Outlook account setup UI (User)","description":"This policy setting determines whether the Exchange ActiveSync button will be displayed in the account setup UI.\r\n\r\nIf you enable this policy setting, the Exchange ActiveSync button will be displayed in Outlook account setup UI.","helpText":"","infoUrls":[],"categoryId":"b161cf66-abfa-4a36-a9ac-c20ca60594e0","categoryName":"Exchange ActiveSync","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_enableeasaccountcreation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_enableeasaccountcreation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookenableofficeconfigserviceinautodiscover","displayName":"Allow Outlook Autodiscover to interact with Office Config Service (User)","description":"This policy setting determines whether Outlook can interact with the Office Config Service to get Autodiscover V2 service endpoint URL for different sovereigns.\r\n\r\nif you enable this policy setting, Outlook will get the URL for the sovereign Autodiscover v2 service endpoint by default.\r\n\r\nIf you disable this policy setting, Outlook will get the URL for the WW Autodiscover v2 service endpoint by default.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookenableofficeconfigserviceinautodiscover_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookenableofficeconfigserviceinautodiscover_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableadminnotifications","displayName":"Disable Outlook tenant admin notifications (User)","description":"This policy setting determines if tenant admins can receive support notifications in Outlook.\r\n\r\nDefault (0): Tenant admins who are signed in will receive status updates about potential issues and fixes that are impacting their tenant.\r\n\r\nIf you enable this setting, tenant admins who are signed in won't receive status updates about potential issues and fixes that are impacting their tenant.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableadminnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableadminnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablecrashnotificationonrestart","displayName":"Disable the Outlook crash notification when Outlook restarts. (User)","description":"This policy setting determines if the Outlook crash notification on restart is allowed. Enabling this setting will block Outlook crash notification on restart.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablecrashnotificationonrestart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablecrashnotificationonrestart_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_allowprivatekeycheck","displayName":"Check for the user's private key when the user sends an encrypted email that includes the user as a recipient (User)","description":"This policy setting controls whether Outlook checks for the user's private key when the user sends an encrypted email and the user is included as a recipient of the email. The user can be included as recipient either directly or as a member of a distribution list.\r\n\r\nIf you enable this policy setting, Outlook checks for the user's private key.\r\n\r\nIf you disable this policy setting, Outlook doesn't check for the user's private key.\r\n\r\nIf you don't configure this policy setting, Outlook checks for the user's private key.\r\n ","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_allowprivatekeycheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_allowprivatekeycheck_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel","displayName":"Junk E-mail protection level (User) (Deprecated)","description":"This policy setting controls your Junk E-mail protection level. The Junk E-mail Filter in Outlook helps to prevent junk e-mail messages, also known as spam, from cluttering user's Inbox. The filter evaluates each incoming message based on several factors, including the time when the message was sent and the content of the message. The filter does not single out any particular sender or message type, but instead analyzes each message based on its content and structure to discover whether or not it is probably spam.\r\n\r\nIf you enable this policy setting, you can select one of the four listed options available. After you select an option, users will not be able to change it.\r\n\r\nIf you disable this policy setting, Outlook reverts to the user-defined protection level.\r\n\r\nIf you do not configure this policy setting, users can change their junk e-mail filtering options.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_l_selectlevel","displayName":"Select level: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_l_selectlevel_4294967295","displayName":"No Protection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_l_selectlevel_6","displayName":"Low (Default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_l_selectlevel_3","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_l_selectlevel_2147483648","displayName":"Trusted Lists Only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2","displayName":"Junk E-mail protection level (User)","description":"This policy setting controls your Junk E-mail protection level. The Junk E-mail Filter in Outlook helps to prevent junk e-mail messages, also known as spam, from cluttering user's Inbox. The filter evaluates each incoming message based on several factors, including the time when the message was sent and the content of the message. The filter does not single out any particular sender or message type, but instead analyzes each message based on its content and structure to discover whether or not it is probably spam.\r\n\r\nIf you enable this policy setting, you can select one of the four listed options available. After you select an option, users will not be able to change it.\r\n\r\nIf you disable this policy setting, Outlook reverts to the user-defined protection level.\r\n\r\nIf you do not configure this policy setting, users can change their junk e-mail filtering options.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel","displayName":"Select level: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_4294967295","displayName":"No Protection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_6","displayName":"Low (Default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_3","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_2147483648","displayName":"Trusted Lists Only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver","displayName":"Authentication with Exchange Server (User) (Deprecated)","description":"This policy setting controls which authentication method Outlook uses to authenticate with Microsoft Exchange Server. Note - Exchange Server supports the Kerberos authentication protocol and NTLM for authentication. The Kerberos protocol is the more secure authentication method and is supported on Windows 2000 Server and later versions. NTLM authentication is supported in pre-Windows 2000 environments.\r\n \r\nIf you enable this policy setting, you can choose from three different options for controlling how Outlook authenticates with Microsoft Exchange Server:\r\n\r\n- Kerberos/NTLM password authentication. Outlook attempts to authenticate using the Kerberos authentication protocol. If this attempt fails, Outlook attempts to authenticate using NTLM. This option is the default configuration.\r\n\r\n- Kerberos password authentication. Outlook attempts to authenticate using the Kerberos protocol only.\r\n\r\n- NTLM password authentication. Outlook attempts to authenticate using NTLM only.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will attempt to authenticate using the Kerberos authentication protocol. If it cannot (because no Windows 2000 or later domain controllers are available), it will authenticate using NTLM.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver","displayName":"Select the authentication with Exchange server. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_9","displayName":"Kerberos/NTLM Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_16","displayName":"Kerberos Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_10","displayName":"NTLM Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_2147545088","displayName":"Insert a smart card","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2","displayName":"Authentication with Exchange Server (User)","description":"This policy setting controls which authentication method Outlook uses to authenticate with Microsoft Exchange Server. Note - Exchange Server supports the Kerberos authentication protocol and NTLM for authentication. The Kerberos protocol is the more secure authentication method and is supported on Windows 2000 Server and later versions. NTLM authentication is supported in pre-Windows 2000 environments.\r\n \r\nIf you enable this policy setting, you can choose from three different options for controlling how Outlook authenticates with Microsoft Exchange Server:\r\n\r\n- Kerberos/NTLM password authentication. Outlook attempts to authenticate using the Kerberos authentication protocol. If this attempt fails, Outlook attempts to authenticate using NTLM. This option is the default configuration.\r\n\r\n- Kerberos password authentication. Outlook attempts to authenticate using the Kerberos protocol only.\r\n\r\n- NTLM password authentication. Outlook attempts to authenticate using NTLM only.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will attempt to authenticate using the Kerberos authentication protocol. If it cannot (because no Windows 2000 or later domain controllers are available), it will authenticate using NTLM.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_l_selecttheauthenticationwithexchangeserver","displayName":"Select the authentication with Exchange server. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_l_selecttheauthenticationwithexchangeserver_9","displayName":"Kerberos/NTLM Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_l_selecttheauthenticationwithexchangeserver_16","displayName":"Kerberos Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_l_selecttheauthenticationwithexchangeserver_10","displayName":"NTLM Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_l_selecttheauthenticationwithexchangeserver_2147545088","displayName":"Insert a smart card","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_predefined_l_disableeditdefaultuserpermissions","displayName":"Limit which permissions can be assigned to Default, Anonymous, or My Organization on mail folders and calendars (User)","description":"This policy setting allows you to limit which permissions can be assigned to Default, Anonymous, or My Organization on mail folders and calendars.\r\n\r\nIf you enable this policy setting, users can assign only the following permissions to Default, Anonymous, or My Organization.\r\n\r\n- None on mail folders\r\n- None or basic Free/Busy information on calendars\r\n\r\nUsers won't be able to assign any other permissions to Default, Anonymous, or My Organization. All permissions will still be available to assign to other users on mail folders and calendars.\r\n\r\nIf you disable or don't configure this policy setting, users can assign any permissions to Default, Anonymous, or My Organization on mail folders and calendars.","helpText":"","infoUrls":[],"categoryId":"d59dfcc1-6c35-41de-bfb6-de94b8120ca5","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_predefined_l_disableeditdefaultuserpermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_predefined_l_disableeditdefaultuserpermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_delegatesentitemsstyle","displayName":"Saving messages sent from a shared mailbox to the Sent Items folder (User)","description":"This policy setting controls whether messages sent from a shared mailbox are saved to the Sent Items folder of the shared mailbox.\r\n\r\nBy default, messages sent from a shared mailbox aren't saved to the Sent Items folder of the shared mailbox.\r\n\r\nIf you enable this policy setting, messages sent from a shared mailbox will be saved to the Sent Items folder of the shared mailbox.\r\n\r\nIf you disable or don’t configure this policy setting, messages sent from a shared mailbox won’t be saved to the Sent Items folder of the shared mailbox.","helpText":"","infoUrls":[],"categoryId":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","categoryName":"Delegates","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_delegatesentitemsstyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_delegatesentitemsstyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype","displayName":"Shorten appointments and meetings (User)","description":"\r\n This policy setting allows you to shorten the default duration of appointments and meetings by a specified number of minutes. If you enable this policy setting, you can choose between the following options: End Early, Start Late, None.\r\n If you select End Early, meetings and appointments will end early by the specified number of minutes. \r\n If you select Start Late, meetings and appointments will start late by the specified number of minutes. \r\n If you select None, the default meeting duration will not be shortened. \r\n In all cases, the settings for this feature will be disabled in the Outlook Options dialog. \r\n If you don’t configure this policy setting, users can modify these settings by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype","displayName":"Select the Shorten Events Type (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype_none","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype_end_early","displayName":"End Early","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype_start_late","displayName":"Start Late","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_alwaysusemsoauthforautodiscover","displayName":"Autodiscover is always capable of using modern authentication (User)","description":"This policy setting controls whether Autodiscover is always capable of using modern authentication, regardless of the authentication methods supported by the primary mailbox connection type.\r\n\r\nBy default, Autodiscover only uses authentication methods that are supported by the primary mailbox connection type. Modern authentication won't always be one of the supported authentication methods for some connection types.\r\n\r\nIf you enable this policy setting, Autodiscover is always capable of using modern authentication, regardless of the authentication methods supported by the primary mailbox connection type. Enabling this policy setting may result in additional prompts for users to provide their password, when modern authentication is used, but not supported for the connection type.\r\n\r\nIf you disable or don’t configure this policy setting, Autodiscover will only use authentication methods supported by the primary mailbox connection type.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_alwaysusemsoauthforautodiscover_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_alwaysusemsoauthforautodiscover_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers","displayName":"Don’t show redirect warnings for Autodiscover for the specified HTTPS server names (User)","description":"This policy setting allows you to specify HTTPS server names for which Autodiscover won’t show a warning message when redirecting from HTTP to HTTPS.\r\n\r\nBy default, when an Autodiscover operation redirects from HTTP to HTTPS, you may be shown a warning message about the redirection.\r\n\r\nIf you enable this policy setting, you need to specify HTTPS server names, and for those server names, you won’t be shown a warning message. For example, if you enter contoso.com, you won’t be shown a warning message when Autodiscover redirects to https://contoso.com.\r\n\r\nIf you disable or don’t configure this policy setting, you may be shown a warning message when an Autodiscover operation redirects from HTTP to HTTPS.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers_l_autodiscoverredirectserverslist","displayName":"HTTPS server names: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v8~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_recommendoutlookextension","displayName":"Recommend the Microsoft Outlook Extension (User)","description":"This policy setting controls whether Windows 10 users of the Outlook app and the Outlook web app will see a recommendation to install the new Microsoft Outlook extension for Microsoft Edge. If a user chooses to click the recommendation, they will be taken to the Microsoft Outlook extension page where they can choose to install this web-based, productivity add on. Your users can dismiss the recommendation and will only see the recommendation twice. If your users choose to install the extension, they will be able to access their mail, calendar, contacts, and tasks from an icon in Microsoft Edge without requiring that they open another browser tab. The extension is a “mini” version of Outlook on the web which operates as a one-click flyout from the browser header.\r\n\r\nIn the future, Microsoft may release a version of this extension for the Chrome browser. Microsoft will respect this policy for future promotions of a Chrome extension, as well.\r\n\r\nIf you enable or do not configure this policy setting, the recommendation will be presented to the user.\r\n\r\nIf you disable this policy setting, the recommendation will not be presented to the user.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise and Outlook web app.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2165458","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v8~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_recommendoutlookextension_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v8~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_recommendoutlookextension_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin","displayName":"Deactivate Outlook web add-ins whose equivalent COM or VSTO add-in is installed (User)","description":"This policy setting allows you to deactivate Outlook web add-ins if the associated COM or VSTO add-in is installed.\r\n\r\nIf you enable this policy setting, users will not be able to use Outlook web add-ins where the corresponding COM or VSTO add-in is installed and you have provided the following information for each add-in.\r\n \"Value name\": Specify the Id of the Outlook web add-in, as noted in its manifest. Note: Do not add {} around the Id.\r\n \"Value\": Specify the programmatic ID (ProgID) for the Outlook COM or VSTO add-in.\r\n\r\nIf you disable or don't configure this policy setting, users will continue to be able to use any versions of the add-in that are installed.\r\n\r\nFor more information about when to use this setting, see https://go.microsoft.com/fwlink/p/?linkid=2156690","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_l_equivalentcomaddin2","displayName":"Outlook web add-ins to deactivate (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_l_equivalentcomaddin2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_l_equivalentcomaddin2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported","displayName":"Maximum Groups Supported (User)","description":"This policy setting controls the maximum number of groups that are accessible through the Navigation Pane in Outlook for Windows.\r\n\r\nIf you enable this policy setting, only the number of groups set in the Groups Count will be shown in the Navigation Pane. \r\n\r\nIf you don’t enable this policy setting, the maximum number of groups displayed defaults to 1000.\r\n ","helpText":"","infoUrls":[],"categoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","categoryName":"Outlook Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported_l_specifymaxgroupssupportedid","displayName":"Groups Count: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","categoryName":"Outlook Options","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_disableautosavewhencoauthoring","displayName":"Don’t automatically save changes when working in the same PowerPoint presentation as others (User)","description":"This policy setting controls whether changes are saved automatically when users are working together in the same presentation.\r\n\r\nBy default, when users are working together in the same presentation, changes are automatically saved. This allows users to see the edits made by others in real time. But, some add-ins or solutions might not be compatible with PowerPoint saving so frequently.\r\n\r\nIf you enable this policy setting, changes aren’t saved automatically and users won’t see real-time edits.\r\n\r\nIf you disable or don't configure this policy setting, changes are saved automatically and users will see real-time edits.\r\n\r\nNote: this policy setting doesn’t affect the AutoRecover settings configured under File > Options > Save.\r\n ","helpText":"","infoUrls":[],"categoryId":"ceacf7fa-fa6e-434d-a381-e20e5245d180","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_disableautosavewhencoauthoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_disableautosavewhencoauthoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_preventcoauthoring","displayName":"Prevent co-authoring (User)","description":"This policy setting controls how PowerPoint opens a file for editing on document management servers that support co-authoring.\r\n\r\nIf you enable this policy setting, PowerPoint will prevent co-authoring by taking an exclusive file lock. \r\n\r\nIf you disable or do not configure this policy setting, PowerPoint will allow co-authoring by taking short-term shared locks. \r\n\r\nNote: When file synchronization via SOAP over HTTP is turned off it will prevent co-authoring.","helpText":"","infoUrls":[],"categoryId":"ceacf7fa-fa6e-434d-a381-e20e5245d180","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_preventcoauthoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_preventcoauthoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_turnoffrevisiontracking","displayName":"Turn off revision tracking (User)","description":"This policy setting allows you to turn off revision tracking in PowerPoint.\r\n\r\nBy default, revision tracking is on in presentations where revision tracking is supported.\r\n\r\nIf you enable this policy setting, revisions made to a presentation aren’t tracked or shown.\r\n\r\nIf you disable or don’t configure this policy setting, revisions made to a presentation are tracked and shown.","helpText":"","infoUrls":[],"categoryId":"ceacf7fa-fa6e-434d-a381-e20e5245d180","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_turnoffrevisiontracking_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_turnoffrevisiontracking_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Specifies the list of error messages to customize.","helpText":"","infoUrls":[],"categoryId":"28ab8eed-623a-4e9b-813e-13256472dbaf","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize80","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"28ab8eed-623a-4e9b-813e-13256472dbaf","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize80_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"28ab8eed-623a-4e9b-813e-13256472dbaf","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize80_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"28ab8eed-623a-4e9b-813e-13256472dbaf","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys158","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys158_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys158_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys158_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinrecordingpresenterview","displayName":"Turn off microphone recording by default when recording a slide show (User)","description":"This policy setting allows you to set microphone recording off by default when recording a slide show.\r\n\r\nBy default, microphone recording is on the first time a user records a slide show. If the user turns off microphone recording, then microphone recording will be off the next time the slide show recording window is launched, even if PowerPoint is closed and reopened.\r\n\r\nIf you enable this policy setting, microphone recording is turned off by default. A user can turn on microphone recording when recording a slide show. But, the next time the slide show recording window is launched, microphone recording will be off by default.\r\n\r\nIf you disable or don’t configure this policy setting, the default state of microphone recording is determined by the user.\r\n\r\nNote: Enabling this policy setting also turns off camera recording by default when recording a slide show. There is a separate policy setting if you just want to turn off camera recording by default when recording a slide show.\r\n ","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinrecordingpresenterview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinrecordingpresenterview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinscreenrecorder","displayName":"Turn off audio recording for screen recording (User)","description":"This policy setting allows you to control the initial audio recording setting for a screen recording in PowerPoint. By default, audio is recorded during a screen recording.\r\n \r\nIf you enable this policy setting, audio isn’t recorded during a screen recording. But, the user can choose to turn on audio recording manually in the UI.\r\n \r\nIf you disable or don’t configure this policy setting, audio is recorded during a screen recording. The user can choose to turn off audio recording manually in the UI.","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinscreenrecorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinscreenrecorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultvideooffinrecordingpresenterview","displayName":"Turn off camera recording by default when recording a slide show (User)","description":"This policy setting allows you to set camera recording off by default when recording a slide show.\r\n\r\nBy default, camera recording is on the first time a user records a slide show. If the user turns off camera recording, then camera recording will be off the next time the slide show recording window is launched, even if PowerPoint is closed and reopened.\r\n\r\nIf you enable this policy setting, camera recording is turned off by default. A user can turn on camera recording when recording a slide show. But, the next time the slide show recording window is launched, camera recording will be off by default.\r\n\r\nIf you disable or don’t configure this policy setting, the default state of camera recording is determined by the user, unless the “Turn off microphone recording by default when recording a slide show” policy setting is enabled. Enabling that policy setting also turns off camera recording by default.\r\n ","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultvideooffinrecordingpresenterview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultvideooffinrecordingpresenterview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable specific command bar buttons and menu items in the specified applications. \r\n\r\nIf you enable this policy setting you can disable specific command bar buttons and menu items in the user interface for the selected application. The predefined list of command bar buttons and menu items you can disable becomes available to you when you enable this policy setting. \r\n\r\nIf you disable or do not configure this policy setting, the predefined list of command bar buttons and menu items are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_broadcastslideshow","displayName":"Slide Show tab | Start Slide Show | Broadcast Slide Show (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_broadcastslideshow_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_broadcastslideshow_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient","displayName":"File tab | Share | Send Using E-mail (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview","displayName":"File tab | Options | Customize Ribbon | All Commands | Web Page Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlinkppt","displayName":"Insert tab | Links | Hyperlink (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlinkppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlinkppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolslanguage","displayName":"Review tab | Language | Language (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolslanguage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolslanguage_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacrosppt","displayName":"Developer tab | Code | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacrosppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacrosppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity","displayName":"Developer tab | Code | Macro Security (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorppt","displayName":"Developer tab | Code | Visual Basic (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddressppt","displayName":"File tab | Options | Customize Ribbon | All Commands | Address (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddressppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddressppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable specific shortcut key combinations in the specified applications. \r\n\r\nIf you enable this policy setting you can disable specific shortcut keys for the selected application. The predefined list of shortcut keys you can disable becomes available to you when you enable this policy setting. \r\n\r\nIf you disable or do not configure this policy setting, the predefined list of shortcut keys are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditorppt","displayName":"Alt+F11 (Developer | Code | Visual Basic) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditorppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditorppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros","displayName":"Alt+F8 (Developer | Code | Macros) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlf5broadcastslideshow","displayName":"Ctrl+F5 (Slide Show | Start Slide Show | Broadcast Slide Show) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlf5broadcastslideshow_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlf5broadcastslideshow_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindppt","displayName":"Ctrl+F (Home | Editing | Find) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkppt","displayName":"Ctrl+K (Insert | Links | Hyperlink) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_enablerecordingribbontab","displayName":"Turn on recording ribbon tab (User)","description":"This policy setting allows you to control the initial recording ribbon tab in PowerPoint. By default, the tab is not visible.\r\n\r\nIf you enable this policy setting, recording ribbon tab is visible. But, the user can choose to turn off the feature manually in the UI.\r\n\r\nIf you disable or don’t configure this policy setting, recording ribbon tab is not visible. The user can choose to turn on the feature manually in the UI.\r\n ","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_enablerecordingribbontab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_enablerecordingribbontab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_hidebuiltintablestyles","displayName":"Hide built in table styles (User)","description":"Hides the built in table styles for PowerPoint. By default, built-in styles are shown.","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_hidebuiltintablestyles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_hidebuiltintablestyles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation","displayName":"Check for accessibility issues while editing (User)","description":"This policy setting controls whether accessibility issues are checked for automatically while the user is editing a presentation. By default, accessibility issues aren’t checked for automatically.\r\n\r\nIf you enable this policy setting, accessibility issues are checked for automatically and users won’t be able to turn it off. The status bar will indicate if accessibility recommendations are available to make the presentation more usable by people with disabilities.\r\n\r\nIf you disable or don’t configure this policy setting, accessibility issues won’t be checked for automatically while editing a presentation. Users can turn on automatic checking by going to File > Options > Ease of Access.\r\n","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation","displayName":"Stop checking for alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that objects such as images and shapes contain alt text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that objects such as images and shapes contain alt text.\r\n\r\nIf you disable or do not configure this policy setting, objects will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsandcolumns","displayName":"Stop checking for blank table rows and columns (User)","description":"This policy setting prevents the Accessibility Checker from verifying that blank rows and columns have not been inserted into tables.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that blank rows and columns have not been inserted into tables.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for blank rows and columns and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsandcolumns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsandcolumns_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformediafilescaptions","displayName":"Stop checking for media files which might need captions (User)","description":"This policy setting prevents the Accessibility Checker from flagging media files that might need caption information.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging media files that might need caption information.\r\n\r\nIf you disable or do not configure this policy setting, presentations will be scanned for media files and the results will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformediafilescaptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformediafilescaptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformergedandsplitcells","displayName":"Stop checking for merged and split cells (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables do not have merged or split cells.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables do not have merged or split cells.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for merged and split cells and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformergedandsplitcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformergedandsplitcells_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingmeaningfulorderofobjectsonslides","displayName":"Stop checking to ensure a meaningful order of objects on slides (User)","description":"This policy setting prevents the Accessibility Checker from checking if a slide has non-placeholder objects which might be read back out of order.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking if a slide has non-placeholder objects which might be read back out of order.\r\n\r\nIf you disable or do not configure this policy setting, slides will be checked for objects which might be read back out of order and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingmeaningfulorderofobjectsonslides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingmeaningfulorderofobjectsonslides_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingpresentationsallowprogrammaticaccess","displayName":"Stop checking to ensure presentations allow programmatic access (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that presentations have not blocked programmatic access through DRM.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that presentations have not blocked programmatic access through DRM.\r\n\r\nIf you disable or do not configure this policy setting, presentations will be checked for programmatic access and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingpresentationsallowprogrammaticaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingpresentationsallowprogrammaticaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation","displayName":"Stop checking for table alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables contain alt text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables contain alt text.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation","displayName":"Stop checking for table header accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables have a header row specified.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables have a header row specified.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for header rows and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtextcontrast","displayName":"Stop checking for text color contrast (User)","description":"This policy setting prevents the Accessibility Checker from flagging text with low contrast and readability.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging text with low contrast and readability.\r\n\r\nIf you disable or do not configure this policy setting, text will be scanned for color contrast and the results will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtextcontrast_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtextcontrast_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingthatslidetitlesexist","displayName":"Stop checking that slide titles exist (User)","description":"This policy setting prevents the Accessibility Checker from verifying that every slide has a title placeholder.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that every slide has a title placeholder.\r\n\r\nIf you disable or do not configure this policy setting, slides will be checked for titles and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingthatslidetitlesexist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingthatslidetitlesexist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensureeachslidehasauniquetitle","displayName":"Stop checking to ensure each slide has a unique title (User)","description":"This policy setting prevents the Accessibility Checker from verifying that every slide has a unique title.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that every slide has a unique title.\r\n\r\nIf you disable or do not configure this policy setting, slide titles will be checked for uniqueness and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensureeachslidehasauniquetitle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensureeachslidehasauniquetitle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful","displayName":"Stop checking to ensure hyperlink text is meaningful (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_defaultcustomtab","displayName":"Show custom templates tab by default in PowerPoint on the Office Start screen and in File | New (User)","description":"This policy setting controls whether custom templates (when they exist) show as the default tab in PowerPoint on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, users will the see custom templates tab as the default tab in PowerPoint on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in PowerPoint on the Office Start screen and in File | New, unless all Office-provided templates have been disabled.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_defaultcustomtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_defaultcustomtab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_disableofficestartpowerpoint","displayName":"Disable the Office Start screen for PowerPoint (User)","description":"This policy setting controls whether the Office Start screen appears on boot for PowerPoint.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot PowerPoint.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot PowerPoint.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_disableofficestartpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_disableofficestartpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_disableslideupdate","displayName":"Disable Slide Update (User)","description":"This policy setting controls whether users can link slides in a presentation with their counterparts in a PowerPoint Slide Library.\r\n\r\nIf you enable this policy setting, PowerPoint cannot check the status of a slide in a Slide Library when a presentation with Slide Update data is opened.\r\n\r\nIf you disable or do not configure this policy setting, each time users open a presentation that contains a shared slide, PowerPoint notifies them if the slide has been updated and provides them with the opportunity to ignore the update, append a new slide to the outdated slide, or replace the outdated slide with the updated one.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_disableslideupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_disableslideupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins, or specify the file name of PowerPoint add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\PowerPoint\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\PowerPoint\\Addins.\r\n\r\nTo obtain the file name of an add-in, click the File menu in the application where the add-in is installed. Click Options, click Add-ins, and then use the Location column to determine the file name of the add-in.\r\n\r\nYou can also obtain the ProgID or the file name of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_personaltemplatespath","displayName":"Personal templates path for PowerPoint (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp","displayName":"Turn off file synchronization via SOAP over HTTP (User)","description":"This policy setting controls file synchronization via SOAP over HTTP for PowerPoint.\r\n\r\nIf you enable this policy setting, file synchronization via SOAP over HTTP is turned off for PowerPoint.\r\n\r\nIf you disable or do not configure this policy setting this policy setting, file synchronization via SOAP over HTTP is turned on for PowerPoint.\r\n\r\nNote: Turning off file synchronization via SOAP over HTTP will also prevent co-authoring and adversely affect the behavior of SharePoint Workspaces.","helpText":"","infoUrls":[],"categoryId":"7aeaf6f8-5511-4216-9483-28f432a5a08f","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_allowautoextendfordesktop","displayName":"Allow PowerPoint to also automatically extend the display when presenting on a desktop (User)","description":"This policy setting specifies whether PowerPoint can also automatically extend the display when users present on a desktop computer.\r\n\r\nIf you enable this policy setting, PowerPoint will automatically extend the display when users present on a desktop computer, if the \"Automatically extend display when presenting on a laptop or tablet\" checkbox on the UI under File | Options | Advanced | Display is checked.\r\n\r\nIf you disable or do not configure this policy setting, PowerPoint does not automatically extend the display when users present on a desktop computer, even if the \"Automatically extend display when presenting on a laptop or tablet\" checkbox on the UI under File | Options | Advanced | Display is checked.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_allowautoextendfordesktop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_allowautoextendfordesktop_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_backgroundprinting","displayName":"Print in background (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_backgroundprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_backgroundprinting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_chartreftrackingenabled","displayName":"Allow formatting and labels to track data points (User)","description":"This policy setting governs how custom formatting and data labels react to data changes in a chart.\r\n\r\nIf you enable or do not configure this policy setting, when the user creates a new presentation, custom formatting and data labels follow data points as they move or change in any chart in the workbook.\r\n\r\nIf you disable this policy setting, custom formatting and data labels do not follow data points, but instead follow data point indices.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_chartreftrackingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_chartreftrackingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_disablesettopology","displayName":"Do not allow PowerPoint to automatically extend the display when presenting on a laptop or tablet (User)","description":"This policy setting specifies whether PowerPoint automatically extends the display when users present on a laptop or tablet computer.\r\n\r\nIf you enable this policy setting, PowerPoint does not automatically extend the display when users present on a laptop or tablet computer. In addition, the \"Automatically extend display when presenting on a laptop or tablet\" checkbox on the user interface (UI) under File | Options | Advanced | Display is unchecked.\r\n\r\nIf you disable or do not configure this policy setting, PowerPoint automatically extends the display when users present on a laptop or tablet computer. Users can change this behavior by unchecking the \"Automatically extend display when presenting on a laptop or tablet\" checkbox on the UI under File | Options | Advanced | Display","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_disablesettopology_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_disablesettopology_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes","displayName":"Display enterprise themes (User)","description":"This policy allows you to display enterprise themes in the ribbon galleries. You can also name the category for the themes, and you can hide all the Office in-box and connected gallery themes.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesdontshowothers","displayName":"Only show enterprise themes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesdontshowothers_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesdontshowothers_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesgallerytitle","displayName":"Enterprise themes category title (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_donotdisturb","displayName":"Set user availablity to Do not Disturb during Slide Show (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_donotdisturb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_donotdisturb_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_draganddroptextediting","displayName":"Allow text to be dragged and dropped (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_draganddroptextediting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_draganddroptextediting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_endwithblackslide","displayName":"End with black slide (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_endwithblackslide_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_endwithblackslide_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_maximumnumberofundos","displayName":"Maximum number of undos (User)","description":"Specifies the maximum number of undo levels.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_maximumnumberofundos_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_maximumnumberofundos_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_maximumnumberofundos_l_maximumnumberofundos2","displayName":"Maximum number of undos (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_popupmenuonrightmouseclick","displayName":"Show menu on right mouse click (User)","description":"Checked: Checks the option ''Show menu on right mouse click''. | Unchecked: Unchecks the option ''Show menu on right mouse click''.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_popupmenuonrightmouseclick_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_popupmenuonrightmouseclick_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printinsertedobjectsatprinterresolution","displayName":"Print inserted objects at printer resolution (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printinsertedobjectsatprinterresolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printinsertedobjectsatprinterresolution_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printtruetypefontsasgraphics","displayName":"Print TrueType fonts as graphics (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printtruetypefontsasgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printtruetypefontsasgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist","displayName":"Number of presentations in the Recent Presentations list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Presentations list that appears when users click Open on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Presentations list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Presentations list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist_l_sizeofrecentlyusedfilelist","displayName":"Size of recently used file list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_showpopupmenubutton","displayName":"Show popup toolbar (User)","description":"Checked: Checks the option ''Show popup toolbar''. | Unchecked: Unchecks the option ''Show popup toolbar''.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_showpopupmenubutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_showpopupmenubutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_usesmartcutandpaste","displayName":"Use smart cut and paste (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_usesmartcutandpaste_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_usesmartcutandpaste_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_verticalruler","displayName":"Show vertical ruler (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_verticalruler_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_verticalruler_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_whenselectingautomaticallyselectentireword","displayName":"When selecting, automatically select entire word (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_whenselectingautomaticallyselectentireword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_whenselectingautomaticallyselectentireword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_windowsintaskbar","displayName":"Show all windows in the Taskbar (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_windowsintaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_windowsintaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_resizegraphicstofitbrowserwindow","displayName":"Resize graphics to fit browser window (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_resizegraphicstofitbrowserwindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_resizegraphicstofitbrowserwindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_showslideanimationwhilebrowsing","displayName":"Show slide animation while browsing (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_showslideanimationwhilebrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_showslideanimationwhilebrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation","displayName":"Slide navigation (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_addslidenavigationcontrols","displayName":"Add slide navigation controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_addslidenavigationcontrols_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_addslidenavigationcontrols_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors","displayName":"Colors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_browsercolors","displayName":"Browser colors","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_presentationschemetextcolor","displayName":"Presentation colors (text color)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_presentationschemeaccentcolor","displayName":"Presentation colors (accent color)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_whitetextonblack","displayName":"White text on black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_blacktextonwhite","displayName":"Black text on white","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"f66fb7e4-a968-4969-b627-f99aaad0dfc3","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_allowselectionfloaties","displayName":"Show Mini Toolbar on selection (User)","description":"Disabling this policy setting will result in Mini Toolbar not being displayed on text selection. By default, Mini Toolbar on selection is enabled and its visibility can be changed via a setting in the PowerPoint Options dialog box.","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_allowselectionfloaties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_allowselectionfloaties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablegallerypreviews","displayName":"Enable Live Preview (User)","description":"Shows or hides the Live Preview that appear when using Galleries that support previews. Live Preview shows how a command would be applied without actually applying it to the document.","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablegallerypreviews_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablegallerypreviews_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disableincrementaldownload","displayName":"Wait to show users a cloud-based presentation until all content is downloaded (User)","description":"\r\nThis policy setting allows you to control whether PowerPoint waits until all content is downloaded before showing a presentation to the user. This policy setting applies to presentations that are opened from a cloud-based location, such as OneDrive Personal, OneDrive for Business, or SharePoint Online.\r\n\r\nBy default, when the user opens a cloud-based presentation in PowerPoint, the user can view the presentation while other content, such as images or video, continues to download. But, some functionality, such as editing and presenting, is limited or not available until the entire contents of the presentation are downloaded.\r\n\r\nIf you enable this policy setting, PowerPoint will wait, when opening a cloud-based presentation, until the entire contents of the presentation are downloaded before showing the presentation to the user.\r\n\r\nYou may want to enable this policy setting if you have add-ins or automated processes that rely on the entire contents of the presentation being available and fully editable as soon as the presentation is shown.\r\n\r\nIf you disable or don't configure this setting, PowerPoint opens cloud-based files more quickly, so the user can start viewing the presentation while the other content downloads.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disableincrementaldownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disableincrementaldownload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablelivesubtitles","displayName":"Don’t allow the use of Live Subtitles (User)","description":"\r\nThis policy setting controls whether users can turn on Live Subtitles during a presentation. By default, Live Subtitles are off but can be turned on by users.\r\n\r\nIf you enable this policy setting, users can't turn on Live Subtitles during a presentation.\r\n\r\nIf you disable or don't configure this policy setting, users can turn on Live Subtitles.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablelivesubtitles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablelivesubtitles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablequickstarter","displayName":"Turn off QuickStarter (User)","description":"This policy setting controls whether QuickStarter is available to users. By default, QuickStarter is available to users if they meet the language and region requirements for the feature.\r\n\r\nIf you enable this policy setting, QuickStarter won’t be available to users.\r\n\r\nIf you disable or don’t configure this policy setting, QuickStarter will be available to users if they meet the language and region requirements for the feature.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablequickstarter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablequickstarter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablesummaryslidesectionzoom","displayName":"Don’t allow Summary Zoom, Slide Zoom, and Section Zoom in a PowerPoint presentation (User)","description":"This policy setting controls whether users can insert and playback a Summary Zoom, a Slide Zoom, or a Section Zoom in a PowerPoint presentation. By default, users can use these types of Zoom in a presentation.\r\n\r\nIf you enable this policy setting, users can’t use these types of Zoom in a presentation.\r\n\r\nIf you disable or don’t configure this policy setting, users can use these types of Zoom in a presentation.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablesummaryslidesectionzoom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablesummaryslidesectionzoom_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_promptifpowerpointisnotdefault","displayName":"Prompt the user if PowerPoint is not the default application for its file extensions (User)","description":"This policy setting specifies whether PowerPoint prompts users to change their file extension associations for any file types that are no longer associated with PowerPoint.\r\n\r\nIf you enable this policy setting, when users start PowerPoint, they are not prompted to change file extensions for any files that are no longer associated with PowerPoint. In addition, the checkbox on the user interface (UI) under File |Options | General | Start up options | Tell me is unchecked.\r\n\r\nIf you disable or do not configure this policy setting, when users start PowerPoint, they are prompted to change file extensions for any files that are no longer associated with PowerPoint. Users can change this behavior either by selecting the checkbox displayed in the prompt, or by selecting the UI checkbox under File |Options | General | Start up options | Tell me (which is selected by default).\r\n","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_promptifpowerpointisnotdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_promptifpowerpointisnotdefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions","displayName":"[Deprecated] PowerPoint Designer Options (User)","description":"Important: This policy setting is no longer supported and will be removed in a future release. Please use the \"PowerPoint Designer Options\" policy setting from the PowerPoint policy set instead.\r\n\r\nThis policy setting allows an administrator to enable or disable PowerPoint Designer","helpText":"","infoUrls":[],"categoryId":"77ca5e78-a1fe-456e-9814-034b1ea2658d","categoryName":"PowerPoint Designer","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_l_powerpointdesigneroptions","displayName":"PowerPoint Designer options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"77ca5e78-a1fe-456e-9814-034b1ea2658d","categoryName":"PowerPoint Designer","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_l_powerpointdesigneroptions_0","displayName":"Disable PowerPoint Designer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_l_powerpointdesigneroptions_73187","displayName":"Enable PowerPoint Designer","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_checkspellingasyoutype","displayName":"Check spelling as you type (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_checkspellingasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_checkspellingasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_enablecontextualspellingpolicy","displayName":"Check grammar with spelling (User)","description":"Enabling this policy to turn contextual spelling on by default.","helpText":"","infoUrls":[],"categoryId":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_enablecontextualspellingpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_enablecontextualspellingpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofitbodytexttoplaceholder","displayName":"AutoFit body text to placeholder (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b792508d-da03-4174-bcf1-666d128ee8ad","categoryName":"AutoFormat as you type","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofitbodytexttoplaceholder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofitbodytexttoplaceholder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofittitletexttoplaceholder","displayName":"AutoFit title text to placeholder (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b792508d-da03-4174-bcf1-666d128ee8ad","categoryName":"AutoFormat as you type","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofittitletexttoplaceholder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofittitletexttoplaceholder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_replacestraightquoteswithsmartquotes","displayName":"Replace straight quotes with smart quotes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b792508d-da03-4174-bcf1-666d128ee8ad","categoryName":"AutoFormat as you type","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_replacestraightquoteswithsmartquotes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_replacestraightquoteswithsmartquotes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_defaultfilelocation","displayName":"Default file location (User)","description":"Specifies the default location for presentation files.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_defaultfilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_defaultfilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_defaultfilelocation_l_defaultfilelocation0","displayName":"Default file location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_disablepackageforcd","displayName":"Disable Package For CD (User)","description":"Check to Disable Package for CD; Uncheck to Enable Package for CD. Shows or hides the File tab | Save & Send | Package Presentation for CD command. Package for CD allows the user to package and burn presentations onto CD for portable viewing even when PowerPoint is not installed.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_disablepackageforcd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_disablepackageforcd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_keeplastautosavedversions","displayName":"Keep the last AutoSaved versions of files for the next session (User)","description":"This policy setting determines whether PowerPoint keeps the last AutoSaved version of a file if a user closes a file without saving it. (Note: AutoSave applies only when AutoRecover is enabled.)\r\n\r\nIf you enable or do not configure this policy setting, PowerPoint keeps the last AutoSaved version of the file and makes it available to the user the next time the file is opened if the user closes a file without saving it.\r\n\r\nIf you disable this policy setting, PowerPoint does not keep the last AutoSaved version of the file if the user closes a file without saving it.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_keeplastautosavedversions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_keeplastautosavedversions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo","displayName":"Save AutoRecover info (User)","description":"Checked: Checks the option ''Save AutoRecover info''. | Unchecked: Unchecks the option ''Save AutoRecover info''.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_l_autorecoversavefrequencyminutes","displayName":"AutoRecover save frequency (minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_l_autorecoversavelocation","displayName":"AutoRecover save location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_l_enablesaveautorecoverinfo","displayName":"Enable save AutoRecover info (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_l_enablesaveautorecoverinfo_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_l_enablesaveautorecoverinfo_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas","displayName":"Default file format (User)","description":"This policy setting governs the default format for new presentation files that users create.\r\n \r\nIf you enable this policy setting, when a user creates a new blank presentation, it is in the specified default format. Users may still override the default and specify a specific format when they create a presentation.\r\n\r\nIf you disable or do not configure this policy setting, PowerPoint Presentation is the default option.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_l_savepowerpointfilesas1","displayName":"Save PowerPoint files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_l_savepowerpointfilesas1_27","displayName":"PowerPoint Presentation (*.pptx)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_l_savepowerpointfilesas1_28","displayName":"PowerPoint Macro-Enabled Presentation (*.pptm)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_l_savepowerpointfilesas1_0","displayName":"PowerPoint 97-2003 Presentation (*.ppt)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_l_savepowerpointfilesas1_52","displayName":"OpenDocument Presentation (*.odp)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_turnofffileformatcompatiblitydialogforodp","displayName":"Suppress file format compatibility dialog box for OpenDocument Presentation format (User)","description":"This policy setting allows you to enable or disable the file format compatibility dialog box when saving a file as an OpenDocument presentation file in Microsoft PowerPoint.\r\n\r\nIf you enable this policy, the file format compatibility dialog is displayed whenever you save as an OpenDocument presentation file in PowerPoint.\r\n\r\nIf you disable this policy, the file format compatibility dialog is not displayed when you save as an OpenDocument presentation file in PowerPoint.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_turnofffileformatcompatiblitydialogforodp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_turnofffileformatcompatiblitydialogforodp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt","displayName":"Scan encrypted macros in PowerPoint Open XML presentations (User)","description":"This policy setting controls whether encrypted macros in Open XML presentations are required to be scanned with anti-virus software before being opened.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n- Scan encrypted macros: encrypted macros are disabled unless anti-virus software is installed. Encrypted macros are scanned by your anti-virus software when you attempt to open an encrypted presentation that contains macros.\r\n- Scan if anti-virus software available: if anti-virus software is installed, scan the encrypted macros first before allowing them to load. If anti-virus software is not available, allow encrypted macros to load.\r\n- Load macros without scanning: do not check for anti-virus software and allow macros to be loaded in an encrypted file.\r\n\r\nIf you disable or do not configure this policy setting, the behavior will be similar to the \"Scan encrypted macros\" option.","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt_l_determinewhethertoforceencryptedpptdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt_l_determinewhethertoforceencryptedpptdropid_0","displayName":"Scan encrypted macros (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt_l_determinewhethertoforceencryptedpptdropid_1","displayName":"Scan if anti-virus software available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt_l_determinewhethertoforceencryptedpptdropid_2","displayName":"Load macros without scanning","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_downloadimages","displayName":"Unblock automatic download of linked images (User)","description":"This policy setting determines whether PowerPoint automatically downloads links from external sources.\r\n\r\nIf you enable this policy setting, PowerPoint will load images saved in remote locations.\r\n\r\nIf you disable or do not configure this policy setting, when PowerPoint opens a presentation it does not display any linked images saved on a different computer unless the presentation itself is saved in a trusted location (as configured in the Trust Center).","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_downloadimages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_downloadimages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_makehiddenmarkupvisible","displayName":"Make hidden markup visible (User)","description":"This policy setting controls whether hidden markup is visible when users open PowerPoint files in standard or HTML format.\r\n\r\nIf you enable this policy setting, PowerPoint ignores this flag when opening a file, and always displays any markup present in the file. In addition, when saving a file, PowerPoint sets the flag to display markup when the presentation is next opened.\r\n\r\nIf you disable this policy setting, PowerPoint sets the flag according to the state of the \"Show Markup\" option on the Review tab of the Ribbon when it saves presentations in standard or HTML format. In addition, PowerPoint enables or disables the \"Show Markup\" option according to the way the flag is set when it opens files, which means that a presentation saved with hidden markup is opened with the markup still hidden.\r\n\r\nIf you disable this policy setting, the behavior is the equivalent of Enabled.","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_makehiddenmarkupvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_makehiddenmarkupvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms","displayName":"Run Programs (User)","description":"This policy setting controls the prompting and activation behavior for the \"Run Programs\" option for action buttons in PowerPoint.\r\n\r\nIf you enable this policy setting, you can choose from three options to control how the \"Run Programs\" option functions:\r\n\r\n- Disable (don't run any programs). If users click an action button with the \"Run Programs\" action assigned to it, nothing will happen. This option enforces the default configuration in PowerPoint.\r\n\r\n- Enable (prompt user before running). If users click an action button with the \"Run Programs\" action assigned to it, PowerPoint will prompt them to continue before running the program.\r\n\r\n- Enable all (run without prompting). If users click an action button with the \"Run Programs\" action assigned to it. PowerPoint will run the program automatically, without prompting.\r\n\r\nIf you disable or do not configure this policy setting, if users click an action with the \"Run Programs\" action assigned to it, nothing will happen. This behavior is the same as Enabled -- Disable (don't run any programs).","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty_0","displayName":"disable (don't run any programs)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty_1","displayName":"enable (prompt user before running)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty_2","displayName":"enable all (run without prompting)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_turnofffilevalidation","displayName":"Turn off file validation (User)","description":"This policy setting allows you turn off the file validation feature.\r\n\r\nIf you enable this policy setting, file validation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, file validation will be turned on. Office Binary Documents (97-2003) are checked to see if they conform against the file format schema before they are opened.","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_turnofffilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_turnofffilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setparametersforcngcontext","displayName":"Set parameters for CNG context (User)","description":"This policy setting allows you to specify the encryption parameters that should be used for the CNG context. \r\n\r\nIf you enable this policy setting, the parameters specified will be passed to the CNG context.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG values will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setparametersforcngcontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setparametersforcngcontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm","displayName":"Specify CNG random number generator algorithm (User)","description":"This policy setting allows you to configure the CNG random number generator to use.\r\n\r\nIf you enable this policy setting, the random number generator specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default random number generator will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_l_specifycngrandomnumbergeneratoralgorithmid","displayName":"Random number generator: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngsaltlength","displayName":"Specify CNG salt length (User)","description":"This policy setting allows you to specific the number of bytes of salt that should be used.\r\n\r\nIf you enable this policy setting, the bytes specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default length or 16 will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngsaltlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngsaltlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility","displayName":"Specify encryption compatibility (User)","description":"This policy setting allows you to specify the encrypted database compatibility.\r\n\r\nIf you enable this policy setting, the compatibility format specified will be applied during encryption for new files\r\n- Use legacy format\r\n- Use next generation format\r\n- All files save with next generation: All files save with the next generation format\r\n\r\nIf you disable or do not configure this policy setting, the default setting, \"Use next generation format,\" will be applied.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_0","displayName":"Use legacy format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_1","displayName":"Use next generation format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_2","displayName":"All files save with next generation","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_usenewkeyonpasswordchange","displayName":"Use new key on password change (User)","description":"This policy setting allows you to specify if a new encryption key is used when the password is changed.\r\n\r\nIf you enable or do not configure this policy setting, a new intermediate key is generated when the password is changed. This causes any extra key encryptors to be removed when the file is saved.\r\n\r\nIf you disable this policy setting, a new intermediate key is not generated when the password is changed.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_usenewkeyonpasswordchange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_usenewkeyonpasswordchange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User) (Deprecated)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve","displayName":"Set maximum number of trust records to preserve (User)","description":"This policy setting allows you to specify the maximum number of trust records to preserve when the purge task detects that this application has trusted more than the number of trusted documents set by the \"Set maximum number of trusted documents\" policy setting.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of trust records to preserve, with an upper limit of 20000. Due to performance reasons, it is not recommended to set it to the upper limit.\r\n\r\nIf you disable or you do not configure this policy setting, the default value for of 400 is used.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_l_setmaximumnumberoftrustrecordstopreservespinid","displayName":"Maximum to preserve: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject","displayName":"Trust access to Visual Basic Project (User)","description":"This policy setting controls whether automation clients such as Microsoft Visual Studio 2005 Tools for Microsoft Office (VSTO) can access the Visual Basic for Applications project system in the specified applications. VSTO projects require access to the Visual Basic for Applications project system in Excel, PowerPoint, and Word, even though the projects do not use Visual Basic for Applications. Design-time support of controls in both Visual Basic and C# projects depends on the Visual Basic for Applications project system in Word and Excel.\r\n\r\nIf you enable this policy setting, VSTO and other automation clients can access the Visual Basic for Applications project system in the specified applications. Users will not be able to change this behavior through the \"Trust access to the VBA project object model\" user interface option under the Macro Settings section of the Trust Center.\r\n\r\nIf you disable this policy setting, VSTO does not have programmatic access to VBA projects. In addition, the \"Trust access to the VBA project object model\" check box is cleared and users cannot change it. Note: Disabling this policy setting prevents VSTO projects from interacting properly with the VBA project system in the selected application.\r\n\r\nIf you do not configure this policy setting, automation clients do not have programmatic access to VBA projects. Users can enable this by selecting the \"Trust access to the VBA project object model\" in the \"Macro Settings\" section of the Trust Center. However, doing so allows macros in any documents the user opens to access the core Visual Basic objects, methods, and properties, which represents a potential security hazard.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocuments","displayName":"Turn off trusted documents (User)","description":"This policy setting allows you to turn off the trusted documents feature. The trusted documents feature allows users to always enable active content in documents such as macros, ActiveX controls, data connections, etc. so that they are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.\r\n\r\nIf you enable this policy setting, you will turn off the trusted documents feature. Users will receive a security prompt every time a document containing active content is opened.\r\n\r\nIf you disable or do not configure this policy setting, documents will be trusted when users enable content for a document, and users will not receive a security prompt.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork","displayName":"Turn off Trusted Documents on the network (User)","description":"This policy setting allows you to turn off the trusted documents feature for documents opened from the network.\r\n\r\nIf you enable this policy setting, users will always see security notifications for active content such as macros, ActiveX controls, data connections, etc. for documents opened from the network.\r\n\r\nIf you disable or do not configure this policy setting, the trusted documents feature allows users to always allow active content in documents such as macros, ActiveX controls, data connections, etc. so that users are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty3","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty3_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty3_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty3_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty3_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters","displayName":"Graphic Filters (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_l_graphicfiltersdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_l_graphicfiltersdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_l_graphicfiltersdropid_1","displayName":"Save blocked","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint","displayName":"Legacy converters for PowerPoint (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint","displayName":"Microsoft Office Open XML converters for PowerPoint (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles","displayName":"OpenDocument Presentation files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles","displayName":"Outline files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles_l_outlinefilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles_l_outlinefilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles_l_outlinefilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles_l_outlinefilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters","displayName":"PowerPoint beta converters (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles","displayName":"PowerPoint beta files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior","displayName":"Set default file block behavior (User)","description":"This policy setting allows you to determine if users can open, view, or edit Word files.\r\n\r\nIf you enable this policy setting, you can set one of these options:\r\n- Blocked files are not opened\r\n- Blocked files open in Protected View and can not be edited\r\n- Blocked files open in Protected View and can be edited\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the same as the \"Blocked files are not opened\" setting. Users will not be able to open blocked files.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_0","displayName":"Blocked files are not opened","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_1","displayName":"Blocked files open in Protected View and can not be edited","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_2","displayName":"Blocked files open in Protected View and can be edited","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages","displayName":"Web Pages (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview","displayName":"Do not open files from the Internet zone in Protected View (User)","description":"This policy setting allows you to determine if files downloaded from the Internet zone open in Protected View.\r\n\r\nIf you enable this policy setting, files downloaded from the Internet zone do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files downloaded from the Internet zone open in Protected View.","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview","displayName":"Do not open files in unsafe locations in Protected View (User)","description":"This policy setting lets you determine if files located in unsafe locations will open in Protected View. If you have not specified unsafe locations, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders are considered unsafe locations.\r\n\r\nIf you enable this policy setting, files located in unsafe locations do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files located in unsafe locations open in Protected View.","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview","displayName":"Open files on local Intranet UNC in Protected View (User)","description":"This policy setting lets you determine if files on local Intranet UNC file shares open in Protected View.\r\n\r\nIf you enable this policy setting, files on local Intranet UNC file shares open in Protected View if their UNC paths appear to be within the Internet zone.\r\n\r\nIf you disable or do not configure this policy setting, files on Intranet UNC file shares do not open in Protected View if their UNC paths appear to be within the Internet zone.","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails","displayName":"Set document behavior if file validation fails (User)","description":"This policy setting controls how Office handles documents when they fail file validation. \r\n\r\nIf you enable this policy setting, you can configure the following options for files that fail file validation:\r\n\r\n- Block files completely. Users cannot open the files.\r\n- Open files in Protected View and disallow edit. Users cannot edit the files. This is also how Office handles the files if you disable this policy setting.\r\n- Open files in Protected View and allow edit. Users can edit the files. This is also how Office handles the files if you do not configure this policy setting.\r\n\r\nIf you disable this policy setting, Office follows the \"Open files in Protected View and disallow edit\" behavior.\r\n\r\nIf you do not configure this policy setting, Office follows the \"Open files in Protected View and allow edit\" behavior.","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_0","displayName":"Block files","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_1","displayName":"Open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3","displayName":"Checked: Allow edit. Unchecked: Do not allow edit. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook","displayName":"Turn off Protected View for attachments opened from Outlook (User)","description":"This policy setting allows you to determine if PowerPoint files in Outlook attachments open in Protected View.\r\n\r\nIf you enable this policy setting, Outlook attachments do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, Outlook attachments open in Protected View.","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork","displayName":"Allow Trusted Locations on the network (User)","description":"This policy setting controls whether trusted locations on the network can be used.\r\n\r\nIf you enable this policy setting, users can specify trusted locations on network shares or in other remote locations that are not under their direct control by clicking the \"Add new location\" button in the Trusted Locations section of the Trust Center. Content, code, and add-ins are allowed to load from trusted locations with minimal security and without prompting the user for permission.\r\n\r\nIf you disable this policy setting, the selected application ignores any network locations listed in the Trusted Locations section of the Trust Center. \r\n\r\nIf you also deploy Trusted Locations via Group Policy, you should verify whether any of them are remote locations. If any of them are remote locations and you do not allow remote locations via this policy setting, those policy keys that point to remote locations will be ignored on client computers.\r\n\r\nDisabling this policy setting does not delete any network locations from the Trusted Locations list, but causes disruption for users who add network locations to the Trusted Locations list. Users are also prevented from adding new network locations to the Trusted Locations list in the Trust Center. We recommended that you do not enable this policy setting (as the \"Allow Trusted Locations on my network (not recommended)\" check box also states). Therefore, in practice, it should be possible to disable this policy setting in most situations without causing significant usability issues for most users.\r\n\r\nIf you do not enable this policy setting, users can select the \"Allow Trusted Locations on my network (not recommended)\" check box if desired and then specify trusted locations by clicking the \"Add new location\" button.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders7","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders7_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders7_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_datecolon5","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_descriptioncolon6","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_pathcolon4","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders11","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders11_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders11_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_datecolon9","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_descriptioncolon10","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_pathcolon8","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders15","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders15_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders15_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_datecolon13","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_descriptioncolon14","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_pathcolon12","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders19","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders19_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders19_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_datecolon17","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_descriptioncolon18","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_pathcolon16","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders23","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders23_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders23_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon21","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_descriptioncolon22","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_pathcolon20","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_datecolon25","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_descriptioncolon26","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_pathcolon24","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders31","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders31_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders31_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_datecolon29","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_descriptioncolon30","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_pathcolon28","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders35","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders35_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders35_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_datecolon33","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders39","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders39_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders39_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_descriptioncolon38","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_pathcolon36","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11","displayName":"Trusted Location #11 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders43","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders43_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders43_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_descriptioncolon42","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_pathcolon40","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders47","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders47_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_datecolon45","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_descriptioncolon46","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_pathcolon44","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders51","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders51_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_datecolon49","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_descriptioncolon50","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_pathcolon48","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders55","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders55_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders55_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_descriptioncolon54","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders59","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders59_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_datecolon57","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_descriptioncolon58","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_pathcolon56","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders63","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders63_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders63_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_datecolon61","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_pathcolon60","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders67","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders67_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders67_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_pathcolon64","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders71","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders71_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders71_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_datecolon69","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_descriptioncolon70","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_pathcolon68","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders75","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders75_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders75_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_datecolon73","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_descriptioncolon74","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_pathcolon72","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders79","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders79_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders79_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_datecolon77","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_descriptioncolon78","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_pathcolon76","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles","displayName":"PowerPoint 2007 and later presentations, shows, templates, themes and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles","displayName":"PowerPoint 97-2003 presentations, shows, templates and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v3~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingsectionname","displayName":"Stop checking for Section with valid name (User)","description":"This policy setting prevents the Accessibility Checker from flagging section with default/untitled name.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging section with default/untitled name.\r\n\r\nIf you disable or do not configure this policy setting, section will be scanned for valid name and the results will appear in the Accessibility Checker.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v3~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingsectionname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v3~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingsectionname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v3~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckinguniquesectionname","displayName":"Stop checking for section with unique name (User)","description":"This policy setting prevents the Accessibility Checker from verifying that every section has a unique name.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that every section has a unique name.\r\n\r\nIf you disable or do not configure this policy setting, sections will be checked for unique names and any issues will appear in the Accessibility Checker.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v3~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckinguniquesectionname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v3~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckinguniquesectionname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v4~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_enablemoderncommentscreatenew","displayName":"Use modern comments in PowerPoint (User)","description":"\r\nThis policy setting controls whether modern comments are used in PowerPoint. For more information about modern comments and when to enable this setting, see https://go.microsoft.com/fwlink/p/?linkid=2116065.\r\n\r\nIf you enable this policy setting, when a user adds comments to a new file or a file without comments, the new comments that are added will be modern comments. If users have a version of PowerPoint that doesn’t support modern comments, a notification appears directing them to use PowerPoint for the web to view modern comments in files that have them.\r\n\r\nIf you disable this policy setting, users will continue to see the previous commenting experience for new files and existing files that do not have any modern comments. Users will still be able to read files that already have modern comments in them if they have a version of PowerPoint that supports modern comments.\r\n\r\nFor information about what happens when you don't configure this policy setting, see https://go.microsoft.com/fwlink/p/?linkid=2116065.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v4~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_enablemoderncommentscreatenew_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v4~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_enablemoderncommentscreatenew_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions","displayName":"OLE Active Content (User)","description":"This policy setting controls the prompting and activation behavior for the \"OLE Active Content\" option in PowerPoint.\r\n\r\nIf you enable this policy setting, you can choose from three options to control how the \"OLE Active Content\" option functions:\r\n\r\n- Disable (don't activate any OLE Active Content). If users click an action button with the \"Object action\" action assigned to it, nothing will happen.\r\n\r\n- Enable (prompt user before activating OLE Active Content). If users click an action button with the \"Object action\" action assigned to it, PowerPoint will prompt them to continue before activating the action. This option enforces the default configuration in PowerPoint.\r\n\r\n- Enable all (allow activating OLE Active Content without prompting). If users click an action button with the \"Object action\" action assigned to it. PowerPoint will activate the action automatically, without prompting.\r\n\r\nIf you do not configure this policy setting, PowerPoint follows the Enable (prompt user before activating OLE Active Content) option.","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions_l_empty_0","displayName":"disable (don't allow activating OLE Active Content)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions_l_empty_1","displayName":"enable (prompt user before activating OLE Active Content)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions_l_empty_2","displayName":"enable all (allow activating OLE Active Content without prompting)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser","displayName":"List of Approved USB-connected print devices (User)","description":"\r\n\r\n This setting is a component of the Device Control Printing Restrictions. To use this setting, enable Device Control Printing by enabling the \"Enable Device Control Printing Restrictions\" setting.\r\n\r\n When Device Control Printing is enabled, the system uses the specified list of vid/pid values to determine if the current USB connected printer is approved for local printing.\r\n\r\n Type all the approved vid/pid combinations (separated by commas) that correspond to approved USB printer models. When a user tries to print to a USB printer queue the device vid/pid will be compared to the approved list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-approvedusbprintdevicesuser"],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser_approvedusbprintdevices_list","displayName":"vid/pid (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":null},{"id":"user_vendor_msft_policy_config_printers_enabledevicecontroluser","displayName":"Enable Device Control Printing Restrictions (User)","description":"\r\n Determines whether Device Control Printing Restrictions are enforced for printing on this computer.\r\n\r\n By default, there are no restrictions to printing based on connection type or printer Make/Model.\r\n\r\n If you enable this setting, the computer will restrict printing to printer connections on the corporate network or approved USB-connected printers.\r\n\r\n If you disable this setting or do not configure it, there are no restrictions to printing based on connection type or printer Make/Model.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-enabledevicecontroluser"],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_enabledevicecontroluser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_enabledevicecontroluser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user","displayName":"Point and Print Restrictions (User)","description":"This policy setting controls the client Point and Print behavior, including the security prompts for Windows Vista computers. The policy setting applies only to non-Print Administrator clients, and only to computers that are members of a domain.\n\n If you enable this policy setting:\n -Windows XP and later clients will only download print driver components from a list of explicitly named servers. If a compatible print driver is available on the client, a printer connection will be made. If a compatible print driver is not available on the client, no connection will be made.\n -You can configure Windows Vista clients so that security warnings and elevated command prompts do not appear when users Point and Print, or when printer connection drivers need to be updated.\n\n If you do not configure this policy setting:\n -Windows Vista client computers can point and print to any server.\n -Windows Vista computers will show a warning and an elevated command prompt when users create a printer connection to any server using Point and Print.\n -Windows Vista computers will show a warning and an elevated command prompt when an existing printer connection driver needs to be updated.\n -Windows Server 2003 and Windows XP client computers can create a printer connection to any server in their forest using Point and Print.\n\n If you disable this policy setting:\n -Windows Vista client computers can create a printer connection to any server using Point and Print.\n -Windows Vista computers will not show a warning or an elevated command prompt when users create a printer connection to any server using Point and Print.\n -Windows Vista computers will not show a warning or an elevated command prompt when an existing printer connection driver needs to be updated.\n -Windows Server 2003 and Windows XP client computers can create a printer connection to any server using Point and Print.\n -The \"Users can only point and print to computers in their forest\" setting applies only to Windows Server 2003 and Windows XP SP1 (and later service packs).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-pointandprintrestrictions-user"],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationoninstall_enum","displayName":"When installing drivers for a new connection: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationoninstall_enum_0","displayName":"Show warning and elevation prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationoninstall_enum_1","displayName":"Show warning only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationonupdate_enum","displayName":"When updating drivers for an existing connection: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationonupdate_enum_0","displayName":"Show warning and elevation prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationonupdate_enum_1","displayName":"Show warning only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedforest_chk","displayName":"Users can only point and print to machines in their forest (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedforest_chk_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedforest_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedservers_chk","displayName":"Users can only point and print to these servers: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedservers_chk_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedservers_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedservers_edit","displayName":"Enter fully qualified server names separated by semicolons (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":null},{"id":"user_vendor_msft_policy_config_privacy_disableprivacyexperience","displayName":"Disable Privacy Experience (User)","description":"Enabling this policy prevents the privacy experience from launching during user logon for new and upgraded users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#disableprivacyexperience"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"user_vendor_msft_policy_config_privacy_disableprivacyexperience_0","displayName":"Disabled","description":"Allow the 'choose privacy settings for your device' screen for a new user during their first logon or when an existing user logs in for the first time after an upgrade.","helpText":null},{"id":"user_vendor_msft_policy_config_privacy_disableprivacyexperience_1","displayName":"Enabled","description":"Do not allow the 'choose privacy settings for your device' screen when a new user logs in or an existing user logs in for the first time after an upgrade.","helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_defaultcustomtab","displayName":"Show custom templates tab by default in Project on the Office Start screen and in File | New (User)","description":"This policy setting controls whether custom templates (when they exist) show as the default tab in Project on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, users will the see custom templates tab as the default tab in Project on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Project on the Office Start screen and in File | New, unless all Office-provided templates have been disabled.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_defaultcustomtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_defaultcustomtab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_disableofficestartproject","displayName":"Disable the Office Start screen for Project (User)","description":"This policy setting controls whether the Office Start screen appears on boot for Project.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot Project.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot Project.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_disableofficestartproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_disableofficestartproject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\MS Project\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\MS Project\\Addins.\r\n\r\nYou can also obtain the ProgID of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength","displayName":"Most Recently Used Template List Length (User)","description":"This setting determines the length of the recently used templates list in the New Document task pane (File New...). The maximum value is 9 and the minimum value is 0. This setting applies only applies to Project.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength_l_mrutemplatelistlength39","displayName":"Most Recently Used Template List Length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath","displayName":"Personal templates path for Project (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"8e48532a-ff0e-4422-82e2-6956b6786005","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjautocalc","displayName":"Automatic Calculation (User)","description":"Specifies that calculations should be done automatically as soon as a change is made.\r\n\r\nIf you enable this setting, calculations will be made after every change to the project.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"ed137c3d-d7bc-48f3-ad86-ff194fc6820d","categoryName":"Calculation options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjautocalc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjautocalc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjcalcall","displayName":"Calculate all open projects (User)","description":"Specifies that Project should recalculate all open projects.\r\n\r\nIf you enable this setting, all open projects will be recalculated anytime Project does a calculation.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"ed137c3d-d7bc-48f3-ad86-ff194fc6820d","categoryName":"Calculation options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjcalcall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjcalcall_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjactualcostscalc","displayName":"Actual costs are always calculated by Microsoft Project (User)","description":"Specifies that Project calculates actual costs automatically, based upon resource rates, per-use resource costs, and fixed task costs.\r\n\r\nIf you enable this setting, Project will automatically calculate actual costs.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjactualcostscalc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjactualcostscalc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmovecompleted","displayName":"And move end of completed parts forward to status date (User)","description":"Moves the completed portion of a task forward to finish at the status date.\r\n\r\nIf you enable this setting, the completed portion of the task moves forward to finish at the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmovecompleted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmovecompleted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmoveremaining","displayName":"And move start of remaining parts back to status date (User)","description":"Moves the remaining portion of a task back to start at the status date.\r\n\r\nIf you enable this setting, the remaining portion of the task moves back to start at the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmoveremaining_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmoveremaining_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcalcmultiplecriticalpaths","displayName":"Calculate multiple critical paths (User)","description":"Specifies that Project should calculate and display a critical path for each independent network of tasks within the project.\r\n\r\nIf you enable this setting, Project will calculate multiple critical paths.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcalcmultiplecriticalpaths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcalcmultiplecriticalpaths_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcritifless","displayName":"Tasks are critical if slack is less than or equal to (User)","description":"Specifies the number of days of slack Project uses to determine critical tasks.\r\n\r\nIf you enable this setting, tasks are marked as critical if the slack is less than or equal to the value you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcritifless_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcritifless_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcritifless_l_pjcritifless29","displayName":"Tasks are critical if slack is less than or equal to (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual","displayName":"Default fixed costs accrual (User)","description":"Specifies how Project sets the fixed cost accrual for new tasks.\r\n\r\nIf you enable this setting, new tasks will accrue fixed cost according to the specification you made.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_l_pjdefaultfixedaccrual28","displayName":"Default fixed costs accrual (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_l_pjdefaultfixedaccrual28_1","displayName":"Start","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_l_pjdefaultfixedaccrual28_3","displayName":"Prorated","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_l_pjdefaultfixedaccrual28_2","displayName":"End","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjeditstototaltask","displayName":"Edits to total task % complete will be spread to the status date (User)","description":"Distributes the changes to total percent complete evenly across the schedule to the project status date (or to the current date if you haven't specified a project status date).\r\n\r\nIf you enable this setting, edits to total task percent complete are evenly distributed across the schedule up to the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjeditstototaltask_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjeditstototaltask_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjedittototalspread","displayName":"Edits to total actual cost will be spread to the status date (User)","description":"Distributes the changes to total actual cost evenly across the schedule to the status date (or to the current date if you have not specified a project status date).\r\n\r\nIf you enable this setting, Project will distribute edits to actual cost evenly across a task up to the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjedittototalspread_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjedittototalspread_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjinsertedprojects","displayName":"Inserted projects are calculated like summary tasks (User)","description":"Specifies that a single critical path is calculated throughout the master project, by treating inserted projects as summary tasks in the master project.\r\n\r\nIf you enable this setting, the critical path is calculated by treating inserted projects as summary tasks.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjinsertedprojects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjinsertedprojects_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjmovecompleted","displayName":"Move end of completed parts after status date back to status date (User)","description":"Moves the completed portion of a task back to finish at the status date.\r\n\r\nIf you enable this setting, the completed portion of the task moves back to finish at the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjmovecompleted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjmovecompleted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjmoveremaining","displayName":"Move start of remaining parts before status date forward to status date (User)","description":"Moves remaining portions of a task forward to start at the status date.\r\n\r\nIf you enable this setting, the remaining portion of the task moves forward to start at the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjmoveremaining_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjmoveremaining_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjupdatingtask","displayName":"Updating task status updates resource status (User)","description":"Automatically updates resource status, such as actual and remaining work and cost, whenever you update task status, such as percent complete, actual duration, or remaining duration.\r\n\r\nIf you enable this setting, task status updates are automatically applied to resources.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjupdatingtask_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjupdatingtask_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline","displayName":"Baseline for Earned Value calculations (User)","description":"Specifies the baseline that is used to measure project performance using earned value analysis.\r\n\r\nIf you enable this setting, Project will calculate earned value using the baseline you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"acbc106b-796a-4ba3-ab5f-c130530ad455","categoryName":"Earned Value options for Project1","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27","displayName":"Baseline for Earned Value calculations (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acbc106b-796a-4ba3-ab5f-c130530ad455","categoryName":"Earned Value options for Project1","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_1","displayName":"Baseline","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_12","displayName":"Baseline 1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_13","displayName":"Baseline 2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_14","displayName":"Baseline 3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_15","displayName":"Baseline 4","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_16","displayName":"Baseline 5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_17","displayName":"Baseline 6","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_18","displayName":"Baseline 7","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_19","displayName":"Baseline 8","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_20","displayName":"Baseline 9","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_21","displayName":"Baseline 10","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod","displayName":"Default task Earned Value method (User)","description":"Specifies the method used for earned value analysis.\r\n\r\nIf you enable this setting, Project will calculate earned value using the method you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"acbc106b-796a-4ba3-ab5f-c130530ad455","categoryName":"Earned Value options for Project1","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_l_pjevmethod26","displayName":"Default task Earned Value method (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acbc106b-796a-4ba3-ab5f-c130530ad455","categoryName":"Earned Value options for Project1","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_l_pjevmethod26_0","displayName":"% Complete","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_l_pjevmethod26_1","displayName":"Physical % Complete","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdayspermonth","displayName":"Days per month (User)","description":"Defines the number of days that you want Project to assign to a task when you enter a duration of a month.\r\n\r\nIf you enable this setting, month-long tasks will be assigned the number of days that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdayspermonth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdayspermonth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdayspermonth_l_pjdayspermonth20","displayName":"Days per month (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultendtime","displayName":"Default end time (User)","description":"Specifies the finish time that Project assigns to tasks by default when you enter a finish date without specifying a time.\r\n\r\nIf you enable this setting, new tasks where the user does not enter an end time will have the end time that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultendtime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultendtime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultendtime_l_pjdefaultendtime2","displayName":"Default end time (Minutes after 12am * 10) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultstarttime","displayName":"Default start time (User)","description":"Specifies the start time that Project assigns to tasks by default when you enter a start date without specifying a time.\r\n\r\nIf you enable this setting, new tasks where the user does not enter a start time will use the start time that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultstarttime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultstarttime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultstarttime_l_pjdefaultstarttime2","displayName":"Default start time (Minutes after 12am * 10) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear","displayName":"Fiscal year starts in (User)","description":"Specifies the month that begins the fiscal year.\r\n\r\nIf you enable this setting, the fiscal year will start on the month you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17","displayName":"Fiscal year starts in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_1","displayName":"January","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_2","displayName":"February","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_3","displayName":"March","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_4","displayName":"April","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_5","displayName":"May","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_6","displayName":"June","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_7","displayName":"July","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_8","displayName":"August","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_9","displayName":"September","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_10","displayName":"October","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_11","displayName":"November","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_12","displayName":"December","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday","displayName":"Hours per day (User)","description":"Defines the number of hours that you want Project to assign to a task when the user enters a duration of one day.\r\n\r\nIf you enable this setting, day-long tasks will be assigned the number of hours that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday_l_pjhoursperday18","displayName":"Hours per day (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperweek","displayName":"Hours per week (User)","description":"Specifies the number of hours that you want Project to assign to a task when the user enters a duration of one week.\r\n\r\nIf you enable this setting, week-long tasks will be assigned the number of hours that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperweek_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperweek_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperweek_l_pjhoursperweek19","displayName":"Hours per week (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjstartingyear","displayName":"Use starting year for FY numbering (User)","description":"Labels the fiscal year using the calendar year in which the fiscal year begins.\r\n\r\nIf you enable this setting, the label for the fiscal year is the calendar year in which the fiscal year begins.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjstartingyear_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjstartingyear_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts","displayName":"Week starts on (User)","description":"Specifies the day of the week on which you want the scheduling week to begin.\r\n\r\nIf you enable this setting, weeks will start on the day you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16","displayName":"Week starts on (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_6","displayName":"Saturday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_0","displayName":"Sunday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_1","displayName":"Monday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_4","displayName":"Thursday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_5","displayName":"Friday","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjallowcelldragdrop","displayName":"Allow cell drag and drop (User)","description":"Allow fields in sheets to be moved using the mouse.\r\nIf you enable this setting, users can move rows and fields to new locations using the mouse.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"d33133b4-77df-429a-9580-ed70f7da676d","categoryName":"Edit options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjallowcelldragdrop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjallowcelldragdrop_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjasktoupdate","displayName":"Ask to update automatic links (User)","description":"Prompts the user to update linked objects whenever they open a file containing OLE links, if the source has changed.\r\n \r\nIf you enable this setting, users are prompted to update linked objects whose source has changed whenever they open a file containing OLE links.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"d33133b4-77df-429a-9580-ed70f7da676d","categoryName":"Edit options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjasktoupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjasktoupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjeditdirectlycell","displayName":"Edit directly in cell (User)","description":"Allows editing directly in the selected cell.\r\n \r\nIf you enable this setting, users can directly edit a cell's value.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"d33133b4-77df-429a-9580-ed70f7da676d","categoryName":"Edit options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjeditdirectlycell_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjeditdirectlycell_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjmoveafterenter","displayName":"Move selection after enter (User)","description":"Automatically selects the field below the current field after the user presses the ENTER key.\r\n \r\nIf you enable this setting, the field below the current field is selected after the user presses the ENTER key.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"d33133b4-77df-429a-9580-ed70f7da676d","categoryName":"Edit options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjmoveafterenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjmoveafterenter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour","displayName":"Followed hyperlink color (User)","description":"Specifies the color of hyperlinks that have already been followed.\r\n\r\nIf you enable this setting, hyperlinks that have been followed are displayed in the color you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15","displayName":"Followed hyperlink color (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_16","displayName":"Automatic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_0","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_1","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_2","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_3","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_4","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_5","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_6","displayName":"Fuchsia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_7","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_8","displayName":"Maroon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_9","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_10","displayName":"Olive","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_11","displayName":"Navy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_12","displayName":"Purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_13","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_14","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_15","displayName":"Silver","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour","displayName":"Hyperlink color (User)","description":"Specifies the color of hyperlinks that have not yet been followed.\r\n \r\nIf you enable this setting, hyperlinks that have not been followed are displayed in the color you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14","displayName":"Hyperlink color (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_16","displayName":"Automatic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_0","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_1","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_2","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_3","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_4","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_5","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_6","displayName":"Fuchsia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_7","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_8","displayName":"Maroon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_9","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_10","displayName":"Olive","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_11","displayName":"Navy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_12","displayName":"Purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_13","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_14","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_15","displayName":"Silver","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjunderlinelinks","displayName":"Underline hyperlinks (User)","description":"Shows hyperlinks with underlined text.\r\n\r\nIf you enable this setting, hyperlinks are underlined.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjunderlinelinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjunderlinelinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjaddspace","displayName":"Add space before label (User)","description":"Adds a space between numbers and time unit labels.\r\n \r\nIf you enable this setting, a space is displayed between numbers and the time unit label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjaddspace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjaddspace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays","displayName":"Days (User)","description":"Sets the label for days.\r\n \r\nIf you enable this setting, days are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10","displayName":"Days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_0","displayName":"d","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_1","displayName":"dy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_2","displayName":"day","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_4","displayName":"\r\n ","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours","displayName":"Hours (User)","description":"Sets the label for hours.\r\n \r\nIf you enable this setting, hours are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9","displayName":"Hours (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_0","displayName":"h","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_1","displayName":"hr","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_2","displayName":"hour","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_4","displayName":"\r\n ","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes","displayName":"Minutes (User)","description":"Sets the label for minutes.\r\n\r\nIf you enable this setting, minutes are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_l_pjminutes8","displayName":"Minutes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_l_pjminutes8_0","displayName":"m","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_l_pjminutes8_1","displayName":"min","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_l_pjminutes8_2","displayName":"minute","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_l_pjminutes8_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_l_pjminutes8_4","displayName":"\r\n ","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths","displayName":"Months (User)","description":"Sets the label for months.\r\n \r\nIf you enable this setting, months are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_l_pjmonths12","displayName":"Months (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_l_pjmonths12_0","displayName":"mo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_l_pjmonths12_1","displayName":"mon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_l_pjmonths12_2","displayName":"month","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_l_pjmonths12_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_l_pjmonths12_4","displayName":"\r\n ","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks","displayName":"Weeks (User)","description":"Sets the label for weeks.\r\n\r\nIf you enable this setting, weeks are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11","displayName":"Weeks (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_0","displayName":"w","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_1","displayName":"wk","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_2","displayName":"week","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_4","displayName":"\r\n ","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears","displayName":"Years (User)","description":"Sets the label for years.\r\n \r\nIf you enable this setting, years are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_l_pjyears13","displayName":"Years (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_l_pjyears13_0","displayName":"y","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_l_pjyears13_1","displayName":"yr","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_l_pjyears13_2","displayName":"year","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_l_pjyears13_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_l_pjyears13_4","displayName":"\r\n ","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels","displayName":"Undo Levels (User)","description":"Limits the number of actions (1-99) that a user can undo. If you enable this setting, you can set a limit on the number of actions (1-99) a user is can undo. If you disable this setting or do not configure it, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels_l_undolevels5","displayName":"Undo Levels (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","categoryName":"General","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjautoaddnew","displayName":"Automatically add new resources and tasks (User)","description":"Automatically adds new resources to the resource pool and assigns them default values whenever a new resource name or new resource's initials are added.\r\n \r\nIf you enable this setting, new resources and tasks are automatically inserted into the project.\r\n\r\nIf you disable this setting, users are alerted whenever a new resource or task is created when making a new assignment.\r\n\r\nIf you do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","categoryName":"General options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjautoaddnew_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjautoaddnew_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultotime","displayName":"Default overtime rate (User)","description":"Specifies the overtime pay rate for new resources.\r\n \r\nIf you enable this setting, all new resources will use the specified overtime pay rate\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","categoryName":"General options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultotime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultotime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultotime_l_pjdefaultotime7","displayName":"Default overtime rate (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","categoryName":"General options for 'Project1'","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultstdrate","displayName":"Default standard rate (User)","description":"Specifies the standard pay rate for new resources.\r\n \r\nIf you enable this setting, all new resources will use the specified standard pay rate.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","categoryName":"General options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultstdrate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultstdrate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultstdrate_l_pjdefaultstdrate6","displayName":"Default standard rate (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","categoryName":"General options for 'Project1'","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjopenlast","displayName":"Open last file on startup (User)","description":"Upon starting Project, automatically opens the last used project file.\r\n \r\nIf you enable this setting, the last file that the user had open automatically re-opens when they start Project.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjopenlast_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjopenlast_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjpromptforinfo","displayName":"Prompt for project info for new projects (User)","description":"Opens the Project Information dialog box whenever the user creates a new project.\r\n\r\nIf you enable this setting, the Project Information dialog box is displayed whenever you create a new project.\r\n\r\nIf you disable or do not configure this setting, the users default setting is followed.","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjpromptforinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjpromptforinfo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjrecentlyused","displayName":"Number of projects in the Recent Projects list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Projects list that appears when users click Open on the File tab in Backstage view. \r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Projects list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Projects list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjrecentlyused_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjrecentlyused_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjrecentlyused_l_pjmrut","displayName":"Number of entries: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjsetautofilter","displayName":"Set AutoFilter on for new projects (User)","description":"This policy setting turns on AutoFilter automatically when the user creates a new project.\r\n\r\nIf you enable or do not configure this policy setting, AutoFilter is automatically turned on when users create a new project.\r\n\r\nIf you disable this policy setting, AutoFilter is not automatically turned on when users create a new project.","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjsetautofilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjsetautofilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"Number of folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface_l_disableinternalidmatching","displayName":"Disable Internal ID Matching (User)","description":"Prevent internal id matching. If you enable this setting, Project will not use internal identifiers to match different-language or renamed Organizer items between projects. If this setting is disabled or not configured, internal identifiers will be used to match different-language or renamed Organizer items between projects.","helpText":"","infoUrls":[],"categoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","categoryName":"Interface","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface_l_disableinternalidmatching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface_l_disableinternalidmatching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettings_l_pjgbuidisplaytoggle","displayName":"Display Project Guide (User)","description":"Displays the side pane containing the Project Guide.\r\n\r\nIf you enable this setting, the Project Guide will be displayed.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"343eb575-3ac8-4da9-b66d-ce84b84be7c3","categoryName":"Project Guide settings","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettings_l_pjgbuidisplaytoggle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettings_l_pjgbuidisplaytoggle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage","displayName":"Project Guide Functionality and Layout page (User)","description":"Choose whether the side pane displays the default Project Guide or a custom Project Guide your organization has developed.\r\n\r\nIf you enable this setting, the Project Guide you specified will be displayed when the Project Guide is opened.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjgbuidefaultpageurl","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjusedefaultstartpage34","displayName":"Project Guide Functionality and Layout page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjusedefaultstartpage34_1","displayName":"Use Microsoft Project's Default page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjusedefaultstartpage34_0","displayName":"Use a custom page","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema","displayName":"Project Guide Content (User)","description":"Specifies whether the side pane displays the Project Guide content that comes with Project or custom content that your organization has developed.\r\n\r\nIf you enable this setting, content for the Project Guide is loaded from the specified location.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema_l_pjgbuixmlschemapath","displayName":"XML file for custom content: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema_l_pjusedefaultxmlschema35","displayName":"Project Guide Content (User)","description":"","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema_l_pjusedefaultxmlschema35_1","displayName":"Use Microsoft Project's default content","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema_l_pjusedefaultxmlschema35_0","displayName":"Use custom content","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjchangedurationooui","displayName":"Edits to work, units or duration (User)","description":"Specifies that the feedback triangle should appear in a corner of a Task Name field if you change the task's start date or finish date.\r\n\r\nIf you enable this setting, a feedback triangle is displayed in the corner of the Task Name field if the user changes the task's start or finish date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"fe7c8652-17d4-40a7-869c-f7cfc3454402","categoryName":"Show indicators and Option butons for","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjchangedurationooui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjchangedurationooui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjdeletenameooui","displayName":"Deletions in the Name column (User)","description":"Specifies that the delete indicator should appear in the Indicators field if you delete text in the Task Name or Resource Names field.\r\n\r\nIf you enable this setting, the delete indicator will appear if the user deletes a Task Name or Resource Names.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"fe7c8652-17d4-40a7-869c-f7cfc3454402","categoryName":"Show indicators and Option butons for","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjdeletenameooui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjdeletenameooui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjenterdateooui","displayName":"Edits to start and finish dates (User)","description":"Specifies that the feedback triangle should appear in a corner of the Duration field or the Task Name field if you change a task's work, units, or duration.\r\n\r\nIf you enable this setting, a feedback triangle is displayed in the corner of the Duration or Task Name field if the user changes the task's work, units, or duration.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"fe7c8652-17d4-40a7-869c-f7cfc3454402","categoryName":"Show indicators and Option butons for","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjenterdateooui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjenterdateooui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjresourceassignooui","displayName":"Resource Assigments (User)","description":"Specifies that the feedback triangle should appear in a corner of a field if the user assigns additional resources to a task that already has resources assigned.\r\n\r\nIf you enable this setting, a feedback triangle is displayed in the corner of a field if users assign additional resources to a task that already has resources assigned.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"fe7c8652-17d4-40a7-869c-f7cfc3454402","categoryName":"Show indicators and Option butons for","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjresourceassignooui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjresourceassignooui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype","displayName":"Save Microsoft Project files as (User)","description":"Specifies the default file format that should be applied when any Project file is saved.\r\n\r\nIf you enable this setting, project files will be saved with the format you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30","displayName":"Save Microsoft Project files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30_msproject.mpp.12","displayName":"Project (*.mpp)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30_msproject.mpt.12","displayName":"Template (*.mpt)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30_msproject.mpp.9","displayName":"Project 2000-2003 (*.mpp)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveoption","displayName":"Save Active Project only (User)","description":"Saves only the active project at the interval you specify. This setting is only used by Project if Auto Save is turned on.\r\n\r\nIf you enable this setting, Project will only save the active project at specified intervals.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveprompt","displayName":"Prompt before saving (User)","description":"Specifies whether Project should prompt the user before saving their project as a result of the Auto Save function.\r\n\r\nIf you enable this setting, users will be prompted before their project is automatically saved.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveprompt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveevery","displayName":"Auto Save every (User)","description":"Specifies that you want Project to automatically save your projects periodically.\r\n\r\nIf you enable this setting, Project will save users projects at the specified interval.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveevery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveevery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval","displayName":"Save Interval (User)","description":"Specifies how often Project should automatically save your projects. This setting is only used by Project if Auto Save has been turned on.\r\n\r\nIf you enable this setting, Project will save users projects at the specified interval.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval_l_pjsaveinterval33","displayName":"Save Interval (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation","displayName":"Local Project Cache Location (User)","description":"Sets the location path of the local project cache on the user's computer.","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation_l_cachelocation37","displayName":"Local Project Cache Location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachesizeperprofile","displayName":"Local Project Cache Size Limit in MB (User)","description":"Sets the size limit in MB of the local project cache. This is applied per user profile. If this setting is enabled, the size of the cache will be set to the number specified. If this setting is disabled or not configured, users are able to set the cache size limit.","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachesizeperprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachesizeperprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachesizeperprofile_l_cachesizeperprofile38","displayName":"Local Project Cache Size Limit in MB (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocprojects","displayName":"Projects (User)","description":"Specifies the default location in the computer system for saving and opening projects.\r\n\r\nIf you enable this policy setting, the location first appears in the Open and Save As dialog box.\r\n\r\nIf you disable or do not configure this policy setting, the users default for this setting is followed.","helpText":"","infoUrls":[],"categoryId":"d679b407-a753-40aa-bc9f-175f363b0eff","categoryName":"File locations","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocprojects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocprojects_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocprojects_l_pjfilelocprojects31","displayName":"Projects (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d679b407-a753-40aa-bc9f-175f363b0eff","categoryName":"File locations","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocusertemplates","displayName":"User Templates (User)","description":"Specifies the default location in the computer system for saving and opening workgroup templates.\r\n\r\nIf you enable this policy setting, the location first appears in the Open and Save As dialog box.\r\n\r\nIf you disable or do not configure this policy setting, the users default for this setting is followed.","helpText":"","infoUrls":[],"categoryId":"d679b407-a753-40aa-bc9f-175f363b0eff","categoryName":"File locations","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocusertemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocusertemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocusertemplates_l_pjfilelocusertemplates32","displayName":"User Templates (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d679b407-a753-40aa-bc9f-175f363b0eff","categoryName":"File locations","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_keeptasksonnearestworkingday","displayName":"Keep tasks on nearest working day (User)","description":"This policy setting will enable a constraint to be applied to tasks when they are toggled from Manually Scheduled Mode to Automatically Scheduled Mode, allowing the task date to be as close to the user-entered date as possible.\r\n\r\nIf you enable this policy setting, the task date will be as close to the user-entered date as possible when tasks are toggled from Manually Scheduled Mode to Automatically Scheduled Mode.\r\n\r\nIf you disable or do not configure this policy setting, the task date will not to be as close to the user-entered date when tasks are toggled from Manually Scheduled Mode to Automatically Scheduled Mode.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_keeptasksonnearestworkingday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_keeptasksonnearestworkingday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjautolinktasks","displayName":"Autolink inserted or moved tasks (User)","description":"This policy setting automatically links tasks when you cut, move, or insert them.\r\n\r\nIf you enable this policy setting, tasks will automatically be linked when you cut, move, or insert them.\r\n\r\nIf you disable or do not configure this policy setting, tasks will not automatically be linked when you cut, move, or insert them.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjautolinktasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjautolinktasks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes","displayName":"Default task type (User)","description":"Specifies the default task type for new tasks.\r\n\r\nIf you enable this setting, new tasks will be set to the type that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes_l_pjdefaulttasktypes25","displayName":"Default task type (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes_l_pjdefaulttasktypes25_1","displayName":"Fixed Duration","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes_l_pjdefaulttasktypes25_0","displayName":"Fixed Units","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes_l_pjdefaulttasktypes25_2","displayName":"Fixed Work","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits","displayName":"Duration is entered in (User)","description":"Specifies the unit of time (minutes, hours, days, weeks, or months) used by default in the Duration field.\r\n\r\nIf you enable this setting, the unit you specify will be used if the user does not specify a unit of time when entering a duration.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23","displayName":"Duration is entered in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_3","displayName":"Minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_5","displayName":"Hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_7","displayName":"Days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_9","displayName":"Weeks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_11","displayName":"Months","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks","displayName":"New tasks (User)","description":"Specifies the default start date for new tasks as they are entered in the current project. For projects scheduled from the start date, the options are \"Start on Project Start Date\" and \"Start on Current Date.\" For projects scheduled from the finish date, the options are \"Finish on Project Finish Date\" and \"Start on Current Date.\"\r\n\r\nIf you enable this setting, new tasks will start on the date you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_l_pjnewtasks22","displayName":"New tasks (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_l_pjnewtasks22_0","displayName":"Start on Project Start Date","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_l_pjnewtasks22_1","displayName":"Start on Current Date","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtaskseffort","displayName":"New tasks are effort driven (User)","description":"This policy setting specifies that new tasks are scheduled such that the work on the task remains constant as you add or remove assignments.\r\n\r\nIf you enable this policy setting, new tasks will be effort-driven.\r\n\r\nIf you disable or do not configure this policy setting, new tasks will not be effort-driven.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtaskseffort_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtaskseffort_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasksestdurations","displayName":"New tasks have estimated durations (User)","description":"Specifies that all new tasks have estimated durations.\r\n\r\nIf you enable this setting, all new tasks will require estimated durations.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasksestdurations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasksestdurations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjshowestimateddurations","displayName":"Show that tasks have estimated durations (User)","description":"Displays a question mark (?) after the duration unit of any task with an estimated duration.\r\n\r\nIf you enable this setting, tasks with estimated durations have a question mark after their duration unit.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjshowestimateddurations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjshowestimateddurations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjsplitinprogresstasks","displayName":"Split in-progress tasks (User)","description":"Allows rescheduling of remaining duration and work when a task slips or reports progress ahead of schedule.\r\n\r\nIf you enable this setting, the remaining duration and work will be rescheduled if a task slips or reports progress ahead of schedule.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjsplitinprogresstasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjsplitinprogresstasks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjtaskshonorconstraints","displayName":"Tasks will always honor their constraint dates (User)","description":"Specifies that Project schedules tasks according to their constraint dates.\r\n\r\nIf you enable this setting, task constraints will always be honored when tasks are scheduled.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjtaskshonorconstraints_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjtaskshonorconstraints_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits","displayName":"Work is entered in (User)","description":"Specifies the default unit of time (minutes, hours, days, weeks, or months) used in the Work field in the current project.\r\n\r\nIf you enable this setting, whenever Project displays work values, the unit you specified will be used.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_l_pjworkunits24","displayName":"Work is entered in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_l_pjworkunits24_3","displayName":"Minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_l_pjworkunits24_5","displayName":"Hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_l_pjworkunits24_7","displayName":"Days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_l_pjworkunits24_9","displayName":"Weeks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_l_pjworkunits24_11","displayName":"Months","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_setdefaultstartdatefornewtasks","displayName":"Set default start date for new tasks (User)","description":"This policy setting specifies the default start date for new tasks as they are entered in the current project. For projects scheduled from the start date, the options are \"Start on Project Start Date\" and \"Start on Current Date.\" For projects scheduled from the finish date, the options are \"Finish on Project Finish Date\" and \"Start on Current Date.\"\r\n\r\nIf you enable or do not configure this policy setting, new tasks will start on the project start date.\r\n\r\nIf you disable this policy setting, new tasks will not start on the project start date.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_setdefaultstartdatefornewtasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_setdefaultstartdatefornewtasks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_setnewtaskstobeautomaticallyscheduled","displayName":"Set new tasks to be automatically scheduled (User)","description":"This policy setting will set new tasks to be automatically scheduled.\r\n\r\nIf you enable this policy setting, new tasks will be automatically scheduled.\r\n\r\nIf you disable or do not configure this policy setting, new tasks will be manually scheduled.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_setnewtaskstobeautomaticallyscheduled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_setnewtaskstobeautomaticallyscheduled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_showtasksschedulesuggestions","displayName":"Show tasks schedule suggestions (User)","description":"This policy setting will allow the display of green task suggestions to indicate potential optimization.\r\n\r\nIf you enable this policy setting, a green task suggestion will be displayed to indicate potential problems.\r\n\r\nIf you disable or do not configure this policy setting, a green task suggestion will not be displayed to indicate potential problems.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_showtasksschedulesuggestions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_showtasksschedulesuggestions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_showtasksschedulewarnings","displayName":"Show tasks schedule warnings (User)","description":"This policy setting will allow the display of red task warnings to indicate potential problems.\r\n\r\nIf you enable or do not configure this policy setting, a red task warning will be displayed to indicate potential problems.\r\n\r\nIf you disable this policy setting, a red task warning will not be displayed to indicate potential problems.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_showtasksschedulewarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_showtasksschedulewarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_taskscanbemadeinactive","displayName":"Tasks can be made inactive (User)","description":"This policy setting will allow tasks to be inactivated.\r\n\r\nIf you enable or do not configure this policy setting, users will be able to use the Inactive tasks feature, and tasks are allowed to be inactivated.\r\n\r\nIf you disable this policy setting, tasks cannot be inactivated.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_taskscanbemadeinactive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_taskscanbemadeinactive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_updatemanuallyscheduledtaskswheneditinglinks","displayName":"Update manually scheduled tasks when editing links (User)","description":"This policy setting will allow the update of manually scheduled task dates when predecessor links are created or updated.\r\n\r\nIf you enable or do not configure this policy setting, manually scheduled task dates will be updated when predecessor links are created or updated.\r\n\r\nIf you disable this policy setting, manually scheduled task dates will not be updated when predecessor links are created or updated.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_updatemanuallyscheduledtaskswheneditinglinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_updatemanuallyscheduledtaskswheneditinglinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits","displayName":"Show assignment units as (User)","description":"Shows resource assignments units as a decimal or percentage.\r\n\r\nIf you enable this setting, resource assignment units will be set to the option you choose from the list.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"304a579b-ff3b-4897-8bb8-5a1dda45356f","categoryName":"Schedule options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_l_pjassignmentunits21","displayName":"Show assignment units as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"304a579b-ff3b-4897-8bb8-5a1dda45356f","categoryName":"Schedule options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_l_pjassignmentunits21_0","displayName":"Percentage","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_l_pjassignmentunits21_1","displayName":"Decimal","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjshowschedmessage","displayName":"Show scheduling messages (User)","description":"Displays messages about schedule inconsistencies, such as a successor task starting before the finish of the predecessor task.\r\n\r\nIf you enable this setting, users will be alerted about scheduling inconsistencies.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"304a579b-ff3b-4897-8bb8-5a1dda45356f","categoryName":"Schedule options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjshowschedmessage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjshowschedmessage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency","displayName":"Default Project Currency (User)","description":"Allows you to manage whether users can set the default currency type for their new project plans. If you enable this setting, the default currency type is enforced for all new project plans. If this setting is disabled or not configured, users can set the default currency type for new project plans.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4","displayName":"Default Project Currency (User)","description":"","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_aed","displayName":"United Arab Emirates, Dirhams","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_afa","displayName":"Afghanistan, Afghanis","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_all","displayName":"Albania, Leke","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_amd","displayName":"Armenia, Drams","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_aoa","displayName":"Angola, Kwanza","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ars","displayName":"Argentina, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_aud","displayName":"Australia, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_awg","displayName":"Aruba, Guilders (also called Florins)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_azm","displayName":"Azerbaijan, Manats","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bam","displayName":"Bosnia and Herzegovina, Convertible Marka","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bbd","displayName":"Barbados, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bdt","displayName":"Bangladesh, Taka","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bgn","displayName":"Bulgaria, Leva","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bhd","displayName":"Bahrain, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bif","displayName":"Burundi, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bmd","displayName":"Bermuda, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bnd","displayName":"Brunei Darussalam, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bob","displayName":"Bolivia, Bolivianos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_brl","displayName":"Brazil, Brazil Real","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bsd","displayName":"Bahamas, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_btn","displayName":"Bhutan, Ngultrum","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bwp","displayName":"Botswana, Pulas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_byr","displayName":"Belarus, Rubles","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bzd","displayName":"Belize, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_cad","displayName":"Canada, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_cdf","displayName":"Congo (DRC)//Kinshasa, Congolese Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_chf","displayName":"Switzerland, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_clp","displayName":"Chile, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_cny","displayName":"China, Yuan Renminbi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_cop","displayName":"Colombia, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_crc","displayName":"Costa Rica, Colones","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_csd","displayName":"Serbia, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_cup","displayName":"Cuba, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_cve","displayName":"Cabo Verde, Escudos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_czk","displayName":"Czech Republic, Koruny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_djf","displayName":"Djibouti, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_dkk","displayName":"Denmark, Kroner","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_dop","displayName":"Dominican Republic, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_dzd","displayName":"Algeria, Algeria Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_egp","displayName":"Egypt, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ern","displayName":"Eritrea, Nakfa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_etb","displayName":"Ethiopia, Birr","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_eur","displayName":"Euro Member Countries, Euro","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_fjd","displayName":"Fiji, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_fkp","displayName":"Falkland (Malvinas) Islands, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gbp","displayName":"United Kingdom, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gel","displayName":"Georgia, Lari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ggp","displayName":"Guernsey, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ghc","displayName":"Ghana, Cedis","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gip","displayName":"Gibraltar, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gmd","displayName":"Gambia, Dalasi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gnf","displayName":"Guinea, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gtq","displayName":"Guatemala, Quetzales","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gyd","displayName":"Guyana, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_hkd","displayName":"Hong Kong, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_hnl","displayName":"Honduras, Lempiras","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_hrk","displayName":"Croatia, Kuna","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_htg","displayName":"Haiti, Gourdes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_huf","displayName":"Hungary, Forint","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_idr","displayName":"Indonesia, Rupiahs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ils","displayName":"Israel, New Shekels","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_imp","displayName":"Isle of Man, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_inr","displayName":"India, Rupees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_iqd","displayName":"Iraq, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_irr","displayName":"Iran, Rials","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_isk","displayName":"Iceland, Kronur","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_jep","displayName":"Jersey, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_jmd","displayName":"Jamaica, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_jod","displayName":"Jordan, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_jpy","displayName":"Japan, Yen","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kes","displayName":"Kenya, Shillings","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kgs","displayName":"Kyrgyzstan, Soms","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_khr","displayName":"Cambodia, Riels","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kmf","displayName":"Comoros, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kpw","displayName":"North Korea, Won","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_krw","displayName":"Korea, Won","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kwd","displayName":"Kuwait, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kyd","displayName":"Cayman Islands, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kzt","displayName":"Kazakhstan, Tenge","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_lak","displayName":"Laos, Kips","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_lbp","displayName":"Lebanon, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_lkr","displayName":"Sri Lanka, Rupees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_lrd","displayName":"Liberia, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_lsl","displayName":"Lesotho, Maloti","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ltl","displayName":"Lithuania, Litai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_lyd","displayName":"Libya, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mad","displayName":"Morocco, Dirhams","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mdl","displayName":"Moldova, Lei","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mga","displayName":"Madagascar, Ariary","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mkd","displayName":"Macedonia FYRO, Denars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mmk","displayName":"Myanmar (Burma), Kyats","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mnt","displayName":"Mongolia, Tugriks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mop","displayName":"Macao, Patacas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mro","displayName":"Mauritania, Ouguiyas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mur","displayName":"Mauritius, Rupees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mvr","displayName":"Maldives (Maldive Islands), Rufiyaa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mwk","displayName":"Malawi, Kwachas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mxn","displayName":"Mexico, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_myr","displayName":"Malaysia, Ringgits","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mzm","displayName":"Mozambique, Meticais","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_nad","displayName":"Namibia, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ngn","displayName":"Nigeria, Nairas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_nio","displayName":"Nicaragua, Cordobas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_nok","displayName":"Norway, Krone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_npr","displayName":"Nepal, Nepal Rupees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_nzd","displayName":"New Zealand, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_omr","displayName":"Oman, Rials","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_pab","displayName":"Panama, Balboa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_pen","displayName":"Peru, Nuevos Soles","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_pgk","displayName":"Papua New Guinea, Kina","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_php","displayName":"Philippines, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_pkr","displayName":"Pakistan, Rupees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_pln","displayName":"Poland, Zlotych","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_pyg","displayName":"Paraguay, Guarani","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_qar","displayName":"Qatar, Rials","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ron","displayName":"Romania, New Lei","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_rub","displayName":"Russia, Rubles","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_rwf","displayName":"Rwanda, Rwanda Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sar","displayName":"Saudi Arabia, Riyals","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sbd","displayName":"Solomon Islands, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_scr","displayName":"Seychelles, Rupees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sdd","displayName":"Sudan, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sek","displayName":"Sweden, Kronor","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sgd","displayName":"Singapore, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_shp","displayName":"Saint Helena, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sll","displayName":"Sierra Leone, Leones","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sos","displayName":"Somalia, Shillings","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_spl","displayName":"Seborga, Luigini","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_srd","displayName":"Suriname, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_std","displayName":"São Tome and Principe, Dobras","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_svc","displayName":"El Salvador, Colones","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_syp","displayName":"Syria, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_szl","displayName":"Swaziland, Emalangeni","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_thb","displayName":"Thailand, Baht","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_tjs","displayName":"Tajikistan, Somoni","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_tmm","displayName":"Turkmenistan, Manats","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_tnd","displayName":"Tunisia, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_top","displayName":"Tonga, Pa'anga","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_try","displayName":"Turkey, Lira","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ttd","displayName":"Trinidad and Tobago, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_tvd","displayName":"Tuvalu, Tuvalu Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_twd","displayName":"Taiwan, New Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_tzs","displayName":"Tanzania, Shillings","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_uah","displayName":"Ukraine, Hryvnia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ugx","displayName":"Uganda, Shillings","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_usd","displayName":"United States of America, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_uyu","displayName":"Uruguay, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_uzs","displayName":"Uzbekistan, Sums","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ves","displayName":"Venezuela, Bolívar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_vnd","displayName":"Vietnam, Dong","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_vuv","displayName":"Vanuatu, Vatu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_wst","displayName":"Samoa, Tala","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xaf","displayName":"Communauté Financière Africaine BEAC, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xag","displayName":"Silver, Ounces","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xau","displayName":"Gold, Ounces","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xcd","displayName":"East Caribbean Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xdr","displayName":"International Monetary Fund (IMF) Special Drawing Rights","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xof","displayName":"Communauté Financière Africaine BCEAO, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xpd","displayName":"Palladium Ounces","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xpf","displayName":"Comptoirs Français du Pacifique Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xpt","displayName":"Platinum, Ounces","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_yer","displayName":"Yemen, Rials","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_zar","displayName":"South Africa, Rand","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_zmk","displayName":"Zambia, Kwacha","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_zwd","displayName":"Zimbabwe, Zimbabwe Dollars","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat","displayName":"Date Format (User)","description":"Specifies the format for displaying dates. Some information, such as time formats and the date separator, is set through the Control Panel.\r\n \r\nIf you enable this setting, dates are displayed in the format you set.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3","displayName":"Date Format (User)","description":"","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_0","displayName":"1/31/00 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_1","displayName":"1/31/00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_20","displayName":"1/31/2000","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_2","displayName":"January 31, 2000 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_3","displayName":"January 31, 2000","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_4","displayName":"Jan 31 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_5","displayName":"Jan 31 '00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_6","displayName":"January 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_7","displayName":"Jan 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_8","displayName":"Mon 1/31/00 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_9","displayName":"Mon 1/31/00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_10","displayName":"Mon Jan 31, '00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_11","displayName":"Mon 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_15","displayName":"Mon Jan 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_16","displayName":"Mon 1/31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_17","displayName":"Mon 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_12","displayName":"1/31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_13","displayName":"31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_14","displayName":"12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_18","displayName":"W1/1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_19","displayName":"W1/1/00 12:33 PM","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview","displayName":"Default View (User)","description":"Specifies the view that Project displays at startup.\r\n \r\nIf you enable this setting, you can set the default view that is displayed at startup.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2","displayName":"Default View (User)","description":"","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_bar rollup","displayName":"Bar Rollup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_calendar","displayName":"Calendar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_descriptive network diagram","displayName":"Descriptive Network Diagram","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_detail gantt","displayName":"Detail Gantt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_gantt chart","displayName":"Gantt Chart","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_leveling gantt","displayName":"Leveling Gantt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_milestone date rollup","displayName":"Milestone Date Rollup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_milestone rollup","displayName":"Milestone Rollup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_network diagram","displayName":"Network Diagram","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_relationship diagram","displayName":"Relationship Diagram","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource allocation","displayName":"Resource Allocation","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource form","displayName":"Resource Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource graph","displayName":"Resource Graph","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource name form","displayName":"Resource Names Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource sheet","displayName":"Resource Sheet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource usage","displayName":"Resource Usage","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task details form","displayName":"Task Details Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task entry","displayName":"Task Entry","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task form","displayName":"Task Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task name form","displayName":"Task Name Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task sheet","displayName":"Task Sheet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task usage","displayName":"Task Usage","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_tracking gantt","displayName":"Tracking Gantt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_projectsummarytask","displayName":"Project Summary Task (User)","description":"Allows you to manage whether the project summary task is displayed. If you enable this setting, the project summary task is displayed. If this setting is disabled or not configured, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_projectsummarytask_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_projectsummarytask_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0","displayName":"Calendar Type (User)","description":"Allows you to set the default calendar type. You need to have the Complex Script and East Asian language packs installed on the operating system in order for this setting to be available. If you enable this setting, you can set the default calendar type. If you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"70b0e7ef-ceac-4c25-8f9f-5a6bf07163b6","categoryName":"Calendar Type","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0_l_calendartype1","displayName":"Calendar Type (User)","description":"","helpText":"","infoUrls":[],"categoryId":"70b0e7ef-ceac-4c25-8f9f-5a6bf07163b6","categoryName":"Calendar Type","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0_l_calendartype1_1","displayName":"Gregorian Calendar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0_l_calendartype1_6","displayName":"Hijri Calendar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0_l_calendartype1_7","displayName":"Thai Buddhist","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_automaticallyaddnewitemstotheglobalproject","displayName":"Automatically add new items to the global project (User)","description":"This policy setting specifies whether new items (views, tables, filters, and groups) are automatically added to the global project so they are available in all of the projects.\r\n\r\nIf you enable or do not configure this policy setting, new items will be automatically added to the global project.\r\n\r\nIf you disable this policy setting, new items will not be automatically added to the global project.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_automaticallyaddnewitemstotheglobalproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_automaticallyaddnewitemstotheglobalproject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjentrybar","displayName":"Entry Bar (User)","description":"Displays the entry bar, in which you can enter or edit field information.\r\nIf you enable this setting, the entry bar is displayed.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjentrybar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjentrybar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjolelinks","displayName":"OLE Link Indicators (User)","description":"Displays the indicator for OLE linked objects in the lower-right corner of the cell that contains the link.\r\nIf you enable this setting, the indicator is displayed for OLE linked objects.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjolelinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjolelinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjprojectscreentips","displayName":"Project Screentips (User)","description":"Displays tips for Gantt bars and field headings, including dates for timescale units, and the full cell contents if a cell is too narrow to completely display the text in sheet and Network Diagram views.\r\n\r\nIf you enable this setting, tips are displayed fro Gantt bars and field headings.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjprojectscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjprojectscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjscrollbar","displayName":"Scroll Bars (User)","description":"Displays scrollbars for views.\r\n \r\nIf you enable this setting, scrollbars are displayed in the views.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjstatusbar","displayName":"Status Bar (User)","description":"Displays the status bar, which shows information about the progress of certain operations in Project.\r\n \r\nIf you enable this setting, the option to display the status bar is selected.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjstatusbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjstatusbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjwindowsinstatusbar","displayName":"Windows in Taskbar (User)","description":"Specifies whether separate windows are opened and displayed as separate buttons on the Windows taskbar for every open project.\r\n \r\nIf you enable this setting, a new window is displayed in the taskbar for each open project.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjwindowsinstatusbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjwindowsinstatusbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_enableuntrustedintranetzoneaccesstoprojectserver","displayName":"Enable untrusted intranet zone access to Project server (User)","description":"Allows users to access Project Server Web sites and Workspaces that have not been added to their trusted internet zones. If you enable this setting, users can access Project Server and Microsoft SharePoint Foundation sites that are not in their trusted internet zones. If this setting is disabled or not configured, users are required to add the Project Server and Microsoft SharePoint Foundation sites to their trusted internet site zones.","helpText":"","infoUrls":[],"categoryId":"623d41fb-000e-41d8-b955-373f8c700def","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_enableuntrustedintranetzoneaccesstoprojectserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_enableuntrustedintranetzoneaccesstoprojectserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats","displayName":"Previous-version file formats (User)","description":"Allows you manage whether users can open or save files in Project with file formats from previous versions or file formats that are not default. By default, users can not open or save files with formats from previous versions.","helpText":"","infoUrls":[],"categoryId":"623d41fb-000e-41d8-b955-373f8c700def","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"623d41fb-000e-41d8-b955-373f8c700def","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats_l_empty_0","displayName":"Do not open or save","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats_l_empty_1","displayName":"Prompt when opening and saving","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats_l_empty_2","displayName":"Allow opening and saving","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setparametersforcngcontext","displayName":"Set parameters for CNG context (User)","description":"This policy setting allows you to specify the encryption parameters that should be used for the CNG context. \r\n\r\nIf you enable this policy setting, the parameters specified will be passed to the CNG context.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG values will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setparametersforcngcontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setparametersforcngcontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm","displayName":"Specify CNG random number generator algorithm (User)","description":"This policy setting allows you to configure the CNG random number generator to use.\r\n\r\nIf you enable this policy setting, the random number generator specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default random number generator will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_l_specifycngrandomnumbergeneratoralgorithmid","displayName":"Random number generator: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngsaltlength","displayName":"Specify CNG salt length (User)","description":"This policy setting allows you to specific the number of bytes of salt that should be used.\r\n\r\nIf you enable this policy setting, the bytes specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default length or 16 will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngsaltlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngsaltlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel","displayName":"Security Level (User)","description":"Specifies the level of security used when opening documents.\r\n\r\nIf you enable this policy setting, the security level you specified will be used when user open documents.\r\n\r\nIf you disable or do not configure this policy setting, the users default for this setting is followed.","helpText":"","infoUrls":[],"categoryId":"26dfd0a7-546b-4583-b0c7-85b98ac5a40c","categoryName":"Tools | Macro","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_l_pjsecuritylevel36","displayName":"Security Level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"26dfd0a7-546b-4583-b0c7-85b98ac5a40c","categoryName":"Tools | Macro","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_l_pjsecuritylevel36_1","displayName":"Low (not recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_l_pjsecuritylevel36_2","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_l_pjsecuritylevel36_3","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_l_pjsecuritylevel36_4","displayName":"Very High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_allowtrustedlocationsonthenetwork","displayName":"Allow Trusted Locations on the network (User)","description":"This policy setting controls whether trusted locations on the network can be used.\r\n\r\nIf you enable this policy setting, users can specify trusted locations on network shares or in other remote locations that are not under their direct control by clicking the \"Add new location\" button in the Trusted Locations section of the Trust Center. Content, code, and add-ins are allowed to load from trusted locations with minimal security and without prompting the user for permission.\r\n\r\nIf you disable this policy setting, the selected application ignores any network locations listed in the Trusted Locations section of the Trust Center. \r\n\r\nIf you also deploy Trusted Locations via Group Policy, you should verify whether any of them are remote locations. If any of them are remote locations and you do not allow remote locations via this policy setting, those policy keys that point to remote locations will be ignored on client computers.\r\n\r\nDisabling this policy setting does not delete any network locations from the Trusted Locations list, but causes disruption for users who add network locations to the Trusted Locations list. Users are also prevented from adding new network locations to the Trusted Locations list in the Trust Center. We recommended that you do not enable this policy setting (as the \"Allow Trusted Locations on my network (not recommended)\" check box also states). Therefore, in practice, it should be possible to disable this policy setting in most situations without causing significant usability issues for most users.\r\n\r\nIf you do not enable this policy setting, users can select the \"Allow Trusted Locations on my network (not recommended)\" check box if desired and then specify trusted locations by clicking the \"Add new location\" button.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_allowtrustedlocationsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_allowtrustedlocationsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users, except if application add-ins are required to be signed by Trusted Publishers.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User) (Deprecated)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n\r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_allowsubfolders15","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_allowsubfolders15_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_allowsubfolders15_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_datecolon13","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_descriptioncolon14","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_pathcolon12","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_datecolon17","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_descriptioncolon18","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_pathcolon16","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_datecolon21","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_descriptioncolon22","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_pathcolon20","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_datecolon25","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_descriptioncolon26","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_pathcolon24","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_l_allowsubfolders31","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_l_allowsubfolders31_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_l_allowsubfolders31_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_l_datecolon29","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_l_descriptioncolon30","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_l_pathcolon28","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_allowsubfolders35","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_allowsubfolders35_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_allowsubfolders35_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_datecolon33","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_allowsubfolders39","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_allowsubfolders39_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_allowsubfolders39_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_descriptioncolon38","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_pathcolon36","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_descriptioncolon42","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_pathcolon40","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_datecolon45","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_descriptioncolon46","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_pathcolon44","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11","displayName":"Trusted Location #11 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_l_allowsubfolders51","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_l_allowsubfolders51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_l_allowsubfolders51_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_l_datecolon49","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_l_descriptioncolon50","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_l_pathcolon48","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_allowsubfolders55","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_allowsubfolders55_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_allowsubfolders55_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_descriptioncolon54","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_l_allowsubfolders59","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_l_allowsubfolders59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_l_allowsubfolders59_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_l_datecolon57","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_l_descriptioncolon58","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_l_pathcolon56","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_l_allowsubfolders63","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_l_allowsubfolders63_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_l_allowsubfolders63_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_l_datecolon61","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_l_pathcolon60","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_pathcolon64","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_datecolon69","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_descriptioncolon70","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_pathcolon68","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_datecolon73","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_descriptioncolon74","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_pathcolon72","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_l_datecolon77","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_l_descriptioncolon78","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_l_pathcolon76","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_datecolon81","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_descriptioncolon82","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_pathcolon80","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_datecolon85","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_descriptioncolon86","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_pathcolon84","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v3~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the internet (User)","description":"\r\nThis policy setting allows you to block macros from running in Office files that come from the internet.\r\n\r\nIf you enable this policy setting, macros are blocked from running, even if \"Enable all macros\" is selected in the Macro Settings section of the Trust Center. Users will receive a notification that macros are blocked from running.\r\n\r\nThe exceptions when macros will be allowed to run are:\r\n- The Office file is saved to a Trusted Location.\r\n- The Office file was previously trusted by the user.\r\n- Macros are digitally signed and the matching Trusted Publisher certificate is installed on the device.\r\n\r\nIf you disable this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the internet.\r\n\r\nIf you don’t configure this policy setting, macros will be blocked from running. Users will receive a notification telling them of the security risks of macros from the internet along with a link to learn more.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2185771.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v3~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v3~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. \r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"907fd656-2a80-4f34-8615-a3acb11a2b95","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"907fd656-2a80-4f34-8615-a3acb11a2b95","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable specific command bar buttons and menu items for Publisher.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, the predefined list of command bar buttons and menu items are enabled for Publisher.","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filepublishtoweb","displayName":"File tab | Export | Publish HTML (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filepublishtoweb_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filepublishtoweb_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailemailpreview","displayName":"File tab | Share | E-mail Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailemailpreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailemailpreview_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailsendthispage","displayName":"File tab | Share | Email (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailsendthispage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailsendthispage_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview","displayName":"Web tab | View | Web Page Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_puboptions1","displayName":"File tab | Options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_puboptions1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_puboptions1_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsaddins","displayName":"Developer tab | Add-Ins | COM Add-Ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsaddins_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsaddins_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacro","displayName":"Developer tab (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacro_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacro_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacros","displayName":"Developer tab | Code | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity","displayName":"Developer tab | Code | Macro Security (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditor","displayName":"Developer tab | Code | Visual Basic (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditor_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditor_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_adddoublequotesinhebrewalphabetnumbering","displayName":"Add double quotes in Hebrew alphabet numbering (User)","description":"Checked: Adds double quotation marks ('') to Hebrew numbering. | Unchecked: Does not add double quotation marks ('') to Hebrew numbering.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_adddoublequotesinhebrewalphabetnumbering_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_adddoublequotesinhebrewalphabetnumbering_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab","displayName":"Default tab to show in Publisher on the Office Start screen and in File | New (User)","description":"This policy setting controls what displays as the default tab in Publisher on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, you can choose one of two options to become the default tab on the Office Start screen and in File | New:\r\n\r\n* Built-in – Users will the see built-in templates tab as the default tab in Publisher on the Office Start screen and in File | New.\r\n\r\n* Custom – Users will the see custom templates tab as the default tab in Publisher on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Publisher on the Office Start screen and in File | New","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab","displayName":"Default tab (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab_0","displayName":"Featured","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab_2","displayName":"Built-in","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab_1","displayName":"Custom","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_disableofficestartpublisher","displayName":"Disable the Office Start screen for Publisher (User)","description":"This policy setting controls whether the Office Start screen appears on boot for Publisher.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot Publisher.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot Publisher.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_disableofficestartpublisher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_disableofficestartpublisher_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\Publisher\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\Publisher\\Addins.\r\n\r\nYou can also obtain the ProgID of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath","displayName":"Personal templates path for Publisher (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_promptusertosetupprinter","displayName":"Prompt user to setup printer (User)","description":"When set, Publisher will show a prompt to the user to start the Printer Setup Wizard when a new printer is found.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_promptusertosetupprinter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_promptusertosetupprinter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_allowtexttobedraggedanddropped","displayName":"Allow text to be dragged and dropped (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_allowtexttobedraggedanddropped_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_allowtexttobedraggedanddropped_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallyhyphenateinnewtextboxes","displayName":"Automatically hyphenate in new text boxes (User)","description":"Checks/Unchecks the option ''Automatically hyphenate in new text boxes''.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallyhyphenateinnewtextboxes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallyhyphenateinnewtextboxes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallysubstitutefontformissingeachars","displayName":"Automatically substitute font for missing East Asian characters (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallysubstitutefontformissingeachars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallysubstitutefontformissingeachars_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallyswitchkeyboard","displayName":"Automatically switch keyboard to match the language of surrounding text (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallyswitchkeyboard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallyswitchkeyboard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_enableincrementalpublishtoweb","displayName":"Enable incremental publish to Web (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_enableincrementalpublishtoweb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_enableincrementalpublishtoweb_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_promptuserwhenreapplyingastyle","displayName":"Prompt user when reapplying a style (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_promptuserwhenreapplyingastyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_promptuserwhenreapplyingastyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_sendentirepublicationasasingle","displayName":"Send entire publication as a single JPEG image (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_sendentirepublicationasasingle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_sendentirepublicationasasingle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setmaximumnumberofmruitemstodisplay","displayName":"Number of publications in the Recent Publications list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Publications list that appears when users click Open on the File tab in Backstage view. \r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Publications list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Publications list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setmaximumnumberofmruitemstodisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setmaximumnumberofmruitemstodisplay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setmaximumnumberofmruitemstodisplay_l_setmaximumnumberofmruitemstodisplayspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_showscreentipsonobjects","displayName":"Show ScreenTips on objects (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_showscreentipsonobjects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_showscreentipsonobjects_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_turnoffdragpreview","displayName":"Turn off drag preview (User)","description":"This policy setting allows you to determine whether Publisher shows a semi-transparent drag preview or a simple outline of the object when the object is dragged.\r\n\r\nIf you enable this policy setting, only the outline of the object is shown while being dragged. This is the recommended setting for older machines because of the resource requirements of this feature.\r\n\r\nIf you disable or do not configure this policy setting, a semi-transparent drag preview of the object is shown while being dragged.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_turnoffdragpreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_turnoffdragpreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usechinesefontsizes","displayName":"Use Chinese font sizes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usechinesefontsizes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usechinesefontsizes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usexpsenhancedprintpath","displayName":"Use XPS-enhanced print path (User)","description":"This policy setting allows you to use XPS-enhanced print path when available. \r\n\r\nIf you enable or do not configure this policy setting, the XPS print path will be used.\r\n\r\nIf you disable this policy setting, the XPS print path is not used.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usexpsenhancedprintpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usexpsenhancedprintpath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenformattingautomaticallyformatentireword","displayName":"When formatting, automatically format entire word (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenformattingautomaticallyformatentireword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenformattingautomaticallyformatentireword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenselectingautomaticallyselectentireword","displayName":"When selecting, automatically select entire word (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenselectingautomaticallyselectentireword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenselectingautomaticallyselectentireword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection","displayName":"Default Publisher direction (User)","description":"Specifies the default layout orientation.","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_l_defaultpublisherdirection3","displayName":"Default Publisher direction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_l_defaultpublisherdirection3_0","displayName":"Left to right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_l_defaultpublisherdirection3_1","displayName":"Right to left","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_setdefaulttextflowdirection","displayName":"Set default text flow direction (User)","description":"This policy setting allows you to set the default text flow between Right-to-Left (RTL) and Left-to-Right (LTR). \r\n\r\nIf you enable this policy setting, you may choose whether text will flow RTL or LTR.\r\n\r\nIf you disable or not configure this policy setting, the default text flow setting is used.","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_setdefaulttextflowdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_setdefaulttextflowdirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_setdefaulttextflowdirection_l_setdefaulttextflowdirectiondropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_setdefaulttextflowdirection_l_setdefaulttextflowdirectiondropid_1","displayName":"Left-to-Right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_setdefaulttextflowdirection_l_setdefaulttextflowdirectiondropid_256","displayName":"Right-to-Left","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_usesequencechecking","displayName":"Use sequence checking (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_usesequencechecking_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_usesequencechecking_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_usetypeandreplace","displayName":"Use type and replace (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_usetypeandreplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_usetypeandreplace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_general_l_showthenewtemplategallerywhenstartingpublisher","displayName":"Show the New template gallery when starting Publisher (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"1a0386fd-354b-441e-a0d6-1523c209dae7","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_general_l_showthenewtemplategallerywhenstartingpublisher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_general_l_showthenewtemplategallerywhenstartingpublisher_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"6d1e32eb-61f7-4907-b9fe-b83fda8ad67d","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype","displayName":"Check spelling as you type (User)","description":"This policy setting allows you to configure options for spelling errors.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n- Check spelling as you type: This option is checked.\r\n- Hide spelling errors: This option is checked, but \"Check spelling as you type\" is unchecked.\r\n- Both: \"Check spelling as you type\" and \"Hide spelling errors\" are both checked.\r\n\r\nIf you disable or do not configure this policy setting, the \"Check spelling as you type\" option is checked.","helpText":"","infoUrls":[],"categoryId":"51e0cebb-cac4-4905-9b31-539295e4b85b","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype_l_checkspellingasyoutypedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"51e0cebb-cac4-4905-9b31-539295e4b85b","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype_l_checkspellingasyoutypedropid_1","displayName":"Check spelling as you type","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype_l_checkspellingasyoutypedropid_2","displayName":"Hide spelling errors","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype_l_checkspellingasyoutypedropid_3","displayName":"Both","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_allowbackgroundsaves","displayName":"Allow background saves (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"038b49c9-4f13-4ace-be8d-bd076bffa23e","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_allowbackgroundsaves_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_allowbackgroundsaves_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery","displayName":"Save AutoRecover info every (minutes) (User)","description":"This policy setting allows you to specify the Save Autorecover interval in minutes.\r\n\r\nIf you enable this policy setting, you may specify the Save Autorecover interval in minutes (valid range: 1-120).\r\n\r\nIf you disable or do not configure this policy setting, the interval specified in the UI will be used.\r\n","helpText":"","infoUrls":[],"categoryId":"038b49c9-4f13-4ace-be8d-bd076bffa23e","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery_l_saveautorecoverinfoeveryid","displayName":"Minutes (range 1-120): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"038b49c9-4f13-4ace-be8d-bd076bffa23e","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_preventfatallycorruptfilesfromopening","displayName":"Prompt to allow fatally corrupt files to open instead of blocking them (User)","description":"When disabled, fatally corrupt files are prevented from opening. When enabled, the user is warned but may choose to open the file.By default, fatally corrupt files are prevented from opening.","helpText":"","infoUrls":[],"categoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_preventfatallycorruptfilesfromopening_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_preventfatallycorruptfilesfromopening_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel","displayName":"Publisher Automation Security Level (User)","description":"This policy setting controls whether macros opened programmatically by another application can run in Publisher.\r\n\r\nIf you enable this policy setting, you may choose an option for controlling macro behavior in Publisher when the application is opened programmatically:\r\n\r\n- Low (enabled): Macros can run in the programmatically opened application.\r\n- By UI (prompted): Macro functionality is determined by the setting in the \"Macro Settings\" section of the Trust Center.\r\n- High (disabled): All macros are disabled in the programmatically opened application.\r\n\r\nIf you disable or do not configure this policy setting, Publisher will use the default Macro setting in Trust Center.","helpText":"","infoUrls":[],"categoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty_1","displayName":"Low (enabled)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty_2","displayName":"By UI (prompted)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty_3","displayName":"High (disabled)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Block application add-ins loading (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users, except if application add-ins are required to be signed by Trusted Publishers.","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins (User) (Deprecated)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2","displayName":"Disable Trust Bar Notification for unsigned application add-ins (User)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v3~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if \"Enable all macros\" is selected in the Macro Settings section of the Trust Center. Users will receive a notification that macros are blocked from running.\r\n\r\n The exceptions when macros will be allowed to run are:\r\n - The Office file is saved to a Trusted Location.\r\n - The Office file was previously trusted by the user.\r\n - Macros are digitally signed and the matching Trusted Publisher certificate is installed on the device.\r\n\r\n If you disable this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the internet.\r\n\r\n If you don’t configure this policy setting, macros will be blocked from running. Users will receive a notification telling them of the security risks of macros from the internet along with a link to learn more.\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2185771.\r\n ","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v3~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v3~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_remotedesktop_autosubscription","displayName":"Auto-subscription (User)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-configuration-service-provider"],"categoryId":"c14c2e8b-0081-46e0-89ac-48ade3b83408","categoryName":"Remote Desktop","options":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection","displayName":"Restrict clipboard transfer from client to server (User)","description":"This policy setting allows you to restrict clipboard data transfers from client to server.\r\n\r\nIf you enable this policy setting, you must choose from the following behaviors:\r\n\r\n- Disable clipboard transfers from client to server.\r\n\r\n- Allow plain text copying from client to server.\r\n\r\n- Allow plain text and images copying from client to server.\r\n\r\n- Allow plain text, images and Rich Text Format copying from client to server.\r\n\r\n- Allow plain text, images, Rich Text Format and HTML copying from client to server.\r\n\r\nIf you disable or do not configure this policy setting, users can copy arbitrary contents from client to server if clipboard redirection is enabled.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the stricter restriction will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-limitclienttoserverclipboardredirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_ts_cs_clipboard_restriction_text","displayName":"Restrict clipboard transfer from client to server: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_ts_cs_clipboard_restriction_text_0","displayName":"Disable clipboard transfers from client to server","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_ts_cs_clipboard_restriction_text_1","displayName":"Allow plain text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_ts_cs_clipboard_restriction_text_2","displayName":"Allow plain text and images","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_ts_cs_clipboard_restriction_text_3","displayName":"Allow plain text, images and Rich Text Format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_ts_cs_clipboard_restriction_text_4","displayName":"Allow plain text, images, Rich Text Format and HTML","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection","displayName":"Restrict clipboard transfer from server to client (User)","description":"This policy setting allows you to restrict clipboard data transfers from server to client.\r\n\r\nIf you enable this policy setting, you must choose from the following behaviors:\r\n\r\n- Disable clipboard transfers from server to client.\r\n\r\n- Allow plain text copying from server to client.\r\n\r\n- Allow plain text and images copying from server to client.\r\n\r\n- Allow plain text, images and Rich Text Format copying from server to client.\r\n\r\n- Allow plain text, images, Rich Text Format and HTML copying from server to client.\r\n\r\nIf you disable or do not configure this policy setting, users can copy arbitrary contents from server to client if clipboard redirection is enabled.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the stricter restriction will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-limitservertoclientclipboardredirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_ts_sc_clipboard_restriction_text","displayName":"Restrict clipboard transfer from server to client: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_ts_sc_clipboard_restriction_text_0","displayName":"Disable clipboard transfers from server to client","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_ts_sc_clipboard_restriction_text_1","displayName":"Allow plain text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_ts_sc_clipboard_restriction_text_2","displayName":"Allow plain text and images","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_ts_sc_clipboard_restriction_text_3","displayName":"Allow plain text, images and Rich Text Format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_ts_sc_clipboard_restriction_text_4","displayName":"Allow plain text, images, Rich Text Format and HTML","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_security_recoveryenvironmentauthentication","displayName":"Recovery Environment Authentication (User)","description":"This policy controls the requirement of Admin Authentication in RecoveryEnvironment.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Security#recoveryenvironmentauthentication"],"categoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_security_recoveryenvironmentauthentication_0","displayName":"current) behavior","description":"current) behavior","helpText":null},{"id":"user_vendor_msft_policy_config_security_recoveryenvironmentauthentication_1","displayName":"RequireAuthentication: Admin Authentication is always required for components in RecoveryEnvironment","description":"RequireAuthentication: Admin Authentication is always required for components in RecoveryEnvironment","helpText":null},{"id":"user_vendor_msft_policy_config_security_recoveryenvironmentauthentication_2","displayName":"NoRequireAuthentication: Admin Authentication is not required for components in RecoveryEnvironment","description":"NoRequireAuthentication: Admin Authentication is not required for components in RecoveryEnvironment","helpText":null}]},{"id":"user_vendor_msft_policy_config_settings_configuretaskbarcalendar","displayName":"Configure Taskbar Calendar (User)","description":"Allows IT Admins to configure the default setting for showing additional calendars (besides the default calendar for the locale) in the taskbar clock and calendar flyout. In this version of Windows 10, supported additional calendars are: Simplified or Traditional Chinese lunar calendar. Turning on one of these calendars will display Chinese lunar dates below the default calendar for the locale. Select Don't show additional calendars to prevent showing other calendars besides the default calendar for the locale.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Settings#configuretaskbarcalendar"],"categoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","categoryName":"Settings","options":[{"id":"user_vendor_msft_policy_config_settings_configuretaskbarcalendar_0","displayName":"User will be allowed to configure the setting.","description":"User will be allowed to configure the setting.","helpText":null},{"id":"user_vendor_msft_policy_config_settings_configuretaskbarcalendar_1","displayName":"Don't show additional calendars.","description":"Don't show additional calendars.","helpText":null},{"id":"user_vendor_msft_policy_config_settings_configuretaskbarcalendar_2","displayName":"Simplified Chinese (Lunar).","description":"Simplified Chinese (Lunar).","helpText":null},{"id":"user_vendor_msft_policy_config_settings_configuretaskbarcalendar_3","displayName":"Traditional Chinese (Lunar).","description":"Traditional Chinese (Lunar).","helpText":null}]},{"id":"user_vendor_msft_policy_config_settings_pagevisibilitylist","displayName":"Page Visibility List (User)","description":"Allows IT Admins to either prevent specific pages in the System Settings app from being visible or accessible, or to do so for all pages except those specified. The mode will be specified by the policy string beginning with either the string showonly: or hide:.  Pages are identified by a shortened version of their already published URIs, which is the URI minus the ms-settings: prefix. For example, if the URI for a settings page is ms-settings:bluetooth, the page identifier used in the policy will be just bluetooth. Multiple page identifiers are separated by semicolons. The following example illustrates a policy that would allow access only to the about and bluetooth pages, which have URI ms-settings:about and ms-settings:bluetooth respectively:showonly:about;bluetooth. If the policy is not specified, the behavior will be that no pages are affected. If the policy string is formatted incorrectly, it will be ignored entirely (i. e. treated as not set) to prevent the machine from becoming unserviceable if data corruption occurs. Note that if a page is already hidden for another reason, then it will remain hidden even if it is in a showonly: list. The format of the PageVisibilityList value is as follows: The value is a unicode string up to 10,000 characters long, which will be used without case sensitivity. There are two variants: one that shows only the given pages and one which hides the given pages. The first variant starts with the string showonly: and the second with the string hide:. Following the variant identifier is a semicolon-delimited list of page identifiers, which must not have any extra whitespace. Each page identifier is the ms-settings:xyz URI for the page, minus the ms-settings: prefix, so the identifier for the page with URI ms-settings:network-wifi would be just network-wifi. The default value for this setting is an empty string, which is interpreted as show everything. Example 1, specifies that only the wifi and bluetooth pages should be shown (they have URIs ms-settings:network-wifi and ms-settings:bluetooth). All other pages (and the categories they're in) will be hidden:showonly:network-wifi;bluetooth. Example 2, specifies that the wifi page should not be shown:hide:network-wifi","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Settings#pagevisibilitylist"],"categoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","categoryName":"Settings","options":null},{"id":"user_vendor_msft_policy_config_start_alwaysshownotificationicon","displayName":"Always Show Notification Icon (User)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#alwaysshownotificationicon"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_alwaysshownotificationicon_0","displayName":"Auto-hide notification bell icon","description":"Auto-hide notification bell icon","helpText":null},{"id":"user_vendor_msft_policy_config_start_alwaysshownotificationicon_1","displayName":"Show notification bell icon","description":"Show notification bell icon","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_configurestartpins","displayName":"Configure Start Pins (User)","description":"Allows admin to override the default items pinned to Start.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#configurestartpins"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":null},{"id":"user_vendor_msft_policy_config_start_disablecontextmenus","displayName":"Disable Context Menus (User)","description":"Enabling this policy prevents context menus from being invoked in the Start Menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#disablecontextmenus"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_disablecontextmenus_0","displayName":"Disabled","description":"Do not disable.","helpText":null},{"id":"user_vendor_msft_policy_config_start_disablecontextmenus_1","displayName":"Enabled","description":"Disable.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_forcestartsize","displayName":"Force Start Size (User)","description":"Forces the start screen size. If there is policy configuration conflict, the latest configuration request is applied to the device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#forcestartsize"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_forcestartsize_0","displayName":"Do not force size of Start.","description":"Do not force size of Start.","helpText":null},{"id":"user_vendor_msft_policy_config_start_forcestartsize_1","displayName":"Force non-fullscreen size of Start.","description":"Force non-fullscreen size of Start.","helpText":null},{"id":"user_vendor_msft_policy_config_start_forcestartsize_2","displayName":"Force a fullscreen size of Start.","description":"Force a fullscreen size of Start.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_hideapplist","displayName":"Hide App List (User)","description":"Setting the value of this policy to 1 or 2 collapses the app list. Setting the value of this policy to 3 removes the app list entirely. Setting the value of this policy to 2 or 3 disables the corresponding toggle in the Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hideapplist"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hideapplist_0","displayName":"None.","description":"None.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hideapplist_1","displayName":"Hide all apps list.","description":"Hide all apps list.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hideapplist_2","displayName":"Hide all apps list, and Disable \"Show app list in Start menu\" in Settings app.","description":"Hide all apps list, and Disable \"Show app list in Start menu\" in Settings app.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hideapplist_3","displayName":"Hide all apps list, remove all apps button, and Disable \"Show app list in Start menu\" in Settings app.","description":"Hide all apps list, remove all apps button, and Disable \"Show app list in Start menu\" in Settings app.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_hidecategoryview","displayName":"Hide Category View (User)","description":"This policy setting allows you to hide the category view in the Start Menu. If you enable this policy setting, the Start Menu will no longer show the category view as an option and will default to grid view.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidecategoryview"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hidecategoryview_0","displayName":"Category view shown.","description":"Category view shown.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hidecategoryview_1","displayName":"Category view hidden.","description":"Category view hidden.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_hidefrequentlyusedapps","displayName":"Hide Frequently Used Apps (User)","description":"Enabling this policy hides the most used apps from appearing on the start menu and disables the corresponding toggle in the Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidefrequentlyusedapps"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hidefrequentlyusedapps_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hidefrequentlyusedapps_1","displayName":"Enabled","description":"Hide.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_hidepeoplebar","displayName":"Hide People Bar (User)","description":"Enabling this policy removes the people icon from the taskbar as well as the corresponding settings toggle. It also prevents users from pinning people to the taskbar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidepeoplebar"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hidepeoplebar_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hidepeoplebar_1","displayName":"Enabled","description":"Hide.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_hiderecentjumplists","displayName":"Hide Recent Jumplists (User)","description":"Enabling this policy hides recent jumplists from appearing on the start menu/taskbar and disables the corresponding toggle in the Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hiderecentjumplists"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hiderecentjumplists_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hiderecentjumplists_1","displayName":"Enabled","description":"Hide.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_hiderecentlyaddedapps","displayName":"Hide Recently Added Apps (User)","description":"Enabling this policy hides recently added apps from appearing on the start menu and disables the corresponding toggle in the Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hiderecentlyaddedapps"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hiderecentlyaddedapps_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hiderecentlyaddedapps_1","displayName":"Enabled","description":"Hide.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_startlayout","displayName":"Start Layout (User)","description":"Important For more information, see Policy scope. Allows you to override the default Start layout and prevents the user from changing it. If both user and device policies are set, the user policy will be used. Apps pinned to the taskbar can also be changed with this policyFor further details on how to customize the Start layout, please see Customize and export Start layout and Configure Windows 10 taskbar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#startlayout"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":null},{"id":"user_vendor_msft_policy_config_start_turnoffabbreviateddatetimeformat","displayName":"Turn Off Abbreviated Date Time Format (User)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#turnoffabbreviateddatetimeformat"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_turnoffabbreviateddatetimeformat_0","displayName":"Show abbreviated time and date format","description":"Show abbreviated time and date format","helpText":null},{"id":"user_vendor_msft_policy_config_start_turnoffabbreviateddatetimeformat_1","displayName":"Show classic time and date format","description":"Show classic time and date format","helpText":null}]},{"id":"user_vendor_msft_policy_config_system_allowtelemetry","displayName":"Allow Telemetry (User)","description":"Allow the device to send diagnostic and usage telemetry data, such as Watson. For more information about diagnostic data for Windows, including what is and what is not collected by Windows, see Configure Windows diagnostic data in your organization. Note: This value is only applicable to Windows Enterprise, Windows Education, Windows Mobile Enterprise, Windows IoT Core (IoT Core), Windows Server 2016, and Windows CPC OS. The following tables describe the supported values:Windows 8. 1 Values:0 - Not allowed. 1 - Allowed, except for Secondary Data Requests. 2 (default) - Allowed. Windows 10 Values:0 - Security. Information that is required to help keep Windows or Windows CPC OS more secure, including data about the Connected User Experience and Telemetry component settings, the Malicious Software Removal Tool, and Windows Defender. Note: This value is only applicable to Windows 10 Enterprise, Windows 10 Education, Windows 10 Mobile Enterprise, Windows IoT Core (IoT Core), Windows Server 2016, and Windows CPC OS. Using this setting on other devices is equivalent to setting the value of 1. 1 - Basic. Basic device info, including: quality-related data, app compatibility, app usage data, and data from the Security level. 2 - Enhanced. Additional insights, including: how Windows, Windows Server, System Center, Windows CPC OS, and apps are used, how they perform, advanced reliability data, and data from both the Basic and the Security levels. 3 - Full. All data necessary to identify and help to fix problems, plus data from the Security, Basic, and Enhanced levels. Important lf you are using Windows 8. 1 MDM server and set a value of 0 using the legacy AllowTelemetry policy on a Windows 10 Mobile device, then the value is not respected and the telemetry level is silently set to level 1. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#allowtelemetry"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"user_vendor_msft_policy_config_system_allowtelemetry_0","displayName":"Security","description":"Security. Information that is required to help keep Windows more secure, including data about the Connected User Experience and Telemetry component settings, the Malicious Software Removal Tool, and Windows Defender.\nNote: This value is only applicable to Windows 10 Enterprise, Windows 10 Education, Windows 10 Mobile Enterprise, Windows 10 IoT Core (IoT Core), and Windows Server 2016. Using this setting on other devices is equivalent to setting the value of 1.","helpText":null},{"id":"user_vendor_msft_policy_config_system_allowtelemetry_1","displayName":"Basic","description":"Basic. Basic device info, including: quality-related data, app compatibility, app usage data, and data from the Security level.","helpText":null},{"id":"user_vendor_msft_policy_config_system_allowtelemetry_3","displayName":"Full","description":"Full. All data necessary to identify and help to fix problems, plus data from the Security, Basic, and Enhanced levels.","helpText":null}]},{"id":"user_vendor_msft_policy_config_teamsv2~policy~l_teams_teams_preventfirstlaunchafterinstall_policy","displayName":"Prevent Microsoft Teams from starting automatically after installation (User)","description":"This policy setting controls whether Microsoft Teams starts automatically when the user logs into a device after Teams is installed.\r\n\r\nIf you enable this policy setting, Teams does not start automatically when the user logs in to the device and the user has not started Teams previously.\r\n\r\nNote: If you enable this policy setting, you must do so before Teams is installed.\r\n\r\nOnce a user starts Teams for the first time, Teams is configured to start automatically the next time the user logs into the device.\r\n\r\nIf you disable or don’t configure this policy setting, Teams automatically starts when a user logs in to the device after Teams is installed.\r\n\r\nNote: The user can configure Teams not to start automatically by configuring user settings within Teams.","helpText":"","infoUrls":[],"categoryId":"501b5a30-253c-48b7-ab40-de1d100e4358","categoryName":"Microsoft Teams","options":[{"id":"user_vendor_msft_policy_config_teamsv2~policy~l_teams_teams_preventfirstlaunchafterinstall_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_teamsv2~policy~l_teams_teams_preventfirstlaunchafterinstall_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy","displayName":"Restrict sign in to Teams to accounts in specific tenants (User)","description":"This policy setting allows you to control the accounts that can be used in Teams on managed devices running Windows. \r\n\r\nIf you enable this policy setting, users will only be allowed to sign in with accounts from Azure Active Directory (Azure AD) tenants that you specify. You can enter a comma separated list of tenant IDs. \r\n \r\nThe policy setting applies to all ways that the user signs in, including first and additional accounts on versions of Teams that support multiple accounts side by side. \r\n\r\nThe policy setting is also enforced when users sign out and sign back in. \r\n\r\nIf you disable or don't configure this policy setting, Teams will continue to allow users to sign in with work or school accounts, or personal Microsoft accounts. \r\n\r\nImportant: This policy setting only restricts which users can sign in. It does not restrict the ability for users to be invited as a guest in other Azure AD tenants, or switch to tenants they were invited to.\r\n\r\nNote: This policy does not apply to Teams web app.","helpText":"","infoUrls":[],"categoryId":"501b5a30-253c-48b7-ab40-de1d100e4358","categoryName":"Microsoft Teams","options":[{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy_restrictteamssignintoaccountsfromtenantlist","displayName":"Tenant IDs: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"501b5a30-253c-48b7-ab40-de1d100e4358","categoryName":"Microsoft Teams","options":null},{"id":"user_vendor_msft_policy_config_timelanguagesettings_restrictlanguagepacksandfeaturesinstall","displayName":"Restrict Language Packs And Features Install (User)","description":"This policy setting restricts the install of language packs and language features, such as spell checkers, on a device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TimeLanguageSettings#restrictlanguagepacksandfeaturesinstall"],"categoryId":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","categoryName":"Time Language Settings","options":[{"id":"user_vendor_msft_policy_config_timelanguagesettings_restrictlanguagepacksandfeaturesinstall_0","displayName":"Disabled","description":"Not restricted.","helpText":null},{"id":"user_vendor_msft_policy_config_timelanguagesettings_restrictlanguagepacksandfeaturesinstall_1","displayName":"Enabled","description":"Restricted.","helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"d5b3cab7-d486-4f74-8525-6bd740b950bc","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize98","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d5b3cab7-d486-4f74-8525-6bd740b950bc","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize98_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"d5b3cab7-d486-4f74-8525-6bd740b950bc","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize98_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"d5b3cab7-d486-4f74-8525-6bd740b950bc","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys100","displayName":"Disable shortcut keys (User)","description":"Specify the virtual key code and modifier for the shortcut key to disable.","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys100_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys100_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys100_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"Specify command bar buttons and menu items to disable.","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient","displayName":"File Tab | Share | Email (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlink","displayName":"Insert tab | Hyperlink (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlink_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlink_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosmacros","displayName":"Developer tab | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosmacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosmacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosvisualbasiceditor","displayName":"Developer tab | Visual Basic (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosvisualbasiceditor_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosvisualbasiceditor_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_visiooptions99","displayName":"File tab | Options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_visiooptions99_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_visiooptions99_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab","displayName":"Default tab to show in Visio on the Office Start screen and in File | New (User)","description":"This policy setting controls what displays as the default tab in Visio on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, you can choose one of two options to become the default tab on the Office Start screen and in File | New:\r\n\r\n* Built-in – Users will the see built-in templates tab as the default tab in Visio on the Office Start screen and in File | New.\r\n\r\n* Custom – Users will the see custom templates tab as the default tab in Visio on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Visio on the Office Start screen and in File | New","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab","displayName":"Default tab (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab_0","displayName":"Featured","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab_2","displayName":"Built-in","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab_1","displayName":"Custom","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_disableofficestartvisio","displayName":"Disable the Office Start screen for Visio (User)","description":"This policy setting controls whether the Office Start screen appears on boot for Visio.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot Visio.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot Visio.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_disableofficestartvisio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_disableofficestartvisio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_emailmessageforsendtocommands","displayName":"Email message for 'Send To' commands (User)","description":"Command in the Send To submenu of the File menu.","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_emailmessageforsendtocommands_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_emailmessageforsendtocommands_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_emailmessageforsendtocommands_l_emailmessageforsendtocommands101","displayName":"Email message for 'Send To' commands (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Visio\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Visio\\Addins.\r\n\r\nYou can also obtain the ProgID of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_personaltemplatespath","displayName":"Personal templates path for Visio (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_alwaysoffermetricandusunitsfornewblankdrawings","displayName":"Always offer 'Metric' and 'US units' for new blank drawings and stencils (User)","description":"This policy setting will allow the showing of both US Units and Metric Units when you create a new blank drawing or stencil.\r\n\r\nIf you enable this policy setting, both US Units and Metric Units are shown as a choice before you create a new blank drawing or stencil. These drawings open with the appropriate rulers and page setup and use the appropriate units for the drawing tools. This does not install the templates and stencils in both unit types. This policy setting is always enabled whenever the Developer Tab is turned on.\r\n\r\nIf you disable or do not configure this policy setting, you are not shown a choice between units when creating a blank drawing or stencil if templates and stencils of only one type of unit are installed.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_alwaysoffermetricandusunitsfornewblankdrawings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_alwaysoffermetricandusunitsfornewblankdrawings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle","displayName":"Angle (User)","description":"Specifies the unit of measure for the angle of rotation.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_l_angle8","displayName":"Angle (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_l_angle8_81","displayName":"Degrees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_l_angle8_82","displayName":"Deg-Min-Sec","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_l_angle8_84","displayName":"Min-Sec","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_l_angle8_85","displayName":"Seconds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_l_angle8_83","displayName":"Radians","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration","displayName":"Duration (User)","description":"Specifies the unit of measure for duration, which is elapsed time as compared to a specific date or a given hour.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_l_duration9","displayName":"Duration (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_l_duration9_43","displayName":"Weeks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_l_duration9_44","displayName":"Days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_l_duration9_45","displayName":"Hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_l_duration9_46","displayName":"Minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_l_duration9_47","displayName":"Seconds","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_preventshowingnewscreenonlaunch","displayName":"Prevent showing New screen on launch (User)","description":"This policy setting allows you to prevent the New screen to be shown on launch of Visio.\r\n\r\nIf you enable this policy setting, the New screen will not be shown on launch.\r\n\r\nIf you disable or do not configure this policy setting, the New screen, including a catalog of templates, is shown when you open Visio.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_preventshowingnewscreenonlaunch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_preventshowingnewscreenonlaunch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist","displayName":"Number of entries in the Recent Drawings list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Drawings list that appears when users click Open on the File tab in Backstage view. \r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Drawings list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Drawings list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist_l_numberofentries","displayName":"Number of entries: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"Number of folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_smarttags","displayName":"Actions (User)","description":"Shows additional actions if you hover over them in the drawing.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_smarttags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_smarttags_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear","displayName":"Specify ScreenTips to appear (User)","description":"This policy setting allows you to specify what ScreenTips appear in Visio to help you identify and use various features, including drawing window rulers, control handles, and ShapeSheet cells.\r\n\r\nIf you enable this policy setting, you may specify one or more other ScreenTips that will appear for:\r\n- Drawing\r\n- Dialogs\r\n- Rulers\r\n- ShapeSheet\r\n\r\nIf you disable or do not configure this policy setting, no ScreenTips will appear for the options listed above.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid1","displayName":"Drawing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid1_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid2","displayName":"Dialogs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid2_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid2_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid3","displayName":"Rulers (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid3_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid4","displayName":"Shapesheet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid4_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid4_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_stencilwindowscreentips","displayName":"Stencil window ScreenTips (User)","description":"Specifies whether ScreenTips (ScreenTips: Tips that appear when you pause the pointer over certain elements in the Visio program, including: masters on stencils, toolbar buttons, and the ruler) appear in Visio to help you identify shapes in the stencil window.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_stencilwindowscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_stencilwindowscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text","displayName":"Text (User)","description":"Specifies the unit of measure for indents, line spacing and other text measurements. The default unit for type size is points (1 point = 1/72 in.). You can enter type size in another unit of measure (for example, 1ft or 12 in) but you can't change the default.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_l_text7","displayName":"Text (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_l_text7_51","displayName":"Picas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_l_text7_50","displayName":"Points","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_l_text7_54","displayName":"Ciceros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_l_text7_53","displayName":"Didots","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_centerselectiononzoom","displayName":"Center selection on zoom (User)","description":"Specifies that when you zoom in, whatever shape was selected appears in the center of the window.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_centerselectiononzoom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_centerselectiononzoom_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enableautoconnect","displayName":"Enable AutoConnect (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enableautoconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enableautoconnect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enablelivedynamics","displayName":"Enable live dynamics (User)","description":"When you resize or rotate a shape, you can see the shape as it is being transformed, instead of just seeing the bounding box until the action is complete","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enablelivedynamics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enablelivedynamics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enalbeconnectorsplitting","displayName":"Enable connector splitting (User)","description":"When you place a shape on the line of a connector, it splits and each piece becomes a separate connector glued to the shape. Not all drawing types support connector splitting.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enalbeconnectorsplitting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enalbeconnectorsplitting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_selectshapespartiallywithinarea","displayName":"Select shapes partially within area (User)","description":"If you select shapes by using a selection net(dragging a box around shapes on the drawing page), you can change the selection settings to also include shapes that are partially within the selection net.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_selectshapespartiallywithinarea_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_selectshapespartiallywithinarea_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_showmorehandles","displayName":"Show more handles on hover (User)","description":"This policy setting allows you to show more shape handles when hovering over a selected shape.\r\n\r\nIf you enable this policy setting, more shape handles will be shown after a brief delay.\r\n\r\nIf you disable or do not configure this policy setting, more shape handles will not be shown.\r\n","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_showmorehandles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_showmorehandles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnoffshapesheetformulaautocomplete","displayName":"Turn off ShapeSheet Formula AutoComplete (User)","description":"This policy setting allows you to configure ShapeSheet Formula AutoComplete.\r\n\r\nIf you enable this policy setting, ShapeSheet Formula AutoComplete is turned off.\r\n\r\nIf you disable or do not configure this policy setting, ShapeSheet Formula AutoComplete is turned on.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnoffshapesheetformulaautocomplete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnoffshapesheetformulaautocomplete_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnoffsmartdeletebehaviorofconnectorswhendeletingshapes","displayName":"Turn off smart delete behavior of connectors when deleting shapes (User)","description":"This policy setting turns off smart delete behavior of connectors when deleting shapes.\r\n\r\nIf you enable this policy setting, connectors are not deleted when shapes are deleted.\r\n\r\nIf you disable or do not configure this policy setting, connectors are deleted when shapes are deleted.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnoffsmartdeletebehaviorofconnectorswhendeletingshapes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnoffsmartdeletebehaviorofconnectorswhendeletingshapes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnofftransitions","displayName":"Turn off transitions (User)","description":"This policy setting allows you to configure transitions, which are smooth animation effects.\r\n\r\nIf you enable this policy setting, transitions are turned off.\r\n\r\nIf you disable or do not configure this policy setting, transitions are turned on.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnofftransitions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnofftransitions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_zoomonrollwithintellimouse","displayName":"Zoom on roll with IntelliMouse (User)","description":"If selected, lets you zoom in or out from a drawing by rolling the wheel of the Microsoft Intellimouse","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_zoomonrollwithintellimouse_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_zoomonrollwithintellimouse_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_addons","displayName":"Add-ons (User)","description":"Displays the additional location of macros and add-ons.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_addons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_addons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_addons_l_addonscolon","displayName":"Add-ons: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings","displayName":"Drawings (User)","description":"Displays the additional location of drawings. When you add a location here, it becomes the default save location.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings_l_drawingscolon","displayName":"Drawings: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_favoritesstencilname","displayName":"Favorites Stencil Name (User)","description":"Displays the name of the stencil created in the My Shapes folder that contains a user's favorite shapes.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_favoritesstencilname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_favoritesstencilname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_favoritesstencilname_l_favoritesstencilnamecolon","displayName":"Favorites Stencil Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_help","displayName":"Help (User)","description":"Displays the additional location of Help files.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_help_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_help_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_help_l_helpcolon","displayName":"Help: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes","displayName":"My Shapes (User)","description":"Displays the path of the My Shapes folder.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes_l_myshapescolon","displayName":"My Shapes: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup","displayName":"Start-up (User)","description":"Displays the additional location for macros and add-ons opened when you start Visio.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup_l_startupcolon","displayName":"Start-up: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_stencils","displayName":"Stencils (User)","description":"Displays the additional location of stencils. When a location is added here, stencils in this location are listed on the Shapes submenu from the file menu.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_stencils_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_stencils_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_stencils_l_stencilscolon","displayName":"Stencils: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates","displayName":"Templates (User)","description":"This policy setting allows you to specify the additional location of templates.\r\n\r\nIf you enable this policy setting, you may specify the additional location of templates. These locations are listed on the New screen of the File tab.\r\n\r\nIf you disable or do not configure this policy setting, no additional location of templates is shown.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates_l_templatescolon","displayName":"Templates: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_enableautomationevents","displayName":"Enable Automation events (User)","description":"Enables Visio events to be sent to Visio add-ons and VBA macros. If cleared, disables all Visio events. If you clear this option, some drawing types in Visio that rely on Automation events may not have full functionality.","helpText":"","infoUrls":[],"categoryId":"4e62ada2-f091-49e1-99dd-ffdf5cf558cd","categoryName":"General Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_enableautomationevents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_enableautomationevents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_openeachshapesheetinthesamewindow","displayName":"Open each ShapeSheet in the same window (User)","description":"Opens multiple ShapeSheets in the same window rather than displaying each ShapeSheet in its own window.","helpText":"","infoUrls":[],"categoryId":"4e62ada2-f091-49e1-99dd-ffdf5cf558cd","categoryName":"General Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_openeachshapesheetinthesamewindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_openeachshapesheetinthesamewindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_putallsettingsinwindowsregistry","displayName":"Put all settings in Windows registry (User)","description":"Adds all possible application settings into the Windows registry. By default, only certain settings are added (non-default settings and very few others, such as file paths, import and export filters, and last files) to keep the registry settings simple.","helpText":"","infoUrls":[],"categoryId":"4e62ada2-f091-49e1-99dd-ffdf5cf558cd","categoryName":"General Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_putallsettingsinwindowsregistry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_putallsettingsinwindowsregistry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4","displayName":"Language for file conversion (User)","description":"This policy setting specifies how Visio determines what language to use when converting to or from an earlier version of Visio. \r\n\r\nIf you enable this policy setting, you may select from one of these options:\r\n\r\n- Let Visio decide language\r\n- Prompt for language\r\n- Use the following language: You must specify the numeric Microsoft Locale ID (LCID) for that language.\r\n\r\nIf you disable or do not configure this policy setting, Visio decides what language to use.","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_l_languageforfileconversion5","displayName":"Language for file conversion (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_l_languageforfileconversion5_0","displayName":"Let Visio decide language","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_l_languageforfileconversion5_1","displayName":"Prompt for language","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_l_languageforfileconversion5_2","displayName":"Use the following language","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_l_uselanguage","displayName":"Use language: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfileopenwarnings","displayName":"Show file open warnings (User)","description":"Indicates whether a warning message is displayed when you open files that contain errors such as invalid XML code.","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfileopenwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfileopenwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfilesavewarnings","displayName":"Show file save warnings (User)","description":"Indicates whether a warning message is displayed when you save files that contain errors such as invalid XML code.","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfilesavewarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfilesavewarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_openresultsnewwindow","displayName":"Open results new window (User)","description":"Indicates whether a new search results stencil is created for every search. If cleared, the results of a search replace the results of any previous search.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_openresultsnewwindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_openresultsnewwindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor","displayName":"Search for: (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_l_searchfor10","displayName":"Search for: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_l_searchfor10_1","displayName":"All of the words (AND)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_l_searchfor10_0","displayName":"Any of the words (OR)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults","displayName":"Search results (User)","description":"Specifies whether results are returned in alphabetical order by shape name or by stencil name (group). Click By Group to help distinguish between shapes that have the same name but appear on different stencils. Selecting this option is also useful if you want to locate the stencil containing the shape.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_l_searchresults11","displayName":"Search results (User)","description":"","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_l_searchresults11_0","displayName":"Alphabetically","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_l_searchresults11_1","displayName":"By Group","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_showshapesearchpane","displayName":"Show Shape Search pane (User)","description":"Displays the shape search user interface elements of the stencil window.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_showshapesearchpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_showshapesearchpane_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_donotshowminitoolbaronselectionoftext","displayName":"Do not show Mini Toolbar on selection of text (User)","description":"This policy setting allows you to configure the Mini Toolbar on selection of text.\r\n\r\nIf you enable this policy setting, the Mini Toolbar is not shown on selection.\r\n\r\nIf you disable or do not configure this policy setting, the Mini Toolbar is shown on selection.","helpText":"","infoUrls":[],"categoryId":"a7d55d90-e1d1-4577-8bfd-fe2641bce461","categoryName":"User Interface Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_donotshowminitoolbaronselectionoftext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_donotshowminitoolbaronselectionoftext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_turnofflivepreview","displayName":"Turn off Live Preview (User)","description":"This policy setting allows you to configure Live Preview, which shows a preview of how a feature affects the document as you hover over different choices.\r\n\r\nIf you enable this policy setting, Live Preview is turned off.\r\n\r\nIf you disable or do not configure this policy setting, Live Preview is turned on.","helpText":"","infoUrls":[],"categoryId":"a7d55d90-e1d1-4577-8bfd-fe2641bce461","categoryName":"User Interface Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_turnofflivepreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_turnofflivepreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_turnofflivepreviewintheshapeswindow","displayName":"Turn off Live Preview in the Shapes window (User)","description":"This policy setting turns off the Live Preview in the Shapes window feature, which shows shapes in the Shapes window with the detail and color depth they will have in a drawing, including theme colors and effects.\r\n\r\nIf you enable this policy setting, Live Preview in the Shapes Window is turned off.\r\n\r\nIf you disable or do not configure this policy setting, Live Preview in the Shapes Window is turned on.","helpText":"","infoUrls":[],"categoryId":"a7d55d90-e1d1-4577-8bfd-fe2641bce461","categoryName":"User Interface Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_turnofflivepreviewintheshapeswindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_turnofflivepreviewintheshapeswindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"2764869c-54a3-462b-bc72-c580621ab6bb","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_fractionswithfractioncharacter","displayName":"Fractions with fraction character (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"af9b2941-29f9-4ee5-ae09-215f4e242943","categoryName":"AutoCorrect Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_fractionswithfractioncharacter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_fractionswithfractioncharacter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_hyphenswithdash","displayName":"Hyphens with dash (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"af9b2941-29f9-4ee5-ae09-215f4e242943","categoryName":"AutoCorrect Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_hyphenswithdash_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_hyphenswithdash_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_ordinalswithsuperscript","displayName":"Ordinals with superscript (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"af9b2941-29f9-4ee5-ae09-215f4e242943","categoryName":"AutoCorrect Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_ordinalswithsuperscript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_ordinalswithsuperscript_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_smileyfacesandarrowswithspecialsymbols","displayName":"Smiley faces and arrows with special symbols (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"af9b2941-29f9-4ee5-ae09-215f4e242943","categoryName":"AutoCorrect Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_smileyfacesandarrowswithspecialsymbols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_smileyfacesandarrowswithspecialsymbols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_straightquoteswithsmartquotes","displayName":"Straight quotes with smart quotes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"af9b2941-29f9-4ee5-ae09-215f4e242943","categoryName":"AutoCorrect Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_straightquoteswithsmartquotes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_straightquoteswithsmartquotes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save_l_turnoffcaddwgfunctionality","displayName":"Turn off CAD/DWG functionality (User)","description":"This policy setting allows you to turn off all entry points related to CAD/DWG files.\r\n\r\nIf you enable this policy setting, CAD/DWG functionality will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, CAD/DWG functionality will be turned on.","helpText":"","infoUrls":[],"categoryId":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save_l_turnoffcaddwgfunctionality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save_l_turnoffcaddwgfunctionality_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto","displayName":"Save checked-out files to (User)","description":"This policy setting allows you to choose if checked-out files are saved to the server drafts location or the web server. \r\n\r\nIf you enable this policy setting, you can choose where checked-out files are saved:\r\n- Server drafts location: The server drafts location on this computer\r\n- Web server: The web server\r\n\r\nIf you disable or do not configure this policy setting, checked-out files are stored in the server drafts location.","helpText":"","infoUrls":[],"categoryId":"2eed22da-106f-4c93-9a45-5ce803b50233","categoryName":"Offline Editing","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_l_savecheckedoutfilestodropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2eed22da-106f-4c93-9a45-5ce803b50233","categoryName":"Offline Editing","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_l_savecheckedoutfilestodropid_1","displayName":"Server drafts location","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_l_savecheckedoutfilestodropid_0","displayName":"Web server","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_promptfordocumentpropertiesonfirstsave","displayName":"Prompt for document properties on first save (User)","description":"Indicates whether the properties dialog box opens when a file is saved for the first time. File properties include author name and information such as the status of the file, preview settings and other properties.","helpText":"","infoUrls":[],"categoryId":"73415dea-0103-4427-83c5-6c97bf81af1d","categoryName":"Save Documents","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_promptfordocumentpropertiesonfirstsave_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_promptfordocumentpropertiesonfirstsave_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas","displayName":"Save Visio files as (User)","description":"Identifies the default file format in which Visio files are saved.","helpText":"","infoUrls":[],"categoryId":"73415dea-0103-4427-83c5-6c97bf81af1d","categoryName":"Save Documents","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas_l_savevisiofilesas6","displayName":"Save Visio files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"73415dea-0103-4427-83c5-6c97bf81af1d","categoryName":"Save Documents","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas_l_savevisiofilesas6_0","displayName":"Visio Document","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas_l_savevisiofilesas6_3","displayName":"Visio Macro-Enabled Document","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas_l_savevisiofilesas6_1","displayName":"Visio 2003-2016 Document","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_enablemicrosoftvisualbasicforapplicationsproject","displayName":"Enable Microsoft Visual Basic for Applications project creation (User)","description":"Enables creations of VBA projects when you open (or create) a document that does not already contain a project. If you clear this check box, you will not be able to create a macro in a document that does not already contain a project.","helpText":"","infoUrls":[],"categoryId":"253fda23-118b-48c7-b24a-27b8c93df41a","categoryName":"Macro Security","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_enablemicrosoftvisualbasicforapplicationsproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_enablemicrosoftvisualbasicforapplicationsproject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_loadmicrosoftvisualbasicforapplicationsprojectsf","displayName":"Load Microsoft Visual Basic for Applications projects from text (User)","description":"If you want to be able to have your VBA project work in drawings created in other versions of Visio, select this option so that your VBA project is compiled when the file is loaded, but the compiled project is never saved.","helpText":"","infoUrls":[],"categoryId":"253fda23-118b-48c7-b24a-27b8c93df41a","categoryName":"Macro Security","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_loadmicrosoftvisualbasicforapplicationsprojectsf_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_loadmicrosoftvisualbasicforapplicationsprojectsf_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_allowtrustedlocationsonthenetwork","displayName":"Allow Trusted Locations on the network (User)","description":"This policy setting controls whether trusted locations on the network can be used.\r\n\r\nIf you enable this policy setting, users can specify trusted locations on network shares or in other remote locations that are not under their direct control by clicking the \"Add new location\" button in the Trusted Locations section of the Trust Center. Content, code, and add-ins are allowed to load from trusted locations with minimal security and without prompting the user for permission.\r\n\r\nIf you disable this policy setting, the selected application ignores any network locations listed in the Trusted Locations section of the Trust Center. \r\n\r\nIf you also deploy Trusted Locations via Group Policy, you should verify whether any of them are remote locations. If any of them are remote locations and you do not allow remote locations via this policy setting, those policy keys that point to remote locations will be ignored on client computers.\r\n\r\nDisabling this policy setting does not delete any network locations from the Trusted Locations list, but causes disruption for users who add network locations to the Trusted Locations list. Users are also prevented from adding new network locations to the Trusted Locations list in the Trust Center. We recommended that you do not enable this policy setting (as the \"Allow Trusted Locations on my network (not recommended)\" check box also states). Therefore, in practice, it should be possible to disable this policy setting in most situations without causing significant usability issues for most users.\r\n\r\nIf you do not enable this policy setting, users can select the \"Allow Trusted Locations on my network (not recommended)\" check box if desired and then specify trusted locations by clicking the \"Add new location\" button.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_allowtrustedlocationsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_allowtrustedlocationsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users, except if application add-ins are required to be signed by Trusted Publishers.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User) (Deprecated)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the 2016 versions of the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the 2016 versions of the specified applications are ignored, including any trusted locations established by Office during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the 2016 versions of the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve","displayName":"Set maximum number of trust records to preserve (User)","description":"This policy setting allows you to specify the maximum number of trust records to preserve when the purge task detects that this application has trusted more than the number of trusted documents set by the \"Set maximum number of trusted documents\" policy setting.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of trust records to preserve, with an upper limit of 20000. Due to performance reasons, it is not recommended to set it to the upper limit.\r\n\r\nIf you disable or you do not configure this policy setting, the default value for of 400 is used.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_l_setmaximumnumberoftrustrecordstopreservespinid","displayName":"Maximum to preserve: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_allowsubfolders15","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_allowsubfolders15_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_allowsubfolders15_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_datecolon13","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_descriptioncolon14","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_pathcolon12","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_datecolon17","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_descriptioncolon18","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_pathcolon16","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_datecolon21","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_descriptioncolon22","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_pathcolon20","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_datecolon25","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_descriptioncolon26","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_pathcolon24","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_allowsubfolders31","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_allowsubfolders31_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_allowsubfolders31_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_datecolon29","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_descriptioncolon30","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_pathcolon28","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_allowsubfolders35","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_allowsubfolders35_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_allowsubfolders35_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_datecolon33","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_allowsubfolders39","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_allowsubfolders39_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_allowsubfolders39_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_descriptioncolon38","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_pathcolon36","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_descriptioncolon42","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_pathcolon40","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_datecolon45","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_descriptioncolon46","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_pathcolon44","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11","displayName":"Trusted Location #11 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_allowsubfolders51","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_allowsubfolders51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_allowsubfolders51_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_datecolon49","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_descriptioncolon50","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_pathcolon48","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_allowsubfolders55","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_allowsubfolders55_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_allowsubfolders55_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_descriptioncolon54","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_allowsubfolders59","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_allowsubfolders59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_allowsubfolders59_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_datecolon57","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_descriptioncolon58","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_pathcolon56","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_allowsubfolders63","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_allowsubfolders63_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_allowsubfolders63_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_datecolon61","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_pathcolon60","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_pathcolon64","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_datecolon69","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_descriptioncolon70","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_pathcolon68","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_datecolon73","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_descriptioncolon74","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_pathcolon72","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_datecolon77","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_descriptioncolon78","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_pathcolon76","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_datecolon81","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_descriptioncolon82","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_pathcolon80","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_datecolon85","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_descriptioncolon86","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_pathcolon84","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocuments","displayName":"Turn off trusted documents (User)","description":"This policy setting allows you to turn off the trusted documents feature. The trusted documents feature allows users to always enable active content in documents such as macros, ActiveX controls, data connections, etc. so that they are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.\r\n\r\nIf you enable this policy setting, you will turn off the trusted documents feature. Users will receive a security prompt every time a document containing active content is opened.\r\n\r\nIf you disable or do not configure this policy setting, documents will be trusted when users enable content for a document, and users will not receive a security prompt.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork","displayName":"Turn off Trusted Documents on the network (User)","description":"This policy setting allows you to turn off the trusted documents feature for documents opened from the network.\r\n\r\nIf you enable this policy setting, users will always see security notifications for active content such as macros, ActiveX controls, data connections, etc. for documents opened from the network.\r\n\r\nIf you disable or do not configure this policy setting, the trusted documents feature allows users to always allow active content in documents such as macros, ActiveX controls, data connections, etc. so that users are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files","displayName":"Visio 2000-2002 Binary Drawings, Templates and Stencils (User)","description":"This policy setting allows you to determine whether users can open or save Visio files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked: Both opening and saving of the file type will be blocked.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_l_visio2000filesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_l_visio2000filesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_l_visio2000filesdropid_2","displayName":"Open/Save blocked","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files","displayName":"Visio 2003-2010 Binary Drawings, Templates and Stencils (User)","description":"This policy setting allows you to determine whether users can open or save Visio files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked: Both opening and saving of the file type will be blocked.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid_2","displayName":"Open/Save blocked","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio50andearlierfiles","displayName":"Visio 5.0 or earlier Binary Drawings, Templates and Stencils (User)","description":"This policy setting allows you to determine whether users can open or save Visio files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked: Both opening and saving of the file type will be blocked.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio50andearlierfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio50andearlierfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio50andearlierfiles_l_visio50andearlierfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio50andearlierfiles_l_visio50andearlierfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio50andearlierfiles_l_visio50andearlierfilesdropid_2","displayName":"Open/Save blocked","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v3~policy~l_microsoftvisio~l_visiooptions~l_proofing_l_disablevisiornrpane","displayName":"Turn off Research and Translation features in Visio (User)","description":"\r\n This policy setting controls whether the Research and Translation features appear in Visio.\r\n\r\n If you enable this policy setting, users won’t see the Research and Translation features in Visio.\r\n\r\n If you disable or don't configure this policy setting, users will see the Research and Translation features in Visio.\r\n\r\n Note: This policy setting only applies to subscription versions of Visio and Visio LTSC 2021.\r\n ","helpText":"","infoUrls":[],"categoryId":"8495c82c-f273-4bcc-8886-6751103a9c7b","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_visio16v3~policy~l_microsoftvisio~l_visiooptions~l_proofing_l_disablevisiornrpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v3~policy~l_microsoftvisio~l_visiooptions~l_proofing_l_disablevisiornrpane_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablefeedbackdialog","displayName":"Disable the send-a-smile feature (User)","description":"This policy disables the Visual Studio send-a-smile feature.","helpText":"","infoUrls":[],"categoryId":"802f3065-0bf1-4578-9d6d-ab1ef02db3ec","categoryName":"Feedback Settings","options":[{"id":"user_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablefeedbackdialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablefeedbackdialog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablescreenshotcapture","displayName":"Disables send-a-smile's screenshot capability (User)","description":"This policy disables the screenshot capability in the send-a-smile feature.","helpText":"","infoUrls":[],"categoryId":"802f3065-0bf1-4578-9d6d-ab1ef02db3ec","categoryName":"Feedback Settings","options":[{"id":"user_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablescreenshotcapture_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablescreenshotcapture_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_allowrecallexport","displayName":"Allow Recall Export (User) (Windows Insiders only)","description":"This policy allows you to determine whether Recall and snapshot information can be exported. Recall and snapshot information may be sensitive, and the files that are exported are unencrypted. Users can export from Settings > Privacy & Security > Recall & Snapshots > Advanced Settings > Export your Recall and snapshot info. Users are warned that the files are unencrypted before exporting. When you set this policy to enabled, users will be able to export Recall and snapshot information. If the policy is set to disabled or not configured, users will not be able to export their Recall and snapshot information.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#allowrecallexport"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_allowrecallexport_0","displayName":"Deny export of Recall and snapshots information","description":"Deny export of Recall and snapshots information","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_allowrecallexport_1","displayName":"Allow export of Recall and snapshot information","description":"Allow export of Recall and snapshot information","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_disableaidataanalysis","displayName":"Disable AI Data Analysis (User)","description":"This policy setting allows you to determine whether end users have the option to allow snapshots to be saved on their PCs. If disabled, end users will have a choice to save snapshots of their screen on their PC and then use Recall to find things they've seen. If the policy is enabled, end users will not be able to save snapshots on their PC. If the policy is not configured, end users will not be able to save snapshots on their PC.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disableaidataanalysis"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_disableaidataanalysis_0","displayName":"Enable Saving Snapshots for Windows.","description":"Enable Saving Snapshots for Windows.","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_disableaidataanalysis_1","displayName":"Disable Saving Snapshots for Windows.","description":"Disable Saving Snapshots for Windows.","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_disableclicktodo","displayName":"Disable Click To Do (User)","description":"Click to Do lets people take action on content on their screens. When activated, it takes a screenshot of their screen and analyzes it to present actions. Click to Do ends when they exit it, and it can't take screenshots while closed. Screenshot analysis is always performed locally on their device. By default, Click to Do is enabled for users. This policy setting allows you to determine whether Click to Do is available for users on their device. When the policy is enabled, the Click to Do component and entry points will not be available to users. When the policy is disabled, users will have Click to Do available on their device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disableclicktodo"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_disableclicktodo_0","displayName":"Click to Do is enabled","description":"Click to Do is enabled","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_disableclicktodo_1","displayName":"Click to Do is disabled.","description":"Click to Do is disabled.","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_removemicrosoftcopilotapp","displayName":"Remove Microsoft Copilot App (User)","description":"This policy setting allows you to uninstall Microsoft Copilot from devices in a targeted way. It will apply to devices/users that meet the below conditions: Microsoft 365 Copilot and Microsoft Copilot are both installed; the Microsoft Copilot app was not installed by the user; the Microsoft Copilot app was not launched in the last 14 days. If this policy is enabled, the Microsoft Copilot app will be uninstalled. Users can still re-install if they choose to. This setting applies to Enterprise, Professional and Education client SKUs only.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#removemicrosoftcopilotapp"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_removemicrosoftcopilotapp_0","displayName":"Removal Disabled.","description":"Removal Disabled.","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_removemicrosoftcopilotapp_1","displayName":"Removal Enabled.","description":"Removal Enabled.","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_setcopilothardwarekey","displayName":"Set Copilot Hardware Key (User)","description":"This policy setting determines which app opens when the user presses the Copilot key on their keyboard. If the policy is enabled, the specified app will open when the user presses the Copilot key. Users can change the key assignment in Settings. If the policy is not configured, Copilot will open if it's available in that country or region.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setcopilothardwarekey"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":null},{"id":"user_vendor_msft_policy_config_windowsai_setdenyapplistforrecall","displayName":"Set Deny App List For Recall (User)","description":"This policy allows you to set a semicolon-separated list of app names which should not be collected in Recall Snapshots\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setdenyapplistforrecall"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":null},{"id":"user_vendor_msft_policy_config_windowsai_setdenyurilistforrecall","displayName":"Set Deny Uri List For Recall (User)","description":"This policy allows you to set a semicolon-separated list of uris which should not be collected in Recall Snapshots\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setdenyurilistforrecall"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots","displayName":"Set Maximum Storage Duration For Recall Snapshots (User)","description":"This policy setting allows you to control the maximum amount of time (in days) that Windows saves snapshots for Recall. The default value for this setting is '0' which doesn't set a time frame to delete snapshots. When the default is used, snapshots aren't deleted until the maximum storage allocation for Recall is reached and the oldest snapshots are deleted first. You can configure the maximum storage duration to be 30, 60, 90, or 180 days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setmaximumstoragedurationforrecallsnapshots"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_0","displayName":"Let the OS define the maximum amount of time the snapshots will be saved","description":"Let the OS define the maximum amount of time the snapshots will be saved","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_30","displayName":"30 days","description":"30 days","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_60","displayName":"60 days","description":"60 days","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_90","displayName":"90 days","description":"90 days","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_180","displayName":"180 days","description":"180 days","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots","displayName":"[Deprecated] Set Maximum Storage Space For Recall Snapshots (User) (Windows Insiders only)","description":"This policy setting allows you to control the maximum amount of disk space that can be used by Windows to save snapshots for Recall. The default value of '0' will let the OS configure the amount of storage allocated to snapshots. When the default value of '0' is used, the OS configures the storage allocation for snapshots based on the device storage capacity. 25 GB is allocated when the device storage capacity is 256 GB. 75 GB is allocated when the device storage capacity is 512 GB. 150 GB is allocated when the device storage capacity is 1 TB or higher.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setmaximumstoragespaceforrecallsnapshots"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_0","displayName":"Let the OS define the maximum storage amount based on hard drive storage size","description":"Let the OS define the maximum storage amount based on hard drive storage size","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_10000","displayName":"10GB","description":"10GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_25000","displayName":"25GB","description":"25GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_50000","displayName":"50GB","description":"50GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_75000","displayName":"75GB","description":"75GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_100000","displayName":"100GB","description":"100GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_150000","displayName":"150GB","description":"150GB","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_v2","displayName":"Set Maximum Storage Space For Recall Snapshots (User)","description":"This policy setting allows you to control the maximum amount of disk space that can be used by Windows to save snapshots for Recall. The default value of '0' will let the OS configure the amount of storage allocated to snapshots. When the default value of '0' is used, the OS configures the storage allocation for snapshots based on the device storage capacity. 25 GB is allocated when the device storage capacity is 256 GB. 75 GB is allocated when the device storage capacity is 512 GB. 150 GB is allocated when the device storage capacity is 1 TB or higher.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setmaximumstoragespaceforrecallsnapshots"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_0","displayName":"Let the OS define the maximum storage amount based on hard drive storage size","description":"Let the OS define the maximum storage amount based on hard drive storage size","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_10240","displayName":"10GB","description":"10GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_25600","displayName":"25GB","description":"25GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_51200","displayName":"50GB","description":"50GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_76800","displayName":"75GB","description":"75GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_102400","displayName":"100GB","description":"100GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_153600","displayName":"150GB","description":"150GB","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_turnoffwindowscopilot","displayName":"Turn Off Copilot in Windows (User)","description":"This policy setting allows you to turn off Windows Copilot. If you enable this policy setting, users will not be able to use Copilot. The Copilot icon will not appear on the taskbar either. If you disable or do not configure this policy setting, users will be able to use Copilot when it's available to them.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#turnoffwindowscopilot"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_turnoffwindowscopilot_0","displayName":"Enable Copilot","description":"Enable Copilot","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_turnoffwindowscopilot_1","displayName":"Disable Copilot","description":"Disable Copilot","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging","displayName":"Turn on PowerShell Script Block Logging (User)","description":"\n This policy setting enables logging of all PowerShell script input to the Microsoft-Windows-PowerShell/Operational event log. If you enable this policy setting,\n Windows PowerShell will log the processing of commands, script blocks, functions, and scripts - whether invoked interactively, or through automation.\n \n If you disable this policy setting, logging of PowerShell script input is disabled.\n \n If you enable the Script Block Invocation Logging, PowerShell additionally logs events when invocation of a command, script block, function, or script\n starts or stops. Enabling Invocation Logging generates a high volume of event logs.\n \n Note: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-windowspowershell#windowspowershell-turnonpowershellscriptblocklogging"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"user_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_enablescriptblockinvocationlogging","displayName":"Log script block invocation start / stop events: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"user_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_enablescriptblockinvocationlogging_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_enablescriptblockinvocationlogging_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablewpm","displayName":"Disable lock‑free coauthoring (User)","description":"This policy controls whether Word can use lock‑free coauthoring in collaboration sessions.\n\nLock‑free coauthoring allows multiple collaborators to edit the same paragraph at the same time when supported for a collaboration session.\n\nIf you enable this policy, Word will not use lock‑free coauthoring and will instead use the existing coauthoring behavior to support collaboration across the session.\n\nIf you disable or do not configure this policy, Word will automatically use lock‑free coauthoring when it is supported for a collaboration session.","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablewpm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablewpm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_skipopenduetolonglocalpath","displayName":"Skip Opening Local Files with Long Paths (User)","description":"This policy controls whether Word should skip opening local files with very long paths.\n\nIf you enable this policy, Word will not open local files that have very long paths. Only enable if local files with long paths are causing issues in your environment.\n\nIf you disable or do not configure this policy, Word will open local files with long paths.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_skipopenduetolonglocalpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_skipopenduetolonglocalpath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v10~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_disablemoderncommentsoptoutoption","displayName":"Hide the modern comments opt-out (User)","description":"This policy setting allows you to hide the modern comments opt-out toggle in Word from your users.\r\n\r\nNote: This opt-out toggle is only temporary and will eventually be removed from Word.\r\n\r\nIf you enable this policy setting, the toggle to turn off modern comments will be hidden from your users.\r\n\r\nIf you disable or don't configure this policy setting, your users will be able to temporarily turn off the new modern comments experience from the Options menu in Word. \r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v10~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_disablemoderncommentsoptoutoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v10~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_disablemoderncommentsoptoutoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v11~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_alternateclplabelcontentmarkanchoringoption","displayName":"Use an alternate method of anchoring content marks from CLP labels (User)","description":"This policy setting switches Word to use a alternate method of anchoring content marks associated with CLP labels, which can improve layout for some content marks.\r\n\r\nIf you enable this policy setting, Word will use the alternate content mark anchoring method.\r\n\r\nIf you disable or don't configure this policy setting, Word will use the original content mark anchoring method.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v11~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_alternateclplabelcontentmarkanchoringoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v11~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_alternateclplabelcontentmarkanchoringoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v12~policy~l_microsoftofficeword_l_stopreadaloudeyesoffexperience","displayName":"Stop Read Aloud when app goes in background (User)","description":"This policy prevents Read Aloud from reading text when app goes in background.\r\n\r\nIf you enable this policy setting, Read Aloud will be disabled and will stop reading the text when app is sent to background.\r\n\r\nIf you disable or do not configure this policy setting, Read Aloud will continue reading the text when app moves to background and user will be able to control Read Aloud via notification.","helpText":"","infoUrls":[],"categoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","categoryName":"Microsoft Word 2016","options":[{"id":"user_vendor_msft_policy_config_word16v12~policy~l_microsoftofficeword_l_stopreadaloudeyesoffexperience_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v12~policy~l_microsoftofficeword_l_stopreadaloudeyesoffexperience_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword_l_showesignribbon","displayName":"Allow the use of SharePoint eSignature for Microsoft Word (User)","description":"This policy setting allows you to control whether users can request eSignatures directly from Word in tenants that have enabled Microsoft's native eSignature service.\r\n\r\nIf you enable this policy setting, users can request eSignatures from within Word. This policy setting applies only to subscription versions of Word.\r\n\r\nIf you disable this policy setting, users cannot request eSignatures from within Word.\r\n\r\nIf you don't configure this policy setting, users cannot request eSignatures from within Word.","helpText":"","infoUrls":[],"categoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","categoryName":"Microsoft Word 2016","options":[{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword_l_showesignribbon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword_l_showesignribbon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_startupboostoption","displayName":"Allow Startup Boost feature (User)","description":"This policy setting configures the \"Startup Boost\" checkbox found under File tab | Options | General. Startup Boost improves Word's boot time by prewarming the app on user login.\r\n\r\nIf you enable or do not configure this policy, users will be able to use the Startup Boost feature. The Startup Boost checkbox will be enabled and checked by default.\r\n\r\nIf you disable this policy setting, the Startup Boost feature will not be available. The Startup Boost checkbox will be disabled and unchecked.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_startupboostoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_startupboostoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v14~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_advancedtypographyoutlook","displayName":"Allow Advanced Typography features for Outlook (User)","description":"This policy setting sets the “Advanced Typography” options found under Outlook’s File tab | Outlook Options | Mail | Editor Options | Advanced | Advanced Typography.\r\n\r\nIf you enable or do not configure this policy setting, Advanced Typography features will be applied. This is the default behavior.\r\n\r\nIf you disable this policy setting, Advanced Typography features will not be applied.\r\n ","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v14~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_advancedtypographyoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v14~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_advancedtypographyoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablecoauthoringondocmfiles","displayName":"Prevent co-authoring on files with macros for Word (User)","description":"This policy controls whether users will be able to co-author Word documents with macros.\r\n\r\nEnabling this policy setting will turn off the ability to co-author Word documents with macros.\r\n\r\nIf you disable or don't configure this policy setting, the user will be able to co-author Word documents with macros.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablecoauthoringondocmfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablecoauthoringondocmfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablertc","displayName":"Disable Real Time Coauthoring for Word (User)","description":"This policy lets admins disable Real Time Coauthoring. They may want to do so if they have solutions that are not compatible with some elements of real time coauthoring, such as add-ins that would trigger too often due to Real Time Coauthoring causing the frequent saving of user content. \r\n\r\nIf you enable this policy setting, it will prevent Real Time Coauthoring. \r\n\r\nIf you disable or do not configure this policy setting, users will be able to experience Real Time Coauthoring feature.","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablertc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablertc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_donotautomaticallymergeserverandlocaldocument","displayName":"Do not automatically merge server and local document (User)","description":"This policy setting determines if changes made to a server document should be automatically merged with the locally-cached copy of the document on the next save. This policy pertains to the co-authoring experience in Word.\r\n\r\nIf you enable this policy setting, then changes made to a server document will not be automatically merged with the locally-cached copy of the document on the next save. \r\n\r\nIf you disable or do not configure this policy setting, then changes made to a server document will be automatically merged with the locally-cached copy of the document on the next save.","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_donotautomaticallymergeserverandlocaldocument_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_donotautomaticallymergeserverandlocaldocument_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_preventcoauthoring","displayName":"Prevent co-authoring (User)","description":"This policy setting controls how Word opens a file for editing on document management servers that support co-authoring.\r\n\r\nIf you enable this policy setting, Word will prevent co-authoring by taking an exclusive file lock. \r\n\r\nIf you disable or do not configure this policy setting, Word will allow co-authoring by taking short-term shared locks. \r\n\r\nNote: When file synchronization via SOAP over HTTP is turned off it will prevent co-authoring.","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_preventcoauthoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_preventcoauthoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize97","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize97_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize97_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable some specific commands in Microsoft Word. Commands are buttons, menus, or other items that can be added to the Quick Access Toolbar or to the Ribbon under File tab | Options | Quick Access Toolbar or via File | Options | Customize Ribbon, respectively.\r\n\r\nIf you enable this policy setting then you can specify what commands in the user interface for Word are disabled.\r\n\r\nIf you disable or do not configure this policy setting, the commands in the predefined list are all enabled in Word.","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient","displayName":"File tab | Share | Email (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview","displayName":"File tab | Options | (\"Customize Ribbon\" or \"Quick Access Toolbar\") | All Commands | Web Page Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlinkwd","displayName":"Insert tab | Links | Hyperlink (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlinkwd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlinkwd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacroswd","displayName":"Developer tab | Code | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacroswd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacroswd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrorecordnewmacro","displayName":"Developer tab | Code | Record Macro (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrorecordnewmacro_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrorecordnewmacro_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity","displayName":"Developer tab | Code | Macro Security (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorwd","displayName":"Developer tab | Code | Visual Basic (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorwd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorwd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrowd","displayName":"View tab | Macros | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrowd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrowd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsprotectdocument","displayName":"File tab | Info | Protect Document (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsprotectdocument_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsprotectdocument_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolstemplatesandaddins","displayName":"Developer tab | Templates | Document Template (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolstemplatesandaddins_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolstemplatesandaddins_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddresswd","displayName":"File tab | Options | (\"Customize Ribbon\" or \"Quick Access Toolbar\") | All Commands | Document Location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddresswd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddresswd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable specific shortcut key combinations in the specified applications. \r\n\r\nIf you enable this policy setting you can disable specific shortcut keys for the selected application. The predefined list of shortcut keys you can disable becomes available to you when you enable this policy setting. \r\n\r\nIf you disable or do not configure this policy setting, the predefined list of shortcut keys are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditorwd","displayName":"Alt+F11 (Developer | Code | Visual Basic) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditorwd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditorwd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros","displayName":"Alt+F8 (Developer | Code | Macros) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindwd","displayName":"Ctrl+F (Home | Editing | Find) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindwd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindwd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkwd","displayName":"Ctrl+K (Insert | Links | Hyperlink) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkwd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkwd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation","displayName":"Check for accessibility issues while editing (User)","description":"This policy setting controls whether accessibility issues are checked for automatically while the user is editing a document. By default, accessibility issues aren’t checked for automatically.\r\n\r\nIf you enable this policy setting, accessibility issues are checked for automatically and users won’t be able to turn it off. The status bar will indicate if accessibility recommendations are available to make the document more usable by people with disabilities.\r\n\r\nIf you disable or don’t configure this policy setting, accessibility issues won’t be checked for automatically while editing a document. Users can turn on automatic checking by going to File > Options > Ease of Access.\r\n","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation","displayName":"Stop checking for alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that objects such as images and shapes contain alt text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that objects such as images and shapes contain alt text.\r\n\r\nIf you disable or do not configure this policy setting, objects will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingblankcharactersusedforformatting","displayName":"Stop checking whether blank characters are used for formatting (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that multiple consecutive whitespace characters have not been used for formatting.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that multiple consecutive whitespace characters have not been used for formatting.\r\n\r\nIf you disable or do not configure this policy setting, documents will be checked for consecutive whitespace usage and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingblankcharactersusedforformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingblankcharactersusedforformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingdocumentsallowprogrammaticaccess","displayName":"Stop checking to ensure documents allow programmatic access (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that documents have not blocked programmatic access through DRM.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that documents have not blocked programmatic access through DRM.\r\n\r\nIf you disable or do not configure this policy setting, documents will be checked for programmatic access and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingdocumentsallowprogrammaticaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingdocumentsallowprogrammaticaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsandcolumns","displayName":"Stop checking for blank table rows and columns (User)","description":"This policy setting prevents the Accessibility Checker from verifying that blank rows and columns have not been inserted into tables.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that blank rows and columns have not been inserted into tables.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for blank rows and columns and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsandcolumns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsandcolumns_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforimagewatermarks","displayName":"Stop checking for image watermarks (User)","description":"This policy setting prevents the Accessibility Checker from checking if a document has image watermarks.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking if a document has image watermarks.\r\n\r\nIf you disable or do not configure this policy setting, documents will be checked for watermarks and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforimagewatermarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforimagewatermarks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingformergedandsplitcells","displayName":"Stop checking for merged and split cells (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables do not have merged or split cells.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables do not have merged or split cells.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for merged and split cells and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingformergedandsplitcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingformergedandsplitcells_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingfortablesusedforlayout","displayName":"Stop checking for tables used for layout (User)","description":"This policy setting prevents the Accessibility Checker from flagging layout tables (i.e. tables with no style applied).\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging layout tables (i.e. tables with no style applied).\r\n\r\nIf you disable or do not configure this policy setting, tables with no style will be flagged and the violations will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingfortablesusedforlayout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingfortablesusedforlayout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingheadingstylesdonotskipstylelevel","displayName":"Stop checking to ensure heading styles do not skip style level (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that headings in a document are used in order.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that headings in a document are used in order.\r\n\r\nIf you disable or do not configure this policy setting, the ordering of headings in a document will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingheadingstylesdonotskipstylelevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingheadingstylesdonotskipstylelevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckinglongdocumentsusestylesforstructure","displayName":"Stop checking to ensure long documents use styles for structure (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that long documents have used styles to define content structure.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that long documents have used styles to define content structure.\r\n\r\nIf you disable or do not configure this policy setting, documents will be checked for style usage and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckinglongdocumentsusestylesforstructure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckinglongdocumentsusestylesforstructure_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingstylesusedfrequently","displayName":"Stop checking to ensure styles have been used frequently (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that documents using styles have used them frequently enough to accurately represent the document's content structure.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that documents using styles have used them frequently enough to accurately represent the document's content structure.\r\n\r\nIf you disable or do not configure this policy setting, the frequency of style usage will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingstylesusedfrequently_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingstylesusedfrequently_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation","displayName":"Stop checking for table header accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables have a header row specified.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables have a header row specified.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for header rows and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensureheadingsaresuccinct","displayName":"Stop checking to ensure headings are succinct (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that headings in a document are succinct.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that headings in a document are succinct.\r\n\r\nIf you disable or do not configure this policy setting, document headings will be checked for length and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensureheadingsaresuccinct_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensureheadingsaresuccinct_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful","displayName":"Stop checking to ensure hyperlink text is meaningful (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingwhetherobjectsarefloating","displayName":"Stop checking whether objects are floating (User)","description":"This policy setting prevents the Accessibility Checker from checking if a document has objects that are floating instead of inline.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking if a document has objects that are floating instead of inline.\r\n\r\nIf you disable or do not configure this policy setting, objects will be checked for floating text wrapping properties and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingwhetherobjectsarefloating_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingwhetherobjectsarefloating_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorepunctuationcharacters","displayName":"Ignore punctuation characters (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorepunctuationcharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorepunctuationcharacters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorewhitespacecharacters","displayName":"Ignore whitespace characters (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorewhitespacecharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorewhitespacecharacters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchbavahafa","displayName":"Match ba/va, ha/fa (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchbavahafa_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchbavahafa_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchcase","displayName":"Match case (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchcase_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchcase_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchchoonusedforvowels","displayName":"Match cho-on used for vowels (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchchoonusedforvowels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchchoonusedforvowels_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchcontractionsyoonsokuon","displayName":"Match contractions (yo-on, sokuon) (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchcontractionsyoonsokuon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchcontractionsyoonsokuon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchdiziduzu","displayName":"Match di/zi, du/zu (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchdiziduzu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchdiziduzu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchfullhalfwidthform","displayName":"Match full/half width form (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchfullhalfwidthform_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchfullhalfwidthform_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhiraganakatakana","displayName":"Match hiragana/katakana (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhiraganakatakana_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhiraganakatakana_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhyuiyubyuvyu","displayName":"Match hyu/iyu, byu/vyu (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhyuiyubyuvyu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhyuiyubyuvyu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchiaiyapianopiyano","displayName":"Match ia/iya (piano/piyano) (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchiaiyapianopiyano_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchiaiyapianopiyano_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchkikutekisutotekusuto","displayName":"Match ki/ku (tekisuto/tekusuto) (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchkikutekisutotekusuto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchkikutekisutotekusuto_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchminusdashchoon","displayName":"Match minus/dash/cho-on (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchminusdashchoon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchminusdashchoon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matcholdkanaforms","displayName":"Match old kana forms (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matcholdkanaforms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matcholdkanaforms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchrepeatcharactermarks","displayName":"Match 'repeat character' marks (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchrepeatcharactermarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchrepeatcharactermarks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchseshezeje","displayName":"Match se/she, ze/je (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchseshezeje_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchseshezeje_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchtsithichidhizi","displayName":"Match tsi/thi/chi, dhi/zi (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchtsithichidhizi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchtsithichidhizi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchvariantformkanjiitaiji","displayName":"Match variant-form kanji (itaiji) (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchvariantformkanjiitaiji_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchvariantformkanjiitaiji_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_alternaterevisionbarpositioninprinteddocument","displayName":"Alternate revision bar position in printed document (User)","description":"Checked: For a multi-column page, revision bars are printed to the side of the column in which the revision appears. | Unchecked: For a multi-column page, revision bars are printed to the side of the page in which the revision appears.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_alternaterevisionbarpositioninprinteddocument_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_alternaterevisionbarpositioninprinteddocument_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_defaultcustomtab","displayName":"Show custom templates tab by default in Word on the Office Start screen and in File | New (User)","description":"This policy setting controls whether custom templates (when they exist) show as the default tab in Word on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, users will the see custom templates tab as the default tab in Word on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Word on the Office Start screen and in File | New, unless all Office-provided templates have been disabled.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_defaultcustomtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_defaultcustomtab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_disablemrulistinfontdropdown","displayName":"Disable MRU list in font dropdown (User)","description":"This policy allows you to hide the list of recently used fonts found under Home tab | Font.\r\n\r\nIf you enable this policy setting, the list of recently used fonts will not be shown.\r\n\r\nIf you disable or do not configure this policy setting, the list of recently used fonts will be shown.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_disablemrulistinfontdropdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_disablemrulistinfontdropdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_disableofficestartword","displayName":"Disable the Office Start screen for Word (User)","description":"This policy setting controls whether the Office Start screen appears on boot for Word.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot Word.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot Word.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_disableofficestartword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_disableofficestartword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinemachinetranslation","displayName":"Do not use online machine translation (User)","description":"This policy setting allows you to prevent online machine translation services from being used for the translation of documents and text through the Research pane.\r\n\r\nIf you enable this policy setting, online machine translation services cannot be used to translate documents and text through the Research pane.\r\n\r\nIf you disable or do not configure this policy setting, online machine translation services can be used to translate text through the Research pane.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinemachinetranslation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinemachinetranslation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinetranslationdictionaries","displayName":"Use online translation dictionaries (User)","description":"This policy setting allows you to prevent online dictionaries from being used for the translation of text through the Research pane.\r\n\r\nIf you enable or do not configure this policy setting, the online dictionaries can be used to translate text through the Research pane.\r\n\r\nIf you disable this policy setting, the online dictionaries cannot be used to translate text through the Research pane.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinetranslationdictionaries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinetranslationdictionaries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins, or specify the file name of Word add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\Word\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\Word\\Addins.\r\n\r\nTo obtain the file name of an add-in, click the File menu in the application where the add-in is installed. Click Options, click Add-ins, and then use the Location column to determine the file name of the add-in.\r\n\r\nYou can also obtain the ProgID or the file name of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.\r\n\r\nTo specify that a Word add-in is always enabled, in addition to configuring this policy setting, you must also specify a location that is used as a trusted source for open files in Word. To do this, configure the \"Trusted Locations\" policy setting at User Configuration\\Administrative Templates\\Microsoft Word 2016\\Word Options\\Security\\Trust Center, and then move the add-in file into the trusted location.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_personaltemplatespath","displayName":"Personal templates path for Word (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_showpeople","displayName":"Show pictures in comments (User)","description":"This policy setting determines whether or not comments show pictures.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_showpeople_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_showpeople_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_toolscompareandmergedocumentslegalblackline","displayName":"Tools | Compare and Merge Documents, Legal blackline (User)","description":"If you enable this policy setting, a comparison between two documents automatically generates a new Legal Blackline document, leaving the original documents unchanged.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_toolscompareandmergedocumentslegalblackline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_toolscompareandmergedocumentslegalblackline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference","displayName":"Volume preference (User)","description":"This policy setting allows you to configure Microsoft Word to retain file path information when you work with files on a network server, either as a mapped drive (Z:\\Folder_Name\\File_Name) or as Universal Naming Convention (UNC) (\\\\Share_Name\\File_Name).\r\n\r\nIf you enable this policy setting, you may select one of these options:\r\n- Use Drive letter or UNC as entered\r\n- Convert Drive letter to UNC\r\n- Convert UNC to Drive letter\r\n\r\nIf you disable or do not configure this policy setting, the default option is \"Use Drive letter or UNC as entered.\"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference_l_volumepreference179","displayName":"Volume preference (User)","description":"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference_l_volumepreference179_0","displayName":"Use Drive letter or UNC as entered","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference_l_volumepreference179_2","displayName":"Convert Drive letter to UNC","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference_l_volumepreference179_1","displayName":"Convert UNC to Drive letter","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp","displayName":"Turn off file synchronization via SOAP over HTTP (User)","description":"This policy setting controls file synchronization via SOAP over HTTP for Word.\r\n\r\nIf you enable this policy setting, file synchronization via SOAP over HTTP is turned off for Word.\r\n\r\nIf you disable or do not configure this policy setting this policy setting, file synchronization via SOAP over HTTP is turned on for Word.\r\n\r\nNote: Turning off file synchronization via SOAP over HTTP will also prevent co-authoring and adversely affect the behavior of SharePoint Workspaces.","helpText":"","infoUrls":[],"categoryId":"b206e4ef-a288-4fb7-a7ee-4a30b4df3b98","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_convertcommonterms","displayName":"Convert common terms (User)","description":"Checks/unchecks the corresponding UI option in the \"Chinese Conversion\" dialog, which found under Review tab | Convert with Options button. This may only be visible when Chinese is enabled as an editing language.","helpText":"","infoUrls":[],"categoryId":"7bee4dea-82a4-4a03-b903-654b374819b1","categoryName":"Chinese Conversion | Convert with Options","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_convertcommonterms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_convertcommonterms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_translationdirection","displayName":"Translation direction (User)","description":"This policy setting allows you to set the default translation direction for Chinese text.\r\n\r\nIf you enable this policy setting, the selected option will check the corresponding checkbox in the \"Chinese Conversion\" dialog. This dialog is found in the Review tab | \"Convert with Options\" button. This may only be visible when Chinese is enabled as an editing language. \r\n\r\nIf you disable or do not configure this policy setting, either translation direction may be set.","helpText":"","infoUrls":[],"categoryId":"7bee4dea-82a4-4a03-b903-654b374819b1","categoryName":"Chinese Conversion | Convert with Options","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_translationdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_translationdirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_translationdirection_l_translationdirection96","displayName":"Translation direction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7bee4dea-82a4-4a03-b903-654b374819b1","categoryName":"Chinese Conversion | Convert with Options","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_translationdirection_l_translationdirection96_2052","displayName":"Traditional Chinese to Simplified Chinese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_translationdirection_l_translationdirection96_1028","displayName":"Simplified Chinese to Traditional Chinese","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_usetaiwanhongkongsarandmacaosarcharactervariants","displayName":"Use Taiwan, Hong Kong SAR and Macao SAR character variants (User)","description":"This policy setting allows you to configure the \"Chinese Conversion\" dialog, which is accessed by the \"Convert with Options\" button in the Review tab. This may only be visible when Chinese is enabled as an editing language.\r\n\r\nIf you enable this policy setting, the option is selected.\r\n\r\nIf you disable or do not configure this policy setting, the option is not selected.","helpText":"","infoUrls":[],"categoryId":"7bee4dea-82a4-4a03-b903-654b374819b1","categoryName":"Chinese Conversion | Convert with Options","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_usetaiwanhongkongsarandmacaosarcharactervariants_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_usetaiwanhongkongsarandmacaosarcharactervariants_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewsetlanguage_l_detectlanguageautomatically","displayName":"Detect language automatically (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"d79c9f9a-f469-4f39-a66a-6f7d5ee77e81","categoryName":"Language | Set Proofing Language...","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewsetlanguage_l_detectlanguageautomatically_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewsetlanguage_l_detectlanguageautomatically_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addbidirectionalmarkswhensavingtextfiles","displayName":"Add Bi-Directional Marks when saving Text files (User)","description":"Checked: Add Bi-Directional Marks when saving Text files. | Unchecked: Do not add Bi-Directional Marks when saving Text files.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addbidirectionalmarkswhensavingtextfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addbidirectionalmarkswhensavingtextfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addcontrolcharactersincutandcopy","displayName":"Add control characters in Cut and Copy (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addcontrolcharactersincutandcopy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addcontrolcharactersincutandcopy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_adddoublequoteforhebrewalphabetnumbering","displayName":"Add double quote for Hebrew alphabet numbering (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_adddoublequoteforhebrewalphabetnumbering_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_adddoublequoteforhebrewalphabetnumbering_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowa4letterpaperresizing","displayName":"Scale content for A4 or 8.5'' x 11'' paper sizes (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowa4letterpaperresizing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowa4letterpaperresizing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowaccenteduppercaseinfrench","displayName":"Allow accented uppercase in French (User)","description":"Checks/unchecks the option ''Enforce accented uppercase in French''.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowaccenteduppercaseinfrench_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowaccenteduppercaseinfrench_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowbackgroundsaves","displayName":"Allow background saves (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowbackgroundsaves_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowbackgroundsaves_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_alwayscreatebackupcopy","displayName":"Always create backup copy (User)","description":"Checks/unchecks the corresponding UI option found under File tab | Options | Advanced | Save.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_alwayscreatebackupcopy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_alwayscreatebackupcopy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_asianfontsalsoapplytolatintext","displayName":"Asian fonts also apply to Latin text (User)","description":"Checks/unchecks the corresponding UI option. This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_asianfontsalsoapplytolatintext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_asianfontsalsoapplytolatintext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_autokeyboardswitching","displayName":"Auto-Keyboard switching (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_autokeyboardswitching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_autokeyboardswitching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_automaticallycreatedrawingcanvaswheninsertingautoshapes","displayName":"Automatically create drawing canvas when inserting AutoShapes (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_automaticallycreatedrawingcanvaswheninsertingautoshapes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_automaticallycreatedrawingcanvaswheninsertingautoshapes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backgroundprinting","displayName":"Print in background (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backgroundprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backgroundprinting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backofthesheet","displayName":"Print on back of the sheet for duplex printing (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backofthesheet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backofthesheet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_bookmarks","displayName":"Show bookmarks (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_bookmarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_bookmarks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_chartreftrackingenabled","displayName":"Allow formatting and labels to track data points (User)","description":"This policy setting governs how custom formatting and data labels react to data changes in a chart.\r\n\r\nIf you enable or do not configure this policy setting, when the user creates a new presentation, custom formatting and data labels follow data points as they move or change in any chart in the workbook.\r\n\r\nIf you disable this policy setting, custom formatting and data labels do not follow data points, but instead follow data point indices.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_chartreftrackingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_chartreftrackingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_confirmconversionatopen","displayName":"Confirm file format conversion on open (User)","description":"This policy setting allows you to set the \"Confirm file format conversion on open\" option in Word Options | Advanced | General.\r\n\r\nIf you enable this policy setting, \"Confirm file format conversion on open\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Confirm file format conversion on open\" will not be set.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_confirmconversionatopen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_confirmconversionatopen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_controlcharacters","displayName":"Show control characters (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_controlcharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_controlcharacters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_copyremotelystoredfiles","displayName":"Copy remotely stored files onto your computer, and update the remote file when saving (User)","description":"This policy setting allows you to set the \"Copy remotely stored files onto your computer, and update the remote file when saving\" option in Word Options | Advanced | Save.\r\n\r\nIf you enable this policy setting, \"Copy remotely stored files onto your computer, and update the remote file when saving\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Copy remotely stored files onto your computer, and update the remote file when saving\" will not be set.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_copyremotelystoredfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_copyremotelystoredfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning","displayName":"Custom markup warning (User)","description":"This policy setting specifies how Word behaves when opening a document that contains custom XML markup.\r\n\r\nIf you enable this policy setting, you can set the behavior to one of the following: \r\n\r\n- 0: Do not prompt the user and silently remove the custom XML markup. \r\n\r\n- 1: Prompt the user regarding the loss of custom XML markup. This is the default option. \r\n\r\n- 2: Prompt the user regarding the loss of custom XML markup, and do not allow them to suppress this prompt. \r\n\r\n- 3: Prompt the user regarding the loss of custom XML markup, and open the file read-only. \r\n\r\n- 4: Prompt the user regarding the loss of custom XML markup, do not allow them to suppress this prompt, and open the file read-only. \r\n\r\n- 5: Do not prompt the user and silently remove the custom XML markup, but open the file read-only.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid","displayName":"Custom markup warning: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid_0","displayName":"Do not prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid_1","displayName":"Prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid_2","displayName":"Always prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid_3","displayName":"Prompt and open the file read-only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid_4","displayName":"Always prompt and open the file read-only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid_5","displayName":"Do not prompt and open the file read-only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_diacritics","displayName":"Diacritics (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_diacritics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_diacritics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_differentcolorfordiacritics","displayName":"Use this color for diacritics (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_differentcolorfordiacritics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_differentcolorfordiacritics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_documentview","displayName":"Document view (User)","description":"Used for complex scripts. Specifies if documents shall be displayed Right-to-left or Left-to-right.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_documentview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_documentview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_documentview_l_documentview7","displayName":"Document view (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_documentview_l_documentview7_1","displayName":"Right-to-left","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_documentview_l_documentview7_0","displayName":"Left-to-Right","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draftfont","displayName":"Use draft font in Draft and Outline views (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draftfont_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draftfont_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draftoutput","displayName":"Use draft quality (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draftoutput_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draftoutput_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draganddroptextediting","displayName":"Allow text to be dragged and dropped (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draganddroptextediting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draganddroptextediting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_drawings","displayName":"Show drawings and text boxes on screen (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_drawings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_drawings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_enableclickandtype","displayName":"Enable click and type (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_enableclickandtype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_enableclickandtype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents","displayName":"English Word 6.0/95 documents (User)","description":"Sets the option to convert the file correctly.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents_l_englishword6095documents11","displayName":"English Word 6.0/95 documents (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents_l_englishword6095documents11_0","displayName":"Contain Asian text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents_l_englishword6095documents11_1","displayName":"Open normally","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents_l_englishword6095documents11_2","displayName":"Automatically detect Asian text","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuimaximumzoomlevel","displayName":"Set the maximum zoom level for expand / collapse on-object UI (User)","description":"This policy setting allows you to specify the maximum zoom level percentage at which point the expand/collapse on-object UI stops rendering. Regardless of the value specified for this policy setting, the expand / collapse feature is still available from the context menu for headings.\r\n\r\nIf you enable this policy setting, you can specify a maximum zoom level percentage from 0-500. If you specify a value of 0, the on-object UI never renders.\r\n\r\nIf you disable or do not configure this policy setting, there will be no maximum.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuimaximumzoomlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuimaximumzoomlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuimaximumzoomlevel_l_setexpandcollapseuimaximumzoomlevelspinid","displayName":"Set the maximum zoom level for expand / collapse on-object UI (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuiminimumzoomlevel","displayName":"Set the minimum zoom level for expand / collapse on-object UI (User)","description":"This policy setting allows you to specify the minimum zoom level percentage at which point the expand/collapse on-object UI stops rendering. Regardless of the value specified for this policy setting, the expand / collapse feature is still available from the context menu for headings.\r\n\r\nIf you enable this policy setting, you can specify a minimum zoom level percentage from 0-500.\r\n\r\nIf you disable or do not configure this policy setting, the minimum zoom level is set to 50%.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuiminimumzoomlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuiminimumzoomlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuiminimumzoomlevel_l_setexpandcollapseuiminimumzoomlevelspinid","displayName":"Set the minimum zoom level for expand / collapse on-object UI (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldcodes","displayName":"Show field codes instead of their values (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldcodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldcodes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading","displayName":"Field shading (User)","description":"Specifies when field shading is displayed.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading_l_fieldshading6","displayName":"Field shading (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading_l_fieldshading6_0","displayName":"Never","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading_l_fieldshading6_1","displayName":"Always","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading_l_fieldshading6_2","displayName":"When selected","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_frontofsheet","displayName":"Print on front of the sheet for duplex printing (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_frontofsheet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_frontofsheet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_horizontalscrollbar","displayName":"Show horizontal scroll bar (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_horizontalscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_horizontalscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_imecontrolactive","displayName":"IME Control Active (User)","description":"Checks/unchecks the corresponding UI option. This option only appears if you configure Word to use an IME.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_imecontrolactive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_imecontrolactive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_imetrueinline","displayName":"IME TrueInLine (User)","description":"Checks/unchecks the corresponding UI option. This option only appears if you configure Word to use an IME.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_imetrueinline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_imetrueinline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_keeptrackofformatting","displayName":"Keep track of formatting (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_keeptrackofformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_keeptrackofformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_leftscrollbar","displayName":"Left scroll bar (User)","description":"Checks/unchecks the corresponding UI option. This option is only available if support for right-to-left languages is enabled through Microsoft Office Language Preferences. This setting also sets Right ruler (Print view only).","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_leftscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_leftscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies","displayName":"Mark formatting inconsistencies (User)","description":"Defines color to use for marking formatting inconsistencies.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_checktoenforcesettingonunchecktoenforcesettingoff18","displayName":"Check to enforce setting on; uncheck to enforce setting off (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_checktoenforcesettingonunchecktoenforcesettingoff18_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_checktoenforcesettingonunchecktoenforcesettingoff18_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies","displayName":"Color for marking formatting inconsistencies (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_0","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_255","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_128","displayName":"Dark Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_3368703","displayName":"Light Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_52479","displayName":"Sky Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_10079487","displayName":"Pale Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_6710937","displayName":"Blue Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_65280","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_32768","displayName":"Dark Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_13056","displayName":"Darker Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_13434828","displayName":"Light Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_3355392","displayName":"Olive Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_3381606","displayName":"Sea Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16711680","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_8388608","displayName":"Dark Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16776960","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_8421376","displayName":"Dark Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16777113","displayName":"Light Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16777215","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_10040064","displayName":"Brown","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16737792","displayName":"Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16750848","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_65535","displayName":"Cyan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_32896","displayName":"Dark Cyan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_13434879","displayName":"Light Cyan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16711935","displayName":"Magenta","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_8388736","displayName":"Dark Magenta","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_13158","displayName":"Dark Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_3355545","displayName":"Indigo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_10079232","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_3394764","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16763904","displayName":"Gold","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_10040166","displayName":"Plum","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16751052","displayName":"Rose","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16764057","displayName":"Tan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_13408767","displayName":"Lavender","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_8421504","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_12632256","displayName":"Gray 25%","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits","displayName":"Show measurements in units of (User)","description":"Selects the default measurement unit for the horizontal ruler and for measurements in dialog boxes.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_l_selectunits","displayName":"Select units: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_l_selectunits_0","displayName":"Inches","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_l_selectunits_2","displayName":"Centimeters","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_l_selectunits_4","displayName":"Millimeters","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_l_selectunits_1","displayName":"Points","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_l_selectunits_3","displayName":"Picas","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames","displayName":"Month names (User)","description":"Used for complex scripts. Specifies if month names shall be of calendar type Gregorian Arabic, Gregorian transliterated English, or Gregorian transliterated French.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_l_monthnames17","displayName":"Month names (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_l_monthnames17_0","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_l_monthnames17_1","displayName":"English transliterated","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_l_monthnames17_2","displayName":"French transliterated","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_movement","displayName":"Cursor movement (User)","description":"Used for complex scripts. Specifies if logical or visual cursor control shall be used.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_movement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_movement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_movement_l_movement4","displayName":"Cursor movement (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_movement_l_movement4_0","displayName":"Logical","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_movement_l_movement4_1","displayName":"Visual","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral","displayName":"Numeral (User)","description":"Used for complex scripts. Specifies if numerals shall be displayed as Arabic, Hindi, Context, or System numerals. ","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_l_numeral16","displayName":"Numeral (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_l_numeral16_0","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_l_numeral16_1","displayName":"Hindi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_l_numeral16_2","displayName":"Context","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_l_numeral16_3","displayName":"System","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_pictureplaceholders","displayName":"Show picture placeholders (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_pictureplaceholders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_pictureplaceholders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_promptbeforesavingnormaltemplate","displayName":"Prompt before saving Normal template (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_promptbeforesavingnormaltemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_promptbeforesavingnormaltemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_prompttoupdatestyle","displayName":"Prompt to update style (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_prompttoupdatestyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_prompttoupdatestyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_providefeedbackwithanimation","displayName":"Provide feedback with animation (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_providefeedbackwithanimation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_providefeedbackwithanimation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_recentlyusedfilelist","displayName":"Number of documents in the Recent Documents list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Documents list that appears when users click Open on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Documents list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Documents list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_recentlyusedfilelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_recentlyusedfilelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_recentlyusedfilelist_l_numberofentries","displayName":"Number of entries: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_reverseprintorder","displayName":"Print pages in reverse order (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_reverseprintorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_reverseprintorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_showpixelsforhtmlfeatures","displayName":"Show pixels for HTML features (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_showpixelsforhtmlfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_showpixelsforhtmlfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth","displayName":"Style area pane width in Draft and Outline views (User)","description":"This policy setting allows you to set the width of the style area that shows the names of applied styles to the side of document text.\r\n\r\nIf you enable this policy setting, you may specify the width of the style area.\r\n\r\nIf you disable or do not configure this policy setting, the default width is used.\r\n","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8","displayName":"Style area pane width in Draft and Outline views (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_0","displayName":"0''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_24","displayName":"0.25''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_48","displayName":"0.5''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_72","displayName":"0.75''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_96","displayName":"1''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_120","displayName":"1.25''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_144","displayName":"1.5''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_168","displayName":"1.75''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_192","displayName":"2''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_216","displayName":"2.25''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_240","displayName":"2.5''","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_textboundaries","displayName":"Show text boundaries (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_textboundaries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_textboundaries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_typeandreplace","displayName":"Type and replace (User)","description":"This policy setting allows you to check or uncheck the \"Type and Replace\" checkbox found under File tab | Options | Advanced. This checkbox may only be shown when certain South East Asian languages, such as Thai or Vietnamese, are enabled.\r\n\r\nSouth Asian languages follow stringent grammatical rules that dictate which textual character elements are allowed next to one another in the composition of words. To compound the complexity of correctly entering South Asian characters, text includes both simple characters and characters that include one or more markings such as diacritics, tone marks, vowels, and accents— for example, in Thai, leading vowels are normally followed by a consonant that does or does not include vowel markings, but diacritics are located below it.\r\n\r\nTo assist you in correctly entering characters in your document that prescribe to the grammar rules for the enabled South Asian language, Word can automatically check the text for you. Word can also make logical substitutions for you by using Type and Replace, a complementary feature.\r\n\r\nSequence checking can be used by itself or in combination with Type and Replace. When sequence checking only is selected, Word will not allow an invalid character to be typed at the insertion point. If Type and Replace is also selected, Word will insert or replace an existing character to make a valid sequence.\r\n\r\nIf you enable or do not configure this policy setting, the \"Type and Replace\" checkbox is checked.\r\n\r\nIf you disable this policy setting, the \"Type and Replace\" checkbox is unchecked.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_typeandreplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_typeandreplace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_typingreplacesselection","displayName":"Typing replaces selected text (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_typingreplacesselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_typingreplacesselection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_updateautomaticlinksatopen","displayName":"Update automatic links at Open (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_updateautomaticlinksatopen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_updateautomaticlinksatopen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usecharacterunits","displayName":"Show measurements in width of characters (User)","description":"Checks/unchecks the corresponding UI option. This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usecharacterunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usecharacterunits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usectrlclicktofollowhyperlink","displayName":"Use CTRL + Click to follow hyperlink (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usectrlclicktofollowhyperlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usectrlclicktofollowhyperlink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesequencechecking","displayName":"Use sequence checking (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesequencechecking_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesequencechecking_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesmartparagraphselection","displayName":"Use smart paragraph selection (User)","description":"This policy setting controls the \"Use smart paragraph selection\" option found under File tab | Options | Advanced | Editing options.\r\n\r\nIf you enable or do not configure this policy setting, Word will automatically select the paragraph mark at the end of a selected range of text.\r\n\r\nIf you disable this policy setting, Word will not automatically select the paragraph mark at the end of a selected range of text. However, a user can still select the paragraph mark manually.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesmartparagraphselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesmartparagraphselection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usetheinskeyforpaste","displayName":"Use the Insert key for paste (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usetheinskeyforpaste_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usetheinskeyforpaste_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalrulerprintviewonly","displayName":"Show vertical ruler in Print Layout view (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalrulerprintviewonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalrulerprintviewonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalscrollbar","displayName":"Show vertical scroll bar (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection","displayName":"Cursor visual selection (User)","description":"Specifies if Block or Continuous selection shall be used. Block selection parodies the selection behavior within the Windows explorer when files in a folder. You draw a rectangle with the curson, and everything inside the rectangle is selected.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_l_visualselection5","displayName":"Cursor visual selection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_l_visualselection5_0","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_l_visualselection5_1","displayName":"Continuous","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_whenselectingautomaticallyselectentireword","displayName":"When selecting, automatically select entire word (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_whenselectingautomaticallyselectentireword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_whenselectingautomaticallyselectentireword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_wraptowindow","displayName":"Show text wrapped within the document window (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_wraptowindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_wraptowindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_relyoncssforfontformatting","displayName":"Rely on CSS for font formatting (User)","description":"This policy setting allows you to configure the \"Use Cascading Style Sheets (CSS) for appearance of messages\" option found under Microsoft Outlook's File tab | Outlook Options | Mail | Message format.\r\n\r\nIf you enable this policy setting, the option is checked.\r\n\r\nIf you disable or do not configure this policy setting, the option is not checked.\r\n","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_relyoncssforfontformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_relyoncssforfontformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_autorecoverfiles","displayName":"AutoRecover files (User)","description":"Defines the default path for storing AutoRecover files.","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_autorecoverfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_autorecoverfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_autorecoverfiles_l_autorecoverfiles13","displayName":"AutoRecover files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_clipartpictures","displayName":"Clipart pictures (User)","description":"This policy setting allows you to define the default path to Clipart pictures that is set in Word Options | Advanced | General | \"File Locations...\"\r\n\r\nIf you enable this policy setting, you may specify the default path to Clipart pictures.\r\n\r\nIf you disable or do not configure this policy setting, no path is specified.","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_clipartpictures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_clipartpictures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_clipartpictures_l_clipartpictures12","displayName":"Clipart pictures (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_defaultfilelocation","displayName":"Default File Location (User)","description":"Defines the default path to documents.","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_defaultfilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_defaultfilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_defaultfilelocation_l_documents","displayName":"Documents (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_startup","displayName":"Startup (User)","description":"Defines the default path to Word's Startup folder.","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_startup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_startup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_startup_l_startup15","displayName":"Startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_tools","displayName":"Tools (User)","description":"Defines the default path to tools.","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_tools_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_tools_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_tools_l_tools14","displayName":"Tools (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustformattingwhenpastingfrommicrosoftexcel","displayName":"Adjust formatting when pasting from Microsoft Excel (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustformattingwhenpastingfrommicrosoftexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustformattingwhenpastingfrommicrosoftexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustparagraphspacingonpaste","displayName":"Adjust paragraph spacing on paste (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustparagraphspacingonpaste_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustparagraphspacingonpaste_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustsentenceandwordspacingautomatically","displayName":"Adjust sentence and word spacing automatically (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustsentenceandwordspacingautomatically_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustsentenceandwordspacingautomatically_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjusttableformattingandalignmentonpaste","displayName":"Adjust table formatting and alignment on paste (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjusttableformattingandalignmentonpaste_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjusttableformattingandalignmentonpaste_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_mergeformattingwhenpastingfrompowerpoint","displayName":"Merge formatting when pasting from PowerPoint (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_mergeformattingwhenpastingfrompowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_mergeformattingwhenpastingfrompowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_mergepastedlistswithsurroundinglists","displayName":"Merge pasted lists with surrounding lists (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_mergepastedlistswithsurroundinglists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_mergepastedlistswithsurroundinglists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_smartstylebehavior","displayName":"Smart style behavior (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_smartstylebehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_smartstylebehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_browser_l_disablefeaturesnotsupportedbyspecifiedbrowsers","displayName":"Disable features not supported by specified browsers (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"56e510be-ca39-46a2-9eb2-6f1af6d4b16a","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_browser_l_disablefeaturesnotsupportedbyspecifiedbrowsers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_browser_l_disablefeaturesnotsupportedbyspecifiedbrowsers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_files_l_checkifwordisthedefaulteditorforallotherwebpages","displayName":"Check if Word is the default editor for all other Web pages (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"d804205d-6c12-4f40-86a0-aa5a5355370f","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_files_l_checkifwordisthedefaulteditorforallotherwebpages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_files_l_checkifwordisthedefaulteditorforallotherwebpages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_documentproperties","displayName":"Print document properties (User)","description":"This policy setting allows you to control the \"Print document properties\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will print an additional page with the printed document's properties, including the document's author, filename, creation date, etc., for every document that is printed.\r\n\r\nIf you disable or do not configure this policy setting, no additional page will be printed.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_documentproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_documentproperties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_drawingobjects","displayName":"Print drawings created in Word (User)","description":"This policy setting allows you to configure the \"Print drawings created in Word\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will print graphics and floating text boxes. \r\n\r\nIf you disable or do not configure this policy setting, Word will not print graphics or floating text boxes. Instead, Word will print a blank box in the place of each graphic and floating text box.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_drawingobjects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_drawingobjects_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_hiddentext","displayName":"Hidden text (User)","description":"This policy setting controls whether text that is formatted as hidden displays on Word users' monitor screens.\r\n\r\nIf you enable this policy setting, Word displays hidden text at all times. Hidden text on monitor screens displays as underlined with a dotted line.\r\n\r\nIf you disable or do not configure this policy setting, Word does not display text formatted as hidden unless \"Show/Hide ¶\" is selected or Word is configured to show hidden text in the \"Display\" section of the \"Word Options\" dialog.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_hiddentext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_hiddentext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_highlight","displayName":"Show highlighter marks (User)","description":"This policy setting controls highlighter marks.\r\n\r\nIf you enable this policy setting, highlighter marks, both on screen and when printing, will be shown.\r\n\r\nIf you disable or do not configure this policy setting, highlighter marks, both on screen and when printing, will be hidden.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_highlight_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_highlight_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_objectanchors","displayName":"Object anchors (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_objectanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_objectanchors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalbreaks","displayName":"Optional breaks (User)","description":"Determines whether the symbol used to represent optional breaks is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalbreaks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalbreaks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalhyphens","displayName":"Optional hyphens (User)","description":"Determines whether the symbol used to represent optional hyphens is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalhyphens_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalhyphens_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_paragraphmarks","displayName":"Paragraph marks (User)","description":"Determines whether the symbol used to represent the end of paragraphs is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_paragraphmarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_paragraphmarks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_screentips","displayName":"Show document tooltips on hover (User)","description":"Determines whether the symbol used to represent Screen Tips are shown in the document.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_screentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_screentips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_spaces","displayName":"Spaces (User)","description":"Determines whether the symbol used to represent spaces is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_spaces_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_spaces_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_tabcharacters","displayName":"Tab characters (User)","description":"Determines whether the symbol used to represent tabs is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_tabcharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_tabcharacters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatefields","displayName":"Update fields before printing (User)","description":"This policy setting allows you to configure the \"Update fields before printing\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will update fields in the document before the document is printed.\r\n\r\nIf you disable or do not configure this policy setting, Word will not update fields in the document before the document is printed.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatefields_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatefields_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatelinks","displayName":"Update linked data before printing (User)","description":"This policy setting controls the \"Update linked data before printing\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will update linked data in the document before the document is printed. One example of linked data in Word is an embedded Excel chart that is linked to an Excel spreadsheet.\r\n\r\nIf you disable or do not configure this policy setting, Word will not update linked data in the document before the document is printed.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatelinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatelinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_whitespacebetweenpagesprintviewonly","displayName":"Show white space between pages in Print Layout view (User)","description":"Determines whether the symbol used to represent white space between pages in Print view only is shown in the document.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_whitespacebetweenpagesprintviewonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_whitespacebetweenpagesprintviewonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"f9e53433-d8d9-4eaf-bdf3-d32de60d686e","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_alertifnotdefault","displayName":"Prompt the user if Word is not the default application for its file extensions (User)","description":"\r\n This policy setting specifies whether to prompt users to change their file extensions association if any of the file type extensions that were associated with Word, are no longer associated with Word.\r\n\r\n If you enable this policy setting, users will never be prompted on program start whenever any of these file types are associated with other applications. If the policy is Enabled, the checkbox under “File->Options-> General -> Start up options-> Tell me …” is Disabled and Unchecked.\r\n\r\n If you disable or do not configure this policy setting users will be prompted on program start whenever any of these file types are associated with other applications. Users can change the behavior of the feature either by checking the checkbox presented in the prompt or by checking the checkbox under “File->Options-> General -> Start up options-> Tell me …”\r\n If the policy is Not Configured or disabled the checkbox is Enabled and Checked by default.","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_alertifnotdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_alertifnotdefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_allowselectionfloaties","displayName":"Show Mini Toolbar on selection (User)","description":"Disabling this policy setting will result in Mini Toolbar not being displayed on text selection. By default, Mini Toolbar on selection is enabled and its visibility can be changed via a setting in the Word Options dialog box.","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_allowselectionfloaties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_allowselectionfloaties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_digitalprint","displayName":"Don't show the option to transform a document to a Sway web page (User)","description":"This policy setting controls whether the File menu option to transform a Word document to a Sway web page is shown to the user. By default, this option is shown to the user.\r\n\r\nIf you enable this policy setting, the File menu option to transform a Word document to a Sway web page is hidden from the user. \r\n\r\nIf you disable or don't configure this policy setting, the File menu option to transform a Word document to a Sway web page is shown to the user.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_digitalprint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_digitalprint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_enablelivepreview","displayName":"Enable Live Preview (User)","description":"This policy setting configures the \"Enable Live Preview\" checkbox found under File tab | Options | General. Live Preview shows how a command would be applied without actually applying it to the document.\r\n\r\nIf you enable this policy setting, the option is checked, and Live Preview will be shown when using Galleries that support previews\r\n\r\nIf you disable or do not configure this policy setting, the option is unchecked, and Live Preview will be hidden when using Galleries that support previews.","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_enablelivepreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_enablelivepreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_linkedinresumeassistant","displayName":"Allow LinkedIn Resume Assistant feature (User)","description":"This policy setting controls whether the LinkedIn Resume Assistant appears in Word.\r\n\r\nIf you enable or do not configure this policy, users will be able to use the LinkedIn Resume Assistant.\r\n\r\nIf you disable this policy setting, the LinkedIn Resume Assistant will not be available.\r\n\r\nImportant: This policy setting only applies to Office 365 clients that are installed by using Click-to-Run, including Office 365 ProPlus, Office 365 Business, Visio Pro for Office 365 and Project Pro for Office 365. It doesn't apply to Office products that use Windows Installer (MSI).\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_linkedinresumeassistant_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_linkedinresumeassistant_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_onlinevideos","displayName":"Allow Online Videos to play within Word (User)","description":"This policy setting controls whether online videos can be played within Word.\r\n\r\nIf you enable or do not configure this policy, users will be able to play online videos within Word.\r\n\r\nIf you disable this policy setting, you will not be able to play online videos within Word.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_onlinevideos_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_onlinevideos_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading","displayName":"Open e-mail attachments in Reading View (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_l_checktoallowstartinginreadinglayout","displayName":"Check to allow starting in Reading Layout (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_l_checktoallowstartinginreadinglayout_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_l_checktoallowstartinginreadinglayout_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype","displayName":"Mark grammar errors as you type (User)","description":"Defines color to use for marking grammatical errors.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_checktoenforcesettingonunchecktoenforcesettingoff0","displayName":"Check to enforce setting on; uncheck to enforce setting off (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_checktoenforcesettingonunchecktoenforcesettingoff0_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_checktoenforcesettingonunchecktoenforcesettingoff0_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors","displayName":"Color for marking grammatical errors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_0","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_255","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_128","displayName":"Dark Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_3368703","displayName":"Light Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_52479","displayName":"Sky Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_10079487","displayName":"Pale Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_6710937","displayName":"Blue Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_65280","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_32768","displayName":"Dark Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_13056","displayName":"Darker Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_13434828","displayName":"Light Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_3355392","displayName":"Olive Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_3381606","displayName":"Sea Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16711680","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_8388608","displayName":"Dark Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16776960","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_8421376","displayName":"Dark Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16777113","displayName":"Light Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16777215","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_10040064","displayName":"Brown","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16737792","displayName":"Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16750848","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_65535","displayName":"Cyan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_32896","displayName":"Dark Cyan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_13434879","displayName":"Light Cyan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16711935","displayName":"Magenta","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_8388736","displayName":"Dark Magenta","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_13158","displayName":"Dark Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_3355545","displayName":"Indigo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_10079232","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_3394764","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16763904","displayName":"Gold","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_10040166","displayName":"Plum","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16751052","displayName":"Rose","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16764057","displayName":"Tan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_13408767","displayName":"Lavender","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_8421504","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_12632256","displayName":"Gray 25%","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarwithspelling","displayName":"Check grammar with spelling (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarwithspelling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarwithspelling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingbackgroundspellingchecker","displayName":"Delay before starting background spelling checker (User)","description":"This policy setting allows you to configure when the background spell check is started.\r\n\r\nIf you enable this policy setting, you may specify the delay, in milliseconds, before the background spell check is started. This setting only applies when Word is running in a terminal server session.\r\n\r\nIf you disable or do not configure this policy setting, Word will behave normally when in a terminal server session.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingbackgroundspellingchecker_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingbackgroundspellingchecker_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingbackgroundspellingchecker_l_delaybeforestartingbackgroundspellingchecker3","displayName":"Milliseconds (e.g. 5000 milliseconds = 5 seconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingotherproofingtools","displayName":"Delay before starting other proofing tools (User)","description":"This policy setting allows you to configure when the background grammar check is started.\r\n\r\nIf you enable this policy setting, you may specify the delay, in milliseconds, before the background grammar check is started. This setting only applies when Word is running in a terminal server session.\r\n\r\nIf you disable or do not configure this policy setting, Word will behave normally when in a terminal server session.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingotherproofingtools_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingotherproofingtools_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingotherproofingtools_l_delaybeforestartingbackgroundgrammarchecker3","displayName":"Milliseconds (e.g. 5000 milliseconds = 5 seconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_donotenableadditionalactionsintherightclickmenu","displayName":"Do not enable additional actions in the right-click menu (User)","description":"This policy setting allows you to configure the \"Enable additional actions in the right-click menu\" button found under File tab | Options | Proofing | Autocorrect Options... | Actions.\r\n\r\nIf you enable this policy setting, the checkbox will not be checked, and Additional Actions recognition will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, the checkbox will be checked, and Additional Actions recognition will be turned on.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_donotenableadditionalactionsintherightclickmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_donotenableadditionalactionsintherightclickmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_showreadabilitystatistics","displayName":"Show readability statistics (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_showreadabilitystatistics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_showreadabilitystatistics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_writingstyle","displayName":"Writing style (User)","description":"Specifies the writing style Word uses when checking the active document.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_writingstyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_writingstyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_writingstyle_l_writingstyle1","displayName":"Writing style (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_writingstyle_l_writingstyle1_0","displayName":"Grammar & Style","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_writingstyle_l_writingstyle1_1","displayName":"Grammar Only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_capitalizefirstletterofsentence","displayName":"Capitalize first letter of sentence (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_capitalizefirstletterofsentence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_capitalizefirstletterofsentence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_capitalizenamesofdays","displayName":"Capitalize names of days (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_capitalizenamesofdays_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_capitalizenamesofdays_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctaccidentalusageofcapslockkey","displayName":"Correct accidental usage of cAPS LOCK key (User)","description":"This policy setting allows you to set the \"Correct accidental usage of cAPS LOCK key\" option in Word Options | Proofing | \"AutoCorrect Options...\" | AutoCorrect.\r\n\r\nIf you enable this policy setting, \"Correct accidental usage of cAPS LOCK key\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Correct accidental usage of cAPS LOCK key\" will not be set.y","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctaccidentalusageofcapslockkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctaccidentalusageofcapslockkey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctkeyboardsetting","displayName":"Correct keyboard setting (User)","description":"This policy setting allows you to set the \"Correct keyboard setting\" option in Word Options | Proofing | \"AutoCorrect Options...\" | AutoCorrect.\r\n\r\nIf you enable this policy setting, \"Correct keyboard setting\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Correct keyboard setting\" will not be set.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctkeyboardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctkeyboardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correcttwoinitialcapitals","displayName":"Correct TWo INitial CApitals (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correcttwoinitialcapitals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correcttwoinitialcapitals_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_replacetextasyoutype","displayName":"Replace text as you type (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_replacetextasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_replacetextasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticbulletedlists","displayName":"Automatic bulleted lists (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticbulletedlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticbulletedlists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticnumberedlists","displayName":"Automatic numbered lists (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticnumberedlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticnumberedlists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_borderlines","displayName":"Border lines (User)","description":"Checks/unchecks the option \"Border Lines.\"","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_borderlines_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_borderlines_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_closingstyletoletterclosings","displayName":"Closing style to letter closings (User)","description":"This policy setting allows you to set the \"Closing style to letter closings\" option found in Word Options | Proofing | AutoCorrect Options... | AutoFormat As You Type.\r\n\r\nIf you enable this policy setting, \"Closing style to letter closings\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Closing style to letter closings\" will not be set.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_closingstyletoletterclosings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_closingstyletoletterclosings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_datestyle","displayName":"Date style (User)","description":"Checks/unchecks the option \"Date style.\" This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_datestyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_datestyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_headings","displayName":"Headings (User)","description":"Checks/unchecks the option ''Built in Heading styles''.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_headings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_headings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_tables","displayName":"Tables (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_tables_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_tables_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_autospace","displayName":"Auto space (User)","description":"This policy setting allows you to set the option \"Delete needless spaces between Asian and Western text\" in the group \"Automatically as you type.\" This option may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, \"Delete needless spaces between Asian and Western text\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Delete needless spaces between Asian and Western text\" will not be set.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_autospace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_autospace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_definestylesbasedonyourformatting","displayName":"Define styles based on your formatting (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_definestylesbasedonyourformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_definestylesbasedonyourformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_formatbeginningoflistitemliketheonebeforeit","displayName":"Format beginning of list item like the one before it (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_formatbeginningoflistitemliketheonebeforeit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_formatbeginningoflistitemliketheonebeforeit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_insertclosingphrasetomatchjapanesesalutation","displayName":"Insert closing phrase to match Japanese salutation (User)","description":"Checks/unchecks the option \"Insert closing phrase to match Japanese salutation.\" This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_insertclosingphrasetomatchjapanesesalutation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_insertclosingphrasetomatchjapanesesalutation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_insertclosingphrasetomatchmemostyle","displayName":"Insert closing phrase to match memo style (User)","description":"Checks/unchecks the option \"Insert closing phrase to match memo style.\" This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_insertclosingphrasetomatchmemostyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_insertclosingphrasetomatchmemostyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_matchparentheses","displayName":"Match parentheses (User)","description":"This policy setting allows you to set the option \"Match opening and closing parentheses\" in Word Options | Proofing | AutoCorrect Options... | AutoFormat As You Type | Automatically as you type. This option may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, \"Match opening and closing parentheses\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Match opening and closing parentheses\" will not be set.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_matchparentheses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_matchparentheses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_setleftindentontabsandbackspace","displayName":"Set left indent on tabs and backspace (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_setleftindentontabsandbackspace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_setleftindentontabsandbackspace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_boldand_italic_withrealformatting","displayName":"*Bold* and _italic_ with real formatting (User)","description":"This policy setting allows you to set the \"*Bold* and _italic_ with real formatting\" option.\r\n\r\nIf you enable this policy setting, you will set the the \"*Bold* and _italic_ with real formatting\" option in File | Options | Proofing | AutoCorrect Options... | AutoFormat.\r\n\r\nIf you disable or do not configure this policy setting, the option is not set.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_boldand_italic_withrealformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_boldand_italic_withrealformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_dashlikecharacters","displayName":"Dash-like characters (User)","description":"Checks/unchecks the option \"Long vowel sounds with dash.\" This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_dashlikecharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_dashlikecharacters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_firstlineindent","displayName":"First line indent (User)","description":"Checks/unchecks the option \"Spaces at beginning of paragraph with first-line indent\" in the group \"Replace as you type.\" This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_firstlineindent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_firstlineindent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_fractions12withfractioncharacter","displayName":"Fractions (1/2) with fraction character (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_fractions12withfractioncharacter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_fractions12withfractioncharacter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_ordinals1stwithsuperscript","displayName":"Ordinals (1st) with superscript (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_ordinals1stwithsuperscript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_ordinals1stwithsuperscript_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_straightquoteswithsmartquotes","displayName":"Straight quotes with smart quotes (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_straightquoteswithsmartquotes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_straightquoteswithsmartquotes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_symbolcharacterswithsymbols","displayName":"Symbol characters (--) with symbols (User)","description":"Checks/unchecks the option ''Hyphens (--) with dash (-)''.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_symbolcharacterswithsymbols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_symbolcharacterswithsymbols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_compatmodeonsaveas","displayName":"Save As Open XML in Compatibility Mode (User)","description":"This policy setting allows you to hide the \"Maintain compatibility with previous versions of Word\" checkbox. For any file format that is in Compatibility Mode, there will be a \"Maintain compatibility with previous versions of Word\" checkbox in the Save As dialog when saving to any of the Open XML file formats. This checkbox allows users to preserve the fidelity of documents that open in compatibility mode when saving those documents to any of the Open XML file formats. Checking this box will prevent conversion to the version of Word that is saving the file.\r\n\r\nConversion maximizes fidelity with the version of Word that is saving the file, and it is recommended for users who want their Word documents to be compatible with this version of Word. However, conversion may impact the fidelity and compatibility of some features when the file is opened by a previous version of Word.\r\n\r\nIf you enable this policy setting, the \"Maintain compatibility with previous versions of Word\" checkbox will be hidden. The Save As behavior for any of the Open XML file formats will always maintain compatibility with previous versions of Word. The file that is in compatibility mode will be prevented from being converted to the version of Word saving this file. \r\n\r\nIf you disable or do not configure this policy setting, the \"Maintain compatibility with previous versions of Word\" checkbox in the Save As dialog will be shown. Unless checked by the user, an Open XML file will be converted when the document is saved. Users will still, by default, be shown a final dialog when saving to confirm that the user wants to save the file without \"Maintain compatibility with previous versions of Word\" checked.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_compatmodeonsaveas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_compatmodeonsaveas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_donotdisplayfileformatcompatiblitydialogforodt","displayName":"Do not display file format compatibility dialog box for OpenDocument text format (User)","description":"This policy setting allows you to configure the file format compatibility dialog box when saving a file as an OpenDocument text file in Word.\r\n \r\nIf you enable this policy setting, the file format compatibility dialog is not displayed whenever you save as an OpenDocument text file in Word.\r\n \r\nIf you disable or do not configure this policy setting, the file format compatibility dialog is displayed when you save as an OpenDocument text file in Word.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_donotdisplayfileformatcompatiblitydialogforodt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_donotdisplayfileformatcompatiblitydialogforodt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_keeplastautosavedversions","displayName":"Keep the last AutoSaved versions of files for the next session (User)","description":"This policy setting determines whether Word keeps the last AutoSaved version of a file if a user closes a file without saving it. (Note: AutoSave applies only when AutoRecover is enabled.)\r\n\r\nIf you enable or do not configure this policy setting, Word keeps the last AutoSaved version of the file and makes it available to the user the next time the file is opened if the user closes a file without saving it.\r\n\r\nIf you disable this policy setting, Word does not keep the last AutoSaved version of the file if the user closes a file without saving it.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_keeplastautosavedversions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_keeplastautosavedversions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo","displayName":"Save AutoRecover info (User)","description":"If you enable this policy setting, you can specify the number of minutes that Word will wait between saving AutoRecover information for the file. To prevent Word from ever saving AutoRecover information for the file, enable this policy and set the value to '0'.\r\n\r\nIf you disable or do not configure this policy setting, this policy will have no effect on the number of minutes that Word will wait between saving AutoRecover information for the file. By default, Word saves AutoRecover information for the file every 10 minutes.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo_l_saveautorecoverinfoeveryminutes","displayName":"Save AutoRecover info every (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas","displayName":"Default file format (User)","description":"This policy setting determines the default file format for saving files in Word.\r\n\r\nIf you enable this policy setting, you can set the default file format from among the following options: \r\n\r\n- Word Document (*.docx): This option is the default configuration in Word.\r\n- Single Files Web Page (*.mht)\r\n- Web Page (*.htm; *.html)\r\n- Web Page, Filtered (*.htm, *.html)\r\n- Rich Text Format (*.rtf)\r\n- Plain Text (*.txt)\r\n- Word 6.0/95 (*.doc)\r\n- Word 6.0/95 - Chinese (Simplified) (*.doc)\r\n- Word 6.0/95 - Chinese (Traditional) (*.doc)\r\n- Word 6.0/95 - Japanese (*.doc)\r\n- Word 6.0/95 - Korean (*.doc)\r\n- Word 97-2002 and 6.0/95 - RTF\r\n- Word 5.1 for Macintosh (*.mcw)\r\n- Word 5.0 for Macintosh (*.mcw)\r\n- Word 2.x for Windows (*.doc)\r\n- Works 4.0 for Windows (*.wps)\r\n- WordPerfect 5.x for Windows (*.doc)\r\n- WordPerfect 5.1 for DOS (*.doc)\r\n- Word Macro-Enabled Document (*.docm)\r\n- Word Template (*.dotx)\r\n- Word Macro-Enabled Template (*.dotm)\r\n- Word 97 - 2003 Document (*.doc)\r\n- Word 97 - 2003 Template (*.dot)\r\n- Word XML Document (*.xml)\r\n- Strict Open XML Document (*.docx)\r\n- OpenDocument Text (*.odt)\r\n\r\nUsers can choose to save presentations or documents in a different file format than the default.\r\n\r\nIf you disable or do not configure this policy setting, Word saves new files in the Office Open XML format: Word files have a .docx extension. For users who run recent versions of Word, Microsoft offers the Microsoft Office Compatibility Pack, which enables them to open and save Office Open XML files. If some users in your organization cannot install the Compatibility Pack, or are running versions of Word older than Microsoft Office 2000 with Service Pack 3, they might not be able to access Office Open XML files.\r\n\r\nThis policy setting is often set in combination with the \"Save As Open XML in Compatibility Mode\" policy setting.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3","displayName":"Save Word files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_","displayName":"Word Document (*.docx)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_webarchive","displayName":"Single Files Web Page (*.mht)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_html","displayName":"Web Page (*.htm; *.html)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_reducedhtml","displayName":"Web Page, Filtered (*.htm, *.html)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_rtf","displayName":"Rich Text Format (*.rtf)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_text","displayName":"Plain Text (*.txt)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msword6exp","displayName":"Word 6.0/95 (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msword6scexp","displayName":"Word 6.0/95 - Chinese (Simplified) (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msword6tcexp","displayName":"Word 6.0/95 - Chinese (Traditional) (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msword6jexp","displayName":"Word 6.0/95 - Japanese (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msword95kexp","displayName":"Word 6.0/95 - Korean (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msword6rtfexp","displayName":"Word 97-2002 & 6.0/95 - RTF","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_mswordmac51","displayName":"Word 5.1 for Macintosh (*.mcw)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_mswordmac5","displayName":"Word 5.0 for Macintosh (*.mcw)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_mswordwin2","displayName":"Word 2.x for Windows (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msworkswin4","displayName":"Works 4.0 for Windows (*.wps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_wrdprfctwin","displayName":"WordPerfect 5.x for Windows (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_wrdprfctdos51","displayName":"WordPerfect 5.1 for DOS (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_macroenableddocument","displayName":"Word Macro-Enabled Document (*.docm)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_template","displayName":"Word Template (*.dotx)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_macroenabledtemplate","displayName":"Word Macro-Enabled Template (*.dotm)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_doc","displayName":"Word 97 - 2003 Document (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_dot","displayName":"Word 97 - 2003 Template (*.dot)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_flatxml","displayName":"Word XML Document (*.xml)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_docxstrict","displayName":"Strict Open XML Document (*.docx)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_odt","displayName":"OpenDocument Text (*.odt)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation","displayName":"Set default compatibility mode on file creation (User)","description":"This policy setting allows you to specify the default compatibility mode when creating new files in Word. There are four modes:\r\n\r\n1. Word 2003: This mode disables features in Word that are not compatible with Word 2003.\r\n2. Word 2007: This mode disables features in Word that are not compatible with Word 2007.\r\n3. Word 2010: This mode disables features in Word that are not compatible with Word 2010.\r\n4. Full functionality mode: This mode ensures that all new features remain enabled. This is the default setting for Word. \r\n\r\nNote: Not all file formats support all four Compatibility Modes. Open XML file formats such as .docx and .dotx, support all four modes.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_l_setdefaultcompatibilitymodeonfilecreationdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_l_setdefaultcompatibilitymodeonfilecreationdropid_11","displayName":"Word 2003","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_l_setdefaultcompatibilitymodeonfilecreationdropid_12","displayName":"Word 2007","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_l_setdefaultcompatibilitymodeonfilecreationdropid_14","displayName":"Word 2010","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_l_setdefaultcompatibilitymodeonfilecreationdropid_15","displayName":"Full functionality mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_disableirmonxpsexport","displayName":"Turn off IRM protection on XPS Export for Word (User)","description":"This policy controls the default IRM protection setting when exporting Word documents to XPS files.\r\n\r\nEnabling this policy setting will turn off IRM protection when exporting to XPS, if not explicitly set by users through the Export Options dialog.\r\n\r\nIf you disable or don't configure this policy setting, the default IRM protection setting for XPS export is based on previous IRM export selection. \r\n ","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_disableirmonxpsexport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_disableirmonxpsexport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_disablewarningonincludefieldsupdate","displayName":"Don’t ask permission before updating IncludePicture and IncludeText fields in Word (User)","description":"This policy setting allows you to control whether Word prompts the user with a security message before updating IncludePicture and IncludeText fields in the document.\r\n\r\nBy default, the user is prompted with a security message before those fields are updated. But, the prompt might effect automated workflows that merge Word documents.\r\n\r\nImportant: Fields that contain IncludePicture and IncludeText references can be used for data exfiltration or phishing exploits. A field containing these references can be modified to point to external websites for content. If credentials are required for accessing the picture or text, the process of updating the field will request a sign-in from the user. While this is a legitimate scenario for trusted sources, it is vulnerable to phishing if the document is not from a trusted source.\r\n\r\nIf you enable this policy setting, the user won’t be prompted with a security message before those fields are updated. Enabling this policy setting is not recommended because of the possible security implications.\r\n\r\nIf you disable or don’t configure this policy setting, the user will be prompted with a security message before those fields are updated.\r\n ","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_disablewarningonincludefieldsupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_disablewarningonincludefieldsupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_makehiddenmarkupvisible","displayName":"Make hidden markup visible (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_makehiddenmarkupvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_makehiddenmarkupvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_storerandomnumbertoimprovemergeaccuracy","displayName":"Store random number to improve merge accuracy (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_storerandomnumbertoimprovemergeaccuracy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_storerandomnumbertoimprovemergeaccuracy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_turnofffilevalidation","displayName":"Turn off file validation (User)","description":"This policy setting allows you turn off the file validation feature.\r\n\r\nIf you enable this policy setting, file validation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, file validation will be turned on. Office Binary Documents (97-2003) are checked to see if they conform against the file format schema before they are opened.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_turnofffilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_turnofffilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_warnbeforeprintingsavingorsendingafilethatcontainstrackedcha","displayName":"Warn before printing, saving or sending a file that contains tracked changes or comments (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_warnbeforeprintingsavingorsendingafilethatcontainstrackedcha_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_warnbeforeprintingsavingorsendingafilethatcontainstrackedcha_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setparametersforcngcontext","displayName":"Set parameters for CNG context (User)","description":"This policy setting allows you to specify the encryption parameters that should be used for the CNG context. \r\n\r\nIf you enable this policy setting, the parameters specified will be passed to the CNG context.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG values will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setparametersforcngcontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setparametersforcngcontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm","displayName":"Specify CNG random number generator algorithm (User)","description":"This policy setting allows you to configure the CNG random number generator to use.\r\n\r\nIf you enable this policy setting, the random number generator specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default random number generator will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_l_specifycngrandomnumbergeneratoralgorithmid","displayName":"Random number generator: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngsaltlength","displayName":"Specify CNG salt length (User)","description":"This policy setting allows you to specify the number of bytes of salt that should be used.\r\n\r\nIf you enable this policy setting, the bytes specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default length of 16 will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngsaltlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngsaltlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility","displayName":"Specify encryption compatibility (User)","description":"This policy setting allows you to specify the encrypted database compatibility.\r\n\r\nIf you enable this policy setting, the compatibility format specified will be applied during encryption for new files\r\n- Use legacy format\r\n- Use next generation format\r\n- All files save with next generation format\r\n\r\nIf you disable or do not configure this policy setting, the default setting, \"Use next generation format,\" will be applied.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_0","displayName":"Use legacy format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_1","displayName":"Use next generation format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_2","displayName":"All files save with next generation format","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_usenewkeyonpasswordchange","displayName":"Use new key on password change (User)","description":"This policy setting allows you to specify if a new encryption key is used when the password is changed.\r\n\r\nIf you enable or do not configure this policy setting, a new intermediate key is generated when the password is changed. This causes any extra key encryptors to be removed when the file is saved.\r\n\r\nIf you disable this policy setting, a new intermediate key is not generated when the password is changed.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_usenewkeyonpasswordchange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_usenewkeyonpasswordchange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde","displayName":"Dynamic Data Exchange (User)","description":"This policy setting controls the ability to use Dynamic Data Exchange (DDE) in Word. By default, DDE isn’t allowed in Word. Allowing DDE isn’t recommended because of security concerns.\r\n \r\nIf you enable this policy setting, you can select either of the following options:\r\n \r\n-Limit Dynamic Data Exchange\r\n-Allow Dynamic Data Exchange\r\n \r\nIf you choose “Limit Dynamic Data Exchange,” DDE requests made to an already running program are allowed.  But, DDE requests that require another executable program to be launched aren’t allowed.\r\n \r\nIf you disable or don’t configure this policy setting, DDE isn’t allowed.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_l_allowddedropid","displayName":"Dynamic Data Exchange setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_l_allowddedropid_1","displayName":"Limited Dynamic Data Exchange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_l_allowddedropid_2","displayName":"Allow Dynamic Data Exchange","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowwordmailloadembeddedfonts","displayName":"Allow embedded TrueType fonts to be sent in messages (User)","description":"\r\n This policy setting controls whether embedded TrueType fonts can be sent in messages.\r\n\r\n By default, embedded TrueType fonts aren't allowed in messages. Allowing embedded TrueType fonts Isn't recommended because of security concerns.\r\n\r\n If you enable this policy setting, embedded TrueType fonts can be sent in messages.\r\n\r\n If you disable or don’t configure this policy setting, embedded TrueType fonts can't be sent in messages.\r\n ","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowwordmailloadembeddedfonts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowwordmailloadembeddedfonts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword","displayName":"Scan encrypted macros in Word Open XML documents (User)","description":"This policy setting controls whether encrypted macros in Open XML documents be are required to be scanned with anti-virus software before being opened.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n- Scan encrypted macros: encrypted macros are disabled unless anti-virus software is installed. Encrypted macros are scanned by your anti-virus software when you attempt to open an encrypted workbook that contains macros.\r\n- Scan if anti-virus software available: if anti-virus software is installed, scan the encrypted macros first before allowing them to load. If anti-virus software is not available, allow encrypted macros to load.\r\n- Load macros without scanning: do not check for anti-virus software and allow macros to be loaded in an encrypted file.\r\n\r\nIf you disable or do not configure this policy setting, the behavior will be similar to the \"Scan encrypted macros\" option.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword_l_determinewhethertoforceencryptedworddropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword_l_determinewhethertoforceencryptedworddropid_0","displayName":"Scan encrypted macros (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword_l_determinewhethertoforceencryptedworddropid_1","displayName":"Scan if anti-virus software available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword_l_determinewhethertoforceencryptedworddropid_2","displayName":"Load macros without scanning","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users, except if application add-ins are required to be signed by Trusted Publishers.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User) (Deprecated)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve","displayName":"Set maximum number of trust records to preserve (User)","description":"This policy setting allows you to specify the maximum number of trust records to preserve when the purge task detects that this application has trusted more than the number of trusted documents set by the \"Set maximum number of trusted documents\" policy setting.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of trust records to preserve, with an upper limit of 20000. Due to performance reasons, it is not recommended to set it to the upper limit.\r\n\r\nIf you disable or you do not configure this policy setting, the default value for of 400 is used.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_l_setmaximumnumberoftrustrecordstopreservespinid","displayName":"Maximum to preserve: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject","displayName":"Trust access to Visual Basic Project (User)","description":"This policy setting controls whether automation clients such as Microsoft Visual Studio 2005 Tools for Microsoft Office (VSTO) can access the Visual Basic for Applications project system in the specified applications. VSTO projects require access to the Visual Basic for Applications project system in Excel, PowerPoint, and Word, even though the projects do not use Visual Basic for Applications. Design-time support of controls in both Visual Basic and C# projects depends on the Visual Basic for Applications project system in Word and Excel.\r\n\r\nIf you enable this policy setting, VSTO and other automation clients can access the Visual Basic for Applications project system in the specified applications. Users will not be able to change this behavior through the \"Trust access to the VBA project object model\" user interface option under the Macro Settings section of the Trust Center.\r\n\r\nIf you disable this policy setting, VSTO does not have programmatic access to VBA projects. In addition, the \"Trust access to the VBA project object model\" check box is cleared and users cannot change it. Note: Disabling this policy setting prevents VSTO projects from interacting properly with the VBA project system in the selected application.\r\n\r\nIf you do not configure this policy setting, automation clients do not have programmatic access to VBA projects. Users can enable this by selecting the \"Trust access to the VBA project object model\" in the \"Macro Settings\" section of the Trust Center. However, doing so allows macros in any documents the user opens to access the core Visual Basic objects, methods, and properties, which represents a potential security hazard.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocuments","displayName":"Turn off trusted documents (User)","description":"This policy setting allows you to turn off the trusted documents feature. The trusted documents feature allows users to always enable active content in documents such as macros, ActiveX controls, data connections, etc. so that they are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.\r\n\r\nIf you enable this policy setting, you will turn off the trusted documents feature. Users will receive a security prompt every time a document containing active content is opened.\r\n\r\nIf you disable or do not configure this policy setting, documents will be trusted when users enable content for a document, and users will not receive a security prompt.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork","displayName":"Turn off Trusted Documents on the network (User)","description":"This policy setting allows you to turn off the trusted documents feature for documents opened from the network.\r\n\r\nIf you enable this policy setting, users will always see security notifications for active content such as macros, ActiveX controls, data connections, etc. for documents opened from the network.\r\n\r\nIf you disable or do not configure this policy setting, the trusted documents feature allows users to always allow active content in documents such as macros, ActiveX controls, data connections, etc. so that users are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty19","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty19_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty19_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty19_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty19_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword","displayName":"Legacy converters for Word (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword","displayName":"Office Open XML converters for Word (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles","displayName":"OpenDocument Text files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles","displayName":"Plain text files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles","displayName":"RTF files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior","displayName":"Set default file block behavior (User)","description":"This policy setting allows you to determine if users can open, view, or edit Word files.\r\n\r\nIf you enable this policy setting, you can set one of these options:\r\n- Blocked files are not opened\r\n- Blocked files open in Protected View and can not be edited\r\n- Blocked files open in Protected View and can be edited\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the same as the \"Blocked files are not opened\" setting. Users will not be able to open blocked files.","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_0","displayName":"Blocked files are not opened","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_1","displayName":"Blocked files open in Protected View and can not be edited","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_2","displayName":"Blocked files open in Protected View and can be edited","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages","displayName":"Web pages (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates","displayName":"Word 2000 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_l_word2000binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_l_word2000binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_l_word2000binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_l_word2000binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_l_word2000binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_l_word2000binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments","displayName":"Word 2003 and plain XML documents (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates","displayName":"Word 2003 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates","displayName":"Word 2007 and later binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates","displayName":"Word 2007 and later documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates","displayName":"Word 2 and earlier binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates","displayName":"Word 6.0 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates","displayName":"Word 95 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_l_word95binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_l_word95binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_l_word95binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_l_word95binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_l_word95binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_l_word95binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates","displayName":"Word 97 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_l_word97binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_l_word97binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_l_word97binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_l_word97binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_l_word97binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_l_word97binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates","displayName":"Word XP binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_l_wordxpbinarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_l_wordxpbinarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_l_wordxpbinarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_l_wordxpbinarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_l_wordxpbinarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_l_wordxpbinarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview","displayName":"Do not open files from the Internet zone in Protected View (User)","description":"This policy setting allows you to determine if files downloaded from the Internet zone open in Protected View.\r\n\r\nIf you enable this policy setting, files downloaded from the Internet zone do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files downloaded from the Internet zone open in Protected View.","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview","displayName":"Do not open files in unsafe locations in Protected View (User)","description":"This policy setting lets you determine if files located in unsafe locations will open in Protected View. If you have not specified unsafe locations, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders are considered unsafe locations.\r\n\r\nIf you enable this policy setting, files located in unsafe locations do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files located in unsafe locations open in Protected View.","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview","displayName":"Open files on local Intranet UNC in Protected View (User)","description":"This policy setting lets you determine if files on local Intranet UNC file shares open in Protected View.\r\n\r\nIf you enable this policy setting, files on local Intranet UNC file shares open in Protected View if their UNC paths appear to be within the Internet zone.\r\n\r\nIf you disable or do not configure this policy setting, files on Intranet UNC file shares do not open in Protected View if their UNC paths appear to be within the Internet zone.","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails","displayName":"Set document behavior if file validation fails (User)","description":"This policy setting controls how Office handles documents when they fail file validation. \r\n\r\nIf you enable this policy setting, you can configure the following options for files that fail file validation:\r\n\r\n- Block files completely. Users cannot open the files.\r\n- Open files in Protected View and disallow edit. Users cannot edit the files. This is also how Office handles the files if you disable this policy setting.\r\n- Open files in Protected View and allow edit. Users can edit the files. This is also how Office handles the files if you do not configure this policy setting.\r\n\r\nIf you disable this policy setting, Office follows the \"Open files in Protected View and disallow edit\" behavior.\r\n\r\nIf you do not configure this policy setting, Office follows the \"Open files in Protected View and allow edit\" behavior.","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_0","displayName":"Block files","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_1","displayName":"Open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3","displayName":"Checked: Allow edit. Unchecked: Do not allow edit. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook","displayName":"Turn off Protected View for attachments opened from Outlook (User)","description":"This policy setting allows you to determine if Word files in Outlook attachments open in Protected View.\r\n\r\nIf you enable this policy setting, Outlook attachments do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, Outlook attachments open in Protected View.","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork","displayName":"Allow Trusted Locations on the network (User)","description":"This policy setting controls whether trusted locations on the network can be used.\r\n\r\nIf you enable this policy setting, users can specify trusted locations on network shares or in other remote locations that are not under their direct control by clicking the \"Add new location\" button in the Trusted Locations section of the Trust Center. Content, code, and add-ins are allowed to load from trusted locations with minimal security and without prompting the user for permission.\r\n\r\nIf you disable this policy setting, the selected application ignores any network locations listed in the Trusted Locations section of the Trust Center. \r\n\r\nIf you also deploy Trusted Locations via Group Policy, you should verify whether any of them are remote locations. If any of them are remote locations and you do not allow remote locations via this policy setting, those policy keys that point to remote locations will be ignored on client computers.\r\n\r\nDisabling this policy setting does not delete any network locations from the Trusted Locations list, but causes disruption for users who add network locations to the Trusted Locations list. Users are also prevented from adding new network locations to the Trusted Locations list in the Trust Center. We recommended that you do not enable this policy setting (as the \"Allow Trusted Locations on my network (not recommended)\" check box also states). Therefore, in practice, it should be possible to disable this policy setting in most situations without causing significant usability issues for most users.\r\n\r\nIf you do not enable this policy setting, users can select the \"Allow Trusted Locations on my network (not recommended)\" check box if desired and then specify trusted locations by clicking the \"Add new location\" button.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders23","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders23_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders23_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_datecolon21","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_descriptioncolon22","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_pathcolon20","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_datecolon25","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_descriptioncolon26","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_pathcolon24","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders31","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders31_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders31_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_datecolon29","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_descriptioncolon30","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_pathcolon28","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders35","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders35_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders35_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_datecolon33","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders39","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders39_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders39_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_descriptioncolon38","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_pathcolon36","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders43","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders43_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders43_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_descriptioncolon42","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_pathcolon40","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders47","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders47_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_datecolon45","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_descriptioncolon46","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_pathcolon44","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders51","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders51_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_datecolon49","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_descriptioncolon50","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_pathcolon48","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders55","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders55_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders55_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_descriptioncolon54","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11","displayName":"Trusted Location #11 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders59","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders59_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_datecolon57","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_descriptioncolon58","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_pathcolon56","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders63","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders63_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders63_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_datecolon61","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_pathcolon60","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders67","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders67_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders67_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_pathcolon64","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders71","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders71_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders71_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_datecolon69","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_descriptioncolon70","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_pathcolon68","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders75","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders75_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders75_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_datecolon73","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_descriptioncolon74","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_pathcolon72","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders79","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders79_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders79_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_datecolon77","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_descriptioncolon78","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_pathcolon76","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders83","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders83_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders83_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_datecolon81","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_descriptioncolon82","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_pathcolon80","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders87","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders87_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders87_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_datecolon85","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_descriptioncolon86","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_pathcolon84","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders91","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders91_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders91_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_datecolon89","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_descriptioncolon90","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_pathcolon88","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders95","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders95_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders95_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_datecolon93","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_descriptioncolon94","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_pathcolon92","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons","displayName":"Balloons (User)","description":"Turning balloons off will show revisions inline. This corresponds to the choices in the Review ribbon.","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty_0","displayName":"Balloons on","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty_2","displayName":"Comments and formatting only in balloons","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty_1","displayName":"Balloons off (revisions inline)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument","displayName":"Compare resulting document (User)","description":"This option determines whether the results of a document compare or combine will appear in a new document or one of the source documents. This corresponds to the option in the Compare dialog box ( Review ribbon | Compare | more options).","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart","displayName":"Document used for result of compare: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart_0","displayName":"Original Document","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart_1","displayName":"Revised Document","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart_2","displayName":"New document","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor","displayName":"Deletions color (User)","description":"Selects the color for tracked deletions. This corresponds to the choices in the Review ribbon | Track changes | Change tracking options dialog box.","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart","displayName":"Color for tracking deletions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_2","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_3","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_4","displayName":"Turquoise","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_5","displayName":"Bright Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_6","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_7","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_8","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_9","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_10","displayName":"Dark Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_11","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_12","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_13","displayName":"Violet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_14","displayName":"Dark Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_15","displayName":"Dark Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_16","displayName":"Gray 50%","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_17","displayName":"Gray 25%","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_ignorewhitespace","displayName":"Ignore White Space (User)","description":"This option determines if white space is compared in document compare. This corresponds to the option in the Compare dialog box ( Review ribbon | Compare | more options).","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_ignorewhitespace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_ignorewhitespace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor","displayName":"Insertions color (User)","description":"Selects the default color for tracked insertions. This corresponds to the choices in the Review ribbon | Track changes | Change tracking options dialog box.","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart","displayName":"Color for tracking insertions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_2","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_3","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_4","displayName":"Turquoise","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_5","displayName":"Bright Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_6","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_7","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_8","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_9","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_10","displayName":"Dark Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_11","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_12","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_13","displayName":"Violet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_14","displayName":"Dark Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_15","displayName":"Dark Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_16","displayName":"Gray 50%","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_17","displayName":"Gray 25%","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors","displayName":"Table compare colors (User)","description":"This option determines the colors used for displaying the results of compared tables. Selecting ''none'' will track the changes, but they will not be colored in the resulting document (they will be listed in the reviewing pane).","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1","displayName":"Color for inserted cells: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_2","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_3","displayName":"Light blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_4","displayName":"Light yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_5","displayName":"Light purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_6","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_7","displayName":"Light green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_8","displayName":"Gray","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2","displayName":"Color for deleted cells: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_2","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_3","displayName":"Light blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_4","displayName":"Light yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_5","displayName":"Light purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_6","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_7","displayName":"Light green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_8","displayName":"Gray","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3","displayName":"Color for merged cells: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_2","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_3","displayName":"Light blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_4","displayName":"Light yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_5","displayName":"Light purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_6","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_7","displayName":"Light green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_8","displayName":"Gray","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4","displayName":"Color for split cells: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_2","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_3","displayName":"Light blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_4","displayName":"Light yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_5","displayName":"Light purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_6","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_7","displayName":"Light green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_8","displayName":"Gray","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v3~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_acronyms","displayName":"Remove the Acronyms command from the ribbon (User)","description":"This policy setting allows you to remove the Acronyms command from the ribbon. The Acronyms command appears on the References tab.\r\n\r\nIf you enable this policy setting, the Acronyms command is removed from the ribbon. Users won't be able to add the Acronyms command to the ribbon manually. Therefore users won't be able to use the Acronyms feature.\r\n\r\nIf you disable or don't configure this policy setting, the Acronyms command appears on the ribbon.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v3~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_acronyms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v3~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_acronyms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook","displayName":"Specify default quality of compression done on inlined images inserted in Outlook (User)","description":"This policy setting allows you to specify default quality of compression done on inlined images in Outlook.\r\n\r\nIf you enable this policy setting, Outlook would compress the inlined images in the message as per the specified quality.\r\n\r\nIf you disable or don't configure this policy setting, inlined images would be compressed at the default quality (220 dpi).\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_l_defaultcompressionqualityforinlinedimagesinoutlookpart","displayName":"Default inline image compression quality for Outlook: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_l_defaultcompressionqualityforinlinedimagesinoutlookpart_0","displayName":"High Fidelity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_l_defaultcompressionqualityforinlinedimagesinoutlookpart_1","displayName":"330 ppi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_l_defaultcompressionqualityforinlinedimagesinoutlookpart_2","displayName":"220 ppi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_l_defaultcompressionqualityforinlinedimagesinoutlookpart_3","displayName":"150 ppi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_l_defaultcompressionqualityforinlinedimagesinoutlookpart_4","displayName":"96 ppi","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_donotcompressinlinedimagesinoutlook","displayName":"Do not compress the inlined images inserted in Outlook (User)","description":"This policy setting allows you to disable compression on inlined images in Outlook.\r\n\r\nIf you enable this policy setting, Outlook won't compress inlined images in the message.\r\n\r\nIf you disable or don't configure this policy setting, inlined images would be compressed.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_donotcompressinlinedimagesinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_donotcompressinlinedimagesinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation","displayName":"Stop checking for table alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables contain alt text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables contain alt text.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningfultext","displayName":"Stop checking to ensure hyperlink text is meaningful (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningfultext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningfultext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningfultextextension","displayName":"Stop checking to ensure hyperlink text extension is meaningful if they include extensions (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text if they include extensions.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text if they include extensions.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text that include extensions will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningfultextextension_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningfultextextension_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}","displayName":"Printer Shared ID (User)","description":"Identifies the Universal Print printer, by its Share ID, you wish to install on the targeted user account. The printer's Share ID can be found in the printer's properties via the Universal Print portal. Note: the targeted user account must have access rights to both the printer and to the Universal Print service.","helpText":"","infoUrls":[],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_clouddeviceid","displayName":"Cloud Device ID (User)","description":"Identifies the Universal Print printer, by its Printer ID, you wish to install on the targeted user account. The printer's Printer ID can be found in the printer's properties via the Universal Print portal. Note: the targeted user account must have access rights to both the printer and to the Universal Print service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PrinterProvisioning-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_errorcode","displayName":"Error code (User)","description":"Univeral Print printer installation error code.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PrinterProvisioning-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_install","displayName":"Install (User)","description":"Install Univeral Print printer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PrinterProvisioning-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_install_true","displayName":"Install","description":"Install this printer","helpText":null}},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_printersharedid","displayName":"Shared ID (User)","description":"Universal Print printer shared id","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/UPPrinterInstalls-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_printersharedname","displayName":"Printer Shared Name (User)","description":"Identifies the Universal Print printer, by its Share Name, you wish to install on the targeted user account. The printer's Share Name can be found in the printer's properties via the Universal Print portal. Note: the targeted user account must have access rights to both the printer and to the Universal Print service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PrinterProvisioning-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_status","displayName":"Status (User)","description":"Univeral Print printer status.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PrinterProvisioning-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},{"id":"vendor_msft_controlledconfiguration_blob","displayName":"Controlled Configuration Blob","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/defender-csp#:~:text=Configuration/TamperProtection"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"vendor_msft_defender_configuration_tamperprotection","displayName":"TamperProtection","description":"Enable tamper protection to prevent Microsoft Defender being disabled.\r\nNot Configured state is default and will have no impact.\r\nEnabled will enable the Tamper Protection restrictions.\r\nDisabled will disable the Tamper Protection restrictions.\r\nWhen the Enabled or Disabled state exists on a client, deploying Not configured will have no impact on the setting. To change the state from currently Enabled/Disabled, you must deploy the opposite setting to have effect.","helpText":null,"infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"vendor_msft_defender_configuration_tamperprotection_0","displayName":"Not configured","description":null,"helpText":null},{"id":"vendor_msft_defender_configuration_tamperprotection_1","displayName":"Enabled","description":null,"helpText":null},{"id":"vendor_msft_defender_configuration_tamperprotection_2","displayName":"Disabled","description":null,"helpText":null}]},{"id":"vendor_msft_defender_configuration_tamperprotection_blob","displayName":"Tamper Protection Blob","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/defender-csp#:~:text=Configuration/TamperProtection"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"vendor_msft_defender_configuration_tamperprotection_options","displayName":"Controlled Configuration (Device)","description":"This setting can be used to turn on controlled configuration or tamper protection to help protect important security features from unwanted changes and interference.\r\n\r\nIf the setting is configured to Tamper Protection (On), this turns on tamper protection to enforce tamper protected settings to their secure defaults. This includes real-time protection, behavior monitoring, and more. Settings are configured with an MDM solution, such as Intune and is available in Windows 10 Enterprise E5 or equivalent subscriptions.\r\n\r\nIf the setting is configured to Controlled Configuration (On), this turns on controlled configuration, which enforces the configuration coming from Intune exclusively and any non-configured settings to their secure defaults. Controlled configuration is applicable to Antivirus and Endpoint detection and response settings.\r\n\r\nIf the setting is configured to OFF, this turns off Controlled Configuration and Tamper Protection.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/defender-csp#:~:text=Configuration/TamperProtection"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"vendor_msft_defender_configuration_tamperprotection_options_1","displayName":"Off","description":null,"helpText":null},{"id":"vendor_msft_defender_configuration_tamperprotection_options_0","displayName":"Tamper Protection (On)","description":null,"helpText":null},{"id":"vendor_msft_defender_configuration_tamperprotection_options_2","displayName":"Controlled Configuration (On)","description":null,"helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_allowlocalipsecpolicymerge","displayName":"Allow Local Ipsec Policy Merge","description":"This value is an on/off switch. If this value is false, connection security rules from the local store are ignored and not enforced, regardless of the schema version and connection security rule version. The merge law for this option is to always use the value of the GroupPolicyRSoPStore.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_allowlocalipsecpolicymerge_false","displayName":"False","description":"AllowLocalIpsecPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_allowlocalipsecpolicymerge_true","displayName":"True","description":"AllowLocalIpsecPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, firewall rules from the local store are ignored and not enforced. The merge law for this option is to always use the value of the GroupPolicyRSoPStore. This value is valid for all schema versions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_allowlocalpolicymerge_false","displayName":"False","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_allowlocalpolicymerge_true","displayName":"True","description":"AllowLocalPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_authappsallowuserprefmerge","displayName":"Auth Apps Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, authorized application firewall rules in the local store are ignored and not enforced. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_authappsallowuserprefmerge_false","displayName":"False","description":"AuthAppsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_authappsallowuserprefmerge_true","displayName":"True","description":"AuthAppsAllowUserPrefMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_defaultinboundaction","displayName":"Default Inbound Action for Domain Profile","description":"This value is the action that the firewall does by default (and evaluates at the very end) on inbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 1 [Block]. The merge law for this option is to let the value of the GroupPolicyRSoPStore.win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_defaultinboundaction_0","displayName":"Allow","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_defaultinboundaction_1","displayName":"Block","description":"Block Inbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow]. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_defaultoutboundaction_0","displayName":"Allow","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_defaultoutboundaction_1","displayName":"Block","description":"Block Outbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disableinboundnotifications","displayName":"Disable Inbound Notifications","description":"This value is an on/off switch. If this value is false, the firewall MAY display a notification to the user when an application is blocked from listening on a port. If this value is on, the firewall MUST NOT display such a notification. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_disableinboundnotifications_false","displayName":"False","description":"Firewall May Display Notification","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disableinboundnotifications_true","displayName":"True","description":"Firewall Must Not Display Notification","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disablestealthmode","displayName":"Disable Stealth Mode","description":"This value is an on/off switch. When this option is false, the server operates in stealth mode. The firewall rules used to enforce stealth mode are implementation-specific. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_disablestealthmode_false","displayName":"False","description":"Use Stealth Mode","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disablestealthmode_true","displayName":"True","description":"Disable Stealth Mode","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disablestealthmodeipsecsecuredpacketexemption","displayName":"Disable Stealth Mode Ipsec Secured Packet Exemption","description":"This value is an on/off switch. This option is ignored if DisableStealthMode is on. Otherwise, when this option is true, the firewall's stealth mode rules MUST NOT prevent the host computer from responding to unsolicited network traffic if that traffic is secured by IPsec. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used. For schema versions 0x0200, 0x0201, and 0x020A, this value is invalid and MUST NOT be used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_disablestealthmodeipsecsecuredpacketexemption_false","displayName":"False","description":"FALSE","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disablestealthmodeipsecsecuredpacketexemption_true","displayName":"True","description":"TRUE","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disableunicastresponsestomulticastbroadcast","displayName":"Disable Unicast Responses To Multicast Broadcast","description":"This value is used as an on/off switch. If it is true, unicast responses to multicast broadcast traffic is blocked. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_disableunicastresponsestomulticastbroadcast_false","displayName":"False","description":"Unicast Responses Not Blocked","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disableunicastresponsestomulticastbroadcast_true","displayName":"True","description":"Unicast Responses Blocked","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablefirewall","displayName":"Enable Domain Network Firewall","description":"This value is an on/off switch for the firewall and advanced security enforcement. If this value is false, the server MUST NOT block any network traffic, regardless of other policy settings. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":" ","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogdroppedpackets","displayName":"Enable Log Dropped Packets","description":"This value is used as an on/off switch. If this value is on, the firewall logs all the dropped packets. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogdroppedpackets_false","displayName":"Disable Logging Of Dropped Packets","description":"Disable Logging Of Dropped Packets","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogdroppedpackets_true","displayName":"Enable Logging Of Dropped Packets","description":"Enable Logging Of Dropped Packets","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogignoredrules","displayName":"Enable Log Ignored Rules","description":"This value is used as an on/off switch. The server MAY use this value in an implementation-specific way to control logging of events if a rule is not enforced for any reason. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogignoredrules_false","displayName":"Disable Logging Of Ignored Rules","description":"Disable Logging Of Ignored Rules","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogignoredrules_true","displayName":"Enable Logging Of Ignored Rules","description":"Enable Logging Of Ignored Rules","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogsuccessconnections","displayName":"Enable Log Success Connections","description":"This value is used as an on/off switch. If this value is on, the firewall logs all successful inbound connections. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogsuccessconnections_false","displayName":"Disable Logging Of Successful Connections","description":"Disable Logging Of Successful Connections","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogsuccessconnections_true","displayName":"Enable Logging Of Successful Connections","description":"Enable Logging Of Successful Connections","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_globalportsallowuserprefmerge","displayName":"Global Ports Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, global port firewall rules in the local store are ignored and not enforced. The setting only has meaning if it is set or enumerated in the Group Policy store or if it is enumerated from the GroupPolicyRSoPStore. The merge law for this option is to let the value GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_globalportsallowuserprefmerge_false","displayName":"False","description":"GlobalPortsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_globalportsallowuserprefmerge_true","displayName":"True","description":"GlobalPortsAllowUserPrefMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_logfilepath","displayName":"Log File Path","description":"This value is a string that represents a file path to the log where the firewall logs dropped packets and successful connections. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_logmaxfilesize","displayName":"Log Max File Size","description":"This value specifies the size, in kilobytes, of the log file where dropped packets and successful connections are logged. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_shielded","displayName":"Shielded","description":"This value is used as an on/off switch. If this value is on and EnableFirewall is on, the server MUST block all incoming traffic regardless of other policy settings. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_shielded_false","displayName":"False","description":"Shielding Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_shielded_true","displayName":"True","description":"Shielding On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}","displayName":" Firewall Rule Name","description":"Unique alpha numeric identifier for the rule. The rule name must not include a forward slash (/).","helpText":"","infoUrls":[],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_action_type","displayName":"Action","description":"Specifies the action the rule enforces to block or allow network traffic.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_action_type_0","displayName":"Block","description":"Block","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_action_type_1","displayName":"Allow","description":"Allow","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_app_filepath","displayName":"File Path","description":"The file path of an app is simply its location on the client device. For example, C:\\Windows\\System\\Notepad.exe or %WINDIR%\\Notepad.exe. You can define one application to be used in each Firewall rule. If you specify multiple conditions in a single rule, these will be treated as an AND operation. i.e program=svchost.exe AND service=mpssvc, etc. All of the app related conditions in a single rule work to scope the traffic even further, so they must all correspond to the specific app/service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_app_packagefamilyname","displayName":"Package Family Name","description":"Package family names can be retrieved by running the Get-AppxPackage command from PowerShell. You can define one application to be used in each Firewall rule. If you specify multiple conditions in a single rule, these will be treated as an AND operation. i.e program=svchost.exe AND service=mpssvc, etc. All of the app related conditions in a single rule work to scope the traffic even further, so they must all correspond to the specific app/service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_app_servicename","displayName":"Service Name","description":"Windows service short names are used in cases when a service, not an application, is sending or receiving traffic. Service short names can be retrieved by running the Get-Service command from PowerShell. You can define one application to be used in each Firewall rule. If you specify multiple conditions in a single rule, these will be treated as an AND operation. i.e program=svchost.exe AND service=mpssvc, etc. All of the app related conditions in a single rule work to scope the traffic even further, so they must all correspond to the specific app/service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_description","displayName":"Description","description":"Specifies the description of the rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_direction","displayName":"Direction","description":"Comma separated list. The rule is enabled based on the traffic direction as following.\n\nIN - the rule applies to inbound traffic.\nOUT - the rule applies to outbound traffic.\n\nIf not specified the detault is OUT.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_direction_in","displayName":"The rule applies to inbound traffic.","description":"The rule applies to inbound traffic.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_direction_out","displayName":"The rule applies to outbound traffic.","description":"The rule applies to outbound traffic.","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_edgetraversal","displayName":"Edge Traversal","description":"Indicates whether edge traversal is enabled or disabled for this rule.\n\nThe EdgeTraversal property indicates that specific inbound traffic is allowed to tunnel through NATs and other edge devices using the Teredo tunneling technology. In order for this setting to work correctly, the application or service with the inbound firewall rule needs to support IPv6. The primary application of this setting allows listeners on the host to be globally addressable through a Teredo IPv6 address.\n\nNew rules have the EdgeTraversal property disabled by default.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_edgetraversal_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_edgetraversal_1","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_enabled","displayName":"Enabled","description":"Indicates whether the rule is enabled or disabled. If not specified - a new rule is enabled by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_enabled_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_enabled_1","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_firewallrulename","displayName":null,"description":null,"helpText":null,"infoUrls":[],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_icmptypesandcodes","displayName":"ICMP Types And Codes","description":"\n String value. Multiple ICMP type+code pairs can be included in the string by separating each value with a \",\". If more than one ICMP type+code pair is specified, the strings must be separated by a comma.\n To specify all ICMP types and codes, use the \"*\" character. For specific ICMP types and codes, use the \":\" to separate the type and code.\n The following are valid examples: 3:4 or 1:*. The \"*\" character can be used to represent any code. The \"*\" character can't be used to specify any type, examples such as \"*:4\" or \"*:*\" are invalid.\n When setting this field in a firewall rule, the protocol field must also be set, to either 1 (ICMP) or 58 (IPv6-ICMP).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes","displayName":"Interface Types","description":"String value. Multiple interface types can be included in the string by separating each value with a \",\". Acceptable values are \"RemoteAccess\", \"Wireless\", \"Lan\", and \"All\".\n If more than one interface type is specified, the strings must be separated by a comma.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_remoteaccess","displayName":"Remote Access","description":"RemoteAccess","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_wireless","displayName":"Wireless","description":"Wireless","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_lan","displayName":"Lan","description":"Lan","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_mobilebroadband","displayName":"[Not Supported] Mobile Broadband","description":"MobileBroadband","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_mbb","displayName":"Mobile Broadband","description":"MobileBroadband","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_all","displayName":"All","description":"All","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_localaddressranges","displayName":"Local Address Ranges","description":"List of local addresses covered by the rule. Valid tokens include:​\r\n\r\n\"*\" indicates any local address. If present, this must be the only token included.\r\nA subnet can be specified using either the subnet mask or network prefix notation. If neither a subnet mask nor a network prefix is specified, the subnet mask defaults to 255.255.255.255.​​\r\nA valid IPv6 address.​​\r\nAn IPv4 address range in the format of \"start address - end address\" with no spaces included, where the start address is less than the end address.​​\r\nAn IPv6 address range in the format of \"start address - end address\" with no spaces included, where the start address is less than the end address.\r\n\r\nIf not specified, the default is \"Any address.\"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_localportranges","displayName":"Local Port Ranges","description":"List of local port ranges. Valid values include:​\r\n\r\nA valid port number between 0 and 65535. For example, 200\r\nA port range in the format of \"start port – end port\" with no spaces included, where the start port is less than the end port. For example, 300-320\r\n\r\nIf not specified, the default is \"All ports.\" When defining multiple local and remote port ranges, the Firewall rule will be evaluated as OR operations within an individual field, and AND operations across rule fields. i.e. (local port A OR local port B) AND (remote port A OR remote port B). When setting this field in a firewall rule, the protocol field must also be set, to either 6 (TCP) or 17 (UDP).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_localuserauthorizedlist","displayName":"Local User Authorized List","description":"Specifies the list of authorized local users for this rule. A list of authorized users cannot be specified if the rule being authored is targeting a Windows service. If not specified, the default is all users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_name","displayName":"Name","description":"Specifies the friendly name of the firewall rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_policyappid","displayName":"Policy App Id","description":" Specifies one WDAC tag. This is a string that can contain any alphanumeric character and any of the characters \":\", \"/\", \".\", and \"_\". \r\n A PolicyAppId and ServiceName cannot be specified in the same rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_profiles","displayName":"Network Types","description":"Specifies the profiles to which the rule belongs: Domain, Private, Public. See FW_PROFILE_TYPE for the bitmasks that are used to identify profile types. If not specified, the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_profiles_1","displayName":"FW_PROFILE_TYPE_DOMAIN: This value represents the profile for networks that are connected to domains.","description":"FW_PROFILE_TYPE_DOMAIN: This value represents the profile for networks that are connected to domains.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_profiles_2","displayName":"FW_PROFILE_TYPE_PRIVATE: This value represents the standard profile for networks. These networks are classified as private by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are behind Network Address Translation (NAT) devices, routers, and other edge devices, and they are in a private location, such as a home or an office. AND FW_PROFILE_TYPE_PRIVATE: This value represents the profile for private networks, which is represented by the same value as that used for FW_PROFILE_TYPE_STANDARD.","description":"FW_PROFILE_TYPE_STANDARD: This value represents the standard profile for networks. These networks are classified as private by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are behind Network Address Translation (NAT) devices, routers, and other edge devices, and they are in a private location, such as a home or an office. AND FW_PROFILE_TYPE_PRIVATE: This value represents the profile for private networks, which is represented by the same value as that used for FW_PROFILE_TYPE_STANDARD.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_profiles_4","displayName":"FWPROFILETYPEPUBLIC: This value represents the profile for public networks. These networks are classified as public by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are those at airports, coffee shops, and other public places where the peers in the network or the network administrator are not trusted.","description":"FW_PROFILE_TYPE_PUBLIC: This value represents the profile for public networks. These networks are classified as public by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are those at airports, coffee shops, and other public places where the peers in the network or the network administrator are not trusted.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_profiles_2147483647","displayName":"FW_PROFILE_TYPE_ALL: This value represents all these network sets and any future network sets.","description":"FW_PROFILE_TYPE_ALL: This value represents all these network sets and any future network sets.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_profiles_-2147483648","displayName":"FW_PROFILE_TYPE_CURRENT: This value represents the current profiles to which the firewall and advanced security components determine the host is connected at the moment of the call. This value can be specified only in method calls, and it cannot be combined with other flags.","description":"FW_PROFILE_TYPE_CURRENT: This value represents the current profiles to which the firewall and advanced security components determine the host is connected at the moment of the call. This value can be specified only in method calls, and it cannot be combined with other flags.","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_protocol","displayName":"Protocol","description":"Select the protocol for this port rule. Transport layer protocols, TCP(6) and UDP(17), allow you to specify ports or port ranges. For custom protocols, enter a number between 0 and 255 representing the IP protocol. If not specified, the default is \"Any.\"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_remoteaddressdynamickeywords","displayName":"Reusable groups","description":"Comma separated list of Dynamic Keyword Address Ids (GUID strings) specifying the remote addresses covered by the rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_remoteaddressranges","displayName":"Remote Address Ranges","description":"List of remote addresses covered by the rule. Tokens are case insensitive. Valid tokens include:​​​\r\n\r\n\"*\" indicates any remote address. If present, this must be the only token included.\r\n\r\n\"Defaultgateway\"\r\n\"DHCP\"\r\n\"DNS\"\r\n\"WINS\"\r\n\"Intranet\" (supported on Windows versions 1809+)\r\n\"RmtIntranet\" (supported on Windows versions 1809+)\r\n\"Internet\" (supported on Windows versions 1809+)\r\n\"Ply2Renders\" ​(supported on Windows versions 1809+)\r\n\"LocalSubnet\" indicates any local address on the local subnet.\r\nA subnet can be specified using either the subnet mask or network prefix notation. If neither a subnet mask nor a network prefix is specified, the subnet mask defaults to 255.255.255.255.\r\nA valid IPv6 address.\r\nAn IPv4 address range in the format of \"start address - end address\" with no spaces included, where the start address is less than the end address.\r\nAn IPv6 address range in the format of \"start address - end address\" with no spaces included, where the start address is less than the end address.​\r\n\r\nIf not specified, the default is \"Any address.\"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_remoteportranges","displayName":"Remote Port Ranges","description":"List of remote port ranges. Valid values include:​\r\n\r\nA valid port number between 0 and 65535. For example, 200\r\nA port range in the format of \"start port – end port\" with no spaces included, where the start port is less than the end port. For example, 300-320\r\n\r\nIf not specified, the default is \"All ports.\" When defining multiple local and remote port ranges, the Firewall rule will be evaluated as OR operations within an individual field, and AND operations across rule fields. i.e. (local port A OR local port B) AND (remote port A OR remote port B). When setting this field in a firewall rule, the protocol field must also be set, to either 6 (TCP) or 17 (UDP).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_global_crlcheck","displayName":"Certificate revocation list verification","description":"This value specifies how certificate revocation list (CRL) verification is enforced. The value MUST be 0, 1, or 2. A value of 0 disables CRL checking. A value of 1 specifies that CRL checking is attempted and that certificate validation fails only if the certificate is revoked. Other failures that are encountered during CRL checking (such as the revocation URL being unreachable) do not cause certificate validation to fail. A value of 2 means that checking is required and that certificate validation fails if any error is encountered during CRL processing. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, use the local store value.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_crlcheck_0","displayName":"None","description":"Disables CRL checking","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_crlcheck_1","displayName":"Attempt","description":"Specifies that CRL checking is attempted and that certificate validation fails only if the certificate is revoked. Other failures that are encountered during CRL checking (such as the revocation URL being unreachable) do not cause certificate validation to fail.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_crlcheck_2","displayName":"Require","description":"Means that checking is required and that certificate validation fails if any error is encountered during CRL processing","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_disablestatefulftp","displayName":"Disable Stateful Ftp","description":"This value is an on/off switch. If off, the firewall performs stateful File Transfer Protocol (FTP) filtering to allow secondary connections. FALSE means off; TRUE means on, so the stateful FTP is disabled. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_disablestatefulftp_false","displayName":"False","description":"Stateful FTP enabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_disablestatefulftp_true","displayName":"True","description":"Stateful FTP disabled","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_enableauditmode","displayName":"Enable Audit Mode","description":"This value specifies if the target machine is in Firewall Audit Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_enableauditmode_false","displayName":"Indicates that Audit mode is disabled","description":"Indicates that Audit mode is disabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_enableauditmode_true","displayName":"Indicates that Audit mode is enabled","description":"Indicates that Audit mode is enabled","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_enablepacketqueue","displayName":"Enable Packet Queue","description":"This value specifies how scaling for the software on the receive side is enabled for both the encrypted receive and clear text forward path for the IPsec tunnel gateway scenario. Use of this option also ensures that the packet order is preserved. The data type for this option value is a integer and is a combination of flags. A value of 0x00 indicates that all queuing is to be disabled. A value of 0x01 specifies that inbound encrypted packets are to be queued. A value of 0x02 specifies that packets are to be queued after decryption is performed for forwarding.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_enablepacketqueue_0","displayName":"Disabled","description":"Indicates that all queuing is to be disabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_enablepacketqueue_1","displayName":"Queue Inbound","description":"Specifies that inbound encrypted packets are to be queued","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_enablepacketqueue_2","displayName":"Queue Outbound","description":"Specifies that packets are to be queued after decryption is performed for forwarding","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt","displayName":"IPsec Exceptions","description":"This value configures IPsec exceptions and MUST be a combination of the valid flags that are defined in IPSEC_EXEMPT_VALUES; therefore, the maximum value MUST always be IPSEC_EXEMPT_MAX-1 for servers supporting a schema version of 0x0201 and IPSEC_EXEMPT_MAX_V2_0-1 for servers supporting a schema version of 0x0200. If the maximum value is exceeded when the method RRPC_FWSetGlobalConfig (Opnum 4) is called, the method returns ERROR_INVALID_PARAMETER. This error code is returned if no other preceding error is discovered. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, use the local store value.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_0","displayName":"FWGLOBALCONFIGIPSECEXEMPTNONE: No IPsec exemptions.","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_NONE: No IPsec exemptions.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_1","displayName":"Exempt neighbor discover IPv6 ICMP type-codes from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_NEIGHBOR_DISC: Exempt neighbor discover IPv6 ICMP type-codes from IPsec.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_2","displayName":"Exempt ICMP from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_ICMP: Exempt ICMP from IPsec.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_4","displayName":"Exempt router discover IPv6 ICMP type-codes from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_ROUTER_DISC: Exempt router discover IPv6 ICMP type-codes from IPsec.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_8","displayName":"Exempt both IPv4 and IPv6 DHCP traffic from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_DHCP: Exempt both IPv4 and IPv6 DHCP traffic from IPsec.","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_opportunisticallymatchauthsetperkm","displayName":"Opportunistically Match Auth Set Per KM","description":"This value is used as an on/off switch. When this option is false, keying modules MUST ignore the entire authentication set if they do not support all of the authentication suites specified in the set. When this option is true, keying modules MUST ignore only the authentication suites that they don’t support. For schema versions 0x0200, 0x0201, and 0x020A, this value is invalid and MUST NOT be used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_opportunisticallymatchauthsetperkm_false","displayName":"False","description":"FALSE","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_opportunisticallymatchauthsetperkm_true","displayName":"True","description":"TRUE","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_presharedkeyencoding","displayName":"Preshared Key Encoding","description":"Specifies the preshared key encoding that is used. MUST be a valid value from the PRESHARED_KEY_ENCODING_VALUES enumeration. Default is 1 [UTF-8]. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, use the local store value.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_presharedkeyencoding_0","displayName":"None","description":"FW_GLOBAL_CONFIG_PRESHARED_KEY_ENCODING_NONE: Preshared key is not encoded. Instead, it is kept in its wide-character format. This symbolic constant has a value of 0.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_presharedkeyencoding_1","displayName":"UTF8","description":"FW_GLOBAL_CONFIG_PRESHARED_KEY_ENCODING_UTF_8: Encode the preshared key using UTF-8. This symbolic constant has a value of 1.","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_saidletime","displayName":"Security association idle time","description":"This value configures the security association idle time, in seconds. Security associations are deleted after network traffic is not seen for this specified period of time. The value MUST be in the range of 300 to 3,600 inclusive. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, use the local store value.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}","displayName":" Firewall Rule Name","description":"Unique alpha numeric identifier for the rule. The rule name must not include a forward slash (/).","helpText":"","infoUrls":[],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_action","displayName":"Action","description":"Specifies the action the rule enforces:\n0 - Block\n1 - Allow","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_action_0","displayName":"Block","description":"Block","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_action_1","displayName":"Allow","description":"Allow","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_direction","displayName":"Direction","description":"The rule is enabled based on the traffic direction as following.\n\nIN - the rule applies to inbound traffic.\nOUT - the rule applies to outbound traffic.\n\nIf not specified the detault is OUT.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_direction_in","displayName":"The rule applies to inbound traffic.","description":"The rule applies to inbound traffic.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_direction_out","displayName":"The rule applies to outbound traffic.","description":"The rule applies to outbound traffic.","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_enabled","displayName":"Enabled","description":"Indicates whether the rule is enabled or disabled. If not specified - a new rule is enabled by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_enabled_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_enabled_1","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_firewallrulename","displayName":null,"description":null,"helpText":null,"infoUrls":[],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_localaddressranges","displayName":"Local Address Ranges","description":"Consists of one or more comma-delimited tokens specifying the local addresses covered by the rule. \"*\" is the default value.\nValid tokens include:\n\"*\" indicates any local address. If present, this must be the only token included.\n\nA subnet can be specified using either the subnet mask or network prefix notation. If neither a subnet mask not a network prefix is specified, the subnet mask defaults to 255.255.255.255.\nA valid IPv6 address.\nAn IPv4 address range in the format of \"start address - end address\" with no spaces included.\nAn IPv6 address range in the format of \"start address - end address\" with no spaces included. If not specified the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_localportranges","displayName":"Local Port Ranges","description":"Comma Separated list of ranges for eg. 100-120,200,300-320. If not specified the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_name","displayName":"Name","description":"Specifies the friendly name of the Hyper-V Firewall rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_priority","displayName":"Priority","description":"This value represents the order of rule enforcement. A lower priority rule is evaluated first. If not specified, block rules are evaluated before allow rules. If priority is configured, it is highly recommended to configure the value for ALL rules to ensure expected evaluation of rules.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_profiles","displayName":"Profiles","description":"Specifies the profiles to which the rule belongs: Domain, Private, Public. See FW_PROFILE_TYPE for the bitmasks that are used to identify profile types. If not specified, the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_profiles_1","displayName":"FWPROFILETYPEDOMAIN: This value represents the profile for networks that are connected to domains.","description":"FW_PROFILE_TYPE_DOMAIN: This value represents the profile for networks that are connected to domains.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_profiles_2","displayName":"FWPROFILETYPESTANDARD: This value represents the standard profile for networks. These networks are classified as private by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are behind Network Address Translation (NAT) devices, routers, and other edge devices, and they are in a private location, such as a home or an office. AND FWPROFILETYPEPRIVATE: This value represents the profile for private networks, which is represented by the same value as that used for FWPROFILETYPESTANDARD.","description":"FW_PROFILE_TYPE_STANDARD: This value represents the standard profile for networks. These networks are classified as private by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are behind Network Address Translation (NAT) devices, routers, and other edge devices, and they are in a private location, such as a home or an office. AND FW_PROFILE_TYPE_PRIVATE: This value represents the profile for private networks, which is represented by the same value as that used for FW_PROFILE_TYPE_STANDARD.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_profiles_4","displayName":"FWPROFILETYPEPUBLIC: This value represents the profile for public networks. These networks are classified as public by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are those at airports, coffee shops, and other public places where the peers in the network or the network administrator are not trusted.","description":"FW_PROFILE_TYPE_PUBLIC: This value represents the profile for public networks. These networks are classified as public by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are those at airports, coffee shops, and other public places where the peers in the network or the network administrator are not trusted.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_profiles_2147483647","displayName":"FWPROFILETYPEALL: This value represents all these network sets and any future network sets.","description":"FW_PROFILE_TYPE_ALL: This value represents all these network sets and any future network sets.","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_protocol","displayName":"Protocol","description":"0-255 number representing the ip protocol (TCP = 6, UDP = 17). If not specified the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_remoteaddressranges","displayName":"Remote Address Ranges","description":"Consists of one or more comma-delimited tokens specifying the remote addresses covered by the rule. The default value is \"*\". Valid tokens include:\n\"*\" indicates any remote address. If present, this must be the only token included.\nA subnet can be specified using either the subnet mask or network prefix notation. If neither a subnet mask not a network prefix is specified, the subnet mask defaults to 255.255.255.255.\nA valid IPv6 address.\nAn IPv4 address range in the format of \"start address - end address\" with no spaces included.\nAn IPv6 address range in the format of \"start address - end address\" with no spaces included. If not specified the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_remoteportranges","displayName":"Remote Port Ranges","description":" Comma Separated list of ranges for eg. 100-120,200,300-320. If not specified the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_vmcreatorid","displayName":"Target","description":"This field specifies the VM Creator ID that this rule is applicable to. Not configuring this setting will result in this rule applying to all VM creators.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_vmcreatorid_wsl","displayName":"Windows Subsystem for Linux","description":"Windows Subsystem for Linux","helpText":null}},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}","displayName":"VM Creator Id","description":"VM Creator ID that these settings apply to. Valid format is a GUID","helpText":"","infoUrls":[],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_allowhostpolicymerge","displayName":"Allow Host Policy Merge","description":"This value is used as an on/off switch. If this value is true, applicable host firewall rules and settings will be applied to Hyper-V Firewall.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_allowhostpolicymerge_false","displayName":"AllowHostPolicyMerge Off","description":"AllowHostPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_allowhostpolicymerge_true","displayName":"AllowHostPolicyMerge On","description":"AllowHostPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, Hyper-V Firewall rules from the local store are ignored and not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_allowlocalpolicymerge_false","displayName":"AllowLocalPolicyMerge Off","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_allowlocalpolicymerge_true","displayName":"AllowLocalPolicyMerge On","description":"AllowLocalPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_defaultinboundaction","displayName":"Default Inbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on inbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 1 [Block].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_defaultinboundaction_0","displayName":"Allow Inbound By Default","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_defaultinboundaction_1","displayName":"Block Inbound By Default","description":"Block Inbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_defaultoutboundaction_0","displayName":"Allow Outbound By Default","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_defaultoutboundaction_1","displayName":"Block Outbound By Default","description":"Block Outbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_enablefirewall","displayName":"Enable Domain Network Firewall","description":"This value is an on/off switch for the Hyper-V Firewall enforcement.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_enableloopback","displayName":"Enable Loopback","description":"This value is an on/off switch for loopback traffic. This determines if this VM is able to send/receive loopback traffic to other VMs or the host.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_enableloopback_false","displayName":"Disable loopback","description":"Disable loopback","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_enableloopback_true","displayName":"Enable loopback","description":"Enable loopback","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, Hyper-V Firewall rules from the local store are ignored and not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_allowlocalpolicymerge_false","displayName":"AllowLocalPolicyMerge Off","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_allowlocalpolicymerge_true","displayName":"AllowLocalPolicyMerge On","description":"AllowLocalPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultinboundaction","displayName":"Default Inbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on inbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 1 [Block].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultinboundaction_0","displayName":"Allow Inbound By Default","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultinboundaction_1","displayName":"Block Inbound By Default","description":"Block Inbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultoutboundaction_0","displayName":"Allow Outbound By Default","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultoutboundaction_1","displayName":"Block Outbound By Default","description":"Block Outbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_enablefirewall","displayName":"Enable Private Network Firewall","description":"This value is an on/off switch for the Hyper-V Firewall enforcement.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, Hyper-V Firewall rules from the local store are ignored and not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_allowlocalpolicymerge_false","displayName":"AllowLocalPolicyMerge Off","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_allowlocalpolicymerge_true","displayName":"AllowLocalPolicyMerge On","description":"AllowLocalPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultinboundaction","displayName":"Default Inbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on inbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 1 [Block].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultinboundaction_0","displayName":"Allow Inbound By Default","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultinboundaction_1","displayName":"Block Inbound By Default","description":"Block Inbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultoutboundaction_0","displayName":"Allow Outbound By Default","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultoutboundaction_1","displayName":"Block Outbound By Default","description":"Block Outbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_enablefirewall","displayName":"Enable Public Network Firewall","description":"This value is an on/off switch for the Hyper-V Firewall enforcement.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_enablefirewall_false","displayName":"False","description":"Disable Hyper-V Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_enablefirewall_true","displayName":"True","description":"Enable Hyper-V Firewall","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_target","displayName":"Target","description":"Settings for the Windows Firewall for Hyper-V containers. Each setting applies on a per-VM Creator basis","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_target_wsl","displayName":"Windows Subsystem for Linux","description":"Windows Subsystem for Linux","helpText":null}},{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalipsecpolicymerge","displayName":"Allow Local Ipsec Policy Merge","description":"This value is an on/off switch. If this value is false, connection security rules from the local store are ignored and not enforced, regardless of the schema version and connection security rule version. The merge law for this option is to always use the value of the GroupPolicyRSoPStore.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalipsecpolicymerge_false","displayName":"False","description":"AllowLocalIpsecPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalipsecpolicymerge_true","displayName":"True","description":"AllowLocalIpsecPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, firewall rules from the local store are ignored and not enforced. The merge law for this option is to always use the value of the GroupPolicyRSoPStore. This value is valid for all schema versions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalpolicymerge_false","displayName":"False","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalpolicymerge_true","displayName":"True","description":"AllowLocalPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_authappsallowuserprefmerge","displayName":"Auth Apps Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, authorized application firewall rules in the local store are ignored and not enforced. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_authappsallowuserprefmerge_false","displayName":"False","description":"AuthAppsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_authappsallowuserprefmerge_true","displayName":"True","description":"AuthAppsAllowUserPrefMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultinboundaction","displayName":"Default Inbound Action for Private Profile","description":"Specifies how to filter inbound traffic. The acceptable values for this parameter are: NotConfigured, Allow, or Block.","helpText":" ","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultinboundaction_0","displayName":"Allow","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultinboundaction_1","displayName":"Block","description":"Block Inbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow]. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultoutboundaction_0","displayName":"Allow","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultoutboundaction_1","displayName":"Block","description":"Block Outbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableinboundnotifications","displayName":"Disable Inbound Notifications","description":"This value is an on/off switch. If this value is false, the firewall MAY display a notification to the user when an application is blocked from listening on a port. If this value is on, the firewall MUST NOT display such a notification. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableinboundnotifications_false","displayName":"False","description":"Firewall May Display Notification","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableinboundnotifications_true","displayName":"True","description":"Firewall Must Not Display Notification","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmode","displayName":"Disable Stealth Mode","description":"This value is an on/off switch. When this option is false, the server operates in stealth mode. The firewall rules used to enforce stealth mode are implementation-specific. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmode_false","displayName":"False","description":"Use Stealth Mode","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmode_true","displayName":"True","description":"Disable Stealth Mode","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmodeipsecsecuredpacketexemption","displayName":"Disable Stealth Mode Ipsec Secured Packet Exemption","description":"This value is an on/off switch. This option is ignored if DisableStealthMode is on. Otherwise, when this option is true, the firewall's stealth mode rules MUST NOT prevent the host computer from responding to unsolicited network traffic if that traffic is secured by IPsec. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used. For schema versions 0x0200, 0x0201, and 0x020A, this value is invalid and MUST NOT be used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmodeipsecsecuredpacketexemption_false","displayName":"False","description":"FALSE","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmodeipsecsecuredpacketexemption_true","displayName":"True","description":"TRUE","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableunicastresponsestomulticastbroadcast","displayName":"Disable Unicast Responses To Multicast Broadcast","description":"This value is used as an on/off switch. If it is true, unicast responses to multicast broadcast traffic is blocked. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableunicastresponsestomulticastbroadcast_false","displayName":"False","description":"Unicast Responses Not Blocked","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableunicastresponsestomulticastbroadcast_true","displayName":"True","description":"Unicast Responses Blocked","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablefirewall","displayName":"Enable Private Network Firewall","description":"This value is an on/off switch for the firewall and advanced security enforcement. If this value is false, the server MUST NOT block any network traffic, regardless of other policy settings. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":" ","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogdroppedpackets","displayName":"Enable Log Dropped Packets","description":"This value is used as an on/off switch. If this value is on, the firewall logs all the dropped packets. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogdroppedpackets_false","displayName":"Disable Logging Of Dropped Packets","description":"Disable Logging Of Dropped Packets","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogdroppedpackets_true","displayName":"Enable Logging Of Dropped Packets","description":"Enable Logging Of Dropped Packets","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogignoredrules","displayName":"Enable Log Ignored Rules","description":"This value is used as an on/off switch. The server MAY use this value in an implementation-specific way to control logging of events if a rule is not enforced for any reason. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogignoredrules_false","displayName":"Disable Logging Of Ignored Rules","description":"Disable Logging Of Ignored Rules","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogignoredrules_true","displayName":"Enable Logging Of Ignored Rules","description":"Enable Logging Of Ignored Rules","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogsuccessconnections","displayName":"Enable Log Success Connections","description":"This value is used as an on/off switch. If this value is on, the firewall logs all successful inbound connections. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogsuccessconnections_false","displayName":"Disable Logging Of Successful Connections","description":"Disable Logging Of Successful Connections","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogsuccessconnections_true","displayName":"Enable Logging Of Successful Connections","description":"Enable Logging Of Successful Connections","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_globalportsallowuserprefmerge","displayName":"Global Ports Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, global port firewall rules in the local store are ignored and not enforced. The setting only has meaning if it is set or enumerated in the Group Policy store or if it is enumerated from the GroupPolicyRSoPStore. The merge law for this option is to let the value GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_globalportsallowuserprefmerge_false","displayName":"False","description":"GlobalPortsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_globalportsallowuserprefmerge_true","displayName":"True","description":"GlobalPortsAllowUserPrefMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_logfilepath","displayName":"Log File Path","description":"This value is a string that represents a file path to the log where the firewall logs dropped packets and successful connections. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_logmaxfilesize","displayName":"Log Max File Size","description":"This value specifies the size, in kilobytes, of the log file where dropped packets and successful connections are logged. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_shielded","displayName":"Shielded","description":"This value is used as an on/off switch. If this value is on and EnableFirewall is on, the server MUST block all incoming traffic regardless of other policy settings. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_shielded_false","displayName":"False","description":"Shielding Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_shielded_true","displayName":"True","description":"Shielding On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalipsecpolicymerge","displayName":"Allow Local Ipsec Policy Merge","description":"This value is an on/off switch. If this value is false, connection security rules from the local store are ignored and not enforced, regardless of the schema version and connection security rule version. The merge law for this option is to always use the value of the GroupPolicyRSoPStore.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalipsecpolicymerge_false","displayName":"False","description":"AllowLocalIpsecPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalipsecpolicymerge_true","displayName":"True","description":"AllowLocalIpsecPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, firewall rules from the local store are ignored and not enforced. The merge law for this option is to always use the value of the GroupPolicyRSoPStore. This value is valid for all schema versions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalpolicymerge_false","displayName":"False","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalpolicymerge_true","displayName":"True","description":"AllowLocalPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_authappsallowuserprefmerge","displayName":"Auth Apps Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, authorized application firewall rules in the local store are ignored and not enforced. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_authappsallowuserprefmerge_false","displayName":"False","description":"AuthAppsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_authappsallowuserprefmerge_true","displayName":"True","description":"AuthAppsAllowUserPrefMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultinboundaction","displayName":"Default Inbound Action for Public Profile","description":"Specifies how to filter inbound traffic. The acceptable values for this parameter are: NotConfigured, Allow, or Block.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultinboundaction_0","displayName":"Allow","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultinboundaction_1","displayName":"Block","description":"Block Inbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow]. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultoutboundaction_0","displayName":"Allow","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultoutboundaction_1","displayName":"Block","description":"Block Outbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disableinboundnotifications","displayName":"Disable Inbound Notifications","description":"This value is an on/off switch. If this value is false, the firewall MAY display a notification to the user when an application is blocked from listening on a port. If this value is on, the firewall MUST NOT display such a notification. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_disableinboundnotifications_false","displayName":"False","description":"Firewall May Display Notification","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disableinboundnotifications_true","displayName":"True","description":"Firewall Must Not Display Notification","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmode","displayName":"Disable Stealth Mode","description":"This value is an on/off switch. When this option is false, the server operates in stealth mode. The firewall rules used to enforce stealth mode are implementation-specific. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmode_false","displayName":"False","description":"Use Stealth Mode","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmode_true","displayName":"True","description":"Disable Stealth Mode","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmodeipsecsecuredpacketexemption","displayName":"Disable Stealth Mode Ipsec Secured Packet Exemption","description":"This value is an on/off switch. This option is ignored if DisableStealthMode is on. Otherwise, when this option is true, the firewall's stealth mode rules MUST NOT prevent the host computer from responding to unsolicited network traffic if that traffic is secured by IPsec. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used. For schema versions 0x0200, 0x0201, and 0x020A, this value is invalid and MUST NOT be used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmodeipsecsecuredpacketexemption_false","displayName":"False","description":"FALSE","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmodeipsecsecuredpacketexemption_true","displayName":"True","description":"TRUE","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disableunicastresponsestomulticastbroadcast","displayName":"Disable Unicast Responses To Multicast Broadcast","description":"This value is used as an on/off switch. If it is true, unicast responses to multicast broadcast traffic is blocked. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_disableunicastresponsestomulticastbroadcast_false","displayName":"False","description":"Unicast Responses Not Blocked","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disableunicastresponsestomulticastbroadcast_true","displayName":"True","description":"Unicast Responses Blocked","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablefirewall","displayName":"Enable Public Network Firewall","description":"This value is an on/off switch for the firewall and advanced security enforcement. If this value is false, the server MUST NOT block any network traffic, regardless of other policy settings. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":" ","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogdroppedpackets","displayName":"Enable Log Dropped Packets","description":"This value is used as an on/off switch. If this value is on, the firewall logs all the dropped packets. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogdroppedpackets_false","displayName":"Disable Logging Of Dropped Packets","description":"Disable Logging Of Dropped Packets","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogdroppedpackets_true","displayName":"Enable Logging Of Dropped Packets","description":"Enable Logging Of Dropped Packets","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogignoredrules","displayName":"Enable Log Ignored Rules","description":"This value is used as an on/off switch. The server MAY use this value in an implementation-specific way to control logging of events if a rule is not enforced for any reason. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogignoredrules_false","displayName":"Disable Logging Of Ignored Rules","description":"Disable Logging Of Ignored Rules","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogignoredrules_true","displayName":"Enable Logging Of Ignored Rules","description":"Enable Logging Of Ignored Rules","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogsuccessconnections","displayName":"Enable Log Success Connections","description":"This value is used as an on/off switch. If this value is on, the firewall logs all successful inbound connections. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogsuccessconnections_false","displayName":"Disable Logging Of Successful Connections","description":"Disable Logging Of Successful Connections","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogsuccessconnections_true","displayName":"Enable Logging Of Successful Connections","description":"Enable Logging Of Successful Connections","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_globalportsallowuserprefmerge","displayName":"Global Ports Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, global port firewall rules in the local store are ignored and not enforced. The setting only has meaning if it is set or enumerated in the Group Policy store or if it is enumerated from the GroupPolicyRSoPStore. The merge law for this option is to let the value GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_globalportsallowuserprefmerge_false","displayName":"False","description":"GlobalPortsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_globalportsallowuserprefmerge_true","displayName":"True","description":"GlobalPortsAllowUserPrefMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_logfilepath","displayName":"Log File Path","description":"This value is a string that represents a file path to the log where the firewall logs dropped packets and successful connections. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_logmaxfilesize","displayName":"Log Max File Size","description":"This value specifies the size, in kilobytes, of the log file where dropped packets and successful connections are logged. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_shielded","displayName":"Shielded","description":"This value is used as an on/off switch. If this value is on and EnableFirewall is on, the server MUST block all incoming traffic regardless of other policy settings. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_shielded_false","displayName":"False","description":"Shielding Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_shielded_true","displayName":"True","description":"Shielding On","helpText":null}]},{"id":"vendor_msft_personalization_companylogourl","displayName":"Company Logo Url","description":"A http or https Url to a jpg, jpeg or png image that neeeds to be downloaded and used as the Company Logo or a file Url to a local image on the file system that needs to be used as the Company Logo. This setting is currently available for boot to cloud shared pc mode only.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Personalization-csp/"],"categoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","categoryName":"Personalization","options":null},{"id":"vendor_msft_personalization_companyname","displayName":"Company Name","description":"The name of the company to be displayed on the sign-in screen. This setting is currently available for boot to cloud shared pc mode only.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Personalization-csp/"],"categoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","categoryName":"Personalization","options":null},{"id":"vendor_msft_personalization_desktopimageurl","displayName":"Desktop Image Url","description":"A http or https Url to a jpg, jpeg or png image that needs to be downloaded and used as the Desktop Image or a file Url to a local image on the file system that needs to be used as the Desktop Image.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Personalization-csp/"],"categoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","categoryName":"Personalization","options":null},{"id":"vendor_msft_personalization_lockscreenimageurl","displayName":"Lock Screen Image Url","description":"A http or https Url to a jpg, jpeg or png image that neeeds to be downloaded and used as the Lock Screen Image or a file Url to a local image on the file system that needs to be used as the Lock Screen Image.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Personalization-csp/"],"categoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","categoryName":"Personalization","options":null},{"id":"vendor_msft_sharedpc_accountmodel","displayName":"Account Model","description":"Configures which type of accounts are allowed to use the PC. Allowed values: 0 (only guest), 1 (domain-joined only), 2 (domain-joined and guest). If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_accountmodel_0","displayName":"Guest","description":"Only guest accounts are allowed.","helpText":null},{"id":"vendor_msft_sharedpc_accountmodel_1","displayName":"Domain","description":"Only domain-joined accounts are allowed.","helpText":null},{"id":"vendor_msft_sharedpc_accountmodel_2","displayName":"Guest and Domain","description":"Domain-joined and guest accounts are allowed.","helpText":null}]},{"id":"vendor_msft_sharedpc_deletionpolicy","displayName":"Deletion Policy","description":"Configures when accounts will be deleted. Allowed values: 0 (delete immediately), 1 (delete at disk space threshold), 2 (Delete at disk space threshold and inactive threshold). If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_deletionpolicy_0","displayName":"Delete immediately","description":"Delete immediately.","helpText":null},{"id":"vendor_msft_sharedpc_deletionpolicy_1","displayName":"Delete at disk space threshold","description":"Delete at disk space threshold","helpText":null},{"id":"vendor_msft_sharedpc_deletionpolicy_2","displayName":"Delete at disk space threshold and inactive threshold","description":"Delete at disk space threshold and inactive threshold","helpText":null}]},{"id":"vendor_msft_sharedpc_disklevelcaching","displayName":"Disk Level Caching","description":"Stop deleting accounts when available disk space reaches this threshold, given as percent of total disk capacity. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_diskleveldeletion","displayName":"Disk Level Deletion","description":"Accounts will start being deleted when available disk space falls below this threshold, given as percent of total disk capacity. Accounts that have been inactive the longest will be deleted first. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_enableaccountmanager","displayName":"Enable Account Manager","description":"Enable the account manager for shared PC mode. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_enableaccountmanager_false","displayName":"false","description":"False","helpText":null},{"id":"vendor_msft_sharedpc_enableaccountmanager_true","displayName":"true","description":"True","helpText":null}]},{"id":"vendor_msft_sharedpc_enablesharedpcmode","displayName":"Enable Shared PC Mode","description":"Setting this node to \"true\" triggers the action to configure a device to Shared PC mode.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_enablesharedpcmode_false","displayName":"false","description":"Not configured","helpText":null},{"id":"vendor_msft_sharedpc_enablesharedpcmode_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"vendor_msft_sharedpc_enablesharedpcmodewithonedrivesync","displayName":"Enable Shared PC Mode With One Drive Sync","description":"Setting this node to “1” triggers the action to configure a device to Shared PC mode with OneDrive sync turned on","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/SharedPC-csp/"],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_enablesharedpcmodewithonedrivesync_false","displayName":"Not configured","description":"Not configured","helpText":null},{"id":"vendor_msft_sharedpc_enablesharedpcmodewithonedrivesync_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"vendor_msft_sharedpc_inactivethreshold","displayName":"Inactive Threshold","description":"Accounts will start being deleted when they have not been logged on during the specified period, given as number of days.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_kioskmodeaumid","displayName":"Kiosk Mode AUMID","description":"Specifies the AUMID of the app to use with assigned access. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_kioskmodeusertiledisplaytext","displayName":"Kiosk Mode User Tile Display Text","description":"Specifies the display text for the account shown on the sign-in screen which launches the app specified by KioskModeAUMID. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_maintenancestarttime","displayName":"Maintenance Start Time","description":"Daily start time of maintenance hour. Given in minutes from midnight. Default is 0 (12am). If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_maxpagefilesizemb","displayName":"Max Page File Size MB","description":"Maximum size of the paging file in MB. Applies only to systems with less than 32 GB storage and at least 3 GB of RAM. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/SharedPC-csp/"],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_restrictlocalstorage","displayName":"Restrict Local Storage","description":"Restricts the user from using local storage. This node is optional. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_restrictlocalstorage_false","displayName":"false","description":"False","helpText":null},{"id":"vendor_msft_sharedpc_restrictlocalstorage_true","displayName":"true","description":"True","helpText":null}]},{"id":"vendor_msft_sharedpc_setedupolicies","displayName":"Set Edu Policies","description":"Set a list of EDU policies.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_setedupolicies_false","displayName":"false","description":"Not configured","helpText":null},{"id":"vendor_msft_sharedpc_setedupolicies_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"vendor_msft_sharedpc_setpowerpolicies","displayName":"Set Power Policies","description":"Set a list of power policies. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_setpowerpolicies_false","displayName":"false","description":"Not configured","helpText":null},{"id":"vendor_msft_sharedpc_setpowerpolicies_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"vendor_msft_sharedpc_signinonresume","displayName":"Sign In On Resume","description":"Require signing in on waking up from sleep. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_signinonresume_false","displayName":"false","description":"False","helpText":null},{"id":"vendor_msft_sharedpc_signinonresume_true","displayName":"true","description":"True","helpText":null}]},{"id":"vendor_msft_sharedpc_sleeptimeout","displayName":"Sleep Timeout","description":"The amount of time before the PC sleeps, giving in seconds. 0 means the PC never sleeps. Default is 5 minutes. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/SharedPC-csp/"],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_tenantlockdown_requirenetworkinoobe","displayName":"Require Network In OOBE (Device)","description":"true - Require network in OOBE, false - no network connection requirement in OOBE","helpText":null,"infoUrls":[],"categoryId":"c4ce54b8-e555-4447-9791-dd8e9dbb86b0","categoryName":"Tenant Lockdown","options":[{"id":"vendor_msft_tenantlockdown_requirenetworkinoobe_true","displayName":"true","description":null,"helpText":null},{"id":"vendor_msft_tenantlockdown_requirenetworkinoobe_false","displayName":"false","description":null,"helpText":null}]},{"id":"vendor_msft_windowslicensing_devicelicensingservice_licensetype","displayName":"License Type","description":"Get/Replace License Type: User Based License = 0, Device Based License = 1\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WindowsLicensing-csp/"],"categoryId":"f8a973d8-b5d6-4d3e-9e82-63f61107fd0c","categoryName":"Windows Licensing","options":[{"id":"vendor_msft_windowslicensing_devicelicensingservice_licensetype_0","displayName":"User Based License","description":"User Based License","helpText":null},{"id":"vendor_msft_windowslicensing_devicelicensingservice_licensetype_1","displayName":"Device Based License","description":"Device Based License","helpText":null}]},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}","displayName":" Connection Profile ID (Windows Insiders only)","description":"Unique identifier of a network preference policy. Unique ID is auto-generated.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":[],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_cellular_plmnid","displayName":"PLMNID (Windows Insiders only)","description":"5- or 6-digit string identifying a cellular network. It consists of the combination of Mobile Country Code (MCC) and Mobile Network Code (MNC). \r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_connectionprofileid","displayName":null,"description":null,"helpText":null,"infoUrls":[],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_priority","displayName":"Priority (Windows Insiders only)","description":"Priority of a policy compared to the others where 1 represents the highest priority. Thus, the smaller this value is, the higher preference this specific network will receive in establishing a data connection. \r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_stayconnected","displayName":"Stay Connected (Windows Insiders only)","description":"When set to 0: Default network discovery behavior is applied. When set to 1: Once connected, the device will always stay connected to this network. This means the device will not attempt to discover or switch to other higher priority networks until it first loses connectivity to this network.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":[{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_stayconnected_0","displayName":"Default network discovery behavior.","description":"Default network discovery behavior.","helpText":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_stayconnected_1","displayName":"Once connected to this network, try to stay connected.","description":"Once connected to this network, try to stay connected.","helpText":null}]},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_wirelesstype","displayName":"Wireless Type (Windows Insiders only)","description":"Type of wireless network (either Cellular or Wi-Fi). 0 represents Cellular, and 1 represents Wi-Fi. Currently only cellular is supported.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":[{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_wirelesstype_0","displayName":"Cellular","description":"Cellular","helpText":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_wirelesstype_1","displayName":"Wi- Fi","description":"Wi-Fi","helpText":null}]},{"id":"vendor_msft_wirelessnetworkpreference_isenabled","displayName":"Is Enabled (Windows Insiders only)","description":"It determines whether the wireless connectivity management policy is enabled or not.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":[{"id":"vendor_msft_wirelessnetworkpreference_isenabled_false","displayName":"Disable the wireless management policy.","description":"Disable the wireless management policy.","helpText":null},{"id":"vendor_msft_wirelessnetworkpreference_isenabled_true","displayName":"Enable the wireless management policy.","description":"Enable the wireless management policy.","helpText":null}]},{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_maxrescanintervalinseconds","displayName":"Max Rescan Interval In Seconds (Windows Insiders only)","description":"Maximum time (in seconds) from the point that no connection could be established using the permissible eSIM profiles on the device to the start of the next round of network discovery attempts. A smaller interval increases network discovery frequency and can decrease battery life significantly. A value of 0 means that the device is to pick a reasonable interval per its own discretion.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_networkdiscoveryoption","displayName":"Network Discovery Option (Windows Insiders only)","description":"Configures which approach should be used in the network discovery process. There are two possible values: (0) no network scan will be performed – rather, registration and connection will be attempted with each eSIM profile in descending order of preference; or (1) Network scan will be performed using the current active eSIM profile. This option works for modems that when performing a network scan show the complete list of available networks independently of which eSIM profile is active.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":[{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_networkdiscoveryoption_0","displayName":"No network scan will be performed -- rather, registration and connection will be attempted with each eSIM profile in descending order of preference.","description":"No network scan will be performed -- rather, registration and connection will be attempted with each eSIM profile in descending order of preference.","helpText":null},{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_networkdiscoveryoption_1","displayName":"Network scan will be performed using the current active eSIM profile.","description":"Network scan will be performed using the current active eSIM profile.","helpText":null}]},{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_preferredprofilewakeconnectiontimerinseconds","displayName":"Preferred Profile Wake Connection Timer In Seconds (Windows Insiders only)","description":"When the device is woken from sleep with the most-preferred profile already enabled, this value configures the amount of time (in seconds) before the agent will give up on waiting for connection re-establishment with the most-preferred profile and start network discovery.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_profileregistrationtimerinseconds","displayName":"Profile Registration Timer In Seconds (Windows Insiders only)","description":"When evaluating eSIM profiles for connectivity, this value configures the amount of time (in seconds) that the agent will wait for network registration before considering this profile unsatisfactory and moving on to the next one.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_screenoffdurationtotriggernetworkdiscoveryinminutes","displayName":"Screen Off Duration To Trigger Network Discovery In Minutes (Windows Insiders only)","description":"When the device experiences screen off and back on, this value configures the minimum duration (in minutes) of the screen off period that will trigger network discovery.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_prefercellularoverwifi","displayName":"Prefer Cellular Over Wi Fi (Windows Insiders only)","description":"It determines the order of preference between Wi-Fi and cellular networks. When the value is set to “False”, Wi-Fi is preferred over cellular. When the value is set to “True”, cellular is preferred over Wi-Fi. \r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":[{"id":"vendor_msft_wirelessnetworkpreference_prefercellularoverwifi_false","displayName":"Prefer Wi-Fi over Cellular.","description":"Prefer Wi-Fi over Cellular.","helpText":null},{"id":"vendor_msft_wirelessnetworkpreference_prefercellularoverwifi_true","displayName":"Prefer Cellular over Wi-Fi.","description":"Prefer Cellular over Wi-Fi.","helpText":null}]}] +[{"id":".globalpreferences_.globalpreferences","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"1829cdc1-1bed-4058-9aba-9b778cd3d955","categoryName":"Global Preferences","options":null},{"id":".globalpreferences_com.apple.autologout.autologoutdelay","displayName":"Auto Log Out Delay","description":"The autologout delay, in seconds. A value of 0 means autologout is off. In some cases, this delay may be restricted to values between 5 minutes and 24 hours.","helpText":null,"infoUrls":[],"categoryId":"1829cdc1-1bed-4058-9aba-9b778cd3d955","categoryName":"Global Preferences","options":null},{"id":".globalpreferences_multiplesessionenabled","displayName":"Multiple Session Enabled","description":"If false, disables fast user switching.","helpText":null,"infoUrls":[],"categoryId":"1829cdc1-1bed-4058-9aba-9b778cd3d955","categoryName":"Global Preferences","options":[{"id":".globalpreferences_multiplesessionenabled_false","displayName":"False","description":null,"helpText":null},{"id":".globalpreferences_multiplesessionenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetversionprefixmicrosoftedge","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetversionprefixmicrosoftedge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetversionprefixmicrosoftedge_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetversionprefixmicrosoftedge_part_targetversionprefix","displayName":"Target version (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","categoryName":"Microsoft Edge Beta","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta_part_targetversionprefix","displayName":"Target version (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","categoryName":"Microsoft Edge Beta","options":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary_part_targetversionprefix","displayName":"Target version (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"13f62499-a266-42c8-a4dc-531efcea55cb","categoryName":"Microsoft Edge Dev","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev_part_targetversionprefix","displayName":"Target version (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"13f62499-a266-42c8-a4dc-531efcea55cb","categoryName":"Microsoft Edge Dev","options":null},{"id":"3~policy~microsoft_edge_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 102.\r\n\r\nIf you enable this policy or leave it unset, the window.opener property is set to null unless the anchor specifies rel=\"opener\".\r\n\r\nIf you disable this policy, popups that target _blank are permitted to access (via JavaScript) the page that requested to open the popup.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"3~policy~microsoft_edge_targetblankimpliesnoopener_0","displayName":"Disabled","description":null,"helpText":null},{"id":"3~policy~microsoft_edge_targetblankimpliesnoopener_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"3~policy~microsoft_edge~httpauthentication_basicauthoverhttpenabled","displayName":"Allow Basic authentication for HTTP (User)","description":"If you enable this policy or leave it unset, Basic authentication challenges received over non-secure HTTP will be allowed.\r\n\r\nIf you disable this policy, non-secure HTTP requests from the Basic authentication scheme are blocked, and only secure HTTPS is allowed.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"3~policy~microsoft_edge~httpauthentication_basicauthoverhttpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"3~policy~microsoft_edge~httpauthentication_basicauthoverhttpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"ade_accountsettings_adminaccountfullname","displayName":"Admin account full name","description":"The full name for the administrator account. This field is to be defaulted to 'Admin'.","helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},{"id":"ade_accountsettings_adminaccountname","displayName":"Admin account username","description":"The account name for the administrator account. This field is to be defaulted to 'Admin'. For macOS ADE enrollment policies without user device affinity, we recommend configuring {{serialNumber}} as the unique identifier of userless devices.","helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},{"id":"ade_accountsettings_adminaccountpasswordrotation","displayName":"Admin account password rotation period (days)","description":null,"helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},{"id":"ade_accountsettings_createlocaladmin","displayName":"Create a local admin account","description":null,"helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_createlocaladmin_0","displayName":"No","description":null,"helpText":null},{"id":"ade_accountsettings_createlocaladmin_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_accountsettings_createlocalprimary","displayName":"Create a local primary account","description":null,"helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_createlocalprimary_0","displayName":"No","description":null,"helpText":null},{"id":"ade_accountsettings_createlocalprimary_1","displayName":"Yes - Standard Account Type","description":null,"helpText":null},{"id":"ade_accountsettings_createlocalprimary_2","displayName":"Yes - Administrator Account Type","description":null,"helpText":null}]},{"id":"ade_accountsettings_hideusersgroups","displayName":"Hide in Users and Groups","description":"Make the admin account hidden in the login window and Users & Groups.","helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_hideusersgroups_0","displayName":"Not Configured","description":null,"helpText":null},{"id":"ade_accountsettings_hideusersgroups_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_accountsettings_prefillaccountinfo","displayName":"Prefill account info","description":"If you select 'Yes', the account name and full name must be configured. Not configured allows the end user to configure these fields.","helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_prefillaccountinfo_0","displayName":"Not Configured","description":null,"helpText":null},{"id":"ade_accountsettings_prefillaccountinfo_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_accountsettings_primaryaccountfullname","displayName":"Primary account full name","description":"The full name for the account. Setup Assistant will user this value to prefill the Full Name field if 'Prefill account info' is set to 'Not configured'. This field is to be defaulted to the variable, {{username}}, for example, 'John Doe'.","helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},{"id":"ade_accountsettings_primaryaccountname","displayName":"Primary account name","description":"The account name for the account. Setup Assistant will use this value to prefill the Account Name field if 'Prefill account info' is set to 'Not configured'. This field is to be defaulted to the variable, {{partialupn}}, for example, 'John'. For macOS ADE enrollment policies without user device affinity, we recommend configuring {{serialNumber}} as the unique identifier of userless devices.","helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},{"id":"ade_accountsettings_restrictediting","displayName":"Restrict editing","description":"Prevent the end user from editing the full name and account name","helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_restrictediting_0","displayName":"Not configured","description":null,"helpText":null},{"id":"ade_accountsettings_restrictediting_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_activatecellulardata","displayName":"Carrier activation server URL","description":"","helpText":"http://activation.carrier.net","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_activatecellulardatachoices","displayName":"Activate cellular data","description":"Activates cellular data plans for devices enabled for eSIM. The carrier must enable activation for devices before you can use this command. You can also activate any time after device enrollment.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_activatecellulardatachoices_0","displayName":"No","description":null,"helpText":null},{"id":"ade_activatecellulardatachoices_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_appleconfiguratorcertificates","displayName":"Apple Configurator certificates","description":"Required to sync data with a supervised device. Make sure you save a local copy of the certificate that you can access later. You won't be able to make changes to the uploaded copy.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_appledevicenametemplate","displayName":"Device name template","description":"Create a unique name for your devices. Names must be 63 characters or less, and can contain letters (a-z, A-Z), numbers (0-9), and hyphens.Variables supported: {{SERIAL}}, {{DEVICETYPE}}","helpText":"{{DEVICETYPE}}-{{SERIAL}}","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_authenticationmethod","displayName":"Intune authentication method","description":"If your organization uses multifactor authentication, select Setup Assistant with modern authentication, which prompts users to authenticate based on settings in Entra.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":{"id":"ade_authenticationmethod_2","displayName":"Setup Assistant with modern authentication","description":null,"helpText":null}},{"id":"ade_awaitconfiguration_basic","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_awaitconfiguration_basic_0","displayName":"No","description":null,"helpText":null},{"id":"ade_awaitconfiguration_basic_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_devicenametemplatechoices","displayName":"Apple device name template","description":"You can create a standard naming format to make it easier to name devices as they enroll in Intune. By default, Apple uses the device type (such as iPad or iPhone) and serial number to name ADE devices.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_devicenametemplatechoices_0","displayName":"No","description":null,"helpText":null},{"id":"ade_devicenametemplatechoices_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_lockedenrollment","displayName":"Locked enrollment","description":"Blocks the user from removing the management profile through the Settings menu.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_lockedenrollment_0","displayName":"No","description":null,"helpText":null},{"id":"ade_lockedenrollment_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_macos_authenticationmethod","displayName":"Intune authentication method","description":"If your organization uses multifactor authentication, select Setup Assistant with modern authentication, which prompts users to authenticate based on settings in Entra.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":{"id":"ade_macos_authenticationmethod_2","displayName":"Setup Assistant with modern authentication","description":null,"helpText":null}},{"id":"ade_macos_awaitconfiguration","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_macos_awaitconfiguration_0","displayName":"No","description":null,"helpText":null},{"id":"ade_macos_awaitconfiguration_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_macos_useraffinity","displayName":"User affinity","description":"User affinity associates devices with users. Users must authenticate to enroll with user affinity.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_macos_useraffinity_1","displayName":"Enroll with user affinity","description":null,"helpText":null},{"id":"ade_macos_useraffinity_0","displayName":"Enroll without user affinity","description":null,"helpText":null}]},{"id":"ade_maximumcachedusers","displayName":"Maximum cached users","description":"The maximum number of users that can use a Shared iPad. You can cache up to 24 users on a 32GB or 64GB device.","helpText":null,"infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_maximumsecondsafterscreenlockbeofrepasswordisrequired","displayName":"Maximum seconds after screen lock before password is required","description":"Available for Shared iPads. Maximum seconds after screen lock before password is required (0-14,400 seconds). If a device has a passcode, a change to a larger value doesn’t take effect until the user logs out or removes the passcode.","helpText":"Enter value","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_maximumsecondsinactivityuntiltemporarysessionlogsout","displayName":"Maximum seconds of inactivity until temporary session logs out","description":"Available for devices running iPadOS versions 14.5 and later. Enter a value in seconds (minimum value to add is 30 seconds). If there isn't any activity after the value you enter, then the temporary session automatically signs out. If you set the value to anything between 0-29, then the temporary session stays signed in. ","helpText":"Enter value","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_maximumsecondsinactivityuntiluserlogsout","displayName":"Maximum seconds of inactivity until user session logs out","description":"Available for devices running iPadOS versions 14.5 and later. Enter a value in seconds (minimum value to add is 30 seconds). If there isn't any activity after the value you enter, the user session automatically signs out. If you set the value to anything between 0-29, then the user session stays signed in.","helpText":"Enter value","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":null},{"id":"ade_modernauth_awaitfinalconfiguration","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_modernauth_awaitfinalconfiguration_0","displayName":"No","description":null,"helpText":null},{"id":"ade_modernauth_awaitfinalconfiguration_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_requiresharedipadtemporarysessiononly","displayName":"Require Shared iPad temporary session only","description":"Available for devices running iPadOS versions 14.5 and later. When set to Yes, users only see the Guest Welcome pane, and can only sign in as a guest user. Users can't sign in with a Managed Apple ID.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_requiresharedipadtemporarysessiononly_0","displayName":"Not configured","description":null,"helpText":null},{"id":"ade_requiresharedipadtemporarysessiononly_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_setupassistant_accessibility","displayName":"Accessibility","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_accessibility_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_accessibility_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_accessibilityappearance","displayName":"Accessibility appearance","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_accessibilityappearance_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_accessibilityappearance_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_actionbutton","displayName":"Action Button","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_actionbutton_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_actionbutton_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_androidmigration","displayName":"Android migration","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_androidmigration_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_androidmigration_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_appearance","displayName":"Appearance","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_appearance_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_appearance_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_appleid","displayName":"Apple ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_appleid_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_appleid_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_applepay","displayName":"Apple Pay","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_applepay_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_applepay_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_appstore","displayName":"App Store","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_appstore_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_appstore_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_camerabutton","displayName":"Camera button","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_camerabutton_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_camerabutton_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_department","displayName":"Department","description":null,"helpText":"Appears to users on About Configuration screen","infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":null},{"id":"ade_setupassistant_departmentphone","displayName":"Department phone","description":null,"helpText":"Appears to users on About Configuration screen","infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":null},{"id":"ade_setupassistant_devicemigration","displayName":"Device to device migration","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_devicemigration_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_devicemigration_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_diagnosticsdata","displayName":"Diagnostics Data","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_diagnosticsdata_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_diagnosticsdata_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_enablelockdownmode","displayName":"Enable Lock down Mode","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_enablelockdownmode_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_enablelockdownmode_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_filevault","displayName":"FileVault","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_filevault_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_filevault_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_getstarted","displayName":"Get Started","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_getstarted_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_getstarted_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_iclouddiagnostics","displayName":"iCloud Diagnostics","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_iclouddiagnostics_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_iclouddiagnostics_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_icloudstorage","displayName":"iCloud Storage","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_icloudstorage_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_icloudstorage_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_imessagefacetime","displayName":"iMessage and FaceTime","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_imessagefacetime_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_imessagefacetime_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_intelligence","displayName":"Intelligence","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_intelligence_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_intelligence_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_liquidglass","displayName":"Liquid Glass","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_liquidglass_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_liquidglass_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_locationservices","displayName":"Location services","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_locationservices_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_locationservices_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_multitasking","displayName":"Multitasking","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_multitasking_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_multitasking_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_osshowcase","displayName":"OS showcase","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_osshowcase_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_osshowcase_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_passcode","displayName":"Passcode","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_passcode_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_passcode_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_privacy","displayName":"Privacy","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_privacy_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_privacy_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_restore","displayName":"Restore","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_restore_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_restore_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_restorecompleted","displayName":"Restore completed","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_restorecompleted_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_restorecompleted_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_safety","displayName":"Emergency SOS","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_safety_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_safety_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_safetyandhandling","displayName":"Safety and handling","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_safetyandhandling_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_safetyandhandling_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_screensaver","displayName":"Screen Saver","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_screensaver_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_screensaver_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_screentime","displayName":"Screen Time","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_screentime_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_screentime_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_simsetup","displayName":"SIM setup","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_simsetup_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_simsetup_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_siri","displayName":"Siri","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_siri_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_siri_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_softwareupdate","displayName":"Software Update","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_softwareupdate_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_softwareupdate_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_softwareupdatecompleted","displayName":"Software Update completed","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_softwareupdatecompleted_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_softwareupdatecompleted_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_taptosetup","displayName":"Tap to Setup","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_taptosetup_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_taptosetup_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_termsandconditions","displayName":"Terms and conditions","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_termsandconditions_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_termsandconditions_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_termsofaddress","displayName":"Terms of Address","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_termsofaddress_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_termsofaddress_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_tips","displayName":"Tips","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_tips_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_tips_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_touchfaceid","displayName":"Touch ID and Face ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_touchfaceid_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_touchfaceid_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_tvhomescreensync","displayName":"TV Home Screen Sync","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_tvhomescreensync_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_tvhomescreensync_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_tvprovidersignin","displayName":"TV Provider Sign In","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_tvprovidersignin_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_tvprovidersignin_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_tvroom","displayName":"TV Room","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_tvroom_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_tvroom_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_unlockwithwatch","displayName":"Auto unlock with Apple Watch","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_unlockwithwatch_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_unlockwithwatch_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_voiceselection","displayName":"Voice selection","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_voiceselection_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_voiceselection_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_watchmigration","displayName":"Watch migration","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_watchmigration_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_watchmigration_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_setupassistant_webcontentfiltering","displayName":"Web Content Filtering","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_webcontentfiltering_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_webcontentfiltering_1","displayName":"Show","description":null,"helpText":null}]},{"id":"ade_useraffinity","displayName":"User affinity","description":"User affinity associates devices with users. Users must authenticate to enroll with user affinity.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_useraffinity_1","displayName":"Enroll with user affinity","description":null,"helpText":null},{"id":"ade_useraffinity_0","displayName":"Enroll without user affinity","description":null,"helpText":null},{"id":"ade_useraffinity_2","displayName":"Enroll with Microsoft Entra ID shared mode","description":null,"helpText":null},{"id":"ade_useraffinity_3","displayName":"Enroll with Shared iPad","description":null,"helpText":null}]},{"id":"ade_useraffinity_awaitfinalconfiguration","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_useraffinity_awaitfinalconfiguration_0","displayName":"No","description":null,"helpText":null},{"id":"ade_useraffinity_awaitfinalconfiguration_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"ade_useraffinitybasic","displayName":"User affinity","description":"User affinity associates devices with users. Users must authenticate to enroll with user affinity.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":{"id":"ade_useraffinitybasic_0","displayName":"Enroll without user affinity","description":null,"helpText":null}},{"id":"app_allowed","displayName":"Allowed","description":"The dictionary of allowed app settings.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_allowedapps","displayName":"Allowed Apps","description":"If present, the device only shows or launches apps with bundle IDs in the array. Include the value `com.apple.webapp` to allow all webclips. This applies to App Store apps, marketplace apps, and locally installed apps (using Configurator, Xcode, and so forth).","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_allowedbinaries","displayName":"Allowed Binaries","description":"If present, the device only allows binaries that match the binary identifier properties to run. A binary only matches when all the binary identifiers match. The device always runs system critical processes. Use \"codesign -dvvv \" to show the information you need to generate these values.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_allowedbinaries_item_cdhash","displayName":"CD Hash","description":"The code signature code directory hash of the binary.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_allowedbinaries_item_pathprefix","displayName":"Path Prefix","description":"The file system path prefix to match binaries.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_allowedbinaries_item_signingid","displayName":"Signing ID","description":"The code signature signing identifier of the binary.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_allowedbinaries_item_signingstate","displayName":"Signing State","description":"The code signing state to match binaries.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_allowed_allowedbinaries_item_signingstate_0","displayName":"All","description":null,"helpText":null},{"id":"app_allowed_allowedbinaries_item_signingstate_1","displayName":"TestFlight","description":null,"helpText":null},{"id":"app_allowed_allowedbinaries_item_signingstate_2","displayName":"DeveloperID","description":null,"helpText":null},{"id":"app_allowed_allowedbinaries_item_signingstate_3","displayName":"Enterprise","description":null,"helpText":null},{"id":"app_allowed_allowedbinaries_item_signingstate_4","displayName":"AppStore","description":null,"helpText":null},{"id":"app_allowed_allowedbinaries_item_signingstate_5","displayName":"Apple","description":null,"helpText":null}]},{"id":"app_allowed_allowedbinaries_item_teamid","displayName":"Team ID","description":"The code signature team identifier of the binary. Use the value \"*APPLE*\" instead of an empty string for Apple binaries with an empty team identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_alwaysallowmanagedapps","displayName":"Always Allow Managed Apps","description":"If `true`, the device implicitly includes managed apps in the effective allow list when `AllowedApps` or `AllowedBinaries` is present.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_allowed_alwaysallowmanagedapps_false","displayName":"Blocked","description":null,"helpText":null},{"id":"app_allowed_alwaysallowmanagedapps_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"app_allowed_deniedapps","displayName":"Denied Apps","description":"If present, the device prevents showing or launching apps with bundle IDs in the\narray. Include the value `com.apple.webapp` to restrict all webclips. This applies to\nApp Store apps, marketplace apps, and locally installed apps (using Configurator,\nXcode, and so forth).\n> Note:\n> Denying system apps may disable other functionality. For example, denying the App\nStore app may prevent users from accepting the terms and conditions for the user-based\nVolume Purchase Program (VPP).","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_deniedbinaries","displayName":"Denied Binaries","description":"If present, the device doesn't allow binaries that match the binary identifier properties to run. A binary only matches when all the binary identifiers match.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_deniedbinaries_item_cdhash","displayName":"CD Hash","description":"The code signature code directory hash of the binary.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_deniedbinaries_item_pathprefix","displayName":"Path Prefix","description":"The file system path prefix to match binaries.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_deniedbinaries_item_signingid","displayName":"Signing ID","description":"The code signature signing identifier of the binary.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_allowed_deniedbinaries_item_signingstate","displayName":"Signing State","description":"The code signing state to match binaries.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_allowed_deniedbinaries_item_signingstate_0","displayName":"All","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_1","displayName":"TestFlight","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_2","displayName":"DeveloperID","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_3","displayName":"Enterprise","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_4","displayName":"AppStore","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_5","displayName":"Apple","description":null,"helpText":null}]},{"id":"app_allowed_deniedbinaries_item_teamid","displayName":"Team ID","description":"The code signature team identifier of the binary. Use the value \"*APPLE*\" instead of an empty string for Apple binaries with an empty team identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_app","displayName":"com.apple.configuration.app.settings","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_privacy","displayName":"Privacy","description":"The dictionary of app settings.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_privacy_permissiondefaults","displayName":"Permission Defaults","description":"The dictionary of app privacy permission defaults. Each key in the dictionary is an app identifier. The dictionary values represent the permission defaults that the device applies for each matching app.\n\nIn iOS, the app identifier is a bundle ID, for example, \"com.example.app\".\n\nIn macOS, the app identifier is a composed identifier. The format of the composed identifier is either \"Bundle-ID\", \"Bundle-ID (Team-ID)\", or \"Bundle-ID {Designated-Requirement}\". \"Bundle-ID\" is the bundle identifier string of the app. \"Team-ID\" is the team identifier from the app's code signature. \"Designated-Requirement\" is the designated requirement string from the code signature of the app. For example, \"com.example.app\" for the bundle ID format, \"com.example.app (ABCD1234)\" for the team ID format, or \"com.example.app {anchor apple generic}\" for the designated requirement format. The device only applies defaults for an app if its code signature matches the composed identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_privacy_permissiondefaults_generickey","displayName":"ANY","description":"The dictionary that defines the app privacy permission defaults. Each key is an app identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_privacy_permissiondefaults_generickey_accessibility","displayName":"Accessibility","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of accessibility.\n* `Allow`: The app privacy permission default is set to allow use of accessibility.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_accessibility_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_accessibility_1","displayName":"Allow","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_bluetooth","displayName":"Bluetooth","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of Bluetooth.\n* `Allow`: The app privacy permission default is set to allow use of Bluetooth.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_bluetooth_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_bluetooth_1","displayName":"Allow","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_camera","displayName":"Camera","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of the camera.\n* `Allow`: The app privacy permission default is set to allow use of the camera.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_camera_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_camera_1","displayName":"Allow","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_dictation","displayName":"Dictation","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of dictation.\n* `Allow`: The app privacy permission default is set to allow use of dictation.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_dictation_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_dictation_1","displayName":"Allow","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_keytobereplaced","displayName":"Permission Defaults","description":"The dictionary of app privacy permission defaults. Each key in the dictionary is an app identifier. The dictionary values represent the permission defaults that the device applies for each matching app.\n\nIn iOS, the app identifier is a bundle ID, for example, \"com.example.app\".\n\nIn macOS, the app identifier is a composed identifier. The format of the composed identifier is either \"Bundle-ID\", \"Bundle-ID (Team-ID)\", or \"Bundle-ID {Designated-Requirement}\". \"Bundle-ID\" is the bundle identifier string of the app. \"Team-ID\" is the team identifier from the app's code signature. \"Designated-Requirement\" is the designated requirement string from the code signature of the app. For example, \"com.example.app\" for the bundle ID format, \"com.example.app (ABCD1234)\" for the team ID format, or \"com.example.app {anchor apple generic}\" for the designated requirement format. The device only applies defaults for an app if its code signature matches the composed identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"app_privacy_permissiondefaults_generickey_localnetwork","displayName":"Local Network","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of the local network.\n* `Allow`: The app privacy permission default is set to allow use of the local network.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_localnetwork_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_localnetwork_1","displayName":"Allow","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_location","displayName":"Location","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for access to location.\n* `WhileUsing`: The app privacy permission default is set to allow access to location only while the user is using the app In macOS, this is equivalent to `Always`.\n* `Always`: The app privacy permission default is set to allow access to location always.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_location_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_location_1","displayName":"WhileUsing","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_location_2","displayName":"Always","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_locationaccuracy","displayName":"Location Accuracy","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for access to precise location.\n* `Approximate`: The app privacy permission default is set to allow approximate access to location.\n* `Precise`: The app privacy permission default is set to allow precise access to location.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_locationaccuracy_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_locationaccuracy_1","displayName":"Approximate","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_locationaccuracy_2","displayName":"Precise","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_microphone","displayName":"Microphone","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of the microphone.\n* `Allow`: The app privacy permission default is set to allow use of the microphone.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_microphone_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_microphone_1","displayName":"Allow","description":null,"helpText":null}]},{"id":"app_privacy_permissiondefaults_generickey_organizationjustification","displayName":"Organization Justification","description":"Text you provide that clearly explains to the user the reason why the organization requires these app permission defaults. The device includes this text in the permission consent prompt it displays when it launches the app.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},{"id":"apple_customprofile_profile","displayName":"Profile","description":"A admin uploaded profile to install.","helpText":null,"infoUrls":[],"categoryId":"ddb64e9d-34b9-44f4-9980-a6623f14e445","categoryName":"Custom Profile","options":null},{"id":"audioaccessory_audioaccessory","displayName":"com.apple.configuration.audio-accessory.settings","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":null},{"id":"audioaccessory_temporarypairing","displayName":"Temporary Pairing","description":"A dictionary that describes audio accessory temporary pairing behavior. The device enables temporary pairing when this key is present and the `Disabled` key isn't `false`. The device doesn't synchronize pairing information with iCloud when temporary pairing is active.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":null},{"id":"audioaccessory_temporarypairing_configuration","displayName":"Configuration","description":"A dictionary providing configuration for temporary pairing. Required if `Disabled` isn't present or is `false`.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":null},{"id":"audioaccessory_temporarypairing_configuration_unpairingtime","displayName":"Unpairing Time","description":"A dictionary that describes when the device automatically unpairs temporarily paired audio accessories.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":null},{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_hour","displayName":"Hour","description":"The local time hour (24-hour clock) when the device automatically unpairs temporarily paired audio accessories. Required when setting the `Policy` key to `Hour`.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":null},{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_policy","displayName":"Policy","description":"A string that specifies the device's unpairing policy.\n- `None`: The device doesn't automatically unpair. Use this only with a return to service device that you erase and reenroll when assigning it from one user to another.\n- `Hour`: The device automatically unpairs temporarily paired audio accessories at the local time that the `Hour` key specifies.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":[{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_policy_0","displayName":"None","description":null,"helpText":null},{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_policy_1","displayName":"Hour","description":null,"helpText":null}]},{"id":"audioaccessory_temporarypairing_disabled","displayName":"Disabled","description":"If `true`, temporary pairing of audio accessories is disabled.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":[{"id":"audioaccessory_temporarypairing_disabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"audioaccessory_temporarypairing_disabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.android.devicerestrictionpolicy.accountsblockmodification","displayName":"Block account changes","description":"If 'True', prevents users from updating or changing accounts when in kiosk mode. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to update user accounts on the device. Available for dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"aad0d3ef-88f5-4b22-831b-27093eafbc64","categoryName":"Users and Accounts","options":[{"id":"com.android.devicerestrictionpolicy.accountsblockmodification_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.accountsblockmodification_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.airplanemodeblocked","displayName":"Block airplane mode","description":"If 'True', the device is prevented from enabling airplane mode. If 'False', Intune doesn't change or update this setting. By default, the OS follows the default airplane mode behavior. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.airplanemodeblocked_false","displayName":"False","description":"The user is allowed to toggle airplane mode on or off.","helpText":null},{"id":"com.android.devicerestrictionpolicy.airplanemodeblocked_true","displayName":"True","description":"Airplane mode is disabled. The user is not allowed to toggle airplane mode on or off.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.appfunctions","displayName":"Block apps from exposing app functions","description":"If 'True', apps on fully managed devices, and apps in the work profile on corporate-owned devices with a work profile, are blocked from exposing app functions. If 'False', apps are allowed to expose app functions, which is the default OS behavior. Available for fully managed, dedicated, and corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"2257f7e1-3e88-4d4d-a666-437bbe42baca","categoryName":"Applications","options":[{"id":"com.android.devicerestrictionpolicy.appfunctions_false","displayName":"False","description":"Apps are allowed to expose app functions.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appfunctions_true","displayName":"True","description":"Apps are blocked from exposing app functions.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.appsallowinstallfromunknownsources","displayName":"Allow installation from unknown sources","description":"If 'True', allows users to enable unknown sources. This setting permits app installation from sources other than the Google Play Store, enabling users to side-load apps through alternative methods. If 'False', Intune doesn't change or update this setting. By default, the OS may prevent users from enabling unknown sources. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"2257f7e1-3e88-4d4d-a666-437bbe42baca","categoryName":"Applications","options":[{"id":"com.android.devicerestrictionpolicy.appsallowinstallfromunknownsources_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsallowinstallfromunknownsources_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy","displayName":"App auto-updates (work profile-level)","description":"Define the auto update policy for apps. Devices check for app updates daily. If set to 'User choice', the end user can set their preference in managed Google Play. If set to 'Never', apps will never auto-update. If set to 'Wi-Fi only', apps will only auto-update when the device is connected to Wi-Fi. If set to 'Always', apps will always auto-update. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"","infoUrls":[],"categoryId":"2257f7e1-3e88-4d4d-a666-437bbe42baca","categoryName":"Applications","options":[{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_notconfigured","displayName":"Not configured","description":"Not configured; this value is ignored.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_userchoice","displayName":"User choice","description":"The user can control auto-updates.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_never","displayName":"Never","description":"Apps are never auto-updated.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_wifionly","displayName":"Wi-Fi only","description":"Apps are auto-updated over Wi-Fi only.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_always","displayName":"Always","description":"Apps are auto-updated at any time. Data charges may apply.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.appsblockinstallfromunknownsourcesaosp","displayName":"Block user from turning on unknown sources","description":"If 'True', prevents users from sideloading apps. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to sideload apps from unknown sources.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.appsblockinstallfromunknownsourcesaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsblockinstallfromunknownsourcesaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.appsdefaultpermissionpolicy","displayName":"Default permission policy (work profile-level)","description":"Define the default permission policy for requests for runtime permissions. Available for fully managed, dedicated and corporate-owned work profile (at work profile level) devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.appsdefaultpermissionpolicy_devicedefault","displayName":"Device default","description":"Device default value, no intent.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsdefaultpermissionpolicy_prompt","displayName":"Prompt","description":"Prompt.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsdefaultpermissionpolicy_autogrant","displayName":"Auto grant","description":"Auto grant.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsdefaultpermissionpolicy_autodeny","displayName":"Auto deny","description":"Auto deny.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.appsrecommendskippingfirstusehints","displayName":"Skip first use hints","description":"If 'True', hides or skips suggestions from apps that step through tutorials, or hints when the app starts. If 'False', Intune doesn't change or update this setting. By default, the OS might show these suggestions when the app starts. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.appsrecommendskippingfirstusehints_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsrecommendskippingfirstusehints_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.assistcontentpolicy","displayName":"Block assist content sharing with privileged apps","description":"If 'True', blocks assist content (such as screenshots and app details) to be sent to a privileged app, like an assistant app. The setting can be used to block Circle to Search (AI feature). If set to 'False', Intune doesn't change or update this setting. By default, the OS might allow sharing assist content with privileged apps. Available for fully managed, dedicated, and corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.assistcontentpolicy_false","displayName":"False","description":"Assist content is allowed to be sent to a privileged app.","helpText":null},{"id":"com.android.devicerestrictionpolicy.assistcontentpolicy_true","displayName":"True","description":"Assist content is blocked from being sent to a privileged app.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.bluetoothblockconfiguration","displayName":"Block Bluetooth configuration","description":"If 'True', prevents users from configuring Bluetooth on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow using Bluetooth on the device. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblockconfiguration_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblockconfiguration_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.bluetoothblockconfigurationaosp","displayName":"Block Bluetooth configuration","description":"If 'True', prevents users from configuring Bluetooth on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to configure Bluetooth.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblockconfigurationaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblockconfigurationaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.bluetoothblockcontactsharing","displayName":"Block contact sharing via Bluetooth (work profile-level)","description":"If 'True', prevents sharing work profile contacts with paired Bluetooth devices, such as cars or mobile devices. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to share their contacts via Bluetooth. Available for corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblockcontactsharing_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblockcontactsharing_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.bluetoothblocked","displayName":"Block Bluetooth","description":"If 'True', disables Bluetooth entirely on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow Bluetooth to be used. Available for fully managed, dedicated, and corporate-owned work profile devices. In comparison, Bluetooth configuration disables the user from making changes to the Bluetooth toggle. As a result, it might be either 'On' or 'Off' depending on the state of Bluetooth prior to applying a policy with Bluetooth configuration enabled.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblocked_true","displayName":"True","description":"True","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblocked_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.bluetoothblockedaosp","displayName":"Block Bluetooth","description":"If 'True', disables Bluetooth on the device so that users can't pair with other devices. If 'False', Intune doesn't change or update this setting. By default, the OS might enable Bluetooth on the device.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblockedaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblockedaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.bluetoothblocksharing","displayName":"Block Bluetooth sharing","description":"If 'True', the device cannot share content over Bluetooth. If set to 'False', Intune doesn't change or update this setting. By default, the OS might allow Bluetooth sharing. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblocksharing_allowed","displayName":"False","description":"Bluetooth sharing is allowed.","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblocksharing_disallowed","displayName":"True","description":"Bluetooth sharing is not allowed.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.camerablocked","displayName":"Block access to camera (work profile-level)","description":"If 'True', prevents access to the camera on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow access to the camera. Intune only manages access to the device camera. It doesn't have access to pictures or videos. Available for fully managed, dedicated and corporate-owned work profile (at work profile level) devices. ","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.camerablocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.camerablocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.camerablockedaosp","displayName":"Block access to camera","description":"If 'True', prevents access to the camera on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow access to the camera. Intune only manages access to the device camera. It doesn't have access to pictures or videos.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.camerablockedaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.camerablockedaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.cellbroadcastsconfigblocked","displayName":"Block configuring cell broadcasts","description":"If 'True', the device is prevented from configuring cell broadcast messages. If 'False', Intune doesn't change or update this setting. By default, the OS might allow cell broadcast configuration. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.cellbroadcastsconfigblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.cellbroadcastsconfigblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.cellularblockwifitethering","displayName":"Block tethering and access to hotspots","description":"If 'True', prevents tethering and access to portable hotspots. If 'False', Intune doesn't change or update this setting. By default, the OS might allow tethering and access to portable hotspots. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.cellularblockwifitethering_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.cellularblockwifitethering_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.cellulartwogblocked","displayName":"Block cellular 2G","description":"If 'True', the device prevents cellular 2G functionality, restricting user access to the setting. If 'False', Intune doesn't change or update this setting. By default, the OS follows the default cellular 2G behavior. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.cellulartwogblocked_false","displayName":"False","description":"The user is allowed to toggle cellular 2G on or off.","helpText":null},{"id":"com.android.devicerestrictionpolicy.cellulartwogblocked_true","displayName":"True","description":"Cellular 2G is disabled. The user is not allowed to toggle cellular 2G on or off.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.certificatecredentialconfigurationdisabled","displayName":"Block users from configuring credentials (work profile-level)","description":"If 'True', prevents users from configuring certificates assigned to devices, even devices that aren't associated with a user account. If 'False', Intune doesn't change or update this setting. By default, the OS might make it possible for users to configure or change their credentials when they access them in the keystore. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"aad0d3ef-88f5-4b22-831b-27093eafbc64","categoryName":"Users and Accounts","options":[{"id":"com.android.devicerestrictionpolicy.certificatecredentialconfigurationdisabled_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.certificatecredentialconfigurationdisabled_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowcopypaste","displayName":"Allow copy and paste between work and personal profiles ","description":"If 'True', allows users copy and paste data between the work and personal profiles. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from pasting text into the personal profile that's copied from the work profile, allow users to copy text from the personal profile, and paste into the work profile or allow users to copy text from the work profile, and paste into the work profile. Available for corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowcopypaste_false","displayName":"False","description":"false","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowcopypaste_true","displayName":"True","description":"true","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing","displayName":"Data sharing between work and personal profile","description":"Choose if data can be shared between work and personal profiles. Available for corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_notconfigured","displayName":"Device default","description":"Not configured; this value defaults to CROSS_PROFILE_DATA_SHARING_UNSPECIFIED.","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_crossprofiledatasharingblocked","displayName":"Block all sharing between profiles","description":"Data cannot be shared from both the personal profile to work profile and the work profile to the personal profile.","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_datasharingfromworktopersonalblocked","displayName":"Block sharing from work to personal profile","description":"Prevents users from sharing data from the work profile to apps in the personal profile. Personal data can be shared with work apps.","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_crossprofiledatasharingallowed","displayName":"No restrictions on sharing","description":"Data from either profile can be shared with the other profile.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesshowworkcontactsinpersonalprofile","displayName":"Block searching of work contacts and displaying work contact caller-id in personal profile","description":"In the personal profile, 'True' prevents users from searching work contacts, and showing work caller ID information. If 'False', Intune doesn't change or update this setting. By default, the OS might allow searching work contacts, and show work caller IDs. Available for corporate-owned work profile devices. Available in Android 8.0 and later.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesshowworkcontactsinpersonalprofile_false","displayName":"False","description":"false","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesshowworkcontactsinpersonalprofile_true","displayName":"True","description":"true","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.dataroamingblocked","displayName":"Block roaming data services","description":"If 'True', prevents data roaming over the cellular network. If 'False', Intune doesn't change or update this setting. By default, the OS might allow data roaming when the device is on a cellular network. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.dataroamingblocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.dataroamingblocked_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.datetimeconfigurationblocked","displayName":"Block date and time changes","description":"If 'True', prevents users from manually setting the date and time. If False, Intune doesn't change or update this setting. By default, the OS might allow users to the set date and time on the device. Available for fully managed, dedicated and corporate-owned work profile (at work profile level) devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.datetimeconfigurationblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.datetimeconfigurationblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.enterprisedisplaynamevisibility","displayName":"Hide organization name","description":"If 'True', prevents the enterprise name from being displayed on the device (such as on the lock screen). If 'False', Intune doesn't change or update this setting. By default, the OS displays the enterprise name set during device setup. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.enterprisedisplaynamevisibility_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.enterprisedisplaynamevisibility_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.factoryresetblocked","displayName":"Block factory reset","description":"If 'True', prevents users from using the factory reset option in the device's settings. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to use this setting on the device. Available for fully managed and dedicated devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.factoryresetblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.factoryresetblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.factoryresetblockedaosp","displayName":"Block factory reset","description":"If 'True', prevents users from using the factory reset option in the device's settings. If 'False', Intune doesn't change or update this setting. By default, the OS might allow external media on the device.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.factoryresetblockedaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.factoryresetblockedaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.locationmode","displayName":"Location","description":"Select how location services are managed. 'Device Default' lets users turn location services on or off. 'Location enabled' requires location services to be on and prevents end users from turning it off. 'Location disabled' requires location services to be off and prevents end users from turning it on. When 'Location disabled' is configured, then any other setting that depends on the device location is affected, including the Locate device remote action that admins use. For corporate-owned work profile devices, this setting will only apply to devices running Android 10 or earlier. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.locationmode_notconfigured","displayName":"Device default","description":"No restrictions on the location detection setting and no specific behavior is set or enforced. This is the default.","helpText":null},{"id":"com.android.devicerestrictionpolicy.locationmode_disabled","displayName":"Location disabled","description":"Location detection setting is disabled on the device.","helpText":null},{"id":"com.android.devicerestrictionpolicy.locationmode_enforced","displayName":"Location enabled","description":"Location detection setting is enforced on the device.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.maxdayswithworkoff","displayName":"Maximum days to turn off work profile","description":"Set the maximum number of days a work profile can be turned off before the work profile is removed. Value of 0 means no limit. Available for corporate-owned work profile (COPE) devices running Android 11+.","helpText":"Enter a number (0-365). 0 means no limit.","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":null},{"id":"com.android.devicerestrictionpolicy.microphoneforcemute","displayName":"Block microphone adjustment","description":"If 'True', prevents users from unmuting the microphone and adjusting the microphone volume. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to use and adjust the volume of the microphone on the device. Available for fully managed, dedicated and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.microphoneforcemute_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.microphoneforcemute_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.minimumwifisecuritylevel","displayName":"Select minimum Wi-Fi security level","description":"Select what Wi-Fi security levels are required to connect to Wi-Fi networks. 'Open network security' allows the device to connect to all types of Wi-Fi networks. 'Personal network security' requires personal networks such as WEP, WPA2-PSK. 'Enterprise network security' requires enterprise EAP networks. 'Enterprise 192-bit network security' requires 192-bit networks. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.minimumwifisecuritylevel_opennetworksecurity","displayName":"Open network security","description":"The device is able to connect to all types of Wi-Fi networks.","helpText":null},{"id":"com.android.devicerestrictionpolicy.minimumwifisecuritylevel_personalnetworksecurity","displayName":"Personal network security","description":"A personal network such as WEP, WPA2-PSK is the minimum required security.","helpText":null},{"id":"com.android.devicerestrictionpolicy.minimumwifisecuritylevel_enterprisenetworksecurity","displayName":"Enterprise network security","description":"An enterprise EAP network is the minimum required security level.","helpText":null},{"id":"com.android.devicerestrictionpolicy.minimumwifisecuritylevel_enterprisebit192networksecurity","displayName":"Enterprise 192-bit network security","description":"A 192-bit enterprise network is the minimum required security level.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.mobilenetworksconfigblocked","displayName":"Block configuring mobile networks","description":"If 'True', the device is prevented from configuring mobile network settings. If 'False', Intune doesn't change or update this setting. By default, the OS might allow mobile network configuration. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.mobilenetworksconfigblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.mobilenetworksconfigblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.networkescapehatchallowed","displayName":"Allow network escape hatch","description":"If 'True', allows users to turn on the network escape hatch feature. If a network connection can't be made at boot time, the escape hatch prompts the user to temporarily connect to a network in order to refresh the device policy. After applying policy, the temporary network will be forgotten and the device will continue booting. This prevents being unable to connect to a network if there is no suitable network in the last policy and the device boots into an app in lock task mode, or the user is otherwise unable to reach device settings. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from turning on the network escape hatch feature on the device. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.networkescapehatchallowed_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.networkescapehatchallowed_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.networkresetblocked","displayName":"Block network reset","description":"If 'True', the device is prevented from performing a network settings reset. If 'False', Intune doesn't change or update this setting. By default, the OS might allow the user to reset network settings. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.networkresetblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.networkresetblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.nfcblockoutgoingbeam","displayName":"Block beaming data from apps using NFC (work profile-level)","description":"If 'True', prevents using the Near Field Communication (NFC) technology to beam data from apps. If 'False', Intune doesn't change or update this setting. By default, the OS might allow using NFC to share data between devices. Available for fully managed, dedicated and corporate-owned work profile (at work profile level) devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.nfcblockoutgoingbeam_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.nfcblockoutgoingbeam_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.outgoingcallsblocked","displayName":"Block outgoing calls","description":"If 'True', the device is prevented from making outgoing phone calls. If 'False', Intune doesn't change or update this setting. By default, the OS might allow outgoing calls. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.outgoingcallsblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.outgoingcallsblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.passwordblockkeyguard","displayName":"Disable lock screen","description":"If 'True', blocks all Keyguard lock screen features from being used. If 'False', Intune doesn't change or update this setting. By default, when the device is in lock screen, the OS might allow all the Keyguard features, such as camera, fingerprint unlock, and more. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordblockkeyguard_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordblockkeyguard_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.passwordexpirationdays","displayName":"Number of days until password expires","description":"Enter the number of days, until the device password must be changed, from 1-365. For example, enter 90 to expire the password after 90 days. When the password expires, users are prompted to create a new password. If the value is blank, Intune doesn't change or update this setting. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-365)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumlength","displayName":"Minimum password length","description":"Enter the minimum number of digits or characters the password must have, between 4 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (4-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumlengthaosp","displayName":"Minimum password length","description":"Enter the minimum number of digits or characters the password must have, from 4 to 16.","helpText":"Enter a number (4-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumlettercharacters","displayName":"Number of characters required","description":"Enter the number of characters the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumlowercasecharacters","displayName":"Number of lowercase characters required","description":"Enter the number of lowercase characters the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumnonlettercharacters","displayName":"Number of non-letter characters required","description":"Enter the number of non-letters (anything other than letters in the alphabet) the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumnumericcharacters","displayName":"Number of numeric characters required","description":"Enter the number of numeric characters (1, 2, 3, and so on) the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumsymbolcharacters","displayName":"Number of symbol characters required","description":"Enter the number of symbol characters (&, #, %, and so on) the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminimumuppercasecharacters","displayName":"Number of uppercase characters required","description":"Enter the number of uppercase characters the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp","displayName":"Maximum minutes of inactivity until screen locks","description":"Enter the maximum length of time, from 1 minute to 1 hour, that devices can be idle before the screen is automatically locked. Users must enter their credentials to regain access. For example, enter 5 to lock the device after 5 minutes of inactivity. Ignored by device if new time is longer than what's currently set on device. If set to Immediately, devices will use the minimum possible value per device.","helpText":"","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_1minute","displayName":"1 Minute","description":"Screen Timeout after 1 Minute of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_5minutes","displayName":"5 Minutes","description":"Screen Timeout after 5 Minutes of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_15minutes","displayName":"15 Minutes","description":"Screen Timeout after 15 Minutes of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_30minutes","displayName":"30 Minutes","description":"Screen Timeout after 30 Minutes of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_1hour","displayName":"1 Hour","description":"Screen Timeout after 1 Hour of Inactivity","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.passwordpreviouspasswordcounttoblock","displayName":"Number of passwords required before user can reuse a password","description":"Use this setting to restrict users from creating previously used passwords. Enter the number of previously used passwords that can't be used, from 1-24. For example, enter 5 so users can't set a new password to their current password or any of their previous four passwords. If the value is blank, Intune doesn't change or update this setting. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-24)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype","displayName":"Required password type","description":"Set the password’s complexity requirements. Additional password requirements will become available based on your selection. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level). For more details, see the information provided in the ‘Learn More’ section below.","helpText":"","infoUrls":["https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-for-work?WT.mc_id=Portal-fx#device-password"],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_devicedefault","displayName":"Device default","description":"Device default value, no intent.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_required","displayName":"Password required, no restrictions","description":"There must be a password set, but there are no restrictions on type.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_lowsecuritybiometric","displayName":"Weak Biometric","description":"Low security biometrics based password required.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_numeric","displayName":"Numeric","description":"At least numeric.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_numericcomplex","displayName":"Numeric Complex","description":"At least numeric with no repeating or ordered sequences.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_alphabetic","displayName":"Alphabetic","description":"At least alphabetic password.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_alphanumeric","displayName":"Alphanumeric","description":"At least alphanumeric password","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_alphanumericwithsymbols","displayName":"Alphanumeric with symbols","description":"At least alphanumeric with symbols.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp","displayName":"Required password type","description":"Set the password’s complexity requirements. Additional password requirements will become available based on your selection. For more details, see the information provided in the ‘Learn More’ section below.","helpText":"","infoUrls":["https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-aosp#:~:text=Required%20password%20type"],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_devicedefault","displayName":"Device default","description":"Device default value, no intent.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_required","displayName":"Password required, no restrictions","description":"There must be a password set, but there are no restrictions on type.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_lowsecuritybiometric","displayName":"Weak Biometric","description":"Low security biometrics based password required.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_numeric","displayName":"Numeric","description":"At least numeric.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_numericcomplex","displayName":"Numeric Complex","description":"At least numeric with no repeating or ordered sequences.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_alphabetic","displayName":"Alphabetic","description":"At least alphabetic password.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_alphanumeric","displayName":"Alphanumeric","description":"At least alphanumeric password","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtypeaosp_alphanumericwithsymbols","displayName":"Alphanumeric with symbols","description":"At least alphanumeric with symbols.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.passwordrequireunlock","displayName":"Required unlock frequency","description":"Select how long users have before they're required to unlock the device using a strong authentication method (password, PIN, or pattern). Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordrequireunlock_devicedefault","displayName":"Device default","description":null,"helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequireunlock_requiredpasswordunlockdailyoption","displayName":"24 hours since last PIN, password, or pattern unlock","description":null,"helpText":null}]},{"id":"com.android.devicerestrictionpolicy.passwordsigninfailurecountbeforefactoryreset","displayName":"Number of sign-in failures before wiping device","description":"Enter the number of wrong passwords allowed before the device is wiped, from 4-11. If the value is blank, Intune doesn't change or update this setting. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (4-11)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.passwordsigninfailurecountbeforefactoryresetaosp","displayName":"Number of sign-in failures before wiping device","description":"Enter the number of sign-in attempts allowed, from 4 to 11, before the device is wiped. 0 (zero) might disable the device wipe functionality. When the value is blank, Intune doesn't change or update this setting.","helpText":"Enter a number (4-11)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},{"id":"com.android.devicerestrictionpolicy.personalprofileappsallowinstallfromunknownsources","displayName":"Allow users to enable app installation from unknown sources in the personal profile","description":"If 'True, allows users to install apps from unknown sources in the personal profile. It allows users to install apps from sources other than the Google Play Store. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from installing apps from unknown sources in the personal profile. Available for corporate-owned work profile devices (at personal profile level).","helpText":null,"infoUrls":[],"categoryId":"990880db-3f64-4436-ab4a-d7d5181dfa5d","categoryName":"Personal Profile","options":[{"id":"com.android.devicerestrictionpolicy.personalprofileappsallowinstallfromunknownsources_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.personalprofileappsallowinstallfromunknownsources_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.personalprofilecamerablocked","displayName":"Block camera","description":"If 'True', prevents access to the camera during personal use. If 'False', Intune doesn't change or update this setting. By default, the OS might allow using the camera in the personal profile. Available for corporate-owned work profile devices (at personal profile level).","helpText":null,"infoUrls":[],"categoryId":"990880db-3f64-4436-ab4a-d7d5181dfa5d","categoryName":"Personal Profile","options":[{"id":"com.android.devicerestrictionpolicy.personalprofilecamerablocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.personalprofilecamerablocked_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.personalprofilescreencaptureblocked","displayName":"Block screen capture","description":"If 'True', prevents screen captures during personal and work use. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to get screen captures or screenshots in the personal and work profile. Available for corporate-owned work profile devices (applies at both work and personal profile level).","helpText":null,"infoUrls":[],"categoryId":"990880db-3f64-4436-ab4a-d7d5181dfa5d","categoryName":"Personal Profile","options":[{"id":"com.android.devicerestrictionpolicy.personalprofilescreencaptureblocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.personalprofilescreencaptureblocked_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.preferentialnetworkservice","displayName":"Allow selection of a preferential network service","description":"If 'True', the device will give priority to the specified network service over other available options (e.g., enterprise slice on 5G networks). If 'False', Intune doesn't change or update this setting. By default, the device connects using its default network selection process. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.preferentialnetworkservice_false","displayName":"False","description":"Preferential network service is disabled.","helpText":null},{"id":"com.android.devicerestrictionpolicy.preferentialnetworkservice_true","displayName":"True","description":"Preferential network service is enabled on the device.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.printingpolicy","displayName":"Block printing","description":"If 'True', the device is prevented from printing documents. If 'False', Intune doesn't change or update this setting. By default, the OS follows the default printing behavior. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.printingpolicy_false","displayName":"False","description":"The user is allowed to print.","helpText":null},{"id":"com.android.devicerestrictionpolicy.printingpolicy_true","displayName":"True","description":"The user is not allowed to print.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.privatespacepolicy","displayName":"Block private space","description":"If 'True', prevents users from creating or using private spaces on the device, ensuring that all data is stored within the corporate profile. All existing private spaces will be deleted. If 'False', Intune doesn't change or update this setting. By default, the OS might allow the creation of private spaces for personal data. Available for corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.privatespacepolicy_allowed","displayName":"False","description":"Users can create a private space profile.","helpText":null},{"id":"com.android.devicerestrictionpolicy.privatespacepolicy_disallowed","displayName":"True","description":"Users cannot create a private space profile. Supported only for company-owned devices with a work profile. Caution: Any existing private space will be removed.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.screencaptureblocked","displayName":"Block screen capture","description":"If 'True', prevents screenshots or screen captures on the device. It also prevents the content from being shown on display devices that don't have a secure video output. If 'False', Intune doesn't change or update this setting. By default, the OS might let users capture the screen contents as an image. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.screencaptureblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.screencaptureblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.screencaptureblockedaosp","displayName":"Block screen capture","description":"If 'True', prevents screenshots or screen captures on the device. It also prevents the content from being shown on display devices that don't have a secure video output. If 'False', Intune doesn't change or update this setting. By default, the OS might let users capture the screen contents as an image.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.screencaptureblockedaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.screencaptureblockedaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.screentimeout","displayName":"Screen timeout","description":"Enter the number of seconds for the screen timeout duration. A value of 0 means there is no restriction. When configured, the device enforces this as the maximum screen timeout. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"Enter a value in seconds (0 = no restriction)","infoUrls":[],"categoryId":"95000481-a8b5-4e18-99e3-367666aee03f","categoryName":"Power","options":null},{"id":"com.android.devicerestrictionpolicy.securityallowdebuggingfeaturesaosp","displayName":"Allow users to turn on debugging features","description":"If 'True', permits users to access the debugging features on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from using the debugging features on the device.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.securityallowdebuggingfeaturesaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.securityallowdebuggingfeaturesaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.securitycommoncriteriamodeenabled","displayName":"Require Common Criteria mode​","description":"If 'True', enables an elevated set of security standards on the device most often used in highly sensitive organizations, such as government establishments. If 'False', Intune doesn't change or update this setting. Available for fully managed, dedicated and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"bf8e3e9c-f7e7-4a43-8898-2caf7b01d987","categoryName":"System Security","options":[{"id":"com.android.devicerestrictionpolicy.securitycommoncriteriamodeenabled_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.securitycommoncriteriamodeenabled_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.securitydevelopersettingsenabled","displayName":"Allow access to developer settings","description":"If 'True', allow users access developer settings on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from accessing developer settings on the device. Available for fully managed, dedicated and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.securitydevelopersettingsenabled_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.securitydevelopersettingsenabled_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.securityrequireverifyapps","displayName":"Require threat scan on apps","description":"If 'True', enables Google Play Protect to scan apps before and after they're installed. If it detects a threat, it might warn users to remove the app from the device. If 'False', Intune doesn't change or update this setting. By default, the OS might not enable or run Google Play Protect to scan apps. Available for fully managed, dedicated and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"bf8e3e9c-f7e7-4a43-8898-2caf7b01d987","categoryName":"System Security","options":[{"id":"com.android.devicerestrictionpolicy.securityrequireverifyapps_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.securityrequireverifyapps_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.setusericonblocked","displayName":"Block setting user icon","description":"If 'True', the device is prevented from changing the user icon. If 'False', Intune doesn't change or update this setting. By default, the OS might allow the user to change their icon. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.setusericonblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.setusericonblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.setwallpaperblocked","displayName":"Block setting wallpaper","description":"If 'True', the device is prevented from changing the wallpaper. If 'False', Intune doesn't change or update this setting. By default, the OS might allow the user to set a wallpaper. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.setwallpaperblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.setwallpaperblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.smsblocked","displayName":"Block SMS","description":"If 'True', the device is prevented from sending and receiving SMS messages. If 'False', Intune doesn't change or update this setting. By default, the OS might allow SMS messaging. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.smsblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.smsblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.statusbarblocked","displayName":"Block access to status bar","description":"If 'True', prevents access to the status bar, including notifications and quick settings. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users access to the status bar. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.statusbarblocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.statusbarblocked_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.stayonpluggedmodes","displayName":"Screen on while device plugged in","description":"Select the battery charging modes for which the device screen stays on while plugged in. When the device is connected using one of the selected power sources, the screen will not turn off automatically. 'AC' keeps the screen on when the device is charging over an AC adapter. 'USB' keeps the screen on when the device is charging over USB. 'Wireless' keeps the screen on when the device is charging wirelessly. When '0 selected' (no modes chosen), the device follows its default screen timeout behavior. When using this setting, it is recommended to clear the 'Time to lock screen' setting so that the device doesn't lock itself while it stays on. Available for fully managed and dedicated devices.","helpText":"Select the power sources that should keep the screen on while charging. Allowed values: AC, USB, WIRELESS. Wireless requires Android 8.1 or later. Selections are combined across policies.","infoUrls":[],"categoryId":"95000481-a8b5-4e18-99e3-367666aee03f","categoryName":"Power","options":[{"id":"com.android.devicerestrictionpolicy.stayonpluggedmodes_ac","displayName":"AC","description":null,"helpText":null},{"id":"com.android.devicerestrictionpolicy.stayonpluggedmodes_usb","displayName":"USB","description":null,"helpText":null},{"id":"com.android.devicerestrictionpolicy.stayonpluggedmodes_wireless","displayName":"Wireless","description":null,"helpText":null}]},{"id":"com.android.devicerestrictionpolicy.storageallowusb","displayName":"Allow USB storage","description":"If 'True', allow users to access USB storage on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent access to USB storage. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.storageallowusb_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.storageallowusb_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.storageblockexternalmedia","displayName":"Block mounting of external media","description":"If 'True', prevents using or connecting any external media on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow external media on the device. Available for fully managed, dedicated and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.storageblockexternalmedia_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.storageblockexternalmedia_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.storageblockexternalmediaaosp","displayName":"Block mounting of external media","description":"If 'True', prevents users from using or connecting any external media on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to connect external media.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.storageblockexternalmediaaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.storageblockexternalmediaaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.storageblockusbfiletransferaosp","displayName":"Block USB file transfer","description":"If 'True', prevents users from transferring files over USB. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to transfer files.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.storageblockusbfiletransferaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.storageblockusbfiletransferaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.systemwindowsblocked","displayName":"Block notification windows","description":"If 'True', window notifications, including toasts, incoming calls, outgoing calls, system alerts, and system errors aren't shown on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might show notifications. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.systemwindowsblocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.systemwindowsblocked_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.ultrawidebandblocked","displayName":"Block ultra wideband","description":"If 'True', the device prevents ultra wideband functionality, restricting user access to the setting. If 'False', Intune doesn't change or update this setting. By default, the OS follows the default ultra wideband behavior. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.ultrawidebandblocked_false","displayName":"False","description":"The user is allowed to toggle ultra wideband on or off.","helpText":null},{"id":"com.android.devicerestrictionpolicy.ultrawidebandblocked_true","displayName":"True","description":"Ultra wideband is disabled. The user is not allowed to toggle ultra wideband on or off.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.unifiedlocksettings","displayName":"Require separate work lock","description":"If 'True', requires a separate lock for the work profile, preventing use of a unified lock for both device and work profile. If set to 'False', Intune doesn't change or update this setting. By default, the OS might allow a common lock for the device and the work profile. Available for corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":[{"id":"com.android.devicerestrictionpolicy.unifiedlocksettings_false","displayName":"False","description":"A common lock for the device and the work profile is allowed.","helpText":null},{"id":"com.android.devicerestrictionpolicy.unifiedlocksettings_true","displayName":"True","description":"A separate lock for the work profile is required.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.usbdataaccess","displayName":"USB access","description":"Select what files and/or data can be transferred via USB. If you block file transfer, only files will be blocked from being transferred and other connection (such as mouse) will still be allowed. If you block USB data transfer, all data will be blocked. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.usbdataaccess_allowusbdatatransfer","displayName":"Allow USB data transfer","description":"All types of USB data transfers are allowed. usbFileTransferDisabled is ignored.","helpText":null},{"id":"com.android.devicerestrictionpolicy.usbdataaccess_disallowusbfiletransfer","displayName":"Disallow USB file transfer","description":"Transferring files over USB is disallowed. Other types of USB data connections, such as mouse and keyboard connection, are allowed. usbFileTransferDisabled is ignored.","helpText":null},{"id":"com.android.devicerestrictionpolicy.usbdataaccess_disallowusbdatatransfer","displayName":"Disallow USB data transfer","description":"When set, all types of USB data transfers are prohibited. Supported for devices running Android 12 or above with USB HAL 1.3 or above. If the setting is not supported, DISALLOW_USB_FILE_TRANSFER will be set. A NonComplianceDetail with API_LEVEL is reported if the Android version is less than 12. A NonComplianceDetail with DEVICE_INCOMPATIBLE is reported if the device does not have USB HAL 1.3 or above. usbFileTransferDisabled is ignored.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.userinitiatedaddesimsettings","displayName":"Block users from adding eSIM profiles","description":"If 'True', users cannot add eSIM profiles to the device. If 'False', Intune doesn't change or update this setting. By default, the OS allows users to add eSIM profiles. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.userinitiatedaddesimsettings_false","displayName":"False","description":"The user is allowed to add eSIM profiles on the device.","helpText":null},{"id":"com.android.devicerestrictionpolicy.userinitiatedaddesimsettings_true","displayName":"True","description":"The user is not allowed to add eSIM profiles on the device.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.volumeblockadjustment","displayName":"Block volume changes","description":"If 'True', prevents users from changing the device's volume, and also mutes the main volume. If 'False', Intune doesn't change or update this setting. By default, the OS might allow using the volume settings on the device. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.volumeblockadjustment_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.volumeblockadjustment_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.vpnconfigblocked","displayName":"Block configuring VPN","description":"If 'True', the device is prevented from configuring VPN connections. If 'False', Intune doesn't change or update this setting. By default, the OS might allow VPN configuration. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.vpnconfigblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.vpnconfigblocked_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurations","displayName":"Block Wi-Fi access point configuration","description":"If 'True', prevents users from creating or changing any Wi-Fi configurations. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to change the Wi-Fi settings on the device. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurations_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurations_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurationsaosp","displayName":"Block Wi-Fi setting changes","description":"If 'True', prevents users from creating or changing any Wi-Fi configurations. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to change the Wi-Fi settings on the device.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurationsaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurationsaosp_true","displayName":"True","description":"True","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.wifiblockeditpolicydefinedconfigurations","displayName":"Block Wi-Fi setting changes","description":"If 'True', prevents users from changing Wi-Fi settings created by the device owner. Users can create their own Wi-Fi configurations. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to change the Wi-Fi settings on the device. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wifiblockeditpolicydefinedconfigurations_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.wifiblockeditpolicydefinedconfigurations_false","displayName":"False","description":"false","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.wifidirectsettings","displayName":"Block Wi-Fi Direct","description":"If 'True', blocks Wi-Fi Direct (a direct, peer-to-peer connection between devices using Wi-Fi frequencies). If set to 'False', Intune doesn't change or update this setting. By default, the OS might allow Wi-Fi Direct. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wifidirectsettings_allowed","displayName":"False","description":"The user is allowed to use Wi-Fi direct.","helpText":null},{"id":"com.android.devicerestrictionpolicy.wifidirectsettings_disallowed","displayName":"True","description":"The user is not allowed to use Wi-Fi direct. A NonComplianceDetail with API_LEVEL is reported if the Android version is less than 13.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.wipedataflag","displayName":"Remove all eSIMs during a device wipe","description":"If 'True', all eSIMs are removed when a device is wiped. If 'False', Intune doesn't change or update this setting. By default, eSIMs are not removed during a device wipe, except where required by the OS. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wipedataflag_false","displayName":"False","description":"eSIMs are not removed during a device wipe, except where required by the OS.","helpText":null},{"id":"com.android.devicerestrictionpolicy.wipedataflag_true","displayName":"True","description":"All eSIMs are removed when the device is wiped.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordexpirationdays","displayName":"Number of days until password expires","description":"Enter the number of days, until the work profile password must be changed, from 1-365. For example, enter 90 to expire the password after 90 days. When the password expires, users are prompted to create a new password. If the value is blank, Intune doesn't change or update this setting. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-365)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumlength","displayName":"Minimum password length","description":"Enter the minimum number of digits or characters the work profile password must have, between 4 and 16 characters. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (4-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumlettercharacters","displayName":"Number of characters required","description":"Enter the number of characters the work profile password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumlowercasecharacters","displayName":"Number of lowercase characters required","description":"Enter the number of lowercase characters the work profile password must have, between 1 and 16 characters. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumnonlettercharacters","displayName":"Number of non-letter characters required","description":"Enter the number of non-letters (anything other than letters in the alphabet) the work profile password must have, between 1 and 16 characters. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumnumericcharacters","displayName":"Number of numeric characters required","description":"Enter the number of numeric characters (1, 2, 3, and so on) the work profile password must have, between 1 and 16 characters. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumsymbolcharacters","displayName":"Number of symbol characters required","description":"Enter the number of symbol characters (&, #, %, and so on) the work profile password must have, between 1 and 16 characters. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumuppercasecharacters","displayName":"Number of uppercase characters required","description":"Enter the number of uppercase characters the work profile password must have, between 1 and 16 characters. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordpreviouspasswordcounttoblock","displayName":"Number of passwords required before user can reuse a password","description":"Use this setting to restrict users from creating previously used work profile passwords. Enter the number of previously used passwords that can't be used, from 1-24. For example, enter 5 so users can't set a new password to their current password or any of their previous four passwords. If the value is blank, Intune doesn't change or update this setting. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-24)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype","displayName":"Required password type","description":"Set the work profile password’s complexity requirements. Additional password requirements will become available based on your selection. Available for corporate-owned work profile devices (at work profile level). For more details, see the information provided in the ‘Learn More’ section below.","helpText":"","infoUrls":["https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-for-work?WT.mc_id=Portal-fx#device-password:~:text=owned%20work%20profiles.-,Required%20password%20type%3A,-Enter%20the%20required"],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":[{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_devicedefault","displayName":"Device default","description":"Device default value, no intent.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_required","displayName":"Password required, no restrictions","description":"There must be a password set, but there are no restrictions on type.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_lowsecuritybiometric","displayName":"Weak Biometric","description":"Low security biometrics based password required.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_numeric","displayName":"Numeric","description":"At least numeric.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_numericcomplex","displayName":"Numeric Complex","description":"At least numeric with no repeating or ordered sequences.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_alphabetic","displayName":"Alphabetic","description":"At least alphabetic password.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_alphanumeric","displayName":"Alphanumeric","description":"At least alphanumeric password","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_alphanumericwithsymbols","displayName":"Alphanumeric with symbols","description":"At least alphanumeric with symbols.","helpText":null}]},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequireunlock","displayName":"Required unlock frequency","description":"Select how long users have before they're required to unlock the work profile using a strong authentication method (password, PIN, or pattern). Available for corporate-owned work profile devices (at work profile level).","helpText":"","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":[{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequireunlock_devicedefault","displayName":"Device default","description":null,"helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequireunlock_requiredpasswordunlockdailyoption","displayName":"24 hours since last PIN, password, or pattern unlock","description":null,"helpText":null}]},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordsigninfailurecountbeforefactoryreset","displayName":"Number of sign-in failures before wiping device","description":"Enter the number of wrong passwords allowed before the work profile is wiped, from 4-11. If the value is blank, Intune doesn't change or update this setting. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (4-11)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},{"id":"com.android.devicerestrictionpolicy.workprofilewidgetsdefault","displayName":"Block widgets from work profile apps","description":"If 'True', prevents users from adding widgets exposed by work profile apps to the home screen. If set to 'False', Intune doesn't change or update this setting. By default, the OS might allow adding work profile widgets to the home screen. Available for corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"2257f7e1-3e88-4d4d-a666-437bbe42baca","categoryName":"Applications","options":[{"id":"com.android.devicerestrictionpolicy.workprofilewidgetsdefault_false","displayName":"False","description":"Work profile widgets are allowed. Users can add widgets exposed by work profile apps to the home screen.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilewidgetsdefault_true","displayName":"True","description":"Work profile widgets are disallowed. Users cannot add widgets from work profile apps to the home screen.","helpText":null}]},{"id":"com.apple.airplay_allowlist","displayName":"Allow List","description":"If present, only AirPlay destinations in this list are available to the device. This allow list applies to supervised devices.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_allowlist_item_deviceid","displayName":"Device ID (Deprecated)","description":"The device ID of the AirPlay destination in the format xx:xx:xx:xx:xx:xx. This field isn’t case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_allowlist_item_devicename","displayName":"Device Name","description":"The name of the AirPlay device.\n\nThe system limits the list of visible AirPlay destinations to devices that are present in the `AllowList` field of all installed AirPlay payloads.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_com.apple.airplay","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_passwords","displayName":"Password","description":"The password for the AirPlay destination.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_passwords_item_deviceid","displayName":"Device ID","description":"The device ID of the AirPlay destination; used in macOS.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_passwords_item_devicename","displayName":"Device Name","description":"The name of the AirPlay destination; used in iOS.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airplay_passwords_item_password","displayName":"Password","description":"The password for the AirPlay destination.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},{"id":"com.apple.airprint_airprint","displayName":"Printers","description":"A list of AirPrint printers that are presented to the user.","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},{"id":"com.apple.airprint_airprint_item_forcetls","displayName":"Force TLS","description":"If true, AirPrint connections are secured by Transport Layer Security (TLS). Available only in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":[{"id":"com.apple.airprint_airprint_item_forcetls_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.airprint_airprint_item_forcetls_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.airprint_airprint_item_ipaddress","displayName":"IP Address","description":"The IP address or hostname of the AirPrint destination.","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},{"id":"com.apple.airprint_airprint_item_port","displayName":"Port","description":"The listening port of the AirPrint destination. Available only in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},{"id":"com.apple.airprint_airprint_item_resourcepath","displayName":"Resource Path","description":"The resource path associated with the printer. This path corresponds to the rp parameter of the _ipps.tcp Bonjour record. For example: printers/Canon_MG5300_series, printers/Xerox_Phaser_7600, ipp/print, Epson_IPP_Printer","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},{"id":"com.apple.airprint_com.apple.airprint","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},{"id":"com.apple.app.lock_app","displayName":"App","description":"A dictionary that contains information about the app.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},{"id":"com.apple.app.lock_app_identifier","displayName":"App Identifier","description":"The bundle identifier of the app.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},{"id":"com.apple.app.lock_app_options","displayName":"Options","description":"A dictionary of options that the user cannot change.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},{"id":"com.apple.app.lock_app_options_disableautolock","displayName":"Disable Auto Lock","description":"If true, the device doesn't automatically go to sleep after an idle period.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disableautolock_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disableautolock_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_disabledevicerotation","displayName":"Disable Device Rotation","description":"If true, disables device rotation sensing.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disabledevicerotation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disabledevicerotation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_disableringerswitch","displayName":"Disable Ringer Switch","description":"If true, disables the ringer switch. When disabled, the ringer behavior depends on what position the switch was in when it was first disabled.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disableringerswitch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disableringerswitch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_disablesleepwakebutton","displayName":"Disable Sleep Wake Button","description":"If true, disables the sleep/wake button.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disablesleepwakebutton_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disablesleepwakebutton_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_disabletouch","displayName":"Disable Touch","description":"If true, disables the touch screen.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disabletouch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disabletouch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_disablevolumebuttons","displayName":"Disable Volume Buttons","description":"If true, disables the volume buttons.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disablevolumebuttons_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disablevolumebuttons_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enableassistivetouch","displayName":"Enable Assistive Touch","description":"If true, enables Assistive Touch.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enableassistivetouch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enableassistivetouch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enableinvertcolors","displayName":"Enable Invert Colors","description":"If true, enables Invert Colors. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enableinvertcolors_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enableinvertcolors_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enablemonoaudio","displayName":"Enable Mono Audio","description":"If true, enables Mono Audio.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enablemonoaudio_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enablemonoaudio_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enablespeakselection","displayName":"Enable Speak Selection","description":"If true, enables Speak Selection.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enablespeakselection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enablespeakselection_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enablevoicecontrol","displayName":"Enable Voice Control","description":"If true, enables Voice Control.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enablevoicecontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enablevoicecontrol_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enablevoiceover","displayName":"Enable Voice Over","description":"If true, enables Voice Over.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enablevoiceover_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enablevoiceover_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_options_enablezoom","displayName":"Enable Zoom","description":"If true, enables Zoom. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enablezoom_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enablezoom_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_userenabledoptions","displayName":"User Enabled Options","description":"A dictionary of user-editable options.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},{"id":"com.apple.app.lock_app_userenabledoptions_assistivetouch","displayName":"Assistive Touch","description":"If true, allows the user to toggle Assistive Touch.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_assistivetouch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_assistivetouch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_userenabledoptions_invertcolors","displayName":"Invert Colors","description":"If true, allows the user to toggle Invert Colors. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_invertcolors_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_invertcolors_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_userenabledoptions_voicecontrol","displayName":"Voice Control","description":"If true, allows the user to toggle Voice Control.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_voicecontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_voicecontrol_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_userenabledoptions_voiceover","displayName":"Voice Over","description":"If true, allows the user to toggle Voice Over. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_voiceover_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_voiceover_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_app_userenabledoptions_zoom","displayName":"Zoom","description":"If true, allows the user to toggle Zoom. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_zoom_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_zoom_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.app.lock_com.apple.app.lock","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},{"id":"com.apple.applicationaccess_allowaccountmodification","displayName":"Allow Account Modification","description":"If false, disables account modification. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowaccountmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowaccountmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowactivitycontinuation","displayName":"Allow Activity Continuation","description":"If false, disables activity continuation. Available in iOS 8 and later, and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowactivitycontinuation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowactivitycontinuation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowaddinggamecenterfriends","displayName":"Allow Adding Game Center Friends","description":"If false, prohibits adding friends to Game Center. As of iOS 13, requires a supervised device. Available in iOS 4.2.1 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowaddinggamecenterfriends_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowaddinggamecenterfriends_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowairdrop","displayName":"Allow AirDrop","description":"If false, disables AirDrop. Requires a supervised device. Available in iOS 7 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowairdrop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowairdrop_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowairplayincomingrequests","displayName":"Allow Air Play Incoming Requests","description":"If false, disables incoming AirPlay requests. Requires a supervised device. Available in macOS 12.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowairplayincomingrequests_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowairplayincomingrequests_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowairprint","displayName":"Allow AirPrint","description":"If false, disables AirPrint. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowairprint_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowairprint_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowairprintcredentialsstorage","displayName":"Allow AirPrint Credentials Storage","description":"If false, disables keychain storage of user name and password for AirPrint. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowairprintcredentialsstorage_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowairprintcredentialsstorage_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowairprintibeacondiscovery","displayName":"Allow AirPrint iBeacon Discovery","description":"If false, disables iBeacon discovery of AirPrint printers, which prevents spurious AirPrint Bluetooth beacons from phishing for network traffic. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowairprintibeacondiscovery_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowairprintibeacondiscovery_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappcellulardatamodification","displayName":"Allow App Cellular Data Modification","description":"If false, disables changing settings for cellular data usage for apps. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappcellulardatamodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappcellulardatamodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappclips","displayName":"Allow App Clips","description":"If false, prevents a user from adding any App Clips, and removes any existing App Clips on the device. Requires a supervised device. Available in iOS 14.0 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappclips_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappclips_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappinstallation","displayName":"Allow App Installation","description":"If false, disables the App Store, and its icon is removed from the Home screen. Users are unable to install or update their apps. In iOS 10 and later, MDM commands can override this restriction. As of iOS 13, this restriction requires a supervised device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappleintelligencereport","displayName":"Allow Apple Intelligence Report (Deprecated)","description":"When false, disables Apple Intelligence reports.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappleintelligencereport_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappleintelligencereport_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowapplepersonalizedadvertising","displayName":"Allow Apple Personalized Advertising","description":"If false, limits Apple personalized advertising. Available in iOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowapplepersonalizedadvertising_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowapplepersonalizedadvertising_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappremoval","displayName":"Allow App Removal","description":"If false, disables removal of apps from an iOS device. Requires a supervised device. Available in iOS 4.2.1 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappremoval_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappremoval_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappstobehidden","displayName":"Allow Apps To Be Hidden","description":"If false, disables the ability for the user to hide apps. It does not affect the user's ability to leave it in the App Library, while removing it from the home screen.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappstobehidden_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappstobehidden_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowappstobelocked","displayName":"Allow Apps To Be Locked","description":"If false, disables the ability for the user to lock apps. Because hiding apps also requires locking them, disallowing locking also disallows hiding.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappstobelocked_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappstobelocked_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowardremotemanagementmodification","displayName":"Allow ARD Remote Management Modification","description":"If 'false', prevents modifying the Remote Management Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowardremotemanagementmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowardremotemanagementmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowassistant","displayName":"Allow Assistant (Deprecated)","description":"If false, disables Siri. Available in iOS 5 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowassistant_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowassistant_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowassistantusergeneratedcontent","displayName":"Allow Assistant User Generated Content (Deprecated)","description":"If false, prevents Siri from querying user-generated content from the web. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowassistantusergeneratedcontent_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowassistantusergeneratedcontent_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowassistantwhilelocked","displayName":"Allow Assistant While Locked (Deprecated)","description":"If false, disables Siri when the device is locked. This restriction is ignored if the device doesn’t have a passcode set. Available in iOS 5.1 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowassistantwhilelocked_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowassistantwhilelocked_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowautocorrection","displayName":"Allow Auto Correction (Deprecated)","description":"If false, disables keyboard autocorrection. Requires a supervised device. Available in iOS 8.1.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowautocorrection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowautocorrection_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowautodim","displayName":"Allow Auto Dim","description":"If set to false, disables auto dim on iPads with OLED displays.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowautodim_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowautodim_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowautomaticappdownloads","displayName":"Allow Automatic App Downloads","description":"If false, prevents automatic downloading of apps purchased on other devices. This setting doesn’t affect updates to existing apps. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowautomaticappdownloads_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowautomaticappdownloads_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowautounlock","displayName":"Allow Auto Unlock","description":"If false, disallows auto unlock. Available in macOS 10.12 and later, and iOS 14.5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowautounlock_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowautounlock_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowbluetoothmodification","displayName":"Allow Bluetooth Modification","description":"If false, prevents modification of Bluetooth settings. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowbluetoothmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowbluetoothmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowbluetoothsharingmodification","displayName":"Allow Bluetooth Sharing Modification","description":"If 'false', prevents modifying Bluetooth setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowbluetoothsharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowbluetoothsharingmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowbookstore","displayName":"Allow Bookstore","description":"If false, removes the Book Store tab from the Books app. Requires a supervised device. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowbookstore_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowbookstore_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowbookstoreerotica","displayName":"Allow Bookstore Erotica","description":"If false, the user can’t download Apple Books media that is tagged as erotica. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowbookstoreerotica_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowbookstoreerotica_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcallrecording","displayName":"Allow Call Recording","description":"If false, call recording is disabled.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcallrecording_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcallrecording_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcamera","displayName":"Allow Camera","description":"If false, disables the camera, and its icon is removed from the Home screen. Users are unable to take photographs. Requires a supervised device. Available in iOS 4 and later, and macOS 10.11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcamera_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcamera_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcellularplanmodification","displayName":"Allow Cellular Plan Modification","description":"If false, users can’t change any settings related to their cellular plan. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcellularplanmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcellularplanmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowchat","displayName":"Allow Chat","description":"If false, disables the use of the iMessage with supervised devices. If the device supports text messaging, the user can still send and receive text messages. Requires a supervised device. Available in iOS 5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowchat_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowchat_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudaddressbook","displayName":"Allow Cloud Address Book","description":"If false, disables iCloud Address Book services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudaddressbook_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudaddressbook_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudbackup","displayName":"Allow Cloud Backup","description":"If false, disables backing up the device to iCloud. Requires a supervised device. Available in iOS 5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudbackup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudbackup_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudbookmarks","displayName":"Allow Cloud Bookmarks","description":"If false, disables iCloud Bookmark sync. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudbookmarks_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudbookmarks_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudcalendar","displayName":"Allow Cloud Calendar","description":"If false, disables iCloud Calendar services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudcalendar_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudcalendar_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowclouddesktopanddocuments","displayName":"Allow Cloud Desktop And Documents","description":"If false, disables cloud desktop and document services. Available in macOS 10.12.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowclouddesktopanddocuments_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowclouddesktopanddocuments_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowclouddocumentsync","displayName":"Allow Cloud Document Sync","description":"If false, disables document and key-value syncing to iCloud. As of iOS 13, this restriction requires a supervised device. Available in iOS 5 and later, and macOS 10.11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowclouddocumentsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowclouddocumentsync_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudfreeform","displayName":"Allow Cloud Freeform","description":"If 'false', disallows iCloud Freeform services.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudfreeform_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudfreeform_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudkeychainsync","displayName":"Allow Cloud Keychain Sync","description":"If false, disables iCloud keychain synchronization. Requires a supervised device. Available in iOS 7 and later and macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudkeychainsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudkeychainsync_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudmail","displayName":"Allow Cloud Mail","description":"If false, disables iCloud Mail services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudmail_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudmail_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudnotes","displayName":"Allow Cloud Notes","description":"If false, disables iCloud Notes services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudnotes_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudnotes_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudphotolibrary","displayName":"Allow Cloud Photo Library","description":"If false, disables iCloud Photo Library. Any photos not fully downloaded from iCloud Photo Library to the device are removed from local storage. Available in iOS 9 and later, and macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudphotolibrary_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudphotolibrary_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudprivaterelay","displayName":"Allow Cloud Private Relay","description":"If false, disables iCloud Private Relay. For iOS devices, this restriction requires a supervised device. Available in macOS 12 and later, and iOS 15 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudprivaterelay_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudprivaterelay_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcloudreminders","displayName":"Allow Cloud Reminders","description":"If false, disables iCloud Reminder services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudreminders_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudreminders_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcontentcaching","displayName":"Allow Content Caching","description":"If false, disables content caching. As of 10.13.4 this is included in the content caching payload. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcontentcaching_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcontentcaching_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowcontinuouspathkeyboard","displayName":"Allow Continuous Path Keyboard (Deprecated)","description":"If false, disables QuickPath keyboard. Requires a supervised device. Available in iOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcontinuouspathkeyboard_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcontinuouspathkeyboard_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdefaultbrowsermodification","displayName":"Allow Default Browser Modification","description":"If false, disables default browser preference modification. The MDM Settings command to set the default browser preference will still work when this is applied.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdefaultbrowsermodification_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdefaultbrowsermodification_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdefaultcallingappmodification","displayName":"Allow Default Calling App Modification","description":"If false, disables default calling app preference modification. The MDM Settings command to set the default calling app preference will still work when this is applied.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdefaultcallingappmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdefaultcallingappmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdefaultmessagingappmodification","displayName":"Allow Default Messaging App Modification","description":"If false, disables default messaging app preference modification. The MDM Settings command to set the default messaging app preference will still work when this is applied.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdefaultmessagingappmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdefaultmessagingappmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdefinitionlookup","displayName":"Allow Definition Lookup (Deprecated)","description":"If false, disables definition lookup. Requires a supervised device on iOS. Available in iOS 8.1.3 and later and macOS 10.11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdefinitionlookup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdefinitionlookup_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdevicenamemodification","displayName":"Allow Device Name Modification","description":"If false, prevents the user from changing the device name. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdevicenamemodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdevicenamemodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdiagnosticsubmission","displayName":"Allow Diagnostic Submission","description":"If false, prevents the device from automatically submitting diagnostic reports to Apple. Available in iOS 6 and later, and macOS 10.13 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdiagnosticsubmission_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdiagnosticsubmission_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdiagnosticsubmissionmodification","displayName":"Allow Diagnostic Submission Modification","description":"If false, disables changing the diagnostic submission and app analytics settings in the Diagnostics & Usage UI in Settings. Requires a supervised device. Available in iOS 9.3.2 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdiagnosticsubmissionmodification_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdiagnosticsubmissionmodification_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowdictation","displayName":"Allow Dictation (Deprecated)","description":"If false, disallows dictation input. Requires a supervised device. Available in iOS 10.3 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdictation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdictation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowedcamerarestrictionbundleids","displayName":"Allowed Camera Restriction Bundle IDs","description":"If present, the system exempts apps with bundle IDs in the array from the `allowCamera` restriction. The system doesn't grant these apps access to the camera automatically; they're only exempted from the `allowCamera` restriction. This key has no effect when the camera isn't restricted. Multiple payloads combine using an intersect operation. Requires a supervised device.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_allowedexternalintelligenceworkspaceids","displayName":"Allowed External Intelligence Workspace IDs (Deprecated)","description":"An array of strings, but currently restricted to a single element. If present, Apple Intelligence allows use of only the given external integration workspace ID, and requires a sign-in to make requests. The user is required to sign in to integrations that support signing in. Multiple payloads combine using an intersect operation. This means the allowed set of workspace IDs can become the empty set if multiple payloads specify conflicting values.\n\nDeprecated: use the declarative management `com.apple.configuration.external-intelligence.settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_allowenablingrestrictions","displayName":"Allow Enabling Restrictions","description":"If false, disables the “Enable Restrictions” option in the Restrictions UI in Settings. In iOS 12 or later, if false, disables the “Enable ScreenTime” option in the ScreenTime UI in Settings and disables ScreenTime if already enabled. Requires a supervised device. Available in iOS 8 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowenablingrestrictions_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowenablingrestrictions_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowenterpriseapptrust","displayName":"Allow Enterprise App Trust","description":"If false, removes the Trust Enterprise Developer button in Settings > General > Profiles & Device Management, preventing apps from being provisioned by universal provisioning profiles. This restriction applies to free developer accounts. However, it doesn’t apply to enterprise app developers who are trusted because their apps were pushed through MDM. It also doesn’t revoke previously granted trust. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowenterpriseapptrust_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowenterpriseapptrust_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowenterprisebookbackup","displayName":"Allow Enterprise Book Backup","description":"If false, disables backup of Enterprise books. Available in iOS 8 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowenterprisebookbackup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowenterprisebookbackup_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowenterprisebookmetadatasync","displayName":"Allow Enterprise Book Metadata Sync","description":"If false, disables sync of Enterprise books, notes, and highlights. Available in iOS 8 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowenterprisebookmetadatasync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowenterprisebookmetadatasync_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowerasecontentandsettings","displayName":"Allow Erase Content And Settings","description":"If false, disables the Erase All Content And Settings option in the Reset UI. Requires a supervised device. Available in iOS 8 and later, and macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowerasecontentandsettings_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowerasecontentandsettings_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowesimmodification","displayName":"Allow ESIM Modification","description":"If false, disables modifications to carrier plan related settings (only available on select carriers). Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowesimmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowesimmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowesimoutgoingtransfers","displayName":"Allow ESIM Outgoing Transfers","description":"If 'false', prevents the transfer of an eSIM from the device on which the restriction is installed to a different device. Available in iOS 18 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowesimoutgoingtransfers_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowesimoutgoingtransfers_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowexplicitcontent","displayName":"Allow Explicit Content","description":"If false, hides explicit music or video content purchased from the iTunes Store. Explicit content is marked as such by content providers, such as record labels, when sold through the iTunes Store. As of iOS 13, requires a supervised device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowexplicitcontent_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowexplicitcontent_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowexternalintelligenceintegrations","displayName":"Allow External Intelligence Integrations (Deprecated)","description":"If false, disables the use of external, cloud-based intelligence services with Siri.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowexternalintelligenceintegrations_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowexternalintelligenceintegrations_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowexternalintelligenceintegrationssignin","displayName":"Allow External Intelligence Integrations Sign In (Deprecated)","description":"If false, forces external intelligence providers into anonymous mode. If a user is already signed in to an external intelligence provider, applying this restriction will cause them to be signed out.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowexternalintelligenceintegrationssignin_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowexternalintelligenceintegrationssignin_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfilesharingmodification","displayName":"Allow File Sharing Modification","description":"If 'false', prevents modifying File Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfilesharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfilesharingmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfilesnetworkdriveaccess","displayName":"Allow Files Network Drive Access","description":"If false, prevents connecting to network drives in the Files app. Requires a supervised device. Available in iOS 13.1 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfilesnetworkdriveaccess_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfilesnetworkdriveaccess_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfilesusbdriveaccess","displayName":"Allow Files USB Drive Access","description":"If false, prevents connecting to any connected USB devices in the Files app. Requires a supervised device. Available in iOS 13.1 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfilesusbdriveaccess_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfilesusbdriveaccess_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfindmydevice","displayName":"Allow Find My Device","description":"If false, disables Find My Device in the Find My app. Requires a supervised device. Available in iOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfindmydevice_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfindmydevice_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfindmyfriends","displayName":"Allow Find My Friends","description":"If false, disables Find My Friends in the Find My app. Requires a supervised device. Available in iOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfindmyfriends_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfindmyfriends_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfindmyfriendsmodification","displayName":"Allow Find My Friends Modification","description":"If false, disables changes to Find My Friends. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfindmyfriendsmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfindmyfriendsmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfingerprintforunlock","displayName":"Allow Fingerprint For Unlock","description":"If false, prevents Touch ID or Face ID from unlocking a device. Available in iOS 7 and later, and macOS 10.12.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfingerprintforunlock_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfingerprintforunlock_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowfingerprintmodification","displayName":"Allow Fingerprint Modification","description":"If false, prevents the user from modifying Touch ID or Face ID. Requires a supervised device. Available in iOS 8.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfingerprintmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfingerprintmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowgamecenter","displayName":"Allow Game Center","description":"If false, disables Game Center, and its icon is removed from the Home screen. Requires a supervised device. Available in iOS 6 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowgamecenter_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowgamecenter_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowgenmoji","displayName":"Allow Genmoji (Deprecated)","description":"When false, prohibits creating new Genmoji.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowgenmoji_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowgenmoji_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowglobalbackgroundfetchwhenroaming","displayName":"Allow Global Background Fetch When Roaming","description":"If false, disables global background fetch activity when an iOS phone is roaming. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowglobalbackgroundfetchwhenroaming_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowglobalbackgroundfetchwhenroaming_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowhostpairing","displayName":"Allow Host Pairing","description":"If false, disables host pairing with the exception of the supervision host. If no supervision host certificate has been configured, all pairing is disabled. Host pairing lets the administrator control if an iOS device can pair with a host Mac or PC. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowhostpairing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowhostpairing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowimageplayground","displayName":"Allow Image Playground (Deprecated)","description":"If false, prohibits the use of image generation.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowimageplayground_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowimageplayground_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowimagewand","displayName":"Allow Image Wand (Deprecated)","description":"When false, prohibits the use of Image Wand.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowimagewand_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowimagewand_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowinapppurchases","displayName":"Allow In App Purchases","description":"If false, prohibits in-app purchasing. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowinapppurchases_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowinapppurchases_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowinternetsharingmodification","displayName":"Allow Internet Sharing Modification","description":"If 'false', prevents modifying Internet Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowinternetsharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowinternetsharingmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowiphonemirroring","displayName":"Allow iPhone Mirroring","description":"If false, prohibits the use of iPhone Mirroring. When used on macOS, this prevents the Mac from mirroring any iPhone. When used on iOS, this prevents the iPhone from mirroring to any Mac.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowiphonemirroring_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowiphonemirroring_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowiphonewidgetsonmac","displayName":"Allow iPhone Widgets On Mac","description":"If 'false', disallows iPhone widgets on a Mac that has signed in the same AppleID for iCloud. Supervised only.\nAvailable on iOS 17 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowiphonewidgetsonmac_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowiphonewidgetsonmac_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowitunes","displayName":"Allow iTunes","description":"If false, disables the iTunes Music Store, and its icon is removed from the Home screen. Users cannot preview, purchase, or download content. As of iOS 13, requires a supervised device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowitunes_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowitunes_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowitunesfilesharing","displayName":"Allow iTunes File Sharing","description":"If false, disables iTunes file sharing services. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowitunesfilesharing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowitunesfilesharing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowkeyboardshortcuts","displayName":"Allow Keyboard Shortcuts (Deprecated)","description":"If false, disables keyboard shortcuts. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowkeyboardshortcuts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowkeyboardshortcuts_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowlistedappbundleids","displayName":"Allow Listed App Bundle IDs","description":"If present, this property allows only bundle IDs listed in the array to be shown or launchable. Include the value com.apple.webapp to allow all webclips. Requires a supervised device. Available in iOS 9.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_allowlivevoicemail","displayName":"Allow Live Voicemail","description":"If set to false, disables live voicemail on the device.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlivevoicemail_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlivevoicemail_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowlocalusercreation","displayName":"Allow Local User Creation","description":"If 'false', prevents creating new users in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlocalusercreation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlocalusercreation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowlockscreencontrolcenter","displayName":"Allow Lock Screen Control Center","description":"If false, prevents Control Center from appearing on the Lock screen. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlockscreencontrolcenter_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlockscreencontrolcenter_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowlockscreennotificationsview","displayName":"Allow Lock Screen Notifications View","description":"If false, disables the Notifications history view on the lock screen, so users can’t view past notifications. However, they can still see notifications when they arrive. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlockscreennotificationsview_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlockscreennotificationsview_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowlockscreentodayview","displayName":"Allow Lock Screen Today View","description":"If false, disables the Today view in Notification Center on the lock screen. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlockscreentodayview_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlockscreentodayview_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmailprivacyprotection","displayName":"Allow Mail Privacy Protection","description":"If false, disables Mail Privacy Protection on the device. Available in iOS 15.2 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmailprivacyprotection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmailprivacyprotection_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmailsmartreplies","displayName":"Allow Mail Smart Replies (Deprecated)","description":"If false, disables smart replies in Mail.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmailsmartreplies_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmailsmartreplies_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmailsummary","displayName":"Allow Mail Summary (Deprecated)","description":"If false, disables the ability to create summaries of email messages manually. This does not affect automatic summary generation.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmailsummary_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmailsummary_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmanagedappscloudsync","displayName":"Allow Managed Apps Cloud Sync","description":"If false, prevents managed apps from using iCloud sync. Available in iOS 8 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmanagedappscloudsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmanagedappscloudsync_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmanagedtowriteunmanagedcontacts","displayName":"Allow Managed To Write Unmanaged Contacts","description":"If true, managed apps can write contacts to unmanaged contacts accounts. If Allow Open From Managed To Unmanaged is true, this restriction has no effect. If this restriction is set to true, you must install the payload through MDM. Available in iOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmanagedtowriteunmanagedcontacts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmanagedtowriteunmanagedcontacts_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmarketplaceappinstallation","displayName":"Allow Marketplace App Installation","description":"When 'false', the device prevents installation of alternative marketplace apps from the web, and prevents any installed alternative marketplace apps from installing apps.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmarketplaceappinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmarketplaceappinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmediasharingmodification","displayName":"Allow Media Sharing Modification","description":"If false, prevents modification of Media Sharing settings.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmediasharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmediasharingmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmultiplayergaming","displayName":"Allow Multiplayer Gaming","description":"If false, prohibits multiplayer gaming. Requires a supervised device. Available in iOS 4.1 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmultiplayergaming_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmultiplayergaming_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowmusicservice","displayName":"Allow Music Service","description":"If false, disables the Music service, and the Music app reverts to classic mode. Requires a supervised device. Available in iOS 9.3 and later, and macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmusicservice_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmusicservice_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allownews","displayName":"Allow News","description":"If false, disables News. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allownews_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allownews_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allownfc","displayName":"Allow NFC","description":"If false, disables NFC. Requires a supervised device. Available in iOS 14.2 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allownfc_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allownfc_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allownotestranscription","displayName":"Allow Notes Transcription (Deprecated)","description":"If false, disables transcription in Notes.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allownotestranscription_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allownotestranscription_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allownotestranscriptionsummary","displayName":"Allow Notes Transcription Summary (Deprecated)","description":"If `false`, disables transcription summarization in Notes.\n\nDeprecated: use the declarative management `com.apple.configuration.intelligence.settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allownotestranscriptionsummary_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allownotestranscriptionsummary_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allownotificationsmodification","displayName":"Allow Notifications Modification","description":"If false, disables modification of notification settings. Requires a supervised device. Available in iOS 9.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allownotificationsmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allownotificationsmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowopenfrommanagedtounmanaged","displayName":"Allow Open From Managed To Unmanaged","description":"If false, documents in managed apps and accounts only open in other managed apps and accounts. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowopenfrommanagedtounmanaged_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowopenfrommanagedtounmanaged_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowopenfromunmanagedtomanaged","displayName":"Allow Open From Unmanaged To Managed","description":"If false, documents in unmanaged apps and accounts only open in other unmanaged apps and accounts. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowopenfromunmanagedtomanaged_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowopenfromunmanagedtomanaged_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowotapkiupdates","displayName":"Allow OTAPKI Updates","description":"If false, disables over-the-air PKI updates. Setting this restriction to false doesn’t disable CRL and OCSP checks. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowotapkiupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowotapkiupdates_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpairedwatch","displayName":"Allow Paired Watch","description":"If false, disables pairing with an Apple Watch. Any currently paired Apple Watch is unpaired and the watch’s content is erased. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpairedwatch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpairedwatch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpassbookwhilelocked","displayName":"Allow Passbook While Locked","description":"If false, hides Passbook notifications from the lock screen. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpassbookwhilelocked_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpassbookwhilelocked_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpasscodemodification","displayName":"Allow Passcode Modification","description":"If false, prevents the device passcode from being added, changed, or removed. This restriction is ignored by Shared iPads. Requires a supervised device. Available in iOS 9 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpasscodemodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpasscodemodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpasswordautofill","displayName":"Allow Password Auto Fill","description":"If false, disables the AutoFill Passwords feature in iOS (with Keychain and third-party password managers) and the user isn’t prompted to use a saved password in Safari or in apps. This restriction also disables Automatic Strong Passwords, and strong passwords are no longer suggested to users. It doesn’t prevent AutoFill for contact info and credit cards in Safari. Requires a supervised device. Available in iOS 12 and later, and macOS 10.14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpasswordautofill_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpasswordautofill_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpasswordproximityrequests","displayName":"Allow Password Proximity Requests","description":"If false, disables requesting passwords from nearby devices. Requires a supervised device. Available in iOS 12 and later, and macOS 10.14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpasswordproximityrequests_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpasswordproximityrequests_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpasswordsharing","displayName":"Allow Password Sharing","description":"If false, disables sharing passwords with the Airdrop Passwords feature. Requires a supervised device. Available in iOS 12 and later, and macOS 10.14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpasswordsharing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpasswordsharing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpersonalhotspotmodification","displayName":"Allow Personal Hotspot Modification","description":"If false, disables modifications of the personal hotspot setting. Requires a supervised device. Available in iOS 12.2 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpersonalhotspotmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpersonalhotspotmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpersonalizedhandwritingresults","displayName":"Allow Personalized Handwriting Results (Deprecated)","description":"If false, prevents the system from generating text in the user's handwriting.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpersonalizedhandwritingresults_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpersonalizedhandwritingresults_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowphotostream","displayName":"Allow Photo Stream (Deprecated)","description":"If false, disables Photo Stream. Available in iOS 5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowphotostream_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowphotostream_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpodcasts","displayName":"Allow Podcasts","description":"If false, disables podcasts. Requires a supervised device. Available in iOS 8 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpodcasts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpodcasts_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowpredictivekeyboard","displayName":"Allow Predictive Keyboard (Deprecated)","description":"If false, disables predictive keyboards. Requires a supervised device. Available in iOS 8.1.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpredictivekeyboard_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpredictivekeyboard_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowprintersharingmodification","displayName":"Allow Printer Sharing Modification","description":"If 'false', prevents modifying Printer Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowprintersharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowprintersharingmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowproximitysetuptonewdevice","displayName":"Allow Proximity Setup To New Device","description":"If false, disables the prompt to set up new devices that are nearby. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowproximitysetuptonewdevice_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowproximitysetuptonewdevice_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowradioservice","displayName":"Allow Radio Service","description":"If false, disables Apple Music Radio. Requires a supervised device. Available in iOS 9.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowradioservice_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowradioservice_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowrapidsecurityresponseinstallation","displayName":"Allow Background Security Improvement Installation (Deprecated)","description":"If false, Rapid Security Response will be disabled. ","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowrapidsecurityresponseinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowrapidsecurityresponseinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowrapidsecurityresponseremoval","displayName":"Allow Background Security Improvement Removal (Deprecated)","description":"If false, users are unable to remove the Rapid Security Response option.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowrapidsecurityresponseremoval_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowrapidsecurityresponseremoval_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowrcsmessaging","displayName":"Allow RCS Messaging","description":"If false, prevents the use of RCS messaging.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowrcsmessaging_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowrcsmessaging_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowremoteappleeventsmodification","displayName":"Allow Remote Apple Events Modification","description":"If 'false', prevents modifying Remote Apple Events Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowremoteappleeventsmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowremoteappleeventsmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowremotescreenobservation","displayName":"Allow Remote Screen Observation","description":"If false, disables remote screen observation by the Classroom app. If Allow Screen Shot is set to false, the Classroom app doesn't observe remote screens. Required a supervised device until iOS 13 and macOS 10.15. Available in iOS 12 and later, and macOS 10.14.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowremotescreenobservation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowremotescreenobservation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowrosettausageawareness","displayName":"Allow Rosetta Usage Awareness","description":"If `false`, disables Rosetta usage awareness. When Rosetta usage awareness is active, the device displays a pop-up dialog to the user when launching an app that uses Rosetta. The pop-up dialog indicates that Rosetta will be removed in a future version of the operating system so that the user can contact the app vendor regarding a replacement for the current app.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowrosettausageawareness_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowrosettausageawareness_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsafari","displayName":"Allow Safari","description":"If false, disables the Safari web browser app, and its icon is removed from the Home screen. This setting also prevents users from opening web clips. As of iOS 13, requires a supervised device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsafari_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsafari_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsafarihistoryclearing","displayName":"Allow Safari History Clearing","description":"If `false`, the system disables the ability to clear browsing history in Safari.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsafarihistoryclearing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsafarihistoryclearing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsafariprivatebrowsing","displayName":"Allow Safari Private Browsing","description":"If `false`, the system disables the ability to use private browsing in Safari.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsafariprivatebrowsing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsafariprivatebrowsing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsafarisummary","displayName":"Allow Safari Summary (Deprecated)","description":"If false, disables the ability to summarize content in Safari.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsafarisummary_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsafarisummary_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsatelliteconnection","displayName":"Allow Satellite Connection","description":"If `false`, the system prohibits the connection to and use of satellite services.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsatelliteconnection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsatelliteconnection_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowscreenshot","displayName":"Allow Screen Shot","description":"If false, disables saving a screenshot of the display and capturing a screen recording. It also disables the Classroom app from observing remote screens. Available in iOS 4 and later, and macOS 10.14.4 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowscreenshot_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowscreenshot_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowshareddevicetemporarysession","displayName":"Allow Shared Device Temporary Session","description":"If false, temporary sessions aren’t available on Shared iPad. Available in iOS 13.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowshareddevicetemporarysession_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowshareddevicetemporarysession_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsharedstream","displayName":"Allow Shared Stream","description":"If false, disables Shared Photo Stream. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsharedstream_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsharedstream_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowspellcheck","displayName":"Allow Spell Check (Deprecated)","description":"If false, disables keyboard spell-check. Requires a supervised device. Available in iOS 8.1.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowspellcheck_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowspellcheck_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowspotlightinternetresults","displayName":"Allow Spotlight Internet Results","description":"If false, disables Spotlight Internet search results in Siri Suggestions. Available in iOS 8 and later, and macOS 10.11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowspotlightinternetresults_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowspotlightinternetresults_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowstartupdiskmodification","displayName":"Allow Startup Disk Modification","description":"If 'false', prevents modification of Startup Disk setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowstartupdiskmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowstartupdiskmodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowsystemappremoval","displayName":"Allow System App Removal","description":"If false, disables the removal of system apps from the device. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsystemappremoval_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsystemappremoval_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowtimemachinebackup","displayName":"Allow Time Machine Backup","description":"If 'false', prevents modification of Time Machine settings in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowtimemachinebackup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowtimemachinebackup_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowuiappinstallation","displayName":"Allow UI App Installation","description":"If false, disables the App Store, and its icon is removed from the Home screen. However, users may continue to use host apps (iTunes, Configurator) to install or update their apps. In iOS 10 and later, MDM commands can override this restriction. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowuiappinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowuiappinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowuiconfigurationprofileinstallation","displayName":"Allow UI Configuration Profile Installation","description":"If false, prohibits the user from installing configuration profiles and certificates interactively. Requires a supervised device. Available in iOS 6 and later and macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowuiconfigurationprofileinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowuiconfigurationprofileinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowuniversalcontrol","displayName":"Allow Universal Control","description":"If false, disables Universal Control. Available in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowuniversalcontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowuniversalcontrol_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowunmanagedtoreadmanagedcontacts","displayName":"Allow Unmanaged To Read Managed Contacts","description":"If true, unmanaged apps can read from managed contacts accounts. If Allow Open From Managed To Unmanaged is true, this restriction has no effect. If this restriction is set to true, you must install the payload through MDM. Available in iOS 12 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowunmanagedtoreadmanagedcontacts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowunmanagedtoreadmanagedcontacts_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowunpairedexternalboottorecovery","displayName":"Allow Unpaired External Boot To Recovery","description":"If true, allows devices to be booted into recovery by an unpaired device. Requires a supervised device. Available in iOS 14.5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowunpairedexternalboottorecovery_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowunpairedexternalboottorecovery_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowuntrustedtlsprompt","displayName":"Allow Untrusted TLS Prompt","description":"If false, automatically rejects untrusted HTTPS certificates without prompting the user. Available in iOS 5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowuntrustedtlsprompt_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowuntrustedtlsprompt_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowusbrestrictedmode","displayName":"Allow USB Restricted Mode","description":"If false, allows the device to always connect to USB accessories while locked. On macOS, allows new USB accessories to connect without authorization.\r\nRequires a supervised device. Available in iOS 11.4.1 and later and macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowusbrestrictedmode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowusbrestrictedmode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowvideoconferencing","displayName":"Allow Video Conferencing","description":"If false, hides the FaceTime app. As of iOS 13, requires a supervised device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowvideoconferencing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowvideoconferencing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowvideoconferencingremotecontrol","displayName":"Allow Video Conferencing Remote Control (Deprecated)","description":"If `false`, disables the ability for a remote FaceTime session to request control of the device.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowvideoconferencingremotecontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowvideoconferencingremotecontrol_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowvisualintelligencesummary","displayName":"Allow Visual Intelligence Summary (Deprecated)","description":"If `false`, the system disables visual intelligence summarization.\n\nDeprecated: use the declarative management `com.apple.configuration.intelligence.settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowvisualintelligencesummary_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowvisualintelligencesummary_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowvoicedialing","displayName":"Allow Voice Dialing (Deprecated)","description":"If false, disables voice dialing if the device is locked with a passcode. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowvoicedialing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowvoicedialing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowvpncreation","displayName":"Allow VPN Creation","description":"If false, disables the creation of VPN configurations. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowvpncreation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowvpncreation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowwallpapermodification","displayName":"Allow Wallpaper Modification","description":"If false, prevents wallpaper from being changed. Requires a supervised device. Available in iOS 9 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowwallpapermodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowwallpapermodification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowwebdistributionappinstallation","displayName":"Allow Web Distribution App Installation","description":"When 'false', the device prevents installation of apps directly from the web.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowwebdistributionappinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowwebdistributionappinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_allowwritingtools","displayName":"Allow Writing Tools (Deprecated)","description":"If false, disables Apple Intelligence writing tools.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowwritingtools_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowwritingtools_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_autonomoussingleappmodepermittedappids","displayName":"Autonomous Single App Mode Permitted App IDs","description":"If present, allows apps identified by the bundle IDs listed in the array to autonomously enter Single App Mode. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_blockedappbundleids","displayName":"Blocked App Bundle IDs","description":"If present, prevents bundle IDs listed in the array from being shown or launchable. Include the value com.apple.webapp to restrict all webclips. Requires a supervised device. Available in iOS 9.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_com.apple.applicationaccess","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_deniediccidsforimessagefacetime","displayName":"Denied ICCIDs For iMessage And FaceTime","description":"An array of strings representing ICCIDs of cellular plans. The device prevents use of any matching cellular networks in iMessage and FaceTime. The array must contain no more than 4 ICCID strings.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_deniediccidsforrcs","displayName":"Denied ICCIDs For RCS","description":"An array of strings representing ICCIDs of cellular plans. The device prevents use of any matching cellular networks with RCS messaging. The array must contain no more than 4 ICCID strings.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_enforcedfingerprinttimeout","displayName":"Enforced Fingerprint Timeout","description":"The value, in seconds, after which the fingerprint unlock will require a password to authenticate. The default value is 48 hours.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_enforcedsoftwareupdatedelay","displayName":"Enforced Software Update Delay (Deprecated)","description":"Sets how many days to delay a software update on the device. With this restriction in place, the user doesn't see a software update until the specified number of days after the software update release date. This value is used by Force Delayed App Software Updates and Force Delayed Software Updates. Requires a supervised device in iOS. Available in iOS 11.3 and later, and macOS 10.13.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_enforcedsoftwareupdatemajorosdeferredinstalldelay","displayName":"Enforced Software Update Major OS Deferred Install Delay (Deprecated)","description":"This restriction allows the admin to set how many days to delay a major software update on the device. When this restriction is in place the user sees a software update only after the specified delay after the release of the software update. This value controls the delay for Force Delayed Major Software Updates. Available in macOS 11.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_enforcedsoftwareupdateminorosdeferredinstalldelay","displayName":"Enforced Software Update Minor OS Deferred Install Delay (Deprecated)","description":"This restriction allows the admin to set how many days to delay a minor OS software update on the device. When this restriction is in place the user see a software update only after the specified delay after the release of the software update. This value controls the delay for Force Delayed Software Updates. Available in macOS 11.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_enforcedsoftwareupdatenonosdeferredinstalldelay","displayName":"Enforced Software Update Non OS Deferred Install Delay (Deprecated)","description":"This restriction allows the admin to set how many days to delay an app software update on the device. When this restriction is in place the user sees a non-OS software update only after the specified delay after the release of the software. This value controls the delay for Force Delayed App Software Updates. Available in macOS 11.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_forceairdropunmanaged","displayName":"Force AirDrop Unmanaged","description":"If true, causes AirDrop to be considered an unmanaged drop target. Available in iOS 9 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceairdropunmanaged_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceairdropunmanaged_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceairplayoutgoingrequestspairingpassword","displayName":"Force AirPlay Outgoing Requests Pairing Password","description":"If true, forces all devices receiving AirPlay requests from this device to use a pairing password. Available in iOS 7.1 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceairplayoutgoingrequestspairingpassword_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceairplayoutgoingrequestspairingpassword_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceairprinttrustedtlsrequirement","displayName":"Force AirPrint Trusted TLS Requirement","description":"If true, requires trusted certificates for TLS printing communication. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceairprinttrustedtlsrequirement_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceairprinttrustedtlsrequirement_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceassistantprofanityfilter","displayName":"Force Assistant Profanity Filter (Deprecated)","description":"If true, forces the use of the profanity filter assistant. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceassistantprofanityfilter_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceassistantprofanityfilter_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceauthenticationbeforeautofill","displayName":"Force Authentication Before Auto Fill","description":"If true, the user must authenticate before passwords or credit card information can be autofilled in Safari and Apps. If this restriction isn’t enforced, the user can toggle this feature in Settings. Only supported on devices with Face ID or Touch ID. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceauthenticationbeforeautofill_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceauthenticationbeforeautofill_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceautomaticdateandtime","displayName":"Force Automatic Date And Time","description":"If true, enables the Set Automatically feature in Date & Time and can’t be disabled by the user. The device’s time zone is updated only when the device can determine its location using a cellular connection or Wi-Fi with location services enabled. Requires a supervised device. Available in iOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceautomaticdateandtime_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceautomaticdateandtime_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcebypassscreencapturealert","displayName":"Force Bypass Screen Capture Alert","description":"If set to true, then the presentation of a screen capture alert will be bypassed.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcebypassscreencapturealert_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcebypassscreencapturealert_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcecaptiveportalconnectionfromlockscreen","displayName":"Force Captive Portal Connection From Lock Screen","description":"If `true`, the system allows use of the captive WiFi portal at login or unlock.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcecaptiveportalconnectionfromlockscreen_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcecaptiveportalconnectionfromlockscreen_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceclassroomautomaticallyjoinclasses","displayName":"Force Classroom Automatically Join Classes","description":"If true, automatically gives permission to the teacher’s requests without prompting the student. Requires a supervised device. Available in iOS 11 and later, and macOS 10.14.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceclassroomautomaticallyjoinclasses_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceclassroomautomaticallyjoinclasses_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceclassroomrequestpermissiontoleaveclasses","displayName":"Force Classroom Request Permission To Leave Classes","description":"If true, a student enrolled in an unmanaged course through Classroom requests permission from the teacher when attempting to leave the course. Requires a supervised device. Available in iOS 11.3 and later, and macOS 10.14.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceclassroomrequestpermissiontoleaveclasses_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceclassroomrequestpermissiontoleaveclasses_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceclassroomunpromptedappanddevicelock","displayName":"Force Classroom Unprompted App And Device Lock","description":"If true, allows the teacher to lock apps or the device without prompting the student. Requires a supervised device. Available in iOS 11 and later, and macOS 10.14.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceclassroomunpromptedappanddevicelock_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceclassroomunpromptedappanddevicelock_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceclassroomunpromptedscreenobservation","displayName":"Force Classroom Unprompted Screen Observation","description":"If `true` and `ScreenObservationPermissionModificationAllowed` is also `true` in the Education payload, a student enrolled in a managed course through the Classroom app automatically gives permission to that course teacher's requests to observe the student's screen without prompting the student.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceclassroomunpromptedscreenobservation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceclassroomunpromptedscreenobservation_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcedelayedappsoftwareupdates","displayName":"Force Delayed App Software Updates (Deprecated)","description":"If set to true, delays user visibility of major OS Software Updates. Available in macOS 11.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcedelayedappsoftwareupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcedelayedappsoftwareupdates_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcedelayedmajorsoftwareupdates","displayName":"Force Delayed Major Software Updates (Deprecated)","description":"If true, delays user visibility of non-OS Software Updates. Requires a supervised device. Visibility of Operating System updates is controlled through Force Delayed Software Updates. The delay is 30 days unless Enforced Software Update Delay is set to another value. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcedelayedmajorsoftwareupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcedelayedmajorsoftwareupdates_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcedelayedsoftwareupdates","displayName":"Force Delayed Software Updates (Deprecated)","description":"If true, delays user visibility of software updates. In macOS, seed build updates are allowed, without delay. The delay is 30 days unless Enforced Software Update Delay is set to another value. Available in iOS 11.3 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcedelayedsoftwareupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcedelayedsoftwareupdates_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceencryptedbackup","displayName":"Force Encrypted Backup","description":"If true, encrypts all backups. Available in iOS 4 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceencryptedbackup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceencryptedbackup_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceitunesstorepasswordentry","displayName":"Force iTunes Store Password Entry (Deprecated)","description":"If true, forces the user to enter their iTunes password for each transaction. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceitunesstorepasswordentry_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceitunesstorepasswordentry_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcelimitadtracking","displayName":"Force Limit Ad Tracking","description":"If true, limits ad tracking. Additionally, it disables app tracking and the Allow Apps To Request To Track setting. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcelimitadtracking_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcelimitadtracking_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceondeviceonlydictation","displayName":"Force On Device Only Dictation (Deprecated)","description":"If true, disables connections to Siri servers for the purposes of dictation. Available in iOS 14.5 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceondeviceonlydictation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceondeviceonlydictation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forceondeviceonlytranslation","displayName":"Force On Device Only Translation (Deprecated)","description":"If true, the device won’t connect to Siri servers for the purposes of translation. Available in iOS 15 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceondeviceonlytranslation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceondeviceonlytranslation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcepreserveesimonerase","displayName":"Force Preserve ESIM On Erase","description":"If set to true, eSIM will be preserved when a device is erased due to too many failed password attempt or the \"Erase All Content and Settings\" option in Settings > General > Reset. eSIM will not be preserved if the device is erased by FindMy.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcepreserveesimonerase_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcepreserveesimonerase_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcewatchwristdetection","displayName":"Force Watch Wrist Detection","description":"If true, forces a paired Apple Watch to use Wrist Detection. Available in iOS 8.2 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcewatchwristdetection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcewatchwristdetection_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcewificonfigurationonlockscreen","displayName":"Force Wifi Configuration On Lock Screen","description":"If `true`, the system allows the user to select WiFi networks at login or unlock.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcewificonfigurationonlockscreen_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcewificonfigurationonlockscreen_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcewifipoweron","displayName":"Force WiFi Power On","description":"If true, prevents Wi-Fi from being turned off in Settings or Control Center, even by entering or leaving Airplane Mode. It doesn’t prevent selecting which Wi-Fi network to use. Requires a supervised device. Available in iOS 13.0 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcewifipoweron_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcewifipoweron_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_forcewifitoallowednetworksonly","displayName":"Force WiFi To Allowed Networks Only","description":"If true, limits device to only join Wi-Fi networks set-up via configuration profile. Requires a supervised device. Available in iOS 14.5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcewifitoallowednetworksonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcewifitoallowednetworksonly_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsau","displayName":"Rating Apps - Australia","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsau_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsau_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsca","displayName":"Rating Apps - Canada","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsca_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsde","displayName":"Rating Apps - Germany","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsde_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsde_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsexemptedbundleids","displayName":"Rating Apps Exempted Bundle IDs","description":"If present, the system exempts apps with bundle IDs in the array from age-based rating restrictions. The system uses intersection combine rules to combine multiple payloads and any exceptions that parental control apps provide, including ScreenTime.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},{"id":"com.apple.applicationaccess_ratingappsfr","displayName":"Rating Apps - France","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsfr_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsgb","displayName":"Rating Apps - Great Britain","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsgb_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsgb_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsie","displayName":"Rating Apps - Ireland","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsie_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsie_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsjp","displayName":"Rating Apps - Japan","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsjp_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsnz","displayName":"Rating Apps - New Zealand","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsnz_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_22","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingappsus","displayName":"Rating Apps - United States","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsus_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsus_1","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsus_2","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsus_3","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsus_4","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsus_5","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesau","displayName":"Rating Movies - Australia","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesau_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_2","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_3","displayName":"M","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_4","displayName":"MA15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_5","displayName":"R18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_6","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesca","displayName":"Rating Movies - Canada","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesca_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesca_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesca_2","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesca_3","displayName":"14A","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesca_4","displayName":"18A","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesca_5","displayName":"R","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesca_6","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesde","displayName":"Rating Movies - Germany","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesde_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesde_1","displayName":"Ab 0 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesde_2","displayName":"Ab 6 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesde_3","displayName":"Ab 12 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesde_4","displayName":"Ab 16 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesde_5","displayName":"Ab 18 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesde_6","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesfr","displayName":"Rating Movies - France","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesfr_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesfr_2","displayName":"10","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesfr_3","displayName":"12","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesfr_4","displayName":"16","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesfr_5","displayName":"18","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesfr_6","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesgb","displayName":"Rating Movies - Great Britain","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesgb_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_1","displayName":"U","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_2","displayName":"UC","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_3","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_4","displayName":"12","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_5","displayName":"12A","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_6","displayName":"15","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_7","displayName":"18","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesgb_8","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesie","displayName":"Rating Movies - Ireland","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesie_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_2","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_3","displayName":"12A","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_4","displayName":"15A","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_5","displayName":"16","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_6","displayName":"18","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesie_7","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesjp","displayName":"Rating Movies - Japan","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesjp_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesjp_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesjp_2","displayName":"PG-12","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesjp_3","displayName":"R15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesjp_4","displayName":"R18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesjp_5","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesnz","displayName":"Rating Movies - New Zealand","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesnz_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_2","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_3","displayName":"M","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_4","displayName":"R13","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_5","displayName":"R15","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_6","displayName":"R16","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_7","displayName":"R18","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_8","displayName":"R","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_9","displayName":"RP16","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesnz_10","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingmoviesus","displayName":"Rating Movies - United States","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesus_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesus_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesus_2","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesus_3","displayName":"PG-13","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesus_4","displayName":"R","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesus_5","displayName":"NC-17","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesus_6","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingregion","displayName":"Rating Region","description":"The country key that profile tools use to display the proper ratings for the given region. This data isn’t recognized or reported by the client.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingregion_0","displayName":"United States","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_1","displayName":"Australia","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_2","displayName":"Canada","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_3","displayName":"Germany","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_4","displayName":"France","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_5","displayName":"Ireland","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_6","displayName":"Japan","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_7","displayName":"New Zealand","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingregion_8","displayName":"Great Britain","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsau","displayName":"Rating TV Shows - Australia","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsau_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_1","displayName":"P","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_2","displayName":"C","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_3","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_4","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_5","displayName":"M","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_6","displayName":"MA15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_7","displayName":"AV15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_8","displayName":"All","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_9","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsca","displayName":"Rating TV Shows - Canada","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsca_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_1","displayName":"C","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_2","displayName":"C8","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_3","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_4","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_5","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_6","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsca_7","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsde","displayName":"Rating TV Shows - Germany","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsde_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_1","displayName":"Ab 0 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_2","displayName":"Ab 6 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_3","displayName":"Ab 12 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_4","displayName":"Ab 16 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_5","displayName":"Ab 18 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_7","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsfr","displayName":"Rating TV Shows - France","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsfr_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_1","displayName":"-10","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_2","displayName":"-12","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_3","displayName":"-16","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_4","displayName":"-18","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_5","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsgb","displayName":"Rating TV Shows - Great Britain","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsgb_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsgb_1","displayName":"Caution","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsgb_2","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsie","displayName":"Rating TV Shows - Ireland","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsie_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsie_1","displayName":"GA","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsie_2","displayName":"CH","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsie_3","displayName":"YA","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsie_4","displayName":"PS","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsie_5","displayName":"MA","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsie_6","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsjp","displayName":"Rating TV Shows - Japan","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsjp_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsjp_1","displayName":"Explicit Allowed","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsjp_2","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsnz","displayName":"Rating TV Shows - New Zealand","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsnz_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsnz_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsnz_2","displayName":"PGR","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsnz_3","displayName":"AO","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsnz_4","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_ratingtvshowsus","displayName":"Rating TV Shows - United States","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsus_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_1","displayName":"TV-Y","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_2","displayName":"TV-Y7","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_3","displayName":"TV-G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_4","displayName":"TV-PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_5","displayName":"TV-14","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_6","displayName":"TB-MA","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_7","displayName":"All","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_requiremanagedpasteboard","displayName":"Require Managed Pasteboard","description":"If true, copy and paste functionality respects the Allow Open From Managed To Unmanaged and Allow Open From Unmanaged To Managed restrictions. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_requiremanagedpasteboard_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_requiremanagedpasteboard_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_safariacceptcookies","displayName":"Safari Accept Cookies","description":"This value defines the conditions under which the device accepts cookies. The user-facing settings changed in iOS 11, although the possible values remain the same. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariacceptcookies_0","displayName":"Prevent Cross-Site Tracking and Block All Cookies are enabled and the user canʼt disable either setting.","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariacceptcookies_1","displayName":"Prevent Cross-Site Tracking is enabled and the user canʼt disable it. Block All Cookies is not enabled, although the user can enable it.","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariacceptcookies_2","displayName":"Prevent Cross-Site Tracking is enabled and Block All Cookies is not enabled. The user can toggle either setting.","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_safariallowautofill","displayName":"Safari Allow Autofill","description":"If false, disables Safari AutoFill for passwords, contact info, and credit cards and also prevents the Keychain from being used for AutoFill. Though third-party password managers are allowed and apps can use AutoFill. As of iOS 13, requires a supervised device. Available in iOS 4 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariallowautofill_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariallowautofill_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_safariallowjavascript","displayName":"Safari Allow Java Script","description":"If false, Safari doesn’t execute JavaScript. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariallowjavascript_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariallowjavascript_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_safariallowpopups","displayName":"Safari Allow Popups","description":"If false, Safari doesn’t allow pop-up windows. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariallowpopups_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariallowpopups_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess_safariforcefraudwarning","displayName":"Safari Force Fraud Warning","description":"If true, enables Safari fraud warning. Available in iOS 4 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariforcefraudwarning_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariforcefraudwarning_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.applicationaccess.new_com.apple.applicationaccess.new","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f019963f-f4ed-4429-b6e3-babfb24c36a8","categoryName":"Parental Controls Application Restrictions","options":null},{"id":"com.apple.applicationaccess.new_familycontrolsenabled","displayName":"Family Controls Enabled","description":"If true, enables app access restrictions.","helpText":null,"infoUrls":[],"categoryId":"f019963f-f4ed-4429-b6e3-babfb24c36a8","categoryName":"Parental Controls Application Restrictions","options":[{"id":"com.apple.applicationaccess.new_familycontrolsenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess.new_familycontrolsenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.appstore_com.apple.appstore","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","categoryName":"App Store","options":null},{"id":"com.apple.appstore_disablesoftwareupdatenotifications","displayName":"Disable Software Update Notifications","description":"If true, disables software update notifications. Available in macOS 10.10 and later.","helpText":null,"infoUrls":[],"categoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","categoryName":"App Store","options":[{"id":"com.apple.appstore_disablesoftwareupdatenotifications_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.appstore_disablesoftwareupdatenotifications_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.appstore_restrict-store-disable-app-adoption","displayName":"Restrict-store-disable-app-adoption","description":"If true, disables app adoption by users. Available in macOS 10.10 and later.","helpText":null,"infoUrls":[],"categoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","categoryName":"App Store","options":[{"id":"com.apple.appstore_restrict-store-disable-app-adoption_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.appstore_restrict-store-disable-app-adoption_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.appstore_restrict-store-softwareupdate-only","displayName":"Restrict Store Software Update Only","description":"If true, prevents App Store from launching. Available in macOS 10.14 and later. Restricts installations to software updates only in macOS 10.10 - 10.13.","helpText":null,"infoUrls":[],"categoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","categoryName":"App Store","options":[{"id":"com.apple.appstore_restrict-store-softwareupdate-only_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.appstore_restrict-store-softwareupdate-only_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.asam_allowedapplications","displayName":"Allowed Applications","description":"An array of dictionaries that specifies the apps that can be granted access to the Accessibility APIs.","helpText":null,"infoUrls":[],"categoryId":"daa2ea69-8026-465a-942c-75eb0396d5b9","categoryName":"Autonomous Single App Mode","options":null},{"id":"com.apple.asam_allowedapplications_item_bundleidentifier","displayName":"Bundle Identifier","description":"The unique bundle identifier. If two dictionaries contain the same Bundle Identifier value but a different Team Identifier value, this will be considered an error and the profile won't be installed.","helpText":null,"infoUrls":[],"categoryId":"daa2ea69-8026-465a-942c-75eb0396d5b9","categoryName":"Autonomous Single App Mode","options":null},{"id":"com.apple.asam_allowedapplications_item_teamidentifier","displayName":"Team Identifier","description":"The developer's team identifier, used when the app was signed.","helpText":null,"infoUrls":[],"categoryId":"daa2ea69-8026-465a-942c-75eb0396d5b9","categoryName":"Autonomous Single App Mode","options":null},{"id":"com.apple.asam_com.apple.asam","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"daa2ea69-8026-465a-942c-75eb0396d5b9","categoryName":"Autonomous Single App Mode","options":null},{"id":"com.apple.assetcache.managed_allowcachedelete","displayName":"Allow Cache Delete","description":"Allow the system to purge content from the cache automatically when it needs disk space for other apps (i.e. when free disk space runs low on the computer). Customers who want Content Caching to be as effective as possible should turn this setting off.\r\nAvailable in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_allowcachedelete_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_allowcachedelete_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_allowpersonalcaching","displayName":"Allow Personal Caching","description":"If true, caches the user's iCloud data. Clients may take some time (hours or days) to react to changes to this setting; it doesn't have an immediate effect.\r\nAt least one of the Allow Personal Caching or Allow Shared Caching settings must be true.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_allowpersonalcaching_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_allowpersonalcaching_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_allowsharedcaching","displayName":"Allow Shared Caching","description":"If true, caches non-iCloud content, such as apps and software updates. Clients may take some time (hours, days) to react to changes to this setting; it does not have an immediate effect.\r\nAt least one of the Allow Personal Caching or Allow Shared Caching settings must be true. ","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_allowsharedcaching_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_allowsharedcaching_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_autoactivation","displayName":"Auto Activation","description":"If true, automatically activates the content cache when possible and prevents it from being disabled. If the Allow Content Caching restriction is set to false, Auto Activation is also false.\r\nRemoving a profile that set Auto Activation to true does not deactivate the Content Cache.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_autoactivation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_autoactivation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_autoenabletetheredcaching","displayName":"Auto Enable Tethered Caching","description":"Automatically enable Internet connection sharing when possible and prevent disabling Internet connection sharing. Deny Tethered Caching overrides Auto Enable Tethered Caching. Tethered caching requires Content Caching. Available in macOS 10.15.4 and later.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_autoenabletetheredcaching_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_autoenabletetheredcaching_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_cachelimit","displayName":"Cache Limit","description":"The maximum number of bytes of disk space that will be used for the content cache. A value of 0 means unlimited disk space.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_com.apple.assetcache.managed","displayName":"Top Level Setting Group Collection","description":"com.apple.AssetCache.managed","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_datapath","displayName":"Data Path","description":"The path to the directory used to store cached content. Changing this setting manually doesn't automatically move cached content from the old location to the new one. To move content automatically, use the Sharing preference's Content Caching pane. The value must be (or end with) /Library/Application Support/Apple/AssetCache/Data.\r\nA directory and its intermediates are created for the given data path if it doesn't already exist. The directory is owned by _assetcache:_assetcache and has mode 0750. Its immediate parent directory (.../Library/Application Support/Apple/AssetCache) is owned by _assetcache:_assetcache and has mode 0755. ","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_denytetheredcaching","displayName":"Deny Tethered Caching","description":"If true, disables tethered caching.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_denytetheredcaching_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_denytetheredcaching_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_displayalerts","displayName":"Display Alerts","description":"If true, Content Caching displays exceptional conditions (alerts) as system notifications in the upper corner of the screen. Alerts were automatically displayed starting in macOS 10.13. In macOS 10.15 the alerts are off by default, but still available via this setting.\r\nAvailable in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_displayalerts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_displayalerts_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_keepawake","displayName":"Keep Awake","description":"If true, prevents the computer from sleeping as long as Content Caching is on (System Preferences > Sharing > Content Caching is on). Customers who want Content Caching to be as available as musch as possible should turn this setting on.\r\nAvailable in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_keepawake_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_keepawake_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_listenranges","displayName":"Listen Ranges","description":"The range of client IP addresses to serve.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_listenranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_listenranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_listenranges_item_type","displayName":"IP Address Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_listenranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_listenranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_listenrangesonly","displayName":"Listen Ranges Only","description":"If true, the content cache provides content to the clients in the Listen Ranges.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_listenrangesonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_listenrangesonly_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_listenwithpeersandparents","displayName":"Listen With Peers And Parents","description":"If true, the content cache provides content to the clients in the union of the Listen Ranges, Peer Listen Ranges and Parents.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_listenwithpeersandparents_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_listenwithpeersandparents_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_localsubnetsonly","displayName":"Local Subnets Only","description":"If true, the content cache offers content to clients only on the same immediate local network only. No content is offered to clients on other networks reachable by the content cache. If LocalSubnetsOnly is set to true, ListenRanges will be ignored.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_localsubnetsonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_localsubnetsonly_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_logclientidentity","displayName":"Log Client Identity","description":"If true, the Content Cache logs the IP address and port number of the clients that request content. ","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_logclientidentity_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_logclientidentity_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_parents","displayName":"Parents","description":"An array of the local IP addresses of other content caches that this cache should download from or upload to, instead of downloading from or uploading to Apple directly. Invalid addresses and addresses of computers that aren't content caches are ignored. Parent caches that become unavailable are skipped. If all parent content caches become unavailable, the content cache downloads from or uploads to Apple directly, until a parent content cache becomes available again.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy","displayName":"Parent Selection Policy","description":"The policy to implement when choosing among more than one configured parent content cache. With every policy, parent caches that are temporarily unavailable are skipped.\r\nfirst-available: Always use the first available parent in the Parents list. Use this policy to designate permanent primary, secondary, and subsequent parents.\r\n\r\nurl-path-hash: Hash the path part of the requested URL so that the same parent is always used for the same URL. This is useful for maximizing the size of the combined caches of the parents.\r\n\r\nrandom: Choose a parent at random. Use this policy for load balancing.\r\n\r\nround-robin: Rotate through the parents in order. Use this policy for load balancing.\r\n\r\nsticky-available: Use the first available parent that is available in the Parents list until it becomes unavailable, then advance to the next one. Use this policy for designating floating primary, secondary, and subsequent parents. ","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_parentselectionpolicy_0","displayName":"first-available","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_1","displayName":"url-path-hash","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_2","displayName":"random","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_3","displayName":"round-robin","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_4","displayName":"sticky-available","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_peerfilterranges","displayName":"Peer Filter Ranges","description":"The ranges of peer IP addresses that the content cache uses to filter its list of peers to query for content. The content cache only queries peers in Peer Filter Ranges. When Peer Filter Ranges is an empty array, the content cache doesn't query any peers.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_peerfilterranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_peerfilterranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_peerfilterranges_item_type","displayName":"IP Address Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_peerfilterranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_peerfilterranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_peerlistenranges","displayName":"Peer Listen Ranges","description":"The ranges of peer IP addresses the content cache responds to. When Peer Listen Ranges is an empty array, the content cache responds with an error to all cache queries.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_peerlistenranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_peerlistenranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_peerlistenranges_item_type","displayName":"IP Address Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_peerlistenranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_peerlistenranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_peerlocalsubnetsonly","displayName":"Peer Local Subnets Only","description":"If true, the content cache only peers with other content caches on the same immediate local network, rather than with content caches that use the same public IP address as the device. When Peer Local Subnets Only is true, it overrides the configuration of Peer Filter Ranges and Peer Listen Ranges. If the network changes, the local network peering restrictions update appropriately. If false, the content cache defers to Peer Filter Ranges and Peer Listen Ranges for configuring the peering restrictions.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_peerlocalsubnetsonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_peerlocalsubnetsonly_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.assetcache.managed_port","displayName":"Port","description":"The TCP port number on which the content cache accepts requests for uploads or downloads. Set the port to 0 to pick a random, available port.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_publicranges","displayName":"Public Ranges","description":"The ranges of public IP addresses that the cloud servers should use for matching clients to content caches.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_publicranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_publicranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},{"id":"com.apple.assetcache.managed_publicranges_item_type","displayName":"IP Address Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_publicranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_publicranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},{"id":"com.apple.associated-domains_com.apple.associated-domains","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8efd284f-5a56-4da8-8821-f51984ff954d","categoryName":"Associated Domains","options":null},{"id":"com.apple.associated-domains_configuration","displayName":"Configuration","description":"Map apps to their associated domains.","helpText":null,"infoUrls":[],"categoryId":"8efd284f-5a56-4da8-8821-f51984ff954d","categoryName":"Associated Domains","options":null},{"id":"com.apple.associated-domains_configuration_item_applicationidentifier","displayName":"Application Identifier","description":"The app identifier to associate the domains with.","helpText":null,"infoUrls":[],"categoryId":"8efd284f-5a56-4da8-8821-f51984ff954d","categoryName":"Associated Domains","options":null},{"id":"com.apple.associated-domains_configuration_item_associateddomains","displayName":"Associated Domains","description":"The domains to be associated with the app. Each string is in the form of \"service:domain\". Domains should be fully qualified hostnames, like www.example.com.","helpText":null,"infoUrls":[],"categoryId":"8efd284f-5a56-4da8-8821-f51984ff954d","categoryName":"Associated Domains","options":null},{"id":"com.apple.associated-domains_configuration_item_enabledirectdownloads","displayName":"Enable Direct Downloads","description":"If true, data for this domain should be downloaded directly instead of through a CDN. The entitlement value for this domain must be set to service:domain?mode=managed or this value will be ignored. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"8efd284f-5a56-4da8-8821-f51984ff954d","categoryName":"Associated Domains","options":[{"id":"com.apple.associated-domains_configuration_item_enabledirectdownloads_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.associated-domains_configuration_item_enabledirectdownloads_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.caldav.account_caldavaccountdescription","displayName":"Cal DAV Account Description","description":"The description of the account.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.caldav.account_caldavhostname","displayName":"Cal DAV Host Name","description":"The server’s address.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.caldav.account_caldavpassword","displayName":"Cal DAV Password","description":"The user’s password. This is only used with encrypted profiles.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.caldav.account_caldavport","displayName":"Cal DAV Port","description":"The server’s port.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.caldav.account_caldavprincipalurl","displayName":"Cal DAV Principal URL","description":"The base URL to the user’s calendar.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.caldav.account_caldavusername","displayName":"Cal DAV Username","description":"The user name for logins.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.caldav.account_caldavusessl","displayName":"Cal DAV Use SSL","description":"If true, enables SSL.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":[{"id":"com.apple.caldav.account_caldavusessl_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.caldav.account_caldavusessl_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.caldav.account_com.apple.caldav.account","displayName":"Top Level Setting Group Collection","description":"com.apple.caldav.account","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},{"id":"com.apple.carddav.account_carddavaccountdescription","displayName":"Card DAV Account Description","description":"The description of the account.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.carddav.account_carddavhostname","displayName":"Card DAV Host Name","description":"The server’s address.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.carddav.account_carddavpassword","displayName":"Card DAV Password","description":"The user’s password.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.carddav.account_carddavport","displayName":"Card DAV Port","description":"The server’s port.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.carddav.account_carddavprincipalurl","displayName":"Card DAV Principal URL","description":"The base URL to the user’s address book.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.carddav.account_carddavusername","displayName":"Card DAV Username","description":"The user name for logins.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.carddav.account_carddavusessl","displayName":"Card DAV Use SSL","description":"If true, enables SSL.","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":[{"id":"com.apple.carddav.account_carddavusessl_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.carddav.account_carddavusessl_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.carddav.account_com.apple.carddav.account","displayName":"Top Level Setting Group Collection","description":"com.apple.carddav.account","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},{"id":"com.apple.cellular_apns","displayName":"APNs","description":"An array of access point dictionaries.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmask","displayName":"Allowed Protocol Mask","description":"The supported Internet Protocol versions. Available in iOS 10.3 and later.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_allowedprotocolmask_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmask_1","displayName":"IPv6","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmask_2","displayName":"Both","description":null,"helpText":null}]},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming","displayName":"Allowed Protocol Mask In Domestic Roaming","description":"The supported Internet Protocol versions while roaming domestically. Available in iOS 10.3 and later.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming_1","displayName":"IPv6","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming_2","displayName":"Both","description":null,"helpText":null}]},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming","displayName":"Allowed Protocol Mask In Roaming","description":"The supported Internet Protocol versions while roaming. Available in iOS 10.3 and later.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming_1","displayName":"IPv6","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming_2","displayName":"Both","description":null,"helpText":null}]},{"id":"com.apple.cellular_apns_item_authenticationtype","displayName":"Authentication Type","description":"The authentication type for logging in.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_authenticationtype_0","displayName":"CHAP","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_authenticationtype_1","displayName":"PAP","description":null,"helpText":null}]},{"id":"com.apple.cellular_apns_item_enablexlat464","displayName":"Enable XLAT464","description":"If true, enables XLAT464. Available in iOS 16 and later.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_enablexlat464_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_enablexlat464_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.cellular_apns_item_name","displayName":"Name","description":"The name for this configuration.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_apns_item_password","displayName":"Password","description":"The user's password for the APN.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_apns_item_proxyport","displayName":"Proxy Port","description":"The proxy server's port number.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_apns_item_proxyserver","displayName":"Proxy Server","description":"The proxy server's address.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_apns_item_username","displayName":"Username","description":"The user name for the APN.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_attachapn","displayName":"Attach APN","description":"A configuration dictionary.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_attachapn_allowedprotocolmask","displayName":"Allowed Protocol Mask","description":"The supported Internet Protocol versions.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_attachapn_allowedprotocolmask_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.cellular_attachapn_allowedprotocolmask_1","displayName":"IPv6","description":null,"helpText":null},{"id":"com.apple.cellular_attachapn_allowedprotocolmask_2","displayName":"Both","description":null,"helpText":null}]},{"id":"com.apple.cellular_attachapn_authenticationtype","displayName":"Authentication Type","description":"The authentication type for logging in.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_attachapn_authenticationtype_0","displayName":"CHAP","description":null,"helpText":null},{"id":"com.apple.cellular_attachapn_authenticationtype_1","displayName":"PAP","description":null,"helpText":null}]},{"id":"com.apple.cellular_attachapn_name","displayName":"Name","description":"The name for this configuration.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_attachapn_password","displayName":"Password","description":"The password for the APN.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_attachapn_username","displayName":"Username","description":"The user name for the APN.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellular_com.apple.cellular","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},{"id":"com.apple.cellularprivatenetwork.managed_cellulardatapreferred","displayName":"Cellular Data Preferred","description":"Set to `true` to prefer this private network over Wi-Fi.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":[{"id":"com.apple.cellularprivatenetwork.managed_cellulardatapreferred_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.cellularprivatenetwork.managed_cellulardatapreferred_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.cellularprivatenetwork.managed_com.apple.cellularprivatenetwork.managed","displayName":"com.apple.cellularprivatenetwork.managed","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_csgnetworkidentifier","displayName":"Csg Network Identifier","description":"A string using the 3GPP \"CSG_ID\" format (defined in 3GPP 23.003, Section 4.7). The device uses this value to match a SIM present on the device.\n\nAll combinations of `NetworkIdentifier` and `CsgNetworkIdentifier` must be unique across all profiles installed on the device.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_datasetname","displayName":"Data Set Name","description":"The name of the private network configuration data set.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_enablenrstandalone","displayName":"Enable NR Standalone","description":"Set to `true` if this private network is NR Standalone.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":[{"id":"com.apple.cellularprivatenetwork.managed_enablenrstandalone_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.cellularprivatenetwork.managed_enablenrstandalone_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.cellularprivatenetwork.managed_geofences","displayName":"Geofences","description":"A list of up to 1000 geofences for private networks. Geofencing is only used on iPhone.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_geofences_item_geofenceid","displayName":"Geofence Id","description":"A geofence identifier that's unique within a list of geofences.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_geofences_item_latitude","displayName":"Latitude","description":"The latitude of the geofence.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_geofences_item_longitude","displayName":"Longitude","description":"The longitude of the geofence.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_geofences_item_radius","displayName":"Radius","description":"Specifies the radius of the geofence in meters. Set this value slightly greater than the private cellular network coverage area.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_networkidentifier","displayName":"Network Identifier","description":"A string using the 3GPP \"Coordinated NID\" (option 1 or option 2) format (defined in 3GPP 31.102, Section 12.7.1). The device uses this value to match a SIM present on the device.\n\nAll combinations of `NetworkIdentifier` and `CsgNetworkIdentifier` must be unique across all profiles installed on the device.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.cellularprivatenetwork.managed_versionnumber","displayName":"Version Number","description":"The version number of this dataset that the system uses to track updates.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},{"id":"com.apple.configurationprofile.identification_com.apple.configurationprofile.identification","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification","displayName":"Payload Identification (Deprecated)","description":"The dictionary containing details about the user.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_authmethod","displayName":"Auth Method","description":"The authorization method. Either the password is supplied in the profile or the user supplies it. ","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":[{"id":"com.apple.configurationprofile.identification_payloadidentification_authmethod_0","displayName":"Password","description":null,"helpText":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_authmethod_1","displayName":"UserEnteredPassword","description":null,"helpText":null}]},{"id":"com.apple.configurationprofile.identification_payloadidentification_emailaddress","displayName":"Email Address","description":"The address for the account.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_fullname","displayName":"Full Name","description":"The full name of the account.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_password","displayName":"Password","description":"The password for the account. Required when the Auth Method is of type password.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_prompt","displayName":"Prompt","description":"The custom instructions for the user, if needed.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_promptmessage","displayName":"Prompt Message","description":"The additional descriptive text for the user prompt.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.configurationprofile.identification_payloadidentification_username","displayName":"User Name","description":"The UNIX user name for the accounts.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},{"id":"com.apple.desktop_com.apple.desktop","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"e42edcd8-fcb0-4255-a774-c78b34f0b0c9","categoryName":"Desktop","options":null},{"id":"com.apple.desktop_override-picture-path","displayName":"Override Picture Path","description":"The path to the desktop picture. If set, this picture is always locked.","helpText":null,"infoUrls":[],"categoryId":"e42edcd8-fcb0-4255-a774-c78b34f0b0c9","categoryName":"Desktop","options":null},{"id":"com.apple.dictionary_com.apple.dictionary","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"65087b94-7e45-4d74-a50d-df4377b67499","categoryName":"Parental Controls Dictionary","options":null},{"id":"com.apple.dictionary_parentalcontrol","displayName":"Parental Control","description":"If true, enables parental controls dictionary restrictions.","helpText":null,"infoUrls":[],"categoryId":"65087b94-7e45-4d74-a50d-df4377b67499","categoryName":"Parental Controls Dictionary","options":[{"id":"com.apple.dictionary_parentalcontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dictionary_parentalcontrol_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adallowmultidomainauth","displayName":"AD Allow Multi Domain Auth","description":"If true, allows authentication from any domain in the namespace.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adallowmultidomainauth_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adallowmultidomainauth_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adallowmultidomainauthflag","displayName":"AD Allow Multi Domain Auth Flag","description":"If true, enables the AD Allow Multi Domain Auth key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adallowmultidomainauthflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adallowmultidomainauthflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adcreatemobileaccountatlogin","displayName":"AD Create Mobile Account At Login","description":"If true, creates a mobile account at login.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adcreatemobileaccountatlogin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adcreatemobileaccountatlogin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adcreatemobileaccountatloginflag","displayName":"AD Create Mobile Account At Login Flag","description":"If true, enables the AD Create Mobile Account At Login key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adcreatemobileaccountatloginflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adcreatemobileaccountatloginflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_addefaultusershell","displayName":"AD Default User Shell","description":"The default user shell. ","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_addefaultusershellflag","displayName":"AD Default User Shell Flag","description":"If true, enables the AD Default User Shell key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_addefaultusershellflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_addefaultusershellflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_addomainadmingrouplist","displayName":"AD Domain Admin Group List","description":"The list of Active Directory groups that are granted admin access.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_addomainadmingrouplistflag","displayName":"AD Domain Admin Group List Flag","description":"If true, enables the AD Domain Admin Group List key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_addomainadmingrouplistflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_addomainadmingrouplistflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adforcehomelocal","displayName":"AD Force Home Local","description":"If true, forces a local home directory.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adforcehomelocal_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adforcehomelocal_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adforcehomelocalflag","displayName":"AD Force Home Local Flag","description":"If true, enables the AD Force Home Local key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adforcehomelocalflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adforcehomelocalflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_admapggidattribute","displayName":"AD Map GGID Attribute","description":"The map group GID to attribute.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_admapggidattributeflag","displayName":"AD Map GGID Attribute Flag","description":"If true, enables the AD Map GGID Attribute Flag key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admapggidattributeflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admapggidattributeflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_admapgidattribute","displayName":"AD Map GID Attribute","description":"The map GID to attribute.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_admapgidattributeflag","displayName":"AD Map GID Attribute Flag","description":"If true, enables the AD Map GID Attribute key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admapgidattributeflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admapgidattributeflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_admapuidattribute","displayName":"AD Map UID Attribute","description":"The map UID to attribute.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_admapuidattributeflag","displayName":"AD Map UID Attribute Flag","description":"If true, enables the AD Map UID Attribute key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admapuidattributeflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admapuidattributeflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_admountstyle","displayName":"AD Mount Style","description":"The network home protocol to use: afp or smb.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admountstyle_0","displayName":"afp","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admountstyle_1","displayName":"smb","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adnamespace","displayName":"AD Namespace","description":"The primary user account naming convention; either forest or domain.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adnamespace_0","displayName":"forest","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adnamespace_1","displayName":"domain","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adnamespaceflag","displayName":"AD Namespace Flag","description":"If true, enables the AD Namespace key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adnamespaceflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adnamespaceflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adorganizationalunit","displayName":"AD Organizational Unit","description":"The organizational unit where the joining computer object is added.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_adpacketencrypt","displayName":"AD Packet Encrypt","description":"The packet encryption policy.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_adpacketencryptflag","displayName":"AD Packet Encrypt Flag","description":"If true, enables the AD Packet Encrypt key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adpacketencryptflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adpacketencryptflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adpacketsign","displayName":"AD Packet Sign","description":"The packet signing policy.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_adpacketsignflag","displayName":"AD Packet Sign Flag","description":"If true, enables the AD Packet Sign key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adpacketsignflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adpacketsignflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adpreferreddcserver","displayName":"AD Preferred DC Server","description":"The preferred domain server.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_adpreferreddcserverflag","displayName":"AD Preferred DC Server Flag","description":"If true, enables the AD Preferred DC Server key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adpreferreddcserverflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adpreferreddcserverflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adrestrictddns","displayName":"AD Restrict DDNS","description":"If true, allows authentication from any domain in the namespace. ","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_adrestrictddnsflag","displayName":"AD Restrict DDNS Flag","description":"If true, enables the AD Restrict DDNS key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adrestrictddnsflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adrestrictddnsflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adtrustchangepassintervaldays","displayName":"AD Trust Change Pass Interval Days","description":"The number of days before requiring a change of the computer trust account password. 0 disables the feature.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_adtrustchangepassintervaldaysflag","displayName":"AD Trust Change Pass Interval Days Flag","description":"If true, enables the AD Trust Change Pass Interval Days key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adtrustchangepassintervaldaysflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adtrustchangepassintervaldaysflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adusewindowsuncpath","displayName":"AD Use Windows UNC Path","description":"If true, uses the UNC path from Active Directory to derive the network home location.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adusewindowsuncpath_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adusewindowsuncpath_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adusewindowsuncpathflag","displayName":"AD Use Windows UNC Path Flag","description":"If true, enables the AD Use Windows UNC Path key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adusewindowsuncpathflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adusewindowsuncpathflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adwarnuserbeforecreatingma","displayName":"AD Warn User Before Creating MA","description":"If true, enables the warning before creating the mobile account.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adwarnuserbeforecreatingma_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adwarnuserbeforecreatingma_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_adwarnuserbeforecreatingmaflag","displayName":"AD Warn User Before Creating MA Flag","description":"If true, enables the AD Warn User Before Creating MA key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adwarnuserbeforecreatingmaflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adwarnuserbeforecreatingmaflag_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.directoryservice.managed_clientid","displayName":"Client ID","description":"The client's identifier.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_com.apple.directoryservice.managed","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_description","displayName":"Description","description":"The directory service description.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_hostname","displayName":"Host Name","description":"The Active Directory domain to join.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_password","displayName":"Password","description":"The password of the account for the domain.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.directoryservice.managed_username","displayName":"User Name","description":"The user name of the account for the domain.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},{"id":"com.apple.discrecording_burnsupport","displayName":"Burn Support","description":"If off, disables disc burning. If on, allows normal default operation. Setting this key to on doesn't enable disc burn support if it has already been disabled by other mechanisms or preferences. It also must be enabled with the Finder profile. If authenticate, requires authentication.","helpText":null,"infoUrls":[],"categoryId":"87f460f4-8403-419c-bfb4-44dec5edcccb","categoryName":"Media Management Disc Burning","options":[{"id":"com.apple.discrecording_burnsupport_0","displayName":"off","description":null,"helpText":null},{"id":"com.apple.discrecording_burnsupport_1","displayName":"authenticate","description":null,"helpText":null},{"id":"com.apple.discrecording_burnsupport_2","displayName":"on","description":null,"helpText":null}]},{"id":"com.apple.discrecording_com.apple.discrecording","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"87f460f4-8403-419c-bfb4-44dec5edcccb","categoryName":"Media Management Disc Burning","options":null},{"id":"com.apple.dnssettings.managed_com.apple.dnssettings.managed","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_dnssettings","displayName":"DNS Settings","description":"A dictionary that defines a configuration for an encrypted DNS server.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_dnssettings_dnsprotocol","displayName":"DNS Protocol","description":"The encrypted transport protocol used to communicate with the DNS server.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_dnssettings_dnsprotocol_0","displayName":"HTTPS","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_dnssettings_dnsprotocol_1","displayName":"TLS","description":null,"helpText":null}]},{"id":"com.apple.dnssettings.managed_dnssettings_serveraddresses","displayName":"Server Addresses","description":"An unordered list of DNS server IP address strings. These IP addresses can be a mixture of IPv4 and IPv6 addresses.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_dnssettings_servername","displayName":"Server Name","description":"The hostname of a DNS-over-TLS server used to validate the server certificate, as defined in RFC 7858. If no ServerAddresses are provided, the hostname will be used to determine the server addresses. This key must be present only if the DNSProtocol is TLS.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_dnssettings_serverurl","displayName":"Server URL","description":"The URI template of a DNS-over-HTTPS server, as defined in RFC 8484. This URL must use the https:// scheme, and the hostname or address in the URL will be used to validate the server certificate. If no ServerAddresses are provided, the hostname or address in the URL will be used to determine the server addresses. This key must be present only if the DNSProtocol is HTTPS.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_dnssettings_supplementalmatchdomains","displayName":"Supplemental Match Domains","description":"A list of domain strings used to determine which DNS queries will use the DNS server. If this array is not provided, all domains will use the DNS server.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules","displayName":"On Demand Rules","description":"An array of rules defining the DNS settings. If rules are not present, the system always applies the DNS settings. These rules are identical to the OnDemandRules array in VPN payloads.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_action","displayName":"Action","description":"The action to take if this dictionary matches the current network.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_action_0","displayName":"Connect","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_action_1","displayName":"Disconnect","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_action_2","displayName":"Evaluate Connection","description":null,"helpText":null}]},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters","displayName":"Action Parameters","description":"A dictionary that provides per-connection rules.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domainaction","displayName":"Domain Action (Deprecated)","description":" The DNS settings behavior for the specified domains.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domainaction_0","displayName":"Never Connect","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domainaction_1","displayName":"Connect If Needed","description":null,"helpText":null}]},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domains","displayName":"Domains (Deprecated)","description":"The domains for which this evaluation applies.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domainaction","displayName":"Domain Action","description":"The DNS settings behavior for the specified domains. Allowed values:\n\n* 'NeverConnect': Don't use the DNS Settings for the specified domains.\n* 'ConnectIfNeeded': Allow using the DNS Settings for the specified domains.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domainaction_0","displayName":"NeverConnect","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domainaction_1","displayName":"ConnectIfNeeded","description":null,"helpText":null}]},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domains","displayName":"Domains","description":"The domains for which this evaluation applies.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_dnsdomainmatch","displayName":"DNS Domain Match","description":"An array of domain names. This rule matches if any of the domain names in the specified list matches any domain in the device’s search domains list.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_dnsserveraddressmatch","displayName":"DNS Server Address Match","description":"An array of IP addresses. This rule matches if any of the network’s specified DNS servers match any entry in the array.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch","displayName":"Interface Type Match","description":"An interface type. If specified, this rule matches only if the primary network interface hardware matches the specified type.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch_0","displayName":"Ethernet","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch_1","displayName":"WiFi","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch_2","displayName":"Cellular","description":null,"helpText":null}]},{"id":"com.apple.dnssettings.managed_ondemandrules_item_ssidmatch","displayName":"SSID Match","description":"An array of SSIDs to match against the current network. If the network is not a Wi-Fi network or if the SSID does not appear in this array, the match fails. Omit this key and the corresponding array to match against any SSID.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_urlstringprobe","displayName":"URL String Probe","description":"A URL to probe. If this URL is successfully fetched (returning a 200 HTTP status code) without redirection, this rule matches.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},{"id":"com.apple.dnssettings.managed_prohibitdisablement","displayName":"Prohibit Disablement","description":"If true, prohibits users from disabling DNS settings. This key is only available on supervised devices.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_prohibitdisablement_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_prohibitdisablement_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.dock_allowdockfixupoverride","displayName":"Allow Dock Fixup Override","description":"If true, use the file in /Library/Preferences/com.apple.dockfixup.plist when a new user or migrated user logs in. This option has no effect for existing users. Available in macOS 10.12 and later. Only available on the device channel.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_allowdockfixupoverride_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_allowdockfixupoverride_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_autohide","displayName":"Auto Hide","description":"If true, enables \"Automatically hide and show the dock.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_autohide_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_autohide_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_autohide-immutable","displayName":"Auto Hide Immutable","description":"If true, locks \"Automatically hide.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_autohide-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_autohide-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_com.apple.dock","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_contents-immutable","displayName":"Contents Immutable","description":"If true, disables changes to the dock.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_contents-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_contents-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_dblclickbehavior","displayName":"Double Click Behavior","description":"The behavior when the window's title bar is double-clicked.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_dblclickbehavior_0","displayName":"Minimize","description":null,"helpText":null},{"id":"com.apple.dock_dblclickbehavior_1","displayName":"Maximize","description":null,"helpText":null},{"id":"com.apple.dock_dblclickbehavior_2","displayName":"None","description":null,"helpText":null}]},{"id":"com.apple.dock_dblclickbehavior-immutable","displayName":"Double Click Behavior Immutable","description":"If true, locks \"Double-click a window's title bar.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_dblclickbehavior-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_dblclickbehavior-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_largesize","displayName":"Large Size","description":"The size of the largest magnification. ","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_launchanim","displayName":"Launch Animation","description":"If true, enables \"Animate opening applications.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_launchanim_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_launchanim_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_launchanim-immutable","displayName":"Launch Animation Immutable","description":"If true, locks \"Animate opening applications.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_launchanim-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_launchanim-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_magnification","displayName":"Magnification","description":"If true, enables magnification.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_magnification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_magnification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_magnify-immutable","displayName":"Magnify Immutable","description":"If true, locks magnification.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_magnify-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_magnify-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_magsize-immutable","displayName":"Magnification Size Immutable","description":"If true, locks the magnification slider.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_magsize-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_magsize-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_mcxdockspecialfolders","displayName":"MCX Dock Special Folders","description":"One or more special folders that may be created at user login time and placed in the dock.\n\nThe 'My Applications' item is only used for Simple Finder environments. The 'Original Network Home' item is only used for mobile account users.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_mineffect","displayName":"Minimize Effect","description":"The minimize effect.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_mineffect_0","displayName":"Genie","description":null,"helpText":null},{"id":"com.apple.dock_mineffect_1","displayName":"Scale","description":null,"helpText":null}]},{"id":"com.apple.dock_mineffect-immutable","displayName":"Minimize Effect Immutable","description":"If true, locks \"Minimize windows using.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_mineffect-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_mineffect-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_minimize-to-application","displayName":"Minimize To Application","description":"If true, enables \"Minimize windows into application icon.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_minimize-to-application_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_minimize-to-application_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_minintoapp-immutable","displayName":"Minimize Into Application Immutable","description":"If true, disables the \"Minimize windows into application icon\" checkbox.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_minintoapp-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_minintoapp-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_orientation","displayName":"Orientation","description":"The orientation of the dock. ","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_orientation_0","displayName":"Bottom","description":null,"helpText":null},{"id":"com.apple.dock_orientation_1","displayName":"Left","description":null,"helpText":null},{"id":"com.apple.dock_orientation_2","displayName":"Right","description":null,"helpText":null}]},{"id":"com.apple.dock_persistent-apps","displayName":"Persistent Apps","description":"Dock items located on the Applications side of the Dock that can be removed.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-apps_item_tile-data","displayName":"Tile Data","description":"The information about the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type","displayName":"File Type","description":"The type of file","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type_0","displayName":"URL","description":null,"helpText":null},{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type_1","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type_2","displayName":"Directory","description":null,"helpText":null}]},{"id":"com.apple.dock_persistent-apps_item_tile-data_label","displayName":"Label","description":"The label of the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-apps_item_tile-data_url","displayName":"URL","description":"The URL string.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-apps_item_tile-type","displayName":"Tile Type","description":"The type of tile.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_persistent-apps_item_tile-type_0","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_persistent-apps_item_tile-type_1","displayName":"Directory","description":null,"helpText":null},{"id":"com.apple.dock_persistent-apps_item_tile-type_2","displayName":"URL","description":null,"helpText":null}]},{"id":"com.apple.dock_persistent-others","displayName":"Persistent Others","description":"Dock items located on the Documents side of the Dock that can be removed.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-others_item_tile-data","displayName":"Tile Data","description":"The information about the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-others_item_tile-data_file-type","displayName":"File Type","description":"The type of file","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_persistent-others_item_tile-data_file-type_0","displayName":"URL","description":null,"helpText":null},{"id":"com.apple.dock_persistent-others_item_tile-data_file-type_1","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_persistent-others_item_tile-data_file-type_2","displayName":"Directory","description":null,"helpText":null}]},{"id":"com.apple.dock_persistent-others_item_tile-data_label","displayName":"Label","description":"The label of the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-others_item_tile-data_url","displayName":"URL","description":"The URL string","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_persistent-others_item_tile-type","displayName":"Tile Type","description":"The type of tile.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_persistent-others_item_tile-type_0","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_persistent-others_item_tile-type_1","displayName":"Directory","description":null,"helpText":null},{"id":"com.apple.dock_persistent-others_item_tile-type_2","displayName":"URL","description":null,"helpText":null}]},{"id":"com.apple.dock_position-immutable","displayName":"Position Immutable","description":"If true, locks the position.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_position-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_position-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_show-process-indicators","displayName":"Show Process Indicators","description":"If true, shows the process indicator.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_show-process-indicators_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_show-process-indicators_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_show-recents","displayName":"Show Recents","description":"If true, enables \"Show recent items.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_show-recents_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_show-recents_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_showindicators-immutable","displayName":"Show Indicators Immutable","description":"If true, locks \"Show indicators.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_showindicators-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_showindicators-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_showrecents-immutable","displayName":"Show Recents Immutable","description":"If true, disables \"Show recent applications\" checkbox.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_showrecents-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_showrecents-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_size-immutable","displayName":"Size Immutable","description":"If true, locks the size slider.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_size-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_size-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_static-apps","displayName":"Static Apps","description":"Dock items located on the Applications side of the Dock and cannot be removed from that location.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-apps_item_tile-data","displayName":"Tile Data","description":"The information about the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-apps_item_tile-data_file-type","displayName":"File Type","description":"The type of file","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-apps_item_tile-data_file-type_0","displayName":"URL","description":null,"helpText":null},{"id":"com.apple.dock_static-apps_item_tile-data_file-type_1","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_static-apps_item_tile-data_file-type_2","displayName":"Directory","description":null,"helpText":null}]},{"id":"com.apple.dock_static-apps_item_tile-data_label","displayName":"Label","description":"The label of the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-apps_item_tile-data_url","displayName":"URL","description":"The URL string","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-apps_item_tile-type","displayName":"Tile Type","description":"The type of tile.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-apps_item_tile-type_0","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_static-apps_item_tile-type_1","displayName":"Directory","description":null,"helpText":null},{"id":"com.apple.dock_static-apps_item_tile-type_2","displayName":"URL","description":null,"helpText":null}]},{"id":"com.apple.dock_static-only","displayName":"Static Only","description":"If true, uses the Static Apps and Static Others dictionaries for the dock and ignores any items in the Persistent Apps and Persistent Others dictionaries. If false, the contents are merged with the static items listed first.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-only_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_static-only_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.dock_static-others","displayName":"Static Others","description":"Dock items located on the Documents side of the Dock and cannot be removed from that location.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-others_item_tile-data","displayName":"Tile Data","description":"The information about the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-others_item_tile-data_file-type","displayName":"File Type","description":"The type of file","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-others_item_tile-data_file-type_0","displayName":"URL","description":null,"helpText":null},{"id":"com.apple.dock_static-others_item_tile-data_file-type_1","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_static-others_item_tile-data_file-type_2","displayName":"Directory","description":null,"helpText":null}]},{"id":"com.apple.dock_static-others_item_tile-data_label","displayName":"Label","description":"The label of the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-others_item_tile-data_url","displayName":"URL","description":"The URL string","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_static-others_item_tile-type","displayName":"Tile Type","description":"The type of tile.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-others_item_tile-type_0","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_static-others_item_tile-type_1","displayName":"Directory","description":null,"helpText":null},{"id":"com.apple.dock_static-others_item_tile-type_2","displayName":"URL","description":null,"helpText":null}]},{"id":"com.apple.dock_tilesize","displayName":"Tile Size","description":"The tile size. Values must be in the range of 16 to 128.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},{"id":"com.apple.dock_windowtabbing","displayName":"Window Tabbing","description":"Set the \"Prefer tabs when opening documents\" to the provided value.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_windowtabbing_0","displayName":"Manual","description":null,"helpText":null},{"id":"com.apple.dock_windowtabbing_1","displayName":"Always","description":null,"helpText":null},{"id":"com.apple.dock_windowtabbing_2","displayName":"Full Screen","description":null,"helpText":null}]},{"id":"com.apple.dock_windowtabbing-immutable","displayName":"Window Tabbing Immutable","description":"If true, disables \"Prefer tabs when opening documents\" checkbox.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_windowtabbing-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_windowtabbing-immutable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.domains_com.apple.domains","displayName":"Top Level Setting Group Collection","description":"com.apple.domains","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},{"id":"com.apple.domains_crosssitetrackingpreventionrelaxedapps","displayName":"Cross Site Tracking Prevention Relaxed Apps","description":"An array of up to 10 strings representing app bundle-ids. Apps matching the bundle-ids listed here have relaxed enforcement of cross-site tracking prevention for the domains listed in `CrossSiteTrackingPreventionRelaxedDomains`.\n\nAvailable in iOS 18 and later and macOS 15 and later.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},{"id":"com.apple.domains_crosssitetrackingpreventionrelaxeddomains","displayName":"Cross Site Tracking Prevention Relaxed Domains","description":"Specify an array of up to ten domains \r\nwhen cross-site tracking is required for functionality.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},{"id":"com.apple.domains_emaildomains","displayName":"Email Domains","description":"An array of domains. Email addresses that lack a suffix matching any of these strings are considered out of domain and marked in Mail.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},{"id":"com.apple.domains_safaripasswordautofilldomains","displayName":"Safari Password Auto Fill Domains","description":"An array of domains. Users can only save passwords in Safari from URLs matching the patterns listed here. This property doesn’t disable the autofill feature itself. Supervised devices or Shared iPads need this property to enable saving passwords in Safari. Available in iOS 9.3 and later.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},{"id":"com.apple.domains_webdomains","displayName":"Web Domains","description":"An array of domains. URLs matching the patterns listed here are considered managed.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},{"id":"com.apple.extensiblesso_authenticationmethod","displayName":"Authentication Method (Deprecated)","description":"The Platform SSO authentication method the extension uses. Requires that the SSO Extension also supports the method.\nAvailable in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_authenticationmethod_0","displayName":"Password","description":null,"helpText":null},{"id":"com.apple.extensiblesso_authenticationmethod_1","displayName":"UserSecureEnclaveKey","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_com.apple.extensiblesso","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_com.apple.extensiblesso-kerberos_kerberos","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_deniedbundleidentifiers","displayName":"Denied Bundle Identifiers","description":"An array of bundle identifiers of apps that don't use SSO provided by this extension.\nAvailable in iOS 15 and later and macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_extensiondata","displayName":"Extension Data","description":"A dictionary of arbitrary data passed through to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_extensiondata_allowautomaticlogin_kerberos","displayName":"Allow Automatic Login","description":"If false, passwords are not allowed to be saved to the keychain.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_allowautomaticlogin_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_allowautomaticlogin_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_allowpassword_kerberos","displayName":"Allow Password","description":"If set to true, the user to switch the user interface to Password mode. (macOS only)","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_allowpassword_kerberos_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_allowpassword_kerberos_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_allowpasswordchange_kerberos","displayName":"Allow Password Change","description":"If false, disables password changes. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_allowpasswordchange_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_allowpasswordchange_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_allowplatformssoauthfallback_kerberos","displayName":"Allow Platform SSO OAuth Fallback","description":"If `true` and `usePlatformSSOTGT` is `true`, the system allows the user to manually sign in. Available in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_allowplatformssoauthfallback_kerberos_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_allowplatformssoauthfallback_kerberos_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_allowsmartcard_kerberos","displayName":"Allow Smart Card","description":"If set to true, the user to switch the user interface to SmartCard mode. (macOS only)","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_allowsmartcard_kerberos_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_allowsmartcard_kerberos_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_credentialbundleidacl_kerberos","displayName":"Credential Bundle ID ACL","description":"A list of bundle IDs allowed to access the ticket-granting ticket (TGT).","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_credentialusemode_kerberos","displayName":"Credential Use Mode","description":"This setting affects how the Kerberos Extension credential is used by other processes.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_credentialusemode_kerberos_0","displayName":"Always","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_credentialusemode_kerberos_1","displayName":"When Not Specified","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_credentialusemode_kerberos_2","displayName":"Kerberos Default ","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_customusernamelabel_kerberos","displayName":"Custom Username Label","description":"The custom user name label used in the Kerberos extension instead of “Username”. For example, “Company ID”. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_delayusersetup_kerberos","displayName":"Delay User Setup","description":"If true, doesn’t prompt the user to setup the Kerberos extension until either the administrator enables it with the app-sso tool or a Kerberos challenge is received. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_delayusersetup_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_delayusersetup_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_domainrealmmapping_generickey_kerberos_keytobereplaced","displayName":"Realm","description":"The name of the realm.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_domainrealmmapping_generickey_kerberos_string","displayName":"Domain Realm Mapping","description":"An array of DNS Suffixes that map to the realm.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_domainrealmmapping_kerberos","displayName":"Domain Realm Mapping","description":"A custom domain-realm mapping for Kerberos. This is used when the DNS name of hosts do not match the realm name. Most administrators will not need to customize this.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_domainrealmmapping_realm_kerberos","displayName":"Realm (Deprecated)","description":"The key should be the name of the realm, and the value is an array of DNS suffixes that map to the realm.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_generickey_boolean","displayName":"Value","description":"Keys and values to pass to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_extensiondata_generickey_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_generickey_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_generickey_integer","displayName":"Value","description":"Keys and values to pass to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_extensiondata_generickey_keytobereplaced","displayName":"Key","description":"Additional extension-specific data to pass to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_extensiondata_generickey_string","displayName":"Value","description":"Keys and values to pass to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_extensiondata_helptext_kerberos","displayName":"Help Text","description":"The text to be displayed to the user at the bottom of the Kerberos login window. It can be used to display help information or disclaimer text. Available in iOS 14 and later and macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_identityissuerautoselectfilter_kerberos","displayName":"Identity Issuer Auto Select Filter","description":"A string with wildcards that can use used to filter the list of available SmartCards by issuer. e.g \"*My CA2*\". If there is one remaining, it will be auto-selected. If there more than one remaining, then the list is shorter. (macOS only)","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_includekerberosappsinbundleidacl_kerberos","displayName":"Include Kerberos Apps In Bundle ID ACL","description":"If true, the Kerberos extension allows the standard kerberos utilities including TicketViewer and klist to access and use the credential. This is in addition to Include Managed Apps In Bundle ID ACL or the Credential Bundle ID ACL, if it is specified.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_includekerberosappsinbundleidacl_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_includekerberosappsinbundleidacl_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_includemanagedappsinbundleidacl_kerberos","displayName":"Include Managed Apps In Bundle ID ACL","description":"If true, the Kerberos extension allows only managed apps to access and use the credential. This is in addition to the Credential Bundle ID ACL, if it is specified. Available in iOS 14 and later, and macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_includemanagedappsinbundleidacl_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_includemanagedappsinbundleidacl_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_isdefaultrealm_kerberos","displayName":"Is Default Realm","description":"This property specifies it is the default realm if there is more than one Kerberos extension configuration.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_isdefaultrealm_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_isdefaultrealm_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_kerberos","displayName":"Extension Data","description":"This is the dictionary used by the Apple built-in Kerberos extension.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_monitorcredentialscache_kerberos","displayName":"Monitor Credentials Cache","description":"If false, the credential is requested on the next matching Kerberos challenge or network state change. If the credential is expired or missing, a new one will be created. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_monitorcredentialscache_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_monitorcredentialscache_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_performkerberosonly_kerberos","displayName":"Perform Kerberos Only","description":"If true, the Kerberos Extension handles Kerberos requests only. It doesn’t check for password expiration, show the password expiration in the menu, check for external password changes, perform password sync, or retrieve the home directory. Available in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_performkerberosonly_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_performkerberosonly_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_preferredkdcs_kerberos","displayName":"Preferred KDCs","description":"The ordered list of perferred Key Distribution Centers (KDCs) to use for Kerberos traffic. Use this if the servers are not discoverable via DNS. If the servers are specified, then they are used for both connectivity checks and attempted first for Kerberos traffic. If the servers do not respond, then the device falls back to DNS discovery. Each entry is formatted the same as it would be in a krb5.conf file.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_principalname_kerberos","displayName":"Principal Name","description":"The principal (aka username) to use. You do not need to include the realm.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_pwchangeurl_kerberos","displayName":"Password Change URL","description":"This URL will launch in the user’s default web browser when they initiate a password change. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_pwnotificationdays_kerberos","displayName":"Password Notification Days","description":"The number of days prior to password expiration when a notification of password expiration will be sent to the user. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_pwreqcomplexity_kerberos","displayName":"Password Req Complexity","description":"If true, passwords must meet Active Directory's definition of \"complex\". Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_pwreqcomplexity_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_pwreqcomplexity_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_pwreqhistory_kerberos","displayName":"Password Req History","description":"The number of prior passwords that cannot be re-used on this domain. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_pwreqlength_kerberos","displayName":"Password Req Length","description":"The minimum length of passwords on the domain. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_pwreqminage_kerberos","displayName":"Password Req Min Age","description":"The minimum age of passwords before they can be changed on this domain. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_pwreqtext_kerberos","displayName":"Password Req Text","description":"The text version of the domain's password requirements. Only for use if Password Req Complexity or Password Req Length aren’t specified. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_requiretlsforldap_kerberos","displayName":"Require TLS For LDAP","description":"Require that LDAP connections use TLS. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_requiretlsforldap_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_requiretlsforldap_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_requireuserpresence_kerberos","displayName":"Require User Presence","description":"If true, requires the user to provide Touch ID, Face ID or their passcode to access the keychain entry.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_requireuserpresence_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_requireuserpresence_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_sitecode_kerberos","displayName":"Site Code","description":"The name of the Active Directory site the Kerberos extension should use. Most administrators will never need to modify this value, as the Kerberos extension can normally find the site automatically.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_extensiondata_startinsmartcardmode_kerberos","displayName":"Start In Smart Card Mode","description":"If set to true, the user interface will start in SmartCard mode. (macOS only)","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_startinsmartcardmode_kerberos_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_startinsmartcardmode_kerberos_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_synclocalpassword_kerberos","displayName":"Sync Local Password","description":"If false, disables password sync. Note that this will not work if the user is logged in with a mobile account. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_synclocalpassword_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_synclocalpassword_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_useplatformssotgt_kerberos","displayName":"Use Platform SSOTGT","description":"If `true`, the system requires this configuration uses a TGT from Platform SSO instead of requesting a new one. Available in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_useplatformssotgt_kerberos_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_useplatformssotgt_kerberos_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensiondata_usesiteautodiscovery_kerberos","displayName":"Use Site Auto Discovery","description":"If false, the Kerberos extension doesn't automatically use LDAP and DNS to determine its AD site name.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_usesiteautodiscovery_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_usesiteautodiscovery_kerberos_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_extensionidentifier","displayName":"Extension Identifier","description":"The bundle identifier of the app extension that performs SSO for the specified URLs.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_extensionidentifier_kerberos","displayName":"Extension Identifier","description":"This value must be com.apple.AppSSOKerberos.KerberosExtension for this extension.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":{"id":"com.apple.extensiblesso_extensionidentifier_kerberos_0","displayName":"com.apple.AppSSOKerberos.KerberosExtension","description":null,"helpText":null}},{"id":"com.apple.extensiblesso_hosts","displayName":"Hosts","description":"An array of host names or domain names that apps can authenticate through the app extension.\r\nRequired for Credential payloads. Ignored for Redirect payloads.\r\n\r\nHost or domain names are matched case-insensitively, and all the host/domain names of all installed Extensible SSO payloads must be unique.\r\n\r\nHosts that begin with a “.” are wildcard suffixes and match all subdomains; otherwise the host must be an exact match.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_hosts_kerberos","displayName":"Hosts","description":"One or more host or domain names for which the app extension performs SSO. Host or domain names are matched case-insensitively, and all the host/domain names of all installed Extensible SSO payloads must be unique. Hosts that begin with a “.” are wildcard suffixes and will match all subdomains, otherwise the host must be an exact match.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_ignored_$typepicker","displayName":"Type","description":"Keys and values to pass to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_ignored_0","displayName":"String","description":"String","helpText":null},{"id":"com.apple.extensiblesso_ignored_1","displayName":"Integer","description":"Integer","helpText":null},{"id":"com.apple.extensiblesso_ignored_2","displayName":"Boolean","description":"Boolean","helpText":null}]},{"id":"com.apple.extensiblesso_ignored_kerberos_$typepicker","displayName":"IGNORED","description":null,"helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":{"id":"com.apple.extensiblesso_ignored_kerberos_0","displayName":"Array","description":null,"helpText":null}},{"id":"com.apple.extensiblesso_platformsso","displayName":"Platform SSO","description":"This is the dictionary used to configure PlatformSSO.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_accountdisplayname","displayName":"Account Display Name","description":"The display name for the account in notifications and authentication requests.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_additionalgroups","displayName":"Additional Groups","description":"The list of groups that are created and do not have administrator access.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_administratorgroups","displayName":"Administrator Groups","description":"The list of groups that are used for administrator access. Membership will be requested during authentication.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_allowdeviceidentifiersinattestation","displayName":"Allow Device Identifiers In Attestation","description":"If `true`, the system includes the device UDID and serial number in Platform SSO attestations.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_allowdeviceidentifiersinattestation_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_allowdeviceidentifiersinattestation_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_authenticationgraceperiod","displayName":"Authentication Grace Period","description":"The amount of time after a 'FileVaultPolicy', 'LoginPolicy', or 'UnlockPolicy' is received or updated that unregistered local accounts can be used. Required when 'AllowAuthenticationGracePeriod' is set.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_authenticationmethod","displayName":"Authentication Method","description":"The Platform SSO authentication method to be used with the extension. Requires that the SSO Extension also support the method.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_authenticationmethod_0","displayName":"Password","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_authenticationmethod_1","displayName":"UserSecureEnclaveKey","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_authenticationmethod_2","displayName":"SmartCard","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_authorizationgroups","displayName":"Authorization Groups","description":"The pairing of Authorization Rights to group names. The Authorization Right will be updated to use the group when used.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_authorizationgroups_authorization right","displayName":"Authorization Right (Deprecated)","description":"The Authorization Right to update.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_authorizationgroups_generickey","displayName":"ANY","description":"The key is an access right value, the value is the group to be associated with that access right.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_authorizationgroups_generickey_keytobereplaced","displayName":"Authorization Groups","description":"The pairing of Authorization Rights to group names. When using this, the system updates the Authorization Right to use the group.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_authorizationgroups_group","displayName":"Group (Deprecated)","description":"The group to use for the Authorization Right.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_enableauthorization","displayName":"Enable Authorization","description":"Enables using identity provider accounts at authorization prompts. Requires 'UseSharedDeviceKeys' is true. The account will be assigned groups using the 'AdministratorGroups', 'AdditionalGroups', or 'AuthorizationGroups'.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_enableauthorization_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_enableauthorization_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_enablecreatefirstuserduringsetup","displayName":"Enable Create First User During Setup","description":"If `true`, the device uses Platform SSO to create the first user account on the Mac during `Setup Assistant`.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_enablecreatefirstuserduringsetup_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_enablecreatefirstuserduringsetup_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_enablecreateuseratlogin","displayName":"Enable Create User At Login","description":"Enables creating new users at the login window with either Passwords or SmartCards. Requires 'UseSharedDeviceKeys' is true.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_enablecreateuseratlogin_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_enablecreateuseratlogin_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_enableregistrationduringsetup","displayName":"Enable Registration During Setup","description":"If `true`, the system enables the PlatformSSO registration process during Setup Assistant on devices running macOS 26 and later. Set this key to `true` when configuring PlatformSSO before enrollment using the `com.apple.psso.required` error response.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_enableregistrationduringsetup_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_enableregistrationduringsetup_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_filevaultpolicy","displayName":"FileVault Policy","description":"The policy to apply when using Platform SSO at FileVault unlock on Apple Silicon Macs. Applies when 'AuthenticationMethod' is `Password`.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_loginfrequency","displayName":"Login Frequency","description":"The frequency where a full login is required instead of a refresh. Default is 18 hours. Must be > 1 hour.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_loginpolicy","displayName":"Login Policy","description":"The policy to apply when using Platform SSO at the login window. Applies when 'AuthenticationMethod' is `Password`.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_newuserauthorizationmode","displayName":"New User Authorization Mode","description":"This setting affects the permissions for accounts created at login by Platform SSO. It is only used when the account is created. Use of the following:\n* Standard\n The account will be a standard user.\n* Admin\n The account will be added to the local administrators group.\n* Groups\n The account will be assigned groups using the 'AdministratorGroups', 'AdditionalGroups', or 'AuthorizationGroups'.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_newuserauthorizationmode_0","displayName":"Standard","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_newuserauthorizationmode_1","displayName":"Admin","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_newuserauthorizationmode_2","displayName":"Groups","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_newuserauthorizationmode_3","displayName":"Temporary","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_nonplatformssoaccounts","displayName":"Non Platform SSO Accounts","description":"The list of local accounts that are not subject to the 'FileVaultPolicy', 'LoginPolicy', or 'UnlockPolicy'. The accounts are also not prompted to register for Platform SSO.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_offlinegraceperiod","displayName":"Offline Grace Period","description":"The amount of time after the last successful Platform SSO login a local account password can be used offline. Required when 'AllowOfflineGracePeriod' is set.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_tokentousermapping","displayName":"Token To User Mapping","description":"The attribute mapping used when creating new users or for authorization.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_tokentousermapping_accountname","displayName":"Account Name","description":"The claim name to use for the user's account name.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_tokentousermapping_fullname","displayName":"Full Name","description":"The claim name to use for the user's full name.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_unlockpolicy","displayName":"Unlock Policy","description":"The policy to apply when using Platform SSO at screensaver unlock. Applies when 'AuthenticationMethod' is `Password`.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_platformsso_userauthorizationmode","displayName":"User Authorization Mode","description":"This setting affects the permissions after authentication by Platform SSO. It is applied each time user authenticates. Use of the following:\n* Standard\n The account will be a standard user. It will be removed from the 'admin' group.\n* Admin\n The account will be added to the local administrators group.\n* Groups\n The account will be assigned groups using the 'AdministratorGroups', 'AdditionalGroups', or 'AuthorizationGroups'.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_userauthorizationmode_0","displayName":"Standard","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_userauthorizationmode_1","displayName":"Admin","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_userauthorizationmode_2","displayName":"Groups","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_platformsso_useshareddevicekeys","displayName":"Use Shared Device Keys","description":"If set to true, Platform SSO will use the same signing and encryption keys for all users.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_useshareddevicekeys_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_useshareddevicekeys_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_realm","displayName":"Realm","description":"The realm name for Credential payloads. Use proper capitalization for this value. This key is ignored for Redirect payloads.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_realm_kerberos","displayName":"Realm","description":"The Kerberos realm, which should be properly capitalized. If in an Active Directory forest, this is the realm where the user logs in.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},{"id":"com.apple.extensiblesso_registrationtoken","displayName":"Registration Token","description":"The token this device uses for registration with Platform SSO. Use it for silent registration with the Identity Provider. Requires that 'AuthenticationMethod' isn't empty.\nAvailable in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_screenlockedbehavior","displayName":"Screen Locked Behavior","description":"When set to Do Not Handle, the request continues without SSO. Available in iOS 15 and later and macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":{"id":"com.apple.extensiblesso_screenlockedbehavior_0","displayName":"Do Not Handle","description":null,"helpText":null}},{"id":"com.apple.extensiblesso_teamidentifier","displayName":"Team Identifier","description":"The team identifier of the app extension. The device requires this key on macOS and ignores it elsewhere.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.extensiblesso_teamidentifier_kerberos","displayName":"Team Identifier","description":"This value must be apple for the Kerberos extension.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":{"id":"com.apple.extensiblesso_teamidentifier_kerberos_0","displayName":"apple","description":null,"helpText":null}},{"id":"com.apple.extensiblesso_type","displayName":"Type","description":"The type of SSO.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_type_0","displayName":"Credential","description":null,"helpText":null},{"id":"com.apple.extensiblesso_type_1","displayName":"Redirect","description":null,"helpText":null}]},{"id":"com.apple.extensiblesso_type_kerberos","displayName":"Type","description":"This value must be Credential for the Kerberos extension.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":{"id":"com.apple.extensiblesso_type_kerberos_0","displayName":"Credential","description":null,"helpText":null}},{"id":"com.apple.extensiblesso_urls","displayName":"URLs","description":"An array of URL prefixes of identity providers where the app extension performs SSO. Required for Redirect payloads. Ignored for Credential payloads. The URLs must begin with http:// or https://, the scheme and host name are matched case-insensitively, query parameters and URL fragments are not allowed, and the URLs of all installed Extensible SSO payloads must be unique.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},{"id":"com.apple.familycontrols.contentfilter_com.apple.familycontrols.contentfilter","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_filterblacklist","displayName":"Filter Blocklist (Deprecated)","description":"The array of URLs that defines a deny list. When Restrict Web and Use Content Filter are enabled, no URLs in the deny list are available to the user.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_filterdenylist","displayName":"Filter Deny List","description":"The array of URLs that defines a deny list. When `restrictWeb` and `useContentFilter` are enabled, no URLs in the deny list are available to the user.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_filterwhitelist","displayName":"Filter Allowlist","description":"The array of URLs that defines an allow list. When Restrict Web and Use Content Filter are enabled, only URLs in the allow list are available to the user.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_restrictweb","displayName":"Restrict Web","description":"If true, enables web content filters.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":[{"id":"com.apple.familycontrols.contentfilter_restrictweb_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.contentfilter_restrictweb_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.contentfilter_sitewhitelist","displayName":"Site Allowlist","description":"An array of sites that defines an allow list. If specified, this defines additional allowed sites besides those in the automated allow list and deny list, including disallowed adult sites. This key is required if Allow List Enabled is true.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_sitewhitelist_item_address","displayName":"Address","description":"The site prefix, including http(s) scheme.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_sitewhitelist_item_pagetitle","displayName":"Page Title","description":"The site page title.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},{"id":"com.apple.familycontrols.contentfilter_usecontentfilter","displayName":"Use Content Filter","description":"If true, filters content automatically. ","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":[{"id":"com.apple.familycontrols.contentfilter_usecontentfilter_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.contentfilter_usecontentfilter_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.contentfilter_whitelistenabled","displayName":"Allowlist Enabled","description":"If true, enables web content filters.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":[{"id":"com.apple.familycontrols.contentfilter_whitelistenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.contentfilter_whitelistenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_com.apple.familycontrols.timelimits.v2","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_familycontrolsenabled","displayName":"Family Controls Enabled","description":"If true, enables time limits. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_familycontrolsenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_familycontrolsenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits","displayName":"Time Limits","description":"The time limits to enforce if Family Controls Enabled is enabled. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance","displayName":"Weekday Allowance","description":"The weekday allowance settings.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_enabled","displayName":"Enabled","description":"If true, enable these settings. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_enabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_end","displayName":"End","description":"The curfew end time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_rangetype","displayName":"Range Type","description":"The type of day range.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_rangetype_0","displayName":"Weekday","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_rangetype_1","displayName":"Weekend","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_secondsperday","displayName":"Seconds Per Day","description":"The allowance for that day, in seconds. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_start","displayName":"Start","description":"The curfew start time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew","displayName":"Weekday Curfew","description":"The weekday curfew settings.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_enabled","displayName":"Enabled","description":"If true, enable these settings. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_enabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_end","displayName":"End","description":"The curfew end time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_rangetype","displayName":"Range Type","description":"The type of day range.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_rangetype_0","displayName":"Weekday","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_rangetype_1","displayName":"Weekend","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_secondsperday","displayName":"Seconds Per Day","description":"The allowance for that day, in seconds. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_start","displayName":"Start","description":"The curfew start time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance","displayName":"Weekend Allowance","description":"The weekend allowance settings.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_enabled","displayName":"Enabled","description":"If true, enable these settings. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_enabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_end","displayName":"End","description":"The curfew end time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_rangetype","displayName":"Range Type","description":"The type of day range.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_rangetype_0","displayName":"Weekday","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_rangetype_1","displayName":"Weekend","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_secondsperday","displayName":"Seconds Per Day","description":"The allowance for that day, in seconds. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_start","displayName":"Start","description":"The curfew start time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew","displayName":"Weekend Curfew","description":"The weekend curfew settings.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_enabled","displayName":"Enabled","description":"If true, enable these settings. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_enabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_end","displayName":"End","description":"The curfew end time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_rangetype","displayName":"Range Type","description":"The type of day range.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_rangetype_0","displayName":"Weekday","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_rangetype_1","displayName":"Weekend","description":null,"helpText":null}]},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_secondsperday","displayName":"Seconds Per Day","description":"The allowance for that day, in seconds. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_start","displayName":"Start","description":"The curfew start time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},{"id":"com.apple.fileproviderd_allowmanagedfileproviderstorequestattribution","displayName":"Allow Managed File Providers To Request Attribution","description":"If true, enables file providers access to the path of the requesting process.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":[{"id":"com.apple.fileproviderd_allowmanagedfileproviderstorequestattribution_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.fileproviderd_allowmanagedfileproviderstorequestattribution_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.fileproviderd_com.apple.fileproviderd","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},{"id":"com.apple.fileproviderd_managementallowsexternalvolumesyncing","displayName":"Management Allows External Volume Syncing","description":"If `false`, the device only allows File Provider extension volume synchronization for the system \"home\" volume and any data separated volume, and prevents synchronization with any other volumes. If `true``, the device allows File Provider extension volume synchronization for the system \"home\" volume, any data separated volume, and any encrypted APFS volumes (on either internal or external media).","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":[{"id":"com.apple.fileproviderd_managementallowsexternalvolumesyncing_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.fileproviderd_managementallowsexternalvolumesyncing_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.fileproviderd_managementallowsknownfoldersyncing","displayName":"Management Allows Known Folder Syncing","description":"If `false`, the device prevents the File Provider extension from using desktop and documents synchronization in any app. This doesn't impact the ability for apps to utilize the File Provider extension for file and folder syncing with remote storage.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":[{"id":"com.apple.fileproviderd_managementallowsknownfoldersyncing_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.fileproviderd_managementallowsknownfoldersyncing_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.fileproviderd_managementallowsremotesyncing","displayName":"Management Allows Remote Syncing","description":"If `false`, the device prevents the File Provider extension from using synchronization in any app. Also, none of the other options will be evaluated. Synchronization will be totally disabled for any application.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":[{"id":"com.apple.fileproviderd_managementallowsremotesyncing_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.fileproviderd_managementallowsremotesyncing_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.fileproviderd_managementdomainautoenablementlist","displayName":"Management Domain Auto Enablement List","description":"An array of strings representing the composed identifiers of apps. The device automatically enables the File Provider domains for the corresponding apps. The device doesn't enable existing domains if enrollment happens after they are created. The device doesn't prevent the user from disabling these File Provider domains. Users need to manually enable File Provider domains in the Finder if their corresponding apps aren't listed here. The format of the app identifiers is \"Bundle-ID (Team-ID)\", for example `com.example.app (ABCD1234)`.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},{"id":"com.apple.fileproviderd_managementexternalvolumesyncingallowlist","displayName":"Management External Volume Syncing Allow List","description":"An array of strings representing the composed identifiers of apps. The device allows the corresponding apps to use File Provider extension volume synchronization. If present, and `ManagementAllowsExternalVolumeSyncing` is set to `true`, the device allows only the apps in this list to use volume synchronization. This key is ignored if `ManagementAllowsExternalVolumeSyncing` is set to `false`. The format of the app identifiers is \"Bundle-ID (Team-ID)\", for example `com.example.app (ABCD1234)`.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},{"id":"com.apple.fileproviderd_managementknownfoldersyncingallowlist","displayName":"Management Known Folder Syncing Allow List","description":"An array of strings representing the composed identifiers of apps. The device allows the corresponding apps to use File Provider extension desktop and documents synchronization. If present, and `ManagementAllowsKnownFolderSyncing` is set to `true`, the device allows only the apps in this list to use desktop and documents synchronization. This key is ignored if `ManagementAllowsKnownFolderSyncing` is set to `false`. This setting doesn't impact the ability for apps to use File Provider extension volume access. The format of the app identifiers is \"Bundle-ID (Team-ID)\", for example `com.example.app (ABCD1234)`.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},{"id":"com.apple.fileproviderd_managementremotesyncingallowlist","displayName":"Management Remote Syncing Allow List","description":"An array of strings representing the composed identifiers of apps. The device allows the corresponding apps to use File Provider extension synchronization. If present, and `ManagementAllowsRemoteSyncing` is set to `true`, the device allows only the apps in this list to use synchronization. This key is ignored if `ManagementAllowsRemoteSyncing` is set to `false`. If present, the other options will only be evaluated for the apps in this list. The format of the app identifiers is \"Bundle-ID (Team-ID)\", for example `com.example.app (ABCD1234)`.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},{"id":"com.apple.finder_com.apple.finder","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":null},{"id":"com.apple.finder_prohibitburn","displayName":"Prohibit Burn","description":"If true, disables the Finder's burn support.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_prohibitburn_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_prohibitburn_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_prohibitconnectto","displayName":"Prohibit Connect To","description":"If true, prohibits users from using a dialog that lets them view, select, or manually connect to servers on the local network or on the internet.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_prohibitconnectto_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_prohibitconnectto_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_prohibiteject","displayName":"Prohibit Eject","description":"If true, users are prevented from ejecting any mounted volumes or media attached to the Mac.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_prohibiteject_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_prohibiteject_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_prohibitgotofolder","displayName":"Prohibit Go To Folder","description":"If true, users are prevented from opening a folder or file by typing the path to that item. ","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_prohibitgotofolder_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_prohibitgotofolder_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_showexternalharddrivesondesktop","displayName":"Show External Hard Drives On Desktop","description":"If false, mounted servers can not appear on the desktop.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_showexternalharddrivesondesktop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_showexternalharddrivesondesktop_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_showharddrivesondesktop","displayName":"Show Hard Drives On Desktop","description":"If true, hard drives can appear on the desktop.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_showharddrivesondesktop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_showharddrivesondesktop_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_showmountedserversondesktop","displayName":"Show Mounted Servers On Desktop","description":"If true, mounted servers can appear on the desktop.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_showmountedserversondesktop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_showmountedserversondesktop_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_showremovablemediaondesktop","displayName":"Show Removable Media On Desktop","description":"If false, removable media can not appear on the desktop.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_showremovablemediaondesktop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_showremovablemediaondesktop_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.finder_warnonemptytrash","displayName":"Warn On Empty Trash","description":"If false, the warning before a user empties the Trash can be disabled.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_warnonemptytrash_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_warnonemptytrash_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.font_com.apple.font","displayName":"com.apple.font","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5401711f-292a-487a-be18-f99593a0477c","categoryName":"Font","options":null},{"id":"com.apple.font_font","displayName":"Font","description":"The contents of the font file.","helpText":null,"infoUrls":[],"categoryId":"5401711f-292a-487a-be18-f99593a0477c","categoryName":"Font","options":null},{"id":"com.apple.font_name","displayName":"Name","description":"The user-visible name for the font. This field is replaced by the actual name of the font after installation. Each payload must contain exactly one font file in trueType (.ttf) or OpenType (.otf) format. Collection formats (.ttc or .otc) are not supported.\n\nFonts are identified by their embedded PostScript names. Two fonts with the same PostScript name are considered to be the same font even if their contents differ. Installing two different fonts with the same PostScript name isn't supported, and the resulting behavior is undefined.","helpText":null,"infoUrls":[],"categoryId":"5401711f-292a-487a-be18-f99593a0477c","categoryName":"Font","options":null},{"id":"com.apple.gamed_com.apple.gamed","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"7ecdd7c9-6ab2-4dac-88ef-9bdad46e1f66","categoryName":"Parental Controls Game Center","options":null},{"id":"com.apple.gamed_gkfeatureaccountmodificationallowed","displayName":"GK Feature Account Modification Allowed","description":"If true, allows account modifications.","helpText":null,"infoUrls":[],"categoryId":"7ecdd7c9-6ab2-4dac-88ef-9bdad46e1f66","categoryName":"Parental Controls Game Center","options":[{"id":"com.apple.gamed_gkfeatureaccountmodificationallowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.gamed_gkfeatureaccountmodificationallowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.ldap.account_com.apple.ldap.account","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapaccountdescription","displayName":"LDAP Account Description","description":"The description of the account.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapaccounthostname","displayName":"LDAP Account Host Name","description":"The server’s address.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapaccountpassword","displayName":"LDAP Account Password","description":"The user’s password. The password is enabled only with encrypted profiles.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapaccountusername","displayName":"LDAP Account User Name","description":"The user name.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapaccountusessl","displayName":"LDAP Account Use SSL","description":"If true, enables SSL.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":[{"id":"com.apple.ldap.account_ldapaccountusessl_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.ldap.account_ldapaccountusessl_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.ldap.account_ldapsearchsettings","displayName":"LDAP Search Settings","description":"An array of search settings dictionaries.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingdescription","displayName":"LDAP Search Setting Description","description":"The description of this search setting.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope","displayName":"LDAP Search Setting Scope","description":"The type of recursion to use in the search. It is one of the following values:\r\n\r\nBase: Only the immediate node that the search base points to.\r\n\r\nOne Level: The node plus its immediate children.\r\n\r\nSubtree: The node plus all children, regardless of depth.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":[{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope_0","displayName":"Base","description":null,"helpText":null},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope_1","displayName":"OneLevel","description":null,"helpText":null},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope_2","displayName":"Subtree","description":null,"helpText":null}]},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingsearchbase","displayName":"LDAP Search Setting Search Base","description":"The path to the node where a search should start. ","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},{"id":"com.apple.loginitems.managed_autolaunchedapplicationdictionary-managed","displayName":"Auto Launch Items","description":"Auto Launch Login Items","helpText":null,"infoUrls":[],"categoryId":"6efb8802-223a-46a7-b13f-a68f28f8b2c2","categoryName":"Login Items","options":null},{"id":"com.apple.loginitems.managed_autolaunchedapplicationdictionary-managed_item_hide","displayName":"Hide","description":"If true, hide this item in the Users & Groups login items list.","helpText":null,"infoUrls":[],"categoryId":"6efb8802-223a-46a7-b13f-a68f28f8b2c2","categoryName":"Login Items","options":[{"id":"com.apple.loginitems.managed_autolaunchedapplicationdictionary-managed_item_hide_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginitems.managed_autolaunchedapplicationdictionary-managed_item_hide_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginitems.managed_autolaunchedapplicationdictionary-managed_item_path","displayName":"Path","description":"The URL or path string to the item's location.","helpText":null,"infoUrls":[],"categoryId":"6efb8802-223a-46a7-b13f-a68f28f8b2c2","categoryName":"Login Items","options":null},{"id":"com.apple.loginitems.managed_com.apple.loginitems.managed","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"6efb8802-223a-46a7-b13f-a68f28f8b2c2","categoryName":"Login Items","options":null},{"id":"com.apple.loginwindow_adminhostinfo","displayName":"Admin Host Info","description":"If this key is included in the payload, its value is displayed in the login window as additional computer information. Before macOS 10.10, this string could contain only certain information (host name, system version, or IP address). After macOS 10.10, setting this key to any value allows the user to click the time area of the menu bar to toggle through various computer information values.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_allowlist","displayName":"Allow List","description":"The list of user GUIDs or group GUIDs of users that are allowed to log in. An asterisk '*' string specifies all users or groups.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_autologinpassword","displayName":"Autologin Password","description":"Optional user password when setting up auto login. If this key does not exist, and a user name was specified, auto login will be set up the next time the specified user logs in to the client.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_autologinusername","displayName":"Autologin Username","description":"Sets up auto login with the specified short user name.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_com.apple.loginwindow","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_denylist","displayName":"Deny List","description":"The list of user GUIDs or group GUIDs of users that cannot log in. This list takes priority over the list in the Allow List key.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_disableconsoleaccess","displayName":"Disable Console Access","description":"If true, disregards the >console special user name, which will provide a command line UI.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_disableconsoleaccess_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_disableconsoleaccess_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_disablescreenlockimmediate","displayName":"Disable Screen Lock Immediate","description":"If true, disables the immediate Screen Lock functions. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_disablescreenlockimmediate_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_disablescreenlockimmediate_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_hideadminusers","displayName":"Hide Admin Users","description":"If true, hides administrator users when showing a user list.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_hideadminusers_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_hideadminusers_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_hidelocalusers","displayName":"Hide Local Users","description":"If true, shows only network and system users when showing a user list.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_hidelocalusers_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_hidelocalusers_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_includenetworkuser","displayName":"Include Network User","description":"If true, shows network users when showing a user list.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_includenetworkuser_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_includenetworkuser_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_loginwindowtext","displayName":"Login Window Text","description":"The text to display in the Login Window.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},{"id":"com.apple.loginwindow_logoutdisabledwhileloggedin","displayName":"Log Out Disabled While Logged In","description":"If true, disables the Log Out menu item when the user is logged in. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_logoutdisabledwhileloggedin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_logoutdisabledwhileloggedin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_poweroffdisabledwhileloggedin","displayName":"Power Off Disabled While Logged In","description":"If true, disables the Power Off menu item when the user is logged in.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_poweroffdisabledwhileloggedin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_poweroffdisabledwhileloggedin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_restartdisabled","displayName":"Restart Disabled","description":"If true, disables the Restart item.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_restartdisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_restartdisabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_restartdisabledwhileloggedin","displayName":"Restart Disabled While Logged In","description":"If true, disables the Restart menu item when the user is logged in.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_restartdisabledwhileloggedin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_restartdisabledwhileloggedin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_showfullname","displayName":"Show Full Name","description":"If true, shows the name and password dialog; if false, displays a list of users. Enabling this setting overrides the behavior of \"Show other users managed\". It's recommended to only use either \"Show full name\" or \"Show other users managed\", but not both.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_showfullname_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_showfullname_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_showinputmenu","displayName":"Show Input Menu","description":"If `true`, the system shows the Input Menu in the Login Window.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_showinputmenu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_showinputmenu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_showotherusers_managed","displayName":"Show Other Users Managed","description":"If true, displays Other... when showing a list of users.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_showotherusers_managed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_showotherusers_managed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_shutdowndisabled","displayName":"Shut Down Disabled","description":"If true, disables the Shut Down button.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_shutdowndisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_shutdowndisabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_shutdowndisabledwhileloggedin","displayName":"Shut Down Disabled While Logged In","description":"If true, disables the Shut Down menu item when the user is logged in.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_shutdowndisabledwhileloggedin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_shutdowndisabledwhileloggedin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.loginwindow_sleepdisabled","displayName":"Sleep Disabled","description":"If true, disables the Sleep button.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_sleepdisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_sleepdisabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_aadwebsitessousingthisprofileenabled","displayName":"Single sign-on for work or school sites using this profile enabled","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\n\nIf you enable or disable this policy, 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will be turned off.\n\nIf you don't configure this policy, users can control whether to use SSO using other credentials present on the machine in edge://settings/profiles/multiProfileSettings.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#aadwebsitessousingthisprofileenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_aadwebsitessousingthisprofileenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_aadwebsitessousingthisprofileenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_accesscontrolallowmethodsincorspreflightspecconformant","displayName":"Make Access-Control-Allow-Methods matching in CORS preflight spec conformant","description":"This policy controls whether request methods are uppercased when matching with Access-Control-Allow-Methods response headers in CORS preflight.\n\nIf you disable this policy, request methods are uppercased. This is the behavior on or before Microsoft Edge 108.\n\nIf you enable or don't configure this policy, request methods are not uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT.\n\nThis would reject fetch(url, {method: 'Foo'}) + \"Access-Control-Allow-Methods: FOO\" response header,\nand would accept fetch(url, {method: 'Foo'}) + \"Access-Control-Allow-Methods: Foo\" response header.\n\nNote: request methods \"post\" and \"put\" are not affected, while \"patch\" is affected.\n\nThis policy is intended to be temporary and will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#accesscontrolallowmethodsincorspreflightspecconformant"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_accesscontrolallowmethodsincorspreflightspecconformant_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_accesscontrolallowmethodsincorspreflightspecconformant_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_accessibilityimagelabelsenabled","displayName":"Let screen reader users get image descriptions from Microsoft","description":"Lets screen reader users get descriptions of unlabeled images on the web.\n\nIf you enable or don't configure this policy, users have the option of using an anonymous Microsoft service. This service provides automatic descriptions for unlabeled images users encounter on the web when they're using a screen reader.\n\nIf you disable this policy, users can't enable the Get Image Descriptions from Microsoft feature.\n\nWhen this feature is enabled, the content of images that need a generated description is sent to Microsoft servers to generate a description.\n\nNo cookies or other user data is sent to Microsoft, and Microsoft doesn't save or log any image content.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#accessibilityimagelabelsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_accessibilityimagelabelsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_accessibilityimagelabelsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_acknowledgeddatacollectionpolicy","displayName":"Automatically acknowledge data collection policy","description":"Suppress the Required Data Collection policy dialog from being shown to users.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/deployoffice/privacy/mac-privacy-preferences#preference-setting-for-the-required-data-notice-dialog-for-microsoft-autoupdate"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_acknowledgeddatacollectionpolicy_0","displayName":"Acknowledge - send required data","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_acknowledgeddatacollectionpolicy_1","displayName":"Acknowledge - send required and optional data (Deprecated)","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_additionaldnsquerytypesenabled","displayName":"Allow DNS queries for more DNS record types","description":"This policy controls whether Microsoft Edge can query more DNS record types when making insecure (non-Secure DNS) requests.\n\nIf this policy is unset or set to Enabled, more record types such as HTTPS (DNS type 65) may be queried in addition to A (DNS type 1) and AAAA (DNS type 28).\n\nIf this policy is set to Disabled, Microsoft Edge will only query A and AAAA record types for insecure DNS requests.\n\nThis setting doesn't affect DNS queries made via Secure DNS, which may always use more record types.\n\nNote: This is a temporary policy and is planned for removal in a future version of Microsoft Edge. After removal, Microsoft Edge will always be able to query more DNS types during insecure requests.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#additionaldnsquerytypesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_additionaldnsquerytypesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_additionaldnsquerytypesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_additionalsearchboxenabled","displayName":"Enable additional search box in browser","description":"A search box is an additional text input field located next to the address bar in a web browser. It allows users to perform web searches directly from the browser interface.\n\nIf you enable or don't configure this policy, the search box will be visible and available for use.\nUsers can toggle the search box in Edge Settings page edge://settings/appearance#SearchBoxInToolbar.\n\nIf you disable this policy, search box will not be visible, and users will have to use the address bar or navigate to a search engine to perform web searches.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#additionalsearchboxenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_additionalsearchboxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_additionalsearchboxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_addressbarmicrosoftsearchinbingproviderenabled","displayName":"Enable Microsoft Search in Bing suggestions in the address bar (Deprecated)","description":"Enables the display of relevant Microsoft Search in Bing suggestions in the address bar's suggestion list when the user types a search string in the address bar. If you enable or don't configure this policy, users can see internal results powered by Microsoft Search in Bing in the Microsoft Edge address bar suggestion list. To see the Microsoft Search in Bing results, the user must be signed into Microsoft Edge with their Azure AD account for that organization.\nIf you disable this policy, users can't see internal results in the Microsoft Edge address bar suggestion list.\nIf you have enabled the set of policies which forces a default search provider (\"DefaultSearchProviderEnabled\", \"DefaultSearchProviderName\" and \"DefaultSearchProviderSearchURL\"), and the search provider specified is not Bing, then this policy is not applicable and there will be no Microsoft Search in Bing suggestions in the address bar's suggestion list.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#addressbarmicrosoftsearchinbingproviderenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_addressbarmicrosoftsearchinbingproviderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_addressbarmicrosoftsearchinbingproviderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_addressbartrendingsuggestenabled","displayName":"Enable Microsoft Bing trending suggestions in the address bar","description":"This policy controls whether Microsoft Bing trending suggestions appear in the address bar’s suggestion dropdown when users click the address bar while on a New Tab Page.\n\nIf this policy is enabled or not configured, Microsoft Bing trending suggestions will appear in the address bar suggestion dropdown.\n\nIf this policy is disabled, Microsoft Edge will not display Microsoft Bing trending suggestions when users click the address bar.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#addressbartrendingsuggestenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_addressbartrendingsuggestenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_addressbartrendingsuggestenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_addressbarworksearchresultsenabled","displayName":"Enable Work Search suggestions in the address bar","description":"Enables the display of relevant workplace suggestions in the address bar’s suggestion dropdown when users type a query in the address bar.\n\nIf this policy is enabled or not configured, users can view internal work-related suggestions, such as bookmarks, files, and people results powered by Microsoft 365, in the Microsoft Edge address bar suggestion dropdown. To access these results, users must be signed into Microsoft Edge with their Entra ID account associated with that organization.\n\nIf this policy is disabled, users will not see internal workplace results in the Microsoft Edge address bar suggestion dropdown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#addressbarworksearchresultsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_addressbarworksearchresultsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_addressbarworksearchresultsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_adhoccodesigningforpwasenabled","displayName":"Native application signing during Progressive Web Application installation","description":"Enabling this policy or leaving it unset enables the use of ad-hoc signatures for the native application that's created when installing a Progressive Web Application (PWA). This ensures that each installed application has a unique identity to macOS system components.\n\nDisabling this policy will result in every native application created when installing Progressive Web Applications having the same identity. This can interfere with macOS functionality.\n\nOnly turn off the policy if you are using an endpoint security solution that blocks applications with an ad-hoc signature.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#adhoccodesigningforpwasenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_adhoccodesigningforpwasenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_adhoccodesigningforpwasenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads","description":"Controls whether ads are blocked on sites with intrusive ads. You can set this policy to one of the following options:\n\n* 1 = Allow ads on all sites.\n\n* 2 = Block ads on sites with intrusive ads (Default value).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#adssettingforintrusiveadssites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_adssettingforintrusiveadssites_0","displayName":"Allow ads on all sites","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_adssettingforintrusiveadssites_1","displayName":"Block ads on sites with intrusive ads. (Default value)","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_adstransparencyenabled","displayName":"Configure if the ads transparency feature is enabled","description":"Lets you decide whether the ads transparency feature is enabled. This behavior only applies to the \"balanced\" mode of tracking prevention, and does not impact \"basic\" or \"strict\" modes. Your users' tracking prevention level can be configured using the \"TrackingPrevention\" policy. AdsTransparencyEnabled will only have an effect if \"TrackingPrevention\" is set to TrackingPreventionBalanced or is not configured.\n\nIf you enable or don't configure this policy, transparency metadata provided by ads will be available to the user when the feature is active.\n\nWhen the feature is enabled, Tracking Prevention will enable exceptions for the associated ad providers that have met Microsoft's privacy standards.\n\nIf you disable this policy, Tracking Prevention will not adjust its behavior even when transparency metadata is provided by ads.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#adstransparencyenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_adstransparencyenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_adstransparencyenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_aigenthemesenabled","displayName":"Enables DALL-E themes generation","description":"This policy lets you generate browser themes using DALL-E and apply them to Microsoft Edge.\n\nIf you enable or don't configure this policy, the AI generated themes will be enabled.\n\nIf you disable this policy, the AI generated themes will be disabled for your organization.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#aigenthemesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_aigenthemesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_aigenthemesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allhttpauthschemesallowedfororigins","displayName":"List of origins that allow all HTTP authentication","description":"Set this policy to specify which origins allow all the HTTP authentication schemes Microsoft Edge supports regardless of the \"AuthSchemes\" policy.\n\nFormat the origin pattern according to this format (https://support.google.com/chrome/a?p=url_blocklist_filter_format). Up to 1,000 exceptions can be defined in \"AllHttpAuthSchemesAllowedForOrigins\".\nWildcards are allowed for the whole origin or parts of the origin. Parts include the scheme, host, or port.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allhttpauthschemesallowedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_allowbackforwardcacheforcachecontrolnostorepageenabled","displayName":"Allow pages with Cache-Control: no-store header to enter back/forward cache","description":"This policy controls if a page with Cache-Control: no-store header can be stored in back/forward cache. The website setting this header may not expect the page to be restored from back/forward cache since some sensitive information could still be displayed after the restoration even if it is no longer accessible.\n\nIf you enable or don't configure this policy, the page with Cache-Control: no-store header might be restored from back/forward cache unless the cache eviction is triggered (e.g. when there is HTTP-only cookie change to the site).\n\nIf you disable this policy, the page with Cache-Control: no-store header will not be stored in back/forward cache.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowbackforwardcacheforcachecontrolnostorepageenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowbackforwardcacheforcachecontrolnostorepageenabled_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowbackforwardcacheforcachecontrolnostorepageenabled_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowcertswithoutmatchingemailaddress","displayName":"Allow S/MIME certificates without a matching email address","description":"Allow users to decrypt and encrypt S/MIME messages when the S/MIME certificate does not match the email address.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#allow-smime-certificates-without-a-matching-email-address"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_allowcertswithoutmatchingemailaddress_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowcertswithoutmatchingemailaddress_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowcrossoriginauthprompt","displayName":"Allow cross-origin HTTP Basic Auth prompts","description":"Controls whether third-party sub-content on a page can open an HTTP Basic Auth dialog box.\n\nTypically, this is disabled as a phishing defense. If you don't configure this policy, it's disabled and third-party sub-content can't open a HTTP Basic Auth dialog box.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowcrossoriginauthprompt"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowcrossoriginauthprompt_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowcrossoriginauthprompt_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowdeletingbrowserhistory","displayName":"Enable deleting browser and download history","description":"Enables deleting browser history and download history and prevents users from changing this setting.\n\nNote that even with this policy is disabled, the browsing and download history aren't guaranteed to be retained: users can edit or delete the history database files directly, and the browser itself may remove (based on expiration period) or archive any or all history items at any time.\n\nIf you enable this policy or don't configure it, users can delete the browsing and download history.\n\nIf you disable this policy, users can't delete browsing and download history.\n\nIf you enable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you enable both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how this policy is configured.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowdeletingbrowserhistory"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowdeletingbrowserhistory_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowdeletingbrowserhistory_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace","description":"Setting the policy on Microsoft Edge turns on the restricted sign-in feature in Google Workspace and prevents users from changing this setting. Users can only access Google tools using accounts from the specified domains. To allow gmail or googlemail accounts, add consumer_accounts to the list of domains. This policy is based on the Chrome policy of the same name.\n\nIf you don't provide a domain name or leave this policy unset, users can access Google Workspace with any account.\n\nUsers cannot change or override this setting.\n\nNote: This policy causes the X-GoogApps-Allowed-Domains header to be appended to all HTTP and HTTPS requests to all google.com domains, as described in https://go.microsoft.com/fwlink/?linkid=2197973.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#alloweddomainsforapps"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_allowedemaildomains","displayName":"Allowed Email Domains","description":"Specify a list of email domains that are allowed to be added to the Outlook profile (e.g. contoso.com). Subdomains will be automatically included (e.g. specifying contoso.com will also allow foo.contoso.com).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#allow-only-corporate-mailboxes-to-be-added"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":null},{"id":"com.apple.managedclient.preferences_allowedthreats","displayName":"Allowed threats","description":"List of threats (identified by their name) that are not blocked by the product and are instead allowed to run.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#allowed-threats"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_allowfileselectiondialogs","displayName":"Allow file selection dialogs","description":"Allow access to local files by letting Microsoft Edge display file selection dialogs.\n\nIf you enable or don't configure this policy, users can open file selection dialogs as normal.\n\nIf you disable this policy, whenever the user performs an action that triggers a file selection dialog (like importing favorites, uploading files, or saving links), a message is displayed instead, and the user is assumed to have clicked Cancel on the file selection dialog.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowfileselectiondialogs"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowfileselectiondialogs_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowfileselectiondialogs_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowpopupsduringpageunload","displayName":"Allows a page to show popups during its unloading","description":"This policy allows an admin to specify that a page can show popups during its unloading.\n\nWhen the policy is set to enabled, pages are allowed to show popups while they're being unloaded.\n\nWhen the policy is set to disabled or unset, pages aren't allowed to show popups while they're being unloaded. This is as per the spec: (https://html.spec.whatwg.org/#apis-for-creating-and-navigating-browsing-contexts-by-name).\n\nThis policy will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowpopupsduringpageunload"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowpopupsduringpageunload_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowpopupsduringpageunload_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowsurfgame","displayName":"Allow surf game","description":"If you disable this policy, users won't be able to play the surf game when the device is offline or if the user navigates to edge://surf.\n\nIf you enable or don't configure this policy, users can play the surf game.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowsurfgame"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowsurfgame_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowsurfgame_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowsyncxhrinpagedismissal","displayName":"Allow pages to send synchronous XHR requests during page dismissal","description":"This policy lets you specify that a page can send synchronous XHR requests during page dismissal.\n\nIf you enable this policy, pages can send synchronous XHR requests during page dismissal.\n\nIf you disable this policy or don't configure this policy, pages aren't allowed to send synchronous XHR requests during page dismissal.\n\nThis policy is temporary and will be removed in a future release.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowsyncxhrinpagedismissal"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowsyncxhrinpagedismissal_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowsyncxhrinpagedismissal_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowtrackingforurls","displayName":"Configure tracking prevention exceptions for specific sites","description":"Configure the list of URL patterns that are excluded from tracking prevention.\n\nIf you configure this policy, the list of configured URL patterns is excluded from tracking prevention.\n\nIf you don't configure this policy, the global default value from the \"Block tracking of users' web-browsing activity\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowtrackingforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_allowvisualbasictobindtosystem","displayName":"Allow Visual Basic macros to use system APIs","description":"Allow Visual Basic macros to use DECLARE to bind to the system() OS API. Recommended: false.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_allowvisualbasictobindtosystem_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowvisualbasictobindtosystem_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_allowwebauthnwithbrokentlscerts","displayName":"Allow Web Authentication requests on sites with broken TLS certificates.","description":"If you enable this policy, Microsoft Edge will allow Web Authentication requests on websites that have TLS certificates with errors (i.e. websites considered not secure).\n\nIf you disable or don't configure this policy, the default behavior of blocking such requests will apply.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowwebauthnwithbrokentlscerts"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowwebauthnwithbrokentlscerts_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowwebauthnwithbrokentlscerts_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_alternateerrorpagesenabled","displayName":"Suggest similar pages when a webpage can’t be found","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\n\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\n\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\n\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\nSpecifically, there's a **Suggest similar pages when a webpage can’t be found** toggle, which the user can switch on or off. Note that if you have enable this policy (AlternateErrorPagesEnabled), the Suggest similar pages when a webpage can’t be found setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the Suggest similar pages when a webpage can’t be found setting is turned off, and the user can't change the setting by using the toggle.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#alternateerrorpagesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_alternateerrorpagesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_alternateerrorpagesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_alwaysopenpdfexternally","displayName":"Always open PDF files externally","description":"Disables the internal PDF viewer in Microsoft Edge.\n\nIf you enable this policy Microsoft Edge treats PDF files as downloads and lets users open them with the default application.\n\nIf you don't configure this policy or disable it, Microsoft Edge will open PDF files (unless the user disables it).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#alwaysopenpdfexternally"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_alwaysopenpdfexternally_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_alwaysopenpdfexternally_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for InPrivate and Guest profiles","description":"Configure this policy to allow/disallow ambient authentication for InPrivate and Guest profiles in Microsoft Edge.\n\nAmbient Authentication is http authentication with default credentials when explicit credentials aren't provided via NTLM/Kerberos/Negotiate challenge/response schemes.\n\nIf you set the policy to RegularOnly (value 0), it allows ambient authentication for Regular sessions only. InPrivate and Guest sessions won't be allowed to ambiently authenticate.\n\nIf you set the policy to InPrivateAndRegular (value 1), it allows ambient authentication for InPrivate and Regular sessions. Guest sessions won't be allowed to ambiently authenticate.\n\nIf you set the policy to GuestAndRegular (value 2), it allows ambient authentication for Guest and Regular sessions. InPrivate sessions won't be allowed to ambiently authenticate\n\nIf you set the policy to All (value 3), it allows ambient authentication for all sessions.\n\nNote that ambient authentication is always allowed on regular profiles.\n\nIf you don't configure this policy, InPrivate and Guest sessions will not be able to ambiently authenticate in future releases of Microsoft Edge, because they will be disallowed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#ambientauthenticationinprivatemodesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_ambientauthenticationinprivatemodesenabled_0","displayName":"Enable ambient authentication in regular sessions only.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_ambientauthenticationinprivatemodesenabled_1","displayName":"Enable ambient authentication in InPrivate and regular sessions","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_ambientauthenticationinprivatemodesenabled_2","displayName":"Enable ambient authentication in guest and regular sessions","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_ambientauthenticationinprivatemodesenabled_3","displayName":"Enable ambient authentication in regular, InPrivate and guest sessions","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_appcacheforceenabled","displayName":"Allows the AppCache feature to be re-enabled, even if it's turned off by default","description":"If you set this policy to true, the AppCache is enabled, even when AppCache in Microsoft Edge is not available by default.\n\nIf you set this policy to false, or don't set it, AppCache will follow Microsoft Edge's defaults.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#appcacheforceenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_appcacheforceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_appcacheforceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem","displayName":"Applications","description":null,"helpText":null,"infoUrls":["https://github.com/pbowden-msft/Payloads"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app","displayName":"Company Portal","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_application id","displayName":"Company Portal Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_lcid","displayName":"Company Portal LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_company portal.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app","displayName":"Microsoft Defender ATP (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_application id","displayName":"Microsoft Defender ATP Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_lcid","displayName":"Microsoft Defender ATP LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app","displayName":"Microsoft Defender","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_application id","displayName":"Microsoft Defender Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_lcid","displayName":"Microsoft Defender LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app","displayName":"Microsoft Edge Beta (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_application id","displayName":"Microsoft Edge Beta Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_lcid","displayName":"Microsoft Edge Beta LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app","displayName":"Microsoft Edge Canary (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_application id","displayName":"Microsoft Edge Canary Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_lcid","displayName":"Microsoft Edge Canary LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app","displayName":"Microsoft Edge Dev (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_application id","displayName":"Microsoft Edge Dev Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_lcid","displayName":"Microsoft Edge Dev LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app","displayName":"Microsoft Edge (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_application id","displayName":"Microsoft Edge Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_lcid","displayName":"Microsoft Edge LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app","displayName":"Microsoft Excel","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_application id","displayName":"Microsoft Excel Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_lcid","displayName":"Microsoft Excel LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft excel.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app","displayName":"Microsoft OneNote","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_application id","displayName":"Microsoft OneNote Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_lcid","displayName":"Microsoft OneNote LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app","displayName":"Microsoft Outlook","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_application id","displayName":"Microsoft Outlook Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_lcid","displayName":"Microsoft Outlook LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app","displayName":"Microsoft PowerPoint","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_application id","displayName":"Microsoft PowerPoint Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_lcid","displayName":"Microsoft PowerPoint LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app","displayName":"Microsoft Remote Desktop (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_application id","displayName":"Microsoft Remote Desktop Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_lcid","displayName":"Microsoft Remote Desktop LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app","displayName":"Microsoft Teams (work or school).app","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_application id","displayName":"Microsoft Teams (work or school) Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_lcid","displayName":"Microsoft Teams (work or school) LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app","displayName":"Microsoft Teams classic","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_application id","displayName":"ApplicationsSystem//Applications/Microsoft Teams classic.app/Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_lcid","displayName":"Microsoft Teams classic LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app","displayName":"Microsoft Teams (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_application id","displayName":"Microsoft Teams Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_lcid","displayName":"Microsoft Teams LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_manifestserver","displayName":"Update channel override (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app","displayName":"Microsoft Word","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_application id","displayName":"Microsoft Word Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_lcid","displayName":"Microsoft Word LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app","displayName":"OneDrive","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_application id","displayName":"OneDrive Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_lcid","displayName":"OneDrive LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app","displayName":"Skype for Business","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_application id","displayName":"Skype for Business Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_lcid","displayName":"Skype for Business LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app","displayName":"Windows App","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_application id","displayName":"Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname","displayName":"Channel Name","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_lcid","displayName":"LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_manifestserver","displayName":"Manifest Server","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app","displayName":"Microsoft Auto Update","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_application id","displayName":"Microsoft AutoUpdate Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_lcid","displayName":"Microsoft AutoUpdate LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_askbeforecloseenabled","displayName":"Get user confirmation before closing a browser window with multiple tabs","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\n\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\n\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#askbeforecloseenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_askbeforecloseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_askbeforecloseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_audiocaptureallowed","displayName":"Allow or block audio capture","description":"Allows you to set whether a user is prompted to grant a website access to their audio capture device. This policy applies to all URLs except for those configured in the \"AudioCaptureAllowedUrls\" list.\n\nIf you enable this policy or don't configure it (the default setting), the user is prompted for audio capture access except from the URLs in the \"AudioCaptureAllowedUrls\" list. These listed URLs are granted access without prompting.\n\nIf you disable this policy, the user is not prompted, and audio capture is accessible only to the URLs configured in \"AudioCaptureAllowedUrls\".\n\nThis policy affects all types of audio inputs, not only the built-in microphone.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#audiocaptureallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_audiocaptureallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_audiocaptureallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_audiocaptureallowedurls","displayName":"Sites that can access audio capture devices without requesting permission","description":"Specify websites, based on URL patterns, that can use audio capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to audio capture devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#audiocaptureallowedurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_audiosandboxenabled","displayName":"Allow the audio sandbox to run","description":"This policy controls the audio process sandbox.\n\nIf you enable this policy, the audio process will run sandboxed.\n\nIf you disable this policy, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\n\nIf you don't configure this policy, the default configuration for the audio sandbox will be used, which might differ based on the platform.\n\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#audiosandboxenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_audiosandboxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_audiosandboxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_authnegotiatedelegateallowlist","displayName":"Specifies a list of servers that Microsoft Edge can delegate user credentials to","description":"Configure the list of servers that Microsoft Edge can delegate to.\n\nSeparate multiple server names with commas. Wildcards (*) are allowed.\n\nIf you don't configure this policy Microsoft Edge won't delegate user credentials even if a server is detected as Intranet.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#authnegotiatedelegateallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_authschemes","displayName":"Supported authentication schemes","description":"Specifies which HTTP authentication schemes are supported.\n\nYou can configure the policy by using these values: 'basic', 'digest', 'ntlm', and 'negotiate'. Separate multiple values with commas.\n\nIf you don't configure this policy, all four schemes are used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#authschemes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_authserverallowlist","displayName":"Configure list of allowed authentication servers","description":"Specifies which servers to enable for integrated authentication. Integrated authentication is only enabled when Microsoft Edge receives an authentication challenge from a proxy or from a server in this list.\n\nSeparate multiple server names with commas. Wildcards (*) are allowed.\n\nIf you don't configure this policy, Microsoft Edge tries to detect if a server is on the intranet - only then will it respond to IWA requests. If the server is on the internet, IWA requests from it are ignored by Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#authserverallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_autodiscardsleepingtabsenabled","displayName":"Configure auto discard sleeping tabs","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab will need to be reloaded.\n\nIf the \"SleepingTabsEnabled\" policy is enabled, then this feature will be enabled by default.\n\nIf the \"SleepingTabsEnabled\" is disabled, then this feature will be disabled by default and cannot be enabled.\n\nIf enabled, idle background tabs will be discarded after 1.5 days.\n\nIf disabled, idle background tab will not be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autodiscardsleepingtabsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autodiscardsleepingtabsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autodiscardsleepingtabsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_autofilladdressenabled","displayName":"Enable AutoFill for addresses","description":"Enables the AutoFill feature and allows users to auto-complete address information in web forms using previously stored information.\n\nIf this policy is enabled or not configured, users can manage AutoFill for addresses in Microsoft Edge settings. AutoFill allows users to complete address fields in web forms using previously saved information.\n\nIf this policy is disabled, Microsoft Edge does not suggest, fill in, or save address information. AutoFill is also disabled for all web forms except payment and password fields, and previously saved addresses are not available.\n\nDisabling this policy also turns off \"EdgeAutofillMlEnabled\".\n\nNote that if you disable this policy you also stop all activity for all web forms, except payment and password forms. No further entries are saved, and Microsoft Edge won't suggest or AutoFill any previous entries.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autofilladdressenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autofilladdressenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autofilladdressenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_autofillcreditcardenabled","displayName":"Enable AutoFill for credit cards","description":"Enables Microsoft Edge's AutoFill feature and lets users auto complete credit card information in web forms using previously stored information.\n\nIf you disable this policy, AutoFill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.\n\nIf you enable this policy or don't configure it, users can control AutoFill for credit cards.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autofillcreditcardenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autofillcreditcardenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autofillcreditcardenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_autofillmembershipsenabled","displayName":"Save and fill memberships","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\n\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autofillmembershipsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autofillmembershipsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autofillmembershipsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_autoimportatfirstrun","displayName":"Automatically import another browser's data and settings at first run","description":"If you enable this policy, all supported datatypes and settings from the specified browser will be silently and automatically imported at first run. During the First Run Experience, the import section will also be skipped.\n\nThe browser data from Microsoft Edge Legacy will always be silently migrated at the first run, irrespective of the value of this policy. You can use the following values for this policy:\n\n* 0 = Automatically imports all supported datatypes and settings from the default browser\n\n* 1 = Automatically imports all supported datatypes and settings from Internet Explorer\n\n* 2 = Automatically imports all supported datatypes and settings from Google Chrome\n\n* 3 = Automatically imports all supported datatypes and settings from Safari\n\n* 4 = Disables automatic import, and the import section of the first-run experience is skipped\n\n* 5 = Automatically imports all supported datatypes and settings from Mozilla Firefox\n\nIf this policy is set to the default value (0), then the datatypes corresponding to the default browser on the managed device will be imported.\n\nIf the browser specified as the value of this policy is not present in the managed device, Microsoft Edge will simply skip the import without any notification to the user.\n\nIf you set this policy to 'DisabledAutoImport' (4), the import section of the first-run experience is skipped entirely and Microsoft Edge doesn't import browser data and settings automatically.\n\nIf this policy is set to the value of Internet Explorer (1), the following datatypes will be imported from Internet Explorer:\n1. Favorites or bookmarks\n2. Saved passwords\n3. Search engines\n4. Browsing history\n5. Home page\n\nIf this policy is set to the value of Google Chrome (2), the following datatypes will be imported from Google Chrome:\n1. Favorites\n2. Saved passwords\n3. Addresses and more\n4. Payment info\n5. Browsing history\n6. Settings\n7. Pinned and Open tabs\n8. Extensions\n9. Cookies\n\nNote: For more details on what is imported from Google Chrome, please see https://go.microsoft.com/fwlink/?linkid=2120835\n\nIf this policy is set to the value of Safari (3), user data is no longer imported into Microsoft Edge. This is due to the way Full Disk Access works on Mac.\nOn macOS Mojave and above, it's no longer possible to have automated and unattended import of Safari data into Microsoft Edge.\n\nStarting with Microsoft Edge version 83, if this policy is set to the value of Mozilla Firefox (5), the following datatypes will be imported from Mozilla Firefox:\n1. Favorites or bookmarks\n2. Saved passwords\n3. Addresses and more\n4. Browsing History\n\nIf you want to restrict specific datatypes from getting imported on the managed devices, you can use this policy with other policies such as \"ImportAutofillFormData\", \"ImportBrowserSettings\", \"ImportFavorites\", and etc.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoimportatfirstrun"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autoimportatfirstrun_0","displayName":"Automatically imports all supported datatypes and settings from the default browser","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autoimportatfirstrun_1","displayName":"Automatically imports all supported datatypes and settings from Internet Explorer","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autoimportatfirstrun_2","displayName":"Automatically imports all supported datatypes and settings from Google Chrome","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autoimportatfirstrun_3","displayName":"Automatically imports all supported datatypes and settings from Safari","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autoimportatfirstrun_4","displayName":"Disables automatic import, and the import section of the first-run experience is skipped","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autoimportatfirstrun_5","displayName":"Automatically imports all supported datatypes and settings from Mozilla Firefox","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_autolaunchprotocolscomponentenabled","displayName":"AutoLaunch Protocols Component Enabled","description":"Specifies whether the AutoLaunch Protocols component should be enabled. This component allows Microsoft to provide a list similar to that of the \"AutoLaunchProtocolsFromOrigins\" policy, allowing certain external protocols to launch without prompt or blocking certain protocols (on specified origins). By default, this component is enabled.\n\nIf you enable or don't configure this policy, the AutoLaunch Protocols component is enabled.\n\nIf you disable this policy, the AutoLaunch Protocols component is disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autolaunchprotocolscomponentenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autolaunchprotocolscomponentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autolaunchprotocolscomponentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_automaticallydownloadexternalcontent","displayName":"Download embedded images","description":"Automatically downloading images will provide users with a better messaging experience. However, be aware of the privacy considerations if you are enabling this setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#specify-when-pictures-are-downloaded-for-email"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_automaticallydownloadexternalcontent_0","displayName":"Never download images","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automaticallydownloadexternalcontent_1","displayName":"Automatically download images from users in the address book","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automaticallydownloadexternalcontent_2","displayName":"Always download images regardless of sender","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_automaticdefinitionupdateenabled","displayName":"Automatic security intelligence updates","description":"Determines whether security intelligence updates are installed automatically:","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-automatic-security-intelligence-updates"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"com.apple.managedclient.preferences_automaticdefinitionupdateenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automaticdefinitionupdateenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_automaticdownloadsallowedforurls","displayName":"Allow multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to perform multiple successive automatic downloads.\nIf you don't configure this policy, \"DefaultAutomaticDownloadsSetting\" applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automaticdownloadsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_automaticdownloadsblockedforurls","displayName":"Block multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, where multiple successive automatic downloads aren't allowed.\nIf you don't configure this policy, \"DefaultAutomaticDownloadsSetting\" applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automaticdownloadsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_automaticfullscreenallowedforurls","displayName":"Allow automatic full screen on specified sites","description":"For security reasons, the\nrequestFullscreen() web API\nrequires a prior user gesture (\"transient activation\") to be called or it will\nfail. Users' personal settings may allow certain origins to call this API\nwithout a prior user gesture.\n\nThis policy supersedes users' personal settings and allows matching origins to\ncall the API without a prior user gesture.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\nWildcards (*) are allowed.\n\nOrigins matching both blocked and allowed policy patterns will be blocked.\nOrigins not specified by policy or user settings will require a prior user\ngesture to call this API.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automaticfullscreenallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_automaticfullscreenblockedforurls","displayName":"Block automatic full screen on specified sites","description":"For security reasons, the\nrequestFullscreen() web API\nrequires a prior user gesture (\"transient activation\") to be called or it will\nfail. Users' personal settings may allow certain origins to call this API\nwithout a prior user gesture.\n\nThis policy supersedes users' personal settings and blocks matching origins\nfrom calling the API without a prior user gesture.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\nWildcards (*) are allowed.\n\nOrigins matching both blocked and allowed policy patterns will be blocked.\nOrigins not specified by policy or user settings will require a prior user\ngesture to call this API.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automaticfullscreenblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_automatichttpsdefault","displayName":"Configure Automatic HTTPS (Deprecated)","description":"This policy lets you manage settings for \"AutomaticHttpsDefault\", which switches connections from HTTP to HTTPS.\n\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\n\nMicrosoft Edge attempts to upgrade some navigations from HTTP to HTTPS, when possible. This policy can be used to disable this behavior. If set to \"AlwaysUpgrade\" or left unset, this feature will be enabled by default.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nStarting in Microsoft Edge 111, \"UpgradePossibleDomains\" is deprecated and is treated the same as \"DisableAutomaticHttps\". It won't work in Microsoft Edge version 114.\n\nPolicy options mapping:\n\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\n\n* UpgradeCapableDomains (1) = (Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\n\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automatichttpsdefault"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_automatichttpsdefault_0","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automatichttpsdefault_1","displayName":"(Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automatichttpsdefault_2","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_automaticsamplesubmission","displayName":"Enable / disable automatic sample submissions","description":"Determines whether suspicious samples (that are likely to contain threats) are sent to Microsoft. You are prompted if the submitted file is likely to contain personal information.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-automatic-sample-submissions"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"com.apple.managedclient.preferences_automaticsamplesubmission_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automaticsamplesubmission_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_automaticsamplesubmissionconsent","displayName":"Automatic sample submission Consent","description":"Sends sample files to Microsoft to help protect device users and your organization from potential threats","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-automatic-sample-submissions"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"com.apple.managedclient.preferences_automaticsamplesubmissionconsent_0","displayName":"none","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automaticsamplesubmissionconsent_1","displayName":"safe","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_automaticsamplesubmissionconsent_2","displayName":"all","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_automaticuploadbandwidthpercentage","displayName":"Automatic upload bandwidth percentage","description":"Enables the sync app to automatically set the amount of bandwidth used based on available bandwidth for uploading files. Accepted values are from 1 through 99.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#automaticuploadbandwidthpercentage"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_autoopenallowedforurls","displayName":"URLs where AutoOpenFileTypes can apply","description":"A list of URLs to which \"AutoOpenFileTypes\" will apply to. This policy has no impact on automatically open values set by users via the download shelf ... > \"Always open files of this type\" menu entry.\n\nIf you set URLs in this policy, files will only automatically open by policy if the URL is part of this set and the file type is listed in \"AutoOpenFileTypes\". If either condition is false, the download won't automatically open by policy.\n\nIf you don't set this policy, all downloads where the file type is in \"AutoOpenFileTypes\" will automatically open.\n\nA URL pattern has to be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoopenallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_autoopenfiletypes","displayName":"List of file types that should be automatically opened on download","description":"This policy sets a list of file types that should be automatically opened on download. Note: The leading separator should not be included when listing the file type, so list \"txt\" instead of \".txt\".\n\nBy default, these file types will be automatically opened on all URLs. You can use the \"AutoOpenAllowedForURLs\" policy to restrict the URLs for which these file types will be automatically opened on.\n\nFiles with types that should be automatically opened will still be subject to the enabled Microsoft Defender SmartScreen checks and won't be opened if they fail those checks.\n\nFile types that a user has already specified to automatically be opened will continue to do so when downloaded. The user will continue to be able to specify other file types to be automatically opened.\n\nIf you don't set this policy, only file types that a user has already specified to automatically be opened will do so when downloaded.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoopenfiletypes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_autoplayallowed","displayName":"Allow media autoplay for websites","description":"This policy sets the media autoplay policy for websites.\n\nThe default setting, \"Not configured\" respects the current media autoplay settings and lets users configure their autoplay settings.\n\nSetting to \"Enabled\" sets media autoplay to \"Allow\". All websites are allowed to autoplay media. Users can’t override this policy.\n\nSetting to \"Disabled\" sets media autoplay to \"Block\". No websites are allowed to autoplay media. Users can’t override this policy.\n\nA tab will need to be closed and re-opened for this policy to take effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoplayallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autoplayallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autoplayallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_autoplayallowlist","displayName":"Allow media autoplay on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to autoplay media.\n\nIf you don't configure this policy, the global default value from the \"AutoplayAllowed\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nNote: * is not an accepted value for this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoplayallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_autoselectcertificateforurls","displayName":"Automatically select client certificates for these sites","description":"Setting the policy lets you make a list of URL patterns that specify sites for which Microsoft Edge can automatically select a client certificate. The value is an array of stringified JSON dictionaries, each with the form { \"pattern\": \"$URL_PATTERN\", \"filter\" : $FILTER }, where $URL_PATTERN is a content setting pattern. $FILTER restricts the client certificates the browser automatically selects from. Independent of the filter, only certificates that match the server's certificate request are selected.\n\nExamples for the usage of the $FILTER section:\n\n* When $FILTER is set to { \"ISSUER\": { \"CN\": \"$ISSUER_CN\" } }, only client certificates issued by a certificate with the CommonName $ISSUER_CN are selected.\n\n* When $FILTER contains both the \"ISSUER\" and the \"SUBJECT\" sections, only client certificates that satisfy both conditions are selected.\n\n* When $FILTER contains a \"SUBJECT\" section with the \"O\" value, a certificate needs at least one organization matching the specified value to be selected.\n\n* When $FILTER contains a \"SUBJECT\" section with a \"OU\" value, a certificate needs at least one organizational unit matching the specified value to be selected.\n\n* When $FILTER is set to {}, the selection of client certificates is not additionally restricted. Note that filters provided by the web server still apply.\n\nIf you leave the policy unset, there's no autoselection for any site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoselectcertificateforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_backgroundtemplatelistupdatesenabled","displayName":"Enables background updates to the list of available templates for Collections and other features that use templates","description":"Lets you enable or disable background updates to the list of available templates for Collections and other features that use templates. Templates are used to extract rich metadata from a webpage when the page is saved to a collection.\n\nIf you enable this setting or the setting is unconfigured, the list of available templates will be downloaded in the background from a Microsoft service every 24 hours.\n\nIf you disable this setting the list of available templates will be downloaded on demand. This type of download might result in small performance penalties for Collections and other features.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#backgroundtemplatelistupdatesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_backgroundtemplatelistupdatesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_backgroundtemplatelistupdatesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_basicauthoverhttpenabled","displayName":"Allow Basic authentication for HTTP","description":"If you enable this policy or leave it unset, Basic authentication challenges received over non-secure HTTP will be allowed.\n\nIf you disable this policy, non-secure HTTP requests from the Basic authentication scheme are blocked, and only secure HTTPS is allowed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#basicauthoverhttpenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_basicauthoverhttpenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_basicauthoverhttpenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_behaviormonitoring","displayName":"Behavior Monitoring","description":"Behavior Monitoring detections with Microsoft Defender for Endpoint.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/behavior-monitor-macos"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_behaviormonitoring_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_behaviormonitoring_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_bingadssuppression","displayName":"Block all ads on Bing search results","description":"Enables an ad-free search experience on Bing.com\n\nIf you enable this policy, then a user can search on bing.com and have an ad-free search experience. At the same time, the SafeSearch setting will be set to 'Strict' and can't be changed by the user.\n\nIf you don't configure this policy, then the default experience will have ads in the search results on bing.com. SafeSearch will be set to 'Moderate' by default and can be changed by the user.\n\nThis policy is only available for K-12 SKUs that are identified as EDU tenants by Microsoft.\n\nPlease refer to https://go.microsoft.com/fwlink/?linkid=2119711 to learn more about this policy or if the following scenarios apply to you:\n\n* You have an EDU tenant, but the policy doesn't work.\n\n* You had your IP whitelisted for having an ad free search experience.\n\n* You were experiencing an ad-free search experience on Microsoft Edge Legacy and want to upgrade to the new version of Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#bingadssuppression"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_bingadssuppression_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_bingadssuppression_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_blockexternalextensions","displayName":"Blocks external extensions from being installed","description":"Control the installation of external extensions.\n\nIf you enable this setting, external extensions are blocked from being installed.\n\nIf you disable this setting or leave it unset, external extensions are allowed to be installed.\n\nExternal extensions and their installation are documented at https://docs.microsoft.com/microsoft-edge/extensions-chromium/developer-guide/alternate-distribution-options.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#blockexternalextensions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_blockexternalextensions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blockexternalextensions_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_blockexternalsync","displayName":"Block external sync","description":"Prevents the sync app from syncing libraries and folders shared from other organizations.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#blockexternalsync"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_blockexternalsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blockexternalsync_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_blockthirdpartycookies","displayName":"Block third party cookies","description":"This policy controls whether third-party cookies are blocked in regular browsing sessions.\n\nIf you enable this policy, web page elements that are not from the domain shown in the address bar can't set cookies.\n\nIf you disable this policy, third-party cookies are allowed, including from domains other than the one shown in the address bar.\n\nIf you don't configure this policy, third-party cookies are allowed by default, but users can change this setting.\n\nNote: This policy doesn't apply in InPrivate mode. In InPrivate, third-party cookies are blocked by default and can only be allowed at the site level using the CookiesAllowedForUrls policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#blockthirdpartycookies"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_blockthirdpartycookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blockthirdpartycookies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_blocktruncatedcookies","displayName":"Block truncated cookies (Deprecated)","description":"This policy provides a temporary opt-out for changes to how Microsoft Edge handles cookies set via JavaScript that contain certain control characters (NULL, carriage return, and line feed).\nPreviously, the presence of any of these characters in a cookie string would cause it to be truncated but still set.\nNow, the presence of these characters will cause the whole cookie string to be ignored.\n\nIf you enable or don't configure this policy, the new behavior is enabled.\n\nIf you disable this policy, the old behavior is enabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#blocktruncatedcookies"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_blocktruncatedcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blocktruncatedcookies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_browseraddprofileenabled","displayName":"Enable profile creation from the Identity flyout menu or the Settings page","description":"Allows users to create new profiles, using the **Add profile** option.\nIf you enable this policy or don't configure it, Microsoft Edge allows users to use **Add profile** on the Identity flyout menu or the Settings page to create new profiles.\n\nIf you disable this policy, users cannot add new profiles from the Identity flyout menu or the Settings page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#browseraddprofileenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_browseraddprofileenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_browseraddprofileenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_browserguestmodeenabled","displayName":"Enable guest mode","description":"Enable the option to allow the use of guest profiles in Microsoft Edge. In a guest profile, the browser doesn't import browsing data from existing profiles, and it deletes browsing data when all guest profiles are closed.\n\nIf you enable this policy or don't configure it, Microsoft Edge lets users browse in guest profiles.\n\nIf you disable this policy, Microsoft Edge doesn't let users browse in guest profiles.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#browserguestmodeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_browserguestmodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_browserguestmodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_browsernetworktimequeriesenabled","displayName":"Allow queries to a Browser Network Time service","description":"Prevents Microsoft Edge from occasionally sending queries to a browser network time service to retrieve an accurate timestamp.\n\nIf you disable this policy, Microsoft Edge will stop sending queries to a browser network time service.\n\nIf you enable this policy or don't configure it, Microsoft Edge will occasionally send queries to a browser network time service.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#browsernetworktimequeriesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_browsernetworktimequeriesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_browsernetworktimequeriesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_browsersignin","displayName":"Browser sign-in settings","description":"Specify whether a user can sign into Microsoft Edge with their account and use account-related services like sync and single sign on. To control the availability of sync, use the \"SyncDisabled\" policy instead.\n\nIf you set this policy to 'Disable browser sign-in', make sure that you also set the \"NonRemovableProfileEnabled\" policy to disabled because \"NonRemovableProfileEnabled\" disables the creation of an automatically signed in browser profile. If both policies are set, Microsoft Edge will use the 'Disable browser sign-in' policy and behave as if \"NonRemovableProfileEnabled\" is set to disabled.\n\nIf you set this policy to 'Enable browser sign-in' (1), users can sign into the browser. Signing into the browser doesn't mean that sync is turned on by default; the user must separately opt-in to use this feature.\n\nIf you set this policy to 'Force browser sign-in' (2) users must sign into a profile to use the browser. By default, this will allow the user to choose whether they want to sync to their account, unless sync is disabled by the domain admin or with the \"SyncDisabled\" policy. The default value of \"BrowserGuestModeEnabled\" policy is set to false.\n\nIf you don't configure this policy users can decide if they want to enable the browser sign-in option and use it as they see fit.\n\n* 0 = Disable browser sign-in\n\n* 1 = Enable browser sign-in\n\n* 2 = Force users to sign-in to use the browser","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#browsersignin"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_browsersignin_0","displayName":"Disable browser sign-in","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_browsersignin_1","displayName":"Enable browser sign-in","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_browsersignin_2","displayName":"Force users to sign-in to use the browser","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_builtinaiapisenabled","displayName":"Allow pages to use the built-in AI APIs.","description":"Use this policy to control whether websites can access the built-in AI APIs, including the LanguageModel API, Summarization API, Writer API, and Rewriter API.\n\nEnable this policy to allow pages to use the APIs. If you don’t configure this policy, the APIs are still allowed.\n\nDisable this policy to block access to the APIs. The APIs will return an error when used.\n\nFor more information, see https://github.com/webmachinelearning/writing-assistance-apis/blob/main/README.md.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#builtinaiapisenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_builtinaiapisenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_builtinaiapisenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_builtincertificateverifierenabled","displayName":"Determines whether the built-in certificate verifier will be used to verify server certificates","description":"This policy is deprecated because it's intended to serve only as a short-term mechanism to give enterprises more time to update their environments and report issues if they are found to be incompatible with the built-in certificate verifier.\n\nThis policy is scheduled to be removed in Microsoft Edge for Mac OS X version 87, when support for the legacy certificate verifier on Mac OS X is planned to be removed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#builtincertificateverifierenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_builtincertificateverifierenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_builtincertificateverifierenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_builtindnsclientenabled","displayName":"Use built-in DNS client","description":"Controls whether to use the built-in DNS client.\n\nThis does not affect which DNS servers are used; just the software stack which is used to communicate with them. For example if the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It is however possible that the built-in DNS client will address servers in different ways by using more modern DNS-related protocols such as DNS-over-TLS.\n\nIf you enable this policy, the built-in DNS client is used, if it's available.\n\nIf you disable this policy, the client is never used.\n\nIf you don't configure this policy, the built-in DNS client is enabled by default on MacOS, and users can change whether to use the built-in DNS client by editing edge://flags or by specifying a command-line flag.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#builtindnsclientenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_builtindnsclientenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_builtindnsclientenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates.","description":"This policy determines the level of access users have when managing CA certificates in Microsoft Edge.\n\nSetting the policy to UserOnly (1) allows users to manage only user-imported certificates. Trust settings for built-in certificates cannot be changed.\n\nSetting the policy to None (2) lets users view certificates but not manage them.\n\nNote: The certificate management experience is available starting in Microsoft Edge version 136.\n\nPolicy options mapping:\n\n* All (0) = Allow users to manage all certificates\n\n* UserOnly (1) = Allow users to manage user certificates\n\n* None (2) = Disallow users from managing certificates\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cacertificatemanagementallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_cacertificatemanagementallowed_0","displayName":"Allow users to manage all certificates","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_cacertificatemanagementallowed_1","displayName":"Allow users to manage user certificates","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_cacertificatemanagementallowed_2","displayName":"Disallow users from managing certificates","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_cacertificates","displayName":"TLS server certificates that should be trusted by Microsoft Edge","description":"This policy enables a list of TLS certificates that should be trusted by Microsoft Edge for server authentication.\nCertificates should be base64-encoded.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cacertificates"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_cadistrustedcertificates","displayName":"TLS certificates that should be distrusted by Microsoft Edge for server authentication","description":"This policy enables defining a list of certificate public keys that should be distrusted by Microsoft Edge for TLS server\nauthentication.\n\nThe policy value is a list of base64-encoded X.509 certificates. Any\ncertificate with a matching SPKI (SubjectPublicKeyInfo) will be distrusted.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cadistrustedcertificates"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication","description":"This policy defines certificates that are not explicitly trusted or distrusted by Microsoft Edge but may be used as hints during certificate path-building.\n\nThe specified certificates will be considered as intermediates during path validation; the server's certificate must still chain to a trusted root to be considered valid.\n\nCertificates must be base64-encoded.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cahintcertificates"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek","displayName":"Specify first day of the week","description":"Set the first day of week in calendar view.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#specify-calendar-first-day-of-week"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_0","displayName":"Sunday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_1","displayName":"Monday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_4","displayName":"Thursday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_5","displayName":"Friday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_6","displayName":"Saturday","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_caplatformintegrationenabled","displayName":"Use user-added TLS certificates from platform trust stores for server authentication","description":"If enabled (or unset), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.\n\nIf disabled, user-added TLS certificates from platform trust stores will not be used in path-building for TLS server authentication.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#caplatformintegrationenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_caplatformintegrationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_caplatformintegrationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_certificatetransparencyenforcementdisabledforcas","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes","description":"Disables enforcement of Certificate Transparency requirements for a list of subjectPublicKeyInfo hashes.\n\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This allows certificates that would otherwise be untrusted because they were not properly publicly disclosed to still be used for Enterprise hosts.\n\nTo disable Certificate Transparency enforcement when this policy is set, one of the following sets of conditions must be met:\n1. The hash is of the server certificate's subjectPublicKeyInfo.\n2. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, that CA certificate is constrained via the X.509v3 nameConstraints extension, one or more directoryName nameConstraints are present in the permittedSubtrees, and the directoryName contains an organizationName attribute.\n3. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, the CA certificate has one or more organizationName attributes in the certificate Subject, and the server's certificate contains the same number of organizationName attributes, in the same order, and with byte-for-byte identical values.\n\nA subjectPublicKeyInfo hash is specified by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\n\nIf you disable this policy or don't configure it, any certificate that's required to be disclosed via Certificate Transparency will be treated as untrusted if it's not disclosed according to the Certificate Transparency policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#certificatetransparencyenforcementdisabledforcas"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_certificatetransparencyenforcementdisabledforlegacycas","displayName":"Disable Certificate Transparency enforcement for a list of legacy certificate authorities (Deprecated)","description":"Disables enforcing Certificate Transparency requirements for a list of legacy certificate authorities (Cas).\n\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This allows certificates that would otherwise be untrusted because they were not properly publicly disclosed, continue to be used for enterprise hosts.\n\nIn order for Certificate Transparency enforcement to be disabled, you must set the hash to a subjectPublicKeyInfo appearing in a CA certificate that is recognized as a legacy certificate authority (CA). A legacy CA is a CA that has been publicly trusted by default by one or more operating systems supported by Microsoft Edge.\n\nYou specify a subjectPublicKeyInfo hash by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\n\nIf you don't configure this policy, any certificate that's required to be disclosed via Certificate Transparency will be treated as untrusted if it isn't disclosed according to the Certificate Transparency policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#certificatetransparencyenforcementdisabledforlegacycas"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_certificatetransparencyenforcementdisabledforurls","displayName":"Disable Certificate Transparency enforcement for specific URLs","description":"Disables enforcing Certificate Transparency requirements for the listed URLs.\n\nThis policy lets you not disclose certificates for the hostnames in the specified URLs via Certificate Transparency. This lets you use certificates that would otherwise be untrusted, because they weren't properly publicly disclosed, but it makes it harder to detect mis-issued certificates for those hosts.\n\nForm your URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322. Because certificates are valid for a given hostname, independent of the scheme, port, or path, only the hostname part of the URL is considered. Wildcard hosts are not supported.\n\nIf you don't configure this policy, any certificate that should be disclosed via Certificate Transparency is treated as untrusted if it's not disclosed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#certificatetransparencyenforcementdisabledforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_channelname","displayName":"Update channel","description":"Specifies the channel to receive updates. The most stable channel is the Current Channel, which is recommended for the majority of your fleet. Users subscribed to the Preview Channel will receive production-quality updates a week before Current Channel users. Users subscribed to the Beta Channel will receive unsupported nightly builds that are designed for testing.","helpText":null,"infoUrls":["https://support.microsoft.com/office/update-office-for-mac-automatically-bfd1e497-c24d-4754-92ab-910a4074d7c1"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_2","displayName":"Current Channel (Deferred)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_3","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_4","displayName":"Current Channel (Monthly)","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_checkfordefinitionsupdate","displayName":"Check for definitions update","description":"Check for definitions update before initiating a scheduled scan","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":[{"id":"com.apple.managedclient.preferences_checkfordefinitionsupdate_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_checkfordefinitionsupdate_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_clearbrowsingdataonexit","displayName":"Clear browsing data when Microsoft Edge closes","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\n\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured \"DefaultCookiesSetting\"\n\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\n\nIf you enable this policy, don't enable the \"AllowDeletingBrowserHistory\" policy, because they both deal with deleting data. If you enable both, this policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"AllowDeletingBrowserHistory\".","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#clearbrowsingdataonexit"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_clearbrowsingdataonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_clearbrowsingdataonexit_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_clearcachedimagesandfilesonexit","displayName":"Clear cached images and files when Microsoft Edge closes","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\n\nIf you enable this policy, cached images and files will be deleted each time Microsoft Edge closes.\n\nIf you disable this policy, users cannot configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\n\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\n\nIf you disable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you configure both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"ClearCachedImagesAndFilesOnExit\".","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#clearcachedimagesandfilesonexit"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_clearcachedimagesandfilesonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_clearcachedimagesandfilesonexit_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_clipboardallowedforurls","displayName":"Allow clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\n\nSetting the policy lets you create a list of URL patterns that specify which sites can use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\n\nLeaving the policy unset means \"DefaultClipboardSetting\" applies for all sites if it's set. If it isn't set, the user's personal setting applies.\n\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#clipboardallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_clipboardblockedforurls","displayName":"Block clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\n\nSetting the policy lets you create a list of URL patterns that specify sites that can't use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\n\nLeaving the policy unset means \"DefaultClipboardSetting\" applies for all sites if it's set. If it isn't set, the user's personal setting applies.\n\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#clipboardblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_cloudblocklevel","displayName":"Cloud Block Level","description":"Determines how aggressive Defender for Endpoint will be in blocking and scanning suspicious files.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#configure-cloud-block-level"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"com.apple.managedclient.preferences_cloudblocklevel_0","displayName":"normal","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_cloudblocklevel_1","displayName":"moderate","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_cloudblocklevel_2","displayName":"high","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_cloudblocklevel_3","displayName":"high_plus","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_cloudblocklevel_4","displayName":"zero_tolerance","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_collectionsservicesandexportsblocklist","displayName":"Block access to a specified list of services and export targets in Collections","description":"List specific services and export targets that users can't access in the Collections feature in Microsoft Edge. This includes displaying additional data from Bing and exporting collections to Microsoft products or external partners.\n\nIf you enable this policy, services and export targets that match the given list are blocked.\n\nIf you don't configure this policy, no restrictions on the acceptable services and export targets are enforced.\n\nPolicy options mapping:\n\n* pinterest_suggestions (pinterest_suggestions) = Pinterest suggestions\n\n* collections_share (collections_share) = Sharing of Collections\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#collectionsservicesandexportsblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_commandlineflagsecuritywarningsenabled","displayName":"Enable security warnings for command-line flags","description":"If disabled, this policy prevents security warnings from appearing when Microsoft Edge is launched with potentially dangerous command-line flags.\n\nIf enabled or unset, security warnings are displayed when these command-line flags are used to launch Microsoft Edge.\n\nFor example, the --disable-gpu-sandbox flag generates this warning: You're using an unsupported command-line flag: --disable-gpu-sandbox. This poses stability and security risks.\n\nOn Windows, this policy is only available on instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro (or Enterprise) instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#commandlineflagsecuritywarningsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_commandlineflagsecuritywarningsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_commandlineflagsecuritywarningsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_componentupdatesenabled","displayName":"Enable component updates in Microsoft Edge","description":"If you enable or don't configure this policy, component updates are enabled in Microsoft Edge.\n\nIf you disable this policy or set it to false, component updates are disabled for all components in Microsoft Edge.\n\nHowever, some components are exempt from this policy. This includes any component that doesn't contain executable code, that doesn't significantly alter the behavior of the browser, or that's critical for security. That is, updates that are deemed \"critical for security\" are still applied even if you disable this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#componentupdatesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_componentupdatesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_componentupdatesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_composeinlineenabled","displayName":"Control access to Microsoft 365 Copilot writing assistance in Microsoft Edge for Business","description":"This policy controls whether users can use writing support features in Microsoft Edge for Business, such as Rewrite, which utilizes Microsoft 365 Copilot Chat. With Rewrite, users can receive help with drafting content, rewriting text, and adjusting style directly in their browser tab. In Edge, users can trigger it when highlighting editable content in their main browser through the right-click context menu.\n\nThis policy applies only to Microsoft Entra accounts and does not apply to Microsoft accounts.\n\nIf you enable this policy, users can use Rewrite in Microsoft Edge when logged in with an Entra account.\n\nIf you disable this policy, users within your tenant will not be able to use Rewrite.\n\nIf you don't configure this policy, the default behavior is as follows:\n\n- Rewrite is available to users\n\n- Users can enable or disable Microsoft 365 Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings.\n\nNote: Rewrite is not available on pages protected by data loss prevention (DLP) policies to help maintain compliance.\n\nLearn more about Microsoft 365 Copilot Chat data, privacy, and security here: https://go.microsoft.com/fwlink/?linkid=2321816","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#composeinlineenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_composeinlineenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_composeinlineenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_compressiondictionarytransportenabled","displayName":"Enable compression dictionary transport support","description":"This feature enables the use of dictionary-specific content encodings in the Accept-Encoding request header (\"sbr\" and \"zst-d\") when dictionaries are available for use.\n\nIf you enable this policy or don't configure it, Microsoft Edge will accept web contents using the compression dictionary transport feature.\n\nIf you disable this policy, Microsoft Edge will turn off the compression dictionary transport feature.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#compressiondictionarytransportenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_compressiondictionarytransportenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_compressiondictionarytransportenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_configuredonottrack","displayName":"Configure Do Not Track","description":"Specify whether to send Do Not Track requests to websites that ask for tracking info. Do Not Track requests let the websites you visit know that you don't want your browsing activity to be tracked. By default, Microsoft Edge doesn't send Do Not Track requests, but users can turn on this feature to send them.\n\nIf you enable this policy, Do Not Track requests are always sent to websites asking for tracking info.\n\nIf you disable this policy, requests are never sent.\n\nIf you don't configure this policy, users can choose whether to send these requests.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#configuredonottrack"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_configuredonottrack_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configuredonottrack_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users","description":"If FriendlyURLs are enabled, Microsoft Edge will compute additional representations of the URL and place them on the clipboard.\n\nThis policy configures what format will be pasted when the user pastes in external applications, or inside Microsoft Edge without the 'Paste as' context menu item.\n\nIf configured, this policy makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu will not be available.\n\n* Not configured = The user will be able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\n\n* 1 = No additional formats will be stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature will be disabled.\n\n* 3 = The user will get a friendly URL whenever they paste into surfaces that accept rich text. The plain URL will still be available for non-rich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\n\n* 4 = (Not currently used)\n\nThe richer formats may not be well-supported in some paste destinations and/or websites. As such, if this policy is to be configured, then the plain URL option is recommended.\n\nPolicy options mapping:\n\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\n\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.\n\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#configurefriendlyurlformat"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat_0","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat_1","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat_2","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_configureonlinetexttospeech","displayName":"Configure Online Text To Speech","description":"Set whether the browser can leverage Online Text to Speech voice fonts, part of Azure Cognitive Services. These voice fonts are higher quality than the pre-installed system voice fonts.\n\nIf you enable or don't configure this policy, web-based applications that use the SpeechSynthesis API can use Online Text to Speech voice fonts.\n\nIf you disable this policy, the voice fonts aren't available.\n\nRead more about this feature here:\nSpeechSynthesis API: https://go.microsoft.com/fwlink/?linkid=2110038\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2110141","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#configureonlinetexttospeech"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_configureonlinetexttospeech_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configureonlinetexttospeech_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_configureshare","displayName":"Configure the Share experience","description":"If you set this policy to 'ShareAllowed' (the default), users will be able to access the Share experience from the Settings and More Menu in Microsoft Edge to share with other apps on the system.\n\nIf you set this policy to 'ShareDisallowed', users won't be able to access the Share experience. If the Share button is on the toolbar, it will also be hidden.\n\nPolicy options mapping:\n\n* ShareAllowed (0) = Allow using the Share experience\n\n* ShareDisallowed (1) = Don't allow using the Share experience\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#configureshare"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_configureshare_0","displayName":"Allow using the Share experience","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configureshare_1","displayName":"Don't allow using the Share experience","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_consumerexperience","displayName":"Control sign-in to consumer version","description":"Specify whether users can sign into the consumer version of Microsoft Defender","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#control-sign-in-to-consumer-version-of-microsoft-defender"],"categoryId":"67cd904c-78e0-4e77-9dd4-c713b21763f3","categoryName":"User interface preferences","options":[{"id":"com.apple.managedclient.preferences_consumerexperience_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_consumerexperience_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_controldefaultstateofallowextensionfromotherstoressettingenabled","displayName":"Configure default state of Allow extensions from other stores setting","description":"This policy allows you to control the default state of the Allow extensions from other stores setting.\nThis policy can't be used to stop installation of extensions from other stores such as Chrome Web Store.\nTo stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098.\n\nWhen enabled, Allow extensions from other stores will be turned on. So, users won't have to turn on the flag manually\nwhile installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting.\nIf the user has already turned on the setting and then turned it off, this setting may not work.\nIf the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it will have no impact on\nuser settings and the setting will remain as it is.\n\nWhen disabled or not configured, the user can manage the Allow extensions from other store setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#controldefaultstateofallowextensionfromotherstoressettingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_controldefaultstateofallowextensionfromotherstoressettingenabled_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_controldefaultstateofallowextensionfromotherstoressettingenabled_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_cookiesallowedforurls","displayName":"Allow cookies on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to set cookies.\n\nIf you don't configure this policy, the global default value from the \"DefaultCookiesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nSee the \"CookiesBlockedForUrls\" and \"CookiesSessionOnlyForUrls\" policies for more information.\n\nNote there cannot be conflicting URL patterns set between these three policies:\n\n- \"CookiesBlockedForUrls\"\n\n- CookiesAllowedForUrls\n\n- \"CookiesSessionOnlyForUrls\"","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cookiesallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_cookiesblockedforurls","displayName":"Block cookies on specific sites","description":"Define a list of sites, based on URL patterns, that can't set cookies.\n\nIf you don't configure this policy, the global default value from the \"DefaultCookiesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nSee the \"CookiesAllowedForUrls\" and \"CookiesSessionOnlyForUrls\" policies for more information.\n\nNote there cannot be conflicting URL patterns set between these three policies:\n\n- CookiesBlockedForUrls\n\n- \"CookiesAllowedForUrls\"\n\n- \"CookiesSessionOnlyForUrls\"","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cookiesblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_cookiessessiononlyforurls","displayName":"Limit cookies from specific websites to the current session","description":"Cookies created by websites that match a URL pattern you define are deleted when the session ends (when the window closes).\n\nCookies created by websites that don't match the pattern are controlled by the \"DefaultCookiesSetting\" policy (if set) or by the user's personal configuration. This is also the default behavior if you don't configure this policy.\n\nIf Microsoft Edge is running in background mode, the session might not close when the last window is closed, meaning the cookies won't be cleared when the window closes. See the \"BackgroundModeEnabled\" policy for information about configuring what happens when Microsoft Edge runs in background mode.\n\nYou can also use the \"CookiesAllowedForUrls\" and \"CookiesBlockedForUrls\" policies to control which websites can create cookies.\n\nNote there cannot be conflicting URL patterns set between these three policies:\n\n- \"CookiesBlockedForUrls\"\n\n- \"CookiesAllowedForUrls\"\n\n- CookiesSessionOnlyForUrls\n\nIf you set the \"RestoreOnStartup\" policy to restore URLs from previous sessions, this policy is ignored, and cookies are stored permanently for those sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#cookiessessiononlyforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_copilotpagecontext","displayName":"Control Copilot access to page context for Microsoft Entra ID profiles","description":"This policy controls access to page contents for Copilot in the Microsoft Edge sidebar when users are logged into their MSA Copilot account. This policy applies only to Microsoft Entra ID Microsoft Edge profiles. To summarize pages and interact with text selections, it needs to be able to access the page contents. This policy does not apply to MSA Microsoft Edge profiles. This policy doesn't control access for Copilot with enterprise data protection (EDP). Access for Copilot with enterprise data protection (EDP) is controlled by the \"EdgeEntraCopilotPageContext\" policy.\n\nIf you enable this policy, Copilot will have access to page content when logged in with Entra ID.\n\nIf this policy is not configured, the default behavior for non-EU countries is that access is initially enabled. For EU countries, the default behavior is that access is initially disabled. In both cases, if the policy is not configured, users can enable or disable Copilot's access to page content using the setting toggle in Microsoft Edge.\n\nIf you disable this policy, Copilot will not be able to access page context.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#copilotpagecontext"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_copilotpagecontext_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_copilotpagecontext_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request header support enabled","description":"This policy lets you configure support of CORS non-wildcard request headers.\n\nMicrosoft Edge version 97 introduces support for CORS non-wildcard request headers. When a script makes a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header must be explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. See https://go.microsoft.com/fwlink/?linkid=2180022 for more detail.\n\nIf you enable or don't configure the policy, Microsoft Edge will support the CORS non-wildcard request headers and behave as previously described.\n\nIf you disable this policy, Microsoft Edge will allow the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\n\nThis policy is a temporary workaround for the new CORS non-wildcard request header feature. It's intended to be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#corsnonwildcardrequestheaderssupport"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_corsnonwildcardrequestheaderssupport_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_corsnonwildcardrequestheaderssupport_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_createpasskeysinicloudkeychain","displayName":"Control whether passkey creation will default to iCloud Keychain.","description":"Microsoft Edge may direct\npasskey/WebAuthn creation requests directly to iCloud Keychain on macOS 13.5\nor later. If iCloud Keychain syncing is not enabled yet, this will\nprompt the user to sign in with iCloud, or might prompt them to enable iCloud\nKeychain syncing.\n\nIf this policy is set to \"true\" then iCloud Keychain will be the default\nwhenever the WebAuthn request is compatible with that choice.\n\nIf this policy isn't set then the default behavior depends on factors such as\nwhether iCloud Drive is enabled, or whether the user has recently used or\ncreated a credential in their\nMicrosoft Edge profile.\n\nIf this policy is set to false, iCloud Keychain will not be used by default\nand the previous behavior (of creating the credential in the Microsoft Edge profile) may be used\ninstead. Users will still be able to select iCloud Keychain as an option, and\nmay still see iCloud Keychain credentials when signing in.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#createpasskeysinicloudkeychain"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_createpasskeysinicloudkeychain_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_createpasskeysinicloudkeychain_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_csscustomstatedeprecatedsyntaxenabled","displayName":"Controls whether the deprecated :--foo syntax for CSS custom state is enabled (Deprecated)","description":"The :--foo syntax for the CSS custom state feature is being changed to :state(foo) in Microsoft Edge in order to comply with changes that have been made in Firefox and Safari. This policy lets the deprecated syntax to be used until Stable 133.\n\nThis deprecation might break some Microsoft Edge-only websites that use the deprecated :--foo syntax.\n\nIf you enable this policy, the deprecated syntax will be enabled.\n\nIf you disable this policy or don't set it, the deprecated syntax will be disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#csscustomstatedeprecatedsyntaxenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_csscustomstatedeprecatedsyntaxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_csscustomstatedeprecatedsyntaxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_customhelplink","displayName":"Specify custom help link","description":"Specify a link for the Help menu or the F1 key.\n\nIf you enable this policy, an admin can specify a link for the Help menu or the F1 key.\n\nIf you disable or don't configure this policy, the default link for the Help menu or the F1 key is used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#customhelplink"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_dailyconfiguration","displayName":"Daily and Hourly quick scan configuration","description":"Check for definitions update before initiating a scheduled scan","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_dailyconfiguration_interval","displayName":"Start time","description":"Specify how many hours should elapse before the next hourly quick scan. 0 indicates no hourly quick scan. 1 indicates a scan every hour. 24 indicates a scan once a day.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_dailyconfiguration_timeofday","displayName":"Time of day","description":"Specifies the time of day, as the number of minutes after midnight, to perform a daily quick scan.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_datalossprevention","displayName":"Use Data Loss Prevention","description":"Whether data loss prevention enforcement is enabled on the machine.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/compliance/data-loss-prevention-policies?view=o365-worldwide"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_datalossprevention_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_datalossprevention_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_dataurlinsvguseenabled","displayName":"Data URL support for SVGUseElement","description":"This policy enables Data URL support for SVGUseElement, which will be disabled\nby default starting in Edge stable version 119.\nIf this policy is Enabled, Data URLs will keep working in SVGUseElement.\nIf this policy is Disabled or left not set, Data URLs won't work in SVGUseElement.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#dataurlinsvguseenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_dataurlinsvguseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dataurlinsvguseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_dataurlwhitespacepreservationenabled","displayName":"DataURL Whitespace Preservation for all media types","description":"This policy provides a temporary opt-out for changes to how Edge handles whitepsace in data URLS.\nPreviously, whitespace would be kept only if the top level media type was text or contained the media type string xml.\nNow, whitespace will be preserved in all data URLs, regardless of media type.\n\nIf this policy is left unset or is set to True, the new behavior is enabled.\n\nWhen this policy is set to False, the old behavior is enabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#dataurlwhitespacepreservationenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_dataurlwhitespacepreservationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dataurlwhitespacepreservationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultautomaticdownloadssetting","displayName":"Default automatic downloads setting","description":"Administrators can use this policy to control whether websites can perform multiple downloads successively. Individual site behavior can be managed using the AutomaticDownloadsAllowedForUrls and AutomaticDownloadsBlockedForUrls policies.\n\nDefault behavior:\n\n- A user gesture is required for each additional download.\n\n- Users can modify their browser settings to disable successive downloads.\n\nPolicy options mapping:\n\n* AllowAutomaticDownloads (1) = Allow all websites to perform multiple downloads without requiring a user gesture between each download.\n\n* BlockAutomaticDownloads (2) = Prevent all websites from performing multiple downloads, even after a user gesture.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultautomaticdownloadssetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultautomaticdownloadssetting_0","displayName":"Allow all websites to perform multiple downloads without requiring a user gesture between each download.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultautomaticdownloadssetting_1","displayName":"Prevent all websites from performing multiple downloads, even after a user gesture.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultbrowsersettingenabled","displayName":"Set Microsoft Edge as default browser","description":"Configures the default browser checks in Microsoft Edge and prevents users from changing them.\n\nIf you enable this policy, Microsoft Edge always checks on startup whether it is the default browser and automatically registers itself, if possible.\n\nIf you disable this policy, Microsoft Edge never checks and disables user controls for setting this option.\n\nIf you don't configure this policy, Microsoft Edge lets the user control whether it's the default browser and whether to show user notifications when it isn't.\n\nNote for Windows administrators: This policy only works for PCs running Windows 7. For later versions of Windows, you have to deploy a \"default application associations\" file that makes Microsoft Edge the handler for the https and http protocols (and, optionally, the ftp protocol and file formats such as .html, .htm, .pdf, .svg, .webp). See https://go.microsoft.com/fwlink/?linkid=2094932 for more information.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultbrowsersettingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultbrowsersettingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultbrowsersettingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultclipboardsetting","displayName":"Default clipboard site permission","description":"This policy controls the default value for the clipboard site permission.\n\nSetting the policy to 2 blocks sites from using the clipboard site permission.\n\nSetting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use an API.\n\nThis policy can be overridden for specific URL patterns using the \"ClipboardAllowedForUrls\" and \"ClipboardBlockedForUrls\" policies.\n\nThis policy only affects clipboard operations controlled by the clipboard site permission and doesn't affect sanitized clipboard writes or trusted copy and paste operations.\n\nPolicy options mapping:\n\n* BlockClipboard (2) = Do not allow any site to use the clipboard site permission\n\n* AskClipboard (3) = Allow sites to ask the user to grant the clipboard site permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultclipboardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultclipboardsetting_0","displayName":"Do not allow any site to use the clipboard site permission","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultclipboardsetting_1","displayName":"Allow sites to ask the user to grant the clipboard site permission","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultcookiessetting","displayName":"Configure cookies","description":"Control whether websites can create cookies on the user's device. This policy is all or nothing - you can let all websites create cookies, or no websites create cookies. You can't use this policy to enable cookies from specific websites.\n\nSet the policy to 'SessionOnly' (4) to clear cookies when the session closes. If Microsoft Edge is running in background mode, the session might not close when the last window is closed, meaning the cookies won't be cleared when the window closes. See \"BackgroundModeEnabled\" policy for information about configuring what happens when Microsoft Edge runs in background mode.\n\nIf you don't configure this policy, the default 'AllowCookies' (1) is used, and users can change this setting in Microsoft Edge Settings. (If you don't want users to be able to change this setting, set the policy.)\n\n* 1 = Let all sites create cookies\n\n* 2 = Don't let any site create cookies\n\n* 4 = Keep cookies for the duration of the session","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultcookiessetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultcookiessetting_0","displayName":"Let all sites create cookies","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultcookiessetting_1","displayName":"Don't let any site create cookies","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultcookiessetting_2","displayName":"Keep cookies for the duration of the session","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultemailaddressordomain","displayName":"Default domain name","description":"Specify the domain or full email address of the Microsoft 365 mailbox to be added on first launch (e.g. contoso.com or fred@contoso.com).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#specify-microsoft-365-mailbox-to-be-added-on-first-launch"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":null},{"id":"com.apple.managedclient.preferences_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading","description":"If you set this policy to 3, websites can ask for read access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\n\nIf you don't set this policy, websites can ask for access. Users can change this setting.\n\nPolicy options mapping:\n\n* BlockFileSystemRead (2) = Don't allow any site to request read access to files and directories via the File System API\n\n* AskFileSystemRead (3) = Allow sites to ask the user to grant read access to files and directories via the File System API\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultfilesystemreadguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultfilesystemreadguardsetting_0","displayName":"Don't allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultfilesystemreadguardsetting_1","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing","description":"If you set this policy to 3, websites can ask for write access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\n\nIf you don't set this policy, websites can ask for access. Users can change this setting.\n\nPolicy options mapping:\n\n* BlockFileSystemWrite (2) = Don't allow any site to request write access to files and directories\n\n* AskFileSystemWrite (3) = Allow sites to ask the user to grant write access to files and directories\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultfilesystemwriteguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultfilesystemwriteguardsetting_0","displayName":"Don't allow any site to request write access to files and directories","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultfilesystemwriteguardsetting_1","displayName":"Allow sites to ask the user to grant write access to files and directories","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultgeolocationsetting","displayName":"Default geolocation setting","description":"Set whether websites can track users' physical locations. You can allow tracking by default (1), deny it by default (2), or ask the user each time a website requests their location (3).\n\nIf you don't configure this policy, 'AskGeolocation' policy is used and the user can change it.\n\n* 1 = Allow sites to track users' physical location\n\n* 2 = Don't allow any site to track users' physical location\n\n* 3 = Ask whenever a site wants to track users' physical location","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultgeolocationsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultgeolocationsetting_0","displayName":"Allow sites to track users' physical location","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultgeolocationsetting_1","displayName":"Don't allow any site to track users' physical location","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultgeolocationsetting_2","displayName":"Ask whenever a site wants to track users' physical location","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultimagessetting","displayName":"Default images setting","description":"Set whether websites can display images. You can allow images on all sites (1) or block them on all sites (2).\n\nIf you don't configure this policy, images are allowed by default, and the user can change this setting.\n\n* 1 = Allow all sites to show all images\n\n* 2 = Don't allow any site to show images","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultimagessetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultimagessetting_0","displayName":"Allow all sites to show all images","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultimagessetting_1","displayName":"Don't allow any site to show images","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions","description":"Allows you to set whether users can add exceptions to allow mixed content for specific sites.\n\nThis policy can be overridden for specific URL patterns using the \"InsecureContentAllowedForUrls\" and \"InsecureContentBlockedForUrls\" policies.\n\nIf this policy isn't set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.\n\n* 2 = Do not allow any site to load blockable mixed content\n\n* 3 = Allow users to add exceptions to allow blockable mixed content","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultinsecurecontentsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultinsecurecontentsetting_0","displayName":"Do not allow any site to load mixed content","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultinsecurecontentsetting_1","displayName":"Allow users to add exceptions to allow mixed content","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT","description":"Allows you to set whether Microsoft Edge will run the v8 JavaScript engine with JIT (Just In Time) compiler enabled or not.\n\nDisabling the JavaScript JIT will mean that Microsoft Edge may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Microsoft Edge to render web content in a more secure configuration.\n\nThis policy can be overridden for specific URL patterns using the \"JavaScriptJitAllowedForSites\" and \"JavaScriptJitBlockedForSites\" policies.\n\nIf you don't configure this policy, JavaScript JIT is enabled.\n\nPolicy options mapping:\n\n* AllowJavaScriptJit (1) = Allow any site to run JavaScript JIT\n\n* BlockJavaScriptJit (2) = Do not allow any site to run JavaScript JIT\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultjavascriptjitsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultjavascriptjitsetting_0","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultjavascriptjitsetting_1","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers","description":"Allows you to set whether Microsoft Edge will run the v8 JavaScript engine with more advanced JavaScript optimizations enabled.\n\nDisabling JavaScript optimizations (by setting this policy's value to 2) will mean that Microsoft Edge may render web content more slowly.\n\nThis policy can be overridden for specific URL patterns using the \"JavaScriptOptimizerAllowedForSites\" and \"JavaScriptOptimizerBlockedForSites\" policies.\n\nIf you don't configure this policy, JavaScript optimizations are enabled.\n\nPolicy options mapping:\n\n* AllowJavaScriptOptimizer (1) = Enable advanced JavaScript optimizations on all sites\n\n* BlockJavaScriptOptimizer (2) = Disable advanced JavaScript optimizations on all sites\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultjavascriptoptimizersetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultjavascriptoptimizersetting_0","displayName":"Enable advanced JavaScript optimizations on all sites","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultjavascriptoptimizersetting_1","displayName":"Disable advanced JavaScript optimizations on all sites","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultjavascriptsetting","displayName":"Default JavaScript setting","description":"Set whether websites can run JavaScript. You can allow it for all sites (1) or block it for all sites (2).\n\nIf you don't configure this policy, all sites can run JavaScript by default, and the user can change this setting.\n\n* 1 = Allow all sites to run JavaScript\n\n* 2 = Don't allow any site to run JavaScript","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultjavascriptsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultjavascriptsetting_0","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultjavascriptsetting_1","displayName":"Don't allow any site to run JavaScript","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultnotificationssetting","displayName":"Default notification setting","description":"Set whether websites can display desktop notifications. You can allow them by default (1), deny them by default (2), or have the user be asked each time a website wants to show a notification (3).\n\nIf you don't configure this policy, notifications are allowed by default, and the user can change this setting.\n\n* 1 = Allow sites to show desktop notifications\n\n* 2 = Don't allow any site to show desktop notifications\n\n* 3 = Ask every time a site wants to show desktop notifications","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultnotificationssetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultnotificationssetting_0","displayName":"Allow sites to show desktop notifications","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultnotificationssetting_1","displayName":"Don't allow any site to show desktop notifications","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultnotificationssetting_2","displayName":"Ask every time a site wants to show desktop notifications","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultpluginssetting","displayName":"Default Adobe Flash setting","description":"Determines whether websites that aren't covered by \"PluginsAllowedForUrls\" or \"PluginsBlockedForUrls\" can automatically run the Adobe Flash plug-in. You can select 'BlockPlugins' (2) to block Adobe Flash on all sites, or you can select 'ClickToPlay' (3) to let Adobe Flash run but require the user to click the placeholder to start it. In any case, the \"PluginsAllowedForUrls\" and \"PluginsBlockedForUrls\" policies take precedence over 'DefaultPluginsSetting'.\n\nAutomatic playback is only allowed for domains explicitly listed in the \"PluginsAllowedForUrls\" policy. If you want to enable automatic playback for all sites, consider adding http://* and https://* to this list.\n\nIf you don't configure this policy, the user can change this setting manually.\n\n* 2 = Block the Adobe Flash plug-in\n\n* 3 = Click to play\n\nThe former '1' option set allow-all, but this functionality is now only handled by the \"PluginsAllowedForUrls\" policy. Existing policies using '1' will operate in Click-to-play mode.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultpluginssetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultpluginssetting_0","displayName":"Block the Adobe Flash plugin","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultpluginssetting_1","displayName":"Click to play","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultpopupssetting","displayName":"Default pop-up window setting","description":"Set whether websites can show pop-up windows. You can allow them on all websites (1) or block them on all sites (2).\n\nIf you don't configure this policy, pop-up windows are blocked by default, and users can change this setting.\n\n* 1 = Allow all sites to show pop-ups\n\n* 2 = Don't allow any site to show pop-up windows","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultpopupssetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultpopupssetting_0","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultpopupssetting_1","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultprinterselection","displayName":"Default printer selection rules","description":"Overrides Microsoft Edge default printer selection rules. This policy determines the rules for selecting the default printer in Microsoft Edge, which happens the first time a user tries to print a page.\n\nWhen this policy is set, Microsoft Edge tries to find a printer that matches all of the specified attributes and uses it as default printer. If there are multiple printers that meet the criteria, the first printer that matches is used.\n\nIf you don't configure this policy or no matching printers are found within the timeout, the printer defaults to the built-in PDF printer or no printer, if the PDF printer isn't available.\n\nThe value is parsed as a JSON object, conforming to the following schema: { \"type\": \"object\", \"properties\": { \"idPattern\": { \"description\": \"Regular expression to match printer id.\", \"type\": \"string\" }, \"namePattern\": { \"description\": \"Regular expression to match printer display name.\", \"type\": \"string\" } } }\n\nOmitting a field means all values match; for example, if you don't specify connectivity Print Preview starts discovering all kinds of local printers. Regular expression patterns must follow the JavaScript RegExp syntax and matches are case sensitive.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultprinterselection"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchprovidercontextmenuaccessallowed","displayName":"Allow default search provider context menu search access","description":"Enables the use of a default search provider on the context menu.\n\nIf you set this policy to disabled the search context menu item that relies on your default search provider and sidebar search will not be available.\n\nIf this policy is set to enabled or not set, the context menu item for your default search provider and sidebar search will be available.\n\nThe policy value is only appled when the \"DefaultSearchProviderEnabled\" policy is enabled, and is not applicable otherwise.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidercontextmenuaccessallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultsearchprovidercontextmenuaccessallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultsearchprovidercontextmenuaccessallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultsearchproviderenabled","displayName":"Enable the default search provider","description":"Enables the use of a default search provider.\n\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\n\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured), the user can choose the default provider.\n\nIf you disable this policy, the user can't search from the address bar.\n\nIf you enable or disable this policy, users can't change or override it.\n\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchproviderenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultsearchproviderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultsearchproviderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultsearchproviderencodings","displayName":"Default search provider encodings","description":"Specify the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They are tried in the order provided.\n\nThis policy is optional. If not configured, the default, UTF-8, is used.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchproviderencodings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\n\nThis policy is optional. If you don't configure it, image search isn't available.\n\nSpecify Bing's Image Search URL as:\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\n\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\n\nSee \"DefaultSearchProviderImageURLPostParams\" policy to finish configuring image search.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchproviderimageurl"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it’s replaced with real image thumbnail data. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nSpecify Bing's Image Search URL Post Params as:\n'imageBin={google:imageThumbnailBase64}'.\n\nSpecify Google's Image Search URL Post Params as:\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\n\nIf you don’t set this policy, image search requests are sent using the GET method.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchproviderimageurlpostparams"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchproviderkeyword","displayName":"Default search provider keyword","description":"Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider.\n\nThis policy is optional. If you don't configure it, no keyword activates the search provider.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchproviderkeyword"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchprovidername","displayName":"Default search provider name","description":"Specifies the name of the default search provider.\n\nIf you enable this policy, you set the name of the default search provider.\n\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\n\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidername"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchprovidersearchurl","displayName":"Default search provider search URL","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\n\nSpecify Bing's search URL as:\n\n'{bing:baseURL}search?q={searchTerms}'.\n\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\n\nThis policy is required when you enable the \"DefaultSearchProviderEnabled\" policy; if you don't enable the latter policy, this policy is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidersearchurl"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions","description":"Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user has entered so far.\n\nThis policy is optional. If you don't configure it, users won't see search suggestions; they will see suggestions from their browsing history and favorites.\n\nBing's suggest URL can be specified as:\n\n'{bing:baseURL}qbox?query={searchTerms}'.\n\nGoogle's suggest URL can be specified as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidersuggesturl"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_defaultsensorssetting","displayName":"Default sensors setting","description":"Set whether websites can access and use sensors such as motion and light sensors. You can completely block or allow websites to get access to sensors.\n\nSetting the policy to 1 lets websites access and use sensors. Setting the policy to 2 denies acess to sensors.\n\nYou can override this policy for specific URL patterns by using the \"SensorsAllowedForUrls\" and \"SensorsBlockedForUrls\" policies.\n\nIf you don't configure this policy, websites can access and use sensors, and users can change this setting. This is the global default for \"SensorsAllowedForUrls\" and \"SensorsBlockedForUrls\".\n\nPolicy options mapping:\n\n* AllowSensors (1) = Allow sites to access sensors\n\n* BlockSensors (2) = Do not allow any site to access sensors\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsensorssetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultsensorssetting_0","displayName":"Allow sites to access sensors","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultsensorssetting_1","displayName":"Do not allow any site to access sensors","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultserialguardsetting","displayName":"Control use of the Serial API","description":"Set whether websites can access serial ports. You can completely block access or ask the user each time a website wants to get access to a serial port.\n\nSetting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\n\nYou can override this policy for specific URL patterns by using the \"SerialAskForUrls\" and \"SerialBlockedForUrls\" policies.\n\nIf you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting.\n\nPolicy options mapping:\n\n* BlockSerial (2) = Do not allow any site to request access to serial ports via the Serial API\n\n* AskSerial (3) = Allow sites to ask for user permission to access a serial port\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultserialguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultserialguardsetting_0","displayName":"Do not allow any site to request access to serial ports via the Serial API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultserialguardsetting_1","displayName":"Allow sites to ask for user permission to access a serial port","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting","displayName":"Set the default \"share additional operating system region\" setting","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\n\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting will be shared with the web through the default JavaScript locale. If shared, websites will be able to query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\n\nIf you set this policy to \"Limited\", the OS Regional format will only be shared if its language part matches the Microsoft Edge display language.\n\nIf you set this policy to \"Always\", the OS Regional format will always be shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months can be displayed in one language while the surrounding text is displayed in another language.\n\nIf you set this policy to \"Never\", the OS Regional format will never be shared.\n\nExample 1: In this example the OS Regional format is set to \"en-GB\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Limited\", or \"Always\".\n\nExample 2: In this example the OS Regional format is set to \"es-MX\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Always\" but will not if the policy is set to \"Limited\".\n\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282\n\nPolicy options mapping:\n\n* Limited (0) = Limited\n\n* Always (1) = Always share the OS Regional format\n\n* Never (2) = Never share the OS Regional format\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultshareadditionalosregionsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting_0","displayName":"Limited","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting_1","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting_2","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultstolocalopensave","displayName":"Default to local files for open/save","description":"Prefer the local file system when accessing the Open and Save dialogs.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-office"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_defaultstolocalopensave_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultstolocalopensave_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultthirdpartystoragepartitioningsetting","displayName":"Default setting for third-party storage partitioning (deprecated)","description":"This policy controls whether third-party storage partitioning is allowed by default.\n\nIf this policy is set to 1 - AllowPartitioning, or unset, third-party storage partitioning will be allowed by default. This default may be overridden for specific top-level origins by other means.\n\nIf this policy is set to 2 - BlockPartitioning, third-party storage partitioning will be disabled for all contexts.\n\nUse ThirdPartyStoragePartitioningBlockedForOrigins to disable third-party storage partitioning for specific top-level origins.\n\nThis feature will be removed starting in Microsoft Edge version 145. To ensure compatibility, use the requestStorageAccess method instead. For more information, see https://developer.mozilla.org/en-US/docs/Web/API/Document/requestStorageAccess.\n\nPolicy options mapping:\n\n* AllowPartitioning (1) = Allow third-party storage partitioning by default.\n\n* BlockPartitioning (2) = Disable third-party storage partitioning.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultthirdpartystoragepartitioningsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultthirdpartystoragepartitioningsetting_0","displayName":"Allow third-party storage partitioning by default.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultthirdpartystoragepartitioningsetting_1","displayName":"Disable third-party storage partitioning.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultweatherlocation","displayName":"Default weather location","description":"Sets the default weather location in the Calendar view. Enter the city and state or country (e.g. Redmond, WA or Paris, France)","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#specify-default-weather-location"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":null},{"id":"com.apple.managedclient.preferences_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API","description":"Control whether websites can access nearby Bluetooth devices. You can completely block access or require the site to ask the user each time it wants to access a Bluetooth device.\n\nIf you don't configure this policy, the default value (3, meaning users are asked each time) is used and users can change it.\n\n* 2 = Don't allow any site to request access to Bluetooth devices by using the Web Bluetooth API\n\n* 3 = Allow sites to ask the user to grant access to a nearby Bluetooth device","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultwebbluetoothguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultwebbluetoothguardsetting_0","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultwebbluetoothguardsetting_1","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultwebhidguardsetting","displayName":"Control use of the WebHID API","description":"Setting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices.\n\nLeaving it unset lets websites ask for access, but users can change this setting.\n\nThis policy can be overridden for specific url patterns using the \"WebHidAskForUrls\" and \"WebHidBlockedForUrls\" policies.\n\nPolicy options mapping:\n\n* BlockWebHid (2) = Do not allow any site to request access to HID devices via the WebHID API\n\n* AskWebHid (3) = Allow sites to ask the user to grant access to a HID device\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultwebhidguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultwebhidguardsetting_0","displayName":"Do not allow any site to request access to HID devices via the WebHID API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultwebhidguardsetting_1","displayName":"Allow sites to ask the user to grant access to a HID device","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API","description":"Set whether websites can access connected USB devices. You can completely block access or ask the user each time a website wants to get access to connected USB devices.\n\nYou can override this policy for specific URL patterns by using the \"WebUsbAskForUrls\" and \"WebUsbBlockedForUrls\" policies.\n\nIf you don't configure this policy, sites can ask users whether they can access the connected USB devices (3) by default, and users can change this setting.\n\n* 2 = Don't allow any site to request access to USB devices via the WebUSB API\n\n* 3 = Allow sites to ask the user to grant access to a connected USB device","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultwebusbguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultwebusbguardsetting_0","displayName":"Do not allow any site to request access to USB devices via the WebUSB API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultwebusbguardsetting_1","displayName":"Allow sites to ask the user to grant access to a connected USB device","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting","description":"Setting the policy to \"BlockWindowManagement\" (value 2) automatically denies the window management permission to sites by default. This limits the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\n\nSetting the policy to \"AskWindowManagement\" (value 3) by default prompts the user when the window management permission is requested. If users allow the permission, it extends the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\n\nNot configuring the policy means the \"AskWindowManagement\" policy applies, but users can change this setting.\n\nPolicy options mapping:\n\n* BlockWindowManagement (2) = Denies the Window Management permission on all sites by default\n\n* AskWindowManagement (3) = Ask every time a site wants obtain the Window Management permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultwindowmanagementsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultwindowmanagementsetting_0","displayName":"Denies the Window Management permission on all sites by default","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultwindowmanagementsetting_1","displayName":"Ask every time a site wants obtain the Window Management permission","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_definitionupdatedue","displayName":"Security intelligence update due (in days)","description":"Determines the number of days after which the last installed security intelligence updates are considered outdated.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-preferences#duration-for-security-intelligence-updates-due-in-days"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":null},{"id":"com.apple.managedclient.preferences_definitionupdatesinterval","displayName":"Security intelligence update interval (in seconds)","description":"Specifies the time interval (in seconds) after which security intelligence updates will be checked.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-preferences#security-intelligence-update-interval-in-seconds"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":null},{"id":"com.apple.managedclient.preferences_deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own.\n\nIf fixing them is possible, it usually requires complex user actions.\n\nEnabling this policy or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched.\n\nDisabling this policy means users will have their password manager data untouched, but will experience a broken password manager functionality.\n\nIf the policy is set, users can't override it in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#deletingundecryptablepasswordsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_deletingundecryptablepasswordsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_deletingundecryptablepasswordsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_developertoolsavailability","displayName":"Control where developer tools can be used","description":"Control where developer tools can be used.\n\nIf you set this policy to 'DeveloperToolsDisallowedForForceInstalledExtensions' (0, the default), users can access the developer tools and the JavaScript console in general, but not in the context of extensions installed by enterprise policy.\n\nIf you set this policy to 'DeveloperToolsAllowed' (1), users can access the developer tools and the JavaScript console in all contexts, including extensions installed by enterprise policy.\n\nIf you set this policy to 'DeveloperToolsDisallowed' (2), users can't access the developer tools or inspect website elements. Keyboard shortcuts and menu or context menu entries that open the developer tools or the JavaScript Console are disabled.\n\n* 0 = Block the developer tools on extensions installed by enterprise policy, allow in other contexts\n\n* 1 = Allow using the developer tools\n\n* 2 = Don't allow using the developer tools","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#developertoolsavailability"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_developertoolsavailability_0","displayName":"Block the developer tools on extensions installed by enterprise policy, allow in other contexts","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_developertoolsavailability_1","displayName":"Allow using the developer tools","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_developertoolsavailability_2","displayName":"Don't allow using the developer tools","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage","description":"This policy controls sending required and optional diagnostic data about browser usage to Microsoft.\n\nRequired diagnostic data is collected keep Microsoft Edge secure, up to date and performing as expected.\n\nOptional diagnostic data includes data about how you use the browser, websites you visit and crash reports to Microsoft for product and service improvement.\n\nThis policy is not supported on Windows 10 devices. To control this data collection on Windows 10, IT admins must use the Windows diagnostic data group policy. This policy will either be 'Allow Telemetry' or 'Allow Diagnostic Data', depending on the version of Windows. Learn more about Windows 10 diagnostic data collection: https://go.microsoft.com/fwlink/?linkid=2099569\n\nUse one of the following settings to configure this policy:\n\n'Off' turns off required and optional diagnostic data collection. This option is not recommended.\n\n'RequiredData' sends required diagnostic data but turns off optional diagnostic data collection. Microsoft Edge will send required diagnostic data to keep Microsoft Edge secure, up to date and performing as expected.\n\n'OptionalData' sends optional diagnostic data includes data about browser usage, websites that are visited, crash reports sent to Microsoft for product and service improvement.\n\nOn Windows 7/macOS, this policy controls sending required and optional data to Microsoft.\n\nIf you don't configure this policy or disable it, Microsoft Edge will default to the user's preference.\n\nPolicy options mapping:\n\n* Off (0) = Off (Not recommended)\n\n* RequiredData (1) = Required data\n\n* OptionalData (2) = Optional data\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#diagnosticdata"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_diagnosticdata_0","displayName":"Off (Not recommended)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_diagnosticdata_1","displayName":"Required data","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_diagnosticdata_2","displayName":"Optional data","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_diagnosticdatatypepreference","displayName":"Diagnostic data level","description":"Controls the amount of telemetry data sent by apps.","helpText":null,"infoUrls":["https://aka.ms/macdiagpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_diagnosticdatatypepreference_0","displayName":"Required data only","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_diagnosticdatatypepreference_1","displayName":"Required and Optional data","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_diagnosticdatatypepreference_2","displayName":"Do not send data","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_diagnosticlevel","displayName":"Diagnostic collection level","description":"Diagnostic data is used to keep Microsoft Defender ATP secure and up-to-date, detect, diagnose and fix problems, and also make product improvements. This setting determines the level of diagnostics sent by the product to Microsoft.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#diagnostic-collection-level"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"com.apple.managedclient.preferences_diagnosticlevel_0","displayName":"optional","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_diagnosticlevel_1","displayName":"required","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disable3dapis","displayName":"Disable support for 3D graphics APIs","description":"Prevent web pages from accessing the graphics processing unit (GPU). Specifically, web pages can't access the WebGL API and plug-ins can't use the Pepper 3D API.\n\nIf you don't configure or disable this policy, it potentially allows web pages to use the WebGL API and plug-ins to use the Pepper 3D API. Microsoft Edge might, by default, still require command line arguments to be passed in order to use these APIs.\n\nIf \"HardwareAccelerationModeEnabled\" policy is set to false, the setting for 'Disable3DAPIs' policy is ignored - it's the equivalent of setting 'Disable3DAPIs' policy to true.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#disable3dapis"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_disable3dapis_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disable3dapis_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableauthnegotiatecnamelookup","displayName":"Disable CNAME lookup when negotiating Kerberos authentication","description":"Determines whether the generated Kerberos SPN is based on the canonical DNS name (CNAME) or on the original name entered.\n\nIf you enable this policy, CNAME lookup is skipped and the server name (as entered) is used.\n\nIf you disable this policy or don't configure it, the canonical name of the server is used. This is determined through CNAME lookup.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#disableauthnegotiatecnamelookup"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_disableauthnegotiatecnamelookup_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableauthnegotiatecnamelookup_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableautoconfig","displayName":"Disable automatic sign in","description":"If you set this value to true the sync app is prevented from automatically signing in with an existing Azure AD credential that is made available to Microsoft applications.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#disableautoconfig"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_disableautoconfig_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableautoconfig_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablecloudfonts","displayName":"Disable cloud fonts","description":"Prevent users from selecting and downloading cloud-based fonts.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-office"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_disablecloudfonts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablecloudfonts_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablednsovertcpparsing","displayName":"Disable DNS over TCP parsing","description":"Disables parsing of DNS over TCP","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablednsovertcpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablednsovertcpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablednsparsing","displayName":"Disable DNS parsing","description":"Disables parsing of DNS traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablednsparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablednsparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disabledonotforward","displayName":"Disable 'Do Not Forward' options","description":"Prevent users from applying the Do Not Forward option to emails when using Microsoft 365 Message Encryption.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-do-not-forward"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disabledonotforward_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disabledonotforward_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableencryptonly","displayName":"Disable Microsoft 365 encryption options","description":"Prevent users from applying the Encrypt-Only option to emails when using Microsoft 365 Message Encryption.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-encrypt-only"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disableencryptonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableencryptonly_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableexport","displayName":"Disable export to OLM files","description":"Prevent users exporting data to the local file system.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-export"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disableexport_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableexport_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableftpparsing","displayName":"Disable FTP parsing","description":"Disables parsing of FTP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disableftpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableftpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablehttpparsing","displayName":"Disable HTTP parsing","description":"Disables parsing of HTTP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablehttpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablehttpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablehydrationtoast","displayName":"Disable download toasts","description":"Prevents toasts from appearing when applications cause file contents to be downloaded.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#disablehydrationtoast"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_disablehydrationtoast_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablehydrationtoast_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableicmpparsing","displayName":"Disable ICMP parsing","description":"Disables parsing of ICMP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disableicmpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableicmpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableimport","displayName":"Disable import from OLM and PST files","description":"Prevent users importing data from the local file system.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-import"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disableimport_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableimport_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableinboundconnectionfiltering","displayName":"Disable inbound connection filtering","description":"Disables filtering of inbound connections","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disableinboundconnectionfiltering_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableinboundconnectionfiltering_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableinsidercheckbox","displayName":"Disable Office Insider membership","description":"Prevent users from changing to an Office Insider channel and obtaining Preview or Beta updates. The default value is false.","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_disableinsidercheckbox_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableinsidercheckbox_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablepersonalsync","displayName":"Disable personal accounts","description":"Blocks users from signing in and syncing files in personal OneDrive accounts. If this key is set after a user has set up sync with a personal account, the user will be signed out.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#disablepersonalsync"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_disablepersonalsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablepersonalsync_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablerdpparsing","displayName":"Disable RDP parsing","description":"Disables parsing of RDP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablerdpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablerdpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablerespondtomeetingwithoutresponse","displayName":"Disable 'Do not send response'","description":"Prevent users from selecting 'Do not send response' when replying to a meeting request.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-outlook#disable-do-not-send-a-response"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disablerespondtomeetingwithoutresponse_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablerespondtomeetingwithoutresponse_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablescreenshots","displayName":"Disable taking screenshots","description":"Controls if users can take screenshots of the browser page.\n\nIf enabled, user can't take screenshots by using keyboard shortcuts or extension APIs.\n\nIf disabled or don't configure this policy, users can take screenshots.\n\nPlease note this policy controls screenshots taken from within the browser itself. Even if you enable this policy, users might still be able to take screenshots using some method outside of the browser (like using an operating system feature or another application).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#disablescreenshots"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_disablescreenshots_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablescreenshots_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablesignatures","displayName":"Disable email signatures","description":"Prevent users from adding, removing, and editing signatures","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-signatures"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disablesignatures_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablesignatures_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableskypemeeting","displayName":"Disable Skype for Business meeting support","description":"Prevent users from adding Skype for Business to meeting invites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-skype-for-business-online-meetings"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disableskypemeeting_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableskypemeeting_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablesmimecompose","displayName":"Disable S/MIME","description":"Prevent users from applying S/MIME option to email messages.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-smime"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disablesmimecompose_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablesmimecompose_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablesmtpparsing","displayName":"Disable SMTP parsing","description":"Disables parsing of SMTP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablesmtpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablesmtpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablesshparsing","displayName":"Disable SSH parsing","description":"Disables parsing of SSH traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablesshparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablesshparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disableteamsmeeting","displayName":"Disable Microsoft Teams meeting support","description":"Prevent users from adding Teams to meeting invites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-teams-online-meetings"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disableteamsmeeting_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableteamsmeeting_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disabletlsparsing","displayName":"Disable TLS parsing","description":"Disables parsing of TLS traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disabletlsparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disabletlsparsing_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disabletutorial","displayName":"Disable tutorial","description":"This setting prevents the tutorial from being shown to users after they set up OneDrive.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#disabletutorial"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_disabletutorial_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disabletutorial_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablevisualbasicexternaldylibs","displayName":"Prevent Visual Basic macros from using external dynamic libraries","description":"Recommended: true, unless third-party add-ins and extensions are being used.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_disablevisualbasicexternaldylibs_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablevisualbasicexternaldylibs_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablevisualbasicmacscript","displayName":"Prevent Visual Basic macros from using legacy MacScript","description":"Recommended: true.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_disablevisualbasicmacscript_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablevisualbasicmacscript_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disablevisualbasictobindtopopen","displayName":"Prevent Visual Basic macros from using pipes to communicate","description":"Recommended: true, unless third-party add-ins and extensions are being used.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_disablevisualbasictobindtopopen_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablevisualbasictobindtopopen_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_disallowedthreatactions","displayName":"Disallowed threat actions","description":"Restricts the actions that the local user of a device can take when threats are detected. The actions included in this list are not displayed in the user interface.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#disallowed-threat-actions"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_diskcachedir","displayName":"Set disk cache directory","description":"Configures the directory to use to store cached files.\n\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified the '--disk-cache-dir' flag. To avoid data loss or other unexpected errors, don't configure this policy to a volume's root directory or to a directory used for other purposes, because Microsoft Edge manages its contents.\n\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables you can use when specifying directories and paths.\n\nIf you don't configure this policy, the default cache directory is used, and users can override that default with the '--disk-cache-dir' command line flag.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#diskcachedir"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_diskcachesize","displayName":"Set disk cache size, in bytes","description":"Configures the size of the cache, in bytes, used to store files on the disk.\n\nIf you enable this policy, Microsoft Edge uses the provided cache size regardless of whether the user has specified the '--disk-cache-size' flag. The value specified in this policy isn't a hard boundary but rather a suggestion to the caching system; any value below a few megabytes is too small and will be rounded up to a reasonable minimum.\n\nIf you set the value of this policy to 0, the default cache size is used, and users can't change it.\n\nIf you don't configure this policy, the default size is used, but users can override it with the '--disk-cache-size' flag.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#diskcachesize"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_dnsinterceptionchecksenabled","displayName":"DNS interception checks enabled","description":"This policy configures a local switch that can be used to disable DNS interception checks. These checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\n\nThis detection might not be necessary in an enterprise environment where the network configuration is known. It can be disabled to avoid additional DNS and HTTP traffic on start-up and each DNS configuration change.\n\nIf you enable or don’t set this policy, the DNS interception checks are performed.\n\nIf you disable this policy, DNS interception checks aren’t performed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#dnsinterceptionchecksenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_dnsinterceptionchecksenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dnsinterceptionchecksenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode","displayName":"Control the mode of DNS-over-HTTPS","description":"Control the mode of the DNS-over-HTTPS resolver. Note that this policy will only set the default mode for each query. The mode can be overridden for special types of queries such as requests to resolve a DNS-over-HTTPS server hostname.\n\nThe \"off\" mode will disable DNS-over-HTTPS.\n\nThe \"automatic\" mode will send DNS-over-HTTPS queries first if a DNS-over-HTTPS server is available and may fallback to sending insecure queries on error.\n\nThe \"secure\" mode will only send DNS-over-HTTPS queries and will fail to resolve on error.\n\nIf you don't configure this policy, the browser might send DNS-over-HTTPS requests to a resolver associated with the user's configured system resolver.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#dnsoverhttpsmode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode_0","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode_1","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode_2","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver","description":"The URI template of the desired DNS-over-HTTPS resolver. To specify multiple DNS-over-HTTPS resolvers, separate the corresponding URI templates with spaces.\n\nIf you set \"DnsOverHttpsMode\" to \"secure\" then this policy must be set and cannot be empty.\n\nIf you set \"DnsOverHttpsMode\" to \"automatic\" and this policy is set then the URI templates specified will be used. If you don't set this policy, then hardcoded mappings will be used to attempt to upgrade the user's current DNS resolver to a DoH resolver operated by the same provider.\n\nIf the URI template contains a dns variable, requests to the resolver will use GET; otherwise requests will use POST.\n\nIncorrectly formatted templates will be ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#dnsoverhttpstemplates"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_doubleclickclosetabenabled","displayName":"Double Click feature in Microsoft Edge enabled (only available in China)","description":"This policy lets you configure the double click feature in Microsoft Edge.\n\nDouble Click lets users close a tab by double clicking the left mouse button.\n\nIf you enable or don't configure this policy, you can use the double click feature to close a tab on Microsoft Edge to start using this feature.\n\nIf you disable this policy, you can't use the double click feature in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#doubleclickclosetabenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_doubleclickclosetabenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_doubleclickclosetabenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_downloadbandwidthlimited","displayName":"Set maximum download throughput","description":"Sets the maximum download throughput rate in kilobytes (KB)/sec for computers running the OneDrive sync app. The minimum rate is 50 KB/sec and the maximum rate is 100,000 KB/sec.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#downloadbandwidthlimited"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_downloaddirectory","displayName":"Set download directory","description":"Configures the directory to use when downloading files.\n\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified one or chosen to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\n\nIf you disable or don't configure this policy, the default download directory is used, and the user can change it.\n\nIf you set an invalid path, Microsoft Edge will default to the user's default download directory.\n\nIf the folder specified by the path doesn't exist, the download will trigger a prompt that asks the user where they want to save their download.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#downloaddirectory"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_downloadrestrictions","displayName":"Allow download restrictions","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\n\nSet 'Block dangerous downloads' (1) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings.\n\nSet 'Block potentially dangerous downloads' (2) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous downloads.\n\nSet 'Block all downloads' (3) to block all downloads.\n\nIf you don't configure this policy or set the 'No special restrictions' (0) option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\n\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\n\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\n\n* 0 = No special restrictions\n\n* 1 = Block dangerous downloads\n\n* 2 = Block potentially dangerous downloads\n\n* 3 = Block all downloads","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#downloadrestrictions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_downloadrestrictions_1","displayName":"Block dangerous downloads","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_downloadrestrictions_2","displayName":"Block potentially dangerous downloads","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_downloadrestrictions_4","displayName":"Block malicious downloads","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_earlypreview","displayName":"Enable / disable early preview","description":"Whether EDR early preview features are enabled or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-early-preview"],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":[{"id":"com.apple.managedclient.preferences_earlypreview_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_earlypreview_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeassetdeliveryserviceenabled","displayName":"Allow features to download assets from the Asset Delivery Service","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\nThese assets can be config files or Machine Learning models that power the features that use this service.\n\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\n\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeassetdeliveryserviceenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeassetdeliveryserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeassetdeliveryserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeautofillmlenabled","displayName":"Machine learning powered autofill suggestions","description":"Allows ML technology to predict and fill in forms and text fields for better browsing. Your personal data is secure and will not be used elsewhere.\n\nIf you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data.\n\nIf you disable this policy, machine learning powered autofill suggestions will not be shown, and autofill will no longer use cloud-based machine learning models to enhance form filling with smarter, context aware suggestions. Instead, autofill will rely on basic form data without the benefits of machine learning.\n\nThis policy will be disabled if you disable \"AutofillAddressEnabled\"..","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeautofillmlenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeautofillmlenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeautofillmlenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgecollectionsenabled","displayName":"Enable the Collections feature","description":"Lets you allow users to access the Collections feature, where they can collect, organize, share, and export content more efficiently and with Office integration.\n\nIf you enable or don't configure this policy, users can access and use the Collections feature in Microsoft Edge.\n\nIf you disable this policy, users can't access and use Collections in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgecollectionsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgecollectionsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgecollectionsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgedisabledialprotocolforcastdiscovery","displayName":"Disable DIAL protocol for cast device discovery","description":"Enable this policy to disable the DIAL (Discovery And Launch) protocol for cast device discovery. (If EnableMediaRouter is disabled, this policy will have no effect).\n\nEnable this policy to disable DIAL protocol.\n\nBy default, Cast device discovery will use DIAL protocol.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgedisabledialprotocolforcastdiscovery"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgedisabledialprotocolforcastdiscovery_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgedisabledialprotocolforcastdiscovery_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeedropenabled","displayName":"Enable Drop feature in Microsoft Edge","description":"This policy lets you configure the Drop feature in Microsoft Edge.\n\nDrop lets users send messages or files to themselves.\n\nIf you enable or don't configure this policy, you can use the Drop feature in Microsoft Edge.\n\nIf you disable this policy, you can't use the Drop feature in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeedropenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeedropenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeedropenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeentracopilotpagecontext","displayName":"Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane","description":"This policy controls whether Copilot in the Microsoft Edge sidepane can access Microsoft Edge page content. This includes page summarization and similar contextual queries sent to Copilot.\n\nThis policy only applies to users who are signed in to Microsoft Edge with their Entra account and are using Copilot in the sidepane. This policy applies to all Copilot products in the Microsoft Edge sidepane - namely, Microsoft 365 Copilot Business Chat and Microsoft Copilot with enterprise data protection (EDP).\n\nIf you enable this policy, Copilot will be able to access Microsoft Edge page content when users ask a contextual query to Copilot in the Microsoft Edge sidepane.\n\nIf you disable this policy, Copilot will not be able to access Microsoft Edge page content.\n\nIf you don't configure this policy, the default behavior is as follows:\n\n- For non-EU countries, access is enabled by default.\n\n- For EU countries, access is disabled by default.\n\n- In both cases, if the policy is not configured, users can enable or disable Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings.\n\nExceptions to the preceding behavior include when a page is protected using data loss prevention (DLP) measures. In that case, Copilot will not be able to access Microsoft Edge page content even when this policy is enabled. This behavior is to ensure the integrity of DLP.\n\nLearn more about Copilot's data usage and consent at https://go.microsoft.com/fwlink/?linkid=2288056","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeentracopilotpagecontext"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeentracopilotpagecontext_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeentracopilotpagecontext_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgehistoryaisearchenabled","displayName":"Control access to AI-enhanced search in History","description":"This policy controls whether users can use AI-enhanced search in their browsing history in Microsoft Edge.\n\nWhen enabled or not configured, users can search using synonyms, natural language phrases, and minor spelling errors to find previously visited pages.\n\nWhen disabled, users can only perform exact match (verbatim) searches in their history.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgehistoryaisearchenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgehistoryaisearchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgehistoryaisearchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgemanagementextensionsfeedbackenabled","displayName":"Microsoft Edge management extensions feedback enabled","description":"This setting controls whether Microsoft Edge sends data about blocked extensions to the Microsoft Edge management service.\n\nThe 'EdgeManagementEnabled' policy must also be enabled for this setting to take effect.\n\nIf you enable this policy, Microsoft Edge will send data to the Microsoft Edge service when a user tries to install a blocked extension.\n\nIf you disable or don't configure this policy, Microsoft Edge won't send any data to the Microsoft Edge service about blocked extensions.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgemanagementextensionsfeedbackenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgemanagementextensionsfeedbackenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgemanagementextensionsfeedbackenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgemanagementpolicyoverridesplatformpolicy","displayName":"Microsoft Edge management service policy overrides platform policy.","description":"If you enable this policy, the cloud-based Microsoft Edge management service policy takes precedence if it conflicts with platform policy.\n\nIf you disable or don't configure this policy, platform policy takes precedence if it conflicts with the cloud-based Microsoft Edge management service policy.\n\nThis mandatory policy affects machine scope cloud-based Microsoft Edge management policies.\n\nMachine policies apply to all edge browser instances regardless of the user who is logged in.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgemanagementpolicyoverridesplatformpolicy"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgemanagementpolicyoverridesplatformpolicy_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgemanagementpolicyoverridesplatformpolicy_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgemanagementuserpolicyoverridescloudmachinepolicy","displayName":"Allow cloud-based Microsoft Edge management service user policies to override local user policies.","description":"If you enable this policy, cloud-based Microsoft Edge management service user policies takes precedence if it conflicts with local user policy.\n\nIf you disable or don't configure this policy, Microsoft Edge management service user policies will take precedence.\n\nThe policy can be combined with \"EdgeManagementPolicyOverridesPlatformPolicy\". If both policies are enabled, all cloud-based Microsoft Edge management service policies will take precedence over conflicting local service policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgemanagementuserpolicyoverridescloudmachinepolicy"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgemanagementuserpolicyoverridescloudmachinepolicy_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgemanagementuserpolicyoverridescloudmachinepolicy_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeopenexternallinkswithappspecifiedprofile","displayName":"Prioritize App specified profile to open external links","description":"This policy controls whether the profile specified by an app (such as Microsoft Teams or Outlook) is given priority when opening external links, instead of the profile selected in the Default profile for external links setting.\n\nPolicy behavior:\n1. Enabled or not configured: The app-specified profile is prioritized for opening external links. This behavior overrides the profile selected in settings, and the behavior defined by the EdgeDefaultProfileEnabled and EdgeOpenExternalLinksWithPrimaryWorkProfileEnabled policies. If the app doesn't specify a profile, this policy has no effect.\n2. Disabled: The profile selected in settings—along with the EdgeDefaultProfileEnabled and EdgeOpenExternalLinksWithPrimaryWorkProfileEnabled policies—will be used to determine which profile opens external links.\n\nNOTE:\nThis policy doesn't override user-defined preferences set through Automatic profile switching, including the Custom site switch setting located within it. If a user has configured specific sites to open in designated profiles, those preferences take precedence.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeopenexternallinkswithappspecifiedprofile"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeopenexternallinkswithappspecifiedprofile_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeopenexternallinkswithappspecifiedprofile_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeopenexternallinkswithprimaryworkprofileenabled","displayName":"Use Primary Work Profile as default to open external links","description":"This policy controls whether Microsoft Edge uses the Primary Work Profile as the default profile when opening external links.\n1. On Windows, the Primary Work Profile refers to the profile signed in with the Entra ID account used to enroll the device.\n2. On macOS and Linux, the Primary Work Profile is the only profile signed in with an Entra ID account. If multiple profiles are signed in with Entra ID accounts, the Primary Work Profile setting doesn't apply.\n\nPolicy behavior:\n1. If enabled or not configured, Microsoft Edge uses the Primary Work Profile as the default for opening external links.\n2. If disabled, the last used profile becomes the default for opening external links.\n\nNote: This policy doesn't override the following scenarios:\n1. If the EdgeDefaultProfileEnabled policy is set, it takes precedence over this policy.\n2. External links opened from Outlook or Microsoft Teams may be configured to launch in a specific profile, which can override the Primary Work Profile setting.\n3. If the user sets a preference for \"Default profile for external links\" in Profile preferences, that setting takes effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeopenexternallinkswithprimaryworkprofileenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeopenexternallinkswithprimaryworkprofileenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeopenexternallinkswithprimaryworkprofileenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeshoppingassistantenabled","displayName":"Shopping in Microsoft Edge Enabled","description":"This policy lets users compare the prices of a product they are looking at, get coupons from the website they're on, or auto-apply coupons during checkout.\n\nIf you enable or don't configure this policy, shopping features such as price comparison and coupons will be automatically applied for retail domains. Coupons for the current retailer and prices from other retailers will be fetched from a server.\n\nIf you disable this policy shopping features such as price comparison and coupons will not be automatically found for retail domains.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeshoppingassistantenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeshoppingassistantenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeshoppingassistantenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgesidebarappurlhostallowlist","displayName":"Allow specific apps to be opened in Microsoft Edge sidebar","description":"Define a list of sites, based on URL patterns, that are not subject to the \"EdgeSidebarAppUrlHostBlockList\".\n\nIf you don't configure this policy, a user can open any app in sidebar except the urls listed in \"EdgeSidebarAppUrlHostBlockList\".\n\nIf you configure this policy, the apps listed in the allow list could be opened in sidebar even if they are listed in the block list.\n\nBy default, all apps are allowed. However, if you prohibited apps by policy, you can use the list of allowed apps to change that policy.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgesidebarappurlhostallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_edgesidebarappurlhostblocklist","displayName":"Control which apps cannot be opened in Microsoft Edge sidebar","description":"Define a list of sites, based on URL patterns, that cannot be opened in sidebar.\n\nIf you don't configure this policy, a user can open any app in sidebar.\n\nIf the \"HubsSidebarEnabled\" policy is disabled, this list isn't used and no sidebar can be opened.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\n\nNote: A blocklist value of '*' means all apps are blocked unless they are explicitly listed in the \"EdgeSidebarAppUrlHostAllowList\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgesidebarappurlhostblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\n\nIf you don't configure this policy, no app is forced to be shown in sidebar.\n\nIf the \"HubsSidebarEnabled\" policy is disabled, this list isn't used and no sidebar can be shown.\n\nFor detailed information about valid url, see https://go.microsoft.com/fwlink/?linkid=2281313.\n\nNote: URL patterns are not supported in this policy. You should provide the exact URL of the app.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgesidebarappurlhostforcelist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_edgesidebarcustomizeenabled","displayName":"Enable sidebar customize","description":"Allow/Disallow to use sidebar customize.\n\nIf you enable or don't configure this policy, users will be able to access sidebar customize.\nIf you disable this policy, users will not be able to access the sidebar customize.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgesidebarcustomizeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgesidebarcustomizeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgesidebarcustomizeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgewalletetreeenabled","displayName":"Edge Wallet E-Tree Enabled","description":"The Edge Wallet E-Tree feature in Microsoft Edge allows users to plant a E-Tree for their own.\n\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\n\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgewalletetreeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgewalletetreeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgewalletetreeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_edgeworkspacesenabled","displayName":"Enable Workspaces","description":"Microsoft Edge Workspaces helps improve productivity for users in your organization.\n\nIf you enable or don't configure this policy, users will be able to access the Microsoft Edge Workspaces feature.\nIf you disable this policy, users will not be able to access the Microsoft Edge Workspaces feature.\n\nTo learn more about the feature, see https://go.microsoft.com/fwlink/?linkid=2209950","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeworkspacesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeworkspacesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeworkspacesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_editfavoritesenabled","displayName":"Allows users to edit favorites","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\n\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#editfavoritesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_editfavoritesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_editfavoritesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_efficiencymode","displayName":"Configure when efficiency mode should become active","description":"This policy setting lets you configure when efficiency mode becomes active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, efficiency mode is disabled by default and does not become active. Please note that Windows Energy Saver settings can influence when efficiency mode becomes active on all devices.\n\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy \"SleepingTabsBlockedForUrls\".\n\nSet this policy to 'AlwaysActive' and efficiency mode is always active.\n\nSet this policy to 'NeverActive' and efficiency mode never becomes active.\n\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode becomes active when the device is unplugged.\n\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode becomes active when the device is unplugged and the battery is low.\n\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\nIf the device does not have a battery, efficiency mode never becomes active in any mode other than 'AlwaysActive' unless the setting or \"EfficiencyModeEnabled\" policy is enabled.\n\nThis policy has no effect if the \"EfficiencyModeEnabled\" policy is disabled.\n\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\n\nLearn more about energy saver: https://learn.microsoft.com/en-us/windows-hardware/design/component-guidelines/energy-saver\n\nPolicy options mapping:\n\n* AlwaysActive (0) = Efficiency mode is always active\n\n* NeverActive (1) = Efficiency mode is never active\n\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\n\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\n\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#efficiencymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_4","displayName":"When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes extra steps to save battery.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_5","displayName":"When the device is unplugged or unplugged and the battery is low, efficiency mode takes extra steps to save battery.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_efficiencymodeenabled","displayName":"Efficiency mode enabled","description":"Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and disabled otherwise.\n\nIf you enable this policy, efficiency mode will become active according to the setting chosen by the user. You can configure the efficiency mode setting using the \"EfficiencyMode\" policy. If the device does not have a battery, efficiency mode will always be active.\n\nIf you disable this policy, efficiency mode will never become active. The \"EfficiencyMode\" and \"EfficiencyModeOnPowerEnabled\" policies will have no effect.\n\nIf you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system.\n\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#efficiencymodeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_efficiencymodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_efficiencymodeonpowerenabled","displayName":"Enable efficiency mode when the device is connected to a power source","description":"Allows efficiency mode to become active when the device is connected to a power source. On devices with no battery, this policy has no effect.\n\nIf you enable this policy, efficiency mode will become active when the device is connected to a power source.\n\nIf you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source.\n\nThis policy has no effect if the \"EfficiencyModeEnabled\" policy is disabled.\n\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#efficiencymodeonpowerenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_efficiencymodeonpowerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymodeonpowerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enableallocsiclients","displayName":"Enable simultaneous edits for Office apps","description":"This setting lets multiple users use the Microsoft 365 Apps for enterprise, Office 2019, or Office 2016 desktop apps to simultaneously edit an Office file stored in OneDrive. It also lets users share files from the Office desktop apps.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#enableallocsiclients"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_enableallocsiclients_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableallocsiclients_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enableauthnegotiateport","displayName":"Include non-standard port in Kerberos SPN","description":"Specifies whether the generated Kerberos SPN should include a non-standard port.\n\nIf you enable this policy, and a user includes a non-standard port (a port other than 80 or 443) in a URL, that port is included in the generated Kerberos SPN.\n\nIf you don't configure or disable this policy, the generated Kerberos SPN won't include a port in any case.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enableauthnegotiateport"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enableauthnegotiateport_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableauthnegotiateport_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablebackgroundaccessibilitychecker","displayName":"Background accessibility checking","description":"The background accessibility checker automatically helps find and fix content in documents that may make it harder for people with disabilities to consume.","helpText":null,"infoUrls":[],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_enablebackgroundaccessibilitychecker_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablebackgroundaccessibilitychecker_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablecheckforupdatesbutton","displayName":"Enable check for updates","description":"Allow users to check for app updates. The default value is true.","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_enablecheckforupdatesbutton_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablecheckforupdatesbutton_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enabled","displayName":"Enable / disable cloud delivered protection","description":"Whether cloud delivered protection is enabled on the device or not. To improve the security of your services, we recommend keeping this feature turned on.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-cloud-delivered-protection"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"com.apple.managedclient.preferences_enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enabledeprecatedwebplatformfeatures","displayName":"Re-enable deprecated web platform features for a limited time","description":"Specify a list of deprecated web platform features to temporarily re-enable.\n\nThis policy lets you re-enable deprecated web platform features for a limited time. Features are identified by a string tag.\n\nIf you don't configure this policy, if the list is empty, or if a feature doesn't match one of the supported string tags, all deprecated web platform features remain disabled.\n\nWhile the policy itself is supported on the above platforms, the feature it's enabling might not be available on all of those platforms. Not all deprecated Web Platform features can be re-enabled. Only those explicitly listed below can be re-enabled, and only for a limited period of time, which differs per feature. You can review the intent behind the Web Platform feature changes at https://bit.ly/blinkintents.\n\nThe general format of the string tag is [DeprecatedFeatureName]_EffectiveUntil[yyyymmdd].\n\n* \"ExampleDeprecatedFeature_EffectiveUntil20080902\" = Enable ExampleDeprecatedFeature API through 2008/09/02","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enabledeprecatedwebplatformfeatures"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_enabledomainactionsdownload","displayName":"Enable Domain Actions Download from Microsoft","description":"In Microsoft Edge, Domain Actions represent a series of compatibility features that help the browser work correctly on the web.\n\nMicrosoft keeps a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken due to the new User Agent string on Microsoft Edge. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\n\nWhen the browser starts up and then periodically afterwards, the browser will contact the Experimentation and Configuration Service that contains the most up to date list of compatibility actions to perform. This list is saved locally after it is first retrieved so that subsequent requests will only update the list if the server's copy has changed.\n\nIf you enable this policy, the list of Domain Actions will continue to be downloaded from the Experimentation and Configuration Service.\n\nIf you disable this policy, the list of Domain Actions will no longer be downloaded from the Experimentation and Configuration Service.\n\nIf you don't configure this policy, the list of Domain Actions will continue to be downloaded from the Experimentation and Configuration Service.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enabledomainactionsdownload"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enabledomainactionsdownload_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enabledomainactionsdownload_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablefilehashcomputation","displayName":"Enable file hash computation","description":"Enables or disables file hash computation feature. When this feature is enabled Windows defender will compute hashes for files it scans. This will help in improving the accuracy of Custom Indicator matches. However, enabling Enable file hash computation may impact device performance.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#configure-file-hash-computation-feature"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_enablefilehashcomputation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablefilehashcomputation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablemediarouter","displayName":"Enable Google Cast","description":"Enable this policy to enable Google Cast. Users will be able to launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.\n\nDisable this policy to disable Google Cast.\n\nBy default, Google Cast is enabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enablemediarouter"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enablemediarouter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablemediarouter_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablenewoutlook","displayName":"Enable New Outlook","description":"Specify whether users should be allowed to switch between Classic and New Outlook.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#enable-new-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_enablenewoutlook_0","displayName":"Classic Outlook only","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablenewoutlook_1","displayName":"Default to Classic Outlook. Users may switch to New Outlook","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablenewoutlook_2","displayName":"Default to New Outlook. Users may revert to Classic Outlook","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablenewoutlook_3","displayName":"New Outlook only","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enableodignore","displayName":"Ignore named files","description":"This setting lets you enter keywords to prevent the OneDrive sync app from uploading certain files to OneDrive or SharePoint. You can enter complete names, such as setup.bin or use the asterisk (*) as a wildcard character to represent a series of characters, such as *.eml. Keywords aren't case-sensitive.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#allow-only-corporate-mailboxes-to-be-added"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_enableonlinerevocationchecks","displayName":"Enable online OCSP/CRL checks","description":"Online revocation checks don't provide a significant security benefit and are disabled by default.\n\nIf you enable this policy, Microsoft Edge will perform soft-fail, online OCSP/CRL checks. \"Soft fail\" means that if the revocation server can't be reached, the certificate will be considered valid.\n\nIf you disable the policy or don't configure it, Microsoft Edge won't perform online revocation checks.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enableonlinerevocationchecks"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enableonlinerevocationchecks_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableonlinerevocationchecks_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablerealtimeprotection","displayName":"Enable real-time protection (deprecated)","description":"Whether real-time protection (scan files as they are accessed) is enabled or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-real-time-protection"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_enablerealtimeprotection_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablerealtimeprotection_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablesetwarntoblock","displayName":"Enable set warn to block","description":"Converts warn determinations into blocks","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_enablesetwarntoblock_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablesetwarntoblock_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enablesha1forlocalanchors","displayName":"Allow certificates signed using SHA-1 when issued by local trust anchors","description":"When this setting is enabled, Microsoft Edge allows connections secured by SHA-1 signed certificates so long as the the certificate chains to a locally-installed root certificate and is otherwise valid.\n\nNote that this policy depends on the operating system (OS) certificate verification stack allowing SHA-1 signatures. If an OS update changes the OS handling of SHA-1 certificates, this policy might no longer have effect. Further, this policy is intended as a temporary workaround to give enterprises more time to move away from SHA-1. This policy will be removed in Microsoft Edge 92 releasing in mid 2021.\n\nIf you don't set this policy or set it to false, or the SHA-1 certificate chains to a publicly trusted certificate root, then Microsoft Edge won't allow certificates signed by SHA-1.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enablesha1forlocalanchors"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enablesha1forlocalanchors_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablesha1forlocalanchors_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enableunsafeswiftshader","displayName":"Allow software WebGL fallback using SwiftShader","description":"Controls whether SwiftShader is used as a fallback for WebGL when hardware GPU acceleration isn't available.\n\nWhen enabled, Microsoft Edge uses SwiftShader to support WebGL on systems without GPU acceleration, such as headless environments or virtual machines.\n\nStarting in Microsoft Edge version 144, SwiftShader has been deprecated due to security concerns. As a result, WebGL context creation fails in scenarios where SwiftShader would have been used. Enabling this policy allows organizations to temporarily defer the deprecation and continue using SwiftShader.\n\nIf you disable or don't configure this policy, WebGL context creation may fail on systems without hardware acceleration. This could cause web content relying on WebGL to function incorrectly if it doesn't handle context creation failures.\n\nNote: This policy is temporary and scheduled for removal in a future release. Microsoft does not guarantee the security of environments where this policy is enabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enableunsafeswiftshader"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enableunsafeswiftshader_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableunsafeswiftshader_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_encryptedclienthelloenabled","displayName":"TLS Encrypted ClientHello Enabled","description":"Encrypted ClientHello (ECH) is an extension to TLS that encrypts the sensitive fields of ClientHello to improve privacy.\n\nIf ECH is enabled, Microsoft Edge might or might not use ECH depending on server support, the availability of the HTTPS DNS record, or the rollout status.\n\nIf you enable or do not configure this policy, Microsoft Edge will follow the default rollout process for ECH.\n\nIf this policy is disabled, Microsoft Edge will not enable ECH.\n\nBecause ECH is an evolving protocol, Microsoft Edge's implementation is subject to change.\n\nAs such, this policy is a temporary measure to control the initial experimental implementation. It will be replaced with final controls as the protocol finalizes.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#encryptedclienthelloenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_encryptedclienthelloenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_encryptedclienthelloenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enforcementlevel","displayName":"Enforcement level","description":"Specifies if network protection is disabled, in audit mode, or enforced","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_enforcementlevel_0","displayName":"disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_1","displayName":"audit","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_2","displayName":"block","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enforcementlevel_antivirusengine","displayName":"Enforcement level","description":"Antivirus engine enforcement mode","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences#enforcement-level-for-antivirus-engine"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_enforcementlevel_antivirusengine_0","displayName":"passive","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_antivirusengine_1","displayName":"on_demand","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_antivirusengine_2","displayName":"real_time","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection","displayName":"Enforcement level","description":"Specifies if tamper protection is disabled, in audit mode, or enforced","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":[{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection_0","displayName":"disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection_1","displayName":"audit","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection_2","displayName":"block","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge","description":"This policy lets you enhance the security state in Microsoft Edge.\n\nIf you set this policy to 'StandardMode', the enhanced mode will be turned off and Microsoft Edge will fallback to its standard security mode.\n\nIf you set this policy to 'BalancedMode', the security state will be in balanced mode.\n\nIf you set this policy to 'StrictMode', the security state will be in strict mode.\n\nIf you set this policy to 'BasicMode', the security state will be in basic mode.\n\nNote: Sites that use WebAssembly (WASM) are not supported on 32-bit systems when \"EnhanceSecurityMode\" is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\n\nStarting in Microsoft Edge 113, 'BasicMode' is deprecated and is treated the same as 'BalancedMode'. It won't work in Microsoft Edge version 116.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895\n\nPolicy options mapping:\n\n* StandardMode (0) = Standard mode\n\n* BalancedMode (1) = Balanced mode\n\n* StrictMode (2) = Strict mode\n\n* BasicMode (3) = (Deprecated) Basic mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enhancesecuritymode_0","displayName":"Standard mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymode_1","displayName":"Balanced mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymode_2","displayName":"Strict mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymode_3","displayName":"(Deprecated) Basic mode","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enhancesecuritymodebypasslistdomains","displayName":"Configure the list of domains for which enhance security mode will not be enforced","description":"Configure the list of enhance security trusted domains. This means that\nenhance security mode will not be enforced when loading the sites in trusted domains.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymodebypasslistdomains"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeenforcelistdomains","displayName":"Configure the list of domains for which enhance security mode will always be enforced","description":"Configure the list of enhance security untrusted domains. This means that\nenhance security mode will always be enforced when loading the sites in untrusted domains.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymodeenforcelistdomains"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeindicatoruienabled","displayName":"Manage the indicator UI of the Enhanced Security Mode (ESM) feature in Microsoft Edge","description":"This policy lets you manage whether the indicator User Interface (UI) for enhanced security mode is shown or not when ESM is turned on.\n\nIf you enable or don't configure this policy, the indicator UI is on.\n\nIf you disable this policy, the indicator UI is off.\n\nNote: If this policy is used, only the indicator User Interface experience is supressed - ESM is still turned on. For more information, see the \"EnhanceSecurityMode\" policy.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymodeindicatoruienabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enhancesecuritymodeindicatoruienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeindicatoruienabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeoptoutuxenabled","displayName":"Manage opt-out user experience for Enhanced Security Mode (ESM) in Microsoft Edge (Deprecated)","description":"This policy lets you manage whether the opt-out user experience for enhanced security mode is presented when ESM is turned on for Microsoft Edge.\n\nIf you enable or don't configure this policy, the UI for the opt-out user experience is on.\n\nIf you disable this policy, the UI for the opt-out user experience is off.\n\nNote: If this policy is used, only the User Interface for the opt-out experience is supressed - ESM is still turned on. For more information, see the \"EnhanceSecurityMode\" policy.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.\n\nAfter careful evaluation, we have determined that this experimental opt-out UX is not required. As a result, this policy will be deprecated and stop working after Edge version 130.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymodeoptoutuxenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enhancesecuritymodeoptoutuxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeoptoutuxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_enterprisehardwareplatformapienabled","displayName":"Allow managed extensions to use the Enterprise Hardware Platform API","description":"When this policy is set to enabled, extensions installed by enterprise policy are allowed to use the Enterprise Hardware Platform API.\nWhen this policy is set to disabled or isn't set, no extensions are allowed to use the Enterprise Hardware Platform API.\nThis policy also applies to component extensions.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enterprisehardwareplatformapienabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enterprisehardwareplatformapienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enterprisehardwareplatformapienabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_exclusions","displayName":"Scan exclusions","description":"Entities that have been excluded from the scan. Exclusions can be specified by full paths, extensions, or file names.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#scan-exclusions"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_$type","displayName":"Type","description":null,"helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_exclusions_item_$type_0","displayName":"Path","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusions_item_$type_1","displayName":"File extension","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusions_item_$type_2","displayName":"File name","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_exclusions_item_args_tamperprotection","displayName":"Process's arguments","description":"Command line arguments","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_extension","displayName":"File extension","description":null,"helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_isdirectory","displayName":"Directory (selected) or file (not selected)","description":"Directory if selected, or file if not selected","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_exclusions_item_isdirectory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusions_item_isdirectory_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_exclusions_item_name","displayName":"Name","description":"Process name, either or full path or file name, wildcards supported","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_path","displayName":"Path","description":"Path to exclude, wildcards are supported","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_path_tamperprotection","displayName":"Process path","description":"Full and exact path to the process binary","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_signingid_tamperprotection","displayName":"Process's Signing Identifier","description":"Code signature Identifier","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":null},{"id":"com.apple.managedclient.preferences_exclusions_item_teamid_tamperprotection","displayName":"Process's TeamIdentifier","description":"Code signature TeamIdentifier","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":null},{"id":"com.apple.managedclient.preferences_exclusions_tamperprotection","displayName":"Process exclusions","description":"Defines process that can interfere with Defender without considering it tampering","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":null},{"id":"com.apple.managedclient.preferences_exclusionsmergepolicy","displayName":"Exclusions merge","description":"Specify the merge policy for exclusions. This can be a combination of administrator-defined and user-defined exclusions (merge) or only administrator-defined exclusions (admin_only). This setting can be used to restrict local users from defining their own exclusions.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#exclusion-merge-policy"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_exclusionsmergepolicy_0","displayName":"merge","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusionsmergepolicy_1","displayName":"admin_only","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users would not see a warning when downloading \"jnlp\" files from \"website1.com\", but see a download warning when downloading \"jnlp\" files from \"website2.com\".\n\nFiles with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\n\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.\n\nIf you enable this policy:\n\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list \"jnlp\" should be used instead of \".jnlp\".\n\nExample:\n\nThe following example value would prevent file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\n\n[\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\n]\n\nNote that while the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#exemptdomainfiletypepairsfromfiletypedownloadwarnings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service","description":"In Microsoft Edge, the Experimentation and Configuration Service is used to deploy Experimentation and Configuration payload.\n\nExperimentation payload consists of a list of early in development features that Microsoft is enabling for testing and feedback.\n\nConfiguration payload consists of a list of settings that Microsoft wants to deploy to Microsoft Edge to optimize user experience. For example, configuration payload may specify how often Microsoft Edge sends requests to the Experimentation and Configuration Service to retrieve the newest payload.\n\nIf you set this policy to \"Retrieve configurations and experiments\" mode, the full payload is downloaded from the Experimentation and Configuration Service. This includes both the experimentation and configuration payloads.\n\nIf you set this policy to \"Retrieve configurations only\" mode, only the configuration payload is delivered.\n\nIf you set this policy to \"Disable communication with the Experimentation and Configuration Service\" mode, the communication with the Experimentation and Configuration Service is stopped completely.\n\nIf you don't configure this policy, on a managed device on Stable and Beta channels the behavior is the same as the \"Retrieve configurations only\" mode.\n\nIf you don't configure this policy, on an unmanaged device the behavior is the same as the \"Retrieve configurations and experiments\" mode.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#experimentationandconfigurationservicecontrol"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_experimentationandconfigurationservicecontrol_0","displayName":"Retrieve configurations and experiments","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_experimentationandconfigurationservicecontrol_1","displayName":"Retrieve configurations only","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_experimentationandconfigurationservicecontrol_2","displayName":"Disable communication with the Experimentation and Configuration Service","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_explicitlyallowednetworkports","displayName":"Explicitly allowed network ports","description":"There is a list of restricted ports built into Microsoft Edge. Connections to these ports will fail. This policy allows bypassing that list. The set of ports is defined as a comma-separated list that outgoing connections should be permitted on.\n\nPorts are restricted to prevent Microsoft Edge from being used as a vector to exploit various network vulnerabilities. Setting this policy may expose your network to attacks. This policy is intended as a temporary workaround for error code \"ERR_UNSAFE_PORT\" while migrating a service running on a blocked port to a standard port (for example port 80 or 443).\n\nMalicious websites can easily detect that this policy is set, and for which ports, then use that information to target attacks.\n\nEach port listed in this policy is labeled with a date that it can be unblocked until. After that date the port will be restricted regardless of if it's specified by the value of this policy.\n\nLeaving the value empty or unset means that all restricted ports will be blocked. Invalid port values set through this policy will be ignored while valid ones will still be applied.\n\nThis policy overrides the \"--explicitly-allowed-ports\" command-line option.\n\nPolicy options mapping:\n\n* 554 (554) = port 554 (can be unblocked until 2021/10/15)\n\n* 10080 (10080) = port 10080 (can be unblocked until 2022/04/01)\n\n* 6566 (6566) = port 6566 (can be unblocked until 2021/10/15)\n\n* 989 (989) = port 989 (can be unblocked until 2022/02/01)\n\n* 990 (990) = port 990 (can be unblocked until 2022/02/01)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#explicitlyallowednetworkports"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extendedlogging","displayName":"Enable extended logging","description":"Write verbose logging events to /Library/Logs/Microsoft/autoupdate.log","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_extendedlogging_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extendedlogging_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_extensionallowedtypes","displayName":"Configure allowed extension types","description":"Controls which extension types can be installed and limits runtime access.\n\nThis setting defines the allowed types of extensions and which hosts they can interact with. The value is a list of strings, each of which should be one of the following: \"extension\", \"theme\", \"user_script\", and \"hosted_app\". See the Microsoft Edge extensions documentation for more information on these types.\n\nNote that this policy also affects extensions to be force-installed by using \"ExtensionInstallForcelist\" policy.\n\nIf you enable this policy, only extensions that match a type in the list are installed.\n\nIf you don't configure this policy, no restrictions on the acceptable extension types are enforced.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensionallowedtypes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page","description":"Control if users can turn on Developer Mode on edge://extensions.\n\nIf the policy isn't set, users can turn on developer mode on the extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\nIf the policy is set to Allow (0), users can turn on developer mode on the extensions page.\nIf the policy is set to Disallow (1), users cannot turn on developer mode on the extensions page.\n\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.\n\nPolicy options mapping:\n\n* Allow (0) = Allow the usage of developer mode on extensions page\n\n* Disallow (1) = Do not allow the usage of developer mode on extensions page\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensiondevelopermodesettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_extensiondevelopermodesettings_0","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extensiondevelopermodesettings_1","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant an extended background lifetime to connecting extensions.","description":"Extensions that connect to one of these origins will keep running as long as the port is connected.\nIf unset, the policy's default values are used. These are the app origins that offer SDKs that are known to not offer the possibility to restart a closed connection to a previous state:\n- Smart Card Connector\n- Citrix Receiver (stable, beta, back-up)\n- VMware Horizon (stable, beta)\n\nIf set, the default value list is extended with the newly configured values. The defaults and policy-provided entries will grant the exception to the connecting extensions, as long as the port is connected.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensionextendedbackgroundlifetimeforportconnectionstourls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensioninstallallowlist","displayName":"Allow specific extensions to be installed","description":"By default, all extensions are allowed. However, if you block all extensions by setting the 'ExtensionInstallBlockList' policy to \"*,\" users can only install extensions defined in this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensioninstallblocklist","displayName":"Control which extensions cannot be installed","description":"List specific extensions that users can NOT install in Microsoft Edge. When you deploy this policy, any extensions on this list that were previously installed will be disabled, and the user won't be able to enable them. If you remove an item from the list of blocked extensions, that extension is automatically re-enabled anywhere it was previously installed.\n\nUse \"*\" to block all extensions that aren't explicitly listed in the allow list.\n\nIf you don't configure this policy, users can install any extension in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensioninstallforcelist","displayName":"Control which extensions are installed silently","description":"Specifies extensions that are installed silently, without user interaction, and that the users can't uninstall or disable (\"force-installed\"). All permissions requested by the extensions are granted implicitly, without user interaction, including any additional permissions requested by future versions of the extension. Furthermore, permissions are granted for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These two APIs are only available to extensions that are force-installed.)\n\nThis policy takes precedence over a potentially conflicting \"ExtensionInstallBlocklist\" policy. When you take an extension off of the force-installed list it's automatically uninstalled by Microsoft Edge.\n\nFor Windows devices that aren't joined to a Microsoft Active Directory domain, forced installation is limited to extensions available in the Microsoft Store.\n\nNote that users can modify the source code of any extension by using Developer Tools, potentially rendering the extension dysfunctional. If this is a concern, set the \"DeveloperToolsAvailability\" policy.\n\nUse the following format to add an extension to the list:\n\n[extensionID];[updateURL]\n\n- extensionID - the 32-letter string found on edge://extensions when in developer mode.\n\n- updateURL (optional) is the address of the Update Manifest XML document for the app or extension, as described at https://go.microsoft.com/fwlink/?linkid=2095043. If you don't set the updateURL, the Microsoft Store update URL is used (currently https://edge.microsoft.com/extensionwebstorebase/v1/crx). Note that the update URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL indicated in the extension's manifest.\n\nFor example, gggmmkjegpiggikcnhidnjjhmicpibll;https://edge.microsoft.com/extensionwebstorebase/v1/crx installs the Microsoft Online app from the Microsoft Store \"update\" URL. For more information about hosting extensions, see: https://go.microsoft.com/fwlink/?linkid=2095044.\n\nIf you don't configure this policy, no extensions are installed automatically, and users can uninstall any extension in Microsoft Edge.\n\nNote that this policy doesn't apply to InPrivate mode.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallforcelist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensioninstallsources","displayName":"Configure extension and user script install sources","description":"Define URLs that can install extensions and themes.\n\nBy default, users have to download a *.crx file for each extension or script they want to install, and then drag it onto the Microsoft Edge settings page. This policy lets specific URLs use install the extension or script for the user.\n\nEach item in this list is an extension-style match pattern (see https://go.microsoft.com/fwlink/?linkid=2095039). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (in other words, the referrer) must be allowed by these patterns.\n\nThe \"ExtensionInstallBlocklist\" policy takes precedence over this policy. Any extensions that's on the block list won't be installed, even if it comes from a site on this list.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallsources"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensioninstalltypeblocklist","displayName":"Blocklist for extension install types","description":"The blocklist controls which extension install types are disallowed.\n\nSetting the \"command_line\" will block an extension from being loaded from command line.\n\nPolicy options mapping:\n\n* command_line (command_line) = Blocks extensions from being loaded from command line\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstalltypeblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability","description":"Control if Manifest v2 extensions can be used by browser.\n\nManifest v2 extensions support will be deprecated and all extensions need to be migrated to v3 in the future. More information about, and the timeline of the migration has not been established.\n\nIf the policy is set to Default or not set, v2 extension loading is decided by browser. This will follow the preceding timeline when it's established.\n\nIf the policy is set to Disable, v2 extensions installation are blocked, and existing ones are disabled. This option is going to be treated the same as if the policy is unset after v2 support is turned off by default.\n\nIf the policy is set to Enable, v2 extensions are allowed. The option is going to be treated the same as if the policy isn't set before v2 support is turned off by default.\n\nIf the policy is set to EnableForForcedExtensions, force installed v2 extensions are allowed. This includes extensions that are listed by \"ExtensionInstallForcelist\" or \"ExtensionSettings\" with installation_mode \"force_installed\" or \"normal_installed\". All other v2 extensions are disabled. The option is always available regardless of the manifest migration state.\n\nExtensions availabilities are still controlled by other policies.\n\nPolicy options mapping:\n\n* Default (0) = Default browser behavior\n\n* Disable (1) = Manifest v2 is disabled\n\n* Enable (2) = Manifest v2 is enabled\n\n* EnableForForcedExtensions (3) = Manifest v2 is enabled for forced extensions only\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensionmanifestv2availability"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_extensionmanifestv2availability_0","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extensionmanifestv2availability_1","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extensionmanifestv2availability_2","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extensionmanifestv2availability_3","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_extensionsperformancedetectorenabled","displayName":"Extensions Performance Detector enabled","description":"This policy controls if users can access the Extensions Performance Detector Recommended Action feature in Browser Essentials. This feature alerts extension users if their extensions are causing performance regressions in the browser and allows them to take action to resolve the issue.\n\nIf you enable or don't configure this policy, users will receive Extensions Performance Detector notifications from Browser Essentials. When there is an active alert, users will be able to view the impact of extensions on their browser's performance and make an informed decision to disable impacting extensions. The detector will exclude browser-managed extensions, such as Google Docs offline, component extensions, and organization-managed extensions (ie. extensions that cannot be disabled).\n\nIf you disable this policy, users will not receive notifications or be able to view the Extensions Performance Detector Recommended Action.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensionsperformancedetectorenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_extensionsperformancedetectorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extensionsperformancedetectorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_externalprotocoldialogshowalwaysopencheckbox","displayName":"Show an \"Always open\" checkbox in external protocol dialog","description":"This policy controls whether the \"Always open\" checkbox is shown on external protocol launch confirmation prompts.\n\nIf you set this policy to True, when an external protocol confirmation prompt is shown, the user can select \"Always open\". The user won’t get any future confirmation prompts for this protocol.\n\nIf you set this policy to False, or the policy is unset, the \"Always open\" checkbox isn’t displayed. The user will be prompted for confirmation every time an external protocol is invoked.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#externalprotocoldialogshowalwaysopencheckbox"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_externalprotocoldialogshowalwaysopencheckbox_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_externalprotocoldialogshowalwaysopencheckbox_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_familysafetysettingsenabled","displayName":"Allow users to configure Family safety","description":"This policy disables and completely hides the Family safety page in Settings. Navigation to edge://settings/familysafety will also be blocked. The Family safety page describes what features are available for family groups and how to join a family group. Learn more about family safety here: (https://go.microsoft.com/fwlink/?linkid=2098432).\n\nIf you enable this policy or don't configure it, the Family safety page will be shown.\n\nIf you disable this policy, the Family safety page will not be shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#familysafetysettingsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_familysafetysettingsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_familysafetysettingsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_favoritesbarenabled","displayName":"Enable favorites bar","description":"Enables or disables the favorites bar.\n\nIf you enable this policy, users will see the favorites bar.\n\nIf you disable this policy, users won't see the favorites bar.\n\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#favoritesbarenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_favoritesbarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_favoritesbarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_featureflagoverridescontrol","displayName":"Configure users ability to override feature flags","description":"Configures users ability to override state of feature flags.\nIf you set this policy to 'CommandLineOverridesEnabled', users can override state of feature flags using command line arguments but not edge://flags page.\n\nIf you set this policy to 'OverridesEnabled', users can override state of feature flags using command line arguments or edge://flags page.\n\nIf you set this policy to 'OverridesDisabled', users can't override state of feature flags using command line arguments or edge://flags page.\n\nIf you don't configure this policy, the behavior is the same as the 'OverridesEnabled'.\n\nPolicy options mapping:\n\n* CommandLineOverridesEnabled (2) = Allow users to override feature flags using command line arguments only\n\n* OverridesEnabled (1) = Allow users to override feature flags\n\n* OverridesDisabled (0) = Prevent users from overriding feature flags\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#featureflagoverridescontrol"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_featureflagoverridescontrol_0","displayName":"Prevent users from overriding feature flags","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_featureflagoverridescontrol_1","displayName":"Allow users to override feature flags","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_featureflagoverridescontrol_2","displayName":"Allow users to override feature flags using command line arguments only","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on shutdown","description":"Controls the duration (in seconds) that keepalive requests are allowed to prevent the browser from completing its shutdown.\n\nIf you configure this policy, the browser will block completing shutdown while it processes any outstanding keepalive requests (see https://fetch.spec.whatwg.org/#request-keepalive-flag) up to the maximum period of time specified by this policy.\n\nIf you disable or don't configure this policy, the default value of 0 seconds is used and outstanding keepalive requests will be immediately cancelled during browser shutdown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#fetchkeepalivedurationsecondsonshutdown"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_fileordirectorypickerwithoutgestureallowedfororigins","displayName":"Allow file or directory picker APIs to be called without prior user gesture","description":"For security reasons, the showOpenFilePicker(), showSaveFilePicker() and showDirectoryPicker() web APIs require a prior user gesture (\"transient activation\") to be called or will otherwise fail.\n\nIf you enable this policy, admins can specify origins on which these APIs can be called without prior user gesture.\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\n\nIf you disable or don't configure this policy, all origins will require a prior user gesture to call these APIs.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#fileordirectorypickerwithoutgestureallowedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_filesondemandenabled","displayName":"Enable Files On-Demand","description":"Specifies whether Files On-Demand is enabled. When set to true, new users who set up the sync app will download online-only files by default. When set to false, Files On-Demand will be disabled and users won't be able to turn it on. NOTE: This setting only applies to macOS Monterey 12.1 and earlier.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#filesondemandenabled"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_filesondemandenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_filesondemandenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_filesystemreadaskforurls","displayName":"Allow read access via the File System API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\n\nLeaving the policy unset means \"DefaultFileSystemReadGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemReadBlockedForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#filesystemreadaskforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_filesystemreadblockedforurls","displayName":"Block read access via the File System API on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\n\nIf you don't set this policy, \"DefaultFileSystemReadGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemReadAskForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#filesystemreadblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_filesystemwriteaskforurls","displayName":"Allow write access to files and directories on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system.\n\nIf you don't set this policy, \"DefaultFileSystemWriteGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemWriteBlockedForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#filesystemwriteaskforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_filesystemwriteblockedforurls","displayName":"Block write access to files and directories on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system.\n\nIf you don't set this policy, \"DefaultFileSystemWriteGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemWriteAskForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#filesystemwriteblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_forcebingsafesearch","displayName":"Enforce Bing SafeSearch","description":"Ensure that queries in Bing web search are done with SafeSearch set to the value specified. Users can't change this setting.\n\nIf you configure this policy to \"Off\", SafeSearch in Bing search falls back to the bing.com value.\n\nIf you configure this policy to \"Moderate\", the moderate setting is used in SafeSearch. The moderate setting filters adult videos and images but not text from search results.\n\nIf you configure this policy to \"Strict\", the strict setting in SafeSearch is used. The strict setting filters adult text, images, and videos.\n\nIf you disable this policy or don't configure it, SafeSearch in Bing search isn't enforced, and users can set the value they want on bing.com.\n\n* 0 = Don't configure search restrictions in Bing\n\n* 1 = Configure moderate search restrictions in Bing\n\n* 2 = Configure strict search restrictions in Bing","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcebingsafesearch"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcebingsafesearch_0","displayName":"Don't configure search restrictions in Bing","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcebingsafesearch_1","displayName":"Configure moderate search restrictions in Bing","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcebingsafesearch_2","displayName":"Configure strict search restrictions in Bing","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forcecertificatepromptsonmultiplematches","displayName":"Configure whether Microsoft Edge should automatically select a certificate when there are multiple certificate matches for a site configured with \"AutoSelectCertificateForUrls\"","description":"Toggles whether users are prompted to select a certificate if there are multiple certificates available and a site is configured with \"AutoSelectCertificateForUrls\". If you don't configure \"AutoSelectCertificateForUrls\" for a site, the user will always be prompted to select a certificate.\n\nIf you set this policy to True, Microsoft Edge will prompt a user to select a certificate for sites on the list defined in \"AutoSelectCertificateForUrls\" if and only if there is more than one certificate.\n\nIf you set this policy to False or don't configure it, Microsoft Edge will automatically select a certificate even if there are multiple matches for a certificate. The user will not be prompted to select a certificate for sites on the list defined in \"AutoSelectCertificateForUrls\".","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcecertificatepromptsonmultiplematches"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcecertificatepromptsonmultiplematches_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcecertificatepromptsonmultiplematches_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forceephemeralprofiles","displayName":"Enable use of ephemeral profiles","description":"Controls whether user profiles are switched to ephemeral mode. An ephemeral profile is created when a session begins, is deleted when the session ends, and is associated with the user's original profile.\n\nIf you enable this policy, profiles run in ephemeral mode. This lets users work from their own devices without saving browsing data to those devices. If you enable this policy as an OS policy (by using GPO on Windows, for example), it applies to every profile on the system.\n\nIf you disable this policy or don't configure it, users get their regular profiles when they sign in to the browser.\n\nIn ephemeral mode, profile data is saved on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies, and web databases aren't saved after the browser is closed. This doesn't prevent a user from manually downloading any data to disk, or from saving pages or printing them. If the user has enabled sync, all data is preserved in their sync accounts just like with regular profiles. Users can also use InPrivate browsing in ephemeral mode unless you explicitly disable this.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forceephemeralprofiles"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forceephemeralprofiles_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forceephemeralprofiles_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forcegooglesafesearch","displayName":"Enforce Google SafeSearch","description":"Forces queries in Google Web Search to be performed with SafeSearch set to active, and prevents users from changing this setting.\n\nIf you enable this policy, SafeSearch in Google Search is always active.\n\nIf you disable this policy or don't configure it, SafeSearch in Google Search isn't enforced.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcegooglesafesearch"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcegooglesafesearch_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcegooglesafesearch_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forcelegacydefaultreferrerpolicy","displayName":"Use a default referrer policy of no-referrer-when-downgrade.","description":"This enterprise policy is for short-term adaptation and will be removed in M82.\n\nMicrosoft Edge’s default referrer policy is being strengthened from its current value of no-referrer-when-downgrade to the more secure strict-origin-when-cross-origin through a gradual rollout targeting M80 stable.\n\nBefore the rollout, this enterprise policy will have no effect. After the rollout, when this enterprise policy is enabled, Microsoft Edge’s default referrer policy will be set to its pre-M80 value of no-referrer-when-downgrade.\n\nThis enterprise policy is disabled by default","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcelegacydefaultreferrerpolicy"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcelegacydefaultreferrerpolicy_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcelegacydefaultreferrerpolicy_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled.","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy.\nCurrently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers.\nThis enterprise policy can be used to opt out of this gradual deprecation by forcing the default to stay enabled.\n\nPages might depend on unload event handlers to save data or signal the end of a user session to the server.\nThis is not recommended because it's unreliable and impacts performance by blocking use of BackForwardCache.\nRecommended alternatives exist, but the unload event has been used for a long time. Some applications might still rely on them.\n\nIf you disable this policy or don't configure it, unload event handlers will gradually be deprecated in-line with the deprecation rollout and sites which don't set Permissions-Policy header will stop firing `unload` events.\n\nIf you enable this policy then unload event handlers will continue to work by default.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcepermissionpolicyunloaddefaultenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcepermissionpolicyunloaddefaultenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcepermissionpolicyunloaddefaultenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forcesync","displayName":"Force synchronization of browser data and do not show the sync consent prompt","description":"Forces data synchronization in Microsoft Edge. This policy also prevents the user from turning sync off.\n\nIf you don't configure this policy, users will be able to turn sync on or off. If you enable this policy, users will not be able to turn sync off.\n\nFor this policy to work as intended,\n\"BrowserSignin\" policy must not be configured, or must be set to enabled. If \"BrowserSignin\" is set to disabled, then \"ForceSync\" will not take affect.\n\n\"SyncDisabled\" must not be configured or must be set to False. If this is set to True, \"ForceSync\" will not take affect.\n\n0 = Do not automatically start sync and show the sync consent (default)\n1 = Force sync to be turned on for Azure AD/Azure AD-Degraded user profile and do not show the sync consent prompt","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcesync"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcesync_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcesync_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_forcesynctypes","displayName":"Configure the list of types that are included for synchronization","description":"If you enable this policy all the specified data types will be included for synchronization for Azure AD/Azure AD-Degraded user profiles. This policy can be used to ensure the type of data uploaded to the Microsoft Edge synchronization service.\n\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", \"history\", \"openTabs\", \"edgeWallet\", \"collections\", \"apps\", and \"edgeFeatureUsage\". The \"edgeFeatureUsage\" data type will be supported starting in Microsoft Edge version 134. Note that these data type names are case sensitive.\n\nUsers will not be able to override the enabled data types.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcesynctypes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode","description":"Enforces a minimum Restricted Mode on YouTube and prevents users from picking a less restricted mode.\n\nSet to Strict (2) to enforce Strict Restricted Mode on YouTube.\n\nSet to Moderate (1) to enforce the user to only use Moderate Restricted Mode and Strict Restricted Mode on YouTube. They can't disable Restricted Mode.\n\nSet to Off (0) or don't configure this policy to not enforce Restricted Mode on YouTube. External policies such as YouTube policies might still enforce Restricted Mode.\n\n* 0 = Do not enforce Restricted Mode on YouTube\n\n* 1 = Enforce at least Moderate Restricted Mode on YouTube\n\n* 2 = Enforce Strict Restricted Mode for YouTube","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forceyoutuberestrict"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forceyoutuberestrict_0","displayName":"Do not enforce Restricted Mode on YouTube","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forceyoutuberestrict_1","displayName":"Enforce at least Moderate Restricted Mode on YouTube","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forceyoutuberestrict_2","displayName":"Enforce Strict Restricted Mode for YouTube","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_genailocalfoundationalmodelsettings","displayName":"Settings for GenAI local foundational model","description":"This policy controls whether Microsoft Edge downloads the foundational GenAI model and uses it for local inference.\n\nIf you enable this policy and set the value to Allowed (0), the model is downloaded automatically and used for inference.\n\nIf you enable this policy and set the value to Disallowed (1), the model is not downloaded.\n\nIf you disable or don't configure this policy, the default applies, and the model is downloaded automatically and used for inference.\n\nNote: This policy supports dynamic refresh, so changes take effect without requiring a browser restart.\n\nModel downloading can also be disabled by ComponentUpdatesEnabled.\n\nPolicy options mapping:\n\n* Allowed (0) = Downloads model automatically\n\n* Disallowed (1) = Do not download model\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#genailocalfoundationalmodelsettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_genailocalfoundationalmodelsettings_0","displayName":"Downloads model automatically","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_genailocalfoundationalmodelsettings_1","displayName":"Do not download model","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_geolocationblockedforurls","displayName":"Block geolocation on these sites","description":"Use this policy to define a list of URL patterns for sites that are blocked from accessing the user's geolocation. These sites also can't prompt the user for location permissions.\n\nIf you enable this policy, the list you provide determines which sites are blocked from requesting or accessing geolocation.\n\nIf you disable or don't configure this policy, DefaultGeolocationSetting applies to all sites, if configured. If it's not configured, the user’s personal browser setting is used.\n\nFor detailed information on valid url patterns, see the documentation on pattern formats: https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#geolocationblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\n\nIf you disable or don’t set this policy, the browser will use the default behavior of cross-site auth, which as of version 80, will be to scope HTTP server authentication credentials by top-level site. So, if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites.\n\nIf you enable this policy HTTP auth credentials entered in the context of one site will automatically be used in the context of another site.\n\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\n\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures and will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#globallyscopehttpauthcacheenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_globallyscopehttpauthcacheenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_globallyscopehttpauthcacheenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_gotointranetsiteforsinglewordentryinaddressbar","displayName":"Force direct intranet site navigation instead of searching on single word entries in the Address Bar","description":"If you enable this policy, the top auto-suggest result in the address bar suggestion list will navigate to intranet sites if the text entered in the address bar is a single word without punctuation.\n\nDefault navigation when typing a single word without punctuation will conduct a navigation to an intranet site matching the entered text.\n\nIf you enable this policy, the second auto-suggest result in the address bar suggestion list will conduct a web search exactly as it was entered, provided that this text is a single word without punctuation. The default search provider will be used unless a policy to prevent web search is also enabled.\n\nTwo effects of enabling this policy are:\n\nNavigation to sites in response to single word queries that would typically resolve to a history item will no longer happen. Instead, the browser will attempt navigate to internal sites that may not exist in an organization’s intranet. This will result in a 404 error.\n\nPopular, single-word search terms will require manual selection of search suggestions to properly conduct a search.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#gotointranetsiteforsinglewordentryinaddressbar"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_gotointranetsiteforsinglewordentryinaddressbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_gotointranetsiteforsinglewordentryinaddressbar_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_groupids","displayName":"Group identifier","description":"","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#group-identifiers"],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":null},{"id":"com.apple.managedclient.preferences_guardagainstappmodification","displayName":"Guard against app modification","description":"Retain and reuse app clones after the update cycle. This allows for future delta updates even when the source app has been modified by a third-party tool.","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_guardagainstappmodification_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_guardagainstappmodification_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_guidedswitchenabled","displayName":"Guided Switch Enabled","description":"Allows Microsoft Edge to prompt the user to switch to the appropriate profile when Microsoft Edge detects that a link is a personal or work link.\n\nIf you enable this policy, you'll be prompted to switch to another account if the current profile doesn't work for the requesting link.\n\nIf you disable this policy, you won't be prompted to switch to another account when there's a profile and link mismatch.\n\nIf this policy isn't configured, guided switch is turned on by default. A user can override this value in the browser settings.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#guidedswitchenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_guidedswitchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_guidedswitchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_happyeyeballsv3enabled","displayName":"Use the Happy Eyeballs V3 algorithm for connection attempts","description":"Controls whether Microsoft Edge uses the Happy Eyeballs V3 algorithm to optimize connection attempts. This algorithm improves reliability and performance in dual-stack (IPv4/IPv6) networks by racing connection attempts across IP versions and HTTP protocols (e.g., HTTP/3 vs. others). For more details, see https://datatracker.ietf.org/doc/draft-pauly-happy-happyeyeballs-v3.\n\nEnabled: Uses the algorithm for connection attempts.\n\nDisabled or not configured: Disables the algorithm.\n\nNote: This policy supports dynamic refresh.\n\nImportant: This policy is temporary and will be removed in a future version.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#happyeyeballsv3enabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_happyeyeballsv3enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_happyeyeballsv3enabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hardwareaccelerationmodeenabled","displayName":"Use hardware acceleration when available","description":"Specify to use hardware acceleration, if it's available. If you enable this policy or don't configure it, hardware acceleration is enabled unless a GPU feature is explicitly blocked.\n\nIf you disable this policy, hardware acceleration is disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#hardwareaccelerationmodeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_hardwareaccelerationmodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hardwareaccelerationmodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_headlessmodeenabled","displayName":"Control use of the Headless Mode","description":"This policy setting lets you decide whether users can launch Microsoft Edge in headless mode.\n\nIf you enable or don't configure this policy, Microsoft Edge allows use of the headless mode.\n\nIf you disable this policy, Microsoft Edge denies use of the headless mode.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#headlessmodeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_headlessmodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_headlessmodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hidedockicon","displayName":"Hide dock icon","description":"Specifies whether the dock icon for OneDrive is hidden.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#hidedockicon"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_hidedockicon_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hidedockicon_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hidefirstrunexperience","displayName":"Hide the First-run experience and splash screen","description":"If you enable this policy, the First-run experience and the splash screen will not be shown to users when they run Microsoft Edge for the first time.\n\nFor the configuration options shown in the First Run Experience, the browser will default to the following:\n\n-On the New Tab Page, the feed type will be set to MSN News and the layout to Inspirational.\n\n-The user will still be automatically signed into Microsoft Edge if the Windows account is of AAD or MSA type.\n\n-Sync will not be enabled by default and users will be able to turn on sync from the sync settings.\n\nIf you disable or don't configure this policy, the First-run experience and the Splash screen will be shown.\n\nNote: The specific configuration options shown to the user in the First Run Experience, can also be managed by using other specific policies. You can use the HideFirstRunExperience policy in combination with these policies to configure a specific browser experience on your managed devices. Some of these other policies are:\n\n-\"AutoImportAtFirstRun\"\n\n-\"NewTabPageLocation\"\n\n-\"NewTabPageSetFeedType\"\n\n-\"SyncDisabled\"\n\n-\"BrowserSignin\"\n\n-\"NonRemovableProfileEnabled\"","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#hidefirstrunexperience"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_hidefirstrunexperience_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hidefirstrunexperience_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hidefoldersonmycomputerrootinfolderlist","displayName":"Hide On My Computer folders","description":"Disable local folder storage.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#hide-local-folders"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_hidefoldersonmycomputerrootinfolderlist_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hidefoldersonmycomputerrootinfolderlist_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hidestatusmenuicon","displayName":"Show / hide status menu icon","description":"Whether the status menu icon (shown in the top-right corner of the screen) is hidden or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#show--hide-status-menu-icon"],"categoryId":"67cd904c-78e0-4e77-9dd4-c713b21763f3","categoryName":"User interface preferences","options":[{"id":"com.apple.managedclient.preferences_hidestatusmenuicon_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hidestatusmenuicon_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_homepageisnewtabpage","displayName":"Set the new tab page as the home page","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\n\nIf you enable this policy, the new tab page is always used for the home page, and the home page URL location is ignored.\n\nIf you disable this policy, the user's home page can't be the new tab page, unless the URL is set to 'edge://newtab'.\n\nIf not configured users can choose whether the new tab page is their home page.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#homepageisnewtabpage"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_homepageisnewtabpage_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_homepageisnewtabpage_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_homepagelocation","displayName":"Configure the home page URL","description":"Configures the default home page URL in Microsoft Edge.\n\nThe home page is the page opened by the Home button. The pages that open on startup are controlled by the \"RestoreOnStartup\" policies.\n\nYou can either set a URL here or set the home page to open the new tab page. If you select to open the new tab page, then this policy doesn't take effect.\n\nIf you enable this policy, users can't change their home page URL, but they can choose to use the new tab page as their home page.\n\nIf you disable or don't configure this policy, users can choose their own home page, as long as the \"HomepageIsNewTabPage\" policy isn't enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#homepagelocation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_howtocheck","displayName":"Enable AutoUpdate","description":"Specifies whether AutoUpdate should download and install updates. This value should be true unless you need to temporarily halt all updates.","helpText":null,"infoUrls":["https://support.microsoft.com/office/update-office-for-mac-automatically-bfd1e497-c24d-4754-92ab-910a4074d7c1"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_howtocheck_0","displayName":"True","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_howtocheck_1","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_howtocheck_2","displayName":"Manual Check","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hstspolicybypasslist","displayName":"Configure the list of names that will bypass the HSTS policy check","description":"Hostnames specified in this list will be exempt from the HSTS policy check that could potentially upgrade requests from \"http://\" to \"https://\". Only single-label hostnames are allowed in this policy. Hostnames must be canonicalized. Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific hostnames specified; it doesn't apply to subdomains of the names in the list.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#hstspolicybypasslist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_httpallowlist","displayName":"HTTP Allowlist","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that won't be upgraded to HTTPS. Organizations can use this policy to maintain access to servers that don't support HTTPS, without needing to disable \"HttpsUpgradesEnabled\".\n\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase.\n\nBlanket host wildcards (that is, \"*\" or \"[*]\") aren't allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies.\n\nNote: This policy doesn't apply to HSTS upgrades.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#httpallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled","description":"This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigations to HTTPS.\n\nIf this setting isn't set or is set to allowed, users are able to enable HTTPS-Only Mode.\nIf this setting is set to `disallowed`, users can't enable HTTPS-Only Mode.\nIf this setting is set to force_enabled, HTTPS-Only Mode is enabled in Strict mode and users can't disable it.\nIf this setting is set to force_balanced_enabled, HTTPS-Only Mode is enabled in Balanced mode and users can't disable it.\n\nIf you set this policy to a value that isn't supported by the version of Microsoft Edge that receives the policy, Microsoft Edge defaults to the allowed setting.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nPolicy options mapping:\n\n* allowed (allowed) = Don't restrict users' HTTPS-Only Mode setting\n\n* disallowed (disallowed) = Don't allow users to enable any HTTPS-Only Mode\n\n* force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode\n\n* force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#httpsonlymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_httpsonlymode_0","displayName":"Don't restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_httpsonlymode_1","displayName":"Don't allow users to enable any HTTPS-Only Mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_httpsonlymode_2","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_httpsonlymode_3","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_httpsupgradesenabled","displayName":"Enable automatic HTTPS upgrades","description":"As of Microsoft Edge version 120, Microsoft Edge tries to upgrade HTTP navigations to HTTPS whenever possible to improve security. Navigations to captive portals, IP addresses, and non-unique hostnames are excluded from automatic upgrades.\n\nIf this policy is enabled or not configured, automatic HTTPS upgrades are turned on by default.\n\nIf this policy is disabled, Microsoft Edge won't attempt to upgrade HTTP connections to HTTPS.\n\nTo exempt specific hostnames or hostname patterns from being upgraded, use the HttpAllowlist policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#httpsupgradesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_httpsupgradesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_httpsupgradesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_hubssidebarenabled","displayName":"Show Hubs Sidebar","description":"The Sidebar is a launcher bar located on the right side of Microsoft Edge.\n\nIf you enable this policy, the Sidebar is always visible.\n\nIf you disable this policy, the Sidebar is never shown.\n\nIf you don't configure this policy, the Sidebar's visibility follows the user's Microsoft Edge settings.\n\nAs of Microsoft Edge version 141, the \"Microsoft365CopilotChatIconEnabled\" policy is the only means of controlling the display of Copilot in the toolbar.\n\nNote: The recommended version of this policy-also known as the \"Default Settings (users can override)\" policy-is obsolete. This policy has never supported the recommended capability.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#hubssidebarenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_hubssidebarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hubssidebarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_idletimeout","displayName":"Delay before running idle actions","description":"Triggers an action when the computer is idle.\n\nIf you set this policy, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy.\n\nIf you do not set this policy, no action will run.\n\nThe minimum threshold is 1 minute.\n\n\"User input\" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#idletimeout"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_idletimeoutactions","displayName":"Actions to run when the computer is idle","description":"When the timeout from the IdleTimeout policy is reached, the browser runs the actions configured in this policy.\n\nIf you don't configure the IdleTimeout policy, this policy has no effect.\n\nIf you don't configure this policy or no actions are selected, the IdleTimeout policy has no effect.\n\nSupported actions are:\n\n'close_browsers': close all browser windows and PWAs for this profile.\n\n'reload_pages': reload all webpages. For some pages, the user might be prompted for confirmation first.\n\n'sign_out': sign out of browser. (This action only applies to iOS.)\n\n'close_tabs': close all open tabs and create an NTP (New Tab Page). Supported in Android and iOS.\n\n'clear_browsing_history', 'clear_download_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', 'clear_autofill', 'clear_site_settings': clear the corresponding browsing data. Deleting cookies using this policy doesn't sign the user out of their profile, the user stays signed in.\n\nSetting 'clear_browsing_history', 'clear_password_signing', 'clear_autofill', and 'clear_site_settings' disables sync for the respective data types if sync isn't already disabled by setting either the SyncDisabled policy or BrowserSignin to disabled.\n\nPolicy options mapping:\n\n* close_browsers (close_browsers) = Close Browsers\n\n* clear_browsing_history (clear_browsing_history) = Clear Browsing History\n\n* clear_download_history (clear_download_history) = Clear Download History\n\n* clear_cookies_and_other_site_data (clear_cookies_and_other_site_data) = Clear Cookies and Other Site Data\n\n* clear_cached_images_and_files (clear_cached_images_and_files) = Clear Cached Images and Files\n\n* clear_password_signin (clear_password_signin) = Clear Password sign in\n\n* clear_autofill (clear_autofill) = Clear Autofill\n\n* clear_site_settings (clear_site_settings) = Clear Site Settings\n\n* reload_pages (reload_pages) = Reload Pages\n\n* sign_out (sign_out) = Sign Out\n\n* close_tabs (close_tabs) = Close Tabs\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#idletimeoutactions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_ignoreexclusions","displayName":"Ignore exclusions","description":"Should exclusions be ignored during a scheduled scan","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":[{"id":"com.apple.managedclient.preferences_ignoreexclusions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_ignoreexclusions_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_imagesallowedforurls","displayName":"Allow images on these sites","description":"Define a list of sites, based on URL patterns, that can display images.\n\nIf you don't configure this policy, the global default value is used for all sites either from the \"DefaultImagesSetting\" policy (if set) or the user's personal configuration.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#imagesallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_imagesblockedforurls","displayName":"Block images on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to display images.\n\nIf you don't configure this policy, the global default value from the \"DefaultImagesSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#imagesblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_importautofillformdata","displayName":"Allow importing of autofill form data","description":"Allows users to import autofill form data from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import autofill data is automatically selected.\n\nIf you disable this policy, autofill form data isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge will import autofill data on first run, but users can select or clear **autofill data** option during manual import.\n\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importautofillformdata"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importautofillformdata_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importautofillformdata_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importbrowsersettings","displayName":"Allow importing of browser settings","description":"Allows users to import browser settings from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, browser settings aren't imported at first run, and users can’t import them manually.\n\nIf you don’t configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\n\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importbrowsersettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importbrowsersettings_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importbrowsersettings_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importcookies","displayName":"Allow importing of Cookies","description":"Allows users to import Cookies from another browser into Microsoft Edge.\n\nIf you disable this policy, Cookies aren't imported on first run.\n\nIf you don’t configure this policy, Cookies are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\n\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importcookies"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importcookies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importextensions","displayName":"Allow importing of extensions","description":"Allows users to import extensions from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **favorites** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importextensions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importextensions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importextensions_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importfavorites","displayName":"Allow importing of favorites","description":"Allows users to import favorites from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Favorites** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, favorites aren't imported at first run, and users can’t import them manually.\n\nIf you don’t configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS) and Apple Safari (on macOS) browsers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importfavorites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importfavorites_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importfavorites_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importhistory","displayName":"Allow importing of browsing history","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Browsing history** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, browsing history data isn't imported at first run, and users can’t import this data manually.\n\nIf you don’t configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS) and Apple Safari (macOS) browsers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importhistory"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importhistory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importhistory_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importhomepage","displayName":"Allow importing of home page settings","description":"Allows users to import their home page setting from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import the home page setting is automatically selected.\n\nIf you disable this policy, the home page setting isn’t imported at first run, and users can’t import it manually.\n\nIf you don’t configure this policy, the home page setting is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports the home page setting on first run, but users can select or clear the **home page** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importhomepage"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importhomepage_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importhomepage_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importopentabs","displayName":"Allow importing of open tabs","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importopentabs"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importopentabs_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importopentabs_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importpaymentinfo","displayName":"Allow importing of payment info","description":"Allows users to import payment info from another browser into Microsoft Edge.\n\nIf you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, payment info isn’t imported at first run, and users can’t import it manually.\n\nIf you don’t configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import.\n\n**Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importpaymentinfo"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importpaymentinfo_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importpaymentinfo_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importsavedpasswords","displayName":"Allow importing of saved passwords","description":"Allows users to import saved passwords from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import saved passwords is automatically selected.\n\nIf you disable this policy, saved passwords aren't imported on first run, and users can't import them manually.\n\nIf you don't configure this policy, passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10) and Google Chrome (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importsavedpasswords"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importsavedpasswords_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importsavedpasswords_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importsearchengine","displayName":"Allow importing of search engine settings","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\n\nIf you enable, this policy, the option to import search engine settings is automatically selected.\n\nIf you disable this policy, search engine settings aren't imported at first run, and users can’t import them manually.\n\nIf you don’t configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importsearchengine"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importsearchengine_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importsearchengine_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_importshortcuts","displayName":"Allow importing of shortcuts","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\n\nIf you disable this policy, Shortcuts aren't imported on first run.\n\nIf you don’t configure this policy, Shortcuts are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\n\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importshortcuts"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importshortcuts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importshortcuts_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_inappsupportenabled","displayName":"In-app support Enabled","description":"Microsoft Edge uses the in-app support feature (enabled by default) to allow users to contact our support agents directly from the browser. Also, by default, users can't disable (turn off) the in-app support feature.\n\nIf you enable this policy or don't configure it, users can invoke in-app support.\n\nIf you disable this policy, users can't invoke in-app support.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#inappsupportenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_inappsupportenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_inappsupportenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_inprivatemodeavailability","displayName":"Configure InPrivate mode availability","description":"Specifies whether the user can open pages in InPrivate mode in Microsoft Edge.\n\nIf you don't configure this policy or set it to 'Enabled' (0), users can open pages in InPrivate mode.\n\nSet this policy to 'Disable' (1) to stop users from using InPrivate mode.\n\nSet this policy to 'Forced' (2) to always use InPrivate mode.\n\n* 0 = InPrivate mode available\n\n* 1 = InPrivate mode disabled\n\n* 2 = InPrivate mode forced","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#inprivatemodeavailability"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_inprivatemodeavailability_0","displayName":"InPrivate mode available","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_inprivatemodeavailability_1","displayName":"InPrivate mode disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_inprivatemodeavailability_2","displayName":"InPrivate mode forced","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_insecurecontentallowedforurls","displayName":"Allow insecure content on specified sites","description":"Create a list of URL patterns to specify sites that can display insecure mixed content (that is, HTTP content on HTTPS sites).\n\nIf you don't configure this policy, blockable mixed content will be blocked and optionally blockable mixed content will be upgraded. However, users will be allowed to set exceptions to allow insecure mixed content for specific sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecurecontentallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_insecurecontentblockedforurls","displayName":"Block insecure content on specified sites","description":"Create a list of URL patterns to specify sites that aren't allowed to display blockable (i.e. active) mixed content (that is, HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled.\n\nIf you don't configure this policy, blockable mixed content will be blocked and optionally blockable mixed content will be upgraded. However, users will be allowed to set exceptions to allow insecure mixed content for specific sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecurecontentblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_insecureformswarningsenabled","displayName":"Enable warnings for insecure forms (deprecated)","description":"This policy controls the handling of insecure forms (forms submitted over HTTP) embedded in secure (HTTPS) sites in the browser.\nIf you enable this policy or don't set it, a full page warning will be shown when an insecure form is submitted. Additionally, a warning bubble will be shown next to the form fields when they are focused, and autofill will be disabled for those forms.\nIf you disable this policy, warnings will not be shown for insecure forms, and autofill will work normally.\n\nThis policy may be removed as soon as Edge 132. The feature is enabled by default since Edge 131.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecureformswarningsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_insecureformswarningsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_insecureformswarningsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_insecureprivatenetworkrequestsallowed","displayName":"Specifies whether to allow websites to make requests to any network endpoint in an insecure manner. (Deprecated)","description":"Controls whether websites are allowed to make requests to more-private network endpoints.\n\nWhen this policy is enabled, all Private Network Access checks are disabled for all origins. This may allow attackers to perform cross-site request forgery (CSRF) attacks on private network servers.\n\nWhen this policy is disabled or not configured, the default behavior for requests to more-private network endpoints will depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests, PrivateNetworkAccessSendPreflights, and PrivateNetworkAccessRespectPreflightResults feature flags. These flags may be controlled by experimentation or set via the command line.\n\nThis policy relates to the Private Network Access specification. See https://wicg.github.io/private-network-access/ for more details.\n\nA network endpoint is more private than another if:\n1) Its IP address is localhost and the other is not.\n2) Its IP address is private and the other is public.\nIn the future, depending on spec evolution, this policy might apply to all cross-origin requests directed at private IPs or localhost.\n\nWhen this policy enabled, websites are allowed to make requests to any network endpoint, subject to other cross-origin checks.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecureprivatenetworkrequestsallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_insecureprivatenetworkrequestsallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_insecureprivatenetworkrequestsallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from in an insecure manner (Deprecated)","description":"List of URL patterns. Requests initiated from websites served by matching origins are not subject to Private Network Access checks.\n\nIf this policy is not set, this policy behaves as if set to the empty list.\n\nFor origins not covered by the patterns specified here, the global default value will be used either from the \"InsecurePrivateNetworkRequestsAllowed\" policy, if it is set, or the user's personal configuration otherwise.\n\nFor detailed information on valid URL patterns, see [Filter format for URL list-based policies](/DeployEdge/edge-learnmmore-url-list-filter%20format).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecureprivatenetworkrequestsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_intensivewakeupthrottlingenabled","displayName":"Control the IntensiveWakeUpThrottling feature","description":"When enabled the IntensiveWakeUpThrottling feature causes Javascript timers in background tabs to be aggressively throttled and coalesced, running no more than once per minute after a page has been backgrounded for 5 minutes or more.\n\nThis is a web standards compliant feature, but it may break functionality on some websites by causing certain actions to be delayed by up to a minute. However, it results in significant CPU and battery savings when enabled. See https://bit.ly/30b1XR4 for more details.\n\nIf you enable this policy, the feature will be force enabled, and users will not be able to override this setting.\nIf you disable this policy, the feature will be force disabled, and users will not be able to override this setting.\nIf you don't configure this policy, the feature will be controlled by its own internal logic. Users can manually configure this setting.\n\nNote that the policy is applied per renderer process, with the most recent value of the policy setting in force when a renderer process starts. A full restart is required to ensure that all the loaded tabs receive a consistent policy setting. It is harmless for processes to be running with different values of this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#intensivewakeupthrottlingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_intensivewakeupthrottlingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intensivewakeupthrottlingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior","displayName":"Intranet Redirection Behavior","description":"This policy configures behavior for intranet redirection via DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\n\nIf this policy isn't configured, the browser will use the default behavior of DNS interception checks and intranet redirect suggestions. In M88, they are enabled by default but will be disabled by default in the future release.\n\n\"DNSInterceptionChecksEnabled\" is a related policy that might also disable DNS interception checks. However, this policy is a more flexible version which might separately control intranet redirection infobars and might be expanded in the future.\nIf either \"DNSInterceptionChecksEnabled\" or this policy make a request to disable interception checks, the checks will be disabled.\nIf DNS interception checks are disabled by this policy but \"GoToIntranetSiteForSingleWordEntryInAddressBar\" is enabled, single word queries will still result in intranet navigations.\n\nPolicy options mapping:\n\n* Default (0) = Use default browser behavior.\n\n* DisableInterceptionChecksDisableInfobar (1) = Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.\n\n* DisableInterceptionChecksEnableInfobar (2) = Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.\n\n* EnableInterceptionChecksEnableInfobar (3) = Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#intranetredirectbehavior"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_0","displayName":"Use default browser behavior.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_1","displayName":"Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_2","displayName":"Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_3","displayName":"Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_ipv6reachabilityoverrideenabled","displayName":"Enable IPv6 reachability check override","description":"This policy enables an override of the IPv6 reachability check. When overridden, the\nsystem will always query AAAA records when resolving host names. It applies to\nall users and interfaces on the device.\n\nIf you enable this policy, the IPv6 reachability check will be overridden.\n\nIf you disable or don't configure this policy, the IPv6 reachability check will not be overridden.\nThe system only queries AAAA records when it is reachable to a global IPv6 host.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#ipv6reachabilityoverrideenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_ipv6reachabilityoverrideenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_ipv6reachabilityoverrideenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_isolateorigins","displayName":"Enable site isolation for specific origins","description":"Specify origins to run in isolation, in their own process.\nThis policy also isolates origins named by subdomains - for example, specifying https://contoso.com/ will cause https://foo.contoso.com/ to be isolated as part of the https://contoso.com/ site.\nIf the policy is enabled, each of the named origins in a comma-separated list will run in its own process.\nIf you disable this policy, then both the 'IsolateOrigins' and 'SitePerProcess' features are disabled. Users can still enable 'IsolateOrigins' policy manually, via command line flags.\nIf you don't configure the policy, the user can change this setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#isolateorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_javascriptallowedforurls","displayName":"Allow JavaScript on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to run JavaScript.\n\nIf you don't configure this policy, the global default value from the \"DefaultJavaScriptSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_javascriptblockedforurls","displayName":"Block JavaScript on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to run JavaScript.\n\nIf you don't configure this policy, the global default value from the \"DefaultJavaScriptSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\n\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitAllowedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT enabled, but fabrikam.com will use the policy from \"DefaultJavaScriptJitSetting\", if set, or default to JavaScript JIT enabled.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptJitSetting\" applies to the site, if set, otherwise Javascript JIT is enabled for the site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptjitallowedforsites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_javascriptjitblockedforsites","displayName":"Block JavaScript from using JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are not allowed to run JavaScript JIT (Just In Time) compiler enabled.\n\nDisabling the JavaScript JIT will mean that Microsoft Edge may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Microsoft Edge to render web content in a more secure configuration.\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitBlockedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT disabled, but fabrikam.com will use the policy from \"DefaultJavaScriptJitSetting\", if set, or default to JavaScript JIT enabled.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptJitSetting\" applies to the site, if set, otherwise JavaScript JIT is enabled for the site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptjitblockedforsites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are enabled.\n\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the \"JavaScriptOptimizerAllowedForSites\" policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations enabled, but fabrikam.com will use the policy from \"DefaultJavaScriptOptimizerSetting\", if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptOptimizerSetting\" applies to the site, if set, otherwise Javascript optimization is enabled for the site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptoptimizerallowedforsites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are disabled.\n\nDisabling JavaScript optimizations will mean that Microsoft Edge may render web content more slowly.\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the \"JavaScriptOptimizerBlockedForSites\" policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations disabled, but fabrikam.com will use the policy from \"DefaultJavaScriptOptimizerSetting\", if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptOptimizerSetting\" applies to the site, if set, otherwise JavaScript optimization is enabled for the site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptoptimizerblockedforsites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_keyboardfocusablescrollersenabled","displayName":"Enable keyboard focusable scrollers (Deprecated)","description":"This policy provides a temporary opt-out for the new keyboard focusable scrollers behavior.\n\nWhen this policy is Enabled or unset, scrollers without focusable children are keyboard focusable by default. Further, scrollers are click focusable and programmatically focusable by default.\n\nWhen this policy is Disabled, scrollers are not focusable by default.\n\nThis policy is a temporary workaround and will be removed in Edge Stable 135.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#keyboardfocusablescrollersenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_keyboardfocusablescrollersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_keyboardfocusablescrollersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_kfmblockoptin","displayName":"Prevent users from using the Folder Backup feature (Known Folder Move)","description":"This setting prevents users from moving their Documents and Desktop folders to any OneDrive account.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmblockoptin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_kfmblockoptin_0","displayName":"No prevention","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmblockoptin_1","displayName":"Prevent Folder Backup","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmblockoptin_2","displayName":"Prevent Folder Backup and Redirect to local device","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_kfmblockoptout","displayName":"Force users to use the Folder Backup feature (Known Folder Move)","description":"This setting forces users to keep their Documents and Desktop folders directed to OneDrive.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmblockoptout"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_kfmblockoptout_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmblockoptout_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_kfmoptinwithwizard","displayName":"Prompt users to enable the Folder Backup feature (Known Folder Move)","description":"This setting displays a wizard that prompts users to move their Documents and Desktop folders to OneDrive. Enter your Microsoft 365 tenant ID to enable this feature.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmoptinwithwizard"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_kfmsilentoptin","displayName":"Automatically and silently enable the Folder Backup feature (Known Folder Move)","description":"Use this setting to redirect and move your users Documents and/or Desktop folders to OneDrive without any user interaction. Enter your Microsoft 365 tenant ID to enable this feature.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmsilentoptin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_kfmsilentoptindesktop","displayName":"Include ~/Desktop in Folder Backup (Known Folder Move)","description":null,"helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmsilentoptin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_kfmsilentoptindesktop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmsilentoptindesktop_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_kfmsilentoptindocuments","displayName":"Include ~/Documents in Folder Backup (Known Folder Move)","description":null,"helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmsilentoptin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_kfmsilentoptindocuments_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmsilentoptindocuments_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_kfmsilentoptinwithnotification","displayName":"Display a notification to users once their folders have been redirected","description":"Display a notification to users once their folders have been redirected","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmsilentoptin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_kfmsilentoptinwithnotification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmsilentoptinwithnotification_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_kioskaddressbareditingenabled","displayName":"Configure address bar editing for kiosk mode public browsing experience","description":"This policy only applies to Microsoft Edge kiosk mode while using the public browsing experience.\r\n\r\nIf you enable or don't configure this policy, users can change the URL in the address bar.\r\n\r\nIf you disable this policy, it prevents users from changing the URL in the address bar.\r\n\r\nFor detailed information on configuring kiosk Mode, see https://go.microsoft.com/fwlink/?linkid=2137578.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#kioskaddressbareditingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_kioskaddressbareditingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kioskaddressbareditingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_legacysamesitecookiebehaviorenabled","displayName":"Enable default legacy SameSite cookie behavior setting","description":"Lets you revert all cookies to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", and removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute.\n\nYou can set the following values for this policy:\n\n* 1 = Revert to legacy SameSite behavior for cookies on all sites\n\n* 2 = Use SameSite-by-default behavior for cookies on all sites\n\nIf you don't set this policy, the default behavior for cookies that don't specify a SameSite attribute will depend on other configuration sources for the SameSite-by-default feature. This feature might be set by a field trial or by enabling the same-site-by-default-cookies flag in edge://flags.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#legacysamesitecookiebehaviorenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_legacysamesitecookiebehaviorenabled_0","displayName":"Revert to legacy SameSite behavior for cookies on all sites","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_legacysamesitecookiebehaviorenabled_1","displayName":"Use SameSite-by-default behavior for cookies on all sites","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_legacysamesitecookiebehaviorenabledfordomainlist","displayName":"Revert to legacy SameSite behavior for cookies on specified sites (Deprecated)","description":"Cookies set for domains match specified patterns will revert to legacy SameSite behavior.\n\nReverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", and removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute.\n\nIf you don't set this policy, the global default value will be used. The global default will also be used for cookies on domains not covered by the patterns you specify.\n\nThe global default value can be configured using the \"LegacySameSiteCookieBehaviorEnabled\" policy. If \"LegacySameSiteCookieBehaviorEnabled\" is unset, the global default value falls back to other configuration sources.\n\nNote that patterns you list in this policy are treated as domains, not URLs, so you should not specify a scheme or port.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#legacysamesitecookiebehaviorenabledfordomainlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_linkedaccountenabled","displayName":"Enable the linked account feature (Deprecated)","description":"Microsoft Edge guides a user to the account management page where they can link a Microsoft Account (MSA) to an Azure Active Directory (Azure AD) account.\n\nIf you enable or don't configure this policy, linked account information will be shown on a flyout. When the Azure AD profile doesn't have a linked account it will show \"Add account\".\n\nIf you disable this policy, linked accounts will be turned off and no extra information will be shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#linkedaccountenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_linkedaccountenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_linkedaccountenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_localnetworkaccessallowedforurls","displayName":"Allow sites to make requests to local network endpoints.","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions.\n\nIf an origin is specified by both this policy and the \"LocalNetworkAccessBlockedForUrls\" policy, the blocked list takes precedence.\n\nFor origins not covered by this policy, the user's personal settings and local network access restrictions will apply.\n\nFor guidance on valid URL pattern syntax, see:\nhttps://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns\n\nNote: This policy enables controlled exceptions to local network access restrictions. It allows specific public websites to access private IP addresses when necessary for trusted local communication scenarios. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localnetworkaccessallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_localnetworkaccessblockedforurls","displayName":"Block sites from making requests to local network endpoints.","description":"List of URL patterns. Requests initiated from websites served by matching origins are blocked from issuing Local Network Access requests.\n\nIf an origin is covered by both this policy and by \"LocalNetworkAccessAllowedForUrls\", this policy takes precedence.\n\nDepending on the stage of the rollout of Local Network Access, LocalNetworkAccessRestrictionsEnabled may also need to be enabled for this policy to block Local Network Access requests.\n\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\n\nFor detailed information on valid URL patterns, please see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\n\nNote: This policy improves local network security by blocking specified public websites from accessing private IP addresses. It helps prevent unauthorized external sites from reaching internal resources unless explicitly permitted. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localnetworkaccessblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to block requests from public websites to devices on a user's local network. (deprecated)","description":"Local Network Access restrictions prevent public websites from making\nrequests to devices on a user's local network without explicit user permission.\n\nIf you enable this policy, Microsoft Edge blocks\nany request that would otherwise trigger a DevTools warning\ndue to Local Network Access checks.\nThese requests are denied without prompting the user.\n\nIf you disable or don't configure this policy, Microsoft Edge handles\nthese requests using the default behavior, which may include showing warnings in DevTools\nand allowing the request to proceed depending on the context.\n\nNote: This feature improves local network security by deprecating direct access to private IP addresses from public websites\nunless explicitly granted by the user. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.\n\nStarting in version 140, Microsoft Edge introduces support for policies that manage Local Network Access behavior on a per-URL basis.\n\nYou can configure exceptions to allow specific URLs to bypass Local Network Access restrictions.\n\nYou can also block specific URLs from making Local Network Access requests.\n\nStarting from Microsoft Edge version 144, this policy is deprecated because Local Network Access restrictions is enabled by default. The policy will be removed in a future release.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localnetworkaccessrestrictionsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionstemporaryoptout","displayName":"Specifies whether to opt out of Local Network Access restrictions","description":"This policy allows for opting out of restrictions on requests to local network endpoints.\n\nIf you enable this policy, Local Network Access requests will only display warnings in Edge DevTools when Local Network Access checks fail.\n\nIf you disable or don't configure this policy, Local Network Access requests will follow the default handling behavior.\n\nFor more information about Local Network Access restrictions, see Local Network Access .\n\nTo allow specific URL patterns that should automatically be granted Local Network Access permission, use the LocalNetworkAccessAllowedForUrls policy.\n\nNote: This opt-out policy is temporary and will be removed after Microsoft Edge version 152.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localnetworkaccessrestrictionstemporaryoptout"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionstemporaryoptout_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionstemporaryoptout_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_localprovidersenabled","displayName":"Allow suggestions from local providers","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\n\nIf you enable this policy, suggestions from local providers are used.\n\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions will not appear.\n\nIf you do not configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\n\nNote that some features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the \"SavingBrowserHistoryDisabled\" policy.\n\nThis policy requires a browser restart to finish applying.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localprovidersenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_localprovidersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_localprovidersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_lowpriorityscheduledscan","displayName":"Low priority scheduled scan","description":"Should scheduled scan be run with low priority. (Scan might take longer to complete).","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":[{"id":"com.apple.managedclient.preferences_lowpriorityscheduledscan_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_lowpriorityscheduledscan_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_managedsearchengines","displayName":"Managed Search Engines","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine.\nYou do not need to specify the encoding. Starting in Microsoft Edge 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge 80.\n\nStarting in Microsoft Edge 83, you can enable search engine discovery with the allow_search_engine_discovery optional parameter. This parameter must be the first item in the list. If allow_search_engine_discovery is not specified, search engine discovery will be disabled by default. Starting in Microsoft Edge 84, you can set this policy as a recommended policy to allow search provider discovery. You do not need to add the allow_search_engine_discovery optional parameter.\n\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\n\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\n\nIf the \"DefaultSearchProviderSearchURL\" policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#managedsearchengines"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_allow_search_engine_discovery","displayName":"Allow search engine discovery","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_managedsearchengines_item_allow_search_engine_discovery_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_allow_search_engine_discovery_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_encoding","displayName":"Encoding","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_image_search_post_params","displayName":"Image search post params","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_image_search_url","displayName":"Image search URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_is_default","displayName":"Is default","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_managedsearchengines_item_is_default_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_is_default_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_keyword","displayName":"Keyword","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_name","displayName":"Name","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_search_url","displayName":"Search URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_suggest_url","displayName":"Suggest URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_mandatoryextensionsforinprivatenavigation","displayName":"Specify extensions users must allow in order to navigate using InPrivate mode","description":"This policy lets you specify a list of extension IDs that must be explicitly allowed by the user to run in InPrivate mode in order to enable InPrivate browsing.\n\nIf users don't allow all listed extensions to run in InPrivate mode, they'll be unable to navigate using InPrivate.\n\nIf any extension in the list isn't installed, InPrivate navigation is blocked.\n\nThis policy only applies when InPrivate mode is enabled. If InPrivate mode is disabled using the InPrivateModeAvailability policy, this policy has no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#mandatoryextensionsforinprivatenavigation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_manifestserver","displayName":"Deferred updates (Deprecated)","description":"You can tell AutoUpdate to either a) wait for a number of days to pass before downloading updates from the Current Channel, or b) stop Office from advancing beyond a given version. Deferred updates only affects Word, Excel, PowerPoint, Outlook, and OneNote. Other applications such as Edge, Defender, and Company Portal will receive updates based on the regular Current Channel schedule.","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_manifestserver_0","displayName":"Defer 3 days","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_1","displayName":"Defer 7 days","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_2","displayName":"Defer 14 days","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_3","displayName":"Defer 21 days","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_4","displayName":"Defer 28 days","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_5","displayName":"Defer 45 days","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_6","displayName":"Pause at 16.64 (August 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_7","displayName":"Pause at 16.63 (July 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_8","displayName":"Pause at 16.62 (June 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_9","displayName":"Pause at 16.61 (May 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_10","displayName":"Pause at 16.60 (April 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_11","displayName":"Pause at 16.59 (March 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_12","displayName":"Pause at 16.58 (February 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_13","displayName":"Pause at 16.57 (January 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_14","displayName":"Pause at 16.56 (December 2021 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_15","displayName":"Pause at 16.55 (November 2021 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_16","displayName":"Pause at 16.54 (October 2021 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_17","displayName":"Pause at 16.53 (September 2021 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_18","displayName":"Pause at 16.52 (August 2021 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_19","displayName":"Pause at 16.51 (July 2021 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_20","displayName":"Pause at 16.80 (December 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_21","displayName":"Pause at 16.79 (November 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_22","displayName":"Pause at 16.78 (October 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_23","displayName":"Pause at 16.77 (September 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_24","displayName":"Pause at 16.76 (August 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_25","displayName":"Pause at 16.75 (July 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_26","displayName":"Pause at 16.74 (June 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_27","displayName":"Pause at 16.73 (May 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_28","displayName":"Pause at 16.72 (April 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_29","displayName":"Pause at 16.71 (March 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_30","displayName":"Pause at 16.70 (February 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_31","displayName":"Pause at 16.69 (January 2023 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_32","displayName":"Pause at 16.68 (December 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_33","displayName":"Pause at 16.67 (November 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_34","displayName":"Pause at 16.66 (October 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_35","displayName":"Pause at 16.65 (September 2022 Release)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_manifestserver_36","displayName":"Change Freeze","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_maxconnectionsperproxy","displayName":"Maximum number of concurrent connections to the proxy server","description":"Specifies the maximum number of simultaneous connections to the proxy server.\n\nSome proxy servers can't handle a high number of concurrent connections per client - you can solve this by setting this policy to a lower value.\n\nThe value of this policy should be lower than 100 and higher than 6. The default value is 32.\n\nSome web apps are known to consume many connections with hanging GETs - lowering the maximum connections below 32 may lead to browser networking hangs if too many of these kind of web apps are open.\n\nIf you don't configure this policy, the default value (32) is used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#maxconnectionsperproxy"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_maximumondemandscanthreads","displayName":"Degree of parallelism for on-demand scans","description":"Specifies the degree of parallelism for on-demand scans. This corresponds to the number of threads used to perform the scan and impacts the CPU usage, as well as the duration of the on-demand scan.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#degree-of-parallelism-for-on-demand-scans"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_mediaroutercastallowallips","displayName":"Allow Google Cast to connect to Cast devices on all IP addresses","description":"Enable this policy to let Google Cast connect to Cast devices on all IP addresses, not just RFC1918/RFC4193 private addresses.\n\nDisable this policy to restrict Google Cast to Cast devices on RFC1918/RFC4193 private addresses.\n\nIf you don't configure this policy, Google Cast connects to Cast devices on RFC1918/RFC4193 private addresses only, unless you enable the CastAllowAllIPs feature.\n\nIf the \"EnableMediaRouter\" policy is disabled, then this policy has no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#mediaroutercastallowallips"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_mediaroutercastallowallips_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_mediaroutercastallowallips_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_merge_policy","displayName":"Performance profiles merge policy","description":"Specify the merge policy for performance profiles. This can be a combination of administrator-defined and user-defined profiles (merge) or only administrator-defined profiles (admin_only).","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/performance-profiles"],"categoryId":"d40a32e1-ab3e-4cbc-aa03-4766792e563e","categoryName":"Performance Profiles Configuration","options":[{"id":"com.apple.managedclient.preferences_merge_policy_0","displayName":"merge","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_merge_policy_1","displayName":"admin_only","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_metricsreportingenabled","displayName":"Enable usage and crash-related data reporting","description":"This policy enables reporting of usage and crash-related data about Microsoft Edge to Microsoft.\n\nEnable this policy to send reporting of usage and crash-related data to Microsoft. Disable this policy to not send the data to Microsoft. In both cases, users can't change or override the setting.\n\nOn Windows 10, Beta and Stable channels, if you don’t configure this policy, Microsoft Edge will default to the Windows diagnostic data setting. If you enable this policy, Microsoft Edge will only send usage data if the Windows Diagnostic data setting is set to Enhanced or Full. If you disable this policy, Microsoft Edge will not send usage data. Crash-related data is sent based on the Windows Diagnostic data setting. Learn more about Windows Diagnostic data settings at https://go.microsoft.com/fwlink/?linkid=2099569\n\nOn Windows 10, Canary and Dev channels, this policy controls sending usage data. If this policy is not configured, Microsoft Edge will default to the user's preference. Crash-related data is sent based on the Windows Diagnostic data setting. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\n\nOn Windows 7, 8, and macOS, this policy controls sending usage and crash-related data. If you don’t configure this policy, Microsoft Edge will default to the user's preference.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#metricsreportingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_metricsreportingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_metricsreportingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_microsoft365copilotchaticonenabled","displayName":"Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar","description":"For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon will be shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users.\n\nThis policy only applies when users are accessing Copilot in the sidepane.\n\nIf the policy is enabled: Copilot will appear in the toolbar.\n\nIf the policy is disabled: Copilot won't appear in the toolbar.\n\nIf the policy isn't configured: Otherwise, Copilot shows in the toolbar and users may enable or disable Copilot from showing by using the Show Copilot toggle in settings.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#microsoft365copilotchaticonenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_microsoft365copilotchaticonenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_microsoft365copilotchaticonenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_microsoftedgeinsiderpromotionenabled","displayName":"Microsoft Edge Insider Promotion Enabled","description":"Shows content promoting the Microsoft Edge Insider channels on the About Microsoft Edge settings page.\n\nIf you enable or don't configure this policy, the Microsoft Edge Insider promotion content will be shown on the About Microsoft Edge page.\n\nIf you disable this policy, the Microsoft Edge Insider promotion content will not be shown on the About Microsoft Edge page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#microsoftedgeinsiderpromotionenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_microsoftedgeinsiderpromotionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_microsoftedgeinsiderpromotionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_microsofteditorproofingenabled","displayName":"Spell checking provided by Microsoft Editor","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages.\n\nIf you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields.\n\nIf you disable this policy, spell check can only be provided by local engines that use platform or Hunspell services. The results from these engines might be less informative than the results Microsoft Editor can provide.\n\nIf the \"SpellcheckEnabled\" policy is set to disabled, or the user disables spell checking in the settings page, this policy will have no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#microsofteditorproofingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_microsofteditorproofingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_microsofteditorproofingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_microsofteditorsynonymsenabled","displayName":"Synonyms are provided when using Microsoft Editor spell checker","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages, and synonyms can be suggested as an integrated feature.\n\nIf you enable this policy, Microsoft Editor spell checker will provide synonyms for suggestions for misspelled words.\n\nIf you disable or don't configure this policy, Microsoft Editor spell checker will not provide synonyms for suggestions for misspelled words.\n\nIf the \"SpellcheckEnabled\" policy or the \"MicrosoftEditorProofingEnabled\" policy are set to disabled, or the user disables spell checking or chooses not to use Microsoft Editor spell checker in the settings page, this policy will have no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#microsofteditorsynonymsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_microsofteditorsynonymsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_microsofteditorsynonymsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_msawebsitessousingthisprofileallowed","displayName":"Allow single sign-on for Microsoft personal sites using this profile","description":"'Allow single sign-on for Microsoft personal sites using this profile' option allows non-MSA profiles to be able to use single sign-on for Microsoft sites using MSA credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-MSA profiles only.\n\nIf you disable this policy, non-MSA profiles will not be able to use single sign-on for Microsoft sites using MSA credentials present on the machine.\n\nIf you enable this policy or don't configure it, users will be able to use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#msawebsitessousingthisprofileallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_msawebsitessousingthisprofileallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_msawebsitessousingthisprofileallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_mutationeventsenabled","displayName":"Enable deprecated/removed Mutation Events (Deprecated)","description":"This policy provides a temporary opt-in back to a deprecated and removed set of platform events named Mutation Events.\n\nIf you enable this policy, mutation events will continue to be fired, even if they've been disabled by default for normal web users.\n\nIf you disable or don't configure this policy, these events will not be fired.\n\nThis policy is a temporary workaround, and enterprises should still work to remove their dependencies on these mutation events.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#mutationeventsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_mutationeventsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_mutationeventsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_nativemessagingallowlist","displayName":"Control which native messaging hosts users can use","description":"List specific native messaging hosts that users can use in Microsoft Edge.\n\nBy default, all native messaging hosts are allowed. If you set the \"NativeMessagingBlocklist\" policy to *, all native messaging hosts are blocked, and only native messaging hosts listed in here are loaded.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#nativemessagingallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_nativemessagingblocklist","displayName":"Configure native messaging block list","description":"Specifies which native messaging hosts that shouldn't be used.\n\nUse '*' to block all native messaging hosts unless they are explicitly listed in the allow list.\n\nIf you don't configure this policy, Microsoft Edge will load all installed native messaging hosts.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#nativemessagingblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_nativemessaginguserlevelhosts","displayName":"Allow user-level native messaging hosts (installed without admin permissions)","description":"Enables user-level installation of native messaging hosts.\n\nIf you disable this policy, Microsoft Edge will only use native messaging hosts installed on the system level.\n\nBy default, if you don't configure this policy, Microsoft Edge will allow usage of user-level native messaging hosts.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#nativemessaginguserlevelhosts"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_nativemessaginguserlevelhosts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_nativemessaginguserlevelhosts_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_networkpredictionoptions","displayName":"Enable network prediction","description":"Enables network prediction and prevents users from changing this setting.\n\nThis controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages.\n\nIf you don't configure this policy, network prediction is enabled but the user can change it.\n\n* 0 = Predict network actions on any network connection\n\n* 2 = Don't predict network actions on any network connection","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#networkpredictionoptions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular. (Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_networkpredictionoptions_2","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newpdfreaderenabled","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\n\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\n\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newpdfreaderenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newpdfreaderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newpdfreaderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpageallowedbackgroundtypes","displayName":"Configure the background types allowed for the new tab page layout","description":"You can configure which types of background image that are allowed on the new tab page layout in Microsoft Edge.\n\nIf you don't configure this policy, all background image types on the new tab page are enabled.\n\nPolicy options mapping:\n\n* DisableImageOfTheDay (1) = Disable daily background image type\n\n* DisableCustomImage (2) = Disable custom background image type\n\n* DisableAll (3) = Disable all background image types\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpageallowedbackgroundtypes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpageallowedbackgroundtypes_0","displayName":"Disable daily background image type","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpageallowedbackgroundtypes_1","displayName":"Disable custom background image type","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpageallowedbackgroundtypes_2","displayName":"Disable all background image types","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpageapplauncherenabled","displayName":"Hide App Launcher on Microsoft Edge new tab page","description":"By default, the App Launcher is shown every time a user opens a new tab page.\n\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge new tab page and App Launcher is there for users.\n\nIf you disable this policy, App Launcher doesn't appear and users won't be able to launch M365 apps from Microsoft Edge new tab page via the App Launcher.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpageapplauncherenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpageapplauncherenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpageapplauncherenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagebingchatenabled","displayName":"Disable Bing chat entry-points on Microsoft Edge Enterprise new tab page","description":"By default, the Microsoft Edge new tab page includes three Bing Chat entry points: one inside the search box, one in the Bing autosuggest dropdown when users click or begin typing in the box, and one as a suggested prompt below the box.\n\nIf you enable or don't configure this policy, these Bing Chat entry points continue to appear on the new tab page.\n\nIf you disable this policy, all Bing Chat entry points are removed from the new tab page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagebingchatenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagebingchatenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagebingchatenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo","displayName":"New Tab Page Company Logo","description":"We are deprecating this policy because it doesn't work as expected and recommend that it not be used.\n\nSpecifies the company logo to use on the new tab page in Microsoft Edge.\n\nThe policy should be configured as a string that expresses the logo(s) in JSON format. For example: { \"default_logo\": { \"url\": \"https://www.contoso.com/logo.png\", \"hash\": \"cd0aa9856147b6c5b4ff2b7dfee5da20aa38253099ef1b4a64aced233c9afe29\" }, \"light_logo\": { \"url\": \"https://www.contoso.com/light_logo.png\", \"hash\": \"517d286edb416bb2625ccfcba9de78296e90da8e32330d4c9c8275c4c1c33737\" } }\n\nYou configure this policy by specifying the URL from which Microsoft Edge can download the logo and its cryptographic hash (SHA-256), which is used to verify the integrity of the download. The logo must be in PNG or SVG format, and its file size must not exceed 16 MB. The logo is downloaded and cached, and it will be redownloaded whenever the URL or the hash changes. The URL must be accessible without any authentication.\n\nThe 'default_logo' is required and will be used when there's no background image. If 'light_logo' is provided, it will be used when the user's new tab page has a background image. We recommend a horizontal logo with a transparent background that is left-aligned and vertically centered. The logo should have a minimum height of 32 pixels and an aspect ratio from 1:1 to 4:1. The 'default_logo' should have proper contrast against a white/black background while the 'light_logo' should have proper contrast against a background image.\n\nIf you enable this policy, Microsoft Edge downloads and shows the specified logo(s) on the new tab page. Users can't override or hide the logo(s).\n\nIf you disable or don't configure this policy, Microsoft Edge will show no company logo or a Microsoft logo on the new tab page.\n\nFor help with determining the SHA-256 hash, see https://docs.microsoft.com/powershell/module/microsoft.powershell.utility/get-filehash.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagecompanylogo"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_default_logo","displayName":"Default logo","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_default_logo_hash","displayName":"Hash","description":"The SHA-256 hash of the image.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_default_logo_url","displayName":"URL","description":"The URL from which the image can be downloaded.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_light_logo","displayName":"Light logo","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_light_logo_hash","displayName":"Hash","description":"The SHA-256 hash of the image.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_light_logo_url","displayName":"URL","description":"The URL from which the image can be downloaded.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogobackplatecolor","displayName":"Set the company logo backplate color on the new tab page.","description":"By default, the new tab page sets the company logo backplate color to the neutralStrokeActive (#cecece) constant.\n\nYou can configure this policy with a color hex code to change the company logo backplate color on the new tab page.\n\nIf this policy is not configured, the default neutralStrokeActive (#cecece) color will be used as the backplate color.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagecompanylogobackplatecolor"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogoenabled","displayName":"Hide the company logo on the Microsoft Edge new tab page","description":"By default, the company logo is shown on the new tab page if the company logo is configured in Admin Portal.\n\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge new tab page and the company logo is there for users.\n\nIf you disable this policy, the company logo doesn't appear on Microsoft Edge new tab page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagecompanylogoenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagecompanylogoenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagecompanylogoenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagehidedefaulttopsites","displayName":"Hide the default top sites from the new tab page","description":"Hides the default top sites from the new tab page in Microsoft Edge.\n\nIf you set this policy to true, the default top site tiles are hidden.\n\nIf you set this policy to false or don't configure it, the default top site tiles remain visible.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagehidedefaulttopsites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagehidedefaulttopsites_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagehidedefaulttopsites_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagelocation","displayName":"Configure the new tab page URL","description":"Configures the default URL for the new tab page.\n\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\n\nThis policy doesn't determine which page opens on startup; that's controlled by the \"RestoreOnStartup\" policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\n\nIf you don't configure this policy, the default new tab page is used.\n\nIf you configure this policy *and* the \"NewTabPageSetFeedType\" policy, this policy has precedence.\n\nIf an invalid URL is provided, new tabs will open about://blank.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagelocation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks","displayName":"New Tab Page Managed Quick Links","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\n\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\n\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' is not provided, the URL is used as the default title. If 'pinned' is not provided, the default value is false.\n\nMicrosoft Edge presents these in the order listed, from left to right, with all pinned tiles displayed ahead of non-pinned tiles.\n\nIf the policy is set as mandatory, the 'pinned' field will be ignored and all tiles will be pinned. The tiles can't be deleted by the user and will always appear at the front of the quick links list.\n\nIf the policy is set as recommended, pinned tiles will remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying non-pinned links via this policy to an existing browser profile, the links may not appear at all, depending on how they rank compared to the user's browsing history.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagemanagedquicklinks"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks_item_pinned","displayName":"Pinned","description":"0 - Not Pinned; 1 - Pinned.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks_item_pinned_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks_item_pinned_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks_item_title","displayName":"Title","description":"The title to display.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks_item_url","displayName":"URL","description":"The URL for the quick link.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_newtabpageprerenderenabled","displayName":"Enable preload of the new tab page for faster rendering","description":"If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpageprerenderenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpageprerenderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpageprerenderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagequicklinksenabled","displayName":"Allow quick links on the new tab page","description":"If you enable or don't configure this policy, Microsoft Edge displays quick links on the new tab page, and the user can interact with the control, turning quick links on and off. Enabling this policy does not force quick links to be visible - the user can continue to turn quick links on and off.\n\nIf you disable this policy, Microsoft Edge hides quick links on the new tab page and disables the quick links control in the NTP settings flyout.\n\nThis policy only applies for Microsoft Edge local user profiles, profiles signed in using a Microsoft Account, and profiles signed in using Active Directory. To configure the Enterprise new tab page for profiles signed in using Azure Active Directory, use the M365 admin portal.\n\nRelated policies: \"NewTabPageAllowedBackgroundTypes\", \"NewTabPageContentEnabled\"","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagequicklinksenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagequicklinksenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagequicklinksenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagesearchbox","displayName":"Configure the new tab page search box experience","description":"You can configure the new tab page search box to use \"Search box (Recommended)\" or \"Address bar\" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\".\n\n If you disable or don't configure this policy and:\n\n- If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.\n- If the address bar default search engine is not Bing, users are offered an additional choice (use \"Address bar\") when searching on new tabs.\n\n\nIf you enable this policy and set it to:\n\n- \"Search box (Recommended)\" ('bing'), the new tab page uses the search box to search on new tabs.\n- \"Address bar\" ('redirect'), the new tab page search box uses the address bar to search on new tabs.\n\nPolicy options mapping:\n\n* bing (bing) = Search box (Recommended)\n\n* redirect (redirect) = Address bar\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagesearchbox"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagesearchbox_0","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagesearchbox_1","displayName":"Address bar","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_newtabpagesetfeedtype","displayName":"Configure the Microsoft Edge new tab page experience","description":"Lets you choose either the Microsoft News or Office 365 feed experience for the new tab page.\n\nWhen you set this policy to Microsoft News feed experience (0), users will see the Microsoft News feed experience on the new tab page.\n\nWhen you set this policy to Office 365 feed experience (1), users with an Azure Active Directory browser sign-in will see the Office 365 feed experience on the new tab page.\n\nIf you disable or don't configure this policy:\n\n- Users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, as well as the standard new tab page feed experience.\n\n- Users without an Azure Active Directory browser sign-in will see the standard new tab page experience.\n\nIf you configure this policy *and* the \"NewTabPageLocation\" policy, \"NewTabPageLocation\" has precedence.\n\nDefault setting: Disabled or not configured.\n\n* 0 = Microsoft News feed experience\n\n* 1 = Office 365 feed experience","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagesetfeedtype"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagesetfeedtype_0","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagesetfeedtype_1","displayName":"Office 365 feed experience","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_notificationsallowedforurls","displayName":"Allow notifications on specific sites","description":"Define a list of sites, based on URL patterns, that can display notifications.\n\nIf you don't configure this policy, the global default value from the \"DefaultNotificationsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#notificationsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_notificationsblockedforurls","displayName":"Block notifications on specific sites","description":"Allows you to create a list of url patterns to specify sites that are not allowed to display notifications.\n\nIf you don’t set this policy, the global default value will be used for all sites. This default value will be from the \"DefaultNotificationsSetting\" policy if it’s set, or from the user's personal configuration. For detailed information on valid url patterns, see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#notificationsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_npssurveydisabled","displayName":"Disable user surveys","description":"Prevent survey and feedback dialogs from being shown to users.","helpText":null,"infoUrls":[],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_npssurveydisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_npssurveydisabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_ntlmv2enabled","displayName":"Control whether NTLMv2 authentication is enabled","description":"Controls whether NTLMv2 is enabled.\n\nAll recent versions of Samba and Windows servers support NTLMv2. You should only disable NTLMv2 to address issues with backwards compatibility as it reduces the security of authentication.\n\nIf you don't configure this policy, NTLMv2 is enabled by default.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#ntlmv2enabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_ntlmv2enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_ntlmv2enabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_officeactivationemailaddress","displayName":"Office Activation Email Address","description":"The sign in sheet for Word, Excel, PowerPoint, Outlook, and OneNote will be automatically populated with the specified value.","helpText":null,"infoUrls":[],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":null},{"id":"com.apple.managedclient.preferences_officeautosignin","displayName":"Enable automatic sign-in","description":"Suppress first run and welcome dialogs when launching apps.","helpText":null,"infoUrls":["https://aka.ms/outlookprefs"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_officeautosignin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_officeautosignin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_officeexperiencesanalyzingcontentpreference","displayName":"Allow experiences and functionality that analyzes user content","description":"Examples: PowerPoint Designer, editing suggestions, Excel data insights.","helpText":null,"infoUrls":["https://aka.ms/macoce"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_officeexperiencesanalyzingcontentpreference_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_officeexperiencesanalyzingcontentpreference_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_officeexperiencesdownloadingcontentpreference","displayName":"Allow experiences and functionality that downloads user content","description":"Examples: Office document templates, online 3D models, online videos.","helpText":null,"infoUrls":["https://aka.ms/macoce"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_officeexperiencesdownloadingcontentpreference_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_officeexperiencesdownloadingcontentpreference_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_officewebaddindisableomexcatalog","displayName":"Disable third-party store add-in catalog","description":"Prevent users from accessing and downloading third-party add-ins from the Microsoft store (affects Word, Excel, and PowerPoint).","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-add-ins"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_officewebaddindisableomexcatalog_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_officewebaddindisableomexcatalog_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdate","displayName":"Enable offline security intelligence updates","description":"Enables or disables offline security intelligence updates feature. When this feature is enabled Defender will use a local mirror server to update the signatures.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-support-offline-security-intelligence-update"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_offlinedefinitionupdate_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdate_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdatefallbacktocloud","displayName":"Fallback to Microsoft cloud updates","description":"Determine the Defender for Endpoint security intelligence update approach when offline mirror server fails to serve the update request. If set to true, the update is retried via the Microsoft cloud when offline security intelligence update failed.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-support-offline-security-intelligence-update#configure-the-endpoints"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_offlinedefinitionupdatefallbacktocloud_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdatefallbacktocloud_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdateurl","displayName":"URL for a security intelligence updates mirror server","description":"Sets the URL for a local offline security intelligence updates mirror server. When the feature is enabled Defender will use it to update the signatures.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-support-offline-security-intelligence-update#configure-the-endpoints"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdateverifysig","displayName":"offline security intelligence updates signature verification","description":"Offline security intelligence updates signature verification with Microsoft Defender for Endpoint. It is recommended to keep this setting enabled when offline updates are enabled.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-support-offline-security-intelligence-update"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_offlinedefinitionupdateverifysig_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdateverifysig_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_oldisablejunkoptionsprefkey","displayName":"Disable Junk settings","description":"Prevent users from applying Junk options to emails.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-junk-settings"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_oldisablejunkoptionsprefkey_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_oldisablejunkoptionsprefkey_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_oopprintdriversallowed","displayName":"Out-of-process print drivers allowed","description":"This policy determines whether Microsoft Edge handles interactions with printer drivers through a separate service process.\n\nUsing a service process for tasks like querying available printers, retrieving print driver settings, and submitting documents to local printers improves browser stability and prevents UI freezing during Print Preview.\n\nEnabled or Not Set: Microsoft Edge will use a separate service process for these printing tasks.\n\nDisabled: Microsoft Edge will perform these printing tasks within the browser process.\n\nNote: This policy will be deprecated in the future once the transition to out-of-process print drivers is fully implemented.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#oopprintdriversallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_oopprintdriversallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_oopprintdriversallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_openatlogin","displayName":"Open at login","description":"Specifies whether OneDrive starts automatically when the user logs in.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#openatlogin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_openatlogin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_openatlogin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_optionalconnectedexperiencespreference","displayName":"Allow optional connected experiences","description":"Allow usage of third-party data controller services. Note: All Outlook add-ins will be disabled if the value is set to false.","helpText":null,"infoUrls":["https://aka.ms/macoce"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_optionalconnectedexperiencespreference_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_optionalconnectedexperiencespreference_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_organizationalbrandingonworkprofileuienabled","displayName":"Allow the use of your organization's branding assets from Microsoft Entra on the profile-related UI of a work or school profile","description":"Allow the use of your organization's branding assets from Entra, if any, on the profile-related UI of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect.\n\nIf you enable this policy, your organization's branding assets from Entra will be used.\n\nIf you disable or don't configure this policy, your organization's branding assets from Entra won't be used.\n\nFor more information about configuring your organization's branding assets on Entra, please visit https://go.microsoft.com/fwlink/?linkid=2254514.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#organizationalbrandingonworkprofileuienabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_organizationalbrandingonworkprofileuienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_organizationalbrandingonworkprofileuienabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_organizationlogooverlayonappiconenabled","displayName":"Allow your organization's logo from Microsoft Entra to be overlaid on the Microsoft Edge app icon of a work or school profile","description":"Allow your organization's logo from Entra, if any, to be overlaid on the Microsoft Edge app icon of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect.\n\nIf you enable this policy, your organization's logo from Entra will be used.\n\nIf you disable or don't configure this policy, your organization's logo from Entra won't be used.\n\nFor more information about configuring your organization's logo on Entra, please visit https://go.microsoft.com/fwlink/?linkid=2254514.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#organizationlogooverlayonappiconenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_organizationlogooverlayonappiconenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_organizationlogooverlayonappiconenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_originagentclusterdefaultenabled","displayName":"Origin-keyed agent clustering enabled by default","description":"The Origin-Agent-Cluster: HTTP header controls whether a document is isolated in an origin-keyed agent cluster or in a site-keyed agent cluster. This has security implications because an origin-keyed agent cluster allows isolating documents by origin. The consequence of this for developers is that the document.domain accessor can no longer be set when origin-keyed agent clustering is enabled.\n\nIf you enable or don't configure this policy, documents without the Origin-Agent-Cluster: header will be assigned to origin-keyed agent clustering by default. On these documents, the document.domain accessor will not be settable.\n\nIf you disable this policy, documents without the Origin-Agent-Cluster: header will be assigned to site-keyed agent clusters by default. On these documents, the document.domain accessor will be settable.\n\nSee https://go.microsoft.com/fwlink/?linkid=2191896 for additional details.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#originagentclusterdefaultenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_originagentclusterdefaultenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_originagentclusterdefaultenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_originkeyedprocessesenabled","displayName":"Enable origin-keyed process isolation for improved security","description":"This policy enables origin-keyed process isolation for most pages, which improves security by separating content from different origins into distinct processes. This may increase the number of processes created. Users can override this setting by using command-line flags or edge://flags to turn the feature on or off.\n\nIf you enable this policy, most origins will be isolated, even from other origins within the same site. For related configuration, see the IsolateOrigins and SitePerProcess policies.\n\nIf you disable this policy, origins will not be isolated from the rest of their site unless the origin explicitly requests isolation.\n\nIf you don’t configure this policy, the browser will decide which origins to isolate and when. By default, this feature is disabled. The default state may change in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#originkeyedprocessesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_originkeyedprocessesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_originkeyedprocessesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_overridesecurityrestrictionsoninsecureorigin","displayName":"Control where security restrictions on insecure origins apply","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*.contoso.com\") for which security restrictions on insecure origins don't apply.\n\nThis policy allows you to specify permitted origins for legacy applications that cannot deploy TLS or for internal web development staging servers. It enables developers to test features requiring secure contexts without the need to configure TLS on the staging server. Patterns are only accepted for hostnames; URLs or origins with schemes must be exact matches. This policy also prevents the origin from being labeled \"Not Secure\" in the omnibox.\n\nSetting a list of URLs in this policy has the same effect as setting the command-line flag '--unsafely-treat-insecure-origin-as-secure' to a comma-separated list of the same URLs. If you enable this policy, it overrides the command-line flag.\n\nFor more information on secure contexts, see https://www.w3.org/TR/secure-contexts/.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#overridesecurityrestrictionsoninsecureorigin"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_partitionedbloburlusage","displayName":"Manage Blob URL Partitioning During Fetching and Navigation","description":"The \"PartitionedBlobUrlUsage\" policy controls whether Blob URLs are partitioned during fetching and navigation.\nIf this policy is set to Enabled or not set, Blob URLs are partitioned.\nIf this policy is set to Disabled, Blob URLs won't be partitioned. This represents the Blob URL behavior before Microsoft Edge version 135.\n\nIf storage partitioning is disabled for a given top-level origin either by \"ThirdPartyStoragePartitioningBlockedForOrigins\" or \"DefaultThirdPartyStoragePartitioningSetting\", then Blob URLs aren't partitioned.\n\nThe policy is scheduled to be available through Microsoft Edge version 146. After this version, the policy will be removed, and Microsoft Edge will no longer support unpartitioned blob storage.\n\nFor detailed information on third-party storage partitioning, see https://github.com/privacycg/storage-partitioning.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#partitionedbloburlusage"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_partitionedbloburlusage_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_partitionedbloburlusage_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passivemode","displayName":"Enable passive mode (deprecated)","description":"Whether the antivirus engine runs in passive mode or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-passive-mode"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_passivemode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passivemode_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passworddeleteonbrowsercloseenabled","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when the \"ClearBrowsingDataOnExit\" policy is enabled.\n\nIf you enable this policy, passwords won't be cleared when the browser closes.\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passworddeleteonbrowsercloseenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passworddeleteonbrowsercloseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passworddeleteonbrowsercloseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passwordexportenabled","displayName":"Enable exporting saved passwords from Password Manager","description":"This policy controls whether the Export Password button in edge://wallet/passwords is enabled.\n\nIf enabled or not configured, users can export saved passwords.\nIf disabled, the Export Password button is unavailable, preventing password exports.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordexportenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordexportenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordexportenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passwordmanagerenabled","displayName":"Enable saving passwords to the password manager","description":"Enable Microsoft Edge to save user passwords.\n\nIf you enable this policy, users can save their passwords in Microsoft Edge. The next time they visit the site, Microsoft Edge will enter the password automatically.\n\nIf you disable this policy, users can't save new passwords, but they can still use previously saved passwords.\n\nIf you enable or disable this policy, users can't change or override it in Microsoft Edge. If you don't configure it, users can save passwords, as well as turn this feature off.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordmanagerenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordmanagerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordmanagerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passwordmanagerrestrictlengthenabled","displayName":"Restrict the length of passwords that can be saved in the Password Manager","description":"Make Microsoft Edge restrict the length of usernames and/or passwords that can be saved in the Password Manager.\n\nIf you enable this policy, Microsoft Edge will not let the user save credentials with usernames and/or passwords longer than 256 characters.\n\nIf you disable or don't configure this policy, Microsoft Edge will let the user save credentials with arbitrarily long usernames and/or passwords.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordmanagerrestrictlengthenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordmanagerrestrictlengthenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordmanagerrestrictlengthenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passwordmonitorallowed","displayName":"Allow Microsoft Edge to monitor user passwords","description":"If you enable this policy and a user consents to enabling the policy, the user will get alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\n\nIf you disable this policy, users will not be asked for permission to enable this feature and will not be alerted. Their passwords will not be scanned.\n\nIf you disable this policy, users can't change or override the policy. However, if you enable or don't configure the policy, users can turn this feature on or off.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordmonitorallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordmonitorallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordmonitorallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL","description":"Configures the change password URL (HTTP and HTTPS schemes only).\n\nPassword protection service will send users to this URL to change their password after seeing a warning in the browser.\n\nIf you enable this policy, then password protection service sends users to this URL to change their password.\n\nIf you disable this policy or don't configure it, then password protection service will not redirect users to a change password URL.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordprotectionchangepasswordurl"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_passwordprotectionloginurls","displayName":"Configure the list of enterprise login URLs where password protection service should capture fingerprint of password","description":"Configure the list of enterprise login URLs (HTTP and HTTPS schemes only) where Microsoft Edge should capture the fingerprint of passwords and use it for password reuse detection.\n\nIf you enable this policy, the password protection service captures fingerprints of passwords on the defined URLs.\n\nIf you disable this policy or don't configure it, no password fingerprints are captured.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordprotectionloginurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_passwordprotectionwarningtrigger","displayName":"Configure password protection warning trigger","description":"Allows you to control when to trigger password protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites.\n\nYou can use the \"PasswordProtectionLoginURLs\" and \"PasswordProtectionChangePasswordURL\" policies to configure which passwords to protect.\n\nExemptions: Passwords for the sites listed in \"PasswordProtectionLoginURLs\" and \"PasswordProtectionChangePasswordURL\", as well as for the sites listed in \"SmartScreenAllowListDomains\", will not trigger a password-protection warning.\n\nSet to 'PasswordProtectionWarningOff' (0) to not show password protection warningss.\n\nSet to 'PasswordProtectionWarningOnPasswordReuse' (1) to show password protection warnings when the user reuses their protected password on a non-whitelisted site.\n\nIf you disable or don't configure this policy, then the warning trigger is not shown.\n\n* 0 = Password protection warning is off.\n\n* 1 = Password protection warning is triggered by password reuse.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordprotectionwarningtrigger"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordprotectionwarningtrigger_0","displayName":"Password protection warning is off","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordprotectionwarningtrigger_1","displayName":"Password protection warning is triggered by password reuse","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_passwordrevealenabled","displayName":"Enable Password reveal button","description":"Lets you configure the default display of the browser password reveal button for password input fields on websites.\n\nIf you enable or don't configure this policy, the browser user setting defaults to displaying the password reveal button.\n\nIf you disable this policy, the browser user setting won't display the password reveal button.\n\nFor accessibility, users can change the browser setting from the default policy.\n\nThis policy only affects the browser password reveal button, it doesn't affect websites' custom reveal buttons.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordrevealenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordrevealenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordrevealenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_paymentmethodqueryenabled","displayName":"Allow websites to query for available payment methods","description":"Allows you to set whether websites can check if the user has payment methods saved.\n\nIf you disable this policy, websites that use PaymentRequest.canMakePayment or PaymentRequest.hasEnrolledInstrument API will be informed that no payment methods are available.\n\nIf you enable this policy or don't set this policy, websites can check if the user has payment methods saved.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#paymentmethodqueryenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_paymentmethodqueryenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_paymentmethodqueryenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_pdfsecuremode","displayName":"Secure mode and Certificate-based Digital Signature validation in native PDF reader","description":"The policy enables Digital Signature validation for PDF files in a secure environment, which shows the correct validation status of the signatures.\n\nIf you enable this policy, PDF files with Certificate-based digital signatures are opened with an option to view and verify the validity of the signatures with high security.\n\nIf you disable or don't configure this policy, the capability to view and verify the signature will not be available.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pdfsecuremode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pdfsecuremode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pdfsecuremode_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_pdfvieweroutofprocessiframeenabled","displayName":"Use out-of-process iframe PDF Viewer","description":"Determines whether the PDF viewer in Microsoft Edge uses an out-of-process iframe (OOPIF).\nThis will be the new PDF viewer architecture going forward, as it is simpler in design and makes adding new features easier. The current GuestView PDF viewer, which relies on an outdated and overly complex architecture, is being deprecated.\n\nWhen this policy is set to Enabled or not set, Microsoft Edge will use the OOPIF PDF viewer architecture. Once Enabled or not set, the default behavior will be decided by Microsoft Edge.\n\nWhen this policy is set to Disabled, Microsoft Edge will strictly use the existing GuestView PDF viewer. This approach embeds a web page with its own separate frame tree into another web page.\n\nThis policy will be removed in the future, after the OOPIF PDF viewer feature has fully rolled out.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pdfvieweroutofprocessiframeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pdfvieweroutofprocessiframeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pdfvieweroutofprocessiframeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_pdfxfaenabled","displayName":"XFA support in native PDF reader enabled","description":"Lets the Microsoft Edge browser enable XFA (XML Forms Architecture) support in the native PDF reader and allows users to open XFA PDF files in the browser.\n\nIf you enable this policy, XFA support in the native PDF reader will be enabled.\n\nIf you disable or don't configure this policy, Microsoft Edge will not enable XFA support in the native PDF reader.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pdfxfaenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pdfxfaenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pdfxfaenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_performancedetectorenabled","displayName":"Performance Detector Enabled","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\n\nIf you enable or don't configure this policy, performance detector is turned on.\n\nIf you disable this policy, performance detector is turned off.\n\nThe user can configure its behavior in edge://settings/system.\n\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#performancedetectorenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_performancedetectorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_performancedetectorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_performanceprofiles","displayName":"Performance Profiles","description":"Performance profiles","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/performance-profiles"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_performanceprofiles_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_performanceprofiles_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_personalizationreportingenabled","displayName":"Allow personalization of ads, search and news by sending browsing history to Microsoft","description":"This policy prevents Microsoft from collecting a user's Microsoft Edge browsing history to be used for personalizing advertising, search, news and other Microsoft services.\n\nThis setting is only available for users with a Microsoft account. This setting is not available for child accounts or enterprise accounts.\n\nIf you disable this policy, users can't change or override the setting. If this policy is enabled or not configured, Microsoft Edge will default to the user’s preference.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#personalizationreportingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_personalizationreportingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_personalizationreportingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_personalizetopsitesincustomizesidebarenabled","displayName":"Personalize my top sites in Customize Sidebar enabled by default","description":"This policy controls whether Microsoft Edge browser be allowed to use the browsing history to personalize the top sites in the customize sidebar page.\n\nIf you enable this policy, Microsoft Edge will use the browsing history to personalize the top sites in the customize sidebar page.\n\nIf you disable this policy, Microsoft Edge will not use the browsing history to personalize the top sites in the customize sidebar page.\n\nIf you don't configure this policy, the default behavior is to use the browsing history to personalize the top sites in the customize sidebar page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#personalizetopsitesincustomizesidebarenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_personalizetopsitesincustomizesidebarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_personalizetopsitesincustomizesidebarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_phoenixonboardingflowfrelaunched","displayName":"Hide the 'Personalize the new Outlook' dialog","description":"Suppress the welcome dialog that appears when users switch to New Outlook.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_phoenixonboardingflowfrelaunched_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_phoenixonboardingflowfrelaunched_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\n\nThe Picture in Picture floating overlay button lets user to watch videos in a floating window on top of other windows.\n\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\n\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pictureinpictureoverlayenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pictureinpictureoverlayenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pictureinpictureoverlayenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_pinbrowseressentialstoolbarbutton","displayName":"Pin browser essentials toolbar button","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\n\nWhen the button is pinned, it will always appear on the toolbar.\n\nWhen the button isn't pinned, it will only appear when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\n\nIf you enable or don't configure this policy, the Browser essentials button will be pinned on the toolbar.\n\nIf you disable this policy, the Browser essentials button won't be pinned on the toolbar.\n\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pinbrowseressentialstoolbarbutton"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pinbrowseressentialstoolbarbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pinbrowseressentialstoolbarbutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_pluginsallowedforurls","displayName":"Allow the Adobe Flash plug-in on specific sites","description":"Define a list of sites, based on URL patterns, that can run the Adobe Flash plug-in.\n\nIf you don't configure this policy, the global default value from the \"DefaultPluginsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pluginsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_pluginsblockedforurls","displayName":"Block the Adobe Flash plug-in on specific sites","description":"Define a list of sites, based on URL patterns, that are blocked from running Adobe Flash.\n\nIf you don't configure this policy, the global default value from the \"DefaultPluginsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pluginsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_popupsallowedforurls","displayName":"Allow pop-up windows on specific sites","description":"Define a list of sites, based on URL patterns, that can open pop-up windows.\n\nIf you don't configure this policy, the global default value from the \"DefaultPopupsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#popupsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_popupsblockedforurls","displayName":"Block pop-up windows on specific sites","description":"Define a list of sites, based on URL patterns, that are blocked from opening pop-up windows.\n\nIf you don't configure this policy, the global default value from the \"DefaultPopupsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#popupsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_postquantumkeyagreementenabled","displayName":"Enable post-quantum key agreement for TLS","description":"This policy configures whether Microsoft Edge offers a post-quantum key agreement algorithm in TLS. This lets supporting servers protect user traffic from being decrypted by quantum computers.\n\nIf you enable or don't configure this policy, Microsoft Edge offers a post-quantum key agreement in TLS connections. TLS connections are protected from quantum computers when communicating with compatible servers.\n\nIf you disable this policy, Microsoft Edge will not offer a post-quantum key agreement in TLS connections. User traffic is unprotected from decryption by quantum computers.\n\nOffering a post-quantum key agreement is backwards-compatible. Existing TLS servers and networking middleware are expected to ignore the new option and continue selecting previous options.\n\nHowever, devices that don't implement TLS correctly may malfunction when offered the new option. For example, they might disconnect in response to unrecognized options or the resulting larger messages. These devices aren't post-quantum-ready and will interfere with an enterprise's post-quantum transition. If this issue is encountered, administrators should contact the vendor for a fix.\n\nThis policy is a temporary measure and will be removed in future versions of Microsoft Edge. You can enable it to test for issues and you can disable it while you resolve issues.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#postquantumkeyagreementenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_postquantumkeyagreementenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_postquantumkeyagreementenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_precisegeolocationallowedforurls","displayName":"Allow precise geolocation on these sites","description":"This policy lets you specify a list of URL patterns for sites that are allowed to access the user's high-accuracy geolocation without prompting for permission.\n\nIf you leave this policy unset, DefaultGeolocationSetting applies to all sites (if configured). Otherwise, the user's personal setting is used.\n\nFor information about valid url patterns, see https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format. Wildcards (*) are supported.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#precisegeolocationallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_prefetchwithserviceworkerenabled","displayName":"Allow SpeculationRules prefetch for ServiceWorker-controlled URLs","description":"Controls whether SpeculationRules prefetch requests are allowed for\nServiceWorker-controlled URLs.\n\nStarting with Microsoft Edge version 138,\nprefetch requests to ServiceWorker-controlled URLs are allowed by default when\nthe PrefetchServiceWorker feature is enabled.\n\nIf this policy is enabled or not configured, that default behavior is used.\n\nTo restore the legacy behavior from versions prior to 138, where prefetch requests\nto ServiceWorker-controlled URLs were blocked, set this policy to disabled.\n\nThis policy is intended to be temporary and will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#prefetchwithserviceworkerenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_prefetchwithserviceworkerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_prefetchwithserviceworkerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverride","displayName":"Prevent bypassing Microsoft Defender SmartScreen prompts for sites","description":"This policy setting lets you decide whether users can override the Microsoft Defender SmartScreen warnings about potentially malicious websites.\n\nIf you enable this setting, users can't ignore Microsoft Defender SmartScreen warnings and they are blocked from continuing to the site.\n\nIf you disable or don't configure this setting, users can ignore Microsoft Defender SmartScreen warnings and continue to the site.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#preventsmartscreenpromptoverride"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverride_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverride_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverrideforfiles","displayName":"Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads","description":"This policy lets you determine whether users can override Microsoft Defender SmartScreen warnings about unverified downloads.\n\nIf you enable this policy, users in your organization can't ignore Microsoft Defender SmartScreen warnings, and they're prevented from completing the unverified downloads.\n\nIf you disable or don't configure this policy, users can ignore Microsoft Defender SmartScreen warnings and complete unverified downloads.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#preventsmartscreenpromptoverrideforfiles"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverrideforfiles_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverrideforfiles_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_preventtyposquattingpromptoverride","displayName":"Prevent bypassing Edge Website Typo Protection prompts for sites","description":"This policy setting lets you decide whether users can override the Edge Website Typo Protection warnings about potential typosquatting websites.\n\nIf you enable this setting, users can't ignore Edge Website Typo Protection warnings and they are blocked from continuing to the site.\n\nIf you disable or don't configure this setting, users can ignore Edge Website Typo Protection warnings and continue to the site.\n\nThis will only take effect when TyposquattingCheckerEnabled policy is not set or set to enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#preventtyposquattingpromptoverride"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_preventtyposquattingpromptoverride_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_preventtyposquattingpromptoverride_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill","description":"The feature helps users add an additional layer of privacy to their online accounts by requiring device authentication (as a way of confirming the user's identity) before the saved password is auto-filled into a web form. This ensures that non-authorized persons can't use saved passwords for autofill. Note that this feature does not protect against locally-running malware.\n\nThis group policy configures the radio button selector that enables this feature for users. It also has a frequency control where users can specify how often they would like to be prompted for authentication.\n\nIf you set this policy to 'Automatically', disable this policy, or don't configure this policy, autofill will not have any authentication flow.\n\nIf you set this policy to 'WithDevicePassword', users will have to enter their device password (or preferred mode of authentication under Windows) to prove their identity before their password is auto filled. Authentication modes include Windows Hello, PIN, face recognition, or fingerprint. The frequency for authentication prompt will be set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\n\nIf you set this policy to 'WithCustomPrimaryPassword', users will be asked to create their custom password and then to be redirected to Settings. After the custom password is set, users can authenticate themselves using the custom password and their passwords will get auto-filled after successful authentication. The frequency for authentication prompt will be set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\n\nIf you set this policy to 'AutofillOff', saved passwords will no longer be suggested for autofill.\n\nPolicy options mapping:\n\n* Automatically (0) = Automatically\n\n* WithDevicePassword (1) = With device password\n\n* WithCustomPrimaryPassword (2) = With custom primary password\n\n* AutofillOff (3) = Autofill off\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#primarypasswordsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_primarypasswordsetting_0","displayName":"Automatically","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_primarypasswordsetting_1","displayName":"With device password","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_primarypasswordsetting_2","displayName":"With custom primary password","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_primarypasswordsetting_3","displayName":"Autofill off","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printertypedenylist","displayName":"Disable printer types on the deny list","description":"The printer types on the deny list won't be discovered or have their capabilities fetched.\n\nPlacing all printer types on the deny list effectively disables printing, because there's no print destination for documents.\n\nIf you don't configure this policy, or the printer list is empty, all printer types are discoverable.\n\nPrinter destinations include extension printers and local printers. Extension printers are also known as print provider destinations, and include any destination that belongs to a Microsoft Edge extension.\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\n\nPolicy options mapping:\n\n* privet (privet) = Zeroconf-based (mDNS + DNS-SD) protocol destinations\n\n* extension (extension) = Extension-based destinations\n\n* pdf (pdf) = The 'Save as PDF' destination\n\n* local (local) = Local printer destinations\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printertypedenylist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_printheaderfooter","displayName":"Print headers and footers","description":"Force 'headers and footers' to be on or off in the printing dialog.\n\nIf you don't configure this policy, users can decide whether to print headers and footers.\n\nIf you disable this policy, users can't print headers and footers.\n\nIf you enable this policy, users always print headers and footers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printheaderfooter"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printheaderfooter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printheaderfooter_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode","description":"Restricts background graphics printing mode. If this policy isn't set there's no restriction on printing background graphics.\n\nPolicy options mapping:\n\n* any (any) = Allow printing with and without background graphics\n\n* enabled (enabled) = Allow printing only with background graphics\n\n* disabled (disabled) = Allow printing only without background graphics\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printingallowedbackgroundgraphicsmodes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printingallowedbackgroundgraphicsmodes_0","displayName":"Allow printing with and without background graphics","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printingallowedbackgroundgraphicsmodes_1","displayName":"Allow printing only without background graphics","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printingallowedbackgroundgraphicsmodes_2","displayName":"Allow printing only with background graphics","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode","description":"Overrides the last used setting for printing background graphics.\nIf you enable this setting, background graphics printing is enabled.\nIf you disable this setting, background graphics printing is disabled.\n\nPolicy options mapping:\n\n* enabled (enabled) = Enable background graphics printing mode by default\n\n* disabled (disabled) = Disable background graphics printing mode by default\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printingbackgroundgraphicsdefault"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printingbackgroundgraphicsdefault_0","displayName":"Disable background graphics printing mode by default","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printingbackgroundgraphicsdefault_1","displayName":"Enable background graphics printing mode by default","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printingenabled","displayName":"Enable printing","description":"Enables printing in Microsoft Edge and prevents users from changing this setting.\n\nIf you enable this policy or don't configure it, users can print.\n\nIf you disable this policy, users can't print from Microsoft Edge. Printing is disabled in the wrench menu, extensions, JavaScript applications, and so on. Users can still print from plug-ins that bypass Microsoft Edge while printing. For example, certain Adobe Flash applications have the print option in their context menu, which isn't covered by this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printingwebpagelayout","displayName":"Sets layout for printing","description":"Configuring this policy sets the layout for printing webpages.\n\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\n\nIf you enable this policy, the selected option is set as the layout option.\n\nPolicy options mapping:\n\n* portrait (0) = Sets layout option as portrait\n\n* landscape (1) = Sets layout option as landscape\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printingwebpagelayout"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printingwebpagelayout_0","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printingwebpagelayout_1","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printpdfasimagedefault","displayName":"Print PDF as Image Default","description":"Controls if Microsoft Edge makes the Print as image option the default when printing PDFs.\n\nIf you enable this policy, Microsoft Edge will default to setting the Print as image option in the Print Preview when printing a PDF.\n\nIf you disable or don't configure this policy, Microsoft Edge will not default to setting the Print as image option in the Print Preview when printing a PDF.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printpdfasimagedefault"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printpdfasimagedefault_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printpdfasimagedefault_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printpreviewusesystemdefaultprinter","displayName":"Set the system default printer as the default printer","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\n\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\n\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printpreviewusesystemdefaultprinter"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printpreviewusesystemdefaultprinter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printpreviewusesystemdefaultprinter_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI","description":"Controls print image resolution when Microsoft Edge prints PDFs with rasterization.\n\nWhen printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution will significantly increase the processing and printing time while a low resolution can lead to poor imaging quality.\n\nIf you set this policy, it allows a particular resolution to be specified for use when rasterizing PDFs for printing.\n\nIf you set this policy to zero or don't configure it, the system default resolution will be used during rasterization of page images.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printrasterizepdfdpi"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_printstickysettings","displayName":"Print preview sticky settings","description":"Specifies whether print preview should apply last used settings for Microsoft Edge PDF and webpages.\n\nIf you set this policy to 'EnableAll' or don't configure it, Microsoft Edge applies the last used print preview settings for both PDF and webpages.\n\nIf you set this policy to 'DisableAll', Microsoft Edge doesn't apply the last used print preview settings for both PDF and webpages.\n\nIf you set this policy to 'DisablePdf', Microsoft Edge doesn't apply the last used print preview settings for PDF printing and retains it for webpages.\n\nIf you set this policy to 'DisableWebpage', Microsoft Edge doesn't apply the last used print preview settings for webpage printing and retain it for PDF.\n\nThis policy is only available if you enable or don't configure the \"PrintingEnabled\" policy.\n\nPolicy options mapping:\n\n* EnableAll (0) = Enable sticky settings for PDF and Webpages\n\n* DisableAll (1) = Disable sticky settings for PDF and Webpages\n\n* DisablePdf (2) = Disable sticky settings for PDF\n\n* DisableWebpage (3) = Disable sticky settings for Webpages\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printstickysettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printstickysettings_0","displayName":"Enable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printstickysettings_1","displayName":"Disable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printstickysettings_2","displayName":"Disable sticky settings for PDF","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printstickysettings_3","displayName":"Disable sticky settings for Webpages","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_privatenetworkaccessrestrictionsenabled","displayName":"Specifies whether to apply restrictions to requests to more private network endpoints (Deprecated)","description":"Specifies whether to apply restrictions to requests to more private\nnetwork endpoints\n\nWhen this policy is Enabled, any time when a warning is supposed to be displayed in the DevTools due to Private Network Access checks failing, the request is blocked.\n\nWhen this policy is Disabled or unset, all Private Network Access warnings are not enforced and the requests are not blocked.\n\nSee https://wicg.github.io/private-network-access/ for Private Network Access restrictions.\n\nNote: A network endpoint is more private than another if:\n1) Its IP address is localhost and the other is not.\n2) Its IP address is private and the other is public.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#privatenetworkaccessrestrictionsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_privatenetworkaccessrestrictionsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_privatenetworkaccessrestrictionsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_proactiveauthenabled","displayName":"Enable Proactive Authentication","description":"Lets you configure whether to turn on Proactive Authentication.\n\nIf you enable this policy, Microsoft Edge tries to proactively authenticate the signed-in user with Microsoft services. At regular intervals, Microsoft Edge checks with an online service for an updated manifest that contains the configuration that governs how to do this.\n\nIf you disable this policy, Microsoft Edge doesn't try to proactively authenticate the signed-in user with Microsoft services. Microsoft Edge no longer checks with an online service for an updated manifest that contains the configuration for doing this.\n\nIf you don't configure this policy, Proactive Authentication is turned on.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proactiveauthenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_proactiveauthenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proactiveauthenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_proactiveauthworkflowenabled","displayName":"Enable proactive authentication","description":"This policy controls the proactive authentication in Microsoft Edge, that connects the signed-in user identity with Microsoft Bing, MSN and Copilot services for a smooth and consistent sign-in experience.\n\nIf you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser.\n\nIf you disable this policy, Microsoft Edge does not send authentications requests to these services and users will need to manually sign-in.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proactiveauthworkflowenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_proactiveauthworkflowenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proactiveauthworkflowenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_profiles","displayName":"Performance Profiles","description":"Names of performance profiles to apply.","helpText":null,"infoUrls":[],"categoryId":"d40a32e1-ab3e-4cbc-aa03-4766792e563e","categoryName":"Performance Profiles Configuration","options":null},{"id":"com.apple.managedclient.preferences_profiletypeinprofilebuttonenabled","displayName":"Controls the display of the profile button label for the work or school profile","description":"Controls whether the label for the work or school profile type is shown in the profile button.\n\nThis policy does not apply when the OrganizationalBrandingOnWorkProfileUIEnabled policy is enabled.\n\nIf you enable this policy, the label for the work or school profile type appears in the profile button.\n\nIf you disable this policy or leave it not configured, the label is not shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#profiletypeinprofilebuttonenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_profiletypeinprofilebuttonenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_profiletypeinprofilebuttonenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_promotionaltabsenabled","displayName":"Enable full-tab promotional content (deprecated)","description":"Control the presentation of full-tab promotional or educational content. This setting controls the presentation of welcome pages that help users sign into Microsoft Edge, choose their default browser, or learn about product features.\n\nIf you enable this policy (set it true) or don't configure it, Microsoft Edge can show full-tab content to users to provide product information.\n\nIf you disable (set to false) this policy, Microsoft Edge can't show full-tab content to users.\n\nThis is deprecated - use ShowRecommendationsEnabled instead.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#promotionaltabsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_promotionaltabsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_promotionaltabsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_promptfordownloadlocation","displayName":"Ask where to save downloaded files","description":"Set whether to ask where to save a file before downloading it.\n\nIf you enable this policy, the user is asked where to save each file before downloading; if you don't configure it, files are saved automatically to the default location, without asking the user.\n\nIf you don't configure this policy, the user will be able to change this setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#promptfordownloadlocation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_promptfordownloadlocation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_promptfordownloadlocation_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_promptonmultiplematchingcertificates","displayName":"Prompt the user to select a certificate when multiple certificates match","description":"This policy controls whether the user is prompted to select a client certificate when more than one certificate matches \"AutoSelectCertificateForUrls\".\nIf this policy is set to True, the user is prompted to select a client certificate whenever the auto-selection policy matches multiple certificates.\nIf this policy is set to False or not set, the user may only be prompted when no certificate matches the auto-selection.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#promptonmultiplematchingcertificates"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_promptonmultiplematchingcertificates_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_promptonmultiplematchingcertificates_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_proxy","displayName":"Set proxy for MDE communication","description":"Configure proxy for all MDE cloud communication. If not set, the system-wide proxy is used.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-preferences#proxy-for-defender-for-endpoint-communication"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":null},{"id":"com.apple.managedclient.preferences_proxybypasslist","displayName":"Configure proxy bypass rules","description":"Defines a list of hosts for which Microsoft Edge bypasses any proxy.\n\nThis policy is applied only if you have selected 'Use fixed proxy servers' in the \"ProxyMode\" policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, you can create a list of hosts for which Microsoft Edge doesn't use a proxy.\n\nIf you don't configure this policy, no list of hosts is created for which Microsoft Edge bypasses a proxy. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\n\nFor more detailed examples go to https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxybypasslist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_proxymode","displayName":"Configure proxy server settings","description":"Specify the proxy server settings used by Microsoft Edge. If you enable this policy, users can't change the proxy settings.\n\nIf you choose to never use a proxy server and to always connect directly, all other options are ignored.\n\nIf you choose to use system proxy settings, all other options are ignored.\n\nIf you choose to auto detect the proxy server, all other options are ignored.\n\nIf you choose fixed server proxy mode, you can specify further options in \"ProxyServer\" and 'Comma-separated list of proxy bypass rules'.\n\nIf you choose to use a .pac proxy script, you must specify the URL to the script in 'URL to a proxy .pac file'.\n\nFor detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.\n\nIf you enable this policy, Microsoft Edge will ignore all proxy-related options specified from the command line.\n\nIf you don't configure this policy users can choose their own proxy settings.\n\n* \"direct\" = Never use a proxy\n\n* \"auto_detect\" = Auto detect proxy settings\n\n* \"pac_script\" = Use a .pac proxy script\n\n* \"fixed_servers\" = Use fixed proxy servers\n\n* \"system\" = Use system proxy settings","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_proxymode_0","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_1","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_2","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_3","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_4","displayName":"Use system proxy settings","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_proxypacurl","displayName":"Set the proxy .pac file URL","description":"Specifies the URL for a proxy auto-config (PAC) file.\n\nThis policy is applied only if you selected 'Use a .pac proxy script' in the \"ProxyMode\" policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, you can specify the URL for a PAC file, which defines how the browser automatically chooses the appropriate proxy server for fetching a particular website.\n\nIf you disable or don't configure this policy, no PAC file is specified. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\n\nFor detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxypacurl"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_proxyserver","displayName":"Configure address or URL of proxy server","description":"Specifies the URL of the proxy server.\n\nThis policy is applied only if you have selected 'Use fixed proxy servers' in the \"ProxyMode\" policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, the proxy server configured by this policy will be used for all URLs.\n\nIf you disable or don't configure this policy, users can choose their own proxy settings while in this proxy mode. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\n\nFor more options and detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxyserver"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_proxysettings","displayName":"Proxy Settings","description":"Configures the proxy settings for Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge ignores all proxy-related options specified from the command line.\n\nIf you don't configure this policy, users can choose their own proxy settings.\n\nThis policy overrides the following individual policies:\n\n\"ProxyMode\"\n\"ProxyPacUrl\"\n\"ProxyServer\"\n\"ProxyBypassList\"\n\nThe ProxyMode field lets you specify the proxy server used by Microsoft Edge and prevents users from changing proxy settings.\n\nThe ProxyPacUrl field is a URL to a proxy .pac file.\n\nThe ProxyServer field is a URL for the proxy server.\n\nThe ProxyBypassList field is a list of proxy hosts that Microsoft Edge bypasses.\n\nIf you choose the 'direct' value as 'ProxyMode', a proxy is never used and all other fields are ignored.\n\nIf you choose the 'system' value as 'ProxyMode', the systems's proxy is used and all other fields are ignored.\n\nIf you choose the 'auto_detect' value as 'ProxyMode', all other fields are ignored.\n\nIf you choose the 'fixed_server' value as 'ProxyMode', the 'ProxyServer' and 'ProxyBypassList' fields are used.\n\nIf you choose the 'pac_script' value as 'ProxyMode', the 'ProxyPacUrl' and 'ProxyBypassList' fields are used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxysettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxybypasslist","displayName":"Proxy Bypass List","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxymode","displayName":"Proxy Mode","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_proxysettings_proxymode_0","displayName":"direct","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxymode_1","displayName":"auto_detect","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxymode_2","displayName":"pac_script","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxymode_3","displayName":"fixed_servers","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxymode_4","displayName":"system","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_proxysettings_proxypacurl","displayName":"Proxy PAC URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_proxysettings_proxyserver","displayName":"Proxy Server","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_qrcodegeneratorenabled","displayName":"Enable QR Code Generator","description":"This policy enables the QR Code generator feature in Microsoft Edge.\n\nIf you enable this policy or don't configure it, the QR Code Generator feature is enabled.\n\nIf you disable this policy, the QR Code Generator feature is disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#qrcodegeneratorenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_qrcodegeneratorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_qrcodegeneratorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_quicallowed","displayName":"Allow QUIC protocol","description":"Allows use of the QUIC protocol in Microsoft Edge.\n\nIf you enable this policy or don't configure it, the QUIC protocol is allowed.\n\nIf you disable this policy, the QUIC protocol is blocked.\n\nQUIC is a transport layer network protocol that can improve performance of web applications that currently use TCP.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#quicallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_quicallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_quicallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_quicksearchshowminimenu","displayName":"Enables Microsoft Edge mini menu (Deprecated)","description":"Enables Microsoft Edge mini menu on websites and PDFs. The mini menu is triggered on text selection and has basic actions like copy and smart actions like definitions.\n\nIf you enable or don't config this policy, selecting text on websites and PDFs will show the Microsoft Edge mini menu.\n\nIf you disable this policy, the Microsoft Edge mini menu will not be shown when text on websites and PDFs is selected.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#quicksearchshowminimenu"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_quicksearchshowminimenu_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_quicksearchshowminimenu_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_quickviewofficefilesenabled","displayName":"Manage QuickView Office files capability in Microsoft Edge","description":"Allows you to set whether users can view publicly accessible Office files on the web that aren't on OneDrive or SharePoint. (For example: Word documents, PowerPoint presentations, and Excel spreadsheets)\n\nIf you enable or don't configure this policy, these files can be viewed in Microsoft Edge using Office Viewer instead of downloading the files.\n\nIf you disable this policy, these files will be downloaded to be viewed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#quickviewofficefilesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_quickviewofficefilesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_quickviewofficefilesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_randomizescanstarttime","displayName":"Randomize scheduled scan start time","description":"Randomize the start time of a daily and weekly scheduled scan to any interval from 0 to 23 hours.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_readaloudenabled","displayName":"Enable Read Aloud feature in Microsoft Edge","description":"Enables the Read Aloud feature within Microsoft Edge.\nUsing this feature, users can listen to the content on the web page. This enables users to multi-task or improve their reading comprehension by hearing content at their own pace.\n\nIf you enable this policy or don't configure it, the Read Aloud option shows up in the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.\nIf you disable this policy, users can't access the Read Aloud feature from the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#readaloudenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_readaloudenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_readaloudenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_reduceipaddresschangenotificationenabled","displayName":"Enable Reduce IP Address Change Notification","description":"This policy lets you configure the Reduce IP address change notification feature in Microsoft Edge on macOS.\n\nIf you enable or don't configure this policy, the Reduce IP address change notification feature is enabled by default. This helps reduce unnecessary network change notifications when IP addresses change.\n\nIf you disable this policy, all IP address changes trigger network change notifications, regardless of the feature's status.\n\nThis feature is only available on macOS.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#reduceipaddresschangenotificationenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_reduceipaddresschangenotificationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_reduceipaddresschangenotificationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers","displayName":"Registered Protocol Handlers","description":"Register a list of protocol handlers. Set the protocol property to the scheme (like 'mailto') and the url property to the URL pattern of the application that handles the scheme. The pattern can include a '%s', which will be replaced by the handled URL.\n\nYou can recommend a specific value for this policy, but you can't require that your users use it.\n\nThe protocol handlers registered by policy are merged with any handlers registered by the user, and both are available for use. The user can override the protocol handlers installed by policy by installing a new default handler, but they can't remove a protocol handler registered by policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#registeredprotocolhandlers"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers_item_default","displayName":"Default","description":"A boolean flag indicating if the protocol handler should be set as the default.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers_item_default_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers_item_default_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers_item_protocol","displayName":"Protocol","description":"The protocol for the protocol handler.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers_item_url","displayName":"URL","description":"The URL of the protocol handler.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_relatedmatchescloudserviceenabled","displayName":"Configure Related Matches in Find on Page (Deprecated)","description":"Specifies how the user receives related matches in Find on Page, which provides spellcheck, synonyms, and Q&A results in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can receive related matches in Find on Page on all sites. The results are processed in a cloud service.\n\nIf you disable this policy, users can receive related matches in Find on Page on limited sites. The results are processed on the user's device.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relatedmatchescloudserviceenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_relatedmatchescloudserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_relatedmatchescloudserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_relatedwebsitesetsenabled","displayName":"Enable Related Website Sets (deprecated)","description":"This policy lets you control the enablement of the Related Website Sets feature. Related Website Sets (RWS) is a way for an organisation to declare relationships among sites, so that Microsoft Edge allows limited third-party cookie access for specific purposes across those sites.\n\nIf this policy set to True or unset, the Related Website Sets feature is enabled.\n\nIf this policy is set to False, the Related Website Sets feature is disabled.\n\nThis policy is deprecated as of Microsoft Edge version 144 with the deprecation of Related Website Sets.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relatedwebsitesetsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_relatedwebsitesetsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_relatedwebsitesetsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_relaunchfastifoutdated","displayName":"Relaunch browser quickly when the current version is outdated","description":"This policy specifies the minimum release age after which relaunch notifications become more aggressive. The release age is calculated from the time the currently running version was last served to clients.\n\nIf a browser relaunch is needed to finalize a pending update and the current version has been outdated for more than the number of days specified by this setting, the RelaunchNotificationPeriod policy is overridden to 2 hours. If the RelaunchNotification policy is set to 1 ('Required'), a browser relaunch will be forced at the end of the period.\n\nIf not set, or if the release age cannot be determined, the RelaunchNotificationPeriod policy will be used for all updates.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relaunchfastifoutdated"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_relaunchnotification","displayName":"Notify a user that a browser restart is recommended or required for pending updates","description":"Notify users that they need to restart Microsoft Edge to apply a pending update.\n\nIf you don't configure this policy, Microsoft Edge adds a recycle icon at the far right of the top menu bar to prompt users to restart the browser to apply the update.\n\nIf you enable this policy and set it to 'Recommended' (1), a recurring warning prompts users that a restart is recommended. Users can dismiss this warning and defer the restart.\n\nIf you set the policy to 'Required' (2), a recurring warning prompts users that the browser will be restarted automatically as soon as a notification period passes. The default period is seven days. You can configure this period with the \"RelaunchNotificationPeriod\" policy.\n\nThe user's session is restored when the browser restarts.\n\n* Recommended (1) = Show a recurring prompt to the user indicating that a restart is recommended\n\n* Required (2) = Show a recurring prompt to the user indicating that a restart is required","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relaunchnotification"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_relaunchnotification_0","displayName":"Recommended - Show a recurring prompt to the user indicating that a restart is recommended","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_relaunchnotification_1","displayName":"Required - Show a recurring prompt to the user indicating that a restart is required","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_relaunchnotificationperiod","displayName":"Set the time period for update notifications","description":"Allows you to set the time period, in milliseconds, over which users are notified that Microsoft Edge must be relaunched or that a Microsoft Edge OS device must be restarted to apply a pending update.\n\nOver this time period, the user will be repeatedly informed of the need for an update. For Microsoft Edge OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Microsoft Edge browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the \"RelaunchNotification\" policy follow this same schedule.\n\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relaunchnotificationperiod"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_remotedebuggingallowed","displayName":"Allow remote debugging","description":"Controls whether users may use remote debugging.\n\nIf you enable or don't configure this policy, users may use remote debugging by specifying --remote-debug-port and --remote-debugging-pipe command line switches.\n\nIf you disable this policy, users are not allowed to use remote debugging.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#remotedebuggingallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_remotedebuggingallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_remotedebuggingallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_resolvenavigationerrorsusewebservice","displayName":"Enable resolution of navigation errors using a web service","description":"Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi.\n\nIf you enable this policy, a web service is used for network connectivity tests.\n\nIf you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues.\n\n**Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues.\n\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\nSpecifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#resolvenavigationerrorsusewebservice"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_resolvenavigationerrorsusewebservice_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_resolvenavigationerrorsusewebservice_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_restoreonstartup","displayName":"Action to take on startup","description":"Specify how Microsoft Edge behaves when it starts.\n\nIf you want a new tab to always open on startup, choose 'Open new tab' (5).\n\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'Restore the last session' (1). The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\n\nIf you want to open a specific set of URLs, choose 'Open a list of URLs' (4).\n\nDisabling this setting is equivalent to leaving it not configured. Users will be able to change it in Microsoft Edge.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\n\n* 5 = Open a new tab\n\n* 1 = Restore the last session\n\n* 4 = Open a list of URLs","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restoreonstartup"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_restoreonstartup_0","displayName":"Restore the last session","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_restoreonstartup_1","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_restoreonstartup_2","displayName":"Open a new tab","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_restoreonstartup_3","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_restoreonstartupurls","displayName":"Sites to open when the browser starts","description":"Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup.\n\nThis policy only works if you also set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4).\n\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restoreonstartupurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_restoreonstartupuserurlsenabled","displayName":"Allow users to add and remove their own sites during startup when the RestoreOnStartupURLs policy is configured","description":"This policy only works if you set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4) and the \"RestoreOnStartupURLs\" policy as mandatory.\nIf you enable this policy, users are allowed to add and remove their own URLs to open when starting Edge while maintaining the admin specified mandatory list of sites specified by setting \"RestoreOnStartup\" policy to open a list of URLS and providing the list of sites in the \"RestoreOnStartupURLs\" policy.\n\nIf you disable or don't configure this policy, there is no change to how the \"RestoreOnStartup\" and \"RestoreOnStartupURLs\" policies work.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restoreonstartupuserurlsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_restoreonstartupuserurlsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_restoreonstartupuserurlsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_restorepdfview","displayName":"Restore PDF view","description":"Enables PDF View Recovery in Microsoft Edge.\n\nIf you enable or don't configure this policy Microsoft Edge will recover the last state of PDF view and land users to the section where they ended reading in the last session.\n\nIf you disable this policy Microsoft Edge will recover the last state of PDF view and land users at the start of the PDF file.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restorepdfview"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_restorepdfview_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_restorepdfview_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_restrictsignintopattern","displayName":"Restrict which accounts can be used as Microsoft Edge primary accounts","description":"Determines which accounts can be set as browser primary accounts in Microsoft Edge (the account that is chosen during the Sync opt-in flow).\n\nIf a user tries to set a browser primary account with a username that doesn't match this pattern, they are blocked and see an appropriate error message.\n\nIf you don't configure this policy or leave it blank, users can set any account as a browser primary account in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restrictsignintopattern"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_runallflashinallowmode","displayName":"Extend Adobe Flash content setting to all content","description":"If you enable this policy, all Adobe Flash content embedded in websites that are set to allow Adobe Flash in the content settings -- either by the user or by enterprise policy -- will run. This includes content from other origins and/or small content.\n\nTo control which websites are allowed to run Adobe Flash, see the specifications in the \"DefaultPluginsSetting\", \"PluginsAllowedForUrls\", and \"PluginsBlockedForUrls\" policies.\n\nIf you disable this policy or don't configure it, Adobe Flash content from other origins (from sites that aren't specified in the three policies mentioned immediately above) or small content might be blocked.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#runallflashinallowmode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_runallflashinallowmode_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_runallflashinallowmode_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_runscanwhenidle","displayName":"Run scheduled scan when idle","description":"Run scheduled scan when the device is idle. Only applicable for weekly full scans.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":[{"id":"com.apple.managedclient.preferences_runscanwhenidle_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_runscanwhenidle_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sameorigintabcaptureallowedbyorigins","displayName":"Allow Same Origin Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin.\n\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\n\nIf a site matches a URL pattern in this policy, the following policies will not be considered: \"TabCaptureAllowedByOrigins\", \"WindowCaptureAllowedByOrigins\", \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sameorigintabcaptureallowedbyorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_sandboxexternalprotocolblocked","displayName":"Allow Microsoft Edge to block navigations to external protocols in a sandboxed iframe","description":"Microsoft Edge will block navigations to external protocols inside a\nsandboxed iframe.\n\nIf you enable or don't configure this policy, Microsoft Edge will block those navigations.\n\nIf you disable this policy, Microsoft Edge will not block those navigations.\n\nThis can be used by administrators who need more time to update their internal website affected by this new restriction. This Enterprise policy is temporary; it's intended to be removed after Microsoft Edge version 117.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sandboxexternalprotocolblocked"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sandboxexternalprotocolblocked_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sandboxexternalprotocolblocked_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_savecookiesonexit","displayName":"Save cookies when Microsoft Edge closes","description":"When this policy is enabled, the specified set of cookies is exempt from deletion when the browser closes. This policy is only effective when:\n- The 'Cookies and other site data' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\n- The policy \"ClearBrowsingDataOnExit\" is enabled or\n- The policy \"DefaultCookiesSetting\" is set to 'Keep cookies for the duration of the session'.\n\nYou can define a list of sites, based on URL patterns, that will have their cookies preserved across sessions.\n\nNote: Users can still edit the cookie site list to add or remove URLs. However, they can't remove URLs that have been added by an Admin.\n\nIf you enable this policy, the list of cookies won't be cleared when the browser closes.\n\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#savecookiesonexit"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_savingbrowserhistorydisabled","displayName":"Disable saving browser history","description":"Disables saving browser history and prevents users from changing this setting.\n\nIf you enable this policy, browsing history isn't saved. This also disables tab syncing.\n\nIf you disable this policy or don't configure it, browsing history is saved.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#savingbrowserhistorydisabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_savingbrowserhistorydisabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_savingbrowserhistorydisabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_scanafterdefinitionupdate","displayName":"Run a scan after definitions are updated","description":"Specifies whether to start a process scan after new security intelligence updates are downloaded on the device. Enabling this setting will trigger an antivirus scan on the running processes of the device.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#run-a-scan-after-definitions-are-updated"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_scanafterdefinitionupdate_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scanafterdefinitionupdate_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_scanarchives","displayName":"Scanning inside archive files","description":"If true, Defender will unpack archives and scan files inside them. Otherwise archive content will be skipped, that will improve scanning performance.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#scan-archives-on-demand-antivirus-scans-only"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_scanarchives_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scanarchives_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_scanhistorymaximumitems","displayName":"Scan history size","description":"Specify the maximum number of entries to keep in the scan history. Entries include all on-demand scans performed in the past and all antivirus detections.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#maximum-number-of-items-in-the-antivirus-scan-history"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_scanresultsretentiondays","displayName":"Scan results retention","description":"Specify the number of days that results are retained in the scan history on the device. Old scan results are removed from the history. Old quarantined files that are also removed from the disk.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#antivirus-scan-history-retention-in-days"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_scarewareblockerallowlistdomains","displayName":"Configure the list of domains where Microsoft Edge Scareware blockers don't run","description":"This policy configures the list of trusted domains for Microsoft Edge Scareware blocker. When a website's source URL matches any domain in this list, Microsoft Edge Scareware blocker doesn't analyze that site.\n\nThis policy takes effect only if the ScarewareBlockerProtectionEnabled policy is enabled.\n\nIf you enable this policy, Microsoft Edge Scareware blocker trusts the specified domains.\n\nIf you disable or don't configure this policy, Microsoft Edge Scareware blocker analyzes all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockerallowlistdomains"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_scarewareblockerblocksdetectedsitesenabled","displayName":"Configure Microsoft Edge scareware blocker to block sites detected as potential tech scams","description":"This policy controls whether Microsoft Edge blocks sites that are detected as potential tech scams.\n\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\n\nIf you enable or don't configure this policy, Microsoft Edge blocks sites detected as potential tech scams.\n\nIf you disable this policy, Microsoft Edge doesn't block sites detected as potential tech scams.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockerblocksdetectedsitesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scarewareblockerblocksdetectedsitesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scarewareblockerblocksdetectedsitesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_scarewareblockerprotectionenabled","displayName":"Configure Microsoft Edge Scareware blocker protection","description":"This policy setting allows administrators to control whether Microsoft Edge enables Scareware blocker, an AI-powered feature for protecting users from potential tech scams. To support this feature, Microsoft Edge downloads a machine learning model file from Microsoft to the device.\n\nIf you enable or don’t configure this policy, Microsoft Edge Scareware blocker uses local AI to detect potential tech scams.\n\nIf you disable this policy, Microsoft Edge Scareware blocker is disabled. The machine learning model file doesn't download to the device, and if downloaded deletion occurs.\n\nWhen this policy is enabled, the policies \"ScarewareBlockerBlocksDetectedSitesEnabled\", \"ScarewareBlockerSendDetectedSitesToSmartScreenEnabled\", and \"ScarewareBlockerAllowListDomains\" can be used to configure the behavior of the Scareware blocker feature. If both of those policies are disabled, enabling this policy has no effect.\n\nWhen this policy is disabled, the policies \"ScarewareBlockerBlocksDetectedSitesEnabled\", \"ScarewareBlockerSendDetectedSitesToSmartScreenEnabled\", and \"ScarewareBlockerAllowListDomains\" have no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockerprotectionenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scarewareblockerprotectionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scarewareblockerprotectionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_scarewareblockersenddetectedsitestosmartscreenenabled","displayName":"Configure Microsoft Edge Scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen","description":"This policy controls whether Microsoft Edge shares URLs of sites that are detected as potential tech scams with Microsoft Defender SmartScreen.\n\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\n\nIf you enable this policy, Microsoft Edge shares URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.\n\nIf you disable or don't configure this policy, Microsoft Edge doesn't share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockersenddetectedsitestosmartscreenenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scarewareblockersenddetectedsitestosmartscreenenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scarewareblockersenddetectedsitestosmartscreenenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_scheduledscan","displayName":"Scheduled Scan","description":"Schedule scans with Microsoft Defender for Endpoint.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-schedule-scan"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_scheduledscan_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scheduledscan_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_screencaptureallowed","displayName":"Allow or deny screen capture","description":"If you enable this policy, or don't configure this policy, a web page can use screen-share APIs (for example, getDisplayMedia() or the Desktop Capture extension API) for a screen capture.\nIf you disable this policy, calls to screen-share APIs will fail. For example, if you're using a web-based online meeting, video or screen sharing will not work.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#screencaptureallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_screencaptureallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_screencaptureallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_screencaptureallowedbyorigins","displayName":"Allow Desktop, Window, and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture.\n\nLeaving the policy unset means that sites will not be considered for an override at this scope of Capture.\n\nThis policy is not considered if a site matches a URL pattern in any of the following policies: \"WindowCaptureAllowedByOrigins\", \"TabCaptureAllowedByOrigins\", \"SameOriginTabCaptureAllowedByOrigins\".\n\nIf a site matches a URL pattern in this policy, the \"ScreenCaptureAllowed\" will not be considered.\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#screencaptureallowedbyorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_screencapturewithoutgestureallowedfororigins","displayName":"Allow screen capture without prior user gesture","description":"For security reasons, the\ngetDisplayMedia() web API requires\na prior user gesture (\"transient activation\") to be called or the API will\nfail.\n\nWhen this policy is configured, admins can specify origins on which this API\ncan be called without prior user gesture.\n\nFor detailed information on valid url patterns, see\nhttps://go.microsoft.com/fwlink/?linkid=2095322. Note: * is not an accepted\nvalue for this policy.\n\nIf this policy is not configured, all origins require a prior user gesture to\ncall this API.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#screencapturewithoutgestureallowedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\n​\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL will be enabled.​\n\nIf you disable this policy, web page scrolling to specific text fragments via a URL will be disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scrolltotextfragmentenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scrolltotextfragmentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scrolltotextfragmentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_seamlesswebtobrowsersigninenabled","displayName":"Seamless Web To Browser Sign-in Enabled","description":"This policy only takes effect when the \"WebToBrowserSignInEnabled\" is enabled.\nIf this policy is enabled, users cannot turn off Seamless Web to Browser Sign-in feature from \"Automatic sign in on Microsoft Edge\" setting on Microsoft Edge profile settings page and that toggle will be greyed out.\nIf this policy is disabled, users cannot turn on Seamless Web to Browser Sign-in feature from \"Automatic sign in on Microsoft Edge\" setting on Microsoft Edge profile settings page and that toggle will be greyed out.\nIf this policy is not configured, users can turn on/off Seamless Web to Browser Sign-in feature from settings by themselves.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#seamlesswebtobrowsersigninenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_seamlesswebtobrowsersigninenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_seamlesswebtobrowsersigninenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_searchfiltersenabled","displayName":"Search Filters Enabled","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions will be shown.\n\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\n\nIf you disable this policy, the autosuggestion dropdown won't display the ribbon of available filters.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#searchfiltersenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_searchfiltersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_searchfiltersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_searchforimageenabled","displayName":"Search for image enabled","description":"This policy lets you configure the Image Search feature in the right-click context menu.\n\nIf you enable or don't configure this policy, then the \"Search the web for image\" option will be visible in the context menu.\n\nIf you disable this policy, then the \"Search the web for image\" will not be visible in the context menu.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#searchforimageenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_searchforimageenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_searchforimageenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_searchinsidebarenabled","displayName":"Search in Sidebar enabled","description":"Search in Sidebar allows users to open search result in sidebar (including sidebar search for Progressive Web Apps).\n\nIf you configure this policy to 'EnableSearchInSidebar' or don't configure it, Search in sidebar will be enabled.\n\nIf you configure this policy to 'DisableSearchInSidebarForKidsMode', Search in sidebar will be disabled when in Kids mode. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\n\nIf you configure this policy to 'DisableSearchInSidebar', Search in sidebar will be disabled. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\n\nPolicy options mapping:\n\n* EnableSearchInSidebar (0) = Enable search in sidebar\n\n* DisableSearchInSidebarForKidsMode (1) = Disable search in sidebar for Kids Mode\n\n* DisableSearchInSidebar (2) = Disable search in sidebar\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#searchinsidebarenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_searchinsidebarenabled_0","displayName":"Enable search in sidebar","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_searchinsidebarenabled_1","displayName":"Disable search in sidebar for Kids Mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_searchinsidebarenabled_2","displayName":"Disable search in sidebar","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_searchsuggestenabled","displayName":"Enable search suggestions","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\n\nIf you enable this policy, web search suggestions are used.\n\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\n\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#searchsuggestenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_searchsuggestenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_searchsuggestenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_securitykeypermitattestation","displayName":"Websites or domains that don't need permission to use direct Security Key attestation","description":"Specifies websites and domains that don't need explicit user permission when attestation certificates from security keys are requested. Additionally, a signal is sent to the security key indicating that it can use individual attestation. Without this, users are prompted each time a site requests attestation of security keys.\n\nSites (like https://contoso.com/some/path) only match as U2F appIDs. Domains (like contoso.com) only match as webauthn RP IDs. To cover both U2F and webauthn APIs for a given site, you need to list both the appID URL and domain.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#securitykeypermitattestation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_sendsiteinfotoimproveservices","displayName":"Send site information to improve Microsoft services","description":"This policy enables sending info about websites visited in Microsoft Edge to Microsoft to improve services like search.\n\nEnable this policy to send info about websites visited in Microsoft Edge to Microsoft. Disable this policy to not send info about websites visited in Microsoft Edge to Microsoft. In both cases, users can't change or override the setting.\n\nOn Windows 10, Beta and Stable if this policy is not configured, Microsoft Edge will default to the Windows diagnostic data setting. If this policy is enabled Microsoft Edge will only send info about websites visited in Microsoft Edge if the Windows Diagnostic data setting is set to Full. If this policy is disabled Microsoft Edge will not send info about websites visited. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\n\nOn Windows 10, Canary and Dev channels, this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.\n\nOn Windows 7, 8, and Mac this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sendsiteinfotoimproveservices"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sendsiteinfotoimproveservices_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sendsiteinfotoimproveservices_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sensorsallowedforurls","displayName":"Allow access to sensors on specific sites","description":"Define a list of sites, based on URL patterns, that can access and use sensors such as motion and light sensors.\n\nIf you don't configure this policy, the global default value from the \"DefaultSensorsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor URL patterns that don't match this policy, the following order of precedence is used: The \"SensorsBlockedForUrls\" policy (if there is a match), the \"DefaultSensorsSetting\" policy (if set), or the user's personal settings.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"SensorsBlockedForUrls\" policy. You can't allow and block a URL.\n\nFor detailed information about valid URL patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sensorsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_sensorsblockedforurls","displayName":"Block access to sensors on specific sites","description":"Define a list of sites, based on URL patterns, that can't access sensors such as motion and light sensors.\n\nIf you don't configure this policy, the global default value from the \"DefaultSensorsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor URL patterns that don't match this policy, the following order of precedence is used: The \"SensorsAllowedForUrls\" policy (if there is a match), the \"DefaultSensorsSetting\" policy (if set), or the user's personal settings.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"SensorsAllowedForUrls\" policy. You can't allow and block a URL.\n\nFor detailed information about valid URL patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sensorsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_serialallowallportsforurls","displayName":"Automatically grant sites permission to connect all serial ports","description":"Setting the policy allows you to list sites which are automatically granted permission to access all available serial ports.\n\nThe URLs must be valid, or the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered.\n\nThis policy overrides \"DefaultSerialGuardSetting\", \"SerialAskForUrls\", \"SerialBlockedForUrls\" and the user's preferences.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#serialallowallportsforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_serialaskforurls","displayName":"Allow the Serial API on specific sites","description":"Specifies URL patterns for sites that are allowed to request access to a serial port.\n\nIf not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings.\n\nFor unmatched sites, the following order applies:\n\n1. \"SerialBlockedForUrls\" (if matched).\n\n2. DefaultSerialGuardSetting (if set).\n\n3. User's settings.\n\nIf URL patterns in this policy conflict with those in \"SerialBlockedForUrls\", they will be ignored.\n\nFor detailed information about valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#serialaskforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_serialblockedforurls","displayName":"Block the Serial API on specific sites","description":"Specifies URL patterns for sites that aren't allowed to request access to a serial port.\n\nIf not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings.\n\nFor unmatched sites, the following order applies:\n\n1. SerialAskForUrls (if matched).\n\n2. DefaultSerialGuardSetting (if set).\n\n3. User's settings.\n\nURL patterns in this policy must not conflict with those in SerialAskForUrls. This policy takes precedence.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#serialblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup","description":"This policy controls whether Microsoft Edge enables the ServiceWorkerAutoPreload feature.\n\nWhen enabled or not configured, Microsoft Edge may initiate the main resource network request concurrently with the Service Worker bootstrap process. This can improve performance in scenarios where the Service Worker isn't already running.\n\nIf you disable this policy, Microsoft Edge will wait to dispatch the navigation request until after the Service Worker has started.\n\nThis is a temporary policy and will be removed in version 144 of Microsoft Edge.\n\nFor more information on the feature, see https://github.com/WICG/service-worker-auto-preload.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#serviceworkerautopreloadenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_serviceworkerautopreloadenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_serviceworkerautopreloadenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_serviceworkertocontrolsrcdociframeenabled","displayName":"Allow ServiceWorker to control srcdoc iframes","description":"https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with the \"allow-same-origin\" sandbox attribute to be under ServiceWorker control.\n\nBy default (if left unset) or when set to Enabled, Microsoft Edge makes srcdoc iframes with \"allow-same-origin\" sandbox attributes to be under ServiceWorker control.\n\nSetting the policy to Disabled prevents ServiceWorker control over srcdoc iframes.\n\nThis policy is temporary and planned for deprecation in 2026.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#serviceworkertocontrolsrcdociframeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_serviceworkertocontrolsrcdociframeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_serviceworkertocontrolsrcdociframeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sharebrowsinghistorywithcopilotsearchallowed","displayName":"Allow sharing tenant-approved browsing history with Microsoft 365 Copilot Search","description":"This policy controls whether browsing history in Microsoft Edge is shared with Microsoft 365 Copilot Search to provide more relevant search results. Only tenant-approved, work-related sites are shared.\n\nThis feature is available only to users who are signed in to Microsoft Edge with an Entra ID account and have an eligible Microsoft 365 Copilot license.\n\nIf you enable or don't configure this policy, browsing history will be shared with Microsoft 365 Copilot Search by default, and users can turn off sharing using the toggle in Microsoft Edge settings.\n\nIf you disable this policy, browsing history won't be shared with Microsoft 365 Copilot Search.\n\nLearn more about how Copilot uses data and consent at https://go.microsoft.com/fwlink/?linkid=2333202","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sharebrowsinghistorywithcopilotsearchallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sharebrowsinghistorywithcopilotsearchallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sharebrowsinghistorywithcopilotsearchallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sharedarraybufferunrestrictedaccessallowed","displayName":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context","description":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context. A SharedArrayBuffer is a binary data buffer that can be used to create views on shared memory. SharedArrayBuffers have a memory access vulnerability in several popular CPUs.\n\nIf you enable this policy, sites are allowed to use SharedArrayBuffers with no restrictions.\n\nIf you disable or don't configure this policy, sites are allowed to use SharedArrayBuffers only when cross-origin isolated.\n\nMicrosoft Edge will require cross-origin isolation when using SharedArrayBuffers from Microsoft Edge 91 onward for Web Compatibility reasons.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sharedarraybufferunrestrictedaccessallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sharedarraybufferunrestrictedaccessallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sharedarraybufferunrestrictedaccessallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sharedlinksenabled","displayName":"Show links shared from Microsoft 365 apps in History","description":"Allows Microsoft Edge to display links recently shared by or shared with the user from Microsoft 365 apps in History.\n\nIf you enable or don't configure this policy, Microsoft Edge displays links recently shared by or shared with the user from Microsoft 365 apps in History.\n\nIf you disable this policy, Microsoft Edge does not display links recently shared by or shared with the user from Microsoft 365 apps in History. The control in Microsoft Edge settings is disabled and set to off.\n\nThis policy only applies for Microsoft Edge local user profiles and profiles signed in using Azure Active Directory.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sharedlinksenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sharedlinksenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sharedlinksenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sharedworkerbloburlfixenabled","displayName":"Make SharedWorker blob URL behavior aligned with the specification","description":"According to Service Worker specification\nhttps://w3c.github.io/ServiceWorker/#control-and-use-worker-client, workers\nshould inherit controllers for blob URLs. Currently, only DedicatedWorkers\ninherit the controller, while SharedWorkers do not.\n\nEnabled/Unset: Microsoft Edge inherits\nthe controller for SharedWorker blob URLs, aligning with the specification.\n\nDisabled: Behavior remains unchanged, not aligning with the specification.\n\nThis policy is temporary and will be removed in a future update.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sharedworkerbloburlfixenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sharedworkerbloburlfixenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sharedworkerbloburlfixenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sharepointonpremfrontdoorurl","displayName":"SharePoint Server Front Door URL","description":"Specifies the SharePoint Server 2019 on-premises URL that the OneDrive sync app should try to authenticate and sync against.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#sharepointonpremfrontdoorurl"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_sharepointonpremprioritizationpolicy","displayName":"SharePoint Prioritization","description":"For hybrid scenarios where the email is the same for both SharePoint Server on-premises and SharePoint Online, determines whether or not the client should set up sync for SharePoint Server or SharePoint Online first during the first-run scenario.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#sharepointonpremprioritizationpolicy"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_sharepointonpremprioritizationpolicy_0","displayName":"Prioritize SharePoint Online","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sharepointonpremprioritizationpolicy_1","displayName":"Prioritize SharePoint Server","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sharepointonpremtenantname","displayName":"SharePoint Server Tenant Name","description":"Specifies the name of the folder created for syncing the SharePoint Server 2019 files specified in the Front Door URL.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#sharepointonpremtenantname"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_showacrobatsubscriptionbutton","displayName":"Shows button on native PDF viewer in Microsoft Edge that allows users to sign up for Adobe Acrobat subscription","description":"This policy lets the native PDF viewer in Microsoft Edge show a button that lets a user looking for advanced digital document features to discover and subscribe to premium offerings. This is done via the Acrobat extension.\n\nIf you enable or don't configure this policy, the button will show up on the native PDF viewer in Microsoft Edge. A user will be able to buy Adobe subscription to access their premium offerings.\n\nIf you disable this policy, the button won't be visible on the native PDF viewer in Microsoft Edge. A user won't be able to discover Adobe's advanced PDF tools or buy their subscriptions.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showacrobatsubscriptionbutton"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showacrobatsubscriptionbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showacrobatsubscriptionbutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showcasticonintoolbar","displayName":"Show the cast icon in the toolbar","description":"Set this policy to true to show the Cast toolbar icon on the toolbar or the overflow menu. Users won't be able to remove it.\n\nIf you don't configure this policy or if you disable it, users can pin or remove the icon by using its contextual menu.\n\nIf you've also set the \"EnableMediaRouter\" policy to false, then this policy is ignored, and the toolbar icon isn't shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showcasticonintoolbar"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showcasticonintoolbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showcasticonintoolbar_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showdocstageonlaunch","displayName":"Show Template Gallery on app launch","description":"Show the template picker when launching Word, Excel, and PowerPoint.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-office"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_showdocstageonlaunch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showdocstageonlaunch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showdownloadsinsecurewarningsenabled","displayName":"Enable insecure download warnings","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\n\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user will receive a UI warning, such as \"Insecure download blocked.\" The user will still have an option to proceed and download the item.\n\nIf you disable this policy, the warnings for insecure downloads will be suppressed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showdownloadsinsecurewarningsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showdownloadsinsecurewarningsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showdownloadsinsecurewarningsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showdownloadstoolbarbutton","displayName":"Show Downloads button on the toolbar","description":"Set this policy to always show the Downloads button on the toolbar.\n\nIf you enable this policy, the Downloads button is pinned to the toolbar.\n\nIf you disable or don't configure the policy, the Downloads button isn't shown on the toolbar by default. Users can toggle the Downloads button in edge://settings/appearance.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showdownloadstoolbarbutton"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showdownloadstoolbarbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showdownloadstoolbarbutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showhistorythumbnails","displayName":"Show thumbnail images for browsing history","description":"This policy lets you configure whether the history thumbnail feature collects and saves images for the sites you visit. When enabled, this feature makes it easier to identify sites when you hover over your history results.\nIf you don't configure this policy, the thumbnail feature is turned on after a user visits the history hub twice in the past 7 days.\nIf you enable this policy, the history thumbnail collects and saves images for visited sites.\nIf you disable this policy, the history thumbnail doesn't collect and save images for visited sites.\nWhen the feature is disabled, existing images are deleted on a per user basis, and the feature no longer collects or saves images when a site is visited.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showhistorythumbnails"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showhistorythumbnails_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showhistorythumbnails_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showhomebutton","displayName":"Show Home button on toolbar","description":"Shows the Home button on Microsoft Edge's toolbar.\n\nEnable this policy to always show the Home button. Disable it to never show the button.\n\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showhomebutton"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showhomebutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showhomebutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showmicrosoftrewards","displayName":"Show Microsoft Rewards experiences","description":"Show Microsoft Rewards experience and notifications.\nIf you enable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\n - The setting to enable Give mode will be enabled and respect the user's setting.\n\nIf you disable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will not see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be disabled and toggled off.\n\nIf you don't configure this policy:\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\n - The setting to enable Give mode will be enabled and respect the user's setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showmicrosoftrewards"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showmicrosoftrewards_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showmicrosoftrewards_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showofficeshortcutinfavoritesbar","displayName":"Show Microsoft Office shortcut in favorites bar","description":"Specifies whether to include a shortcut to Office.com in the favorites bar. For users signed into Microsoft Edge the shortcut takes users to their Microsoft Office apps and docs.\n\nIf this policy is enabled or not configure, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu.\n\nIf the policy is disabled, the shortcut won't be shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showofficeshortcutinfavoritesbar"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showofficeshortcutinfavoritesbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showofficeshortcutinfavoritesbar_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showpdfdefaultrecommendationsenabled","displayName":"Allow notifications to set Microsoft Edge as default PDF reader","description":"This policy setting lets you decide whether employees should receive recommendations to set Microsoft Edge as PDF handler.\n\nIf you enable or don't configure this setting, employees receive recommendations from Microsoft Edge to set itself as the default PDF handler.\n\nIf you disable this setting, employees will not receive any notifications from Microsoft Edge to set itself as the default PDF handler.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showpdfdefaultrecommendationsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showpdfdefaultrecommendationsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showpdfdefaultrecommendationsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showrecommendationsenabled","displayName":"Allow feature recommendations and browser assistance notifications from Microsoft Edge","description":"This setting controls the in-browser assistance notifications which are intended to help users get the most out of Microsoft Edge. This is done by recommending features and by helping them use browser features. These notifications take the form of dialog boxes, flyouts, coach marks and banners in the browser. An example of an assistance notification would be when a user has many tabs opened in the browser. In this instance Microsoft Edge may prompt the user to try out the vertical tabs feature which is designed to give better browser tab management.\n\nDisabling this policy will stop this message from appearing again even if the user has too many tabs open.\n Any features that have been disabled by a management policy are not suggested to users.\nIf you enable or don't configure this setting, users will receive recommendations or notifications from Microsoft Edge.\n If you disable this setting, users will not receive any recommendations or notifications from Microsoft Edge","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showrecommendationsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showrecommendationsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showrecommendationsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showtabpreviewenabled","displayName":"Enable tab preview on hover","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\n\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\n\nIf you disable this policy, tab previews will not be shown on hover.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showtabpreviewenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showtabpreviewenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showtabpreviewenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_showwhatsnewonlaunch","displayName":"Show Whats New dialog","description":"Show the monthly Whats New dialog to users.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-office"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_showwhatsnewonlaunch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showwhatsnewonlaunch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support","description":"Enable support for Signed HTTP Exchange (SXG).\n\nIf this policy isn't set or enabled, Microsoft Edge will accept web contents served as Signed HTTP Exchanges.\n\nIf this policy is set to disabled, Signed HTTP Exchanges can't be loaded.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#signedhttpexchangeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_signedhttpexchangeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_signedhttpexchangeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_silentprintingenabled","displayName":"Enable Silent Printing","description":"This policy controls whether Microsoft Edge uses silent printing.\n\nIf you enable this policy, Edge automatically closes the print preview window and prints to the default printer using its default settings. If the default printer is Save as PDF, the file is saved to the user's Downloads folder.\n\nIf you disable or don't configure this policy, silent printing is disabled. The print preview window stays open and the user must choose print settings as usual.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#silentprintingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_silentprintingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_silentprintingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_siteperprocess","displayName":"Enable site isolation for every site","description":"The 'SitePerProcess' policy can be used to prevent users from opting out of the default behavior of isolating all sites. Note that you can also use the \"IsolateOrigins\" policy to isolate additional, finer-grained origins.\nIf you enable this policy, users can't opt out of the default behavior where each site runs in its own process.\nIf you disable or don’t configure this policy, a user can opt out of site isolation. (For example, by using \"Disable site isolation\" entry in edge://flags.) Disabling the policy or not configuring the policy doesn't turn off Site Isolation.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#siteperprocess"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_siteperprocess_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_siteperprocess_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sleepingtabsblockedforurls","displayName":"Block Sleeping Tabs on specific sites","description":"Define a list of sites, based on URL patterns, that are not allowed to be put to sleep by Sleeping Tabs.\n\nIf the policy \"SleepingTabsEnabled\" is disabled, this list is not used and no sites will be put to sleep automatically.\n\nIf you don't configure this policy, all sites will be eligible to be put to sleep unless the user's personal configuration blocks them.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sleepingtabsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_sleepingtabsenabled","displayName":"Configure Sleeping Tabs","description":"This policy setting lets you configure whether to turn on Sleeping Tabs. Sleeping Tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, Sleeping Tabs is turned on.\n\nIndividual sites may be blocked from being put to sleep by configuring the policy \"SleepingTabsBlockedForUrls\".\n\nIf you enable this setting, Sleeping Tabs is turned on.\n\nIf you disable this setting, Sleeping Tabs is turned off.\n\nIf you don't configure this setting, users can choose whether to use Sleeping Tabs.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sleepingtabsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sleepingtabsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if Sleeping Tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\n\nTabs are only put to sleep automatically when the policy \"SleepingTabsEnabled\" is enabled or is not configured and the user has enabled the Sleeping Tabs setting.\n\nIf you don't configure this policy, users can choose the timeout value.\n\nPolicy options mapping:\n\n* 5Minutes (300) = 5 minutes of inactivity\n\n* 15Minutes (900) = 15 minutes of inactivity\n\n* 30Minutes (1800) = 30 minutes of inactivity\n\n* 1Hour (3600) = 1 hour of inactivity\n\n* 2Hours (7200) = 2 hours of inactivity\n\n* 3Hours (10800) = 3 hours of inactivity\n\n* 6Hours (21600) = 6 hours of inactivity\n\n* 12Hours (43200) = 12 hours of inactivity\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sleepingtabstimeout"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_0","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_1","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_2","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_3","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_4","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_5","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_6","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_7","displayName":"12 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_8","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_smartactionsblocklist","displayName":"Block smart actions for a list of services","description":"List specific services, such as PDFs, and websites that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\n\nIf you enable the policy:\n - The smart action in the mini and full context menu will be disabled for all profiles for services that match the given list.\n - Users will not see the smart action in the mini and full context menu on text selection for services that match the given list.\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be disabled for services that match the given list.\n\nIf you disable or don't configure this policy:\n - The smart action in the mini and full context menu will be enabled for all profiles.\n - Users will see the smart action in the mini and full context menu on text selection.\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be enabled.\n\nPolicy options mapping:\n\n* smart_actions (smart_actions) = Smart actions in pdfs and on websites\n\n* smart_actions_website (smart_actions_website) = Smart actions on websites\n\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartactionsblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_smartscreenallowlistdomains","displayName":"Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings","description":"Configure the list of Microsoft Defender SmartScreen trusted domains. This means:\nMicrosoft Defender SmartScreen won't check for potentially malicious resources like phishing software and other malware if the source URLs match these domains.\nThe Microsoft Defender SmartScreen download protection service won't check downloads hosted on these domains.\n\nIf you enable this policy, Microsoft Defender SmartScreen trusts these domains.\nIf you disable or don't set this policy, default Microsoft Defender SmartScreen protection is applied to all resources.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender Advanced Threat Protection. You must configure your allow and block lists in Microsoft Defender Security Center instead.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartscreenallowlistdomains"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_smartscreendnsrequestsenabled","displayName":"Enable Microsoft Defender SmartScreen DNS requests","description":"This policy lets you configure whether to enable DNS requests made by Microsoft Defender SmartScreen. Note: Disabling DNS requests will prevent Microsoft Defender SmartScreen from getting IP addresses, and potentially impact the IP-based protections provided.\n\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen will make DNS requests.\n\nIf you disable this setting, Microsoft Defender SmartScreen will not make any DNS requests.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartscreendnsrequestsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_smartscreendnsrequestsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smartscreendnsrequestsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_smartscreenenabled","displayName":"Configure Microsoft Defender SmartScreen","description":"This policy setting lets you configure whether to turn on Microsoft Defender SmartScreen. Microsoft Defender SmartScreen provides warning messages to help protect your users from potential phishing scams and malicious software. By default, Microsoft Defender SmartScreen is turned on.\n\nIf you enable this setting, Microsoft Defender SmartScreen is turned on.\n\nIf you disable this setting, Microsoft Defender SmartScreen is turned off.\n\nIf you don't configure this setting, users can choose whether to use Microsoft Defender SmartScreen.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartscreenenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_smartscreenenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smartscreenenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_smartscreenpuaenabled","displayName":"Configure Microsoft Defender SmartScreen to block potentially unwanted apps","description":"This policy setting lets you configure whether to turn on blocking for potentially unwanted apps in Microsoft Defender SmartScreen. Potentially unwanted app blocking in Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking in Microsoft Defender SmartScreen is turned off by default.\n\nIf you enable this setting, potentially unwanted app blocking in Microsoft Defender SmartScreen is turned on.\n\nIf you disable this setting, potentially unwanted app blocking in Microsoft Defender SmartScreen is turned off.\n\nIf you don't configure this setting, users can choose whether to use potentially unwanted app blocking in Microsoft Defender SmartScreen.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartscreenpuaenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_smartscreenpuaenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smartscreenpuaenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder","displayName":"Set the order in which S/MIME certificates are considered","description":"Set the order in which certificates will be used to decrypt and encrypt S/MIME messages.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#set-the-order-in-which-smime-certificates-are-considered"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_0","displayName":"Contacts","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_1","displayName":"Global Address List","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_2","displayName":"Device","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_3","displayName":"LDAP","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_speechrecognitionenabled","displayName":"Configure Speech Recognition","description":"Set whether websites can use the W3C Web Speech API to recognize speech from the user. The Microsoft Edge implementation of the Web Speech API uses Azure Cognitive Services, so voice data will leave the machine.\n\nIf you enable or don't configure this policy, web-based applications that use the Web Speech API can use Speech Recognition.\n\nIf you disable this policy, Speech Recognition is not available through the Web Speech API.\n\nRead more about this feature here:\nSpeechRecognition API: https://go.microsoft.com/fwlink/?linkid=2143388\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2143680","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#speechrecognitionenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_speechrecognitionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_speechrecognitionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_spellcheckenabled","displayName":"Enable spellcheck","description":"If you enable or don't configure this policy, the user can use spellcheck.\n\nIf you disable this policy, the user can't use spellcheck and the \"SpellcheckLanguage\" and \"SpellcheckLanguageBlocklist\" policies are also disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#spellcheckenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_spellcheckenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_spellcheckenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_splitscreenenabled","displayName":"Enable split screen feature in Microsoft Edge","description":"This policy lets you configure the split screen feature in Microsoft Edge. This feature lets a user open two web pages in one tab.\n\nIf you enable or don't configure this policy, users can use the split screen feature in Microsoft Edge.\n\nIf you disable this policy, users can't use the split screen feature in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#splitscreenenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_splitscreenenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_splitscreenenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sslerroroverrideallowed","displayName":"Allow users to proceed from the HTTPS warning page","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure (default) this policy, users can click through these warning pages.\n\nIf you disable this policy, users are blocked from clicking through any warning page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sslerroroverrideallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sslerroroverrideallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sslerroroverrideallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_sslerroroverrideallowedfororigins","displayName":"Allow users to proceed from the HTTPS warning page for specific origins","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure the \"SSLErrorOverrideAllowed\" policy, this policy does nothing.\n\nIf you disable the \"SSLErrorOverrideAllowed\" policy, configuring this policy lets you configure a list of origin patterns for sites where users can continue to click through SSL error pages. Users can't click through SSL error pages on origins that are not on this list.\n\nIf you don't configure this policy, the \"SSLErrorOverrideAllowed\" policy applies for all sites.\n\nFor detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy. This policy only matches based on origin, so any path or query in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sslerroroverrideallowedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_sslversionmin","displayName":"Minimum TLS version enabled","description":"Sets the minimum supported version of SSL. If you don't configure this policy, Microsoft Edge uses a default minimum version, TLS 1.0.\n\nIf you enable this policy, you can set the minimum version to one of the following values: \"tls1\", \"tls1.1\" or \"tls1.2\". When set, Microsoft Edge won't use any version of SSL/TLS lower than the specified version. Any unrecognized value is ignored.\n\n* \"tls1\" = TLS 1.0\n\n* \"tls1.1\" = TLS 1.1\n\n* \"tls1.2\" = TLS 1.2","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sslversionmin"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sslversionmin_0","displayName":"TLS 1.0","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sslversionmin_1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sslversionmin_2","displayName":"TLS 1.2","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_startdaemononapplaunch","displayName":"Register app on launch","description":"Force Office apps to register with AutoUpdate on each launch.","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_startdaemononapplaunch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_startdaemononapplaunch_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_strictermixedcontenttreatmentenabled","displayName":"Enable stricter treatment for mixed content","description":"This policy controls the treatment for mixed content (HTTP content in HTTPS sites) in the browser.\n\nIf you set this policy to true or not set, audio and video mixed content will be automatically upgraded to HTTPS (that is, the URL will be rewritten as HTTPS, without a fallback if the resource isn’t available over HTTPS) and a 'Not Secure' warning will be shown in the URL bar for image mixed content.\n\nIf you set the policy to false, auto upgrades will be disabled for audio and video, and no warning will be shown for images.\n\nThis policy does not affect other types of mixed content other than audio, video, and images.\n\nThis policy will no longer take effect starting in Microsoft Edge 84.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#strictermixedcontenttreatmentenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_strictermixedcontenttreatmentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_strictermixedcontenttreatmentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_suppresso365autodiscoveroverride","displayName":"Use domain-based autodiscover instead of Office 365","description":"When true, autodiscover will contact the endpoint for the mailbox domain instead of the Office 365 service. This is recommended for on-premises Exchange mailboxes.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_suppresso365autodiscoveroverride_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_suppresso365autodiscoveroverride_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_suppressunsupportedoswarning","displayName":"Suppress the unsupported OS warning","description":"Suppresses the warning that appears when Microsoft Edge is running on a computer or operating system that is no longer supported.\n\nIf this policy is false or unset, the warnings will appear on such unsupported computers or operating systems.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#suppressunsupportedoswarning"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_suppressunsupportedoswarning_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_suppressunsupportedoswarning_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_switchintranetsitestoworkprofile","displayName":"Switch intranet sites to a work or school profile","description":"Allows Microsoft Edge to switch to the appropriate profile when Microsoft Edge detects that a URL is the intranet.\n\nIf you enable or don't configure this policy, navigations to intranet URLs will switch to the most recently used work or school profile if one exists.\n\nIf you disable this policy, navigations to intranet URLs will remain in the current browser profile.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#switchintranetsitestoworkprofile"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_switchintranetsitestoworkprofile_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_switchintranetsitestoworkprofile_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_syncdisabled","displayName":"Disable synchronization of data using Microsoft sync services","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\n\nIf you don't set this policy or apply it as recommended, users will be able to turn sync on or off. If you apply this policy as mandatory, users will not be able to turn sync on.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#syncdisabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_syncdisabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_syncdisabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_synctypeslistdisabled","displayName":"Configure the list of types that are excluded from synchronization","description":"If you enable this policy all the specified data types will be excluded from synchronization. This policy can be used to limit the type of data uploaded to the Microsoft Edge synchronization service.\n\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", and “collections”. Note that these data type names are case sensitive.\n\nUsers will not be able to override the disabled data types.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#synctypeslistdisabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_systemextensions","displayName":"Use System Extensions","description":"Whether system extensions are used on MacOS 10.15 (Catalina) or not.","helpText":null,"infoUrls":["https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-atp-for-mac-is-moving-to-system-extensions/ba-p/1608736"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_systemextensions_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_systemextensions_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_tabcaptureallowedbyorigins","displayName":"Allow Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Tab Capture.\n\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\n\nThis policy is not considered if a site matches a URL pattern in the \"SameOriginTabCaptureAllowedByOrigins\" policy.\n\nIf a site matches a URL pattern in this policy, the following policies will not be considered: \"WindowCaptureAllowedByOrigins\", \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tabcaptureallowedbyorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_tabfreezingenabled","displayName":"Allow freezing of background tabs","description":"Controls whether Microsoft Edge can freeze tabs that are in the background for at least 5 minutes.\n\nTab freezing reduces CPU, battery, and memory usage. Microsoft Edge uses heuristics to avoid freezing tabs that do useful work in the background, such as display notifications, play sound, and stream video.\n\nIf you enable or don't configure this policy, tabs that have been in the background for at least 5 minutes might be frozen.\n\nIf you disable this policy, no tabs will be frozen.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tabfreezingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_tabfreezingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_tabfreezingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_tabservicesenabled","displayName":"Enable tab organization suggestions","description":"This policy controls whether Microsoft Edge can use its tab organization service to help name or suggest tab groups to increase productivity.\n\nIf you enable or don't configure this policy, when a user creates a tab group or activates certain \"Group Similar Tabs\" features Microsoft Edge sends tab data to its tab organization service. This data includes URLs, page titles, and existing group information. The service uses this data to return suggestions for better groupings and group names.\n\nIf you disable this policy, no data will be sent to the tab organization service. Microsoft Edge won't suggest group names when a group is created and certain \"Group Similar Tabs\" features that rely on the service won't be available.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tabservicesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_tabservicesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_tabservicesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_tags","displayName":"Device tags","description":null,"helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#device-tags"],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":null},{"id":"com.apple.managedclient.preferences_tags_item_key","displayName":"Type of tag","description":"Specify a tag name and its value. The GROUP tag, tags the device with the specified value. The tag is reflected in the portal under the device page and can be used for filtering and grouping devices.","helpText":null,"infoUrls":[],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":{"id":"com.apple.managedclient.preferences_tags_item_key_0","displayName":"GROUP","description":null,"helpText":null}},{"id":"com.apple.managedclient.preferences_tags_item_value","displayName":"Value of tag","description":"Only one value per tag type can be set. Type of tags are unique, and should not be repeated in the same configuration profile.","helpText":null,"infoUrls":[],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":null},{"id":"com.apple.managedclient.preferences_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank","description":"If you enable this policy or leave it unset, the window.opener property is set to null unless the anchor specifies rel=\"opener\".\n\nIf you disable this policy, popups that target _blank are permitted to access (via JavaScript) the page that requested to open the popup.\n\nThis policy will be obsoleted in Microsoft Edge version 95.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#targetblankimpliesnoopener"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_targetblankimpliesnoopener_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_targetblankimpliesnoopener_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_taskmanagerendprocessenabled","displayName":"Enable ending processes in the Browser task manager","description":"If you enable or don't configure this policy, users can end processes in the Browser task manager. If you disable it, users can't end processes, and the End process button is disabled in the Browser task manager.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#taskmanagerendprocessenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_taskmanagerendprocessenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_taskmanagerendprocessenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_textpredictionenabled","displayName":"Text prediction enabled by default","description":"The Microsoft Turing service uses natural language processing to generate predictions for long-form editable text fields on web pages.\n\nIf you enable or don't configure this policy, text predictions will be provided for eligible text fields.\n\nIf you disable this policy, text predictions will not be provided in eligible text fields. Sites may still provide their own text predictions.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#textpredictionenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_textpredictionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_textpredictionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_thirdpartystoragepartitioningblockedfororigins","displayName":"Disable third-party storage partitioning for specific top-level origins (deprecated)","description":"This policy lets you set a list of URL patterns that specify top-level origins for which third-party storage partitioning (partitioning of cross-origin iframe storage) should be disabled.\n\nIf this policy isn't set or a top-level origin doesn't match one of the URL patterns, then the value from \"DefaultThirdPartyStoragePartitioningSetting\" will be used.\n\nNote that the patterns you list are treated as origins, not URLs, so you shouldn't specify a path. For detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nThis feature will be removed starting in Microsoft Edge version 145. To ensure compatibility, use the requestStorageAccess method instead. For more information, see https://developer.mozilla.org/en-US/docs/Web/API/Document/requestStorageAccess.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#thirdpartystoragepartitioningblockedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_threattypesettings","displayName":"Threat type settings","description":"The threatTypeSettings preference in the antivirus engine is used to control how certain threat types are handled by the product.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#threat-type-settings"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},{"id":"com.apple.managedclient.preferences_threattypesettings_item_key","displayName":"Threat type","description":"Type of the threat for which the behavior is configured.","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_threattypesettings_item_key_0","displayName":"potentially_unwanted_application","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_threattypesettings_item_key_1","displayName":"archive_bomb","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_threattypesettings_item_value","displayName":"Action to take","description":"Action to take when coming across a threat of the type specified in the preceding section.","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_threattypesettings_item_value_0","displayName":"audit","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_threattypesettings_item_value_1","displayName":"block","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_threattypesettings_item_value_2","displayName":"off","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_threattypesettingsmergepolicy","displayName":"Threat type settings merge","description":"Specify the merge policy for threat type settings. This can be a combination of administrator-defined and user-defined settings (merge) or only administrator-defined settings (admin_only). This setting can be used to restrict local users from defining their own settings for different threat types.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#threat-type-settings-merge-policy"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_threattypesettingsmergepolicy_0","displayName":"merge","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_threattypesettingsmergepolicy_1","displayName":"admin_only","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_tls13earlydataenabled","displayName":"Control whether TLS 1.3 Early Data is enabled in Microsoft Edge","description":"This policy controls whether TLS 1.3 Early Data is enabled in Microsoft Edge.\n\nTLS 1.3 Early Data is an extension that allows an HTTP request to be sent in parallel with the TLS handshake. When enabled and supported by the server, this can improve page load performance.\n\nEnabled – Microsoft Edge enables TLS 1.3 Early Data.\n\nDisabled – Microsoft Edge disables TLS 1.3 Early Data.\n\nNot configured – Microsoft Edge follows the default rollout process for TLS 1.3 Early Data.\n\nNOTE: When this feature is enabled, whether TLS 1.3 Early Data is used depends on server support. Most modern TLS servers and middleware can handle or reject Early Data without interrupting the connection. However, improperly implemented TLS stacks may cause connection failures. If such issues occur, contact the device or software vendor for a resolution.\n\nThis policy is temporary and intended to help test for compatibility issues. It may be removed in a future release once the feature is fully rolled out.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tls13earlydataenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_tls13earlydataenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_tls13earlydataenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors.","description":"This policy controls a security feature in TLS 1.3 that protects connections against downgrade attacks. It is backwards-compatible and will not affect connections to compliant TLS 1.2 servers or proxies. However, older versions of some TLS-intercepting proxies have an implementation flaw which causes them to be incompatible.\n\nIf you set this policy to True, Microsoft Edge will enable these security protections for all connections.\n\nIf you set this policy to False or don’t set it, Microsoft Edge will disable these security protections for connections authenticated with locally-installed CA certificates. These protections are always enabled for connections authenticated with publicly-trusted CA certificates.\n\nThis policy may be used to test for any affected proxies and upgrade them. Affected proxies are expected to fail connections with an error code of ERR_TLS13_DOWNGRADE_DETECTED. A later version of Microsoft Edge will enable this option by default.\n\nAfter it is enabled by default, administrators who need more time to upgrade affected proxies may use this policy to temporarily disable this security feature. This policy will be removed after version 85.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tls13hardeningforlocalanchorsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_tls13hardeningforlocalanchorsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_tls13hardeningforlocalanchorsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_tlsciphersuitedenylist","displayName":"Specify the TLS cipher suites to disable","description":"Configure the list of cipher suites that are disabled for TLS connections.\n\nIf you configure this policy, the list of configured cipher suites will not be used when establishing TLS connections.\n\nIf you don't configure this policy, the browser will choose which TLS cipher suites to use.\n\nCipher suite values to be disabled are specified as 16-bit hexadecimal values. The values are assigned by the Internet Assigned Numbers Authority (IANA) registry.\n\nThe TLS 1.3 cipher suite TLS_AES_128_GCM_SHA256 (0x1301) is required for TLS 1.3 and can't be disabled by this policy.\n\nThis policy does not affect QUIC-based connections. QUIC can be turned off via the \"QuicAllowed\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tlsciphersuitedenylist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_totalmemorylimitmb","displayName":"Set limit on megabytes of memory a single Microsoft Edge instance can use.","description":"Configures the amount of memory that a single Microsoft Edge instance can use before tabs start getting discarded to save memory. The memory used by the tab will be freed and the tab will have to be reloaded when switched to.\n\nIf you enable this policy, the browser will start to discard tabs to save memory once the limitation is exceeded. However, there is no guarantee that the browser is always running under the limit. Any value under 1024 will be rounded up to 1024.\n\nIf you don't set this policy, the browser will only attempt to save memory when it has detected that the amount of physical memory on its machine is low.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#totalmemorylimitmb"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_trackingprevention","displayName":"Block tracking of users' web-browsing activity","description":"Lets you decide whether to block websites from tracking users' web-browsing activity.\n\nIf you enable this policy, you have the following options for setting the level of tracking prevention:\n\n* 0 = Off (no tracking prevention)\n\n* 1 = Basic (blocks harmful trackers, content and ads will be personalized)\n\n* 2 = Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)\n\n* 3 = Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)\n\nIf you disable this policy or don't configure it, users can set their own level of tracking prevention.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#trackingprevention"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_trackingprevention_0","displayName":"Off (no tracking prevention)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_trackingprevention_1","displayName":"Basic (blocks harmful trackers, content and ads will be personalized)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_trackingprevention_2","displayName":"Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_trackingprevention_3","displayName":"Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_translateenabled","displayName":"Enable Translate","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge offers translation functionality to the user by showing an integrated translate flyout when appropriate, and a translate option on the right-click context menu.\n\nDisable this policy to disable all built-in translate features.\n\nIf you don't configure the policy, users can choose whether to use the translation functionality or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#translateenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_translateenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_translateenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_trusto365autodiscoverredirect","displayName":"Trust Office 365 autodiscover redirects","description":"When true, users will not see a dialog if autodiscover redirects the client to a different server. Recommended: true.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_trusto365autodiscoverredirect_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_trusto365autodiscoverredirect_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_typosquattingallowlistdomains","displayName":"Configure the list of domains for which Edge Website Typo Protection won't trigger warnings","description":"Configure the list of Edge Website Typo Protection trusted domains. This means:\nEdge Website Typo Protection won't check for potentially malicious typosquatting websites.\n\nIf you enable this policy, Edge Website Typo Protection trusts these domains.\nIf you disable or don't set this policy, default Edge Website Typo Protection protection is applied to all resources.\n\nThis will only take effect when TyposquattingCheckerEnabled policy is not set or set to enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10/11 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender for Endpoint. You must configure your allow and block lists in Microsoft 365 Defender portal using Indicators (Settings > Endpoints > Indicators).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#typosquattingallowlistdomains"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_typosquattingcheckerenabled","displayName":"Configure Edge Website Typo Protection","description":"This policy setting lets you configure whether to turn on Edge Website Typo Protection. Edge Website Typo Protection provides warning messages to help protect your users from potential typosquatting sites. By default, Edge Website Typo Protection is turned on.\n\nIf you enable this policy, Edge Website Typo Protection is turned on.\n\nIf you disable this policy, Edge Website Typo Protection is turned off.\n\nIf you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#typosquattingcheckerenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_typosquattingcheckerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_typosquattingcheckerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_unthrottlednestedtimeoutenabled","displayName":"JavaScript setTimeout will not be clamped until a higher nesting threshold is set (deprecated)","description":"This policy is deprecated because it is a temporary policy for web standards compliance. It won't work in Microsoft Edge as soon as version 107.\nIf you enable this policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4ms, will not be clamped. This improves short horizon performance, but websites abusing the API will still eventually have their setTimeout usages clamped.\nIf you disable or don't configure policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4ms, will be clamped.\n\nThis is a web standards compliancy feature that may change task ordering on a web page, leading to unexpected behavior on sites that are dependent on a certain ordering.\nIt also may affect sites with a lot of usage of a timeout of 0ms for setTimeout. For example, increasing CPU load.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#unthrottlednestedtimeoutenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_unthrottlednestedtimeoutenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_unthrottlednestedtimeoutenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_updatecache","displayName":"Update cache server","description":"Specify the HTTP(S) URL of the server that you use for cached package updates (PKG files). You must include a trailing forward slash.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/deployoffice/mac/mau-preferences#updatecache"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_updatecheckfrequency","displayName":"Update check frequency (mins)","description":"Specify how often AutoUpdate checks for updates. The allowed range is 240 minutes (4 hours) - 720 minutes (12 hours).","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_updatedeadline.daysbeforeforcedquit","displayName":"Days before forced updates","description":"Specify the maximum number of days that an update can be pending before the user is forced to update the app. Set the value to 0 to disable forced updates.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/deployoffice/mac/mau-deadline"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_updatedeadline.finalcountdown","displayName":"Number of minutes for the final countdown timer","description":"Specify the number of minutes for the forced deadline countdown timer. The allowed range is 10 - 720 minutes (12 hours). The default is 60 minutes.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/deployoffice/mac/mau-deadline"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},{"id":"com.apple.managedclient.preferences_updatepolicyoverride","displayName":"Specifies how Microsoft Edge Update handles available updates from Microsoft Edge","description":"If you enable this policy, Microsoft Edge Update handles Microsoft Edge updates according to how you configure the following options:\n\n- Automatic silent updates only: Updates are applied only when they're found by the periodic update check.\n\n- Manual updates only: Updates are applied only when the user runs a manual update check. (Not all apps provide an interface for this option.)\n\nIf you select manual updates, make sure you periodically check for updates by using Microsoft Autoupdate.\n\nIf you don't enable and configure this policy, Microsoft Edge Update automatically checks for updates.\n\nPolicy options mapping:\n\n* automatic-silent-only (automatic-silent-only) = Updates are applied only when they're found by the periodic update check.\n\n* manual-only (manual-only) = Updates are applied only when the user runs a manual update check. (Not all apps provide an interface for this option.)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#updatepolicyoverride"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_updatepolicyoverride_0","displayName":"silent-only - Updates are applied only when they're found by the periodic update check.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_updatepolicyoverride_1","displayName":"only - Updates are applied only when the user runs a manual update check. (Not all apps provide an interface for this option.)","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_updateroptimization","displayName":"Updater optimization technique","description":"By default AutoUpdate will optimize for smaller packages on the network. However, this can cause larger CPU overheads when security agents (e.g. CrowdStrike) are installed. Alternatively, you can choose to lower the CPU overheads to process updates but accept larger download packages","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_updateroptimization_0","displayName":"Lower network overhead","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_updateroptimization_1","displayName":"Lower processor overhead","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_updateroptimization_2","displayName":"Always use full updates","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_uploadbandwidthlimited","displayName":"Set maximum upload throughput","description":"Sets the maximum upload throughput rate in kilobytes (KB)/sec for computers running the OneDrive sync app. The minimum rate is 50 KB/sec and the maximum rate is 100,000 KB/sec.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#uploadbandwidthlimited"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},{"id":"com.apple.managedclient.preferences_uploadfromphoneenabled","displayName":"Enable upload files from mobile in Microsoft Edge desktop","description":"This policy lets you configure the \"Upload from mobile\" feature in Microsoft Edge.\n\nUpload from mobile lets users select file from mobile devices to desktop when user upload file in a webpage in Microsoft Edge.\n\nIf you enable or don't configure this policy, you can use the Upload from mobile feature in Microsoft Edge.\n\nIf you disable this policy, you can't use the Upload from mobile feature in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#uploadfromphoneenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_uploadfromphoneenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_uploadfromphoneenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_urlallowlist","displayName":"Define a list of allowed URLs","description":"Allow access to the listed URLs, as exceptions to the URL block list.\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can use this policy to open exceptions to restrictive block lists. For example, you can include '*' in the block list to block all requests, and then use this policy to allow access to a limited list of URLs. You can use this policy to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths.\n\nThe most specific filter determines if a URL is blocked or allowed. The allowed list takes precedence over the block list.\n\nThis policy is limited to 1000 entries; subsequent entries are ignored.\n\nIf you don't configure this policy, there are no exceptions to the block list in the \"URLBlocklist\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#urlallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_urlblocklist","displayName":"Block access to a list of URLs","description":"Define a list of sites, based on URL patterns, that are blocked (your users can't load them).\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can define exceptions in the \"URLAllowlist\" policy. These policies are limited to 1000 entries; subsequent entries are ignored.\n\nNote that blocking internal 'edge://*' URLs isn't recommended - this may lead to unexpected errors.\n\nThis policy doesn't prevent the page from updating dynamically through JavaScript. For example, if you block 'contoso.com/abc', users might still be able to visit 'contoso.com' and click on a link to visit 'contoso.com/abc', as long as the page doesn't refresh.\n\nIf you don't configure this policy, no URLs are blocked.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#urlblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_useragentclienthintsenabled","displayName":"Enable the User-Agent Client Hints feature","description":"This policy is deprecated because it's only intended to be a short-term mechanism to give enterprises more time to update their web content if and when it's found to be incompatible with the User-Agent Client Hints feature. It won't work in Microsoft Edge version 89.\n\nWhen enabled the User-Agent Client Hints feature sends granular request headers that provide information about the user browser (for example, the browser version) and environment (for example, the system architecture).\n\nThis is an additive feature, but the new headers may break some websites that restrict the characters that requests may contain.\n\nIf you enable or don't configure this policy, the User-Agent Client Hints feature is enabled. If you disable this policy, this feature is unavailable.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#useragentclienthintsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_useragentclienthintsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_useragentclienthintsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_useragentreduction","displayName":"Enable or disable the User-Agent Reduction (deprecated)","description":"The User-Agent HTTP request header has been reduced by default since Microsoft Edge version 119. To continue receiving detailed platform information, migrate to User-Agent Client Hints, which replace the deprecated detailed User-Agent header. For more information, visit: https://web.dev/articles/migrate-to-ua-ch\n\nIf you don't configure this policy or set it to Default, the User-Agent header will be reduced and controlled by experimentation.\n\nSet this policy to 'ForceEnabled' to force the reduced version of the User-Agent request header for all origins.\n\nSet this policy to 'ForceDisabled' to always use the full (legacy) User-Agent header.\n\nTo learn more about the User-Agent string, read here:\n\nhttps://go.microsoft.com/fwlink/?linkid=2186267\n\nPolicy options mapping:\n\n* Default (0) = Reduced User Agent, or controlled by experimentation.\n\n* ForceDisabled (1) = Full (legacy) User Agent.\n\n* ForceEnabled (2) = Reduced User Agent.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#useragentreduction"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_useragentreduction_0","displayName":"Reduced User Agent, or controlled by experimentation.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_useragentreduction_1","displayName":"Full (legacy) User Agent.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_useragentreduction_2","displayName":"Reduced User Agent.","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_userdatadir","displayName":"Set the user data directory","description":"Set the directory to use for storing user data.\n\nIf you enable this policy, Microsoft Edge uses the specified directory regardless of whether the user has set the '--user-data-dir' command-line flag.\n\nIf you don't enable this policy, the default profile path is used, but the user can override it by using the '--user-data-dir' flag. Users can find the directory for the profile at edge://version/ under profile path.\n\nTo avoid data loss or other errors, don't configure this policy to a volume's root directory or to a directory that's used for other purposes, because Microsoft Edge manages its contents.\n\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#userdatadir"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_userfeedbackallowed","displayName":"Allow user feedback","description":"Microsoft Edge uses the Edge Feedback feature (enabled by default) to allow users to send feedback, suggestions or customer surveys and to report any issues with the browser. Also, by default, users can't disable (turn off) the Edge Feedback feature.\n\nIf you enable this policy or don't configure it, users can invoke Edge Feedback.\n\nIf you disable this policy, users can't invoke Edge Feedback.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#userfeedbackallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_userfeedbackallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userfeedbackallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_userinitiatedfeedback","displayName":"User initiated feedback","description":"Specify whether users can submit feedback to Microsoft by going to Help > Send Feedback.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#diagnostic-collection-level"],"categoryId":"67cd904c-78e0-4e77-9dd4-c713b21763f3","categoryName":"User interface preferences","options":[{"id":"com.apple.managedclient.preferences_userinitiatedfeedback_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userinitiatedfeedback_1","displayName":"disabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_userpreference_apptheming","displayName":"Set theme","description":"Set the theme color.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_userpreference_apptheming_0","displayName":"Blue","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_apptheming_1","displayName":"Purple","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_apptheming_2","displayName":"Pink","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_apptheming_3","displayName":"Orange","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_apptheming_4","displayName":"Red","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_apptheming_5","displayName":"Green","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_userpreference_maxchecklistdisplaydurationmet","displayName":"Hide the 'Get started with Outlook' control in the task pane","description":"Suppress the task pane control that advertises access to toolbar customization, notification preferences, theme, and adding secondary accounts.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_userpreference_maxchecklistdisplaydurationmet_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_maxchecklistdisplaydurationmet_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_usesystemprintdialog","displayName":"Print using system print dialog","description":"Shows the system print dialog instead of print preview.\n\nIf you enable this policy, Microsoft Edge opens the system print dialog instead of the built-in print preview when a user prints a page.\n\nIf you don't configure or disable this policy, print commands trigger the Microsoft Edge print preview screen.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#usesystemprintdialog"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_usesystemprintdialog_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_usesystemprintdialog_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_vbaobjectmodelistrusted","displayName":"Allow macros to modify Visual Basic projects","description":"Allow Visual Basic macros to modify Visual Basic projects. Recommended: false.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_vbaobjectmodelistrusted_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_vbaobjectmodelistrusted_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_verticaltabsallowed","displayName":"Configures availability of a vertical layout for tabs on the side of the browser","description":"Configures whether a user can access an alternative layout where tabs are vertically aligned on the side of the browser instead of at the top.\nWhen there are several tabs open, this layout provides better tab viewing and management. There's better visibility of the site titles,\nit's easier to scan aligned icons, and there's more space to manage and close tabs.\n\nIf you disable this policy, then the vertical tab layout will not be available as an option for users.\n\nIf you enable or don't configure this policy, the tab layout will still be at the top, but a user has the option to turn on vertical tabs on the side.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#verticaltabsallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_verticaltabsallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_verticaltabsallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_videocaptureallowed","displayName":"Allow or block video capture","description":"Control whether sites can capture video.\n\nIf enabled or not configured (default), the user will be asked about video capture access for all sites except those with URLs configured in the \"VideoCaptureAllowedUrls\" policy list, which will be granted access without prompting.\n\nIf you disable this policy, the user isn't prompted, and video capture is only available to URLs configured in \"VideoCaptureAllowedUrls\" policy.\n\nThis policy affects all types of video inputs, not only the built-in camera.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#videocaptureallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_videocaptureallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_videocaptureallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_videocaptureallowedurls","displayName":"Sites that can access video capture devices without requesting permission","description":"Specify websites, based on URL patterns, that can use video capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to video capture devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#videocaptureallowedurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_visualbasicentirelydisabled","displayName":"Prevent all Visual Basic macros from executing","description":"Prevent all Visual Basic code from running in Word, Excel, and PowerPoint - even from trusted locations like the default template. Requires 16.32 or later. Recommended: true, where macros should never be used.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_visualbasicentirelydisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_visualbasicentirelydisabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_visualbasicmacroexecutionstate","displayName":"Visual Basic macro policy","description":"Controls whether Visual Basic macros are allowed to execute in Word, Excel, and PowerPoint.","helpText":null,"infoUrls":["https://aka.ms/macvbpref"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_visualbasicmacroexecutionstate_0","displayName":"Macros disabled by default, with warning to enable","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_visualbasicmacroexecutionstate_1","displayName":"Disable all macros","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_visualbasicmacroexecutionstate_2","displayName":"Always allow macros to run (potentially dangerous)","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_visualsearchenabled","displayName":"Visual search enabled","description":"Visual search lets you quickly explore more related content about entities in an image.\n\nIf you enable or don't configure this policy, visual search will be enabled via image hover, context menu, and search in sidebar.\n\nIf you disable this policy, visual search will be disabled and you won't be able to get more info about images via hover, context menu, and search in sidebar.\n\nNote: Visual Search in Web Capture is still managed by \"WebCaptureEnabled\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#visualsearchenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_visualsearchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_visualsearchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_walletdonationenabled","displayName":"Wallet Donation Enabled","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\n\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\n\nIf you disable this policy, users can't use the Wallet Donation feature.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#walletdonationenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_walletdonationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_walletdonationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_weather_update_automatically","displayName":"Disable automatic updating of weather location","description":"Prevent users from choosing Update Location Automatically for weather location.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-automatic-updating-of-weather-location"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_weather_update_automatically_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_weather_update_automatically_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webappinstallforcelist","displayName":"Web App Install Force List","description":"Specifies a list of websites that are installed silently, without user interaction, and which can't be uninstalled or disabled by the user.\n\nEach list item of the policy is an object with the following members:\n - \"url\", which is mandatory. \"url\" should be the URL of the web app to install.\n\nValues for the optional members are:\n - \"launch_container\" should be either \"window\" or \"tab\" to indicate how the Web App will be opened after it's installed.\n - \"create_desktop_shortcut\" should be true if a desktop shortcut should be created on Windows.\n\nIf \"default_launch_container\" is omitted, the app will open in a tab by default. Regardless of the value of \"default_launch_container\", users can change which container the app will open in. If \"create_desktop_shortcuts\" is omitted, no desktop shortcuts will be created.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webappinstallforcelist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_create_desktop_shortcut","displayName":"Create desktop shortcut","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_create_desktop_shortcut_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_create_desktop_shortcut_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_default_launch_container","displayName":"Default launch container","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_default_launch_container_0","displayName":"tab","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_default_launch_container_1","displayName":"window","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_url","displayName":"URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webaudiooutputbufferingenabled","displayName":"Enable adaptive buffering for Web Audio","description":"This policy determines whether the browser enables adaptive buffering\nfor Web Audio. Adaptive buffering can reduce audio glitches but may\nincrease latency to varying degrees.\n\nEnabled: The browser will always use adaptive buffering.\nDisabled or Not Set: The browser will automatically decide during the\n feature launch process whether to use adaptive buffering.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webaudiooutputbufferingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webaudiooutputbufferingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webaudiooutputbufferingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webauthenticationremotedesktopallowedorigins","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications.","description":"This policy defines a list of allowed HTTPS origins for remote desktop client applications that initiate WebAuthn API requests from a browsing session on a remote host.\n\nOrigins specified in this policy can request WebAuthn authentication for Relying Party IDs (RP IDs) they would not typically be authorized to claim.\n\nOnly HTTPS origins are supported. Wildcards are not permitted. Entries that do not\nmeet these requirements will be ignored.\n\nFor more information about the WebAuthn Remote Desktop Support feature, please see https://github.com/w3c/webauthn/wiki/Explainer:-Remote-Desktop-Support/a4e158c569f456c759d0ddd294a9015bd4d4eb9a.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webauthenticationremotedesktopallowedorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webcaptureenabled","displayName":"Enable web capture feature in Microsoft Edge","description":"Enables the web capture feature in Microsoft Edge that allows users to capture web content and annotate the capture using inking tools.\nIf you enable this policy or don't configure it, the Web capture option shows up in the context menu, Settings and more menu, and by using the keyboard shortcut, CTRL+SHIFT+S.\nIf you disable this policy, users can't access the web capture feature in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webcaptureenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webcaptureenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webcaptureenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84.","description":"The Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and have been disabled by default starting in M80. This policy allows these features to be selectively re-enabled until M84.\n\n If you set this policy is set to True, the Web Components v0 features will be enabled for all sites.\n\n If you set this policy to False or don't set this policy, the Web Components v0 features will be disabled by default, starting in M80.\n\n This policy will be removed after Microsoft Edge 84.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webcomponentsv0enabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webcomponentsv0enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webcomponentsv0enabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webdriveroverridesincompatiblepolicies","displayName":"Allow WebDriver to Override Incompatible Policies","description":"This policy was removed in M83, because it is not necessary anymore as\nWebDriver is now compatible with all existing policies.\n\nThis policy allows users of the WebDriver feature to override\npolicies which can interfere with its operation.\n\nCurrently this policy disables \"SitePerProcess\" and \"IsolateOrigins\" policies.\n\nIf the policy is enabled, WebDriver will be able to override incomaptible\npolicies.\nIf the policy is disabled or not configured, WebDriver will not be allowed\nto override incompatible policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webdriveroverridesincompatiblepolicies"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webdriveroverridesincompatiblepolicies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webdriveroverridesincompatiblepolicies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webhidallowalldevicesforurls","displayName":"Allow listed sites to connect to any HID device","description":"This setting allows you to list sites which are automatically granted permission to access all available devices.\n\nThe URLs must be valid or the policy is ignored. Only the origin (scheme, host and port) of the URL is evaluated.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\n\nThis policy overrides \"DefaultWebHidGuardSetting\", \"WebHidAskForUrls\", \"WebHidBlockedForUrls\" and the user's preferences.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webhidallowalldevicesforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webhidaskforurls","displayName":"Allow the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\n\nLeaving the policy unset means \"DefaultWebHidGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\n\n * \"WebHidBlockedForUrls\" (if there is a match),\n\n * \"DefaultWebHidGuardSetting\" (if set), or\n\n * Users' personal settings.\n\nURL patterns must not conflict with \"WebHidBlockedForUrls\". Neither policy takes precedence if a URL matches both patterns.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webhidaskforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webhidblockedforurls","displayName":"Block the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a HID device.\n\nLeaving the policy unset means \"DefaultWebHidGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\n\n * \"WebHidAskForUrls\" (if there is a match),\n\n * \"DefaultWebHidGuardSetting\" (if set), or\n\n * Users' personal settings.\n\nURL patterns can't conflict with \"WebHidAskForUrls\". Neither policy takes precedence if a URL matches both patterns.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webhidblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webrtcallowlegacytlsprotocols","displayName":"Allow legacy TLS/DTLS downgrade in WebRTC","description":"If you enable this policy, WebRTC peer connections can downgrade to obsolete\nversions of the TLS/DTLS (DTLS 1.0, TLS 1.0 and TLS 1.1) protocols.\nIf you disable or don't set this policy, these TLS/DTLS versions are\ndisabled.\n\nThis policy is temporary and will be removed in a future version\nof Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtcallowlegacytlsprotocols"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webrtcallowlegacytlsprotocols_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtcallowlegacytlsprotocols_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling","displayName":"Restrict exposure of local IP address by WebRTC","description":"Allows you to set whether or not WebRTC exposes the user's local IP address.\n\nIf you set this policy to \"AllowAllInterfaces\" ('default') or \"AllowPublicAndPrivateInterfaces\" ('default_public_and_private_interfaces'), WebRTC exposes the local IP address.\n\nIf you set this policy to \"AllowPublicInterfaceOnly\" ('default_public_interface_only') or \"DisableNonProxiedUdp\" ('disable_non_proxied_udp'), WebRTC doesn't expose the local IP address.\n\nIf you don't set this policy, or if you disable it, WebRTC exposes the local IP address.\n\n * 'default' = Allow all interfaces. This exposes the local IP address.\n * 'default_public_and_private_interfaces' = Allow public and private interfaces over http default route. This exposes the local IP address.\n * 'default_public_interface_only' = Allow public interface over http default route. This doesn't expose the local IP address.\n * 'disable_non_proxied_udp' = Use TCP unless proxy server supports UDP. This doesn't expose the local IP address.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtclocalhostiphandling"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_0","displayName":"Allow all interfaces. This exposes the local IP address","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_1","displayName":"Allow public and private interfaces over http default route. This exposes the local IP address","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_2","displayName":"Allow public interface over http default route. This doesn't expose the local IP address","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_3","displayName":"Use TCP unless proxy server supports UDP. This doesn't expose the local IP address","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webrtclocalipsallowedurls","displayName":"Manage exposure of local IP addressess by WebRTC","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*contoso.com*\") for which local IP address should be exposed by WebRTC.\n\nIf you enable this policy and set a list of origins (URLs) or hostname patterns, when edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will expose the local IP address for cases that match patterns in the list.\n\nIf you disable or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will not expose local IP addresses. The local IP address is concealed with an mDNS hostname.\n\nIf you enable, disable, or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, WebRTC will expose local IP addresses.\n\nPlease note that this policy weakens the protection of local IP addresses that might be needed by administrators.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtclocalipsallowedurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC","description":"This policy controls the use of post-quantum key agreement for WebRTC in Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge will offer post-quantum key agreement for WebRTC.\n\nIf you disable this policy, post-quantum key agreement will not be offered for WebRTC.\n\nIf you don't configure this policy, post-quantum key agreement will not be offered for WebRTC. A future version of Microsoft Edge may enable this feature by default.\n\nOffering a post-quantum key agreement is backwards compatible. Existing datagram transport layer security (DTLS) peers and networking middleware are expected to ignore the new option and continue using previous options.\n\nHowever, devices that don't correctly implement DTLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or larger message sizes. Such devices aren’t post-quantum-ready and may interfere with an organization's post-quantum transition. If this issue occurs, administrators should contact the device vendor for a fix.\n\nThis policy is temporary and will be removed in a future release.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtcpostquantumkeyagreement"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webrtcpostquantumkeyagreement_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtcpostquantumkeyagreement_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC","description":"Restricts the UDP port range used by WebRTC to a specified port interval (endpoints included).\n\nBy configuring this policy, you specify the range of local UDP ports that WebRTC can use.\n\nIf you don't configure this policy, or if you set it to an empty string or invalid port range, WebRTC can use any available local UDP port.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtcudpportrange"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webtobrowsersigninenabled","displayName":"Web To Browser Sign-in Enabled","description":"Allow user to sign in to the same account in Microsoft Edge when a user signs in to a Microsoft website.\nIf this policy is enabled or not configured, user are able to get sign in CTA or seamless sign in experience(if \"SeamlessWebToBrowserSignInEnabled\" is enabled) when user sign in on Microsoft website.\nIf this policy is disabled, user will not get sign in CTA or seamless sign in experience when user sign in on Microsoft website.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webtobrowsersigninenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webtobrowsersigninenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webtobrowsersigninenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_webusbaskforurls","displayName":"Allow WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can ask the user for access to a USB device.\n\nIf you don't configure this policy, the global default value from the \"DefaultWebUsbGuardSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"WebUsbBlockedForUrls\" policy - you can't both allow and block a URL.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webusbaskforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_webusbblockedforurls","displayName":"Block WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can't ask the user to grant them access to a USB device.\n\nIf you don't configure this policy, the global default value from the \"DefaultWebUsbGuardSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nURL patterns in this policy can't conflict with those configured in the \"WebUsbAskForUrls\" policy. You can't both allow and block a URL.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webusbblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_weeklyconfiguration","displayName":"Weekly scheduled scan configuration","description":"Should scheduled scan be run with low priority. (Scan might take longer to complete).","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_weeklyconfiguration_dayofweek","displayName":"Day of week","description":"Specifies the day of the week to perform a weekly scan. 0 indicates never. 1-7 indicates Sunday - Saturday. 8 indicates every day.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_weeklyconfiguration_scantype","displayName":"Scan type","description":"Specifies the type of scan to perform.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":[{"id":"com.apple.managedclient.preferences_weeklyconfiguration_scantype_0","displayName":"quick","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_weeklyconfiguration_scantype_1","displayName":"full","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_weeklyconfiguration_timeofday","displayName":"Time of day","description":"Specifies the time of day, as the number of minutes after midnight, to perform a weekly scan.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},{"id":"com.apple.managedclient.preferences_whatsnewpageforentraprofilesenabled","displayName":"Control whether an informational webpage for Edge for Business is shown in the new tab after major browser updates","description":"Starting in Microsoft Edge version 145, users with Microsoft Entra ID profiles will see an informational page about new Edge for Business features after major browser updates. This page highlights recent enhancements designed to promote secure and productive browsing.\n\nThis policy controls whether users with Microsoft Entra ID profiles see this informational page. This policy applies only to Microsoft Entra ID profiles and does not apply to Microsoft account (MSA) profiles.\n\nThis policy is available starting in Microsoft Edge version 144 to allow configuration ahead of the changes introduced in version 145.\n\nIf you enable this policy or do not configure it, Microsoft Edge shows the informational page by default.\nIf you disable this policy, Microsoft Edge does not show the informational page to users.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#whatsnewpageforentraprofilesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_whatsnewpageforentraprofilesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_whatsnewpageforentraprofilesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_windowcaptureallowedbyorigins","displayName":"Allow Window and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Window and Tab Capture.\n\nLeaving the policy unset means that sites will not be considered for an override at this scope of Capture.\n\nThis policy is not considered if a site matches a URL pattern in any of the following policies: \"TabCaptureAllowedByOrigins\", \"SameOriginTabCaptureAllowedByOrigins\".\n\nIf a site matches a URL pattern in this policy, the following policies will not be considered: \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#windowcaptureallowedbyorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_windowmanagementallowedforurls","displayName":"Allow Window Management permission on specified sites","description":"Lets you configure a list of site url patterns that specify sites which will automatically grant the window management permission. This extends the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\n\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\n\nIf this policy isn't configured for a site, then the policy from \"DefaultWindowManagementSetting\" applies to the site, if configured. Otherwise the permission will follow the browser's defaults and let users choose this permission per site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#windowmanagementallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_windowmanagementblockedforurls","displayName":"Block Window Management permission on specified sites","description":"Lets you configure a list of site url patterns that specify sites which will automatically deny the window management permission. This limits the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\n\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\n\nIf this policy isn't configured for a site, then the policy from \"DefaultWindowManagementSetting\" applies to the site, if configured. Otherwise the permission will follow the browser's defaults and let users choose this permission per site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#windowmanagementblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},{"id":"com.apple.managedclient.preferences_wpadquickcheckenabled","displayName":"Set WPAD optimization","description":"Allows you to turn off WPAD (Web Proxy Auto-Discovery) optimization in Microsoft Edge.\n\nIf you disable this policy, WPAD optimization is disabled, which makes the browser wait longer for DNS-based WPAD servers.\n\nIf you enable or don't configure the policy, WPAD optimization is enabled.\n\nIndependent of whether or how this policy is enabled, the WPAD optimization setting cannot be changed by users.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#wpadquickcheckenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_wpadquickcheckenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_wpadquickcheckenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.managedclient.preferences_zstdcontentencodingenabled","displayName":"Enable zstd content encoding support (Deprecated)","description":"This feature enables advertising \"zstd\" support in the Accept-Encoding request header and support for decompressing zstd web content.\n\nIf you enable or don't configure this policy, Microsoft Edge will accept server responses compressed with zstd.\n\nIf you disable this policy, the zstd content encoding feature will not be advertised or supported when processing server responses.\n\nThis policy is temporary and will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#zstdcontentencodingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_zstdcontentencodingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_zstdcontentencodingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.mcx_cachedaccounts.askforsecuretokenauthbypass","displayName":"Ask For Secure Token Auth Bypass","description":"If true, bypasses the secure token authorization dialog. This dialog only appears on APFS volumes.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_cachedaccounts.askforsecuretokenauthbypass_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_cachedaccounts.askforsecuretokenauthbypass_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_cachedaccounts.expiry.delete.disusedseconds","displayName":"Expiry Delete Disused Seconds","description":"The minimum number of seconds a mobile account can exist before an automatic attempt is made to remove the mobile account. Set to 0 to try to remove it at next login or logout time. Set to -1 to never try to remove the mobile account.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":null},{"id":"com.apple.mcx_cachedaccounts.warnoncreate.allownever","displayName":"Warn On Create Allow Never","description":"If true, allows the user to stop the prompts about mobile account creation every time the user logs in. This key is only valid if Warn On Create is set to true.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_cachedaccounts.warnoncreate.allownever_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_cachedaccounts.warnoncreate.allownever_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.cachedaccounts.createatlogin","displayName":"Create At Login","description":"If true, creates the mobile account at login time.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_com.apple.cachedaccounts.createatlogin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.cachedaccounts.createatlogin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.cachedaccounts.warnoncreate","displayName":"Warn On Create","description":"If true, asks the user if the mobile account should be created and allow the user to not create it.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_com.apple.cachedaccounts.warnoncreate_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.cachedaccounts.warnoncreate_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower","displayName":"Desktop Power","description":"The settings for a desktop computer.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_automatic restart on power loss","displayName":"Automatic Restart On Power Loss","description":"If true, enables \"Start up automatically after a power failure.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_automatic restart on power loss_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_automatic restart on power loss_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_disk sleep timer","displayName":"Disk Sleep Timer","description":"The disk sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_display sleep timer","displayName":"Display Sleep Timer","description":"The display sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_dynamic power step","displayName":"Dynamic Power Step","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_dynamic power step_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_dynamic power step_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_reduce processor speed","displayName":"Reduce Processor Speed","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_reduce processor speed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_reduce processor speed_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_system sleep timer","displayName":"System Sleep Timer","description":"System sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_wake on lan","displayName":"Wake on LAN","description":"If true, enables \"Wake for network access.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_wake on lan_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_wake on lan_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_wake on modem ring","displayName":"Wake On Modem Ring","description":"If true, enables \"Wake for modem ring.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_wake on modem ring_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_wake on modem ring_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule","displayName":"Desktop Schedule","description":"The schedule for turning a computer on and off.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff","displayName":"Repeating Power Off","description":"The schedule for turning the device off. ","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype","displayName":"Event Type","description":"The type of action defined by this schedule.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype_0","displayName":"Wake","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype_1","displayName":"Power On","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype_2","displayName":"Wake Power On","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype_3","displayName":"Sleep","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype_4","displayName":"Shutdown","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_eventtype_5","displayName":"Restart","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_time","displayName":"Time","description":"The time, in minutes, since midnight.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays","displayName":"Weekdays","description":"One or more days of the week that the device will automatically shutdown. ","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_0","displayName":"Mon","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_1","displayName":"Tue","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_2","displayName":"Wed","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_3","displayName":"Thu","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_4","displayName":"Fri","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_5","displayName":"Sat","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweroff_weekdays_6","displayName":"Sun","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron","displayName":"Repeating Power On","description":"The schedule for powering the device on. ","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype","displayName":"Event Type","description":"The type of action defined by this schedule.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype_0","displayName":"Wake","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype_1","displayName":"Power On","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype_2","displayName":"Wake Power On","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype_3","displayName":"Sleep","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype_4","displayName":"Shutdown","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_eventtype_5","displayName":"Restart","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_time","displayName":"Time","description":"The time, in minutes, since midnight.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays","displayName":"Weekdays","description":"One or more days of the week that the device will automatically power on.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_0","displayName":"Mon","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_1","displayName":"Tue","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_2","displayName":"Wed","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_3","displayName":"Thu","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_4","displayName":"Fri","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_5","displayName":"Sat","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron_weekdays_6","displayName":"Sun","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower","displayName":"Laptop Power","description":"The settings for a laptop computer using AC power. ","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_automatic restart on power loss","displayName":"Automatic Restart On Power Loss","description":"If true, enables \"Start up automatically after a power failure.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_automatic restart on power loss_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_automatic restart on power loss_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_disk sleep timer","displayName":"Disk Sleep Timer","description":"The disk sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_display sleep timer","displayName":"Display Sleep Timer","description":"The display sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_dynamic power step","displayName":"Dynamic Power Step","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_dynamic power step_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_dynamic power step_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_reduce processor speed","displayName":"Reduce Processor Speed","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_reduce processor speed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_reduce processor speed_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_system sleep timer","displayName":"System Sleep Timer","description":"System sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on lan","displayName":"Wake on LAN","description":"If true, enables \"Wake for network access.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on lan_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on lan_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on modem ring","displayName":"Wake On Modem Ring","description":"If true, enables \"Wake for modem ring.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on modem ring_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on modem ring_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower","displayName":"Laptop Battery Power","description":"The settings for a laptop computer using battery power.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_automatic restart on power loss","displayName":"Automatic Restart On Power Loss","description":"If true, enables \"Start up automatically after a power failure.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_automatic restart on power loss_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_automatic restart on power loss_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_disk sleep timer","displayName":"Disk Sleep Timer","description":"The disk sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_display sleep timer","displayName":"Display Sleep Timer","description":"The display sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_dynamic power step","displayName":"Dynamic Power Step","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_dynamic power step_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_dynamic power step_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_reduce processor speed","displayName":"Reduce Processor Speed","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_reduce processor speed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_reduce processor speed_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_system sleep timer","displayName":"System Sleep Timer","description":"System sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on lan","displayName":"Wake on LAN","description":"If true, enables \"Wake for network access.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on lan_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on lan_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on modem ring","displayName":"Wake On Modem Ring","description":"If true, enables \"Wake for modem ring.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on modem ring_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on modem ring_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_com.apple.mcx-accounts","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","categoryName":"Accounts","options":null},{"id":"com.apple.mcx_com.apple.mcx-energysaver","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},{"id":"com.apple.mcx_com.apple.mcx-fdefilevaultoptions","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","categoryName":"FileVault Options","options":null},{"id":"com.apple.mcx_com.apple.mcx-mobileaccounts","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":null},{"id":"com.apple.mcx_com.apple.mcx-timeserver","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"853f4181-42e8-411c-91cf-c06968c0a543","categoryName":"Time Server","options":null},{"id":"com.apple.mcx_destroyfvkeyonstandby","displayName":"Destroy FV Key On Standby","description":"If true, prevents the OS from storing a temporary FileVault key in SMC or RAM for standby.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_destroyfvkeyonstandby_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_destroyfvkeyonstandby_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_disableguestaccount","displayName":"Disable Guest Account","description":"If true, disables the guest account. This property has no effect if Enable Guest Account is true.","helpText":null,"infoUrls":[],"categoryId":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","categoryName":"Accounts","options":[{"id":"com.apple.mcx_disableguestaccount_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_disableguestaccount_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_dontallowfdedisable","displayName":"Prevent FileVault From Being Disabled","description":"Set to true to prevent FileVault from being disabled.","helpText":null,"infoUrls":[],"categoryId":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","categoryName":"FileVault Options","options":[{"id":"com.apple.mcx_dontallowfdedisable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_dontallowfdedisable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_dontallowfdeenable","displayName":"Prevent FileVault From Being Enabled","description":"Set to true to prevent FileVault from being enabled.","helpText":null,"infoUrls":[],"categoryId":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","categoryName":"FileVault Options","options":[{"id":"com.apple.mcx_dontallowfdeenable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_dontallowfdeenable_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_enableguestaccount","displayName":"Enable Guest Account","description":"If true, enables the guest account.","helpText":null,"infoUrls":[],"categoryId":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","categoryName":"Accounts","options":[{"id":"com.apple.mcx_enableguestaccount_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_enableguestaccount_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_sleepdisabled","displayName":"Sleep Disabled","description":"If true, disables sleep.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_sleepdisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_sleepdisabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx_timeserver","displayName":"Time Server","description":"The NTP server to connect to. Use commas to separate multiple time servers.","helpText":null,"infoUrls":[],"categoryId":"853f4181-42e8-411c-91cf-c06968c0a543","categoryName":"Time Server","options":null},{"id":"com.apple.mcx_timezone","displayName":"Time Zone","description":"The time zone path location string in /usr/share/zoneinfo/; for example, America/Denver or Zulu. ","helpText":null,"infoUrls":[],"categoryId":"853f4181-42e8-411c-91cf-c06968c0a543","categoryName":"Time Server","options":null},{"id":"com.apple.mcx.filevault2_com.apple.mcx.filevault2","displayName":"Top Level Setting Group Collection","description":"com.apple.MCX.FileVault2","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},{"id":"com.apple.mcx.filevault2_defer","displayName":"Defer","description":"If true, defers enabling FileVault until the designated user logs out. For details, see fdesetup(8). The person enabling FileVault must be either a local user or a mobile account user.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":{"id":"com.apple.mcx.filevault2_defer_true","displayName":"Enabled","description":null,"helpText":null}},{"id":"com.apple.mcx.filevault2_deferdontaskatuserlogout","displayName":"Defer Dont Ask At User Logout","description":"If true, prevents requests for enabling FileVault at user logout time.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_deferdontaskatuserlogout_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_deferdontaskatuserlogout_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_deferforceatuserloginmaxbypassattempts","displayName":"Defer Force At User Login Max Bypass Attempts","description":"The maximum number of times users can bypass enabling FileVault before being required to enable it to log in. If the value is 0, the user will be required to enabled FileVault the next time they attempt to log in. Setting this key to –1 disables the feature.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},{"id":"com.apple.mcx.filevault2_enable","displayName":"Enable","description":"If true, enables FileVault.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_enable_0","displayName":"On","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_enable_1","displayName":"Off","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_forceenableinsetupassistant","displayName":"Force Enable In Setup Assistant","description":"If 'true', and installation of this payload occurs after enrolling with MDM in Setup Assistant, the system requests Setup Assistant to enable FileVault at setup time. In this case, the system also ignores all other keys in this payload, except for 'ShowRecoveryKey'.\nTo use this, enable the Await Device Configured DEP configuration option and send this profile with this key set, before sending the DeviceConfiguredCommand. An admin SecureToken user is required, otherwise the FileVault pane does not appear.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_forceenableinsetupassistant_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_forceenableinsetupassistant_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_outputpath","displayName":"Output Path","description":"The path to the location where the recovery key and computer information property list are stored.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},{"id":"com.apple.mcx.filevault2_password","displayName":"Password","description":"The password of the Open Directory user to be added to FileVault. Use the 'UserEntersMissingInfo' key if you want to prompt for this information.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths","displayName":"Recovery Key Rotation In Months","description":"The frequency to rotate the recovery key, in months","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_0","displayName":"Not configured","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_1","displayName":"1 month","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_2","displayName":"2 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_3","displayName":"3 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_4","displayName":"4 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_5","displayName":"5 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_6","displayName":"6 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_7","displayName":"7 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_8","displayName":"8 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_9","displayName":"9 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_10","displayName":"10 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_11","displayName":"11 months","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_recoverykeyrotationinmonths_12","displayName":"12 months","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_showrecoverykey","displayName":"Show Recovery Key","description":"If false, prevents display of the personal recovery key to the user after FileVault is enabled.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_showrecoverykey_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_showrecoverykey_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_usekeychain","displayName":"Use Keychain","description":"If 'true' and no certificate information is provided in this payload, the keychain created at '/Library/Keychains/FileVaultMaster.keychain' is used when the institutional recovery key is added.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_usekeychain_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_usekeychain_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_userecoverykey","displayName":"Use Recovery Key","description":"If true, creates a personal recovery key and displays it to the user.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":{"id":"com.apple.mcx.filevault2_userecoverykey_true","displayName":"Enabled","description":null,"helpText":null}},{"id":"com.apple.mcx.filevault2_userentersmissinginfo","displayName":"User Enters Missing Info","description":"If true, enables a prompt for missing user name or password fields.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_userentersmissinginfo_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_userentersmissinginfo_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx.filevault2_username","displayName":"Username","description":"The user name of the Open Directory user to be added to FileVault.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},{"id":"com.apple.mcx.timemachine_autobackup","displayName":"Auto Backup","description":"If true, performs automatic backups at regular intervals.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":[{"id":"com.apple.mcx.timemachine_autobackup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.timemachine_autobackup_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx.timemachine_backupallvolumes","displayName":"Backup All Volumes","description":"If true, backs up only the startup volume by default.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":[{"id":"com.apple.mcx.timemachine_backupallvolumes_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.timemachine_backupallvolumes_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx.timemachine_backupdesturl","displayName":"Backup Destination URL","description":"The URL of the backup destination.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},{"id":"com.apple.mcx.timemachine_backupsizemb","displayName":"Backup Size MB","description":"The backup size limit, in megabytes. Set to 0 for unlimited.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},{"id":"com.apple.mcx.timemachine_backupskipsys","displayName":"Backup Skip System","description":"If true, skips system files and folders by default.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":[{"id":"com.apple.mcx.timemachine_backupskipsys_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.timemachine_backupskipsys_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx.timemachine_basepaths","displayName":"Base Paths","description":"The list of paths to back up besides the startup volume.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},{"id":"com.apple.mcx.timemachine_com.apple.mcx.timemachine","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},{"id":"com.apple.mcx.timemachine_mobilebackups","displayName":"Mobile Backups","description":"If true, create local backup snapshots when not connected to the network.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":[{"id":"com.apple.mcx.timemachine_mobilebackups_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.timemachine_mobilebackups_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcx.timemachine_skippaths","displayName":"Skip Paths","description":"The path to skip from start volume.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},{"id":"com.apple.mcxmenuextras_airport.menu","displayName":"AirPort","description":"If true, enables the AirPort menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_airport.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_airport.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_battery.menu","displayName":"Battery","description":"If true, enables the Battery menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_battery.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_battery.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_bluetooth.menu","displayName":"Bluetooth","description":"If true, enables the Bluetooth menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_bluetooth.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_bluetooth.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_clock.menu","displayName":"Clock","description":"If true, enables the Clock menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_clock.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_clock.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_com.apple.mcxmenuextras","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":null},{"id":"com.apple.mcxmenuextras_cpu.menu","displayName":"CPU","description":"If true, enables the CPU menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_cpu.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_cpu.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_delayseconds","displayName":"Delay Seconds","description":"The number of seconds to delay after login before adding or removing menu extras. If the delay is too short, the menu extras don't appear, or disappear from the menu bar.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":null},{"id":"com.apple.mcxmenuextras_displays.menu","displayName":"Displays","description":"If true, enables the Displays menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_displays.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_displays.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_eject.menu","displayName":"Eject","description":"If true, enables the Eject menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_eject.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_eject.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_fax.menu","displayName":"Fax","description":"If true, enables the Fax menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_fax.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_fax.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_homesync.menu","displayName":"HomeSync","description":"If true, enables the HomeSync menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_homesync.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_homesync.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_ichat.menu","displayName":"iChat","description":"If true, enables the iChat menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_ichat.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_ichat.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_ink.menu","displayName":"Ink","description":"If true, enables the Ink menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_ink.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_ink.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_irda.menu","displayName":"IrDA","description":"If true, enables the IrDA menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_irda.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_irda.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_maxwaitseconds","displayName":"Max Wait Seconds","description":"The maximum wait, in seconds, for all menu extras to be added or removed.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":null},{"id":"com.apple.mcxmenuextras_pccard.menu","displayName":"PCCard","description":"If true, enables the PCCard menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_pccard.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_pccard.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_ppp.menu","displayName":"PPP","description":"If true, enables the PPP menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_ppp.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_ppp.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_pppoe.menu","displayName":"PPPoE","description":"If true, enables the PPPoE menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_pppoe.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_pppoe.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_remotedesktop.menu","displayName":"Remote Desktop","description":"If true, enables the Remote Desktop menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_remotedesktop.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_remotedesktop.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_script menu.menu","displayName":"Script Menu","description":"If true, enables the Script menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_script menu.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_script menu.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_spaces.menu","displayName":"Spaces","description":"If true, enables the Spaces menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_spaces.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_spaces.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_sync.menu","displayName":"Sync","description":"If true, enables the Sync menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_sync.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_sync.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_textinput.menu","displayName":"Text Input","description":"If true, enables the Text Input menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_textinput.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_textinput.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_timemachine.menu","displayName":"TimeMachine","description":"If true, enables the TimeMachine menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_timemachine.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_timemachine.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_universalaccess.menu","displayName":"Universal Access","description":"If true, enables the Universal Access menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_universalaccess.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_universalaccess.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_user.menu","displayName":"User","description":"If true, enables the User menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_user.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_user.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_volume.menu","displayName":"Volume","description":"If true, enables the Volume menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_volume.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_volume.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_vpn.menu","displayName":"VPN","description":"If true, enables the VPN menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_vpn.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_vpn.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxmenuextras_wwan.menu","displayName":"WWAN","description":"If true, enables the WWAN menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_wwan.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_wwan.menu_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_allowlocalprinters","displayName":"Allow Local Printers","description":"If true, allows printers that connect directly to a user's computer.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_allowlocalprinters_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_allowlocalprinters_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_com.apple.mcxprinting","displayName":"Top Level Setting Group Collection","description":"com.apple.mcxprinting","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_defaultprinter","displayName":"Default Printer","description":"The default printer for the user.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_defaultprinter_deviceuri","displayName":"Device URI","description":"The device URI.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_defaultprinter_displayname","displayName":"Display Name","description":"The display name.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_footerfontname","displayName":"Footer Font Name","description":"The footer font name.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_footerfontsize","displayName":"Footer Font Size","description":"The footer font size.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_printfooter","displayName":"Print Footer","description":"If true, prints the page footer (including the user name and date).","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_printfooter_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_printfooter_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_printmacaddress","displayName":"Print MAC Address","description":"If true, includes the MAC address.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_printmacaddress_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_printmacaddress_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_requireadmintoaddprinters","displayName":"Require Admin To Add Printers","description":"If true, requires an administrator password to add printers.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_requireadmintoaddprinters_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_requireadmintoaddprinters_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_requireadmintoprintlocally","displayName":"Require Admin To Print Locally","description":"If true, requires an administrator password to print locally.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_requireadmintoprintlocally_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_requireadmintoprintlocally_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_showonlymanagedprinters","displayName":"Show Only Managed Printers","description":"If true, shows only managed printers.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_showonlymanagedprinters_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_showonlymanagedprinters_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mcxprinting_userprinterlist","displayName":"User Printer List","description":"The printers available to a user.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer","displayName":"Printer","description":"A dictionary of printer details.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_deviceuri","displayName":"Device URI","description":"The device URI.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_displayname","displayName":"Display Name","description":"The display name.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_location","displayName":"Location","description":"The printer's location.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_model","displayName":"Model","description":"The printer's model.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_ppdurl","displayName":"PPD URL","description":"The printer's PPDURL.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_printerlocked","displayName":"Printer Locked","description":"If true, locks the printer.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_userprinterlist_printer_printerlocked_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_printerlocked_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mobiledevice.passwordpolicy_allowsimple","displayName":"Allow Simple Passcode","description":"If true, allows a simple passcode. A simple passcode contains repeated characters, or increasing or decreasing characters (such as 123 or CBA). Setting this value to false has the same result as setting Min Complex Characters to 1.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":[{"id":"com.apple.mobiledevice.passwordpolicy_allowsimple_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mobiledevice.passwordpolicy_allowsimple_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mobiledevice.passwordpolicy_changeatnextauth","displayName":"Change At Next Auth","description":"If true, causes a password reset to occur the next time the user tries to authenticate. If this key is set in a device profile, the setting takes effect for all users, and admin authentications may fail until the admin user password is also reset. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":[{"id":"com.apple.mobiledevice.passwordpolicy_changeatnextauth_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mobiledevice.passwordpolicy_changeatnextauth_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mobiledevice.passwordpolicy_com.apple.mobiledevice.passwordpolicy","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_customregex","displayName":"Custom Regex","description":"Specifies a regular expression, and its description, used to enforce password compliance. Use the simpler passcode restrictions whenever possible, and rely on regular expression matching only when necessary. Mistakes in regular expressions can lead to frustrating user experiences, such as unsatisfiable passcode policies, or policy descriptions that don't match the enforced policy.\n\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentdescription","displayName":"Password Content Description","description":"Contains a dictionary of keys for supported OS language IDs (for example, \"en-US\"), and whose values represent a localized description of the policy enforced by the regular expression. Use the special `default` key can for languages that aren't contained in the dictionary.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentdescription_generickey","displayName":"Description","description":"A localized description.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentdescription_generickey_keytobereplaced","displayName":"Password Content Description","description":"Contains a dictionary of keys for supported OS language IDs (for example, \"en-US\"), and whose values represent a localized description of the policy enforced by the regular expression. Use the special `default` key can for languages that aren't contained in the dictionary.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentregex","displayName":"Password Content Regex","description":"A regular expression string that they system matches against the password to determine whether it complies with a policy. The regular expression uses the ICU syntax (). The string must not exceed 2048 characters in length.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_forcepin","displayName":"Force PIN","description":"If true, forces the user to enter a PIN.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":[{"id":"com.apple.mobiledevice.passwordpolicy_forcepin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mobiledevice.passwordpolicy_forcepin_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.mobiledevice.passwordpolicy_maxfailedattempts","displayName":"Max Failed Attempts","description":"The number of allowed failed attempts to enter the passcode at the device's lock screen. After six failed attempts, a time delay is imposed before a passcode can be entered again. The delay increases with each attempt. In macOS, set Minutes Until Failed Login Reset to define a delay before the next passcode can be entered. When this number is exceeded in macOS, the device is locked; in iOS, the device is wiped.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_maxgraceperiod","displayName":"Max Grace Period","description":"The maximum grace period, in minutes, to unlock the phone without entering a passcode. The default is 0, which is no grace period and requires a passcode immediately. In macOS, this grace period value is translated to screen-saver settings.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_maxinactivity","displayName":"Max Inactivity","description":"The maximum number of minutes for which the device can be idle, without being unlocked by the user, before it gets locked by the system. When this limit is reached, the device is locked and the passcode must be entered. The user can edit this setting, but the value cannot exceed the Max Inactivity value. In macOS, this inactivity value is translated to screen-saver settings.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_maxpinageindays","displayName":"Max PIN Age In Days","description":"The number of days for which the passcode can remain unchanged. After this number of days, the user is forced to change the passcode before the device is unlocked.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_mincomplexchars","displayName":"Min Complex Characters","description":"The minimum number of complex characters that a passcode must contain. A complex character is a character other than a number or a letter, such as & % $ #. This property is ignored for User Enrollments.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_minlength","displayName":"Min Length","description":"The minimum overall length of the passcode. This parameter is independent of the also optional Min Complex Characters argument.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_minutesuntilfailedloginreset","displayName":"Minutes Until Failed Login Reset","description":"The number of minutes before the login is reset after the maximum number of unsuccessful login attempts is reached. This key requires setting Max Failed Attempts. Available in macOS 10.10 and later.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_pinhistory","displayName":"PIN History","description":"This value defines N, where the new passcode must be unique within the last N entries in the passcode history. ","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},{"id":"com.apple.mobiledevice.passwordpolicy_requirealphanumeric","displayName":"Require Alphanumeric Passcode","description":"If true, requires alphabetic characters (abcd) instead of only numeric characters.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":[{"id":"com.apple.mobiledevice.passwordpolicy_requirealphanumeric_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mobiledevice.passwordpolicy_requirealphanumeric_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.networkusagerules_applicationrules","displayName":"Application Rules","description":"An array of application rules, that apply to only managed apps.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},{"id":"com.apple.networkusagerules_applicationrules_item_allowcellulardata","displayName":"Allow Cellular Data","description":"If false, disables cellular data for all matching managed apps.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":[{"id":"com.apple.networkusagerules_applicationrules_item_allowcellulardata_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.networkusagerules_applicationrules_item_allowcellulardata_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.networkusagerules_applicationrules_item_allowroamingcellulardata","displayName":"Allow Roaming Cellular Data","description":"If false, disables cellular data while roaming for all matching managed apps.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":[{"id":"com.apple.networkusagerules_applicationrules_item_allowroamingcellulardata_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.networkusagerules_applicationrules_item_allowroamingcellulardata_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.networkusagerules_applicationrules_item_appidentifiermatches","displayName":"App Identifier Matches","description":"A list of managed app identifiers, as strings, that must follow the associated rules. If this key is missing, the rules apply to all managed apps on the device. Each string in the AppIdentifierMatches array may either be an exact app identifier match (for example, com.mycompany.myapp) or it may specify a prefix match for the bundle ID by using the * wildcard character. If used, this character must appear after a period (.) and may only appear once, at the end of the string; for example, com.mycompany.*.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},{"id":"com.apple.networkusagerules_com.apple.networkusagerules","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},{"id":"com.apple.networkusagerules_simrules","displayName":"SIM Rules","description":"An array of SIM rules, that apply to all apps.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},{"id":"com.apple.networkusagerules_simrules_item_iccids","displayName":"ICCI Ds","description":"One or more ICCIDs of SIM cards for which the `WiFiAssistPolicy` applies. All ICCIDs in all installed Network Usage Rules payloads must be unique. An example ICCID is `89310410106543789301`.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},{"id":"com.apple.networkusagerules_simrules_item_wifiassistpolicy","displayName":"Wi Fi Assist Policy","description":"The Wi-Fi Assist policy to apply to the SIM cards specified in the ICCIDs. See About Wi-Fi Assist to learn more.\n* '2': Use the default system policy for the specified SIM card(s).\n* '3': Make Wi-Fi Assist switch more aggressively from a poor Wi-Fi connection to cellular data for the specified SIM card(s). This setting may increase cellular data use and may impact battery life.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":[{"id":"com.apple.networkusagerules_simrules_item_wifiassistpolicy_0","displayName":"2","description":null,"helpText":null},{"id":"com.apple.networkusagerules_simrules_item_wifiassistpolicy_1","displayName":"3","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_com.apple.notificationsettings","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":null},{"id":"com.apple.notificationsettings_notificationsettings","displayName":"Notification Settings","description":"An array of notification settings dictionaries.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":null},{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype","displayName":"Alert Type","description":"The type of alert for notifications for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype_1","displayName":"Temporary Banner","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype_2","displayName":"Persistent Banner","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_badgesenabled","displayName":"Badges Enabled","description":"If true, enables badges for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_badgesenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_badgesenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_bundleidentifier","displayName":"Bundle Identifier","description":"The bundle identifier of the app to which to apply these notification settings. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":null},{"id":"com.apple.notificationsettings_notificationsettings_item_criticalalertenabled","displayName":"Critical Alert Enabled","description":"If true, enables critical alerts that can ignore Do Not Disturb and ringer settings for this app. Available in iOS 12 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_criticalalertenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_criticalalertenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_groupingtype","displayName":"Grouping Type","description":"The type of grouping for notifications for this app. Available in iOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_groupingtype_0","displayName":"Automatic: Group notifications into app-specified groups","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_groupingtype_1","displayName":"By app: Group notifications into one group","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_groupingtype_2","displayName":"Off: Don't group notifications","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_notificationsenabled","displayName":"Notifications Enabled","description":"If true, enables notifications for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_notificationsenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_notificationsenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype","displayName":"Preview Type","description":"The type previews for notifications. This key overrides the value at Settings>Notifications>Show Previews. Available in iOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype_0","displayName":"Always: Previews will be shown when the device is locked and unlocked","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype_1","displayName":"When Unlocked: Previews will only be shown when the device is unlocked","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype_2","displayName":"Never: Previews will never be shown","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_showincarplay","displayName":"Show In Car Play","description":"If true, enables notifications in CarPlay for this app. Available in iOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_showincarplay_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_showincarplay_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_showinlockscreen","displayName":"Show In Lock Screen","description":"If true, enables notifications on the lock screen for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_showinlockscreen_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_showinlockscreen_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_showinnotificationcenter","displayName":"Show In Notification Center","description":"If true, enables notifications in the notification center for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_showinnotificationcenter_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_showinnotificationcenter_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.notificationsettings_notificationsettings_item_soundsenabled","displayName":"Sounds Enabled","description":"If true, enables sounds for this app.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_soundsenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_soundsenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.nsextension_allowedextensions","displayName":"Allowed Extensions","description":"An array of identifiers for extensions that are allowed to run on the system.","helpText":null,"infoUrls":[],"categoryId":"d875dca1-dc97-4cc5-9df3-c50b813622a3","categoryName":"NS Extension Management","options":null},{"id":"com.apple.nsextension_com.apple.nsextension","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"d875dca1-dc97-4cc5-9df3-c50b813622a3","categoryName":"NS Extension Management","options":null},{"id":"com.apple.nsextension_deniedextensionpoints","displayName":"Denied Extension Points","description":"An array of extension points for extensions that aren't allowed to run on the system.","helpText":null,"infoUrls":[],"categoryId":"d875dca1-dc97-4cc5-9df3-c50b813622a3","categoryName":"NS Extension Management","options":null},{"id":"com.apple.nsextension_deniedextensions","displayName":"Denied Extensions","description":"An array of identifiers for extensions that aren't allowed to run on the system.","helpText":null,"infoUrls":[],"categoryId":"d875dca1-dc97-4cc5-9df3-c50b813622a3","categoryName":"NS Extension Management","options":null},{"id":"com.apple.preference.security_com.apple.preference.security","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8abddb23-7036-4ba8-8912-529279a849ea","categoryName":"Security Preferences","options":null},{"id":"com.apple.preference.security_dontallowfirewallui","displayName":"Do Not Allow Firewall UI","description":"If true, disables user changes to the firewall settings.","helpText":null,"infoUrls":[],"categoryId":"8abddb23-7036-4ba8-8912-529279a849ea","categoryName":"Security Preferences","options":[{"id":"com.apple.preference.security_dontallowfirewallui_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.preference.security_dontallowfirewallui_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.preference.security_dontallowlockmessageui","displayName":"Do Not Allow Lock Message UI","description":"If true, disables user changes to the lock message. ","helpText":null,"infoUrls":[],"categoryId":"8abddb23-7036-4ba8-8912-529279a849ea","categoryName":"Security Preferences","options":[{"id":"com.apple.preference.security_dontallowlockmessageui_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.preference.security_dontallowlockmessageui_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.preference.security_dontallowpasswordresetui","displayName":"Do Not Allow Password Reset UI","description":"If true, disables user changes to the password.","helpText":null,"infoUrls":[],"categoryId":"8abddb23-7036-4ba8-8912-529279a849ea","categoryName":"Security Preferences","options":[{"id":"com.apple.preference.security_dontallowpasswordresetui_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.preference.security_dontallowpasswordresetui_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.preference.users_com.apple.preference.users","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"0a9f982a-3515-4728-a231-fa000eb9e550","categoryName":"User Preferences","options":null},{"id":"com.apple.preference.users_disableusingicloudpassword","displayName":"Disable Using iCloud Password","description":"If true, disables the iCloud password for local accounts.","helpText":null,"infoUrls":[],"categoryId":"0a9f982a-3515-4728-a231-fa000eb9e550","categoryName":"User Preferences","options":[{"id":"com.apple.preference.users_disableusingicloudpassword_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.preference.users_disableusingicloudpassword_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.profileremovalpassword_com.apple.profileremovalpassword","displayName":"Top Level Setting Group Collection","description":"com.apple.profileRemovalPassword","helpText":null,"infoUrls":[],"categoryId":"e905d6cf-7820-48d4-86e0-b55fa991a5ad","categoryName":"Profile Removal Password","options":null},{"id":"com.apple.profileremovalpassword_removalpassword","displayName":"Removal Password","description":"The password for allowing the profile to be removed.","helpText":null,"infoUrls":[],"categoryId":"e905d6cf-7820-48d4-86e0-b55fa991a5ad","categoryName":"Profile Removal Password","options":null},{"id":"com.apple.proxy.http.global_com.apple.proxy.http.global","displayName":"Top Level Setting Group Collection","description":"com.apple.proxy.http.global","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},{"id":"com.apple.proxy.http.global_proxycaptiveloginallowed","displayName":"Proxy Captive Login Allowed","description":"If true, allows the device to bypass the proxy server to display the login page for captive networks.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":[{"id":"com.apple.proxy.http.global_proxycaptiveloginallowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.proxy.http.global_proxycaptiveloginallowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.proxy.http.global_proxypacfallbackallowed","displayName":"Proxy PAC Fallback Allowed","description":"If true, allows connecting directly to the destination if the proxy autoconfiguration (PAC) file is unreachable. ","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":[{"id":"com.apple.proxy.http.global_proxypacfallbackallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.proxy.http.global_proxypacfallbackallowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.proxy.http.global_proxypacurl","displayName":"Proxy PAC URL","description":"The URL of the PAC file that defines the proxy configuration. Starting in iOS 13 and macOS 10.15, only URLs that begin with http:// or https:// are allowed.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},{"id":"com.apple.proxy.http.global_proxypassword","displayName":"Proxy Password","description":"The password used to authenticate to the proxy server.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},{"id":"com.apple.proxy.http.global_proxyserver","displayName":"Proxy Server","description":"The proxy server's network address.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},{"id":"com.apple.proxy.http.global_proxyserverport","displayName":"Proxy Server Port","description":"The proxy server's port number.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},{"id":"com.apple.proxy.http.global_proxytype","displayName":"Proxy Type","description":"The proxy type. For a manual proxy type, the profile contains the proxy server address, including its port, and optionally a user name and password. For an auto proxy type, you can enter a PAC URL.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":[{"id":"com.apple.proxy.http.global_proxytype_0","displayName":"Manual","description":null,"helpText":null},{"id":"com.apple.proxy.http.global_proxytype_1","displayName":"Auto","description":null,"helpText":null}]},{"id":"com.apple.proxy.http.global_proxyusername","displayName":"Proxy Username","description":"The user name used to authenticate to the proxy server.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},{"id":"com.apple.screensaver_askforpassword","displayName":"Ask For Password","description":"If true, the user is prompted for a password when the screen saver is unlocked or stopped. When you use this prompt, you must also provide Ask For Password Delay. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":[{"id":"com.apple.screensaver_askforpassword_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.screensaver_askforpassword_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.screensaver_askforpassworddelay","displayName":"Ask For Password Delay","description":"The number of seconds to delay before the password will be required to unlock or stop the screen saver (the grace period). A value of 2147483647 (for example, 0x7FFFFFFF) disables this requirement. To use this option, you must set Ask For Password to true. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":null},{"id":"com.apple.screensaver_com.apple.screensaver","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":null},{"id":"com.apple.screensaver_loginwindowidletime","displayName":"Login Window Idle Time","description":"The number of seconds of inactivity before the screen saver activates (0 = Never activate). ","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":null},{"id":"com.apple.screensaver_loginwindowmodulepath","displayName":"Login Window Module Path","description":"The full path to the screen-saver module to use. ","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":null},{"id":"com.apple.screensaver_modulename","displayName":"Module Name","description":"The name of the screen saver module.","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":null},{"id":"com.apple.screensaver.user_com.apple.screensaver.user","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"11c4cf0f-a03d-4309-93b2-011be4c410d5","categoryName":"Screensaver User","options":null},{"id":"com.apple.screensaver.user_idletime","displayName":"Idle Time","description":"The number of seconds of inactivity before the screen saver activates (0 = Never activate).","helpText":null,"infoUrls":[],"categoryId":"11c4cf0f-a03d-4309-93b2-011be4c410d5","categoryName":"Screensaver User","options":null},{"id":"com.apple.screensaver.user_modulename","displayName":"Module Name","description":"The module name.","helpText":null,"infoUrls":[],"categoryId":"11c4cf0f-a03d-4309-93b2-011be4c410d5","categoryName":"Screensaver User","options":null},{"id":"com.apple.screensaver.user_modulepath","displayName":"Module Path","description":"A full path to the screen saver module to use.","helpText":null,"infoUrls":[],"categoryId":"11c4cf0f-a03d-4309-93b2-011be4c410d5","categoryName":"Screensaver User","options":null},{"id":"com.apple.security.fderecoverykeyescrow_com.apple.security.fderecoverykeyescrow","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"bd5533e1-f1ee-4994-8a79-cffe02b12d5c","categoryName":"FileVault Recovery Key Escrow","options":null},{"id":"com.apple.security.fderecoverykeyescrow_devicekey","displayName":"Device Key","description":"The string that's included in help text if the user appears to have forgotten the password. Site admins can use this key to look up the escrowed key for the particular computer. This key replaces the Record Number key used in the previous escrow mechanism. If the key is missing, the device serial number is used instead.","helpText":null,"infoUrls":[],"categoryId":"bd5533e1-f1ee-4994-8a79-cffe02b12d5c","categoryName":"FileVault Recovery Key Escrow","options":null},{"id":"com.apple.security.fderecoverykeyescrow_location","displayName":"Location","description":"The description of the location where the recovery key will be escrowed. This text will be inserted into the message the user sees when enabling FileVault.","helpText":null,"infoUrls":[],"categoryId":"bd5533e1-f1ee-4994-8a79-cffe02b12d5c","categoryName":"FileVault Recovery Key Escrow","options":null},{"id":"com.apple.security.firewall_allowsigned","displayName":"Allow Signed","description":"If true, allows built-in software to receive incoming connections. Available in macOS 12.3 and later.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_allowsigned_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_allowsigned_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_allowsignedapp","displayName":"Allow Signed App","description":"If true, allows downloaded signed software to receive incoming connections. Available in macOS 12.3 and later.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_allowsignedapp_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_allowsignedapp_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_applications","displayName":"Applications","description":"The list of apps with connections controlled by the firewall.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":null},{"id":"com.apple.security.firewall_applications_item_allowed","displayName":"Allowed","description":"If true, allows connections for the app.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_applications_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_applications_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_applications_item_bundleid","displayName":"Bundle ID","description":"The bundle identifier for an app.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":null},{"id":"com.apple.security.firewall_blockallincoming","displayName":"Block All Incoming","description":"If true, enables blocking of all incoming connections. ","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_blockallincoming_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_blockallincoming_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_com.apple.security.firewall","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":null},{"id":"com.apple.security.firewall_enablefirewall","displayName":"Enable Firewall","description":"If true, enables the firewall.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_enablefirewall_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_enablefirewall_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_enablelogging","displayName":"Enable Logging (Deprecated)","description":"If true, enables logging. Available in macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_enablelogging_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_enablelogging_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_enablestealthmode","displayName":"Enable Stealth Mode","description":"If true, enables stealth mode. ","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_enablestealthmode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_enablestealthmode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.firewall_loggingoption","displayName":"Logging Option (Deprecated)","description":"This string specifies the type of logging. Available in macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_loggingoption_0","displayName":"throttled","description":null,"helpText":null},{"id":"com.apple.security.firewall_loggingoption_1","displayName":"brief","description":null,"helpText":null},{"id":"com.apple.security.firewall_loggingoption_2","displayName":"detail","description":null,"helpText":null}]},{"id":"com.apple.security.smartcard_allowsmartcard","displayName":"Allow Smart Card","description":"If false, disables the SmartCard for logins, authorizations, and screen saver unlocking. It is still allowed for other functions, such as signing emails and accessing the web. A restart is required for a setting change to take effect. ","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":[{"id":"com.apple.security.smartcard_allowsmartcard_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.smartcard_allowsmartcard_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.smartcard_checkcertificatetrust","displayName":"Check Certificate Trust","description":"Disable certificate trust check: Turns off certificate trust check.\r\n\r\nEnable certificate trust check and standard validity check: Turns on certificate trust check. A standard validity check is performed but doesn't include additional revocation checks.\r\n\r\nEnable certificate trust check and soft revocation check: Turns on certificate trust check. A soft revocation check is also performed. Until the certificate is explicitly rejected by CRL/OCSP, it's considered valid. This setting means that unavailable or unreachable CRL/OCSP allow this check to succeed.\r\n\r\nEnable certificate trust check and hard revocation check: Turns on certificate trust check. A hard revocation check is also performed. Unless CRL/OCSP explicitly says \"This certificate is OK,\" it's considered invalid. This option is the most secure.","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":[{"id":"com.apple.security.smartcard_checkcertificatetrust_0","displayName":"Disable certificate trust check","description":null,"helpText":null},{"id":"com.apple.security.smartcard_checkcertificatetrust_1","displayName":"Enable certificate trust check and standard validity check","description":null,"helpText":null},{"id":"com.apple.security.smartcard_checkcertificatetrust_2","displayName":"Enable certificate trust check and soft revocation check","description":null,"helpText":null},{"id":"com.apple.security.smartcard_checkcertificatetrust_3","displayName":"Enable certificate trust check and hard revocation check","description":null,"helpText":null}]},{"id":"com.apple.security.smartcard_com.apple.security.smartcard","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":null},{"id":"com.apple.security.smartcard_enforcesmartcard","displayName":"Enforce Smart Card","description":"If true, a user can only log in or authenticate with a SmartCard. Ensure that users have a SmartCard before being targeted with this setting, or they may not be able to access the device. Available in macOS 10.13.2 and later.","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":[{"id":"com.apple.security.smartcard_enforcesmartcard_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.smartcard_enforcesmartcard_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.smartcard_onecardperuser","displayName":"One Card Per User","description":"If true, a user can pair with only one SmartCard, although existing pairings are allowed if already set up. ","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":[{"id":"com.apple.security.smartcard_onecardperuser_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.smartcard_onecardperuser_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.security.smartcard_tokenremovalaction","displayName":"Token Removal Action","description":"If set to Enabled, the screen saver is enabled when the SmartCard is removed. Available in macOS 10.13.4 and later.","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":[{"id":"com.apple.security.smartcard_tokenremovalaction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.security.smartcard_tokenremovalaction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.security.smartcard_userpairing","displayName":"User Pairing","description":"If false, users don't get the pairing dialog, although existing pairings still work. ","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":[{"id":"com.apple.security.smartcard_userpairing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.smartcard_userpairing_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.servicemanagement_com.apple.servicemanagement","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},{"id":"com.apple.servicemanagement_rules","displayName":"Rules","description":"An array of rule dictionaries.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},{"id":"com.apple.servicemanagement_rules_item_comment","displayName":"Comment","description":"An optional description of the rule.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},{"id":"com.apple.servicemanagement_rules_item_ruletype","displayName":"Rule Type","description":"The type of comparision to make.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":[{"id":"com.apple.servicemanagement_rules_item_ruletype_0","displayName":"Bundle Identifier","description":null,"helpText":null},{"id":"com.apple.servicemanagement_rules_item_ruletype_1","displayName":"Bundle Identifier Prefix","description":null,"helpText":null},{"id":"com.apple.servicemanagement_rules_item_ruletype_2","displayName":"Label","description":null,"helpText":null},{"id":"com.apple.servicemanagement_rules_item_ruletype_3","displayName":"Label Prefix","description":null,"helpText":null},{"id":"com.apple.servicemanagement_rules_item_ruletype_4","displayName":"Team Identifier","description":null,"helpText":null}]},{"id":"com.apple.servicemanagement_rules_item_rulevalue","displayName":"Rule Value","description":"The value to compare with each login item's value, to determine a match to this rule.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},{"id":"com.apple.servicemanagement_rules_item_teamidentifier","displayName":"Team Identifier","description":"An additional constraint to limit the scope of the rule that is tested after matching the Rule Type and Rule Value.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},{"id":"com.apple.shareddeviceconfiguration_assettaginformation","displayName":"Asset Tag Information","description":"The asset tag information for the device, displayed in the Login Window and Lock Screen.","helpText":null,"infoUrls":[],"categoryId":"dec8381a-0a61-406b-842b-fc6ae9930795","categoryName":"Lock Screen Message","options":null},{"id":"com.apple.shareddeviceconfiguration_com.apple.shareddeviceconfiguration","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"dec8381a-0a61-406b-842b-fc6ae9930795","categoryName":"Lock Screen Message","options":null},{"id":"com.apple.shareddeviceconfiguration_lockscreenfootnote","displayName":"Lock Screen Footnote","description":"The footnote displayed in the login window and Lock screen. ","helpText":null,"infoUrls":[],"categoryId":"dec8381a-0a61-406b-842b-fc6ae9930795","categoryName":"Lock Screen Message","options":null},{"id":"com.apple.softwareupdate_allowprereleaseinstallation","displayName":"Allow Pre Release Installation (Deprecated)","description":"If true, prerelease software can be installed on this computer. ","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_allowprereleaseinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_allowprereleaseinstallation_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_automaticallyinstallappupdates","displayName":"Automatically Install App Updates (Deprecated)","description":"If false, deselects the \"Install app updates from the App Store\" option and prevents the user from changing the option. ","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_automaticallyinstallappupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_automaticallyinstallappupdates_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_automaticallyinstallmacosupdates","displayName":"Automatically Install Mac OS Updates (Deprecated)","description":"If false, restricts the \"Install macOS Updates\" option and prevents the user from changing the option.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_automaticallyinstallmacosupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_automaticallyinstallmacosupdates_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_automaticcheckenabled","displayName":"Automatic Check Enabled (Deprecated)","description":"If false, deselects the \"Check for updates\" option and prevents the user from changing the option.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_automaticcheckenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_automaticcheckenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_automaticdownload","displayName":"Automatic Download (Deprecated)","description":"If false, deselects the \"Download new updates when available from the App Store\" option and prevents the user from changing the option.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_automaticdownload_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_automaticdownload_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_com.apple.softwareupdate","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":null},{"id":"com.apple.softwareupdate_configdatainstall","displayName":"Config Data Install (Deprecated)","description":"If false, restricts the automatic installation of configuration data.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_configdatainstall_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_configdatainstall_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_criticalupdateinstall","displayName":"Critical Update Install (Deprecated)","description":"If false, disables the automatic installation of critical updates and prevents the user from changing the \"Install system data files and security updates\" option.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_criticalupdateinstall_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_criticalupdateinstall_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.softwareupdate_restrict-software-update-require-admin-to-install","displayName":"Restrict Software Update Require Admin To Install (Deprecated)","description":"If true, restrict app installations to admin users. This key has the same function as the Restrict Store Require Admin To Install key in the App Store profile. ","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_restrict-software-update-require-admin-to-install_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_restrict-software-update-require-admin-to-install_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.subscribedcalendar.account_com.apple.subscribedcalendar.account","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":null},{"id":"com.apple.subscribedcalendar.account_subcalaccountdescription","displayName":"Account Description","description":"The description of the account.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":null},{"id":"com.apple.subscribedcalendar.account_subcalaccounthostname","displayName":"Account Host Name","description":"The server’s address.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":null},{"id":"com.apple.subscribedcalendar.account_subcalaccountpassword","displayName":"Account Password","description":"The user’s password.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":null},{"id":"com.apple.subscribedcalendar.account_subcalaccountusername","displayName":"Account Username","description":"The user's username.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":null},{"id":"com.apple.subscribedcalendar.account_subcalaccountusessl","displayName":"Account Use SSL","description":"If true, enables SSL.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":[{"id":"com.apple.subscribedcalendar.account_subcalaccountusessl_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.subscribedcalendar.account_subcalaccountusessl_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.system-extension-policy_allowedsystemextensions","displayName":"Allowed System Extensions","description":"A dictionary of approved system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension to install. It’s an error for the same team identifier to appear in both the AllowedTeamIdentifiers array and as a key in this dictionary.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowedsystemextensions_generickey","displayName":"Allowed System Extensions","description":"The mapping of team identifiers to arrays of bundle identifiers, where the bundle identifier defines the system extension to install.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowedsystemextensions_generickey_keytobereplaced","displayName":"Team Identifier","description":"Add a Team Identifier of valid and signed system extensions to load. The team identifier must be alphanumeric (letters and numbers) and have 10 characters. For example, enter ABCDE12345.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowedsystemextensiontypes","displayName":"Allowed System Extension Types","description":"A dictionary that maps a team identifier to an array of strings, where each string is a type of system extension that you can install for that team identifier. The allowed extension types are DriverExtension, NetworkExtension, and EndpointSecurityExtension. If there’s no entry for a specified team identifier in the dictionary, the system allows all extension types.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowedsystemextensiontypes_generickey","displayName":"Allowed System Extension Types","description":"The mapping of team identifier to an array of strings, where each string is a type of system extension that you can install for that team identifier.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowedsystemextensiontypes_generickey_keytobereplaced","displayName":"Team Identifier","description":"Add a Team Identifier of valid and signed system extensions to load. The team identifier must be alphanumeric (letters and numbers) and have 10 characters. For example, enter ABCDE12345.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowedteamidentifiers","displayName":"Allowed Team Identifiers","description":"An array of team identifiers that defines valid, signed system extensions that are allowable to load. Approved system extensions are those signed with any of the specified team identifiers. It’s an error for the same team identifier to appear in both this array and as a key in the Allowed System Extensions dictionary.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_allowuseroverrides","displayName":"Allow User Overrides","description":"If false, restricts users from approving additional system extensions that configuration profiles don’t explicitly allow.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":[{"id":"com.apple.system-extension-policy_allowuseroverrides_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.system-extension-policy_allowuseroverrides_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.system-extension-policy_com.apple.system-extension-policy","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_nonremovablefromuisystemextensions","displayName":"Non Removable From UI System Extensions","description":"A dictionary of system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension which cannot be disabled or uninstalled from System Settings or Finder. The set of system extensions between 'RemovableSystemExtensions' and 'NonRemovableFromUISystemExtensions' are allowed to overlap.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_nonremovablefromuisystemextensions_generickey","displayName":"ANY","description":"System extension bundle identifiers","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_nonremovablefromuisystemextensions_generickey_keytobereplaced","displayName":"Non Removable From UI System Extensions","description":"A dictionary of system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension which cannot be disabled or uninstalled from System Settings or Finder. The set of system extensions between 'RemovableSystemExtensions' and 'NonRemovableFromUISystemExtensions' are allowed to overlap.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_nonremovablesystemextensions","displayName":"Non Removable System Extensions","description":"A dictionary of system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension which cannot be disabled or uninstalled when SIP is enabled. It's an error for the same mapping to appear in the dictionary values corresponding to 'RemovableSystemExtensions' and 'NonRemovableSystemExtensions' keys.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_nonremovablesystemextensions_generickey","displayName":"ANY","description":"System extension bundle identifiers","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_nonremovablesystemextensions_generickey_keytobereplaced","displayName":"Non Removable System Extensions","description":"A dictionary of system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension which cannot be disabled or uninstalled when SIP is enabled. It's an error for the same mapping to appear in the dictionary values corresponding to 'RemovableSystemExtensions' and 'NonRemovableSystemExtensions' keys.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_removablesystemextensions","displayName":"Removable System Extensions","description":"A dictionary of system extensions that are allowed to remove themselves from the machine. The dictionary maps team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension. An application using the OSSystemExtensionDeactivationRequest API can deactivate the specified system extensions without requiring an administrator to authorize the operation. Available in macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_removablesystemextensions_generickey","displayName":"Removable System Extensions","description":"The dictionary maps team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system-extension-policy_removablesystemextensions_generickey_keytobereplaced","displayName":"Team Identifier","description":"Add a Team Identifier of valid and signed system extensions to load. The team identifier must be alphanumeric (letters and numbers) and have 10 characters. For example, enter ABCDE12345.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},{"id":"com.apple.system.logging_com.apple.system.logging","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","categoryName":"System Logging","options":null},{"id":"com.apple.system.logging_system","displayName":"System","description":"This dictionary has one key, Enable Private Data. Setting that value to true enables private data logging for the entire system.","helpText":null,"infoUrls":[],"categoryId":"0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","categoryName":"System Logging","options":null},{"id":"com.apple.system.logging_system_enable-private-data","displayName":"Enable Private Data","description":"Setting this value to true enables private data logging for the entire system.","helpText":null,"infoUrls":[],"categoryId":"0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","categoryName":"System Logging","options":[{"id":"com.apple.system.logging_system_enable-private-data_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.system.logging_system_enable-private-data_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_com.apple.systemconfiguration","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies","displayName":"Proxies","description":"The dictionary containing all the proxies for this device.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_exceptionslist","displayName":"Exceptions List","description":"The list of hosts and domains that should bypass proxy settings.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_fallbackallowed","displayName":"Fall Back Allowed","description":"If true, enables fallback.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_fallbackallowed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_fallbackallowed_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_ftpenable","displayName":"FTP Enable","description":"If true, enables FTP proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_ftpenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_ftpenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_ftppassive","displayName":"FTP Passive","description":"If true, enables passive FTP mode. ","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_ftppassive_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_ftppassive_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_ftpport","displayName":"FTP Port","description":"The FTP proxy port.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_ftpproxy","displayName":"FTP Proxy","description":"The host name or IP address for the FTP proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_gopherenable","displayName":"Gopher Enable","description":"If true, enables gopher proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_gopherenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_gopherenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_gopherport","displayName":"Gopher Port","description":"The gopher proxy port. ","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_gopherproxy","displayName":"Gopher Proxy","description":"The host name or IP address for the gopher proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_httpenable","displayName":"HTTP Enable","description":"If true, enables web proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_httpenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_httpenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_httpport","displayName":"HTTP Port","description":"The web proxy port.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_httpproxy","displayName":"HTTP Proxy","description":"The host name or IP address for the web proxy. ","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_httpsenable","displayName":"HTTPS Enable","description":"If true, enables secure web proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_httpsenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_httpsenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_httpsport","displayName":"HTTPS Port","description":"The secure web proxy port.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_httpsproxy","displayName":"HTTPS Proxy","description":"The host name or IP address for the secure web proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_proxyautoconfigenable","displayName":"Proxy Auto Config Enable","description":"If true, enables automatic proxy configuration.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_proxyautoconfigenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_proxyautoconfigenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_proxyautoconfigurlstring","displayName":"Proxy Auto Config URL String","description":"The automatic proxy configuration URL.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_proxycaptiveloginallowed","displayName":"Proxy Captive Login Allowed","description":"If true, allows client to log into captive portal network.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_proxycaptiveloginallowed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_proxycaptiveloginallowed_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_rtspenable","displayName":"RTSP Enable","description":"If true, enable streaming proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_rtspenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_rtspenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_rtspport","displayName":"RTSP Port","description":"The streaming proxy port.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_rtspproxy","displayName":"RTSP Proxy","description":"The host name or IP address for the streaming proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_socksenable","displayName":"SOCKS Enable","description":"If true, enable the SOCKS proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_socksenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_socksenable_1","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systemconfiguration_proxies_socksportinteger","displayName":"SOCKS Port Integer","description":"The SOCKS proxy port.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systemconfiguration_proxies_socksproxy","displayName":"SOCKS Proxy","description":"The host name or IP address for the SOCKS proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},{"id":"com.apple.systempolicy.control_allowidentifieddevelopers","displayName":"Allow Identified Developers","description":"If true, enables Gatekeeper's \"Mac App Store and identified developers\" option.\r\nIf false, enables Gatekeeper's \"Mac App Store\" option.\r\n\r\nIf the value of Enable Assessment isn't set to true, this key has no effect.","helpText":null,"infoUrls":[],"categoryId":"763525a0-8456-4336-a8d1-392253e8fdd8","categoryName":"System Policy Control","options":[{"id":"com.apple.systempolicy.control_allowidentifieddevelopers_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systempolicy.control_allowidentifieddevelopers_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systempolicy.control_com.apple.systempolicy.control","displayName":"Top Level Setting Group Collection","description":"com.apple.systempolicy.control","helpText":null,"infoUrls":[],"categoryId":"763525a0-8456-4336-a8d1-392253e8fdd8","categoryName":"System Policy Control","options":null},{"id":"com.apple.systempolicy.control_enableassessment","displayName":"Enable Assessment","description":"If true, enables Gatekeeper.","helpText":null,"infoUrls":[],"categoryId":"763525a0-8456-4336-a8d1-392253e8fdd8","categoryName":"System Policy Control","options":[{"id":"com.apple.systempolicy.control_enableassessment_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systempolicy.control_enableassessment_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systempolicy.control_enablexprotectmalwareupload","displayName":"Enable XProtect Malware Upload","description":"If false, will prevent Gatekeeper from prompting the user to upload blocked malware to Apple for purposes of improving malware detection.","helpText":null,"infoUrls":[],"categoryId":"763525a0-8456-4336-a8d1-392253e8fdd8","categoryName":"System Policy Control","options":[{"id":"com.apple.systempolicy.control_enablexprotectmalwareupload_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.systempolicy.control_enablexprotectmalwareupload_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.systempolicy.managed_com.apple.systempolicy.managed","displayName":"Top Level Setting Group Collection","description":"com.apple.systempolicy.managed","helpText":null,"infoUrls":[],"categoryId":"64538726-8745-4e7a-b370-332f725b58bf","categoryName":"System Policy Managed","options":null},{"id":"com.apple.systempolicy.managed_disableoverride","displayName":"Disable Override","description":"If true, disables the Finder's contextual menu item.","helpText":null,"infoUrls":[],"categoryId":"64538726-8745-4e7a-b370-332f725b58bf","categoryName":"System Policy Managed","options":[{"id":"com.apple.systempolicy.managed_disableoverride_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systempolicy.managed_disableoverride_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.systempreferences_com.apple.systempreferences","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","categoryName":"System Preferences","options":null},{"id":"com.apple.systempreferences_disabledpreferencepanes","displayName":"Disabled Preference Panes","description":"The list of disabled System Preferences panes.","helpText":null,"infoUrls":[],"categoryId":"c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","categoryName":"System Preferences","options":null},{"id":"com.apple.systempreferences_enabledpreferencepanes","displayName":"Enabled Preference Panes","description":"The list of enabled System Preferences panes.","helpText":null,"infoUrls":[],"categoryId":"c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","categoryName":"System Preferences","options":null},{"id":"com.apple.tcc.configuration-profile-policy_com.apple.tcc.configuration-profile-policy","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services","displayName":"Services","description":"A dictionary whose keys are limited to the privacy policy control services. In the case of conflicting specifications, the most restrictive setting (deny) is used.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility","displayName":"Accessibility (deprecated)","description":"Specifies the policies for the app via the Accessibility subsystem. This profile deprecated its ability to grant access as of macOS 26.2, and removes that ability in macOS 27.0.\n\nDeprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app-settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook","displayName":"Address Book","description":"Specifies the policies for contact information managed by the Contacts.app.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents","displayName":"Apple Events","description":"Specifies the policies for the app sending restricted AppleEvents to another process.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_aereceivercoderequirement","displayName":"AE Receiver Code Requirement","description":"The code requirement for the receiving binary.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_aereceiveridentifier","displayName":"AE Receiver Identifier","description":"The identifier of the process receiving an Apple Event sent by the Identifier process.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_aereceiveridentifiertype","displayName":"AE Receiver Identifier Type","description":"The type of AE Receiver Identifier value, either bundle ID or path.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_aereceiveridentifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_aereceiveridentifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways","displayName":"Bluetooth Always (deprecated)","description":"Specifies the policies for the app to access Bluetooth devices.\n\nDeprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app-settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_aereceivercoderequirement","displayName":"AE Receiver Code Requirement","description":"The code requirement for the receiving binary. This code requirement is required for AppleEvents service; not valid for other services.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_aereceiveridentifier","displayName":"AE Receiver Identifier","description":"The identifier of the process receiving an AppleEvent sent by the Identifier process. This identifier is required for AppleEvents service; not valid for other services.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_aereceiveridentifiertype","displayName":"AE Receiver Identifier Type","description":"The type of AEReceiverIdentifier value, either `bundleID` or `path`. This setting is required for AppleEvents service; not valid for other services.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_aereceiveridentifiertype_0","displayName":"bundleID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_aereceiveridentifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_allowed","displayName":"Allowed","description":"If `true`, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.\n\n> Note:\n> Every payload needs to include either `Authorization` or `Allowed`, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_allowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_allowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_authorization","displayName":"Authorization","description":"The `Authorization` key is an optional replacement for the `Allowed` key, which has one of the following possible values:\n\n- `Allow`: Equivalent to a `true` value for the `Allowed` key\n- `Deny`: Equivalent to a `false` value for the `Allowed` key\n- `AllowStandardUserToSetSystemService`: Allows a standard (non-admin) user to configure the permissions for the specified app in the Privacy preferences for services that otherwise require admin authorization; only valid for the `ListenEvent` and `ScreenCapture` services\n\n> Note:\n> Every payload needs to include either `Authorization` or `Allowed`, but not both.\n\nAvailable in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_authorization_2","displayName":"AllowStandardUserToSetSystemService","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command ''codesign -display -r -''.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_comment","displayName":"Comment","description":"Not used.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifiertype_0","displayName":"bundleID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_staticcode","displayName":"Static Code","description":"If `true`, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_staticcode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_staticcode_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar","displayName":"Calendar","description":"Specifies the policies for calendar information managed by the Calendar.app.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_calendar_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_camera","displayName":"Camera (deprecated)","description":"A system camera. A profile can't grant access to the camera; it can only deny it.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence","displayName":"File Provider Presence","description":"Allows a File Provider application to know when the user is using files managed by the File Provider.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent","displayName":"Listen Event","description":"Allows the application to use CoreGraphics and HID APIs to listen to (receive) CGEvents and HID events from all processes. A profile can't grant access to these events; it can only deny it.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_allowed","displayName":"Allowed (Deprecated)","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary","displayName":"Media Library","description":"Allows the application to access Apple Music, music and video activity, and the media library.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone","displayName":"Microphone (deprecated)","description":"A system microphone. A profile can't grant access to the microphone; it can only deny it.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_photos","displayName":"Photos","description":"The pictures managed by the Photos app in `~/Pictures/.photoslibrary`.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent","displayName":"Post Event","description":"Specifies the policies for the application to use CoreGraphics APIs to send CGEvents to the system event stream.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders","displayName":"Reminders","description":"Specifies the policies for reminders information managed by the Reminders app.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture","displayName":"Screen Capture","description":"Allows the application to capture (read) the contents of the system display. A profile can't grant access to the contents; it can only deny it.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_allowed","displayName":"Allowed (Deprecated)","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition","displayName":"Speech Recognition (deprecated)","description":"Allows the application to use the system Speech Recognition facility and to send speech data to Apple.\n\nDeprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app-settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles","displayName":"System Policy All Files","description":"Allows the application access to all protected files, including system administration files.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles","displayName":"System Policy App Bundles","description":"Allows the application to update or delete other apps. Available in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata","displayName":"System Policy App Data","description":"Specifies the policies for the app to access the data of other apps.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_allowed","displayName":"Allowed","description":"If 'true', access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_allowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_allowed_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_authorization","displayName":"Authorization","description":"The 'Authorization' key is an optional replacement for the 'Allowed' key. Every payload must specify either 'Authorization' or 'Allowed', but not both.\n'Allow': Equivalent to a 'true' value for the 'Allowed' key.\n'Deny': Equivalent to a 'false' value for the 'Allowed' key.\n'AllowStandardUserToSetSystemService:' allows a standard (non-admin) user to configure the permissions for the specified app in the Privacy preferences for services that otherwise require admin authorization. 'AllowStandardUserToSetSystemService' is only valid for the 'ListenEvent' and 'ScreenCapture' services.\nAvailable in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_authorization_2","displayName":"AllowStandardUserToSetSystemService","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command ''codesign -display -r -''.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifiertype_0","displayName":"bundleID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_staticcode","displayName":"Static Code","description":"If `true`, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_staticcode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_staticcode_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder","displayName":"System Policy Desktop Folder","description":"Allows the application to access files in the user's Desktop folder.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder","displayName":"System Policy Documents Folder","description":"Allows the application to access files in the user's Documents folder.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydocumentsfolder_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder","displayName":"System Policy Downloads Folder","description":"Allows the application to access files in the user's Downloads folder.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes","displayName":"System Policy Network Volumes","description":"Allows the application to access files on network volumes.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes","displayName":"System Policy Removable Volumes","description":"Allows the application to access files on removable volumes.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles","displayName":"System Policy Sys Admin Files","description":"Allows the application access to some files used in system administration.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_allowed_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_closeviewfarpoint","displayName":"Close View Far Point","description":"The minimum zoom level in the Zoom options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_closeviewhotkeysenabled","displayName":"Close View Hotkeys Enabled","description":"If true, enables \"Use keyboard shortcuts\" in the Zoom options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_closeviewhotkeysenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_closeviewhotkeysenabled_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_closeviewnearpoint","displayName":"Close View Near Point","description":"The maximum zoom level in the Zoom options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_closeviewscrollwheeltoggle","displayName":"Close View Scroll Wheel Toggle","description":"If true, enables \"Use scroll gesture\" in the Zoom options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_closeviewscrollwheeltoggle_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_closeviewscrollwheeltoggle_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_closeviewsmoothimages","displayName":"Close View Smooth Images","description":"If true, enables \"Smooth images\" in the Zoom options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_closeviewsmoothimages_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_closeviewsmoothimages_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_com.apple.universalaccess","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_contrast","displayName":"Contrast","description":"The contrast value in the Display options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_flashscreen","displayName":"Flash Screen","description":"If true, enables \"Flash the screen\" in the Audio options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_flashscreen_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_flashscreen_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_mousedriver","displayName":"Mouse Driver","description":"If true, enables Mouse Keys in the Mouse & Trackpad options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_mousedriver_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_mousedriver_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_mousedrivercursorsize","displayName":"Mouse Driver Cursor Size","description":"The size of the cursor.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_mousedriverignoretrackpad","displayName":"Mouse Driver Ignore Trackpad","description":"If true, ignores the built-in trackpad.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_mousedriverignoretrackpad_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_mousedriverignoretrackpad_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_mousedriverinitialdelay","displayName":"Mouse Driver Initial Delay","description":"The initial delay before moving the mouse with Mouse Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_mousedrivermaxspeed","displayName":"Mouse Driver Max Speed","description":"The maximum speed for the cursor when using Mouse Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_slowkey","displayName":"Slow Key","description":"If true, enables \"Slow Keys\" in the Keyboard options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_slowkey_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_slowkey_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_slowkeybeepon","displayName":"Slow Key Beep On","description":"If true, enables \"click key sounds\" for Slow Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_slowkeybeepon_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_slowkeybeepon_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_slowkeydelay","displayName":"Slow Key Delay","description":"The acceptance delay, in milliseconds, for Slow Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},{"id":"com.apple.universalaccess_stereoasmono","displayName":"Stereo as Mono","description":"If true, plays stereo audio as mono.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_stereoasmono_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_stereoasmono_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_stickykey","displayName":"Sticky Key","description":"If true, enables Sticky Keys in the Keyboard options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_stickykey_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_stickykey_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_stickykeybeeponmodifier","displayName":"Sticky Key Beep On Modifier","description":"If true, enables the beep when a modifier key is set for Sticky Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_stickykeybeeponmodifier_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_stickykeybeeponmodifier_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_stickykeyshowwindow","displayName":"Sticky Key Show Window","description":"If true, enables \"Display pressed keys on screen\" for Sticky Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_stickykeyshowwindow_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_stickykeyshowwindow_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_voiceoveronoffkey","displayName":"Voice Over On Off Key","description":"If true, enables Voice Over.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_voiceoveronoffkey_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_voiceoveronoffkey_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.universalaccess_whiteonblack","displayName":"White On Black","description":"If true, enables Invert Colors in Display Accommodations.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_whiteonblack_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_whiteonblack_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_allowlistbookmarks","displayName":"Allow List Bookmarks","description":"An array of dictionaries defining the pages that the user can visit.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_allowlistbookmarks_item_title","displayName":"Title","description":"The title of the bookmark.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_allowlistbookmarks_item_url","displayName":"URL","description":"The URL of the bookmark in the allow list.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_autofilterenabled","displayName":"Auto Filter Enabled","description":"If true, automatic filtering is in an enabled state. This function evaluates each web page as it loads and attempts to identify and block content not suitable for children. The search algorithm is complex and may vary from release to release, but it’s basically looking for adult language.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_autofilterenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_autofilterenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_com.apple.webcontent-filter","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_denylisturls","displayName":"Deny List URLs","description":"An array of URLs that are inaccessible. Limit the number of these URLs to about 500.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_filterbrowsers","displayName":"Filter Browsers","description":"If true, enables the filtering of WebKit traffic.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_filterbrowsers_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_filterbrowsers_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_filterdataproviderbundleidentifier","displayName":"Filter Data Provider Bundle Identifier","description":"The bundle identifier string of the filter data provider system extension. This string identifies the filter data provider when the filter starts running. This field is a requirement if Filter Sockets is true.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_filterdataproviderdesignatedrequirement","displayName":"Filter Data Provider Designated Requirement","description":"The designated requirement string that the system embeds in the code signature of the filter data provider system extension. This string identifies the filter data provider when the filter starts running. This field is a requirement if Filter Sockets is true.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_filtergrade","displayName":"Filter Grade","description":"This value is for deriving the relative order of content filters. Filters with a grade of firewall see network traffic before filters with a grade of inspector. The system doesn’t define the order of filters within a grade.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_filtergrade_0","displayName":"firewall","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_filtergrade_1","displayName":"inspector","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_filterpacketproviderbundleidentifier","displayName":"Filter Packet Provider Bundle Identifier","description":"The bundle identifier string of the filter packet provider system extension. This string identifies the filter packet provider when the filter starts running. This field is a requirement if Filter Packets is true.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_filterpacketproviderdesignatedrequirement","displayName":"Filter Packet Provider Designated Requirement","description":"The designated requirement string that the system embeds in the code signature of the filter packet provider system extension. This string identifies the filter packet provider when the filter starts running. This field is a requirement if Filter Packets is true.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_filterpackets","displayName":"Filter Packets","description":"If this value is true, the property enables the filtering of network packets. Either Filter Packets or Filter Sockets must be true for the filter to have an effect.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_filterpackets_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_filterpackets_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_filtersockets","displayName":"Filter Sockets","description":"If true, enables the filtering of socket traffic.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_filtersockets_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_filtersockets_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_filtertype","displayName":"Filter Type","description":"The type of filter, built-in or plug-in. In macOS, the system supports only the plug-in value.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_filtertype_0","displayName":"Built-in","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_filtertype_1","displayName":"Plug-in","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_hidedenylisturls","displayName":"Hide Deny List UR Ls","description":"If `true`, the device hides the `DenyListURLs` item in the profiles that display in Settings > General > VPN & Device Management.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_hidedenylisturls_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_hidedenylisturls_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_organization","displayName":"Organization","description":"The organization string that passes to the third-party plug-in.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_password","displayName":"Password","description":"The password for the service.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_permittedurls","displayName":"Permitted URLs","description":"An array or URLs that are accessible whether or not the automatic filter allows access. The system uses this array only when Auto Filter Enabled is true. Otherwise, it ignores this field.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_pluginbundleid","displayName":"Plugin Bundle ID","description":"The bundle ID of the plug-in that provides filtering service.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_safarihistoryretentionenabled","displayName":"Safari History Retention Enabled","description":"If `true`, this payload enforces a policy which requires retention of browsing history. This causes Safari to disable clearing of browsing history, and prevents the use of private browsing mode because that mode doesn't keep browsing history.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_safarihistoryretentionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_safarihistoryretentionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.apple.webcontent-filter_serveraddress","displayName":"Server Address","description":"The server address, which may be the IP address, hostname, or URL.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_userdefinedname","displayName":"User Defined Name","description":"The display name for this filtering configuration.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.webcontent-filter_username","displayName":"User Name","description":"The user name for the service.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},{"id":"com.apple.xsan_com.apple.xsan","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":null},{"id":"com.apple.xsan_fsnameservers","displayName":"FS Name Servers","description":"An array of storage area network (SAN) File System Name Server coordinators. The list should contain the same addresses in the same order as the metadata controller (MDC) /Library/Preferences/Xsan/fsnameservers file. Xsan SAN clients automatically receive updates to the fsnameservers list from the SAN configuration servers whenever this list changes. StorNext administrators should update their profile whenever the fsnameservers list changes. This key is required for StorNext SANs.","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":null},{"id":"com.apple.xsan_sanauthmethod","displayName":"San Auth Method","description":"The authentication method for the SAN. This key is required for all Xsan SANs. It's optional for StorNext SANs but should be set if the StorNext SAN uses an auth_secret file. Only one value is accepted: auth_secret","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":{"id":"com.apple.xsan_sanauthmethod_0","displayName":"auth_secret","description":null,"helpText":null}},{"id":"com.apple.xsan_sanconfigurls","displayName":"San Config URLs","description":"An array of LDAP URLs where Xsan systems can obtain SAN configuration updates. This key is required for all Xsan SANs. There should be one entry for each Xsan MDC. Example URL: ldaps://mdc1.example.com:389","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":null},{"id":"com.apple.xsan_sanname","displayName":"San Name","description":"The name of the SAN. This key is required for all Xsan SANs. The name must exactly match the name of the SAN defined in the metadata server.","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":null},{"id":"com.apple.xsan_sharedsecret","displayName":"Shared Secret","description":"The shared secret used for Xsan network authentication. This key is required when the San Auth Method key is present. The value should equal the content of the MDC's /Library/Preferences/Xsan/.auth_secret file.","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":null},{"id":"com.apple.xsan.preferences_com.apple.xsan.preferences","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},{"id":"com.apple.xsan.preferences_denydlc","displayName":"Deny DLC","description":"An array of StorNext volume names. If the Xsan client is attempting to mount a volume named in this array, the client only mounts the volume if its logical units (LUNs) are available through Fibre Channel. It doesn't attempt to mount the volume using Distributed LAN Client (DLC).","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},{"id":"com.apple.xsan.preferences_denymount","displayName":"Deny Mount","description":"An array of Xsan or StorNext volume names. If no Only Mount array is present, the Xsan client automatically attempts to mount all SAN volumes except the volumes in this array. The system administrator can mount those volumes manually by using the xsanctl(8) mount command.","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},{"id":"com.apple.xsan.preferences_onlymount","displayName":"Only Mount","description":"An array of Xsan or StorNext volume names. The Xsan client attempts to automatically mount these volumes at startup. The system administrator can mount additional volumes manually by using the xsanctl(8) mount command.","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},{"id":"com.apple.xsan.preferences_preferdlc","displayName":"Prefer DLC","description":"An array of StorNext volume names. If the Xsan client is attempting to mount a volume named in this array, the Xsan client attempts to mount the volume using DLC. If DLC isn't available, the client attempts to mount the volume if its LUNs are available through Fibre Channel. The volume name must not also appear in Deny DLC.","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},{"id":"com.apple.xsan.preferences_usedlc","displayName":"Use DLC","description":"If true, use the DLC for all volumes.","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":[{"id":"com.apple.xsan.preferences_usedlc_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.xsan.preferences_usedlc_true","displayName":"True","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.accesscontrolallowmethodsincorspreflightspecconformant","displayName":"Make Access-Control-Allow-Methods matching in CORS preflight spec conformant","description":"This policy controls whether request methods are uppercased when matching with Access-Control-Allow-Methods response headers in CORS preflight.\n\nIf you disable this policy, request methods are uppercased. This is the behavior on or before Microsoft Edge 108.\n\nIf you enable or don't configure this policy, request methods aren't uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT.\n\nThis would reject fetch(url, {method: 'Foo'}) + \"Access-Control-Allow-Methods: FOO\" response header,\nand would accept fetch(url, {method: 'Foo'}) + \"Access-Control-Allow-Methods: Foo\" response header.\n\nNote: request methods \"post\" and \"put\" aren't affected, while \"patch\" is affected.\n\nThis policy is intended to be temporary and will be removed in the future.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.accesscontrolallowmethodsincorspreflightspecconformant_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.accesscontrolallowmethodsincorspreflightspecconformant_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.accessibilityimagelabelsenabled","displayName":"Let screen reader users get image descriptions from Microsoft","description":"Lets screen reader users get descriptions of unlabeled images on the web.\n\nIf you enable or don't configure this policy, users have the option of using an anonymous Microsoft service. This service provides automatic descriptions for unlabeled images users encounter on the web when they're using a screen reader.\n\nIf you disable this policy, users can't enable the Get Image Descriptions from Microsoft feature.\n\nWhen this feature is enabled, the content of images that need a generated description is sent to Microsoft servers to generate a description.\n\nNo cookies or other user data is sent to Microsoft, and Microsoft doesn't save or log any image content.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.accessibilityimagelabelsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.accessibilityimagelabelsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.additionalsearchboxenabled","displayName":"Enable additional search box in browser","description":"A search box is another text input field located next to the address bar in a web browser. It allows users to perform web searches directly from the browser interface.\n\nIf you enable or don't configure this policy, the search box is visible and available for use.\nUsers can toggle the search box in Microsoft Edge Settings page edge://settings/appearance#SearchBoxInToolbar.\n\nIf you disable this policy, search box won't be visible, and users have to use the address bar or navigate to a search engine to perform web searches.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.additionalsearchboxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.additionalsearchboxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbareditingenabled","displayName":"Configure address bar editing","description":"If you enable or don't configure this policy, users can change the URL in the address bar.\n\nIf you disable this policy, it prevents users from changing the URL in the address bar.\n\nNote: This policy doesn't prevent the browser from navigating to any URL. Users can still navigate to any URL using the search option in the default New Tab Page, or using any link that leads to a web search engine. To ensure that users can only go to sites you expect, consider configuring the following policies in addition to this policy:\n\n- \"NewTabPageLocation\"\n\n- \"HomepageLocation\"\n\n- \"HomepageIsNewTabPage\"\n\n- \"URLBlocklist\" and \"URLAllowlist\" to scope the pages that browser can navigate to.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbareditingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbareditingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarmicrosoftsearchinbingproviderenabled","displayName":"Enable Microsoft Search in Bing suggestions in the address bar (Obsolete)","description":"Enables the display of relevant Microsoft Search in Bing suggestions in the address bar's suggestion list when the user enters a search query in the address bar. If you enable or don't configure this policy, users can see internal results powered by Microsoft Search in Bing in the Microsoft Edge address bar suggestion list. To access Microsoft Search in Bing results, the user must be signed in to Microsoft Edge with their organization's Azure AD account.\n\nIf you disable this policy, users won't see internal results in the Microsoft Edge address bar suggestion list.\n\nStarting with Microsoft Edge version 89, Microsoft Search in Bing suggestions will be available even if Bing isn't the user's default search provider.\n\nThis policy is no longer applicable due to changes in access to work search through Bing-related endpoints.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarmicrosoftsearchinbingproviderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarmicrosoftsearchinbingproviderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbartrendingsuggestenabled","displayName":"Enable Microsoft Bing trending suggestions in the address bar","description":"This policy controls whether Microsoft Bing trending suggestions appear in the address bar’s suggestion dropdown when users select the address bar while on a New Tab Page.\n\nIf this policy is enabled or not configured, Microsoft Bing trending suggestions appear in the address bar suggestion dropdown.\n\nIf this policy is disabled, Microsoft Edge doesn't display Microsoft Bing trending suggestions when users select the address bar.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbartrendingsuggestenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbartrendingsuggestenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarworksearchresultsenabled","displayName":"Enable Work Search suggestions in the address bar","description":"Enables the display of relevant workplace suggestions in the address bar’s suggestion dropdown when users type a query in the address bar.\n\nIf this policy is enabled or not configured, users can view internal work-related suggestions, such as bookmarks, files, and people results powered by Microsoft 365, in the Microsoft Edge address bar suggestion dropdown. To access these results, users must be signed into Microsoft Edge with their Entra ID account associated with that organization.\n\nIf this policy is disabled, users can't see internal workplace results in the Microsoft Edge address bar suggestion dropdown.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarworksearchresultsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarworksearchresultsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads","description":"Controls whether ads are blocked on sites with intrusive ads.\n\nPolicy options mapping:\n\n* AllowAds (1) = Allow ads on all sites\n\n* BlockAds (2) = Block ads on sites with intrusive ads. (Default value)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.adssettingforintrusiveadssites_allowads","displayName":"Allow ads on all sites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.adssettingforintrusiveadssites_blockads","displayName":"Block ads on sites with intrusive ads. (Default value)","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.adstransparencyenabled","displayName":"Configure if the ads transparency feature is enabled","description":"Lets you decide whether the ads transparency feature is enabled. This behavior only applies to the \"balanced\" mode of tracking prevention, and doesn't impact \"basic\" or \"strict\" modes. Your users' tracking prevention level can be configured using the \"TrackingPrevention\" policy. AdsTransparencyEnabled will only have an effect if \"TrackingPrevention\" is set to TrackingPreventionBalanced or isn't configured.\n\nIf you enable or don't configure this policy, transparency metadata provided by ads are available to the user when the feature is active.\n\nWhen the feature is enabled, Tracking Prevention enables exceptions for the associated ad providers that have met Microsoft's privacy standards.\n\nIf you disable this policy, Tracking Prevention won't adjust its behavior even when transparency metadata is provided by ads.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.adstransparencyenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.adstransparencyenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.aigenthemesenabled","displayName":"Enables DALL-E themes generation","description":"This policy lets you generate browser themes using DALL-E and apply them to Microsoft Edge.\n\nIf you enable or don't configure this policy, the AI generated themes are enabled.\n\nIf you disable this policy, the AI generated themes are disabled for your organization.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.aigenthemesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.aigenthemesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbackforwardcacheforcachecontrolnostorepageenabled","displayName":"Allow pages with Cache-Control: no-store header to enter back/forward cache","description":"This policy controls whether a page with Cache-Control: no-store header can be stored in back/forward cache. The website setting in this header may not expect the page to be restored from back/forward cache since some sensitive information could still be displayed after the restoration even if it's no longer accessible.\n\nIf you enable or don't configure this policy, the page with Cache-Control: no-store header is restored from back/forward cache unless the cache eviction is triggered (for example, when there's HTTP-only cookie change to the site).\n\nIf you disable this policy, the page with Cache-Control: no-store header isn't stored in back/forward cache.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbackforwardcacheforcachecontrolnostorepageenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbackforwardcacheforcachecontrolnostorepageenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge.","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\n\nBrowsing with Copilot is available only on domains specified in the \"BrowsingWithCopilotAllowList\" policy and is blocked on domains specified in the \"BrowsingWithCopilotBlockList\" policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\n\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\n\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?linkid=2346300.\n\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\n\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\n\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_recommended","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge. (users can override)","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\n\nBrowsing with Copilot is available only on domains specified in the \"BrowsingWithCopilotAllowList\" policy and is blocked on domains specified in the \"BrowsingWithCopilotBlockList\" policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\n\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\n\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?linkid=2346300.\n\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\n\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\n\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowdeletingbrowserhistory","displayName":"Enable deleting browser and download history","description":"Enables deleting browser history and download history and prevents users from changing this setting.\n\nEven if this policy is disabled, the browsing and download history aren't guaranteed to be retained: users can edit or delete the history database files directly, and the browser itself can remove (based on expiration period) or archive any or all history items at any time.\n\nIf you enable this policy or don't configure it, users can delete the browsing and download history.\n\nIf you disable this policy, users can't delete browsing and download history. Disabling this policy disables history sync and open tab sync.\n\nIf you enable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you enable both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how this policy is configured.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowdeletingbrowserhistory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowdeletingbrowserhistory_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace","description":"Setting the policy on Microsoft Edge turns on the restricted sign-in feature in Google Workspace and prevents users from changing this setting. Users can only access Google tools using accounts from the specified domains. To allow gmail or googlemail accounts, add consumer_accounts to the list of domains. This policy is based on the Chrome policy of the same name.\n\nIf you don't provide a domain name or leave this policy unset, users can access Google Workspace with any account.\n\nUsers can't change or override this setting.\n\nNote: This policy causes the X-GoogApps-Allowed-Domains header to be appended to all HTTP and HTTPS requests to all google.com domains, as described in https://go.microsoft.com/fwlink/?linkid=2197973.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowgamesmenu","displayName":"Allow users to access the games menu (Deprecated)","description":"This policy is deprecated because it can be managed using the \"HubsSidebarEnabled\" policy.\n\nIf you enable or don't configure this policy, users can access the games menu.\n\nIf you disable this policy, users won't be able to access the games menu.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowgamesmenu_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowgamesmenu_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowpopupsduringpageunload","displayName":"Allows a page to show popups during its unloading (Obsolete)","description":"This policy allows an admin to specify that a page can show popups during its unloading.\n\nWhen the policy is set to enabled, pages are allowed to show popups while they're being unloaded.\n\nWhen the policy is set to disabled or unset, pages aren't allowed to show popups while they're being unloaded. This restriction is as per the spec: (https://html.spec.whatwg.org/#apis-for-creating-and-navigating-browsing-contexts-by-name).\n\nThis policy was removed in Microsoft Edge 88 and is ignored if set.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowpopupsduringpageunload_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowpopupsduringpageunload_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsurfgame","displayName":"Allow surf game","description":"If you disable this policy, users won't be able to play the surf game when the device is offline or if the user navigates to edge://surf.\n\nIf you enable or don't configure this policy, users can play the surf game.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsurfgame_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsurfgame_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsyncxhrinpagedismissal","displayName":"Allow pages to send synchronous XHR requests during page dismissal (Obsolete)","description":"This policy is obsolete because it was only intended to be a short-term mechanism to give enterprises more time to update their web content if and when it was found to be incompatible with the change to disallow synchronous XHR requests during page dismissal. It doesn't work in Microsoft Edge after version 99.\n\nThis policy lets you specify that a page can send synchronous XHR requests during page dismissal.\n\nIf you enable this policy, pages can send synchronous XHR requests during page dismissal.\n\nIf you disable this policy or don't configure this policy, pages aren't allowed to send synchronous XHR requests during page dismissal.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsyncxhrinpagedismissal_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsyncxhrinpagedismissal_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsystemnotifications","displayName":"Allows system notifications","description":"Lets you use system notifications instead of Microsoft Edge's embedded Message Center on Windows and Linux.\n\nIf set to True or not set, Microsoft Edge is allowed to use system notifications.\n\nIf set to False, Microsoft Edge won't use system notifications. Microsoft Edge's embedded Message Center is used as a fallback.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsystemnotifications_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsystemnotifications_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowtrackingforurls","displayName":"Configure tracking prevention exceptions for specific sites","description":"Configure the list of URL patterns that are excluded from tracking prevention.\n\nIf you configure this policy, the list of configured URL patterns is excluded from tracking prevention.\n\nIf you don't configure this policy, the global default value from the \"Block tracking of users' web-browsing activity\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowwebauthnwithbrokentlscerts","displayName":"Allow Web Authentication requests on sites with broken TLS certificates.","description":"If you enable this policy, Microsoft Edge allows Web Authentication requests on websites that have TLS certificates with errors (that is, websites considered not secure).\n\nIf you disable or don't configure this policy, the default behavior of blocking such requests apply.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowwebauthnwithbrokentlscerts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowwebauthnwithbrokentlscerts_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alternateerrorpagesenabled","displayName":"Suggest similar pages when a webpage can't be found","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\n\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\n\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\n\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\nSpecifically, there's a **Suggest similar pages when a webpage can't be found** toggle, which the user can switch on or off. If you enable this policy (AlternateErrorPagesEnabled), the **Suggest similar pages when a webpage can't be found** setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the **Suggest similar pages when a webpage can't be found** setting is turned off, and the user can't change the setting by using the toggle.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.alternateerrorpagesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alternateerrorpagesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alternateerrorpagesenabled_recommended","displayName":"Suggest similar pages when a webpage can't be found (users can override)","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\n\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\n\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\n\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\nSpecifically, there's a **Suggest similar pages when a webpage can't be found** toggle, which the user can switch on or off. If you enable this policy (AlternateErrorPagesEnabled), the **Suggest similar pages when a webpage can't be found** setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the **Suggest similar pages when a webpage can't be found** setting is turned off, and the user can't change the setting by using the toggle.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.alternateerrorpagesenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alternateerrorpagesenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alwaysopenpdfexternally","displayName":"Always open PDF files externally","description":"Disables the internal PDF viewer in Microsoft Edge.\n\nIf you enable this policy Microsoft Edge treats PDF files as downloads and lets users open them with the default application.\n\nIf Microsoft Edge is the default PDF reader, PDF files aren't downloaded and continue to open in Microsoft Edge.\n\nIf you don't configure this policy or disable it, Microsoft Edge opens PDF files (unless the user disables it).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.alwaysopenpdfexternally_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.alwaysopenpdfexternally_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.askbeforecloseenabled","displayName":"Get user confirmation before closing a browser window with multiple tabs","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\n\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\n\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.askbeforecloseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.askbeforecloseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.askbeforecloseenabled_recommended","displayName":"Get user confirmation before closing a browser window with multiple tabs (users can override)","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\n\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\n\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.askbeforecloseenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.askbeforecloseenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.audiocaptureallowedurls","displayName":"Sites that can access audio capture devices without requesting permission","description":"Specify websites, based on URL patterns, that can use audio capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to audio capture devices. Note, however, that the pattern \"*\", which matches any URL, isn't supported by this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled","displayName":"Configure auto discard sleeping tabs","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab needs to be reloaded.\n\nIf the \"SleepingTabsEnabled\" policy is enabled, then this feature is enabled by default.\n\nIf the \"SleepingTabsEnabled\" is disabled, then this feature is disabled by default and can't be enabled.\n\nIf enabled, idle background tabs will be discarded after 1.5 days.\n\nIf disabled, idle background tab won't be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_recommended","displayName":"Configure auto discard sleeping tabs (users can override)","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab needs to be reloaded.\n\nIf the \"SleepingTabsEnabled\" policy is enabled, then this feature is enabled by default.\n\nIf the \"SleepingTabsEnabled\" is disabled, then this feature is disabled by default and can't be enabled.\n\nIf enabled, idle background tabs will be discarded after 1.5 days.\n\nIf disabled, idle background tab won't be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled","displayName":"Enable AutoFill for addresses","description":"Enables the AutoFill feature and allows users to autocomplete address information in web forms through previously stored information.\n\nIf you have enabled or not configured this policy, users manage AutoFill for addresses in Microsoft Edge settings. AutoFill allows users to complete address fields in web forms using previously saved information.\n\nIf you have disabled this policy, Microsoft Edge doesn't suggest, fill in, or save address information. AutoFill is also disabled for all web forms except payment and password fields, and previously saved addresses aren't available.\n\nIf you disable this policy, then \"EdgeAutofillMlEnabled\" is turned off.\n\nIf you disable this policy, all activities for all web forms are stopped, except payment and password forms. No further entries are saved, and Microsoft Edge doesn't suggest or AutoFill any previous entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_recommended","displayName":"Enable AutoFill for addresses (users can override)","description":"Enables the AutoFill feature and allows users to autocomplete address information in web forms through previously stored information.\n\nIf you have enabled or not configured this policy, users manage AutoFill for addresses in Microsoft Edge settings. AutoFill allows users to complete address fields in web forms using previously saved information.\n\nIf you have disabled this policy, Microsoft Edge doesn't suggest, fill in, or save address information. AutoFill is also disabled for all web forms except payment and password fields, and previously saved addresses aren't available.\n\nIf you disable this policy, then \"EdgeAutofillMlEnabled\" is turned off.\n\nIf you disable this policy, all activities for all web forms are stopped, except payment and password forms. No further entries are saved, and Microsoft Edge doesn't suggest or AutoFill any previous entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillcreditcardenabled","displayName":"Enable AutoFill for payment instruments","description":"Enables Microsoft Edge's AutoFill feature and lets users auto complete payment instruments like credit or debit cards in web forms using previously stored information. Includes suggesting new payment instruments like Buy Now Pay Later (BNPL) in web forms and Express Checkout.\n\nIf you enable this policy or don't configure it, users can control AutoFill for payment instruments.\n\nIf you disable this policy, AutoFill never suggests, fills, or recommends new payment Instruments. Additionally, it won't save any payment instrument information that users submit while browsing the web.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillcreditcardenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillcreditcardenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillcreditcardenabled_recommended","displayName":"Enable AutoFill for payment instruments (users can override)","description":"Enables Microsoft Edge's AutoFill feature and lets users auto complete payment instruments like credit or debit cards in web forms using previously stored information. Includes suggesting new payment instruments like Buy Now Pay Later (BNPL) in web forms and Express Checkout.\n\nIf you enable this policy or don't configure it, users can control AutoFill for payment instruments.\n\nIf you disable this policy, AutoFill never suggests, fills, or recommends new payment Instruments. Additionally, it won't save any payment instrument information that users submit while browsing the web.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillcreditcardenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillcreditcardenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled","displayName":"Save and fill memberships","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\n\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_recommended","displayName":"Save and fill memberships (users can override)","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\n\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autolaunchprotocolscomponentenabled","displayName":"AutoLaunch Protocols Component Enabled","description":"Specifies whether the AutoLaunch Protocols component should be enabled. This component allows Microsoft to provide a list similar to that of the \"AutoLaunchProtocolsFromOrigins\" policy, allowing certain external protocols to launch without prompt or blocking certain protocols (on specified origins). By default, this component is enabled.\n\nIf you enable or don't configure this policy, the AutoLaunch Protocols component is enabled.\n\nIf you disable this policy, the AutoLaunch Protocols component is disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autolaunchprotocolscomponentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autolaunchprotocolscomponentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user","description":"Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator shouldn't be included when listing the protocol and the protocol should be all lower case. For example, list \"skype\" instead of \"skype:\", \"skype://\" or \"Skype\".\n\nIf you configure this policy, a protocol is only permitted to launch an external application without prompting by policy if:\n\n- the protocol is listed\n\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\n\nIf either condition is false, the external protocol launch prompt isn't omitted, by policy.\n\nIf you don't configure this policy, no protocols can launch without a prompt. Users can opt out of prompts on a per-protocol/per-site basis unless the \"ExternalProtocolDialogShowAlwaysOpenCheckbox\" policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users.\n\nThe origin-matching patterns use a similar format to those for the \"URLBlocklist\" policy, which are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\n\nHowever, origin-matching patterns for this policy can't contain \"/path\" or \"@query\" elements. Any pattern that contains a \"/path\" or \"@query\" element is ignored.\n\nThis policy doesn't work as expected with file://* wildcards.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automaticdownloadsallowedforurls","displayName":"Allow multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to perform multiple successive automatic downloads.\nIf you don't configure this policy, \"DefaultAutomaticDownloadsSetting\" applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automaticdownloadsblockedforurls","displayName":"Block multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, where multiple successive automatic downloads aren't allowed.\nIf you don't configure this policy, \"DefaultAutomaticDownloadsSetting\" applies for all sites, if that setting is active. If it isn't set, then the user's personal setting applies.\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automaticfullscreenallowedforurls","displayName":"Allow automatic full screen on specified sites","description":"For security reasons, the\nrequestFullscreen() web API\nrequires a prior user gesture (\"transient activation\") to be called or it\nfails. Users' personal settings can allow certain origins to call this API\nwithout a prior user gesture.\n\nThis policy supersedes users' personal settings and allows matching origins to\ncall the API without a prior user gesture.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\nWildcards (*) are allowed.\n\nOrigins matching both blocked and allowed policy patterns are blocked.\nOrigins not specified by policy or user settings require a prior user\ngesture to call this API.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automaticfullscreenblockedforurls","displayName":"Block automatic full screen on specified sites","description":"For security reasons, the\nrequestFullscreen() web API\nrequires a prior user gesture (\"transient activation\") to be called or it\nfails. Users' personal settings can allow certain origins to call this API\nwithout a prior user gesture.\n\nThis policy supersedes users' personal settings and blocks matching origins\nfrom calling the API without a prior user gesture.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\nWildcards (*) are allowed.\n\nOrigins matching both blocked and allowed policy patterns are blocked.\nOrigins not specified by policy or user settings require a prior user\ngesture to call this API.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault","displayName":"Configure Automatic HTTPS (Obsolete)","description":"This policy lets you manage settings for \"AutomaticHttpsDefault\", which switches connections from HTTP to HTTPS.\n\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\n\nMicrosoft Edge attempts to upgrade some navigations from HTTP to HTTPS, when possible. This policy can be used to disable this behavior. If set to \"AlwaysUpgrade\" or left unset, this feature is enabled by default.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nThis policy is obsolete, and is replaced with the policy \"HttpsUpgradesEnabled\".\n\nPolicy options mapping:\n\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\n\n* UpgradeCapableDomains (1) = (Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\n\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_disableautomatichttps","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_upgradecapabledomains","displayName":"(Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_alwaysupgrade","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended","displayName":"Configure Automatic HTTPS (Obsolete) (users can override)","description":"This policy lets you manage settings for \"AutomaticHttpsDefault\", which switches connections from HTTP to HTTPS.\n\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\n\nMicrosoft Edge attempts to upgrade some navigations from HTTP to HTTPS, when possible. This policy can be used to disable this behavior. If set to \"AlwaysUpgrade\" or left unset, this feature is enabled by default.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nThis policy is obsolete, and is replaced with the policy \"HttpsUpgradesEnabled\".\n\nPolicy options mapping:\n\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\n\n* UpgradeCapableDomains (1) = (Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\n\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended_disableautomatichttps","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended_upgradecapabledomains","displayName":"(Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended_alwaysupgrade","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoopenallowedforurls","displayName":"URLs where AutoOpenFileTypes can apply","description":"A list of URLs to which \"AutoOpenFileTypes\" applies to. This policy has no impact on automatically open values set by users via the download shelf ... > \"Always open files of this type\" menu entry.\n\nIf you set URLs in this policy, files will only automatically open by policy if the URL is part of this set and the file type is listed in \"AutoOpenFileTypes\". If either condition is false, the download won't automatically open by policy.\n\nIf you don't set this policy, all downloads where the file type is in \"AutoOpenFileTypes\" automatically opens.\n\nA URL pattern has to be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nThis policy doesn't work as expected with file://* wildcards.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoopenfiletypes","displayName":"List of file types that should be automatically opened on download","description":"This policy sets a list of file types that should be automatically opened on download. Note: The leading separator shouldn't be included when listing the file type, so list \"txt\" instead of \".txt\".\n\nBy default, these file types are automatically opened on all URLs. You can use the \"AutoOpenAllowedForURLs\" policy to restrict the URLs on which these file types are automatically opened.\n\nFiles with types that should be automatically opened are still subject to the enabled Microsoft Defender SmartScreen checks and won't be opened if they fail those checks.\n\nFile types that a user has already specified to automatically be opened continue to do so when downloaded. The user continues to be able to specify other file types to be automatically opened.\n\nIf you don't set this policy, only file types that a user has already specified to automatically be opened will do so when downloaded.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory or instances that enrolled for device management.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoplayallowed","displayName":"Allow media autoplay for websites","description":"This policy controls media autoplay behavior for websites.\n\nIf you don't configure this policy, Microsoft Edge uses the current media autoplay setting, and users can change their autoplay settings.\n\nIf you enable this policy, media autoplay is set to \"Allow\". All websites can autoplay media, and users can't override this setting.\n\nIf you disable this policy, media autoplay is set to \"Limit\" in Microsoft Edge version 148 and later. Autoplay is limited to webpages with high media engagement or active WebRTC streams, and users can't override this setting.\n\nIn versions 92 through 145, disabling this policy also set autoplay to \"Limit\". In versions 146 and 147, disabling this policy set autoplay to \"Block\".\n\nTabs must be closed and reopened for this policy to take effect.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoplayallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoplayallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoplayallowlist","displayName":"Allow media autoplay on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to autoplay media.\n\nIf you don't configure this policy, the global default value from the \"AutoplayAllowed\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nNote: * is not an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoselectcertificateforurls","displayName":"Automatically select client certificates for these sites","description":"Setting the policy lets you make a list of URL patterns that specify sites for which Microsoft Edge can automatically select a client certificate. The value is an array of stringified JSON dictionaries, each with the form { \"pattern\": \"$URL_PATTERN\", \"filter\" : $FILTER }, where $URL_PATTERN is a content setting pattern. $FILTER restricts the client certificates the browser automatically selects from. Independent of the filter, only certificates that match the server's certificate request are selected.\n\nExamples for the usage of the $FILTER section:\n\n* When $FILTER is set to { \"ISSUER\": { \"CN\": \"$ISSUER_CN\" } }, only client certificates issued by a certificate with the CommonName $ISSUER_CN are selected.\n\n* When $FILTER contains both the \"ISSUER\" and the \"SUBJECT\" sections, only client certificates that satisfy both conditions are selected.\n\n* When $FILTER contains a \"SUBJECT\" section with the \"O\" value, a certificate needs at least one organization matching the specified value to be selected.\n\n* When $FILTER contains a \"SUBJECT\" section with a \"OU\" value, a certificate needs at least one organizational unit matching the specified value to be selected.\n\n* When $FILTER is set to {}, the selection of client certificates isn't additionally restricted. Filters provided by the web server still apply.\n\nIf you leave the policy unset, there's no autoselection for any site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.backgroundtemplatelistupdatesenabled","displayName":"Enables background updates to the list of available templates for Collections and other features that use templates (Deprecated)","description":"This policy is deprecated because we are moving to a new policy. It won't work in Microsoft Edge as soon as version 104. The new policy to use is \"EdgeAssetDeliveryServiceEnabled\".\n\nLets you enable or disable background updates to the list of available templates for Collections and other features that use templates. Templates are used to extract rich metadata from a webpage when the page is saved to a collection.\n\nIf you enable this setting or the setting is unconfigured, the list of available templates are downloaded in the background from a Microsoft service every 24 hours.\n\nIf you disable this setting the list of available templates are downloaded on demand. This type of download might result in small performance penalties for Collections and other features.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.backgroundtemplatelistupdatesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.backgroundtemplatelistupdatesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.beforeunloadeventcancelbypreventdefaultenabled","displayName":"Control the behavior for the cancel dialog produced by the beforeunload event (Obsolete)","description":"This policy provides a temporary opt-out for two related fixes to the behavior of the confirmation dialog that’s shown by the beforeunload event.\n\nIf you've enabled this policy, the new (correct) behavior is used.\nIf you've disabled this policy, the old (legacy) behavior is used.\nIf you haven't configured this policy, the default behavior is used.\nNote: This policy is a temporary workaround and is going to be removed in a future release.\n\nNew and correct behavior: In `beforeunload`, calling `event.preventDefault()` triggers the confirmation dialog. Setting `event.returnValue` to the empty string doesn’t trigger the confirmation dialog.\n\nOld and legacy behavior: In `beforeunload`, calling `event.preventDefault()` doesn’t trigger the confirmation dialog. Setting `event.returnValue` to the empty string triggers the confirmation dialog.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.beforeunloadeventcancelbypreventdefaultenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.beforeunloadeventcancelbypreventdefaultenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockexternalextensions","displayName":"Blocks external extensions from being installed","description":"Control the installation of external extensions.\n\nIf you enable this setting, external extensions are blocked from being installed.\n\nIf you disable this setting or leave it unset, external extensions are allowed to be installed.\n\nExternal extensions and their installation are documented at [Alternate extension distribution methods](/microsoft-edge/extensions-chromium/developer-guide/alternate-distribution-options).","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockexternalextensions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockexternalextensions_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies","displayName":"Block third party cookies","description":"This policy controls whether third-party cookies are blocked in regular browsing sessions.\n\nIf you enable this policy, web page elements that are not from the domain shown in the address bar can't set cookies.\n\nIf you disable this policy, third-party cookies are allowed, including from domains other than the one shown in the address bar.\n\nIf you don't configure this policy, third-party cookies are allowed by default, but users can change this setting.\n\nNote: This policy doesn't apply in InPrivate mode. In InPrivate, third-party cookies are blocked by default and can only be allowed at the site level using the CookiesAllowedForUrls policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_recommended","displayName":"Block third party cookies (users can override)","description":"This policy controls whether third-party cookies are blocked in regular browsing sessions.\n\nIf you enable this policy, web page elements that are not from the domain shown in the address bar can't set cookies.\n\nIf you disable this policy, third-party cookies are allowed, including from domains other than the one shown in the address bar.\n\nIf you don't configure this policy, third-party cookies are allowed by default, but users can change this setting.\n\nNote: This policy doesn't apply in InPrivate mode. In InPrivate, third-party cookies are blocked by default and can only be allowed at the site level using the CookiesAllowedForUrls policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blocktruncatedcookies","displayName":"Block truncated cookies (Obsolete)","description":"This policy provides a temporary opt-out for changes to how Microsoft Edge handles cookies set via JavaScript that contain certain control characters (NULL, carriage return, and line feed).\nPreviously, the presence of any of these characters in a cookie string would cause it to be truncated but still set.\nNow, the presence of these characters will cause the whole cookie string to be ignored.\n\nIf you enable or don't configure this policy, the new behavior is enabled.\n\nIf you disable this policy, the old behavior is enabled.\n\nThis policy is obsolete because this policy was originally implemented as a safety measure if there was a breakage, but none have been reported.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.blocktruncatedcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blocktruncatedcookies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsernetworktimequeriesenabled","displayName":"Allow queries to a Browser Network Time service","description":"Prevents Microsoft Edge from occasionally sending queries to a browser network time service to retrieve an accurate timestamp.\n\nIf you disable this policy, Microsoft Edge stops sending queries to a browser network time service.\n\nIf you enable this policy or don't configure it, Microsoft Edge occasionally sends queries to a browser network time service.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsernetworktimequeriesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsernetworktimequeriesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsingdatalifetime","displayName":"Browsing Data Lifetime Settings","description":"This policy controls how long specific types of browsing data are retained.\nIf Sync is enabled, this policy has no effect.\n\nYou can specify the following data types:\n'browsing_history'\n'download_history'\n'cookies_and_other_site_data'\n'cached_images_and_files'\n'password_signin'\n'autofill'\n'site_settings'\n'hosted_app_data'\n\nMicrosoft Edge periodically deletes data of the selected types that's older than the value set by 'time_to_live_in_hours'.\n\nExpired data is removed 15 seconds after browser startup and every hour while the browser is running.\n\nNote: Deleting cookies using this policy doesn't sign the user out of their profile, the user stays signed in.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsingwithcopilotallowlist","displayName":"Browsing with Copilot Allowed URLs","description":"Allows you to define a list of URLs where browsing with Copilot is available. Users cannot modify this list.\n\nIf you enable this policy, browsing with Copilot is available only on the sites specified in the list. To allow a broader set of sites while blocking specific exceptions, configure this policy together with the \"BrowsingWithCopilotBlockList\" policy. For example, you can include '*' to allow all sites, and then use the block list to restrict access to specific URLs.\n\nYou can define exceptions based on schemes, subdomains, ports, or origins. When multiple filters apply, the most specific match determines whether a URL is allowed or blocked. The block list takes precedence over the allow list.\n\nIf you disable or do not configure this policy, browsing with Copilot is unavailable on all sites, even if the \"AllowBrowsingWithCopilot\" policy is enabled.\n\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. This policy applies only to the site origin; any path specified in the URL pattern is ignored. For guidance on formatting URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsingwithcopilotblocklist","displayName":"Browsing with Copilot Blocked URLs","description":"Controls the list of URLs where browsing with Copilot is blocked. Users can't modify this list.\n\nUse this policy to define exceptions to broader allowlists. For example, you can set \"BrowsingWithCopilotAllowList\" to '*' to allow all sites, and then use this policy to block access to specific URLs.\n\nThis policy supports blocking by scheme, subdomain, or port. When multiple URL patterns apply, the most specific match determines whether access is allowed or blocked. Blocklist entries take precedence over allowlist entries.\n\nIf you don't configure this policy, no exceptions are applied to \"BrowsingWithCopilotAllowList\".\n\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. URL matching is based on the site origin only; any path specified in the pattern is ignored.\n\nFor information about URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.builtinaiapisenabled","displayName":"Allow pages to use the built-in AI APIs.","description":"Use this policy to control whether websites can access the built-in AI APIs, including the LanguageModel API, Summarization API, Writer API, and Rewriter API.\n\nEnable this policy to allow pages to use the APIs. If you don’t configure this policy, the APIs are still allowed.\n\nDisable this policy to block access to the APIs. The APIs will return an error when used.\n\nFor more information, see https://github.com/webmachinelearning/writing-assistance-apis/blob/main/README.md.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.builtinaiapisenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.builtinaiapisenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates.","description":"This policy determines the level of access users have when managing CA certificates in Microsoft Edge.\n\nSetting the policy to UserOnly (1) allows users to manage only user-imported certificates. Trust settings for built-in certificates cannot be changed.\n\nSetting the policy to None (2) lets users view certificates but not manage them.\n\nNote: The certificate management experience is available starting in Microsoft Edge version 136.\n\nPolicy options mapping:\n\n* All (0) = Allow users to manage all certificates\n\n* UserOnly (1) = Allow users to manage user certificates\n\n* None (2) = Disallow users from managing certificates\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.cacertificatemanagementallowed_all","displayName":"Allow users to manage all certificates","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cacertificatemanagementallowed_useronly","displayName":"Allow users to manage user certificates","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cacertificatemanagementallowed_none","displayName":"Disallow users from managing certificates","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cacertificates","displayName":"TLS server certificates that should be trusted by Microsoft Edge","description":"This policy enables a list of Transport Layer Security (TLS) certificates that Microsoft Edge trusts for server authentication.\nCertificates should be base64 encoded.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Microsoft Edge for server authentication with constraints","description":"This policy enables a list of TLS certificates that should be trusted by Microsoft Edge for server authentication, with constraints added outside the certificate. If no constraint of a certain type is present, then any name of that type is allowed.\nCertificates should be base64-encoded. At least one constraint must be specified for each certificate.\n\nThe permitted_dns_names field is a list of DNS names that are allowed for the certificate. If the DNS name in the certificate request doesn't match one of the specified DNS names, the certificate isn't trusted.\n\nThe permitted_cidrs field is a list of CIDR (Classless Inter-Domain Routing) ranges that will be allowed for the certificate. If the IP address in the certificate request doesn't fall within one of the permitted CIDR ranges, the certificate isn't trusted.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cadistrustedcertificates","displayName":"TLS certificates that should be distrusted by Microsoft Edge for server authentication","description":"This policy enables defining a list of certificate public keys that should be distrusted by Microsoft Edge for TLS server\nauthentication.\n\nThe policy value is a list of base64-encoded X.509 certificates. Any\ncertificate with a matching SPKI (SubjectPublicKeyInfo) is distrusted.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication","description":"This policy defines certificates that Microsoft Edge doesn't explicitly trust or distrust but may be used as hints during certificate path-building.\n\nThe specified certificates are considered as intermediates during path validation; the server's certificate still chain to a trusted root to be considered valid.\n\nCertificates must be base64-encoded.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.caplatformintegrationenabled","displayName":"Use user-added TLS certificates from platform trust stores for server authentication","description":"If enabled (or unset), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.\n\nIf disabled, user-added TLS certificates from platform trust stores won't be used in path-building for TLS server authentication.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.caplatformintegrationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.caplatformintegrationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.certificatetransparencyenforcementdisabledforcas","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes","description":"Disables enforcement of Certificate Transparency requirements for a list of subjectPublicKeyInfo hashes.\n\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This allows certificates that would otherwise be untrusted because they weren't properly publicly disclosed to still be used for Enterprise hosts.\n\nTo disable Certificate Transparency enforcement when this policy is set, one of the following sets of conditions must be met:\n1. The hash is of the server certificate's subjectPublicKeyInfo.\n2. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, that CA certificate is constrained via the X.509v3 nameConstraints extension, one or more directoryName nameConstraints are present in the permittedSubtrees, and the directoryName contains an organizationName attribute.\n3. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, the CA certificate has one or more organizationName attributes in the certificate Subject, and the server's certificate contains the same number of organizationName attributes, in the same order, and with byte-for-byte identical values.\n\nA subjectPublicKeyInfo hash is specified by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\n\nIf you disable this policy or don't configure it, any certificate required to be disclosed via Certificate Transparency is treated as untrusted if not disclosed according to the Certificate Transparency policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.certificatetransparencyenforcementdisabledforlegacycas","displayName":"Disable Certificate Transparency enforcement for a list of legacy certificate authorities (Obsolete)","description":"Disables enforcing Certificate Transparency requirements for a list of legacy certificate authorities (Cas).\n\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This disablement of requirements allows otherwise-untrusted certificates (on account of not being publicly disclosed) to continue to be used for enterprise hosts.\n\nFor Certificate Transparency enforcement to be disabled, you must set the hash to a subjectPublicKeyInfo appearing in an authority-issued certificate that's recognized as a legacy certificate authority (CA). A legacy CA is a CA publicly trusted, by default, by one or more operating systems supported by Microsoft Edge.\n\nYou specify a subjectPublicKeyInfo hash by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\n\nIf you don't configure this policy, any certificate that's required to be disclosed via Certificate Transparency is treated as untrusted if it isn't disclosed according to the Certificate Transparency policy.\n\nThis policy is obsolete because the feature to disable Certificate Transparency enforcement for legacy certificates has been removed.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit","displayName":"Clear browsing data when Microsoft Edge closes","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\n\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured \"DefaultCookiesSetting\"\n\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\n\nIf you enable this policy, don't configure the \"AllowDeletingBrowserHistory\" or the \"ClearCachedImagesAndFilesOnExit\" policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured \"AllowDeletingBrowserHistory\" or \"ClearCachedImagesAndFilesOnExit\".\n\nTo exclude cookies from being deleted on exit, configure the \"SaveCookiesOnExit\" policy.\nTo exclude passwords from being deleted on exit, configure the \"PasswordDeleteOnBrowserCloseEnabled\" policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_recommended","displayName":"Clear browsing data when Microsoft Edge closes (users can override)","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\n\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured \"DefaultCookiesSetting\"\n\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\n\nIf you enable this policy, don't configure the \"AllowDeletingBrowserHistory\" or the \"ClearCachedImagesAndFilesOnExit\" policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured \"AllowDeletingBrowserHistory\" or \"ClearCachedImagesAndFilesOnExit\".\n\nTo exclude cookies from being deleted on exit, configure the \"SaveCookiesOnExit\" policy.\nTo exclude passwords from being deleted on exit, configure the \"PasswordDeleteOnBrowserCloseEnabled\" policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit","displayName":"Clear cached images and files when Microsoft Edge closes","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\n\nIf you enable this policy, cached images and files are deleted each time Microsoft Edge closes.\n\nIf you disable this policy, users can't configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\n\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\n\nIf you disable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you configure both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"ClearCachedImagesAndFilesOnExit\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_recommended","displayName":"Clear cached images and files when Microsoft Edge closes (users can override)","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\n\nIf you enable this policy, cached images and files are deleted each time Microsoft Edge closes.\n\nIf you disable this policy, users can't configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\n\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\n\nIf you disable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you configure both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"ClearCachedImagesAndFilesOnExit\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clipboardallowedforurls","displayName":"Allow clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\n\nSetting the policy lets you create a list of URL patterns that specify which sites can use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users can still paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\n\nLeaving the policy unset means \"DefaultClipboardSetting\" applies for all sites if it's set. If it isn't set, the user's personal setting applies.\n\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clipboardblockedforurls","displayName":"Block clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\n\nSetting the policy lets you create a list of URL patterns that specify sites that can't use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users can still paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\n\nLeaving the policy unset means \"DefaultClipboardSetting\" applies for all sites if it's set. If it isn't set, the user's personal setting applies.\n\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist","displayName":"Block access to a specified list of services and export targets in Collections","description":"List specific services and export targets that users can't access in the Collections feature in Microsoft Edge. This includes displaying additional data from Bing and exporting collections to Microsoft products or external partners.\n\nIf you enable this policy, services and export targets that match the given list are blocked.\n\nIf you don't configure this policy, no restrictions on the acceptable services and export targets are enforced.\n\nPolicy options mapping:\n\n* pinterest_suggestions (pinterest_suggestions) = Pinterest suggestions\n\n* collections_share (collections_share) = Sharing of Collections\n\n* local_pdf (local_pdf) = Save local PDFs in Collections to OneDrive\n\n* send_word (send_word) = Send collection to Microsoft Word\n\n* send_excel (send_excel) = Send collection to Microsoft Excel\n\n* send_onenote (send_onenote) = Send collection to Microsoft OneNote\n\n* send_pinterest (send_pinterest) = Send collection to Pinterest\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_pinterest_suggestions","displayName":"Pinterest suggestions","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_collections_share","displayName":"Sharing of Collections","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_local_pdf","displayName":"Save local PDFs in Collections to OneDrive","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_send_word","displayName":"Send collection to Microsoft Word","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_send_excel","displayName":"Send collection to Microsoft Excel","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_send_onenote","displayName":"Send collection to Microsoft OneNote","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.collectionsservicesandexportsblocklist_send_pinterest","displayName":"Send collection to Pinterest","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.composeinlineenabled","displayName":"Control access to Microsoft 365 Copilot writing assistance in Microsoft Edge for Business","description":"This policy controls whether users can use writing support features in Microsoft Edge for Business, such as Rewrite, which utilizes Microsoft 365 Copilot Chat. With Rewrite, users can receive help with drafting content, rewriting text, and adjusting style directly in their browser tab. In Microsoft Edge, users can trigger it when highlighting editable content in their main browser through the right-click context menu.\n\nThis policy applies only to Microsoft Entra accounts and doesn't apply to Microsoft accounts.\n\nIf you enable this policy, users can use Rewrite in Microsoft Edge when logged in with an Entra account.\n\nIf you disable this policy, users within your tenant can't use Rewrite.\n\nIf you don't configure this policy, the default behavior is as follows:\n\n- Rewrite is available to users\n\n- Users can enable or disable Microsoft 365 Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings.\n\nNote: Rewrite isn't available on pages protected by data loss prevention (DLP) policies to help maintain compliance.\n\nLearn more about Microsoft 365 Copilot Chat data, privacy, and security here: https://go.microsoft.com/fwlink/?linkid=2321816","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.composeinlineenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.composeinlineenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.compressiondictionarytransportenabled","displayName":"Enable compression dictionary transport support","description":"This feature enables the use of dictionary-specific content encodings in the Accept-Encoding request header (\"sbr\" and \"zst-d\") when dictionaries are available for use.\n\nIf you enable this policy or don't configure it, Microsoft Edge accepts web contents using the compression dictionary transport feature.\n\nIf you disable this policy, Microsoft Edge turns off the compression dictionary transport feature.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.compressiondictionarytransportenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.compressiondictionarytransportenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configuredonottrack","displayName":"Configure Do Not Track","description":"Specify whether to send Do Not Track requests to websites that ask for tracking info. Do Not Track requests let the websites you visit know that you don't want your browsing activity to be tracked. By default, Microsoft Edge doesn't send Do Not Track requests, but users can turn on this feature to send them.\n\nIf you enable this policy, Do Not Track requests are always sent to websites asking for tracking info.\n\nIf you disable this policy, requests are never sent.\n\nIf you don't configure this policy, users can choose whether to send these requests.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configuredonottrack_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configuredonottrack_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users","description":"If FriendlyURLs are enabled, Microsoft Edge computes more representations of the URL and places them on the clipboard.\n\nThis policy configures what format is pasted when the user pastes in external applications or inside Microsoft Edge without the 'Paste as' context menu item.\n\nIf you configure this policy, it makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu won't be available.\n\n* Not configured = The users are able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\n\n* 1 = No additional formats are stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge, and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature is disabled.\n\n* 3 = The user gets a friendly URL whenever they paste into surfaces that accept rich text. The plain URL is still available for nonrich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\n\n* 4 = (Not currently used)\n\nThe richer formats may not be supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy.\n\nThe recommended policy is available in Microsoft Edge 105 or later.\n\nPolicy options mapping:\n\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\n\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.\n\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_plaintext","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_titledhyperlink","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_webpreview","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (users can override)","description":"If FriendlyURLs are enabled, Microsoft Edge computes more representations of the URL and places them on the clipboard.\n\nThis policy configures what format is pasted when the user pastes in external applications or inside Microsoft Edge without the 'Paste as' context menu item.\n\nIf you configure this policy, it makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu won't be available.\n\n* Not configured = The users are able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\n\n* 1 = No additional formats are stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge, and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature is disabled.\n\n* 3 = The user gets a friendly URL whenever they paste into surfaces that accept rich text. The plain URL is still available for nonrich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\n\n* 4 = (Not currently used)\n\nThe richer formats may not be supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy.\n\nThe recommended policy is available in Microsoft Edge 105 or later.\n\nPolicy options mapping:\n\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\n\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.\n\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended_plaintext","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended_titledhyperlink","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended_webpreview","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurekeyboardshortcuts","displayName":"Configure the list of commands for which to disable keyboard shortcuts","description":"Configure the list of Microsoft Edge commands for which keyboard shortcuts must be disabled.\n\nSee https://go.microsoft.com/fwlink/?linkid=2186950 for a list of possible commands to disable.\n\nIf you enable this policy, commands in the 'disabled' list are no longer activated by keyboard shortcuts.\n\nIf you disable this policy, all keyboard shortcuts behave as usual.\n\nNote: Disabling a command only removes its shortcut mapping. Commands in the 'disabled' list still function if accessed via browser UI.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility","displayName":"Configure whether the Discover or Work feed tabs are shown on the New Tab Page.","description":"This policy configures whether the Discover or Work feed tabs are shown on the New Tab Page. By default, both Work and Discover tabs are enabled.\n\nIf you set this policy to 'EnableBothWorkDiscover' (0) or do not configure this policy, Microsoft Edge shows both the Work and Discover feed tabs on the new tab page.\n\nIf you set this policy to 'EnableOnlyWork' (1), Microsoft Edge shows only the Work feed tab on the new tab page.\n\nIf you set this policy to 'EnableOnlyDiscover' (2), Microsoft Edge shows only the Discover feed tab on the new tab page.\n\nThis policy works with the SetNTPDefaultFeedTab policy, which controls which feed tab is selected by default when both tabs are available.\n\nPolicy options mapping:\n\n* EnableBothWorkDiscover (0) = Enable both Work and Discover tabs\n\n* EnableOnlyWork (1) = Enable only Work tab\n\n* EnableOnlyDiscover (2) = Enable only Discover tab\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility_enablebothworkdiscover","displayName":"Enable both Work and Discover tabs","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility_enableonlywork","displayName":"Enable only Work tab","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility_enableonlydiscover","displayName":"Enable only Discover tab","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureonlinetexttospeech","displayName":"Configure Online Text To Speech","description":"Set whether the browser can apply Online Text to Speech voice fonts, part of Azure Cognitive Services. These voice fonts are higher quality than the pre-installed system voice fonts.\n\nIf you enable or don't configure this policy, web-based applications that use the SpeechSynthesis API can use Online Text to Speech voice fonts.\n\nIf you disable this policy, the voice fonts aren't available.\n\nRead more about this feature here:\nSpeechSynthesis API: https://go.microsoft.com/fwlink/?linkid=2110038\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2110141","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureonlinetexttospeech_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureonlinetexttospeech_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureshare","displayName":"Configure the Share experience","description":"If you set this policy to 'ShareAllowed' (the default), users can access the Share experience from the Settings and More Menu in Microsoft Edge to share with other apps on the system.\n\nIf you set this policy to 'ShareDisallowed', users can't access the Share experience. If the Share button is on the toolbar, it's hidden as well.\n\nPolicy options mapping:\n\n* ShareAllowed (0) = Allow using the Share experience\n\n* ShareDisallowed (1) = Don't allow using the Share experience\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureshare_shareallowed","displayName":"Allow using the Share experience","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureshare_sharedisallowed","displayName":"Don't allow using the Share experience","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.controldefaultstateofallowextensionfromotherstoressettingenabled","displayName":"Configure default state of Allow extensions from other stores setting","description":"This policy allows you to control the default state of the Allow extensions from other stores setting.\nThis policy can't be used to stop installation of extensions from other stores such as Chrome Web Store.\nTo stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098.\n\nWhen enabled, Allow extensions from other stores will be turned on. So, users won't have to turn on the flag manually\nwhile installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting.\nIf the user has already turned on the setting and then turned it off, this setting may not work.\nIf the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it will have no impact on\nuser settings and the setting will remain as it is.\n\nWhen disabled or not configured, the user can manage the Allow extensions from other store setting.\n","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.controldefaultstateofallowextensionfromotherstoressettingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.controldefaultstateofallowextensionfromotherstoressettingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.controldefaultstateofallowextensionfromotherstoressettingenabled_recommended","displayName":"Configure default state of Allow extensions from other stores setting (users can override)","description":"This policy allows you to control the default state of the Allow extensions from other stores setting.\nThis policy can't be used to stop installation of extensions from other stores such as Chrome Web Store.\nTo stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098.\n\nWhen enabled, Allow extensions from other stores are turned on. So, users don't have to turn on the flag manually\nwhile installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting.\nIf the user turned on the setting and then turned it off, this setting may not work.\nIf the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it has no impact on\nuser settings and the setting remains as it is.\n\nWhen disabled or not configured, the user can manage the Allow extensions from other store setting.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.controldefaultstateofallowextensionfromotherstoressettingenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.controldefaultstateofallowextensionfromotherstoressettingenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cookiesallowedforurls","displayName":"Allow cookies on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to set cookies. URL patterns can be a single URL indicating that the site can use cookies on all top-level sites. Patterns can also be two URLs delimited by a comma. The first specifies the site that should be allowed to use cookies. The second specifies the top-level site that the first value should be applied on. If you use a pair of URLs, the first value in the pair supports *, but the second value doesn't. Using * for the first value indicates that all sites can use cookies when the second URL is the top-level site.\n\nIf you don't configure this policy, the global default value from the \"DefaultCookiesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor more information, see the \"CookiesBlockedForUrls\" and \"CookiesSessionOnlyForUrls\" policies.\n\nNote there can't be conflicting URL patterns set between these three policies:\n\n- \"CookiesBlockedForUrls\"\n\n- CookiesAllowedForUrls\n\n- \"CookiesSessionOnlyForUrls\"\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.\n\nTo allow third-party cookies to be set, specify a pair of URL patterns delimited by a comma. The first value in the pair specifies the third-party site that should be allowed to use cookies. The second value in the pair specifies the top-level site that the first value should be applied on. The first value in the pair supports * but the second value doesn't.\n\nTo exclude cookies from being deleted on exit, configure the \"SaveCookiesOnExit\" policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cookiesblockedforurls","displayName":"Block cookies on specific sites","description":"Define a list of sites, based on URL patterns, that can't set cookies.\n\nIf you don't configure this policy, the global default value from the \"DefaultCookiesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nSee the \"CookiesAllowedForUrls\" and \"CookiesSessionOnlyForUrls\" policies for more information.\n\nNote there can't be conflicting URL patterns set between these three policies:\n\n- CookiesBlockedForUrls\n\n- \"CookiesAllowedForUrls\"\n\n- \"CookiesSessionOnlyForUrls\"\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cookiessessiononlyforurls","displayName":"Limit cookies from specific websites to the current session","description":"Cookies created by websites that match a URL pattern you define are deleted when the session ends (when the window closes).\n\nCookies created by websites that don't match the pattern are controlled by the \"DefaultCookiesSetting\" policy (if set) or by the user's personal configuration. This is also the default behavior if you don't configure this policy.\n\nYou can also use the \"CookiesAllowedForUrls\" and \"CookiesBlockedForUrls\" policies to control which websites can create cookies.\n\nNote there can't be conflicting URL patterns set between these three policies:\n\n- \"CookiesBlockedForUrls\"\n\n- \"CookiesAllowedForUrls\"\n\n- CookiesSessionOnlyForUrls\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.\n\nIf you set the \"RestoreOnStartup\" policy to restore URLs from previous sessions, this policy is ignored, and cookies are stored permanently for those sites.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotaddressbarsuggestionsenabled","displayName":"Enable Copilot address bar suggestions","description":"This policy controls whether Copilot chat suggestions appear in the address bar of Microsoft Edge.\n\nIf you enable this policy or don't configure it, Copilot chat suggestions appear in the address bar.\n\nIf you disable this policy, Copilot chat suggestions don't appear in the address bar.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotaddressbarsuggestionsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotaddressbarsuggestionsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotcdppagecontext","displayName":"Control Copilot with Commercial Data Protection access to page context for Microsoft Entra ID profiles (Obsolete)","description":"This policy has been obsoleted as of Edge 133. Instead of this obsolete policy, we recommend using \"EdgeEntraCopilotPageContext\".\n\nThis policy controls access to page contents for Copilot with Commercial Data Protection in the Edge sidebar. This policy applies only to Microsoft Entra ID profiles. To summarize pages and interact with text selections, it needs to be able to access the page contents. This policy doesn't apply to MSA profiles. This policy doesn't control access for Copilot without Commercial Data Protection. Access for Copilot without Commercial Data Protection is controlled by the policy CopilotPageContext.\n\nIf you enable this policy, Copilot with Commercial Data Protection will have access to page context.\n\nIf you don't configure this policy, a user can enable access to page context for Copilot with Commercial Data Protection using the setting toggle in Edge.\n\nIf you disable this policy, Copilot with Commercial Data Protection won't be able to access page context.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotcdppagecontext_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotcdppagecontext_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled","displayName":"Enable the Copilot new tab page","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\n\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\n\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\n\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\n\nIf you enable this policy, the Copilot new tab page is turned on.\n\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_recommended","displayName":"Enable the Copilot new tab page (users can override)","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\n\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\n\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\n\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\n\nIf you enable this policy, the Copilot new tab page is turned on.\n\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotpagecontext","displayName":"Control Copilot access to page context for Microsoft Entra ID profiles","description":"This policy controls whether Copilot in the Microsoft Edge side pane can access page content.\n\nThis policy applies only to Microsoft Entra ID profiles in Microsoft Edge. It doesn't apply to Microsoft account (MSA) profiles.\n\nCopilot requires access to page content to summarize pages and interact with text selections.\n\nThis policy doesn't control access for Copilot with enterprise data protection (EDP). Access for Copilot with EDP is controlled by the \"EdgeEntraCopilotPageContext\" policy.\n\nIf you enable this policy, Copilot can access page content.\n\nIf you disable this policy, Copilot can't access page content. This also disables the \"M365LinksAutoOpenCopilotEnabled\" feature, because Copilot requires page content access to provide contextual insights for Microsoft 365 links.\n\nIf you don't configure this policy:\n- Access is enabled by default in non-EU regions.\n- Access is disabled by default in EU regions.\n- Users can turn this setting on or off in Microsoft Edge settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotpagecontext_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotpagecontext_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request header support enabled","description":"This policy lets you configure support for CORS non-wildcard request headers.\n\nMicrosoft Edge version 97 introduces support for CORS non-wildcard request headers. When a script makes a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header is explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. For more information, see https://go.microsoft.com/fwlink/?linkid=2180022.\n\nIf you enable or don't configure the policy, Microsoft Edge supports the CORS non-wildcard request headers and behaves as previously described.\n\nIf you disable this policy, Microsoft Edge allows the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\n\nThis policy is a temporary workaround for the new CORS non-wildcard request header feature. It's planned to be removed in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.corsnonwildcardrequestheaderssupport_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.corsnonwildcardrequestheaderssupport_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cpuperformancetieroverride","displayName":"Override for the CPU performance tier","description":"This policy allows you to override the value returned by the CPU Performance API (that is, navigator.cpuPerformance).\n\nIf you enable this policy, the value of navigator.cpuPerformance is overridden with the specified value.\n\nIf you don’t configure this policy, the default performance tier calculation is used.\n\nYou can specify a value from 0 through 4.\n\nFor more information, see https://github.com/WICG/cpu-performance.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.createpasskeysinicloudkeychain","displayName":"Control whether passkey creation will default to iCloud Keychain.","description":"Microsoft Edge may direct\npasskey/WebAuthn creation requests directly to iCloud Keychain on macOS version 13.5\nor later. If iCloud Keychain syncing isn't enabled yet, this will\nprompt the user to sign in with iCloud, or might prompt them to enable iCloud\nKeychain syncing.\n\nIf you have enabled this policy, then iCloud Keychain is the default\nwhenever the WebAuthn request is compatible with that choice.\n\nIf you haven't configured this policy, then the default behavior depends on factors such as\nwhether iCloud Drive is enabled, or whether the user has recently used or\ncreated a credential in their\nMicrosoft Edge profile.\n\nIf you have disabled this policy, iCloud Keychain isn't used by default\nand the previous behavior (of creating the credential in the Microsoft Edge profile) is used\ninstead. Users can still select iCloud Keychain as an option, and\ncan still see iCloud Keychain credentials when signing in.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.createpasskeysinicloudkeychain_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.createpasskeysinicloudkeychain_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.crossoriginwebassemblymodulesharingenabled","displayName":"Specifies whether WebAssembly modules can be sent cross-origin (Obsolete)","description":"Specifies whether WebAssembly modules can be sent to another window or worker cross-origin. Cross-origin WebAssembly module sharing was deprecated as part of the efforts to deprecate document.domain, see https://github.com/mikewest/deprecating-document-domain. This policy allowed re-enabling of cross-origin WebAssembly module sharing. This policy is obsolete because it was intended to offer a longer transition period in the deprecation process.\n\nIf you enable this policy, sites can send WebAssembly modules cross-origin\nwithout restrictions.\n\nIf you disable or don't configure this policy, sites can only send\nWebAssembly modules to windows and workers in the same origin.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.crossoriginwebassemblymodulesharingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.crossoriginwebassemblymodulesharingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cryptowalletenabled","displayName":"Enable CryptoWallet feature (Obsolete)","description":"This policy is obsoleted because this feature will no longer be supported, starting in Microsoft Edge 128. There's no replacement for this policy.\n Enables CryptoWallet feature in Microsoft Edge.\n\n If you enable this policy or don't configure it, users can use CryptoWallet feature that allows users to securely store, manage, and transact digital assets such as Bitcoin, Ethereum, and other cryptocurrencies. Therefore, Microsoft Edge may access Microsoft servers to communicate with the web3 world during the use of the CryptoWallet feature.\n\n If you disable this policy, users can't use CryptoWallet feature.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.cryptowalletenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cryptowalletenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.csscustomstatedeprecatedsyntaxenabled","displayName":"Controls whether the deprecated :--foo syntax for CSS custom state is enabled (Obsolete)","description":"The :--foo syntax for the CSS custom state feature is being changed to :state(foo) in Microsoft Edge to comply with changes that are made in Firefox and Safari. This policy allows the deprecated syntax to be used until Stable 132.\n\nThis deprecation breaks some Microsoft Edge-only websites that use the deprecated :--foo syntax.\n\nIf you enable this policy, the deprecated syntax is enabled.\n\nIf you disable or don't configure this policy, the deprecated syntax is disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.csscustomstatedeprecatedsyntaxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.csscustomstatedeprecatedsyntaxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.customhelplink","displayName":"Specify custom help link","description":"Specify a link for the Help menu or the F1 key.\n\nIf you enable this policy, an admin can specify a link for the Help menu or the F1 key.\n\nIf you disable or don't configure this policy, the default link for the Help menu or the F1 key is used.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinsvguseenabled","displayName":"Data URL support for SVGUseElement","description":"This policy enables Data URL support for SVGUseElement, which is disabled\nby default starting in Microsoft Edge version 119.\nIf this policy is enabled, Data URLs keep working in SVGUseElement.\nIf this policy is disabled or not configured, Data URLs can't work in SVGUseElement.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinsvguseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinsvguseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinwebworkeropaqueoriginenabled","displayName":"Enable opaque origins for data URLs in Web Workers","description":"This policy controls whether Web Workers created from data URLs are assigned\na unique opaque origin.\n\nWeb Workers can be created using a data URL that contains the worker script.\nPreviously, these workers inherited the origin of the page that created them,\nwhich allowed them to access the same origin-bound data, such as local\nstorage and cookies.\n\nStarting in Microsoft Edge version\n149, Web Workers created from data URLs are assigned a unique opaque origin\nby default. This behavior improves security and aligns with the HTML\nspecification by isolating these workers from the page that created them.\n\nIf you enable this policy or don't configure it, Web Workers created from\ndata URLs are assigned a unique opaque origin.\n\nIf you disable this policy, Web Workers created from data URLs inherit the\norigin of the page that created them. Use this setting only as a temporary\nmitigation for compatibility issues with internal applications that depend\non the legacy behavior.\n\nThis policy is temporary and will be removed in Microsoft Edge\nversion 157.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinwebworkeropaqueoriginenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinwebworkeropaqueoriginenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultautomaticdownloadssetting","displayName":"Default automatic downloads setting","description":"Administrators can use this policy to control whether websites can perform multiple downloads successively. Individual site behavior can be managed using the AutomaticDownloadsAllowedForUrls and AutomaticDownloadsBlockedForUrls policies.\n\nDefault behavior:\n\n- A user gesture is required for each additional download.\n\n- Users can modify their browser settings to disable successive downloads.\n\nPolicy options mapping:\n\n* AllowAutomaticDownloads (1) = Allow all websites to perform multiple downloads without requiring a user gesture between each download.\n\n* BlockAutomaticDownloads (2) = Prevent all websites from performing multiple downloads, even after a user gesture.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultautomaticdownloadssetting_allowautomaticdownloads","displayName":"Allow all websites to perform multiple downloads without requiring a user gesture between each download.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultautomaticdownloadssetting_blockautomaticdownloads","displayName":"Prevent all websites from performing multiple downloads, even after a user gesture.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultclipboardsetting","displayName":"Default clipboard site permission","description":"This policy controls the default value for the clipboard site permission.\n\nSetting the policy to 2 blocks sites from using the clipboard site permission.\n\nSetting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use an API.\n\nThis policy can be overridden for specific URL patterns using the \"ClipboardAllowedForUrls\" and \"ClipboardBlockedForUrls\" policies.\n\nThis policy only affects clipboard operations controlled by the clipboard site permission and doesn't affect sanitized clipboard writes or trusted copy and paste operations.\n\nPolicy options mapping:\n\n* BlockClipboard (2) = Do not allow any site to use the clipboard site permission\n\n* AskClipboard (3) = Allow sites to ask the user to grant the clipboard site permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultclipboardsetting_blockclipboard","displayName":"Do not allow any site to use the clipboard site permission","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultclipboardsetting_askclipboard","displayName":"Allow sites to ask the user to grant the clipboard site permission","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultcookiessetting","displayName":"Configure cookies","description":"Control whether websites can create cookies on the user's device. This policy is all or nothing - you can let all websites create cookies, or no websites create cookies. You can't use this policy to enable cookies from specific websites.\n\nSet the policy to 'SessionOnly' to clear cookies when the session closes.\n\nIf you don't configure this policy, the default 'AllowCookies' is used, and users can change this setting in Microsoft Edge Settings. (If you don't want users to be able to change this setting, set the policy.)\n\nPolicy options mapping:\n\n* AllowCookies (1) = Let all sites create cookies\n\n* BlockCookies (2) = Don't let any site create cookies\n\n* SessionOnly (4) = Keep cookies for the duration of the session, except ones listed in \"SaveCookiesOnExit\"\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultcookiessetting_allowcookies","displayName":"Let all sites create cookies","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultcookiessetting_blockcookies","displayName":"Don't let any site create cookies","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultcookiessetting_sessiononly","displayName":"Keep cookies for the duration of the session, except ones listed in \"SaveCookiesOnExit\"","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultdownloaddirectory_recommended","displayName":"Set default download directory (users can override)","description":"This policy sets the default directory that Microsoft Edge uses to download files. Users can change the directory through browser settings.\n\nIf you don't configure this policy, Microsoft Edge uses the platform-specific default download directory.\n\nThis policy has no effect if the DownloadDirectory policy is set.\n\nFor a list of supported variables, see https://learn.microsoft.com/en-us/deployedge/edge-learnmore-create-user-directory-vars .","helpText":null,"infoUrls":[],"categoryId":"5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","categoryName":"Downloads","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading","description":"If you set this policy to 3, websites can ask for read access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\n\nIf you don't set this policy, websites can ask for access. Users can change this setting.\n\nPolicy options mapping:\n\n* BlockFileSystemRead (2) = Don't allow any site to request read access to files and directories via the File System API\n\n* AskFileSystemRead (3) = Allow sites to ask the user to grant read access to files and directories via the File System API\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemreadguardsetting_blockfilesystemread","displayName":"Don't allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemreadguardsetting_askfilesystemread","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing","description":"If you set this policy to 3, websites can ask for write access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\n\nIf you don't set this policy, websites can ask for access. Users can change this setting.\n\nPolicy options mapping:\n\n* BlockFileSystemWrite (2) = Don't allow any site to request write access to files and directories\n\n* AskFileSystemWrite (3) = Allow sites to ask the user to grant write access to files and directories\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemwriteguardsetting_blockfilesystemwrite","displayName":"Don't allow any site to request write access to files and directories","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemwriteguardsetting_askfilesystemwrite","displayName":"Allow sites to ask the user to grant write access to files and directories","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultgeolocationsetting","displayName":"Default geolocation setting","description":"Set whether websites can track users' physical locations. You can allow tracking by default ('AllowGeolocation'), deny it by default ('BlockGeolocation'), or ask the user each time a website requests their location ('AskGeolocation').\n\nIf you don't configure this policy, 'AskGeolocation' is used and the user can change it.\n\nPolicy options mapping:\n\n* AllowGeolocation (1) = Allow sites to track users' physical location\n\n* BlockGeolocation (2) = Don't allow any site to track users' physical location\n\n* AskGeolocation (3) = Ask whenever a site wants to track users' physical location\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultgeolocationsetting_allowgeolocation","displayName":"Allow sites to track users' physical location","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultgeolocationsetting_blockgeolocation","displayName":"Don't allow any site to track users' physical location","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultgeolocationsetting_askgeolocation","displayName":"Ask whenever a site wants to track users' physical location","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting","displayName":"Default idle detection setting","description":"Setting this policy to 1 - AllowIdleDetection allows websites to use the Idle Detection API without requesting user permission.\n\nSetting this policy to 2 - BlockIdleDetection prevents websites from using the Idle Detection API.\n\nSetting this policy to 3 - AskIdleDetection requires websites to request user permission each time before using the Idle Detection API.\n\nIf you do not configure this policy, users can decide whether to allow the Idle Detection API and can change this setting themselves.\n\nPolicy options mapping:\n\n* AllowIdleDetection (1) = Allow sites to detect idle state without asking the user\n\n* BlockIdleDetection (2) = Do not allow any site to detect the user's idle state\n\n* AskIdleDetection (3) = Ask every time a site wants to detect the user's idle state\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting_allowidledetection","displayName":"Allow sites to detect idle state without asking the user","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting_blockidledetection","displayName":"Do not allow any site to detect the user's idle state","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting_askidledetection","displayName":"Ask every time a site wants to detect the user's idle state","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultimagessetting","displayName":"Default images setting","description":"Set whether websites can display images. You can allow images on all sites ('AllowImages') or block them on all sites ('BlockImages').\n\nIf you don't configure this policy, images are allowed by default, and the user can change this setting.\n\nPolicy options mapping:\n\n* AllowImages (1) = Allow all sites to show all images\n\n* BlockImages (2) = Don't allow any site to show images\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultimagessetting_allowimages","displayName":"Allow all sites to show all images","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultimagessetting_blockimages","displayName":"Don't allow any site to show images","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions","description":"Allows you to set whether users can add exceptions to allow mixed content for specific sites.\n\nThis policy can be overridden for specific URL patterns using the \"InsecureContentAllowedForUrls\" and \"InsecureContentBlockedForUrls\" policies.\n\nIf this policy isn't set, users are allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.\n\nPolicy options mapping:\n\n* BlockInsecureContent (2) = Don't allow any site to load mixed content\n\n* AllowExceptionsInsecureContent (3) = Allow users to add exceptions to allow mixed content\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultinsecurecontentsetting_blockinsecurecontent","displayName":"Don't allow any site to load mixed content","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultinsecurecontentsetting_allowexceptionsinsecurecontent","displayName":"Allow users to add exceptions to allow mixed content","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT","description":"Allows you to set whether Microsoft Edge runs the v8 JavaScript engine with JIT (Just In Time) compiler enabled or not.\n\nDisabling the JavaScript JIT means that Microsoft Edge can render web content more slowly, and can also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT can allow Microsoft Edge to render web content in a more secure configuration.\n\nThis policy can be overridden for specific URL patterns using the \"JavaScriptJitAllowedForSites\" and \"JavaScriptJitBlockedForSites\" policies.\n\nIf you don't configure this policy, JavaScript JIT is enabled.\n\nPolicy options mapping:\n\n* AllowJavaScriptJit (1) = Allow any site to run JavaScript JIT\n\n* BlockJavaScriptJit (2) = Do not allow any site to run JavaScript JIT\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptjitsetting_allowjavascriptjit","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptjitsetting_blockjavascriptjit","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers","description":"Allows you to set whether Microsoft Edge will run the v8 JavaScript engine with more advanced JavaScript optimizations enabled.\n\nDisabling JavaScript optimizations (by setting this policy's value to 2) will mean that Microsoft Edge may render web content more slowly.\n\nThis policy can be overridden for specific URL patterns using the \"JavaScriptOptimizerAllowedForSites\" and \"JavaScriptOptimizerBlockedForSites\" policies.\n\nIf you don't configure this policy, JavaScript optimizations are enabled.\n\nPolicy options mapping:\n\n* AllowJavaScriptOptimizer (1) = Enable advanced JavaScript optimizations on all sites\n\n* BlockJavaScriptOptimizer (2) = Disable advanced JavaScript optimizations on all sites\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptoptimizersetting_allowjavascriptoptimizer","displayName":"Enable advanced JavaScript optimizations on all sites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptoptimizersetting_blockjavascriptoptimizer","displayName":"Disable advanced JavaScript optimizations on all sites","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptsetting","displayName":"Default JavaScript setting","description":"Set whether websites can run JavaScript. You can allow it for all sites ('AllowJavaScript') or block it for all sites ('BlockJavaScript').\n\nIf you don't configure this policy, all sites can run JavaScript by default, and the user can change this setting.\n\nPolicy options mapping:\n\n* AllowJavaScript (1) = Allow all sites to run JavaScript\n\n* BlockJavaScript (2) = Don't allow any site to run JavaScript\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptsetting_allowjavascript","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultjavascriptsetting_blockjavascript","displayName":"Don't allow any site to run JavaScript","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultlocalfontssetting","displayName":"Default Local Fonts permission setting","description":"Setting this policy controls the default behavior for the local fonts permission.\n\nIf you set the policy to BlockLocalFonts (value 2), access to local fonts is denied by default. Sites are prevented from accessing information about local fonts.\n\nIf you set the policy to AskLocalFonts (value 3), users are prompted when a site requests access to local fonts. If permission is granted, the site can access information about local fonts.\n\nIf a site is included in \"LocalFontsAllowedForUrls\" or \"LocalFontsBlockedForUrls\", then that setting overrides the value set for this policy.\n\nIf you don't configure this policy, users are prompted by default and can change this setting.\n\nPolicy options mapping:\n\n* BlockLocalFonts (2) = Denies the Local Fonts permission on all sites by default\n\n* AskLocalFonts (3) = Ask every time a site wants to obtain the Local Fonts permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultlocalfontssetting_blocklocalfonts","displayName":"Denies the Local Fonts permission on all sites by default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultlocalfontssetting_asklocalfonts","displayName":"Ask every time a site wants to obtain the Local Fonts permission","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultnotificationssetting","displayName":"Default notification setting","description":"Set whether websites can display desktop notifications. You can allow them by default ('AllowNotifications'), deny them by default ('BlockNotifications'), or have the user be asked each time a website wants to show a notification ('AskNotifications').\n\nIf you don't configure this policy, notifications are allowed by default, and the user can change this setting.\n\nPolicy options mapping:\n\n* AllowNotifications (1) = Allow sites to show desktop notifications\n\n* BlockNotifications (2) = Don't allow any site to show desktop notifications\n\n* AskNotifications (3) = Ask every time a site wants to show desktop notifications\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultnotificationssetting_allownotifications","displayName":"Allow sites to show desktop notifications","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultnotificationssetting_blocknotifications","displayName":"Don't allow any site to show desktop notifications","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultnotificationssetting_asknotifications","displayName":"Ask every time a site wants to show desktop notifications","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpluginssetting","displayName":"Default Adobe Flash setting (Obsolete)","description":"This policy doesn't work because Flash is no longer supported by Microsoft Edge.\n\n\"PluginsAllowedForUrls\" and \"PluginsBlockedForUrls\" are checked first, then this policy. The options are 'ClickToPlay' and 'BlockPlugins'. If you set this policy to 'BlockPlugins', this plugin is denied for all websites. 'ClickToPlay' lets the Flash plugin run, but users click the placeholder to start it.\n\nIf you don't configure this policy, the user can change this setting manually.\n\nNote: Automatic playback is only for domains explicitly listed in the \"PluginsAllowedForUrls\" policy. To turn automatic playback on for all sites, add http://* and https://* to the allowed list of URLs.\n\nPolicy options mapping:\n\n* BlockPlugins (2) = Block the Adobe Flash plugin\n\n* ClickToPlay (3) = Click to play\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpluginssetting_blockplugins","displayName":"Block the Adobe Flash plugin","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpluginssetting_clicktoplay","displayName":"Click to play","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpopupssetting","displayName":"Default pop-up window setting","description":"Set whether websites can show pop-up windows. You can allow them on all websites ('AllowPopups') or block them on all sites ('BlockPopups').\n\nIf you don't configure this policy, pop-up windows are blocked by default, and users can change this setting.\n\nPolicy options mapping:\n\n* AllowPopups (1) = Allow all sites to show pop-ups\n\n* BlockPopups (2) = Do not allow any site to show popups\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpopupssetting_allowpopups","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpopupssetting_blockpopups","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultprinterselection","displayName":"Default printer selection rules","description":"Overrides Microsoft Edge default printer selection rules. This policy determines the rules for selecting the default printer in Microsoft Edge, which happens the first time a user tries to print a page.\n\nWhen this policy is set, Microsoft Edge tries to find a printer that matches all of the specified attributes and uses it as default printer. If there are multiple printers that meet the criteria, the first printer that matches is used.\n\nIf you don't configure this policy or no matching printers are found within the timeout, the printer defaults to the built-in PDF printer or no printer, if the PDF printer isn't available.\n\nThe value is parsed as a JSON object, conforming to the following schema: { \"type\": \"object\", \"properties\": { \"idPattern\": { \"description\": \"Regular expression to match printer id.\", \"type\": \"string\" }, \"namePattern\": { \"description\": \"Regular expression to match printer display name.\", \"type\": \"string\" } } }\n\nOmitting a field means all values match; for example, if you don't specify connectivity Print Preview starts discovering all kinds of local printers. Regular expression patterns must follow the JavaScript RegExp syntax and matches are case sensitive.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidercontextmenuaccessallowed","displayName":"Allow default search provider context menu search access","description":"Enables the use of a default search provider on the context menu.\n\nIf you disable this policy, the search context menu item that relies on your default search provider and sidebar search isn't available.\n\nIf you enable or don't configure this policy, the context menu item for your default search provider and sidebar search is available.\n\nThe policy value is only applied when the \"DefaultSearchProviderEnabled\" policy is enabled, and isn't applicable otherwise.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidercontextmenuaccessallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidercontextmenuaccessallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderenabled","displayName":"Enable the default search provider","description":"Enables the ability to use a default search provider.\n\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\n\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider.\n\nIf you disable this policy, the user can't search from the address bar.\n\nIf you enable or disable this policy, users can't change or override it.\n\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderenabled_recommended","displayName":"Enable the default search provider (users can override)","description":"Enables the ability to use a default search provider.\n\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\n\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider.\n\nIf you disable this policy, the user can't search from the address bar.\n\nIf you enable or disable this policy, users can't change or override it.\n\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderencodings","displayName":"Default search provider encodings","description":"Specify the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided.\n\nThis policy is optional. If not configured, the default, UTF-8, is used.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderencodings_recommended","displayName":"Default search provider encodings (users can override)","description":"Specify the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided.\n\nThis policy is optional. If not configured, the default, UTF-8, is used.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\n\nThis policy is optional. If you don't configure it, image search isn't available.\n\nSpecify Bing's Image Search URL as:\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\n\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\n\nSee \"DefaultSearchProviderImageURLPostParams\" policy to finish configuring image search.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderimageurl_recommended","displayName":"Specifies the search-by-image feature for the default search provider (users can override)","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\n\nThis policy is optional. If you don't configure it, image search isn't available.\n\nSpecify Bing's Image Search URL as:\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\n\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\n\nSee \"DefaultSearchProviderImageURLPostParams\" policy to finish configuring image search.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it's replaced with real image thumbnail data. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nSpecify Bing's Image Search URL Post Params as:\n'imageBin={google:imageThumbnailBase64}'.\n\nSpecify Google's Image Search URL Post Params as:\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\n\nIf you don't set this policy, image search requests are sent using the GET method.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderimageurlpostparams_recommended","displayName":"Parameters for an image URL that uses POST (users can override)","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it's replaced with real image thumbnail data. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nSpecify Bing's Image Search URL Post Params as:\n'imageBin={google:imageThumbnailBase64}'.\n\nSpecify Google's Image Search URL Post Params as:\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\n\nIf you don't set this policy, image search requests are sent using the GET method.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderkeyword","displayName":"Default search provider keyword","description":"Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider.\n\nThis policy is optional. If you don't configure it, no keyword activates the search provider.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderkeyword_recommended","displayName":"Default search provider keyword (users can override)","description":"Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider.\n\nThis policy is optional. If you don't configure it, no keyword activates the search provider.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidername","displayName":"Default search provider name","description":"Specifies the name of the default search provider.\n\nIf you enable this policy, you set the name of the default search provider.\n\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\n\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy isn't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidername_recommended","displayName":"Default search provider name (users can override)","description":"Specifies the name of the default search provider.\n\nIf you enable this policy, you set the name of the default search provider.\n\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\n\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy isn't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidersearchurl","displayName":"Default search provider search URL","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\n\nSpecify Bing's search URL as:\n\n'{bing:baseURL}search?q={searchTerms}'.\n\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\n\nThis policy is required when you enable the \"DefaultSearchProviderEnabled\" policy; if you don't enable the latter policy, this policy is ignored.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidersearchurl_recommended","displayName":"Default search provider search URL (users can override)","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\n\nSpecify Bing's search URL as:\n\n'{bing:baseURL}search?q={searchTerms}'.\n\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\n\nThis policy is required when you enable the \"DefaultSearchProviderEnabled\" policy; if you don't enable the latter policy, this policy is ignored.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions","description":"Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user entered so far.\n\nThis policy is optional. If you don't configure it, users can't see search suggestions; they see suggestions from their browsing history and favorites.\n\nBing's suggest URL can be specified as:\n\n'{bing:baseURL}qbox?query={searchTerms}'.\n\nGoogle's suggest URL can be specified as:\n\n'{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy isn't added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidersuggesturl_recommended","displayName":"Default search provider URL for suggestions (users can override)","description":"Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user entered so far.\n\nThis policy is optional. If you don't configure it, users can't see search suggestions; they see suggestions from their browsing history and favorites.\n\nBing's suggest URL can be specified as:\n\n'{bing:baseURL}qbox?query={searchTerms}'.\n\nGoogle's suggest URL can be specified as:\n\n'{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy isn't added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsensorssetting","displayName":"Default sensors setting","description":"Set whether websites can access and use sensors such as motion and light sensors. You can completely block or allow websites to get access to sensors.\n\nSetting the policy to 1 lets websites access and use sensors. Setting the policy to 2 denies access to sensors.\n\nYou can override this policy for specific URL patterns by using the \"SensorsAllowedForUrls\" and \"SensorsBlockedForUrls\" policies.\n\nIf you don't configure this policy, websites can access and use sensors, and users can change this setting. This setting is the global default for \"SensorsAllowedForUrls\" and \"SensorsBlockedForUrls\".\n\nPolicy options mapping:\n\n* AllowSensors (1) = Allow sites to access sensors\n\n* BlockSensors (2) = Do not allow any site to access sensors\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsensorssetting_allowsensors","displayName":"Allow sites to access sensors","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsensorssetting_blocksensors","displayName":"Do not allow any site to access sensors","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultserialguardsetting","displayName":"Control use of the Serial API","description":"Set whether websites can access serial ports. You can completely block access or ask the user each time a website wants to get access to a serial port.\n\nSetting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\n\nYou can override this policy for specific URL patterns by using the \"SerialAskForUrls\" and \"SerialBlockedForUrls\" policies.\n\nIf you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting.\n\nPolicy options mapping:\n\n* BlockSerial (2) = Do not allow any site to request access to serial ports via the Serial API\n\n* AskSerial (3) = Allow sites to ask for user permission to access a serial port\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultserialguardsetting_blockserial","displayName":"Do not allow any site to request access to serial ports via the Serial API","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultserialguardsetting_askserial","displayName":"Allow sites to ask for user permission to access a serial port","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting","displayName":"Set the default \"share additional operating system region\" setting","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\n\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting is shared with the web through the default JavaScript locale. If shared, websites can query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\n\nIf you set this policy to \"Limited\", the OS Regional format is shared only if its language part matches the Microsoft Edge display language.\n\nIf you set this policy to \"Always\", the OS Regional format is always shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months are displayed in one language while the surrounding text is displayed in another language.\n\nIf you set this policy to \"Never\", the OS Regional format is never shared.\n\nExample 1: In this example the OS Regional format is set to \"en-GB\", and the browser display language is set to \"en-US\". Then the OS Regional format is shared if the policy is set to \"Limited\", or \"Always\".\n\nExample 2: In this example the OS Regional format is set to \"es-MX\", and the browser display language is set to \"en-US\". Then the OS Regional format is shared if the policy is set to \"Always\"; however, the OS Regional format isn't shared if the policy is set to \"Limited\".\n\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282.\n\nPolicy options mapping:\n\n* Limited (0) = Limited\n\n* Always (1) = Always share the OS Regional format\n\n* Never (2) = Never share the OS Regional format\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_limited","displayName":"Limited","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_always","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_never","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended","displayName":"Set the default \"share additional operating system region\" setting (users can override)","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\n\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting is shared with the web through the default JavaScript locale. If shared, websites can query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\n\nIf you set this policy to \"Limited\", the OS Regional format is shared only if its language part matches the Microsoft Edge display language.\n\nIf you set this policy to \"Always\", the OS Regional format is always shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months are displayed in one language while the surrounding text is displayed in another language.\n\nIf you set this policy to \"Never\", the OS Regional format is never shared.\n\nExample 1: In this example the OS Regional format is set to \"en-GB\", and the browser display language is set to \"en-US\". Then the OS Regional format is shared if the policy is set to \"Limited\", or \"Always\".\n\nExample 2: In this example the OS Regional format is set to \"es-MX\", and the browser display language is set to \"en-US\". Then the OS Regional format is shared if the policy is set to \"Always\"; however, the OS Regional format isn't shared if the policy is set to \"Limited\".\n\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282.\n\nPolicy options mapping:\n\n* Limited (0) = Limited\n\n* Always (1) = Always share the OS Regional format\n\n* Never (2) = Never share the OS Regional format\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended_limited","displayName":"Limited","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended_always","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended_never","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultthirdpartystoragepartitioningsetting","displayName":"Default setting for third-party storage partitioning (Obsolete)","description":"This policy controls whether third-party storage partitioning is allowed by default.\n\nIf this policy is set to 1 - AllowPartitioning, or unset, third-party storage partitioning will be allowed by default. This default may be overridden for specific top-level origins by other means.\n\nIf this policy is set to 2 - BlockPartitioning, third-party storage partitioning will be disabled for all contexts.\n\nUse ThirdPartyStoragePartitioningBlockedForOrigins to disable third-party storage partitioning for specific top-level origins.\n\nThis feature has been removed starting in Microsoft Edge version 146. To ensure compatibility, use the requestStorageAccess method instead. For more information, see https://developer.mozilla.org/en-US/docs/Web/API/Document/requestStorageAccess.\n\nPolicy options mapping:\n\n* AllowPartitioning (1) = Allow third-party storage partitioning by default.\n\n* BlockPartitioning (2) = Disable third-party storage partitioning.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultthirdpartystoragepartitioningsetting_allowpartitioning","displayName":"Allow third-party storage partitioning by default.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultthirdpartystoragepartitioningsetting_blockpartitioning","displayName":"Disable third-party storage partitioning.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API","description":"Control whether websites can access nearby Bluetooth devices. You can completely block access or require the site to ask the user each time it wants to access a Bluetooth device.\n\nIf you don't configure this policy, the default value ('AskWebBluetooth', meaning users are asked each time) is used and users can change it.\n\nPolicy options mapping:\n\n* BlockWebBluetooth (2) = Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API\n\n* AskWebBluetooth (3) = Allow sites to ask the user to grant access to a nearby Bluetooth device\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebbluetoothguardsetting_blockwebbluetooth","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebbluetoothguardsetting_askwebbluetooth","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebhidguardsetting","displayName":"Control use of the WebHID API","description":"Setting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices.\n\nLeaving it unset lets websites ask for access, but users can change this setting.\n\nThis policy can be overridden for specific url patterns using the \"WebHidAskForUrls\" and \"WebHidBlockedForUrls\" policies.\n\nPolicy options mapping:\n\n* BlockWebHid (2) = Do not allow any site to request access to HID devices via the WebHID API\n\n* AskWebHid (3) = Allow sites to ask the user to grant access to a HID device\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebhidguardsetting_blockwebhid","displayName":"Do not allow any site to request access to HID devices via the WebHID API","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebhidguardsetting_askwebhid","displayName":"Allow sites to ask the user to grant access to a HID device","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebusbguardsetting","displayName":"Control use of the WebUSB API","description":"Set whether websites can access connected USB devices. You can completely block access or ask the user each time a website wants to get access to connected USB devices.\n\nYou can override this policy for specific URL patterns by using the \"WebUsbAskForUrls\" and \"WebUsbBlockedForUrls\" policies.\n\nIf you don't configure this policy, sites can ask users whether they can access the connected USB devices ('AskWebUsb') by default, and users can change this setting.\n\nPolicy options mapping:\n\n* BlockWebUsb (2) = Do not allow any site to request access to USB devices via the WebUSB API\n\n* AskWebUsb (3) = Allow sites to ask the user to grant access to a connected USB device\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebusbguardsetting_blockwebusb","displayName":"Do not allow any site to request access to USB devices via the WebUSB API","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebusbguardsetting_askwebusb","displayName":"Allow sites to ask the user to grant access to a connected USB device","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwindowmanagementsetting","displayName":"Default Window Management permission setting","description":"Setting the policy to \"BlockWindowManagement\" (value 2) automatically denies the window management permission to sites by default. This setting limits the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\n\nSetting the policy to \"AskWindowManagement\" (value 3) by default prompts the user when the window management permission is requested. If users allow the permission, it extends the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\n\nNot configuring the policy means the \"AskWindowManagement\" policy applies, but users can change this setting.\n\nPolicy options mapping:\n\n* BlockWindowManagement (2) = Denies the Window Management permission on all sites by default\n\n* AskWindowManagement (3) = Ask every time a site wants obtain the Window Management permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwindowmanagementsetting_blockwindowmanagement","displayName":"Denies the Window Management permission on all sites by default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwindowmanagementsetting_askwindowmanagement","displayName":"Ask every time a site wants obtain the Window Management permission","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.definepreferredlanguages","displayName":"Define an ordered list of preferred languages that websites should display in if the site supports the language","description":"Configures the language variants that Microsoft Edge sends to websites as part of the Accept-Language request HTTP header and prevents users from adding, removing, or changing the order of preferred languages in Microsoft Edge settings. Users who want to change the languages Microsoft Edge displays in or offers to translate pages to will be limited to the languages configured in this policy.\n\nIf you enable this policy, websites will appear in the first language in the list that they support unless other site-specific logic is used to determine the display language. The language variants defined in this policy override the languages configured as part of the \"SpellcheckLanguage\" policy.\n\nIf you don't configure or disable this policy, Microsoft Edge sends websites the user-specified preferred languages as part of the Accept-Language request HTTP header.\n\nFor detailed information on valid language variants, see https://go.microsoft.com/fwlink/?linkid=2148854.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.delaynavigationsforinitialsitelistdownload","displayName":"Require that the Enterprise Mode Site List is available before tab navigation","description":"Lets you specify whether Microsoft Edge tabs wait to navigate until the browser downloaded the initial Enterprise Mode Site List. This setting is intended for the scenario where the browser home page should load in Internet Explorer (IE) mode, and it's important that it does so on browser first run after IE mode is enabled. If this scenario doesn't exist, we recommend not enabling this setting because it negatively impacts the performance of loading the home page. The setting only applies when Microsoft Edge doesn't have a cached Enterprise Mode Site List, such as on browser first run after IE mode is enabled.\n\nThis setting works if \"InternetExplorerIntegrationLevel\" is set to 'IEMode' and if either the \"InternetExplorerIntegrationSiteList\" or the \"InternetExplorerIntegrationCloudSiteList\" policies be enabled, where the list has at least one entry.\n\nThe timeout behavior of this policy is configured with the \"NavigationDelayForInitialSiteListDownloadTimeout\" policy.\n\nIf you set this policy to 'All' and when Microsoft Edge doesn't have a cached version of the Enterprise Mode Site List, tabs delay navigating until the browser downloaded the site list. Sites configured to open in Internet Explorer mode by the site list load in Internet Explorer mode, even during the initial navigation of the browser. Sites that can't be configured to open in Internet Explorer, such as any site with a scheme other than http:, https:, file:, or ftp: don't delay navigating and load immediately in Microsoft Edge mode.\n\nWhen used with the \"InternetExplorerIntegrationCloudSiteList\" policy, during first launch of Microsoft Edge, there is a delay because implicit sign in needs to finish before Microsoft Edge attempts to download the site list from the Microsoft cloud since this requires authentication to the cloud service.\n\nIf you set this policy to 'None' or don't configure it and when Microsoft Edge doesn't have a cached version of the Enterprise Mode Site List, tabs navigate immediately and don't wait for the browser to download the Enterprise Mode Site List. Sites configured to open in Internet Explorer mode by the site list open in Microsoft Edge mode until the browser finished downloading the Enterprise Mode Site List.\n\nPolicy options mapping:\n\n* None (0) = None\n\n* All (1) = All eligible navigations\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.delaynavigationsforinitialsitelistdownload_none","displayName":"None","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.delaynavigationsforinitialsitelistdownload_all","displayName":"All eligible navigations","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values don't become decryptable on their own.\n\nIf fixing them is possible, it usually requires complex user actions.\n\nEnabling this policy or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state remain untouched.\n\nDisabling this policy means users will have their password manager data untouched but will experience a broken password manager functionality.\n\nIf the policy is set, users can't override it in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.deletingundecryptablepasswordsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.deletingundecryptablepasswordsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailability","displayName":"Control where developer tools can be used","description":"Controls whether users can access developer tools in Microsoft Edge.\n\nIf you set this policy to 'DeveloperToolsDisallowedForForceInstalledExtensions' (default), users can access developer tools and the JavaScript console, except in the context of extensions installed by enterprise policy.\n\nIf you set this policy to 'DeveloperToolsAllowed', users can access developer tools and the JavaScript console in all contexts, including extensions installed by enterprise policy.\n\nIf you set this policy to 'DeveloperToolsDisallowed', users cannot access developer tools or inspect website elements. Keyboard shortcuts, menu options, and context menu entries that open developer tools or the JavaScript console are disabled.\n\nAs of version 99, this policy also controls access to the 'View page source' feature. If you set this policy to 'DeveloperToolsDisallowed', users cannot view page source through keyboard shortcuts or the context menu. To fully block source viewing, add 'view-source:*' to the \"URLBlocklist\" policy.\n\nAs of version 119, this policy also controls whether developer mode for Isolated Web Apps can be enabled.\n\nAs of version 128, this policy does not control developer mode on the extensions page if the \"ExtensionDeveloperModeSettings\" policy is configured.\n\nDeveloper tools availability is determined in the following order of precedence:\n\n1. If a URL matches a pattern in \"DeveloperToolsAvailabilityAllowlist\", developer tools are allowed.\n2. If the allowlist is configured and the blocklist is not, URLs not on the allowlist are blocked.\n3. If a URL matches a pattern in \"DeveloperToolsAvailabilityBlocklist\", developer tools are blocked.\n4. If a URL is not covered by either list, this policy (\"DeveloperToolsAvailability\") applies.\n\nPolicy options mapping:\n\n* DeveloperToolsDisallowedForForceInstalledExtensions (0) = Block the developer tools on extensions installed by enterprise policy, allow in other contexts\n\n* DeveloperToolsAllowed (1) = Allow using the developer tools\n\n* DeveloperToolsDisallowed (2) = Don't allow using the developer tools\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailability_developertoolsdisallowedforforceinstalledextensions","displayName":"Block the developer tools on extensions installed by enterprise policy, allow in other contexts","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailability_developertoolsallowed","displayName":"Allow using the developer tools","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailability_developertoolsdisallowed","displayName":"Don't allow using the developer tools","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailabilityallowlist","displayName":"List of URL patterns for which developer tools are allowed to be opened","description":"This policy controls where developer tools can be used in Microsoft Edge by specifying an allowlist of URL patterns.\n\nURL patterns are matched against the URL of every frame on the page being inspected.\n\nIf you configure this policy and do not configure the \"DeveloperToolsAvailabilityBlocklist\" policy, developer tools are available only when every frame on the page matches a pattern in this allowlist. If any frame does not match, developer tools are blocked for the entire page. For information on the URL format, see https://go.microsoft.com/fwlink/?linkid=2095322 .\n\nIf you configure both this policy and the \"DeveloperToolsAvailabilityBlocklist\" policy, this allowlist takes precedence. URLs that match this allowlist are allowed even if they also match the blocklist. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither are governed by the \"DeveloperToolsAvailability\" policy.\n\nIf you disable or do not configure this policy, developer tools availability is determined by the \"DeveloperToolsAvailabilityBlocklist\" and \"DeveloperToolsAvailability\" policies.\n\nThis policy applies to developer tools opened for websites, extensions, and web applications.\n\nThis policy supports up to 1,000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailabilityblocklist","displayName":"List of URL patterns for which developer tools are blocked","description":"This policy specifies URL patterns where developer tools are blocked. For information on the URL format, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nURL patterns are evaluated against the URL of every frame on the page being inspected. If any frame matches a pattern in this policy, developer tools are blocked for the entire page.\n\nIf you configure this policy and do not configure the \"DeveloperToolsAvailabilityAllowlist\" policy, developer tools are blocked when any frame matches a pattern in this policy. If no frames match, availability is determined by the \"DeveloperToolsAvailability\" policy.\n\nIf you configure both this policy and the \"DeveloperToolsAvailabilityAllowlist\" policy, the allowlist takes precedence. URLs that match the allowlist are allowed, even if they also match this policy. URLs that match this policy (but not the allowlist) are blocked. If a URL matches neither, the \"DeveloperToolsAvailability\" policy determines availability.\n\nIf you disable or do not configure this policy, developer tools availability is determined by the \"DeveloperToolsAvailabilityAllowlist\" and \"DeveloperToolsAvailability\" policies.\n\nThis policy supports up to 1,000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.disable3dapis","displayName":"Disable support for 3D graphics APIs","description":"Prevent web pages from accessing the graphics processing unit (GPU). Specifically, web pages can't access the WebGL API and plug-ins can't use the Pepper 3D API.\n\nIf you don't configure or disable this policy, it potentially allows web pages to use the WebGL API and plug-ins to use the Pepper 3D API. Microsoft Edge might, by default, still require command line arguments to be passed in order to use these APIs.\n\nIf \"HardwareAccelerationModeEnabled\" policy is set to false, the setting for 'Disable3DAPIs' policy is ignored - it's the equivalent of setting 'Disable3DAPIs' policy to true.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.disable3dapis_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.disable3dapis_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.discoverpagecontextenabled","displayName":"Enable Discover access to page contents for AAD profiles (Obsolete)","description":"This policy is obsolete as of Microsoft Edge version 127. Two new Microsoft Edge Policies took its place. Those policies are CopilotPageContext (Control Copilot access to page contents for AAD profiles) and CopilotCDPPageContext (Control Copilot with Commercial Data Protection access to page contents for AAD profiles).\n\nThis policy didn't allow for separate control of Copilot and Copilot with Commercial Data Protection. The new policies allow separate control of these versions of Copilot. The new policies also allow admins to force-enable Copilot access to Microsoft Edge page contents by enabling the policy, whereas DiscoverPageContextEnabled only allows force-disabling of Copilot page access.\n\nThis policy controls Discover access to page contents for AAD profiles. Discover is an extension that hosts Bing Chat. To summarize pages and interact with text selections, it must access the page contents. When enabled, page contents are sent to Bing. This policy doesn't affect MSA profiles.\n\nIf you enable or don't configure this policy, Discover has access to page contents.\n\nIf you disable this policy, Discover can't access page contents.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.discoverpagecontextenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.discoverpagecontextenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.displaycapturepermissionspolicyenabled","displayName":"Specifies whether the display-capture permissions-policy is checked or skipped (Obsolete)","description":"This policy is obsolete. The policy was a temporary workaround for non-spec-compliant enterprise applications.\n\nThis policy stopped working in Microsoft Edge version 107 and was obsoleted in Microsoft Edge 110.\n\nThe display-capture permissions-policy gates access to getDisplayMedia(),\nas per this spec:\nhttps://www.w3.org/TR/screen-capture/#feature-policy-integration\nHowever, if this policy is Disabled, this requirement isn't enforced,\nand getDisplayMedia() is allowed from contexts that would otherwise be\nforbidden.\n\nIf you enable or don't configure this policy, sites can only call getDisplayMedia() from\ncontexts that are allowlisted by the display-capture permissions-policy.\n\nIf you disable this policy, sites can call getDisplayMedia() even from contexts\nwhich are not allowlisted by the display-capture permissions policy.\nOther restrictions may still apply.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.displaycapturepermissionspolicyenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.displaycapturepermissionspolicyenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.donotsilentlyblockprotocolsfromorigins","displayName":"Define a list of protocols that can not be silently blocked by anti-flood protection","description":"Allows you to create a list of protocols and an associated list of allowed origin patterns, for each protocol. These origins aren't silently blocked from launching an external application by anti-flood protection. The trailing separator shouldn't be included when listing the protocol. For example, list \"skype\" instead of \"skype:\" or \"skype://\".\n\nIf you configure this policy, a protocol is only permitted to bypass being silently blocked by anti-flood protection if:\n\n- the protocol is listed\n\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\n\nIf either condition is false, anti-flood protection protection blocks the external protocol launch.\n\nIf you don't configure this policy, no protocols can bypass being silently blocked.\n\nThe origin-matching patterns use a similar format to those patterns for the \"URLBlocklist\" policy, which are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\n\nHowever, origin-matching patterns for this policy can't contain \"/path\" or \"@query\" elements. Any pattern that contains a \"/path\" or \"@query\" element is ignored.\n\nThis policy doesn't work as expected with file://* wildcards.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.doubleclickclosetabenabled","displayName":"Double Click feature in Microsoft Edge enabled (only available in China)","description":"This policy lets you configure the double click feature in Microsoft Edge.\n\nDouble Click lets users close a tab by double clicking the left mouse button.\n\nIf you enable or don't configure this policy, you can use the double click feature to close a tab on Microsoft Edge to start using this feature.\n\nIf you disable this policy, you can't use the double click feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.doubleclickclosetabenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.doubleclickclosetabenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloaddirectory","displayName":"Set download directory","description":"Configures the directory to use when downloading files.\n\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user specified one or chose to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\n\nIf you disable or don't configure this policy, the default download directory is used, and the user can change it.\n\nIf you set an invalid path, Microsoft Edge defaults to the user's default download directory.\n\nIf the folder specified by the path doesn't exist, the download triggers a prompt that asks the user where they want to save their download.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloaddirectory_recommended","displayName":"Set download directory (users can override)","description":"Configures the directory to use when downloading files.\n\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user specified one or chose to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\n\nIf you disable or don't configure this policy, the default download directory is used, and the user can change it.\n\nIf you set an invalid path, Microsoft Edge defaults to the user's default download directory.\n\nIf the folder specified by the path doesn't exist, the download triggers a prompt that asks the user where they want to save their download.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions","displayName":"Allow download restrictions","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\n\nSet 'BlockDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known dangerous downloads or that have dangerous file type extensions.\n\nSet 'BlockPotentiallyDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous or unwanted downloads or that have dangerous file type extensions.\n\nSet 'BlockAllDownloads' to block all downloads.\n\nSet 'BlockMaliciousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known malicious downloads.\n\nIf you don't configure this policy or set the 'DefaultDownloadSecurity' option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\n\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\n\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\n\nPolicy options mapping:\n\n* DefaultDownloadSecurity (0) = No special restrictions\n\n* BlockDangerousDownloads (1) = Block malicious downloads and dangerous file types\n\n* BlockPotentiallyDangerousDownloads (2) = Block potentially dangerous or unwanted downloads and dangerous file types\n\n* BlockAllDownloads (3) = Block all downloads\n\n* BlockMaliciousDownloads (4) = Block malicious downloads\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_defaultdownloadsecurity","displayName":"No special restrictions","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_blockdangerousdownloads","displayName":"Block malicious downloads and dangerous file types","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_blockpotentiallydangerousdownloads","displayName":"Block potentially dangerous or unwanted downloads and dangerous file types","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_blockalldownloads","displayName":"Block all downloads","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_blockmaliciousdownloads","displayName":"Block malicious downloads","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_recommended","displayName":"Allow download restrictions (users can override)","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\n\nSet 'BlockDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known dangerous downloads or that have dangerous file type extensions.\n\nSet 'BlockPotentiallyDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous or unwanted downloads or that have dangerous file type extensions.\n\nSet 'BlockAllDownloads' to block all downloads.\n\nSet 'BlockMaliciousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known malicious downloads.\n\nIf you don't configure this policy or set the 'DefaultDownloadSecurity' option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\n\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\n\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\n\nPolicy options mapping:\n\n* DefaultDownloadSecurity (0) = No special restrictions\n\n* BlockDangerousDownloads (1) = Block malicious downloads and dangerous file types\n\n* BlockPotentiallyDangerousDownloads (2) = Block potentially dangerous or unwanted downloads and dangerous file types\n\n* BlockAllDownloads (3) = Block all downloads\n\n* BlockMaliciousDownloads (4) = Block malicious downloads\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_recommended_defaultdownloadsecurity","displayName":"No special restrictions","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_recommended_blockdangerousdownloads","displayName":"Block malicious downloads and dangerous file types","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_recommended_blockpotentiallydangerousdownloads","displayName":"Block potentially dangerous or unwanted downloads and dangerous file types","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_recommended_blockalldownloads","displayName":"Block all downloads","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.downloadrestrictions_recommended_blockmaliciousdownloads","displayName":"Block malicious downloads","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled","displayName":"Allow features to download assets from the Asset Delivery Service","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\nThese assets can be config files or Machine Learning models that power the features that use this service.\n\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\n\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_recommended","displayName":"Allow features to download assets from the Asset Delivery Service (users can override)","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\nThese assets can be config files or Machine Learning models that power the features that use this service.\n\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\n\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeautofillmlenabled","displayName":"Machine learning powered autofill suggestions","description":"Allows ML technology to predict and fill in forms and text fields for better browsing. Your personal data is secure and isn't used elsewhere.\n\nIf you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data.\n\nIf you disable this policy, machine learning-powered autofill suggestions aren't shown, and autofill no longer uses cloud-based machine learning models to enhance form filling with smarter, context aware suggestions. Instead, autofill will rely on basic form data without the benefits of machine learning.\n\nThis policy will be disabled if you disable \"AutofillAddressEnabled\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeautofillmlenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeautofillmlenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeautofillmlenabled_recommended","displayName":"Machine learning powered autofill suggestions (users can override)","description":"Allows ML technology to predict and fill in forms and text fields for better browsing. Your personal data is secure and isn't used elsewhere.\n\nIf you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data.\n\nIf you disable this policy, machine learning-powered autofill suggestions aren't shown, and autofill no longer uses cloud-based machine learning models to enhance form filling with smarter, context aware suggestions. Instead, autofill will rely on basic form data without the benefits of machine learning.\n\nThis policy will be disabled if you disable \"AutofillAddressEnabled\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeautofillmlenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeautofillmlenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgecollectionsenabled","displayName":"Enable the Collections feature","description":"Lets you allow users to access the Collections feature, where they can collect, organize, share, and export content more efficiently and with Office integration.\n\nIf you enable or don't configure this policy, users can access and use the Collections feature in Microsoft Edge.\n\nIf you disable this policy, users can't access and use Collections in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgecollectionsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgecollectionsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled","displayName":"Discover feature In Microsoft Edge (Obsolete)","description":"This policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy.\n\nThis policy lets you configure the Discover feature in Microsoft Edge.\n\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\n\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\n\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_recommended","displayName":"Discover feature In Microsoft Edge (Obsolete) (users can override)","description":"This policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy.\n\nThis policy lets you configure the Discover feature in Microsoft Edge.\n\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\n\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\n\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeedropenabled","displayName":"Enable Drop feature in Microsoft Edge","description":"This policy lets you configure the Drop feature in Microsoft Edge.\n\nDrop lets users send messages or files to themselves.\n\nIf you enable or don't configure this policy, you can use the Drop feature in Microsoft Edge.\n\nIf you disable this policy, you can't use the Drop feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeedropenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeedropenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeenhanceimagesenabled","displayName":"Enhance images enabled (Obsolete)","description":"The enhance images feature is deprecated and starting in Microsoft Edge version 122, this policy will be removed. Set whether Microsoft Edge can automatically enhance images to show you sharper images with better color, lighting, and contrast.\n\nIf you enable this policy or don't configure the policy, Microsoft Edge automatically enhances images on specific web applications.\n\nIf you disable this policy, Microsoft Edge doesn't enhance images.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeenhanceimagesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeenhanceimagesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeentracopilotpagecontext","displayName":"Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane","description":"This policy controls whether Copilot in the Microsoft Edge side pane can access page content. This includes page summarization and other contextual queries.\n\nThis policy applies only to users who are signed in to Microsoft Edge with a Microsoft Entra account and are using Copilot in the side pane. It applies to Copilot experiences in the side pane, including Microsoft 365 Copilot Business Chat and Microsoft Copilot with enterprise data protection (EDP).\n\nIf you enable this policy, Copilot can access page content when users submit contextual queries in the side pane.\n\nIf you disable this policy, Copilot can't access page content. This also disables the M365LinksAutoOpenCopilotEnabled feature, because Copilot requires page content access to provide contextual insights for Microsoft 365 links.\n\nIf you don't configure this policy:\n- Access is enabled by default in non-EU regions.\n- Access is disabled by default in EU regions.\n- Users can turn this setting on or off in Microsoft Edge settings.\n\nCopilot can't access page content on pages protected by data loss prevention (DLP) policies, even if this policy is enabled.\n\nFor more information about Copilot data usage and consent, see https://go.microsoft.com/fwlink/?linkid=2288056","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeentracopilotpagecontext_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeentracopilotpagecontext_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgefollowenabled","displayName":"Enable Follow service in Microsoft Edge (Obsolete)","description":"Lets Microsoft Edge browser enable Follow service and apply it to users.\n\nUsers can use the Follow feature for an influencer, site, or topic in Microsoft Edge.\n\nIf you enable or don't configure this policy, Follow in Microsoft Edge is applied.\n\nIf you disable this policy, Microsoft Edge won't communicate with Follow service to provide the follow feature.\n\nThis policy is obsolete after version 126.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgefollowenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgefollowenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgehistoryaisearchenabled","displayName":"Control access to AI-enhanced search in History","description":"This policy controls whether users can use AI-enhanced search in their browsing history in Microsoft Edge.\n\nWhen enabled or not configured, users can search using synonyms, natural language phrases, and minor spelling errors to find previously visited pages.\n\nWhen disabled, users can only perform exact match (verbatim) searches in their history.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgehistoryaisearchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgehistoryaisearchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgemanagementextensionsfeedbackenabled","displayName":"Microsoft Edge management extensions feedback enabled","description":"This setting controls whether Microsoft Edge sends data about blocked extensions to the Microsoft Edge management service.\n\nThe 'EdgeManagementEnabled' policy must also be enabled for this setting to take effect.\n\nIf you enable this policy, Microsoft Edge sends data to the Microsoft Edge service when a user tries to install a blocked extension.\n\nIf you disable or don't configure this policy, Microsoft Edge can't send any data to the Microsoft Edge service about blocked extensions.","helpText":null,"infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgemanagementextensionsfeedbackenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgemanagementextensionsfeedbackenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesafehostingextensionenabled","displayName":"Control Microsoft Edge Safe Hosting Extension","description":"This policy controls whether the Microsoft Edge Safe Hosting component extension is installed automatically when users visit supported Microsoft services, such as Microsoft 365 Copilot app.\n\nThe Microsoft Edge Safe Hosting extension provides additional security capabilities for these services. When a user accesses a supported service, the extension installs automatically to enable those protections.\n\nIf you enable or don't configure this policy, the extension installs automatically and remains installed for 90 days after the user's last visit, then is removed if no further activity occurs.\n\nIf you disable this policy, the extension won't install automatically. If it’s already installed, it will be removed.\n\nNote: This policy controls only automatic installation. It doesn’t prevent users from manually installing other extensions from the Microsoft Edge Add-ons website.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesafehostingextensionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesafehostingextensionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeshoppingassistantenabled","displayName":"Shopping in Microsoft Edge Enabled","description":"This policy lets users compare the prices of a product they're looking at, get coupons or rebates from the website they're on, autoapply coupons, and help checkout faster using autofill data.\n\nIf you enable or don't configure this policy, shopping features such as price comparison, coupons, rebates, and express checkout are automatically applied for retail domains. Coupons for the current retailer and prices from other retailers are fetched from a server.\n\nIf you disable this policy, shopping features such as price comparison, coupons, rebates, and express checkout aren't automatically found for retail domains.\n\nStarting from version 90.0.818.56, the behavior of the messaging letting users know that there's a coupon, rebate, price comparison, or price history available on shopping domains is also done through a horizontal banner below the address bar. Previously, this messaging was done on the address bar.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeshoppingassistantenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeshoppingassistantenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeshoppingassistantenabled_recommended","displayName":"Shopping in Microsoft Edge Enabled (users can override)","description":"This policy lets users compare the prices of a product they're looking at, get coupons or rebates from the website they're on, autoapply coupons, and help checkout faster using autofill data.\n\nIf you enable or don't configure this policy, shopping features such as price comparison, coupons, rebates, and express checkout are automatically applied for retail domains. Coupons for the current retailer and prices from other retailers are fetched from a server.\n\nIf you disable this policy, shopping features such as price comparison, coupons, rebates, and express checkout aren't automatically found for retail domains.\n\nStarting from version 90.0.818.56, the behavior of the messaging letting users know that there's a coupon, rebate, price comparison, or price history available on shopping domains is also done through a horizontal banner below the address bar. Previously, this messaging was done on the address bar.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeshoppingassistantenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeshoppingassistantenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesidebarappurlhostallowlist","displayName":"Allow specific apps to be opened in Microsoft Edge sidebar","description":"Define a list of sites, based on URL patterns, that aren't subject to the \"EdgeSidebarAppUrlHostBlockList\".\n\nIf you don't configure this policy, a user can open any app in sidebar except the urls listed in \"EdgeSidebarAppUrlHostBlockList\".\n\nIf you configure this policy, the apps listed in the allow list could be opened in sidebar even if they are listed in the block list.\n\nBy default, all apps are allowed. However, if you prohibited apps by policy, you can use the list of allowed apps to change that policy.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesidebarappurlhostblocklist","displayName":"Control which apps cannot be opened in Microsoft Edge sidebar","description":"Define a list of sites, based on URL patterns, that cannot be opened in sidebar.\n\nIf you don't configure this policy, a user can open any app in sidebar.\n\nIf the \"HubsSidebarEnabled\" policy is disabled, this list isn't used and no sidebar can be opened.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\n\nNote: A blocklist value of '*' means all apps are blocked unless they are explicitly listed in the \"EdgeSidebarAppUrlHostAllowList\" policy.\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the sidebar.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\n\nIf you don't configure this policy, no app is forced to be shown in sidebar.\n\nIf the \"HubsSidebarEnabled\" policy is disabled, this list isn't used, and no sidebar can be shown.\n\nFor detailed information about valid URL, see https://go.microsoft.com/fwlink/?linkid=2281313.\n\nNote: URL patterns aren't supported in this policy. You should provide the exact URL of the app.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled","displayName":"Enable Wallet Checkout feature","description":"Enables Wallet Checkout feature in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can choose whether to use wallet checkout while shopping on Microsoft Edge.\n\nIf you disable this policy, users can't use wallet checkout while shopping on Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_recommended","displayName":"Enable Wallet Checkout feature (users can override)","description":"Enables Wallet Checkout feature in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can choose whether to use wallet checkout while shopping on Microsoft Edge.\n\nIf you disable this policy, users can't use wallet checkout while shopping on Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled","displayName":"Edge Wallet E-Tree Enabled (Deprecated)","description":"This policy is deprecated because the E-Tree feature has been removed from Microsoft Edge.\n\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\n\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_recommended","displayName":"Edge Wallet E-Tree Enabled (Deprecated) (users can override)","description":"This policy is deprecated because the E-Tree feature has been removed from Microsoft Edge.\n\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\n\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeworkspacesenabled","displayName":"Enable Workspaces","description":"Microsoft Edge Workspaces helps improve productivity for users in your organization.\n\nIf you enable or don't configure this policy, users can access the Microsoft Edge Workspaces feature.\nIf you disable this policy, users won't be able to access the Microsoft Edge Workspaces feature.\n\nTo learn more about the feature, see https://go.microsoft.com/fwlink/?linkid=2209950","helpText":null,"infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeworkspacesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeworkspacesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.editfavoritesenabled","displayName":"Allows users to edit favorites","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\n\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.editfavoritesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.editfavoritesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.editprofileenabled","displayName":"Enable editing profile in settings","description":"This policy controls whether users can modify profile properties (such as profile avatar) from the profile settings page.\n\nIf you enable or don't configure this policy, users can edit profile properties. The edit button is available on the profile settings page.\n\nIf you disable this policy, users can't edit profile properties. The edit button is disabled on the profile settings page.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.editprofileenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.editprofileenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enabledeprecatedwebplatformfeatures","displayName":"Re-enable deprecated web platform features for a limited time (Obsolete)","description":"This policy is obsolete because dedicated web platform policies are now used to manage individual web platform feature deprecations.\n\nSpecify a list of deprecated web platform features to temporarily re-enable.\n\nThis policy lets you re-enable deprecated web platform features for a limited time. Features are identified by a string tag.\n\nIf you don't configure this policy, if the list is empty, or if a feature doesn't match one of the supported string tags, all deprecated web platform features remain disabled.\n\nWhile the policy itself is supported on the above platforms, the feature it's enabling might not be available on all of those platforms. Not all deprecated Web Platform features can be re-enabled. Only the following explicitly listed features can be re-enabled, and only for a limited period of time, which differs per feature. You can review the intent behind the Web Platform feature changes at https://bit.ly/blinkintents.\n\nThe general format of the string tag is [DeprecatedFeatureName]_EffectiveUntil[yyyymmdd].\n\nPolicy options mapping:\n\n* ExampleDeprecatedFeature (ExampleDeprecatedFeature_EffectiveUntil20080902) = Enable ExampleDeprecatedFeature API through 2008/09/02\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":{"id":"com.microsoft.edge.mamedgeappconfigsettings.enabledeprecatedwebplatformfeatures_exampledeprecatedfeature","displayName":"Enable ExampleDeprecatedFeature API through 2008/09/02","description":null,"helpText":null}},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enablemediarouter","displayName":"Enable Google Cast","description":"Enable this policy to enable Google Cast. Users can launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.\n\nDisable this policy to disable Google Cast.\n\nBy default, Google Cast is enabled.","helpText":null,"infoUrls":[],"categoryId":"fddc444c-3591-4a50-865b-d8993b798e12","categoryName":"Cast","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enablemediarouter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enablemediarouter_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge","description":"This policy lets you enhance the security state in Microsoft Edge.\n\nIf you set this policy to 'StandardMode', the enhanced mode is turned off, and Microsoft Edge falls back to its standard security mode.\n\nIf you set this policy to 'BalancedMode', the security state is in balanced mode.\n\nIf you set this policy to 'StrictMode', the security state is in strict mode.\n\nIf you set this policy to 'BasicMode', the security state is in basic mode.\n\nNote: Sites that use WebAssembly (WASM) aren't supported on 32-bit systems when \"EnhanceSecurityMode\" is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\n\nStarting from Microsoft Edge version 113, 'BasicMode' is deprecated and is treated the same as 'BalancedMode'. It doesn't work in Microsoft Edge version 116.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.\n\nPolicy options mapping:\n\n* StandardMode (0) = Standard mode\n\n* BalancedMode (1) = Balanced mode\n\n* StrictMode (2) = Strict mode\n\n* BasicMode (3) = (Deprecated) Basic mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_standardmode","displayName":"Standard mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_balancedmode","displayName":"Balanced mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_strictmode","displayName":"Strict mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_basicmode","displayName":"(Deprecated) Basic mode","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeallowuserbypass","displayName":"Allow users to bypass Enhanced Security Mode","description":"Microsoft Edge lets users bypass Enhanced Security Mode on a site via Settings page or PageInfo flyout. This policy lets you configure whether users can bypass Enhanced Security Mode.\n\nIf you disable this policy, Microsoft Edge can't allow users to bypass Enhanced Security Mode.\n\nIf you enable or don't configure this policy, Microsoft Edge allows users to bypass Enhanced Security Mode.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeallowuserbypass_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeallowuserbypass_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypassintranet","displayName":"Enhanced Security Mode configuration for Intranet zone sites","description":"Microsoft Edge applies Enhanced Security Mode on Intranet zone sites by default. This can lead to Intranet zone sites acting in an unexpected manner.\n\nIf you enable this policy, Microsoft Edge can't apply Enhanced Security Mode on Intranet zone sites.\n\nIf you disable or don't configure this policy, Microsoft Edge applies Enhanced Security Mode on Intranet zone sites.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypassintranet_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypassintranet_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypasslistdomains","displayName":"Configure the list of domains for which enhance security mode will not be enforced","description":"Configures the list of enhance security trusted domains. This means that enhance security mode isn't enforced when loading the sites in trusted domains.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeenforcelistdomains","displayName":"Configure the list of domains for which enhance security mode will always be enforced","description":"Configure the list of enhance security untrusted domains. This means that\nenhance security mode is always enforced when loading the sites in untrusted domains.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeindicatoruienabled","displayName":"Manage the indicator UI of the Enhanced Security Mode (ESM) feature in Microsoft Edge","description":"This policy manages whether the indicator User Interface (UI) for enhanced security mode is shown or not when ESM is on.\n\nIf you enable or don't configure this policy, the indicator UI is on.\n\nIf you disable this policy, the indicator UI is off.\n\nNote: If this policy is used, only the indicator User Interface experience is supressed - ESM is still turned on. For more information, see the \"EnhanceSecurityMode\" policy.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeindicatoruienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeindicatoruienabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeoptoutuxenabled","displayName":"Manage opt-out user experience for Enhanced Security Mode (ESM) in Microsoft Edge (Obsolete)","description":"This policy is obsolete because we determined that this experimental opt-out UX isn't required.\n\nThis policy lets you manage whether the opt-out user experience for enhanced security mode is presented when ESM is turned on for Microsoft Edge.\n\nIf you enable or don't configure this policy, the UI for the opt-out user experience is on.\n\nIf you disable this policy, the UI for the opt-out user experience is off.\n\nNote: If this policy is used, only the User Interface for the opt-out experience is supressed - ESM is still turned on. For more information, see the \"EnhanceSecurityMode\" policy.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeoptoutuxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeoptoutuxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisehardwareplatformapienabled","displayName":"Allow managed extensions to use the Enterprise Hardware Platform API","description":"When this policy is set to enabled, extensions installed by enterprise policy are allowed to use the Enterprise Hardware Platform API.\nWhen this policy is set to disabled or isn't set, no extensions are allowed to use the Enterprise Hardware Platform API.\nThis policy also applies to component extensions.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisehardwareplatformapienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisehardwareplatformapienabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisemodesitelistmanagerallowed","displayName":"Allow access to the Enterprise Mode Site List Manager tool","description":"Allows you to set whether Enterprise Mode Site List Manager is available to users.\n\nIf you enable this policy, users can see the Enterprise Mode Site List Manager nav button on edge://compat page, navigate to the tool, and use it.\n\nIf you disable or don't configure this policy, users can't see the Enterprise Mode Site List Manager nav button and can't use it.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisemodesitelistmanagerallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisemodesitelistmanagerallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.eventpathenabled","displayName":"Re-enable the Event.path API until Microsoft Edge version 115 (Obsolete)","description":"Starting in Microsoft Edge version 109, the nonstandard API Event.path is removed to improve web compatibility. This policy re-enables the API until version 115.\n\nIf you enable this policy, the Event.path API is available.\n\nIf you disable this policy, the Event.path API is unavailable.\n\nIf you don't configure this policy, the Event.path API is in the following default states: available before version 109, and unavailable in version 109 to version 114.\n\nThis policy is made obsolete after Microsoft Edge version 115.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.eventpathenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.eventpathenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (Obsolete)","description":"This policy is obsoleted in favor of \"ExemptFileTypeDownloadWarnings\" because of a type mismatch that caused errors in Mac.\n\nYou can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that are exempted from file type extension-based download warnings. This exemption lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users don't see a warning when downloading \"jnlp\" files from \"website1.com\" but see a download warning when downloading \"jnlp\" files from \"website2.com\".\n\nFiles with file type extensions specified for domains identified by this policy are still subject to nonfile type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\n\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings show warnings to the user.\n\nIf you enable this policy:\n\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n* The file type extension entered must be in lower-cased ASCII. The leading separator shouldn't be included when listing the file type extension; so, list \"jnlp\" should be used instead of \".jnlp\".\n\nExample:\n\nThe following example value prevents file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It shows the user a file type extension-based download warning on any other domain for exe and jnlp files but not for swf files.\n\n[\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\n]\n\nWhile the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension isn't recommended due to security concerns. It's shown in the example merely to demonstrate the ability to do so.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.exemptfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that are exempted from file type extension-based download warnings. This exemption lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users can't see a warning when downloading \"jnlp\" files from \"website1.com\" but can see a download warning when downloading \"jnlp\" files from \"website2.com\".\n\nFiles with file type extensions specified for domains identified by this policy are still subject to nonfile type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\n\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings show warnings to the user.\n\nIf you enable this policy:\n\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n* The file type extension entered must be in lower-cased ASCII. The leading separator shouldn't be included when listing the file type extension; so, list \"jnlp\" should be used instead of \".jnlp\".\n\nExample:\n\nThe following example value prevents file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It shows the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\n\n[\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\n]\n\nWhile the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension isn't recommended due to security concerns. It's shown in the example merely to demonstrate the ability to do so.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.exemptsmartscreendownloadwarnings","displayName":"Disable SmartScreen AppRep based warnings for specified file types on specified domains","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that are exempted from SmartScreen AppRep warnings. For example, if the `vbe` extension is associated with \"contoso.com,\" users can't see a SmartScreen AppRep warning when downloading `vbe` files from \"contoso.com.\" They can, however, see a download warning when downloading `vbe` files from \"fabrikam.com.\"\n\nFiles with file type extensions specified for domains identified by this policy are still subject to file type extension-based security warnings and mixed-content download warnings.\n\nIf you disable this policy or don't configure it, files that trigger SmartScreen AppRep download warnings show warnings to the user.\n\nIf you enable this policy:\n\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n* The file type extension entered must be in lower-cased ASCII. The leading separator shouldn't be included when listing the file type extension; so, `vbe` should be used instead of `.vbe`.\n\nExample:\n\nThe following example prevents SmartScreen AppRep warnings on msi, exe, and vbe extensions for *.contoso.com domains. It might show the user a SmartScreen AppRep warning on any other domain for exe and msi files but not for vbe files.\n\n[\n { \"file_extension\": \"msi\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"vbe\", \"domains\": [\"*\"] }\n]\n\nNote: While the preceding example shows the suppression of SmartScreen AppRep download warnings for `vbe` files for all domains, applying suppression of such warnings for all domains isn't recommended due to security concerns. The ability to suppress warnings for all domains is shown in the example merely to demonstrate the ability to do so.","helpText":null,"infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes","displayName":"Configure allowed extension types","description":"Setting the policy controls which apps and extensions can be installed in Microsoft Edge, which hosts they can interact with, and limits runtime access.\n\nIf you don't set this policy, there aren't any restrictions on acceptable extension and app types.\n\nExtensions and apps, which have a type that's not on the list can't be installed. Each value should be one of these strings:\n\n* \"extension\"\n\n* \"theme\"\n\n* \"user_script\"\n\n* \"hosted_app\"\n\nSee the Microsoft Edge extensions documentation for more information about these types.\n\nNote: This policy also affects extensions and apps to be force-installed using \"ExtensionInstallForcelist\".\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.\n\nPolicy options mapping:\n\n* extension (extension) = Extension\n\n* theme (theme) = Theme\n\n* user_script (user_script) = User script\n\n* hosted_app (hosted_app) = Hosted app\n\n* legacy_packaged_app (legacy_packaged_app) = Legacy packaged app\n\n* platform_app (platform_app) = Platform app\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes_extension","displayName":"Extension","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes_theme","displayName":"Theme","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes_user_script","displayName":"User script","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes_hosted_app","displayName":"Hosted app","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes_legacy_packaged_app","displayName":"Legacy packaged app","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionallowedtypes_platform_app","displayName":"Platform app","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page","description":"Control if users can turn on Developer Mode on edge://extensions.\n\nIf the policy isn't set, users can turn on developer mode on the extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\nIf the policy is set to Allow (0), users can turn on developer mode on the extensions page.\nIf the policy is set to Disallow (1), users can't turn on developer mode on the extensions page.\n\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.\n\nPolicy options mapping:\n\n* Allow (0) = Allow the usage of developer mode on extensions page\n\n* Disallow (1) = Do not allow the usage of developer mode on extensions page\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensiondevelopermodesettings_allow","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensiondevelopermodesettings_disallow","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant an extended background lifetime to connecting extensions.","description":"Extensions that connect to one of these origins keep running as long as the port is connected.\nIf unset, the policy's default values are used. These are the app origins that offer software development kits (SDKs) that are known to not offer the possibility of restarting a closed connection to a previous state:\n- Smart Card Connector\n- Citrix Receiver (stable, beta, back-up)\n- VMware Horizon (stable, beta)\n\nIf set, the default value list is extended with the newly configured values. The defaults and policy-provided entries grant the exception to the connecting extensions as long as the port is connected.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallallowlist","displayName":"Allow specific extensions to be installed","description":"Setting this policy specifies which extensions aren't subject to the blocklist.\n\nA blocklist value of * means all extensions are blocked and users can only install extensions listed in the allow list.\n\nBy default, all extensions are allowed. However, if you prohibited extensions by policy, you can use the list of allowed extensions to change that policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallblocklist","displayName":"Control which extensions cannot be installed","description":"Lets you specify which extensions the users CANNOT install. Extensions already installed will be disabled if blocked, without a way for the user to enable them. After a disabled extension is removed from the blocklist it will automatically get re-enabled.\n\nA blocklist value of '*' means all extensions are blocked unless they are explicitly listed in the allowlist.\n\nIf this policy isn't set, the user can install any extension in Microsoft Edge.\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallforcelist","displayName":"Control which extensions are installed silently","description":"Set this policy to specify a list of apps and extensions that install silently, without user interaction. Users can't uninstall or turn off this setting. Permissions are granted implicitly, including the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. Note: These two APIs aren't available to apps and extensions that aren't force-installed.\n\nIf you don't set this policy, no apps or extensions are autoinstalled and users can uninstall any app in Microsoft Edge.\n\nThis policy supersedes \"ExtensionInstallBlocklist\" policy. If a previously force-installed app or extension is removed from this list, Microsoft Edge automatically uninstalls it.\n\nFor Windows instances not joined to a Microsoft Active Directory domain, forced installation is limited to apps and extensions listed in the Microsoft Edge Add-ons website.\n\nOn macOS instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be force installed if the instance is managed via MDM, or joined to a domain via MCX.\n\nThe source code of any extension can be altered by users with developer tools, potentially rendering the extension unfunctional. If there's a concern, configure the \"DeveloperToolsAvailability\" policy.\n\nEach list item of the policy is a string that contains an extension ID and, optionally, and an optional \"update\" URL separated by a semicolon (;). The extension ID is the 32-letter string found, for example, on edge://extensions when in Developer mode. If specified, the \"update\" URL should point to an Update Manifest XML document ( https://go.microsoft.com/fwlink/?linkid=2095043 ). The update URL should use one of the following schemes: http, https, or file. By default, the Microsoft Edge Add-ons website's update URL is used. The \"update\" URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL in the extension's manifest. The update url for subsequent updates can be overridden using the ExtensionSettings policy. See https://learn.microsoft.com/deployedge/microsoft-edge-manage-extensions-ref-guide.\n\nNote: This policy doesn't apply to InPrivate mode. Read about hosting extensions at [Publish and update extensions in the Microsoft Edge Add-ons website](/microsoft-edge/extensions-chromium/enterprise/hosting-and-updating).\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallsources","displayName":"Configure extension and user script install sources","description":"Define URLs that can install extensions and themes.\n\nDefine URLs that can install extensions and themes directly without having to drag and drop the packages to the edge://extensions page.\n\nEach item in this list is an extension-style match pattern (see https://go.microsoft.com/fwlink/?linkid=2095039). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (in other words, the referrer) must be allowed by these patterns. Don't host the files at a location that requires authentication.\n\nThe \"ExtensionInstallBlocklist\" policy takes precedence over this policy. Any extensions that's on the blocklist won't be installed, even if it comes from a site on this list.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstalltypeblocklist","displayName":"Blocklist for extension install types","description":"The blocklist controls which extension install types are disallowed.\n\nSetting the \"command_line\" will block an extension from being loaded from command line.\n\nPolicy options mapping:\n\n* command_line (command_line) = Blocks extensions from being loaded from command line\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstalltypeblocklist_command_line","displayName":"Blocks extensions from being loaded from command line","description":null,"helpText":null}},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability","description":"Control if Manifest v2 extensions can be used by browser.\n\nManifest v2 extensions support will be deprecated and all extensions need to be migrated to v3 in the future. More information about and the timeline of the migration hasn't been established.\n\nIf the policy is set to Default or not set, v2 extension loading is decided by browser. This follows the preceding timeline when it's established.\n\nIf the policy is set to Disable, v2 extensions installation are blocked, and existing ones are disabled. This option is going to be treated the same as if the policy is unset after v2 support is turned off by default.\n\nIf the policy is set to Enable, v2 extensions are allowed. The option is going to be treated the same as if the policy isn't set before v2 support is turned off by default.\n\nIf the policy is set to EnableForForcedExtensions, force installed v2 extensions are allowed. This includes extensions that are listed by \"ExtensionInstallForcelist\" or \"ExtensionSettings\" with installation_mode \"force_installed\" or \"normal_installed\". All other v2 extensions are disabled. The option is always available regardless of the manifest migration state.\n\nExtensions availabilities are still controlled by other policies.\n\nPolicy options mapping:\n\n* Default (0) = Default browser behavior\n\n* Disable (1) = Manifest v2 is disabled\n\n* Enable (2) = Manifest v2 is enabled\n\n* EnableForForcedExtensions (3) = Manifest v2 is enabled for forced extensions only\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_default","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_disable","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_enable","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_enableforforcedextensions","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsettings","displayName":"Configure extension management settings","description":"Setting this policy controls extension management settings for Microsoft Edge, including those configured by other extension-related policies. This policy supersedes any legacy policies.\n\nThis policy maps an extension ID or update URL to a specific configuration. You can define a default configuration using the special ID \"*\", which applies to extensions without a custom configuration.\n\nNote that any per-ID extension setting from either \"ExtensionInstallForcelist\", \"ExtensionInstallAllowlist\", \"ExtensionInstallBlocklist\", or \"ExtensionSettings\" will only inherit 'installation_mode' and 'update_url' from the \"*\" defaults. It will not inherit any other properties. With an update URL, configuration applies to extensions with the exact update URL stated in the extension manifest. If the 'override_update_url' flag is set to true, the extension is installed and updated using the update URL specified in the \"ExtensionInstallForcelist\" policy or in 'update_url' field in this policy. The flag 'override_update_url' is ignored if the 'update_url' is the Edge Add-ons website update URL. For more details, check out the detailed guide to ExtensionSettings policy available at https://go.microsoft.com/fwlink/?linkid=2161555.\n\nTo block extensions from a particular third party store, you only need to block the update_url for that store. For example, if you want to block extensions from Chrome Web Store, you can use the following JSON.\n\n{\"update_url:https://clients2.google.com/service/update2/crx\":{\"installation_mode\":\"blocked\"}}\n\nNote that you can still use \"ExtensionInstallForcelist\" and \"ExtensionInstallAllowlist\" to allow / force install specific extensions even if the store is blocked using the JSON in the previous example.\n\nIf the 'sidebar_auto_open_blocked' flag is set to true in an extension's configuration, the hub-app (sidebar app) corresponding to the specified extension will be prevented from automatically opening.\n\nOn Windows instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be forced installed if the instance is joined to a Microsoft Active Directory domain or joined to Microsoft Azure Active Directory®.\n\nOn macOS instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be force installed if the instance is managed via MDM, joined to a domain via MCX.\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsperformancedetectorenabled","displayName":"Extensions Performance Detector enabled","description":"This policy controls if users can access the Extensions Performance Detector Recommended Action feature in Browser Essentials. This feature alerts extension users if their extensions are causing performance regressions in the browser and allows them to take action to resolve the issue.\n\nIf you enable or don't configure this policy, users receive Extensions Performance Detector notifications from Browser Essentials. When there's an active alert, users are able to view the impact of extensions on their browser's performance and make an informed decision to disable impacting extensions. The detector will exclude browser-managed extensions, such as Google Docs offline, component extensions, and organization-managed extensions (that is, extensions that can't be disabled).\n\nIf you disable this policy, users won't receive notifications or be able to view the Extensions Performance Detector Recommended Action.","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsperformancedetectorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsperformancedetectorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsperformancedetectorenabled_recommended","displayName":"Extensions Performance Detector enabled (users can override)","description":"This policy controls if users can access the Extensions Performance Detector Recommended Action feature in Browser Essentials. This feature alerts extension users if their extensions are causing performance regressions in the browser and allows them to take action to resolve the issue.\n\nIf you enable or don't configure this policy, users receive Extensions Performance Detector notifications from Browser Essentials. When there's an active alert, users are able to view the impact of extensions on their browser's performance and make an informed decision to disable impacting extensions. The detector will exclude browser-managed extensions, such as Google Docs offline, component extensions, and organization-managed extensions (that is, extensions that can't be disabled).\n\nIf you disable this policy, users won't receive notifications or be able to view the Extensions Performance Detector Recommended Action.","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsperformancedetectorenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsperformancedetectorenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.externalprotocoldialogshowalwaysopencheckbox","displayName":"Show an \"Always open\" checkbox in external protocol dialog","description":"This policy controls whether the \"Always allow this site to open links of this type\" checkbox is shown on external protocol launch confirmation prompts. This policy only applies to https:// links.\n\nIf you enable this policy, when an external protocol confirmation prompt is shown, the user can select \"Always allow\" to skip all future confirmation prompts for the protocol on this site.\n\nIf you disable this policy, the \"Always allow\" checkbox isn't displayed. The user is prompted for confirmation every time an external protocol is invoked.\n\nPrior to Microsoft Edge 83, if you don't configure this policy, the \"Always allow\" checkbox isn't displayed. The user is prompted for confirmation every time an external protocol is invoked.\n\nOn Microsoft Edge 83, if you don't configure this policy, the checkbox visibility is controlled by the \"Enable remembering protocol launch prompting preferences\" flag in edge://flags\n\nAs of Microsoft Edge 84, if you don't configure this policy, when an external protocol confirmation prompt is shown, the user can select \"Always allow\" to skip all future confirmation prompts for the protocol on this site.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.externalprotocoldialogshowalwaysopencheckbox_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.externalprotocoldialogshowalwaysopencheckbox_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.familysafetysettingsenabled","displayName":"Allow users to configure Family safety and Kids Mode","description":"This policy disables two family safety-related features in the browser. This hides the Family page inside Settings, and navigation to edge://settings/family is blocked. The family settings page describes what features are available with family groups with Microsoft Family Safety. Learn more about Family Safety here: (https://go.microsoft.com/fwlink/?linkid=2098432). Starting in Microsoft Edge version 90, this policy also disables Kids Mode, a kid-friendly browsing mode with custom themes and allow list browsing that requires the device password to exit. Learn more about Kids Mode here: (https://go.microsoft.com/fwlink/?linkid=2146910)\n\nIf you enable this policy or don't configure it, the family page in Settings is shown and Kids Mode is available.\n\nIf you disable this policy, the family page isn't shown, and Kids Mode is hidden.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.familysafetysettingsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.familysafetysettingsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled","displayName":"Enable favorites bar","description":"Enables or disables the favorites bar.\n\nIf you enable this policy, users will see the favorites bar.\n\nIf you disable this policy, users won't see the favorites bar.\n\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_recommended","displayName":"Enable favorites bar (users can override)","description":"Enables or disables the favorites bar.\n\nIf you enable this policy, users will see the favorites bar.\n\nIf you disable this policy, users won't see the favorites bar.\n\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on shutdown","description":"Controls the duration (in seconds) that keepalive requests are allowed to prevent the browser from completing its shutdown.\n\nIf you configure this policy, the browser blocks completing shutdown while it processes any outstanding keepalive requests (see https://fetch.spec.whatwg.org/#request-keepalive-flag) up to the maximum period of time specified by this policy.\n\nIf you disable or don't configure this policy, the default value of 0 seconds is used, and the outstanding keepalive requests are immediately cancelled during browser shutdown.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.fileordirectorypickerwithoutgestureallowedfororigins","displayName":"Allow file or directory picker APIs to be called without prior user gesture","description":"For security reasons, the showOpenFilePicker(), showSaveFilePicker(), and showDirectoryPicker() web APIs require a prior user gesture (\"transient activation\") to be called; else, they fail.\n\nIf you enable this policy, admins can specify origins on which these APIs can be called without prior user gesture.\n\nFor detailed information on valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.\n\nIf you disable or don't configure this policy, all origins will require a prior user gesture to call these APIs.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.filesystemreadaskforurls","displayName":"Allow read access via the File System API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\n\nLeaving the policy unset means \"DefaultFileSystemReadGuardSetting\" applies for all sites, if set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemReadBlockedForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.filesystemreadblockedforurls","displayName":"Block read access via the File System API on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\n\nIf you don't set this policy, \"DefaultFileSystemReadGuardSetting\" applies for all sites, if set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemReadAskForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.filesystemwriteaskforurls","displayName":"Allow write access to files and directories on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system.\n\nIf you don't set this policy, \"DefaultFileSystemWriteGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemWriteBlockedForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.filesystemwriteblockedforurls","displayName":"Block write access to files and directories on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system.\n\nIf you don't set this policy, \"DefaultFileSystemWriteGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemWriteAskForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcebingsafesearch","displayName":"Enforce Bing SafeSearch","description":"Ensure that queries in Bing web search are done with SafeSearch set to the value specified. Users can't change this setting.\n\nIf you configure this policy to 'BingSafeSearchNoRestrictionsMode', SafeSearch in Bing search falls back to the bing.com value.\n\nIf you configure this policy to 'BingSafeSearchModerateMode', the moderate setting is used in SafeSearch. The moderate setting filters adult videos and images but not text from search results.\n\nIf you configure this policy to 'BingSafeSearchStrictMode', the strict setting in SafeSearch is used. The strict setting filters adult text, images, and videos.\n\nIf you disable this policy or don't configure it, SafeSearch in Bing search isn't enforced, and users can set the value they want on bing.com.\n\nPolicy options mapping:\n\n* BingSafeSearchNoRestrictionsMode (0) = Don't configure search restrictions in Bing\n\n* BingSafeSearchModerateMode (1) = Configure moderate search restrictions in Bing\n\n* BingSafeSearchStrictMode (2) = Configure strict search restrictions in Bing\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcebingsafesearch_bingsafesearchnorestrictionsmode","displayName":"Don't configure search restrictions in Bing","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcebingsafesearch_bingsafesearchmoderatemode","displayName":"Configure moderate search restrictions in Bing","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcebingsafesearch_bingsafesearchstrictmode","displayName":"Configure strict search restrictions in Bing","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceephemeralprofiles","displayName":"Enable use of ephemeral profiles","description":"Controls whether user profiles are switched to ephemeral mode. An ephemeral profile is created when a session begins, is deleted when the session ends, and is associated with the user's original profile.\n\nIf you enable this policy, profiles run in ephemeral mode. This setting lets users work from their own devices without saving browsing data to those devices. If you enable this policy as an OS policy (by using GPO on Windows, for example), it applies to every profile on the system.\n\nIf you disable this policy or don't configure it, users get their regular profiles when they sign in to the browser.\n\nIn ephemeral mode, profile data is saved on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies, and web databases aren't saved after the browser is closed. This setting doesn't prevent a user from manually downloading any data to disk, or from saving pages or printing them. If the user enabled sync, all data is preserved in their sync accounts just like with regular profiles. Users can also use InPrivate browsing in ephemeral mode unless you explicitly disable this setting.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceephemeralprofiles_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceephemeralprofiles_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceforegroundpriorityforurls","displayName":"Force foreground priority for specific URLs","description":"This policy allows you to specify a list of URL patterns for which background web content is forced to run at foreground priority.\n\nIf the ForceForegroundPriorityForAllTabs policy is enabled, this policy is ignored because all tabs are already forced to run at foreground priority.\n\nIf the ForceForegroundPriorityForAllTabs policy is disabled or not configured, only background content that matches the URL patterns in this list is forced to run at foreground priority.\n\nFor more information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nIf you don’t configure this policy or the list is empty, no background content is forced to run at foreground priority.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcegooglesafesearch","displayName":"Enforce Google SafeSearch","description":"Forces queries in Google Web Search to be performed with SafeSearch set to active, and prevents users from changing this setting.\n\nIf you enable this policy, SafeSearch in Google Search is always active.\n\nIf you disable this policy or don't configure it, SafeSearch in Google Search isn't enforced.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcegooglesafesearch_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcegooglesafesearch_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcemajorversiontominorpositioninuseragent","displayName":"Enable or disable freezing the User-Agent string at major version 99 (Obsolete)","description":"This policy was removed in Microsoft Edge 118 and is ignored if configured.\n\nThis policy controls whether the User-Agent string major\nversion should be frozen at 99.\n\nThe User-Agent request header lets websites identify the application,\noperating system, vendor, and/or version of the requesting user agent.\nSome websites make assumptions about how this header is formatted and may\nencounter issues with version strings that include three digits in the\nmajor position (for example, 100.0.0.0).\n\nIf you set this policy to 'Default' or don't configure it, then it defaults to\nbrowser settings for the User-Agent string major version.\nIf you set this policy to 'ForceEnabled', the User-Agent string will always report the\nmajor version as 99 and include the browser's major version in the minor\nposition. For example, browser version 101.0.0.0 would send a User-Agent\nrequest header that reports version 99.101.0.0.\nIf you set this policy to 'ForceDisabled', the User-Agent string won't freeze the\nmajor version.\n\nThis policy is temporary and will be deprecated in the future. If this policy and\nUser-Agent Reduction are\nboth enabled, the User-Agent version string will always be 99.0.0.0.\n\nPolicy options mapping:\n\n* Default (0) = Default to browser settings for User-Agent string version.\n\n* ForceDisabled (1) = The User-Agent string won't freeze the major version.\n\n* ForceEnabled (2) = The User-Agent string will freeze the major version as 99 and include the browser's major version in the minor position.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcemajorversiontominorpositioninuseragent_default","displayName":"Default to browser settings for User-Agent string version.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcemajorversiontominorpositioninuseragent_forcedisabled","displayName":"The User-Agent string won't freeze the major version.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcemajorversiontominorpositioninuseragent_forceenabled","displayName":"The User-Agent string will freeze the major version as 99 and include the browser's major version in the minor position.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcesync","displayName":"Force synchronization of browser data and do not show the sync consent prompt","description":"Forces data synchronization in Microsoft Edge. This policy also prevents the user from turning off sync.\n\nIf you don't configure this policy, users can turn on or turn off sync. If you enable this policy, users can't turn off sync.\n\nFor this policy to work as intended,\n\"BrowserSignin\" policy must not be configured, or must be set to enabled. If \"BrowserSignin\" is set to disabled, then \"ForceSync\" doesn't take affect.\n\n\"SyncDisabled\" must not be configured or must be set to False. If this policy is set to True, \"ForceSync\" doesn't take affect. If you wish to ensure specific datatypes sync or don't sync, use the \"ForceSyncTypes\" policy and \"SyncTypesListDisabled\" policy, respectively.\n\n0 = Do not automatically start sync and show the sync consent (default)\n1 = Force sync to turn on for Azure AD/Azure AD-Degraded user profile and do not show the sync consent prompt","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcesync_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcesync_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcesynctypes","displayName":"Configure the list of types that are included for synchronization","description":"If you enable this policy, all the specified data types are included for synchronization for Azure AD/Azure AD-Degraded user profiles. This policy can be used to ensure the type of data uploaded to the Microsoft Edge synchronization service.\n\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", \"history\", \"openTabs\", \"edgeWallet\", \"collections\", \"apps\", and \"edgeFeatureUsage\". The \"edgeFeatureUsage\" data type is supported starting in Microsoft Edge version 134. Note that these data type names are case sensitive.\n\nUsers can't override the enabled data types.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode","description":"Enforces a minimum Restricted Mode on YouTube and prevents users from picking a less restricted mode.\n\nSet to 'Strict' to enforce Strict Restricted Mode on YouTube.\n\nSet to 'Moderate' to enforce the user to only use Moderate Restricted Mode and Strict Restricted Mode on YouTube. They can't disable Restricted Mode.\n\nSet to 'Off' or don't configure this policy to not enforce Restricted Mode on YouTube. External policies such as YouTube policies might still enforce Restricted Mode.\n\nPolicy options mapping:\n\n* Off (0) = Do not enforce Restricted Mode on YouTube\n\n* Moderate (1) = Enforce at least Moderate Restricted Mode on YouTube\n\n* Strict (2) = Enforce Strict Restricted Mode for YouTube\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceyoutuberestrict_off","displayName":"Do not enforce Restricted Mode on YouTube","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceyoutuberestrict_moderate","displayName":"Enforce at least Moderate Restricted Mode on YouTube","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forceyoutuberestrict_strict","displayName":"Enforce Strict Restricted Mode for YouTube","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.fullscreenallowed","displayName":"Allow full screen mode","description":"Set the availability of full screen mode - all Microsoft Edge UI is hidden and only web content is visible.\n\nIf you enable this policy or don't configure it, the user, apps, and extensions with appropriate permissions can enter full screen mode.\n\nIf you disable this policy, users, apps, and extensions can't enter full screen mode.\n\nOpening Microsoft Edge in kiosk mode using the command line is unavailable when full screen mode is disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.fullscreenallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.fullscreenallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled","displayName":"Enable Gamer Mode (Obsolete)","description":"Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more.\n\nIf you enable or don't configure this policy, users can opt into Gamer Mode.\nIf you disable this policy, Gamer Mode is disabled.\nNote: With Microsoft Edge version 141, this policy is obsolete because the Gamer Mode feature is removed.","helpText":null,"infoUrls":[],"categoryId":"81c518f1-522e-4957-b850-e8a66d2ab215","categoryName":"Games settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_recommended","displayName":"Enable Gamer Mode (Obsolete) (users can override)","description":"Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more.\n\nIf you enable or don't configure this policy, users can opt into Gamer Mode.\nIf you disable this policy, Gamer Mode is disabled.\nNote: With Microsoft Edge version 141, this policy is obsolete because the Gamer Mode feature is removed.","helpText":null,"infoUrls":[],"categoryId":"81c518f1-522e-4957-b850-e8a66d2ab215","categoryName":"Games settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.geolocationblockedforurls","displayName":"Block geolocation on these sites","description":"Use this policy to define a list of URL patterns for sites that are blocked from accessing the user's geolocation. These sites also can't prompt the user for location permissions.\n\nIf you enable this policy, the list you provide determines which sites are blocked from requesting or accessing geolocation.\n\nIf you disable or don't configure this policy, DefaultGeolocationSetting applies to all sites, if configured. If it's not configured, the user’s personal browser setting is used.\n\nFor detailed information on valid url patterns, see the documentation on pattern formats: https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\n\nIf you disable or don't set this policy, the browser uses the default behavior of cross-site auth. This behavior is to scope HTTP server authentication credentials by top-level site. So, if two sites use resources from the same authenticating domain, credentials need to be provided independently in the context of both sites. Cached proxy credentials are reused across sites.\n\nIf you enable this policy, HTTP auth credentials entered in the context of one site is automatically used in the context of another site.\n\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\n\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures and will be removed in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.globallyscopehttpauthcacheenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.globallyscopehttpauthcacheenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.guidedswitchenabled","displayName":"Guided Switch Enabled","description":"Allows Microsoft Edge to prompt the user to switch to the appropriate profile when Microsoft Edge detects that a link is a personal or work link.\n\nIf you enable this policy, you're prompted to switch to another account if the current profile doesn't work for the requesting link.\n\nIf you disable this policy, you aren't prompted to switch to another account when there's a profile and link mismatch.\n\nIf this policy isn't configured, guided switch is turned on by default. A user can override this value in the browser settings.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.guidedswitchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.guidedswitchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepageisnewtabpage","displayName":"Set the new tab page as the home page","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\n\nIf you enable this policy, the Home button is set to the new tab page as configured by the user or with the policy \"NewTabPageLocation\" and the URL set with the policy \"HomepageLocation\" is not taken into consideration.\n\nIf you disable this policy, the Home button is the set URL as configured by the user or as configured in the policy \"HomepageLocation\".\n\nIf you don't configure this policy, users can choose whether the set URL or the new tab page is their home page.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepageisnewtabpage_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepageisnewtabpage_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepageisnewtabpage_recommended","displayName":"Set the new tab page as the home page (users can override)","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\n\nIf you enable this policy, the Home button is set to the new tab page as configured by the user or with the policy \"NewTabPageLocation\" and the URL set with the policy \"HomepageLocation\" is not taken into consideration.\n\nIf you disable this policy, the Home button is the set URL as configured by the user or as configured in the policy \"HomepageLocation\".\n\nIf you don't configure this policy, users can choose whether the set URL or the new tab page is their home page.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepageisnewtabpage_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepageisnewtabpage_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepagelocation","displayName":"Configure the home page URL","description":"Configures the default home page URL in Microsoft Edge.\n\nThe home page is the page opened by the Home button. \"RestoreOnStartup\" policies control the pages that open on startup.\n\nYou can either set a URL here or set the home page to open the new tab page 'edge://newtab'. By default, the Home button opens the new tab page (as configured by the user or with the policy \"NewTabPageLocation\"), and the user is able to choose between the URL configured by this policy and the new tab page.\n\nIf you enable this policy, users can't change their home page URL, but they can choose the behavior for the Home button to open either the set URL or the new tab page. If you wish to enforce the usage of the set URL, you must also configure \"HomepageIsNewTabPage\"=Disabled.\n\nIf you disable or don't configure this policy, users can choose their own home page, as long as the \"HomepageIsNewTabPage\" policy isn't enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepagelocation_recommended","displayName":"Configure the home page URL (users can override)","description":"Configures the default home page URL in Microsoft Edge.\n\nThe home page is the page opened by the Home button. \"RestoreOnStartup\" policies control the pages that open on startup.\n\nYou can either set a URL here or set the home page to open the new tab page 'edge://newtab'. By default, the Home button opens the new tab page (as configured by the user or with the policy \"NewTabPageLocation\"), and the user is able to choose between the URL configured by this policy and the new tab page.\n\nIf you enable this policy, users can't change their home page URL, but they can choose the behavior for the Home button to open either the set URL or the new tab page. If you wish to enforce the usage of the set URL, you must also configure \"HomepageIsNewTabPage\"=Disabled.\n\nIf you disable or don't configure this policy, users can choose their own home page, as long as the \"HomepageIsNewTabPage\" policy isn't enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.hstspolicybypasslist","displayName":"Configure the list of names that will bypass the HSTS policy check","description":"Setting the policy specifies a list of hostnames that bypass preloaded HSTS (HTTP Strict Transport Security) upgrades from http to https.\n\nOnly single-label hostnames are allowed in this policy, and this policy only applies to static HSTS-preloaded entries (for example, \"app\", \"new\", \"search\", and \"play\"). This policy doesn't prevent HSTS upgrades for servers that have dynamically requested HSTS upgrades using a Strict-Transport-Security response header.\n\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific single-label hostnames specified and not to subdomains of those names.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpallowlist","displayName":"HTTP Allowlist","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that won't be upgraded to HTTPS. Organizations can use this policy to maintain access to servers that don't support HTTPS, without needing to disable \"HttpsUpgradesEnabled\".\n\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase.\n\nBlanket host wildcards (that is, \"*\" or \"[*]\") aren't allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies.\n\nNote: This policy doesn't apply to HSTS upgrades.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled","description":"This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigation to HTTPS.\n\nIf this setting isn't set or is set to Allowed, users are able to enable HTTPS-Only Mode.\nIf this setting is set to Disallowed, HTTPS-Only Mode will be disabled.\nIf this setting is set to Force Enabled, HTTPS-Only Mode is enabled in Strict mode.\nIf this setting is set to Force Balance Enabled, HTTPS-Only Mode is enabled in Balanced mode.\n\nThe settings Force Enabled and Force Enabled can be recommended to users. HTTPS-Only Mode will be set to Strict or Balanced initially, but users are allowed to change it.\n\nIf you set this policy to a value that isn't supported by the version of Microsoft Edge that receives the policy, Microsoft Edge defaults to the Allowed setting.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nPolicy options mapping:\n\n* allowed (allowed) = Don't restrict users' HTTPS-Only Mode setting\n\n* disallowed (disallowed) = Disable HTTPS-Only Mode\n\n* force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode\n\n* force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_allowed","displayName":"Don't restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_disallowed","displayName":"Disable HTTPS-Only Mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_force_enabled","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_force_balanced_enabled","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended","displayName":"Allow HTTPS-Only Mode to be enabled (users can override)","description":"This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigation to HTTPS.\n\nIf this setting isn't set or is set to Allowed, users are able to enable HTTPS-Only Mode.\nIf this setting is set to Disallowed, HTTPS-Only Mode will be disabled.\nIf this setting is set to Force Enabled, HTTPS-Only Mode is enabled in Strict mode.\nIf this setting is set to Force Balance Enabled, HTTPS-Only Mode is enabled in Balanced mode.\n\nThe settings Force Enabled and Force Enabled can be recommended to users. HTTPS-Only Mode will be set to Strict or Balanced initially, but users are allowed to change it.\n\nIf you set this policy to a value that isn't supported by the version of Microsoft Edge that receives the policy, Microsoft Edge defaults to the Allowed setting.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nPolicy options mapping:\n\n* allowed (allowed) = Don't restrict users' HTTPS-Only Mode setting\n\n* disallowed (disallowed) = Disable HTTPS-Only Mode\n\n* force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode\n\n* force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_allowed","displayName":"Don't restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_disallowed","displayName":"Disable HTTPS-Only Mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_force_enabled","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_force_balanced_enabled","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsupgradesenabled","displayName":"Enable automatic HTTPS upgrades","description":"As of Microsoft Edge version 120, Microsoft Edge tries to upgrade HTTP navigations to HTTPS, whenever possible, to improve security. Navigations to captive portals, IP addresses, and nonunique hostnames are excluded from automatic upgrades.\n\nIf this policy is enabled or not configured, automatic HTTPS upgrades are turned on by default.\n\nIf this policy is disabled, Microsoft Edge doesn't attempt to upgrade HTTP connections to HTTPS.\n\nTo exempt specific hostnames or hostname patterns from being upgraded, use the HttpAllowlist policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsupgradesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsupgradesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.hubssidebarenabled","displayName":"Show Hubs Sidebar","description":"The Sidebar is a launcher bar located on the right side of Microsoft Edge.\n\nIf you enable this policy, the Sidebar is always visible.\n\nIf you disable this policy, the Sidebar is never shown.\n\nIf you don't configure this policy, the Sidebar's visibility follows the user's Microsoft Edge settings.\n\nAs of Microsoft Edge version 141, the \"Microsoft365CopilotChatIconEnabled\" policy is the only means of controlling the display of Copilot in the toolbar.\n\nNote: The recommended version of this policy-also known as the \"Default Settings (users can override)\" policy-is obsolete. This policy has never supported the recommended capability.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.hubssidebarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.hubssidebarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.hubssidebarenabled_recommended","displayName":"Show Hubs Sidebar (users can override)","description":"The Sidebar is a launcher bar located on the right side of Microsoft Edge.\n\nIf you enable this policy, the Sidebar is always visible.\n\nIf you disable this policy, the Sidebar is never shown.\n\nIf you don't configure this policy, the Sidebar's visibility follows the user's Microsoft Edge settings.\n\nAs of Microsoft Edge version 141, the \"Microsoft365CopilotChatIconEnabled\" policy is the only means of controlling the display of Copilot in the toolbar.\n\nNote: The recommended version of this policy-also known as the \"Default Settings (users can override)\" policy-is obsolete. This policy has never supported the recommended capability.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.hubssidebarenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.hubssidebarenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idledetectionallowedforurls","displayName":"Allow idle detection on these sites","description":"Allows you to specify a list of URL patterns for sites that are allowed to use the Idle Detection API.\n\nIf you don't configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise.\n\nOnly the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported. For detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=209532.\n\nURL patterns specified in the blocklist take precedence over this allowlist. This allowlist takes precedence over the DefaultIdleDetectionSetting policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idledetectionblockedforurls","displayName":"Block idle detection on these sites","description":"Allows you to specify a list of URL patterns for sites that are not allowed to use the Idle Detection API.\n\nOnly the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported.\n\nFor detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nIf you do not configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeout","displayName":"Delay before running idle actions","description":"Triggers an action when the computer is idle.\n\nIf you set this policy, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy.\n\nIf you don't set this policy, the browser doesn't run any action.\n\nThe minimum threshold is 1 minute.\n\n\"User input\" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.","helpText":null,"infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions","displayName":"Actions to run when the computer is idle","description":"When the timeout from the IdleTimeout policy is reached, the browser runs the actions configured in this policy.\n\nIf you don't configure the IdleTimeout policy, this policy has no effect.\n\nIf you don't configure this policy or no actions are selected, the IdleTimeout policy has no effect.\n\nSupported actions are:\n\n'close_browsers': close all browser windows and Progressive Web Apps (PWAs) for this profile.\n\n'reload_pages': reload all webpages. For some pages, the user might be prompted for confirmation first.\n\n'sign_out': sign out of browser. (This action only applies to iOS.)\n\n'close_tabs': close all open tabs and create an NTP (New Tab Page). Supported in Android and iOS.\n\n'clear_browsing_history', 'clear_download_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', 'clear_autofill', 'clear_site_settings': clear the corresponding browsing data. Deleting cookies using this policy doesn't sign the user out of their profile, the user stays signed in.\n\nSetting 'clear_browsing_history', 'clear_password_signing', 'clear_autofill', and 'clear_site_settings' disables sync for the respective data types if sync isn't already disabled by setting either the SyncDisabled policy or BrowserSignin to disabled.\n\nPolicy options mapping:\n\n* close_browsers (close_browsers) = Close Browsers\n\n* clear_browsing_history (clear_browsing_history) = Clear Browsing History\n\n* clear_download_history (clear_download_history) = Clear Download History\n\n* clear_cookies_and_other_site_data (clear_cookies_and_other_site_data) = Clear Cookies and Other Site Data\n\n* clear_cached_images_and_files (clear_cached_images_and_files) = Clear Cached Images and Files\n\n* clear_password_signin (clear_password_signin) = Clear Password sign in\n\n* clear_autofill (clear_autofill) = Clear Autofill\n\n* clear_site_settings (clear_site_settings) = Clear Site Settings\n\n* reload_pages (reload_pages) = Reload Pages\n\n* sign_out (sign_out) = Sign Out\n\n* close_tabs (close_tabs) = Close Tabs\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_close_browsers","displayName":"Close Browsers","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_browsing_history","displayName":"Clear Browsing History","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_download_history","displayName":"Clear Download History","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_cookies_and_other_site_data","displayName":"Clear Cookies and Other Site Data","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_cached_images_and_files","displayName":"Clear Cached Images and Files","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_password_signin","displayName":"Clear Password sign in","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_autofill","displayName":"Clear Autofill","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_clear_site_settings","displayName":"Clear Site Settings","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_reload_pages","displayName":"Reload Pages","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_sign_out","displayName":"Sign Out","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.idletimeoutactions_close_tabs","displayName":"Close Tabs","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.imagesallowedforurls","displayName":"Allow images on these sites","description":"Define a list of sites, based on URL patterns, that can display images.\n\nIf you don't configure this policy, the global default value is used for all sites either from the \"DefaultImagesSetting\" policy (if set) or the user's personal configuration.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.imagesblockedforurls","displayName":"Block images on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to display images.\n\nIf you don't configure this policy, the global default value from the \"DefaultImagesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.immersivereadergrammartoolsenabled","displayName":"Enable Grammar Tools feature within Immersive Reader in Microsoft Edge (Obsolete)","description":"This policy is obsoleted because Grammar Tools is deprecated from Microsoft Edge. This policy can't work in Microsoft Edge version 126. Enables the Grammar Tools feature within Immersive Reader in Microsoft Edge.\nThis helps improve reading comprehension by splitting words into syllables and highlighting nouns, verbs, adverbs, and adjectives.\n\nIf you enable this policy or don't configure it, the Grammar Tools option shows up within Immersive Reader.\nIf you disable this policy, users can't access the Grammar Tools feature within Immersive Reader.","helpText":null,"infoUrls":[],"categoryId":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","categoryName":"Immersive Reader settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.immersivereadergrammartoolsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.immersivereadergrammartoolsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.immersivereaderpicturedictionaryenabled","displayName":"Enable Picture Dictionary feature within Immersive Reader in Microsoft Edge (Obsolete)","description":"This Policy is obsoleted because Picture Dictionary is deprecated from Edge as of Sept, 2023. This policy won't work in Microsoft Edge Version 127. Enables the Picture Dictionary feature within Immersive Reader in Microsoft Edge.\nThis feature helps in reading comprehension by letting a user to click on any single word and see an illustration related to the meaning.\n\nIf you enable this policy or don't configure it, the Picture Dictionary option shows up within Immersive Reader.\nIf you disable this policy, users can't access the Picture Dictionary feature within Immersive Reader.","helpText":null,"infoUrls":[],"categoryId":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","categoryName":"Immersive Reader settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.immersivereaderpicturedictionaryenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.immersivereaderpicturedictionaryenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata","displayName":"Allow importing of autofill form data","description":"Allows users to import autofill form data from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import autofill data is automatically selected.\n\nIf you disable this policy, autofill form data isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports autofill data on first run, but users can select or clear autofill data option during manual import.\n\nNote: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS) and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_recommended","displayName":"Allow importing of autofill form data (users can override)","description":"Allows users to import autofill form data from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import autofill data is automatically selected.\n\nIf you disable this policy, autofill form data isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports autofill data on first run, but users can select or clear autofill data option during manual import.\n\nNote: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS) and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importbrowsersettings","displayName":"Allow importing of browser settings","description":"Allows users to import browser settings from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, browser settings aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This option means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\n\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importbrowsersettings_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importbrowsersettings_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importbrowsersettings_recommended","displayName":"Allow importing of browser settings (users can override)","description":"Allows users to import browser settings from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, browser settings aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This option means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\n\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importbrowsersettings_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importbrowsersettings_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies","displayName":"Allow importing of Cookies","description":"Allows users to import Cookies from another browser into Microsoft Edge.\n\nIf you disable this policy, Cookies aren't imported on first run.\n\nIf you don't configure this policy, Cookies are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\n\nNote: This policy currently manages Google Chrome import (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_recommended","displayName":"Allow importing of Cookies (users can override)","description":"Allows users to import Cookies from another browser into Microsoft Edge.\n\nIf you disable this policy, Cookies aren't imported on first run.\n\nIf you don't configure this policy, Cookies are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\n\nNote: This policy currently manages Google Chrome import (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importextensions","displayName":"Allow importing of extensions","description":"Allows users to import extensions from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importextensions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importextensions_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importextensions_recommended","displayName":"Allow importing of extensions (users can override)","description":"Allows users to import extensions from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importextensions_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importextensions_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites","displayName":"Allow importing of favorites","description":"Allows users to import favorites from another browser into Microsoft Edge.\n\nIf you enable this policy, the Favorites check box is automatically selected in the Import browser data dialog box.\n\nIf you disable this policy, favorites aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_recommended","displayName":"Allow importing of favorites (users can override)","description":"Allows users to import favorites from another browser into Microsoft Edge.\n\nIf you enable this policy, the Favorites check box is automatically selected in the Import browser data dialog box.\n\nIf you disable this policy, favorites aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory","displayName":"Allow importing of browsing history","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\n\nIf you enable this policy, the Browsing history check box is automatically selected in the Import browser data dialog box.\n\nIf you disable this policy, browsing history data isn't imported at first run, and users can't import this data manually.\n\nIf you don't configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_recommended","displayName":"Allow importing of browsing history (users can override)","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\n\nIf you enable this policy, the Browsing history check box is automatically selected in the Import browser data dialog box.\n\nIf you disable this policy, browsing history data isn't imported at first run, and users can't import this data manually.\n\nIf you don't configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhomepage","displayName":"Allow importing of home page settings","description":"Allows users to import their home page setting from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import the home page setting is automatically selected.\n\nIf you disable this policy, the home page setting isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, the home page setting is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This option means that Microsoft Edge imports the home page setting on first run, but users can select or clear the **home page** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhomepage_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhomepage_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importoneachlaunch","displayName":"Allow import of data from other browsers on each Microsoft Edge launch","description":"If you enable this policy, users will see a prompt to import their browsing data from other browsers on each Microsoft Edge launch.\n\nIf you disable this policy, users will never see a prompt to import their browsing data from other browsers on each Microsoft Edge launch.\n\nIf the policy is left unconfigured, users can activate this feature from a Microsoft Edge prompt or from the Settings page.\n\nNote: A similar policy named \"AutoImportAtFirstRun\" exists. This policy should be used if you want to import supported data from other browsers only once while setting up your device.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importoneachlaunch_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importoneachlaunch_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importopentabs","displayName":"Allow importing of open tabs","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importopentabs_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importopentabs_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importopentabs_recommended","displayName":"Allow importing of open tabs (users can override)","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importopentabs_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importopentabs_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo","displayName":"Allow importing of payment info","description":"Allows users to import payment info from another browser into Microsoft Edge.\n\nIf you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, payment info isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This option means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import.\n\n**Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_recommended","displayName":"Allow importing of payment info (users can override)","description":"Allows users to import payment info from another browser into Microsoft Edge.\n\nIf you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, payment info isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This option means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import.\n\n**Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords","displayName":"Allow importing of saved passwords","description":"Allows users to import saved passwords from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import saved passwords is automatically selected.\n\nIf you disable this policy, saved passwords aren't imported on first run, and users can't import them manually.\n\nIf you don't configure this policy, no passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_recommended","displayName":"Allow importing of saved passwords (users can override)","description":"Allows users to import saved passwords from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import saved passwords is automatically selected.\n\nIf you disable this policy, saved passwords aren't imported on first run, and users can't import them manually.\n\nIf you don't configure this policy, no passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine","displayName":"Allow importing of search engine settings","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\n\nIf you enable, this policy, the option to import search engine settings is automatically selected.\n\nIf you disable this policy, search engine settings aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This option means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_recommended","displayName":"Allow importing of search engine settings (users can override)","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\n\nIf you enable, this policy, the option to import search engine settings is automatically selected.\n\nIf you disable this policy, search engine settings aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This option means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importshortcuts","displayName":"Allow importing of shortcuts","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\n\nIf you disable this policy, Shortcuts aren't imported on first run.\n\nIf you don't configure this policy, Shortcuts are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\n\nNote: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importshortcuts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importshortcuts_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importshortcuts_recommended","displayName":"Allow importing of shortcuts (users can override)","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\n\nIf you disable this policy, Shortcuts aren't imported on first run.\n\nIf you don't configure this policy, Shortcuts are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\n\nNote: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importshortcuts_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importshortcuts_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importstartuppagesettings","displayName":"Allow importing of startup page settings","description":"Allows users to import Startup settings from another browser into Microsoft Edge.\n\nIf you enable this policy, the Startup settings are always imported.\n\nIf you disable this policy, startup settings aren't imported at first run or at manual import.\n\nIf you don't configure this policy, startup settings are imported at first run, and users can choose whether to import this data manually by selecting browser settings option during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge will import startup settings on first run, but users can select or clear **browser settings** option during manual import.\n\n**Note**: This policy currently manages importing from Microsoft Edge Legacy and Google Chrome (on Windows 7, 8, and 10) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importstartuppagesettings_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importstartuppagesettings_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importstartuppagesettings_recommended","displayName":"Allow importing of startup page settings (users can override)","description":"Allows users to import Startup settings from another browser into Microsoft Edge.\n\nIf you enable this policy, the Startup settings are always imported.\n\nIf you disable this policy, startup settings aren't imported at first run or at manual import.\n\nIf you don't configure this policy, startup settings are imported at first run, and users can choose whether to import this data manually by selecting browser settings option during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge will import startup settings on first run, but users can select or clear **browser settings** option during manual import.\n\n**Note**: This policy currently manages importing from Microsoft Edge Legacy and Google Chrome (on Windows 7, 8, and 10) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importstartuppagesettings_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importstartuppagesettings_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeavailability","displayName":"Configure InPrivate mode availability","description":"Specifies whether the user can open pages in InPrivate mode in Microsoft Edge.\n\nIf you don't configure this policy or set it to 'Enabled', users can open pages in InPrivate mode.\n\nSet this policy to 'Disabled' to stop users from using InPrivate mode.\n\nSet this policy to 'Forced' to always use InPrivate mode.\n\nThe \"InPrivateModeUrlAllowlist\" policy takes precedence over this policy and can allow specific URLs to open in InPrivate mode.\n\nIf this policy disables InPrivate mode and an allowlist is configured, InPrivate mode is permitted only for URLs that match entries in the allowlist. All other URLs are blocked from opening in InPrivate mode.\n\nPolicy options mapping:\n\n* Enabled (0) = InPrivate mode available\n\n* Disabled (1) = InPrivate mode disabled\n\n* Forced (2) = InPrivate mode forced\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeavailability_enabled","displayName":"InPrivate mode available","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeavailability_disabled","displayName":"InPrivate mode disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeavailability_forced","displayName":"InPrivate mode forced","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeurlallowlist","displayName":"Allow access to a list of URLs in InPrivate mode.","description":"This policy allows administrators to specify a list of URL patterns that are permitted to open in InPrivate mode. It can be used to create exceptions for URL patterns defined in \"InPrivateModeUrlBlocklist\". See how to format a URL pattern (https://go.microsoft.com/fwlink/?linkid=2095322).\n\nIf both this policy and \"InPrivateModeUrlBlocklist\" are configured, the allowlist takes precedence. URLs that match a pattern on this allowlist are allowed. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither list fall back to \"URLBlocklist\" and \"URLAllowlist\".\n\nIf this policy is configured and \"InPrivateModeUrlBlocklist\" is not configured, only the URLs specified in this allowlist can be opened in InPrivate mode. All other URLs are blocked.\n\nIf \"InPrivateModeAvailability\" is set to disallow (value 1) but this policy is configured, InPrivate mode is available only for URLs that match the allowlist.\n\nIf this policy is not configured, no exceptions are applied to \"InPrivateModeUrlBlocklist\" or \"InPrivateModeAvailability\".\n\nThis policy applies only to InPrivate mode. To allow URLs across all browsing modes and profiles, use the \"URLAllowlist\" policy.\n\nThis policy supports up to 1000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeurlblocklist","displayName":"Block access to a list of URLs in InPrivate mode.","description":"This policy controls which URLs are blocked from loading in InPrivate mode in Microsoft Edge.\n\nAdministrators can specify a list of URL patterns that are blocked when users browse in InPrivate mode. For information about the supported URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nIf both \"InPrivateModeUrlBlocklist\" and \"InPrivateModeUrlAllowlist\" are configured, the allowlist takes precedence.\n- URLs that match the allowlist are allowed.\n- URLs that match the blocklist but not the allowlist are blocked.\n- URLs that match neither list follow the behavior defined by the general \"URLBlocklist\" and \"URLAllowlist\" policies.\n\nIf \"InPrivateModeUrlAllowlist\" is configured and this policy is not configured, only URLs on the allowlist can be opened in InPrivate mode.\n\nIf \"InPrivateModeAvailability\" is set to disallow (value 1) and \"InPrivateModeUrlAllowlist\" is configured, InPrivate mode is available only for URLs that match the allowlist.\n\nThis policy applies only to InPrivate mode. To block URLs across all browsing modes, use \"URLBlocklist\".\n\nThis policy supports up to 1000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecurecontentallowedforurls","displayName":"Allow insecure content on specified sites","description":"Create a list of URL patterns to specify sites that can display or, as of version 94, download insecure mixed content (that is, HTTP content on HTTPS sites).\n\nIf you don't configure this policy, blockable mixed content is blocked and optionally blockable mixed content is upgraded. However, users are allowed to set exceptions to allow insecure mixed content for specific sites.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecurecontentblockedforurls","displayName":"Block insecure content on specified sites","description":"Creates a list of URL patterns to specify sites that aren't allowed to display blockable (that is, active) mixed content (that is, HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades are disabled.\n\nIf you don't configure this policy, blockable mixed content is blocked, and optionally blockable mixed content is upgraded. However, users are allowed to set exceptions to allow insecure mixed content for specific sites.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureformswarningsenabled","displayName":"Enable warnings for insecure forms (Deprecated)","description":"This policy controls the handling of insecure forms (forms submitted over HTTP) embedded in secure (HTTPS) sites in the browser.\nIf you enable this policy or don't set it, a full page warning is shown when an insecure form is submitted. Additionally, a warning bubble is shown next to the form fields when they're focused, and autofill will be disabled for those forms.\nIf you disable this policy, warnings won't be shown for insecure forms, and autofill works normally.\n\nThis policy may be removed as soon as Edge 132. The feature is enabled by default since Edge 131.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureformswarningsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureformswarningsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowed","displayName":"Specifies whether to allow websites to make requests to any network endpoint in an insecure manner. (Obsolete)","description":"Controls whether websites are allowed to make requests to more-private network endpoints.\n\nWhen this policy is enabled, all Private Network Access checks are disabled for all origins. This may allow attackers to perform cross-site request forgery (CSRF) attacks on private network servers.\n\nWhen this policy is disabled or not configured, the default behavior for requests to more-private network endpoints depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests, PrivateNetworkAccessSendPreflights, and PrivateNetworkAccessRespectPreflightResults feature flags. These flags may be controlled by experimentation or set via the command line.\n\nThis policy relates to the Private Network Access specification. See https://wicg.github.io/private-network-access/ for more details.\n\nA network endpoint is more private than another if:\n1) Its IP address is localhost and the other isn't.\n2) Its IP address is private and the other is public.\nIn the future, depending on spec evolution, this policy might apply to all cross-origin requests directed at private IPs or localhost.\n\nWhen this policy enabled, websites are allowed to make requests to any network endpoint, subject to other cross-origin checks.\n\nThis policy is obsolete. The previous blanket override has been replaced by the permission-based Local Network Access model, which blocks cross-space requests until users grant explicit consent.","helpText":null,"infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from in an insecure manner (Obsolete)","description":"List of URL patterns. Requests initiated from websites served by matching origins aren't subject to Private Network Access checks.\n\nIf this policy isn't set, this policy behaves as if set to the empty list.\n\nFor origins not covered by the patterns specified here, the global default value is used either from the \"InsecurePrivateNetworkRequestsAllowed\" policy, if it's set, or the user's personal configuration otherwise.\n\nFor detailed information on valid URL patterns, see [Filter format for URL list-based policies](/DeployEdge/edge-learnmmore-url-list-filter%20format).\n\nThis policy is obsolete. The previous blanket override has been replaced by the permission-based Local Network Access model, which blocks cross-space requests until users grant explicit consent.","helpText":null,"infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationalwaysuseoscapture","displayName":"Always use the OS capture engine to avoid issues with capturing Internet Explorer mode tabs","description":"Configure this policy to control whether Microsoft Edge will use the \"OS capture engine\" or the \"Browser capture engine\" when capturing browser windows in the same process using the screen-share APIs.\n\nYou should configure this policy if you want to capture the contents of Internet Explorer mode tabs. However, enabling this policy may negatively impact performance when capturing browser windows in the same process.\n\nThis policy only affects window capture, not tab capture. The contents of Internet Explorer mode tabs won't be captured when you choose to capture only a single tab, even if you configure this policy.\n\nIf you enable this policy, Microsoft Edge always uses the OS capture engine for window capture. Internet Explorer mode tabs will have their contents captured.\n\nIf you disable or don't configure this policy, Microsoft Edge uses the Browser capture engine for browser windows in the same process. Internet Explorer mode tabs in these windows won't have their contents captured.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2174004","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationalwaysuseoscapture_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationalwaysuseoscapture_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationalwayswaitforunload","displayName":"Wait for Internet Explorer mode tabs to completely unload before ending the browser session","description":"This policy causes Microsoft Edge to continue running until all Internet Explorer tabs have completely finished unloading. This allows Internet Explorer plugins like ActiveX controls to perform other critical work even after the browser has been closed. However, this can cause stability and performance issues, and Microsoft Edge processes may remain active in the background with no visible windows if the webpage or plugin prevents Internet Explorer from unloading. This policy should only be used if your organization depends on a plugin that requires this behavior.\n\nIf you enable this policy, Microsoft Edge always waits for Internet Explorer mode tabs to fully unload before ending the browser session.\n\nIf you disable or don't configure this policy, Microsoft Edge won't always wait for Internet Explorer mode tabs to fully unload before ending the browser session.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2174004","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationalwayswaitforunload_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationalwayswaitforunload_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcloudneutralsitesreporting","displayName":"Configure reporting of potentially misconfigured neutral site URLs to the M365 Admin Center Site Lists app","description":"This setting lets you enable reporting of sites that need to be configured as a neutral site on the Enterprise Mode Site List. The user must be signed in to Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant specified by the policy.\n\nIf you configure this policy, Microsoft Edge sends a report to the Microsoft 365 Admin Center Site Lists app when a navigation appears stuck redirecting back and forth between the Microsoft Edge and Internet Explorer (IE) engines several times. This indicates that redirection to an authentication server is switching engines, which repeatedly fails in a loop. The report shows the URL of the site that's the redirect target, minus any query string or fragment. The user's identity isn't reported.\n\nFor this reporting to work correctly, you must have successfully visited the Microsoft Edge Site Lists app in the Microsoft 365 Admin Center at least once. This activates a per-tenant storage account used to store these reports. Microsoft Edge still attempts to send reports if this step hasn't been completed. However, the reports aren't stored in the Site Lists app.\n\nIf you enable this policy, you must specify your Office 365 tenant ID. To learn more about finding your Office 365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668.\n\nIf you disable or don't configure this policy, Microsoft Edge never sends reports about misconfigured neutral sites to the Site Lists app.\n\nTo learn more about IE mode, see https://go.microsoft.com/fwlink/?linkid=2165707.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcloudsitelist","displayName":"Configure the Enterprise Mode Cloud Site List","description":"The Microsoft Edge Site Lists setting in the Microsoft 365 Admin Center allows you to host your site list(s) in a compliant cloud location and manage the contents of your site list(s) through the built-in experience. This setting allows you to specify which site list within the Microsoft 365 Admin Center is to be deploy to your users. The user must be signed in to Microsoft Edge with a valid work or school account. Otherwise, Microsoft Edge doesn't download the site list from the cloud location.\n\nThis setting is applicable only when the \"InternetExplorerIntegrationLevel\" setting is configured.\n\nIf you configure this policy, Microsoft Edge uses the specified site list. When enabled, you can enter the identifier of the site list that you created and published to the cloud in M365 Admin Center.\n\nThis setting takes precedence over the \"InternetExplorerIntegrationSiteList\" policy of Microsoft Edge as well as Internet Explorer's site list setting (Use the Enterprise mode IE website list). If you disable or don't configure this policy, Microsoft Edge will use the \"InternetExplorerIntegrationSiteList\" policy instead.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcloudusersitesreporting","displayName":"Configure reporting of IE Mode user list entries to the M365 Admin Center Site Lists app","description":"This setting lets you enable reporting of sites that Microsoft Edge users add to their local IE Mode site list. The user must be signed in to Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant that the policy specifies.\n\nIf you configure this policy, Microsoft Edge sends a report to the Microsoft 365 Admin Center Site Lists app when a user adds a site to their local IE mode site list. The report shows the URL of the site the user added, minus any query string or fragment. The user's identity isn't reported.\n\nFor this reporting to work correctly, you must successfully visit the Microsoft Edge Site Lists app in the Microsoft 365 Admin Center at least once. This visit activates a per-tenant storage account used to store these reports. Microsoft Edge still attempts to send reports if this step isn't completed. However, the reports aren't stored in the Site Lists app.\n\nIf you enable this policy, you must specify your O365 tenant ID. To learn more about finding your O365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668.\n\nIf you disable or don't configure this policy, Microsoft Edge never sends reports about URLs added to a user's local site list to the Site Lists app.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes","displayName":"Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode","description":"From Microsoft Edge version 96, navigations that switch between Internet Explorer mode and Microsoft Edge include form data.\n\nIf you enable this policy, you specify which data types are included in navigations between Microsoft Edge and Internet Explorer mode.\n\nIf you disable or don't configure this policy, Microsoft Edge uses the new behavior of including form data in navigations that change modes.\n\nTo learn more, see https://go.microsoft.com/fwlink/?linkid=2174004.\n\nPolicy options mapping:\n\n* IncludeNone (0) = Do not send form data or headers\n\n* IncludeFormDataOnly (1) = Send form data only\n\n* IncludeHeadersOnly (2) = Send additional headers only\n\n* IncludeFormDataAndHeaders (3) = Send form data and additional headers\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includenone","displayName":"Do not send form data or headers","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includeformdataonly","displayName":"Send form data only","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includeheadersonly","displayName":"Send additional headers only","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includeformdataandheaders","displayName":"Send form data and additional headers","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationenhancedhangdetection","displayName":"Configure enhanced hang detection for Internet Explorer mode","description":"Enhanced hang detection is a more granular approach to detecting hung webpages in Internet Explorer mode than what standalone Internet Explorer uses. When a hung webpage is detected, the browser applies a mitigation to prevent the rest of the browser from hanging.\n\nThis setting allows you to configure the use of enhanced hang detection in case you run into incompatible issues with any of your websites. We recommend disabling this policy only if you see notifications such as \"(website) is not responding\" in Internet Explorer mode but not in standalone Internet Explorer.\n\nThis setting works in conjunction with:\n\"InternetExplorerIntegrationLevel\" is set to 'IEMode'\nand\n\"InternetExplorerIntegrationSiteList\" policy where the list has at least one entry.\n\nIf you set this policy to 'Enabled' or don't configure it, websites running in Internet Explorer mode use enhanced hang detection.\n\nIf you set this policy to 'Disabled', enhanced hang detection is disabled, and users get the basic Internet Explorer hang detection behavior.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210\n\nPolicy options mapping:\n\n* Disabled (0) = Enhanced hang detection disabled\n\n* Enabled (1) = Enhanced hang detection enabled\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationenhancedhangdetection_disabled","displayName":"Enhanced hang detection disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationenhancedhangdetection_enabled","displayName":"Enhanced hang detection enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlevel","displayName":"Configure Internet Explorer integration","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210\n\nPolicy options mapping:\n\n* None (0) = None\n\n* IEMode (1) = Internet Explorer mode\n\n* NeedIE (2) = Internet Explorer 11\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlevel_none","displayName":"None","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlevel_iemode","displayName":"Internet Explorer mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlevel_needie","displayName":"Internet Explorer 11","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileallowed","displayName":"Allow launching of local files in Internet Explorer mode","description":"This policy controls the availability of the --ie-mode-file-url command line argument used to launch Microsoft Edge with a local file specified on the command line into Internet Explorer mode.\n\nThis setting works in conjunction with \"InternetExplorerIntegrationLevel\" (which is set to 'IEMode').\n\nIf this policy is set to \"true\", or don't configure it, the user is allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\n\nIf this policy is set to \"false\", the user isn't allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\n\nFor more information about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileextensionallowlist","displayName":"Open local files in Internet Explorer mode file extension allow list","description":"This policy limits which file:// URLs are allowed to launch into Internet Explorer mode based on file extension.\n\nThis setting works when \"InternetExplorerIntegrationLevel\" is set to 'IEMode'.\n\nWhen a file:// URL is requested to launch in Internet Explorer mode, the file extension of the URL must be present in this list for the URL to be allowed to launch in Internet Explorer mode. A URL that's blocked from opening in Internet Explorer mode is instead opened in Microsoft Edge mode.\n\nIf you set this policy to the special value \"*\" or don't configure it, all file extensions are allowed.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileshowcontextmenu","displayName":"Show context menu to open a file:// link in Internet Explorer mode","description":"This policy controls the visibility of the 'Open link in new Internet Explorer mode tab' option on the context menu for file:// links.\n\nThis setting works in conjunction with:\n\"InternetExplorerIntegrationLevel\", which is set to 'IEMode'.\n\nIf you enable this policy, the 'Open link in new Internet Explorer mode tab' context menu item is available for file:// links.\n\nIf you disable or don't configure this policy, the context menu item won't be added.\n\nIf the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy allows users to reload sites in Internet Explorer mode, then the 'Open link in new Internet Explorer mode tab' context menu item is available for all links, except links to sites explicitly configured by the site list to use Microsoft Edge mode. In this case, if you enable this policy, the context menu item is available for file:// links even for sites configured to use Microsoft Edge mode. If you disable or don't configure this policy, the policy has no effect.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileshowcontextmenu_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalfileshowcontextmenu_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalmhtfileallowed","displayName":"Allow local MHTML files to open automatically in Internet Explorer mode","description":"This policy controls whether local mht or mhtml files launched from the command line open automatically in Internet Explorer mode based on the file content without specifying the --ie-mode-file-url command line.\n\nThis setting works when \"InternetExplorerIntegrationLevel\" is set to 'IEMode' and \"InternetExplorerIntegrationLocalFileAllowed\" is enabled or not configured.\n\nIf you enable or don't configure this policy, local mht or mhtml files launch in Microsoft Edge or Internet Explorer mode. Then, you can view these files in the best way.\n\nIf you disable this policy, local mht or mhtml files launch in Microsoft Edge.\n\nIf you use the --ie-mode-file-url command line argument for launching local mht or mhtml files, it takes precedence over how you configured this policy.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalmhtfileallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationlocalmhtfileallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationreloadiniemodeallowed","displayName":"Allow unconfigured sites to be reloaded in Internet Explorer mode","description":"This policy allows users to reload unconfigured sites (ones that aren't configured in the Enterprise Mode Site List) in Internet Explorer mode when browsing in Microsoft Edge, and a site requires Internet Explorer for compatibility.\n\nAfter a site is reloaded in Internet Explorer mode, \"in-page\" navigation stays in Internet Explorer mode (for example, a link, script, or form on the page, or a server-side redirect from another \"in-page\" navigation). Users can choose to exit from Internet Explorer mode, or Microsoft Edge automatically exits from Internet Explorer mode when a navigation that isn't \"in-page\" occurs (for example, using the address bar, the back button, or a favorite link).\n\nUsers can also optionally tell Microsoft Edge to use Internet Explorer mode for the site in the future. This choice is remembered for a length of time managed by the \"InternetExplorerIntegrationLocalSiteListExpirationDays\" policy.\n\nIf the \"InternetExplorerIntegrationLevel\" policy is set to 'IEMode', then sites explicitly configured by the \"InternetExplorerIntegrationSiteList\" policy's site list to use Microsoft Edge aren't reloaded in Internet Explorer mode, and sites configured by the site list or by the \"SendIntranetToInternetExplorer\" policy to use Internet Explorer mode can't exit from Internet Explorer mode.\n\nIf you enable this policy, users are allowed to reload unconfigured sites in Internet Explorer mode.\n\nIf you disable this policy, users aren't allowed to reload unconfigured sites in Internet Explorer mode.\n\nIf you enable this policy, it takes precedence over how you configured the \"InternetExplorerIntegrationTestingAllowed\" policy, and that policy is disabled.\n\nFor more information about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationreloadiniemodeallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationreloadiniemodeallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationreloadiniemodeallowed_recommended","displayName":"Allow unconfigured sites to be reloaded in Internet Explorer mode (users can override)","description":"This policy allows users to reload unconfigured sites (ones that aren't configured in the Enterprise Mode Site List) in Internet Explorer mode when browsing in Microsoft Edge, and a site requires Internet Explorer for compatibility.\n\nAfter a site is reloaded in Internet Explorer mode, \"in-page\" navigation stays in Internet Explorer mode (for example, a link, script, or form on the page, or a server-side redirect from another \"in-page\" navigation). Users can choose to exit from Internet Explorer mode, or Microsoft Edge automatically exits from Internet Explorer mode when a navigation that isn't \"in-page\" occurs (for example, using the address bar, the back button, or a favorite link).\n\nUsers can also optionally tell Microsoft Edge to use Internet Explorer mode for the site in the future. This choice is remembered for a length of time managed by the \"InternetExplorerIntegrationLocalSiteListExpirationDays\" policy.\n\nIf the \"InternetExplorerIntegrationLevel\" policy is set to 'IEMode', then sites explicitly configured by the \"InternetExplorerIntegrationSiteList\" policy's site list to use Microsoft Edge aren't reloaded in Internet Explorer mode, and sites configured by the site list or by the \"SendIntranetToInternetExplorer\" policy to use Internet Explorer mode can't exit from Internet Explorer mode.\n\nIf you enable this policy, users are allowed to reload unconfigured sites in Internet Explorer mode.\n\nIf you disable this policy, users aren't allowed to reload unconfigured sites in Internet Explorer mode.\n\nIf you enable this policy, it takes precedence over how you configured the \"InternetExplorerIntegrationTestingAllowed\" policy, and that policy is disabled.\n\nFor more information about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationreloadiniemodeallowed_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationreloadiniemodeallowed_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsitelist","displayName":"Configure the Enterprise Mode Site List","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsitelistrefreshinterval","displayName":"Configure how frequently the Enterprise Mode Site List is refreshed","description":"This setting lets you specify a custom refresh interval for the Enterprise Mode Site List. The refresh interval is specified in minutes. The minimum refresh interval is 30 minutes.\n\nThis setting is applicable only when the \"InternetExplorerIntegrationSiteList\" or \"InternetExplorerIntegrationCloudSiteList\" setting is configured.\n\nIf you configure this policy, Microsoft Edge attempts to retrieve an updated version of the configured Enterprise Mode Site List using the specified refresh interval.\n\nIf you disable or don't configure this policy, Microsoft Edge uses a default refresh interval, it's 10080 minutes (7 days) starting from version 110 or later, 120 minutes from version 93 to 110, and 30 minutes before version 93.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect","displayName":"Specify how \"in-page\" navigations to unconfigured sites behave when started from Internet Explorer mode pages","description":"An \"in-page\" navigation is started from a link, a script, or a form on the current page. It can also be a server-side redirect of a previous \"in-page\" navigation attempt. Conversely, a user can start a navigation that isn't \"in-page\" and that's independent of the current page in several ways by using the browser controls, for example, using the address bar, the back button, or a favorite link.\n\nThis setting lets you specify whether navigations from pages loaded in Internet Explorer mode to unconfigured sites (that aren't configured in the Enterprise Mode Site List) switch back to Microsoft Edge or remain in Internet Explorer mode.\n\nThis setting works in conjunction with \"InternetExplorerIntegrationLevel\" policy that's set to 'IEMode', and with \"InternetExplorerIntegrationSiteList\" policy where the list has at least one entry.\n\nIf you disable or don't configure this policy, only sites configured to open in Internet Explorer mode open in that mode. Any site not configured to open in Internet Explorer mode is redirected back to Microsoft Edge.\n\nIf you set this policy to 'Default', only sites configured to open in Internet Explorer mode open in that mode. Any site not configured to open in Internet Explorer mode is redirected back to Microsoft Edge.\n\nIf you set this policy to 'AutomaticNavigationsOnly', you get the default experience except that all automatic navigations (such as 302 redirects) to unconfigured sites are kept in Internet Explorer mode.\n\nIf you set this policy to 'AllInPageNavigations', all navigations from pages loaded in IE mode to unconfigured sites are kept in Internet Explorer mode (Least Recommended).\n\nIf the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy allows users to reload sites in Internet Explorer mode, then all in-page navigations from unconfigured sites that users have chosen to reload in Internet Explorer mode are kept in Internet Explorer mode, regardless of how this policy is configured.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2105106.\n\nPolicy options mapping:\n\n* Default (0) = Default\n\n* AutomaticNavigationsOnly (1) = Keep only automatic navigations in Internet Explorer mode\n\n* AllInPageNavigations (2) = Keep all in-page navigations in Internet Explorer mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect_default","displayName":"Default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect_automaticnavigationsonly","displayName":"Keep only automatic navigations in Internet Explorer mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect_allinpagenavigations","displayName":"Keep all in-page navigations in Internet Explorer mode","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationtestingallowed","displayName":"Allow Internet Explorer mode testing (Obsolete)","description":"This policy is obsolete because it has been superseded by an improved feature. It doesn't work in Microsoft Edge after version 94. To allow users to open applications in Internet Explorer mode, use the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy instead. Alternatively, users can still use the --ie-mode-test flag.\n\nThis policy allows users to test applications in Internet Explorer mode by opening an Internet Explorer mode tab in Microsoft Edge.\n\nUsers can do so from within the \"More tools\" menu by selecting 'Open sites in Internet Explorer mode'.\n\nAdditionally, users can test their applications in a modern browser without removing applications from the site list using the option 'Open sites in Edge mode'.\n\nThis setting works in conjunction with \"InternetExplorerIntegrationLevel\" which is set to 'IEMode'.\n\nIf you enable this policy, the option 'Open sites in Internet Explorer mode' is visible under \"More tools\". Users can view their sites in Internet Explorer mode on this tab. Another option 'Open sites in Edge mode' is also visible under \"More tools\" to help testing sites in a modern browser without removing them from the site list. If the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy is enabled, it takes precedence and these options will not be visible under \"More tools\".\n\nIf you disable or don't configure this policy, users can't see the options 'Open in Internet Explorer mode' and 'Open in Edge mode' under \"More tools\" menu. However, users can configure these options with the --ie-mode-test flag.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationtestingallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationtestingallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationwindowopenheightadjustment","displayName":"Configure the pixel adjustment between window.open heights sourced from IE mode pages vs. Edge mode pages","description":"This setting lets you specify a custom adjustment to the height of popup windows generated via window.open from the Internet Explorer mode site.\n\nIf you configure this policy, Microsoft Edge will add the adjustment value to the height, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 5.\n\nIf you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window height calculations.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationwindowopenwidthadjustment","displayName":"Configure the pixel adjustment between window.open widths sourced from IE mode pages vs. Edge mode pages","description":"This setting lets you specify a custom adjustment to the width of popup windows generated via window.open from the Internet Explorer mode site.\n\nIf you configure this policy, Microsoft Edge will add the adjustment value to the width, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 4.\n\nIf you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window width calculations.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationzoneidentifiermhtfileallowed","displayName":"Automatically open downloaded MHT or MHTML files from the web in Internet Explorer mode","description":"This policy controls whether MHT or MHTML files that are downloaded from the web are automatically opened in Internet Explorer mode.\n\nIf you enable this policy, the MHT or MHTML files that are downloaded from the web can be opened in both Microsoft Edge and Internet Explorer mode to provide the best user experience.\n\nIf you disable or don't configure this policy, MHT or MHTML files that are downloaded from the web won't automatically open in Internet Explorer mode.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationzoneidentifiermhtfileallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationzoneidentifiermhtfileallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodecleardataonexitenabled","displayName":"Clear history for IE and IE mode every time you exit","description":"This policy controls whether browsing history is deleted from Internet Explorer and Internet Explorer mode every time Microsoft Edge is closed.\n\nUsers can configure this setting in the 'Clear browsing data for Internet Explorer' option in the Privacy, search, and services menu of Settings.\n\nIf you enable this policy, Internet Explorer browsing history will be cleared on browser exit.\n\nIf you disable or don't configure this policy, Internet Explorer browsing history won't be cleared on browser exit.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodecleardataonexitenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodecleardataonexitenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodeenablesavepageas","displayName":"Allow Save page as in Internet Explorer mode","description":"This policy enables 'Save page as' functionality in Internet Explorer mode.\nUsers can use this option to save the current page in the browser. When a user reopens a saved page, it's loaded in the default browser.\n\nIf you enable this policy, the \"Save page as\" option is clickable in \"More tools\".\n\nIf you disable or don't configure this policy, users can't select the \"Save page as\" option in \"More tools\".\n\nNote: To make the \"Ctrl+S\" shortcut work, users must enable the Internet Explorer policy, namely 'Enable extended hot key in Internet Explorer mode'.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodeenablesavepageas_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodeenablesavepageas_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetabinedgemodeallowed","displayName":"Allow sites configured for Internet Explorer mode to open in Microsoft Edge","description":"This policy lets sites configured to open in Internet Explorer mode to be opened by Microsoft Edge for testing on a modern browser without removing them from the site list.\n\nUsers can configure this setting in the \"More tools\" menu by selecting 'Open sites in Microsoft Edge'.\n\nIf you enable this policy, the option to 'Open sites in Microsoft Edge' is visible under \"More tools\". Users use this option to test IE mode sites on a modern browser.\n\nIf you disable or don't configure this policy, users can't see the option 'Open in Microsoft Edge' under the \"More tools\" menu. However, users can access this menu option with the --ie-mode-test flag.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetabinedgemodeallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetabinedgemodeallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled","displayName":"Show the Reload in Internet Explorer mode button in the toolbar","description":"Set this policy to show the Reload in Internet Explorer mode button in the toolbar. Users can hide the button in the toolbar through edge://settings/appearance. The button is only shown on the toolbar when the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy is enabled or if the user chose to enable \"Allow sites to be reloaded in Internet Explorer mode\".\n\nIf you enable this policy, the Reload in Internet mode button is pinned to the toolbar.\n\nIf you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default. Users can toggle the Show Internet Explorer mode button in edge://settings/appearance.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_recommended","displayName":"Show the Reload in Internet Explorer mode button in the toolbar (users can override)","description":"Set this policy to show the Reload in Internet Explorer mode button in the toolbar. Users can hide the button in the toolbar through edge://settings/appearance. The button is only shown on the toolbar when the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy is enabled or if the user chose to enable \"Allow sites to be reloaded in Internet Explorer mode\".\n\nIf you enable this policy, the Reload in Internet mode button is pinned to the toolbar.\n\nIf you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default. Users can toggle the Show Internet Explorer mode button in edge://settings/appearance.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorersetforegroundwhenactive","displayName":"Keep the active Microsoft Edge window with an Internet Explorer mode tab always in the foreground.","description":"This policy controls whether to always keep the active Microsoft Edge window with an Internet Explorer mode tab in the foreground.\n\nIf you enable this policy, the active Microsoft Edge window with an Internet Explorer mode tab remains in the foreground.\n\nIf you disable or don't configure this policy, the active Microsoft Edge window with an Internet Explorer mode tab isn't kept in the foreground.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorersetforegroundwhenactive_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorersetforegroundwhenactive_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerzoomdisplay","displayName":"Display zoom in IE Mode tabs with DPI Scale included like it is in Internet Explorer","description":"Lets you display zoom in IE Mode tabs similar to how it was displayed in Internet Explorer, where the DPI scale of the display is factored in.\n\nFor example, if you have a page zoomed to 200% on a 100 DPI scale display and you change the display to 150 DPI, Microsoft Edge would still display the zoom as 200%. However, Internet Explorer factors in the DPI scale and displays 300%.\n\nIf you enable this policy, zoom values will be displayed with the DPI scale included for IE Mode tabs.\n\nIf you disable or don't configure this policy, zoom values will be displayed without DPI scale included for IE Mode tabs","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerzoomdisplay_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerzoomdisplay_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.intranetfilelinksenabled","displayName":"Allow intranet zone file URL links from Microsoft Edge to open in Windows File Explorer","description":"This setting allows file URL links to intranet zone files from intranet zone HTTPS websites to open Windows File Explorer for that file or directory.\n\nIf you enable this policy, intranet zone file URL links originating from intranet zone HTTPS pages open Windows File Explorer to the parent directory of the file and select the file. Intranet zone directory URL links originating from intranet zone HTTPS pages open Windows File Explorer to the directory with no items in the directory selected.\n\nIf you disable or don't configure this policy, file URL links don't open.\n\nMicrosoft Edge uses the definition of intranet zone as configured for Internet Explorer. https://localhost/ is blocked as an exception of allowed intranet zone host, while loopback addresses (127.0.0.*, [::1]) are considered internet zone by default.\n\nUsers may opt out of prompts on a per-protocol/per-site basis unless the \"ExternalProtocolDialogShowAlwaysOpenCheckbox\" policy is disabled.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.intranetfilelinksenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.intranetfilelinksenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptallowedforurls","displayName":"Allow JavaScript on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to run JavaScript.\n\nIf you don't configure this policy, \"DefaultJavaScriptSetting\" applies for all sites, when the setting is enabled. If not, the user's personal setting applies.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptblockedforurls","displayName":"Block JavaScript on specific sites","description":"Defines a list of sites, based on URL patterns, that aren't allowed to run JavaScript.\n\nIf you don't configure this policy, \"DefaultJavaScriptSetting\" applies for all sites, if it's set. If not, the user's personal setting applies.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nThis policy blocks JavaScript based on whether the origin of the top-level document (usually the page URL that's also displayed in the address bar) matches any of the patterns. Therefore, this policy isn't appropriate for mitigating web supply-chain attacks. For example, supplying the pattern `https://[*.]foo.com/` doesn't prevent a page hosted on, say, `https://contoso.com`, from running a script loaded from `https://www.foo.com/example.js`. Furthermore, supplying the pattern `https://contoso.com/` doesn't prevent a document from `https://contoso.com` from running scripts if it isn't the top-level document, but embedded as a subframe into a page hosted on another origin, say, `https://www.fabrikam.com`.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites","description":"Allows you to set a list of site URL patterns that specify sites that are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\n\nFor detailed information on valid site URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com won't correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there's no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top-level origin URL alone; so, for example, if contoso.com is listed in the JavaScriptJitAllowedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT enabled, but fabrikam.com will use the policy from \"DefaultJavaScriptJitSetting\", if set, or default to JavaScript JIT enabled.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptJitSetting\" applies to the site, if set, otherwise Javascript JIT is enabled for the site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptjitblockedforsites","displayName":"Block JavaScript from using JIT on these sites","description":"Allows you to set a list of site URL patterns that specify sites that aren't allowed to run JavaScript JIT (Just In Time) compiler enabled.\n\nDisabling the JavaScript JIT means that Microsoft Edge may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Microsoft Edge to render web content in a more secure configuration.\n\nFor detailed information on valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top-level origin URL alone; so, for example, if contoso.com is listed in the JavaScriptJitBlockedForSites policy but contoso.com loads a frame containing fabrikam.com, then contoso.com has JavaScript JIT disabled, but fabrikam.com uses the policy from \"DefaultJavaScriptJitSetting\", if set, or default to JavaScript JIT enabled.\n\nIf you don't configure this policy for a site, then the policy from \"DefaultJavaScriptJitSetting\" applies to the site, if set; otherwise, JavaScript JIT is enabled for the site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites","description":"Allows you to set a list of site URL patterns that specify sites for which advanced JavaScript optimizations are enabled.\n\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com doesn't correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there's no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top-level origin URL alone; so, for example, if contoso.com is listed in the \"JavaScriptOptimizerAllowedForSites\" policy but contoso.com loads a frame containing fabrikam.com, then contoso.com has JavaScript optimizations enabled, but fabrikam.com uses the policy from \"DefaultJavaScriptOptimizerSetting\", if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\n\nIf you don't configure this policy for a site, then the policy from \"DefaultJavaScriptOptimizerSetting\" applies to the site, if set, otherwise Javascript optimization is enabled for the site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are disabled.\n\nDisabling JavaScript optimizations means that Microsoft Edge may render web content more slowly.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com won't correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there's no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and isn't based on top-level origin url alone; so, for example, if contoso.com is listed in the \"JavaScriptOptimizerBlockedForSites\" policy but contoso.com loads a frame containing fabrikam.com, then contoso.com has JavaScript optimizations disabled, but fabrikam.com will use the policy from \"DefaultJavaScriptOptimizerSetting\", if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\n\nIf you don't configure this policy for a site, then the policy from \"DefaultJavaScriptOptimizerSetting\" applies to the site, if set; otherwise, JavaScript optimization is enabled for the site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.keyboardfocusablescrollersenabled","displayName":"Enable keyboard focusable scrollers (Obsolete)","description":"This policy provides a temporary opt-out for the new keyboard focusable scrollers behavior.\n\nWhen this policy is Enabled or unset, scrollers without focusable children are keyboard focusable by default.\n\nWhen this policy is Disabled, scrollers aren't keyboard focusable by default.\n\nThis policy is a temporary workaround. Starting in Microsoft Edge version 139, this policy is obsolete.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.keyboardfocusablescrollersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.keyboardfocusablescrollersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.legacysamesitecookiebehaviorenabled","displayName":"Enable default legacy SameSite cookie behavior setting (Obsolete)","description":"This policy doesn't work because it was only intended to serve only as a short-term mechanism to give enterprises more time to update their environments if they were found to be incompatible with the SameSite behavior change.\n\nIf you still require legacy cookie behavior, please use \"LegacySameSiteCookieBehaviorEnabledForDomainList\" to configure behavior on a per-domain basis.\n\nLets you revert all cookies to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute, and skips the scheme comparison when evaluating if two sites are same-site.\n\nIf you don't set this policy, the default SameSite behavior for cookies will depend on other configuration sources for the SameSite-by-default feature, the Cookies-without-SameSite-must-be-secure feature, and the Schemeful Same-Site feature. These features can also be configured by a field trial or the same-site-by-default-cookies flag, the cookies-without-same-site-must-be-secure flag, or the schemeful-same-site flag in edge://flags.\n\nPolicy options mapping:\n\n* DefaultToLegacySameSiteCookieBehavior (1) = Revert to legacy SameSite behavior for cookies on all sites\n\n* DefaultToSameSiteByDefaultCookieBehavior (2) = Use SameSite-by-default behavior for cookies on all sites\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.legacysamesitecookiebehaviorenabled_defaulttolegacysamesitecookiebehavior","displayName":"Revert to legacy SameSite behavior for cookies on all sites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.legacysamesitecookiebehaviorenabled_defaulttosamesitebydefaultcookiebehavior","displayName":"Use SameSite-by-default behavior for cookies on all sites","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.legacysamesitecookiebehaviorenabledfordomainlist","displayName":"Revert to legacy SameSite behavior for cookies on specified sites (Obsolete)","description":"Cookies set for domains match specified patterns revert to legacy SameSite behavior.\n\nReverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute, and skips the scheme comparison when evaluating if two sites are same-site.\n\nIf you don't set this policy, the global default value is used. The global default is also used for cookies on domains not covered by the patterns you specify.\n\nThe global default value can be configured using the \"LegacySameSiteCookieBehaviorEnabled\" policy. If \"LegacySameSiteCookieBehaviorEnabled\" is unset, the global default value falls back to other configuration sources.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nPatterns you list in this policy are treated as domains, not URLs, so you shouldn't specify a scheme or port.\n\nThe policy is discontinued from Edge 132.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.linkedaccountenabled","displayName":"Enable the linked account feature (Obsolete)","description":"This policy is obsolete because Microsoft Edge no longer supports the linked account feature.\n\nMicrosoft Edge guides a user to the account management page where they can link a Microsoft Account (MSA) to an Azure Active Directory (Azure AD) account.\n\nIf you enable or don't configure this policy, linked account information is shown on a flyout. When the Azure AD profile doesn't have a linked account, it shows \"Add account\".\n\nIf you disable this policy, linked accounts are turned off and no extra information is shown.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.linkedaccountenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.linkedaccountenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.livecaptionsallowed","displayName":"Live captions allowed","description":"Allow users to turn the Live captions feature on or off.\n\nLive captions is an accessibility feature that converts speech from the audio that plays in Microsoft Edge into text and shows this text in a separate window. The entire process happens on the device and no audio or caption text ever leaves the device.\n\nNote: This feature isn't generally available. Clients that have the \"ExperimentationAndConfigurationServiceControl\" policy set to 'FullMode' receive the feature before broad availability. Broad availability is announced via Microsoft Edge release notes.\n\nIf you enable or don't configure this policy, users can turn on this feature or turn it off at edge://settings/accessibility.\n\nIf you disable this policy, users can't turn on this accessibility feature. If speech recognition files were downloaded previously, they will be deleted from the device in 30 days. We recommend avoiding this option unless it's needed in your environment.\n\nIf users choose to turn on Live captions, speech recognition files (approximately 100 megabytes) are downloaded to the device on first run and then periodically to improve performance and accuracy. These files will be deleted after 30 days.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.livecaptionsallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.livecaptionsallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.livevideotranslationenabled","displayName":"Allows users to translate videos to different languages.","description":"This policy configures the on-device real-time video translation feature in Microsoft Edge.\nWith this feature, users can watch videos translated into their selected language in real time.\n\nWhen a user selects the Translate icon and chooses a source (video language) and target language (translated language),\ntranslation components are downloaded on first use (approximately 200 MB per language pair).\n\nThese components can be updated periodically to improve performance and translation quality.\nTranslation is performed locally on the user’s device and no data is sent outside of the device.\nThe feature is available only for non-DRM videos, on supported high-end devices, with select language pairs, and in select regions.\nFor more information, see https://www.microsoft.com/en-us/edge/features/real-time-video-translation.\n\nIf you enable or don’t configure this policy, the on-device real-time video translation feature is enabled and\nusers will see the Translate button when hovering over videos.\n\nIf you disable this policy, the on-device real-time video translation feature is disabled and the Translate button is not shown.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.livevideotranslationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.livevideotranslationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localbrowserdatashareenabled","displayName":"Enable Windows to search local Microsoft Edge browsing data","description":"Enables Windows to index Microsoft Edge browsing data stored locally on the user's device and allows users to find and launch previously stored browsing data directly from Windows features such as the search box on the taskbar in Windows.\n\nIf you enable this policy or don't configure it, Microsoft Edge publishes local browsing data to the Windows Indexer.\n\nIf you disable this policy, Microsoft Edge won't share data to the Windows Indexer.\n\nNote that if you disable this policy, Microsoft Edge removes the data shared with Windows on the device and stops sharing any new browsing data.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localbrowserdatashareenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localbrowserdatashareenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localbrowserdatashareenabled_recommended","displayName":"Enable Windows to search local Microsoft Edge browsing data (users can override)","description":"Enables Windows to index Microsoft Edge browsing data stored locally on the user's device and allows users to find and launch previously stored browsing data directly from Windows features such as the search box on the taskbar in Windows.\n\nIf you enable this policy or don't configure it, Microsoft Edge publishes local browsing data to the Windows Indexer.\n\nIf you disable this policy, Microsoft Edge won't share data to the Windows Indexer.\n\nNote that if you disable this policy, Microsoft Edge removes the data shared with Windows on the device and stops sharing any new browsing data.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localbrowserdatashareenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localbrowserdatashareenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localfontsallowedforurls","displayName":"Allow Local Fonts permission on these sites","description":"Specifies a list of site URL patterns for which the local fonts permission is automatically granted. Sites in this list can access information about local fonts.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are supported. This policy matches based on origin only; any path in the URL pattern is ignored.\n\nIf a site isn't included in this policy, the \"DefaultLocalFontsSetting\" policy applies if configured. Otherwise, the browser default behavior applies, and users can choose the permission on a per-site basis.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localfontsblockedforurls","displayName":"Block Local Fonts permission on these sites","description":"Specifies a list of site URL patterns for which the local fonts permission is automatically denied. Sites in this list are prevented from accessing information about local fonts.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are supported. This policy matches based on origin only; any path in the URL pattern is ignored.\n\nIf a site isn't included in this policy, the \"DefaultLocalFontsSetting\" policy applies if configured. Otherwise, the browser default behavior applies, and users can choose the permission on a per-site basis.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessallowedforurls","displayName":"Allow sites to make network requests to local devices and local network endpoints.","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions.\n\nNetwork requests initiated from websites served by matching origins are not subject to Local Network Access checks.\n\nFor origins not covered by the patterns specified here, the user's personal configuration and applicable local network access restrictions apply.\n\nThere are multiple policies that control origins impacting requests to local device and local network endpoints. If an origin matches more than one of the following policies, the policies take precedence in the following order:\n\n- LocalNetworkBlockedForUrls\n- LocalNetworkAllowedForUrls\n- LoopbackNetworkAccessBlockedForUrls\n- LoopbackNetworkAccessAllowedForUrls\n- LocalNetworkAccessBlockedForUrls\n- LocalNetworkAccessAllowedForUrls\n\nFor detailed information about valid URL pattern syntax, see:\nhttps://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns\n\nFor more information about Local Network Access, see:\nhttps://wicg.github.io/local-network-access/\n\nNote: This policy enables controlled exceptions to local network access restrictions. It allows specified public websites to access private IP addresses when required for trusted local communication scenarios.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessblockedforurls","displayName":"Block sites from making network requests to local devices and local network endpoints.","description":"Specifies a list of URL patterns for which requests initiated from matching origins are blocked from issuing Local Network Access requests.\n\nNetwork requests initiated from websites served by matching origins are prevented from accessing local device and local network endpoints.\n\nFor origins not covered by the patterns specified here, the user's personal configuration applies.\n\nThere are multiple policies that control origins impacting requests to local device and local network endpoints. If an origin matches more than one of the following policies, the policies take precedence in the following order:\n\n- LocalNetworkBlockedForUrls\n- LocalNetworkAllowedForUrls\n- LoopbackNetworkAccessBlockedForUrls\n- LoopbackNetworkAccessAllowedForUrls\n- LocalNetworkAccessBlockedForUrls\n- LocalNetworkAccessAllowedForUrls\n\nFor detailed information about valid URL pattern syntax, see:\nhttps://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns\n\nFor more information about Local Network Access, see:\nhttps://wicg.github.io/local-network-access/\n\nNote: This policy blocks specified public websites from accessing private IP addresses. It helps reduce exposure of internal network resources unless access is explicitly permitted by policy.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to block requests from public websites to devices on a user's local network. (Obsolete)","description":"Local Network Access restrictions prevent public websites from making\nrequests to devices on a user's local network without explicit user permission.\n\nIf you enable this policy, Microsoft Edge blocks\nany request that would otherwise trigger a DevTools warning\ndue to Local Network Access checks.\nThese requests are denied without prompting the user.\n\nIf you disable or don't configure this policy, Microsoft Edge handles\nthese requests using the default behavior, which may include showing warnings in DevTools\nand allowing the request to proceed depending on the context.\n\nNote: This feature improves local network security by deprecating direct access to private IP addresses from public websites\nunless explicitly granted by the user. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.\n\nStarting in version 140, Microsoft Edge introduces support for policies that manage Local Network Access behavior on a per-URL basis.\n\nYou can configure exceptions to allow specific URLs to bypass Local Network Access restrictions.\n\nYou can also block specific URLs from making Local Network Access requests.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessrestrictionsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessrestrictionsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessrestrictionstemporaryoptout","displayName":"Specifies whether to opt out of Local Network Access restrictions","description":"This policy allows for opting out of restrictions on requests to local network endpoints.\n\nIf you enable this policy, Local Network Access requests will only display warnings in Edge DevTools when Local Network Access checks fail.\n\nIf you disable or don't configure this policy, Local Network Access requests follow the default handling behavior.\n\nFor more information about Local Network Access restrictions, see Local Network Access.\n\nTo allow specific URL patterns that should automatically be granted Local Network Access permission, use the LocalNetworkAccessAllowedForUrls policy.\n\nNote: This opt-out policy is temporary and will be removed after Microsoft Edge version 152.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessrestrictionstemporaryoptout_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkaccessrestrictionstemporaryoptout_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkallowedforurls","displayName":"Allow sites to make network requests to local network endpoints.","description":"Controls which website origins are exempt from Local Network Access checks when accessing local network endpoints.\n\nNetwork requests initiated from websites that match the specified URL patterns are not subject to Local Network Access checks.\n\nFor origins not covered by the patterns specified in this policy, the user's personal configuration applies.\n\nFor detailed information about valid URL patterns, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\n\nFor more information about Local Network Access restrictions, see https://wicg.github.io/local-network-access/.\n\nMultiple policies can list origins that affect requests to local network endpoints. If an origin matches more than one of the following policies, they take precedence in the following order:\n- LocalNetworkBlockedForUrls\n- LocalNetworkAllowedForUrls\n- LoopbackNetworkBlockedForUrls\n- LoopbackNetworkAllowedForUrls\n- LocalNetworkAccessBlockedForUrls\n- LocalNetworkAccessAllowedForUrls\n\nThis policy controls access to local network endpoints (private IP addresses) and can be used to allow specific websites to access local network resources.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localnetworkblockedforurls","displayName":"Block sites from making network requests to local network endpoints.","description":"Controls which website origins are blocked from making Local Network Access requests to local network endpoints.\n\nNetwork requests initiated from websites that match the specified URL patterns are blocked from issuing Local Network Access requests.\n\nFor origins not covered by the patterns specified in this policy, the user's personal configuration applies.\n\nFor detailed information about valid URL patterns, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\n\nFor more information about Local Network Access restrictions, see https://wicg.github.io/local-network-access/.\n\nMultiple policies can list origins that affect requests to local network endpoints. If an origin matches more than one of the following policies, they take precedence in the following order:\n- LocalNetworkBlockedForUrls\n- LocalNetworkAllowedForUrls\n- LoopbackNetworkBlockedForUrls\n- LoopbackNetworkAllowedForUrls\n- LocalNetworkAccessBlockedForUrls\n- LocalNetworkAccessAllowedForUrls\n\nThis policy controls access to local network endpoints (private IP addresses) and can be used to block specific websites from accessing local network resources.","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled","displayName":"Allow suggestions from local providers","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\n\nIf you enable this policy, suggestions from local providers are used.\n\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions won't appear.\n\nIf you don't configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\n\nSome features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the \"SavingBrowserHistoryDisabled\" policy.\n\nThis policy requires a browser restart to finish applying.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_recommended","displayName":"Allow suggestions from local providers (users can override)","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\n\nIf you enable this policy, suggestions from local providers are used.\n\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions won't appear.\n\nIf you don't configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\n\nSome features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the \"SavingBrowserHistoryDisabled\" policy.\n\nThis policy requires a browser restart to finish applying.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.loopbacknetworkallowedforurls","displayName":"Allow sites to make network requests to the local device.","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions when accessing loopback addresses (127.0.0.1, ::1, localhost).\n\nIf a requesting origin matches a URL pattern specified in this policy, requests to loopback addresses are allowed and are not subject to Local Network Access restrictions.\n\nFor origins not covered by this policy, the user's personal settings and local network access restrictions apply.\n\nIf this policy is disabled or not configured, no additional exemptions are granted beyond the user's existing configuration.\n\nMultiple policies can specify origins that affect requests to the local device. If an origin matches more than one of the following policies, they are applied in the following order of precedence:\n- LoopbackNetworkBlockedForUrls\n- LoopbackNetworkAllowedForUrls\n- LocalNetworkAccessBlockedForUrls\n- LocalNetworkAccessAllowedForUrls\n\nFor guidance on valid URL pattern syntax, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns .","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.loopbacknetworkblockedforurls","displayName":"Block sites from making network requests to the local device.","description":"Specifies a list of URL patterns for which requests initiated from matching origins to loopback addresses (127.0.0.1, ::1, localhost) are blocked from issuing Local Network Access requests.\n\nIf a requesting origin matches a URL pattern specified in this policy, requests to loopback addresses are blocked.\n\nFor origins not covered by this policy, the user's personal settings and local network access restrictions apply.\n\nMultiple policies can specify origins that affect requests to the local device. If an origin matches more than one of the following policies, they are applied in the following order of precedence:\n- LoopbackNetworkBlockedForUrls\n- LoopbackNetworkAllowedForUrls\n- LocalNetworkAccessBlockedForUrls\n- LocalNetworkAccessAllowedForUrls\n\nNote: This policy improves local network security by blocking specified public websites from accessing loopback addresses. It helps prevent unauthorized external sites from reaching local services running on the device unless explicitly permitted.\n\nFor more information about Local Network Access, see https://wicg.github.io/local-network-access/","helpText":null,"infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365authpopupsinworkenabled","displayName":"Allow M365 authentication popups in work profiles","description":"This policy controls whether Microsoft Edge allows Microsoft 365 authentication pop-ups to bypass the pop-up blocker in work profiles.\n\nWhen users are signed in with a work account, some Microsoft 365 sites (for example, microsoft.com, cloud.microsoft, and visualstudio.com) may open authentication pop-ups to login.microsoftonline.com, login.live.com, or login.microsoft.com. These pop-ups are required to complete sign-in.\n\nIf you enable this policy or don't configure it, Microsoft 365 authentication pop-ups are allowed in work profiles.\n\nIf you disable this policy, Microsoft 365 authentication pop-ups follow the default settings like other pop-ups.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365authpopupsinworkenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365authpopupsinworkenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365linksautoopencopilotenabled","displayName":"Automatically open Copilot side pane with contextual insights for links opened from Outlook","description":"This policy controls whether Microsoft Edge automatically opens the Microsoft Copilot side pane when users open eligible web links from Outlook emails sent from the same tenant.\n\nStarting in Microsoft Edge version 148, eligible links from Outlook emails sent from the same tenant can open with the Copilot side pane. Copilot can use the originating Outlook email as context to surface relevant insights and suggested next steps alongside the web content.\n\nIf you enable this policy or don't configure it, the Copilot side pane opens automatically when users open eligible links from Outlook emails sent from the same tenant.\n\nIf you disable this policy, the Copilot side pane doesn't open automatically for those links.\n\nThis policy is not yet supported. When support becomes available, eligible links from Outlook emails sent from the same tenant can open with the Copilot side pane.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365linksautoopencopilotenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365linksautoopencopilotenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.managedconfigurationperorigin","displayName":"Sets managed configuration values for websites to specific origins","description":"Setting this policy defines the return value of Managed Configuration API for given origin.\n\nManaged Configuration API is a key-value configuration that can be accessed via navigator.device.getManagedConfiguration() javascript call. This API is only available to origins, which correspond to force-installed web applications via \"WebAppInstallForceList\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.managedfavorites","displayName":"Configure favorites","description":"Configures a list of managed favorites.\n\nThe policy creates a list of favorites. Each favorite contains the keys \"name\" and \"url,\" which hold the favorite's name and its target. You can configure a subfolder by defining a favorite without an \"url\" key but with an extra \"children\" key that contains a list of favorites as defined earlier (some of which may be folders again). Microsoft Edge amends incomplete URLs as if they were submitted via the Address Bar, for example \"microsoft.com\" becomes \"https://microsoft.com/\".\n\nThese favorites are placed in a folder that can't be modified by the user (but the user can choose to hide it from the favorites bar). By default the folder name is \"Managed favorites\" but you can change it by adding to the list of favorites a dictionary containing the key \"toplevel_name\" with the desired folder name as the value.\n\nManaged favorites aren't synced to the user account and can't be modified by extensions.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.managedsearchengines","displayName":"Manage Search Engines","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine. With Microsoft Edge version 100, you can configure up to 100 engines.\n\nYou don't need to specify the encoding. With Microsoft Edge version 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge version 80.\n\nWith Microsoft Edge version 83, you can enable search engine discovery with the optional allow_search_engine_discovery parameter. This parameter must be the first item in the list. If allow_search_engine_discovery isn't specified, search engine discovery is disabled by default. With Microsoft Edge version 84, you can set this policy as a recommended policy to allow search provider discovery. You don't need to add the optional allow_search_engine_discovery parameter. With Microsoft Edge version 100, setting this policy as a recommended policy also allows users to manually add new search engines from their Microsoft Edge settings.\n\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\n\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\n\nIf the \"DefaultSearchProviderSearchURL\" policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.managedsearchengines_recommended","displayName":"Manage Search Engines (users can override)","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine. With Microsoft Edge version 100, you can configure up to 100 engines.\n\nYou don't need to specify the encoding. With Microsoft Edge version 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge version 80.\n\nWith Microsoft Edge version 83, you can enable search engine discovery with the optional allow_search_engine_discovery parameter. This parameter must be the first item in the list. If allow_search_engine_discovery isn't specified, search engine discovery is disabled by default. With Microsoft Edge version 84, you can set this policy as a recommended policy to allow search provider discovery. You don't need to add the optional allow_search_engine_discovery parameter. With Microsoft Edge version 100, setting this policy as a recommended policy also allows users to manually add new search engines from their Microsoft Edge settings.\n\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\n\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\n\nIf the \"DefaultSearchProviderSearchURL\" policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.mandatoryextensionsforinprivatenavigation","displayName":"Specify extensions users must allow in order to navigate using InPrivate mode","description":"This policy lets you specify a list of extension IDs that the user must explicitly allow to run in InPrivate mode in order to enable InPrivate browsing.\n\nIf users don't allow all listed extensions to run in InPrivate mode, they're unable to navigate using InPrivate.\n\nIf any extension in the list isn't installed, InPrivate navigation is blocked.\n\nThis policy only applies when InPrivate mode is enabled. If InPrivate mode is disabled using the InPrivateModeAvailability policy, this policy has no effect.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoft365copilotchaticonenabled","displayName":"Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar","description":"For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon is shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users.\n\nThis policy only applies when users are accessing Copilot in the sidepane.\n\nIf the policy is enabled: Copilot appears in the toolbar.\n\nIf the policy is disabled: Copilot doesn't appear in the toolbar.\n\nIf the policy isn't configured: Otherwise, Copilot shows in the toolbar and users can enable or disable Copilot from showing by using the Show Copilot toggle in settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoft365copilotchaticonenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoft365copilotchaticonenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoft365copilotchaticonenabled_recommended","displayName":"Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar (users can override)","description":"For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon is shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users.\n\nThis policy only applies when users are accessing Copilot in the sidepane.\n\nIf the policy is enabled: Copilot appears in the toolbar.\n\nIf the policy is disabled: Copilot doesn't appear in the toolbar.\n\nIf the policy isn't configured: Otherwise, Copilot shows in the toolbar and users can enable or disable Copilot from showing by using the Show Copilot toggle in settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoft365copilotchaticonenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoft365copilotchaticonenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftedgeinsiderpromotionenabled","displayName":"Microsoft Edge Insider Promotion Enabled","description":"Shows content promoting the Microsoft Edge Insider channels on the About Microsoft Edge settings page.\n\nIf you enable or don't configure this policy, the Microsoft Edge Insider promotion content is shown on the About Microsoft Edge page.\n\nIf you disable this policy, the Microsoft Edge Insider promotion content isn't shown on the About Microsoft Edge page.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftedgeinsiderpromotionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftedgeinsiderpromotionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsofteditorproofingenabled","displayName":"Spell checking provided by Microsoft Editor","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages.\n\nIf you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields.\n\nIf you disable this policy, spell check can only be provided by local engines that use platform or Hunspell services. The results from these engines might be less informative than the results Microsoft Editor can provide.\n\nIf the \"SpellcheckEnabled\" policy is set to disabled, or the user disables spell checking in the settings page, this policy will have no effect.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsofteditorproofingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsofteditorproofingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsofteditorsynonymsenabled","displayName":"Synonyms are provided when using Microsoft Editor spell checker","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages, and synonyms can be suggested as an integrated feature.\n\nIf you enable this policy, Microsoft Editor spell checker provides synonyms for suggestions for misspelled words.\n\nIf you disable or don't configure this policy, Microsoft Editor spell checker won't provide synonyms for suggestions for misspelled words.\n\nIf the \"SpellcheckEnabled\" policy or the \"MicrosoftEditorProofingEnabled\" policy are set to disabled, or the user disables spell checking or chooses not to use Microsoft Editor spell checker in the settings page, this policy will have no effect.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsofteditorsynonymsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsofteditorsynonymsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftofficemenuenabled","displayName":"Allow users to access the Microsoft Office menu (Deprecated)","description":"This policy is deprecated because the Microsoft Edge sidebar replaced it. Microsoft Office applications are now available in the sidebar, which are managed by HubsSidebarEnabled policy.\n\nWhen users can access the Microsoft Office menu, they can get access to Office applications such as Microsoft Word and Microsoft Excel.\n\nIf you enable or don't configure this policy, users can open the Microsoft Office menu.\n\nIf you disable this policy, users can't access the Microsoft Office menu.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftofficemenuenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftofficemenuenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.mousegestureenabled","displayName":"Mouse Gesture Enabled","description":"This policy lets you configure the Mouse Gesture feature in Microsoft Edge.\n\nThis feature provides an easy way for users to complete tasks like scroll forward or backward, open new tab, refresh page, etc. They can finish a task by pressing and holding the mouse right button to draw certain patterns on a webpage, instead of clicking the buttons or using keyboard shortcuts.\n\nIf you enable or don't configure this policy, you can use the Mouse Gesture feature on Microsoft Edge to start using this feature.\n\nIf you disable this policy, you can't use the Mouse Gesture feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.mousegestureenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.mousegestureenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.mutationeventsenabled","displayName":"Enable deprecated/removed Mutation Events (Obsolete)","description":"This policy provides a temporary opt-in back to a deprecated and removed set of platform events named Mutation Events.\n\nIf you enable this policy, mutation events continue to be fired, even if they've been disabled by default for normal web users.\n\nIf you disable or don't configure this policy, these events won't be fired.\n\nNote:\nThis policy is a temporary workaround and will be obsolete starting with Microsoft Edge version 137.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.mutationeventsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.mutationeventsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativehostsexecutableslaunchdirectly","displayName":"Force Windows executable Native Messaging hosts to launch directly","description":"This policy controls whether native host executables launch directly on Windows.\n\nIf you enable this policy, Microsoft Edge is forced to launch native messaging hosts implemented as executables directly.\n\nIf you disable this policy, Microsoft Edge launches hosts using cmd.exe as an intermediary process.\n\nIf you don't configure this policy, Microsoft Edge decides which approach to use based on a progressive rollout from the legacy behavior to the Launch Directly behavior, guided by ecosystem compatibility.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativehostsexecutableslaunchdirectly_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativehostsexecutableslaunchdirectly_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessagingallowlist","displayName":"Control which native messaging hosts users can use","description":"Setting the policy specifies which native messaging hosts aren't subject to the deny list. A deny list value of * means all native messaging hosts are denied unless they're explicitly allowed.\n\nAll native messaging hosts are allowed by default. However, if a native messaging host is denied by policy, the admin can use the allow list to change that policy.","helpText":null,"infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessagingblocklist","displayName":"Configure native messaging block list","description":"Setting this policy specifies which native messaging hosts shouldn't be loaded. A deny list value of * means all native messaging hosts are denied unless they're explicitly allowed.\n\nIf you leave this policy unset, Microsoft Edge loads all installed native messaging hosts.","helpText":null,"infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessaginguserlevelhosts","displayName":"Allow user-level native messaging hosts (installed without admin permissions)","description":"If you set this policy to Enabled or leave it unset, Microsoft Edge can use native messaging hosts installed at the user level.\n\nIf you set this policy to Disabled, Microsoft Edge can only use these hosts if they're installed at the system level.","helpText":null,"infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessaginguserlevelhosts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessaginguserlevelhosts_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.navigationdelayforinitialsitelistdownloadtimeout","displayName":"Set a timeout for delay of tab navigation for the Enterprise Mode Site List","description":"Allows you to set a timeout, in seconds, for Microsoft Edge tabs waiting to navigate until the browser has downloaded the initial Enterprise Mode Site List.\n\nThis setting works in conjunction with: \"InternetExplorerIntegrationLevel\" is set to 'IEMode' and \"InternetExplorerIntegrationSiteList\" policy where the list has at least one entry and \"DelayNavigationsForInitialSiteListDownload\" is set to \"All eligible navigations\" (1).\n\nTabs won't wait longer than this timeout for the Enterprise Mode Site List to download. If the browser hasn't finished downloading the Enterprise Mode Site List when the timeout expires, Microsoft Edge tabs continue navigating anyway. The value of the timeout should be no greater than 20 seconds and no fewer than 1 second.\n\nIf you set the timeout in this policy to a value greater than 2 seconds, an information bar is shown to the user after 2 seconds. The information bar contains a button that allows the user to quit waiting for the Enterprise Mode Site List download to complete.\n\nIf you don't configure this policy, the default timeout of 4 seconds is used. This default is subject to change in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions","displayName":"Enable network prediction","description":"Enables network prediction and prevents users from changing this setting.\n\nThis controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages.\n\nIf you don't configure this policy, network prediction is enabled but the user can change it.\n\nPolicy options mapping:\n\n* NetworkPredictionAlways (0) = Predict network actions on any network connection\n\n* NetworkPredictionWifiOnly (1) = Not supported, if this value is used it will be treated as if 'Predict network actions on any network connection' (0) was set\n\n* NetworkPredictionNever (2) = Don't predict network actions on any network connection\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_networkpredictionalways","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_networkpredictionwifionly","displayName":"Not supported, if this value is used it will be treated as if 'Predict network actions on any network connection' (0) was set","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_networkpredictionnever","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_recommended","displayName":"Enable network prediction (users can override)","description":"Enables network prediction and prevents users from changing this setting.\n\nThis controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages.\n\nIf you don't configure this policy, network prediction is enabled but the user can change it.\n\nPolicy options mapping:\n\n* NetworkPredictionAlways (0) = Predict network actions on any network connection\n\n* NetworkPredictionWifiOnly (1) = Not supported, if this value is used it will be treated as if 'Predict network actions on any network connection' (0) was set\n\n* NetworkPredictionNever (2) = Don't predict network actions on any network connection\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_recommended_networkpredictionalways","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_recommended_networkpredictionwifionly","displayName":"Not supported, if this value is used it will be treated as if 'Predict network actions on any network connection' (0) was set","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.networkpredictionoptions_recommended_networkpredictionnever","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\n\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\n\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_recommended","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled (users can override)","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\n\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\n\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageallowedbackgroundtypes","displayName":"Configure the background types allowed for the new tab page layout","description":"You can configure which types of background image that are allowed on the new tab page layout in Microsoft Edge.\n\nIf you don't configure this policy, all background image types on the new tab page are enabled.\n\nPolicy options mapping:\n\n* DisableImageOfTheDay (1) = Disable daily background image type\n\n* DisableCustomImage (2) = Disable custom background image type\n\n* DisableAll (3) = Disable all background image types\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageallowedbackgroundtypes_disableimageoftheday","displayName":"Disable daily background image type","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageallowedbackgroundtypes_disablecustomimage","displayName":"Disable custom background image type","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageallowedbackgroundtypes_disableall","displayName":"Disable all background image types","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageapplauncherenabled","displayName":"Hide App Launcher on Microsoft Edge new tab page","description":"By default, the App Launcher is shown every time a user opens a new tab page.\n\nIf you enable or don't configure this policy, there's no change on the Microsoft Edge new tab page and App Launcher is there for users.\n\nIf you disable this policy, App Launcher doesn't appear and users can't launch Microsoft 365 apps from Microsoft Edge new tab page via the App Launcher.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageapplauncherenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageapplauncherenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagebingchatenabled","displayName":"Disable Bing chat entry-points on Microsoft Edge Enterprise new tab page","description":"By default, the Microsoft Edge new tab page includes three Bing Chat entry points: one inside the search box, one in the Bing autosuggest dropdown when users select or begin typing in the box, and one as a suggested prompt below the box.\n\nIf you enable or don't configure this policy, these Bing Chat entry points continue to appear on the new tab page.\n\nIf you disable this policy, all Bing Chat entry points are removed from the new tab page.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagebingchatenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagebingchatenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogo","displayName":"Set new tab page company logo (Obsolete)","description":"This policy didn't work as expected due to changes in operational requirements. Therefore, it's obsolete and shouldn't be used.\n\nSpecifies the company logo that's to be used on the new tab page in Microsoft Edge.\n\nThe policy should be configured as a string that expresses the logo(s) in JSON format. For example: { \"default_logo\": { \"url\": \"https://www.contoso.com/logo.png\", \"hash\": \"cd0aa9856147b6c5b4ff2b7dfee5da20aa38253099ef1b4a64aced233c9afe29\" }, \"light_logo\": { \"url\": \"https://www.contoso.com/light_logo.png\", \"hash\": \"517d286edb416bb2625ccfcba9de78296e90da8e32330d4c9c8275c4c1c33737\" } }\n\nYou configure this policy by specifying the URL from which Microsoft Edge can download the logo and its cryptographic hash (SHA-256), which is used to verify the integrity of the download. The logo must be in PNG or SVG format, and its file size must not exceed 16 MB. The logo is downloaded and cached, and it will be redownloaded whenever the URL or the hash changes. The URL must be accessible without any authentication.\n\nThe 'default_logo' is required and used when there's no background image. If 'light_logo' is provided, it's used when the user's new tab page has a background image. We recommend a horizontal logo with a transparent background that's left-aligned and vertically centered. The logo should have a minimum height of 32 pixels and an aspect ratio from 1:1 to 4:1. The 'default_logo' should have proper contrast against a white/black background, while the 'light_logo' should have proper contrast against a background image.\n\nIf you enable this policy, Microsoft Edge downloads and shows the specified logo(s) on the new tab page. Users can't override or hide the logo(s).\n\nIf you disable or don't configure this policy, Microsoft Edge shows no company logo or a Microsoft logo on the new tab page.\n\nFor help with determining the SHA-256 hash, see [Get-FileHash](/powershell/module/microsoft.powershell.utility/get-filehash).","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogobackplatecolor","displayName":"Set the company logo backplate color on the new tab page.","description":"By default, the new tab page sets the company logo backplate color to the neutralStrokeActive (#cecece) constant.\n\nYou can configure this policy with a color hex code to change the company logo backplate color on the new tab page.\n\nIf this policy isn't configured, the default neutralStrokeActive (#cecece) color is used as the backplate color.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogoenabled","displayName":"Hide the company logo on the Microsoft Edge new tab page","description":"By default, the company logo is shown on the new tab page if the company logo is configured in Admin Portal.\n\nIf you enable or don't configure this policy, there's no change on the Microsoft Edge new tab page and the company logo is there for users.\n\nIf you disable this policy, the company logo doesn't appear on Microsoft Edge new tab page.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogoenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogoenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecontentenabled","displayName":"Allow Microsoft content on the new tab page","description":"This policy applies for Microsoft Edge to all profile types, namely unsigned local user profiles, profiles signed in using a Microsoft Account, profiles signed in using Active Directory, and profiles signed in using Microsoft Entra ID. The Enterprise new tab page for profiles signed in using Microsoft Entra ID can be configured in the Microsoft 365 admin portal, but this policy setting takes precedence; therefore, any Microsoft 365 admin portal configurations are ignored.\n\nIf you enable or don't configure this policy, Microsoft Edge displays Microsoft content on the new tab page. The user can choose different display options for the content. These options include, but aren't limited to: \"Content off\", \"Content visible on scroll\", \"Headings only\", and \"Content visible\". Enabling this policy doesn't force content to be visible - the users can keep setting their own preferred content position.\n\nIf you disable this policy, Microsoft Edge doesn't display Microsoft content on the new tab page. The Content control in the NTP settings flyout is disabled and set to \"Content off\", and the Layout control in the NTP settings flyout is disabled and set to \"Custom\".\n\nRelated policies: \"NewTabPageAllowedBackgroundTypes\", \"NewTabPageQuickLinksEnabled\"","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecontentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecontentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagehidedefaulttopsites","displayName":"Hide the default top sites from the new tab page","description":"Hides the default top sites from the new tab page in Microsoft Edge.\n\nIf you set this policy to true, the default top site tiles are hidden.\n\nIf you set this policy to false or don't configure it, the default top site tiles remain visible.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagehidedefaulttopsites_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagehidedefaulttopsites_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagelocation","displayName":"Configure the new tab page URL","description":"Configures the default URL for the new tab page.\n\nThe recommended version of this policy doesn't currently work and functions exactly like the mandatory version.\n\nThis policy determines the page that opens when new tabs are created (including when new windows are opened). It also affects the startup page if this page opens to the new tab page.\n\nThis policy doesn't determine which page opens on startup; that factor is controlled by the \"RestoreOnStartup\" policy. It also doesn't affect the home page if this home page opens to the new tab page.\n\nIf you don't configure this policy, the default new tab page is used.\n\nIf you configure this policy *and* the \"NewTabPageSetFeedType\" policy, this policy takes precedence.\n\nIf a blank tab is preferred, \"about:blank\" is the correct URL to use, not \"about://blank\".\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or joined to instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagelocation_recommended","displayName":"Configure the new tab page URL (users can override)","description":"Configures the default URL for the new tab page.\n\nThe recommended version of this policy doesn't currently work and functions exactly like the mandatory version.\n\nThis policy determines the page that opens when new tabs are created (including when new windows are opened). It also affects the startup page if this page opens to the new tab page.\n\nThis policy doesn't determine which page opens on startup; that factor is controlled by the \"RestoreOnStartup\" policy. It also doesn't affect the home page if this home page opens to the new tab page.\n\nIf you don't configure this policy, the default new tab page is used.\n\nIf you configure this policy *and* the \"NewTabPageSetFeedType\" policy, this policy takes precedence.\n\nIf a blank tab is preferred, \"about:blank\" is the correct URL to use, not \"about://blank\".\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or joined to instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagemanagedquicklinks","displayName":"Set new tab page quick links","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\n\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\n\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' isn't provided, the URL is used as the default title. If 'pinned' isn't provided, the default value is false.\n\nMicrosoft Edge presents these tiles in the order listed, from left to right, with all pinned tiles displayed ahead of nonpinned tiles.\n\nIf you set this policy as mandatory, the 'pinned' field is ignored and all tiles are pinned. The tiles can't be deleted by the user and always appear at the front of the quick links list.\n\nIf you set this policy as recommended, pinned tiles remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying nonpinned links via this policy to an existing browser profile, the links don't appear at all, depending on how they rank compared to the user's browsing history.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagemanagedquicklinks_recommended","displayName":"Set new tab page quick links (users can override)","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\n\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\n\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' isn't provided, the URL is used as the default title. If 'pinned' isn't provided, the default value is false.\n\nMicrosoft Edge presents these tiles in the order listed, from left to right, with all pinned tiles displayed ahead of nonpinned tiles.\n\nIf you set this policy as mandatory, the 'pinned' field is ignored and all tiles are pinned. The tiles can't be deleted by the user and always appear at the front of the quick links list.\n\nIf you set this policy as recommended, pinned tiles remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying nonpinned links via this policy to an existing browser profile, the links don't appear at all, depending on how they rank compared to the user's browsing history.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled","displayName":"Enable preload of the new tab page for faster rendering","description":"If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_recommended","displayName":"Enable preload of the new tab page for faster rendering (users can override)","description":"If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagequicklinksenabled","displayName":"Allow quick links on the new tab page","description":"If you enable or don't configure this policy, Microsoft Edge displays quick links on the new tab page, and the user can interact with the control, turning quick links on and off. Enabling this policy doesn't force quick links to be visible - the user can continue to turn quick links on and off.\n\nIf you disable this policy, Microsoft Edge hides quick links on the new tab page and disables the quick links control in the NTP settings flyout.\n\nThis policy only applies for Microsoft Edge local user profiles, profiles signed in using a Microsoft Account, and profiles signed in using Active Directory. To configure the Enterprise new tab page for profiles signed in using Azure Active Directory, use the M365 admin portal.\n\nRelated policies: \"NewTabPageAllowedBackgroundTypes\", \"NewTabPageContentEnabled\"","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagequicklinksenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagequicklinksenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox","displayName":"Configure the new tab page search box experience","description":"You can configure the new tab page search box to use \"Search box (Recommended)\" or \"Address bar\" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\".\n\n If you disable or don't configure this policy and:\n\n- If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.\n- If the address bar default search engine isn't Bing, users are offered an additional choice (use \"Address bar\") when searching on new tabs.\n\n\nIf you enable this policy and set it to:\n\n- \"Search box (Recommended)\" ('bing'), the new tab page uses the search box to search on new tabs.\n- \"Address bar\" ('redirect'), the new tab page search box uses the address bar to search on new tabs.\n\nPolicy options mapping:\n\n* bing (bing) = Search box (Recommended)\n\n* redirect (redirect) = Address bar\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_bing","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_redirect","displayName":"Address bar","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_recommended","displayName":"Configure the new tab page search box experience (users can override)","description":"You can configure the new tab page search box to use \"Search box (Recommended)\" or \"Address bar\" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\".\n\n If you disable or don't configure this policy and:\n\n- If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.\n- If the address bar default search engine isn't Bing, users are offered an additional choice (use \"Address bar\") when searching on new tabs.\n\n\nIf you enable this policy and set it to:\n\n- \"Search box (Recommended)\" ('bing'), the new tab page uses the search box to search on new tabs.\n- \"Address bar\" ('redirect'), the new tab page search box uses the address bar to search on new tabs.\n\nPolicy options mapping:\n\n* bing (bing) = Search box (Recommended)\n\n* redirect (redirect) = Address bar\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_recommended_bing","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_recommended_redirect","displayName":"Address bar","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype","displayName":"Configure the Microsoft Edge new tab page experience (Obsolete)","description":"This policy is obsolete because the new version of the enterprise new tab page no longer requires choosing between different content types. Instead, the content that's presented to the user can be controlled via the Microsoft 365 admin center. To get to the Microsoft 365 admin center, sign in at https://admin.microsoft.com with your admin account.\n\nLets you choose either the Microsoft News or Office 365 feed experience for the new tab page.\n\nIf you set this policy to 'News', users see the Microsoft News feed experience on the new tab page.\n\nIf you set this policy to 'Office', users with an Azure Active Directory browser sign-in see the Office 365 feed experience on the new tab page.\n\nIf you disable or don't configure this policy, users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, and the standard new tab page feed experience. Users without an Azure Active Directory browser sign-in to see the standard new tab page experience.\n\nIf you enable this policy *and* the \"NewTabPageLocation\" policy, \"NewTabPageLocation\" has precedence.\n\nPolicy options mapping:\n\n* News (0) = Microsoft News feed experience\n\n* Office (1) = Office 365 feed experience\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_news","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_office","displayName":"Office 365 feed experience","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_recommended","displayName":"Configure the Microsoft Edge new tab page experience (Obsolete) (users can override)","description":"This policy is obsolete because the new version of the enterprise new tab page no longer requires choosing between different content types. Instead, the content that's presented to the user can be controlled via the Microsoft 365 admin center. To get to the Microsoft 365 admin center, sign in at https://admin.microsoft.com with your admin account.\n\nLets you choose either the Microsoft News or Office 365 feed experience for the new tab page.\n\nIf you set this policy to 'News', users see the Microsoft News feed experience on the new tab page.\n\nIf you set this policy to 'Office', users with an Azure Active Directory browser sign-in see the Office 365 feed experience on the new tab page.\n\nIf you disable or don't configure this policy, users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, and the standard new tab page feed experience. Users without an Azure Active Directory browser sign-in to see the standard new tab page experience.\n\nIf you enable this policy *and* the \"NewTabPageLocation\" policy, \"NewTabPageLocation\" has precedence.\n\nPolicy options mapping:\n\n* News (0) = Microsoft News feed experience\n\n* Office (1) = Office 365 feed experience\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_recommended_news","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_recommended_office","displayName":"Office 365 feed experience","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.notificationsallowedforurls","displayName":"Allow notifications on specific sites","description":"Allows you to create a list of URL patterns to specify sites that are allowed to display notifications.\n\nIf you don't set this policy, the global default value is used for all sites. This default value is from the \"DefaultNotificationsSetting\" policy if set, or from the user's personal configuration. For detailed information on valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.notificationsblockedforurls","displayName":"Block notifications on specific sites","description":"Allows you to create a list of url patterns to specify sites that aren't allowed to display notifications.\n\nIf you don't set this policy, the global default value is used for all sites. This default value is from the \"DefaultNotificationsSetting\" policy if it's set, or from the user's personal configuration. For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.onbulkdataentryenterpriseconnector","displayName":"Configuration policy for bulk data entry for Microsoft Edge for Business Data Loss Prevention Connectors","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when data is entered in Microsoft Edge from the clipboard or by drag and dropping web content.\n\nConnector Fields\n\n1. url_list,\ntags,\nenable,\ndisable\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\nAnalysis is triggered if at least one tag is included in the request.\n\n2. service_provider\nIdentifies the analysis service provider the configuration applies to.\n\n3. block_until_verdict\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\nAny other integer value allows the page to access the data immediately.\n\n4. default_action\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\nAny other value permits the page to access the data.\n\n5. minimum_data_size\nSpecifies the minimum size (in bytes) that the entered data must meet or exceed to be scanned.\nDefault: 100 bytes if the field isn't set.\n\nThis policy requires further setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.onfileattachedenterpriseconnector","displayName":"Configuration policy for files attached for Microsoft Edge for Business Data Loss Prevention Connectors","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when a file is attached to Microsoft Edge.\n\nConnector Fields\n\n1. url_list,\ntags,\nenable,\ndisable\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\nAnalysis is triggered if at least one tag is included in the request.\n\n2. service_provider\nIdentifies the analysis service provider the configuration applies to.\n\n3. block_until_verdict\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\nAny other integer value allows the page to access the data immediately.\n\n4. default_action\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\nAny other value permits the page to access the data.\n\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.onprintenterpriseconnector","displayName":"Configuration policy for print for Microsoft Edge for Business Data Loss Prevention Connectors","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when a page or file is printed from Microsoft Edge.\n\nConnector Fields\n\n1. url_list,\ntags,\nenable,\ndisable\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\nAnalysis is triggered if at least one tag is included in the request.\n\n2. service_provider\nIdentifies the analysis service provider the configuration applies to.\n\n3. block_until_verdict\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\nAny other integer value allows the page to access the data immediately.\n\n4. default_action\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\nAny other value permits the page to access the data.\n\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.onsecurityevententerpriseconnector","displayName":"Configuration policy for Microsoft Edge for Business Reporting Connectors","description":"Defines the Microsoft Edge for Business Reporting Connectors service settings that apply when a security event occurs in Microsoft Edge. These events include negative verdicts from Data Loss Prevention Connectors, password reuse, navigation to unsafe pages, and other security-sensitive actions.\n\nThe service_provider field specifies the reporting service provider. The enabled_event_names field lists the security events enabled for that provider.\n\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2325446.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.organizationalbrandingonworkprofileuienabled_recommended","displayName":"Allow the use of your organization's branding assets from Microsoft Entra on the profile-related UI of a work or school profile (users can override)","description":"Allow the use of your organization's branding assets from Entra, if any, on the profile-related UI of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect.\n\nIf you enable this policy, your organization's branding assets from Entra are used.\n\nIf you disable or don't configure this policy, your organization's branding assets from Entra aren't used.\n\nFor more information about configuring your organization's branding assets on Entra, visit https://go.microsoft.com/fwlink/?linkid=2254514.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.organizationalbrandingonworkprofileuienabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.organizationalbrandingonworkprofileuienabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.organizationlogooverlayonappiconenabled_recommended","displayName":"Allow your organization's logo from Microsoft Entra to be overlaid on the Microsoft Edge app icon of a work or school profile (users can override)","description":"Allows your organization's logo from Entra, if any, to be overlaid on the Microsoft Edge app icon of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect.\n\nIf you enable this policy, your organization's logo from Entra is used.\n\nIf you disable or don't configure this policy, your organization's logo from Entra won't be used.\n\nFor more information about configuring your organization's logo on Entra, visit https://go.microsoft.com/fwlink/?linkid=2254514.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.organizationlogooverlayonappiconenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.organizationlogooverlayonappiconenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.originagentclusterdefaultenabled","displayName":"Origin-keyed agent clustering enabled by default","description":"The Origin-Agent-Cluster: HTTP header controls whether a document is isolated in an origin-keyed agent cluster or in a site-keyed agent cluster. This functionality has security implications because an origin-keyed agent cluster allows isolating documents by origin. The consequence of this for developers is that the document.domain accessor can no longer be set when origin-keyed agent clustering is enabled.\n\nIf you enable or don't configure this policy, documents without the Origin-Agent-Cluster: header are assigned to origin-keyed agent clustering by default. On these documents, the document.domain accessor isn't settable.\n\nIf you disable this policy, documents without the Origin-Agent-Cluster: header are assigned to site-keyed agent clusters by default. On these documents, the document.domain accessor is settable.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2191896.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.originagentclusterdefaultenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.originagentclusterdefaultenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.outlookhubmenuenabled","displayName":"Allow users to access the Outlook menu (Obsolete)","description":"This policy doesn't work because the Outlook menu is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy.\n\nThis policy is used to manage access to the Outlook menu from Microsoft Edge.\n\nIf you enable or don't configure this policy, users can access the Outlook menu.\nIf you disable this policy, users can't access the Outlook menu.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.outlookhubmenuenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.outlookhubmenuenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.outlookhubmenuenabled_recommended","displayName":"Allow users to access the Outlook menu (Obsolete) (users can override)","description":"This policy doesn't work because the Outlook menu is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy.\n\nThis policy is used to manage access to the Outlook menu from Microsoft Edge.\n\nIf you enable or don't configure this policy, users can access the Outlook menu.\nIf you disable this policy, users can't access the Outlook menu.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.outlookhubmenuenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.outlookhubmenuenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.partitionedbloburlusage","displayName":"Manage Blob URL Partitioning During Fetching and Navigation","description":"The \"PartitionedBlobUrlUsage\" policy controls whether Blob URLs are partitioned during fetching and navigation.\nIf this policy is set to Enabled or not set, Blob URLs are partitioned.\nIf this policy is set to Disabled, Blob URLs can't be partitioned. This represents the Blob URL behavior before Microsoft Edge version 135.\n\nThe policy is scheduled to be available through Microsoft Edge version 146. After this version, the policy will be removed, and Microsoft Edge will no longer support unpartitioned blob storage.\n\nFor detailed information on third-party storage partitioning, see https://github.com/privacycg/storage-partitioning.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.partitionedbloburlusage_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.partitionedbloburlusage_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when the \"ClearBrowsingDataOnExit\" policy is enabled.\n\nIf you enable this policy, passwords aren't cleared when the browser closes.\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_recommended","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes (users can override)","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when the \"ClearBrowsingDataOnExit\" policy is enabled.\n\nIf you enable this policy, passwords aren't cleared when the browser closes.\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordexportenabled","displayName":"Enable exporting saved passwords from Password Manager","description":"This policy controls whether the Export Password button in edge://wallet/passwords is enabled.\n\nIf enabled or not configured, users can export saved passwords.\nIf disabled, the Export Password button is unavailable, preventing password exports.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordexportenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordexportenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordgeneratorenabled","displayName":"Allow users to get a strong password suggestion whenever they are creating an account online","description":"Configures the Password Generator Settings toggle that enables/disables the feature for users.\n\nIf you enable or don't configure this policy, then Password Generator offers users a strong and unique password suggestion (via a dropdown) on Signup and Change Password pages.\n\nIf you disable this policy, users no longer see strong password suggestions on Signup or Change Password pages.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordgeneratorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordgeneratorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerblocklist","displayName":"Configure the list of domains for which the password manager UI (Save and Fill) will be disabled","description":"Configure the list of domains where Microsoft Edge should disable the password manager. This means that Save and Fill workflows are disabled, ensuring that passwords for those websites can't be saved or auto filled into web forms.\n\nIf you enable this policy, the password manager is disabled for the specified set of domains.\n\nIf you disable or don't configure this policy, password manager works as usual for all domains.\n\nIf you configure this policy, that is, add domains for which password manager is blocked, users can't change or override the behavior in Microsoft Edge. In addition, users can't use password manager for those URLs.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerenabled","displayName":"Enable saving passwords to the password manager","description":"Enable Microsoft Edge to save user passwords. The next time a user visits a site with a saved password, Microsoft Edge will enter the password automatically.\n\nIf you enable or don't configure this policy, users can save and add their passwords in Microsoft Edge.\n\nIf you disable this policy, users can't save and add new passwords, but they can still use previously saved passwords.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerenabled_recommended","displayName":"Enable saving passwords to the password manager (users can override)","description":"Enable Microsoft Edge to save user passwords. The next time a user visits a site with a saved password, Microsoft Edge will enter the password automatically.\n\nIf you enable or don't configure this policy, users can save and add their passwords in Microsoft Edge.\n\nIf you disable this policy, users can't save and add new passwords, but they can still use previously saved passwords.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerpasskeysenabled","displayName":"Enable saving passkeys to the password manager","description":"This policy controls whether users can save passkeys in the built-in password manager. It does not limit access to, or change the contents of, passkeys already saved in the password manager.\n\nIf the PasswordManagerEnabled policy is Disabled, saving to the built-in password manager is disabled in general, including passkeys. In this case, this policy has no effect.\n\nIf this policy is enabled or not configured, users can save passkeys in the built-in password manager when signed in to Microsoft Edge.\n\nIf this policy is disabled, users cannot save new passkeys to the built-in password manager. Previously saved passkeys continue to work.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerpasskeysenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerpasskeysenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerrestrictlengthenabled","displayName":"Restrict the length of passwords that can be saved in the Password Manager","description":"Make Microsoft Edge restrict the length of usernames and/or passwords that can be saved in the Password Manager.\n\nIf you enable this policy, Microsoft Edge doesn't let the user save credentials with usernames and/or passwords longer than 256 characters.\n\nIf you disable or don't configure this policy, Microsoft Edge lets the user save credentials with arbitrarily long usernames and/or passwords.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerrestrictlengthenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmanagerrestrictlengthenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmonitorallowed","displayName":"Allow users to be alerted if their passwords are found to be unsafe","description":"Allow Microsoft Edge to monitor user passwords.\n\nIf you enable this policy, the user gets alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\n\nIf you disable this policy, users aren't asked for permission to enable this feature. Their passwords aren't scanned, and they aren't alerted either.\n\nIf you don't configure the policy, users can turn this feature on or off.\n\nTo learn more about how Microsoft Edge finds unsafe passwords see https://go.microsoft.com/fwlink/?linkid=2133833\n\nAdditional guidance:\n\nThis policy can be set as both Recommended and Mandatory, however with an important callout.\n\nMandatory enabled: If the policy is set to Mandatory enabled, the UI in Settings will be disabled but remain in 'On' state, and a briefcase icon will be made visible next to it with this description displayed on hover - \"This setting is managed by your organization.\"\n\nRecommended enabled: If the policy is set to Recommended enabled, the UI in Settings will remain in 'Off' state, but a briefcase icon will be made visible next to it with this description displayed on hover - \"Your organization recommends a specific value for this setting and you have chosen a different value\"\n\nMandatory and Recommended disabled: Both these states will work the normal way, with the usual captions being shown to users.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmonitorallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmonitorallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmonitorallowed_recommended","displayName":"Allow users to be alerted if their passwords are found to be unsafe (users can override)","description":"Allow Microsoft Edge to monitor user passwords.\n\nIf you enable this policy, the user gets alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\n\nIf you disable this policy, users aren't asked for permission to enable this feature. Their passwords aren't scanned, and they aren't alerted either.\n\nIf you don't configure the policy, users can turn this feature on or off.\n\nTo learn more about how Microsoft Edge finds unsafe passwords see https://go.microsoft.com/fwlink/?linkid=2133833\n\nAdditional guidance:\n\nThis policy can be set as both Recommended and Mandatory, however with an important callout.\n\nMandatory enabled: If the policy is set to Mandatory enabled, the UI in Settings will be disabled but remain in 'On' state, and a briefcase icon will be made visible next to it with this description displayed on hover - \"This setting is managed by your organization.\"\n\nRecommended enabled: If the policy is set to Recommended enabled, the UI in Settings will remain in 'Off' state, but a briefcase icon will be made visible next to it with this description displayed on hover - \"Your organization recommends a specific value for this setting and you have chosen a different value\"\n\nMandatory and Recommended disabled: Both these states will work the normal way, with the usual captions being shown to users.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmonitorallowed_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordmonitorallowed_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordprotectionchangepasswordurl","displayName":"Configure the change password URL","description":"Configures the change password URL (HTTP and HTTPS schemes only).\n\nPassword protection service will send users to this URL to change their password after seeing a warning in the browser.\n\nIf you enable this policy, then password protection service sends users to this URL to change their password.\n\nIf you disable this policy or don't configure it, then password protection service can't redirect users to a change password URL.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordprotectionloginurls","displayName":"Configure the list of enterprise login URLs where the password protection service should capture salted hashes of a password","description":"Configure the list of enterprise login URLs (HTTP and HTTPS schemes only) where Microsoft Edge should capture the salted hashes of passwords and use it for password reuse detection.\n\nIf you enable this policy, the password protection service captures fingerprints of passwords on the defined URLs.\n\nIf you disable this policy or don't configure it, no password fingerprints are captured.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordprotectionwarningtrigger","displayName":"Configure password protection warning trigger","description":"Allows you to control when to trigger password protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites.\n\nYou can use the \"PasswordProtectionLoginURLs\" and \"PasswordProtectionChangePasswordURL\" policies to configure which passwords to protect.\n\nExemptions: Passwords for the sites listed in \"PasswordProtectionLoginURLs\" and \"PasswordProtectionChangePasswordURL\", and for the sites listed in \"SmartScreenAllowListDomains\", don't trigger a password-protection warning.\n\nSet to PasswordProtectionWarningOff to not show password protection warnings.\n\nSet to PasswordProtectionWarningOnPasswordReuse to show password protection warnings when the users reuse their protected password on a non-allowlisted site.\n\nIf you disable or don't configure this policy, then the warning trigger isn't shown.\n\nPolicy options mapping:\n\n* PasswordProtectionWarningOff (0) = Password protection warning is off\n\n* PasswordProtectionWarningOnPasswordReuse (1) = Password protection warning is triggered by password reuse\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordprotectionwarningtrigger_passwordprotectionwarningoff","displayName":"Password protection warning is off","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordprotectionwarningtrigger_passwordprotectionwarningonpasswordreuse","displayName":"Password protection warning is triggered by password reuse","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordrevealenabled","displayName":"Enable Password reveal button","description":"Lets you configure the default display of the browser password reveal button for password input fields on websites.\n\nIf you enable or don't configure this policy, the browser user setting defaults to displaying the password reveal button.\n\nIf you disable this policy, the browser user setting won't display the password reveal button.\n\nFor accessibility, users can change the browser setting from the default policy.\n\nThis policy only affects the browser password reveal button, it doesn't affect websites' custom reveal buttons.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordrevealenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordrevealenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordrevealenabled_recommended","displayName":"Enable Password reveal button (users can override)","description":"Lets you configure the default display of the browser password reveal button for password input fields on websites.\n\nIf you enable or don't configure this policy, the browser user setting defaults to displaying the password reveal button.\n\nIf you disable this policy, the browser user setting can't display the password reveal button.\n\nFor accessibility, users can change the browser setting from the default policy.\n\nThis policy only affects the browser password reveal button but doesn't affect websites' custom reveal buttons.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordrevealenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passwordrevealenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.paymentmethodqueryenabled","displayName":"Allow websites to query for available payment methods","description":"Allows you to set whether websites can check if the user has payment methods saved.\n\nIf you disable this policy, websites that use PaymentRequest.canMakePayment or PaymentRequest.hasEnrolledInstrument API will be informed that no payment methods are available.\n\nIf you enable this policy or don't set this policy, websites can check if the user has payment methods saved.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.paymentmethodqueryenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.paymentmethodqueryenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdflocalfileaccessallowedfordomains","displayName":"Allow specified sites to access file:// URLs in the PDF Viewer","description":"Controls which sites can access file:// URLs in the PDF Viewer.\n\nIf you enable this policy, sites in the list can access file:// URLs in the PDF Viewer.\n\nIf you disable or don't configure this policy, sites cannot access file:// URLs in the PDF Viewer.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfsecuremode","displayName":"Secure mode and Certificate-based Digital Signature validation in native PDF reader","description":"The policy enables Digital Signature validation for PDF files in a secure environment, which shows the correct validation status of the signatures.\n\nIf you enable this policy, PDF files with Certificate-based digital signatures are opened with an option to view and verify the validity of the signatures with high security.\n\nIf you disable or don't configure this policy, the capability to view and verify the signature isn't available.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfsecuremode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfsecuremode_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfvieweroutofprocessiframeenabled","displayName":"Use out-of-process iframe PDF Viewer","description":"Determines whether the PDF viewer in Microsoft Edge uses an out-of-process iframe (OOPIF).\nThis is the new PDF viewer architecture going forward, as it's simpler in design and makes adding new features easier. The current GuestView PDF viewer, which relies on an outdated and overly complex architecture, is being deprecated.\n\nIf you enable this policy or don't configure it, Microsoft Edge uses the OOPIF PDF viewer architecture. The default behavior will be decided by Microsoft Edge.\n\nIf you disable this policy, Microsoft Edge strictly uses the existing GuestView PDF viewer. This approach embeds a web page with its own separate frame tree into another web page.\n\nThis policy will be removed in the future, after the OOPIF PDF viewer feature has fully rolled out.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfvieweroutofprocessiframeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfvieweroutofprocessiframeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfxfaenabled","displayName":"XFA support in native PDF reader enabled","description":"Lets the Microsoft Edge browser enable XFA (XML Forms Architecture) support in the native PDF reader and allows users to open XFA PDF files in the browser.\n\nIf you enable this policy, XFA support in the native PDF reader is enabled.\n\nIf you disable or don't configure this policy, Microsoft Edge won't enable XFA support in the native PDF reader.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfxfaenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pdfxfaenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled","displayName":"Performance Detector Enabled","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\n\nIf you enable or don't configure this policy, performance detector is turned on.\n\nIf you disable this policy, performance detector is turned off.\n\nThe user can configure its behavior in edge://settings/system.\n\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_recommended","displayName":"Performance Detector Enabled (users can override)","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\n\nIf you enable or don't configure this policy, performance detector is turned on.\n\nIf you disable this policy, performance detector is turned off.\n\nThe user can configure its behavior in edge://settings/system.\n\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.personalizationreportingenabled","displayName":"Allow personalization of ads, Microsoft Edge, search, news and other Microsoft services by sending browsing history, favorites and collections, usage and other browsing data to Microsoft","description":"This policy prevents Microsoft from collecting a user's Microsoft Edge browsing history, favorites and collections, usage, and other browsing data to be used for personalizing advertising, search, news, Microsoft Edge, and other Microsoft services.\n\nThis setting isn't available for child accounts or enterprise accounts.\n\nIf you disable this policy, users can't change or override the setting. If this policy is enabled or not configured, Microsoft Edge defaults to the user's preference.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.personalizationreportingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.personalizationreportingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.personalizetopsitesincustomizesidebarenabled","displayName":"Personalize my top sites in Customize Sidebar enabled by default","description":"This policy controls whether Microsoft Edge browser be allowed to use the browsing history to personalize the top sites in the customize sidebar page.\n\nIf you enable this policy, Microsoft Edge uses the browsing history to personalize the top sites in the customize sidebar page.\n\nIf you disable this policy, Microsoft Edge doesn't use the browsing history to personalize the top sites in the customize sidebar page.\n\nIf you don't configure this policy, the default behavior is to use the browsing history to personalize the top sites in the customize sidebar page.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.personalizetopsitesincustomizesidebarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.personalizetopsitesincustomizesidebarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\n\nThe Picture in Picture floating overlay button lets the user watch videos in a floating window on top of other windows.\n\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\n\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pictureinpictureoverlayenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pictureinpictureoverlayenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pinbrowseressentialstoolbarbutton","displayName":"Pin browser essentials toolbar button","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\n\nWhen the button is pinned, it always appears on the toolbar.\n\nWhen the button isn't pinned, it only appears when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\n\nIf you enable or don't configure this policy, the Browser essentials button is pinned on the toolbar.\n\nIf you disable this policy, the Browser essentials button isn't pinned on the toolbar.\n\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pinbrowseressentialstoolbarbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pinbrowseressentialstoolbarbutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pinbrowseressentialstoolbarbutton_recommended","displayName":"Pin browser essentials toolbar button (users can override)","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\n\nWhen the button is pinned, it always appears on the toolbar.\n\nWhen the button isn't pinned, it only appears when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\n\nIf you enable or don't configure this policy, the Browser essentials button is pinned on the toolbar.\n\nIf you disable this policy, the Browser essentials button isn't pinned on the toolbar.\n\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pinbrowseressentialstoolbarbutton_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pinbrowseressentialstoolbarbutton_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pluginsallowedforurls","displayName":"Allow the Adobe Flash plug-in on specific sites (Obsolete)","description":"This policy doesn't work because Flash is no longer supported by Microsoft Edge.\n\nDefine a list of sites, based on URL patterns, that can run the Adobe Flash plug-in.\n\nIf you don't configure this policy, the global default value from the \"DefaultPluginsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. However, starting in M85, patterns with '*' and '[*.]' wildcards in the host are no longer supported for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pluginsblockedforurls","displayName":"Block the Adobe Flash plug-in on specific sites (Obsolete)","description":"This policy doesn't work because Flash is no longer supported by Microsoft Edge.\n\nDefine a list of sites, based on URL patterns, that are blocked from running Adobe Flash.\n\nIf you don't configure this policy, the global default value from the \"DefaultPluginsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. However, starting in M85, patterns with '*' and '[*.]' wildcards in the host are no longer supported for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.popupsallowedforurls","displayName":"Allow pop-up windows on specific sites","description":"Define a list of sites, based on URL patterns, that can open pop-up windows. Wildcards (*) are allowed.\n\nIf you don't configure this policy, the global default value from the \"DefaultPopupsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.popupsblockedforurls","displayName":"Block pop-up windows on specific sites","description":"Define a list of sites, based on URL patterns, that are blocked from opening pop-up windows. Wildcards (*) are allowed.\n\nIf you don't configure this policy, the global default value from the \"DefaultPopupsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.precisegeolocationallowedforurls","displayName":"Allow precise geolocation on these sites","description":"This policy lets you specify a list of URL patterns for sites that are allowed to access the user's high-accuracy geolocation without prompting for permission.\n\nIf you leave this policy unset, DefaultGeolocationSetting applies to all sites (if configured). Otherwise, the user's personal setting is used.\n\nFor information about valid url patterns, see https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format. Wildcards (*) are supported.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.prefetchwithserviceworkerenabled","displayName":"Allow SpeculationRules prefetch for ServiceWorker-controlled URLs","description":"Controls whether SpeculationRules prefetch requests are allowed for\nServiceWorker-controlled URLs.\n\nWith Microsoft Edge version 138,\nprefetch requests to ServiceWorker-controlled URLs are allowed by default when\nthe PrefetchServiceWorker feature is enabled.\n\nIf this policy is enabled or not configured, that default behavior is used.\n\nTo restore the legacy behavior from versions before 138, where prefetch requests\nto ServiceWorker-controlled URLs were blocked, set this policy to disabled.\n\nThis policy is intended to be temporary and will be removed in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.prefetchwithserviceworkerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.prefetchwithserviceworkerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventsmartscreenpromptoverride","displayName":"Prevent bypassing Microsoft Defender SmartScreen prompts for sites","description":"This policy setting lets you decide whether users can override the Microsoft Defender SmartScreen warnings about potentially malicious websites.\n\nIf you enable this setting, users can't ignore Microsoft Defender SmartScreen warnings and they're blocked from continuing to the site.\n\nIf you disable or don't configure this setting, users can ignore Microsoft Defender SmartScreen warnings and continue to the site.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventsmartscreenpromptoverride_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventsmartscreenpromptoverride_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventsmartscreenpromptoverrideforfiles","displayName":"Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads","description":"This policy lets you determine whether users can override Microsoft Defender SmartScreen warnings about unverified downloads.\n\nIf you enable this policy, users in your organization can't ignore Microsoft Defender SmartScreen warnings, and they're prevented from completing the unverified downloads.\n\nIf you disable or don't configure this policy, users can ignore Microsoft Defender SmartScreen warnings and complete unverified downloads.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventsmartscreenpromptoverrideforfiles_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventsmartscreenpromptoverrideforfiles_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventtyposquattingpromptoverride","displayName":"Prevent bypassing Edge Website Typo Protection prompts for sites","description":"This policy setting lets you decide whether users can override the Edge Website Typo Protection warnings about potential typosquatting websites.\n\nIf you enable this setting, users can't ignore Edge Website Typo Protection warnings, and they're blocked from continuing to the site.\n\nIf you disable or don't configure this setting, users can ignore Edge Website Typo Protection warnings and continue to the site.\n\nThis only takes effect when TyposquattingCheckerEnabled policy isn't set or is set to enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventtyposquattingpromptoverride_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventtyposquattingpromptoverride_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill","description":"This feature helps users add an additional layer of privacy to their online accounts by requiring device authentication (as a way of confirming the user's identity) before the saved password is autofilled into a web form. This layer ensures that non-authorized persons can't use saved passwords for autofill. This feature doesn't protect against locally running malware.\n\nThis group policy configures the radio button selector that enables this feature for users. It also has a frequency control where users can specify how often they would like to be prompted for authentication.\n\nIf you set this policy to 'Automatically', disable this policy, or don't configure this policy, autofill won't have any authentication flow.\n\nIf you set this policy to 'WithDevicePassword', users have to enter their device password (or preferred mode of authentication under Windows) to prove their identity before their password is autofilled. Authentication modes include Windows Hello, PIN, face recognition, or fingerprint. The frequency for authentication prompt is set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\n\nIf you set this policy to 'WithCustomPrimaryPassword', users are asked to create their custom password and to be redirected to Settings. After the custom password is set, users can authenticate themselves using the custom password and their passwords get autofilled after successful authentication. The frequency for authentication prompt is set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\n\nIf you set this policy to 'AutofillOff', saved passwords are no longer suggested for autofill.\n\nThe Custom Primary Password feature will be removed with Edge 149. From this version onward, the Custom Primary Password option will no longer be available. Users who currently have this setting enabled will be automatically migrated to the \"Prompt for the device sign-in options\" authentication method. Any associated group policies for Custom Primary Password will also be marked as obsolete.\n\nPolicy options mapping:\n\n* Automatically (0) = Automatically\n\n* WithDevicePassword (1) = With device password\n\n* WithCustomPrimaryPassword (2) = With custom primary password\n\n* AutofillOff (3) = Autofill off\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.primarypasswordsetting_automatically","displayName":"Automatically","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.primarypasswordsetting_withdevicepassword","displayName":"With device password","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.primarypasswordsetting_withcustomprimarypassword","displayName":"With custom primary password","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.primarypasswordsetting_autofilloff","displayName":"Autofill off","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printertypedenylist","displayName":"Disable printer types on the deny list","description":"The printer types on the deny list aren't discovered or have their capabilities fetched.\n\nPlacing all printer types on the deny list effectively disables printing because there's no print destination for documents.\n\nIf you don't configure this policy, or the printer list is empty, all printer types are discoverable.\n\nPrinter destinations include extension printers and local printers. Extension printers are also known as print provider destinations, and include any destination that belongs to a Microsoft Edge extension.\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\n\nIn Microsoft version 93 or later, if you set this policy to 'pdf' it also disables the 'save as Pdf' option from the right click context menu.\n\nIn Microsoft version 103 or later, if you set this policy to 'onedrive' it also disables the 'save as Pdf (OneDrive)' option from print preview.\n\nPolicy options mapping:\n\n* privet (privet) = Zeroconf-based (mDNS + DNS-SD) protocol destinations\n\n* extension (extension) = Extension-based destinations\n\n* pdf (pdf) = The 'Save as PDF' destination. (93 or later, also disables from context menu)\n\n* local (local) = Local printer destinations\n\n* onedrive (onedrive) = Save as PDF (OneDrive) printer destinations. (103 or later)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printertypedenylist_privet","displayName":"Zeroconf-based (mDNS + DNS-SD) protocol destinations","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printertypedenylist_extension","displayName":"Extension-based destinations","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printertypedenylist_pdf","displayName":"The 'Save as PDF' destination. (93 or later, also disables from context menu)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printertypedenylist_local","displayName":"Local printer destinations","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printertypedenylist_onedrive","displayName":"Save as PDF (OneDrive) printer destinations. (103 or later)","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode","description":"Restricts background graphics printing mode. If this policy isn't set there's no restriction on printing background graphics.\n\nPolicy options mapping:\n\n* any (any) = Allow printing with and without background graphics\n\n* enabled (enabled) = Allow printing only with background graphics\n\n* disabled (disabled) = Allow printing only without background graphics\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes_any","displayName":"Allow printing with and without background graphics","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes_enabled","displayName":"Allow printing only with background graphics","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes_disabled","displayName":"Allow printing only without background graphics","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode","description":"Overrides the last used setting for printing background graphics.\nIf you enable this setting, background graphics printing is enabled.\nIf you disable this setting, background graphics printing is disabled.\n\nPolicy options mapping:\n\n* enabled (enabled) = Enable background graphics printing mode by default\n\n* disabled (disabled) = Disable background graphics printing mode by default\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingbackgroundgraphicsdefault_enabled","displayName":"Enable background graphics printing mode by default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingbackgroundgraphicsdefault_disabled","displayName":"Disable background graphics printing mode by default","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingenabled","displayName":"Enable printing","description":"Enables printing in Microsoft Edge and prevents users from changing this setting.\n\nIf you enable this policy or don't configure it, users can print.\n\nIf you disable this policy, users can't print from Microsoft Edge. Printing is disabled in the wrench menu, extensions, JavaScript applications, and so on. Users can still print from plug-ins that bypass Microsoft Edge while printing. For example, certain Adobe Flash applications have the print option in their context menu, which isn't covered by this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingpapersizedefault","displayName":"Default printing page size","description":"Overrides default printing page size.\n\nName should contain one of the listed formats or 'custom' if required paper size isn't in the list. If 'custom' value is provided custom_size property should be specified. It describes the desired height and width in micrometers. Otherwise custom_size property shouldn't be specified. Policy that violates these rules is ignored.\n\nIf the page size is unavailable on the printer chosen by the user, this policy is ignored.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout","displayName":"Sets layout for printing","description":"Configuring this policy sets the layout for printing webpages.\n\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\n\nIf you enable this policy, the selected option is set as the layout option.\n\nPolicy options mapping:\n\n* portrait (0) = Sets layout option as portrait\n\n* landscape (1) = Sets layout option as landscape\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_portrait","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_landscape","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_recommended","displayName":"Sets layout for printing (users can override)","description":"Configuring this policy sets the layout for printing webpages.\n\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\n\nIf you enable this policy, the selected option is set as the layout option.\n\nPolicy options mapping:\n\n* portrait (0) = Sets layout option as portrait\n\n* landscape (1) = Sets layout option as landscape\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_recommended_portrait","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_recommended_landscape","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpdfasimagedefault","displayName":"Print PDF as Image Default","description":"Controls if Microsoft Edge makes the Print as image option the default when printing PDFs.\n\nIf you enable this policy, Microsoft Edge defaults to setting the Print as image option in the Print Preview when printing a PDF.\n\nIf you disable or don't configure this policy, Microsoft Edge won't default to setting the Print as image option in the Print Preview when printing a PDF.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpdfasimagedefault_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpdfasimagedefault_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpostscriptmode","displayName":"Print PostScript Mode","description":"Controls how Microsoft Edge prints on Microsoft Windows.\n\nPrinting to a PostScript printer on Microsoft Windows different PostScript generation methods can affect printing performance.\n\nIf you set this policy to Default, Microsoft Edge uses a set of default options when generating PostScript. Text in particular, is always rendered using Type 3 fonts.\n\nIf you set this policy to Type42, Microsoft Edge renders text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\n\nIf you don't configure this policy, Microsoft Edge remains in Default mode.\n\nPolicy options mapping:\n\n* Default (0) = Default\n\n* Type42 (1) = Type42\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpostscriptmode_default","displayName":"Default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpostscriptmode_type42","displayName":"Type42","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewstickysettings","displayName":"Configure the sticky print preview settings","description":"Configuring this policy sets the print preview settings as the most recent choice in Print Preview instead of the default print preview settings.\n\nEach item of this policy expects a boolean:\n\nLayout specifies if the webpage layout should be kept sticky or not in print preview settings. If you set this to True, the webpage layout uses the recent choice; otherwise, it sets to default value.\n\nSize specifies if the page size should be kept sticky or not in print preview settings. If you set this to True, the page size uses the recent choice; otherwise, it sets to default value.\n\nScale Type specifies if the scaling percentage and scale type should be kept sticky or not in print preview settings. If you set this to True, the scale percentage and scale type both use the recent choice; otherwise, it will set to default value.\n\nMargins specifies if the page margin should be kept sticky or not in print preview settings. If you set this to True, the page margins use the recent choice; otherwise, it sets to default value.\n\nIf you enable this policy, the selected values use the most recent choice in Print Preview.\n\nIf you disable or don't configure this policy, print preview settings aren't impacted.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewstickysettings_recommended","displayName":"Configure the sticky print preview settings (users can override)","description":"Configuring this policy sets the print preview settings as the most recent choice in Print Preview instead of the default print preview settings.\n\nEach item of this policy expects a boolean:\n\nLayout specifies if the webpage layout should be kept sticky or not in print preview settings. If you set this to True, the webpage layout uses the recent choice; otherwise, it sets to default value.\n\nSize specifies if the page size should be kept sticky or not in print preview settings. If you set this to True, the page size uses the recent choice; otherwise, it sets to default value.\n\nScale Type specifies if the scaling percentage and scale type should be kept sticky or not in print preview settings. If you set this to True, the scale percentage and scale type both use the recent choice; otherwise, it will set to default value.\n\nMargins specifies if the page margin should be kept sticky or not in print preview settings. If you set this to True, the page margins use the recent choice; otherwise, it sets to default value.\n\nIf you enable this policy, the selected values use the most recent choice in Print Preview.\n\nIf you disable or don't configure this policy, print preview settings aren't impacted.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewusesystemdefaultprinter","displayName":"Set the system default printer as the default printer","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\n\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\n\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewusesystemdefaultprinter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewusesystemdefaultprinter_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewusesystemdefaultprinter_recommended","displayName":"Set the system default printer as the default printer (users can override)","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\n\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\n\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewusesystemdefaultprinter_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewusesystemdefaultprinter_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printrasterizationmode","displayName":"Print Rasterization Mode","description":"Controls how Microsoft Edge prints on Windows. When printing to a non-PostScript printer on Windows, some print jobs need to be rasterized to print correctly.\n\nIf you set this policy to 'Full' or don't configure it, Microsoft Edge performs full page rasterization if necessary.\n\nIf you set this policy to 'Fast', Microsoft Edge reduces the amount of rasterization, which can decrease print job sizes and increase printing speed.\n\nPolicy options mapping:\n\n* Full (0) = Full page rasterization\n\n* Fast (1) = Avoid rasterization if possible\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printrasterizationmode_full","displayName":"Full page rasterization","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printrasterizationmode_fast","displayName":"Avoid rasterization if possible","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI","description":"Controls print image resolution when Microsoft Edge prints PDFs with rasterization.\n\nWhen printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution significantly increases the processing and printing time while a low resolution can lead to poor imaging quality.\n\nIf you set this policy, it allows a particular resolution to be specified for use when rasterizing PDFs for printing.\n\nIf you set this policy to zero or don't configure it, the system default resolution is used during rasterization of page images.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings","displayName":"Print preview sticky settings","description":"Specifies whether print preview should apply last used settings for Microsoft Edge PDF and webpages.\n\nIf you set this policy to 'EnableAll' or don't configure it, Microsoft Edge applies the last used print preview settings for both PDF and webpages.\n\nIf you set this policy to 'DisableAll', Microsoft Edge doesn't apply the last used print preview settings for both PDF and webpages.\n\nIf you set this policy to 'DisablePdf', Microsoft Edge doesn't apply the last used print preview settings for PDF printing and retains it for webpages.\n\nIf you set this policy to 'DisableWebpage', Microsoft Edge doesn't apply the last used print preview settings for webpage printing and retain it for PDF.\n\nThis policy is only available if you enable or don't configure the \"PrintingEnabled\" policy.\n\nPolicy options mapping:\n\n* EnableAll (0) = Enable sticky settings for PDF and Webpages\n\n* DisableAll (1) = Disable sticky settings for PDF and Webpages\n\n* DisablePdf (2) = Disable sticky settings for PDF\n\n* DisableWebpage (3) = Disable sticky settings for Webpages\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_enableall","displayName":"Enable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_disableall","displayName":"Disable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_disablepdf","displayName":"Disable sticky settings for PDF","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_disablewebpage","displayName":"Disable sticky settings for Webpages","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthenabled","displayName":"Enable Proactive Authentication (Obsolete)","description":"This policy is obsolete because it doesn't work independently of browser sign in. It doesn't work in Microsoft Edge after version 90. If you want to configure browser sign in, use the \"BrowserSignin\" policy.\n\nLets you configure whether to turn on Proactive Authentication in Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge tries to seamlessly authenticate to websites and services using the account which is signed-in to the browser.\n\nIf you disable this policy, Microsoft Edge doesn't try to authenticate with websites or services using single sign-on (SSO). Authenticated experiences like the Enterprise New Tab Page won't work (for example, recent and recommended Office documents will not be available).\n\nIf you don't configure this policy, Proactive Authentication is turned on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthworkflowenabled","displayName":"Enable proactive authentication","description":"This policy controls the proactive authentication in Microsoft Edge, that connects the signed-in user identity with Microsoft Bing, MSN and Copilot services for a smooth and consistent sign-in experience.\n\nIf you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser.\n\nIf you disable this policy, Microsoft Edge doesn't send authentications requests to these services, and users need to manually sign-in.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthworkflowenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthworkflowenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.promptfordownloadlocation","displayName":"Ask where to save downloaded files","description":"Set whether to ask where to save a file before downloading it.\n\nIf you enable this policy, the user is asked where to save each file before downloading; if you don't configure it, files are saved automatically to the default location, without asking the user.\n\nIf you don't configure this policy, the user can change this setting.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.promptfordownloadlocation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.promptfordownloadlocation_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.promptonmultiplematchingcertificates","displayName":"Prompt the user to select a certificate when multiple certificates match","description":"This policy controls whether the user is prompted to select a client certificate when more than one certificate matches \"AutoSelectCertificateForUrls\".\nIf this policy is set to True, the user is prompted to select a client certificate whenever the auto-selection policy matches multiple certificates.\nIf this policy is set to False or not set, the user may only be prompted when no certificate matches the auto-selection.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.promptonmultiplematchingcertificates_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.promptonmultiplematchingcertificates_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.protectedcontentidentifiersallowed","displayName":"Allows web pages to use identifiers for the purpose of protected content playback","description":"This policy controls whether sites can use hardware-specific device identifiers to enable hardware-secure DRM (for example, Widevine L1 or PlayReady SL3000), which may be required for high-resolution protected content playback.\n\nIf you enable this policy or do not configure it, sites are allowed to use protected content identifiers.\n\nIf you disable this policy, sites are not allowed to use protected content identifiers.","helpText":null,"infoUrls":[],"categoryId":"2af24920-f611-4f03-99a6-205773869ae6","categoryName":"Protected Content","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.protectedcontentidentifiersallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.protectedcontentidentifiersallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxybypasslist","displayName":"Configure proxy bypass rules (Deprecated)","description":"This policy is deprecated, use \"ProxySettings\" instead. It doesn't work in Microsoft Edge version 91.\n\nDefines a list of hosts for which Microsoft Edge bypasses any proxy.\n\nThis policy is applied only if the \"ProxySettings\" policy isn't specified and you selected either fixed_servers or pac_script in the \"ProxyMode\" policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, you can create a list of hosts for which Microsoft Edge doesn't use a proxy.\n\nIf you don't configure this policy, no list of hosts is created for which Microsoft Edge bypasses a proxy. Leave this policy unconfigured if you specified any other method for setting proxy policies.\n\nFor more detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode","displayName":"Configure proxy server settings (Deprecated)","description":"This policy is deprecated and doesn't work in Microsoft Edge version 91. Use \"ProxySettings\" instead.\n\nIf you set this policy to Enabled, you can specify the proxy server Microsoft Edge uses and prevents users from changing proxy settings. Microsoft Edge ignores all proxy-related options specified from the command line. The policy is only applied if the \"ProxySettings\" policy isn't specified.\n\nOther options are ignored if you choose one of the following options:\n * direct = Never use a proxy server and always connect directly\n * system = Use system proxy settings\n * auto_detect = Auto detect the proxy server\n\nIf you choose to use:\n * fixed_servers = Fixed proxy servers. You can specify further options with \"ProxyServer\" and \"ProxyBypassList\".\n * pac_script = A .pac proxy script. Use \"ProxyPacUrl\" to set the URL to a proxy .pac file.\n\nFor detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.\n\nIf you don't configure this policy, users can choose their own proxy settings.\n\nPolicy options mapping:\n\n* ProxyDisabled (direct) = Never use a proxy\n\n* ProxyAutoDetect (auto_detect) = Auto detect proxy settings\n\n* ProxyPacScript (pac_script) = Use a .pac proxy script\n\n* ProxyFixedServers (fixed_servers) = Use fixed proxy servers\n\n* ProxyUseSystem (system) = Use system proxy settings\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxydisabled","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxyautodetect","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxypacscript","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxyfixedservers","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxyusesystem","displayName":"Use system proxy settings","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxyoverriderules","displayName":"Proxy override rules","description":"This policy enables rule-based proxy selection that determines which proxy Microsoft Edge uses based on the destination URL and any other conditions you define.\n\nWhen this policy is configured, it takes precedence over proxy settings configured by the ProxySettings policy, the Edge.proxy extension API, and any manual user settings.\n\nIf this policy is disabled or not configured, existing proxy policies and user-defined settings continue to apply.\n\nWhen Edge selects a proxy, it evaluates entries in the ProxyOverrideRules policy in order. A rule is considered a match when all the following conditions are met:\n* At least one URL pattern in DestinationMatchers is matched.\n* No URL pattern in ExcludeDestinationMatchers is matched.\n* If Conditions is specified and non-empty, all conditions are satisfied.\n\nFor a matching rule, the value specified in ProxyList is used as the proxy. If no rule matches, proxy selection falls back to the settings defined by the ProxySettings policy.\n\nThe URL patterns supported by DestinationMatchers and ExcludeDestinationMatchers are documented at https://review.learn.microsoft.com/en-us/DeployEdge/configure-microsoft-edge-proxy-support?branch=pr-en-us-6681#proxy-config-url-patterns .\nEntries in ProxyList correspond to PAC-style proxy strings, such as:\n* DIRECT\n* PROXY host:port\n* HTTPS host:port\n* SOCKS4 host:port\n* SOCKS5 host:port\n\nAlternatively, URL-form proxy specifiers can be used, for example:\n* http://host :port\n* https://host :port\n* socks4://host:port\n* socks5://host:port\n\nThe first reachable proxy in the list is used. Invalid entries are ignored.\n\nThe Conditions field specifies conditions that must all be met for an override rule to be applied when selecting a proxy. If this field is not set, the rule is applied when at least one host in DestinationMatchers matches.\n\nThe DnsProbe condition checks whether the specified DNS Host can be resolved to an IP address. The host must include a hostname (for example, example.com) and can optionally include a scheme or port (for example, https://example.com, example.com:123, or https://example.com:123). When a secure scheme (for example, https) is specified, the DNS lookup may also request the HTTPS record (see RFC 9460).\n\nIf Result is set to resolved, the condition is met when resolution succeeds. If set to not_found, the condition is met only when resolution fails.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxypacurl","displayName":"Set the proxy .pac file URL (Deprecated)","description":"This policy is deprecated; use \"ProxySettings\" instead. It doesn't work in Microsoft Edge version 91.\n\nSpecifies the URL for a proxy auto-config (PAC) file.\n\nThis policy is applied only if the \"ProxySettings\" policy isn't specified, and if you've selected pac_script in the \"ProxyMode\" policy. If you've selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, specify the URL for a PAC file, which defines how the browser automatically chooses the appropriate proxy server for fetching a particular website.\n\nIf you disable or don't configure this policy, no PAC file is specified. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\n\nFor detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxyserver","displayName":"Configure address or URL of proxy server (Deprecated)","description":"This policy is deprecated, use \"ProxySettings\" instead. It doesn't work in Microsoft Edge version 91.\n\nSpecifies the URL of the proxy server.\n\nThis policy is applied only if the \"ProxySettings\" policy isn't specified and you selected fixed_servers in the \"ProxyMode\" policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, the proxy server configured by this policy is used for all URLs.\n\nIf you disable or don't configure this policy, users can choose their own proxy settings while in this proxy mode. Leave this policy unconfigured if you specified any other method for setting proxy policies.\n\nFor more options and detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxysettings","displayName":"Proxy settings","description":"Configures the proxy settings for Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge ignores all proxy-related options specified from the command line.\n\nIf you don't configure this policy, users can choose their own proxy settings.\n\nThis policy overrides the following individual policies:\n\n\"ProxyMode\"\n\n\"ProxyPacUrl\"\n\n\"ProxyServer\"\n\n\"ProxyBypassList\"\n\nSetting the \"ProxySettings\" policy accepts the following fields:\n\n* ProxyMode, which lets you specify the proxy server used by Microsoft Edge and prevents users from changing proxy settings\n\n* ProxyPacUrl, a URL to a proxy .pac file or a PAC script encoded as a data URL with MIME type application/x-ns-proxy-autoconfig\n\n* ProxyPacMandatory, a boolean flag that prevents the network stack from falling back to direct connections with invalid or unavailable PAC script\n\n* ProxyServer, a URL for the proxy server\n\n* ProxyBypassList, a list of proxy hosts that Microsoft Edge bypasses\n\nFor ProxyMode, the following values when chosen lead to the following results:\n\n* direct, a proxy is never used and all other fields are ignored.\n\n* system, the systems's proxy is used and all other fields are ignored.\n\n* auto_detect, all other fields are ignored.\n\n* fixed_servers, the ProxyServer and ProxyBypassList fields are used.\n\n* pac_script, the ProxyPacUrl, ProxyPacMandatory and ProxyBypassList fields are used.\n\nFor more detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu","displayName":"Enables Microsoft Edge mini menu","description":"Enables the Microsoft Edge mini menu on websites and PDFs. The mini menu appears when users select text and provides basic actions like Copy and smart actions such as Definitions.\n\nIf you enable or don't configure this policy, selecting text on websites or PDFs shows the mini menu.\n\nIf you disable this policy, the mini menu doesn't appear when users select text on websites or PDFs.\n\nNote: Starting in Microsoft Edge for Mac version 143, this policy is obsolete because the mini menu feature is removed on Mac.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_recommended","displayName":"Enables Microsoft Edge mini menu (users can override)","description":"Enables the Microsoft Edge mini menu on websites and PDFs. The mini menu appears when users select text and provides basic actions like Copy and smart actions such as Definitions.\n\nIf you enable or don't configure this policy, selecting text on websites or PDFs shows the mini menu.\n\nIf you disable this policy, the mini menu doesn't appear when users select text on websites or PDFs.\n\nNote: Starting in Microsoft Edge for Mac version 143, this policy is obsolete because the mini menu feature is removed on Mac.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quickviewofficefilesenabled","displayName":"Manage QuickView Office files capability in Microsoft Edge","description":"Allows you to set whether users can view publicly accessible Office files on the web that aren't on OneDrive or SharePoint. (For example: Word documents, PowerPoint presentations, and Excel spreadsheets)\n\nIf you enable or don't configure this policy, these files can be viewed in Microsoft Edge using Office Viewer instead of downloading the files.\n\nIf you disable this policy, these files are downloaded to be viewed.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.quickviewofficefilesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quickviewofficefilesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.readaloudenabled","displayName":"Enable Read Aloud feature in Microsoft Edge","description":"Enables the Read Aloud feature within Microsoft Edge.\nWith this feature, users can listen to the content on the web page. This feature enables users to multi-task or improve their reading comprehension by hearing content at their own pace.\n\nIf you enable this policy or don't configure it, the Read Aloud option shows up in the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.\nIf you disable this policy, users can't access the Read Aloud feature from the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.readaloudenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.readaloudenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.registeredprotocolhandlers","displayName":"Register protocol handlers","description":"Set this policy (recommended only) to register a list of protocol handlers. This list is merged with ones registered by the user and both are available to use.\n\nTo register a protocol handler:\n\n- Set the protocol property to the scheme (for example, \"mailto\")\n- Set the URL property to the URL property of the application that handlers the scheme specified in the \"protocol\" field. The pattern can include a \"%s\" placeholder, which the handled URL replaces.\n\nUsers can't remove a protocol handler registered by this policy. However, they can install a new default protocol handler to override the existing protocol handlers.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.registeredprotocolhandlers_recommended","displayName":"Register protocol handlers (users can override)","description":"Set this policy (recommended only) to register a list of protocol handlers. This list is merged with ones registered by the user and both are available to use.\n\nTo register a protocol handler:\n\n- Set the protocol property to the scheme (for example, \"mailto\")\n- Set the URL property to the URL property of the application that handlers the scheme specified in the \"protocol\" field. The pattern can include a \"%s\" placeholder, which the handled URL replaces.\n\nUsers can't remove a protocol handler registered by this policy. However, they can install a new default protocol handler to override the existing protocol handlers.\n\nIn the examples in this section, the URL points to the Outlook on the Web (OWA) endpoint used in Exchange Online. If you're targeting Exchange Server (on-premises), use the following URL and replace mail.contoso.com with your organization's OWA endpoint:\n\nhttps://mail.contoso.com/?path=/mail/action/compose&mailtouri=%s","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedmatchescloudserviceenabled","displayName":"Configure Related Matches in Find on Page (Obsolete)","description":"Specifies how the user receives related matches in Find on Page, which provides spellcheck, synonyms, and Q&A results in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can receive related matches in Find on Page on all sites. The results are processed through a cloud service.\n\nIf you disable this policy, users can receive related matches in Find on Page on a limited set of sites. In this case, results are processed locally on the user's device.\n\nNote: This policy is obsolete. The associated cloud service is discontinued, so the feature and policy aren't supported on any versions of Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedmatchescloudserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedmatchescloudserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedwebsitesetsenabled","displayName":"Enable Related Website Sets (Deprecated)","description":"This policy lets you control the enablement of the Related Website Sets feature. Related Website Sets (RWS) is a way for an organisation to declare relationships among sites, so that Microsoft Edge allows limited third-party cookie access for specific purposes across those sites.\n\nIf this policy set to True or unset, the Related Website Sets feature is enabled.\n\nIf this policy is set to False, the Related Website Sets feature is disabled.\n\nThis policy is deprecated as of Microsoft Edge version 144 with the deprecation of Related Website Sets.","helpText":null,"infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedwebsitesetsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedwebsitesetsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (Deprecated)","description":"This policy provides a way to override the list of sets Microsoft Edge uses for Related Website Sets\n\nEach set in the browser's list of Related Website Sets must meet the requirements of a Related Website Set. A Related Website Set must contain a primary site and one or more member sites.\nA set can also contain a list of service sites that it owns, and a map from a site to all its ccTLD variants. For more information on how Microsoft Edge uses Related Website Sets, see https://github.com/WICG/first-party-sets.\n\n\nAll sites in a Related Website Set must be a registrable domain served over HTTPS. Each site in a Related Website Set must also be unique, which means a site can't be listed more than once in a Related Website Set.\n\nWhen this policy is given an empty dictionary, Microsoft Edge uses the public list of Related Website Sets.\n\nFor all sites in a Related Website Set from the replacements list, if a site is also present on a Related Website Set in the browser's list, then that site will be removed from the browser's Related Website Set. After this step, the policy's Related Website Set is added to the Microsoft Edge's list of Related Website Sets.\n\nFor all sites in a Related Website Set from the additions list, if a site is also present on a Related Website Set in Microsoft Edge's list, then the browser's Related Website Set is updated so that the new Related Website Set can be added to the browser's list. After the browser's list has been updated, the policy's Related Website Set is added to the browser's list of Related Website Sets.\n\nThe browser's list of Related Website Sets requires that for all sites in its list, no site is in\nmore than one set. This requirement is also required for both the replacements list\nand the additions list. Similarly, a site can't be in both the\nreplacements list and the additions list.\n\nWildcards (*) aren't supported as a policy value, or as a value within any Related Website Set in these lists.\n\nThis policy is deprecated as of Microsoft Edge version 144 with the deprecation of Related Website Sets.","helpText":null,"infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.resolvenavigationerrorsusewebservice","displayName":"Enable resolution of navigation errors using a web service","description":"Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi.\n\nIf you enable this policy, a web service is used for network connectivity tests.\n\nIf you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues.\n\n**Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues.\n\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\nSpecifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.resolvenavigationerrorsusewebservice_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.resolvenavigationerrorsusewebservice_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.resolvenavigationerrorsusewebservice_recommended","displayName":"Enable resolution of navigation errors using a web service (users can override)","description":"Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi.\n\nIf you enable this policy, a web service is used for network connectivity tests.\n\nIf you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues.\n\n**Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues.\n\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\nSpecifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.resolvenavigationerrorsusewebservice_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.resolvenavigationerrorsusewebservice_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup","displayName":"Action to take on Microsoft Edge startup","description":"Specify how Microsoft Edge behaves when it starts.\n\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\n\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session is restored as it was. This option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\n\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\n\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\n\nDisabling this setting is the same as leaving it not configured. Users can change it in Microsoft Edge.\n\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\n\nPolicy options mapping:\n\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\n\n* RestoreOnStartupIsLastSession (1) = Restore the last session\n\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\n\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupisnewtabpage","displayName":"Open a new tab","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupislastsession","displayName":"Restore the last session","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupisurls","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupislastsessionandurls","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_recommended","displayName":"Action to take on Microsoft Edge startup (users can override)","description":"Specify how Microsoft Edge behaves when it starts.\n\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\n\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session is restored as it was. This option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\n\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\n\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\n\nDisabling this setting is the same as leaving it not configured. Users can change it in Microsoft Edge.\n\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\n\nPolicy options mapping:\n\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\n\n* RestoreOnStartupIsLastSession (1) = Restore the last session\n\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\n\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_recommended_restoreonstartupisnewtabpage","displayName":"Open a new tab","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_recommended_restoreonstartupislastsession","displayName":"Restore the last session","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_recommended_restoreonstartupisurls","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_recommended_restoreonstartupislastsessionandurls","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartupurls","displayName":"Sites to open when the browser starts","description":"Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup.\n\nThis policy only works if you also set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4).\n\nThis policy is available only on specific Windows instances. These instances include devices that are joined to a Microsoft Active Directory domain, devices joined to Microsoft Azure Active Directory`, or devices enrolled for device management.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartupurls_recommended","displayName":"Sites to open when the browser starts (users can override)","description":"Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup.\n\nThis policy only works if you also set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4).\n\nThis policy is available only on specific Windows instances. These instances include devices that are joined to a Microsoft Active Directory domain, devices joined to Microsoft Azure Active Directory`, or devices enrolled for device management.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartupuserurlsenabled","displayName":"Allow users to add and remove their own sites during startup when the RestoreOnStartupURLs policy is configured.","description":"This policy only works if you set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4) and the RestoreOnStartupURLs policy as mandatory.\nIf you enable this policy, users are allowed to add and remove their own URLs to open when starting Microsoft Edge while maintaining the admin specified mandatory list of sites specified by setting \"RestoreOnStartup\" policy to open a list of URLS and providing the list of sites in the RestoreOnStartupURLs policy.\n\nIf you disable or don't configure this policy, there's no change to how the \"RestoreOnStartup\" and RestoreOnStartupURLs policies work.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartupuserurlsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartupuserurlsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restorepdfview","displayName":"Restore PDF view","description":"Enables PDF View Recovery in Microsoft Edge.\n\nIf you enable or don't configure this policy, Microsoft Edge recovers the last state of PDF view and lands users to the section where they ended reading in the last session.\n\nIf you disable this policy, Microsoft Edge recovers the last state of PDF view and lands users at the start of the PDF file.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.restorepdfview_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restorepdfview_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.runallflashinallowmode","displayName":"Extend Adobe Flash content setting to all content (Obsolete)","description":"This policy doesn't work because Flash is no longer supported by Microsoft Edge.\n\nIf you enable this policy, all Adobe Flash content embedded in websites that are set to allow Adobe Flash in the content settings, either by the user or by enterprise policy, run. This includes content from other origins and/or small content.\n\nTo control which websites are allowed to run Adobe Flash, see the specifications in the \"DefaultPluginsSetting\", \"PluginsAllowedForUrls\", and \"PluginsBlockedForUrls\" policies.\n\nIf you disable this policy or don't configure it, Adobe Flash content from other origins (sites that aren't specified in the preceding three policies) or small content might be blocked.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.runallflashinallowmode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.runallflashinallowmode_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sameorigintabcaptureallowedbyorigins","displayName":"Allow Same Origin Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin.\n\nLeaving the policy unset means that sites won't be considered for an override at this scope of capture.\n\nIf a site matches a URL pattern in this policy, the following policies won't be considered: \"TabCaptureAllowedByOrigins\", \"WindowCaptureAllowedByOrigins\", \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sandboxexternalprotocolblocked","displayName":"Allow Microsoft Edge to block navigations to external protocols in a sandboxed iframe","description":"Microsoft Edge blocks navigations to external protocols inside a sandboxed iframe.\n\nIf you enable or don't configure this policy, Microsoft Edge blocks those navigations.\n\nIf you disable this policy, Microsoft Edge doesn't block those navigations.\n\nThis policy can be used by administrators who need more time to update their internal website affected by this new restriction. This Enterprise policy is temporary; it's intended to be removed after Microsoft Edge version 117.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sandboxexternalprotocolblocked_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sandboxexternalprotocolblocked_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.savecookiesonexit","displayName":"Save cookies when Microsoft Edge closes","description":"When this policy is enabled, the specified set of cookies is exempt from deletion when the browser closes. This policy is only effective when:\n- The 'Cookies and other site data' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\n- The policy \"ClearBrowsingDataOnExit\" is enabled or\n- The policy \"DefaultCookiesSetting\" is set to 'Keep cookies for the duration of the session'.\n\nYou can define a list of sites, based on URL patterns, that have their cookies preserved across sessions.\n\nNote: Users can still edit the cookie site list to add or remove URLs. However, they can't remove URLs that are added by an Admin.\n\nIf you enable this policy, the list of cookies aren't cleared when the browser closes.\n\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.savingbrowserhistorydisabled","displayName":"Disable saving browser history","description":"Disables saving browser history and prevents users from changing this setting.\n\nIf you enable this policy, browsing history isn't saved. This also disables tab syncing.\n\nIf you disable this policy or don't configure it, browsing history is saved.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.savingbrowserhistorydisabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.savingbrowserhistorydisabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.scarewareblockerallowlistdomains","displayName":"Configure the list of domains where Microsoft Edge Scareware blockers don't run","description":"This policy configures the list of trusted domains for Microsoft Edge Scareware blocker. When a website's source URL matches any domain in this list, Microsoft Edge Scareware blocker doesn't analyze that site.\n\nThis policy takes effect only if the ScarewareBlockerProtectionEnabled policy is enabled.\n\nIf you enable this policy, Microsoft Edge Scareware blocker trusts the specified domains.\n\nIf you disable or don't configure this policy, Microsoft Edge Scareware blocker analyzes all sites.","helpText":null,"infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowed","displayName":"Allow or deny screen capture","description":"If you enable this policy, or don't configure this policy, a webpage uses screen-share APIs (for example, getDisplayMedia() or the Desktop Capture extension API) for a screen capture.\nIf you disable this policy, calls to screen-share APIs fail. For example, if you're using a web-based online meeting, video or screen sharing won't work. However, this policy isn't considered.\n(and a site will be allowed to use screen-share APIs) if the site matches an origin pattern in any of the following policies:\n\"ScreenCaptureAllowedByOrigins\",\n\"WindowCaptureAllowedByOrigins\",\n\"TabCaptureAllowedByOrigins\",\n\"SameOriginTabCaptureAllowedByOrigins\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowedbyorigins","displayName":"Allow Desktop, Window, and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture.\n\nLeaving the policy unset means that sites won't be considered for an override at this scope of Capture.\n\nThis policy isn't considered if a site matches a URL pattern in any of the following policies: \"WindowCaptureAllowedByOrigins\", \"TabCaptureAllowedByOrigins\", \"SameOriginTabCaptureAllowedByOrigins\".\n\nIf a site matches a URL pattern in this policy, the \"ScreenCaptureAllowed\" isn't considered.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencapturewithoutgestureallowedfororigins","displayName":"Allow screen capture without prior user gesture","description":"For security reasons, the\ngetDisplayMedia() web API requires\na prior user gesture (\"transient activation\") to be called or the API\nfails.\n\nWhen this policy is configured, admins can specify origins on which this API\ncan be called without prior user gesture.\n\nFor detailed information on valid url patterns, see\nhttps://go.microsoft.com/fwlink/?linkid=2095322. Note: * isn't an accepted\nvalue for this policy.\n\nIf this policy isn't configured, all origins require a prior user gesture to\ncall this API.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\n\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL is enabled.\n\nIf you disable this policy, web page scrolling to specific text fragments via a URL is disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.scrolltotextfragmentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.scrolltotextfragmentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled","displayName":"Search Filters Enabled","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions are shown.\n\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\n\nIf you disable this policy, the autosuggestion dropdown can't display the ribbon of available filters.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_recommended","displayName":"Search Filters Enabled (users can override)","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions are shown.\n\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\n\nIf you disable this policy, the autosuggestion dropdown can't display the ribbon of available filters.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchforimageenabled","displayName":"Search for image enabled","description":"This policy lets you configure the Image Search feature in the right-click context menu.\n\nIf you enable or don't configure this policy, then the \"Search the web for image\" option is visible in the context menu.\n\nIf you disable this policy, then the \"Search the web for image\" won't be visible in the context menu.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchforimageenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchforimageenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchinsidebarenabled","displayName":"Search in Sidebar enabled","description":"Search in Sidebar allows users to open search result in sidebar (including sidebar search for Progressive Web Apps).\n\nIf you configure this policy to 'EnableSearchInSidebar' or don't configure it, Search in sidebar is enabled.\n\nIf you configure this policy to 'DisableSearchInSidebarForKidsMode', Search in sidebar is disabled when in Kids mode. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\n\nIf you configure this policy to 'DisableSearchInSidebar', Search in sidebar is disabled. Some methods that would invoke sidebar search invoke a traditional search instead.\n\nPolicy options mapping:\n\n* EnableSearchInSidebar (0) = Enable search in sidebar\n\n* DisableSearchInSidebarForKidsMode (1) = Disable search in sidebar for Kids Mode\n\n* DisableSearchInSidebar (2) = Disable search in sidebar\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchinsidebarenabled_enablesearchinsidebar","displayName":"Enable search in sidebar","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchinsidebarenabled_disablesearchinsidebarforkidsmode","displayName":"Disable search in sidebar for Kids Mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchinsidebarenabled_disablesearchinsidebar","displayName":"Disable search in sidebar","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled","displayName":"Enable search suggestions","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\n\nIf you enable this policy, web search suggestions are used.\n\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\n\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_recommended","displayName":"Enable search suggestions (users can override)","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\n\nIf you enable this policy, web search suggestions are used.\n\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\n\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.securitykeypermitattestation","displayName":"Websites or domains that don't need permission to use direct Security Key attestation","description":"Specifies the WebAuthn RP IDs that don't need explicit user permission when attestation certificates from security keys are requested. Additionally, a signal is sent to the security key indicating that it can use enterprise attestation. Without this policy, users are prompted each time a site requests attestation of security keys.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.selectparserrelaxationenabled","displayName":"Controls whether the new HTML parser behavior for the element. This policy supports the old HTML parser behavior through Microsoft Edge version 138.\n\nIf this policy is enabled or unset, the HTML parser allows additional tags inside the element.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.selectparserrelaxationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.selectparserrelaxationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sendintranettointernetexplorer","displayName":"Send all intranet sites to Internet Explorer","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sendintranettointernetexplorer_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sendintranettointernetexplorer_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sendmouseeventsdisabledformcontrolsenabled","displayName":"Control the new behavior for event dispatching on disabled form controls (Obsolete)","description":"Event dispatching on disabled form controls is being changed in Microsoft Edge to improve compatibility with other browsers and to improve the developer experience.\n\nWith this change, MouseEvents get dispatched on disabled form control elements. Exceptions for this behavior are click, mouseup, and mousedown. Some examples of the new events are mousemove, mouseenter, and mouseleave.\n\nThis change also truncates the event path of click, mouseup, and mousedown when they’re dispatched on children of disabled form controls. These events aren’t dispatched on the disabled form control or on any of its ancestors.\n\nNote: This new behavior might break some websites.\n\nIf you enable or don't configure this policy, the new behavior is used.\n\nIf you disable this policy, the old behavior is used.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sendmouseeventsdisabledformcontrolsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sendmouseeventsdisabledformcontrolsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sensorsallowedforurls","displayName":"Allow access to sensors on specific sites","description":"Define a list of sites, based on URL patterns, that can access and use sensors such as motion and light sensors.\n\nIf you don't configure this policy, the global default value from the \"DefaultSensorsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor URL patterns that don't match this policy, the following order of precedence is used: The \"SensorsBlockedForUrls\" policy (if there's a match), the \"DefaultSensorsSetting\" policy (if set), or the user's personal settings.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"SensorsBlockedForUrls\" policy. You can't allow and block a URL.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sensorsblockedforurls","displayName":"Block access to sensors on specific sites","description":"Define a list of sites, based on URL patterns, that can't access sensors such as motion and light sensors.\n\nIf you don't configure this policy, the global default value from the \"DefaultSensorsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor URL patterns that don't match this policy, the following order of precedence is used: The \"SensorsAllowedForUrls\" policy (if there's a match), the \"DefaultSensorsSetting\" policy (if set), or the user's personal settings.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"SensorsAllowedForUrls\" policy. You can't allow and block a URL.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serialaskforurls","displayName":"Allow the Serial API on specific sites","description":"Specifies URL patterns for sites that are allowed to request access to a serial port.\n\nIf not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings.\n\nFor unmatched sites, the following order applies:\n\n1. \"SerialBlockedForUrls\" (if matched).\n\n2. DefaultSerialGuardSetting (if set).\n\n3. User's settings.\n\nIf URL patterns in this policy conflict with those in \"SerialBlockedForUrls\", they're ignored.\n\nFor detailed information about valid URL patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serialblockedforurls","displayName":"Block the Serial API on specific sites","description":"Specifies URL patterns for sites that aren't allowed to request access to a serial port.\n\nIf not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings.\n\nFor unmatched sites, the following order applies:\n\n1. SerialAskForUrls (if matched).\n\n2. DefaultSerialGuardSetting (if set).\n\n3. User's settings.\n\nURL patterns in this policy must not conflict with those in SerialAskForUrls. This policy takes precedence.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup","description":"This policy controls whether Microsoft Edge enables the ServiceWorkerAutoPreload feature.\n\nIf you enable or don't configure this policy, Microsoft Edge can initiate the main resource network request concurrently with the Service Worker bootstrap process. This can improve performance in scenarios where the Service Worker isn't already running.\n\nIf you disable this policy, Microsoft Edge will wait to dispatch the navigation request until after the Service Worker starts.\n\nThis is a temporary policy and is removed in version 144 of Microsoft Edge.\n\nFor more information on the feature, see https://github.com/WICG/service-worker-auto-preload.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkerautopreloadenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkerautopreloadenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkertocontrolsrcdociframeenabled","displayName":"Allow ServiceWorker to control srcdoc iframes","description":"https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with the \"allow-same-origin\" sandbox attribute to be under ServiceWorker control.\n\nBy default (if left unset) or when set to Enabled, Microsoft Edge makes srcdoc iframes with \"allow-same-origin\" sandbox attributes to be under ServiceWorker control.\n\nSetting the policy to Disabled prevents ServiceWorker control over srcdoc iframes.\n\nThis policy is temporary and planned for deprecation in 2026.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkertocontrolsrcdociframeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkertocontrolsrcdociframeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover","description":"This policy sets the default feed tab on the New Tab Page to Work or Discover.\n\nIf you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work.\n\nIf you set this policy to 'Discover' (1), Microsoft Edge sets the default feed tab to Discover.\n\nThis policy only takes effect when \"ConfigureNTPFeedTabVisibility\" is set to 'EnableBothWorkDiscover' (0) or is not configured. If only one tab is visible, this policy has no effect.\n\nPolicy options mapping:\n\n* NTPDefaultFeedTabWork (0) = Work\n\n* NTPDefaultFeedTabDiscover (1) = Discover\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_ntpdefaultfeedtabwork","displayName":"Work","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_ntpdefaultfeedtabdiscover","displayName":"Discover","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_recommended","displayName":"Set the default New Tab Page feed tab to Work or Discover (users can override)","description":"This policy sets the default feed tab on the New Tab Page to Work or Discover.\n\nIf you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work.\n\nIf you set this policy to 'Discover' (1), Microsoft Edge sets the default feed tab to Discover.\n\nThis policy only takes effect when \"ConfigureNTPFeedTabVisibility\" is set to 'EnableBothWorkDiscover' (0) or is not configured. If only one tab is visible, this policy has no effect.\n\nPolicy options mapping:\n\n* NTPDefaultFeedTabWork (0) = Work\n\n* NTPDefaultFeedTabDiscover (1) = Discover\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_recommended_ntpdefaultfeedtabwork","displayName":"Work","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_recommended_ntpdefaultfeedtabdiscover","displayName":"Discover","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.settimeoutwithout1msclampenabled","displayName":"Control Javascript setTimeout() function minimum timeout (Obsolete)","description":"This policy is obsolete and doesn't work in Microsoft Edge after version 109.\nThis policy was only provided temporarily to allow Enterprises to adapt to the new clamping behavior.\n\n If you enable this policy, the JavaScript setTimeout() with a timeout of 0 ms is no longer fixed to 1 ms to schedule timer-based callbacks.\n If you disable this policy, the JavaScript setTimeout() with a timeout of 0 ms is fixed to 1 ms to schedule timer-based callbacks.\n If you don't configure this policy, use the browser's default behavior for setTimeout() function.\n\n This is a web standards compliancy feature; however, it may change task ordering on a webpage, leading to unexpected behavior on sites that are dependent on a certain ordering.\n It also affects sites with many setTimeout()s with a timeout of 0-ms usage, for example, increasing CPU load.\n\n For users where this policy is unset, Microsoft Edge Stable rolls out the change gradually on the stable channel.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.settimeoutwithout1msclampenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.settimeoutwithout1msclampenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharebrowsinghistorywithcopilotsearchallowed","displayName":"Allow sharing tenant-approved browsing history with Microsoft 365 Copilot Search","description":"This policy controls whether browsing history in Microsoft Edge is shared with Microsoft 365 Copilot Search to provide more relevant search results. Only tenant-approved, work-related sites are shared.\n\nThis feature is available only to users who are signed in to Microsoft Edge with an Entra ID account and have an eligible Microsoft 365 Copilot license.\n\nIf you enable or don't configure this policy, browsing history will be shared with Microsoft 365 Copilot Search by default, and users can turn off sharing using the toggle in Microsoft Edge settings.\n\nIf you disable this policy, browsing history won't be shared with Microsoft 365 Copilot Search.\n\nLearn more about how Copilot uses data and consent at https://go.microsoft.com/fwlink/?linkid=2333202","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharebrowsinghistorywithcopilotsearchallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharebrowsinghistorywithcopilotsearchallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedarraybufferunrestrictedaccessallowed","displayName":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context","description":"Specifies whether SharedArrayBuffers can be used in a non-cross-origin-isolated context. A SharedArrayBuffer is a binary data buffer that's used to create views on shared memory. SharedArrayBuffers have a memory access vulnerability in several popular CPUs.\n\nIf you enable this policy, sites are allowed to use SharedArrayBuffers with no restrictions.\n\nIf you disable or don't configure this policy, sites are allowed to use SharedArrayBuffers only when cross-origin isolated.\n\nMicrosoft Edge requires cross-origin isolation when using SharedArrayBuffers from Microsoft Edge version 91 onward for Web Compatibility reasons.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedarraybufferunrestrictedaccessallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedarraybufferunrestrictedaccessallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedworkerbloburlfixenabled","displayName":"Make SharedWorker blob URL behavior aligned with the specification","description":"According to Service Worker specification\nhttps://w3c.github.io/ServiceWorker/#control-and-use-worker-client, workers\nshould inherit controllers for blob URLs. Currently, only DedicatedWorkers\ninherit the controller, while SharedWorkers do not.\n\nEnabled/Unset: Microsoft Edge inherits\nthe controller for SharedWorker blob URLs, aligning with the specification.\n\nDisabled: Behavior remains unchanged, not aligning with the specification.\n\nThis policy is temporary and will be removed in a future update.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedworkerbloburlfixenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedworkerbloburlfixenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedworkerextendedlifetimeenabled","displayName":"Enable the extended lifetime option for SharedWorkers","description":"Controls whether Microsoft Edge allows SharedWorkers to use the extendedLifetime option.\n\nIf you enable or don't configure this policy, SharedWorkers can use the extended lifetime option in the SharedWorker constructor.\n\nIf you disable this policy, the extended lifetime option is ignored, even if it is requested by the page.\n\nThis policy is temporary and will be removed in a future release.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedworkerextendedlifetimeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sharedworkerextendedlifetimeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showacrobatsubscriptionbutton","displayName":"Shows button on native PDF viewer in Microsoft Edge that allows users to sign up for Adobe Acrobat subscription","description":"This policy lets the native PDF viewer in Microsoft Edge show a button that lets a user looking for advanced digital document features to discover and subscribe to premium offerings. This is done via the Acrobat extension.\n\nIf you enable or don't configure this policy, the button shows up on the native PDF viewer in Microsoft Edge. A user can buy Adobe subscription to access their premium offerings.\n\nIf you disable this policy, the button isn't visible on the native PDF viewer in Microsoft Edge. A user can't discover Adobe's advanced PDF tools or buy their subscriptions.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showacrobatsubscriptionbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showacrobatsubscriptionbutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showcasticonintoolbar","displayName":"Show the cast icon in the toolbar","description":"Set this policy to true to show the Cast toolbar icon on the toolbar or the overflow menu. Users won't be able to remove it.\n\nIf you don't configure this policy or if you disable it, users can pin or remove the icon by using its contextual menu.\n\nIf you've also set the \"EnableMediaRouter\" policy to false, then this policy is ignored, and the toolbar icon isn't shown.","helpText":null,"infoUrls":[],"categoryId":"fddc444c-3591-4a50-865b-d8993b798e12","categoryName":"Cast","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showcasticonintoolbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showcasticonintoolbar_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadsinsecurewarningsenabled","displayName":"Enable insecure download warnings","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\n\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user receives a UI warning, such as \"Insecure download blocked\". The user can still download the item.\n\nIf you disable this policy, the warnings for insecure downloads are suppressed.","helpText":null,"infoUrls":[],"categoryId":"5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","categoryName":"Downloads","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadsinsecurewarningsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadsinsecurewarningsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadsinsecurewarningsenabled_recommended","displayName":"Enable insecure download warnings (users can override)","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\n\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user receives a UI warning, such as \"Insecure download blocked\". The user can still download the item.\n\nIf you disable this policy, the warnings for insecure downloads are suppressed.","helpText":null,"infoUrls":[],"categoryId":"5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","categoryName":"Downloads","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadsinsecurewarningsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadsinsecurewarningsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadstoolbarbutton","displayName":"Show Downloads button on the toolbar","description":"Set this policy to always show the Downloads button on the toolbar.\n\nIf you enable this policy, the Downloads button is pinned to the toolbar.\n\nIf you disable or don't configure the policy, the Downloads button isn't shown on the toolbar by default. Users can toggle the Downloads button in edge://settings/appearance.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadstoolbarbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadstoolbarbutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhistorythumbnails","displayName":"Show thumbnail images for browsing history","description":"This policy lets you configure whether the history thumbnail feature collects and saves images for the sites you visit. When enabled, this feature makes it easier to identify sites when you hover over your history results.\nIf you don't configure this policy, the thumbnail feature is turned on after a user visits the history hub twice in the past seven days.\nIf you enable this policy, the history thumbnail collects and saves images for visited sites.\nIf you disable this policy, the history thumbnail doesn't collect and save images for visited sites.\nWhen the feature is disabled, existing images are deleted on a per user basis, and the feature no longer collects or saves images when a site is visited.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhistorythumbnails_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhistorythumbnails_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton","displayName":"Show Home button on toolbar","description":"Shows the Home button on Microsoft Edge's toolbar.\n\nEnable this policy to always show the Home button. Disable it to never show the button.\n\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_recommended","displayName":"Show Home button on toolbar (users can override)","description":"Shows the Home button on Microsoft Edge's toolbar.\n\nEnable this policy to always show the Home button. Disable it to never show the button.\n\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards","displayName":"Show Microsoft Rewards experiences","description":"Show Microsoft Rewards experience and notifications.\nIf you enable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.\n\nIf you disable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets won't see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is disabled and toggled off.\n\nIf you don't configure this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_recommended","displayName":"Show Microsoft Rewards experiences (users can override)","description":"Show Microsoft Rewards experience and notifications.\nIf you enable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.\n\nIf you disable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets won't see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is disabled and toggled off.\n\nIf you don't configure this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showofficeshortcutinfavoritesbar","displayName":"Show Microsoft Office shortcut in favorites bar (Deprecated)","description":"This policy didn't work as expected due to changes in operational requirements. Therefore, the policy is deprecated and shouldn't be used.\n\nSpecifies whether to include a shortcut to Office.com in the favorites bar. For users signed into Microsoft Edge, the shortcut takes users to their Microsoft Office apps and docs.\n If you enable or don't configure this policy, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu.\n If you disable this policy, the shortcut isn't shown.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showofficeshortcutinfavoritesbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showofficeshortcutinfavoritesbar_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showpdfdefaultrecommendationsenabled","displayName":"Allow notifications to set Microsoft Edge as default PDF reader","description":"This policy setting lets you decide whether employees should receive recommendations to set Microsoft Edge as PDF handler.\n\nIf you enable or don't configure this setting, employees receive recommendations from Microsoft Edge to set itself as the default PDF handler.\n\nIf you disable this setting, employees can't receive any notifications from Microsoft Edge to set itself as the default PDF handler.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showpdfdefaultrecommendationsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showpdfdefaultrecommendationsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showrecommendationsenabled","displayName":"Allow feature recommendations and browser assistance notifications from Microsoft Edge","description":"This setting controls the in-browser assistance notifications that are intended to help users get the most out of Microsoft Edge. This is done by recommending features and by helping them use browser features. These notifications take the form of dialog boxes, flyouts, coach marks and banners in the browser. An example of an assistance notification would be when a user has many tabs opened in the browser. In this instance, Microsoft Edge may prompt the user to try out the vertical tabs feature which is designed to give better browser tab management.\n\nDisabling this policy stops this message from appearing again even if the user has too many tabs open.\nAny features that have been disabled by a management policy aren't suggested to users.\nIf you enable or don't configure this setting, users receive recommendations or notifications from Microsoft Edge.\nIf you disable this setting, users won't receive any recommendations or notifications from Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showrecommendationsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showrecommendationsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled","displayName":"Enable tab preview on hover","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\n\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\n\nIf you disable this policy, tab previews aren't shown on hover.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_recommended","displayName":"Enable tab preview on hover (users can override)","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\n\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\n\nIf you disable this policy, tab previews aren't shown on hover.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support","description":"Enable support for Signed HTTP Exchange (SXG).\n\nIf this policy isn't set or enabled, Microsoft Edge accepts web contents served as Signed HTTP Exchanges.\n\nIf this policy is set to disabled, Signed HTTP Exchanges can't be loaded.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.signedhttpexchangeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.signedhttpexchangeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsblockedforurls","displayName":"Block sleeping tabs on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to be put to sleep by sleeping tabs. Sites in this list are also excluded from other performance optimizations like efficiency mode and tab discard.\n\nIf the policy \"SleepingTabsEnabled\" is disabled, this list isn't used and no sites are put to sleep automatically.\n\nIf you don't configure this policy, all sites are eligible to be put to sleep unless the user's personal configuration blocks them.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsblockedforurls_recommended","displayName":"Block sleeping tabs on specific sites (users can override)","description":"Define a list of sites, based on URL patterns, that aren't allowed to be put to sleep by sleeping tabs. Sites in this list are also excluded from other performance optimizations like efficiency mode and tab discard.\n\nIf the policy \"SleepingTabsEnabled\" is disabled, this list isn't used and no sites are put to sleep automatically.\n\nIf you don't configure this policy, all sites are eligible to be put to sleep unless the user's personal configuration blocks them.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled","displayName":"Configure sleeping tabs","description":"This policy setting lets you configure whether to turn on sleeping tabs. Sleeping tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, sleeping tabs is turned on.\n\nIndividual sites may be blocked from being put to sleep by configuring the policy \"SleepingTabsBlockedForUrls\".\n\nIf this policy is enabled, sleeping tabs are turned on.\n\nIf this policy is disabled, sleeping tabs are turned off. However, during moderate memory pressure, the system may freeze (sleep) tabs before discarding them.\n\nIf this policy is not configured, users can choose whether to enable sleeping tabs.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_recommended","displayName":"Configure sleeping tabs (users can override)","description":"This policy setting lets you configure whether to turn on sleeping tabs. Sleeping tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, sleeping tabs is turned on.\n\nIndividual sites may be blocked from being put to sleep by configuring the policy \"SleepingTabsBlockedForUrls\".\n\nIf this policy is enabled, sleeping tabs are turned on.\n\nIf this policy is disabled, sleeping tabs are turned off. However, during moderate memory pressure, the system may freeze (sleep) tabs before discarding them.\n\nIf this policy is not configured, users can choose whether to enable sleeping tabs.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs are automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\n\nTabs are only put to sleep automatically when the policy \"SleepingTabsEnabled\" is enabled or isn't configured, and the user has enabled the sleeping tabs setting.\n\nIf you don't configure this policy, users can choose the timeout value.\n\nPolicy options mapping:\n\n* 30Seconds (30) = 30 seconds of inactivity\n\n* 5Minutes (300) = 5 minutes of inactivity\n\n* 15Minutes (900) = 15 minutes of inactivity\n\n* 30Minutes (1800) = 30 minutes of inactivity\n\n* 1Hour (3600) = 1 hour of inactivity\n\n* 2Hours (7200) = 2 hours of inactivity\n\n* 3Hours (10800) = 3 hours of inactivity\n\n* 6Hours (21600) = 6 hours of inactivity\n\n* 12Hours (43200) = 12 hours of inactivity\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_30seconds","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_5minutes","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_15minutes","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_30minutes","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_1hour","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_2hours","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_3hours","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_6hours","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_12hours","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended","displayName":"Set the background tab inactivity timeout for sleeping tabs (users can override)","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs are automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\n\nTabs are only put to sleep automatically when the policy \"SleepingTabsEnabled\" is enabled or isn't configured, and the user has enabled the sleeping tabs setting.\n\nIf you don't configure this policy, users can choose the timeout value.\n\nPolicy options mapping:\n\n* 30Seconds (30) = 30 seconds of inactivity\n\n* 5Minutes (300) = 5 minutes of inactivity\n\n* 15Minutes (900) = 15 minutes of inactivity\n\n* 30Minutes (1800) = 30 minutes of inactivity\n\n* 1Hour (3600) = 1 hour of inactivity\n\n* 2Hours (7200) = 2 hours of inactivity\n\n* 3Hours (10800) = 3 hours of inactivity\n\n* 6Hours (21600) = 6 hours of inactivity\n\n* 12Hours (43200) = 12 hours of inactivity\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_30seconds","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_5minutes","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_15minutes","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_30minutes","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_1hour","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_2hours","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_3hours","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_6hours","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_recommended_12hours","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist","displayName":"Block smart actions for a list of services","description":"List specific services, such as PDFs, and websites that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\n\nIf you enable the policy:\n - The smart action in the mini and full context menu is disabled for all profiles for services that match the given list.\n - Users won't see the smart action in the mini and full context menu on text selection for services that match the given list.\n - In Microsoft Edge settings, the smart action in the mini and full context menu is disabled for services that match the given list.\n\nIf you disable or don't configure this policy:\n - The smart action in the mini and full context menu is enabled for all profiles.\n - Users will see the smart action in the mini and full context menu on text selection.\n - In Microsoft Edge settings, the smart action in the mini and full context menu is enabled.\n\nPolicy options mapping:\n\n* smart_actions (smart_actions) = Smart actions in pdfs and on websites\n\n* smart_actions_website (smart_actions_website) = Smart actions on websites\n\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_smart_actions","displayName":"Smart actions in pdfs and on websites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_smart_actions_website","displayName":"Smart actions on websites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_smart_actions_pdf","displayName":"Smart actions in PDF","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_recommended","displayName":"Block smart actions for a list of services (users can override)","description":"List specific services, such as PDFs, and websites that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\n\nIf you enable the policy:\n - The smart action in the mini and full context menu is disabled for all profiles for services that match the given list.\n - Users won't see the smart action in the mini and full context menu on text selection for services that match the given list.\n - In Microsoft Edge settings, the smart action in the mini and full context menu is disabled for services that match the given list.\n\nIf you disable or don't configure this policy:\n - The smart action in the mini and full context menu is enabled for all profiles.\n - Users will see the smart action in the mini and full context menu on text selection.\n - In Microsoft Edge settings, the smart action in the mini and full context menu is enabled.\n\nPolicy options mapping:\n\n* smart_actions (smart_actions) = Smart actions in pdfs and on websites\n\n* smart_actions_website (smart_actions_website) = Smart actions on websites\n\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_recommended_smart_actions","displayName":"Smart actions in pdfs and on websites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_recommended_smart_actions_website","displayName":"Smart actions on websites","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartactionsblocklist_recommended_smart_actions_pdf","displayName":"Smart actions in PDF","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenallowlistdomains","displayName":"Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings","description":"Configures the list of Microsoft Defender SmartScreen trusted domains. This means:\n\n- Microsoft Defender SmartScreen won't check for potentially malicious resources like phishing software and other malware if the source URLs match these domains.\n- The Microsoft Defender SmartScreen download protection service won't check downloads hosted on these domains.\n\nIf you enable this policy, Microsoft Defender SmartScreen trusts these domains.\nIf you disable or don't set this policy, default Microsoft Defender SmartScreen protection is applied to all resources.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10/11 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via mobile device management (MDM) or joined to a domain via MCX.\nNote: If your organization has enabled Microsoft Defender for Endpoint, this policy and any allowlists created with the policy are ignored. You must configure your allowlists and blocklists in Microsoft 365 Defender portal using \"Indicators\" (Settings > Endpoints > Indicators).","helpText":null,"infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenfortrusteddownloadsenabled","displayName":"Force Microsoft Defender SmartScreen checks on downloads from trusted sources","description":"This policy setting lets you configure whether Microsoft Defender SmartScreen checks download reputation from a trusted source.\n\nIn Windows, the policy determines a trusted source by checking its Internet zone. If the source comes from the local system, intranet, or trusted sites zone, then the download is considered trusted and safe.\n\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download's reputation regardless of source.\n\nIf you disable this setting, Microsoft Defender SmartScreen doesn't check the download's reputation when downloading from a trusted source.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.","helpText":null,"infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenfortrusteddownloadsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenfortrusteddownloadsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenfortrusteddownloadsenabled_recommended","displayName":"Force Microsoft Defender SmartScreen checks on downloads from trusted sources (users can override)","description":"This policy setting lets you configure whether Microsoft Defender SmartScreen checks download reputation from a trusted source.\n\nIn Windows, the policy determines a trusted source by checking its Internet zone. If the source comes from the local system, intranet, or trusted sites zone, then the download is considered trusted and safe.\n\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download's reputation regardless of source.\n\nIf you disable this setting, Microsoft Defender SmartScreen doesn't check the download's reputation when downloading from a trusted source.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.","helpText":null,"infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenfortrusteddownloadsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.smartscreenfortrusteddownloadsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.speechrecognitionenabled","displayName":"Configure Speech Recognition","description":"Set whether websites can use the W3C Web Speech API to recognize speech from the user. The Microsoft Edge implementation of the Web Speech API uses Azure Cognitive Services, so voice data leaves the machine.\n\nIf you enable or don't configure this policy, web-based applications that use the Web Speech API can use Speech Recognition.\n\nIf you disable this policy, Speech Recognition isn't available through the Web Speech API.\n\nRead more about this feature here:\nSpeechRecognition API: https://go.microsoft.com/fwlink/?linkid=2143388\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2143680","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.speechrecognitionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.speechrecognitionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellcheckenabled","displayName":"Enable spellcheck","description":"If you enable or don't configure this policy, the user can use spellcheck.\n\nIf you disable this policy, the user can't use spellcheck and the \"SpellcheckLanguage\" and \"SpellcheckLanguageBlocklist\" policies are also disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellcheckenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellcheckenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellchecklanguage","displayName":"Enable specific spellcheck languages","description":"Enables different languages for spellcheck. Any language that you specify that isn't recognized is ignored.\n\nIf you enable this policy, spellcheck is enabled for the languages specified, and any languages the user enabled.\n\nIf you don't configure or disable this policy, there's no change to the user's spellcheck preferences.\n\nIf the \"SpellcheckEnabled\" policy is disabled, this policy has no effect.\n\nIf a language is included in both the 'SpellcheckLanguage' and the \"SpellcheckLanguageBlocklist\" policy, the spellcheck language is enabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellchecklanguageblocklist","displayName":"Force disable spellcheck languages","description":"Force-disables spellcheck languages. Unrecognized languages in that list will be ignored.\n\nIf you enable this policy, spellcheck will be disabled for the languages specified. The user can still enable or disable spellcheck for languages not in the list.\n\nIf you don't set this policy, or disable it, there is no change to the user's spellcheck preferences.\n\nIf the \"SpellcheckEnabled\" policy is set to disabled, this policy has no effect.\n\nIf a language is included in both the \"SpellcheckLanguage\" and the 'SpellcheckLanguageBlocklist' policy, the spellcheck language is enabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowed","displayName":"Allow users to proceed from the HTTPS warning page","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure (default) this policy, users can click through these warning pages.\n\nIf you disable this policy, users are blocked from clicking through any warning page.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowedfororigins","displayName":"Allow users to proceed from the HTTPS warning page for specific origins","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure the \"SSLErrorOverrideAllowed\" policy, this policy does nothing.\n\nIf you disable the \"SSLErrorOverrideAllowed\" policy, configuring this policy lets you configure a list of origin patterns for sites where users can continue to click through SSL error pages. Users can't click through SSL error pages on origins that are not on this list.\n\nIf you don't configure this policy, the \"SSLErrorOverrideAllowed\" policy applies for all sites.\n\nFor detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy. This policy only matches based on origin, so any path or query in the URL pattern is ignored.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.standardizedbrowserzoomenabled","displayName":"Enable Standardized Browser Zoom Behavior","description":"Configures whether the CSS \"zoom\" property follows the current CSS specification or legacy behavior.\n\nWhen this policy is enabled or not configured, the CSS \"zoom\" property follows the current specification defined by the CSS Working Group:\nhttps://drafts.csswg.org/css-viewport/#zoom-property\n\nWhen this policy is disabled, the CSS \"zoom\" property uses its legacy, pre-standardized behavior.\n\nThis policy is temporary and is intended to provide time for organizations to migrate web content to the updated behavior. In a future Microsoft Edge release, this policy will be removed and the standardized behavior will be enforced by default.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.standardizedbrowserzoomenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.standardizedbrowserzoomenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.staticstoragequotaenabled","displayName":"Control whether storage quota APIs will return static values","description":"Controls how the Storage Quota APIs report the available quota to websites.\n\nWhen enabled, the Storage Quota APIs return a static quota value equal to the current usage plus the smaller of 10 GiB or the device's total storage rounded up to the nearest 1 GiB.\n\nWhen disabled, the Storage Quota APIs return a dynamic quota value that reflects the actual available device storage.\n\nWhen unset, the browser uses the default platform behavior.\n\nThis policy does not affect sites with unlimited storage permissions or enforced quota settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.staticstoragequotaenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.staticstoragequotaenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.strictermixedcontenttreatmentenabled","displayName":"Enable stricter treatment for mixed content (Obsolete)","description":"This policy doesn't work because it was only intended to be a short-term mechanism to give enterprises more time to update their web content if it was found to be incompatible with stricter mixed content treatment.\n\nThis policy controls the treatment for mixed content (HTTP content in HTTPS sites) in the browser.\n\nIf you set this policy to true or not set, audio and video mixed content is automatically upgraded to HTTPS (that is, the URL will be rewritten as HTTPS, without a fallback if the resource isn't available over HTTPS), and a 'Not Secure' warning is shown in the URL bar for image mixed content.\n\nIf you set the policy to false, auto upgrades are disabled for audio and video, and no warning is shown for images.\n\nThis policy doesn't affect other types of mixed content other than audio, video, and images.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.strictermixedcontenttreatmentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.strictermixedcontenttreatmentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.superdragdropenabled","displayName":"Super Drag Drop Enabled","description":"This policy lets you configure the Super Drag Drop feature in Microsoft Edge.\n\nWith this feature, users can drag a link or text from a webpage and drop it onto the same page. They can then either open the URL in a new tab or search the text using the default search engine.\n\nIf you enable or don't configure this policy, you can use the Super Drag Drop feature on Microsoft Edge.\n\nIf you disable this policy, you can't use the Super Drag Drop feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.superdragdropenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.superdragdropenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.syncdisabled","displayName":"Disable synchronization of data using Microsoft sync services","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\n\nThis policy disables cloud synchronization only and has no impact on the \"RoamingProfileSupportEnabled\" policy.\n\nIf you don't set this policy or apply it as recommended, users can turn on or turn off sync. If you apply this policy as mandatory, users won't be able to turn on sync.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.syncdisabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.syncdisabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.syncdisabled_recommended","displayName":"Disable synchronization of data using Microsoft sync services (users can override)","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\n\nThis policy disables cloud synchronization only and has no impact on the \"RoamingProfileSupportEnabled\" policy.\n\nIf you don't set this policy or apply it as recommended, users can turn on or turn off sync. If you apply this policy as mandatory, users won't be able to turn on sync.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.syncdisabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.syncdisabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.synctypeslistdisabled","displayName":"Configure the list of types that are excluded from synchronization","description":"If you enable this policy, all the specified data types are excluded from synchronization. This policy can be used to limit the type of data uploaded to the Microsoft Edge synchronization service.\n\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", \"history\", \"openTabs\", \"edgeWallet\", \"collections\", \"apps\", and \"edgeFeatureUsage\". The \"edgeFeatureUsage\" data type are supported starting in Microsoft Edge version 134. These data type names are case sensitive.\n\nUsers can't override the disabled data types.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.tabcaptureallowedbyorigins","displayName":"Allow Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Tab Capture.\n\nLeaving the policy unset means that sites aren't considered for an override at this scope of capture.\n\nThis policy is not considered if a site matches a URL pattern in the \"SameOriginTabCaptureAllowedByOrigins\" policy.\n\nIf a site matches a URL pattern in this policy, the following policies aren't considered: \"WindowCaptureAllowedByOrigins\", \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.tabservicesenabled","displayName":"Enable tab organization suggestions","description":"This policy controls whether Microsoft Edge can use its tab organization service to help name or suggest tab groups to increase productivity.\n\nIf you enable or don't configure this policy, when a user creates a tab group or activates certain \"Group Similar Tabs\" features Microsoft Edge sends tab data to its tab organization service. This data includes URLs, page titles, and existing group information. The service uses this data to return suggestions for better groupings and group names.\n\nIf you disable this policy, no data is sent to the tab organization service. Microsoft Edge can't suggest group names when a group is created and certain \"Group Similar Tabs\" features that rely on the service aren't available.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.tabservicesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.tabservicesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.textpredictionenabled","displayName":"Text prediction enabled by default","description":"The Microsoft Turing service uses natural language processing to generate predictions for long-form editable text fields on web pages.\n\nIf you enable or don't configure this policy, text predictions are provided for eligible text fields.\n\nIf you disable this policy, text predictions aren't provided in eligible text fields. Sites may still provide their own text predictions.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.textpredictionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.textpredictionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.thirdpartystoragepartitioningblockedfororigins","displayName":"Disable third-party storage partitioning for specific top-level origins (Obsolete)","description":"This policy lets you set a list of URL patterns that specify top-level origins for which third-party storage partitioning (partitioning of cross-origin iframe storage) should be disabled.\n\nIf this policy isn't set or a top-level origin doesn't match one of the URL patterns, then the value from \"DefaultThirdPartyStoragePartitioningSetting\" will be used.\n\nNote that the patterns you list are treated as origins, not URLs, so you shouldn't specify a path. For detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nThis feature has been removed starting in Microsoft Edge version 146. To ensure compatibility, use the requestStorageAccess method instead. For more information, see https://developer.mozilla.org/en-US/docs/Web/API/Document/requestStorageAccess.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors (Obsolete)","description":"This policy doesn't work because it was only intended to be a short-term mechanism to give enterprises more time to upgrade affected proxies.\n\nThis policy controls a security feature in TLS 1.3 that protects connections against downgrade attacks. It's backwards-compatible and doesn't affect connections to compliant TLS 1.2 servers or proxies. However, older versions of some TLS-intercepting proxies have an implementation flaw which causes them to be incompatible.\n\nIf you enable or don't configure this policy, Microsoft Edge enables these security protections for all connections.\n\nIf you disable this policy, Microsoft Edge disables these security protections for connections authenticated with locally-installed CA certificates. These protections are always enabled for connections authenticated with publicly-trusted CA certificates.\n\nThis policy can be used to test for any affected proxies and upgrade them. Affected proxies are expected to fail connections with an error code of ERR_TLS13_DOWNGRADE_DETECTED.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.tls13hardeningforlocalanchorsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.tls13hardeningforlocalanchorsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention","displayName":"Block tracking of users' web-browsing activity","description":"Lets you decide whether to block websites from tracking users' web-browsing activity.\n\nIf you disable this policy or don't configure it, users set their own level of tracking prevention.\n\nPolicy options mapping:\n\n* TrackingPreventionOff (0) = Off (no tracking prevention)\n\n* TrackingPreventionBasic (1) = Basic (blocks harmful trackers, content and ads will be personalized)\n\n* TrackingPreventionBalanced (2) = Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)\n\n* TrackingPreventionStrict (3) = Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionoff","displayName":"Off (no tracking prevention)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionbasic","displayName":"Basic (blocks harmful trackers, content and ads will be personalized)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionbalanced","displayName":"Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionstrict","displayName":"Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.translateenabled","displayName":"Enable Translate","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge offers to translate a webpage by showing an integrated translate flyout when the language detected on a webpage isn't listed under preferred languages. A translate option is available on the right-click context menu.\n\nUsers can also translate selected text on a webpage via the right-click context menu, or on a PDF via the PDF toolbar and the right-click context menu.\n\nIf you don't configure this policy, the policy is enabled by default. Users can choose whether to use the translation functionality or not.\n\nYou can disable this policy to disable all built-in translate features.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.translateenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.translateenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.translateenabled_recommended","displayName":"Enable Translate (users can override)","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge offers to translate a webpage by showing an integrated translate flyout when the language detected on a webpage isn't listed under preferred languages. A translate option is available on the right-click context menu.\n\nUsers can also translate selected text on a webpage via the right-click context menu, or on a PDF via the PDF toolbar and the right-click context menu.\n\nIf you don't configure this policy, the policy is enabled by default. Users can choose whether to use the translation functionality or not.\n\nYou can disable this policy to disable all built-in translate features.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.translateenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.translateenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.travelassistanceenabled","displayName":"Enable travel assistance (Obsolete)","description":"This policy is obsolete as the feature is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy. It doesn't work in Microsoft Edge after version 105.\nConfigure this policy to allow/disallow travel assistance.\n\nThe travel assistance feature gives helpful and relevant information to a user who performs a travel-related task within the browser. This feature provides trusted and validated suggestions/information to the users from across sources gathered by Microsoft.\n\nIf you enable or don't configure this setting, travel assistance is enabled for the users when they are performing travel-related tasks.\n\nIf you disable this setting, travel assistance will be disabled, and users won't be able to see any travel-related recommendations.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.travelassistanceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.travelassistanceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.travelassistanceenabled_recommended","displayName":"Enable travel assistance (Obsolete) (users can override)","description":"This policy is obsolete as the feature is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy. It doesn't work in Microsoft Edge after version 105.\nConfigure this policy to allow/disallow travel assistance.\n\nThe travel assistance feature gives helpful and relevant information to a user who performs a travel-related task within the browser. This feature provides trusted and validated suggestions/information to the users from across sources gathered by Microsoft.\n\nIf you enable or don't configure this setting, travel assistance is enabled for the users when they are performing travel-related tasks.\n\nIf you disable this setting, travel assistance will be disabled, and users won't be able to see any travel-related recommendations.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.travelassistanceenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.travelassistanceenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.typosquattingallowlistdomains","displayName":"Configure the list of domains for which Microsoft Edge Website Typo Protection won't trigger warnings","description":"Configures the list of Microsoft Edge Website Typo Protection trusted domains. This means:\nMicrosoft Edge Website Typo Protection won't check for potentially malicious typosquatting websites.\n\nIf you enable this policy, Microsoft Edge Website Typo Protection trusts these domains.\nIf you disable or don't set this policy, default Microsoft Edge Website Typo Protection protection is applied to all resources.\n\nThis only takes effect when TyposquattingCheckerEnabled policy isn't set or is set to enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10/11 Pro; or Enterprise instances that enrolled for device management; or macOS instances that are that are managed via MDM or joined to a domain via MCX.\nThis policy doesn't apply if your organization has enabled Microsoft Defender for Endpoint. You must configure your allowlists and blocklists in Microsoft 365 Defender portal using Indicators (Settings > Endpoints > Indicators).","helpText":null,"infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.u2fsecuritykeyapienabled","displayName":"Allow using the deprecated U2F Security Key API (Obsolete)","description":"This policy is obsolete because it was intended to be a short-term mechanism to give enterprises more time to update their web content that's incompatible with the change to remove the U2F Security Key API. It doesn't work in Microsoft Edge after version 103.\n\nIf you enable this policy, the deprecated U2F Security Key API can be used and the deprecation reminder prompt shown for U2F API requests is suppressed.\n\nIf you disable this policy or don't configure it, the U2F Security Key API is disabled by default and can only be used by sites that register for and use the U2FSecurityKeyAPI origin trial, which ended after Microsoft Edge version 103.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.u2fsecuritykeyapienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.u2fsecuritykeyapienabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.unthrottlednestedtimeoutenabled","displayName":"JavaScript setTimeout will not be clamped until a higher nesting threshold is set (Deprecated)","description":"This policy is deprecated because it's a temporary policy for web standards compliance. It doesn't work in Microsoft Edge version 107 onward.\nIf you enable this policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4 ms, aren't clamped. This improves short horizon performance; however, websites abusing the API still have their setTimeout usages clamped.\nIf you disable or don't configure this policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4 ms, are clamped.\n\nThis is a web standards compliancy feature that changes task ordering on a webpage, leading to unexpected behavior on sites that are dependent on a certain ordering.\nIt also affects sites with a lot of usage of a timeout of 0 ms for setTimeout, for example, increasing CPU load.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.unthrottlednestedtimeoutenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.unthrottlednestedtimeoutenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.uploadfromphoneenabled","displayName":"Enable upload files from mobile in Microsoft Edge desktop","description":"This policy lets you configure the \"Upload from mobile\" feature in Microsoft Edge.\n\nUpload from mobile lets users select file from mobile devices to desktop when user upload file in a webpage in Microsoft Edge.\n\nIf you enable or don't configure this policy, you can use the Upload from mobile feature in Microsoft Edge.\n\nIf you disable this policy, you can't use the Upload from mobile feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.uploadfromphoneenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.uploadfromphoneenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.urlallowlist","displayName":"Define a list of allowed URLs","description":"Setting the policy provides access to the listed URLs as exceptions to \"URLBlocklist\".\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can use this policy to open exceptions to restrictive blocklists. For example, you can include '*' in the blocklist to block all requests, and then use this policy to allow access to a limited list of URLs. You can use this policy to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths.\n\nThe most specific filter determines if a URL is blocked or allowed. The allowed list takes precedence over the blocked list.\n\nThis policy is limited to 1000 entries; subsequent entries are ignored.\n\nThis policy also allows the browser to automatically invoke external applications registered as protocol handlers for protocols like \"tel:\" or \"ssh:\".\n\nIf you don't configure this policy, there are no exceptions to the blocklist in the \"URLBlocklist\" policy.\n\nThis policy doesn't work as expected with file://* wildcards.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.urlblocklist","displayName":"Block access to a list of URLs","description":"Defines a list of sites, based on URL patterns, that are blocked (your users can't load them).\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can define exceptions in the \"URLAllowlist\" policy. These policies are limited to 1000 entries; subsequent entries are ignored.\n\nBlocking internal 'edge://*' URLs isn't recommended - this may lead to unexpected errors.\n\nThis policy doesn't prevent the page from updating dynamically through JavaScript. For example, if you block 'contoso.com/abc', users can visit 'contoso.com' and select on a link to visit 'contoso.com/abc', as long as the page doesn't refresh.\n\nIf you don't configure this policy, no URLs are blocked.\n\nThis policy doesn't work as expected with file://* wildcards.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction","displayName":"Enable or disable the User-Agent Reduction (Obsolete)","description":"The User-Agent HTTP request header has been reduced by default since Microsoft Edge version 119. To continue receiving detailed platform information, migrate to User-Agent Client Hints, which replace the deprecated detailed User-Agent header. For more information, visit: https://web.dev/articles/migrate-to-ua-ch\n\nIf you don't configure this policy or set it to Default, the User-Agent header will be reduced and controlled by experimentation.\n\nSet this policy to 'ForceEnabled' to force the reduced version of the User-Agent request header for all origins.\n\nSet this policy to 'ForceDisabled' to always use the full (legacy) User-Agent header.\n\nTo learn more about the User-Agent string, read here:\n\nhttps://go.microsoft.com/fwlink/?linkid=2186267\n\nPolicy options mapping:\n\n* Default (0) = Reduced User Agent, or controlled by experimentation.\n\n* ForceDisabled (1) = Full (legacy) User Agent.\n\n* ForceEnabled (2) = Reduced User Agent.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction_default","displayName":"Reduced User Agent, or controlled by experimentation.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction_forcedisabled","displayName":"Full (legacy) User Agent.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction_forceenabled","displayName":"Reduced User Agent.","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.usesystemprintdialog","displayName":"Print using system print dialog","description":"Shows the system print dialog instead of print preview.\n\nIf you enable this policy, Microsoft Edge opens the system print dialog instead of the built-in print preview when a user prints a page.\n\nIf you don't configure or disable this policy, print commands trigger the Microsoft Edge print preview screen.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.usesystemprintdialog_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.usesystemprintdialog_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.verticaltabsallowed","displayName":"Configures availability of a vertical layout for tabs on the side of the browser","description":"Configures whether a user can access an alternative layout where tabs are vertically aligned on the side of the browser instead of at the top.\nWhen there are several tabs open, this layout provides better tab viewing and management. There's better visibility of the site titles,\nit's easier to scan aligned icons, and there's more space to manage and close tabs.\n\nIf you disable this policy, then the vertical tab layout isn't available as an option for users.\n\nIf you enable or don't configure this policy, the tab layout remains at the top, but a user has the option to turn on vertical tabs on the side.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.verticaltabsallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.verticaltabsallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.videocaptureallowed","displayName":"Allow or block video capture","description":"Control whether sites can capture video.\n\nIf enabled or not configured (default), the user is asked about video capture access for all sites except sites with URLs configured in the \"VideoCaptureAllowedUrls\" policy list, which is granted without prompting.\n\nIf you disable this policy, the user isn't prompted, and video capture is only available to URLs configured in \"VideoCaptureAllowedUrls\" policy.\n\nThis policy affects all types of video inputs, not only the built-in camera.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.videocaptureallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.videocaptureallowed_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.videocaptureallowedurls","displayName":"Sites that can access video capture devices without requesting permission","description":"Specify websites, based on URL patterns, that can use video capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to video capture devices. However, the pattern \"*\", which matches any URL, isn't supported by this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.viewxfapdfiniemodeallowedfilehash","displayName":"View XFA-based PDF files using IE Mode for allowed file hash.","description":"XFA is a legacy technology that's deprecated by its original creators. It's not an ISO standard and as such, it doesn't align with the modern web architecture. Continued use poses potential risks and vulnerabilities. For more information, see \"ViewXFAPDFInIEModeAllowedOrigins\".\n\nIf you enable this policy, you can configure the list of base64 encoded SHA256 file hashes for which XFA PDF files automatically open in Microsoft Edge using IE Mode.\n\nIf you disable or don't configure this policy, XFA PDFs won't be considered for opening via IE mode except the files from file origin mentioned in Policy \"ViewXFAPDFInIEModeAllowedOrigins\"\n\nFor more information, see - [Get-FileHash](https://go.microsoft.com/fwlink/?linkid=2294823), [Dot Net Convert API](https://go.microsoft.com/fwlink/?linkid=2294913).","helpText":null,"infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.viewxfapdfiniemodeallowedorigins","displayName":"View XFA-based PDF files using IE Mode for allowed file origin.","description":"Internet Explorer (IE) mode uses the Adobe Acrobat Active-X PDF Plugin to open XFA-based PDF files. This policy works only if the Active-X plugin is already on the user's device, it's not installed as part of this policy.\n\nIt's important to note that XFA is a legacy technology that's deprecated by its original creators. It's not an ISO standard and as such doesn't align with the modern web architecture. Continued use poses potential risks and vulnerabilities.\n\nGiven the deprecated status of XFA technology and the lack of any investment by its creators, we strongly recommend that you start planning your transition to more advanced HTML\\PDF form-based solutions.\n\nIn the interim, this policy provides a workaround for users to view XFA PDF in Microsoft Edge.\n\nIf you enable this policy, you can configure the list of origins from which XFA PDF files will be automatically opened in Microsoft Edge using IE Mode.\n\nIf you disable or don't configure the policy, XFA PDFs won't be considered for opening via Internet Explorer mode.\n\nFor detailed information on valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322\n\nAlternatively, \"ViewXFAPDFInIEModeAllowedFileHash\" can also be used to configure list of file hashes instead of URL origins, which enables those files to be automatically opened in Microsoft Edge using IE Mode.","helpText":null,"infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled","displayName":"Visual search enabled","description":"Visual search lets you quickly explore more related content about entities in an image.\n\nIf you enable or don't configure this policy, visual search is enabled via image hover, context menu, and search in sidebar.\n\nIf you disable this policy, visual search is disabled and you can't get more info about images via hover, context menu, and search in sidebar.\n\nNote: Visual Search in Web Capture is still managed by \"WebCaptureEnabled\" policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_recommended","displayName":"Visual search enabled (users can override)","description":"Visual search lets you quickly explore more related content about entities in an image.\n\nIf you enable or don't configure this policy, visual search is enabled via image hover, context menu, and search in sidebar.\n\nIf you disable this policy, visual search is disabled and you can't get more info about images via hover, context menu, and search in sidebar.\n\nNote: Visual Search in Web Capture is still managed by \"WebCaptureEnabled\" policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled","displayName":"Wallet Donation Enabled (Deprecated)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\n\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\n\nIf you disable this policy, users can't use the Wallet Donation feature.\n\nThis policy is deprecated because the Wallet Donation feature has been removed from Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_recommended","displayName":"Wallet Donation Enabled (Deprecated) (users can override)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\n\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\n\nIf you disable this policy, users can't use the Wallet Donation feature.\n\nThis policy is deprecated because the Wallet Donation feature has been removed from Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webappinstallbyuserenabled","displayName":"Enable User Web App Install From Browser","description":"This policy controls whether users can install web apps through Microsoft Edge.\nIf you enable or don’t configure this policy, users can install web apps through the browser.\nIf you disable this policy, users can’t install web apps through the browser, and the \"apps\" data type is excluded from synchronization.\nThis policy doesn't support dynamic refresh. Changes to this policy, whether enabled, disabled, or not configured, take effect only after the browser is restarted.\nThis policy doesn't affect the 'WebAppInstallForceList' policy. Web apps specified by that policy are installed regardless of this policy setting.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webappinstallbyuserenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webappinstallbyuserenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webappinstallforcelist","displayName":"Configure list of force-installed Web Apps","description":"Setting the policy specifies a list of web apps that install silently, without user interaction. Users can't turn off the policy or uninstall these web apps.\n\nEach list item of the policy is an object with a mandatory member:\nurl (the URL of the web app to install)\n\nand 6 optional members:\n- default_launch_container\n(for how the web app opens—a new tab is the default)\n\n- create_desktop_shortcut\n(True if you want to create Linux and\nMicrosoft Windows desktop shortcuts).\n\n- fallback_app_name\n(Starting with Microsoft Edge version 90,\nyou can permanently override the app name if it's not a Progressive Web App (PWA)\nor you can temporarily override the app name if authentication is required before\ninstallation can be completed. If both\ncustom_name and\nfallback_app_name are provided,\nthe latter is ignored.)\n\n- custom_name\n(Starting with Microsoft Edge version 112\non all desktop platforms, you can permanently override the app name for all\nweb apps and PWAs.)\n\n- custom_icon\n(Starting with Microsoft Edge version 112\non all desktop platforms, you can override the app icon of installed apps.\nThe icons have to be square, maximal 1 MB in size, and in one of the following formats:\njpeg, png, gif, webp, ico. The hash value has to be the SHA256 hash of the icon file.\nThe url should be accessible without authentication to\nensure that the icon can be used upon app installation.)\n\n- install_as_shortcut\n(Starting with Microsoft Edge\nversion 107). If enabled, the given url is installed as a shortcut,\nas if done via the \"Create Shortcut...\" option in the desktop browser GUI.\nWhen installed as a shortcut, it won't be updated if the manifest in url changes.\nIf disabled or unset, the web app at the given url is installed normally.\n(This isn't currently supported in Microsoft Edge.)\n\nThe 'WebAppInstallByUserEnabled' policy doesn't affect this policy. Web apps specified by this policy are installed regardless of the 'WebAppInstallByUserEnabled' policy setting.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webappsettings","displayName":"Web App management settings","description":"This policy allows an admin to specify settings for installed web apps. This policy maps a Web App ID to its specific setting. A default configuration can be set using the special ID *, which applies to all web apps without a custom configuration in this policy.\n\n- The manifest_id field is the Manifest ID for the Web App.\nSee https://developer.chrome.com/blog/pwa-manifest-id/\nfor instructions on how to determine the Manifest ID for an installed web app.\n- The run_on_os_login field specifies if a web app can be run during OS sign in.\nIf you set this field to blocked, the web app doesn't run during OS sign in, and the user can't enable this later.\nIf you set this field to run_windowed, the web app runs during OS sign in, and the user can't disable this later.\nIf you set this field to allowed, the user configures the web app to run at OS sign in.\nThe default policy configuration only allows the allowed and blocked values.\n- (Starting with Microsoft Edge version 120) The prevent_close_after_run_on_os_login field specifies if a web app can be prevented from closing in any way.\nFor example, by the user, by task manager, or by web APIs. This behavior can only be enabled if run_on_os_login is set to run_windowed.\nIf the app is already running, this setting will only take effect after the app is restarted.\nIf this field isn't defined, users can close the app.\n(This is currently not supported in Microsoft Edge.)\n- (Since version 118) The force_unregister_os_integration field specifies if all OS integration for a web app, that is, shortcuts, file handlers, protocol handlers and so on, will be removed or not.\nIf an app is already running, this property comes into effect after the app restarts.\nThis should be used with caution, since it can override any OS integration that is set automatically during the startup of the web applications system. This currently only works on Windows, Mac and Linux platforms.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webaudiooutputbufferingenabled","displayName":"Enable adaptive buffering for Web Audio","description":"This policy determines whether the browser enables adaptive buffering\nfor Web Audio. Adaptive buffering can reduce audio glitches but can\nincrease latency to varying degrees.\n\nIf this policy is enabled, the browser uses adaptive buffering.\nIf this policy is disabled or not configured, the browser automatically decides during the\n feature launch process whether to use adaptive buffering.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webaudiooutputbufferingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webaudiooutputbufferingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webauthenticationremotedesktopallowedorigins","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications.","description":"This policy defines a list of allowed HTTPS origins for remote desktop client applications that initiate WebAuthn API requests from a browsing session on a remote host.\n\nOrigins specified in this policy can request WebAuthn authentication for Relying Party IDs (RP IDs) they wouldn't typically be authorized to claim.\n\nOnly HTTPS origins are supported. Wildcards aren't permitted. Entries that don't\nmeet these requirements will be ignored.\n\nFor more information about the WebAuthn Remote Desktop Support feature, see https://github.com/w3c/webauthn/wiki/Explainer:-Remote-Desktop-Support/a4e158c569f456c759d0ddd294a9015bd4d4eb9a.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84 (Obsolete)","description":"This policy doesn't work because this policy allowed these features to be selectively re-enabled until Microsoft Edge version 85. The Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and are disabled by default starting in Microsoft Edge version 80.\n\nIf you set this policy to True, the Web Components v0 features are enabled for all sites.\n\nIf you set this policy to False or don't set this policy, the Web Components v0 features are disabled by default, starting in Microsoft Edge version 80.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webcomponentsv0enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webcomponentsv0enabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webhidaskforurls","displayName":"Allow the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\n\nLeaving the policy unset means \"DefaultWebHidGuardSetting\" applies for all sites, if set. If not, users' personal settings apply.\n\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\n\n * \"WebHidBlockedForUrls\" (if there's a match),\n\n * \"DefaultWebHidGuardSetting\" (if set), or\n\n * Users' personal settings.\n\nURL patterns must not conflict with \"WebHidBlockedForUrls\". Neither policy takes precedence if a URL matches both patterns.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webhidblockedforurls","displayName":"Block the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a HID device.\n\nLeaving the policy unset means \"DefaultWebHidGuardSetting\" applies for all sites, if set. If not, users' personal settings apply.\n\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\n\n * \"WebHidAskForUrls\" (if there's a match),\n\n * \"DefaultWebHidGuardSetting\" (if set), or\n\n * Users' personal settings.\n\nURL patterns can't conflict with \"WebHidAskForUrls\". Neither policy takes precedence if a URL matches both patterns.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtciphandlingurl","displayName":"WebRTC IP Handling Policy for URL Patterns","description":"Controls which IP addresses and network interfaces WebRTC can use\nwhen establishing connections for specific URL patterns.\n\nHow It Works:\nAccepts a list of URL patterns, each paired with a handling type.\nWebRTC evaluates patterns sequentially; the first match determines the handling type.\nIf no match is found, WebRTC defaults to the WebRtcLocalhostIpHandling WebRtcLocalhostIpHandling. policy.\nThis policy applies only to origins—URL path components are ignored.\nWildcards (*) are supported in URL patterns.\n\nSupported Handling Values:\ndefault – Uses all available network interfaces.\ndefault_public_and_private_interfaces – WebRTC uses all public and private interfaces.\ndefault_public_interface_only – WebRTC uses only public interfaces.\ndisable_non_proxied_udp – WebRTC uses UDP SOCKS proxying or falls back to TCP proxying.\n\nMore Information:\nValid input patterns: https://go.microsoft.com/fwlink/?linkid=2095322\nHandling types: https://tools.ietf.org/html/rfc8828.html#section-5.2","helpText":null,"infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtclocalhostiphandling","displayName":"Restrict exposure of local IP address by WebRTC","description":"Allows you to set whether or not WebRTC exposes the user's local IP address.\n\nIf you set this policy to \"AllowAllInterfaces\" or \"AllowPublicAndPrivateInterfaces\", WebRTC exposes the local IP address.\n\nIf you set this policy to \"AllowPublicInterfaceOnly\" or \"DisableNonProxiedUdp\", WebRTC doesn't expose the local IP address.\n\nIf you don't set this policy, or if you disable it, WebRTC exposes the local IP address.\n\nNote that this policy doesn't provide an option to exclude specific domains.\n\nPolicy options mapping:\n\n* AllowAllInterfaces (default) = Allow all interfaces. This exposes the local IP address\n\n* AllowPublicAndPrivateInterfaces (default_public_and_private_interfaces) = Allow public and private interfaces over http default route. This exposes the local IP address\n\n* AllowPublicInterfaceOnly (default_public_interface_only) = Allow public interface over http default route. This doesn't expose the local IP address\n\n* DisableNonProxiedUdp (disable_non_proxied_udp) = Use TCP unless proxy server supports UDP. This doesn't expose the local IP address\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtclocalhostiphandling_allowallinterfaces","displayName":"Allow all interfaces. This exposes the local IP address","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtclocalhostiphandling_allowpublicandprivateinterfaces","displayName":"Allow public and private interfaces over http default route. This exposes the local IP address","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtclocalhostiphandling_allowpublicinterfaceonly","displayName":"Allow public interface over http default route. This doesn't expose the local IP address","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtclocalhostiphandling_disablenonproxiedudp","displayName":"Use TCP unless proxy server supports UDP. This doesn't expose the local IP address","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtclocalipsallowedurls","displayName":"Manage exposure of local IP addressess by WebRTC","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*contoso.com*\") for which local IP address should be exposed by WebRTC.\n\nIf you enable this policy and set a list of origins (URLs) or hostname patterns, when edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will expose the local IP address for cases that match patterns in the list.\n\nIf you disable or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will not expose local IP addresses. The local IP address is concealed with an mDNS hostname.\n\nIf you enable, disable, or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, WebRTC will expose local IP addresses.\n\nPlease note that this policy weakens the protection of local IP addresses that might be needed by administrators.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC","description":"This policy controls the use of post-quantum key agreement for WebRTC in Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge will offer post-quantum key agreement for WebRTC.\n\nIf you disable this policy, post-quantum key agreement won't be offered for WebRTC.\n\nIf you don't configure this policy, post-quantum key agreement won't be offered for WebRTC. A future version of Microsoft Edge may enable this feature by default.\n\nOffering a post-quantum key agreement is backwards compatible. Existing datagram transport layer security (DTLS) peers and networking middleware are expected to ignore the new option and continue using previous options.\n\nHowever, devices that don't correctly implement DTLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or larger message sizes. Such devices aren’t post-quantum-ready and may interfere with an organization's post-quantum transition. If this issue occurs, administrators should contact the device vendor for a fix.\n\nThis policy is temporary and will be removed in a future release.","helpText":null,"infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtcpostquantumkeyagreement_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtcpostquantumkeyagreement_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC","description":"Restricts the UDP port range used by WebRTC to a specified port interval (endpoints included).\n\nBy configuring this policy, you specify the range of local UDP ports that WebRTC can use.\n\nIf you don't configure this policy, or if you set it to an empty string or invalid port range, WebRTC can use any available local UDP port.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webselectenabled","displayName":"Web Select Enabled (Obsolete)","description":"This policy is obsoleted because Web Select is part of Web Capture and can be controlled by \"WebCaptureEnabled\". This policy doesn't work in Microsoft Edge version 117. If Web Capture is disabled by \"WebCaptureEnabled\", Web select won't be available in Web Capture.\n\nWeb select lets users select and copy web content while preserving its formatting when pasted in most cases. It also allows more targeted selection on some web elements, such as copying a single column in a table.\n\nIf you enable or don't configure this policy, Web select is available in Web Capture and can be accessed directly using the CTRL+SHIFT+X keyboard shortcut.\n\nIf you disable this policy, Web select won't be available in Web Capture and the CTRL+SHIFT+X keyboard shortcut will also not work.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webselectenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webselectenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlaccess","displayName":"Force WebSQL to be enabled (Obsolete)","description":"This policy was removed in Microsoft Edge 124 and is ignored if set.\n\nWebSQL is on by default as of Microsoft Edge version 101, but can be disabled via a Microsoft Edge flag.\nIf you enable this policy, WebSQL cannot be disabled.\nIf you disable or don't configure this policy, WebSQL can be disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlaccess_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlaccess_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlnonsecurecontextenabled","displayName":"Force WebSQL in non-secure contexts to be enabled (Obsolete)","description":"This policy doesn't work because WebSQL in nonsecure contexts is on by default as of Microsoft Edge 105.\nIf you enable this policy, WebSQL in nonsecure contexts is enabled.\nIf you disable or don't configure this policy, WebSQL in nonsecure contexts follows the default settings of the browser.\n\nThis policy was removed in Microsoft Edge 113, and it's ignored if configured.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlnonsecurecontextenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlnonsecurecontextenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webusballowdevicesforurls","displayName":"Grant access to specific sites to connect to specific USB devices","description":"Allows you to set a list of URLs that specify which sites will automatically be granted permission to access a USB device with the given vendor and product IDs. Each item in the list must contain both devices and URLs for the policy to be valid. Each item in devices can contain a vendor ID and product ID field. Any ID that is omitted is treated as a wildcard with one exception, and that exception is that a product ID can't be specified without a vendor ID also being specified. Otherwise, the policy isn't valid and is ignored.\n\nThe USB permission model uses the URL of the requesting site (\"requesting URL\") and the URL of the top-level frame site (\"embedding URL\") to grant permission to the requesting URL to access the USB device. The requesting URL may be different than the embedding URL when the requesting site is loaded in an iframe. Therefore, the \"urls\" field can contain up to two URL strings delimited by a comma to specify the requesting and embedding URL respectively. If only one URL is specified, then access to the corresponding USB devices is granted when the requesting site's URL matches this URL regardless of embedding status. The URLs in \"urls\" must be valid URLs; otherwise, the policy is ignored.\n\nThis is deprecated and only supported for backwards compatibility in the following manner. If both a requesting and embedding URL are specified, then the embedding URL is granted the permission as top-level origin, and the requesting URL is ignored entirely.\n\nIf you don't configure this policy, the global default value is used for all sites either from the \"DefaultWebUsbGuardSetting\" policy if it is set, or the user's personal configuration otherwise.\n\nURL patterns in this policy shouldn't clash with the ones configured via \"WebUsbBlockedForUrls\". If there's a clash, this policy takes precedence over \"WebUsbBlockedForUrls\" and \"WebUsbAskForUrls\".","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webusbaskforurls","displayName":"Allow WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can ask the user for access to a USB device.\n\nIf you don't configure this policy, the global default value from the \"DefaultWebUsbGuardSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"WebUsbBlockedForUrls\" policy - you can't both allow and block a URL. For detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webusbblockedforurls","displayName":"Block WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can't ask the user to grant them access to a USB device.\n\nIf you don't configure this policy, the global default value from the \"DefaultWebUsbGuardSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nURL patterns in this policy can't conflict with those configured in the \"WebUsbAskForUrls\" policy. You can't both allow and block a URL. For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.whatsnewpageforentraprofilesenabled","displayName":"Control whether an informational webpage for Edge for Business is shown in the new tab after major browser updates","description":"Starting in Microsoft Edge version 145, users with Microsoft Entra ID profiles will see an informational page about new Edge for Business features after major browser updates. This page highlights recent enhancements designed to promote secure and productive browsing.\n\nThis policy controls whether users with Microsoft Entra ID profiles see this informational page. This policy applies only to Microsoft Entra ID profiles and does not apply to Microsoft account (MSA) profiles.\n\nThis policy is available starting in Microsoft Edge version 144 to allow configuration ahead of the changes introduced in version 145.\n\nIf you enable this policy or do not configure it, Microsoft Edge shows the informational page by default.\nIf you disable this policy, Microsoft Edge does not show the informational page to users.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.whatsnewpageforentraprofilesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.whatsnewpageforentraprofilesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.edge.mamedgeappconfigsettings.windowcaptureallowedbyorigins","displayName":"Allow Window and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Window and Tab Capture.\n\nLeaving the policy unset means that sites won't be considered for an override at this scope of Capture.\n\nThis policy isn't considered if a site matches a URL pattern in any of the following policies: \"TabCaptureAllowedByOrigins\", \"SameOriginTabCaptureAllowedByOrigins\".\n\nIf a site matches a URL pattern in this policy, the following policies aren't considered: \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin; so, any path in the URL pattern is ignored.","helpText":null,"infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.windowmanagementallowedforurls","displayName":"Allow Window Management permission on specified sites","description":"Lets you configure a list of site URL patterns that specify sites, which automatically grant the window management permission. This extends the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\n\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\n\nIf this policy isn't configured for a site, then the policy from \"DefaultWindowManagementSetting\" applies to the site, if configured. Otherwise the permission follows the browser's defaults and lets users choose this permission per site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.windowmanagementblockedforurls","displayName":"Block Window Management permission on specified sites","description":"Lets you configure a list of site URL patterns that specify sites which can automatically deny the window management permission. This limits the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\n\nFor detailed information on valid site URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\n\nIf this policy isn't configured for a site, then the policy from \"DefaultWindowManagementSetting\" applies to the site, if configured. Otherwise the permission follows the browser's defaults and lets users choose this permission per site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.workspacesnavigationsettings","displayName":"Configure navigation settings per groups of URLs in Microsoft Edge Workspaces","description":"This setting lets you define groups of URLs, and apply specific Microsoft Edge Workspaces navigation settings to each group.\n\nIf you configure this policy, Microsoft Edge Workspaces use the configured settings when deciding whether and how to share navigations among collaborators in a Microsoft Edge Workspace.\n\nIf you don't configure this policy, Microsoft Edge Workspaces use only default and internally configured navigation settings.\n\nFor more information about configuration options, see https://go.microsoft.com/fwlink/?linkid=2218655\n\nNote, format url_patterns according to https://go.microsoft.com/fwlink/?linkid=2095322. You can configure the url_regex_patterns in this policy to match multiple URLs using a Perl style regular expression for the pattern. Note that pattern matches are case sensitive. For more information about the regular expression rules that are used, refer to https://go.microsoft.com/fwlink/p/?linkid=2133903.","helpText":null,"infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.xsltenabled","displayName":"Control the availability of the XSLT feature","description":"Controls whether the XSLT feature (the XSLTProcessor JavaScript API and the XSL processing instruction) is available in Microsoft Edge.\n\nIf you enable this policy, XSLT is available regardless of the browser's default configuration.\n\nIf you disable this policy, XSLT is unavailable regardless of the browser's default configuration.\n\nIf you don't configure this policy, XSLT availability is determined by the browser's default configuration and any applicable field trials.\n\nThis policy is temporary and will be removed in a future version of Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.xsltenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.xsltenabled_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"com.microsoft.intune.mam.managedbrowser.appproxyredirection","displayName":"Application proxy redirection","description":"Enable App proxy redirection to give users access to corporate links and on-premise web apps.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.intune.mam.managedbrowser.appproxyredirection_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.intune.mam.managedbrowser.appproxyredirection_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"command_remotedesktop","displayName":"Remote Desktop","description":"","helpText":null,"infoUrls":[],"categoryId":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","categoryName":"Remote Desktop","options":null},{"id":"command_remotedesktop_remotedesktop","displayName":"Remote Desktop","description":"Enable/Disable Remote Desktop on the device","helpText":null,"infoUrls":[],"categoryId":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","categoryName":"Remote Desktop","options":[{"id":"command_remotedesktop_remotedesktop_true","displayName":"Enable","description":null,"helpText":null},{"id":"command_remotedesktop_remotedesktop_false","displayName":"Disable","description":null,"helpText":null}]},{"id":"contentcaching_allowcachedelete","displayName":"Allow Cache Delete","description":"If `true`, the system purges content from the cache automatically when it needs disk space for other apps when free disk space runs low on the computer. Set to `false` to maximize effectiveness of Content Caching.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_allowcachedelete_false","displayName":"Blocked","description":null,"helpText":null},{"id":"contentcaching_allowcachedelete_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"contentcaching_allowpersonalcaching","displayName":"Allow Personal Caching","description":"If `true`, the system caches the user's iCloud data. Changes to this value don't have an immediate effect. Clients may take some time to react to changes.\n\n> Note:\n> At least one of the `AllowPersonalCaching` or `AllowSharedCaching` keys need to be `true`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_allowpersonalcaching_false","displayName":"Blocked","description":null,"helpText":null},{"id":"contentcaching_allowpersonalcaching_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"contentcaching_allowsharedcaching","displayName":"Allow Shared Caching","description":"If `true`, the system caches non-iCloud content, such as apps and software updates. Changes to this value don't have an immediate effect. Clients may take some time to react to changes.\n\n> Note:\n> At least one of the `AllowPersonalCaching` or `AllowSharedCaching` keys need to be `true`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_allowsharedcaching_false","displayName":"Blocked","description":null,"helpText":null},{"id":"contentcaching_allowsharedcaching_true","displayName":"Allowed","description":null,"helpText":null}]},{"id":"contentcaching_autoactivation","displayName":"Auto Activation","description":"If `true`, the system automatically activates the content cache when possible and prevents disabling it. If `allowContentCaching` is `false`, `AutoActivation` is also `false`.\n\nRemoving a profile that set `AutoActivation` to `true` doesn't deactivate the Content Cache.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_autoactivation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_autoactivation_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"contentcaching_autoenabletetheredcaching","displayName":"Auto Enable Tethered Caching","description":"If `true`, the system automatically enables Internet connection sharing when possible and prevent disabling Internet connection sharing. `DenyTetheredCaching` overrides `AutoEnableTetheredCaching`. Tethered caching requires Content Caching.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_autoenabletetheredcaching_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_autoenabletetheredcaching_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"contentcaching_cachelimit","displayName":"Cache Limit","description":"The maximum number of bytes of disk space to use for the content cache. Set to `0` for unlimited disk space. Also serves as the upper bound to the `PersonalCacheLimit`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_contentcaching","displayName":"com.apple.configuration.content-cache.settings","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_datapath","displayName":"Data Path","description":"The path to the directory used to store cached content. Changing this setting manually doesn't automatically move cached content from the old location to the new one. To move content automatically, use the Sharing preference's Content Caching pane. The value must be (or end with) `/Library/Application Support/Apple/AssetCache/Data`.\n\nThe system creates a directory and its intermediates for the given data path if it doesn't already exist. The directory is owned by `_assetcache:_assetcache` and has mode 0750. Its immediate parent directory (`.../Library/Application Support/Apple/AssetCache`) is owned by `_assetcache:_assetcache` and has mode `0755`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_declarativestatusinterval","displayName":"Declarative Status Interval","description":"The time interval in seconds the system uses to update the `StatusContentCacheInfo` declarative status item. The reporting interval can't be less than 60 (1 per minute) or larger than 86400 (1 per day), defaults to 0 (off)","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_denyactivation","displayName":"Deny Activation","description":"If `true`, the system disables Content Caching. This is the inverse of the `allowContentCaching` restriction in MDM. It overrides the `AutoActivation` key. Use this key to prevent launching the Content Caching service.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_denyactivation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_denyactivation_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"contentcaching_denytetheredcaching","displayName":"Deny Tethered Caching","description":"If `true`, the system disables tethered caching.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_denytetheredcaching_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_denytetheredcaching_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"contentcaching_displayalerts","displayName":"Display Alerts","description":"If `true`, Content Caching displays exceptional conditions (alerts) as system notifications in the upper corner of the screen.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_displayalerts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_displayalerts_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"contentcaching_keepawake","displayName":"Keep Awake","description":"If `true`, the system prevents the computer from sleeping as long as Content Caching is on (System Preferences > Sharing > Content Caching is on). Customers who want Content Caching to be as available as much as possible should turn this setting on.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_keepawake_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_keepawake_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"contentcaching_listenranges","displayName":"Listen Ranges","description":"An array of dictionaries that describe a range of client IP addresses to serve.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_listenranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_listenranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_listenranges_item_type","displayName":"Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_listenranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"contentcaching_listenranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},{"id":"contentcaching_listenrangesonly","displayName":"Listen Ranges Only","description":"If `true`, the content cache provides content to the clients in the `ListenRanges`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_listenrangesonly_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_listenrangesonly_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"contentcaching_listenwithpeersandparents","displayName":"Listen With Peers And Parents","description":"If `true`, the content cache provides content to the clients in the union of the `ListenRanges`, `PeerListenRanges` and `Parents`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_listenwithpeersandparents_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_listenwithpeersandparents_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"contentcaching_localsubnetsonly","displayName":"Local Subnets Only","description":"If `true`, the content cache offers content to clients only on the same immediate local network only. The content cache offers no content to clients on other networks reachable by the content cache. If `LocalSubnetsOnly` is `true`, the system ignores `ListenRanges`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_localsubnetsonly_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_localsubnetsonly_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"contentcaching_logclientidentity","displayName":"Log Client Identity","description":"If `true`, the Content Cache logs the IP address and port number of the clients that request content.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_logclientidentity_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_logclientidentity_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"contentcaching_parents","displayName":"Parents","description":"An array of the local IP addresses of other content caches that this cache should download from or upload to, instead of downloading from or uploading to Apple directly. The system ignores invalid addresses and addresses of computers that aren't content caches. The system skips Parent caches that become unavailable. If all parent content caches become unavailable, the content cache downloads from or uploads to Apple directly, until a parent content cache becomes available again.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_parentselectionpolicy","displayName":"Parent Selection Policy","description":"The policy to implement when choosing among more than one configured parent content cache. With every policy, the system skips parent caches that are temporarily unavailable. Allowed values:\n\n- `first-available`: Always use the first available parent in the Parents list. Use this policy to designate permanent primary, secondary, and subsequent parents.\n- `url-path-hash`: Hash the path part of the requested URL so that the same parent is always used for the same URL. This is useful for maximizing the size of the combined caches of the parents.\n- `random`: Choose a parent at random. Use this policy for load balancing.\n- `round-robin`: Rotate through the parents in order. Use this policy for load balancing.\n- `sticky-available`: Use the first available parent in the Parents list until it becomes unavailable, then advance to the next one. Use this policy for designating floating primary, secondary, and subsequent parents.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_parentselectionpolicy_0","displayName":"first-available","description":null,"helpText":null},{"id":"contentcaching_parentselectionpolicy_1","displayName":"url-path-hash","description":null,"helpText":null},{"id":"contentcaching_parentselectionpolicy_2","displayName":"random","description":null,"helpText":null},{"id":"contentcaching_parentselectionpolicy_3","displayName":"round-robin","description":null,"helpText":null},{"id":"contentcaching_parentselectionpolicy_4","displayName":"sticky-available","description":null,"helpText":null}]},{"id":"contentcaching_peerfilterranges","displayName":"Peer Filter Ranges","description":"An array of dictionaries describing a range of peer IP addresses that the content cache uses to filter its list of peers to query for content. The content cache only queries peers in `PeerFilterRanges`. When `PeerFilterRanges` is an empty array, the content cache doesn't query any peers.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_peerfilterranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_peerfilterranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_peerfilterranges_item_type","displayName":"Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_peerfilterranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"contentcaching_peerfilterranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},{"id":"contentcaching_peerlistenranges","displayName":"Peer Listen Ranges","description":"An array of dictionaries describing a range of peer IP addresses the content cache responds to. When `PeerListenRanges` is an empty array, the content cache responds with an error to all cache queries.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_peerlistenranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_peerlistenranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_peerlistenranges_item_type","displayName":"Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_peerlistenranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"contentcaching_peerlistenranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},{"id":"contentcaching_peerlocalsubnetsonly","displayName":"Peer Local Subnets Only","description":"If `true`, the content cache only peers with other content caches on the same immediate local network, rather than with content caches that use the same public IP address as the device. When `PeerLocalSubnetsOnly` is `true`, it overrides the configuration of `PeerFilterRanges` and `PeerListenRanges`. If the network changes, the local network peering restrictions update appropriately. If `false`, the content cache defers to `PeerFilterRanges` and `PeerListenRanges` for configuring the peering restrictions.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_peerlocalsubnetsonly_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_peerlocalsubnetsonly_true","displayName":"Enabled","description":null,"helpText":null}]},{"id":"contentcaching_personalcachelimit","displayName":"Personal Cache Limit","description":"The maximum number of bytes of disk space to use for the personal content cache. The content cache limits the maximum value to the `CacheLimit` value. Set to `0` to use the overall `CacheLimit`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_port","displayName":"Port","description":"The TCP port number on which the content cache accepts requests for uploads or downloads. Set to `0` to pick a random, available port.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_publicranges","displayName":"Public Ranges","description":"An array of dictionaries describing a range of public IP addresses that the cloud servers should use for matching clients to content caches.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_publicranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_publicranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},{"id":"contentcaching_publicranges_item_type","displayName":"Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_publicranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"contentcaching_publicranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},{"id":"ddm-latestsoftwareupdate_ddm-latestsoftwareupdate","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"15be55d8-7477-4274-9b09-b775bce68416","categoryName":"Software Update Enforce Latest","options":null},{"id":"ddm-latestsoftwareupdate_delayindays","displayName":"Delay In Days","description":"Specify the number of days that should pass before a deadline is enforced after a new update is released by Apple.","helpText":null,"infoUrls":[],"categoryId":"15be55d8-7477-4274-9b09-b775bce68416","categoryName":"Software Update Enforce Latest","options":null},{"id":"ddm-latestsoftwareupdate_enforcelatestsoftwareupdateversion","displayName":"Enforce Latest Software Update Version","description":"If true, devices will upgrade to the latest OS version that is available for that device model. This uses the Software Update Enforcement configuration and will force devices to restart and install the update after the deadline passes.","helpText":null,"infoUrls":[],"categoryId":"15be55d8-7477-4274-9b09-b775bce68416","categoryName":"Software Update Enforce Latest","options":{"id":"ddm-latestsoftwareupdate_enforcelatestsoftwareupdateversion_0","displayName":"True","description":null,"helpText":null}},{"id":"ddm-latestsoftwareupdate_installtime","displayName":"Install Time","description":"Specify the local device time for when updates are enforced. This setting uses the 24-hour clock format where midnight is 00:00 and 11:59pm is 23:59. Ensure that you include the leading 0 on single digit hours. For example, 01:00, 02:00, 03:00.","helpText":null,"infoUrls":[],"categoryId":"15be55d8-7477-4274-9b09-b775bce68416","categoryName":"Software Update Enforce Latest","options":null},{"id":"defender_disableprivacymode","displayName":"Allow users to view the full History results","description":"Disable the privacy mode","helpText":null,"infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"defender_disableprivacymode_0","displayName":"No","description":null,"helpText":null},{"id":"defender_disableprivacymode_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"defender_disablerestorepoint","displayName":"Create a system restore point before computers are cleaned","description":"Disables restore point","helpText":null,"infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"defender_disablerestorepoint_0","displayName":"No","description":null,"helpText":null},{"id":"defender_disablerestorepoint_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"defender_randomizescheduletasktimes","displayName":"Randomize scheduled scan and security intelligence update start times","description":"This setting allows you to enable or disable randomization of the scheduled scan start time and the scheduled definition update start time. This setting is used to distribute the resource impact of scanning. For example, it could be used in guest virtual machines sharing a host, to prevent multiple guest virtual machines from undertaking a disk-intensive operation at the same time.","helpText":null,"infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"defender_randomizescheduletasktimes_0","displayName":"No","description":null,"helpText":null},{"id":"defender_randomizescheduletasktimes_1","displayName":"Yes","description":null,"helpText":null}]},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_deletionpolicy","displayName":"Deletion Policy","description":"Configures when profiles will be deleted. Allowed values: 0 (delete immediately upon device returning to a state with no currently active users); 1 (delete at storage capacity threshold); 2 (delete at both storage capacity threshold and profile inactivity threshold).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":[{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_deletionpolicy_0","displayName":"Delete immediately upon device returning to a state with no currently active users)","description":"Delete immediately upon device returning to a state with no currently active users)","helpText":null},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_deletionpolicy_1","displayName":"Delete at storage capacity threshold","description":"Delete at storage capacity threshold","helpText":null},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_deletionpolicy_2","displayName":"Delete at both storage capacity threshold and profile inactivity threshold","description":"Delete at both storage capacity threshold and profile inactivity threshold","helpText":null}]},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_enableprofilemanager","displayName":"Enable Profile Manager","description":"Enable profile lifetime mangement for shared or communal device scenarios.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":[{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_enableprofilemanager_false","displayName":"False","description":"False","helpText":null},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_enableprofilemanager_true","displayName":"True","description":"True","helpText":null}]},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_profileinactivitythreshold","displayName":"Profile Inactivity Threshold","description":"Start deleting profiles when they have not been logged on during the specified period, given as number of days.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":null},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_storagecapacitystartdeletion","displayName":"Storage Capacity Start Deletion","description":"Start deleting profiles when available storage capacity falls below this threshold, given as percent of total storage available for profiles. Profiles that have been inactive the longest will be deleted first.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":null},{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_storagecapacitystopdeletion","displayName":"Storage Capacity Stop Deletion","description":"Stop deleting profiles when available storage capacity is brought up to this threshold, given as percent of total storage available for profiles.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":null},{"id":"device_vendor_msft_bitlocker_allowstandarduserencryption","displayName":"Allow Standard User Encryption","description":"Allows Admin to enforce \"RequireDeviceEncryption\" policy for scenarios where policy is pushed while current logged on user is non-admin/standard user.\n \"AllowStandardUserEncryption\" policy is tied to \"AllowWarningForOtherDiskEncryption\" policy being set to \"0\", i.e, Silent encryption is enforced.\n If \"AllowWarningForOtherDiskEncryption\" is not set, or is set to \"1\", \"RequireDeviceEncryption\" policy will not try to encrypt drive(s) if a standard user\n is the current logged on user in the system.\n\n The expected values for this policy are: \n\n 1 = \"RequireDeviceEncryption\" policy will try to enable encryption on all fixed drives even if a current logged in user is standard user.\n 0 = This is the default, when the policy is not set. If current logged on user is a standard user, \"RequireDeviceEncryption\" policy\n will not try to enable encryption on any drive.\n\n If you want to disable this policy use the following SyncML:\n 111./Device/Vendor/MSFT/BitLocker/AllowStandardUserEncryptionint0","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":[{"id":"device_vendor_msft_bitlocker_allowstandarduserencryption_0","displayName":"Disabled","description":"This is the default, when the policy is not set. If current logged on user is a standard user, \"RequireDeviceEncryption\" policy will not try to enable encryption on any drive.","helpText":null},{"id":"device_vendor_msft_bitlocker_allowstandarduserencryption_1","displayName":"Enabled","description":"\"RequireDeviceEncryption\" policy will try to enable encryption on all fixed drives even if a current logged in user is standard user.","helpText":null}]},{"id":"device_vendor_msft_bitlocker_allowwarningforotherdiskencryption","displayName":"Allow Warning For Other Disk Encryption","description":"Allows Admin to disable all UI (notification for encryption and warning prompt for other disk encryption)\n and turn on encryption on the user machines silently.\n Warning: When you enable BitLocker on a device with third party encryption, it may render the device unusable and will\n require reinstallation of Windows.\n Note: This policy takes effect only if \"RequireDeviceEncryption\" policy is set to 1.\n The format is integer.\n The expected values for this policy are: \n\n 1 = This is the default, when the policy is not set. Warning prompt and encryption notification is allowed.\n 0 = Disables the warning prompt and encryption notification. Starting in Windows 10, next major update, \n the value 0 only takes affect on Entra ID joined devices. \n Windows will attempt to silently enable BitLocker for value 0.\n\n If you want to disable this policy use the following SyncML:\n 110./Device/Vendor/MSFT/BitLocker/AllowWarningForOtherDiskEncryptionint0","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#allowwarningforotherdiskencryption"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":[{"id":"device_vendor_msft_bitlocker_allowwarningforotherdiskencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_allowwarningforotherdiskencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation","displayName":"Configure Recovery Password Rotation","description":" Allows Admin to configure Numeric Recovery Password Rotation upon use for OS and fixed drives on Entra ID and Hybrid domain joined devices.\n When not configured, Rotation is turned on by default for Entra ID only and off on Hybrid. The Policy will be effective only when \n Active Directory back up for recovery password is configured to required.\n For OS drive: Turn on \"Do not enable Bitlocker until recovery information is stored to AD DS for operating system drives\"\n For Fixed drives: Turn on \"Do not enable Bitlocker until recovery information is stored to AD DS for fixed data drives\"\n \n Supported Values: 0 - Numeric Recovery Passwords rotation OFF.\n 1 - Numeric Recovery Passwords Rotation upon use ON for Entra ID joined devices. Default value\n 2 - Numeric Recovery Passwords Rotation upon use ON for both Entra ID and Hybrid devices\n \n If you want to disable this policy use the following SyncML:\n \n 112./Device/Vendor/MSFT/BitLocker/ConfigureRecoveryPasswordRotationint0","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":[{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation_0","displayName":"Refresh off (default)","description":"Refresh off (default)","helpText":null},{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation_1","displayName":"Refresh on for Entra ID-joined devices","description":"Refresh on for Entra ID-joined devices","helpText":null},{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation_2","displayName":"Refresh on for both Entra ID-joined and hybrid-joined devices","description":"Refresh on for both Entra ID-joined and hybrid-joined devices","helpText":null}]},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype","displayName":"Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)","description":"This policy setting allows you to configure the algorithm and cipher strength used by BitLocker Drive Encryption. This policy setting is applied when you turn on BitLocker. Changing the encryption method has no effect if the drive is already encrypted, or if encryption is in progress.\n\nIf you enable this policy setting you will be able to configure an encryption algorithm and key cipher strength for fixed data drives, operating system drives, and removable data drives individually. For fixed and operating system drives, we recommend that you use the XTS-AES algorithm. For removable drives, you should use AES-CBC 128-bit or AES-CBC 256-bit if the drive will be used in other devices that are not running Windows 10 (Version 1511).\n\nIf you disable or do not configure this policy setting, BitLocker will use AES with the same bit strength (128-bit or 256-bit) as the \"Choose drive encryption method and cipher strength (Windows Vista, Windows Server 2008, Windows 7)\" and \"Choose drive encryption method and cipher strength\" policy settings (in that order), if they are set. If none of the policies are set, BitLocker will use the default encryption method of XTS-AES 128-bit or the encryption method specified by the setup script.”\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#encryptionmethodbydrivetype"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsfdvdropdown_name","displayName":"Select the encryption method for fixed data drives:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#encryptionmethodbydrivetype"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsfdvdropdown_name_3","displayName":"AES-CBC 128-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsfdvdropdown_name_4","displayName":"AES-CBC 256-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsfdvdropdown_name_6","displayName":"XTS-AES 128-bit (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsfdvdropdown_name_7","displayName":"XTS-AES 256-bit","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsosdropdown_name","displayName":"Select the encryption method for operating system drives:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#encryptionmethodbydrivetype"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsosdropdown_name_3","displayName":"AES-CBC 128-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsosdropdown_name_4","displayName":"AES-CBC 256-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsosdropdown_name_6","displayName":"XTS-AES 128-bit (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsosdropdown_name_7","displayName":"XTS-AES 256-bit","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name","displayName":"Select the encryption method for removable data drives:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#encryptionmethodbydrivetype"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_3","displayName":"AES-CBC 128-bit (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_4","displayName":"AES-CBC 256-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_6","displayName":"XTS-AES 128-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_7","displayName":"XTS-AES 256-bit","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype","displayName":"Enforce drive encryption type on fixed data drives","description":"This policy setting allows you to configure the encryption type used by BitLocker Drive Encryption. This policy setting is applied when you turn on BitLocker. Changing the encryption type has no effect if the drive is already encrypted or if encryption is in progress. Choose full encryption to require that the entire drive be encrypted when BitLocker is turned on. Choose used space only encryption to require that only the portion of the drive used to store data is encrypted when BitLocker is turned on.\r\n\r\nIf you enable this policy setting the encryption type that BitLocker will use to encrypt drives is defined by this policy and the encryption type option will not be presented in the BitLocker setup wizard.\r\n\r\nIf you disable or do not configure this policy setting, the BitLocker setup wizard will ask the user to select the encryption type before turning on BitLocker.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name","displayName":"Select the encryption type:","description":"","helpText":"","infoUrls":[],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name_0","displayName":"Allow user to choose (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name_1","displayName":"Full encryption","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name_2","displayName":"Used Space Only encryption","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions","displayName":"Choose how BitLocker-protected fixed drives can be recovered","description":"This policy setting allows you to control how BitLocker-protected fixed data drives are recovered in the absence of the required credentials. This policy setting is applied when you turn on BitLocker.\n\nThe \"Allow data recovery agent\" check box is used to specify whether a data recovery agent can be used with BitLocker-protected fixed data drives. Before a data recovery agent can be used it must be added from the Public Key Policies item in either the Group Policy Management Console or the Local Group Policy Editor. Consult the BitLocker Drive Encryption Deployment Guide on Microsoft TechNet for more information about adding data recovery agents.\n\nIn \"Configure user storage of BitLocker recovery information\" select whether users are allowed, required, or not allowed to generate a 48-digit recovery password or a 256-bit recovery key.\n\nSelect \"Omit recovery options from the BitLocker setup wizard\" to prevent users from specifying recovery options when they turn on BitLocker on a drive. This means that you will not be able to specify which recovery option to use when you turn on BitLocker, instead BitLocker recovery options for the drive are determined by the policy setting.\n\nIn \"Save BitLocker recovery information to Active Directory Domain Services\" choose which BitLocker recovery information to store in AD DS for fixed data drives. If you select \"Backup recovery password and key package\", both the BitLocker recovery password and key package are stored in AD DS. Storing the key package supports recovering data from a drive that has been physically corrupted. If you select \"Backup recovery password only,\" only the recovery password is stored in AD DS.\n\nSelect the \"Do not enable BitLocker until recovery information is stored in AD DS for fixed data drives\" check box if you want to prevent users from enabling BitLocker unless the computer is connected to the domain and the backup of BitLocker recovery information to AD DS succeeds.\n\nNote: If the \"Do not enable BitLocker until recovery information is stored in AD DS for fixed data drives\" check box is selected, a recovery password is automatically generated.\n\nIf you enable this policy setting, you can control the methods available to users to recover data from BitLocker-protected fixed data drives.\n\nIf this policy setting is not configured or disabled, the default recovery options are supported for BitLocker recovery. By default a DRA is allowed, the recovery options can be specified by the user including the recovery password and recovery key, and recovery information is not backed up to AD DS\n\n","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackup_name","displayName":"Save BitLocker recovery information to AD DS for fixed data drives","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackup_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackup_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackupdropdown_name","displayName":"Configure storage of BitLocker recovery information to AD DS:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackupdropdown_name_1","displayName":"Backup recovery passwords and key packages","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackupdropdown_name_2","displayName":"Backup recovery passwords only","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvallowdra_name","displayName":"Allow data recovery agent","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvallowdra_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvallowdra_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvhiderecoverypage_name","displayName":"Omit recovery options from the BitLocker setup wizard","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvhiderecoverypage_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvhiderecoverypage_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name","displayName":"FDVRecoveryKeyUsageDropDown_Name","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name_2","displayName":"Allow 256-bit recovery key","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name_1","displayName":"Require 256-bit recovery key","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name_0","displayName":"Do not allow 256-bit recovery key","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverypasswordusagedropdown_name","displayName":"Configure user storage of BitLocker recovery information:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverypasswordusagedropdown_name_2","displayName":"Allow 48-digit recovery password","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverypasswordusagedropdown_name_1","displayName":"Require 48-digit recovery password","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverypasswordusagedropdown_name_0","displayName":"Do not allow 48-digit recovery password","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrequireactivedirectorybackup_name","displayName":"Do not enable BitLocker until recovery information is stored to AD DS for fixed data drives","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrequireactivedirectorybackup_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrequireactivedirectorybackup_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_fixeddrivesrequireencryption","displayName":"Deny write access to fixed drives not protected by BitLocker","description":"This policy setting determines whether BitLocker protection is required for fixed data drives to be writable on a computer.\n\nIf you enable this policy setting, all fixed data drives that are not BitLocker-protected will be mounted as read-only. If the drive is protected by BitLocker, it will be mounted with read and write access.\n\nIf you disable or do not configure this policy setting, all fixed data drives on the computer will be mounted with read and write access.\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrequireencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrequireencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_identificationfield","displayName":"Provide the unique identifiers for your organization","description":"This policy setting allows you to associate unique organizational identifiers to a new drive that is enabled with BitLocker. These identifiers are stored as the identification field and allowed identification field. The identification field allows you to associate a unique organizational identifier to BitLocker-protected drives. This identifier is automatically added to new BitLocker-protected drives and can be updated on existing BitLocker-protected drives using the manage-bde command-line tool. An identification field is required for management of certificate-based data recovery agents on BitLocker-protected drives and for potential updates to the BitLocker To Go Reader. BitLocker will only manage and update data recovery agents when the identification field on the drive matches the value configured in the identification field. In a similar manner, BitLocker will only update the BitLocker To Go Reader when the identification field on the drive matches the value configured for the identification field.\r\n\r\nThe allowed identification field is used in combination with the \"Deny write access to removable drives not protected by BitLocker\" policy setting to help control the use of removable drives in your organization. It is a comma separated list of identification fields from your organization or other external organizations.\r\n\r\nYou can configure the identification fields on existing drives by using manage-bde.exe.\r\n\r\nIf you enable this policy setting, you can configure the identification field on the BitLocker-protected drive and any allowed identification field used by your organization.\r\n\r\nWhen a BitLocker-protected drive is mounted on another BitLocker-enabled computer the identification field and allowed identification field will be used to determine whether the drive is from an outside organization.\r\n\r\nIf you disable or do not configure this policy setting, the identification field is not required.\r\n\r\nNote: Identification fields are required for management of certificate-based data recovery agents on BitLocker-protected drives. BitLocker will only manage and update certificate-based data recovery agents when the identification field is present on a drive and is identical to the value configured on the computer. The identification field can be any value of 260 characters or fewer.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_identificationfield_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_identificationfield_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_identificationfield_identificationfield","displayName":"BitLocker identification field:","description":"","helpText":"","infoUrls":[],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":null},{"id":"device_vendor_msft_bitlocker_identificationfield_secidentificationfield","displayName":"Allowed BitLocker identification field:","description":"","helpText":"","infoUrls":[],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":null},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde","displayName":"Control use of BitLocker on removable drives","description":"This policy setting controls the use of BitLocker on removable data drives. This policy setting is applied when you turn on BitLocker.\r\n\r\nWhen this policy setting is enabled you can select property settings that control how users can configure BitLocker. Choose \"Allow users to apply BitLocker protection on removable data drives\" to permit the user to run the BitLocker setup wizard on a removable data drive. Choose \"Allow users to suspend and decrypt BitLocker on removable data drives\" to permit the user to remove BitLocker Drive encryption from the drive or suspend the encryption while maintenance is performed. Consult the BitLocker Drive Encryption Deployment Guide on Microsoft TechNet for more information on suspending BitLocker protection.\r\n\r\nIf you do not configure this policy setting, users can use BitLocker on removable disk drives.\r\n\r\nIf you disable this policy setting, users cannot use BitLocker on removable disk drives.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvallowbde_name","displayName":"Allow users to apply BitLocker protection on removable data drives","description":"","helpText":"","infoUrls":[],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvallowbde_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvallowbde_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvdisablebde_name","displayName":"Allow users to suspend and decrypt BitLocker protection on removable data drives","description":"","helpText":"","infoUrls":[],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvdisablebde_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvdisablebde_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype","displayName":"Enforce drive encryption type on removable data drives","description":"This policy setting allows you to configure the encryption type used by BitLocker Drive Encryption. This policy setting is applied when you turn on BitLocker. Changing the encryption type has no effect if the drive is already encrypted or if encryption is in progress. Choose full encryption to require that the entire drive be encrypted when BitLocker is turned on. Choose used space only encryption to require that only the portion of the drive used to store data is encrypted when BitLocker is turned on.\r\n\r\nIf you enable this policy setting the encryption type that BitLocker will use to encrypt drives is defined by this policy and the encryption type option will not be presented in the BitLocker setup wizard.\r\n\r\nIf you disable or do not configure this policy setting, the BitLocker setup wizard will ask the user to select the encryption type before turning on BitLocker.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_rdvencryptiontypedropdown_name","displayName":"Select the encryption type:","description":"","helpText":"","infoUrls":[],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_rdvencryptiontypedropdown_name_0","displayName":"Allow user to choose (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_rdvencryptiontypedropdown_name_1","displayName":"Full encryption","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_rdvencryptiontypedropdown_name_2","displayName":"Used Space Only encryption","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_removabledrivesexcludedfromencryption","displayName":"Removable Drives Excluded From Encryption","description":"When enabled, allows you to exclude removable drives and devices connected over USB interface from BitLocker Device Encryption. Excluded devices cannot be encrypted, even manually. Additionally, if \"Deny write access to removable drives not protected by BitLocker\" is configured, user will not be prompted for encryption and drive will be mounted in read/write mode. Provide a comma separated list of excluded removable drives\\devices, using the Hardware ID of the disk device. Example USBSTOR\\SEAGATE_ST39102LW_______0004.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":null},{"id":"device_vendor_msft_bitlocker_removabledrivesrequireencryption","displayName":"Deny write access to removable drives not protected by BitLocker","description":"This policy setting configures whether BitLocker protection is required for a computer to be able to write data to a removable data drive.\n\nIf you enable this policy setting, all removable data drives that are not BitLocker-protected will be mounted as read-only. If the drive is protected by BitLocker, it will be mounted with read and write access.\n\nIf the \"Deny write access to devices configured in another organization\" option is selected, only drives with identification fields matching the computer's identification fields will be given write access. When a removable data drive is accessed it will be checked for valid identification field and allowed identification fields. These fields are defined by the \"Provide the unique identifiers for your organization\" policy setting.\n\nIf you disable or do not configure this policy setting, all removable data drives on the computer will be mounted with read and write access.\n\nNote: This policy setting can be overridden by the policy settings under User Configuration\\Administrative Templates\\System\\Removable Storage Access. If the \"Removable Disks: Deny write access\" policy setting is enabled this policy setting will be ignored.\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesrequireencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesrequireencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_removabledrivesrequireencryption_rdvcrossorg","displayName":"Do not allow write access to devices configured in another organization","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesrequireencryption_rdvcrossorg_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesrequireencryption_rdvcrossorg_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_requiredeviceencryption","displayName":"Require Device Encryption","description":"Allows the Admin to require encryption to be turned on using BitLocker\\Device Encryption.\n The format is integer.\n Sample value for this node to enable this policy:\n 1\n\n Disabling the policy will not turn off the encryption on the system drive. But will stop prompting the user to turn it on.\n If you want to disable this policy use the following SyncML:\n 101./Device/Vendor/MSFT/BitLocker/RequireDeviceEncryptionint0","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":[{"id":"device_vendor_msft_bitlocker_requiredeviceencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_requiredeviceencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesdisallowstandarduserscanchangepin","displayName":"Disallow standard users from changing the PIN or password","description":"This policy setting allows you to configure whether or not standard users are allowed to change BitLocker volume PINs, provided they are able to provide the existing PIN first.\r\n\r\nThis policy setting is applied when you turn on BitLocker.\r\n\r\nIf you enable this policy setting, standard users will not be allowed to change BitLocker PINs or passwords.\r\n\r\nIf you disable or do not configure this policy setting, standard users will be permitted to change BitLocker PINs and passwords.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesdisallowstandarduserscanchangepin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesdisallowstandarduserscanchangepin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesenableprebootinputprotectorsonslates","displayName":"Enable use of BitLocker authentication requiring preboot keyboard input on slates","description":"This policy setting allows users to turn on authentication options that require user input from the pre-boot environment, even if the platform lacks pre-boot input capability.\r\n\r\nThe Windows touch keyboard (such as that used by tablets) isn't available in the pre-boot environment where BitLocker requires additional information such as a PIN or Password.\r\n\r\nIf you enable this policy setting, devices must have an alternative means of pre-boot input (such as an attached USB keyboard).\r\n\r\nIf this policy is not enabled, the Windows Recovery Environment must be enabled on tablets to support the entry of the BitLocker recovery password. When the Windows Recovery Environment is not enabled and this policy is not enabled, you cannot turn on BitLocker on a device that uses the Windows touch keyboard.\r\n\r\nNote that if you do not enable this policy setting, options in the \"Require additional authentication at startup\" policy might not be available on such devices. These options include:\r\n- Configure TPM startup PIN: Required/Allowed\r\n- Configure TPM startup key and PIN: Required/Allowed\r\n- Configure use of passwords for operating system drives.\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesenableprebootinputprotectorsonslates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesenableprebootinputprotectorsonslates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesenableprebootpinexceptionondecapabledevice","displayName":"Allow devices compliant with InstantGo or HSTI to opt out of pre-boot PIN.","description":"This policy setting allows users on devices that are compliant with InstantGo or Microsoft Hardware Security Test Interface (HSTI) to not have a PIN for pre-boot authentication. This overrides the \"Require startup PIN with TPM\" and \"Require startup key and PIN with TPM\" options of the \"Require additional authentication at startup\" policy on compliant hardware.\r\n\r\nIf you enable this policy setting, users on InstantGo and HSTI compliant devices will have the choice to turn on BitLocker without pre-boot authentication.\r\n\r\nIf this policy is not enabled, the options of \"Require additional authentication at startup\" policy apply.\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesenableprebootpinexceptionondecapabledevice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesenableprebootpinexceptionondecapabledevice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype","displayName":"Enforce drive encryption type on operating system drives","description":"This policy setting allows you to configure the encryption type used by BitLocker Drive Encryption. This policy setting is applied when you turn on BitLocker. Changing the encryption type has no effect if the drive is already encrypted or if encryption is in progress. Choose full encryption to require that the entire drive be encrypted when BitLocker is turned on. Choose used space only encryption to require that only the portion of the drive used to store data is encrypted when BitLocker is turned on.\r\n\r\nIf you enable this policy setting the encryption type that BitLocker will use to encrypt drives is defined by this policy and the encryption type option will not be presented in the BitLocker setup wizard.\r\n\r\nIf you disable or do not configure this policy setting, the BitLocker setup wizard will ask the user to select the encryption type before turning on BitLocker.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype_osencryptiontypedropdown_name","displayName":"Select the encryption type:","description":"","helpText":"","infoUrls":[],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype_osencryptiontypedropdown_name_0","displayName":"Allow user to choose (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype_osencryptiontypedropdown_name_1","displayName":"Full encryption","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesencryptiontype_osencryptiontypedropdown_name_2","displayName":"Used Space Only encryption","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesenhancedpin","displayName":"Allow enhanced PINs for startup","description":"This policy setting allows you to configure whether or not enhanced startup PINs are used with BitLocker.\r\n\r\nEnhanced startup PINs permit the use of characters including uppercase and lowercase letters, symbols, numbers, and spaces. This policy setting is applied when you turn on BitLocker.\r\n\r\nIf you enable this policy setting, all new BitLocker startup PINs set will be enhanced PINs.\r\n\r\nNote: Not all computers may support enhanced PINs in the pre-boot environment. It is strongly recommended that users perform a system check during BitLocker setup.\r\n\r\nIf you disable or do not configure this policy setting, enhanced PINs will not be used.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesenhancedpin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesenhancedpin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength","displayName":"Configure minimum PIN length for startup","description":"\n This policy setting allows you to configure a minimum length for a Trusted Platform Module (TPM) startup PIN. This policy setting is applied when you turn on BitLocker. The startup PIN must have a minimum length of 4 digits and can have a maximum length of 20 digits.\n\n If you enable this policy setting, you can require a minimum number of digits to be used when setting the startup PIN.\n\n If you disable or do not configure this policy setting, users can configure a startup PIN of any length between 6 and 20 digits.\n\n NOTE: If minimum PIN length is set below 6 digits, Windows will attempt to update the TPM 2.0 lockout period to be greater than the default when a PIN is changed. If successful, Windows will only reset the TPM lockout period back to default if the TPM is reset.\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength_minpinlength","displayName":"Minimum characters:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage","displayName":"Configure pre-boot recovery message and URL","description":"This policy setting lets you configure the entire recovery message or replace the existing URL that are displayed on the pre-boot key recovery screen when the OS drive is locked.\n\nIf you select the \"Use default recovery message and URL\" option, the default BitLocker recovery message and URL will be displayed in the pre-boot key recovery screen. If you have previously configured a custom recovery message or URL and want to revert to the default message, you must keep the policy enabled and select the \"Use default recovery message and URL\" option.\n\nIf you select the \"Use custom recovery message\" option, the message you type in the \"Custom recovery message option\" text box will be displayed in the pre-boot key recovery screen. If a recovery URL is available, include it in the message.\n\nIf you select the \"Use custom recovery URL\" option, the URL you type in the \"Custom recovery URL option\" text box will replace the default URL in the default recovery message, which will be displayed in the pre-boot key recovery screen.\n\nNote: Not all characters and languages are supported in pre-boot. It is strongly recommended that you test that the characters you use for the custom message or URL appear correctly on the pre-boot recovery screen.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_prebootrecoveryinfodropdown_name","displayName":"Select an option for the pre-boot recovery message:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_prebootrecoveryinfodropdown_name_0","displayName":"","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_prebootrecoveryinfodropdown_name_1","displayName":"Use default recovery message and URL","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_prebootrecoveryinfodropdown_name_2","displayName":"Use custom recovery message","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_prebootrecoveryinfodropdown_name_3","displayName":"Use custom recovery URL","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_recoverymessage_input","displayName":"Custom recovery message option:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoverymessage_recoveryurl_input","displayName":"Custom recovery URL option:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions","displayName":"Choose how BitLocker-protected operating system drives can be recovered","description":"This policy setting allows you to control how BitLocker-protected operating system drives are recovered in the absence of the required startup key information. This policy setting is applied when you turn on BitLocker.\n\nThe \"Allow certificate-based data recovery agent\" check box is used to specify whether a data recovery agent can be used with BitLocker-protected operating system drives. Before a data recovery agent can be used it must be added from the Public Key Policies item in either the Group Policy Management Console or the Local Group Policy Editor. Consult the BitLocker Drive Encryption Deployment Guide on Microsoft TechNet for more information about adding data recovery agents.\n\nIn \"Configure user storage of BitLocker recovery information\" select whether users are allowed, required, or not allowed to generate a 48-digit recovery password or a 256-bit recovery key.\n\nSelect \"Omit recovery options from the BitLocker setup wizard\" to prevent users from specifying recovery options when they turn on BitLocker on a drive. This means that you will not be able to specify which recovery option to use when you turn on BitLocker, instead BitLocker recovery options for the drive are determined by the policy setting.\n\nIn \"Save BitLocker recovery information to Active Directory Domain Services\", choose which BitLocker recovery information to store in AD DS for operating system drives. If you select \"Backup recovery password and key package\", both the BitLocker recovery password and key package are stored in AD DS. Storing the key package supports recovering data from a drive that has been physically corrupted. If you select \"Backup recovery password only,\" only the recovery password is stored in AD DS.\n\nSelect the \"Do not enable BitLocker until recovery information is stored in AD DS for operating system drives\" check box if you want to prevent users from enabling BitLocker unless the computer is connected to the domain and the backup of BitLocker recovery information to AD DS succeeds.\n\nNote: If the \"Do not enable BitLocker until recovery information is stored in AD DS for operating system drives\" check box is selected, a recovery password is automatically generated.\n\nIf you enable this policy setting, you can control the methods available to users to recover data from BitLocker-protected operating system drives.\n\nIf this policy setting is disabled or not configured, the default recovery options are supported for BitLocker recovery. By default a DRA is allowed, the recovery options can be specified by the user including the recovery password and recovery key, and recovery information is not backed up to AD DS.\n\n","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackup_name","displayName":"Save BitLocker recovery information to AD DS for operating system drives","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackup_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackup_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackupdropdown_name","displayName":"Configure storage of BitLocker recovery information to AD DS:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackupdropdown_name_1","displayName":"Store recovery passwords and key packages","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackupdropdown_name_2","displayName":"Store recovery passwords only","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osallowdra_name","displayName":"Allow data recovery agent","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osallowdra_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osallowdra_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_oshiderecoverypage_name","displayName":"Omit recovery options from the BitLocker setup wizard","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_oshiderecoverypage_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_oshiderecoverypage_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverykeyusagedropdown_name","displayName":"OSRecoveryKeyUsageDropDown_Name","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverykeyusagedropdown_name_2","displayName":"Allow 256-bit recovery key","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverykeyusagedropdown_name_1","displayName":"Require 256-bit recovery key","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverykeyusagedropdown_name_0","displayName":"Do not allow 256-bit recovery key","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverypasswordusagedropdown_name","displayName":"Configure user storage of BitLocker recovery information:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverypasswordusagedropdown_name_2","displayName":"Allow 48-digit recovery password","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverypasswordusagedropdown_name_1","displayName":"Require 48-digit recovery password","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrecoverypasswordusagedropdown_name_0","displayName":"Do not allow 48-digit recovery password","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrequireactivedirectorybackup_name","displayName":"Do not enable BitLocker until recovery information is stored to AD DS for operating system drives","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrequireactivedirectorybackup_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osrequireactivedirectorybackup_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication","displayName":"Require additional authentication at startup","description":"This policy setting allows you to configure whether BitLocker requires additional authentication each time the computer starts and whether you are using BitLocker with or without a Trusted Platform Module (TPM). This policy setting is applied when you turn on BitLocker.\n\nNote: Only one of the additional authentication options can be required at startup, otherwise a policy error occurs.\n\nIf you want to use BitLocker on a computer without a TPM, select the \"Allow BitLocker without a compatible TPM\" check box. In this mode either a password or a USB drive is required for start-up. When using a startup key, the key information used to encrypt the drive is stored on the USB drive, creating a USB key. When the USB key is inserted the access to the drive is authenticated and the drive is accessible. If the USB key is lost or unavailable or if you have forgotten the password then you will need to use one of the BitLocker recovery options to access the drive.\n\nOn a computer with a compatible TPM, four types of authentication methods can be used at startup to provide added protection for encrypted data. When the computer starts, it can use only the TPM for authentication, or it can also require insertion of a USB flash drive containing a startup key, the entry of a 6-digit to 20-digit personal identification number (PIN), or both.\n\nIf you enable this policy setting, users can configure advanced startup options in the BitLocker setup wizard.\n\nIf you disable or do not configure this policy setting, users can configure only basic options on computers with a TPM.\n\nNote: If you want to require the use of a startup PIN and a USB flash drive, you must configure BitLocker settings using the command-line tool manage-bde instead of the BitLocker Drive Encryption setup wizard.\n\n","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurenontpmstartupkeyusage_name","displayName":"Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurenontpmstartupkeyusage_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurenontpmstartupkeyusage_name_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurepinusagedropdown_name","displayName":"Configure TPM startup PIN:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurepinusagedropdown_name_2","displayName":"Allow startup PIN with TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurepinusagedropdown_name_1","displayName":"Require startup PIN with TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurepinusagedropdown_name_0","displayName":"Do not allow startup PIN with TPM","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmpinkeyusagedropdown_name","displayName":"Configure TPM startup key and PIN:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmpinkeyusagedropdown_name_2","displayName":"Allow startup key and PIN with TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmpinkeyusagedropdown_name_1","displayName":"Require startup key and PIN with TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmpinkeyusagedropdown_name_0","displayName":"Do not allow startup key and PIN with TPM","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmstartupkeyusagedropdown_name","displayName":"Configure TPM startup key:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmstartupkeyusagedropdown_name_2","displayName":"Allow startup key with TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmstartupkeyusagedropdown_name_1","displayName":"Require startup key with TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmstartupkeyusagedropdown_name_0","displayName":"Do not allow startup key with TPM","description":null,"helpText":null}]},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name","displayName":"Configure TPM startup:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name_2","displayName":"Allow TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name_1","displayName":"Require TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name_0","displayName":"Do not allow TPM","description":null,"helpText":null}]},{"id":"device_vendor_msft_clouddesktop_boottocloudpcenhanced","displayName":"Boot To Cloud PC Enhanced","description":"This node allows to configure different kinds of Boot to Cloud mode. Boot to cloud mode enables users to seamlessly sign-in to a Cloud PC. For using this feature, Cloud Provider application must be installed on the PC and the user must have a Cloud PC provisioned. This node supports the below options: 0. Not Configured. 1. Enable Boot to Cloud Shared PC Mode: Boot to Cloud Shared PC mode allows multiple users to sign-in on the device and use for shared purpose. 2. Enable Boot to Cloud Dedicated Mode (Cloud only): Dedicated mode allows user to sign-in on the device using various authentication mechanism configured by their organization (For ex. PIN, Biometrics etc). This mode preserves user personalization, including their profile picture and username in local machine, and facilitates fast account switching.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/CloudDesktop-csp/"],"categoryId":"39e4c352-be9c-4e75-8111-8236279c7f1e","categoryName":"Cloud Desktop","options":[{"id":"device_vendor_msft_clouddesktop_boottocloudpcenhanced_0","displayName":"Not Configured","description":"Not Configured","helpText":null},{"id":"device_vendor_msft_clouddesktop_boottocloudpcenhanced_1","displayName":"Enable Boot to Cloud Shared PC Mode","description":"Enable Boot to Cloud Shared PC Mode","helpText":null},{"id":"device_vendor_msft_clouddesktop_boottocloudpcenhanced_2","displayName":"Enable Boot to Cloud Dedicated Mode (Cloud only)","description":"Enable Boot to Cloud Dedicated Mode (Cloud only)","helpText":null}]},{"id":"device_vendor_msft_clouddesktop_enableboottocloudsharedpcmode","displayName":"[Deprecated] Enable Boot To Cloud Shared PC Mode","description":"Setting this node to \"true\" configures boot to cloud for Shared PC mode. Boot to cloud mode enables users to seamlessly sign-in to a Cloud PC. Shared PC mode allows multiple users to sign-in on the device and use for shared purpose. For enabling boot to cloud shared pc feature, Cloud Provider application must be installed on the PC and the user must have a Cloud PC provisioned.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/CloudDesktop-csp/"],"categoryId":"39e4c352-be9c-4e75-8111-8236279c7f1e","categoryName":"Cloud Desktop","options":[{"id":"device_vendor_msft_clouddesktop_enableboottocloudsharedpcmode_false","displayName":"Not configured","description":"Not configured","helpText":null},{"id":"device_vendor_msft_clouddesktop_enableboottocloudsharedpcmode_true","displayName":"Boot to cloud shared pc mode enabled","description":"Boot to cloud shared pc mode enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_aiagentnetworkinspection","displayName":"Ai Agent Network Inspection","description":"This setting controls Defender's runtime AI Agent network protection that scans network traffic originated from AI Agents. When enabled, Defender inspects the network traffic of agent processes and blocks any traffic that matches a detection for malware/abuse signals before the agent executes it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_aiagentnetworkinspection_0","displayName":"AI Agent protection is disabled (default).","description":"AI Agent protection is disabled (default).","helpText":null},{"id":"device_vendor_msft_defender_configuration_aiagentnetworkinspection_1","displayName":"AI Agent protection is enabled in block mode - prompts that match a detection are blocked.","description":"AI Agent protection is enabled in block mode - prompts that match a detection are blocked.","helpText":null},{"id":"device_vendor_msft_defender_configuration_aiagentnetworkinspection_2","displayName":"AI Agent protection is enabled in audit mode - prompts that match a detection are logged but not blocked.","description":"AI Agent protection is enabled in audit mode - prompts that match a detection are logged but not blocked.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_aiagentprotection","displayName":"Ai Agent Protection","description":"This setting controls Defender's runtime AI Agent protection that scans prompts submitted to managed AI coding agents (e.g., Claude Code, GitHub Copilot CLI). When enabled, Defender invokes a bridge process from the agent's hook framework to scan each prompt for malware/abuse signals before the agent executes it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_aiagentprotection_0","displayName":"AI Agent protection is disabled (default).","description":"AI Agent protection is disabled (default).","helpText":null},{"id":"device_vendor_msft_defender_configuration_aiagentprotection_1","displayName":"AI Agent protection is enabled in block mode - prompts that match a detection are blocked.","description":"AI Agent protection is enabled in block mode - prompts that match a detection are blocked.","helpText":null},{"id":"device_vendor_msft_defender_configuration_aiagentprotection_2","displayName":"AI Agent protection is enabled in audit mode - prompts that match a detection are logged but not blocked.","description":"AI Agent protection is enabled in audit mode - prompts that match a detection are logged but not blocked.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_allowdatagramprocessingonwinserver","displayName":"Allow Datagram Processing On Win Server","description":"This settings controls whether Network Protection is allowed to enable datagram processing on Windows Server. If false, the value of DisableDatagramProcessing will be ignored and default to disabling Datagram inspection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_allowdatagramprocessingonwinserver_1","displayName":"Datagram processing on Windows Server is enabled.","description":"Datagram processing on Windows Server is enabled.","helpText":null},{"id":"device_vendor_msft_defender_configuration_allowdatagramprocessingonwinserver_0","displayName":"Datagram processing on Windows Server is disabled.","description":"Datagram processing on Windows Server is disabled.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_allownetworkprotectiondownlevel","displayName":"Allow Network Protection Down Level","description":"This settings controls whether Network Protection is allowed to be configured into block or audit mode on windows downlevel of RS3. If false, the value of EnableNetworkProtection will be ignored.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_allownetworkprotectiondownlevel_1","displayName":"Network protection will be enabled downlevel.","description":"Network protection will be enabled downlevel.","helpText":null},{"id":"device_vendor_msft_defender_configuration_allownetworkprotectiondownlevel_0","displayName":"Network protection will be disabled downlevel.","description":"Network protection will be disabled downlevel.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_allownetworkprotectiononwinserver","displayName":"Allow Network Protection On Win Server","description":"This settings controls whether Network Protection is allowed to be configured into block or audit mode on Windows Server. If false, the value of EnableNetworkProtection will be ignored.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_allownetworkprotectiononwinserver_1","displayName":"Allow","description":"Allow","helpText":null},{"id":"device_vendor_msft_defender_configuration_allownetworkprotectiononwinserver_0","displayName":"Disallow","description":"Disallow","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_allowswitchtoasyncinspection","displayName":"Allow Switch To Async Inspection","description":"Control whether network protection can improve performance by switching from real-time inspection to asynchronous inspection","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_allowswitchtoasyncinspection_1","displayName":"Allow switching to asynchronous inspection","description":"Allow switching to asynchronous inspection","helpText":null},{"id":"device_vendor_msft_defender_configuration_allowswitchtoasyncinspection_0","displayName":"Don’t allow asynchronous inspection","description":"Don’t allow asynchronous inspection","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_archivemaxdepth","displayName":"Archive Max Depth","description":"Specify the maximum folder depth to extract from archive files for scanning. If this configuration is off or not set, the default value (0) is applied, and all archives are extracted up to the deepest folder for scanning.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_archivemaxsize","displayName":"Archive Max Size","description":"Specify the maximum size, in KB, of archive files to be extracted and scanned. If this configuration is off or not set, the default value (0) is applied, and all archives are extracted and scanned regardless of size.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_asronlyperruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionaggressiveness","displayName":"Remote Encryption Protection Aggressiveness","description":"Set the criteria for when Remote Encryption Protection blocks IP addresses.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionaggressiveness_0","displayName":"Low: Block only when confidence level is 100% (Default)","description":"Low: Block only when confidence level is 100% (Default)","helpText":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionaggressiveness_1","displayName":"Medium: Use cloud aggregation and block when confidence level is above 99%","description":"Medium: Use cloud aggregation and block when confidence level is above 99%","helpText":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionaggressiveness_2","displayName":"High: Use cloud intel and context, and block when confidence level is above 90%","description":"High: Use cloud intel and context, and block when confidence level is above 90%","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionconfiguredstate","displayName":"Remote Encryption Protection Configured State","description":"Remote Encryption Protection in Microsoft Defender Antivirus detects and blocks attempts to replace local files with encrypted versions from another device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionconfiguredstate_0","displayName":"Not configured: Apply defaults set for the antivirus engine and platform","description":"Not configured: Apply defaults set for the antivirus engine and platform","helpText":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionconfiguredstate_1","displayName":"Block: Prevent suspicious and malicious behaviors","description":"Block: Prevent suspicious and malicious behaviors","helpText":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionconfiguredstate_2","displayName":"Audit: Generate EDR detections without blocking","description":"Audit: Generate EDR detections without blocking","helpText":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionconfiguredstate_4","displayName":"Off: Feature is off with no performance impact","description":"Off: Feature is off with no performance impact","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionexclusions","displayName":"Remote Encryption Protection Exclusions","description":"Specify IP addresses, subnets, or workstation names to exclude from being blocked by Remote Encryption Protection. Note that attackers can spoof excluded addresses and names to bypass protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionmaxblocktime","displayName":"Remote Encryption Protection Max Block Time","description":"Set the maximum time an IP address is blocked by Remote Encryption Protection. After this time, blocked IP addresses will be able to reinitiate connections. If set to 0, internal feature logic will determine blocking time.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_dataduplicationdirectory","displayName":"Data Duplication Directory","description":"Define data duplication directory for device control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_dataduplicationlocalretentionperiod","displayName":"Data Duplication Local Retention Period","description":"Define the retention period in days of how much time the evidence data will be kept on the client machine should any transfer to the remote locations would occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_dataduplicationmaximumquota","displayName":"Data Duplication Maximum Quota","description":"Defines the maximum data duplication quota in MB that can be collected. When the quota is reached the filter will stop duplicating any data until the service manages to dispatch the existing collected data, thus decreasing the quota again below the maximum. The valid interval is [5-5000] MB. By default, the maximum quota will be 500 MB.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_dataduplicationremotelocation","displayName":"Data Duplication Remote Location","description":"Define data duplication remote location for Device Control. When configuring this setting, ensure that Device Control is Enabled and that the provided path is a remote path the user can access.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_daysuntilaggressivecatchupquickscan","displayName":"Days Until Aggressive Catchup Quick Scan","description":"Configure how many days can pass before an aggressive catchup quick scan is triggered. Valid values are 0 and [7-60]. Configuring this setting to 0 will disable aggressive catchup quick scans. By default, these scans will run every 30 days when enabled. These scans are only enabled if catchup scans (quick and full) are disabled, and Microsoft Defender Antivirus is not in Passive mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_defaultenforcement","displayName":"Default Enforcement","description":"Control Device Control default enforcement. This is the enforcement applied if there are no policy rules present or at the end of the policy rules evaluation none were matched.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_defaultenforcement_1","displayName":"Default Allow Enforcement","description":"Default Allow Enforcement","helpText":null},{"id":"device_vendor_msft_defender_configuration_defaultenforcement_2","displayName":"Default Deny Enforcement","description":"Default Deny Enforcement","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_deploymentchannel","displayName":"Deployment Channel","description":"Enable this policy to specify when devices receive Microsoft Defender binary updates based on the chosen deployment channel rollout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_deploymentchannel_0","displayName":"Not Configured (Default). If you don't configure this policy, devices are added to the release channel. Microsoft determines whether devices receive updates earlier or later within the release channel.","description":"Not Configured (Default). If you don't configure this policy, devices are added to the release channel. Microsoft determines whether devices receive updates earlier or later within the release channel.","helpText":null},{"id":"device_vendor_msft_defender_configuration_deploymentchannel_10","displayName":"Validation Channel: Devices set to this channel are the first to receive new monthly binary (platform and engine) updates. The likelihood of new issues occurring is higher, so add only devices with the highest risk tolerance to this channel (recommended for 1% or less of devices in your environment).","description":"Validation Channel: Devices set to this channel are the first to receive new monthly binary (platform and engine) updates. The likelihood of new issues occurring is higher, so add only devices with the highest risk tolerance to this channel (recommended for 1% or less of devices in your environment).","helpText":null},{"id":"device_vendor_msft_defender_configuration_deploymentchannel_20","displayName":"Release Channel - Early: The release channel is appropriate for most of your production environment. Devices set to this channel are offered updates earliest in the release channel. Distribute devices across early, fast and broad depending on their risk tolerance. Add devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment.","description":"Release Channel - Early: The release channel is appropriate for most of your production environment. Devices set to this channel are offered updates earliest in the release channel. Distribute devices across early, fast and broad depending on their risk tolerance. Add devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment.","helpText":null},{"id":"device_vendor_msft_defender_configuration_deploymentchannel_30","displayName":"Release Channel - Fast: The release channel is appropriate for most of your production environment. Devices are offered updates later during the gradual release cycle. Distribute devices across early, fast and broad depending on their risk tolerance. Use devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment.","description":"Release Channel - Fast: The release channel is appropriate for most of your production environment. Devices are offered updates later during the gradual release cycle. Distribute devices across early, fast and broad depending on their risk tolerance. Use devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment.","helpText":null},{"id":"device_vendor_msft_defender_configuration_deploymentchannel_40","displayName":"Release Channel - Broad: The release channel is appropriate for most of your production environment. Devices in this channel receive updates at the end of the gradual release cycle. Distribute devices across early, fast and broad depending on their risk tolerance. Use devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment.","description":"Release Channel - Broad: The release channel is appropriate for most of your production environment. Devices in this channel receive updates at the end of the gradual release cycle. Distribute devices across early, fast and broad depending on their risk tolerance. Use devices in the earlier channels to surface issues sooner and avoid impacting the rest of your environment.","helpText":null},{"id":"device_vendor_msft_defender_configuration_deploymentchannel_50","displayName":"Delayed Channel: Devices in this channel are offered updates approximately 48 hours after the devices in the release channel (broad). Use this channel for critical infrastructure and high value assets (~1% or less of devices).","description":"Delayed Channel: Devices in this channel are offered updates approximately 48 hours after the devices in the release channel (broad). Use this channel for critical infrastructure and high value assets (~1% or less of devices).","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}","displayName":"ID","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata","displayName":"Policy rule","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry","displayName":"Access","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask","displayName":"Access mask","description":"Defines the access.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":[{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_1","displayName":"Read","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_2","displayName":"Write","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_4","displayName":"Execute","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_8","displayName":"File read","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_16","displayName":"File write","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_32","displayName":"File execute","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_accesmask_64","displayName":"Print","description":"","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_computersid","displayName":"Computer Sid","description":"Local computer Sid or computer Sid group or the Sid of the AD object, defines whether to apply this policy over a specific machine or machine group; one entry can have a maximum of one ComputerSid and an entry without any ComputerSid means applying the policy over the machine. If you want to apply an Entry to a specific user and specific machine, add both Sid and ComputerSid into the same Entry.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_id","displayName":"ID","description":"One PolicyRule can have multiple entries; each entry with a unique GUID tells Device Control one restriction.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_options","displayName":"Options","description":"Defines whether to display notification or not.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":[{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_options_0","displayName":"None","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_options_1","displayName":"Show notification","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_options_2","displayName":"Send event","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_options_3","displayName":"Send notification and event","description":"","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_options_4","displayName":"Disable","description":"","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_sid","displayName":"Sid","description":"Local user Sid or user Sid group or the Sid of the AD object, defines whether to apply this policy over a specific user or user group; one entry can have a maximum of one Sid and an entry without any Sid means applying the policy over the machine.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type","displayName":"Type","description":"Defines the action for the removable storage groups in IncludedIDList\nEnforcement: Allow or Deny\nAudit: AuditAllowed or AuditDenied","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":[{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_allow","displayName":"Allow","description":null,"helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_deny","displayName":"Deny","description":null,"helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_auditallowed","displayName":"Audit Allowed","description":null,"helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_auditdenied","displayName":"Audit Denied","description":null,"helpText":null}]},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_excludedidlist","displayName":"Excluded Devices","description":"The group(s) that the policy will not be applied to.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_excludedidlist_groupid","displayName":"Excluded Devices","description":"The group(s) that the policy will not be applied to.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_id","displayName":"ID","description":"GUID, a unique ID, represents the policy and will be used in the reporting and troubleshooting.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_includedidlist","displayName":"Included Devices","description":"The group(s) that the policy will be applied to. If multiple groups are added, the policy will be applied to any media in all those groups.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_includedidlist_groupid","displayName":"Included Devices","description":"The group(s) that the policy will be applied to. If multiple groups are added, the policy will be applied to any media in all those groups.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_name","displayName":"Name","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},{"id":"device_vendor_msft_defender_configuration_devicecontrolenabled","displayName":"Device Control Enabled","description":"Control Device Control feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_devicecontrolenabled_1","displayName":"Device Control is enabled","description":"Device Control is enabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrolenabled_0","displayName":"Device Control is disabled","description":"Device Control is disabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablecachemaintenance","displayName":"Disable Cache Maintenance","description":"Defines whether the cache maintenance idle task will perform the cache maintenance or not.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablecachemaintenance_1","displayName":"Cache maintenance is disabled","description":"Cache maintenance is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablecachemaintenance_0","displayName":"Cache maintenance is enabled (default)","description":"Cache maintenance is enabled (default)","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablecoreserviceecsintegration","displayName":"Disable Core Service ECS Integration","description":"Turn off ECS integration for Defender core service","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablecoreserviceecsintegration_0","displayName":"The Defender core service will use the Experimentation and Configuration Service (ECS) to rapidly deliver critical, org-specific fixes.","description":"The Defender core service will use the Experimentation and Configuration Service (ECS) to rapidly deliver critical, org-specific fixes.","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablecoreserviceecsintegration_1","displayName":"The Defender core service stops using the Experimentation and Configuration Service (ECS). Fixes will continue to be delivered through security intelligence updates.","description":"The Defender core service stops using the Experimentation and Configuration Service (ECS). Fixes will continue to be delivered through security intelligence updates.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablecoreservicetelemetry","displayName":"Disable Core Service Telemetry","description":"Turn off OneDsCollector telemetry for Defender core service","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablecoreservicetelemetry_0","displayName":"The Defender core service will use the OneDsCollector framework to rapidly collect telemetry.","description":"The Defender core service will use the OneDsCollector framework to rapidly collect telemetry.","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablecoreservicetelemetry_1","displayName":"The Defender core service stops using the OneDsCollector framework to rapidly collect telemetry, impacting Microsoft's ability to quickly recognize and address poor performance, false positives, and other problems.","description":"The Defender core service stops using the OneDsCollector framework to rapidly collect telemetry, impacting Microsoft's ability to quickly recognize and address poor performance, false positives, and other problems.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablecputhrottleonidlescans","displayName":"Disable Cpu Throttle On Idle Scans","description":"Indicates whether the CPU will be throttled for scheduled scans while the device is idle. This feature is enabled by default and will not throttle the CPU for scheduled scans performed when the device is otherwise idle, regardless of what ScanAvgCPULoadFactor is set to. For all other scheduled scans this flag will have no impact and normal throttling will occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablecputhrottleonidlescans_1","displayName":"Disable CPU Throttle on idle scans","description":"Disable CPU Throttle on idle scans","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablecputhrottleonidlescans_0","displayName":"Enable CPU Throttle on idle scans","description":"Enable CPU Throttle on idle scans","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disabledatagramprocessing","displayName":"Disable Datagram Processing","description":"Control whether network protection inspects User Datagram Protocol (UDP) traffic","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disabledatagramprocessing_1","displayName":"UDP inspection is off","description":"UDP inspection is off","helpText":null},{"id":"device_vendor_msft_defender_configuration_disabledatagramprocessing_0","displayName":"UDP inspection is on","description":"UDP inspection is on","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablednsovertcpparsing","displayName":"Disable Dns Over Tcp Parsing","description":"This setting disables DNS over TCP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablednsovertcpparsing_1","displayName":"DNS over TCP parsing is disabled","description":"DNS over TCP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablednsovertcpparsing_0","displayName":"DNS over TCP parsing is enabled","description":"DNS over TCP parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablednsparsing","displayName":"Disable Dns Parsing","description":"This setting disables DNS Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablednsparsing_1","displayName":"DNS parsing is disabled","description":"DNS parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablednsparsing_0","displayName":"DNS parsing is enabled","description":"DNS parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disableftpparsing","displayName":"Disable Ftp Parsing","description":"This setting disables FTP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disableftpparsing_1","displayName":"FTP parsing is disabled","description":"FTP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disableftpparsing_0","displayName":"FTP parsing is enabled","description":"FTP parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablegradualrelease","displayName":"Disable Gradual Release","description":"Enable this policy to disable gradual rollout of Defender updates.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablegradualrelease_1","displayName":"Gradual release is disabled","description":"Gradual release is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablegradualrelease_0","displayName":"Gradual release is enabled","description":"Gradual release is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablehttpparsing","displayName":"Disable Http Parsing","description":"This setting disables HTTP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablehttpparsing_1","displayName":"HTTP parsing is disabled","description":"HTTP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablehttpparsing_0","displayName":"HTTP parsing is enabled","description":"HTTP parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disableinboundconnectionfiltering","displayName":"Disable Inbound Connection Filtering","description":"This setting disables Inbound connection filtering for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disableinboundconnectionfiltering_1","displayName":"Inbound connection filtering is disabled","description":"Inbound connection filtering is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disableinboundconnectionfiltering_0","displayName":"Inbound connection filtering is enabled","description":"Inbound connection filtering is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablelocaladminmerge","displayName":"Disable Local Admin Merge","description":"When this value is set to false, it allows a local admin the ability to specify some settings for complex list type that will then merge /override the Preference settings with the Policy settings","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablelocaladminmerge_0","displayName":"Enable Local Admin Merge","description":"Enable Local Admin Merge","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablelocaladminmerge_1","displayName":"Disable Local Admin Merge","description":"Disable Local Admin Merge","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablenetworkprotectionperftelemetry","displayName":"Disable Network Protection Perf Telemetry","description":"This setting disables the gathering and send of performance telemetry from Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablenetworkprotectionperftelemetry_1","displayName":"Network protection telemetry is disabled","description":"Network protection telemetry is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablenetworkprotectionperftelemetry_0","displayName":"Network protection telemetry is enabled","description":"Network protection telemetry is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablequicparsing","displayName":"Disable Quic Parsing","description":"This setting disables QUIC Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablequicparsing_1","displayName":"QUIC parsing is disabled","description":"QUIC parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablequicparsing_0","displayName":"QUIC parsing is enabled","description":"QUIC parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablerdpparsing","displayName":"Disable Rdp Parsing","description":"This setting disables RDP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablerdpparsing_1","displayName":"RDP Parsing is disabled","description":"RDP Parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablerdpparsing_0","displayName":"RDP Parsing is enabled","description":"RDP Parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablesmtpparsing","displayName":"Disable Smtp Parsing","description":"This setting disables SMTP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablesmtpparsing_1","displayName":"SMTP parsing is disabled","description":"SMTP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablesmtpparsing_0","displayName":"SMTP parsing is enabled","description":"SMTP parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disablesshparsing","displayName":"Disable Ssh Parsing","description":"This setting disables SSH Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablesshparsing_1","displayName":"SSH parsing is disabled","description":"SSH parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablesshparsing_0","displayName":"SSH parsing is enabled","description":"SSH parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_disabletlsparsing","displayName":"Disable Tls Parsing","description":"This setting disables TLS Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disabletlsparsing_1","displayName":"TLS parsing is disabled","description":"TLS parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disabletlsparsing_0","displayName":"TLS parsing is enabled","description":"TLS parsing is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_enableconvertwarntoblock","displayName":"Enable Convert Warn To Block","description":"This setting controls whether network protection blocks network traffic instead of displaying a warning","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_enableconvertwarntoblock_1","displayName":"Warn verdicts are converted to block","description":"Warn verdicts are converted to block","helpText":null},{"id":"device_vendor_msft_defender_configuration_enableconvertwarntoblock_0","displayName":"Warn verdicts are not converted to block","description":"Warn verdicts are not converted to block","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_enablednssinkhole","displayName":"[Deprecated] Enable Dns Sinkhole","description":"This setting is deprecated and no longer has impact on devices. This setting enables the DNS Sinkhole feature for Network Protection, respecting the value of EnableNetworkProtection for block vs audit, does nothing in inspect mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_enablednssinkhole_0","displayName":"DNS Sinkhole is disabled","description":"DNS Sinkhole is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_enablednssinkhole_1","displayName":"DNS Sinkhole is enabled","description":"DNS Sinkhole is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_enablefilehashcomputation","displayName":"Enable File Hash Computation","description":"Enables or disables file hash computation feature. When this feature is enabled Windows defender will compute hashes for files it scans.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_enablefilehashcomputation_0","displayName":"Disable","description":"Disable","helpText":null},{"id":"device_vendor_msft_defender_configuration_enablefilehashcomputation_1","displayName":"Enable","description":"Enable","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_enableudpreceiveoffload","displayName":"Enable Udp Receive Offload","description":"This setting enables Udp Receive Offload Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_enableudpreceiveoffload_0","displayName":"Udp Receive Offload is disabled","description":"Udp Receive Offload is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_enableudpreceiveoffload_1","displayName":"Udp Receive Offload is enabled","description":"Udp Receive Offload is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_enableudpsegmentationoffload","displayName":"Enable Udp Segmentation Offload","description":"This setting enables Udp Segmentation Offload Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_enableudpsegmentationoffload_0","displayName":"Udp Segmentation Offload is disabled","description":"Udp Segmentation Offload is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_enableudpsegmentationoffload_1","displayName":"Udp Segmentation Offload is enabled","description":"Udp Segmentation Offload is enabled","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_engineupdateschannel","displayName":"Engine Updates Channel","description":"[to be deprecated] Enable this policy to specify when devices receive Microsoft Defender engine updates during the monthly gradual rollout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_engineupdateschannel_0","displayName":"Not configured (Default). The device will stay up to date automatically during the gradual release cycle. Suitable for most devices.","description":"Not configured (Default). The device will stay up to date automatically during the gradual release cycle. Suitable for most devices.","helpText":null},{"id":"device_vendor_msft_defender_configuration_engineupdateschannel_2","displayName":"Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.","description":"Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.","helpText":null},{"id":"device_vendor_msft_defender_configuration_engineupdateschannel_3","displayName":"Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.","description":"Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.","helpText":null},{"id":"device_vendor_msft_defender_configuration_engineupdateschannel_4","displayName":"Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).","description":"Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).","helpText":null},{"id":"device_vendor_msft_defender_configuration_engineupdateschannel_5","displayName":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).","description":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).","helpText":null},{"id":"device_vendor_msft_defender_configuration_engineupdateschannel_6","displayName":"Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.","description":"Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_excludedipaddresses","displayName":"Excluded Ip Addresses","description":"Allows an administrator to explicitly disable network packet inspection made by wdnisdrv on a particular set of IP addresses.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocaladmins","displayName":"Hide Exclusions From Local Admins","description":"This policy setting controls whether or not exclusions are visible to local admins. To control local users exlcusions visibility use HideExclusionsFromLocalUsers. If HideExclusionsFromLocalAdmins is set then HideExclusionsFromLocalUsers will be implicitly set.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocaladmins_1","displayName":"If you enable this setting, local admins will no longer be able to see the exclusion list in Windows Security App or via PowerShell.","description":"If you enable this setting, local admins will no longer be able to see the exclusion list in Windows Security App or via PowerShell.","helpText":null},{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocaladmins_0","displayName":"If you disable or do not configure this setting, local admins will be able to see exclusions in the Windows Security App and via PowerShell.","description":"If you disable or do not configure this setting, local admins will be able to see exclusions in the Windows Security App and via PowerShell.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocalusers","displayName":"Hide Exclusions From Local Users","description":"This policy setting controls whether or not exclusions are visible to local users. If HideExclusionsFromLocalAdmins is set then this policy will be implicitly set.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocalusers_1","displayName":"If you enable this setting, local users will no longer be able to see the exclusion list in Windows Security App or via PowerShell.","description":"If you enable this setting, local users will no longer be able to see the exclusion list in Windows Security App or via PowerShell.","helpText":null},{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocalusers_0","displayName":"If you disable or do not configure this setting, local users will be able to see exclusions in the Windows Security App and via PowerShell.","description":"If you disable or do not configure this setting, local users will be able to see exclusions in the Windows Security App and via PowerShell.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_inteltdtenabled","displayName":"Intel TDT Enabled","description":"This policy setting configures the Intel TDT integration level for Intel TDT-capable devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_inteltdtenabled_0","displayName":"If you do not configure this setting, the default value will be applied. The default value is controlled by Microsoft security intelligence updates. Microsoft will enable Intel TDT if there is a known threat.","description":"If you do not configure this setting, the default value will be applied. The default value is controlled by Microsoft security intelligence updates. Microsoft will enable Intel TDT if there is a known threat.","helpText":null},{"id":"device_vendor_msft_defender_configuration_inteltdtenabled_1","displayName":"If you configure this setting to enabled, Intel TDT integration will turn on.","description":"If you configure this setting to enabled, Intel TDT integration will turn on.","helpText":null},{"id":"device_vendor_msft_defender_configuration_inteltdtenabled_2","displayName":"If you configure this setting to disabled, Intel TDT integration will turn off.","description":"If you configure this setting to disabled, Intel TDT integration will turn off.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_meteredconnectionupdates","displayName":"Metered Connection Updates","description":"Allow managed devices to update through metered connections. Default is 0 - not allowed, 1 - allowed","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_meteredconnectionupdates_1","displayName":"Allowed","description":"Allowed","helpText":null},{"id":"device_vendor_msft_defender_configuration_meteredconnectionupdates_0","displayName":"Not Allowed","description":"Not Allowed","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_networkprotectionreputationmode","displayName":"Network Protection Reputation Mode","description":"This sets the reputation mode engine for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_networkprotectionreputationmode_0","displayName":"Use standard reputation engine","description":"Use standard reputation engine","helpText":null},{"id":"device_vendor_msft_defender_configuration_networkprotectionreputationmode_1","displayName":"Use ESP reputation engine","description":"Use ESP reputation engine","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_oobeenablertpandsigupdate","displayName":"Oobe Enable Rtp And Sig Update","description":"This setting allows you to configure whether real-time protection and Security Intelligence Updates are enabled during OOBE (Out of Box experience).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_oobeenablertpandsigupdate_1","displayName":"If you enable this setting, real-time protection and Security Intelligence Updates are enabled during OOBE.","description":"If you enable this setting, real-time protection and Security Intelligence Updates are enabled during OOBE.","helpText":null},{"id":"device_vendor_msft_defender_configuration_oobeenablertpandsigupdate_0","displayName":"If you either disable or do not configure this setting, real-time protection and Security Intelligence Updates during OOBE is not enabled.","description":"If you either disable or do not configure this setting, real-time protection and Security Intelligence Updates during OOBE is not enabled.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_passiveremediation","displayName":"Passive Remediation","description":"Setting to control automatic remediation for Sense scans.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_passiveremediation_0","displayName":"Passive Remediation is turned off (default)","description":"Passive Remediation is turned off (default)","helpText":null},{"id":"device_vendor_msft_defender_configuration_passiveremediation_1","displayName":"PASSIVEREMEDIATIONFLAGSENSEAUTOREMEDIATION: Passive Remediation Sense AutoRemediation","description":"PASSIVE_REMEDIATION_FLAG_SENSE_AUTO_REMEDIATION: Passive Remediation Sense AutoRemediation","helpText":null},{"id":"device_vendor_msft_defender_configuration_passiveremediation_2","displayName":"PASSIVEREMEDIATIONFLAGRTPAUDIT: Passive Remediation Realtime Protection Audit","description":"PASSIVE_REMEDIATION_FLAG_RTP_AUDIT: Passive Remediation Realtime Protection Audit","helpText":null},{"id":"device_vendor_msft_defender_configuration_passiveremediation_4","displayName":"PASSIVEREMEDIATIONFLAGRTPREMEDIATION: Passive Remediation Realtime Protection Remediation","description":"PASSIVE_REMEDIATION_FLAG_RTP_REMEDIATION: Passive Remediation Realtime Protection Remediation","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_performancemodestatus","displayName":"Performance Mode Status","description":"This setting allows IT admins to configure performance mode in either enabled or disabled mode for managed devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_performancemodestatus_0","displayName":"Performance mode is enabled (default). A service restart is required after changing this value.","description":"Performance mode is enabled (default). A service restart is required after changing this value.","helpText":null},{"id":"device_vendor_msft_defender_configuration_performancemodestatus_1","displayName":"Performance mode is disabled. A service restart is required after changing this value.","description":"Performance mode is disabled. A service restart is required after changing this value.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_platformupdateschannel","displayName":"Platform Updates Channel","description":"[to be deprecated] Enable this policy to specify when devices receive Microsoft Defender platform updates during the monthly gradual rollout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_platformupdateschannel_0","displayName":"Not configured (Default). The device will stay up to date automatically during the gradual release cycle. Suitable for most devices.","description":"Not configured (Default). The device will stay up to date automatically during the gradual release cycle. Suitable for most devices.","helpText":null},{"id":"device_vendor_msft_defender_configuration_platformupdateschannel_2","displayName":"Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.","description":"Beta Channel: Devices set to this channel will be the first to receive new updates. Select Beta Channel to participate in identifying and reporting issues to Microsoft. Devices in the Windows Insider Program are subscribed to this channel by default. For use in (manual) test environments only and a limited number of devices.","helpText":null},{"id":"device_vendor_msft_defender_configuration_platformupdateschannel_3","displayName":"Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.","description":"Current Channel (Preview): Devices set to this channel will be offered updates earliest during the monthly gradual release cycle. Suggested for pre-production/validation environments.","helpText":null},{"id":"device_vendor_msft_defender_configuration_platformupdateschannel_4","displayName":"Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).","description":"Current Channel (Staged): Devices will be offered updates after the monthly gradual release cycle. Suggested to apply to a small, representative part of your production population (~10%).","helpText":null},{"id":"device_vendor_msft_defender_configuration_platformupdateschannel_5","displayName":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).","description":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in your production population (~10-100%).","helpText":null},{"id":"device_vendor_msft_defender_configuration_platformupdateschannel_6","displayName":"Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.","description":"Critical - Time delay: Devices will be offered updates with a 48-hour delay. Suggested for critical environments only.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_quickscanincludeexclusions","displayName":"Quick Scan Include Exclusions","description":"This setting allows you to scan excluded files and directories during quick scans.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_quickscanincludeexclusions_0","displayName":"If you set this setting to 0 or do not configure it, exclusions are not scanned during quick scans.","description":"If you set this setting to 0 or do not configure it, exclusions are not scanned during quick scans.","helpText":null},{"id":"device_vendor_msft_defender_configuration_quickscanincludeexclusions_1","displayName":"If you set this setting to 1, all files and directories that are excluded from real-time protection using contextual exclusions are scanned during a quick scan.","description":"If you set this setting to 1, all files and directories that are excluded from real-time protection using contextual exclusions are scanned during a quick scan.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_randomizescheduletasktimes","displayName":"Randomize Schedule Task Times","description":"In Microsoft Defender Antivirus, randomize the start time of the scan to any interval from 0 to 23 hours. This can be useful in virtual machines or VDI deployments.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_randomizescheduletasktimes_1","displayName":"Widen or narrow the randomization period for scheduled scans. Specify a randomization window of between 1 and 23 hours by using the setting SchedulerRandomizationTime.","description":"Widen or narrow the randomization period for scheduled scans. Specify a randomization window of between 1 and 23 hours by using the setting SchedulerRandomizationTime.","helpText":null},{"id":"device_vendor_msft_defender_configuration_randomizescheduletasktimes_0","displayName":"Scheduled tasks will not be randomized.","description":"Scheduled tasks will not be randomized.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_reporting_enabledynamicsignaturedroppedeventreporting","displayName":"Enable Dynamic Signature Dropped Event Reporting","description":"This setting controls whether to report a Dynamic Security Intelligence Update dropped event. By default, such events are not reported.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_reporting_enabledynamicsignaturedroppedeventreporting_0","displayName":"Dynamic Security intelligence update dropped events will not be reported.","description":"Dynamic Security intelligence update dropped events will not be reported.","helpText":null},{"id":"device_vendor_msft_defender_configuration_reporting_enabledynamicsignaturedroppedeventreporting_1","displayName":"Dynamic Security intelligence update events will be reported.","description":"Dynamic Security intelligence update events will be reported.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_scanonlyifidleenabled","displayName":"Scan Only If Idle Enabled","description":"In Microsoft Defender Antivirus, this setting will run scheduled scans only if the system is idle.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_scanonlyifidleenabled_1","displayName":"Runs scheduled scans only if the system is idle.","description":"Runs scheduled scans only if the system is idle.","helpText":null},{"id":"device_vendor_msft_defender_configuration_scanonlyifidleenabled_0","displayName":"Runs scheduled scans regardless of whether the system is idle.","description":"Runs scheduled scans regardless of whether the system is idle.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_schedulerrandomizationtime","displayName":"Scheduler Randomization Time","description":"This setting allows you to configure the scheduler randomization in hours. The randomization interval is [1 - 23] hours. For more information on the randomization effect please check the RandomizeScheduleTaskTimes setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday","displayName":"Schedule Security Intelligence Update Day","description":"This setting allows you to specify the day of the week on which to check for security intelligence updates. By default, this setting is configured to never check for security intelligence updates.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_0","displayName":"Daily","description":"Daily","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_1","displayName":"Sunday","description":"Sunday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_2","displayName":"Monday","description":"Monday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_3","displayName":"Tuesday","description":"Tuesday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_4","displayName":"Wednesday","description":"Wednesday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_5","displayName":"Thursday","description":"Thursday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_6","displayName":"Friday","description":"Friday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_7","displayName":"Saturday","description":"Saturday","helpText":null},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdateday_8","displayName":"Never","description":"Never","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_schedulesecurityintelligenceupdatetime","displayName":"Schedule Security Intelligence Update Time","description":"This setting allows you to specify the time of day at which to check for security intelligence updates. The time value is represented as the number of minutes past midnight (00:00). For example, 120 is equivalent to 02:00 AM. By default, this setting is configured to check for security intelligence updates 15 minutes before the scheduled scan time. The schedule is based on local time on the computer where the check is occurring.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_secureddevicesconfiguration","displayName":"Secured Devices Configuration","description":"Defines which device's primary ids should be secured by Defender Device Control. The primary id values should be pipe (|) separated. Example: RemovableMediaDevices|CdRomDevices. If this configuration is not set the default value will be applied, meaning all supported devices will be secured. Currently supported primary ids are: RemovableMediaDevices, CdRomDevices, WpdDevices, PrinterDevices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_secureddevicesconfiguration_removablemediadevices","displayName":"Removable Media Devices","description":"RemovableMediaDevices","helpText":null},{"id":"device_vendor_msft_defender_configuration_secureddevicesconfiguration_cdromdevices","displayName":"Cd Rom Devices","description":"CdRomDevices","helpText":null},{"id":"device_vendor_msft_defender_configuration_secureddevicesconfiguration_wpddevices","displayName":"Wpd Devices","description":"WpdDevices","helpText":null},{"id":"device_vendor_msft_defender_configuration_secureddevicesconfiguration_printerdevices","displayName":"Printer Devices","description":"PrinterDevices","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_securityintelligencelocationupdateatscheduledtimeonly","displayName":"Security Intelligence Location Update At Scheduled Time Only","description":"This setting allows you to configure security intelligence updates according to the scheduler for VDI-configured computers. It is used together with the shared security intelligence location (SecurityIntelligenceLocation).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_securityintelligencelocationupdateatscheduledtimeonly_1","displayName":"If you enable this setting and configure SecurityIntelligenceLocation, updates from the configured location occur only at the previously configured scheduled update time.","description":"If you enable this setting and configure SecurityIntelligenceLocation, updates from the configured location occur only at the previously configured scheduled update time.","helpText":null},{"id":"device_vendor_msft_defender_configuration_securityintelligencelocationupdateatscheduledtimeonly_0","displayName":"If you either disable or do not configure this setting, updates occur whenever a new security intelligence update is detected at the location that is specified by SecurityIntelligenceLocation.","description":"If you either disable or do not configure this setting, updates occur whenever a new security intelligence update is detected at the location that is specified by SecurityIntelligenceLocation.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel","displayName":"Security Intelligence Updates Channel","description":"Enable this policy to specify when devices receive Microsoft Defender security intelligence updates during the daily gradual rollout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel_0","displayName":"Not configured (Default). Microsoft will either assign the device to Current Channel (Broad) or a beta channel early in the gradual release cycle. The channel selected by Microsoft might be one that receives updates early during the gradual release cycle, which may not be suitable for devices in a production or critical environment","description":"Not configured (Default). Microsoft will either assign the device to Current Channel (Broad) or a beta channel early in the gradual release cycle. The channel selected by Microsoft might be one that receives updates early during the gradual release cycle, which may not be suitable for devices in a production or critical environment","helpText":null},{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel_4","displayName":"Current Channel (Staged): Same as Current Channel (Broad).","description":"Current Channel (Staged): Same as Current Channel (Broad).","helpText":null},{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel_5","displayName":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in all populations, including production.","description":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in all populations, including production.","helpText":null}]},{"id":"device_vendor_msft_defender_configuration_supportloglocation","displayName":"Support Log Location","description":"The support log location setting allows the administrator to specify where the Microsoft Defender Antivirus diagnostic data collection tool (MpCmdRun.exe) will save the resulting log files. This setting is configured with an MDM solution, such as Intune, and is available for Windows 10 Enterprise.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"device_vendor_msft_defender_configuration_throttleforscheduledscanonly","displayName":"Throttle For Scheduled Scan Only","description":"A CPU usage limit can be applied to scheduled scans only, or to scheduled and custom scans. The default value applies a CPU usage limit to scheduled scans only.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_throttleforscheduledscanonly_1","displayName":"If you enable this setting, CPU throttling will apply only to scheduled scans.","description":"If you enable this setting, CPU throttling will apply only to scheduled scans.","helpText":null},{"id":"device_vendor_msft_defender_configuration_throttleforscheduledscanonly_0","displayName":"If you disable this setting, CPU throttling will apply to scheduled and custom scans.","description":"If you disable this setting, CPU throttling will apply to scheduled and custom scans.","helpText":null}]},{"id":"device_vendor_msft_dmclient_provider_{providerid}","displayName":" Provider ID","description":"This node contains the URI-encoded value of the bootstrapped device management account’s Provider ID. Scope is dynamic. This value is set and controlled by the MDM server. As a best practice, use text that doesn’t require XML/URI escaping.","helpText":"","infoUrls":[],"categoryId":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","categoryName":"Config Refresh","options":null},{"id":"device_vendor_msft_dmclient_provider_{providerid}_configrefresh_cadence","displayName":"Refresh cadence","description":"This node determines the number of minutes between refreshes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/DMClient-csp/"],"categoryId":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","categoryName":"Config Refresh","options":null},{"id":"device_vendor_msft_dmclient_provider_{providerid}_configrefresh_enabled","displayName":"Config refresh","description":"This node determines whether or not a periodic settings refresh for MDM policies will occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/DMClient-csp/"],"categoryId":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","categoryName":"Config Refresh","options":[{"id":"device_vendor_msft_dmclient_provider_{providerid}_configrefresh_enabled_false","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_dmclient_provider_{providerid}_configrefresh_enabled_true","displayName":"Enabled.","description":"Enabled.","helpText":null}]},{"id":"device_vendor_msft_email_accountname","displayName":"Account Name","description":"Exchange ActiveSync account name, displayed to user as name of EAS profile.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/email2-csp"],"categoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","categoryName":"Email","options":null},{"id":"device_vendor_msft_email_emailaddressattributeaad","displayName":"Email address attribute from AAD","description":"The attribute Intune gets from Azure AD to dynamically generate the email address that will be used by this profile e.g. MyName@contoso.com (UPN).","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/email2-csp"],"categoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","categoryName":"Email","options":null},{"id":"device_vendor_msft_email_emailserver","displayName":"Email Server","description":"The Exchange location (URL) of the email server to which the app you specified connects to get email.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/email2-csp"],"categoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","categoryName":"Email","options":null},{"id":"device_vendor_msft_email_usernameattributeaad","displayName":"Username attribute from AAD","description":"The attribute Intune gets from Azure AD to dynamically generate the username that will be used by this profile e.g. MyName@contoso.com (UPN) or MyName (username).","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/email2-csp"],"categoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","categoryName":"Email","options":null},{"id":"device_vendor_msft_euiccs_{euicc}","displayName":"eSIM","description":"Represents information associated with an eUICC. There is one subtree for each known eUICC, created by the Local Profile Assistant (LPA) when the eUICC is first seen. The node name is the eUICC ID (EID). The node name \"Default\" represents the currently active eUICC.","helpText":"","infoUrls":[],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}","displayName":"Download Servers","description":"Node representing the discovery operation for a server name. The node name is the fully qualified domain name of the SM-DP+ server that will be used for profile discovery. Creation of this subtree triggers a discovery request.","helpText":"","infoUrls":[],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_autoenable","displayName":"Auto Enable","description":"Indicates whether the discovered profile must be enabled automatically after install. This must be set by the MDM when the ServerName subtree is created.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":[{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_autoenable_false","displayName":"Disable","description":"Disable","helpText":null},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_autoenable_true","displayName":"Enable","description":"Enable","helpText":null}]},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_isdiscoveryserver","displayName":"Is Discovery Server","description":"Indicates whether the server is a discovery server or if it is used for bulk download. A discovery server is used every time a user requests a profile discovery operation. Optional, default value is false.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":[{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_isdiscoveryserver_false","displayName":"Is Not Discovery Server","description":"Is Not Discovery Server","helpText":null},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_isdiscoveryserver_true","displayName":"Is Discovery Server","description":"Is Discovery Server","helpText":null}]},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_maximumattempts","displayName":"Maximum Attempts (Windows Insiders only)","description":"How many times profile download should be attempted before giving up. A value of 0 indicates unlimited retry attempts. When a value is not specified, it defaults to 50, which is equivalent to about a month of retry attempts.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_servername","displayName":"Server Name","description":null,"helpText":null,"infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_euiccs_{euicc}_policies_localuienabled","displayName":"Display Local UI","description":"Determines whether the local user interface of the LUI is available (true if available, false otherwise). Initially populated by the LPA when the eUICC tree is created, can be queried and changed by the MDM server.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":[{"id":"device_vendor_msft_euiccs_{euicc}_policies_localuienabled_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_euiccs_{euicc}_policies_localuienabled_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}","displayName":"ICCID","description":"Node representing an enterprise-owned eUICC profile. The node name is the ICCID of the profile (which is a unique identifier). Creation of this subtree triggers an AddProfile request by the LPA (which installs the profile on the eUICC). Removal of this subtree triggers the LPA to delete the profile (if resident on the eUICC).","helpText":"","infoUrls":[],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}_isenabled","displayName":"Is Enabled","description":"Indicates whether this eSIM profile is enabled. Can be set by both the MDM and the CSP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":[{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}_isenabled_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}_isenabled_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}_matchingid","displayName":"Matching ID","description":"Matching ID (activation code token) for profile download. Must be set by the MDM when the ICCID subtree is created.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}_servername","displayName":"Server Name","description":"Fully qualified domain name of the SM-DP+ that can download this profile. Must be set by the MDM when the ICCID subtree is created.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},{"id":"device_vendor_msft_keyboardfilter_blockedkeys","displayName":"Blocked Keys (Windows Insiders only)","description":"Get operations return a comma-delimited string of keys and key combinations that are currently blocked. Returned list does not include scancodes that have been blocked. Use BlockedScancodes to retrieve blocked scancodes and modifier+scancode combinations.\nReplace operations expect a comma-delimited string of keys or modifier(s)+key values and sets them as blocked keys. Invalid keys result in an error. All keys are case-insensitive; to block upper-case letters, specify shift+letter. To block comma, space, tab, or other special characters, specify the key name. Examples of valid key names and modifier names can be found here: https://learn.microsoft.com/en-us/windows/configuration/keyboard-filter/keyboardfilter-key-names \n\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":null},{"id":"device_vendor_msft_keyboardfilter_blockedscancodes","displayName":"Blocked Scancodes (Windows Insiders only)","description":"Get operations return a comma-delimited string of scancodes and modifier+scancode combinations that are currently blocked in hexadecimal format without the \"0x\" prefix. Returned list does not include keys that have been blocked. Use GetBlockedKeys to retrieve blocked keys and key combinations.\nReplace operations expect a comma-delimited string of scancodes or modifier(s)+scancode values in hexadecimal and sets them as blocked scancodes. When specifying hexadecimal values, do not include the \"0x\" prefix. Invalid inputs result in an error. Examples of modifier names can be found here: https://learn.microsoft.com/en-us/windows/configuration/keyboard-filter/keyboardfilter-key-names. Valid scancodes can be found here: https://learn.microsoft.com/en-us/windows/win32/inputdev/about-keyboard-input#scan-codes\n\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":null},{"id":"device_vendor_msft_keyboardfilter_breakoutkeyscancode","displayName":"Breakout Key Scancode (Windows Insiders only)","description":"Get or set the scancode that forces the device to the login screen when pressed five times consecutively. The value is the string representation of the hexadecimal scancode (without the \"0x\" prefix). Defaults to \"5b\", the scancode for the \"left windows key\". Only set a single scancode; scancode combinations are not supported. After setting this value, a reboot is required for the change to take effect.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":null},{"id":"device_vendor_msft_keyboardfilter_disableaccessibilitysettings","displayName":"Disable Accessibility Settings (Windows Insiders only)","description":"Determines if Accessibility settings (e.g. Ease of Access) are disabled. Defaults to false.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":[{"id":"device_vendor_msft_keyboardfilter_disableaccessibilitysettings_false","displayName":"Accessibility settings are honored","description":"Accessibility settings are honored","helpText":null},{"id":"device_vendor_msft_keyboardfilter_disableaccessibilitysettings_true","displayName":"Accessibility settings are disabled","description":"Accessibility settings are disabled","helpText":null}]},{"id":"device_vendor_msft_keyboardfilter_disablekeyboardfilterforadministrators","displayName":"Disable Keyboard Filter For Administrators (Windows Insiders only)","description":"Determines if Keyboard Filter should be disabled for administrators. Defaults to false. If an admin is currently signed in when this value is set, it will take effect on the next sign-in. \r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":[{"id":"device_vendor_msft_keyboardfilter_disablekeyboardfilterforadministrators_false","displayName":"Blocked keys and scancodes are blocked for Administrators","description":"Blocked keys and scancodes are blocked for Administrators","helpText":null},{"id":"device_vendor_msft_keyboardfilter_disablekeyboardfilterforadministrators_true","displayName":"Blocked keys and scancodes are not blocked for Administrators","description":"Blocked keys and scancodes are not blocked for Administrators","helpText":null}]},{"id":"device_vendor_msft_laps_policies_adencryptedpasswordhistorysize","displayName":"AD Encrypted Password History Size ","description":"Use this setting to configure how many previous encrypted passwords will be remembered in Active Directory.\n\nIf not specified, this setting will default to 0 passwords (disabled).\n\nThis setting has a minimum allowed value of 0 passwords.\n\nThis setting has a maximum allowed value of 12 passwords.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_administratoraccountname","displayName":"Administrator Account Name ","description":"Use this setting to configure the name of the managed local administrator account.\n\nIf not specified, the default built-in local administrator account will be located by well-known SID (even if renamed).\n\nIf specified, the specified account's password will be managed.\n\nNote: if a custom managed local administrator account name is specified in this setting, that account must be created via other means. Specifying a name in this setting will not cause the account to be created.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_adpasswordencryptionenabled","displayName":"AD Password Encryption Enabled ","description":"Use this setting to configure whether the password is encrypted before being stored in Active Directory.\n\nThis setting is ignored if the password is currently being stored in Azure.\n\nThis setting is only honored when the Active Directory domain is at Windows Server 2016 Domain Functional Level or higher.\n\nIf this setting is enabled, and the Active Directory domain meets the DFL prerequisite, the password will be encrypted before before being stored in Active Directory.\n\nIf this setting is disabled, or the Active Directory domain does not meet the DFL prerequisite, the password will be stored as clear-text in Active Directory.\n\nIf not specified, this setting defaults to True.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_adpasswordencryptionenabled_false","displayName":"Store the password in clear-text form in Active Directory","description":"Store the password in clear-text form in Active Directory","helpText":null},{"id":"device_vendor_msft_laps_policies_adpasswordencryptionenabled_true","displayName":"Store the password in encrypted form in Active Directory","description":"Store the password in encrypted form in Active Directory","helpText":null}]},{"id":"device_vendor_msft_laps_policies_adpasswordencryptionprincipal","displayName":"AD Password Encryption Principal ","description":"Use this setting to configure the name or SID of a user or group that can decrypt the password stored in Active Directory.\n\nThis setting is ignored if the password is currently being stored in Azure.\n\nIf not specified, the password will be decryptable by the Domain Admins group in the device's domain.\n\nIf specified, the specified user or group will be able to decrypt the password stored in Active Directory.\n\nIf the specified user or group account is invalid the device will fallback to using the Domain Admins group in the device's domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementenableaccount","displayName":"Automatic Account Management Enable Account","description":"Use this setting to configure whether the automatically managed account is enabled or disabled.\n\nIf this setting is enabled, the target account will be enabled.\n\nIf this setting is disabled, the target account will be disabled.\n\nIf not specified, this setting defaults to False.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementenableaccount_false","displayName":"The target account will be disabled","description":"The target account will be disabled","helpText":null},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementenableaccount_true","displayName":"The target account will be enabled","description":"The target account will be enabled","helpText":null}]},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementenabled","displayName":"Automatic Account Management Enabled","description":"Use this setting to specify whether automatic account management is enabled.\n\nIf this setting is enabled, the target account will be automatically managed.\n\nIf this setting is disabled, the target account will not be automatically managed.\n\nIf not specified, this setting defaults to False.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementenabled_false","displayName":"The target account will not be automatically managed","description":"The target account will not be automatically managed","helpText":null},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementenabled_true","displayName":"The target account will be automatically managed","description":"The target account will be automatically managed","helpText":null}]},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementnameorprefix","displayName":"Automatic Account Management Name Or Prefix","description":"Use this setting to configure the name or prefix of the managed local administrator account.\n\nIf specified, the value will be used as the name or name prefix of the managed account.\n\nIf not specified, this setting will default to \"WLapsAdmin\".","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementrandomizename","displayName":"Automatic Account Management Randomize Name","description":"Use this setting to configure whether the name of the automatically managed account uses a random numeric suffix each time the password is rotated.\n\nIf this setting is enabled, the name of the target account will use a random numeric suffix.\n\nIf this setting is disbled, the name of the target account will not use a random numeric suffix..\n\nIf not specified, this setting defaults to False.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementrandomizename_false","displayName":"The name of the target account will not use a random numeric suffix.","description":"The name of the target account will not use a random numeric suffix.","helpText":null},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementrandomizename_true","displayName":"The name of the target account will use a random numeric suffix.","description":"The name of the target account will use a random numeric suffix.","helpText":null}]},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementtarget","displayName":"Automatic Account Management Target","description":"Use this setting to configure which account is automatically managed.\n\nThe allowable settings are:\n\n0=The builtin administrator account will be managed.\n1=A new account created by Windows LAPS will be managed.\n\nIf not specified, this setting will default to 1.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementtarget_0","displayName":"Manage the built-in administrator account","description":"Manage the built-in administrator account","helpText":null},{"id":"device_vendor_msft_laps_policies_automaticaccountmanagementtarget_1","displayName":"Manage a new custom administrator account","description":"Manage a new custom administrator account","helpText":null}]},{"id":"device_vendor_msft_laps_policies_backupdirectory","displayName":"Backup Directory ","description":"Use this setting to configure which directory the local admin account password is backed up to.\n\nThe allowable settings are:\n\n0=Disabled (password will not be backed up)\n1=Backup the password to Microsoft Entra ID only\n2=Backup the password to Active Directory only\n\nIf not specified, this setting will default to 0.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_backupdirectory_0","displayName":"Disabled (password will not be backed up)","description":"Disabled (password will not be backed up)","helpText":null},{"id":"device_vendor_msft_laps_policies_backupdirectory_1","displayName":"Backup the password to Microsoft Entra ID only","description":"Backup the password to Microsoft Entra ID only","helpText":null},{"id":"device_vendor_msft_laps_policies_backupdirectory_2","displayName":"Backup the password to Active Directory only","description":"Backup the password to Active Directory only","helpText":null}]},{"id":"device_vendor_msft_laps_policies_passphraselength","displayName":"Passphrase Length","description":"Use this setting to configure the number of passphrase words.\n\nIf not specified, this setting will default to 6 words\n\nThis setting has a minimum allowed value of 3 words.\n\nThis setting has a maximum allowed value of 10 words.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_passwordagedays","displayName":"Password Age Days ","description":"Use this policy to configure the maximum password age of the managed local administrator account.\n\nIf not specified, this setting will default to 30 days\n\nThis setting has a minimum allowed value of 1 day when backing the password to onpremises Active Directory, and 7 days when backing the password to Microsoft Entra ID..\n\nThis setting has a maximum allowed value of 365 days.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_passwordagedays_aad","displayName":"Password Age Days","description":"Use this policy to configure the maximum password age of the managed local administrator account.\n\nIf not specified, this setting will default to 30 days\n\nThis setting has a minimum allowed value of 1 day when backing the password to onpremises Active Directory, and 7 days when backing the password to Azure AD.\n\nThis setting has a maximum allowed value of 365 days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity","displayName":"Password Complexity ","description":"Use this setting to configure password complexity of the managed local administrator account.\n\nThe allowable settings are:\n\n1=Large letters\n2=Large letters + small letters\n3=Large letters + small letters + numbers\n4=Large letters + small letters + numbers + special characters\n\nIf not specified, this setting will default to 4.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_passwordcomplexity_1","displayName":"Large letters","description":"Large letters","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_2","displayName":"Large letters + small letters","description":"Large letters + small letters","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_3","displayName":"Large letters + small letters + numbers","description":"Large letters + small letters + numbers","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_4","displayName":"Large letters + small letters + numbers + special characters","description":"Large letters + small letters + numbers + special characters","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_5","displayName":"Large letters + small letters + numbers + special characters (improved readability)","description":"Large letters + small letters + numbers + special characters (improved readability)","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_6","displayName":"Passphrase (long words)","description":"Passphrase (long words)","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_7","displayName":"Passphrase (short words)","description":"Passphrase (short words)","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_8","displayName":"Passphrase (short words with unique prefixes)","description":"Passphrase (short words with unique prefixes)","helpText":null}]},{"id":"device_vendor_msft_laps_policies_passwordexpirationprotectionenabled","displayName":"Password Expiration Protection Enabled ","description":"Use this setting to configure additional enforcement of maximum password age for the managed local administrator account.\n\nWhen this setting is enabled, planned password expiration that would result in a password age greater than that dictated by \"PasswordAgeDays\" policy is NOT allowed. When such expiration is detected, the password is changed immediately and the new password expiration date is set according to policy.\n\nIf not specified, this setting defaults to True.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_passwordexpirationprotectionenabled_false","displayName":"Allow configured password expiriration timestamp to exceed maximum password age","description":"Allow configured password expiriration timestamp to exceed maximum password age","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordexpirationprotectionenabled_true","displayName":"Do not allow configured password expiriration timestamp to exceed maximum password age","description":"Do not allow configured password expiriration timestamp to exceed maximum password age","helpText":null}]},{"id":"device_vendor_msft_laps_policies_passwordlength","displayName":"Password Length ","description":"Use this setting to configure the length of the password of the managed local administrator account.\n\nIf not specified, this setting will default to 14 characters.\n\nThis setting has a minimum allowed value of 8 characters.\n\nThis setting has a maximum allowed value of 64 characters.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_laps_policies_postauthenticationactions","displayName":"Post Authentication Actions ","description":"Use this setting to specify the actions to take upon expiration of the configured grace period.\n\nIf not specified, this setting will default to 3 (Reset the password and logoff the managed account).\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_postauthenticationactions_1","displayName":"Reset password: upon expiry of the grace period, the managed account password will be reset.","description":"Reset password: upon expiry of the grace period, the managed account password will be reset.","helpText":null},{"id":"device_vendor_msft_laps_policies_postauthenticationactions_3","displayName":"Reset the password and logoff the managed account: upon expiry of the grace period, the managed account password will be reset and any interactive logon sessions using the managed account will terminated.","description":"Reset the password and logoff the managed account: upon expiry of the grace period, the managed account password will be reset and any interactive logon sessions using the managed account will terminated.","helpText":null},{"id":"device_vendor_msft_laps_policies_postauthenticationactions_5","displayName":"Reset the password and reboot: upon expiry of the grace period, the managed account password will be reset and the managed device will be immediately rebooted.","description":"Reset the password and reboot: upon expiry of the grace period, the managed account password will be reset and the managed device will be immediately rebooted.","helpText":null},{"id":"device_vendor_msft_laps_policies_postauthenticationactions_11","displayName":"Reset the password, logoff the managed account, and terminate any remaining processes: upon expiration of the grace period, the managed account password is reset, any interactive logon sessions using the managed account are logged off, and any remaining processes are terminated.","description":"Reset the password, logoff the managed account, and terminate any remaining processes: upon expiration of the grace period, the managed account password is reset, any interactive logon sessions using the managed account are logged off, and any remaining processes are terminated.","helpText":null}]},{"id":"device_vendor_msft_laps_policies_postauthenticationresetdelay","displayName":"Post Authentication Reset Delay ","description":"Use this setting to specify the amount of time (in hours) to wait after an authentication before executing the specified post-authentication actions.\n\n If not specified, this setting will default to 24 hours.\n\n This setting has a minimum allowed value of 0 hours (this disables all post-authentication actions).\n\n This setting has a maximum allowed value of 24 hours.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},{"id":"device_vendor_msft_maintenancewindows_dayofmonth","displayName":"Day of month","description":"Specify the day of the month on which the maintenance window should run. Value must be between 1 and 28.","helpText":"1–28.","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":null},{"id":"device_vendor_msft_maintenancewindows_dayoftheweek","displayName":"Day of the week","description":"Select the day of the week on which the maintenance window should run.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_1","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_2","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_3","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_4","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_5","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_6","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_7","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_maintenancewindows_duration","displayName":"Duration (hours)","description":"Specify the duration of the maintenance window in hours. Value must be between 2 and 24 hours.","helpText":"Between 2 and 24 hours.","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":null},{"id":"device_vendor_msft_maintenancewindows_enablemaintenancewindows","displayName":"Enable Maintenance windows","description":"Configure when devices receive specific updates. During the maintenance window, the selected update action runs on the assigned devices.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_enablemaintenancewindows_0","displayName":"Off","description":"Maintenance windows are disabled","helpText":null},{"id":"device_vendor_msft_maintenancewindows_enablemaintenancewindows_1","displayName":"On","description":"Maintenance windows are enabled","helpText":null}]},{"id":"device_vendor_msft_maintenancewindows_monthlyscheduletype","displayName":"Monthly – Schedule type","description":"Select the type of monthly schedule for the maintenance window.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_monthlyscheduletype_1","displayName":"Day-based","description":"Schedule by a specific day of the month","helpText":null},{"id":"device_vendor_msft_maintenancewindows_monthlyscheduletype_2","displayName":"Week-based","description":"Schedule by a specific week and day of the month","helpText":null},{"id":"device_vendor_msft_maintenancewindows_monthlyscheduletype_3","displayName":"Last day of month","description":"Schedule on the last day of every month","helpText":null}]},{"id":"device_vendor_msft_maintenancewindows_repeatschedule","displayName":"Repeat schedule","description":"Select how often the maintenance window repeats.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_repeatschedule_1","displayName":"None","description":"No repeat schedule","helpText":null},{"id":"device_vendor_msft_maintenancewindows_repeatschedule_2","displayName":"Daily","description":"Repeat daily","helpText":null},{"id":"device_vendor_msft_maintenancewindows_repeatschedule_3","displayName":"Weekly","description":"Repeat weekly on selected days","helpText":null},{"id":"device_vendor_msft_maintenancewindows_repeatschedule_4","displayName":"Monthly","description":"Repeat monthly","helpText":null}]},{"id":"device_vendor_msft_maintenancewindows_startdate","displayName":"Start date","description":"Specify the start date for the maintenance window in YYYY-MM-DD format.","helpText":"Pick a date","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":null},{"id":"device_vendor_msft_maintenancewindows_starttime","displayName":"Start time","description":"Specify the start time for the maintenance window in HH:MM format (24-hour clock).","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":null},{"id":"device_vendor_msft_maintenancewindows_updateaction","displayName":"Update action","description":"Select the update action to perform during the maintenance window.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_updateaction_1","displayName":"Download, install and restart","description":"Download, install and restart the device","helpText":null},{"id":"device_vendor_msft_maintenancewindows_updateaction_2","displayName":"Install and restart","description":"Install and restart the device","helpText":null},{"id":"device_vendor_msft_maintenancewindows_updateaction_3","displayName":"Restart only","description":"Restart the device only","helpText":null}]},{"id":"device_vendor_msft_maintenancewindows_weekinmonth","displayName":"Week in Month","description":"Select the week of the month on which the maintenance window should run.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_weekinmonth_1","displayName":"First","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weekinmonth_2","displayName":"Second","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weekinmonth_3","displayName":"Third","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weekinmonth_4","displayName":"Fourth","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weekinmonth_5","displayName":"Last","description":null,"helpText":null}]},{"id":"device_vendor_msft_maintenancewindows_weeklydayselection","displayName":"Weekly – Day selection","description":"Select the days of the week on which the maintenance window should repeat.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_1","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_2","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_4","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_8","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_16","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_32","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_64","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_maintenancewindows_workloadtype","displayName":"Workload type","description":"Select one or more workloads for the maintenance window.","helpText":"Select one or more workloads.","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":{"id":"device_vendor_msft_maintenancewindows_workloadtype_1","displayName":"Updates","description":"Windows Updates workload","helpText":null}},{"id":"device_vendor_msft_multisim_{modemid}","displayName":"Modem ID","description":"Node representing a Mobile Broadband Modem. The node name is the Modem ID. Modem ID is a GUID without curly braces, with exception of \"Embedded\" which represents the embedded Modem.","helpText":"","infoUrls":[],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":null},{"id":"device_vendor_msft_multisim_{modemid}_policies_slotselectionenabled","displayName":"Slot Selection Enabled","description":"Determines whether the user is allowed to change slots in the Cellular settings UI. Default is true.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/MultiSIM-csp/"],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":[{"id":"device_vendor_msft_multisim_{modemid}_policies_slotselectionenabled_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_policies_slotselectionenabled_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}","displayName":" Slot ID","description":"Node representing a SIM Slot. The node name is the Slot ID. SIM Slot ID format is \"0\", \"1\", etc., with exception of \"Embedded\" which represents the embedded Slot.","helpText":"","infoUrls":[],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier","displayName":"Slot ID","description":"Node representing a SIM Slot. The node name is the Slot ID. SIM Slot ID format is \"0\", \"1\", etc., with exception of \"Embedded\" which represents the embedded Slot.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/MultiSIM-csp/"],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":[{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier_embedded","displayName":"Embedded","description":"Embedded","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier_0","displayName":"SIM Slot Id 0","description":"0","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier_1","displayName":"SIM Slot Id 1","description":"1","helpText":null}]},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_isselected","displayName":"Is Selected","description":"Indicates whether this Slot is selected or not.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/MultiSIM-csp/"],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":[{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_isselected_false","displayName":"Not selected","description":"Not selected","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_isselected_true","displayName":"Selected","description":"Selected","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}","displayName":"Device-scoped settings","description":"This policy specifies the Tenant ID in the format of a Globally Unique Identifier (GUID) without curly braces ( { , } ), which will be used as part of Windows Hello for Business provisioning and management.","helpText":"","infoUrls":[],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_enablepinrecovery","displayName":"Enable Pin Recovery","description":"If the user forgets their PIN, it can be changed to a new PIN using the Windows Hello for Business PIN recovery service. This cloud service encrypts a recovery secret which is stored locally on the client, but which can only be decrypted by the cloud service.\n\nIf you enable this policy setting, the PIN recovery secret will be stored on the device and the user will be able to change to a new PIN in case their PIN is forgotten.\n\nIf you disable or do not configure this policy setting, the PIN recovery secret will not be created or stored. If the user's PIN is forgotten, the only way to get a new PIN is by deleting the existing PIN and creating a new one, which will require the user to re-register with any services the old PIN provided access to.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_enablepinrecovery_false","displayName":"false","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_enablepinrecovery_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_excludesecuritydevices_tpm12","displayName":"Restrict use of TPM 1.2","description":"Some Trusted Platform Modules (TPMs) are only compliant with the older 1.2 revision of the TPM specification defined by the Trusted Computing Group (TCG).\n\nIf you enable this policy setting, TPM revision 1.2 modules will be disallowed from being used with Windows Hello for Business.\n\nIf you disable or do not configure this policy setting, TPM revision 1.2 modules will be allowed to be used with Windows Hello for Business.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_excludesecuritydevices_tpm12_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_excludesecuritydevices_tpm12_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_digits","displayName":"Digits","description":"Use this policy setting to configure the use of digits in the Windows Hello for Business PIN.\n\nA value of 1 corresponds to “Required.” If you configure this policy setting to 1, Windows Hello for Business requires users to include at least one digit in their PIN.\n\nA value of 2 corresponds to “Disallow.” If you configure this policy setting to 2, Windows Hello for Business prevents users from using digits in their PIN.\n\nIf you do not configure this policy setting, Windows Hello for Business requires users to use digits in their PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_digits_0","displayName":"Allows the use of digits in PIN.","description":"Allows the use of digits in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_digits_1","displayName":"Requires the use of at least one digits in PIN.","description":"Requires the use of at least one digits in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_digits_2","displayName":"Does not allow the use of digits in PIN.","description":"Does not allow the use of digits in PIN.","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_expiration","displayName":"Expiration","description":"This policy specifies when the PIN expires (in days). Valid values are 0 to 730 inclusive. If this policy is set to 0, then PINs do not expire.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_history","displayName":"PIN History","description":"This policy specifies the number of past PINs that can be stored in the history that can’t be used. Valid values are 0 to 50 inclusive. If this policy is set to 0, then storage of previous PINs is not required. PIN history is not preserved through PIN reset.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_lowercaseletters","displayName":"Lowercase Letters","description":"Use this policy setting to configure the use of lowercase letters in the Windows Hello for Business PIN.\n\nA value of 1 corresponds to “Required.” If you configure this policy setting to 1, Windows Hello for Business requires users to include at least one lowercase letter in their PIN.\n\nA value of 2 corresponds to “Disallow.” If you configure this policy setting to 2, Windows Hello for Business prevents users from using lowercase letters in their PIN.\n\nIf you do not configure this policy setting, Windows Hello for Business does not allow users to use lowercase letters in their PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_lowercaseletters_0","displayName":"Allowed","description":"Allows the use of lowercase letters in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_lowercaseletters_1","displayName":"Required","description":"Requires the use of at least one lowercase letters in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_lowercaseletters_2","displayName":"Blocked","description":"Does not allow the use of lowercase letters in PIN.","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_maximumpinlength","displayName":"Maximum PIN Length","description":"Maximum PIN length configures the maximum number of characters allowed for the PIN. The largest number you can configure for this policy setting is 127. The lowest number you can configure must be larger than the number configured in the Minimum PIN length policy setting or the number 4, whichever is greater.\n\nIf you configure this policy setting, the PIN length must be less than or equal to this number.\n\nIf you do not configure this policy setting, the PIN length must be less than or equal to 127.\n\nNOTE: If the above specified conditions for the maximum PIN length are not met, default values will be used for both the maximum and minimum PIN lengths.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_minimumpinlength","displayName":"Minimum PIN Length","description":"Minimum PIN length configures the minimum number of characters required for the PIN. The lowest number you can configure for this policy setting is 4. The largest number you can configure must be less than the number configured in the Maximum PIN length policy setting or the number 127, whichever is the lowest.\n\nIf you configure this policy setting, the PIN length must be greater than or equal to this number.\n\nIf you do not configure this policy setting, the PIN length must be greater than or equal to 4.\n\nNOTE: If the above specified conditions for the minimum PIN length are not met, default values will be used for both the maximum and minimum PIN lengths.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters","displayName":"Special Characters","description":"Use this policy setting to configure the use of special characters in the Windows Hello for Business PIN gesture. Valid special characters for Windows Hello for Business PIN gestures include: ! \" # $ % & ' ( ) * + , - . / : ; < = > ? @ [ \\ ] ^ _ ` { | } ~ .\n\nA value of 1 corresponds to “Required.” If you configure this policy setting to 1, Windows Hello for Business requires users to include at least one special character in their PIN.\n\nA value of 2 corresponds to “Disallow.” If you configure this policy setting to 2, Windows Hello for Business prevents users from using special characters in their PIN.\n\nIf you do not configure this policy setting, Windows Hello for Business does not allow users to use special characters in their PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters_0","displayName":"Allows the use of special characters in PIN.","description":"Allows the use of special characters in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters_1","displayName":"Requires the use of at least one special characters in PIN.","description":"Requires the use of at least one special characters in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters_2","displayName":"Does not allow the use of special characters in PIN.","description":"Does not allow the use of special characters in PIN.","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters","displayName":"Uppercase Letters","description":"Use this policy setting to configure the use of uppercase letters in the Windows Hello for Business PIN.\n\nA value of 1 corresponds to “Required.” If you configure this policy setting to 1, Windows Hello for Business requires users to include at least one uppercase letter in their PIN.\n\nA value of 2 corresponds to “Disallow.” If you configure this policy setting to 2, Windows Hello for Business prevents users from using uppercase letters in their PIN.\n\nIf you do not configure this policy setting, Windows Hello for Business does not allow users to use uppercase letters in their PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters_0","displayName":"Allowed","description":"Allows the use of uppercase letters in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters_1","displayName":"Required","description":"Requires the use of at least one uppercase letters in PIN.","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters_2","displayName":"Blocked","description":"Does not allow the use of uppercase letters in PIN.","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_remote_useremotepassport","displayName":"Use Remote Passport","description":"Boolean that specifies if phone sign-in can be used with a device. Phone sign-in provides the ability for a portable, registered device to be usable as a companion device for desktop authentication.\n\nDefault value is false. If you enable this setting, a desktop device will allow a registered, companion device to be used as an authentication factor. If you disable this setting, a companion device cannot be used in desktop authentication scenarios.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_remote_useremotepassport_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_remote_useremotepassport_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_requiresecuritydevice","displayName":"Require Security Device","description":"A Trusted Platform Module (TPM) provides additional security benefits over software because data stored within it cannot be used on other devices.\n\nIf you enable this policy setting, only devices with a usable TPM provision Windows Hello for Business.\n\nIf you disable or do not configure this policy setting, the TPM is still preferred, but all devices provision Windows Hello for Business using software if the TPM is non-functional or unavailable.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_requiresecuritydevice_false","displayName":"false","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_requiresecuritydevice_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usecertificateforonpremauth","displayName":"Use Certificate For On Prem Auth","description":"Windows Hello for Business can use certificates to authenticate to on-premise resources. \n\nIf you enable this policy setting, Windows Hello for Business will wait until the device has received a certificate payload from the mobile device management server before provisioning a PIN.\n\nIf you disable or do not configure this policy setting, the PIN will be provisioned when the user logs in, without waiting for a certificate payload.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usecertificateforonpremauth_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usecertificateforonpremauth_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usecloudtrustforonpremauth","displayName":"Use Cloud Trust For On Prem Auth","description":"Windows Hello for Business to use Azure AD Kerberos to authenticate to on-premises resources. \n\nIf you enable this policy setting, Windows Hello for Business will use an Azure AD Kerberos ticket to authenticate to on-premises resources.\n\nIf you disable or do not configure this policy setting, Windows Hello for Business will use a key or certificate to authenticate to on-premises resources.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usecloudtrustforonpremauth_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usecloudtrustforonpremauth_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usehellocertificatesassmartcardcertificates","displayName":"Use Hello Certificates As Smart Card Certificates","description":"If you enable this policy setting, applications use Windows Hello for Business certificates as smart card certificates. Biometric factors are unavailable when a user is asked to authorize the use of the certificate's private key. This policy setting is designed to allow compatibility with applications that rely exclusively on smart card certificates.\n\nIf you disable or do not configure this policy setting, applications do not use Windows Hello for Business certificates as smart card certificates, and biometric factors are available when a user is asked to authorize the use of the certificate's private key.\n\nWindows requires a user to lock and unlock their session after changing this setting if the user is currently signed in.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usehellocertificatesassmartcardcertificates_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usehellocertificatesassmartcardcertificates_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usepassportforwork","displayName":"Use Windows Hello For Business (Device)","description":"Windows Hello for Business is an alternative method for signing into Windows using your Active Directory or Azure Active Directory account that can replace passwords, Smart Cards, and Virtual Smart Cards.\n\nIf you enable or do not configure this policy setting, the device provisions Windows Hello for Business for all users.\n\nIf you disable this policy setting, the device does not provision Windows Hello for Business for any user.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usepassportforwork_false","displayName":"false","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_usepassportforwork_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_biometrics_enableesswithsupportedperipherals","displayName":"Enable ESS with Supported Peripherals","description":"Enhanced Sign-in Security (ESS) isolates both biometric template data and matching operations to trusted hardware or specified memory regions, meaning the rest of the operating system cannot access or tamper with them. Because the channel of communication between the sensors and the algorithm is also secured, it is impossible for malware to inject or replay data in order to simulate a user signing in or to lock a user out of their machine.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_biometrics_enableesswithsupportedperipherals_0","displayName":"Enhanced sign-in security will be disabled on all systems. If a user already has a secure Windows Hello enrollment, they will lose their enrollment and must reset PIN, and they will have the option to re-enroll in normal face and fingerprint. Peripheral usage will be enabled by disabling Enhanced sign-in security. OS will not attempt to start secure components, even if the secure hardware and software components are present. (not recommended)","description":"Enhanced sign-in security will be disabled on all systems. If a user already has a secure Windows Hello enrollment, they will lose their enrollment and must reset PIN, and they will have the option to re-enroll in normal face and fingerprint. Peripheral usage will be enabled by disabling Enhanced sign-in security. OS will not attempt to start secure components, even if the secure hardware and software components are present. (not recommended)","helpText":null},{"id":"device_vendor_msft_passportforwork_biometrics_enableesswithsupportedperipherals_1","displayName":"Enhanced sign-in security will be enabled on systems with capable software and hardware, following the existing default behavior in Windows. For systems with one secure modality (face or fingerprint) and one insecure modality (fingerprint or face), only the secure sensor can be used for sign-in and the insecure sensor(s) will be blocked. This includes peripheral devices, which are unsupported and will be unusable. (default and recommended for highest security)","description":"Enhanced sign-in security will be enabled on systems with capable software and hardware, following the existing default behavior in Windows. For systems with one secure modality (face or fingerprint) and one insecure modality (fingerprint or face), only the secure sensor can be used for sign-in and the insecure sensor(s) will be blocked. This includes peripheral devices, which are unsupported and will be unusable. (default and recommended for highest security)","helpText":null}]},{"id":"device_vendor_msft_passportforwork_biometrics_facialfeaturesuseenhancedantispoofing","displayName":"Facial Features Use Enhanced Anti Spoofing","description":"This setting determines whether enhanced anti-spoofing is required for Windows Hello face authentication.\n\nIf you enable this setting, Windows requires all users on managed devices to use enhanced anti-spoofing for Windows Hello face authentication. This disables Windows Hello face authentication on devices that do not support enhanced anti-spoofing.\n\nIf you disable or do not configure this setting, Windows doesn't require enhanced anti-spoofing for Windows Hello face authentication.\n\nNote that enhanced anti-spoofing for Windows Hello face authentication is not required on unmanaged devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_biometrics_facialfeaturesuseenhancedantispoofing_false","displayName":"false","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_biometrics_facialfeaturesuseenhancedantispoofing_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_biometrics_usebiometrics","displayName":"Allow Use of Biometrics","description":"Windows Hello for Business enables users to use biometric gestures, such as face and fingerprints, as an alternative to the PIN gesture. However, users must still configure a PIN to use in case of failures.\n\nIf you enable or do not configure this policy setting, Windows Hello for Business allows the use of biometric gestures.\n\nIf you disable this policy setting, Windows Hello for Business prevents the use of biometric gestures.\n\nNOTE: Disabling this policy prevents the use of biometric gestures on the device for all account types.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_biometrics_usebiometrics_false","displayName":"False","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_biometrics_usebiometrics_true","displayName":"True","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_deviceunlock_groupa","displayName":"Group A","description":"Contains a list of providers by GUID that are to be considered for the first step of authentication","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_deviceunlock_groupb","displayName":"Group B","description":"Contains a list of providers by GUID that are to be considered for the second step of authentication","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_deviceunlock_plugins","displayName":"Device Unlock Plugins","description":"List of plugins that the passive provider monitors to detect user presence","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_dynamiclock_dynamiclock","displayName":"Dynamic Lock","description":"Enables/Disables Dyanamic Lock","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_dynamiclock_dynamiclock_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_dynamiclock_dynamiclock_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_passportforwork_dynamiclock_plugins","displayName":"Dynamic Lock Plugins","description":"List of plugins that the passive provider monitors to detect user absence","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},{"id":"device_vendor_msft_passportforwork_securitykey_usesecuritykeyforsignin","displayName":"Use Security Key For Signin","description":"Use security key for signin. 0 is disabled. 1 is enable. If you do not configure this policy setting, the default is disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_securitykey_usesecuritykeyforsignin_0","displayName":"Disabled","description":"disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_securitykey_usesecuritykeyforsignin_1","displayName":"Enabled","description":"enabled","helpText":null}]},{"id":"device_vendor_msft_pkcscertificate_certificatevalidityperiod","displayName":"Certificate validity period","description":"The amount of time remaining before the certificate expires. Enter a value that is equal to or lower than the validity period shown in the certificate template. Default is set at one year.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},{"id":"device_vendor_msft_pkcscertificate_certificationauthority","displayName":"Certification Authority","description":"The fully qualified domain name of the server that hosts the Certification Authority role and issues certificates.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},{"id":"device_vendor_msft_pkcscertificate_keystorageprovider","displayName":"Key storage provider (KSP)","description":"Select where you want to store the certificate’s key.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},{"id":"device_vendor_msft_pkcscertificate_renewalthreshold","displayName":"Renewal threshold (%)","description":"Enter the percentage (between 1 and 99 percent) of remaining certificate lifetime that is allowed before a device can request renewal of the certificate. The recommended amount in Intune is 20%. (1-99)","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},{"id":"device_vendor_msft_pkcscertificate_subjectnameformat","displayName":"Subject name format","description":"CN={{UserName}},E={{EmailAddress}},OU=EnterpriseUsers,O=Contoso Corporation,L=Redmond,ST=WA,C=US\\nor\\nCN={{AAD_Device_ID}},E={{EmailAddress}},OU=EnterpriseUsers,O=Contoso Corporation,L=Redmond,ST=WA,C=US","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},{"id":"device_vendor_msft_pkcsimportedcertificate_intendedpurpose","displayName":"Intended Purpose","description":null,"helpText":"","infoUrls":[],"categoryId":"b2b85670-5475-4148-ab3d-c4c86b4d5af0","categoryName":"PKCS imported certificate","options":null},{"id":"device_vendor_msft_pkcsimportedcertificate_keystorageprovider","displayName":"Key storage provider (KSP)","description":"Select where you want to store the certificate’s key.","helpText":"","infoUrls":[],"categoryId":"b2b85670-5475-4148-ab3d-c4c86b4d5af0","categoryName":"PKCS imported certificate","options":null},{"id":"device_vendor_msft_policy_config_abovelock_allowcortanaabovelock","displayName":"Allow Cortana Above Lock","description":"Added in Windows 10, version 1607. Specifies whether or not the user can interact with Cortana using speech while the system is locked. If you allow or don’t configure this setting, the user can interact with Cortana using speech while the system is locked. If you block this setting, the system will need to be unlocked for the user to interact with Cortana using speech.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-abovelock#allowcortanaabovelock"],"categoryId":"ef8b8f2d-7791-4c44-a4f2-e39051f2e715","categoryName":"Above Lock","options":[{"id":"device_vendor_msft_policy_config_abovelock_allowcortanaabovelock_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_abovelock_allowcortanaabovelock_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_abovelock_allowtoasts","displayName":"Allow Toasts","description":"Specifies whether to allow toast notifications above the device lock screen. Most restrictive value is \"Block\".","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-abovelock#allowtoasts"],"categoryId":"ef8b8f2d-7791-4c44-a4f2-e39051f2e715","categoryName":"Above Lock","options":[{"id":"device_vendor_msft_policy_config_abovelock_allowtoasts_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_abovelock_allowtoasts_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_accounts_allowaddingnonmicrosoftaccountsmanually","displayName":"Allow Adding Non Microsoft Accounts Manually","description":"Specifies whether user is allowed to add non-MSA email accounts. Most restricted value is 0. Note This policy will only block UI/UX-based methods for adding non-Microsoft accounts. Even if this policy is enforced, you can still provision non-MSA accounts using the EMAIL2 CSP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Accounts#AllowAddingNonMicrosoftAccountsManually"],"categoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","categoryName":"Accounts","options":[{"id":"device_vendor_msft_policy_config_accounts_allowaddingnonmicrosoftaccountsmanually_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_accounts_allowaddingnonmicrosoftaccountsmanually_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountconnection","displayName":"Allow Microsoft Account Connection","description":"Specifies whether the user is allowed to use an MSA account for non-email related connection authentication and services. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Accounts#AllowMicrosoftAccountConnection"],"categoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","categoryName":"Accounts","options":[{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountconnection_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountconnection_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountsigninassistant","displayName":"Allow Microsoft Account Sign In Assistant","description":"Allows IT Admins the ability to disable the Microsoft Account Sign-In Assistant (wlidsvc) NT service. Note If the MSA service is disabled, Windows Update will no longer offer feature updates to devices running Windows 10 1709 or higher. See Feature updates are not being offered while other updates are. Note: If the MSA service is disabled, the Subscription Activation feature will not work properly and your users will not be able to “step-up” from Windows 10 Pro to Windows 10 Enterprise, because the MSA ticket for license authentication cannot be generated. The machine will remain on Windows 10 Pro and no error will be displayed in the Activation Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Accounts#AllowMicrosoftAccountSignInAssistant"],"categoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","categoryName":"Accounts","options":[{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountsigninassistant_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountsigninassistant_1","displayName":"Manual start","description":"Manual start","helpText":null}]},{"id":"device_vendor_msft_policy_config_accounts_domainnamesforemailsync","displayName":"Domain Names For Email Sync","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Accounts#domainnamesforemailsync"],"categoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","categoryName":"Accounts","options":null},{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites","displayName":"Approved Installation Sites for ActiveX Controls","description":"This policy setting determines which ActiveX installation sites standard users in your organization can use to install ActiveX controls on their computers. When this setting is enabled, the administrator can create a list of approved Activex Install sites specified by host URL. \n\nIf you enable this setting, the administrator can create a list of approved ActiveX Install sites specified by host URL. \n \nIf you disable or do not configure this policy setting, ActiveX controls prompt the user for administrative credentials before installation. \n\nNote: Wild card characters cannot be used when specifying the host URLs.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-activexcontrols#activexcontrols-approvedinstallationsites"],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites_approvedactivexinstallsiteslist","displayName":"Host URLs","description":"","helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":null},{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites_approvedactivexinstallsiteslist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":null},{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites_approvedactivexinstallsiteslist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies","displayName":"Establish ActiveX installation policy for sites in Trusted zones","description":"This policy setting controls the installation of ActiveX controls for sites in Trusted zone. \r\n\r\nIf you enable this policy setting, ActiveX controls are installed according to the settings defined by this policy setting. \r\n \r\nIf you disable or do not configure this policy setting, ActiveX controls prompt the user before installation. \r\n\r\nIf the trusted site uses the HTTPS protocol, this policy setting can also control how ActiveX Installer Service responds to certificate errors. By default all HTTPS connections must supply a server certificate that passes all validation criteria. If you are aware that a trusted site has a certificate error but you want to trust it anyway you can select the certificate errors that you want to ignore. \r\n \r\nNote: This policy setting applies to all sites in Trusted zones.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-activexinstallservice#admx-activexinstallservice-axisurlzonepolicies"],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcertdate","displayName":"Expired certificate validation date","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcertdate_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcertdate_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcn","displayName":"Invalid certificate name (CN)","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcn_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcn_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreunknownca","displayName":"Unknown certifcation authority (CA)","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreunknownca_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreunknownca_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignorewrongcertusage","displayName":"Wrong certificate usage","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignorewrongcertusage_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignorewrongcertusage_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installsignedocx","displayName":"Installation Policy for signed ActiveX control","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installsignedocx_0","displayName":"Don't install","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installsignedocx_1","displayName":"Prompt the user","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installsignedocx_2","displayName":"Silently install","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installtrustedocx","displayName":"Installation Policy for ActiveX control signed by trusted publisher","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installtrustedocx_0","displayName":"Don't install","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installtrustedocx_1","displayName":"Prompt the user","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installtrustedocx_2","displayName":"Silently install","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installunsignedocx","displayName":"Installation Policy for unsigned ActiveX control","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installunsignedocx_0","displayName":"Don't install","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installunsignedocx_1","displayName":"Prompt the user","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd","displayName":"Password Settings","description":"\nConfigures password parameters\n\nPassword complexity: which characters are used when generating a new password\n Default: Large letters + small letters + numbers + special characters\n\nPassword length\n Minimum: 8 characters\n Maximum: 64 characters\n Default: 14 characters\n\nPassword age in days\n Minimum: 1 day\n Maximum: 365 days\n Default: 30 days\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-admpwd#admx-admpwd-pol-admpwd"],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":[{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname","displayName":"Name of administrator account to manage","description":"\nAdministrator account name: name of the local account you want to manage password for.\n DO NOT configure when you use built-in admin account. Built-in admin account is auto-detected by well-known SID, even when renamed\n\n DO configure when you use custom local admin account\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-admpwd#admx-admpwd-pol-admpwd-adminname"],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":[{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname_txt_adminaccountname","displayName":"Administrator account name","description":"","helpText":"","infoUrls":[],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_dontallowpwdexpirationbehindpolicy","displayName":"Do not allow password expiration time longer than required by policy","description":"\nWhen you enable this setting, planned password expiration longer than password age dictated by \"Password Settings\" policy is NOT allowed. When such expiration is detected, password is changed immediately and password expiration is set according to policy.\n\nWhen you disable or not configure this setting, password expiration time may be longer than required by \"Password Settings\" policy.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-admpwd#admx-admpwd-pol-admpwd-dontallowpwdexpirationbehindpolicy"],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":[{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_dontallowpwdexpirationbehindpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_dontallowpwdexpirationbehindpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordagedays","displayName":"Password Age (Days)","description":"","helpText":"","infoUrls":[],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordcomplexity","displayName":"Password Complexity","description":"","helpText":"","infoUrls":[],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":[{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordcomplexity_1","displayName":"Large letters","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordcomplexity_2","displayName":"Large letters + small letters","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordcomplexity_3","displayName":"Large letters + small letters + numbers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordcomplexity_4","displayName":"Large letters + small letters + numbers + specials","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordlength","displayName":"Password Length","description":"","helpText":"","infoUrls":[],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_enabled","displayName":"Enable local admin password management","description":"\nEnables management of password for local administrator account\n\nIf you enable this setting, local administrator password is managed\n\nIf you disable or not configure this setting, local administrator password is NOT managed\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-admpwd#admx-admpwd-pol-admpwd-enabled"],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":[{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatprevent16bitmach","displayName":"Prevent access to 16-bit applications","description":"Specifies whether to prevent the MS-DOS subsystem (ntvdm.exe) from running on this computer. This setting affects the launching of 16-bit applications in the operating system.\r\n\r\nYou can use this setting to turn off the MS-DOS subsystem, which will reduce resource usage and prevent users from running 16-bit applications. To run any 16-bit application or any application with 16-bit components, ntvdm.exe must be allowed to run. The MS-DOS subsystem starts when the first 16-bit application is launched. While the MS-DOS subsystem is running, any subsequent 16-bit applications launch faster, but overall resource usage on the system is increased.\r\n\r\nIf the status is set to Enabled, the MS-DOS subsystem is prevented from running, which then prevents any 16-bit applications from running. In addition, any 32-bit applications with 16-bit installers or other 16-bit components cannot run.\r\n\r\nIf the status is set to Disabled, the MS-DOS subsystem runs for all users on this computer.\r\n\r\nIf the status is set to Not Configured, the OS falls back on a local policy set by the registry DWORD value HKLM\\System\\CurrentControlSet\\Control\\WOW\\DisallowedPolicyDefault. If that value is non-0, this prevents all 16-bit applications from running. If that value is 0, 16-bit applications are allowed to run. If that value is also not present, on Windows 10 and above the OS will launch the 16-bit application support control panel to allow an elevated administrator to make the decision; on windows 7 and downlevel, the OS will allow 16-bit applications to run.\r\n\r\nNote: This setting appears in only Computer Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatprevent16bitmach"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatprevent16bitmach_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatprevent16bitmach_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatremoveprogramcompatproppage","displayName":"Remove Program Compatibility Property Page","description":"This policy controls the visibility of the Program Compatibility property page shell extension. This shell extension is visible on the property context-menu of any program shortcut or executable file.\r\n\r\nThe compatibility property page displays a list of options that can be selected and applied to the application to resolve the most common issues affecting legacy applications. Enabling this policy setting removes the property page from the context-menus, but does not affect previous compatibility settings applied to application using this interface.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatremoveprogramcompatproppage"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatremoveprogramcompatproppage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatremoveprogramcompatproppage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffapplicationimpacttelemetry","displayName":"Turn off Application Telemetry","description":"The policy controls the state of the Application Telemetry engine in the system.\r\n\r\nApplication Telemetry is a mechanism that tracks anonymous usage of specific Windows system components by applications.\r\n\r\nTurning Application Telemetry off by selecting \"enable\" will stop the collection of usage data.\r\n\r\nIf the customer Experience Improvement program is turned off, Application Telemetry will be turned off regardless of how this policy is set.\r\n\r\nDisabling telemetry will take effect on any newly launched applications. To ensure that telemetry collection has stopped for all applications, please reboot your machine.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffapplicationimpacttelemetry"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffapplicationimpacttelemetry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffapplicationimpacttelemetry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffengine","displayName":"Turn off Application Compatibility Engine","description":" This policy controls the state of the application compatibility engine in the system.\r\n\r\nThe engine is part of the loader and looks through a compatibility database every time an application is started on the system. If a match for the application is found it provides either run-time solutions or compatibility fixes, or displays an Application Help message if the application has a know problem.\r\n\r\nTurning off the application compatibility engine will boost system performance. However, this will degrade the compatibility of many popular legacy applications, and will not block known incompatible applications from installing. (For Instance: This may result in a blue screen if an old anti-virus application is installed.)\r\n\r\nThe Windows Resource Protection and User Account Control features of Windows use the application compatibility engine to provide mitigations for application problems. If the engine is turned off, these mitigations will not be applied to applications and their installers and these applications may fail to install or run properly.\r\n\r\nThis option is useful to server administrators who require faster performance and are aware of the compatibility of the applications they are using. It is particularly useful for a web server where applications may be launched several hundred times a second, and the performance of the loader is essential.\r\n\r\nNOTE: Many system processes cache the value of this setting for performance reasons. If you make changes to this setting, please reboot to ensure that your system accurately reflects those changes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffengine"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffengine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffengine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffprogramcompatibilityassistant_2","displayName":"Turn off Program Compatibility Assistant","description":"This policy setting controls the state of the Program Compatibility Assistant (PCA).\r\n \r\nThe PCA monitors applications run by the user. When a potential compatibility issue with an application is detected, the PCA will prompt the user with recommended solutions. To configure the diagnostic settings for the PCA, go to System->Troubleshooting and Diagnostics->Application Compatibility Diagnostics. \r\n\r\nIf you enable this policy setting, the PCA will be turned off. The user will not be presented with solutions to known compatibility issues when running applications. Turning off the PCA can be useful for system administrators who require better performance and are already aware of application compatibility issues. \r\n\r\nIf you disable or do not configure this policy setting, the PCA will be turned on. To configure the diagnostic settings for the PCA, go to System->Troubleshooting and Diagnostics->Application Compatibility Diagnostics.\r\n\r\nNote: The Diagnostic Policy Service (DPS) and Program Compatibility Assistant Service must be running for the PCA to run. These services can be configured by using the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffprogramcompatibilityassistant-2"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffprogramcompatibilityassistant_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffprogramcompatibilityassistant_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffprograminventory","displayName":"Turn off Inventory Collector","description":"This policy setting controls the state of the Inventory Collector. \r\n\r\nThe Inventory Collector inventories applications, files, devices, and drivers on the system and sends the information to Microsoft. This information is used to help diagnose compatibility problems.\r\n\r\nIf you enable this policy setting, the Inventory Collector will be turned off and data will not be sent to Microsoft. Collection of installation data through the Program Compatibility Assistant is also disabled.\r\n\r\nIf you disable or do not configure this policy setting, the Inventory Collector will be turned on.\r\n\r\nNote: This policy setting has no effect if the Customer Experience Improvement Program is turned off. The Inventory Collector will be off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffprograminventory"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffprograminventory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffprograminventory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffswitchback","displayName":"Turn off SwitchBack Compatibility Engine","description":"The policy controls the state of the Switchback compatibility engine in the system. \r\n\r\nSwitchback is a mechanism that provides generic compatibility mitigations to older applications by providing older behavior to old applications and new behavior to new applications. \r\n\r\nSwitchback is on by default.\r\n\r\nIf you enable this policy setting, Switchback will be turned off. Turning Switchback off may degrade the compatibility of older applications. This option is useful for server administrators who require performance and are aware of compatibility of the applications they are using. \r\n\r\nIf you disable or do not configure this policy setting, the Switchback will be turned on.\r\n\r\nPlease reboot the system after changing the setting to ensure that your system accurately reflects those changes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffswitchback"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffswitchback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffswitchback_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffuseractionrecord","displayName":"Turn off Steps Recorder","description":"This policy setting controls the state of Steps Recorder.\r\n\r\nSteps Recorder keeps a record of steps taken by the user. The data generated by Steps Recorder can be used in feedback systems such as Windows Error Reporting to help developers understand and fix problems. The data includes user actions such as keyboard input and mouse input, user interface data, and screen shots. Steps Recorder includes an option to turn on and off data collection.\r\n\r\nIf you enable this policy setting, Steps Recorder will be disabled.\r\n\r\nIf you disable or do not configure this policy setting, Steps Recorder will be enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffuseractionrecord"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffuseractionrecord_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffuseractionrecord_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appxpackagemanager_allowdeploymentinspecialprofiles","displayName":"Allow deployment operations in special profiles","description":"This policy setting allows you to manage the deployment of Windows Store apps when the user is signed in using a special profile. Special profiles are the following user profiles, where changes are discarded after the user signs off:\r\n\r\nRoaming user profiles to which the \"Delete cached copies of roaming profiles\" Group Policy setting applies\r\n\r\nMandatory user profiles and super-mandatory profiles, which are created by an administrator\r\n\r\nTemporary user profiles, which are created when an error prevents the correct profile from loading\r\n\r\nUser profiles for the Guest account and members of the Guests group\r\n\r\n\r\nIf you enable this policy setting, Group Policy allows deployment operations (adding, registering, staging, updating, or removing an app package) of Windows Store apps when using a special profile.\r\n\r\nIf you disable or do not configure this policy setting, Group Policy blocks deployment operations of Windows Store apps when using a special profile.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appxpackagemanager#admx-appxpackagemanager-allowdeploymentinspecialprofiles"],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_admx_appxpackagemanager_allowdeploymentinspecialprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appxpackagemanager_allowdeploymentinspecialprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeapplicationcontenturirules","displayName":"Turn on dynamic Content URI Rules for packaged Microsoft Store apps","description":"This policy setting lets you turn on Content URI Rules to supplement the static Content URI Rules that were defined as part of the app manifest and apply to all Windows Store apps that use the enterpriseAuthentication capability on a computer.\r\n\r\nIf you enable this policy setting, you can define additional Content URI Rules that all Windows Store apps that use the enterpriseAuthentication capability on a computer can use.\r\n\r\nIf you disable or don't set this policy setting, Windows Store apps will only use the static Content URI Rules.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appxruntime#admx-appxruntime-appxruntimeapplicationcontenturirules"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeapplicationcontenturirules_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeapplicationcontenturirules_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeapplicationcontenturirules_listbox_contenturirules","displayName":"Content URI Rules:","description":null,"helpText":"","infoUrls":[],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":null},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockfileelevation","displayName":"Block launching desktop apps associated with a file.","description":"This policy setting lets you control whether Windows Store apps can open files using the default desktop app for a file type. Because desktop apps run at a higher integrity level than Windows Store apps, there is a risk that a Windows Store app might compromise the system by opening a file in the default desktop app for a file type.\r\n\r\nIf you enable this policy setting, Windows Store apps cannot open files in the default desktop app for a file type; they can open files only in other Windows Store apps.\r\n\r\nIf you disable or do not configure this policy setting, Windows Store apps can open files in the default desktop app for a file type.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appxruntime#admx-appxruntime-appxruntimeblockfileelevation"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockfileelevation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockfileelevation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockhostedappaccesswinrt","displayName":"Block launching Universal Windows apps with Windows Runtime API access from hosted content.","description":"\r\n This policy setting controls whether Universal Windows apps with Windows Runtime API access directly from web content can be launched.\r\n\r\n If you enable this policy setting, Universal Windows apps which declare Windows Runtime API access in ApplicationContentUriRules section of the manifest cannot be launched; Universal Windows apps which have not declared Windows Runtime API access in the manifest are not affected.\r\n\r\n If you disable or do not configure this policy setting, all Universal Windows apps can be launched.\r\n\r\n This policy should not be enabled unless recommended by Microsoft as a security response because it can cause severe app compatibility issues.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appxruntime#admx-appxruntime-appxruntimeblockhostedappaccesswinrt"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockhostedappaccesswinrt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockhostedappaccesswinrt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockprotocolelevation","displayName":"Block launching desktop apps associated with a URI scheme","description":"This policy setting lets you control whether Windows Store apps can open URIs using the default desktop app for a URI scheme. Because desktop apps run at a higher integrity level than Windows Store apps, there is a risk that a URI scheme launched by a Windows Store app might compromise the system by launching a desktop app.\r\n\r\nIf you enable this policy setting, Windows Store apps cannot open URIs in the default desktop app for a URI scheme; they can open URIs only in other Windows Store apps.\r\n\r\nIf you disable or do not configure this policy setting, Windows Store apps can open URIs in the default desktop app for a URI scheme.\r\n\r\nNote: Enabling this policy setting does not block Windows Store apps from opening the default desktop app for the http, https, and mailto URI schemes. The handlers for these URI schemes are hardened against URI-based vulnerabilities from untrusted sources, reducing the associated risk.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appxruntime#admx-appxruntime-appxruntimeblockprotocolelevation"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockprotocolelevation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockprotocolelevation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_auditsettings_includecmdline","displayName":"Include command line in process creation events","description":"This policy setting determines what information is logged in security audit events when a new process has been created.\r\n\r\nThis setting only applies when the Audit Process Creation policy is enabled. If you enable this policy setting the command line information for every process will be logged in plain text in the security event log as part of the Audit Process Creation event 4688, \"a new process has been created,\" on the workstations and servers on which this policy setting is applied.\r\n\r\nIf you disable or do not configure this policy setting, the process's command line information will not be included in Audit Process Creation events.\r\n\r\nDefault: Not configured\r\n\r\nNote: When this policy setting is enabled, any user with access to read the security events will be able to read the command line arguments for any successfully created process. Command line arguments can contain sensitive or private information such as passwords or user data.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-auditsettings#admx-auditsettings-includecmdline"],"categoryId":"76bbc368-9d0b-4aa7-b8e2-2dcfd864b9ee","categoryName":"Audit Process Creation","options":[{"id":"device_vendor_msft_policy_config_admx_auditsettings_includecmdline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_auditsettings_includecmdline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablebranchcache","displayName":"Do not allow the BITS client to use Windows Branch Cache","description":"This setting affects whether the BITS client is allowed to use Windows Branch Cache. If the Windows Branch Cache component is installed and enabled on a computer, BITS jobs on that computer can use Windows Branch Cache by default.\r\n\r\n If you enable this policy setting, the BITS client does not use Windows Branch Cache.\r\n\r\n If you disable or do not configure this policy setting, the BITS client uses Windows Branch Cache.\r\n\r\n Note: This policy setting does not affect the use of Windows Branch Cache by applications other than BITS. This policy setting does not apply to BITS transfers over SMB. This setting has no effect if the computer's administrative settings for Windows Branch Cache disable its use entirely.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-disablebranchcache"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablebranchcache_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablebranchcache_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablepeercachingclient","displayName":"Do not allow the computer to act as a BITS Peercaching client","description":"This policy setting specifies whether the computer will act as a BITS peer caching client. By default, when BITS peer caching is enabled, the computer acts as both a peer caching server (offering files to its peers) and a peer caching client (downloading files from its peers).\r\n\r\n If you enable this policy setting, the computer will no longer use the BITS peer caching feature to download files; files will be downloaded only from the origin server. However, the computer will still make files available to its peers.\r\n\r\n If you disable or do not configure this policy setting, the computer attempts to download peer-enabled BITS jobs from peer computers before reverting to the origin server.\r\n\r\n Note: This policy setting has no effect if the \"Allow BITS peer caching\" policy setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-disablepeercachingclient"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablepeercachingclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablepeercachingclient_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablepeercachingserver","displayName":"Do not allow the computer to act as a BITS Peercaching server","description":"This policy setting specifies whether the computer will act as a BITS peer caching server. By default, when BITS peer caching is enabled, the computer acts as both a peer caching server (offering files to its peers) and a peer caching client (downloading files from its peers).\r\n\r\n If you enable this policy setting, the computer will no longer cache downloaded files and offer them to its peers. However, the computer will still download files from peers.\r\n\r\n If you disable or do not configure this policy setting, the computer will offer downloaded and cached files to its peers.\r\n\r\n Note: This setting has no effect if the \"Allow BITS peer caching\" setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-disablepeercachingserver"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablepeercachingserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablepeercachingserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_enablepeercaching","displayName":"Allow BITS Peercaching","description":"This policy setting determines if the Background Intelligent Transfer Service (BITS) peer caching feature is enabled on a specific computer. By default, the files in a BITS job are downloaded only from the origin server specified by the job's owner.\r\n\r\n If BITS peer caching is enabled, BITS caches downloaded files and makes them available to other BITS peers. When transferring a download job, BITS first requests the files for the job from its peers in the same IP subnet. If none of the peers in the subnet have the requested files, BITS downloads them from the origin server.\r\n\r\n If you enable this policy setting, BITS downloads files from peers, caches the files, and responds to content requests from peers. Using the \"Do not allow the computer to act as a BITS peer caching server\" and \"Do not allow the computer to act as a BITS peer caching client\" policy settings, it is possible to control BITS peer caching functionality at a more detailed level. However, it should be noted that the \"Allow BITS peer caching\" policy setting must be enabled for the other two policy settings to have any effect.\r\n\r\n If you disable or do not configure this policy setting, the BITS peer caching feature will be disabled, and BITS will download files directly from the origin server.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-enablepeercaching"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_enablepeercaching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_enablepeercaching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthservedforpeers","displayName":"Limit the maximum network bandwidth used for Peercaching","description":"This policy setting limits the network bandwidth that BITS uses for peer cache transfers (this setting does not affect transfers from the origin server).\r\n To prevent any negative impact to a computer caused by serving other peers, by default BITS will use up to 30 percent of the bandwidth of the slowest active network interface. For example, if a computer has both a 100 Mbps network card and a 56 Kbps modem, and both are active, BITS will use a maximum of 30 percent of 56 Kbps. \r\n You can change the default behavior of BITS, and specify a fixed maximum bandwidth that BITS will use for peer caching.\r\n\r\n If you enable this policy setting, you can enter a value in bits per second (bps) between 1048576 and 4294967200 to use as the maximum network bandwidth used for peer caching.\r\n\r\n If you disable this policy setting or do not configure it, the default value of 30 percent of the slowest active network interface will be used.\r\n\r\n Note: This setting has no effect if the \"Allow BITS peer caching\" policy setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxbandwidthservedforpeers"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthservedforpeers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthservedforpeers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthservedforpeers_bits_maxbandwidthservedforpeerslist","displayName":"Maximum network bandwidth used for Peercaching (bps):","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance","displayName":"Set up a maintenance schedule to limit the maximum network bandwidth used for BITS background transfers","description":"This policy setting limits the network bandwidth that Background Intelligent Transfer Service (BITS) uses for background transfers during the maintenance days and hours. Maintenance schedules further limit the network bandwidth that is used for background transfers.\r\n\r\n If you enable this policy setting, you can define a separate set of network bandwidth limits and set up a schedule for the maintenance period.\r\n\r\n You can specify a limit to use for background jobs during a maintenance schedule. For example, if normal priority jobs are currently limited to 256 Kbps on a work schedule, you can further limit the network bandwidth of normal priority jobs to 0 Kbps from 8:00 A.M. to 10:00 A.M. on a maintenance schedule.\r\n\r\n If you disable or do not configure this policy setting, the limits defined for work or nonwork schedules will be used.\r\n\r\n Note: The bandwidth limits that are set for the maintenance period supersede any limits defined for work and other schedules.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxbandwidthv2-maintenance"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysfrom_6","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_6","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehighprioritylimit","displayName":"High Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehighpriorityunit","displayName":"High Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehighpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehighpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehighpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_23","displayName":"11 PM","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_23","displayName":"11 PM","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancelowprioritylimit","displayName":"Low Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancelowpriorityunit","displayName":"Low Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancelowpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancelowpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancelowpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalprioritylimit","displayName":"Normal Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit","displayName":"Normal Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work","displayName":"Set up a work schedule to limit the maximum network bandwidth used for BITS background transfers","description":"This policy setting limits the network bandwidth that Background Intelligent Transfer Service (BITS) uses for background transfers during the work and nonwork days and hours. The work schedule is defined using a weekly calendar, which consists of days of the week and hours of the day. All hours and days that are not defined in a work schedule are considered non-work hours.\r\n\r\n If you enable this policy setting, you can set up a schedule for limiting network bandwidth during both work and nonwork hours. After the work schedule is defined, you can set the bandwidth usage limits for each of the three BITS background priority levels: high, normal, and low.\r\n\r\n You can specify a limit to use for background jobs during a work schedule. For example, you can limit the network bandwidth of low priority jobs to 128 Kbps from 8:00 A.M. to 5:00 P.M. on Monday through Friday, and then set the limit to 512 Kbps for nonwork hours.\r\n\r\n If you disable or do not configure this policy setting, BITS uses all available unused bandwidth for background job transfers.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxbandwidthv2-work"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_ignorelimitsonlan","displayName":"Ignore bandwidth limits if the source and the destination are on the same subnet.","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_ignorelimitsonlan_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_ignorelimitsonlan_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworkhighprioritylimit","displayName":"High Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworkhighpriorityunit","displayName":"High Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworkhighpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworkhighpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworkhighpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworklowprioritylimit","displayName":"Low Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworklowpriorityunit","displayName":"Low Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworklowpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworklowpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworklowpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalprioritylimit","displayName":"Normal Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit","displayName":"Normal Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_6","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_6","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhighprioritylimit","displayName":"High Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhighpriorityunit","displayName":"High Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhighpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhighpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhighpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_23","displayName":"11 PM","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursto_23","displayName":"11 PM","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worklowprioritylimit","displayName":"Low Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worklowpriorityunit","displayName":"Low Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worklowpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worklowpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worklowpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worknormalprioritylimit","displayName":"Normal Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worknormalpriorityunit","displayName":"Normal Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worknormalpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worknormalpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_worknormalpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcachesize","displayName":"Limit the BITS Peercache size","description":"This policy setting limits the maximum amount of disk space that can be used for the BITS peer cache, as a percentage of the total system disk size. BITS will add files to the peer cache and make those files available to peers until the cache content reaches the specified cache size. By default, BITS will use 1 percent of the total system disk for the peercache.\r\n\r\n If you enable this policy setting, you can enter the percentage of disk space to be used for the BITS peer cache. You can enter a value between 1 percent and 80 percent.\r\n\r\n If you disable or do not configure this policy setting, the default size of the BITS peer cache is 1 percent of the total system disk size.\r\n\r\n Note: This policy setting has no effect if the \"Allow BITS peer caching\" setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxcachesize"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcachesize_bits_maxsize","displayName":"Percentage of disk space to be used for the BITS peercache:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcontentage","displayName":"Limit the age of files in the BITS Peercache","description":"This policy setting limits the maximum age of files in the Background Intelligent Transfer Service (BITS) peer cache. In order to make the most efficient use of disk space, by default BITS removes any files in the peer cache that have not been accessed in the past 90 days.\r\n\r\n If you enable this policy setting, you can specify in days the maximum age of files in the cache. You can enter a value between 1 and 120 days.\r\n\r\n If you disable or do not configure this policy setting, files that have not been accessed for the past 90 days will be removed from the peer cache.\r\n\r\n Note: This policy setting has no effect if the \"Allow BITS Peercaching\" policy setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxcontentage"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcontentage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcontentage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcontentage_bits_maxcontentagelist","displayName":"Number of days:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxdownloadtime","displayName":"Limit the maximum BITS job download time","description":"This policy setting limits the amount of time that Background Intelligent Transfer Service (BITS) will take to download the files in a BITS job.\r\n\r\n The time limit applies only to the time that BITS is actively downloading files. When the cumulative download time exceeds this limit, the job is placed in the error state.\r\n\r\n By default BITS uses a maximum download time of 90 days (7,776,000 seconds).\r\n\r\n If you enable this policy setting, you can set the maximum job download time to a specified number of seconds.\r\n\r\n If you disable or do not configure this policy setting, the default value of 90 days (7,776,000 seconds) will be used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxdownloadtime"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxdownloadtime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxdownloadtime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxdownloadtime_bits_maxdownloadseconds","displayName":"Active Job Timeout in seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxfilesperjob","displayName":"Limit the maximum number of files allowed in a BITS job","description":"This policy setting limits the number of files that a BITS job can contain. By default, a BITS job is limited to 200 files. You can use this setting to raise or lower the maximum number of files a BITS jobs can contain.\r\n\r\n If you enable this policy setting, BITS will limit the maximum number of files a job can contain to the specified number.\r\n\r\n If you disable or do not configure this policy setting, BITS will use the default value of 200 for the maximum number of files a job can contain.\r\n\r\n Note: BITS Jobs created by services and the local administrator account do not count toward this limit.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxfilesperjob"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxfilesperjob_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxfilesperjob_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxfilesperjob_bits_maxfilesperjoblist","displayName":"Maximum number of files allowed in a BITS job:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobspermachine","displayName":"Limit the maximum number of BITS jobs for this computer","description":"This policy setting limits the number of BITS jobs that can be created for all users of the computer. By default, BITS limits the total number of jobs that can be created on the computer to 300 jobs. You can use this policy setting to raise or lower the maximum number of user BITS jobs.\r\n\r\n If you enable this policy setting, BITS will limit the maximum number of BITS jobs to the specified number.\r\n\r\n If you disable or do not configure this policy setting, BITS will use the default BITS job limit of 300 jobs.\r\n\r\n Note: BITS jobs created by services and the local administrator account do not count toward this limit.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxjobspermachine"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobspermachine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobspermachine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobspermachine_bits_maxjobspermachinelist","displayName":"Maximum number of BITS jobs for this computer:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser","displayName":"Limit the maximum number of BITS jobs for each user","description":"This policy setting limits the number of BITS jobs that can be created by a user. By default, BITS limits the total number of jobs that can be created by a user to 60 jobs. You can use this setting to raise or lower the maximum number of BITS jobs a user can create.\r\n\r\n If you enable this policy setting, BITS will limit the maximum number of BITS jobs a user can create to the specified number.\r\n\r\n If you disable or do not configure this policy setting, BITS will use the default user BITS job limit of 300 jobs.\r\n\r\n Note: This limit must be lower than the setting specified in the \"Maximum number of BITS jobs for this computer\" policy setting, or 300 if the \"Maximum number of BITS jobs for this computer\" policy setting is not configured. BITS jobs created by services and the local administrator account do not count toward this limit.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxjobsperuser"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser_bits_maxjobsperuserlist","displayName":"Maximum number of BITS jobs for each user:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxrangesperfile","displayName":"Limit the maximum number of ranges that can be added to the file in a BITS job","description":"This policy setting limits the number of ranges that can be added to a file in a BITS job. By default, files in a BITS job are limited to 500 ranges per file. You can use this setting to raise or lower the maximum number ranges per file.\r\n\r\n If you enable this policy setting, BITS will limit the maximum number of ranges that can be added to a file to the specified number.\r\n\r\n If you disable or do not configure this policy setting, BITS will limit ranges to 500 ranges per file.\r\n\r\n Note: BITS Jobs created by services and the local administrator account do not count toward this limit.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxrangesperfile"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxrangesperfile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxrangesperfile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxrangesperfile_bits_maxrangesperfilelist","displayName":"Maximum number of ranges that can be added to the file in a BITS job:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslciphersuiteorder","displayName":"SSL Cipher Suite Order","description":"This policy setting determines the cipher suites used by the Secure Socket Layer (SSL).\r\n\r\nIf you enable this policy setting, SSL cipher suites are prioritized in the order specified.\r\n\r\nIf you disable or do not configure this policy setting, default cipher suite order is used.\r\n\r\nLink for all the cipherSuites: http://go.microsoft.com/fwlink/?LinkId=517265\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ciphersuiteorder#admx-ciphersuiteorder-sslciphersuiteorder"],"categoryId":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","categoryName":"SSL Configuration Settings","options":[{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslciphersuiteorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslciphersuiteorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslciphersuiteorder_pol_sslciphersuiteorder","displayName":"SSL Cipher Suites","description":null,"helpText":"","infoUrls":[],"categoryId":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","categoryName":"SSL Configuration Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder","displayName":"ECC Curve Order","description":"This policy setting determines the priority order of ECC curves used with ECDHE cipher suites.\r\n\r\nIf you enable this policy setting, ECC curves are prioritized in the order specified.(Enter one Curve name per line)\r\n\r\nIf you disable or do not configure this policy setting, the default ECC curve order is used.\r\n\r\nDefault Curve Order\r\n============\r\ncurve25519\r\nNistP256\r\nNistP384\r\n\r\nTo See all the curves supported on the system, Use the following command:\r\n\r\nCertUtil.exe -DisplayEccCurve\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ciphersuiteorder#admx-ciphersuiteorder-sslcurveorder"],"categoryId":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","categoryName":"SSL Configuration Settings","options":[{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder_sslcurveorderlist","displayName":"ECC Curve Order:","description":null,"helpText":"","infoUrls":[],"categoryId":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","categoryName":"SSL Configuration Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_com_appmgmt_com_searchforclsid_2","displayName":"Download missing COM components","description":"This policy setting directs the system to search Active Directory for missing Component Object Model (COM) components that a program requires.\r\n\r\nMany Windows programs, such as the MMC snap-ins, use the interfaces provided by the COM components. These programs cannot perform all their functions unless Windows has internally registered the required components.\r\n\r\nIf you enable this policy setting and a component registration is missing, the system searches for it in Active Directory and, if it is found, downloads it. The resulting searches might make some programs start or run slowly.\r\n\r\nIf you disable or do not configure this policy setting, the program continues without the registration. As a result, the program might not perform all its functions, or it might stop.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-com#admx-com-appmgmt-com-searchforclsid-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_com_appmgmt_com_searchforclsid_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_com_appmgmt_com_searchforclsid_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen","displayName":"Force a specific default lock screen and logon image","description":"This setting allows you to force a specific default lock screen and logon image by entering the path (location) of the image file. The same image will be used for both the lock and logon screens.\r\n\r\nThis setting lets you specify the default lock screen and logon image shown when no user is signed in, and also sets the specified image as the default for all users (it replaces the inbox default image).\r\n\r\nTo use this setting, type the fully qualified path and name of the file that stores the default lock screen and logon image. You can type a local path, such as C:\\Windows\\Web\\Screen\\img104.jpg or a UNC path, such as \\\\Server\\Share\\Corp.jpg.\r\n\r\nThis can be used in conjunction with the \"Prevent changing lock screen and logon image\" setting to always force the specified lock screen and logon image to be shown.\r\n\r\nNote: This setting only applies to Enterprise, Education, and Server SKUs.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-forcedefaultlockscreen"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_lockscreenimage","displayName":"Path to lock screen image:","description":null,"helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_lockscreenoverlaysdisabled","displayName":"Turn off fun facts, tips, tricks, and more on lock screen","description":null,"helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_lockscreenoverlaysdisabled_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_lockscreenoverlaysdisabled_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nochanginglockscreen","displayName":"Prevent changing lock screen and logon image","description":"Prevents users from changing the background image shown when the machine is locked or when on the logon screen.\r\n\r\nBy default, users can change the background image shown when the machine is locked or displaying the logon screen.\r\n\r\nIf you enable this setting, the user will not be able to change their lock screen and logon image, and they will instead see the default image.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-nochanginglockscreen"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nochanginglockscreen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nochanginglockscreen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nochangingstartmenubackground","displayName":"Prevent changing start menu background","description":"Prevents users from changing the look of their start menu background, such as its color or accent.\r\n\r\nBy default, users can change the look of their start menu background, such as its color or accent.\r\n\r\nIf you enable this setting, the user will be assigned the default start menu background and colors and will not be allowed to change them.\r\n\r\nIf the \"Force a specific background and accent color\" policy is also set on a supported version of Windows, then those colors take precedence over this policy.\r\n\r\nIf the \"Force a specific Start background\" policy is also set on a supported version of Windows, then that background takes precedence over this policy.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-nochangingstartmenubackground"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nochangingstartmenubackground_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nochangingstartmenubackground_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nolockscreen","displayName":"Do not display the lock screen","description":"This policy setting controls whether the lock screen appears for users.\r\n\r\nIf you enable this policy setting, users that are not required to press CTRL + ALT + DEL before signing in will see their selected tile after locking their PC.\r\n\r\nIf you disable or do not configure this policy setting, users that are not required to press CTRL + ALT + DEL before signing in will see a lock screen after locking their PC. They must dismiss the lock screen using touch, the keyboard, or by dragging it with the mouse.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-nolockscreen"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nolockscreen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nolockscreen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_personalcolors","displayName":"Force a specific background and accent color","description":"Forces Windows to use the specified colors for the background and accent. The color values are specified in hex as #RGB.\r\n\r\nBy default, users can change the background and accent colors.\r\n\r\nIf this setting is enabled, the background and accent colors of Windows will be set to the specified colors and users cannot change those colors. This setting will not be applied if the specified colors do not meet a contrast ratio of 2:1 with white text.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-personalcolors"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_personalcolors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_personalcolors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_personalcolors_personalcolors_accent","displayName":"Accent color:","description":null,"helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_personalcolors_personalcolors_background","displayName":"Start background color:","description":null,"helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme","displayName":"Load a specific theme","description":"Specifies which theme file is applied to the computer the first time a user logs on.\n\nIf you enable this setting, the theme that you specify will be applied when a new user logs on for the first time. This policy does not prevent the user from changing the theme or any of the theme elements such as the desktop background, color, sounds, or screen saver after the first logon.\n\nIf you disable or do not configure this setting, the default theme will be applied at the first logon.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-settheme"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_themefilename","displayName":"Path to theme file:","description":"","helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_startbackground","displayName":"Force a specific Start background","description":"Forces the Start screen to use one of the available backgrounds, 1 through 20, and prevents the user from changing it.\r\n\r\nIf this setting is set to zero or not configured, then Start uses the default background, and users can change it.\r\n\r\nIf this setting is set to a nonzero value, then Start uses the specified background, and users cannot change it. If the specified background is not supported, the default background is used.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-startbackground"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_startbackground_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_startbackground_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_startbackground_startbackgroundspin","displayName":"Background ID:","description":null,"helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":null},{"id":"device_vendor_msft_policy_config_admx_cpls_usedefaulttile","displayName":"Apply the default account picture to all users","description":"This policy setting allows an administrator to standardize the account pictures for all users on a system to the default account picture. One application for this policy setting is to standardize the account pictures to a company logo.\r\n\r\nNote: The default account picture is stored at %PROGRAMDATA%\\Microsoft\\User Account Pictures\\user.jpg. The default guest picture is stored at %PROGRAMDATA%\\Microsoft\\User Account Pictures\\guest.jpg. If the default pictures do not exist, an empty frame is displayed.\r\n\r\nIf you enable this policy setting, the default user account picture will display for all users on the system with no customization allowed.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to customize their account pictures.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-cpls#admx-cpls-usedefaulttile"],"categoryId":"6b87c5da-cfd9-44bc-be05-ed08eb2144c7","categoryName":"User Accounts","options":[{"id":"device_vendor_msft_policy_config_admx_cpls_usedefaulttile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_cpls_usedefaulttile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_allowdomaindelaylock","displayName":"Allow users to select when a password is required when resuming from connected standby","description":"This policy setting allows you to control whether a user can change the time before a password is required when a Connected Standby device screen turns off.\r\n\r\nIf you enable this policy setting, a user on a Connected Standby device can change the amount of time after the device's screen turns off before a password is required when waking the device. The time is limited by any EAS settings or Group Policies that affect the maximum idle time before a device locks. Additionally, if a password is required when a screensaver turns on, the screensaver timeout will limit the options the user may choose.\r\n\r\nIf you disable this policy setting, a user cannot change the amount of time after the device's screen turns off before a password is required when waking the device. Instead, a password is required immediately after the screen turns off.\r\n\r\nIf you don't configure this policy setting on a domain-joined device, a user cannot change the amount of time after the device's screen turns off before a password is required when waking the device. Instead, a password is required immediately after the screen turns off.\r\n\r\nIf you don't configure this policy setting on a workgroup device, a user on a Connected Standby device can change the amount of time after the device's screen turns off before a password is required when waking the device. The time is limited by any EAS settings or Group Policies that affect the maximum idle time before a device locks. Additionally, if a password is required when a screensaver turns on, the screensaver timeout will limit the options the user may choose.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credentialproviders#admx-credentialproviders-allowdomaindelaylock"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_credentialproviders_allowdomaindelaylock_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_allowdomaindelaylock_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider","displayName":"Assign a default credential provider","description":"This policy setting allows the administrator to assign a specified credential provider as the default credential provider.\r\n\r\nIf you enable this policy setting, the specified credential provider is selected on other user tile.\r\n\r\nIf you disable or do not configure this policy setting, the system picks the default credential provider on other user tile.\r\n\r\nNote: A list of registered credential providers and their GUIDs can be found in the registry at HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Authentication\\Credential Providers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credentialproviders#admx-credentialproviders-defaultcredentialprovider"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider_defaultcredentialprovider_message","displayName":"Assign the following credential provider as the default credential provider:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_excludedcredentialproviders","displayName":"Exclude credential providers","description":"This policy setting allows the administrator to exclude the specified\r\ncredential providers from use during authentication.\r\n\r\nNote: credential providers are used to process and validate user\r\ncredentials during logon or when authentication is required.\r\nWindows Vista provides two default credential providers:\r\nPassword and Smart Card. An administrator can install additional\r\ncredential providers for different sets of credentials\r\n(for example, to support biometric authentication).\r\n\r\nIf you enable this policy, an administrator can specify the CLSIDs\r\nof the credential providers to exclude from the set of installed\r\ncredential providers available for authentication purposes.\r\n\r\nIf you disable or do not configure this policy, all installed and otherwise enabled credential providers are available for authentication purposes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credentialproviders#admx-credentialproviders-excludedcredentialproviders"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_credentialproviders_excludedcredentialproviders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_excludedcredentialproviders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_excludedcredentialproviders_excludedcredentialproviders_message","displayName":"Exclude the following credential providers:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials","displayName":"Allow delegating default credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved by using a trusted X509 certificate or Kerberos.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's default credentials can be delegated (default credentials are those that you use when first logging on to Windows).\r\n\r\nThe policy becomes effective the next time the user signs on to a computer running Windows.\r\n\r\nIf you disable or do not configure (by default) this policy setting, delegation of default credentials is not permitted to any computer. Applications depending upon this delegation behavior might fail authentication. For more information, see KB.\r\n\r\nFWlink for KB:\r\nhttp://go.microsoft.com/fwlink/?LinkId=301508\r\n\r\nNote: The \"Allow delegating default credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowdefaultcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials_allowdefaultcredentials_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials_concatenatedefaults_adc","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials_concatenatedefaults_adc_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefaultcredentials_concatenatedefaults_adc_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly","displayName":"Allow delegating default credentials with NTLM-only server authentication","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via NTLM.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's default credentials can be delegated (default credentials are those that you use when first logging on to Windows).\r\n\r\nIf you disable or do not configure (by default) this policy setting, delegation of default credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating default credentials with NTLM-only server authentication\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowdefcredentialswhenntlmonly"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_allowdefcredentialswhenntlmonly_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_concatenatedefaults_adcn","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_concatenatedefaults_adcn_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_concatenatedefaults_adcn_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle","displayName":"Encryption Oracle Remediation","description":"Encryption Oracle Remediation\r\n\r\nThis policy setting applies to applications using the CredSSP component (for example: Remote Desktop Connection).\r\n\r\nSome versions of the CredSSP protocol are vulnerable to an encryption oracle attack against the client. This policy controls compatibility with vulnerable clients and servers. This policy allows you to set the level of protection desired for the encryption oracle vulnerability.\r\n\r\nIf you enable this policy setting, CredSSP version support will be selected based on the following options:\r\n\r\nForce Updated Clients: Client applications which use CredSSP will not be able to fall back to the insecure versions and services using CredSSP will not accept unpatched clients. Note: this setting should not be deployed until all remote hosts support the newest version.\r\n\r\nMitigated: Client applications which use CredSSP will not be able to fall back to the insecure version but services using CredSSP will accept unpatched clients. See the link below for important information about the risk posed by remaining unpatched clients.\r\n\r\nVulnerable: Client applications which use CredSSP will expose the remote servers to attacks by supporting fall back to the insecure versions and services using CredSSP will accept unpatched clients.\r\n\r\nFor more information about the vulnerability and servicing requirements for protection, see https://go.microsoft.com/fwlink/?linkid=866660\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowencryptionoracle"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle_allowencryptionoracledrop","displayName":"Protection Level:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle_allowencryptionoracledrop_0","displayName":"Force Updated Clients","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle_allowencryptionoracledrop_1","displayName":"Mitigated","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowencryptionoracle_allowencryptionoracledrop_2","displayName":"Vulnerable","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials","displayName":"Allow delegating fresh credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via a trusted X509 certificate or Kerberos.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's fresh credentials can be delegated (fresh credentials are those that you are prompted for when executing the application).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of fresh credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*).\r\n\r\nIf you disable this policy setting, delegation of fresh credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating fresh credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com\r\nRemote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowfreshcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_allowfreshcredentials_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_concatenatedefaults_afc","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_concatenatedefaults_afc_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_concatenatedefaults_afc_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly","displayName":"Allow delegating fresh credentials with NTLM-only server authentication","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via NTLM.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's fresh credentials can be delegated (fresh credentials are those that you are prompted for when executing the application).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of fresh credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*).\r\n\r\nIf you disable this policy setting, delegation of fresh credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating fresh credentials with NTLM-only server authentication\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowfreshcredentialswhenntlmonly"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_allowfreshcredentialswhenntlmonly_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_concatenatedefaults_afcn","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_concatenatedefaults_afcn_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_concatenatedefaults_afcn_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials","displayName":"Allow delegating saved credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via a trusted X509 certificate or Kerberos.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's saved credentials can be delegated (saved credentials are those that you elect to save/remember using the Windows credential manager).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of saved credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*).\r\n\r\nIf you disable this policy setting, delegation of saved credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating saved credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowsavedcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_allowsavedcredentials_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_concatenatedefaults_asc","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_concatenatedefaults_asc_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_concatenatedefaults_asc_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly","displayName":"Allow delegating saved credentials with NTLM-only server authentication","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via NTLM.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's saved credentials can be delegated (saved credentials are those that you elect to save/remember using the Windows credential manager).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of saved credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*) if the client machine is not a member of any domain. If the client is domain-joined, by default the delegation of saved credentials is not permitted to any machine.\r\n\r\nIf you disable this policy setting, delegation of saved credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating saved credentials with NTLM-only server authentication\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowsavedcredentialswhenntlmonly"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_allowsavedcredentialswhenntlmonly_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_concatenatedefaults_ascn","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_concatenatedefaults_ascn_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_concatenatedefaults_ascn_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials","displayName":"Deny delegating default credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's default credentials cannot be delegated (default credentials are those that you use when first logging on to Windows).\r\n\r\nIf you disable or do not configure (by default) this policy setting, this policy setting does not specify any server.\r\n\r\nNote: The \"Deny delegating default credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials cannot be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n\r\nThis policy setting can be used in combination with the \"Allow delegating default credentials\" policy setting to define exceptions for specific servers that are otherwise permitted when using wildcard characters in the \"Allow delegating default credentials\" server list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-denydefaultcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_concatenatedefaults_ddc","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_concatenatedefaults_ddc_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_concatenatedefaults_ddc_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_denydefaultcredentials_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials","displayName":"Deny delegating fresh credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's fresh credentials cannot be delegated (fresh credentials are those that you are prompted for when executing the application).\r\n\r\nIf you disable or do not configure (by default) this policy setting, this policy setting does not specify any server.\r\n\r\nNote: The \"Deny delegating fresh credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials cannot be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n\r\nThis policy setting can be used in combination with the \"Allow delegating fresh credentials\" policy setting to define exceptions for specific servers that are otherwise permitted when using wildcard characters in the \"Allow delegating fresh credentials\" server list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-denyfreshcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials_concatenatedefaults_dfc","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials_concatenatedefaults_dfc_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials_concatenatedefaults_dfc_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denyfreshcredentials_denyfreshcredentials_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials","displayName":"Deny delegating saved credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's saved credentials cannot be delegated (saved credentials are those that you elect to save/remember using the Windows credential manager).\r\n\r\nIf you disable or do not configure (by default) this policy setting, this policy setting does not specify any server.\r\n\r\nNote: The \"Deny delegating saved credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials cannot be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n\r\nThis policy setting can be used in combination with the \"Allow delegating saved credentials\" policy setting to define exceptions for specific servers that are otherwise permitted when using wildcard characters in the \"Allow delegating saved credentials\" server list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-denysavedcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials_concatenatedefaults_dsc","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials_concatenatedefaults_dsc_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials_concatenatedefaults_dsc_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_denysavedcredentials_denysavedcredentials_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration","displayName":"Restrict delegation of credentials to remote servers","description":"When running in Restricted Admin or Remote Credential Guard mode, participating apps do not expose signed in or supplied credentials to a remote host. Restricted Admin limits access to resources located on other servers or networks from the remote host because credentials are not delegated. Remote Credential Guard does not limit access to resources because it redirects all requests back to the client device.\r\n\r\nParticipating apps:\r\nRemote Desktop Client\r\n\r\nIf you enable this policy setting, the following options are supported:\r\n \r\nRestrict credential delegation: Participating applications must use Restricted Admin or Remote Credential Guard to connect to remote hosts.\r\n \r\nRequire Remote Credential Guard: Participating applications must use Remote Credential Guard to connect to remote hosts.\r\n \r\nRequire Restricted Admin: Participating applications must use Restricted Admin to connect to remote hosts.\r\n\r\nIf you disable or do not configure this policy setting, Restricted Admin and Remote Credential Guard mode are not enforced and participating apps can delegate credentials to remote devices.\r\n\r\nNote: To disable most credential delegation, it may be sufficient to deny delegation in Credential Security Support Provider (CredSSP) by modifying Administrative template settings (located at Computer Configuration\\Administrative Templates\\System\\Credentials Delegation).\r\n\r\nNote: On Windows 8.1 and Windows Server 2012 R2, enabling this policy will enforce Restricted Administration mode, regardless of the mode chosen. These versions do not support Remote Credential Guard.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-restrictedremoteadministration"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop","displayName":"Use the following restricted mode:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop_3","displayName":"Restrict Credential Delegation","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop_2","displayName":"Require Remote Credential Guard","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop_1","displayName":"Require Restricted Admin","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credui_enablesecurecredentialprompting","displayName":"Require trusted path for credential entry","description":"This policy setting requires the user to enter Microsoft Windows credentials using a trusted path, to prevent a Trojan horse or other types of malicious code from stealing the user’s Windows credentials.\r\n\r\nNote: This policy affects nonlogon authentication tasks only. As a security best practice, this policy should be enabled.\r\n\r\nIf you enable this policy setting, users will be required to enter Windows credentials on the Secure Desktop by means of the trusted path mechanism.\r\n\r\nIf you disable or do not configure this policy setting, users will enter Windows credentials within the user’s desktop session, potentially allowing malicious code access to the user’s Windows credentials.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credui#admx-credui-enablesecurecredentialprompting"],"categoryId":"58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","categoryName":"Credential User Interface","options":[{"id":"device_vendor_msft_policy_config_admx_credui_enablesecurecredentialprompting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credui_enablesecurecredentialprompting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_credui_nolocalpasswordresetquestions","displayName":"Prevent the use of security questions for local accounts","description":"If you turn this policy setting on, local users won’t be able to set up and use security questions to reset their passwords.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credui#admx-credui-nolocalpasswordresetquestions"],"categoryId":"58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","categoryName":"Credential User Interface","options":[{"id":"device_vendor_msft_policy_config_admx_credui_nolocalpasswordresetquestions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credui_nolocalpasswordresetquestions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_datacollection_commercialidpolicy","displayName":"Configure the Commercial ID","description":"This policy setting defines the identifier used to uniquely associate this device’s telemetry data as belonging to a given organization. If your organization is participating in a program that requires this device to be identified as belonging to your organization then use this setting to provide that identification. The value for this setting will be provided by Microsoft as part of the onboarding process for the program. \r\n\r\nIf you disable or do not configure this policy setting, then Microsoft will not be able to use this identifier to associate this machine and its telemetry data with your organization.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-datacollection#admx-datacollection-commercialidpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_datacollection_commercialidpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_datacollection_commercialidpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_datacollection_commercialidpolicy_commercialidvalue","displayName":"Commercial Id:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckallowlocallist","displayName":"Allow local activation security check exemptions","description":"Allows you to specify that local computer administrators can supplement the \"Define Activation Security Check exemptions\" list.\r\n\r\nIf you enable this policy setting, and DCOM does not find an explicit entry for a DCOM server application id (appid) in the \"Define Activation Security Check exemptions\" policy (if enabled), DCOM will look for an entry in the locally configured list.\r\n\r\nIf you disable this policy setting, DCOM will not look in the locally configured DCOM activation security check exemption list.\r\n\r\nIf you do not configure this policy setting, DCOM will only look in the locally configured exemption list if the \"Define Activation Security Check exemptions\" policy is not configured.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dcom#admx-dcom-dcomactivationsecuritycheckallowlocallist"],"categoryId":"a57b27b6-48e0-42b2-812a-2be86c113a0c","categoryName":"Application Compatibility Settings","options":[{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckallowlocallist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckallowlocallist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckexemptionlist","displayName":"Define Activation Security Check exemptions","description":"Allows you to view and change a list of DCOM server application ids (appids) which are exempted from the DCOM Activation security check. DCOM uses two such lists, one configured via Group Policy through this policy setting, and the other via the actions of local computer administrators. DCOM ignores the second list when this policy setting is configured, unless the \"Allow local activation security check exemptions\" policy is enabled.\r\n\r\nDCOM server appids added to this policy must be listed in curly-brace format. For example: {b5dcb061-cefb-42e0-a1be-e6a6438133fe}. If you enter a non-existent or improperly formatted appid DCOM will add it to the list without checking for errors.\r\n\r\nIf you enable this policy setting, you can view and change the list of DCOM activation security check exemptions defined by Group Policy settings. If you add an appid to this list and set its value to 1, DCOM will not enforce the Activation security check for that DCOM server. If you add an appid to this list and set its value to 0 DCOM will always enforce the Activation security check for that DCOM server regardless of local settings.\r\n\r\nIf you disable this policy setting, the appid exemption list defined by Group Policy is deleted, and the one defined by local computer administrators is used.\r\n\r\nIf you do not configure this policy setting, the appid exemption list defined by local computer administrators is used.\r\n\r\nNotes:\r\n\r\nThe DCOM Activation security check is done after a DCOM server process is started, but before an object activation request is dispatched to the server process. This access check is done against the DCOM server's custom launch permission security descriptor if it exists, or otherwise against the configured defaults.\r\n\r\nIf the DCOM server's custom launch permission contains explicit DENY entries this may mean that object activations that would have previously succeeded for such specified users, once the DCOM server process was up and running, might now fail instead. The proper action in this situation is to re-configure the DCOM server's custom launch permission settings for correct security settings, but this policy setting may be used in the short-term as an application compatibility deployment aid.\r\n\r\nDCOM servers added to this exemption list are only exempted if their custom launch permissions do not contain specific LocalLaunch, RemoteLaunch, LocalActivate, or RemoteActivate grant or deny entries for any users or groups. Also note, exemptions for DCOM Server Appids added to this list will apply to both 32-bit and 64-bit versions of the server if present.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dcom#admx-dcom-dcomactivationsecuritycheckexemptionlist"],"categoryId":"a57b27b6-48e0-42b2-812a-2be86c113a0c","categoryName":"Application Compatibility Settings","options":[{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckexemptionlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckexemptionlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckexemptionlist_dcom_lbl_actseccheckexemptionlist","displayName":"Add\\remove DCOM servers to the exemption list:","description":null,"helpText":"","infoUrls":[],"categoryId":"a57b27b6-48e0-42b2-812a-2be86c113a0c","categoryName":"Application Compatibility Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckexemptionlist_dcom_lbl_actseccheckexemptionlist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"a57b27b6-48e0-42b2-812a-2be86c113a0c","categoryName":"Application Compatibility Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckexemptionlist_dcom_lbl_actseccheckexemptionlist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"a57b27b6-48e0-42b2-812a-2be86c113a0c","categoryName":"Application Compatibility Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_desktop_nodesktop","displayName":"Hide and disable all items on the desktop","description":"Removes icons, shortcuts, and other default and user-defined items from the desktop, including Briefcase, Recycle Bin, Computer, and Network Locations.\n\nRemoving icons and shortcuts does not prevent the user from using another method to start the programs or opening the items they represent.\n\nAlso, see \"Items displayed in Places Bar\" in User Configuration\\Administrative Templates\\Windows Components\\Common Open File Dialog to remove the Desktop icon from the Places Bar. This will help prevent users from saving data to the Desktop.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-nodesktop"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_desktop_nodesktop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_desktop_nodesktop_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_devicecompat_deviceflags","displayName":"Device compatibility settings","description":"Changes behavior of Microsoft bus drivers to work with specific devices.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-devicecompat#admx-devicecompat-deviceflags"],"categoryId":"27087ae6-d02f-4b54-a143-6cde89c04989","categoryName":"Device and Driver Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_devicecompat_deviceflags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicecompat_deviceflags_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_devicecompat_drivershims","displayName":"Driver compatibility settings","description":"Changes behavior of 3rd-party drivers to work around incompatibilities introduced between OS versions.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-devicecompat#admx-devicecompat-drivershims"],"categoryId":"27087ae6-d02f-4b54-a143-6cde89c04989","categoryName":"Device and Driver Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_devicecompat_drivershims_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicecompat_drivershims_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceguard_configcipolicy","displayName":"Deploy App Control for Business","description":"Deploy Windows Defender Application Control\r\n\r\nThis policy setting lets you deploy a Code Integrity Policy to a machine to control what is allowed to run on that machine.\r\n\r\nIf you deploy a Code Integrity Policy, Windows will restrict what can run in both kernel mode and on the Windows Desktop based on the policy. To enable this policy the machine must be rebooted. \r\n\r\nThe file path must be either a UNC path (for example, \\\\ServerName\\ShareName\\SIPolicy.p7b), or a locally valid path (for example, C:\\FolderName\\SIPolicy.p7b). The local machine account (LOCAL SYSTEM) must have access permission to the policy file.\r\n \r\nIf using a signed and protected policy then disabling this policy setting doesn't remove the feature from the computer. Instead, you must either:\r\n\r\n 1) first update the policy to a non-protected policy and then disable the setting, or\r\n 2) disable the setting and then remove the policy from each computer, with a physically present user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceguard#admx-deviceguard-configcipolicy"],"categoryId":"909339a5-8f04-4fa2-8807-5d38c83ef547","categoryName":"Device Guard","options":[{"id":"device_vendor_msft_policy_config_admx_deviceguard_configcipolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceguard_configcipolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceguard_configcipolicy_configcipolicyfilepathtext","displayName":"Code Integrity Policy file path:","description":null,"helpText":"","infoUrls":[],"categoryId":"909339a5-8f04-4fa2-8807-5d38c83ef547","categoryName":"Device Guard","options":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_allowadmininstall","displayName":"Allow administrators to override Device Installation Restriction policies","description":"This policy setting allows you to determine whether members of the Administrators group can install and update the drivers for any device, regardless of other policy settings.\r\n\r\nIf you enable this policy setting, members of the Administrators group can use the Add Hardware wizard or the Update Driver wizard to install and update the drivers for any device. If you enable this policy setting on a remote desktop server, the policy setting affects redirection of the specified devices from a remote desktop client to the remote desktop server.\r\n\r\nIf you disable or do not configure this policy setting, members of the Administrators group are subject to all policy settings that restrict device installation.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-allowadmininstall"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_allowadmininstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_allowadmininstall_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext","displayName":"Display a custom message when installation is prevented by a policy setting","description":"This policy setting allows you to display a custom message to users in a notification when a device installation is attempted and a policy setting prevents the installation.\r\n\r\nIf you enable this policy setting, Windows displays the text you type in the Detail Text box when a policy setting prevents device installation.\r\n\r\nIf you disable or do not configure this policy setting, Windows displays a default message when a policy setting prevents device installation.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-deniedpolicy-detailtext"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext_deviceinstall_deniedpolicy_detailtext_text","displayName":"Detail Text","description":null,"helpText":"","infoUrls":[],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext","displayName":"Display a custom message title when device installation is prevented by a policy setting","description":"This policy setting allows you to display a custom message title in a notification when a device installation is attempted and a policy setting prevents the installation.\r\n\r\nIf you enable this policy setting, Windows displays the text you type in the Main Text box as the title text of a notification when a policy setting prevents device installation.\r\n\r\nIf you disable or do not configure this policy setting, Windows displays a default title in a notification when a policy setting prevents device installation.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-deniedpolicy-simpletext"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext_deviceinstall_deniedpolicy_simpletext_text","displayName":"Main Text","description":null,"helpText":"","infoUrls":[],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_installtimeout","displayName":"Configure device installation time-out","description":"This policy setting allows you to configure the number of seconds Windows waits for a device installation task to complete. \r\n\r\nIf you enable this policy setting, Windows waits for the number of seconds you specify before terminating the installation.\r\n\r\nIf you disable or do not configure this policy setting, Windows waits 240 seconds for a device installation task to complete before terminating the installation.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-installtimeout"],"categoryId":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","categoryName":"Device Installation","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_installtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_installtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_installtimeout_deviceinstall_installtimeout_time","displayName":"Device Installation Timeout (in seconds)","description":null,"helpText":"","infoUrls":[],"categoryId":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","categoryName":"Device Installation","options":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime","displayName":"Time (in seconds) to force reboot when required for policy changes to take effect","description":"This policy setting establishes the amount of time (in seconds) that the system will wait to reboot in order to enforce a change in device installation restriction policies.\r\n\r\nIf you enable this policy setting, set the amount of seconds you want the system to wait until a reboot.\r\n\r\nIf you disable or do not configure this policy setting, the system does not force a reboot.\r\n\r\nNote: If no reboot is forced, the device installation restriction right will not take effect until the system is restarted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-policy-reboottime"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime_deviceinstall_policy_reboottime_time","displayName":"Reboot Timeout (in seconds)","description":null,"helpText":"","infoUrls":[],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_removable_deny","displayName":"Prevent installation of removable devices","description":"This policy setting allows you to prevent Windows from installing removable devices. A device is considered removable when the driver for the device to which it is connected indicates that the device is removable. For example, a Universal Serial Bus (USB) device is reported to be removable by the drivers for the USB hub to which the device is connected. This policy setting takes precedence over any other policy setting that allows Windows to install a device.\r\n\r\nIf you enable this policy setting, Windows is prevented from installing removable devices and existing removable devices cannot have their drivers updated. If you enable this policy setting on a remote desktop server, the policy setting affects redirection of removable devices from a remote desktop client to the remote desktop server.\r\n\r\nIf you disable or do not configure this policy setting, Windows can install and update device drivers for removable devices as allowed or prevented by other policy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-removable-deny"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_removable_deny_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_removable_deny_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_systemrestore","displayName":"Prevent creation of a system restore point during device activity that would normally prompt creation of a restore point","description":"This policy setting allows you to prevent Windows from creating a system restore point during device activity that would normally prompt Windows to create a system restore point. Windows normally creates restore points for certain driver activity, such as the installation of an unsigned driver. A system restore point enables you to more easily restore your system to its state before the activity. \r\n\r\nIf you enable this policy setting, Windows does not create a system restore point when one would normally be created.\r\n\r\nIf you disable or do not configure this policy setting, Windows creates a system restore point as it normally would.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-systemrestore"],"categoryId":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","categoryName":"Device Installation","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_systemrestore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_systemrestore_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser","displayName":"Allow non-administrators to install drivers for these device setup classes","description":"This policy setting specifies a list of device setup class GUIDs describing driver packages that non-administrator members of the built-in Users group may install on the system.\n\nIf you enable this policy setting, members of the Users group may install new drivers for the specified device setup classes. The drivers must be signed according to Windows Driver Signing Policy, or be signed by publishers already in the TrustedPublisher store.\n\nIf you disable or do not configure this policy setting, only members of the Administrators group are allowed to install new driver packages on the system.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-driverinstall-classes-allowuser"],"categoryId":"1943deba-33f7-4c3d-98c8-6b5319ec98ab","categoryName":"Driver Installation","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser_driverinstall_classes_allowuser_list","displayName":"Allow Users to install driver packages for these classes:","description":"","helpText":"","infoUrls":[],"categoryId":"1943deba-33f7-4c3d-98c8-6b5319ec98ab","categoryName":"Driver Installation","options":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_deviceinstall_balloontips","displayName":"Turn off \"Found New Hardware\" balloons during device installation","description":"This policy setting allows you to turn off \"Found New Hardware\" balloons during device installation.\r\n\r\nIf you enable this policy setting, \"Found New Hardware\" balloons do not appear while a device is being installed.\r\n\r\nIf you disable or do not configure this policy setting, \"Found New Hardware\" balloons appear while a device is being installed, unless the driver for the device suppresses the balloons.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-devicesetup#admx-devicesetup-deviceinstall-balloontips"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_devicesetup_deviceinstall_balloontips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_deviceinstall_balloontips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration","displayName":"Specify search order for device driver source locations","description":"This policy setting allows you to specify the order in which Windows searches source locations for device drivers. \r\n\r\nIf you enable this policy setting, you can select whether Windows searches for drivers on Windows Update unconditionally, only if necessary, or not at all.\r\n\r\nNote that searching always implies that Windows will attempt to search Windows Update exactly one time. With this setting, Windows will not continually search for updates. This setting is used to ensure that the best software will be found for the device, even if the network is temporarily available.\r\n\r\nIf the setting for searching only if needed is specified, then Windows will search for a driver only if a driver is not locally available on the system.\r\n\r\nIf you disable or do not configure this policy setting, members of the Administrators group can determine the priority order in which Windows searches source locations for device drivers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-devicesetup#admx-devicesetup-driversearchplaces-searchorderconfiguration"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown","displayName":"Select search order:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown_1","displayName":"Always search Windows Update","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown_2","displayName":"Search Windows Update only if needed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown_0","displayName":"Do not search Windows Update","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dfs_dfsdiscoverdc","displayName":"Configure how often a DFS client discovers domain controllers","description":"This policy setting allows you to configure how often a Distributed File System (DFS) client attempts to discover domain controllers on a network. By default, a DFS client attempts to discover domain controllers every 15 minutes.\r\n\r\nIf you enable this policy setting, you can configure how often a DFS client attempts to discover domain controllers. This value is specified in minutes.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 15 minutes applies.\r\n\r\nNote: The minimum value you can select is 15 minutes. If you try to set this setting to a value less than 15 minutes, the default value of 15 minutes is applied.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dfs#admx-dfs-dfsdiscoverdc"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_dfs_dfsdiscoverdc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dfs_dfsdiscoverdc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dfs_dfsdiscoverdc_dfsdiscoverdialog","displayName":"Time in minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_digitallocker_digitalx_diableapplication_titletext_2","displayName":"Do not allow Digital Locker to run","description":"Specifies whether Digital Locker can run.\r\n\r\nDigital Locker is a dedicated download manager associated with Windows Marketplace and a feature of Windows that can be used to manage and download products acquired and stored in the user's Windows Marketplace Digital Locker.\r\n\r\nIf you enable this setting, Digital Locker will not run.\r\n\r\nIf you disable or do not configure this setting, Digital Locker can be run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-digitallocker#admx-digitallocker-digitalx-diableapplication-titletext-2"],"categoryId":"1dabc7da-bdf8-4c60-95de-427a4b2cb6bf","categoryName":"Digital Locker","options":[{"id":"device_vendor_msft_policy_config_admx_digitallocker_digitalx_diableapplication_titletext_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_digitallocker_digitalx_diableapplication_titletext_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy","displayName":"Disk Diagnostic: Configure custom alert text","description":"This policy setting substitutes custom alert text in the disk diagnostic message shown to users when a disk reports a S.M.A.R.T. fault. \r\n\r\nIf you enable this policy setting, Windows displays custom alert text in the disk diagnostic message. The custom text may not exceed 512 characters. \r\n\r\nIf you disable or do not configure this policy setting, Windows displays the default alert text in the disk diagnostic message. \r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately. \r\n\r\nThis policy setting only takes effect if the Disk Diagnostic scenario policy setting is enabled or not configured and the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console. \r\n\r\nNote: For Windows Server systems, this policy setting applies only if the Desktop Experience optional component is installed and the Remote Desktop Services role is not installed. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskdiagnostic#admx-diskdiagnostic-dfdalertpolicy"],"categoryId":"e3ca94a7-e506-4133-8fae-41931dc863a5","categoryName":"Disk Diagnostic","options":[{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy_dfdalertpolicytitle","displayName":"Custom alert text","description":null,"helpText":"","infoUrls":[],"categoryId":"e3ca94a7-e506-4133-8fae-41931dc863a5","categoryName":"Disk Diagnostic","options":null},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_wdiscenarioexecutionpolicy","displayName":"Disk Diagnostic: Configure execution level","description":"This policy setting determines the execution level for S.M.A.R.T.-based disk diagnostics. \r\n\r\nSelf-Monitoring And Reporting Technology (S.M.A.R.T.) is a standard mechanism for storage devices to report faults to Windows. A disk that reports a S.M.A.R.T. fault may need to be repaired or replaced. The Diagnostic Policy Service (DPS) detects and logs S.M.A.R.T. faults to the event log when they occur. \r\n\r\nIf you enable this policy setting, the DPS also warns users of S.M.A.R.T. faults and guides them through backup and recovery to minimize potential data loss. \r\n\r\nIf you disable this policy, S.M.A.R.T. faults are still detected and logged, but no corrective action is taken. \r\n\r\nIf you do not configure this policy setting, the DPS enables S.M.A.R.T. fault resolution by default. \r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured. \r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately. \r\n\r\nThis policy setting takes effect only when the DPS is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console. \r\n\r\nNote: For Windows Server systems, this policy setting applies only if the Desktop Experience optional component is installed and the Remote Desktop Services role is not installed. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskdiagnostic#admx-diskdiagnostic-wdiscenarioexecutionpolicy"],"categoryId":"e3ca94a7-e506-4133-8fae-41931dc863a5","categoryName":"Disk Diagnostic","options":[{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_disknvcache_bootresumepolicy","displayName":"Turn off boot and resume optimizations","description":"This policy setting turns off the boot and resume optimizations for the hybrid hard disks in the system.\r\n\r\nIf you enable this policy setting, the system does not use the non-volatile (NV) cache to optimize boot and resume.\r\n\r\nIf you disable this policy setting, the system uses the NV cache to achieve faster boot and resume. The system determines the data that will be stored in the NV cache to optimize boot and resume. The required data is stored in the NV cache during shutdown and hibernate, respectively. This might cause a slight increase in the time taken for shutdown and hibernate.\r\n\r\nIf you do not configure this policy setting, the default behavior is observed and the NV cache is used for boot and resume optimizations.\r\n\r\nNote: This policy setting is applicable only if the NV cache feature is on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-disknvcache#admx-disknvcache-bootresumepolicy"],"categoryId":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","categoryName":"Disk NV Cache","options":[{"id":"device_vendor_msft_policy_config_admx_disknvcache_bootresumepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_disknvcache_bootresumepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_disknvcache_cachepowermodepolicy","displayName":"Turn off cache power mode","description":"This policy setting turns off power save mode on the hybrid hard disks in the system.\r\n\r\nIf you enable this policy setting, the hard disks are not put into NV cache power save mode and no power savings are achieved.\r\n\r\nIf you disable this policy setting, the hard disks are put into an NV cache power saving mode. In this mode, the system tries to save power by aggressively spinning down the disk.\r\n\r\nIf you do not configure this policy setting, the default behavior is to allow the hybrid hard disks to be in power save mode.\r\n\r\nNote: This policy setting is applicable only if the NV cache feature is on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-disknvcache#admx-disknvcache-cachepowermodepolicy"],"categoryId":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","categoryName":"Disk NV Cache","options":[{"id":"device_vendor_msft_policy_config_admx_disknvcache_cachepowermodepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_disknvcache_cachepowermodepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_disknvcache_featureoffpolicy","displayName":"Turn off non-volatile cache feature","description":"This policy setting turns off all support for the non-volatile (NV) cache on all hybrid hard disks in the system. To check if you have hybrid hard disks in the system, from Device Manager, right-click the disk drive and select Properties. The NV cache can be used to optimize boot and resume by reading data from the cache while the disks are spinning up. The NV cache can also be used to reduce the power consumption of the system by keeping the disks spun down while satisfying reads and writes from the cache.\r\n\r\nIf you enable this policy setting, the system will not manage the NV cache and will not enable NV cache power saving mode.\r\n\r\nIf you disable this policy setting, the system will manage the NV cache on the disks if the other policy settings for the NV cache are appropriately configured.\r\n\r\nNote: This policy setting will take effect on next boot.\r\n\r\nIf you do not configure this policy setting, the default behavior is to turn on support for the NV cache.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-disknvcache#admx-disknvcache-featureoffpolicy"],"categoryId":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","categoryName":"Disk NV Cache","options":[{"id":"device_vendor_msft_policy_config_admx_disknvcache_featureoffpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_disknvcache_featureoffpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_disknvcache_solidstatepolicy","displayName":"Turn off solid state mode","description":"This policy setting turns off the solid state mode for the hybrid hard disks. \r\n\r\nIf you enable this policy setting, frequently written files such as the file system metadata and registry may not be stored in the NV cache.\r\n\r\nIf you disable this policy setting, the system will store frequently written data into the non-volatile (NV) cache. This allows the system to exclusively run out of the NV cache and power down the disk for longer periods to save power. Note that this can cause increased wear of the NV cache.\r\n\r\nIf you do not configure this policy setting, the default behavior of the system is observed and frequently written files will be stored in the NV cache.\r\n\r\nNote: This policy setting is applicable only if the NV cache feature is on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-disknvcache#admx-disknvcache-solidstatepolicy"],"categoryId":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","categoryName":"Disk NV Cache","options":[{"id":"device_vendor_msft_policy_config_admx_disknvcache_solidstatepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_disknvcache_solidstatepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_enable","displayName":"Enable disk quotas","description":"This policy setting turns on and turns off disk quota management on all NTFS volumes of the computer, and prevents users from changing the setting.\r\n\r\nIf you enable this policy setting, disk quota management is turned on, and users cannot turn it off.\r\n\r\nIf you disable the policy setting, disk quota management is turned off, and users cannot turn it on.\r\n\r\nIf this policy setting is not configured, disk quota management is turned off by default, but administrators can turn it on.\r\n\r\nTo prevent users from changing the setting while a setting is in effect, the system disables the \"Enable quota management\" option on the Quota tab of NTFS volumes.\r\n\r\nNote: This policy setting turns on disk quota management but does not establish or enforce a particular disk quota limit. To specify a disk quota limit, use the \"Default quota limit and warning level\" policy setting. Otherwise, the system uses the physical space on the volume as the quota limit.\r\n\r\nNote: To turn on or turn off disk quota management without specifying a setting, in My Computer, right-click the name of an NTFS volume, click Properties, click the Quota tab, and then click \"Enable quota management.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskquota#admx-diskquota-dq-enable"],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_enable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_enable_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_enforce","displayName":"Enforce disk quota limit","description":"This policy setting determines whether disk quota limits are enforced and prevents users from changing the setting.\r\n\r\nIf you enable this policy setting, disk quota limits are enforced. If you disable this policy setting, disk quota limits are not enforced. When you enable or disable this policy setting, the system disables the \"Deny disk space to users exceeding quota limit\" option on the Quota tab so administrators cannot make changes while the setting is in effect.\r\n\r\nIf you do not configure this policy setting, the disk quota limit is not enforced by default, but administrators can change the setting.\r\n\r\nEnforcement is optional. When users reach an enforced disk quota limit, the system responds as though the physical space on the volume were exhausted. When users reach an unenforced limit, their status in the Quota Entries window changes, but they can continue to write to the volume as long as physical space is available.\r\n\r\nNote: This policy setting overrides user settings that enable or disable quota enforcement on their volumes.\r\n\r\nNote: To specify a disk quota limit, use the \"Default quota limit and warning level\" policy setting. Otherwise, the system uses the physical space on the volume as the quota limit.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskquota#admx-diskquota-dq-enforce"],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_enforce_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_enforce_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit","displayName":"Specify default quota limit and warning level","description":"This policy setting specifies the default disk quota limit and warning level for new users of the volume.\r\n\r\nThis policy setting determines how much disk space can be used by each user on each of the NTFS file system volumes on a computer. It also specifies the warning level, the point at which the user's status in the Quota Entries window changes to indicate that the user is approaching the disk quota limit.\r\n\r\nThis setting overrides new users’ settings for the disk quota limit and warning level on their volumes, and it disables the corresponding options in the \"Select the default quota limit for new users of this volume\" section on the Quota tab.\r\n\r\nThis policy setting applies to all new users as soon as they write to the volume. It does not affect disk quota limits for current users, or affect customized limits and warning levels set for particular users (on the Quota tab in Volume Properties).\r\n\r\nIf you disable or do not configure this policy setting, the disk space available to users is not limited. The disk quota management feature uses the physical space on each volume as its quota limit and warning level.\r\n\r\nWhen you select a limit, remember that the same limit applies to all users on all volumes, regardless of actual volume size. Be sure to set the limit and warning level so that it is reasonable for the range of volumes in the group.\r\n\r\nThis policy setting is effective only when disk quota management is enabled on the volume. Also, if disk quotas are not enforced, users can exceed the quota limit you set. When users reach the quota limit, their status in the Quota Entries window changes, but users can continue to write to the volume.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskquota#admx-diskquota-dq-limit"],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits","displayName":"Units","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_1","displayName":"KB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_2","displayName":"MB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_3","displayName":"GB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_4","displayName":"TB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_5","displayName":"PB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_6","displayName":"EB","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitvalue","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits","displayName":"Units","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits_1","displayName":"KB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits_2","displayName":"MB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits_3","displayName":"GB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits_4","displayName":"TB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits_5","displayName":"PB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdunits_6","displayName":"EB","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdvalue","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_logeventoverlimit","displayName":"Log event when quota limit is exceeded","description":"This policy setting determines whether the system records an event in the local Application log when users reach their disk quota limit on a volume, and prevents users from changing the logging setting.\r\n\r\nIf you enable this policy setting, the system records an event when the user reaches their limit. If you disable this policy setting, no event is recorded. Also, when you enable or disable this policy setting, the system disables the \"Log event when a user exceeds their quota limit\" option on the Quota tab, so administrators cannot change the setting while a setting is in effect.\r\n\r\nIf you do not configure this policy setting, no events are recorded, but administrators can use the Quota tab option to change the setting.\r\n\r\nThis policy setting is independent of the enforcement policy settings for disk quotas. As a result, you can direct the system to log an event, regardless of whether or not you choose to enforce the disk quota limit.\r\n\r\nAlso, this policy setting does not affect the Quota Entries window on the Quota tab. Even without the logged event, users can detect that they have reached their limit, because their status in the Quota Entries window changes.\r\n\r\nNote: To find the logging option, in My Computer, right-click the name of an NTFS file system volume, click Properties, and then click the Quota tab.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskquota#admx-diskquota-dq-logeventoverlimit"],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_logeventoverlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_logeventoverlimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_logeventoverthreshold","displayName":"Log event when quota warning level is exceeded","description":"This policy setting determines whether the system records an event in the Application log when users reach their disk quota warning level on a volume.\r\n\r\nIf you enable this policy setting, the system records an event. If you disable this policy setting, no event is recorded. When you enable or disable this policy setting, the system disables the corresponding \"Log event when a user exceeds their warning level\" option on the Quota tab so that administrators cannot change logging while a policy setting is in effect.\r\n\r\nIf you do not configure this policy setting, no event is recorded, but administrators can use the Quota tab option to change the logging setting.\r\n\r\nThis policy setting does not affect the Quota Entries window on the Quota tab. Even without the logged event, users can detect that they have reached their warning level because their status in the Quota Entries window changes.\r\n\r\nNote: To find the logging option, in My Computer, right-click the name of an NTFS file system volume, click Properties, and then click the Quota tab.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskquota#admx-diskquota-dq-logeventoverthreshold"],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_logeventoverthreshold_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_logeventoverthreshold_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_removablemedia","displayName":"Apply policy to removable media","description":"This policy setting extends the disk quota policies in this folder to NTFS file system volumes on removable media.\r\n\r\nIf you disable or do not configure this policy setting, the disk quota policies established in this folder apply to fixed-media NTFS volumes only. Note: When this policy setting is applied, the computer will apply the disk quota to both fixed and removable media.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskquota#admx-diskquota-dq-removablemedia"],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_removablemedia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_removablemedia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_distributedlinktracking_dlt_allowdomainmode","displayName":"Allow Distributed Link Tracking clients to use domain resources","description":"Specifies that Distributed Link Tracking clients in this domain may use the Distributed Link Tracking (DLT) server, which runs on domain controllers. The DLT client enables programs to track linked files that are moved within an NTFS volume, to another NTFS volume on the same computer, or to an NTFS volume on another computer. The DLT client can more reliably track links when allowed to use the DLT server. This policy should not be set unless the DLT server is running on all domain controllers in the domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-distributedlinktracking#admx-distributedlinktracking-dlt-allowdomainmode"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_distributedlinktracking_dlt_allowdomainmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_distributedlinktracking_dlt_allowdomainmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_allowfqdnnetbiosqueries","displayName":"Allow NetBT queries for fully qualified domain names","description":"Specifies that NetBIOS over TCP/IP (NetBT) queries are issued for fully qualified domain names. \r\n\r\nIf you enable this policy setting, NetBT queries will be issued for multi-label and fully qualified domain names such as \"www.example.com\" in addition to single-label names. \r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, NetBT queries will only be issued for single-label names such as \"example\" and not for multi-label and fully qualified domain names.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-allowfqdnnetbiosqueries"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_allowfqdnnetbiosqueries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_allowfqdnnetbiosqueries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_appendtomultilabelname","displayName":"Allow DNS suffix appending to unqualified multi-label name queries","description":"Specifies that computers may attach suffixes to an unqualified multi-label name before sending subsequent DNS queries if the original name query fails.\r\n\r\nA name containing dots, but not dot-terminated, is called an unqualified multi-label name, for example \"server.corp\" is an unqualified multi-label name. The name \"server.corp.contoso.com.\" is an example of a fully qualified name because it contains a terminating dot.\r\n\r\nFor example, if attaching suffixes is allowed, an unqualified multi-label name query for \"server.corp\" will be queried by the DNS client first. If the query succeeds, the response is returned to the client. If the query fails, the unqualified multi-label name is appended with DNS suffixes. These suffixes can be derived from a combination of the local DNS client's primary domain suffix, a connection-specific domain suffix, and a DNS suffix search list.\r\n\r\nIf attaching suffixes is allowed, and a DNS client with a primary domain suffix of \"contoso.com\" performs a query for \"server.corp\" the DNS client will send a query for \"server.corp\" first, and then a query for \"server.corp.contoso.com.\" second if the first query fails.\r\n\r\nIf you enable this policy setting, suffixes are allowed to be appended to an unqualified multi-label name if the original name query fails.\r\n\r\nIf you disable this policy setting, no suffixes are appended to unqualified multi-label name queries if the original name query fails.\r\n\r\nIf you do not configure this policy setting, computers will use their local DNS client settings to determine the query behavior for unqualified multi-label names.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-appendtomultilabelname"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_appendtomultilabelname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_appendtomultilabelname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domain","displayName":"Connection-specific DNS suffix","description":"Specifies a connection-specific DNS suffix. This policy setting supersedes local connection-specific DNS suffixes, and those configured using DHCP.\r\n\r\nTo use this policy setting, click Enabled, and then enter a string value representing the DNS suffix.\r\n\r\nIf you enable this policy setting, the DNS suffix that you enter will be applied to all network connections used by computers that receive this policy setting.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers will use the local or DHCP supplied connection specific DNS suffix, if configured.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-domain"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domain_dns_domainlabel","displayName":"DNS suffix:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel","displayName":"Primary DNS suffix devolution level","description":"Specifies if the devolution level that DNS clients will use if they perform primary DNS suffix devolution during the name resolution process.\r\n\r\nWith devolution, a DNS client creates queries by appending a single-label, unqualified domain name with the parent suffix of the primary DNS suffix name, and the parent of that suffix, and so on, stopping if the name is successfully resolved or at a level determined by devolution settings. Devolution can be used when a user or application submits a query for a single-label domain name.\r\n\r\nThe DNS client appends DNS suffixes to the single-label, unqualified domain name based on the state of the Append primary and connection specific DNS suffixes radio button and Append parent suffixes of the primary DNS suffix check box on the DNS tab in Advanced TCP/IP Settings for the Internet Protocol (TCP/IP) Properties dialog box.\r\n\r\nDevolution is not enabled if a global suffix search list is configured using Group Policy.\r\n\r\nIf a global suffix search list is not configured, and the Append primary and connection specific DNS suffixes radio button is selected, the DNS client appends the following names to a single-label name when it sends DNS queries:\r\n\r\nThe primary DNS suffix, as specified on the Computer Name tab of the System control panel.\r\n\r\nEach connection-specific DNS suffix, assigned either through DHCP or specified in the DNS suffix for this connection box on the DNS tab in the Advanced TCP/IP Settings dialog box for each connection.\r\n\r\nFor example, when a user submits a query for a single-label name such as \"example,\" the DNS client attaches a suffix such as \"microsoft.com\" resulting in the query \"example.microsoft.com,\" before sending the query to a DNS server.\r\n\r\nIf a DNS suffix search list is not specified, the DNS client attaches the primary DNS suffix to a single-label name. If this query fails, the connection-specific DNS suffix is attached for a new query. If none of these queries are resolved, the client devolves the primary DNS suffix of the computer (drops the leftmost label of the primary DNS suffix), attaches this devolved primary DNS suffix to the single-label name, and submits this new query to a DNS server.\r\n\r\nFor example, if the primary DNS suffix ooo.aaa.microsoft.com is attached to the non-dot-terminated single-label name \"example,\" and the DNS query for example.ooo.aaa.microsoft.com fails, the DNS client devolves the primary DNS suffix (drops the leftmost label) till the specified devolution level, and submits a query for example.aaa.microsoft.com. If this query fails, the primary DNS suffix is devolved further if it is under specified devolution level and the query example.microsoft.com is submitted. If this query fails, devolution continues if it is under specified devolution level and the query example.microsoft.com is submitted, corresponding to a devolution level of two. The primary DNS suffix cannot be devolved beyond a devolution level of two. The devolution level can be configured using this policy setting. The default devolution level is two.\r\n\r\nIf you enable this policy setting and DNS devolution is also enabled, DNS clients use the DNS devolution level that you specify.\r\n\r\nIf this policy setting is disabled, or if this policy setting is not configured, DNS clients use the default devolution level of two provided that DNS devolution is enabled.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-domainnamedevolutionlevel"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel_dns_domainnamedevolutionlevellabel","displayName":"Set the primary DNS suffix devolution level","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnencoding","displayName":"Turn off IDN encoding","description":"Specifies whether the DNS client should convert internationalized domain names (IDNs) to Punycode when the computer is on non-domain networks with no WINS servers configured.\r\n\r\nIf this policy setting is enabled, IDNs are not converted to Punycode.\r\n\r\nIf this policy setting is disabled, or if this policy setting is not configured, IDNs are converted to Punycode when the computer is on non-domain networks with no WINS servers configured.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-idnencoding"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnencoding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnencoding_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnmapping","displayName":"IDN mapping","description":"Specifies whether the DNS client should convert internationalized domain names (IDNs) to the Nameprep form, a canonical Unicode representation of the string.\r\n\r\nIf this policy setting is enabled, IDNs are converted to the Nameprep form.\r\n\r\nIf this policy setting is disabled, or if this policy setting is not configured, IDNs are not converted to the Nameprep form.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-idnmapping"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnmapping_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnmapping_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_nameserver","displayName":"DNS servers","description":"Defines the DNS servers to which a computer sends queries when it attempts to resolve names. This policy setting supersedes the list of DNS servers configured locally and those configured using DHCP. \r\n\r\nTo use this policy setting, click Enabled, and then enter a space-delimited list of IP addresses in the available field. To use this policy setting, you must enter at least one IP address.\r\n\r\nIf you enable this policy setting, the list of DNS servers is applied to all network connections used by computers that receive this policy setting. \r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers will use the local or DHCP supplied list of DNS servers, if configured.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-nameserver"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_nameserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_nameserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_nameserver_dns_nameserverlabel","displayName":"IP addresses:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_preferlocalresponsesoverlowerorderdns","displayName":"Prefer link local responses over DNS when received over a network with higher precedence","description":"Specifies that responses from link local name resolution protocols received over a network interface that is higher in the binding order are preferred over DNS responses from network interfaces lower in the binding order. Examples of link local name resolution protocols include link local multicast name resolution (LLMNR) and NetBIOS over TCP/IP (NetBT).\r\n\r\nIf you enable this policy setting, responses from link local protocols will be preferred over DNS responses if the local responses are from a network with a higher binding order.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, then DNS responses from networks lower in the binding order will be preferred over responses from link local protocols received from networks higher in the binding order.\r\n\r\nNote: This policy setting is applicable only if the turn off smart multi-homed name resolution policy setting is disabled or not configured.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-preferlocalresponsesoverlowerorderdns"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_preferlocalresponsesoverlowerorderdns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_preferlocalresponsesoverlowerorderdns_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_primarydnssuffix","displayName":"Primary DNS suffix","description":"Specifies the primary DNS suffix used by computers in DNS name registration and DNS name resolution.\r\n\r\nTo use this policy setting, click Enabled and enter the entire primary DNS suffix you want to assign. For example: microsoft.com.\r\n\r\nImportant: In order for changes to this policy setting to be applied on computers that receive it, you must restart Windows.\r\n\r\nIf you enable this policy setting, it supersedes the primary DNS suffix configured in the DNS Suffix and NetBIOS Computer Name dialog box using the System control panel.\r\n\r\nYou can use this policy setting to prevent users, including local administrators, from changing the primary DNS suffix.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, each computer uses its local primary DNS suffix, which is usually the DNS name of Active Directory domain to which it is joined.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-primarydnssuffix"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_primarydnssuffix_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_primarydnssuffix_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_primarydnssuffix_dns_primarydnssuffixbox","displayName":"Enter a primary DNS suffix:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registeradaptername","displayName":"Register DNS records with connection-specific DNS suffix","description":"Specifies if a computer performing dynamic DNS registration will register A and PTR resource records with a concatenation of its computer name and a connection-specific DNS suffix, in addition to registering these records with a concatenation of its computer name and the primary DNS suffix.\r\n\r\nBy default, a DNS client performing dynamic DNS registration registers A and PTR resource records with a concatenation of its computer name and the primary DNS suffix. For example, a computer name of mycomputer and a primary DNS suffix of microsoft.com will be registered as: mycomputer.microsoft.com.\r\n\r\nIf you enable this policy setting, a computer will register A and PTR resource records with its connection-specific DNS suffix, in addition to the primary DNS suffix. This applies to all network connections used by computers that receive this policy setting.\r\n\r\nFor example, with a computer name of mycomputer, a primary DNS suffix of microsoft.com, and a connection specific DNS suffix of VPNconnection, a computer will register A and PTR resource records for mycomputer.VPNconnection and mycomputer.microsoft.com when this policy setting is enabled.\r\n\r\nImportant: This policy setting is ignored on a DNS client computer if dynamic DNS registration is disabled.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, a DNS client computer will not register any A and PTR resource records using a connection-specific DNS suffix.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registeradaptername"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registeradaptername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registeradaptername_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup","displayName":"Register PTR records","description":"Specifies if DNS client computers will register PTR resource records.\r\n\r\nBy default, DNS clients configured to perform dynamic DNS registration will attempt to register PTR resource record only if they successfully registered the corresponding A resource record.\r\n\r\nIf you enable this policy setting, registration of PTR records will be determined by the option that you choose under Register PTR records.\r\n\r\nTo use this policy setting, click Enabled, and then select one of the following options from the drop-down list:\r\n\r\nDo not register: Computers will not attempt to register PTR resource records.\r\n\r\nRegister: Computers will attempt to register PTR resource records even if registration of the corresponding A records was not successful.\r\n\r\nRegister only if A record registration succeeds: Computers will attempt to register PTR resource records only if registration of the corresponding A records was successful.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers will use locally configured settings.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registerreverselookup"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup_dns_registerreverselookup_box","displayName":"Register PTR records:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup_dns_registerreverselookup_box_2","displayName":"Register only if A record registration succeeds","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup_dns_registerreverselookup_box_1","displayName":"Register","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registerreverselookup_dns_registerreverselookup_box_0","displayName":"Do not register","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationenabled","displayName":"Dynamic update","description":"Specifies if DNS dynamic update is enabled. Computers configured for DNS dynamic update automatically register and update their DNS resource records with a DNS server.\r\n\r\nIf you enable this policy setting, or you do not configure this policy setting, computers will attempt to use dynamic DNS registration on all network connections that have connection-specific dynamic DNS registration enabled. For a dynamic DNS registration to be enabled on a network connection, the connection-specific configuration must allow dynamic DNS registration, and this policy setting must not be disabled.\r\n\r\nIf you disable this policy setting, computers may not use dynamic DNS registration for any of their network connections, regardless of the configuration for individual network connections.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registrationenabled"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationoverwritesinconflict","displayName":"Replace addresses in conflicts","description":"Specifies whether dynamic updates should overwrite existing resource records that contain conflicting IP addresses.\r\n\r\nThis policy setting is designed for computers that register address (A) resource records in DNS zones that do not use Secure Dynamic Updates. Secure Dynamic Update preserves ownership of resource records and does not allow a DNS client to overwrite records that are registered by other computers.\r\n\r\nDuring dynamic update of resource records in a zone that does not use Secure Dynamic Updates, an A resource record might exist that associates the client's host name with an IP address different than the one currently in use by the client. By default, the DNS client attempts to replace the existing A resource record with an A resource record that has the client's current IP address.\r\n\r\nIf you enable this policy setting or if you do not configure this policy setting, DNS clients maintain their default behavior and will attempt to replace conflicting A resource records during dynamic update.\r\n\r\nIf you disable this policy setting, existing A resource records that contain conflicting IP addresses will not be replaced during a dynamic update, and an error will be recorded in Event Viewer.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registrationoverwritesinconflict"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationoverwritesinconflict_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationoverwritesinconflict_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationrefreshinterval","displayName":"Registration refresh interval","description":"Specifies the interval used by DNS clients to refresh registration of A and PTR resource. This policy setting only applies to computers performing dynamic DNS updates.\r\n\r\nComputers configured to perform dynamic DNS registration of A and PTR resource records periodically reregister their records with DNS servers, even if the record has not changed. This reregistration is required to indicate to DNS servers that records are current and should not be automatically removed (scavenged) when a DNS server is configured to delete stale records.\r\n\r\nWarning: If record scavenging is enabled on the zone, the value of this policy setting should never be longer than the value of the DNS zone refresh interval. Configuring the registration refresh interval to be longer than the refresh interval of the DNS zone might result in the undesired deletion of A and PTR resource records.\r\n\r\nTo specify the registration refresh interval, click Enabled and then enter a value of 1800 or greater. The value that you specify is the number of seconds to use for the registration refresh interval. For example, 1800 seconds is 30 minutes.\r\n\r\nIf you enable this policy setting, registration refresh interval that you specify will be applied to all network connections used by computers that receive this policy setting.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers will use the local or DHCP supplied setting. By default, client computers configured with a static IP address attempt to update their DNS resource records once every 24 hours and DHCP clients will attempt to update their DNS resource records when a DHCP lease is granted or renewed.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registrationrefreshinterval"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationrefreshinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationrefreshinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationrefreshinterval_dns_registrationrefreshintervallabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationttl","displayName":"TTL value for A and PTR records","description":"\r\nSpecifies the value of the time to live (TTL) field in A and PTR resource records that are registered by computers to which this policy setting is applied.\r\n\r\nTo specify the TTL, click Enabled and then enter a value in seconds (for example, 900 is 15 minutes).\r\n\r\nIf you enable this policy setting, the TTL value that you specify will be applied to DNS resource records registered for all network connections used by computers that receive this policy setting.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers will use the TTL settings specified in DNS. By default, the TTL is 1200 seconds (20 minutes).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registrationttl"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationttl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationttl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationttl_dns_registrationttllabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_searchlist","displayName":"DNS suffix search list","description":"Specifies the DNS suffixes to attach to an unqualified single-label name before submission of a DNS query for that name.\r\n\r\nAn unqualified single-label name contains no dots. The name \"example\" is a single-label name. This is different from a fully qualified domain name such as \"example.microsoft.com.\"\r\n\r\nClient computers that receive this policy setting will attach one or more suffixes to DNS queries for a single-label name. For example, a DNS query for the single-label name \"example\" will be modified to \"example.microsoft.com\" before sending the query to a DNS server if this policy setting is enabled with a suffix of \"microsoft.com.\"\r\n\r\nTo use this policy setting, click Enabled, and then enter a string value representing the DNS suffixes that should be appended to single-label names. You must specify at least one suffix. Use a comma-delimited string, such as \"microsoft.com,serverua.microsoft.com,office.microsoft.com\" to specify multiple suffixes.\r\n\r\nIf you enable this policy setting, one DNS suffix is attached at a time for each query. If a query is unsuccessful, a new DNS suffix is added in place of the failed suffix, and this new query is submitted. The values are used in the order they appear in the string, starting with the leftmost value and proceeding to the right until a query is successful or all suffixes are tried.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, the primary DNS suffix and network connection-specific DNS suffixes are appended to the unqualified queries.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-searchlist"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_searchlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_searchlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_searchlist_dns_searchlistlabel","displayName":"DNS Suffixes:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartmultihomednameresolution","displayName":"Turn off smart multi-homed name resolution","description":"Specifies that a multi-homed DNS client should optimize name resolution across networks. The setting improves performance by issuing parallel DNS, link local multicast name resolution (LLMNR) and NetBIOS over TCP/IP (NetBT) queries across all networks. In the event that multiple positive responses are received, the network binding order is used to determine which response to accept.\r\n\r\nIf you enable this policy setting, the DNS client will not perform any optimizations. DNS queries will be issued across all networks first. LLMNR queries will be issued if the DNS queries fail, followed by NetBT queries if LLMNR queries fail.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, name resolution will be optimized when issuing DNS, LLMNR and NetBT queries.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-smartmultihomednameresolution"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartmultihomednameresolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartmultihomednameresolution_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartprotocolreorder","displayName":"Turn off smart protocol reordering","description":"Specifies that the DNS client should prefer responses from link local name resolution protocols on non-domain networks over DNS responses when issuing queries for flat names. Examples of link local name resolution protocols include link local multicast name resolution (LLMNR) and NetBIOS over TCP/IP (NetBT).\r\n\r\nIf you enable this policy setting, the DNS client will prefer DNS responses, followed by LLMNR, followed by NetBT for all networks. \r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, the DNS client will prefer link local responses for flat name queries on non-domain networks. \r\n\r\nNote: This policy setting is applicable only if the turn off smart multi-homed name resolution policy setting is disabled or not configured.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-smartprotocolreorder"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartprotocolreorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartprotocolreorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel","displayName":"Update security level","description":"Specifies the security level for dynamic DNS updates.\r\n\r\nTo use this policy setting, click Enabled and then select one of the following values:\r\n\r\nUnsecure followed by secure - computers send secure dynamic updates only when nonsecure dynamic updates are refused.\r\n\r\nOnly unsecure - computers send only nonsecure dynamic updates.\r\n\r\nOnly secure - computers send only secure dynamic updates.\r\n\r\nIf you enable this policy setting, computers that attempt to send dynamic DNS updates will use the security level that you specify in this policy setting.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers will use local settings. By default, DNS clients attempt to use unsecured dynamic update first. If an unsecured update is refused, clients try to use secure update.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-updatesecuritylevel"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box","displayName":"Update security level:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box_256","displayName":"Only secure","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box_16","displayName":"Only unsecure","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box_0","displayName":"Unsecure followed by secure","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatetopleveldomainzones","displayName":"Update top level domain zones","description":"Specifies if computers may send dynamic updates to zones with a single label name. These zones are also known as top-level domain zones, for example: \"com.\"\r\n\r\nBy default, a DNS client that is configured to perform dynamic DNS update will update the DNS zone that is authoritative for its DNS resource records unless the authoritative zone is a top-level domain or root zone.\r\n\r\nIf you enable this policy setting, computers send dynamic updates to any zone that is authoritative for the resource records that the computer needs to update, except the root zone.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, computers do not send dynamic updates to the root zone or top-level domain zones that are authoritative for the resource records that the computer needs to update.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-updatetopleveldomainzones"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatetopleveldomainzones_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatetopleveldomainzones_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_usedomainnamedevolution","displayName":"Primary DNS suffix devolution","description":"Specifies if the DNS client performs primary DNS suffix devolution during the name resolution process.\r\n\r\nWith devolution, a DNS client creates queries by appending a single-label, unqualified domain name with the parent suffix of the primary DNS suffix name, and the parent of that suffix, and so on, stopping if the name is successfully resolved or at a level determined by devolution settings. Devolution can be used when a user or application submits a query for a single-label domain name.\r\n\r\nThe DNS client appends DNS suffixes to the single-label, unqualified domain name based on the state of the Append primary and connection specific DNS suffixes radio button and Append parent suffixes of the primary DNS suffix check box on the DNS tab in Advanced TCP/IP Settings for the Internet Protocol (TCP/IP) Properties dialog box.\r\n\r\nDevolution is not enabled if a global suffix search list is configured using Group Policy.\r\n\r\nIf a global suffix search list is not configured, and the Append primary and connection specific DNS suffixes radio button is selected, the DNS client appends the following names to a single-label name when it sends DNS queries:\r\n\r\nThe primary DNS suffix, as specified on the Computer Name tab of the System control panel.\r\n\r\nEach connection-specific DNS suffix, assigned either through DHCP or specified in the DNS suffix for this connection box on the DNS tab in the Advanced TCP/IP Settings dialog box for each connection.\r\n\r\nFor example, when a user submits a query for a single-label name such as \"example,\" the DNS client attaches a suffix such as \"microsoft.com\" resulting in the query \"example.microsoft.com,\" before sending the query to a DNS server.\r\n\r\nIf a DNS suffix search list is not specified, the DNS client attaches the primary DNS suffix to a single-label name. If this query fails, the connection-specific DNS suffix is attached for a new query. If none of these queries are resolved, the client devolves the primary DNS suffix of the computer (drops the leftmost label of the primary DNS suffix), attaches this devolved primary DNS suffix to the single-label name, and submits this new query to a DNS server.\r\n\r\nFor example, if the primary DNS suffix ooo.aaa.microsoft.com is attached to the non-dot-terminated single-label name \"example,\" and the DNS query for example.ooo.aaa.microsoft.com fails, the DNS client devolves the primary DNS suffix (drops the leftmost label) till the specified devolution level, and submits a query for example.aaa.microsoft.com. If this query fails, the primary DNS suffix is devolved further if it is under specified devolution level and the query example.microsoft.com is submitted. If this query fails, devolution continues if it is under specified devolution level and the query example.microsoft.com is submitted, corresponding to a devolution level of two. The primary DNS suffix cannot be devolved beyond a devolution level of two. The devolution level can be configured using the primary DNS suffix devolution level policy setting. The default devolution level is two.\r\n\r\nIf you enable this policy setting, or if you do not configure this policy setting, DNS clients attempt to resolve single-label names using concatenations of the single-label name to be resolved and the devolved primary DNS suffix.\r\n\r\nIf you disable this policy setting, DNS clients do not attempt to resolve names that are concatenations of the single-label name to be resolved and the devolved primary DNS suffix.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-usedomainnamedevolution"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_usedomainnamedevolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_usedomainnamedevolution_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dnsclient_turn_off_multicast","displayName":"Turn off multicast name resolution","description":"Specifies that link local multicast name resolution (LLMNR) is disabled on client computers.\r\n\r\nLLMNR is a secondary name resolution protocol. With LLMNR, queries are sent using multicast over a local network link on a single subnet from a client computer to another client computer on the same subnet that also has LLMNR enabled. LLMNR does not require a DNS server or DNS client configuration, and provides name resolution in scenarios in which conventional DNS name resolution is not possible.\r\n\r\nIf you enable this policy setting, LLMNR will be disabled on all available network adapters on the client computer.\r\n\r\nIf you disable this policy setting, or you do not configure this policy setting, LLMNR will be enabled on all available network adapters.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-turn-off-multicast"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_turn_off_multicast_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_turn_off_multicast_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2","displayName":"Specify a default color","description":"This policy setting controls the default color for window frames when the user does not specify a color. \r\n\r\nIf you enable this policy setting and specify a default color, this color is used in glass window frames, if the user does not specify a color. \r\n\r\nIf you disable or do not configure this policy setting, the default internal color is used, if the user does not specify a color. \r\n\r\nNote: This policy setting can be used in conjunction with the \"Prevent color changes of window frames\" setting, to enforce a specific color for window frames that cannot be changed by users.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dwm#admx-dwm-dwmdefaultcolorizationcolor-2"],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":[{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_dwmdefaultcolorizationcoloralpha","displayName":"Alpha","description":null,"helpText":"","infoUrls":[],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_dwmdefaultcolorizationcolorblue","displayName":"Blue","description":null,"helpText":"","infoUrls":[],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_dwmdefaultcolorizationcolorgreen","displayName":"Green","description":null,"helpText":"","infoUrls":[],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_dwmdefaultcolorizationcolorred","displayName":"Red","description":null,"helpText":"","infoUrls":[],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdisallowanimations_2","displayName":"Do not allow window animations","description":"This policy setting controls the appearance of window animations such as those found when restoring, minimizing, and maximizing windows. \r\n\r\nIf you enable this policy setting, window animations are turned off. \r\n\r\nIf you disable or do not configure this policy setting, window animations are turned on. \r\n\r\nChanging this policy setting requires a logoff for it to be applied.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dwm#admx-dwm-dwmdisallowanimations-2"],"categoryId":"d52dd970-febb-4891-8eb7-1c8616cfb6cb","categoryName":"Desktop Window Manager","options":[{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdisallowanimations_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdisallowanimations_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdisallowcolorizationcolorchanges_2","displayName":"Do not allow color changes","description":"This policy setting controls the ability to change the color of window frames. \r\n\r\nIf you enable this policy setting, you prevent users from changing the default window frame color. \r\n\r\nIf you disable or do not configure this policy setting, you allow users to change the default window frame color. \r\n\r\nNote: This policy setting can be used in conjunction with the \"Specify a default color for window frames\" policy setting, to enforce a specific color for window frames that cannot be changed by users.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dwm#admx-dwm-dwmdisallowcolorizationcolorchanges-2"],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":[{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdisallowcolorizationcolorchanges_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdisallowcolorizationcolorchanges_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_encryptfilesonmove_noencryptonmove","displayName":"Do not automatically encrypt files moved to encrypted folders","description":"This policy setting prevents File Explorer from encrypting files that are moved to an encrypted folder.\r\n\r\nIf you enable this policy setting, File Explorer will not automatically encrypt files that are moved to an encrypted folder.\r\n\r\nIf you disable or do not configure this policy setting, File Explorer automatically encrypts files that are moved to an encrypted folder.\r\n\r\nThis setting applies only to files moved within a volume. When files are moved to other volumes, or if you create a new file in an encrypted folder, File Explorer encrypts those files automatically.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-encryptfilesonmove#admx-encryptfilesonmove-noencryptonmove"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_encryptfilesonmove_noencryptonmove_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_encryptfilesonmove_noencryptonmove_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedenstordevices","displayName":"Configure list of Enhanced Storage devices usable on your computer","description":"This policy setting allows you to configure a list of Enhanced Storage devices by manufacturer and product ID that are usable on your computer.\r\n\r\nIf you enable this policy setting, only Enhanced Storage devices that contain a manufacturer and product ID specified in this policy are usable on your computer.\r\n\r\nIf you disable or do not configure this policy setting, all Enhanced Storage devices are usable on your computer.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-enhancedstorage#admx-enhancedstorage-approvedenstordevices"],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedenstordevices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedenstordevices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedenstordevices_approvedenstordevices_list","displayName":"Usable Enhanced Storage Devices:","description":null,"helpText":"","infoUrls":[],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedsilos","displayName":"Configure list of IEEE 1667 silos usable on your computer","description":"This policy setting allows you to create a list of IEEE 1667 silos, compliant with the Institute of Electrical and Electronics Engineers, Inc. (IEEE) 1667 specification, that are usable on your computer.\r\n\r\nIf you enable this policy setting, only IEEE 1667 silos that match a silo type identifier specified in this policy are usable on your computer.\r\n\r\nIf you disable or do not configure this policy setting, all IEEE 1667 silos on Enhanced Storage devices are usable on your computer.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-enhancedstorage#admx-enhancedstorage-approvedsilos"],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedsilos_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedsilos_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_approvedsilos_approvedsilos_list","displayName":"Usable IEEE 1667 Silo Type Identifiers:","description":null,"helpText":"","infoUrls":[],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_disablepasswordauthentication","displayName":"Do not allow password authentication of Enhanced Storage devices","description":"This policy setting configures whether or not a password can be used to unlock an Enhanced Storage device.\r\n\r\nIf you enable this policy setting, a password cannot be used to unlock an Enhanced Storage device.\r\n\r\nIf you disable or do not configure this policy setting, a password can be used to unlock an Enhanced Storage device.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-enhancedstorage#admx-enhancedstorage-disablepasswordauthentication"],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_disablepasswordauthentication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_disablepasswordauthentication_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_disallowlegacydiskdevices","displayName":"Do not allow non-Enhanced Storage removable devices","description":"This policy setting configures whether or not non-Enhanced Storage removable devices are allowed on your computer.\r\n\r\nIf you enable this policy setting, non-Enhanced Storage removable devices are not allowed on your computer.\r\n\r\nIf you disable or do not configure this policy setting, non-Enhanced Storage removable devices are allowed on your computer.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-enhancedstorage#admx-enhancedstorage-disallowlegacydiskdevices"],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_disallowlegacydiskdevices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_disallowlegacydiskdevices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_lockdeviceonmachinelock","displayName":"Lock Enhanced Storage when the computer is locked","description":"This policy setting locks Enhanced Storage devices when the computer is locked.\r\n\r\nThis policy setting is supported in Windows Server SKUs only.\r\n\r\nIf you enable this policy setting, the Enhanced Storage device remains locked when the computer is locked.\r\n\r\nIf you disable or do not configure this policy setting, the Enhanced Storage device state is not changed when the computer is locked.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-enhancedstorage#admx-enhancedstorage-lockdeviceonmachinelock"],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_lockdeviceonmachinelock_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_lockdeviceonmachinelock_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_roothubconnectedenstordevices","displayName":"Allow only USB root hub connected Enhanced Storage devices","description":"This policy setting configures whether or not only USB root hub connected Enhanced Storage devices are allowed. Allowing only root hub connected Enhanced Storage devices minimizes the risk of an unauthorized USB device reading data on an Enhanced Storage device.\r\n\r\nIf you enable this policy setting, only USB root hub connected Enhanced Storage devices are allowed.\r\n\r\nIf you disable or do not configure this policy setting, USB Enhanced Storage devices connected to both USB root hubs and non-root hubs will be allowed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-enhancedstorage#admx-enhancedstorage-roothubconnectedenstordevices"],"categoryId":"2461b964-02f6-4da2-921a-f7e8f868c69d","categoryName":"Enhanced Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_roothubconnectedenstordevices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_enhancedstorage_roothubconnectedenstordevices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef","displayName":"Default application reporting settings","description":"This policy setting controls whether errors in general applications are included in reports when Windows Error Reporting is enabled.\r\n\r\nIf you enable this policy setting, you can instruct Windows Error Reporting in the Default pull-down menu to report either all application errors (the default setting), or no application errors.\r\n\r\nIf the Report all errors in Microsoft applications check box is filled, all errors in Microsoft applications are reported, regardless of the setting in the Default pull-down menu. When the Report all errors in Windows check box is filled, all errors in Windows applications are reported, regardless of the setting in the Default dropdown list. The Windows applications category is a subset of Microsoft applications.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable Windows Error Reporting in Control Panel. The default setting in Control Panel is Upload all applications.\r\n\r\nThis policy setting is ignored if the Configure Error Reporting policy setting is disabled or not configured.\r\n\r\nFor related information, see the Configure Error Reporting and Report Operating System Errors policy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-allornonedef"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonedef_list","displayName":"Default:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonedef_list_1","displayName":"Report all application errors","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonedef_list_0","displayName":"Do not report any application errors","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornoneincms_chk","displayName":"Report all errors in Microsoft applications.","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornoneincms_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornoneincms_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonewincomp_chk","displayName":"Report all errors in Windows components.","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonewincomp_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonewincomp_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex","displayName":"List of applications to never report errors for","description":"This policy setting controls Windows Error Reporting behavior for errors in general applications when Windows Error Reporting is turned on.\r\n\r\nIf you enable this policy setting, you can create a list of applications that are never included in error reports. To create a list of applications for which Windows Error Reporting never reports errors, click Show under the Exclude errors for applications on this list setting, and then add or remove applications from the list of application file names in the Show Contents dialog box (example: notepad.exe). File names must always include the .exe file name extension. Errors that are generated by applications in this list are not reported, even if the Default Application Reporting Settings policy setting is configured to report all application errors.\r\n\r\nIf this policy setting is enabled, the Exclude errors for applications on this list setting takes precedence. If an application is listed both in the List of applications to always report errors for policy setting, and in the exclusion list in this policy setting, the application is excluded from error reporting. You can also use the exclusion list in this policy setting to exclude specific Microsoft applications or parts of Windows if the check boxes for these categories are filled in the Default application reporting settings policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Default application reporting settings policy setting takes precedence.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-allornoneex"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex_pch_allornoneex_list","displayName":"Exclude errors for applications on this list:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc","displayName":"List of applications to always report errors for","description":"This policy setting specifies applications for which Windows Error Reporting should always report errors.\r\n\r\nTo create a list of applications for which Windows Error Reporting never reports errors, click Show under the Exclude errors for applications on this list setting, and then add or remove applications from the list of application file names in the Show Contents dialog box (example: notepad.exe). Errors that are generated by applications in this list are not reported, even if the Default Application Reporting Settings policy setting is configured to report all application errors.\r\n\r\nIf you enable this policy setting, you can create a list of applications that are always included in error reporting. To add applications to the list, click Show under the Report errors for applications on this list setting, and edit the list of application file names in the Show Contents dialog box. The file names must include the .exe file name extension (for example, notepad.exe). Errors that are generated by applications on this list are always reported, even if the Default dropdown in the Default application reporting policy setting is set to report no application errors.\r\n\r\nIf the Report all errors in Microsoft applications or Report all errors in Windows components check boxes in the Default Application Reporting policy setting are filled, Windows Error Reporting reports errors as if all applications in these categories were added to the list in this policy setting. (Note: The Microsoft applications category includes the Windows components category.)\r\n\r\nIf you disable this policy setting or do not configure it, the Default application reporting settings policy setting takes precedence.\r\n\r\nAlso see the \"Default Application Reporting\" and \"Application Exclusion List\" policies.\r\n\r\nThis setting will be ignored if the 'Configure Error Reporting' setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-allornoneinc"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc_pch_allornoneinc_list","displayName":"Report errors for applications on this list:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport","displayName":"Configure Error Reporting","description":"This policy setting configures how errors are reported to Microsoft, and what information is sent when Windows Error Reporting is enabled.\r\n\r\nThis policy setting does not enable or disable Windows Error Reporting. To turn Windows Error Reporting on or off, see the Turn off Windows Error Reporting policy setting in Computer Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings.\r\n\r\nImportant: If the Turn off Windows Error Reporting policy setting is not configured, then Control Panel settings for Windows Error Reporting override this policy setting.\r\n\r\nIf you enable this policy setting, the setting overrides any user changes made to Windows Error Reporting settings in Control Panel, and default values are applied for any Windows Error Reporting policy settings that are not configured (even if users have changed settings by using Control Panel). If you enable this policy setting, you can configure the following settings in the policy setting:\r\n\r\n- \"Do not display links to any Microsoft ‘More information’ websites\": Select this option if you do not want error dialog boxes to display links to Microsoft websites.\r\n\r\n- \"Do not collect additional files\": Select this option if you do not want additional files to be collected and included in error reports.\r\n\r\n- \"Do not collect additional computer data\": Select this if you do not want additional information about the computer to be collected and included in error reports.\r\n\r\n- \"Force queue mode for application errors\": Select this option if you do not want users to report errors. When this option is selected, errors are stored in a queue directory, and the next administrator to log on to the computer can send the error reports to Microsoft.\r\n\r\n- \"Corporate file path\": Type a UNC path to enable Corporate Error Reporting. All errors are stored at the specified location instead of being sent directly to Microsoft, and the next administrator to log onto the computer can send the error reports to Microsoft.\r\n\r\n- \"Replace instances of the word ‘Microsoft’ with\": You can specify text with which to customize your error report dialog boxes. The word \"Microsoft\" is replaced with the specified text.\r\n\r\nIf you do not configure this policy setting, users can change Windows Error Reporting settings in Control Panel. By default, these settings are Enable Reporting on computers that are running Windows XP, and Report to Queue on computers that are running Windows Server 2003.\r\n\r\nIf you disable this policy setting, configuration settings in the policy setting are left blank.\r\n\r\nSee related policy settings Display Error Notification (same folder as this policy setting), and Turn off Windows Error Reporting in Computer Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-configurereport"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_companytext_edit","displayName":"Replace instances of the word 'Microsoft' with:","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_dumppath_edit","displayName":"Corporate upload file path:","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_forceq_chk","displayName":"Force queue mode for application errors","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_forceq_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_forceq_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_noexternalurl_chk","displayName":"Do not display links to any Microsoft provided 'more information' web sites.","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_noexternalurl_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_noexternalurl_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_nofilecollect_chk","displayName":"Do not collect additional files","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_nofilecollect_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_nofilecollect_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_noleveltwo_chk","displayName":"Do not collect additional machine data","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_noleveltwo_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_noleveltwo_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_reportoperatingsystemfaults","displayName":"Report operating system errors","description":"This policy setting controls whether errors in the operating system are included Windows Error Reporting is enabled.\r\n\r\nIf you enable this policy setting, Windows Error Reporting includes operating system errors.\r\n\r\nIf you disable this policy setting, operating system errors are not included in error reports.\r\n\r\nIf you do not configure this policy setting, users can change this setting in Control Panel. By default, Windows Error Reporting settings in Control Panel are set to upload operating system errors.\r\n\r\nSee also the Configure Error Reporting policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-reportoperatingsystemfaults"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_reportoperatingsystemfaults_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_reportoperatingsystemfaults_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2","displayName":"Configure Report Archive","description":"This policy setting controls the behavior of the Windows Error Reporting archive.\r\n\r\nIf you enable this policy setting, you can configure Windows Error Reporting archiving behavior. If Archive behavior is set to Store all, all data collected for each error report is stored in the appropriate location. If Archive behavior is set to Store parameters only, only the minimum information required to check for an existing solution is stored. The Maximum number of reports to store setting determines how many reports are stored before older reports are automatically deleted.\r\n\r\nIf you disable or do not configure this policy setting, no Windows Error Reporting information is stored.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werarchive-2"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2_werarchivebehavior","displayName":"Archive behavior:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2_werarchivebehavior_2","displayName":"Store all","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2_werarchivebehavior_1","displayName":"Store parameters only","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werarchive_2_wermaxarchivecount","displayName":"Maximum number of reports to store:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werautoapproveosdumps_2","displayName":"Automatically send memory dumps for OS-generated error reports","description":"This policy setting controls whether memory dumps in support of OS-generated error reports can be sent to Microsoft automatically. This policy does not apply to error reports generated by 3rd-party products, or additional data other than memory dumps.\r\n\r\nIf you enable or do not configure this policy setting, any memory dumps generated for error reports by Microsoft Windows are automatically uploaded, without notification to the user.\r\n\r\nIf you disable this policy setting, then all memory dumps are uploaded according to the default consent and notification settings.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werautoapproveosdumps-2"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werautoapproveosdumps_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werautoapproveosdumps_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_2","displayName":"Do not throttle additional data","description":"This policy setting determines whether Windows Error Reporting (WER) sends additional, second-level report data even if a CAB file containing data about the same event types has already been uploaded to the server.\r\n\r\nIf you enable this policy setting, WER does not throttle data; that is, WER uploads additional CAB files that can contain data about the same event types as an earlier uploaded report.\r\n\r\nIf you disable or do not configure this policy setting, WER throttles data by default; that is, WER does not upload more than one CAB file for a report that contains data about the same event types.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypassdatathrottling-2"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassnetworkcostthrottling_2","displayName":"Send data when on connected to a restricted/costed network","description":"This policy setting determines whether Windows Error Reporting (WER) checks for a network cost policy that restricts the amount of data that is sent over the network.\r\n\r\nIf you enable this policy setting, WER does not check for network cost policy restrictions, and transmits data even if network cost is restricted.\r\n\r\nIf you disable or do not configure this policy setting, WER does not send data, but will check the network cost policy again if the network profile is changed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypassnetworkcostthrottling-2"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassnetworkcostthrottling_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassnetworkcostthrottling_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypasspowerthrottling_2","displayName":"Send additional data when on battery power","description":"This policy setting determines whether Windows Error Reporting (WER) checks if the computer is running on battery power. By default, when a computer is running on battery power, WER only checks for solutions, but does not upload additional report data until the computer is connected to a more permanent power source.\r\n\r\nIf you enable this policy setting, WER does not determine whether the computer is running on battery power, but checks for solutions and uploads report data normally.\r\n\r\nIf you disable or do not configure this policy setting, WER checks for solutions while a computer is running on battery power, but does not upload report data until the computer is connected to a more permanent power source.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypasspowerthrottling-2"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypasspowerthrottling_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypasspowerthrottling_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer","displayName":"Configure Corporate Windows Error Reporting","description":"This policy setting specifies a corporate server to which Windows Error Reporting sends reports (if you do not want to send error reports to Microsoft).\r\n\r\nIf you enable this policy setting, you can specify the name or IP address of an error report destination server on your organization’s network. You can also select Connect using SSL to transmit error reports over a Secure Sockets Layer (SSL) connection, and specify a port number on the destination server for transmission.\r\n\r\nIf you disable or do not configure this policy setting, Windows Error Reporting sends error reports to Microsoft.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-wercer"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercercorporateportnumber","displayName":"Server port:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerserver","displayName":"Corporate server name:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_werceruploadonfreenetworksonly","displayName":"Only upload on free networks","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_werceruploadonfreenetworksonly_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_werceruploadonfreenetworksonly_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerusessl","displayName":"Connect using SSL","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerusessl_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerusessl_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werconsentoverride_2","displayName":"Ignore custom consent settings","description":"This policy setting determines the behavior of the Configure Default Consent setting in relation to custom consent settings.\r\n\r\nIf you enable this policy setting, the default consent levels of Windows Error Reporting always override any other consent policy setting.\r\n\r\nIf you disable or do not configure this policy setting, custom consent policy settings for error reporting determine the consent level for specified event types, and the default consent setting determines only the consent level of any other error reports.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werconsentoverride-2"],"categoryId":"184981d4-712b-425e-b0a3-93eac7fbd3ee","categoryName":"Consent","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werconsentoverride_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werconsentoverride_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2","displayName":"Configure Default consent","description":"This policy setting determines the default consent behavior of Windows Error Reporting.\r\n\r\nIf you enable this policy setting, you can set the default consent handling for error reports. The following list describes the Consent level settings that are available in the pull-down menu in this policy setting:\r\n\r\n- Always ask before sending data: Windows prompts users for consent to send reports.\r\n\r\n- Send parameters: Only the minimum data that is required to check for an existing solution is sent automatically, and Windows prompts users for consent to send any additional data that is requested by Microsoft.\r\n\r\n- Send parameters and safe additional data: the minimum data that is required to check for an existing solution, along with data which Windows has determined (within a high probability) does not contain personally-identifiable information is sent automatically, and Windows prompts the user for consent to send any additional data that is requested by Microsoft.\r\n\r\n- Send all data: any error reporting data requested by Microsoft is sent automatically.\r\n\r\nIf this policy setting is disabled or not configured, then the consent level defaults to the highest-privacy setting: Always ask before sending data.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werdefaultconsent-2"],"categoryId":"184981d4-712b-425e-b0a3-93eac7fbd3ee","categoryName":"Consent","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_werconsent","displayName":"Consent level","description":null,"helpText":"","infoUrls":[],"categoryId":"184981d4-712b-425e-b0a3-93eac7fbd3ee","categoryName":"Consent","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_werconsent_1","displayName":"Always ask before sending data","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_werconsent_2","displayName":"Send parameters","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_werconsent_3","displayName":"Send parameters and safe additional data","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_2_werconsent_4","displayName":"Send all data","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werexlusion_2","displayName":"List of applications to be excluded","description":"This policy setting limits Windows Error Reporting behavior for errors in general applications when Windows Error Reporting is turned on.\r\n\r\nIf you enable this policy setting, you can create a list of applications that are never included in error reports. To create a list of applications for which Windows Error Reporting never reports errors, click Show, and then add or remove applications from the list of application file names in the Show Contents dialog box (example: notepad.exe). File names must always include the .exe file name extension. To remove an application from the list, click the name, and then press DELETE. If this policy setting is enabled, the Exclude errors for applications on this list setting takes precedence.\r\n\r\nIf you disable or do not configure this policy setting, errors are reported on all Microsoft and Windows applications by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werexlusion-2"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werexlusion_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werexlusion_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werexlusion_2_werexlusionlist","displayName":"List of applications to be excluded","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wernologging_2","displayName":"Disable logging","description":"This policy setting controls whether Windows Error Reporting saves its own events and error messages to the system event log.\r\n\r\nIf you enable this policy setting, Windows Error Reporting events are not recorded in the system event log.\r\n\r\nIf you disable or do not configure this policy setting, Windows Error Reporting events and errors are logged to the system event log, as with other Windows-based programs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-wernologging-2"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_wernologging_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wernologging_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2","displayName":"Configure Report Queue","description":"This policy setting determines the behavior of the Windows Error Reporting report queue.\r\n\r\nIf you enable this policy setting, you can configure report queue behavior by using the controls in the policy setting. When the Queuing behavior pull-down list is set to Default, Windows determines, when a problem occurs, whether the report should be placed in the reporting queue, or the user should be prompted to send it immediately. When Queuing behavior is set to Always queue, all reports are added to the queue until the user is prompted to send the reports, or until the user sends problem reports by using the Solutions to Problems page in Control Panel. If Queuing behavior is set to Always queue for administrator, reports are queued until an administrator is prompted to send them, or until the administrator sends them by using the Solutions to Problems page in Control Panel.\r\n\r\nThe Maximum number of reports to queue setting determines how many reports can be queued before older reports are automatically deleted. The setting for Number of days between solution check reminders determines the interval time between the display of system notifications that remind the user to check for solutions to problems. A value of 0 disables the reminder.\r\n\r\nIf you disable or do not configure this policy setting, Windows Error Reporting reports are not queued, and users can only send reports at the time that a problem occurs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werqueue-2"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_wermaxqueuecount","displayName":"Maximum number of reports to queue:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_wermaxqueuesize","displayName":"Maximum size of the queue (MB):","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werminfreediskspace","displayName":"Minimum free disk space (MB):","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werqueuebehavior","displayName":"Queuing behavior:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werqueuebehavior_0","displayName":"Default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werqueuebehavior_1","displayName":"Always queue","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werqueuebehavior_2","displayName":"Always queue for administrator","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werupdatecheck","displayName":"Number of days between solution check reminders:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_forwarderresourceusage","displayName":"Configure forwarder resource usage","description":"This policy setting controls resource usage for the forwarder (source computer) by controlling the events/per second sent to the Event Collector.\r\n\r\nIf you enable this policy setting, you can control the volume of events sent to the Event Collector by the source computer. This may be required in high volume environments.\r\n\r\nIf you disable or do not configure this policy setting, forwarder resource usage is not specified.\r\n\r\nThis setting applies across all subscriptions for the forwarder (source computer).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventforwarding#admx-eventforwarding-forwarderresourceusage"],"categoryId":"c859dc1a-fdeb-4591-af97-79d078ee715b","categoryName":"Event Forwarding","options":[{"id":"device_vendor_msft_policy_config_admx_eventforwarding_forwarderresourceusage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_forwarderresourceusage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_forwarderresourceusage_maxforwardingrate","displayName":"The maximum forwarding rate ( events/sec ) allowed for the forwarder:","description":null,"helpText":"","infoUrls":[],"categoryId":"c859dc1a-fdeb-4591-af97-79d078ee715b","categoryName":"Event Forwarding","options":null},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager","displayName":"Configure target Subscription Manager","description":"This policy setting allows you to configure the server address, refresh interval, and issuer certificate authority (CA) of a target Subscription Manager.\r\n\r\nIf you enable this policy setting, you can configure the Source Computer to contact a specific FQDN (Fully Qualified Domain Name) or IP Address and request subscription specifics.\r\n\r\nUse the following syntax when using the HTTPS protocol:\r\nServer=https://:5986/wsman/SubscriptionManager/WEC,Refresh=,IssuerCA=. When using the HTTP protocol, use port 5985.\r\n\r\nIf you disable or do not configure this policy setting, the Event Collector computer will not be specified.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventforwarding#admx-eventforwarding-subscriptionmanager"],"categoryId":"c859dc1a-fdeb-4591-af97-79d078ee715b","categoryName":"Event Forwarding","options":[{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager_subscriptionmanager_listbox","displayName":"SubscriptionManagers","description":null,"helpText":"","infoUrls":[],"categoryId":"c859dc1a-fdeb-4591-af97-79d078ee715b","categoryName":"Event Forwarding","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_1","displayName":"Back up log automatically when full","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size and takes effect only if the \"Retain old events\" policy setting is enabled.\r\n\r\nIf you enable this policy setting and the \"Retain old events\" policy setting is enabled, the Event Log file is automatically closed and renamed when it is full. A new file is then started.\r\n\r\nIf you disable this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and old events are retained.\r\n\r\nIf you do not configure this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and the old events are retained.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-autobackup-1"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_2","displayName":"Back up log automatically when full","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size and takes effect only if the \"Retain old events\" policy setting is enabled.\r\n\r\nIf you enable this policy setting and the \"Retain old events\" policy setting is enabled, the Event Log file is automatically closed and renamed when it is full. A new file is then started.\r\n\r\nIf you disable this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and old events are retained.\r\n\r\nIf you do not configure this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and the old events are retained.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-autobackup-2"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_3","displayName":"Back up log automatically when full","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size and takes effect only if the \"Retain old events\" policy setting is enabled.\r\n\r\nIf you enable this policy setting and the \"Retain old events\" policy setting is enabled, the Event Log file is automatically closed and renamed when it is full. A new file is then started.\r\n\r\nIf you disable this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and old events are retained.\r\n\r\nIf you do not configure this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and the old events are retained.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-autobackup-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_4","displayName":"Back up log automatically when full","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size and takes effect only if the \"Retain old events\" policy setting is enabled.\r\n\r\nIf you enable this policy setting and the \"Retain old events\" policy setting is enabled, the Event Log file is automatically closed and renamed when it is full. A new file is then started.\r\n\r\nIf you disable this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and old events are retained.\r\n\r\nIf you do not configure this policy setting and the \"Retain old events\" policy setting is enabled, new events are discarded and the old events are retained.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-autobackup-4"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_autobackup_4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1","displayName":"Configure log access","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string.\r\n\r\nIf you enable this policy setting, only those users matching the security descriptor can access the log.\r\n\r\nIf you disable or do not configure this policy setting, all authenticated users and system services can write, read, or clear this log.\r\n\r\nNote: If you enable this policy setting, some tools and APIs may ignore it. The same change should be made to the \"Configure log access (legacy)\" policy setting to enforce this change across all tools and APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-1"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_2","displayName":"Configure log access","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You cannot configure write permissions for this log. You must set both \"configure log access\" policy settings for this log in order to affect the both modern and legacy tools.\r\n\r\nIf you enable this policy setting, only those users whose security descriptor matches the configured specified value can access the log.\r\n\r\nIf you disable or do not configure this policy setting, only system software and administrators can read or clear this log.\r\n\r\nNote: If you enable this policy setting, some tools and APIs may ignore it. The same change should be made to the \"Configure log access (legacy)\" policy setting to enforce this change across all tools and APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-2"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_2_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_3","displayName":"Configure log access","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string.\r\n\r\nIf you enable this policy setting, only those users matching the security descriptor can access the log.\r\n\r\nIf you disable or do not configure this policy setting, all authenticated users and system services can write, read, or clear this log.\r\n\r\nNote: If you enable this policy setting, some tools and APIs may ignore it. The same change should be made to the \"Configure log access (legacy)\" policy setting to enforce this change across all tools and APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_3_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_4","displayName":"Configure log access","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You must set both \"configure log access\" policy settings for this log in order to affect the both modern and legacy tools.\r\n\r\nIf you enable this policy setting, only users whose security descriptor matches the configured value can access the log.\r\n\r\nIf you disable or do not configure this policy setting, only system software and administrators can write or clear this log, and any authenticated user can read events from it.\r\n\r\nNote: If you enable this policy setting, some tools and APIs may ignore it. The same change should be made to the \"Configure log access (legacy)\" policy setting to enforce this change across all tools and APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-4"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_4_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_5","displayName":"Configure log access (legacy)","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You must set both \"configure log access\" policy settings for this log in order to affect the both modern and legacy tools.\r\n\r\nIf you enable this policy setting, only those users matching the security descriptor can access the log.\r\n\r\nIf you disable this policy setting, all authenticated users and system services can write, read, or clear this log.\r\n\r\nIf you do not configure this policy setting, the previous policy setting configuration remains in effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-5"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_5_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_5_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_5_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6","displayName":"Configure log access (legacy)","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You cannot configure write permissions for this log.\r\n\r\nIf you enable this policy setting, only those users whose security descriptor matches the configured specified value can access the log.\r\n\r\nIf you disable this policy setting, only system software and administrators can read or clear this log.\r\n\r\nIf you do not configure this policy setting, the previous policy setting configuration remains in effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-6"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7","displayName":"Configure log access (legacy)","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You must set both \"configure log access\" policy settings for this log in order to affect the both modern and legacy tools.\r\n\r\nIf you enable this policy setting, only those users matching the security descriptor can access the log.\r\n\r\nIf you disable this policy setting, all authenticated users and system services can write, read, or clear this log.\r\n\r\nIf you do not configure this policy setting, the previous policy setting configuration remains in effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-7"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_8","displayName":"Configure log access (legacy)","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string.\r\n\r\nIf you enable this policy setting, only users whose security descriptor matches the configured value can access the log.\r\n\r\nIf you disable this policy setting, only system software and administrators can write or clear this log, and any authenticated user can read events from it.\r\n\r\nIf you do not configure this policy setting, the previous policy setting configuration remains in effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-8"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_8_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_8_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_2","displayName":"Control Event Log behavior when the log file reaches its maximum size","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size.\r\n\r\nIf you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost.\r\n\r\nIf you disable or do not configure this policy setting and a log file reaches its maximum size, new events overwrite old events.\r\n\r\nNote: Old events may or may not be retained according to the \"Backup log automatically when full\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-retention-2"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_3","displayName":"Control Event Log behavior when the log file reaches its maximum size","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size.\r\n\r\nIf you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost.\r\n\r\nIf you disable or do not configure this policy setting and a log file reaches its maximum size, new events overwrite old events.\r\n\r\nNote: Old events may or may not be retained according to the \"Backup log automatically when full\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-retention-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_4","displayName":"Control Event Log behavior when the log file reaches its maximum size","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size.\r\n\r\nIf you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost.\r\n\r\nIf you disable or do not configure this policy setting and a log file reaches its maximum size, new events overwrite old events.\r\n\r\nNote: Old events may or may not be retained according to the \"Backup log automatically when full\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-retention-4"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logenabled","displayName":"Turn on logging","description":"This policy setting turns on logging.\r\n\r\nIf you enable or do not configure this policy setting, then events can be written to this log.\r\n\r\nIf the policy setting is disabled, then no new events can be logged. Events can always be read from the log, regardless of this policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logenabled"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1","displayName":"Control the location of the log file","description":"This policy setting controls the location of the log file. The location of the file must be writable by the Event Log service and should only be accessible to administrators.\r\n\r\nIf you enable this policy setting, the Event Log uses the path specified in this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Event Log uses the folder %SYSTEMROOT%\\System32\\winevt\\Logs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logfilepath-1"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1_channel_logfilepath","displayName":"Log File Path","description":null,"helpText":"","infoUrls":[],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_2","displayName":"Control the location of the log file","description":"This policy setting controls the location of the log file. The location of the file must be writable by the Event Log service and should only be accessible to administrators.\r\n\r\nIf you enable this policy setting, the Event Log uses the path specified in this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Event Log uses the folder %SYSTEMROOT%\\System32\\winevt\\Logs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logfilepath-2"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_2_channel_logfilepath","displayName":"Log File Path","description":null,"helpText":"","infoUrls":[],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3","displayName":"Control the location of the log file","description":"This policy setting controls the location of the log file. The location of the file must be writable by the Event Log service and should only be accessible to administrators.\r\n\r\nIf you enable this policy setting, the Event Log uses the path specified in this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Event Log uses the folder %SYSTEMROOT%\\System32\\winevt\\Logs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logfilepath-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3_channel_logfilepath","displayName":"Log File Path","description":null,"helpText":"","infoUrls":[],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_4","displayName":"Control the location of the log file","description":"This policy setting controls the location of the log file. The location of the file must be writable by the Event Log service and should only be accessible to administrators.\r\n\r\nIf you enable this policy setting, the Event Log uses the path specified in this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Event Log uses the folder %SYSTEMROOT%\\System32\\winevt\\Logs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logfilepath-4"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_4_channel_logfilepath","displayName":"Log File Path","description":null,"helpText":"","infoUrls":[],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3","displayName":"Specify the maximum log file size (KB)","description":"This policy setting specifies the maximum size of the log file in kilobytes.\r\n\r\nIf you enable this policy setting, you can configure the maximum log file size to be between 1 megabyte (1024 kilobytes) and 2 terabytes (2147483647 kilobytes), in kilobyte increments.\r\n\r\nIf you disable or do not configure this policy setting, the maximum size of the log file will be set to the locally configured value. This value can be changed by the local administrator using the Log Properties dialog, and it defaults to 1 megabyte.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logmaxsize-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3_channel_logmaxsize","displayName":"Maximum Log Size (KB)","description":null,"helpText":"","infoUrls":[],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":null},{"id":"device_vendor_msft_policy_config_admx_eventlogging_enableprotectedeventlogging","displayName":"Enable Protected Event Logging","description":"\r\nThis policy setting lets you configure Protected Event Logging.\r\n\r\nIf you enable this policy setting, components that support it will use the certificate you supply to encrypt potentially sensitive event log data before writing it to the event log. Data will be encrypted using the Cryptographic Message Syntax (CMS) standard and the public key you provide. You can use the Unprotect-CmsMessage PowerShell cmdlet to decrypt these encrypted messages, provided that you have access to the private key corresponding to the public key that they were encrypted with.\r\n\r\nIf you disable or do not configure this policy setting, components will not encrypt event log messages before writing them to the event log.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlogging#admx-eventlogging-enableprotectedeventlogging"],"categoryId":"75e080fb-3ed7-4a73-a6e0-eb93f0119d68","categoryName":"Event Logging","options":[{"id":"device_vendor_msft_policy_config_admx_eventlogging_enableprotectedeventlogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlogging_enableprotectedeventlogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventlogging_enableprotectedeventlogging_encryptioncertificate","displayName":"Provide an encryption certificate to be used by Protected Event Logging. You may provide either:\n\n - The content of a base-64 encoded X.509 certificate\n - The thumbprint of a certificate that can be found in the Local Machine certificate store (usually deployed by PKI infrastructure)\n - The full path to a certificate (can be local, or a remote share)\n - The path to a directory containing a certificate or certificates (can be local, or a remote share)\n - The subject name of a certificate that can be found in the Local Machine certificate store (usually deployed by PKI infrastructure)\n\nThe resulting certificate must have 'Document Encryption' as an enhanced key usage (1.3.6.1.4.1.311.80.1), as well as either Data Encipherment or Key Encipherment key usages enabled.","description":null,"helpText":"","infoUrls":[],"categoryId":"75e080fb-3ed7-4a73-a6e0-eb93f0119d68","categoryName":"Event Logging","options":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogram","displayName":"Events.asp program","description":"This is the program that will be invoked when the user clicks the events.asp link.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventviewer#admx-eventviewer-eventviewer-redirectionprogram"],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":[{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogram_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogram_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogram_eventviewer_redirectionprogram","displayName":"Events.asp program","description":null,"helpText":"","infoUrls":[],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters","displayName":"Events.asp program command line parameters","description":"This specifies the command line parameters that will be passed to the events.asp program\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventviewer#admx-eventviewer-eventviewer-redirectionprogramcommandlineparameters"],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":[{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters_eventviewer_redirectionprogramcommandlineparameters","displayName":"Events.asp program command line parameters","description":null,"helpText":"","infoUrls":[],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionurl","displayName":"Events.asp URL","description":"This is the URL that will be passed to the Description area in the Event Properties dialog box. Change this value if you want to use a different Web server to handle event information requests.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventviewer#admx-eventviewer-eventviewer-redirectionurl"],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":[{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionurl_eventviewer_redirectionurl","displayName":"Events.asp URL","description":null,"helpText":"","infoUrls":[],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":null},{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl","displayName":"Set a support web page link","description":"Sets the target of the More Information link that will be displayed when the user attempts to run a program that is blocked by policy.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-explorer#admx-explorer-admininfourl"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl_admininfourl_textbox","displayName":"Support Web page URL","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_explorer_disableroamedprofileinit","displayName":"Do not reinitialize a pre-existing roamed user profile when it is loaded on a machine for the first time","description":"This policy setting allows administrators who have configured roaming profile in conjunction with Delete Cached Roaming Profile Group Policy setting to ensure that Explorer will not reinitialize default program associations and other settings to default values. \r\n\r\nIf you enable this policy setting on a machine that does not contain all programs installed in the same manner as it was on the machine on which the user had last logged on, unexpected behavior could occur. \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-explorer#admx-explorer-disableroamedprofileinit"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_explorer_disableroamedprofileinit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_explorer_disableroamedprofileinit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_hibernate","displayName":"Allow hibernate (S4) when starting from a Windows To Go workspace","description":"\r\n\r\nSpecifies whether the PC can use the hibernation sleep state (S4) when started from a Windows To Go workspace.\r\n\r\nIf you enable this setting, Windows, when started from a Windows To Go workspace, can hibernate the PC.\r\n\r\nIf you disable or don't configure this setting, Windows, when started from a Windows To Go workspace, can't hibernate the PC.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-externalboot#admx-externalboot-portableoperatingsystem-hibernate"],"categoryId":"68a3b82d-d1f4-422d-bfee-2168ec260ad7","categoryName":"Portable Operating System","options":[{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_hibernate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_hibernate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_launcher","displayName":"Windows To Go Default Startup Options","description":"\r\n\r\nThis policy setting controls whether the PC will boot to Windows To Go if a USB device containing a Windows To Go workspace is connected, and controls whether users can make changes using the Windows To Go Startup Options Control Panel item.\r\n\r\nIf you enable this setting, booting to Windows To Go when a USB device is connected will be enabled, and users will not be able to make changes using the Windows To Go Startup Options Control Panel item.\r\n\r\nIf you disable this setting, booting to Windows To Go when a USB device is connected will not be enabled unless a user configures the option manually in the BIOS or other boot order configuration.\r\n\r\nIf you do not configure this setting, users who are members of the Administrators group can make changes using the Windows To Go Startup Options Control Panel item.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-externalboot#admx-externalboot-portableoperatingsystem-launcher"],"categoryId":"68a3b82d-d1f4-422d-bfee-2168ec260ad7","categoryName":"Portable Operating System","options":[{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_launcher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_launcher_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_sleep","displayName":"Disallow standby sleep states (S1-S3) when starting from a Windows to Go workspace","description":"\r\n\r\nSpecifies whether the PC can use standby sleep states (S1-S3) when starting from a Windows To Go workspace.\r\n\r\nIf you enable this setting, Windows, when started from a Windows To Go workspace, can't use standby states to make the PC sleep.\r\n\r\nIf you disable or don't configure this setting, Windows, when started from a Windows To Go workspace, can use standby states to make the PC sleep.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-externalboot#admx-externalboot-portableoperatingsystem-sleep"],"categoryId":"68a3b82d-d1f4-422d-bfee-2168ec260ad7","categoryName":"Portable Operating System","options":[{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_sleep_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_sleep_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy","displayName":"Configure Corrupted File Recovery behavior","description":"This policy setting allows you to configure the recovery behavior for corrupted files to one of three states:\r\n\r\nRegular: Detection, troubleshooting, and recovery of corrupted files will automatically start with a minimal UI display. Windows will attempt to present you with a dialog box when a system restart is required. This is the default recovery behavior for corrupted files.\r\n\r\nSilent: Detection, troubleshooting, and recovery of corrupted files will automatically start with no UI. Windows will log an administrator event when a system restart is required. This behavior is recommended for headless operation.\r\n\r\nTroubleshooting Only: Detection and troubleshooting of corrupted files will automatically start with no UI. Recovery is not attempted automatically. Windows will log an administrator event with instructions if manual recovery is possible.\r\n\r\nIf you enable this setting, the recovery behavior for corrupted files will be set to either the regular (default), silent, or troubleshooting only state.\r\n\r\nIf you disable this setting, the recovery behavior for corrupted files will be disabled. No troubleshooting or resolution will be attempted.\r\n\r\nIf you do not configure this setting, the recovery behavior for corrupted files will be set to the regular recovery behavior.\r\n\r\nNo system or service restarts are required for changes to this policy to take immediate effect after a Group Policy refresh.\r\n\r\nNote: This policy setting will take effect only when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, system file recovery will not be attempted. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filerecovery#admx-filerecovery-wdiscenarioexecutionpolicy"],"categoryId":"736134cb-4d82-427a-97b7-d219ac6a22f0","categoryName":"Corrupted File Recovery","options":[{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"736134cb-4d82-427a-97b7-d219ac6a22f0","categoryName":"Corrupted File Recovery","options":[{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_1","displayName":"Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_2","displayName":"Regular","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_3","displayName":"Silent","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_fileservervssprovider_pol_encryptprotocol","displayName":"Allow or Disallow use of encryption to protect the RPC protocol messages between File Share Shadow Copy Provider running on application server and File Share Shadow Copy Agent running on the file servers.","description":"Determines whether the RPC protocol messagese used by VSS for SMB2 File Shares feature is enabled.\r\n\r\nVSS for SMB2 File Shares feature enables VSS aware backup applications to perform application consistent backup and restore of VSS aware applications storing data on SMB2 File Shares.\r\n\r\nBy default, the RPC protocol message between File Server VSS provider and File Server VSS Agent is signed but not encrypted. \r\n\r\nNote: To make changes to this setting effective, you must restart Volume Shadow Copy (VSS) Service .\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-fileservervssprovider#admx-fileservervssprovider-pol-encryptprotocol"],"categoryId":"d9f5ccc9-5180-43b7-9c81-89ac3364ce00","categoryName":"File Share Shadow Copy Provider","options":[{"id":"device_vendor_msft_policy_config_admx_fileservervssprovider_pol_encryptprotocol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_fileservervssprovider_pol_encryptprotocol_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_disablecompression","displayName":"Do not allow compression on all NTFS volumes","description":"Compression can add to the processing overhead of filesystem operations. Enabling this setting will prevent access to and creation of compressed files. \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-disablecompression"],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_disablecompression_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_disablecompression_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_disabledeletenotification","displayName":"Disable delete notifications on all volumes","description":"Delete notification is a feature that notifies the underlying storage device of clusters that are freed due to a file delete operation.\r\n\r\nA value of 0, the default, will enable delete notifications for all volumes. \r\nA value of 1 will disable delete notifications for all volumes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-disabledeletenotification"],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_disabledeletenotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_disabledeletenotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_disableencryption","displayName":"Do not allow encryption on all NTFS volumes","description":"Encryption can add to the processing overhead of filesystem operations. Enabling this setting will prevent access to and creation of encrypted files\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-disableencryption"],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_disableencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_disableencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_enablepagefileencryption","displayName":"Enable NTFS pagefile encryption","description":"Encrypting the page file prevents malicious users from reading data that has been paged to disk, but also adds processing overhead for filesystem operations. Enabling this setting will cause the page files to be encrypted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-enablepagefileencryption"],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_enablepagefileencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_enablepagefileencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_longpathsenabled","displayName":"Enable Win32 long paths","description":"Enabling Win32 long paths will allow manifested win32 applications and Windows Store applications to access paths beyond the normal 260 character limit per node on file systems that support it. Enabling this setting will cause the long paths to be accessible within the process.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-longpathsenabled"],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_longpathsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_longpathsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings","displayName":"Short name creation options","description":"These settings provide control over whether or not short names are generated during file creation. Some applications require short names for compatibility, but short names have a negative performance impact on the system.\r\n\r\nIf you enable short names on all volumes then short names will always be generated. If you disable them on all volumes then they will never be generated. If you set short name creation to be configurable on a per volume basis then an on-disk flag will determine whether or not short names are created on a given volume. If you disable short name creation on all data volumes then short names will only be generated for files created on the system volume.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-shortnamecreationsettings"],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_shortnamecreationsetting_levels","displayName":"Short name creation options","description":null,"helpText":"","infoUrls":[],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_shortnamecreationsetting_levels_0","displayName":"Enable on all volumes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_shortnamecreationsetting_levels_1","displayName":"Disable on all volumes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_shortnamecreationsetting_levels_2","displayName":"Enable / disable on a per volume basis","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_shortnamecreationsettings_shortnamecreationsetting_levels_3","displayName":"Disable on all data volumes","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation","displayName":"Selectively allow the evaluation of a symbolic link","description":"Symbolic links can introduce vulnerabilities in certain applications. To mitigate this issue, you can selectively enable or disable the evaluation of these types of symbolic links:\r\n\r\nLocal Link to a Local Target\r\nLocal Link to a Remote Target\r\nRemote Link to Remote Target\r\nRemote Link to Local Target\r\n\r\nFor further information please refer to the Windows Help section\r\n\r\nNOTE: If this policy is Disabled or Not Configured, local administrators may select the types of symbolic links to be evaluated.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-symlinkevaluation"],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2l","displayName":"Local Link to Local Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2l_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2l_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2r","displayName":"Local Link to a Remote Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2r_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2r_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2l","displayName":"Remote Link to Local Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2l_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2l_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2r","displayName":"Remote Link to Remote Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2r_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2r_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_filesys_txfdeprecatedfunctionality","displayName":"Enable / disable TXF deprecated features","description":"TXF deprecated features included savepoints, secondary RM, miniversion and roll forward. Please enable it if you want to use the APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-txfdeprecatedfunctionality"],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_txfdeprecatedfunctionality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_txfdeprecatedfunctionality_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_folderredirection_localizexprelativepaths_2","displayName":"Use localized subfolder names when redirecting Start Menu and My Documents","description":"This policy setting allows the administrator to define whether Folder Redirection should use localized names for the All Programs, Startup, My Music, My Pictures, and My Videos subfolders when redirecting the parent Start Menu and legacy My Documents folder respectively.\r\n\r\nIf you enable this policy setting, Windows Vista, Windows 7, Windows 8, and Windows Server 2012 will use localized folder names for these subfolders when redirecting the Start Menu or legacy My Documents folder.\r\n\r\nIf you disable or not configure this policy setting, Windows Vista, Windows 7, Windows 8, and Windows Server 2012 will use the standard English names for these subfolders when redirecting the Start Menu or legacy My Documents folder.\r\n\r\nNote: This policy is valid only on Windows Vista, Windows 7, Windows 8, and Windows Server 2012 when it processes a legacy redirection policy already deployed for these folders in your existing localized environment.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-folderredirection#admx-folderredirection-localizexprelativepaths-2"],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_folderredirection_localizexprelativepaths_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_folderredirection_localizexprelativepaths_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_folderredirection_primarycomputer_fr_2","displayName":"Redirect folders on primary computers only","description":"This policy setting controls whether folders are redirected on a user's primary computers only. This policy setting is useful to improve logon performance and to increase security for user data on computers where the user might not want to download private data, such as on a meeting room computer or on a computer in a remote office.\r\n\r\nTo designate a user's primary computers, an administrator must use management software or a script to add primary computer attributes to the user's account in Active Directory Domain Services (AD DS). This policy setting also requires the Windows Server 2012 version of the Active Directory schema to function.\r\n\r\nIf you enable this policy setting and the user has redirected folders, such as the Documents and Pictures folders, the folders are redirected on the user's primary computer only.\r\n\r\nIf you disable or do not configure this policy setting and the user has redirected folders, the folders are redirected on every computer that the user logs on to.\r\n\r\nNote: If you enable this policy setting in Computer Configuration and User Configuration, the Computer Configuration policy setting takes precedence.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-folderredirection#admx-folderredirection-primarycomputer-fr-2"],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_folderredirection_primarycomputer_fr_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_folderredirection_primarycomputer_fr_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_fthsvc_wdiscenarioexecutionpolicy","displayName":"Configure Scenario Execution Level","description":"This policy setting permits or prohibits the Diagnostic Policy Service (DPS) from automatically resolving any heap corruption problems.\r\n\r\nIf you enable this policy setting, the DPS detects, troubleshoots, and attempts to resolve automatically any heap corruption problems.\r\n\r\nIf you disable this policy setting, Windows cannot detect, troubleshoot, and attempt to resolve automatically any heap corruption problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS enables Fault Tolerant Heap for resolution by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nThis policy setting takes effect only when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n\r\nNo system restart or service restart is required for this policy setting to take effect: changes take effect immediately.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-fthsvc#admx-fthsvc-wdiscenarioexecutionpolicy"],"categoryId":"476e0bfc-ddb6-4612-8446-bed86e875141","categoryName":"Fault Tolerant Heap","options":[{"id":"device_vendor_msft_policy_config_admx_fthsvc_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_fthsvc_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_blockuserinputmethodsforsignin","displayName":"Disallow copying of user input methods to the system account for sign-in","description":"\r\n This policy prevents automatic copying of user input methods to the system account for use on the sign-in screen. The user is restricted to the set of input methods that are enabled in the system account.\r\n\r\n Note this does not affect the availability of user input methods on the lock screen or with the UAC prompt.\r\n\r\n If the policy is Enabled, then the user will get input methods enabled for the system account on the sign-in page.\r\n\r\n If the policy is Disabled or Not Configured, then the user will be able to use input methods enabled for their user account on the sign-in page.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-blockuserinputmethodsforsignin"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_blockuserinputmethodsforsignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_blockuserinputmethodsforsignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_customlocalesnoselect_2","displayName":"Disallow selection of Custom Locales","description":"This policy setting prevents a user from selecting a supplemental custom locale as their user locale. The user is restricted to the set of locales that are installed with the operating system.\r\n\r\nThis does not affect the selection of replacement locales. To prevent the selection of replacement locales, adjust the permissions of the %windir%\\Globalization directory to prevent the installation of locales by unauthorized users.\r\n\r\nThe policy setting \"Restrict user locales\" can also be enabled to disallow selection of a custom locale, even if this policy setting is not configured.\r\n\r\nIf you enable this policy setting, the user cannot select a custom locale as their user locale, but they can still select a replacement locale if one is installed.\r\n\r\nIf you disable or do not configure this policy setting, the user can select a custom locale as their user locale.\r\n\r\nIf this policy setting is enabled at the machine level, it cannot be disabled by a per-user policy setting. If this policy setting is disabled at the machine level, the per-user policy setting will be ignored. If this policy setting is not configured at the machine level, restrictions will be based on per-user policy settings.\r\n\r\nTo set this policy setting on a per-user basis, make sure that you do not configure the per-machine policy setting.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-customlocalesnoselect-2"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_customlocalesnoselect_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_customlocalesnoselect_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_implicitdatacollectionoff_2","displayName":"Turn off automatic learning","description":"\r\n This policy setting turns off the automatic learning component of handwriting recognition personalization. \r\n\r\n\t\tAutomatic learning enables the collection and storage of text and ink written by the user in order to help adapt handwriting recognition to the vocabulary and handwriting style of the user. \r\n\r\n\t\tText that is collected includes all outgoing messages in Windows Mail, and MAPI enabled email clients, as well as URLs from the Internet Explorer browser history. The information that is stored includes word frequency and new words not already known to the handwriting recognition engines (for example, proper names and acronyms). Deleting email content or the browser history does not delete the stored personalization data. Ink entered through Input Panel is collected and stored. \r\n\r\n\t\tNote: Automatic learning of both text and ink might not be available for all languages, even when handwriting personalization is available. See Tablet PC Help for more information.\r\n\r\n\t\tIf you enable this policy setting, automatic learning stops and any stored data is deleted. Users cannot configure this setting in Control Panel.\r\n\r\n\t\tIf you disable this policy setting, automatic learning is turned on. Users cannot configure this policy setting in Control Panel. Collected data is only used for handwriting recognition, if handwriting personalization is turned on.\r\n\r\n\t\tIf you do not configure this policy, users can choose to enable or disable automatic learning either from the Handwriting tab in the Tablet Settings in Control Panel or from the opt-in dialog.\r\n\r\n\t\tThis policy setting is related to the \"Turn off handwriting personalization\" policy setting.\r\n\r\n\t\tNote: The amount of stored ink is limited to 50 MB and the amount of text information to approximately 5 MB. When these limits are reached and new data is collected, old data is deleted to make room for more recent data.\r\n\r\n\t\tNote: Handwriting personalization works only for Microsoft handwriting recognizers, and not with third-party recognizers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-implicitdatacollectionoff-2"],"categoryId":"9a79d480-8cb4-47b5-95c7-5da56eea5bb8","categoryName":"Handwriting personalization","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_implicitdatacollectionoff_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_implicitdatacollectionoff_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict","displayName":"Restrict system locales","description":"This policy setting restricts the permitted system locales to the specified list. If the list is empty, it locks the system locale to its current value. This policy setting does not change the existing system locale; however, the next time that an administrator attempts to change the computer's system locale, they will be restricted to the specified list.\r\n\r\nThe locale list is specified using language names, separated by a semicolon (;). For example, en-US is English (United States). Specifying \"en-US;en-CA\" would restrict the system locale to English (United States) and English (Canada).\r\n\r\nIf you enable this policy setting, administrators can select a system locale only from the specified system locale list.\r\n\r\nIf you disable or do not configure this policy setting, administrators can select any system locale shipped with the operating system.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-localesystemrestrict"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict_allowablesystemlocaletaglist","displayName":"System Locales","description":null,"helpText":"","infoUrls":[],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":null},{"id":"device_vendor_msft_policy_config_admx_globalization_localeuserrestrict_2","displayName":"Restrict user locales","description":"This policy setting restricts users on a computer to the specified list of user locales. If the list is empty, it locks all user locales to their current values. This policy setting does not change existing user locale settings; however, the next time a user attempts to change their user locale, their choices will be restricted to locales in this list.\r\n\r\nTo set this policy setting on a per-user basis, make sure that you do not configure the per-computer policy setting.\r\n\r\nThe locale list is specified using language tags, separated by a semicolon (;). For example, en-US is English (United States). Specifying \"en-CA;fr-CA\" would restrict the user locale to English (Canada) and French (Canada).\r\n\r\nIf you enable this policy setting, only locales in the specified locale list can be selected by users.\r\n\r\nIf you disable or do not configure this policy setting, users can select any locale installed on the computer, unless restricted by the \"Disallow selection of Custom Locales\" policy setting.\r\n\r\nIf this policy setting is enabled at the computer level, it cannot be disabled by a per-user policy. If this policy setting is disabled at the computer level, the per-user policy is ignored. If this policy setting is not configured at the computer level, restrictions are based on per-user policies.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-localeuserrestrict-2"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_localeuserrestrict_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_localeuserrestrict_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_localeuserrestrict_2_allowableuserlocaletaglist","displayName":"User Locales","description":null,"helpText":"","infoUrls":[],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage","displayName":"Restricts the UI language Windows uses for all logged users","description":"This policy setting restricts the Windows UI language for all users.\r\n\r\nThis is a policy setting for computers with more than one UI language installed.\r\n\r\nIf you enable this policy setting, the UI language of Windows menus and dialogs for systems with more than one language will follow the language specified by the administrator as the system UI languages. The UI language selected by the user will be ignored if it is different than any of the system UI languages.\r\n\r\nIf you disable or do not configure this policy setting, the user can specify which UI language is used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-lockmachineuilanguage"],"categoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","categoryName":"Regional and Language Options","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect","displayName":"Restrict users to the following language:","description":null,"helpText":"","infoUrls":[],"categoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","categoryName":"Regional and Language Options","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_en-us","displayName":"English","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_ja-jp","displayName":"Japanese","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_ko-kr","displayName":"Korean","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_de-de","displayName":"German","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_zh-cn","displayName":"Simplified Chinese","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_zh-tw","displayName":"Traditional Chinese (Taiwan)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_fr-fr","displayName":"French","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_es-es","displayName":"Spanish","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_it-it","displayName":"Italian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_sv-se","displayName":"Swedish","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_nl-nl","displayName":"Dutch","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_pt-br","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_fi-fi","displayName":"Finnish","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_nb-no","displayName":"Norwegian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_da-dk","displayName":"Danish","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_hu-hu","displayName":"Hungarian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_pl-pl","displayName":"Polish","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_ru-ru","displayName":"Russian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_cs-cz","displayName":"Czech","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_el-gr","displayName":"Greek","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_pt-pt","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_tr-tr","displayName":"Turkish","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_ar-sa","displayName":"Arabic","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_he-il","displayName":"Hebrew","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_sk-sk","displayName":"Slovak","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_sl-si","displayName":"Slovenian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_ro-ro","displayName":"Romanian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_hr-hr","displayName":"Croatian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_bg-bg","displayName":"Bulgarian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_et-ee","displayName":"Estonian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_lt-lt","displayName":"Lithuanian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_lv-lv","displayName":"Latvian","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_th-th","displayName":"Thai","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_zh-hk","displayName":"Traditional Chinese (Hong Kong)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_sr-latn-cs","displayName":"Serbian (Latin)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_uilangselect_uk-ua","displayName":"Ukrainian","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_preventgeoidchange_2","displayName":"Disallow changing of geographic location","description":"This policy setting prevents users from changing their user geographical location (GeoID).\r\n\r\nIf you enable this policy setting, users cannot change their GeoID.\r\n\r\nIf you disable or do not configure this policy setting, users may select any GeoID.\r\n\r\nIf you enable this policy setting at the computer level, it cannot be disabled by a per-user policy setting. If you disable this policy setting at the computer level, the per-user policy is ignored. If you do not configure this policy setting at the computer level, restrictions are based on per-user policy settings.\r\n\r\nTo set this policy setting on a per-user basis, make sure that the per-computer policy setting is not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-preventgeoidchange-2"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_preventgeoidchange_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_preventgeoidchange_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_globalization_preventuseroverrides_2","displayName":"Disallow user override of locale settings","description":"This policy setting prevents the user from customizing their locale by changing their user overrides.\r\n\r\nAny existing overrides in place when this policy is enabled will be frozen. To remove existing user overrides, first reset the user(s) values to the defaults and then apply this policy.\r\n\r\nWhen this policy setting is enabled, users can still choose alternate locales installed on the system unless prevented by other policies, however, they will be unable to customize those choices. The user cannot customize their user locale with user overrides.\r\n\r\nIf this policy setting is disabled or not configured, then the user can customize their user locale overrides.\r\n\r\nIf this policy is set to Enabled at the computer level, then it cannot be disabled by a per-User policy. If this policy is set to Disabled at the computer level, then the per-User policy will be ignored. If this policy is set to Not Configured at the computer level, then restrictions will be based on per-User policies.\r\n\r\nTo set this policy on a per-user basis, make sure that the per-computer policy is set to Not Configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-preventuseroverrides-2"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_preventuseroverrides_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_preventuseroverrides_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_allowx-forestpolicy-and-rup","displayName":"Allow cross-forest user policy and roaming user profiles","description":"This policy setting allows user-based policy processing, roaming user profiles, and user object logon scripts for interactive logons across forests.\r\n\r\nThis policy setting affects all user accounts that interactively log on to a computer in a different forest when a trust across forests or a two-way forest trust exists.\r\n\r\nIf you do not configure this policy setting:\r\n- No user-based policy settings are applied from the user's forest.\r\n- Users do not receive their roaming profiles; they receive a local profile on the computer from the local forest. A warning message appears to the user, and an event log message (1529) is posted.\r\n- Loopback Group Policy processing is applied, using the Group Policy Objects (GPOs) that are scoped to the computer.\r\n- An event log message (1109) is posted, stating that loopback was invoked in Replace mode.\r\n\r\nIf you enable this policy setting, the behavior is exactly the same as in Windows 2000: user policy is applied, and a roaming user profile is allowed from the trusted forest.\r\n\r\nIf you disable this policy setting, the behavior is the same as if it is not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-allowx-forestpolicy-and-rup"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_allowx-forestpolicy-and-rup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_allowx-forestpolicy-and-rup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_corpconnsyncwaittime","displayName":"Specify workplace connectivity wait time for policy processing","description":"This policy setting specifies how long Group Policy should wait for workplace connectivity notifications during startup policy processing. If the startup policy processing is synchronous, the computer is blocked until workplace connectivity is available or the wait time is reached. If the startup policy processing is asynchronous, the computer is not blocked and policy processing will occur in the background. In either case, configuring this policy setting overrides any system-computed wait times.\r\n\r\nIf you enable this policy setting, Group Policy uses this administratively configured maximum wait time for workplace connectivity, and overrides any default or system-computed wait time.\r\n\r\nIf you disable or do not configure this policy setting, Group Policy will use the default wait time of 60 seconds on computers running Windows operating systems greater than Windows 7 configured for workplace connectivity.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-corpconnsyncwaittime"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_corpconnsyncwaittime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_corpconnsyncwaittime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_corpconnsyncwaittime_corpconnsyncwaittime_seconds","displayName":"Amount of time to wait (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt","displayName":"Configure software Installation policy processing","description":"This policy setting determines when software installation policies are updated.\r\n\r\nThis policy setting affects all policy settings that use the software installation component of Group Policy, such as policy settings in Software Settings\\Software Installation. You can set software installation policy only for Group Policy Objects stored in Active Directory, not for Group Policy Objects on the local computer.\r\n\r\nThis policy setting overrides customized settings that the program implementing the software installation policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy setting implementations specify that they are updated only when changed. However, you might want to update unchanged policy settings, such as reapplying a desired policies in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-appmgmt"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_cse_nochanges1","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_cse_nochanges1_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_cse_nochanges1_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_cse_slowlink1","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_cse_slowlink1_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_cse_slowlink1_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota","displayName":"Configure disk quota policy processing","description":"This policy setting determines when disk quota policies are updated.\r\n\r\nThis policy setting affects all policies that use the disk quota component of Group Policy, such as those in Computer Configuration\\Administrative Templates\\System\\Disk Quotas.\r\n\r\nThis policy setting overrides customized settings that the program implementing the disk quota policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-diskquota"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_nobackground2","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_nobackground2_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_nobackground2_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_nochanges2","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_nochanges2_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_nochanges2_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_slowlink2","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_slowlink2_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_diskquota_cse_slowlink2_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery","displayName":"Configure EFS recovery policy processing","description":"This policy setting determines when encryption policies are updated.\r\n\r\nThis policy setting affects all policies that use the encryption component of Group Policy, such as policies related to encryption in Windows Settings\\Security Settings.\r\n\r\nIt overrides customized settings that the program implementing the encryption policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-efsrecovery"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nobackground3","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nobackground3_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nobackground3_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nochanges3","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nochanges3_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nochanges3_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_slowlink3","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_slowlink3_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_slowlink3_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection","displayName":"Configure folder redirection policy processing","description":"This policy setting determines when folder redirection policies are updated.\r\n\r\nThis policy setting affects all policies that use the folder redirection component of Group Policy, such as those in WindowsSettings\\Folder Redirection. You can only set folder redirection policy for Group Policy objects, stored in Active Directory, not for Group Policy objects on the local computer.\r\n\r\nThis policy setting overrides customized settings that the program implementing the folder redirection policy setting set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-folderredirection"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_nochanges4","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_nochanges4_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_nochanges4_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_slowlink4","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_slowlink4_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_slowlink4_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem","displayName":"Configure Internet Explorer Maintenance policy processing","description":"This policy setting determines when Internet Explorer Maintenance policies are updated.\r\n\r\nThis policy setting affects all policies that use the Internet Explorer Maintenance component of Group Policy, such as those in Windows Settings\\Internet Explorer Maintenance.\r\n\r\nThis policy setting overrides customized settings that the program implementing the Internet Explorer Maintenance policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-iem"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_nobackground5","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_nobackground5_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_nobackground5_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_nochanges5","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_nochanges5_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_nochanges5_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_slowlink5","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_slowlink5_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_slowlink5_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity","displayName":"Configure IP security policy processing","description":"This policy setting determines when IP security policies are updated.\r\n\r\nThis policy setting affects all policies that use the IP security component of Group Policy, such as policies in Computer Configuration\\Windows Settings\\Security Settings\\IP Security Policies on Local Machine.\r\n\r\nThis policy setting overrides customized settings that the program implementing the IP security policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-ipsecurity"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nobackground6","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nobackground6_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nobackground6_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nochanges6","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nochanges6_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nochanges6_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_slowlink6","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_slowlink6_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_slowlink6_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry","displayName":"Configure registry policy processing","description":"This policy setting determines when registry policies are updated.\r\n\r\nThis policy setting affects all policies in the Administrative Templates folder and any other policies that store values in the registry. It overrides customized settings that the program implementing a registry policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-registry"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nobackground10","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nobackground10_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nobackground10_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nochanges10","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nochanges10_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nochanges10_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts","displayName":"Configure scripts policy processing","description":"This policy setting determines when policies that assign shared scripts are updated.\r\n\r\nThis policy setting affects all policies that use the scripts component of Group Policy, such as those in WindowsSettings\\Scripts. It overrides customized settings that the program implementing the scripts policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-scripts"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nobackground7","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nobackground7_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nobackground7_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nochanges7","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nochanges7_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nochanges7_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_slowlink7","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_slowlink7_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_slowlink7_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security","displayName":"Configure security policy processing","description":"This policy setting determines when security policies are updated.\r\n\r\nThis policy setting affects all policies that use the security component of Group Policy, such as those in Windows Settings\\Security Settings.\r\n\r\nThis policy setting overrides customized settings that the program implementing the security policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they be updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-security"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nobackground11","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nobackground11_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nobackground11_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nochanges11","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nochanges11_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nochanges11_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired","displayName":"Configure wired policy processing","description":"This policy setting determines when policies that assign wired network settings are updated.\r\n\r\nThis policy setting affects all policies that use the wired network component of Group Policy, such as those in Windows Settings\\Wired Network Policies.\r\n\r\nIt overrides customized settings that the program implementing the wired network set when it was installed.\r\n\r\nIf you enable this policy, you can use the check boxes provided to change the options.\r\n\r\nIf you disable this setting or do not configure it, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-wired"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_nobackground8","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_nobackground8_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_nobackground8_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_nochanges8","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_nochanges8_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_nochanges8_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_slowlink8","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_slowlink8_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wired_cse_slowlink8_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless","displayName":"Configure wireless policy processing","description":"This policy setting determines when policies that assign wireless network settings are updated.\r\n\r\nThis policy setting affects all policies that use the wireless network component of Group Policy, such as those in WindowsSettings\\Wireless Network Policies.\r\n\r\nIt overrides customized settings that the program implementing the wireless network set when it was installed.\r\n\r\nIf you enable this policy, you can use the check boxes provided to change the options.\r\n\r\nIf you disable this setting or do not configure it, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-wireless"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_nobackground9","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_nobackground9_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_nobackground9_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_nochanges9","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_nochanges9_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_nochanges9_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_slowlink9","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_slowlink9_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_wireless_cse_slowlink9_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_denyrsoptointeractiveuser_2","displayName":"Determine if interactive users can generate Resultant Set of Policy data","description":"This policy setting controls the ability of users to view their Resultant Set of Policy (RSoP) data.\r\n\r\nBy default, interactively logged on users can view their own Resultant Set of Policy (RSoP) data.\r\n\r\nIf you enable this policy setting, interactive users cannot generate RSoP data.\r\n\r\nIf you disable or do not configure this policy setting, interactive users can generate RSoP.\r\n\r\nNote: This policy setting does not affect administrators. If you enable or disable this policy setting, by default administrators can view RSoP data.\r\n\r\nNote: To view RSoP data on a client computer, use the RSoP snap-in for the Microsoft Management Console. You can launch the RSoP snap-in from the command line by typing RSOP.msc\r\n\r\nNote: This policy setting exists as both a User Configuration and Computer Configuration setting.\r\n\r\nAlso, see the \"Turn off Resultant set of Policy logging\" policy setting in Computer Configuration\\Administrative Templates\\System\\GroupPolicy.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-denyrsoptointeractiveuser-2"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_denyrsoptointeractiveuser_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_denyrsoptointeractiveuser_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disableaoacprocessing","displayName":"Turn off Group Policy Client Service AOAC optimization","description":"This policy setting prevents the Group Policy Client Service from stopping when idle.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-disableaoacprocessing"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disableaoacprocessing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disableaoacprocessing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disablebackgroundpolicy","displayName":"Turn off background refresh of Group Policy","description":"This policy setting prevents Group Policy from being updated while the computer is in use. This policy setting applies to Group Policy for computers, users, and domain controllers.\r\n\r\nIf you enable this policy setting, the system waits until the current user logs off the system before updating the computer and user settings.\r\n\r\nIf you disable or do not configure this policy setting, updates can be applied while users are working. The frequency of updates is determined by the \"Set Group Policy refresh interval for computers\" and \"Set Group Policy refresh interval for users\" policy settings.\r\n\r\nNote: If you make changes to this policy setting, you must restart your computer for it to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-disablebackgroundpolicy"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disablebackgroundpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disablebackgroundpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disablelgpoprocessing","displayName":"Turn off Local Group Policy Objects processing","description":"This policy setting prevents Local Group Policy Objects (Local GPOs) from being applied.\r\n\r\nBy default, the policy settings in Local GPOs are applied before any domain-based GPO policy settings. These policy settings can apply to both users and the local computer. You can disable the processing and application of all Local GPOs to ensure that only domain-based GPOs are applied.\r\n\r\nIf you enable this policy setting, the system does not process and apply any Local GPOs.\r\n\r\nIf you disable or do not configure this policy setting, Local GPOs continue to be applied.\r\n\r\nNote: For computers joined to a domain, it is strongly recommended that you only configure this policy setting in domain-based GPOs. This policy setting will be ignored on computers that are joined to a workgroup.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-disablelgpoprocessing"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disablelgpoprocessing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disablelgpoprocessing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disableusersfrommachgp","displayName":"Remove users' ability to invoke machine policy refresh","description":"This policy setting allows you to control a user's ability to invoke a computer policy refresh.\r\n\r\nIf you enable this policy setting, users are not able to invoke a refresh of computer policy. Computer policy will still be applied at startup or when an official policy refresh occurs.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior applies. By default, computer policy is applied when the computer starts up. It also applies at a specified refresh interval or when manually invoked by the user.\r\n\r\nNote: This policy setting applies only to non-administrators. Administrators can still invoke a refresh of computer policy at any time, no matter how this policy setting is configured.\r\n\r\nAlso, see the \"Set Group Policy refresh interval for computers\" policy setting to change the policy refresh interval.\r\n\r\nNote: If you make changes to this policy setting, you must restart your computer for it to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-disableusersfrommachgp"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disableusersfrommachgp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_disableusersfrommachgp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablecdp","displayName":"Continue experiences on this device","description":"\r\nThis policy setting determines whether the Windows device is allowed to participate in cross-device experiences (continue experiences).\r\n\r\nIf you enable this policy setting, the Windows device is discoverable by other Windows devices that belong to the same user, and can participate in cross-device experiences.\r\n\r\nIf you disable this policy setting, the Windows device is not discoverable by other devices, and cannot participate in cross-device experiences.\r\n\r\nIf you do not configure this policy setting, the default behavior depends on the Windows edition. Changes to this policy take effect on reboot.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-enablecdp"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablecdp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablecdp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimization","displayName":"Configure Group Policy Caching","description":"\r\n This policy setting allows you to configure Group Policy caching behavior.\r\n\r\n If you enable or do not configure this policy setting, Group Policy caches policy information after every background processing session. This cache saves applicable GPOs and the settings contained within them. When Group Policy runs in synchronous foreground mode, it refers to this cache, which enables it to run faster. When the cache is read, Group Policy attempts to contact a logon domain controller to determine the link speed. When Group Policy runs in background mode or asynchronous foreground mode, it continues to download the latest version of the policy information, and it uses a bandwidth estimate to determine slow link thresholds. (See the “Configure Group Policy Slow Link Detection” policy setting to configure asynchronous foreground behavior.)\r\n\r\n The slow link value that is defined in this policy setting determines how long Group Policy will wait for a response from the domain controller before reporting the link speed as slow. The default is 500 milliseconds.\r\n\r\n The timeout value that is defined in this policy setting determines how long Group Policy will wait for a response from the domain controller before determining that there is no network connectivity. This stops the current Group Policy processing. Group Policy will run in the background the next time a connection to a domain controller is established. Setting this value too high might result in longer waits for the user at boot or logon. The default is 5000 milliseconds.\r\n\r\n If you disable this policy setting, the Group Policy client will not cache applicable GPOs or settings that are contained within the GPOs. When Group Policy runs synchronously, it downloads the latest version of the policy from the network and uses bandwidth estimates to determine slow link thresholds. (See the “Configure Group Policy Slow Link Detection” policy setting to configure asynchronous foreground behavior.)\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-enablelogonoptimization"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimization_syncmodenodcthreshold1","displayName":"Timeout value: [number field] milliseconds","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimization_syncmodeslowlinkthreshold1","displayName":"Slow link value:[number field] milliseconds","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimizationonserversku","displayName":"Enable Group Policy Caching for Servers","description":"\r\n This policy setting allows you to configure Group Policy caching behavior on Windows Server machines.\r\n If you enable this policy setting, Group Policy caches policy information after every background processing session. This cache saves applicable GPOs and the settings contained within them. When Group Policy runs in synchronous foreground mode, it refers to this cache, which enables it to run faster. When the cache is read, Group Policy attempts to contact a logon domain controller to determine the link speed. When Group Policy runs in background mode or asynchronous foreground mode, it continues to download the latest version of the policy information, and it uses a bandwidth estimate to determine slow link thresholds. (See the “Configure Group Policy Slow Link Detection” policy setting to configure asynchronous foreground behavior.)\r\n The slow link value that is defined in this policy setting determines how long Group Policy will wait for a response from the domain controller before reporting the link speed as slow. The default is 500 milliseconds.\r\n The timeout value that is defined in this policy setting determines how long Group Policy will wait for a response from the domain controller before determining that there is no network connectivity. This stops the current Group Policy processing. Group Policy will run in the background the next time a connection to a domain controller is established. Setting this value too high might result in longer waits for the user at boot or logon. The default is 5000 milliseconds.\r\n If you disable or do not configure this policy setting, the Group Policy client will not cache applicable GPOs or settings that are contained within the GPOs. When Group Policy runs synchronously, it downloads the latest version of the policy from the network and uses bandwidth estimates to determine slow link thresholds. (See the “Configure Group Policy Slow Link Detection” policy setting to configure asynchronous foreground behavior.)\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-enablelogonoptimizationonserversku"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimizationonserversku_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimizationonserversku_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimizationonserversku_syncmodenodcthreshold1","displayName":"Timeout value: [number field] milliseconds","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablelogonoptimizationonserversku_syncmodeslowlinkthreshold1","displayName":"Slow link value:[number field] milliseconds","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablemmx","displayName":"Phone-PC linking on this device","description":"\r\nThis policy allows IT admins to turn off the ability to Link a Phone with a PC to continue reading, emailing and other tasks that requires linking between Phone and PC.\r\n\r\nIf you enable this policy setting, the Windows device will be able to enroll in Phone-PC linking functionality and participate in Continue on PC experiences.\r\n\r\nIf you disable this policy setting, the Windows device is not allowed to be linked to Phones, will remove itself from the device list of any linked Phones, and cannot participate in Continue on PC experiences.\r\n\r\nIf you do not configure this policy setting, the default behavior depends on the Windows edition. Changes to this policy take effect on reboot.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-enablemmx"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablemmx_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablemmx_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation","displayName":"Untrusted Font Blocking","description":"This security feature provides a global setting to prevent programs from loading untrusted fonts. Untrusted fonts are any font installed outside of the %windir%\\Fonts directory. This feature can be configured to be in 3 modes: On, Off, and Audit. By default, it is Off and no fonts are blocked. If you aren't quite ready to deploy this feature into your organization, you can run it in Audit mode to see if blocking untrusted fonts causes any usability or compatibility issues.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-fontmitigation"],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation_fontmitigation_dl","displayName":"Mitigation Options","description":null,"helpText":"","infoUrls":[],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation_fontmitigation_dl_1000000000000","displayName":"Block untrusted fonts and log events","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation_fontmitigation_dl_2000000000000","displayName":"Do not block untrusted fonts","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_fontmitigation_fontmitigation_dl_3000000000000","displayName":"Log events without blocking untrusted fonts","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2","displayName":"Configure Group Policy slow link detection","description":"This policy setting defines a slow connection for purposes of applying and updating Group Policy.\r\n\r\nIf the rate at which data is transferred from the domain controller providing a policy update to the computers in this group is slower than the rate specified by this setting, the system considers the connection to be slow.\r\n\r\nThe system's response to a slow policy connection varies among policies. The program implementing the policy can specify the response to a slow link. Also, the policy processing settings in this folder lets you override the programs' specified responses to slow links.\r\n\r\nIf you enable this setting, you can, in the \"Connection speed\" box, type a decimal number between 0 and 4,294,967,200, indicating a transfer rate in kilobits per second. Any connection slower than this rate is considered to be slow. If you type 0, all connections are considered to be fast.\r\n\r\nIf you disable this setting or do not configure it, the system uses the default value of 500 kilobits per second.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. The setting in Computer Configuration defines a slow link for policies in the Computer Configuration folder. The setting in User Configuration defines a slow link for settings in the User Configuration folder.\r\n\r\nAlso, see the \"Do not detect slow network connections\" and related policies in Computer Configuration\\Administrative Templates\\System\\User Profile. Note: If the profile server has IP connectivity, the connection speed setting is used. If the profile server does not have IP connectivity, the SMB timing is used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-gptransferrate-2"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_cse_3g_default_to_slowlink_computer","displayName":"Always treat WWAN connections as a slow link","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_cse_3g_default_to_slowlink_computer_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_cse_3g_default_to_slowlink_computer_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_transferrateop2","displayName":"Connection speed (Kbps):","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrate","displayName":"Set Group Policy refresh interval for computers","description":"This policy setting specifies how often Group Policy for computers is updated while the computer is in use (in the background). This setting specifies a background update rate only for Group Policies in the Computer Configuration folder.\r\n\r\nIn addition to background updates, Group Policy for the computer is always updated when the system starts.\r\n\r\nBy default, computer Group Policy is updated in the background every 90 minutes, with a random offset of 0 to 30 minutes.\r\n\r\nIf you enable this setting, you can specify an update rate from 0 to 64,800 minutes (45 days). If you select 0 minutes, the computer tries to update Group Policy every 7 seconds. However, because updates might interfere with users' work and increase network traffic, very short update intervals are not appropriate for most installations.\r\n\r\nIf you disable this setting, Group Policy is updated every 90 minutes (the default). To specify that Group Policy should never be updated while the computer is in use, select the \"Turn off background refresh of Group Policy\" policy.\r\n\r\nThe Set Group Policy refresh interval for computers policy also lets you specify how much the actual update interval varies. To prevent clients with the same update interval from requesting updates simultaneously, the system varies the update interval for each client by a random number of minutes. The number you type in the random time box sets the upper limit for the range of variance. For example, if you type 30 minutes, the system selects a variance of 0 to 30 minutes. Typing a large number establishes a broad range and makes it less likely that client requests overlap. However, updates might be delayed significantly.\r\n\r\nThis setting establishes the update rate for computer Group Policy. To set an update rate for user policies, use the \"Set Group Policy refresh interval for users\" setting (located in User Configuration\\Administrative Templates\\System\\Group Policy).\r\n\r\nThis setting is only used when the \"Turn off background refresh of Group Policy\" setting is not enabled.\r\n\r\nNote: Consider notifying users that their policy is updated periodically so that they recognize the signs of a policy update. When Group Policy is updated, the Windows desktop is refreshed; it flickers briefly and closes open menus. Also, restrictions imposed by Group Policies, such as those that limit the programs users can run, might interfere with tasks in progress.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-grouppolicyrefreshrate"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrate_gprefreshrate1","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrate_gprefreshrateoffset1","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc","displayName":"Set Group Policy refresh interval for domain controllers","description":"This policy setting specifies how often Group Policy is updated on domain controllers while they are running (in the background). The updates specified by this setting occur in addition to updates performed when the system starts.\r\n\r\nBy default, Group Policy on the domain controllers is updated every five minutes.\r\n\r\nIf you enable this setting, you can specify an update rate from 0 to 64,800 minutes (45 days). If you select 0 minutes, the domain controller tries to update Group Policy every 7 seconds. However, because updates might interfere with users' work and increase network traffic, very short update intervals are not appropriate for most installations.\r\n\r\nIf you disable or do not configure this setting, the domain controller updates Group Policy every 5 minutes (the default). To specify that Group Policies for users should never be updated while the computer is in use, select the \"Turn off background refresh of Group Policy\" setting.\r\n\r\nThis setting also lets you specify how much the actual update interval varies. To prevent domain controllers with the same update interval from requesting updates simultaneously, the system varies the update interval for each controller by a random number of minutes. The number you type in the random time box sets the upper limit for the range of variance. For example, if you type 30 minutes, the system selects a variance of 0 to 30 minutes. Typing a large number establishes a broad range and makes it less likely that update requests overlap. However, updates might be delayed significantly.\r\n\r\nNote: This setting is used only when you are establishing policy for a domain, site, organizational unit (OU), or customized group. If you are establishing policy for a local computer only, the system ignores this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-grouppolicyrefreshratedc"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_gprefreshrate2","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_gprefreshrateoffset2","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay","displayName":"Configure Logon Script Delay","description":"\r\n Enter “0” to disable Logon Script Delay.\r\n\r\n This policy setting allows you to configure how long the Group Policy client waits after logon before running scripts.\r\n\r\n By default, the Group Policy client waits five minutes before running logon scripts. This helps create a responsive desktop environment by preventing disk contention.\r\n\r\n If you enable this policy setting, Group Policy will wait for the specified amount of time before running logon scripts.\r\n\r\n If you disable this policy setting, Group Policy will run scripts immediately after logon.\r\n\r\n If you do not configure this policy setting, Group Policy will wait five minutes before running logon scripts.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-logonscriptdelay"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay_asyncscriptdelay1","displayName":"minute:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_onlyuselocaladminfiles","displayName":"Always use local ADM files for Group Policy Object Editor","description":"This policy setting lets you always use local ADM files for the Group Policy snap-in.\r\n\r\nBy default, when you edit a Group Policy Object (GPO) using the Group Policy Object Editor snap-in, the ADM files are loaded from that GPO into the Group Policy Object Editor snap-in. This allows you to use the same version of the ADM files that were used to create the GPO while editing this GPO.\r\n\r\nThis leads to the following behavior:\r\n\r\n- If you originally created the GPO with, for example, an English system, the GPO contains English ADM files.\r\n\r\n- If you later edit the GPO from a different-language system, you get the English ADM files as they were in the GPO.\r\n\r\nYou can change this behavior by using this setting.\r\n\r\nIf you enable this setting, the Group Policy Object Editor snap-in always uses local ADM files in your %windir%\\inf directory when editing GPOs.\r\n\r\nThis leads to the following behavior:\r\n\r\n- If you had originally created the GPO with an English system, and then you edit the GPO with a Japanese system, the Group Policy Object Editor snap-in uses the local Japanese ADM files, and you see the text in Japanese under Administrative Templates.\r\n\r\nIf you disable or do not configure this setting, the Group Policy Object Editor snap-in always loads all ADM files from the actual GPO.\r\n\r\nNote: If the ADMs that you require are not all available locally in your %windir%\\inf directory, you might not be able to see all the settings that have been configured in the GPO that you are editing.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-onlyuselocaladminfiles"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_onlyuselocaladminfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_onlyuselocaladminfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions","displayName":"Process Mitigation Options","description":"\r\n This security feature provides a means to override individual process MitigationOptions settings. This can be used to enforce a number of security policies specific to applications. The application name is specified as the Value name, including extension. The Value is specified as a bit field with a series of flags in particular positions. Bits can be set to either 0 (setting is forced off), 1 (setting is forced on), or ? (setting retains its existing value prior to GPO evaluation). The recognized bit locations are:\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_DEP_ENABLE (0x00000001)\r\n Enables data execution prevention (DEP) for the child process\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_DEP_ATL_THUNK_ENABLE (0x00000002)\r\n Enables DEP-ATL thunk emulation for the child process. DEP-ATL thunk emulation causes the system to intercept NX faults that originate from the Active Template Library (ATL) thunk layer.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_SEHOP_ENABLE (0x00000004)\r\n Enables structured exception handler overwrite protection (SEHOP) for the child process. SEHOP blocks exploits that use the structured exception handler (SEH) overwrite technique.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_FORCE_RELOCATE_IMAGES_ALWAYS_ON (0x00000100)\r\n The force Address Space Layout Randomization (ASLR) policy forcibly rebases images that are not dynamic base compatible by acting as though an image base collision happened at load time. If relocations are required, images that do not have a base relocation section will not be loaded.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_ON (0x00010000)\r\n PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_OFF (0x00020000)\r\n The bottom-up randomization policy, which includes stack randomization options, causes a random location to be used as the lowest user address.\r\n\r\n For instance, to enable PROCESS_CREATION_MITIGATION_POLICY_DEP_ENABLE and PROCESS_CREATION_MITIGATION_POLICY_FORCE_RELOCATE_IMAGES_ALWAYS_ON, disable PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_OFF, and to leave all other options at their default values, specify a value of:\r\n ???????????????0???????1???????1\r\n\r\n Setting flags not specified here to any value other than ? results in undefined behavior.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-processmitigationoptions"],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_processmitigationoptionslist","displayName":"Process Mitigation Options","description":null,"helpText":"","infoUrls":[],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_processmitigationoptionslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_processmitigationoptionslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_resetdfsclientinfoduringrefreshpolicy","displayName":"Enable AD/DFS domain controller synchronization during policy refresh","description":"Enabling this setting will cause the Group Policy Client to connect to the same domain controller for DFS shares as is being used for Active Directory.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-resetdfsclientinfoduringrefreshpolicy"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_resetdfsclientinfoduringrefreshpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_resetdfsclientinfoduringrefreshpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_rsoplogging","displayName":"Turn off Resultant Set of Policy logging","description":"This setting allows you to enable or disable Resultant Set of Policy (RSoP) logging on a client computer.\r\n\r\nRSoP logs information on Group Policy settings that have been applied to the client. This information includes details such as which Group Policy Objects (GPO) were applied, where they came from, and the client-side extension settings that were included.\r\n\r\nIf you enable this setting, RSoP logging is turned off.\r\n\r\nIf you disable or do not configure this setting, RSoP logging is turned on. By default, RSoP logging is always on.\r\n\r\nNote: To view the RSoP information logged on a client computer, you can use the RSoP snap-in in the Microsoft Management Console (MMC).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-rsoplogging"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_rsoplogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_rsoplogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaultfordirectaccess","displayName":"Configure Direct Access connections as a fast network connection","description":"This policy setting allows an administrator to define the Direct Access connection to be considered a fast network connection for the purposes of applying and updating Group Policy.\r\n\r\nWhen Group Policy detects the bandwidth speed of a Direct Access connection, the detection can sometimes fail to provide any bandwidth speed information. If Group Policy detects a bandwidth speed, Group Policy will follow the normal rules for evaluating if the Direct Access connection is a fast or slow network connection. If no bandwidth speed is detected, Group Policy will default to a slow network connection. This policy setting allows the administrator the option to override the default to slow network connection and instead default to using a fast network connection in the case that no network bandwidth speed is determined.\r\n\r\nNote: When Group Policy detects a slow network connection, Group Policy will only process those client side extensions configured for processing across a slow link (slow network connection).\r\n\r\nIf you enable this policy, when Group Policy cannot determine the bandwidth speed across Direct Access, Group Policy will evaluate the network connection as a fast link and process all client side extensions.\r\n\r\nIf you disable this setting or do not configure it, Group Policy will evaluate the network connection as a slow link and process only those client side extensions configured to process over a slow link.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-slowlinkdefaultfordirectaccess"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaultfordirectaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaultfordirectaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaulttoasync","displayName":"Change Group Policy processing to run asynchronously when a slow network connection is detected.","description":"This policy directs Group Policy processing to skip processing any client side extension that requires synchronous processing (that is, whether computers wait for the network to be fully initialized during computer startup and user logon) when a slow network connection is detected.\r\n\r\nIf you enable this policy setting, when a slow network connection is detected, Group Policy processing will always run in an asynchronous manner.\r\nClient computers will not wait for the network to be fully initialized at startup and logon. Existing users will be logged on using cached credentials,\r\nwhich will result in shorter logon times. Group Policy will be applied in the background after the network becomes available.\r\nNote that because this is a background refresh, extensions requiring synchronous processing such as Software Installation, Folder Redirection\r\nand Drive Maps preference extension will not be applied.\r\n\r\nNote: There are two conditions that will cause Group Policy to be processed synchronously even if this policy setting is enabled:\r\n1 - At the first computer startup after the client computer has joined the domain.\r\n2 - If the policy setting \"Always wait for the network at computer startup and logon\" is enabled.\r\n\r\nIf you disable or do not configure this policy setting, detecting a slow network connection will not affect whether Group Policy processing will be synchronous or asynchronous.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-slowlinkdefaulttoasync"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaulttoasync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaulttoasync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_syncwaittime","displayName":"Specify startup policy processing wait time","description":"This policy setting specifies how long Group Policy should wait for network availability notifications during startup policy processing. If the startup policy processing is synchronous, the computer is blocked until the network is available or the default wait time is reached. If the startup policy processing is asynchronous, the computer is not blocked and policy processing will occur in the background. In either case, configuring this policy setting overrides any system-computed wait times.\r\n\r\nIf you enable this policy setting, Group Policy will use this administratively configured maximum wait time and override any default or system-computed wait time.\r\n\r\nIf you disable or do not configure this policy setting, Group Policy will use the default wait time of 30 seconds on computers running Windows Vista operating system.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-syncwaittime"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_syncwaittime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_syncwaittime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_syncwaittime_syncwaittime_minutes","displayName":"Amount of time to wait (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode","displayName":"Configure user Group Policy loopback processing mode","description":"This policy setting directs the system to apply the set of Group Policy objects for the computer to any user who logs on to a computer affected by this setting. It is intended for special-use computers, such as those in public places, laboratories, and classrooms, where you must modify the user setting based on the computer that is being used.\r\n\r\nBy default, the user's Group Policy Objects determine which user settings apply. If this setting is enabled, then, when a user logs on to this computer, the computer's Group Policy Objects determine which set of Group Policy Objects applies.\r\n\r\nIf you enable this setting, you can select one of the following modes from the Mode box:\r\n\r\n\"Replace\" indicates that the user settings defined in the computer's Group Policy Objects replace the user settings normally applied to the user.\r\n\r\n\"Merge\" indicates that the user settings defined in the computer's Group Policy Objects and the user settings normally applied to the user are combined. If the settings conflict, the user settings in the computer's Group Policy Objects take precedence over the user's normal settings.\r\n\r\nIf you disable this setting or do not configure it, the user's Group Policy Objects determines which user settings apply.\r\n\r\nNote: This setting is effective only when both the computer account and the user account are in at least Windows 2000 domains.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-userpolicymode"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_userpolicymodeop","displayName":"Mode:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_userpolicymodeop_1","displayName":"Merge","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_userpolicymodeop_2","displayName":"Replace","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_help_disablehhdep","displayName":"Turn off Data Execution Prevention for HTML Help Executible","description":"This policy setting allows you to exclude HTML Help Executable from being monitored by software-enforced Data Execution Prevention.\r\n\r\n Data Execution Prevention (DEP) is designed to block malicious code that takes advantage of exception-handling mechanisms in Windows by monitoring your programs to make sure that they use system memory safely.\r\n\r\n If you enable this policy setting, DEP for HTML Help Executable is turned off. This will allow certain legacy ActiveX controls to function without DEP shutting down HTML Help Executable.\r\n\r\n If you disable or do not configure this policy setting, DEP is turned on for HTML Help Executable. This provides an additional security benefit, but HTLM Help stops if DEP detects system memory abnormalities.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-help#admx-help-disablehhdep"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_help_disablehhdep_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_help_disablehhdep_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp","displayName":"Restrict potentially unsafe HTML Help functions to specified folders","description":"This policy setting allows you to restrict certain HTML Help commands to function only in HTML Help (.chm) files within specified folders and their subfolders. Alternatively, you can disable these commands on the entire system. It is strongly recommended that only folders requiring administrative privileges be added to this policy setting.\r\n\r\n If you enable this policy setting, the commands function only for .chm files in the specified folders and their subfolders.\r\n\r\n To restrict the commands to one or more folders, enable the policy setting and enter the desired folders in the text box on the Settings tab of the Policy Properties dialog box. Use a semicolon to separate folders. For example, to restrict the commands to only .chm files in the %windir%\\help folder and D:\\somefolder, add the following string to the edit box: \"%windir%\\help;D:\\somefolder\".\r\n\r\n Note: An environment variable may be used, (for example, %windir%), as long as it is defined on the system. For example, %programfiles% is not defined on some early versions of Windows.\r\n\r\n The \"Shortcut\" command is used to add a link to a Help topic, and runs executables that are external to the Help file. The \"WinHelp\" command is used to add a link to a Help topic, and runs a WinHLP32.exe Help (.hlp) file.\r\n\r\n To disallow the \"Shortcut\" and \"WinHelp\" commands on the entire local system, enable the policy setting and leave the text box on the Settings tab of the Policy Properties dialog box blank.\r\n\r\n If you disable or do not configure this policy setting, these commands are fully functional for all Help files.\r\n\r\n Note: Only folders on the local computer can be specified in this policy setting. You cannot use this policy setting to enable the \"Shortcut\" and \"WinHelp\" commands for .chm files that are stored on mapped drives or accessed using UNC paths.\r\n\r\n For additional options, see the \"Restrict these programs from being launched from Help\" policy.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-help#admx-help-helpqualifiedrootdir-comp"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp_helpqualifiedrootdir_edit","displayName":"Enter folder names separated by semi-colons:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_help_restrictrunfromhelp_comp","displayName":"Restrict these programs from being launched from Help","description":"\r\n This policy setting allows you to restrict programs from being run from online Help.\r\n \r\n If you enable this policy setting, you can prevent specified programs from being run from Help. When you enable this policy setting, enter the file names names of the programs you want to restrict, separated by commas.\r\n \r\n If you disable or do not configure this policy setting, users can run all applications from online Help.\r\n \r\n Note: You can also restrict users from running applications by using the Software Restriction Policy settings available in Computer Configuration\\Security Settings.\r\n \r\n Note: This policy setting is available under Computer Configuration and User Configuration. If both are settings are used, any programs listed in either of these locations cannot launched from Help\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-help#admx-help-restrictrunfromhelp-comp"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_help_restrictrunfromhelp_comp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_help_restrictrunfromhelp_comp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_help_restrictrunfromhelp_comp_restrictrunfromhelp_edit","displayName":"Enter executables separated by commas:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_helpandsupport_activehelp","displayName":"Turn off Active Help","description":"This policy setting specifies whether active content links in trusted assistance content are rendered. By default, the Help viewer renders trusted assistance content with active elements such as ShellExecute links and Guided Help links.\r\n\r\nIf you enable this policy setting, active content links are not rendered. The text is displayed, but there are no clickable links for these elements.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior applies (Help viewer renders trusted assistance content with active elements).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-helpandsupport#admx-helpandsupport-activehelp"],"categoryId":"5be35eeb-62e9-4317-8804-018a9dd31149","categoryName":"Online Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_helpandsupport_activehelp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_helpandsupport_activehelp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_hotspotauth_hotspotauth_enable","displayName":"Enable Hotspot Authentication","description":"This policy setting defines whether WLAN hotspots are probed for Wireless Internet Service Provider roaming (WISPr) protocol support.\r\n\r\nIf a WLAN hotspot supports the WISPr protocol, users can submit credentials when manually connecting to the network. If authentication is successful, users will be connected automatically on subsequent attempts. Credentials can also be configured by network operators.\r\n\r\nIf you enable this policy setting, or if you do not configure this policy setting, WLAN hotspots are automatically probed for WISPR protocol support.\r\n\r\nIf you disable this policy setting, WLAN hotspots are not probed for WISPr protocol support, and users can only authenticate with WLAN hotspots using a web browser.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-hotspotauth#admx-hotspotauth-hotspotauth-enable"],"categoryId":"6d4184ab-a66c-47f1-b54e-af55f654e2a5","categoryName":"Hotspot Authentication","options":[{"id":"device_vendor_msft_policy_config_admx_hotspotauth_hotspotauth_enable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_hotspotauth_hotspotauth_enable_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_ceipenable","displayName":"Turn off Windows Customer Experience Improvement Program","description":"This policy setting turns off the Windows Customer Experience Improvement Program. The Windows Customer Experience Improvement Program collects information about your hardware configuration and how you use our software and services to identify trends and usage patterns. Microsoft will not collect your name, address, or any other personally identifiable information. There are no surveys to complete, no salesperson will call, and you can continue working without interruption. It is simple and user-friendly.\r\n\r\nIf you enable this policy setting, all users are opted out of the Windows Customer Experience Improvement Program.\r\n\r\nIf you disable this policy setting, all users are opted into the Windows Customer Experience Improvement Program.\r\n\r\nIf you do not configure this policy setting, the administrator can use the Problem Reports and Solutions component in Control Panel to enable Windows Customer Experience Improvement Program for all users.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-ceipenable"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_ceipenable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_ceipenable_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_certmgr_disableautorootupdates","displayName":"Turn off Automatic Root Certificates Update","description":"This policy setting specifies whether to automatically update root certificates using the Windows Update website. \r\n\r\nTypically, a certificate is used when you use a secure website or when you send and receive secure email. Anyone can issue certificates, but to have transactions that are as secure as possible, certificates must be issued by a trusted certificate authority (CA). Microsoft has included a list in Windows XP and other products of companies and organizations that it considers trusted authorities.\r\n\r\nIf you enable this policy setting, when you are presented with a certificate issued by an untrusted root authority, your computer will not contact the Windows Update website to see if Microsoft has added the CA to its list of trusted authorities.\r\n\r\nIf you disable or do not configure this policy setting, your computer will contact the Windows Update website.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-certmgr-disableautorootupdates"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_certmgr_disableautorootupdates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_certmgr_disableautorootupdates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_driversearchplaces_dontsearchwindowsupdate","displayName":"Turn off Windows Update device driver searching","description":"This policy setting specifies whether Windows searches Windows Update for device drivers when no local drivers for a device are present.\r\n\r\nIf you enable this policy setting, Windows Update is not searched when a new device is installed.\r\n\r\nIf you disable this policy setting, Windows Update is always searched for drivers when no local drivers are present.\r\n\r\nIf you do not configure this policy setting, searching Windows Update is optional when installing a device.\r\n\r\nAlso see \"Turn off Windows Update device driver search prompt\" in \"Administrative Templates/System,\" which governs whether an administrator is prompted before searching Windows Update for device drivers if a driver is not found locally.\r\n\r\nNote: This policy setting is replaced by \"Specify Driver Source Search Order\" in \"Administrative Templates/System/Device Installation\" on newer versions of Windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-driversearchplaces-dontsearchwindowsupdate"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_driversearchplaces_dontsearchwindowsupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_driversearchplaces_dontsearchwindowsupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_eventviewer_disablelinks","displayName":"Turn off Event Viewer \"Events.asp\" links","description":"This policy setting specifies whether \"Events.asp\" hyperlinks are available for events within the Event Viewer application.\r\n\r\nThe Event Viewer normally makes all HTTP(S) URLs into hyperlinks that activate the Internet browser when clicked. In addition, \"More Information\" is placed at the end of the description text if the event is created by a Microsoft component. This text contains a link (URL) that, if clicked, sends information about the event to Microsoft, and allows users to learn more about why that event occurred.\r\n\r\nIf you enable this policy setting, event description hyperlinks are not activated and the text \"More Information\" is not displayed at the end of the description.\r\n\r\nIf you disable or do not configure this policy setting, the user can click the hyperlink, which prompts the user and then sends information about the event over the Internet to Microsoft. Also, see \"Events.asp URL\", \"Events.asp program\", and \"Events.asp Program Command Line Parameters\" settings in \"Administrative Templates/Windows Components/Event Viewer\".\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-eventviewer-disablelinks"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_eventviewer_disablelinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_eventviewer_disablelinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_hss_headlinespolicy","displayName":"Turn off Help and Support Center \"Did you know?\" content","description":"This policy setting specifies whether to show the \"Did you know?\" section of Help and Support Center.\r\n\r\nThis content is dynamically updated when users who are connected to the Internet open Help and Support Center, and provides up-to-date information about Windows and the computer.\r\n\r\nIf you enable this policy setting, the Help and Support Center no longer retrieves nor displays \"Did you know?\" content.\r\n\r\nIf you disable or do not configure this policy setting, the Help and Support Center retrieves and displays \"Did you know?\" content.\r\n\r\nYou might want to enable this policy setting for users who do not have Internet access, because the content in the \"Did you know?\" section will remain static indefinitely without an Internet connection.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-hss-headlinespolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_hss_headlinespolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_hss_headlinespolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_hss_kbsearchpolicy","displayName":"Turn off Help and Support Center Microsoft Knowledge Base search","description":"This policy setting specifies whether users can perform a Microsoft Knowledge Base search from the Help and Support Center.\r\n\r\nThe Knowledge Base is an online source of technical support information and self-help tools for Microsoft products, and is searched as part of all Help and Support Center searches with the default search options.\r\n\r\nIf you enable this policy setting, it removes the Knowledge Base section from the Help and Support Center \"Set search options\" page, and only Help content on the local computer is searched. \r\n\r\nIf you disable or do not configure this policy setting, the Knowledge Base is searched if the user has a connection to the Internet and has not disabled the Knowledge Base search from the Search Options page.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-hss-kbsearchpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_hss_kbsearchpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_hss_kbsearchpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_internetmanagement_restrictcommunication_2","displayName":"Restrict Internet communication","description":"This policy setting specifies whether Windows can access the Internet to accomplish tasks that require Internet resources.\r\n\r\nIf you enable this setting, all of the the policy settings listed in the \"Internet Communication settings\" section are set such that their respective features cannot access the Internet.\r\n\r\nIf you disable this policy setting, all of the the policy settings listed in the \"Internet Communication settings\" section are set such that their respective features can access the Internet.\r\n\r\nIf you do not configure this policy setting, all of the the policy settings in the \"Internet Communication settings\" section are set to not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-internetmanagement-restrictcommunication-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_internetmanagement_restrictcommunication_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_internetmanagement_restrictcommunication_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_nc_exitonisp","displayName":"Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com","description":"This policy setting specifies whether the Internet Connection Wizard can connect to Microsoft to download a list of Internet Service Providers (ISPs).\r\n\r\nIf you enable this policy setting, the \"Choose a list of Internet Service Providers\" path in the Internet Connection Wizard causes the wizard to exit. This prevents users from retrieving the list of ISPs, which resides on Microsoft servers.\r\n\r\nIf you disable or do not configure this policy setting, users can connect to Microsoft to download a list of ISPs for their area.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-nc-exitonisp"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_nc_exitonisp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_nc_exitonisp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_nc_noregistration","displayName":"Turn off Registration if URL connection is referring to Microsoft.com","description":"This policy setting specifies whether the Windows Registration Wizard connects to Microsoft.com for online registration.\r\n\r\nIf you enable this policy setting, it blocks users from connecting to Microsoft.com for online registration and users cannot register their copy of Windows online.\r\n\r\nIf you disable or do not configure this policy setting, users can connect to Microsoft.com to complete the online Windows Registration.\r\n\r\nNote that registration is optional and involves submitting some personal information to Microsoft. However, Windows Product Activation is required but does not involve submitting any personal information (except the country/region you live in).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-nc-noregistration"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_nc_noregistration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_nc_noregistration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_pch_donotreport","displayName":"Turn off Windows Error Reporting","description":"This policy setting controls whether or not errors are reported to Microsoft.\r\n\r\nError Reporting is used to report information about a system or application that has failed or has stopped responding and is used to improve the quality of the product.\r\n\r\nIf you enable this policy setting, users are not given the option to report errors.\r\n\r\nIf you disable or do not configure this policy setting, the errors may be reported to Microsoft via the Internet or to a corporate file share.\r\n\r\nThis policy setting overrides any user setting made from the Control Panel for error reporting.\r\n\r\nAlso see the \"Configure Error Reporting\", \"Display Error Notification\" and \"Disable Windows Error Reporting\" policy settings under Computer Configuration/Administrative Templates/Windows Components/Windows Error Reporting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-pch-donotreport"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_pch_donotreport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_pch_donotreport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_removewindowsupdate_icm","displayName":"Turn off access to all Windows Update features","description":"This policy setting allows you to remove access to Windows Update.\r\n\r\nIf you enable this policy setting, all Windows Update features are removed. This includes blocking access to the Windows Update website at http://windowsupdate.microsoft.com, from the Windows Update hyperlink on the Start menu, and also on the Tools menu in Internet Explorer. Windows automatic updating is also disabled; you will neither be notified about nor will you receive critical updates from Windows Update. This policy setting also prevents Device Manager from automatically installing driver updates from the Windows Update website.\r\n\r\nIf you disable or do not configure this policy setting, users can access the Windows Update website and enable automatic updating to receive notifications and critical updates from Windows Update.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-removewindowsupdate-icm"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_removewindowsupdate_icm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_removewindowsupdate_icm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_searchcompanion_disablefileupdates","displayName":"Turn off Search Companion content file updates","description":"This policy setting specifies whether Search Companion should automatically download content updates during local and Internet searches.\r\n\r\nWhen users search the local computer or the Internet, Search Companion occasionally connects to Microsoft to download an updated privacy policy and additional content files used to format and display results.\r\n\r\nIf you enable this policy setting, Search Companion does not download content updates during searches.\r\n\r\nIf you disable or do not configure this policy setting, Search Companion downloads content updates unless the user is using Classic Search.\r\n\r\nNote: Internet searches still send the search text and information about the search to Microsoft and the chosen search provider. Choosing Classic Search turns off the Search Companion feature completely.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-searchcompanion-disablefileupdates"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_searchcompanion_disablefileupdates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_searchcompanion_disablefileupdates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_shellnouseinternetopenwith_2","displayName":"Turn off Internet File Association service","description":"This policy setting specifies whether to use the Microsoft Web service for finding an application to open a file with an unhandled file association.\r\n\r\nWhen a user opens a file that has an extension that is not associated with any applications on the computer, the user is given the choice to select a local application or use the Web service to find an application.\r\n\r\nIf you enable this policy setting, the link and the dialog for using the Web service to open an unhandled file association are removed.\r\n\r\nIf you disable or do not configure this policy setting, the user is allowed to use the Web service.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellnouseinternetopenwith-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_shellnouseinternetopenwith_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_shellnouseinternetopenwith_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_shellnousestoreopenwith_2","displayName":"Turn off access to the Store","description":"This policy setting specifies whether to use the Store service for finding an application to open a file with an unhandled file type or protocol association.\r\n\r\nWhen a user opens a file type or protocol that is not associated with any applications on the computer, the user is given the choice to select a local application or use the Store service to find an application.\r\n\r\nIf you enable this policy setting, the \"Look for an app in the Store\" item in the Open With dialog is removed.\r\n\r\nIf you disable or do not configure this policy setting, the user is allowed to use the Store service and the Store item is available in the Open With dialog.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellnousestoreopenwith-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_shellnousestoreopenwith_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_shellnousestoreopenwith_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_shellremoveorderprints_2","displayName":"Turn off the \"Order Prints\" picture task","description":"This policy setting specifies whether the \"Order Prints Online\" task is available from Picture Tasks in Windows folders.\r\n\r\nThe Order Prints Online Wizard is used to download a list of providers and allow users to order prints online.\r\n\r\nIf you enable this policy setting, the task \"Order Prints Online\" is removed from Picture Tasks in File Explorer folders.\r\n\r\nIf you disable or do not configure this policy setting, the task is displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellremoveorderprints-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_shellremoveorderprints_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_shellremoveorderprints_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_2","displayName":"Turn off the \"Publish to Web\" task for files and folders","description":"This policy setting specifies whether the tasks \"Publish this file to the Web,\" \"Publish this folder to the Web,\" and \"Publish the selected items to the Web\" are available from File and Folder Tasks in Windows folders.\r\n\r\nThe Web Publishing Wizard is used to download a list of providers and allow users to publish content to the web.\r\n\r\nIf you enable this policy setting, these tasks are removed from the File and Folder tasks in Windows folders.\r\n\r\nIf you disable or do not configure this policy setting, the tasks are shown.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellremovepublishtoweb-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_icm_winmsg_noinstrumentation_2","displayName":"Turn off the Windows Messenger Customer Experience Improvement Program","description":"This policy setting specifies whether Windows Messenger collects anonymous information about how Windows Messenger software and service is used.\r\n\r\nWith the Customer Experience Improvement program, users can allow Microsoft to collect anonymous information about how the product is used. This information is used to improve the product in future releases.\r\n\r\nIf you enable this policy setting, Windows Messenger does not collect usage information, and the user settings to enable the collection of usage information are not shown.\r\n\r\nIf you disable this policy setting, Windows Messenger collects anonymous usage information, and the setting is not shown.\r\n\r\nIf you do not configure this policy setting, users have the choice to opt in and allow information to be collected.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-winmsg-noinstrumentation-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_winmsg_noinstrumentation_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_winmsg_noinstrumentation_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iis_preventiisinstall","displayName":"Prevent IIS installation","description":"\"This policy setting prevents installation of Internet Information Services (IIS) on this computer. If you enable this policy setting, Internet Information Services (IIS) cannot be installed, and you will not be able to install Windows components or applications that require IIS. Users installing Windows components or applications that require IIS might not receive a warning that IIS cannot be installed because of this Group Policy setting. Enabling this setting will not have any effect on IIS if IIS is already installed on the computer. If you disable or do not configure this policy setting, IIS can be installed, as well as all the programs and applications that require IIS to run.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iis#admx-iis-preventiisinstall"],"categoryId":"93c28398-faef-4ca5-9667-f5ed004da32c","categoryName":"Internet Information Services","options":[{"id":"device_vendor_msft_policy_config_admx_iis_preventiisinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iis_preventiisinstall_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configureisnsservers","displayName":"Do not allow manual configuration of iSNS servers","description":"If enabled then new iSNS servers may not be added and thus new targets discovered via those iSNS servers; existing iSNS servers may not be removed. If disabled then new iSNS servers may be added and thus new targets discovered via those iSNS servers; existing iSNS servers may be removed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsidiscovery-configureisnsservers"],"categoryId":"60ea8de3-bc6d-4b01-974a-a53860fe4ef6","categoryName":"i SCSI Target Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configureisnsservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configureisnsservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configuretargetportals","displayName":"Do not allow manual configuration of target portals","description":"If enabled then new target portals may not be added and thus new targets discovered on those portals; existing target portals may not be removed. If disabled then new target portals may be added and thus new targets discovered on those portals; existing target portals may be removed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsidiscovery-configuretargetportals"],"categoryId":"60ea8de3-bc6d-4b01-974a-a53860fe4ef6","categoryName":"i SCSI Target Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configuretargetportals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configuretargetportals_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configuretargets","displayName":"Do not allow manual configuration of discovered targets","description":"If enabled then discovered targets may not be manually configured. If disabled then discovered targets may be manually configured. Note: if enabled there may be cases where this will break VDS.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsidiscovery-configuretargets"],"categoryId":"60ea8de3-bc6d-4b01-974a-a53860fe4ef6","categoryName":"i SCSI Target Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configuretargets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_configuretargets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_newstatictargets","displayName":"Do not allow adding new targets via manual configuration","description":"If enabled then new targets may not be manually configured by entering the target name and target portal; already discovered targets may be manually configured. If disabled then new and already discovered targets may be manually configured. Note: if enabled there may be cases where this will break VDS.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsidiscovery-newstatictargets"],"categoryId":"60ea8de3-bc6d-4b01-974a-a53860fe4ef6","categoryName":"i SCSI Target Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_newstatictargets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsidiscovery_newstatictargets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsigeneral_changeiqnname","displayName":"Do not allow changes to initiator iqn name","description":" If enabled then do not allow the initiator iqn name to be changed. If disabled then the initiator iqn name may be changed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsigeneral-changeiqnname"],"categoryId":"ca1aedf4-b951-45f5-a77c-dec776a82e21","categoryName":"General i SCSI","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsigeneral_changeiqnname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsigeneral_changeiqnname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsigeneral_restrictadditionallogins","displayName":"Do not allow additional session logins","description":"If enabled then only those sessions that are established via a persistent login will be established and no new persistent logins may be created. If disabled then additional persistent and non persistent logins may be established.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsigeneral-restrictadditionallogins"],"categoryId":"ca1aedf4-b951-45f5-a77c-dec776a82e21","categoryName":"General i SCSI","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsigeneral_restrictadditionallogins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsigeneral_restrictadditionallogins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_changechapsecret","displayName":"Do not allow changes to initiator CHAP secret","description":" If enabled then do not allow the initiator CHAP secret to be changed. If disabled then the initiator CHAP secret may be changed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsisecurity-changechapsecret"],"categoryId":"6c1d9109-e4d1-4718-a537-dd685464fdbe","categoryName":"i SCSI Security","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_changechapsecret_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_changechapsecret_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requireipsec","displayName":"Do not allow connections without IPSec","description":"If enabled then only those connections that are configured for IPSec may be established. If disabled then connections that are configured for IPSec or connections not configured for IPSec may be established.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsisecurity-requireipsec"],"categoryId":"6c1d9109-e4d1-4718-a537-dd685464fdbe","categoryName":"i SCSI Security","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requireipsec_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requireipsec_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requiremutualchap","displayName":"Do not allow sessions without mutual CHAP","description":"If enabled then only those sessions that are configured for mutual CHAP may be established. If disabled then sessions that are configured for mutual CHAP or sessions not configured for mutual CHAP may be established.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsisecurity-requiremutualchap"],"categoryId":"6c1d9109-e4d1-4718-a537-dd685464fdbe","categoryName":"i SCSI Security","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requiremutualchap_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requiremutualchap_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requireonewaychap","displayName":"Do not allow sessions without one way CHAP","description":"If enabled then only those sessions that are configured for one-way CHAP may be established. If disabled then sessions that are configured for one-way CHAP or sessions not configured for one-way CHAP may be established. Note that if the \"Do not allow sessions without mutual CHAP\" setting is enabled then that setting overrides this one.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsisecurity-requireonewaychap"],"categoryId":"6c1d9109-e4d1-4718-a537-dd685464fdbe","categoryName":"i SCSI Security","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requireonewaychap_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requireonewaychap_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor","displayName":"KDC support for claims, compound authentication and Kerberos armoring","description":"This policy setting allows you to configure a domain controller to support claims and compound authentication for Dynamic Access Control and Kerberos armoring using Kerberos authentication.\r\n\r\nIf you enable this policy setting, client computers that support claims and compound authentication for Dynamic Access Control and are Kerberos armor-aware will use this feature for Kerberos authentication messages. This policy should be applied to all domain controllers to ensure consistent application of this policy in the domain. \r\n\r\nIf you disable or do not configure this policy setting, the domain controller does not support claims, compound authentication or armoring.\r\n\r\nIf you configure the \"Not supported\" option, the domain controller does not support claims, compound authentication or armoring which is the default behavior for domain controllers running Windows Server 2008 R2 or earlier operating systems.\r\n\r\nNote: For the following options of this KDC policy to be effective, the Kerberos Group Policy \"Kerberos client support for claims, compound authentication and Kerberos armoring\" must be enabled on supported systems. If the Kerberos policy setting is not enabled, Kerberos authentication messages will not use these features. \r\n\r\nIf you configure \"Supported\", the domain controller supports claims, compound authentication and Kerberos armoring. The domain controller advertises to Kerberos client computers that the domain is capable of claims and compound authentication for Dynamic Access Control and Kerberos armoring. \r\n\r\nDomain functional level requirements\r\nFor the options \"Always provide claims\" and \"Fail unarmored authentication requests\", when the domain functional level is set to Windows Server 2008 R2 or earlier then domain controllers behave as if the \"Supported\" option is selected. \r\n\r\nWhen the domain functional level is set to Windows Server 2012 then the domain controller advertises to Kerberos client computers that the domain is capable of claims and compound authentication for Dynamic Access Control and Kerberos armoring, and:\r\n - If you set the \"Always provide claims\" option, always returns claims for accounts and supports the RFC behavior for advertising the flexible authentication secure tunneling (FAST).\r\n - If you set the \"Fail unarmored authentication requests\" option, rejects unarmored Kerberos messages.\r\n\r\nWarning: When \"Fail unarmored authentication requests\" is set, then client computers which do not support Kerberos armoring will fail to authenticate to the domain controller.\r\n\r\nTo ensure this feature is effective, deploy enough domain controllers that support claims and compound authentication for Dynamic Access Control and are Kerberos armor-aware to handle the authentication requests. Insufficient number of domain controllers that support this policy result in authentication failures whenever Dynamic Access Control or Kerberos armoring is required (that is, the \"Supported\" option is enabled).\r\n\r\nImpact on domain controller performance when this policy setting is enabled:\r\n - Secure Kerberos domain capability discovery is required resulting in additional message exchanges.\r\n - Claims and compound authentication for Dynamic Access Control increases the size and complexity of the data in the message which results in more processing time and greater Kerberos service ticket size.\r\n - Kerberos armoring fully encrypts Kerberos messages and signs Kerberos errors which results in increased processing time, but does not change the service ticket size.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-cbacandarmor"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_cbacandarmor_levels","displayName":"Claims, compound authentication for Dynamic Access Control and Kerberos armoring options:","description":null,"helpText":"","infoUrls":[],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_cbacandarmor_levels_0","displayName":"Not supported","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_cbacandarmor_levels_1","displayName":"Supported","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_cbacandarmor_levels_2","displayName":"Always provide claims","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_cbacandarmor_cbacandarmor_levels_3","displayName":"Fail unarmored authentication requests","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_emitlili","displayName":"Provide information about previous logons to client computers","description":"This policy setting controls whether the domain controller provides information about previous logons to client computers.\r\n\r\nIf you enable this policy setting, the domain controller provides the information message about previous logons.\r\n\r\nFor Windows Logon to leverage this feature, the \"Display information about previous logons during user logon\" policy setting located in the Windows Logon Options node under Windows Components also needs to be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the domain controller does not provide information about previous logons unless the \"Display information about previous logons during user logon\" policy setting is enabled.\r\n\r\nNote: Information about previous logons is provided only if the domain functional level is Windows Server 2008. In domains with a domain functional level of Windows Server 2003, Windows 2000 native, or Windows 2000 mixed, domain controllers cannot provide information about previous logons, and enabling this policy setting does not affect anything.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-emitlili"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_emitlili_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_emitlili_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_forestsearch","displayName":"Use forest search order","description":"This policy setting defines the list of trusting forests that the Key Distribution Center (KDC) searches when attempting to resolve two-part service principal names (SPNs).\r\n\r\nIf you enable this policy setting, the KDC will search the forests in this list if it is unable to resolve a two-part SPN in the local forest. The forest search is performed by using a global catalog or name suffix hints. If a match is found, the KDC will return a referral ticket to the client for the appropriate domain.\r\n\r\nIf you disable or do not configure this policy setting, the KDC will not search the listed forests to resolve the SPN. If the KDC is unable to resolve the SPN because the name is not found, NTLM authentication might be used.\r\n\r\nTo ensure consistent behavior, this policy setting must be supported and set identically on all domain controllers in the domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-forestsearch"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_forestsearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_forestsearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_forestsearch_forestsearchlist","displayName":"Forests to Search","description":null,"helpText":"","infoUrls":[],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":null},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness","displayName":"KDC support for PKInit Freshness Extension","description":"Support for PKInit Freshness Extension requires Windows Server 2016 domain functional level (DFL). If the domain controller’s domain is not at Windows Server 2016 DFL or higher this policy will not be applied.\r\n\r\nThis policy setting allows you to configure a domain controller (DC) to support the PKInit Freshness Extension.\r\n\r\nIf you enable this policy setting, the following options are supported:\r\n\r\nSupported: PKInit Freshness Extension is supported on request. Kerberos clients successfully authenticating with the PKInit Freshness Extension will get the fresh public key identity SID.\r\n\r\nRequired: PKInit Freshness Extension is required for successful authentication. Kerberos clients which do not support the PKInit Freshness Extension will always fail when using public key credentials.\r\n\r\nIf you disable or not configure this policy setting, then the DC will never offer the PKInit Freshness Extension and accept valid authentication requests without checking for freshness. Users will never receive the fresh public key identity SID.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-pkinitfreshness"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels","displayName":"PKInit Freshness Extension options:","description":null,"helpText":"","infoUrls":[],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels_1","displayName":"Supported","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels_2","displayName":"Required","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_requestcompoundid","displayName":"Request compound authentication","description":"This policy setting allows you to configure a domain controller to request compound authentication.\r\n\r\nNote: For a domain controller to request compound authentication, the policy \"KDC support for claims, compound authentication, and Kerberos armoring\" must be configured and enabled. \r\n\r\nIf you enable this policy setting, domain controllers will request compound authentication. The returned service ticket will contain compound authentication only when the account is explicitly configured. This policy should be applied to all domain controllers to ensure consistent application of this policy in the domain. \r\n\r\nIf you disable or do not configure this policy setting, domain controllers will return service tickets that contain compound authentication any time the client sends a compound authentication request regardless of the account configuration.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-requestcompoundid"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_requestcompoundid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_requestcompoundid_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_ticketsizethreshold","displayName":"Warning for large Kerberos tickets","description":"This policy setting allows you to configure at what size Kerberos tickets will trigger the warning event issued during Kerberos authentication. The ticket size warnings are logged in the System log.\r\n\r\nIf you enable this policy setting, you can set the threshold limit for Kerberos ticket which trigger the warning events. If set too high, then authentication failures might be occurring even though warning events are not being logged. If set too low, then there will be too many ticket warnings in the log to be useful for analysis. This value should be set to the same value as the Kerberos policy \"Set maximum Kerberos SSPI context token buffer size\" or the smallest MaxTokenSize used in your environment if you are not configuring using Group Policy.\r\n \r\nIf you disable or do not configure this policy setting, the threshold value defaults to 12,000 bytes, which is the default Kerberos MaxTokenSize for Windows 7, Windows Server 2008 R2 and prior versions.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-ticketsizethreshold"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_ticketsizethreshold_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_ticketsizethreshold_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kdc_ticketsizethreshold_ticketsizethreshold","displayName":"Ticket Size Threshold","description":null,"helpText":"","infoUrls":[],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_alwayssendcompoundid","displayName":"Always send compound authentication first","description":"This policy setting controls whether a device always sends a compound authentication request when the resource domain requests compound identity.\r\n\r\nNote: For a domain controller to request compound authentication, the policies \"KDC support for claims, compound authentication, and Kerberos armoring\" and \"Request compound authentication\" must be configured and enabled in the resource account domain. \r\n\r\nIf you enable this policy setting and the resource domain requests compound authentication, devices that support compound authentication always send a compound authentication request. \r\n\r\nIf you disable or do not configure this policy setting and the resource domain requests compound authentication, devices will send a non-compounded authentication request first then a compound authentication request when the service requests compound authentication.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-alwayssendcompoundid"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_alwayssendcompoundid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_alwayssendcompoundid_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled","displayName":"Support device authentication using certificate","description":"Support for device authentication using certificate will require connectivity to a DC in the device account domain which supports certificate authentication for computer accounts. \r\n\r\nThis policy setting allows you to set support for Kerberos to attempt authentication using the certificate for the device to the domain.\r\n\r\nIf you enable this policy setting, the device’s credentials will be selected based on the following options:\r\n\r\nAutomatic: Device will attempt to authenticate using its certificate. If the DC does not support computer account authentication using certificates then authentication with password will be attempted.\r\n\r\nForce: Device will always authenticate using its certificate. If a DC cannot be found which support computer account authentication using certificates then authentication will fail.\r\n\r\nIf you disable this policy setting, certificates will never be used.\r\nIf you do not configure this policy setting, Automatic will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-devicepkinitenabled"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_devicepkinitbehavior","displayName":"Device authentication behavior using certificate:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_devicepkinitbehavior_0","displayName":"Automatic","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_devicepkinitbehavior_1","displayName":"Force","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm","displayName":"Define host name-to-Kerberos realm mappings","description":"This policy setting allows you to specify which DNS host names and which DNS suffixes are mapped to a Kerberos realm.\r\n\r\nIf you enable this policy setting, you can view and change the list of DNS host names and DNS suffixes mapped to a Kerberos realm as defined by Group Policy. To view the list of mappings, enable the policy setting and then click the Show button. To add a mapping, enable the policy setting, note the syntax, and then click Show. In the Show Contents dialog box in the Value Name column, type a realm name. In the Value column, type the list of DNS host names and DNS suffixes using the appropriate syntax format. To remove a mapping from the list, click the mapping entry to be removed, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.\r\n\r\nIf you disable this policy setting, the host name-to-Kerberos realm mappings list defined by Group Policy is deleted.\r\n\r\nIf you do not configure this policy setting, the system uses the host name-to-Kerberos realm mappings that are defined in the local registry, if they exist.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-hosttorealm"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm_hosttorealm","displayName":"Define host name-to-realm mappings:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm_hosttorealm_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm_hosttorealm_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxydisableserverrevocationcheck","displayName":"Disable revocation checking for the SSL certificate of KDC proxy servers","description":"This policy setting allows you to disable revocation check for the SSL certificate of the targeted KDC proxy server.\r\n\r\nIf you enable this policy setting, revocation check for the SSL certificate of the KDC proxy server is ignored by the Kerberos client. This policy setting should only be used in troubleshooting KDC proxy connections. \r\nWarning: When revocation check is ignored, the server represented by the certificate is not guaranteed valid. \r\n\r\nIf you disable or do not configure this policy setting, the Kerberos client enforces the revocation check for the SSL certificate. The connection to the KDC proxy server is not established if the revocation check fails.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-kdcproxydisableserverrevocationcheck"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxydisableserverrevocationcheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxydisableserverrevocationcheck_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver","displayName":"Specify KDC proxy servers for Kerberos clients","description":"This policy setting configures the Kerberos client's mapping to KDC proxy servers for domains based on their DNS suffix names.\r\n\r\nIf you enable this policy setting, the Kerberos client will use the KDC proxy server for a domain when a domain controller cannot be located based on the configured mappings. To map a KDC proxy server to a domain, enable the policy setting, click Show, and then map the KDC proxy server name(s) to the DNS name for the domain using the syntax described in the options pane. In the Show Contents dialog box in the Value Name column, type a DNS suffix name. In the Value column, type the list of proxy servers using the appropriate syntax format. To view the list of mappings, enable the policy setting and then click the Show button. To remove a mapping from the list, click the mapping entry to be removed, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.\r\n\r\nIf you disable or do not configure this policy setting, the Kerberos client does not have KDC proxy servers settings defined by Group Policy.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-kdcproxyserver"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_kdcproxyserver","displayName":"Define KDC proxy servers settings:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_kdcproxyserver_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_kdcproxyserver_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms","displayName":"Define interoperable Kerberos V5 realm settings","description":"This policy setting configures the Kerberos client so that it can authenticate with interoperable Kerberos V5 realms, as defined by this policy setting.\r\n \r\nIf you enable this policy setting, you can view and change the list of interoperable Kerberos V5 realms and their settings. To view the list of interoperable Kerberos V5 realms, enable the policy setting and then click the Show button. To add an interoperable Kerberos V5 realm, enable the policy setting, note the syntax, and then click Show. In the Show Contents dialog box in the Value Name column, type the interoperable Kerberos V5 realm name. In the Value column, type the realm flags and host names of the host KDCs using the appropriate syntax format. To remove an interoperable Kerberos V5 realm Value Name or Value entry from the list, click the entry, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.\r\n\r\nIf you disable this policy setting, the interoperable Kerberos V5 realm settings defined by Group Policy are deleted.\r\n\r\nIf you do not configure this policy setting, the system uses the interoperable Kerberos V5 realm settings that are defined in the local registry, if they exist.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-mitrealms"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_mitrealms","displayName":"Define interoperable Kerberos V5 realm settings:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_mitrealms_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_mitrealms_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound","displayName":"Support compound authentication","description":"This policy setting controls configuring the device's Active Directory account for compound authentication.\r\n\r\nSupport for providing compound authentication which is used for access control will require enough domain controllers in the resource account domains to support the requests. The Domain Administrator must configure the policy \"Support Dynamic Access Control and Kerberos armoring\" on all the domain controllers to support this policy.\r\n\r\nIf you enable this policy setting, the device's Active Directory account will be configured for compound authentication by the following options:\r\n\r\nNever: Compound authentication is never provided for this computer account.\r\n\r\nAutomatic: Compound authentication is provided for this computer account when one or more applications are configured for Dynamic Access Control.\r\n\r\nAlways: Compound authentication is always provided for this computer account.\r\n\r\nIf you disable this policy setting, Never will be used.\r\nIf you do not configure this policy setting, Automatic will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-serveracceptscompound"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled","displayName":"Support authorization with client device information:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled_1","displayName":"Automatic","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled_2","displayName":"Always","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_kerberos_stricttarget","displayName":"Require strict target SPN match on remote procedure calls","description":" This policy setting allows you to configure this server so that Kerberos can decrypt a ticket that contains this system-generated SPN. When an application attempts to make a remote procedure call (RPC) to this server with a NULL value for the service principal name (SPN), computers running Windows 7 or later attempt to use Kerberos by generating an SPN.\r\n \r\nIf you enable this policy setting, only services running as LocalSystem or NetworkService are allowed to accept these connections. Services running as identities different from LocalSystem or NetworkService might fail to authenticate.\r\n\r\nIf you disable or do not configure this policy setting, any service is allowed to accept incoming connections by using this system-generated SPN.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-stricttarget"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_stricttarget_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_stricttarget_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_ciphersuiteorder","displayName":"Cipher suite order","description":"This policy setting determines the cipher suites used by the SMB server.\r\n\r\nIf you enable this policy setting, cipher suites are prioritized in the order specified.\r\n\r\nIf you enable this policy setting and do not specify at least one supported cipher suite, or if you disable or do not configure this policy setting, the default cipher suite order is used.\r\n\r\nSMB 3.11 cipher suites:\r\n\r\nAES_128_GCM\r\nAES_128_CCM\r\n\r\nSMB 3.0 and 3.02 cipher suites:\r\n\r\nAES_128_CCM\r\n\r\nHow to modify this setting:\r\n\r\nArrange the desired cipher suites in the edit box, one cipher suite per line, in order from most to least preferred, with the most preferred cipher suite at the top. Remove any cipher suites you don't want to use.\r\n\r\nNote: When configuring this security setting, changes will not take effect until you restart Windows.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanserver#admx-lanmanserver-pol-ciphersuiteorder"],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_ciphersuiteorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_ciphersuiteorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_ciphersuiteorder_multitext_ciphersuiteorder","displayName":"Cipher suites:","description":null,"helpText":"","infoUrls":[],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication","displayName":"Hash Publication for BranchCache","description":"This policy setting specifies whether a hash generation service generates hashes, also called content information, for data that is stored in shared folders. This policy setting must be applied to server computers that have the File Services role and both the File Server and the BranchCache for Network Files role services installed.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, hash publication settings are not applied to file servers. In the circumstance where file servers are domain members but you do not want to enable BranchCache on all file servers, you can specify Not Configured for this domain Group Policy setting, and then configure local machine policy to enable BranchCache on individual file servers. Because the domain Group Policy setting is not configured, it will not over-write the enabled setting that you use on individual servers where you want to enable BranchCache.\r\n\r\n- Enabled. With this selection, hash publication is turned on for all file servers where Group Policy is applied. For example, if Hash Publication for BranchCache is enabled in domain Group Policy, hash publication is turned on for all domain member file servers to which the policy is applied. The file servers are then able to create content information for all content that is stored in BranchCache-enabled file shares.\r\n\r\n- Disabled. With this selection, hash publication is turned off for all file servers where Group Policy is applied.\r\n\r\nIn circumstances where this policy setting is enabled, you can also select the following configuration options:\r\n\r\n- Allow hash publication for all shared folders. With this option, BranchCache generates content information for all content in all shares on the file server. \r\n\r\n- Allow hash publication only for shared folders on which BranchCache is enabled. With this option, content information is generated only for shared folders on which BranchCache is enabled. If you use this setting, you must enable BranchCache for individual shares in Share and Storage Management on the file server.\r\n\r\n- Disallow hash publication on all shared folders. With this option, BranchCache does not generate content information for any shares on the computer and does not send content information to client computers that request content.\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanserver#admx-lanmanserver-pol-hashpublication"],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo","displayName":"Hash publication actions:","description":null,"helpText":"","infoUrls":[],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo_0","displayName":"Allow hash publication only for shared folders on which BranchCache is enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo_1","displayName":"Disallow hash publication on all shared folders","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo_2","displayName":"Allow hash publication for all shared folders","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion","displayName":"Hash Version support for BranchCache","description":"This policy setting specifies whether the BranchCache hash generation service supports version 1 (V1) hashes, version 2 (V2) hashes, or both V1 and V2 hashes. Hashes, also called content information, are created based on the data in shared folders where BranchCache is enabled. \r\n\r\nIf you specify only one version that is supported, content information for that version is the only type that is generated by BranchCache, and it is the only type of content information that can be retrieved by client computers. For example, if you enable support for V1 hashes, BranchCache generates only V1 hashes and client computers can retrieve only V1 hashes.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy setting. In this circumstance, which is the default, both V1 and V2 hash generation and retrieval are supported.\r\n\r\n- Enabled. With this selection, the policy setting is applied and the hash version(s) that are specified in \"Hash version supported\" are generated and retrieved.\r\n\r\n- Disabled. With this selection, both V1 and V2 hash generation and retrieval are supported.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\nHash version supported:\r\n\r\n- To support V1 content information only, configure \"Hash version supported\" with the value of 1.\r\n\r\n- To support V2 content information only, configure \"Hash version supported\" with the value of 2.\r\n\r\n- To support both V1 and V2 content information, configure \"Hash version supported\" with the value of 3.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanserver#admx-lanmanserver-pol-hashsupportversion"],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion_lbl_hashversionsupportactioncombo","displayName":"Hash version supported:","description":null,"helpText":"","infoUrls":[],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion_lbl_hashversionsupportactioncombo_1","displayName":"Supports V1 hash version only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion_lbl_hashversionsupportactioncombo_2","displayName":"Supports V2 hash version only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashsupportversion_lbl_hashversionsupportactioncombo_3","displayName":"Supports V1 as well as V2 versions","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_honorciphersuiteorder","displayName":"Honor cipher suite order","description":"This policy setting determines how the SMB server selects a cipher suite when negotiating a new connection with an SMB client.\r\n\r\nIf you enable this policy setting, the SMB server will select the cipher suite it most prefers from the list of client-supported cipher suites, ignoring the client's preferences.\r\n\r\nIf you disable or do not configure this policy setting, the SMB server will select the cipher suite the client most prefers from the list of server-supported cipher suites.\r\n\r\nNote: When configuring this security setting, changes will not take effect until you restart Windows.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanserver#admx-lanmanserver-pol-honorciphersuiteorder"],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_honorciphersuiteorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_honorciphersuiteorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_ciphersuiteorder","displayName":"Cipher suite order","description":"This policy setting determines the cipher suites used by the SMB client.\r\n\r\nIf you enable this policy setting, cipher suites are prioritized in the order specified.\r\n\r\nIf you enable this policy setting and do not specify at least one supported cipher suite, or if you disable or do not configure this policy setting, the default cipher suite order is used.\r\n\r\nSMB 3.11 cipher suites:\r\n\r\nAES_128_GCM\r\nAES_128_CCM\r\n\r\nSMB 3.0 and 3.02 cipher suites:\r\n\r\nAES_128_CCM\r\n\r\nHow to modify this setting:\r\n\r\nArrange the desired cipher suites in the edit box, one cipher suite per line, in order from most to least preferred, with the most preferred cipher suite at the top. Remove any cipher suites you don't want to use.\r\n\r\nNote: When configuring this security setting, changes will not take effect until you restart Windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanworkstation#admx-lanmanworkstation-pol-ciphersuiteorder"],"categoryId":"88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","categoryName":"Lanman Workstation","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_ciphersuiteorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_ciphersuiteorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_ciphersuiteorder_multitext_ciphersuiteorder","displayName":"Cipher suites:","description":null,"helpText":"","infoUrls":[],"categoryId":"88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","categoryName":"Lanman Workstation","options":null},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_enablehandlecachingforcafiles","displayName":"Handle Caching on Continuous Availability Shares","description":"\r\n This policy setting determines the behavior of SMB handle caching for clients connecting to an SMB share where the Continuous Availability (CA) flag is enabled.\r\n\r\n If you enable this policy setting, the SMB client will allow cached handles to files on CA shares. This may lead to better performance when repeatedly accessing a large number of unstructured data files on CA shares running in Microsoft Azure Files.\r\n\r\n If you disable or do not configure this policy setting, Windows will prevent use of cached handles to files opened through CA shares.\r\n\r\n Note: This policy has no effect when connecting Scale-out File Server shares provided by a Windows Server. Microsoft does not recommend enabling this policy for clients that routinely connect to files hosted on a Windows Failover Cluster with the File Server for General Use role, as it can lead to adverse failover times and increased memory and CPU usage.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanworkstation#admx-lanmanworkstation-pol-enablehandlecachingforcafiles"],"categoryId":"88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","categoryName":"Lanman Workstation","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_enablehandlecachingforcafiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_enablehandlecachingforcafiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_enableofflinefilesforcashares","displayName":"Offline Files Availability on Continuous Availability Shares","description":"\r\n This policy setting determines the behavior of Offline Files on clients connecting to an SMB share where the Continuous Availability (CA) flag is enabled.\r\n\r\n If you enable this policy setting, the \"Always Available offline\" option will appear in the File Explorer menu on a Windows computer when connecting to a CA-enabled share. Pinning of files on CA-enabled shares using client-side caching will also be possible.\r\n\r\n If you disable or do not configure this policy setting, Windows will prevent use of Offline Files with CA-enabled shares.\r\n\r\n Note: Microsoft does not recommend enabling this group policy. Use of CA with Offline Files will lead to very long transition times between the online and offline states.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanworkstation#admx-lanmanworkstation-pol-enableofflinefilesforcashares"],"categoryId":"88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","categoryName":"Lanman Workstation","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_enableofflinefilesforcashares_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanworkstation_pol_enableofflinefilesforcashares_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_leakdiagnostic_wdiscenarioexecutionpolicy","displayName":"Configure Scenario Execution Level","description":"This policy setting determines whether Diagnostic Policy Service (DPS) diagnoses memory leak problems.\r\n\r\nIf you enable or do not configure this policy setting, the DPS enables Windows Memory Leak Diagnosis by default.\r\n\r\nIf you disable this policy setting, the DPS is not able to diagnose memory leak problems.\r\n\r\nThis policy setting takes effect only under the following conditions: \r\n-- If the diagnostics-wide scenario execution policy is not configured. \r\n-- When the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed.\r\n\r\nNote: The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n\r\nNo operating system restart or service restart is required for this policy to take effect. Changes take effect immediately.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-leakdiagnostic#admx-leakdiagnostic-wdiscenarioexecutionpolicy"],"categoryId":"2b54b208-5459-4e40-8db1-002cb90495bc","categoryName":"Windows Memory Leak Diagnosis","options":[{"id":"device_vendor_msft_policy_config_admx_leakdiagnostic_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_leakdiagnostic_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio","displayName":"Turn on Mapper I/O (LLTDIO) driver","description":"This policy setting changes the operational behavior of the Mapper I/O network protocol driver.\r\n\r\nLLTDIO allows a computer to discover the topology of a network it's connected to. It also allows a computer to initiate Quality-of-Service requests such as bandwidth estimation and network health analysis.\r\n\r\nIf you enable this policy setting, additional options are available to fine-tune your selection. You may choose the \"Allow operation while in domain\" option to allow LLTDIO to operate on a network interface that's connected to a managed network. On the other hand, if a network interface is connected to an unmanaged network, you may choose the \"Allow operation while in public network\" and \"Prohibit operation while in private network\" options instead.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior of LLTDIO will apply.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-linklayertopologydiscovery#admx-linklayertopologydiscovery-lltd-enablelltdio"],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowondomain","displayName":"Allow operation while in domain","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowondomain_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowondomain_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowonpublicnet","displayName":"Allow operation while in public network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowonpublicnet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowonpublicnet_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_prohibitonprivatenet","displayName":"Prohibit operation while in private network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_prohibitonprivatenet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_prohibitonprivatenet_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr","displayName":"Turn on Responder (RSPNDR) driver","description":"This policy setting changes the operational behavior of the Responder network protocol driver.\r\n\r\nThe Responder allows a computer to participate in Link Layer Topology Discovery requests so that it can be discovered and located on the network. It also allows a computer to participate in Quality-of-Service activities such as bandwidth estimation and network health analysis.\r\n\r\nIf you enable this policy setting, additional options are available to fine-tune your selection. You may choose the \"Allow operation while in domain\" option to allow the Responder to operate on a network interface that's connected to a managed network. On the other hand, if a network interface is connected to an unmanaged network, you may choose the \"Allow operation while in public network\" and \"Prohibit operation while in private network\" options instead.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior for the Responder will apply.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-linklayertopologydiscovery#admx-linklayertopologydiscovery-lltd-enablerspndr"],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowondomain","displayName":"Allow operation while in domain","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowondomain_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowondomain_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowonpublicnet","displayName":"Allow operation while in public network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowonpublicnet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowonpublicnet_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_prohibitonprivatenet","displayName":"Prohibit operation while in private network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_prohibitonprivatenet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_prohibitonprivatenet_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_locationprovideradm_disablewindowslocationprovider_1","displayName":"Turn off Windows Location Provider","description":"\r\n This policy setting turns off the Windows Location Provider feature for this computer.\r\n\r\n If you enable this policy setting, the Windows Location Provider feature will be turned off, and all programs on this computer will not be able to use the Windows Location Provider feature.\r\n\r\n If you disable or do not configure this policy setting, all programs on this computer can use the Windows Location Provider feature.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-locationprovideradm#admx-locationprovideradm-disablewindowslocationprovider-1"],"categoryId":"3f8986f3-195d-4ee5-ae8d-96a007b20883","categoryName":"Windows Location Provider","options":[{"id":"device_vendor_msft_policy_config_admx_locationprovideradm_disablewindowslocationprovider_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_locationprovideradm_disablewindowslocationprovider_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_blockuserfromshowingaccountdetailsonsignin","displayName":"Block user from showing account details on sign-in","description":"This policy prevents the user from showing account details (email address or user name) on the sign-in screen.\r\n\r\nIf you enable this policy setting, the user cannot choose to show account details on the sign-in screen.\r\n\r\nIf you disable or do not configure this policy setting, the user may choose to show account details on the sign-in screen.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-blockuserfromshowingaccountdetailsonsignin"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_blockuserfromshowingaccountdetailsonsignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_blockuserfromshowingaccountdetailsonsignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_disableacrylicbackgroundonlogon","displayName":"Show clear logon background","description":"This policy setting disables the acrylic blur effect on logon background image.\r\n\r\n If you enable this policy, the logon background image shows without blur.\r\n If you disable or do not configure this policy, the logon background image adopts the acrylic blur effect.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-disableacrylicbackgroundonlogon"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_disableacrylicbackgroundonlogon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_disableacrylicbackgroundonlogon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_disableexplorerrunlegacy_2","displayName":"Do not process the legacy run list","description":"This policy setting ignores the customized run list.\r\n\r\nYou can create a customized list of additional programs and documents that the system starts automatically when it runs on Windows Vista, Windows XP Professional, and Windows 2000 Professional. These programs are added to the standard run list of programs and services that the system starts.\r\n\r\nIf you enable this policy setting, the system ignores the run list for Windows Vista, Windows XP Professional, and Windows 2000 Professional.\r\n\r\nIf you disable or do not configure this policy setting, Windows Vista adds any customized run list configured to its run list.\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy setting in Computer Configuration takes precedence over the policy setting in User Configuration.\r\n\r\nNote: To create a customized run list by using a policy setting, use the \"Run these applications at startup\" policy setting.\r\n\r\nAlso, see the \"Do not process the run once list\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-disableexplorerrunlegacy-2"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_disableexplorerrunlegacy_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_disableexplorerrunlegacy_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_disableexplorerrunoncelegacy_2","displayName":"Do not process the run once list","description":"This policy setting ignores customized run-once lists.\r\n\r\nYou can create a customized list of additional programs and documents that are started automatically the next time the system starts (but not thereafter). These programs are added to the standard list of programs and services that the system starts.\r\n\r\nIf you enable this policy setting, the system ignores the run-once list.\r\n\r\nIf you disable or do not configure this policy setting, the system runs the programs in the run-once list.\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy setting in Computer Configuration takes precedence over the policy setting in User Configuration.\r\n\r\nNote: Customized run-once lists are stored in the registry in HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce.\r\n\r\nAlso, see the \"Do not process the legacy run list\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-disableexplorerrunoncelegacy-2"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_disableexplorerrunoncelegacy_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_disableexplorerrunoncelegacy_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_disablestatusmessages","displayName":"Remove Boot / Shutdown / Logon / Logoff status messages","description":"This policy setting suppresses system status messages.\r\n\r\nIf you enable this setting, the system does not display a message reminding users to wait while their system starts or shuts down, or while users log on or off.\r\n\r\nIf you disable or do not configure this policy setting, the system displays the message reminding users to wait while their system starts or shuts down, or while users log on or off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-disablestatusmessages"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_logon_disablestatusmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_disablestatusmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_dontenumerateconnectedusers","displayName":"Do not enumerate connected users on domain-joined computers","description":"This policy setting prevents connected users from being enumerated on domain-joined computers. \r\n\r\nIf you enable this policy setting, the Logon UI will not enumerate any connected users on domain-joined computers.\r\n\r\nIf you disable or do not configure this policy setting, connected users will be enumerated on domain-joined computers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-dontenumerateconnectedusers"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_dontenumerateconnectedusers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_dontenumerateconnectedusers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_nowelcometips_2","displayName":"Do not display the Getting Started welcome screen at logon","description":"This policy setting hides the welcome screen that is displayed on Windows 2000 Professional each time the user logs on.\r\n\r\nIf you enable this policy setting, the welcome screen is hidden from the user logging on to a computer where this policy is applied.\r\n\r\nUsers can still display the welcome screen by selecting it on the Start menu or by typing \"Welcome\" in the Run dialog box.\r\n\r\nIf you disable or do not configure this policy, the welcome screen is displayed each time a user logs on to the computer.\r\n\r\nThis setting applies only to Windows 2000 Professional. It does not affect the \"Configure Your Server on a Windows 2000 Server\" screen on Windows 2000 Server.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To display the welcome screen, click Start, point to Programs, point to Accessories, point to System Tools, and then click \"Getting Started.\" To suppress the welcome screen without specifying a setting, clear the \"Show this screen at startup\" check box on the welcome screen.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-nowelcometips-2"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_nowelcometips_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_nowelcometips_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_run_2","displayName":"Run these programs at user logon","description":"This policy setting specifies additional programs or documents that Windows starts automatically when a user logs on to the system.\r\n\r\nIf you enable this policy setting, you can specify which programs can run at the time the user logs on to this computer that has this policy applied.\r\n\r\nTo specify values for this policy setting, click Show. In the Show Contents dialog box in the Value column, type the name of the executable program (.exe) file or document file. To specify another name, press ENTER, and type the name. Unless the file is located in the %Systemroot% directory, you must specify the fully qualified path to the file.\r\n\r\nIf you disable or do not configure this policy setting, the user will have to start the appropriate programs after logon.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the system starts the programs specified in the Computer Configuration setting just before it starts the programs specified in the User Configuration setting.\r\n\r\nAlso, see the \"Do not process the legacy run list\" and the \"Do not process the run once list\" settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-run-2"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_run_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_run_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_run_2_runlistbox2","displayName":"Items to run at logon","description":null,"helpText":"","infoUrls":[],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_logon_syncforegroundpolicy","displayName":"Always wait for the network at computer startup and logon","description":"This policy setting determines whether Group Policy processing is synchronous (that is, whether computers wait for the network to be fully initialized during computer startup and user logon). By default, on client computers, Group Policy processing is not synchronous; client computers typically do not wait for the network to be fully initialized at startup and logon. Existing users are logged on using cached credentials, which results in shorter logon times. Group Policy is applied in the background after the network becomes available. \r\n\r\nNote that because this is a background refresh, extensions such as Software Installation and Folder Redirection take two logons to apply changes. To be able to operate safely, these extensions require that no users be logged on. Therefore, they must be processed in the foreground before users are actively using the computer. In addition, changes that are made to the user object, such as adding a roaming profile path, home directory, or user object logon script, may take up to two logons to be detected.\r\n\r\nIf a user with a roaming profile, home directory, or user object logon script logs on to a computer, computers always wait for the network to be initialized before logging the user on. If a user has never logged on to this computer before, computers always wait for the network to be initialized.\r\n\r\nIf you enable this policy setting, computers wait for the network to be fully initialized before users are logged on. Group Policy is applied in the foreground, synchronously. \r\n\r\nOn servers running Windows Server 2008 or later, this policy setting is ignored during Group Policy processing at computer startup and Group Policy processing will be synchronous (these servers wait for the network to be initialized during computer startup). \r\n\r\nIf the server is configured as follows, this policy setting takes effect during Group Policy processing at user logon:\r\n• The server is configured as a terminal server (that is, the Terminal Server role service is installed and configured on the server); and\r\n• The “Allow asynchronous user Group Policy processing when logging on through Terminal Services” policy setting is enabled. This policy setting is located under Computer Configuration\\Policies\\Administrative templates\\System\\Group Policy\\.\r\n\r\nIf this configuration is not implemented on the server, this policy setting is ignored. In this case, Group Policy processing at user logon is synchronous (these servers wait for the network to be initialized during user logon).\r\n\r\nIf you disable or do not configure this policy setting and users log on to a client computer or a server running Windows Server 2008 or later and that is configured as described earlier, the computer typically does not wait for the network to be fully initialized. In this case, users are logged on with cached credentials. Group Policy is applied asynchronously in the background.\r\n\r\nNotes: \r\n-If you want to guarantee the application of Folder Redirection, Software Installation, or roaming user profile settings in just one logon, enable this policy setting to ensure that Windows waits for the network to be available before applying policy. \r\n-If Folder Redirection policy will apply during the next logon, security policies will be applied asynchronously during the next update cycle, if network connectivity is available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-syncforegroundpolicy"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_syncforegroundpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_syncforegroundpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_useoembackground","displayName":"Always use custom logon background","description":"This policy setting ignores Windows Logon Background.\r\n\r\nThis policy setting may be used to make Windows give preference to a custom logon background. \r\n\r\nIf you enable this policy setting, the logon screen always attempts to load a custom background instead of the Windows-branded logon background. \r\n\r\nIf you disable or do not configure this policy setting, Windows uses the default Windows logon background or custom background.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-useoembackground"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_useoembackground_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_useoembackground_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_logon_verbosestatus","displayName":"Display highly detailed status messages","description":"This policy setting directs the system to display highly detailed status messages.\r\n\r\nThis policy setting is designed for advanced users who require this information.\r\n\r\nIf you enable this policy setting, the system displays status messages that reflect each step in the process of starting, shutting down, logging on, or logging off the system.\r\n\r\nIf you disable or do not configure this policy setting, only the default status messages are displayed to the user during these processes.\r\n\r\nNote: This policy setting is ignored if the \"Remove Boot/Shutdown/Logon/Logoff status messages\" policy setting is enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-verbosestatus"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_logon_verbosestatus_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_verbosestatus_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_allowfastservicestartup","displayName":"Allow antimalware service to startup with normal priority","description":"This policy setting controls the load priority for the antimalware service. Increasing the load priority will allow for faster service startup, but may impact performance.\r\n\r\n If you enable or do not configure this setting, the antimalware service will load as a normal priority task.\r\n\r\n If you disable this setting, the antimalware service will load as a low priority task.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-allowfastservicestartup"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_allowfastservicestartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_allowfastservicestartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableantispywaredefender","displayName":"Turn off Microsoft Defender Antivirus","description":"This policy setting turns off Microsoft Defender Antivirus.\r\n \r\n If you enable this policy setting, Microsoft Defender Antivirus does not run, and will not scan computers for malware or other potentially unwanted software.\r\n\r\n If you disable this policy setting, Microsoft Defender Antivirus will run regardless of any other installed antivirus product.\r\n\r\n If you do not configure this policy setting, Windows will internally manage Microsoft Defender Antivirus. If you install another antivirus program, Windows automatically disables Microsoft Defender Antivirus. Otherwise, Microsoft Defender Antivirus will scan your computers for malware and other potentially unwanted software.\r\n\r\n Enabling or disabling this policy may lead to unexpected or unsupported behavior. It is recommended that you leave this policy setting unconfigured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disableantispywaredefender"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableantispywaredefender_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableantispywaredefender_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableautoexclusions","displayName":"Turn off Auto Exclusions","description":"\r\n Allows an administrator to specify if Automatic Exclusions feature for Server SKUs should be turned off.\r\n\r\n Disabled (Default):\r\n Microsoft Defender will exclude pre-defined list of paths from the scan to improve performance.\r\n\r\n Enabled:\r\n Microsoft Defender will not exclude pre-defined list of paths from scans. This can impact machine performance in some scenarios.\r\n\r\n Not configured:\r\n Same as Disabled.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disableautoexclusions"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableautoexclusions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableautoexclusions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableblockatfirstseen","displayName":"Configure the 'Block at First Sight' feature","description":"This feature ensures the device checks in real time with the Microsoft Active Protection Service (MAPS) before allowing certain content to be run or accessed. If this feature is disabled, the check will not occur, which will lower the protection state of the device.\r\n Enabled – The Block at First Sight setting is turned on.\r\n Disabled – The Block at First Sight setting is turned off.\r\n \r\n This feature requires these Group Policy settings to be set as follows:\r\n MAPS -> The “Join Microsoft MAPS” must be enabled or the “Block at First Sight” feature will not function.\r\n MAPS -> The “Send file samples when further analysis is required” should be set to 1 (Send safe samples) or 3 (Send all samples). Setting to 0 (Always Prompt) will lower the protection state of the device. Setting to 2 (Never send) means the “Block at First Sight” feature will not function.\r\n Real-time Protection -> The “Scan all downloaded files and attachments” policy must be enabled or the “Block at First Sight” feature will not function.\r\n Real-time Protection -> Do not enable the “Turn off real-time protection” policy or the “Block at First Sight” feature will not function.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disableblockatfirstseen"],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableblockatfirstseen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableblockatfirstseen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablelocaladminmerge","displayName":"Configure local administrator merge behavior for lists","description":"This policy setting controls whether or not complex list settings configured by a local administrator are merged with Group Policy settings. This setting applies to lists such as threats and Exclusions.\r\n\r\n If you disable or do not configure this setting, unique items defined in Group Policy and in preference settings configured by the local administrator will be merged into the resulting effective policy. In the case of conflicts, Group policy Settings will override preference settings.\r\n\r\n If you enable this setting, only items defined by Group Policy will be used in the resulting effective policy. Group Policy settings will override preference settings configured by the local administrator.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disablelocaladminmerge"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablelocaladminmerge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablelocaladminmerge_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablerealtimemonitoring","displayName":"Turn off real-time protection","description":"This policy setting turns off real-time protection prompts for known malware detection.\r\n\r\n Microsoft Defender Antivirus alerts you when malware or potentially unwanted software attempts to install itself or to run on your computer.\r\n\r\n If you enable this policy setting, Microsoft Defender Antivirus will not prompt users to take actions on malware detections.\r\n\r\n If you disable or do not configure this policy setting, Microsoft Defender Antivirus will prompt users to take actions on malware detections.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disablerealtimemonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablerealtimemonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablerealtimemonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableroutinelytakingaction","displayName":"Turn off routine remediation","description":"\r\n This policy setting allows you to configure whether Microsoft Defender Antivirus automatically takes action on all detected threats. The action to be taken on a particular threat is determined by the combination of the policy-defined action, user-defined action, and the signature-defined action.\r\n\r\n If you enable this policy setting, Microsoft Defender Antivirus does not automatically take action on the detected threats, but prompts users to choose from the actions available for each threat.\r\n\r\n If you disable or do not configure this policy setting, Microsoft Defender Antivirus automatically takes action on all detected threats after a nonconfigurable delay of approximately five seconds.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disableroutinelytakingaction"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableroutinelytakingaction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableroutinelytakingaction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_extensions","displayName":"Extension Exclusions","description":"This policy setting allows you specify a list of file types that should be excluded from scheduled, custom, and real-time scanning. File types should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of the file type extension (such as \"obj\" or \"lib\"). The value is not used and it is recommended that this be set to 0.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exclusions-extensions"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_extensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_extensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_extensions_exclusions_extensionslist","displayName":"Extension Exclusions","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_extensions_exclusions_extensionslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_extensions_exclusions_extensionslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths","displayName":"Path Exclusions","description":"This policy setting allows you to disable scheduled and real-time scanning for files under the paths specified or for the fully qualified resources specified. Paths should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of a path or a fully qualified resource name. As an example, a path might be defined as: \"c:\\Windows\" to exclude all files in this directory. A fully qualified resource name might be defined as: \"C:\\Windows\\App.exe\". The value is not used and it is recommended that this be set to 0.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exclusions-paths"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_exclusions_pathslist","displayName":"Path Exclusions","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_exclusions_pathslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_exclusions_pathslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes","displayName":"Process Exclusions","description":"This policy setting allows you to disable real-time scanning for any file opened by any of the specified processes. This policy does not apply to scheduled scans. The process itself will not be excluded. To exclude the process, use the Path exclusion. Processes should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of the path to the process image. Note that only executables can be excluded. For example, a process might be defined as: \"c:\\windows\\app.exe\". The value is not used and it is recommended that this be set to 0.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exclusions-processes"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_exclusions_processeslist","displayName":"Process Exclusions","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_exclusions_processeslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_exclusions_processeslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_asronlyexclusions","displayName":"Exclude files and paths from Attack Surface Reduction Rules","description":"\r\n Exclude files and paths from Attack Surface Reduction (ASR) rules.\r\n\r\n Enabled:\r\n Specify the folders or files and resources that should be excluded from ASR rules in the Options section.\r\n Enter each rule on a new line as a name-value pair:\r\n - Name column: Enter a folder path or a fully qualified resource name. For example, \"C:\\Windows\" will exclude all files in that directory. \"C:\\Windows\\App.exe\" will exclude only that specific file in that specific folder\r\n - Value column: Enter \"0\" for each item\r\n\r\n Disabled:\r\n No exclusions will be applied to the ASR rules.\r\n\r\n Not configured:\r\n Same as Disabled.\r\n\r\n You can configure ASR rules in the Configure Attack Surface Reduction rules GP setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exploitguard-asr-asronlyexclusions"],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_asronlyexclusions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_asronlyexclusions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_asronlyexclusions_exploitguard_asr_asronlyexclusions","displayName":"Exclusions from ASR rules:","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_asronlyexclusions_exploitguard_asr_asronlyexclusions_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_asronlyexclusions_exploitguard_asr_asronlyexclusions_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules","displayName":"Configure Attack Surface Reduction rules","description":"\r\n Set the state for each Attack Surface Reduction (ASR) rule.\r\n\r\n After enabling this setting, you can set each rule to the following in the Options section:\r\n - Block: the rule will be applied\r\n - Audit Mode: if the rule would normally cause an event, then it will be recorded (although the rule will not actually be applied)\r\n - Off: the rule will not be applied\r\n - Not Configured: the rule is enabled with default values\r\n - Warn: the rule will be applied and the end-user will have the option to bypass the block\r\n\r\n Unless the ASR rule is disabled, a subsample of audit events are collected for ASR rules will the value of not configured.\r\n\r\n Enabled:\r\n Specify the state for each ASR rule under the Options section for this setting.\r\n Enter each rule on a new line as a name-value pair:\r\n - Name column: Enter a valid ASR rule ID\r\n - Value column: Enter the status ID that relates to state you want to specify for the associated rule\r\n\r\n The following status IDs are permitted under the value column:\r\n - 1 (Block)\r\n - 0 (Off)\r\n - 2 (Audit)\r\n - 5 (Not Configured)\r\n - 6 (Warn)\r\n\r\n \r\n Example:\r\n xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx 0\r\n xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx 1\r\n xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx 2\r\n\r\n Disabled:\r\n No ASR rules will be configured.\r\n\r\n Not configured:\r\n Same as Disabled.\r\n\r\n You can exclude folders or files in the \"Exclude files and paths from Attack Surface Reduction Rules\" GP setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exploitguard-asr-rules"],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules_exploitguard_asr_rules","displayName":"Set the state for each ASR rule:","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules_exploitguard_asr_rules_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules_exploitguard_asr_rules_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications","displayName":"Configure allowed applications","description":"\r\n Add additional applications that should be considered \"trusted\" by controlled folder access.\r\n\r\n These applications are allowed to modify or delete files in controlled folder access folders.\r\n\r\n Microsoft Defender Antivirus automatically determines which applications should be trusted. You can configure this setting to add additional applications.\r\n\r\n Enabled: \r\n Specify additional allowed applications in the Options section..\r\n\r\n Disabled:\r\n No additional applications will be added to the trusted list.\r\n\r\n Not configured:\r\n Same as Disabled.\r\n\r\n You can enable controlled folder access in the Configure controlled folder access GP setting.\r\n\r\n Default system folders are automatically guarded, but you can add folders in the configure protected folders GP setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exploitguard-controlledfolderaccess-allowedapplications"],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications_exploitguard_controlledfolderaccess_allowedapplications","displayName":"Enter the applications that should be trusted:","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications_exploitguard_controlledfolderaccess_allowedapplications_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications_exploitguard_controlledfolderaccess_allowedapplications_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders","displayName":"Configure protected folders","description":"\r\n Specify additional folders that should be guarded by the Controlled folder access feature.\r\n\r\n Files in these folders cannot be modified or deleted by untrusted applications.\r\n\r\n Default system folders are automatically protected. You can configure this setting to add additional folders. \r\n The list of default system folders that are protected is shown in Windows Security.\r\n\r\n Enabled:\r\n Specify additional folders that should be protected in the Options section.\r\n\r\n Disabled:\r\n No additional folders will be protected.\r\n\r\n Not configured:\r\n Same as Disabled.\r\n\r\n You can enable controlled folder access in the Configure controlled folder access GP setting.\r\n\r\n Microsoft Defender Antivirus automatically determines which applications can be trusted. You can add additional trusted applications in the Configure allowed applications GP setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exploitguard-controlledfolderaccess-protectedfolders"],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders_exploitguard_controlledfolderaccess_protectedfolders","displayName":"Enter the folders that should be guarded:","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders_exploitguard_controlledfolderaccess_protectedfolders_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders_exploitguard_controlledfolderaccess_protectedfolders_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_mpengine_enablefilehashcomputation","displayName":"Enable file hash computation feature","description":"\r\n Enable or disable file hash computation feature.\r\n\r\n Enabled:\r\n When this feature is enabled Microsoft Defender will compute hash value for files it scans.\r\n\r\n Disabled:\r\n File hash value is not computed\r\n \r\n Not configured:\r\n Same as Disabled.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-mpengine-enablefilehashcomputation"],"categoryId":"adc4eb7f-0f34-4f43-b361-dc42363eccab","categoryName":"Mp Engine","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_mpengine_enablefilehashcomputation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_mpengine_enablefilehashcomputation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_disablesignatureretirement","displayName":"Turn on definition retirement","description":"This policy setting allows you to configure definition retirement for network protection against exploits of known vulnerabilities. Definition retirement checks to see if a computer has the required security updates necessary to protect it against a particular vulnerability. If the system is not vulnerable to the exploit detected by a definition, then that definition is \"retired\". If all security intelligence for a given protocal are retired then that protocol is no longer parsed. Enabling this feature helps to improve performance. On a computer that is up-to-date with all the latest security updates, network protection will have no impact on network performance.\r\n\r\n If you enable or do not configure this setting, definition retirement will be enabled.\r\n\r\n If you disable this setting, definition retirement will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-nis-consumers-ips-disablesignatureretirement"],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_disablesignatureretirement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_disablesignatureretirement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid","displayName":"Specify additional definition sets for network traffic inspection","description":"This policy setting defines additional definition sets to enable for network traffic inspection. Definition set GUIDs should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of a definition set GUID. As an example, the definition set GUID to enable test security intelligence is defined as: “{b54b6ac9-a737-498e-9120-6616ad3bf590}”. The value is not used and it is recommended that this be set to 0.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-nis-consumers-ips-sku-differentiation-signature-set-guid"],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid_nis_consumers_ips_sku_differentiation_signature_set_guidlist","displayName":"Specify additional definition sets for network traffic inspection","description":null,"helpText":"","infoUrls":[],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid_nis_consumers_ips_sku_differentiation_signature_set_guidlist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid_nis_consumers_ips_sku_differentiation_signature_set_guidlist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_disableprotocolrecognition","displayName":"Turn on protocol recognition","description":"This policy setting allows you to configure protocol recognition for network protection against exploits of known vulnerabilities.\r\n\r\n If you enable or do not configure this setting, protocol recognition will be enabled.\r\n\r\n If you disable this setting, protocol recognition will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-nis-disableprotocolrecognition"],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_disableprotocolrecognition_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_disableprotocolrecognition_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass","displayName":"Define addresses to bypass proxy server","description":"This policy, if defined, will prevent antimalware from using the configured proxy server when communicating with the specified IP addresses. The address value should be entered as a valid URL.\r\n\r\n If you enable this setting, the proxy server will be bypassed for the specified addresses.\r\n\r\n If you disable or do not configure this setting, the proxy server will not be bypassed for the specified addresses.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-proxybypass"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass_proxybypass","displayName":"Define addresses to bypass proxy server","description":null,"helpText":"","infoUrls":[],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxypacurl","displayName":"Define proxy auto-config (.pac) for connecting to the network","description":"This policy setting defines the URL of a proxy .pac file that should be used when the client attempts to connect the network for security intelligence updates and MAPS reporting. If the proxy auto-config fails or if there is no proxy auto-config specified, the client will fall back to the alternative options (in order):\r\n 1. Proxy server (if specified)\r\n 2. Proxy .pac URL (if specified)\r\n 3. None\r\n 4. Internet Explorer proxy settings\r\n 5. Autodetect\r\n\r\n If you enable this setting, the proxy setting will be set to use the specified proxy .pac according to the order specified above.\r\n\r\n If you disable or do not configure this setting, the proxy will skip over this fallback step according to the order specified above.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-proxypacurl"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxypacurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxypacurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxypacurl_proxypacurl","displayName":"Define proxy auto-config (.pac) for connecting to the network","description":null,"helpText":"","infoUrls":[],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxyserver","displayName":"Define proxy server for connecting to the network","description":"This policy setting allows you to configure the named proxy that should be used when the client attempts to connect to the network for security intelligence updates and MAPS reporting. If the named proxy fails or if there is no proxy specified, the client will fall back to the alternative options (in order):\r\n 1. Proxy server (if specified)\r\n 2. Proxy .pac URL (if specified)\r\n 3. None\r\n 4. Internet Explorer proxy settings\r\n 5. Autodetect\r\n\r\n If you enable this setting, the proxy will be set to the specified URL according to the order specified above. The URL should be proceeded with either http:// or https://.\r\n\r\n If you disable or do not configure this setting, the proxy will skip over this fallback step according to the order specified above.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-proxyserver"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxyserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxyserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxyserver_proxyserver","displayName":"Define proxy server for connecting to the network","description":null,"helpText":"","infoUrls":[],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_localsettingoverridepurgeitemsafterdelay","displayName":"Configure local setting override for the removal of items from Quarantine folder","description":"This policy setting configures a local override for the configuration of the number of days items should be kept in the Quarantine folder before being removed. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-quarantine-localsettingoverridepurgeitemsafterdelay"],"categoryId":"a004deb8-6f52-4411-8d94-41563a8203fc","categoryName":"Quarantine","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_localsettingoverridepurgeitemsafterdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_localsettingoverridepurgeitemsafterdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_purgeitemsafterdelay","displayName":"Configure removal of items from Quarantine folder","description":"This policy setting defines the number of days items should be kept in the Quarantine folder before being removed.\r\n\r\n If you enable this setting, items will be removed from the Quarantine folder after the number of days specified.\r\n\r\n If you disable or do not configure this setting, items will be kept in the quarantine folder indefinitely and will not be automatically removed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-quarantine-purgeitemsafterdelay"],"categoryId":"a004deb8-6f52-4411-8d94-41563a8203fc","categoryName":"Quarantine","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_purgeitemsafterdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_purgeitemsafterdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_purgeitemsafterdelay_quarantine_purgeitemsafterdelay","displayName":"Configure removal of items from Quarantine folder","description":null,"helpText":"","infoUrls":[],"categoryId":"a004deb8-6f52-4411-8d94-41563a8203fc","categoryName":"Quarantine","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_randomizescheduletasktimes","displayName":"Randomize scheduled task times","description":"This policy setting allows you to enable or disable randomization of the scheduled scan start time and the scheduled security intelligence update start time. This setting is used to distribute the resource impact of scanning. For example, it could be used in guest virtual machines sharing a host, to prevent multiple guest virtual machines from undertaking a disk-intensive operation at the same time.\r\n\r\n If you enable or do not configure this setting, scheduled tasks will begin at a random time within an interval of 4 hours after the specified start time.\r\n\r\n If you disable this setting, scheduled tasks will begin at the specified start time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-randomizescheduletasktimes"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_randomizescheduletasktimes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_randomizescheduletasktimes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablebehaviormonitoring","displayName":"Turn on behavior monitoring","description":"This policy setting allows you to configure behavior monitoring.\r\n\r\n If you enable or do not configure this setting, behavior monitoring will be enabled.\r\n\r\n If you disable this setting, behavior monitoring will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disablebehaviormonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablebehaviormonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablebehaviormonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableioavprotection","displayName":"Scan all downloaded files and attachments","description":"This policy setting allows you to configure scanning for all downloaded files and attachments.\r\n\r\n If you enable or do not configure this setting, scanning for all downloaded files and attachments will be enabled.\r\n\r\n If you disable this setting, scanning for all downloaded files and attachments will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disableioavprotection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableioavprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableioavprotection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableonaccessprotection","displayName":"Monitor file and program activity on your computer","description":"This policy setting allows you to configure monitoring for file and program activity.\r\n\r\n If you enable or do not configure this setting, monitoring for file and program activity will be enabled.\r\n\r\n If you disable this setting, monitoring for file and program activity will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disableonaccessprotection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableonaccessprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableonaccessprotection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablerawwritenotification","displayName":"Turn on raw volume write notifications","description":"This policy setting controls whether raw volume write notifications are sent to behavior monitoring.\r\n\r\n If you enable or do not configure this setting, raw write notifications will be enabled.\r\n\r\n If you disable this setting, raw write notifications be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disablerawwritenotification"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablerawwritenotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablerawwritenotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablescanonrealtimeenable","displayName":"Turn on process scanning whenever real-time protection is enabled","description":"This policy setting allows you to configure process scanning when real-time protection is turned on. This helps to catch malware which could start when real-time protection is turned off.\r\n\r\n If you enable or do not configure this setting, a process scan will be initiated when real-time protection is turned on.\r\n\r\n If you disable this setting, a process scan will not be initiated when real-time protection is turned on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disablescanonrealtimeenable"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablescanonrealtimeenable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablescanonrealtimeenable_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize","displayName":"Define the maximum size of downloaded files and attachments to be scanned","description":"This policy setting defines the maximum size (in kilobytes) of downloaded files and attachments that will be scanned.\r\n\r\n If you enable this setting, downloaded files and attachments smaller than the size specified will be scanned.\r\n\r\n If you disable or do not configure this setting, a default size will be applied.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-ioavmaxsize"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize_realtimeprotection_ioavmaxsize","displayName":"Define the maximum size of downloaded files and attachments to be scanned","description":null,"helpText":"","infoUrls":[],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablebehaviormonitoring","displayName":"Configure local setting override for turn on behavior monitoring","description":"This policy setting configures a local override for the configuration of behavior monitoring. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverridedisablebehaviormonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablebehaviormonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablebehaviormonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableioavprotection","displayName":"Configure local setting override for scanning all downloaded files and attachments","description":"This policy setting configures a local override for the configuration of scanning for all downloaded files and attachments. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverridedisableioavprotection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableioavprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableioavprotection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableonaccessprotection","displayName":"Configure local setting override for monitoring file and program activity on your computer","description":"This policy setting configures a local override for the configuration of monitoring for file and program activity on your computer. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverridedisableonaccessprotection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableonaccessprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableonaccessprotection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablerealtimemonitoring","displayName":"Configure local setting override to turn on real-time protection","description":"This policy setting configures a local override for the configuration to turn on real-time protection. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverridedisablerealtimemonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablerealtimemonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablerealtimemonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverriderealtimescandirection","displayName":"Configure local setting override for monitoring for incoming and outgoing file activity","description":"This policy setting configures a local override for the configuration of monitoring for incoming and outgoing file activity. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverriderealtimescandirection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverriderealtimescandirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverriderealtimescandirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_localsettingoverridescan_scheduletime","displayName":"Configure local setting override for the time of day to run a scheduled full scan to complete remediation","description":"This policy setting configures a local override for the configuration of the time to run a scheduled full scan to complete remediation. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-remediation-localsettingoverridescan-scheduletime"],"categoryId":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","categoryName":"Remediation","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_localsettingoverridescan_scheduletime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_localsettingoverridescan_scheduletime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday","displayName":"Specify the day of the week to run a scheduled full scan to complete remediation","description":"This policy setting allows you to specify the day of the week on which to perform a scheduled full scan in order to complete remediation. The scan can also be configured to run every day or to never run at all.\r\n\r\n This setting can be configured with the following ordinal number values:\r\n (0x0) Every Day\r\n (0x1) Sunday \r\n (0x2) Monday\r\n (0x3) Tuesday\r\n (0x4) Wednesday\r\n (0x5) Thursday\r\n (0x6) Friday\r\n (0x7) Saturday\r\n (0x8) Never (default)\r\n\r\n If you enable this setting, a scheduled full scan to complete remediation will run at the frequency specified.\r\n\r\n If you disable or do not configure this setting, a scheduled full scan to complete remediation will run at a default frequency.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-remediation-scan-scheduleday"],"categoryId":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","categoryName":"Remediation","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday","displayName":"Specify the day of the week to run a scheduled full scan to complete remediation","description":null,"helpText":"","infoUrls":[],"categoryId":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","categoryName":"Remediation","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_8","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_0","displayName":"Every Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_1","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_2","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_3","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_4","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_5","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_6","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduleday_remediation_scan_scheduleday_7","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduletime","displayName":"Specify the time of day to run a scheduled full scan to complete remediation","description":"This policy setting allows you to specify the time of day at which to perform a scheduled full scan in order to complete remediation. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. The schedule is based on local time on the computer where the scan is executing.\r\n\r\n If you enable this setting, a scheduled full scan to complete remediation will run at the time of day specified.\r\n\r\n If you disable or do not configure this setting, a scheduled full scan to complete remediation will run at a default time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-remediation-scan-scheduletime"],"categoryId":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","categoryName":"Remediation","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduletime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduletime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_remediation_scan_scheduletime_remediation_scan_scheduletime","displayName":"Specify the time of day to run a scheduled full scan to complete remediation","description":null,"helpText":"","infoUrls":[],"categoryId":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","categoryName":"Remediation","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_additionalactiontimeout","displayName":"Configure time out for detections requiring additional action","description":"This policy setting configures the time in minutes before a detection in the \"additional action\" state moves to the \"cleared\" state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-additionalactiontimeout"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_additionalactiontimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_additionalactiontimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_additionalactiontimeout_reporting_additionalactiontimeout","displayName":"Configure time out for detections requiring additional action","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_criticalfailuretimeout","displayName":"Configure time out for detections in critically failed state","description":"This policy setting configures the time in minutes before a detection in the “critically failed” state to moves to either the “additional action” state or the “cleared” state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-criticalfailuretimeout"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_criticalfailuretimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_criticalfailuretimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_criticalfailuretimeout_reporting_criticalfailuretimeout","displayName":"Configure time out for detections in critically failed state","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disableenhancednotifications","displayName":"Turn off enhanced notifications","description":"\r\n Use this policy setting to specify if you want Microsoft Defender Antivirus enhanced notifications to display on clients.\r\n \r\n If you disable or do not configure this setting, Microsoft Defender Antivirus enhanced notifications will display on clients.\r\n \r\n If you enable this setting, Microsoft Defender Antivirus enhanced notifications will not display on clients.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-disableenhancednotifications"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disableenhancednotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disableenhancednotifications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disablegenericreports","displayName":"Configure Watson events","description":"This policy setting allows you to configure whether or not Watson events are sent.\r\n\r\n If you enable or do not configure this setting, Watson events will be sent.\r\n\r\n If you disable this setting, Watson events will not be sent.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-disablegenericreports"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disablegenericreports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disablegenericreports_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_noncriticaltimeout","displayName":"Configure time out for detections in non-critical failed state","description":"This policy setting configures the time in minutes before a detection in the \"non-critically failed\" state moves to the \"cleared\" state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-noncriticaltimeout"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_noncriticaltimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_noncriticaltimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_noncriticaltimeout_reporting_noncriticaltimeout","displayName":"Configure time out for detections in non-critical failed state","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_recentlycleanedtimeout","displayName":"Configure time out for detections in recently remediated state","description":"This policy setting configures the time in minutes before a detection in the \"completed\" state moves to the \"cleared\" state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-recentlycleanedtimeout"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_recentlycleanedtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_recentlycleanedtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_recentlycleanedtimeout_reporting_recentlycleanedtimeout","displayName":"Configure time out for detections in recently remediated state","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracingcomponents","displayName":"Configure Windows software trace preprocessor components","description":"This policy configures Windows software trace preprocessor (WPP Software Tracing) components.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-wpptracingcomponents"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracingcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracingcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracingcomponents_reporting_wpptracingcomponents","displayName":"Configure Windows software trace preprocessor components","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracinglevel","displayName":"Configure WPP tracing level","description":"This policy allows you to configure tracing levels for Windows software trace preprocessor (WPP Software Tracing). \r\n Tracing levels are defined as:\r\n 1 - Error\r\n 2 - Warning\r\n 3 - Info\r\n 4 - Debug\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-wpptracinglevel"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracinglevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracinglevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_wpptracinglevel_reporting_wpptracinglevel","displayName":"Configure WPP tracing level","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_allowpause","displayName":"Allow users to pause scan","description":"This policy setting allows you to manage whether or not end users can pause a scan in progress.\r\n\r\n If you enable or do not configure this setting, a new context menu will be added to the task tray icon to allow the user to pause a scan.\r\n\r\n If you disable this setting, users will not be able to pause scans.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-allowpause"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_allowpause_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_allowpause_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxdepth","displayName":"Specify the maximum depth to scan archive files","description":"This policy setting allows you to configure the maximum directory depth level into which archive files such as .ZIP or .CAB are unpacked during scanning. The default directory depth level is 0.\r\n\r\n If you enable this setting, archive files will be scanned to the directory depth level specified.\r\n\r\n If you disable or do not configure this setting, archive files will be scanned to the default directory depth level.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-archivemaxdepth"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxdepth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxdepth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxdepth_scan_archivemaxdepth","displayName":"Specify the maximum depth to scan archive files","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize","displayName":"Specify the maximum size of archive files to be scanned","description":"This policy setting allows you to configure the maximum size of archive files such as .ZIP or .CAB that will be scanned. The value represents file size in kilobytes (KB). The default value is 0 and represents no limit to archive size for scanning.\r\n\r\n If you enable this setting, archive files less than or equal to the size specified will be scanned.\r\n\r\n If you disable or do not configure this setting, archive files will be scanned according to the default value.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-archivemaxsize"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize_scan_archivemaxsize","displayName":"Specify the maximum size of archive files to be scanned","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablearchivescanning","displayName":"Scan archive files","description":"This policy setting allows you to configure scans for malicious software and unwanted software in archive files such as .ZIP or .CAB files.\r\n\r\n If you enable or do not configure this setting, archive files will be scanned.\r\n\r\n If you disable this setting, archive files will not be scanned.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablearchivescanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablearchivescanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablearchivescanning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableemailscanning","displayName":"Turn on e-mail scanning","description":"This policy setting allows you to configure e-mail scanning. When e-mail scanning is enabled, the engine will parse the mailbox and mail files, according to their specific format, in order to analyze the mail bodies and attachments. Several e-mail formats are currently supported, for example: pst (Outlook), dbx, mbx, mime (Outlook Express), binhex (Mac).\r\n\r\n If you enable this setting, e-mail scanning will be enabled.\r\n\r\n If you disable or do not configure this setting, e-mail scanning will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disableemailscanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableemailscanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableemailscanning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableheuristics","displayName":"Turn on heuristics","description":"This policy setting allows you to configure heuristics. Suspicious detections will be suppressed right before reporting to the engine client. Turning off heuristics will reduce the capability to flag new threats. It is recommended that you do not turn off heuristics.\r\n\r\n If you enable or do not configure this setting, heuristics will be enabled.\r\n\r\n If you disable this setting, heuristics will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disableheuristics"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableheuristics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableheuristics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablepackedexescanning","displayName":"Scan packed executables","description":"This policy setting allows you to configure scanning for packed executables. It is recommended that this type of scanning remain enabled.\r\n\r\n If you enable or do not configure this setting, packed executables will be scanned.\r\n\r\n If you disable this setting, packed executables will not be scanned.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablepackedexescanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablepackedexescanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablepackedexescanning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableremovabledrivescanning","displayName":"Scan removable drives","description":"This policy setting allows you to manage whether or not to scan for malicious software and unwanted software in the contents of removable drives, such as USB flash drives, when running a full scan.\r\n\r\n If you enable this setting, removable drives will be scanned during any type of scan.\r\n\r\n If you disable or do not configure this setting, removable drives will not be scanned during a full scan. Removable drives may still be scanned during quick scan and custom scan.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disableremovabledrivescanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableremovabledrivescanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableremovabledrivescanning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablereparsepointscanning","displayName":"Turn on reparse point scanning","description":"This policy setting allows you to configure reparse point scanning. If you allow reparse points to be scanned, there is a possible risk of recursion. However, the engine supports following reparse points to a maximum depth so at worst scanning could be slowed. Reparse point scanning is disabled by default and this is the recommended state for this functionality. \r\n\r\n If you enable this setting, reparse point scanning will be enabled.\r\n\r\n If you disable or do not configure this setting, reparse point scanning will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablereparsepointscanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablereparsepointscanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablereparsepointscanning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablerestorepoint","displayName":"Create a system restore point","description":"This policy setting allows you to create a system restore point on the computer on a daily basis prior to cleaning. \r\n\r\n If you enable this setting, a system restore point will be created.\r\n\r\n If you disable or do not configure this setting, a system restore point will not be created.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablerestorepoint"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablerestorepoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablerestorepoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablescanningmappednetworkdrivesforfullscan","displayName":"Run full scan on mapped network drives","description":"This policy setting allows you to configure scanning mapped network drives.\r\n\r\n If you enable this setting, mapped network drives will be scanned.\r\n\r\n If you disable or do not configure this setting, mapped network drives will not be scanned.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablescanningmappednetworkdrivesforfullscan"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablescanningmappednetworkdrivesforfullscan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablescanningmappednetworkdrivesforfullscan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablescanningnetworkfiles","displayName":"Configure scanning of network files","description":"This policy setting allows you to configure scanning for network files. It is recommended that you do not enable this setting.\r\n\r\n If you enable this setting, network files will be scanned.\r\n\r\n If you disable or do not configure this setting, network files will not be scanned.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablescanningnetworkfiles"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablescanningnetworkfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablescanningnetworkfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideavgcpuloadfactor","displayName":"Configure local setting override for maximum percentage of CPU utilization","description":"This policy setting configures a local override for the configuration of maximum percentage of CPU utilization during scan. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverrideavgcpuloadfactor"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideavgcpuloadfactor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideavgcpuloadfactor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescanparameters","displayName":"Configure local setting override for the scan type to use for a scheduled scan","description":"This policy setting configures a local override for the configuration of the scan type to use during a scheduled scan. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverridescanparameters"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescanparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescanparameters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduleday","displayName":"Configure local setting override for schedule scan day","description":"This policy setting configures a local override for the configuration of scheduled scan day. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverridescheduleday"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduleday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduleday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideschedulequickscantime","displayName":"Configure local setting override for scheduled quick scan time","description":"This policy setting configures a local override for the configuration of scheduled quick scan time. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverrideschedulequickscantime"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideschedulequickscantime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideschedulequickscantime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduletime","displayName":"Configure local setting override for scheduled scan time","description":"This policy setting configures a local override for the configuration of scheduled scan time. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverridescheduletime"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduletime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduletime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_lowcpupriority","displayName":"Configure low CPU priority for scheduled scans","description":"\r\n This policy setting allows you to enable or disable low CPU priority for scheduled scans.\r\n\r\n If you enable this setting, low CPU priority will be used during scheduled scans.\r\n\r\n If you disable or do not configure this setting, not changes will be made to CPU priority for scheduled scans.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-lowcpupriority"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_lowcpupriority_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_lowcpupriority_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_missedscheduledscancountbeforecatchup","displayName":"Define the number of days after which a catch-up scan is forced","description":"\r\n This policy setting allows you to define the number of consecutive scheduled scans that can be missed after which a catch-up scan will be forced. By default, the value of this setting is 2 consecutive scheduled scans.\r\n\r\n If you enable this setting, a catch-up scan will occur after the specified number consecutive missed scheduled scans.\r\n\r\n If you disable or do not configure this setting, a catch-up scan will occur after the 2 consecutive missed scheduled scans.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-missedscheduledscancountbeforecatchup"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_missedscheduledscancountbeforecatchup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_missedscheduledscancountbeforecatchup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_missedscheduledscancountbeforecatchup_scan_missedscheduledscancountbeforecatchup","displayName":"Define the number of scheduled scans that can be missed after which a catch-up scan is forced","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_purgeitemsafterdelay","displayName":"Turn on removal of items from scan history folder","description":"This policy setting defines the number of days items should be kept in the scan history folder before being permanently removed. The value represents the number of days to keep items in the folder. If set to zero, items will be kept forever and will not be automatically removed. By default, the value is set to 30 days.\r\n\r\n If you enable this setting, items will be removed from the scan history folder after the number of days specified.\r\n\r\n If you disable or do not configure this setting, items will be kept in the scan history folder for the default number of days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-purgeitemsafterdelay"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_purgeitemsafterdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_purgeitemsafterdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_purgeitemsafterdelay_scan_purgeitemsafterdelay","displayName":"Turn on removal of items from scan history folder","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_quickscaninterval","displayName":"Specify the interval to run quick scans per day","description":"This policy setting allows you to specify an interval at which to perform a quick scan. The time value is represented as the number of hours between quick scans. Valid values range from 1 (every hour) to 24 (once per day). If set to zero, interval quick scans will not occur. By default, this setting is set to 0.\r\n\r\n If you enable this setting, a quick scan will run at the interval specified.\r\n\r\n If you disable or do not configure this setting, a quick scan will run at a default time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-quickscaninterval"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_quickscaninterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_quickscaninterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_quickscaninterval_scan_quickscaninterval","displayName":"Specify the interval to run quick scans per day","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scanonlyifidle","displayName":"Start the scheduled scan only when computer is on but not in use","description":"This policy setting allows you to configure scheduled scans to start only when your computer is on but not in use.\r\n\r\n If you enable or do not configure this setting, scheduled scans will only run when the computer is on but not in use.\r\n\r\n If you disable this setting, scheduled scans will run at the scheduled time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-scanonlyifidle"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scanonlyifidle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scanonlyifidle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday","displayName":"Specify the day of the week to run a scheduled scan","description":"This policy setting allows you to specify the day of the week on which to perform a scheduled scan. The scan can also be configured to run every day or to never run at all.\r\n\r\n This setting can be configured with the following ordinal number values:\r\n (0x0) Every Day\r\n (0x1) Sunday \r\n (0x2) Monday\r\n (0x3) Tuesday\r\n (0x4) Wednesday\r\n (0x5) Thursday\r\n (0x6) Friday\r\n (0x7) Saturday\r\n (0x8) Never (default)\r\n\r\n If you enable this setting, a scheduled scan will run at the frequency specified.\r\n\r\n If you disable or do not configure this setting, a scheduled scan will run at a default frequency.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-scheduleday"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday","displayName":"Specify the day of the week to run a scheduled scan","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_8","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_0","displayName":"Every Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_1","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_2","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_3","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_4","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_5","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_6","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduleday_scan_scheduleday_7","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduletime","displayName":"Specify the time of day to run a scheduled scan","description":"This policy setting allows you to specify the time of day at which to perform a scheduled scan. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. By default, this setting is set to a time value of 2:00 AM. The schedule is based on local time on the computer where the scan is executing.\r\n\r\n If you enable this setting, a scheduled scan will run at the time of day specified.\r\n\r\n If you disable or do not configure this setting, a scheduled scan will run at a default time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-scheduletime"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduletime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduletime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduletime_scan_scheduletime","displayName":"Specify the time of day to run a scheduled scan","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_servicekeepalive","displayName":"Allow antimalware service to remain running always","description":"This policy setting allows you to configure whether or not the antimalware service remains running when antivirus and antispyware security intelligence is disabled. It is recommended that this setting remain disabled.\r\n\r\n If you enable this setting, the antimalware service will always remain running even if both antivirus and antispyware security intelligence is disabled.\r\n\r\n If you disable or do not configure this setting, the antimalware service will be stopped when both antivirus and antispyware security intelligence is disabled. If the computer is restarted, the service will be started if it is set to Automatic startup. After the service has started, there will be a check to see if antivirus and antispyware security intelligence is enabled. If at least one is enabled, the service will remain running. If both are disabled, the service will be stopped.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-servicekeepalive"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_servicekeepalive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_servicekeepalive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_assignaturedue","displayName":"Define the number of days before spyware security intelligence is considered out of date","description":"This policy setting allows you to define the number of days that must pass before spyware security intelligence is considered out of date. If security intelligence is determined to be out of date, this state may trigger several additional actions, including falling back to an alternative update source or displaying a warning icon in the user interface. By default, this value is set to 7 days.\r\n\r\n If you enable this setting, spyware security intelligence will be considered out of date after the number of days specified have passed without an update.\r\n\r\n If you disable or do not configure this setting, spyware security intelligence will be considered out of date after the default number of days have passed without an update.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-assignaturedue"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_assignaturedue_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_assignaturedue_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_assignaturedue_signatureupdate_assignaturedue","displayName":"Define the number of days before spyware security intelligence is considered out of date","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_avsignaturedue","displayName":"Define the number of days before virus security intelligence is considered out of date","description":"This policy setting allows you to define the number of days that must pass before virus security intelligence is considered out of date. If security intelligence is determined to be out of date, this state may trigger several additional actions, including falling back to an alternative update source or displaying a warning icon in the user interface. By default, this value is set to 7 days.\r\n\r\n If you enable this setting, virus security intelligence will be considered out of date after the number of days specified have passed without an update.\r\n\r\n If you disable or do not configure this setting, virus security intelligence will be considered out of date after the default number of days have passed without an update.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-avsignaturedue"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_avsignaturedue_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_avsignaturedue_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_avsignaturedue_signatureupdate_avsignaturedue","displayName":"Define the number of days before virus security intelligence is considered out of date","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_definitionupdatefilesharessources","displayName":"Define file shares for downloading security intelligence updates","description":"This policy setting allows you to configure UNC file share sources for downloading security intelligence updates. Sources will be contacted in the order specified. The value of this setting should be entered as a pipe-separated string enumerating the security intelligence update sources. For example: \"{\\\\unc1 | \\\\unc2 }\". The list is empty by default.\r\n\r\n If you enable this setting, the specified sources will be contacted for security intelligence updates. Once security intelligence updates have been successfully downloaded from one specified source, the remaining sources in the list will not be contacted.\r\n\r\n If you disable or do not configure this setting, the list will remain empty by default and no sources will be contacted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-definitionupdatefilesharessources"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_definitionupdatefilesharessources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_definitionupdatefilesharessources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_definitionupdatefilesharessources_signatureupdate_definitionupdatefilesharessources","displayName":"Define file shares for downloading security intelligence updates","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescanonupdate","displayName":"Turn on scan after security intelligence update","description":"This policy setting allows you to configure the automatic scan which starts after a security intelligence update has occurred.\r\n\r\n If you enable or do not configure this setting, a scan will start following a security intelligence update.\r\n\r\n If you disable this setting, a scan will not start following a security intelligence update.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-disablescanonupdate"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescanonupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescanonupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescheduledsignatureupdateonbattery","displayName":"Allow security intelligence updates when running on battery power","description":"This policy setting allows you to configure security intelligence updates when the computer is running on battery power.\r\n\r\n If you enable or do not configure this setting, security intelligence updates will occur as usual regardless of power state.\r\n\r\n If you disable this setting, security intelligence updates will be turned off while the computer is running on battery power.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-disablescheduledsignatureupdateonbattery"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescheduledsignatureupdateonbattery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescheduledsignatureupdateonbattery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disableupdateonstartupwithoutengine","displayName":"Initiate security intelligence update on startup","description":"This policy setting allows you to configure security intelligence updates on startup when there is no antimalware engine present.\r\n\r\n If you enable or do not configure this setting, security intelligence updates will be initiated on startup when there is no antimalware engine present.\r\n\r\n If you disable this setting, security intelligence updates will not be initiated on startup when there is no antimalware engine present.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-disableupdateonstartupwithoutengine"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disableupdateonstartupwithoutengine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disableupdateonstartupwithoutengine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder","displayName":"Define the order of sources for downloading security intelligence updates","description":"This policy setting allows you to define the order in which different security intelligence update sources should be contacted. The value of this setting should be entered as a pipe-separated string enumerating the security intelligence update sources in order. Possible values are: “InternalDefinitionUpdateServer”, “MicrosoftUpdateServer”, “MMPC”, and “FileShares”\r\n\r\n For example: { InternalDefinitionUpdateServer | MicrosoftUpdateServer | MMPC }\r\n\r\n If you enable this setting, security intelligence update sources will be contacted in the order specified. Once security intelligence updates have been successfully downloaded from one specified source, the remaining sources in the list will not be contacted.\r\n\r\n If you disable or do not configure this setting, security intelligence update sources will be contacted in a default order.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-fallbackorder"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder_signatureupdate_fallbackorder","displayName":"Define the order of sources for downloading security intelligence updates","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_forceupdatefrommu","displayName":"Allow security intelligence updates from Microsoft Update","description":"This policy setting allows you to enable download of security intelligence updates from Microsoft Update even if the Automatic Updates default server is configured to another download source such as Windows Update.\r\n\r\n If you enable this setting, security intelligence updates will be downloaded from Microsoft Update.\r\n\r\n If you disable or do not configure this setting, security intelligence updates will be downloaded from the configured download source.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-forceupdatefrommu"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_forceupdatefrommu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_forceupdatefrommu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_realtimesignaturedelivery","displayName":"Allow real-time security intelligence updates based on reports to Microsoft MAPS","description":"This policy setting allows you to enable real-time security intelligence updates in response to reports sent to Microsoft MAPS. If the service reports a file as an unknown and Microsoft MAPS finds that the latest security intelligence update has security intelligence for a threat involving that file, the service will receive all of the latest security intelligence for that threat immediately. You must have configured your computer to join Microsoft MAPS for this functionality to work.\r\n\r\n If you enable or do not configure this setting, real-time security intelligence updates will be enabled.\r\n\r\n If you disable this setting, real-time security intelligence updates will disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-realtimesignaturedelivery"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_realtimesignaturedelivery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_realtimesignaturedelivery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday","displayName":"Specify the day of the week to check for security intelligence updates","description":"This policy setting allows you to specify the day of the week on which to check for security intelligence updates. The check can also be configured to run every day or to never run at all.\r\n\r\n This setting can be configured with the following ordinal number values:\r\n (0x0) Every Day (default)\r\n (0x1) Sunday \r\n (0x2) Monday\r\n (0x3) Tuesday\r\n (0x4) Wednesday\r\n (0x5) Thursday\r\n (0x6) Friday\r\n (0x7) Saturday\r\n (0x8) Never\r\n\r\n If you enable this setting, the check for security intelligence updates will occur at the frequency specified.\r\n\r\n If you disable or do not configure this setting, the check for security intelligence updates will occur at a default frequency.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-scheduleday"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday","displayName":"Specify the day of the week to check for security intelligence updates","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_8","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_0","displayName":"Every Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_1","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_2","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_3","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_4","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_5","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_6","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduleday_signatureupdate_scheduleday_7","displayName":"Saturday","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduletime","displayName":"Specify the time to check for security intelligence updates","description":"This policy setting allows you to specify the time of day at which to check for security intelligence updates. The time value is represented as the number of minutes past midnight (00:00). For example, 120 (0x78) is equivalent to 02:00 AM. By default this setting is configured to check for security intelligence updates 15 minutes before the scheduled scan time. The schedule is based on local time on the computer where the check is occurring.\r\n\r\n If you enable this setting, the check for security intelligence updates will occur at the time of day specified.\r\n\r\n If you disable or do not configure this setting, the check for security intelligence updates will occur at the default time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-scheduletime"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduletime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduletime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_scheduletime_signatureupdate_scheduletime","displayName":"Specify the time to check for security intelligence updates","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation","displayName":"Define security intelligence location for VDI clients.","description":"This policy setting allows you to define the security intelligence location for VDI-configured computers. \r\n\r\n If you disable or do not configure this setting, security intelligence will be referred from the default local source.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-sharedsignatureslocation"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation_signatureupdate_sharedsignatureslocation","displayName":"Define file share for downloading security intelligence updates in virtual environments","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signaturedisablenotification","displayName":"Allow notifications to disable security intelligence based reports to Microsoft MAPS","description":"This policy setting allows you to configure the antimalware service to receive notifications to disable individual security intelligence in response to reports it sends to Microsoft MAPS. Microsoft MAPS uses these notifications to disable security intelligence that are causing false positive reports. You must have configured your computer to join Microsoft MAPS for this functionality to work.\r\n\r\n If you enable this setting or do not configure, the antimalware service will receive notifications to disable security intelligence.\r\n\r\n If you disable this setting, the antimalware service will not receive notifications to disable security intelligence.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-signaturedisablenotification"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signaturedisablenotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signaturedisablenotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signatureupdatecatchupinterval","displayName":"Define the number of days after which a catch-up security intelligence update is required","description":"This policy setting allows you to define the number of days after which a catch-up security intelligence update will be required. By default, the value of this setting is 1 day.\r\n\r\n If you enable this setting, a catch-up security intelligence update will occur after the specified number of days.\r\n\r\n If you disable or do not configure this setting, a catch-up security intelligence update will be required after the default number of days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-signatureupdatecatchupinterval"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signatureupdatecatchupinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signatureupdatecatchupinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signatureupdatecatchupinterval_signatureupdate_signatureupdatecatchupinterval","displayName":"Define the number of days after which a catch-up security intelligence update is required","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_updateonstartup","displayName":"Check for the latest virus and spyware security intelligence on startup","description":"This policy setting allows you to manage whether a check for new virus and spyware security intelligence will occur immediately after service startup.\r\n\r\n If you enable this setting, a check for new security intelligence will occur after service startup.\r\n\r\n If you disable this setting or do not configure this setting, a check for new security intelligence will not occur after service startup.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-updateonstartup"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_updateonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_updateonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynet_localsettingoverridespynetreporting","displayName":"Configure local setting override for reporting to Microsoft MAPS","description":"This policy setting configures a local override for the configuration to join Microsoft MAPS. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-spynet-localsettingoverridespynetreporting"],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynet_localsettingoverridespynetreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynet_localsettingoverridespynetreporting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting","displayName":"Join Microsoft MAPS","description":"This policy setting allows you to join Microsoft MAPS. Microsoft MAPS is the online community that helps you choose how to respond to potential threats. The community also helps stop the spread of new malicious software infections.\r\n\r\n You can choose to send basic or additional information about detected software. Additional information helps Microsoft create new security intelligence and help it to protect your computer. This information can include things like location of detected items on your computer if harmful software was removed. The information will be automatically collected and sent. In some instances, personal information might unintentionally be sent to Microsoft. However, Microsoft will not use this information to identify you or contact you.\r\n\r\n Possible options are:\r\n (0x0) Disabled (default)\r\n (0x1) Basic membership\r\n (0x2) Advanced membership\r\n\r\n Basic membership will send basic information to Microsoft about software that has been detected, including where the software came from, the actions that you apply or that are applied automatically, and whether the actions were successful.\r\n\r\n Advanced membership, in addition to basic information, will send more information to Microsoft about malicious software, spyware, and potentially unwanted software, including the location of the software, file names, how the software operates, and how it has impacted your computer.\r\n\r\n If you enable this setting, you will join Microsoft MAPS with the membership specified.\r\n\r\n If you disable or do not configure this setting, you will not join Microsoft MAPS.\r\n \r\n In Windows 10, Basic membership is no longer available, so setting the value to 1 or 2 enrolls the device into Advanced membership.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-spynetreporting"],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting","displayName":"Join Microsoft MAPS","description":null,"helpText":"","infoUrls":[],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting_1","displayName":"Basic MAPS","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting_2","displayName":"Advanced MAPS","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction","displayName":"Specify threats upon which default action should not be taken when detected","description":"This policy setting customize which remediation action will be taken for each listed Threat ID when it is detected during a scan. Threats should be added under the Options for this setting. Each entry must be listed as a name value pair. The name defines a valid Threat ID, while the value contains the action ID for the remediation action that should be taken.\r\n\r\n Valid remediation action values are:\r\n 2 = Quarantine\r\n 3 = Remove\r\n 6 = Ignore\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-threats-threatiddefaultaction"],"categoryId":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","categoryName":"Threats","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction_threats_threatiddefaultactionlist","displayName":"Specify threats upon which default action should not be taken when detected","description":null,"helpText":"","infoUrls":[],"categoryId":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","categoryName":"Threats","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction_threats_threatiddefaultactionlist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","categoryName":"Threats","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction_threats_threatiddefaultactionlist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","categoryName":"Threats","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_customdefaultactiontoaststring","displayName":"Display additional text to clients when they need to perform an action","description":"This policy setting allows you to configure whether or not to display additional text to clients when they need to perform an action. The text displayed is a custom administrator-defined string. For example, the phone number to call the company help desk. The client interface will only display a maximum of 1024 characters. Longer strings will be truncated before display.\r\n\r\n If you enable this setting, the additional text specified will be displayed.\r\n\r\n If you disable or do not configure this setting, there will be no additional text displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-ux-configuration-customdefaultactiontoaststring"],"categoryId":"a5060182-4d22-412b-bd0e-3a1e009b36c6","categoryName":"Client Interface","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_customdefaultactiontoaststring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_customdefaultactiontoaststring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_customdefaultactiontoaststring_ux_configuration_customdefaultactiontoaststring","displayName":"Display additional text to clients when they need to perform an action","description":null,"helpText":"","infoUrls":[],"categoryId":"a5060182-4d22-412b-bd0e-3a1e009b36c6","categoryName":"Client Interface","options":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_notification_suppress","displayName":"Suppress all notifications","description":"Use this policy setting to specify if you want Microsoft Defender Antivirus notifications to display on clients.\r\n If you disable or do not configure this setting, Microsoft Defender Antivirus notifications will display on clients.\r\n\r\n If you enable this setting, Microsoft Defender Antivirus notifications will not display on clients.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-ux-configuration-notification-suppress"],"categoryId":"a5060182-4d22-412b-bd0e-3a1e009b36c6","categoryName":"Client Interface","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_notification_suppress_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_notification_suppress_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_suppressrebootnotification","displayName":"Suppresses reboot notifications","description":"\r\n This policy setting allows user to supress reboot notifications in UI only mode (for cases where UI can't be in lockdown mode).\r\n\r\n If you enable this setting AM UI won't show reboot notifications.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-ux-configuration-suppressrebootnotification"],"categoryId":"a5060182-4d22-412b-bd0e-3a1e009b36c6","categoryName":"Client Interface","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_suppressrebootnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_suppressrebootnotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_uilockdown","displayName":"Enable headless UI mode","description":"\r\n This policy setting allows you to configure whether or not to display AM UI to the users.\r\n If you enable this setting AM UI won't be available to users.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-ux-configuration-uilockdown"],"categoryId":"a5060182-4d22-412b-bd0e-3a1e009b36c6","categoryName":"Client Interface","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_uilockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_ux_configuration_uilockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mobilepcmobilitycenter_mobilitycenterenable_2","displayName":"Turn off Windows Mobility Center","description":"This policy setting turns off Windows Mobility Center.\r\n\r\nIf you enable this policy setting, the user is unable to invoke Windows Mobility Center. The Windows Mobility Center UI is removed from all shell entry points and the .exe file does not launch it.\r\n\r\nIf you disable this policy setting, the user is able to invoke Windows Mobility Center and the .exe file launches it.\r\n\r\nIf you do not configure this policy setting, Windows Mobility Center is on by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mobilepcmobilitycenter#admx-mobilepcmobilitycenter-mobilitycenterenable-2"],"categoryId":"1ed9f90e-d8b6-413f-bfc2-face955141bc","categoryName":"Windows Mobility Center","options":[{"id":"device_vendor_msft_policy_config_admx_mobilepcmobilitycenter_mobilitycenterenable_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mobilepcmobilitycenter_mobilitycenterenable_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mobilepcpresentationsettings_presentationsettingsenable_2","displayName":"Turn off Windows presentation settings","description":"This policy setting turns off Windows presentation settings.\r\n\r\nIf you enable this policy setting, Windows presentation settings cannot be invoked.\r\n\r\nIf you disable this policy setting, Windows presentation settings can be invoked. The presentation settings icon will be displayed in the notification area. This will give users a quick and easy way to configure their system settings before a presentation to block system notifications and screen blanking, adjust speaker volume, and apply a custom background image.\r\n\r\nNote: Users will be able to customize their system settings for presentations in Windows Mobility Center.\r\n\r\nIf you do not configure this policy setting, Windows presentation settings can be invoked.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mobilepcpresentationsettings#admx-mobilepcpresentationsettings-presentationsettingsenable-2"],"categoryId":"751cf9ec-7214-4b38-a09e-24922684bd8f","categoryName":"Presentation Settings","options":[{"id":"device_vendor_msft_policy_config_admx_mobilepcpresentationsettings_presentationsettingsenable_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mobilepcpresentationsettings_presentationsettingsenable_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msapolicy_microsoftaccount_disableuserauth","displayName":"Block all consumer Microsoft account user authentication","description":"This setting controls whether users can provide Microsoft accounts for authentication for applications or services. If this setting is enabled, all applications and services on the device are prevented from using Microsoft accounts for authentication. \r\nThis applies both to existing users of a device and new users who may be added. However, any application or service that has already authenticated a user will not be affected by enabling this setting until the authentication cache expires. \r\nIt is recommended to enable this setting before any user signs in to a device to prevent cached tokens from being present. If this setting is disabled or not configured, applications and services can use Microsoft accounts for authentication. \r\nBy default, this setting is Disabled. This setting does not affect whether users can sign in to devices by using Microsoft accounts, or the ability for users to provide Microsoft accounts via the browser for authentication with web-based applications. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msapolicy#admx-msapolicy-microsoftaccount-disableuserauth"],"categoryId":"60b898a9-0490-4599-b7f1-3cd451236266","categoryName":"Microsoft account","options":[{"id":"device_vendor_msft_policy_config_admx_msapolicy_microsoftaccount_disableuserauth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msapolicy_microsoftaccount_disableuserauth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy","displayName":"Automatic Maintenance Activation Boundary","description":"\r\n This policy setting allows you to configure Automatic Maintenance activation boundary.\r\n\r\n The maintenance activation boundary is the daily schduled time at which Automatic Maintenance starts\r\n\r\n If you enable this policy setting, this will override the default daily scheduled time as specified in Security and Maintenance/Automatic Maintenance Control Panel.\r\n\r\n If you disable or do not configure this policy setting, the daily scheduled time as specified in Security and Maintenance/Automatic Maintenance Control Panel will apply.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msched#admx-msched-activationboundarypolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy_activationboundary","displayName":"Regular maintenance activation boundary","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_msched_randomdelaypolicy","displayName":"Automatic Maintenance Random Delay","description":"\r\n This policy setting allows you to configure Automatic Maintenance activation random delay.\r\n\r\n The maintenance random delay is the amount of time up to which Automatic Maintenance will delay starting from its Activation Boundary.\r\n\r\n If you enable this policy setting, Automatic Maintenance will delay starting from its Activation Boundary, by upto this time.\r\n\r\n If you do not configure this policy setting, 4 hour random delay will be applied to Automatic Maintenance.\r\n\r\n If you disable this policy setting, no random delay will be applied to Automatic Maintenance.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msched#admx-msched-randomdelaypolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_msched_randomdelaypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msched_randomdelaypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msched_randomdelaypolicy_randomdelay","displayName":"Regular maintenance random delay","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdtsupportprovider","displayName":"Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider","description":"This policy setting configures Microsoft Support Diagnostic Tool (MSDT) interactive communication with the support provider. MSDT gathers diagnostic data for analysis by support professionals.\r\n\r\nIf you enable this policy setting, users can use MSDT to collect and send diagnostic data to a support professional to resolve a problem.\r\n\r\nBy default, the support provider is set to Microsoft Corporation.\r\n\r\nIf you disable this policy setting, MSDT cannot run in support mode, and no data can be collected or sent to the support provider.\r\n\r\nIf you do not configure this policy setting, MSDT support mode is enabled by default.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect. Changes take effect immediately.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msdt#admx-msdt-msdtsupportprovider"],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_msdtsupportprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdtsupportprovider_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy","displayName":"Microsoft Support Diagnostic Tool: Restrict tool download","description":"This policy setting restricts the tool download policy for Microsoft Support Diagnostic Tool.\r\n\r\nMicrosoft Support Diagnostic Tool (MSDT) gathers diagnostic data for analysis by support professionals. For some problems, MSDT may prompt the user to download additional tools for troubleshooting.\r\n\r\nThese tools are required to completely troubleshoot the problem. If tool download is restricted, it may not be possible to find the root cause of the problem.\r\n\r\nIf you enable this policy setting for remote troubleshooting, MSDT prompts the user to download additional tools to diagnose problems on remote computers only. If you enable this policy setting for local and remote troubleshooting, MSDT always prompts for additional tool downloading.\r\n\r\nIf you disable this policy setting, MSDT never downloads tools, and is unable to diagnose problems on remote computers.\r\n\r\nIf you do not configure this policy setting, MSDT prompts the user before downloading any additional tools.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect. Changes take effect immediately.\r\n\r\nThis policy setting will take effect only when MSDT is enabled.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msdt#admx-msdt-msdttooldownloadpolicy"],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_msdttooldownloadpolicylevel","displayName":"Tool downloads allowed","description":null,"helpText":"","infoUrls":[],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_msdttooldownloadpolicylevel_1","displayName":"Remote troubleshooting only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_msdttooldownloadpolicylevel_2","displayName":"Local and remote troubleshooting","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msdt_wdiscenarioexecutionpolicy","displayName":"Microsoft Support Diagnostic Tool: Configure execution level","description":"This policy setting determines the execution level for Microsoft Support Diagnostic Tool.\r\n\r\nMicrosoft Support Diagnostic Tool (MSDT) gathers diagnostic data for analysis by support professionals.\r\n\r\nIf you enable this policy setting, administrators can use MSDT to collect and send diagnostic data to a support professional to resolve a problem.\r\n\r\nIf you disable this policy setting, MSDT cannot gather diagnostic data.\r\n\r\nIf you do not configure this policy setting, MSDT is turned on by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect. Changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msdt#admx-msdt-wdiscenarioexecutionpolicy"],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownbrowse","displayName":"Allow users to browse for source while elevated","description":"This policy setting allows users to search for installation files during privileged installations.\r\n\r\nIf you enable this policy setting, the Browse button in the \"Use feature from\" dialog box is enabled. As a result, users can search for installation files even when the installation program is running with elevated system privileges.\r\n\r\nBecause the installation is running with elevated system privileges, users can browse through directories that their own permissions would not allow.\r\n\r\nThis policy setting does not affect installations that run in the user's security context. Also, see the \"Remove browse dialog box for new source\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, by default, only system administrators can browse during installations with elevated privileges, such as installations offered on the desktop or displayed in Add or Remove Programs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-allowlockdownbrowse"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownbrowse_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownbrowse_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownmedia","displayName":"Allow users to use media source while elevated","description":"This policy setting allows users to install programs from removable media during privileged installations.\r\n\r\nIf you enable this policy setting, all users are permitted to install programs from removable media, such as floppy disks and CD-ROMs, even when the installation program is running with elevated system privileges.\r\n\r\nThis policy setting does not affect installations that run in the user's security context. By default, users can install from removable media when the installation runs in their own security context.\r\n\r\nIf you disable or do not configure this policy setting, by default, users can install programs from removable media only when the installation runs in the user's security context. During privileged installations, such as those offered on the desktop or displayed in Add or Remove Programs, only system administrators can install from removable media.\r\n\r\nAlso, see the \"Prevent removable media source for any install\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-allowlockdownmedia"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownmedia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownmedia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownpatch","displayName":"Allow users to patch elevated products","description":"This policy setting allows users to patch elevated products.\r\n\r\nIf you enable this policy setting, all users are permitted to install patches, even when the installation program is running with elevated system privileges. Patches are updates or upgrades that replace only those program files that have changed. Because patches can easily be vehicles for malicious programs, some installations prohibit their use.\r\n\r\nIf you disable or do not configure this policy setting, by default, only system administrators can apply patches during installations with elevated privileges, such as installations offered on the desktop or displayed in Add or Remove Programs.\r\n\r\nThis policy setting does not affect installations that run in the user's security context. By default, users can install patches to programs that run in their own security context. Also, see the \"Prohibit patching\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-allowlockdownpatch"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownpatch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownpatch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown","displayName":"Prohibit use of Restart Manager","description":"This policy setting controls Windows Installer's interaction with the Restart Manager. The Restart Manager API can eliminate or reduce the number of system restarts that are required to complete an installation or update.\r\n\r\nIf you enable this policy setting, you can use the options in the Prohibit Use of Restart Manager box to control file in use detection behavior.\r\n\r\n-- The \"Restart Manager On\" option instructs Windows Installer to use Restart Manager to detect files in use and mitigate a system restart, when possible.\r\n\r\n-- The \"Restart Manager Off\" option turns off Restart Manager for file in use detection and the legacy file in use behavior is used.\r\n\r\n-- The \"Restart Manager Off for Legacy App Setup\" option applies to packages that were created for Windows Installer versions lesser than 4.0. This option lets those packages display the legacy files in use UI while still using Restart Manager for detection.\r\n\r\nIf you disable or do not configure this policy setting, Windows Installer will use Restart Manager to detect files in use and mitigate a system restart, when possible.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disableautomaticapplicationshutdown"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_disableautomaticapplicationshutdown","displayName":"Prohibit Usage of Restart Manager","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_disableautomaticapplicationshutdown_0","displayName":"Restart Manager On","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_disableautomaticapplicationshutdown_1","displayName":"Restart Manager Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_disableautomaticapplicationshutdown_2","displayName":"Restart Manager Off for Legacy App Setup","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disablebrowse","displayName":"Remove browse dialog box for new source","description":"\r\n This policy setting prevents users from searching for installation files when they add features or components to an installed program.\r\n\r\n If you enable this policy setting, the Browse button beside the \"Use feature from\" list in the Windows Installer dialog box is disabled. As a result, users must select an installation file source from the \"Use features from\" list that the system administrator configures.\r\n\r\n This policy setting applies even when the installation is running in the user's security context.\r\n\r\n If you disable or do not configure this policy setting, the Browse button is enabled when an installation is running in the user's security context. But only system administrators can browse when an installation is running with elevated system privileges, such as installations offered on the desktop or in Add or Remove Programs.\r\n\r\n This policy setting affects Windows Installer only. It does not prevent users from selecting other browsers, such as File Explorer or Network Locations, to search for installation files.\r\n\r\n Also, see the \"Enable user to browse for source while elevated\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablebrowse"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablebrowse_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablebrowse_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disableflyweightpatching","displayName":"Prohibit flyweight patching","description":"This policy setting controls the ability to turn off all patch optimizations.\r\n\r\nIf you enable this policy setting, all Patch Optimization options are turned off during the installation.\r\n\r\nIf you disable or do not configure this policy setting, it enables faster application of patches by removing execution of unnecessary actions. The flyweight patching mode is primarily designed for patches that just update a few files or registry values. The Installer will analyze the patch for specific changes to determine if optimization is possible. If so, the patch will be applied using a minimal set of processing.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disableflyweightpatching"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableflyweightpatching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableflyweightpatching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disableflyweightpatching_disableflyweightpatching","displayName":"Prohibit Flyweight Patching","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableflyweightpatching_disableflyweightpatching_1","displayName":"Patch Optimization Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableflyweightpatching_disableflyweightpatching_0","displayName":"Patch Optimization On","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage","displayName":"Turn off logging via package settings","description":"This policy setting controls Windows Installer's processing of the MsiLogging property. The MsiLogging property in an installation package can be used to enable automatic logging of all install operations for the package.\r\n\r\nIf you enable this policy setting, you can use the options in the Disable logging via package settings box to control automatic logging via package settings behavior.\r\n\r\n-- The \"Logging via package settings on\" option instructs Windows Installer to automatically generate log files for packages that include the MsiLogging property.\r\n\r\n-- The \"Logging via package settings off\" option turns off the automatic logging behavior when specified via the MsiLogging policy. Log files can still be generated using the logging command line switch or the Logging policy.\r\n\r\nIf you disable or do not configure this policy setting, Windows Installer will automatically generate log files for those packages that include the MsiLogging property.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disableloggingfrompackage"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_disableloggingfrompackage","displayName":"Disable logging via package settings","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_disableloggingfrompackage_1","displayName":"Disable logging via package settings off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_disableloggingfrompackage_0","displayName":"Disable logging via package settings on","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi","displayName":"Turn off Windows Installer","description":"This policy setting restricts the use of Windows Installer.\r\n\r\nIf you enable this policy setting, you can prevent users from installing software on their systems or permit users to install only those programs offered by a system administrator. You can use the options in the Disable Windows Installer box to establish an installation setting.\r\n\r\n-- The \"Never\" option indicates Windows Installer is fully enabled. Users can install and upgrade software. This is the default behavior for Windows Installer on Windows 2000 Professional, Windows XP Professional and Windows Vista when the policy is not configured.\r\n\r\n-- The \"For non-managed applications only\" option permits users to install only those programs that a system administrator assigns (offers on the desktop) or publishes (adds them to Add or Remove Programs). This is the default behavior of Windows Installer on Windows Server 2003 family when the policy is not configured.\r\n\r\n-- The \"Always\" option indicates that Windows Installer is disabled.\r\n\r\nThis policy setting affects Windows Installer only. It does not prevent users from using other methods to install and upgrade programs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablemsi"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_disablemsi","displayName":"Disable Windows Installer","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_disablemsi_2","displayName":"Always","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_disablemsi_1","displayName":"For non-managed applications only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_disablemsi_0","displayName":"Never","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disablepatch","displayName":"Prevent users from using Windows Installer to install updates and upgrades","description":"This policy setting prevents users from using Windows Installer to install patches.\r\n\r\nIf you enable this policy setting, users are prevented from using Windows Installer to install patches. Patches are updates or upgrades that replace only those program files that have changed. Because patches can be easy vehicles for malicious programs, some installations prohibit their use.\r\n\r\nNote: This policy setting applies only to installations that run in the user's security context.\r\n\r\nIf you disable or do not configure this policy setting, by default, users who are not system administrators cannot apply patches to installations that run with elevated system privileges, such as those offered on the desktop or in Add or Remove Programs.\r\n\r\nAlso, see the \"Enable user to patch elevated products\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablepatch"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablepatch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablepatch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disablerollback_2","displayName":"Prohibit rollback","description":"This policy setting prohibits Windows Installer from generating and saving the files it needs to reverse an interrupted or unsuccessful installation.\r\n\r\nIf you enable this policy setting, Windows Installer is prevented from recording the original state of the system and sequence of changes it makes during installation. It also prevents Windows Installer from retaining files it intends to delete later. As a result, Windows Installer cannot restore the computer to its original state if the installation does not complete.\r\n\r\nThis policy setting is designed to reduce the amount of temporary disk space required to install programs. Also, it prevents malicious users from interrupting an installation to gather data about the internal state of the computer or to search secure system files. However, because an incomplete installation can render the system or a program inoperable, do not use this policy setting unless it is essential.\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If the policy setting is enabled in either folder, it is considered be enabled, even if it is explicitly disabled in the other folder.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablerollback-2"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablerollback_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablerollback_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_disablesharedcomponent","displayName":"Turn off shared components","description":"This policy setting controls the ability to turn off shared components.\r\n\r\nIf you enable this policy setting, no packages on the system get the shared component functionality enabled by the msidbComponentAttributesShared attribute in the Component Table.\r\n\r\nIf you disable or do not configure this policy setting, by default, the shared component functionality is allowed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablesharedcomponent"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablesharedcomponent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablesharedcomponent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableluapatching","displayName":"Prohibit non-administrators from applying vendor signed updates","description":"This policy setting controls the ability of non-administrators to install updates that have been digitally signed by the application vendor.\r\n\r\nNon-administrator updates provide a mechanism for the author of an application to create digitally signed updates that can be applied by non-privileged users.\r\n\r\nIf you enable this policy setting, only administrators or users with administrative privileges can apply updates to Windows Installer based applications.\r\n\r\nIf you disable or do not configure this policy setting, users without administrative privileges can install non-administrator updates.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-disableluapatching"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableluapatching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableluapatching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablepatchuninstall","displayName":"Prohibit removal of updates","description":"This policy setting controls the ability for users or administrators to remove Windows Installer based updates.\r\n\r\nThis policy setting should be used if you need to maintain a tight control over updates. One example is a lockdown environment where you want to ensure that updates once installed cannot be removed by users or administrators.\r\n\r\nIf you enable this policy setting, updates cannot be removed from the computer by a user or an administrator. The Windows Installer can still remove an update that is no longer applicable to the product.\r\n\r\nIf you disable or do not configure this policy setting, a user can remove an update from the computer only if the user has been granted privileges to remove the update. This can depend on whether the user is an administrator, whether \"Disable Windows Installer\" and \"Always install with elevated privileges\" policy settings are set, and whether the update was installed in a per-user managed, per-user unmanaged, or per-machine context.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-disablepatchuninstall"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablepatchuninstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablepatchuninstall_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablesrcheckpoints","displayName":"Turn off creation of System Restore checkpoints","description":"This policy setting prevents Windows Installer from creating a System Restore checkpoint each time an application is installed. System Restore enables users, in the event of a problem, to restore their computers to a previous state without losing personal data files.\r\n\r\nIf you enable this policy setting, the Windows Installer does not generate System Restore checkpoints when installing applications.\r\n\r\nIf you disable or do not configure this policy setting, by default, the Windows Installer automatically creates a System Restore checkpoint each time an application is installed, so that users can restore their computer to the state it was in before installing the application.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-disablesrcheckpoints"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablesrcheckpoints_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablesrcheckpoints_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls","displayName":"Prohibit User Installs","description":"This policy setting allows you to configure user installs. To configure this policy setting, set it to enabled and use the drop-down list to select the behavior you want.\r\n\r\nIf you do not configure this policy setting, or if the policy setting is enabled and \"Allow User Installs\" is selected, the installer allows and makes use of products that are installed per user, and products that are installed per computer. If the installer finds a per-user install of an application, this hides a per-computer installation of that same product.\r\n\r\nIf you enable this policy setting and \"Hide User Installs\" is selected, the installer ignores per-user applications. This causes a per-computer installed application to be visible to users, even if those users have a per-user install of the product registered in their user profile.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-disableuserinstalls"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_msi_disableuserinstallsbox","displayName":"User Install Behavior:","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_msi_disableuserinstallsbox_0","displayName":"Allow User Installs","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_msi_disableuserinstallsbox_1","displayName":"Hide User Installs","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_enforceupgradecomponentrules","displayName":"Enforce upgrade component rules","description":"This policy setting causes the Windows Installer to enforce strict rules for component upgrades.\r\n\r\nIf you enable this policy setting, strict upgrade rules will be enforced by the Windows Installer which may cause some upgrades to fail. Upgrades can fail if they attempt to do one of the following:\r\n\r\n(1) Remove a component from a feature.\r\nThis can also occur if you change the GUID of a component. The component identified by the original GUID appears to be removed and the component as identified by the new GUID appears as a new component.\r\n\r\n(2) Add a new feature to the top or middle of an existing feature tree.\r\nThe new feature must be added as a new leaf feature to an existing feature tree.\r\n\r\nIf you disable or do not configure this policy setting, the Windows Installer will use less restrictive rules for component upgrades.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-enforceupgradecomponentrules"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_enforceupgradecomponentrules_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_enforceupgradecomponentrules_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize","displayName":"Control maximum size of baseline file cache","description":"\r\n This policy controls the percentage of disk space available to the Windows Installer baseline file cache.\r\n\r\n The Windows Installer uses the baseline file cache to save baseline files modified by binary delta difference updates. The cache is used to retrieve the baseline file for future updates. The cache eliminates user prompts for source media when new updates are applied.\r\n\r\n If you enable this policy setting you can modify the maximum size of the Windows Installer baseline file cache.\r\n\r\n If you set the baseline cache size to 0, the Windows Installer will stop populating the baseline cache for new updates. The existing cached files will remain on disk and will be deleted when the product is removed.\r\n\r\n If you set the baseline cache to 100, the Windows Installer will use available free space for the baseline file cache.\r\n\r\n If you disable or do not configure this policy setting, the Windows Installer will uses a default value of 10 percent for the baseline file cache maximum size.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-maxpatchcachesize"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize_msi_maxpatchcachesize","displayName":"Baseline file cache maximum size","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":null},{"id":"device_vendor_msft_policy_config_admx_msi_msidisableembeddedui","displayName":"Prevent embedded UI","description":"This policy setting controls the ability to prevent embedded UI.\r\n\r\nIf you enable this policy setting, no packages on the system can run embedded UI.\r\n\r\nIf you disable or do not configure this policy setting, embedded UI is allowed to run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msidisableembeddedui"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msidisableembeddedui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msidisableembeddedui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msilogging","displayName":"Specify the types of events Windows Installer records in its transaction log","description":"\r\n Specifies the types of events that Windows Installer records in its transaction log for each installation. The log, Msi.log, appears in the Temp directory of the system volume.\r\n\r\n When you enable this policy setting, you can specify the types of events you want Windows Installer to record. To indicate that an event type is recorded, type the letter representing the event type. You can type the letters in any order and list as many or as few event types as you want.\r\n\r\n To disable logging, delete all of the letters from the box.\r\n\r\n If you disable or do not configure this policy setting, Windows Installer logs the default event types, represented by the letters \"iweap.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msilogging"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msilogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msilogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_msilogging_msilogging","displayName":"Logging","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":null},{"id":"device_vendor_msft_policy_config_admx_msi_safeforscripting","displayName":"Prevent Internet Explorer security prompt for Windows Installer scripts","description":"This policy setting allows Web-based programs to install software on the computer without notifying the user.\r\n\r\nIf you disable or do not configure this policy setting, by default, when a script hosted by an Internet browser tries to install a program on the system, the system warns users and allows them to select or refuse the installation.\r\n\r\nIf you enable this policy setting, the warning is suppressed and allows the installation to proceed.\r\n\r\nThis policy setting is designed for enterprises that use Web-based tools to distribute programs to their employees. However, because this policy setting can pose a security risk, it should be applied cautiously.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-safeforscripting"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_safeforscripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_safeforscripting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msi_transformssecure","displayName":"Save copies of transform files in a secure location on workstation","description":"This policy setting saves copies of transform files in a secure location on the local computer.\r\n\r\nTransform files consist of instructions to modify or customize a program during installation.\r\n\r\nIf you enable this policy setting, the transform file is saved in a secure location on the user's computer.\r\n\r\nIf you do not configure this policy setting on Windows Server 2003, Windows Installer requires the transform file in order to repeat an installation in which the transform file was used, therefore, the user must be using the same computer or be connected to the original or identical media to reinstall, remove, or repair the installation.\r\n\r\nThis policy setting is designed for enterprises to prevent unauthorized or malicious editing of transform files.\r\n\r\nIf you disable this policy setting, Windows Installer stores transform files in the Application Data directory in the user's profile.\r\n\r\nIf you do not configure this policy setting on Windows 2000 Professional, Windows XP Professional and Windows Vista, when a user reinstalls, removes, or repairs an installation, the transform file is available, even if the user is on a different computer or is not connected to the network.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-transformssecure"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_transformssecure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_transformssecure_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy","displayName":"Configure MSI Corrupted File Recovery behavior","description":"This policy setting allows you to configure the recovery behavior for corrupted MSI files to one of three states:\r\n\r\nPrompt for Resolution: Detection, troubleshooting, and recovery of corrupted MSI applications will be turned on. Windows will prompt the user with a dialog box when application reinstallation is required. This is the default recovery behavior on Windows client.\r\n\r\nSilent: Detection, troubleshooting, and notification of MSI application to reinstall will occur with no UI. Windows will log an event when corruption is determined and will suggest the application that should be re-installed. This behavior is recommended for headless operation and is the default recovery behavior on Windows server.\r\n\r\nTroubleshooting Only: Detection and verification of file corruption will be performed without UI. Recovery is not attempted.\r\n\r\nIf you enable this policy setting, the recovery behavior for corrupted files is set to either the Prompt For Resolution (default on Windows client), Silent (default on Windows server), or Troubleshooting Only. \r\n\r\nIf you disable this policy setting, the troubleshooting and recovery behavior for corrupted files will be disabled. No troubleshooting or resolution will be attempted.\r\n\r\nIf you do not configure this policy setting, the recovery behavior for corrupted files will be set to the default recovery behavior.\r\n\r\nNo system or service restarts are required for changes to this policy setting to take immediate effect after a Group Policy refresh.\r\n\r\nNote: This policy setting will take effect only when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, system file recovery will not be attempted. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msifilerecovery#admx-msifilerecovery-wdiscenarioexecutionpolicy"],"categoryId":"e50acc0f-d177-4803-aa31-fc97eeb60ff2","categoryName":"MSI Corrupted File Recovery","options":[{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"e50acc0f-d177-4803-aa31-fc97eeb60ff2","categoryName":"MSI Corrupted File Recovery","options":[{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_1","displayName":"Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_2","displayName":"Prompt for Resolution","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_3","displayName":"Silent","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoadminlogon","displayName":"MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)","description":"MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autoadminlogon"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoadminlogon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoadminlogon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoreboot","displayName":"MSS: (AutoReboot) Allow Windows to automatically restart after a system crash (recommended except for highly secure environments)","description":"MSS: (AutoReboot) Allow Windows to automatically restart after a system crash (recommended except for highly secure environments)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autoreboot"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoreboot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoreboot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoshareserver","displayName":"MSS: (AutoShareServer) Enable Administrative Shares (recommended except for highly secure environments)","description":"MSS: (AutoShareServer) Enable Administrative Shares (recommended except for highly secure environments)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autoshareserver"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoshareserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoshareserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autosharewks","displayName":"MSS: (AutoShareWks) Enable Administrative Shares (recommended except for highly secure environments)","description":"MSS: (AutoShareWks) Enable Administrative Shares (recommended except for highly secure environments)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autosharewks"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autosharewks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autosharewks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_disablesavepassword","displayName":"MSS: (DisableSavePassword) Prevent the dial-up passsword from being saved (recommended)","description":"MSS: (DisableSavePassword) Prevent the dial-up passsword from being saved (recommended)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-disablesavepassword"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_disablesavepassword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_disablesavepassword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_enabledeadgwdetect","displayName":"MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)","description":"MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-enabledeadgwdetect"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_enabledeadgwdetect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_enabledeadgwdetect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_hidefrombrowselist","displayName":"MSS: (Hidden) Hide Computer From the Browse List (not recommended except for highly secure environments)","description":"MSS: (Hidden) Hide Computer From the Browse List (not recommended except for highly secure environments)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-hidefrombrowselist"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_hidefrombrowselist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_hidefrombrowselist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime","displayName":"MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds","description":"MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-keepalivetime"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime","displayName":"KeepAliveTime","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_150000","displayName":"150000 or 2.5 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_300000","displayName":"300000 or 5 minutes (recommended) ","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_600000","displayName":"600000 or 10 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_1200000","displayName":"1200000 or 20 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_2400000","displayName":"2400000 or 40 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_3600000","displayName":"3600000 or 1 hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_keepalivetime_keepalivetime_7200000","displayName":"7200000 or 2 hours (default value)","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt","displayName":"MSS: (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic. ","description":"MSS: (NoDefaultExempt) Configure IPSec exemptions for various types of network traffic. \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-nodefaultexempt"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt","displayName":"NoDefaultExempt","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_0","displayName":"Allow all exemptions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_1","displayName":"Multicast, broadcast, & ISAKMP exempt.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_2","displayName":"RSVP, Kerberos, and ISAKMP are exempt.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_3","displayName":"Only ISAKMP is exempt.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation","displayName":"MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames","description":"MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-ntfsdisable8dot3namecreation"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation","displayName":"NtfsDisable8dot3NameCreation","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_0","displayName":"Enable 8Dot3 Creation on all Volumes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_1","displayName":"Disable 8Dot3 Creation on all Volumes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_2","displayName":"Set 8dot3 name creation per volume using FSUTIL","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_3","displayName":"Disable 8Dot3 name creation on all volumes except system volume","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_performrouterdiscovery","displayName":"MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)","description":"MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to DoS)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-performrouterdiscovery"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_performrouterdiscovery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_performrouterdiscovery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_safedllsearchmode","displayName":"MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)","description":"MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-safedllsearchmode"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_safedllsearchmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_safedllsearchmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_screensavergraceperiod","displayName":"MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)","description":"MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-screensavergraceperiod"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_screensavergraceperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_screensavergraceperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_screensavergraceperiod_screensavergraceperiod","displayName":"ScreenSaverGracePeriod","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect","displayName":"MSS: (SynAttackProtect) Syn attack protection level (protects against DoS)","description":"MSS: (SynAttackProtect) Syn attack protection level (protects against DoS)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-synattackprotect"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_synattackprotect","displayName":"SynAttackProtect","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_synattackprotect_0","displayName":"No additional protection, use default settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_synattackprotect_1","displayName":"Connections time out sooner if a SYN attack is detected","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions","displayName":"MSS: (TcpMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged","description":"MSS: (TcpMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-tcpmaxconnectresponseretransmissions"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_tcpmaxconnectresponseretransmissions","displayName":"TcpMaxConnectResponseRetransmissions","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_tcpmaxconnectresponseretransmissions_0","displayName":"No retransmission, half-open connections dropped after 3 seconds","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_tcpmaxconnectresponseretransmissions_1","displayName":"3 seconds, half-open connections dropped after 9 seconds","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_tcpmaxconnectresponseretransmissions_2","displayName":"3 & 6 seconds, half-open connections dropped after 21 seconds","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_tcpmaxconnectresponseretransmissions_3","displayName":"3, 6, & 9 seconds, half-open connections dropped after 45 seconds","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions","displayName":"MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)","description":"MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-tcpmaxdataretransmissions"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions_tcpmaxdataretransmissions","displayName":"TcpMaxDataRetransmissions","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6","displayName":"MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)","description":"MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-tcpmaxdataretransmissionsipv6"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6_tcpmaxdataretransmissions","displayName":"TcpMaxDataRetransmissions","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel","displayName":"MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning","description":"MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-warninglevel"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_warninglevel","displayName":"WarningLevel","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_warninglevel_50","displayName":"50%","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_warninglevel_60","displayName":"60%","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_warninglevel_70","displayName":"70%","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_warninglevel_80","displayName":"80%","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_warninglevel_warninglevel_90","displayName":"90%","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_corporateresources","displayName":"Corporate Resources","description":"Specifies resources on your intranet that are normally accessible to DirectAccess clients. Each entry is a string that identifies the type of resource and the location of the resource. \r\n\r\nEach string can be one of the following types:\r\n\t \r\n- A DNS name or IPv6 address that NCA pings. The syntax is “PING:” followed by a fully qualified domain name (FQDN) that resolves to an IPv6 address, or an IPv6 address. Examples: PING:myserver.corp.contoso.com or PING:2002:836b:1::1. \r\n \r\nNote \r\n\r\nWe recommend that you use FQDNs instead of IPv6 addresses wherever possible.\r\n\r\nImportant \r\n\r\nAt least one of the entries must be a PING: resource.\r\n\r\n-\tA Uniform Resource Locator (URL) that NCA queries with a Hypertext Transfer Protocol (HTTP) request. The contents of the web page do not matter. The syntax is “HTTP:” followed by a URL. The host portion of the URL must resolve to an IPv6 address of a Web server or contain an IPv6 address. Examples: HTTP:http://myserver.corp.contoso.com/ or HTTP:http://2002:836b:1::1/.\r\n\r\n-\tA Universal Naming Convention (UNC) path to a file that NCA checks for existence. The contents of the file do not matter. The syntax is “FILE:” followed by a UNC path. The ComputerName portion of the UNC path must resolve to an IPv6 address or contain an IPv6 address. Examples: FILE:\\\\myserver\\myshare\\test.txt or FILE:\\\\2002:836b:1::1\\myshare\\test.txt.\r\n\r\nYou must configure this setting to have complete NCA functionality.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-corporateresources"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_corporateresources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_corporateresources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_corporateresources_corporateresources_control","displayName":"Corporate Resources","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_nca_customcommands","displayName":"Custom Commands","description":"Specifies commands configured by the administrator for custom logging. These commands will run in addition to default log commands.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-customcommands"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_customcommands_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_customcommands_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_customcommands_customcommands_control","displayName":"CustomCommands","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_nca_dtes","displayName":"IPsec Tunnel Endpoints","description":"Specifies the IPv6 addresses of the endpoints of the Internet Protocol security (IPsec) tunnels that enable DirectAccess. NCA attempts to access the resources that are specified in the Corporate Resources setting through these configured tunnel endpoints. \r\n\r\nBy default, NCA uses the same DirectAccess server that the DirectAccess client computer connection is using. In default configurations of DirectAccess, there are typically two IPsec tunnel endpoints: one for the infrastructure tunnel and one for the intranet tunnel. You should configure one endpoint for each tunnel. \r\n\t \r\nEach entry consists of the text PING: followed by the IPv6 address of an IPsec tunnel endpoint. Example: PING:2002:836b:1::836b:1.\r\n\r\nYou must configure this setting to have complete NCA functionality.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-dtes"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_dtes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_dtes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_dtes_dtes_control","displayName":"DTEs","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname","displayName":"Friendly Name","description":"Specifies the string that appears for DirectAccess connectivity when the user clicks the Networking notification area icon. For example, you can specify “Contoso Intranet Access” for the DirectAccess clients of the Contoso Corporation.\r\n\r\nIf this setting is not configured, the string that appears for DirectAccess connectivity is “Corporate Connection”.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-friendlyname"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname_friendlyname_control","displayName":"Friendly Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_nca_localnameson","displayName":"Prefer Local Names Allowed","description":"Specifies whether the user has Connect and Disconnect options for the DirectAccess entry when the user clicks the Networking notification area icon.\r\n\r\nIf the user clicks the Disconnect option, NCA removes the DirectAccess rules from the Name Resolution Policy Table (NRPT) and the DirectAccess client computer uses whatever normal name resolution is available to the client computer in its current network configuration, including sending all DNS queries to the local intranet or Internet DNS servers. Note that NCA does not remove the existing IPsec tunnels and users can still access intranet resources across the DirectAccess server by specifying IPv6 addresses rather than names.\r\n\r\nThe ability to disconnect allows users to specify single-label, unqualified names (such as “PRINTSVR”) for local resources when connected to a different intranet and for temporary access to intranet resources when network location detection has not correctly determined that the DirectAccess client computer is connected to its own intranet.\r\n\r\nTo restore the DirectAccess rules to the NRPT and resume normal DirectAccess functionality, the user clicks Connect.\r\n\r\nNote \r\nIf the DirectAccess client computer is on the intranet and has correctly determined its network location, the Disconnect option has no effect because the rules for DirectAccess are already removed from the NRPT.\r\n\r\nIf this setting is not configured, users do not have Connect or Disconnect options.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-localnameson"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_localnameson_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_localnameson_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_passivemode","displayName":"DirectAccess Passive Mode","description":"Specifies whether NCA service runs in Passive Mode or not.\r\n\r\nSet this to Disabled to keep NCA probing actively all the time. If this setting is not configured, NCA probing is in active mode by default.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-passivemode"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_passivemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_passivemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_showui","displayName":"User Interface","description":"Specifies whether an entry for DirectAccess connectivity appears when the user clicks the Networking notification area icon.\r\n\r\nSet this to Disabled to prevent user confusion when you are just using DirectAccess to remotely manage DirectAccess client computers from your intranet and not providing seamless intranet access. \r\n\r\nIf this setting is not configured, the entry for DirectAccess connectivity appears.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-showui"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_showui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_showui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_supportemail","displayName":"Support Email Address","description":"Specifies the e-mail address to be used when sending the log files that are generated by NCA to the network administrator. \r\n\r\nWhen the user sends the log files to the Administrator, NCA uses the default e-mail client to open a new message with the support email address in the To: field of the message, then attaches the generated log files as a .html file. The user can review the message and add additional information before sending the message.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-supportemail"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_supportemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_supportemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_nca_supportemail_supportemail_control","displayName":"Support Email","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobecontent","displayName":"Specify corporate DNS probe host address","description":"This policy setting enables you to specify the expected address of the host name used for the DNS probe. Successful resolution of the host name to this address indicates corporate connectivity.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-corpdnsprobecontent"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobecontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobecontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobecontent_ncsi_corpdnsprobecontentbox","displayName":"Corporate DNS Probe Address:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobehost","displayName":"Specify corporate DNS probe host name","description":"This policy setting enables you to specify the host name of a computer known to be on the corporate network. Successful resolution of this host name to the expected address indicates corporate connectivity.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-corpdnsprobehost"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobehost_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobehost_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobehost_ncsi_corpdnsprobehostbox","displayName":"Corporate DNS Probe Hostname:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpsiteprefixes","displayName":"Specify corporate site prefix list","description":"This policy setting enables you to specify the list of IPv6 corporate site prefixes to monitor for corporate connectivity. Reachability of addresses with any of these prefixes indicates corporate connectivity.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-corpsiteprefixes"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpsiteprefixes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpsiteprefixes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpsiteprefixes_ncsi_corpsiteprefixesbox","displayName":"Corporate Site Prefix List:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpwebprobeurl","displayName":"Specify corporate Website probe URL","description":"This policy setting enables you to specify the URL of the corporate website, against which an active probe is performed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-corpwebprobeurl"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpwebprobeurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpwebprobeurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpwebprobeurl_ncsi_corpwebprobeurlbox","displayName":"Corporate Website Probe URL:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_domainlocationdeterminationurl","displayName":"Specify domain location determination URL","description":"This policy setting enables you to specify the HTTPS URL of the corporate website that clients use to determine the current domain location (i.e. whether the computer is inside or outside the corporate network). Reachability of the URL destination indicates that the client location is inside corporate network; otherwise it is outside the network.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-domainlocationdeterminationurl"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_domainlocationdeterminationurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_domainlocationdeterminationurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_domainlocationdeterminationurl_ncsi_domainlocationdeterminationurlbox","displayName":"Corporate Domain Location Determination URL:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_globaldns","displayName":"Specify global DNS","description":"This policy setting enables you to specify DNS binding behavior. NCSI by default will restrict DNS lookups to the interface it is currently probing on. If you enable this setting, NCSI will allow the DNS lookups to happen on any interface.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-globaldns"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_globaldns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_globaldns_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_globaldns_ncsi_useglobaldns_checkbox","displayName":"Use global DNS","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_globaldns_ncsi_useglobaldns_checkbox_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_globaldns_ncsi_useglobaldns_checkbox_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling","displayName":"Specify passive polling","description":"This Policy setting enables you to specify passive polling behavior. NCSI polls various measurements throughout the network stack on a frequent interval to determine if network connectivity has been lost. Use the options to control the passive polling behavior.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-passivepolling"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_ncsi_disablepassivepolling_checkbox","displayName":"Disable passive polling","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_ncsi_disablepassivepolling_checkbox_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_ncsi_disablepassivepolling_checkbox_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresslookuponpingbehavior","displayName":"Specify address lookup behavior for DC locator ping","description":"This policy setting configures how a domain controller (DC) behaves when responding to a client whose IP address does not map to any configured site.\r\n\r\nDomain controllers use the client IP address during a DC locator ping request to compute which Active Directory site the client belongs to. If no site mapping can be computed, the DC may do an address lookup on the client network name to discover other IP addresses which may then be used to compute a matching site for the client. \r\n\r\nThe allowable values for this setting result in the following behaviors:\r\n\r\n0 - DCs will never perform address lookups.\r\n1 - DCs will perform an exhaustive address lookup to discover additional client IP addresses.\r\n2 - DCs will perform a fast, DNS-only address lookup to discover additional client IP addresses.\r\n\r\nTo specify this behavior in the DC Locator DNS SRV records, click Enabled, and then enter a value. The range of values is from 0 to 2.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-addresslookuponpingbehavior"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresslookuponpingbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresslookuponpingbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresslookuponpingbehavior_netlogon_addresslookuponpingbehaviorlabel","displayName":"Address lookup behavior:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresstypereturned","displayName":"Return domain controller address type","description":"This policy setting detremines the type of IP address that is returned for a domain controller. The DC Locator APIs return the IP address of the DC with the other parts of information. Before the support of IPv6, the returned DC IP address was IPv4. But with the support of IPv6, the DC Locator APIs can return IPv6 DC address. The returned IPv6 DC address may not be correctly handled by some of the existing applications. So this policy is provided to support such scenarios.\r\n\r\nBy default, DC Locator APIs can return IPv4/IPv6 DC address. But if some applications are broken due to the returned IPv6 DC address, this policy can be used to disable the default behavior and enforce to return only IPv4 DC address. Once applications are fixed, this policy can be used to enable the default behavior.\r\n\r\nIf you enable this policy setting, DC Locator APIs can return IPv4/IPv6 DC address. This is the default behavior of the DC Locator.\r\n\r\nIf you disable this policy setting, DC Locator APIs will ONLY return IPv4 DC address if any. So if the domain controller supports both IPv4 and IPv6 addresses, DC Locator APIs will return IPv4 address. But if the domain controller supports only IPv6 address, then DC Locator APIs will fail.\r\n\r\nIf you do not configure this policy setting, DC Locator APIs can return IPv4/IPv6 DC address. This is the default behavior of the DC Locator.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-addresstypereturned"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresstypereturned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_addresstypereturned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowdnssuffixsearch","displayName":"Use DNS name resolution when a single-label domain name is used, by appending different registered DNS suffixes, if the AllowSingleLabelDnsDomain setting is not enabled.","description":"This policy setting specifies whether the computers to which this setting is applied attemps DNS name resolution of single-lablel domain names, by appending different registered DNS suffixes, and uses NetBIOS name resolution only if DNS name resolution fails. This policy, including the specified default behavior, is not used if the AllowSingleLabelDnsDomain policy setting is enabled.\r\n\r\nBy default, when no setting is specified for this policy, the behavior is the same as explicitly enabling this policy, unless the AllowSingleLabelDnsDomain policy setting is enabled.\r\n\r\nIf you enable this policy setting, when the AllowSingleLabelDnsDomain policy is not enabled, computers to which this policy is applied, will locate a domain controller hosting an Active Directory domain specified with a single-label name, by appending different registered DNS suffixes to perform DNS name resolution. The single-label name is not used without appending DNS suffixes unless the computer is joined to a domain that has a single-label DNS name in the Active Directory forest. NetBIOS name resolution is performed on the single-label name only, in the event that DNS resolution fails.\r\n\r\nIf you disable this policy setting, when the AllowSingleLabelDnsDomain policy is not enabled, computers to which this policy is applied, will only use NetBIOS name resolution to attempt to locate a domain controller hosting an Active Directory domain specified with a single-label name. The computers will not attempt DNS name resolution in this case, unless the computer is searching for a domain with a single label DNS name to which this computer is joined, in the Active Directory forest.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-allowdnssuffixsearch"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowdnssuffixsearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowdnssuffixsearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allownt4crypto","displayName":"Allow cryptography algorithms compatible with Windows NT 4.0","description":"This policy setting controls whether the Net Logon service will allow the use of older cryptography algorithms that are used in Windows NT 4.0. The cryptography algorithms used in Windows NT 4.0 and earlier are not as secure as newer algorithms used in Windows 2000 or later, including this version of Windows.\r\n\r\nBy default, Net Logon will not allow the older cryptography algorithms to be used and will not include them in the negotiation of cryptography algorithms. Therefore, computers running Windows NT 4.0 will not be able to establish a connection to this domain controller.\r\n \r\nIf you enable this policy setting, Net Logon will allow the negotiation and use of older cryptography algorithms compatible with Windows NT 4.0. However, using the older algorithms represents a potential security risk.\r\n\r\nIf you disable this policy setting, Net Logon will not allow the negotiation and use of older cryptography algorithms. \r\n\r\nIf you do not configure this policy setting, Net Logon will not allow the negotiation and use of older cryptography algorithms.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-allownt4crypto"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allownt4crypto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allownt4crypto_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowsinglelabeldnsdomain","displayName":"Use DNS name resolution with a single-label domain name instead of NetBIOS name resolution to locate the DC","description":"This policy setting specifies whether the computers to which this setting is applied attempt DNS name resolution of a single-label domain names.\r\n\r\nBy default, the behavior specified in the AllowDnsSuffixSearch is used. If the AllowDnsSuffixSearch policy is disabled, then NetBIOS name resolution is used exclusively, to locate a domain controller hosting an Active Directory domain specified with a single-label name.\r\n\r\nIf you enable this policy setting, computers to which this policy is applied will attempt to locate a domain controller hosting an Active Directory domain specified with a single-label name using DNS name resolution.\r\n\r\nIf you disable this policy setting, computers to which this setting is applied will use the AllowDnsSuffixSearch policy, if it is not disabled or perform NetBIOS name resolution otherwise, to attempt to locate a domain controller that hosts an Active Directory domain specified with a single-label name. the computers will not the DNS name resolution in this case, unless the computer is searching for a domain with a single label DNS name that exists in the Active Directory forest to which this computer is joined.\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-allowsinglelabeldnsdomain"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowsinglelabeldnsdomain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowsinglelabeldnsdomain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_autositecoverage","displayName":"Use automated site coverage by the DC Locator DNS SRV Records","description":"This policy setting determines whether domain controllers (DC) will dynamically register DC Locator site-specific SRV records for the closest sites where no DC for the same domain exists (or no Global Catalog for the same forest exists). These DNS records are dynamically registered by the Net Logon service, and they are used to locate the DC.\r\n\r\nIf you enable this policy setting, the DCs to which this setting is applied dynamically register DC Locator site-specific DNS SRV records for the closest sites where no DC for the same domain, or no Global Catalog for the same forest, exists.\r\n\r\nIf you disable this policy setting, the DCs will not register site-specific DC Locator DNS SRV records for any other sites but their own.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-autositecoverage"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_autositecoverage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_autositecoverage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_avoidfallbacknetbiosdiscovery","displayName":"Do not use NetBIOS-based discovery for domain controller location when DNS-based discovery fails","description":"This policy setting allows you to control the domain controller (DC) location algorithm. By default, the DC location algorithm prefers DNS-based discovery if the DNS domain name is known. If DNS-based discovery fails and the NetBIOS domain name is known, the algorithm then uses NetBIOS-based discovery as a fallback mechanism.\r\n\r\nNetBIOS-based discovery uses a WINS server and mailslot messages but does not use site information. Hence it does not ensure that clients will discover the closest DC. It also allows a hub-site client to discover a branch-site DC even if the branch-site DC only registers site-specific DNS records (as recommended). For these reasons, NetBIOS-based discovery is not recommended.\r\n\r\nNote that this policy setting does not affect NetBIOS-based discovery for DC location if only the NetBIOS domain name is known.\r\n\r\nIf you enable or do not configure this policy setting, the DC location algorithm does not use NetBIOS-based discovery as a fallback mechanism when DNS-based discovery fails. This is the default behavior.\r\n\r\nIf you disable this policy setting, the DC location algorithm can use NetBIOS-based discovery as a fallback mechanism when DNS based discovery fails.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-avoidfallbacknetbiosdiscovery"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_avoidfallbacknetbiosdiscovery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_avoidfallbacknetbiosdiscovery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_avoidpdconwan","displayName":"Contact PDC on logon failure","description":"This policy setting defines whether a domain controller (DC) should attempt to verify the password provided by a client with the PDC emulator if the DC failed to validate the password.\r\n\r\nContacting the PDC emulator is useful in case the client’s password was recently changed and did not propagate to the DC yet. Users may want to disable this feature if the PDC emulator is located over a slow WAN connection.\r\n\r\nIf you enable this policy setting, the DCs to which this policy setting applies will attempt to verify a password with the PDC emulator if the DC fails to validate the password.\r\n\r\nIf you disable this policy setting, the DCs will not attempt to verify any passwords with the PDC emulator. \r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-avoidpdconwan"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_avoidpdconwan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_avoidpdconwan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod","displayName":"Use initial DC discovery retry setting for background callers","description":"This policy setting determines the amount of time (in seconds) to wait before the first retry for applications that perform periodic searches for domain controllers (DC) that are unable to find a DC.\r\n\r\nThe default value for this setting is 10 minutes (10*60). The maximum value for this setting is 49 days (0x49*24*60*60=4233600). The minimum value for this setting is 0.\r\n\r\nThis setting is relevant only to those callers of DsGetDcName that have specified the DS_BACKGROUND_ONLY flag.\r\n\r\nIf the value of this setting is less than the value specified in the NegativeCachePeriod subkey, the value in the NegativeCachePeriod subkey is used.\r\n\r\nWarning: If the value for this setting is too large, a client will not attempt to find any DCs that were initially unavailable. If the value set in this setting is very small and the DC is not available, the traffic caused by periodic DC discoveries may be excessive.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-backgroundretryinitialperiod"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod_netlogon_backgroundretryinitialperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretrymaximumperiod","displayName":"Use maximum DC discovery retry interval setting for background callers","description":"This policy setting determines the maximum retry interval allowed when applications performing periodic searches for Domain Controllers (DCs) are unable to find a DC.\r\n\r\nFor example, the retry intervals may be set at 10 minutes, then 20 minutes and then 40 minutes, but when the interval reaches the value set in this setting, that value becomes the retry interval for all subsequent retries until the value set in Final DC Discovery Retry Setting is reached.\r\n\r\nThe default value for this setting is 60 minutes (60*60). The maximum value for this setting is 49 days (0x49*24*60*60=4233600). The minimum value for this setting is 0.\r\n\r\nIf the value for this setting is smaller than the value specified for the Initial DC Discovery Retry Setting, the Initial DC Discovery Retry Setting is used.\r\n\r\nWarning: If the value for this setting is too large, a client may take very long periods to try to find a DC.\r\n\r\nIf the value for this setting is too small and the DC is not available, the frequent retries may produce excessive network traffic.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-backgroundretrymaximumperiod"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretrymaximumperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretrymaximumperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretrymaximumperiod_netlogon_backgroundretrymaximumperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryquittime","displayName":"Use final DC discovery retry setting for background callers","description":"This policy setting determines when retries are no longer allowed for applications that perform periodic searches for domain controllers (DC) are unable to find a DC. For example, retires may be set to occur according to the Use maximum DC discovery retry interval policy setting, but when the value set in this policy setting is reached, no more retries occur. If a value for this policy setting is smaller than the value in the Use maximum DC discovery retry interval policy setting, the value for Use maximum DC discovery retry interval policy setting is used.\r\n\r\nThe default value for this setting is to not quit retrying (0). The maximum value for this setting is 49 days (0x49*24*60*60=4233600). The minimum value for this setting is 0.\r\n\r\nWarning: If the value for this setting is too small, a client will stop trying to find a DC too soon.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-backgroundretryquittime"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryquittime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryquittime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryquittime_netlogon_backgroundretryquittimelabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundsuccessfulrefreshperiod","displayName":"Use positive periodic DC cache refresh for background callers","description":"This policy setting determines when a successful DC cache entry is refreshed. This policy setting is applied to caller programs that periodically attempt to locate DCs, and it is applied before returning the DC information to the caller program. The default value for this setting is infinite (4294967200). The maximum value for this setting is (4294967200), while the maximum that is not treated as infinity is 49 days (49*24*60*60=4233600). Any larger value is treated as infinity. The minimum value for this setting is to always refresh (0).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-backgroundsuccessfulrefreshperiod"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundsuccessfulrefreshperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundsuccessfulrefreshperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundsuccessfulrefreshperiod_netlogon_backgroundsuccessfulrefreshperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_debugflag","displayName":"Specify log file debug output level","description":"This policy setting specifies the level of debug output for the Net Logon service.\r\n\r\nThe Net Logon service outputs debug information to the log file netlogon.log in the directory %windir%\\debug. By default, no debug information is logged.\r\n\r\nIf you enable this policy setting and specify a non-zero value, debug information will be logged to the file. Higher values result in more verbose logging; the value of 536936447 is commonly used as an optimal setting.\r\n\r\nIf you specify zero for this policy setting, the default behavior occurs as described above.\r\n\r\nIf you disable this policy setting or do not configure it, the default behavior occurs as described above.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-debugflag"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_debugflag_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_debugflag_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_debugflag_netlogon_debugflaglabel","displayName":"Level:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords","displayName":"Specify DC Locator DNS records not registered by the DCs","description":"This policy setting determines which DC Locator DNS records are not registered by the Net Logon service.\r\n\r\nIf you enable this policy setting, select Enabled and specify a list of space-delimited mnemonics (instructions) for the DC Locator DNS records that will not be registered by the DCs to which this setting is applied.\r\n\r\nSelect the mnemonics from the following list:\r\n\r\nMnemonic Type DNS Record\r\n\r\nLdapIpAddress A \r\nLdap SRV _ldap._tcp.\r\nLdapAtSite SRV _ldap._tcp.._sites.\r\nPdc SRV _ldap._tcp.pdc._msdcs.\r\nGc SRV _ldap._tcp.gc._msdcs.\r\nGcAtSite SRV _ldap._tcp.._sites.gc._msdcs.\r\nDcByGuid SRV _ldap._tcp..domains._msdcs.\r\nGcIpAddress A gc._msdcs.\r\nDsaCname CNAME ._msdcs.\r\nKdc SRV _kerberos._tcp.dc._msdcs.\r\nKdcAtSite SRV _kerberos._tcp.._sites.dc._msdcs.\r\nDc SRV _ldap._tcp.dc._msdcs.\r\nDcAtSite SRV _ldap._tcp.._sites.dc._msdcs.\r\nRfc1510Kdc SRV _kerberos._tcp.\r\nRfc1510KdcAtSite SRV _kerberos._tcp.._sites.\r\nGenericGc SRV _gc._tcp.\r\nGenericGcAtSite SRV _gc._tcp.._sites.\r\nRfc1510UdpKdc SRV _kerberos._udp.\r\nRfc1510Kpwd SRV _kpasswd._tcp.\r\nRfc1510UdpKpwd SRV _kpasswd._udp.\r\n\r\nIf you disable this policy setting, DCs configured to perform dynamic registration of DC Locator DNS records register all DC Locator DNS resource records.\r\n\r\nIf you do not configure this policy setting, DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-dnsavoidregisterrecords"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords_netlogon_dnsavoidregisterrecordslabel","displayName":"Mnemonics:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsrefreshinterval","displayName":"Specify Refresh Interval of the DC Locator DNS records","description":"This policy setting specifies the Refresh Interval of the DC Locator DNS resource records for DCs to which this setting is applied. These DNS records are dynamically registered by the Net Logon service and are used by the DC Locator algorithm to locate the DC. This setting may be applied only to DCs using dynamic update.\r\n\r\nDCs configured to perform dynamic registration of the DC Locator DNS resource records periodically reregister their records with DNS servers, even if their records’ data has not changed. If authoritative DNS servers are configured to perform scavenging of the stale records, this reregistration is required to instruct the DNS servers configured to automatically remove (scavenge) stale records that these records are current and should be preserved in the database.\r\n\r\nWarning: If the DNS resource records are registered in zones with scavenging enabled, the value of this setting should never be longer than the Refresh Interval configured for these zones. Setting the Refresh Interval of the DC Locator DNS records to longer than the Refresh Interval of the DNS zones may result in the undesired deletion of DNS resource records.\r\n\r\nTo specify the Refresh Interval of the DC records, click Enabled, and then enter a value larger than 1800. This value specifies the Refresh Interval of the DC records in seconds (for example, the value 3600 is 60 minutes).\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-dnsrefreshinterval"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsrefreshinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsrefreshinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsrefreshinterval_netlogon_dnsrefreshintervallabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnssrvrecorduselowercasehostnames","displayName":"Use lowercase DNS host names when registering domain controller SRV records","description":"This policy setting configures whether the domain controllers to which this setting is applied will lowercase their DNS host name when registering SRV records.\r\n\r\nIf enabled, domain controllers will lowercase their DNS host name when registering domain controller SRV records. A best-effort attempt will be made to delete any previously registered SRV records that contain mixed-case DNS host names. For more information and potential manual cleanup procedures, see the link below.\r\n\r\nIf disabled, domain controllers will use their configured DNS host name as-is when registering domain controller SRV records.\r\n\r\nIf not configured, domain controllers will default to using their local configuration.\r\n\r\nThe default local configuration is enabled.\r\n\r\nA reboot is not required for changes to this setting to take effect.\r\n\r\nMore information is available at https://aka.ms/lowercasehostnamesrvrecord\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-dnssrvrecorduselowercasehostnames"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnssrvrecorduselowercasehostnames_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnssrvrecorduselowercasehostnames_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl","displayName":"Set TTL in the DC Locator DNS Records","description":"This policy setting specifies the value for the Time-To-Live (TTL) field in SRV resource records that are registered by the Net Logon service. These DNS records are dynamically registered, and they are used to locate the domain controller (DC).\r\n\r\nTo specify the TTL for DC Locator DNS records, click Enabled, and then enter a value in seconds (for example, the value \"900\" is 15 minutes).\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-dnsttl"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl_netlogon_dnsttllabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay","displayName":"Specify expected dial-up delay on logon","description":"This policy setting specifies the additional time for the computer to wait for the domain controller’s (DC) response when logging on to the network.\r\n\r\nTo specify the expected dial-up delay at logon, click Enabled, and then enter the desired value in seconds (for example, the value \"60\" is 1 minute).\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-expecteddialupdelay"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay_netlogon_expecteddialupdelaylabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_forcerediscoveryinterval","displayName":"Force Rediscovery Interval","description":"This policy setting determines the interval for when a Force Rediscovery is carried out by DC Locator.\r\n\r\nThe Domain Controller Locator (DC Locator) service is used by clients to find domain controllers for their Active Directory domain. When DC Locator finds a domain controller, it caches domain controllers to improve the efficiency of the location algorithm. As long as the cached domain controller meets the requirements and is running, DC Locator will continue to return it. If a new domain controller is introduced, existing clients will only discover it when a Force Rediscovery is carried out by DC Locator. To adapt to changes in network conditions DC Locator will by default carry out a Force Rediscovery according to a specific time interval and maintain efficient load-balancing of clients across all available domain controllers in all domains or forests. The default time interval for Force Rediscovery by DC Locator is 12 hours. Force Rediscovery can also be triggered if a call to DC Locator uses the DS_FORCE_REDISCOVERY flag. Rediscovery resets the timer on the cached domain controller entries.\r\n\r\nIf you enable this policy setting, DC Locator on the machine will carry out Force Rediscovery periodically according to the configured time interval. The minimum time interval is 3600 seconds (1 hour) to avoid excessive network traffic from rediscovery. The maximum allowed time interval is 4294967200 seconds, while any value greater than 4294967 seconds (~49 days) will be treated as infinity.\r\n\r\nIf you disable this policy setting, Force Rediscovery will be used by default for the machine at every 12 hour interval.\r\n\r\nIf you do not configure this policy setting, Force Rediscovery will be used by default for the machine at every 12 hour interval, unless the local machine setting in the registry is a different value.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-forcerediscoveryinterval"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_forcerediscoveryinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_forcerediscoveryinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_forcerediscoveryinterval_netlogon_forcerediscoveryintervallabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage","displayName":"Specify sites covered by the GC Locator DNS SRV Records","description":"This policy setting specifies the sites for which the global catalogs (GC) should register site-specific GC locator DNS SRV resource records. These records are registered in addition to the site-specific SRV records registered for the site where the GC resides, and records registered by a GC configured to register GC Locator DNS SRV records for those sites without a GC that are closest to it. \r\n\r\nThe GC Locator DNS records and the site-specific SRV records are dynamically registered by the Net Logon service, and they are used to locate the GC. An Active Directory site is one or more well-connected TCP/IP subnets that allow administrators to configure Active Directory access and replication. A GC is a domain controller that contains a partial replica of every domain in Active Directory.\r\n\r\nTo specify the sites covered by the GC Locator DNS SRV records, click Enabled, and enter the sites' names in a space-delimited format.\r\n\r\nIf you do not configure this policy setting, it is not applied to any GCs, and GCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-gcsitecoverage"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage_netlogon_gcsitecoveragelabel","displayName":"Sites:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ignoreincomingmailslotmessages","displayName":"Do not process incoming mailslot messages used for domain controller location based on NetBIOS domain names","description":"This policy setting allows you to control the processing of incoming mailslot messages by a local domain controller (DC).\r\n\r\nNote: To locate a remote DC based on its NetBIOS (single-label) domain name, DC Locator first gets the list of DCs from a WINS server that is configured in its local client settings. DC Locator then sends a mailslot message to each remote DC to get more information. DC location succeeds only if a remote DC responds to the mailslot message.\r\n\r\nThis policy setting is recommended to reduce the attack surface on a DC, and can be used in an environment without WINS, in an IPv6-only environment, and whenever DC location based on a NetBIOS domain name is not required. This policy setting does not affect DC location based on DNS names.\r\n\r\nIf you enable this policy setting, this DC does not process incoming mailslot messages that are used for NetBIOS domain name based DC location.\r\n\r\nIf you disable or do not configure this policy setting, this DC processes incoming mailslot messages. This is the default behavior of DC Locator.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-ignoreincomingmailslotmessages"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ignoreincomingmailslotmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ignoreincomingmailslotmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvpriority","displayName":"Set Priority in the DC Locator DNS SRV records","description":"This policy setting specifies the Priority field in the SRV resource records registered by domain controllers (DC) to which this setting is applied. These DNS records are dynamically registered by the Net Logon service and are used to locate the DC.\r\n\r\nThe Priority field in the SRV record sets the preference for target hosts (specified in the SRV record’s Target field). DNS clients that query for SRV resource records attempt to contact the first reachable host with the lowest priority number listed.\r\n\r\nTo specify the Priority in the DC Locator DNS SRV resource records, click Enabled, and then enter a value. The range of values is from 0 to 65535.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-ldapsrvpriority"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvpriority_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvpriority_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvpriority_netlogon_ldapsrvprioritylabel","displayName":"Priority:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvweight","displayName":"Set Weight in the DC Locator DNS SRV records","description":"This policy setting specifies the Weight field in the SRV resource records registered by the domain controllers (DC) to which this setting is applied. These DNS records are dynamically registered by the Net Logon service, and they are used to locate the DC.\r\n\r\nThe Weight field in the SRV record can be used in addition to the Priority value to provide a load-balancing mechanism where multiple servers are specified in the SRV records Target field and are all set to the same priority. The probability with which the DNS client randomly selects the target host to be contacted is proportional to the Weight field value in the SRV record.\r\n\r\nTo specify the Weight in the DC Locator DNS SRV records, click Enabled, and then enter a value. The range of values is from 0 to 65535.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-ldapsrvweight"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvweight_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvweight_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ldapsrvweight_netlogon_ldapsrvweightlabel","displayName":"Weight:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_maximumlogfilesize","displayName":"Specify maximum log file size","description":"This policy setting specifies the maximum size in bytes of the log file netlogon.log in the directory %windir%\\debug when logging is enabled.\r\n\r\nBy default, the maximum size of the log file is 20MB. If you enable this policy setting, the maximum size of the log file is set to the specified size. Once this size is reached the log file is saved to netlogon.bak and netlogon.log is truncated. A reasonable value based on available storage should be specified.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior occurs as indicated above.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-maximumlogfilesize"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_maximumlogfilesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_maximumlogfilesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_maximumlogfilesize_netlogon_maximumlogfilesizelabel","displayName":"Bytes:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ndncsitecoverage","displayName":"Specify sites covered by the application directory partition DC Locator DNS SRV records","description":"This policy setting specifies the sites for which the domain controllers (DC) that host the application directory partition should register the site-specific, application directory partition-specific DC Locator DNS SRV resource records. These records are registered in addition to the site-specific SRV records registered for the site where the DC resides, and records registered by a DC configured to register DC Locator DNS SRV records for those sites without a DC that are closest to it. \r\n\r\nThe application directory partition DC Locator DNS records and the site-specific SRV records are dynamically registered by the Net Logon service, and they are used to locate the application directory partition-specific DC. An Active Directory site is one or more well-connected TCP/IP subnets that allow administrators to configure Active Directory access and replication.\r\n\r\nTo specify the sites covered by the DC Locator application directory partition-specific DNS SRV records, click Enabled, and then enter the site names in a space-delimited format.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-ndncsitecoverage"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ndncsitecoverage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ndncsitecoverage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ndncsitecoverage_netlogon_ndncsitecoveragelabel","displayName":"Sites:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_negativecacheperiod","displayName":"Specify negative DC Discovery cache setting","description":"This policy setting specifies the amount of time (in seconds) the DC locator remembers that a domain controller (DC) could not be found in a domain. When a subsequent attempt to locate the DC occurs within the time set in this setting, DC Discovery immediately fails, without attempting to find the DC.\r\n\r\nThe default value for this setting is 45 seconds. The maximum value for this setting is 7 days (7*24*60*60). The minimum value for this setting is 0.\r\n\r\nWarning: If the value for this setting is too large, a client will not attempt to find any DCs that were initially unavailable. If the value for this setting is too small, clients will attempt to find DCs even when none are available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-negativecacheperiod"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_negativecacheperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_negativecacheperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_negativecacheperiod_netlogon_negativecacheperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_netlogonsharecompatibilitymode","displayName":"Set Netlogon share compatibility","description":"This policy setting controls whether or not the Netlogon share created by the Net Logon service on a domain controller (DC) should support compatibility in file sharing semantics with earlier applications.\r\n\r\nIf you enable this policy setting, the Netlogon share will honor file sharing semantics that grant requests for exclusive read access to files on the share even when the caller has only read permission.\r\n\r\nIf you disable or do not configure this policy setting, the Netlogon share will grant shared read access to files on the share when exclusive access is requested and the caller has only read permission.\r\n\r\nBy default, the Netlogon share will grant shared read access to files on the share when exclusive access is requested.\r\n\r\nNote: The Netlogon share is a share created by the Net Logon service for use by client machines in the domain. The default behavior of the Netlogon share ensures that no application with only read permission to files on the Netlogon share can lock the files by requesting exclusive read access, which might prevent Group Policy settings from being updated on clients in the domain. When this setting is enabled, an application that relies on the ability to lock files on the Netlogon share with only read permission will be able to deny Group Policy clients from reading the files, and in general the availability of the Netlogon share on the domain will be decreased.\r\n\r\nIf you enable this policy setting, domain administrators should ensure that the only applications using the exclusive read capability in the domain are those approved by the administrator.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-netlogonsharecompatibilitymode"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_netlogonsharecompatibilitymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_netlogonsharecompatibilitymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_nonbackgroundsuccessfulrefreshperiod","displayName":"Specify positive periodic DC Cache refresh for non-background callers","description":"This policy setting determines when a successful DC cache entry is refreshed. This policy setting is applied to caller programs that do not periodically attempt to locate DCs, and it is applied before the returning the DC information to the caller program. This policy setting is relevant to only those callers of DsGetDcName that have not specified the DS_BACKGROUND_ONLY flag.\r\n\r\nThe default value for this setting is 30 minutes (1800). The maximum value for this setting is (4294967200), while the maximum that is not treated as infinity is 49 days (49*24*60*60=4233600). Any larger value will be treated as infinity. The minimum value for this setting is to always refresh (0).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-nonbackgroundsuccessfulrefreshperiod"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_nonbackgroundsuccessfulrefreshperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_nonbackgroundsuccessfulrefreshperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_nonbackgroundsuccessfulrefreshperiod_netlogon_nonbackgroundsuccessfulrefreshperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode","displayName":"Use urgent mode when pinging domain controllers","description":"This policy setting configures whether the computers to which this setting is applied are more aggressive when trying to locate a domain controller (DC).\r\n\r\nWhen an environment has a large number of DCs running both old and new operating systems, the default DC locator discovery behavior may be insufficient to find DCs running a newer operating system. This policy setting can be enabled to configure DC locator to be more aggressive about trying to locate a DC in such an environment, by pinging DCs at a higher frequency. Enabling this setting may result in additional network traffic and increased load on DCs. You should disable this setting once all DCs are running the same OS version.\r\n\r\nThe allowable values for this setting result in the following behaviors:\r\n\r\n1 - Computers will ping DCs at the normal frequency.\r\n2 - Computers will ping DCs at the higher frequency.\r\n\r\nTo specify this behavior, click Enabled and then enter a value. The range of values is from 1 to 2.\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-pingurgencymode"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode_netlogon_pingurgencymodelabel","displayName":"Ping urgency mode:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_scavengeinterval","displayName":"Set scavenge interval","description":"This policy setting determines the interval at which Netlogon performs the following scavenging operations:\r\n\r\n- Checks if a password on a secure channel needs to be modified, and modifies it if necessary.\r\n\r\n- On the domain controllers (DC), discovers a DC that has not been discovered.\r\n\r\n- On the PDC, attempts to add the [1B] NetBIOS name if it hasn’t already been successfully added.\r\n\r\nNone of these operations are critical. 15 minutes is optimal in all but extreme cases. For instance, if a DC is separated from a trusted domain by an expensive (e.g., ISDN) line, this parameter might be adjusted upward to avoid frequent automatic discovery of DCs in a trusted domain.\r\n\r\nTo enable the setting, click Enabled, and then specify the interval in seconds.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-scavengeinterval"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_scavengeinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_scavengeinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_scavengeinterval_netlogon_scavengeintervallabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitecoverage","displayName":"Specify sites covered by the DC Locator DNS SRV records","description":"This policy setting specifies the sites for which the domain controllers (DC) register the site-specific DC Locator DNS SRV resource records. These records are registered in addition to the site-specific SRV records registered for the site where the DC resides, and records registered by a DC configured to register DC Locator DNS SRV records for those sites without a DC that are closest to it. \r\n\r\nThe DC Locator DNS records are dynamically registered by the Net Logon service, and they are used to locate the DC. An Active Directory site is one or more well-connected TCP/IP subnets that allow administrators to configure Active Directory access and replication.\r\n\r\nTo specify the sites covered by the DC Locator DNS SRV records, click Enabled, and then enter the sites names in a space-delimited format.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-sitecoverage"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitecoverage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitecoverage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitecoverage_netlogon_sitecoveragelabel","displayName":"Sites:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename","displayName":"Specify site name","description":"This policy setting specifies the Active Directory site to which computers belong.\r\n\r\nAn Active Directory site is one or more well-connected TCP/IP subnets that allow administrators to configure Active Directory access and replication.\r\n\r\nTo specify the site name for this setting, click Enabled, and then enter the site name. When the site to which a computer belongs is not specified, the computer automatically discovers its site from Active Directory.\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-sitename"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename_netlogon_sitenamelabel","displayName":"Site:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sysvolsharecompatibilitymode","displayName":"Set SYSVOL share compatibility","description":"This policy setting controls whether or not the SYSVOL share created by the Net Logon service on a domain controller (DC) should support compatibility in file sharing semantics with earlier applications.\r\n\r\nWhen this setting is enabled, the SYSVOL share will honor file sharing semantics that grant requests for exclusive read access to files on the share even when the caller has only read permission.\r\n\r\nWhen this setting is disabled or not configured, the SYSVOL share will grant shared read access to files on the share when exclusive access is requested and the caller has only read permission.\r\n\r\nBy default, the SYSVOL share will grant shared read access to files on the share when exclusive access is requested.\r\n\r\nNote: The SYSVOL share is a share created by the Net Logon service for use by Group Policy clients in the domain. The default behavior of the SYSVOL share ensures that no application with only read permission to files on the sysvol share can lock the files by requesting exclusive read access, which might prevent Group Policy settings from being updated on clients in the domain. When this setting is enabled, an application that relies on the ability to lock files on the SYSVOL share with only read permission will be able to deny Group Policy clients from reading the files, and in general the availability of the SYSVOL share on the domain will be decreased.\r\n\r\nIf you enable this policy setting, domain administrators should ensure that the only applications using the exclusive read capability in the domain are those approved by the administrator.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-sysvolsharecompatibilitymode"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sysvolsharecompatibilitymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sysvolsharecompatibilitymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_trynextclosestsite","displayName":"Try Next Closest Site","description":"This policy setting enables DC Locator to attempt to locate a DC in the nearest site based on the site link cost if a DC in same the site is not found. In scenarios with multiple sites, failing over to the try next closest site during DC Location streamlines network traffic more effectively.\r\n\r\nThe DC Locator service is used by clients to find domain controllers for their Active Directory domain. The default behavior for DC Locator is to find a DC in the same site. If none are found in the same site, a DC in another site, which might be several site-hops away, could be returned by DC Locator. Site proximity between two sites is determined by the total site-link cost between them. A site is closer if it has a lower site link cost than another site with a higher site link cost. \r\n\r\nIf you enable this policy setting, Try Next Closest Site DC Location will be turned on for the computer.\r\n\r\nIf you disable this policy setting, Try Next Closest Site DC Location will not be used by default for the computer. However, if a DC Locator call is made using the DS_TRY_NEXTCLOSEST_SITE flag explicitly, the Try Next Closest Site behavior is honored.\r\n\r\nIf you do not configure this policy setting, Try Next Closest Site DC Location will not be used by default for the machine. If the DS_TRY_NEXTCLOSEST_SITE flag is used explicitly, the Next Closest Site behavior will be used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-trynextclosestsite"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_trynextclosestsite_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_trynextclosestsite_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_usedynamicdns","displayName":"Specify dynamic registration of the DC Locator DNS Records","description":"This policy setting determines if dynamic registration of the domain controller (DC) locator DNS resource records is enabled. These DNS records are dynamically registered by the Net Logon service and are used by the Locator algorithm to locate the DC.\r\n\r\nIf you enable this policy setting, DCs to which this setting is applied dynamically register DC Locator DNS resource records through dynamic DNS update-enabled network connections.\r\n\r\nIf you disable this policy setting, DCs will not register DC Locator DNS resource records.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-usedynamicdns"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_usedynamicdns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_usedynamicdns_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_donotshowlocalonlyicon","displayName":"Do not show the \"local access only\" network icon","description":"Specifies whether or not the \"local access only\" network icon will be shown.\r\n\r\nWhen enabled, the icon for Internet access will be shown in the system tray even when a user is connected to a network with local access only.\r\n\r\nIf you disable this setting or do not configure it, the \"local access only\" icon will be used when a user is connected to a network with local access only.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-donotshowlocalonlyicon"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_donotshowlocalonlyicon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_donotshowlocalonlyicon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_forcetunneling","displayName":"Route all traffic through the internal network","description":"This policy setting determines whether a remote client computer routes Internet traffic through the internal network or whether the client accesses the Internet directly.\r\n\r\nWhen a remote client computer connects to an internal network using DirectAccess, it can access the Internet in two ways: through the secure tunnel that DirectAccess establishes between the computer and the internal network, or directly through the local default gateway.\r\n\r\nIf you enable this policy setting, all traffic between a remote client computer running DirectAccess and the Internet is routed through the internal network.\r\n\r\nIf you disable this policy setting, traffic between remote client computers running DirectAccess and the Internet is not routed through the internal network.\r\n\r\nIf you do not configure this policy setting, traffic between remote client computers running DirectAccess and the Internet is not routed through the internal network.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-forcetunneling"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_forcetunneling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_forcetunneling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_forcetunneling_stateselect","displayName":"Select from the following states:","description":null,"helpText":"","infoUrls":[],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_forcetunneling_stateselect_enabled","displayName":"Enabled State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_forcetunneling_stateselect_disabled","displayName":"Disabled State","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_personalfirewallconfig","displayName":"Prohibit use of Internet Connection Firewall on your DNS domain network","description":"Prohibits use of Internet Connection Firewall on your DNS domain network.\r\n\r\nDetermines whether users can enable the Internet Connection Firewall feature on a connection, and if the Internet Connection Firewall service can run on a computer.\r\n\r\nImportant: This setting is location aware. It only applies when a computer is connected to the same DNS domain network it was connected to when the setting was refreshed on that computer. If a computer is connected to a DNS domain network other than the one it was connected to when the setting was refreshed, this setting does not apply.\r\n\r\nThe Internet Connection Firewall is a stateful packet filter for home and small office users to protect them from Internet network security threats.\r\n\r\nIf you enable this setting, Internet Connection Firewall cannot be enabled or configured by users (including administrators), and the Internet Connection Firewall service cannot run on the computer. The option to enable the Internet Connection Firewall through the Advanced tab is removed. In addition, the Internet Connection Firewall is not enabled for remote access connections created through the Make New Connection Wizard. The Network Setup Wizard is disabled.\r\n\r\nNote: If you enable the \"Windows Firewall: Protect all network connections\" policy setting, the \"Prohibit use of Internet Connection Firewall on your DNS domain network\" policy setting has no effect on computers that are running Windows Firewall, which replaces Internet Connection Firewall when you install Windows XP Service Pack 2.\r\n\r\nIf you disable this setting or do not configure it, the Internet Connection Firewall is disabled when a LAN Connection or VPN connection is created, but users can use the Advanced tab in the connection properties to enable it. The Internet Connection Firewall is enabled by default on the connection for which Internet Connection Sharing is enabled. In addition, remote access connections created through the Make New Connection Wizard have the Internet Connection Firewall enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-personalfirewallconfig"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_personalfirewallconfig_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_personalfirewallconfig_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_showsharedaccessui","displayName":"Prohibit use of Internet Connection Sharing on your DNS domain network","description":"Determines whether administrators can enable and configure the Internet Connection Sharing (ICS) feature of an Internet connection and if the ICS service can run on the computer.\r\n\r\nICS lets administrators configure their system as an Internet gateway for a small network and provides network services, such as name resolution and addressing through DHCP, to the local private network.\r\n\r\nIf you enable this setting, ICS cannot be enabled or configured by administrators, and the ICS service cannot run on the computer. The Advanced tab in the Properties dialog box for a LAN or remote access connection is removed. The Internet Connection Sharing page is removed from the New Connection Wizard. The Network Setup Wizard is disabled.\r\n\r\nIf you disable this setting or do not configure it and have two or more connections, administrators can enable ICS. The Advanced tab in the properties dialog box for a LAN or remote access connection is available. In addition, the user is presented with the option to enable Internet Connection Sharing in the Network Setup Wizard and Make New Connection Wizard. (The Network Setup Wizard is available only in Windows XP Professional.)\r\n\r\nBy default, ICS is disabled when you create a remote access connection, but administrators can use the Advanced tab to enable it. When running the New Connection Wizard or Network Setup Wizard, administrators can choose to enable ICS.\r\n\r\nNote: Internet Connection Sharing is only available when two or more network connections are present.\r\n\r\nNote: When the \"Prohibit access to properties of a LAN connection,\" \"Ability to change properties of an all user remote access connection,\" or \"Prohibit changing properties of a private remote access connection\" settings are set to deny access to the Connection Properties dialog box, the Advanced tab for the connection is blocked.\r\n\r\nNote: Nonadministrators are already prohibited from configuring Internet Connection Sharing, regardless of this setting.\r\n\r\nNote: Disabling this setting does not prevent Wireless Hosted Networking from using the ICS service for DHCP services. To prevent the ICS service from running, on the Network Permissions tab in the network's policy properties, select the \"Don't use hosted networks\" check box.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-showsharedaccessui"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_showsharedaccessui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_showsharedaccessui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_stddomainusersetlocation","displayName":"Require domain users to elevate when setting a network's location","description":"This policy setting determines whether to require domain users to elevate when setting a network's location.\r\n\r\nIf you enable this policy setting, domain users must elevate when setting a network's location.\r\n\r\nIf you disable or do not configure this policy setting, domain users can set a network's location without elevating.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-stddomainusersetlocation"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_stddomainusersetlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_networkconnections_nc_stddomainusersetlocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_alwayspinsubfolders","displayName":"Subfolders always available offline","description":"Makes subfolders available offline whenever their parent folder is made available offline.\r\n\r\nThis setting automatically extends the \"make available offline\" setting to all new and existing subfolders of a folder. Users do not have the option of excluding subfolders.\r\n\r\nIf you enable this setting, when you make a folder available offline, all folders within that folder are also made available offline. Also, new folders that you create within a folder that is available offline are made available offline when the parent folder is synchronized.\r\n\r\nIf you disable this setting or do not configure it, the system asks users whether they want subfolders to be made available offline when they make a parent folder available offline.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-alwayspinsubfolders"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_alwayspinsubfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_alwayspinsubfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2","displayName":"Specify administratively assigned Offline Files","description":"This policy setting lists network files and folders that are always available for offline use. This ensures that the specified files and folders are available offline to users of the computer.\r\n\r\nIf you enable this policy setting, the files you enter are always available offline to users of the computer. To specify a file or folder, click Show. In the Show Contents dialog box in the Value Name column, type the fully qualified UNC path to the file or folder. Leave the Value column field blank.\r\n\r\nIf you disable this policy setting, the list of files or folders made always available offline (including those inherited from lower precedence GPOs) is deleted and no files or folders are made available for offline use by Group Policy (though users can still specify their own files and folders for offline use).\r\n\r\nIf you do not configure this policy setting, no files or folders are made available for offline use by Group Policy.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy settings will be combined and all specified files will be available for offline use.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-assignedofflinefiles-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_lbl_assignedofflinefileslist","displayName":"Files and Folders:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_lbl_assignedofflinefileslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_lbl_assignedofflinefileslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings","displayName":"Configure Background Sync","description":"This policy setting controls when background synchronization occurs while operating in slow-link mode, and applies to any user who logs onto the specified machine while this policy is in effect. To control slow-link mode, use the \"Configure slow-link mode\" policy setting.\r\n\r\nIf you enable this policy setting, you can control when Windows synchronizes in the background while operating in slow-link mode. Use the 'Sync Interval' and 'Sync Variance' values to override the default sync interval and variance settings. Use 'Blockout Start Time' and 'Blockout Duration' to set a period of time where background sync is disabled. Use the 'Maximum Allowed Time Without A Sync' value to ensure that all network folders on the machine are synchronized with the server on a regular basis.\r\n\r\nYou can also configure Background Sync for network shares that are in user selected Work Offline mode. This mode is in effect when a user selects the Work Offline button for a specific share. When selected, all configured settings will apply to shares in user selected Work Offline mode as well.\r\n\r\nIf you disable or do not configure this policy setting, Windows performs a background sync of offline folders in the slow-link mode at a default interval with the start of the sync varying between 0 and 60 additional minutes. In Windows 7 and Windows Server 2008 R2, the default sync interval is 360 minutes. In Windows 8 and Windows Server 2012, the default sync interval is 120 minutes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-backgroundsyncsettings"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncblockoutperiodduration","displayName":"Blockout Duration (minutes)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncblockoutperiodstarttime","displayName":"Blockout Start Time (HHMM)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncdefaultsynctime","displayName":"Sync Interval (minutes)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncignoreblockouttime","displayName":"Maximum Allowed Time Without A Sync (minutes)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncinforcedoffline","displayName":"Enable Background Sync for shares in user selected \"Work Offline\" mode","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncinforcedoffline_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncinforcedoffline_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncvariance","displayName":"Sync Variance (minutes)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize","displayName":"Limit disk space used by Offline Files","description":"This policy setting limits the amount of disk space that can be used to store offline files. This includes the space used by automatically cached files and files that are specifically made available offline. Files can be automatically cached if the user accesses a file on an automatic caching network share.\r\n\r\nThis setting also disables the ability to adjust, through the Offline Files control panel applet, the disk space limits on the Offline Files cache. This prevents users from trying to change the option while a policy setting controls it.\r\n\r\nIf you enable this policy setting, you can specify the disk space limit (in megabytes) for offline files and also specify how much of that disk space can be used by automatically cached files.\r\n\r\nIf you disable this policy setting, the system limits the space that offline files occupy to 25 percent of the total space on the drive where the Offline Files cache is located. The limit for automatically cached files is 100 percent of the total disk space limit.\r\n\r\nIf you do not configure this policy setting, the system limits the space that offline files occupy to 25 percent of the total space on the drive where the Offline Files cache is located. The limit for automatically cached files is 100 percent of the total disk space limit. However, the users can change these values using the Offline Files control applet.\r\n\r\nIf you enable this setting and specify a total size limit greater than the size of the drive hosting the Offline Files cache, and that drive is the system drive, the total size limit is automatically adjusted downward to 75 percent of the size of the drive. If the cache is located on a drive other than the system drive, the limit is automatically adjusted downward to 100 percent of the size of the drive.\r\n\r\nIf you enable this setting and specify a total size limit less than the amount of space currently used by the Offline Files cache, the total size limit is automatically adjusted upward to the amount of space currently used by offline files. The cache is then considered full.\r\n\r\nIf you enable this setting and specify an auto-cached space limit greater than the total size limit, the auto-cached limit is automatically adjusted downward to equal the total size limit.\r\n\r\nThis setting replaces the Default Cache Size setting used by pre-Windows Vista systems.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-cachesize"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize_lbl_autocachesizespin","displayName":"Size of auto-cached files:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize_lbl_totalcachesizespin","displayName":"Total size of offline files:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_2","displayName":"Non-default server disconnect actions","description":"Determines how computers respond when they are disconnected from particular offline file servers. This setting overrides the default response, a user-specified response, and the response specified in the \"Action on server disconnect\" setting.\r\n\r\nTo use this setting, click Show. In the Show Contents dialog box in the Value Name column box, type the server's computer name. Then, in the Value column box, type \"0\" if users can work offline when they are disconnected from this server, or type \"1\" if they cannot.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured for a particular server, the setting in Computer Configuration takes precedence over the setting in User Configuration. Both Computer and User configuration take precedence over a user's setting. This setting does not prevent users from setting custom actions through the Offline Files tab. However, users are unable to change any custom actions established via this setting.\r\n\r\nTip: To configure this setting without establishing a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then click Advanced. This setting corresponds to the settings in the \"Exception list\" section.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-customgoofflineactions-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_2_lbl_customgoofflineactionslist","displayName":"Customize actions:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_2_lbl_customgoofflineactionslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_2_lbl_customgoofflineactionslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize","displayName":"Default cache size","description":"Limits the percentage of the computer's disk space that can be used to store automatically cached offline files.\r\n\r\nThis setting also disables the \"Amount of disk space to use for temporary offline files\" option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.\r\n\r\nAutomatic caching can be set on any network share. When a user opens a file on the share, the system automatically stores a copy of the file on the user's computer.\r\n\r\nThis setting does not limit the disk space available for files that user's make available offline manually.\r\n\r\nIf you enable this setting, you can specify an automatic-cache disk space limit.\r\n\r\nIf you disable this setting, the system limits the space that automatically cached files occupy to 10 percent of the space on the system drive.\r\n\r\nIf you do not configure this setting, disk space for automatically cached files is limited to 10 percent of the system drive by default, but users can change it.\r\n\r\nTip: To change the amount of disk space used for automatic caching without specifying a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then use the slider bar associated with the \"Amount of disk space to use for temporary offline files\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-defcachesize"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize_lbl_defcachesizespin","displayName":"Default cache size:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_enabled","displayName":"Allow or Disallow use of the Offline Files feature","description":"This policy setting determines whether the Offline Files feature is enabled. Offline Files saves a copy of network files on the user's computer for use when the computer is not connected to the network.\r\n\r\nIf you enable this policy setting, Offline Files is enabled and users cannot disable it.\r\n\r\nIf you disable this policy setting, Offline Files is disabled and users cannot enable it.\r\n\r\nIf you do not configure this policy setting, Offline Files is enabled on Windows client computers, and disabled on computers running Windows Server, unless changed by the user.\r\n\r\nNote: Changes to this policy setting do not take effect until the affected computer is restarted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-enabled"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_encryptofflinefiles","displayName":"Encrypt the Offline Files cache","description":"This policy setting determines whether offline files are encrypted.\r\n\r\nOffline files are locally cached copies of files from a network share. Encrypting this cache reduces the likelihood that a user could access files from the Offline Files cache without proper permissions.\r\n\r\nIf you enable this policy setting, all files in the Offline Files cache are encrypted. This includes existing files as well as files added later. The cached copy on the local computer is affected, but the associated network copy is not. The user cannot unencrypt Offline Files through the user interface.\r\n\r\nIf you disable this policy setting, all files in the Offline Files cache are unencrypted. This includes existing files as well as files added later, even if the files were stored using NTFS encryption or BitLocker Drive Encryption while on the server. The cached copy on the local computer is affected, but the associated network copy is not. The user cannot encrypt Offline Files through the user interface.\r\n\r\nIf you do not configure this policy setting, encryption of the Offline Files cache is controlled by the user through the user interface. The current cache state is retained, and if the cache is only partially encrypted, the operation completes so that it is fully encrypted. The cache does not return to the unencrypted state. The user must be an administrator on the local computer to encrypt or decrypt the Offline Files cache.\r\n\r\nNote: By default, this cache is protected on NTFS partitions by ACLs.\r\n\r\nThis setting is applied at user logon. If this setting is changed after user logon then user logoff and logon is required for this setting to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-encryptofflinefiles"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_encryptofflinefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_encryptofflinefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_eventlogginglevel_2","displayName":"Event logging level","description":"Determines which events the Offline Files feature records in the event log.\r\n\r\nOffline Files records events in the Application log in Event Viewer when it detects errors. By default, Offline Files records an event only when the offline files storage cache is corrupted. However, you can use this setting to specify additional events you want Offline Files to record.\r\n\r\nTo use this setting, in the \"Enter\" box, select the number corresponding to the events you want the system to log. The levels are cumulative; that is, each level includes the events in all preceding levels.\r\n\r\n\"0\" records an error when the offline storage cache is corrupted.\r\n\r\n\"1\" also records an event when the server hosting the offline file is disconnected from the network.\r\n\r\n\"2\" also records events when the local computer is connected and disconnected from the network.\r\n\r\n\"3\" also records an event when the server hosting the offline file is reconnected to the network.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-eventlogginglevel-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_eventlogginglevel_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_eventlogginglevel_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_eventlogginglevel_2_lbl_eventlogginglevelspin","displayName":"Enter [0-3]:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings","displayName":"Enable file screens","description":"This policy setting enables administrators to block certain file types from being created in the folders that have been made available offline.\r\n\r\nIf you enable this policy setting, a user will be unable to create files with the specified file extensions in any of the folders that have been made available offline.\r\n\r\nIf you disable or do not configure this policy setting, a user can create a file of any type in the folders that have been made available offline.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-exclusionlistsettings"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings_lbl_exclusionlistsettingslist","displayName":"Extensions: ","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_extexclusionlist","displayName":"Files not cached","description":"Lists types of files that cannot be used offline.\r\n\r\nThis setting lets you exclude certain types of files from automatic and manual caching for offline use. The system does not cache files of the type specified in this setting even when they reside on a network share configured for automatic caching. Also, if users try to make a file of this type available offline, the operation will fail and the following message will be displayed in the Synchronization Manager progress dialog box: \"Files of this type cannot be made available offline.\"\r\n\r\nThis setting is designed to protect files that cannot be separated, such as database components.\r\n\r\nTo use this setting, type the file name extension in the \"Extensions\" box. To type more than one extension, separate the extensions with a semicolon (;).\r\n\r\nNote: To make changes to this setting effective, you must log off and log on again.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-extexclusionlist"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_extexclusionlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_extexclusionlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_extexclusionlist_lbl_extexclusionlistedit","displayName":"Extensions: ","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2","displayName":"Action on server disconnect","description":"Determines whether network files remain available if the computer is suddenly disconnected from the server hosting the files.\r\n\r\nThis setting also disables the \"When a network connection is lost\" option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.\r\n\r\nIf you enable this setting, you can use the \"Action\" box to specify how computers in the group respond.\r\n\r\n-- \"Work offline\" indicates that the computer can use local copies of network files while the server is inaccessible.\r\n\r\n-- \"Never go offline\" indicates that network files are not available while the server is inaccessible.\r\n\r\nIf you disable this setting or select the \"Work offline\" option, users can work offline if disconnected.\r\n\r\nIf you do not configure this setting, users can work offline by default, but they can change this option.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To configure this setting without establishing a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, click Advanced, and then select an option in the \"When a network connection is lost\" section.\r\n\r\nAlso, see the \"Non-default server disconnect actions\" setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-goofflineaction-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_lbl_goofflineactioncombo","displayName":"Action:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_lbl_goofflineactioncombo_0","displayName":"Work offline","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_lbl_goofflineactioncombo_1","displayName":"Never go offline","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nocacheviewer_2","displayName":"Prevent use of Offline Files folder","description":"Disables the Offline Files folder.\r\n\r\nThis setting disables the \"View Files\" button on the Offline Files tab. As a result, users cannot use the Offline Files folder to view or open copies of network files stored on their computer. Also, they cannot use the folder to view characteristics of offline files, such as their server status, type, or location.\r\n\r\nThis setting does not prevent users from working offline or from saving local copies of files available offline. Also, it does not prevent them from using other programs, such as Windows Explorer, to view their offline files.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To view the Offline Files Folder, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then click \"View Files.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-nocacheviewer-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nocacheviewer_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nocacheviewer_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noconfigcache_2","displayName":"Prohibit user configuration of Offline Files","description":"Prevents users from enabling, disabling, or changing the configuration of Offline Files.\r\n\r\nThis setting removes the Offline Files tab from the Folder Options dialog box. It also removes the Settings item from the Offline Files context menu and disables the Settings button on the Offline Files Status dialog box. As a result, users cannot view or change the options on the Offline Files tab or Offline Files dialog box.\r\n\r\nThis is a comprehensive setting that locks down the configuration you establish by using other settings in this folder.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: This setting provides a quick method for locking down the default settings for Offline Files. To accept the defaults, just enable this setting. You do not have to disable any other settings in this folder.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-noconfigcache-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noconfigcache_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noconfigcache_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nomakeavailableoffline_2","displayName":"Remove \"Make Available Offline\" command","description":"This policy setting prevents users from making network files and folders available offline.\r\n\r\nIf you enable this policy setting, users cannot designate files to be saved on their computer for offline use. However, Windows will still cache local copies of files that reside on network shares designated for automatic caching.\r\n\r\nIf you disable or do not configure this policy setting, users can manually specify files and folders that they want to make available offline.\r\n\r\nNotes:\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy setting in Computer Configuration takes precedence.\r\n\r\nThe \"Make Available Offline\" command is called \"Always available offline\" on computers running Windows Server 2012, Windows Server 2008 R2, Windows Server 2008, Windows 8, Windows 7, or Windows Vista.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-nomakeavailableoffline-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nomakeavailableoffline_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nomakeavailableoffline_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2","displayName":"Remove \"Make Available Offline\" for these files and folders","description":"This policy setting allows you to manage a list of files and folders for which you want to block the \"Make Available Offline\" command.\r\n\r\nIf you enable this policy setting, the \"Make Available Offline\" command is not available for the files and folders that you list. To specify these files and folders, click Show. In the Show Contents dialog box, in the Value Name column box, type the fully qualified UNC path to the file or folder. Leave the Value column field blank.\r\n\r\nIf you disable this policy setting, the list of files and folders is deleted, including any lists inherited from lower precedence GPOs, and the \"Make Available Offline\" command is displayed for all files and folders.\r\n\r\nIf you do not configure this policy setting, the \"Make Available Offline\" command is available for all files and folders.\r\n\r\nNotes:\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy settings are combined, and the \"Make Available Offline\" command is unavailable for all specified files and folders.\r\n\r\nThe \"Make Available Offline\" command is called \"Always available offline\" on computers running Windows Server 2012, Windows Server 2008 R2, Windows Server 2008, Windows 8, Windows 7, or Windows Vista.\r\n\r\nThis policy setting does not prevent files from being automatically cached if the network share is configured for \"Automatic Caching.\" It only affects the display of the \"Make Available Offline\" command in File Explorer.\r\n\r\nIf the \"Remove 'Make Available Offline' command\" policy setting is enabled, this setting has no effect.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-nopinfiles-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_lbl_nopinfileslist","displayName":"Files and Folders:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_lbl_nopinfileslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_lbl_nopinfileslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noreminders_2","displayName":"Turn off reminder balloons","description":"Hides or displays reminder balloons, and prevents users from changing the setting.\r\n\r\nReminder balloons appear above the Offline Files icon in the notification area to notify users when they have lost the connection to a networked file and are working on a local copy of the file. Users can then decide how to proceed.\r\n\r\nIf you enable this setting, the system hides the reminder balloons, and prevents users from displaying them.\r\n\r\nIf you disable the setting, the system displays the reminder balloons and prevents users from hiding them.\r\n\r\nIf this setting is not configured, reminder balloons are displayed by default when you enable offline files, but users can change the setting.\r\n\r\nTo prevent users from changing the setting while a setting is in effect, the system disables the \"Enable reminders\" option on the Offline Files tab\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To display or hide reminder balloons without establishing a setting, in Windows Explorer, on the Tools menu, click Folder Options, and then click the Offline Files tab. This setting corresponds to the \"Enable reminders\" check box.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-noreminders-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noreminders_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noreminders_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings","displayName":"Enable Transparent Caching","description":"This policy setting controls whether files read from file shares over a slow network are transparently cached in the Offline Files cache for future reads. When a user tries to access a file that has been transparently cached, Windows reads from the cached copy after verifying its integrity. This improves end-user response times and decreases bandwidth consumption over WAN links.\r\n\r\nThe cached files are temporary and are not available to the user when offline. The cached files are not kept in sync with the version on the server, and the most current version from the server is always available for subsequent reads.\r\n\r\nThis policy setting is triggered by the configured round trip network latency value. We recommend using this policy setting when the network connection to the server is slow. For example, you can configure a value of 60 ms as the round trip latency of the network above which files should be transparently cached in the Offline Files cache. If the round trip latency of the network is less than 60ms, reads to remote files will not be cached.\r\n\r\nIf you enable this policy setting, transparent caching is enabled and configurable.\r\n\r\nIf you disable or do not configure this policy setting, remote files will be not be transparently cached on client computers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-onlinecachingsettings"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings_lbl_onlinecachingsettingslist","displayName":"Enter network latency value in milliseconds","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_purgeatlogoff","displayName":"At logoff, delete local copy of user’s offline files","description":"Deletes local copies of the user's offline files when the user logs off.\r\n\r\nThis setting specifies that automatically and manually cached offline files are retained only while the user is logged on to the computer. When the user logs off, the system deletes all local copies of offline files.\r\n\r\nIf you disable this setting or do not configure it, automatically and manually cached copies are retained on the user's computer for later offline use.\r\n\r\nCaution: Files are not synchronized before they are deleted. Any changes to local files since the last synchronization are lost.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-purgeatlogoff"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_purgeatlogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_purgeatlogoff_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_purgeatlogoff_lbl_purgeonlyautocachedfiles","displayName":"Delete only the temporary offline files.","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_purgeatlogoff_lbl_purgeonlyautocachedfiles_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_purgeatlogoff_lbl_purgeonlyautocachedfiles_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_quickadimpin","displayName":"Turn on economical application of administratively assigned Offline Files","description":"This policy setting allows you to turn on economical application of administratively assigned Offline Files.\r\n\r\nIf you enable or do not configure this policy setting, only new files and folders in administratively assigned folders are synchronized at logon. Files and folders that are already available offline are skipped and are synchronized later.\r\n\r\nIf you disable this policy setting, all administratively assigned folders are synchronized at logon.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-quickadimpin"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_quickadimpin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_quickadimpin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2","displayName":"Reminder balloon frequency","description":"Determines how often reminder balloon updates appear.\r\n\r\nIf you enable this setting, you can select how often reminder balloons updates appear and also prevent users from changing this setting.\r\n\r\nReminder balloons appear when the user's connection to a network file is lost or reconnected, and they are updated periodically. By default, the first reminder for an event is displayed for 30 seconds. Then, updates appear every 60 minutes and are displayed for 15 seconds. You can use this setting to change the update interval.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To set reminder balloon frequency without establishing a setting, in Windows Explorer, on the Tools menu, click Folder Options, and then click the Offline Files tab. This setting corresponds to the \"Display reminder balloons every ... minutes\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-reminderfreq-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2_lbl_reminderfreqspin","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_2","displayName":"Initial reminder balloon lifetime","description":"Determines how long the first reminder balloon for a network status change is displayed.\r\n\r\nReminder balloons appear when the user's connection to a network file is lost or reconnected, and they are updated periodically. By default, the first reminder for an event is displayed for 30 seconds. Then, updates appear every 60 minutes and are displayed for 15 seconds. You can use this setting to change the duration of the first reminder.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-reminderinittimeout-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_2_lbl_reminderinittimeoutspin","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_remindertimeout_2","displayName":"Reminder balloon lifetime","description":"Determines how long updated reminder balloons are displayed.\r\n\r\nReminder balloons appear when the user's connection to a network file is lost or reconnected, and they are updated periodically. By default, the first reminder for an event is displayed for 30 seconds. Then, updates appear every 60 minutes and are displayed for 15 seconds. You can use this setting to change the duration of the update reminder.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-remindertimeout-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_remindertimeout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_remindertimeout_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_remindertimeout_2_lbl_remindertimeoutspin","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings","displayName":"Configure slow-link mode","description":"This policy setting controls the network latency and throughput thresholds that will cause a client computers to transition files and folders that are already available offline to the slow-link mode so that the user's access to this data is not degraded due to network slowness. When Offline Files is operating in the slow-link mode, all network file requests are satisfied from the Offline Files cache. This is similar to a user working offline.\r\n\r\nIf you enable this policy setting, Offline Files uses the slow-link mode if the network throughput between the client and the server is below (slower than) the Throughput threshold parameter, or if the round-trip network latency is above (slower than) the Latency threshold parameter.\r\n\r\nYou can configure the slow-link mode by specifying threshold values for Throughput (in bits per second) and/or Latency (in milliseconds) for specific UNC paths. We recommend that you always specify a value for Latency, since the round-trip network latency detection is faster. You can use wildcard characters (*) for specifying UNC paths. If you do not specify a Latency or Throughput value, computers running Windows Vista or Windows Server 2008 will not use the slow-link mode.\r\n\r\nIf you do not configure this policy setting, computers running Windows Vista or Windows Server 2008 will not transition a shared folder to the slow-link mode. Computers running Windows 7 or Windows Server 2008 R2 will use the default latency value of 80 milliseconds when transitioning a folder to the slow-link mode. Computers running Windows 8 or Windows Server 2012 will use the default latency value of 35 milliseconds when transitioning a folder to the slow-link mode. To avoid extra charges on cell phone or broadband plans, it may be necessary to configure the latency threshold to be lower than the round-trip network latency.\r\n\r\nIn Windows Vista or Windows Server 2008, once transitioned to slow-link mode, users will continue to operate in slow-link mode until the user clicks the Work Online button on the toolbar in Windows Explorer. Data will only be synchronized to the server if the user manually initiates synchronization by using Sync Center.\r\n\r\nIn Windows 7, Windows Server 2008 R2, Windows 8 or Windows Server 2012, when operating in slow-link mode Offline Files synchronizes the user's files in the background at regular intervals, or as configured by the \"Configure Background Sync\" policy. While in slow-link mode, Windows periodically checks the connection to the folder and brings the folder back online if network speeds improve.\r\n\r\nIn Windows 8 or Windows Server 2012, set the Latency threshold to 1ms to keep users always working offline in slow-link mode.\r\n\r\nIf you disable this policy setting, computers will not use the slow-link mode.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-slowlinksettings"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_lbl_slowlinksettingslist","displayName":"UNC Paths:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_lbl_slowlinksettingslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_lbl_slowlinksettingslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinkspeed","displayName":"Configure Slow link speed","description":"Configures the threshold value at which Offline Files considers a network connection to be \"slow\". Any network speed below this value is considered to be slow.\r\n\r\nWhen a connection is considered slow, Offline Files automatically adjust its behavior to avoid excessive synchronization traffic and will not automatically reconnect to a server when the presence of a server is detected.\r\n\r\nIf you enable this setting, you can configure the threshold value that will be used to determine a slow network connection.\r\n\r\nIf this setting is disabled or not configured, the default threshold value of 64,000 bps is used to determine if a network connection is considered to be slow.\r\n\r\nNote: Use the following formula when entering the slow link value: [ bps / 100]. For example, if you want to set a threshold value of 128,000 bps, enter a value of 1280.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-slowlinkspeed"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinkspeed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinkspeed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinkspeed_lbl_slowlinkspeedspin","displayName":"Value:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogoff_2","displayName":"Synchronize all offline files before logging off","description":"Determines whether offline files are fully synchronized when users log off.\r\n\r\nThis setting also disables the \"Synchronize all offline files before logging off\" option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.\r\n\r\nIf you enable this setting, offline files are fully synchronized. Full synchronization ensures that offline files are complete and current.\r\n\r\nIf you disable this setting, the system only performs a quick synchronization. Quick synchronization ensures that files are complete, but does not ensure that they are current.\r\n\r\nIf you do not configure this setting, the system performs a quick synchronization by default, but users can change this option.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To change the synchronization method without changing a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then select the \"Synchronize all offline files before logging off\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-syncatlogoff-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogoff_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogoff_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogon_2","displayName":"Synchronize all offline files when logging on","description":"Determines whether offline files are fully synchronized when users log on.\r\n\r\nThis setting also disables the \"Synchronize all offline files before logging on\" option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.\r\n\r\nIf you enable this setting, offline files are fully synchronized at logon. Full synchronization ensures that offline files are complete and current. Enabling this setting automatically enables logon synchronization in Synchronization Manager.\r\n\r\nIf this setting is disabled and Synchronization Manager is configured for logon synchronization, the system performs only a quick synchronization. Quick synchronization ensures that files are complete but does not ensure that they are current.\r\n\r\nIf you do not configure this setting and Synchronization Manager is configured for logon synchronization, the system performs a quick synchronization by default, but users can change this option.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To change the synchronization method without setting a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then select the \"Synchronize all offline files before logging on\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-syncatlogon-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogon_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogon_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_2","displayName":"Synchronize offline files before suspend","description":"Determines whether offline files are synchonized before a computer is suspended.\r\n\r\nIf you enable this setting, offline files are synchronized whenever the computer is suspended. Setting the synchronization action to \"Quick\" ensures only that all files in the cache are complete. Setting the synchronization action to \"Full\" ensures that all cached files and folders are up-to-date with the most current version.\r\n\r\nIf you disable or do not configuring this setting, files are not synchronized when the computer is suspended.\r\n\r\nNote: If the computer is suspended by closing the display on a portable computer, files are not synchronized. If multiple users are logged on to the computer at the time the computer is suspended, a synchronization is not performed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-syncatsuspend-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_2_lbl_syncatsuspendcombo","displayName":"Action:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_2_lbl_syncatsuspendcombo_0","displayName":"Quick","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_2_lbl_syncatsuspendcombo_1","displayName":"Full","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_synconcostednetwork","displayName":"Enable file synchronization on costed networks","description":"This policy setting determines whether offline files are synchronized in the background when it could result in extra charges on cell phone or broadband plans.\r\n\r\nIf you enable this setting, synchronization can occur in the background when the user's network is roaming, near, or over the plan's data limit. This may result in extra charges on cell phone or broadband plans.\r\n\r\nIf this setting is disabled or not configured, synchronization will not run in the background on network folders when the user's network is roaming, near, or over the plan's data limit. The network folder must also be in \"slow-link\" mode, as specified by the \"Configure slow-link mode\" policy to avoid network usage.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-synconcostednetwork"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_synconcostednetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_synconcostednetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_workofflinedisabled_2","displayName":"Remove \"Work offline\" command","description":"This policy setting removes the \"Work offline\" command from Explorer, preventing users from manually changing whether Offline Files is in online mode or offline mode.\r\n\r\nIf you enable this policy setting, the \"Work offline\" command is not displayed in File Explorer.\r\n\r\nIf you disable or do not configure this policy setting, the \"Work offline\" command is displayed in File Explorer.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-workofflinedisabled-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_workofflinedisabled_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_workofflinedisabled_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectblockeddriverspolicy","displayName":"Notify blocked drivers","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectblockeddriverspolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectblockeddriverspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectblockeddriverspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomcomponentfailurespolicy","displayName":"Detect application failures caused by deprecated COM objects","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectdeprecatedcomcomponentfailurespolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomcomponentfailurespolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomcomponentfailurespolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomcomponentfailurespolicy_detectdeprecatedcomcomponentfailureslevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomcomponentfailurespolicy_detectdeprecatedcomcomponentfailureslevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomcomponentfailurespolicy_detectdeprecatedcomcomponentfailureslevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy","displayName":"Detect application failures caused by deprecated Windows DLLs","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectdeprecatedcomponentfailurespolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_detectdeprecatedcomponentfailureslevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_detectdeprecatedcomponentfailureslevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_detectdeprecatedcomponentfailureslevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectinstallfailurespolicy","displayName":"Detect application install failures","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectinstallfailurespolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectinstallfailurespolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectinstallfailurespolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectundetectedinstallerspolicy","displayName":"Detect application installers that need to be run as administrator","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectundetectedinstallerspolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectundetectedinstallerspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectundetectedinstallerspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectundetectedinstallerspolicy_detectundetectedinstallerslevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectundetectedinstallerspolicy_detectundetectedinstallerslevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectundetectedinstallerspolicy_detectundetectedinstallerslevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy","displayName":"Detect applications unable to launch installers under UAC","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectupdatefailurespolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_detectupdatefailureslevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_detectupdatefailureslevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_detectupdatefailureslevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pca_disablepcauipolicy","displayName":"Detect compatibility issues for applications and drivers","description":"This policy setting configures the Program Compatibility Assistant (PCA) to diagnose failures with application and driver compatibility. \r\n\r\nIf you enable this policy setting, the PCA is configured to detect failures during application installation, failures during application runtime, and drivers blocked due to compatibility issues. When failures are detected, the PCA will provide options to run the application in a compatibility mode or get help online through a Microsoft website.\r\n\r\nIf you disable this policy setting, the PCA does not detect compatibility issues for applications and drivers.\r\n\r\nIf you do not configure this policy setting, the PCA is configured to detect failures during application installation, failures during application runtime, and drivers blocked due to compatibility issues.\r\n\r\nNote: This policy setting has no effect if the \"Turn off Program Compatibility Assistant\" policy setting is enabled. The Diagnostic Policy Service (DPS) and Program Compatibility Assistant Service must be running for the PCA to run. These services can be configured by using the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-disablepcauipolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_disablepcauipolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_disablepcauipolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache","displayName":"Turn on BranchCache","description":"This policy setting specifies whether BranchCache is enabled on client computers to which this policy is applied. In addition to this policy setting, you must specify whether the client computers are hosted cache mode or distributed cache mode clients. To do so, configure one of the following the policy settings: \r\n\r\n- Set BranchCache Distributed Cache mode\r\n\r\n- Set BranchCache Hosted Cache mode\r\n\r\n- Configure Hosted Cache Servers\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to enable BranchCache on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the enabled setting that you use on individual client computers where you want to enable BranchCache.\r\n\r\n- Enabled. With this selection, BranchCache is turned on for all client computers where the policy is applied. For example, if this policy is enabled in domain Group Policy, BranchCache is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache is turned off for all client computers where the policy is applied.\r\n\r\n* This policy setting is supported on computers that are running Windows Vista Business, Enterprise, and Ultimate editions with Background Intelligent Transfer Service (BITS) 4.0 installed.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-enablewindowsbranchcache"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_distributed","displayName":"Set BranchCache Distributed Cache mode","description":"This policy setting specifies whether BranchCache distributed cache mode is enabled on client computers to which this policy is applied. In addition to this policy, you must use the policy \"Turn on BranchCache\" to enable BranchCache on client computers.\r\n\r\nIn distributed cache mode, client computers download content from BranchCache-enabled main office content servers, cache the content locally, and serve the content to other BranchCache distributed cache mode clients in the branch office.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to enable BranchCache on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the enabled setting that you use on individual client computers where you want to enable BranchCache.\r\n\r\n- Enabled. With this selection, BranchCache distributed cache mode is enabled for all client computers where the policy is applied. For example, if this policy is enabled in domain Group Policy, BranchCache distributed cache mode is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache distributed cache mode is turned off for all client computers where the policy is applied.\r\n\r\n* This policy setting is supported on computers that are running Windows Vista Business, Enterprise, and Ultimate editions with Background Intelligent Transfer Service (BITS) 4.0 installed.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-enablewindowsbranchcache-distributed"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_distributed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_distributed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hosted","displayName":"Set BranchCache Hosted Cache mode","description":"This policy setting specifies whether BranchCache hosted cache mode is enabled on client computers to which this policy is applied. In addition to this policy, you must use the policy \"Turn on BranchCache\" to enable BranchCache on client computers.\r\n\r\nWhen a client computer is configured as a hosted cache mode client, it is able to download cached content from a hosted cache server that is located at the branch office. In addition, when the hosted cache client obtains content from a content server, the client can upload the content to the hosted cache server for access by other hosted cache clients at the branch office.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to enable BranchCache on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the enabled setting that you use on individual client computers where you want to enable BranchCache.\r\n\r\n- Enabled. With this selection, BranchCache hosted cache mode is enabled for all client computers where the policy is applied. For example, if this policy is enabled in domain Group Policy, BranchCache hosted cache mode is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache hosted cache mode is turned off for all client computers where the policy is applied.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\n- Type the name of the hosted cache server. Specifies the computer name of the hosted cache server. Because the hosted cache server name is also specified in the certificate enrolled to the hosted cache server, the name that you enter here must match the name of the hosted cache server that is specified in the server certificate. \r\n\r\nHosted cache clients must trust the server certificate that is issued to the hosted cache server. Ensure that the issuing CA certificate is installed in the Trusted Root Certification Authorities certificate store on all hosted cache client computers.\r\n\r\n* This policy setting is supported on computers that are running Windows Vista Business, Enterprise, and Ultimate editions with Background Intelligent Transfer Service (BITS) 4.0 installed.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-enablewindowsbranchcache-hosted"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hosted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hosted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hosted_wbc_cache_textbox","displayName":"Type the name of the hosted cache server","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedcachediscovery","displayName":"Enable Automatic Hosted Cache Discovery by Service Connection Point","description":"This policy setting specifies whether client computers should attempt the automatic configuration of hosted cache mode by searching for hosted cache servers publishing service connection points that are associated with the client's current Active Directory site. If you enable this policy setting, client computers to which the policy setting is applied search for hosted cache servers using Active Directory, and will prefer both these servers and hosted cache mode rather than manual BranchCache configuration or BranchCache configuration by other group policies.\r\n\r\nIf you enable this policy setting in addition to the \"Turn on BranchCache\" policy setting, BranchCache clients attempt to discover hosted cache servers in the local branch office. If client computers detect hosted cache servers, hosted cache mode is turned on. If they do not detect hosted cache servers, hosted cache mode is not turned on, and the client uses any other configuration that is specified manually or by Group Policy.\r\n\r\nWhen this policy setting is applied, the client computer performs or does not perform automatic hosted cache server discovery under the following circumstances:\r\n\r\nIf no other BranchCache mode-based policy settings are applied, the client computer performs automatic hosted cache server discovery. If one or more hosted cache servers is found, the client computer self-configures for hosted cache mode.\r\n\r\nIf the policy setting \"Set BranchCache Distributed Cache Mode\" is applied in addition to this policy, the client computer performs automatic hosted cache server discovery. If one or more hosted cache servers are found, the client computer self-configures for hosted cache mode only.\r\n\r\nIf the policy setting \"Set BranchCache Hosted Cache Mode\" is applied, the client computer does not perform automatic hosted cache discovery. This is also true in cases where the policy setting \"Configure Hosted Cache Servers\" is applied.\r\n\r\nThis policy setting can only be applied to client computers that are running at least Windows 8. This policy has no effect on computers that are running Windows 7 or Windows Vista. \r\n\r\nIf you disable, or do not configure this setting, a client will not attempt to discover hosted cache servers by service connection point.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy setting, and client computers do not perform hosted cache server discovery.\r\n\r\n- Enabled. With this selection, the policy setting is applied to client computers, which perform automatic hosted cache server discovery and which are configured as hosted cache mode clients.\r\n\r\n- Disabled. With this selection, this policy is not applied to client computers.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-enablewindowsbranchcache-hostedcachediscovery"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedcachediscovery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedcachediscovery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedmultipleservers","displayName":"Configure Hosted Cache Servers","description":"This policy setting specifies whether client computers are configured to use hosted cache mode and provides the computer name of the hosted cache servers that are available to the client computers. Hosted cache mode enables client computers in branch offices to retrieve content from one or more hosted cache servers that are installed in the same office location. You can use this setting to automatically configure client computers that are configured for hosted cache mode with the computer names of the hosted cache servers in the branch office.\r\n\r\nIf you enable this policy setting and specify valid computer names of hosted cache servers, hosted cache mode is enabled for all client computers to which the policy setting is applied. For this policy setting to take effect, you must also enable the \"Turn on BranchCache\" policy setting.\r\n\r\nThis policy setting can only be applied to client computers that are running at least Windows 8. This policy has no effect on computers that are running Windows 7 or Windows Vista. Client computers to which this policy setting is applied, in addition to the \"Set BranchCache Hosted Cache mode\" policy setting, use the hosted cache servers that are specified in this policy setting and do not use the hosted cache server that is configured in the policy setting \"Set BranchCache Hosted Cache Mode.\"\r\n\r\nIf you do not configure this policy setting, or if you disable this policy setting, client computers that are configured with hosted cache mode still function correctly.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache settings are not applied to client computers by this policy setting.\r\n\r\n- Enabled. With this selection, the policy setting is applied to client computers, which are configured as hosted cache mode clients that use the hosted cache servers that you specify in \"Hosted cache servers.\"\r\n\r\n- Disabled. With this selection, this policy is not applied to client computers.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\n- Hosted cache servers. To add hosted cache server computer names to this policy setting, click Enabled, and then click Show. The Show Contents dialog box opens. Click Value, and then type the computer names of the hosted cache servers.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-enablewindowsbranchcache-hostedmultipleservers"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedmultipleservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedmultipleservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_hostedmultipleservers_wbc_multipleservers_listbox","displayName":"Hosted cache servers","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_smb","displayName":"Configure BranchCache for network files","description":"This policy setting is used only when you have deployed one or more BranchCache-enabled file servers at your main office. This policy setting specifies when client computers in branch offices start caching content from file servers based on the network latency - or delay - that occurs when the clients download content from the main office over a Wide Area Network (WAN) link. When you configure a value for this setting, which is the maximum round trip network latency allowed before caching begins, clients do not cache content until the network latency reaches the specified value; when network latency is greater than the value, clients begin caching content after they receive it from the file servers.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache latency settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to configure a BranchCache latency setting on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache latency settings on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the latency setting that you use on individual client computers.\r\n\r\n- Enabled. With this selection, the BranchCache maximum round trip latency setting is enabled for all client computers where the policy is applied. For example, if Configure BranchCache for network files is enabled in domain Group Policy, the BranchCache latency setting that you specify in the policy is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache client computers use the default latency setting of 80 milliseconds.\r\n\r\nIn circumstances where this policy setting is enabled, you can also select and configure the following option:\r\n\r\n- Type the maximum round trip network latency (milliseconds) after which caching begins. Specifies the amount of time, in milliseconds, after which BranchCache client computers begin to cache content locally.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-enablewindowsbranchcache-smb"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_smb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_smb_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_enablewindowsbranchcache_smb_wbc_smblatency_decimaltextbox","displayName":"Type the maximum round trip network latency (milliseconds) after which caching begins","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent","displayName":"Set percentage of disk space used for client computer cache","description":"This policy setting specifies the default percentage of total disk space that is allocated for the BranchCache disk cache on client computers.\r\n\r\nIf you enable this policy setting, you can configure the percentage of total disk space to allocate for the cache.\r\n\r\nIf you disable or do not configure this policy setting, the cache is set to 5 percent of the total disk space on the client computer.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache client computer cache settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to configure a BranchCache client computer cache setting on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache client computer cache settings on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the client computer cache setting that you use on individual client computers.\r\n\r\n- Enabled. With this selection, the BranchCache client computer cache setting is enabled for all client computers where the policy is applied. For example, if Set percentage of disk space used for client computer cache is enabled in domain Group Policy, the BranchCache client computer cache setting that you specify in the policy is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache client computers use the default client computer cache setting of five percent of the total disk space on the client computer.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\n- Specify the percentage of total disk space allocated for the cache. Specifies an integer that is the percentage of total client computer disk space to use for the BranchCache client computer cache.\r\n\r\n* This policy setting is supported on computers that are running Windows Vista Business, Enterprise, and Ultimate editions with Background Intelligent Transfer Service (BITS) 4.0 installed.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-setcachepercent"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent_wbc_cache_size_percent_dctxtbox","displayName":"Specify the percentage of total disk space allocated for the cache","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdatacacheentrymaxage","displayName":"Set age for segments in the data cache","description":"This policy setting specifies the default age in days for which segments are valid in the BranchCache data cache on client computers.\r\n\r\nIf you enable this policy setting, you can configure the age for segments in the data cache.\r\n\r\nIf you disable or do not configure this policy setting, the age is set to 28 days.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache client computer cache age settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to configure a BranchCache client computer cache age setting on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache client computer cache age settings on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the client computer cache age setting that you use on individual client computers.\r\n\r\n- Enabled. With this selection, the BranchCache client computer cache age setting is enabled for all client computers where the policy is applied. For example, if this policy setting is enabled in domain Group Policy, the BranchCache client computer cache age that you specify in the policy is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache client computers use the default client computer cache age setting of 28 days on the client computer.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\n- Specify the age in days for which segments in the data cache are valid.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-setdatacacheentrymaxage"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdatacacheentrymaxage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdatacacheentrymaxage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdatacacheentrymaxage_wbc_cache_maxage_dctxtbox","displayName":"Specify the age in days for which segments in the data cache are valid","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading","displayName":"Configure Client BranchCache Version Support","description":"This policy setting specifies whether BranchCache-capable client computers operate in a downgraded mode in order to maintain compatibility with previous versions of BranchCache. If client computers do not use the same BranchCache version, cache efficiency might be reduced because client computers that are using different versions of BranchCache might store cache data in incompatible formats.\r\n\r\nIf you enable this policy setting, all clients use the version of BranchCache that you specify in \"Select from the following versions.\"\r\n\r\nIf you do not configure this setting, all clients will use the version of BranchCache that matches their operating system.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, this policy setting is not applied to client computers, and the clients run the version of BranchCache that is included with their operating system.\r\n\r\n- Enabled. With this selection, this policy setting is applied to client computers based on the value of the option setting \"Select from the following versions\" that you specify.\r\n\r\n- Disabled. With this selection, this policy setting is not applied to client computers, and the clients run the version of BranchCache that is included with their operating system.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\nSelect from the following versions\r\n\r\n- Windows Vista with BITS 4.0 installed, Windows 7, or Windows Server 2008 R2. If you select this version, later versions of Windows run the version of BranchCache that is included in these operating systems rather than later versions of BranchCache.\r\n\r\n- Windows 8. If you select this version, Windows 8 will run the version of BranchCache that is included in the operating system.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-setdowngrading"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_downgrading_version","displayName":"Select from the following versions:","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_downgrading_version_1","displayName":"Windows Vista with BITS 4.0 installed, Windows 7, or Windows Server 2008 R2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_downgrading_version_2","displayName":"Windows 8","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pentraining_pentrainingoff_2","displayName":"Turn off Tablet PC Pen Training","description":"Turns off Tablet PC Pen Training.\r\n\r\nIf you enable this policy setting, users cannot open Tablet PC Pen Training.\r\n\r\nIf you disable or do not configure this policy setting, users can open Tablet PC Pen Training.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pentraining#admx-pentraining-pentrainingoff-2"],"categoryId":"fe65603b-1980-446b-ae17-516eb885c6be","categoryName":"Tablet PC Pen Training","options":[{"id":"device_vendor_msft_policy_config_admx_pentraining_pentrainingoff_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pentraining_pentrainingoff_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1","displayName":"Configure Scenario Execution Level","description":"Determines the execution level for Windows Boot Performance Diagnostics.\r\n\r\nIf you enable this policy setting, you must select an execution level from the dropdown menu. If you select problem detection and troubleshooting only, the Diagnostic Policy Service (DPS) will detect Windows Boot Performance problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will detect Windows Boot Performance problems and indicate to the user that assisted resolution is available.\r\n\r\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve any Windows Boot Performance problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS will enable Windows Boot Performance for resolution by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo system restart or service restart is required for this policy to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-performancediagnostics#admx-performancediagnostics-wdiscenarioexecutionpolicy-1"],"categoryId":"18b972fd-74f2-4345-9449-087c80dd38a3","categoryName":"Windows Boot Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"18b972fd-74f2-4345-9449-087c80dd38a3","categoryName":"Windows Boot Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_wdiscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_wdiscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_2","displayName":"Configure Scenario Execution Level","description":"Determines the execution level for Windows System Responsiveness Diagnostics.\r\n\r\nIf you enable this policy setting, you must select an execution level from the dropdown menu. If you select problem detection and troubleshooting only, the Diagnostic Policy Service (DPS) will detect Windows System Responsiveness problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will detect Windows System Responsiveness problems and indicate to the user that assisted resolution is available.\r\n\r\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve any Windows System Responsiveness problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS will enable Windows System Responsiveness for resolution by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo system restart or service restart is required for this policy to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-performancediagnostics#admx-performancediagnostics-wdiscenarioexecutionpolicy-2"],"categoryId":"32b20540-8fe9-4730-a4b0-ff41f6b13a97","categoryName":"Windows System Responsiveness Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_2_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"32b20540-8fe9-4730-a4b0-ff41f6b13a97","categoryName":"Windows System Responsiveness Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_2_wdiscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_2_wdiscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3","displayName":"Configure Scenario Execution Level","description":"Determines the execution level for Windows Shutdown Performance Diagnostics.\r\n\r\nIf you enable this policy setting, you must select an execution level from the dropdown menu. If you select problem detection and troubleshooting only, the Diagnostic Policy Service (DPS) will detect Windows Shutdown Performance problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will detect Windows Shutdown Performance problems and indicate to the user that assisted resolution is available.\r\n\r\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve any Windows Shutdown Performance problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS will enable Windows Shutdown Performance for resolution by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo system restart or service restart is required for this policy to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-performancediagnostics#admx-performancediagnostics-wdiscenarioexecutionpolicy-3"],"categoryId":"cebd5934-9dfe-4278-966d-b9d880cb30e7","categoryName":"Windows Shutdown Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"cebd5934-9dfe-4278-966d-b9d880cb30e7","categoryName":"Windows Shutdown Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_wdiscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_wdiscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_4","displayName":"Configure Scenario Execution Level","description":"Determines the execution level for Windows Standby/Resume Performance Diagnostics.\n\nIf you enable this policy setting, you must select an execution level from the dropdown menu. If you select problem detection and troubleshooting only, the Diagnostic Policy Service (DPS) will detect Windows Standby/Resume Performance problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will detect Windows Standby/Resume Performance problems and indicate to the user that assisted resolution is available.\n\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve any Windows Standby/Resume Performance problems that are handled by the DPS.\n\nIf you do not configure this policy setting, the DPS will enable Windows Standby/Resume Performance for resolution by default.\n\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\n\nNo system restart or service restart is required for this policy to take effect: changes take effect immediately.\n\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-performancediagnostics#admx-performancediagnostics-wdiscenarioexecutionpolicy-4"],"categoryId":"a7e7529f-1030-41da-8b4d-024e1c08bbac","categoryName":"Windows Standby Resume Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_4_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":"","helpText":"","infoUrls":[],"categoryId":"a7e7529f-1030-41da-8b4d-024e1c08bbac","categoryName":"Windows Standby Resume Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_4_wdiscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_4_wdiscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_acconnectivityinstandby_2","displayName":"Allow network connectivity during connected-standby (plugged in)","description":"This policy setting allows you to control the network connectivity state in standby on modern standby-capable systems.\r\n\r\nIf you enable this policy setting, network connectivity will be maintained in standby.\r\n\r\nIf you disable this policy setting, network connectivity in standby is not guaranteed. This connectivity restriction currently applies to WLAN networks only, and is subject to change.\r\n\r\nIf you do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-acconnectivityinstandby-2"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_acconnectivityinstandby_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_acconnectivityinstandby_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_accriticalsleeptransitionsdisable_2","displayName":"Turn on the ability for applications to prevent sleep transitions (plugged in)","description":"This policy setting allows you to turn on the ability for applications and services to prevent the system from sleeping.\r\n\r\nIf you enable this policy setting, an application or service may prevent the system from sleeping (Hybrid Sleep, Stand By, or Hibernate).\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-accriticalsleeptransitionsdisable-2"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_accriticalsleeptransitionsdisable_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_accriticalsleeptransitionsdisable_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2","displayName":"Select the Start menu Power button action (plugged in)","description":"This policy setting specifies the action that Windows takes when a user presses the Start menu Power button.\r\n\r\nIf you enable this policy setting, select one of the following actions:\r\n-Sleep\r\n-Hibernate\r\n-Shut down\r\n\r\nIf you disable this policy or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-acstartmenubuttonaction-2"],"categoryId":"5d03766c-9480-43f2-9e85-461a44c821d4","categoryName":"Button Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2_selectacstartmenubuttonaction","displayName":"User Interface Sleep Button Action","description":null,"helpText":"","infoUrls":[],"categoryId":"5d03766c-9480-43f2-9e85-461a44c821d4","categoryName":"Button Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2_selectacstartmenubuttonaction_0","displayName":"Sleep","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2_selectacstartmenubuttonaction_1","displayName":"Hibernate","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_acstartmenubuttonaction_2_selectacstartmenubuttonaction_2","displayName":"Shut down","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestac","displayName":"Allow applications to prevent automatic sleep (plugged in)","description":"This policy setting allows applications and services to prevent automatic sleep.\r\n\r\nIf you enable this policy setting, any application, service, or device driver prevents Windows from automatically transitioning to sleep after a period of user inactivity.\r\n\r\nIf you disable or do not configure this policy setting, applications, services, or drivers do not prevent Windows from automatically transitioning to sleep. Only user input is used to determine if Windows should automatically sleep.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystempowerrequestac"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestac_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestac_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestdc","displayName":"Allow applications to prevent automatic sleep (on battery)","description":"This policy setting allows applications and services to prevent automatic sleep.\r\n\r\nIf you enable this policy setting, any application, service, or device driver prevents Windows from automatically transitioning to sleep after a period of user inactivity.\r\n\r\nIf you disable or do not configure this policy setting, applications, services, or drivers do not prevent Windows from automatically transitioning to sleep. Only user input is used to determine if Windows should automatically sleep.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystempowerrequestdc"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestdc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestdc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopenac","displayName":"Allow automatic sleep with Open Network Files (plugged in)","description":"This policy setting allows you to manage automatic sleep with open network files.\r\n\r\nIf you enable this policy setting, the computer automatically sleeps when network files are open.\r\n\r\nIf you disable or do not configure this policy setting, the computer does not automatically sleep when network files are open.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystemsleepwithremotefilesopenac"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopenac_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopenac_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopendc","displayName":"Allow automatic sleep with Open Network Files (on battery)","description":"This policy setting allows you to manage automatic sleep with open network files.\r\n\r\nIf you enable this policy setting, the computer automatically sleeps when network files are open.\r\n\r\nIf you disable or do not configure this policy setting, the computer does not automatically sleep when network files are open.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystemsleepwithremotefilesopendc"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopendc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopendc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2","displayName":"Specify a custom active power plan","description":"This policy setting specifies the active power plan from a specified power plan’s GUID. The GUID for a custom power plan GUID can be retrieved by using powercfg, the power configuration command line tool. \r\n\r\nIf you enable this policy setting, you must specify a power plan, specified as a GUID using the following format: XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX (For example, 103eea6e-9fcd-4544-a713-c282d8e50083), indicating the power plan to be active.\r\n\r\nIf you disable or do not configure this policy setting, users can see and change this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-customactiveschemeoverride-2"],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":[{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2_customactiveschemeoverrideenter","displayName":"Custom Active Power Plan (GUID):","description":null,"helpText":"","infoUrls":[],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2","displayName":"Critical battery notification action","description":"This policy setting specifies the action that Windows takes when battery capacity reaches the critical battery notification level.\r\n\r\nIf you enable this policy setting, select one of the following actions:\r\n-Take no action\r\n-Sleep\r\n-Hibernate\r\n-Shut down\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargeaction0-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0","displayName":"Critical Battery Notification Action","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_0","displayName":"Take no action","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_1","displayName":"Sleep","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_2","displayName":"Hibernate","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_3","displayName":"Shut down","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2","displayName":"Low battery notification action","description":"This policy setting specifies the action that Windows takes when battery capacity reaches the low battery notification level.\r\n\r\nIf you enable this policy setting, select one of the following actions:\r\n-Take no action\r\n-Sleep\r\n-Hibernate\r\n-Shut down\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargeaction1-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_selectdcbatterydischargeaction1","displayName":"Low Battery Notification Action","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_selectdcbatterydischargeaction1_0","displayName":"Take no action","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_selectdcbatterydischargeaction1_1","displayName":"Sleep","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_selectdcbatterydischargeaction1_2","displayName":"Hibernate","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction1_2_selectdcbatterydischargeaction1_3","displayName":"Shut down","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel0_2","displayName":"Critical battery notification level","description":"This policy setting specifies the percentage of battery capacity remaining that triggers the critical battery notification action.\r\n\r\nIf you enable this policy setting, you must enter a numeric value (percentage) to set the battery level that triggers the critical notification.\r\n\r\nTo set the action that is triggered, see the \"Critical Battery Notification Action\" policy setting.\r\n\r\nIf you disable this policy setting or do not configure it, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargelevel0-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel0_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel0_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel0_2_enterdcbatterydischargelevel0","displayName":"Critical Battery Notification Level","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2","displayName":"Low battery notification level","description":"This policy setting specifies the percentage of battery capacity remaining that triggers the low battery notification action.\r\n\r\nIf you enable this policy setting, you must enter a numeric value (percentage) to set the battery level that triggers the low notification.\r\n\r\nTo set the action that is triggered, see the \"Low Battery Notification Action\" policy setting.\r\n\r\nIf you disable this policy setting or do not configure it, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargelevel1-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2_enterdcbatterydischargelevel1","displayName":"Low Battery Notification Level","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1uinotification_2","displayName":"Turn off low battery user notification","description":"This policy setting turns off the user notification when the battery capacity remaining equals the low battery notification level.\r\n\r\nIf you enable this policy setting, Windows shows a notification when the battery capacity remaining equals the low battery notification level. To configure the low battery notification level, see the \"Low Battery Notification Level\" policy setting.\r\n\r\nThe notification will only be shown if the \"Low Battery Notification Action\" policy setting is configured to \"No Action\".\r\n\r\nIf you disable or do not configure this policy setting, users can control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargelevel1uinotification-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1uinotification_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1uinotification_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcconnectivityinstandby_2","displayName":"Allow network connectivity during connected-standby (on battery)","description":"This policy setting allows you to control the network connectivity state in standby on modern standby-capable systems.\r\n\r\nIf you enable this policy setting, network connectivity will be maintained in standby.\r\n\r\nIf you disable this policy setting, network connectivity in standby is not guaranteed. This connectivity restriction currently applies to WLAN networks only, and is subject to change.\r\n\r\nIf you do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcconnectivityinstandby-2"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcconnectivityinstandby_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcconnectivityinstandby_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dccriticalsleeptransitionsdisable_2","displayName":"Turn on the ability for applications to prevent sleep transitions (on battery)","description":"This policy setting allows you to turn on the ability for applications and services to prevent the system from sleeping.\r\n\r\nIf you enable this policy setting, an application or service may prevent the system from sleeping (Hybrid Sleep, Stand By, or Hibernate).\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dccriticalsleeptransitionsdisable-2"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dccriticalsleeptransitionsdisable_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dccriticalsleeptransitionsdisable_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2","displayName":"Select the Start menu Power button action (on battery)","description":"This policy setting specifies the action that Windows takes when a user presses the Start menu Power button.\r\n\r\nIf you enable this policy setting, select one of the following actions:\r\n-Sleep\r\n-Hibernate\r\n-Shut down\r\n\r\nIf you disable this policy or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcstartmenubuttonaction-2"],"categoryId":"5d03766c-9480-43f2-9e85-461a44c821d4","categoryName":"Button Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2_selectdcstartmenubuttonaction","displayName":"User Interface Sleep Button Action","description":null,"helpText":"","infoUrls":[],"categoryId":"5d03766c-9480-43f2-9e85-461a44c821d4","categoryName":"Button Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2_selectdcstartmenubuttonaction_0","displayName":"Sleep","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2_selectdcstartmenubuttonaction_1","displayName":"Hibernate","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcstartmenubuttonaction_2_selectdcstartmenubuttonaction_2","displayName":"Shut down","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2","displayName":"Turn Off the hard disk (plugged in)","description":"This policy setting specifies the period of inactivity before Windows turns off the hard disk.\r\n\r\nIf you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows turns off the hard disk.\r\n\r\nIf you disable or do not configure this policy setting, users can see and change this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-diskacpowerdowntimeout-2"],"categoryId":"91c02e14-8848-485d-8844-b9933fa888ec","categoryName":"Hard Disk Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2_enterdiskacpowerdowntimeout","displayName":"Turn Off the Hard Disk (seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"91c02e14-8848-485d-8844-b9933fa888ec","categoryName":"Hard Disk Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_power_diskdcpowerdowntimeout_2","displayName":"Turn Off the hard disk (on battery)","description":"This policy setting specifies the period of inactivity before Windows turns off the hard disk.\r\n\r\nIf you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows turns off the hard disk.\r\n\r\nIf you disable or do not configure this policy setting, users can see and change this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-diskdcpowerdowntimeout-2"],"categoryId":"91c02e14-8848-485d-8844-b9933fa888ec","categoryName":"Hard Disk Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_diskdcpowerdowntimeout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_diskdcpowerdowntimeout_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_diskdcpowerdowntimeout_2_enterdiskdcpowerdowntimeout","displayName":"Turn Off the Hard Disk (seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"91c02e14-8848-485d-8844-b9933fa888ec","categoryName":"Hard Disk Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_power_dont_poweroff_aftershutdown","displayName":"Do not turn off system power after a Windows system shutdown has occurred.","description":"This policy setting allows you to configure whether power is automatically turned off when Windows shutdown completes. This setting does not affect Windows shutdown behavior when shutdown is manually selected using the Start menu or Task Manager user interfaces. Applications such as UPS software may rely on Windows shutdown behavior.\r\n\r\nThis setting is only applicable when Windows shutdown is initiated by software programs invoking the Windows programming interfaces ExitWindowsEx() or InitiateSystemShutdown().\r\n\r\nIf you enable this policy setting, the computer system safely shuts down and remains in a powered state, ready for power to be safely removed.\r\n\r\nIf you disable or do not configure this policy setting, the computer system safely shuts down to a fully powered-off state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dont-poweroff-aftershutdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_power_dont_poweroff_aftershutdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dont_poweroff_aftershutdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_enabledesktopslideshowac","displayName":"Turn on desktop background slideshow (plugged in)","description":"This policy setting allows you to specify if Windows should enable the desktop background slideshow.\n\nIf you enable this policy setting, desktop background slideshow is enabled.\n\nIf you disable this policy setting, the desktop background slideshow is disabled.\n\nIf you disable or do not configure this policy setting, users control this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-enabledesktopslideshowac"],"categoryId":"01da0c26-af30-4eb2-a899-7d5e7ecb9738","categoryName":"Video and Display Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_enabledesktopslideshowac_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_enabledesktopslideshowac_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_enabledesktopslideshowdc","displayName":"Turn on desktop background slideshow (on battery)","description":"This policy setting allows you to specify if Windows should enable the desktop background slideshow.\n\nIf you enable this policy setting, desktop background slideshow is enabled.\n\nIf you disable this policy setting, the desktop background slideshow is disabled.\n\nIf you disable or do not configure this policy setting, users control this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-enabledesktopslideshowdc"],"categoryId":"01da0c26-af30-4eb2-a899-7d5e7ecb9738","categoryName":"Video and Display Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_enabledesktopslideshowdc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_enabledesktopslideshowdc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2","displayName":"Select an active power plan","description":"This policy setting specifies the active power plan from a list of default Windows power plans. To specify a custom power plan, use the Custom Active Power Plan setting.\r\n\r\nIf you enable this policy setting, specify a power plan from the Active Power Plan list.\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-inboxactiveschemeoverride-2"],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":[{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter","displayName":"Active Power Plan:","description":null,"helpText":"","infoUrls":[],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":[{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter_381b4222-f694-41f0-9685-ff5bb260df2e","displayName":"Automatic (recommended)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter_a1841308-3541-4fab-bc81-f71556f20b4a","displayName":"Power Saver","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter_8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c","displayName":"High Performance","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_powerthrottlingturnoff","displayName":"Turn off Power Throttling","description":"This policy setting allows you to turn off Power Throttling.\r\n\r\nIf you enable this policy setting, Power Throttling will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-powerthrottlingturnoff"],"categoryId":"86b4fa22-f6f1-4ca5-8fe4-8788f9b3fd89","categoryName":"Power Throttling Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_powerthrottlingturnoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_powerthrottlingturnoff_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_reservebatterynotificationlevel","displayName":"Reserve battery notification level","description":"This policy setting specifies the percentage of battery capacity remaining that triggers the reserve power mode.\r\n\r\nIf you enable this policy setting, you must enter a numeric value (percentage) to set the battery level that triggers the reserve power notification.\r\n\r\nIf you disable or do not configure this policy setting, users can see and change this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-reservebatterynotificationlevel"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_reservebatterynotificationlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_reservebatterynotificationlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_power_reservebatterynotificationlevel_enterreservebatterynotificationlevel","displayName":"Reserve Battery Notification Level (percent):","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging","displayName":"Turn on Module Logging","description":"\r\n This policy setting allows you to turn on logging for Windows PowerShell modules.\r\n\r\n If you enable this policy setting, pipeline execution events for members of the specified modules are recorded in the Windows PowerShell log in Event Viewer. Enabling this policy setting for a module is equivalent to setting the LogPipelineExecutionDetails property of the module to True.\r\n\r\n If you disable this policy setting, logging of execution events is disabled for all Windows PowerShell modules. Disabling this policy setting for a module is equivalent to setting the LogPipelineExecutionDetails property of the module to False.\r\n\r\n If this policy setting is not configured, the LogPipelineExecutionDetails property of a module or snap-in determines whether the execution events of a module or snap-in are logged. By default, the LogPipelineExecutionDetails property of all modules and snap-ins is set to False.\r\n\r\n To add modules and snap-ins to the policy setting list, click Show, and then type the module names in the list. The modules and snap-ins in the list must be installed on the computer.\r\n\r\n Note: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enablemodulelogging"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging_listbox_modulenames","displayName":"Module Names","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts","displayName":"Turn on Script Execution","description":"This policy setting lets you configure the script execution policy, controlling which scripts are allowed to run.\r\n\r\nIf you enable this policy setting, the scripts selected in the drop-down list are allowed to run.\r\n\r\nThe \"Allow only signed scripts\" policy setting allows scripts to execute only if they are signed by a trusted publisher.\r\n\r\nThe \"Allow local scripts and remote signed scripts\" policy setting allows any local scrips to run; scripts that originate from the Internet must be signed by a trusted publisher.\r\n\r\nThe \"Allow all scripts\" policy setting allows all scripts to run.\r\n\r\nIf you disable this policy setting, no scripts are allowed to run.\r\n\r\nNote: This policy setting exists under both \"Computer Configuration\" and \"User Configuration\" in the Local Group Policy Editor. The \"Computer Configuration\" has precedence over \"User Configuration.\"\r\n\r\nIf you disable or do not configure this policy setting, it reverts to a per-machine preference setting; the default if that is not configured is \"No scripts allowed.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enablescripts"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_executionpolicy","displayName":"Execution Policy","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_executionpolicy_allsigned","displayName":"Allow only signed scripts","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_executionpolicy_remotesigned","displayName":"Allow local scripts and remote signed scripts","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_executionpolicy_unrestricted","displayName":"Allow all scripts","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting","displayName":"Turn on PowerShell Transcription","description":"\r\n This policy setting lets you capture the input and output of Windows PowerShell commands into text-based transcripts.\r\n\r\n If you enable this policy setting, Windows PowerShell will enable transcripting for Windows PowerShell, the Windows PowerShell ISE, and any other\r\n applications that leverage the Windows PowerShell engine. By default, Windows PowerShell will record transcript output to each users' My Documents\r\n directory, with a file name that includes 'PowerShell_transcript', along with the computer name and time started. Enabling this policy is equivalent\r\n to calling the Start-Transcript cmdlet on each Windows PowerShell session.\r\n\r\n If you disable this policy setting, transcripting of PowerShell-based applications is disabled by default, although transcripting can still be enabled\r\n through the Start-Transcript cmdlet.\r\n \r\n If you use the OutputDirectory setting to enable transcript logging to a shared location, be sure to limit access to that directory to prevent users\r\n from viewing the transcripts of other users or computers.\r\n\r\n Note: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enabletranscripting"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_enableinvocationheader","displayName":"Include invocation headers:","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_enableinvocationheader_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_enableinvocationheader_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_outputdirectory","displayName":"Transcript output directory","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath","displayName":"Set the default source path for Update-Help","description":"This policy setting allows you to set the default value of the SourcePath parameter on the Update-Help cmdlet.\r\n\r\nIf you enable this policy setting, the Update-Help cmdlet will use the specified value as the default value for the SourcePath parameter. This default value can be overridden by specifying a different value with the SourcePath parameter on the Update-Help cmdlet.\r\n\r\nIf this policy setting is disabled or not configured, this policy setting does not set a default value for the SourcePath parameter of the Update-Help cmdlet.\r\n\r\nNote: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enableupdatehelpdefaultsourcepath"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath_sourcepathforupdatehelp","displayName":"Default Source Path","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablebackuprestore_2","displayName":"Prevent restoring previous versions from backups","description":"This policy setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a local file, in which the previous version is stored on a backup.\r\n\r\nIf you enable this policy setting, the Restore button is disabled when the user selects a previous version corresponding to a backup.\r\n\r\nIf you disable this policy setting, the Restore button remains active for a previous version corresponding to a backup. If the Restore button is clicked, Windows attempts to restore the file from the backup media.\r\n\r\nIf you do not configure this policy setting, it is disabled by default. The Restore button is active when the previous version is of a local file and stored on the backup.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disablebackuprestore-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_disablebackuprestore_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablebackuprestore_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalpage_2","displayName":"Hide previous versions list for local files","description":"This policy setting lets you hide the list of previous versions of files that are on local disks. The previous versions could come from the on-disk restore points or from backup media.\r\n\r\nIf you enable this policy setting, users cannot list or restore previous versions of files on local disks.\r\n\r\nIf you disable this policy setting, users cannot list and restore previous versions of files on local disks.\r\n\r\nIf you do not configure this policy setting, it defaults to disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disablelocalpage-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalpage_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalpage_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_2","displayName":"Prevent restoring local previous versions","description":"This policy setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a local file.\r\n\r\nIf you enable this policy setting, the Restore button is disabled when the user selects a previous version corresponding to a local file.\r\n\r\nIf you disable this policy setting, the Restore button remains active for a previous version corresponding to a local file. If the user clicks the Restore button, Windows attempts to restore the file from the local disk.\r\n\r\nIf you do not configure this policy setting, it is disabled by default. The Restore button is active when the previous version is of a local file.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disablelocalrestore-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_previousversions_disableremotepage_2","displayName":"Hide previous versions list for remote files","description":"This policy setting lets you hide the list of previous versions of files that are on file shares. The previous versions come from the on-disk restore points on the file share.\r\n\r\nIf you enable this policy setting, users cannot list or restore previous versions of files on file shares.\r\n\r\nIf you disable this policy setting, users can list and restore previous versions of files on file shares.\r\n\r\nIf you do not configure this policy setting, it is disabled by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disableremotepage-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_disableremotepage_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disableremotepage_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_previousversions_disableremoterestore_2","displayName":"Prevent restoring remote previous versions","description":"This setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a file on a file share.\r\n\r\nIf you enable this policy setting, the Restore button is disabled when the user selects a previous version corresponding to a file on a file share.\r\n\r\nIf you disable this policy setting, the Restore button remains active for a previous version corresponding to a file on a file share. If the user clicks the Restore button, Windows attempts to restore the file from the file share.\r\n\r\nIf you do not configure this policy setting, it is disabled by default. The Restore button is active when the previous version is of a file on a file share.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disableremoterestore-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_disableremoterestore_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disableremoterestore_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_previousversions_hidebackupentries_2","displayName":"Hide previous versions of files on backup location","description":"This policy setting lets you hide entries in the list of previous versions of a file in which the previous version is located on backup media. Previous versions can come from the on-disk restore points or the backup media.\r\n\r\nIf you enable this policy setting, users cannot see any previous versions corresponding to backup copies, and can see only previous versions corresponding to on-disk restore points.\r\n\r\nIf you disable this policy setting, users can see previous versions corresponding to backup copies as well as previous versions corresponding to on-disk restore points.\r\n\r\nIf you do not configure this policy setting, it is disabled by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-hidebackupentries-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_hidebackupentries_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_hidebackupentries_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_allowwebprinting","displayName":"Activate Internet printing","description":"Internet printing lets you display printers on Web pages so that printers can be viewed, managed, and used across the Internet or an intranet.\r\n\r\n If you enable this policy setting, Internet printing is activated on this server.\r\n\r\n If you disable this policy setting or do not configure it, Internet printing is not activated.\r\n\r\n Internet printing is an extension of Internet Information Services (IIS). To use Internet printing, IIS must be installed, and printing support and this setting must be enabled.\r\n\r\n Note: This setting affects the server side of Internet printing only. It does not prevent the print client on the computer from printing across the Internet.\r\n\r\n Also, see the \"Custom support URL in the Printers folder's left pane\" setting in this folder and the \"Browse a common Web site to find printers\" setting in User Configuration\\Administrative Templates\\Control Panel\\Printers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-allowwebprinting"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_allowwebprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_allowwebprinting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_applicationdriverisolation","displayName":"Isolate print drivers from applications","description":"Determines if print driver components are isolated from applications instead of normally loading them into applications. Isolating print drivers greatly reduces the risk of a print driver failure causing an application crash.\r\n\r\nNot all applications support driver isolation. By default, Microsoft Excel 2007, Excel 2010, Word 2007, Word 2010 and certain other applications are configured to support it. Other applications may also be capable of isolating print drivers, depending on whether they are configured for it.\r\n\r\nIf you enable or do not configure this policy setting, then applications that are configured to support driver isolation will be isolated.\r\n\r\nIf you disable this policy setting, then print drivers will be loaded within all associated application processes.\r\n\r\nNotes:\r\n-This policy setting applies only to applications opted into isolation.\r\n-This policy setting applies only to print drivers loaded by applications. Print drivers loaded by the print spooler are not affected.\r\n-This policy setting is only checked once during the lifetime of a process. After changing the policy, a running application must be relaunched before settings take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-applicationdriverisolation"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_applicationdriverisolation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_applicationdriverisolation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_customizedsupporturl","displayName":"Custom support URL in the Printers folder's left pane","description":"By default, the Printers folder includes a link to the Microsoft Support Web page called \"Get help with printing\". It can also include a link to a Web page supplied by the vendor of the currently selected printer.\r\n\r\n If you enable this policy setting, you replace the \"Get help with printing\" default link with a link to a Web page customized for your enterprise.\r\n\r\n If you disable this setting or do not configure it, or if you do not enter an alternate Internet address, the default link will appear in the Printers folder.\r\n\r\n Note: Web pages links only appear in the Printers folder when Web view is enabled. If Web view is disabled, the setting has no effect. (To enable Web view, open the Printers folder, and, on the Tools menu, click Folder Options, click the General tab, and then click \"Enable Web content in folders.\")\r\n\r\n Also, see the \"Activate Internet printing\" setting in this setting folder and the \"Browse a common web site to find printers\" setting in User Configuration\\Administrative Templates\\Control Panel\\Printers.\r\n\r\n Web view is affected by the \"Turn on Classic Shell\" and \"Do not allow Folder Options to be opened from the Options button on the View tab of the ribbon\" settings in User Configuration\\Administrative Templates\\Windows Components\\Windows Explorer, and by the \"Enable Active Desktop\" setting in User Configuration\\Administrative Templates\\Desktop\\Active Desktop.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-customizedsupporturl"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_customizedsupporturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_customizedsupporturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_customizedsupporturl_customizedsupporturl_link","displayName":"URL","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters","displayName":"Add Printer wizard - Network scan page (Managed network)","description":"If you enable this policy setting, it sets the maximum number of printers (of each type) that the Add Printer wizard will display on a computer on a managed network (when the computer is able to reach a domain controller, e.g. a domain-joined laptop on a corporate network.)\r\n\r\n If this policy setting is disabled, the network scan page will not be displayed.\r\n\r\n If this policy setting is not configured, the Add Printer wizard will display the default number of printers of each type:\r\n Directory printers: 20\r\n TCP/IP printers: 0\r\n Web Services printers: 0\r\n Bluetooth printers: 10\r\n Shared printers: 0\r\n\r\n In order to view available Web Services printers on your network, ensure that network discovery is turned on. To turn on network discovery, click \"Start\", click \"Control Panel\", and then click \"Network and Internet\". On the \"Network and Internet\" page, click \"Network and Sharing Center\". On the Network and Sharing Center page, click \"Change advanced sharing settings\". On the Advanced sharing settings page, click the arrow next to \"Domain\" arrow, click \"turn on network discovery\", and then click \"Save changes\".\r\n\r\n If you would like to not display printers of a certain type, enable this policy and set the number of printers to display to 0.\r\n\r\n In Windows 10 and later, only TCP/IP printers can be shown in the wizard. If you enable this policy setting, only TCP/IP printer limits are applicable. On Windows 10 only, if you disable or do not configure this policy setting, the default limit is applied.\r\n \r\n In Windows 8 and later, Bluetooth printers are not shown so its limit does not apply to those versions of Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-domainprinters"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_adprinters","displayName":"Number of directory printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_bluetoothprinters","displayName":"Number of Bluetooth printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_ipprinters","displayName":"Number of TCP/IP printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_shareprinters","displayName":"Number of shared printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_wsdprinters","displayName":"Number of Web Services Printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_donotinstallcompatibledriverfromwindowsupdate","displayName":"Extend Point and Print connection to search Windows Update","description":"This policy setting allows you to manage where client computers search for Point and Printer drivers.\r\n\r\nIf you enable this policy setting, the client computer will continue to search for compatible Point and Print drivers from Windows Update after it fails to find the compatible driver from the local driver store and the server driver cache.\r\n\r\nIf you disable this policy setting, the client computer will only search the local driver store and server driver cache for compatible Point and Print drivers. If it is unable to find a compatible driver, then the Point and Print connection will fail.\r\n\r\nThis policy setting is not configured by default, and the behavior depends on the version of Windows that you are using.\r\nBy default, Windows Ultimate, Professional and Home SKUs will continue to search for compatible Point and Print drivers from Windows Update, if needed. However, you must explicitly enable this policy setting for other versions of Windows (for example Windows Enterprise, and all versions of Windows Server 2008 R2 and later) to have the same behavior.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-donotinstallcompatibledriverfromwindowsupdate"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_donotinstallcompatibledriverfromwindowsupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_donotinstallcompatibledriverfromwindowsupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_emfdespooling","displayName":"Always render print jobs on the server","description":"When printing through a print server, determines whether the print spooler on the client will process print jobs itself, or pass them on to the server to do the work.\r\n\r\nThis policy setting only effects printing to a Windows print server.\r\n\r\nIf you enable this policy setting on a client machine, the client spooler will not process print jobs before sending them to the print server. This decreases the workload on the client at the expense of increasing the load on the server.\r\n\r\nIf you disable this policy setting on a client machine, the client itself will process print jobs into printer device commands. These commands will then be sent to the print server, and the server will simply pass the commands to the printer. This increases the workload of the client while decreasing the load on the server.\r\n\r\nIf you do not enable this policy setting, the behavior is the same as disabling it.\r\n\r\nNote: This policy does not determine whether offline printing will be available to the client. The client print spooler can always queue print jobs when not connected to the print server. Upon reconnecting to the server, the client will submit any pending print jobs.\r\n\r\nNote: Some printer drivers require a custom print processor. In some cases the custom print processor may not be installed on the client machine, such as when the print server does not support transferring print processors during point-and-print. In the case of a print processor mismatch, the client spooler will always send jobs to the print server for rendering. Disabling the above policy setting does not override this behavior.\r\n\r\nNote: In cases where the client print driver does not match the server print driver (mismatched connection), the client will always process the print job, regardless of the setting of this policy.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-emfdespooling"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_emfdespooling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_emfdespooling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_forcesoftwarerasterization","displayName":"Always rasterize content to be printed using a software rasterizer","description":"Determines whether the XPS Rasterization Service or the XPS-to-GDI conversion (XGC) is forced to use a software rasterizer instead of a Graphics Processing Unit (GPU) to rasterize pages.\r\n\r\nThis setting may improve the performance of the XPS Rasterization Service or the XPS-to-GDI conversion (XGC) on machines that have a relatively powerful CPU as compared to the machine’s GPU.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-forcesoftwarerasterization"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_forcesoftwarerasterization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_forcesoftwarerasterization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_kmprintersareblocked","displayName":"Disallow installation of printers using kernel-mode drivers","description":"Determines whether printers using kernel-mode drivers may be installed on the local computer. Kernel-mode drivers have access to system-wide memory, and therefore poorly-written kernel-mode drivers can cause stop errors.\r\n\r\nIf you disable this setting, or do not configure it, then printers using a kernel-mode drivers may be installed on the local computer running Windows XP Home Edition and Windows XP Professional.\r\n\r\nIf you do not configure this setting on Windows Server 2003 family products, the installation of kernel-mode printer drivers will be blocked.\r\n\r\nIf you enable this setting, installation of a printer using a kernel-mode driver will not be allowed.\r\n\r\nNote: By applying this policy, existing kernel-mode drivers will be disabled upon installation of service packs or reinstallation of the Windows XP operating system. This policy does not apply to 64-bit kernel-mode printer drivers as they cannot be installed and associated with a print queue.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-kmprintersareblocked"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_kmprintersareblocked_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_kmprintersareblocked_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_mxdwuselegacyoutputformatmsxps","displayName":"Change Microsoft XPS Document Writer (MXDW) default output format to the legacy Microsoft XPS format (*.xps)","description":"Microsoft XPS Document Writer (MXDW) generates OpenXPS (*.oxps) files by default in %WINDOWS_CLIENT_CURRENT_VERSION%, %WINDOWS_ARM_CURRENT_VERSION% and %WINDOWS_SERVER_CURRENT_VERSION%.\r\n\r\n If you enable this group policy setting, the default MXDW output format is the legacy Microsoft XPS (*.xps).\r\n\r\n If you disable or do not configure this policy setting, the default MXDW output format is OpenXPS (*.oxps).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-mxdwuselegacyoutputformatmsxps"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_mxdwuselegacyoutputformatmsxps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_mxdwuselegacyoutputformatmsxps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters","displayName":"Add Printer wizard - Network scan page (Unmanaged network)","description":"This policy sets the maximum number of printers (of each type) that the Add Printer wizard will display on a computer on an unmanaged network (when the computer is not able to reach a domain controller, e.g. a domain-joined laptop on a home network.)\r\n\r\nIf this setting is disabled, the network scan page will not be displayed.\r\n\r\nIf this setting is not configured, the Add Printer wizard will display the default number of printers of each type:\r\nTCP/IP printers: 50\r\nWeb Services printers: 50\r\nBluetooth printers: 10\r\nShared printers: 50\r\n\r\nIf you would like to not display printers of a certain type, enable this policy and set the number of printers to display to 0.\r\n\r\nIn Windows 10 and later, only TCP/IP printers can be shown in the wizard. If you enable this policy setting, only TCP/IP printer limits are applicable. On Windows 10 only, if you disable or do not configure this policy setting, the default limit is applied.\r\n \r\nIn Windows 8 and later, Bluetooth printers are not shown so its limit does not apply to those versions of Windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-nondomainprinters"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_bluetoothprinters","displayName":"Number of Bluetooth printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_ipprinters","displayName":"Number of TCP/IP printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_shareprinters","displayName":"Number of shared printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_wsdprinters","displayName":"Number of Web Services Printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintonly_win7","displayName":"Only use Package Point and print","description":"This policy restricts clients computers to use package point and print only.\r\n\r\nIf this setting is enabled, users will only be able to point and print to printers that use package-aware drivers. When using package point and print, client computers will check the driver signature of all drivers that are downloaded from print servers.\r\n\r\nIf this setting is disabled, or not configured, users will not be restricted to package-aware point and print only.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-packagepointandprintonly-win7"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintonly_win7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintonly_win7_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintserverlist_win7","displayName":"Package Point and print - Approved servers","description":"Restricts package point and print to approved servers.\r\n\r\nThis policy setting restricts package point and print connections to approved servers. This setting only applies to Package Point and Print connections, and is completely independent from the \"Point and Print Restrictions\" policy that governs the behavior of non-package point and print connections.\r\n\r\nWindows Vista and later clients will attempt to make a non-package point and print connection anytime a package point and print connection fails, including attempts that are blocked by this policy. Administrators may need to set both policies to block all print connections to a specific print server.\r\n\r\nIf this setting is enabled, users will only be able to package point and print to print servers approved by the network administrator. When using package point and print, client computers will check the driver signature of all drivers that are downloaded from print servers.\r\n\r\nIf this setting is disabled, or not configured, package point and print will not be restricted to specific print servers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-packagepointandprintserverlist-win7"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintserverlist_win7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintserverlist_win7_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintserverlist_win7_packagepointandprintserverlist_edit","displayName":"Enter fully qualified server names","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_physicallocation","displayName":"Computer location","description":"If this policy setting is enabled, it specifies the default location criteria used when searching for printers.\r\n\r\n This setting is a component of the Location Tracking feature of Windows printers. To use this setting, enable Location Tracking by enabling the \"Pre-populate printer search location text\" setting.\r\n\r\n When Location Tracking is enabled, the system uses the specified location as a criterion when users search for printers. The value you type here overrides the actual location of the computer conducting the search.\r\n\r\n Type the location of the user's computer. When users search for printers, the system uses the specified location (and other search criteria) to find a printer nearby. You can also use this setting to direct users to a particular printer or group of printers that you want them to use.\r\n\r\n If you disable this setting or do not configure it, and the user does not type a location as a search criterion, the system searches for a nearby printer based on the IP address and subnet mask of the user's computer.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-physicallocation"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_physicallocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_physicallocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_physicallocation_physicallocation_name","displayName":"Location","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_printing_physicallocationsupport","displayName":"Pre-populate printer search location text","description":"Enables the physical Location Tracking setting for Windows printers.\r\n\r\nUse Location Tracking to design a location scheme for your enterprise and assign computers and printers to locations in the scheme. Location Tracking overrides the standard method used to locate and associate computers and printers. The standard method uses a printer's IP address and subnet mask to estimate its physical location and proximity to computers.\r\n\r\nIf you enable this setting, users can browse for printers by location without knowing the printer's location or location naming scheme. Enabling Location Tracking adds a Browse button in the Add Printer wizard's Printer Name and Sharing Location screen and to the General tab in the Printer Properties dialog box. If you enable the Group Policy Computer location setting, the default location you entered appears in the Location field by default.\r\n\r\nIf you disable this setting or do not configure it, Location Tracking is disabled. Printer proximity is estimated using the standard method (that is, based on IP address and subnet mask).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-physicallocationsupport"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_physicallocationsupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_physicallocationsupport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationexecutionpolicy","displayName":"Execute print drivers in isolated processes","description":"This policy setting determines whether the print spooler will execute print drivers in an isolated or separate process. When print drivers are loaded in an isolated process (or isolated processes), a print driver failure will not cause the print spooler service to fail.\r\n\r\nIf you enable or do not configure this policy setting, the print spooler will execute print drivers in an isolated process by default.\r\n\r\nIf you disable this policy setting, the print spooler will execute print drivers in the print spooler process.\r\n\r\n\r\nNotes:\r\n-Other system or driver policy settings may alter the process in which a print driver is executed.\r\n-This policy setting applies only to print drivers loaded by the print spooler. Print drivers loaded by applications are not affected.\r\n-This policy setting takes effect without restarting the print spooler service.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-printdriverisolationexecutionpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationoverridecompat","displayName":"Override print driver execution compatibility setting reported by print driver","description":"This policy setting determines whether the print spooler will override the Driver Isolation compatibility reported by the print driver. This enables executing print drivers in an isolated process, even if the driver does not report compatibility.\r\n\r\nIf you enable this policy setting, the print spooler isolates all print drivers that do not explicitly opt out of Driver Isolation.\r\n\r\nIf you disable or do not configure this policy setting, the print spooler uses the Driver Isolation compatibility flag value reported by the print driver.\r\n\r\nNotes:\r\n-Other system or driver policy settings may alter the process in which a print driver is executed.\r\n-This policy setting applies only to print drivers loaded by the print spooler. Print drivers loaded by applications are not affected.\r\n-This policy setting takes effect without restarting the print spooler service.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-printdriverisolationoverridecompat"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationoverridecompat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationoverridecompat_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_printerserverthread","displayName":"Printer browsing","description":"Announces the presence of shared printers to print browse master servers for the domain.\r\n\r\nOn domains with Active Directory, shared printer resources are available in Active Directory and are not announced.\r\n\r\nIf you enable this setting, the print spooler announces shared printers to the print browse master servers.\r\n\r\nIf you disable this setting, shared printers are not announced to print browse master servers, even if Active Directory is not available.\r\n\r\nIf you do not configure this setting, shared printers are announced to browse master servers only when Active Directory is not available.\r\n\r\nNote: A client license is used each time a client computer announces a printer to a print browse master on the domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-printerserverthread"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_printerserverthread_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_printerserverthread_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_showjobtitleineventlogs","displayName":"Allow job name in event logs","description":"\r\n This policy controls whether the print job name will be included in print event logs.\r\n\r\n If you disable or do not configure this policy setting, the print job name will not be included.\r\n\r\n If you enable this policy setting, the print job name will be included in new log entries.\r\n\r\n Note: This setting does not apply to Branch Office Direct Printing jobs.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-showjobtitleineventlogs"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_showjobtitleineventlogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_showjobtitleineventlogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing_v4driverdisallowprinterextension","displayName":"Do not allow v4 printer drivers to show printer extensions","description":"This policy determines if v4 printer drivers are allowed to run printer extensions.\r\n\r\n V4 printer drivers may include an optional, customized user interface known as a printer extension. These extensions may provide access to more device features, but this may not be appropriate for all enterprises.\r\n\r\n If you enable this policy setting, then all printer extensions will not be allowed to run.\r\n\r\n If you disable this policy setting or do not configure it, then all printer extensions that have been installed will be allowed to run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-v4driverdisallowprinterextension"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_v4driverdisallowprinterextension_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_v4driverdisallowprinterextension_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_autopublishing","displayName":"Automatically publish new printers in Active Directory","description":"Determines whether the Add Printer Wizard automatically publishes the computer's shared printers in Active Directory.\r\n\r\n If you enable this setting or do not configure it, the Add Printer Wizard automatically publishes all shared printers.\r\n\r\n If you disable this setting, the Add Printer Wizard does not automatically publish printers. However, you can publish shared printers manually.\r\n\r\n The default behavior is to automatically publish shared printers in Active Directory.\r\n\r\n Note: This setting is ignored if the \"Allow printers to be published\" setting is disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-autopublishing"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_autopublishing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_autopublishing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_immortalprintqueue","displayName":"Allow pruning of published printers","description":"Determines whether the domain controller can prune (delete from Active Directory) the printers published by this computer.\r\n\r\n By default, the pruning service on the domain controller prunes printer objects from Active Directory if the computer that published them does not respond to contact requests. When the computer that published the printers restarts, it republishes any deleted printer objects.\r\n\r\n If you enable this setting or do not configure it, the domain controller prunes this computer's printers when the computer does not respond.\r\n\r\n If you disable this setting, the domain controller does not prune this computer's printers. This setting is designed to prevent printers from being pruned when the computer is temporarily disconnected from the network.\r\n\r\n Note: You can use the \"Directory Pruning Interval\" and \"Directory Pruning Retry\" settings to adjust the contact interval and number of contact attempts.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-immortalprintqueue"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_immortalprintqueue_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_immortalprintqueue_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel","displayName":"Prune printers that are not automatically republished","description":"Determines whether the pruning service on a domain controller prunes printer objects that are not automatically republished whenever the host computer does not respond,just as it does with Windows 2000 printers. This setting applies to printers running operating systems other than Windows 2000 and to Windows 2000 printers published outside their forest.\r\n\r\n The Windows pruning service prunes printer objects from Active Directory when the computer that published them does not respond to contact requests. Computers running Windows 2000 Professional detect and republish deleted printer objects when they rejoin the network. However, because non-Windows 2000 computers and computers in other domains cannot republish printers in Active Directory automatically, by default, the system never prunes their printer objects.\r\n\r\n You can enable this setting to change the default behavior. To use this setting, select one of the following options from the \"Prune non-republishing printers\" box:\r\n\r\n -- \"Never\" specifies that printer objects that are not automatically republished are never pruned. \"Never\" is the default.\r\n\r\n -- \"Only if Print Server is found\" prunes printer objects that are not automatically republished only when the print server responds, but the printer is unavailable.\r\n\r\n -- \"Whenever printer is not found\" prunes printer objects that are not automatically republished whenever the host computer does not respond, just as it does with Windows 2000 printers.\r\n\r\n Note: This setting applies to printers published by using Active Directory Users and Computers or Pubprn.vbs. It does not apply to printers published by using Printers in Control Panel.\r\n\r\n Tip: If you disable automatic pruning, remember to delete printer objects manually whenever you remove a printer or print server.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-prunedownlevel"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle","displayName":"Prune non-republishing printers:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle_1","displayName":"Only if Print Server is found","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle_2","displayName":"Whenever printer is not found","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval","displayName":"Directory pruning interval","description":"Specifies how often the pruning service on a domain controller contacts computers to verify that their printers are operational.\r\n\r\n The pruning service periodically contacts computers that have published printers. If a computer does not respond to the contact message (optionally, after repeated attempts), the pruning service \"prunes\" (deletes from Active Directory) printer objects the computer has published.\r\n\r\n By default, the pruning service contacts computers every eight hours and allows two repeated contact attempts before deleting printers from Active Directory.\r\n\r\n If you enable this setting, you can change the interval between contact attempts.\r\n\r\n If you do not configure or disable this setting the default values will be used.\r\n\r\n Note: This setting is used only on domain controllers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-pruninginterval"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle","displayName":"Interval:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_0","displayName":"Continuous","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_10","displayName":"10 Minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_30","displayName":"30 Minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_60","displayName":"1 Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_240","displayName":"4 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_480","displayName":"8 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_720","displayName":"12 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_1440","displayName":"1 Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_2880","displayName":"2 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_4320","displayName":"3 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_5760","displayName":"4 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_7200","displayName":"5 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_8640","displayName":"6 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_10080","displayName":"1 Week","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_20160","displayName":"2 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_30240","displayName":"3 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_40320","displayName":"4 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_50400","displayName":"5 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_60480","displayName":"6 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_70560","displayName":"7 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_4294967295","displayName":"Infinite","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority","displayName":"Directory pruning priority","description":"Sets the priority of the pruning thread.\r\n\r\n The pruning thread, which runs only on domain controllers, deletes printer objects from Active Directory if the printer that published the object does not respond to contact attempts. This process keeps printer information in Active Directory current.\r\n\r\n The thread priority influences the order in which the thread receives processor time and determines how likely it is to be preempted by higher priority threads.\r\n\r\n By default, the pruning thread runs at normal priority. However, you can adjust the priority to improve the performance of this service.\r\n\r\n Note: This setting is used only on domain controllers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-pruningpriority"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_prioritylevel","displayName":"Priority level:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_prioritylevel_4294967294","displayName":"Lowest","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_prioritylevel_4294967295","displayName":"Below Normal","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_prioritylevel_0","displayName":"Normal","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_prioritylevel_1","displayName":"Above Normal","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningpriority_prioritylevel_2","displayName":"Highest","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries","displayName":"Directory pruning retry","description":"Specifies how many times the pruning service on a domain controller repeats its attempt to contact a computer before pruning the computer's printers.\r\n\r\n The pruning service periodically contacts computers that have published printers to verify that the printers are still available for use. If a computer does not respond to the contact message, the message is repeated for the specified number of times. If the computer still fails to respond, then the pruning service \"prunes\" (deletes from Active Directory) printer objects the computer has published.\r\n\r\n By default, the pruning service contacts computers every eight hours and allows two retries before deleting printers from Active Directory. You can use this setting to change the number of retries.\r\n\r\n If you enable this setting, you can change the interval between attempts.\r\n\r\n If you do not configure or disable this setting, the default values are used.\r\n\r\n Note: This setting is used only on domain controllers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-pruningretries"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle","displayName":"Retries:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_0","displayName":"No Retry","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_1","displayName":"1 Retry","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_2","displayName":"2 Retries","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_3","displayName":"3 Retries","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_4","displayName":"4 Retries","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_5","displayName":"5 Retries","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretries_pruningretriestitle_6","displayName":"6 Retries","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretrylog","displayName":"Log directory pruning retry events","description":"Specifies whether or not to log events when the pruning service on a domain controller attempts to contact a computer before pruning the computer's printers.\r\n\r\n The pruning service periodically contacts computers that have published printers to verify that the printers are still available for use. If a computer does not respond to the contact attempt, the attempt is retried a specified number of times, at a specified interval. The \"Directory pruning retry\" setting determines the number of times the attempt is retried; the default value is two retries. The \"Directory Pruning Interval\" setting determines the time interval between retries; the default value is every eight hours. If the computer has not responded by the last contact attempt, its printers are pruned from the directory.\r\n\r\n If you enable this policy setting, the contact events are recorded in the event log.\r\n\r\n If you disable or do not configure this policy setting, the contact events are not recorded in the event log.\r\n\r\n Note: This setting does not affect the logging of pruning events; the actual pruning of a printer is always logged.\r\n\r\n Note: This setting is used only on domain controllers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-pruningretrylog"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretrylog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruningretrylog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_registerspoolerremoterpcendpoint","displayName":"Allow Print Spooler to accept client connections","description":"This policy controls whether the print spooler will accept client connections.\r\n\r\nWhen the policy is unconfigured or enabled, the spooler will always accept client connections.\r\n\r\nWhen the policy is disabled, the spooler will not accept client connections nor allow users to share printers. All printers currently shared will continue to be shared.\r\n\r\nThe spooler must be restarted for changes to this policy to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-registerspoolerremoterpcendpoint"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_registerspoolerremoterpcendpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_registerspoolerremoterpcendpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate","displayName":"Check published state","description":"Directs the system to periodically verify that the printers published by this computer still appear in Active Directory. This setting also specifies how often the system repeats the verification.\r\n\r\n By default, the system only verifies published printers at startup. This setting allows for periodic verification while the computer is operating.\r\n\r\n To enable this additional verification, enable this setting, and then select a verification interval.\r\n\r\n To disable verification, disable this setting, or enable this setting and select \"Never\" for the verification interval.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-verifypublishedstate"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle","displayName":"Published State Check Interval:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_30","displayName":"30 Minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_60","displayName":"1 Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_240","displayName":"4 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_480","displayName":"8 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_720","displayName":"12 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_1440","displayName":"1 Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_4294967295","displayName":"Never","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_pushtoinstall_disablepushtoinstall","displayName":"Turn off Push To Install service","description":"If you enable this setting, users will not be able to push Apps to this device from the Microsoft Store running on other devices or the web.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pushtoinstall#admx-pushtoinstall-disablepushtoinstall"],"categoryId":"05305a87-0b19-41bb-bf1e-0bd92bfcdc16","categoryName":"Push To Install","options":[{"id":"device_vendor_msft_policy_config_admx_pushtoinstall_disablepushtoinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pushtoinstall_disablepushtoinstall_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosmaxoutstandingsends","displayName":"Limit outstanding packets","description":"Specifies the maximum number of outstanding packets permitted on the system. When the number of outstanding packets reaches this limit, the Packet Scheduler postpones all submissions to network adapters until the number falls below this limit.\r\n\r\n\"Outstanding packets\" are packets that the Packet Scheduler has submitted to a network adapter for transmission, but which have not yet been sent.\r\n\r\nIf you enable this setting, you can limit the number of outstanding packets.\r\n\r\nIf you disable this setting or do not configure it, then the setting has no effect on the system.\r\n\r\nImportant: If the maximum number of outstanding packets is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosmaxoutstandingsends"],"categoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","categoryName":"Qo S Packet Scheduler","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosmaxoutstandingsends_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosmaxoutstandingsends_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosmaxoutstandingsends_qosmaxoutstandingsends_box","displayName":"Number of packets:","description":null,"helpText":"","infoUrls":[],"categoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","categoryName":"Qo S Packet Scheduler","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosnonbesteffortlimit","displayName":"Limit reservable bandwidth","description":"Determines the percentage of connection bandwidth that the system can reserve. This value limits the combined bandwidth reservations of all programs running on the system.\r\n\r\nBy default, the Packet Scheduler limits the system to 80 percent of the bandwidth of a connection, but you can use this setting to override the default.\r\n\r\nIf you enable this setting, you can use the \"Bandwidth limit\" box to adjust the amount of bandwidth the system can reserve.\r\n\r\nIf you disable this setting or do not configure it, the system uses the default value of 80 percent of the connection.\r\n\r\nImportant: If a bandwidth limit is set for a particular network adapter in the registry, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosnonbesteffortlimit"],"categoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","categoryName":"Qo S Packet Scheduler","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosnonbesteffortlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosnonbesteffortlimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosnonbesteffortlimit_qosnonbesteffortlimit_box","displayName":"Bandwidth limit (%):","description":null,"helpText":"","infoUrls":[],"categoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","categoryName":"Qo S Packet Scheduler","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c","displayName":"Best effort service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Best Effort service type (ServiceTypeBestEffort). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Best Effort service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypebesteffort-c"],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_nc","displayName":"Best effort service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Best Effort service type (ServiceTypeBestEffort). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that do not conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Best Effort service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypebesteffort-nc"],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_nc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_nc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv","displayName":"Best effort service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Best Effort service type (ServiceTypeBestEffort). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Best Effort service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypebesteffort-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_c","displayName":"Controlled load service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Controlled Load service type (ServiceTypeControlledLoad). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Controlled Load service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 24 (0x18).\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypecontrolledload-c"],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_c_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_c_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_nc","displayName":"Controlled load service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Controlled Load service type (ServiceTypeControlledLoad). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that do not conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Controlled Load service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypecontrolledload-nc"],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_nc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_nc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_pv","displayName":"Controlled load service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Controlled Load service type (ServiceTypeControlledLoad). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Controlled Load service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypecontrolledload-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_pv_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_c","displayName":"Guaranteed service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Guaranteed service type (ServiceTypeGuaranteed). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Guaranteed service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 40 (0x28).\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypeguaranteed-c"],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_c_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_c_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc","displayName":"Guaranteed service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Guaranteed service type (ServiceTypeGuaranteed). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that do not conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Guaranteed service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypeguaranteed-nc"],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv","displayName":"Guaranteed service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Guaranteed service type (ServiceTypeGuaranteed). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Guaranteed service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypeguaranteed-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_c","displayName":"Network control service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Network Control service type (ServiceTypeNetworkControl). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Network Control service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 48 (0x30).\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypenetworkcontrol-c"],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_c_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_c_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_nc","displayName":"Network control service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Network Control service type (ServiceTypeNetworkControl). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that do not conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Network Control service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypenetworkcontrol-nc"],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_nc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_nc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_pv","displayName":"Network control service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Network Control service type (ServiceTypeNetworkControl). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Network Control service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypenetworkcontrol-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_pv_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenetworkcontrol_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenonconforming","displayName":"Non-conforming packets","description":"Specifies an alternate link layer (Layer-2) priority value for packets that do not conform to the flow specification. The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with nonconforming packets.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for nonconforming packets is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypenonconforming"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenonconforming_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenonconforming_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenonconforming_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_c","displayName":"Qualitative service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Qualitative service type (ServiceTypeQualitative). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Qualitative service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypequalitative-c"],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_c_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_c_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_nc","displayName":"Qualitative service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Qualitative service type (ServiceTypeQualitative). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that do not conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Qualitative service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypequalitative-nc"],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_nc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_nc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv","displayName":"Qualitative service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Qualitative service type (ServiceTypeQualitative). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Qualitative service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypequalitative-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},{"id":"device_vendor_msft_policy_config_admx_qos_qostimerresolution","displayName":"Set timer resolution","description":"Determines the smallest unit of time that the Packet Scheduler uses when scheduling packets for transmission. The Packet Scheduler cannot schedule packets for transmission more frequently than permitted by the value of this entry.\r\n\r\nIf you enable this setting, you can override the default timer resolution established for the system, usually units of 10 microseconds.\r\n\r\nIf you disable this setting or do not configure it, the setting has no effect on the system.\r\n\r\nImportant: If a timer resolution is specified in the registry for a particular network adapter, then this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qostimerresolution"],"categoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","categoryName":"Qo S Packet Scheduler","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qostimerresolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qostimerresolution_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_qos_qostimerresolution_qostimerresolution_box","displayName":"Timer units (in microseconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","categoryName":"Qo S Packet Scheduler","options":null},{"id":"device_vendor_msft_policy_config_admx_radar_wdiscenarioexecutionpolicy","displayName":"Configure Scenario Execution Level","description":"Determines the execution level for Windows Resource Exhaustion Detection and Resolution.\r\n\r\nIf you enable this policy setting, you must select an execution level from the dropdown menu. If you select problem detection and troubleshooting only, the Diagnostic Policy Service (DPS) will detect Windows Resource Exhaustion problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will detect Windows Resource Exhaustion problems and indicate to the user that assisted resolution is available.\r\n\r\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve any Windows Resource Exhaustion problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS will enable Windows Resource Exhaustion for resolution by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo system restart or service restart is required for this policy to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-radar#admx-radar-wdiscenarioexecutionpolicy"],"categoryId":"ffd1a98f-0fac-47fe-813f-7510d0dacbc3","categoryName":"Windows Resource Exhaustion Detection and Resolution","options":[{"id":"device_vendor_msft_policy_config_admx_radar_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_radar_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_radar_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"ffd1a98f-0fac-47fe-813f-7510d0dacbc3","categoryName":"Windows Resource Exhaustion Detection and Resolution","options":[{"id":"device_vendor_msft_policy_config_admx_radar_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_radar_wdiscenarioexecutionpolicy_wdiscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_reliability_ee_enablepersistenttimestamp","displayName":"Enable Persistent Time Stamp","description":"This policy setting allows the system to detect the time of unexpected shutdowns by writing the current time to disk on a schedule controlled by the Timestamp Interval.\r\n\r\nIf you enable this policy setting, you are able to specify how often the Persistent System Timestamp is refreshed and subsequently written to the disk. You can specify the Timestamp Interval in seconds.\r\n\r\nIf you disable this policy setting, the Persistent System Timestamp is turned off and the timing of unexpected shutdowns is not recorded.\r\n\r\nIf you do not configure this policy setting, the Persistent System Timestamp is refreshed according the default, which is every 60 seconds beginning with Windows Server 2003.\r\n\r\nNote: This feature might interfere with power configuration settings that turn off hard disks after a period of inactivity. These power settings may be accessed in the Power Options Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-reliability#admx-reliability-ee-enablepersistenttimestamp"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_reliability_ee_enablepersistenttimestamp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_reliability_ee_enablepersistenttimestamp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_reliability_ee_enablepersistenttimestamp_ee_enablepersistenttimestamp_desc4","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_reliability_pch_reportshutdownevents","displayName":"Report unplanned shutdown events","description":"This policy setting controls whether or not unplanned shutdown events can be reported when error reporting is enabled.\r\n\r\nIf you enable this policy setting, error reporting includes unplanned shutdown events.\r\n\r\nIf you disable this policy setting, unplanned shutdown events are not included in error reporting.\r\n\r\nIf you do not configure this policy setting, users can adjust this setting using the control panel, which is set to \"Upload unplanned shutdown events\" by default.\r\n\r\nAlso see the \"Configure Error Reporting\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-reliability#admx-reliability-pch-reportshutdownevents"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_reliability_pch_reportshutdownevents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_reliability_pch_reportshutdownevents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdowneventtrackerstatefile","displayName":"Activate Shutdown Event Tracker System State Data feature","description":"This policy setting defines when the Shutdown Event Tracker System State Data feature is activated.\r\n\r\nThe system state data file contains information about the basic system state as well as the state of all running processes.\r\n\r\nIf you enable this policy setting, the System State Data feature is activated when the user indicates that the shutdown or restart is unplanned.\r\n\r\nIf you disable this policy setting, the System State Data feature is never activated.\r\n\r\nIf you do not configure this policy setting, the default behavior for the System State Data feature occurs.\r\n\r\nNote: By default, the System State Data feature is always enabled on Windows Server 2003. See \"Supported on\" for all supported versions.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-reliability#admx-reliability-shutdowneventtrackerstatefile"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_reliability_shutdowneventtrackerstatefile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdowneventtrackerstatefile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason","displayName":"Display Shutdown Event Tracker","description":"The Shutdown Event Tracker can be displayed when you shut down a workstation or server. This is an extra set of questions that is displayed when you invoke a shutdown to collect information related to why you are shutting down the computer.\r\n\r\nIf you enable this setting and choose \"Always\" from the drop-down menu list, the Shutdown Event Tracker is displayed when the computer shuts down.\r\n\r\nIf you enable this policy setting and choose \"Server Only\" from the drop-down menu list, the Shutdown Event Tracker is displayed when you shut down a computer running Windows Server. (See \"Supported on\" for supported versions.)\r\n\r\nIf you enable this policy setting and choose \"Workstation Only\" from the drop-down menu list, the Shutdown Event Tracker is displayed when you shut down a computer running a client version of Windows. (See \"Supported on\" for supported versions.)\r\n\r\nIf you disable this policy setting, the Shutdown Event Tracker is not displayed when you shut down the computer.\r\n\r\nIf you do not configure this policy setting, the default behavior for the Shutdown Event Tracker occurs.\r\n\r\nNote: By default, the Shutdown Event Tracker is only displayed on computers running Windows Server.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-reliability#admx-reliability-shutdownreason"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason_shutdownreason_box","displayName":"Shutdown Event Tracker should be displayed:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason_shutdownreason_box_1","displayName":"Always","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason_shutdownreason_box_2","displayName":"Workstation Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_reliability_shutdownreason_shutdownreason_box_3","displayName":"Server Only","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_encryptedticketonly","displayName":"Allow only Windows Vista or later connections","description":"This policy setting enables Remote Assistance invitations to be generated with improved encryption so that only computers running this version (or later versions) of the operating system can connect. This policy setting does not affect Remote Assistance connections that are initiated by instant messaging contacts or the unsolicited Offer Remote Assistance.\r\n\r\nIf you enable this policy setting, only computers running this version (or later versions) of the operating system can connect to this computer.\r\n\r\nIf you disable this policy setting, computers running this version and a previous version of the operating system can connect to this computer.\r\n\r\nIf you do not configure this policy setting, users can configure the setting in System Properties in the Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-remoteassistance#admx-remoteassistance-ra-encryptedticketonly"],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_encryptedticketonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_encryptedticketonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth","displayName":"Turn on bandwidth optimization","description":"This policy setting allows you to improve performance in low bandwidth scenarios.\r\n\r\nThis setting is incrementally scaled from \"No optimization\" to \"Full optimization\". Each incremental setting includes the previous optimization setting.\r\n\r\nFor example:\r\n\r\n\"Turn off background\" will include the following optimizations:\r\n-No full window drag\r\n-Turn off background\r\n\r\n\"Full optimization\" will include the following optimizations:\r\n-Use 16-bit color (8-bit color in Windows Vista)\r\n-Turn off font smoothing (not supported in Windows Vista)\r\n-No full window drag\r\n-Turn off background\r\n\r\nIf you enable this policy setting, bandwidth optimization occurs at the level specified.\r\n\r\nIf you disable this policy setting, application-based settings are used.\r\n\r\nIf you do not configure this policy setting, application-based settings are used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-remoteassistance#admx-remoteassistance-ra-optimize-bandwidth"],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_ra_optimize_bandwidth_list","displayName":"Optimize settings for reduced bandwidth:","description":null,"helpText":"","infoUrls":[],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_ra_optimize_bandwidth_list_14","displayName":"No optimization","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_ra_optimize_bandwidth_list_12","displayName":"No full window drag","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_ra_optimize_bandwidth_list_8","displayName":"Turn off background","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_ra_optimize_bandwidth_list_0","displayName":"Full optimization","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_accessrights_reboottime_2","displayName":"Set time (in seconds) to force reboot","description":"This policy setting configures the amount of time (in seconds) that the operating system waits to reboot in order to enforce a change in access rights to removable storage devices.\r\n\r\nIf you enable this policy setting, you can set the number of seconds you want the system to wait until a reboot.\r\n\r\nIf you disable or do not configure this setting, the operating system does not force a reboot.\r\n\r\nNote: If no reboot is forced, the access right does not take effect until the operating system is restarted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-accessrights-reboottime-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_accessrights_reboottime_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_accessrights_reboottime_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_accessrights_reboottime_2_accessrights_reboottime_seconds","displayName":"Time (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyexecute_access_2","displayName":"CD and DVD: Deny execute access","description":"This policy setting denies execute access to the CD and DVD removable storage class.\r\n\r\nIf you enable this policy setting, execute access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, execute access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-cdanddvd-denyexecute-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyexecute_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyexecute_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyread_access_2","displayName":"CD and DVD: Deny read access","description":"This policy setting denies read access to the CD and DVD removable storage class.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-cdanddvd-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denywrite_access_2","displayName":"CD and DVD: Deny write access","description":"This policy setting denies write access to the CD and DVD removable storage class.\r\n\r\nIf you enable this policy setting, write access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-cdanddvd-denywrite-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denywrite_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denywrite_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_2","displayName":"Custom Classes: Deny read access","description":"This policy setting denies read access to custom removable storage classes.\r\n\r\nIf you enable this policy setting, read access is denied to these removable storage classes.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to these removable storage classes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-customclasses-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_2_customclasses_list","displayName":"GUID for custom removable storage class:","description":null,"helpText":"","infoUrls":[],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_2","displayName":"Custom Classes: Deny write access","description":"This policy setting denies write access to custom removable storage classes.\r\n\r\nIf you enable this policy setting, write access is denied to these removable storage classes.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to these removable storage classes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-customclasses-denywrite-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_2_customclasses_list","displayName":"GUID for custom removable storage class:","description":null,"helpText":"","infoUrls":[],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyexecute_access_2","displayName":"Floppy Drives: Deny execute access","description":"This policy setting denies execute access to the Floppy Drives removable storage class, including USB Floppy Drives.\r\n\r\nIf you enable this policy setting, execute access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, execute access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-floppydrives-denyexecute-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyexecute_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyexecute_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_2","displayName":"Floppy Drives: Deny read access","description":"This policy setting denies read access to the Floppy Drives removable storage class, including USB Floppy Drives.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-floppydrives-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denywrite_access_2","displayName":"Floppy Drives: Deny write access","description":"This policy setting denies write access to the Floppy Drives removable storage class, including USB Floppy Drives.\r\n\r\nIf you enable this policy setting, write access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-floppydrives-denywrite-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denywrite_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denywrite_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removable_remote_allow_access","displayName":"All Removable Storage: Allow direct access in remote sessions","description":"This policy setting grants normal users direct access to removable storage devices in remote sessions.\r\n\r\nIf you enable this policy setting, remote users can open direct handles to removable storage devices in remote sessions.\r\n\r\nIf you disable or do not configure this policy setting, remote users cannot open direct handles to removable storage devices in remote sessions.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-removable-remote-allow-access"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_removable_remote_allow_access_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removable_remote_allow_access_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyexecute_access_2","displayName":"Removable Disks: Deny execute access","description":"This policy setting denies execute access to removable disks.\r\n\r\nIf you enable this policy setting, execute access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, execute access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-removabledisks-denyexecute-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyexecute_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyexecute_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyread_access_2","displayName":"Removable Disks: Deny read access","description":"This policy setting denies read access to removable disks.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-removabledisks-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removablestorageclasses_denyall_access_2","displayName":"All Removable Storage classes: Deny all access","description":"Configure access to all removable storage classes.\r\n\r\nThis policy setting takes precedence over any individual removable storage policy settings. To manage individual classes, use the policy settings available for each class.\r\n\r\nIf you enable this policy setting, no access is allowed to any removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write and read accesses are allowed to all removable storage classes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-removablestorageclasses-denyall-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_removablestorageclasses_denyall_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removablestorageclasses_denyall_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denyexecute_access_2","displayName":"Tape Drives: Deny execute access","description":"This policy setting denies execute access to the Tape Drive removable storage class.\r\n\r\nIf you enable this policy setting, execute access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, execute access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-tapedrives-denyexecute-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denyexecute_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denyexecute_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denyread_access_2","displayName":"Tape Drives: Deny read access","description":"This policy setting denies read access to the Tape Drive removable storage class.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-tapedrives-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_2","displayName":"Tape Drives: Deny write access","description":"This policy setting denies write access to the Tape Drive removable storage class.\r\n\r\nIf you enable this policy setting, write access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-tapedrives-denywrite-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_wpddevices_denyread_access_2","displayName":"WPD Devices: Deny read access","description":"This policy setting denies read access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-wpddevices-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_wpddevices_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_wpddevices_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_removablestorage_wpddevices_denywrite_access_2","displayName":"WPD Devices: Deny write access","description":"This policy setting denies write access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices.\r\n\r\nIf you enable this policy setting, write access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-wpddevices-denywrite-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_wpddevices_denywrite_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_wpddevices_denywrite_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation","displayName":"Propagate extended error information","description":"This policy setting controls whether the RPC runtime generates extended error information when an error occurs.\r\n\r\nExtended error information includes the local time that the error occurred, the RPC version, and the name of the computer on which the error occurred, or from which it was propagated. Programs can retrieve the extended error information by using standard Windows application programming interfaces (APIs).\r\n\r\nIf you disable this policy setting, the RPC Runtime only generates a status code to indicate an error condition.\r\n\r\nIf you do not configure this policy setting, it remains disabled. It will only generate a status code to indicate an error condition.\r\n\r\nIf you enable this policy setting, the RPC runtime will generate extended error information. You must select an error response type in the drop-down box.\r\n\r\n-- \"Off\" disables all extended error information for all processes. RPC only generates an error code.\r\n\r\n-- \"On with Exceptions\" enables extended error information, but lets you disable it for selected processes. To disable extended error information for a process while this policy setting is in effect, the command that starts the process must begin with one of the strings in the Extended Error Information Exception field.\r\n\r\n-- \"Off with Exceptions\" disables extended error information, but lets you enable it for selected processes. To enable extended error information for a process while this policy setting is in effect, the command that starts the process must begin with one of the strings in the Extended Error Information Exception field.\r\n\r\n-- \"On\" enables extended error information for all processes.\r\n\r\nNote: For information about the Extended Error Information Exception field, see the Windows Software Development Kit (SDK).\r\n\r\nNote: Extended error information is formatted to be compatible with other operating systems and older Microsoft operating systems, but only newer Microsoft operating systems can read and respond to the information.\r\n\r\nNote: The default policy setting, \"Off,\" is designed for systems where extended error information is considered to be sensitive, and it should not be made available remotely.\r\n\r\nNote: This policy setting will not be applied until the system is rebooted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-rpc#admx-rpc-rpcextendederrorinformation"],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_rpcextendederrorinformationlist","displayName":"Propagation of extended error information:","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_rpcextendederrorinformationlist_0","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_rpcextendederrorinformationlist_1","displayName":"On with Exceptions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_rpcextendederrorinformationlist_2","displayName":"Off with Exceptions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_rpcextendederrorinformationlist_3","displayName":"On","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcextendederrorinformation_rpcexterrorexceptions","displayName":"Extended Error Information Exceptions:","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure","displayName":"Ignore Delegation Failure","description":"This policy setting controls whether the RPC Runtime ignores delegation failures when delegation is requested.\r\n\r\nThe constrained delegation model, introduced in Windows Server 2003, does not report that delegation was enabled on a security context when a client connects to a server. Callers of RPC and COM are encouraged to use the RPC_C_QOS_CAPABILITIES_IGNORE_DELEGATE_FAILURE flag, but some applications written for the traditional delegation model prior to Windows Server 2003 may not use this flag and will encounter RPC_S_SEC_PKG_ERROR when connecting to a server that uses constrained delegation.\r\n\r\nIf you disable this policy setting, the RPC Runtime will generate RPC_S_SEC_PKG_ERROR errors to applications that ask for delegation and connect to servers using constrained delegation. \r\n\r\nIf you do not configure this policy setting, it remains disabled and will generate RPC_S_SEC_PKG_ERROR errors to applications that ask for delegation and connect to servers using constrained delegation. \r\n\r\nIf you enable this policy setting, then:\r\n\r\n-- \"Off\" directs the RPC Runtime to generate RPC_S_SEC_PKG_ERROR if the client asks for delegation, but the created security context does not support delegation.\r\n\r\n-- \"On\" directs the RPC Runtime to accept security contexts that do not support delegation even if delegation was asked for.\r\n\r\nNote: This policy setting will not be applied until the system is rebooted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-rpc#admx-rpc-rpcignoredelegationfailure"],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_rpcignoredelegationfailurelist","displayName":"Ignoring Delegation Failure:","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_rpcignoredelegationfailurelist_0","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_rpcignoredelegationfailurelist_1","displayName":"On","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcminimumhttpconnectiontimeout","displayName":"Set Minimum Idle Connection Timeout for RPC/HTTP connections","description":"This policy setting controls the idle connection timeout for RPC/HTTP connections. \r\n\r\nThis policy setting is useful in cases where a network agent like an HTTP proxy or a router uses a lower idle connection timeout than the IIS server running the RPC/HTTP proxy. In such cases, RPC/HTTP clients may encounter errors because connections will be timed out faster than expected. Using this policy setting you can force the RPC Runtime and the RPC/HTTP Proxy to use a lower connection timeout.\r\n\r\nThis policy setting is only applicable when the RPC Client, the RPC Server and the RPC HTTP Proxy are all running Windows Server 2003 family/Windows XP SP1 or higher versions. If either the RPC Client or the RPC Server or the RPC HTTP Proxy run on an older version of Windows, this policy setting will be ignored.\r\n\r\nThe minimum allowed value for this policy setting is 90 seconds. The maximum is 7200 seconds (2 hours).\r\n\r\nIf you disable this policy setting, the idle connection timeout on the IIS server running the RPC HTTP proxy will be used.\r\n\r\nIf you do not configure this policy setting, it will remain disabled. The idle connection timeout on the IIS server running the RPC HTTP proxy will be used.\r\n\r\nIf you enable this policy setting, and the IIS server running the RPC HTTP proxy is configured with a lower idle connection timeout, the timeout on the IIS server is used. Otherwise, the provided timeout value is used. The timeout is given in seconds.\r\n\r\nNote: This policy setting will not be applied until the system is rebooted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-rpc#admx-rpc-rpcminimumhttpconnectiontimeout"],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcminimumhttpconnectiontimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcminimumhttpconnectiontimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcminimumhttpconnectiontimeout_rpcminimumhttpconnectiontimeoutvalue","displayName":"Minimum Idle Connection Timeout (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation","displayName":"Maintain RPC Troubleshooting State Information","description":"This policy setting determines whether the RPC Runtime maintains RPC state information for the system, and how much information it maintains. Basic state information, which consists only of the most commonly needed state data, is required for troubleshooting RPC problems.\r\n\r\nIf you disable this policy setting, the RPC runtime defaults to \"Auto2\" level.\r\n\r\nIf you do not configure this policy setting, the RPC defaults to \"Auto2\" level. \r\n\r\nIf you enable this policy setting, you can use the drop-down box to determine which systems maintain RPC state information.\r\n\r\n-- \"None\" indicates that the system does not maintain any RPC state information. Note: Because the basic state information required for troubleshooting has a negligible effect on performance and uses only about 4K of memory, this setting is not recommended for most installations.\r\n\r\n-- \"Auto1\" directs RPC to maintain basic state information only if the computer has at least 64 MB of memory.\r\n\r\n-- \"Auto2\" directs RPC to maintain basic state information only if the computer has at least 128 MB of memory and is running Windows 2000 Server, Windows 2000 Advanced Server, or Windows 2000 Datacenter Server. \r\n\r\n-- \"Server\" directs RPC to maintain basic state information on the computer, regardless of its capacity.\r\n\r\n-- \"Full\" directs RPC to maintain complete RPC state information on the system, regardless of its capacity. Because this level can degrade performance, it is recommended for use only while you are investigating an RPC problem.\r\n\r\nNote: To retrieve the RPC state information from a system that maintains it, you must use a debugging tool.\r\n\r\nNote: This policy setting will not be applied until the system is rebooted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-rpc#admx-rpc-rpcstateinformation"],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist","displayName":"RPC Runtime state information to maintain:","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_0","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_1","displayName":"Auto1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_2","displayName":"Auto2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_3","displayName":"Server","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_4","displayName":"Full","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation","displayName":"Configure validation of ROCA-vulnerable WHfB keys during authentication","description":"This policy setting allows you to configure how domain controllers handle Windows Hello for Business (WHfB) keys that are vulnerable to the \"Return of Coppersmith's attack\" (ROCA) vulnerability.\n\nFor more information on the ROCA vulnerability, please see:\n\nhttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15361\n\nhttps://en.wikipedia.org/wiki/ROCA_vulnerability\n\nIf you enable this policy setting the following options are supported:\n\nIgnore: during authentication the domain controller will not probe any WHfB keys for the ROCA vulnerability.\n\nAudit: during authentication the domain controller will emit audit events for WHfB keys that are subject to the ROCA vulnerability (authentications will still succeed).\n\nBlock: during authentication the domain controller will block the use of WHfB keys that are subject to the ROCA vulnerability (authentications will fail).\n\nThis setting only takes effect on domain controllers.\n\nIf not configured, domain controllers will default to using their local configuration. The default local configuration is Audit.\n\nA reboot is not required for changes to this setting to take effect.\n\nNote: to avoid unexpected disruptions this setting should not be set to Block until appropriate mitigations have been performed, for example patching of vulnerable TPMs.\n\nMore information is available at https://go.microsoft.com/fwlink/?linkid=2116430.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sam#admx-sam-samngckeyrocavalidation"],"categoryId":"03a966f7-8f8e-4ecb-aab3-055fe907f5ab","categoryName":"Security Account Manager","options":[{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings","displayName":"Options for handling ROCA-vulnerable WHfB keys:","description":"","helpText":"","infoUrls":[],"categoryId":"03a966f7-8f8e-4ecb-aab3-055fe907f5ab","categoryName":"Security Account Manager","options":[{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings_0","displayName":"Ignore ROCA-vulnerable WHfB keys","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings_1","displayName":"Audit ROCA-vulnerable WHfB keys on use","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings_2","displayName":"Block ROCA-vulnerable WHfB keys on use","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_allow_logon_script_netbiosdisabled","displayName":"Allow logon scripts when NetBIOS or WINS is disabled","description":"This policy setting allows user logon scripts to run when the logon cross-forest, DNS suffixes are not configured, and NetBIOS or WINS is disabled. This policy setting affects all user accounts interactively logging on to the computer.\r\n\r\nIf you enable this policy setting, user logon scripts run if NetBIOS or WINS is disabled during cross-forest logons without the DNS suffixes being configured.\r\n\r\nIf you disable or do not configure this policy setting, user account cross-forest, interactive logging cannot run logon scripts if NetBIOS or WINS is disabled, and the DNS suffixes are not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-allow-logon-script-netbiosdisabled"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_allow_logon_script_netbiosdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_allow_logon_script_netbiosdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_maxgposcriptwaitpolicy","displayName":"Specify maximum wait time for Group Policy scripts","description":"This policy setting determines how long the system waits for scripts applied by Group Policy to run. \r\n\r\nThis setting limits the total time allowed for all logon, logoff, startup, and shutdown scripts applied by Group Policy to finish running. If the scripts have not finished running when the specified time expires, the system stops script processing and records an error event.\r\n\r\nIf you enable this setting, then, in the Seconds box, you can type a number from 1 to 32,000 for the number of seconds you want the system to wait for the set of scripts to finish. To direct the system to wait until the scripts have finished, no matter how long they take, type 0. \r\n\r\nThis interval is particularly important when other system tasks must wait while the scripts complete. By default, each startup script must complete before the next one runs. Also, you can use the \"Run logon scripts synchronously\" setting to direct the system to wait for the logon scripts to complete before loading the desktop. \r\n\r\nAn excessively long interval can delay the system and inconvenience users. However, if the interval is too short, prerequisite tasks might not be done, and the system can appear to be ready prematurely.\r\n\r\nIf you disable or do not configure this setting the system lets the combined set of scripts run for up to 600 seconds (10 minutes). This is the default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-maxgposcriptwaitpolicy"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_maxgposcriptwaitpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_maxgposcriptwaitpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_maxgposcriptwaitpolicy_maxgposcriptwait","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_computer_ps_scripts_first","displayName":"Run Windows PowerShell scripts first at computer startup, shutdown","description":"This policy setting determines whether Windows PowerShell scripts are run before non-Windows PowerShell scripts during computer startup and shutdown. By default, Windows PowerShell scripts run after non-Windows PowerShell scripts. \r\n \r\nIf you enable this policy setting, within each applicable Group Policy Object (GPO), Windows PowerShell scripts are run before non-Windows PowerShell scripts during computer startup and shutdown. \r\n\r\nFor example, assume the following scenario: \r\n\r\nThere are three GPOs (GPO A, GPO B, and GPO C). This policy setting is enabled in GPO A. \r\n\r\nGPO B and GPO C include the following computer startup scripts:\r\n\r\nGPO B: B.cmd, B.ps1\r\nGPO C: C.cmd, C.ps1\r\n\r\nAssume also that there are two computers, DesktopIT and DesktopSales. \r\nFor DesktopIT, GPOs A, B, and C are applied. Therefore, the scripts for GPOs B and C run in the following order for DesktopIT:\r\n\r\nWithin GPO B: B.ps1, B.cmd\r\nWithin GPO C: C.ps1, C.cmd\r\n \r\nFor DesktopSales, GPOs B and C are applied, but not GPO A. Therefore, the scripts for GPOs B and C run in the following order for DesktopSales:\r\n\r\nWithin GPO B: B.cmd, B.ps1\r\nWithin GPO C: C.cmd, C.ps1\r\n\r\nNote: This policy setting determines the order in which computer startup and shutdown scripts are run within all applicable GPOs. You can override this policy setting for specific script types within a specific GPO by configuring the following policy settings for the GPO:\r\n \r\nComputer Configuration\\Policies\\Windows Settings\\Scripts (Startup/Shutdown)\\Startup\r\nComputer Configuration\\Policies\\Windows Settings\\Scripts (Startup/Shutdown)\\Shutdown\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-computer-ps-scripts-first"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_run_computer_ps_scripts_first_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_computer_ps_scripts_first_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_run_logon_script_sync_2","displayName":"Run logon scripts synchronously","description":"This policy setting directs the system to wait for logon scripts to finish running before it starts the File Explorer interface program and creates the desktop.\r\n\r\nIf you enable this policy setting, File Explorer does not start until the logon scripts have finished running. This policy setting ensures that logon script processing is complete before the user starts working, but it can delay the appearance of the desktop.\r\n\r\nIf you disable or do not configure this policy setting, the logon scripts and File Explorer are not synchronized and can run simultaneously.\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. The policy setting set in Computer Configuration takes precedence over the policy setting set in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-logon-script-sync-2"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_run_logon_script_sync_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_logon_script_sync_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_run_shutdown_script_visible","displayName":"Display instructions in shutdown scripts as they run","description":"This policy setting displays the instructions in shutdown scripts as they run.\r\n\r\nShutdown scripts are batch files of instructions that run when the user restarts the system or shuts it down. By default, the system does not display the instructions in the shutdown script.\r\n\r\nIf you enable this policy setting, the system displays each instruction in the shutdown script as it runs. The instructions appear in a command window.\r\n\r\nIf you disable or do not configure this policy setting, the instructions are suppressed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-shutdown-script-visible"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_run_shutdown_script_visible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_shutdown_script_visible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_run_startup_script_sync","displayName":"Run startup scripts asynchronously","description":"This policy setting lets the system run startup scripts simultaneously.\r\n\r\nStartup scripts are batch files that run before the user is invited to log on. By default, the system waits for each startup script to complete before it runs the next startup script.\r\n\r\nIf you enable this policy setting, the system does not coordinate the running of startup scripts. As a result, startup scripts can run simultaneously.\r\n\r\nIf you disable or do not configure this policy setting, a startup cannot run until the previous script is complete.\r\n\r\nNote: Starting with Windows Vista operating system, scripts that are configured to run asynchronously are no longer visible on startup, whether the \"Run startup scripts visible\" policy setting is enabled or not.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-startup-script-sync"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_run_startup_script_sync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_startup_script_sync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_run_startup_script_visible","displayName":"Display instructions in startup scripts as they run","description":"This policy setting displays the instructions in startup scripts as they run.\r\n\r\nStartup scripts are batch files of instructions that run before the user is invited to log on. By default, the system does not display the instructions in the startup script.\r\n\r\nIf you enable this policy setting, the system displays each instruction in the startup script as it runs. Instructions appear in a command window. This policy setting is designed for advanced users.\r\n\r\nIf you disable or do not configure this policy setting, the instructions are suppressed.\r\n\r\nNote: Starting with Windows Vista operating system, scripts that are configured to run asynchronously are no longer visible on startup, whether this policy setting is enabled or not.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-startup-script-visible"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_run_startup_script_visible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_startup_script_visible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_scripts_run_user_ps_scripts_first","displayName":"Run Windows PowerShell scripts first at user logon, logoff","description":"This policy setting determines whether Windows PowerShell scripts are run before non-Windows PowerShell scripts during user logon and logoff. By default, Windows PowerShell scripts run after non-Windows PowerShell scripts. \r\n \r\nIf you enable this policy setting, within each applicable Group Policy Object (GPO), PowerShell scripts are run before non-PowerShell scripts during user logon and logoff. \r\n\r\nFor example, assume the following scenario: \r\n\r\nThere are three GPOs (GPO A, GPO B, and GPO C). This policy setting is enabled in GPO A. \r\n\r\nGPO B and GPO C include the following user logon scripts:\r\n\r\nGPO B: B.cmd, B.ps1\r\nGPO C: C.cmd, C.ps1\r\n\r\nAssume also that there are two users, Qin Hong and Tamara Johnston. \r\nFor Qin, GPOs A, B, and C are applied. Therefore, the scripts for GPOs B and C run in the following order for Qin:\r\n\r\nWithin GPO B: B.ps1, B.cmd\r\nWithin GPO C: C.ps1, C.cmd\r\n \r\nFor Tamara, GPOs B and C are applied, but not GPO A. Therefore, the scripts for GPOs B and C run in the following order for Tamara:\r\n\r\nWithin GPO B: B.cmd, B.ps1\r\nWithin GPO C: C.cmd, C.ps1\r\n\r\nNote: This policy setting determines the order in which user logon and logoff scripts are run within all applicable GPOs. You can override this policy setting for specific script types within a specific GPO by configuring the following policy settings for the GPO:\r\n \r\nUser Configuration\\Policies\\Windows Settings\\Scripts (Logon/Logoff)\\Logon\r\nUser Configuration\\Policies\\Windows Settings\\Scripts (Logon/Logoff)\\Logoff\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. The policy setting set in Computer Configuration takes precedence over the setting set in User Configuration.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-user-ps-scripts-first"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_run_user_ps_scripts_first_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_run_user_ps_scripts_first_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sdiageng_betterwhenconnected","displayName":"Troubleshooting: Allow users to access online troubleshooting content on Microsoft servers from the Troubleshooting Control Panel (via the Windows Online Troubleshooting Service - WOTS)","description":"This policy setting allows users who are connected to the Internet to access and search troubleshooting content that is hosted on Microsoft content servers. Users can access online troubleshooting content from within the Troubleshooting Control Panel UI by clicking \"Yes\" when they are prompted by a message that states, \"Do you want the most up-to-date troubleshooting content?\"\r\n\r\nIf you enable or do not configure this policy setting, users who are connected to the Internet can access and search troubleshooting content that is hosted on Microsoft content servers from within the Troubleshooting Control Panel user interface.\r\n\r\nIf you disable this policy setting, users can only access and search troubleshooting content that is available locally on their computers, even if they are connected to the Internet. They are prevented from connecting to the Microsoft servers that host the Windows Online Troubleshooting Service.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sdiageng#admx-sdiageng-betterwhenconnected"],"categoryId":"b6bb653a-73f0-42f4-b097-1ce556310904","categoryName":"Scripted Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_sdiageng_betterwhenconnected_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sdiageng_betterwhenconnected_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticsexecutionpolicy","displayName":"Troubleshooting: Allow users to access and run Troubleshooting Wizards","description":"This policy setting allows users to access and run the troubleshooting tools that are available in the Troubleshooting Control Panel and to run the troubleshooting wizard to troubleshoot problems on their computers.\r\n\r\nIf you enable or do not configure this policy setting, users can access and run the troubleshooting tools from the Troubleshooting Control Panel.\r\n\r\nIf you disable this policy setting, users cannot access or run the troubleshooting tools from the Control Panel.\r\n\r\nNote that this setting also controls a user's ability to launch standalone troubleshooting packs such as those found in .diagcab files.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sdiageng#admx-sdiageng-scripteddiagnosticsexecutionpolicy"],"categoryId":"b6bb653a-73f0-42f4-b097-1ce556310904","categoryName":"Scripted Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticsexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticsexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticssecuritypolicy","displayName":"Configure Security Policy for Scripted Diagnostics","description":"This policy setting determines whether scripted diagnostics will execute diagnostic packages that are signed by untrusted publishers.\r\n\r\nIf you enable this policy setting, the scripted diagnostics execution engine validates the signer of any diagnostic package and runs only those signed by trusted publishers.\r\n\r\nIf you disable or do not configure this policy setting, the scripted diagnostics execution engine runs all digitally signed packages.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sdiageng#admx-sdiageng-scripteddiagnosticssecuritypolicy"],"categoryId":"b6bb653a-73f0-42f4-b097-1ce556310904","categoryName":"Scripted Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticssecuritypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticssecuritypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sdiagschd_scheduleddiagnosticsexecutionpolicy","displayName":"Configure Scheduled Maintenance Behavior","description":"Determines whether scheduled diagnostics will run to proactively detect and resolve system problems.\r\n\r\nIf you enable this policy setting, you must choose an execution level. If you choose detection and troubleshooting only, Windows will periodically detect and troubleshoot problems. The user will be notified of the problem for interactive resolution. \r\n\r\nIf you choose detection, troubleshooting and resolution, Windows will resolve some of these problems silently without requiring user input.\r\n\r\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve problems on a scheduled basis.\r\n\r\nIf you do not configure this policy setting, local troubleshooting preferences will take precedence, as configured in the control panel. If no local troubleshooting preference is configured, scheduled diagnostics are enabled for detection, troubleshooting and resolution by default.\r\n\r\nNo reboots or service restarts are required for this policy to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Task Scheduler service is in the running state. When the service is stopped or disabled, scheduled diagnostics will not be executed. The Task Scheduler service can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sdiagschd#admx-sdiagschd-scheduleddiagnosticsexecutionpolicy"],"categoryId":"fe3cb879-8869-4163-91d7-e432abd75da8","categoryName":"Scheduled Maintenance","options":[{"id":"device_vendor_msft_policy_config_admx_sdiagschd_scheduleddiagnosticsexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sdiagschd_scheduleddiagnosticsexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sdiagschd_scheduleddiagnosticsexecutionpolicy_scheduleddiagnosticsexecutionpolicylevel","displayName":"Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"fe3cb879-8869-4163-91d7-e432abd75da8","categoryName":"Scheduled Maintenance","options":[{"id":"device_vendor_msft_policy_config_admx_sdiagschd_scheduleddiagnosticsexecutionpolicy_scheduleddiagnosticsexecutionpolicylevel_1","displayName":"Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sdiagschd_scheduleddiagnosticsexecutionpolicy_scheduleddiagnosticsexecutionpolicylevel_2","displayName":"Regular","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_securitycenter_securitycenter_securitycenterindomain","displayName":"Turn on Security Center (Domain PCs only)","description":"This policy setting specifies whether Security Center is turned on or off for computers that are joined to an Active Directory domain. When Security Center is turned on, it monitors essential security settings and notifies the user when the computer might be at risk. The Security Center Control Panel category view also contains a status section, where the user can get recommendations to help increase the computer's security. When Security Center is not enabled on the domain, neither the notifications nor the Security Center status section are displayed. \r\n\r\nNote that Security Center can only be turned off for computers that are joined to a Windows domain. When a computer is not joined to a Windows domain, the policy setting will have no effect.\r\n\r\nIf you do not congifure this policy setting, the Security Center is turned off for domain members. \r\n\r\nIf you enable this policy setting, Security Center is turned on for all users. \r\n\r\nIf you disable this policy setting, Security Center is turned off for domain members.\r\n\r\nWindows XP SP2\r\n----------------------\r\nIn Windows XP SP2, the essential security settings that are monitored by Security Center include firewall, antivirus, and Automatic Updates. Note that Security Center might not be available following a change to this policy setting until after the computer is restarted for Windows XP SP2 computers. \r\n\r\nWindows Vista\r\n---------------------\r\nIn Windows Vista, this policy setting monitors essential security settings to include firewall, antivirus, antispyware, Internet security settings, User Account Control, and Automatic Updates. Windows Vista computers do not require a reboot for this policy setting to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-securitycenter#admx-securitycenter-securitycenter-securitycenterindomain"],"categoryId":"31d3b4c4-767e-403a-834c-51f3691bbf2b","categoryName":"Security Center","options":[{"id":"device_vendor_msft_policy_config_admx_securitycenter_securitycenter_securitycenterindomain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_securitycenter_securitycenter_securitycenterindomain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sensors_disablelocationscripting_2","displayName":"Turn off location scripting","description":"\r\n This policy setting turns off scripting for the location feature.\r\n\r\n If you enable this policy setting, scripts for the location feature will not run.\r\n\r\n If you disable or do not configure this policy setting, all location scripts will run.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sensors#admx-sensors-disablelocationscripting-2"],"categoryId":"b40cfb22-8f17-4317-bcbb-c1c871497446","categoryName":"Location and Sensors","options":[{"id":"device_vendor_msft_policy_config_admx_sensors_disablelocationscripting_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sensors_disablelocationscripting_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sensors_disablesensors_2","displayName":"Turn off sensors","description":"\r\n This policy setting turns off the sensor feature for this computer.\r\n\r\n If you enable this policy setting, the sensor feature is turned off, and all programs on this computer cannot use the sensor feature.\r\n\r\n If you disable or do not configure this policy setting, all programs on this computer can use the sensor feature.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sensors#admx-sensors-disablesensors-2"],"categoryId":"b40cfb22-8f17-4317-bcbb-c1c871497446","categoryName":"Location and Sensors","options":[{"id":"device_vendor_msft_policy_config_admx_sensors_disablesensors_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sensors_disablesensors_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servermanager_do_not_display_manage_your_server_page","displayName":"Do not display Manage Your Server page at logon","description":"This policy setting allows you to turn off the automatic display of the Manage Your Server page. \r\n\r\nIf you enable this policy setting, the Manage Your Server page is not displayed each time an administrator logs on to the server. \r\n\r\nIf you disable or do not configure this policy setting, the Manage Your Server page is displayed each time an administrator logs on to the server. However, if the administrator has selected the \"Don’t display this page at logon\" option at the bottom of the Manage Your Server page, the page is not displayed.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servermanager#admx-servermanager-do-not-display-manage-your-server-page"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_servermanager_do_not_display_manage_your_server_page_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servermanager_do_not_display_manage_your_server_page_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servermanager_donotlaunchinitialconfigurationtasks","displayName":"Do not display Initial Configuration Tasks window automatically at logon","description":"This policy setting allows you to turn off the automatic display of the Initial Configuration Tasks window at logon on Windows Server 2008 and Windows Server 2008 R2. \r\n\r\nIf you enable this policy setting, the Initial Configuration Tasks window is not displayed when an administrator logs on to the server. \r\n\r\nIf you disable this policy setting, the Initial Configuration Tasks window is displayed when an administrator logs on to the server.\r\n\r\nIf you do not configure this policy setting, the Initial Configuration Tasks window is displayed when an administrator logs on to the server. However, if an administrator selects the \"Do not show this window at logon\" option, the window is not displayed on subsequent logons.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servermanager#admx-servermanager-donotlaunchinitialconfigurationtasks"],"categoryId":"e042b102-b12c-48d1-86ef-f6d296da5b95","categoryName":"Server Manager","options":[{"id":"device_vendor_msft_policy_config_admx_servermanager_donotlaunchinitialconfigurationtasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servermanager_donotlaunchinitialconfigurationtasks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servermanager_donotlaunchservermanager","displayName":"Do not display Server Manager automatically at logon","description":"This policy setting allows you to turn off the automatic display of Server Manager at logon.\r\n\r\nIf you enable this policy setting, Server Manager is not displayed automatically when a user logs on to the server.\r\n\r\nIf you disable this policy setting, Server Manager is displayed automatically when a user logs on to the server.\r\n\r\nIf you do not configure this policy setting, Server Manager is displayed when a user logs on to the server. However, if the \"Do not show me this console at logon\" (Windows Server 2008 and Windows Server 2008 R2) or “Do not start Server Manager automatically at logon” (Windows Server 2012) option is selected, the console is not displayed automatically at logon.\r\n\r\nNote: Regardless of the status of this policy setting, Server Manager is available from the Start menu or the Windows taskbar.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servermanager#admx-servermanager-donotlaunchservermanager"],"categoryId":"e042b102-b12c-48d1-86ef-f6d296da5b95","categoryName":"Server Manager","options":[{"id":"device_vendor_msft_policy_config_admx_servermanager_donotlaunchservermanager_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servermanager_donotlaunchservermanager_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate","displayName":"Configure the refresh interval for Server Manager","description":"This policy setting allows you to set the refresh interval for Server Manager. Each refresh provides Server Manager with updated information about which roles and features are installed on servers that you are managing by using Server Manager. Server Manager also monitors the status of roles and features installed on managed servers.\r\n\r\nIf you enable this policy setting, Server Manager uses the refresh interval specified in the policy setting instead of the “Configure Refresh Interval” setting (in Windows Server 2008 and Windows Server 2008 R2), or the “Refresh the data shown in Server Manager every [x] [minutes/hours/days]” setting (in Windows Server 2012) that is configured in the Server Manager console.\r\n\r\nIf you disable this policy setting, Server Manager does not refresh automatically. If you do not configure this policy setting, Server Manager uses the refresh interval settings that are specified in the Server Manager console.\r\n\r\nNote: The default refresh interval for Server Manager is two minutes in Windows Server 2008 and Windows Server 2008 R2, or 10 minutes in Windows Server 2012.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servermanager#admx-servermanager-servermanagerautorefreshrate"],"categoryId":"e042b102-b12c-48d1-86ef-f6d296da5b95","categoryName":"Server Manager","options":[{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate_refreshrate","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"e042b102-b12c-48d1-86ef-f6d296da5b95","categoryName":"Server Manager","options":null},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing","displayName":"Specify settings for optional component installation and component repair","description":"\r\nThis policy setting specifies the network locations that will be used for the repair of operating system corruption and for enabling optional features that have had their payload files removed.\r\n\r\nIf you enable this policy setting and specify the new location, the files in that location will be used to repair operating system corruption and for enabling optional features that have had their payload files removed. You must enter the fully qualified path to the new location in the \"Alternate source file path\" text box. Multiple locations can be specified when each path is separated by a semicolon. \r\n\r\nThe network location can be either a folder, or a WIM file. If it is a WIM file, the location should be specified by prefixing the path with “wim:” and include the index of the image to use in the WIM file. For example “wim:\\\\server\\share\\install.wim:3”.\r\n\r\nIf you disable or do not configure this policy setting, or if the required files cannot be found at the locations specified in this policy setting, the files will be downloaded from Windows Update, if that is allowed by the policy settings for the computer.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servicing#admx-servicing-servicing"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_checkbox_neverusewu","displayName":"Never attempt to download payload from Windows Update","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_checkbox_neverusewu_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_checkbox_neverusewu_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_checkbox_sidestepwsus","displayName":"Download repair content and optional features directly from Windows Update instead of Windows Server Update Services (WSUS)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_checkbox_sidestepwsus_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_checkbox_sidestepwsus_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_servicing_servicing_localsourcepath_textbox","displayName":"Alternate source file path","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableapplicationsettingsync","displayName":"Do not sync app settings","description":"Prevent the \"app settings\" group from syncing to and from this PC. This turns off and disables the \"app settings\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"app settings\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn app settings syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"app settings\" group is on by default and configurable by the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disableapplicationsettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disableapplicationsettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableapplicationsettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableapplicationsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"app settings\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disableapplicationsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableapplicationsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync","displayName":"Do not sync Apps","description":"\r\n Prevent the \"AppSync\" group from syncing to and from this PC. This turns off and disables the \"AppSync\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"AppSync\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn app syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"AppSync\" group is on by default and configurable by the user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disableappsyncsettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"AppSync\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablecredentialssettingsync","displayName":"Do not sync passwords","description":"Prevent the \"passwords\" group from syncing to and from this PC. This turns off and disables the \"passwords\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"passwords\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn passwords syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"passwords\" group is on by default and configurable by the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablecredentialssettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablecredentialssettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablecredentialssettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablecredentialssettingsync_checkbox_useroverride","displayName":"Allow users to turn \"passwords\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablecredentialssettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablecredentialssettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync","displayName":"Do not sync desktop personalization","description":"Prevent the \"desktop personalization\" group from syncing to and from this PC. This turns off and disables the \"desktop personalization\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"desktop personalization\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn desktop personalization syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"desktop personalization\" group is on by default and configurable by the user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disabledesktopthemesettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_checkbox_useroverride","displayName":"Allow users to turn \"desktop personalization\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync","displayName":"Do not sync personalize","description":"Prevent the \"personalize\" group from syncing to and from this PC. This turns off and disables the \"personalize\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"personalize\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn personalize syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"personalize\" group is on by default and configurable by the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablepersonalizationsettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"personalize\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync","displayName":"Do not sync","description":"Prevent syncing to and from this PC. This turns off and disables the \"sync your settings\" switch on the \"sync your settings\" page in PC Settings.\r\n\r\nIf you enable this policy setting, \"sync your settings\" will be turned off, and none of the \"sync your setting\" groups will be synced on this PC.\r\n\r\nUse the option \"Allow users to turn syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, \"sync your settings\" is on by default and configurable by the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablesettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_checkbox_useroverride","displayName":"Allow users to turn syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync","displayName":"Do not sync start settings","description":"\r\n Prevent the \"Start layout\" group from syncing to and from this PC. This turns off and disables the \"Start layout\" group on the \"sync your settings\" page in PC settings.\r\n\r\n If you enable this policy setting, the \"Start layout\" group will not be synced.\r\n\r\n Use the option \"Allow users to turn start syncing on\" so that syncing is turned off by default but not disabled.\r\n\r\n If you do not set or disable this setting, syncing of the \"Start layout\" group is on by default and configurable by the user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablestartlayoutsettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"start layout\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesynconpaidnetwork","displayName":"Do not sync on metered connections","description":"Prevent syncing to and from this PC when on metered Internet connections. This turns off and disables \"sync your settings on metered connections\" switch on the \"sync your settings\" page in PC Settings.\r\n\r\nIf you enable this policy setting, syncing on metered connections will be turned off, and no syncing will take place when this PC is on a metered connection.\r\n\r\nIf you do not set or disable this setting, syncing on metered connections is configurable by the user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablesynconpaidnetwork"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesynconpaidnetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesynconpaidnetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablewindowssettingsync","displayName":"Do not sync other Windows settings","description":"Prevent the \"Other Windows settings\" group from syncing to and from this PC. This turns off and disables the \"Other Windows settings\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"Other Windows settings\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn other Windows settings syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"Other Windows settings\" group is on by default and configurable by the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablewindowssettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablewindowssettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablewindowssettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablewindowssettingsync_checkbox_useroverride","displayName":"Allow users to turn \"other Windows settings\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablewindowssettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablewindowssettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_sharing_disablehomegroup","displayName":"Prevent the computer from joining a homegroup","description":"This policy setting specifies whether users can add computers to a homegroup. By default, users can add their computer to a homegroup on a private network.\r\n\r\nIf you enable this policy setting, users cannot add computers to a homegroup. This policy setting does not affect other network sharing features.\r\n\r\nIf you disable or do not configure this policy setting, users can add computers to a homegroup. However, data on a domain-joined computer is not shared with the homegroup.\r\n\r\nThis policy setting is not configured by default.\r\n\r\nYou must restart the computer for this policy setting to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sharing#admx-sharing-disablehomegroup"],"categoryId":"d0e46713-238c-42b7-a996-653cf952c367","categoryName":"Home Group","options":[{"id":"device_vendor_msft_policy_config_admx_sharing_disablehomegroup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sharing_disablehomegroup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowcertificateswithnoeku","displayName":"Allow certificates with no extended key usage certificate attribute","description":"This policy setting lets you allow certificates without an Extended Key Usage (EKU) set to be used for logon.\r\n\r\nIn versions of Windows prior to Windows Vista, smart card certificates that are used for logon require an enhanced key usage (EKU) extension with a smart card logon object identifier. This policy setting can be used to modify that restriction.\r\n\r\nIf you enable this policy setting, certificates with the following attributes can also be used to log on with a smart card:\r\n- Certificates with no EKU\r\n- Certificates with an All Purpose EKU\r\n- Certificates with a Client Authentication EKU\r\n\r\nIf you disable or do not configure this policy setting, only certificates that contain the smart card logon object identifier can be used to log on with a smart card.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowcertificateswithnoeku"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowcertificateswithnoeku_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowcertificateswithnoeku_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowintegratedunblock","displayName":"Allow Integrated Unblock screen to be displayed at the time of logon","description":"This policy setting lets you determine whether the integrated unblock feature will be available in the logon User Interface (UI).\r\n\r\nIn order to use the integrated unblock feature your smart card must support this feature. Please check with your hardware manufacturer to see if your smart card supports this feature.\r\n\r\nIf you enable this policy setting, the integrated unblock feature will be available.\r\n\r\nIf you disable or do not configure this policy setting then the integrated unblock feature will not be available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowintegratedunblock"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowintegratedunblock_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowintegratedunblock_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowsignatureonlykeys","displayName":"Allow signature keys valid for Logon","description":"This policy setting lets you allow signature key-based certificates to be enumerated and available for logon.\r\n\r\nIf you enable this policy setting then any certificates available on the smart card with a signature only key will be listed on the logon screen.\r\n\r\nIf you disable or do not configure this policy setting, any available smart card signature key-based certificates will not be listed on the logon screen.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowsignatureonlykeys"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowsignatureonlykeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowsignatureonlykeys_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowtimeinvalidcertificates","displayName":"Allow time invalid certificates","description":"This policy setting permits those certificates to be displayed for logon that are either expired or not yet valid.\r\n\r\nUnder previous versions of Microsoft Windows, certificates were required to contain a valid time and not be expired. The certificate must still be accepted by the domain controller in order to be used. This setting only controls the displaying of the certificate on the client machine. \r\n\r\nIf you enable this policy setting certificates will be listed on the logon screen regardless of whether they have an invalid time or their time validity has expired.\r\n\r\nIf you disable or do not configure this policy setting, certificates which are expired or not yet valid will not be listed on the logon screen.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowtimeinvalidcertificates"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowtimeinvalidcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowtimeinvalidcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_certpropenabledstring","displayName":"Turn on certificate propagation from smart card","description":"This policy setting allows you to manage the certificate propagation that occurs when a smart card is inserted.\r\n\r\nIf you enable or do not configure this policy setting then certificate propagation will occur when you insert your smart card.\r\n\r\nIf you disable this policy setting, certificate propagation will not occur and the certificates will not be made available to applications such as Outlook.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-certpropenabledstring"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_certpropenabledstring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certpropenabledstring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring","displayName":"Configure root certificate clean up","description":"This policy setting allows you to manage the clean up behavior of root certificates. If you enable this policy setting then root certificate cleanup will occur according to the option selected. If you disable or do not configure this setting then root certificate clean up will occur on log off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-certproprootcleanupstring"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels","displayName":"Root certificate clean up options","description":null,"helpText":"","infoUrls":[],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels_0","displayName":"No cleanup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels_1","displayName":"Clean up certificates on smart card removal","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels_2","displayName":"Clean up certificates on log off","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootenabledstring","displayName":"Turn on root certificate propagation from smart card","description":"This policy setting allows you to manage the root certificate propagation that occurs when a smart card is inserted.\r\n\r\nIf you enable or do not configure this policy setting then root certificate propagation will occur when you insert your smart card. Note: For this policy setting to work the following policy setting must also be enabled: Turn on certificate propagation from smart card.\r\n\r\nIf you disable this policy setting then root certificates will not be propagated from the smart card.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-certproprootenabledstring"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootenabledstring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootenabledstring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_disallowplaintextpin","displayName":"Prevent plaintext PINs from being returned by Credential Manager","description":"This policy setting prevents plaintext PINs from being returned by Credential Manager. \r\n\r\nIf you enable this policy setting, Credential Manager does not return a plaintext PIN. \r\n\r\nIf you disable or do not configure this policy setting, plaintext PINs can be returned by Credential Manager.\r\n\r\nNote: Enabling this policy setting could prevent certain smart cards from working on Windows. Please consult your smart card manufacturer to find out whether you will be affected by this policy setting.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-disallowplaintextpin"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_disallowplaintextpin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_disallowplaintextpin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_enumerateecccerts","displayName":"Allow ECC certificates to be used for logon and authentication","description":"This policy setting allows you to control whether elliptic curve cryptography (ECC) certificates on a smart card can be used to log on to a domain.\r\n\r\nIf you enable this policy setting, ECC certificates on a smart card can be used to log on to a domain.\r\n\r\nIf you disable or do not configure this policy setting, ECC certificates on a smart card cannot be used to log on to a domain. \r\n\r\nNote: This policy setting only affects a user's ability to log on to a domain. ECC certificates on a smart card that are used for other applications, such as document signing, are not affected by this policy setting. \r\nNote: If you use an ECDSA key to log on, you must also have an associated ECDH key to permit logons when you are not connected to the network.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-enumerateecccerts"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_enumerateecccerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_enumerateecccerts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_filterduplicatecerts","displayName":"Filter duplicate logon certificates","description":"This policy settings lets you configure if all your valid logon certificates are displayed.\r\n\r\nDuring the certificate renewal period, a user can have multiple valid logon certificates issued from the same certificate template. This can cause confusion as to which certificate to select for logon. The common case for this behavior is when a certificate is renewed and the old one has not yet expired. Two certificates are determined to be the same if they are issued from the same template with the same major version and they are for the same user (determined by their UPN). \r\n \r\nIf there are two or more of the \"same\" certificate on a smart card and this policy is enabled then the certificate that is used for logon on Windows 2000, Windows XP, and Windows 2003 Server will be shown, otherwise the the certificate with the expiration time furthest in the future will be shown. Note: This setting will be applied after the following policy: \"Allow time invalid certificates\"\r\n\r\nIf you enable or do not configure this policy setting, filtering will take place.\r\n\r\nIf you disable this policy setting, no filtering will take place.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-filterduplicatecerts"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_filterduplicatecerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_filterduplicatecerts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_forcereadingallcertificates","displayName":"Force the reading of all certificates from the smart card","description":"This policy setting allows you to manage the reading of all certificates from the smart card for logon.\r\n\r\nDuring logon Windows will by default only read the default certificate from the smart card unless it supports retrieval of all certificates in a single call. This setting forces Windows to read all the certificates from the card. This can introduce a significant performance decrease in certain situations. Please contact your smart card vendor to determine if your smart card and associated CSP supports the required behavior.\r\n\r\nIf you enable this setting, then Windows will attempt to read all certificates from the smart card regardless of the feature set of the CSP.\r\n\r\nIf you disable or do not configure this setting, Windows will only attempt to read the default certificate from those cards that do not support retrieval of all certificates in a single call. Certificates other than the default will not be available for logon.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-forcereadingallcertificates"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_forcereadingallcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_forcereadingallcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_integratedunblockpromptstring","displayName":"Display string when smart card is blocked","description":"This policy setting allows you to manage the displayed message when a smart card is blocked.\r\n\r\nIf you enable this policy setting, the specified message will be displayed to the user when the smart card is blocked. Note: The following policy setting must be enabled - Allow Integrated Unblock screen to be displayed at the time of logon.\r\n\r\nIf you disable or do not configure this policy setting, the default message will be displayed to the user when the smart card is blocked, if the integrated unblock feature is enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-integratedunblockpromptstring"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_integratedunblockpromptstring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_integratedunblockpromptstring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_integratedunblockpromptstring_integratedunblockpromptstring","displayName":"Display string when smart card is blocked","description":null,"helpText":"","infoUrls":[],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_reversesubject","displayName":"Reverse the subject name stored in a certificate when displaying","description":"This policy setting lets you reverse the subject name from how it is stored in the certificate when displaying it during logon. \r\n \r\nBy default the user principal name (UPN) is displayed in addition to the common name to help users distinguish one certificate from another. For example, if the certificate subject was CN=User1, OU=Users, DN=example, DN=com and had an UPN of user1@example.com then \"User1\" will be displayed along with \"user1@example.com.\" If the UPN is not present then the entire subject name will be displayed. This setting controls the appearance of that subject name and might need to be adjusted per organization.\r\n\r\nIf you enable this policy setting or do not configure this setting, then the subject name will be reversed. \r\n\r\nIf you disable , the subject name will be displayed as it appears in the certificate.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-reversesubject"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_reversesubject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_reversesubject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_scpnpenabled","displayName":"Turn on Smart Card Plug and Play service","description":"This policy setting allows you to control whether Smart Card Plug and Play is enabled.\r\n\r\nIf you enable or do not configure this policy setting, Smart Card Plug and Play will be enabled and the system will attempt to install a Smart Card device driver when a card is inserted in a Smart Card Reader for the first time.\r\n\r\nIf you disable this policy setting, Smart Card Plug and Play will be disabled and a device driver will not be installed when a card is inserted in a Smart Card Reader.\r\n\r\nNote: This policy setting is applied only for smart cards that have passed the Windows Hardware Quality Labs (WHQL) testing process.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-scpnpenabled"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_scpnpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_scpnpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_scpnpnotification","displayName":"Notify user of successful smart card driver installation","description":"This policy setting allows you to control whether a confirmation message is displayed when a smart card device driver is installed.\r\n\r\nIf you enable or do not configure this policy setting, a confirmation message will be displayed when a smart card device driver is installed.\r\n\r\nIf you disable this policy setting, a confirmation message will not be displayed when a smart card device driver is installed.\r\n\r\nNote: This policy setting is applied only for smart cards that have passed the Windows Hardware Quality Labs (WHQL) testing process.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-scpnpnotification"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_scpnpnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_scpnpnotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_smartcard_x509hintsneeded","displayName":"Allow user name hint","description":"This policy setting lets you determine whether an optional field will be displayed during logon and elevation that allows a user to enter his or her user name or user name and domain, thereby associating a certificate with that user.\r\n\r\nIf you enable this policy setting then an optional field that allows a user to enter their user name or user name and domain will be displayed.\r\n\r\nIf you disable or do not configure this policy setting, an optional field that allows users to enter their user name or user name and domain will not be displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-x509hintsneeded"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_x509hintsneeded_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_x509hintsneeded_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_communities","displayName":"Specify communities","description":"This policy setting configures a list of the communities defined to the Simple Network Management Protocol (SNMP) service.\r\n\r\nSNMP is a protocol designed to give a user the capability to remotely manage a computer network, by polling and setting terminal values and monitoring network events.\r\n\r\nA valid community is a community recognized by the SNMP service, while a community is a group of hosts (servers, workstations, hubs, and routers) that are administered together by SNMP. The SNMP service is a managed network node that receives SNMP packets from the network.\r\n\r\nIf you enable this policy setting, the SNMP agent only accepts requests from management systems within the communities it recognizes, and only SNMP Read operation is allowed for the community.\r\n\r\nIf you disable or do not configure this policy setting, the SNMP service takes the Valid Communities configured on the local computer instead.\r\n\r\nBest practice: For security purposes, it is recommended to restrict the HKLM\\SOFTWARE\\Policies\\SNMP\\Parameters\\ValidCommunities key to allow only the local admin group full control.\r\n\r\nNote: It is good practice to use a cryptic community name.\r\n\r\nNote: This policy setting has no effect if the SNMP agent is not installed on the client computer.\r\n\r\nAlso, see the other two SNMP settings: \"Specify permitted managers\" and \"Specify trap configuration\".\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-snmp#admx-snmp-snmp-communities"],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":[{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_communities_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_communities_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_communities_snmp_communitieslistbox","displayName":"Communities","description":null,"helpText":"","infoUrls":[],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":null},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers","displayName":"Specify permitted managers","description":"This policy setting determines the permitted list of hosts that can submit a query to the Simple Network Management (SNMP) agent running on the client computer.\r\n\r\nSimple Network Management Protocol is a protocol designed to give a user the capability to remotely manage a computer network by polling and setting terminal values and monitoring network events.\r\n\r\nThe manager is located on the host computer on the network. The manager's role is to poll the agents for certain requested information.\r\n\r\nIf you enable this policy setting, the SNMP agent only accepts requests from the list of permitted managers that you configure using this setting.\r\n\r\nIf you disable or do not configure this policy setting, SNMP service takes the permitted managers configured on the local computer instead.\r\n\r\nBest practice: For security purposes, it is recommended to restrict the HKLM\\SOFTWARE\\Policies\\SNMP\\Parameters\\PermittedManagers key to allow only the local admin group full control.\r\n\r\nNote: This policy setting has no effect if the SNMP agent is not installed on the client computer.\r\n\r\nAlso, see the other two SNMP policy settings: \"Specify trap configuration\" and \"Specify Community Name\".\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-snmp#admx-snmp-snmp-permittedmanagers"],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":[{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers_snmp_permittedmanagerslistbox","displayName":"Permitted managers","description":null,"helpText":"","infoUrls":[],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":null},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_traps_public","displayName":"Specify traps for public community","description":"This policy setting allows trap configuration for the Simple Network Management Protocol (SNMP) agent.\r\n\r\nSimple Network Management Protocol is a protocol designed to give a user the capability to remotely manage a computer network by polling and setting terminal values and monitoring network events.\r\n\r\nThis policy setting allows you to configure the name of the hosts that receive trap messages for the community sent by the SNMP service. A trap message is an alert or significant event that allows the SNMP agent to notify management systems asynchronously.\r\n\r\nIf you enable this policy setting, the SNMP service sends trap messages to the hosts within the \"public\" community.\r\n\r\nIf you disable or do not configure this policy setting, the SNMP service takes the trap configuration configured on the local computer instead.\r\n\r\nNote: This setting has no effect if the SNMP agent is not installed on the client computer.\r\n\r\nAlso, see the other two SNMP settings: \"Specify permitted managers\" and \"Specify Community Name\".\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-snmp#admx-snmp-snmp-traps-public"],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":[{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_traps_public_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_traps_public_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_traps_public_snmp_traps_publiclistbox","displayName":"Trap configuration","description":null,"helpText":"","infoUrls":[],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":null},{"id":"device_vendor_msft_policy_config_admx_soundrec_soundrec_diableapplication_titletext_2","displayName":"Do not allow Sound Recorder to run","description":"Specifies whether Sound Recorder can run.\r\n\r\nSound Recorder is a feature of Microsoft Windows Vista that can be used to record sound from an audio input device where the recorded sound is encoded and saved as an audio file.\r\n\r\nIf you enable this policy setting, Sound Recorder will not run.\r\n\r\nIf you disable or do not configure this policy setting, Sound Recorder can be run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-soundrec#admx-soundrec-soundrec-diableapplication-titletext-2"],"categoryId":"088b8d8d-5f3f-4979-aa18-b3c4b2616a24","categoryName":"Sound Recorder","options":[{"id":"device_vendor_msft_policy_config_admx_soundrec_soundrec_diableapplication_titletext_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_soundrec_soundrec_diableapplication_titletext_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration","displayName":"Customize message for Access Denied errors","description":"This policy setting specifies the message that users see when they are denied access to a file or folder. You can customize the Access Denied message to include additional text and links. You can also provide users with the ability to send an email to request access to the file or folder to which they were denied access.\r\n\r\nIf you enable this policy setting, users receive a customized Access Denied message from the file servers on which this policy setting is applied. \r\n\r\nIf you disable this policy setting, users see a standard Access Denied message that doesn't provide any of the functionality controlled by this policy setting, regardless of the file server configuration.\r\n\r\nIf you do not configure this policy setting, users see a standard Access Denied message unless the file server is configured to display the customized Access Denied message. By default, users see the standard Access Denied message.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-srmfci#admx-srmfci-accessdeniedconfiguration"],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_additonalemailtotext","displayName":"Additional recipients:","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_allowemailrequestscheck","displayName":"Enable users to request assistance","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_allowemailrequestscheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_allowemailrequestscheck_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_emailmessagetext","displayName":"Add the following text to the end of the email:","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_errormessagetext","displayName":"Display the following message to users who are denied access:","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_generatelogcheck","displayName":"Log emails in Application and Services event log","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_generatelogcheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_generatelogcheck_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includedeviceclaimscheck","displayName":"Include device claims","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includedeviceclaimscheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includedeviceclaimscheck_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includeuserclaimscheck","displayName":"Include user claims","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includeuserclaimscheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includeuserclaimscheck_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_putadminontocheck","displayName":"File server administrator","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_putadminontocheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_putadminontocheck_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_putdataownerontocheck","displayName":"Folder owner","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_putdataownerontocheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_putdataownerontocheck_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist","displayName":"File Classification Infrastructure: Specify classification properties list","description":"This policy setting controls which set of properties is available for classifying files on affected computers.\r\n\r\nAdministrators can define the properties for the organization by using Active Directory Domain Services (AD DS), and then group these properties into lists. Administrators can supplement these properties on individual file servers by using File Classification Infrastructure, which is part of the File Server Resource Manager role service.\r\n\r\nIf you enable this policy setting, you can select which list of properties is available for classification on the affected computers. \r\n\r\nIf you disable or do not configure this policy setting, the Global Resource Property List in AD DS provides the default set of properties.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-srmfci#admx-srmfci-centralclassificationlist"],"categoryId":"dd9a3dad-5851-4899-a5c1-c23318986846","categoryName":"File Classification Infrastructure","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist_centralclassificationlisttextelement","displayName":"Classification properties list:","description":null,"helpText":"","infoUrls":[],"categoryId":"dd9a3dad-5851-4899-a5c1-c23318986846","categoryName":"File Classification Infrastructure","options":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_enablemanualux","displayName":"File Classification Infrastructure: Display Classification tab in File Explorer","description":"This policy setting controls whether the Classification tab is displayed in the Properties dialog box in File Explorer.\r\n\r\nThe Classification tab enables users to manually classify files by selecting properties from a list. Administrators can define the properties for the organization by using Group Policy, and supplement these with properties defined on individual file servers by using File Classification Infrastructure, which is part of the File Server Resource Manager role service.\r\n\r\nIf you enable this policy setting, the Classification tab is displayed.\r\n\r\nIf you disable or do not configure this policy setting, the Classification tab is hidden.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-srmfci#admx-srmfci-enablemanualux"],"categoryId":"dd9a3dad-5851-4899-a5c1-c23318986846","categoryName":"File Classification Infrastructure","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_enablemanualux_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_enablemanualux_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_srmfci_enableshellaccesscheck","displayName":"Enable access-denied assistance on client for all file types","description":"This Group Policy Setting should be set on Windows clients to enable access-denied assistance for all file types\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-srmfci#admx-srmfci-enableshellaccesscheck"],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_enableshellaccesscheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_enableshellaccesscheck_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_hidepoweroptions","displayName":"Remove and prevent access to the Shut Down, Restart, Sleep, and Hibernate commands","description":"This policy setting prevents users from performing the following commands from the Windows security screen, the logon screen, and the Start menu: Shut Down, Restart, Sleep, and Hibernate. This policy setting does not prevent users from running Windows-based programs that perform these functions.\r\n\r\nIf you enable this policy setting, the shutdown, restart, sleep, and hibernate commands are removed from the Start menu. The Power button is also removed from the Windows Security screen, which appears when you press CTRL+ALT+DELETE, and from the logon screen.\r\n\r\nIf you disable or do not configure this policy setting, the Power button and the Shut Down, Restart, Sleep, and Hibernate commands are available on the Start menu. The Power button on the Windows Security and logon screens is also available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-hidepoweroptions"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_hidepoweroptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_hidepoweroptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_nochangestartmenu","displayName":"Prevent users from customizing their Start Screen","description":"This policy setting allows you to prevent users from changing their Start screen layout.\n\nIf you enable this setting, you will prevent a user from selecting an app, resizing a tile, pinning/unpinning a tile or a secondary tile, entering the customize mode and rearranging tiles within Start and Apps.\n\nIf you disable or do not configure this setting, you will allow a user to select an app, resize a tile, pin/unpin a tile or a secondary tile, enter the customize mode and rearrange tiles within Start and Apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nochangestartmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nochangestartmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nochangestartmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist","displayName":"Remove All Programs list from the Start menu","description":"If you enable this setting, the Start Menu will either collapse or remove the all apps list from the Start menu.\r\n\r\nSelecting \"Collapse\" will not display the app list next to the pinned tiles in Start. An \"All apps\" button will be displayed on Start to open the all apps list. This is equivalent to setting the \"Show app list in Start\" in Settings to Off.\r\n\r\nSelecting \"Collapse and disable setting\" will do the same as the collapse option and disable the \"Show app list in Start menu\" in Settings, so users cannot turn it to On.\r\n\r\nSelecting \"Remove and disable setting\" will remove the all apps list from Start and disable the \"Show app list in Start menu\" in Settings, so users cannot turn it to On. Select this option for compatibility with earlier versions of Windows.\r\n\r\nIf you disable or do not configure this setting, the all apps list will be visible by default, and the user can change \"Show app list in Start\" in Settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nomoreprogramslist"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown","displayName":"Choose one of the following actions","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_0","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_3","displayName":"Collapse","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_2","displayName":"Collapse and disable setting","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_1","displayName":"Remove and disable setting","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_norun","displayName":"Remove Run menu from Start Menu","description":"Allows you to remove the Run command from the Start menu, Internet Explorer, and Task Manager.\n\nIf you enable this setting, the following changes occur:\n\n(1) The Run command is removed from the Start menu.\n\n(2) The New Task (Run) command is removed from Task Manager.\n\n(3) The user will be blocked from entering the following into the Internet Explorer Address Bar:\n\n--- A UNC path: \\\\\\\n\n---Accessing local drives: e.g., C:\n\n--- Accessing local folders: e.g., \\temp>\n\nAlso, users with extended keyboards will no longer be able to display the Run dialog box by pressing the Application key (the key with the Windows logo) + R.\n\nIf you disable or do not configure this setting, users will be able to access the Run command in the Start menu and in Task Manager and use the Internet Explorer Address Bar.\n\n\n\nNote:This setting affects the specified interface only. It does not prevent users from using other methods to run programs.\n\nNote: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-norun"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_norun_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_norun_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_nosettaskbar","displayName":"Prevent changes to Taskbar and Start Menu Settings","description":"This policy setting allows you to prevent changes to Taskbar and Start Menu Settings.\n\nIf you enable this policy setting, The user will be prevented from opening the Taskbar Properties dialog box.\n\nIf the user right-clicks the taskbar and then clicks Properties, a message appears explaining that a setting prevents the action.\n\nIf you disable or do not configure this policy setting, the Taskbar and Start Menu items are available from Settings on the Start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosettaskbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nosettaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nosettaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_notraycontextmenu","displayName":"Remove access to the context menus for the taskbar","description":"This policy setting allows you to remove access to the context menus for the taskbar.\n\nIf you enable this policy setting, the menus that appear when you right-click the taskbar and items on the taskbar are hidden, such as the Start button, the clock, and the taskbar buttons.\n\nIf you disable or do not configure this policy setting, the context menus for the taskbar are available.\n\nThis policy setting does not prevent users from using other methods to issue the commands that appear on these menus.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-notraycontextmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_notraycontextmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_notraycontextmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart","displayName":"Prevent users from uninstalling applications from Start","description":"If you enable this setting, users cannot uninstall apps from Start.\n\nIf you disable this setting or do not configure it, users can access the uninstall command from Start","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nouninstallfromstart"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled","displayName":"Pin Apps to Start when installed","description":"This policy setting allows pinning apps to Start by default, when they are included by AppID on the list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-startpinappswheninstalled"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_startpinappswheninstalled_name","displayName":"Add AppIDs to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_systemrestore_sr_disableconfig","displayName":"Turn off Configuration","description":"Allows you to disable System Restore configuration through System Protection.\r\n\r\nThis policy setting allows you to turn off System Restore configuration through System Protection.\r\n\r\nSystem Restore enables users, in the event of a problem, to restore their computers to a previous state without losing personal data files. The behavior of this policy setting depends on the \"Turn off System Restore\" policy setting.\r\n\r\nIf you enable this policy setting, the option to configure System Restore through System Protection is disabled.\r\n\r\nIf you disable or do not configure this policy setting, users can change the System Restore settings through System Protection. \r\n\r\nAlso, see the \"Turn off System Restore\" policy setting. If the \"Turn off System Restore\" policy setting is enabled, the \"Turn off System Restore configuration\" policy setting is overwritten.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-systemrestore#admx-systemrestore-sr-disableconfig"],"categoryId":"5c9a2f21-d3a8-4295-a803-e0535aa29489","categoryName":"System Restore","options":[{"id":"device_vendor_msft_policy_config_admx_systemrestore_sr_disableconfig_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_systemrestore_sr_disableconfig_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_autocomplete_2","displayName":"Turn off AutoComplete integration with Input Panel","description":"Turns off the integration of application auto complete lists with Tablet PC Input Panel in applications where this behavior is available.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, application auto complete lists will never appear next to Input Panel. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, application auto complete lists will appear next to Input Panel in applications where the functionality is available. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, application auto complete lists will appear next to Input Panel in applications where the functionality is available. Users will be able to configure this setting on the Text completion tab in Input Panel Options.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-autocomplete-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_autocomplete_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_autocomplete_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_edgetarget_2","displayName":"Prevent Input Panel tab from appearing","description":"Prevents Input Panel tab from appearing on the edge of the Tablet PC screen.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel tab will not appear on the edge of the Tablet PC screen. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel tab will appear on the edge of the Tablet PC screen. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel tab will appear on the edge of the Tablet PC screen. Users will be able to configure this setting on the Opening tab in Input Panel Options.\r\n\r\nCaution: If you enable both the “Prevent Input Panel from appearing next to text entry areas” policy and the “Prevent Input Panel tab from appearing” policy, and disable the “Show Input Panel taskbar icon” policy, the user will then have no way to access Input Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-edgetarget-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_edgetarget_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_edgetarget_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_2","displayName":"For tablet pen input, don’t show the Input Panel icon","description":"Prevents the Tablet PC Input Panel icon from appearing next to any text entry area in applications where this behavior is available. This policy applies only when using a tablet pen as an input device.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel will never appear next to text entry areas when using a tablet pen as an input device. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel will appear next to any text entry area in applications where this behavior is available. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel will appear next to text entry areas in applications where this behavior is available. Users will be able to configure this setting on the Opening tab in Input Panel Options.\r\n\r\nCaution: If you enable both the “Prevent Input Panel from appearing next to text entry areas” policy and the “Prevent Input Panel tab from appearing” policy, and disable the “Show Input Panel taskbar icon” policy, the user will then have no way to access Input Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-iptiptarget-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptouchtarget_2","displayName":"For touch input, don’t show the Input Panel icon","description":"Prevents the Tablet PC Input Panel icon from appearing next to any text entry area in applications where this behavior is available. This policy applies only when a user is using touch input.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel will never appear next to any text entry area when a user is using touch input. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel will appear next to text entry areas in applications where this behavior is available. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel will appear next to text entry areas in applications where this behavior is available. Users will be able to configure this setting on the Opening tab in Input Panel Options.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-iptiptouchtarget-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptouchtarget_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptouchtarget_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2","displayName":"Turn off password security in Input Panel","description":"Adjusts password security settings in Touch Keyboard and Handwriting panel (a.k.a. Tablet PC Input Panel in Windows 7 and Windows Vista). These settings include using the on-screen keyboard by default, preventing users from switching to another Input Panel skin (the writing pad or character pad), and not showing what keys are tapped when entering a password.\r\n\r\nTouch Keyboard and Handwriting panel enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy and choose “Low” from the drop-down box, password security is set to “Low.” At this setting, all password security settings are turned off. Users will not be able to configure this setting in the Input Panel Options dialog box. \r\n\r\nIf you enable this policy and choose “Medium-Low” from the drop-down box, password security is set to “Medium-Low.” At this setting, when users enter passwords from Input Panel they use the on-screen keyboard by default, skin switching is allowed, and Input Panel displays the cursor and which keys are tapped. Users will not be able to configure this setting in the Input Panel Options dialog box. \r\n\r\nIf you enable this policy and choose “Medium” from the drop-down box, password security is set to “Medium.” At this setting, when users enter passwords from Input Panel they use the on-screen keyboard by default, skin switching is not allowed, and Input Panel displays the cursor and which keys are tapped. Users will not be able to configure this setting in the Input Panel Options dialog box. \r\n\r\nIf you enable this policy and choose to “Medium-High” from the drop-down box, password security is set to “Medium-High.” At this setting, when users enter passwords from Input Panel they use the on-screen keyboard by default, skin switching is allowed, and Input Panel does not display the cursor or which keys are tapped. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you enable this policy and choose “High” from the drop-down box, password security is set to “High.” At this setting, when users enter passwords from Input Panel they use the on-screen keyboard by default, skin switching is not allowed, and Input Panel does not display the cursor or which keys are tapped. Users will not be able to configure this setting in the Input Panel Options dialog box. \r\n\r\nIf you disable this policy, password security is set to “Medium-High.” At this setting, when users enter passwords from Input Panel they use the on-screen keyboard by default, skin switching is allowed, and Input Panel does not display the cursor or which keys are tapped. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n \r\nIf you do not configure this policy, password security is set to “Medium-High” by default. At this setting, when users enter passwords from Input Panel they use the on-screen keyboard by default, skin switching is allowed, and Input Panel does not display the cursor or which keys are tapped. Users will be able to configure this setting on the Advanced tab in Input Panel Options in Windows 7 and Windows Vista.\r\n\r\nCaution: If you lower password security settings, people who can see the user’s screen might be able to see their passwords.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-passwordsecurity-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity","displayName":"Turn off password security in Input Panel","description":null,"helpText":"","infoUrls":[],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_1","displayName":"Low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_3","displayName":"Medium","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_4","displayName":"Medium High","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_5","displayName":"High","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_prediction_2","displayName":"Disable text prediction","description":"Prevents the Touch Keyboard and Handwriting panel (a.k.a. Tablet PC Input Panel in Windows 7 and Windows Vista) from providing text prediction suggestions. This policy applies for both the on-screen keyboard and the handwriting tab when the feature is available for the current input area and input language.\r\n\r\nTouch Keyboard and Handwriting panel enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel will not provide text prediction suggestions. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel will provide text prediction suggestions. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel will provide text prediction suggestions. Users will be able to configure this setting on the Text Completion tab in Input Panel Options in Windows 7 and Windows Vista.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-prediction-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_prediction_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_prediction_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_rarechar_2","displayName":"Include rarely used Chinese, Kanji, or Hanja characters","description":"Includes rarely used Chinese, Kanji, and Hanja characters when handwriting is converted to typed text. This policy applies only to the use of the Microsoft recognizers for Chinese (Simplified), Chinese (Traditional), Japanese, and Korean. This setting appears in Input Panel Options (in Windows 7 and Windows Vista only) only when these input languages or keyboards are installed. \r\n\r\nTouch Keyboard and Handwriting panel (a.k.a. Tablet PC Input Panel in Windows 7 and Windows Vista) enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, rarely used Chinese, Kanji, and Hanja characters will be included in recognition results when handwriting is converted to typed text. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, rarely used Chinese, Kanji, and Hanja characters will not be included in recognition results when handwriting is converted to typed text. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, rarely used Chinese, Kanji, and Hanja characters will not be included in recognition results when handwriting is converted to typed text. Users will be able to configure this setting on the Ink to text conversion tab in Input Panel Options (in Windows 7 and Windows Vista).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-rarechar-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_rarechar_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_rarechar_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2","displayName":"Turn off tolerant and Z-shaped scratch-out gestures","description":"\r\n Turns off both the more tolerant scratch-out gestures that were added in Windows Vista and the Z-shaped scratch-out gesture that was available in Microsoft Windows XP Tablet PC Edition.\r\n\r\n The tolerant gestures let users scratch out ink in Input Panel by using strikethrough and other scratch-out gesture shapes.\r\n\r\n Tablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\n If you enable this policy and choose “All” from the drop-down menu, no scratch-out gestures will be available in Input Panel. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\n If you enable this policy and choose “Tolerant,\" users will be able to use the Z-shaped scratch-out gesture that was available in Microsoft Windows XP Tablet PC Edition. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\n If you enable this policy and choose “None,” users will be able to use both the tolerant scratch-out gestures and the Z-shaped scratch-out gesture. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\n If you disable this policy, users will be able to use both the tolerant scratch-out gestures and the Z-shaped scratch-out gesture. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\n If you do not configure this policy, users will be able to use both the tolerant scratch-out gestures and the Z-shaped scratch-out gesture. Users will be able to configure this setting on the Gestures tab in Input Panel Options.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-scratchout-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout","displayName":"Turn off tolerant and Z-shaped scratch-out gestures","description":null,"helpText":"","infoUrls":[],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout_1","displayName":"All","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout_2","displayName":"Tolerant","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout_3","displayName":"None","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disableinkball_2","displayName":"Do not allow Inkball to run","description":"Prevents start of InkBall game.\r\n\r\nIf you enable this policy, the InkBall game will not run.\r\n\r\nIf you disable this policy, the InkBall game will run.\r\n\r\nIf you do not configure this policy, the InkBall game will run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-disableinkball-2"],"categoryId":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","categoryName":"Accessories","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_disableinkball_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disableinkball_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablejournal_2","displayName":"Do not allow Windows Journal to be run","description":"Prevents start of Windows Journal.\r\n\r\nIf you enable this policy, the Windows Journal accessory will not run.\r\n\r\nIf you disable this policy, the Windows Journal accessory will run.\r\n\r\nIf you do not configure this policy, the Windows Journal accessory will run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-disablejournal-2"],"categoryId":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","categoryName":"Accessories","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablejournal_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablejournal_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablenotewriterprinting_2","displayName":"Do not allow printing to Journal Note Writer","description":"Prevents printing to Journal Note Writer.\r\n\r\nIf you enable this policy, the Journal Note Writer printer driver will not allow printing to it. It will remain displayed in the list of available printers, but attempts to print to it will fail.\r\n\r\nIf you disable this policy, you will be able to use this feature to print to a Journal Note.\r\n\r\nIf you do not configure this policy, users will be able to use this feature to print to a Journal Note.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-disablenotewriterprinting-2"],"categoryId":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","categoryName":"Accessories","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablenotewriterprinting_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablenotewriterprinting_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablesnippingtool_2","displayName":"Do not allow Snipping Tool to run","description":"Prevents the snipping tool from running.\r\n\r\nIf you enable this policy setting, the Snipping Tool will not run.\r\n\r\nIf you disable this policy setting, the Snipping Tool will run.\r\n\r\nIf you do not configure this policy setting, the Snipping Tool will run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-disablesnippingtool-2"],"categoryId":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","categoryName":"Accessories","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablesnippingtool_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disablesnippingtool_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventbackescmapping_2","displayName":"Prevent Back-ESC mapping","description":"Removes the Back->ESC mapping that normally occurs when menus are visible, and for applications that subscribe to this behavior.\r\n\r\nIf you enable this policy, a button assigned to Back will not map to ESC.\r\n\r\nIf you disable this policy, Back->ESC mapping will occur.\r\n\r\nIf you do not configure this policy, Back->ESC mapping will occur.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventbackescmapping-2"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventbackescmapping_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventbackescmapping_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflicks_2","displayName":"Prevent flicks","description":"Makes pen flicks and all related features unavailable.\r\n\r\nIf you enable this policy, pen flicks and all related features are unavailable. This includes: pen flicks themselves, pen flicks training, pen flicks training triggers in Internet Explorer, the pen flicks notification and the pen flicks tray icon.\r\n\r\nIf you disable or do not configure this policy, pen flicks and related features are available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventflicks-2"],"categoryId":"b524d6e2-75bc-4409-ae3d-07605707d7ee","categoryName":"Pen UX Behaviors","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflicks_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflicks_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflickslearningmode_2","displayName":"Prevent Flicks Learning Mode","description":"Makes pen flicks learning mode unavailable.\r\n\r\nIf you enable this policy, pen flicks are still available but learning mode is not. Pen flicks are off by default and can be turned on system-wide, but cannot be restricted to learning mode applications. This means that the pen flicks training triggers in Internet Explorer are disabled and that the pen flicks notification will never be displayed. However, pen flicks, the pen flicks tray icon and pen flicks training (that can be accessed through CPL) are still available. Conceptually this policy is a subset of the Disable pen flicks policy.\r\n\r\nIf you disable or do not configure this policy, all the features described above will be available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventflickslearningmode-2"],"categoryId":"6f0e6df6-8654-4b57-b1d5-2160c5a0a54e","categoryName":"Pen Flicks Learning","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflickslearningmode_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflickslearningmode_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_2","displayName":"Prevent launch an application","description":"Prevents the user from launching an application from a Tablet PC hardware button.\r\n\r\nIf you enable this policy, applications cannot be launched from a hardware button, and \"Launch an application\" is removed from the drop down menu for configuring button actions (in the Tablet PC Control Panel buttons tab).\r\n\r\nIf you disable this policy, applications can be launched from a hardware button.\r\n\r\nIf you do not configure this policy, applications can be launched from a hardware button.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventlaunchapp-2"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventpressandhold_2","displayName":"Prevent press and hold","description":"Prevents press and hold actions on hardware buttons, so that only one action is available per button.\r\n\r\nIf you enable this policy, press and hold actions are unavailable, and the button configuration dialog will display the following text: \"Some settings are controlled by Group Policy. If a setting is unavailable, contact your system administrator.\"\r\n\r\nIf you disable this policy, press and hold actions for buttons will be available.\r\n\r\nIf you do not configure this policy, press and hold actions will be available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventpressandhold-2"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventpressandhold_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventpressandhold_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnoffbuttons_2","displayName":"Turn off hardware buttons","description":"Turns off Tablet PC hardware buttons.\r\n\r\nIf you enable this policy, no actions will occur when the buttons are pressed, and the buttons tab in Tablet PC Control Panel will be removed.\r\n\r\nIf you disable this policy, user and OEM defined button actions will occur when the buttons are pressed.\r\n\r\nIf you do not configure this policy, user and OEM defined button actions will occur when the buttons are pressed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-turnoffbuttons-2"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnoffbuttons_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnoffbuttons_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnofffeedback_2","displayName":"Turn off pen feedback","description":"Disables visual pen action feedback, except for press and hold feedback.\r\n\r\nIf you enable this policy, all visual pen action feedback is disabled except for press and hold feedback. Additionally, the mouse cursors are shown instead of the pen cursors.\r\n\r\nIf you disable or do not configure this policy, visual feedback and pen cursors will be shown unless the user disables them in Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-turnofffeedback-2"],"categoryId":"9b894b32-3697-4a83-9731-3db2a35455ad","categoryName":"Cursors","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnofffeedback_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnofffeedback_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_taskbar_disablenotificationcenter","displayName":"Remove Notifications and Action Center","description":"This policy setting removes Notifications and Action Center from the notification area on the taskbar.\n\nThe notification area is located at the far right end of the taskbar and includes icons for current notifications and the system clock.\n\nIf this setting is enabled, Notifications and Action Center is not displayed in the notification area. The user will be able to read notifications when they appear, but they won’t be able to review any notifications they miss.\n\nIf you disable or do not configure this policy setting, Notification and Security and Maintenance will be displayed on the taskbar.\n\nA reboot is required for this policy setting to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-disablenotificationcenter"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_taskbar_disablenotificationcenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_taskbar_disablenotificationcenter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_taskbar_taskbarnopinnedlist","displayName":"Remove pinned programs from the Taskbar","description":"This policy setting allows you to remove pinned programs from the taskbar.\n\nIf you enable this policy setting, pinned programs are prevented from being shown on the Taskbar. Users cannot pin programs to the Taskbar.\n\nIf you disable or do not configure this policy setting, users can pin programs so that the program shortcuts stay on the Taskbar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-taskbarnopinnedlist"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_taskbar_taskbarnopinnedlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_taskbar_taskbarnopinnedlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name","displayName":"Set 6to4 Relay Name","description":"This policy setting allows you to specify a 6to4 relay name for a 6to4 host. A 6to4 relay is used as a default gateway for IPv6 network traffic sent by the 6to4 host. The 6to4 relay name setting has no effect if 6to4 connectivity is not available on the host.\r\n\r\nIf you enable this policy setting, you can specify a relay name for a 6to4 host.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used, and you cannot specify a relay name for a 6to4 host.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-6to4-router-name"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval","displayName":"Set 6to4 Relay Name Resolution Interval","description":"This policy setting allows you to specify the interval at which the relay name is resolved. The 6to4 relay name resolution interval setting has no effect if 6to4 connectivity is not available on the host.\r\n\r\nIf you enable this policy setting, you can specify the value for the duration at which the relay name is resolved periodically.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-6to4-router-name-resolution-interval"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval_routernameresolutionintervalbox","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_routernamebox","displayName":"Enter a router or relay name:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state","displayName":"Set 6to4 State","description":"This policy setting allows you to configure 6to4, an address assignment and router-to-router automatic tunneling technology that is used to provide unicast IPv6 connectivity between IPv6 sites and hosts across the IPv4 Internet. 6to4 uses the global address prefix: 2002:WWXX:YYZZ::/48 in which the letters are a hexadecimal representation of the global IPv4 address (w.x.y.z) assigned to a site.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\nIf you enable this policy setting, you can configure 6to4 with one of the following settings:\r\n\r\nPolicy Default State: 6to4 is enabled if the host has only link-local IPv6 connectivity and a public IPv4 address. If no global IPv6 address is present and no global IPv4 address is present, the host will not have a 6to4 interface. If no global IPv6 address is present and a global IPv4 address is present, the host will have a 6to4 interface.\r\n\r\nPolicy Enabled State: If a global IPv4 address is present, the host will have a 6to4 interface. If no global IPv4 address is present, the host will not have a 6to4 interface.\r\n\r\nPolicy Disabled State: 6to4 is turned off and connectivity with 6to4 will not be available.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-6to4-state"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state_stateselect","displayName":"Select from the following states:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state_stateselect_default","displayName":"Default State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state_stateselect_enabled","displayName":"Enabled State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_state_stateselect_disabled","displayName":"Disabled State","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_ip_stateless_autoconfiguration_limits_state","displayName":"Set IP Stateless Autoconfiguration Limits State","description":"This policy setting allows you to configure IP Stateless Autoconfiguration Limits.\r\n\r\nIf you enable or do not configure this policy setting, IP Stateless Autoconfiguration Limits will be enabled and system will limit the number of autoconfigured addresses and routes.\r\n\r\nIf you disable this policy setting, IP Stateless Autoconfiguration Limits will be disabled and system will not limit the number of autoconfigured addresses and routes.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-ip-stateless-autoconfiguration-limits-state"],"categoryId":"91789113-6339-4e96-8e1d-73a4dec4967f","categoryName":"Parameters","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_ip_stateless_autoconfiguration_limits_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_ip_stateless_autoconfiguration_limits_state_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate","displayName":"Set IP-HTTPS State","description":"This policy setting allows you to configure IP-HTTPS, a tunneling technology that uses the HTTPS protocol to provide IP connectivity to a remote network.\r\n\r\nIf you disable or do not configure this policy setting, the local host settings are used.\r\n\r\nIf you enable this policy setting, you can specify an IP-HTTPS server URL. You will be able to configure IP-HTTPS with one of the following settings:\r\n\r\nPolicy Default State: The IP-HTTPS interface is used when there are no other connectivity options.\r\n\r\nPolicy Enabled State: The IP-HTTPS interface is always present, even if the host has other connectivity options.\r\n\r\nPolicy Disabled State: No IP-HTTPS interfaces are present on the host.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-iphttps-clientstate"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_iphttpsclienturlbox","displayName":"Enter the IPHTTPS Url:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_stateselect","displayName":"Select Interface state from the following options:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_stateselect_0","displayName":"Default State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_stateselect_2","displayName":"Enabled State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_stateselect_3","displayName":"Disabled State","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_router_name","displayName":"Set ISATAP Router Name","description":"This policy setting allows you to specify a router name or Internet Protocol version 4 (IPv4) address for an ISATAP router.\r\n\r\nIf you enable this policy setting, you can specify a router name or IPv4 address for an ISATAP router. If you enter an IPv4 address of the ISATAP router in the text box, DNS services are not required.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-isatap-router-name"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_router_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_router_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_router_name_routernamebox","displayName":"Enter a router or relay name:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state","displayName":"Set ISATAP State","description":"This policy setting allows you to configure Intra-Site Automatic Tunnel Addressing Protocol (ISATAP), an address-to-router and host-to-host, host-to-router and router-to-host automatic tunneling technology that is used to provide unicast IPv6 connectivity between IPv6 hosts across an IPv4 intranet.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\nIf you enable this policy setting, you can configure ISATAP with one of the following settings:\r\n\r\nPolicy Default State: If the ISATAP router name is resolved successfully, the host will have ISATAP configured with a link-local address and an address for each prefix received from the ISATAP router through stateless address auto-configuration. If the ISATAP router name is not resolved successfully, ISATAP connectivity is not available on the host using the corresponding IPv4 address.\r\n\r\nPolicy Enabled State: If the ISATAP name is resolved successfully, the host will have ISATAP configured with a link-local address and an address for each prefix received from the ISATAP router through stateless address auto-configuration. If the ISATAP name is not resolved successfully, the host will have an ISATAP interface configured with a link-local address.\r\n\r\nPolicy Disabled State: No ISATAP interfaces are present on the host.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-isatap-state"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_stateselect","displayName":"Select from the following states:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_stateselect_default","displayName":"Default State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_stateselect_enabled","displayName":"Enabled State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_stateselect_disabled","displayName":"Disabled State","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_client_port","displayName":"Set Teredo Client Port","description":"This policy setting allows you to select the UDP port the Teredo client will use to send packets. If you leave the default of 0, the operating system will select a port (recommended). If you select a UDP port that is already in use by a system, the Teredo client will fail to initialize.\r\n\r\nIf you enable this policy setting, you can customize a UDP port for the Teredo client.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-client-port"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_client_port_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_client_port_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_client_port_teredoclientportbox","displayName":"The range is 0 to 65535. Default (recommended) is 0 which is to let the local system pick the port.","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_default_qualified","displayName":"Set Teredo Default Qualified","description":"This policy setting allows you to set Teredo to be ready to communicate, a process referred to as qualification. By default, Teredo enters a dormant state when not in use. The qualification process brings it out of a dormant state.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\nThis policy setting contains only one state:\r\n\r\nPolicy Enabled State: If Default Qualified is enabled, Teredo will attempt qualification immediately and remain qualified if the qualification process succeeds.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-default-qualified"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_default_qualified_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_default_qualified_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_default_qualified_stateselect","displayName":"Select from the following states:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_default_qualified_stateselect_enabled","displayName":"Enabled State","description":null,"helpText":null}},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate","displayName":"Set Teredo Refresh Rate","description":"This policy setting allows you to configure the Teredo refresh rate.\r\n\r\nNote: On a periodic basis (by default, every 30 seconds), Teredo clients send a single Router Solicitation packet to the Teredo server. The Teredo server sends a Router Advertisement Packet in response. This periodic packet refreshes the IP address and UDP port mapping in the translation table of the Teredo client's NAT device.\r\n\r\nIf you enable this policy setting, you can specify the refresh rate. If you choose a refresh rate longer than the port mapping in the Teredo client's NAT device, Teredo might stop working or connectivity might be intermittent.\r\n\r\nIf you disable or do not configure this policy setting, the refresh rate is configured using the local settings on the computer. The default refresh rate is 30 seconds.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-refresh-rate"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate_teredorefreshratebox","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name","displayName":"Set Teredo Server Name","description":"This policy setting allows you to specify the name of the Teredo server. This server name will be used on the Teredo client computer where this policy setting is applied.\r\n\r\nIf you enable this policy setting, you can specify a Teredo server name that applies to a Teredo client.\r\n\r\nIf you disable or do not configure this policy setting, the local settings on the computer are used to determine the Teredo server name.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-server-name"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name_teredoservernamebox","displayName":"Enter a Teredo server name:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state","displayName":"Set Teredo State","description":"This policy setting allows you to configure Teredo, an address assignment and automatic tunneling technology that provides unicast IPv6 connectivity across the IPv4 Internet.\r\n\r\nIf you disable or do not configure this policy setting, the local host settings are used.\r\n\r\nIf you enable this policy setting, you can configure Teredo with one of the following settings:\r\n\r\nDefault: The default state is \"Client.\"\r\n\r\nDisabled: No Teredo interfaces are present on the host.\r\n\r\nClient: The Teredo interface is present only when the host is not on a network that includes a domain controller.\r\n\r\nEnterprise Client: The Teredo interface is always present, even if the host is on a network that includes a domain controller.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-state"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect","displayName":"Select from the following states:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_default","displayName":"Default State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_disabled","displayName":"Disabled State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_client","displayName":"Client","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_enterprise client","displayName":"Enterprise Client","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tcpip_windows_scaling_heuristics_state","displayName":"Set Window Scaling Heuristics State","description":"This policy setting allows you to configure Window Scaling Heuristics. Window Scaling Heuristics is an algorithm to identify connectivity and throughput problems caused by many Firewalls and other middle boxes that don't interpret Window Scaling option correctly.\r\n\r\nIf you do not configure this policy setting, the local host settings are used.\r\n\r\nIf you enable this policy setting, Window Scaling Heuristics will be enabled and system will try to identify connectivity and throughput problems and take appropriate measures.\r\n\r\nIf you disable this policy setting, Window Scaling Heuristics will be disabled and system will not try to identify connectivity and throughput problems casued by Firewalls or other middle boxes.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-windows-scaling-heuristics-state"],"categoryId":"91789113-6339-4e96-8e1d-73a4dec4967f","categoryName":"Parameters","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_windows_scaling_heuristics_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_windows_scaling_heuristics_state_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_auto_reconnect","displayName":"Automatic reconnection","description":"Specifies whether to allow Remote Desktop Connection clients to automatically reconnect to sessions on an RD Session Host server if their network link is temporarily lost. By default, a maximum of twenty reconnection attempts are made at five second intervals.\r\n\r\nIf the status is set to Enabled, automatic reconnection is attempted for all clients running Remote Desktop Connection whenever their network connection is lost.\r\n\r\nIf the status is set to Disabled, automatic reconnection of clients is prohibited.\r\n\r\nIf the status is set to Not Configured, automatic reconnection is not specified at the Group Policy level. However, users can configure automatic reconnection using the \"Reconnect if connection is dropped\" checkbox on the Experience tab in Remote Desktop Connection.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-auto-reconnect"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_auto_reconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_auto_reconnect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_camera_redirection","displayName":"Do not allow video capture redirection","description":"This policy setting lets you control the redirection of video capture devices to the remote computer in a Remote Desktop Services session. \r\n\r\nBy default, Remote Desktop Services allows redirection of video capture devices.\r\n\r\nIf you enable this policy setting, users cannot redirect their video capture devices to the remote computer. \r\n\r\nIf you disable or do not configure this policy setting, users can redirect their video capture devices to the remote computer. Users can use the More option on the Local Resources tab of Remote Desktop Connection to choose the video capture devices to redirect to the remote computer.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-camera-redirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_camera_redirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_camera_redirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy","displayName":"Server authentication certificate template","description":"This policy setting allows you to specify the name of the certificate template that determines which certificate is automatically selected to authenticate an RD Session Host server.\r\n\r\nA certificate is needed to authenticate an RD Session Host server when TLS 1.0, 1.1 or 1.2 is used to secure communication between a client and an RD Session Host server during RDP connections.\r\n\r\nIf you enable this policy setting, you need to specify a certificate template name. Only certificates created by using the specified certificate template will be considered when a certificate to authenticate the RD Session Host server is automatically selected. Automatic certificate selection only occurs when a specific certificate has not been selected.\r\n\r\nIf no certificate can be found that was created with the specified certificate template, the RD Session Host server will issue a certificate enrollment request and will use the current certificate until the request is completed. If more than one certificate is found that was created with the specified certificate template, the certificate that will expire latest and that matches the current name of the RD Session Host server will be selected.\r\n\r\nIf you disable or do not configure this policy, the certificate template name is not specified at the Group Policy level. By default, a self-signed certificate is used to authenticate the RD Session Host server. \r\n\r\nNote: If you select a specific certificate to be used to authenticate the RD Session Host server, that certificate will take precedence over this policy setting.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-certificate-template-policy"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy_ts_certificate_template_name","displayName":"Certificate Template Name","description":null,"helpText":"","infoUrls":[],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_signed_files_2","displayName":"Allow .rdp files from valid publishers and user's default .rdp settings","description":"This policy setting allows you to specify whether users can run Remote Desktop Protocol (.rdp) files from a publisher that signed the file with a valid certificate. A valid certificate is one that is issued by an authority recognized by the client, such as the issuers in the client's Third-Party Root Certification Authorities certificate store. This policy setting also controls whether the user can start an RDP session by using default .rdp settings (for example, when a user directly opens the Remote Desktop Connection [RDC] client without specifying an .rdp file).\r\n\r\nIf you enable or do not configure this policy setting, users can run .rdp files that are signed with a valid certificate. Users can also start an RDP session with default .rdp settings by directly opening the RDC client. When a user starts an RDP session, the user is asked to confirm whether they want to connect.\r\n\r\nIf you disable this policy setting, users cannot run .rdp files that are signed with a valid certificate. Additionally, users cannot start an RDP session by directly opening the RDC client and specifying the remote computer name. When a user tries to start an RDP session, the user receives a message that the publisher has been blocked.\r\n\r\nNote: You can define this policy setting in the Computer Configuration node or in the User Configuration node. If you configure this policy setting for the computer, all users on the computer are affected.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-allow-signed-files-2"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_signed_files_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_signed_files_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_2","displayName":"Allow .rdp files from unknown publishers","description":"This policy setting allows you to specify whether users can run unsigned Remote Desktop Protocol (.rdp) files and .rdp files from unknown publishers on the client computer.\r\n\r\nIf you enable or do not configure this policy setting, users can run unsigned .rdp files and .rdp files from unknown publishers on the client computer. Before a user starts an RDP session, the user receives a warning message and is asked to confirm whether they want to connect.\r\n\r\nIf you disable this policy setting, users cannot run unsigned .rdp files and .rdp files from unknown publishers on the client computer. If the user tries to start an RDP session, the user receives a message that the publisher has been blocked.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-allow-unsigned-files-2"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio","displayName":"Allow audio and video playback redirection","description":"This policy setting allows you to specify whether users can redirect the remote computer's audio and video output in a Remote Desktop Services session.\r\nUsers can specify where to play the remote computer's audio output by configuring the remote audio settings on the Local Resources tab in Remote Desktop Connection (RDC). Users can choose to play the remote audio on the remote computer or on the local computer. Users can also choose to not play the audio. Video playback can be configured by using the videoplayback setting in a Remote Desktop Protocol (.rdp) file. By default, video playback is enabled.\r\n\r\nBy default, audio and video playback redirection is not allowed when connecting to a computer running Windows Server 2008 R2, Windows Server 2008, or Windows Server 2003. Audio and video playback redirection is allowed by default when connecting to a computer running Windows 8, Windows Server 2012, Windows 7, Windows Vista, or Windows XP Professional.\r\n\r\nIf you enable this policy setting, audio and video playback redirection is allowed.\r\n\r\nIf you disable this policy setting, audio and video playback redirection is not allowed, even if audio playback redirection is specified in RDC, or video playback is specified in the .rdp file.\r\n\r\nIf you do not configure this policy setting audio and video playback redirection is not specified at the Group Policy level. \r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-audio"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_capture","displayName":"Allow audio recording redirection","description":"This policy setting allows you to specify whether users can record audio to the remote computer in a Remote Desktop Services session.\r\nUsers can specify whether to record audio to the remote computer by configuring the remote audio settings on the Local Resources tab in Remote Desktop Connection (RDC). Users can record audio by using an audio input device on the local computer, such as a built-in microphone.\r\n\r\nBy default, audio recording redirection is not allowed when connecting to a computer running Windows Server 2008 R2. Audio recording redirection is allowed by default when connecting to a computer running at least Windows 7, or Windows Server 2008 R2. \r\n\r\nIf you enable this policy setting, audio recording redirection is allowed.\r\n\r\nIf you disable this policy setting, audio recording redirection is not allowed, even if audio recording redirection is specified in RDC.\r\n\r\nIf you do not configure this policy setting, Audio recording redirection is not specified at the Group Policy level.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-audio-capture"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_capture_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_capture_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality","displayName":"Limit audio playback quality","description":"This policy setting allows you to limit the audio playback quality for a Remote Desktop Services session. Limiting the quality of audio playback can improve connection performance, particularly over slow links.\r\n\r\nIf you enable this policy setting, you must select one of the following: High, Medium, or Dynamic. If you select High, the audio will be sent without any compression and with minimum latency. This requires a large amount of bandwidth. If you select Medium, the audio will be sent with some compression and with minimum latency as determined by the codec that is being used. If you select Dynamic, the audio will be sent with a level of compression that is determined by the bandwidth of the remote connection.\r\n\r\nThe audio playback quality that you specify on the remote computer by using this policy setting is the maximum quality that can be used for a Remote Desktop Services session, regardless of the audio playback quality configured on the client computer. For example, if the audio playback quality configured on the client computer is higher than the audio playback quality configured on the remote computer, the lower level of audio playback quality will be used.\r\n\r\nAudio playback quality can be configured on the client computer by using the audioqualitymode setting in a Remote Desktop Protocol (.rdp) file. By default, audio playback quality is set to Dynamic.\r\n\r\nIf you disable or do not configure this policy setting, audio playback quality will be set to Dynamic.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-audio-quality"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level","displayName":"Audio Quality","description":null,"helpText":"","infoUrls":[],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level_1","displayName":"Dynamic","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level_3","displayName":"Medium","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level_7","displayName":"High","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_clipboard","displayName":"Do not allow Clipboard redirection","description":"This policy setting specifies whether to prevent the sharing of Clipboard contents (Clipboard redirection) between a remote computer and a client computer during a Remote Desktop Services session.\r\n\r\nYou can use this setting to prevent users from redirecting Clipboard data to and from the remote computer and the local computer. By default, Remote Desktop Services allows Clipboard redirection.\r\n\r\nIf you enable this policy setting, users cannot redirect Clipboard data.\r\n\r\nIf you disable this policy setting, Remote Desktop Services always allows Clipboard redirection.\r\n\r\nIf you do not configure this policy setting, Clipboard redirection is not specified at the Group Policy level. \r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-clipboard"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_clipboard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_clipboard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_com","displayName":"Do not allow COM port redirection","description":"This policy setting specifies whether to prevent the redirection of data to client COM ports from the remote computer in a Remote Desktop Services session.\r\n\r\nYou can use this setting to prevent users from redirecting data to COM port peripherals or mapping local COM ports while they are logged on to a Remote Desktop Services session. By default, Remote Desktop Services allows this COM port redirection.\r\n\r\nIf you enable this policy setting, users cannot redirect server data to the local COM port.\r\n\r\nIf you disable this policy setting, Remote Desktop Services always allows COM port redirection.\r\n\r\nIf you do not configure this policy setting, COM port redirection is not specified at the Group Policy level. \r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-com"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_com_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_com_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_default_m","displayName":"Do not set default client printer to be default printer in a session","description":"This policy setting allows you to specify whether the client default printer is automatically set as the default printer in a session on an RD Session Host server.\r\n\r\nBy default, Remote Desktop Services automatically designates the client default printer as the default printer in a session on an RD Session Host server. You can use this policy setting to override this behavior.\r\n\r\nIf you enable this policy setting, the default printer is the printer specified on the remote computer.\r\n\r\nIf you disable this policy setting, the RD Session Host server automatically maps the client default printer and sets it as the default printer upon connection.\r\n\r\nIf you do not configure this policy setting, the default printer is not specified at the Group Policy level.\r\n\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-default-m"],"categoryId":"f1455024-7de9-448f-8d8f-a42db2af0a35","categoryName":"Printer Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_default_m_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_default_m_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_hardware_mode","displayName":"Do not allow hardware accelerated decoding","description":"This policy setting specifies whether the Remote Desktop Connection can use hardware acceleration if supported hardware is available. If you use this setting, the Remote Desktop Client will use only software decoding. For example, if you have a problem that you suspect may be related to hardware acceleration, use this setting to disable the acceleration; then, if the problem still occurs, you will know that there are additional issues to investigate. If you disable this setting or leave it not configured, the Remote Desktop client will use hardware accelerated decoding if supported hardware is available.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-disable-hardware-mode"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_hardware_mode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_hardware_mode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_lpt","displayName":"Do not allow LPT port redirection","description":"This policy setting specifies whether to prevent the redirection of data to client LPT ports during a Remote Desktop Services session.\r\n\r\nYou can use this setting to prevent users from mapping local LPT ports and redirecting data from the remote computer to local LPT port peripherals. By default, Remote Desktop Services allows LPT port redirection.\r\n\r\nIf you enable this policy setting, users in a Remote Desktop Services session cannot redirect server data to the local LPT port.\r\n\r\nIf you disable this policy setting, LPT port redirection is always allowed.\r\n\r\nIf you do not configure this policy setting, LPT port redirection is not specified at the Group Policy level. \r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-lpt"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_lpt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_lpt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_pnp","displayName":"Do not allow supported Plug and Play device redirection","description":"This policy setting lets you control the redirection of supported Plug and Play and RemoteFX USB devices, such as Windows Portable Devices, to the remote computer in a Remote Desktop Services session. \r\n\r\nBy default, Remote Desktop Services does not allow redirection of supported Plug and Play and RemoteFX USB devices.\r\n\r\nIf you disable this policy setting, users can redirect their supported Plug and Play devices to the remote computer. Users can use the More option on the Local Resources tab of Remote Desktop Connection to choose the supported Plug and Play devices to redirect to the remote computer.\r\n\r\nIf you enable this policy setting, users cannot redirect their supported Plug and Play devices to the remote computer.If you do not configure this policy setting, users can redirect their supported Plug and Play devices to the remote computer only if it is running Windows Server 2012 R2 and earlier versions.\r\n\r\nNote: You can disable redirection of specific types of supported Plug and Play devices by using Computer Configuration\\Administrative Templates\\System\\Device Installation\\Device Installation Restrictions policy settings.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-pnp"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_pnp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_pnp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_printer","displayName":"Do not allow client printer redirection","description":"This policy setting allows you to specify whether to prevent the mapping of client printers in Remote Desktop Services sessions.\r\n\r\nYou can use this policy setting to prevent users from redirecting print jobs from the remote computer to a printer attached to their local (client) computer. By default, Remote Desktop Services allows this client printer mapping.\r\n\r\nIf you enable this policy setting, users cannot redirect print jobs from the remote computer to a local client printer in Remote Desktop Services sessions.\r\n\r\nIf you disable this policy setting, users can redirect print jobs with client printer mapping.\r\n\r\nIf you do not configure this policy setting, client printer mapping is not specified at the Group Policy level.\r\n\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-printer"],"categoryId":"f1455024-7de9-448f-8d8f-a42db2af0a35","categoryName":"Printer Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_printer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_printer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_trusted_certificate_thumbprints_1","displayName":"Specify SHA1 thumbprints of certificates representing trusted .rdp publishers","description":"This policy setting allows you to specify a list of Secure Hash Algorithm 1 (SHA1) certificate thumbprints that represent trusted Remote Desktop Protocol (.rdp) file publishers.\r\n\r\nIf you enable this policy setting, any certificate with an SHA1 thumbprint that matches a thumbprint on the list is trusted. If a user tries to start an .rdp file that is signed by a trusted certificate, the user does not receive any warning messages when they start the file. To obtain the thumbprint, view the certificate details, and then click the Thumbprint field.\r\n\r\nIf you disable or do not configure this policy setting, no publisher is treated as a trusted .rdp publisher.\r\n\r\nNotes:\r\n\r\nYou can define this policy setting in the Computer Configuration node or in the User Configuration node. If you configure this policy setting for the computer, the list of certificate thumbprints trusted for a user is a combination of the list defined for the computer and the list defined for the user.\r\n\r\nThis policy setting overrides the behavior of the \"Allow .rdp files from valid publishers and user's default .rdp settings\" policy setting.\r\n\r\nIf the list contains a string that is not a certificate thumbprint, it is ignored.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-trusted-certificate-thumbprints-1"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_trusted_certificate_thumbprints_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_trusted_certificate_thumbprints_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_trusted_certificate_thumbprints_1_trusted_certificate_thumbprints","displayName":"Comma-separated list of SHA1 trusted certificate thumbprints:","description":null,"helpText":"","infoUrls":[],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_turn_off_udp","displayName":"Turn Off UDP On Client","description":"This policy setting specifies whether the UDP protocol will be used to access servers via Remote Desktop Protocol. \r\n\r\nIf you enable this policy setting, Remote Desktop Protocol traffic will only use the TCP protocol.\r\n\r\nIf you disable or do not configure this policy setting, Remote Desktop Protocol traffic will attempt to use both TCP and UDP protocols.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-turn-off-udp"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_turn_off_udp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_turn_off_udp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth","displayName":"Limit maximum color depth","description":"This policy setting allows you to specify the maximum color resolution (color depth) for Remote Desktop Services connections.\r\n\r\nYou can use this policy setting to set a limit on the color depth of any connection that uses RDP. Limiting the color depth can improve connection performance, particularly over slow links, and reduce server load.\r\n\r\nIf you enable this policy setting, the color depth that you specify is the maximum color depth allowed for a user's RDP connection. The actual color depth for the connection is determined by the color support available on the client computer. If you select Client Compatible, the highest color depth supported by the client will be used.\r\n\r\nIf you disable or do not configure this policy setting, the color depth for connections is not specified at the Group Policy level.\r\n\r\nNote:\r\n1.\tSetting the color depth to 24 bits is only supported on Windows Server 2003 and Windows XP Professional.\r\n2.\tThe value specified in this policy setting is not applied to connections from client computers that are using at least Remote Desktop Protocol 8.0 (computers running at least Windows 8 or Windows Server 2012). The 32-bit color depth format is always used for these connections.\r\n3.\tFor connections from client computers that are using Remote Desktop Protocol 7.1 or earlier versions that are connecting to computers running at least Windows 8 or Windows Server 2012, the minimum of the following values is used as the color depth format:\r\na.\tValue specified by this policy setting\r\nb.\tMaximum color depth supported by the client\r\nc.\tValue requested by the client\r\n\r\nIf the client does not support at least 16 bits, the connection is terminated.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-colordepth"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_ts_color_depth","displayName":"Color Depth","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_ts_color_depth_999","displayName":"Client Compatible","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_ts_color_depth_2","displayName":"15 bit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_ts_color_depth_3","displayName":"16 bit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_ts_color_depth_4","displayName":"24 bit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_colordepth_ts_color_depth_5","displayName":"32 bit","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_delete_roaming_user_profiles","displayName":"Limit the size of the entire roaming user profile cache","description":"This policy setting allows you to limit the size of the entire roaming user profile cache on the local drive. This policy setting only applies to a computer on which the Remote Desktop Session Host role service is installed.\r\n\r\nNote: If you want to limit the size of an individual user profile, use the \"Limit profile size\" policy setting located in User Configuration\\Policies\\Administrative Templates\\System\\User Profiles.\r\n\r\nIf you enable this policy setting, you must specify a monitoring interval (in minutes) and a maximum size (in gigabytes) for the entire roaming user profile cache. The monitoring interval determines how often the size of the entire roaming user profile cache is checked. When the size of the entire roaming user profile cache exceeds the maximum size that you have specified, the oldest (least recently used) roaming user profiles will be deleted until the size of the entire roaming user profile cache is less than the maximum size specified.\r\n\r\nIf you disable or do not configure this policy setting, no restriction is placed on the size of the entire roaming user profile cache on the local drive.\r\n\r\nNote: This policy setting is ignored if the \"Prevent Roaming Profile changes from propagating to the server\" policy setting located in Computer Configuration\\Policies\\Administrative Templates\\System\\User Profiles is enabled.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-delete-roaming-user-profiles"],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_delete_roaming_user_profiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_delete_roaming_user_profiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_delete_roaming_user_profiles_ts_profile_directory_monitoring_interval","displayName":"Monitoring interval (minutes):","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_delete_roaming_user_profiles_ts_profile_directory_quota","displayName":"Maximum cache size (GBs):","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_disable_remote_desktop_wallpaper","displayName":"Enforce Removal of Remote Desktop Wallpaper","description":"Specifies whether desktop wallpaper is displayed to remote clients connecting via Remote Desktop Services.\r\n\r\nYou can use this setting to enforce the removal of wallpaper during a Remote Desktop Services session. By default, Windows XP Professional displays wallpaper to remote clients connecting through Remote Desktop, depending on the client configuration (see the Experience tab in the Remote Desktop Connection options for more information). Servers running Windows Server 2003 do not display wallpaper by default to Remote Desktop Services sessions.\r\n\r\nIf the status is set to Enabled, wallpaper never appears in a Remote Desktop Services session.\r\n\r\nIf the status is set to Disabled, wallpaper might appear in a Remote Desktop Services session, depending on the client configuration.\r\n\r\nIf the status is set to Not Configured, the default behavior applies.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-disable-remote-desktop-wallpaper"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_disable_remote_desktop_wallpaper_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_disable_remote_desktop_wallpaper_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_dx_use_full_hwgpu","displayName":"Use hardware graphics adapters for all Remote Desktop Services sessions","description":"This policy setting enables system administrators to change the graphics rendering for all Remote Desktop Services sessions.\r\n\r\nIf you enable this policy setting, all Remote Desktop Services sessions use the hardware graphics renderer instead of the Microsoft Basic Render Driver as the default adapter.\r\n\r\nIf you disable this policy setting, all Remote Desktop Services sessions use the Microsoft Basic Render Driver as the default adapter.\r\n\r\nIf you do not configure this policy setting, Remote Desktop Services sessions on the RD Session Host server use the Microsoft Basic Render Driver as the default adapter. In all other cases, Remote Desktop Services sessions use the hardware graphics renderer by default.\r\n\r\nNOTE: The policy setting enables load-balancing of graphics processing units (GPU) on a computer with more than one GPU installed. The GPU configuration of the local session is not affected by this policy setting.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-dx-use-full-hwgpu"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_dx_use_full_hwgpu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_dx_use_full_hwgpu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_easy_print","displayName":"Use Remote Desktop Easy Print printer driver first","description":"This policy setting allows you to specify whether the Remote Desktop Easy Print printer driver is used first to install all client printers. \r\n\r\nIf you enable or do not configure this policy setting, the RD Session Host server first tries to use the Remote Desktop Easy Print printer driver to install all client printers. If for any reason the Remote Desktop Easy Print printer driver cannot be used, a printer driver on the RD Session Host server that matches the client printer is used. If the RD Session Host server does not have a printer driver that matches the client printer, the client printer is not available for the Remote Desktop session.\r\n\r\nIf you disable this policy setting, the RD Session Host server tries to find a suitable printer driver to install the client printer. If the RD Session Host server does not have a printer driver that matches the client printer, the server tries to use the Remote Desktop Easy Print driver to install the client printer. If for any reason the Remote Desktop Easy Print printer driver cannot be used, the client printer is not available for the Remote Desktop Services session.\r\n\r\nNote: If the \"Do not allow client printer redirection\" policy setting is enabled, the \"Use Remote Desktop Easy Print printer driver first\" policy setting is ignored.\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-easy-print"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_easy_print_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_easy_print_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_enablevirtualgraphics","displayName":"Configure RemoteFX","description":"This policy setting allows you to control the availability of RemoteFX on both a Remote Desktop Virtualization Host (RD Virtualization Host) server and a Remote Desktop Session Host (RD Session Host) server.\r\n\r\nWhen deployed on an RD Virtualization Host server, RemoteFX delivers a rich user experience by rendering content on the server by using graphics processing units (GPUs). By default, RemoteFX for RD Virtualization Host uses server-side GPUs to deliver a rich user experience over LAN connections and RDP 7.1.\r\n\r\nWhen deployed on an RD Session Host server, RemoteFX delivers a rich user experience by using a hardware-accelerated compression scheme.\r\n\r\nIf you enable this policy setting, RemoteFX will be used to deliver a rich user experience over LAN connections and RDP 7.1.\r\n\r\nIf you disable this policy setting, RemoteFX will be disabled.\r\n\r\nIf you do not configure this policy setting, the default behavior will be used. By default, RemoteFX for RD Virtualization Host is enabled and RemoteFX for RD Session Host is disabled.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-enablevirtualgraphics"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_enablevirtualgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_enablevirtualgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype","displayName":"Specify RD Session Host server fallback printer driver behavior","description":"This policy setting allows you to specify the RD Session Host server fallback printer driver behavior.\r\n\r\nBy default, the RD Session Host server fallback printer driver is disabled. If the RD Session Host server does not have a printer driver that matches the client's printer, no printer will be available for the Remote Desktop Services session.\r\n\r\nIf you enable this policy setting, the fallback printer driver is enabled, and the default behavior is for the RD Session Host server to find a suitable printer driver. If one is not found, the client's printer is not available. You can choose to change this default behavior. The available options are:\r\n\r\n\"Do nothing if one is not found\" - If there is a printer driver mismatch, the server will attempt to find a suitable driver. If one is not found, the client's printer is not available. This is the default behavior.\r\n\r\n\"Default to PCL if one is not found\" - If no suitable printer driver can be found, default to the Printer Control Language (PCL) fallback printer driver.\r\n\r\n\"Default to PS if one is not found\" - If no suitable printer driver can be found, default to the PostScript (PS) fallback printer driver.\r\n\r\n\"Show both PCL and PS if one is not found\" - If no suitable driver can be found, show both PS and PCL-based fallback printer drivers.\r\n\r\nIf you disable this policy setting, the RD Session Host server fallback driver is disabled and the RD Session Host server will not attempt to use the fallback printer driver.\r\n\r\nIf you do not configure this policy setting, the fallback printer driver behavior is off by default.\r\n\r\nNote: If the \"Do not allow client printer redirection\" setting is enabled, this policy setting is ignored and the fallback printer driver is disabled.\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-fallbackprintdrivertype"],"categoryId":"f1455024-7de9-448f-8d8f-a42db2af0a35","categoryName":"Printer Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_ts_fallback_options","displayName":"When attempting to find a suitable driver:","description":"\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":[],"categoryId":"f1455024-7de9-448f-8d8f-a42db2af0a35","categoryName":"Printer Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_ts_fallback_options_1","displayName":"Do nothing if one is not found.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_ts_fallback_options_2","displayName":"Default to PCL if one is not found.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_ts_fallback_options_3","displayName":"Default to PS if one is not found.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_fallbackprintdrivertype_ts_fallback_options_4","displayName":"Show both PCL and PS if one is not found.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_forcible_logoff","displayName":"Deny logoff of an administrator logged in to the console session","description":"This policy setting determines whether an administrator attempting to connect remotely to the console of a server can log off an administrator currently logged on to the console.\r\n\r\nThis policy is useful when the currently connected administrator does not want to be logged off by another administrator. If the connected administrator is logged off, any data not previously saved is lost.\r\n\r\nIf you enable this policy setting, logging off the connected administrator is not allowed.\r\n\r\nIf you disable or do not configure this policy setting, logging off the connected administrator is allowed.\r\n\r\nNote: The console session is also known as Session 0. Console access can be obtained by using the /console switch from Remote Desktop Connection in the computer field name or from the command line.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-forcible-logoff"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_forcible_logoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_forcible_logoff_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_join_session_directory","displayName":"Join RD Connection Broker","description":"This policy setting allows you to specify whether the RD Session Host server should join a farm in RD Connection Broker. RD Connection Broker tracks user sessions and allows a user to reconnect to their existing session in a load-balanced RD Session Host server farm. To participate in RD Connection Broker, the Remote Desktop Session Host role service must be installed on the server.\r\n\r\nIf the policy setting is enabled, the RD Session Host server joins the farm that is specified in the RD Connection Broker farm name policy setting. The farm exists on the RD Connection Broker server that is specified in the Configure RD Connection Broker server name policy setting.\r\n\r\nIf you disable this policy setting, the server does not join a farm in RD Connection Broker, and user session tracking is not performed. If the policy setting is disabled, you cannot use either the Remote Desktop Session Host Configuration tool or the Remote Desktop Services WMI Provider to join the server to RD Connection Broker.\r\n\r\nIf the policy setting is not configured, the policy setting is not specified at the Group Policy level. \r\n\r\nNotes:\r\n\r\n 1. If you enable this policy setting, you must also enable the Configure RD Connection Broker farm name and Configure RD Connection Broker server name policy settings.\r\n\r\n 2. For Windows Server 2008, this policy setting is supported on at least Windows Server 2008 Standard.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-join-session-directory"],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_join_session_directory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_join_session_directory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive","displayName":"Configure keep-alive connection interval","description":"This policy setting allows you to enter a keep-alive interval to ensure that the session state on the RD Session Host server is consistent with the client state.\r\n\r\nAfter an RD Session Host server client loses the connection to an RD Session Host server, the session on the RD Session Host server might remain active instead of changing to a disconnected state, even if the client is physically disconnected from the RD Session Host server. If the client logs on to the same RD Session Host server again, a new session might be established (if the RD Session Host server is configured to allow multiple sessions), and the original session might still be active.\r\n\r\nIf you enable this policy setting, you must enter a keep-alive interval. The keep-alive interval determines how often, in minutes, the server checks the session state. The range of values you can enter is 1 to 999,999.\r\n\r\nIf you disable or do not configure this policy setting, a keep-alive interval is not set and the server will not check the session state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-keep-alive"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive_ts_keep_alive_interval","displayName":"Keep-Alive interval:","description":null,"helpText":"","infoUrls":[],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_secgroup","displayName":"License server security group","description":"This policy setting allows you to specify the RD Session Host servers to which a Remote Desktop license server will offer Remote Desktop Services client access licenses (RDS CALs).\r\n\r\nYou can use this policy setting to control which RD Session Host servers are issued RDS CALs by the Remote Desktop license server. By default, a license server issues an RDS CAL to any RD Session Host server that requests one.\r\n\r\nIf you enable this policy setting and this policy setting is applied to a Remote Desktop license server, the license server will only respond to RDS CAL requests from RD Session Host servers whose computer accounts are a member of the RDS Endpoint Servers group on the license server.\r\n\r\nBy default, the RDS Endpoint Servers group is empty.\r\n\r\nIf you disable or do not configure this policy setting, the Remote Desktop license server issues an RDS CAL to any RD Session Host server that requests one. The RDS Endpoint Servers group is not deleted or changed in any way by disabling or not configuring this policy setting.\r\n\r\nNote: You should only enable this policy setting when the license server is a member of a domain. You can only add computer accounts for RD Session Host servers to the RDS Endpoint Servers group when the license server is a member of a domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-license-secgroup"],"categoryId":"0456dcd5-c003-4a8b-80e6-61bacf854330","categoryName":"RD Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_secgroup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_secgroup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers","displayName":"Use the specified Remote Desktop license servers","description":"This policy setting allows you to specify the order in which an RD Session Host server attempts to locate Remote Desktop license servers.\r\n\r\nIf you enable this policy setting, an RD Session Host server first attempts to locate the specified license servers. If the specified license servers cannot be located, the RD Session Host server will attempt automatic license server discovery. In the automatic license server discovery process, an RD Session Host server in a Windows Server-based domain attempts to contact a license server in the following order:\r\n\r\n 1. Remote Desktop license servers that are published in Active Directory Domain Services.\r\n\r\n 2. Remote Desktop license servers that are installed on domain controllers in the same domain as the RD Session Host server.\r\n\r\nIf you disable or do not configure this policy setting, the RD Session Host server does not specify a license server at the Group Policy level.\r\n\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-license-servers"],"categoryId":"4b540860-0858-48f4-8830-18383bb1766f","categoryName":"Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers_ts_license_edit","displayName":"License servers to use:","description":"\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":[],"categoryId":"4b540860-0858-48f4-8830-18383bb1766f","categoryName":"Licensing","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_tooltip","displayName":"Hide notifications about RD Licensing problems that affect the RD Session Host server","description":"This policy setting determines whether notifications are displayed on an RD Session Host server when there are problems with RD Licensing that affect the RD Session Host server.\r\n\r\nBy default, notifications are displayed on an RD Session Host server after you log on as a local administrator, if there are problems with RD Licensing that affect the RD Session Host server. If applicable, a notification will also be displayed that notes the number of days until the licensing grace period for the RD Session Host server will expire.\r\n\r\nIf you enable this policy setting, these notifications will not be displayed on the RD Session Host server.\r\n\r\nIf you disable or do not configure this policy setting, these notifications will be displayed on the RD Session Host server after you log on as a local administrator.\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-license-tooltip"],"categoryId":"4b540860-0858-48f4-8830-18383bb1766f","categoryName":"Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_tooltip_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_tooltip_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode","displayName":"Set the Remote Desktop licensing mode","description":"\r\n This policy setting allows you to specify the type of Remote Desktop Services client access license (RDS CAL) that is required to connect to this RD Session Host server.\r\n\r\n You can use this policy setting to select one of three licensing modes: Per User , Per Device and AAD Per User .\r\n\r\n Per User licensing mode requires that each user account connecting to this RD Session Host server have an RDS Per User CAL issued from an RD Licensing server.\r\n\r\n Per Device licensing mode requires that each device connecting to this RD Session Host server have an RDS Per Device CAL issued from an RD Licensing server.\r\n\r\n AAD Per User licensing mode requires that each user account connecting to this RD Session Host server have a service plan that supports RDS licenses assigned in AAD.\r\n \r\n If you enable this policy setting, the Remote Desktop licensing mode that you specify is honored by the Remote Desktop license server and RD Session Host.\r\n\r\n If you disable or do not configure this policy setting, the licensing mode is not specified at the Group Policy level.\r\n \r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-licensing-mode"],"categoryId":"4b540860-0858-48f4-8830-18383bb1766f","categoryName":"Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode_ts_licensing_name","displayName":"Specify the licensing mode for the RD Session Host server.","description":"\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":[],"categoryId":"4b540860-0858-48f4-8830-18383bb1766f","categoryName":"Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode_ts_licensing_name_2","displayName":"Per Device","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode_ts_licensing_name_4","displayName":"Per User","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_licensing_mode_ts_licensing_name_6","displayName":"AAD Per User","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_max_con_policy","displayName":"Limit number of connections","description":"Specifies whether Remote Desktop Services limits the number of simultaneous connections to the server.\r\n\r\nYou can use this setting to restrict the number of Remote Desktop Services sessions that can be active on a server. If this number is exceeded, addtional users who try to connect receive an error message telling them that the server is busy and to try again later. Restricting the number of sessions improves performance because fewer sessions are demanding system resources. By default, RD Session Host servers allow an unlimited number of Remote Desktop Services sessions, and Remote Desktop for Administration allows two Remote Desktop Services sessions.\r\n\r\nTo use this setting, enter the number of connections you want to specify as the maximum for the server. To specify an unlimited number of connections, type 999999.\r\n\r\nIf the status is set to Enabled, the maximum number of connections is limited to the specified number consistent with the version of Windows and the mode of Remote Desktop Services running on the server.\r\n\r\nIf the status is set to Disabled or Not Configured, limits to the number of connections are not enforced at the Group Policy level.\r\n\r\nNote: This setting is designed to be used on RD Session Host servers (that is, on servers running Windows with Remote Desktop Session Host role service installed).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-max-con-policy"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_max_con_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_max_con_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_max_con_policy_ts_maximum_connections_allowed","displayName":"RD Maximum Connections allowed","description":null,"helpText":"","infoUrls":[],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxdisplayres","displayName":"Limit maximum display resolution","description":"This policy setting allows you to specify the maximum display resolution that can be used by each monitor used to display a Remote Desktop Services session. Limiting the resolution used to display a remote session can improve connection performance, particularly over slow links, and reduce server load.\r\n\r\nIf you enable this policy setting, you must specify a resolution width and height. The resolution specified will be the maximum resolution that can be used by each monitor used to display a Remote Desktop Services session.\r\n\r\nIf you disable or do not configure this policy setting, the maximum resolution that can be used by each monitor to display a Remote Desktop Services session will be determined by the values specified on the Display Settings tab in the Remote Desktop Session Host Configuration tool.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-maxdisplayres"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxdisplayres_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxdisplayres_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxdisplayres_ts_displayres_height","displayName":"Height","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxdisplayres_ts_displayres_width","displayName":"Width","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxmonitor","displayName":"Limit number of monitors","description":"This policy setting allows you to limit the number of monitors that a user can use to display a Remote Desktop Services session. Limiting the number of monitors to display a Remote Desktop Services session can improve connection performance, particularly over slow links, and reduce server load.\r\n\r\nIf you enable this policy setting, you can specify the number of monitors that can be used to display a Remote Desktop Services session. You can specify a number from 1 to 16.\r\n\r\nIf you disable or do not configure this policy setting, the number of monitors that can be used to display a Remote Desktop Services session is not specified at the Group Policy level.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-maxmonitor"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxmonitor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxmonitor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_maxmonitor_ts_max_monitor","displayName":"Maximum Monitors","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_nodisconnectmenu","displayName":"Remove \"Disconnect\" option from Shut Down dialog","description":"This policy setting allows you to remove the \"Disconnect\" option from the Shut Down Windows dialog box in Remote Desktop Services sessions.\r\n\r\nYou can use this policy setting to prevent users from using this familiar method to disconnect their client from an RD Session Host server.\r\n\r\nIf you enable this policy setting, \"Disconnect\" does not appear as an option in the drop-down list in the Shut Down Windows dialog box.\r\n\r\nIf you disable or do not configure this policy setting, \"Disconnect\" is not removed from the list in the Shut Down Windows dialog box.\r\n\r\nNote: This policy setting affects only the Shut Down Windows dialog box. It does not prevent users from using other methods to disconnect from a Remote Desktop Services session. This policy setting also does not prevent disconnected sessions at the server. You can control how long a disconnected session remains active on the server by configuring the \"Computer Configuration\\Administrative Templates\\Windows Components\\Remote Desktop Services\\RD Session Host\\Session Time Limits\\Set time limit for disconnected sessions\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-nodisconnectmenu"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_nodisconnectmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_nodisconnectmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_nosecuritymenu","displayName":"Remove Windows Security item from Start menu","description":"Specifies whether to remove the Windows Security item from the Settings menu on Remote Desktop clients. You can use this setting to prevent inexperienced users from logging off from Remote Desktop Services inadvertently.\r\n\r\nIf the status is set to Enabled, Windows Security does not appear in Settings on the Start menu. As a result, users must type a security attention sequence, such as CTRL+ALT+END, to open the Windows Security dialog box on the client computer.\r\n\r\nIf the status is set to Disabled or Not Configured, Windows Security remains in the Settings menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-nosecuritymenu"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_nosecuritymenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_nosecuritymenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_preventlicenseupgrade","displayName":"Prevent license upgrade","description":"This policy setting allows you to specify which version of Remote Desktop Services client access license (RDS CAL) a Remote Desktop Services license server will issue to clients connecting to RD Session Host servers running other Windows-based operating systems.\r\n\r\nA license server attempts to provide the most appropriate RDS or TS CAL for a connection. For example, a Windows Server 2008 license server will try to issue a Windows Server 2008 TS CAL for clients connecting to a terminal server running Windows Server 2008, and will try to issue a Windows Server 2003 TS CAL for clients connecting to a terminal server running Windows Server 2003.\r\n\r\nBy default, if the most appropriate RDS CAL is not available for a connection, a Windows Server 2008 license server will issue a Windows Server 2008 TS CAL, if available, to the following:\r\n\r\n* A client connecting to a Windows Server 2003 terminal server\r\n* A client connecting to a Windows 2000 terminal server\r\n\r\nIf you enable this policy setting, the license server will only issue a temporary RDS CAL to the client if an appropriate RDS CAL for the RD Session Host server is not available. If the client has already been issued a temporary RDS CAL and the temporary RDS CAL has expired, the client will not be able to connect to the RD Session Host server unless the RD Licensing grace period for the RD Session Host server has not expired.\r\n\r\nIf you disable or do not configure this policy setting, the license server will exhibit the default behavior noted earlier.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-preventlicenseupgrade"],"categoryId":"0456dcd5-c003-4a8b-80e6-61bacf854330","categoryName":"RD Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_preventlicenseupgrade_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_preventlicenseupgrade_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_promt_creds_client_comp","displayName":"Prompt for credentials on the client computer","description":"This policy setting determines whether a user will be prompted on the client computer to provide credentials for a remote connection to an RD Session Host server.\r\n\r\nIf you enable this policy setting, a user will be prompted on the client computer instead of on the RD Session Host server to provide credentials for a remote connection to an RD Session Host server. If saved credentials for the user are available on the client computer, the user will not be prompted to provide credentials.\r\n\r\nNote: If you enable this policy setting in releases of Windows Server 2008 R2 with SP1 or Windows Server 2008 R2, and a user is prompted on both the client computer and on the RD Session Host server to provide credentials, clear the Always prompt for password check box on the Log on Settings tab in Remote Desktop Session Host Configuration.\r\n\r\nIf you disable or do not configure this policy setting, the version of the operating system on the RD Session Host server will determine when a user is prompted to provide credentials for a remote connection to an RD Session Host server. For Windows Server 2003 and Windows 2000 Server a user will be prompted on the terminal server to provide credentials for a remote connection. For Windows Server 2008 and Windows Server 2008 R2, a user will be prompted on the client computer to provide credentials for a remote connection.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-promt-creds-client-comp"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_promt_creds_client_comp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_promt_creds_client_comp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_rdsappx_waitforregistration","displayName":"Suspend user sign-in to complete app registration","description":"This policy setting allows you to specify whether the app registration is completed before showing the Start screen to the user. \r\n\r\nBy default, when a new user signs in to a computer, the Start screen is shown and apps are registered in the background. However, some apps may not work until app registration is complete.\r\n\r\nIf you enable this policy setting, user sign-in is blocked for up to 6 minutes to complete the app registration. You can use this policy setting when customizing the Start screen on Remote Desktop Session Host servers. \r\n\r\nIf you disable or do not configure this policy setting, the Start screen is shown and apps are registered in the background.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-rdsappx-waitforregistration"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_rdsappx_waitforregistration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_rdsappx_waitforregistration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2","displayName":"Set rules for remote control of Remote Desktop Services user sessions","description":"If you enable this policy setting, administrators can interact with a user's Remote Desktop Services session based on the option selected. Select the desired level of control and permission from the options list:\r\n\r\n1. No remote control allowed: Disallows an administrator to use remote control or view a remote user session.\r\n2. Full Control with user's permission: Allows the administrator to interact with the session, with the user's consent.\r\n3. Full Control without user's permission: Allows the administrator to interact with the session, without the user's consent.\r\n4. View Session with user's permission: Allows the administrator to watch the session of a remote user with the user's consent. \r\n5. View Session without user's permission: Allows the administrator to watch the session of a remote user without the user's consent.\r\n\r\nIf you disable this policy setting, administrators can interact with a user's Remote Desktop Services session, with the user's consent.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-remotecontrol-2"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels","displayName":"Options:","description":null,"helpText":"","infoUrls":[],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_0","displayName":"No remote control allowed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_1","displayName":"Full Control with user's permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_2","displayName":"Full Control without user's permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_3","displayName":"View Session with user's permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_4","displayName":"View Session without user's permission","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics","displayName":"Optimize visual experience when using RemoteFX","description":"This policy setting allows you to specify the visual experience that remote users will have in Remote Desktop Connection (RDC) connections that use RemoteFX. You can use this policy to balance the network bandwidth usage with the type of graphics experience that is delivered.\r\n\r\nDepending on the requirements of your users, you can reduce network bandwidth usage by reducing the screen capture rate. You can also reduce network bandwidth usage by reducing the image quality (increasing the amount of image compression that is performed).\r\n\r\nIf you have a higher than average bandwidth network, you can maximize the utilization of bandwidth by selecting the highest setting for screen capture rate and the highest setting for image quality.\r\n\r\nBy default, Remote Desktop Connection sessions that use RemoteFX are optimized for a balanced experience over LAN conditions. If you disable or do not configure this policy setting, Remote Desktop Connection sessions that use RemoteFX will be the same as if the medium screen capture rate and the medium image compression settings were selected (the default behavior). \r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-remotedesktopvirtualgraphics"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screencapturerate","displayName":"Screen capture rate (frames per second):","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screencapturerate_1","displayName":"Highest (best quality)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screencapturerate_2","displayName":"Medium (default)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screencapturerate_3","displayName":"Lowest","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screenimagequality","displayName":"Screen Image Quality:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screenimagequality_1","displayName":"Highest (best quality)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screenimagequality_2","displayName":"Medium (default)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_ts_remotedesktopvirtualgraphics_screenimagequality_3","displayName":"Lowest","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_clustname","displayName":"Configure RD Connection Broker farm name","description":"This policy setting allows you to specify the name of a farm to join in RD Connection Broker. RD Connection Broker uses the farm name to determine which RD Session Host servers are in the same RD Session Host server farm. Therefore, you must use the same farm name for all RD Session Host servers in the same load-balanced farm. The farm name does not have to correspond to a name in Active Directory Domain Services.\r\n\r\nIf you specify a new farm name, a new farm is created in RD Connection Broker. If you specify an existing farm name, the server joins that farm in RD Connection Broker.\r\n\r\nIf you enable this policy setting, you must specify the name of a farm in RD Connection Broker.\r\n\r\nIf you disable or do not configure this policy setting, the farm name is not specified at the Group Policy level. \r\n\r\nNotes:\r\n\r\n 1. This policy setting is not effective unless both the Join RD Connection Broker and the Configure RD Connection Broker server name policy settings are enabled and configured by using Group Policy.\r\n\r\n 2. For Windows Server 2008, this policy setting is supported on at least Windows Server 2008 Standard.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sd-clustname"],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_clustname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_clustname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_clustname_ts_sd_clustname","displayName":"Configure RD Connection Broker farm name:","description":null,"helpText":"","infoUrls":[],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_expose_address","displayName":"Use IP Address Redirection","description":"This policy setting allows you to specify the redirection method to use when a client device reconnects to an existing Remote Desktop Services session in a load-balanced RD Session Host server farm. This setting applies to an RD Session Host server that is configured to use RD Connection Broker and not to the RD Connection Broker server.\r\n\r\nIf you enable this policy setting, a Remote Desktop Services client queries the RD Connection Broker server and is redirected to their existing session by using the IP address of the RD Session Host server where their session exists. To use this redirection method, client computers must be able to connect directly by IP address to RD Session Host servers in the farm.\r\n\r\nIf you disable this policy setting, the IP address of the RD Session Host server is not sent to the client. Instead, the IP address is embedded in a token. When a client reconnects to the load balancer, the routing token is used to redirect the client to their existing session on the correct RD Session Host server in the farm. Only disable this setting when your network load-balancing solution supports the use of RD Connection Broker routing tokens and you do not want clients to directly connect by IP address to RD Session Host servers in the load-balanced farm.\r\n\r\nIf you do not configure this policy setting, the Use IP address redirection policy setting is not enforced at the group Group policy Policy level and the default will be used. This setting is enabled by default.\r\n\r\nNotes:\r\n\r\n 1. For Windows Server 2008, this policy setting is supported on at least Windows Server 2008 Standard.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sd-expose-address"],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_expose_address_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_expose_address_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_loc","displayName":"Configure RD Connection Broker server name","description":"This policy setting allows you to specify the RD Connection Broker server that the RD Session Host server uses to track and redirect user sessions for a load-balanced RD Session Host server farm. The specified server must be running the Remote Desktop Connection Broker service. All RD Session Host servers in a load-balanced farm should use the same RD Connection Broker server.\r\n\r\nIf you enable this policy setting, you must specify the RD Connection Broker server by using its fully qualified domain name (FQDN). In Windows Server 2012, for a high availability setup with multiple RD Connection Broker servers, you must provide a semi-colon separated list of the FQDNs of all the RD Connection Broker servers.\r\n\r\nIf you disable or do not configure this policy setting, the policy setting is not specified at the Group Policy level.\r\n\r\nNotes:\r\n\r\n 1. For Windows Server 2008, this policy setting is supported on at least Windows Server 2008 Standard.\r\n\r\n 2. This policy setting is not effective unless the Join RD Connection Broker policy setting is enabled.\r\n\r\n 3. To be an active member of an RD Session Host server farm, the computer account for each RD Session Host server in the farm must be a member of one of the following local groups on the RD Connection Broker server: Session Directory Computers, Session Broker Computers, or RDS Endpoint Servers.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sd-loc"],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_loc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_loc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_loc_ts_sd_loc","displayName":"Configure RD Connection Broker server name:","description":null,"helpText":"","infoUrls":[],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy","displayName":"Require use of specific security layer for remote (RDP) connections","description":"This policy setting specifies whether to require the use of a specific security layer to secure communications between clients and RD Session Host servers during Remote Desktop Protocol (RDP) connections.\r\n\r\nIf you enable this policy setting, all communications between clients and RD Session Host servers during remote connections must use the security method specified in this setting. The following security methods are available:\r\n\r\n* Negotiate: The Negotiate method enforces the most secure method that is supported by the client. If Transport Layer Security (TLS) version 1.0 is supported, it is used to authenticate the RD Session Host server. If TLS is not supported, native Remote Desktop Protocol (RDP) encryption is used to secure communications, but the RD Session Host server is not authenticated. Native RDP encryption (as opposed to SSL encryption) is not recommended.\r\n\r\n* RDP: The RDP method uses native RDP encryption to secure communications between the client and RD Session Host server. If you select this setting, the RD Session Host server is not authenticated. Native RDP encryption (as opposed to SSL encryption) is not recommended.\r\n\r\n* SSL (TLS 1.0): The SSL method requires the use of TLS 1.0 to authenticate the RD Session Host server. If TLS is not supported, the connection fails. This is the recommended setting for this policy.\r\n\r\nIf you disable or do not configure this policy setting, the security method to be used for remote connections to RD Session Host servers is not specified at the Group Policy level.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-security-layer-policy"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_ts_security_layer","displayName":"Security Layer","description":null,"helpText":"","infoUrls":[],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_ts_security_layer_0","displayName":"RDP","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_ts_security_layer_1","displayName":"Negotiate","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_ts_security_layer_2","displayName":"SSL","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect","displayName":"Select network detection on the server","description":"This policy setting allows you to specify how the Remote Desktop Protocol will try to detect the network quality (bandwidth and latency).\r\n\r\nYou can choose to disable Connect Time Detect, Continuous Network Detect, or both Connect Time Detect and Continuous Network Detect. \r\n\r\nIf you disable Connect Time Detect, Remote Desktop Protocol will not determine the network quality at the connect time, and it will assume that all traffic to this server originates from a low-speed connection.\r\n\r\nIf you disable Continuous Network Detect, Remote Desktop Protocol will not try to adapt the remote user experience to varying network quality. \r\n\r\nIf you disable Connect Time Detect and Continuous Network Detect, Remote Desktop Protocol will not try to determine the network quality at the connect time; instead it will assume that all traffic to this server originates from a low-speed connection, and it will not try to adapt the user experience to varying network quality.\r\n\r\nIf you disable or do not configure this policy setting, Remote Desktop Protocol will spend up to a few seconds trying to determine the network quality prior to the connection, and it will continuously try to adapt the user experience to varying network quality.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-select-network-detect"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_ts_select_network_detect_level","displayName":"Select Network Detect Level","description":null,"helpText":"","infoUrls":[],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_ts_select_network_detect_level_0","displayName":"Use both Connect Time Detect and Continuous Network Detect","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_ts_select_network_detect_level_1","displayName":"Turn off Connect Time Detect","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_ts_select_network_detect_level_2","displayName":"Turn off Continuous Network Detect","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_network_detect_ts_select_network_detect_level_3","displayName":"Turn off Connect Time Detect and Continuous Network Detect","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport","displayName":"Select RDP transport protocols","description":"This policy setting allows you to specify which protocols can be used for Remote Desktop Protocol (RDP) access to this server.\r\n\r\nIf you enable this policy setting, you must specify if you would like RDP to use UDP.\r\n\r\nYou can select one of the following options: \"Use both UDP and TCP\", \"Use only TCP\" or \"Use either UDP or TCP (default)\" \r\n\r\nIf you select \"Use either UDP or TCP\" and the UDP connection is successful, most of the RDP traffic will use UDP.\r\n\r\nIf the UDP connection is not successful or if you select \"Use only TCP,\" all of the RDP traffic will use TCP.\r\n\r\nIf you disable or do not configure this policy setting, RDP will choose the optimal protocols for delivering the best user experience.\r\n\t \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-select-transport"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport_ts_select_transport_type","displayName":"Select Transport Type","description":null,"helpText":"","infoUrls":[],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport_ts_select_transport_type_0","displayName":"Use both UDP and TCP","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport_ts_select_transport_type_1","displayName":"Use only TCP","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_select_transport_ts_select_transport_type_2","displayName":"Use either UDP or TCP","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_advanced_remotefx_remoteapp","displayName":"Use advanced RemoteFX graphics for RemoteApp","description":"This policy setting allows you to enable RemoteApp programs to use advanced graphics, including support for transparency, live thumbnails, and seamless application moves. This policy setting applies only to RemoteApp programs and does not apply to remote desktop sessions.\r\n\r\nIf you enable or do not configure this policy setting, RemoteApp programs published from this RD Session Host server will use these advanced graphics.\r\n\r\nIf you disable this policy setting, RemoteApp programs published from this RD Session Host server will not use these advanced graphics. You may want to choose this option if you discover that applications published as RemoteApp programs do not support these advanced graphics. \r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-advanced-remotefx-remoteapp"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_advanced_remotefx_remoteapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_advanced_remotefx_remoteapp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth","displayName":"Configure server authentication for client","description":"This policy setting allows you to specify whether the client will establish a connection to the RD Session Host server when the client cannot authenticate the RD Session Host server.\r\n\r\nIf you enable this policy setting, you must specify one of the following settings:\r\n\r\nAlways connect, even if authentication fails: The client connects to the RD Session Host server even if the client cannot authenticate the RD Session Host server.\r\n\r\nWarn me if authentication fails: The client attempts to authenticate the RD Session Host server. If the RD Session Host server can be authenticated, the client establishes a connection to the RD Session Host server. If the RD Session Host server cannot be authenticated, the user is prompted to choose whether to connect to the RD Session Host server without authenticating the RD Session Host server.\r\n\r\nDo not connect if authentication fails: The client establishes a connection to the RD Session Host server only if the RD Session Host server can be authenticated.\r\n\r\nIf you disable or do not configure this policy setting, the authentication setting that is specified in Remote Desktop Connection or in the .rdp file determines whether the client establishes a connection to the RD Session Host server when the client cannot authenticate the RD Session Host server.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-auth"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_ts_server_auth_level","displayName":"Authentication setting:","description":null,"helpText":"","infoUrls":[],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_ts_server_auth_level_0","displayName":"Always connect, even if authentication fails","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_ts_server_auth_level_2","displayName":"Warn me if authentication fails","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_ts_server_auth_level_1","displayName":"Do not connect if authentication fails","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc_hw_encode_preferred","displayName":"Configure H.264/AVC hardware encoding for Remote Desktop Connections","description":"This policy setting lets you enable H.264/AVC hardware encoding support for Remote Desktop Connections. When you enable hardware encoding, if an error occurs, we will attempt to use software encoding. If you disable or do not configure this policy, we will always use software encoding.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-avc-hw-encode-preferred"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc_hw_encode_preferred_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc_hw_encode_preferred_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc444_mode_preferred","displayName":"Prioritize H.264/AVC 444 graphics mode for Remote Desktop Connections","description":"This policy setting prioritizes the H.264/AVC 444 graphics mode for non-RemoteFX vGPU scenarios. When you use this setting on the RDP server, the server will use H.264/AVC 444 as the codec in an RDP 10 connection where both the client and server can use H.264/AVC 444.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-avc444-mode-preferred"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc444_mode_preferred_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc444_mode_preferred_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor","displayName":"Configure compression for RemoteFX data","description":"This policy setting allows you to specify which Remote Desktop Protocol (RDP) compression algorithm to use.\r\n\r\nBy default, servers use an RDP compression algorithm that is based on the server's hardware configuration.\r\n\r\nIf you enable this policy setting, you can specify which RDP compression algorithm to use. If you select the algorithm that is optimized to use less memory, this option is less memory-intensive, but uses more network bandwidth. If you select the algorithm that is optimized to use less network bandwidth, this option uses less network bandwidth, but is more memory-intensive. Additionally, a third option is available that balances memory usage and network bandwidth. In Windows 8 only the compression algorithm that balances memory usage and bandwidth is used.\r\n\r\nYou can also choose not to use an RDP compression algorithm. Choosing not to use an RDP compression algorithm will use more network bandwidth and is only recommended if you are using a hardware device that is designed to optimize network traffic. Even if you choose not to use an RDP compression algorithm, some graphics data will still be compressed.\r\n\r\nIf you disable or do not configure this policy setting, the default RDP compression algorithm will be used.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-compressor"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_ts_compressor_levels","displayName":"RDP compression algorithm:","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_ts_compressor_levels_1","displayName":"Optimized to use less memory","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_ts_compressor_levels_3","displayName":"Optimized to use less network bandwidth","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_ts_compressor_levels_2","displayName":"Balances memory and network bandwidth","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_compressor_ts_compressor_levels_0","displayName":"Do not use an RDP compression algorithm","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality","displayName":"Configure image quality for RemoteFX Adaptive Graphics","description":"This policy setting allows you to specify the visual quality for remote users when connecting to this computer by using Remote Desktop Connection. You can use this policy setting to balance the network bandwidth usage with the visual quality that is delivered.\r\n If you enable this policy setting and set quality to Low, RemoteFX Adaptive Graphics uses an encoding mechanism that results in low quality images. This mode consumes the lowest amount of network bandwidth of the quality modes.\r\n If you enable this policy setting and set quality to Medium, RemoteFX Adaptive Graphics uses an encoding mechanism that results in medium quality images. This mode provides better graphics quality than low quality and uses less bandwidth than high quality.\r\n If you enable this policy setting and set quality to High, RemoteFX Adaptive Graphics uses an encoding mechanism that results in high quality images and consumes moderate network bandwidth.\r\n If you enable this policy setting and set quality to Lossless, RemoteFX Adaptive Graphics uses lossless encoding. In this mode, the color integrity of the graphics data is not impacted. However, this setting results in a significant increase in network bandwidth consumption. We recommend that you set this for very specific cases only.\r\n If you disable or do not configure this policy setting, RemoteFX Adaptive Graphics uses an encoding mechanism that results in medium quality images.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-image-quality"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_ts_server_image_quality_levels","displayName":"Image quality:","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_ts_server_image_quality_levels_1","displayName":"Lossless","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_ts_server_image_quality_levels_2","displayName":"High","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_ts_server_image_quality_levels_3","displayName":"Medium","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_ts_server_image_quality_levels_4","displayName":"Low","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_legacy_rfx","displayName":"Enable RemoteFX encoding for RemoteFX clients designed for Windows Server 2008 R2 SP1","description":"This policy setting allows you to configure graphics encoding to use the RemoteFX Codec on the Remote Desktop Session Host server so that the sessions are compatible with non-Windows thin client devices designed for Windows Server 2008 R2 SP1. These clients only support the Windows Server 2008 R2 SP1 RemoteFX Codec.If you enable this policy setting, users' sessions on this server will only use the Windows Server 2008 R2 SP1 RemoteFX Codec for encoding. This mode is compatible with thin client devices that only support the Windows Server 2008 R2 SP1 RemoteFX Codec.If you disable or do not configure this policy setting, non-Windows thin clients that only support the Windows Server 2008 R2 SP1 RemoteFX Codec will not be able to connect to this server. This policy setting applies only to clients that are using Remote Desktop Protocol (RDP) 7.1, and does not affect clients that are using other RDP versions.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-legacy-rfx"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_legacy_rfx_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_legacy_rfx_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile","displayName":"Configure RemoteFX Adaptive Graphics","description":"This policy setting allows the administrator to configure the RemoteFX experience for Remote Desktop Session Host or Remote Desktop Virtualization Host servers. By default, the system will choose the best experience based on available nework bandwidth.\r\n\r\nIf you enable this policy setting, the RemoteFX experience could be set to one of the following options:\r\n1. Let the system choose the experience for the network condition\r\n2. Optimize for server scalability\r\n3. Optimize for minimum bandwidth usage\r\n\r\nIf you disable or do not configure this policy setting, the RemoteFX experience will change dynamically based on the network condition.\"\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-profile"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile_ts_server_profile_levels","displayName":"RDP experience:","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile_ts_server_profile_levels_2","displayName":"Let the system choose experience for network condition","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile_ts_server_profile_levels_1","displayName":"Optimize for server scalability","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_profile_ts_server_profile_levels_3","displayName":"Optimize for minimum bandwidth usage","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp","displayName":"Optimize visual experience for Remote Desktop Service Sessions","description":"This policy setting allows you to specify the visual experience that remote users receive in Remote Desktop Services sessions. Remote sessions on the remote computer are then optimized to support this visual experience.\r\n\r\nBy default, Remote Desktop Services sessions are optimized for rich multimedia, such as applications that use Silverlight or Windows Presentation Foundation.\r\n\r\nIf you enable this policy setting, you must select the visual experience for which you want to optimize Remote Desktop Services sessions. You can select either Rich multimedia or Text.\r\n\r\nIf you disable or do not configure this policy setting, Remote Desktop Services sessions are optimized for rich multimedia.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-visexp"],"categoryId":"b7bde490-eac6-4f57-8808-e0786b8191a1","categoryName":"Remote FX for Windows Server 2008 R2","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_ts_visexp_settings","displayName":"Visual experience:","description":null,"helpText":"","infoUrls":[],"categoryId":"b7bde490-eac6-4f57-8808-e0786b8191a1","categoryName":"Remote FX for Windows Server 2008 R2","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_ts_visexp_settings_1","displayName":"Rich multimedia","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_ts_visexp_settings_2","displayName":"Text","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_wddm_graphics_driver","displayName":"Use WDDM graphics display driver for Remote Desktop Connections","description":"This policy setting lets you enable WDDM graphics display driver for Remote Desktop Connections.\r\n\r\nIf you enable or do not configure this policy setting, Remote Desktop Connections will use WDDM graphics display driver.\r\n\r\nIf you disable this policy setting, Remote Desktop Connections will NOT use WDDM graphics display driver. In this case, the Remote Desktop Connections will use XDDM graphics display driver.\r\n\r\nFor this change to take effect, you must restart Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-wddm-graphics-driver"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_wddm_graphics_driver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_wddm_graphics_driver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_session_end_on_limit_2","displayName":"End session when time limits are reached","description":"This policy setting specifies whether to end a Remote Desktop Services session that has timed out instead of disconnecting it.\r\n\r\nYou can use this setting to direct Remote Desktop Services to end a session (that is, the user is logged off and the session is deleted from the server) after time limits for active or idle sessions are reached. By default, Remote Desktop Services disconnects sessions that reach their time limits.\r\n\r\nTime limits are set locally by the server administrator or by using Group Policy. See the policy settings Set time limit for active Remote Desktop Services sessions and Set time limit for active but idle Remote Desktop Services sessions policy settings.\r\n\r\nIf you enable this policy setting, Remote Desktop Services ends any session that reaches its time-out limit.\r\n\r\nIf you disable this policy setting, Remote Desktop Services always disconnects a timed-out session, even if specified otherwise by the server administrator.\r\n\r\nIf you do not configure this policy setting, Remote Desktop Services disconnects a timed-out session, unless specified otherwise in local settings.\r\n\r\nNote: This policy setting only applies to time-out limits that are explicitly set by the administrator. This policy setting does not apply to time-out events that occur due to connectivity or network conditions. This setting appears in both Computer Configuration and User Configuration. If both settings are configured, the Computer Configuration setting takes precedence.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-session-end-on-limit-2"],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_session_end_on_limit_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_session_end_on_limit_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2","displayName":"Set time limit for disconnected sessions","description":"This policy setting allows you to configure a time limit for disconnected Remote Desktop Services sessions.\r\n\r\nYou can use this policy setting to specify the maximum amount of time that a disconnected session remains active on the server. By default, Remote Desktop Services allows users to disconnect from a Remote Desktop Services session without logging off and ending the session.\r\n\r\nWhen a session is in a disconnected state, running programs are kept active even though the user is no longer actively connected. By default, these disconnected sessions are maintained for an unlimited time on the server.\r\n\r\nIf you enable this policy setting, disconnected sessions are deleted from the server after the specified amount of time. To enforce the default behavior that disconnected sessions are maintained for an unlimited time, select Never. If you have a console session, disconnected session time limits do not apply.\r\n\r\n\r\nIf you disable or do not configure this policy setting, this policy setting is not specified at the Group Policy level. Be y default, Remote Desktop Services disconnected sessions are maintained for an unlimited amount of time. \r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the Computer Configuration policy setting takes precedence.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sessions-disconnected-timeout-2"],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected","displayName":"End a disconnected session","description":null,"helpText":"","infoUrls":[],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_60000","displayName":"1 minute","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_300000","displayName":"5 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_600000","displayName":"10 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_900000","displayName":"15 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_1800000","displayName":"30 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_3600000","displayName":"1 hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_7200000","displayName":"2 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_10800000","displayName":"3 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_21600000","displayName":"6 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_28800000","displayName":"8 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_43200000","displayName":"12 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_57600000","displayName":"16 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_64800000","displayName":"18 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_86400000","displayName":"1 day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_172800000","displayName":"2 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_259200000","displayName":"3 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_345600000","displayName":"4 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_disconnected_timeout_2_ts_sessions_enddisconnected_432000000","displayName":"5 days","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2","displayName":"Set time limit for active but idle Remote Desktop Services sessions","description":"This policy setting allows you to specify the maximum amount of time that an active Remote Desktop Services session can be idle (without user input) before it is automatically disconnected.\r\n\r\nIf you enable this policy setting, you must select the desired time limit in the Idle session limit list. Remote Desktop Services will automatically disconnect active but idle sessions after the specified amount of time. The user receives a warning two minutes before the session disconnects, which allows the user to press a key or move the mouse to keep the session active. If you have a console session, idle session time limits do not apply.\r\n\r\nIf you disable or do not configure this policy setting, the time limit is not specified at the Group Policy level. By default, Remote Desktop Services allows sessions to remain active but idle for an unlimited amount of time. \r\n\r\nIf you want Remote Desktop Services to end instead of disconnect a session when the time limit is reached, you can configure the policy setting Computer Configuration\\Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Session Time Limits\\End session when time limits are reached.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the Computer Configuration policy setting takes precedence.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sessions-idle-limit-2"],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext","displayName":"Idle session limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_60000","displayName":"1 minute","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_300000","displayName":"5 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_600000","displayName":"10 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_900000","displayName":"15 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_1800000","displayName":"30 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_3600000","displayName":"1 hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_7200000","displayName":"2 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_10800000","displayName":"3 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_21600000","displayName":"6 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_28800000","displayName":"8 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_43200000","displayName":"12 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_57600000","displayName":"16 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_64800000","displayName":"18 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_86400000","displayName":"1 day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_172800000","displayName":"2 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_259200000","displayName":"3 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_345600000","displayName":"4 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_432000000","displayName":"5 days","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2","displayName":"Set time limit for active Remote Desktop Services sessions","description":"This policy setting allows you to specify the maximum amount of time that a Remote Desktop Services session can be active before it is automatically disconnected.\r\n\r\nIf you enable this policy setting, you must select the desired time limit in the Active session limit list. Remote Desktop Services will automatically disconnect active sessions after the specified amount of time. The user receives a warning two minutes before the Remote Desktop Services session disconnects, which allows the user to save open files and close programs. If you have a console session, active session time limits do not apply.\r\n\r\nIf you disable or do not configure this policy setting, this policy setting is not specified at the Group Policy level. By default, Remote Desktop Services allows sessions to remain active for an unlimited amount of time. \r\n\r\nIf you want Remote Desktop Services to end instead of disconnect a session when the time limit is reached, you can configure the policy setting Computer Configuration\\Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Session Time Limits\\End session when time limits are reached.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the Computer Configuration policy setting takes precedence.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sessions-limits-2"],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit","displayName":"Active session limit :","description":null,"helpText":"","infoUrls":[],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_60000","displayName":"1 minute","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_300000","displayName":"5 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_600000","displayName":"10 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_900000","displayName":"15 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_1800000","displayName":"30 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_3600000","displayName":"1 hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_7200000","displayName":"2 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_10800000","displayName":"3 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_21600000","displayName":"6 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_28800000","displayName":"8 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_43200000","displayName":"12 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_57600000","displayName":"16 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_64800000","displayName":"18 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_86400000","displayName":"1 day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_172800000","displayName":"2 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_259200000","displayName":"3 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_345600000","displayName":"4 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_2_ts_sessions_activelimit_432000000","displayName":"5 days","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_single_session","displayName":"Restrict Remote Desktop Services users to a single Remote Desktop Services session","description":"This policy setting allows you to restrict users to a single Remote Desktop Services session.\r\n\r\nIf you enable this policy setting, users who log on remotely by using Remote Desktop Services will be restricted to a single session (either active or disconnected) on that server. If the user leaves the session in a disconnected state, the user automatically reconnects to that session at the next logon.\r\n\r\nIf you disable this policy setting, users are allowed to make unlimited simultaneous remote connections by using Remote Desktop Services.\r\n\r\nIf you do not configure this policy setting, this policy setting is not specified at the Group Policy level.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-single-session"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_single_session_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_single_session_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_smart_card","displayName":"Do not allow smart card device redirection","description":"This policy setting allows you to control the redirection of smart card devices in a Remote Desktop Services session.\r\n\r\nIf you enable this policy setting, Remote Desktop Services users cannot use a smart card to log on to a Remote Desktop Services session.\r\n\r\nIf you disable or do not configure this policy setting, smart card device redirection is allowed. By default, Remote Desktop Services automatically redirects smart card devices on connection.\r\n\r\nNote: The client computer must be running at least Microsoft Windows 2000 Server or at least Microsoft Windows XP Professional and the target server must be joined to a domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-smart-card"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_smart_card_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_smart_card_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2","displayName":"Start a program on connection","description":"Configures Remote Desktop Services to run a specified program automatically upon connection.\r\n\r\nYou can use this setting to specify a program to run automatically when a user logs on to a remote computer.\r\n\r\nBy default, Remote Desktop Services sessions provide access to the full Windows desktop, unless otherwise specified with this setting, by the server administrator, or by the user in configuring the client connection. Enabling this setting overrides the \"Start Program\" settings set by the server administrator or user. The Start menu and Windows Desktop are not displayed, and when the user exits the program the session is automatically logged off.\r\n\r\nTo use this setting, in Program path and file name, type the fully qualified path and file name of the executable file to be run when the user logs on. If necessary, in Working Directory, type the fully qualified path to the starting directory for the program. If you leave Working Directory blank, the program runs with its default working directory. If the specified program path, file name, or working directory is not the name of a valid directory, the RD Session Host server connection fails with an error message.\r\n\r\nIf the status is set to Enabled, Remote Desktop Services sessions automatically run the specified program and use the specified Working Directory (or the program default directory, if Working Directory is not specified) as the working directory for the program.\r\n\r\nIf the status is set to Disabled or Not Configured, Remote Desktop Services sessions start with the full desktop, unless the server administrator or user specify otherwise. (See \"Computer Configuration\\Administrative Templates\\System\\Logon\\Run these programs at user logon\" setting.)\r\n\r\nNote: This setting appears in both Computer Configuration and User Configuration. If both settings are configured, the Computer Configuration setting overrides.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-start-program-2"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_ts_program_name","displayName":"Program path and file name","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_ts_workdir","displayName":"Working Directory","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_delete","displayName":"Do not delete temp folders upon exit","description":"This policy setting specifies whether Remote Desktop Services retains a user's per-session temporary folders at logoff.\r\n\r\nYou can use this setting to maintain a user's session-specific temporary folders on a remote computer, even if the user logs off from a session. By default, Remote Desktop Services deletes a user's temporary folders when the user logs off.\r\n\r\nIf you enable this policy setting, a user's per-session temporary folders are retained when the user logs off from a session.\r\n\r\nIf you disable this policy setting, temporary folders are deleted when a user logs off, even if the server administrator specifies otherwise.\r\n\r\nIf you do not configure this policy setting, Remote Desktop Services deletes the temporary folders from the remote computer at logoff, unless specified otherwise by the server administrator.\r\n\r\nNote: This setting only takes effect if per-session temporary folders are in use on the server. If you enable the Do not use temporary folders per session policy setting, this policy setting has no effect.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-temp-delete"],"categoryId":"b40b8f80-c0e6-4494-8085-f90cadc167a9","categoryName":"Temporary folders","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_delete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_delete_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_per_session","displayName":"Do not use temporary folders per session","description":"This policy setting allows you to prevent Remote Desktop Services from creating session-specific temporary folders.\r\n\r\nYou can use this policy setting to disable the creation of separate temporary folders on a remote computer for each session. By default, Remote Desktop Services creates a separate temporary folder for each active session that a user maintains on a remote computer. These temporary folders are created on the remote computer in a Temp folder under the user's profile folder and are named with the sessionid.\r\n\r\nIf you enable this policy setting, per-session temporary folders are not created. Instead, a user's temporary files for all sessions on the remote computer are stored in a common Temp folder under the user's profile folder on the remote computer.\r\n\r\nIf you disable this policy setting, per-session temporary folders are always created, even if the server administrator specifies otherwise.\r\n\r\nIf you do not configure this policy setting, per-session temporary folders are created unless the server administrator specifies otherwise.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-temp-per-session"],"categoryId":"b40b8f80-c0e6-4494-8085-f90cadc167a9","categoryName":"Temporary folders","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_per_session_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_per_session_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_time_zone","displayName":"Allow time zone redirection","description":"This policy setting determines whether the client computer redirects its time zone settings to the Remote Desktop Services session.\r\n\r\nIf you enable this policy setting, clients that are capable of time zone redirection send their time zone information to the server. The server base time is then used to calculate the current session time (current session time = server base time + client time zone).\r\n\r\nIf you disable or do not configure this policy setting, the client computer does not redirect its time zone information and the session time zone is the same as the server time zone.\r\n\r\nNote: Time zone redirection is possible only when connecting to at least a Microsoft Windows Server 2003 terminal server with a client using RDP 5.1 and later.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-time-zone"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_time_zone_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_time_zone_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_tscc_permissions_policy","displayName":"Do not allow local administrators to customize permissions","description":"This policy setting specifies whether to disable the administrator rights to customize security permissions for the Remote Desktop Session Host server. \r\n\r\nYou can use this setting to prevent administrators from making changes to the user groups allowed to connect remotely to the RD Session Host server. By default, administrators are able to make such changes.\r\n\r\nIf you enable this policy setting the default security descriptors for existing groups on the RD Session Host server cannot be changed. All the security descriptors are read-only.\r\n\r\nIf you disable or do not configure this policy setting, server administrators have full read/write permissions to the user security descriptors by using the Remote Desktop Session WMI Provider.\r\n\r\nNote: The preferred method of managing user access is by adding a user to the Remote Desktop Users group.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-tscc-permissions-policy"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_tscc_permissions_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_tscc_permissions_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_turnoff_singleapp","displayName":"Always show desktop on connection","description":"This policy setting determines whether the desktop is always displayed after a client connects to a remote computer or an initial program can run. It can be used to require that the desktop be displayed after a client connects to a remote computer, even if an initial program is already specified in the default user profile, Remote Desktop Connection, Remote Desktop Services client, or through Group Policy.\r\n\r\nIf you enable this policy setting, the desktop is always displayed when a client connects to a remote computer. This policy setting overrides any initial program policy settings.\r\n\r\nIf you disable or do not configure this policy setting, an initial program can be specified that runs on the remote computer after the client connects to the remote computer. If an initial program is not specified, the desktop is always displayed on the remote computer after the client connects to the remote computer.\r\n\r\nNote: If this policy setting is enabled, then the \"Start a program on connection\" policy setting is ignored.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-turnoff-singleapp"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_turnoff_singleapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_turnoff_singleapp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable","displayName":"Allow RDP redirection of other supported RemoteFX USB devices from this computer","description":"This policy setting allows you to permit RDP redirection of other supported RemoteFX USB devices from this computer. Redirected RemoteFX USB devices will not be available for local usage on this computer.\r\n\r\nIf you enable this policy setting, you can choose to give the ability to redirect other supported RemoteFX USB devices over RDP to all users or only to users who are in the Administrators group on the computer.\r\n\r\nIf you disable or do not configure this policy setting, other supported RemoteFX USB devices are not available for RDP redirection by using any user account.\r\n\r\nFor this change to take effect, you must restart Windows.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-usb-redirection-disable"],"categoryId":"e6b767af-2ce1-4c91-9360-15abbb0bf3bc","categoryName":"Remote FX USB Device Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_usbaccessright","displayName":"RemoteFX USB Redirection Access Rights","description":null,"helpText":"","infoUrls":[],"categoryId":"e6b767af-2ce1-4c91-9360-15abbb0bf3bc","categoryName":"Remote FX USB Device Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_usbaccessright_1","displayName":"Adminstrators Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_usbaccessright_2","displayName":"Adminstrators and Users","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_authentication_policy","displayName":"Require user authentication for remote connections by using Network Level Authentication","description":"This policy setting allows you to specify whether to require user authentication for remote connections to the RD Session Host server by using Network Level Authentication. This policy setting enhances security by requiring that user authentication occur earlier in the remote connection process.\r\n\r\nIf you enable this policy setting, only client computers that support Network Level Authentication can connect to the RD Session Host server.\r\n\r\nTo determine whether a client computer supports Network Level Authentication, start Remote Desktop Connection on the client computer, click the icon in the upper-left corner of the Remote Desktop Connection dialog box, and then click About. In the About Remote Desktop Connection dialog box, look for the phrase Network Level Authentication supported.\r\n\r\nIf you disable this policy setting, Network Level Authentication is not required for user authentication before allowing remote connections to the RD Session Host server.\r\n\r\nIf you do not configure this policy setting, the local setting on the target computer will be enforced. On Windows Server 2012 and Windows 8, Network Level Authentication is enforced by default.\r\n\r\nImportant: Disabling this policy setting provides less security because user authentication will occur later in the remote connection process.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-user-authentication-policy"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_authentication_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_authentication_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home","displayName":"Set Remote Desktop Services User Home Directory","description":"Specifies whether Remote Desktop Services uses the specified network share or local directory path as the root of the user's home directory for a Remote Desktop Services session.\r\n\r\nTo use this setting, select the location for the home directory (network or local) from the Location drop-down list. If you choose to place the directory on a network share, type the Home Dir Root Path in the form \\\\Computername\\Sharename, and then select the drive letter to which you want the network share to be mapped.\r\n\r\nIf you choose to keep the home directory on the local computer, type the Home Dir Root Path in the form \"Drive:\\Path\" (without quotes), without environment variables or ellipses. Do not specify a placeholder for user alias, because Remote Desktop Services automatically appends this at logon.\r\n\r\nNote: The Drive Letter field is ignored if you choose to specify a local path. If you choose to specify a local path but then type the name of a network share in Home Dir Root Path, Remote Desktop Services places user home directories in the network location.\r\n\r\nIf the status is set to Enabled, Remote Desktop Services creates the user's home directory in the specified location on the local computer or the network. The home directory path for each user is the specified Home Dir Root Path and the user's alias.\r\n\r\nIf the status is set to Disabled or Not Configured, the user's home directory is as specified at the server.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-user-home"],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter","displayName":"Drive Letter","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_g:","displayName":"G:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_h:","displayName":"H:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_i:","displayName":"I:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_j:","displayName":"J:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_k:","displayName":"K:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_l:","displayName":"L:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_m:","displayName":"M:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_n:","displayName":"N:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_o:","displayName":"O:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_p:","displayName":"P:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_q:","displayName":"Q:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_r:","displayName":"R:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_s:","displayName":"S:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_t:","displayName":"T:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_u:","displayName":"U:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_v:","displayName":"V:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_w:","displayName":"W:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_x:","displayName":"X:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_y:","displayName":"Y:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_z:","displayName":"Z:","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_home_dir","displayName":"Home Dir Root Path:","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_user_home_location","displayName":"Location:","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_user_home_location_1","displayName":"On the Network","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_user_home_location_0","displayName":"On the Local machine","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_mandatory_profiles","displayName":"Use mandatory profiles on the RD Session Host server","description":"This policy setting allows you to specify whether Remote Desktop Services uses a mandatory profile for all users connecting remotely to the RD Session Host server.\r\n\r\nIf you enable this policy setting, Remote Desktop Services uses the path specified in the \"Set path for Remote Desktop Services Roaming User Profile\" policy setting as the root folder for the mandatory user profile. All users connecting remotely to the RD Session Host server use the same user profile.\r\n\r\nIf you disable or do not configure this policy setting, mandatory user profiles are not used by users connecting remotely to the RD Session Host server.\r\n\r\nNote:\r\n\r\nFor this policy setting to take effect, you must also enable and configure the \"Set path for Remote Desktop Services Roaming User Profile\" policy setting.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-user-mandatory-profiles"],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_mandatory_profiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_mandatory_profiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_profiles","displayName":"Set path for Remote Desktop Services Roaming User Profile","description":"This policy setting allows you to specify the network path that Remote Desktop Services uses for roaming user profiles.\r\n\r\nBy default, Remote Desktop Services stores all user profiles locally on the RD Session Host server. You can use this policy setting to specify a network share where user profiles can be centrally stored, allowing a user to access the same profile for sessions on all RD Session Host servers that are configured to use the network share for user profiles.\r\n\r\nIf you enable this policy setting, Remote Desktop Services uses the specified path as the root directory for all user profiles. The profiles are contained in subfolders named for the account name of each user.\r\n\r\nTo configure this policy setting, type the path to the network share in the form of \\\\Computername\\Sharename. Do not specify a placeholder for the user account name, because Remote Desktop Services automatically adds this when the user logs on and the profile is created. If the specified network share does not exist, Remote Desktop Services displays an error message on the RD Session Host server and will store the user profiles locally on the RD Session Host server.\r\n\r\nIf you disable or do not configure this policy setting, user profiles are stored locally on the RD Session Host server. You can configure a user's profile path on the Remote Desktop Services Profile tab on the user's account Properties dialog box.\r\n\r\nNotes:\r\n1. The roaming user profiles enabled by the policy setting apply only to Remote Desktop Services connections. A user might also have a Windows roaming user profile configured. The Remote Desktop Services roaming user profile always takes precedence in a Remote Desktop Services session.\r\n2. To configure a mandatory Remote Desktop Services roaming user profile for all users connecting remotely to the RD Session Host server, use this policy setting together with the \"Use mandatory profiles on the RD Session Host server\" policy setting located in Computer Configuration\\Administrative Templates\\Windows Components\\Remote Desktop Services\\RD Session Host\\Profiles. The path set in the \"Set path for Remote Desktop Services Roaming User Profile\" policy setting should contain the mandatory profile.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-user-profiles"],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_profiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_profiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_profiles_ts_profile_path","displayName":"Profile path","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_touchinput_panningeverywhereoff_2","displayName":"Turn off Touch Panning","description":"Turn off Panning \r\nTurns off touch panning, which allows users pan inside windows by touch. On a compatible PC with a touch digitizer, by default users are able to scroll or pan inside a scrolling area by dragging up or down directly on the scrolling content.\r\n\r\nIf you enable this setting, the user will not be able to pan windows by touch. \r\n\r\nIf you disable this setting, the user can pan windows by touch.\r\n\r\nIf you do not configure this setting, Touch Panning is on by default.\r\n\r\nNote: Changes to this setting will not take effect until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-touchinput#admx-touchinput-panningeverywhereoff-2"],"categoryId":"abf781d7-1179-4f24-8d01-5611db14eddc","categoryName":"Touch Input","options":[{"id":"device_vendor_msft_policy_config_admx_touchinput_panningeverywhereoff_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_touchinput_panningeverywhereoff_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_touchinput_touchinputoff_2","displayName":"Turn off Tablet PC touch input","description":"Turn off Tablet PC touch input\r\n\r\nTurns off touch input, which allows the user to interact with their computer using their finger.\r\n\r\nIf you enable this setting, the user will not be able to produce input with touch. They will not be able to use touch input or touch gestures such as tap and double tap, the touch pointer, and other touch-specific features.\r\n\r\nIf you disable this setting, the user can produce input with touch, by using gestures, the touch pointer, and other-touch specific features.\r\n\r\nIf you do not configure this setting, touch input is on by default.\r\n\r\nNote: Changes to this setting will not take effect until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-touchinput#admx-touchinput-touchinputoff-2"],"categoryId":"abf781d7-1179-4f24-8d01-5611db14eddc","categoryName":"Touch Input","options":[{"id":"device_vendor_msft_policy_config_admx_touchinput_touchinputoff_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_touchinput_touchinputoff_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_blockedcommandslist_name","displayName":"Configure the list of blocked TPM commands","description":"This policy setting allows you to manage the Group Policy list of Trusted Platform Module (TPM) commands blocked by Windows.\r\n\r\nIf you enable this policy setting, Windows will block the specified commands from being sent to the TPM on the computer. TPM commands are referenced by a command number. For example, command number 129 is TPM_OwnerReadInternalPub, and command number 170 is TPM_FieldUpgrade. To find the command number associated with each TPM command with TPM 1.2, run \"tpm.msc\" and navigate to the \"Command Management\" section.\r\n\r\nIf you disable or do not configure this policy setting, only those TPM commands specified through the default or local lists may be blocked by Windows. The default list of blocked TPM commands is pre-configured by Windows. You can view the default list by running \"tpm.msc\", navigating to the \"Command Management\" section, and making visible the \"On Default Block List\" column. The local list of blocked TPM commands is configured outside of Group Policy by running \"tpm.msc\" or through scripting against the Win32_Tpm interface. See related policy settings to enforce or ignore the default and local lists of blocked TPM commands.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-blockedcommandslist-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_blockedcommandslist_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_blockedcommandslist_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_blockedcommandslist_name_blockedcommandslist_ordinals2","displayName":"The list of blocked TPM commands:","description":null,"helpText":"","infoUrls":[],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":null},{"id":"device_vendor_msft_policy_config_admx_tpm_cleartpmifnotready_name","displayName":"Configure the system to clear the TPM if it is not in a ready state.","description":"This policy setting configures the system to prompt the user to clear the TPM if the TPM is detected to be in any state other than Ready. This policy will take effect only if the system’s TPM is in a state other than Ready, including if the TPM is “Ready, with reduced functionality”. The prompt to clear the TPM will start occurring after the next reboot, upon user login only if the logged in user is part of the Administrators group for the system. The prompt can be dismissed, but will reappear after every reboot and login until the policy is disabled or until the TPM is in a Ready state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-cleartpmifnotready-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_cleartpmifnotready_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_cleartpmifnotready_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_ignoredefaultlist_name","displayName":"Ignore the default list of blocked TPM commands","description":"This policy setting allows you to enforce or ignore the computer's default list of blocked Trusted Platform Module (TPM) commands.\r\n\r\nIf you enable this policy setting, Windows will ignore the computer's default list of blocked TPM commands and will only block those TPM commands specified by Group Policy or the local list.\r\n\r\nThe default list of blocked TPM commands is pre-configured by Windows. You can view the default list by running \"tpm.msc\", navigating to the \"Command Management\" section, and making visible the \"On Default Block List\" column. The local list of blocked TPM commands is configured outside of Group Policy by running \"tpm.msc\" or through scripting against the Win32_Tpm interface. See the related policy setting to configure the Group Policy list of blocked TPM commands.\r\n\r\nIf you disable or do not configure this policy setting, Windows will block the TPM commands in the default list, in addition to commands in the Group Policy and local lists of blocked TPM commands. \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-ignoredefaultlist-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_ignoredefaultlist_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_ignoredefaultlist_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_ignorelocallist_name","displayName":"Ignore the local list of blocked TPM commands","description":"This policy setting allows you to enforce or ignore the computer's local list of blocked Trusted Platform Module (TPM) commands.\r\n\r\nIf you enable this policy setting, Windows will ignore the computer's local list of blocked TPM commands and will only block those TPM commands specified by Group Policy or the default list.\r\n\r\nThe local list of blocked TPM commands is configured outside of Group Policy by running \"tpm.msc\" or through scripting against the Win32_Tpm interface. The default list of blocked TPM commands is pre-configured by Windows. See the related policy setting to configure the Group Policy list of blocked TPM commands.\r\n\r\nIf you disable or do not configure this policy setting, Windows will block the TPM commands found in the local list, in addition to commands in the Group Policy and default lists of blocked TPM commands.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-ignorelocallist-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_ignorelocallist_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_ignorelocallist_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_optintodsha_name","displayName":"Enable Device Health Attestation Monitoring and Reporting","description":"This group policy enables Device Health Attestation reporting (DHA-report) on supported devices. It enables supported devices to send Device Health Attestation related information (device boot logs, PCR values, TPM certificate, etc.) to Device Health Attestation Service (DHA-Service) every time a device starts. Device Health Attestation Service validates the security state and health of the devices, and makes the findings accessible to enterprise administrators via a cloud based reporting portal. This policy is independent of DHA reports that are initiated by device manageability solutions (like MDM or SCCM), and will not interfere with their workflows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-optintodsha-name"],"categoryId":"99b4ac32-50b5-4659-a7a1-94bc708ae71a","categoryName":"Device Health Attestation Service","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_optintodsha_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_optintodsha_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name","displayName":"Configure the level of TPM owner authorization information available to the operating system","description":"This policy setting configures how much of the TPM owner authorization information is stored in the registry of the local computer. Depending on the amount of TPM owner authorization information stored locally, the operating system and TPM-based applications can perform certain TPM actions which require TPM owner authorization without requiring the user to enter the TPM owner password.\r\n\r\nYou can choose to have the operating system store either the full TPM owner authorization value, the TPM administrative delegation blob plus the TPM user delegation blob, or none.\r\n\r\nIf you enable this policy setting, Windows will store the TPM owner authorization in the registry of the local computer according to the operating system managed TPM authentication setting you choose.\r\n\r\nChoose the operating system managed TPM authentication setting of \"Full\" to store the full TPM owner authorization, the TPM administrative delegation blob and the TPM user delegation blob in the local registry. This setting allows use of the TPM without requiring remote or external storage of the TPM owner authorization value. This setting is appropriate for scenarios which do not depend on preventing reset of the TPM anti-hammering logic or changing the TPM owner authorization value. Some TPM-based applications may require this setting be changed before features which depend on the TPM anti-hammering logic can be used.\r\n\r\nChoose the operating system managed TPM authentication setting of \"Delegated\" to store only the TPM administrative delegation blob and the TPM user delegation blob in the local registry. This setting is appropriate for use with TPM-based applications that depend on the TPM anti-hammering logic.\r\n\r\nChoose the operating system managed TPM authentication setting of \"None\" for compatibility with previous operating systems and applications or for use with scenarios that require TPM owner authorization not be stored locally. Using this setting might cause issues with some TPM-based applications.\r\n\r\nNote: If the operating system managed TPM authentication setting is changed from \"Full\" to \"Delegated\", the full TPM owner authorization value will be regenerated and any copies of the original TPM owner authorization value will be invalid.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-osmanagedauth-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name_selectosmanagedauthlevel","displayName":"Operating system managed TPM authentication level:","description":null,"helpText":"","infoUrls":[],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name_selectosmanagedauthlevel_4","displayName":"Full","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name_selectosmanagedauthlevel_2","displayName":"Delegated","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_osmanagedauth_name_selectosmanagedauthlevel_0","displayName":"None","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureduration_name","displayName":"Standard User Lockout Duration","description":"This policy setting allows you to manage the duration in minutes for counting standard user authorization failures for Trusted Platform Module (TPM) commands requiring authorization. If the number of TPM commands with an authorization failure within the duration equals a threshold, a standard user is prevented from sending commands requiring authorization to the TPM.\r\n\r\nThis setting helps administrators prevent the TPM hardware from entering a lockout mode because it slows the speed standard users can send commands requiring authorization to the TPM.\r\n\r\nAn authorization failure occurs each time a standard user sends a command to the TPM and receives an error response indicating an authorization failure occurred. Authorization failures older than this duration are ignored.\r\n\r\nFor each standard user two thresholds apply. Exceeding either threshold will prevent the standard user from sending a command to the TPM that requires authorization.\r\n\r\nThe Standard User Lockout Threshold Individual value is the maximum number of authorization failures each standard user may have before the user is not allowed to send commands requiring authorization to the TPM.\r\n\r\nThe Standard User Lockout Total Threshold value is the maximum total number of authorization failures all standard users may have before all standard users are not allowed to send commands requiring authorization to the TPM.\r\n\r\nThe TPM is designed to protect itself against password guessing attacks by entering a hardware lockout mode when it receives too many commands with an incorrect authorization value. When the TPM enters a lockout mode it is global for all users including administrators and Windows features like BitLocker Drive Encryption. The number of authorization failures a TPM allows and how long it stays locked out vary by TPM manufacturer. Some TPMs may enter lockout mode for successively longer periods of time with fewer authorization failures depending on past failures. Some TPMs may require a system restart to exit the lockout mode. Other TPMs may require the system to be on so enough clock cycles elapse before the TPM exits the lockout mode.\r\n\r\nAn administrator with the TPM owner password may fully reset the TPM's hardware lockout logic using the TPM Management Console (tpm.msc). Each time an administrator resets the TPM's hardware lockout logic all prior standard user TPM authorization failures are ignored; allowing standard users to use the TPM normally again immediately.\r\n\r\nIf this value is not configured, a default value of 480 minutes (8 hours) is used.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-standarduserauthorizationfailureduration-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureduration_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureduration_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureduration_name_dxt_standarduserauthorizationfailureduration_name","displayName":"Duration for counting TPM authorization failures (minutes):","description":null,"helpText":"","infoUrls":[],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":null},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureindividualthreshold_name","displayName":"Standard User Individual Lockout Threshold","description":"This policy setting allows you to manage the maximum number of authorization failures for each standard user for the Trusted Platform Module (TPM). If the number of authorization failures for the user within the duration for Standard User Lockout Duration equals this value, the standard user is prevented from sending commands to the Trusted Platform Module (TPM) that require authorization.\r\n\r\nThis setting helps administrators prevent the TPM hardware from entering a lockout mode because it slows the speed standard users can send commands requiring authorization to the TPM.\r\n\r\nAn authorization failure occurs each time a standard user sends a command to the TPM and receives an error response indicating an authorization failure occurred. Authorization failures older than the duration are ignored.\r\n\r\nFor each standard user two thresholds apply. Exceeding either threshold will prevent the standard user from sending a command to the TPM that requires authorization.\r\n\r\nThis value is the maximum number of authorization failures each standard user may have before the user is not allowed to send commands requiring authorization to the TPM.\r\n\r\nThe Standard User Lockout Total Threshold value is the maximum total number of authorization failures all standard users may have before all standard users are not allowed to send commands requiring authorization to the TPM.\r\n\r\nThe TPM is designed to protect itself against password guessing attacks by entering a hardware lockout mode when it receives too many commands with an incorrect authorization value. When the TPM enters a lockout mode it is global for all users including administrators and Windows features like BitLocker Drive Encryption. The number of authorization failures a TPM allows and how long it stays locked out vary by TPM manufacturer. Some TPMs may enter lockout mode for successively longer periods of time with fewer authorization failures depending on past failures. Some TPMs may require a system restart to exit the lockout mode. Other TPMs may require the system to be on so enough clock cycles elapse before the TPM exits the lockout mode.\r\n\r\nAn administrator with the TPM owner password may fully reset the TPM's hardware lockout logic using the TPM Management Console (tpm.msc). Each time an administrator resets the TPM's hardware lockout logic all prior standard user TPM authorization failures are ignored; allowing standard users to use the TPM normally again immediately.\r\n\r\nIf this value is not configured, a default value of 4 is used.\r\n\r\nA value of zero means the OS will not allow standard users to send commands to the TPM which may cause an authorization failure.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-standarduserauthorizationfailureindividualthreshold-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureindividualthreshold_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureindividualthreshold_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailureindividualthreshold_name_dxt_standarduserauthorizationfailureindividualthreshold_name","displayName":"Maximum number of authorization failures per duration:","description":null,"helpText":"","infoUrls":[],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":null},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailuretotalthreshold_name","displayName":"Standard User Total Lockout Threshold","description":"This policy setting allows you to manage the maximum number of authorization failures for all standard users for the Trusted Platform Module (TPM). If the total number of authorization failures for all standard users within the duration for Standard User Lockout Duration equals this value, all standard users are prevented from sending commands to the Trusted Platform Module (TPM) that require authorization.\r\n\r\nThis setting helps administrators prevent the TPM hardware from entering a lockout mode because it slows the speed standard users can send commands requiring authorization to the TPM.\r\n\r\nAn authorization failure occurs each time a standard user sends a command to the TPM and receives an error response indicating an authorization failure occurred. Authorization failures older than the duration are ignored.\r\n\r\nFor each standard user two thresholds apply. Exceeding either threshold will prevent the standard user from sending a command to the TPM that requires authorization.\r\n\r\nThe Standard User Individual Lockout value is the maximum number of authorization failures each standard user may have before the user is not allowed to send commands requiring authorization to the TPM.\r\n\r\nThis value is the maximum total number of authorization failures all standard users may have before all standard users are not allowed to send commands requiring authorization to the TPM.\r\n\r\nThe TPM is designed to protect itself against password guessing attacks by entering a hardware lockout mode when it receives too many commands with an incorrect authorization value. When the TPM enters a lockout mode it is global for all users including administrators and Windows features like BitLocker Drive Encryption. The number of authorization failures a TPM allows and how long it stays locked out vary by TPM manufacturer. Some TPMs may enter lockout mode for successively longer periods of time with fewer authorization failures depending on past failures. Some TPMs may require a system restart to exit the lockout mode. Other TPMs may require the system to be on so enough clock cycles elapse before the TPM exits the lockout mode.\r\n\r\nAn administrator with the TPM owner password may fully reset the TPM's hardware lockout logic using the TPM Management Console (tpm.msc). Each time an administrator resets the TPM's hardware lockout logic all prior standard user TPM authorization failures are ignored; allowing standard users to use the TPM normally again immediately.\r\n\r\nIf this value is not configured, a default value of 9 is used.\r\n\r\nA value of zero means the OS will not allow standard users to send commands to the TPM which may cause an authorization failure.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-standarduserauthorizationfailuretotalthreshold-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailuretotalthreshold_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailuretotalthreshold_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailuretotalthreshold_name_dxt_standarduserauthorizationfailuretotalthreshold_name","displayName":"Maximum number of authorization failures per duration:","description":null,"helpText":"","infoUrls":[],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":null},{"id":"device_vendor_msft_policy_config_admx_tpm_uselegacydap_name","displayName":"Configure the system to use legacy Dictionary Attack Prevention Parameters setting for TPM 2.0.","description":"This policy setting configures the TPM to use the Dictionary Attack Prevention Parameters (lockout threshold and recovery time) to the values that were used for Windows 10 Version 1607 and below. Setting this policy will take effect only if a) the TPM was originally prepared using a version of Windows after Windows 10 Version 1607 and b) the System has a TPM 2.0. Note that enabling this policy will only take effect after the TPM maintenance task runs (which typically happens after a system restart). Once this policy has been enabled on a system and has taken effect (after a system restart), disabling it will have no impact and the system's TPM will remain configured using the legacy Dictionary Attack Prevention parameters, regardless of the value of this group policy. The only way for the disabled setting of this policy to take effect on a system where it was once enabled is to a) disable it from group policy and b)clear the TPM on the system.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-uselegacydap-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_uselegacydap_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_uselegacydap_name_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_calculator","displayName":"Calculator","description":"This policy setting configures the synchronization of user settings of Calculator.\r\nBy default, the user settings of Calculator synchronize between computers. Use the policy setting to prevent the user settings of Calculator from synchronization between computers. \r\nIf you enable this policy setting, the Calculator user settings continue to synchronize. \r\nIf you disable this policy setting, Calculator user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-calculator"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_calculator_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_calculator_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod","displayName":"Configure Sync Method","description":"This policy setting configures the sync provider used by User Experience Virtualization (UE-V) to sync settings between users’ computers. With Sync Method set to ”SyncProvider,” the UE-V Agent uses a built-in sync provider to keep user settings synchronized between the computer and the settings storage location. This is the default value. You can disable the sync provider on computers that never go offline and are always connected to the settings storage location.\r\nWhen SyncMethod is set to “None,” the UE-V Agent uses no sync provider. Settings are written directly to the settings storage location rather than being cached to sync later. \r\nSet SyncMethod to “External” when an external synchronization engine is being deployed for settings sync. This could use OneDrive, Work Folders, SharePoint or any other engine that uses a local folder to synchronize data between users’ computers. In this mode, UE-V writes settings data to the local folder specified in the settings storage path. These settings are then synchronized to other computers by an external synchronization engine. UE-V has no control over this synchronization. It only reads and writes the settings data when the normal UE-V triggers take place.\r\nWith notifications enabled, UE-V users receive a message when the settings sync is delayed. The notification delay policy setting defines the delay before a notification appears.\r\nIf you disable this policy setting, the sync provider is used to synchronize settings between computers and the settings storage location.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-configuresyncmethod"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_delay","displayName":"Notification delay (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_enable","displayName":"Enable notification","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_enable_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_enable_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_syncmethodconfiguration_list","displayName":"Sync Method:","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_syncmethodconfiguration_list_syncprovider","displayName":"SyncProvider","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_syncmethodconfiguration_list_none","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_syncmethodconfiguration_list_external","displayName":"External","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi","displayName":"VDI Configuration","description":"This policy setting configures the synchronization of User Experience Virtualization (UE-V) rollback information for computers running in a non-persistent, pooled VDI environment. UE-V settings rollback data and checkpoints are normally stored only on the local computer. With this policy setting enabled, the rollback information is copied to the settings storage location when the user logs off or shuts down their VDI session. Enable this setting to register a VDI-specific settings location template and restore data on computers in pooled VDI environments that reset to a clean state on logout. With this policy enabled you can roll settings back to the state when UE-V was installed or to “last-known-good” configurations. Only enable this policy setting on computers running in a non-persistent VDI environment. The VDI Collection Name defines the name of the virtual desktop collection containing the virtual computers. \r\nIf you enable this policy setting, the UE-V rollback state is copied to the settings storage location on logout and restored on login.\r\nIf you disable this policy setting, no UE-V rollback state is copied to the settings storage location.\r\nIf you do not configure this policy, no UE-V rollback state is copied to the settings storage location.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-configurevdi"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi_vdicollectionname","displayName":"VDI Collection Name:","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactitdescription","displayName":"Contact IT Link Text","description":"This policy setting specifies the text of the Contact IT URL hyperlink in the Company Settings Center.\r\nIf you enable this policy setting, the Company Settings Center displays the specified text in the link to the Contact IT URL.\r\nIf you disable this policy setting, the Company Settings Center does not display an IT Contact link.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-contactitdescription"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactitdescription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactitdescription_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactitdescription_contactitdescription","displayName":"Contact IT Link Text","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactiturl","displayName":"Contact IT URL","description":"This policy setting specifies the URL for the Contact IT link in the Company Settings Center.\r\nIf you enable this policy setting, the Company Settings Center Contact IT text links to the specified URL. The link can be of any standard protocol such as http or mailto. \r\nIf you disable this policy setting, the Company Settings Center does not display an IT Contact link.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-contactiturl"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactiturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactiturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactiturl_contactiturl","displayName":"Contact IT URL","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewin8sync","displayName":"Do not synchronize Windows Apps","description":"This policy setting defines whether the User Experience Virtualization (UE-V) Agent synchronizes settings for Windows apps.\r\nBy default, the UE-V Agent synchronizes settings for Windows apps between the computer and the settings storage location. \r\nIf you enable this policy setting, the UE-V Agent will not synchronize settings for Windows apps.\r\nIf you disable this policy setting, the UE-V Agent will synchronize settings for Windows apps. \r\nIf you do not configure this policy setting, any defined values are deleted.\r\nNote: If the user connects their Microsoft account for their computer then the UE-V Agent will not synchronize Windows apps. The Windows apps will default to whatever settings are configured in the Sync your settings configuration in Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-disablewin8sync"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewin8sync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewin8sync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings","displayName":"Synchronize Windows settings","description":"\r\nThis policy setting configures the synchronization of Windows settings between computers.\r\nCertain Windows settings will synchronize between computers by default. These settings include Windows themes, Windows desktop settings, Ease of Access settings, and network printers. Use this policy setting to specify which Windows settings synchronize between computers. You can also use these settings to enable synchronization of users' sign-in information for certain apps, networks, and certificates.\r\nIf you enable this policy setting, only the selected Windows settings synchronize. Unselected Windows settings are excluded from settings synchronization.\r\nIf you disable this policy setting, all Windows Settings are excluded from the settings synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-disablewindowsossettings"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_desktopsettings","displayName":"Desktop settings","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_desktopsettings_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_desktopsettings_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_easeofaccesssettings","displayName":"Ease of access","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_easeofaccesssettings_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_easeofaccesssettings_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_networkprinters","displayName":"Network Printers","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_networkprinters_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_networkprinters_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings","displayName":"Roaming Credentials","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_themesettings","displayName":"Themes","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_themesettings_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_themesettings_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_enableuev","displayName":"Enable UEV","description":"This policy setting allows you to enable or disable User Experience Virtualization (UE-V) feature. Reboot is needed for enable to take effect. With Auto-register inbox templates enabled, the UE-V inbox templates such as Office 2016 will be automatically registered when the UE-V Service is enabled. If this option is changed, it will only take effect when UE-V service is re-enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-enableuev"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_enableuev_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_enableuev_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_enableuev_registerinboxtemplates","displayName":"Auto-register inbox templates","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_enableuev_registerinboxtemplates_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_enableuev_registerinboxtemplates_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_finance","displayName":"Finance","description":"This policy setting configures the synchronization of user settings for the Finance app.\r\nBy default, the user settings of Finance sync between computers. Use the policy setting to prevent the user settings of Finance from synchronizing between computers.\r\nIf you enable this policy setting, Finance user settings continue to sync.\r\nIf you disable this policy setting, Finance user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-finance"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_finance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_finance_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_firstusenotificationenabled","displayName":"First Use Notification","description":"This policy setting enables a notification in the system tray that appears when the User Experience Virtualization (UE-V) Agent runs for the first time.\r\nBy default, a notification informs users that Company Settings Center, the user-facing name for the UE-V Agent, now helps to synchronize settings between their work computers.\r\nWith this setting enabled, the notification appears the first time that the UE-V Agent runs.\r\nWith this setting disabled, no notification appears.\r\nIf you do not configure this policy setting, any defined values are deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-firstusenotificationenabled"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_firstusenotificationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_firstusenotificationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_games","displayName":"Games","description":"This policy setting configures the synchronization of user settings for the Games app.\r\nBy default, the user settings of Games sync between computers. Use the policy setting to prevent the user settings of Games from synchronizing between computers.\r\nIf you enable this policy setting, Games user settings continue to sync.\r\nIf you disable this policy setting, Games user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-games"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_games_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_games_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10","displayName":"Internet Explorer 10","description":"This policy setting configures the synchronization of user settings of Internet Explorer 10.\r\nBy default, the user settings of Internet Explorer 10 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 10 from synchronization between computers. \r\nIf you enable this policy setting, the Internet Explorer 10 user settings continue to synchronize. \r\nIf you disable this policy setting, Internet Explorer 10 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer10"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer11","displayName":"Internet Explorer 11","description":"This policy setting configures the synchronization of user settings of Internet Explorer 11.\r\nBy default, the user settings of Internet Explorer 11 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 11 from synchronization between computers.\r\nIf you enable this policy setting, the Internet Explorer 11 user settings continue to synchronize.\r\nIf you disable this policy setting, Internet Explorer 11 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer11"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer8","displayName":"Internet Explorer 8","description":"This policy setting configures the synchronization of user settings for Internet Explorer 8.\r\nBy default, the user settings of Internet Explorer 8 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 8 from synchronization between computers. \r\nIf you enable this policy setting, the Internet Explorer 8 user settings continue to synchronize. \r\nIf you disable this policy setting, Internet Explorer 8 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer8"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer8_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer9","displayName":"Internet Explorer 9","description":"This policy setting configures the synchronization of user settings for Internet Explorer 9.\r\nBy default, the user settings of Internet Explorer 9 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 9 from synchronization between computers. \r\nIf you enable this policy setting, the Internet Explorer 9 user settings continue to synchronize. \r\nIf you disable this policy setting, Internet Explorer 9 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer9"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer9_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer9_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorercommon","displayName":"Internet Explorer Common Settings","description":"This policy setting configures the synchronization of user settings which are common between the versions of Internet Explorer.\r\nBy default, the user settings which are common between the versions of Internet Explorer synchronize between computers. Use the policy setting to prevent the user settings of Internet Explorer from synchronization between computers. \r\nIf you enable this policy setting, the user settings which are common between the versions of Internet Explorer continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the versions of Internet Explorer are excluded from settings synchronization. If any version of the Internet Explorer settings are enabled this policy setting should not be disabled.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorercommon"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorercommon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorercommon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maps","displayName":"Maps","description":"This policy setting configures the synchronization of user settings for the Maps app.\r\nBy default, the user settings of Maps sync between computers. Use the policy setting to prevent the user settings of Maps from synchronizing between computers.\r\nIf you enable this policy setting, Maps user settings continue to sync.\r\nIf you disable this policy setting, Maps user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-maps"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maxpackagesizeinbytes","displayName":"Settings package size warning threshold","description":"This policy setting allows you to configure the UE-V Agent to write a warning event to the event log when a settings package file size reaches a defined threshold. By default the UE-V Agent does not report information about package file size. \r\nIf you enable this policy setting, specify the threshold file size in bytes. When the settings package file exceeds this threshold the UE-V Agent will write a warning event to the event log.\r\nIf you disable or do not configure this policy setting, no event is written to the event log to report settings package size.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-maxpackagesizeinbytes"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maxpackagesizeinbytes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maxpackagesizeinbytes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_maxpackagesizeinbytes_maxpackagesizeinbytes","displayName":"Package size threshold (in bytes):","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010access","displayName":"Microsoft Access 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Access 2010.\r\nBy default, the user settings of Microsoft Access 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Access 2010 from synchronization between computers. \r\nIf you enable this policy setting, Microsoft Access 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Access 2010 user settings are excluded from the synchronization settings. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010access"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010access_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010access_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010common","displayName":"Microsoft Office 2010 Common Settings","description":"This policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2010 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2010 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2010 applications from synchronization between computers. \r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2010 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2010 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2010 applications are enabled, this policy setting should not be disabled \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010common_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010excel","displayName":"Microsoft Excel 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Excel 2010.\r\nBy default, the user settings of Microsoft Excel 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Excel 2010 from synchronization between computers. \r\nIf you enable this policy setting, Microsoft Excel 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Excel 2010 user settings are excluded from the synchronization settings. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010excel"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010excel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010excel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010infopath","displayName":"Microsoft InfoPath 2010","description":"This policy setting configures the synchronization of user settings for Microsoft InfoPath 2010.\r\nBy default, the user settings of Microsoft InfoPath 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft InfoPath 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft InfoPath 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft InfoPath 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010infopath"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010infopath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010infopath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010lync","displayName":"Microsoft Lync 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Lync 2010.\r\nBy default, the user settings of Microsoft Lync 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Lync 2010 from synchronization between computers. \r\nIf you enable this policy setting, Microsoft Lync 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Lync 2010 user settings are excluded from the synchronization settings. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010lync"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010lync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010lync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010onenote","displayName":"Microsoft OneNote 2010","description":"This policy setting configures the synchronization of user settings for Microsoft OneNote 2010.\r\nBy default, the user settings of Microsoft OneNote 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010onenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010outlook","displayName":"Microsoft Outlook 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Outlook 2010.\r\nBy default, the user settings of Microsoft Outlook 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Outlook 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Outlook 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Outlook 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010outlook"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010outlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010outlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010powerpoint","displayName":"Microsoft PowerPoint 2010","description":"This policy setting configures the synchronization of user settings for Microsoft PowerPoint 2010.\r\nBy default, the user settings of Microsoft PowerPoint 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft PowerPoint 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft PowerPoint 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft PowerPoint 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010powerpoint"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010powerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010powerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010project","displayName":"Microsoft Project 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Project 2010.\r\nBy default, the user settings of Microsoft Project 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Project 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Project 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Project 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010project"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010project_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010project_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010publisher","displayName":"Microsoft Publisher 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Publisher 2010.\r\nBy default, the user settings of Microsoft Publisher 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Publisher 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Publisher 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Publisher 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010publisher"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010publisher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010publisher_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointdesigner","displayName":"Microsoft SharePoint Designer 2010","description":"This policy setting configures the synchronization of user settings for Microsoft SharePoint Designer 2010.\r\nBy default, the user settings of Microsoft SharePoint Designer 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Designer 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Designer 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Designer 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010sharepointdesigner"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointdesigner_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointdesigner_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace","displayName":"Microsoft SharePoint Workspace 2010","description":"This policy setting configures the synchronization of user settings for Microsoft SharePoint Workspace 2010.\r\nBy default, the user settings of Microsoft SharePoint Workspace 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Workspace 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Workspace 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Workspace 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010sharepointworkspace"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010visio","displayName":"Microsoft Visio 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Visio 2010.\r\nBy default, the user settings of Microsoft Visio 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Visio 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Visio 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Visio 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010visio"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010visio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010visio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010word","displayName":"Microsoft Word 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Word 2010.\r\nBy default, the user settings of Microsoft Word 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Word 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Word 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Word 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010word"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010word_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010word_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013access","displayName":"Microsoft Access 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Access 2013.\r\nBy default, the user settings of Microsoft Access 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Access 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Access 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Access 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013access"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013access_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013access_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013accessbackup","displayName":"Access 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Access 2013.\r\nMicrosoft Access 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Access 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Access 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Access 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013accessbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013accessbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013accessbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013common","displayName":"Microsoft Office 2013 Common Settings","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2013 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2013 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2013 applications from synchronization between computers.\r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2013 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2013 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2013 applications are enabled, this policy setting should not be disabled.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013common_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013commonbackup","displayName":"Common 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings which are common between the Microsoft Office Suite 2013 applications.\r\nMicrosoft Office Suite 2013 has user settings which are common between applications and are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific common Microsoft Office Suite 2013 applications.\r\nIf you enable this policy setting, certain user settings which are common between the Microsoft Office Suite 2013 applications will continue to be backed up.\r\nIf you disable this policy setting, certain user settings which are common between the Microsoft Office Suite 2013 applications will not be backed up. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013commonbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013commonbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013commonbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excel","displayName":"Microsoft Excel 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Excel 2013.\r\nBy default, the user settings of Microsoft Excel 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Excel 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Excel 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Excel 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013excel"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excelbackup","displayName":"Excel 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Excel 2013.\r\nMicrosoft Excel 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Excel 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Excel 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Excel 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013excelbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excelbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excelbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopath","displayName":"Microsoft InfoPath 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft InfoPath 2013.\r\nBy default, the user settings of Microsoft InfoPath 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft InfoPath 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft InfoPath 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft InfoPath 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013infopath"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup","displayName":"InfoPath 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft InfoPath 2013.\r\nMicrosoft InfoPath 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft InfoPath 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft InfoPath 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft InfoPath 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013infopathbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lync","displayName":"Microsoft Lync 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Lync 2013.\r\nBy default, the user settings of Microsoft Lync 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Lync 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Lync 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Lync 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013lync"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lyncbackup","displayName":"Lync 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Lync 2013.\r\nMicrosoft Lync 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Lync 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Lync 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Lync 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013lyncbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lyncbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lyncbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onedriveforbusiness","displayName":"Microsoft OneDrive for Business 2013","description":"\r\nThis policy setting configures the synchronization of user settings for OneDrive for Business 2013.\r\nBy default, the user settings of OneDrive for Business 2013 synchronize between computers. Use the policy setting to prevent the user settings of OneDrive for Business 2013 from synchronization between computers.\r\nIf you enable this policy setting, OneDrive for Business 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, OneDrive for Business 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013onedriveforbusiness"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onedriveforbusiness_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onedriveforbusiness_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenote","displayName":"Microsoft OneNote 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft OneNote 2013.\r\nBy default, the user settings of Microsoft OneNote 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenotebackup","displayName":"OneNote 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft OneNote 2013.\r\nMicrosoft OneNote 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft OneNote 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft OneNote 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft OneNote 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013onenotebackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenotebackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenotebackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlook","displayName":"Microsoft Outlook 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Outlook 2013.\r\nBy default, the user settings of Microsoft Outlook 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Outlook 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Outlook 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Outlook 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013outlook"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlookbackup","displayName":"Outlook 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Outlook 2013.\r\nMicrosoft Outlook 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Outlook 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Outlook 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Outlook 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013outlookbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlookbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlookbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpoint","displayName":"Microsoft PowerPoint 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft PowerPoint 2013.\r\nBy default, the user settings of Microsoft PowerPoint 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft PowerPoint 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft PowerPoint 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft PowerPoint 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013powerpoint"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpointbackup","displayName":"PowerPoint 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft PowerPoint 2013.\r\nMicrosoft PowerPoint 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft PowerPoint 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft PowerPoint 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft PowerPoint 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013powerpointbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpointbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpointbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013project","displayName":"Microsoft Project 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Project 2013.\r\nBy default, the user settings of Microsoft Project 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Project 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Project 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Project 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013project"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013project_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013project_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013projectbackup","displayName":"Project 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Project 2013.\r\nMicrosoft Project 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Project 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Project 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Project 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013projectbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013projectbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013projectbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisher","displayName":"Microsoft Publisher 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Publisher 2013.\r\nBy default, the user settings of Microsoft Publisher 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Publisher 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Publisher 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Publisher 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013publisher"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisher_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisherbackup","displayName":"Publisher 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Publisher 2013.\r\nMicrosoft Publisher 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Publisher 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Publisher 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Publisher 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013publisherbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisherbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisherbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesigner","displayName":"Microsoft SharePoint Designer 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft SharePoint Designer 2013.\r\nBy default, the user settings of Microsoft SharePoint Designer 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Designer 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Designer 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Designer 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013sharepointdesigner"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesigner_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesigner_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesignerbackup","displayName":"SharePoint Designer 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft SharePoint Designer 2013.\r\nMicrosoft SharePoint Designer 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft SharePoint Designer 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft SharePoint Designer 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft SharePoint Designer 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013sharepointdesignerbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesignerbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesignerbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013uploadcenter","displayName":"Microsoft Office 2013 Upload Center","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 2013 Upload Center.\r\nBy default, the user settings of Microsoft Office 2013 Upload Center synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Office 2013 Upload Center from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Office 2013 Upload Center user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Office 2013 Upload Center user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013uploadcenter"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013uploadcenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013uploadcenter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visio","displayName":"Microsoft Visio 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Visio 2013.\r\nBy default, the user settings of Microsoft Visio 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Visio 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Visio 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Visio 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013visio"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visiobackup","displayName":"Visio 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Visio 2013.\r\nMicrosoft Visio 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Visio 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Visio 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Visio 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013visiobackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visiobackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visiobackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013word","displayName":"Microsoft Word 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Word 2013.\r\nBy default, the user settings of Microsoft Word 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Word 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Word 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Word 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013word"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013word_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013word_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013wordbackup","displayName":"Word 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Word 2013.\r\nMicrosoft Word 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Word 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Word 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Word 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013wordbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013wordbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013wordbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016access","displayName":"Microsoft Access 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Access 2016.\r\nBy default, the user settings of Microsoft Access 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Access 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Access 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Access 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016access"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016access_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016access_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016accessbackup","displayName":"Access 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Access 2016.\r\nMicrosoft Access 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Access 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Access 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Access 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016accessbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016accessbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016accessbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common","displayName":"Microsoft Office 2016 Common Settings","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2016 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2016 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2016 applications from synchronization between computers.\r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2016 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2016 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2016 applications are enabled, this policy setting should not be disabled.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016commonbackup","displayName":"Common 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings which are common between the Microsoft Office Suite 2016 applications.\r\nMicrosoft Office Suite 2016 has user settings which are common between applications and are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific common Microsoft Office Suite 2016 applications.\r\nIf you enable this policy setting, certain user settings which are common between the Microsoft Office Suite 2016 applications will continue to be backed up.\r\nIf you disable this policy setting, certain user settings which are common between the Microsoft Office Suite 2016 applications will not be backed up. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016commonbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016commonbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016commonbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excel","displayName":"Microsoft Excel 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Excel 2016.\r\nBy default, the user settings of Microsoft Excel 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Excel 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Excel 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Excel 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016excel"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excelbackup","displayName":"Excel 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Excel 2016.\r\nMicrosoft Excel 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Excel 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Excel 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Excel 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016excelbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excelbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excelbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lync","displayName":"Microsoft Lync 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Lync 2016.\r\nBy default, the user settings of Microsoft Lync 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Lync 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Lync 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Lync 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016lync"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lyncbackup","displayName":"Lync 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Lync 2016.\r\nMicrosoft Lync 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Lync 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Lync 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Lync 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016lyncbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lyncbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lyncbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onedriveforbusiness","displayName":"Microsoft OneDrive for Business 2016","description":"\r\nThis policy setting configures the synchronization of user settings for OneDrive for Business 2016.\r\nBy default, the user settings of OneDrive for Business 2016 synchronize between computers. Use the policy setting to prevent the user settings of OneDrive for Business 2016 from synchronization between computers.\r\nIf you enable this policy setting, OneDrive for Business 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, OneDrive for Business 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016onedriveforbusiness"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onedriveforbusiness_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onedriveforbusiness_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote","displayName":"Microsoft OneNote 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft OneNote 2016.\r\nBy default, the user settings of Microsoft OneNote 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenotebackup","displayName":"OneNote 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft OneNote 2016.\r\nMicrosoft OneNote 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft OneNote 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft OneNote 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft OneNote 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016onenotebackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenotebackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenotebackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlook","displayName":"Microsoft Outlook 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Outlook 2016.\r\nBy default, the user settings of Microsoft Outlook 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Outlook 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Outlook 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Outlook 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016outlook"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup","displayName":"Outlook 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Outlook 2016.\r\nMicrosoft Outlook 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Outlook 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Outlook 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Outlook 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016outlookbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016powerpoint","displayName":"Microsoft PowerPoint 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft PowerPoint 2016.\r\nBy default, the user settings of Microsoft PowerPoint 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft PowerPoint 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft PowerPoint 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft PowerPoint 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016powerpoint"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016powerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016powerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016powerpointbackup","displayName":"PowerPoint 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft PowerPoint 2016.\r\nMicrosoft PowerPoint 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft PowerPoint 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft PowerPoint 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft PowerPoint 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016powerpointbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016powerpointbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016powerpointbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016project","displayName":"Microsoft Project 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Project 2016.\r\nBy default, the user settings of Microsoft Project 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Project 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Project 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Project 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016project"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016project_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016project_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016projectbackup","displayName":"Project 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Project 2016.\r\nMicrosoft Project 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Project 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Project 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Project 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016projectbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016projectbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016projectbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisher","displayName":"Microsoft Publisher 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Publisher 2016.\r\nBy default, the user settings of Microsoft Publisher 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Publisher 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Publisher 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Publisher 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016publisher"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisher_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisherbackup","displayName":"Publisher 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Publisher 2016.\r\nMicrosoft Publisher 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Publisher 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Publisher 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Publisher 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016publisherbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisherbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisherbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016uploadcenter","displayName":"Microsoft Office 2016 Upload Center","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 2016 Upload Center.\r\nBy default, the user settings of Microsoft Office 2016 Upload Center synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Office 2016 Upload Center from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Office 2016 Upload Center user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Office 2016 Upload Center user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016uploadcenter"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016uploadcenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016uploadcenter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visio","displayName":"Microsoft Visio 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Visio 2016.\r\nBy default, the user settings of Microsoft Visio 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Visio 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Visio 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Visio 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016visio"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visiobackup","displayName":"Visio 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Visio 2016.\r\nMicrosoft Visio 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Visio 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Visio 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Visio 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016visiobackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visiobackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visiobackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016word","displayName":"Microsoft Word 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Word 2016.\r\nBy default, the user settings of Microsoft Word 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Word 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Word 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Word 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016word"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016word_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016word_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016wordbackup","displayName":"Word 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Word 2016.\r\nMicrosoft Word 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Word 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Word 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Word 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016wordbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016wordbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016wordbackup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2013","displayName":"Microsoft Office 365 Access 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Access 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Access 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Access 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Access 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Access 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365access2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2016","displayName":"Microsoft Office 365 Access 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Access 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Access 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Access 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Access 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Access 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365access2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2013","displayName":"Microsoft Office 365 Common 2013","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2013 applications.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings which are common between the Microsoft Office Suite 2013 applications will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings which are common between the Microsoft Office Suite 2013 applications from synchronization between computers with UE-V.\r\nIf you enable this policy setting, user settings which are common between the Microsoft Office Suite 2013 applications continue to synchronize with UE-V.\r\nIf you disable this policy setting, user settings which are common between the Microsoft Office Suite 2013 applications are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365common2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2016","displayName":"Microsoft Office 365 Common 2016","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2016 applications.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings which are common between the Microsoft Office Suite 2016 applications will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings which are common between the Microsoft Office Suite 2016 applications from synchronization between computers with UE-V.\r\nIf you enable this policy setting, user settings which are common between the Microsoft Office Suite 2016 applications continue to synchronize with UE-V.\r\nIf you disable this policy setting, user settings which are common between the Microsoft Office Suite 2016 applications are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365common2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2013","displayName":"Microsoft Office 365 Excel 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Excel 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Excel 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Excel 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Excel 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Excel 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365excel2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2016","displayName":"Microsoft Office 365 Excel 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Excel 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Excel 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Excel 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Excel 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Excel 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365excel2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365infopath2013","displayName":"Microsoft Office 365 InfoPath 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 InfoPath 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 InfoPath 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 InfoPath 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 InfoPath 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 InfoPath 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365infopath2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365infopath2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365infopath2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013","displayName":"Microsoft Office 365 Lync 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Lync 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Lync 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Lync 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Lync 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Lync 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365lync2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016","displayName":"Microsoft Office 365 Lync 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Lync 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Lync 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Lync 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Lync 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Lync 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365lync2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2013","displayName":"Microsoft Office 365 OneNote 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 OneNote 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 OneNote 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 OneNote 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 OneNote 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 OneNote 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365onenote2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2016","displayName":"Microsoft Office 365 OneNote 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 OneNote 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 OneNote 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 OneNote 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 OneNote 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 OneNote 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365onenote2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013","displayName":"Microsoft Office 365 Outlook 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Outlook 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Outlook 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Outlook 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Outlook 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Outlook 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365outlook2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2016","displayName":"Microsoft Office 365 Outlook 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Outlook 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Outlook 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Outlook 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Outlook 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Outlook 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365outlook2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013","displayName":"Microsoft Office 365 PowerPoint 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 PowerPoint 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 PowerPoint 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 PowerPoint 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 PowerPoint 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 PowerPoint 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365powerpoint2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2016","displayName":"Microsoft Office 365 PowerPoint 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 PowerPoint 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 PowerPoint 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 PowerPoint 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 PowerPoint 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 PowerPoint 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365powerpoint2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2013","displayName":"Microsoft Office 365 Project 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Project 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Project 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Project 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Project 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Project 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365project2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016","displayName":"Microsoft Office 365 Project 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Project 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Project 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Project 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Project 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Project 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365project2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2013","displayName":"Microsoft Office 365 Publisher 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Publisher 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Publisher 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Publisher 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Publisher 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Publisher 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365publisher2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2016","displayName":"Microsoft Office 365 Publisher 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Publisher 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Publisher 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Publisher 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Publisher 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Publisher 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365publisher2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365sharepointdesigner2013","displayName":"Microsoft Office 365 SharePoint Designer 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 SharePoint Designer 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 SharePoint Designer 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 SharePoint Designer 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 SharePoint Designer 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 SharePoint Designer 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365sharepointdesigner2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365sharepointdesigner2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365sharepointdesigner2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2013","displayName":"Microsoft Office 365 Visio 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Visio 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Visio 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Visio 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Visio 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Visio 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365visio2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016","displayName":"Microsoft Office 365 Visio 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Visio 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Visio 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Visio 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Visio 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Visio 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365visio2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365word2013","displayName":"Microsoft Office 365 Word 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Word 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Word 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Word 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Word 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Word 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365word2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365word2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365word2013_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365word2016","displayName":"Microsoft Office 365 Word 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Word 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Word 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Word 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Word 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Word 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365word2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365word2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365word2016_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_music","displayName":"Music","description":"This policy setting configures the synchronization of user settings for the Music app.\r\nBy default, the user settings of Music sync between computers. Use the policy setting to prevent the user settings of Music from synchronizing between computers.\r\nIf you enable this policy setting, Music user settings continue to sync.\r\nIf you disable this policy setting, Music user settings are excluded from the synchronizing settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-music"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_music_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_music_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_news","displayName":"News","description":"This policy setting configures the synchronization of user settings for the News app.\r\nBy default, the user settings of News sync between computers. Use the policy setting to prevent the user settings of News from synchronizing between computers.\r\nIf you enable this policy setting, News user settings continue to sync.\r\nIf you disable this policy setting, News user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-news"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_news_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_news_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_notepad","displayName":"Notepad","description":"This policy setting configures the synchronization of user settings of Notepad.\r\nBy default, the user settings of Notepad synchronize between computers. Use the policy setting to prevent the user settings of Notepad from synchronization between computers. \r\nIf you enable this policy setting, the Notepad user settings continue to synchronize. \r\nIf you disable this policy setting, Notepad user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-notepad"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_notepad_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_notepad_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_reader","displayName":"Reader","description":"This policy setting configures the synchronization of user settings for the Reader app.\r\nBy default, the user settings of Reader sync between computers. Use the policy setting to prevent the user settings of Reader from synchronizing between computers.\r\nIf you enable this policy setting, Reader user settings continue to sync.\r\nIf you disable this policy setting, Reader user settings are excluded from the synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-reader"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_reader_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_reader_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_repositorytimeout","displayName":"Synchronization timeout","description":"This policy setting configures the number of milliseconds that the computer waits when retrieving user settings from the settings storage location. \r\nYou can use this setting to override the default value of 2000 milliseconds. \r\nIf you enable this policy setting, set the number of milliseconds that the system waits to retrieve settings. \r\nIf you disable or do not configure this policy setting, the default value of 2000 milliseconds is used.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-repositorytimeout"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_repositorytimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_repositorytimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_repositorytimeout_repositorytimeout","displayName":"Synchronization timeout (in milliseconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingsstoragepath","displayName":"Settings storage path","description":"This policy setting configures where the settings package files that contain user settings are stored. \r\nIf you enable this policy setting, the user settings are stored in the specified location. \r\nIf you disable or do not configure this policy setting, the user settings are stored in the user’s home directory if configured for your environment. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-settingsstoragepath"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingsstoragepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingsstoragepath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingsstoragepath_settingsstoragepath","displayName":"Settings storage path","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath","displayName":"Settings template catalog path","description":"This policy setting configures where custom settings location templates are stored and if the catalog will be used to replace the default Microsoft templates installed with the UE-V Agent.\r\nIf you enable this policy setting, the UE-V Agent checks the specified location once each day and updates its synchronization behavior based on the templates in this location. Settings location templates added or updated since the last check are registered by the UE-V Agent. The UE-V Agent deregisters templates that were removed from this location.\r\nIf you specify a UNC path and leave the option to replace the default Microsoft templates unchecked, the UE-V Agent will use the default Microsoft templates installed by the UE-V Agent and custom templates in the settings template catalog. If there are custom templates in the settings template catalog which use the same ID as the default Microsoft templates, they will be ignored.\r\nIf you specify a UNC path and check the option to replace the default Microsoft templates, all of the default Microsoft templates installed by the UE-V Agent will be deleted from the computer and only the templates located in the settings template catalog will be used.\r\nIf you disable this policy setting, the UE-V Agent will not use the custom settings location templates. If you disable this policy setting after it has been enabled, the UE-V Agent will not restore the default Microsoft templates. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-settingstemplatecatalogpath"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_overridemstemplates","displayName":"Replace the default Microsoft templates","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_overridemstemplates_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_overridemstemplates_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_settingstemplatecatalogpath","displayName":"Settings template catalog path","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_sports","displayName":"Sports","description":"This policy setting configures the synchronization of user settings for the Sports app.\r\nBy default, the user settings of Sports sync between computers. Use the policy setting to prevent the user settings of Sports from synchronizing between computers.\r\nIf you enable this policy setting, Sports user settings continue to sync.\r\nIf you disable this policy setting, Sports user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-sports"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_sports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_sports_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncenabled","displayName":"Use User Experience Virtualization (UE-V)","description":"This policy setting allows you to enable or disable User Experience Virtualization (UE-V). Only applies to Windows 10 or earlier.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncenabled"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetwork","displayName":"Sync settings over metered connections","description":"This policy setting defines whether the User Experience Virtualization (UE-V) Agent synchronizes settings over metered connections.\r\nBy default, the UE-V Agent does not synchronize settings over a metered connection.\r\nWith this setting enabled, the UE-V Agent synchronizes settings over a metered connection.\r\nWith this setting disabled, the UE-V Agent does not synchronize settings over a metered connection.\r\nIf you do not configure this policy setting, any defined values are deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncovermeterednetwork"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetworkwhenroaming","displayName":"Sync settings over metered connections even when roaming","description":"This policy setting defines whether the User Experience Virtualization (UE-V) Agent synchronizes settings over metered connections outside of the home provider network, for example when connected via a roaming connection.\r\nBy default, the UE-V Agent does not synchronize settings over a metered connection that is roaming.\r\nWith this setting enabled, the UE-V Agent synchronizes settings over a metered connection that is roaming.\r\nWith this setting disabled, the UE-V Agent will not synchronize settings over a metered connection that is roaming.\r\nIf you do not configure this policy setting, any defined values are deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncovermeterednetworkwhenroaming"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetworkwhenroaming_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetworkwhenroaming_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncproviderpingenabled","displayName":"Ping the settings storage location before sync","description":"This policy setting allows you to configure the User Experience Virtualization (UE-V) sync provider to ping the settings storage path before attempting to sync settings. If the ping is successful then the sync provider attempts to synchronize the settings packages. If the ping is unsuccessful then the sync provider doesn’t attempt the synchronization. \r\nIf you enable this policy setting, the sync provider pings the settings storage location before synchronizing settings packages.\r\nIf you disable this policy setting, the sync provider doesn’t ping the settings storage location before synchronizing settings packages. \r\nIf you do not configure this policy, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncproviderpingenabled"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncproviderpingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncproviderpingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncunlistedwindows8apps","displayName":"Sync Unlisted Windows Apps","description":"This policy setting defines the default settings sync behavior of the User Experience Virtualization (UE-V) Agent for Windows apps that are not explicitly listed in Windows App List.\r\nBy default, the UE-V Agent only synchronizes settings of those Windows apps included in the Windows App List.\r\nWith this setting enabled, the settings of all Windows apps not expressly disable in the Windows App List are synchronized.\r\nWith this setting disabled, only the settings of the Windows apps set to synchronize in the Windows App List are synchronized.\r\nIf you do not configure this policy setting, any defined values are deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncunlistedwindows8apps"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncunlistedwindows8apps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncunlistedwindows8apps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_travel","displayName":"Travel","description":"This policy setting configures the synchronization of user settings for the Travel app.\r\nBy default, the user settings of Travel sync between computers. Use the policy setting to prevent the user settings of Travel from synchronizing between computers.\r\nIf you enable this policy setting, Travel user settings continue to sync.\r\nIf you disable this policy setting, Travel user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-travel"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_travel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_travel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_trayiconenabled","displayName":"Tray Icon","description":"This policy setting enables the User Experience Virtualization (UE-V) tray icon. By default, an icon appears in the system tray that displays notifications for UE-V. This icon also provides a link to the UE-V Agent application, Company Settings Center. Users can open the Company Settings Center by right-clicking the icon and selecting Open or by double-clicking the icon. When this group policy setting is enabled, the UE-V tray icon is visible, the UE-V notifications display, and the Company Settings Center is accessible from the tray icon.\r\nWith this setting disabled, the tray icon does not appear in the system tray, UE-V never displays notifications, and the user cannot access Company Settings Center from the system tray. The Company Settings Center remains accessible through the Control Panel and the Start menu or Start screen.\r\nIf you do not configure this policy setting, any defined values are deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-trayiconenabled"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_trayiconenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_trayiconenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_video","displayName":"Video","description":"This policy setting configures the synchronization of user settings for the Video app.\r\nBy default, the user settings of Video sync between computers. Use the policy setting to prevent the user settings of Video from synchronizing between computers.\r\nIf you enable this policy setting, Video user settings continue to sync.\r\nIf you disable this policy setting, Video user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-video"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_video_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_video_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_weather","displayName":"Weather","description":"This policy setting configures the synchronization of user settings for the Weather app.\r\nBy default, the user settings of Weather sync between computers. Use the policy setting to prevent the user settings of Weather from synchronizing between computers.\r\nIf you enable this policy setting, Weather user settings continue to sync.\r\nIf you disable this policy setting, Weather user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-weather"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_weather_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_weather_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_wordpad","displayName":"WordPad","description":"This policy setting configures the synchronization of user settings of WordPad.\r\nBy default, the user settings of WordPad synchronize between computers. Use the policy setting to prevent the user settings of WordPad from synchronization between computers. \r\nIf you enable this policy setting, the WordPad user settings continue to synchronize. \r\nIf you disable this policy setting, WordPad user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-wordpad"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_wordpad_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_wordpad_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles","displayName":"Delete user profiles older than a specified number of days on system restart","description":"This policy setting allows an administrator to automatically delete user profiles on system restart that have not been used within a specified number of days. Note: One day is interpreted as 24 hours after a specific user profile was accessed.\r\n\r\nIf you enable this policy setting, the User Profile Service will automatically delete on the next system restart all user profiles on the computer that have not been used within the specified number of days. \r\n\r\nIf you disable or do not configure this policy setting, User Profile Service will not automatically delete any profiles on the next system restart.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-cleanupprofiles"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles_cleanupprofiles_days","displayName":"Delete user profiles older than (days)","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_dontforceunloadhive","displayName":"Do not forcefully unload the users registry at user logoff","description":"This policy setting controls whether Windows forcefully unloads the user's registry at logoff, even if there are open handles to the per-user registry keys. \r\n\r\nNote: This policy setting should only be used for cases where you may be running into application compatibility issues due to this specific Windows behavior. It is not recommended to enable this policy by default as it may prevent users from getting an updated version of their roaming user profile.\r\n\r\nIf you enable this policy setting, Windows will not forcefully unload the users registry at logoff, but will unload the registry when all open handles to the per-user registry keys are closed.\r\n\r\nIf you disable or do not configure this policy setting, Windows will always unload the users registry at logoff, even if there are any open handles to the per-user registry keys at user logoff.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-dontforceunloadhive"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_dontforceunloadhive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_dontforceunloadhive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_leaveappmgmtdata","displayName":"Leave Windows Installer and Group Policy Software Installation Data","description":"This policy setting determines whether the system retains a roaming user's Windows Installer and Group Policy based software installation data on their profile deletion.\r\n\r\nBy default Windows deletes all information related to a roaming user (which includes the user's settings, data, Windows Installer related data, and the like) when their profile is deleted. As a result, the next time a roaming user whose profile was previously deleted on that client logs on, they will need to reinstall all apps published via policy at logon increasing logon time. You can use this policy setting to change this behavior.\r\n\r\nIf you enable this policy setting, Windows will not delete Windows Installer or Group Policy software installation data for roaming users when profiles are deleted from the machine. This will improve the performance of Group Policy based Software Installation during user logon when a user profile is deleted and that user subsequently logs on to the machine.\r\n\r\nIf you disable or do not configure this policy setting, Windows will delete the entire profile for roaming users, including the Windows Installer and Group Policy software installation data when those profiles are deleted.\r\n\r\nNote: If this policy setting is enabled for a machine, local administrator action is required to remove the Windows Installer or Group Policy software installation data stored in the registry and file system of roaming users' profiles on the machine.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-leaveappmgmtdata"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_leaveappmgmtdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_leaveappmgmtdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_profileerroraction","displayName":"Do not log users on with temporary profiles","description":"This policy setting will automatically log off a user when Windows cannot load their profile. \r\n\r\nIf Windows cannot access the user profile folder or the profile contains errors that prevent it from loading, Windows logs on the user with a temporary profile. This policy setting allows the administrator to disable this behavior, preventing Windows from loggin on the user with a temporary profile.\r\n\r\nIf you enable this policy setting, Windows will not log on a user with a temporary profile. Windows logs the user off if their profile cannot be loaded.\r\n\r\nIf you disable this policy setting or do not configure it, Windows logs on the user with a temporary profile when Windows cannot load their user profile.\r\n\r\nAlso, see the \"Delete cached copies of roaming profiles\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-profileerroraction"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_profileerroraction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_profileerroraction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout","displayName":"Control slow network connection timeout for user profiles","description":"This policy setting defines a slow connection for roaming user profiles and establishes thresholds for two tests of network speed. \r\n\r\nTo determine the network performance characteristics, a connection is made to the file share storing the user's profile and 64 kilobytes of data is transfered. From that connection and data transfer, the network's latency and connection speed are determined.\r\n\r\nThis policy setting and related policy settings in this folder together define the system's response when roaming user profiles are slow to load.\r\n\r\nIf you enable this policy setting, you can change how long Windows waits for a response from the server before considering the connection to be slow.\r\n\r\nIf you disable or do not configure this policy setting, Windows considers the network connection to be slow if the server returns less than 500 kilobits of data per second or take 120 milliseconds to respond.Consider increasing this value for clients using DHCP Service-assigned addresses or for computers accessing profiles across dial-up connections.Important: If the \"Do not detect slow network connections\" policy setting is enabled, this policy setting is ignored. Also, if the \"Delete cached copies of roaming profiles\" policy setting is enabled, there is no local copy of the roaming profile to load when the system detects a slow connection.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-slowlinktimeout"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout_slowlinkwaitinterval","displayName":"Time (milliseconds)","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout_transferrateop","displayName":"Connection speed (Kbps):","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home","displayName":"Set user home folder","description":"This policy setting allows you to specify the location and root (file share or local path) of a user's home folder for a logon session.\r\n\r\nIf you enable this policy setting, the user's home folder is configured to the specified local or network location, creating a new folder for each user name.\r\n\r\nTo use this policy setting, in the Location list, choose the location for the home folder. If you choose “On the network,” enter the path to a file share in the Path box (for example, \\\\ComputerName\\ShareName), and then choose the drive letter to assign to the file share. If you choose “On the local computer,” enter a local path (for example, C:\\HomeFolder) in the Path box.\r\n\r\nDo not specify environment variables or ellipses in the path. Also, do not specify a placeholder for the user name because the user name will be appended at logon.\r\n\r\nNote: The Drive letter box is ignored if you choose “On the local computer” from the Location list. If you choose “On the local computer” and enter a file share, the user's home folder will be placed in the network location without mapping the file share to a drive letter.\r\n\r\nIf you disable or do not configure this policy setting, the user's home folder is configured as specified in the user's Active Directory Domain Services account.\r\n\r\nIf the \"Set Remote Desktop Services User Home Directory\" policy setting is enabled, the “Set user home folder” policy setting has no effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-user-home"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter","displayName":"Drive letter","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_g:","displayName":"G:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_h:","displayName":"H:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_i:","displayName":"I:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_j:","displayName":"J:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_k:","displayName":"K:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_l:","displayName":"L:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_m:","displayName":"M:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_n:","displayName":"N:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_o:","displayName":"O:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_p:","displayName":"P:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_q:","displayName":"Q:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_r:","displayName":"R:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_s:","displayName":"S:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_t:","displayName":"T:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_u:","displayName":"U:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_v:","displayName":"V:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_w:","displayName":"W:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_x:","displayName":"X:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_y:","displayName":"Y:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_drive_letter_z:","displayName":"Z:","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_home_path","displayName":"Path:","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_user_home_location","displayName":"Location:","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_user_home_location_1","displayName":"On the network","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_user_home_user_home_location_0","displayName":"On the local computer","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction","displayName":"User management of sharing user name, account picture, and domain information with apps (not desktop apps)","description":"This setting prevents users from managing the ability to allow apps to access the user name, account picture, and domain information.\r\n\r\nIf you enable this policy setting, sharing of user name, picture and domain information may be controlled by setting one of the following options:\r\n\r\n\"Always on\" - users will not be able to change this setting and the user's name and account picture will be shared with apps (not desktop apps). In addition apps (not desktop apps) that have the enterprise authentication capability will also be able to retrieve the user's UPN, SIP/URI, and DNS.\r\n\r\n\"Always off\" - users will not be able to change this setting and the user's name and account picture will not be shared with apps (not desktop apps). In addition apps (not desktop apps) that have the enterprise authentication capability will not be able to retrieve the user's UPN, SIP/URI, and DNS. Selecting this option may have a negative impact on certain enterprise software and/or line of business apps that depend on the domain information protected by this setting to connect with network resources.\r\n\r\nIf you do not configure or disable this policy the user will have full control over this setting and can turn it off and on. Selecting this option may have a negative impact on certain enterprise software and/or line of business apps that depend on the domain information protected by this setting to connect with network resources if users choose to turn the setting off.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-userinfoaccessaction"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_allowuserinfoaccess","displayName":"Action:","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_allowuserinfoaccess_1","displayName":"Always on","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_allowuserinfoaccess_2","displayName":"Always off","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config","displayName":"Global Configuration Settings","description":"This policy setting allows you to specify Clock discipline and General values for the Windows Time service (W32time) for domain controllers including RODCs.\r\n\r\nIf this policy setting is enabled, W32time Service on target machines use the settings provided here. Otherwise, the service on target machines use locally configured settings values.\r\n\r\nFor more details on individual parameters, combinations of parameter values as well as definitions of flags, see https://go.microsoft.com/fwlink/?linkid=847809.\r\n\r\n FrequencyCorrectRate\r\nThis parameter controls the rate at which the W32time corrects the local clock's frequency. Lower values cause slower corrections; larger values cause more frequent corrections. Default: 4 (scalar).\r\n\r\n HoldPeriod\r\nThis parameter indicates how many consistent time samples the client computer must receive in a series before subsequent time samples are evaluated as potential spikes. Default: 5\r\n\r\n LargePhaseOffset\r\nIf a time sample differs from the client computer's local clock by more than LargePhaseOffset, the local clock is deemed to have drifted considerably, or in other words, spiked. Default: 50,000,000 100-nanosecond units (ns) or 5 seconds.\r\n\r\n MaxAllowedPhaseOffset\r\nIf a response is received that has a time variation that is larger than this parameter value, W32time sets the client computer's local clock immediately to the time that is accepted as accurate from the Network Time Protocol (NTP) server. If the time variation is less than this value, the client computer's local clock is corrected gradually. Default: 300 seconds.\r\n\r\n MaxNegPhaseCorrection\r\nIf a time sample is received that indicates a time in the past (as compared to the client computer's local clock) that has a time difference that is greater than the MaxNegPhaseCorrection value, the time sample is discarded. Default: 172,800 seconds.\r\n\r\n MaxPosPhaseCorrection\r\nIf a time sample is received that indicates a time in the future (as compared to the client computer's local clock) that has a time difference greater than the MaxPosPhaseCorrection value, the time sample is discarded. Default: 172,800 seconds.\r\n\r\n PhaseCorrectRate\r\nThis parameter controls how quickly W32time corrects the client computer's local clock difference to match time samples that are accepted as accurate from the NTP server. Lower values cause the clock to correct more slowly; larger values cause the clock to correct more quickly. Default: 7 (scalar).\r\n\r\n PollAdjustFactor\r\nThis parameter controls how quickly W32time changes polling intervals. When responses are considered to be accurate, the polling interval lengthens automatically. When responses are considered to be inaccurate, the polling interval shortens automatically. Default: 5 (scalar).\r\n\r\n SpikeWatchPeriod\r\nThis parameter specifies the amount of time that samples with time offset larger than LargePhaseOffset are received before these samples are accepted as accurate. SpikeWatchPeriod is used in conjunction with HoldPeriod to help eliminate sporadic, inaccurate time samples that are returned from a peer. Default: 900 seconds.\r\n\r\n UpdateInterval\r\nThis parameter specifies the amount of time that W32time waits between corrections when the clock is being corrected gradually. When it makes a gradual correction, the service adjusts the clock slightly, waits this amount of time, and then checks to see if another adjustment is needed, until the correction is finished. Default: 100 1/100th second units, or 1 second.\r\n\r\n General parameters:\r\n\r\n AnnounceFlags\r\nThis parameter is a bitmask value that controls how time service availability is advertised through NetLogon. Default: 0x0a hexadecimal\r\n\r\n EventLogFlags\r\nThis parameter controls special events that may be logged to the Event Viewer System log. Default: 0x02 hexadecimal bitmask.\r\n\r\n LocalClockDispersion\r\nThis parameter indicates the maximum error in seconds that is reported by the NTP server to clients that are requesting a time sample. (Applies only when the NTP server is using the time of the local CMOS clock.) Default: 10 seconds.\r\n\r\n MaxPollInterval\r\nThis parameter controls the maximum polling interval, which defines the maximum amount of time between polls of a peer. Default: 10 in log base-2, or 1024 seconds. (Should not be set higher than 15.)\r\n\r\n MinPollInterval\r\nThis parameter controls the minimum polling interval that defines the minimum amount of time between polls of a peer. Default: 6 in log base-2, or 64 seconds.\r\n\r\n ClockHoldoverPeriod\r\nThis parameter indicates the maximum number of seconds a system clock can nominally hold its accuracy without synchronizing with a time source. If this period of time passes without W32time obtaining new samples from any of its input providers, W32time initiates a rediscovery of time sources. Default: 7800 seconds.\r\n\r\n RequireSecureTimeSyncRequests\r\nThis parameter controls whether or not the DC will respond to time sync requests that use older authentication protocols. If enabled (set to 1), the DC will not respond to requests using such protocols. Default: 0 Boolean.\r\n\r\n UtilizeSslTimeData\r\nThis parameter controls whether W32time will use time data computed from SSL traffic on the machine as an additional input for correcting the local clock. Default: 1 (enabled) Boolean\r\n\r\n ClockAdjustmentAuditLimit\r\nThis parameter specifies the smallest local clock adjustments that may be logged to the W32time service event log on the target machine. Default: 800 Parts per million (PPM).\r\n\r\n RODC parameters:\r\n\r\n ChainEntryTimeout\r\nThis parameter specifies the maximum amount of time that an entry can remain in the chaining table before the entry is considered to be expired. Expired entries may be removed when the next request or response is processed. Default: 16 seconds.\r\n\r\n ChainMaxEntries\r\nThis parameter controls the maximum number of entries that are allowed in the chaining table. If the chaining table is full and no expired entries can be removed, any incoming requests are discarded. Default: 128 entries.\r\n\r\n ChainMaxHostEntries\r\nThis parameter controls the maximum number of entries that are allowed in the chaining table for a particular host. Default: 4 entries.\r\n\r\n ChainDisable\r\nThis parameter controls whether or not the chaining mechanism is disabled. If chaining is disabled (set to 0), the RODC can synchronize with any domain controller, but hosts that do not have their passwords cached on the RODC will not be able to synchronize with the RODC. Default: 0 Boolean.\r\n\r\n ChainLoggingRate\r\nThis parameter controls the frequency at which an event that indicates the number of successful and unsuccessful chaining attempts is logged to the System log in Event Viewer. Default: 30 minutes.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-w32time#admx-w32time-w32time-policy-config"],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":[{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_announceflags","displayName":"AnnounceFlags","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chaindisable","displayName":"ChainDisable","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chainentrytimeout","displayName":"ChainEntryTimeout","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chainloggingrate","displayName":"ChainLoggingRate","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chainmaxentries","displayName":"ChainMaxEntries","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chainmaxhostentries","displayName":"ChainMaxHostEntries","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_clockadjustmentauditlimit","displayName":"ClockAdjustmentAuditLimit","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_clockholdoverperiod","displayName":"ClockHoldoverPeriod","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_eventlogflags","displayName":"EventLogFlags","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_frequencycorrectrate","displayName":"FrequencyCorrectRate","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_holdperiod","displayName":"HoldPeriod","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_largephaseoffset","displayName":"LargePhaseOffset","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_localclockdispersion","displayName":"LocalClockDispersion","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_maxallowedphaseoffset","displayName":"MaxAllowedPhaseOffset","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_maxnegphasecorrection","displayName":"MaxNegPhaseCorrection","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_maxpollinterval","displayName":"MaxPollInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_maxposphasecorrection","displayName":"MaxPosPhaseCorrection","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_minpollinterval","displayName":"MinPollInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_phasecorrectrate","displayName":"PhaseCorrectRate","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_polladjustfactor","displayName":"PollAdjustFactor","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_requiresecuretimesyncrequests","displayName":"RequireSecureTimeSyncRequests","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_spikewatchperiod","displayName":"SpikeWatchPeriod","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_updateinterval","displayName":"UpdateInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_utilizessltimedata","displayName":"UtilizeSslTimeData","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient","displayName":"Configure Windows NTP Client","description":"This policy setting specifies a set of parameters for controlling the Windows NTP Client.\r\n\r\nIf you enable this policy setting, you can specify the following parameters for the Windows NTP Client.\r\n\r\nIf you disable or do not configure this policy setting, the WIndows NTP Client uses the defaults of each of the following parameters.\r\n\r\nNtpServer\r\nThe Domain Name System (DNS) name or IP address of an NTP time source. This value is in the form of \"dnsName,flags\" where \"flags\" is a hexadecimal bitmask of the flags for that host. For more information, see the NTP Client Group Policy Settings Associated with Windows Time section of the Windows Time Service Group Policy Settings. The default value is \"time.windows.com,0x09\". \r\n\r\nType\r\nThis value controls the authentication that W32time uses. The default value is NT5DS.\r\n\r\nCrossSiteSyncFlags\r\nThis value, expressed as a bitmask, controls how W32time chooses time sources outside its own site. The possible values are 0, 1, and 2. Setting this value to 0 (None) indicates that the time client should not attempt to synchronize time outside its site. Setting this value to 1 (PdcOnly) indicates that only the computers that function as primary domain controller (PDC) emulator operations masters in other domains can be used as synchronization partners when the client has to synchronize time with a partner outside its own site. Setting a value of 2 (All) indicates that any synchronization partner can be used. This value is ignored if the NT5DS value is not set. The default value is 2 decimal (0x02 hexadecimal).\r\n\r\nResolvePeerBackoffMinutes\r\nThis value, expressed in minutes, controls how long W32time waits before it attempts to resolve a DNS name when a previous attempt failed. The default value is 15 minutes.\r\n\r\nResolvePeerBackoffMaxTimes\r\nThis value controls how many times W32time attempts to resolve a DNS name before the discovery process is restarted. Each time DNS name resolution fails, the amount of time to wait before the next attempt will be twice the previous amount. The default value is seven attempts.\r\n\r\nSpecialPollInterval\r\nThis NTP client value, expressed in seconds, controls how often a manually configured time source is polled when the time source is configured to use a special polling interval. If the SpecialInterval flag is enabled on the NTPServer setting, the client uses the value that is set as the SpecialPollInterval, instead of a variable interval between MinPollInterval and MaxPollInterval values, to determine how frequently to poll the time source. SpecialPollInterval must be in the range of [MinPollInterval, MaxPollInterval], else the nearest value of the range is picked. Default: 1024 seconds.\r\n\r\nEventLogFlags\r\nThis value is a bitmask that controls events that may be logged to the System log in Event Viewer. Setting this value to 0x1 indicates that W32time will create an event whenever a time jump is detected. Setting this value to 0x2 indicates that W32time will create an event whenever a time source change is made. Because it is a bitmask value, setting 0x3 (the addition of 0x1 and 0x2) indicates that both time jumps and time source changes will be logged.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-w32time#admx-w32time-w32time-policy-configure-ntpclient"],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":[{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_crosssitesyncflags","displayName":"CrossSiteSyncFlags","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_ntpclienteventlogflags","displayName":"EventLogFlags","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_ntpserver","displayName":"NtpServer","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_resolvepeerbackoffmaxtimes","displayName":"ResolvePeerBackoffMaxTimes","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_resolvepeerbackoffminutes","displayName":"ResolvePeerBackoffMinutes","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_specialpollinterval","displayName":"SpecialPollInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_type","displayName":"Type","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":[{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_type_nosync","displayName":"NoSync","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_type_ntp","displayName":"NTP","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_type_nt5ds","displayName":"NT5DS","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_type_allsync","displayName":"AllSync","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpclient","displayName":"Enable Windows NTP Client","description":"This policy setting specifies whether the Windows NTP Client is enabled.\r\n\r\nEnabling the Windows NTP Client allows your computer to synchronize its computer clock with other NTP servers. You might want to disable this service if you decide to use a third-party time provider.\r\n\r\nIf you enable this policy setting, you can set the local computer clock to synchronize time with NTP servers.\r\n\r\nIf you disable or do not configure this policy setting, the local computer clock does not synchronize time with NTP servers.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-w32time#admx-w32time-w32time-policy-enable-ntpclient"],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":[{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpclient_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpserver","displayName":"Enable Windows NTP Server","description":"This policy setting allows you to specify whether the Windows NTP Server is enabled.\r\n\r\nIf you enable this policy setting for the Windows NTP Server, your computer can service NTP requests from other computers.\r\n\r\n\r\nIf you disable or do not configure this policy setting, your computer cannot service NTP requests from other computers.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-w32time#admx-w32time-w32time-policy-enable-ntpserver"],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":[{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_disablepowermanagement","displayName":"Disable power management in connected standby mode","description":"This policy setting specifies that power management is disabled when the machine enters connected standby mode. \r\n\r\nIf this policy setting is enabled, Windows Connection Manager does not manage adapter radios to reduce power consumption when the machine enters connected standby mode.\r\n\r\nIf this policy setting is not configured or is disabled, power management is enabled when the machine enters connected standby mode.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wcm#admx-wcm-wcm-disablepowermanagement"],"categoryId":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","categoryName":"Windows Connection Manager","options":[{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_disablepowermanagement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_disablepowermanagement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_enablesoftdisconnect","displayName":"Enable Windows to soft-disconnect a computer from a network","description":"This policy setting determines whether Windows will soft-disconnect a computer from a network.\r\n\r\nIf this policy setting is enabled or not configured, Windows will soft-disconnect a computer from a network when it determines that the computer should no longer be connected to a network.\r\n\r\nIf this policy setting is disabled, Windows will disconnect a computer from a network immediately when it determines that the computer should no longer be connected to a network.\r\n\r\nWhen soft disconnect is enabled:\r\n- When Windows decides that the computer should no longer be connected to a network, it waits for traffic to settle on that network. The existing TCP session will continue uninterrupted.\r\n- Windows then checks the traffic level on the network periodically. If the traffic level is above a certain threshold, no further action is taken. The computer stays connected to the network and continues to use it. For example, if the network connection is currently being used to download files from the Internet, the files will continue to be downloaded using that network connection.\r\n- When the network traffic drops below this threshold, the computer will be disconnected from the network. Apps that keep a network connection active even when they’re not actively using it (for example, email apps) might lose their connection. If this happens, these apps should re-establish their connection over a different network. \r\n\r\nThis policy setting depends on other group policy settings. For example, if 'Minimize the number of simultaneous connections to the Internet or a Windows Domain' is disabled, Windows will not disconnect from any networks.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wcm#admx-wcm-wcm-enablesoftdisconnect"],"categoryId":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","categoryName":"Windows Connection Manager","options":[{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_enablesoftdisconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_enablesoftdisconnect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections","displayName":"Minimize the number of simultaneous connections to the Internet or a Windows Domain","description":"\r\n This policy setting determines if a computer can have multiple connections to the internet or to a Windows domain. If multiple connections are allowed, it then determines how network traffic will be routed.\r\n\r\n If this policy setting is set to 0, a computer can have simultaneous connections to the internet, to a Windows domain, or to both. Internet traffic can be routed over any connection - including a cellular connection and any metered network. This was previously the Disabled state for this policy setting. This option was first available in Windows 8.\r\n\r\n If this policy setting is set to 1, any new automatic internet connection is blocked when the computer has at least one active internet connection to a preferred type of network. Here's the order of preference (from most preferred to least preferred): Ethernet, WLAN, then cellular. Ethernet is always preferred when connected. Users can still manually connect to any network. This was previously the Enabled state for this policy setting. This option was first available in Windows 8.\r\n\r\n If this policy setting is set to 2, the behavior is similar to 1. However, if a cellular data connection is available, it will always stay connected for services that require a cellular connection. When the user is connected to a WLAN or Ethernet connection, no internet traffic will be routed over the cellular connection. This option was first available in Windows 10 (Version 1703).\r\n\r\n If this policy setting is set to 3, the behavior is similar to 2. However, if there's an Ethernet connection, Windows won't allow users to connect to a WLAN manually. A WLAN can only be connected (automatically or manually) when there's no Ethernet connection.\r\n\r\n This policy setting is related to the \"Enable Windows to soft-disconnect a computer from a network\" policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wcm#admx-wcm-wcm-minimizeconnections"],"categoryId":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","categoryName":"Windows Connection Manager","options":[{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_wcm_minimizeconnections_options","displayName":"Minimize Policy Options","description":null,"helpText":"","infoUrls":[],"categoryId":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","categoryName":"Windows Connection Manager","options":[{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_wcm_minimizeconnections_options_0","displayName":"0 = Allow simultaneous connections","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_wcm_minimizeconnections_options_1","displayName":"1 = Minimize simultaneous connections","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_wcm_minimizeconnections_options_2","displayName":"2 = Stay connected to cellular","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_minimizeconnections_wcm_minimizeconnections_options_3","displayName":"3 = Prevent Wi-Fi when on Ethernet","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy","displayName":"Diagnostics: Configure scenario retention","description":"This policy setting determines the data retention limit for Diagnostic Policy Service (DPS) scenario data.\r\n\r\nIf you enable this policy setting, you must enter the maximum size of scenario data that should be retained in megabytes. Detailed troubleshooting data related to scenarios will be retained until this limit is reached.\r\n\r\nIf you disable or do not configure this policy setting, the DPS deletes scenario data once it exceeds 128 megabytes in size.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenario data will not be deleted. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wdi#admx-wdi-wdidpsscenariodatasizelimitpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy_wdidpsscenariodatasizelimitpolicyvalue","displayName":"Scenario data size limit (in MB)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy","displayName":"Diagnostics: Configure scenario execution level","description":"This policy setting determines the execution level for Diagnostic Policy Service (DPS) scenarios.\r\n\r\nIf you enable this policy setting, you must select an execution level from the drop-down menu. If you select problem detection and troubleshooting only, the DPS will detect problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will attempt to automatically fix problems it detects or indicate to the user that assisted resolution is available.\r\n\r\nIf you disable this policy setting, Windows cannot detect, troubleshoot, or resolve any problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS enables all scenarios for resolution by default, unless you configure separate scenario-specific policy settings.\r\n\r\nThis policy setting takes precedence over any scenario-specific policy settings when it is enabled or disabled. Scenario-specific policy settings only take effect if this policy setting is not configured.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wdi#admx-wdi-wdidpsscenarioexecutionpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_wdidpsscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_wdidpsscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_wdidpsscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wincal_turnoffwincal_2","displayName":"Turn off Windows Calendar","description":"Windows Calendar is a feature that allows users to manage appointments and tasks by creating personal calendars, publishing them, and subscribing to other users calendars.\r\n\r\nIf you enable this setting, Windows Calendar will be turned off.\r\n\r\nIf you disable or do not configure this setting, Windows Calendar will be turned on.\r\n\r\nThe default is for Windows Calendar to be turned on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wincal#admx-wincal-turnoffwincal-2"],"categoryId":"fff51673-04b8-4277-98ef-4baffbd8d192","categoryName":"Windows Calendar","options":[{"id":"device_vendor_msft_policy_config_admx_wincal_turnoffwincal_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wincal_turnoffwincal_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_2","displayName":"Prohibit installing or uninstalling color profiles","description":"This policy setting affects the ability of users to install or uninstall color profiles.\r\n\r\nIf you enable this policy setting, users cannot install new color profiles or uninstall previously installed color profiles.\r\n\r\nIf you disable or do not configure this policy setting, all users can install new color profiles. Standard users can uninstall color profiles that they previously installed. Administrators will be able to uninstall all color profiles.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowscolorsystem#admx-windowscolorsystem-prohibitchanginginstalledprofilelist-2"],"categoryId":"444409a4-8b03-402d-91d0-1cd9565fb0fb","categoryName":"Windows Color System","options":[{"id":"device_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_2","displayName":"Prohibit access of the Windows Connect Now wizards","description":"This policy setting prohibits access to Windows Connect Now (WCN) wizards. \r\n\r\nIf you enable this policy setting, the wizards are turned off and users have no access to any of the wizard tasks. All the configuration related tasks, including \"Set up a wireless router or access point\" and \"Add a wireless device\" are disabled. \r\n\r\nIf you disable or do not configure this policy setting, users can access the wizard tasks, including \"Set up a wireless router or access point\" and \"Add a wireless device.\" The default for this policy setting allows users to access all WCN wizards.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsconnectnow#admx-windowsconnectnow-wcn-disablewcnui-2"],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar","displayName":"Configuration of wireless settings using Windows Connect Now","description":"This policy setting allows the configuration of wireless settings using Windows Connect Now (WCN). The WCN Registrar enables the discovery and configuration of devices over Ethernet (UPnP), over In-band 802.11 WLAN, through the Windows Portable Device API (WPD), and via USB Flash drives.\r\n\r\nAdditional options are available to allow discovery and configuration over a specific medium. \r\n\r\nIf you enable this policy setting, additional choices are available to turn off the operations over a specific medium. \r\n\r\nIf you disable this policy setting, operations are disabled over all media. \r\n\r\nIf you do not configure this policy setting, operations are enabled over all media. \r\n\r\nThe default for this policy setting allows operations over all media.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsconnectnow#admx-windowsconnectnow-wcn-enableregistrar"],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableflashconfig","displayName":"Turn off ability to configure using a USB Flash Drive","description":null,"helpText":"","infoUrls":[],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableflashconfig_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableflashconfig_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableinband802dot11","displayName":"Turn off ability to configure using WCN over In-band 802.11 WLAN","description":null,"helpText":"","infoUrls":[],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableinband802dot11_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableinband802dot11_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableupnp","displayName":"Turn off ability to configure using WCN over Ethernet (UPnP)","description":null,"helpText":"","infoUrls":[],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableupnp_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disableupnp_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disablewpd","displayName":"Turn off ability to configure Windows Portable Device (WPD)","description":null,"helpText":"","infoUrls":[],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disablewpd_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_disablewpd_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_enableregistrar_maxwcndevicenumber","displayName":"Maximum number of WCN devices allowed:","description":null,"helpText":"","infoUrls":[],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_higher_precedence_registrar","displayName":"Higher precedence medium for devices discovered by multiple media:","description":null,"helpText":"","infoUrls":[],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_higher_precedence_registrar_1","displayName":"WCN over Ethernet (UPnP)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_enableregistrar_wcn_higher_precedence_registrar_2","displayName":"WCN over In-band 802.11 WLAN","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_checksamesourceandtargetforfranddfs","displayName":"Verify old and new Folder Redirection targets point to the same share before redirecting","description":"This policy setting allows you to prevent data loss when you change the target location for Folder Redirection, and the new and old targets point to the same network share, but have different network paths.\r\n\r\nIf you enable this policy setting, Folder Redirection creates a temporary file in the old location in order to verify that new and old locations point to the same network share. If both new and old locations point to the same share, the target path is updated and files are not copied or deleted. The temporary file is deleted.\r\n\r\nIf you disable or do not configure this policy setting, Folder Redirection does not create a temporary file and functions as if both new and old locations point to different shares when their network paths are different.\r\n\r\nNote: If the paths point to different network shares, this policy setting is not required. If the paths point to the same network share, any data contained in the redirected folders is deleted if this policy setting is not enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-checksamesourceandtargetforfranddfs"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_checksamesourceandtargetforfranddfs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_checksamesourceandtargetforfranddfs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_defaultlibrarieslocation","displayName":"Location where all default Library definition files for users/machines reside.","description":"\r\nThis policy setting allows you to specify a location where all default Library definition files for users/machines reside.\r\n\r\nIf you enable this policy setting, administrators can specify a path where all default Library definition files for users reside. The user will not be allowed to make changes to these Libraries from the UI. On every logon, the policy settings are verified and Libraries for the user are updated or changed according to the path defined.\r\n\r\nIf you disable or do not configure this policy setting, no changes are made to the location of the default Library definition files.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-defaultlibrarieslocation"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_defaultlibrarieslocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_defaultlibrarieslocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_defaultlibrarieslocation_defaultlibrarieslocation","displayName":"Default Libraries definition location","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_disablebinddirectlytopropertysetstorage","displayName":"Disable binding directly to IPropertySetStorage without intermediate layers.","description":"\r\nChanges the behavior of IShellFolder::BindToObject for IID_IPropertySetStorage to not bind directly to the IPropertySetStorage implementation, and to include the intermediate layers provided by the Property System. This behavior is consistent with Windows Vista's behavior in this scenario.\r\n\r\nThis disables access to user-defined properties, and properties stored in NTFS secondary streams.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-disablebinddirectlytopropertysetstorage"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_disablebinddirectlytopropertysetstorage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_disablebinddirectlytopropertysetstorage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_disablemotwoninsecurepathcopy","displayName":"Do not apply the Mark of the Web tag to files copied from insecure sources","description":"This policy setting determines the application of the Mark of the Web tag to files sourced from insecure locations.\n\nIf you enable this policy setting, files copied from unsecure sources will not be tagged with the Mark of the Web.\n\nIf you disable or do not configure this policy setting, files copied from unsecure sources will be tagged with the appropriate Mark of the Web.\n\nNote: Failure to tag files from unsecure sources with the Mark of the Web can expose users’ computers to security risks.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-disablemotwoninsecurepathcopy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_disablemotwoninsecurepathcopy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_disablemotwoninsecurepathcopy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enableshellshortcuticonremotepath","displayName":"Allow the use of remote paths in file shortcut icons","description":"This policy setting determines whether remote paths can be used for file shortcut (.lnk file) icons.\r\n\r\nIf you enable this policy setting, file shortcut icons are allowed to be obtained from remote paths.\r\n\r\nIf you disable or do not configure this policy setting, file shortcut icons that use remote paths are prevented from being displayed.\r\n\r\nNote: Allowing the use of remote paths in file shortcut icons can expose users’ computers to security risks.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-enableshellshortcuticonremotepath"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enableshellshortcuticonremotepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enableshellshortcuticonremotepath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen","displayName":"Configure Windows Defender SmartScreen","description":"This policy allows you to turn Windows Defender SmartScreen on or off. SmartScreen helps protect PCs by warning users before running potentially malicious programs downloaded from the Internet. This warning is presented as an interstitial dialog shown before running an app that has been downloaded from the Internet and is unrecognized or known to be malicious. No dialog is shown for apps that do not appear to be suspicious.\r\n\r\nSome information is sent to Microsoft about files and programs run on PCs with this feature enabled.\r\n\r\nIf you enable this policy, SmartScreen will be turned on for all users. Its behavior can be controlled by the following options:\r\n\r\n• Warn and prevent bypass\r\n• Warn\r\n\r\nIf you enable this policy with the \"Warn and prevent bypass\" option, SmartScreen's dialogs will not present the user with the option to disregard the warning and run the app. SmartScreen will continue to show the warning on subsequent attempts to run the app.\r\n\r\nIf you enable this policy with the \"Warn\" option, SmartScreen's dialogs will warn the user that the app appears suspicious, but will permit the user to disregard the warning and run the app anyway. SmartScreen will not warn the user again for that app if the user tells SmartScreen to run the app.\r\n\r\nIf you disable this policy, SmartScreen will be turned off for all users. Users will not be warned if they try to run suspicious apps from the Internet.\r\n\r\nIf you do not configure this policy, SmartScreen will be enabled by default, but users may change their settings.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-enablesmartscreen"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_enablesmartscreendropdown","displayName":"Pick one of the following settings:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_enablesmartscreendropdown_block","displayName":"Warn and prevent bypass","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_enablesmartscreendropdown_warn","displayName":"Warn","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized","displayName":"Start File Explorer with ribbon minimized","description":"This policy setting allows you to specify whether the ribbon appears minimized or in full when new File Explorer windows are opened. If you enable this policy setting, you can set how the ribbon appears the first time users open File Explorer and whenever they open new windows. If you disable or do not configure this policy setting, users can choose how the ribbon appears when they open new windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-explorerribbonstartsminimized"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_explorerribbonstartsminimizeddropdown","displayName":"Pick one of the following settings","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_explorerribbonstartsminimizeddropdown_1","displayName":"Always open new File Explorer windows with the ribbon minimized.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_explorerribbonstartsminimizeddropdown_2","displayName":"Never open new File Explorer windows with the ribbon minimized.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_explorerribbonstartsminimizeddropdown_3","displayName":"Minimize the ribbon when File Explorer is opened the first time.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_explorerribbonstartsminimizeddropdown_4","displayName":"Display the full ribbon when File Explorer is opened the first time.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internet","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-internet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internetlockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-internetlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internetlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internetlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranet","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-intranet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranetlockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-intranetlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranetlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranetlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachine","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-localmachine"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-localmachinelockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restricted","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users cannot preview items or get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-restricted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restricted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restricted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restrictedlockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users cannot preview items or get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-restrictedlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restrictedlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restrictedlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trusted","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-trusted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trusted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trusted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trustedlockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-trustedlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trustedlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trustedlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internet","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-internet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internetlockdown","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-internetlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internetlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internetlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranet","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-intranet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranetlockdown","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-intranetlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranetlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranetlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_localmachine","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-localmachine"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_localmachine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_localmachine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_localmachinelockdown","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-localmachinelockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_localmachinelockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_localmachinelockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_restricted","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users cannot perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-restricted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_restricted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_restricted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_restrictedlockdown","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users cannot perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-restrictedlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_restrictedlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_restrictedlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trusted","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-trusted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trusted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trusted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trustedlockdown","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-trustedlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trustedlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trustedlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_nonewappalert","displayName":"Do not show the 'new application installed' notification","description":"This policy removes the end-user notification for new application associations. These associations are based on file types (e.g. *.txt) or protocols (e.g. http:)\r\n\r\nIf this group policy is enabled, no notifications will be shown. If the group policy is not configured or disabled, notifications will be shown to the end user if a new application has been installed that can handle the file type or protocol association that was invoked.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nonewappalert"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_nonewappalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_nonewappalert_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_nostrcmplogical","displayName":"Turn off numerical sorting in File Explorer","description":"\r\nThis policy setting allows you to have file names sorted literally (as in Windows 2000 and earlier) rather than in numerical order.\r\nIf you enable this policy setting, File Explorer will sort file names by each digit in a file name (for example, 111 < 22 < 3).\r\nIf you disable or do not configure this policy setting, File Explorer will sort file names by increasing number value (for example, 3 < 22 < 111).\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nostrcmplogical"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_nostrcmplogical_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_nostrcmplogical_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_shellprotocolprotectedmodetitle_2","displayName":"Turn off shell protocol protected mode","description":"This policy setting allows you to configure the amount of functionality that the shell protocol can have. When using the full functionality of this protocol, applications can open folders and launch files. The protected mode reduces the functionality of this protocol allowing applications to only open a limited set of folders. Applications are not able to open files with this protocol when it is in the protected mode. It is recommended to leave this protocol in the protected mode to increase the security of Windows.\r\n\r\nIf you enable this policy setting the protocol is fully enabled, allowing the opening of folders and files.\r\n\r\nIf you disable this policy setting the protocol is in the protected mode, allowing applications to only open a limited set of folders.\r\n\r\nIf you do not configure this policy setting the protocol is in the protected mode, allowing applications to only open a limited set of folders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-shellprotocolprotectedmodetitle-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_shellprotocolprotectedmodetitle_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_shellprotocolprotectedmodetitle_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showhibernateoption","displayName":"Show hibernate in the power options menu","description":"Shows or hides hibernate from the power options menu.\r\n\r\nIf you enable this policy setting, the hibernate option will be shown in the Power Options menu (as long as it is supported by the machine's hardware).\r\n\r\nIf you disable this policy setting, the hibernate option will never be shown in the Power Options menu.\r\n\r\nIf you do not configure this policy setting, users will be able to choose whether they want hibernate to show through the Power Options Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-showhibernateoption"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showhibernateoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showhibernateoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showsleepoption","displayName":"Show sleep in the power options menu","description":"Shows or hides sleep from the power options menu.\r\n\r\nIf you enable this policy setting, the sleep option will be shown in the Power Options menu (as long as it is supported by the machine's hardware).\r\n\r\nIf you disable this policy setting, the sleep option will never be shown in the Power Options menu.\r\n\r\nIf you do not configure this policy setting, users will be able to choose whether they want sleep to show through the Power Options Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-showsleepoption"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showsleepoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showsleepoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpdllcachedir","displayName":"Specify Windows File Protection cache location (Windows Insiders only)","description":"This policy setting specifies an alternate location for the Windows File Protection cache.\r\n\r\nIf you enable this policy setting, enter the fully qualified local path to the new location in the \"Cache file path\" box.\r\n\r\nIf you disable this setting or do not configure it, the Windows File Protection cache is located in the %Systemroot%\\System32\\Dllcache directory.\r\n\r\nNote: Do not put the cache on a network shared directory.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsfileprotection#admx-windowsfileprotection-wfpdllcachedir"],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":[{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpdllcachedir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpdllcachedir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpdllcachedir_wfpdllcachedirbox","displayName":"Cache file path: (Device)","description":"\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":[],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpquota","displayName":"Limit Windows File Protection cache size (Windows Insiders only)","description":"This policy setting specifies the maximum amount of disk space that can be used for the Windows File Protection file cache.\r\n\r\nWindows File Protection adds protected files to the cache until the cache content reaches the quota. If the quota is greater than 50 MB, Windows File Protection adds other important Windows XP files to the cache until the cache size reaches the quota.\r\n\r\nIf you enable this policy setting, enter the maximum amount of disk space to be used (in MB). To indicate that the cache size is unlimited, select \"4294967295\" as the maximum amount of disk space.\r\n\r\nIf you disable this policy setting or do not configure it, the default value is set to 50 MB on Windows XP Professional and is unlimited (4294967295 MB) on Windows Server 2003.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsfileprotection#admx-windowsfileprotection-wfpquota"],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":[{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpquota_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpquota_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpquota_wfpquota_size","displayName":"Cache size (in MB) (Device)","description":"\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":[],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpscan","displayName":"Set Windows File Protection scanning (Windows Insiders only)","description":"This policy setting allows you to set when Windows File Protection scans protected files. This policy setting directs Windows File Protection to enumerate and scan all system files for changes.\r\n\r\nIf you enable this policy setting, select a rate from the \"Scanning Frequency\" box. You can use this setting to direct Windows File Protection to scan files more often.\r\n\r\n-- \"Do not scan during startup,\" the default, scans files only during setup.\r\n\r\n-- \"Scan during startup\" also scans files each time you start Windows XP. This setting delays each startup.\r\n\r\nIf you disable or do not configure this policy setting, by default, files are scanned only during setup.\r\n\r\nNote: This policy setting affects file scanning only. It does not affect the standard background file change detection that Windows File Protection provides.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsfileprotection#admx-windowsfileprotection-wfpscan"],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":[{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpscan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpscan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpscan_wfpscanlist","displayName":"Scanning frequency: (Device)","description":"\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":[],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":[{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpscan_wfpscanlist_0","displayName":"Do not scan during startup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpscan_wfpscanlist_1","displayName":"Scan during startup","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpshowprogress","displayName":"Hide the file scan progress window (Windows Insiders only)","description":"This policy setting hides the file scan progress window. This window provides status information to sophisticated users, but it might confuse novices.\r\n\r\nIf you enable this policy setting, the file scan window does not appear during file scanning.\r\n\r\nIf you disable or do not configure this policy setting, the file scan progress window appears.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsfileprotection#admx-windowsfileprotection-wfpshowprogress"],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":[{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpshowprogress_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpshowprogress_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediadrm_disableonline","displayName":"Prevent Windows Media DRM Internet Access","description":"Prevents Windows Media Digital Rights Management (DRM) from accessing the Internet (or intranet).\r\n\r\nWhen enabled, Windows Media DRM is prevented from accessing the Internet (or intranet) for license acquisition and security upgrades.\r\n\r\nWhen this policy is enabled, programs are not able to acquire licenses for secure content, upgrade Windows Media DRM security components, or restore backed up content licenses. Secure content that is already licensed to the local computer will continue to play. Users are also able to protect music that they copy from a CD and play this protected content on their computer, since the license is generated locally in this scenario.\r\n\r\nWhen this policy is either disabled or not configured, Windows Media DRM functions normally and will connect to the Internet (or intranet) to acquire licenses, download security upgrades, and perform license restoration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediadrm#admx-windowsmediadrm-disableonline"],"categoryId":"19ab385f-14f5-47cd-87b2-f4784eedcdd9","categoryName":"Windows Media Digital Rights Management","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediadrm_disableonline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediadrm_disableonline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disableautoupdate","displayName":"Prevent Automatic Updates","description":"This policy setting allows you to turn off do not show first use dialog boxes.\r\n\r\nIf you enable this policy setting, the Privacy Options and Installation Options dialog boxes are prevented from being displayed the first time a user starts Windows Media Player.\r\n\r\nThis policy setting prevents the dialog boxes which allow users to select privacy, file types, and other desktop options from being displayed when the Player is first started. Some of the options can be configured by using other Windows Media Player group policies.\r\n\r\nIf you disable or do not configure this policy setting, the dialog boxes are displayed when the user starts the Player for the first time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-disableautoupdate"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disableautoupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disableautoupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disablesetupfirstuseconfiguration","displayName":"Do Not Show First Use Dialog Boxes","description":"This policy setting allows you to prevent the anchor window from being displayed when Windows Media Player is in skin mode.\r\n\r\nIf you enable this policy setting, the anchor window is hidden when the Player is in skin mode. In addition, the option on the Player tab in the Player that enables users to choose whether the anchor window displays is not available.\r\n\r\nIf you disable or do not configure this policy setting, users can show or hide the anchor window when the Player is in skin mode by using the Player tab in the Player.\r\n\r\nIf you do not configure this policy setting, and the \"Set and lock skin\" policy setting is enabled, some options in the anchor window are not available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-disablesetupfirstuseconfiguration"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disablesetupfirstuseconfiguration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disablesetupfirstuseconfiguration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_dontuseframeinterpolation","displayName":"Prevent Video Smoothing","description":"This policy setting allows you to prevent video smoothing from occurring.\r\n\r\nIf you enable this policy setting, video smoothing is prevented, which can improve video playback on computers with limited resources. In addition, the Use Video Smoothing check box in the Video Acceleration Settings dialog box in the Player is cleared and is not available.\r\n\r\nIf you disable this policy setting, video smoothing occurs if necessary, and the Use Video Smoothing check box is selected and is not available.\r\n\r\nIf you do not configure this policy setting, video smoothing occurs if necessary. Users can change the setting for the Use Video Smoothing check box.\r\n\r\nVideo smoothing is available only on the Windows XP Home Edition and Windows XP Professional operating systems.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-dontuseframeinterpolation"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_dontuseframeinterpolation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_dontuseframeinterpolation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventlibrarysharing","displayName":"Prevent Media Sharing","description":"This policy setting allows you to prevent media sharing from Windows Media Player.\r\n\r\nIf you enable this policy setting, any user on this computer is prevented from sharing digital media content from Windows Media Player with other computers and devices that are on the same network. Media sharing is disabled from Windows Media Player or from programs that depend on the Player's media sharing feature.\r\n\r\nIf you disable or do not configure this policy setting, anyone using Windows Media Player can turn media sharing on or off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-preventlibrarysharing"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventlibrarysharing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventlibrarysharing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventquicklaunchshortcut","displayName":"Prevent Quick Launch Toolbar Shortcut Creation","description":"This policy setting allows you to prevent a shortcut for the Player from being added to the Quick Launch bar.\r\n\r\nIf you enable this policy setting, the user cannot add the shortcut for the Player to the Quick Launch bar.\r\n\r\nIf you disable or do not configure this policy setting, the user can choose whether to add the shortcut for the Player to the Quick Launch bar.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-preventquicklaunchshortcut"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventquicklaunchshortcut_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventquicklaunchshortcut_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventwmpdesktopshortcut","displayName":"Prevent Desktop Shortcut Creation","description":"This policy setting allows you to prevent a shortcut icon for the Player from being added to the user's desktop.\r\n\r\nIf you enable this policy setting, users cannot add the Player shortcut icon to their desktops.\r\n\r\nIf you disable or do not configure this policy setting, users can choose whether to add the Player shortcut icon to their desktops.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-preventwmpdesktopshortcut"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventwmpdesktopshortcut_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_preventwmpdesktopshortcut_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsremotemanagement_disallowkerberos_1","displayName":"Disallow Kerberos authentication","description":"This policy setting allows you to manage whether the Windows Remote Management (WinRM) service accepts Kerberos credentials over the network.\r\n\r\n If you enable this policy setting, the WinRM service does not accept Kerberos credentials over the network.\r\n\r\n If you disable or do not configure this policy setting, the WinRM service accepts Kerberos authentication from a remote client.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsremotemanagement#admx-windowsremotemanagement-disallowkerberos-1"],"categoryId":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","categoryName":"Win RM Service","options":[{"id":"device_vendor_msft_policy_config_admx_windowsremotemanagement_disallowkerberos_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsremotemanagement_disallowkerberos_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsremotemanagement_disallowkerberos_2","displayName":"Disallow Kerberos authentication","description":"This policy setting allows you to manage whether the Windows Remote Management (WinRM) client uses Kerberos authentication directly.\r\n\r\nIf you enable this policy setting, the Windows Remote Management (WinRM) client does not use Kerberos authentication directly. Kerberos can still be used if the WinRM client is using the Negotiate authentication and Kerberos is selected.\r\n\r\nIf you disable or do not configure this policy setting, the WinRM client uses the Kerberos authentication directly.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsremotemanagement#admx-windowsremotemanagement-disallowkerberos-2"],"categoryId":"0f6d725e-2c2d-4926-8e78-3d2d5867eef5","categoryName":"Win RM Client","options":[{"id":"device_vendor_msft_policy_config_admx_windowsremotemanagement_disallowkerberos_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsremotemanagement_disallowkerberos_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableautodownloadwin8","displayName":"Turn off Automatic Download of updates on Win8 machines","description":"Enables or disables the automatic download of app updates on PCs running Windows 8.\r\n\r\nIf you enable this setting, the automatic download of app updates is turned off.\r\n\r\nIf you disable this setting, the automatic download of app updates is turned on.\r\n\r\nIf you don't configure this setting, the automatic download of app updates is determined by a registry setting that the user can change using Settings in the Microsoft Store.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsstore#admx-windowsstore-disableautodownloadwin8"],"categoryId":"be9bdbec-b52e-4174-9c5b-cf765dee855b","categoryName":"Store","options":[{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableautodownloadwin8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableautodownloadwin8_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableosupgrade_2","displayName":"Turn off the offer to update to the latest version of Windows","description":"Enables or disables the Store offer to update to the latest version of Windows.\r\n\r\nIf you enable this setting, the Store application will not offer updates to the latest version of Windows.\r\n\r\nIf you disable or do not configure this setting the Store application will offer updates to the latest version of Windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsstore#admx-windowsstore-disableosupgrade-2"],"categoryId":"be9bdbec-b52e-4174-9c5b-cf765dee855b","categoryName":"Store","options":[{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableosupgrade_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableosupgrade_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_windowsstore_removewindowsstore_2","displayName":"Turn off the Store application","description":"Denies or allows access to the Store application.\r\n\r\nIf you enable this setting, access to the Store application is denied. Access to the Store is required for installing app updates.\r\n\r\nIf you disable or don't configure this setting, access to the Store application is allowed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsstore#admx-windowsstore-removewindowsstore-2"],"categoryId":"be9bdbec-b52e-4174-9c5b-cf765dee855b","categoryName":"Store","options":[{"id":"device_vendor_msft_policy_config_admx_windowsstore_removewindowsstore_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsstore_removewindowsstore_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wininit_disablenamedpipeshutdownpolicydescription","displayName":"Turn off legacy remote shutdown interface","description":"This policy setting controls the legacy remote shutdown interface (named pipe). The named pipe remote shutdown interface is needed in order to shutdown this system from a remote Windows XP or Windows Server 2003 system.\r\n\r\nIf you enable this policy setting, the system does not create the named pipe remote shutdown interface.\r\n\r\nIf you disable or do not configure this policy setting, the system creates the named pipe remote shutdown interface.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wininit#admx-wininit-disablenamedpipeshutdownpolicydescription"],"categoryId":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","categoryName":"Shutdown Options","options":[{"id":"device_vendor_msft_policy_config_admx_wininit_disablenamedpipeshutdownpolicydescription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wininit_disablenamedpipeshutdownpolicydescription_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wininit_hiberboot","displayName":"Require use of fast startup","description":"This policy setting controls the use of fast startup. \r\n\r\nIf you enable this policy setting, the system requires hibernate to be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the local setting is used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wininit#admx-wininit-hiberboot"],"categoryId":"60b55db1-53fc-45ea-93d3-e4372b1e19a5","categoryName":"Shutdown","options":[{"id":"device_vendor_msft_policy_config_admx_wininit_hiberboot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wininit_hiberboot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription","displayName":"Timeout for hung logon sessions during shutdown","description":"This policy setting configures the number of minutes the system waits for the hung logon sessions before proceeding with the system shutdown.\r\n\r\nIf you enable this policy setting, the system waits for the hung logon sessions for the number of minutes specified.\r\n\r\nIf you disable or do not configure this policy setting, the default timeout value is 3 minutes for workstations and 15 minutes for servers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wininit#admx-wininit-shutdowntimeouthungsessionsdescription"],"categoryId":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","categoryName":"Shutdown Options","options":[{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription_shutdownsessiontimeout_time","displayName":"Hung session timeout in Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","categoryName":"Shutdown Options","options":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_displaylastlogoninfodescription","displayName":"Display information about previous logons during user logon","description":"This policy setting controls whether or not the system displays information about previous logons and logon failures to the user.\r\n\r\nFor local user accounts and domain user accounts in domains of at least a Windows Server 2008 functional level, if you enable this setting, a message appears after the user logs on that displays the date and time of the last successful logon by that user, the date and time of the last unsuccessful logon attempted with that user name, and the number of unsuccessful logons since the last successful logon by that user. This message must be acknowledged by the user before the user is presented with the Microsoft Windows desktop.\r\n\r\nFor domain user accounts in Windows Server 2003, Windows 2000 native, or Windows 2000 mixed functional level domains, if you enable this setting, a warning message will appear that Windows could not retrieve the information and the user will not be able to log on. Therefore, you should not enable this policy setting if the domain is not at the Windows Server 2008 domain functional level.\r\n\r\nIf you disable or do not configure this setting, messages about the previous logon or logon failures are not displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-winlogon#admx-winlogon-displaylastlogoninfodescription"],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_admx_winlogon_displaylastlogoninfodescription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_displaylastlogoninfodescription_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_winlogon_reportcachedlogonpolicydescription","displayName":"Report when logon server was not available during user logon","description":"This policy controls whether the logged on user should be notified if the logon server could not be contacted during logon and he has been logged on using previously stored account information.\r\n\r\nIf enabled, a notification popup will be displayed to the user when the user logs on with cached credentials.\r\n\r\nIf disabled or not configured, no popup will be displayed to the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-winlogon#admx-winlogon-reportcachedlogonpolicydescription"],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_admx_winlogon_reportcachedlogonpolicydescription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_reportcachedlogonpolicydescription_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration","displayName":"Disable or enable software Secure Attention Sequence","description":"This policy setting controls whether or not software can simulate the Secure Attention Sequence (SAS).\r\n\r\nIf you enable this policy setting, you have one of four options:\r\n\r\nIf you set this policy setting to \"None,\" user mode software cannot simulate the SAS.\r\nIf you set this policy setting to \"Services,\" services can simulate the SAS.\r\nIf you set this policy setting to \"Ease of Access applications,\" Ease of Access applications can simulate the SAS.\r\nIf you set this policy setting to \"Services and Ease of Access applications,\" both services and Ease of Access applications can simulate the SAS.\r\n\r\nIf you disable or do not configure this setting, only Ease of Access applications running on the secure desktop can simulate the SAS.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-winlogon#admx-winlogon-softwaresasgeneration"],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_softwaresasgenerationdescription","displayName":"Set which software is allowed to generate the Secure Attention Sequence","description":null,"helpText":"","infoUrls":[],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_softwaresasgenerationdescription_0","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_softwaresasgenerationdescription_1","displayName":"Services","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_softwaresasgenerationdescription_2","displayName":"Ease of Access applications","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_softwaresasgenerationdescription_3","displayName":"Services and Ease of Access applications","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_winsrv_allowblockingappsatshutdown","displayName":"Turn off automatic termination of applications that block or cancel shutdown","description":"This policy setting specifies whether Windows will allow console applications and GUI applications without visible top-level windows to block or cancel shutdown. By default, such applications are automatically terminated if they attempt to cancel shutdown or block it indefinitely.\r\n\r\nIf you enable this setting, console applications or GUI applications without visible top-level windows that block or cancel shutdown will not be automatically terminated during shutdown.\r\n\r\nIf you disable or do not configure this setting, these applications will be automatically terminated during shutdown, helping to ensure that Windows can shut down faster and more smoothly.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-winsrv#admx-winsrv-allowblockingappsatshutdown"],"categoryId":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","categoryName":"Shutdown Options","options":[{"id":"device_vendor_msft_policy_config_admx_winsrv_allowblockingappsatshutdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winsrv_allowblockingappsatshutdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost","displayName":"Set Cost","description":"This policy setting configures the cost of Wireless LAN (WLAN) connections on the local machine.\r\n\r\nIf this policy setting is enabled, a drop-down list box presenting possible cost values will be active. Selecting one of the following values from the list will set the cost of all WLAN connections on the local machine:\r\n\r\n- Unrestricted: Use of this connection is unlimited and not restricted by usage charges and capacity constraints. \r\n\r\n- Fixed: Use of this connection is not restricted by usage charges and capacity constraints up to a certain data limit. \r\n\r\n- Variable: This connection is costed on a per byte basis.\r\n\r\nIf this policy setting is disabled or is not configured, the cost of Wireless LAN connections is Unrestricted by default.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wlansvc#admx-wlansvc-setcost"],"categoryId":"6cd02266-a42f-4675-b83e-37360dbf3c68","categoryName":"WLAN Media Cost","options":[{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost_cost_dropdownlist","displayName":"Please select a wlan connection cost value to set:","description":null,"helpText":"","infoUrls":[],"categoryId":"6cd02266-a42f-4675-b83e-37360dbf3c68","categoryName":"WLAN Media Cost","options":[{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost_cost_dropdownlist_1","displayName":"Unrestricted","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost_cost_dropdownlist_2","displayName":"Fixed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setcost_cost_dropdownlist_3","displayName":"Variable","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinenforced","displayName":"Require PIN pairing","description":"This policy applies to Wireless Display connections. This policy means that the use of a PIN for pairing to Wireless Display devices is required rather than optional.\r\n\r\nConversely it means that Push Button is NOT allowed.\r\n\r\nIf this policy setting is disabled or is not configured, by default Push Button pairing is allowed (but not necessarily preferred).\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wlansvc#admx-wlansvc-setpinenforced"],"categoryId":"4dd8280d-6c01-4a06-bfd1-e1cb4c529494","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinenforced_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinenforced_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinpreferred","displayName":"Prefer PIN pairing","description":"This policy applies to Wireless Display connections. This policy changes the preference order of the pairing methods.\r\n\r\nWhen enabled, it makes the connections to prefer a PIN for pairing to Wireless Display devices over the Push Button pairing method.\r\n\r\nIf this policy setting is disabled or is not configured, by default Push Button pairing is preferred (if allowed by other policies).\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wlansvc#admx-wlansvc-setpinpreferred"],"categoryId":"4dd8280d-6c01-4a06-bfd1-e1cb4c529494","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinpreferred_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinpreferred_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_workfoldersclient_pol_machineenableworkfolders","displayName":"Force automatic setup for all users","description":"This policy setting specifies whether Work Folders should be set up automatically for all users of the affected computer.\r\n \r\nIf you enable this policy setting, Work Folders will be set up automatically for all users of the affected computer. This prevents users from choosing not to use Work Folders on the computer; it also prevents them from manually specifying the local folder in which Work Folders stores files. Work Folders will use the settings specified in the \"Specify Work Folders settings\" policy setting in User Configuration\\Administrative Templates\\Windows Components\\WorkFolders. If the \"Specify Work Folders settings\" policy setting does not apply to a user, Work Folders is not automatically set up.\r\n \r\nIf you disable or do not configure this policy setting, Work Folders uses the \"Force automatic setup\" option of the \"Specify Work Folders settings\" policy setting to determine whether to automatically set up Work Folders for a given user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-workfoldersclient#admx-workfoldersclient-pol-machineenableworkfolders"],"categoryId":"87667b72-85ce-48c2-8023-e6db7f5fe739","categoryName":"Work Folders","options":[{"id":"device_vendor_msft_policy_config_admx_workfoldersclient_pol_machineenableworkfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_workfoldersclient_pol_machineenableworkfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_admx_wpn_notoastnotification","displayName":"Turn off toast notifications","description":"\n This policy setting turns off toast notifications for applications.\n\n If you enable this policy setting, applications will not be able to raise toast notifications.\n\n Note that this policy does not affect taskbar notification balloons.\n\n Note that Windows system features are not affected by this policy. You must enable/disable system features individually to stop their ability to raise toast notifications.\n\n If you disable or do not configure this policy setting, toast notifications are enabled and can be turned off by the administrator or user.\n\n No reboots or service restarts are required for this policy setting to take effect.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wpn#admx-wpn-notoastnotification"],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":[{"id":"device_vendor_msft_policy_config_admx_wpn_notoastnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wpn_notoastnotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls","displayName":"App Control for Business Built In Controls","description":"App Control for Business Built In Controls","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_enable_app_control","displayName":"Enable App Control for Business policy to trust Windows components and Store apps","description":"Select Audit only to log all events in local client logs but not block any apps from running or select Enforce to actively block apps from running in a deployed App Control for Business base policy. App Control for Business policies created in either Audit only or Enforce mode will be deployed as rebootless base policies to all devices targeted./nBy default, any devices targeted with this App Control for Business policy will have the setting to Trust Windows components and Store apps enabled, in either audit or enforce mode based on your selection.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_enable_app_control_0","displayName":"Enforce","description":"Enforce","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_enable_app_control_1","displayName":"Audit only","description":"Audit only","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_trust_apps","displayName":"Select additional rules for trusting apps","description":"By default, any devices targeted with this App Control for Business policy will have the setting to Trust Windows components and Store apps enabled, in either audit or enforce mode based on your selection./nFurther, you can optionally add some additional rules to your policy, such as selecting Trust apps with good reputation to allow reputable apps as defined by the Microsoft Intelligent Security Graph to run./nSelect Trust apps from managed installers to allow apps deployed via authorized sources of application deployment (managed installers). The Intune management extension will be considered a managed installer if it has been set as such within your organization. Any apps not marked as coming from a managed installer will not be allowed to run./nAll other apps and files not specified by the rules in this App Control for Business policy will be audited only in local client logs (if Audit only is selected), or blocked (if Enforce is selected) from running on devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_trust_apps_0","displayName":"Trust apps with good reputation","description":"Trust app with good reputation","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_trust_apps_1","displayName":"Trust apps from managed installers","description":"Trust apps from managed installers","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrol_policies_{policyguid}_policiesoptions","displayName":"Configuration settings format","description":"Select Enter XML data to type or paste an XML property list that contains your App Control for Business policy. Select Use built-in controls to choose from toggles exposed in this App Control for Business policy. Setting this to Not Configured will result in default behaviour on the device with no added options from the ApplicationControl CSP on the device.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_applicationcontrol_configure_xml_selected","displayName":"Enter xml data","description":"Enter xml data","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_selected","displayName":"Use built-in controls","description":"Use built-in controls","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrol_policies_{policyguid}_xml","displayName":"App Control for Business policy","description":"The format of the XML property list varies depending on the settings you are configuring for the ApplicationControl CSP. Microsoft Endpoint Manager will validate the XML format; but not validate the settings behaviour, the settings applicability nor sign the policy binary. ApplicationControl CSP supports base and supplemental policies for devices running the Windows 1903 build and later. Supplemental policies are required to loosen a base policy; and are always less restrictive. A supplemental policy needs to support a specific base policy that has been deployed to the same client. If not, there is no effect on assigned Windows devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_auditmode","displayName":"Audit mode","description":"Turning audit mode on will not enforce the policy. We recommend first running the poliy with audit mode turned on prior to enforcement to determine the impacts of the policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_auditmode_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_auditmode_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_buildoptions","displayName":"Policy creation type","description":"Select Enter XML data to type or paste an XML property list that contains your Application Control policy. Select Use built-in controls to choose from toggles exposed in this Application Control policy. Setting this to Not Configured will result in default behaviour on the device with no added options from the ApplicationControl CSP on the device.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_buildoptions_upload_xml_selected","displayName":"XML upload","description":"XML upload","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_buildoptions_built_in_controls_selected","displayName":"Built-in controls","description":"Built-in controls","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions","displayName":"Configuration settings format","description":"Select Enter XML data to type or paste an XML property list that contains your Application Control policy. Select Use built-in controls to choose from toggles exposed in this Application Control policy. Setting this to Not Configured will result in default behaviour on the device with no added options from the ApplicationControl CSP on the device.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_uploadxml","displayName":"Enter xml data","description":"Enter xml data","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_builtincontrols","displayName":"Use built-in controls","description":"Use built-in controls","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}","displayName":"Policy rules","description":"","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/defender-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_action","displayName":"Action","description":"Sets a rule to allow or deny the configured settings.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_action_allow","displayName":"Allow","description":null,"helpText":null}},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_id","displayName":"Rule Id","description":"The Id of the rule, leave this field blank, it will be filled in automatically.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_name","displayName":"Rule Name","description":"The name of the rule","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type","displayName":"Rule Type","description":"Rule Type","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisher","displayName":"Publisher","description":"Creates a rule for a file that is signed by the software publisher. Upload the output generated by the binary file information extractor for your selected reference file.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filehash","displayName":"File Hash","description":"Creates a rule for a file based on its corresponding hash values. Upload a CSV file containing a list of hash values you want to include in this rule or directly type your hash values in the text area below.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filepath","displayName":"File Path","description":"Creates a rule for a specific file path or folder. Selecting folder will affect all files in a folder.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes","displayName":"File Attributes","description":"Creates a rule for a file based on one of its attributes. Select a file to use as reference for your rule.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_filedescriptiondetails","displayName":"File description","description":"The description of the selected file as stated in the file attributes.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_filenamedetails","displayName":"Original file name","description":"The original name of the applications executable as stated in the file attributes.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_internalnamedetails","displayName":"Internal name","description":"The Internal name of the selected file as stated in the file attributes.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_productnamedetails","displayName":"Product name","description":"The product name of the selected file as stated in the file attributes.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributesdetails","displayName":"File Attributes","description":"Creates a rule for attributes of a selected file.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_filename","displayName":"Original file name","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_filedescription","displayName":"File description","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_productname","displayName":"Minimum version","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes_internalname","displayName":"Internal name","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filehashdetails","displayName":"File hash","description":"A set of coma separated hashes for use of the application of this rule.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filepathdetails","displayName":"File Path","description":"The path of the directory or file for application of this rule.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails","displayName":"Publisher","description":"Creates a rule for a file that is signed by the software publisher. Upload the output generated by the binary file information extractor for your selected reference file.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_issuingca","displayName":"Issuing certificate authority","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_publishername","displayName":"Publisher","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_minimumversion","displayName":"Minimum version","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherfilename","displayName":"File name","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_issuingcadetails","displayName":"Issuing certificate authority","description":"The name of the issuing certificate authority","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_minimumversiondetails","displayName":"Minimum Version","description":"The application's minimum version","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_publishernamedetails","displayName":"Publisher","description":"The name of the application publisher","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherfilenamedetails","displayName":"File name","description":"The name of the applications executable file name.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_basepolicyid","displayName":"Base policy id","description":"The id of the base policy for which this supplemental policy applies.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_disableruntimefilepathrules","displayName":"Disable runtime file path rules","description":"Turning this off will disable FilePath rule protection of enforcing user-writeability and onlu allowing admin-writable locations.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_disableruntimefilepathrules_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_disableruntimefilepathrules_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_hypervisorprotectedcodeintegrity","displayName":"Hypervisor protected Code Integrity","description":"When enabled, code integrity runs in a hypervisor-protected container.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_hypervisorprotectedcodeintegrity_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_hypervisorprotectedcodeintegrity_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappsfrommanagedinstaller","displayName":"Trust apps from managed installer","description":"Turning Trust apps from managed installer on will not enforce the policy. We recommend first running the poliy with Trust apps from managed installer turned on prior to enforcement to determine the impacts of the policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappsfrommanagedinstaller_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappsfrommanagedinstaller_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappswithgoodreputation","displayName":"Trust apps with good reputation","description":"When enabled, applications with known good reputation as defined by the Microsoft's Intelligent Security Graph (ISG) are white listed.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappswithgoodreputation_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappswithgoodreputation_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_uploadxmldetails","displayName":"XML Upload","description":"The format of the XML property list varies depending on the settings you are configuring for the ApplicationControl CSP. Microsoft Endpoint Manager will validate the XML format; but not validate the settings behaviour, the settings applicability nor sign the policy binary. ApplicationControl CSP supports base and supplemental policies for devices running the Windows 1903 build and later. Supplemental policies are required to loosen a base policy; and are always less restrictive. A supplemental policy needs to support a specific base policy that has been deployed to the same client. If not, there is no effect on assigned Windows devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappsfrommanagedinstaller","displayName":"Trust apps from managed installer","description":"Turning Trust apps from managed installer on will not enforce the policy. We recommend first running the poliy with Trust apps from managed installer turned on prior to enforcement to determine the impacts of the policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappsfrommanagedinstaller_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappsfrommanagedinstaller_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappswithgoodreputation","displayName":"Trust apps with good reputation","description":"When enabled, applications with known good reputation as defined by the Microsoft's Intelligent Security Graph (ISG) are white listed.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappswithgoodreputation_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappswithgoodreputation_enabled","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_xmlupload","displayName":"XML upload","description":"The format of the XML property list varies depending on the settings you are configuring for the ApplicationControl CSP. Microsoft Endpoint Manager will validate the XML format; but not validate the settings behaviour, the settings applicability nor sign the policy binary. ApplicationControl CSP supports base and supplemental policies for devices running the Windows 1903 build and later. Supplemental policies are required to loosen a base policy; and are always less restrictive. A supplemental policy needs to support a specific base policy that has been deployed to the same client. If not, there is no effect on assigned Windows devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},{"id":"device_vendor_msft_policy_config_applicationdefaults_defaultassociationsconfiguration","displayName":"Default Associations Configuration","description":"This policy allows an administrator to set default file type and protocol associations. When set, default associations will be applied on sign-in to the PC. The association file can be created using the DISM tool (dism /online /export-defaultappassociations:appassoc. xml), and then needs to be base64 encoded before being added to SyncML. If policy is enabled and the client machine is Azure Active Directory joined, the associations assigned in SyncML will be processed and default associations will be applied.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationDefaults#defaultassociationsconfiguration"],"categoryId":"ddcc8634-edc3-40ef-a444-45f806439c18","categoryName":"Application Defaults","options":null},{"id":"device_vendor_msft_policy_config_applicationdefaults_enableappurihandlers","displayName":"Enable App Uri Handlers","description":"Enables web-to-app linking, which allows apps to be launched with a http(s) URI","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationDefaults#enableappurihandlers"],"categoryId":"ddcc8634-edc3-40ef-a444-45f806439c18","categoryName":"Application Defaults","options":[{"id":"device_vendor_msft_policy_config_applicationdefaults_enableappurihandlers_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationdefaults_enableappurihandlers_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowalltrustedapps","displayName":"Allow All Trusted Apps","description":"Specifies whether non Microsoft Store apps are allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowalltrustedapps"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowalltrustedapps_0","displayName":"Explicit deny.","description":"Explicit deny.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowalltrustedapps_1","displayName":"Explicit allow unlock.","description":"Explicit allow unlock.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowalltrustedapps_65535","displayName":"Not configured.","description":"Not configured.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowappstoreautoupdate","displayName":"Allow apps from the Microsoft app store to auto update","description":"Specifies whether automatic update of apps from Microsoft Store are allowed. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowappstoreautoupdate"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowappstoreautoupdate_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowappstoreautoupdate_1","displayName":"Allowed.","description":"Allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowappstoreautoupdate_2","displayName":"Not configured.","description":"Not configured.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock","displayName":"Allow Developer Unlock","description":"Specifies whether developer unlock is allowed. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowdeveloperunlock"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock_0","displayName":"Explicit deny.","description":"Explicit deny.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock_1","displayName":"Explicit allow unlock.","description":"Explicit allow unlock.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock_65535","displayName":"Not configured.","description":"Not configured.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowgamedvr","displayName":"Allow Game DVR","description":"Note The policy is only enforced in Windows 10 for desktop. Specifies whether DVR and broadcasting is allowed. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowgamedvr"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowgamedvr_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowgamedvr_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowshareduserappdata","displayName":"Allow Shared User App Data","description":"With this policy, you can configure Windows 10 to share application data among multiple users on the system and with other instances of that app. Data shared through the SharedLocal folder is available through the Windows. Storage API. If you previously enabled this policy and now want to disable it, any shared app data remains in the SharedLocal folder.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowshareduserappdata"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowshareduserappdata_0","displayName":"Block","description":"Prevented/not allowed, but Microsoft Edge downloads book files to a per-user folder for each user.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowshareduserappdata_1","displayName":"Allow","description":"Allowed. Microsoft Edge downloads book files into a shared folder. For this policy to work correctly, you must also enable the Allow a Windows app to share application data between users group policy. Also, the users must be signed in with a school or work account.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_blocknonadminuserinstall","displayName":"Block Non Admin User Install","description":"Manages non-administrator users' ability to install Windows app packages. If you enable this policy, non-administrators will be unable to initiate installation of Windows app packages. Administrators who wish to install an app will need to do so from an Administrator context (for example, an Administrator PowerShell window). All users will still be able to install Windows app packages via the Microsoft Store, if permitted by other policies. If you disable or do not configure this policy, all users will be able to initiate installation of Windows app packages.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#blocknonadminuserinstall"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_blocknonadminuserinstall_0","displayName":"Block","description":"Disabled. All users will be able to initiate installation of Windows app packages.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_blocknonadminuserinstall_1","displayName":"Allow","description":"Enabled. Non-administrator users will not be able to initiate installation of Windows app packages.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_disablestoreoriginatedapps","displayName":"Disable Store Originated Apps","description":"Boolean value that disables the launch of all apps from Microsoft Store that came pre-installed or were downloaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#disablestoreoriginatedapps"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_disablestoreoriginatedapps_0","displayName":"Disabled","description":"Enable launch of apps.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_disablestoreoriginatedapps_1","displayName":"Enabled","description":"Disable launch of apps.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_launchappafterlogon","displayName":"Launch App After Log On","description":"List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are to be launched after logon.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#launchappafterlogon"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_msiallowusercontroloverinstall","displayName":"MSI Allow User Control Over Install","description":"This policy setting permits users to change installation options that typically are available only to system administrators. If you enable this policy setting, some of the security features of Windows Installer are bypassed. It permits installations to complete that otherwise would be halted due to a security violation. If you disable or do not configure this policy setting, the security features of Windows Installer prevent users from changing installation options typically reserved for system administrators, such as specifying the directory to which files are installed. If Windows Installer detects that an installation package has permitted the user to change a protected option, it stops the installation and displays a message. These security features operate only when the installation program is running in a privileged security context in which it has access to directories denied to the user. This policy setting is designed for less restrictive environments. It can be used to circumvent errors in an installation program that prevents software from being installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#msiallowusercontroloverinstall"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_msiallowusercontroloverinstall_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_msiallowusercontroloverinstall_1","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_msialwaysinstallwithelevatedprivileges","displayName":"MSI Always Install With Elevated Privileges","description":"This policy setting directs Windows Installer to use elevated permissions when it installs any program on the system. If you enable this policy setting, privileges are extended to all programs. These privileges are usually reserved for programs that have been assigned to the user (offered on the desktop), assigned to the computer (installed automatically), or made available in Add or Remove Programs in Control Panel. This profile setting lets users install programs that require access to directories that the user might not have permission to view or change, including directories on highly restricted computers. If you disable or do not configure this policy setting, the system applies the current user's permissions when it installs programs that a system administrator does not distribute or offer. Note: This policy setting appears both in the Computer Configuration and User Configuration folders. To make this policy setting effective, you must enable it in both folders. Caution: Skilled users can take advantage of the permissions this policy setting grants to change their privileges and gain permanent access to restricted files and folders. Note that the User Configuration version of this policy setting is not guaranteed to be secure.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#msialwaysinstallwithelevatedprivileges"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_msialwaysinstallwithelevatedprivileges_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_msialwaysinstallwithelevatedprivileges_1","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages","displayName":"Remove Default Microsoft Store packages from the system.","description":"Removes Default Microsoft Store packages from the system.\n\nIf you enable this policy, the selected Microsoft Store apps in the provided list will be uninstalled from the system. You can make adjustments to the default settings.\n\nUnselected apps in the list will not be removed.\n\nDefault is 'disabled' (key not present).\n\nIf the policy is disabled or not configured, no Default Microsoft Store packages will be removed from the system.\n\n* This is a headless app (no UI)\n\n** This app is the default handler for a common file type or protocol. Removing this app might result in a degraded user experience. We do not recommend removing this app.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-applicationmanagement#applicationmanagement-removedefaultmicrosoftstorepackages"],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2","displayName":"Remove Microsoft Store apps with dynamic list","description":"Removes Default Microsoft Store packages from the system.\r\n\r\nIf you enable this policy, the selected Microsoft Store apps in the provided list will be uninstalled from the system. You can make adjustments to the default settings.\r\n\r\nUnselected apps in the list will not be removed.\r\n\r\n* This is a headless app (no UI)\r\n\r\n** This app is the default handler for a common file type or protocol. Removing this app might result in a degraded user experience. We do not recommend removing this app.\r\n\r\nIf you enable this policy, you can also remove an app by entering the app's package family name(e.g., Microsoft.WindowsCalculator_8wekyb3d8bbwe) in the dynamic list under \"Specify additional package family names to remove.\".\r\n\r\nIf this policy is enabled, reinstallation of a previously removed app requires de-selecting the app from the provided list or removing the app's package family name from the dynamic list.\r\n\r\nYou cannot remove Windows System components via the dynamic app removal list.\r\n\r\nValidation of package family names in the dynamic app removal list occurs upon user login, not at policy configuration time.\r\n\r\nDefault is 'disabled' (key not present).\r\n\r\nIf the policy is disabled or not configured, no Default apps will be removed from the system.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-applicationmanagement#applicationmanagement-removedefaultmicrosoftstorepackages-2"],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingnews","displayName":"Microsoft News (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingnews_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingnews_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingweather","displayName":"MSN Weather (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingweather_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingweather_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_clipchamp","displayName":"Microsoft Clipchamp (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_clipchamp_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_clipchamp_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_copilot","displayName":"Microsoft Copilot (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_copilot_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_copilot_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_dynamicremovallist","displayName":"Specify additional package family names to remove (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_gamingapp","displayName":"Xbox Gaming App (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_gamingapp_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_gamingapp_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_mediaplayer","displayName":"Windows Media Player ** (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_mediaplayer_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_mediaplayer_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftofficehub","displayName":"Microsoft 365 Copilot (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftofficehub_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftofficehub_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftsolitairecollection","displayName":"Microsoft Solitaire Collection (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftsolitairecollection_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftsolitairecollection_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftstickynotes","displayName":"Microsoft Sticky Notes (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftstickynotes_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftstickynotes_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_msteams","displayName":"Microsoft Teams (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_msteams_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_msteams_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_outlookforwindows","displayName":"Outlook for Windows (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_outlookforwindows_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_outlookforwindows_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_paint","displayName":"Paint (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_paint_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_paint_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_photos","displayName":"Microsoft Photos ** (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_photos_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_photos_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_quickassist","displayName":"Quick Assist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_quickassist_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_quickassist_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_screensketch","displayName":"Snipping Tool (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_screensketch_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_screensketch_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_todo","displayName":"Microsoft To Do (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_todo_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_todo_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscalculator","displayName":"Windows Calculator (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscalculator_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscalculator_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscamera","displayName":"Windows Camera ** (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscamera_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscamera_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsfeedbackhub","displayName":"Feedback Hub (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsfeedbackhub_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsfeedbackhub_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsnotepad","displayName":"Windows Notepad ** (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsnotepad_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsnotepad_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowssoundrecorder","displayName":"Windows Sound Recorder (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowssoundrecorder_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowssoundrecorder_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsterminal","displayName":"Windows Terminal (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsterminal_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsterminal_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxidentityprovider","displayName":"Xbox Identity Provider * (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxidentityprovider_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxidentityprovider_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxspeechtotextoverlay","displayName":"Xbox Speech To Text Overlay * (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxspeechtotextoverlay_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxspeechtotextoverlay_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxtcui","displayName":"Xbox TCUI * (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxtcui_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_xboxtcui_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_bingnews","displayName":"Microsoft News","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_bingnews_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_bingnews_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_bingweather","displayName":"MSN Weather","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_bingweather_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_bingweather_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_clipchamp","displayName":"Microsoft Clipchamp","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_clipchamp_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_clipchamp_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_copilot","displayName":"Microsoft Copilot","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_copilot_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_copilot_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_gamingapp","displayName":"Xbox Gaming App","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_gamingapp_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_gamingapp_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_mediaplayer","displayName":"Windows Media Player **","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_mediaplayer_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_mediaplayer_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftofficehub","displayName":"Microsoft 365 Copilot","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftofficehub_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftofficehub_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftsolitairecollection","displayName":"Microsoft Solitaire Collection","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftsolitairecollection_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftsolitairecollection_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftstickynotes","displayName":"Microsoft Sticky Notes","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftstickynotes_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftstickynotes_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_msteams","displayName":"Microsoft Teams","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_msteams_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_msteams_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_outlookforwindows","displayName":"Outlook for Windows","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_outlookforwindows_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_outlookforwindows_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_paint","displayName":"Paint","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_paint_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_paint_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_photos","displayName":"Microsoft Photos **","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_photos_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_photos_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_quickassist","displayName":"Quick Assist","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_quickassist_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_quickassist_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_screensketch","displayName":"Snipping Tool","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_screensketch_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_screensketch_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_todo","displayName":"Microsoft To Do","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_todo_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_todo_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowscalculator","displayName":"Windows Calculator","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowscalculator_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowscalculator_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowscamera","displayName":"Windows Camera **","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowscamera_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowscamera_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsfeedbackhub","displayName":"Feedback Hub","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsfeedbackhub_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsfeedbackhub_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsnotepad","displayName":"Windows Notepad **","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsnotepad_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsnotepad_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowssoundrecorder","displayName":"Windows Sound Recorder","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowssoundrecorder_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowssoundrecorder_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsterminal","displayName":"Windows Terminal","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsterminal_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsterminal_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxidentityprovider","displayName":"Xbox Identity Provider *","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxidentityprovider_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxidentityprovider_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxspeechtotextoverlay","displayName":"Xbox Speech To Text Overlay *","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxspeechtotextoverlay_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxspeechtotextoverlay_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxtcui","displayName":"Xbox TCUI *","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxtcui_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_xboxtcui_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_requireprivatestoreonly","displayName":"Require Private Store Only","description":"Allows disabling of the retail catalog and only enables the Private store. Most restricted value is 1.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#requireprivatestoreonly"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_requireprivatestoreonly_0","displayName":"Allow both public and Private store.","description":"Allow both public and Private store.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_requireprivatestoreonly_1","displayName":"Only Private store is enabled.","description":"Only Private store is enabled.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_restrictappdatatosystemvolume","displayName":"Restrict App Data To System Volume","description":"Specifies whether application data is restricted to the system drive. Most restricted value is 1.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#restrictappdatatosystemvolume"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_restrictappdatatosystemvolume_0","displayName":"Disabled","description":"Not restricted.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_restrictappdatatosystemvolume_1","displayName":"Enabled","description":"Restricted.","helpText":null}]},{"id":"device_vendor_msft_policy_config_applicationmanagement_restrictapptosystemvolume","displayName":"Restrict App To System Volume","description":"Specifies whether the installation of applications is restricted to the system drive. Most restricted value is 1.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#restrictapptosystemvolume"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_restrictapptosystemvolume_0","displayName":"Disabled","description":"Not restricted.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_restrictapptosystemvolume_1","displayName":"Enabled","description":"Restricted.","helpText":null}]},{"id":"device_vendor_msft_policy_config_appruntime_allowmicrosoftaccountstobeoptional","displayName":"Allow Microsoft accounts to be optional","description":"This policy setting lets you control whether Microsoft accounts are optional for packaged Microsoft Store apps that require an account to sign in. This policy only affects packaged Microsoft Store apps that support it.\n\nIf you enable this policy setting, packaged Microsoft Store apps that typically require a Microsoft account to sign in will allow users to sign in with an enterprise account instead.\n\nIf you disable or do not configure this policy setting, users will need to sign in with a Microsoft account.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-appruntime#appruntime-allowmicrosoftaccountstobeoptional"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"device_vendor_msft_policy_config_appruntime_allowmicrosoftaccountstobeoptional_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appruntime_allowmicrosoftaccountstobeoptional_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowappvclient","displayName":"Enable App-V Client","description":"This policy setting allows you to enable or disable Microsoft Application Virtualization (App-V) feature. Reboot is needed for disable to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowappvclient"],"categoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","categoryName":"App-V","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowappvclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowappvclient_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowdynamicvirtualization","displayName":"Enable Dynamic Virtualization","description":"Enables Dynamic Virtualization of supported shell extensions, browser helper objects, and ActiveX controls.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowdynamicvirtualization"],"categoryId":"10835ce3-31c8-4ec6-aa00-c5af48e550a8","categoryName":"Virtualization","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowdynamicvirtualization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowdynamicvirtualization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagecleanup","displayName":"Enable automatic cleanup of unused appv packages","description":"Enables automatic cleanup of appv packages that were added after Windows10 anniversary release.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowpackagecleanup"],"categoryId":"f125d7cd-a333-4f24-a5f4-99fc289c6d22","categoryName":"Package Management","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagecleanup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagecleanup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagescripts","displayName":"Enable Package Scripts","description":"Enables scripts defined in the package manifest of configuration files that should run.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowpackagescripts"],"categoryId":"efabaf11-42e4-48ab-81ca-4514199d239b","categoryName":"Scripting","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagescripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagescripts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpublishingrefreshux","displayName":"Enable Publishing Refresh UX","description":"Enables a UX to display to the user when a publishing refresh is performed on the client.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowpublishingrefreshux"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowpublishingrefreshux_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpublishingrefreshux_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver","displayName":"Reporting Server","description":"Reporting Server URL: Displays the URL of reporting server.\n\n Reporting Time: When the client data should be reported to the server. Acceptable range is 0~23, corresponding to the 24 hours in a day. A good practice is, don't set this time to a busy hour, e.g. 9AM.\n \n Delay reporting for the random minutes: The maximum minutes of random delay on top of the reporting time. For a busy system, the random delay will help reduce the server load.\n \n Repeat reporting for every (days): The periodical interval in days for sending the reporting data.\n \n Data Cache Limit: This value specifies the maximum size in megabytes (MB) of the XML cache for storing reporting information. The default value is 20 MB. The size applies to the cache in memory. When the limit is reached, the log file will roll over. When a new record is to be added (bottom of the list), one or more of the oldest records (top of the list) will be deleted to make room. A warning will be logged to the Client log and the event log the first time this occurs, and will not be logged again until after the cache has been successfully cleared on transmission and the log has filled up again.\n\n Data Block Size: This value specifies the maximum size in bytes to transmit to the server at once on a reporting upload, to avoid permanent transmission failures when the log has reached a significant size. The default value is 65536. When transmitting report data to the server, one block at a time of application records that is less than or equal to the block size in bytes of XML data will be removed from the cache and sent to the server. Each block will have the general Client data and global package list data prepended, and these will not factor into the block size calculations; the potential exists for an extremely large package list to result in transmission failures over low bandwidth or unreliable connections.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowreportingserver"],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_data_block_size","displayName":"Data Block Size","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_data_cache_limit","displayName":"Data Cache Limit","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_interval","displayName":"Repeat reporting for every (days)","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_random_delay","displayName":"Delay reporting for the random minutes","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_reporting_server_url_prompt","displayName":"Reporting Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_start_time","displayName":"Reporting Time","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingfileexclusions","displayName":"Roaming File Exclusions","description":"Specifies the file paths relative to %userprofile% that do not roam with a user's profile. Example usage: /FILEEXCLUSIONLIST='desktop;my pictures'.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowroamingfileexclusions"],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingfileexclusions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingfileexclusions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingfileexclusions_integration_roaming_file_exclusions_prompt","displayName":"Roaming Registry Exclusions","description":"","helpText":"","infoUrls":[],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingregistryexclusions","displayName":"Roaming Registry Exclusions","description":"Specifies the registry paths that do not roam with a user profile. Example usage: /REGISTRYEXCLUSIONLIST=software\\classes;software\\clients.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowroamingregistryexclusions"],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingregistryexclusions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingregistryexclusions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingregistryexclusions_integration_roaming_registry_exclusions_prompt","displayName":"Roaming File Exclusions","description":"","helpText":"","infoUrls":[],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload","displayName":"Specify what to load in background (aka AutoLoad)","description":"Specifies how new packages should be loaded automatically by App-V on a specific computer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowstreamingautoload"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload_steaming_autoload_options","displayName":"Autoload Options","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload_steaming_autoload_options_0","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload_steaming_autoload_options_1","displayName":"Previously Used","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowstreamingautoload_steaming_autoload_options_2","displayName":"All","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_clientcoexistenceallowmigrationmode","displayName":"Enable Migration Mode","description":"Migration mode allows the App-V client to modify shortcuts and FTA's for packages created using a previous version of App-V.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-clientcoexistenceallowmigrationmode"],"categoryId":"b9201072-3681-4e95-ad90-869e6166b129","categoryName":"Client Coexistence","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_clientcoexistenceallowmigrationmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_clientcoexistenceallowmigrationmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootglobal","displayName":"Integration Root User","description":"Specifies the location where symbolic links are created to the current version of a per-user published package. Shortcuts, file type associations, etc. are created pointing to this path. If empty, symbolic links are not used during publishing. Example: %localappdata%\\Microsoft\\AppV\\Client\\Integration.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-integrationallowrootglobal"],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootglobal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootglobal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootglobal_integration_root_user_prompt","displayName":"Integration Root User","description":"","helpText":"","infoUrls":[],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootuser","displayName":"Integration Root Global","description":"Specifies the location where symbolic links are created to the current version of a globally published package. Shortcuts, file type associations, etc. are created pointing to this path. If empty, symbolic links are not used during publishing. Example: %allusersprofile%\\Microsoft\\AppV\\Client\\Integration.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-integrationallowrootuser"],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_integrationallowrootuser_integration_root_global_prompt","displayName":"Integration Root Global","description":"","helpText":"","infoUrls":[],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1","displayName":"Publishing Server 1 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver1"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_publishing_refresh_options","displayName":"Global Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_interval_prompt","displayName":"Global Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_onlogon_options","displayName":"Global Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_unit_options","displayName":"Global Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_global_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_publishing_server1_name_prompt","displayName":"Publishing Server Display Name","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_onlogon_options","displayName":"User Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_unit_options","displayName":"User Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2","displayName":"Publishing Server 2 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver2"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_publishing_refresh_options","displayName":"Global Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_interval_prompt","displayName":"Global Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_onlogon_options","displayName":"Global Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_unit_options","displayName":"Global Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_global_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_publishing_server2_name_prompt","displayName":"Publishing Server Display Name","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_onlogon_options","displayName":"User Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_unit_options","displayName":"User Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver2_user_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3","displayName":"Publishing Server 3 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver3"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_publishing_refresh_options","displayName":"Global Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_interval_prompt","displayName":"Global Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_onlogon_options","displayName":"Global Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_unit_options","displayName":"Global Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_publishing_server3_name_prompt","displayName":"Publishing Server Display Name","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_onlogon_options","displayName":"User Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_unit_options","displayName":"User Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4","displayName":"Publishing Server 4 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver4"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_publishing_refresh_options","displayName":"Global Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_interval_prompt","displayName":"Global Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_onlogon_options","displayName":"Global Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_unit_options","displayName":"Global Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_global_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_publishing_server4_name_prompt","displayName":"Publishing Server Display Name","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_onlogon_options","displayName":"User Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_unit_options","displayName":"User Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5","displayName":"Publishing Server 5 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver5"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_publishing_refresh_options","displayName":"Global Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_interval_prompt","displayName":"Global Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_onlogon_options","displayName":"Global Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_unit_options","displayName":"Global Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_publishing_server5_name_prompt","displayName":"Publishing Server Display Name","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_onlogon_options","displayName":"User Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_unit_options","displayName":"User Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_user_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl","displayName":"Certificate Filter For Client SSL","description":"Specifies the path to a valid certificate in the certificate store.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowcertificatefilterforclient-ssl"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl_streaming_certificate_filter_for_client_ssl_prompt","displayName":"Certificate Filter For Client SSL","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowhighcostlaunch","displayName":"Allow First Time Application Launches if on a High Cost Windows 8 Metered Connection","description":"This setting controls whether virtualized applications are launched on Windows 8 machines connected via a metered network connection (e.g. 4G).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowhighcostlaunch"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowhighcostlaunch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowhighcostlaunch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowlocationprovider","displayName":"Location Provider","description":"Specifies the CLSID for a compatible implementation of the IAppvPackageLocationProvider interface.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowlocationprovider"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowlocationprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowlocationprovider_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowlocationprovider_streaming_location_provider_prompt","displayName":"Location Provider","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackageinstallationroot","displayName":"Package Installation Root","description":"Specifies directory where all new applications and updates will be installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowpackageinstallationroot"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackageinstallationroot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackageinstallationroot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackageinstallationroot_streaming_package_installation_root_prompt","displayName":"Package Installation Root","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackagesourceroot","displayName":"Package Source Root","description":"Overrides source location for downloading package content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowpackagesourceroot"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackagesourceroot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackagesourceroot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackagesourceroot_package_source_root_prompt","displayName":"Package Source Root","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentinterval","displayName":"Reestablishment Interval","description":"Specifies the number of seconds between attempts to reestablish a dropped session.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowreestablishmentinterval"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentinterval_streaming_reestablishment_interval_prompt","displayName":"Reestablishment Interval:","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries","displayName":"Reestablishment Retries","description":"Specifies the number of times to retry a dropped session.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowreestablishmentretries"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries_streaming_reestablishment_retries_prompt","displayName":"Reestablishment Retries:","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingsharedcontentstoremode","displayName":"Shared Content Store (SCS) mode","description":"Specifies that streamed package contents will be not be saved to the local hard disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingsharedcontentstoremode"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingsharedcontentstoremode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingsharedcontentstoremode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingsupportbranchcache","displayName":"Enable Support for BranchCache","description":"If enabled, the App-V client will support BrancheCache compatible HTTP streaming. If BranchCache support is not desired, this should be disabled. The client can then apply HTTP optimizations which are incompatible with BranchCache","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingsupportbranchcache"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingsupportbranchcache_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingsupportbranchcache_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingverifycertificaterevocationlist","displayName":"Verify certificate revocation list","description":"Verifies Server certificate revocation status before streaming using HTTPS.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingverifycertificaterevocationlist"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingverifycertificaterevocationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingverifycertificaterevocationlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_virtualcomponentsallowlist","displayName":"Virtual Component Process Allow List","description":"Specifies a list of process paths (may contain wildcards) which are candidates for using virtual components (shell extensions, browser helper objects, etc). Only processes whose full path matches one of these items can use virtual components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-virtualcomponentsallowlist"],"categoryId":"10835ce3-31c8-4ec6-aa00-c5af48e550a8","categoryName":"Virtualization","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_virtualcomponentsallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_virtualcomponentsallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_appvirtualization_virtualcomponentsallowlist_virtualization_jitvallowlist_prompt","displayName":"Virtual Component Process Allow List","description":"","helpText":"","infoUrls":[],"categoryId":"10835ce3-31c8-4ec6-aa00-c5af48e550a8","categoryName":"Virtualization","options":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation","displayName":"Account Logon Audit Credential Validation","description":"This policy setting allows you to audit events generated by validation tests on user account logon credentials. Events in this subcategory occur only on the computer that is authoritative for those credentials. For domain accounts, the domain controller is authoritative. For local accounts, the local computer is authoritative.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogon_auditcredentialvalidation"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosauthenticationservice","displayName":"Account Logon Audit Kerberos Authentication Service","description":"This policy setting allows you to audit events generated by Kerberos authentication ticket-granting ticket (TGT) requests. If you configure this policy setting, an audit event is generated after a Kerberos authentication TGT request. Success audits record successful requests and Failure audits record unsuccessful requests. If you do not configure this policy setting, no audit event is generated after a Kerberos authentication TGT request.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogon_auditkerberosauthenticationservice"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosauthenticationservice_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosauthenticationservice_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosauthenticationservice_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosauthenticationservice_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosserviceticketoperations","displayName":"Account Logon Audit Kerberos Service Ticket Operations","description":"This policy setting allows you to audit events generated by Kerberos authentication ticket-granting ticket (TGT) requests submitted for user accounts. If you configure this policy setting, an audit event is generated after a Kerberos authentication TGT is requested for a user account. Success audits record successful requests and Failure audits record unsuccessful requests. If you do not configure this policy setting, no audit event is generated after a Kerberos authentication TGT is request for a user account.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogon_auditkerberosserviceticketoperations"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosserviceticketoperations_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosserviceticketoperations_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosserviceticketoperations_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditkerberosserviceticketoperations_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditotheraccountlogonevents","displayName":"Account Logon Audit Other Account Logon Events","description":"This policy setting allows you to audit events generated by responses to credential requests submitted for a user account logon that are not credential validation or Kerberos tickets. Currently, there are no events in this subcategory.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogon_auditotheraccountlogonevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditotheraccountlogonevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditotheraccountlogonevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditotheraccountlogonevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditotheraccountlogonevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout","displayName":"Account Logon Logoff Audit Account Lockout","description":"This policy setting allows you to audit events generated by a failed attempt to log on to an account that is locked out. If you configure this policy setting, an audit event is generated when an account cannot log on to a computer because the account is locked out. Success audits record successful attempts and Failure audits record unsuccessful attempts. Logon events are essential for understanding user activity and to detect potential attacks.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditaccountlockout"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership","displayName":"Account Logon Logoff Audit Group Membership","description":"This policy allows you to audit the group memberhsip information in the user's logon token. Events in this subcategory are generated on the computer on which a logon session is created. For an interactive logon, the security audit event is generated on the computer that the user logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the computer hosting the resource. When this setting is configured, one or more security audit events are generated for each successful logon. You must also enable the Audit Logon setting under Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff. Multiple events are generated if the group memberhsip information cannot fit in a single security audit event.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditgroupmembership"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecextendedmode","displayName":"Account Logon Logoff Audit I Psec Extended Mode","description":"This policy setting allows you to audit events generated by Internet Key Exchange protocol (IKE) and Authenticated Internet Protocol (AuthIP) during Extended Mode negotiations. If you configure this policy setting, an audit event is generated during an IPsec Extended Mode negotiation. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated during an IPsec Extended Mode negotiation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditipsecextendedmode"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecextendedmode_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecextendedmode_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecextendedmode_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecextendedmode_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecmainmode","displayName":"Account Logon Logoff Audit I Psec Main Mode","description":"This policy setting allows you to audit events generated by Internet Key Exchange protocol (IKE) and Authenticated Internet Protocol (AuthIP) during Main Mode negotiations. If you configure this policy setting, an audit event is generated during an IPsec Main Mode negotiation. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated during an IPsec Main Mode negotiation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditipsecmainmode"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecmainmode_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecmainmode_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecmainmode_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecmainmode_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode","displayName":"Account Logon Logoff Audit I Psec Quick Mode","description":"This policy setting allows you to audit events generated by Internet Key Exchange protocol (IKE) and Authenticated Internet Protocol (AuthIP) during Quick Mode negotiations. If you configure this policy setting, an audit event is generated during an IPsec Quick Mode negotiation. Success audits record successful attempts and Failure audits record unsuccessful attempts.If you do not configure this policy setting, no audit event is generated during an IPsec Quick Mode negotiation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditipsecquickmode"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogoff","displayName":"Account Logon Logoff Audit Logoff","description":"This policy setting allows you to audit events generated by the closing of a logon session. These events occur on the computer that was accessed. For an interactive logoff the security audit event is generated on the computer that the user account logged on to. If you configure this policy setting, an audit event is generated when a logon session is closed. Success audits record successful attempts to close sessions and Failure audits record unsuccessful attempts to close sessions. If you do not configure this policy setting, no audit event is generated when a logon session is closed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditlogoff"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogoff_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogoff_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogoff_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogoff_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogon","displayName":"Account Logon Logoff Audit Logon","description":"This policy setting allows you to audit events generated by user account logon attempts on the computer. Events in this subcategory are related to the creation of logon sessions and occur on the computer which was accessed. For an interactive logon, the security audit event is generated on the computer that the user account logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the computer hosting the resource. The following events are included: Successful logon attempts. Failed logon attempts. Logon attempts using explicit credentials. This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch logon configurations, such as scheduled tasks or when using the RUNAS command. Security identifiers (SIDs) were filtered and not allowed to log on.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditlogon"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogon_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogon_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogon_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditlogon_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditnetworkpolicyserver","displayName":"Account Logon Logoff Audit Network Policy Server","description":"This policy setting allows you to audit events generated by RADIUS (IAS) and Network Access Protection (NAP) user access requests. These requests can be Grant, Deny, Discard, Quarantine, Lock, and Unlock. If you configure this policy setting, an audit event is generated for each IAS and NAP user access request. Success audits record successful user access requests and Failure audits record unsuccessful attempts. If you do not configure this policy settings, IAS and NAP user access requests are not audited.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditnetworkpolicyserver"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditnetworkpolicyserver_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditnetworkpolicyserver_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditnetworkpolicyserver_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditnetworkpolicyserver_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditotherlogonlogoffevents","displayName":"Audit Other Logon Logoff Events","description":"This policy setting allows you to audit other logon/logoff-related events that are not covered in the “Logon/Logoff” policy setting such as the following: Terminal Services session disconnections. New Terminal Services sessions. Locking and unlocking a workstation. Invoking a screen saver. Dismissal of a screen saver. Detection of a Kerberos replay attack, in which a Kerberos request was received twice with identical information. This condition could be caused by network misconfiguration. Access to a wireless network granted to a user or computer account. Access to a wired 802.1x network granted to a user or computer account.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditotherlogonlogoffevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditotherlogonlogoffevents_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditotherlogonlogoffevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditotherlogonlogoffevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditotherlogonlogoffevents_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon","displayName":"Audit Special Logon","description":"This policy setting allows you to audit events generated by special logons such as the following : The use of a special logon, which is a logon that has administrator-equivalent privileges and can be used to elevate a process to a higher level. A logon by a member of a Special Group. Special Groups enable you to audit events generated when a member of a certain group has logged on to your network. You can configure a list of group security identifiers (SIDs) in the registry. If any of those SIDs are added to a token during logon and the subcategory is enabled, an event is logged. For more information about this feature, see article 947223 in the Microsoft Knowledge Base (https://go.microsoft.com/fwlink/?LinkId=121697).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditspeciallogon"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_audituserdeviceclaims","displayName":"Account Logon Logoff Audit User Device Claims","description":"This policy allows you to audit user and device claims information in the user's logon token. Events in this subcategory are generated on the computer on which a logon session is created. For an interactive logon, the security audit event is generated on the computer that the user logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the computer hosting the resource. User claims are added to a logon token when claims are included with a user's account attributes in Active Directory. Device claims are added to the logon token when claims are included with a device's computer account attributes in Active Directory. In addition, compound identity must be enabled for the domain and on the computer where the user logged on. When this setting is configured, one or more security audit events are generated for each successful logon. You must also enable the Audit Logon setting under Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff. Multiple events are generated if the user and device claims information cannot fit in a single security audit event.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_audituserdeviceclaims"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_audituserdeviceclaims_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_audituserdeviceclaims_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_audituserdeviceclaims_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_audituserdeviceclaims_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditapplicationgroupmanagement","displayName":"Account Management Audit Application Group Management","description":"This policy setting allows you to audit events generated by changes to application groups such as the following: Application group is created, changed, or deleted. Member is added or removed from an application group. If you configure this policy setting, an audit event is generated when an attempt to change an application group is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an application group changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountmanagement_auditapplicationgroupmanagement"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditapplicationgroupmanagement_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditapplicationgroupmanagement_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditapplicationgroupmanagement_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditapplicationgroupmanagement_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditcomputeraccountmanagement","displayName":"Account Management Audit Computer Account Management","description":"This policy setting allows you to audit events generated by changes to computer accounts such as when a computer account is created, changed, or deleted. If you configure this policy setting, an audit event is generated when an attempt to change a computer account is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a computer account changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountmanagement_auditcomputeraccountmanagement"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditcomputeraccountmanagement_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditcomputeraccountmanagement_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditcomputeraccountmanagement_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditcomputeraccountmanagement_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditdistributiongroupmanagement","displayName":"Account Management Audit Distribution Group Management","description":"This policy setting allows you to audit events generated by changes to distribution groups such as the following: Distribution group is created, changed, or deleted. Member is added or removed from a distribution group. Distribution group type is changed. If you configure this policy setting, an audit event is generated when an attempt to change a distribution group is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a distribution group changes. Note: Events in this subcategory are logged only on domain controllers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountmanagement_auditdistributiongroupmanagement"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditdistributiongroupmanagement_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditdistributiongroupmanagement_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditdistributiongroupmanagement_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditdistributiongroupmanagement_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditotheraccountmanagementevents","displayName":"Account Management Audit Other Account Management Events","description":"This policy setting allows you to audit events generated by other user account changes that are not covered in this category, such as the following: The password hash of a user account was accessed. This typically happens during an Active Directory Management Tool password migration. The Password Policy Checking API was called. Calls to this function can be part of an attack when a malicious application tests the policy to reduce the number of attempts during a password dictionary attack. Changes to the Default Domain Group Policy under the following Group Policy paths: Computer Configuration\\Windows Settings\\Security Settings\\Account Policies\\Password Policy Computer Configuration\\Windows Settings\\Security Settings\\Account Policies\\Account Lockout Policy","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountmanagement_auditotheraccountmanagementevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditotheraccountmanagementevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditotheraccountmanagementevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditotheraccountmanagementevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditotheraccountmanagementevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditsecuritygroupmanagement","displayName":"Audit Security Group Management","description":"This policy setting allows you to audit events generated by changes to security groups such as the following: Security group is created, changed, or deleted. Member is added or removed from a security group. Group type is changed. If you configure this policy setting, an audit event is generated when an attempt to change a security group is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a security group changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountmanagement_auditsecuritygroupmanagement"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditsecuritygroupmanagement_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditsecuritygroupmanagement_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditsecuritygroupmanagement_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_auditsecuritygroupmanagement_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_audituseraccountmanagement","displayName":"Audit User Account Management","description":"This policy setting allows you to audit changes to user accounts. Events include the following: A user account is created, changed, deleted; renamed, disabled, enabled, locked out, or unlocked. A user account’s password is set or changed. A security identifier (SID) is added to the SID History of a user account. The Directory Services Restore Mode password is configured. Permissions on administrative user accounts are changed. Credential Manager credentials are backed up or restored. If you configure this policy setting, an audit event is generated when an attempt to change a user account is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a user account changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountmanagement_audituseraccountmanagement"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountmanagement_audituseraccountmanagement_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_audituseraccountmanagement_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_audituseraccountmanagement_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountmanagement_audituseraccountmanagement_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity","displayName":"Detailed Tracking Audit DPAPI Activity","description":"This policy setting allows you to audit events generated when encryption or decryption requests are made to the Data Protection application interface (DPAPI). DPAPI is used to protect secret information such as stored password and key information. For more information about DPAPI, see https://go.microsoft.com/fwlink/?LinkId=121720. If you configure this policy setting, an audit event is generated when an encryption or decryption request is made to DPAPI. Success audits record successful requests and Failure audits record unsuccessful requests. If you do not configure this policy setting, no audit event is generated when an encryption or decryption request is made to DPAPI.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditdpapiactivity"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity","displayName":"Detailed Tracking Audit PNP Activity","description":"This policy setting allows you to audit when plug and play detects an external device. If you configure this policy setting, an audit event is generated whenever plug and play detects an external device. Only Success audits are recorded for this category. If you do not configure this policy setting, no audit event is generated when an external device is detected by plug and play.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditpnpactivity"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation","displayName":"Detailed Tracking Audit Process Creation","description":"This policy setting allows you to audit events generated when a process is created or starts. The name of the application or user that created the process is also audited. If you configure this policy setting, an audit event is generated when a process is created. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a process is created.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditprocesscreation"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination","displayName":"Detailed Tracking Audit Process Termination","description":"This policy setting allows you to audit events generated when a process ends. If you configure this policy setting, an audit event is generated when a process ends. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a process ends.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditprocesstermination"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents","displayName":"Detailed Tracking Audit RPC Events","description":"This policy setting allows you to audit inbound remote procedure call (RPC) connections. If you configure this policy setting, an audit event is generated when a remote RPC connection is attempted. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a remote RPC connection is attempted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditrpcevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted","displayName":"Detailed Tracking Audit Token Right Adjusted","description":"This policy setting allows you to audit events generated by adjusting the privileges of a token.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_audittokenrightadjusted"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdetaileddirectoryservicereplication","displayName":"DS Access Audit Detailed Directory Service Replication","description":"This policy setting allows you to audit events generated by detailed Active Directory Domain Services (AD DS) replication between domain controllers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#dsaccess_auditdetaileddirectoryservicereplication"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdetaileddirectoryservicereplication_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdetaileddirectoryservicereplication_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdetaileddirectoryservicereplication_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdetaileddirectoryservicereplication_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryserviceaccess","displayName":"DS Access Audit Directory Service Access","description":"This policy setting allows you to audit events generated when an Active Directory Domain Services (AD DS) object is accessed. Only AD DS objects with a matching system access control list (SACL) are logged. Events in this subcategory are similar to the Directory Service Access events available in previous versions of Windows.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#dsaccess_auditdirectoryserviceaccess"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryserviceaccess_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryserviceaccess_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryserviceaccess_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryserviceaccess_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicechanges","displayName":"Audit Directory Service Changes","description":"This policy setting allows you to audit events generated by changes to objects in Active Directory Domain Services (AD DS). Events are logged when an object is created, deleted, modified, moved, or undeleted. When possible, events logged in this subcategory indicate the old and new values of the object’s properties. Events in this subcategory are logged only on domain controllers, and only objects in AD DS with a matching system access control list (SACL) are logged. Note: Actions on some objects and properties do not cause audit events to be generated due to settings on the object class in the schema. If you configure this policy setting, an audit event is generated when an attempt to change an object in AD DS is made. Success audits record successful attempts, however unsuccessful attempts are NOT recorded. If you do not configure this policy setting, no audit event is generated when an attempt to change an object in AD DS object is made.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#dsaccess_auditdirectoryservicechanges"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicechanges_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicechanges_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicechanges_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicechanges_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicereplication","displayName":"DS Access Audit Directory Service Replication","description":"This policy setting allows you to audit replication between two Active Directory Domain Services (AD DS) domain controllers. If you configure this policy setting, an audit event is generated during AD DS replication. Success audits record successful replication and Failure audits record unsuccessful replication. If you do not configure this policy setting, no audit event is generated during AD DS replication.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#dsaccess_auditdirectoryservicereplication"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicereplication_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicereplication_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicereplication_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_dsaccess_auditdirectoryservicereplication_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditapplicationgenerated","displayName":"Object Access Audit Application Generated","description":"This policy setting allows you to audit applications that generate events using the Windows Auditing application programming interfaces (APIs). Applications designed to use the Windows Auditing API use this subcategory to log auditing events related to their function. Events in this subcategory include: Creation of an application client context. Deletion of an application client context. Initialization of an application client context. Other application operations using the Windows Auditing APIs.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditapplicationgenerated"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditapplicationgenerated_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditapplicationgenerated_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditapplicationgenerated_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditapplicationgenerated_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcentralaccesspolicystaging","displayName":"Object Access Audit Central Access Policy Staging","description":"This policy setting allows you to audit access requests where the permission granted or denied by a proposed policy differs from the current central access policy on an object. If you configure this policy setting, an audit event is generated each time a user accesses an object and the permission granted by the current central access policy on the object differs from that granted by the proposed policy. The resulting audit event will be generated as follows: 1) Success audits, when configured, records access attempts when the current central access policy grants access but the proposed policy denies access. 2) Failure audits when configured records access attempts when: a) The current central access policy does not grant access but the proposed policy grants access. b) A principal requests the maximum access rights they are allowed and the access rights granted by the current central access policy are different than the access rights granted by the proposed policy. Volume: Potentially high on a file server when the proposed policy differs significantly from the current central access policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditcentralaccesspolicystaging"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcentralaccesspolicystaging_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcentralaccesspolicystaging_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcentralaccesspolicystaging_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcentralaccesspolicystaging_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcertificationservices","displayName":"Object Access Audit Certification Services","description":"This policy setting allows you to audit Active Directory Certificate Services (AD CS) operations. AD CS operations include the following: AD CS startup/shutdown/backup/restore. Changes to the certificate revocation list (CRL). New certificate requests. Issuing of a certificate. Revocation of a certificate. Changes to the Certificate Manager settings for AD CS. Changes in the configuration of AD CS. Changes to a Certificate Services template. Importing of a certificate. Publishing of a certification authority certificate is to Active Directory Domain Services. Changes to the security permissions for AD CS. Archival of a key. Importing of a key. Retrieval of a key. Starting of Online Certificate Status Protocol (OCSP) Responder Service. Stopping of Online Certificate Status Protocol (OCSP) Responder Service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditcertificationservices"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcertificationservices_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcertificationservices_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcertificationservices_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditcertificationservices_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditdetailedfileshare","displayName":"Object Access Audit Detailed File Share","description":"This policy setting allows you to audit attempts to access files and folders on a shared folder. The Detailed File Share setting logs an event every time a file or folder is accessed, whereas the File Share setting only records one event for any connection established between a client and file share. Detailed File Share audit events include detailed information about the permissions or other criteria used to grant or deny access. If you configure this policy setting, an audit event is generated when an attempt is made to access a file or folder on a share. The administrator can specify whether to audit only successes, only failures, or both successes and failures. Note: There are no system access control lists (SACLs) for shared folders. If this policy setting is enabled, access to all shared files and folders on the system is audited.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditdetailedfileshare"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditdetailedfileshare_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditdetailedfileshare_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditdetailedfileshare_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditdetailedfileshare_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare","displayName":"Audit File Share Access","description":"This policy setting allows you to audit attempts to access a shared folder. If you configure this policy setting, an audit event is generated when an attempt is made to access a shared folder. If this policy setting is defined, the administrator can specify whether to audit only successes, only failures, or both successes and failures. Note: There are no system access control lists (SACLs) for shared folders. If this policy setting is enabled, access to all shared folders on the system is audited.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditfileshare"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilesystem","displayName":"Object Access Audit File System","description":"This policy setting allows you to audit user attempts to access file system objects. A security audit event is generated only for objects that have system access control lists (SACL) specified, and only if the type of access requested, such as Write, Read, or Modify and the account making the request match the settings in the SACL. For more information about enabling object access auditing, see https://go.microsoft.com/fwlink/?LinkId=122083. If you configure this policy setting, an audit event is generated each time an account accesses a file system object with a matching SACL. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an account accesses a file system object with a matching SACL. Note: You can set a SACL on a file system object using the Security tab in that object's Properties dialog box.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditfilesystem"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilesystem_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilesystem_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilesystem_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilesystem_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformconnection","displayName":"Object Access Audit Filtering Platform Connection","description":"This policy setting allows you to audit connections that are allowed or blocked by the Windows Filtering Platform (WFP). The following events are included: The Windows Firewall Service blocks an application from accepting incoming connections on the network. The WFP allows a connection. The WFP blocks a connection. The WFP permits a bind to a local port. The WFP blocks a bind to a local port. The WFP allows a connection. The WFP blocks a connection. The WFP permits an application or service to listen on a port for incoming connections. The WFP blocks an application or service to listen on a port for incoming connections. If you configure this policy setting, an audit event is generated when connections are allowed or blocked by the WFP. Success audits record events generated when connections are allowed and Failure audits record events generated when connections are blocked. If you do not configure this policy setting, no audit event is generated when connected are allowed or blocked by the WFP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditfilteringplatformconnection"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformconnection_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformconnection_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformconnection_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformconnection_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformpacketdrop","displayName":"Object Access Audit Filtering Platform Packet Drop","description":"This policy setting allows you to audit packets that are dropped by Windows Filtering Platform (WFP).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditfilteringplatformpacketdrop"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformpacketdrop_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformpacketdrop_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformpacketdrop_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfilteringplatformpacketdrop_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_audithandlemanipulation","displayName":"Object Access Audit Handle Manipulation","description":"This policy setting allows you to audit events generated when a handle to an object is opened or closed. Only objects with a matching system access control list (SACL) generate security audit events. If you configure this policy setting, an audit event is generated when a handle is manipulated. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a handle is manipulated. Note: Events in this subcategory generate events only for object types where the corresponding Object Access subcategory is enabled. For example, if File system object access is enabled, handle manipulation security audit events are generated. If Registry object access is not enabled, handle manipulation security audit events will not be generated.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_audithandlemanipulation"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_audithandlemanipulation_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_audithandlemanipulation_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_audithandlemanipulation_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_audithandlemanipulation_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject","displayName":"Object Access Audit Kernel Object","description":"This policy setting allows you to audit attempts to access the kernel, which include mutexes and semaphores. Only kernel objects with a matching system access control list (SACL) generate security audit events. Note: The Audit: Audit the access of global system objects policy setting controls the default SACL of kernel objects.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditkernelobject"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents","displayName":"Object Access Audit Other Object Access Events","description":"This policy setting allows you to audit events generated by the management of task scheduler jobs or COM+ objects. For scheduler jobs, the following are audited: Job created. Job deleted. Job enabled. Job disabled. Job updated. For COM+ objects, the following are audited: Catalog object added. Catalog object updated. Catalog object deleted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditotherobjectaccessevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry","displayName":"Object Access Audit Registry","description":"This policy setting allows you to audit attempts to access registry objects. A security audit event is generated only for objects that have system access control lists (SACLs) specified, and only if the type of access requested, such as Read, Write, or Modify, and the account making the request match the settings in the SACL. If you configure this policy setting, an audit event is generated each time an account accesses a registry object with a matching SACL. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an account accesses a registry object with a matching SACL. Note: You can set a SACL on a registry object using the Permissions dialog box.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditregistry"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditremovablestorage","displayName":"Object Access Audit Removable Storage","description":"This policy setting allows you to audit user attempts to access file system objects on a removable storage device. A security audit event is generated only for all objects for all types of access requested. If you configure this policy setting, an audit event is generated each time an account accesses a file system object on a removable storage. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an account accesses a file system object on a removable storage.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditremovablestorage"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditremovablestorage_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditremovablestorage_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditremovablestorage_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditremovablestorage_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam","displayName":"Object Access Audit SAM","description":"This policy setting allows you to audit events generated by attempts to access to Security Accounts Manager (SAM) objects. SAM objects include the following: SAM_ALIAS -- A local group. SAM_GROUP -- A group that is not a local group. SAM_USER – A user account. SAM_DOMAIN – A domain. SAM_SERVER – A computer account. If you configure this policy setting, an audit event is generated when an attempt to access a kernel object is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an attempt to access a kernel object is made. Note: Only the System Access Control List (SACL) for SAM_SERVER can be modified. Volume: High on domain controllers. For information about reducing the amount of events generated in this subcategory, see article 841001 in the Microsoft Knowledge Base (https://go.microsoft.com/fwlink/?LinkId=121698).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditsam"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange","displayName":"Audit Authentication Policy Change","description":"This policy setting allows you to audit events generated by changes to the authentication policy such as the following: Creation of forest and domain trusts. Modification of forest and domain trusts. Removal of forest and domain trusts. Changes to Kerberos policy under Computer Configuration\\Windows Settings\\Security Settings\\Account Policies\\Kerberos Policy. Granting of any of the following user rights to a user or group: Access This Computer From the Network. Allow Logon Locally. Allow Logon Through Terminal Services. Logon as a Batch Job. Logon a Service. Namespace collision. For example, when a new trust has the same name as an existing namespace name. If you configure this policy setting, an audit event is generated when an attempt to change the authentication policy is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when the authentication policy is changed. Note: The security audit event is logged when the group policy is applied. It does not occur at the time when the settings are modified.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditauthenticationpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthorizationpolicychange","displayName":"Audit Authorization Policy Change","description":"This policy setting allows you to audit events generated by changes to the authorization policy such as the following: Assignment of user rights (privileges), such as SeCreateTokenPrivilege, that are not audited through the “Authentication Policy Change” subcategory. Removal of user rights (privileges), such as SeCreateTokenPrivilege, that are not audited through the “Authentication Policy Change” subcategory. Changes in the Encrypted File System (EFS) policy. Changes to the Resource attributes of an object. Changes to the Central Access Policy (CAP) applied to an object. If you configure this policy setting, an audit event is generated when an attempt to change the authorization policy is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when the authorization policy changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditauthorizationpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthorizationpolicychange_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthorizationpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthorizationpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthorizationpolicychange_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_policychange_auditfilteringplatformpolicychange","displayName":"Policy Change Audit Filtering Platform Policy Change","description":"This policy setting allows you to audit events generated by changes to the Windows Filtering Platform (WFP) such as the following: IPsec services status. Changes to IPsec policy settings. Changes to Windows Firewall policy settings. Changes to WFP providers and engine. If you configure this policy setting, an audit event is generated when a change to the WFP is attempted. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a change occurs to the WFP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditfilteringplatformpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditfilteringplatformpolicychange_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditfilteringplatformpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditfilteringplatformpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditfilteringplatformpolicychange_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_policychange_auditmpssvcrulelevelpolicychange","displayName":"Policy Change Audit MPSSVC Rule Level Policy Change","description":"This policy setting allows you to audit events generated by changes in policy rules used by the Microsoft Protection Service (MPSSVC). This service is used by Windows Firewall. Events include the following: Reporting of active policies when Windows Firewall service starts. Changes to Windows Firewall rules. Changes to Windows Firewall exception list. Changes to Windows Firewall settings. Rules ignored or not applied by Windows Firewall Service. Changes to Windows Firewall Group Policy settings. If you configure this policy setting, an audit event is generated by attempts to change policy rules used by the MPSSVC. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated by changes in policy rules used by the MPSSVC.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditmpssvcrulelevelpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditmpssvcrulelevelpolicychange_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditmpssvcrulelevelpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditmpssvcrulelevelpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditmpssvcrulelevelpolicychange_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_policychange_auditotherpolicychangeevents","displayName":"Policy Change Audit Other Policy Change Events","description":"This policy setting allows you to audit events generated by other security policy changes that are not audited in the policy change category, such as the following: Trusted Platform Module (TPM) configuration changes. Kernel-mode cryptographic self tests. Cryptographic provider operations. Cryptographic context operations or modifications. Applied Central Access Policies (CAPs) changes. Boot Configuration Data (BCD) modifications.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditotherpolicychangeevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditotherpolicychangeevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditotherpolicychangeevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditotherpolicychangeevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditotherpolicychangeevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange","displayName":"Audit Changes to Audit Policy","description":"This policy setting allows you to audit changes in the security audit policy settings such as the following: Settings permissions and audit settings on the Audit Policy object. Changes to the system audit policy. Registration of security event sources. De-registration of security event sources. Changes to the per-user audit settings. Changes to the value of CrashOnAuditFail. Changes to the system access control list on a file system or registry object. Changes to the Special Groups list. Note: System access control list (SACL) change auditing is done when a SACL for an object changes and the policy change category is enabled. Discretionary access control list (DACL) and ownership changes are audited when object access auditing is enabled and the object's SACL is configured for auditing of DACL/Owner change.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditnonsensitiveprivilegeuse","displayName":"Privilege Use Audit Non Sensitive Privilege Use","description":"This policy setting allows you to audit events generated by the use of non-sensitive privileges (user rights). The following privileges are non-sensitive: Access Credential Manager as a trusted caller. Access this computer from the network. Add workstations to domain. Adjust memory quotas for a process. Allow log on locally. Allow log on through Terminal Services. Bypass traverse checking. Change the system time. Create a pagefile. Create global objects. Create permanent shared objects. Create symbolic links. Deny access this computer from the network. Deny log on as a batch job. Deny log on as a service. Deny log on locally. Deny log on through Terminal Services. Force shutdown from a remote system. Increase a process working set. Increase scheduling priority. Lock pages in memory. Log on as a batch job. Log on as a service. Modify an object label. Perform volume maintenance tasks. Profile single process. Profile system performance. Remove computer from docking station. Shut down the system. Synchronize directory service data. If you configure this policy setting, an audit event is generated when a non-sensitive privilege is called. Success audits record successful calls and Failure audits record unsuccessful calls. If you do not configure this policy setting, no audit event is generated when a non-sensitive privilege is called.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#privilegeuse_auditnonsensitiveprivilegeuse"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditnonsensitiveprivilegeuse_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditnonsensitiveprivilegeuse_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditnonsensitiveprivilegeuse_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditnonsensitiveprivilegeuse_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditotherprivilegeuseevents","displayName":"Privilege Use Audit Other Privilege Use Events","description":"Not used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#privilegeuse_auditotherprivilegeuseevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditotherprivilegeuseevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditotherprivilegeuseevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditotherprivilegeuseevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditotherprivilegeuseevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse","displayName":"Privilege Use Audit Sensitive Privilege Use","description":"This policy setting allows you to audit events generated when sensitive privileges (user rights) are used such as the following: A privileged service is called. One of the following privileges are called: Act as part of the operating system. Back up files and directories. Create a token object. Debug programs. Enable computer and user accounts to be trusted for delegation. Generate security audits. Impersonate a client after authentication. Load and unload device drivers. Manage auditing and security log. Modify firmware environment values. Replace a process-level token. Restore files and directories. Take ownership of files or other objects. If you configure this policy setting, an audit event is generated when sensitive privilege requests are made. Success audits record successful requests and Failure audits record unsuccessful requests. If you do not configure this policy setting, no audit event is generated when sensitive privilege requests are made. ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#privilegeuse_auditsensitiveprivilegeuse"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver","displayName":"System Audit I Psec Driver","description":"This policy setting allows you to audit events generated by the IPsec filter driver such as the following: Startup and shutdown of the IPsec services. Network packets dropped due to integrity check failure. Network packets dropped due to replay check failure. Network packets dropped due to being in plaintext. Network packets received with incorrect Security Parameter Index (SPI). This may indicate that either the network card is not working correctly or the driver needs to be updated. Inability to process IPsec filters. If you configure this policy setting, an audit event is generated on an IPsec filter driver operation. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated on an IPSec filter driver operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditipsecdriver"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_system_auditothersystemevents","displayName":"System Audit Other System Events","description":"This policy setting allows you to audit any of the following events: Startup and shutdown of the Windows Firewall service and driver. Security policy processing by the Windows Firewall Service. Cryptography key file and migration operations.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditothersystemevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditothersystemevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditothersystemevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditothersystemevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditothersystemevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritystatechange","displayName":"System Audit Security State Change","description":"This policy setting allows you to audit events generated by changes in the security state of the computer such as the following events: Startup and shutdown of the computer. Change of system time. Recovering the system from CrashOnAuditFail, which is logged after a system restarts when the security event log is full and the CrashOnAuditFail registry entry is configured.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditsecuritystatechange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritystatechange_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritystatechange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritystatechange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritystatechange_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension","displayName":"Audit Security System Extension","description":"This policy setting allows you to audit events related to security system extensions or services such as the following: A security system extension, such as an authentication, notification, or security package is loaded and is registered with the Local Security Authority (LSA). It is used to authenticate logon attempts, submit logon requests, and any account or password changes. Examples of security system extensions are Kerberos and NTLM. A service is installed and registered with the Service Control Manager. The audit log contains information about the service name, binary, type, start type, and service account. If you configure this policy setting, an audit event is generated when an attempt is made to load a security system extension. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an attempt is made to load a security system extension.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditsecuritysystemextension"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_audit_system_auditsystemintegrity","displayName":"System Audit System Integrity","description":"This policy setting allows you to audit events that violate the integrity of the security subsystem, such as the following: Events that could not be written to the event log because of a problem with the auditing system. A process that uses a local procedure call (LPC) port that is not valid in an attempt to impersonate a client by replying, reading, or writing to or from a client address space. The detection of a Remote Procedure Call (RPC) that compromises system integrity. The detection of a hash value of an executable file that is not valid as determined by Code Integrity. Cryptographic operations that compromise system integrity.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditsystemintegrity"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditsystemintegrity_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsystemintegrity_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsystemintegrity_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsystemintegrity_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_allowaadpasswordreset","displayName":"Allow Aad Password Reset","description":"Specifies whether password reset is enabled for AAD accounts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#allowaadpasswordreset"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":[{"id":"device_vendor_msft_policy_config_authentication_allowaadpasswordreset_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_allowaadpasswordreset_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_allowfastreconnect","displayName":"Allow Fast Reconnect","description":"Allows EAP Fast Reconnect from being attempted for EAP Method TLS. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#allowfastreconnect"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":[{"id":"device_vendor_msft_policy_config_authentication_allowfastreconnect_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_allowfastreconnect_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_allowsecondaryauthenticationdevice","displayName":"Allow Secondary Authentication Device","description":"Allows secondary authentication devices to work with Windows. The default for this policy must be on for consumer devices (defined as local or Microsoft account connected device) and off for enterprise devices (such as cloud domain-joined, cloud domain-joined in an on-premises only environment, cloud domain-joined in a hybrid environment, and BYOD). In the next major release of Windows 10, the default for this policy for consumer devices will be changed to off. This will only affect users that have not already set up a secondary authentication device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#allowsecondaryauthenticationdevice"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":[{"id":"device_vendor_msft_policy_config_authentication_allowsecondaryauthenticationdevice_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_allowsecondaryauthenticationdevice_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_configurewebcamaccessdomainnames","displayName":"Configure Webcam Access Domain Names","description":"Specifies a list of domains that are allowed to access the webcam in Web Sign-in based authentication scenarios.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#configurewebcamaccessdomainnames"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":null},{"id":"device_vendor_msft_policy_config_authentication_configurewebsigninallowedurls","displayName":"Configure Web Sign In Allowed Urls","description":"Specifies a list of URLs that are navigable in Web Sign-in based authentication scenarios.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#configurewebsigninallowedurls"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":null},{"id":"device_vendor_msft_policy_config_authentication_enablefastfirstsignin","displayName":"Enable Fast First Sign In","description":"Specifies whether new non-admin AAD accounts should auto-connect to pre-created candidate local accounts","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#enablefastfirstsignin"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":[{"id":"device_vendor_msft_policy_config_authentication_enablefastfirstsignin_0","displayName":"The feature defaults to the existing SKU and device capabilities.","description":"The feature defaults to the existing SKU and device capabilities.","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_enablefastfirstsignin_1","displayName":"Enabled. Auto-connect new non-admin Azure AD accounts to pre-configured candidate local accounts","description":"Enabled. Auto-connect new non-admin Azure AD accounts to pre-configured candidate local accounts","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_enablefastfirstsignin_2","displayName":"Disabled. Do not auto-connect new non-admin Azure AD accounts to pre-configured local accounts","description":"Disabled. Do not auto-connect new non-admin Azure AD accounts to pre-configured local accounts","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_enablepasswordlessexperience","displayName":"Enable Passwordless Experience","description":"Specifies whether connected users on AADJ devices receive a Passwordless experience on Windows\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#enablepasswordlessexperience"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":[{"id":"device_vendor_msft_policy_config_authentication_enablepasswordlessexperience_0","displayName":"The feature defaults to the existing edition and device capabilities.","description":"The feature defaults to the existing edition and device capabilities.","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_enablepasswordlessexperience_1","displayName":"Enabled. The Passwordless experience will be enabled on Windows","description":"Enabled. The Passwordless experience will be enabled on Windows","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_enablepasswordlessexperience_2","displayName":"Disabled. The Passwordless experience will not be enabled on Windows","description":"Disabled. The Passwordless experience will not be enabled on Windows","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_enablewebsignin","displayName":"Enable Web Sign In","description":"Specifies whether web-based sign-in is allowed for signing in to Windows","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#enablewebsignin"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":[{"id":"device_vendor_msft_policy_config_authentication_enablewebsignin_0","displayName":"The feature defaults to the existing SKU and device capabilities.","description":"The feature defaults to the existing SKU and device capabilities.","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_enablewebsignin_1","displayName":"Enabled. Web Sign-in will be enabled for signing in to Windows","description":"Enabled. Web Sign-in will be enabled for signing in to Windows","helpText":null},{"id":"device_vendor_msft_policy_config_authentication_enablewebsignin_2","displayName":"Disabled. Web Sign-in will not be enabled for signing in to Windows","description":"Disabled. Web Sign-in will not be enabled for signing in to Windows","helpText":null}]},{"id":"device_vendor_msft_policy_config_authentication_preferredaadtenantdomainname","displayName":"Preferred Aad Tenant Domain Name","description":"Specifies the preferred domain among available domains in the AAD tenant.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#preferredaadtenantdomainname"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":null},{"id":"device_vendor_msft_policy_config_autoplay_disallowautoplayfornonvolumedevices","displayName":"Disallow Autoplay for non-volume devices","description":"This policy setting disallows AutoPlay for MTP devices like cameras or phones.\n\n If you enable this policy setting, AutoPlay is not allowed for MTP devices like cameras or phones.\n\n If you disable or do not configure this policy setting, AutoPlay is enabled for non-volume devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-autoplay#autoplay-disallowautoplayfornonvolumedevices"],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"device_vendor_msft_policy_config_autoplay_disallowautoplayfornonvolumedevices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_autoplay_disallowautoplayfornonvolumedevices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior","displayName":"Set the default behavior for AutoRun","description":"This policy setting sets the default behavior for Autorun commands.\n\n Autorun commands are generally stored in autorun.inf files. They often launch the installation program or other routines.\n\n Prior to Windows Vista, when media containing an autorun command is inserted, the system will automatically execute the program without user intervention.\n\n This creates a major security concern as code may be executed without user's knowledge. The default behavior starting with Windows Vista is to prompt the user whether autorun command is to be run. The autorun command is represented as a handler in the Autoplay dialog.\n\n If you enable this policy setting, an Administrator can change the default Windows Vista or later behavior for autorun to:\n\n a) Completely disable autorun commands, or\n b) Revert back to pre-Windows Vista behavior of automatically executing the autorun command.\n\n If you disable or not configure this policy setting, Windows Vista or later will prompt the user whether autorun command is to be run.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-autoplay#autoplay-setdefaultautorunbehavior"],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_noautorun_dropdown","displayName":"Default AutoRun Behavior","description":"","helpText":"","infoUrls":[],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_noautorun_dropdown_1","displayName":"Do not execute any autorun commands","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_noautorun_dropdown_2","displayName":"Automatically execute autorun commands","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_autoplay_turnoffautoplay","displayName":"Turn off Autoplay","description":"This policy setting allows you to turn off the Autoplay feature.\n\n Autoplay begins reading from a drive as soon as you insert media in the drive. As a result, the setup file of programs and the music on audio media start immediately.\n\n Prior to Windows XP SP2, Autoplay is disabled by default on removable drives, such as the floppy disk drive (but not the CD-ROM drive), and on network drives.\n\n Starting with Windows XP SP2, Autoplay is enabled for removable drives as well, including Zip drives and some USB mass storage devices.\n\n If you enable this policy setting, Autoplay is disabled on CD-ROM and removable media drives, or disabled on all drives.\n\n This policy setting disables Autoplay on additional types of drives. You cannot use this setting to enable Autoplay on drives on which it is disabled by default.\n\n If you disable or do not configure this policy setting, AutoPlay is enabled.\n\n Note: This policy setting appears in both the Computer Configuration and User Configuration folders. If the policy settings conflict, the policy setting in Computer Configuration takes precedence over the policy setting in User Configuration.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-autoplay#autoplay-turnoffautoplay"],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"device_vendor_msft_policy_config_autoplay_turnoffautoplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_autoplay_turnoffautoplay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_autoplay_turnoffautoplay_autorun_box","displayName":"Turn off Autoplay on:","description":"","helpText":"","infoUrls":[],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"device_vendor_msft_policy_config_autoplay_turnoffautoplay_autorun_box_181","displayName":"CD-ROM and removable media drives","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_autoplay_turnoffautoplay_autorun_box_255","displayName":"All drives","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_bits_bandwidththrottlingendtime","displayName":"Bandwidth Throttling End Time","description":"This policy specifies the bandwidth throttling end time that Background Intelligent Transfer Service (BITS) uses for background transfers. This policy setting does not affect foreground transfers. This policy is based on the 24-hour clock. Value type is integer. Default value is 17 (5 PM). Supported value range: 0 - 23You can specify a limit to use during a specific time interval and at all other times. For example, limit the use of network bandwidth to 10 Kbps from 8:00 A. M. to 5:00 P. M. , and use all available unused bandwidth the rest of the day's hours. Using the three policies together (BandwidthThrottlingStartTime, BandwidthThrottlingEndTime, BandwidthThrottlingTransferRate), BITS will limit its bandwidth usage to the specified values. You can specify the limit in kilobits per second (Kbps). If you specify a value less than 2 kilobits, BITS will continue to use approximately 2 kilobits. To prevent BITS transfers from occurring, specify a limit of 0. If you disable or do not configure this policy setting, BITS uses all available unused bandwidth. Note: You should base the limit on the speed of the network link, not the computer's network interface card (NIC). This policy setting does not affect peer caching transfers between peer computers (it does affect transfers from the origin server); the Limit the maximum network bandwidth used for Peercaching policy setting should be used for that purpose. Consider using this setting to prevent BITS transfers from competing for network bandwidth when the client computer has a fast network card (10Mbs), but is connected to the network via a slow link (56Kbs).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#bandwidththrottlingendtime"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":null},{"id":"device_vendor_msft_policy_config_bits_bandwidththrottlingstarttime","displayName":"Bandwidth Throttling Start Time","description":"This policy specifies the bandwidth throttling start time that Background Intelligent Transfer Service (BITS) uses for background transfers. This policy setting does not affect foreground transfers. This policy is based on the 24-hour clock. Value type is integer. Default value is 8 (8 am). Supported value range: 0 - 23You can specify a limit to use during a specific time interval and at all other times. For example, limit the use of network bandwidth to 10 Kbps from 8:00 A. M. to 5:00 P. M. , and use all available unused bandwidth the rest of the day's hours. Using the three policies together (BandwidthThrottlingStartTime, BandwidthThrottlingEndTime, BandwidthThrottlingTransferRate), BITS will limit its bandwidth usage to the specified values. You can specify the limit in kilobits per second (Kbps). If you specify a value less than 2 kilobits, BITS will continue to use approximately 2 kilobits. To prevent BITS transfers from occurring, specify a limit of 0. If you disable or do not configure this policy setting, BITS uses all available unused bandwidth. Note: You should base the limit on the speed of the network link, not the computer's network interface card (NIC). This policy setting does not affect peer caching transfers between peer computers (it does affect transfers from the origin server); the Limit the maximum network bandwidth used for Peercaching policy setting should be used for that purpose. Consider using this setting to prevent BITS transfers from competing for network bandwidth when the client computer has a fast network card (10Mbs), but is connected to the network via a slow link (56Kbs).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#bandwidththrottlingstarttime"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":null},{"id":"device_vendor_msft_policy_config_bits_bandwidththrottlingtransferrate","displayName":"Bandwidth Throttling Transfer Rate","description":"This policy specifies the bandwidth throttling transfer rate in kilobits per second (Kbps) that Background Intelligent Transfer Service (BITS) uses for background transfers. This policy setting does not affect foreground transfers. Value type is integer. Default value is 1000. Supported value range: 0 - 4294967200. You can specify a limit to use during a specific time interval and at all other times. For example, limit the use of network bandwidth to 10 Kbps from 8:00 A. M. to 5:00 P. M. , and use all available unused bandwidth the rest of the day's hours. Using the three policies together (BandwidthThrottlingStartTime, BandwidthThrottlingEndTime, BandwidthThrottlingTransferRate), BITS will limit its bandwidth usage to the specified values. You can specify the limit in kilobits per second (Kbps). If you specify a value less than 2 kilobits, BITS will continue to use approximately 2 kilobits. To prevent BITS transfers from occurring, specify a limit of 0. If you disable or do not configure this policy setting, BITS uses all available unused bandwidth. Note: You should base the limit on the speed of the network link, not the computer's network interface card (NIC). This policy setting does not affect peer caching transfers between peer computers (it does affect transfers from the origin server); the Limit the maximum network bandwidth used for Peercaching policy setting should be used for that purpose. Consider using this setting to prevent BITS transfers from competing for network bandwidth when the client computer has a fast network card (10Mbs), but is connected to the network via a slow link (56Kbs).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#bandwidththrottlingtransferrate"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority","displayName":"Costed Network Behavior Background Priority","description":"This policy setting defines the default behavior that the Background Intelligent Transfer Service (BITS) uses for background transfers when the system is connected to a costed network (3G, etc. ). Download behavior policies further limit the network usage of background transfers. If you enable this policy setting, you can define a default download policy for each BITS job priority. This setting does not override a download policy explicitly configured by the application that created the BITS job, but does apply to jobs that are created by specifying only a priority. For example, you can specify that background jobs are by default to transfer only when on uncosted network connections, but foreground jobs should proceed only when not roaming. The values that can be assigned are:1 - Always transfer2 - Transfer unless roaming3 - Transfer unless surcharge applies (when not roaming or overcap)4 - Transfer unless nearing limit (when not roaming or nearing cap)5 - Transfer only if unconstrained","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#costednetworkbehaviorbackgroundpriority"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":[{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_1","displayName":"Always transfer","description":"Always transfer","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_2","displayName":"Transfer unless roaming","description":"Transfer unless roaming","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_3","displayName":"Transfer unless surcharge applies (when not roaming or over cap)","description":"Transfer unless surcharge applies (when not roaming or over cap)","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_4","displayName":"Transfer unless nearing limit (when not roaming or nearing cap)","description":"Transfer unless nearing limit (when not roaming or nearing cap)","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_5","displayName":"Transfer only if unconstrained","description":"Transfer only if unconstrained","helpText":null}]},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorforegroundpriority","displayName":"Costed Network Behavior Foreground Priority","description":"This policy setting defines the default behavior that the foreground Intelligent Transfer Service (BITS) uses for foreground transfers when the system is connected to a costed network (3G, etc. ). Download behavior policies further limit the network usage of foreground transfers. If you enable this policy setting, you can define a default download policy for each BITS job priority. This setting does not override a download policy explicitly configured by the application that created the BITS job, but does apply to jobs that are created by specifying only a priority. For example, you can specify that foreground jobs are by default to transfer only when on uncosted network connections, but foreground jobs should proceed only when not roaming. The values that can be assigned are:1 - Always transfer2 - Transfer unless roaming3 - Transfer unless surcharge applies (when not roaming or overcap)4 - Transfer unless nearing limit (when not roaming or nearing cap)5 - Transfer only if unconstrained","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#costednetworkbehaviorforegroundpriority"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":[{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorforegroundpriority_1","displayName":"Always transfer","description":"Always transfer","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorforegroundpriority_2","displayName":"Transfer unless roaming","description":"Transfer unless roaming","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorforegroundpriority_3","displayName":"Transfer unless surcharge applies (when not roaming or over cap)","description":"Transfer unless surcharge applies (when not roaming or over cap)","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorforegroundpriority_4","displayName":"Transfer unless nearing limit (when not roaming or nearing cap)","description":"Transfer unless nearing limit (when not roaming or nearing cap)","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorforegroundpriority_5","displayName":"Transfer only if unconstrained","description":"Transfer only if unconstrained","helpText":null}]},{"id":"device_vendor_msft_policy_config_bits_jobinactivitytimeout","displayName":"Job Inactivity Timeout","description":"This policy setting specifies the number of days a pending BITS job can remain inactive before the job is considered abandoned. By default BITS will wait 90 days before considering an inactive job abandoned. After a job is determined to be abandoned, the job is deleted from BITS and any downloaded files for the job are deleted from the disk. NoteAny property changes to the job or any successful download action will reset this timeout. Value type is integer. Default is 90 days. Supported values range: 0 - 999Consider increasing the timeout value if computers tend to stay offline for a long period of time and still have pending jobs. Consider decreasing this value if you are concerned about orphaned jobs occupying disk space. If you disable or do not configure this policy setting, the default value of 90 (days) will be used for the inactive job timeout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#jobinactivitytimeout"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":null},{"id":"device_vendor_msft_policy_config_bluetooth_allowadvertising","displayName":"Allow Advertising","description":"Specifies whether the device can send out Bluetooth advertisements. If this is not set or it is deleted, the default value of 1 (Allow) is used. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#allowadvertising"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":[{"id":"device_vendor_msft_policy_config_bluetooth_allowadvertising_0","displayName":"Block","description":"Not allowed. When set to 0, the device will not send out advertisements. To verify, use any Bluetooth LE app and enable it to do advertising. Then, verify that the advertisement is not received by the peripheral.","helpText":null},{"id":"device_vendor_msft_policy_config_bluetooth_allowadvertising_1","displayName":"Allow","description":"Allowed. When set to 1, the device will send out advertisements. To verify, use any Bluetooth LE app and enable it to do advertising. Then, verify that the advertisement is received by the peripheral.","helpText":null}]},{"id":"device_vendor_msft_policy_config_bluetooth_allowdiscoverablemode","displayName":"Allow Discoverable Mode","description":"Specifies whether other Bluetooth-enabled devices can discover the device. If this is not set or it is deleted, the default value of 1 (Allow) is used. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#allowdiscoverablemode"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":[{"id":"device_vendor_msft_policy_config_bluetooth_allowdiscoverablemode_0","displayName":"Block","description":"Not allowed. When set to 0, other devices will not be able to detect the device. To verify, open the Bluetooth control panel on the device. Then, go to another Bluetooth-enabled device, open the Bluetooth control panel, and verify that you cannot see the name of the device.","helpText":null},{"id":"device_vendor_msft_policy_config_bluetooth_allowdiscoverablemode_1","displayName":"Allow","description":"Allowed. When set to 1, other devices will be able to detect the device. To verify, open the Bluetooth control panel on the device. Then, go to another Bluetooth-enabled device, open the Bluetooth control panel and verify that you can discover it.","helpText":null}]},{"id":"device_vendor_msft_policy_config_bluetooth_allowprepairing","displayName":"Allow Prepairing","description":"Specifies whether to allow specific bundled Bluetooth peripherals to automatically pair with the host device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#allowprepairing"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":[{"id":"device_vendor_msft_policy_config_bluetooth_allowprepairing_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_bluetooth_allowprepairing_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_bluetooth_allowpromptedproximalconnections","displayName":"Allow Prompted Proximal Connections","description":"This policy allows the IT admin to block users on these managed devices from using Swift Pair and other proximity based scenarios.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#allowpromptedproximalconnections"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":[{"id":"device_vendor_msft_policy_config_bluetooth_allowpromptedproximalconnections_0","displayName":"Block","description":"Disallow. Block users on these managed devices from using Swift Pair and other proximity based scenarios","helpText":null},{"id":"device_vendor_msft_policy_config_bluetooth_allowpromptedproximalconnections_1","displayName":"Allow","description":"Allow. Allow users on these managed devices to use Swift Pair and other proximity based scenarios","helpText":null}]},{"id":"device_vendor_msft_policy_config_bluetooth_localdevicename","displayName":"Local Device Name","description":"Sets the local Bluetooth device name. If this is set, the value that it is set to will be used as the Bluetooth device name. To verify the policy is set, open the Bluetooth control panel on the device. Then, go to another Bluetooth-enabled device, open the Bluetooth control panel, and verify that the value that was specified. If this policy is not set or it is deleted, the default local radio name is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#localdevicename"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":null},{"id":"device_vendor_msft_policy_config_bluetooth_servicesallowedlist","displayName":"Services Allowed List","description":"Set a list of allowable services and profiles. String hex formatted array of Bluetooth service UUIDs in canonical format, delimited by semicolons. For example, {782AFCFC-7CAA-436C-8BF0-78CD0FFBD4AF}. The default value is an empty string. For more information, see ServicesAllowedList usage guide","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#servicesallowedlist"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":null},{"id":"device_vendor_msft_policy_config_bluetooth_setminimumencryptionkeysize","displayName":"Set Minimum Encryption Key Size","description":"There are multiple levels of encryption strength when pairing Bluetooth devices. This policy helps prevent weaker devices cryptographically being used in high security environments.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#setminimumencryptionkeysize"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":null},{"id":"device_vendor_msft_policy_config_browser_allowaddressbardropdown","displayName":"Allow Address Bar Dropdown","description":"This policy setting lets you decide whether the Address bar drop-down functionality is available in Microsoft Edge. We recommend disabling this setting if you want to minimize network connections from Microsoft Edge to Microsoft services.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowaddressbardropdown"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowaddressbardropdown_0","displayName":"Block","description":"Prevented/not allowed. Hide the Address bar drop-down functionality and disable the Show search and site suggestions as I type toggle in Settings.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowaddressbardropdown_1","displayName":"Allow","description":"Allowed. Show the Address bar drop-down list and make it available.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowautofill","displayName":"Allow Autofill","description":"This setting lets you decide whether employees can use Autofill to automatically fill in form fields while using Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowautofill"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowautofill_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowautofill_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowconfigurationupdateforbookslibrary","displayName":"Allow Configuration Update For Books Library","description":"This policy setting lets you decide whether Microsoft Edge can automatically update the configuration data for the Books Library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowconfigurationupdateforbookslibrary"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowconfigurationupdateforbookslibrary_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowconfigurationupdateforbookslibrary_1","displayName":"Allow","description":"Allowed. Microsoft Edge updates the configuration data for the Books Library automatically.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowcookies","displayName":"Allow Cookies","description":"This setting lets you configure how your company deals with cookies.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowcookies"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowcookies_0","displayName":"Block all cookies from all sites","description":"Block all cookies from all sites","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowcookies_1","displayName":"Block only cookies from third party websites","description":"Block only cookies from third party websites","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowcookies_2","displayName":"Allow all cookies from all sites","description":"Allow all cookies from all sites","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowdevelopertools","displayName":"Allow Developer Tools","description":"This setting lets you decide whether employees can use F12 Developer Tools on Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowdevelopertools"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowdevelopertools_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowdevelopertools_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowdonottrack","displayName":"Allow Do Not Track","description":"This setting lets you decide whether employees can send Do Not Track headers to websites that request tracking info.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowdonottrack"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowdonottrack_0","displayName":"Block","description":"Never send tracking information.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowdonottrack_1","displayName":"Allow","description":"Send tracking information.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowextensions","displayName":"Allow Extensions","description":"This setting lets you decide whether employees can load extensions in Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowextensions"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowextensions_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowextensions_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowflash","displayName":"Allow Flash","description":"This setting lets you decide whether employees can run Adobe Flash in Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowflash"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowflash_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowflash_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowflashclicktorun","displayName":"Allow Flash Click To Run","description":"Configure the Adobe Flash Click-to-Run setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowflashclicktorun"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowflashclicktorun_0","displayName":"Block","description":"Load and run Adobe Flash content automatically.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowflashclicktorun_1","displayName":"Allow","description":"Does not load or run Adobe Flash content automatically. Requires action from the user.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowfullscreenmode","displayName":"Allow Full Screen Mode","description":"With this policy, you can specify whether to allow full-screen mode, which shows only the web content and hides the Microsoft Edge UI. If enabled or not configured, full-screen mode is available for use in Microsoft Edge. Your users and extensions must have the proper permissions. If disabled, full-screen mode is unavailable for use in Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowfullscreenmode"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowfullscreenmode_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowfullscreenmode_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowinprivate","displayName":"Allow InPrivate","description":"This setting lets you decide whether employees can browse using InPrivate website browsing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowinprivate"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowinprivate_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowinprivate_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowmicrosoftcompatibilitylist","displayName":"Allow Microsoft Compatibility List","description":"This policy setting lets you decide whether the Microsoft Compatibility List is enabled or disabled in Microsoft Edge. This feature uses a Microsoft-provided list to ensure that any sites with known compatibility issues are displayed correctly when a user navigates to them. By default, the Microsoft Compatibility List is enabled and can be viewed by navigating to about:compat. If you enable or don’t configure this setting, Microsoft Edge will periodically download the latest version of the list from Microsoft and will apply the configurations specified there during browser navigation. If a user visits a site on the Microsoft Compatibility List, he or she will be prompted to open the site in Internet Explorer 11. Once in Internet Explorer, the site will automatically be rendered as if the user is viewing it in the previous version of Internet Explorer it requires to display correctly. If you disable this setting, the Microsoft Compatibility List will not be used during browser navigation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowmicrosoftcompatibilitylist"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowmicrosoftcompatibilitylist_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowmicrosoftcompatibilitylist_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowpasswordmanager","displayName":"Allow Password Manager","description":"This setting lets you decide whether employees can save their passwords locally, using Password Manager.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowpasswordmanager"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowpasswordmanager_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowpasswordmanager_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowpopups","displayName":"Allow Popups","description":"This setting lets you decide whether to turn on Pop-up Blocker and whether to allow pop-ups to appear in secondary windows.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowpopups"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowpopups_0","displayName":"Block","description":"Turn off Pop-up Blocker letting pop-up windows open.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowpopups_1","displayName":"Allow","description":"Turn on Pop-up Blocker stopping pop-up windows from opening.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowprelaunch","displayName":"Allow Prelaunch","description":"Allow Microsoft Edge to pre-launch at Windows startup, when the system is idle, and each time Microsoft Edge is closed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowprelaunch"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowprelaunch_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowprelaunch_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowprinting","displayName":"Allow Printing","description":"With this policy, you can restrict whether printing web content in Microsoft Edge is allowed. If enabled, printing is allowed. If disabled, printing is not allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowprinting"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowprinting_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowprinting_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowsavinghistory","displayName":"Allow Saving History","description":"Microsoft Edge saves your user's browsing history, which is made up of info about the websites they visit, on their devices. If enabled or not configured, the browsing history is saved and visible in the History pane. If disabled, the browsing history stops saving and is not visible in the History pane. If browsing history exists before this policy was disabled, the previous browsing history remains visible in the History pane. This policy, when disabled, does not stop roaming of existing history or history coming from other roamed devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsavinghistory"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsavinghistory_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsavinghistory_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowsearchenginecustomization","displayName":"Allow Search Engine Customization","description":"Allow search engine customization for MDM enrolled devices. Users can change their default search engine. If this setting is turned on or not configured, users can add new search engines and change the default used in the address bar from within Microsoft Edge Settings. If this setting is disabled, users will be unable to add search engines or change the default used in the address bar. This policy will only apply on domain joined machines or when the device is MDM enrolled. For more information, see Microsoft browser extension policy (aka.ms/browserpolicy).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsearchenginecustomization"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsearchenginecustomization_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsearchenginecustomization_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowsearchsuggestionsinaddressbar","displayName":"Allow Search Suggestionsin Address Bar","description":"This setting lets you decide whether search suggestions should appear in the Address bar of Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsearchsuggestionsinaddressbar"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsearchsuggestionsinaddressbar_0","displayName":"Block","description":"Prevented/Not allowed. Hide the search suggestions.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsearchsuggestionsinaddressbar_1","displayName":"Allow","description":"Allowed. Show the search suggestions.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowsideloadingofextensions","displayName":"Allow Sideloading Of Extensions","description":"This setting lets you decide whether employees can sideload extensions in Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsideloadingofextensions"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsideloadingofextensions_0","displayName":"Block","description":"Prevented/Not allowed. Disabling does not prevent sideloading of extensions using Add-AppxPackage via Powershell. To prevent this, set the ApplicationManagement/AllowDeveloperUnlock policy to 1 (enabled).","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsideloadingofextensions_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowsmartscreen","displayName":"Allow Smart Screen","description":"This setting lets you decide whether to turn on Windows Defender SmartScreen.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsmartscreen"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsmartscreen_0","displayName":"Block","description":"Turned off. Do not protect users from potential threats and prevent users from turning it on.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsmartscreen_1","displayName":"Allow","description":"Turned on. Protect users from potential threats and prevent users from turning it off.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowtabpreloading","displayName":"Allow Tab Preloading","description":"Prevent Microsoft Edge from starting and loading the Start and New Tab page at Windows startup and each time Microsoft Edge is closed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowtabpreloading"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowtabpreloading_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowtabpreloading_1","displayName":"Allow","description":"Allowed. Preload Start and New tab pages.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_allowwebcontentonnewtabpage","displayName":"Allow Web Content On New Tab Page","description":"This policy setting lets you configure what appears when Microsoft Edge opens a new tab. By default, Microsoft Edge opens the New Tab page. If you enable this setting, Microsoft Edge opens a new tab with the New Tab page. If you disable this setting, Microsoft Edge opens a new tab with a blank page. If you use this setting, employees can't change it. If you don't configure this setting, employees can choose how new tabs appears.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowwebcontentonnewtabpage"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowwebcontentonnewtabpage_0","displayName":"Block","description":"Load a blank page instead of the default New tab page and prevent users from changing it.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowwebcontentonnewtabpage_1","displayName":"Allow","description":"Load the default New tab page.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_alwaysenablebookslibrary","displayName":"Always Enable Books Library","description":"Specifies whether the Books Library in Microsoft Edge will always be visible regardless of the country or region setting for the device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#alwaysenablebookslibrary"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_alwaysenablebookslibrary_0","displayName":"Disabled","description":"Show the Books Library only in countries or regions where supported.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_alwaysenablebookslibrary_1","displayName":"Enabled","description":"Show the Books Library, regardless of the device's country or region.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_clearbrowsingdataonexit","displayName":"Clear Browsing Data On Exit","description":"Specifies whether to always clear browsing history on exiting Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#clearbrowsingdataonexit"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_clearbrowsingdataonexit_0","displayName":"Disabled","description":"Prevented/not allowed. Users can configure the 'Clear browsing data' option in Settings.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_clearbrowsingdataonexit_1","displayName":"Enabled","description":"Allowed. Clear the browsing data upon exit automatically.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_configureadditionalsearchengines","displayName":"Configure Additional Search Engines","description":"Allows you to add up to 5 additional search engines for MDM-enrolled devices. If this setting is turned on, you can add up to 5 additional search engines for your employee. For each additional search engine you wish to add, you must specify a link to the OpenSearch XML file that contains, at minimum, the short name and the URL to the search engine. This policy does not affect the default search engine. Employees will not be able to remove these search engines, but they can set any one of these as the default. If this setting is not configured, the search engines are the ones specified in the App settings. If this setting is disabled, the search engines you had added will be deleted from your employee's machine. Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configureadditionalsearchengines"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_configurefavoritesbar","displayName":"Configure Favorites Bar","description":"The favorites bar shows your user's links to sites they have added to it. With this policy, you can specify whether to set the favorites bar to always be visible or hidden on any page. If enabled, favorites bar is always visible on any page, and the favorites bar toggle in Settings sets to On, but disabled preventing your users from making changes. An error message also shows at the top of the Settings pane indicating that your organization manages some settings. The show bar/hide bar option is hidden from the context menu. If disabled, the favorites bar is hidden, and the favorites bar toggle resets to Off, but disabled preventing your users from making changes. An error message also shows at the top of the Settings pane indicating that your organization manages some settings. If not configured, the favorites bar is hidden but is visible on the Start and New Tab pages, and the favorites bar toggle in Settings sets to Off but is enabled allowing the user to make changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configurefavoritesbar"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configurefavoritesbar_0","displayName":"Disabled","description":"Hide the favorites bar on all pages. Also, the favorites bar toggle, in Settings, is set to Off and disabled preventing users from making changes. Microsoft Edge also hides the “show bar/hide bar” option in the context menu.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurefavoritesbar_1","displayName":"Enabled","description":"Show the favorites bar on all pages. Also, the favorites bar toggle, in Settings, is set to On and disabled preventing users from making changes. Microsoft Edge also hides the “show bar/hide bar” option in the context menu.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_configurehomebutton","displayName":"Configure Home Button","description":"The Home button loads either the default Start page, the New tab page, or a URL defined in the Set Home Button URL policy. By default, this policy is disabled or not configured and clicking the home button loads the default Start page. When enabled, the home button is locked down preventing your users from making changes in Microsoft Edge's UI settings. To let your users change the Microsoft Edge UI settings, enable the Unlock Home Button policy. If Enabled AND: - Show home button & set to Start page is selected, clicking the home button loads the Start page. - Show home button & set to New tab page is selected, clicking the home button loads a New tab page. - Show home button & set a specific page is selected, clicking the home button loads the URL specified in the Set Home Button URL policy. - Hide home button is selected, the home button is hidden in Microsoft Edge. Default setting: Disabled or not configured Related policies: - Set Home Button URL - Unlock Home Button","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configurehomebutton"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configurehomebutton_0","displayName":"Show home button and load the Start page","description":"Show home button and load the Start page","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurehomebutton_1","displayName":"Show home button and load the New tab page","description":"Show home button and load the New tab page","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurehomebutton_2","displayName":"Show home button and load the custom URL defined in the Set Home Button URL policy","description":"Show home button and load the custom URL defined in the Set Home Button URL policy","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurehomebutton_3","displayName":"Hide home button","description":"Hide home button","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_configurekioskmode","displayName":"Configure Kiosk Mode","description":"Configure how Microsoft Edge behaves when it’s running in kiosk mode with assigned access, either as a single app or as one of multiple apps running on the kiosk device. You can control whether Microsoft Edge runs InPrivate full screen, InPrivate multi-tab with limited functionality, or normal Microsoft Edge. You need to configure Microsoft Edge in assigned access for this policy to take effect; otherwise, these settings are ignored. To learn more about assigned access and kiosk configuration, see “Configure kiosk and shared devices running Windows desktop editions” (https://aka.ms/E489vw). If enabled and set to 0 (Default or not configured): - If it’s a single app, it runs InPrivate full screen for digital signage or interactive displays. - If it’s one of many apps, Microsoft Edge runs as normal. If enabled and set to 1: - If it’s a single app, it runs a limited multi-tab version of InPrivate and is the only app available for public browsing. Users can’t minimize, close, or open windows or customize Microsoft Edge, but can clear browsing data and downloads and restart by clicking “End session.” You can configure Microsoft Edge to restart after a period of inactivity by using the “Configure kiosk reset after idle timeout” policy. - If it’s one of many apps, it runs in a limited multi-tab version of InPrivate for public browsing with other apps. Users can minimize, close, and open multiple InPrivate windows, but they can’t customize Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configurekioskmode"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configurekioskmode_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurekioskmode_0","displayName":"Disable","description":"Disable","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_configurekioskresetafteridletimeout","displayName":"Configure Kiosk Reset After Idle Timeout","description":"You can configure Microsoft Edge to reset to the configured start experience after a specified amount of idle time. The reset timer begins after the last user interaction. Resetting to the configured start experience deletes the current user’s browsing data. If enabled, you can set the idle time in minutes (0-1440). You must set the Configure kiosk mode policy to 1 and configure Microsoft Edge in assigned access as a single app for this policy to work. Once the idle time meets the time specified, a confirmation message prompts the user to continue, and if no user action, Microsoft Edge resets after 30 seconds. If you set this policy to 0, Microsoft Edge does not use an idle timer. If disabled or not configured, the default value is 5 minutes. If you do not configure Microsoft Edge in assigned access, then this policy does not take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configurekioskresetafteridletimeout"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_configureopenmicrosoftedgewith","displayName":"Configure Open Microsoft Edge With","description":"You can configure Microsoft Edge to lock down the Start page, preventing users from changing or customizing it. If enabled, you can choose one of the following options: - Start page: the Start page loads ignoring the Configure Start Pages policy. - New tab page: the New tab page loads ignoring the Configure Start Pages policy. - Previous pages: all tabs the user had open when Microsoft Edge last closed loads ignoring the Configure Start Pages policy. - A specific page or pages: the URL(s) specified with Configure Start Pages policy load(s). If selected, you must specify at least one URL in Configure Start Pages; otherwise, this policy is ignored. When enabled, and you want to make changes, you must first set the Disable Lockdown of Start Pages to not configured, make the changes to the Configure Open Edge With policy, and then enable the Disable Lockdown of Start Pages policy. If disabled or not configured, and you enable the Disable Lockdown of Start Pages policy, your users can change or customize the Start page. Default setting: A specific page or pages (default) Related policies: -Disable Lockdown of Start Pages -Configure Start Pages","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configureopenmicrosoftedgewith"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configureopenmicrosoftedgewith_0","displayName":"Load the Start page","description":"Load the Start page","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configureopenmicrosoftedgewith_1","displayName":"Load the New tab page","description":"Load the New tab page","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configureopenmicrosoftedgewith_2","displayName":"Load the previous pages","description":"Load the previous pages","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configureopenmicrosoftedgewith_3","displayName":"Load a specific page or pages","description":"Load a specific page or pages","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_configuretelemetryformicrosoft365analytics","displayName":"Configure Telemetry For Microsoft 365 Analytics","description":"Configures what browsing data will be sent to Microsoft 365 Analytics for devices belonging to an organization.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configuretelemetryformicrosoft365analytics"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configuretelemetryformicrosoft365analytics_0","displayName":"No data collected or sent","description":"No data collected or sent","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configuretelemetryformicrosoft365analytics_1","displayName":"Send intranet history only","description":"Send intranet history only","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configuretelemetryformicrosoft365analytics_2","displayName":"Send Internet history only","description":"Send Internet history only","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configuretelemetryformicrosoft365analytics_3","displayName":"Send both intranet and Internet history","description":"Send both intranet and Internet history","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_disablelockdownofstartpages","displayName":"Disable Lockdown Of Start Pages","description":"You can configure Microsoft Edge to disable the lockdown of Start pages allowing users to change or customize their start pages. To do this, you must also enable the Configure Start Pages or Configure Open Microsoft With policy. When enabled, all configured start pages are editable. Any Start page configured using the Configure Start pages policy is not locked down allowing users to edit their Start pages. If disabled or not configured, the Start pages configured in the Configure Start Pages policy cannot be changed and remain locked down. Supported devices: Domain-joined or MDM-enrolled Related policy: - Configure Start Pages - Configure Open Microsoft Edge With","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#disablelockdownofstartpages"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_disablelockdownofstartpages_0","displayName":"Disabled","description":"Lock down Start pages configured in either the ConfigureOpenEdgeWith policy and HomePages policy.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_disablelockdownofstartpages_1","displayName":"Enabled","description":"Unlocked. Users can make changes to all configured start pages.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_enableextendedbookstelemetry","displayName":"Enable Extended Books Telemetry","description":"This setting allows organizations to send extended telemetry on book usage from the Books Library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#enableextendedbookstelemetry"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_enableextendedbookstelemetry_0","displayName":"Disabled","description":"Gather and send only basic diagnostic data, depending on the device configuration.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_enableextendedbookstelemetry_1","displayName":"Enabled","description":"Gather all diagnostic data.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_enterprisemodesitelist","displayName":"Enterprise Mode Site List","description":"This setting lets you configure whether your company uses Enterprise Mode and the Enterprise Mode Site List to address common compatibility problems with legacy websites.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#enterprisemodesitelist"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_enterprisesitelistserviceurl","displayName":"Enterprise Site List Service Url","description":"Important. Discontinued in Windows 10, version 1511. Use the Browser/EnterpriseModeSiteList policy instead.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#enterprisesitelistserviceurl"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_homepages","displayName":"Home Pages","description":"When you enable the Configure Open Microsoft Edge With policy, you can configure one or more Start pages. When you enable this policy, users are not allowed to make changes to their Start pages. If enabled, you must include URLs to the pages, separating multiple pages using angle brackets in the following format: If disabled or not configured, the webpages specified in App settings loads as the default Start pages. Version 1703 or later: If you do not want to send traffic to Microsoft, enable this policy and use the value, which honors domain- and non-domain-joined devices, when it is the only configured URL. Version 1809: If enabled, and you select either Start page, New Tab page, or previous page in the Configure Open Microsoft Edge With policy, Microsoft Edge ignores the Configure Start Pages policy. If not configured or you set the Configure Open Microsoft Edge With policy to a specific page or pages, Microsoft Edge uses the Configure Start Pages policy. Supported devices: Domain-joined or MDM-enrolled Related policy: - Configure Open Microsoft Edge With - Disable Lockdown of Start Pages","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#homepages"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_lockdownfavorites","displayName":"Lockdown Favorites","description":"This policy setting lets you decide whether employees can add, import, sort, or edit the Favorites list on Microsoft Edge. If you enable this setting, employees won't be able to add, import, or change anything in the Favorites list. Also as part of this, Save a Favorite, Import settings, and the context menu items (such as, Create a new folder) are all turned off. Important Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge. If you disable or don't configure this setting (default), employees can add, import and make changes to the Favorites list.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#lockdownfavorites"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_lockdownfavorites_0","displayName":"Disabled","description":"Allowed/not locked down. Users can add, import, and make changes to the favorites.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_lockdownfavorites_1","displayName":"Enabled","description":"Prevented/locked down.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_preventaccesstoaboutflagsinmicrosoftedge","displayName":"Prevent Access To About Flags In Microsoft Edge","description":"Prevent access to the about:flags page in Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventaccesstoaboutflagsinmicrosoftedge"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventaccesstoaboutflagsinmicrosoftedge_0","displayName":"Disabled","description":"Allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventaccesstoaboutflagsinmicrosoftedge_1","displayName":"Enabled","description":"Prevents users from accessing the about:flags page.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_preventcerterroroverrides","displayName":"Prevent Cert Error Overrides","description":"Web security certificates are used to ensure a site your users go to is legitimate, and in some circumstances encrypts the data. With this policy, you can specify whether to prevent users from bypassing the security warning to sites that have SSL errors. If enabled, overriding certificate errors are not allowed. If disabled or not configured, overriding certificate errors are allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventcerterroroverrides"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventcerterroroverrides_0","displayName":"Disabled","description":"Allowed/turned on. Override the security warning to sites that have SSL errors.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventcerterroroverrides_1","displayName":"Enabled","description":"Prevented/turned on.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_preventlivetiledatacollection","displayName":"Prevent Live Tile Data Collection","description":"This policy lets you decide whether Microsoft Edge can gather Live Tile metadata from the ieonline.microsoft.com service to provide a better experience while pinning a Live Tile to the Start menu. Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventlivetiledatacollection"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventlivetiledatacollection_0","displayName":"Disabled","description":"Collect and send Live Tile metadata.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventlivetiledatacollection_1","displayName":"Enabled","description":"No data collected.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverride","displayName":"Prevent Smart Screen Prompt Override","description":"Don't allow Windows Defender SmartScreen warning overrides","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventsmartscreenpromptoverride"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverride_0","displayName":"Disabled","description":"Allowed/turned off. Users can ignore the warning and continue to the site.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverride_1","displayName":"Enabled","description":"Prevented/turned on.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverrideforfiles","displayName":"Prevent Smart Screen Prompt Override For Files","description":"Don't allow Windows Defender SmartScreen warning overrides for unverified files.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventsmartscreenpromptoverrideforfiles"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverrideforfiles_0","displayName":"Disabled","description":"Allowed/turned off. Users can ignore the warning and continue to download the unverified file(s).","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverrideforfiles_1","displayName":"Enabled","description":"Prevented/turned on.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_preventturningoffrequiredextensions","displayName":"Prevent Turning Off Required Extensions","description":"You can define a list of extensions in Microsoft Edge that users cannot turn off. You must deploy extensions through any available enterprise deployment channel, such as Microsoft Intune. When you enable this policy, users cannot uninstall extensions from their computer, but they can configure options for extensions defined in this policy, such as allow for InPrivate browsing. Any additional permissions requested by future updates of the extension gets granted automatically. When you enable this policy, you must provide a semi-colon delimited list of extension package family names (PFNs). For example, adding Microsoft.OneNoteWebClipper_8wekyb3d8bbwe;Microsoft.OfficeOnline_8wekyb3d8bbwe prevents a user from turning off the OneNote Web Clipper and Office Online extension. When enabled, removing extensions from the list does not uninstall the extension from the user’s computer automatically. To uninstall the extension, use any available enterprise deployment channel. If you enable the Allow Developer Tools policy, then this policy does not prevent users from debugging and altering the logic on an extension. If disabled or not configured, extensions defined as part of this policy get ignored. Default setting: Disabled or not configured Related policies: Allow Developer Tools Related Documents: - Find a package family name (PFN) for per-app VPN (https://docs.microsoft.com/en-us/sccm/protect/deploy-use/find-a-pfn-for-per-app-vpn) - How to manage apps you purchased from the Microsoft Store for Business with Microsoft Intune (https://docs.microsoft.com/en-us/intune/windows-store-for-business) - How to assign apps to groups with Microsoft Intune (https://docs.microsoft.com/en-us/intune/apps-deploy) - Manage apps from the Microsoft Store for Business with System Center Configuration Manager (https://docs.microsoft.com/en-us/sccm/apps/deploy-use/manage-apps-from-the-windows-store-for-business) - How to add Windows line-of-business (LOB) apps to Microsoft Intune (https://docs.microsoft.com/en-us/intune/lob-apps-windows)","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventturningoffrequiredextensions"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_preventusinglocalhostipaddressforwebrtc","displayName":"Prevent Using Local Host IP Address For Web RTC","description":"Prevent using localhost IP address for WebRTC","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventusinglocalhostipaddressforwebrtc"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventusinglocalhostipaddressforwebrtc_0","displayName":"Disabled","description":"Allowed. Show localhost IP addresses.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventusinglocalhostipaddressforwebrtc_1","displayName":"Enabled","description":"Prevented/Not allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_provisionfavorites","displayName":"Provision Favorites","description":"This policy setting allows you to configure a default set of favorites, which will appear for employees. Employees cannot modify, sort, move, export or delete these provisioned favorites. If you enable this setting, you can set favorite URL's and favorite folders to appear on top of users' favorites list (either in the Hub or Favorites Bar). The user favorites will appear after these provisioned favorites. Important Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge. If you disable or don't configure this setting, employees will see the favorites they set in the Hub and Favorites Bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#provisionfavorites"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_sendintranettraffictointernetexplorer","displayName":"Send Intranet Trafficto Internet Explorer","description":"Sends all intranet traffic over to Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#sendintranettraffictointernetexplorer"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_sendintranettraffictointernetexplorer_0","displayName":"Disabled","description":"All sites, including intranet sites, open in Microsoft Edge automatically.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_sendintranettraffictointernetexplorer_1","displayName":"Enabled","description":"Only intranet sites open in Internet Explorer 11 automatically.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_setdefaultsearchengine","displayName":"Set Default Search Engine","description":"Sets the default search engine for MDM-enrolled devices. Users can still change their default search engine. If this setting is turned on, you are setting the default search engine that you would like your employees to use. Employees can still change the default search engine, unless you apply the AllowSearchEngineCustomization policy which will disable the ability to change it. You must specify a link to the OpenSearch XML file that contains, at minimum, the short name and the URL to the search engine. If you would like for your employees to use the Edge factory settings for the default search engine for their market, set the string EDGEDEFAULT; if you would like for your employees to use Bing as the default search engine, set the string EDGEBING. If this setting is not configured, the default search engine is set to the one specified in App settings and can be changed by your employees. If this setting is disabled, the policy-set search engine will be removed, and, if it is the current default, the default will be set back to the factory Microsoft Edge search engine for the market. Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#setdefaultsearchengine"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_sethomebuttonurl","displayName":"Set Home Button URL","description":"The home button can be configured to load a custom URL when your user clicks the home button. If enabled, or configured, and the Configure Home Button policy is enabled, and the Show home button & set a specific page is selected, a custom URL loads when your user clicks the home button. Default setting: Blank or not configured Related policy: Configure Home Button","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#sethomebuttonurl"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_setnewtabpageurl","displayName":"Set New Tab Page URL","description":"You can set the default New Tab page URL in Microsoft Edge. Enabling this policy prevents your users from changing the New tab page setting. When enabled and the Allow web content on New Tab page policy is disabled, Microsoft Edge ignores the URL specified in this policy and opens about:blank. If enabled, you can set the default New Tab page URL. If disabled or not configured, the default Microsoft Edge new tab page is used. Default setting: Disabled or not configured Related policy: Allow web content on New Tab page","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#setnewtabpageurl"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},{"id":"device_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer","displayName":"Show Message When Opening Sites In Internet Explorer","description":"You can configure Microsoft Edge to open a site automatically in Internet Explorer 11 and choose to display a notification before the site opens. If you want to display a notification, you must enable Configure the Enterprise Mode Site List or Send all intranets sites to Internet Explorer 11 or both. If enabled, the notification appears on a new page. If you want users to continue in Microsoft Edge, select the Show Keep going in Microsoft Edge option from the drop-down list under Options. If disabled or not configured, the default app behavior occurs and no additional page displays. Default setting: Disabled or not configured Related policies: -Configure the Enterprise Mode Site List -Send all intranet sites to Internet Explorer 11","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#showmessagewhenopeningsitesininternetexplorer"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer_0","displayName":"No additional message displays.","description":"No additional message displays.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer_1","displayName":"Show an additional message stating that a site has opened in IE11.","description":"Show an additional message stating that a site has opened in IE11.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer_2","displayName":"Show an additional message with a \"Keep going in Microsoft Edge\" link.","description":"Show an additional message with a \"Keep going in Microsoft Edge\" link.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_syncfavoritesbetweenieandmicrosoftedge","displayName":"Sync Favorites Between IE And Microsoft Edge","description":"Specifies whether favorites are kept in sync between Internet Explorer and Microsoft Edge. Changes to favorites in one browser are reflected in the other, including: additions, deletions, modifications, and ordering.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#syncfavoritesbetweenieandmicrosoftedge"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_syncfavoritesbetweenieandmicrosoftedge_0","displayName":"Disabled","description":"Turned off/not syncing.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_syncfavoritesbetweenieandmicrosoftedge_1","displayName":"Enabled","description":"Turned on/syncing.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_unlockhomebutton","displayName":"Unlock Home Button","description":"By default, when enabling Configure Home Button or Set Home Button URL, the home button is locked down to prevent your users from changing what page loads when clicking the home button. Use this policy to let users change the home button even when Configure Home Button or Set Home Button URL are enabled. If enabled, the UI settings for the home button are enabled allowing your users to make changes, including hiding and showing the home button as well as configuring a custom URL. If disabled or not configured, the UI settings for the home button are disabled preventing your users from making changes. Default setting: Disabled or not configured Related policy: -Configure Home Button -Set Home Button URL","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#unlockhomebutton"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_unlockhomebutton_0","displayName":"Disabled","description":"Lock down and prevent users from making changes to the settings.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_unlockhomebutton_1","displayName":"Enabled","description":"Let users make changes.","helpText":null}]},{"id":"device_vendor_msft_policy_config_browser_usesharedfolderforbooks","displayName":"Use Shared Folder For Books","description":"This setting specifies whether organizations should use a folder shared across users to store books from the Books Library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#usesharedfolderforbooks"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_usesharedfolderforbooks_0","displayName":"Disabled","description":"Prevented/not allowed, but Microsoft Edge downloads book files to a per-user folder for each user.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_usesharedfolderforbooks_1","displayName":"Enabled","description":"Allowed. Microsoft Edge downloads book files to a shared folder. For this policy to work correctly, you must also enable the Allow a Windows app to share application data between users group policy. Also, the users must be signed in with a school or work account.","helpText":null}]},{"id":"device_vendor_msft_policy_config_camera_allowcamera","displayName":"Allow Camera","description":"Disables or enables the camera. Most restrictive value is Block","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-camera#allowcamera"],"categoryId":"18893f00-c309-4695-bcaf-b66286ad99c1","categoryName":"Camera","options":[{"id":"device_vendor_msft_policy_config_camera_allowcamera_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_camera_allowcamera_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},{"id":"device_vendor_msft_policy_config_camera_configurecameraoptions","displayName":"Configure Camera Options","description":"This policy will allow camera mode to be managed by IT admins and enable camera to run in safe or auto share mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Camera#configurecameraoptions"],"categoryId":"18893f00-c309-4695-bcaf-b66286ad99c1","categoryName":"Camera","options":[{"id":"device_vendor_msft_policy_config_camera_configurecameraoptions_0","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_camera_configurecameraoptions_1","displayName":"AutoShare - Allow camera access by multiple applications simultaneously.","description":"AutoShare - Allow camera access by multiple applications simultaneously.","helpText":null},{"id":"device_vendor_msft_policy_config_camera_configurecameraoptions_2","displayName":"SafeMode - The camera is configured to auto‑share and operate in a non‑accelerated mode, bypassing OEM/IHV‑provided plugins where applicable.","description":"SafeMode - The camera is configured to auto‑share and operate in a non‑accelerated mode, bypassing OEM/IHV‑provided plugins where applicable.","helpText":null}]},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata","displayName":"Let Apps Access Cellular Data","description":"This policy setting specifies whether Windows apps can access cellular data.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":[{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_0","displayName":"User is in control","description":"User is in control","helpText":null},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_1","displayName":"Force Allow","description":"Force Allow","helpText":null},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_2","displayName":"Force Deny","description":"Force Deny","helpText":null}]},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_forceallowtheseapps","displayName":"Let Apps Access Cellular Data Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Windows Store Apps. Listed apps are allowed access to cellular data. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata_forceallowtheseapps"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":null},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_forcedenytheseapps","displayName":"Let Apps Access Cellular Data Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to cellular data. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata_forcedenytheseapps"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":null},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_userincontroloftheseapps","displayName":"Let Apps Access Cellular Data User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the cellular data access setting for the listed apps. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata_userincontroloftheseapps"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":null},{"id":"device_vendor_msft_policy_config_cellular_showappcellularaccessui","displayName":"Set Per-App Cellular Access UI Visibility","description":"This policy setting configures the visibility of the link to the per-application cellular access control page in the cellular setting UX.\n\nIf this policy setting is enabled, a drop-down list box presenting possible values will be active. Select \"Hide\" or \"Show\" to hide or show the link to the per-application cellular access control page.\nIf this policy setting is disabled or is not configured, the link to the per-application cellular access control page is showed by default.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-cellular#cellular-showappcellularaccessui"],"categoryId":"eefc9ae4-b9ae-4d77-8b68-359b9e5ec6f7","categoryName":"WWAN UI Settings","options":[{"id":"device_vendor_msft_policy_config_cellular_showappcellularaccessui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_cellular_showappcellularaccessui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_cellular_showappcellularaccessui_showappcellularaccessui_option","displayName":"Please select one option to set:","description":"","helpText":"","infoUrls":[],"categoryId":"eefc9ae4-b9ae-4d77-8b68-359b9e5ec6f7","categoryName":"WWAN UI Settings","options":[{"id":"device_vendor_msft_policy_config_cellular_showappcellularaccessui_showappcellularaccessui_option_0","displayName":"Hide","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_cellular_showappcellularaccessui_showappcellularaccessui_option_1","displayName":"Show","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_abusiveexperienceinterventionenforce","displayName":"Abusive Experience Intervention Enforce","description":"If SafeBrowsingEnabled is not Disabled, then setting AbusiveExperienceInterventionEnforce to Enabled or leaving it unset prevents sites with abusive experiences from opening new windows or tabs.\r\n\r\nSetting SafeBrowsingEnabled to Disabled or AbusiveExperienceInterventionEnforce to Disabled lets sites with abusive experiences open new windows or tabs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_abusiveexperienceinterventionenforce_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_abusiveexperienceinterventionenforce_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_accessibilityimagelabelsenabled","displayName":"Enable Get Image Descriptions from Google.","description":"The Get Image Descriptions from Google\r\naccessibility feature enables visually-impaired screen reader users to\r\nget descriptions of unlabeled images on the web. Users who choose to enable it\r\nwill have the option of using an anonymous Google service to provide\r\nautomatic descriptions for unlabeled images they encounter on the web.\r\n\r\nIf this feature is enabled, the content of images will be sent to Google\r\nservers in order to generate a description. No cookies or other user\r\ndata is sent, and Google does not save or log any image content.\r\n\r\nIf this policy is set to Enabled, the\r\nGet Image Descriptions from Google\r\nfeature will be enabled, though it will only affect users who are using a\r\nscreen reader or other similar assistive technology.\r\n\r\nIf this policy is set to Disabled, users will not have the option of enabling\r\nthe feature.\r\n\r\nIf this policy is not set, user can choose to use this feature or not.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_accessibilityimagelabelsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_accessibilityimagelabelsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_additionaldnsquerytypesenabled","displayName":"Allow DNS queries for additional DNS record types","description":"This policy controls whether Google Chrome may query additional DNS record types when making insecure DNS requests. This policy has no effect on DNS queries made via Secure DNS, which may always query additional DNS types.\r\n\r\nIf this policy is unset or set to Enabled, additional types such as HTTPS (DNS type 65) may be queried in addition to A (DNS type 1) and AAAA (DNS type 28).\r\n\r\nIf this policy is set to Disabled, DNS will only be queried for A (DNS type 1) and/or AAAA (DNS type 28).\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Google Chrome. After removal of the policy, Google Chrome will always be able to query additional DNS types.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_additionaldnsquerytypesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_additionaldnsquerytypesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads","description":"Unless SafeBrowsingEnabled is set to False, then setting AdsSettingForIntrusiveAdsSites to 1 or leaving it unset allows ads on all sites.\r\n\r\nSetting the policy to 2 blocks ads on sites with intrusive ads.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_adssettingforintrusiveadssites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_adssettingforintrusiveadssites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_adssettingforintrusiveadssites_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_adssettingforintrusiveadssites_adssettingforintrusiveadssites_1","displayName":"Allow ads on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_adssettingforintrusiveadssites_adssettingforintrusiveadssites_2","displayName":"Do not allow ads on sites with intrusive ads","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_advancedprotectionallowed","displayName":"Enable additional protections for users enrolled in the Advanced Protection program","description":"This policy controls whether users enrolled in the Advanced Protection program receive extra protections. Some of these features may involve the sharing of data with Google (for example, Advanced Protection users will be able to send their downloads to Google for malware scanning). If set to True or not set, enrolled users will receive extra protections. If set to False, Advanced Protection users will receive only the standard consumer features.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_advancedprotectionallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_advancedprotectionallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdeletingbrowserhistory","displayName":"Enable deleting browser and download history","description":"Setting the policy to Enabled or leaving it unset means browser history and download history can be deleted in Chrome, and users can't change this setting.\r\n\r\nSetting the policy to Disabled means browser history and download history can't be deleted. Even with this policy off, the browsing and download history are not guaranteed to be retained. Users may be able to edit or delete the history database files directly, and the browser itself may expire or archive any or all history items at any time.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdeletingbrowserhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdeletingbrowserhistory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdinosaureasteregg","displayName":"Allow Dinosaur Easter Egg Game","description":"Setting the policy to True allows users to play the dinosaur game. Setting the policy to False means users can't play the dinosaur easter egg game when device is offline.\r\n\r\nLeaving the policy unset means users can't play the game on enrolled Google Chrome OS, but can under other circumstances.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdinosaureasteregg_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdinosaureasteregg_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace","description":"Setting the policy turns on Chrome's restricted sign-in feature in Google Workspace and prevents users from changing this setting. Users can only access Google tools using accounts from the specified domains (to allow gmail or googlemail accounts, add consumer_accounts to the list of domains). This setting prevents users from signing in and adding a Secondary Account on a managed device that requires Google authentication, if that account doesn't belong to one of the explicitly allowed domains.\r\n\r\nLeaving this setting empty or unset means users can access Google Workspace with any account.\r\n\r\nUsers cannot change or override this setting.\r\n\r\nNote: This policy causes the X-GoogApps-Allowed-Domains header to be appended to all HTTP and HTTPS requests to all google.com domains, as described in https://support.google.com/a/answer/1668854.\r\n\r\nExample value: managedchrome.com,example.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowfileselectiondialogs","displayName":"Allow invocation of file selection dialogs","description":"Setting the policy to Enabled or leaving it unset means Chrome can display, and users can open, file selection dialogs.\r\n\r\nSetting the policy to Disabled means that whenever users perform actions provoking a file selection dialog, such as importing bookmarks, uploading files, and saving links, a message appears instead. The user is assumed to have clicked Cancel on the file selection dialog.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowfileselectiondialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowfileselectiondialogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal","displayName":"Allows a page to perform synchronous XHR requests during page dismissal.","description":"This policy allows an admin to specify that a page may send synchronous XHR requests during page dismissal.\r\n\r\nWhen the policy is set to enabled, pages are allowed to send synchronous XHR requests during page dismissal.\r\n\r\nWhen the policy is set to disabled or not set, pages are not allowed to send synchronous XHR requests during page dismissal.\r\n\r\nThis policy will be removed in Chrome 93.\r\n\r\nSee https://www.chromestatus.com/feature/4664843055398912 .","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alternateerrorpagesenabled","displayName":"Enable alternate error pages","description":"Setting the policy to True means Google Chrome uses alternate error pages built into (such as \"page not found\"). Setting the policy to False means Google Chrome never uses alternate error pages.\r\n\r\nIf you set the policy, users can't change it. If not set, the policy is on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alternateerrorpagesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alternateerrorpagesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alwaysopenpdfexternally","displayName":"Always Open PDF files externally","description":"Setting the policy to Enabled turns the internal PDF viewer off in Google Chrome, treats PDF files as a download, and lets users open PDFs with the default application.\r\n\r\nSetting the policy to Disabled means that unless users turns off the PDF plugin, it will open PDF files.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users can choose whether to open PDF externally or not.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alwaysopenpdfexternally_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alwaysopenpdfexternally_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for profile types.","description":"Configuring this policy will allow/disallow ambient authentication for Incognito and Guest profiles in Google Chrome.\r\n\r\nAmbient Authentication is http authentication with default credentials if explicit credentials are not provided via NTLM/Kerberos/Negotiate challenge/response schemes.\r\n\r\nSetting the RegularOnly (value 0), allows ambient authentication for Regular sessions only. Incognito and Guest sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the IncognitoAndRegular (value 1), allows ambient authentication for Incognito and Regular sessions. Guest sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the GuestAndRegular (value 2), allows ambient authentication for Guest and Regular sessions. Incognito sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the All (value 3), allows ambient authentication for all sessions.\r\n\r\nNote that, ambient authentication is always allowed on regular profiles.\r\n\r\nIn Google Chrome version 81 and later, if the policy is left not set, ambient authentication will be enabled in regular sessions only.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for profile types. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_0","displayName":"Enable ambient authentication in regular sessions only.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_1","displayName":"Enable ambient authentication in incognito and regular sessions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_2","displayName":"Enable ambient authentication in guest and regular sessions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_3","displayName":"Enable ambient authentication in regular, incognito and guest sessions.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_applicationlocalevalue","displayName":"Application locale","description":"Setting the policy specifies the locale Google Chrome uses.\r\n\r\nTurning it off or leaving it unset means the locale will be the first valid locale from:\r\n1) The user specified locale (if configured).\r\n2) The system locale.\r\n3) The fallback locale (en-US).\r\n\r\nExample value: en","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_applicationlocalevalue_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_applicationlocalevalue_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_applicationlocalevalue_applicationlocalevalue","displayName":"Application locale (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowed","displayName":"Allow or deny audio capture","description":"Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the AudioCaptureAllowedUrls list, users get prompted for audio capture access.\r\n\r\nSetting the policy to Disabled turns off prompts, and audio capture is only available to URLs set in the AudioCaptureAllowedUrls list.\r\n\r\nNote: The policy affects all audio input (not just the built-in microphone).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowedurls","displayName":"URLs that will be granted access to audio capture devices without prompt","description":"Setting the policy means you specify the URL list whose patterns get matched to the security origin of the requesting URL. A match grants access to audio capture devices without prompt\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com/\r\nhttps://[*.]example.edu/","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowedurls_audiocaptureallowedurlsdesc","displayName":"URLs that will be granted access to audio capture devices without prompt (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audioprocesshighpriorityenabled","displayName":"Allow the audio process to run with priority above normal on Windows","description":"This policy controls the priority of the audio process on Windows.\r\nIf this policy is enabled, the audio process will run with above normal priority.\r\nIf this policy is disabled, the audio process will run with normal priority.\r\nIf this policy is not set, the default configuration for the audio process will be used.\r\nThis policy is intended as a temporary measure to give enterprises the ability to\r\nrun audio with higher priority to address certain performance issues with audio capture.\r\nThis policy will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audioprocesshighpriorityenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audioprocesshighpriorityenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled","displayName":"Allow the audio sandbox to run","description":"This policy controls the audio process sandbox.\r\nIf this policy is enabled, the audio process will run sandboxed.\r\nIf this policy is disabled, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\r\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\r\nIf this policy is not set, the default configuration for the audio sandbox will be used, which may differ per platform.\r\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofilladdressenabled","displayName":"Enable AutoFill for addresses","description":"Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI.\r\n\r\nSetting the policy to False means Autofill never suggests or fills address information, nor does it save additional address information that users submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofilladdressenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofilladdressenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled","displayName":"Enable AutoFill for credit cards","description":"Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI.\r\n\r\nSetting the policy to False means autofill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user","description":"Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator should not be included when listing the protocol, so list \"skype\" instead of \"skype:\" or \"skype://\".\r\n\r\nIf this policy is set, a protocol will only be permitted to launch an external application without prompting by policy if the protocol is listed, and the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list. If either condition is false the external protocol launch prompt will not be omitted by policy.\r\n\r\nIf this policy is not set, no protocols can launch without a prompt by default. Users may opt out of prompts on a per-protocol/per-site basis unless the ExternalProtocolDialogShowAlwaysOpenCheckbox policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' policy, which are documented at http://www.chromium.org/administrators/url-blocklist-filter-format.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=AutoLaunchProtocolsFromOrigins for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"protocol\": \"spotify\",\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"teams\",\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"outlook\",\r\n \"allowed_origins\": [\r\n \"*\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenallowedforurls","displayName":"URLs where AutoOpenFileTypes can apply","description":"List of URLs specifying which urls AutoOpenFileTypes will apply to. This policy has no impact on automatically open values set by users.\r\n\r\nIf this policy is set, files will only automatically open by policy if the url is part of this set and the file type is listed in AutoOpenFileTypes. If either condition is false the download won't automatically open by policy.\r\n\r\nIf this policy isn't set, all downloads where the file type is in AutoOpenFileTypes will automatically open.\r\n\r\nA URL pattern has to be formatted according to https://www.chromium.org/administrators/url-blocklist-filter-format.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenallowedforurls_autoopenallowedforurlsdesc","displayName":"URLs where AutoOpenFileTypes can apply (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes","displayName":"List of file types that should be automatically opened on download","description":"List of file types that should be automatically opened on download. The leading separator should not be included when listing the file type, so list \"txt\" instead of \".txt\".\r\n\r\nFiles with types that should be automatically opened will still be subject to the enabled safe browsing checks and won't be opened if they fail those checks.\r\n\r\nIf this policy isn't set, only file types that a user has already specified to automatically be opened will do so when downloaded.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nexe\r\ntxt","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes_autoopenfiletypesdesc","displayName":"List of file types that should be automatically opened on download (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowed","displayName":"Allow media autoplay","description":"Setting the policy to True lets Google Chrome autoplay media. Setting the policy to False stops Google Chrome from autoplaying media.\r\n\r\n By default, Google Chrome doesn't autoplay media. But, for certain URL patterns, you can use the AutoplayAllowlist policy to change this setting.\r\n\r\nIf this policy changes while Google Chrome is running, it only applies to newly opened tabs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowlist","displayName":"Allow media autoplay on a allowlist of URL patterns","description":"Setting the policy lets videos play automatically (without user consent) with audio content in Google Chrome. If AutoplayAllowed policy is set to True, then this policy has no effect. If AutoplayAllowed is set to False, then any URL patterns set in this policy can still play. If this policy changes while Google Chrome is running, it only applies to newly opened tabs.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowlist_autoplayallowlistdesc","displayName":"Allow media autoplay on a allowlist of URL patterns (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_backgroundmodeenabled","displayName":"Continue running background apps when Google Chrome is closed","description":"Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there.\r\n\r\nSetting the policy to Disabled turns background mode off.\r\n\r\nIf you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_backgroundmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_backgroundmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_blockthirdpartycookies","displayName":"Block third party cookies","description":"Setting the policy to Enabled prevents webpage elements that aren't from the domain that's in the browser's address bar from setting cookies. Setting the policy to Disabled lets those elements set cookies and prevents users from changing this setting.\r\n\r\nLeaving it unset turns third-party cookies on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_blockthirdpartycookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_blockthirdpartycookies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_bookmarkbarenabled","displayName":"Enable Bookmark Bar","description":"Setting the policy to True displays a bookmark bar in Google Chrome. Setting the policy to False means users never see the bookmark bar.\r\n\r\nIf you set the policy, users can't change it. If not set, users decide whether to use this function.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_bookmarkbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_bookmarkbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browseraddpersonenabled","displayName":"Enable add person in user manager","description":"If this policy is set to true or not configured, Google Chrome will allow Add Person from the user manager.\r\n\r\nIf this policy is set to false, Google Chrome will not allow creation of new profiles from the user manager.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browseraddpersonenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browseraddpersonenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenabled","displayName":"Enable guest mode in browser","description":"If this policy is set to true or not configured, Google Chrome will enable guest logins. Guest logins are Google Chrome profiles where all windows are in incognito mode.\r\n\r\nIf this policy is set to false, Google Chrome will not allow guest profiles to be started.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenforced","displayName":"Enforce browser guest mode","description":"Setting the policy to Enabled means Google Chrome enforces guest sessions and prevents profile sign-ins. Guest sign-ins are Google Chrome profiles where windows are in Incognito mode.\r\n\r\nSetting the policy to Disabled, leaving it unset, or disabling browser Guest mode (through BrowserGuestModeEnabled) allows the use of new and existing profiles.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenforced_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenforced_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlabsenabled","displayName":"Browser experiments icon in toolbar","description":"Setting the policy to Enabled or leaving the policy unset means that users can access browser experimental features through an icon in the toolbar\r\n\r\nSetting the policy to Disabled removes the browser experimental features icon from the toolbar.\r\n\r\nchrome://flags and any other means of turning off and on browser features will still behave as expected regardless of whether this policy is Enabled or Disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlegacyextensionpointsblocked","displayName":"Block Browser Legacy Extension Points","description":"Setting the policy to Enabled or leaving it unset will enable ProcessExtensionPointDisablePolicy to block legacy extension points in the Browser process.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security and stability as unknown and potentially hostile code can load inside Google Chrome's browser process. Only turn off the policy if there are compatibility issues with third-party software that must run inside Google Chrome's browser process.\r\n\r\nNote: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlegacyextensionpointsblocked_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlegacyextensionpointsblocked_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsernetworktimequeriesenabled","displayName":"Allow queries to a Google time service","description":"Setting the policy to Enabled or leaving it unset means Google Chrome send occasional queries to a Google server to retrieve an accurate timestamp.\r\n\r\nSetting the policy to Disabled stops Google Chrome from sending these queries.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsernetworktimequeriesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsernetworktimequeriesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin","displayName":"Browser sign in settings","description":"This policy controls the sign-in behavior of the browser. It allows you to specify if the user can sign in to Google Chrome with their account and use account related services like Google Chrome Sync.\r\n\r\nIf the policy is set to \"Disable browser sign-in\" then the user cannot sign in to the browser and use account-based services. In this case browser-level features like Google Chrome Sync cannot be used and will be unavailable. On iOS, if the user was signed in and the policy is set to \"Disabled\" they will be signed out immediately. On other platforms, they will be signed out the next time they run Google Chrome. On all platforms, their local profile data like bookmarks, passwords etc. will be preserved and still usable. The user will still be able to sign into and use Google web services like Gmail.\r\n\r\nIf the policy is set to \"Enable browser sign-in,\" then the user is allowed to sign in to the browser. On all platforms except iOS, the user is automatically signed in to the browser when signed in to Google web services like Gmail. Being signed in to the browser means the user's account information will be kept by the browser. However, it does not mean that Google Chrome Sync will be turned on by default; the user must separately opt-in to use this feature. Enabling this policy will prevent the user from turning off the setting that allows browser sign-in. To control the availability of Google Chrome Sync, use the SyncDisabled policy.\r\n\r\nIf the policy is set to \"Force browser sign-in\" the user is presented with an account selection dialog and has to choose and sign in to an account to use the browser. This ensures that for managed accounts the policies associated with the account are applied and enforced. The default value of BrowserGuestModeEnabled will be set to disabled. Note that existing unsigned profiles will be locked and inaccessible after enabling this policy. For more information, see help center article: https://support.google.com/chrome/a/answer/7572556 . This option is not supported on Linux, Android or iOS. It will fall back to \"Enable browser sign-in\" if used.\r\n\r\nIf this policy is not set then the user can decide if they want to enable browser sign-in in the Google Chrome settings and use it as they see fit.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin_browsersignin","displayName":"Browser sign in settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin_browsersignin_0","displayName":"Disable browser sign-in","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin_browsersignin_1","displayName":"Enable browser sign-in","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsersignin_browsersignin_2","displayName":"Force users to sign-in to use the browser","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor","displayName":"Configure the color of the browser's theme","description":"This policy allows admins to configure the color of Google Chrome's theme. The input string should be a valid hex color string matching the format \"#RRGGBB\".\r\n\r\nSetting the policy to a valid hex color causes a theme based on that color to be automatically generated and applied to the browser. Users won't be able to change the theme set by the policy.\r\n\r\nLeaving the policy unset lets users change their browser's theme as preferred.\r\n\r\nExample value: #FFFFFF","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor_browserthemecolor","displayName":"Configure the color of the browser's theme (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings","description":"Configures browsing data lifetime settings for Google Chrome. This policy allows admins to configure (per data-type) when data is deleted by the browser. This is useful for customers that work with sensitive customer data. The policy will only take effect if SyncDisabled is set to true.\r\n\r\nThe available data types are 'browsing_history', 'download_history', 'cookies_and_other_site_data', 'cached_images_and_files', 'password_signin', 'autofill', 'site_settings' and 'hosted_app_data'.\r\n\r\nThe browser will automatically remove data of selected types that is older than 'time_to_live_in_hours'. The minimum value that can be set is 1 hour.\r\n\r\nThe deletion of expired data will happen 15 seconds after the browser starts then every hour while the browser is running.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=BrowsingDataLifetime for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"time_to_live_in_hours\": 24,\r\n \"data_types\": [\r\n \"browsing_history\"\r\n ]\r\n },\r\n {\r\n \"time_to_live_in_hours\": 12,\r\n \"data_types\": [\r\n \"password_signin\",\r\n \"autofill\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_builtindnsclientenabled","displayName":"Use built-in DNS client","description":"This policy controls which software stack is used to communicate with the DNS server: the Operating System DNS client, or Google Chrome's built-in DNS client. This policy does not affect which DNS servers are used: if, for example, the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It also does not control if DNS-over-HTTPS is used; Google Chrome will always use the built-in resolver for DNS-over-HTTPS requests. Please see the DnsOverHttpsMode policy for information on controlling DNS-over-HTTPS.\r\n\r\nIf this policy is set to Enabled, the built-in DNS client will be used, if available.\r\n\r\nIf this policy is set to Disabled, the built-in DNS client will only be used when DNS-over-HTTPS is in use.\r\n\r\nIf this policy is left unset, the built-in DNS client will be enabled by default on macOS, Android (when neither Private DNS nor VPN are enabled) and Google Chrome OS.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_builtindnsclientenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_builtindnsclientenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled","displayName":"CECPQ2 post-quantum key-agreement enabled for TLS","description":"If this policy is not configured, or is set to enabled, then Google Chrome will follow the default rollout process for CECPQ2, a post-quantum key-agreement algorithm in TLS.\r\n\r\nCECPQ2 results in larger TLS messages which, in very rare cases, can trigger bugs in some networking hardware. This policy can be set to False to disable CECPQ2 while networking issues are resolved.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Google Chrome.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforcas","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes","description":"Setting the policy turns off enforcement of Certificate Transparency disclosure requirements for a list of subjectPublicKeyInfo hashes. Enterprise hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed). To turn off enforcement, the hash must meet one of these conditions:\r\n\r\n* It's of the server certificate's subjectPublicKeyInfo.\r\n\r\n* It's of a subjectPublicKeyInfo that appears in a Certificate Authority (CA) certificate in the certificate chain. That CA certificate is constrained through the X.509v3 nameConstraints extension, one or more directoryName nameConstraints are present in the permittedSubtrees, and the directoryName has an organizationName attribute.\r\n\r\n* It's of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, the CA certificate has one or more organizationName attributes in the certificate Subject, and the server's certificate has the same number of organizationName attributes, in the same order, and with byte-for-byte identical values.\r\n\r\nSpecify a subjectPublicKeyInfo hash by linking the hash algorithm name, a slash, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. Base64 encoding format matches that of an SPKI Fingerprint. The only recognized hash algorithm is sha256; others are ignored.\r\n\r\nLeaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforcas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforcas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforcas_certificatetransparencyenforcementdisabledforcasdesc","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas","displayName":"Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities","description":"Setting the policy turns off enforcement of Certificate Transparency disclosure requirements for a list of Legacy Certificate Authorities (CA) for certificate chains with a specified subjectPublicKeyInfo hash. Enterprise hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed). To turn off enforcement, the subjectPublicKeyInfo hash must appear in a CA certificate recognized as a Legacy CA. A Legacy CA is publicly trusted by one or more operating systems supported by Google Chrome, but not Android Open Source Project or Google Chrome OS.\r\n\r\nSpecify a subjectPublicKeyInfo hash by linking the hash algorithm name, a slash and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. Base64 encoding format matches that of an SPKI Fingerprint. The only recognized hash algorithm is sha256; others are ignored.\r\n\r\nLeaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_certificatetransparencyenforcementdisabledforlegacycasdesc","displayName":"Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforurls","displayName":"Disable Certificate Transparency enforcement for a list of URLs","description":"Setting the policy turns off Certificate Transparency disclosure requirements for the hostnames in the specified URLs. While making it harder to detect misissued certificates, hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed).\r\n\r\nLeaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.\r\n\r\nA URL pattern follows this format ( https://www.chromium.org/administrators/url-blocklist-filter-format ). However, because the validity of certificates for a given hostname is independent of the scheme, port, or path, Google Chrome only considers the hostname portion of the URL. Wildcard hosts aren't supported.\r\n\r\nExample value:\r\n\r\nexample.com\r\n.example.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforurls_certificatetransparencyenforcementdisabledforurlsdesc","displayName":"Disable Certificate Transparency enforcement for a list of URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromecleanupenabled","displayName":"Enable Chrome Cleanup on Windows","description":"Setting the policy to Enabled or leaving it unset means Chrome Cleanup periodically scans the system for unwanted software and should any be found, will ask the user if they wish to remove it. Manually triggering Chrome Cleanup from chrome://settings is allowed.\r\n\r\nSetting the policy to Disabled means Chrome Cleanup won't periodically scan and manual triggering is disabled.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromecleanupenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromecleanupenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromecleanupreportingenabled","displayName":"Control how Chrome Cleanup reports data to Google","description":"Setting the policy to Enabled means if Chrome Cleanup detects unwanted software, it may, in line with policy set by SafeBrowsingExtendedReportingEnabled, report about the scan to Google. Chrome Cleanup asks users if they want the cleanup. It sends results to Google.\r\n\r\nSetting the policy to Disabled means if Chrome Cleanup detects unwanted software, it won't report about the scan to Google, regardless of the value of SafeBrowsingExtendedReportingEnabled. Chrome Cleanup asks users if they want the cleanup. The results aren't reported to Google.\r\n\r\nLeaving the policy unset means Chrome Cleanup may, in line with policy set by SafeBrowsingExtendedReportingEnabled, report about scans for detecting unwanted software to Google. Chrome Cleanup asks users if they want the cleanup and to share the results with Google to help with future unwanted software detection. These results have file metadata, automatically installed extensions, and registry keys, as described by the Chrome Privacy Whitepaper.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromecleanupreportingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromecleanupreportingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations","displayName":"Determine the availability of variations","description":"Configuring this policy allows to specify which variations are allowed to be applied in Google Chrome.\r\n\r\nVariations provide a means for offering modifications to Google Chrome without shipping a new version of the browser by selectively enabling or disabling already existing features. See https://support.google.com/chrome/a?p=Manage_the_Chrome_variations_framework for more information.\r\n\r\nSetting the VariationsEnabled (value 0), or leaving the policy not set allows all variations to be applied to the browser.\r\n\r\nSetting the CriticalFixesOnly (value 1), allows only variations considered critical security or stability fixes to be applied to Google Chrome.\r\n\r\nSetting the VariationsDisabled (value 2), prevent all variations from being applied to the browser. Please note that this mode can potentially prevent the Google Chrome developers from providing critical security fixes in a timely manner and is thus not recommended.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations","displayName":"Determine the availability of variations (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_0","displayName":"Enable all variations","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_1","displayName":"Enable variations concerning critical fixes only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_2","displayName":"Disable all variations","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist","displayName":"Clear Browsing Data on Exit","description":"Configures a list of browsing data types that should be deleted when the user closes all browser windows. The available data types are browsing history (browsing_history), download history (download_history), cookies (cookies_and_other_site_data), cache(cached_images_and_files), autofill (autofill), passwords (password_signin), site settings (site_settings) and hosted apps data (hosted_app_data). This policy does not take precedence over AllowDeletingBrowserHistory.\r\n\r\nThis policy requires the SyncDisabled policy to be set to true, otherwise it will be ignored. If this policy is set at platform level, Sync should be disabled at platform level. If this policy is set at user level, Sync should be disabled for that user in order for this policy to take effect.\r\n\r\nIf Google Chrome does not exit cleanly (for example, if the browser or the OS crashes), the browsing data will be cleared the next time the profile is loaded.\r\n\r\nExample value:\r\n\r\nbrowsing_history\r\ndownload_history\r\ncookies_and_other_site_data\r\ncached_images_and_files\r\npassword_signin\r\nautofill\r\nsite_settings\r\nhosted_app_data","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist_clearbrowsingdataonexitlistdesc","displayName":"Clear Browsing Data on Exit (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clicktocallenabled","displayName":"Enable the Click to Call Feature","description":"Enable the Click to Call feature which allows users to send phone numbers from Chrome Desktops to an Android device when the user is Signed-in. For more information, see help center article: https://support.google.com/chrome/answer/9430554?hl=en.\r\n\r\nIf this policy is set to enabled, the capability of sending phone numbers to Android devices will be enabled for the Chrome user.\r\n\r\nIf this policy is set to disabled, the capability of sending phone numbers to Android devices will be disabled for the Chrome user.\r\n\r\nIf you set this policy, users cannot change or override it.\r\n\r\nIf this policy is left unset, the Click to Call feature is enabled by default.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clicktocallenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clicktocallenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmentmandatory","displayName":"Enable mandatory cloud management enrollment","description":"Setting the policy to Enabled mandates Chrome Browser Cloud Management enrollment and blocks Google Chrome launch process if failed.\r\n\r\nSetting the policy to Disabled or leaving it unset renders Chrome Browser Cloud Management optional and doesn't block Google Chrome launch process if failed.\r\n\r\nMachine scope cloud policy enrollment on desktop uses this policy. See https://support.google.com/chrome/a/answer/9301891?ref_topic=9301744 for details.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmentmandatory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmentmandatory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmenttoken","displayName":"The enrollment token of cloud policy on desktop","description":"Setting the policy means Google Chrome tries to register itself with Chrome Browser Cloud Management. The value of this policy is an enrollment token you can retrieve from the Google Admin console.\r\n\r\nSee https://support.google.com/chrome/a/answer/9301891?ref_topic=9301744 for details.\r\n\r\nExample value: 37185d02-e055-11e7-80c1-9a214cf093ae","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmenttoken_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmenttoken_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudmanagementenrollmenttoken_cloudmanagementenrollmenttoken","displayName":"The enrollment token of cloud policy on desktop (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudpolicyoverridesplatformpolicy","displayName":"Google Chrome cloud policy overrides Platform policy.","description":"Setting the policy to Enabled means cloud policy takes precedence if it conflicts with platform policy.\r\n\r\nSetting the policy to Disabled or leaving it unset means platform policy takes precedence if it conflicts with cloud policy.\r\n\r\nThis mandatory policy affects machine scope cloud policies.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudpolicyoverridesplatformpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudpolicyoverridesplatformpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clouduserpolicymerge","displayName":"Enables merging of user cloud policies into machine-level policies","description":"Setting the policy to Enabled allows policies associated with a Google Workspace account to be merged into machine-level policies.\r\n\r\nOnly policies originating from secure users can be merged. A secure user is affiliated with the organization that manages their browser using Chrome Browser Cloud Management. All other user-level policies will always be ignored.\r\n\r\nPolicies that need to be merged also need to be set in either PolicyListMultipleSourceMergeList or PolicyDictionaryMultipleSourceMergeList. This policy will be ignored if neither of the two aforementioned policies is configured.\r\n\r\nLeaving the policy unset or setting it to Disabled prevents user-level cloud policies from being merged with policies from any other sources.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clouduserpolicymerge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clouduserpolicymerge_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clouduserpolicyoverridescloudmachinepolicy","displayName":"Allow user cloud policies to override Chrome Browser Cloud Management policies.","description":"Setting the policy to Enabled allows policies associated with a Google Workspace account to take precedence if they conflict with Chrome Browser Cloud Management policies.\r\n\r\nOnly policies originating from secure users can be merged. A secure user is affiliated with the organization that manages their browser using Chrome Browser Cloud Management. All other user-level policies will have default precedence.\r\n\r\nThe policy can be combined with CloudPolicyOverridesPlatformPolicy. If both policies are enabled, user cloud policies will also take precedence over conflicting platform policies.\r\n\r\nLeaving the policy unset or setting it to disabled causes user-level cloud policies to have default priority.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clouduserpolicyoverridescloudmachinepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clouduserpolicyoverridescloudmachinepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_commandlineflagsecuritywarningsenabled","displayName":"Enable security warnings for command-line flags","description":"Setting the policy to Enabled or leaving it unset means security warnings appear when potentially dangerous command-line flags are used to launch Chrome.\r\n\r\nSetting the policy to Disabled prevents security warnings from appearing when Chrome is launched with potentially dangerous command-line flags.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_commandlineflagsecuritywarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_commandlineflagsecuritywarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_componentupdatesenabled","displayName":"Enable component updates in Google Chrome","description":"Enables component updates for all components in Google Chrome when not set or set to enabled.\r\n\r\nIf set to disabled, updates to components are disabled. However, some components are exempt from this policy: updates to any component that does not contain executable code, or does not significantly alter the behavior of the browser, or is critical for its security will not be disabled.\r\nExamples of such components include the certificate revocation lists and Safe Browsing data.\r\nSee https://developers.google.com/safe-browsing for more info on Safe Browsing.\r\nPlease note that setting this policy to disabled can potentially prevent the Google Chrome developers from providing critical security fixes in a timely manner and is thus not recommended.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_componentupdatesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_componentupdatesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request headers support","description":"Configures support of CORS non-wildcard request headers.\r\n\r\nGoogle Chrome version 97 introduces support for CORS non-wildcard request headers. When scripts make a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header must be explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. See https://www.chromest atus.com/feature/5768642492891136 for more detail.\r\n\r\nIf this policy is not set, or set to True, Google Chrome will support the CORS non-wildcard request headers and behave as described above.\r\n\r\nWhen this policy is set to False, chrome will allow the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\r\n\r\nThis Enterprise policy is temporary; it's intended to be removed after Google Chrome version 103.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_corsnonwildcardrequestheaderssupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_corsnonwildcardrequestheaderssupport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled","displayName":"Specifies whether WebAssembly modules can be sent cross-origin","description":"\r\nSpecifies whether WebAssembly modules can be sent to another window or worker cross-origin. Cross-origin WebAssembly module sharing will be deprecated as part of the efforts to deprecate document.domain, see https://github.com/mikewest/deprecating-document-domain. This policy allows to re-enable cross-origin WebAssembly module sharing to offer a longer transition period in the deprecation process.\r\n\r\nWhen set to True, sites can send WebAssembly modules also cross-origin without restrictions.\r\n\r\nWhen set to False or not set, sites can only send WebAssembly modules to windows and workers in the same origin.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultbrowsersettingenabled","displayName":"Set Google Chrome as Default Browser","description":"Setting the policy to True has Google Chrome always check whether it's the default browser on startup and, if possible, automatically register itself. Setting the policy to False stops Google Chrome from ever checking if it's the default and turns user controls off for this option.\r\n\r\nLeaving the policy unset means Google Chrome lets users control whether it's the default and, if not, whether user notifications should appear.\r\n\r\nNote: For Microsoft®Windows® administrators, turning this setting on only works for machines running Windows 7. For later versions, you must deploy a \"default application associations\" file that makes Google Chrome the handler for the https and http protocols (and, optionally, the ftp protocol and other file formats). See Chrome Help ( https://support.google.com/chrome?p=make_chrome_default_win ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultbrowsersettingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultbrowsersettingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultsearchprovidercontextmenuaccessallowed","displayName":"Allow default search provider context menu search access","description":"Enables the use of a default search provider on the context menu.\r\n\r\nIf you set this policy to disabled the search context menu item that relies on your default search provider will not be available.\r\n\r\nIf this policy is set to enabled or not set, the context menu item for your default search provider will be available.\r\n\r\nThe policy value is only appled when the DefaultSearchProviderEnabled policy is enabled, and is not applicable otherwise.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultsearchprovidercontextmenuaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultsearchprovidercontextmenuaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_desktopsharinghubenabled","displayName":"Enable desktop sharing in the omnibox and 3-dot menu","description":"Setting the policy to True or leaving it unset lets users share or save the current webpage using actions provided by the desktop sharing hub. The sharing hub is accessed through either an omnibox icon or the 3-dot menu.\r\n\r\nSetting the policy to False removes the sharing icon from the omnibox and the entry from the 3-dot menu.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_desktopsharinghubenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_desktopsharinghubenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability","displayName":"Control where Developer Tools can be used","description":"Setting the policy to 0 (the default) means you can access the developer tools and the JavaScript console, but not in the context of extensions installed by enterprise policy. Setting the policy to 1 means you can access the developer tools and the JavaScript console in all contexts, including that of extensions installed by enterprise policy. Setting the policy to 2 means you can't acess developer tools, and you can't inspect website elements.\r\n\r\nThis setting also turns off keyboard shortcuts and menu or context menu entries to open developer tools or the JavaScript console.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability","displayName":"Control where Developer Tools can be used (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability_0","displayName":"Disallow usage of the Developer Tools on extensions installed by enterprise policy, allow usage of the Developer Tools in other contexts","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability_1","displayName":"Allow usage of the Developer Tools","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability_2","displayName":"Disallow usage of the Developer Tools","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disable3dapis","displayName":"Disable support for 3D graphics APIs","description":"Setting the policy to True (or setting HardwareAccelerationModeEnabled to False) prevents webpages from accessing the WebGL API, and plugins can't use the Pepper 3D API.\r\n\r\nSetting the policy to False or leaving it unset lets webpages use the WebGL API and plugins use the Pepper 3D API, but the browser's default settings might still require command line arguments to use these APIs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disable3dapis_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disable3dapis_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablesafebrowsingproceedanyway","displayName":"Disable proceeding from the Safe Browsing warning page","description":"Setting the policy to Enabled prevents users from proceeding past the warning page the Safe Browsing service shows to the malicious site. This policy only prevents users from proceeding on Safe Browsing warnings such as malware and phishing, not for SSL certificate-related issues such as invalid or expired certificates.\r\n\r\nSetting the policy to Disabled or leaving it unset means users can choose to proceed to the flagged site after the warning appears.\r\n\r\nSee more about Safe Browsing ( https://developers.google.com/safe-browsing ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablesafebrowsingproceedanyway_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablesafebrowsingproceedanyway_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablescreenshots","displayName":"Disable taking screenshots","description":"Setting the policy to True disallows screenshots taken with keyboard shortcuts or extension APIs. Setting the policy to False allows screenshots.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablescreenshots_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablescreenshots_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir","displayName":"Set disk cache directory","description":"Setting the policy has Google Chrome use the directory you provide for storing cached files on the disk—whether or not users specify the --disk-cache-dir flag.\r\n\r\nIf not set, Google Chrome uses the default cache directory, but users can change that setting with the --disk-cache-dir command line flag.\r\n\r\nGoogle Chrome manages the contents of a volume's root directory. So to avoid data loss or other errors, do not set this policy to the root directory or any directory used for other purposes. See the variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: ${user_home}/Chrome_cache","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir_diskcachedir","displayName":"Set disk cache directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachesize","displayName":"Set disk cache size in bytes","description":"Setting the policy to None has Google Chrome use the default cache size for storing cached files on the disk. Users can't change it.\r\n\r\nIf you set the policy, Google Chrome uses the cache size you provide—whether or not users specify the --disk-cache-size flag. (Values below a few megabytes are rounded up.)\r\n\r\nIf not set, Google Chrome uses the default size. Users can change that setting using the --disk-cache-size flag.\r\n\r\nNote: The value specified in this policy is used as a hint to various cache subsystems in the browser. Therefore the actual total disk consumption of all caches will be higher but within the same order of magnitude as the value specified.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachesize_diskcachesize","displayName":"Set disk cache size: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_displaycapturepermissionspolicyenabled","displayName":"Specifies whether the display-capture permissions-policy is checked or skipped.","description":"\r\nThe display-capture permissions-policy gates access to getDisplayMedia(), as per this spec: https://www.w3.org/TR/screen-capture/#feature-policy-integration. However, if this policy is Disabled, this requirement is not enforced, and getDisplayMedia() is allowed from contexts that would otherwise be forbidden. This Enterprise policy is temporary; it's intended to be removed after Google Chrome version 100. It is intended to unblock Enterprise users whose application is non-spec compliant, but needs time to be fixed.\r\n\r\nWhen enabled or not set, sites can only call getDisplayMedia() from contexts which are allowlisted by the display-capture permissions-policy.\r\n\r\nWhen disabled, sites can call getDisplayMedia() even from contexts which are not allowlisted by the display-capture permissions policy. Note that other restrictions may still apply.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_displaycapturepermissionspolicyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_displaycapturepermissionspolicyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsinterceptionchecksenabled","displayName":"DNS interception checks enabled","description":"This policy configures a local switch that can be used to disable DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\r\n\r\nThis detection may not be necessary in an enterprise environment where the network configuration is known, since it causes some amount of DNS and HTTP traffic on start-up and each DNS configuration change.\r\n\r\nWhen this policy is not set, or is enabled, the DNS interception checks are performed. When explicitly disabled, they're not.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsinterceptionchecksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsinterceptionchecksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode","displayName":"Controls the mode of DNS-over-HTTPS","description":"Controls the mode of the DNS-over-HTTPS resolver. Please note that this policy will only set the default mode for each query. The mode may be overridden for special types of queries such as requests to resolve a DNS-over-HTTPS server hostname.\r\n\r\nThe \"off\" mode will disable DNS-over-HTTPS.\r\n\r\nThe \"automatic\" mode will send DNS-over-HTTPS queries first if a DNS-over-HTTPS server is available and may fallback to sending insecure queries on error.\r\n\r\nThe \"secure\" mode will only send DNS-over-HTTPS queries and will fail to resolve on error.\r\n\r\nOn Android Pie and above, if DNS-over-TLS is active, Google Chrome will not send insecure DNS requests.\r\n\r\nIf this policy is unset the browser may send DNS-over-HTTPS requests to a resolver associated with the user's configured system resolver.\r\n\r\nExample value: off","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode","displayName":"Controls the mode of DNS-over-HTTPS (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_off","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_automatic","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_secure","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver","description":"The URI template of the desired DNS-over-HTTPS resolver. To specify multiple DNS-over-HTTPS resolvers, separate the corresponding URI templates with spaces.\r\n\r\nIf the DnsOverHttpsMode is set to \"secure\" then this policy must be set and not empty.\r\n\r\nIf the DnsOverHttpsMode is set to \"automatic\" and this policy is set then the URI templates specified will be used; if this policy is unset then hardcoded mappings will be used to attempt to upgrade the user's current DNS resolver to a DoH resolver operated by the same provider.\r\n\r\nIf the URI template contains a dns variable, requests to the resolver will use GET; otherwise requests will use POST.\r\n\r\nIncorrectly formatted templates will be ignored.\r\n\r\nExample value: https://dns.example.net/dns-query{?dns}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloaddirectory","displayName":"Set download directory","description":"Setting the policy sets up the directory Chrome uses for downloading files. It uses the provided directory, whether or not users specify one or turned on the flag to be prompted for download location every time.\r\n\r\nLeaving the policy unset means Chrome uses the default download directory, and users can change it.\r\n\r\nNote: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloaddirectory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloaddirectory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloaddirectory_downloaddirectory","displayName":"Set download directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions","displayName":"Allow download restrictions","description":"Setting the policy means users can't bypass download security decisions.\r\n\r\nThere are many types of download warnings within Chrome, which roughly break down into these categories (learn more about Safe Browsing verdicts https://support.google.com/chrome/?p=ib_download_blocked):\r\n\r\n* Malicious, as flagged by the Safe Browsing server\r\n* Uncommon or unwanted, as flagged by the Safe Browsing server\r\n* A dangerous file type (e.g. all SWF downloads and many EXE downloads)\r\n\r\nSetting the policy blocks different subsets of these, depending on it's value:\r\n\r\n0: No special restrictions. Default.\r\n\r\n1: Blocks malicious files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n2: Blocks malicious files flagged by the Safe Browsing server AND Blocks uncommon or unwanted files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n3: Blocks all downloads. Not recommended, except for special use cases.\r\n\r\n4: Blocks malicious files flagged by the Safe Browsing server, does not block dangerous file types. Recommended.\r\n\r\nNote: These restrictions apply to downloads triggered from webpage content, as well as the Download link... menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options. Read more about Safe Browsing ( https://developers.google.com/safe-browsing ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_downloadrestrictions","displayName":"Download restrictions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_downloadrestrictions_0","displayName":"No special restrictions. Default.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_downloadrestrictions_2","displayName":"Block malicious downloads, uncommon or unwanted downloads and dangerous file types.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_downloadrestrictions_3","displayName":"Block all downloads.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_downloadrestrictions_4","displayName":"Block malicious downloads. Recommended.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_editbookmarksenabled","displayName":"Enable or disable bookmark editing","description":"Setting the policy to True or leaving it unset lets users add, remove, or modify bookmarks.\r\n\r\nSetting the policy to False means users can't add, remove, or modify bookmarks. They can still use existing bookmarks.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_editbookmarksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_editbookmarksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies","displayName":"Enables experimental policies","description":"Allows Google Chrome to load experimental policies.\r\n\r\nWARNING: Experimental policies are unsupported and subject to change or be removed without notice in future version of the browser!\r\n\r\nAn experimental policy may not be finished or still have known or unknown defects. It may be changed or even removed without any notification. By enabling experimental policies, you could lose browser data or compromise your security or privacy.\r\n\r\nIf a policy is not in the list and it's not officially released, its value will be ignored on Beta and Stable channel.\r\n\r\nIf a policy is in the list and it's not officially released, its value will be applied.\r\n\r\nThis policy has no effect on already released policies.\r\n\r\nExample value:\r\n\r\nExtensionInstallAllowlist\r\nExtensionInstallBlocklist","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies_enableexperimentalpoliciesdesc","displayName":"Enables experimental policies (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableonlinerevocationchecks","displayName":"Enable online OCSP/CRL checks","description":"Setting the policy to True means online OCSP/CRL checks are performed.\r\n\r\nSetting the policy to False or leaving it unset means Google Chrome won't perform online revocation checks in Google Chrome 19 and later.\r\n\r\nNote: OCSP/CRL checks provide no effective security benefit.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableonlinerevocationchecks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableonlinerevocationchecks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled","displayName":"Enables managed extensions to use the Enterprise Hardware Platform API","description":"Setting the policy to True lets extensions installed by enterprise policy use the Enterprise Hardware Platform API.\r\n\r\nSetting the policy to False or leaving it unset prevents extensions from using this API.\r\n\r\nNote: This policy also applies to component extensions, such as the Hangout Services extension.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_explicitlyallowednetworkports","displayName":"Explicitly allowed network ports","description":"There is a list of restricted ports built into Google Chrome. Connections to these ports will fail. This setting permits bypassing that list. The value is a comma-separated list of zero or more ports that outgoing connections will be permitted on.\r\n\r\nPorts are restricted to prevent Google Chrome being used as a vector to exploit various network vulnerabilities. Setting this policy may expose your network to attacks. This policy is intended as a temporary workaround for errors with code \"ERR_UNSAFE_PORT\" while migrating a service running on a blocked port to a standard port (ie. port 80 or 443).\r\n\r\nMalicious websites can easily detect that this policy is set, and for what ports, and use that information to target attacks.\r\n\r\nEach port here is labelled with a date that it can be unblocked until. After that date the port will be restricted regardless of this setting.\r\n\r\nLeaving the value empty or unset means that all restricted ports will be blocked. If there is a mixture of valid and invalid values, the valid ones will be applied.\r\n\r\nThis policy overrides the \"--explicitly-allowed-ports\" command-line option.\r\n\r\nExample value:\r\n\r\n10080","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_explicitlyallowednetworkports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_explicitlyallowednetworkports_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_explicitlyallowednetworkports_explicitlyallowednetworkportsdesc","displayName":"Explicitly allowed network ports (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_externalprotocoldialogshowalwaysopencheckbox","displayName":"Show an \"Always open\" checkbox in external protocol dialog.","description":"This policy controls whether or not the \"Always open\" checkbox is shown on external protocol launch confirmation prompts.\r\n\r\n If this policy is set to True or not set, when an external protocol confirmation is shown, the user can select \"Always allow\" to skip all future confirmation prompts for the protocol on this site.\r\n\r\n If this policy is set to False, the \"Always allow\" checkbox is not displayed and the user will be prompted each time an external protocol is invoked.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_externalprotocoldialogshowalwaysopencheckbox_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_externalprotocoldialogshowalwaysopencheckbox_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on Shutdown","description":"Controls the duration (in seconds) allowed for keepalive requests on browser shutdown.\r\n\r\nWhen specified, browser shutdown can be blocked up to the specified seconds,\r\nto process keepalive (https://fetch.spec.whatwg.org/#request-keepalive-flag) requests.\r\n\r\nThe default value (0) means this feature is disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fetchkeepalivedurationsecondsonshutdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fetchkeepalivedurationsecondsonshutdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fetchkeepalivedurationsecondsonshutdown_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on Shutdown: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages","displayName":"Configure the content and order of preferred languages","description":"This policy allows admins to configure the order of the preferred languages in Google Chrome's settings.\r\n\r\nThe order of the list will appear in the same order under the \"Order languages based on your preference\" section in chrome://settings/languages. Users won't be able to remove or reorder languages set by the policy, but will be able to add languages underneath those set by the policy. Users will also have full control over the browser's UI language and translation/spell check settings, unless enforced by other policies.\r\n\r\nLeaving the policy unset lets users manipulate the entire list of preferred languages.\r\n\r\nExample value:\r\n\r\nen-US","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages_forcedlanguagesdesc","displayName":"Configure the content and order of preferred languages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceephemeralprofiles","displayName":"Ephemeral profile","description":"If set to enabled this policy forces the profile to be switched to ephemeral mode. If this policy is specified as an OS policy (e.g. GPO on Windows) it will apply to every profile on the system; if the policy is set as a Cloud policy it will apply only to a profile signed in with a managed account.\r\n\r\nIn this mode the profile data is persisted on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies and web databases are not preserved after the browser is closed. However this does not prevent the user from downloading any data to disk manually, save pages or print them.\r\n\r\nIf the user has enabled sync all this data is preserved in their sync profile just like with regular profiles. Incognito mode is also available if not explicitly disabled by policy.\r\n\r\nIf the policy is set to disabled or left not set signing in leads to regular profiles.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceephemeralprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceephemeralprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcegooglesafesearch","displayName":"Force Google SafeSearch","description":"Setting the policy to Enabled means SafeSearch in Google Search is always active, and users can't change this setting.\r\n\r\nSetting the policy to Disabled or leaving it unset means SafeSearch in Google Search is not enforced.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcegooglesafesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcegooglesafesearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode","description":"Setting the policy enforces a minimum Restricted mode on YouTube and prevents users from picking a less restricted mode. If you set it to:\r\n\r\n* Strict, Strict Restricted mode on YouTube is always active.\r\n\r\n* Moderate, the user may only pick Moderate Restricted mode and Strict Restricted mode on YouTube, but can't turn off Restricted mode.\r\n\r\n* Off or if no value is set, Restricted mode on YouTube isn't enforced by Chrome. External policies such as YouTube policies might still enforce Restricted mode.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict_forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict_forceyoutuberestrict_0","displayName":"Do not enforce Restricted Mode on YouTube","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict_forceyoutuberestrict_1","displayName":"Enforce at least Moderate Restricted Mode on YouTube","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forceyoutuberestrict_forceyoutuberestrict_2","displayName":"Enforce Strict Restricted Mode for YouTube","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fullscreenallowed","displayName":"Allow fullscreen mode","description":"Setting the policy to True or leaving it unset means that, with appropriate permissions, users, apps, and extensions can enter Fullscreen mode (in which only web content appears).\r\n\r\nSetting the policy to False means users, apps, and extensions can't enter Fullscreen mode.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fullscreenallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fullscreenallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\r\n\r\nIf this policy is unset or disabled, the browser will use the default behavior of cross-site auth, which as of version 80, will be to scope HTTP server authentication credentials by top-level site, so if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites.\r\n\r\nIf the policy is enabled, HTTP auth credentials entered in the context of one site will automatically be used in the context of another.\r\n\r\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\r\n\r\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures, and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_globallyscopehttpauthcacheenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_globallyscopehttpauthcacheenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hardwareaccelerationmodeenabled","displayName":"Use hardware acceleration when available","description":"Setting the policy to Enabled or leaving it unset turns on hardware acceleration, if available.\r\n\r\nSetting the policy to Disabled turns off hardware acceleration.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hardwareaccelerationmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hardwareaccelerationmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode","displayName":"Control use of the Headless Mode","description":"Setting this policy to Enabled or leaving the policy unset allows use of the headless mode. Setting this policy to Disabled denies use of the headless mode.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_headlessmode","displayName":"Control use of the Headless Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_headlessmode_1","displayName":"Allow use of the Headless Mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_headlessmode_2","displayName":"Do not allow use of the Headless Mode","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hidewebstoreicon","displayName":"Hide the web store from the New Tab Page and app launcher","description":"Hide the Chrome Web Store app and footer link from the New Tab Page and Google Chrome OS app launcher.\r\n\r\nWhen this policy is set to true, the icons are hidden.\r\n\r\nWhen this policy is set to false or is not configured, the icons are visible.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hidewebstoreicon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hidewebstoreicon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_historyclustersvisible","displayName":"Show history clusters on the Chrome history page","description":"This policy controls the visibility of history clusters on the Chrome history page.\r\n\r\nIf the policy is set to Enabled, history clusters will be visible at chrome://history/journeys.\r\n\r\nIf the policy is set to Disabled, history clusters will not be visible at chrome://history/journeys.\r\n\r\nIf the policy is left unset, history clusters will be visible at chrome://history/journeys by default and users can change the visibility of history clusters.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_historyclustersvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_historyclustersvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hstspolicybypasslist","displayName":"List of names that will bypass the HSTS policy check","description":"Setting the policy specifies a list of hostnames that bypass preloaded HSTS upgrades from http to https.\r\n\r\nOnly single-label hostnames are allowed in this policy, and this policy only applies to \"static\" HSTS-preloaded entries (for instance, \"app\", \"new\", \"search\", \"play\"). This policy does not prevent HSTS upgrades for servers that have \"dynamically\" requested HSTS upgrades using a Strict-Transport-Security response header.\r\n\r\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific single-label hostnames specified, not to subdomains of those names.\r\n\r\nExample value:\r\n\r\nmeet","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hstspolicybypasslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hstspolicybypasslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hstspolicybypasslist_hstspolicybypasslistdesc","displayName":"List of names that will bypass the HSTS policy check (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled","description":"This policy controls whether users can enable HTTPS-Only Mode in Settings. HTTPS-Only Mode upgrades all navigations to HTTPS.\r\nIf this setting is not set or set to allowed, users will be allowed to enable HTTPS-Only Mode.\r\nIf this setting is set to disallowed, users will not be allowed to enable HTTPS-Only Mode.\r\nForce enabling HTTPS-Only Mode is not currently supported.\r\n\r\nExample value: disallowed","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode_allowed","displayName":"Allow users to enable HTTPS-Only Mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode_disallowed","displayName":"Do not allow users to enable HTTPS-Only Mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode_force_enabled","displayName":"Force enable HTTPS-Only Mode (not supported yet)","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importautofillformdata","displayName":"Import autofill form data from default browser on first run","description":"Setting the policy to Enabled imports autofill form data from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run.\r\n\r\nUsers can trigger an import dialog and the autofill form data checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importautofillformdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importautofillformdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importbookmarks","displayName":"Import bookmarks from default browser on first run","description":"Setting the policy to Enabled imports bookmarks from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run.\r\n\r\nUsers can trigger an import dialog and the bookmarks checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importbookmarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importbookmarks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhistory","displayName":"Import browsing history from default browser on first run","description":"Setting the policy to Enabled imports browsing history from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run.\r\n\r\nUsers can trigger an import dialog and the browsing history checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhistory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhomepage","displayName":"Import of homepage from default browser on first run","description":"Setting the policy to Enabled imports the homepage from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the homepage isn't imported on first run.\r\n\r\nUsers can trigger an import dialog and the homepage checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsavedpasswords","displayName":"Import saved passwords from default browser on first run","description":"Setting the policy to Enabled imports saved passwords from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no saved passwords are imported on first run.\r\n\r\nUsers can trigger an import dialog and the saved passwords checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsavedpasswords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsavedpasswords_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsearchengine","displayName":"Import search engines from default browser on first run","description":"Setting the policy to Enabled imports the default search engine from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run.\r\n\r\nUsers can trigger an import dialog and the default search engine checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsearchengine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsearchengine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability","displayName":"Incognito mode availability","description":"Specifies whether the user may open pages in Incognito mode in Google Chrome.\r\n\r\nIf 'Enabled' is selected or the policy is left unset, pages may be opened in Incognito mode.\r\n\r\nIf 'Disabled' is selected, pages may not be opened in Incognito mode.\r\n\r\nIf 'Forced' is selected, pages may be opened ONLY in Incognito mode. Note that 'Forced' does not work for Android-on-Chrome\r\n\r\nNote: On iOS, if the policy is changed during a session, it will only take effect on relaunch.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability","displayName":"Incognito mode availability (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability_0","displayName":"Incognito mode available","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability_1","displayName":"Incognito mode disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability_2","displayName":"Incognito mode forced","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureformswarningsenabled","displayName":"Enable warnings for insecure forms","description":"This policy controls the treatment for insecure forms (forms that submit over HTTP) embedded in secure (HTTPS) sites in the browser.\r\nIf the policy is enabled or unset, a full page warning will be shown when an insecure form is submitted. Additionally, a warning bubble will be shown next to the form fields when they are focused, and autofill will be disabled for those forms.\r\nIf the policy is disabled, warnings will not be shown for insecure forms, and autofill will work normally.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureformswarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureformswarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowed","displayName":"Specifies whether to allow insecure websites to make requests to more-private network endpoints","description":"Controls whether insecure websites are allowed to make requests to more-private network endpoints.\r\n\r\nThis policy relates to the Private Network Access specification. See https://wicg.github.io/private-network-access/ for more details.\r\n\r\nA network endpoint is more private than another if:\r\n1) Its IP address is localhost and the other is not.\r\n2) Its IP address is private and the other is public.\r\nIn the future, depending on spec evolution, this policy might apply to all cross-origin requests directed at private IPs or localhost.\r\n\r\nA website is deemed secure if it meets the definition of a secure context in https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts. Otherwise, it will be treated as an insecure context.\r\n\r\nWhen this policy is either not set or set to false, the default behavior for requests from insecure contexts to more-private network endpoints will depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests feature, which may be set by a field trial or on the command line.\r\n\r\nWhen this policy is set to true, insecure websites are allowed to make requests to any network endpoint, subject to other cross-origin checks.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts.","description":"List of URL patterns. Private network requests initiated from insecure websites served by matching origins are allowed.\r\n\r\nIf unset, this policy behaves as if set to the empty list.\r\n\r\nFor origins not covered by the patterns specified here, the global default value will be used either from the InsecurePrivateNetworkRequestsAllowed policy, if it is set, or the user's personal configuration otherwise.\r\n\r\nNote that this policy only affects insecure origins, so secure origins (e.g. https://example.com) included in this list will be ignored.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls_insecureprivatenetworkrequestsallowedforurlsdesc","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intensivewakeupthrottlingenabled","displayName":"Control the IntensiveWakeUpThrottling feature.","description":"When enabled the IntensiveWakeUpThrottling feature causes Javascript timers in background tabs to be aggressively throttled and coalesced, running no more than once per minute after a page has been backgrounded for 5 minutes or more.\r\n\r\nThis is a web standards compliant feature, but it may break functionality\r\non some websites by causing certain actions to be delayed by up to a\r\nminute. However, it results in significant CPU and battery savings when\r\nenabled. See https://bit.ly/30b1XR4 for more details.\r\n\r\nIf this policy is set to enabled then the feature will be force enabled, and\r\nusers will not be able to override this.\r\n\r\nIf this policy is set to disabled then the feature will be force disabled, and\r\nusers will not be able to override this.\r\n\r\nIf this policy is left unset then the feature will be controlled by its\r\nown internal logic, which can be manually configured by users.\r\n\r\nNote that the policy is applied per renderer process, with the most recent\r\nvalue of the policy setting in force when a renderer process starts. A full\r\nrestart is required to ensure that all loaded tabs receive a consistent\r\npolicy setting. It is harmless for processes to be running with different\r\nvalues of this policy.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intensivewakeupthrottlingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intensivewakeupthrottlingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior","displayName":"Intranet Redirection Behavior","description":"This policy configures behavior for intranet redirection via DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\r\n\r\nIf this policy is not set, the browser will use the default behavior of DNS interception checks and intranet redirect suggestions. In M88, they are enabled by default but will be disabled by default in the future release.\r\n\r\nDNSInterceptionChecksEnabled is a related policy that may also disable DNS interception checks; this policy is a more flexible version which may separately control intranet redirection infobars and may be expanded in the future.\r\nIf either DNSInterceptionChecksEnabled or this policy requests to disable interception checks, the checks will be disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_intranetredirectbehavior","displayName":"Intranet Redirection Behavior (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_intranetredirectbehavior_0","displayName":"Use default browser behavior.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_intranetredirectbehavior_1","displayName":"Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_intranetredirectbehavior_2","displayName":"Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_intranetredirectbehavior_intranetredirectbehavior_3","displayName":"Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_isolateorigins","displayName":"Enable Site Isolation for specified origins","description":"Setting the policy means each of the named origins in a comma-separated list runs in a dedicated process. Each named origin's process will only be allowed to contain documents from that origin and its subdomains. For example, specifying https://a1.example.com/ allows https://a2.a1.example.com/ in the same process, but not https://example.com or https://b.example.com.\r\n\r\nSince Google Chrome 77, you can also specify a range of origins to isolate using a wildcard. For example, specifying https://[*.]corp.example.com will give every origin underneath https://corp.example.com its own dedicated process, including https://corp.example.com itself, https://a1.corp.example.com, and https://a2.a1.corp.example.com.\r\n\r\nNote that all sites (i.e., scheme plus eTLD+1, such as https://example.com) are already isolated by default on Desktop platforms, as noted in the SitePerProcess policy. This IsolateOrigins policy is useful to isolate specific origins at a finer granularity (e.g., https://a.example.com).\r\n\r\nAlso note that origins isolated by this policy will be unable to script other origins in the same site, which is otherwise possible if two same-site documents modify their document.domain values to match. Administrators should confirm this uncommon behavior is not used on an origin before isolating it.\r\n\r\nSetting the policy to off or leaving it unset lets users change this setting.\r\n\r\nNote: For Android, use the IsolateOriginsAndroid policy instead.\r\n\r\nExample value: https://a.example.com/,https://othersite.org/,https://[*.]corp.example.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_isolateorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_isolateorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_isolateorigins_isolateorigins","displayName":"Enable Site Isolation for specified origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lensregionsearchenabled","displayName":"Allow Google Lens region search menu item to be shown in context menu if supported.","description":"Leaving the policy unset or setting it to Enabled allows users to view and use the Google Lens region search menu item in the context menu. Setting the policy to Disabled means users will not see the Google Lens region search menu item in the context menu when Google Lens region search is supported.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lensregionsearchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lensregionsearchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lockiconinaddressbarenabled","displayName":"Enable lock icon in the omnibox for secure connections","description":"This policy controls the treatment for lock icon in the omnibox.\r\nFrom Chrome M93, there is a new omnibox icon for secure connections.\r\nIf the policy is Enabled, Chrome will use the existing lock icon for secure connections.\r\nIf the policy is Disabled or not set, Chrome will use the default icon for secure connections.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lockiconinaddressbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lockiconinaddressbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains","displayName":"Suppress lookalike domain warnings on domains","description":"This policy prevents the display of lookalike URL warnings on the sites listed. These warnings are typically shown on sites that Google Chrome believes might be trying to spoof another site the user is familiar with.\r\n\r\nIf the policy is enabled and set to one or more domains, no lookalike warnings pages will be shown when the user visits pages on that domain.\r\n\r\nIf the policy is not set, or set to an empty list, warnings may appear on any site the user visits.\r\n\r\nA hostname can be allowed with a complete host match, or any domain match. For example, a URL like \"https://foo.example.com/bar\" may have warnings suppressed if this list includes either \"foo.example.com\" or \"example.com\".\r\n\r\nExample value:\r\n\r\nfoo.example.com\r\nexample.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_lookalikewarningallowlistdomainsdesc","displayName":"Suppress lookalike domain warnings on domains (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction","displayName":"Add restrictions on managed accounts","description":"\r\n This policy requires SigninInterceptionEnabled to be set to True to take effect.\r\n\r\n If this policy is set to 'primary_account' at the machine level, all managed accounts will be forced to be primary.\r\n If this policy is set to 'primary_account' on an account, that account will always be a primary account, but may have secondary accounts in its profile.\r\n\r\n If this policy is set to 'primary_account_strict' at the machine level, all managed accounts will be forced to be primary.\r\n If this policy is set to 'primary_account_strict' on an account, that account will always be a primary account and will not have any secondary accounts in its profile.\r\n\r\n If this policy is set to 'none' or not set, managed accounts have no restrictions. This may result in a managed account being a secondary account, which disables its ability to receive policies set on the account by the admin.\r\n\r\n\r\nExample value: primary_account","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction_managedaccountssigninrestriction","displayName":"Add restrictions on managed accounts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction_managedaccountssigninrestriction_primary_account","displayName":"A Managed account must be a primary account","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction_managedaccountssigninrestriction_primary_account_strict","displayName":"A Managed account must be a primary account and have no secondary accounts","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedaccountssigninrestriction_managedaccountssigninrestriction_none","displayName":"No restrictions on managed accounts","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedbookmarks","displayName":"Managed Bookmarks","description":"Setting the policy sets up a list of bookmarks where each one is a dictionary with the keys \"name\" and \"url\". These keys hold the bookmark's name and target. Admins can set up a subfolder by defining a bookmark without a \"url\" key, but with an additional \"children\" key. This key also has a list of bookmarks, some of which can also be folders. Chrome amends incomplete URLs as if they were submitted through the address bar. For example, \"google.com\" becomes \"https://google.com/\".\r\n\r\nUsers can't change the folders the bookmarks are placed in (though they can hide it from the bookmark bar). The default folder name for managed bookmarks is \"Managed bookmarks\" but it can be changed by adding a new sub-dictionary to the policy with a single key named \"toplevel_name\" with the desired folder name as its value. Managed bookmarks are not synced to the user account and extensions can't modify them.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ManagedBookmarks for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"toplevel_name\": \"My managed bookmarks folder\"\r\n },\r\n {\r\n \"name\": \"Google\",\r\n \"url\": \"google.com\"\r\n },\r\n {\r\n \"name\": \"Youtube\",\r\n \"url\": \"youtube.com\"\r\n },\r\n {\r\n \"name\": \"Chrome links\",\r\n \"children\": [\r\n {\r\n \"name\": \"Chromium\",\r\n \"url\": \"chromium.org\"\r\n },\r\n {\r\n \"name\": \"Chromium Developers\",\r\n \"url\": \"dev.chromium.org\"\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedbookmarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedbookmarks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedbookmarks_managedbookmarks","displayName":"Managed Bookmarks (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedconfigurationperorigin","displayName":"Sets managed configuration values to websites to specific origins","description":"Setting the policy defines the return value of Managed Configuration API for given origin.\r\n\r\n Managed configuration API is a key-value configuration that can be accessed via navigator.managed.getManagedConfiguration() javascript call. This API is only available to origins which correspond to force-installed web applications via WebAppInstallForceList.\r\n\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ManagedConfigurationPerOrigin for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"origin\": \"https://www.google.com\",\r\n \"managed_configuration_url\": \"https://gstatic.google.com/configuration.json\",\r\n \"managed_configuration_hash\": \"asd891jedasd12ue9h\"\r\n },\r\n {\r\n \"origin\": \"https://www.example.com\",\r\n \"managed_configuration_url\": \"https://gstatic.google.com/configuration2.json\",\r\n \"managed_configuration_hash\": \"djio12easd89u12aws\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedconfigurationperorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedconfigurationperorigin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_managedconfigurationperorigin_managedconfigurationperorigin","displayName":"Sets managed configuration values to websites to specific origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxconnectionsperproxy","displayName":"Maximal number of concurrent connections to the proxy server","description":"Setting the policy specifies the maximal number of simultaneous connections to the proxy server. Some proxy servers can't handle a high number of concurrent connections per client, which is solved by setting this policy to a lower value. The value should be lower than 100 and higher than 6. Some web apps are known to consume many connections with hanging GETs, so setting a value below 32 may lead to browser networking hangs if there are too many web apps with hanging connections open. Lower below the default at your own risk.\r\n\r\nLeaving the policy unset means a default of 32 is used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxconnectionsperproxy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxconnectionsperproxy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxconnectionsperproxy_maxconnectionsperproxy","displayName":"Maximal number of concurrent connections to the proxy server: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay","displayName":"Maximum fetch delay after a policy invalidation","description":"Setting the policy specifies the maximum delay in milliseconds between receiving a policy invalidation and fetching the new policy from the device management service. Valid values range from 1,000 (1 second) to 300,000 (5 minutes). Values outside this range will be clamped to the respective boundary.\r\n\r\nLeaving the policy unset means Google Chrome uses the default value of 10 seconds.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay_maxinvalidationfetchdelay","displayName":"Maximum fetch delay after a policy invalidation: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled","displayName":"Enable Media Recommendations","description":"By default the browser will show media recommendations that are personalized to the user. Setting this policy to Disabled will result in these recommendations being hidden from the user. Setting this policy to Enabled or leaving it unset will result in the media recommendations being shown to the user.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediaroutercastallowallips","displayName":"Allow Google Cast to connect to Cast devices on all IP addresses.","description":"Unless EnableMediaRouter is set to Disabled, setting MediaRouterCastAllowAllIPs to Enabled connects Google Cast to Cast devices on all IP addresses, not just RFC1918/RFC4193 private addresses.\r\n\r\nSetting the policy to Disabled connects Google Cast to Cast devices only on RFC1918/RFC4193.\r\n\r\nLeaving the policy unset connects Google Cast to Cast devices only on RFC1918/RFC4193, unless the CastAllowAllIPs feature is turned on.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediaroutercastallowallips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediaroutercastallowallips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_metricsreportingenabled","displayName":"Enable reporting of usage and crash-related data","description":"When this policy is enabled, anonymous reporting of usage and crash-related data about Chrome to Google is enabled by default. Users will still be able to change this setting in the Chrome settings.\r\n\r\nWhen this policy is disabled, anonymous reporting is disabled and no usage or crash data is sent to Google. Users won't be able to change this setting.\r\n\r\nWhen this policy isn't set, users can choose the anonymous reporting behavior at installation or first run, and can later change the setting in the Chrome settings.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain or Windows 10 Pro or Enterprise instances that are enrolled for device management, and macOS instances that are managed via MDM or joined to a domain via MCX.\r\n\r\n(For Chrome OS, see DeviceMetricsReportingEnabled.)","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_metricsreportingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_metricsreportingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions","displayName":"Enable network prediction","description":"This policy controls network prediction in Google Chrome. It controls DNS prefetching, TCP, and SSL preconnection and prerendering of webpages.\r\n\r\nIf you set the policy, users can't change it. Leaving it unset turns on network prediction, but the user can change it.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions","displayName":"Enable network prediction (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_2","displayName":"Do not predict network actions on any network connection","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkservicesandboxenabled","displayName":"Enable the network service sandbox","description":"This policy controls whether or not the network service process runs sandboxed.\r\nIf this policy is enabled, the network service process will run sandboxed.\r\nIf this policy is disabled, the network service process will run unsandboxed. This leaves users open to additional security risks related to running the network service unsandboxed.\r\nIf this policy is not set, the default configuration for the network sandbox will be used. This may vary depending on Google Chrome release, currently running field trials, and platform.\r\nThis policy is intended to give enterprises flexibility to disable the network sandbox if they use third party software that interferes with the network service sandbox.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkservicesandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkservicesandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcardsvisible","displayName":"Show cards on the New Tab Page","description":"This policy controls the visibility of cards on the New Tab Page. Cards surface entry points to launch common user journeys based on the user's browsing behavior.\r\n\r\nIf the policy is set to Enabled, the New Tab Page will show cards if content is available.\r\n\r\nIf the policy is set to Disabled, the New Tab Page won't show cards.\r\n\r\nIf the policy is not set, the user can control the card visibility. The default is visible.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcardsvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcardsvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled","displayName":"Allow users to customize the background on the New Tab page","description":"If the policy is set to false, the New Tab page won't allow users to customize the background. Any existing custom background will be permanently removed even if the policy is set to true later.\r\n\r\nIf the policy is set to true or unset, users can customize the background on the New Tab page.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply","description":"Setting the policy specifies a list of origins (URLs) or hostname patterns (such as *.example.com) for which security restrictions on insecure origins won't apply. Organizations can specify origins for legacy applications that can't deploy TLS or set up a staging server for internal web development, so developers can test out features requiring secure contexts without having to deploy TLS on the staging server. This policy also prevents the origin from being labeled \"Not Secure\" in the address bar.\r\n\r\nSetting a list of URLs in this policy amounts to setting the command-line flag --unsafely-treat-insecure-origin-as-secure to a comma-separated list of the same URLs. The policy overrides the command-line flag and UnsafelyTreatInsecureOriginAsSecure, if present.\r\n\r\nFor more information on secure contexts, see Secure Contexts ( https://www.w3.org/TR/secure-contexts ).\r\n\r\nExample value:\r\n\r\nhttp://testserver.example.com/\r\n*.example.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin_overridesecurityrestrictionsoninsecureorigindesc","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_paymentmethodqueryenabled","displayName":"Allow websites to query for available payment methods.","description":"Allows you to set whether websites are allowed to check if the user has payment methods saved.\r\n\r\nIf this policy is set to disabled, websites that use PaymentRequest.canMakePayment or PaymentRequest.hasEnrolledInstrument API will be informed that no payment methods are available.\r\n\r\nIf the setting is enabled or not set then websites are allowed to check if the user has payment methods saved.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_paymentmethodqueryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_paymentmethodqueryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled","displayName":"Enables the concept of policy atomic groups","description":"Setting the policy to Enabled means policies coming from an atomic group that don't share the source with the highest priority from that group get ignored.\r\n\r\nSetting the policy to Disabled means no policy is ignored because of its source. Policies are ignored only if there's a conflict, and the policy doesn't have the highest priority.\r\n\r\nIf this policy is set from a cloud source, it can't target a specific user.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policydictionarymultiplesourcemergelist","displayName":"Allow merging dictionary policies from different sources","description":"Setting the policy allows merging of selected policies when they come from different sources, with the same scopes and level. This merging is in the first level keys of the dictionary from each source. The key coming from the highest priority source takes precedence.\r\n\r\nIf a policy is in the list and there's conflict between sources with:\r\n\r\n* The same scopes and level: The values merge into a new policy dictionary.\r\n\r\n* Different scopes or level: The policy with the highest priority applies.\r\n\r\nIf a policy isn't in the list and there's conflict between sources, scopes, or level, the policy with the highest priority applies.\r\n\r\nExample value:\r\n\r\nExtensionSettings","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policydictionarymultiplesourcemergelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policydictionarymultiplesourcemergelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policydictionarymultiplesourcemergelist_policydictionarymultiplesourcemergelistdesc","displayName":"Allow merging dictionary policies from different sources (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policylistmultiplesourcemergelist","displayName":"Allow merging list policies from different sources","description":"Setting the policy allows merging of selected policies when they come from different sources, with the same scopes and level.\r\n\r\nIf a policy is in the list and there's conflict between sources with:\r\n\r\n* The same scopes and level: The values merge into a new policy list.\r\n\r\n* Different scopes or level: The policy with the highest priority applies.\r\n\r\nIf a policy isn't in the list and there's conflict between sources, scopes, or level, the policy with the highest priority applies.\r\n\r\nExample value:\r\n\r\nExtensionInstallAllowlist\r\nExtensionInstallBlocklist","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policylistmultiplesourcemergelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policylistmultiplesourcemergelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policylistmultiplesourcemergelist_policylistmultiplesourcemergelistdesc","displayName":"Allow merging list policies from different sources (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyrefreshrate","displayName":"Refresh rate for user policy","description":"Setting the policy specifies the period in milliseconds at which the device management service is queried for user policy information. Valid values range from 1,800,000 (30 minutes) to 86,400,000 (1 day). Values outside this range will be clamped to the respective boundary.\r\n\r\nLeaving the policy unset uses the default value of 3 hours.\r\n\r\nNote: Policy notifications force a refresh when the policy changes, making frequent refreshes unnecessary. So, if the platform supports these notifications, the refresh delay is 24 hours (ignoring defaults and the value of this policy).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyrefreshrate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyrefreshrate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyrefreshrate_policyrefreshrate","displayName":"Refresh rate for user policy: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability","displayName":"Profile picker availability on startup","description":"Specifies whether the profile picker is enabled, disabled or forced at the browser startup.\r\n\r\nBy default the profile picker is not shown if the browser starts in guest or incognito mode, a profile directory and/or urls are specified by command line, an app is explicitly requested to open, the browser was launched by a native notification, there is only one profile available or the policy ForceBrowserSignin is set to true.\r\n\r\nIf 'Enabled' (0) is selected or the policy is left unset, the profile picker will be shown at startup by default, but users will be able to enable/disable it.\r\n\r\nIf 'Disabled' (1) is selected, the profile picker will never be shown, and users will not be able to change the setting.\r\n\r\nIf 'Forced' (2) is selected, the profile picker cannot be suppressed by the user. The profile picker will be shown even if there is only one profile available.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability","displayName":"Profile picker availability on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_0","displayName":"Profile picker available at startup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_1","displayName":"Profile picker disabled at startup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_2","displayName":"Profile picker forced at startup","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promotionaltabsenabled","displayName":"Enable showing full-tab promotional content","description":"Setting the policy to True or leaving it unset lets Google Chrome show users product information as full-tab content.\r\n\r\nSetting the policy to False prevents Google Chrome from showing product information as full-tab content.\r\n\r\nSetting the policy controls the presentation of the welcome pages that help users sign in to Google Chrome, set Google Chrome as users' default browser, or otherwise inform them of product features.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promotionaltabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promotionaltabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promptfordownloadlocation","displayName":"Ask where to save each file before downloading","description":"Setting the policy to Enabled means users are asked where to save each file before downloading. Setting the policy to Disabled has downloads start immediately, and users aren't asked where to save the file.\r\n\r\nLeaving the policy unset lets users change this setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promptfordownloadlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promptfordownloadlocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings","displayName":"Proxy settings","description":"Setting the policy configures the proxy settings for Chrome and ARC-apps, which ignore all proxy-related options specified from the command line.\r\n\r\n Leaving the policy unset lets users choose their proxy settings.\r\n\r\n Setting the ProxySettings policy accepts the following fields:\r\n * ProxyMode, which lets you specify the proxy server Chrome uses and prevents users from changing proxy settings\r\n * ProxyPacUrl, a URL to a proxy .pac file\r\n * ProxyPacMandatory, which prevents the network stack from falling back to direct connections with invalid or unavailable PAC script\r\n * ProxyServer, a URL of the proxy server\r\n * ProxyBypassList, a list of hosts for which the proxy will be bypassed\r\n\r\n The ProxyServerMode field is deprecated in favor of the ProxyMode field.\r\n\r\n For ProxyMode, if you choose the value:\r\n * direct, a proxy is never used and all other fields are ignored.\r\n * system, the systems's proxy is used and all other fields are ignored.\r\n * auto_detect, all other fields are ignored.\r\n * fixed_servers, the ProxyServer and ProxyBypassList fields are used.\r\n * pac_script, the ProxyPacUrl, ProxyPacMandatory and ProxyBypassList fields are used.\r\n\r\nNote: For more detailed examples, visit The Chromium Projects ( https://www.chromium.org/developers/design-documents/network-settings#TOC-Command-line-options-for-proxy-sett ).\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ProxySettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"ProxyMode\": \"fixed_servers\",\r\n \"ProxyServer\": \"123.123.123.123:8080\",\r\n \"ProxyBypassList\": \"https://www.example1.com,https://www.example2.com,https://internalsite/\"\r\n}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings_proxysettings","displayName":"Proxy settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed","displayName":"Allow QUIC protocol","description":"Setting the policy to Enabled or leaving it unset allows the use of QUIC protocol in Google Chrome.\r\n\r\nSetting the policy to Disabled disallows the use of QUIC protocol.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alternateerrorpagesenabled_recommended","displayName":"Enable alternate error pages","description":"Setting the policy to True means Google Chrome uses alternate error pages built into (such as \"page not found\"). Setting the policy to False means Google Chrome never uses alternate error pages.\r\n\r\nIf you set the policy, users can't change it. If not set, the policy is on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alternateerrorpagesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alternateerrorpagesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alwaysopenpdfexternally_recommended","displayName":"Always Open PDF files externally","description":"Setting the policy to Enabled turns the internal PDF viewer off in Google Chrome, treats PDF files as a download, and lets users open PDFs with the default application.\r\n\r\nSetting the policy to Disabled means that unless users turns off the PDF plugin, it will open PDF files.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users can choose whether to open PDF externally or not.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alwaysopenpdfexternally_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alwaysopenpdfexternally_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended","displayName":"Application locale","description":"Setting the policy specifies the locale Google Chrome uses.\r\n\r\nTurning it off or leaving it unset means the locale will be the first valid locale from:\r\n1) The user specified locale (if configured).\r\n2) The system locale.\r\n3) The fallback locale (en-US).\r\n\r\nExample value: en","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended_applicationlocalevalue","displayName":"Application locale (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofilladdressenabled_recommended","displayName":"Enable AutoFill for addresses","description":"Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI.\r\n\r\nSetting the policy to False means Autofill never suggests or fills address information, nor does it save additional address information that users submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofilladdressenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofilladdressenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofillcreditcardenabled_recommended","displayName":"Enable AutoFill for credit cards","description":"Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI.\r\n\r\nSetting the policy to False means autofill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofillcreditcardenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofillcreditcardenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended","displayName":"Continue running background apps when Google Chrome is closed","description":"Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there.\r\n\r\nSetting the policy to Disabled turns background mode off.\r\n\r\nIf you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_blockthirdpartycookies_recommended","displayName":"Block third party cookies","description":"Setting the policy to Enabled prevents webpage elements that aren't from the domain that's in the browser's address bar from setting cookies. Setting the policy to Disabled lets those elements set cookies and prevents users from changing this setting.\r\n\r\nLeaving it unset turns third-party cookies on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_blockthirdpartycookies_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_blockthirdpartycookies_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_bookmarkbarenabled_recommended","displayName":"Enable Bookmark Bar","description":"Setting the policy to True displays a bookmark bar in Google Chrome. Setting the policy to False means users never see the bookmark bar.\r\n\r\nIf you set the policy, users can't change it. If not set, users decide whether to use this function.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_bookmarkbarenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_bookmarkbarenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended","displayName":"Set default download directory","description":"Setting the policy changes the default directory that Chrome downloads files to, but users can change the directory.\r\n\r\nLeaving the policy unset means Chrome uses its platform-specific default directory.\r\n\r\nNote: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_defaultdownloaddirectory","displayName":"Set default download directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultsearchprovidercontextmenuaccessallowed_recommended","displayName":"Allow default search provider context menu search access","description":"Enables the use of a default search provider on the context menu.\r\n\r\nIf you set this policy to disabled the search context menu item that relies on your default search provider will not be available.\r\n\r\nIf this policy is set to enabled or not set, the context menu item for your default search provider will be available.\r\n\r\nThe policy value is only appled when the DefaultSearchProviderEnabled policy is enabled, and is not applicable otherwise.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultsearchprovidercontextmenuaccessallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultsearchprovidercontextmenuaccessallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloaddirectory_recommended","displayName":"Set download directory","description":"Setting the policy sets up the directory Chrome uses for downloading files. It uses the provided directory, whether or not users specify one or turned on the flag to be prompted for download location every time.\r\n\r\nLeaving the policy unset means Chrome uses the default download directory, and users can change it.\r\n\r\nNote: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloaddirectory_recommended_downloaddirectory","displayName":"Set download directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended","displayName":"Allow download restrictions","description":"Setting the policy means users can't bypass download security decisions.\r\n\r\nThere are many types of download warnings within Chrome, which roughly break down into these categories (learn more about Safe Browsing verdicts https://support.google.com/chrome/?p=ib_download_blocked):\r\n\r\n* Malicious, as flagged by the Safe Browsing server\r\n* Uncommon or unwanted, as flagged by the Safe Browsing server\r\n* A dangerous file type (e.g. all SWF downloads and many EXE downloads)\r\n\r\nSetting the policy blocks different subsets of these, depending on it's value:\r\n\r\n0: No special restrictions. Default.\r\n\r\n1: Blocks malicious files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n2: Blocks malicious files flagged by the Safe Browsing server AND Blocks uncommon or unwanted files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n3: Blocks all downloads. Not recommended, except for special use cases.\r\n\r\n4: Blocks malicious files flagged by the Safe Browsing server, does not block dangerous file types. Recommended.\r\n\r\nNote: These restrictions apply to downloads triggered from webpage content, as well as the Download link... menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options. Read more about Safe Browsing ( https://developers.google.com/safe-browsing ).","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions","displayName":"Download restrictions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_0","displayName":"No special restrictions. Default.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_2","displayName":"Block malicious downloads, uncommon or unwanted downloads and dangerous file types.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_3","displayName":"Block all downloads.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_4","displayName":"Block malicious downloads. Recommended.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importautofillformdata_recommended","displayName":"Import autofill form data from default browser on first run","description":"Setting the policy to Enabled imports autofill form data from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run.\r\n\r\nUsers can trigger an import dialog and the autofill form data checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importautofillformdata_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importautofillformdata_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importbookmarks_recommended","displayName":"Import bookmarks from default browser on first run","description":"Setting the policy to Enabled imports bookmarks from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run.\r\n\r\nUsers can trigger an import dialog and the bookmarks checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importbookmarks_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importbookmarks_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importhistory_recommended","displayName":"Import browsing history from default browser on first run","description":"Setting the policy to Enabled imports browsing history from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run.\r\n\r\nUsers can trigger an import dialog and the browsing history checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importhistory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importhistory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsavedpasswords_recommended","displayName":"Import saved passwords from default browser on first run","description":"Setting the policy to Enabled imports saved passwords from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no saved passwords are imported on first run.\r\n\r\nUsers can trigger an import dialog and the saved passwords checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsavedpasswords_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsavedpasswords_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended","displayName":"Import search engines from default browser on first run","description":"Setting the policy to Enabled imports the default search engine from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run.\r\n\r\nUsers can trigger an import dialog and the default search engine checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_metricsreportingenabled_recommended","displayName":"Enable reporting of usage and crash-related data","description":"When this policy is enabled, anonymous reporting of usage and crash-related data about Chrome to Google is enabled by default. Users will still be able to change this setting in the Chrome settings.\r\n\r\nWhen this policy is disabled, anonymous reporting is disabled and no usage or crash data is sent to Google. Users won't be able to change this setting.\r\n\r\nWhen this policy isn't set, users can choose the anonymous reporting behavior at installation or first run, and can later change the setting in the Chrome settings.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain or Windows 10 Pro or Enterprise instances that are enrolled for device management, and macOS instances that are managed via MDM or joined to a domain via MCX.\r\n\r\n(For Chrome OS, see DeviceMetricsReportingEnabled.)","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_metricsreportingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_metricsreportingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended","displayName":"Enable network prediction","description":"This policy controls network prediction in Google Chrome. It controls DNS prefetching, TCP, and SSL preconnection and prerendering of webpages.\r\n\r\nIf you set the policy, users can't change it. Leaving it unset turns on network prediction, but the user can change it.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions","displayName":"Enable network prediction (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions_2","displayName":"Do not predict network actions on any network connection","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_safebrowsingfortrustedsourcesenabled_recommended","displayName":"Enable Safe Browsing for trusted sources","description":"Setting the policy to Enabled or leaving it unset means downloaded files are sent to be analyzed by Safe Browsing, even when it's from a trusted source.\r\n\r\nSetting the policy to Disabled means downloaded files won't be sent to be analyzed by Safe Browsing when it's from a trusted source.\r\n\r\nThese restrictions apply to downloads triggered from webpage content, as well as the Download link menu option. These restrictions don't apply to the save or download of the currently displayed page or to saving as PDF from the printing options.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_safebrowsingfortrustedsourcesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_safebrowsingfortrustedsourcesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_searchsuggestenabled_recommended","displayName":"Enable search suggestions","description":"Setting the policy to True turns on search suggestions in Google Chrome's address bar. Setting the policy to False turns off these search suggestions.\r\n\r\nIf you set the policy, users can't change it. If not set, search suggestions are on at first, but users can turn them off any time.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_searchsuggestenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_searchsuggestenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_showfullurlsinaddressbar_recommended","displayName":"Show Full URLs","description":"This feature enables display of the full URL in the address bar.\r\nIf this policy is set to True, then the full URL will be shown in the address bar, including schemes and subdomains.\r\nIf this policy is set to False, then the default URL display will apply.\r\nIf this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.\r\n","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_showfullurlsinaddressbar_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_showfullurlsinaddressbar_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_spellcheckserviceenabled_recommended","displayName":"Enable or disable spell checking web service","description":"Setting the policy to Enabled puts a Google web service in use to help resolve spelling errors. This policy only controls the use of the online service. Setting the policy to Disabled means this service is never used.\r\n\r\nLeaving the policy unset lets users choose whether to use the spellcheck service.\r\n\r\nThe spell check can always use a downloaded dictionary locally unless the feature is disabled by SpellcheckEnabled in which case this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_spellcheckserviceenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_spellcheckserviceenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_translateenabled_recommended","displayName":"Enable Translate","description":"Setting the policy to True provides translation functionality when it's appropriate for users by showing an integrated translate toolbar in Google Chrome and a translate option on the right-click context menu. Setting the policy to False shuts off all built-in translate features.\r\n\r\nIf you set the policy, users can't change this function. Leaving it unset lets them change the setting.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_translateenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_translateenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended","displayName":"Register protocol handlers","description":"Setting the policy (as recommended only) lets you register a list of protocol handlers, which merge with the ones that the user registers, putting both sets in use. Set the property \"protocol\" to the scheme, such as \"mailto\", and set the property \"URL\" to the URL pattern of the application that handles the scheme specified in the \"protocol\" field. The pattern can include a \"%s\" placeholder, which the handled URL replaces.\r\n\r\nUsers can't remove a protocol handler registered by policy. However, by installing a new default handler, they can change the protocol handlers installed by policy.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=RegisteredProtocolHandlers for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"protocol\": \"mailto\",\r\n \"url\": \"https://mail.google.com/mail/?extsrc=mailto&url=%s\",\r\n \"default\": true\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"962a2377-ad9a-4654-a526-a77c14152fd7","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_registeredprotocolhandlers","displayName":"Register protocol handlers (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"962a2377-ad9a-4654-a526-a77c14152fd7","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended","displayName":"List of alternate URLs for the default search provider","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderAlternateURLs specifies a list of alternate URLs for extracting search terms from the search engine. The URLs should include the string '{searchTerms}'.\r\n\r\nLeaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms.\r\n\r\nExample value:\r\n\r\nhttps://search.my.company/suggest#q={searchTerms}\r\nhttps://search.my.company/suggest/search#q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended_defaultsearchprovideralternateurlsdesc","displayName":"List of alternate URLs for the default search provider (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended","displayName":"Enable the default search provider","description":"Setting the policy to Enabled means a default search is performed when a user enters non-URL text in the address bar. To specify the default search provider, set the rest of the default search policies. If you leave those policies empty, the user can choose the default provider. Setting the policy to Disabled means there's no search when the user enters non-URL text in the address bar.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, the default search provider is on, and users can set the search provider list.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended","displayName":"Default search provider encodings","description":"If DefaultSearchProviderEnabled is on, setting DefaultSearchProviderEncodings specifies the character encodings supported by the search provider. Encodings are code page names such as UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided.\r\n\r\nLeaving DefaultSearchProviderEncodings unset puts UTF-8 in use.\r\n\r\nExample value:\r\n\r\nUTF-8\r\nUTF-16\r\nGB2312\r\nISO-8859-1","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidericonurl_recommended","displayName":"Default search provider icon","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderIconURL specifies the default search provider's favorite icon URL.\r\n\r\nLeaving DefaultSearchProviderIconURL unset means there's no icon for the search provider.\r\n\r\nExample value: https://search.my.company/favicon.ico","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidericonurl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidericonurl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidericonurl_recommended_defaultsearchprovidericonurl","displayName":"Default search provider icon (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended","displayName":"Parameter providing search-by-image feature for the default search provider","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURL specifies the URL of the search engine used for image search. (If DefaultSearchProviderImageURLPostParams is set, then image search requests use the POST method instead.)\r\n\r\nLeaving DefaultSearchProviderImageURL unset means no image search is used.\r\n\r\nExample value: https://search.my.company/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_defaultsearchproviderimageurl","displayName":"Parameter providing search-by-image feature for the default search provider (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended","displayName":"Parameters for image URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURLPostParams specifies the parameters during image search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as {imageThumbnail}, real image thumbnail data replaces it.\r\n\r\nLeaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_defaultsearchproviderimageurlpostparams","displayName":"Parameters for image URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended","displayName":"Default search provider keyword","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider.\r\n\r\nLeaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_defaultsearchproviderkeyword","displayName":"Default search provider keyword (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended","displayName":"Default search provider name","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name.\r\n\r\nLeaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_defaultsearchprovidername","displayName":"Default search provider name (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended","displayName":"Default search provider new tab page URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderNewTabURL specifies the URL of the search engine used to provide a New Tab page.\r\n\r\nLeaving DefaultSearchProviderNewTabURL unset means no new tab page is provided.\r\n\r\nExample value: https://search.my.company/newtab","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended_defaultsearchprovidernewtaburl","displayName":"Default search provider new tab page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended","displayName":"Default search provider search URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURL specifies the URL of the search engine used during a default search. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms.\r\n\r\nYou can specify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\r\n\r\nExample value: https://search.my.company/search?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended","displayName":"Parameters for search URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended_defaultsearchprovidersearchurlpostparams","displayName":"Parameters for search URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended","displayName":"Default search provider suggest URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURL specifies the URL of the search engine to provide search suggestions. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms.\r\n\r\nYou can specify Google's search URL as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nExample value: https://search.my.company/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturlpostparams_recommended","displayName":"Parameters for suggest URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURLPostParams specifies the parameters during suggestion search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSuggestURLPostParams unset unset means suggest search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturlpostparams_recommended_defaultsearchprovidersuggesturlpostparams","displayName":"Parameters for suggest URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_autofillenabled_recommended","displayName":"Enable AutoFill","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"de643352-007f-4a47-8c83-d75a79516b39","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_autofillenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_autofillenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_safebrowsingenabled_recommended","displayName":"Enable Safe Browsing","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"de643352-007f-4a47-8c83-d75a79516b39","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_safebrowsingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_safebrowsingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordleakdetectionenabled_recommended","displayName":"Enable leak detection for entered credentials","description":"Setting the policy to Enabled lets users have Google Chrome check whether usernames and passwords entered were part of a leak.\r\n\r\nIf the policy is set, users can't change it in Google Chrome. If not set, credential leak checking is allowed, but the user can turn it off.\r\n\r\nThis behavior will not trigger if Safe Browsing is disabled (either by policy or by the user). In order to force Safe Browsing on, use the SafeBrowsingEnabled policy or the SafeBrowsingProtectionLevel policy.","helpText":"","infoUrls":[],"categoryId":"6d6b289c-c1e9-4004-b5ab-3123920cf10d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordleakdetectionenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordleakdetectionenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordmanagerenabled_recommended","displayName":"Enable saving passwords to the password manager","description":"Setting the policy to Enabled means users have Google Chrome remember passwords and provide them the next time they sign in to a site.\r\n\r\nSetting the policy to Disabled means users can't save new passwords, but previously saved passwords will still work.\r\n\r\nIf the policy is set, users can't change it in Google Chrome. If not set, the user can turn off password saving.","helpText":"","infoUrls":[],"categoryId":"6d6b289c-c1e9-4004-b5ab-3123920cf10d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordmanagerenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordmanagerenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printheaderfooter_recommended","displayName":"Print Headers and Footers","description":"Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview.\r\n\r\nIf you set the policy, users can't change it. If unset, users decides whether headers and footers appear.","helpText":"","infoUrls":[],"categoryId":"20ceae56-e189-46ec-a440-791ce7454017","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printheaderfooter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printheaderfooter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpdfasimagedefault_recommended","displayName":"Print PDF as Image Default","description":"Controls if Google Chrome makes the Print as image option default to set when printing PDFs.\r\n\r\nWhen this policy is set to Enabled, Google Chrome will default to setting the Print as image option in the Print Preview when printing a PDF.\r\n\r\nWhen this policy is set to Disabled or not set Google Chrome then the user selection for Print as image option will be initially unset. The user will be allowed to select it for each individual PDFs print job, if the option is available.\r\n\r\nFor Microsoft® Windows® or macOS this policy only has an effect if PrintPdfAsImageAvailability is also enabled.","helpText":"","infoUrls":[],"categoryId":"20ceae56-e189-46ec-a440-791ce7454017","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpdfasimagedefault_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpdfasimagedefault_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended","displayName":"Use System Default Printer as Default","description":"Setting the policy to Enabled means Google Chrome uses the OS default printer as the default destination for print preview.\r\n\r\nSetting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.","helpText":"","infoUrls":[],"categoryId":"20ceae56-e189-46ec-a440-791ce7454017","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_clearsitedataonexit_recommended","displayName":"Clear site data on browser shutdown (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_clearsitedataonexit_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_clearsitedataonexit_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturl_recommended","displayName":"Default search provider instant URL","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturl_recommended_defaultsearchproviderinstanturl","displayName":"Default search provider instant URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended","displayName":"Parameters for instant URL which uses POST","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended_defaultsearchproviderinstanturlpostparams","displayName":"Parameters for instant URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchprovidersearchtermsreplacementkey_recommended","displayName":"Parameter controlling search term placement for the default search provider","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchprovidersearchtermsreplacementkey_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchprovidersearchtermsreplacementkey_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchprovidersearchtermsreplacementkey_recommended_defaultsearchprovidersearchtermsreplacementkey","displayName":"Parameter controlling search term placement for the default search provider (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended","displayName":"Enable network prediction","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_instantenabled_recommended","displayName":"Enable Instant","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_instantenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_instantenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended","displayName":"Safe Browsing Protection Level","description":"Allows you to control whether Google Chrome's Safe Browsing feature is enabled and the mode it operates in.\r\n\r\nIf this policy is set to 'NoProtection' (value 0), Safe Browsing is never active.\r\n\r\nIf this policy is set to 'StandardProtection' (value 1, which is the default), Safe Browsing is always active in the standard mode.\r\n\r\nIf this policy is set to 'EnhancedProtection' (value 2), Safe Browsing is always active in the enhanced mode, which provides better security, but requires sharing more browsing information with Google.\r\n\r\nIf you set this policy as mandatory, users cannot change or override the Safe Browsing setting in Google Chrome.\r\n\r\nIf this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting.\r\n\r\nSee https://developers.google.com/safe-browsing for more info on Safe Browsing.","helpText":"","infoUrls":[],"categoryId":"af351b0c-3d9e-4b18-957b-8179e4eaba15","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_safebrowsingprotectionlevel","displayName":"Safe Browsing Protection Level (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"af351b0c-3d9e-4b18-957b-8179e4eaba15","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_safebrowsingprotectionlevel_0","displayName":"Safe Browsing is never active.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_safebrowsingprotectionlevel_1","displayName":"Safe Browsing is active in the standard mode.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_safebrowsingprotectionlevel_2","displayName":"Safe Browsing is active in the enhanced mode. This mode provides better security, but requires sharing more browsing information with Google.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepageisnewtabpage_recommended","displayName":"Use New Tab Page as homepage","description":"Setting the policy to Enabled makes the New Tab page the user's homepage, ignoring any homepage URL location. Setting the policy to Disabled means that their homepage is never the New Tab page, unless the user's homepage URL is set to chrome://newtab.\r\n\r\nIf you set the policy, users can't change their homepage type in Google Chrome. If not set, the user decides whether or not the New Tab page is their homepage.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepageisnewtabpage_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepageisnewtabpage_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepagelocation_recommended","displayName":"Configure the home page URL","description":"Setting the policy sets the default homepage URL in Google Chrome. You open the homepage using the Home button. On desktop, the RestoreOnStartup policies control the pages that open on startup.\r\n\r\nIf the homepage is set to the New Tab Page, by the user or HomepageIsNewTabPage, this policy has no effect.\r\n\r\n The URL needs a standard scheme, such as http://example.com or https://example.com. When this policy is set, users can't change their homepage URL in Google Chrome.\r\n\r\nLeaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepagelocation_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepagelocation_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_homepagelocation_recommended_homepagelocation","displayName":"Home page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended","displayName":"Action on startup","description":"Setting the policy lets you specify system behavior on startup. Turning this setting off amounts to leaving it unset as Google Chrome must have specified start up behavior.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users can change it.\r\n\r\nSetting this policy to RestoreOnStartupIsLastSession turns off some settings that rely on sessions or that perform actions on exit, such as clearing browsing data on exit or session-only cookies.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup","displayName":"Action on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_5","displayName":"Open New Tab Page","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended","displayName":"URLs to open on startup","description":"If RestoreOnStartup is set to RestoreOnStartupIsURLs, then setting RestoreOnStartupURLs to a list of URLs specify which URLs open.\r\n\r\nIf not set, the New Tab page opens on start up.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nhttps://example.com\r\nhttps://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_restoreonstartupurlsdesc","displayName":"URLs to open on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_showhomebutton_recommended","displayName":"Show Home button on toolbar","description":"Setting the policy to Enabled shows the Home button on Google Chrome's toolbar. Setting the policy to Disabled keeps the Home button from appearing.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users chooses whether to show the Home button.","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_showhomebutton_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_showhomebutton_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification","displayName":"Notify a user that a browser relaunch or device restart is recommended or required","description":"Notify users that Google Chrome must be relaunched or Google Chrome OS must be restarted to apply a pending update.\r\n\r\nThis policy setting enables notifications to inform the user that a browser relaunch or device restart is recommended or required. If not set, Google Chrome indicates to the user that a relaunch is needed via subtle changes to its menu, while Google Chrome OS indicates such via a notification in the system tray. If set to 'Recommended', a recurring warning will be shown to the user that a relaunch is recommended. The user can dismiss this warning to defer the relaunch. If set to 'Required', a recurring warning will be shown to the user indicating that a browser relaunch will be forced once the notification period passes. The default period is seven days for Google Chrome and four days for Google Chrome OS, and may be configured via the RelaunchNotificationPeriod policy setting.\r\n\r\nThe user's session is restored following the relaunch/restart.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_relaunchnotification","displayName":"Notify a user that a browser relaunch or device restart is recommended or required (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_relaunchnotification_1","displayName":"Show a recurring prompt to the user indicating that a relaunch is recommended","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_relaunchnotification_2","displayName":"Show a recurring prompt to the user indicating that a relaunch is required","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod","displayName":"Set the time period for update notifications","description":"Allows you to set the time period, in milliseconds, over which users are notified that Google Chrome must be relaunched or that a Google Chrome OS device must be restarted to apply a pending update.\r\n\r\nOver this time period, the user will be repeatedly informed of the need for an update. For Google Chrome OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Google Chrome browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the RelaunchNotification policy follow this same schedule.\r\n\r\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod_relaunchnotificationperiod","displayName":"Time period (milliseconds): (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow","displayName":"Set the time interval for relaunch","description":"Specify a target time window for the end of the relaunch notification period.\r\n\r\nUsers are notified of the need for a browser relaunch or device restart based on the RelaunchNotification and RelaunchNotificationPeriod policy settings. Browsers and devices are forcibly restarted at the end of the notification period when the RelaunchNotification policy is set to 'Required'. This RelaunchWindow policy can be used to defer the end of the notification period so that it falls within a specific time window.\r\n\r\nIf this policy is not set, the default target time window for Google Chrome OS is between 2 AM and 4 AM. The default target time window for Google Chrome is the whole day (i.e., the end of the notification period is never deferred).\r\n\r\nNote: Though the policy can accept multiple items in entries, all but the first item are ignored.\r\nWarning: Setting this policy may delay application of software updates.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=RelaunchWindow for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"entries\": [\r\n {\r\n \"start\": {\r\n \"hour\": 2,\r\n \"minute\": 15\r\n },\r\n \"duration_mins\": 240\r\n }\r\n ]\r\n}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow_relaunchwindow","displayName":"Relaunch time window (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_remotedebuggingallowed","displayName":"Allow remote debugging","description":"Controls whether users may use remote debugging.\r\n\r\nIf this policy is set to Enabled or not set, users may use remote debugging by specifying --remote-debugging-port and --remote-debugging-pipe command line switches.\r\n\r\nIf this policy is set to Disabled, users are not allowed to use remote debugging.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_remotedebuggingallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_remotedebuggingallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_renderercodeintegrityenabled","displayName":"Enable Renderer Code Integrity","description":"Setting the policy to Enabled or leaving it unset turns Renderer Code Integrity on.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security and stability as unknown and potentially hostile code can load inside Google Chrome's renderer processes. Only turn off the policy if there are compatibility issues with third-party software that must run inside Google Chrome's renderer processes.\r\n\r\nNote: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_renderercodeintegrityenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_renderercodeintegrityenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_requireonlinerevocationchecksforlocalanchors","displayName":"Require online OCSP/CRL checks for local trust anchors","description":"Setting the policy to True means Google Chrome always performs revocation checking for successfully validated server certificates signed by locally installed CA certificates. If Google Chrome can't get revocation status information, Google Chrome treats these certificates as revoked (hard-fail).\r\n\r\nSetting the policy to False or leaving it unset means Google Chrome uses existing online revocation-checking settings.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_requireonlinerevocationchecksforlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_requireonlinerevocationchecksforlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_restrictsignintopattern","displayName":"Restrict which Google accounts are allowed to be set as browser primary accounts in Google Chrome","description":"Contains a regular expression which is used to determine which Google accounts can be set as browser primary accounts in Google Chrome (i.e. the account that is chosen during the Sync opt-in flow).\r\n\r\nAn appropriate error is displayed if a user tries to set a browser primary account with a username that does not match this pattern.\r\n\r\nIf this policy is left not set or blank, then the user can set any Google account as a browser primary account in Google Chrome.\r\n\r\nExample value: .*@example\\.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_restrictsignintopattern_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_restrictsignintopattern_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_restrictsignintopattern_restrictsignintopattern","displayName":"Restrict which Google accounts are allowed to be set as browser primary accounts in Google Chrome (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation","displayName":"Set the roaming profile directory","description":"Configures the directory that Google Chrome will use for storing the roaming copy of the profiles.\r\n\r\nIf you set this policy, Google Chrome will use the provided directory to store the roaming copy of the profiles if the RoamingProfileSupportEnabled policy has been enabled. If the RoamingProfileSupportEnabled policy is disabled or left unset the value stored in this policy is not used.\r\n\r\nSee https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used.\r\n\r\nOn non-Windows platforms, this policy must be set for roaming profiles to work.\r\n\r\nOn Windows, if this policy is left unset, the default roaming profile path will be used.\r\n\r\nExample value: ${roaming_app_data}\\chrome-profile","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_roamingprofilelocation","displayName":"Set the roaming profile directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilesupportenabled","displayName":"Enable the creation of roaming copies for Google Chrome profile data","description":"If you enable this setting, the settings stored in Google Chrome profiles like bookmarks, autofill data, passwords, etc. will also be written to a file stored in the Roaming user profile folder or a location specified by the Administrator through the RoamingProfileLocation policy. Enabling this policy disables cloud sync.\r\n\r\nIf this policy is disabled or left not set only the regular local profiles will be used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilesupportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilesupportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safebrowsingfortrustedsourcesenabled","displayName":"Enable Safe Browsing for trusted sources","description":"Setting the policy to Enabled or leaving it unset means downloaded files are sent to be analyzed by Safe Browsing, even when it's from a trusted source.\r\n\r\nSetting the policy to Disabled means downloaded files won't be sent to be analyzed by Safe Browsing when it's from a trusted source.\r\n\r\nThese restrictions apply to downloads triggered from webpage content, as well as the Download link menu option. These restrictions don't apply to the save or download of the currently displayed page or to saving as PDF from the printing options.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safebrowsingfortrustedsourcesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safebrowsingfortrustedsourcesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safesitesfilterbehavior","displayName":"Control SafeSites adult content filtering.","description":"Setting the policy controls the SafeSites URL filter, which uses the Google Safe Search API to classify URLs as pornographic or not.\r\n\r\nWhen this policy is set to:\r\n\r\n* Do not filter sites for adult content, or not set, sites aren't filtered\r\n\r\n* Filter top level sites for adult content, pornographic sites are filtered","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safesitesfilterbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safesitesfilterbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safesitesfilterbehavior_safesitesfilterbehavior","displayName":"Control SafeSites adult content filtering. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safesitesfilterbehavior_safesitesfilterbehavior_0","displayName":"Do not filter sites for adult content","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_safesitesfilterbehavior_safesitesfilterbehavior_1","displayName":"Filter top level sites (but not embedded iframes) for adult content","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sandboxexternalprotocolblocked","displayName":"Allow Chrome to block navigations toward external protocols in sandboxed iframes","description":"Chrome will block navigations toward external protocols inside\r\nsandboxed iframe. See https://chromestatus.com/features/5680742077038592.\r\n\r\nWhen True, this lets Chrome blocks those navigations.\r\n\r\nWhen False, this prevents Chrome from blocking those navigations.\r\n\r\nThis defaults to True: security feature enabled.\r\n\r\nThis can be used by administrators who need more time to update their internal website affected by this new restriction. This Enterprise policy is temporary; it's intended to be removed after Google Chrome version 104.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sandboxexternalprotocolblocked_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sandboxexternalprotocolblocked_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_savingbrowserhistorydisabled","displayName":"Disable saving browser history","description":"Setting the policy to Enabled means browsing history is not saved, tab syncing is off and users can't change this setting.\r\n\r\nSetting the policy to Disabled or leaving it unset saves browsing history.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_savingbrowserhistorydisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_savingbrowserhistorydisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature allows for hyperlinks and address bar URL navigations to target specific text within a web page, which will be scrolled to once the loading of the web page is complete.\r\n\r\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via URL will be enabled.\r\n\r\nIf you disable this policy, web page scrolling to specific text fragments via URL will be disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_searchsuggestenabled","displayName":"Enable search suggestions","description":"Setting the policy to True turns on search suggestions in Google Chrome's address bar. Setting the policy to False turns off these search suggestions.\r\n\r\nIf you set the policy, users can't change it. If not set, search suggestions are on at first, but users can turn them off any time.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_searchsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_searchsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation","displayName":"URLs/domains automatically permitted direct Security Key attestation","description":"Setting the policy specifies URLs and domains for which no prompt appears when attestation certificates from Security Keys are requested. A signal is also sent to the Security Key indicating that individual attestation may be used. Without this, when sites request attestation of Security Keys, users are prompted in Google Chrome version 65 and later.\r\n\r\nURLs will only match as U2F appIDs. Domains only match as webauthn RP IDs. So to cover both U2F and webauthn APIs, list the appID URL and domain for a given site.\r\n\r\nExample value:\r\n\r\nhttps://example.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation_securitykeypermitattestationdesc","displayName":"URLs/domains automatically permitted direct Security Key attestation (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedarraybufferunrestrictedaccessallowed","displayName":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context","description":"\r\nSpecifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context. Google Chrome will require cross-origin isolation when using SharedArrayBuffers from Google Chrome 91 onward (2021-05-25) for Web Compatibility reasons. Additional details can be found on: https://developer.chrome.com/blog/enabling-shared-array-buffer/.\r\n\r\nWhen set to Enabled, sites can use SharedArrayBuffer with no restrictions.\r\n\r\nWhen set to Disabled or not set, sites can only use SharedArrayBuffers when cross-origin isolated.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedarraybufferunrestrictedaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedarraybufferunrestrictedaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedclipboardenabled","displayName":"Enable the Shared Clipboard Feature","description":"Enable the Shared Clipboard feature which allows users to send text between Chrome Desktops and an Android device when Sync is enabled and the user is Signed-in.\r\n\r\nIf this policy is set to true, the capability of sending text, cross device, for chrome user is enabled.\r\n\r\nIf this policy is set to false, the capability of sending text, cross device, for chrome user is disabled.\r\n\r\nIf you set this policy, users cannot change or override it.\r\n\r\nIf this policy is left unset, the shared clipboard feature is enabled by default.\r\n\r\nIt is up to the admins to set policies in all platforms they care about. It's recommended to set this policy to one value in all platforms.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedclipboardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedclipboardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_showappsshortcutinbookmarkbar","displayName":"Show the apps shortcut in the bookmark bar","description":"Setting the policy to True displays the apps shortcut. Setting the policy to False means this shortcut never appears.\r\n\r\nIf you set the policy, users can't change it. If not set, users decide to show or hide the apps shortcut from the bookmark bar context menu.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_showappsshortcutinbookmarkbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_showappsshortcutinbookmarkbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_showfullurlsinaddressbar","displayName":"Show Full URLs","description":"This feature enables display of the full URL in the address bar.\r\nIf this policy is set to True, then the full URL will be shown in the address bar, including schemes and subdomains.\r\nIf this policy is set to False, then the default URL display will apply.\r\nIf this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_showfullurlsinaddressbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_showfullurlsinaddressbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support","description":"Setting the policy to True or leaving it unset means Google Chrome will accept web contents served as Signed HTTP Exchanges.\r\n\r\nSetting the policy to False prevents Signed HTTP Exchanges from loading.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signedhttpexchangeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signedhttpexchangeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signininterceptionenabled","displayName":"Enable signin interception","description":"This settings enables or disables signin interception.\r\n\r\nWhen this policy not set or is set to True, the signin interception dialog triggers when a Google account is added on the web, and the user may benefit from moving this account to another (new or existing) profile.\r\n\r\nWhen this is set to False, the signin interception dialog does not trigger.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signininterceptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signininterceptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_siteperprocess","displayName":"Require Site Isolation for every site","description":"Since Google Chrome 67, site isolation has been enabled by default on all Desktop platforms, causing every site to run in its own process. A site is a scheme plus eTLD+1 (e.g., https://example.com). Setting this policy to Enabled does not change that behavior; it only prevents users from opting out (for example, using Disable site isolation in chrome://flags). Since Google Chrome 76, setting the policy to Disabled or leaving it unset doesn't turn off site isolation, but instead allows users to opt out.\r\n\r\nIsolateOrigins might also be useful for isolating specific origins at a finer granularity than site (e.g., https://a.example.com).\r\n\r\nOn Google Chrome OS version 76 and earlier, set the DeviceLoginScreenSitePerProcess device policy to the same value. (If the values don't match, a delay can occur when entering a user session.)\r\n\r\nNote: For Android, use the SitePerProcessAndroid policy instead.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_siteperprocess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_siteperprocess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckenabled","displayName":"Enable spellcheck","description":"Setting the policy to Enabled turns spellcheck on, and users can't turn it off. On Microsoft® Windows®, Google Chrome OS and Linux®, spellcheck languages can be switched on or off individually, so users can still turn spellcheck off by switching off every spellcheck language. To avoid that, use the SpellcheckLanguage to force-enable specific spellcheck languages.\r\n\r\nSetting the policy to Disabled turns off spellcheck from all sources, and users can't turn it on. The SpellCheckServiceEnabled, SpellcheckLanguage and SpellcheckLanguageBlocklist policies have no effect when this policy is set to False.\r\n\r\nLeaving the policy unset lets users turn spellcheck on or off in the language settings.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguage","displayName":"Force enable spellcheck languages","description":"Force-enables spellcheck languages. Unrecognized languages in the list will be ignored.\r\n\r\nIf you enable this policy, spellcheck will be enabled for the languages specified, in addition to the languages for which the user has enabled spellcheck.\r\n\r\nIf you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences.\r\n\r\nIf the SpellcheckEnabled policy is set to false, this policy will have no effect.\r\n\r\nIf a language is included in both this policy and the SpellcheckLanguageBlocklist policy, this policy is prioritized and the spellcheck language is enabled.\r\n\r\nThe currently supported languages are: af, bg, ca, cs, da, de, el, en-AU, en-CA, en-GB, en-US, es, es-419, es-AR, es-ES, es-MX, es-US, et, fa, fo, fr, he, hi, hr, hu, id, it, ko, lt, lv, nb, nl, pl, pt-BR, pt-PT, ro, ru, sh, sk, sl, sq, sr, sv, ta, tg, tr, uk, vi.\r\n\r\nExample value:\r\n\r\nfr\r\nes","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguage_spellchecklanguagedesc","displayName":"Force enable spellcheck languages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguageblocklist","displayName":"Force disable spellcheck languages","description":"Force-disables spellcheck languages. Unrecognized languages in that list will be ignored.\r\n\r\nIf you enable this policy, spellcheck will be disabled for the languages specified. The user can still enable or disable spellcheck for languages not in the list.\r\n\r\nIf you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences.\r\n\r\nIf the SpellcheckEnabled policy is set to false, this policy will have no effect.\r\n\r\nIf a language is included in both this policy and the SpellcheckLanguage policy, the latter is prioritized and the spellcheck language will be enabled.\r\n\r\nThe currently supported languages are: af, bg, ca, cs, da, de, el, en-AU, en-CA, en-GB, en-US, es, es-419, es-AR, es-ES, es-MX, es-US, et, fa, fo, fr, he, hi, hr, hu, id, it, ko, lt, lv, nb, nl, pl, pt-BR, pt-PT, ro, ru, sh, sk, sl, sq, sr, sv, ta, tg, tr, uk, vi.\r\n\r\nExample value:\r\n\r\nfr\r\nes","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguageblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguageblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellchecklanguageblocklist_spellchecklanguageblocklistdesc","displayName":"Force disable spellcheck languages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckserviceenabled","displayName":"Enable or disable spell checking web service","description":"Setting the policy to Enabled puts a Google web service in use to help resolve spelling errors. This policy only controls the use of the online service. Setting the policy to Disabled means this service is never used.\r\n\r\nLeaving the policy unset lets users choose whether to use the spellcheck service.\r\n\r\nThe spell check can always use a downloaded dictionary locally unless the feature is disabled by SpellcheckEnabled in which case this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckserviceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckserviceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowed","displayName":"Allow proceeding from the SSL warning page","description":"Setting the policy to Enabled or leaving it unset lets users click through warning pages Google Chrome shows when users navigate to sites that have SSL errors.\r\n\r\nSetting the policy to Disabled prevent users from clicking through any warning pages.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowedfororigins","displayName":"Allow proceeding from the SSL warning page on specific origins","description":"If SSLErrorOverrideAllowed is Disabled, setting the policy lets you set a list of origin patterns that specify the sites where a user can click through warning pages Google Chrome shows when users navigate to sites that have SSL errors. Users will not be able to click through SSL warning pages on origins that are not on this list.\r\n\r\nIf SSLErrorOverrideAllowed is Enabled or unset, this policy does nothing.\r\n\r\nLeaving the policy unset means SSLErrorOverrideAllowed applies for all sites.\r\n\r\nFor detailed information on valid input patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowedfororigins_sslerroroverrideallowedfororiginsdesc","displayName":"Allow proceeding from the SSL warning page on specific origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin","displayName":"Minimum SSL version enabled","description":"Setting the policy to a valid value means Google Chrome won't use SSL/TLS versions less than the specified version. Unrecognized values are ignored.\r\n\r\nIf this policy is not set, then Google Chrome will show an error for TLS 1.0 and TLS 1.1, but the user will be able to bypass it.\r\n\r\nIf this policy is set to \"tls1.2\", the user will not be able to bypass this error.\r\n\r\nSupport for setting this policy to \"tls1\" or \"tls1.1\" was removed in version 91. Suppressing the TLS 1.0/1.1 warning is no longer supported.\r\n\r\nExample value: tls1.2","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin","displayName":"Minimum SSL version enabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1","displayName":"TLS 1.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1.1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs","displayName":"Suppress JavaScript Dialogs triggered from different origin subframes","description":"As described in https://www.chromestatus.com/feature/5148698084376576 , JavaScript modal dialogs, triggered by window.alert, window.confirm, and window.prompt, will be blocked in Google Chrome if triggered from a subframe whose origin is different from the main frame origin.\r\nThis policy allows overriding that change.\r\nIf the policy is set to enabled or unset, JavaScript dialogs triggered from a different origin subframe will be blocked.\r\nIf the policy is set to disabled, JavaScript dialogs triggered from a different origin subframe will not be blocked.\r\n\r\nThis policy will be removed in Google Chrome version 95.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressunsupportedoswarning","displayName":"Suppress the unsupported OS warning","description":"Setting the policy to Enabled suppresses the warning that appears when Google Chrome is running on an unsupported computer or operating system.\r\n\r\nSetting the policy to Disabled or leaving it unset means the warnings appear on unsupported systems.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressunsupportedoswarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressunsupportedoswarning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_syncdisabled","displayName":"Disable synchronization of data with Google","description":"Setting the policy to Enabled turns off data synchronization in Google Chrome using Google-hosted synchronization services.\r\nTo fully turn off Chrome Sync services, we recommend that you turn off the service in the Google Admin console.\r\n\r\nIf the policy is set to Disabled or not set, users are allowed to choose whether to use Chrome Sync.\r\n\r\nNote: Do not turn on this policy when RoamingProfileSupportEnabled is Enabled, because that feature shares the same client-side functionality. The Google-hosted synchronization is off completely in this case.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_syncdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_syncdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled","displayName":"List of types that should be excluded from synchronization","description":"If this policy is set all specified data types will be excluded from synchronization both for Chrome Sync as well as for roaming profile synchronization. This can be beneficial to reduce the size of the roaming profile or limit the type of data uploaded to the Chrome Sync Servers.\r\n\r\nThe current data types for this policy are: \"bookmarks\", \"readingList\", \"preferences\", \"passwords\", \"autofill\", \"themes\", \"typedUrls\", \"extensions\", \"apps\", \"tabs\", \"wifiConfigurations\". Those names are case sensitive!\r\n\r\nExample value:\r\n\r\nbookmarks","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled_synctypeslistdisableddesc","displayName":"List of types that should be excluded from synchronization (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank","description":"Setting the policy to Disabled allows popups targeting _blank to access (via JavaScript) the page that requested to open the popup.\r\n\r\nSetting the policy to Enabled or leaving it unset causes the window.opener property to be set to null unless the anchor specifies rel=\"opener\".\r\n\r\nThis policy will be removed in Google Chrome version 95.\r\n\r\nSee https://chromestatus.com/feature/6140064063029248.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_taskmanagerendprocessenabled","displayName":"Enable ending processes in Task Manager","description":"Setting the policy to Disabled prevents users from ending processes in the Task Manager.\r\n\r\nSetting the policy to Enabled or leaving it unset lets users end processes in the Task Manager.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_taskmanagerendprocessenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_taskmanagerendprocessenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_thirdpartyblockingenabled","displayName":"Enable third party software injection blocking","description":"Setting the policy to Enabled or leaving it unset prevents third-party software from injecting executable code into Google Chrome's processes.\r\n\r\nSetting the policy to Disabled allows this software to inject such code into Google Chrome's processes.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_thirdpartyblockingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_thirdpartyblockingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_totalmemorylimitmb","displayName":"Set limit on megabytes of memory a single Chrome instance can use.","description":"Configures the amount of memory that a single Google Chrome instance can use before tabs start being discarded (I.E. the memory used by the tab will be freed and the tab will have to be reloaded when switched to) to save memory.\r\n\r\nIf the policy is set, browser will begin to discard tabs to save memory once the limitation is exceeded. However, there is no guarantee that the browser is always running under the limit. Any value under 1024 will be rounded up to 1024.\r\n\r\nIf this policy is not set, the browser will only begin attempts to save memory once it has detected that the amount of physical memory on its machine is low.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_totalmemorylimitmb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_totalmemorylimitmb_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_totalmemorylimitmb_totalmemorylimitmb","displayName":"Set memory limit for Chrome instances: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled","displayName":"Enable Translate","description":"Setting the policy to True provides translation functionality when it's appropriate for users by showing an integrated translate toolbar in Google Chrome and a translate option on the right-click context menu. Setting the policy to False shuts off all built-in translate features.\r\n\r\nIf you set the policy, users can't change this function. Leaving it unset lets them change the setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_u2fsecuritykeyapienabled","displayName":"Allow using the deprecated U2F Security Key API","description":"If set to Enabled, the deprecated U2F Security Key API can be used and the deprecation reminder prompt shown for U2F API requests is suppressed.\r\n\r\nIf the policy is set to Disabled or left unset, the default behavior will apply.\r\n\r\nThe U2F Security Key API is deprecated and it will be disabled by default in Chrome 98.\r\n\r\nThis is a temporary opt-out mechanism. The U2F API will be removed from Chrome in Chrome 104, at which point this policy will cease to be supported.\r\n\r\nFor more information about the deprecation of the U2F Security Key API, please refer to https://groups.google.com/a/chromium.org/g/blink-dev/c/xHC3AtU_65A.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_u2fsecuritykeyapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_u2fsecuritykeyapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist","displayName":"Allow access to a list of URLs","description":"Setting the policy provides access to the listed URLs, as exceptions to URLBlocklist. See that policy's description for the format of entries of this list. For example, setting URLBlocklist to * will block all requests, and you can use this policy to allow access to a limited list of URLs. Use it to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths, using the format specified at ( https://www.chromium.org/administrators/url-blocklist-filter-format ). The most specific filter determines if a URL is blocked or allowed. The URLAllowlist policy takes precedence over URLBlocklist. This policy is limited to 1,000 entries.\r\n\r\nThis policy also allows enabling the automatic invocation by the browser of external application registered as protocol handlers for the listed protocols like \"tel:\" or \"ssh:\".\r\n\r\nLeaving the policy unset allows no exceptions to URLBlocklist.\r\n\r\nFrom Google Chrome version 92, this policy is also supported in the headless mode.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist_urlallowlistdesc","displayName":"Allow access to a list of URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlblocklist","displayName":"Block access to a list of URLs","description":"Setting the policy prevents webpages with prohibited URLs from loading. It provides a list of URL patterns that specify forbidden URLs. Leaving the policy unset means no URLs are prohibited in the browser. Format the URL pattern according to this format ( https://www.chromium.org/administrators/url-blocklist-filter-format ). Up to 1,000 exceptions can be defined in URLAllowlist.\r\n\r\nFrom Google Chrome version 73, you can block javascript://* URLs. However, it affects only JavaScript entered in the address bar (or, for example, bookmarklets). In-page JavaScript URLs with dynamically loaded data aren't subject to this policy. For example, if you block example.com/abc, then example.com can still load example.com/abc using XMLHTTPRequest.\r\n\r\nFrom Google Chrome version 92, this policy is also supported in the headless mode.\r\n\r\nNote: Blocking internal chrome://* URLs can lead to unexpected errors.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlblocklist_urlblocklistdesc","displayName":"Block access to a list of URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlkeyedanonymizeddatacollectionenabled","displayName":"Enable URL-keyed anonymized data collection","description":"Setting the policy to Enabled means URL-keyed anonymized data collection, which sends URLs of pages the user visits to Google to make searches and browsing better, is always active.\r\n\r\nSetting the policy to Disabled results in no URL-keyed anonymized data collection.\r\n\r\nIf you set the policy, users can't change. If not set, then URL-keyed anonymized data collection at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlkeyedanonymizeddatacollectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlkeyedanonymizeddatacollectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir","displayName":"Set user data directory","description":"Configures the directory that Google Chrome will use for storing user data.\r\n\r\nIf you set this policy, Google Chrome will use the provided directory regardless whether the user has specified the '--user-data-dir' flag or not. To avoid data loss or other unexpected errors this policy should not be set to a directory used for other purposes, because Google Chrome manages its contents.\r\n\r\nSee https://support.google.com/chrome/a?p=Supported_directory_variables for a list of variables that can be used.\r\n\r\nIf this policy is left not set the default profile path will be used and the user will be able to override it with the '--user-data-dir' command line flag.\r\n\r\nExample value: ${users}/${user_name}/Chrome","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir_userdatadir","displayName":"Set user data directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit","displayName":"Limits the number of user data snapshots retained for use in case of emergency rollback.","description":"Following each major version update, Chrome will create a snapshot of certain portions of the user's browsing data for use in case of a later emergency version rollback. If an emergency rollback is performed to a version for which a user has a corresponding snapshot, the data in the snapshot is restored. This allows users to retain such settings as bookmarks and autofill data.\r\n\r\nIf this policy is not set, the default value of 3 is used\r\n\r\nIf the policy is set, old snapshots are deleted as needed to respect the limit. If the policy is set to 0, no snapshots will be taken","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit_userdatasnapshotretentionlimit","displayName":"Limits the number of user data snapshots retained for use in case of emergency rollback.: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userfeedbackallowed","displayName":"Allow user feedback","description":"Setting the policy to Enabled or leaving it unset lets users send feedback to Google through Menu > Help > Report an Issue or key combination.\r\n\r\nSetting the policy to Disabled means users can't send feedback to Google.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userfeedbackallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userfeedbackallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowed","displayName":"Allow or deny video capture","description":"Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the VideoCaptureAllowedUrls list, users get prompted for video capture access.\r\n\r\nSetting the policy to Disabled turns off prompts, and video capture is only available to URLs set in the VideoCaptureAllowedUrls list.\r\n\r\nNote: The policy affects all video input (not just the built-in camera).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowedurls","displayName":"URLs that will be granted access to video capture devices without prompt","description":"Setting the policy means you specify the URL list whose patterns get matched to the security origin of the requesting URL. A match grants access to video capture devices without prompt\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com/\r\nhttps://[*.]example.edu/","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowedurls_videocaptureallowedurlsdesc","displayName":"URLs that will be granted access to video capture devices without prompt (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist","displayName":"Configure list of force-installed Web Apps","description":"Setting the policy specifies a list of web apps that install silently, without user interaction, and which users can't uninstall or turn off.\r\n\r\nEach list item of the policy is an object with a mandatory member:\r\nurl (the URL of the web app to install)\r\n\r\nand 5 optional members:\r\n- default_launch_container\r\n(for how the web app opens—a new tab is the default)\r\n\r\n- create_desktop_shortcut\r\n(True if you want to create Linux and\r\nMicrosoft® Windows® desktop shortcuts).\r\n\r\n- fallback_app_name\r\n(Starting with Google Chrome version 90,\r\nallows you to override the app name if it is not a\r\nProgressive Web App (PWA), or the app name that is temporarily\r\ninstalled if it is a PWA but authentication is required before the\r\ninstallation can be completed. If both\r\ncustom_name and\r\nfallback_app_name are provided,\r\nthe latter will be ignored.)\r\n\r\n- custom_name\r\n(Starting with Google Chrome\r\nversion 96, allows you to permanently override the app name for all web\r\napps and PWAs. Currently only supported on\r\nGoogle Chrome OS.)\r\n\r\n- custom_icon\r\n(Starting with Google Chrome\r\nversion 96, allows you to override the app icon of installed apps. The\r\nicons have to be square, maximal 1 MB in size, and in one of the following\r\nformats: jpeg, png, gif, webp, ico. The hash value has to be the SHA256\r\nhash of the icon file. Currently only supported on\r\nGoogle Chrome OS.)\r\n\r\nSee PinnedLauncherApps for pinning apps to the Google Chrome OS shelf.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebAppInstallForceList for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.google.com/maps\",\r\n \"default_launch_container\": \"window\",\r\n \"create_desktop_shortcut\": true\r\n },\r\n {\r\n \"url\": \"https://docs.google.com\",\r\n \"default_launch_container\": \"tab\"\r\n },\r\n {\r\n \"url\": \"https://docs.google.com/editor\",\r\n \"default_launch_container\": \"window\",\r\n \"fallback_app_name\": \"Editor\"\r\n },\r\n {\r\n \"url\": \"https://docs.google.com/sheets\",\r\n \"default_launch_container\": \"window\",\r\n \"custom_name\": \"Spreadsheets\"\r\n },\r\n {\r\n \"url\": \"https://weather.example.com\",\r\n \"custom_icon\": {\r\n \"url\": \"https://mydomain.example.com/sunny_icon.png\",\r\n \"hash\": \"c28f469c450e9ab2b86ea47038d2b324c6ad3b1e9a4bd8960da13214afd0ca38\"\r\n }\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_webappinstallforcelist","displayName":"URLs for Web Apps to be silently installed. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcallowlegacytlsprotocols","displayName":"Allow legacy TLS/DTLS downgrade in WebRTC","description":"If enabled, WebRTC peer connections can downgrade to obsolete\r\nversions of the TLS/DTLS (DTLS 1.0, TLS 1.0 and TLS 1.1) protocols.\r\nWhen this policy is disabled or not set, these TLS/DTLS versions are\r\ndisabled.\r\n\r\nThis policy is temporary and will be removed in a future version\r\nof Google Chrome.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcallowlegacytlsprotocols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcallowlegacytlsprotocols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtceventlogcollectionallowed","displayName":"Allow collection of WebRTC event logs from Google services","description":"Setting the policy to Enabled means Google Chrome can collect WebRTC event logs from Google services such as Hangouts Meet and upload them to Google. These logs have diagnostic information for debugging issues with audio or video meetings in Google Chrome, such as the time and size of RTP packets, feedback about congestion on the network, and metadata about time and quality of audio and video frames. These logs have no audio or video content from the meeting. To make debugging easier, Google might associate these logs, by means of a session ID, with other logs collected by the Google service itself.\r\n\r\nSetting the policy to Disabled results in no collection or uploading of such logs.\r\n\r\nLeaving the policy unset on versions up to and including M76 means Google Chrome defaults to not being able to collect and upload these logs. Starting at M77, Google Chrome defaults to being able to collect and upload these logs from most profiles affected by cloud-based, user-level enterprise policies. From M77 up to and including M80, Google Chrome can also collect and upload these logs by default from profiles affected by Google Chrome on-premise management.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtceventlogcollectionallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtceventlogcollectionallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling","displayName":"The IP handling policy of WebRTC","description":"This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection. See RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2). When unset, defaults to using all available interfaces.\r\n\r\nExample value: default","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling","displayName":"The IP handling policy of WebRTC (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_default","displayName":"WebRTC will use all available interfaces when searching for the best path.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_default_public_and_private_interfaces","displayName":"WebRTC will only use the interface connecting to the public Internet, but may connect using private IP addresses.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_default_public_interface_only","displayName":"WebRTC will only use the interface connecting to the public Internet, and will not connect using private IP addresses.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_disable_non_proxied_udp","displayName":"WebRTC will use TCP on the public-facing interface, and will only use UDP if supported by a configured proxy.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtclocalipsallowedurls","displayName":"URLs for which local IPs are exposed in WebRTC ICE candidates","description":"Patterns in this list will be matched against the security origin of the requesting URL.\r\nIf a match is found or chrome://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, the local IP addresses are shown in WebRTC ICE candidates.\r\nOtherwise, local IP addresses are concealed with mDNS hostnames.\r\nPlease note that this policy weakens the protection of local IPs if needed by administrators.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n*example.com*","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtclocalipsallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtclocalipsallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtclocalipsallowedurls_webrtclocalipsallowedurlsdesc","displayName":"URLs for which local IPs are exposed in WebRTC ICE candidates (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC","description":"If the policy is set, the UDP port range used by WebRTC is restricted to the specified port interval (endpoints included).\r\n\r\nIf the policy is not set, or if it is set to the empty string or an invalid port range, WebRTC is allowed to use any available local UDP port.\r\n\r\nExample value: 10000-11999","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcudpportrange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcudpportrange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcudpportrange_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_websqlinthirdpartycontextenabled","displayName":"Force WebSQL in third-party contexts to be re-enabled.","description":"WebSQL in third-party contexts (e.g., cross-site iframes) is off by default as of M97 and will be fully removed in M101.\r\nIf this policy is set to false or unset, WebSQL in third party contexts will remain off.\r\nIf this policy is set to true, WebSQL in third-party contexts will be re-enabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_websqlinthirdpartycontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_websqlinthirdpartycontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_windowocclusionenabled","displayName":"Enable Window Occlusion","description":"Enables window occlusion in Google Chrome.\r\n\r\nIf you enable this setting, to reduce CPU and power consumption Google Chrome will detect when a window is covered by other windows, and will suspend work painting pixels.\r\n\r\nIf you disable this setting Google Chrome will not detect when a window is covered by other windows.\r\n\r\nIf this policy is left not set, occlusion detection will be enabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_windowocclusionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_windowocclusionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_wpadquickcheckenabled","displayName":"Enable WPAD optimization","description":"Setting the policy to Enabled or leaving it unset turns on WPAD (Web Proxy Auto-Discovery) optimization in Google Chrome.\r\n\r\nSetting the policy to Disabled turns off WPAD optimization, causing Google Chrome to wait longer for DNS-based WPAD servers.\r\n\r\nWhether or not this policy is set, users can't change the WPAD optimization setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_wpadquickcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_wpadquickcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserparameters","displayName":"Command-line parameters for the alternative browser.","description":"Setting the policy to a list of strings means each string is passed to the alternative browser as separate command-line parameters. On Microsoft® Windows®, the parameters are joined with spaces. On macOS and Linux®, a parameter can have spaces and still be treated as a single parameter.\r\n\r\nIf an parameter contains ${url}, ${url} is replaced with the URL of the page to open. If no parameter contains ${url}, the URL is appended at the end of the command line.\r\n\r\nEnvironment variables are expanded. On Microsoft® Windows®, %ABC% is replaced with the value of the ABC environment variable. On macOS and Linux®, ${ABC} is replaced with the value of the ABC environment variable.\r\n\r\nLeaving the policy unset means only the URL is passed as a command-line parameter.\r\n\r\nExample value:\r\n\r\n-foreground\r\n-new-window\r\n${url}\r\n-profile\r\n%HOME%\\browser_profile","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserparameters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserparameters_alternativebrowserparametersdesc","displayName":"Command-line parameters for the alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserpath","displayName":"Alternative browser to launch for configured websites.","description":"Setting the policy controls which command to use to open URLs in an alternative browser. The policy can be set to one of ${ie}, ${firefox}, ${safari}, ${opera}, ${edge} or a file path. When this policy is set to a file path, that file is used as an executable file. ${ie} is only available on Microsoft® Windows®. ${safari} and ${edge} are only available on Microsoft® Windows® and macOS.\r\n\r\nLeaving the policy unset puts a platform-specific default in use: Internet Explorer® for Microsoft® Windows®, or Safari® for macOS. On Linux®, launching an alternative browser will fail.\r\n\r\nExample value: ${ie}","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserpath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_alternativebrowserpath_alternativebrowserpath","displayName":"Alternative browser to launch for configured websites. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters","displayName":"Command-line parameters for switching from the alternative browser.","description":"Setting the policy to a list of strings means the strings are joined with spaces and passed from Internet Explorer® to Google Chrome as command-line parameters. If an parameter contains ${url}, ${url} is replaced with the URL of the page to open. If no parameter contains ${url}, the URL is appended at the end of the command line.\r\n\r\nEnvironment variables are expanded. On Microsoft® Windows®, %ABC% is replaced with the value of the ABC environment variable.\r\n\r\nLeaving the policy unset means Internet Explorer® only passes the URL to Google Chrome as a command-line parameter.\r\n\r\nNote: If the Legacy Browser Support add-in for Internet Explorer® isn't installed, this policy has no effect.\r\n\r\nExample value:\r\n\r\n--force-dark-mode","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_browserswitcherchromeparametersdesc","displayName":"Command-line parameters for switching from the alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromepath","displayName":"Path to Chrome for switching from the alternative browser.","description":"This policy controls the command to use to open URLs in Google Chrome when switching from Internet Explorer®. This policy can be set to an executable file path or ${chrome} to autodetect the location of Google Chrome.\r\n\r\nLeaving the policy unset means Internet Explorer® autodetects Google Chrome's own executable path when launching Google Chrome from Internet Explorer.\r\n\r\nNote: If the Legacy Browser Support add-in for Internet Explorer® isn't installed, this policy has no effect.\r\n\r\nExample value: ${chrome}","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromepath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromepath_browserswitcherchromepath","displayName":"Path to Chrome for switching from the alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay","displayName":"Delay before launching alternative browser (milliseconds)","description":"Setting the policy to a number has Google Chrome show a message for that number of milliseconds, then it opens an alternative browser.\r\n\r\nLeaving the policy unset or set to 0 means navigating to a designated URL immediately opens it in an alternative browser.","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay_browserswitcherdelay","displayName":"Delay before launching alternative browser (milliseconds): (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherenabled","displayName":"Enable the Legacy Browser Support feature.","description":"Setting the policy to Enabled means Google Chrome will try to launch some URLs in an alternate browser, such as Internet Explorer®. This feature is set using the policies in the Legacy Browser support group.\r\n\r\nSetting the policy to Disabled or leaving it unset means Google Chrome won't try to launch designated URLs in an alternate browser.","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalgreylisturl","displayName":"URL of an XML file that contains URLs that should never trigger a browser switch.","description":"Setting the policy to a valid URL has Google Chrome download the site list from that URL and apply the rules as if they were set up with the BrowserSwitcherUrlGreylist policy. These policies prevent Google Chrome and the alternative browser from opening one another.\r\n\r\nLeaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for not switching browsers.\r\n\r\nNote: This policy points to an XML file in the same format as Internet Explorer®'s SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer®. Read more on Internet Explorer®'s SiteList policy ( https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode )\r\n\r\nExample value: http://example.com/greylist.xml","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalgreylisturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalgreylisturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalgreylisturl_browserswitcherexternalgreylisturl","displayName":"URL of an XML file that contains URLs that should never trigger a browser switch. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl","displayName":"URL of an XML file that contains URLs to load in an alternative browser.","description":"Setting the policy to a valid URL has Google Chrome download the site list from that URL and apply the rules as if they were set up with the BrowserSwitcherUrlList policy.\r\n\r\nLeaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for switching browsers.\r\n\r\nNote: This policy points to an XML file in the same format as Internet Explorer®'s SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer®. Read more on Internet Explorer®'s SiteList policy ( https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode)\r\n\r\nExample value: http://example.com/sitelist.xml","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl_browserswitcherexternalsitelisturl","displayName":"URL of an XML file that contains URLs to load in an alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherkeeplastchrometab","displayName":"Keep last tab open in Chrome.","description":"Setting the policy to Enabled or leaving it unset has Google Chrome keep at least one tab open, after switching to an alternate browser.\r\n\r\nSetting the policy to Disabled has Google Chrome close the tab after switching to an alternate browser, even if it was the last tab. This causes Google Chrome to exit completely.","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherkeeplastchrometab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherkeeplastchrometab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode","displayName":"Sitelist parsing mode","description":"This policy controls how Google Chrome interprets sitelist/greylist policies for the Legacy Browser Support feature. It affects the following policies: BrowserSwitcherUrlList, BrowserSwitcherUrlGreylist, BrowserSwitcherUseIeSitelist, BrowserSwitcherExternalSitelistUrl, and BrowserSwitcherExternalGreylistUrl.\r\n\r\nIf 'Default' (0) or unset, URL matching is less strict. Rules that do not contain \"/\" look for a substring anywhere in the URL's hostname. Matching the path component of a URL is case-sensitive.\r\n\r\nIf 'IESiteListMode' (1), URL matching is more strict. Rules that do not contain \"/\" only match at the end of the hostname. They must also be at a domain name boundary. Matching the path component of a URL is case-insensitive. This is more compatible with Microsoft® Internet Explorer® and Microsoft® Edge®.\r\n\r\nFor example, with the rules \"example.com\" and \"acme.com/abc\":\r\n\r\n\"http://example.com/\", \"http://subdomain.example.com/\" and \"http://acme.com/abc\" match regardless of parsing mode.\r\n\r\n\"http://notexample.com/\", \"http://example.com.invalid.com/\", \"http://example.comabc/\" only match in 'Default' mode.\r\n\r\n\"http://acme.com/ABC\" only matches in 'IESiteListMode'.","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_browserswitcherparsingmode","displayName":"Sitelist parsing mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_browserswitcherparsingmode_0","displayName":"Default behavior for LBS.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_browserswitcherparsingmode_1","displayName":"More compatible with Microsoft IE/Edge enterprise mode sitelists.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurlgreylist","displayName":"Websites that should never trigger a browser switch.","description":"Setting the policy controls the list of websites that will never cause a browser switch. Each item is treated as a rule. Those rules that match won't open an alternative browser. Unlike the BrowserSwitcherUrlList policy, rules apply to both directions. When the Internet Explorer® add-in is on, it also controls whether Internet Explorer® should open these URLs in Google Chrome.\r\n\r\nLeaving the policy unset adds no websites to the list.\r\n\r\nNote: Elements can also be added to this list through the BrowserSwitcherExternalGreylistUrl policy.\r\n\r\nExample value:\r\n\r\nie.com\r\n!open-in-chrome.ie.com\r\nfoobar.com/ie-only/","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurlgreylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurlgreylist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurlgreylist_browserswitcherurlgreylistdesc","displayName":"Websites that should never trigger a browser switch. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist","displayName":"Websites to open in alternative browser","description":"Setting the policy controls the list of websites to open in an alternative browser. Each item is treated as a rule for something to open in an alternative browser. Google Chrome uses those rules when choosing if a URL should open in an alternative browser. When the Internet Explorer® add-in is on, Internet Explorer® switches back to Google Chrome when the rules don't match. If rules contradict each other, Google Chrome uses the most specific rule.\r\n\r\nLeaving the policy unset adds no websites to the list.\r\n\r\nNote: Elements can also be added to this list through the BrowserSwitcherUseIeSitelist and BrowserSwitcherExternalSitelistUrl policies.\r\n\r\nExample value:\r\n\r\nie.com\r\n!open-in-chrome.ie.com\r\nfoobar.com/ie-only/","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist_browserswitcherurllistdesc","displayName":"Websites to open in alternative browser (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcheruseiesitelist","displayName":"Use Internet Explorer's SiteList policy for Legacy Browser Support.","description":"This policy controls whether to load rules from Internet Explorer®'s SiteList policy.\r\n\r\nWhen this policy is set to true, Google Chrome reads Internet Explorer®'s SiteList to obtain the site list's URL. Google Chrome then downloads the site list from that URL, and applies the rules as if they had been configured with the BrowserSwitcherUrlList policy.\r\n\r\nWhen this policy is false or unset, Google Chrome does not use Internet Explorer®'s SiteList policy as a source of rules for switching browsers.\r\n\r\nFor more information on Internet Explorer's SiteList policy: https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcheruseiesitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcheruseiesitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_autoselectcertificateforurls","displayName":"Automatically select client certificates for these sites","description":"Setting the policy lets you make a list of URL patterns that specify sites for which Chrome can automatically select a client certificate. The value is an array of stringified JSON dictionaries, each with the form { \"pattern\": \"$URL_PATTERN\", \"filter\" : $FILTER }, where $URL_PATTERN is a content setting pattern. $FILTER restricts the client certificates the browser automatically selects from. Independent of the filter, only certificates that match the server's certificate request are selected.\r\n\r\nExamples for the usage of the $FILTER section:\r\n\r\n* When $FILTER is set to { \"ISSUER\": { \"CN\": \"$ISSUER_CN\" } }, only client certificates issued by a certificate with the CommonName $ISSUER_CN are selected.\r\n\r\n* When $FILTER contains both the \"ISSUER\" and the \"SUBJECT\" sections, only client certificates that satisfy both conditions are selected.\r\n\r\n* When $FILTER contains a \"SUBJECT\" section with the \"O\" value, a certificate needs at least one organization matching the specified value to be selected.\r\n\r\n* When $FILTER contains a \"SUBJECT\" section with a \"OU\" value, a certificate needs at least one organizational unit matching the specified value to be selected.\r\n\r\n* When $FILTER is set to {}, the selection of client certificates is not additionally restricted. Note that filters provided by the web server still apply.\r\n\r\nLeaving the policy unset means there's no autoselection for any site.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=AutoSelectCertificateForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\"pattern\":\"https://www.example.com\",\"filter\":{\"ISSUER\":{\"CN\":\"certificate issuer name\", \"L\": \"certificate issuer location\", \"O\": \"certificate issuer org\", \"OU\": \"certificate issuer org unit\"}, \"SUBJECT\":{\"CN\":\"certificate subject name\", \"L\": \"certificate subject location\", \"O\": \"certificate subject org\", \"OU\": \"certificate subject org unit\"}}}","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_autoselectcertificateforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_autoselectcertificateforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_autoselectcertificateforurls_autoselectcertificateforurlsdesc","displayName":"Automatically select client certificates for these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls","displayName":"Allow cookies on these sites","description":"Allows you to set a list of url patterns that specify sites which are allowed to set cookies.\r\n\r\nIf this policy is left not set the global default value will be used for all sites either from the DefaultCookiesSetting policy if it is set, or the user's personal configuration otherwise.\r\n\r\nSee also policies CookiesBlockedForUrls and CookiesSessionOnlyForUrls. Note that there must be no conflicting URL patterns between these three policies - it is unspecified which policy takes precedence.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls_cookiesallowedforurlsdesc","displayName":"Allow cookies on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls","displayName":"Block cookies on these sites","description":"Setting the policy lets you make a list of URL patterns that specify sites that can't set cookies.\r\n\r\nLeaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nWhile no specific policy takes precedence, see CookiesAllowedForUrls and CookiesSessionOnlyForUrls. URL patterns among these 3 policies must not conflict.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls_cookiesblockedforurlsdesc","displayName":"Block cookies on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls","displayName":"Limit cookies from matching URLs to the current session","description":"Unless the RestoreOnStartup policy is set to permanently restore URLs from previous sessions, then setting CookiesSessionOnlyForUrls lets you make a list of URL patterns that specify sites that can and can't set cookies for one session.\r\n\r\nLeaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. URLs not covered by the patterns specified also result in the use of defaults.\r\n\r\nWhile no specific policy takes precedence, see CookiesBlockedForUrls and CookiesAllowedForUrls. URL patterns among these 3 policies must not conflict.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls_cookiessessiononlyforurlsdesc","displayName":"Limit cookies from matching URLs to the current session (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting","displayName":"Default cookies setting","description":"Unless the RestoreOnStartup policy is set to permanently restore URLs from previous sessions, then setting CookiesSessionOnlyForUrls lets you make a list of URL patterns that specify sites that can and can't set cookies for one session.\r\n\r\nLeaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. URLs not covered by the patterns specified also result in the use of defaults.\r\n\r\nWhile no specific policy takes precedence, see CookiesBlockedForUrls and CookiesAllowedForUrls. URL patterns among these 3 policies must not conflict.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_defaultcookiessetting","displayName":"Default cookies setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_defaultcookiessetting_1","displayName":"Allow all sites to set local data","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_defaultcookiessetting_2","displayName":"Do not allow any site to set local data","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_defaultcookiessetting_4","displayName":"Keep cookies for the duration of the session","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading","description":"Setting the policy to 3 lets websites ask for read access to files and directories in the host operating system's file system via the File System API. Setting the policy to 2 denies access.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_2","displayName":"Do not allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_3","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing","description":"Setting the policy to 3 lets websites ask for write access to files and directories in the host operating system's file system. Setting the policy to 2 denies access.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemwriteguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemwriteguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting_2","displayName":"Do not allow any site to request write access to files and directories","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting_3","displayName":"Allow sites to ask the user to grant write access to files and directories","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting","displayName":"Default geolocation setting","description":"Setting the policy to 1 lets sites track the users' physical location as the default state. Setting the policy to 2 denies this tracking by default. You can set the policy to ask whenever a site wants to track the users' physical location.\r\n\r\nLeaving the policy unset means the AskGeolocation policy applies, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting","displayName":"Default geolocation setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting_1","displayName":"Allow sites to track the users' physical location","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting_2","displayName":"Do not allow any site to track the users' physical location","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting_3","displayName":"Ask whenever a site wants to track the users' physical location","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting","displayName":"Default images setting","description":"Setting the policy to 1 lets all websites display images. Setting the policy to 2 denies image display.\r\n\r\nLeaving it unset allows images, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_defaultimagessetting","displayName":"Default images setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_defaultimagessetting_1","displayName":"Allow all sites to show all images","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_defaultimagessetting_2","displayName":"Do not allow any site to show images","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions","description":"Allows you to set whether users can add exceptions to allow mixed content for specific sites.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'InsecureContentAllowedForUrls' and 'InsecureContentBlockedForUrls' policies.\r\n\r\nIf this policy is left not set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_2","displayName":"Do not allow any site to load mixed content","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_3","displayName":"Allow users to add exceptions to allow mixed content","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT","description":"Allows you to set whether Google Chrome will run the v8 JavaScript engine with JIT (Just In Time) compiler enabled or not.\r\n\r\nDisabling the JavaScript JIT will mean that Google Chrome may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Google Chrome to render web content in a more secure configuration.\r\n\r\nThis policy can be overridden for specific URL patterns using the JavaScriptJitAllowedForSites and JavaScriptJitBlockedForSites policies.\r\n\r\nIf this policy is left not set, JavaScript JIT is enabled.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_1","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_2","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting","displayName":"Default JavaScript setting","description":"Setting the policy to 1 lets websites run JavaScript. Setting the policy to 2 denies JavaScript.\r\n\r\nLeaving it unset allows JavaScript, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting","displayName":"Default JavaScript setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_1","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_2","displayName":"Do not allow any site to run JavaScript","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting","displayName":"Default notification setting","description":"Setting the policy to 1 lets websites display desktop notifications. Setting the policy to 2 denies desktop notifications.\r\n\r\nLeaving it unset means AskNotifications applies, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting","displayName":"Default notification setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting_1","displayName":"Allow sites to show desktop notifications","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting_2","displayName":"Do not allow any site to show desktop notifications","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting_3","displayName":"Ask every time a site wants to show desktop notifications","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting","displayName":"Default popups setting","description":"Setting the policy to 1 lets websites display pop-ups. Setting the policy to 2 denies pop-ups.\r\n\r\nLeaving it unset means BlockPopups applies, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_defaultpopupssetting","displayName":"Default popups setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_defaultpopupssetting_1","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_defaultpopupssetting_2","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultsensorssetting","displayName":"Default sensors setting","description":"Setting the policy to 1 lets websites access and use sensors such as motion and light. Setting the policy to 2 denies acess to sensors.\r\n\r\nLeaving it unset means AllowSensors applies, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultsensorssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultsensorssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultsensorssetting_defaultsensorssetting","displayName":"Default sensors setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultsensorssetting_defaultsensorssetting_1","displayName":"Allow sites to access sensors","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultsensorssetting_defaultsensorssetting_2","displayName":"Do not allow any site to access sensors","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultserialguardsetting","displayName":"Control use of the Serial API","description":"Setting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultserialguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultserialguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultserialguardsetting_defaultserialguardsetting","displayName":"Control use of the Serial API (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultserialguardsetting_defaultserialguardsetting_2","displayName":"Do not allow any site to request access to serial ports via the Serial API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultserialguardsetting_defaultserialguardsetting_3","displayName":"Allow sites to ask the user to grant access to a serial port","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API","description":"Setting the policy to 3 lets websites ask for access to nearby Bluetooth devices. Setting the policy to 2 denies access to nearby Bluetooth devices.\r\n\r\nLeaving the policy unset lets sites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_2","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_3","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API","description":"Setting the policy to 3 lets websites ask for access to connected USB devices. Setting the policy to 2 denies access to connected USB devices.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting_2","displayName":"Do not allow any site to request access to USB devices via the WebUSB API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting_3","displayName":"Allow sites to ask the user to grant access to a connected USB device","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadaskforurls","displayName":"Allow read access via the File System API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\r\n\r\nLeaving the policy unset means DefaultFileSystemReadGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns must not conflict with FileSystemReadBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadaskforurls_filesystemreadaskforurlsdesc","displayName":"Allow read access via the File System API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadblockedforurls","displayName":"Block read access via the File System API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\r\n\r\nLeaving the policy unset means DefaultFileSystemReadGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with FileSystemReadAskForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadblockedforurls_filesystemreadblockedforurlsdesc","displayName":"Block read access via the File System API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls","displayName":"Allow write access to files and directories on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nLeaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns must not conflict with FileSystemWriteBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls_filesystemwriteaskforurlsdesc","displayName":"Allow write access to files and directories on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteblockedforurls","displayName":"Block write access to files and directories on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nLeaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with FileSystemWriteAskForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteblockedforurls_filesystemwriteblockedforurlsdesc","displayName":"Block write access to files and directories on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls","displayName":"Allow images on these sites","description":"Setting the policy lets you set a list of URL patterns that specify sites that may display images.\r\n\r\nLeaving the policy unset means DefaultImagesSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nNote that previously this policy was erroneously enabled on Android, but this functionality has never been fully supported on Android.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_imagesallowedforurlsdesc","displayName":"Allow images on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesblockedforurls","displayName":"Block images on these sites","description":"Setting the policy lets you set a list of URL patterns that specify sites that can't display images.\r\n\r\nLeaving the policy unset means DefaultImagesSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\n For detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\n Note that previously this policy was erroneously enabled on Android, but this functionality has never been fully supported on Android.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesblockedforurls_imagesblockedforurlsdesc","displayName":"Block images on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls","displayName":"Allow insecure content on these sites","description":"Allows you to set a list of url patterns that specify sites which are allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled.\r\n\r\nIf this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, and users will be allowed to set exceptions to allow it for specific sites.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls_insecurecontentallowedforurlsdesc","displayName":"Allow insecure content on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls","displayName":"Block insecure content on these sites","description":"Allows you to set a list of url patterns that specify sites which are not allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites), and for which optionally blockable (i.e. passive) mixed content will be upgraded.\r\n\r\nIf this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, but users will be allowed to set exceptions to allow it for specific sites.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_insecurecontentblockedforurlsdesc","displayName":"Block insecure content on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls","displayName":"Allow JavaScript on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can run JavaScript.\r\n\r\nLeaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls_javascriptallowedforurlsdesc","displayName":"Allow JavaScript on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptblockedforurls","displayName":"Block JavaScript on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can't run JavaScript.\r\n\r\nLeaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptblockedforurls_javascriptblockedforurlsdesc","displayName":"Block JavaScript on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT enabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise Javascript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_javascriptjitallowedforsitesdesc","displayName":"Allow JavaScript to use JIT on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites","displayName":"Block JavaScript from using JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are not allowed to run JavaScript JIT (Just In Time) compiler enabled.\r\n\r\nDisabling the JavaScript JIT will mean that Google Chrome may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Google Chrome to render web content in a more secure configuration.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitBlockedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT disabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise JavaScript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites_javascriptjitblockedforsitesdesc","displayName":"Block JavaScript from using JIT on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist","displayName":"Revert to legacy SameSite behavior for cookies on these sites","description":"Cookies set for domains matching these patterns will revert to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute, and skips the scheme comparison when evaluating if two sites are same-site. See https://www.chromium.org/administrators/policy-list-3/cookie-legacy-samesite-policies for full description.\r\n\r\nFor cookies on domains not covered by the patterns specified here, or for all cookies if this policy is not set, the global default value will be the user's personal configuration.\r\n\r\nFor detailed information on valid patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nNote that patterns you list here are treated as domains, not URLs, so you should not specify a scheme or port.\r\n\r\nExample value:\r\n\r\nwww.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_legacysamesitecookiebehaviorenabledfordomainlistdesc","displayName":"Revert to legacy SameSite behavior for cookies on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsallowedforurls","displayName":"Allow notifications on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can display notifications.\r\n\r\nLeaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsallowedforurls_notificationsallowedforurlsdesc","displayName":"Allow notifications on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls","displayName":"Block notifications on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can't display notifications.\r\n\r\nLeaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls_notificationsblockedforurlsdesc","displayName":"Block notifications on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls","displayName":"Allow popups on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can open pop-ups.\r\n\r\nLeaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls_popupsallowedforurlsdesc","displayName":"Allow popups on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsblockedforurls","displayName":"Block popups on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can't open pop-ups.\r\n\r\nLeaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsblockedforurls_popupsblockedforurlsdesc","displayName":"Block popups on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls","displayName":"Allow access to sensors on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can access sensors like motion and light sensors.\r\n\r\nLeaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nIf the same URL pattern exists in both this policy and the SensorsBlockedForUrls policy, the latter is prioritized and access to motion or light sensors will be blocked.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls_sensorsallowedforurlsdesc","displayName":"Allow access to sensors on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls","displayName":"Block access to sensors on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can't access sensors like motion and light sensors.\r\n\r\nLeaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nIf the same URL pattern exists in both this policy and the SensorsAllowedForUrls policy, this policy is prioritized and access to motion or light sensors will be blocked.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls_sensorsblockedforurlsdesc","displayName":"Block access to sensors on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowallportsforurls","displayName":"Automatically grant permission to sites to connect all serial ports.","description":"Setting the policy allows you to list sites which are automatically granted permission to access all available serial ports.\r\n\r\nThe URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered.\r\n\r\nOn Chrome OS, this policy only applies to affiliated users.\r\n\r\nThis policy overrides DefaultSerialGuardSetting, SerialAskForUrls, SerialBlockedForUrls and the user's preferences.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowallportsforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowallportsforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowallportsforurls_serialallowallportsforurlsdesc","displayName":"Automatically grant permission to sites to connect all serial ports. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowusbdevicesforurls","displayName":"Automatically grant permission to sites to connect to USB serial devices.","description":"Setting the policy allows you to list sites which are automatically granted permission to access USB serial devices with vendor and product IDs matching the vendor_id and product_id fields. Omitting the product_id field allows the given sites permission to access devices with a vendor ID matching the vendor_id field and any product ID.\r\n\r\nThe URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered.\r\n\r\nOn Chrome OS, this policy only applies to affiliated users.\r\n\r\nThis policy overrides DefaultSerialGuardSetting, SerialAskForUrls, SerialBlockedForUrls and the user's preferences.\r\n\r\nThis policy only affects access to USB devices through the Web Serial API. To grant access to USB devices through the WebUSB API see the WebUsbAllowDevicesForUrls policy.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=SerialAllowUsbDevicesForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234,\r\n \"product_id\": 5678\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://specific-device.example.com\"\r\n ]\r\n },\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://all-vendor-devices.example.com\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowusbdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowusbdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowusbdevicesforurls_serialallowusbdevicesforurls","displayName":"Automatically grant permission to sites to connect to USB serial devices. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialaskforurls","displayName":"Allow the Serial API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a serial port.\r\n\r\nLeaving the policy unset means DefaultSerialGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns which do not match the policy SerialBlockedForUrls (if there is a match), DefaultSerialGuardSetting (if set), or the users' personal settings take precedence, in that order.\r\n\r\nURL patterns must not conflict with SerialBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialaskforurls_serialaskforurlsdesc","displayName":"Allow the Serial API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialblockedforurls","displayName":"Block the Serial API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a serial port.\r\n\r\nLeaving the policy unset means DefaultSerialGuardSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor URL patterns which do not match the policy SerialAskForUrls (if there is a match), DefaultSerialGuardSetting (if set), or the users' personal settings take precedence, in that order.\r\n\r\nURL patterns can't conflict with SerialAskForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialblockedforurls_serialblockedforurlsdesc","displayName":"Block the Serial API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to USB devices with the given vendor and product IDs.","description":"Setting the policy lets you list the URL patterns that specify which sites are automatically granted permission to access a USB device with the given vendor and product IDs. Each item in the list requires both devices and urls fields for the policy to be valid. Each item in the devices field can have a vendor_id and product_id field. Omitting the vendor_id field will create a policy matching any device. Omitting the product_id field will create a policy matching any device with the given vendor ID. A policy which has a product_id field without a vendor_id field is invalid.\r\n\r\nThe USB permission model will grant the specified URL permission to access the USB device as a top-level origin. If embedded frames need to access USB devices, the 'usb' feature-policy header should be used to grant access. The URL must be valid, otherwise the policy is ignored.\r\n\r\nDeprecated: The USB permission model used to support specifying both the requesting and embedding URLs. This is deprecated and only supported for backwards compatiblity in this manner: if both a requesting and embedding URL is specified, then the embedding URL will be granted the permission as top-level origin and the requsting URL will be ignored entirely.\r\n\r\nThis policy overrides DefaultWebUsbGuardSetting, WebUsbAskForUrls, WebUsbBlockedForUrls and the user's preferences.\r\n\r\nThis policy only affects access to USB devices through the WebUSB API. To grant access to USB devices through the Web Serial API see the SerialAllowUsbDevicesForUrls policy.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebUsbAllowDevicesForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234,\r\n \"product_id\": 5678\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://google.com\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls_webusballowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to USB devices with the given vendor and product IDs. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbaskforurls","displayName":"Allow WebUSB on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a USB device.\r\n\r\nLeaving the policy unset means DefaultWebUsbGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns must not conflict with WebUsbAskForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbaskforurls_webusbaskforurlsdesc","displayName":"Allow WebUSB on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbblockedforurls","displayName":"Block WebUSB on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a USB device.\r\n\r\nLeaving the policy unset means DefaultWebUsbGuardSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nURL patterns can't conflict with WebUsbAskForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbblockedforurls_webusbblockedforurlsdesc","displayName":"Block WebUSB on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls","displayName":"List of alternate URLs for the default search provider","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderAlternateURLs specifies a list of alternate URLs for extracting search terms from the search engine. The URLs should include the string '{searchTerms}'.\r\n\r\nLeaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms.\r\n\r\nExample value:\r\n\r\nhttps://search.my.company/suggest#q={searchTerms}\r\nhttps://search.my.company/suggest/search#q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls_defaultsearchprovideralternateurlsdesc","displayName":"List of alternate URLs for the default search provider (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderenabled","displayName":"Enable the default search provider","description":"Setting the policy to Enabled means a default search is performed when a user enters non-URL text in the address bar. To specify the default search provider, set the rest of the default search policies. If you leave those policies empty, the user can choose the default provider. Setting the policy to Disabled means there's no search when the user enters non-URL text in the address bar.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, the default search provider is on, and users can set the search provider list.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings","displayName":"Default search provider encodings","description":"If DefaultSearchProviderEnabled is on, setting DefaultSearchProviderEncodings specifies the character encodings supported by the search provider. Encodings are code page names such as UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided.\r\n\r\nLeaving DefaultSearchProviderEncodings unset puts UTF-8 in use.\r\n\r\nExample value:\r\n\r\nUTF-8\r\nUTF-16\r\nGB2312\r\nISO-8859-1","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl","displayName":"Default search provider icon","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderIconURL specifies the default search provider's favorite icon URL.\r\n\r\nLeaving DefaultSearchProviderIconURL unset means there's no icon for the search provider.\r\n\r\nExample value: https://search.my.company/favicon.ico","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_defaultsearchprovidericonurl","displayName":"Default search provider icon (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurl","displayName":"Parameter providing search-by-image feature for the default search provider","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURL specifies the URL of the search engine used for image search. (If DefaultSearchProviderImageURLPostParams is set, then image search requests use the POST method instead.)\r\n\r\nLeaving DefaultSearchProviderImageURL unset means no image search is used.\r\n\r\nExample value: https://search.my.company/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurl_defaultsearchproviderimageurl","displayName":"Parameter providing search-by-image feature for the default search provider (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurlpostparams","displayName":"Parameters for image URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURLPostParams specifies the parameters during image search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as {imageThumbnail}, real image thumbnail data replaces it.\r\n\r\nLeaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurlpostparams_defaultsearchproviderimageurlpostparams","displayName":"Parameters for image URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword","displayName":"Default search provider keyword","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider.\r\n\r\nLeaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword_defaultsearchproviderkeyword","displayName":"Default search provider keyword (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername","displayName":"Default search provider name","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name.\r\n\r\nLeaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_defaultsearchprovidername","displayName":"Default search provider name (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl","displayName":"Default search provider new tab page URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderNewTabURL specifies the URL of the search engine used to provide a New Tab page.\r\n\r\nLeaving DefaultSearchProviderNewTabURL unset means no new tab page is provided.\r\n\r\nExample value: https://search.my.company/newtab","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl_defaultsearchprovidernewtaburl","displayName":"Default search provider new tab page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurl","displayName":"Default search provider search URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURL specifies the URL of the search engine used during a default search. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms.\r\n\r\nYou can specify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\r\n\r\nExample value: https://search.my.company/search?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurl_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams","displayName":"Parameters for search URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_defaultsearchprovidersearchurlpostparams","displayName":"Parameters for search URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURL specifies the URL of the search engine to provide search suggestions. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms.\r\n\r\nYou can specify Google's search URL as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nExample value: https://search.my.company/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturlpostparams","displayName":"Parameters for suggest URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURLPostParams specifies the parameters during suggestion search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSuggestURLPostParams unset unset means suggest search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturlpostparams_defaultsearchprovidersuggesturlpostparams","displayName":"Parameters for suggest URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authnegotiatedelegatewhitelist","displayName":"Kerberos delegation server whitelist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: foobar.example.com","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authnegotiatedelegatewhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authnegotiatedelegatewhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authnegotiatedelegatewhitelist_authnegotiatedelegatewhitelist","displayName":"Kerberos delegation server whitelist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authserverwhitelist","displayName":"Authentication server whitelist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: *.example.com,example.com","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authserverwhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authserverwhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_authserverwhitelist_authserverwhitelist","displayName":"Authentication server whitelist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autofillenabled","displayName":"Enable AutoFill","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autofillenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autofillenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autoplaywhitelist","displayName":"Allow media autoplay on a whitelist of URL patterns","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autoplaywhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autoplaywhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_autoplaywhitelist_autoplaywhitelistdesc","displayName":"Allow media autoplay on a whitelist of URL patterns (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting","displayName":"Default mediastream setting","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_defaultmediastreamsetting","displayName":"Default mediastream setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_defaultmediastreamsetting_2","displayName":"Do not allow any site to access the camera and microphone","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_defaultmediastreamsetting_3","displayName":"Ask every time a site wants to access the camera and/or microphone","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_developertoolsdisabled","displayName":"Disable Developer Tools","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_developertoolsdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_developertoolsdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_disabledschemes","displayName":"Disable URL protocol schemes","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nfile\r\nhttps","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_disabledschemes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_disabledschemes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_disabledschemes_disabledschemesdesc","displayName":"List of disabled protocol schemes (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallblacklist","displayName":"Configure extension installation blacklist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallblacklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallblacklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallblacklist_extensioninstallblacklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist","displayName":"Configure extension installation whitelist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist_extensioninstallwhitelistdesc","displayName":"Extension IDs to exempt from the blacklist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcebrowsersignin","displayName":"Enable force sign in for Google Chrome","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcebrowsersignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcebrowsersignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcesafesearch","displayName":"Force SafeSearch","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcesafesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcesafesearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forceyoutubesafetymode","displayName":"Force YouTube Safety Mode","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forceyoutubesafetymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forceyoutubesafetymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_incognitoenabled","displayName":"Enable Incognito mode","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_incognitoenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_incognitoenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_javascriptenabled","displayName":"Enable JavaScript","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_javascriptenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_javascriptenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist","displayName":"Configure native messaging blocklist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist_nativemessagingblacklistdesc","displayName":"Names of the forbidden native messaging hosts (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingwhitelist","displayName":"Configure native messaging whitelist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingwhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingwhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingwhitelist_nativemessagingwhitelistdesc","displayName":"Names of the native messaging hosts to exempt from the blocklist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativewindowocclusionenabled","displayName":"Enable Native Window Occlusion","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativewindowocclusionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativewindowocclusionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxybypasslist","displayName":"Proxy bypass rules","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: https://www.example1.com,https://www.example2.com,https://internalsite/","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxybypasslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxybypasslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxybypasslist_proxybypasslist","displayName":"Comma-separated list of proxy bypass rules (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode","displayName":"Choose how to specify proxy server settings","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: direct","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode","displayName":"Choose how to specify proxy server settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_direct","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_auto_detect","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_pac_script","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_fixed_servers","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_system","displayName":"Use system proxy settings","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxypacurl","displayName":"URL to a proxy .pac file","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: https://internal.site/example.pac","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxypacurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxypacurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxypacurl_proxypacurl","displayName":"URL to a proxy .pac file (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyserver","displayName":"Address or URL of proxy server","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: 123.123.123.123:8080","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyserver_proxyserver","displayName":"Address or URL of proxy server (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode","displayName":"Choose how to specify proxy server settings","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_proxyservermode","displayName":"Choose how to specify proxy server settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_proxyservermode_0","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_proxyservermode_1","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_proxyservermode_2","displayName":"Manually specify proxy settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyservermode_proxyservermode_3","displayName":"Use system proxy settings","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostclientdomain","displayName":"Configure the required domain name for remote access clients","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: my-awesome-domain.com","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostclientdomain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostclientdomain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostclientdomain_remoteaccesshostclientdomain","displayName":"Configure the required domain name for remote access clients (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostdomain","displayName":"Configure the required domain name for remote access hosts","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value: my-awesome-domain.com","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostdomain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostdomain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostdomain_remoteaccesshostdomain","displayName":"Configure the required domain name for remote access hosts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled","displayName":"Enable Safe Browsing","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingwhitelistdomains","displayName":"Configure the list of domains on which Safe Browsing will not trigger warnings.","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingwhitelistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingwhitelistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingwhitelistdomains_safebrowsingwhitelistdomainsdesc","displayName":"Configure the list of domains on which Safe Browsing will not trigger warnings. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_signinallowed","displayName":"Allow sign in to Google Chrome","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_signinallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_signinallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_spellchecklanguageblacklist","displayName":"Force disable spellcheck languages","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nfr\r\nes","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_spellchecklanguageblacklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_spellchecklanguageblacklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_spellchecklanguageblacklist_spellchecklanguageblacklistdesc","displayName":"Force disable spellcheck languages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_strictermixedcontenttreatmentenabled","displayName":"Enable stricter treatment for mixed content","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_strictermixedcontenttreatmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_strictermixedcontenttreatmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttp://testserver.example.com/\r\n*.example.org","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_unsafelytreatinsecureoriginassecuredesc","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlblacklist","displayName":"Block access to a list of URLs","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlblacklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlblacklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlblacklist_urlblacklistdesc","displayName":"Block access to a list of URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist","displayName":"Allow access to a list of URLs","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist_urlwhitelistdesc","displayName":"Allow access to a list of URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_blockexternalextensions","displayName":"Blocks external extensions from being installed","description":"Controls external extensions installation.\r\n\r\nEnabling this setting blocks external extensions from being installed.\r\n\r\nDisabling this setting or leaving it unset allows external extensions to be installed.\r\n\r\nExternal extensions and their installation are documented at https://developer.chrome.com/apps/external_extensions.\r\n","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_blockexternalextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_blockexternalextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionallowedtypes","displayName":"Configure allowed app/extension types","description":"Setting the policy controls which apps and extensions may be installed in Google Chrome, which hosts they can interact with, and limits runtime access.\r\n\r\nLeaving the policy unset results in no restrictions on the acceptable extension and app types.\r\n\r\nExtensions and apps which have a type that's not on the list won't be installed. Each value should be one of these strings:\r\n\r\n* \"extension\"\r\n\r\n* \"theme\"\r\n\r\n* \"user_script\"\r\n\r\n* \"hosted_app\"\r\n\r\n* \"legacy_packaged_app\"\r\n\r\n* \"platform_app\"\r\n\r\nSee the Google Chrome extensions documentation for more information on these types.\r\n\r\nVersions earlier than 75 that use multiple comma separated extension IDs aren't supported and are skipped. The rest of the policy applies.\r\n\r\nNote: This policy also affects extensions and apps to be force-installed using ExtensionInstallForcelist.\r\n\r\nExample value:\r\n\r\nhosted_app","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionallowedtypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionallowedtypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionallowedtypes_extensionallowedtypesdesc","displayName":"Types of extensions/apps that are allowed to be installed (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist","displayName":"Configure extension installation allow list","description":"Setting the policy specifies which extensions are not subject to the blocklist.\r\n\r\nA blocklist value of * means all extensions are blocked and users can only install extensions listed in the allow list.\r\n\r\nBy default, all extensions are allowed. But, if you prohibited extensions by policy, use the list of allowed extensions to change that policy.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_extensioninstallallowlistdesc","displayName":"Extension IDs to exempt from the blocklist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallblocklist","displayName":"Configure extension installation blocklist","description":"Allows you to specify which extensions the users can NOT install. Extensions already installed will be disabled if blocked, without a way for the user to enable them. Once an extension disabled due to the blocklist is removed from it, it will automatically get re-enabled.\r\n\r\nA blocklist value of '*' means all extensions are blocked unless they are explicitly listed in the allowlist.\r\n\r\nIf this policy is left not set the user can install any extension in Google Chrome.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallblocklist_extensioninstallblocklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist","displayName":"Configure the list of force-installed apps and extensions","description":"Setting the policy specifies a list of apps and extensions that install silently, without user interaction, and which users can't uninstall or turn off. Permissions are granted implicitly, including for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These 2 APIs aren't available to apps and extensions that aren't force-installed.)\r\n\r\nLeaving the policy unset means no apps or extensions are autoinstalled, and users can uninstall any app or extension in Google Chrome.\r\n\r\nThis policy superseeds ExtensionInstallBlocklist policy. If a previously force-installed app or extension is removed from this list, Google Chrome automatically uninstalls it.\r\n\r\nOn Microsoft® Windows® instances, apps and extensions from outside the Chrome Web Store can only be forced installed if the instance is joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management.\r\n\r\nOn macOS instances, apps and extensions from outside the Chrome Web Store can only be force installed if the instance is managed via MDM, or joined to a domain via MCX.\r\n\r\nThe source code of any extension may be altered by users through developer tools, potentially rendering the extension dysfunctional. If this is a concern, set the DeveloperToolsDisabled policy.\r\n\r\nEach list item of the policy is a string that contains an extension ID and, optionally, an \"update\" URL separated by a semicolon (;). The extension ID is the 32-letter string found, for example, on chrome://extensions when in Developer mode. If specified, the \"update\" URL should point to an Update Manifest XML document ( https://developer.chrome.com/extensions/autoupdate ). By default, the Chrome Web Store's update URL is used. The \"update\" URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL in the extension's manifest.\r\n\r\n Note: This policy doesn't apply to Incognito mode. Read about hosting extensions ( https://developer.chrome.com/extensions/hosting ).\r\n\r\nExample value:\r\n\r\naaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa;https://clients2.google.com/service/update2/crx\r\nabcdefghijklmnopabcdefghijklmnop","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist_extensioninstallforcelistdesc","displayName":"Extension/App IDs and update URLs to be silently installed (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources","displayName":"Configure extension, app, and user script install sources","description":"Setting the policy specifies which URLs may install extensions, apps, and themes. Before Google Chrome 21, users could click on a link to a *.crx file, and Google Chrome would offer to install the file after a few warnings. Afterwards, such files must be downloaded and dragged to the Google Chrome settings page. This setting allows specific URLs to have the old, easier installation flow.\r\n\r\nEach item in this list is an extension-style match pattern (see https://developer.chrome.com/extensions/match_patterns). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (the referrer) must be allowed by these patterns.\r\n\r\nExtensionInstallBlocklist takes precedence over this policy. That is, an extension on the blocklist won't be installed, even if it happens from a site on this list.\r\n\r\nExample value:\r\n\r\nhttps://corp.mycompany.com/*","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_extensioninstallsourcesdesc","displayName":"URL patterns to allow extension, app, and user script installs from (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings","displayName":"Extension management settings","description":"Setting the policy controls extension management settings for Google Chrome, including any controlled by existing extension-related policies. The policy supersedes any legacy policies that might be set.\r\n\r\nThis policy maps an extension ID or an update URL to its specific setting only. A default configuration can be set for the special ID \"*\", which applies to all extensions without a custom configuration in this policy. With an update URL, configuration applies to extensions with the exact update URL stated in the extension manifest ( http://support.google.com/chrome/a?p=Configure_ExtensionSettings_policy ). If the 'override_update_url' flag is set to true, the extension is installed and updated using the \"update\" URL specified in the ExtensionInstallForcelist policy or in 'update_url' field in this policy. The flag 'override_update_url' is ignored if the 'update_url' is a Chrome Web Store url.\r\n\r\nNote: For Windows® instances not joined to a Microsoft® Active Directory® domain, forced installation is limited to apps and extensions listed in the Chrome Web Store.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ExtensionSettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"abcdefghijklmnopabcdefghijklmnop\": {\r\n \"installation_mode\": \"allowed\",\r\n \"blocked_permissions\": [\r\n \"history\"\r\n ],\r\n \"minimum_version_required\": \"1.0.1\",\r\n \"toolbar_pin\": \"force_pinned\"\r\n },\r\n \"bcdefghijklmnopabcdefghijklmnopa\": {\r\n \"installation_mode\": \"force_installed\",\r\n \"update_url\": \"https://example.com/update_url\",\r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ],\r\n \"runtime_blocked_hosts\": [\r\n \"*://*.example.com\"\r\n ],\r\n \"runtime_allowed_hosts\": [\r\n \"*://good.example.com\"\r\n ]\r\n },\r\n \"cdefghijklmnopabcdefghijklmnopab\": {\r\n \"installation_mode\": \"blocked\",\r\n \"blocked_install_message\": \"Custom error message.\"\r\n },\r\n \"defghijklmnopabcdefghijklmnopabc,efghijklmnopabcdefghijklmnopabcd\": {\r\n \"installation_mode\": \"blocked\",\r\n \"blocked_install_message\": \"Custom error message.\"\r\n },\r\n \"update_url:https://www.example.com/update.xml\": {\r\n \"blocked_permissions\": [\r\n \"wallpaper\"\r\n ],\r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ],\r\n \"installation_mode\": \"allowed\"\r\n },\r\n \"fghijklmnopabcdefghijklmnopabcde\": {\r\n \"installation_mode\": \"removed\",\r\n \"blocked_install_message\": \"Custom removal message.\"\r\n },\r\n \"ghijklmnopabcdefghijklmnopabcdef\": {\r\n \"installation_mode\": \"force_installed\",\r\n \"update_url\": \"https://example.com/update_url\",\r\n \"override_update_url\": true\r\n },\r\n \"*\": {\r\n \"installation_mode\": \"blocked\",\r\n \"blocked_permissions\": [\r\n \"downloads\",\r\n \"bookmarks\"\r\n ],\r\n \"install_sources\": [\r\n \"https://company-intranet/chromeapps\"\r\n ],\r\n \"allowed_types\": [\r\n \"hosted_app\"\r\n ],\r\n \"runtime_blocked_hosts\": [\r\n \"*://*.example.com\"\r\n ],\r\n \"runtime_allowed_hosts\": [\r\n \"*://good.example.com\"\r\n ],\r\n \"blocked_install_message\": \"Custom error message.\"\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings_extensionsettings","displayName":"Extension management settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_enablemediarouter","displayName":"Enable Google Cast","description":"Setting the policy to Enabled or leaving it unset turns on Google Cast, which users can launch from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.\r\n\r\nSetting the policy to Disabled turns off Google Cast.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_enablemediarouter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_enablemediarouter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_showcasticonintoolbar","displayName":"Show the Google Cast toolbar icon","description":"Setting the policy to Enabled displays the Cast toolbar icon on the toolbar or the overflow menu, and users can't remove it.\r\n\r\nSetting the policy to Disabled or leaving it unset lets users pin or remove the icon through its contextual menu.\r\n\r\nIf the policy EnableMediaRouter is set to Disabled, then this policy's value has no effect, and the toolbar icon doesn't appear.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_showcasticonintoolbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_showcasticonintoolbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_allowcrossoriginauthprompt","displayName":"Cross-origin HTTP Authentication prompts","description":"Setting the policy to Enabled allows third-party images on a page to show an authentication prompt.\r\n\r\n Setting the policy to Disabled or leaving it unset renders third-party images unable to show an authentication prompt.\r\n\r\nTypically, this policy is Disabled as a phishing defense.","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_allowcrossoriginauthprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_allowcrossoriginauthprompt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authnegotiatedelegateallowlist","displayName":"Kerberos delegation server allowlist","description":"Setting the policy assigns servers that Google Chrome may delegate to. Separate multiple server names with commas. Wildcards, *, are allowed.\r\n\r\nLeaving the policy unset means Google Chrome won't delegate user credentials, even if a server is detected as intranet.\r\n\r\nExample value: foobar.example.com","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authnegotiatedelegateallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authnegotiatedelegateallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authnegotiatedelegateallowlist_authnegotiatedelegateallowlist","displayName":"Kerberos delegation server allowlist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes","displayName":"Supported authentication schemes","description":"Setting the policy specifies which HTTP authentication schemes Google Chrome supports.\r\n\r\nLeaving the policy unset employs all 4 schemes.\r\n\r\nValid values:\r\n\r\n* basic\r\n\r\n* digest\r\n\r\n* ntlm\r\n\r\n* negotiate\r\n\r\nNote: Separate multiple values with commas.\r\n\r\nExample value: basic,digest,ntlm,negotiate","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes_authschemes","displayName":"Supported authentication schemes (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist","displayName":"Authentication server allowlist","description":"Setting the policy specifies which servers should be allowed for integrated authentication. Integrated authentication is only on when Google Chrome gets an authentication challenge from a proxy or from a server in this permitted list.\r\n\r\nLeaving the policy unset means Google Chrome tries to detect if a server is on the intranet. Only then will it respond to IWA requests. If a server is detected as internet, then Google Chrome ignores IWA requests from it.\r\n\r\nNote: Separate multiple server names with commas. Wildcards, *, are allowed.\r\n\r\nExample value: *.example.com,example.com","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist_authserverallowlist","displayName":"Authentication server allowlist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_basicauthoverhttpenabled","displayName":"Allow Basic authentication for HTTP","description":"Setting the policy to Enabled or leaving it unset will allow Basic authentication challenges received over non-secure HTTP.\r\n\r\nSetting the policy to Disabled forbids non-secure HTTP requests from using the Basic authentication scheme; only secure HTTPS is allowed.\r\n\r\nThis policy setting is ignored (and Basic is always forbidden) if the AuthSchemes policy is set and does not include Basic.","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_basicauthoverhttpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_basicauthoverhttpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_disableauthnegotiatecnamelookup","displayName":"Disable CNAME lookup when negotiating Kerberos authentication","description":"Setting the policy to Enabled skips CNAME lookup. The server name is used as entered when generating the Kerberos SPN.\r\n\r\nSetting the policy to Disabled or leaving it unset means CNAME lookup determines the canonical name of the server when generating the Kerberos SPN.","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_disableauthnegotiatecnamelookup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_disableauthnegotiatecnamelookup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_enableauthnegotiateport","displayName":"Include non-standard port in Kerberos SPN","description":"Setting the policy to Enabled and entering a nonstandard port (in other words, a port other than 80 or 443) includes it in the generated Kerberos SPN.\r\n\r\nSetting the policy to Disabled or leaving it unset means the generated Kerberos SPN won't include a port.","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_enableauthnegotiateport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_enableauthnegotiateport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingallowlist","displayName":"Configure native messaging allowlist","description":"Setting the policy specifies which native messaging hosts aren't subject to the deny list. A deny list value of * means all native messaging hosts are denied, unless they're explicitly allowed.\r\n\r\nAll native messaging hosts are allowed by default. But, if all native messaging hosts are denied by policy, the admin can use the allow list to change that policy.\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingallowlist_nativemessagingallowlistdesc","displayName":"Names of the native messaging hosts to exempt from the blocklist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingblocklist","displayName":"Configure native messaging blocklist","description":"Setting the policy specifies which native messaging hosts shouldn't be loaded. A deny list value of * means all native messaging hosts are denied, unless they're explicitly allowed.\r\n\r\nLeaving the policy unset means Google Chrome loads all installed native messaging hosts.\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingblocklist_nativemessagingblocklistdesc","displayName":"Names of the forbidden native messaging hosts (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessaginguserlevelhosts","displayName":"Allow user-level Native Messaging hosts (installed without admin permissions)","description":"Setting the policy to Enabled or leaving it unset means Google Chrome can use native messaging hosts installed at the user level.\r\n\r\nSetting the policy to Disabled means Google Chrome can only use these hosts if installed at the system level.","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessaginguserlevelhosts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessaginguserlevelhosts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~other_promptonmultiplematchingcertificates","displayName":"Prompt for the client certificate when multiple certificates match.","description":"This policy controls whether the user is prompted to select a client certificate when more than one certificate matches AutoSelectCertificateForUrls.\r\nIf this policy is set to Enabled, the user is prompted to select a client certificate whenever the auto-selection policy matches multiple certificates.\r\nIf this policy is set to Disabled or not set, the user may only be prompted when no certificate matches the auto-selection.","helpText":"","infoUrls":[],"categoryId":"b46f4e70-d3d1-4177-8e22-62f806d4568c","categoryName":"Other","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~other_promptonmultiplematchingcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~other_promptonmultiplematchingcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordleakdetectionenabled","displayName":"Enable leak detection for entered credentials","description":"Setting the policy to Enabled lets users have Google Chrome check whether usernames and passwords entered were part of a leak.\r\n\r\nIf the policy is set, users can't change it in Google Chrome. If not set, credential leak checking is allowed, but the user can turn it off.\r\n\r\nThis behavior will not trigger if Safe Browsing is disabled (either by policy or by the user). In order to force Safe Browsing on, use the SafeBrowsingEnabled policy or the SafeBrowsingProtectionLevel policy.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordleakdetectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordleakdetectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordmanagerenabled","displayName":"Enable saving passwords to the password manager","description":"Setting the policy to Enabled means users have Google Chrome remember passwords and provide them the next time they sign in to a site.\r\n\r\nSetting the policy to Disabled means users can't save new passwords, but previously saved passwords will still work.\r\n\r\nIf the policy is set, users can't change it in Google Chrome. If not set, the user can turn off password saving.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordmanagerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordmanagerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled","displayName":"Enable Google Cloud Print proxy","description":"Setting the policy to Enabled or leaving it unset lets Google Chrome act as a proxy between Google Cloud Print and legacy printers connected to the machine. Using their Google Account, users may turn on the cloud print proxy by authentication.\r\n\r\nSetting the policy to Disabled means users can't turn on the proxy, and the machine can't share its printers with Google Cloud Print.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintsubmitenabled","displayName":"Enable submission of documents to Google Cloud Print","description":"Setting the policy to Enabled or leaving it unset lets users print to Google Cloud Print from the Google Chrome print dialog. Google Chrome can submit documents to Google Cloud Print for printing. This doesn't prevent users from submitting print jobs on websites.\r\n\r\nSetting the policy to Disabled means users can't print to Google Cloud Print from the Google Chrome print dialog.\r\n\r\nIn order to keep Google Cloud Print destinations discoverable, this policy must be set to Enabled and cloud must not be included in the PrinterTypeDenyList policy.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintsubmitenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintsubmitenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection","displayName":"Default printer selection rules","description":"Setting the policy sets the rules for selecting the default printer in Google Chrome, overriding the default rules. Printer selection occurs the first time users try to print, when Google Chrome seeks a printer matching the specified attributes. In case of a less than perfect match, Google Chrome can be set to select any matching printer, depending on the order printers are discovered.\r\n\r\nLeaving the policy unset or set to attributes for which there's no match means the built-in PDF printer is the default. If there's no PDF printer, Google Chrome defaults to none.\r\n\r\nPrinters connected to Google Cloud Print are considered \"cloud\", the rest of the printers are classified as \"local\".\r\n\r\nNote: Omitting a field means all values match. For example, not specifying connectivity causes Print Preview to start discovery of all kinds of printers, \"local\" and \"cloud\". Regular expression patterns must follow the JavaScript RegExp syntax, and matches are case sensistive.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=DefaultPrinterSelection for more information about schema and formatting.\r\n\r\n\r\nExample value: { \"kind\": \"cloud\", \"idPattern\": \".*public\", \"namePattern\": \".*Color\" }","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection_defaultprinterselection","displayName":"Default printer selection rules (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_disableprintpreview","displayName":"Disable Print Preview","description":"Setting the policy to Enabled has Google Chrome open the system print dialog instead of the built-in print preview when users request a printout.\r\n\r\nSetting the policy to Disabled or leaving it unset has print commands trigger the print preview screen.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_disableprintpreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_disableprintpreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist","displayName":"Disable printer types on the deny list","description":"The printers of types placed on the deny list will be disabled from being discovered or having their capabilities fetched.\r\n\r\nPlacing all printer types on the deny list effectively disables printing, as there would be no available destinations to send a document for printing.\r\n\r\nIncluding cloud on the deny list has the same effect as setting the CloudPrintSubmitEnabled policy to false. In order to keep Google Cloud Print destinations discoverable, the CloudPrintSubmitEnabled policy must be set to true and cloud must not be on the deny list.\r\n\r\nIf the policy is not set, or is set to an empty list, all printer types will be available for discovery.\r\n\r\nExtension printers are also known as print provider destinations, and include any destination that belongs to a Google Chrome extension.\r\n\r\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\r\n\r\nExample value:\r\n\r\ncloud\r\nprivet","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist_printertypedenylistdesc","displayName":"Disable printer types on the deny list (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter","displayName":"Print Headers and Footers","description":"Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview.\r\n\r\nIf you set the policy, users can't change it. If unset, users decides whether headers and footers appear.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode","description":"Restricts background graphics printing mode. Unset policy is treated as no restriction.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_any","displayName":"Allow printing both with and without background graphics","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_enabled","displayName":"Allow printing only with background graphics","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_disabled","displayName":"Allow printing only without background graphics","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode","description":"Overrides default background graphics printing mode.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_enabled","displayName":"Enable background graphics printing mode by default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_disabled","displayName":"Disable background graphics printing mode by default","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingenabled","displayName":"Enable printing","description":"Setting the policy to Enabled or leaving it unset lets users print in Google Chrome, and users can't change this setting.\r\n\r\nSetting the policy to Disabled means users can't print from Google Chrome. Printing is off in the three dots menu, extensions, and JavaScript applications.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault","displayName":"Default printing page size","description":"Overrides default printing page size.\r\n\r\nname should contain one of the listed formats or 'custom' if required paper size is not in the list. If 'custom' value is provided custom_size property should be specified. It describes the desired height and width in micrometers. Otherwise custom_size property shouldn't be specified. Policy that violates these rules is ignored.\r\n\r\nIf the page size is unavailable on the printer chosen by the user this policy is ignored.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=PrintingPaperSizeDefault for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"name\": \"custom\",\r\n \"custom_size\": {\r\n \"width\": 210000,\r\n \"height\": 297000\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault_printingpapersizedefault","displayName":"Default printing page size (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpdfasimageavailability","displayName":"Print PDF as Image Available","description":"Controls how Google Chrome makes the Print as image option available on Microsoft® Windows® and macOS when printing PDFs.\r\n\r\nWhen printing a PDF on Microsoft® Windows® or macOS, sometimes print jobs need to be rasterized to an image for certain printers to get correct looking output.\r\n\r\nWhen this policy is set to Enabled, Google Chrome will make the Print as image option available in the Print Preview when printing a PDF.\r\n\r\nWhen this policy is set to Disabled or not set Google Chrome the Print as image option will not be available to users in Print Preview and PDFs will be printed as usual without being rasterized to an image before being sent to the destination.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpdfasimageavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpdfasimageavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode","displayName":"Print PostScript Mode","description":"Controls how Google Chrome prints on Microsoft® Windows®.\r\n\r\nWhen printing to a PostScript printer on Microsoft® Windows® different PostScript generation methods can affect printing performance.\r\n\r\nWhen this policy is set to Default, Google Chrome will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts.\r\n\r\nWhen this policy is set to Type42, Google Chrome will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\r\n\r\nWhen this policy is not set, Google Chrome will be in Default mode.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode","displayName":"Print PostScript Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode_0","displayName":"Default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode_1","displayName":"Type42","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpreviewusesystemdefaultprinter","displayName":"Use System Default Printer as Default","description":"Setting the policy to Enabled means Google Chrome uses the OS default printer as the default destination for print preview.\r\n\r\nSetting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpreviewusesystemdefaultprinter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpreviewusesystemdefaultprinter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode","displayName":"Print Rasterization Mode","description":"Controls how Google Chrome prints on Microsoft® Windows®.\r\n\r\nWhen printing to a non-PostScript printer on Microsoft® Windows®, sometimes print jobs need to be rasterized to print correctly.\r\n\r\nWhen this policy is set to Full, Google Chrome will do full page rasterization if necessary.\r\n\r\nWhen this policy is set to Fast, Google Chrome will avoid rasterization if possible, reducing the amount of rasterization can help reduce print job sizes and increase printing speed.\r\n\r\nWhen this policy is not set, Google Chrome will be in Full mode.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_printrasterizationmode","displayName":"Print Rasterization Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_printrasterizationmode_0","displayName":"Full","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_printrasterizationmode_1","displayName":"Fast","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI","description":"Controls print image resolution when Google Chrome prints PDFs with rasterization.\r\n\r\nWhen printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution will significantly increase the processing and printing time while a low resolution can lead to poor imaging quality.\r\n\r\nThis policy allows a particular resolution to be specified for use when rasterizing PDFs for printing.\r\n\r\nIf this policy is set to zero or not set at all then the system default resolution will be used during rasterization of page images.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizepdfdpi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizepdfdpi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizepdfdpi_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowclientpairing","displayName":"Enable or disable PIN-less authentication for remote access hosts","description":"Setting the policy to Enabled or leaving it unset lets users pair clients and hosts at connection time, eliminating the need to enter a PIN every time.\r\n\r\nSetting the policy to Disabled makes this feature unavailable.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowclientpairing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowclientpairing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer","displayName":"Allow remote access users to transfer files to/from the host","description":"Setting the policy to Enabled or leaving it unset allows users connected to a remote access host to transfer files between the client and the host. This doesn't apply to remote assistance connections, which don't support file transfer.\r\n\r\nSetting the policy to Disabled disallows file transfer.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowrelayedconnection","displayName":"Enable the use of relay servers by the remote access host","description":"If RemoteAccessHostFirewallTraversal is set to Enabled, setting RemoteAccessHostAllowRelayedConnection to Enabled or leaving it unset allows the use of remote clients to use relay servers to connect to this machine when a direct connection is not available, for example, because of firewall restrictions.\r\n\r\nSetting the policy to Disabled doesn't turn remote access off, but only allows connections from the same network (not NAT traversal or relay).","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowrelayedconnection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowrelayedconnection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowremoteaccessconnections","displayName":"Allow remote access connections to this machine","description":"If this policy is Disabled, the remote access host service cannot be started or configured to accept incoming connections. This policy does not affect remote support scenarios.\r\n\r\nThis policy has no effect if it is set to Enabled, left empty, or is not set.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowremoteaccessconnections_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowremoteaccessconnections_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowremotesupportconnections","displayName":"Allow remote support connections to this machine","description":"If this policy is disabled, the remote support host cannot be started or configured to accept incoming connections.\r\n\r\nThis policy does not affect remote access scenarios.\r\n\r\nThis policy does not prevent enterprise admins from connecting to managed Chrome OS devices.\r\n\r\nThis policy has no effect if enabled, left empty, or is not set.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowremotesupportconnections_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowremotesupportconnections_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowuiaccessforremoteassistance","displayName":"Allow remote users to interact with elevated windows in remote assistance sessions","description":"Setting the policy to Enabled means the remote assistance host runs in a process with uiAccess permissions. This lets remote users interact with elevated windows on the local user's desktop.\r\n\r\nSetting the policy to Disabled or leaving it unset means the remote assistance host runs in the user's context, and remote users can't interact with elevated windows on the desktop.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowuiaccessforremoteassistance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowuiaccessforremoteassistance_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist","displayName":"Configure the required domain names for remote access clients","description":"Setting the policy specifies the client domain names that are imposed on remote access clients, and users can't change them. Only clients from one of the specified domains can connect to the host.\r\n\r\nSetting the policy to an empty list or leaving it unset applies the default policy for the connection type. For remote assistance, this allows clients from any domain to connect to the host. For anytime remote access, only the host owner can connect.\r\n\r\nSee also RemoteAccessHostDomainList.\r\n\r\nNote: This setting overrides RemoteAccessHostClientDomain, if present.\r\n\r\nExample value:\r\n\r\nmy-awesome-domain.com\r\nmy-auxiliary-domain.com","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist_remoteaccesshostclientdomainlistdesc","displayName":"Configure the required domain names for remote access clients (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes","displayName":"The maximum size, in bytes, that can be transferred between client and host via clipboard synchronization","description":"If this policy is set, clipboard data sent to and from the host will be truncated to the limit set by this policy.\r\n\r\nIf a value of 0 is set, then clipboard sync is disabled.\r\n\r\nThis policy affects both remote access and remote support scenarios.\r\n\r\nThis policy has no effect if it is not set.\r\n\r\nSetting the policy to a value that is not within the min/max range may prevent the host from starting.\r\n\r\nPlease note that the actual upper bound for the clipboard size is based on the maximum WebRTC data channel message size which this policy does not control.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes_remoteaccesshostclipboardsizebytes","displayName":"The maximum size, in bytes, that can be transferred between client and host via clipboard synchronization: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostdomainlist","displayName":"Configure the required domain names for remote access hosts","description":"Setting the policy specifies the host domain names that are imposed on remote access hosts, and users can't change them. Hosts can be shared only using accounts registered on one of the specified domain names.\r\n\r\nSetting the policy to an empty list or leaving it unset means hosts can be shared using any account.\r\n\r\nSee also RemoteAccessHostClientDomainList.\r\n\r\nNote: This setting will override RemoteAccessHostDomain, if present.\r\n\r\nExample value:\r\n\r\nmy-awesome-domain.com\r\nmy-auxiliary-domain.com","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostdomainlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostdomainlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostdomainlist_remoteaccesshostdomainlistdesc","displayName":"Configure the required domain names for remote access hosts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostfirewalltraversal","displayName":"Enable firewall traversal from remote access host","description":"Setting the policy to Enabled or leaving it unset allows the usage of STUN servers, letting remote clients discover and connect to this machine, even if separated by a firewall.\r\n\r\nSetting the policy to Disabled when outgoing UDP connections are filtered by the firewall means the machine only allows connections from client machines within the local network.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostfirewalltraversal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostfirewalltraversal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes","displayName":"Maximum session duration allowed for remote access connections","description":"If this policy is set, remote access connections will automatically disconnect after the number of minutes defined in the policy have elapsed. This does not prevent the client from reconnecting after the maximum session duration has been reached. Setting the policy to a value that is not within the min/max range may prevent the host from starting. This policy does not affect remote support scenarios.\r\n\r\nThis policy has no effect if it is not set. In this case, remote access connections will have no maximum duration on this machine.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes_remoteaccesshostmaximumsessiondurationminutes","displayName":"Maximum session duration allowed for remote access connections: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostrequirecurtain","displayName":"Enable curtaining of remote access hosts","description":"Setting the policy to Enabled turns off remote access hosts' physical input and output devices during a remote connection.\r\n\r\nSetting the policy to Disabled or leaving it unset lets both local and remote users interact with the host while it's shared.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostrequirecurtain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostrequirecurtain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostudpportrange","displayName":"Restrict the UDP port range used by the remote access host","description":"Setting the policy restricts the UDP port range used by the remote access host in this machine.\r\n\r\nLeaving the policy unset or set to an empty string means the remote access host can use any available port.\r\n\r\nNote: If RemoteAccessHostFirewallTraversal is Disabled, the remote access host will use UDP ports in the 12400-12409 range.\r\n\r\nExample value: 12400-12409","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostudpportrange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostudpportrange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostudpportrange_remoteaccesshostudpportrange","displayName":"Restrict the UDP port range used by the remote access host (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_additionallaunchparameters","displayName":"Additional command line parameters for Google Chrome","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_additionallaunchparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_additionallaunchparameters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_additionallaunchparameters_additionallaunchparameters","displayName":"Additional command line parameters for Google Chrome (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled","displayName":"Enable sending downloads to Google for deep scanning for users enrolled in the Advanced Protection program","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowoutdatedplugins","displayName":"Allow running plugins that are outdated","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowoutdatedplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowoutdatedplugins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowpopupsduringpageunload","displayName":"Allows a page to show popups during its unloading","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowpopupsduringpageunload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowpopupsduringpageunload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_alwaysauthorizeplugins","displayName":"Always runs plugins that require authorization (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_alwaysauthorizeplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_alwaysauthorizeplugins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_appcacheforceenabled","displayName":"Allows the AppCache feature to be re-enabled even if it is off by default.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_appcacheforceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_appcacheforceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframecontenttypes","displayName":"Allow Google Chrome Frame to handle the listed content types","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframecontenttypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframecontenttypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframecontenttypes_chromeframecontenttypesdesc","displayName":"Allow Google Chrome Frame to handle the listed content types (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings","displayName":"Default HTML renderer for Google Chrome Frame","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_chromeframerenderersettings","displayName":"Default HTML renderer for Google Chrome Frame (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_chromeframerenderersettings_0","displayName":"Use the host browser by default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_chromeframerenderersettings_1","displayName":"Use Google Chrome Frame by default","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_clearsitedataonexit","displayName":"Clear site data on browser shutdown (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_clearsitedataonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_clearsitedataonexit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_cloudprintwarningssuppressed","displayName":"Suppress Google Cloud Print deprecation messages","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_cloudprintwarningssuppressed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_cloudprintwarningssuppressed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corslegacymodeenabled","displayName":"Use the legacy CORS implementation rather than new CORS","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corslegacymodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corslegacymodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist","displayName":"Enable CORS check mitigations in the new CORS implementation","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_corsmitigationlistdesc","displayName":"Enable CORS check mitigations in the new CORS implementation (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting","displayName":"Control use of the File Handling API","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_defaultfilehandlingguardsetting","displayName":"Control use of the File Handling API (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_defaultfilehandlingguardsetting_2","displayName":"Do not allow any web app to access file types via the File Handling API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_defaultfilehandlingguardsetting_3","displayName":"Allow web apps to ask the user to grant access to file types via the File Handling API","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting","displayName":"Default key generation setting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_defaultkeygensetting","displayName":"Default key generation setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_defaultkeygensetting_1","displayName":"Allow all sites to use key generation","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_defaultkeygensetting_2","displayName":"Do not allow any site to use key generation","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting","displayName":"Default Flash setting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting","displayName":"Default Flash setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting_1","displayName":"Allow all sites to automatically run the Flash plugin","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting_2","displayName":"Block the Flash plugin","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting_3","displayName":"Click to play","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl","displayName":"Default search provider instant URL","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_defaultsearchproviderinstanturl","displayName":"Default search provider instant URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturlpostparams","displayName":"Parameters for instant URL which uses POST","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturlpostparams_defaultsearchproviderinstanturlpostparams","displayName":"Parameters for instant URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey","displayName":"Parameter controlling search term placement for the default search provider","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_defaultsearchprovidersearchtermsreplacementkey","displayName":"Parameter controlling search term placement for the default search provider (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_dheenabled","displayName":"Enable DHE cipher suites in TLS","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_dheenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_dheenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins","displayName":"Specify a list of disabled plugins","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins_disabledpluginsdesc","displayName":"List of disabled plugins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledpluginsexceptions","displayName":"Specify a list of plugins that the user can enable or disable","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledpluginsexceptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledpluginsexceptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledpluginsexceptions_disabledpluginsexceptionsdesc","displayName":"List of exceptions to the list of disabled plugins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablepluginfinder","displayName":"Specify whether the plugin finder should be disabled (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablepluginfinder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablepluginfinder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablespdy","displayName":"Disable SPDY protocol","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablespdy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablespdy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablesslrecordsplitting","displayName":"Disable TLS False Start","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablesslrecordsplitting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablesslrecordsplitting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_dnsprefetchingenabled","displayName":"Enable network prediction","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_dnsprefetchingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_dnsprefetchingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablecommonnamefallbackforlocalanchors","displayName":"Allow certificates issued by local trust anchors without subjectAlternativeName extension","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablecommonnamefallbackforlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablecommonnamefallbackforlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedprivetprinting","displayName":"Enable deprecated privet printing","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedprivetprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedprivetprinting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebbasedsignin","displayName":"Enable the old web-based signin flow","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebbasedsignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebbasedsignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebplatformfeatures","displayName":"Enable deprecated web platform features for a limited time","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebplatformfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebplatformfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedwebplatformfeatures_enabledeprecatedwebplatformfeaturesdesc","displayName":"Enable deprecated web platform features for a limited time (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledplugins","displayName":"Specify a list of enabled plugins","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledplugins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledplugins_enabledpluginsdesc","displayName":"List of enabled plugins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesha1forlocalanchors","displayName":"Allow SHA-1 signed certificates issued by local trust anchors","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesha1forlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesha1forlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesymanteclegacyinfrastructure","displayName":"Enable trust in Symantec Corporation's Legacy PKI Infrastructure","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesymanteclegacyinfrastructure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesymanteclegacyinfrastructure_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename","displayName":"Enterprise web store name (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_enterprisewebstorename","displayName":"Enterprise web store name (deprecated) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl","displayName":"Enterprise web store URL (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl_enterprisewebstoreurl","displayName":"Enterprise web store URL (deprecated) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_extensionallowinsecureupdates","displayName":"Allow insecure algorithms in integrity checks on extension updates and installs","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_extensionallowinsecureupdates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_extensionallowinsecureupdates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls","displayName":"Allow the File Handling API on these web apps","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_filehandlingallowedforurlsdesc","displayName":"Allow the File Handling API on these web apps (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingblockedforurls","displayName":"Block the File Handling API on these web apps","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingblockedforurls_filehandlingblockedforurlsdesc","displayName":"Block the File Handling API on these web apps (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcelegacydefaultreferrerpolicy","displayName":"Use a default referrer policy of no-referrer-when-downgrade.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcelegacydefaultreferrerpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcelegacydefaultreferrerpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcenetworkinprocess","displayName":"Force networking code to run in the browser process","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcenetworkinprocess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcenetworkinprocess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_gcfuserdatadir","displayName":"Set Google Chrome Frame user data directory","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_gcfuserdatadir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_gcfuserdatadir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_gcfuserdatadir_gcfuserdatadir","displayName":"Set user data directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_hidewebstorepromo","displayName":"Prevent app promotions from appearing on the new tab page","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_hidewebstorepromo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_hidewebstorepromo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_http09onnondefaultportsenabled","displayName":"Enable HTTP/0.9 support on non-default ports","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_http09onnondefaultportsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_http09onnondefaultportsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_instantenabled","displayName":"Enable Instant","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_instantenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_instantenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenallowedforurls","displayName":"Allow key generation on these sites","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenallowedforurls_keygenallowedforurlsdesc","displayName":"Allow key generation on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls","displayName":"Block key generation on these sites","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_keygenblockedforurlsdesc","displayName":"Block key generation on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled","displayName":"Default legacy SameSite cookie behavior setting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled","displayName":"Default legacy SameSite cookie behavior setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_1","displayName":"Revert to legacy SameSite behavior for cookies on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_2","displayName":"Use SameSite-by-default behavior for cookies on all sites","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_localdiscoveryenabled","displayName":"Enable chrome://devices","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_localdiscoveryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_localdiscoveryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_machinelevelusercloudpolicyenrollmenttoken","displayName":"The enrollment token of cloud policy on desktop","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_machinelevelusercloudpolicyenrollmenttoken_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_machinelevelusercloudpolicyenrollmenttoken_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_machinelevelusercloudpolicyenrollmenttoken_machinelevelusercloudpolicyenrollmenttoken","displayName":"The enrollment token of cloud policy on desktop (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize","displayName":"Set media disk cache size in bytes","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_mediacachesize","displayName":"Set media disk cache size: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pachttpsurlstrippingenabled","displayName":"Enable PAC URL stripping (for https://)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pachttpsurlstrippingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pachttpsurlstrippingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_passwordmanagerallowshowpasswords","displayName":"Allow users to show passwords in Password Manager (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_passwordmanagerallowshowpasswords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_passwordmanagerallowshowpasswords_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls","displayName":"Allow the Flash plugin on these sites","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls_pluginsallowedforurlsdesc","displayName":"Allow the Flash plugin on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsblockedforurls","displayName":"Block the Flash plugin on these sites","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsblockedforurls_pluginsblockedforurlsdesc","displayName":"Block the Flash plugin on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled","displayName":"Enable RC4 cipher suites in TLS","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccessclientfirewalltraversal","displayName":"Enable firewall traversal from remote access client","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccessclientfirewalltraversal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccessclientfirewalltraversal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies","displayName":"Policy overrides for Debug builds of the remote access host","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies_remoteaccesshostdebugoverridepolicies","displayName":"Policy overrides for Debug builds of the remote access host (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostrequiretwofactor","displayName":"Enable two-factor authentication for remote access hosts","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostrequiretwofactor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostrequiretwofactor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshosttalkgadgetprefix","displayName":"Configure the TalkGadget prefix for remote access hosts","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshosttalkgadgetprefix_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshosttalkgadgetprefix_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshosttalkgadgetprefix_remoteaccesshosttalkgadgetprefix","displayName":"Configure the TalkGadget prefix for remote access hosts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinchromeframelist","displayName":"Always render the following URL patterns in Google Chrome Frame","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinchromeframelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinchromeframelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinchromeframelist_renderinchromeframelistdesc","displayName":"Always render the following URL patterns in Google Chrome Frame (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist","displayName":"Always render the following URL patterns in the host browser","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist_renderinhostlistdesc","displayName":"Always render the following URL patterns in the host browser (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_runallflashinallowmode","displayName":"Extend Flash content setting to all content (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_runallflashinallowmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_runallflashinallowmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_safebrowsingextendedreportingoptinallowed","displayName":"Allow users to opt in to Safe Browsing extended reporting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_safebrowsingextendedreportingoptinallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_safebrowsingextendedreportingoptinallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_skipmetadatacheck","displayName":"Skip the meta tag check in Google Chrome Frame","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_skipmetadatacheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_skipmetadatacheck_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin","displayName":"Minimum TLS version to fallback to","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_sslversionfallbackmin","displayName":"Minimum TLS version to fallback to (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_sslversionfallbackmin_tls1.1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_sslversionfallbackmin_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax","displayName":"Maximum SSL version enabled","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_sslversionmax","displayName":"Maximum SSL version enabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_sslversionmax_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_sslversionmax_tls1.3","displayName":"TLS 1.3","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_supervisedusercreationenabled","displayName":"Enable creation of supervised users","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_supervisedusercreationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_supervisedusercreationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_suppresschromeframeturndownprompt","displayName":"Suppress the Google Chrome Frame turndown prompt","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_suppresschromeframeturndownprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_suppresschromeframeturndownprompt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled","displayName":"Allow background tabs freeze","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabunderallowed","displayName":"Allow sites to simultaneously navigate and open pop-ups","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabunderallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabunderallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tls13hardeningforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tls13hardeningforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tripledesenabled","displayName":"Enable 3DES cipher suites in TLS","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tripledesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tripledesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_uselegacyformcontrols","displayName":"Use Legacy Form Controls until M84.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_uselegacyformcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_uselegacyformcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_useragentclienthintsenabled","displayName":"Control the User-Agent Client Hints feature.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_useragentclienthintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_useragentclienthintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webdriveroverridesincompatiblepolicies","displayName":"Allow WebDriver to Override Incompatible Policies","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webdriveroverridesincompatiblepolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webdriveroverridesincompatiblepolicies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_welcomepageonosupgradeenabled","displayName":"Enable showing the welcome page on the first browser launch following OS upgrade","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_welcomepageonosupgradeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_welcomepageonosupgradeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL.","description":"Setting the policy sets the URL for users to change their password after seeing a warning in the browser. The password protection service sends users to the URL (HTTP and HTTPS protocols only) you designate through this policy. For Google Chrome to correctly capture the salted hash of the new password on this change password page, make sure your change password page follows these guidelines ( https://www.chromium.org/developers/design-documents/create-amazing-password-forms ).\r\n\r\nTurning the policy off or leaving it unset means the service sends users to https://myaccount.google.com to change their password.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://mydomain.com/change_password.html","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionchangepasswordurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionchangepasswordurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionchangepasswordurl_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls","displayName":"Configure the list of enterprise login URLs where password protection service should capture salted hashes of passwords.","description":"Setting the policy sets the list of enterprise login URLs (HTTP and HTTPS protocols only). Password protection service will capture salted hashes of passwords on these URLs and use them for password reuse detection. For Google Chrome to correctly capture password salted hashes, ensure your sign-in pages follow these guidelines ( https://www.chromium.org/developers/design-documents/create-amazing-password-forms ).\r\n\r\nTurning this setting off or leaving it unset means the password protection service only captures the password salted hashes on https://accounts.google.com.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nhttps://mydomain.com/login.html\r\nhttps://login.mydomain.com","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls_passwordprotectionloginurlsdesc","displayName":"Configure the list of enterprise login URLs where password protection service should capture salted hashes of passwords. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger","displayName":"Password protection warning trigger","description":"Setting the policy lets you control the triggering of password protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites.\r\n\r\nUse PasswordProtectionLoginURLs and PasswordProtectionChangePasswordURL to set which password to protect.\r\n\r\nIf this policy is set to:\r\n\r\n* PasswordProtectionWarningOff, no password protection warning will be shown.\r\n\r\n* PasswordProtectionWarningOnPasswordReuse, password protection warning will be shown when the user reuses their protected password on a non-allowed site.\r\n\r\n* PasswordProtectionWarningOnPhishingReuse, password protection warning will be shown when the user reuses their protected password on a phishing site.\r\n\r\nLeaving the policy unset has the password protection service only protect Google passwords, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger","displayName":"Password protection warning trigger (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger_0","displayName":"Password protection warning is off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger_1","displayName":"Password protection warning is triggered by password reuse","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger_2","displayName":"Password protection warning is triggered by password reuse on phishing page","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains","displayName":"Configure the list of domains on which Safe Browsing will not trigger warnings.","description":"Setting the policy to Enabled means Safe Browsing will trust the domains you designate. It won't check them for dangerous resources such as phishing, malware, or unwanted software. Safe Browsing's download protection service won't check downloads hosted on these domains. Its password protection service won't check for password reuse.\r\n\r\nLeaving the policy unset means default Safe Browsing protection applies to all resources.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains_safebrowsingallowlistdomainsdesc","displayName":"Configure the list of domains on which Safe Browsing will not trigger warnings. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingextendedreportingenabled","displayName":"Enable Safe Browsing Extended Reporting","description":"Setting the policy to Enabled turns on Google Chrome's Safe Browsing Extended Reporting, which sends some system information and page content to Google servers to help detect dangerous apps and sites.\r\n\r\nSetting the policy to Disabled means reports are never sent.\r\n\r\nIf you set this policy, users can't change it. If not set, users can decide whether to send reports or not.\r\n\r\nSee more about Safe Browsing ( https://developers.google.com/safe-browsing ).","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingextendedreportingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingextendedreportingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel","displayName":"Safe Browsing Protection Level","description":"Allows you to control whether Google Chrome's Safe Browsing feature is enabled and the mode it operates in.\r\n\r\nIf this policy is set to 'NoProtection' (value 0), Safe Browsing is never active.\r\n\r\nIf this policy is set to 'StandardProtection' (value 1, which is the default), Safe Browsing is always active in the standard mode.\r\n\r\nIf this policy is set to 'EnhancedProtection' (value 2), Safe Browsing is always active in the enhanced mode, which provides better security, but requires sharing more browsing information with Google.\r\n\r\nIf you set this policy as mandatory, users cannot change or override the Safe Browsing setting in Google Chrome.\r\n\r\nIf this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting.\r\n\r\nSee https://developers.google.com/safe-browsing for more info on Safe Browsing.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel_safebrowsingprotectionlevel","displayName":"Safe Browsing Protection Level (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel_safebrowsingprotectionlevel_0","displayName":"Safe Browsing is never active.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel_safebrowsingprotectionlevel_1","displayName":"Safe Browsing is active in the standard mode.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingprotectionlevel_safebrowsingprotectionlevel_2","displayName":"Safe Browsing is active in the enhanced mode. This mode provides better security, but requires sharing more browsing information with Google.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins","displayName":"Allow Same Origin Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this level of capture.\r\n\r\nNote that windowed Chrome Apps with the same origin as this site will still be allowed to be captured.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: TabCaptureAllowedByOrigins, WindowCaptureAllowedByOrigins, ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins_sameorigintabcaptureallowedbyoriginsdesc","displayName":"Allow Same Origin Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowed","displayName":"Allow or deny screen capture","description":"If enabled or not configured (default), a Web page can use\r\nscreen-share APIs (e.g., getDisplayMedia() or the Desktop Capture extension API)\r\nto prompt the user to select a tab, window or desktop to capture.\r\n\r\nWhen this policy is disabled, any calls to screen-share APIs will fail\r\nwith an error; however this policy is not considered (and a site will be\r\nallowed to use screen-share APIs) if the site matches an origin pattern in\r\nany of the following policies:\r\nScreenCaptureAllowedByOrigins,\r\nWindowCaptureAllowedByOrigins,\r\nTabCaptureAllowedByOrigins,\r\nSameOriginTabCaptureAllowedByOrigins.\r\n","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowedbyorigins","displayName":"Allow Desktop, Window, and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this level of Capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in any of the following policies: WindowCaptureAllowedByOrigins, TabCaptureAllowedByOrigins, SameOriginTabCaptureAllowedByOrigins.\r\n\r\nIf a site matches a URL pattern in this policy, the ScreenCaptureAllowed will not be considered.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowedbyorigins_screencaptureallowedbyoriginsdesc","displayName":"Allow Desktop, Window, and Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_tabcaptureallowedbyorigins","displayName":"Allow Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this level of capture.\r\n\r\nNote that windowed Chrome Apps will still be allowed to be captured.\r\n\r\nThis policy is not considered if a site matches a URL pattern in the SameOriginTabCaptureAllowedByOrigins policy.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: WindowCaptureAllowedByOrigins, ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_tabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_tabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_tabcaptureallowedbyorigins_tabcaptureallowedbyoriginsdesc","displayName":"Allow Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_windowcaptureallowedbyorigins","displayName":"Allow Window and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Window and Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this level of Capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in any of the following policies: TabCaptureAllowedByOrigins, SameOriginTabCaptureAllowedByOrigins.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_windowcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_windowcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_windowcaptureallowedbyorigins_windowcaptureallowedbyoriginsdesc","displayName":"Allow Window and Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepageisnewtabpage","displayName":"Use New Tab Page as homepage","description":"Setting the policy to Enabled makes the New Tab page the user's homepage, ignoring any homepage URL location. Setting the policy to Disabled means that their homepage is never the New Tab page, unless the user's homepage URL is set to chrome://newtab.\r\n\r\nIf you set the policy, users can't change their homepage type in Google Chrome. If not set, the user decides whether or not the New Tab page is their homepage.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepageisnewtabpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepageisnewtabpage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation","displayName":"Configure the home page URL","description":"Setting the policy sets the default homepage URL in Google Chrome. You open the homepage using the Home button. On desktop, the RestoreOnStartup policies control the pages that open on startup.\r\n\r\nIf the homepage is set to the New Tab Page, by the user or HomepageIsNewTabPage, this policy has no effect.\r\n\r\n The URL needs a standard scheme, such as http://example.com or https://example.com. When this policy is set, users can't change their homepage URL in Google Chrome.\r\n\r\nLeaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_homepagelocation","displayName":"Home page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation","displayName":"Configure the New Tab page URL","description":"Setting the policy configures the default New Tab page URL and prevents users from changing it.\r\n\r\nThe New Tab page opens with new tabs and windows.\r\n\r\nThis policy doesn't decide which pages open on start up. Those are controlled by the RestoreOnStartup policies. This policy does affect the homepage, if that's set to open the New Tab page, as well as the startup page if it's set to open the New Tab page.\r\n\r\nIt is a best practice to provide fully canonicalized URL, if the URL is not fully canonicalized Google Chrome will default to https://.\r\n\r\nLeaving the policy unset or empty puts the default New Tab page in use.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation_newtabpagelocation","displayName":"New Tab page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup","displayName":"Action on startup","description":"Setting the policy lets you specify system behavior on startup. Turning this setting off amounts to leaving it unset as Google Chrome must have specified start up behavior.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users can change it.\r\n\r\nSetting this policy to RestoreOnStartupIsLastSession turns off some settings that rely on sessions or that perform actions on exit, such as clearing browsing data on exit or session-only cookies.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup","displayName":"Action on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup_5","displayName":"Open New Tab Page","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartupurls","displayName":"URLs to open on startup","description":"If RestoreOnStartup is set to RestoreOnStartupIsURLs, then setting RestoreOnStartupURLs to a list of URLs specify which URLs open.\r\n\r\nIf not set, the New Tab page opens on start up.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nhttps://example.com\r\nhttps://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartupurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartupurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartupurls_restoreonstartupurlsdesc","displayName":"URLs to open on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_showhomebutton","displayName":"Show Home button on toolbar","description":"Setting the policy to Enabled shows the Home button on Google Chrome's toolbar. Setting the policy to Disabled keeps the Home button from appearing.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users chooses whether to show the Home button.","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_showhomebutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_showhomebutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowbackforwardcacheforcachecontrolnostorepageenabled","displayName":"Allow pages with Cache-Control: no-store header to enter back/forward cache","description":"This policy controls if a page with Cache-Control: no-store header can be stored in back/forward cache. The website setting this header may not expect the page to be restored from back/forward cache since some sensitive information could still be displayed after the restoration even if it is no longer accessible.\r\n\r\nIf the policy is enabled or unset, the page with Cache-Control: no-store header might be restored from back/forward cache unless the cache eviction is triggered (e.g. when there is HTTP-only cookie change to the site).\r\n\r\nIf the policy is disabled, the page with Cache-Control: no-store header will not be stored in back/forward cache.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowbackforwardcacheforcachecontrolnostorepageenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowbackforwardcacheforcachecontrolnostorepageenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowwebauthnwithbrokentlscerts","displayName":"Allow Web Authentication requests on sites with broken TLS certificates.","description":"If set to Enabled, Google Chrome will\r\nallow Web Authentication requests on websites that have TLS certificates with\r\nerrors (i.e. websites considered not secure).\r\n\r\nIf the policy is set to Disabled or left unset, the default behavior of\r\nblocking such requests will apply.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowwebauthnwithbrokentlscerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowwebauthnwithbrokentlscerts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_applicationboundencryptionenabled","displayName":"Enable Application Bound Encryption","description":"Setting the policy to Enabled or leaving it unset binds encryption keys used for local data storage to Google Chrome whenever that is possible.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security as unknown and potentially hostile apps can retrieve encryption keys used to secure data.\r\n\r\nOnly turn off the policy if there are compatibility issues, such as other applications that need legitimate access to Google Chrome's data, encrypted user data is expected to be fully portable between different computers or the integrity and location of Google Chrome's executable files is not consistent.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_applicationboundencryptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_applicationboundencryptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability","displayName":"Enable Battery Saver Mode","description":"This policy enables or disables the Battery Saver Mode setting.\r\nOn Chrome, this setting makes it so that frame rate is throttled to lower power consumption. If this policy is unset, the end user can control this setting in chrome://settings/performance.\r\nOn ChromeOS, this setting makes it so that frame rate and CPU frequency are throttled, backlights are dimmed, and Android is put in Battery Saver Mode. On devices with multiple CPUs, some CPUs will be turned off.\r\nThe different levels are:\r\nDisabled (0): Battery Saver Mode will be disabled.\r\nEnabledBelowThreshold (1): Battery Saver Mode will be enabled when the device is on battery power and battery level is low.\r\nEnabledOnBattery (2): This value is deprecated as of M121. From M121 onwards, values will be treated as EnabledBelowThreshold.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability_batterysavermodeavailability","displayName":"Enable Battery Saver Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability_batterysavermodeavailability_0","displayName":"Battery Saver Mode will be disabled.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability_batterysavermodeavailability_1","displayName":"Battery Saver Mode will be enabled when the device is on battery power and battery level is low.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_batterysavermodeavailability_batterysavermodeavailability_2","displayName":"This value is deprecated as of M121. In M121 and after, values will be treated as EnabledBelowThreshold.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_builtinaiapisenabled","displayName":"Allow pages to use the built-in AI APIs.","description":"This policy controls if a page can use the built-in AI APIs (such as LanguageModel API, Summarization API, Writer API, and Rewriter API).\r\n\r\nIf the policy is enabled or unset, the APIs are enabled to be used.\r\n\r\nIf the policy is disabled, attempting using the APIs will result in an error.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_builtinaiapisenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_builtinaiapisenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_chromefortestingallowed","displayName":"Allow Chrome for Testing","description":"Controls whether users may use Chrome for Testing.\r\n\r\nIf this policy is set to Enabled or not set, users may install and run Chrome for Testing.\r\n\r\nIf this policy is set to Disabled, users are not allowed to run Chrome for Testing. Users will still be able to install Chrome for Testing, however it will not run with the profiles where this policy is set to Disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_chromefortestingallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_chromefortestingallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_domainreliabilityallowed","displayName":"Allow reporting of domain reliability related data","description":"If this policy is set false, domain reliability diagnostic data reporting is disabled and no data is sent to Google.\r\nIf this policy is set true or not set, domain reliability diagnostic data reporting will follow the behavior of MetricsReportingEnabled for Google Chrome or DeviceMetricsReportingEnabled for Google ChromeOS.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_domainreliabilityallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_domainreliabilityallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings","displayName":"Dynamic Code Settings","description":"This policy controls the dynamic code settings for Google Chrome.\r\n\r\nDisabling dynamic code improves the security of Google Chrome by preventing potentially hostile dynamic code and third-party code from making changes to Google Chrome's behavior, but might cause compatibility issues with third-party software (e.g. certain printer drivers) that must run inside the browser process.\r\n\r\nIf the policy is set to 0 - Default or left unset then Google Chrome will use the default settings.\r\n\r\nIf the policy is set to 1 - DisabledForBrowser then the Google Chrome browser process will be prevented from creating dynamic code.\r\n\r\nNote: Read more about process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_dynamiccodesettings","displayName":"Dynamic Code Settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_dynamiccodesettings_0","displayName":"Default dynamic code settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_dynamiccodesettings_1","displayName":"Prevent the browser process from creating dynamic code","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enableunsafeswiftshader","displayName":"Allow software WebGL fallback using SwiftShader","description":"A policy that controls if SwiftShader will be used as a WebGL fallback when hardware GPU acceleration is not available.\r\n\r\nSwiftShader has been used to support WebGL on systems without GPU acceleration such as headless systems or virtual machines but has been deprecated due to security issues. Starting in M139, WebGL context creation will fail when it would have otherwise used SwiftShader. This policy allows the browser or administrator to temporarily defer the deprecation.\r\n\r\nSetting the policy to Enabled, SwiftShader will be used as a software WebGL fallback.\r\n\r\nSetting the policy to Disabled or not set, WebGL context creation may fail if hardware GPU acceleration is not available. Web pages may misbehave if they do not gracefully handle WebGL context creation failure.\r\n\r\nThis is a temporary policy which will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enableunsafeswiftshader_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enableunsafeswiftshader_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_encryptedclienthelloenabled","displayName":"Enable TLS Encrypted ClientHello","description":"Encrypted ClientHello (ECH) is an extension to TLS to encrypt sensitive fields of the ClientHello and improve privacy.\r\n\r\nIf this policy is not configured, or is set to enabled, Google Chrome will follow the default rollout process for ECH. If it is disabled, Google Chrome will not enable ECH.\r\n\r\nWhen the feature is enabled, Google Chrome may or may not use ECH depending on server support, availability of the HTTPS DNS record, or rollout status.\r\n\r\nECH is an evolving protocol, so Google Chrome's implementation is subject to change. As such, this policy is a temporary measure to control the initial experimental implementation. It will be replaced with final controls as the protocol finalizes.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_encryptedclienthelloenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_encryptedclienthelloenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel","displayName":"Set a custom enterprise label for a managed profile","description":"This policy controls a custom label used to identify managed profiles. For managed profiles, this label will be shown next to the avatar in the toolbar. The custom label will not be translated.\r\n\r\nWhen this policy is applied, any strings that surpass 16 characters will be truncated with a “...” Please refrain from using extended names.\r\n\r\nThis policy can only be set as a user policy.\r\n\r\nNote that this policy has no effect if the EnterpriseProfileBadgeToolbarSettings policy is set to hide_expanded_enterprise_toolbar_badge (value 1).\r\n\r\nExample value: Chromium","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel_enterprisecustomlabel","displayName":"Set a custom enterprise label for a managed profile (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabelforbrowser","displayName":"Set a custom enterprise label for a managed browser","description":"This policy controls a custom label used to indicate a managed browser. For managed browsers, this label will be shown in a management disclaimer on a footer on the New Tab page. The custom label will not be translated.\r\n\r\nNote that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\n\r\nExample value: Chromium","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabelforbrowser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabelforbrowser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabelforbrowser_enterprisecustomlabelforbrowser","displayName":"Set a custom enterprise label for a managed browser (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourl","displayName":"Enterprise Logo URL for a managed profile","description":"A URL to an image that will be used as an enterprise badge for a managed profile. The URL must point to an image.\r\n\r\nThis policy can only be set as a user policy.\r\n\r\nIt is recommended to use the favicon (example https://www.google.com/favicon.ico) or an icon no smaller than 48 x 48 px.\r\n\r\nExample value: https://example.com/image.png","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourl_enterpriselogourl","displayName":"Enterprise Logo URL for a managed profile (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser","displayName":"Enterprise Logo URL for a managed browser","description":"A URL to an image that will be used as an enterprise badge for a managed browser. The URL must point to an image.\r\n\r\nIt is recommended to use the favicon (example https://www.google.com/favicon.ico) or an icon no smaller than 48 x 48 px.\r\n\r\nNote that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\n\r\nExample value: https://example.com/image.png","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser_enterpriselogourlforbrowser","displayName":"Enterprise Logo URL for a managed browser (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings","displayName":"Controls visibility of enterprise profile badge in the toolbar","description":"For work and school profiles, the toolbar will show a \"Work\" or \"School\" label by default next to the toolbar avatar. The label will only be shown if the signed in account is managed.\r\n\r\nSetting this policy to hide_expanded_enterprise_toolbar_badge (value 1) will hide the enterprise badge for a managed profile in the toolbar.\r\n\r\nLeaving this policy unset or setting it to show_expanded_enterprise_toolbar_badge (value 0) will show the enterprise badge.\r\n\r\nThe label is customizable via the EnterpriseCustomLabel policy.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings","displayName":"Controls visibility of enterprise profile badge in the toolbar (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings_0","displayName":"Show expanded enterprise toolbar badge","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings_1","displayName":"Hide expanded enterprise toolbar badge","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilecreationkeepbrowsingdata","displayName":"Keep browsing data when creating enterprise profile by default","description":"If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default.\r\n\r\nIf this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.\r\n\r\nRegardless of the value, the user will be able to decide whether or not to keep any existing browsing data when creating an enterprise profile.\r\n\r\nThis policy has no effect if the option to keep existing browsing data is not available; this happens if enterprise profile separation is strictly enforced, or if the data would be from an already managed profile.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilecreationkeepbrowsingdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilecreationkeepbrowsingdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings","displayName":"Enterprise search aggregator settings","description":"This policy allows administrators to set a designated enterprise search aggregator that will provide search recommendations and results within the omnibox (address bar) and the search box on the New Tab page.\r\n\r\nBy default, enterprise search suggestions will be blended and shown alongside regular Google Chrome recommendations. Users can explicitly scope their search to just the enterprise search aggregator by typing the keyword specified in the shortcut field with or without the @ prefix (e.g. @work) followed by Space or Tab in the omnibox. Scoped enterprise searches (triggered by a keyword) are currently only supported in the omnibox and not in the search box on the New Tab page.\r\n\r\nThe following fields are required: name, shortcut, search_url, suggest_url.\r\n\r\nThe name field corresponds to the search engine name shown to the user in the address bar.\r\n\r\nThe shortcut field corresponds to the keyword that the user enters to trigger the search. The shortcut can include plain words and characters, but cannot include spaces or start with the @ symbol. Shortcuts must be unique.\r\n\r\nThe search_url field specifies the URL on which to search. Enter the web address for the search engine's results page, and use '{searchTerms}' in place of the query.\r\n\r\nThe suggest_url field specifies the URL that provides search suggestions. A POST request will be made and the user's query will be passed in the POST params under key 'query'.\r\n\r\nThe icon_url field specifies the URL to an image that will be used on the search suggestions. A default icon will be used when this field is not set. It's recommended to use a favicon (example https://www.google.com/favicon.ico). Supported image file formats: JPEG, PNG, and ICO.\r\n\r\nThe require_shortcut field specifies whether the address bar shortcut is required to see search recommendations. If required, suggestions will not be shown in the search box on the New Tab page, but will continue to be shown in the omnibox (address bar) in scoped search mode. If this field is not set, the address bar shortcut is not required.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=EnterpriseSearchAggregatorSettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"name\": \"My Search Aggregator\",\r\n \"shortcut\": \"work\",\r\n \"search_url\": \"https://www.aggregator.com/search?q={searchTerms}\",\r\n \"suggest_url\": \"https://www.aggregator.com/suggest\",\r\n \"icon_url\": \"https://www.google.com/favicon.ico\",\r\n \"require_shortcut\": true\r\n}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings_enterprisesearchaggregatorsettings","displayName":"Enterprise search aggregator settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users would not see a warning when downloading \"jnlp\" files from \"website1.com\", but see a download warning when downloading \"jnlp\" files from \"website2.com\".\r\n\r\nFiles with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Safe Browsing warnings.\r\n\r\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.\r\n\r\nIf you enable this policy:\r\n\r\n* The URL pattern should be formatted according to https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list \"jnlp\" should be used instead of \".jnlp\".\r\n\r\nExample:\r\n\r\nThe following example value would prevent file type extension-based download warnings on \"exe\" and \"jnlp\" extensions for *.example.com domains, and on \"swf\" extensions for all domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\r\n\r\n[\r\n{ \"file_extension\": \"jnlp\", \"domains\": [\"example.com\"] },\r\n{ \"file_extension\": \"exe\", \"domains\": [\"example.com\"] },\r\n{ \"file_extension\": \"swf\", \"domains\": [\"*\"] }\r\n]\r\n\r\nNote that while the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.\r\n\r\nIf this policy is enabled alongside DownloadRestrictions, then the exemptions to file type extension-based warnings specified by this policy take precedence over a DownloadRestrictions setting that would block dangerous file types. The exemptions specified by this policy only apply to the \"block dangerous file types\" behavior specified by values 1 and 2 of DownloadRestrictions.\r\n\r\nFor example, if this policy specifies an exemption for \"exe\" downloads from \"website1.com\", and DownloadRestrictions is set to block malicious downloads and dangerous file types (value 1), then \"exe\" downloads from \"website1.com\" will be exempt from file type extension-based blocking but will still be blocked if they are malicious.\r\n\r\nMore information about DownloadRestrictions can be found at https://chromeenterprise.google/policies/?policy=DownloadRestrictions.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ExemptDomainFileTypePairsFromFileTypeDownloadWarnings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"domains\": [\r\n \"https://example.com\",\r\n \"example2.com\"\r\n ],\r\n \"file_extension\": \"jnlp\"\r\n },\r\n {\r\n \"domains\": [\r\n \"*\"\r\n ],\r\n \"file_extension\": \"swf\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings_exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_feedbacksurveysenabled","displayName":"Specifies whether in-product Google Chrome surveys are shown to users.","description":"Google Chrome in-product surveys collect user feedback for the browser. Survey responses are not associated with user accounts.\r\nWhen this policy is Enabled or not set, in-product surveys may be shown to users.\r\nWhen this policy is Disabled, in-product surveys are not shown to users.\r\n\r\nThis policy has no effect if MetricsReportingEnabled is set to Disabled, which disables in-product surveys as well.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_feedbacksurveysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_feedbacksurveysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_fileordirectorypickerwithoutgestureallowedfororigins","displayName":"Allow file or directory picker APIs to be called without prior user gesture","description":"For security reasons, the\r\nshowOpenFilePicker(),\r\nshowSaveFilePicker() and\r\nshowDirectoryPicker() web APIs\r\nrequire a prior user gesture (\"transient activation\") to be called or will\r\notherwise fail.\r\n\r\nWith this policy set, admins can specify origins on which these APIs can be\r\ncalled without prior user gesture.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is\r\nnot an accepted value for this policy.\r\n\r\nIf this policy is unset, all origins will require a prior user gesture to call\r\nthese APIs.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_fileordirectorypickerwithoutgestureallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_fileordirectorypickerwithoutgestureallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_fileordirectorypickerwithoutgestureallowedfororigins_fileordirectorypickerwithoutgestureallowedfororiginsdesc","displayName":"Allow file or directory picker APIs to be called without prior user gesture (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled.","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy. Currently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers. This enterprise policy can be used to opt out of this gradual deprecation by forcing the default to remain as enabled.\r\n\r\nPages may depend on unload event handlers to save data or signal the end of a user session to the server. This is not recommended as it is unreliable and impacts performance by blocking use of BackForwardCache. Recommended alternatives exist, however the unload event has been used for a long time. Some applications may still rely on them.\r\n\r\nIf this policy is set to false or not set, then unload events handlers will be gradually deprecated in-line with the deprecation rollout and sites which do not set Permissions-Policy header will stop firing `unload` events.\r\n\r\nIf this policy is set to true then unload event handlers will continue to work by default.\r\n\r\nNOTE: This policy had an incorrectly documented default of `true` in M117. The unload event did and will not change in M117, so this policy has no effect in that version.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_forcepermissionpolicyunloaddefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_forcepermissionpolicyunloaddefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_googlesearchsidepanelenabled","displayName":"Enable Google Search Side Panel","description":"If set to Enabled or not set, Google Search Side Panel is allowed on all web pages.\r\n\r\nIf set to Disabled, Google Search Side Panel is not available on any webpage.\r\n\r\nGenAI capabilities that are part of this feature are not available for Educational or Enterprise accounts.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_googlesearchsidepanelenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_googlesearchsidepanelenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_highefficiencymodeenabled","displayName":"Enable High Efficiency Mode","description":"This policy enables or disables the High Efficiency Mode setting. This setting makes it so that tabs are discarded after some period of time in the background to reclaim memory.\r\nIf this policy is unset, the end user can control this setting in chrome://settings/performance.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_highefficiencymodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_highefficiencymodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist","displayName":"HTTP Allowlist","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as\r\n'[*.]example.com') that will not be upgraded to HTTPS and will not show an\r\nerror interstitial if HTTPS-First Mode is enabled. Organizations can use this\r\npolicy to maintain access to servers that do not support HTTPS, without\r\nneeding to disable HTTPS Upgrades and/or HTTPS-First Mode.\r\n\r\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their\r\nA-label format, and all ASCII letters must be lowercase.\r\n\r\nBlanket host wildcards (i.e., \"*\" or \"[*]\") are not allowed. Instead,\r\nHTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their\r\nspecific policies.\r\n\r\nNote: This policy does not apply to HSTS upgrades.\r\n\r\nExample value:\r\n\r\ntestserver.example.com\r\n[*.]example.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist_httpallowlistdesc","displayName":"HTTP Allowlist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpsupgradesenabled","displayName":"Enable automatic HTTPS upgrades","description":"Google Chrome attempts to upgrade some\r\nnavigations from HTTP to HTTPS, when possible. This policy can be used to\r\ndisable this behavior. If set to \"true\" or left unset, this feature will be\r\nenabled by default.\r\n\r\nThe separate HttpAllowlist policy\r\ncan be used to exempt specific hostnames or hostname patterns from being\r\nupgraded to HTTPS by this feature.\r\n\r\nSee also the HttpsOnlyMode policy.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpsupgradesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpsupgradesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensdesktopntpsearchenabled","displayName":"Allow Google Lens button to be shown in the search box on the New Tab page if supported.","description":"Leaving the policy unset or setting it to Enabled allows users to view and use the Google Lens button in the search box on the New Tab page. Setting the policy to Disabled means users will not see the Google Lens button in the search box on the New Tab page.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensdesktopntpsearchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensdesktopntpsearchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings","displayName":"Settings for the Lens Overlay feature","description":"Lens Overlay lets users perform contextual Google searches either via a screenshot or by asking a question about the current page's contents. This feature requires the end user to opt-in.\r\n\r\nThis feature is available to all users with Google as their default search engine, unless it is disabled by this policy.\r\n\r\nWhen policy is set to 0 - Allow or not set, the feature will be available to users.\r\n\r\nWhen policy is set to 1 - Do not allow, the feature will not be available.\r\n\r\nStarting in Google Chrome 140, if the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_lensoverlaysettings","displayName":"Settings for the Lens Overlay feature (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_lensoverlaysettings_0","displayName":"Allow","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_lensoverlaysettings_1","displayName":"Do not allow","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings","displayName":"Change Memory Saver Mode Savings","description":"This policy changes the savings level of Memory Saver.\r\n\r\nThis only takes effect when Memory Saver is enabled through settings or through the HighEfficiencyModeEnabled policy, and will affect how heuristics are used to determine when to discard tabs. For example, reducing the lifetime of an inactive tab before discarding it can save memory, but it also means that tabs will be reloaded more frequently which can lead to bad user experience and cost more network traffic.\r\n\r\nSetting the policy to 0 - Memory Saver will get moderate memory savings. Tabs become inactive after a longer period of time\r\n\r\nSetting the policy to 1 - Memory Saver will get balanced memory savings. Tabs become inactive after an optimal period of time.\r\n\r\nSetting the policy to 2 - Memory Saver will get maximum memory savings. Tabs become inactive after a shorter period of time.\r\n\r\nIf this policy is unset, the end user can control this setting in chrome://settings/performance.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings","displayName":"Change Memory Saver Mode Savings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings_0","displayName":"Moderate memory savings.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings_1","displayName":"Balanced memory savings.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings_2","displayName":"Maximum memory savings.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_nativehostsexecutableslaunchdirectly","displayName":"Force Windows executable Native Messaging hosts to launch directly","description":"This policy controls whether native host executables launch directly on Windows.\r\n\r\nSetting the policy to Enabled forces Google Chrome to launch native messaging hosts implemented as executables directly.\r\n\r\nSetting the policy to Disabled will result in Google Chrome launching hosts using cmd.exe as an intermediary process.\r\n\r\nLeaving the policy unset allows Google Chrome to decide which approach to use.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_nativehostsexecutableslaunchdirectly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_nativehostsexecutableslaunchdirectly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpfooterextensionattributionenabled","displayName":"Control the visibility of the extension attribution on the New Tab page","description":"This policy determines whether an attribution to the extension modifying the New Tab Page (NTP) is displayed in the NTP's footer.\r\n\r\nBy default, if an extension has overridden the standard NTP, a message attributing this change to the specific extension will appear in the footer. This attribution typically includes a link to the relevant extension in the Chrome Web Store.\r\n\r\nIf this policy is left unset or set to true, the extension attribution will be visible on the NTP footer when an extension is controlling the NTP.\r\n\r\nIf this policy is set to false, the attribution to the extension in the NTP footer will be suppressed.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpfooterextensionattributionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpfooterextensionattributionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpfootermanagementnoticeenabled","displayName":"Control the visibility of the management notice on the New Tab Page for managed browsers","description":"This policy controls the visibility of the management notice within the footer of the New Tab Page (NTP). By default, the NTP footer displays information when the browser is managed by an organization (indicated by a building icon and \"Managed by [domain name]\"). This can be customized using the EnterpriseCustomLabelForBrowser and EnterpriseLogoUrlForBrowser policies.\r\n\r\nIf this policy is left unset or set to true, managed browsers will display a “Managed by…” notice with an icon.\r\n\r\nIf this policy is set to false, the management notice will be hidden.\r\n\r\nNote that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpfootermanagementnoticeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpfootermanagementnoticeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpmiddleslotannouncementvisible","displayName":"Show the middle slot announcement on the New Tab Page","description":"This policy controls the visibility of the middle slot announcement on the New Tab Page.\r\n\r\nIf the policy is set to Enabled, the New Tab Page will show the middle slot announcement if it is available.\r\n\r\nIf the policy is set to Disabled, the New Tab Page will not show the middle slot announcement even if it is available.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpmiddleslotannouncementvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpmiddleslotannouncementvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpoutlookcardvisible","displayName":"Show Outlook Calendar card on the New Tab Page","description":"This policy controls the visibility of the Outlook Card on the New Tab Page. The card will only be displayed on the New Tab Page if the policy is enabled and your organization authorized the usage of the Outlook Calendar data in the browser.\r\n\r\nOutlook data will not be stored by the browser.\r\n\r\nThe Outlook card shows the next calendar event, along with a glanceable look at the rest of the day's meetings. It aims to address the issue of context switching and enhance productivity by giving users a shortcut to their next meeting.\r\n\r\nThe Microsoft Outlook card will require additional admin configuration. For detailed information on connecting the Chrome New Tab Page Card to Outlook, please see https://support.google.com/chrome/a?p=chrome_ntp_microsoft_cards.\r\n\r\nIf the NTPCardsVisible is disabled, the Outlook Card will not be shown. If NTPCardsVisible is enabled, the Outlook card will be shown if this policy is also enabled and there is data to be shown. If NTPCardsVisible is unset, the Outlook card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpoutlookcardvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpoutlookcardvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpsharepointcardvisible","displayName":"Show SharePoint and OneDrive File Card on the New Tab Page","description":"This policy controls the visibility of the SharePoint and OneDrive File Card on the New Tab Page. The card will only be displayed on the New Tab Page if the policy is enabled and your organization authorized the usage of the SharePoint and OneDrive File data in the browser.\r\n\r\nSharePoint and OneDrive data will not be stored by the browser.\r\n\r\nThe SharePoint and OneDrive Files recommendation card shows a list of recommended files. It aims to address the issue of context switching and enhance productivity by giving users a shortcut to their most important documents.\r\n\r\nThe Microsoft SharePoint and OneDrive card will require additional admin configuration. For detailed information on connecting the Chrome New Tab Page Card to Sharepoint, please see https://support.google.com/chrome/a?p=chrome_ntp_microsoft_cards.\r\n\r\nIf the NTPCardsVisible is disabled, the SharePoint and OneDrive Card will not be shown. If NTPCardsVisible is enabled, the SharePoint and OneDrive card will be shown if this policy is also enabled and there is data to be shown. If NTPCardsVisible is unset, the SharePoint and OneDrive card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpsharepointcardvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpsharepointcardvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts","displayName":"Setting shortcuts on the New Tab Page (Beta)","description":"In development: for early preview only.\r\n\r\nSetting the policy pre-configures up to 10 custom shortcuts on the Google Chrome New Tab page.\r\n\r\nIf set, users will see these shortcuts by default and users can toggle between “My shortcuts,\" \"Most visited sites\" or \"My organization's shortcuts\" on the \"Customize Chrome\" panel. If empty or unset, the user will only be able to toggle between “My shortcuts\" or \"Most visited sites\" on the \"Customize Chrome\" panel.\r\n\r\nShortcut URLs must be unique.\r\n\r\nIf allow_user_edit is set to true, users can change the name of the shortcut. If set to false or unset, users cannot edit the name.\r\n\r\nIf allow_user_delete is set to true, users can remove the shortcut. If set to false or unset, users cannot remove the shortcut.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=NTPShortcuts for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"name\": \"Google\",\r\n \"url\": \"https://www.google.com\"\r\n },\r\n {\r\n \"name\": \"YouTube\",\r\n \"url\": \"https://www.youtube.com\"\r\n },\r\n {\r\n \"name\": \"Google Drive\",\r\n \"url\": \"https://www.drive.google.com\",\r\n \"allow_user_edit\": true,\r\n \"allow_user_delete\": true\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts_ntpshortcuts","displayName":"Setting shortcuts on the New Tab Page (Beta) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_originagentclusterdefaultenabled","displayName":"Allows origin-keyed agent clustering by default.","description":"This policy allows origin-keyed agent clustering by default.\r\n\r\nThe Origin-Agent-Cluster HTTP header controls whether a document is\r\nisolated in an origin-keyed agent cluster, or in a site-keyed agent\r\ncluster. This has security implications since an origin-keyed agent\r\ncluster allows isolating documents by origin. The developer-visible\r\nconsequence of this is that the document.domain accessor can no longer\r\nbe set.\r\n\r\nThe default behaviour - when no Origin-Agent-Cluster header has been set -\r\nchanges in M111 from site-keyed to origin-keyed.\r\n\r\nIf this policy is enabled or not set, the browser will follow this\r\nnew default from that version on.\r\n\r\nIf this policy is disabled this change is reversed and\r\ndocuments without Origin-Agent-Cluster headers will be assigned to\r\nsite-keyed agent clusters. As a consequence, the document.domain accessor\r\nremains settable by default. This matches the legacy behaviour.\r\n\r\nSee https://developer.chrome.com/blog/immutable-document-domain/ for\r\nadditional details.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_originagentclusterdefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_originagentclusterdefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfannotationsenabled","displayName":"Enable PDF Annotations","description":"Controls if the PDF viewer in Google Chrome can annotate PDFs.\r\n\r\nWhen this policy is not set, or is set to true, then the PDF viewer will be able to annotate PDFs.\r\n\r\nWhen this policy is set to false, then the PDF viewer will not be able to annotate PDFs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfannotationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfannotationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfuseskiarendererenabled","displayName":"Use Skia renderer for PDF rendering","description":"Controls whether the PDF viewer in Google Chrome uses Skia renderer.\r\n\r\nWhen this policy is enabled, the PDF viewer uses Skia renderer.\r\n\r\nWhen this policy is disabled, the PDF viewer uses its current AGG renderer.\r\n\r\nWhen this policy is not set, the PDF renderer will be chosen by the browser.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfuseskiarendererenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfuseskiarendererenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfvieweroutofprocessiframeenabled","displayName":"Use out-of-process iframe PDF Viewer","description":"Controls whether the PDF viewer in Google Chrome uses an out-of-process iframe (OOPIF). This will be the new PDF viewer architecture in the future, as it is simpler and makes adding new features easier. The existing GuestView PDF viewer is an outdated, complex architecture that is being deprecated.\r\n\r\nWhen this policy is set to Enabled or not set, Google Chrome will be able to use the OOPIF PDF viewer architecture. Once Enabled or not set, the default behavior will be decided by Google Chrome.\r\n\r\nWhen this policy is set to Disabled, Google Chrome will strictly use the existing GuestView PDF viewer. It embeds a web page with a separate frame tree into another web page.\r\n\r\nThis policy will be removed in the future, after the OOPIF PDF viewer feature has fully rolled out.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfvieweroutofprocessiframeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfvieweroutofprocessiframeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_postquantumkeyagreementenabled","displayName":"Enable post-quantum key agreement for TLS","description":"This policy configures whether Google Chrome will offer a post-quantum key agreement algorithm in TLS, using the ML-KEM NIST standard. Prior to Google Chrome 131, the algorithm was Kyber, an earlier draft iteration of the standard. This allows supporting servers to protect user traffic from being later decrypted by quantum computers.\r\n\r\nIf this policy is Enabled or not set, Google Chrome will offer a post-quantum key agreement in TLS connections. User traffic will then be protected from quantum computers when communicating with compatible servers.\r\n\r\nIf this policy is Disabled, Google Chrome will not offer a post-quantum key agreement in TLS connections. User traffic will then be unprotected from quantum computers.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing TLS servers and networking middleware are expected to ignore the new option and continue selecting previous options.\r\n\r\nHowever, devices that do not correctly implement TLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or the resulting larger messages. Such devices are not post-quantum-ready and will interfere with an enterprise's post-quantum transition. If encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed sometime after Google Chrome version 145. It may be Enabled to allow you to test for issues, and may be Disabled while issues are being resolved.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_postquantumkeyagreementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_postquantumkeyagreementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled","displayName":"Allow SpeculationRules prefetch to ServiceWorker-controlled URLs","description":"SpeculationRules prefetch can be issued to URLs that are controlled by\r\nServiceWorker. However, legacy code did not allow it and canceled the prefetch\r\nrequests. This policy enables to control the behavior.\r\n\r\nSetting this policy to Enabled or not set allows SpeculationRules prefetch to\r\nServiceWorker-controlled URLs (if the PrefetchServiceWorker feature flag is\r\nenabled). This is the current default behavior and is aligned with the\r\nspecifications.\r\n\r\nSetting this policy to Disabled disallows SpeculationRules prefetch to\r\nServiceWorker-controlled URLs. This is the legacy behavior.\r\n\r\nThis policy is intended to be temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt","displayName":"Prompt users to re-authenticate to the profile","description":"When set to DoNotPrompt or left unset, Google Chrome does not automatically prompt the user to re-authenticate to the browser.\r\n\r\nWhen set to PromptInTab, when the user's authentication expires, immediately open a new tab with the Google login page. This only happens if using Chrome Sync.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_profilereauthprompt","displayName":"Prompt users to re-authenticate to the profile (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_profilereauthprompt_0","displayName":"Do not prompt for reauth","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_profilereauthprompt_1","displayName":"Prompt for reauth in a tab","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_promotionsenabled","displayName":"Enable showing promotional content","description":"Setting the policy to True or leaving it unset lets Google Chrome show users product promotional content.\r\n\r\nSetting the policy to False prevents Google Chrome from showing product promotional content.\r\n\r\nSetting the policy controls the presentation of promotional content, including the welcome pages that help users sign in to Google Chrome, set Google Chrome as users' default browser, or otherwise inform them of product features.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_promotionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_promotionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_qrcodegeneratorenabled","displayName":"Enable QR Code Generator","description":"This policy enables the QR Code generator feature in Google Chrome.\r\n\r\nIf you enable this policy or don't configure it, the QR Code Generator feature is enabled.\r\n\r\nIf you disable this policy, the QR Code Generator feature is disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_qrcodegeneratorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_qrcodegeneratorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended","displayName":"Enable Battery Saver Mode","description":"This policy enables or disables the Battery Saver Mode setting.\r\nOn Chrome, this setting makes it so that frame rate is throttled to lower power consumption. If this policy is unset, the end user can control this setting in chrome://settings/performance.\r\nOn ChromeOS, this setting makes it so that frame rate and CPU frequency are throttled, backlights are dimmed, and Android is put in Battery Saver Mode. On devices with multiple CPUs, some CPUs will be turned off.\r\nThe different levels are:\r\nDisabled (0): Battery Saver Mode will be disabled.\r\nEnabledBelowThreshold (1): Battery Saver Mode will be enabled when the device is on battery power and battery level is low.\r\nEnabledOnBattery (2): This value is deprecated as of M121. From M121 onwards, values will be treated as EnabledBelowThreshold.\r\n","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability","displayName":"Enable Battery Saver Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability_0","displayName":"Battery Saver Mode will be disabled.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability_1","displayName":"Battery Saver Mode will be enabled when the device is on battery power and battery level is low.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability_2","displayName":"This value is deprecated as of M121. In M121 and after, values will be treated as EnabledBelowThreshold.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_domainreliabilityallowed_recommended","displayName":"Allow reporting of domain reliability related data","description":"If this policy is set false, domain reliability diagnostic data reporting is disabled and no data is sent to Google.\r\nIf this policy is set true or not set, domain reliability diagnostic data reporting will follow the behavior of MetricsReportingEnabled for Google Chrome or DeviceMetricsReportingEnabled for Google ChromeOS.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_domainreliabilityallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_domainreliabilityallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_enterpriseprofilecreationkeepbrowsingdata_recommended","displayName":"Keep browsing data when creating enterprise profile by default","description":"If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default.\r\n\r\nIf this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.\r\n\r\nRegardless of the value, the user will be able to decide whether or not to keep any existing browsing data when creating an enterprise profile.\r\n\r\nThis policy has no effect if the option to keep existing browsing data is not available; this happens if enterprise profile separation is strictly enforced, or if the data would be from an already managed profile.\r\n","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_enterpriseprofilecreationkeepbrowsingdata_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_enterpriseprofilecreationkeepbrowsingdata_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_originkeyedprocessesenabled_recommended","displayName":"Enable origin-keyed process isolation by default.","description":"Enables origin-keyed process isolation for most pages (i.e., those assigned to an origin-keyed agent cluster by default). This improves security but also increases the number of processes created. Users are allowed to override the set policy value via the command-line flags or chrome://flags (both to turn this feature on or off).\r\n\r\nSetting the policy to Enabled results in most origins being isolated, even from other origins in the same site. See also the IsolateOrigins and SitePerProcess policies.\r\n\r\nSetting the policy to Disabled results in no origins being isolated from the rest of their site unless an origin explicitly asks to.\r\n\r\nNot setting the policy results in the browser determining which origins to isolate and when to isolate them.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_originkeyedprocessesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_originkeyedprocessesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livecaptionenabled_recommended","displayName":"Enable Live Caption","description":"Enable the Live Caption feature.\r\n\r\nIf this policy is set to Enabled, Live Caption will always be turned on.\r\n\r\nIf this policy is set to Disabled, Live Caption will always be turned off.\r\n\r\nIf you set this policy as mandatory, users cannot change or override it.\r\n\r\nIf this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.","helpText":"","infoUrls":[],"categoryId":"12142994-4b30-486c-bab1-9206528b2b96","categoryName":"Accessibility settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livecaptionenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livecaptionenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livetranslateenabled_recommended","displayName":"Enable Live Translate","description":"Enable translation of live captions. Captions will be sent to Google for translation.\r\n\r\nIf this policy is set to Enabled, Live Translate will always be turned on.\r\n\r\nIf this policy is set to Disabled, Live Translate will always be turned off.\r\n\r\nIf you set this policy as mandatory, users cannot change or override it.\r\n\r\nIf this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime.\r\n\r\nIn LiveCaptionEnabled is set to Disabled, Live Translate will be disabled regardless of this policy setting.","helpText":"","infoUrls":[],"categoryId":"12142994-4b30-486c-bab1-9206528b2b96","categoryName":"Accessibility settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livetranslateenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livetranslateenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_reduceacceptlanguageenabled","displayName":"Control Accept-Language Reduction","description":"The Accept-Language HTTP request header and the JavaScript navigator.languages getter are planned for reduction for privacy reasons.\r\nTo facilitate testing and ensure compatibility, this policy allows you to enable or disable the Accept-Language Reduction feature.\r\n\r\nIf this policy is set to enabled or left unset, Accept-Language Reduction will be applied through field trials.\r\nIf this policy is set to disabled, field trials will not be able to activate Accept-Language Reduction.\r\n\r\nFor more information about this feature, please visit: https://github.com/explainers-by-googlers/reduce-accept-language.\r\n\r\nNOTE: Only newly-started renderer processes will reflect changes to this policy while the browser is running.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_reduceacceptlanguageenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_reduceacceptlanguageenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_relaunchfastifoutdated","displayName":"Relaunch fast if outdated","description":"Specifies the minimum release age beyond which relaunch notifications are more aggressive. The age is calculated from the time the currently-running version was last served to clients.\r\n\r\nIf a browser relaunch or device restart is needed to finalize a pending update and the current version has been outdated for more than the number of days specified by this setting, the RelaunchNotificationPeriod policy is overridden to 2 hours. If the RelaunchNotification policy is set to 1 ('Required'), users will be forced to relaunch or restart at the end of the period.\r\n\r\nIf not set, or if the release age cannot be determined, the RelaunchNotificationPeriod policy will be used for all updates.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_relaunchfastifoutdated_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_relaunchfastifoutdated_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_relaunchfastifoutdated_relaunchfastifoutdated","displayName":"Time period (days): (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_rendererappcontainerenabled","displayName":"Enable Renderer App Container","description":"Setting the policy to Enabled or leaving it unset means Renderer App Container configuration will be enabled on supported platforms.\r\n\r\nSetting the policy to Disabled has a detrimental effect on the security and stability of Google Chrome as it will weaken the sandbox that renderer processes use. Only turn off the policy if there are compatibility issues with third-party software that must run inside renderer processes.\r\n\r\nNote: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_rendererappcontainerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_rendererappcontainerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer","displayName":"Restrict CPU core sharing for renderer process","description":"This policy mitigates side-channel cross process memory attacks by isolating the renderer process on the CPU core and preventing other processes from sharing the same core. The mitigation is supported on Microsoft® Windows® 11 24H2 and above. If the OS does not have the required scheduling support, this policy will have no effect. This policy may slow down performance in some demanding scenarios similar to disabling hyperthreading. For more information refer https://learn.microsoft.com/en-us/windows/win32/api/winnt/ns-winnt-process_mitigation_side_channel_isolation_policy\r\nIf this policy is enabled, all other processes will not be scheduled on the same CPU core when the renderer process is running.\r\nIf this policy is disabled, all other processes can be scheduled on the same CPU core if a renderer process is running on it.\r\nIf this policy is not set, all other processes can be scheduled on the same CPU core if a renderer process is running on the core. This may vary depending on Google Chrome release, currently running field trials, and platform.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_screencapturewithoutgestureallowedfororigins","displayName":"Allow screen capture without prior user gesture","description":"For security reasons, the\r\ngetDisplayMedia() web API requires\r\na prior user gesture (\"transient activation\") to be called or will otherwise\r\nfail.\r\n\r\nWith this policy set, admins can specify origins on which this API can be\r\ncalled without prior user gesture.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is\r\nnot an accepted value for this policy.\r\n\r\nIf this policy is unset, all origins will require a prior user gesture to call\r\nthis API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_screencapturewithoutgestureallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_screencapturewithoutgestureallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_screencapturewithoutgestureallowedfororigins_screencapturewithoutgestureallowedfororiginsdesc","displayName":"Allow screen capture without prior user gesture (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup","description":"https://github.com/WICG/service-worker-auto-preload\r\nThe ServiceWorkerAutoPreload feature dispatches a network request for a main resource at the same time it begins the ServiceWorker bootstrap process.\r\n\r\nSetting the policy to Enabled or leaving it unset means\r\nGoogle Chrome enables ServiceWorkerAutoPreload. The navigation request is automatically dispatched while starting the ServiceWorker in some scenarios, e.g. ServiceWorker is not running,\r\n\r\nIf it is disabled, Google Chrome will not enable ServiceWorkerAutoPreload. The navigation request is dispatched always after starting the ServiceWorker.\r\n\r\nThis policy is a temporary measure to control the feature and will be removed in M144.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkerautopreloadenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkerautopreloadenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled","displayName":"Allow ServiceWorker to control srcdoc iframes","description":"https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with\r\nthe \"allow-same-origin\" sandbox attribute to be under ServiceWorker control.\r\n\r\nSetting the policy to Enabled or leaving it unset means\r\nGoogle Chrome makes srcdoc iframes\r\nwith \"allow-same-origin\" sandbox attributes to be under ServiceWorker control.\r\n\r\nSetting the policy to Disabled leaves the srcdoc iframe not controlled by\r\nServiceWorker.\r\n\r\nThis policy is intended to be temporary and will be removed in 2026.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sharedworkerbloburlfixenabled","displayName":"Make SharedWorker blob URL behavior aligned with the specification","description":"Upon https://w3c.github.io/ServiceWorker/#control-and-use-worker-client,\r\nworkers should inherit controllers for the blob URL. However, existing code\r\nallows only DedicatedWorkers to inherit the controller, and SharedWorkers do\r\nnot inherit the controller.\r\n\r\nSetting the policy to Enabled or leaving it unset means\r\nGoogle Chrome inherit the controller\r\nif a blob URL is used as a SharedWorker URL.\r\n\r\nSetting the policy to Disabled leaves the behavior not aligned with the\r\nspecification as-is.\r\n\r\nThis policy is intended to be temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sharedworkerbloburlfixenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sharedworkerbloburlfixenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_shoppinglistenabled","displayName":"Allow the shopping list feature to be enabled","description":"This policy controls the availability of the shopping list feature.\r\nIf enabled, users will be presented with UI to track the price of the product displayed on the current page. The tracked product will be shown in the bookmarks side panel.\r\nIf this policy is set to Enabled or not set, the shopping list feature will be available to users.\r\nIf this policy is set to Disabled, the shopping list feature will be unavailable.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_shoppinglistenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_shoppinglistenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sidesearchenabled","displayName":"Allow showing the most recent default search engine results page in a Browser side panel","description":"Setting the policy to Enabled or leaving the policy unset means that users can bring up their most recent default search engine results page in a side panel via toggling an icon in the toolbar.\r\n\r\nSetting the policy to Disabled removes the icon from the toolbar that opens the side panel with the default search engine results page.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sidesearchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sidesearchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sitesearchsettings","displayName":"Site search settings","description":"This policy provides a list of sites that users can quickly search using shortcuts in the address bar. Users can initiate a search by typing the shortcut or @shortcut (e.g. @work), followed by Space or Tab, in the address bar.\r\n\r\nThe following fields are required for each site: name, shortcut, url.\r\n\r\nThe name field corresponds to the site or search engine name to be shown to the user in the address bar.\r\n\r\nThe shortcut can include plain words and characters, but cannot include spaces or start with the @ symbol. Shortcuts must also be unique.\r\n\r\nFor each entry, the url field specifies the URL of the search engine used during a search with the corresponding keyword. The URL must include the string '{searchTerms}', replaced in the query by the user's search terms. Invalid entries and entries with duplicate shortcuts are ignored.\r\n\r\nSite search entries configured as featured are displayed in the address bar when the user types \"@\". Up to three entries can be selected as featured.\r\n\r\nFor a site search entry where allow_user_override is true, users have the ability to edit or disable that entry. However, featured engines (beginning with \"@\") can only be disabled. If a user modifies an entry that was initially created by this policy, it will no longer be managed by policy and will be treated like a user-created shortcut. When allow_user_override is false or unspecified for a site search entry, users cannot edit or disable that entry. The setting to allow user override is only supported on M139 and later; earlier versions will default to disabling user override.\r\n\r\nUsers cannot create new site search entries with a shortcut previously created via this policy unless allow_user_override is set to true for the site search entry.\r\n\r\nIn case of a conflict with a shortcut previously created by the user, the user setting takes precedence. However, users can still trigger the option created by the policy by typing \"@\" in the search bar. For example, if the user already defined \"work\" as a shortcut to URL1 and the policy defines \"work\" as a shortcut to URL2, then typing \"work\" in the search bar will trigger a search to URL1, but typing \"@work\" in the search bar will trigger a search to URL2.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=SiteSearchSettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"featured\": true,\r\n \"name\": \"Google Wikipedia\",\r\n \"shortcut\": \"wikipedia\",\r\n \"url\": \"https://www.google.com/search?q=site%3Awikipedia.com+%s\"\r\n },\r\n {\r\n \"name\": \"YouTube\",\r\n \"shortcut\": \"youtube\",\r\n \"url\": \"https://www.youtube.com/results?search_query=%s\"\r\n },\r\n {\r\n \"name\": \"Google Drive\",\r\n \"shortcut\": \"drive\",\r\n \"url\": \"https://drive.google.com/?q=%s\",\r\n \"allow_user_override\": true\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sitesearchsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sitesearchsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_sitesearchsettings_sitesearchsettings","displayName":"Site search settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_standardizedbrowserzoomenabled","displayName":"Enable Standardized Browser Zoom Behavior","description":"This policy enables conformance to the newly-adopted specification of CSS zoom.\r\n\r\nWhen this policy is Enabled or unset, the CSS \"zoom\" property will adhere to the specification:\r\n\r\nhttps://drafts.csswg.org/css-viewport/#zoom-property\r\n\r\nWhen Disabled, the CSS \"zoom\" property will fall back to its legacy pre-standardized behavior.\r\n\r\nThis policy is a temporary reprieve to allow time to migrate web content to the new behavior. There is also an origin trial (\"DisableStandardizedBrowserZoom\") that corresponds to the behavior when this policy is Disabled. This policy will be removed and the \"Enabled\" behavior made permanent in milestone 134.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_standardizedbrowserzoomenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_standardizedbrowserzoomenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_strictmimetypecheckforworkerscriptsenabled","displayName":"Enable strict MIME type checking for worker scripts","description":"This policy enables strict MIME type checking for worker scripts.\r\n\r\nWhen enabled or unset, then worker scripts will use strict MIME type checking for JavaScript, which is the new default behaviour. Worker scripts with legacy MIME types will be rejected.\r\n\r\nWhen disabled, then worker scripts will use lax MIME type checking, so that worker scripts with legacy MIME types, e.g. text/ascii, will continue to be loaded and executed.\r\n\r\nBrowsers traditionally used lax MIME type checking, so that resources with a number of legacy MIME types were supported. E.g. for JavaScript resources, text/ascii is a legacy supported MIME type. This may cause security issues, by allowing to load resources as scripts that were never intended to be used as such. Chrome will transition to use strict MIME type checking in the near future. The enabled policy will track the default behaviour. Disabling this policy allows administrators to retain the legacy behaviour, if desired.\r\n\r\nSee https://html.spec.whatwg.org/multipage/scripting.html#scriptingLanguage for details about JavaScript / ECMAScript media types.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_strictmimetypecheckforworkerscriptsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_strictmimetypecheckforworkerscriptsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions","displayName":"URL pattern Exceptions to tab discarding","description":"This policy makes it so that any URL matching one or more of the patterns it specifies (using the URLBlocklist filter format) will never be discarded by the browser.\r\nThis applies to memory pressure and high efficiency mode discarding.\r\nA discarded page is unloaded and its resources fully reclaimed. The tab its associated with remains in the tabstrip, but making it visible will trigger a full reload.\r\n\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://*\r\n*","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_tabdiscardingexceptionsdesc","displayName":"URL pattern Exceptions to tab discarding (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tls13earlydataenabled","displayName":"Enable TLS 1.3 Early Data","description":"TLS 1.3 Early Data is an extension to TLS 1.3 to send an HTTP request simultaneously with the TLS handshake.\r\n\r\nIf this policy is not configured, Google Chrome will follow the default rollout process for TLS 1.3 Early Data.\r\n\r\nIf it is enabled, Google Chrome will enable TLS 1.3 Early Data.\r\n\r\nIf it is disabled, Google Chrome will not enable TLS 1.3 Early Data.\r\n\r\nWhen the feature is enabled, Google Chrome may or may not use TLS 1.3 Early Data depending on server support.\r\n\r\nTLS 1.3 Early Data is an established protocol. Existing TLS servers, middleboxes, and security software are expected to either handle or reject TLS 1.3 Early Data without dropping the connection.\r\n\r\nHowever, devices that do not correctly implement TLS may malfunction and disconnect when TLS 1.3 Early Data is in use. If this occurs, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure to control the feature and will be removed afterwards. The policy may be enabled to allow you to test for issues and disabled while issues are being resolved.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tls13earlydataenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tls13earlydataenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_translatorapiallowed","displayName":"Allow Translator API","description":"Setting the policy to Enabled or leaving it unset allows the use of Translator API in Google Chrome.\r\n\r\nSetting the policy to Disabled disallows the use of Translator API.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_translatorapiallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_translatorapiallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webappsettings","displayName":"Web App management settings","description":"This policy allows an admin to specify settings for installed web apps. This policy maps a Web App ID to its specific setting. A default configuration can be set using the special ID *, which applies to all web apps without a custom configuration in this policy.\r\n\r\nThe manifest_id field is the Manifest ID for the Web App. See https://developer.chrome.com/blog/pwa-manifest-id/ for instructions on how to determine the Manifest ID for an installed web app.\r\nThe run_on_os_login field specifies if a web app can be run during OS login. If this field is set to blocked, the web app will not run during OS login and the user will not be able to enable this later. If this field is set to run_windowed, the web app will run during OS login and the user will not be able to disable this later. If this field is set to allowed, the user will be able to configure the web app to run at OS login. The default configuration only allows the allowed and blocked values.\r\n(Since version 117) The prevent_close_after_run_on_os_login field specifies if a web app shall be prevented from closing in any way (e.g. by the user, task manager, web APIs). This behavior can only be enabled if run_on_os_login is set to run_windowed. If the app were already running, this property will only come into effect after the app is restarted. If this field is not defined, apps will be closable by users.\r\n(Since version 118) The force_unregister_os_integration field specifies if all OS integration for a web app, i.e. shortcuts, file handlers, protocol handlers etc will be removed or not. If an app is already running, this property will come into effect after the app has restarted. This should be used with caution, since this can override any OS integration that is set automatically during the startup of the web applications system. Currently only works on Windows, Mac and Linux platforms.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebAppSettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"manifest_id\": \"https://foo.example/index.html\",\r\n \"run_on_os_login\": \"allowed\"\r\n },\r\n {\r\n \"manifest_id\": \"https://bar.example/index.html\",\r\n \"run_on_os_login\": \"allowed\"\r\n },\r\n {\r\n \"manifest_id\": \"https://foobar.example/index.html\",\r\n \"run_on_os_login\": \"run_windowed\",\r\n \"prevent_close_after_run_on_os_login\": true\r\n },\r\n {\r\n \"manifest_id\": \"*\",\r\n \"run_on_os_login\": \"blocked\"\r\n },\r\n {\r\n \"manifest_id\": \"https://foo.example/index.html\",\r\n \"force_unregister_os_integration\": true\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webappsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webappsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webappsettings_webappsettings","displayName":"Web App management settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webaudiooutputbufferingenabled","displayName":"Enable adaptive buffering for Web Audio","description":"This policy controls whether the browser uses adaptive buffering for\r\nWeb Audio, which may decrease audio glitches but may increase\r\nlatency by a variable amount.\r\n\r\nSetting the policy to Enabled will always use adaptive buffering.\r\n\r\nSetting the policy to Disabled or not set will allow the browser\r\nfeature launch process to decide if adaptive buffering is used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webaudiooutputbufferingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webaudiooutputbufferingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webauthenticationremotedesktopallowedorigins","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications.","description":"A list of origins of remote desktop client apps that may execute WebAuthn API\r\nrequests that originate from a browsing session on a remote host.\r\n\r\nAny origin configured in this policy can make WebAuthn requests for Relying\r\nParty IDs (RP IDs) that it would normally not allowed to be able to claim.\r\n\r\nOnly valid HTTPS origins are allowed. Wildcards are not supported.\r\nAny invalid entries are ignored.\r\n\r\nExample value:\r\n\r\nhttps://remotedesktop.google.com\r\nhttps://vdi.corp.example\r\nhttps://server:8080/","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webauthenticationremotedesktopallowedorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webauthenticationremotedesktopallowedorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webauthenticationremotedesktopallowedorigins_webauthenticationremotedesktopallowedoriginsdesc","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webrtctextlogcollectionallowed","displayName":"Allow WebRTC text logs collection from Google Services","description":"Setting the policy to enabled means Google Chrome can collect WebRTC text logs from Google services such as Google Meet and upload them to Google. These logs have diagnostic information for debugging issues with audio or video meetings in Google Chrome, such as textual metadata describing incoming and outgoing WebRTC streams, WebRTC specific log entries and additional system information. These logs have no audio or video content from the meeting.\r\nSetting the policy to disabled results in no uploading of such logs to Google. Logs would still accumulate locally on the user's device.\r\nLeaving the policy unset means Google Chrome defaults to being able to collect and upload these logs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webrtctextlogcollectionallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webrtctextlogcollectionallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livecaptionenabled","displayName":"Enable Live Caption","description":"Enable the Live Caption feature.\r\n\r\nIf this policy is set to Enabled, Live Caption will always be turned on.\r\n\r\nIf this policy is set to Disabled, Live Caption will always be turned off.\r\n\r\nIf you set this policy as mandatory, users cannot change or override it.\r\n\r\nIf this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.","helpText":"","infoUrls":[],"categoryId":"d9432f48-3072-4171-9031-4ebead394151","categoryName":"Accessibility settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livecaptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livecaptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livetranslateenabled","displayName":"Enable Live Translate","description":"Enable translation of live captions. Captions will be sent to Google for translation.\r\n\r\nIf this policy is set to Enabled, Live Translate will always be turned on.\r\n\r\nIf this policy is set to Disabled, Live Translate will always be turned off.\r\n\r\nIf you set this policy as mandatory, users cannot change or override it.\r\n\r\nIf this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime.\r\n\r\nIn LiveCaptionEnabled is set to Disabled, Live Translate will be disabled regardless of this policy setting.","helpText":"","infoUrls":[],"categoryId":"d9432f48-3072-4171-9031-4ebead394151","categoryName":"Accessibility settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livetranslateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livetranslateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_uiautomationproviderenabled","displayName":"Enable the browser's UI Automation accessibility framework provider on Windows","description":"Enables the UI Automation accessibility framework\r\nprovider in Google Chrome for use by\r\naccessibility tools.\r\n\r\nThis policy is supported in\r\nGoogle Chrome for a one-year\r\ntransition period to allow enterprise administrators to control the deployment\r\nof the browser's UI Automation accessibility\r\nframework provider. Accessibility and other tools that use the\r\nUI Automation accessibility framework to interoperate\r\nwith the browser may require updates to function properly with the browser's\r\nUI Automation provider. Administrators can use this\r\npolicy to temporarily disable the browser's\r\nUI Automation provider (thereby reverting to the old\r\nbehavior) while they work with vendors to provide updates to impacted tools.\r\n\r\nWhen set to false, Google Chrome only\r\nenables its Microsoft Active Accessibility\r\nprovider. Accessibility and other tools that use the newer\r\nUI Automation accessibility framework to interoperate\r\nwith the browser will communicate with it by way of a compatibility shim in\r\nMicrosoft® Windows®.\r\n\r\nWhen set to true, Google Chrome\r\nenables its UI Automation provider in addition to its\r\nMicrosoft Active Accessibility provider.\r\nAccessibility and other tools that use the newer\r\nUI Automation accessibility framework to interoperate\r\nwith the browser will communicate directly with it.\r\n\r\nWhen left unset, the variations framework in Google Chrome is used to enable or disable\r\nthe provider.\r\n\r\nSupport for this policy setting will end in Google Chrome 146.","helpText":"","infoUrls":[],"categoryId":"d9432f48-3072-4171-9031-4ebead394151","categoryName":"Accessibility settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_uiautomationproviderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_uiautomationproviderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled","displayName":"Allow automatic sign-in to Microsoft® cloud identity providers","description":"Configures automatic user sign-in for accounts backed by a Microsoft® cloud identity provider.\r\n\r\nBy setting this policy to 1 (Enabled), users who sign into their computer with an account backed by a Microsoft® cloud identity provider (i.e., Microsoft® Azure® Active Directory® or the consumer Microsoft® account identity provider) or who have added a work or school account to Microsoft® Windows® can be signed into web properties using that identity automatically. Information pertaining to the user's device and account is transmitted to the user's cloud identity provider for each authentication event.\r\n\r\nBy setting this policy to 0 (Disabled) or leaving it unset, automatic sign-in as described above is disabled.\r\n\r\nThis feature is available starting in Microsoft® Windows® 10.\r\n\r\nNote: This policy doesn't apply to Incognito or Guest modes.","helpText":"","infoUrls":[],"categoryId":"463e6791-7d54-4964-a36b-63bbedb7d0cd","categoryName":"Microsoft Active Directory management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_cloudapauthenabled","displayName":"Allow automatic sign-in to Microsoft® cloud identity providers (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"463e6791-7d54-4964-a36b-63bbedb7d0cd","categoryName":"Microsoft Active Directory management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_cloudapauthenabled_0","displayName":"Disable Microsoft® cloud authentication","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_cloudapauthenabled_1","displayName":"Enable Microsoft® cloud authentication","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout","displayName":"Delay before running idle actions","description":"Triggers an action when the computer is idle.\r\n\r\nIf this policy is set, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy.\r\n\r\nIf this policy is not set, no action will be ran.\r\n\r\nThe minimum threshold is 1 minute.\r\n\r\n\"User input\" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.","helpText":"","infoUrls":[],"categoryId":"8c35f124-e249-43e3-9044-ecc0b0a5855a","categoryName":"Idle Browser Actions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout_idletimeout","displayName":"Delay before running idle actions: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8c35f124-e249-43e3-9044-ecc0b0a5855a","categoryName":"Idle Browser Actions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions","displayName":"Actions to run when the computer is idle","description":"List of actions to run when the timeout from the IdleTimeout policy is reached.\r\n\r\nWarning: Setting this policy can impact and permanently remove local personal data. It is recommended to test your settings before deploying to prevent accidental deletion of personal data.\r\n\r\nIf the IdleTimeout policy is unset, this policy has no effect.\r\n\r\nWhen the timeout from the IdleTimeout policy is reached, the browser runs the actions configured in this policy.\r\n\r\nIf this policy is empty or left unset, the IdleTimeout policy has no effect.\r\n\r\nSupported actions are:\r\n\r\n'close_browsers': close all browser windows and PWAs for this profile. Not supported on Android and iOS.\r\n\r\n'close_tabs': close all open tabs in open windows. Only supported on iOS.\r\n\r\n'show_profile_picker': show the Profile Picker window. Not supported on Android and iOS.\r\n\r\n'sign_out': Signs out the current signed in user. Only supported on iOS.\r\n\r\n'clear_browsing_history', 'clear_download_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', 'clear_autofill', 'clear_site_settings', 'clear_hosted_app_data': clear the corresponding browsing data. See the ClearBrowsingDataOnExitList policy for more details. The types supported on iOS are 'clear_browsing_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', and 'clear_autofill'\r\n\r\n'reload_pages': reload all webpages. For some pages, the user may be prompted for confirmation first. Not supported on iOS.\r\n\r\nThe user will stay signed into their Google account when deleting cookies using 'clear_cookies_and_other_site_data'.\r\n\r\nSetting 'clear_browsing_history', 'clear_password_signing', 'clear_autofill', and 'clear_site_settings' will disable sync for the respective data types if neither `Chrome Sync` is disabled by setting the SyncDisabled policy nor BrowserSignin is disabled.\r\n\r\nExample value:\r\n\r\nclose_browsers\r\nshow_profile_picker","helpText":"","infoUrls":[],"categoryId":"8c35f124-e249-43e3-9044-ecc0b0a5855a","categoryName":"Idle Browser Actions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions_idletimeoutactionsdesc","displayName":"Actions to run when the computer is idle (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8c35f124-e249-43e3-9044-ecc0b0a5855a","categoryName":"Idle Browser Actions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates.","description":"Setting the policy to All (0) or leaving it unset lets users edit trust settings for all CA certificates, remove user-imported certificates, and import certificates using Certificate Manager. Setting the policy to UserOnly (1) lets users manage only user-imported certificates, but not change trust settings of built-in certificates. Setting it to None (2) lets users view (not manage) CA certificates.","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed_0","displayName":"Allow users to manage all certificates","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed_1","displayName":"Allow users to manage user certificates","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed_2","displayName":"Disallow users from managing certificates","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication","description":"A list of TLS certificates that should be trusted by Google Chrome for server authentication.\r\nCertificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_cacertificatesdesc","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication with constraints","description":"A list of TLS certificates that should be trusted by Google Chrome for server authentication, with constraints added outside the certificate. If no constraint of a certain type is present, then any name of that type is allowed.\r\nCertificates should be base64-encoded. At least one constraint must be specified for each certificate.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=CACertificatesWithConstraints for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"certificate\": \"MIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X\",\r\n \"constraints\": {\r\n \"permitted_dns_names\": [\r\n \"example.org\"\r\n ],\r\n \"permitted_cidrs\": [\r\n \"10.1.1.0/24\"\r\n ]\r\n }\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication with constraints (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cadistrustedcertificates","displayName":"TLS certificates that should be distrusted by Google Chrome for server authentication","description":"A list of certificate public keys that should be distrusted by Google Chrome for TLS server\r\nauthentication.\r\n\r\nThe policy value is a list of base64-encoded X.509 certificates. Any\r\ncertificate with a matching SPKI (SubjectPublicKeyInfo) will be distrusted.\r\n\r\nExample value:\r\n\r\nMIIB/TCCAaOgAwIBAgIUQthnWVsd1jWpUCNBf/uILjXC+t4wCgYIKoZIzj0EAwIwVDELMAkGA1UEBhMCVVMxETAPBgNVBAgMCFZpcmdpbmlhMQ8wDQYDVQQHDAZSZXN0b24xITAfBgNVBAoMGEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDAeFw0yMzEyMDcxNjE5NTVaFw0yMzEyMjExNjE5NTVaMFQxCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhWaXJnaW5pYTEPMA0GA1UEBwwGUmVzdG9uMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQ9Akav/KB0aVA9FM1QK4J1CEHn5rFOyY/nxcr5HG3+Fom0Kwu5zTR/kz9eOYgtG/1NmCzbiEKaULDfzA8V9aJ7o1MwUTAdBgNVHQ4EFgQUq37bLKiuw8Y/G+rurMf46hw7EekwHwYDVR0jBBgwFoAUq37bLKiuw8Y/G+rurMf46hw7EekwDwYDVR0TAQH/BAUwAwEB/zAKBggqhkjOPQQDAgNIADBFAiEA/JhtLSgtVOcXkgFJ9V5Vb6lhGdiKQFfzO9wTxPeCxCECIFePYPucys2n/r9MOBMHiX/8068ssv+uceqokzUg0mAb","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cadistrustedcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cadistrustedcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cadistrustedcertificates_cadistrustedcertificatesdesc","displayName":"TLS certificates that should be distrusted by Google Chrome for server authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication","description":"A list of certificates that are not trusted or distrusted in Google Chrome\r\nbut can be used as hints for path-building. Certificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIIFljCCA36gAwIBAgINAgO8U1lrNMcY9QFQZjANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjEwHhcNMjAwODEzMDAwMDQyWhcNMjcwOTMwMDAwMDQyWjBGMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzETMBEGA1UEAxMKR1RTIENBIDFDMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPWI3+dijB43+DdCkH9sh9D7ZYIl/ejLa6T/belaI+KZ9hzpkgOZE3wJCor6QtZeViSqejOEH9Hpabu5dOxXTGZok3c3VVP+ORBNtzS7XyV3NzsXlOo85Z3VvMO0Q+sup0fvsEQRY9i0QYXdQTBIkxu/t/bgRQIh4JZCF8/ZK2VWNAcmBA2o/X3KLu/qSHw3TT8An4Pf73WELnlXXPxXbhqW//yMmqaZviXZf5YsBvcRKgKAgOtjGDxQSYflispfGStZloEAoPtR28p3CwvJlk/vcEnHXG0g/Zm0tOLKLnf9LdwLtmsTDIwZKxeWmLnwi/agJ7u2441Rj72ux5uxiZ0CAwEAAaOCAYAwggF8MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQUinR/r4XN7pXNPZzQ4kYU83E1HScwHwYDVR0jBBgwFoAU5K8rJnEaK0gnhS9SZizv8IkTcT4waAYIKwYBBQUHAQEEXDBaMCYGCCsGAQUFBzABhhpodHRwOi8vb2NzcC5wa2kuZ29vZy9ndHNyMTAwBggrBgEFBQcwAoYkaHR0cDovL3BraS5nb29nL3JlcG8vY2VydHMvZ3RzcjEuZGVyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6Ly9jcmwucGtpLmdvb2cvZ3RzcjEvZ3RzcjEuY3JsMFcGA1UdIARQME4wOAYKKwYBBAHWeQIFAzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3BraS5nb29nL3JlcG9zaXRvcnkvMAgGBmeBDAECATAIBgZngQwBAgIwDQYJKoZIhvcNAQELBQADggIBAIl9rCBcDDy+mqhXlRu0rvqrpXJxtDaV/d9AEQNMwkYUuxQkq/BQcSLbrcRuf8/xam/IgxvYzolfh2yHuKkMo5uhYpSTld9brmYZCwKWnvy15xBpPnrLRklfRuFBsdeYTWU0AIAaP0+fbH9JAIFTQaSSIYKCGvGjRFsqUBITTcFTNvNCCK9U+o53UxtkOCcXCb1YyRt8OS1b887U7ZfbFAO/CVMkH8IMBHmYJvJh8VNS/UKMG2YrPxWhu//2m+OBmgEGcYk1KCTd4b3rGS3hSMs9WYNRtHTGnXzGsYZbr8w0xNPM1IERlQCh9BIiAfq0g3GvjLeMcySsN1PCAJA/Ef5c7TaUEDu9Ka7ixzpiO2xj2YC/WXGsYye5TBeg2vZzFb8q3o/zpWwygTMD0IZRcZk0upONXbVRWPeyk+gB9lm+cZv9TSjOz23HFtz30dZGm6fKa+l3D/2gthsjgx0QGtkJAITgRNOidSOzNIb2ILCkXhAd4FJGAJ2xDx8hcFH1mt0G/FX0Kw4zd8NLQsLxdxP8c4CU6x+7Nz/OAipmsHMdMqUybDKwjuDEI/9bfU1lcKwrmz3O2+BtjjKAvpafkmO8l7tdufThcV4q5O8DIrGKZTqPwJNl1IXNDw9bg1kWRxYtnCQ6yICmJhSFm/Y3m6xv+cXDBlHz4n/FsRC6UfTd","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_cahintcertificatesdesc","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled","displayName":"Use user-added TLS certificates from platform trust stores for server authentication","description":"If enabled(or not set), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.\r\n\r\nIf disabled, user-added TLS certificates from platform trust stores will not be used in path-building for TLS server authentication.","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls","displayName":"Allow automatic fullscreen on these sites","description":"For security reasons, the\r\nrequestFullscreen() web API\r\nrequires a prior user gesture (\"transient activation\") to be called or will\r\notherwise fail. Users' personal settings may allow certain origins to call\r\nthis API without a prior user gesture, as described in\r\nhttps://chromestatus.com/feature/6218822004768768.\r\n\r\nThis policy supersedes users' personal settings and allows matching origins to\r\ncall the API without a prior user gesture.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nOrigins matching both blocked and allowed policy patterns will be blocked.\r\nOrigins not specified by policy nor user settings will require a prior user\r\ngesture to call this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls_automaticfullscreenallowedforurlsdesc","displayName":"Allow automatic fullscreen on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenblockedforurls","displayName":"Block automatic fullscreen on these sites","description":"For security reasons, the\r\nrequestFullscreen() web API\r\nrequires a prior user gesture (\"transient activation\") to be called or will\r\notherwise fail. Users' personal settings may allow certain origins to call\r\nthis API without a prior user gesture, as described in\r\nhttps://chromestatus.com/feature/6218822004768768.\r\n\r\nThis policy supersedes users' personal settings and blocks matching origins\r\nfrom calling the API without a prior user gesture.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nOrigins matching both blocked and allowed policy patterns will be blocked.\r\nOrigins not specified by policy nor user settings will require a prior user\r\ngesture to call this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenblockedforurls_automaticfullscreenblockedforurlsdesc","displayName":"Block automatic fullscreen on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardallowedforurls","displayName":"Allow clipboard on these sites","description":"Setting the policy lets you set a list of URL patterns that specify sites that can use the clipboard site permission. This does not include all clipboard operations on origins matching the patterns. For instance, users will still be able to paste using keyboard shortcuts as this isn't gated by the clipboard site permission.\r\n\r\n\r\nLeaving the policy unset means DefaultClipboardSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardallowedforurls_clipboardallowedforurlsdesc","displayName":"Allow clipboard on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardblockedforurls","displayName":"Block clipboard on these sites","description":"Setting the policy lets you set a list of URL patterns that specify sites that can't use the clipboard site permission. This does not include all clipboard operations on origins matching the patterns. For instance, users will still be able to paste using keyboard shortcuts as this isn't gated by the clipboard site permission.\r\n\r\nLeaving the policy unset means DefaultClipboardSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardblockedforurls_clipboardblockedforurlsdesc","displayName":"Block clipboard on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_dataurlinsvguseenabled","displayName":"Data URL support for SVGUseElement.","description":"This policy enables Data URL support for SVGUseElement, which will be disabled\r\nby default starting in M119.\r\nIf this policy is set to Enabled, Data URLs will continue to work in SVGUseElement.\r\nIf this policy is set to Disabled or not set, Data URLs won't work in SVGUseElement.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_dataurlinsvguseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_dataurlinsvguseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultclipboardsetting","displayName":"Default clipboard setting","description":"Setting the policy to 2 blocks sites from using the clipboard site permission. Setting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use one.\r\n\r\nThis policy can be overridden for specific URL patterns using the ClipboardAllowedForUrls and ClipboardBlockedForUrls policies.\r\n\r\nThis policy only affects clipboard operations controlled by the clipboard site permission, and does not affect sanitized clipboard writes or trusted copy and paste operations.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultclipboardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultclipboardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultclipboardsetting_defaultclipboardsetting","displayName":"Default clipboard setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultclipboardsetting_defaultclipboardsetting_2","displayName":"Do not allow any site to use the clipboard site permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultclipboardsetting_defaultclipboardsetting_3","displayName":"Allow sites to ask the user to grant the clipboard site permission","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers","description":"Allows you to set whether Google Chrome\r\nwill run the v8 JavaScript engine with more advanced JavaScript optimizations enabled.\r\n\r\nDisabling JavaScript optimizations (by setting this policy's value to 2) will\r\nmean that Google Chrome may render web\r\ncontent more slowly.\r\n\r\nThis policy can be overridden for specific URL patterns using the JavaScriptOptimizerAllowedForSites and JavaScriptOptimizerBlockedForSites policies.\r\n\r\nIf this policy is left not set, JavaScript optimizations are enabled.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting_1","displayName":"Enable advanced JavaScript optimizations on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting_2","displayName":"Disable advanced JavaScript optimizations on all sites","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting","description":"Setting the policy to BlockLocalFonts (value 2) automatically denies the local fonts permission to sites by default. This will limit the ability of sites to see information about local fonts.\r\n\r\nSetting the policy to AskLocalFonts (value 3) will prompt the user when the local fonts permission is requested by default. If users allow the permission, it will extend the ability of sites to see information about local fonts.\r\n\r\nLeaving the policy unset means the default behavior applies which is to prompt the user, but users can change this setting","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_2","displayName":"Denies the Local Fonts permission on all sites by default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_3","displayName":"Ask every time a site wants obtain the Local Fonts permission","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting","displayName":"Control use of the WebHID API","description":"Setting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.\r\n\r\nThis policy can be overridden for specific url patterns using the WebHidAskForUrls and WebHidBlockedForUrls policies.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_defaultwebhidguardsetting","displayName":"Control use of the WebHID API (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_defaultwebhidguardsetting_2","displayName":"Do not allow any site to request access to HID devices via the WebHID API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_defaultwebhidguardsetting_3","displayName":"Allow sites to ask the user to grant access to a HID device","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting","description":"Setting the policy to BlockWindowManagement (value 2) automatically denies the window management permission to sites by default. This will limit the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nSetting the policy to AskWindowManagement (value 3) will prompt the user when the window management permission is requested by default. If users allow the permission, it will extend the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nLeaving the policy unset means the AskWindowManagement policy applies, but users can change this setting.\r\n\r\nThis replaces the deprecated DefaultWindowPlacementSetting policy.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_defaultwindowmanagementsetting_2","displayName":"Denies the Window Management permission on all sites by default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_defaultwindowmanagementsetting_3","displayName":"Ask every time a site wants obtain the Window Management permission","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites","description":"Allows you to set a list of site url patterns that specify sites for which\r\nadvanced JavaScript optimizations are enabled.\r\n\r\nFor detailed information on valid site url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site\r\ngranularity (eTLD+1). A policy set for only subdomain.site.com will not\r\ncorrectly apply to site.com or subdomain.site.com since they both resolve to\r\nthe same eTLD+1 (site.com) for which there is no policy. In this case, policy\r\nmust be set on site.com to apply correctly for both site.com and\r\nsubdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level\r\norigin url alone, so e.g. if site-one.com is listed in the JavaScriptOptimizerAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript optimizations\r\nenabled, but site-two.com will use the policy from DefaultJavaScriptOptimizerSetting, if set, or default to JavaScript\r\noptimizations enabled. Blocklist entries have higher priority than allowlist\r\nentries, which in turn have higher priority than the configured default value.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise\r\nJavascript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites_javascriptoptimizerallowedforsitesdesc","displayName":"Allow JavaScript optimization on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites","description":"Allows you to set a list of site url patterns that specify sites for which\r\nadvanced JavaScript optimizations are disabled.\r\n\r\nDisabling JavaScript optimizations will mean that Google Chrome may render web content more slowly.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site\r\ngranularity (eTLD+1). A policy set for only subdomain.site.com will not\r\ncorrectly apply to site.com or subdomain.site.com since they both resolve to\r\nthe same eTLD+1 (site.com) for which there is no policy. In this case, policy\r\nmust be set on site.com to apply correctly for both site.com and\r\nsubdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level\r\norigin url alone, so e.g. if site-one.com is listed in the JavaScriptOptimizerBlockedForSites policy but site-one.com loads a frame\r\ncontaining site-two.com then site-one.com will have JavaScript optimizations\r\ndisabled, but site-two.com will use the policy from DefaultJavaScriptOptimizerSetting, if set, or default to JavaScript\r\noptimizations enabled. Blocklist entries have higher priority than allowlist\r\nentries, which in turn have higher priority than the configured default value.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise\r\nJavaScript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites_javascriptoptimizerblockedforsitesdesc","displayName":"Block JavaScript optimizations on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls","displayName":"Allow Local Fonts permission on these sites","description":"Sets a list of site url patterns that specify sites which will automatically grant the local fonts permission. This will extend the ability of sites to see information about local fonts.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls_localfontsallowedforurlsdesc","displayName":"Allow Local Fonts permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsblockedforurls","displayName":"Block Local Fonts permission on these sites","description":"Sets a list of site url patterns that specify sites which will automatically deny the local fonts permission. This will limit the ability of sites to see information about local fonts.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsblockedforurls_localfontsblockedforurlsdesc","displayName":"Block Local Fonts permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_partitionedbloburlusage","displayName":"Choose whether Blob URLs are partitioned during fetching and navigations","description":"This policy controls whether Blob URLs are partitioned during fetching and navigation.\r\nIf this policy is set to Enabled or not set, Blob URLs will be partitioned.\r\nIf this policy is set to Disabled, Blob URLs won't be partitioned.\r\n\r\nIf storage partitioning is disabled for a given top-level origin by either\r\nThirdPartyStoragePartitioningBlockedForOrigins\r\nor DefaultThirdPartyStoragePartitioningSetting,\r\nthen Blob URLs will also not be partitioned.\r\n\r\nIf you must use the policy, please file a bug at\r\nGoogle Chrome\r\nexplaining your use case. The policy is scheduled to be offered through\r\nGoogle Chrome version 143, after which\r\nthe old implementation will be removed.\r\n\r\nNOTE: Only newly-started renderer processes will reflect changes to this\r\npolicy while the browser is running.\r\n\r\nFor detailed information on third-party storage partitioning, please see\r\nhttps://developers.google.com/privacy-sandbox/cookies/storage-partitioning.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_partitionedbloburlusage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_partitionedbloburlusage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_pdflocalfileaccessallowedfordomains","displayName":"Allow local file access to file:// URLs on these sites in the PDF Viewer","description":"Setting this policy allows the domains listed to access file:// URLs in the PDF Viewer.\r\nAdding to the policy allows the domain to access file:// URLs in the PDF Viewer.\r\nRemoving from the policy disallows the domain from accessing file:// URLs in the PDF Viewer.\r\nLeaving the policy unset disallows all domains from accessing file:// URLs in the PDF Viewer.\r\n\r\nExample value:\r\n\r\nexample.com\r\ngoogle.com","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_pdflocalfileaccessallowedfordomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_pdflocalfileaccessallowedfordomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_pdflocalfileaccessallowedfordomains_pdflocalfileaccessallowedfordomainsdesc","displayName":"Allow local file access to file:// URLs on these sites in the PDF Viewer (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls","displayName":"Automatically grant permission to sites to connect to any HID device.","description":"Setting the policy allows you to list sites which are automatically granted permission to access all available devices.\r\n\r\nThe URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered.\r\n\r\nOn ChromeOS, this policy only applies to affiliated users.\r\n\r\nThis policy overrides DefaultWebHidGuardSetting, WebHidAskForUrls, WebHidBlockedForUrls and the user's preferences.\r\n\r\nExample value:\r\n\r\nhttps://google.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_webhidallowalldevicesforurlsdesc","displayName":"Automatically grant permission to sites to connect to any HID device. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices with the given vendor and product IDs.","description":"Setting the policy lets you list the URLs that specify which sites are automatically granted permission to access a HID device with the given vendor and product IDs. Each item in the list requires both devices and urls fields for the item to be valid, otherwise the item is ignored. Each item in the devices field must have a vendor_id and may have a product_id field. Omitting the product_id field will create a policy matching any device with the specified vendor ID. An item which has a product_id field without a vendor_id field is invalid and is ignored.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies, if it's set. If not, the user's personal setting applies.\r\n\r\nURLs in this policy shouldn't conflict with those configured through WebHidBlockedForUrls. If they do, this policy takes precedence over WebHidBlockedForUrls.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebHidAllowDevicesForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"product_id\": 5678,\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://google.com\",\r\n \"https://chromium.org\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls_webhidallowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices with the given vendor and product IDs. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage.","description":"Setting the policy lets you list the URLs that specify which sites are automatically granted permission to access a HID device containing a top-level collection with the given HID usage. Each item in the list requires both usages and urls fields for the policy to be valid. Each item in the usages field must have a usage_page and may have a usage field. Omitting the usage field will create a policy matching any device containing a top-level collection with a usage from the specified usage page. An item which has a usage field without a usage_page field is invalid and is ignored.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies, if it's set. If not, the user's personal setting applies.\r\n\r\nURLs in this policy shouldn't conflict with those configured through WebHidBlockedForUrls. If they do, this policy takes precedence over WebHidBlockedForUrls.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebHidAllowDevicesWithHidUsagesForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"urls\": [\r\n \"https://google.com\",\r\n \"https://chromium.org\"\r\n ],\r\n \"usages\": [\r\n {\r\n \"usage\": 5678,\r\n \"usage_page\": 1234\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdeviceswithhidusagesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdeviceswithhidusagesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdeviceswithhidusagesforurls_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls","displayName":"Allow the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns which do not match the policy, the following take precedence, in this order:\r\n\r\n * WebHidBlockedForUrls (if there is a match),\r\n\r\n * DefaultWebHidGuardSetting (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns must not conflict with WebHidBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://google.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_webhidaskforurlsdesc","displayName":"Allow the WebHID API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidblockedforurls","displayName":"Block the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns which do not match the policy, the following take precedence, in this order:\r\n\r\n * WebHidAskForUrls (if there is a match),\r\n\r\n * DefaultWebHidGuardSetting (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns can't conflict with WebHidAskForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://google.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidblockedforurls_webhidblockedforurlsdesc","displayName":"Block the WebHID API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls","displayName":"Allow Window Management permission on these sites","description":"Allows you to set a list of site url patterns that specify sites which will automatically grant the window management permission. This will extend the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nThis replaces the deprecated WindowPlacementAllowedForUrls policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls_windowmanagementallowedforurlsdesc","displayName":"Allow Window Management permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls","displayName":"Block Window Management permission on these sites","description":"Allows you to set a list of site url patterns that specify sites which will automatically deny the window management permission. This will limit the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nThis replaces the deprecated WindowPlacementBlockedForUrls policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_windowmanagementblockedforurlsdesc","displayName":"Block Window Management permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultthirdpartystoragepartitioningsetting","displayName":"Default third-party storage partitioning setting","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultthirdpartystoragepartitioningsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultthirdpartystoragepartitioningsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting","displayName":"Default third-party storage partitioning setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting_1","displayName":"Allow third-party storage partitioning by default.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting_2","displayName":"Disable third-party storage partitioning.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultwindowplacementsetting","displayName":"Default Window Placement permission setting","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultwindowplacementsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultwindowplacementsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultwindowplacementsetting_defaultwindowplacementsetting","displayName":"Default Window Placement permission setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultwindowplacementsetting_defaultwindowplacementsetting_2","displayName":"Denies the Window Placement permission on all sites by default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_defaultwindowplacementsetting_defaultwindowplacementsetting_3","displayName":"Ask every time a site wants obtain the Window Placement permission","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins","displayName":"Disable third-party storage partitioning for specific top-level origins","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nwww.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins_thirdpartystoragepartitioningblockedfororiginsdesc","displayName":"Disable third-party storage partitioning for specific top-level origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction","displayName":"Enable or disable the User-Agent Reduction.","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_useragentreduction","displayName":"Enable or disable the User-Agent Reduction. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_useragentreduction_0","displayName":"Reduced User Agent.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_useragentreduction_1","displayName":"Full (legacy) User Agent.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_useragentreduction_2","displayName":"Reduced User Agent.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls","displayName":"Allow Window Placement permission on these sites","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls_windowplacementallowedforurlsdesc","displayName":"Allow Window Placement permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls","displayName":"Block Window Placement permission on these sites","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls_windowplacementblockedforurlsdesc","displayName":"Block Window Placement permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page","description":"Control if users can turn on Developer Mode on chrome://extensions.\r\n\r\nIf the policy is not set, users can turn on developer mode on extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\r\nIf the policy is set to Allow (0), users can turn on developer mode on extensions page.\r\nIf the policy is set to Disallow (1), users can not turn on developer mode on extensions page.\r\n\r\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings_0","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings_1","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant extended background lifetime to the connecting extensions.","description":"Extensions that connect to one of these origins will be be kept running as long as the port is connected.\r\n\r\nIf unset, the policy's default values will be used. These are app origins that offer SDKs that are known to not offer the possibility to restart a closed connection to a previous state:\r\n- Smart Card Connector\r\n- Citrix Receiver (stable, beta, back-up)\r\n- VMware Horizon (stable, beta)\r\n\r\nIf set, the default value list is extended with the newly configured values. Both defaults and the policy-provided entries will grant the exception to the connecting extensions, as long as the port is connected.\r\n\r\nExample value:\r\n\r\nchrome-extension://abcdefghijklmnopabcdefghijklmnop/\r\nchrome-extension://bcdefghijklmnopabcdefghijklmnopa/","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_extensionextendedbackgroundlifetimeforportconnectionstourlsdesc","displayName":"Configure a list of origins that grant extended background lifetime to the connecting extensions. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist","displayName":"Blocklist for install types of extensions","description":"The blocklist controls which extensions install types are disallowed.\r\n\r\nSetting \"command_line\" will block extension from being loaded from\r\ncommand line.\r\n\r\nExample value:\r\n\r\ncommand_line","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_extensioninstalltypeblocklistdesc","displayName":"Blocklist for install types of extensions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability","displayName":"Control availability of extensions unpublished on the Chrome Web Store.","description":"If this policy is enabled, extensions that are unpublished on the Chrome Web\r\nStore will be disabled in Google Chrome.\r\nThis policy only applies to extensions that are installed and updated from the\r\nChrome Web Store.\r\n\r\nOff-store extensions such as unpacked extensions installed using developer\r\nmode and extensions installed using the command-line switch are ignored.\r\nForce-installed extensions that are self-hosted are ignored. All\r\nversion-pinned extensions are also ignored.\r\n\r\nIf the policy is set to AllowUnpublished (0) or not set, extensions that are unpublished on the Chrome Web Store are allowed.\r\nIf the policy is set to DisableUnpublished (1), extensions that are unpublished on the Chrome Web Store are disabled.","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_extensionunpublishedavailability","displayName":"Control availability of extensions unpublished on the Chrome Web Store. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_extensionunpublishedavailability_0","displayName":"Allow unpublished extensions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_extensionunpublishedavailability_1","displayName":"Disable unpublished extensions","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsenabled","displayName":"Enable First-Party Sets.","description":"This policy is provided as a way to opt-out of the First-Party Sets feature.\r\n\r\nWhen this policy is unset or set to Enabled, the First-Party Sets feature is enabled.\r\n\r\nWhen this policy is set to Disabled, the First-Party Sets feature is disabled.\r\n\r\nIt controls whether Chrome supports First-Party Sets related integrations.\r\n\r\nThis is the equivalent of the RelatedWebsiteSetsEnabled policy.\r\nEither policy may be used, but this one will be deprecated soon so the RelatedWebsiteSetsEnabled policy is preferred.\r\nThey both have the same effect on the browser's behavior.","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides","displayName":"Override First-Party Sets.","description":"This policy provides a way to override the list of sets the browser uses for First-Party Sets features.\r\n\r\nEach set in the browser's list of First-Party Sets must meet the requirements of a First-Party Set.\r\nA First-Party Set must contain a primary site and one or more member sites.\r\nA set can also contain a list of service sites that it owns, as well as a map from a site to all of its ccTLD variants.\r\nSee https://github.com/WICG/first-party-sets for more information on First-Party Sets are used by Google Chrome.\r\n\r\nAll sites in a First-Party Set must be a registrable domain served over HTTPS. Each site in a First-Party Set must also be unique,\r\nmeaning a site cannot be listed more than once in a First-Party Set.\r\n\r\nWhen this policy is given an empty dictionary, the browser uses the public list of First-Party Sets.\r\n\r\nFor all sites in a First-Party Set from the replacements list, if a site is also present\r\non a First-Party Set in the browser's list, then that site will be removed from the browser's First-Party Set.\r\nAfter this, the policy's First-Party Set will be added to the browser's list of First-Party Sets.\r\n\r\nFor all sites in a First-Party Set from the additions list, if a site is also present\r\non a First-Party Set in the browser's list, then the browser's First-Party Set will be updated so that the\r\nnew First-Party Set can be added to the browser's list. After the browser's list has been updated,\r\nthe policy's First-Party Set will be added to the browser's list of First-Party Sets.\r\n\r\nThe browser's list of First-Party Sets requires that for all sites in its list, no site is in\r\nmore than one set. This is also required for both the replacements list\r\nand the additions list. Similarly, a site cannot be in both the\r\nreplacements list and the additions list.\r\n\r\nWildcards (*) are not supported as a policy value, nor within any First-Party Set in these lists.\r\n\r\nAll sets provided by the policy must be valid First-Party Sets, if they aren't then an\r\nappropriate error will be outputted.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\n\r\nThis is the equivalent of the RelatedWebsiteSetsOverrides policy.\r\nEither policy may be used, but this one will be deprecated soon so the RelatedWebsiteSetsOverrides policy is preferred.\r\nThey both have the same effect on the browser's behavior.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=FirstPartySetsOverrides for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"additions\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate2.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate2.test\": [\r\n \"https://associate2.com\"\r\n ]\r\n },\r\n \"primary\": \"https://primary2.test\",\r\n \"serviceSites\": [\r\n \"https://associate2-content.test\"\r\n ]\r\n }\r\n ],\r\n \"replacements\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate1.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate1.test\": [\r\n \"https://associate1.co.uk\"\r\n ]\r\n },\r\n \"primary\": \"https://primary1.test\",\r\n \"serviceSites\": [\r\n \"https://associate1-content.test\"\r\n ]\r\n }\r\n ]\r\n}","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_firstpartysetsoverrides","displayName":"Override First-Party Sets. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings","displayName":"Settings for Google's AI Mode integrations in the address bar and New Tab page search box.","description":"This policy controls Google's AI Mode integrations in the address bar and the New Tab page search box.\r\n\r\nTo access this feature, Google must be set as the user's default search engine.\r\n\r\n0/unset = The feature will be available to users.\r\n\r\n1 = The feature will not be available to users.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_aimodesettings","displayName":"Settings for Google's AI Mode integrations in the address bar and New Tab page search box. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_aimodesettings_0","displayName":"Allow AI Mode integrations.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_aimodesettings_1","displayName":"Do not allow AI Mode integrations.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings","displayName":"Settings for enhanced autofill","description":"Specifies whether users can let Google Chrome use Generative AI to better understand forms and help them fill more fields.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings_autofillpredictionsettings","displayName":"Settings for enhanced autofill (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings_autofillpredictionsettings_0","displayName":"Allow enhanced autofill and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings_autofillpredictionsettings_1","displayName":"Allow enhanced autofill without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_autofillpredictionsettings_autofillpredictionsettings_2","displayName":"Do not allow enhanced autofill.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings","displayName":"Settings for Create Themes with AI","description":"Create Themes with AI lets users create custom themes/wallpapers by preselecting from a list of options.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings_createthemessettings","displayName":"Settings for Create Themes with AI (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings_createthemessettings_0","displayName":"Allow Create Themes and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings_createthemessettings_1","displayName":"Allow Create Themes without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_createthemessettings_createthemessettings_2","displayName":"Do not allow Create Themes.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings","displayName":"Settings for DevTools Generative AI Features","description":"These features in Google Chrome's DevTools employ generative AI models to provide additional debugging information. To use these features, Google Chrome has to collect data such as error messages, stack traces, code snippets, and network requests and send them to a server owned by Google, which runs a generative AI model. Response body or authentication and cookie headers in network requests are not included in the data sent to the server.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nDevTools Generative AI features include:\r\n\r\n- Console Insights: explains console messages and offers suggestions on how to fix console errors.\r\n\r\n- AI assistance: get help with understanding CSS styles (since version 131), network requests, performance, and files (all since version 132).\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings_devtoolsgenaisettings","displayName":"Settings for DevTools Generative AI Features (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings_devtoolsgenaisettings_0","displayName":"Allow DevTools Generative AI Features and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings_devtoolsgenaisettings_1","displayName":"Allow DevTools Generative AI Features without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_devtoolsgenaisettings_devtoolsgenaisettings_2","displayName":"Do not allow DevTools Generative AI Features.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings","displayName":"Settings for Gemini integration","description":"This setting allows Gemini app integrations.\r\n\r\n0/unset = Gemini integration will be available for users.\r\n\r\n1 = Gemini integration will not be available for users.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information, please check the Help Center article https://support.google.com/chrome/a?p=gemini_in_chrome.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_geminisettings","displayName":"Settings for Gemini integration (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_geminisettings_0","displayName":"Allow Gemini integrations.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_geminisettings_1","displayName":"Do not allow Gemini integrations.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings","displayName":"Settings for GenAI local foundational model","description":"Configure how Google Chrome downloads the foundational GenAI model and uses for inference locally.\r\n\r\nWhen the policy is set to Allowed (0) or not set, the model is downloaded automatically, and used for inference.\r\n\r\nWhen the policy is set to Disabled (1), the model will not be downloaded.\r\n\r\nModel downloading can also be disabled by ComponentUpdatesEnabled.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings","displayName":"Settings for GenAI local foundational model (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings_0","displayName":"Downloads model automatically","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings_1","displayName":"Do not download model","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings","displayName":"Settings for Help Me Write","description":"Help Me Write is an AI-based writing assistant for short-form content on the web. Suggested content is based on prompts entered by the user and the content of the web page.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings","displayName":"Settings for Help Me Write (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_0","displayName":"Allow Help Me Write and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_1","displayName":"Allow Help Me Write without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_2","displayName":"Do not allow Help Me Write.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings","displayName":"Settings for AI-powered History Search","description":"AI History Search is a feature that allows users to search their browsing history and receive generated answers based on page contents and not just the page title and URL.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings","displayName":"Settings for AI-powered History Search (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings_0","displayName":"Allow AI History Search and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings_1","displayName":"Allow AI History Search without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings_2","displayName":"Do not allow AI History Search.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings","displayName":"Tab Compare settings","description":"Tab Compare is an AI-powered tool for comparing information across a user's tabs. As an example, the feature can be offered to the user when multiple tabs with products in a similar category are open.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_tabcomparesettings","displayName":"Tab Compare settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_tabcomparesettings_0","displayName":"Allow Tab Compare and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_tabcomparesettings_1","displayName":"Allow Tab Compare without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_tabcomparesettings_2","displayName":"Do not allow Tab Compare.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration","displayName":"Specifies how long (in seconds) a cast device selected with an access code or QR code stays in the Google Cast menu's list of cast devices.","description":"This policy specifies how long (in seconds) a cast device that was previously selected via an access code or QR code can be seen within the Google Cast menu of cast devices.\r\nThe lifetime of an entry starts at the time the access code was first entered or the QR code was first scanned.\r\nDuring this period the cast device will appear in the Google Cast menu's list of cast devices.\r\nAfter this period, in order to use the cast device again the access code must be reentered or the QR code must be rescanned.\r\nBy default, the period is zero seconds, so cast devices will not stay in the Google Cast menu, and so the access code must be reentered, or the QR code rescanned, in order to initiate a new casting session.\r\nNote that this policy only affects how long a cast devices appears in the Google Cast menu, and has no effect on any ongoing cast session which will continue even if the period expires.\r\nThis policy has no effect unless the AccessCodeCastEnabled policy is Enabled.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration_accesscodecastdeviceduration","displayName":"Specifies how long (in seconds) a cast device selected with an access code or QR code stays in the Google Cast menu's list of cast devices.: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastenabled","displayName":"Allow users to select cast devices with an access code or QR code from within the Google Cast menu.","description":"This policy controls whether a user will be presented with an option, within the Google Cast menu which allows them to cast to cast devices that do not appear in the Google Cast menu, using either the access code or QR code displayed on the cast devices's screen.\r\nBy default, a user must reenter the access code or rescan the QR code in order to initiate a subsequent casting session, but if the AccessCodeCastDeviceDuration policy has been set to a non-zero value (the default is zero), then the cast device will remain in the list of available cast devices until the specified period of time has expired.\r\nWhen this policy is set to Enabled, users will be presented with the option to select cast devices by using an access code or by scanning a QR code.\r\nWhen this policy is set to Disabled or not set, users will not be given the option to select cast devices by using an access code or by scanning a QR code.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_showcastsessionsstartedbyotherdevices","displayName":"Show media controls for Google Cast sessions started by other devices on the local network","description":"When this policy is enabled, media playback controls UI is available for Google Cast sessions started by other devices on the local network.\r\n\r\nWhen this policy is unset for enterprise users or is disabled, media playback controls UI is unavailable for Google Cast sessions started by other devices on the local network.\r\n\r\nIf the policy EnableMediaRouter is disabled, then this policy's value has no effect, as the entire Google Cast functionality is disabled.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_showcastsessionsstartedbyotherdevices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_showcastsessionsstartedbyotherdevices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins","displayName":"List of origins allowing all HTTP authentication","description":"Setting the policy specifies for which origins to allow all the HTTP authentication schemes Google Chrome supports regardless of the AuthSchemes policy.\r\n\r\nFormat the origin pattern according to this format (https://support.google.com/chrome/a?p=url_blocklist_filter_format). Up to 1,000 exceptions can be defined in AllHttpAuthSchemesAllowedForOrigins.\r\nWildcards are allowed for the whole origin or parts of the origin, either the scheme, host, port.\r\n\r\nExample value:\r\n\r\n*.example.com","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins_allhttpauthschemesallowedfororiginsdesc","displayName":"List of origins allowing all HTTP authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls","displayName":"Allow sites to make requests to local network endpoints.","description":"List of URL patterns. Requests initiated from websites served by matching origins are not subject to Local Network Access checks.\r\n\r\nIf an origin is covered by both this policy and by LocalNetworkAccessBlockedForUrls, LocalNetworkAccessBlockedForUrls takes precedence.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_localnetworkaccessallowedforurlsdesc","displayName":"Allow sites to make requests to local network endpoints. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls","displayName":"Block sites from making requests to local network endpoints.","description":"List of URL patterns. Requests initiated from websites served by matching origins are blocked from issuing Local Network Access requests.\r\n\r\nIf an origin is covered by both this policy and by LocalNetworkAccessAllowedForUrls, this policy takes precedence.\r\n\r\nDepending on the stage of the rollout of Local Network Access, LocalNetworkAccessRestrictionsEnabled may also need to be enabled for this policy to block Local Network Access requests.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls_localnetworkaccessblockedforurlsdesc","displayName":"Block sites from making requests to local network endpoints. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to apply restrictions to requests to local network endpoints","description":"When this policy is set to Enabled, any time when a warning is supposed to be\r\ndisplayed in the DevTools due to Local Network Access checks failing, the\r\nmain request will be blocked instead.\r\n\r\nWhen this policy is set to Disabled or unset, Local Network Access requests will use the\r\ndefault handling of these requests.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessrestrictionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessrestrictionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_accesscontrolallowmethodsincorspreflightspecconformant","displayName":"Make Access-Control-Allow-Methods matching in CORS preflight spec conformant","description":"This policy controls whether request methods are uppercased when matching with Access-Control-Allow-Methods response headers in CORS preflight.\r\n\r\nIf the policy is Disabled, request methods are uppercased.\r\nThis is the behavior on or before Google Chrome 108.\r\n\r\nIf the policy is Enabled or not set, request methods are not uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT.\r\nThis would reject fetch(url, {method: 'Foo'}) + \"Access-Control-Allow-Methods: FOO\" response header,\r\nand would accept fetch(url, {method: 'Foo'}) + \"Access-Control-Allow-Methods: Foo\" response header.\r\n\r\nNote: request methods \"post\" and \"put\" are not affected, while \"patch\" is affected.\r\n\r\nThis policy is intended to be temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"fa2722a8-dcfd-4e14-a429-2b0041642c77","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_accesscontrolallowmethodsincorspreflightspecconformant_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_accesscontrolallowmethodsincorspreflightspecconformant_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_compressiondictionarytransportenabled","displayName":"Enable compression dictionary transport support","description":"This feature enables the use of dictionary-specific content encodings in the Accept-Encoding request header (\"sbr\" and \"zst-d\") when dictionaries are available for use.\r\n\r\nSetting the policy to Enabled or leaving it unset means Google Chrome will accept web contents using the compression dictionary transport feature.\r\nSetting the policy to Disabled turns off the compression dictionary transport feature.","helpText":"","infoUrls":[],"categoryId":"fa2722a8-dcfd-4e14-a429-2b0041642c77","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_compressiondictionarytransportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_compressiondictionarytransportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_dataurlwhitespacepreservationenabled","displayName":"DataURL Whitespace Preservation for all media types","description":"This policy provides a temporary opt-out for changes to how Chrome handles whitepsace in data URLS.\r\nPreviously, whitespace would be kept only if the top level media type was text or contained the media type string xml.\r\nNow, whitespace will be preserved in all data URLs, regardless of media type.\r\n\r\nIf this policy is left unset or is set to True, the new behavior is enabled.\r\n\r\nWhen this policy is set to False, the old behavior is enabled.","helpText":"","infoUrls":[],"categoryId":"fa2722a8-dcfd-4e14-a429-2b0041642c77","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_dataurlwhitespacepreservationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_dataurlwhitespacepreservationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_happyeyeballsv3enabled","displayName":"Use the Happy Eyeballs V3 algorithm","description":"This feature enables the Happy Eyeballs V3 algorithm to make connection attempts. See https://datatracker.ietf.org/doc/draft-pauly-happy-happyeyeballs-v3 for details.\r\n\r\nSetting the policy to Enabled means Google Chrome will use the Happy Eyeballs V3 algorithm for connection attempts.\r\n\r\nSetting the policy to Disabled turns off the Happy Eyeballs V3 algorithm.\r\n\r\nNot setting the policy, Google Chrome will turn on or off the Happy Eyeballs V3 algorithm based on chrome://flags/#happy-eyeballs-v3.\r\n\r\nThis policy supports dynamic refresh.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Google Chrome.","helpText":"","infoUrls":[],"categoryId":"fa2722a8-dcfd-4e14-a429-2b0041642c77","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_happyeyeballsv3enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_happyeyeballsv3enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_ipv6reachabilityoverrideenabled","displayName":"Enable IPv6 reachability check override","description":"Setting the policy to true overrides the IPv6 reachability check. This means that the\r\nsystem will always query AAAA records when resolving host names. It applies to\r\nall users and interfaces on the device.\r\n\r\nSetting the policy to false or leaving it unset does not overrides the IPv6 reachability check.\r\nThe system only queries AAAA records when it is reachable to a global IPv6 host.","helpText":"","infoUrls":[],"categoryId":"fa2722a8-dcfd-4e14-a429-2b0041642c77","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_ipv6reachabilityoverrideenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_ipv6reachabilityoverrideenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings","displayName":"Enable automated password change","description":"This policy controls the availability of Google Chrome's automated password change feature.\r\n\r\nIf enabled, a user can trigger a process where the browser attempts to change their password on a website automatically. This process is managed by Generative AI. The new password is saved in the browser's password manager.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings","displayName":"Enable automated password change (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_0","displayName":"Allow feature use and improving AI models","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_1","displayName":"Allow feature use without improving AI models","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_2","displayName":"Do not allow feature","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own and, if fixing them is possible, it usually requires complex user actions.\r\n\r\nSetting the policy to Enabled or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched.\r\n\r\nSetting the policy to Disabled means users will leave their password manager data untouched, but will experience a broken password manager functionality.\r\n\r\nIf the policy is set, users can't change it in Google Chrome.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passworddismisscompromisedalertenabled","displayName":"Enable dismissing compromised password alerts for entered credentials","description":"Setting the policy to Enabled or leaving it unset gives the user the option to dismiss/restore compromised password alerts.\r\n\r\nIf you disable this setting, users will not be able to dismiss alerts about compromised passwords. If enabled, users will be able to dismiss alerts about compromised passwords.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passworddismisscompromisedalertenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passworddismisscompromisedalertenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist","displayName":"Configure the list of domains for which the Password Manager (Save and Fill) will be disabled","description":"Configure the list of domains where Google Chrome should disable the Password Manager. This means that Save and Fill workflows will be disabled, ensuring that passwords for those websites can't be saved or auto filled into web forms.\r\n\r\nIf a domain is present in the list, the Password Manager will be disabled for it.\r\n\r\nIf a domain is not present in the list, the Password Manager will be available for it.\r\n\r\nIf the policy is unset, the Password Manager will be available for all domains.\r\n\r\nExample value:\r\n\r\nexample.com\r\nlogin.example.com","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_passwordmanagerblocklistdesc","displayName":"Configure the list of domains for which the Password Manager (Save and Fill) will be disabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerpasskeysenabled","displayName":"Enable saving passkeys to the password manager","description":"This policy controls the browser's ability to save passkeys in the built-in password manager. It does not limit access to, or change the contents of, passkeys already saved in the password manager. If the PasswordManagerEnabled policy is set to Disabled then saving in the built-in password manager is disabled in general, including passkeys and passwords, and thus this policy is not applicable.\r\n\r\nSetting the policy to Enabled or leaving unset means that users can save passkeys in the built-in password manager if signed into Google Chrome.\r\n\r\nSetting the policy to Disabled means users can't save passkeys to the built-in password manager, but previously saved passkeys will still work.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerpasskeysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerpasskeysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordsharingenabled","displayName":"Enable sharing user credentials with other users","description":"Setting the policy to Enabled lets users send to and receive from family members (according to Family Service) their passwords.\r\nWhen the policy is Enabled or not set, there is a button in the Password Manager allowing to send a password.\r\nThe received passwords are stored into user's account and are available in the Password Manager.\r\n\r\nSetting the policy to Disabled means users can't send passwords from Password Manager to other users, and can't receive passwords from other users.\r\n\r\nThe feature is not available if synchronization of Passwords is turned off (either via user settings or SyncDisabled policy is Enabled).\r\n\r\nManaged accounts aren't eligible to join or create a family group and therefore cannot share passwords.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordsharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordsharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed","displayName":"Out-of-process print drivers allowed","description":"Controls if Google Chrome interacts with printer drivers from a separate service process. Platform printing calls to query available printers, get print driver settings, and submit documents for printing to local printers are made from a service process. Moving such calls out of the browser process helps improve stability and reduce frozen UI behavior in Print Preview.\r\n\r\nWhen this policy is set to Enabled or not set, Google Chrome will use a separate service process for platform printing tasks.\r\n\r\nWhen this policy is set to Disabled, Google Chrome will use the browser process for platform printing tasks.\r\n\r\nThis policy will be removed in the future, after the out-of-process print drivers feature has fully rolled out.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printinglpacsandboxenabled","displayName":"Enable Printing LPAC Sandbox","description":"Setting the policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services whenever the system configuration supports it.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security as services used for printing might run in a weaker sandbox configuration.\r\n\r\nOnly turn off the policy if there are compatibility issues with third party software that prevent printing services from operating correctly inside the LPAC Sandbox.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printinglpacsandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printinglpacsandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printpdfasimagedefault","displayName":"Print PDF as Image Default","description":"Controls if Google Chrome makes the Print as image option default to set when printing PDFs.\r\n\r\nWhen this policy is set to Enabled, Google Chrome will default to setting the Print as image option in the Print Preview when printing a PDF.\r\n\r\nWhen this policy is set to Disabled or not set Google Chrome then the user selection for Print as image option will be initially unset. The user will be allowed to select it for each individual PDFs print job, if the option is available.\r\n\r\nFor Microsoft® Windows® or macOS this policy only has an effect if PrintPdfAsImageAvailability is also enabled.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printpdfasimagedefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printpdfasimagedefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadmeasurementenabled","displayName":"Choose whether the Privacy Sandbox ad measurement setting can be disabled","description":"A policy to control whether the Privacy Sandbox Ad measurement setting can be disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Ad measurement setting will be turned off for your users.\r\nIf you set this policy to Enabled or keep it unset, your users will be able to turn on or off the Privacy Sandbox Ad measurement setting on their device.\r\n\r\nSetting this policy requires setting the PrivacySandboxPromptEnabled policy to Disabled.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadmeasurementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadmeasurementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadtopicsenabled","displayName":"Choose whether the Privacy Sandbox Ad topics setting can be disabled","description":"A policy to control whether the Privacy Sandbox Ad topics setting can be disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Ad topics setting will be turned off for your users.\r\nIf you set this policy to Enabled or keep it unset, your users will be able to turn on or off the Privacy Sandbox Ad topics setting on their device.\r\n\r\nSetting this policy requires setting the PrivacySandboxPromptEnabled policy to Disabled.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadtopicsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadtopicsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxfingerprintingprotectionenabled","displayName":"Choose whether the Privacy Sandbox Fingerprinting Protection feature is to be enabled in Incognito mode.","description":"A policy to control whether the Privacy Sandbox Fingerprinting Protection setting is to be enabled in Incognito mode or disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Fingerprinting Protection feature setting will be turned off for your users.\r\nIf you set this policy to Enabled, your users will have the Fingerprinting Protection feature setting turned on in Incognito mode.\r\nIf the policy is not set, users will be able to turn on or off the Fingerprinting Protection feature for Incognito mode in their UI settings. The default state will be false or disabled, meaning the Fingerprinting Protection feature will be turned off.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxfingerprintingprotectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxfingerprintingprotectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxipprotectionenabled","displayName":"Choose whether the Privacy Sandbox IP Protection feature should be enabled.","description":"A policy to control whether the Privacy Sandbox IP Protection feature should be enabled.\r\n\r\nIP Protection is a feature that limits availability of a user's original IP address for certain third-party network requests made while browsing in Incognito mode, enhancing protections against cross-site tracking during Incognito browsing sessions.\r\n\r\nIf the policy is set to Disabled, then IP Protection will be disabled and users won't be able to enable the feature via UI settings.\r\nIf the policy is set to Enabled, then IP Protection will be enabled and users won't be able to disable the feature via UI settings.\r\nIf the policy is not set, IP Protection will be enabled by default and users will be able to control the feature on their device via UI settings.\r\n\r\nSome considerations regarding whether enterprises should disable IP Protection include:\r\n\r\n- DNS lookups won't be performed for requests that are proxied, which may impact DNS-based monitoring or filtering.\r\n\r\n- Enterprise applications may experience breakage when used in Incognito mode if they rely on requests to domains (or subdomains of those domains) on the Masked Domain List (Google Chrome) and require those requests to come from specific IP address ranges.\r\n\r\n- Traffic might not be proxied in Incognito mode under certain conditions, for example when users launch Incognito mode from a Chrome profile they aren't signed in to. In general the feature requires the user to have been signed in to Chrome with a personal Google account when launching Incognito mode.\r\n\r\n- The list of domains on the Masked Domain List may change over time, with new versions being pushed to users automatically. For more information on the Masked Domain List, see: Google Chrome.\r\n\r\nFor more information on IP Protection, see: Google Chrome.\r\n\r\nIP Protection will be launched no sooner than M139.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxipprotectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxipprotectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxpromptenabled","displayName":"Choose whether the Privacy Sandbox prompt can be shown to your users","description":"A policy to control whether your users see the Privacy Sandbox prompt.\r\nThe prompt is a user-blocking flow which informs your users of the Privacy Sandbox settings. See https://privacysandbox.com for details about Chrome’s effort to deprecate third-party cookies.\r\n\r\nIf you set this policy to Disabled, then Google Chrome won’t show the Privacy Sandbox prompt.\r\nIf you set this policy to Enabled or keep it unset, then Google Chrome determines whether the Privacy Sandbox prompt can be shown or not and then show it if possible.\r\n\r\nIf any of the following policies are set, it’s required to set this policy to Disabled:\r\nPrivacySandboxAdTopicsEnabled\r\nPrivacySandboxSiteEnabledAdsEnabled\r\nPrivacySandboxAdMeasurementEnabled","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxpromptenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxpromptenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxsiteenabledadsenabled","displayName":"Choose whether the Privacy Sandbox Site-suggested ads setting can be disabled","description":"A policy to control whether the Privacy Sandbox Site-suggested ads setting can be disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Site-suggested ads setting will be turned off for your users.\r\nIf you set this policy to Enabled or keep it unset, your users will be able to turn on or off the Privacy Sandbox Site-suggested ads setting on their device.\r\n\r\nSetting this policy requires setting the PrivacySandboxPromptEnabled policy to Disabled.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxsiteenabledadsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxsiteenabledadsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~protectedcontent_protectedcontentidentifiersallowed","displayName":"Allows web pages to use identifiers for the purpose of protected content playback","description":"If the policy is set to true or unset, the use of protected content identifiers is allowed, which can help enable higher quality of protected content playback.\r\n\r\nIf the policy is set to false, protected content identifiers are not allowed to be used.","helpText":"","infoUrls":[],"categoryId":"4cd10f38-02cf-40f2-aa87-ad70a2190a1a","categoryName":"Protected Content","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~protectedcontent_protectedcontentidentifiersallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~protectedcontent_protectedcontentidentifiersallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsenabled","displayName":"Enable Related Website Sets","description":"This policy allows to control the Related Website Sets feature enablement.\r\n\r\nThis policy overrides the FirstPartySetsEnabled policy.\r\n\r\nWhen this policy is unset or set to True, the Related Website Sets feature is enabled.\r\n\r\nWhen this policy is set to False, the Related Website Sets feature is disabled.","helpText":"","infoUrls":[],"categoryId":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","categoryName":"Related Website Sets Settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets.","description":"This policy provides a way to override the list of sets the browser uses for Related Website Sets features.\r\n\r\nThis policy overrides the FirstPartySetsOverrides policy.\r\n\r\nEach set in the browser's list of Related Website Sets must meet the requirements of a Related Website Set.\r\nA Related Website Set must contain a primary site and one or more member sites.\r\nA set can also contain a list of service sites that it owns, as well as a map from a site to all of its ccTLD variants.\r\nSee https://github.com/WICG/first-party-sets for more information on how Google Chrome uses Related Website Sets.\r\n\r\n\r\nAll sites in a Related Website Set must be a registrable domain served over HTTPS. Each site in a Related Website Set must also be unique,\r\nmeaning a site cannot be listed more than once in a Related Website Set.\r\n\r\nWhen this policy is given an empty dictionary, the browser uses the public list of Related Website Sets.\r\n\r\nFor all sites in a Related Website Set from the replacements list, if a site is also present\r\non a Related Website Set in the browser's list, then that site will be removed from the browser's Related Website Set.\r\nAfter this, the policy's Related Website Set will be added to the browser's list of Related Website Sets.\r\n\r\nFor all sites in a Related Website Set from the additions list, if a site is also present\r\non a Related Website Set in the browser's list, then the browser's Related Website Set will be updated so that the\r\nnew Related Website Set can be added to the browser's list. After the browser's list has been updated,\r\nthe policy's Related Website Set will be added to the browser's list of Related Website Sets.\r\n\r\nThe browser's list of Related Website Sets requires that for all sites in its list, no site is in\r\nmore than one set. This is also required for both the replacements list\r\nand the additions list. Similarly, a site cannot be in both the\r\nreplacements list and the additions list.\r\n\r\nWildcards (*) are not supported as a policy value, nor within any Related Website Set in these lists.\r\n\r\nAll sets provided by the policy must be valid Related Website Sets, if they aren't then an\r\nappropriate error will be outputted.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=RelatedWebsiteSetsOverrides for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"additions\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate2.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate2.test\": [\r\n \"https://associate2.com\"\r\n ]\r\n },\r\n \"primary\": \"https://primary2.test\",\r\n \"serviceSites\": [\r\n \"https://associate2-content.test\"\r\n ]\r\n }\r\n ],\r\n \"replacements\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate1.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate1.test\": [\r\n \"https://associate1.co.uk\"\r\n ]\r\n },\r\n \"primary\": \"https://primary1.test\",\r\n \"serviceSites\": [\r\n \"https://associate1-content.test\"\r\n ]\r\n }\r\n ]\r\n}","helpText":"","infoUrls":[],"categoryId":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","categoryName":"Related Website Sets Settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsoverrides_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","categoryName":"Related Website Sets Settings","options":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~remoteaccess_remoteaccesshostallowpinauthentication","displayName":"Allow PIN and pairing authentication methods for remote access hosts","description":"Setting the policy to Enabled allows the remote access host to use PIN and pairing authentications when accepting client connections.\r\n\r\nSetting the policy to Disabled disallows PIN or pairing authentications.\r\n\r\nLeaving it unset lets the host decide whether PIN and/or pairing authentications can be used.\r\n\r\nNote: If the setting results in no mutually supported authentication methods by both the host and the client, then the connection will be rejected.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~remoteaccess_remoteaccesshostallowpinauthentication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~remoteaccess_remoteaccesshostallowpinauthentication_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~remoteaccess_remoteaccesshostallowurlforwarding","displayName":"Allow remote access users to open host-side URLs in their local client browser","description":"Setting the policy to Enabled or leaving it unset may allow users connected to a remote access host to open host-side URLs in their local client browser.\r\n\r\nSetting the policy to Disabled will prevent the remote access host from sending URLs to the client.\r\n\r\nThis setting doesn't apply to remote assistance connections as the feature is not supported for that connection mode.\r\n\r\nNote: This feature is not yet generally available so enabling it does not mean that the feature will be visible in the client UI.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~remoteaccess_remoteaccesshostallowurlforwarding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~remoteaccess_remoteaccesshostallowurlforwarding_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_assistantwebenabled","displayName":"Allow using Google Assistant on the web, e.g. to enable changing passwords automatically","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_assistantwebenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_assistantwebenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_beforeunloadeventcancelbypreventdefaultenabled","displayName":"Control new behavior for the cancel dialog produced by the beforeunload event","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_beforeunloadeventcancelbypreventdefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_beforeunloadeventcancelbypreventdefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_blocktruncatedcookies","displayName":"Block truncated cookies","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_blocktruncatedcookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_blocktruncatedcookies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappsenabled","displayName":"Extend support for Chrome Apps on Microsoft® Windows®, macOS, and Linux.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappswebviewpermissivebehaviorallowed","displayName":"Restore permissive Chrome Apps behavior","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappswebviewpermissivebehaviorallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappswebviewpermissivebehaviorallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromerootstoreenabled","displayName":"Determines whether the Chrome Root Store and built-in certificate verifier will be used to verify server certificates","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromerootstoreenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromerootstoreenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_csscustomstatedeprecatedsyntaxenabled","displayName":"Controls whether the deprecated :--foo syntax for CSS custom state is enabled","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_csscustomstatedeprecatedsyntaxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_csscustomstatedeprecatedsyntaxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_downloadbubbleenabled","displayName":"Enable download bubble UI","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_downloadbubbleenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_downloadbubbleenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_enforcelocalanchorconstraintsenabled","displayName":"Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_enforcelocalanchorconstraintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_enforcelocalanchorconstraintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_eventpathenabled","displayName":"Re-enable the Event.path API until M115.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_eventpathenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_eventpathenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_0","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_1","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_2","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_3","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled","displayName":"Re-enable the deprecated async interface for FileSystemSyncAccessHandle in File System Access API","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forceenablepeppervideodecoderdevapi","displayName":"Enable support for the PPB_VideoDecoder(Dev) API.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forceenablepeppervideodecoderdevapi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forceenablepeppervideodecoderdevapi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent","displayName":"Freeze User-Agent string major version at 99","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_forcemajorversiontominorpositioninuseragent","displayName":"Freeze User-Agent string major version at 99 (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_forcemajorversiontominorpositioninuseragent_0","displayName":"Default to browser settings for User-Agent string version.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_forcemajorversiontominorpositioninuseragent_1","displayName":"The User-Agent string will not freeze the major version.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_forcemajorversiontominorpositioninuseragent_2","displayName":"The User-Agent string will freeze the major version as 99 and include the browser's major version in the minor position.","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_insecurehashesintlshandshakesenabled","displayName":"Insecure Hashes in TLS Handshakes Enabled","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_insecurehashesintlshandshakesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_insecurehashesintlshandshakesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_keyboardfocusablescrollersenabled","displayName":"Enable keyboard focusable scrollers","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_keyboardfocusablescrollersenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_keyboardfocusablescrollersenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_loadcryptotokenextension","displayName":"Load the CryptoToken component extension at startup","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_loadcryptotokenextension_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_loadcryptotokenextension_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled","displayName":"Re-enable deprecated/removed Mutation Events","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_nativeclientforceallowed","displayName":"Forces Native Client (NaCl) to be allowed to run.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_nativeclientforceallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_nativeclientforceallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_newbaseurlinheritancebehaviorallowed","displayName":"Allows enabling the feature NewBaseUrlInheritanceBehavior","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_newbaseurlinheritancebehaviorallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_newbaseurlinheritancebehaviorallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled","displayName":"Control the new behavior of HTMLElement.offsetParent","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_optimizationguidefetchingenabled","displayName":"Enable Optimization Guide Fetching","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_optimizationguidefetchingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_optimizationguidefetchingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_persistentquotaenabled","displayName":"Force persistent quota to be enabled","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_persistentquotaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_persistentquotaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_ppapisharedimagesswapchainallowed","displayName":"Allow modern buffer allocation for Graphics3D APIs PPAPI plugin.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_ppapisharedimagesswapchainallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_ppapisharedimagesswapchainallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedstorageinfoenabled","displayName":"Re-enable the deprecated window.webkitStorageInfo API","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedstorageinfoenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedstorageinfoenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability","displayName":"Manage the deprecated prefixed video fullscreen API's availability","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability","displayName":"Manage the deprecated prefixed video fullscreen API's availability (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability_runtime-enabled","displayName":"Follows regular deprecation timelines for the PrefixedVideoFullscreen API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability_disabled","displayName":"Disables prefixed video fullscreen APIs","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability_enabled","displayName":"Enables prefixed video fullscreen APIs","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_privatenetworkaccessrestrictionsenabled","displayName":"Specifies whether to apply restrictions to requests to more-private network endpoints","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_privatenetworkaccessrestrictionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_privatenetworkaccessrestrictionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_rsakeyusageforlocalanchorsenabled","displayName":"Check RSA key usage for server certificates issued by local trust anchors","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_rsakeyusageforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_rsakeyusageforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_selectparserrelaxationenabled","displayName":"Controls whether the new HTML parser behavior for the element is enabled","description":"The HTML parser is being changed to allow additional HTML tags inside the element.\r\n\r\nIf this policy is disabled, then the HTML parser will restrict which tags can be put in the element is enabled (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_selectparserrelaxationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_selectparserrelaxationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_sendmouseeventsdisabledformcontrolsenabled","displayName":"Control the new behavior for event dispatching on disabled form controls (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_sendmouseeventsdisabledformcontrolsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_sendmouseeventsdisabledformcontrolsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_settimeoutwithout1msclampenabled","displayName":"Control Javascript setTimeout() function minimum timeout. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_settimeoutwithout1msclampenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_settimeoutwithout1msclampenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings","displayName":"Settings for Tab Organizer (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings","displayName":"Settings for Tab Organizer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings_0","displayName":"Allow Tab Organizer and improve AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings_1","displayName":"Allow Tab Organizer without improving AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings_2","displayName":"Do not allow Tab Organizer.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_throttlenonvisiblecrossoriginiframesallowed","displayName":"Allows enabling throttling of non-visible, cross-origin iframes (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_throttlenonvisiblecrossoriginiframesallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_throttlenonvisiblecrossoriginiframesallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings","displayName":"Managed toolbar avatar label setting (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_toolbaravatarlabelsettings","displayName":"Managed toolbar avatar label setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_toolbaravatarlabelsettings_0","displayName":"Always display management label","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_toolbaravatarlabelsettings_1","displayName":"Display management labels for 30s","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_unthrottlednestedtimeoutenabled","displayName":"Control the nesting threshold before which Javascript setTimeout() function start being clamped (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_unthrottlednestedtimeoutenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_unthrottlednestedtimeoutenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled","displayName":"Control the URL parameter filter feature (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_usemojovideodecoderforpepperallowed","displayName":"Allow Pepper to use a new decoder for hardware accelerated video decoding. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_usemojovideodecoderforpepperallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_usemojovideodecoderforpepperallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_useragentclienthintsgreaseupdateenabled","displayName":"Control the User-Agent Client Hints GREASE Update feature. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_useragentclienthintsgreaseupdateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_useragentclienthintsgreaseupdateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlaccess","displayName":"Force WebSQL to be enabled. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlnonsecurecontextenabled","displayName":"Force WebSQL in non-secure contexts to be enabled. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlnonsecurecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlnonsecurecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled","displayName":"Enable zstd content-encoding support (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled","displayName":"Allow download deep scanning for Safe Browsing-enabled users (User)","description":"When this policy is enabled or left unset, Google Chrome can send suspicious downloads from Safe Browsing-enabled users to Google to scan for malware, or prompt users to provide a password for encrypted archives.\r\nWhen this policy is disabled, this scanning will not be performed.\r\nThis policy does not impact download content analysis configured by Chrome Enterprise Connectors.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingproxiedrealtimechecksallowed","displayName":"Allow Safe Browsing Proxied Real Time Checks (User)","description":"This controls whether Safe Browsing's standard protection mode is allowed to\r\nsend partial hashes of URLs to Google through a proxy via Oblivious HTTP\r\nin order to determine whether they are safe to visit.\r\n\r\nThe proxy allows browsers to upload partial hashes of URLs to Google\r\nwithout them being linked to the user's IP address. The policy also allows\r\nbrowsers to upload the partial hashes of URLs with higher frequency for\r\nbetter Safe Browsing protection quality.\r\n\r\nThis policy will be ignored if Safe Browsing is disabled or set to enhanced\r\nprotection mode.\r\n\r\nSetting the policy to Enabled or leaving it unset allows the\r\nhigher-protection proxied lookups.\r\n\r\nSetting the policy to Disabled disallows the higher-protection proxied\r\nlookups. Partial hashes of URLs will be uploaded to Google directly with much\r\nlower frequency, which will degrade protection.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingproxiedrealtimechecksallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingproxiedrealtimechecksallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingsurveysenabled","displayName":"Allow Safe Browsing Surveys (User)","description":"When this policy is enabled or left unset, the user may receive surveys related to Safe Browsing.\r\nWhen this policy is disabled, the user will not receive surveys related to Safe Browsing.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingsurveysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingsurveysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_boundsessioncredentialsenabled","displayName":"Bind Google credentials to a device (User)","description":"Controls the state of the Device Bound Session Credentials feature.\r\n\r\nDevice Bound Session Credentials protects Google authentication cookies against cookie theft by regularly providing a cryptographic proof of device possession to Google servers.\r\n\r\nIf this policy is set to false, Device Bound Session Credentials feature will be disabled.\r\n\r\nIf this policy is set to true, Device Bound Session Credentials feature will be enabled.\r\n\r\nIf this policy is unset, Google Chrome will follow the default rollout process for the Device Bound Session Credentials feature, which means that the feature will be gradually rolled out to an increasing number of users.","helpText":"","infoUrls":[],"categoryId":"f00e9baf-9bbf-48e4-aaac-57410730f016","categoryName":"Sign-in settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_boundsessioncredentialsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_boundsessioncredentialsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist","displayName":"Enterprise profile separation secondary domain allowlist (User)","description":"If this policy is unset, account logins will not be required to create a new separate profile.\r\n\r\nIf this policy is set, account logins from the listed domains will not be required to create a new separate profile.\r\n\r\nThis policy can be set to an empty string so that all account logins are required to create a new separate profile.\r\n\r\nExample value:\r\n\r\ndomain.com\r\notherdomain.com","helpText":"","infoUrls":[],"categoryId":"f00e9baf-9bbf-48e4-aaac-57410730f016","categoryName":"Sign-in settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist_profileseparationdomainexceptionlistdesc","displayName":"Enterprise profile separation secondary domain allowlist (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f00e9baf-9bbf-48e4-aaac-57410730f016","categoryName":"Sign-in settings","options":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl","displayName":"WebRTC per URL IP Handling (User)","description":"This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection for each specific URL pattern.\r\n\r\nIt accepts a list of URL patterns and handling type pairs. The URL patterns are checked in order and the first match will configure which handling is used by WebRTC for the domain. When the URL of the current document is not matched against any entry, it uses the configuration set by the policy WebRtcIPHandling.\r\n\r\nFor detailed information on valid input patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nValid handling values:\r\n\r\n* default - WebRTC uses all network interfaces.\r\n\r\n* default_public_and_private_interfaces - WebRTC uses all public and private interfaces.\r\n\r\n* default_public_interface_only - WebRTC uses all public interfaces, but not private ones.\r\n\r\n* disable_non_proxied_udp - WebRTC uses either UDP SOCKS proxying or will fallback to TCP proxying.\r\n\r\nSee RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2) for a detailed description of all the handling values.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebRtcIPHandlingUrl for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.example.com\",\r\n \"handling\": \"default_public_and_private_interfaces\"\r\n },\r\n {\r\n \"url\": \"https://[*.]example.edu\",\r\n \"handling\": \"default_public_interface_only\"\r\n },\r\n {\r\n \"url\": \"*\",\r\n \"handling\": \"disable_non_proxied_udp\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","categoryName":"Web Rtc settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl_webrtciphandlingurl","displayName":"WebRTC per URL IP Handling (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","categoryName":"Web Rtc settings","options":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC (User)","description":"This policy allows controlling post-quantum key agreement for WebRTC.\r\n\r\nIf this policy is set to Enabled, post-quantum key agreement would be offered for\r\nWebRTC.\r\n\r\nIf this policy is set to Disabled, post-quantum key agreement would not be offered\r\nfor WebRTC.\r\n\r\nIf this policy is not set, the value would be set by the default rollout process\r\nfor post-quantum key agreement offered for WebRTC.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing DTLS\r\npeers and networking middleware are expected to ignore the new option and\r\ncontinue selecting previous options.\r\n\r\nHowever, devices that do not correctly implement DTLS may malfunction when\r\noffered the new option. For example, they may disconnect in response to\r\nunrecognized options or the resulting larger messages. Such devices are not\r\npost-quantum-ready and will interfere with an enterprise's post-quantum\r\ntransition. If encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed after some milestones.","helpText":"","infoUrls":[],"categoryId":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","categoryName":"Web Rtc settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_connectivity_disablecrossdeviceresume","displayName":"Disable Cross Device Resume (User)","description":"This policy allows IT admins to turn off CrossDeviceResume feature to continue tasks, such as browsing file, continue using 1P/ 3P apps that require linking between Phone and PC. If you enable this policy setting, the Windows device will not receive any CrossDeviceResume notification. If you disable this policy setting, the Windows device will receive notification to resume activity from linked phone. If you do not configure this policy setting, the default behavior is that the CrossDeviceResume feature is turned 'ON'. Changes to this policy take effect on reboot.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Connectivity#disablecrossdeviceresume"],"categoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","categoryName":"Connectivity","options":[{"id":"user_vendor_msft_policy_config_connectivity_disablecrossdeviceresume_0","displayName":"CrossDeviceResume is Enabled","description":"CrossDeviceResume is Enabled","helpText":null},{"id":"user_vendor_msft_policy_config_connectivity_disablecrossdeviceresume_1","displayName":"CrossDeviceResume is Disabled","description":"CrossDeviceResume is Disabled","helpText":null}]},{"id":"user_vendor_msft_policy_config_credentialsui_disablepasswordreveal","displayName":"Do not display the password reveal button (User)","description":"This policy setting allows you to configure the display of the password reveal button in password entry user experiences.\n\nIf you enable this policy setting, the password reveal button will not be displayed after a user types a password in the password entry text box.\n\nIf you disable or do not configure this policy setting, the password reveal button will be displayed after a user types a password in the password entry text box.\n\nBy default, the password reveal button is displayed after a user types a password in the password entry text box. To display the password, click the password reveal button.\n\nThe policy applies to all Windows components and applications that use the Windows system controls, including Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-credentialsui#credentialsui-disablepasswordreveal"],"categoryId":"58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","categoryName":"Credential User Interface","options":[{"id":"user_vendor_msft_policy_config_credentialsui_disablepasswordreveal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_credentialsui_disablepasswordreveal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_desktop_preventuserredirectionofprofilefolders","displayName":"Prohibit User from manually redirecting Profile Folders (User)","description":"Prevents users from changing the path to their profile folders.\n\nBy default, a user can change the location of their individual profile folders like Documents, Music etc. by typing a new path in the Locations tab of the folder's Properties dialog box.\n\nIf you enable this setting, users are unable to type a new location in the Target box.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-desktop#desktop-preventuserredirectionofprofilefolders"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_desktop_preventuserredirectionofprofilefolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_desktop_preventuserredirectionofprofilefolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_display_configuremultipledisplaymode","displayName":"Configure Multiple Display Mode (User)","description":"Set the default display arrangement as clone, extend, internalOnly, externalOnly or default Windows Settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Display#configuremultipledisplaymode"],"categoryId":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_display_configuremultipledisplaymode_0","displayName":"Default.","description":"Default.","helpText":null},{"id":"user_vendor_msft_policy_config_display_configuremultipledisplaymode_1","displayName":"Internal Only.","description":"Internal Only.","helpText":null},{"id":"user_vendor_msft_policy_config_display_configuremultipledisplaymode_2","displayName":"External Only.","description":"External Only.","helpText":null},{"id":"user_vendor_msft_policy_config_display_configuremultipledisplaymode_3","displayName":"Clone.","description":"Clone.","helpText":null},{"id":"user_vendor_msft_policy_config_display_configuremultipledisplaymode_4","displayName":"Extend.","description":"Extend.","helpText":null}]},{"id":"user_vendor_msft_policy_config_display_enableperprocessdpi","displayName":"Enable Per Process Dpi (User)","description":"Enable or disable Per-Process System DPI for all applications.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Display#enableperprocessdpi"],"categoryId":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_display_enableperprocessdpi_0","displayName":"Disabled","description":"Disable.","helpText":null},{"id":"user_vendor_msft_policy_config_display_enableperprocessdpi_1","displayName":"Enabled","description":"Enable.","helpText":null}]},{"id":"user_vendor_msft_policy_config_display_setclonepreferredresolutionsource","displayName":"Set Clone Preferred Resolution Source (User)","description":"Set the cloned monitor preferred resolution source as internal or external monitor or set to default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Display#setclonepreferredresolutionsource"],"categoryId":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_display_setclonepreferredresolutionsource_0","displayName":"Default.","description":"Default.","helpText":null},{"id":"user_vendor_msft_policy_config_display_setclonepreferredresolutionsource_1","displayName":"Internal.","description":"Internal.","helpText":null},{"id":"user_vendor_msft_policy_config_display_setclonepreferredresolutionsource_2","displayName":"External.","description":"External.","helpText":null}]},{"id":"user_vendor_msft_policy_config_education_allowgraphingcalculator","displayName":"Allow Graphing Calculator (User)","description":"This policy setting allows you to control whether graphing functionality is available in the Windows Calculator app. If you disable this policy setting, graphing functionality will not be accessible in the Windows Calculator app. If you enable or don't configure this policy setting, users will be able to access graphing functionality.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Education#allowgraphingcalculator"],"categoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","categoryName":"Education","options":[{"id":"user_vendor_msft_policy_config_education_allowgraphingcalculator_0","displayName":"Block","description":"Disabled.","helpText":null},{"id":"user_vendor_msft_policy_config_education_allowgraphingcalculator_1","displayName":"Allow","description":"Enabled.","helpText":null}]},{"id":"user_vendor_msft_policy_config_education_defaultprintername","displayName":"Default Printer Name (User)","description":"This policy sets user's default printer","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Education#defaultprintername"],"categoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","categoryName":"Education","options":null},{"id":"user_vendor_msft_policy_config_education_preventaddingnewprinters","displayName":"Prevent Adding New Printers (User)","description":"Boolean that specifies whether or not to prevent user to install new printers","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Education#preventaddingnewprinters"],"categoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","categoryName":"Education","options":[{"id":"user_vendor_msft_policy_config_education_preventaddingnewprinters_0","displayName":"Disabled","description":"Allow user installation.","helpText":null},{"id":"user_vendor_msft_policy_config_education_preventaddingnewprinters_1","displayName":"Enabled","description":"Prevent user installation.","helpText":null}]},{"id":"user_vendor_msft_policy_config_education_printernames","displayName":"Printer Names (User)","description":"This policy provisions per-user network printers","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Education#printernames"],"categoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","categoryName":"Education","options":null},{"id":"user_vendor_msft_policy_config_enterprisecloudprint_cloudprinterdiscoveryendpoint","displayName":"Cloud Printer Discovery End Point (User)","description":"This policy provisions per-user discovery end point to discover cloud printers","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-EnterpriseCloudPrint#cloudprinterdiscoveryendpoint"],"categoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","categoryName":"Enterprise Cloud Print","options":null},{"id":"user_vendor_msft_policy_config_enterprisecloudprint_cloudprintoauthauthority","displayName":"Cloud Print OAuth Authority (User)","description":"Authentication endpoint for acquiring OAuth tokens","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-EnterpriseCloudPrint#cloudprintoauthauthority"],"categoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","categoryName":"Enterprise Cloud Print","options":null},{"id":"user_vendor_msft_policy_config_enterprisecloudprint_cloudprintoauthclientid","displayName":"Cloud Print OAuth Client Id (User)","description":"A GUID identifying the client application authorized to retrieve OAuth tokens from the OAuthAuthority","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-EnterpriseCloudPrint#cloudprintoauthclientid"],"categoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","categoryName":"Enterprise Cloud Print","options":null},{"id":"user_vendor_msft_policy_config_enterprisecloudprint_cloudprintresourceid","displayName":"Cloud Print Resource Id (User)","description":"Resource URI for which access is being requested by the Enterprise Cloud Print client during OAuth authentication","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-EnterpriseCloudPrint#cloudprintresourceid"],"categoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","categoryName":"Enterprise Cloud Print","options":null},{"id":"user_vendor_msft_policy_config_enterprisecloudprint_mopriadiscoveryresourceid","displayName":"Mopria Discovery Resource Id (User)","description":"Resource URI for which access is being requested by the Mopria discovery client during OAuth authentication","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-EnterpriseCloudPrint#mopriadiscoveryresourceid"],"categoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","categoryName":"Enterprise Cloud Print","options":null},{"id":"user_vendor_msft_policy_config_excel16~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_blockinsecureprotocolsinexcelworksheetfunctions","displayName":"Block Insecure Protocols in Excel Worksheet Functions (User)","description":"\n\t\t This policy controls whether the following Excel functions can access the web via insecure protocols: WEBSERVICE, IMPORTCSV, IMPORTTEXT\n\n\t\t If you enable this policy setting, WEBSERVICE, IMPORTCSV, and IMPORTTEXT functions will be blocked from accessing the web via insecure protocols.\n\n\t\t If you disable or don't configure this policy setting, WEBSERVICE, IMPORTCSV, and IMPORTTEXT functions will be allowed to access the web via insecure protocols.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_blockinsecureprotocolsinexcelworksheetfunctions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_blockinsecureprotocolsinexcelworksheetfunctions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v10~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_excelforcesupportforunicodesurrogates","displayName":"Force support for Unicode surrogates in Excel 2021 and Excel 2024 (User)","description":"Warning: this setting alters how your app calculates LEN, MID, SEARCH, FIND and REPLACE and forces files to Compatibility Version 2. When these workbooks are shared, users may see different calculation results. This setting only applies to non-subscription Excel 2021 and Excel 2024.\r\n \r\nIf you enable this policy setting, when any workbook is opened in non-subscription Excel 2021 or Excel 2024, it will automatically be set to Compatibility Version 2. This will cause LEN, MID, SEARCH, FIND and REPLACE functions to calculate differently in those workbooks.\r\n \r\nIf you disable or do not configure this policy setting, the Compatibility Version will not be automatically set when a file is opened in any version of non-subscription Excel 2021 and Excel 2024 (this setting never affects other versions).","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v10~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_excelforcesupportforunicodesurrogates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v10~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_excelforcesupportforunicodesurrogates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Enter error ID for Value Name and custom button text for Value","helpText":"","infoUrls":[],"categoryId":"5b832259-c30b-43bb-b249-9d3ea4d5b028","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize87","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5b832259-c30b-43bb-b249-9d3ea4d5b028","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize87_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"5b832259-c30b-43bb-b249-9d3ea4d5b028","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize87_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5b832259-c30b-43bb-b249-9d3ea4d5b028","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_datarecovery_l_donotshowdataextractionoptionswhenopeningcorruptworkbooks","displayName":"Do not show data extraction options when opening corrupt workbooks (User)","description":"This policy setting controls whether Excel presents users with a list of data extraction options before beginning an Open and Repair operation when users choose to open a corrupt workbook in repair or extract mode.\r\n \r\nIf you enable this policy setting, Excel opens the file using the Safe Load process and does not prompt users to choose between repairing or extracting data.\r\n \r\nIf you disable or do not configure this policy setting, Excel prompts the user to select either to repair or to extract data, and to select either to convert to values or to recover formulas.","helpText":"","infoUrls":[],"categoryId":"28831364-ca54-4f31-acca-1aa0c7a7d3d2","categoryName":"Data Recovery","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_datarecovery_l_donotshowdataextractionoptionswhenopeningcorruptworkbooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_datarecovery_l_donotshowdataextractionoptionswhenopeningcorruptworkbooks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems165","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"3b7e16e7-171f-4169-8904-c8483b06700d","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems165_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems165_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems165_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b7e16e7-171f-4169-8904-c8483b06700d","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys166","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"3b7e16e7-171f-4169-8904-c8483b06700d","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys166_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys166_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys166_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b7e16e7-171f-4169-8904-c8483b06700d","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable specific command bar buttons and menu items in the specified applications.\r\n \r\n If you enable this policy setting you can disable specific command bar buttons and menu items in the user interface for the selected application. The predefined list of command bar buttons and menu items you can disable becomes available to you when you enable this policy setting.\r\n \r\n If you disable or do not configure this policy setting, the predefined list of command bar buttons and menu items are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodemacros","displayName":"Developer tab | Code | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodemacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodemacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodemacrosecurity","displayName":"Developer tab | Code | Macro Security (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodemacrosecurity_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodemacrosecurity_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercoderecordmacro","displayName":"Developer tab | Code | Record Macro (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercoderecordmacro_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercoderecordmacro_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodevisualbasic","displayName":"Developer tab | Code | Visual Basic (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodevisualbasic_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_developercodevisualbasic_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_insertlinkshyperlink","displayName":"Insert tab | Links | Hyperlink (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_insertlinkshyperlink_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_insertlinkshyperlink_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizationmailrecipient","displayName":"File tab | Share | Email (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizationmailrecipient_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizationmailrecipient_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizedocumentlocation","displayName":"File tab | Options | Customize Ribbon | All Commands | Document Location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizedocumentlocation_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizedocumentlocation_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonxceloptionscustomizationcombinedpreviewwebpagepreview","displayName":"File tab | Options | Customize Ribbon | All Commands | Web Page Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonxceloptionscustomizationcombinedpreviewwebpagepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonxceloptionscustomizationcombinedpreviewwebpagepreview_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectsharing","displayName":"Review tab | Changes | Protect and Share Workbook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectsharing_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectsharing_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectsheet","displayName":"Review tab | Changes | Protect Sheet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectsheet_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectsheet_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectworkbook","displayName":"Review tab | Changes | Protect Workbook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectworkbook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectworkbook_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_viewmacrosmacros","displayName":"View tab | Macros | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_viewmacrosmacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_viewmacrosmacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable specific shortcut key combinations in the specified applications.\r\n \r\n If you enable this policy setting you can disable specific shortcut keys for the selected application. The predefined list of shortcut keys you can disable becomes available to you when you enable this policy setting.\r\n \r\n If you disable or do not configure this policy setting, the predefined list of shortcut keys are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros","displayName":"Alt+F8 (Developer | Code | Macros) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altlvdevelopercodevisualbasic","displayName":"Alt+F11 (Developer | Code | Visual Basic) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altlvdevelopercodevisualbasic_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altlvdevelopercodevisualbasic_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlfhomeeditingfind","displayName":"Ctrl+F (Home | Editing | Find & Select | Find) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlfhomeeditingfind_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlfhomeeditingfind_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinsertlinkshyperlinks","displayName":"Ctrl+K (Insert | Links | Hyperlink) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinsertlinkshyperlinks_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinsertlinkshyperlinks_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alertbeforeoverwritingcells","displayName":"Alert before overwriting cells (User)","description":"This policy setting sets the \"Alert before overwriting cells\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will give a warning if cells are about to be overwritten. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will suppress the warning that cells are about to be overwritten.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alertbeforeoverwritingcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alertbeforeoverwritingcells_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation","displayName":"Alternate startup file location (User)","description":"This policy setting allows you to specify the folder where files will be opened by Excel at startup.\r\n\r\nIf you enable this policy setting, you may specify the folder where files will be opened by Excel at startup. Files will be opened from this folder in addition to the XLSTART folder in the Microsoft Office installation directory (default C:\\Program Files\\Microsoft Office\\Office14\\XLSTART).\r\n\r\nIf you disable or do not configure this policy setting, files will only be opened from the XLSTART folder.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation_l_alternatestartupfilelocation86","displayName":"Alternate startup file location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_asktoupdateautomaticlinks","displayName":"Ask to update automatic links (User)","description":"This policy setting controls whether Excel prompts users to update automatic links, or whether the updates occur in the background with no prompt.\r\n \r\nIf you enable or do not configure this policy setting, Excel will prompt users to update automatic links. In addition, the \"Ask to update automatic links\" user interface option under File tab | Advanced | General is selected.\r\n \r\nIf you disable this policy setting, Excel updates automatic links without prompting or informing users, which could compromise the integrity of some of the information in the workbook.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_asktoupdateautomaticlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_asktoupdateautomaticlinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyflashfill","displayName":"Automatically Flash Fill (User)","description":"This policy setting controls the \"Automatically Flash Fill\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will enable automatic Flash Fill. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will turn off the Automatic Flash Fill feature.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyflashfill_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyflashfill_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyinsertadecimalpoint","displayName":"Automatically insert a decimal point (User)","description":"This policy setting allows you to configure the \"Automatically insert a decimal point\" option.\r\n\r\nIf you enable this policy setting, the \"Automatically insert a decimal point\" option will be checked and the Places option is set to 2.\r\n\r\nIf you disable or do not configure this policy setting, the \"Automatically insert a decimal point\" option will not be checked.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyinsertadecimalpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyinsertadecimalpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_chartreftrackingenabled","displayName":"Allow formatting and labels to track data points (User)","description":"This policy setting governs how custom formatting and data labels react to data changes in a chart.\r\n\r\nIf you enable or do not configure this policy setting, when the user creates a new workbook, custom formatting and data labels follow data points as they move or change in any chart in the workbook.\r\n\r\nIf you disable this policy setting, custom formatting and data labels do not follow data points, but instead follow data point indices.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_chartreftrackingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_chartreftrackingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments","displayName":"Comments (User)","description":"Determines how comments are displayed on the worksheet.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_l_comments85","displayName":"Comments (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_l_comments85_0","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_l_comments85_1","displayName":"Comment indicator only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_l_comments85_2","displayName":"Comment & indicator","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement","displayName":"Cursor movement (User)","description":"Determines how the insertion point moves through bi-directional text. Possible values are Logical or Visual and the default is Logical.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_l_cursormovement82","displayName":"Cursor movement (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_l_cursormovement82_0","displayName":"Logical","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_l_cursormovement82_1","displayName":"Visual","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cutandcopyobjectswithcells","displayName":"Cut and copy objects with cells (User)","description":"This policy setting sets the \"Cut, copy, and sort inserted objects with their parent cells\" option found under File tab | Options | Advanced | Cut, copy, and paste Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will cut, copy, and sort inserted objects with their parent cells.\r\n\r\nIf you disable this policy setting, Excel will not cut and copy inserted objects with their parent cells.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cutandcopyobjectswithcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cutandcopyobjectswithcells_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection","displayName":"Default sheet direction (User)","description":"This setting controls the default sheet direction, which is either \"Left to Right\" or \"Right to Left\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_l_defaultdirection81","displayName":"Default sheet direction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_l_defaultdirection81_1","displayName":"Right-to-Left","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_l_defaultdirection81_0","displayName":"Left-to-Right","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_editdirectlyincell","displayName":"Edit directly in cell (User)","description":"This policy setting sets the \"Edit directly in cell\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will allow editing directly in the cell This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will not allow editing to be done directly in the cell.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_editdirectlyincell_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_editdirectlyincell_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enableautocompleteforcellvalues","displayName":"Enable AutoComplete for cell values (User)","description":"This policy setting sets the \"Enable AutoComplete for cell values\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will allow AutoComplete for cell values. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will turn off the AutoComplete feature.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enableautocompleteforcellvalues_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enableautocompleteforcellvalues_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enableautomaticpercententry","displayName":"Enable automatic percent entry (User)","description":"Enabling this policy selects the Advanced (Editing options) user option to \"Enable automatic percent entry\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enableautomaticpercententry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enableautomaticpercententry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enablefillhandleandcelldraganddrop","displayName":"Enable fill handle and cell drag-and-drop (User)","description":"This policy setting sets the \"Enable fill handle and cell drag-and-drop\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will enable the fill handle and allow drag-and-drop. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will disable the fill handle and drag-and-drop will not be allowed.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enablefillhandleandcelldraganddrop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enablefillhandleandcelldraganddrop_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_extenddatarangeformatsandformulas","displayName":"Extend data range formats and formulas (User)","description":"This policy setting sets the \"Extend data range formats and formulas\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will allow the user to automatically format new items added to the end of a list to match the format of the rest of the list. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will not automatically format new items added to the end of a list.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_extenddatarangeformatsandformulas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_extenddatarangeformatsandformulas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_functiontooltips","displayName":"Function tooltips (User)","description":"Enabling this setting selects the Advanced (Display) user option to \"Show function ScreenTips\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_functiontooltips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_functiontooltips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_ignoreotherapplications","displayName":"Ignore other applications (User)","description":"This policy setting controls whether Excel can exchange data with other applications that use Dynamic Data Exchange (DDE).\r\n \r\n If you enable this policy setting, Excel does not allow the exchange of data with other applications that use DDE. In addition, the \"Ignore other applications that use Dynamic Data Exchange (DDE)\" user interface option under Excel Options | General is selected and users cannot change it. Enabling this policy setting can cause disruptions for users who rely on the DDE functionality in Excel to update information in workbooks. These users will have to use some other method to update information provided by other applications.\r\n \r\n If you disable or do not configure this policy setting, Excel can use the Dynamic Data Exchange (DDE) protocol to exchange messages and data with other applications. For example, a cell in an Excel workbook can be dynamically linked to a value provided by another application, such as weather or stock price information. When the value provided by the other application changes, Excel can automatically update the value in the workbook. Note: users can change this behavior by selecting the \"Ignore other applications that use Dynamic Data Exchange (DDE)\" user interface option under Excel Options | General.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_ignoreotherapplications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_ignoreotherapplications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_microsoftexcelmenuorhelpkey","displayName":"Microsoft Excel menu or Help key (User)","description":"This policy setting allows you to set the ASCII value for the key of choice (e.g. '/'=47).","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_microsoftexcelmenuorhelpkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_microsoftexcelmenuorhelpkey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_microsoftexcelmenuorhelpkey_l_helpkey","displayName":"Enter ASCII value (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenter","displayName":"Move selection after Enter (User)","description":"Enabling this policy selects the Advanced (Editing Options) user option to \"After pressing Enter, move selection\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection","displayName":"Move selection after Enter direction (User)","description":"Specifies the direction that the selection is moved after the Enter key is pressed.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_l_moveselectionafterenterdirection84","displayName":"Move selection after Enter direction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_l_moveselectionafterenterdirection84_0","displayName":"Down","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_l_moveselectionafterenterdirection84_1","displayName":"Right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_l_moveselectionafterenterdirection84_2","displayName":"Up","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_l_moveselectionafterenterdirection84_3","displayName":"Left","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_recentlyusedfilelist","displayName":"Number of workbooks in the Recent Workbooks list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Workbooks list that appears when users click Open on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Workbooks list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Workbooks list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_recentlyusedfilelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_recentlyusedfilelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_recentlyusedfilelist_l_entriesonrecentlyusedfilelist","displayName":"Entries on recently used file list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showalertifnotdefault","displayName":"Show Alert if Excel is not the default for its associated file types (User)","description":"This policy setting controls the \"Tell me if Microsoft Excel isn't the default progam for viewing and editing spreadsheets\" option found under File tab | Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will show an alert if it isn't the default progam for viewing and editing spreadsheets. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will turn off the alert.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showalertifnotdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showalertifnotdefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showcontrolcharacters","displayName":"Show control characters (User)","description":"Enabling this policy selects the user option to \"Show control characters\". This option appears in the Advanced category when certain languages have been enabled.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showcontrolcharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showcontrolcharacters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinfullview","displayName":"Show Formula bar in Full View (User)","description":"Checked: Displays the Formula bar when the Full Screen command in the View menu is set. | Unchecked: Does not dispaly the Formula bar when the Full Screen command in the View menu is set.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinfullview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinfullview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinnormalview","displayName":"Show Formula bar in Normal View (User)","description":"Enabling this setting selects the Advanced (Display) user option to \"Show formula bar\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinnormalview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinnormalview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showinsertoptionsbuttons","displayName":"Show Insert Options buttons (User)","description":"This policy setting sets the \"Show Insert Options buttons\" option found under File tab | Options | Advanced | Cut, copy, and paste options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will show the Insert Options button after inserting cells, rows, or columns that contain formatting. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will not display the Insert Options buttons on insert.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showinsertoptionsbuttons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showinsertoptionsbuttons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_shownames","displayName":"Show names (User)","description":"Enabling this setting selects the Advanced (Display) user option to \"Show chart element names on hover\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_shownames_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_shownames_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showpasteoptionsbuttonwhencontentispasted","displayName":"Show Paste Options button when content is pasted (User)","description":"This policy setting sets the \"Show Paste Options button when content is pasted\" option found under File tab | Options | Advanced | Cut, copy, and paste options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will show the Paste Options button after inserting cells, rows, or columns that contain formatting. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will not display the Paste Options buttons on paste.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showpasteoptionsbuttonwhencontentispasted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showpasteoptionsbuttonwhencontentispasted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showvalues","displayName":"Show values (User)","description":"Enabling this setting selects the Advanced (Display) user option to \"Show data point values on hover\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showvalues_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showvalues_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_transitionnavigationkeys","displayName":"Transition navigation keys (User)","description":"Enabling this policy checks the Advanced (Lotus compatibility) user option named \"Transition navigation keys\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_transitionnavigationkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_transitionnavigationkeys_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_zoomonrollwithintellimouse","displayName":"Zoom on roll with IntelliMouse (User)","description":"This policy setting sets the \"Zoom on roll with IntelliMouse'\" option found under File tab | Options | Advanced | Editing options\r\n\r\nIf you enable this policy setting, rolling the mouse wheel will change the zoom level of the worksheet.\r\n\r\nIf you disable or do not configure this policy setting, rolling the mouse wheel will scroll the worksheet. This is the default behavior.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_zoomonrollwithintellimouse_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_zoomonrollwithintellimouse_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced~l_weboptions~l_general_l_loadpicturesfromwebpagesnotcreatedinexcel","displayName":"Load pictures from Web pages not created in Excel (User)","description":"This policy setting controls whether Excel loads graphics when opening Web pages that were not created in Excel. It configures the \"Load pictures from Web pages not created in Excel\" option under the File tab | Options | Advanced | General | Web Options... | General tab.\r\n \r\nIf you enable or do not configure this policy setting, Excel loads any graphics that are included in the pages, regardless of whether they were originally created in Excel.\r\n \r\nIf you disable this policy setting, Excel will not load any pictures from Web pages that were not created in Excel.","helpText":"","infoUrls":[],"categoryId":"b90fb0dc-b8c1-4fc3-b9f9-dfbda4b3f03d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced~l_weboptions~l_general_l_loadpicturesfromwebpagesnotcreatedinexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced~l_weboptions~l_general_l_loadpicturesfromwebpagesnotcreatedinexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_formulas_l_r1c1referencestyle","displayName":"R1C1 reference style (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"9215e382-4e7b-4554-8c80-80277136b544","categoryName":"Formulas","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_formulas_l_r1c1referencestyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_formulas_l_r1c1referencestyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"d1e2bb0d-6c0e-4f40-9f2e-52055edc14b5","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_allowquickanalysis","displayName":"Show Quick Analysis options on selection (User)","description":"This policy setting controls the \"Show Quick Analysis options on selection\" option found under File tab | Options | General | User Interface Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will show Quick Analysis options when data is selected. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will not show these options on selection.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_allowquickanalysis_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_allowquickanalysis_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_allowselectionfloaties","displayName":"Show Mini Toolbar on selection (User)","description":"Disabling this policy setting will result in Mini Toolbar not being displayed on text selection. By default, Mini Toolbar on selection is enabled and its visibility can be changed via a setting in the Excel Options dialog box.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_allowselectionfloaties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_allowselectionfloaties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_defaultsheets","displayName":"Default Sheets (User)","description":"Specifies the initial number of worksheets to create in a new workbook.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_defaultsheets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_defaultsheets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_defaultsheets_l_sheetsinnewworkbook","displayName":"Sheets in new workbook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_disablelivepreview","displayName":"Enable Live Preview (User)","description":"Shows or hides the Live Previews that appear when using Galleries that support previews. Live Preview shows how a command would be applied without actually applying it to the document.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_disablelivepreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_disablelivepreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_font","displayName":"Font (User)","description":"Specifies the \"Standard font\" font name and size.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_font_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_font_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_font_l_namesize","displayName":"Name, Size (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_windowsintaskbar","displayName":"Show all windows in the Taskbar (User)","description":"When multiple workbooks are open simultaneously, this determines whether the user will see a single entry for Excel in the taskbar or a separate entry in the taskbar for each open workbook.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_windowsintaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_windowsintaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_includenewrowsandcolumnsinlist","displayName":"Include new rows and columns in table (User)","description":"When working in cells adjacent to a table (known as a \"list\" in previous versions of Excel), enabling this setting causes the adjacent row or column to become part of the table.","helpText":"","infoUrls":[],"categoryId":"67eb1dab-7805-41bb-af5a-798dc7e29f23","categoryName":"Autocorrect Options","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_includenewrowsandcolumnsinlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_includenewrowsandcolumnsinlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_internetandnetworkpathsashyperlinks","displayName":"Internet and network paths as hyperlinks (User)","description":"This policy setting determines whether Excel automatically creates hyperlinks when users enter URL or UNC path information.\r\n \r\nIf you enable this policy setting, when users type a string of characters that Excel recognizes as a Uniform Resource Locator (URL) or Uniform Naming Convention (UNC) path to a resource on the Internet or a local network, Excel will automatically transform it into a hyperlink. Clicking the hyperlink opens it in the configured default Web browser or the appropriate application.\r\n \r\nIf you disable this policy setting, Excel will not transform URLs and UNC paths to hyperlinks.\r\n \r\nIf you do not configure this policy setting, Excel will automatically transform URLs and UNC paths to hyperlinks and users can change the behavior by selecting or deselecting the \"Internet and network paths as hyperlinks\" check box under File tab | Help | Options | Proofing | AutoCorrect Options... | AutoFormat as You Type tab | Replace as you type.","helpText":"","infoUrls":[],"categoryId":"67eb1dab-7805-41bb-af5a-798dc7e29f23","categoryName":"Autocorrect Options","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_internetandnetworkpathsashyperlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_internetandnetworkpathsashyperlinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoverdelay","displayName":"AutoRecover delay (User)","description":"This policy specifies how long (in seconds) the user must be idle before AutoRecover information will be saved.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoverdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoverdelay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoverdelay_l_secondsofidletimebeforeautorecoverstarts","displayName":"Seconds of idle time before AutoRecover starts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoversavelocation","displayName":"AutoRecover save location (User)","description":"This policy setting allows you to specify the location where AutoRecover information is to be saved. Directing the location to a network drive may allow you to back up these files along with other network files.\r\n\r\nIf you enable this policy setting, you may specify the location where AutoRecover information is to be saved.\r\n\r\nIf you disable or you do not configure this policy setting, the default location is %userprofile%\\Application Data\\Microsoft\\Excel.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoversavelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoversavelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecoversavelocation_l_autorecoversavelocation2","displayName":"AutoRecover save location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecovertime","displayName":"AutoRecover time (User)","description":"This policy determines the interval (in minutes) at which AutoRecover information will be saved.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecovertime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecovertime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_autorecovertime_l_saveautorecoverinfoevery","displayName":"Save AutoRecover info every (minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_defaultfilelocation","displayName":"Default file location (User)","description":"This policy setting allows you to specify the folder that Excel uses when opening or saving a file. This setting can be found under File tab | Options | Save | Save workbook Options.\r\n\r\nIf you enable this policy setting, you may specify this folder.\r\n\r\nIf you disable or do not configure this policy setting, the default folder will be used.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_defaultfilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_defaultfilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_defaultfilelocation_l_defaultfilelocation0","displayName":"Default file location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_disableautorepublish","displayName":"Disable AutoRepublish (User)","description":"This policy setting allows administrators to disable the AutoRepublish feature in Excel. If users choose to publish Excel data to a static Web page and enable the AutoRepublish feature, Excel saves a copy of the data to the Web page every time the user saves the workbook. By default, a message dialog displays every time the user saves a published workbook when AutoRepublish is enabled. From this dialog, the user can disable AutoRepublish temporarily or permanently, or select \"Do not show this message again\" to prevent the dialog from appearing after every save. If the user selects \"Do not show this message again\", Excel will continue to automatically republish the data after every save without informing the user.\r\n \r\n If you enable this policy setting, the AutoRepublish feature is turned off and Excel users will need to publish data to the Web manually.\r\n \r\n If you disable or do not configure this policy setting, users can enable the AutoRepublish feature to automatically republish workbooks saved as type Web Page.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_disableautorepublish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_disableautorepublish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_donotshowautorepublishwarningalert","displayName":"Do not show AutoRepublish warning alert (User)","description":"This policy setting controls whether Excel displays an alert before republishing a workbook to the World Wide Web.\r\n\r\nIf you enable this policy setting, no warning appears when the user saves a published workbook when AutoRepublish is enabled.\r\n \r\nIf you disable or do not configure this policy setting, a message dialog appears every time the user saves a published workbook when AutoRepublish is enabled. From this dialog, the user can disable AutoRepublish temporarily or permanently, or select \"Do not show this message again\" to prevent the dialog from appearing after every save. If the user selects \"Do not show this message again\", Excel will continue to automatically republish the data after every save without informing the user.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_donotshowautorepublishwarningalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_donotshowautorepublishwarningalert_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_keeplastautosavedversions","displayName":"Keep the last AutoSaved versions of files for the next session (User)","description":"This policy setting determines whether Excel keeps the last AutoSaved version of a file if a user closes a file without saving it. (Note: AutoSave applies only when AutoRecover is enabled.)\r\n\r\nIf you enable or do not configure this policy setting, Excel keeps the last AutoSaved version of the file and makes it available to the user the next time the file is opened if the user closes a file without saving it.\r\n\r\nIf you disable this policy setting, Excel does not keep the last AutoSaved version of the file if the user closes a file without saving it.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_keeplastautosavedversions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_keeplastautosavedversions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_promptforworkbookproperties","displayName":"Prompt for workbook properties (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_promptforworkbookproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_promptforworkbookproperties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveautorecoverinfo","displayName":"Save AutoRecover info (User)","description":"Enabling this policy selects the user option to \"Save AutoRecover information every N minutes\".","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveautorecoverinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveautorecoverinfo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas","displayName":"Default file format (User)","description":"This policy setting controls the default file format for saving workbooks in Excel.\r\n\r\nIf you enable this policy setting, you can set the default file format for Excel from among the following options:\r\n\r\n- Excel Workbook (.xlsx).This option is the default configuration in Excel 2016.\r\n- Excel Macro-Enabled Workbook (.xlsm)\r\n- Excel Binary Workbook (.xlsb)\r\n- Web Page (.htm; .html)\r\n- Excel 97-2003 Workbook (.xls)\r\n- Excel 5.0/95 Workbook (.xls)\r\n- OpenDocument Spreadsheet (*.ods)\r\n\r\nUsers can choose to save workbooks in a different file format than the default.\r\n\r\nIf you disable or you do not configure this policy setting, Excel saves new workbooks in the Office Open XML format with an .xlsx extension.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1","displayName":"Save Excel files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_51","displayName":"Excel Workbook (*.xlsx)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_52","displayName":"Excel Macro-Enabled Workbook (*.xlsm)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_50","displayName":"Excel Binary Workbook (*.xlsb)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_44","displayName":"Web Page (*.htm; *.html)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_56","displayName":"Excel 97-2003 Workbook (*.xls)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_39","displayName":"Excel 5.0/95 Workbook (*.xls)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_60","displayName":"OpenDocument Spreadsheet (*.ods)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_turnofffileformatcompatiblitydialogforods","displayName":"Suppress file format compatibility dialog box for OpenDocument Spreadsheet format (User)","description":"This policy setting allows you to configure the file format compatibility dialog box when saving a file as an OpenDocument Spreadsheet file in Microsoft Excel.\r\n\r\nIf you enable this policy setting, the file format compatibility dialog is not displayed whenever you save as an OpenDocument Spreadsheet file in Excel.\r\n\r\nIf you disable or do not configure this policy setting, the file format compatibility dialog is displayed when you save as an OpenDocument Spreadsheet file in Excel.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_turnofffileformatcompatiblitydialogforods_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_turnofffileformatcompatiblitydialogforods_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel","displayName":"Scan encrypted macros in Excel Open XML workbooks (User)","description":"This policy setting controls whether encrypted macros in Open XML workbooks be are required to be scanned with anti-virus software before being opened.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n- Scan encrypted macros: encrypted macros are disabled unless anti-virus software is installed. Encrypted macros are scanned by your anti-virus software when you attempt to open an encrypted workbook that contains macros.\r\n- Scan if anti-virus software available: if anti-virus software is installed, scan the encrypted macros first before allowing them to load. If anti-virus software is not available, allow encrypted macros to load.\r\n- Load macros without scanning: do not check for anti-virus software and allow macros to be loaded in an encrypted file.\r\n\r\nIf you disable or do not configure this policy setting, the behavior will be similar to the \"Scan encrypted macros\" option.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid_0","displayName":"Scan encrypted macros (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid_1","displayName":"Scan if anti-virus software available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid_2","displayName":"Load macros without scanning","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch","displayName":"Force file extension to match file type (User)","description":"This policy setting controls how Excel loads file types that do not match their extension. Excel can load files with extensions that do not match the files' type. For example, if a comma-separated values (CSV) file named example.csv is renamed example.xls (or any other file extension supported by Excel 2003 and earlier only), Excel can properly load it as a CSV file.\r\n\r\nIf you enable this policy setting, you can choose from three options for working with files that have non-matching extensions:\r\n\r\n- Allow different - Excel opens the files properly without warning users that the files have non-matching extensions. If users subsequently edit and save the files, Excel preserves both the true, underlying file format and the incorrect file extension.\r\n\r\n- Allow different, but warn - Excel opens the files properly, but warns users about the file type mismatch. This option is the default configuration in Excel.\r\n\r\n- Always match file type - Excel does not open any files that have non-matching extensions.\r\n\r\nIf you disable or do not configure this policy setting, if users attempt to open files with the wrong extension, Excel opens the file and displays a warning that the file type is not what Excel expected.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_l_empty_0","displayName":"Allow different","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_l_empty_1","displayName":"Allow different, but warn","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_l_empty_2","displayName":"Always match file type","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches","displayName":"Perform file validation on pivot caches (User)","description":"This policy key configures whether or not pivot caches should go through file validation and get scanned for security problems when documents in Excel 97-2003 format are opened.\r\n\r\nIf you enable this policy setting, you may select one of these options:\r\n\r\n- No file validation: Never perform file validation on pivot caches for all Excel files (not recommended).\r\n- Web and email sources: Perform file validation on pivot caches for documents that come from the web and email, in addition to all documents that trigger pivot caches on load (default).\r\n- Always perform validation: Always perform file validation on pivot caches for all Excel files.\r\n\r\nThis setting can be overridden by the Object Model property Application.FileValidationPivot.\r\n\r\nIf you disable or do not configure this policy setting, the \"Web and email source\" setting will apply.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches_l_performfilevalidationonpivotcachesdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches_l_performfilevalidationonpivotcachesdropid_0","displayName":"No file validation","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches_l_performfilevalidationonpivotcachesdropid_1","displayName":"Web and email sources","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_performfilevalidationonpivotcaches_l_performfilevalidationonpivotcachesdropid_2","displayName":"Always perform validation","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_turnofffilevalidation","displayName":"Turn off file validation (User)","description":"This policy setting allows you turn off the file validation feature.\r\n\r\nIf you enable this policy setting, file validation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, file validation will be turned on. Office Binary Documents (97-2003) are checked to see if they conform against the file format schema before they are opened.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_turnofffilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_turnofffilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel","displayName":"WEBSERVICE Function Notification Settings (User)","description":"This policy setting controls how Excel will warn users when WEBSERVICE functions are present.\r\n\r\nIf you enable this policy setting, you can choose from three options for determining how the specified applications will warn the user about WEBSERVICE functions:\r\n\r\n- Disable all with notification: The application displays the Trust Bar for all WEBSERVICE functions. This option enforces the default configuration in Office.\r\n- Disable all without notification: The application disables all WEBSERVICE functions and does not notify users.\r\n- Enable all WEBSERVICE functions (not recommended): The application enables all WEBSERVICE functions and does not notify users. This option can significantly reduce security by allowing information disclosure to third party web services.\r\n\r\nIf you disable this policy setting, the “Disable all with notification” will be the default setting.\r\nIf you do not configure this policy setting, when users open workbooks that contain WEBSERVICE functions, Excel will open the files with the WEBSERVICE functions disabled and display the Trust Bar with a warning that WEBSERVICE functions are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content,\" then the document is added as a trusted document.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel_l_webcontentwarninglevelvalue","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel_l_webcontentwarninglevelvalue_0","displayName":"Enable all WEBSERVICE functions (not recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel_l_webcontentwarninglevelvalue_1","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_webcontentwarninglevel_l_webcontentwarninglevelvalue_2","displayName":"Disable all without notification","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setparametersforcngcontext","displayName":"Set parameters for CNG context (User)","description":"This policy setting allows you to specify the encryption parameters that should be used for the CNG context. \r\n\r\nIf you enable this policy setting, the parameters specified will be passed to the CNG context.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG values will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setparametersforcngcontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setparametersforcngcontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm","displayName":"Specify CNG random number generator algorithm (User)","description":"This policy setting allows you to configure the CNG random number generator to use.\r\n\r\nIf you enable this policy setting, the random number generator specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default random number generator will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_l_specifycngrandomnumbergeneratoralgorithmid","displayName":"Random number generator: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngsaltlength","displayName":"Specify CNG salt length (User)","description":"This policy setting allows you to specific the number of bytes of salt that should be used.\r\n\r\nIf you enable this policy setting, the bytes specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default length or 16 will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngsaltlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngsaltlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility","displayName":"Specify encryption compatibility (User)","description":"This policy setting allows you to specify the encrypted database compatibility.\r\n\r\nIf you enable this policy setting, the compatibility format specified will be applied during encryption for new files\r\n- Use legacy format\r\n- Use next generation format\r\n- All files save with next generation format\r\n\r\nIf you disable or do not configure this policy setting, the default setting, \"Use next generation format,\" will be applied.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_0","displayName":"Use legacy format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_1","displayName":"Use next generation format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_2","displayName":"All files save with next generation format","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_usenewkeyonpasswordchange","displayName":"Use new key on password change (User)","description":"This policy setting allows you to specify if a new encryption key is used when the password is changed.\r\n\r\nIf you enable or do not configure this policy setting, a new intermediate key is generated when the password is changed. This causes any extra key encryptors to be removed when the file is saved.\r\n\r\nIf you disable this policy setting, a new intermediate key is not generated when the password is changed.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_usenewkeyonpasswordchange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_usenewkeyonpasswordchange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users, except if application add-ins are required to be signed by Trusted Publishers.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User) (Deprecated)","description":"This policy setting controls whether the specified Office 2016 applications notify users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the ''Require that application add-ins are signed by Trusted Publisher'' policy setting, which prevents users from changing this policy setting. \r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if an application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the ''Add-ins'' category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User)","description":"This policy setting controls whether the specified Office 2016 applications notify users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the ''Require that application add-ins are signed by Trusted Publisher'' policy setting, which prevents users from changing this policy setting. \r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if an application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the ''Add-ins'' category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for the specified Office 2016 applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, Office 2016 applications do not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.\r\n","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve","displayName":"Set maximum number of trust records to preserve (User)","description":"This policy setting allows you to specify the maximum number of trust records to preserve when the purge task detects that this application has trusted more than the number of trusted documents set by the \"Set maximum number of trusted documents\" policy setting.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of trust records to preserve, with an upper limit of 20000. Due to performance reasons, it is not recommended to set it to the upper limit.\r\n\r\nIf you disable or you do not configure this policy setting, the default value for of 400 is used.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_l_setmaximumnumberoftrustrecordstopreservespinid","displayName":"Maximum to preserve: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_storemacroinpersonalmacroworkbookbydefault","displayName":"Store macro in Personal Macro Workbook by default (User)","description":"This policy setting controls the default location for storing macros in Excel.\r\n \r\n If this policy setting is enabled, Excel stores macros in users' personal macro workbook.\r\n \r\n If you disable or do not configure this policy setting, Excel stores macros in the active workbook from which they are created.\r\n \r\n Note: In the user interface (UI), the \"Store macro in\" drop down list box in the Record Macro dialog box (Macros | Record Macro) allows users to choose whether to store the new macro in the current workbook, a new workbook, or their personal macro workbook (Personal.xlsb), a hidden workbook that opens every time Excel starts.\r\n \r\n By default, Excel displays the \"Store macro in\" box with \"This Workbook\" already selected in the drop-down list. If a user saves a macro in the active workbook and then distributes the workbook to others, the macro is distributed along with the workbook. If you enable this policy setting, Excel displays the \"Store macro in\" box with \"Personal Macro Workbook\" already selected. Users can still select one of the other two options in the drop-down menu.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_storemacroinpersonalmacroworkbookbydefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_storemacroinpersonalmacroworkbookbydefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject","displayName":"Trust access to Visual Basic Project (User)","description":"This policy setting controls whether automation clients such as Microsoft Visual Studio 2005 Tools for Microsoft Office (VSTO) can access the Visual Basic for Applications project system in the specified applications. VSTO projects require access to the Visual Basic for Applications project system in Excel, PowerPoint, and Word, even though the projects do not use Visual Basic for Applications. Design-time support of controls in both Visual Basic and C# projects depends on the Visual Basic for Applications project system in Word and Excel.\r\n\r\nIf you enable this policy setting, VSTO and other automation clients can access the Visual Basic for Applications project system in the specified applications. Users will not be able to change this behavior through the \"Trust access to the VBA project object model\" user interface option under the Macro Settings section of the Trust Center.\r\n\r\nIf you disable this policy setting, VSTO does not have programmatic access to VBA projects. In addition, the \"Trust access to the VBA project object model\" check box is cleared and users cannot change it. Note: Disabling this policy setting prevents VSTO projects from interacting properly with the VBA project system in the selected application.\r\n\r\nIf you do not configure this policy setting, automation clients do not have programmatic access to VBA projects. Users can enable this by selecting the \"Trust access to the VBA project object model\" in the \"Macro Settings\" section of the Trust Center. However, doing so allows macros in any documents the user opens to access the core Visual Basic objects, methods, and properties, which represents a potential security hazard.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_turnofftrusteddocuments","displayName":"Turn off trusted documents (User)","description":"This policy setting allows you to turn off the trusted documents feature. The trusted documents feature allows users to always enable active content in documents such as macros, ActiveX controls, data connections, etc. so that they are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.\r\n\r\nIf you enable this policy setting, you will turn off the trusted documents feature. Users will receive a security prompt every time a document containing active content is opened.\r\n\r\nIf you disable or do not configure this policy setting, documents will be trusted when users enable content for a document, and users will not receive a security prompt.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_turnofftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_turnofftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork","displayName":"Turn off Trusted Documents on the network (User)","description":"This policy setting allows you to turn off the trusted documents feature for documents opened from the network.\r\n\r\nIf you enable this policy setting, users will always see security notifications for active content such as macros, ActiveX controls, data connections, etc. for documents opened from the network.\r\n\r\nIf you disable or do not configure this policy setting, the trusted documents feature allows users to always allow active content in documents such as macros, ActiveX controls, data connections, etc. so that users are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty4","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty4_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty4_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty4_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty4_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles","displayName":"dBase III / IV files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_l_dbaseiiiandivfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_l_dbaseiiiandivfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_l_dbaseiiiandivfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles","displayName":"Dif and Sylk files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles_l_difandsylkfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles_l_difandsylkfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles_l_difandsylkfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_difandsylkfiles_l_difandsylkfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles","displayName":"Excel 2007 and later add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles_l_excel2007andlateraddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles_l_excel2007andlateraddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles_l_excel2007andlateraddinfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlateraddinfiles_l_excel2007andlateraddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks","displayName":"Excel 2007 and later binary workbooks (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterbinaryworkbooks_l_excel2007andlaterbinaryworkbooksdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates","displayName":"Excel 2007 and later macro-enabled workbooks and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlatermacroenabledworkbooksandtemplates_l_excel2007andlatermacroenabledworkbooksandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates","displayName":"Excel 2007 and later workbooks and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2007andlaterworkbooksandtemplates_l_excel2007andlaterworkbooksandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles","displayName":"Excel 2 macrosheets and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_l_excel2macrosheetsandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_l_excel2macrosheetsandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_l_excel2macrosheetsandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_l_excel2macrosheetsandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_l_excel2macrosheetsandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_l_excel2macrosheetsandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets","displayName":"Excel 2 worksheets (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_l_excel2worksheetsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_l_excel2worksheetsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_l_excel2worksheetsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_l_excel2worksheetsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_l_excel2worksheetsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2worksheets_l_excel2worksheetsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles","displayName":"Excel 3 macrosheets and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_l_excel3macrosheetsandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_l_excel3macrosheetsandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_l_excel3macrosheetsandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_l_excel3macrosheetsandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_l_excel3macrosheetsandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_l_excel3macrosheetsandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets","displayName":"Excel 3 worksheets (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_l_excel3worksheetsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_l_excel3worksheetsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_l_excel3worksheetsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_l_excel3worksheetsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_l_excel3worksheetsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3worksheets_l_excel3worksheetsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles","displayName":"Excel 4 macrosheets and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_l_excel4macrosheetsandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_l_excel4macrosheetsandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_l_excel4macrosheetsandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_l_excel4macrosheetsandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_l_excel4macrosheetsandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4macrosheetsandaddinfiles_l_excel4macrosheetsandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks","displayName":"Excel 4 workbooks (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets","displayName":"Excel 4 worksheets (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates","displayName":"Excel 95-97 workbooks and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks","displayName":"Excel 95 workbooks (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_l_excel95workbooksdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles","displayName":"Excel 97-2003 add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles_l_excel972003addinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles_l_excel972003addinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles_l_excel972003addinfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003addinfiles_l_excel972003addinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates","displayName":"Excel 97-2003 workbooks and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel972003workbooksandtemplates_l_excel972003workbooksandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles","displayName":"Excel add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_l_exceladdinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_l_exceladdinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_l_exceladdinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel","displayName":"Legacy converters for Excel (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_l_legacyconvertersforexceldropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_l_legacyconvertersforexceldropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_l_legacyconvertersforexceldropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_l_legacyconvertersforexceldropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_l_legacyconvertersforexceldropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforexcel_l_legacyconvertersforexceldropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel","displayName":"Microsoft Office Open XML converters for Excel (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforexcel_l_microsoftofficeopenxmlconvertersforexceldropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles","displayName":"Microsoft Office query files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficequeryfiles_l_microsoftofficequeryfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles","displayName":"Microsoft Office data connection files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_l_officedataconnectionfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_l_officedataconnectionfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_l_officedataconnectionfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_offlinecubefiles","displayName":"Offline cube files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_offlinecubefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_offlinecubefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_offlinecubefiles_l_offlinecubefilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_offlinecubefiles_l_offlinecubefilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_offlinecubefiles_l_offlinecubefilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles","displayName":"OpenDocument Spreadsheet files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_otherdatasourcefiles","displayName":"Other data source files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_otherdatasourcefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_otherdatasourcefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_otherdatasourcefiles_l_otherdatasourcefilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_otherdatasourcefiles_l_otherdatasourcefilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_otherdatasourcefiles_l_otherdatasourcefilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior","displayName":"Set default file block behavior (User)","description":"This policy setting allows you to determine if users can open, view, or edit Excel files.\r\n\r\nIf you enable this policy setting, you can set one of these options:\r\n- Blocked files are not opened\r\n- Blocked files open in Protected View and can not be edited\r\n- Blocked files open in Protected View and can be edited\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the same as the \"Blocked files are not opened\" setting. Users will not be able to open blocked files.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_0","displayName":"Blocked files are not opened","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_1","displayName":"Blocked files open in Protected View and can not be edited","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_2","displayName":"Blocked files open in Protected View and can be edited","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles","displayName":"Text files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles_l_textfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles_l_textfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles_l_textfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_textfiles_l_textfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets","displayName":"Web pages and Excel 2003 XML spreadsheets (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles","displayName":"XML files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles_l_xmlfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles_l_xmlfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles_l_xmlfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_xmlfiles_l_xmlfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview","displayName":"Do not open files from the Internet zone in Protected View (User)","description":"This policy setting allows you to determine if files downloaded from the Internet zone open in Protected View.\r\n\r\nIf you enable this policy setting, files downloaded from the Internet zone do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files downloaded from the Internet zone open in Protected View.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview","displayName":"Do not open files in unsafe locations in Protected View (User)","description":"This policy setting lets you determine if files located in unsafe locations will open in Protected View. If you have not specified unsafe locations, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders are considered unsafe locations.\r\n\r\nIf you enable this policy setting, files located in unsafe locations do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files located in unsafe locations open in Protected View.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview","displayName":"Open files on local Intranet UNC in Protected View (User)","description":"This policy setting lets you determine if files on local Intranet UNC file shares open in Protected View.\r\n\r\nIf you enable this policy setting, files on local Intranet UNC file shares open in Protected View if their UNC paths appear to be within the Internet zone.\r\n\r\nIf you disable or do not configure this policy setting, files on Intranet UNC file shares do not open in Protected View if their UNC paths appear to be within the Internet zone.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails","displayName":"Set document behavior if file validation fails (User)","description":"This policy setting controls how Office handles documents when they fail file validation. \r\n\r\nIf you enable this policy setting, you can configure the following options for files that fail file validation:\r\n\r\n- Block files completely. Users cannot open the files.\r\n- Open files in Protected View and disallow edit. Users cannot edit the files. This is also how Office handles the files if you disable this policy setting.\r\n- Open files in Protected View and allow edit. Users can edit the files. This is also how Office handles the files if you do not configure this policy setting.\r\n\r\nIf you disable this policy setting, Office follows the \"Open files in Protected View and disallow edit\" behavior.\r\n\r\nIf you do not configure this policy setting, Office follows the \"Open files in Protected View and allow edit\" behavior.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_0","displayName":"Block files","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_1","displayName":"Open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3","displayName":"Checked: Allow edit. Unchecked: Do not allow edit. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook","displayName":"Turn off Protected View for attachments opened from Outlook (User)","description":"This policy setting allows you to determine if Excel files in Outlook attachments open in Protected View.\r\n\r\nIf you enable this policy setting, Outlook attachments do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, Outlook attachments open in Protected View.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork","displayName":"Allow Trusted Locations on the network (User)","description":"This policy setting controls whether trusted locations on the network can be used.\r\n\r\nIf you enable this policy setting, users can specify trusted locations on network shares or in other remote locations that are not under their direct control by clicking the \"Add new location\" button in the Trusted Locations section of the Trust Center. Content, code, and add-ins are allowed to load from trusted locations with minimal security and without prompting the user for permission.\r\n\r\nIf you disable this policy setting, the selected application ignores any network locations listed in the Trusted Locations section of the Trust Center. \r\n\r\nIf you also deploy Trusted Locations via Group Policy, you should verify whether any of them are remote locations. If any of them are remote locations and you do not allow remote locations via this policy setting, those policy keys that point to remote locations will be ignored on client computers.\r\n\r\nDisabling this policy setting does not delete any network locations from the Trusted Locations list, but causes disruption for users who add network locations to the Trusted Locations list. Users are also prevented from adding new network locations to the Trusted Locations list in the Trust Center. We recommended that you do not enable this policy setting (as the \"Allow Trusted Locations on my network (not recommended)\" check box also states). Therefore, in practice, it should be possible to disable this policy setting in most situations without causing significant usability issues for most users.\r\n\r\nIf you do not enable this policy setting, users can select the \"Allow Trusted Locations on my network (not recommended)\" check box if desired and then specify trusted locations by clicking the \"Add new location\" button.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders8","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders8_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders8_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_datecolon6","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_descriptioncolon7","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_pathcolon5","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders12","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders12_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders12_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_datecolon10","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_descriptioncolon11","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_pathcolon9","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders16","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders16_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders16_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_datecolon14","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_descriptioncolon15","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_pathcolon13","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders20","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders20_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders20_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_datecolon18","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_descriptioncolon19","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_pathcolon17","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders24","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders24_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders24_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon22","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_descriptioncolon23","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_pathcolon21","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders28","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders28_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders28_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_datecolon26","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_descriptioncolon27","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_pathcolon25","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders32","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders32_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders32_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_datecolon30","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_descriptioncolon31","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_pathcolon29","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders36","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders36_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders36_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_datecolon34","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_descriptioncolon35","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_pathcolon33","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders40","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders40_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders40_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_datecolon38","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_descriptioncolon39","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_pathcolon37","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11","displayName":"Trusted Location #11 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders44","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders44_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders44_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_datecolon42","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_descriptioncolon43","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_pathcolon41","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders48","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders48_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders48_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_datecolon46","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_descriptioncolon47","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_pathcolon45","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders52","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders52_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders52_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_datecolon50","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_descriptioncolon51","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_pathcolon49","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders56","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders56_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders56_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_datecolon54","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_descriptioncolon55","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_pathcolon53","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders60","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders60_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders60_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_datecolon58","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_descriptioncolon59","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_pathcolon57","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders64","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders64_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders64_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_datecolon62","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_descriptioncolon63","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_pathcolon61","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders68","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders68_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders68_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_datecolon66","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_descriptioncolon67","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_pathcolon65","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders72","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders72_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders72_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_datecolon70","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_descriptioncolon71","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_pathcolon69","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders76","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders76_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders76_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_datecolon74","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_descriptioncolon75","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_pathcolon73","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders80","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders80_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders80_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_datecolon78","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_descriptioncolon79","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_pathcolon77","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation","displayName":"Check for accessibility issues while editing (User)","description":"This policy setting controls whether accessibility issues are checked for automatically while the user is editing a workbook. By default, accessibility issues aren’t checked for automatically.\r\n\r\nIf you enable this policy setting, accessibility issues are checked for automatically and users won’t be able to turn it off. The status bar will indicate if accessibility recommendations are available to make the workbook more usable by people with disabilities.\r\n\r\nIf you disable or don’t configure this policy setting, accessibility issues won’t be checked for automatically while editing a workbook. Users can turn on automatic checking by going to File > Options > Ease of Access.\r\n","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation","displayName":"Stop checking for alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that objects such as images and shapes contain alternative text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that objects such as images and shapes contain alternative text.\r\n\r\nIf you disable or do not configure this policy setting, objects will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsusedasformatting","displayName":"Stop checking for blank table rows used as formatting (User)","description":"This policy setting allows you to configure Accessibility Checker and whether it checks for blank table rows used as formatting.\r\n\r\nIf you enable this policy setting, no check for blank table rows used as formatting will be done.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for blank rows and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsusedasformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsusedasformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingformergedcells","displayName":"Stop checking for merged cells (User)","description":"This policy setting allows you to configure whether Accessibility Checker will verify that tables do not have merged cells.\r\n\r\nIf you enable this policy setting, no check will be made.\r\n\r\nIf you disable or do not configure this policy setting, worksheets will be checked for merged cells and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingformergedcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingformergedcells_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation","displayName":"Stop checking for table header accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables have a header row specified.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables have a header row specified.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for header rows and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful","displayName":"Stop checking to ensure hyperlink text is meaningful (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensurenondefaultsheetnames","displayName":"Stop checking to ensure non-default sheet names (User)","description":"This policy setting prevents the Accessibility Checker from verifying that worksheets with content have non-default names.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that worksheets with content have non-default names.\r\n\r\nIf you disable or do not configure this policy setting, worksheet names will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensurenondefaultsheetnames_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensurenondefaultsheetnames_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensureworkbooksallowprogrammaticaccess","displayName":"Stop checking to ensure workbooks allow programmatic access (User)","description":"This policy setting allows you to configure Accessibility Checker and whether it checks to ensure that workbooks have not blocked programmatic access through DRM.\r\n\r\nIf you enable this policy setting, no check will be made.\r\n\r\nIf you disable or do not configure this policy setting, workbooks will be checked for programmatic access and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensureworkbooksallowprogrammaticaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtoensureworkbooksallowprogrammaticaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_intelligentservices_l_insights","displayName":"Remove Ideas button from the Ribbon (User)","description":"\r\nThis policy setting allows you to prevent users from accessing Ideas in Excel, an intelligent service providing suggestions and analyses based on your data. By default, a button for Ideas appears in the “Ideas” group on the “Home” tab on the ribbon.\r\n\r\nIf you enable this policy setting, the button for Ideas is removed from the ribbon and users can’t add the button to the ribbon manually. Users won’t be able to access Ideas.\r\n\r\nIf you disable or don’t configure this policy setting, the button for Ideas appears on the ribbon and users can access Ideas.\r\n\t\t","helpText":"","infoUrls":[],"categoryId":"9a2bfe77-7e03-4a24-a9fa-c42a225a28b8","categoryName":"Intelligent Services","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_intelligentservices_l_insights_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_intelligentservices_l_insights_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_defaultcustomtab","displayName":"Show custom templates tab by default in Excel on the Office Start screen and in File | New (User)","description":"This policy setting controls whether custom templates (when they exist) show as the default tab in Excel on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, users will the see custom templates tab as the default tab in Excel on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Excel on the Office Start screen and in File | New, unless all Office-provided templates have been disabled.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_defaultcustomtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_defaultcustomtab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_disableofficestartexcel","displayName":"Disable the Office Start screen for Excel (User)","description":"This policy setting controls whether the Office Start screen appears on boot for Excel.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot Excel.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot Excel.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_disableofficestartexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_disableofficestartexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_donotcachenetworkfileslocally","displayName":"Do not cache network files locally (User)","description":"This policy setting allows you to configure whether network files are locally cached when editing spreadsheets stored on network shares.\r\n\r\nIf you enable this policy setting, a file located on a network share may not be saved if the network connection was lost at any time while editing the file and the file contains a pivot table, VBE code or an embedded OLE object. \r\n\r\nIf you disable or do not configure this policy setting, network files are locally cached when editing spreadsheets stored on network shares. This may help prevent data loss during network failures.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_donotcachenetworkfileslocally_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_donotcachenetworkfileslocally_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_enablefourdigityeardisplay","displayName":"Enable four-digit year display (User)","description":"When this setting is not enabled, Excel follows the Short date style setting under Regional Settings in Control Panel. When this setting is enabled, Excel always displays four digits when you type a date that includes a four-digit year, which may override the Short date style setting under Regional Settings in Control Panel.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_enablefourdigityeardisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_enablefourdigityeardisplay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_graphgallerypath","displayName":"Graph gallery path (User)","description":"Sets the path where user defined graph templates are stored.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_graphgallerypath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_graphgallerypath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_graphgallerypath_l_graphgallerypath169","displayName":"Graph gallery path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins, Excel Automation add-ins, and RTD add-ins, or specify the file name of Excel XLL add-ins and Excel add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\Excel\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\Excel\\Addins.\r\n\r\nTo obtain the file name of an add-in, click the File menu in the application where the add-in is installed. Click Options, click Add-ins, and then use the Location column to determine the file name of the add-in.\r\n\r\nYou can also obtain the ProgID or the file name of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting","displayName":"OLAP PivotTable User Defined Function (UDF) security setting (User)","description":"PivotTable reports can contain OLAP queries with references to User Defined Functions (UDFs). UDFs can be compiled executables, therefore posing a potential security threat. With this setting you can either (1) allow all UDFs in OLAP queries to execute with no IObjectSafety check, (2) allow only UDFs where the developer has used IObjectSafety to mark the UDF as a safe executable, or (3) disable all UDFs from executing in OLAP queries. The effect of setting this key is for Excel to pass the selected value to the OLAP provider.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting_l_olappivottableuserdefinedfunctionudfsecuritysetting171","displayName":"OLAP PivotTable User Defined Function (UDF) security setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting_l_olappivottableuserdefinedfunctionudfsecuritysetting171_1","displayName":"Allow ALL UDFs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting_l_olappivottableuserdefinedfunctionudfsecuritysetting171_2","displayName":"Allow safe UDFs only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_olappivottableuserdefinedfunctionudfsecuritysetting_l_olappivottableuserdefinedfunctionudfsecuritysetting171_3","displayName":"Allow NO UDFs","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_personaltemplatespath","displayName":"Personal templates path for Excel (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp","displayName":"Turn off file synchronization via SOAP over HTTP (User)","description":"This policy setting controls file synchronization via SOAP over HTTP for Excel.\r\n\r\nIf you enable this policy setting, file synchronization via SOAP over HTTP is turned off for Excel.\r\n\r\nIf you disable or do not configure this policy setting this policy setting, file synchronization via SOAP over HTTP is turned on for Excel.\r\n\r\nNote: Turning off file synchronization via SOAP over HTTP will adversely affect the behavior of SharePoint Workspaces.","helpText":"","infoUrls":[],"categoryId":"183628a3-d0a5-47de-b444-e132d634ca38","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlaunch","displayName":"Don’t allow Dynamic Data Exchange (DDE) server launch in Excel (User)","description":"This policy setting allows you to control whether Dynamic Data Exchange (DDE) server launch is allowed.\r\n\r\nBy default, DDE server launch is turned off, but users can turn on DDE server launch by going to File > Options > Trust Center > Trust Center Settings > External Content.\r\n\r\nFor security reasons, turning on DDE server launch is not recommended.\r\n\r\nNote: For DDE server launch to work, Dynamic Data Exchange (DDE) server lookup must be turned on. Be sure that the “Don’t allow Dynamic Data Exchange (DDE) server lookup” policy setting isn’t enabled, because enabling that policy setting turns off DDE server lookup.\r\n\r\nIf you enable this policy setting, DDE server launch isn’t allowed, and users can’t turn on DDE server launch in the Trust Center.\r\n\r\nIf you disable this policy setting, DDE server launch is allowed, and users cannot turn off DDE server launch in the Trust Center. For security reasons, this is not recommended.\r\n\r\nIf you don’t configure this policy setting, DDE server launch is turned off, but users can turn on DDE server launch in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"e36863b6-3232-4a29-be02-32ee67cc48b9","categoryName":"External Content","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlaunch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlaunch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlookup","displayName":"Don’t allow Dynamic Data Exchange (DDE) server lookup in Excel (User)","description":"This policy setting allows you to control whether Dynamic Data Exchange (DDE) server lookup is allowed.\r\n\r\nBy default, DDE server lookup is turned on, but users can turn off DDE server lookup by going to File > Options > Trust Center > Trust Center Settings > External Content.\r\n\r\nIf you enable this policy setting, DDE server lookup isn’t allowed, and users can’t turn on DDE server lookup in the Trust Center.\r\n\r\nNote: If you’re using Dynamic Data Exchange (DDE) server launch, which isn’t recommended, don’t enable this policy setting, because DDE server launch requires DDE server lookup to be on.\r\n\r\nIf you disable or don’t configure this policy setting, DDE server lookup is turned on, but users can turn off DDE server lookup in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"e36863b6-3232-4a29-be02-32ee67cc48b9","categoryName":"External Content","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlookup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlookup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_enableblockunsecurequeryfiles","displayName":"Always prevent untrusted Microsoft Query files from opening (User)","description":"This policy setting controls whether Microsoft Query files (.iqy, oqy, .dqy, and .rqy) in an untrusted location are prevented from opening.\r\n\r\nIf you enable this policy setting, Microsoft Query files in an untrusted location are prevented from opening. Users will not be able to change this setting under File > Options > Trust Center > Trust Center Settings > External Content.\r\n\r\nIf you disable or don’t configure this policy setting, Microsoft Query files in an untrusted location are not prevented from opening, unless users have changed this setting in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"e36863b6-3232-4a29-be02-32ee67cc48b9","categoryName":"External Content","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_enableblockunsecurequeryfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_enableblockunsecurequeryfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_enabledatabasefileprotectedview","displayName":"Always open untrusted database files in Protected View (User)","description":"This policy setting controls whether database files (.dbf) opened from an untrusted location are always opened in Protected View.\r\n\r\nIf you enable this policy setting, database files opened from an untrusted location are always opened in Protected View. Users will not be able to change this setting under File > Options > Trust Center > Trust Center Settings > Protected View.\r\n\r\nIf you disable or don’t configure this policy setting, database files opened from an untrusted location are not opened in Protected View, unless users have changed this setting in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_enabledatabasefileprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_enabledatabasefileprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_enableforeigntextfileprotectedview","displayName":"Always open untrusted text-based files in Protected View (User)","description":"This policy setting controls whether text-based files (.csv, .dif, and .sylk) opened from an untrusted location are always opened in Protected View.\r\n\r\nIf you enable this policy setting, text-based files opened from an untrusted location are always opened in Protected View. Users will not be able to change this setting under File > Options > Trust Center > Trust Center Settings > Protected View.\r\n\r\nIf you disable or don’t configure this policy setting, text-based files opened from an untrusted location are not opened in Protected View, unless users have changed this setting in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_enableforeigntextfileprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_enableforeigntextfileprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v4~policy~l_microsoftofficeexcel~l_powerbi_l_disablefrompowerbidatasetorganizationname","displayName":"Disable displaying organization name in the buttons to create PivotTables from Power BI datasets (User)","description":"\r\n This policy setting allows you to prevent the organization name from being displayed in the buttons in the Excel ribbon used to create PivotTables from Power BI datasets. By default, the organization name will be shown in the ribbon if it is available from Graph.\r\n\r\n If you enable this policy setting, the organization name will not be shown.\r\n\r\n If you disable or don’t configure this policy setting, the organization name will be shown.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"b473c6fa-a971-4e5d-ad15-2c27c17c5d3e","categoryName":"Power BI","options":[{"id":"user_vendor_msft_policy_config_excel16v4~policy~l_microsoftofficeexcel~l_powerbi_l_disablefrompowerbidatasetorganizationname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v4~policy~l_microsoftofficeexcel~l_powerbi_l_disablefrompowerbidatasetorganizationname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v5~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation","displayName":"Stop checking for table alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables contain alternative text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables contain alternative text.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v5~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v5~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v6~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_xl4killswitchpolicy","displayName":"Prevent Excel from running XLM macros (User)","description":"This policy setting will prevent Excel from running Excel 4.0 (XLM) macros.\r\n\r\nIf you enable this policy setting, XLM macros cannot be run in Excel.\r\n\r\nIf you disable or don’t configure this policy setting, XLM macros can be run in Excel.","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v6~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_xl4killswitchpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v6~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_xl4killswitchpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v7~policy~l_microsoftofficeexcel~l_miscellaneous168_l_exceldisableofficescripts","displayName":"Disable Office Scripts in Excel for Windows Desktop (User)","description":"This policy setting controls whether Office Scripts (including the relevant commands on the Automate tab) are available for use.\r\n\r\nIf you enable this policy setting, Office Scripts will not be available for use on the installed Excel app on a desktop.\r\n\r\nIf you disable or don't configure this policy setting, Office Scripts will be available for use provided all other prerequisites are met, including the applicable Microsoft 365 subscription license.\r\n\r\nNote: This policy setting is independent of Office Scripts settings available to administrators in the Microsoft 365 Admin Center. Admin Center settings are always honored by the Excel app regardless of the state of this policy; however, turning on this policy will also hide Office Scripts-related entry points.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v7~policy~l_microsoftofficeexcel~l_miscellaneous168_l_exceldisableofficescripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v7~policy~l_microsoftofficeexcel~l_miscellaneous168_l_exceldisableofficescripts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet","displayName":"Block Excel XLL Add-ins that come from an untrusted source (User)","description":"\r\n This policy setting allows you to block Excel XLL Add-ins that come from an untrusted source.\r\n\r\n If you enable this policy setting, you can set one of these options:\r\n - Block: XLL add-ins from untrusted sources are blocked. Users will receive a notification that the add-in was blocked.\r\n - Show Additional Warning: Show an additional warning prompt after the user chooses to enable an XLL add-in from an untrusted source.\r\n - Allow: XLL add-ins from an untrusted source are allowed.\r\n\r\n The exceptions when Excel XLL Add-ins will be allowed to run are:\r\n - The XLL is stored in a Trusted Location.\r\n - The XLL is digitally signed and the matching Trusted Publisher certificate is installed on the device.\r\n\r\n If you disable this policy setting, the settings configured in the Macro and Add-in Settings sections of the Trust Center determine whether Excel XLL Add-ins that come from an untrusted source will be allowed.\r\n\r\n If you disable or do not configure this policy setting, users will be able to override default behavior by modifying the registry.\r\n\r\n For more information, see https://support.microsoft.com/topic/1e3752e2-1177-4444-a807-7b700266a6fb.\r\n ","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet_l_blockxllfrominternetenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet_l_blockxllfrominternetenum_1","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet_l_blockxllfrominternetenum_0","displayName":"Show Additional Warning","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v8~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_blockxllfrominternet_l_blockxllfrominternetenum_2","displayName":"Allow","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_excel16v9~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excelfileblockexternallinks","displayName":"File Block includes external link files (User)","description":"This setting determines whether Trust Center settings for blocking load of potentially unsecure workbooks applies to those accessed by external links.\r\n\r\nIf you enable this policy setting, external links to workbooks that are blocked by File Block settings in Trust Center will not refresh. Attempts to create new links or refresh data from blocked workbooks may result in errors.\r\n\r\nIf you disable this policy setting, attempts to access external links data will not be subject to File Block settings in Trust Center.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v9~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excelfileblockexternallinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v9~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excelfileblockexternallinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_allowspotlightcollection","displayName":"Allow Spotlight Collection (User)","description":"Specifies whether Spotlight collection is allowed as a Personalization->Background Setting. If you enable this policy setting, Spotlight collection will show as an option in the user's Personalization Settings, and the user will be able to get daily images from Microsoft displayed on their desktop. If you disable this policy setting, Spotlight collection will not show as an option in Personliazation Settings, and the user will not have the choice of getting Microsoft daily images shown on their desktop.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowspotlightcollection"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":null},{"id":"user_vendor_msft_policy_config_experience_allowtailoredexperienceswithdiagnosticdata","displayName":"Allow Tailored Experiences With Diagnostic Data (User)","description":"This policy allows you to prevent Windows from using diagnostic data to provide customized experiences to the user. If you enable this policy setting, Windows will not use diagnostic data from this device to customize content shown on the lock screen, Windows tips, Microsoft consumer features, or other related features. If these features are enabled, users will still see recommendations, tips and offers, but they may be less relevant. If you disable or do not configure this policy setting, Microsoft will use diagnostic data to provide personalized recommendations, tips, and offers to tailor Windows for the user's needs and make it work better for them. Diagnostic data can include browser, app and feature usage, depending on the Diagnostic and usage data setting value. Note This setting does not control Cortana cutomized experiences because there are separate policies to configure it. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowtailoredexperienceswithdiagnosticdata"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowtailoredexperienceswithdiagnosticdata_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowtailoredexperienceswithdiagnosticdata_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_allowthirdpartysuggestionsinwindowsspotlight","displayName":"Allow Third Party Suggestions In Windows Spotlight (User)","description":"Specifies whether to allow app and content suggestions from third-party software publishers in Windows spotlight features like lock screen spotlight, suggested apps in the Start menu, and Windows tips. Users may still see suggestions for Microsoft features, apps, and services.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowthirdpartysuggestionsinwindowsspotlight"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowthirdpartysuggestionsinwindowsspotlight_0","displayName":"Block","description":"Third-party suggestions not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowthirdpartysuggestionsinwindowsspotlight_1","displayName":"Allow","description":"Third-party suggestions allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlight","displayName":"Allow Windows Spotlight (User)","description":"Specifies whether to turn off all Windows spotlight features at once. If you enable this policy setting, Windows spotlight on lock screen, Windows Tips, Microsoft consumer features and other related features will be turned off. You should enable this policy setting if your goal is to minimize network traffic from target devices. If you disable or do not configure this policy setting, Windows spotlight features are allowed and may be controlled individually using their corresponding policy settings. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlight"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlight_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlight_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonactioncenter","displayName":"Allow Windows Spotlight On Action Center (User)","description":"This policy allows administrators to prevent Windows spotlight notifications from being displayed in the Action Center. If you enable this policy, Windows spotlight notifications will no longer be displayed in the Action Center. If you disable or do not configure this policy, Microsoft may display notifications in the Action Center that will suggest apps or features to help users be more productive on Windows. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlightonactioncenter"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonactioncenter_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonactioncenter_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonsettings","displayName":"Allow Windows Spotlight On Settings (User)","description":"This policy allows IT admins to turn off Suggestions in Settings app. These suggestions from Microsoft may show after each OS clean install, upgrade or an on-going basis to help users discover apps/features on Windows or across devices, to make their experience productive. User setting is under Settings -> Privacy -> General -> Show me suggested content in Settings app. User Setting is changeable on a per user basis. If the Group policy is set to off, no suggestions will be shown to the user in Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlightonsettings"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonsettings_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonsettings_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightwindowswelcomeexperience","displayName":"Allow Windows Spotlight Windows Welcome Experience (User)","description":"This policy setting lets you turn off the Windows spotlight Windows welcome experience feature. The Windows welcome experience feature introduces onboard users to Windows; for example, launching Microsoft Edge with a webpage that highlights new features. If you enable this policy, the Windows welcome experience will no longer be displayed when there are updates and changes to Windows and its apps. If you disable or do not configure this policy, the Windows welcome experience will be launched to inform onboard users about what's new, changed, and suggested. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlightwindowswelcomeexperience"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightwindowswelcomeexperience_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightwindowswelcomeexperience_1","displayName":"Allow","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_configurewindowsspotlightonlockscreen","displayName":"Configure Windows Spotlight On Lock Screen (User)","description":"Allows IT admins to specify whether spotlight should be used on the user's lock screen. If your organization does not have an Enterprise spotlight content service, then this policy will behave the same as a setting of 1.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#configurewindowsspotlightonlockscreen"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_configurewindowsspotlightonlockscreen_0","displayName":"Windows spotlight disabled.","description":"Windows spotlight disabled.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_configurewindowsspotlightonlockscreen_1","displayName":"Windows spotlight enabled.","description":"Windows spotlight enabled.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_configurewindowsspotlightonlockscreen_2","displayName":"Windows spotlight is always enabled, the user cannot disable it","description":"Windows spotlight is always enabled, the user cannot disable it","helpText":null},{"id":"user_vendor_msft_policy_config_experience_configurewindowsspotlightonlockscreen_3","displayName":"Windows spotlight is always enabled, the user cannot disable it. For special configurations only","description":"Windows spotlight is always enabled, the user cannot disable it. For special configurations only","helpText":null}]},{"id":"user_vendor_msft_policy_config_experience_enableorganizationalmessages","displayName":"Enable delivery of organizational messages (User)","description":"Organizational messages allow Administrators to deliver messages to their end users on selected Windows 11 experiences. Organizational messages are available to Administrators via services like Microsoft Endpoint Manager. By default, this policy is disabled. If you enable this policy, these experiences will show content booked by Administrators. Enabling this policy will have no impact on existing MDM policy settings governing delivery of content from Microsoft on Windows experiences.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#enableorganizationalmessages"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_enableorganizationalmessages_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"user_vendor_msft_policy_config_experience_enableorganizationalmessages_1","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork","displayName":"Allow Option To Show Network (User)","description":"When the Network folder is restricted, give the user the option to enumerate and navigate into it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#allowoptiontoshownetwork"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork_0","displayName":"Not Allowed.","description":"Not Allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc","displayName":"Allow Option To Show This PC (User)","description":"When This PC location is restricted, give the user the option to enumerate and navigate into it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#allowoptiontoshowthispc"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc_0","displayName":"Not Allowed.","description":"Not Allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations","displayName":"Set Allowed Folder Locations (User)","description":"A value that can represent one or more folder locations in File Explorer. If not specified, the default is access to all folder locations.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#setallowedfolderlocations"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations_0","displayName":"Access to all folder locations.","description":"Access to all folder locations.","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations_13","displayName":"Documents, Pictures, Downloads","description":"Documents, Pictures, Downloads","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations_15","displayName":"Desktop, Documents, Pictures, Downloads","description":"Desktop, Documents, Pictures, Downloads","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations_31","displayName":"Desktop, Documents, Pictures, Downloads, Network","description":"Desktop, Documents, Pictures, Downloads, Network","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations_47","displayName":"This PC, Desktop, Documents, Pictures, Downloads","description":"This PC, Desktop, Documents, Pictures, Downloads","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedfolderlocations_63","displayName":"This PC, Desktop, Documents, Pictures, Downloads, Network","description":"This PC, Desktop, Documents, Pictures, Downloads, Network","helpText":null}]},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations","displayName":"Set Allowed Storage Locations (User)","description":"A value that can represent one or more storage locations in File Explorer. If not specified, the default is access to all storage locations.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#setallowedstoragelocations"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_0","displayName":"Access to all storage locations.","description":"Access to all storage locations.","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_1","displayName":"Removable Drives","description":"Removable Drives","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_2","displayName":"Sync roots","description":"Sync roots","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_3","displayName":"Removable Drives, Sync roots","description":"Removable Drives, Sync roots","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_4","displayName":"Local Drives","description":"Local Drives","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_5","displayName":"Removable Drives, Local Drives","description":"Removable Drives, Local Drives","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_6","displayName":"Sync Roots, Local Drives","description":"Sync Roots, Local Drives","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_setallowedstoragelocations_7","displayName":"Removable Drives, Sync Roots, Local Drives","description":"Removable Drives, Sync Roots, Local Drives","helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_addsearchprovider","displayName":"Add a specific list of search providers to the user's list of search providers (User)","description":"This policy setting allows you to add a specific list of search providers to the user's default list of search providers. Normally, search providers can be added from third-party toolbars or in Setup. The user can also add a search provider from the provider's website.\n\nIf you enable this policy setting, the user can add and remove search providers, but only from the set of search providers specified in the list of policy keys for search providers (found under [HKCU or HKLM\\Software\\policies\\Microsoft\\Internet Explorer\\SearchScopes]). Note: This list can be created from a custom administrative template file. For information about creating this custom administrative template file, see the Internet Explorer documentation on search providers.\n\nIf you disable or do not configure this policy setting, the user can configure their list of search providers unless another policy setting restricts such configuration.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-addsearchprovider"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_addsearchprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_addsearchprovider_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowactivexfiltering","displayName":"Turn on ActiveX Filtering (User)","description":"This policy setting controls the ActiveX Filtering feature for websites that are running ActiveX controls. The user can choose to turn off ActiveX Filtering for specific websites so that ActiveX controls can run properly.\n\nIf you enable this policy setting, ActiveX Filtering is enabled by default for the user. The user cannot turn off ActiveX Filtering, although they may add per-site exceptions.\n\nIf you disable or do not configure this policy setting, ActiveX Filtering is not enabled by default for the user. The user can turn ActiveX Filtering on or off.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowactivexfiltering"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowactivexfiltering_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowactivexfiltering_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowaddonlist","displayName":"Add-on List (User)","description":"This policy setting allows you to manage a list of add-ons to be allowed or denied by Internet Explorer. Add-ons in this case are controls like ActiveX Controls, Toolbars, and Browser Helper Objects (BHOs) which are specifically written to extend or enhance the functionality of the browser or web pages.\n\nThis list can be used with the 'Deny all add-ons unless specifically allowed in the Add-on List' policy setting, which defines whether add-ons not listed here are assumed to be denied.\n\nIf you enable this policy setting, you can enter a list of add-ons to be allowed or denied by Internet Explorer. For each entry that you add to the list, enter the following information:\n\nName of the Value - the CLSID (class identifier) for the add-on you wish to add to the list. The CLSID should be in brackets for example, ‘{000000000-0000-0000-0000-0000000000000}'. The CLSID for an add-on can be obtained by reading the OBJECT tag from a Web page on which the add-on is referenced.\n\nValue - A number indicating whether Internet Explorer should deny or allow the add-on to be loaded. To specify that an add-on should be denied enter a 0 (zero) into this field. To specify that an add-on should be allowed, enter a 1 (one) into this field. To specify that an add-on should be allowed and also permit the user to manage the add-on through Add-on Manager, enter a 2 (two) into this field.\n\nIf you disable this policy setting, the list is deleted. The 'Deny all add-ons unless specifically allowed in the Add-on List' policy setting will still determine whether add-ons not in this list are assumed to be denied.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowaddonlist"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowaddonlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowaddonlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowaddonlist_addonlist","displayName":"Add-on List (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowaddonlist_addonlist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowaddonlist_addonlist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete","displayName":"Turn on the auto-complete feature for user names and passwords on forms (User)","description":"This AutoComplete feature can remember and suggest User names and passwords on Forms.\n\nIf you enable this setting, the user cannot change \"User name and passwords on forms\" or \"prompt me to save passwords\". The Auto Complete feature for User names and passwords on Forms will be turned on. You have to decide whether to select \"prompt me to save passwords\".\n\nIf you disable this setting the user cannot change \"User name and passwords on forms\" or \"prompt me to save passwords\". The Auto Complete feature for User names and passwords on Forms is turned off. The user also cannot opt to be prompted to save passwords.\n\nIf you do not configure this setting, the user has the freedom of turning on Auto complete for User name and passwords on forms and the option of prompting to save passwords. To display this option, the users open the Internet Options dialog box, click the Contents Tab and click the Settings button.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowautocomplete"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_chkbox_passwordask","displayName":"Prompt me to save passwords (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_chkbox_passwordask_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_chkbox_passwordask_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowcertificateaddressmismatchwarning","displayName":"Turn on certificate address mismatch warning (User)","description":"This policy setting allows you to turn on the certificate address mismatch security warning. When this policy setting is turned on, the user is warned when visiting Secure HTTP (HTTPS) websites that present certificates issued for a different website address. This warning helps prevent spoofing attacks.\n\nIf you enable this policy setting, the certificate address mismatch warning always appears.\n\nIf you disable or do not configure this policy setting, the user can choose whether the certificate address mismatch warning appears (by using the Advanced page in the Internet Control panel).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowcertificateaddressmismatchwarning"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowcertificateaddressmismatchwarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowcertificateaddressmismatchwarning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowdeletingbrowsinghistoryonexit","displayName":"Allow deleting browsing history on exit (User)","description":"This policy setting allows the automatic deletion of specified items when the last browser window closes. The preferences selected in the Delete Browsing History dialog box (such as deleting temporary Internet files, cookies, history, form data, and passwords) are applied, and those items are deleted.\n\nIf you enable this policy setting, deleting browsing history on exit is turned on.\n\nIf you disable this policy setting, deleting browsing history on exit is turned off.\n\nIf you do not configure this policy setting, it can be configured on the General tab in Internet Options.\n\nIf the \"Prevent access to Delete Browsing History\" policy setting is enabled, this policy setting has no effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowdeletingbrowsinghistoryonexit"],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowdeletingbrowsinghistoryonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowdeletingbrowsinghistoryonexit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedprotectedmode","displayName":"Turn on Enhanced Protected Mode (User)","description":"Enhanced Protected Mode provides additional protection against malicious websites by using 64-bit processes on 64-bit versions of Windows. For computers running at least Windows 8, Enhanced Protected Mode also limits the locations Internet Explorer can read from in the registry and the file system.\n\nIf you enable this policy setting, Enhanced Protected Mode will be turned on. Any zone that has Protected Mode enabled will use Enhanced Protected Mode. Users will not be able to disable Enhanced Protected Mode.\n\nIf you disable this policy setting, Enhanced Protected Mode will be turned off. Any zone that has Protected Mode enabled will use the version of Protected Mode introduced in Internet Explorer 7 for Windows Vista.\n\nIf you do not configure this policy, users will be able to turn on or turn off Enhanced Protected Mode on the Advanced tab of the Internet Options dialog.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenhancedprotectedmode"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar","displayName":"Allow Microsoft services to provide enhanced suggestions as the user types in the Address bar (User)","description":"This policy setting allows Internet Explorer to provide enhanced suggestions as the user types in the Address bar. To provide enhanced suggestions, the user's keystrokes are sent to Microsoft through Microsoft services.\n\nIf you enable this policy setting, users receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.\n\nIf you disable this policy setting, users won't receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.\n\nIf you don't configure this policy setting, users can change the Suggestions setting on the Settings charm.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenhancedsuggestionsinaddressbar"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu","displayName":"Let users turn on and use Enterprise Mode from the Tools menu (User)","description":"This policy setting lets you decide whether users can turn on Enterprise Mode for websites with compatibility issues. Optionally, this policy also lets you specify where to get reports (through post messages) about the websites for which users turn on Enterprise Mode using the Tools menu.\n\nIf you turn this setting on, users can see and use the Enterprise Mode option from the Tools menu. If you turn this setting on, but don't specify a report location, Enterprise Mode will still be available to your users, but you won't get any reports.\n\nIf you disable or don't configure this policy setting, the menu option won't appear and users won't be able to run websites in Enterprise Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenterprisemodefromtoolsmenu"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu_enterreportbackprompt","displayName":"Type the location (URL) of where to receive reports about the websites for which users turn on and use Enterprise Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodesitelist","displayName":"Use the Enterprise Mode IE website list (User)","description":"This policy setting lets you specify where to find the list of websites you want opened using Enterprise Mode IE, instead of Standard mode, because of compatibility issues. Users can't edit this list.\n\nIf you enable this policy setting, Internet Explorer downloads the website list from your location (HKCU or HKLM\\Software\\policies\\Microsoft\\Internet Explorer\\Main\\EnterpriseMode), opening all listed websites using Enterprise Mode IE.\n\nIf you disable or don't configure this policy setting, Internet Explorer opens all websites using Standards mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenterprisemodesitelist"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodesitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodesitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodesitelist_entersitelistprompt","displayName":"Type the location (URL) of your Enterprise Mode IE website list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorer7policylist","displayName":"Use Policy List of Internet Explorer 7 sites (User)","description":"This policy setting allows you to add specific sites that must be viewed in Internet Explorer 7 Compatibility View.\n\nIf you enable this policy setting, the user can add and remove sites from the list, but the user cannot remove the entries that you specify.\n\nIf you disable or do not configure this policy setting, the user can add and remove sites from the list.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowinternetexplorer7policylist"],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorer7policylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorer7policylist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorer7policylist_compatview_sitelist","displayName":"List of sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorerstandardsmode","displayName":"Turn on Internet Explorer Standards Mode for local intranet (User)","description":"This policy setting controls how Internet Explorer displays local intranet content. Intranet content is defined as any webpage that belongs to the local intranet security zone.\n\nIf you enable this policy setting, Internet Explorer uses the current user agent string for local intranet content. Additionally, all local intranet Standards Mode pages appear in the Standards Mode available with the latest version of Internet Explorer. The user cannot change this behavior through the Compatibility View Settings dialog box.\n\nIf you disable this policy setting, Internet Explorer uses an Internet Explorer 7 user agent string (with an additional string appended) for local intranet content. Additionally, all local intranet Standards Mode pages appear in Internet Explorer 7 Standards Mode. The user cannot change this behavior through the Compatibility View Settings dialog box.\n\nIf you do not configure this policy setting, Internet Explorer uses an Internet Explorer 7 user agent string (with an additional string appended) for local intranet content. Additionally, all local intranet Standards Mode pages appear in Internet Explorer 7 Standards Mode. This option results in the greatest compatibility with existing webpages, but newer content written to common Internet standards may be displayed incorrectly. This option matches the default behavior of Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowinternetexplorerstandardsmode"],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorerstandardsmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorerstandardsmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate","displayName":"Internet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowinternetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_iz_partnameinternetzonetemplate","displayName":"Internet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_iz_partnameinternetzonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_iz_partnameinternetzonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_iz_partnameinternetzonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_iz_partnameinternetzonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_iz_partnameinternetzonetemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate","displayName":"Intranet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowintranetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate","displayName":"Intranet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate","displayName":"Local Machine Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlocalmachinezonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate","displayName":"Local Machine Zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate","displayName":"Locked-Down Internet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddowninternetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_iz_partnameinternetzonelockdowntemplate","displayName":"Locked-Down Internet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_iz_partnameinternetzonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_iz_partnameinternetzonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_iz_partnameinternetzonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_iz_partnameinternetzonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddowninternetzonetemplate_iz_partnameinternetzonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate","displayName":"Locked-Down Intranet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownintranetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_iz_partnameintranetzonelockdowntemplate","displayName":"Locked-Down Intranet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_iz_partnameintranetzonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_iz_partnameintranetzonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_iz_partnameintranetzonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_iz_partnameintranetzonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_iz_partnameintranetzonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate","displayName":"Locked-Down Local Machine Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownlocalmachinezonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_iz_partnamelocalmachinezonelockdowntemplate","displayName":"Locked-Down Local Machine Zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_iz_partnamelocalmachinezonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_iz_partnamelocalmachinezonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_iz_partnamelocalmachinezonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_iz_partnamelocalmachinezonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_iz_partnamelocalmachinezonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate","displayName":"Locked-Down Restricted Sites Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownrestrictedsiteszonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate","displayName":"Locked-Down Restricted Sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowonewordentry","displayName":"Go to an intranet site for a one-word entry in the Address bar (User)","description":"This policy allows the user to go directly to an intranet site for a one-word entry in the Address bar.\n\nIf you enable this policy setting, Internet Explorer goes directly to an intranet site for a one-word entry in the Address bar, if it is available.\n\nIf you disable or do not configure this policy setting, Internet Explorer does not go directly to an intranet site for a one-word entry in the Address bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowonewordentry"],"categoryId":"a1fbe395-3b60-475f-8a34-3710d6b2e09f","categoryName":"Browsing","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowonewordentry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowonewordentry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsavetargetasiniemode","displayName":"Allow \"Save Target As\" in Internet Explorer mode (User)","description":"This policy setting allows admins to enable \"Save Target As\" context menu in Internet Explorer mode.\n\nIf you enable this policy, \"Save Target As\" will show up in the Internet Explorer mode context menu and work the same as Internet Explorer.\n\nIf you disable or do not configure this policy setting, \"Save Target As\" will not show up in the Internet Explorer mode context menu.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2102115","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsavetargetasiniemode"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsavetargetasiniemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsavetargetasiniemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist","displayName":"Site to Zone Assignment List (User)","description":"This policy setting allows you to manage a list of sites that you want to associate with a particular security zone. These zone numbers have associated security settings that apply to all of the sites in the zone.\n\nInternet Explorer has 4 security zones, numbered 1-4, and these are used by this policy setting to associate sites to zones. They are: (1) Intranet zone, (2) Trusted Sites zone, (3) Internet zone, and (4) Restricted Sites zone. Security settings can be set for each of these zones through other policy settings, and their default settings are: Trusted Sites zone (Low template), Intranet zone (Medium-Low template), Internet zone (Medium template), and Restricted Sites zone (High template). (The Local Machine zone and its locked down equivalent have special security settings that protect your local computer.)\n\nIf you enable this policy setting, you can enter a list of sites and their related zone numbers. The association of a site with a zone will ensure that the security settings for the specified zone are applied to the site.  For each entry that you add to the list, enter the following information:\n\nValuename – A host for an intranet site, or a fully qualified domain name for other sites. The valuename may also include a specific protocol. For example, if you enter http://www.contoso.com as the valuename, other protocols are not affected. If you enter just www.contoso.com, then all protocols are affected for that site, including http, https, ftp, and so on. The site may also be expressed as an IP address (e.g., 127.0.0.1) or range (e.g., 127.0.0.1-10). To avoid creating conflicting policies, do not include additional characters after the domain such as trailing slashes or URL path. For example, policy settings for www.contoso.com and www.contoso.com/mail would be treated as the same policy setting by Internet Explorer, and would therefore be in conflict.\n\nValue - A number indicating the zone with which this site should be associated for security settings. The Internet Explorer zones described above are 1-4.\n\nIf you disable or do not configure this policy, users may choose their own site-to-zone assignments.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsitetozoneassignmentlist"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_iz_zonemapprompt","displayName":"Enter the zone assignments here. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_iz_zonemapprompt_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_iz_zonemapprompt_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate","displayName":"Locked-Down Trusted Sites Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowslockeddowntrustedsiteszonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate","displayName":"Locked-Down Trusted Sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid","displayName":"Allow software to run or install even if the signature is invalid (User)","description":"This policy setting allows you to manage whether software, such as ActiveX controls and file downloads, can be installed or run by the user even though the signature is invalid. An invalid signature might indicate that someone has tampered with the file.\n\nIf you enable this policy setting, users will be prompted to install or run files with an invalid signature.\n\nIf you disable this policy setting, users cannot run or install files with an invalid signature.\n\nIf you do not configure this policy, users can choose to run or install files with an invalid signature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsoftwarewhensignatureisinvalid"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate","displayName":"Restricted Sites Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsrestrictedsiteszonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonetemplate","displayName":"Restricted Sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonetemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsuggestedsites","displayName":"Turn on Suggested Sites (User)","description":"This policy setting controls the Suggested Sites feature, which recommends websites based on the user’s browsing activity. Suggested Sites reports a user’s browsing history to Microsoft to suggest sites that the user might want to visit.\n\nIf you enable this policy setting, the user is not prompted to enable Suggested Sites. The user’s browsing history is sent to Microsoft to produce suggestions.\n\nIf you disable this policy setting, the entry points and functionality associated with this feature are turned off.\n\nIf you do not configure this policy setting, the user can turn on and turn off the Suggested Sites feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsuggestedsites"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsuggestedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsuggestedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate","displayName":"Trusted Sites Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowtrustedsiteszonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate","displayName":"Trusted Sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_4","displayName":"High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_autodetectintranet","displayName":"Turn on automatic detection of intranet (User)","description":"This policy setting enables intranet mapping rules to be applied automatically if the computer belongs to a domain.\n\nIf you enable this policy setting, automatic detection of the intranet is turned on, and intranet mapping rules are applied automatically if the computer belongs to a domain.\n\nIf you disable this policy setting, automatic detection of the intranet is turned off, and intranet mapping rules are applied however they are configured.\n\nIf this policy setting is not configured, the user can choose whether or not to automatically detect the intranet through the intranet settings dialog in Control Panel.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-autodetectintranet"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_autodetectintranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_autodetectintranet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation","displayName":"Check for server certificate revocation (User)","description":"This policy setting allows you to manage whether Internet Explorer will check revocation status of servers' certificates. Certificates are revoked when they have been compromised or are no longer valid, and this option protects users from submitting confidential data to a site that may be fraudulent or not secure.\n\nIf you enable this policy setting, Internet Explorer will check to see if server certificates have been revoked.\n\nIf you disable this policy setting, Internet Explorer will not check server certificates to see if they have been revoked.\n\nIf you do not configure this policy setting, Internet Explorer will not check server certificates to see if they have been revoked.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-checkservercertificaterevocation"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms","displayName":"Check for signatures on downloaded programs (User)","description":"This policy setting allows you to manage whether Internet Explorer checks for digital signatures (which identifies the publisher of signed software and verifies it hasn't been modified or tampered with) on user computers before downloading executable programs.\n\nIf you enable this policy setting, Internet Explorer will check the digital signatures of executable programs and display their identities before downloading them to user computers.\n\nIf you disable this policy setting, Internet Explorer will not check the digital signatures of executable programs or display their identities before downloading them to user computers.\n\nIf you do not configure this policy, Internet Explorer will not check the digital signatures of executable programs or display their identities before downloading them to user computers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-checksignaturesondownloadedprograms"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel","displayName":"Configure which channel of Microsoft Edge to use for opening redirected sites (User)","description":"Enables you to configure up to three versions of Microsoft Edge to open a redirected site (in order of preference). Use this policy if your environment is configured to redirect sites from Internet Explorer 11 to Microsoft Edge. If any of the chosen versions are not installed on the device, that preference will be bypassed.\n\nIf both the Windows Update for the next version of Microsoft Edge* and Microsoft Edge Stable channel are installed, the following behaviors occur:\n- If you disable or don't configure this policy, Microsoft Edge Stable channel is used. This is the default behavior.\n- If you enable this policy, you can configure redirected sites to open in up to three of the following channels where:\n 1 = Microsoft Edge Stable\n 2 = Microsoft Edge Beta version 77 or later\n 3 = Microsoft Edge Dev version 77 or later\n 4 = Microsoft Edge Canary version 77 or later\n\nIf the Windows Update for the next version of Microsoft Edge* or Microsoft Edge Stable channel are not installed, the following behaviors occur:\n- If you disable or don't configure this policy, Microsoft Edge version 45 or earlier is automatically used. This is the default behavior.\n- If you enable this policy, you can configure redirected sites to open in up to three of the following channels where:\n 0 = Microsoft Edge version 45 or earlier\n 1 = Microsoft Edge Stable\n 2 = Microsoft Edge Beta version 77 or later\n 3 = Microsoft Edge Dev version 77 or later\n 4 = Microsoft Edge Canary version 77 or later\n\n*For more information about the Windows update for the next version of Microsoft Edge including how to disable it, see https://go.microsoft.com/fwlink/?linkid=2102115. This update applies only to Windows 10 version 1709 and higher.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-configureedgeredirectchannel"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser","displayName":"First choice (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_","displayName":"","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_1","displayName":"Microsoft Edge Stable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_2","displayName":"Microsoft Edge Beta version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_3","displayName":"Microsoft Edge Dev version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_4","displayName":"Microsoft Edge Canary version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_0","displayName":"Microsoft Edge version 45 or earlier","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2","displayName":"Second choice (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_","displayName":"","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_1","displayName":"Microsoft Edge Stable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_2","displayName":"Microsoft Edge Beta version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_3","displayName":"Microsoft Edge Dev version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_4","displayName":"Microsoft Edge Canary version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_0","displayName":"Microsoft Edge version 45 or earlier","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3","displayName":"Third choice (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3_","displayName":"","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3_1","displayName":"Microsoft Edge Stable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3_2","displayName":"Microsoft Edge Beta version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3_3","displayName":"Microsoft Edge Dev version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3_4","displayName":"Microsoft Edge Canary version 77 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser3_0","displayName":"Microsoft Edge version 45 or earlier","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"Internet Explorer uses Multipurpose Internet Mail Extensions (MIME) data to determine file handling procedures for files received through a Web server.\n\nThis policy setting determines whether Internet Explorer requires that all file-type information provided by Web servers be consistent. For example, if the MIME type of a file is text/plain but the MIME sniff indicates that the file is really an executable file, Internet Explorer renames the file by saving it in the Internet Explorer cache and changing its extension.\n\nIf you enable this policy setting, Internet Explorer requires consistent MIME data for all received files.\n\nIf you disable this policy setting, Internet Explorer will not require consistent MIME data for all received files.\n\nIf you do not configure this policy setting, Internet Explorer requires consistent MIME data for all received files.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-consistentmimehandlinginternetexplorerprocesses"],"categoryId":"ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","categoryName":"Consistent Mime Handling","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableactivexversionlistautodownload","displayName":"Turn off automatic download of the ActiveX VersionList (User)","description":"This setting determines whether IE automatically downloads updated versions of Microsoft’s VersionList.XML. IE uses this file to determine whether an ActiveX control should be stopped from loading.\n\nIf you enable this setting, IE stops downloading updated versions of VersionList.XML. Turning off this automatic download breaks the out-of-date ActiveX control blocking feature by not letting the version list update with newly outdated controls, potentially compromising the security of your computer.\n\nIf you disable or don't configure this setting, IE continues to download updated versions of VersionList.XML.\n\nFor more information, see \"Out-of-date ActiveX control blocking\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableactivexversionlistautodownload"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableactivexversionlistautodownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableactivexversionlistautodownload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableadobeflash","displayName":"Turn off Adobe Flash in Internet Explorer and prevent applications from using Internet Explorer technology to instantiate Flash objects (User)","description":"This policy setting turns off Adobe Flash in Internet Explorer and prevents applications from using Internet Explorer technology to instantiate Flash objects.\r\n\r\nIf you enable this policy setting, Flash is turned off for Internet Explorer, and applications cannot use Internet Explorer technology to instantiate Flash objects. In the Manage Add-ons dialog box, the Flash status will be 'Disabled', and users cannot enable Flash. If you enable this policy setting, Internet Explorer will ignore settings made for Adobe Flash through the \"Add-on List\" and \"Deny all add-ons unless specifically allowed in the Add-on List\" policy settings.\r\n\r\nIf you disable, or do not configure this policy setting, Flash is turned on for Internet Explorer, and applications can use Internet Explorer technology to instantiate Flash objects. Users can enable or disable Flash in the Manage Add-ons dialog box.\r\n\r\nNote that Adobe Flash can still be disabled through the \"Add-on List\" and \"Deny all add-ons unless specifically allowed in the Add-on List\" policy settings, even if this policy setting is disabled, or not configured. However, if Adobe Flash is disabled through the \"Add-on List\" and \"Deny all add-ons unless specifically allowed in the Add-on List\" policy settings and not through this policy setting, all applications that use Internet Explorer technology to instantiate Flash object can still do so. For more information, see \"Group Policy Settings in Internet Explorer 10\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-InternetExplorer#internetexplorer-disableadobeflash"],"categoryId":"89c0381d-3b9b-4be5-8077-ffb18d47e910","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableadobeflash_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableadobeflash_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarnings","displayName":"Prevent bypassing SmartScreen Filter warnings (User)","description":"This policy setting determines whether the user can bypass warnings from SmartScreen Filter. SmartScreen Filter prevents the user from browsing to or downloading from sites that are known to host malicious content. SmartScreen Filter also prevents the execution of files that are known to be malicious.\n\nIf you enable this policy setting, SmartScreen Filter warnings block the user.\n\nIf you disable or do not configure this policy setting, the user can bypass SmartScreen Filter warnings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablebypassofsmartscreenwarnings"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarningsaboutuncommonfiles","displayName":"Prevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the Internet (User)","description":"This policy setting determines whether the user can bypass warnings from SmartScreen Filter. SmartScreen Filter warns the user about executable files that Internet Explorer users do not commonly download from the Internet.\n\nIf you enable this policy setting, SmartScreen Filter warnings block the user.\n\nIf you disable or do not configure this policy setting, the user can bypass SmartScreen Filter warnings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablebypassofsmartscreenwarningsaboutuncommonfiles"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarningsaboutuncommonfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarningsaboutuncommonfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecompatview","displayName":"Turn off Compatibility View (User)","description":"This policy setting controls the Compatibility View feature, which allows the user to fix website display problems that he or she may encounter while browsing.\n\nIf you enable this policy setting, the user cannot use the Compatibility View button or manage the Compatibility View sites list.\n\nIf you disable or do not configure this policy setting, the user can use the Compatibility View button and manage the Compatibility View sites list.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecompatview"],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablecompatview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecompatview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableconfiguringhistory","displayName":"Disable \"Configuring History\" (User)","description":"This setting specifies the number of days that Internet Explorer tracks views of pages in the History List. To access the Temporary Internet Files and History Settings dialog box, from the Menu bar, on the Tools menu, click Internet Options, click the General tab, and then click Settings under Browsing history.\n\nIf you enable this policy setting, a user cannot set the number of days that Internet Explorer tracks views of the pages in the History List. You must specify the number of days that Internet Explorer tracks views of pages in the History List. Users can not delete browsing history.\n\nIf you disable or do not configure this policy setting, a user can set the number of days that Internet Explorer tracks views of pages in the History list. Users can delete browsing history.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableconfiguringhistory"],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableconfiguringhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableconfiguringhistory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableconfiguringhistory_daystokeep_prompt","displayName":"Days to keep pages in History (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecrashdetection","displayName":"Turn off Crash Detection (User)","description":"This policy setting allows you to manage the crash detection feature of add-on Management.\n\nIf you enable this policy setting, a crash in Internet Explorer will exhibit behavior found in Windows XP Professional Service Pack 1 and earlier, namely to invoke Windows Error Reporting. All policy settings for Windows Error Reporting continue to apply.\n\nIf you disable or do not configure this policy setting, the crash detection feature for add-on management will be functional.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecrashdetection"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablecrashdetection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecrashdetection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation","displayName":"Prevent participation in the Customer Experience Improvement Program (User)","description":"This policy setting prevents the user from participating in the Customer Experience Improvement Program (CEIP).\n\nIf you enable this policy setting, the user cannot participate in the CEIP, and the Customer Feedback Options command does not appear on the Help menu.\n\nIf you disable this policy setting, the user must participate in the CEIP, and the Customer Feedback Options command does not appear on the Help menu.\n\nIf you do not configure this policy setting, the user can choose to participate in the CEIP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecustomerexperienceimprovementprogramparticipation"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disabledeletinguservisitedwebsites","displayName":"Prevent deleting websites that the user has visited (User)","description":"This policy setting prevents the user from deleting the history of websites that he or she has visited. This feature is available in the Delete Browsing History dialog box.\n\nIf you enable this policy setting, websites that the user has visited are preserved when he or she clicks Delete.\n\nIf you disable this policy setting, websites that the user has visited are deleted when he or she clicks Delete.\n\nIf you do not configure this policy setting, the user can choose whether to delete or preserve visited websites when he or she clicks Delete.\n\nIf the \"Prevent access to Delete Browsing History\" policy setting is enabled, this policy setting is enabled by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disabledeletinguservisitedwebsites"],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disabledeletinguservisitedwebsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disabledeletinguservisitedwebsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableenclosuredownloading","displayName":"Prevent downloading of enclosures (User)","description":"This policy setting prevents the user from having enclosures (file attachments) downloaded from a feed to the user's computer.\n\nIf you enable this policy setting, the user cannot set the Feed Sync Engine to download an enclosure through the Feed property page. A developer cannot change the download setting through the Feed APIs.\n\nIf you disable or do not configure this policy setting, the user can set the Feed Sync Engine to download an enclosure through the Feed property page. A developer can change the download setting through the Feed APIs.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableenclosuredownloading"],"categoryId":"9aaa7ee2-727d-426f-8a2b-6b10a4cd084f","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableenclosuredownloading_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableenclosuredownloading_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport","displayName":"Turn off encryption support (User)","description":"This policy setting allows you to turn off support for Transport Layer Security (TLS) 1.0, TLS 1.1, TLS 1.2, Secure Sockets Layer (SSL) 2.0, or SSL 3.0 in the browser. TLS and SSL are protocols that help protect communication between the browser and the target server. When the browser attempts to set up a protected communication with the target server, the browser and server negotiate which protocol and version to use. The browser and server attempt to match each other’s list of supported protocols and versions, and they select the most preferred match.\n\nIf you enable this policy setting, the browser negotiates or does not negotiate an encryption tunnel by using the encryption methods that you select from the drop-down list.\n\nIf you disable or do not configure this policy setting, the user can select which encryption method the browser supports.\n\nNote: SSL 2.0 is off by default and is no longer supported starting with Windows 10 Version 1607. SSL 2.0 is an outdated security protocol, and enabling SSL 2.0 impairs the performance and functionality of TLS 1.0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableencryptionsupport"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions","displayName":"Secure Protocol combinations (User)","description":"","helpText":"","infoUrls":[],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_0","displayName":"Use no secure protocols","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_8","displayName":"[Obsolete] Only use SSL 2.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_32","displayName":"Only use SSL 3.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_40","displayName":"[Obsolete] Use SSL 2.0 and SSL 3.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_128","displayName":"Only use TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_136","displayName":"[Obsolete] Use SSL 2.0 and TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_160","displayName":"Use SSL 3.0 and TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_168","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, and TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_512","displayName":"Only use TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_520","displayName":"[Obsolete] Use SSL 2.0 and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_544","displayName":"Use SSL 3.0 and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_552","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_640","displayName":"Use TLS 1.0 and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_648","displayName":"[Obsolete] Use SSL 2.0, TLS 1.0, and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_672","displayName":"Use SSL 3.0, TLS 1.0, and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_680","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, TLS 1.0, and TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2048","displayName":"Only use TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2056","displayName":"[Obsolete] Use SSL 2.0 and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2080","displayName":"Use SSL 3.0 and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2088","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2176","displayName":"Use TLS 1.0 and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2184","displayName":"[Obsolete] Use SSL 2.0, TLS 1.0, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2208","displayName":"Use SSL 3.0, TLS 1.0, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2216","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, TLS 1.0, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2560","displayName":"Use TLS 1.1 and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2568","displayName":"[Obsolete] Use SSL 2.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2592","displayName":"Use SSL 3.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2600","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2688","displayName":"Use TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2696","displayName":"[Obsolete] Use SSL 2.0, TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2720","displayName":"Use SSL 3.0, TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2728","displayName":"[Obsolete] Use SSL 2.0, SSL 3.0, TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_8192","displayName":"Only use TLS 1.3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10240","displayName":"Use TLS 1.2 and TLS 1.3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10752","displayName":"Use TLS 1.1, TLS 1.2, and TLS 1.3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10880","displayName":"Use TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10912","displayName":"Use SSL 3.0, TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefeedsbackgroundsync","displayName":"Turn off background synchronization for feeds and Web Slices (User)","description":"This policy setting controls whether to have background synchronization for feeds and Web Slices.\n\nIf you enable this policy setting, the ability to synchronize feeds and Web Slices in the background is turned off.\n\nIf you disable or do not configure this policy setting, the user can synchronize feeds and Web Slices in the background.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablefeedsbackgroundsync"],"categoryId":"9aaa7ee2-727d-426f-8a2b-6b10a4cd084f","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablefeedsbackgroundsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefeedsbackgroundsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard","displayName":"Prevent running First Run wizard (User)","description":"This policy setting prevents Internet Explorer from running the First Run wizard the first time a user starts the browser after installing Internet Explorer or Windows.\n\nIf you enable this policy setting, you must make one of the following choices:\n • Skip the First Run wizard, and go directly to the user's home page.\n • Skip the First Run wizard, and go directly to the \"Welcome to Internet Explorer\" webpage.\n\nStarting with Windows 8, the \"Welcome to Internet Explorer\" webpage is not available. The user's home page will display regardless of which option is chosen.\n\nIf you disable or do not configure this policy setting, Internet Explorer may run the First Run wizard the first time the browser is started after installation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablefirstrunwizard"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_firstrunoptions","displayName":"Select your choice (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_firstrunoptions_1","displayName":"Go directly to home page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_firstrunoptions_2","displayName":"Go directly to \"Welcome To IE\" page","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature","displayName":"Turn off the flip ahead with page prediction feature (User)","description":"This policy setting determines whether a user can swipe across a screen or click Forward to go to the next pre-loaded page of a website.\n\nMicrosoft collects your browsing history to improve how flip ahead with page prediction works. This feature isn't available for Internet Explorer for the desktop.\n\nIf you enable this policy setting, flip ahead with page prediction is turned off and the next webpage isn't loaded into the background.\n\nIf you disable this policy setting, flip ahead with page prediction is turned on and the next webpage is loaded into the background.\n\nIf you don't configure this setting, users can turn this behavior on or off, using the Settings charm.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableflipaheadfeature"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablegeolocation","displayName":"Turn off browser geolocation (User)","description":"This policy setting allows you to disable browser geolocation support. This will prevent websites from requesting location data about the user.\n\nIf you enable this policy setting, browser geolocation support is turned off.\n\nIf you disable this policy setting, browser geolocation support is turned on.\n\nIf you do not configure this policy setting, browser geolocation support can be turned on or off in Internet Options on the Privacy tab.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablegeolocation"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablegeolocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablegeolocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablehomepagechange","displayName":"Disable changing home page settings (User)","description":"The Home page specified on the General tab of the Internet Options dialog box is the default Web page that Internet Explorer loads whenever it is run.\n\nIf you enable this policy setting, a user cannot set a custom default home page. You must specify which default home page should load on the user machine. For machines with at least Internet Explorer 7, the home page can be set within this policy to override other home page policies.\n\nIf you disable or do not configure this policy setting, the Home page box is enabled and users can choose their own home page.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablehomepagechange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablehomepagechange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablehomepagechange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablehomepagechange_enterhomepageprompt","displayName":"Home Page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablehtmlapplication","displayName":"Disable HTML Application (User)","description":"This policy setting specifies if running the HTML Application (HTA file) is blocked or allowed.\n\nIf you enable this policy setting, running the HTML Application (HTA file) will be blocked.\n\nIf you disable or do not configure this policy setting, running the HTML Application (HTA file) is allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablehtmlapplication"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablehtmlapplication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablehtmlapplication_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableignoringcertificateerrors","displayName":"Prevent ignoring certificate errors (User)","description":"This policy setting prevents the user from ignoring Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificate errors that interrupt browsing (such as \"expired\", \"revoked\", or \"name mismatch\" errors) in Internet Explorer.\n\nIf you enable this policy setting, the user cannot continue browsing.\n\nIf you disable or do not configure this policy setting, the user can choose to ignore certificate errors and continue browsing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableignoringcertificateerrors"],"categoryId":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","categoryName":"Internet Control Panel","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableignoringcertificateerrors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableignoringcertificateerrors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinprivatebrowsing","displayName":"Turn off InPrivate Browsing (User)","description":"This policy setting allows you to turn off the InPrivate Browsing feature.\n\nInPrivate Browsing prevents Internet Explorer from storing data about a user's browsing session. This includes cookies, temporary Internet files, history, and other data.\n\nIf you enable this policy setting, InPrivate Browsing is turned off.\n\nIf you disable this policy setting, InPrivate Browsing is available for use.\n\nIf you do not configure this policy setting, InPrivate Browsing can be turned on or off through the registry.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinprivatebrowsing"],"categoryId":"f26fe4c2-d073-4e51-90bf-61c4bbdeb4f2","categoryName":"Privacy","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableinprivatebrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinprivatebrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp","displayName":"[Deprecated] Disable Internet Explorer 11 as a standalone browser (User)","description":"This policy lets you restrict launching of Internet Explorer as a standalone browser.\r\n\r\nIf you enable this policy, it:\r\n- Prevents Internet Explorer 11 from launching as a standalone browser.\r\n- Restricts Internet Explorer's usage to Microsoft Edge's native 'Internet Explorer mode'.\r\n- Redirects all attempts at launching Internet Explorer 11 to Microsoft Edge Stable Channel browser.\r\n- Overrides any other policies that redirect to Internet Explorer 11.\r\n\r\nIf you disable, or don’t configure this policy, all sites are opened using the current active browser settings. Note: Microsoft Edge Stable Channel must be installed for this policy to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinternetexplorerapp"],"categoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2","displayName":"Disable Internet Explorer 11 as a standalone browser (User)","description":"This policy lets you restrict launching of Internet Explorer as a standalone browser.\n\nIf you enable this policy, it:\n- Prevents Internet Explorer 11 from launching as a standalone browser.\n- Restricts Internet Explorer's usage to Microsoft Edge's native 'Internet Explorer mode'.\n- Redirects attempts at launching Internet Explorer 11 to Microsoft Edge Stable Channel browser.\n- Overrides any other policies that redirect to Internet Explorer 11.\n\nEven with this policy enabled launching Internet Explorer 11 using COM automation will still be allowed. To disable COM automation launches of Internet Explorer 11 use the \"Disable Internet Explorer 11 COM Automation\" group policy.\n\nIf you disable, or don’t configure this policy, all sites are opened using the current active browser settings. Note: Microsoft Edge Stable Channel must be installed for this policy to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinternetexplorerapp"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_notifydisableieoptions","displayName":"Notify that Internet Explorer 11 browser is disabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_notifydisableieoptions_0","displayName":"Never","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_notifydisableieoptions_1","displayName":"Always","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_notifydisableieoptions_2","displayName":"Once per user","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerlaunchviacom","displayName":"Disable Internet Explorer 11 Launch Via COM Automation (User)","description":"This policy lets you restrict launching of Internet Explorer using COM automation.\n\nIf you enable this policy, it prevents Internet Explorer 11 from being launched using COM automation.\n\nIf you disable, or don’t configure this policy, Internet Explorer 11 COM automation launches are allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinternetexplorerlaunchviacom"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerlaunchviacom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerlaunchviacom_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableprocessesinenhancedprotectedmode","displayName":"Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows (User)","description":"This policy setting determines whether Internet Explorer 11 uses 64-bit processes (for greater security) or 32-bit processes (for greater compatibility) when running in Enhanced Protected Mode on 64-bit versions of Windows.\n\nImportant: Some ActiveX controls and toolbars may not be available when 64-bit processes are used.\n\nIf you enable this policy setting, Internet Explorer 11 will use 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows.\n\nIf you disable this policy setting, Internet Explorer 11 will use 32-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows.\n\nIf you don't configure this policy setting, users can turn this feature on or off using Internet Explorer settings. This feature is turned off by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableprocessesinenhancedprotectedmode"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableprocessesinenhancedprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableprocessesinenhancedprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disableproxychange","displayName":"Prevent changing proxy settings (User)","description":"This policy setting specifies if a user can change proxy settings.\n\nIf you enable this policy setting, the user will not be able to configure proxy settings.\n\nIf you disable or do not configure this policy setting, the user can configure proxy settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableproxychange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableproxychange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableproxychange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesearchproviderchange","displayName":"Prevent changing the default search provider (User)","description":"This policy setting prevents the user from changing the default search provider for the Address bar and the toolbar Search box.\n\nIf you enable this policy setting, the user cannot change the default search provider.\n\nIf you disable or do not configure this policy setting, the user can change the default search provider.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablesearchproviderchange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablesearchproviderchange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesearchproviderchange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange","displayName":"Disable changing secondary home page settings (User)","description":"Secondary home pages are the default Web pages that Internet Explorer loads in separate tabs from the home page whenever the browser is run. This policy setting allows you to set default secondary home pages.\n\nIf you enable this policy setting, you can specify which default home pages should load as secondary home pages. The user cannot set custom default secondary home pages.\n\nIf you disable or do not configure this policy setting, the user can add secondary home pages.\n\nNote: If the “Disable Changing Home Page Settings” policy is enabled, the user cannot add secondary home pages.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablesecondaryhomepagechange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_secondaryhomepageslist","displayName":"Secondary home pages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecuritysettingscheck","displayName":"Turn off the Security Settings Check feature (User)","description":"This policy setting turns off the Security Settings Check feature, which checks Internet Explorer security settings to determine when the settings put Internet Explorer at risk.\n\nIf you enable this policy setting, the feature is turned off.\n\nIf you disable or do not configure this policy setting, the feature is turned on.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablesecuritysettingscheck"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecuritysettingscheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecuritysettingscheck_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_disablewebaddressautocomplete","displayName":"Turn off the auto-complete feature for web addresses (User)","description":"This AutoComplete feature suggests possible matches when users are entering Web addresses in the browser address bar.\n\nIf you enable this policy setting, user will not be suggested matches when entering Web addresses. The user cannot change the auto-complete for web-address setting.\n\nIf you disable this policy setting, user will be suggested matches when entering Web addresses. The user cannot change the auto-complete for web-address setting.\n\nIf you do not configure this policy setting, a user will have the freedom to choose to turn the auto-complete setting for web-addresses on or off.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablewebaddressautocomplete"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablewebaddressautocomplete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablewebaddressautocomplete_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_donotallowactivexcontrolsinprotectedmode","displayName":"Do not allow ActiveX controls to run in Protected Mode when Enhanced Protected Mode is enabled (User)","description":"This policy setting prevents ActiveX controls from running in Protected Mode when Enhanced Protected Mode is enabled. When a user has an ActiveX control installed that is not compatible with Enhanced Protected Mode and a website attempts to load the control, Internet Explorer notifies the user and gives the option to run the website in regular Protected Mode. This policy setting disables this notification and forces all websites to run in Enhanced Protected Mode.\n\nEnhanced Protected Mode provides additional protection against malicious websites by using 64-bit processes on 64-bit versions of Windows. For computers running at least Windows 8, Enhanced Protected Mode also limits the locations Internet Explorer can read from in the registry and the file system.\n\nWhen Enhanced Protected Mode is enabled, and a user encounters a website that attempts to load an ActiveX control that is not compatible with Enhanced Protected Mode, Internet Explorer notifies the user and gives the option to disable Enhanced Protected Mode for that particular website.\n\nIf you enable this policy setting, Internet Explorer will not give the user the option to disable Enhanced Protected Mode. All Protected Mode websites will run in Enhanced Protected Mode.\n\nIf you disable or do not configure this policy setting, Internet Explorer notifies users and provides an option to run websites with incompatible ActiveX controls in regular Protected Mode. This is the default behavior.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-donotallowactivexcontrolsinprotectedmode"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_donotallowactivexcontrolsinprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_donotallowactivexcontrolsinprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrols","displayName":"Turn off blocking of outdated ActiveX controls for Internet Explorer (User)","description":"This policy setting determines whether Internet Explorer blocks specific outdated ActiveX controls. Outdated ActiveX controls are never blocked in the Intranet Zone.\n\nIf you enable this policy setting, Internet Explorer stops blocking outdated ActiveX controls.\n\nIf you disable or don't configure this policy setting, Internet Explorer continues to block specific outdated ActiveX controls.\n\nFor more information, see \"Outdated ActiveX Controls\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-donotblockoutdatedactivexcontrols"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrolsonspecificdomains","displayName":"Turn off blocking of outdated ActiveX controls for Internet Explorer on specific domains (User)","description":"This policy setting allows you to manage a list of domains on which Internet Explorer will stop blocking outdated ActiveX controls. Outdated ActiveX controls are never blocked in the Intranet Zone.\n\nIf you enable this policy setting, you can enter a custom list of domains for which outdated ActiveX controls won't be blocked in Internet Explorer. Each domain entry must be formatted like one of the following:\n\n1. \"domain.name.TLD\". For example, if you want to include *.contoso.com/*, use \"contoso.com\"\n2. \"hostname\". For example, if you want to include http://example, use \"example\"\n3. \"file:///path/filename.htm\". For example, use \"file:///C:/Users/contoso/Desktop/index.htm\"\n\nIf you disable or don't configure this policy setting, the list is deleted and Internet Explorer continues to block specific outdated ActiveX controls on all domains in the Internet Zone.\n\nFor more information, see \"Outdated ActiveX Controls\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-donotblockoutdatedactivexcontrolsonspecificdomains"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrolsonspecificdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrolsonspecificdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrolsonspecificdomains_domainlist","displayName":"Domain allow list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":null},{"id":"user_vendor_msft_policy_config_internetexplorer_enableextendediemodehotkeys","displayName":"Enable extended hot keys in Internet Explorer mode (User)","description":"This policy setting lets admins enable extended Microsoft Edge Internet Explorer mode hotkeys, such as \"Ctrl+S\" to have \"Save as\" functionality.\n\nIf you enable this policy, extended hotkey functionality is enabled in Internet Explorer mode and work the same as Internet Explorer.\n\nIf you disable, or don't configure this policy, extended hotkeys will not work in Internet Explorer mode.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2102115","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-enableextendediemodehotkeys"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_enableextendediemodehotkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_enableextendediemodehotkeys_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_enableglobalwindowlistiniemode","displayName":"Enable global window list in Internet Explorer mode (User)","description":"This setting allows Internet Explorer mode to use the global window list that enables sharing state with other applications.\nThe setting will take effect only when Internet Explorer 11 is disabled as a standalone browser.\n\nIf you enable this policy, Internet Explorer mode will use the global window list.\n\nIf you disable or don’t configure this policy, Internet Explorer mode will continue to maintain a separate window list.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2102921\nTo learn more about disabling Internet Explorer 11 as a standalone browser, see https://go.microsoft.com/fwlink/?linkid=2168340","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-enableglobalwindowlistiniemode"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_enableglobalwindowlistiniemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_enableglobalwindowlistiniemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_includealllocalsites","displayName":"Intranet Sites: Include all local (intranet) sites not listed in other zones (User)","description":"This policy setting controls whether local sites which are not explicitly mapped into any Security Zone are forced into the local Intranet security zone.\n\nIf you enable this policy setting, local sites which are not explicitly mapped into a zone are considered to be in the Intranet Zone.\n\nIf you disable this policy setting, local sites which are not explicitly mapped into a zone will not be considered to be in the Intranet Zone (so would typically be in the Internet Zone).\n\nIf you do not configure this policy setting, users choose whether to force local sites into the Intranet Zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-includealllocalsites"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_includealllocalsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_includealllocalsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths","displayName":"Intranet Sites: Include all network paths (UNCs) (User)","description":"This policy setting controls whether URLs representing UNCs are mapped into the local Intranet security zone.\n\nIf you enable this policy setting, all network paths are mapped into the Intranet Zone.\n\nIf you disable this policy setting, network paths are not necessarily mapped into the Intranet Zone (other rules might map one there).\n\nIf you do not configure this policy setting, users choose whether network paths are mapped into the Intranet Zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-includeallnetworkpaths"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_includeallproxybypasssites","displayName":"Intranet Sites: Include all sites that bypass the proxy server (User)","description":"This policy setting controls whether sites which bypass the proxy server are mapped into the local Intranet security zone.\n\nIf you enable this policy setting, sites which bypass the proxy server are mapped into the Intranet Zone.\n\nIf you disable this policy setting, sites which bypass the proxy server aren't necessarily mapped into the Intranet Zone (other rules might map one there).\n\nIf you do not configure this policy setting, users choose whether sites which bypass the proxy server are mapped into the Intranet Zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-includeallproxybypasssites"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_includeallproxybypasssites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_includeallproxybypasssites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowaccesstodatasources"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowautomaticpromptingforactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript","displayName":"Allow cut, copy or paste operations from the clipboard via script (User)","description":"This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region.\n\nIf you enable this policy setting, a script can perform a clipboard operation.\n\nIf you select Prompt in the drop-down box, users are queried as to whether to perform clipboard operations.\n\nIf you disable this policy setting, a script cannot perform a clipboard operation.\n\nIf you do not configure this policy setting, a script can perform a clipboard operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowcopypasteviascript"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407","displayName":"Allow paste operations via script (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles","displayName":"Allow drag and drop or copy and paste files (User)","description":"This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone.\n\nIf you enable this policy setting, users can drag files or copy and paste files from this zone automatically. If you select Prompt in the drop-down box, users are queried to choose whether to drag or copy files from this zone.\n\nIf you disable this policy setting, users are prevented from dragging files or copying and pasting files from this zone.\n\nIf you do not configure this policy setting, users can drag files or copy and paste files from this zone automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowdraganddropcopyandpastefiles"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles_iz_partname1802","displayName":"Allow drag and drop or copy and paste files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles_iz_partname1802_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles_iz_partname1802_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowdraganddropcopyandpastefiles_iz_partname1802_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowfontdownloads"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowlessprivilegedsites"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles","displayName":"Allow loading of XAML files (User)","description":"This policy setting allows you to manage the loading of Extensible Application Markup Language (XAML) files. XAML is an XML-based declarative markup language commonly used for creating rich user interfaces and graphics that take advantage of the Windows Presentation Foundation.\n\nIf you enable this policy setting and set the drop-down box to Enable, XAML files are automatically loaded inside Internet Explorer. The user cannot change this behavior. If you set the drop-down box to Prompt, the user is prompted for loading XAML files.\n\nIf you disable this policy setting, XAML files are not loaded inside Internet Explorer. The user cannot change this behavior.\n\nIf you do not configure this policy setting, the user can decide whether to load XAML files inside Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowloadingofxamlfiles"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402","displayName":"XAML Files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallownetframeworkreliantcomponents"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstouseactivexcontrols","displayName":"Allow only approved domains to use ActiveX controls without prompt (User)","description":"This policy setting controls whether or not the user is prompted to allow ActiveX controls to run on websites other than the website that installed the ActiveX control.\n\nIf you enable this policy setting, the user is prompted before ActiveX controls can run from websites in this zone. The user can choose to allow the control to run from the current site or from all sites.\n\nIf you disable this policy setting, the user does not see the per-site ActiveX prompt, and ActiveX controls can run from all sites in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowonlyapproveddomainstouseactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstouseactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstouseactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b","displayName":"Only allow approved domains to use ActiveX controls without prompt (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol","displayName":"Allow only approved domains to use the TDC ActiveX control (User)","description":"This policy setting controls whether or not the user is allowed to run the TDC ActiveX control on websites.\n\nIf you enable this policy setting, the TDC ActiveX control will not run from websites in this zone.\n\nIf you disable this policy setting, the TDC Active X control will run from all sites in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowonlyapproveddomainstousetdcactivexcontrol"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c","displayName":"Only allow approved domains to use the TDC ActiveX control (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols","displayName":"Allow scripting of Internet Explorer WebBrowser controls (User)","description":"This policy setting determines whether a page can control embedded WebBrowser controls via script.\n\nIf you enable this policy setting, script access to the WebBrowser control is allowed.\n\nIf you disable this policy setting, script access to the WebBrowser control is not allowed.\n\nIf you do not configure this policy setting, the user can enable or disable script access to the WebBrowser control. By default, script access to the WebBrowser control is allowed only in the Local Machine and Intranet zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowscriptingofinternetexplorerwebbrowsercontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206","displayName":"Internet Explorer web browser control (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows","displayName":"Allow script-initiated windows without size or position constraints (User)","description":"This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars.\n\nIf you enable this policy setting, Windows Restrictions security will not apply in this zone. The security zone runs without the added layer of security provided by this feature.\n\nIf you disable this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.\n\nIf you do not configure this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowscriptinitiatedwindows"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102","displayName":"Allow script-initiated windows without size or position constraints (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowscriptlets"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowsmartscreenie"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowupdatestostatusbarviascript","displayName":"Allow updates to status bar via script (User)","description":"This policy setting allows you to manage whether script is allowed to update the status bar within the zone.\n\nIf you enable this policy setting, script is allowed to update the status bar.\n\nIf you disable or do not configure this policy setting, script is not allowed to update the status bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowupdatestostatusbarviascript"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowupdatestostatusbarviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowupdatestostatusbarviascript_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowupdatestostatusbarviascript_iz_partname2103","displayName":"Status bar updates via script (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowupdatestostatusbarviascript_iz_partname2103_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowupdatestostatusbarviascript_iz_partname2103_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowuserdatapersistence"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer","displayName":"Allow VBScript to run in Internet Explorer (User)","description":"This policy setting allows you to manage whether VBScript can be run on pages from the specified zone in Internet Explorer.\n\nIf you selected Enable in the drop-down box, VBScript can run without user intervention.\n\nIf you selected Prompt in the drop-down box, users are asked to choose whether to allow VBScript to run.\n\nIf you selected Disable in the drop-down box, VBScript is prevented from running.\n\nIf you do not configure or disable this policy setting, VBScript is prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowvbscripttorunininternetexplorer"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c","displayName":"Allow VBScript to run in Internet Explorer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols","displayName":"Download signed ActiveX controls (User)","description":"This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone.\n\nIf you enable this policy, users can download signed controls without user intervention. If you select Prompt in the drop-down box, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.\n\nIf you disable the policy setting, signed controls cannot be downloaded.\n\nIf you do not configure this policy setting, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedownloadsignedactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_iz_partname1001","displayName":"Download signed ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_iz_partname1001_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_iz_partname1001_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_iz_partname1001_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols","displayName":"Download unsigned ActiveX controls (User)","description":"This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone. Such code is potentially harmful, especially when coming from an untrusted zone.\n\nIf you enable this policy setting, users can run unsigned controls without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to allow the unsigned control to run.\n\nIf you disable this policy setting, users cannot run unsigned controls.\n\nIf you do not configure this policy setting, users cannot run unsigned controls.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedownloadunsignedactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004","displayName":"Download unsigned ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter","displayName":"Turn on Cross-Site Scripting Filter (User)","description":"This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into websites in this zone.\n\nIf you enable this policy setting, the XSS Filter is turned on for sites in this zone, and the XSS Filter attempts to block cross-site script injections.\n\nIf you disable this policy setting, the XSS Filter is turned off for sites in this zone, and Internet Explorer permits cross-site script injections.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenablecrosssitescriptingfilter"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_iz_partname1409","displayName":"Turn on Cross-Site Scripting (XSS) Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_iz_partname1409_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_iz_partname1409_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows","displayName":"Enable dragging of content from different domains across windows (User)","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in different windows.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when both the source and destination are in different windows. Users cannot change this setting.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in different windows. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy or do not configure it, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709","displayName":"Enable dragging of content from different domains across windows (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows","displayName":"Enable dragging of content from different domains within a window (User)","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in the same window.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting in the Internet Options dialog.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in the same window. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy setting or do not configure it, users can drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting in the Internet Options dialog.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708","displayName":"Enable dragging of content from different domains within a window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing","displayName":"Enable MIME Sniffing (User)","description":"This policy setting allows you to manage MIME sniffing for file promotion from one type to another based on a MIME sniff. A MIME sniff is the recognition by Internet Explorer of the file type based on a bit signature.\n\nIf you enable this policy setting, the MIME Sniffing Safety Feature will not apply in this zone. The security zone will run without the added layer of security provided by this feature.\n\nIf you disable this policy setting, the actions that may be harmful cannot run; this Internet Explorer security feature will be turned on in this zone, as dictated by the feature control setting for the process.\n\nIf you do not configure this policy setting, the MIME Sniffing Safety Feature will not apply in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenablemimesniffing"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100","displayName":"Enable MIME Sniffing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenableprotectedmode"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver","displayName":"Include local path when user is uploading files to a server (User)","description":"This policy setting controls whether or not local path information is sent when the user is uploading a file via an HTML form. If the local path information is sent, some information may be unintentionally revealed to the server. For instance, files sent from the user's desktop may contain the user name as a part of the path.\n\nIf you enable this policy setting, path information is sent when the user is uploading a file via an HTML form.\n\nIf you disable this policy setting, path information is removed when the user is uploading a file via an HTML form.\n\nIf you do not configure this policy setting, the user can choose whether path information is sent when he or she is uploading a file via an HTML form. By default, path information is sent.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneincludelocalpathwhenuploadingfilestoserver"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a","displayName":"Include local directory path when uploading files to a server (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneinitializeandscriptactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, the permission is set to High Safety.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonejavapermissions"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe","displayName":"Launching applications and files in an IFRAME (User)","description":"This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone.\n\nIf you enable this policy setting, users can run applications and download files from IFRAMEs on the pages in this zone without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.\n\nIf you disable this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.\n\nIf you do not configure this policy setting, users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonelaunchingapplicationsandfilesiniframe"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804","displayName":"Launching applications and files in an IFRAME (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions","displayName":"Logon options (User)","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon only in Intranet zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonelogonoptions"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonenavigatewindowsandframes"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode","displayName":"Run .NET Framework-reliant components signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute signed managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute signed managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute signed managed components.\n\nIf you do not configure this policy setting, Internet Explorer will execute signed managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonerunnetframeworkreliantcomponentssignedwithauthenticode"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001","displayName":"Run .NET Framework-reliant components signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles","displayName":"Show security warning for potentially unsafe files (User)","description":"This policy setting controls whether or not the \"Open File - Security Warning\" message appears when the user tries to open executable files or other potentially unsafe files (from an intranet file share by using File Explorer, for example).\n\nIf you enable this policy setting and set the drop-down box to Enable, these files open without a security warning. If you set the drop-down box to Prompt, a security warning appears before the files open.\n\nIf you disable this policy setting, these files do not open.\n\nIf you do not configure this policy setting, the user can configure how the computer handles these files. By default, these files are blocked in the Restricted zone, enabled in the Intranet and Local Computer zones, and set to prompt in the Internet and Trusted zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneshowsecuritywarningforpotentiallyunsafefiles"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806","displayName":"Launching programs and unsafe files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker","displayName":"Use Pop-up Blocker (User)","description":"This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link are not blocked.\n\nIf you enable this policy setting, most unwanted pop-up windows are prevented from appearing.\n\nIf you disable this policy setting, pop-up windows are not prevented from appearing.\n\nIf you do not configure this policy setting, most unwanted pop-up windows are prevented from appearing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneusepopupblocker"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_iz_partname1809","displayName":"Use Pop-up Blocker (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_iz_partname1809_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_iz_partname1809_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowaccesstodatasources"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowautomaticpromptingforactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, users will receive a file download dialog for automatic download attempts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowfontdownloads"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowlessprivilegedsites"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallownetframeworkreliantcomponents"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowscriptlets"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowsmartscreenie"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowuserdatapersistence"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://learn.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneenableprotectedmode"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneinitializeandscriptactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, the permission is set to Medium Safety.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonejavapermissions"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions","displayName":"Logon options (User)","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon only in Intranet zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonelogonoptions"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonenavigatewindowsandframes"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_jscriptreplacement","displayName":"Replace JScript by loading JScript9Legacy in place of JScript. (User)","description":"This policy setting specifies whether JScript or JScript9Legacy is loaded.\n \nIf you enable this policy setting or not configured, JScript9Legacy will be loaded in situations where JScript is instantiated.\n\nIf you disable this policy, then JScript will be utilized.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-jscriptreplacement"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_jscriptreplacement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_jscriptreplacement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_keepintranetsitesininternetexplorer","displayName":"Keep all intranet sites in Internet Explorer (User)","description":"Prevents intranet sites from being opened in any browser except Internet Explorer. But note that If the ‘Send all sites not included in the Enterprise Mode Site List to Microsoft Edge’ (‘RestrictIE’) policy isn’t enabled, this policy has no effect.\n\nIf you enable this policy, all intranet sites are opened in Internet Explorer 11. The only exceptions are sites listed in your Enterprise Mode Site List.\n\nIf you disable or don’t configure this policy, all intranet sites are automatically opened in Microsoft Edge.\n\nWe strongly recommend keeping this policy in sync with the ‘Send all intranet sites to Internet Explorer’ (‘SendIntranetToInternetExplorer’) policy. Additionally, it’s best to enable this policy only if your intranet sites have known compatibility problems with Microsoft Edge.\n\nRelated policies:\n- Send all intranet sites to Internet Explorer (‘SendIntranetToInternetExplorer’)\n- Send all sites not included in the Enterprise Mode Site List to Microsoft Edge (‘RestrictIE’)\n\nFor more info about how to use this policy together with other related policies to create the optimal configuration for your organization, see https://go.microsoft.com/fwlink/?linkid=2094210.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-keepintranetsitesininternetexplorer"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_keepintranetsitesininternetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_keepintranetsitesininternetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowaccesstodatasources"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowautomaticpromptingforactivexcontrols"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, users will receive a file download dialog for automatic download attempts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowautomaticpromptingforfiledownloads"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowfontdownloads"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowlessprivilegedsites"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallownetframeworkreliantcomponents"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowscriptlets"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowsmartscreenie"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowuserdatapersistence"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://learn.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneenableprotectedmode"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, users are queried whether to allow the control to be loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneinitializeandscriptactivexcontrols"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, the permission is set to Medium Safety.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezonejavapermissions"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions","displayName":"Logon options (User)","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon with current username and password.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezonelogonoptions"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezonenavigatewindowsandframes"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowaccesstodatasources"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowautomaticpromptingforactivexcontrols"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowfontdownloads"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowlessprivilegedsites"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallownetframeworkreliantcomponents"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowscriptlets"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowsmartscreenie"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowuserdatapersistence"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneinitializeandscriptactivexcontrols"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzonejavapermissions"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzonenavigatewindowsandframes"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetjavapermissions"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetjavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowaccesstodatasources"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowautomaticpromptingforactivexcontrols"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowfontdownloads"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowlessprivilegedsites"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallownetframeworkreliantcomponents"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowscriptlets"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowsmartscreenie"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowuserdatapersistence"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneinitializeandscriptactivexcontrols"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzonenavigatewindowsandframes"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowaccesstodatasources"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowfontdownloads"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowlessprivilegedsites"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallownetframeworkreliantcomponents"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowscriptlets"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowsmartscreenie"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowuserdatapersistence"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneinitializeandscriptactivexcontrols"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezonejavapermissions"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezonenavigatewindowsandframes"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowaccesstodatasources"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, users are queried whether to allow HTML fonts to download.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowfontdownloads"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowlessprivilegedsites"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowscriptlets"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowsmartscreenie"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowuserdatapersistence"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszonejavapermissions"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open additional windows and frames from other domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow additional windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open other windows and frames from other domains or access applications from different domains.\n\nIf you do not configure this policy setting, users cannot open other windows and frames from different domains or access applications from different domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszonenavigatewindowsandframes"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowaccesstodatasources"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowfontdownloads"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowlessprivilegedsites"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallownetframeworkreliantcomponents"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowscriptlets"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowsmartscreenie"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowuserdatapersistence"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszonejavapermissions"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszonenavigatewindowsandframes"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_mimesniffingsafetyfeatureinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"This policy setting determines whether Internet Explorer MIME sniffing will prevent promotion of a file of one type to a more dangerous file type.\n\nIf you enable this policy setting, MIME sniffing will never promote a file of one type to a more dangerous file type.\n\nIf you disable this policy setting, Internet Explorer processes will allow a MIME sniff promoting a file of one type to a more dangerous file type.\n\nIf you do not configure this policy setting, MIME sniffing will never promote a file of one type to a more dangerous file type.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-mimesniffingsafetyfeatureinternetexplorerprocesses"],"categoryId":"b03bfdc7-f42a-400e-935b-2b07fc71a7f1","categoryName":"Mime Sniffing Safety Feature","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_mimesniffingsafetyfeatureinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_mimesniffingsafetyfeatureinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_mkprotocolsecurityrestrictioninternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"The MK Protocol Security Restriction policy setting reduces attack surface area by preventing the MK protocol. Resources hosted on the MK protocol will fail.\n\nIf you enable this policy setting, the MK Protocol is prevented for File Explorer and Internet Explorer, and resources hosted on the MK protocol will fail.\n\nIf you disable this policy setting, applications can use the MK protocol API. Resources hosted on the MK protocol will work for the File Explorer and Internet Explorer processes.\n\nIf you do not configure this policy setting, the MK Protocol is prevented for File Explorer and Internet Explorer, and resources hosted on the MK protocol will fail.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-mkprotocolsecurityrestrictioninternetexplorerprocesses"],"categoryId":"853d5a82-91e4-4c53-8338-fd1a3d9b542c","categoryName":"MK Protocol Security Restriction","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_mkprotocolsecurityrestrictioninternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_mkprotocolsecurityrestrictioninternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage","displayName":"Specify default behavior for a new tab (User)","description":"This policy setting allows you to specify what is displayed when the user opens a new tab.\n\nIf you enable this policy setting, you can choose which page to display when the user opens a new tab: blank page (about:blank), the first home page, the new tab page or the new tab page with my news feed.\n\nIf you disable or do not configure this policy setting, the user can select his or her preference for this behavior.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-newtabdefaultpage"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_newtabactionoptions","displayName":"New tab behavior (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_newtabactionoptions_3","displayName":"New tab page with my news feed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_newtabactionoptions_0","displayName":"about:blank","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_newtabactionoptions_2","displayName":"New tab page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_newtabactionoptions_1","displayName":"Home page","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_notificationbarinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"This policy setting allows you to manage whether the Notification bar is displayed for Internet Explorer processes when file or code installs are restricted. By default, the Notification bar is displayed for Internet Explorer processes.\n\nIf you enable this policy setting, the Notification bar will be displayed for Internet Explorer Processes.\n\nIf you disable this policy setting, the Notification bar will not be displayed for Internet Explorer processes.\n\nIf you do not configure this policy setting, the Notification bar will be displayed for Internet Explorer Processes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-notificationbarinternetexplorerprocesses"],"categoryId":"18296501-4825-47ea-835d-66a01aba9384","categoryName":"Notification bar","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_notificationbarinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_notificationbarinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter","displayName":"Prevent managing SmartScreen Filter (User)","description":"This policy setting prevents the user from managing SmartScreen Filter, which warns the user if the website being visited is known for fraudulent attempts to gather personal information through \"phishing,\" or is known to host malware.\n\nIf you enable this policy setting, the user is not prompted to turn on SmartScreen Filter. All website addresses that are not on the filter's allow list are sent automatically to Microsoft without prompting the user.\n\nIf you disable or do not configure this policy setting, the user is prompted to decide whether to turn on SmartScreen Filter during the first-run experience.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-preventmanagingsmartscreenfilter"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_ie9safetyfilteroptions","displayName":"Select SmartScreen Filter mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_ie9safetyfilteroptions_0","displayName":"Off","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_ie9safetyfilteroptions_1","displayName":"On","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_preventperuserinstallationofactivexcontrols","displayName":"Prevent per-user installation of ActiveX controls (User)","description":"This policy setting allows you to prevent the installation of ActiveX controls on a per-user basis.\n\nIf you enable this policy setting, ActiveX controls cannot be installed on a per-user basis.\n\nIf you disable or do not configure this policy setting, ActiveX controls can be installed on a per-user basis.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-preventperuserinstallationofactivexcontrols"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_preventperuserinstallationofactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_preventperuserinstallationofactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_protectionfromzoneelevationinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"Internet Explorer places restrictions on each Web page it opens. The restrictions are dependent upon the location of the Web page (Internet, Intranet, Local Machine zone, etc.). Web pages on the local computer have the fewest security restrictions and reside in the Local Machine zone, making the Local Machine security zone a prime target for malicious users. Zone Elevation also disables JavaScript navigation if there is no security context.\n\nIf you enable this policy setting, any zone can be protected from zone elevation by Internet Explorer processes.\n\nIf you disable this policy setting, no zone receives such protection for Internet Explorer processes.\n\nIf you do not configure this policy setting, any zone can be protected from zone elevation by Internet Explorer processes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-protectionfromzoneelevationinternetexplorerprocesses"],"categoryId":"3bbaff1b-7d59-4b9c-ab53-c235d72b2fb0","categoryName":"Protection From Zone Elevation","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_protectionfromzoneelevationinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_protectionfromzoneelevationinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols","displayName":"Remove \"Run this time\" button for outdated ActiveX controls in Internet Explorer (User)","description":"This policy setting allows you to stop users from seeing the \"Run this time\" button and from running specific outdated ActiveX controls in Internet Explorer.\n\nIf you enable this policy setting, users won't see the \"Run this time\" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control.\n\nIf you disable or don't configure this policy setting, users will see the \"Run this time\" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control. Clicking this button lets the user run the outdated ActiveX control once.\n\nFor more information, see \"Outdated ActiveX Controls\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-removerunthistimebuttonforoutdatedactivexcontrols"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_resetzoomfordialoginiemode","displayName":"Reset zoom to default for HTML dialogs in Internet Explorer mode (User)","description":"This policy setting lets admins reset zoom to default for HTML dialogs in Internet Explorer mode.\n\nIf you enable this policy, the zoom of an HTML dialog in Internet Explorer mode will not get propagated from its parent page.\n\nIf you disable, or don't configure this policy, the zoom of an HTML dialog in Internet Explorer mode will be set based on the zoom of it's parent page.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2220107","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-resetzoomfordialoginiemode"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_resetzoomfordialoginiemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_resetzoomfordialoginiemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictactivexinstallinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"This policy setting enables blocking of ActiveX control installation prompts for Internet Explorer processes.\n\nIf you enable this policy setting, prompting for ActiveX control installations will be blocked for Internet Explorer processes.\n\nIf you disable this policy setting, prompting for ActiveX control installations will not be blocked for Internet Explorer processes.\n\nIf you do not configure this policy setting, the user's preference will be used to determine whether to block ActiveX control installations for Internet Explorer processes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictactivexinstallinternetexplorerprocesses"],"categoryId":"e6911a08-946f-4b70-99cb-2a8b92c461e0","categoryName":"Restrict ActiveX Install","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictactivexinstallinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictactivexinstallinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowaccesstodatasources"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting","displayName":"Allow active scripting (User)","description":"This policy setting allows you to manage whether script code on pages in the zone is run.\n\nIf you enable this policy setting, script code on pages in the zone can run automatically. If you select Prompt in the drop-down box, users are queried to choose whether to allow script code on pages in the zone to run.\n\nIf you disable this policy setting, script code on pages in the zone is prevented from running.\n\nIf you do not configure this policy setting, script code on pages in the zone is prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowactivescripting"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400","displayName":"Allow active scripting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowautomaticpromptingforactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors","displayName":"Allow binary and script behaviors (User)","description":"This policy setting allows you to manage dynamic binary and script behaviors: components that encapsulate specific functionality for HTML elements to which they were attached.\n\nIf you enable this policy setting, binary and script behaviors are available. If you select Administrator approved in the drop-down box, only behaviors listed in the Admin-approved Behaviors under Binary Behaviors Security Restriction policy are available.\n\nIf you disable this policy setting, binary and script behaviors are not available unless applications have implemented a custom security manager.\n\nIf you do not configure this policy setting, binary and script behaviors are not available unless applications have implemented a custom security manager.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowbinaryandscriptbehaviors"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000","displayName":"Allow Binary and Script Behaviors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000_65536","displayName":"Administrator approved","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript","displayName":"Allow cut, copy or paste operations from the clipboard via script (User)","description":"This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region.\n\nIf you enable this policy setting, a script can perform a clipboard operation.\n\nIf you select Prompt in the drop-down box, users are queried as to whether to perform clipboard operations.\n\nIf you disable this policy setting, a script cannot perform a clipboard operation.\n\nIf you do not configure this policy setting, a script cannot perform a clipboard operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowcopypasteviascript"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407","displayName":"Allow paste operations via script (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles","displayName":"Allow drag and drop or copy and paste files (User)","description":"This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone.\n\nIf you enable this policy setting, users can drag files or copy and paste files from this zone automatically. If you select Prompt in the drop-down box, users are queried to choose whether to drag or copy files from this zone.\n\nIf you disable this policy setting, users are prevented from dragging files or copying and pasting files from this zone.\n\nIf you do not configure this policy setting, users are queried to choose whether to drag or copy files from this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowdraganddropcopyandpastefiles"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_iz_partname1802","displayName":"Allow drag and drop or copy and paste files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_iz_partname1802_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_iz_partname1802_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_iz_partname1802_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads","displayName":"Allow file downloads (User)","description":"This policy setting allows you to manage whether file downloads are permitted from the zone. This option is determined by the zone of the page with the link causing the download, not the zone from which the file is delivered.\n\nIf you enable this policy setting, files can be downloaded from the zone.\n\nIf you disable this policy setting, files are prevented from being downloaded from the zone.\n\n If you do not configure this policy setting, files are prevented from being downloaded from the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowfiledownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_iz_partname1803","displayName":"Allow file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_iz_partname1803_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_iz_partname1803_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, users are queried whether to allow HTML fonts to download.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowfontdownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowlessprivilegedsites"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles","displayName":"Allow loading of XAML files (User)","description":"This policy setting allows you to manage the loading of Extensible Application Markup Language (XAML) files. XAML is an XML-based declarative markup language commonly used for creating rich user interfaces and graphics that take advantage of the Windows Presentation Foundation.\n\nIf you enable this policy setting and set the drop-down box to Enable, XAML files are automatically loaded inside Internet Explorer. The user cannot change this behavior. If you set the drop-down box to Prompt, the user is prompted for loading XAML files.\n\nIf you disable this policy setting, XAML files are not loaded inside Internet Explorer. The user cannot change this behavior.\n\nIf you do not configure this policy setting, the user can decide whether to load XAML files inside Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowloadingofxamlfiles"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402","displayName":"XAML Files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowmetarefresh","displayName":"Allow META REFRESH (User)","description":"This policy setting allows you to manage whether a user's browser can be redirected to another Web page if the author of the Web page uses the Meta Refresh setting (tag) to redirect browsers to another Web page.\n\nIf you enable this policy setting, a user's browser that loads a page containing an active Meta Refresh setting can be redirected to another Web page.\n\nIf you disable this policy setting, a user's browser that loads a page containing an active Meta Refresh setting cannot be redirected to another Web page.\n\nIf you do not configure this policy setting, a user's browser that loads a page containing an active Meta Refresh setting cannot be redirected to another Web page.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowmetarefresh"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowmetarefresh_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowmetarefresh_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowmetarefresh_iz_partname1608","displayName":"Allow META REFRESH (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowmetarefresh_iz_partname1608_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowmetarefresh_iz_partname1608_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallownetframeworkreliantcomponents"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols","displayName":"Allow only approved domains to use ActiveX controls without prompt (User)","description":"This policy setting controls whether or not the user is prompted to allow ActiveX controls to run on websites other than the website that installed the ActiveX control.\n\nIf you enable this policy setting, the user is prompted before ActiveX controls can run from websites in this zone. The user can choose to allow the control to run from the current site or from all sites.\n\nIf you disable this policy setting, the user does not see the per-site ActiveX prompt, and ActiveX controls can run from all sites in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b","displayName":"Only allow approved domains to use ActiveX controls without prompt (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol","displayName":"Allow only approved domains to use the TDC ActiveX control (User)","description":"This policy setting controls whether or not the user is allowed to run the TDC ActiveX control on websites.\n\nIf you enable this policy setting, the TDC ActiveX control will not run from websites in this zone.\n\nIf you disable this policy setting, the TDC Active X control will run from all sites in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c","displayName":"Only allow approved domains to use the TDC ActiveX control (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols","displayName":"Allow scripting of Internet Explorer WebBrowser controls (User)","description":"This policy setting determines whether a page can control embedded WebBrowser controls via script.\n\nIf you enable this policy setting, script access to the WebBrowser control is allowed.\n\nIf you disable this policy setting, script access to the WebBrowser control is not allowed.\n\nIf you do not configure this policy setting, the user can enable or disable script access to the WebBrowser control. By default, script access to the WebBrowser control is allowed only in the Local Machine and Intranet zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206","displayName":"Internet Explorer web browser control (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows","displayName":"Allow script-initiated windows without size or position constraints (User)","description":"This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars.\n\nIf you enable this policy setting, Windows Restrictions security will not apply in this zone. The security zone runs without the added layer of security provided by this feature.\n\nIf you disable this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.\n\nIf you do not configure this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowscriptinitiatedwindows"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_iz_partname2102","displayName":"Allow script-initiated windows without size or position constraints (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_iz_partname2102_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_iz_partname2102_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowscriptlets"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowsmartscreenie"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript","displayName":"Allow updates to status bar via script (User)","description":"This policy setting allows you to manage whether script is allowed to update the status bar within the zone.\n\nIf you enable this policy setting, script is allowed to update the status bar.\n\nIf you disable or do not configure this policy setting, script is not allowed to update the status bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowupdatestostatusbarviascript"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_iz_partname2103","displayName":"Status bar updates via script (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_iz_partname2103_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_iz_partname2103_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowuserdatapersistence"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer","displayName":"Allow VBScript to run in Internet Explorer (User)","description":"This policy setting allows you to manage whether VBScript can be run on pages from the specified zone in Internet Explorer.\n\nIf you selected Enable in the drop-down box, VBScript can run without user intervention.\n\nIf you selected Prompt in the drop-down box, users are asked to choose whether to allow VBScript to run.\n\nIf you selected Disable in the drop-down box, VBScript is prevented from running.\n\nIf you do not configure or disable this policy setting, VBScript is prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowvbscripttorunininternetexplorer"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_iz_partname140c","displayName":"Allow VBScript to run in Internet Explorer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_iz_partname140c_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_iz_partname140c_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_iz_partname140c_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols","displayName":"Download signed ActiveX controls (User)","description":"This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone.\n\nIf you enable this policy, users can download signed controls without user intervention. If you select Prompt in the drop-down box, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.\n\nIf you disable the policy setting, signed controls cannot be downloaded.\n\nIf you do not configure this policy setting, signed controls cannot be downloaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonedownloadsignedactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001","displayName":"Download signed ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols","displayName":"Download unsigned ActiveX controls (User)","description":"This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone. Such code is potentially harmful, especially when coming from an untrusted zone.\n\nIf you enable this policy setting, users can run unsigned controls without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to allow the unsigned control to run.\n\nIf you disable this policy setting, users cannot run unsigned controls.\n\nIf you do not configure this policy setting, users cannot run unsigned controls.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonedownloadunsignedactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004","displayName":"Download unsigned ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter","displayName":"Turn on Cross-Site Scripting Filter (User)","description":"This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into websites in this zone.\n\nIf you enable this policy setting, the XSS Filter is turned on for sites in this zone, and the XSS Filter attempts to block cross-site script injections.\n\nIf you disable this policy setting, the XSS Filter is turned off for sites in this zone, and Internet Explorer permits cross-site script injections.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenablecrosssitescriptingfilter"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_iz_partname1409","displayName":"Turn on Cross-Site Scripting (XSS) Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_iz_partname1409_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_iz_partname1409_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows","displayName":"Enable dragging of content from different domains across windows (User)","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in different windows.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when both the source and destination are in different windows. Users cannot change this setting.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in different windows. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy or do not configure it, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709","displayName":"Enable dragging of content from different domains across windows (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows","displayName":"Enable dragging of content from different domains within a window (User)","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in the same window.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting in the Internet Options dialog.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in the same window. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy setting or do not configure it, users can drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting in the Internet Options dialog.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708","displayName":"Enable dragging of content from different domains within a window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing","displayName":"Enable MIME Sniffing (User)","description":"This policy setting allows you to manage MIME sniffing for file promotion from one type to another based on a MIME sniff. A MIME sniff is the recognition by Internet Explorer of the file type based on a bit signature.\n\nIf you enable this policy setting, the MIME Sniffing Safety Feature will not apply in this zone. The security zone will run without the added layer of security provided by this feature.\n\nIf you disable this policy setting, the actions that may be harmful cannot run; this Internet Explorer security feature will be turned on in this zone, as dictated by the feature control setting for the process.\n\nIf you do not configure this policy setting, the actions that may be harmful cannot run; this Internet Explorer security feature will be turned on in this zone, as dictated by the feature control setting for the process.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenablemimesniffing"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_iz_partname2100","displayName":"Enable MIME Sniffing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_iz_partname2100_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_iz_partname2100_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver","displayName":"Include local path when user is uploading files to a server (User)","description":"This policy setting controls whether or not local path information is sent when the user is uploading a file via an HTML form. If the local path information is sent, some information may be unintentionally revealed to the server. For instance, files sent from the user's desktop may contain the user name as a part of the path.\n\nIf you enable this policy setting, path information is sent when the user is uploading a file via an HTML form.\n\nIf you disable this policy setting, path information is removed when the user is uploading a file via an HTML form.\n\nIf you do not configure this policy setting, the user can choose whether path information is sent when he or she is uploading a file via an HTML form. By default, path information is sent.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a","displayName":"Include local directory path when uploading files to a server (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonejavapermissions"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe","displayName":"Launching applications and files in an IFRAME (User)","description":"This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone.\n\nIf you enable this policy setting, users can run applications and download files from IFRAMEs on the pages in this zone without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.\n\nIf you disable this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.\n\nIf you do not configure this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonelaunchingapplicationsandfilesiniframe"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804","displayName":"Launching applications and files in an IFRAME (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions","displayName":"Logon options (User)","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Prompt for username and password.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonelogonoptions"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open additional windows and frames from other domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow additional windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open other windows and frames from other domains or access applications from different domains.\n\nIf you do not configure this policy setting, users cannot open other windows and frames from different domains or access applications from different domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonenavigatewindowsandframes"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins","displayName":"Run ActiveX controls and plugins (User)","description":"This policy setting allows you to manage whether ActiveX controls and plug-ins can be run on pages from the specified zone.\n\nIf you enable this policy setting, controls and plug-ins can run without user intervention.\n\nIf you selected Prompt in the drop-down box, users are asked to choose whether to allow the controls or plug-in to run.\n\nIf you disable this policy setting, controls and plug-ins are prevented from running.\n\nIf you do not configure this policy setting, controls and plug-ins are prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonerunactivexcontrolsandplugins"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200","displayName":"Run ActiveX controls and plugins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_65536","displayName":"Administrator approved","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode","displayName":"Run .NET Framework-reliant components signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute signed managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute signed managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute signed managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute signed managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001","displayName":"Run .NET Framework-reliant components signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting","displayName":"Script ActiveX controls marked safe for scripting (User)","description":"This policy setting allows you to manage whether an ActiveX control marked safe for scripting can interact with a script.\n\nIf you enable this policy setting, script interaction can occur automatically without user intervention.\n\nIf you select Prompt in the drop-down box, users are queried to choose whether to allow script interaction.\n\nIf you disable this policy setting, script interaction is prevented from occurring.\n\nIf you do not configure this policy setting, script interaction is prevented from occurring.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_iz_partname1405","displayName":"Script ActiveX controls marked safe for scripting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_iz_partname1405_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_iz_partname1405_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_iz_partname1405_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets","displayName":"Scripting of Java applets (User)","description":"This policy setting allows you to manage whether applets are exposed to scripts within the zone.\n\nIf you enable this policy setting, scripts can access applets automatically without user intervention.\n\nIf you select Prompt in the drop-down box, users are queried to choose whether to allow scripts to access applets.\n\nIf you disable this policy setting, scripts are prevented from accessing applets.\n\nIf you do not configure this policy setting, scripts are prevented from accessing applets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonescriptingofjavaapplets"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402","displayName":"Scripting of Java applets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles","displayName":"Show security warning for potentially unsafe files (User)","description":"This policy setting controls whether or not the \"Open File - Security Warning\" message appears when the user tries to open executable files or other potentially unsafe files (from an intranet file share by using File Explorer, for example).\n\nIf you enable this policy setting and set the drop-down box to Enable, these files open without a security warning. If you set the drop-down box to Prompt, a security warning appears before the files open.\n\nIf you disable this policy setting, these files do not open.\n\nIf you do not configure this policy setting, the user can configure how the computer handles these files. By default, these files are blocked in the Restricted zone, enabled in the Intranet and Local Computer zones, and set to prompt in the Internet and Trusted zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806","displayName":"Launching programs and unsafe files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneturnonprotectedmode"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker","displayName":"Use Pop-up Blocker (User)","description":"This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link are not blocked.\n\nIf you enable this policy setting, most unwanted pop-up windows are prevented from appearing.\n\nIf you disable this policy setting, pop-up windows are not prevented from appearing.\n\nIf you do not configure this policy setting, most unwanted pop-up windows are prevented from appearing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneusepopupblocker"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_iz_partname1809","displayName":"Use Pop-up Blocker (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_iz_partname1809_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_iz_partname1809_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictfiledownloadinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"This policy setting enables blocking of file download prompts that are not user initiated.\n\nIf you enable this policy setting, file download prompts that are not user initiated will be blocked for Internet Explorer processes.\n\nIf you disable this policy setting, prompting will occur for file downloads that are not user initiated for Internet Explorer processes.\n\nIf you do not configure this policy setting, the user's preference determines whether to prompt for file downloads that are not user initiated for Internet Explorer processes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictfiledownloadinternetexplorerprocesses"],"categoryId":"17bc9899-d157-4eac-a949-810b4a841e28","categoryName":"Restrict File Download","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictfiledownloadinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictfiledownloadinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_scriptedwindowsecurityrestrictionsinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"Internet Explorer allows scripts to programmatically open, resize, and reposition windows of various types. The Window Restrictions security feature restricts popup windows and prohibits scripts from displaying windows in which the title and status bars are not visible to the user or obfuscate other Windows' title and status bars.\n\nIf you enable this policy setting, popup windows and other restrictions apply for File Explorer and Internet Explorer processes.\n\nIf you disable this policy setting, scripts can continue to create popup windows and windows that obfuscate other windows.\n\nIf you do not configure this policy setting, popup windows and other restrictions apply for File Explorer and Internet Explorer processes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-scriptedwindowsecurityrestrictionsinternetexplorerprocesses"],"categoryId":"622c83ff-f780-47e6-8b9c-bf82552e3f04","categoryName":"Scripted Window Security Restrictions","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_scriptedwindowsecurityrestrictionsinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_scriptedwindowsecurityrestrictionsinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_searchproviderlist","displayName":"Restrict search providers to a specific list (User)","description":"This policy setting allows you to restrict the search providers that appear in the Search box in Internet Explorer to those defined in the list of policy keys for search providers (found under [HKCU or HKLM\\Software\\policies\\Microsoft\\Internet Explorer\\SearchScopes]). Normally, search providers can be added from third-party toolbars or in Setup, but the user can also add them from a search provider's website.\n\nIf you enable this policy setting, the user cannot configure the list of search providers on his or her computer, and any default providers installed do not appear (including providers installed from other applications). The only providers that appear are those in the list of policy keys for search providers. Note: This list can be created through a custom administrative template file. For information about creating this custom administrative template file, see the Internet Explorer documentation on search providers.\n\nIf you disable or do not configure this policy setting, the user can configure his or her list of search providers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-searchproviderlist"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_searchproviderlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_searchproviderlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_sendsitesnotinenterprisesitelisttoedge","displayName":"Send all sites not included in the Enterprise Mode Site List to Microsoft Edge. (User)","description":"This setting lets you decide whether to open all sites not included in the Enterprise Mode Site List in Microsoft Edge. If you use this setting, you must also turn on the Administrative Templates\\Windows Components\\Internet Explorer\\Use the Enterprise Mode IE website list policy setting and you must include at least one site in the Enterprise Mode Site List.\n\nEnabling this setting automatically opens all sites not included in the Enterprise Mode Site List in Microsoft Edge.\n\nDisabling, or not configuring this setting, opens all sites based on the currently active browser.\n\nNote: If you've also enabled the Administrative Templates\\Windows Components\\Microsoft Edge\\Send all intranet sites to Internet Explorer 11 policy setting, then all intranet sites will continue to open in Internet Explorer 11.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-sendsitesnotinenterprisesitelisttoedge"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_sendsitesnotinenterprisesitelisttoedge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_sendsitesnotinenterprisesitelisttoedge_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_specifyuseofactivexinstallerservice","displayName":"Specify use of ActiveX Installer Service for installation of ActiveX controls (User)","description":"This policy setting allows you to specify how ActiveX controls are installed.\n\nIf you enable this policy setting, ActiveX controls are installed only if the ActiveX Installer Service is present and has been configured to allow the installation of ActiveX controls.\n\nIf you disable or do not configure this policy setting, ActiveX controls, including per-user controls, are installed through the standard installation process.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-specifyuseofactivexinstallerservice"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_specifyuseofactivexinstallerservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_specifyuseofactivexinstallerservice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowaccesstodatasources"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowautomaticpromptingforactivexcontrols"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, users will receive a file download dialog for automatic download attempts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowfontdownloads"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, a warning is issued to the user that potentially risky navigation is about to occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowlessprivilegedsites"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallownetframeworkreliantcomponents"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowscriptlets"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowsmartscreenie"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowuserdatapersistence"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://learn.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneenableprotectedmode"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, users are queried whether to allow the control to be loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions","displayName":"Java permissions (User)","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, the permission is set to Low Safety.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszonejavapermissions"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions","displayName":"Logon options (User)","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon with current username and password.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszonelogonoptions"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszonenavigatewindowsandframes"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_kioskbrowser_blockedurlexceptions","displayName":"Blocked Url Exceptions (User)","description":"List of exceptions to the blocked website URLs (with wildcard support). This is used to configure URLs kiosk browsers are allowed to navigate to, which are a subset of the blocked URLs.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#blockedurlexceptions"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_blockedurls","displayName":"Blocked Urls (User)","description":"List of blocked website URLs (with wildcard support). This is used to configure blocked URLs kiosk browsers can not navigate to.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#blockedurls"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_defaulturl","displayName":"Default URL (User)","description":"Configures the default URL kiosk browsers to navigate on launch and restart.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#defaulturl"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton","displayName":"Enable End Session Button (User)","description":"Enable/disable kiosk browser's end session button.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enableendsessionbutton"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"user_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton_0","displayName":"Disable","description":"Disable","helpText":null}]},{"id":"user_vendor_msft_policy_config_kioskbrowser_enablehomebutton","displayName":"Enable Home Button (User)","description":"Enable/disable kiosk browser's home button.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enablehomebutton"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"user_vendor_msft_policy_config_kioskbrowser_enablehomebutton_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_enablehomebutton_0","displayName":"Disable","description":"Disable","helpText":null}]},{"id":"user_vendor_msft_policy_config_kioskbrowser_enablenavigationbuttons","displayName":"Enable Navigation Buttons (User)","description":"Enable/disable kiosk browser's navigation buttons (forward/back).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enablenavigationbuttons"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"user_vendor_msft_policy_config_kioskbrowser_enablenavigationbuttons_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_enablenavigationbuttons_0","displayName":"Disable","description":"Disable","helpText":null}]},{"id":"user_vendor_msft_policy_config_kioskbrowser_restartonidletime","displayName":"Restart On Idle Time (User)","description":"Amount of time in minutes the session is idle until the kiosk browser restarts in a fresh state.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#restartonidletime"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfigurationmode_1","displayName":"Specify server (User)","description":"\r\nSpecifies how Microsoft Lync identifies the server.\r\n\r\nIf you enable this policy setting, you must specify the server name that Microsoft Lync uses.\r\n\r\nIf you disable this policy setting, Microsoft Lync uses a DNS lookup to identify the server.\r\n\r\nIf you do not configure this policy setting, the user can choose automatic configuration, or the user can specify the name of the server in Microsoft Lync user preferences. To set the user preferences, from the Microsoft Lync Tools menu, click Options, click the Personal tab, within the SIP Communications My Account area click Advanced, select Configure Settings, type the server name in the Server name field.\r\n\r\nNote: You can configure this policy setting under both Computer Configuration and User Configuration, but the policy setting under Computer Configuration takes precedence.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfigurationmode_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfigurationmode_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfigurationmode_1_l_serveraddressexternal_value","displayName":"DNS name of the external server (User)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfigurationmode_1_l_serveraddressinternal_value","displayName":"DNS name of the internal server (User)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1","displayName":"Additional server versions supported (User)","description":"\r\nSpecify a semicolon separated list of server version names, e.g. RTC/2.9;RTC/3.0;RTC/4.0, to which Microsoft Lync allows logon in addition to the server versions that are supported by default. Space character is treated as part of the version string.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1_l_configuredservercheckvalues_value","displayName":"Server version names (semicolon separated list): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1","displayName":"Disable automatic upload of sign-in failure logs (User)","description":"\r\nUploads the sign-in failure logs to the Microsoft Lync Server automatically for analysis. No logs will be automatically uploaded if sign-in is successful.\r\n\r\nIf this policy is not configured, then the following happens: \r\nFor Lync Online Users: Sign-in failure logs are automatically uploaded.\r\nFor Lync On-Premise Users: A confirmation seeking consent from the user is shown before upload.\r\n\r\nWhen this is disabled, sign-in logs would be uploaded to the Microsoft Lync Server for both Lync On-Premise and Online users automatically.\r\n\r\nWhen this is enabled, sign-in logs will never be uploaded automatically.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1","displayName":"Disable HTTP fallback for SIP connection (User)","description":"Prevents from HTTP being used for SIP connection in case TLS or TCP fail.","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablentcredentials_1","displayName":"Require logon credentials (User)","description":"\r\nRequires the user to provide logon credentials for Microsoft Lync rather than automatically using the Windows credentials when Microsoft Lync authenticates the user using NTLM or Kerberos.\r\n\r\nIf you enable this policy setting, Microsoft Lync requires the user to provide logon credentials.\r\n\r\nIf you disable or do not configure this policy setting, Microsoft Lync authenticates the user based on the logon credentials for Windows.\r\n\r\nNote: You can configure this policy setting under both Computer Configuration and User Configuration, but the policy setting under Computer Configuration takes precedence.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablentcredentials_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablentcredentials_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableservercheck_1","displayName":"Disable server version check (User)","description":"Prevents Microsoft Lync from checking the server version before signing in.","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableservercheck_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableservercheck_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablebitsforgaldownload_1","displayName":"Enable using BITS to download Address Book Service files (User)","description":"This policy allows Microsoft Lync to use BITS (Background Intelligent Transfer Service) to download the Address Book Services files.","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablebitsforgaldownload_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablebitsforgaldownload_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablesiphighsecuritymode_1","displayName":"Configure SIP security mode (User)","description":"\r\nWhen Lync connects to the server, it supports various authentication mechanisms. This policy allows the user to specify whether Digest and Basic authentication are supported.\r\n\r\nDisabled (default): NTLM/Kerberos/TLS-DSK/Digest/Basic\r\nEnabled:\r\n Authentication mechanisms: NTLM/Kerberos/TLS-DSK\r\n Gal Download: Requires HTTPS if user is not logged in as an internal user.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablesiphighsecuritymode_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablesiphighsecuritymode_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policygaldownloadinitialdelay_1","displayName":"Global Address Book Download Initial Delay (User)","description":"\r\nWhen set, this will delay the initial download of the Global Address Book by a random number between 0 and the number of minutes specified after sign-in. When the value is 0, the download will begin immediately after sign-in. By default, the value is 60. This means that there will be a random delay between 0 and 60 minutes after sign-in before Lync begins to download the address book.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policygaldownloadinitialdelay_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policygaldownloadinitialdelay_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policygaldownloadinitialdelay_1_l_galdownloadinitialdelay_value","displayName":"Maximum possible number of minutes to delay download: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policypreventrun_1","displayName":"Prevent users from running Microsoft Lync (User)","description":"\r\nPrevents users from running Microsoft Lync.\r\n\r\nIf you enable this policy setting, users cannot run Microsoft Lync.\r\n\r\nIf you disable or do not configure this policy setting, users can run Microsoft Lync.\r\n\r\nNote: You can configure this policy setting under both Computer Configuration and User Configuration, but the policy setting under Computer Configuration takes precedence.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policypreventrun_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policypreventrun_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysavepassword_1","displayName":"Allow storage of user passwords (User)","description":"\r\nAllows Microsoft Lync to store user passwords.\r\n\r\nIf you enable this policy setting, Microsoft Lync can store a password on request from the user.\r\n\r\nIf you disable this policy setting, Microsoft Lync cannot store a password.\r\n\r\nIf you do not configure this policy setting and the user logs on to a domain, Microsoft Lync does not store the password. If you do not configure this policy setting and the user does not log on to a domain (for example, if the user logs on to a workgroup), Microsoft Lync can store the password.\r\n\r\nNote: You can configure this policy setting under both Computer Configuration and User Configuration, but the policy setting under Computer Configuration takes precedence.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysavepassword_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysavepassword_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1","displayName":"Configure SIP compression mode (User)","description":"\r\nDefines when to turn on SIP compression. Default: Based on adaptor speed.\r\n\r\nSetting this policy may cause an increase in sign-in time.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_l_policysipcompression","displayName":"Configure SIP compression mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_l_policysipcompression_0","displayName":"Always disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_l_policysipcompression_1","displayName":"Always enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_l_policysipcompression_2","displayName":"Based on adaptor speed (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1_l_policysipcompression_3","displayName":"Based on ping round-trip time","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_1","displayName":"Trusted Domain List (User)","description":"\r\nWhen Lync connects to an unknown domain, it needs explicit user consent. A dialog is shown asking the user for confirmation on whether it should continue.\r\n\r\nThis policy gives administrators the ability to provide trusted domain names. If a domain name is added to this list, Lync will trust that domain and will not show the dialog requesting permission. Multiple domain addresses as comma separated values can be provided.\r\n\r\nBy setting this policy, Lync will not explicitly trust the default domains specified below. It will exclusively trust the domain specified by the policy.\r\n\r\nSupported values:\r\n Not Configured (Default)/Disabled: By default the following domains will be trusted: \"lync.com, outlook.com, lync.glbdns.microsoft.com, and microsoftonline.com.\"\r\n Enabled: The list of domains to be trusted. For example: \"contoso.com, contoso.co.in\"\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_1_l_trustmodeldata_value","displayName":"Trusted Domains (comma separated list): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder","displayName":"Configure the location of the browser executable folder (User)","description":"This policy configures WebView2 applications to use the WebView2 Runtime in the specified path. The folder should contain the following files: msedgewebview2.exe, msedge.dll, and so on.\r\n\r\nTo set the value for the folder path, provide a Value name and Value pair. Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications.\r\n\r\nExample value:\r\n\r\nName: *, Value: C:\\Program Files\\Microsoft Edge WebView2 Runtime Redistributable 85.0.541.0 x64","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc","displayName":"Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference","displayName":"Set the release channel search order preference (User)","description":"The default channel search order is WebView2 Runtime, Beta, Dev, and Canary.\r\n\r\nTo reverse the default search order, set this policy to 1.\r\n\r\nTo set the value for the release channel preference, provide a Value name and Value pair. Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications.\r\n\r\nExample value:\r\n\r\nName: *, Value: 1","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference_releasechannelpreferencedesc","displayName":"Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference_releasechannelpreferencedesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference_releasechannelpreferencedesc_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service (User)","description":"The Experimentation and Configuration Service is used to deploy Experimentation and Configuration payloads to the client.\r\n\r\nExperimentation payload consists of a list of early in development features that Microsoft is enabling for testing and feedback.\r\n\r\nConfiguration payload consists of a list of recommended settings that Microsoft wants to deploy to optimize the user experience.\r\n\r\nConfiguration payload may also contain a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\r\n\r\nIf you set this policy to 'FullMode', the full payload is downloaded from the Experimentation and Configuration Service. This includes both the experimentation and configuration payloads.\r\n\r\nIf you set this policy to 'ConfigurationsOnlyMode', only the configuration payload is downloaded.\r\n\r\nIf you set this policy to 'RestrictedMode', the communication with the Experimentation and Configuration Service is stopped completely. Microsoft does not recommend this setting.\r\n\r\nIf you don't configure this policy on a managed device, the behavior on Beta and Stable channels is the same as the 'ConfigurationsOnlyMode'. On Canary and Dev channels the behavior is the same as 'FullMode'.\r\n\r\nIf you don't configure this policy on an unmanaged device, the behavior is the same as the 'FullMode'.\r\n\r\nPolicy options mapping:\r\n\r\n* FullMode (2) = Retrieve configurations and experiments\r\n\r\n* ConfigurationsOnlyMode (1) = Retrieve configurations only\r\n\r\n* RestrictedMode (0) = Disable communication with the Experimentation and Configuration Service\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol_2","displayName":"Retrieve configurations and experiments","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol_1","displayName":"Retrieve configurations only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol_0","displayName":"Disable communication with the Experimentation and Configuration Service","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled. (User)","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy.\r\nCurrently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers.\r\nThis enterprise policy can be used to opt out of this gradual deprecation by forcing the default to stay enabled.\r\n\r\nPages might depend on unload event handlers to save data or signal the end of a user session to the server.\r\nThis is not recommended because it's unreliable and impacts performance by blocking use of BackForwardCache.\r\nRecommended alternatives exist, but the unload event has been used for a long time. Some applications might still rely on them.\r\n\r\nIf you disable this policy or don't configure it, unload event handlers will gradually be deprecated in-line with the deprecation rollout and sites which don't set Permissions-Policy header will stop firing `unload` events.\r\n\r\nIf you enable this policy then unload event handlers will continue to work by default.","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_forcepermissionpolicyunloaddefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_forcepermissionpolicyunloaddefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist","displayName":"HTTP Allowlist (User)","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that will not be upgraded to HTTPS and will not show an error interstitial if HTTPS-First Mode is enabled. Organizations can use this policy to maintain access to servers that do not support HTTPS, without needing to disable \"AutomaticHttpsDefault\".\r\n\r\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase.\r\n\r\nBlanket host wildcards (i.e., \"*\" or \"[*]\") are not allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies.\r\n\r\nNote: This policy does not apply to HSTS upgrades.\r\n\r\nExample value:\r\n\r\ntestserver.example.com\r\n[*.]example.org","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_httpallowlistdesc","displayName":"HTTP Allowlist (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_httpallowlistdesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_httpallowlistdesc_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newbaseurlinheritancebehaviorallowed","displayName":"Allows enabling the feature NewBaseUrlInheritanceBehavior (User)","description":"NewBaseUrlInheritanceBehavior is a Microsoft Edge feature that causes about:blank and about:srcdoc frames to consistently inherit their base url values via snapshots of their initiator's base url.\r\n\r\nIf you disable this policy, it prevents users or Microsoft Edge variations from enabling NewBaseUrlInheritanceBehavior, in case compatibility issues are discovered.\r\n\r\nIf you enable or don't configure this policy, it allows enabling NewBaseUrlInheritanceBehavior.","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newbaseurlinheritancebehaviorallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newbaseurlinheritancebehaviorallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newpdfreaderwebview2list","displayName":"Enable built-in PDF reader powered by Adobe Acrobat for WebView2 (User)","description":"This policy configures WebView2 applications to launch the new version of the PDF reader that's powered by Adobe Acrobat's PDF reader. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF file handling, and greater accessibility.\r\n\r\nIf this policy is specified for an application, it is possible that it may impact other related applications as well. The policy is applied to all WebView2s sharing the same WebView2 user data folder. These WebView2s could potentially belong to multiple applications if those applications, which are likely from the same product family, are designed to share the same user data folder.\r\n\r\nUse a name-value pair to enable the new PDF reader for the application. Set the name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications. Set the Value to true to enable the new reader or set it to false to use the existing one.\r\n\r\nIf you enable this policy for the specified WebView2 applications, they will use the new Adobe Acrobat powered PDF reader to open all PDF files.\r\n\r\nIf you disable the policy for the specified WebView2 applications or don't configure it, they will use the existing PDF reader to open all PDF files.\r\n\r\nExample value:\r\n\r\n{\"name\": \"app1.exe\", \"value\": true}\r\n{\"name\": \"app_id_for_app2\", \"value\": true}\r\n{\"name\": \"*\", \"value\": false}","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newpdfreaderwebview2list_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newpdfreaderwebview2list_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newpdfreaderwebview2list_newpdfreaderwebview2listdesc","displayName":"Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newpdfreaderwebview2list_newpdfreaderwebview2listdesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_newpdfreaderwebview2list_newpdfreaderwebview2listdesc_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_rsakeyusageforlocalanchorsenabled","displayName":"Check RSA key usage for server certificates issued by local trust anchors (User)","description":"The X.509 key usage extension declares how the key in a certificate can be\r\nused. These instructions ensure certificates aren't used in an unintended\r\ncontext, which protects against a class of cross-protocol attacks on HTTPS and\r\nother protocols. HTTPS clients must verify that server certificates match the\r\nconnection's TLS parameters.\r\n\r\nIf this policy is enabled,\r\nMicrosoft Edge will perform this key\r\ncheck. This helps prevent attacks where an attacker manipulates the browser into\r\ninterpreting a key in ways that the certificate owner did not intend.\r\n\r\nIf this policy is set to disabled or not configured,\r\nMicrosoft Edge will skip this key check in\r\nHTTPS connections that negotiate TLS 1.2 and use an RSA certificate that\r\nchains to a local trust anchor. Examples of local trust anchors include\r\npolicy-provided or user-installed root certificates. In all other cases, the\r\ncheck is performed independent of this policy's setting.\r\n\r\nThis policy is available for administrators to preview the behavior of a\r\nfuture release, which will enable this check by default. At that point, this\r\npolicy will remain temporarily available for administrators that need more\r\ntime to update their certificates to meet the new RSA key usage requirements.\r\n\r\nConnections that fail this check will fail with the error\r\nERR_SSL_KEY_USAGE_INCOMPATIBLE. Sites that fail with this error likely have a\r\nmisconfigured certificate. Modern ECDHE_RSA cipher suites use the\r\n\"digitalSignature\" key usage option, while legacy RSA decryption cipher suites\r\nuse the \"keyEncipherment\" key usage option. If uncertain, administrators should\r\ninclude both in RSA certificates meant for HTTPS.","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_rsakeyusageforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_rsakeyusageforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_addressbarclipboardsuggestenabled","displayName":"Enable clipboard suggestions in the address bar (User)","description":"This policy controls whether suggestions based on clipboard content are shown in the address bar suggestion dropdown.\n\nIf you enable this policy or don't configure it, Microsoft Edge may show suggestions based on clipboard content in the address bar suggestion dropdown.\n\nIf you disable this policy, Microsoft Edge doesn't show suggestions based on clipboard content in the address bar suggestion dropdown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_addressbarclipboardsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_addressbarclipboardsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowdeletingbrowserhistory","displayName":"Enable deleting browser and download history (User)","description":"Enables deleting browser history and download history and prevents users from changing this setting.\r\n\r\nNote that even with this policy is disabled, the browsing and download history aren't guaranteed to be retained: users can edit or delete the history database files directly, and the browser itself may remove (based on expiration period) or archive any or all history items at any time.\r\n\r\nIf you enable this policy or don't configure it, users can delete the browsing and download history.\r\n\r\nIf you disable this policy, users can't delete browsing and download history.\r\n\r\nIf you enable this policy, don't enable the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) policy, because they both deal with deleting data. If you enable both, the 'ClearBrowsingDataOnExit' policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how this policy is configured.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowdeletingbrowserhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowdeletingbrowserhistory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowfileselectiondialogs","displayName":"Allow file selection dialogs (User)","description":"Allow access to local files by letting Microsoft Edge display file selection dialogs.\r\n\r\nIf you enable or don't configure this policy, users can open file selection dialogs as normal.\r\n\r\nIf you disable this policy, whenever the user performs an action that triggers a file selection dialog (like importing favorites, uploading files, or saving links), a message is displayed instead, and the user is assumed to have clicked Cancel on the file selection dialog.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowfileselectiondialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowfileselectiondialogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowsocketpoolsizerandomizationforproxies","displayName":"Allow socket pool size randomization for proxies (User)","description":"Controls whether Microsoft Edge randomizes socket pool sizes for proxy connections.\n\nSocket pool size randomization is a security mechanism that helps prevent attackers from using deterministic connection limits to infer cross-site information. For example, if the configured proxy socket pool limit is 128, Microsoft Edge can randomly set the effective limit between 128 and 256. This can allow up to twice as many proxy connections, though the expected increase is closer to 1.2x in practice.\n\nThis policy affects the limits configured by the 'MaxConnectionsPerProxy' (Maximum number of concurrent connections to the proxy server for non-WebSocket requests) and 'MaxConnectionsPerProxyForWebSocket' (Maximum number of concurrent connections to the proxy server for WebSocket requests) policies. When this policy is enabled, the effective upper limit can be randomized up to 2x the values configured by those policies.\n\nIf you enable this policy or don't configure it, Microsoft Edge enables socket pool size randomization for proxy connections.\n\nIf you disable this policy, Microsoft Edge disables socket pool size randomization for proxy connections. The values configured by 'MaxConnectionsPerProxy' and 'MaxConnectionsPerProxyForWebSocket' are used as the upper limits without randomization.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowsocketpoolsizerandomizationforproxies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowsocketpoolsizerandomizationforproxies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_alwaysopenpdfexternally","displayName":"Always open PDF files externally (User)","description":"Disables the internal PDF viewer in Microsoft Edge.\r\n\r\nIf you enable this policy Microsoft Edge treats PDF files as downloads and lets users open them with the default application.\r\n\r\nIf you don't configure this policy or disable it, Microsoft Edge will open PDF files (unless the user disables it).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_alwaysopenpdfexternally_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_alwaysopenpdfexternally_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_applicationlocalevalue","displayName":"Set application locale (User)","description":"Configures the application locale in Microsoft Edge and prevents users from changing the locale.\r\n\r\nIf you enable this policy, Microsoft Edge uses the specified locale. If the configured locale isn't supported, 'en-US' is used instead.\r\n\r\nIf you disable or don't configure this setting, Microsoft Edge uses either the user-specified preferred locale (if configured) or the fallback locale 'en-US'.\r\n\r\nExample value: en","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_applicationlocalevalue_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_applicationlocalevalue_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_applicationlocalevalue_applicationlocalevalue","displayName":"Application locale (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowed","displayName":"Allow or block audio capture (User)","description":"Allows you to set whether a user is prompted to grant a website access to their audio capture device. This policy applies to all URLs except for those configured in the 'AudioCaptureAllowedUrls' (Sites that can access audio capture devices without requesting permission) list.\r\n\r\nIf you enable this policy or don't configure it (the default setting), the user is prompted for audio capture access except from the URLs in the 'AudioCaptureAllowedUrls' list. These listed URLs are granted access without prompting.\r\n\r\nIf you disable this policy, the user is not prompted, and audio capture is accessible only to the URLs configured in 'AudioCaptureAllowedUrls'.\r\n\r\nThis policy affects all types of audio inputs, not only the built-in microphone.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls","displayName":"Sites that can access audio capture devices without requesting permission (User)","description":"Specify websites, based on URL patterns, that can use audio capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to audio capture devices. Note, however, that the pattern \"*\", which matches any URL, is not supported by this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com/\r\nhttps://[*.]contoso.edu/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls_audiocaptureallowedurlsdesc","displayName":"Sites that can access audio capture devices without requesting permission (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofilladdressenabled","displayName":"Enable AutoFill for addresses (User)","description":"Enables the AutoFill feature and allows users to auto-complete address information in web forms using previously stored information.\r\n\r\nIf you disable this policy, AutoFill never suggests or fills in address information, nor does it save additional address information that the user might submit while browsing the web.\r\n\r\nIf you enable this policy or don't configure it, users can control AutoFill for addresses in the user interface.\r\n\r\nNote that if you disable this policy you also stop all activity for all web forms, except payment and password forms. No further entries are saved, and Microsoft Edge won't suggest or AutoFill any previous entries.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofilladdressenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofilladdressenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofillcreditcardenabled","displayName":"Enable AutoFill for payment instruments (User)","description":"Enables Microsoft Edge's AutoFill feature and lets users auto complete payment instruments like credit or debit cards in web forms using previously stored information. This includes suggesting new payment instruments like Buy Now Pay Later (BNPL) in web forms and Express Checkout.\r\n\r\nIf you enable this policy or don't configure it, users can control AutoFill for payment instruments.\r\n\r\nIf you disable this policy, AutoFill never suggests, fills, or recommends new payment Instruments. Additionally, it won't save any payment instrument information that users submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofillcreditcardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofillcreditcardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun","displayName":"Automatically import another browser's data and settings at first run (User)","description":"If you enable this policy, all supported datatypes and settings from the specified browser will be silently and automatically imported at first run. During the First Run Experience, the import section will also be skipped.\r\n\r\nThe browser data from Microsoft Edge Legacy will always be silently migrated at the first run, irrespective of the value of this policy. You can use the following values for this policy:\r\n\r\n* 0 = Automatically imports all supported datatypes and settings from the default browser\r\n\r\n* 1 = Automatically imports all supported datatypes and settings from Internet Explorer\r\n\r\n* 2 = Automatically imports all supported datatypes and settings from Google Chrome\r\n\r\n* 3 = Automatically imports all supported datatypes and settings from Safari\r\n\r\n* 4 = Disables automatic import, and the import section of the first-run experience is skipped\r\n\r\n* 5 = Automatically imports all supported datatypes and settings from Mozilla Firefox\r\n\r\nIf this policy is set to the default value (0), then the datatypes corresponding to the default browser on the managed device will be imported.\r\n\r\nIf the browser specified as the value of this policy is not present in the managed device, Microsoft Edge will simply skip the import without any notification to the user.\r\n\r\nIf you set this policy to 'DisabledAutoImport' (4), the import section of the first-run experience is skipped entirely and Microsoft Edge doesn't import browser data and settings automatically.\r\n\r\nIf this policy is set to the value of Internet Explorer (1), the following datatypes will be imported from Internet Explorer:\r\n1. Favorites or bookmarks\r\n2. Saved passwords\r\n3. Search engines\r\n4. Browsing history\r\n5. Home page\r\n\r\nIf this policy is set to the value of Google Chrome (2), the following datatypes will be imported from Google Chrome:\r\n1. Favorites\r\n2. Saved passwords\r\n3. Addresses and more\r\n4. Payment info\r\n5. Browsing history\r\n6. Settings\r\n7. Pinned and Open tabs\r\n8. Extensions\r\n9. Cookies\r\n\r\nNote: For more details on what is imported from Google Chrome, please see https://go.microsoft.com/fwlink/?linkid=2120835\r\n\r\nIf this policy is set to the value of Safari (3), the following datatypes will be imported from Safari:\r\n1. Favorites or bookmarks\r\n2. Browsing history\r\n\r\nStarting with Microsoft Edge version 83, if this policy is set to the value of Mozilla Firefox (5), the following datatypes will be imported from Mozilla Firefox:\r\n1. Favorites or bookmarks\r\n2. Saved passwords\r\n3. Addresses and more\r\n4. Browsing History\r\n\r\nIf you want to restrict specific datatypes from getting imported on the managed devices, you can use this policy with other policies such as 'ImportAutofillFormData' (Allow importing of autofill form data), 'ImportBrowserSettings' (Allow importing of browser settings), 'ImportFavorites' (Allow importing of favorites), and etc.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun","displayName":"Automatically import another browser's data and settings at first run (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_0","displayName":"Automatically imports all supported datatypes and settings from the default browser","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_1","displayName":"Automatically imports all supported datatypes and settings from Internet Explorer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_2","displayName":"Automatically imports all supported datatypes and settings from Google Chrome","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_3","displayName":"Automatically imports all supported datatypes and settings from Safari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_4","displayName":"Disables automatic import, and the import section of the first-run experience is skipped","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_backgroundmodeenabled","displayName":"Continue running background apps after Microsoft Edge closes (User)","description":"Allows Microsoft Edge processes to start at OS sign-in and keep running after the last browser window is closed. In this scenario, background apps and the current browsing session remain active, including any session cookies. An open background process displays an icon in the system tray and can always be closed from there.\r\n\r\nIf you enable this policy, background mode is turned on.\r\n\r\nIf you disable this policy, background mode is turned off.\r\n\r\nIf you don't configure this policy, background mode is initially turned off, and the user can configure its behavior in edge://settings/system.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_backgroundmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_backgroundmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies","displayName":"Block third party cookies (User)","description":"Block web page elements that aren't from the domain that's in the address bar from setting cookies.\r\n\r\nIf you enable this policy, web page elements that are not from the domain that is in the address bar can't set cookies\r\n\r\nIf you disable this policy, web page elements from domains other than in the address bar can set cookies.\r\n\r\nIf you don't configure this policy, third-party cookies are enabled but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browseraddprofileenabled","displayName":"Enable profile creation from the Identity flyout menu or the Settings page (User)","description":"Allows users to create new profiles, using the **Add profile** option.\r\nIf you enable this policy or don't configure it, Microsoft Edge allows users to use **Add profile** on the Identity flyout menu or the Settings page to create new profiles.\r\n\r\nIf you disable this policy, users cannot add new profiles from the Identity flyout menu or the Settings page.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browseraddprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browseraddprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browserguestmodeenabled","displayName":"Enable guest mode (User)","description":"Enable the option to allow the use of guest profiles in Microsoft Edge. In a guest profile, the browser doesn't import browsing data from existing profiles, and it deletes browsing data when all guest profiles are closed.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge lets users browse in guest profiles.\r\n\r\nIf you disable this policy, Microsoft Edge doesn't let users browse in guest profiles.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browserguestmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browserguestmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsernetworktimequeriesenabled","displayName":"Allow queries to a Browser Network Time service (User)","description":"Prevents Microsoft Edge from occasionally sending queries to a browser network time service to retrieve an accurate timestamp.\r\n\r\nIf you disable this policy, Microsoft Edge will stop sending queries to a browser network time service.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will occasionally send queries to a browser network time service.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsernetworktimequeriesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsernetworktimequeriesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin","displayName":"Browser sign-in settings (User)","description":"Specify whether a user can sign into Microsoft Edge with their account and use account-related services like sync and single sign on. To control the availability of sync, use the 'SyncDisabled' (Disable synchronization of data using Microsoft sync services) policy instead.\r\n\r\nIf you set this policy to 'Disable browser sign-in', make sure that you also set the 'NonRemovableProfileEnabled' (Configure whether a user always has a default profile automatically signed in with their work or school account) policy to disabled because 'NonRemovableProfileEnabled' disables the creation of an automatically signed in browser profile. If both policies are set, Microsoft Edge will use the 'Disable browser sign-in' policy and behave as if 'NonRemovableProfileEnabled' is set to disabled.\r\n\r\nIf you set this policy to 'Enable browser sign-in' (1), users can sign into the browser. Signing into the browser doesn't mean that sync is turned on by default; the user must separately opt-in to use this feature.\r\n\r\nIf you set this policy to 'Force browser sign-in' (2) users must sign into a profile to use the browser. By default, this will allow the user to choose whether they want to sync to their account, unless sync is disabled by the domain admin or with the 'SyncDisabled' policy. The default value of 'BrowserGuestModeEnabled' (Enable guest mode) policy is set to false.\r\n\r\nIf you don't configure this policy users can decide if they want to enable the browser sign-in option and use it as they see fit.\r\n\r\n* 0 = Disable browser sign-in\r\n\r\n* 1 = Enable browser sign-in\r\n\r\n* 2 = Force users to sign-in to use the browser","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin_browsersignin","displayName":"Browser sign-in settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin_browsersignin_0","displayName":"Disable browser sign-in","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin_browsersignin_1","displayName":"Enable browser sign-in","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browsersignin_browsersignin_2","displayName":"Force users to sign-in to use the browser","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled","displayName":"Use built-in DNS client (User)","description":"Controls whether to use the built-in DNS client.\r\n\r\nThis does not affect which DNS servers are used; just the software stack which is used to communicate with them. For example if the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It is however possible that the built-in DNS client will address servers in different ways by using more modern DNS-related protocols such as DNS-over-TLS.\r\n\r\nIf you enable this policy, the built-in DNS client is used, if it's available.\r\n\r\nIf you disable this policy, the client is never used.\r\n\r\nIf you don't configure this policy, the built-in DNS client is enabled by default on MacOS, and users can change whether to use the built-in DNS client by editing edge://flags or by specifying a command-line flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes (User)","description":"Disables enforcement of Certificate Transparency requirements for a list of subjectPublicKeyInfo hashes.\r\n\r\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This allows certificates that would otherwise be untrusted because they were not properly publicly disclosed to still be used for Enterprise hosts.\r\n\r\nTo disable Certificate Transparency enforcement when this policy is set, one of the following sets of conditions must be met:\r\n1. The hash is of the server certificate's subjectPublicKeyInfo.\r\n2. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, that CA certificate is constrained via the X.509v3 nameConstraints extension, one or more directoryName nameConstraints are present in the permittedSubtrees, and the directoryName contains an organizationName attribute.\r\n3. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, the CA certificate has one or more organizationName attributes in the certificate Subject, and the server's certificate contains the same number of organizationName attributes, in the same order, and with byte-for-byte identical values.\r\n\r\nA subjectPublicKeyInfo hash is specified by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\r\n\r\nIf you disable this policy or don't configure it, any certificate that's required to be disclosed via Certificate Transparency will be treated as untrusted if it's not disclosed according to the Certificate Transparency policy.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas_certificatetransparencyenforcementdisabledforcasdesc","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforlegacycas","displayName":"Disable Certificate Transparency enforcement for a list of legacy certificate authorities (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 131.\r\n\r\nDisables enforcing Certificate Transparency requirements for a list of legacy certificate authorities (Cas).\r\n\r\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This allows certificates that would otherwise be untrusted because they were not properly publicly disclosed, continue to be used for enterprise hosts.\r\n\r\nIn order for Certificate Transparency enforcement to be disabled, you must set the hash to a subjectPublicKeyInfo appearing in a CA certificate that is recognized as a legacy certificate authority (CA). A legacy CA is a CA that has been publicly trusted by default by one or more operating systems supported by Microsoft Edge.\r\n\r\nYou specify a subjectPublicKeyInfo hash by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\r\n\r\nIf you don't configure this policy, any certificate that's required to be disclosed via Certificate Transparency will be treated as untrusted if it isn't disclosed according to the Certificate Transparency policy.\r\n\r\nThis policy is obsolete because the feature to disable Certificate Transparency enforcement for legacy certificates has been removed.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforlegacycas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforlegacycas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforlegacycas_certificatetransparencyenforcementdisabledforlegacycasdesc","displayName":"Disable Certificate Transparency enforcement for a list of legacy certificate authorities (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforurls","displayName":"Disable Certificate Transparency enforcement for specific URLs (User)","description":"Disables enforcing Certificate Transparency requirements for the listed URLs.\r\n\r\nThis policy lets you not disclose certificates for the hostnames in the specified URLs via Certificate Transparency. This lets you use certificates that would otherwise be untrusted, because they weren't properly publicly disclosed, but it makes it harder to detect mis-issued certificates for those hosts.\r\n\r\nForm your URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322. Because certificates are valid for a given hostname, independent of the scheme, port, or path, only the hostname part of the URL is considered. Wildcard hosts are not supported.\r\n\r\nIf you don't configure this policy, any certificate that should be disclosed via Certificate Transparency is treated as untrusted if it's not disclosed.\r\n\r\nExample value:\r\n\r\ncontoso.com\r\n.contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforurls_certificatetransparencyenforcementdisabledforurlsdesc","displayName":"Disable Certificate Transparency enforcement for specific URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_componentupdatesenabled","displayName":"Enable component updates in Microsoft Edge (User)","description":"If you enable or don't configure this policy, component updates are enabled in Microsoft Edge.\r\n\r\nIf you disable this policy or set it to false, component updates are disabled for all components in Microsoft Edge.\r\n\r\nHowever, some components are exempt from this policy. This includes any component that doesn't contain executable code, that doesn't significantly alter the behavior of the browser, or that's critical for security. That is, updates that are deemed \"critical for security\" are still applied even if you disable this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_componentupdatesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_componentupdatesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_configuredonottrack","displayName":"Configure Do Not Track (User)","description":"Specify whether to send Do Not Track requests to websites that ask for tracking info. Do Not Track requests let the websites you visit know that you don't want your browsing activity to be tracked. By default, Microsoft Edge doesn't send Do Not Track requests, but users can turn on this feature to send them.\r\n\r\nIf you enable this policy, Do Not Track requests are always sent to websites asking for tracking info.\r\n\r\nIf you disable this policy, requests are never sent.\r\n\r\nIf you don't configure this policy, users can choose whether to send these requests.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_configuredonottrack_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_configuredonottrack_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_configureonlinetexttospeech","displayName":"Configure Online Text To Speech (User)","description":"Set whether the browser can leverage Online Text to Speech voice fonts, part of Azure Cognitive Services. These voice fonts are higher quality than the pre-installed system voice fonts.\r\n\r\nIf you enable or don't configure this policy, web-based applications that use the SpeechSynthesis API can use Online Text to Speech voice fonts.\r\n\r\nIf you disable this policy, the voice fonts aren't available.\r\n\r\nRead more about this feature here:\r\nSpeechSynthesis API: https://go.microsoft.com/fwlink/?linkid=2110038\r\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2110141","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_configureonlinetexttospeech_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_configureonlinetexttospeech_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_copilotaddressbarsuggestionsenabled","displayName":"Enable Copilot address bar suggestions (User)","description":"This policy controls whether Copilot chat suggestions appear in the address bar of Microsoft Edge.\n\nIf you enable this policy or don't configure it, Copilot chat suggestions appear in the address bar.\n\nIf you disable this policy, Copilot chat suggestions don't appear in the address bar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_copilotaddressbarsuggestionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_copilotaddressbarsuggestionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride","displayName":"Override for the CPU performance tier (User)","description":"This policy allows you to override the value returned by the CPU Performance API (that is, navigator.cpuPerformance).\n\nIf you enable this policy, the value of navigator.cpuPerformance is overridden with the specified value.\n\nIf you don’t configure this policy, the default performance tier calculation is used.\n\nYou can specify a value from 0 through 4.\n\nFor more information, see https://github.com/WICG/cpu-performance.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride_cpuperformancetieroverride","displayName":"Override for the CPU performance tier: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_dataurlinwebworkeropaqueoriginenabled","displayName":"Enable opaque origins for data URLs in Web Workers (User)","description":"This policy controls whether Web Workers created from data URLs are assigned\na unique opaque origin.\n\nWeb Workers can be created using a data URL that contains the worker script.\nPreviously, these workers inherited the origin of the page that created them,\nwhich allowed them to access the same origin-bound data, such as local\nstorage and cookies.\n\nStarting in Microsoft Edge version\n149, Web Workers created from data URLs are assigned a unique opaque origin\nby default. This behavior improves security and aligns with the HTML\nspecification by isolating these workers from the page that created them.\n\nIf you enable this policy or don't configure it, Web Workers created from\ndata URLs are assigned a unique opaque origin.\n\nIf you disable this policy, Web Workers created from data URLs inherit the\norigin of the page that created them. Use this setting only as a temporary\nmitigation for compatibility issues with internal applications that depend\non the legacy behavior.\n\nThis policy is temporary and will be removed in Microsoft Edge\nversion 157.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_dataurlinwebworkeropaqueoriginenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_dataurlinwebworkeropaqueoriginenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability","displayName":"Control where developer tools can be used (User)","description":"Control where developer tools can be used.\r\n\r\nIf you set this policy to 'DeveloperToolsDisallowedForForceInstalledExtensions' (0, the default), users can access the developer tools and the JavaScript console in general, but not in the context of extensions installed by enterprise policy.\r\n\r\nIf you set this policy to 'DeveloperToolsAllowed' (1), users can access the developer tools and the JavaScript console in all contexts, including extensions installed by enterprise policy.\r\n\r\nIf you set this policy to 'DeveloperToolsDisallowed' (2), users can't access the developer tools or inspect website elements. Keyboard shortcuts and menu or context menu entries that open the developer tools or the JavaScript Console are disabled.\r\n\r\n* 0 = Block the developer tools on extensions installed by enterprise policy, allow in other contexts\r\n\r\n* 1 = Allow using the developer tools\r\n\r\n* 2 = Don't allow using the developer tools","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability","displayName":"Control where developer tools can be used (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability_0","displayName":"Block the developer tools on extensions installed by enterprise policy, allow in other contexts","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability_1","displayName":"Allow using the developer tools","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability_2","displayName":"Don't allow using the developer tools","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disable3dapis","displayName":"Disable support for 3D graphics APIs (User)","description":"Prevent web pages from accessing the graphics processing unit (GPU). Specifically, web pages can't access the WebGL API and plug-ins can't use the Pepper 3D API.\r\n\r\nIf you don't configure or disable this policy, it potentially allows web pages to use the WebGL API and plug-ins to use the Pepper 3D API. Microsoft Edge might, by default, still require command line arguments to be passed in order to use these APIs.\r\n\r\nIf 'HardwareAccelerationModeEnabled' (Use hardware acceleration when available) policy is set to false, the setting for 'Disable3DAPIs' policy is ignored - it's the equivalent of setting 'Disable3DAPIs' policy to true.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disable3dapis_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disable3dapis_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disablescreenshots","displayName":"Disable taking screenshots (User)","description":"Controls if users can take screenshots of the browser page.\r\n\r\nIf enabled, user can't take screenshots by using keyboard shortcuts or extension APIs.\r\n\r\nIf disabled or don't configure this policy, users can take screenshots.\r\n\r\nPlease note this policy controls screenshots taken from within the browser itself. Even if you enable this policy, users might still be able to take screenshots using some method outside of the browser (like using an operating system feature or another application).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disablescreenshots_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disablescreenshots_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir","displayName":"Set disk cache directory (User)","description":"Configures the directory to use to store cached files.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified the '--disk-cache-dir' flag. To avoid data loss or other unexpected errors, don't configure this policy to a volume's root directory or to a directory used for other purposes, because Microsoft Edge manages its contents.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables you can use when specifying directories and paths.\r\n\r\nIf you don't configure this policy, the default cache directory is used, and users can override that default with the '--disk-cache-dir' command line flag.\r\n\r\nExample value: ${user_home}/Edge_cache","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir_diskcachedir","displayName":"Set disk cache directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize","displayName":"Set disk cache size, in bytes (User)","description":"Configures the size of the cache, in bytes, used to store files on the disk.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided cache size regardless of whether the user has specified the '--disk-cache-size' flag. The value specified in this policy isn't a hard boundary but rather a suggestion to the caching system; any value below a few megabytes is too small and will be rounded up to a reasonable minimum.\r\n\r\nIf you set the value of this policy to 0, the default cache size is used, and users can't change it.\r\n\r\nIf you don't configure this policy, the default size is used, but users can override it with the '--disk-cache-size' flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize_diskcachesize","displayName":"Set disk cache size: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory","displayName":"Set download directory (User)","description":"Configures the directory to use when downloading files.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified one or chosen to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\r\n\r\nIf you disable or don't configure this policy, the default download directory is used, and the user can change it.\r\n\r\nIf you set an invalid path, Microsoft Edge will default to the user's default download directory.\r\n\r\nIf the folder specified by the path doesn't exist, the download will trigger a prompt that asks the user where they want to save their download.\r\n\r\nExample value: \r\n Linux-based OSes (including Mac): /home/${user_name}/Downloads\r\n Windows: C:\\Users\\${user_name}\\Downloads","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory_downloaddirectory","displayName":"Set download directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions","displayName":"Allow download restrictions (User)","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'Block dangerous downloads' (1) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings.\r\n\r\nSet 'Block potentially dangerous downloads' (2) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous downloads.\r\n\r\nSet 'Block all downloads' (3) to block all downloads.\r\n\r\nIf you don't configure this policy or set the 'No special restrictions' (0) option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\n* 0 = No special restrictions\r\n\r\n* 1 = Block dangerous downloads\r\n\r\n* 2 = Block potentially dangerous downloads\r\n\r\n* 3 = Block all downloads","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions","displayName":"Download restrictions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_1","displayName":"Block dangerous downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_2","displayName":"Block potentially dangerous downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_edgereadingmodeservicebasedextractionenabled","displayName":"Enable service-based extraction for Reading Mode in Microsoft Edge (User)","description":"This policy controls whether Microsoft Edge can use the Microsoft online extraction service to improve Reading Mode rendering.\n\nIf you enable or don't configure this policy, Microsoft Edge can send the text of the page being read to the service for processing.\n\nIf you disable this policy, Microsoft Edge doesn't send the text of the page being read to the service. Reading Mode remains available, but extraction quality may be limited.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_edgereadingmodeservicebasedextractionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_edgereadingmodeservicebasedextractionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled","displayName":"Allows users to edit favorites (User)","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\r\n\r\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledeprecatedwebplatformfeatures","displayName":"Re-enable deprecated web platform features for a limited time (User)","description":"Specify a list of deprecated web platform features to temporarily re-enable.\r\n\r\nThis policy lets you re-enable deprecated web platform features for a limited time. Features are identified by a string tag.\r\n\r\nIf you don't configure this policy, if the list is empty, or if a feature doesn't match one of the supported string tags, all deprecated web platform features remain disabled.\r\n\r\nWhile the policy itself is supported on the above platforms, the feature it's enabling might not be available on all of those platforms. Not all deprecated Web Platform features can be re-enabled. Only those explicitly listed below can be re-enabled, and only for a limited period of time, which differs per feature. You can review the intent behind the Web Platform feature changes at https://bit.ly/blinkintents.\r\n\r\nThe general format of the string tag is [DeprecatedFeatureName]_EffectiveUntil[yyyymmdd].\r\n\r\n* \"ExampleDeprecatedFeature_EffectiveUntil20080902\" = Enable ExampleDeprecatedFeature API through 2008/09/02\r\n\r\nExample value:\r\n\r\nExampleDeprecatedFeature_EffectiveUntil20080902","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledeprecatedwebplatformfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledeprecatedwebplatformfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledeprecatedwebplatformfeatures_enabledeprecatedwebplatformfeaturesdesc","displayName":"Re-enable deprecated web platform features for a limited time (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledomainactionsdownload","displayName":"Enable Domain Actions Download from Microsoft (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nAlthough this policy is used to enable/disable download of the domain actions list, it doesn't always achieve the desired state. The Experimentation and Configuration Service, which handles the download, has its own group policy to configure what is downloaded from the service. To avoid conflicting states, this policy is being deprecated and will be obsolete in milestone 85 onward. Please use the 'ExperimentationAndConfigurationServiceControl' (Control communication with the Experimentation and Configuration Service) policy instead.\r\n\r\nIn Microsoft Edge, Domain Actions represent a series of compatibility features that help the browser work correctly on the web.\r\n\r\nMicrosoft keeps a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken due to the new User Agent string on Microsoft Edge. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\r\n\r\nWhen the browser starts up and then periodically afterwards, the browser will contact the Experimentation and Configuration Service that contains the most up to date list of compatibility actions to perform. This list is saved locally after it is first retrieved so that subsequent requests will only update the list if the server's copy has changed.\r\n\r\nIf you enable this policy, the list of Domain Actions will continue to be downloaded from the Experimentation and Configuration Service.\r\n\r\nIf you disable this policy, the list of Domain Actions will no longer be downloaded from the Experimentation and Configuration Service.\r\n\r\nIf you don't configure this policy, the list of Domain Actions will continue to be downloaded from the Experimentation and Configuration Service.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledomainactionsdownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledomainactionsdownload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enableonlinerevocationchecks","displayName":"Enable online OCSP/CRL checks (User)","description":"Online revocation checks don't provide a significant security benefit and are disabled by default.\r\n\r\nIf you enable this policy, Microsoft Edge will perform soft-fail, online OCSP/CRL checks. \"Soft fail\" means that if the revocation server can't be reached, the certificate will be considered valid.\r\n\r\nIf you disable the policy or don't configure it, Microsoft Edge won't perform online revocation checks.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enableonlinerevocationchecks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enableonlinerevocationchecks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service (User)","description":"In Microsoft Edge, the Experimentation and Configuration Service is used to deploy Experimentation and Configuration payload.\r\n\r\nExperimentation payload consists of a list of early in development features that Microsoft is enabling for testing and feedback.\r\n\r\nConfiguration payload consists of a list of settings that Microsoft wants to deploy to Microsoft Edge to optimize user experience. For example, configuration payload may specify how often Microsoft Edge sends requests to the Experimentation and Configuration Service to retrieve the newest payload.\r\n\r\nAdditionaly, configuration payload may also contain a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken due to the new User Agent string on Microsoft Edge. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\r\n\r\nIf you set this policy to \"Retrieve configurations and experiments\" mode, the full payload is downloaded from the Experimentation and Configuration Service. This includes both the experimentation and configuration payloads.\r\n\r\nIf you set this policy to \"Retrieve configurations only\" mode, only the configuration payload is delivered.\r\n\r\nIf you set this policy to \"Disable communication with the Experimentation and Configuration Service\" mode, the communication with the Experimentation and Configuration Service is stopped completely.\r\n\r\nIf you don't configure this policy, on a managed device on Stable and Beta channels the behavior is the same as the \"Retrieve configurations only\" mode.\r\n\r\nIf you don't configure this policy, on an unmanaged device the behavior is the same as the \"Retrieve configurations and experiments\" mode.\r\n\r\n* 0 = Disable communication with the Experimentation and Configuration Service\r\n\r\n* 1 = Retrieve configurations only\r\n\r\n* 2 = Retrieve configurations and experiments","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol_2","displayName":"Retrieve configurations and experiments","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol_1","displayName":"Retrieve configurations only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_experimentationandconfigurationservicecontrol_0","displayName":"Disable communication with the Experimentation and Configuration Service","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled","displayName":"Enable favorites bar (User)","description":"Enables or disables the favorites bar.\r\n\r\nIf you enable this policy, users will see the favorites bar.\r\n\r\nIf you disable this policy, users won't see the favorites bar.\r\n\r\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch","displayName":"Enforce Bing SafeSearch (User)","description":"Ensure that queries in Bing web search are done with SafeSearch set to the value specified. Users can't change this setting.\r\n\r\nIf you configure this policy to \"Off\", SafeSearch in Bing search falls back to the bing.com value.\r\n\r\nIf you configure this policy to \"Moderate\", the moderate setting is used in SafeSearch. The moderate setting filters adult videos and images but not text from search results.\r\n\r\nIf you configure this policy to \"Strict\", the strict setting in SafeSearch is used. The strict setting filters adult text, images, and videos.\r\n\r\nIf you disable this policy or don't configure it, SafeSearch in Bing search isn't enforced, and users can set the value they want on bing.com.\r\n\r\n* 0 = Don't configure search restrictions in Bing\r\n\r\n* 1 = Configure moderate search restrictions in Bing\r\n\r\n* 2 = Configure strict search restrictions in Bing","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch","displayName":"Enforce Bing SafeSearch (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch_0","displayName":"Don't configure search restrictions in Bing","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch_1","displayName":"Configure moderate search restrictions in Bing","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch_2","displayName":"Configure strict search restrictions in Bing","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceephemeralprofiles","displayName":"Enable use of ephemeral profiles (User)","description":"Controls whether user profiles are switched to ephemeral mode. An ephemeral profile is created when a session begins, is deleted when the session ends, and is associated with the user's original profile.\r\n\r\nIf you enable this policy, profiles run in ephemeral mode. This lets users work from their own devices without saving browsing data to those devices. If you enable this policy as an OS policy (by using GPO on Windows, for example), it applies to every profile on the system.\r\n\r\nIf you disable this policy or don't configure it, users get their regular profiles when they sign in to the browser.\r\n\r\nIn ephemeral mode, profile data is saved on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies, and web databases aren't saved after the browser is closed. This doesn't prevent a user from manually downloading any data to disk, or from saving pages or printing them. If the user has enabled sync, all data is preserved in their sync accounts just like with regular profiles. Users can also use InPrivate browsing in ephemeral mode unless you explicitly disable this.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceephemeralprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceephemeralprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcegooglesafesearch","displayName":"Enforce Google SafeSearch (User)","description":"Forces queries in Google Web Search to be performed with SafeSearch set to active, and prevents users from changing this setting.\r\n\r\nIf you enable this policy, SafeSearch in Google Search is always active.\r\n\r\nIf you disable this policy or don't configure it, SafeSearch in Google Search isn't enforced.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcegooglesafesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcegooglesafesearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode (User)","description":"Enforces a minimum Restricted Mode on YouTube and prevents users from picking a less restricted mode.\r\n\r\nSet to Strict (2) to enforce Strict Restricted Mode on YouTube.\r\n\r\nSet to Moderate (1) to enforce the user to only use Moderate Restricted Mode and Strict Restricted Mode on YouTube. They can't disable Restricted Mode.\r\n\r\nSet to Off (0) or don't configure this policy to not enforce Restricted Mode on YouTube. External policies such as YouTube policies might still enforce Restricted Mode.\r\n\r\n* 0 = Do not enforce Restricted Mode on YouTube\r\n\r\n* 1 = Enforce at least Moderate Restricted Mode on YouTube\r\n\r\n* 2 = Enforce Strict Restricted Mode for YouTube","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_forceyoutuberestrict_0","displayName":"Do not enforce Restricted Mode on YouTube","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_forceyoutuberestrict_1","displayName":"Enforce at least Moderate Restricted Mode on YouTube","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_forceyoutuberestrict_2","displayName":"Enforce Strict Restricted Mode for YouTube","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_fullscreenallowed","displayName":"Allow full screen mode (User)","description":"Set the availability of full screen mode - all Microsoft Edge UI is hidden and only web content is visible.\r\n\r\nIf you enable this policy or don't configure it, the user, apps, and extensions with appropriate permissions can enter full screen mode.\r\n\r\nIf you disable this policy, users, apps, and extensions can't enter full screen mode.\r\n\r\nOpening Microsoft Edge in kiosk mode using the command line is unavailable when full screen mode is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_fullscreenallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_fullscreenallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_hardwareaccelerationmodeenabled","displayName":"Use hardware acceleration when available (User)","description":"Specify to use hardware acceleration, if it's available. If you enable this policy or don't configure it, hardware acceleration is enabled unless a GPU feature is explicitly blocked.\r\n\r\nIf you disable this policy, hardware acceleration is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_hardwareaccelerationmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_hardwareaccelerationmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importautofillformdata","displayName":"Allow importing of autofill form data (User)","description":"Allows users to import autofill form data from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the option to manually import autofill data is automatically selected.\r\n\r\nIf you disable this policy, autofill form data isn't imported at first run, and users can't import it manually.\r\n\r\nIf you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge will import autofill data on first run, but users can select or clear **autofill data** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS) and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importautofillformdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importautofillformdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importfavorites","displayName":"Allow importing of favorites (User)","description":"Allows users to import favorites from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Favorites** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, favorites aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importfavorites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importfavorites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importhistory","displayName":"Allow importing of browsing history (User)","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browsing history** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browsing history data isn't imported at first run, and users can’t import this data manually.\r\n\r\nIf you don’t configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importhistory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importhomepage","displayName":"Allow importing of home page settings (User)","description":"Allows users to import their home page setting from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the option to manually import the home page setting is automatically selected.\r\n\r\nIf you disable this policy, the home page setting isn’t imported at first run, and users can’t import it manually.\r\n\r\nIf you don’t configure this policy, the home page setting is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports the home page setting on first run, but users can select or clear the **home page** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importpaymentinfo","displayName":"Allow importing of payment info (User)","description":"Allows users to import payment info from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, payment info isn’t imported at first run, and users can’t import it manually.\r\n\r\nIf you don’t configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import.\r\n\r\n**Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importpaymentinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importpaymentinfo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsavedpasswords","displayName":"Allow importing of saved passwords (User)","description":"Allows users to import saved passwords from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the option to manually import saved passwords is automatically selected.\r\n\r\nIf you disable this policy, saved passwords aren't imported on first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsavedpasswords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsavedpasswords_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsearchengine","displayName":"Allow importing of search engine settings (User)","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\r\n\r\nIf you enable, this policy, the option to import search engine settings is automatically selected.\r\n\r\nIf you disable this policy, search engine settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsearchengine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsearchengine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability","displayName":"Configure InPrivate mode availability (User)","description":"Specifies whether the user can open pages in InPrivate mode in Microsoft Edge.\r\n\r\nIf you don't configure this policy or set it to 'Enabled' (0), users can open pages in InPrivate mode.\r\n\r\nSet this policy to 'Disable' (1) to stop users from using InPrivate mode.\r\n\r\nSet this policy to 'Forced' (2) to always use InPrivate mode.\r\n\r\n* 0 = InPrivate mode available\r\n\r\n* 1 = InPrivate mode disabled\r\n\r\n* 2 = InPrivate mode forced","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_inprivatemodeavailability","displayName":"Configure InPrivate mode availability (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_inprivatemodeavailability_0","displayName":"InPrivate mode available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_inprivatemodeavailability_1","displayName":"InPrivate mode disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_inprivatemodeavailability_2","displayName":"InPrivate mode forced","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel","displayName":"Configure Internet Explorer integration (User)","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210\r\n\r\n* 0 = None\r\n\r\n* 1 = Internet Explorer mode\r\n\r\n* 2 = Internet Explorer 11","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_internetexplorerintegrationlevel","displayName":"Configure Internet Explorer integration (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_internetexplorerintegrationlevel_1","displayName":"Internet Explorer mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_internetexplorerintegrationlevel_2","displayName":"Internet Explorer 11","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins","displayName":"Enable site isolation for specific origins (User)","description":"Specify origins to run in isolation, in their own process.\r\nThis policy also isolates origins named by subdomains - for example, specifying https://contoso.com/ will cause https://foo.contoso.com/ to be isolated as part of the https://contoso.com/ site.\r\nIf the policy is enabled, each of the named origins in a comma-separated list will run in its own process.\r\nIf you disable this policy, then both the 'IsolateOrigins' and 'SitePerProcess' features are disabled. Users can still enable 'IsolateOrigins' policy manually, via command line flags.\r\nIf you don't configure the policy, the user can change this setting.\r\n\r\nExample value: https://contoso.com/,https://fabrikam.com/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins_isolateorigins","displayName":"Enable site isolation for specific origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites","displayName":"Configure favorites (User)","description":"Configures a list of managed favorites.\r\n\r\nThe policy creates a list of favorites. Each favorite contains the keys \"name\" and \"url,\" which hold the favorite's name and its target. You can configure a subfolder by defining a favorites without an \"url\" key but with an additional \"children\" key that contains a list of favorites as defined above (some of which may be folders again). Microsoft Edge amends incomplete URLs as if they were submitted via the Address Bar, for example \"microsoft.com\" becomes \"https://microsoft.com/\".\r\n\r\nThese favorites are placed in a folder that can't be modified by the user (but the user can choose to hide it from the favorites bar). By default the folder name is \"Managed favorites\" but you can change it by adding to the list of favorites a dictionary containing the key \"toplevel_name\" with the desired folder name as the value.\r\n\r\nManaged favorites are not synced to the user account and can't be modified by extensions.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"toplevel_name\": \"My managed favorites folder\"\r\n }, \r\n {\r\n \"url\": \"microsoft.com\", \r\n \"name\": \"Microsoft\"\r\n }, \r\n {\r\n \"url\": \"bing.com\", \r\n \"name\": \"Bing\"\r\n }, \r\n {\r\n \"name\": \"Microsoft Edge links\", \r\n \"children\": [\r\n {\r\n \"url\": \"www.microsoftedgeinsider.com\", \r\n \"name\": \"Microsoft Edge Insiders\"\r\n }, \r\n {\r\n \"url\": \"www.microsoft.com/windows/microsoft-edge\", \r\n \"name\": \"Microsoft Edge\"\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites_managedfavorites","displayName":"Configure favorites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines","displayName":"Manage Search Engines (User)","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine.\r\nYou do not need to specify the encoding. Starting in Microsoft Edge 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge 80.\r\n\r\nStarting in Microsoft Edge 83, you can enable search engine discovery with the allow_search_engine_discovery optional parameter. This parameter must be the first item in the list. If allow_search_engine_discovery is not specified, search engine discovery will be disabled by default.\r\n\r\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\r\n\r\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\r\n\r\nIf the 'DefaultSearchProviderSearchURL' (Default search provider search URL) policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allow_search_engine_discovery\": true\r\n }, \r\n {\r\n \"is_default\": true, \r\n \"suggest_url\": \"https://www.example1.com/qbox?query={searchTerms}\", \r\n \"search_url\": \"https://www.example1.com/search?q={searchTerms}\", \r\n \"name\": \"Example1\", \r\n \"keyword\": \"example1.com\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example2.com/qbox?query={searchTerms}\", \r\n \"image_search_url\": \"https://www.example2.com/images/detail/search?iss=sbiupload\", \r\n \"name\": \"Example2\", \r\n \"keyword\": \"example2.com\", \r\n \"image_search_post_params\": \"content={imageThumbnail},url={imageURL},sbisrc={SearchSource}\", \r\n \"search_url\": \"https://www.example2.com/search?q={searchTerms}\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example3.com/qbox?query={searchTerms}\", \r\n \"image_search_url\": \"https://www.example3.com/images/detail/search?iss=sbiupload\", \r\n \"name\": \"Example3\", \r\n \"keyword\": \"example3.com\", \r\n \"encoding\": \"UTF-8\", \r\n \"search_url\": \"https://www.example3.com/search?q={searchTerms}\"\r\n }, \r\n {\r\n \"search_url\": \"https://www.example4.com/search?q={searchTerms}\", \r\n \"name\": \"Example4\", \r\n \"keyword\": \"example4.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines_managedsearchengines","displayName":"Manage Search Engines (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_maxconnectionsperproxy","displayName":"Maximum number of concurrent connections to the proxy server (User)","description":"Specifies the maximum number of simultaneous connections to the proxy server.\r\n\r\nSome proxy servers can't handle a high number of concurrent connections per client - you can solve this by setting this policy to a lower value.\r\n\r\nThe value of this policy should be lower than 100 and higher than 6. The default value is 32.\r\n\r\nSome web apps are known to consume many connections with hanging GETs - lowering the maximum connections below 32 may lead to browser networking hangs if too many of these kind of web apps are open.\r\n\r\nIf you don't configure this policy, the default value (32) is used.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_maxconnectionsperproxy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_maxconnectionsperproxy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_maxconnectionsperproxy_maxconnectionsperproxy","displayName":"Maximum number of concurrent connections to the proxy server: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_mediaroutercastallowallips","displayName":"Allow Google Cast to connect to Cast devices on all IP addresses (User)","description":"Enable this policy to let Google Cast connect to Cast devices on all IP addresses, not just RFC1918/RFC4193 private addresses.\r\n\r\nDisable this policy to restrict Google Cast to Cast devices on RFC1918/RFC4193 private addresses.\r\n\r\nIf you don't configure this policy, Google Cast connects to Cast devices on RFC1918/RFC4193 private addresses only, unless you enable the CastAllowAllIPs feature.\r\n\r\nIf the 'EnableMediaRouter' (Enable Google Cast) policy is disabled, then this policy has no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_mediaroutercastallowallips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_mediaroutercastallowallips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_metricsreportingenabled","displayName":"Enable usage and crash-related data reporting (User)","description":"This policy enables reporting of usage and crash-related data about Microsoft Edge to Microsoft.\r\n\r\nEnable this policy to send reporting of usage and crash-related data to Microsoft. Disable this policy to not send the data to Microsoft. In both cases, users can't change or override the setting.\r\n\r\nOn Windows 10, Beta and Stable channels, if you don’t configure this policy, Microsoft Edge will default to the Windows diagnostic data setting. If you enable this policy, Microsoft Edge will only send usage data if the Windows Diagnostic data setting is set to Enhanced or Full. If you disable this policy, Microsoft Edge will not send usage data. Crash-related data is sent based on the Windows Diagnostic data setting. Learn more about Windows Diagnostic data settings at https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nOn Windows 10, Canary and Dev channels, this policy controls sending usage data. If this policy is not configured, Microsoft Edge will default to the user's preference. Crash-related data is sent based on the Windows Diagnostic data setting. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nOn Windows 7, 8, and macOS, this policy controls sending usage and crash-related data. If you don’t configure this policy, Microsoft Edge will default to the user's preference.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_metricsreportingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_metricsreportingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions","displayName":"Enable network prediction (User)","description":"Enables network prediction and prevents users from changing this setting.\r\n\r\nThis controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages.\r\n\r\nIf you don't configure this policy, network prediction is enabled but the user can change it.\r\n\r\n* 0 = Predict network actions on any network connection\r\n\r\n* 2 = Don't predict network actions on any network connection","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions","displayName":"Enable network prediction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions_2","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin","displayName":"Control where security restrictions on insecure origins apply (User)","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*.contoso.com\") for which security restrictions on insecure origins don't apply.\r\n\r\nThis policy lets you specify allowed origins for legacy applications that can't deploy TLS or set up a staging server for internal web development so that developers can test out features requiring secure contexts without having to deploy TLS on the staging server. This policy also prevents the origin from being labeled \"Not Secure\" in the omnibox.\r\n\r\nSetting a list of URLs in this policy has the same effect as setting the command-line flag '--unsafely-treat-insecure-origin-as-secure' to a comma-separated list of the same URLs. If you enable this policy, it overrides the command-line flag.\r\n\r\nFor more information on secure contexts, see https://www.w3.org/TR/secure-contexts/.\r\n\r\nExample value:\r\n\r\nhttp://testserver.contoso.com/\r\n*.contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin_overridesecurityrestrictionsoninsecureorigindesc","displayName":"Control where security restrictions on insecure origins apply (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_proactiveauthenabled","displayName":"Enable Proactive Authentication (User)","description":"Lets you configure whether to turn on Proactive Authentication.\r\n\r\nIf you enable this policy, Microsoft Edge tries to proactively authenticate the signed-in user with Microsoft services. At regular intervals, Microsoft Edge checks with an online service for an updated manifest that contains the configuration that governs how to do this.\r\n\r\nIf you disable this policy, Microsoft Edge doesn't try to proactively authenticate the signed-in user with Microsoft services. Microsoft Edge no longer checks with an online service for an updated manifest that contains the configuration for doing this.\r\n\r\nIf you don't configure this policy, Proactive Authentication is turned on.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_proactiveauthenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_proactiveauthenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_processisolationenabled","displayName":"Enable Process Isolation (User)","description":"This policy controls Process Isolation in Microsoft Edge.\n\nWhen this policy is enabled, Microsoft Edge uses Process Isolation to help improve browser security by preventing authorized applications on the device from reading or modifying the contents of Microsoft Edge's running processes. This also helps prevent other applications from accessing encrypted data used by Microsoft Edge.\n\nEnabling Process Isolation may cause incompatibilities with third party applications that rely on being able to inject or tamper with Microsoft Edge's processes, such as antivirus, screen reader or window manager applications.\n\nSetting the policy to Enabled turns on process isolation in Microsoft Edge.\n\nSetting the policy to Disabled turns off process isolation in Microsoft Edge.\n\nIf this policy is unset, Microsoft Edge will follow the default rollout process for the Process Isolation feature, which means that the feature will be gradually rolled out to an increasing number of users.\n\nNote: This policy is applied when Microsoft Edge starts. If the policy is changed while Microsoft Edge is running, the new setting will take effect on the next restart.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_processisolationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_processisolationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_promotionaltabsenabled","displayName":"Enable full-tab promotional content (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nControl the presentation of full-tab promotional or educational content. This setting controls the presentation of welcome pages that help users sign into Microsoft Edge, choose their default browser, or learn about product features.\r\n\r\nIf you enable this policy (set it true) or don't configure it, Microsoft Edge can show full-tab content to users to provide product information.\r\n\r\nIf you disable (set to false) this policy, Microsoft Edge can't show full-tab content to users.\r\n\r\nThis is deprecated - use ShowRecommendationsEnabled instead.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_promotionaltabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_promotionaltabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_promptfordownloadlocation","displayName":"Ask where to save downloaded files (User)","description":"Set whether to ask where to save a file before downloading it.\r\n\r\nIf you enable this policy, the user is asked where to save each file before downloading; if you don't configure it, files are saved automatically to the default location, without asking the user.\r\n\r\nIf you don't configure this policy, the user will be able to change this setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_promptfordownloadlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_promptfordownloadlocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_quicallowed","displayName":"Allow QUIC protocol (User)","description":"Allows use of the QUIC protocol in Microsoft Edge.\r\n\r\nIf you enable this policy or don't configure it, the QUIC protocol is allowed.\r\n\r\nIf you disable this policy, the QUIC protocol is blocked.\r\n\r\nQUIC is a transport layer network protocol that can improve performance of web applications that currently use TCP.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_quicallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_quicallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_addressbarclipboardsuggestenabled_recommended","displayName":"Enable clipboard suggestions in the address bar (User)","description":"This policy controls whether suggestions based on clipboard content are shown in the address bar suggestion dropdown.\n\nIf you enable this policy or don't configure it, Microsoft Edge may show suggestions based on clipboard content in the address bar suggestion dropdown.\n\nIf you disable this policy, Microsoft Edge doesn't show suggestions based on clipboard content in the address bar suggestion dropdown.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_addressbarclipboardsuggestenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_addressbarclipboardsuggestenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended","displayName":"Set application locale (User)","description":"Configures the application locale in Microsoft Edge and prevents users from changing the locale.\r\n\r\nIf you enable this policy, Microsoft Edge uses the specified locale. If the configured locale isn't supported, 'en-US' is used instead.\r\n\r\nIf you disable or don't configure this setting, Microsoft Edge uses either the user-specified preferred locale (if configured) or the fallback locale 'en-US'.\r\n\r\nExample value: en","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended_applicationlocalevalue","displayName":"Application locale (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_autofilladdressenabled_recommended","displayName":"Enable AutoFill for addresses (User)","description":"Enables the AutoFill feature and allows users to auto-complete address information in web forms using previously stored information.\r\n\r\nIf you disable this policy, AutoFill never suggests or fills in address information, nor does it save additional address information that the user might submit while browsing the web.\r\n\r\nIf you enable this policy or don't configure it, users can control AutoFill for addresses in the user interface.\r\n\r\nNote that if you disable this policy you also stop all activity for all web forms, except payment and password forms. No further entries are saved, and Microsoft Edge won't suggest or AutoFill any previous entries.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_autofilladdressenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_autofilladdressenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_autofillcreditcardenabled_recommended","displayName":"Enable AutoFill for credit cards (User)","description":"Enables Microsoft Edge's AutoFill feature and lets users auto complete credit card information in web forms using previously stored information.\r\n\r\nIf you disable this policy, AutoFill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.\r\n\r\nIf you enable this policy or don't configure it, users can control AutoFill for credit cards.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_autofillcreditcardenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_autofillcreditcardenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_backgroundmodeenabled_recommended","displayName":"Continue running background apps after Microsoft Edge closes (User)","description":"Allows Microsoft Edge processes to start at OS sign-in and keep running after the last browser window is closed. In this scenario, background apps and the current browsing session remain active, including any session cookies. An open background process displays an icon in the system tray and can always be closed from there.\r\n\r\nIf you enable this policy, background mode is turned on.\r\n\r\nIf you disable this policy, background mode is turned off.\r\n\r\nIf you don't configure this policy, background mode is initially turned off, and the user can configure its behavior in edge://settings/system.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_backgroundmodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_backgroundmodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_blockthirdpartycookies_recommended","displayName":"Block third party cookies (User)","description":"Block web page elements that aren't from the domain that's in the address bar from setting cookies.\r\n\r\nIf you enable this policy, web page elements that are not from the domain that is in the address bar can't set cookies\r\n\r\nIf you disable this policy, web page elements from domains other than in the address bar can set cookies.\r\n\r\nIf you don't configure this policy, third-party cookies are enabled but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_blockthirdpartycookies_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_blockthirdpartycookies_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloaddirectory_recommended","displayName":"Set download directory (User)","description":"Configures the directory to use when downloading files.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified one or chosen to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\r\n\r\nIf you disable or don't configure this policy, the default download directory is used, and the user can change it.\r\n\r\nIf you set an invalid path, Microsoft Edge will default to the user's default download directory.\r\n\r\nIf the folder specified by the path doesn't exist, the download will trigger a prompt that asks the user where they want to save their download.\r\n\r\nExample value: \r\n Linux-based OSes (including Mac): /home/${user_name}/Downloads\r\n Windows: C:\\Users\\${user_name}\\Downloads","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloaddirectory_recommended_downloaddirectory","displayName":"Set download directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended","displayName":"Allow download restrictions (User)","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'Block dangerous downloads' (1) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings.\r\n\r\nSet 'Block potentially dangerous downloads' (2) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous downloads.\r\n\r\nSet 'Block all downloads' (3) to block all downloads.\r\n\r\nIf you don't configure this policy or set the 'No special restrictions' (0) option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\n* 0 = No special restrictions\r\n\r\n* 1 = Block dangerous downloads\r\n\r\n* 2 = Block potentially dangerous downloads\r\n\r\n* 3 = Block all downloads","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions","displayName":"Download restrictions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_1","displayName":"Block dangerous downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_2","displayName":"Block potentially dangerous downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_favoritesbarenabled_recommended","displayName":"Enable favorites bar (User)","description":"Enables or disables the favorites bar.\r\n\r\nIf you enable this policy, users will see the favorites bar.\r\n\r\nIf you disable this policy, users won't see the favorites bar.\r\n\r\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_favoritesbarenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_favoritesbarenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importautofillformdata_recommended","displayName":"Allow importing of autofill form data (User)","description":"Allows users to import autofill form data from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the option to manually import autofill data is automatically selected.\r\n\r\nIf you disable this policy, autofill form data isn't imported at first run, and users can't import it manually.\r\n\r\nIf you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge will import autofill data on first run, but users can select or clear **autofill data** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS) and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importautofillformdata_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importautofillformdata_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended","displayName":"Allow importing of favorites (User)","description":"Allows users to import favorites from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Favorites** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, favorites aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importhistory_recommended","displayName":"Allow importing of browsing history (User)","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browsing history** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browsing history data isn't imported at first run, and users can’t import this data manually.\r\n\r\nIf you don’t configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importhistory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importhistory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importpaymentinfo_recommended","displayName":"Allow importing of payment info (User)","description":"Allows users to import payment info from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, payment info isn’t imported at first run, and users can’t import it manually.\r\n\r\nIf you don’t configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import.\r\n\r\n**Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importpaymentinfo_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importpaymentinfo_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsavedpasswords_recommended","displayName":"Allow importing of saved passwords (User)","description":"Allows users to import saved passwords from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the option to manually import saved passwords is automatically selected.\r\n\r\nIf you disable this policy, saved passwords aren't imported on first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsavedpasswords_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsavedpasswords_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsearchengine_recommended","displayName":"Allow importing of search engine settings (User)","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\r\n\r\nIf you enable, this policy, the option to import search engine settings is automatically selected.\r\n\r\nIf you disable this policy, search engine settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsearchengine_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsearchengine_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended","displayName":"Enable network prediction (User)","description":"Enables network prediction and prevents users from changing this setting.\r\n\r\nThis controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages.\r\n\r\nIf you don't configure this policy, network prediction is enabled but the user can change it.\r\n\r\n* 0 = Predict network actions on any network connection\r\n\r\n* 2 = Don't predict network actions on any network connection","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended_networkpredictionoptions","displayName":"Enable network prediction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_networkpredictionoptions_recommended_networkpredictionoptions_2","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_resolvenavigationerrorsusewebservice_recommended","displayName":"Enable resolution of navigation errors using a web service (User)","description":"Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi.\r\n\r\nIf you enable this policy, a web service is used for network connectivity tests.\r\n\r\nIf you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues.\r\n\r\n**Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_resolvenavigationerrorsusewebservice_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_resolvenavigationerrorsusewebservice_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_searchsuggestenabled_recommended","displayName":"Enable search suggestions (User)","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\r\n\r\nIf you enable this policy, web search suggestions are used.\r\n\r\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\r\n\r\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_searchsuggestenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_searchsuggestenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended","displayName":"Disable synchronization of data using Microsoft sync services (User)","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\r\n\r\nIf you don't set this policy or apply it as recommended, users will be able to turn sync on or off. If you apply this policy as mandatory, users will not be able to turn sync on.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_translateenabled_recommended","displayName":"Enable Translate (User)","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\r\n\r\nIf you enable this policy, Microsoft Edge offers translation functionality to the user by showing an integrated translate flyout when appropriate, and a translate option on the right-click context menu.\r\n\r\nDisable this policy to disable all built-in translate features.\r\n\r\nIf you don't configure the policy, users can choose whether to use the translation functionality or not.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_translateenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_translateenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended","displayName":"Register protocol handlers (User)","description":"Register a list of protocol handlers. Set the protocol property to the scheme (like 'mailto') and the url property to the URL pattern of the application that handles the scheme. The pattern can include a '%s', which will be replaced by the handled URL.\r\n\r\nYou can recommend a specific value for this policy, but you can't require that your users use it.\r\n\r\nThe protocol handlers registered by policy are merged with any handlers registered by the user, and both are available for use. The user can override the protocol handlers installed by policy by installing a new default handler, but they can't remove a protocol handler registered by policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://mail.contoso.com/mail/?extsrc=mailto&url=%s\", \r\n \"default\": true, \r\n \"protocol\": \"mailto\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"0d4cf1d9-d8ad-4628-bd71-fa0de6598f28","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_registeredprotocolhandlers","displayName":"Register protocol handlers (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0d4cf1d9-d8ad-4628-bd71-fa0de6598f28","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmanagerenabled_recommended","displayName":"Enable saving passwords to the password manager (User)","description":"Enable Microsoft Edge to save user passwords.\r\n\r\nIf you enable this policy, users can save their passwords in Microsoft Edge. The next time they visit the site, Microsoft Edge will enter the password automatically.\r\n\r\nIf you disable this policy, users can't save new passwords, but they can still use previously saved passwords.\r\n\r\nIf you enable or disable this policy, users can't change or override it in Microsoft Edge. If you don't configure it, users can save passwords, as well as turn this feature off.","helpText":"","infoUrls":[],"categoryId":"a877a2ff-f144-421f-814c-593e972a8a20","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmanagerenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmanagerenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printheaderfooter_recommended","displayName":"Print headers and footers (User)","description":"Force 'headers and footers' to be on or off in the printing dialog.\r\n\r\nIf you don't configure this policy, users can decide whether to print headers and footers.\r\n\r\nIf you disable this policy, users can't print headers and footers.\r\n\r\nIf you enable this policy, users always print headers and footers.","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printheaderfooter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printheaderfooter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended","displayName":"Set the system default printer as the default printer (User)","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\r\n\r\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\r\n\r\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenenabled_recommended","displayName":"Configure Microsoft Defender SmartScreen (User)","description":"This policy setting lets you configure whether to turn on Microsoft Defender SmartScreen. Microsoft Defender SmartScreen provides warning messages to help protect your users from potential phishing scams and malicious software. By default, Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you enable this setting, Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepageisnewtabpage_recommended","displayName":"Set the new tab page as the home page (User)","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\r\n\r\nIf you enable this policy, the new tab page is always used for the home page, and the home page URL location is ignored.\r\n\r\nIf you disable this policy, the user's home page can't be the new tab page, unless the URL is set to 'edge://newtab'.\r\n\r\nIf not configured users can choose whether the new tab page is their home page.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepageisnewtabpage_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepageisnewtabpage_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepagelocation_recommended","displayName":"Configure the home page URL (User)","description":"Configures the default home page URL in Microsoft Edge.\r\n\r\nThe home page is the page opened by the Home button. The pages that open on startup are controlled by the 'RestoreOnStartup' (Action to take on startup) policies.\r\n\r\nYou can either set a URL here or set the home page to open the new tab page. If you select to open the new tab page, then this policy doesn't take effect.\r\n\r\nIf you enable this policy, users can't change their home page URL, but they can choose to use the new tab page as their home page.\r\n\r\nIf you disable or don't configure this policy, users can choose their own home page, as long as the 'HomepageIsNewTabPage' (Set the new tab page as the home page) policy isn't enabled.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\nExample value: https://www.contoso.com","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepagelocation_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepagelocation_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepagelocation_recommended_homepagelocation","displayName":"Home page URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended","displayName":"Configure the new tab page URL (User)","description":"Configures the default URL for the new tab page.\r\n\r\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\r\n\r\nThis policy doesn't determine which page opens on startup; that's controlled by the 'RestoreOnStartup' (Action to take on startup) policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\r\n\r\nIf you don't configure this policy, the default new tab page is used.\r\n\r\nIf you configure this policy *and* the 'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) policy, this policy has precedence.\r\n\r\nIf an invalid URL is provided, new tabs will open about://blank.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_newtabpagelocation","displayName":"New tab page URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'Open new tab' (5).\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'Restore the last session' (1). The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'Open a list of URLs' (4).\r\n\r\nDisabling this setting is equivalent to leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\n* 1 = Restore the last session\r\n\r\n* 4 = Open a list of URLs\r\n\r\n* 5 = Open a new tab","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup","displayName":"Action to take on startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartupurls_recommended","displayName":"Sites to open when the browser starts (User)","description":"Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup.\r\n\r\nThis policy only works if you also set the 'RestoreOnStartup' (Action to take on startup) policy to 'Open a list of URLs' (4).\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com\r\nhttps://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartupurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartupurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartupurls_recommended_restoreonstartupurlsdesc","displayName":"Sites to open when the browser starts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_showhomebutton_recommended","displayName":"Show Home button on toolbar (User)","description":"Shows the Home button on Microsoft Edge's toolbar.\r\n\r\nEnable this policy to always show the Home button. Disable it to never show the button.\r\n\r\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_showhomebutton_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_showhomebutton_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification","displayName":"Notify a user that a browser restart is recommended or required for pending updates (User)","description":"Notify users that they need to restart Microsoft Edge to apply a pending update.\r\n\r\nIf you don't configure this policy, Microsoft Edge adds a recycle icon at the far right of the top menu bar to prompt users to restart the browser to apply the update.\r\n\r\nIf you enable this policy and set it to 'Recommended' (1), a recurring warning prompts users that a restart is recommended. Users can dismiss this warning and defer the restart.\r\n\r\nIf you set the policy to 'Required' (2), a recurring warning prompts users that the browser will be restarted automatically as soon as a notification period passes. The default period is seven days. You can configure this period with the 'RelaunchNotificationPeriod' (Set the time period for update notifications) policy.\r\n\r\nThe user's session is restored when the browser restarts.\r\n\r\n* 1 = Recommended - Show a recurring prompt to the user indicating that a restart is recommended\r\n\r\n* 2 = Required - Show a recurring prompt to the user indicating that a restart is required","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_relaunchnotification","displayName":"Notify a user that a browser restart is recommended or required for pending updates (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_relaunchnotification_1","displayName":"Recommended - Show a recurring prompt to the user indicating that a restart is recommended","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_relaunchnotification_2","displayName":"Required - Show a recurring prompt to the user indicating that a restart is required","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod","displayName":"Set the time period for update notifications (User)","description":"Allows you to set the time period, in milliseconds, over which users are notified that Microsoft Edge must be relaunched or that a Microsoft Edge OS device must be restarted to apply a pending update.\r\n\r\nOver this time period, the user will be repeatedly informed of the need for an update. For Microsoft Edge OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Microsoft Edge browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the 'RelaunchNotification' (Notify a user that a browser restart is recommended or required for pending updates) policy follow this same schedule.\r\n\r\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_relaunchnotificationperiod","displayName":"Set the time period for update notifications: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_requireonlinerevocationchecksforlocalanchors","displayName":"Specify if online OCSP/CRL checks are required for local trust anchors (User)","description":"Control whether online revocation checks (OCSP/CRL checks) are required. If Microsoft Edge can't get revocation status information, these certificates are treated as revoked (\"hard-fail\").\r\n\r\nIf you enable this policy, Microsoft Edge always performs revocation checking for server certificates that successfully validate and are signed by locally-installed CA certificates.\r\n\r\nIf you don't configure or disable this policy, then Microsoft Edge uses the existing online revocation checking settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_requireonlinerevocationchecksforlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_requireonlinerevocationchecksforlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_resolvenavigationerrorsusewebservice","displayName":"Enable resolution of navigation errors using a web service (User)","description":"Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi.\r\n\r\nIf you enable this policy, a web service is used for network connectivity tests.\r\n\r\nIf you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues.\r\n\r\n**Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_resolvenavigationerrorsusewebservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_resolvenavigationerrorsusewebservice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictbackgroundfetchfromserviceworkerenabled","displayName":"Restrict Background Fetch API when called from a Service Worker (User)","description":"This policy controls whether background fetch requests from Service Workers are restricted. If a feature that downloads files in the background is affected, this policy may be relevant.\n\nIf you enable this policy or don't configure it, the restriction is active, and background fetch requests from Service Worker contexts may be blocked.\n\nIf you disable this policy, the restriction is bypassed, allowing Service Workers to make background fetch requests.\n\nThis policy is temporary and will be removed after Microsoft Edge version 152.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictbackgroundfetchfromserviceworkerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictbackgroundfetchfromserviceworkerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictsignintopattern","displayName":"Restrict which accounts can be used to sign in to Microsoft Edge (User)","description":"Determines which accounts can be used to sign in to the Microsoft Edge account that's chosen during the Sync opt-in flow.\r\n\r\nYou can configure this policy to match multiple accounts using a Perl style regular expression for the pattern. If a user tries to sign in to the browser with an account whose username doesn't match this pattern, they are blocked and will get the appropriate error message. Note that pattern matches are case sensitive. For more information about the regular expression rules that are used, refer to https://go.microsoft.com/fwlink/p/?linkid=2133903.\r\n\r\nIf you don't configure this policy or leave it blank, users can use any account to sign in to Microsoft Edge.\r\n\r\nNote that signed-in profiles with a username that doesn't match this pattern will be signed out after this policy is enabled.\r\n\r\nExample value: .*@contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictsignintopattern_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictsignintopattern_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictsignintopattern_restrictsignintopattern","displayName":"Restrict which accounts can be used as Microsoft Edge primary accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_runallflashinallowmode","displayName":"Extend Adobe Flash content setting to all content (User)","description":"If you enable this policy, all Adobe Flash content embedded in websites that are set to allow Adobe Flash in the content settings -- either by the user or by enterprise policy -- will run. This includes content from other origins and/or small content.\r\n\r\nTo control which websites are allowed to run Adobe Flash, see the specifications in the 'DefaultPluginsSetting' (Default Adobe Flash setting), 'PluginsAllowedForUrls' (Allow the Adobe Flash plug-in on specific sites), and 'PluginsBlockedForUrls' (Block the Adobe Flash plug-in on specific sites) policies.\r\n\r\nIf you disable this policy or don't configure it, Adobe Flash content from other origins (from sites that aren't specified in the three policies mentioned immediately above) or small content might be blocked.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_runallflashinallowmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_runallflashinallowmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_savingbrowserhistorydisabled","displayName":"Disable saving browser history (User)","description":"Disables saving browser history and prevents users from changing this setting.\r\n\r\nIf you enable this policy, browsing history isn't saved. This also disables tab syncing.\r\n\r\nIf you disable this policy or don't configure it, browsing history is saved.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_savingbrowserhistorydisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_savingbrowserhistorydisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_searchsuggestenabled","displayName":"Enable search suggestions (User)","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\r\n\r\nIf you enable this policy, web search suggestions are used.\r\n\r\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\r\n\r\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_searchsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_searchsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_securitykeypermitattestation","displayName":"Websites or domains that don't need permission to use direct Security Key attestation (User)","description":"Specifies websites and domains that don't need explicit user permission when attestation certificates from security keys are requested. Additionally, a signal is sent to the security key indicating that it can use individual attestation. Without this, users are prompted each time a site requests attestation of security keys.\r\n\r\nSites (like https://contoso.com/some/path) only match as U2F appIDs. Domains (like contoso.com) only match as webauthn RP IDs. To cover both U2F and webauthn APIs for a given site, you need to list both the appID URL and domain.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_securitykeypermitattestation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_securitykeypermitattestation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_securitykeypermitattestation_securitykeypermitattestationdesc","displayName":"Websites or domains that don't need permission to use direct Security Key attestation (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer","displayName":"Send all intranet sites to Internet Explorer (User)","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices","displayName":"Send site information to improve Microsoft services (User)","description":"This policy enables sending info about websites visited in Microsoft Edge to Microsoft to improve services like search.\r\n\r\nEnable this policy to send info about websites visited in Microsoft Edge to Microsoft. Disable this policy to not send info about websites visited in Microsoft Edge to Microsoft. In both cases, users can't change or override the setting.\r\n\r\nOn Windows 10, Beta and Stable if this policy is not configured, Microsoft Edge will default to the Windows diagnostic data setting. If this policy is enabled Microsoft Edge will only send info about websites visited in Microsoft Edge if the Windows Diagnostic data setting is set to Full. If this policy is disabled Microsoft Edge will not send info about websites visited. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nOn Windows 10, Canary and Dev channels, this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.\r\n\r\nOn Windows 7, 8, and Mac this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_showofficeshortcutinfavoritesbar","displayName":"Show Microsoft Office shortcut in favorites bar (User)","description":"Specifies whether to include a shortcut to Office.com in the favorites bar. For users signed into Microsoft Edge the shortcut takes users to their Microsoft Office apps and docs.\r\n\r\nIf this policy is enabled or not configure, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu.\r\n\r\nIf the policy is disabled, the shortcut won't be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_showofficeshortcutinfavoritesbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_showofficeshortcutinfavoritesbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_siteperprocess","displayName":"Enable site isolation for every site (User)","description":"\r\nThe 'SitePerProcess' policy can be used to prevent users from opting out of the default behavior of isolating all sites. Note that you can also use the 'IsolateOrigins' (Enable site isolation for specific origins) policy to isolate additional, finer-grained origins.\r\nIf you enable this policy, users can't opt out of the default behavior where each site runs in its own process.\r\nIf you disable or don’t configure this policy, a user can opt out of site isolation. (For example, by using \"Disable site isolation\" entry in edge://flags.) Disabling the policy or not configuring the policy doesn't turn off Site Isolation.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_siteperprocess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_siteperprocess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellcheckenabled","displayName":"Enable spellcheck (User)","description":"If you enable or don't configure this policy, the user can use spellcheck.\r\n\r\nIf you disable this policy, the user can't use spellcheck and the 'SpellcheckLanguage' (Enable specific spellcheck languages) and 'SpellcheckLanguageBlocklist' (Force disable spellcheck languages) policies are also disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellchecklanguage","displayName":"Enable specific spellcheck languages (User)","description":"Enables different languages for spellcheck. Any language that you specify that isn't recognized is ignored.\r\n\r\nIf you enable this policy, spellcheck is enabled for the languages specified, as well as any languages the user has enabled.\r\n\r\nIf you don't configure or disable this policy, there's no change to the user's spellcheck preferences.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy is disabled, this policy will have no effect.\r\n\r\nIf a language is included in both the 'SpellcheckLanguage' and the 'SpellcheckLanguageBlocklist' (Force disable spellcheck languages) policy, the spellcheck language is enabled.\r\n\r\nThe supported languages are: af, bg, ca, cs, cy, da, de, el, en-AU, en-CA, en-GB, en-US, es, es-419, es-AR, es-ES, es-MX, es-US, et, fa, fo, fr, he, hi, hr, hu, id, it, ko, lt, lv, nb, nl, pl, pt-BR, pt-PT, ro, ru, sh, sk, sl, sq, sr, sv, ta, tg, tr, uk, vi.\r\n\r\nExample value:\r\n\r\nfr\r\nes","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellchecklanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellchecklanguage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellchecklanguage_spellchecklanguagedesc","displayName":"Enable specific spellcheck languages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslerroroverrideallowed","displayName":"Allow users to proceed from the HTTPS warning page (User)","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\r\n\r\nIf you enable or don't configure (default) this policy, users can click through these warning pages.\r\n\r\nIf you disable this policy, users are blocked from clicking through any warning page.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslerroroverrideallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslerroroverrideallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin","displayName":"Minimum TLS version enabled (User)","description":"Sets the minimum supported version of SSL. If you don't configure this policy, Microsoft Edge uses a default minimum version, TLS 1.0.\r\n\r\nIf you enable this policy, you can set the minimum version to one of the following values: \"tls1\", \"tls1.1\" or \"tls1.2\". When set, Microsoft Edge won't use any version of SSL/TLS lower than the specified version. Any unrecognized value is ignored.\r\n\r\n* \"tls1\" = TLS 1.0\r\n\r\n* \"tls1.1\" = TLS 1.1\r\n\r\n* \"tls1.2\" = TLS 1.2\r\n\r\nExample value: tls1","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin","displayName":"Minimum SSL version enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin_tls1","displayName":"TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin_tls1.1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_strictmimetypecheckforworkerscriptsenabled","displayName":"Enable strict MIME type checking for worker scripts (User)","description":"This policy controls whether strict MIME type checking is used for worker scripts.\n\nIf you enable or don't configure this policy, worker scripts use strict MIME type checking for JavaScript. Worker scripts that use legacy MIME types are rejected.\n\nIf you disable this policy, worker scripts use lax MIME type checking. This allows worker scripts that use legacy MIME types, such as text/ascii, to continue to load and run.\n\nBrowsers traditionally used lax MIME type checking, which allowed JavaScript resources to load with several legacy MIME types. This behavior can create security risks by allowing resources to load as scripts when they weren't intended to be used that way.\n\nMicrosoft Edge uses strict MIME type checking by default. Enabling this policy follows the default behavior. Disabling this policy lets admins temporarily retain the legacy behavior for compatibility.\n\nFor more information about JavaScript and ECMAScript media types, see https://html.spec.whatwg.org/multipage/scripting.html#scriptingLanguage.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_strictmimetypecheckforworkerscriptsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_strictmimetypecheckforworkerscriptsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_suppressunsupportedoswarning","displayName":"Suppress the unsupported OS warning (User)","description":"Suppresses the warning that appears when Microsoft Edge is running on a computer or operating system that is no longer supported.\r\n\r\nIf this policy is false or unset, the warnings will appear on such unsupported computers or operating systems.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_suppressunsupportedoswarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_suppressunsupportedoswarning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_syncdisabled","displayName":"Disable synchronization of data using Microsoft sync services (User)","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\r\n\r\nIf you don't set this policy or apply it as recommended, users will be able to turn sync on or off. If you apply this policy as mandatory, users will not be able to turn sync on.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_syncdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_syncdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled","displayName":"Configure tab lifecycles (User)","description":"The tab lifecycles feature reclaims CPU and memory associated with running tabs that haven't been used in a long time, by first throttling, then freezing, and finally discarding them.\r\n\r\nIf you disable this policy, the tab lifecycles feature is disabled, and all tabs are left running normally.\r\n\r\nIf you enable or don't configure this policy, the tab lifecycles feature is enabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_taskmanagerendprocessenabled","displayName":"Enable ending processes in the Browser task manager (User)","description":"If you enable or don't configure this policy, users can end processes in the Browser task manager. If you disable it, users can't end processes, and the End process button is disabled in the Browser task manager.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_taskmanagerendprocessenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_taskmanagerendprocessenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_translateenabled","displayName":"Enable Translate (User)","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\r\n\r\nIf you enable this policy, Microsoft Edge offers translation functionality to the user by showing an integrated translate flyout when appropriate, and a translate option on the right-click context menu.\r\n\r\nDisable this policy to disable all built-in translate features.\r\n\r\nIf you don't configure the policy, users can choose whether to use the translation functionality or not.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_translateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_translateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist","displayName":"Define a list of allowed URLs (User)","description":"Allow access to the listed URLs, as exceptions to the URL block list.\r\n\r\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nYou can use this policy to open exceptions to restrictive block lists. For example, you can include '*' in the block list to block all requests, and then use this policy to allow access to a limited list of URLs. You can use this policy to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths.\r\n\r\nThe most specific filter determines if a URL is blocked or allowed. The allowed list takes precedence over the block list.\r\n\r\nThis policy is limited to 1000 entries; subsequent entries are ignored.\r\n\r\nIf you don't configure this policy, there are no exceptions to the block list in the 'URLBlocklist' (Block access to a list of URLs) policy.\r\n\r\nExample value:\r\n\r\ncontoso.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist_urlallowlistdesc","displayName":"Define a list of allowed URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlblocklist","displayName":"Block access to a list of URLs (User)","description":"Define a list of sites, based on URL patterns, that are blocked (your users can't load them).\r\n\r\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nYou can define exceptions in the 'URLAllowlist' (Define a list of allowed URLs) policy. These policies are limited to 1000 entries; subsequent entries are ignored.\r\n\r\nNote that blocking internal 'edge://*' URLs isn't recommended - this may lead to unexpected errors.\r\n\r\nThis policy doesn't prevent the page from updating dynamically through JavaScript. For example, if you block 'contoso.com/abc', users might still be able to visit 'contoso.com' and click on a link to visit 'contoso.com/abc', as long as the page doesn't refresh.\r\n\r\nIf you don't configure this policy, no URLs are blocked.\r\n\r\nExample value:\r\n\r\ncontoso.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlblocklist_urlblocklistdesc","displayName":"Block access to a list of URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir","displayName":"Set the user data directory (User)","description":"Set the directory to use for storing user data.\r\n\r\nIf you enable this policy, Microsoft Edge uses the specified directory regardless of whether the user has set the '--user-data-dir' command-line flag.\r\n\r\nIf you don't enable this policy, the default profile path is used, but the user can override it by using the '--user-data-dir' flag. Users can find the directory for the profile at edge://version/ under profile path.\r\n\r\nTo avoid data loss or other errors, don't configure this policy to a volume's root directory or to a directory that's used for other purposes, because Microsoft Edge manages its contents.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\r\n\r\nExample value: ${users}/${user_name}/Edge","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir_userdatadir","displayName":"Set the user data directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userfeedbackallowed","displayName":"Allow user feedback (User)","description":"Microsoft Edge uses the Edge Feedback feature (enabled by default) to allow users to send feedback, suggestions or customer surveys and to report any issues with the browser. Also, by default, users can't disable (turn off) the Edge Feedback feature.\r\n\r\nIf you enable this policy or don't configure it, users can invoke Edge Feedback.\r\n\r\nIf you disable this policy, users can't invoke Edge Feedback.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userfeedbackallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userfeedbackallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowed","displayName":"Allow or block video capture (User)","description":"Control whether sites can capture video.\r\n\r\nIf enabled or not configured (default), the user will be asked about video capture access for all sites except those with URLs configured in the 'VideoCaptureAllowedUrls' (Sites that can access video capture devices without requesting permission) policy list, which will be granted access without prompting.\r\n\r\nIf you disable this policy, the user isn't prompted, and video capture is only available to URLs configured in 'VideoCaptureAllowedUrls' policy.\r\n\r\nThis policy affects all types of video inputs, not only the built-in camera.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls","displayName":"Sites that can access video capture devices without requesting permission (User)","description":"Specify websites, based on URL patterns, that can use video capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to video capture devices. Note, however, that the pattern \"*\", which matches any URL, is not supported by this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com/\r\nhttps://[*.]contoso.edu/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls_videocaptureallowedurlsdesc","displayName":"Sites that can access video capture devices without requesting permission (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webdriveroverridesincompatiblepolicies","displayName":"Allow WebDriver to Override Incompatible Policies (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\n\r\nThis policy was removed in M83, because it is not necessary anymore as\r\nWebDriver is now compatible with all existing policies.\r\n\r\nThis policy allows users of the WebDriver feature to override\r\npolicies which can interfere with its operation.\r\n\r\nCurrently this policy disables 'SitePerProcess' (Enable site isolation for every site) and 'IsolateOrigins' (Enable site isolation for specific origins) policies.\r\n\r\nIf the policy is enabled, WebDriver will be able to override incomaptible\r\npolicies.\r\nIf the policy is disabled or not configured, WebDriver will not be allowed\r\nto override incompatible policies.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webdriveroverridesincompatiblepolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webdriveroverridesincompatiblepolicies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling","displayName":"Restrict exposure of local IP address by WebRTC (User)","description":"Allows you to set whether or not WebRTC exposes the user's local IP address.\r\n\r\nIf you set this policy to \"AllowAllInterfaces\" ('default') or \"AllowPublicAndPrivateInterfaces\" ('default_public_and_private_interfaces'), WebRTC exposes the local IP address.\r\n\r\nIf you set this policy to \"AllowPublicInterfaceOnly\" ('default_public_interface_only') or \"DisableNonProxiedUdp\" ('disable_non_proxied_udp'), WebRTC doesn't expose the local IP address.\r\n\r\nIf you don't set this policy, or if you disable it, WebRTC exposes the local IP address.\r\n\r\n * 'default' = Allow all interfaces. This exposes the local IP address.\r\n * 'default_public_and_private_interfaces' = Allow public and private interfaces over http default route. This exposes the local IP address.\r\n * 'default_public_interface_only' = Allow public interface over http default route. This doesn't expose the local IP address.\r\n * 'disable_non_proxied_udp' = Use TCP unless proxy server supports UDP. This doesn't expose the local IP address.\r\n\r\nExample value: default","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling","displayName":"Restrict exposure of localhost IP address by WebRTC (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_default","displayName":"Allow all interfaces. This exposes the local IP address","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_default_public_and_private_interfaces","displayName":"Allow public and private interfaces over http default route. This exposes the local IP address","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_default_public_interface_only","displayName":"Allow public interface over http default route. This doesn't expose the local IP address","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_disable_non_proxied_udp","displayName":"Use TCP unless proxy server supports UDP. This doesn't expose the local IP address","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC (User)","description":"Restricts the UDP port range used by WebRTC to a specified port interval (endpoints included).\r\n\r\nBy configuring this policy, you specify the range of local UDP ports that WebRTC can use.\r\n\r\nIf you don't configure this policy, or if you set it to an empty string or invalid port range, WebRTC can use any available local UDP port.\r\n\r\nExample value: 10000-11999","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_wpadquickcheckenabled","displayName":"Set WPAD optimization (User)","description":"Allows you to turn off WPAD (Web Proxy Auto-Discovery) optimization in Microsoft Edge.\r\n\r\nIf you disable this policy, WPAD optimization is disabled, which makes the browser wait longer for DNS-based WPAD servers.\r\n\r\nIf you enable or don't configure the policy, WPAD optimization is enabled.\r\n\r\nIndependent of whether or how this policy is enabled, the WPAD optimization setting cannot be changed by users.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_wpadquickcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_wpadquickcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls","displayName":"Automatically select client certificates for these sites (User)","description":"Specify a list of sites, based on URL patterns, for which Microsoft Edge should automatically select a client certificate, if the site requests one.\r\n\r\nThe value must be an array of stringified JSON dictionaries. Each dictionary must have the form { \"pattern\": \"$URL_PATTERN\", \"filter\" : $FILTER }, where $URL_PATTERN is a content setting pattern. $FILTER restricts from which client certificates the browser will automatically select. Independent of the filter, only certificates will be selected that match the server's certificate request. For example, if $FILTER has the form { \"ISSUER\": { \"CN\": \"$ISSUER_CN\" } }, additionally only client certificates are selected that are issued by a certificate with the CommonName $ISSUER_CN. If $FILTER contains an \"ISSUER\" and a \"SUBJECT\" section, a client certificate must satisfy both conditions to be selected. If $FILTER specifies an organization (\"O\"), a certificate must have at least one organization which matches the specified value to be selected. If $FILTER specifies an organization unit (\"OU\"), a certificate must have at least one organization unit which matches the specified value to be selected. If $FILTER is the empty dictionary {}, the selection of client certificates is not additionally restricted.\r\n\r\nIf you don't configure this policy, auto-selection isn't done for any site.\r\n\r\nExample value:\r\n\r\n{\"pattern\":\"https://www.contoso.com\",\"filter\":{\"ISSUER\":{\"CN\":\"certificate issuer name\", \"L\": \"certificate issuer location\", \"O\": \"certificate issuer org\", \"OU\": \"certificate issuer org unit\"}, \"SUBJECT\":{\"CN\":\"certificate subject name\", \"L\": \"certificate subject location\", \"O\": \"certificate subject org\", \"OU\": \"certificate subject org unit\"}}}","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls_autoselectcertificateforurlsdesc","displayName":"Automatically select client certificates for these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls","displayName":"Allow cookies on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are allowed to set cookies.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nSee the 'CookiesBlockedForUrls' (Block cookies on specific sites) and 'CookiesSessionOnlyForUrls' (Limit cookies from specific websites to the current session) policies for more information.\r\n\r\nNote there cannot be conflicting URL patterns set between these three policies:\r\n\r\n- 'CookiesBlockedForUrls'\r\n\r\n- CookiesAllowedForUrls\r\n\r\n- 'CookiesSessionOnlyForUrls'\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls_cookiesallowedforurlsdesc","displayName":"Allow cookies on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls","displayName":"Block cookies on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can't set cookies.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nSee the 'CookiesAllowedForUrls' (Allow cookies on specific sites) and 'CookiesSessionOnlyForUrls' (Limit cookies from specific websites to the current session) policies for more information.\r\n\r\nNote there cannot be conflicting URL patterns set between these three policies:\r\n\r\n- CookiesBlockedForUrls\r\n\r\n- 'CookiesAllowedForUrls'\r\n\r\n- 'CookiesSessionOnlyForUrls'\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls_cookiesblockedforurlsdesc","displayName":"Block cookies on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiessessiononlyforurls","displayName":"Limit cookies from specific websites to the current session (User)","description":"Cookies created by websites that match a URL pattern you define are deleted when the session ends (when the window closes).\r\n\r\nCookies created by websites that don't match the pattern are controlled by the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or by the user's personal configuration. This is also the default behavior if you don't configure this policy.\r\n\r\nIf Microsoft Edge is running in background mode, the session might not close when the last window is closed, meaning the cookies won't be cleared when the window closes. See the 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about configuring what happens when Microsoft Edge runs in background mode.\r\n\r\nYou can also use the 'CookiesAllowedForUrls' (Allow cookies on specific sites) and 'CookiesBlockedForUrls' (Block cookies on specific sites) policies to control which websites can create cookies.\r\n\r\nNote there cannot be conflicting URL patterns set between these three policies:\r\n\r\n- 'CookiesBlockedForUrls'\r\n\r\n- 'CookiesAllowedForUrls'\r\n\r\n- CookiesSessionOnlyForUrls\r\n\r\nIf you set the 'RestoreOnStartup' (Action to take on startup) policy to restore URLs from previous sessions, this policy is ignored, and cookies are stored permanently for those sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiessessiononlyforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiessessiononlyforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiessessiononlyforurls_cookiessessiononlyforurlsdesc","displayName":"Limit cookies from specific websites to the current session (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting","displayName":"Configure cookies (User)","description":"Control whether websites can create cookies on the user's device. This policy is all or nothing - you can let all websites create cookies, or no websites create cookies. You can't use this policy to enable cookies from specific websites.\r\n\r\nSet the policy to 'SessionOnly' (4) to clear cookies when the session closes. If Microsoft Edge is running in background mode, the session might not close when the last window is closed, meaning the cookies won't be cleared when the window closes. See 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about configuring what happens when Microsoft Edge runs in background mode.\r\n\r\nIf you don't configure this policy, the default 'AllowCookies' (1) is used, and users can change this setting in Microsoft Edge Settings. (If you don't want users to be able to change this setting, set the policy.)\r\n\r\n* 1 = Let all sites create cookies\r\n\r\n* 2 = Don't let any site create cookies\r\n\r\n* 4 = Keep cookies for the duration of the session","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting","displayName":"Configure cookies (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting_1","displayName":"Let all sites create cookies","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting_2","displayName":"Don't let any site create cookies","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting_4","displayName":"Keep cookies for the duration of the session","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting","displayName":"Default geolocation setting (User)","description":"Set whether websites can track users' physical locations. You can allow tracking by default (1), deny it by default (2), or ask the user each time a website requests their location (3).\r\n\r\nIf you don't configure this policy, 'AskGeolocation' policy is used and the user can change it.\r\n\r\n* 1 = Allow sites to track users' physical location\r\n\r\n* 2 = Don't allow any site to track users' physical location\r\n\r\n* 3 = Ask whenever a site wants to track users' physical location","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting","displayName":"Default geolocation setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting_1","displayName":"Allow sites to track users' physical location","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting_2","displayName":"Don't allow any site to track users' physical location","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_defaultgeolocationsetting_3","displayName":"Ask whenever a site wants to track users' physical location","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting","displayName":"Default images setting (User)","description":"Set whether websites can display images. You can allow images on all sites (1) or block them on all sites (2).\r\n\r\nIf you don't configure this policy, images are allowed by default, and the user can change this setting.\r\n\r\n* 1 = Allow all sites to show all images\r\n\r\n* 2 = Don't allow any site to show images","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_defaultimagessetting","displayName":"Default images setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_defaultimagessetting_1","displayName":"Allow all sites to show all images","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_defaultimagessetting_2","displayName":"Don't allow any site to show images","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting","displayName":"Default JavaScript setting (User)","description":"Set whether websites can run JavaScript. You can allow it for all sites (1) or block it for all sites (2).\r\n\r\nIf you don't configure this policy, all sites can run JavaScript by default, and the user can change this setting.\r\n\r\n* 1 = Allow all sites to run JavaScript\r\n\r\n* 2 = Don't allow any site to run JavaScript","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting","displayName":"Default JavaScript setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_1","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_2","displayName":"Don't allow any site to run JavaScript","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting (User)","description":"Setting this policy controls the default behavior for the local fonts permission.\n\nIf you set the policy to BlockLocalFonts (value 2), access to local fonts is denied by default. Sites are prevented from accessing information about local fonts.\n\nIf you set the policy to AskLocalFonts (value 3), users are prompted when a site requests access to local fonts. If permission is granted, the site can access information about local fonts.\n\nIf a site is included in 'LocalFontsAllowedForUrls' (Allow Local Fonts permission on these sites) or 'LocalFontsBlockedForUrls' (Block Local Fonts permission on these sites), then that setting overrides the value set for this policy.\n\nIf you don't configure this policy, users are prompted by default and can change this setting.\n\nPolicy options mapping:\n\n* BlockLocalFonts (2) = Denies the Local Fonts permission on all sites by default\n\n* AskLocalFonts (3) = Ask every time a site wants to obtain the Local Fonts permission\n\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_2","displayName":"Denies the Local Fonts permission on all sites by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_3","displayName":"Ask every time a site wants to obtain the Local Fonts permission","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting","displayName":"Default notification setting (User)","description":"Set whether websites can display desktop notifications. You can allow them by default (1), deny them by default (2), or have the user be asked each time a website wants to show a notification (3).\r\n\r\nIf you don't configure this policy, notifications are allowed by default, and the user can change this setting.\r\n\r\n* 1 = Allow sites to show desktop notifications\r\n\r\n* 2 = Don't allow any site to show desktop notifications\r\n\r\n* 3 = Ask every time a site wants to show desktop notifications","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting","displayName":"Default notification setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting_1","displayName":"Allow sites to show desktop notifications","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting_2","displayName":"Don't allow any site to show desktop notifications","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting_3","displayName":"Ask every time a site wants to show desktop notifications","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting","displayName":"Default Adobe Flash setting (User)","description":"Determines whether websites that aren't covered by 'PluginsAllowedForUrls' (Allow the Adobe Flash plug-in on specific sites) or 'PluginsBlockedForUrls' (Block the Adobe Flash plug-in on specific sites) can automatically run the Adobe Flash plug-in. You can select 'BlockPlugins' (2) to block Adobe Flash on all sites, or you can select 'ClickToPlay' (3) to let Adobe Flash run but require the user to click the placeholder to start it. In any case, the 'PluginsAllowedForUrls' and 'PluginsBlockedForUrls' policies take precedence over 'DefaultPluginsSetting'.\r\n\r\nAutomatic playback is only allowed for domains explicitly listed in the 'PluginsAllowedForUrls' policy. If you want to enable automatic playback for all sites, consider adding http://* and https://* to this list.\r\n\r\nIf you don't configure this policy, the user can change this setting manually.\r\n\r\n* 2 = Block the Adobe Flash plug-in\r\n\r\n* 3 = Click to play\r\n\r\nThe former '1' option set allow-all, but this functionality is now only handled by the 'PluginsAllowedForUrls' policy. Existing policies using '1' will operate in Click-to-play mode.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_defaultpluginssetting","displayName":"Default Adobe Flash setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_defaultpluginssetting_2","displayName":"Block the Adobe Flash plugin","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_defaultpluginssetting_3","displayName":"Click to play","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting","displayName":"Default pop-up window setting (User)","description":"Set whether websites can show pop-up windows. You can allow them on all websites (1) or block them on all sites (2).\r\n\r\nIf you don't configure this policy, pop-up windows are blocked by default, and users can change this setting.\r\n\r\n* 1 = Allow all sites to show pop-ups\r\n\r\n* 2 = Don't allow any site to show pop-up windows","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting","displayName":"Default pop-up window setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting_1","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting_2","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API (User)","description":"Control whether websites can access nearby Bluetooth devices. You can completely block access or require the site to ask the user each time it wants to access a Bluetooth device.\r\n\r\nIf you don't configure this policy, the default value (3, meaning users are asked each time) is used and users can change it.\r\n\r\n* 2 = Don't allow any site to request access to Bluetooth devices by using the Web Bluetooth API\r\n\r\n* 3 = Allow sites to ask the user to grant access to a nearby Bluetooth device","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_2","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_3","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API (User)","description":"Set whether websites can access connected USB devices. You can completely block access or ask the user each time a website wants to get access to connected USB devices.\r\n\r\nYou can override this policy for specific URL patterns by using the 'WebUsbAskForUrls' (Allow WebUSB on specific sites) and 'WebUsbBlockedForUrls' (Block WebUSB on specific sites) policies.\r\n\r\nIf you don't configure this policy, sites can ask users whether they can access the connected USB devices (3) by default, and users can change this setting.\r\n\r\n* 2 = Don't allow any site to request access to USB devices via the WebUSB API\r\n\r\n* 3 = Allow sites to ask the user to grant access to a connected USB device","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebusbguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebusbguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting_2","displayName":"Do not allow any site to request access to USB devices via the WebUSB API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting_3","displayName":"Allow sites to ask the user to grant access to a connected USB device","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesallowedforurls","displayName":"Allow images on these sites (User)","description":"Define a list of sites, based on URL patterns, that can display images.\r\n\r\nIf you don't configure this policy, the global default value is used for all sites either from the 'DefaultImagesSetting' (Default images setting) policy (if set) or the user's personal configuration.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesallowedforurls_imagesallowedforurlsdesc","displayName":"Allow images on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls","displayName":"Block images on specific sites (User)","description":"Define a list of sites, based on URL patterns, that aren't allowed to display images.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultImagesSetting' (Default images setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_imagesblockedforurlsdesc","displayName":"Block images on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptallowedforurls","displayName":"Allow JavaScript on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are allowed to run JavaScript.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultJavaScriptSetting' (Default JavaScript setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptallowedforurls_javascriptallowedforurlsdesc","displayName":"Allow JavaScript on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls","displayName":"Block JavaScript on specific sites (User)","description":"Define a list of sites, based on URL patterns, that aren't allowed to run JavaScript.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultJavaScriptSetting' (Default JavaScript setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls_javascriptblockedforurlsdesc","displayName":"Block JavaScript on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsallowedforurls","displayName":"Allow Local Fonts permission on these sites (User)","description":"Specifies a list of site URL patterns for which the local fonts permission is automatically granted. Sites in this list can access information about local fonts.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are supported. This policy matches based on origin only; any path in the URL pattern is ignored.\n\nIf a site isn't included in this policy, the 'DefaultLocalFontsSetting' (Default Local Fonts permission setting) policy applies if configured. Otherwise, the browser default behavior applies, and users can choose the permission on a per-site basis.\n\nExample value:\n\nhttps://www.example.com\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsallowedforurls_localfontsallowedforurlsdesc","displayName":"Allow Local Fonts permission on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsblockedforurls","displayName":"Block Local Fonts permission on these sites (User)","description":"Specifies a list of site URL patterns for which the local fonts permission is automatically denied. Sites in this list are prevented from accessing information about local fonts.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are supported. This policy matches based on origin only; any path in the URL pattern is ignored.\n\nIf a site isn't included in this policy, the 'DefaultLocalFontsSetting' (Default Local Fonts permission setting) policy applies if configured. Otherwise, the browser default behavior applies, and users can choose the permission on a per-site basis.\n\nExample value:\n\nhttps://www.example.com\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsblockedforurls_localfontsblockedforurlsdesc","displayName":"Block Local Fonts permission on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsallowedforurls","displayName":"Allow notifications on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can display notifications.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultNotificationsSetting' (Default notification setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsallowedforurls_notificationsallowedforurlsdesc","displayName":"Allow notifications on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls","displayName":"Block notifications on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are blocked from displaying notifications.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultNotificationsSetting' (Default notification setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_notificationsblockedforurlsdesc","displayName":"Block notifications on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsallowedforurls","displayName":"Allow the Adobe Flash plug-in on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can run the Adobe Flash plug-in.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultPluginsSetting' (Default Adobe Flash setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsallowedforurls_pluginsallowedforurlsdesc","displayName":"Allow the Adobe Flash plug-in on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls","displayName":"Block the Adobe Flash plug-in on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are blocked from running Adobe Flash.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultPluginsSetting' (Default Adobe Flash setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls_pluginsblockedforurlsdesc","displayName":"Block the Adobe Flash plug-in on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls","displayName":"Allow pop-up windows on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can open pop-up windows.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultPopupsSetting' (Default pop-up window setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls_popupsallowedforurlsdesc","displayName":"Allow pop-up windows on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsblockedforurls","displayName":"Block pop-up windows on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are blocked from opening pop-up windows.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultPopupsSetting' (Default pop-up window setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsblockedforurls_popupsblockedforurlsdesc","displayName":"Block pop-up windows on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls","displayName":"Grant access to specific sites to connect to specific USB devices (User)","description":"Allows you to set a list of urls that specify which sites will automatically be granted permission to access a USB device with the given vendor and product IDs. Each item in the list must contain both devices and urls in order for the policy to be valid. Each item in devices can contain a vendor ID and product ID field. Any ID that is omitted is treated as a wildcard with one exception, and that exception is that a product ID cannot be specified without a vendor ID also being specified. Otherwise, the policy will not be valid and will be ignored.\r\n\r\nThe USB permission model uses the URL of the requesting site (\"requesting URL\") and the URL of the top-level frame site (\"embedding URL\") to grant permission to the requesting URL to access the USB device. The requesting URL may be different than the embedding URL when the requesting site is loaded in an iframe. Therefore, the \"urls\" field can contain up to two URL strings delimited by a comma to specify the requesting and embedding URL respectively. If only one URL is specified, then access to the corresponding USB devices will be granted when the requesting site's URL matches this URL regardless of embedding status. The URLs in \"urls\" must be valid URLs, otherwise the policy will be ignored.\r\n\r\nIf this policy is left not set, the global default value will be used for all sites either from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy if it is set, or the user's personal configuration otherwise.\r\n\r\nURL patterns in this policy should not clash with the ones configured via 'WebUsbBlockedForUrls' (Block WebUSB on specific sites). If there is a clash, this policy will take precedence over 'WebUsbBlockedForUrls' and 'WebUsbAskForUrls' (Allow WebUSB on specific sites).\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"urls\": [\r\n \"https://contoso.com\", \r\n \"https://fabrikam.com\"\r\n ], \r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234, \r\n \"product_id\": 5678\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_webusballowdevicesforurls","displayName":"Grant access to specific sites to connect to specific USB devices (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls","displayName":"Allow WebUSB on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can ask the user for access to a USB device.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nThe URL patterns defined in this policy can't conflict with those configured in the 'WebUsbBlockedForUrls' (Block WebUSB on specific sites) policy - you can't both allow and block a URL.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls_webusbaskforurlsdesc","displayName":"Allow WebUSB on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls","displayName":"Block WebUSB on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can't ask the user to grant them access to a USB device.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nURL patterns in this policy can't conflict with those configured in the 'WebUsbAskForUrls' (Allow WebUSB on specific sites) policy. You can't both allow and block a URL.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls_webusbblockedforurlsdesc","displayName":"Block WebUSB on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderenabled","displayName":"Enable the default search provider (User)","description":"Enables the ability to use a default search provider.\r\n\r\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\r\n\r\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider.\r\n\r\nIf you disable this policy, the user can't search from the address bar.\r\n\r\nIf you enable or disable this policy, users can't change or override it.\r\n\r\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderencodings","displayName":"Default search provider encodings (User)","description":"Specify the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They are tried in the order provided.\r\n\r\nThis policy is optional. If not configured, the default, UTF-8, is used.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value:\r\n\r\nUTF-8\r\nUTF-16\r\nGB2312\r\nISO-8859-1","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderencodings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderencodings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderencodings_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider (User)","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\r\n\r\nThis policy is optional. If you don't configure it, image search isn't available.\r\n\r\nSpecify Bing's Image Search URL as:\r\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\r\n\r\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\r\n\r\nSee 'DefaultSearchProviderImageURLPostParams' (Parameters for an image URL that uses POST) policy to finish configuring image search.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: https://search.contoso.com/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST (User)","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it’s replaced with real image thumbnail data. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nSpecify Bing's Image Search URL Post Params as:\r\n'imageBin={google:imageThumbnailBase64}'.\r\n\r\nSpecify Google's Image Search URL Post Params as:\r\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\r\n\r\nIf you don’t set this policy, image search requests are sent using the GET method.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderkeyword","displayName":"Default search provider keyword (User)","description":"Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider.\r\n\r\nThis policy is optional. If you don't configure it, no keyword activates the search provider.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderkeyword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderkeyword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderkeyword_defaultsearchproviderkeyword","displayName":"Default search provider keyword (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"Specifies the name of the default search provider.\r\n\r\nIf you enable this policy, you set the name of the default search provider.\r\n\r\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\r\n\r\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidername_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidername_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (User)","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\r\n\r\nSpecify Bing's search URL as:\r\n\r\n'{bing:baseURL}search?q={searchTerms}'.\r\n\r\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\r\n\r\nThis policy is required when you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) policy; if you don't enable the latter policy, this policy is ignored.\r\n\r\nExample value: https://search.contoso.com/search?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersearchurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersearchurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersearchurl_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions (User)","description":"Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user has entered so far.\r\n\r\nThis policy is optional. If you don't configure it, users won't see search suggestions; they will see suggestions from their browsing history and favorites.\r\n\r\nBing's suggest URL can be specified as:\r\n\r\n'{bing:baseURL}qbox?query={searchTerms}'.\r\n\r\nGoogle's suggest URL can be specified as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: https://search.contoso.com/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl_defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes","displayName":"Configure allowed extension types (User)","description":"Controls which extension types can be installed and limits runtime access.\r\n\r\nThis setting defines the allowed types of extensions and which hosts they can interact with. The value is a list of strings, each of which should be one of the following: \"extension\", \"theme\", \"user_script\", and \"hosted_app\". See the Microsoft Edge extensions documentation for more information on these types.\r\n\r\nNote that this policy also affects extensions to be force-installed by using 'ExtensionInstallForcelist' (Control which extensions are installed silently) policy.\r\n\r\nIf you enable this policy, only extensions that match a type in the list are installed.\r\n\r\nIf you don't configure this policy, no restrictions on the acceptable extension types are enforced.\r\n\r\nExample value:\r\n\r\nhosted_app","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes_extensionallowedtypesdesc","displayName":"Types of extensions/apps that are allowed to be installed (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist","displayName":"Allow specific extensions to be installed (User)","description":"By default, all extensions are allowed. However, if you block all extensions by setting the 'ExtensionInstallBlockList' policy to \"*,\" users can only install extensions defined in this policy.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist_extensioninstallallowlistdesc","displayName":"Extension IDs to exempt from the block list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallblocklist","displayName":"Control which extensions cannot be installed (User)","description":"List specific extensions that users can NOT install in Microsoft Edge. When you deploy this policy, any extensions on this list that were previously installed will be disabled, and the user won't be able to enable them. If you remove an item from the list of blocked extensions, that extension is automatically re-enabled anywhere it was previously installed.\r\n\r\nUse \"*\" to block all extensions that aren't explicitly listed in the allow list.\r\n\r\nIf you don't configure this policy, users can install any extension in Microsoft Edge.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallblocklist_extensioninstallblocklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallforcelist","displayName":"Control which extensions are installed silently (User)","description":"Specifies extensions that are installed silently, without user interaction, and that the users can't uninstall or disable (\"force-installed\"). All permissions requested by the extensions are granted implicitly, without user interaction, including any additional permissions requested by future versions of the extension. Furthermore, permissions are granted for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These two APIs are only available to extensions that are force-installed.)\r\n\r\nThis policy takes precedence over a potentially conflicting 'ExtensionInstallBlocklist' (Control which extensions cannot be installed) policy. When you take an extension off of the force-installed list it's automatically uninstalled by Microsoft Edge.\r\n\r\nFor Windows devices that aren't joined to a Microsoft Active Directory domain, forced installation is limited to extensions available in the Microsoft Store.\r\n\r\nNote that users can modify the source code of any extension by using Developer Tools, potentially rendering the extension dysfunctional. If this is a concern, set the 'DeveloperToolsAvailability' (Control where developer tools can be used) policy.\r\n\r\nUse the following format to add an extension to the list:\r\n\r\n[extensionID];[updateURL]\r\n\r\n- extensionID - the 32-letter string found on edge://extensions when in developer mode.\r\n\r\n- updateURL (optional) is the address of the Update Manifest XML document for the app or extension, as described at https://go.microsoft.com/fwlink/?linkid=2095043. If you don't set the updateURL, the Microsoft Store update URL is used (currently https://edge.microsoft.com/extensionwebstorebase/v1/crx). Note that the update URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL indicated in the extension's manifest.\r\n\r\nFor example, gggmmkjegpiggikcnhidnjjhmicpibll;https://edge.microsoft.com/extensionwebstorebase/v1/crx installs the Microsoft Online app from the Microsoft Store \"update\" URL. For more information about hosting extensions, see: https://go.microsoft.com/fwlink/?linkid=2095044.\r\n\r\nIf you don't configure this policy, no extensions are installed automatically, and users can uninstall any extension in Microsoft Edge.\r\n\r\nNote that this policy doesn't apply to InPrivate mode.\r\n\r\nExample value:\r\n\r\ngbchcmhmhahfdphkhkmpfmihenigjmpp;https://edge.microsoft.com/extensionwebstorebase/v1/crx\r\nabcdefghijklmnopabcdefghijklmnop","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallforcelist_extensioninstallforcelistdesc","displayName":"Extension/App IDs and update URLs to be silently installed (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallsources","displayName":"Configure extension and user script install sources (User)","description":"Define URLs that can install extensions and themes.\r\n\r\nBy default, users have to download a *.crx file for each extension or script they want to install, and then drag it onto the Microsoft Edge settings page. This policy lets specific URLs use install the extension or script for the user.\r\n\r\nEach item in this list is an extension-style match pattern (see https://go.microsoft.com/fwlink/?linkid=2095039). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (in other words, the referrer) must be allowed by these patterns.\r\n\r\nThe 'ExtensionInstallBlocklist' (Control which extensions cannot be installed) policy takes precedence over this policy. Any extensions that's on the block list won't be installed, even if it comes from a site on this list.\r\n\r\nExample value:\r\n\r\nhttps://corp.contoso.com/*","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallsources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallsources_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallsources_extensioninstallsourcesdesc","displayName":"URL patterns to allow extension, app, and user script installs from (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings","displayName":"Configure extension management settings (User)","description":"Configures extension management settings for Microsoft Edge.\r\n\r\nThis policy controls multiple settings, including settings controlled by any existing extension-related policies. This policy overrides any legacy policies if both are set.\r\n\r\nThis policy maps an extension ID or an update URL to its configuration. With an extension ID, the configuration is applied only to the specified extension. Set a default configuration for the special ID \"*\", to apply to all extensions that aren't specifically listed in this policy. With an update URL, the configuration is applied to all extensions with the exact update URL stated in manifest of this extension, as described at https://go.microsoft.com/fwlink/?linkid=2095043.\r\n\r\nExample value:\r\n\r\n{\r\n \"abcdefghijklmnopabcdefghijklmnop\": {\r\n \"blocked_permissions\": [\r\n \"history\"\r\n ], \r\n \"installation_mode\": \"allowed\", \r\n \"minimum_version_required\": \"1.0.1\"\r\n }, \r\n \"bcdefghijklmnopabcdefghijklmnopa\": {\r\n \"runtime_blocked_hosts\": [\r\n \"*://*.contoso.com\"\r\n ], \r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ], \r\n \"update_url\": \"https://contoso.com/update_url\", \r\n \"runtime_allowed_hosts\": [\r\n \"*://good.contoso.com\"\r\n ], \r\n \"installation_mode\": \"force_installed\"\r\n }, \r\n \"cdefghijklmnopabcdefghijklmnopab\": {\r\n \"blocked_install_message\": \"Custom error message.\", \r\n \"installation_mode\": \"blocked\"\r\n }, \r\n \"*\": {\r\n \"blocked_permissions\": [\r\n \"downloads\", \r\n \"bookmarks\"\r\n ], \r\n \"installation_mode\": \"blocked\", \r\n \"runtime_blocked_hosts\": [\r\n \"*://*.contoso.com\"\r\n ], \r\n \"blocked_install_message\": \"Custom error message.\", \r\n \"allowed_types\": [\r\n \"hosted_app\"\r\n ], \r\n \"runtime_allowed_hosts\": [\r\n \"*://good.contoso.com\"\r\n ], \r\n \"install_sources\": [\r\n \"https://company-intranet/apps\"\r\n ]\r\n }, \r\n \"defghijklmnopabcdefghijklmnopabc,efghijklmnopabcdefghijklmnopabcd\": {\r\n \"blocked_install_message\": \"Custom error message.\", \r\n \"installation_mode\": \"blocked\"\r\n }, \r\n \"fghijklmnopabcdefghijklmnopabcde\": {\r\n \"blocked_install_message\": \"Custom removal message.\", \r\n \"installation_mode\": \"removed\"\r\n }, \r\n \"update_url:https://www.contoso.com/update.xml\": {\r\n \"blocked_permissions\": [\r\n \"wallpaper\"\r\n ], \r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ], \r\n \"installation_mode\": \"allowed\"\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings_extensionsettings","displayName":"Configure extension management settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_enablemediarouter","displayName":"Enable Google Cast (User)","description":"Enable this policy to enable Google Cast. Users will be able to launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.\r\n\r\nDisable this policy to disable Google Cast.\r\n\r\nBy default, Google Cast is enabled.","helpText":"","infoUrls":[],"categoryId":"fddc444c-3591-4a50-865b-d8993b798e12","categoryName":"Cast","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_enablemediarouter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_enablemediarouter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_showcasticonintoolbar","displayName":"Show the cast icon in the toolbar (User)","description":"Set this policy to true to show the Cast toolbar icon on the toolbar or the overflow menu. Users won't be able to remove it.\r\n\r\nIf you don't configure this policy or if you disable it, users can pin or remove the icon by using its contextual menu.\r\n\r\nIf you've also set the 'EnableMediaRouter' (Enable Google Cast) policy to false, then this policy is ignored, and the toolbar icon isn't shown.","helpText":"","infoUrls":[],"categoryId":"fddc444c-3591-4a50-865b-d8993b798e12","categoryName":"Cast","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_showcasticonintoolbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_showcasticonintoolbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_allowcrossoriginauthprompt","displayName":"Allow cross-origin HTTP Basic Auth prompts (User)","description":"Controls whether third-party sub-content on a page can open an HTTP Basic Auth dialog box.\r\n\r\nTypically, this is disabled as a phishing defense. If you don't configure this policy, it's disabled and third-party sub-content can't open a HTTP Basic Auth dialog box.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_allowcrossoriginauthprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_allowcrossoriginauthprompt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authnegotiatedelegateallowlist","displayName":"Specifies a list of servers that Microsoft Edge can delegate user credentials to (User)","description":"Configure the list of servers that Microsoft Edge can delegate to.\r\n\r\nSeparate multiple server names with commas. Wildcards (*) are allowed.\r\n\r\nIf you don't configure this policy Microsoft Edge won't delegate user credentials even if a server is detected as Intranet.\r\n\r\nExample value: contoso.com","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authnegotiatedelegateallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authnegotiatedelegateallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authnegotiatedelegateallowlist_authnegotiatedelegateallowlist","displayName":"Specifies a list of servers that Microsoft Edge can delegate user credentials to (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authschemes","displayName":"Supported authentication schemes (User)","description":"Specifies which HTTP authentication schemes are supported.\r\n\r\nYou can configure the policy by using these values: 'basic', 'digest', 'ntlm', and 'negotiate'. Separate multiple values with commas.\r\n\r\nIf you don't configure this policy, all four schemes are used.\r\n\r\nExample value: basic,digest,ntlm,negotiate","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authschemes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authschemes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authschemes_authschemes","displayName":"Supported authentication schemes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authserverallowlist","displayName":"Configure list of allowed authentication servers (User)","description":"Specifies which servers to enable for integrated authentication. Integrated authentication is only enabled when Microsoft Edge receives an authentication challenge from a proxy or from a server in this list.\r\n\r\nSeparate multiple server names with commas. Wildcards (*) are allowed.\r\n\r\nIf you don't configure this policy, Microsoft Edge tries to detect if a server is on the intranet - only then will it respond to IWA requests. If the server is on the internet, IWA requests from it are ignored by Microsoft Edge.\r\n\r\nExample value: *contoso.com,contoso.com","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authserverallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authserverallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authserverallowlist_authserverallowlist","displayName":"Configure list of allowed authentication servers (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_disableauthnegotiatecnamelookup","displayName":"Disable CNAME lookup when negotiating Kerberos authentication (User)","description":"Determines whether the generated Kerberos SPN is based on the canonical DNS name (CNAME) or on the original name entered.\r\n\r\nIf you enable this policy, CNAME lookup is skipped and the server name (as entered) is used.\r\n\r\nIf you disable this policy or don't configure it, the canonical name of the server is used. This is determined through CNAME lookup.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_disableauthnegotiatecnamelookup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_disableauthnegotiatecnamelookup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_enableauthnegotiateport","displayName":"Include non-standard port in Kerberos SPN (User)","description":"Specifies whether the generated Kerberos SPN should include a non-standard port.\r\n\r\nIf you enable this policy, and a user includes a non-standard port (a port other than 80 or 443) in a URL, that port is included in the generated Kerberos SPN.\r\n\r\nIf you don't configure or disable this policy, the generated Kerberos SPN won't include a port in any case.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_enableauthnegotiateport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_enableauthnegotiateport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~identity_nonmicrosoftaccountsigninenabled","displayName":"Enable sign-in to Microsoft Edge using non-Microsoft accounts (User)","description":"This policy controls whether users can sign in to Microsoft Edge using non-Microsoft accounts, such as Google or Apple accounts.\n\nIf you enable this policy or don't configure it, users can sign in to Microsoft Edge with non-Microsoft accounts when the feature is available. Related sign-in entry points, such as Google or Apple sign-in buttons in the profile flyout and unified sign-in experience, are shown when available.\n\nIf you disable this policy, users can't sign in to Microsoft Edge with non-Microsoft accounts. Related sign-in entry points and code paths are hidden and disabled, regardless of related feature flag settings.\n\nUsers can still sign in with Microsoft accounts.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~identity_nonmicrosoftaccountsigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~identity_nonmicrosoftaccountsigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist","displayName":"Control which native messaging hosts users can use (User)","description":"List specific native messaging hosts that users can use in Microsoft Edge.\r\n\r\nBy default, all native messaging hosts are allowed. If you set the 'NativeMessagingBlocklist' (Configure native messaging block list) policy to *, all native messaging hosts are blocked, and only native messaging hosts listed in here are loaded.\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist_nativemessagingallowlistdesc","displayName":"Names of the native messaging hosts to exempt from the block list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingblocklist","displayName":"Configure native messaging block list (User)","description":"Specifies which native messaging hosts that shouldn't be used.\r\n\r\nUse '*' to block all native messaging hosts unless they are explicitly listed in the allow list.\r\n\r\nIf you don't configure this policy, Microsoft Edge will load all installed native messaging hosts.\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingblocklist_nativemessagingblocklistdesc","displayName":"Names of the forbidden native messaging hosts (or * for all) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts","displayName":"Allow user-level native messaging hosts (installed without admin permissions) (User)","description":"Enables user-level installation of native messaging hosts.\r\n\r\nIf you disable this policy, Microsoft Edge will only use native messaging hosts installed on the system level.\r\n\r\nBy default, if you don't configure this policy, Microsoft Edge will allow usage of user-level native messaging hosts.","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordmanagerenabled","displayName":"Enable saving passwords to the password manager (User)","description":"Enable Microsoft Edge to save user passwords.\r\n\r\nIf you enable this policy, users can save their passwords in Microsoft Edge. The next time they visit the site, Microsoft Edge will enter the password automatically.\r\n\r\nIf you disable this policy, users can't save new passwords, but they can still use previously saved passwords.\r\n\r\nIf you enable or disable this policy, users can't change or override it in Microsoft Edge. If you don't configure it, users can save passwords, as well as turn this feature off.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordmanagerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordmanagerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL (User)","description":"Configures the change password URL (HTTP and HTTPS schemes only).\r\n\r\nPassword protection service will send users to this URL to change their password after seeing a warning in the browser.\r\n\r\nIf you enable this policy, then password protection service sends users to this URL to change their password.\r\n\r\nIf you disable this policy or don't configure it, then password protection service will not redirect users to a change password URL.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://contoso.com/change_password.html","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls","displayName":"Configure the list of enterprise login URLs where password protection service should capture fingerprint of password (User)","description":"Configure the list of enterprise login URLs (HTTP and HTTPS schemes only) where Microsoft Edge should capture the fingerprint of passwords and use it for password reuse detection.\r\n\r\nIf you enable this policy, the password protection service captures fingerprints of passwords on the defined URLs.\r\n\r\nIf you disable this policy or don't configure it, no password fingerprints are captured.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com/login.html\r\nhttps://login.contoso.com","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls_passwordprotectionloginurlsdesc","displayName":"Configure the list of enterprise login URLs where password protection service should capture fingerprint of password (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionwarningtrigger","displayName":"Configure password protection warning trigger (User)","description":"Allows you to control when to trigger password protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites.\r\n\r\nYou can use the 'PasswordProtectionLoginURLs' (Configure the list of enterprise login URLs where password protection service should capture fingerprint of password) and 'PasswordProtectionChangePasswordURL' (Configure the change password URL) policies to configure which passwords to protect.\r\n\r\nExemptions: Passwords for the sites listed in 'PasswordProtectionLoginURLs' and 'PasswordProtectionChangePasswordURL', as well as for the sites listed in 'SmartScreenAllowListDomains' (Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings), will not trigger a password-protection warning.\r\n\r\nSet to 'PasswordProtectionWarningOff' (0) to not show password protection warningss.\r\n\r\nSet to 'PasswordProtectionWarningOnPasswordReuse' (1) to show password protection warnings when the user reuses their protected password on a non-allowlisted site.\r\n\r\nIf you disable or don't configure this policy, then the warning trigger is not shown.\r\n\r\n* 0 = Password protection warning is off.\r\n\r\n* 1 = Password protection warning is triggered by password reuse.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionwarningtrigger_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionwarningtrigger_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger","displayName":"Configure password protection warning trigger (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger_0","displayName":"Password protection warning is off","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionwarningtrigger_passwordprotectionwarningtrigger_1","displayName":"Password protection warning is triggered by password reuse","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_defaultprinterselection","displayName":"Default printer selection rules (User)","description":"Overrides Microsoft Edge default printer selection rules. This policy determines the rules for selecting the default printer in Microsoft Edge, which happens the first time a user tries to print a page.\r\n\r\nWhen this policy is set, Microsoft Edge tries to find a printer that matches all of the specified attributes and uses it as default printer. If there are multiple printers that meet the criteria, the first printer that matches is used.\r\n\r\nIf you don't configure this policy or no matching printers are found within the timeout, the printer defaults to the built-in PDF printer or no printer, if the PDF printer isn't available.\r\n\r\nThe value is parsed as a JSON object, conforming to the following schema: { \"type\": \"object\", \"properties\": { \"idPattern\": { \"description\": \"Regular expression to match printer id.\", \"type\": \"string\" }, \"namePattern\": { \"description\": \"Regular expression to match printer display name.\", \"type\": \"string\" } } }\r\n\r\nOmitting a field means all values match; for example, if you don't specify connectivity Print Preview starts discovering all kinds of local printers. Regular expression patterns must follow the JavaScript RegExp syntax and matches are case sensitive.\r\n\r\nExample value: { \"idPattern\": \".*public\", \"namePattern\": \".*Color\" }","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_defaultprinterselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_defaultprinterselection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_defaultprinterselection_defaultprinterselection","displayName":"Default printer selection rules (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printheaderfooter","displayName":"Print headers and footers (User)","description":"Force 'headers and footers' to be on or off in the printing dialog.\r\n\r\nIf you don't configure this policy, users can decide whether to print headers and footers.\r\n\r\nIf you disable this policy, users can't print headers and footers.\r\n\r\nIf you enable this policy, users always print headers and footers.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printheaderfooter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printheaderfooter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printingenabled","displayName":"Enable printing (User)","description":"Enables printing in Microsoft Edge and prevents users from changing this setting.\r\n\r\nIf you enable this policy or don't configure it, users can print.\r\n\r\nIf you disable this policy, users can't print from Microsoft Edge. Printing is disabled in the wrench menu, extensions, JavaScript applications, and so on. Users can still print from plug-ins that bypass Microsoft Edge while printing. For example, certain Adobe Flash applications have the print option in their context menu, which isn't covered by this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printpreviewusesystemdefaultprinter","displayName":"Set the system default printer as the default printer (User)","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\r\n\r\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\r\n\r\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printpreviewusesystemdefaultprinter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printpreviewusesystemdefaultprinter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_usesystemprintdialog","displayName":"Print using system print dialog (User)","description":"Shows the system print dialog instead of print preview.\r\n\r\nIf you enable this policy, Microsoft Edge opens the system print dialog instead of the built-in print preview when a user prints a page.\r\n\r\nIf you don't configure or disable this policy, print commands trigger the Microsoft Edge print preview screen.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_usesystemprintdialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_usesystemprintdialog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxybypasslist","displayName":"Configure proxy bypass rules (User)","description":"Defines a list of hosts for which Microsoft Edge bypasses any proxy.\r\n\r\nThis policy is applied only if you have selected 'Use fixed proxy servers' in the 'ProxyMode' (Configure proxy server settings) policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\r\n\r\nIf you enable this policy, you can create a list of hosts for which Microsoft Edge doesn't use a proxy.\r\n\r\nIf you don't configure this policy, no list of hosts is created for which Microsoft Edge bypasses a proxy. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\r\n\r\nFor more detailed examples go to https://go.microsoft.com/fwlink/?linkid=2094936.\r\n\r\nExample value: https://www.contoso.com, https://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxybypasslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxybypasslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxybypasslist_proxybypasslist","displayName":"Comma-separated list of proxy bypass rules (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode","displayName":"Configure proxy server settings (User)","description":"Specify the proxy server settings used by Microsoft Edge. If you enable this policy, users can't change the proxy settings.\r\n\r\nIf you choose to never use a proxy server and to always connect directly, all other options are ignored.\r\n\r\nIf you choose to use system proxy settings, all other options are ignored.\r\n\r\nIf you choose to auto detect the proxy server, all other options are ignored.\r\n\r\nIf you choose fixed server proxy mode, you can specify further options in 'ProxyServer' (Configure address or URL of proxy server) and 'Comma-separated list of proxy bypass rules'.\r\n\r\nIf you choose to use a .pac proxy script, you must specify the URL to the script in 'URL to a proxy .pac file'.\r\n\r\nFor detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.\r\n\r\nIf you enable this policy, Microsoft Edge will ignore all proxy-related options specified from the command line.\r\n\r\nIf you don't configure this policy users can choose their own proxy settings.\r\n\r\n* \"direct\" = Never use a proxy\r\n\r\n* \"auto_detect\" = Auto detect proxy settings\r\n\r\n* \"pac_script\" = Use a .pac proxy script\r\n\r\n* \"fixed_servers\" = Use fixed proxy servers\r\n\r\n* \"system\" = Use system proxy settings\r\n\r\nExample value: direct","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_proxymode","displayName":"Configure proxy server settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_proxymode_direct","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_proxymode_auto_detect","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_proxymode_pac_script","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_proxymode_fixed_servers","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_proxymode_system","displayName":"Use system proxy settings","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxypacurl","displayName":"Set the proxy .pac file URL (User)","description":"Specifies the URL for a proxy auto-config (PAC) file.\r\n\r\nThis policy is applied only if you selected 'Use a .pac proxy script' in the 'ProxyMode' (Configure proxy server settings) policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\r\n\r\nIf you enable this policy, you can specify the URL for a PAC file, which defines how the browser automatically chooses the appropriate proxy server for fetching a particular website.\r\n\r\nIf you disable or don't configure this policy, no PAC file is specified. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\r\n\r\nFor detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.\r\n\r\nExample value: https://internal.contoso.com/example.pac","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxypacurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxypacurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxypacurl_proxypacurl","displayName":"Set the proxy .pac file URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxyserver","displayName":"Configure address or URL of proxy server (User)","description":"Specifies the URL of the proxy server.\r\n\r\nThis policy is applied only if you have selected 'Use fixed proxy servers' in the 'ProxyMode' (Configure proxy server settings) policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\r\n\r\nIf you enable this policy, the proxy server configured by this policy will be used for all URLs.\r\n\r\nIf you disable or don't configure this policy, users can choose their own proxy settings while in this proxy mode. Leave this policy unconfigured if you've specified any other method for setting proxy policies.\r\n\r\nFor more options and detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936.\r\n\r\nExample value: 123.123.123.123:8080","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxyserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxyserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxyserver_proxyserver","displayName":"Configure address or URL of proxy server (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxysettings","displayName":"Proxy settings (User)","description":"Configures the proxy settings for Microsoft Edge.\r\n\r\nIf you enable this policy, Microsoft Edge ignores all proxy-related options specified from the command line.\r\n\r\nIf you don't configure this policy, users can choose their own proxy settings.\r\n\r\nThis policy overrides the following individual policies:\r\n\r\n'ProxyMode' (Configure proxy server settings)\r\n'ProxyPacUrl' (Set the proxy .pac file URL)\r\n'ProxyServer' (Configure address or URL of proxy server)\r\n'ProxyBypassList' (Configure proxy bypass rules)\r\n\r\nThe ProxyMode field lets you specify the proxy server used by Microsoft Edge and prevents users from changing proxy settings.\r\n\r\nThe ProxyPacUrl field is a URL to a proxy .pac file.\r\n\r\nThe ProxyServer field is a URL for the proxy server.\r\n\r\nThe ProxyBypassList field is a list of proxy hosts that Microsoft Edge bypasses.\r\n\r\nIf you choose the 'direct' value as 'ProxyMode', a proxy is never used and all other fields are ignored.\r\n\r\nIf you choose the 'system' value as 'ProxyMode', the systems's proxy is used and all other fields are ignored.\r\n\r\nIf you choose the 'auto_detect' value as 'ProxyMode', all other fields are ignored.\r\n\r\nIf you choose the 'fixed_server' value as 'ProxyMode', the 'ProxyServer' and 'ProxyBypassList' fields are used.\r\n\r\nIf you choose the 'pac_script' value as 'ProxyMode', the 'ProxyPacUrl' and 'ProxyBypassList' fields are used.\r\n\r\nExample value:\r\n\r\n{\r\n \"ProxyMode\": \"direct\", \r\n \"ProxyPacUrl\": \"https://internal.site/example.pac\", \r\n \"ProxyServer\": \"123.123.123.123:8080\", \r\n \"ProxyBypassList\": \"https://www.example1.com,https://www.example2.com,https://internalsite/\"\r\n}","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxysettings_proxysettings","displayName":"Proxy settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverride","displayName":"Prevent bypassing Microsoft Defender SmartScreen prompts for sites (User)","description":"This policy setting lets you decide whether users can override the Microsoft Defender SmartScreen warnings about potentially malicious websites.\r\n\r\nIf you enable this setting, users can't ignore Microsoft Defender SmartScreen warnings and they are blocked from continuing to the site.\r\n\r\nIf you disable or don't configure this setting, users can ignore Microsoft Defender SmartScreen warnings and continue to the site.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverride_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverride_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverrideforfiles","displayName":"Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads (User)","description":"This policy lets you determine whether users can override Microsoft Defender SmartScreen warnings about unverified downloads.\r\n\r\nIf you enable this policy, users in your organization can't ignore Microsoft Defender SmartScreen warnings, and they're prevented from completing the unverified downloads.\r\n\r\nIf you disable or don't configure this policy, users can ignore Microsoft Defender SmartScreen warnings and complete unverified downloads.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverrideforfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverrideforfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains","displayName":"Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings (User)","description":"Configure the list of Microsoft Defender SmartScreen trusted domains. This means:\r\nMicrosoft Defender SmartScreen won't check for potentially malicious resources like phishing software and other malware if the source URLs match these domains.\r\nThe Microsoft Defender SmartScreen download protection service won't check downloads hosted on these domains.\r\n\r\nIf you enable this policy, Microsoft Defender SmartScreen trusts these domains.\r\nIf you disable or don't set this policy, default Microsoft Defender SmartScreen protection is applied to all resources.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender Advanced Threat Protection. You must configure your allow and block lists in Microsoft Defender Security Center instead.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains_smartscreenallowlistdomainsdesc","displayName":"Configure the list of domains for which SmartScreen won't trigger warnings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenenabled","displayName":"Configure Microsoft Defender SmartScreen (User)","description":"This policy setting lets you configure whether to turn on Microsoft Defender SmartScreen. Microsoft Defender SmartScreen provides warning messages to help protect your users from potential phishing scams and malicious software. By default, Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you enable this setting, Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepageisnewtabpage","displayName":"Set the new tab page as the home page (User)","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\r\n\r\nIf you enable this policy, the new tab page is always used for the home page, and the home page URL location is ignored.\r\n\r\nIf you disable this policy, the user's home page can't be the new tab page, unless the URL is set to 'edge://newtab'.\r\n\r\nIf not configured users can choose whether the new tab page is their home page.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepageisnewtabpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepageisnewtabpage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation","displayName":"Configure the home page URL (User)","description":"Configures the default home page URL in Microsoft Edge.\r\n\r\nThe home page is the page opened by the Home button. The pages that open on startup are controlled by the 'RestoreOnStartup' (Action to take on startup) policies.\r\n\r\nYou can either set a URL here or set the home page to open the new tab page. If you select to open the new tab page, then this policy doesn't take effect.\r\n\r\nIf you enable this policy, users can't change their home page URL, but they can choose to use the new tab page as their home page.\r\n\r\nIf you disable or don't configure this policy, users can choose their own home page, as long as the 'HomepageIsNewTabPage' (Set the new tab page as the home page) policy isn't enabled.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\nExample value: https://www.contoso.com","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation_homepagelocation","displayName":"Home page URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagehidedefaulttopsites","displayName":"Hide the default top sites from the new tab page (User)","description":"Hides the default top sites from the new tab page in Microsoft Edge.\r\n\r\nIf you set this policy to true, the default top site tiles are hidden.\r\n\r\nIf you set this policy to false or don't configure it, the default top site tiles remain visible.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagehidedefaulttopsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagehidedefaulttopsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation","displayName":"Configure the new tab page URL (User)","description":"Configures the default URL for the new tab page.\r\n\r\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\r\n\r\nThis policy doesn't determine which page opens on startup; that's controlled by the 'RestoreOnStartup' (Action to take on startup) policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\r\n\r\nIf you don't configure this policy, the default new tab page is used.\r\n\r\nIf you configure this policy *and* the 'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) policy, this policy has precedence.\r\n\r\nIf an invalid URL is provided, new tabs will open about://blank.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation_newtabpagelocation","displayName":"New tab page URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'Open new tab' (5).\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'Restore the last session' (1). The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'Open a list of URLs' (4).\r\n\r\nDisabling this setting is equivalent to leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\n* 1 = Restore the last session\r\n\r\n* 4 = Open a list of URLs\r\n\r\n* 5 = Open a new tab","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup","displayName":"Action to take on startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartupurls","displayName":"Sites to open when the browser starts (User)","description":"Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup.\r\n\r\nThis policy only works if you also set the 'RestoreOnStartup' (Action to take on startup) policy to 'Open a list of URLs' (4).\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com\r\nhttps://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartupurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartupurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartupurls_restoreonstartupurlsdesc","displayName":"Sites to open when the browser starts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_showhomebutton","displayName":"Show Home button on toolbar (User)","description":"Shows the Home button on Microsoft Edge's toolbar.\r\n\r\nEnable this policy to always show the Home button. Disable it to never show the button.\r\n\r\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_showhomebutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_showhomebutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions","displayName":"Allow download restrictions (User)","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'BlockDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known or potentially dangerous downloads or that have dangerous file type extensions.\r\n\r\nSet 'BlockPotentiallyDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous or unwanted downloads or that have dangerous file type extensions.\r\n\r\nSet 'BlockAllDownloads' to block all downloads.\r\n\r\nSet 'BlockMaliciousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known malicious downloads.\r\n\r\nIf you don't configure this policy or set the 'DefaultDownloadSecurity' option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\nPolicy options mapping:\r\n\r\n* DefaultDownloadSecurity (0) = No special restrictions\r\n\r\n* BlockDangerousDownloads (1) = Block malicious downloads and dangerous file types\r\n\r\n* BlockPotentiallyDangerousDownloads (2) = Block potentially dangerous or unwanted downloads and dangerous file types\r\n\r\n* BlockAllDownloads (3) = Block all downloads\r\n\r\n* BlockMaliciousDownloads (4) = Block malicious downloads\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions","displayName":"Download restrictions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_2","displayName":"Block potentially dangerous or unwanted downloads and dangerous file types","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_4","displayName":"Block malicious downloads","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended","displayName":"Allow download restrictions (User)","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'BlockDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known or potentially dangerous downloads or that have dangerous file type extensions.\r\n\r\nSet 'BlockPotentiallyDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous or unwanted downloads or that have dangerous file type extensions.\r\n\r\nSet 'BlockAllDownloads' to block all downloads.\r\n\r\nSet 'BlockMaliciousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known malicious downloads.\r\n\r\nIf you don't configure this policy or set the 'DefaultDownloadSecurity' option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\nPolicy options mapping:\r\n\r\n* DefaultDownloadSecurity (0) = No special restrictions\r\n\r\n* BlockDangerousDownloads (1) = Block malicious downloads and dangerous file types\r\n\r\n* BlockPotentiallyDangerousDownloads (2) = Block potentially dangerous or unwanted downloads and dangerous file types\r\n\r\n* BlockAllDownloads (3) = Block all downloads\r\n\r\n* BlockMaliciousDownloads (4) = Block malicious downloads\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions","displayName":"Download restrictions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_2","displayName":"Block potentially dangerous or unwanted downloads and dangerous file types","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_4","displayName":"Block malicious downloads","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_adstransparencyenabled","displayName":"Configure if the ads transparency feature is enabled (User)","description":"Lets you decide whether the ads transparency feature is enabled. This behavior only applies to the \"balanced\" mode of tracking prevention, and does not impact \"basic\" or \"strict\" modes. Your users' tracking prevention level can be configured using the 'TrackingPrevention' (Block tracking of users' web-browsing activity) policy. AdsTransparencyEnabled will only have an effect if 'TrackingPrevention' is set to TrackingPreventionBalanced or is not configured.\r\n\r\nIf you enable or don't configure this policy, transparency metadata provided by ads will be available to the user when the feature is active.\r\n\r\nWhen the feature is enabled, Tracking Prevention will enable exceptions for the associated ad providers that have met Microsoft's privacy standards.\r\n\r\nIf you disable this policy, Tracking Prevention will not adjust its behavior even when transparency metadata is provided by ads.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_adstransparencyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_adstransparencyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_hiderestoredialogenabled","displayName":"Hide restore pages dialog after browser crash (User)","description":"This policy gives an option to hide the \"Restore pages\" dialog after Microsoft Edge has crashed. The \"Restore pages\" dialog gives users the option to restore the pages that were previously open before Microsoft Edge crashed.\r\n\r\nIf you enable this policy, the \"Restore pages\" dialog will not be shown. In the event of a crash, Microsoft Edge will not restore previous tabs and will start the session with a new tab page.\r\n\r\nIf you disable or don't set this policy, the \"Restore pages\" dialog will be shown.\r\n\r\nIf you set this policy, do not set the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) or 'SavingBrowserHistoryDisabled' (Disable saving browser history) policy since that prevents history from being saved which also disables the dialog.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_hiderestoredialogenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_hiderestoredialogenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_pdfsecuremode","displayName":"Secure mode and Certificate-based Digital Signature validation in native PDF reader (User)","description":"The policy enables Digital Signature validation for PDF files in a secure environment, which shows the correct validation status of the signatures.\r\n\r\nIf you enable this policy, PDF files with Certificate-based digital signatures are opened with an option to view and verify the validity of the signatures with high security.\r\n\r\nIf you disable or don't configure this policy, the capability to view and verify the signature will not be available.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_pdfsecuremode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_pdfsecuremode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_promptonmultiplematchingcertificates","displayName":"Prompt the user to select a certificate when multiple certificates match (User)","description":"This policy controls whether the user is prompted to select a client certificate when more than one certificate matches 'AutoSelectCertificateForUrls' (Automatically select client certificates for these sites).\r\nIf this policy is set to True, the user is prompted to select a client certificate whenever the auto-selection policy matches multiple certificates.\r\nIf this policy is set to False or not set, the user may only be prompted when no certificate matches the auto-selection.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_promptonmultiplematchingcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_promptonmultiplematchingcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting","displayName":"Control use of the WebHID API (User)","description":"Setting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.\r\n\r\nThis policy can be overridden for specific url patterns using the 'WebHidAskForUrls' (Allow the WebHID API on these sites) and 'WebHidBlockedForUrls' (Block the WebHID API on these sites) policies.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockWebHid (2) = Do not allow any site to request access to HID devices via the WebHID API\r\n\r\n* AskWebHid (3) = Allow sites to ask the user to grant access to a HID device\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_defaultwebhidguardsetting","displayName":"Control use of the WebHID API (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_defaultwebhidguardsetting_2","displayName":"Do not allow any site to request access to HID devices via the WebHID API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_defaultwebhidguardsetting_3","displayName":"Allow sites to ask the user to grant access to a HID device","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls","displayName":"Allow the WebHID API on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\r\n\r\n * 'WebHidBlockedForUrls' (Block the WebHID API on these sites) (if there is a match),\r\n\r\n * 'DefaultWebHidGuardSetting' (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns must not conflict with 'WebHidBlockedForUrls'. Neither policy takes precedence if a URL matches both patterns.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://microsoft.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_webhidaskforurlsdesc","displayName":"Allow the WebHID API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidblockedforurls","displayName":"Block the WebHID API on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\r\n\r\n * 'WebHidAskForUrls' (Allow the WebHID API on these sites) (if there is a match),\r\n\r\n * 'DefaultWebHidGuardSetting' (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns can't conflict with 'WebHidAskForUrls'. Neither policy takes precedence if a URL matches both patterns.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://microsoft.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidblockedforurls_webhidblockedforurlsdesc","displayName":"Block the WebHID API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts","displayName":"Configure the list of commands for which to disable keyboard shortcuts (User)","description":"Configure the list of Microsoft Edge commands for which to disable keyboard shortcuts.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2186950 for a list of possible commands to disable.\r\n\r\nIf you enable this policy, commands in the 'disabled' list will no longer be activated by keyboard shortcuts.\r\n\r\nIf you disable this policy, all keyboard shortcuts behave as usual.\r\n\r\nNote: Disabling a command will only remove its shortcut mapping. Commands in the 'disabled' list will still function if accessed via browser UI.\r\n\r\nExample value:\r\n\r\n{\r\n \"disabled\": [\r\n \"new_tab\",\r\n \"fullscreen\"\r\n ]\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"disabled\": [\"new_tab\", \"fullscreen\"]}","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts_configurekeyboardshortcuts","displayName":"Configure the list of commands for which to disable keyboard shortcuts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_edgeassetdeliveryserviceenabled","displayName":"Allow features to download assets from the Asset Delivery Service (User)","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\r\nThese assets can be config files or Machine Learning models that power the features that use this service.\r\n\r\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\r\n\r\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_edgeassetdeliveryserviceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_edgeassetdeliveryserviceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_internetexplorermodeenablesavepageas","displayName":"Allow Save page as in Internet Explorer mode (User)","description":"This policy enables 'Save page as' functionality in Internet Explorer mode.\r\nUsers can use this option to save the current page in the browser. When a user re-opens a saved page, it will be loaded in the default browser.\r\n\r\nIf you enable this policy, the \"Save page as\" option will be clickable in \"More tools\".\r\n\r\nIf you disable or don't configure this policy, users can't select the \"Save page as\" option in \"More tools\".\r\n\r\nNote: To make the \"Ctrl+S\" shortcut work, users must enable the Internet Explorer policy, 'Enable extended hot key in Internet Explorer mode'.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_internetexplorermodeenablesavepageas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_internetexplorermodeenablesavepageas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_edgeassetdeliveryserviceenabled_recommended","displayName":"Allow features to download assets from the Asset Delivery Service (User)","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\r\nThese assets can be config files or Machine Learning models that power the features that use this service.\r\n\r\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\r\n\r\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_edgeassetdeliveryserviceenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_edgeassetdeliveryserviceenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_sitesafetyservicesenabled_recommended","displayName":"Allow users to configure Site safety services (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nThis policy is obselete as the feature is being removed after Microsoft Edge version 127.\r\n\r\nThis policy disables site safety services from showing top site info in the page info dialog.\r\n\r\nIf you enable this policy or don't configure it, the top site info will be shown.\r\n\r\nIf you disable this policy, the top site info will not be shown.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_sitesafetyservicesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_sitesafetyservicesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended~extensions_recommended_controldefaultstateofallowextensionfromotherstoressettingenabled_recommended","displayName":"Configure default state of Allow extensions from other stores setting (User)","description":"This policy allows you to control the default state of the Allow extensions from other stores setting.\r\nThis policy can't be used to stop installation of extensions from other stores such as Chrome Web Store.\r\nTo stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098.\r\n\r\nWhen enabled, Allow extensions from other stores will be turned on. So, users won't have to turn on the flag manually\r\nwhile installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting.\r\nIf the user has already turned on the setting and then turned it off, this setting may not work.\r\nIf the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it will have no impact on\r\nuser settings and the setting will remain as it is.\r\n\r\nWhen disabled or not configured, the user can manage the Allow extensions from other store setting.","helpText":"","infoUrls":[],"categoryId":"b96b63eb-0292-4a73-85d7-c68d330c109e","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended~extensions_recommended_controldefaultstateofallowextensionfromotherstoressettingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended~extensions_recommended_controldefaultstateofallowextensionfromotherstoressettingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_sitesafetyservicesenabled","displayName":"Allow users to configure Site safety services (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nThis policy is obselete as the feature is being removed after Microsoft Edge version 127.\r\n\r\nThis policy disables site safety services from showing top site info in the page info dialog.\r\n\r\nIf you enable this policy or don't configure it, the top site info will be shown.\r\n\r\nIf you disable this policy, the top site info will not be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_sitesafetyservicesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_sitesafetyservicesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled","displayName":"Default Profile Setting Enabled (User)","description":"Configuring this policy will let you set a default profile in Microsoft Edge to be used when opening the browser rather than the last profile used. This policy won't affect when \"--profile-directory\" parameter has been specified. Set the value to \"Default\" to refer to the default profile. The value is case sensitive.\r\nThe value of the policy is the name of the profile (case sensitive) and can be configured with string that is the name of a specific profile.\r\nThe value \"Edge Kids Mode\" and \"Guest Profile\" are considered not useful values because they not supposed to be a default profile.\r\nThis policy won't impact the following scenarios:\r\n 1) Settings specified in \"Profile preferences for sites\" in \"Profile preferences\"\r\n 2) Links opening from Outlook and Teams.\r\n\r\nThe following statements are under the condition of not specify the \"--profile-directory\" and configured value is not \"Edge Kids Mode\" or \"Guest Profile\":\r\nIf you enable this policy and configure it with a specific profile name and the specified profile can be found, Microsoft Edge will use the specified profile when launching and the setting of \"Default profile for external link\" is changed to the specified profile name and greyed out.\r\nIf you enable this policy and configure it with a specific profile name but it can't be found, the policy will behave like it's never been set before.\r\nIf you enable this policy, but don't configure or disable it, the policy will behave like it's never been set before.\r\n\r\nExample value: Default","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled_edgedefaultprofileenabled","displayName":"Default Profile Setting Enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~kioskmode_kioskswipegesturesenabled","displayName":"Swipe gestures in Microsoft Edge kiosk mode enabled (User)","description":"This policy only applies to Microsoft Edge kiosk mode.\r\n\r\nIf you enable this policy or don't configure it, swipe gestures will behave as expected.\r\n\r\nIf you disable this policy, the user will not be able to use swipe gestures (for example navigate forwards and backwards, refresh page).\r\n\r\nFor detailed information on configuring kiosk mode, see https://go.microsoft.com/fwlink/?linkid=2137578.","helpText":"","infoUrls":[],"categoryId":"d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","categoryName":"Kiosk Mode settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~kioskmode_kioskswipegesturesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~kioskmode_kioskswipegesturesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_networkservicesandboxenabled","displayName":"Enable the network service sandbox (User)","description":"This policy controls whether or not the network service process runs sandboxed.\r\nIf this policy is enabled, the network service process will run sandboxed.\r\nIf this policy is disabled, the network service process will run unsandboxed. This leaves users open to additional security risks related to running the network service unsandboxed.\r\nIf this policy is not set, the default configuration for the network sandbox will be used. This may vary depending on Microsoft Edge release, currently running field trials, and platform.\r\nThis policy is intended to give enterprises flexibility to disable the network sandbox if they use third party software that interferes with the network service sandbox.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_networkservicesandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_networkservicesandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_outlookhubmenuenabled","displayName":"Allow users to access the Outlook menu (User)","description":"This policy is used to manage access to the Outlook menu from Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, users can access the Outlook menu.\r\nIf you disable this policy, users can't access the Outlook menu.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_outlookhubmenuenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_outlookhubmenuenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_recommended_outlookhubmenuenabled_recommended","displayName":"Allow users to access the Outlook menu (User)","description":"This policy is used to manage access to the Outlook menu from Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, users can access the Outlook menu.\r\nIf you disable this policy, users can't access the Outlook menu.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_recommended_outlookhubmenuenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_recommended_outlookhubmenuenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_settimeoutwithout1msclampenabled","displayName":"Control Javascript setTimeout() function minimum timeout (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nWhen the policy is set to Enabled, the Javascript setTimeout() with a timeout of 0ms will no longer be fixed to 1ms to schedule timer-based callbacks.\r\nWhen the policy is set to Disabled, the Javascript setTimeout() with a timeout of 0ms will be fixed to 1ms to schedule timer-based callbacks.\r\nWhen the policy is unset, use the browser's default behavior for setTimeout() function.\r\n\r\nThis is a web standards compliancy feature, but it may change task ordering on a web page, leading to unexpected behavior on sites that are dependent on a certain ordering.\r\nIt also may affect sites with a lot of setTimeout()s with a timeout of 0ms usage. For example, increasing CPU load.\r\n\r\nFor users where this policy is unset, Microsoft Edge Stable will roll out the change gradually on the stable channel.\r\n\r\nThis is a temporary policy that is planned to be removed in Microsoft Edge Stable 105.\r\nThis deadline may be extended if there is a need for enterprises.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_settimeoutwithout1msclampenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_settimeoutwithout1msclampenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_useragentclienthintsgreaseupdateenabled","displayName":"Control the User-Agent Client Hints GREASE Update feature (User)","description":"The User-Agent GREASE specification recommends the inclusion of additional GREASE characters beyond the current semicolon and space, and recommends that the arbitrary version number be varied over time.\r\n\r\nWhen enabled, the User-Agent Client Hints GREASE Update feature aligns the User-Agent GREASE algorithm with the latest version from the specification. The updated specification may break some websites that restrict the characters that requests may contain. For more information, see the following specification: https://wicg.github.io/ua-client-hints/#grease\r\n\r\nIf this policy is enabled or not configured, the User-Agent GREASE algorithm from the specification will be used. If the policy is disabled, the prior User-Agent GREASE algorithm will be used.\r\n\r\nThis policy is a temporary measure and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_useragentclienthintsgreaseupdateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_useragentclienthintsgreaseupdateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge~httpauthentication_allhttpauthschemesallowedfororigins","displayName":"List of origins that allow all HTTP authentication (User)","description":"Set this policy to specify which origins allow all the HTTP authentication schemes Microsoft Edge supports regardless of the 'AuthSchemes' (Supported authentication schemes) policy.\r\n\r\nFormat the origin pattern according to this format (https://support.google.com/chrome/a?p=url_blocklist_filter_format). Up to 1,000 exceptions can be defined in 'AllHttpAuthSchemesAllowedForOrigins' (List of origins that allow all HTTP authentication).\r\nWildcards are allowed for the whole origin or parts of the origin. Parts include the scheme, host, or port.\r\n\r\nExample value:\r\n\r\n*.example.com","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge~httpauthentication_allhttpauthschemesallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge~httpauthentication_allhttpauthschemesallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge~httpauthentication_allhttpauthschemesallowedfororigins_allhttpauthschemesallowedfororiginsdesc","displayName":"List of origins that allow all HTTP authentication (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_internetexplorerzoomdisplay","displayName":"Display zoom in IE Mode tabs with DPI Scale included like it is in Internet Explorer (User)","description":"Lets you display zoom in IE Mode tabs similar to how it was displayed in Internet Explorer, where the DPI scale of the display is factored in.\r\n\r\nFor example, if you have a page zoomed to 200% on a 100 DPI scale display and you change the display to 150 DPI, Microsoft Edge would still display the zoom as 200%. However, Internet Explorer factors in the DPI scale and displays 300%.\r\n\r\nIf you enable this policy, zoom values will be displayed with the DPI scale included for IE Mode tabs.\r\n\r\nIf you disable or don't configure this policy, zoom values will be displayed without DPI scale included for IE Mode tabs","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_internetexplorerzoomdisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_internetexplorerzoomdisplay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_livecaptionsallowed","displayName":"Live captions allowed (User)","description":"Allow users to turn the Live captions feature on or off.\r\n\r\nLive captions is an accessibility feature that converts speech from the audio that plays in Microsoft Edge in to text and shows this text in a separate window. The entire process happens on the device and no audio or caption text ever leaves the device.\r\n\r\nNote: This feature is not generally available. Clients that have the 'ExperimentationAndConfigurationServiceControl' (Control communication with the Experimentation and Configuration Service) policy set to 'FullMode' may receive the feature before broad availability. Broad availability will be announced via Microsoft Edge release notes.\r\n\r\nIf you enable or don't configure this policy, users can turn this feature on or off at edge://settings/accessibility.\r\n\r\nIf you disable this policy, users will not be able to turn this accessibility feature on. If speech recognition files have been downloaded previously, they will be deleted from the device in 30 days. We recommend avoiding this option unless it's needed in your environment.\r\n\r\nIf users choose to turn on Live captions, speech recognition files (approximately 100 megabytes) will be downloaded to the device on first run and then periodically to improve performance and accuracy. These files will be deleted after 30 days.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_livecaptionsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_livecaptionsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_originagentclusterdefaultenabled","displayName":"Origin-keyed agent clustering enabled by default (User)","description":"The Origin-Agent-Cluster: HTTP header controls whether a document is isolated in an origin-keyed agent cluster or in a site-keyed agent cluster. This has security implications because an origin-keyed agent cluster allows isolating documents by origin. The consequence of this for developers is that the document.domain accessor can no longer be set when origin-keyed agent clustering is enabled.\r\n\r\nIf you enable or don't configure this policy, documents without the Origin-Agent-Cluster: header will be assigned to origin-keyed agent clustering by default. On these documents, the document.domain accessor will not be settable.\r\n\r\nIf you disable this policy, documents without the Origin-Agent-Cluster: header will be assigned to site-keyed agent clusters by default. On these documents, the document.domain accessor will be settable.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2191896 for additional details.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_originagentclusterdefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_originagentclusterdefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled","displayName":"Guided Switch Enabled (User)","description":"Allows Microsoft Edge to prompt the user to switch to the appropriate profile when Microsoft Edge detects that a link is a personal or work link.\r\n\r\nIf you enable this policy, you'll be prompted to switch to another account if the current profile doesn't work for the requesting link.\r\n\r\nIf you disable this policy, you won't be prompted to switch to another account when there's a profile and link mismatch.\r\n\r\nIf this policy isn't configured, guided switch is turned on by default. A user can override this value in the browser settings.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace (User)","description":"Setting the policy on Microsoft Edge turns on the restricted sign-in feature in Google Workspace and prevents users from changing this setting. Users can only access Google tools using accounts from the specified domains. To allow gmail or googlemail accounts, add consumer_accounts to the list of domains. This policy is based on the Chrome policy of the same name.\r\n\r\nIf you don't provide a domain name or leave this policy unset, users can access Google Workspace with any account.\r\n\r\nUsers cannot change or override this setting.\r\n\r\nNote: This policy causes the X-GoogApps-Allowed-Domains header to be appended to all HTTP and HTTPS requests to all google.com domains, as described in https://go.microsoft.com/fwlink/?linkid=2197973.\r\n\r\nExample value: example.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_alloweddomainsforapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_alloweddomainsforapps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_alloweddomainsforapps_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_askbeforecloseenabled","displayName":"Get user confirmation before closing a browser window with multiple tabs (User)","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\r\n\r\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\r\n\r\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_askbeforecloseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_askbeforecloseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting","displayName":"Configure browser process code integrity guard setting (User)","description":"This policy controls the use of code integrity guard in the browser process, which only allows Microsoft signed binaries to load.\r\n\r\nSetting this policy to Enabled will enable code integrity guard in the browser process.\r\n\r\nSetting this policy to Disabled, or if the policy is not set, will prevent the browser from enabling code integrity guard in the browser process.\r\n\r\nThe policy value Audit (1) is obsolete as of version 110. Setting this value is equivalent to the Disabled value.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro or Enterprise instances that enrolled for device management.\r\n\r\nThis policy will only take effect on Windows 10 RS2 and above.\r\n\r\nPolicy options mapping:\r\n\r\n* Disabled (0) = Do not enable code integrity guard in the browser process.\r\n\r\n* Audit (1) = Enable code integrity guard audit mode in the browser process.\r\n\r\n* Enabled (2) = Enable code integrity guard enforcement in the browser process.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_browsercodeintegritysetting","displayName":"Configure browser process code integrity guard setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_browsercodeintegritysetting_0","displayName":"Do not enable code integrity guard in the browser process.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_browsercodeintegritysetting_1","displayName":"Enable code integrity guard audit mode in the browser process.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_browsercodeintegritysetting_2","displayName":"Enable code integrity guard enforcement in the browser process.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_doubleclickclosetabenabled","displayName":"Double Click feature in Microsoft Edge enabled (only available in China) (User)","description":"This policy lets you configure the double click feature in Microsoft Edge.\r\n\r\nDouble Click lets users close a tab by double clicking the left mouse button.\r\n\r\nIf you enable or don't configure this policy, you can use the double click feature to close a tab on Microsoft Edge to start using this feature.\r\n\r\nIf you disable this policy, you can't use the double click feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_doubleclickclosetabenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_doubleclickclosetabenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_edgeedropenabled","displayName":"Enable Drop feature in Microsoft Edge (User)","description":"This policy lets you configure the Drop feature in Microsoft Edge.\r\n\r\nDrop lets users send messages or files to themselves.\r\n\r\nIf you enable or don't configure this policy, you can use the Drop feature in Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Drop feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_edgeedropenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_edgeedropenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_importoneachlaunch","displayName":"Allow import of data from other browsers on each Microsoft Edge launch (User)","description":"If you enable this policy, users will see a prompt to import their browsing data from other browsers on each Microsoft Edge launch.\r\n\r\nIf you disable this policy, users will never see a prompt to import their browsing data from other browsers on each Microsoft Edge launch.\r\n\r\nIf the policy is left unconfigured, users can activate this feature from a Microsoft Edge prompt or from the Settings page.\r\n\r\nNote: A similar policy named 'AutoImportAtFirstRun' (Automatically import another browser's data and settings at first run) exists. This policy should be used if you want to import supported data from other browsers only once while setting up your device.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_importoneachlaunch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_importoneachlaunch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_pdfxfaenabled","displayName":"XFA support in native PDF reader enabled (User)","description":"Lets the Microsoft Edge browser enable XFA (XML Forms Architecture) support in the native PDF reader and allows users to open XFA PDF files in the browser.\r\n\r\nIf you enable this policy, XFA support in the native PDF reader will be enabled.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not enable XFA support in the native PDF reader.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_pdfxfaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_pdfxfaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_quicksearchshowminimenu","displayName":"Enables Microsoft Edge mini menu (User)","description":"Enables Microsoft Edge mini menu on websites and PDFs. The mini menu is triggered on text selection and has basic actions like copy and smart actions like definitions.\r\n\r\nIf you enable or don't config this policy, selecting text on websites and PDFs will show the Microsoft Edge mini menu.\r\n\r\nIf you disable this policy, the Microsoft Edge mini menu will not be shown when text on websites and PDFs is selected.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_quicksearchshowminimenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_quicksearchshowminimenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_askbeforecloseenabled_recommended","displayName":"Get user confirmation before closing a browser window with multiple tabs (User)","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\r\n\r\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\r\n\r\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_askbeforecloseenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_askbeforecloseenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_quicksearchshowminimenu_recommended","displayName":"Enables Microsoft Edge mini menu (User)","description":"Enables Microsoft Edge mini menu on websites and PDFs. The mini menu is triggered on text selection and has basic actions like copy and smart actions like definitions.\r\n\r\nIf you enable or don't config this policy, selecting text on websites and PDFs will show the Microsoft Edge mini menu.\r\n\r\nIf you disable this policy, the Microsoft Edge mini menu will not be shown when text on websites and PDFs is selected.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_quicksearchshowminimenu_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_quicksearchshowminimenu_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_textpredictionenabled","displayName":"Text prediction enabled by default (User)","description":"The Microsoft Turing service uses natural language processing to generate predictions for long-form editable text fields on web pages.\r\n\r\nIf you enable or don't configure this policy, text predictions will be provided for eligible text fields.\r\n\r\nIf you disable this policy, text predictions will not be provided in eligible text fields. Sites may still provide their own text predictions.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_textpredictionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_textpredictionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge~passwordmanager_passwordmanagerrestrictlengthenabled","displayName":"Restrict the length of passwords that can be saved in the Password Manager (User)","description":"Make Microsoft Edge restrict the length of usernames and/or passwords that can be saved in the Password Manager.\r\n\r\nIf you enable this policy, Microsoft Edge will not let the user save credentials with usernames and/or passwords longer than 256 characters.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will let the user save credentials with arbitrarily long usernames and/or passwords.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge~passwordmanager_passwordmanagerrestrictlengthenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge~passwordmanager_passwordmanagerrestrictlengthenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_exemptfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (User)","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users would not see a warning when downloading \"jnlp\" files from \"website1.com\", but see a download warning when downloading \"jnlp\" files from \"website2.com\".\r\n\r\nFiles with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\r\n\r\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.\r\n\r\nIf you enable this policy:\r\n\r\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list \"jnlp\" should be used instead of \".jnlp\".\r\n\r\nExample:\r\n\r\nThe following example value would prevent file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\r\n\r\n[\r\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\r\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\r\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\r\n]\r\n\r\nNote that while the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"domains\": [\r\n \"https://contoso.com\",\r\n \"contoso2.com\"\r\n ],\r\n \"file_extension\": \"jnlp\"\r\n },\r\n {\r\n \"domains\": [\r\n \"*\"\r\n ],\r\n \"file_extension\": \"swf\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_exemptfiletypedownloadwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_exemptfiletypedownloadwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_exemptfiletypedownloadwarnings_exemptfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_internetexplorerintegrationalwayswaitforunload","displayName":"Wait for Internet Explorer mode tabs to completely unload before ending the browser session (User)","description":"This policy causes Microsoft Edge to continue running until all Internet Explorer tabs have completely finished unloading. This allows Internet Explorer plugins like ActiveX controls to perform additional critical work even after the browser has been closed. However, this can cause stability and performance issues, and Microsoft Edge processes may remain active in the background with no visible windows if the webpage or plugin prevents Internet Explorer from unloading. This policy should only be used if your organization depends on a plugin that requires this behavior.\r\n\r\nIf you enable this policy, Microsoft Edge will always wait for Internet Explorer mode tabs to fully unload before ending the browser session.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not always wait for Internet Explorer mode tabs to fully unload before ending the browser session.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2174004","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_internetexplorerintegrationalwayswaitforunload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_internetexplorerintegrationalwayswaitforunload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled","displayName":"Spell checking provided by Microsoft Editor (User)","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages.\r\n\r\nIf you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields.\r\n\r\nIf you disable this policy, spell check can only be provided by local engines that use platform or Hunspell services. The results from these engines might be less informative than the results Microsoft Editor can provide.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy is set to disabled, or the user disables spell checking in the settings page, this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorsynonymsenabled","displayName":"Synonyms are provided when using Microsoft Editor spell checker (User)","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages, and synonyms can be suggested as an integrated feature.\r\n\r\nIf you enable this policy, Microsoft Editor spell checker will provide synonyms for suggestions for misspelled words.\r\n\r\nIf you disable or don't configure this policy, Microsoft Editor spell checker will not provide synonyms for suggestions for misspelled words.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy or the 'MicrosoftEditorProofingEnabled' (Spell checking provided by Microsoft Editor) policy are set to disabled, or the user disables spell checking or chooses not to use Microsoft Editor spell checker in the settings page, this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorsynonymsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorsynonymsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (User)","description":"If FriendlyURLs are enabled, Microsoft Edge will compute additional representations of the URL and place them on the clipboard.\r\n\r\nThis policy configures what format will be pasted when the user pastes in external applications, or inside Microsoft Edge without the 'Paste as' context menu item.\r\n\r\nIf configured, this policy makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu will not be available.\r\n\r\n* Not configured = The user will be able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\r\n\r\n* 1 = No additional formats will be stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature will be disabled.\r\n\r\n* 3 = The user will get a friendly URL whenever they paste into surfaces that accept rich text. The plain URL will still be available for non-rich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\r\n\r\n* 4 = (Not currently used)\r\n\r\nThe richer formats may not be well-supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy.\r\n\r\nThe recommended policy is available in Microsoft Edge 105 or later.\r\n\r\nPolicy options mapping:\r\n\r\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\r\n\r\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.\r\n\r\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_configurefriendlyurlformat_1","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_configurefriendlyurlformat_3","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_configurefriendlyurlformat_4","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_unthrottlednestedtimeoutenabled","displayName":"JavaScript setTimeout will not be clamped until a higher nesting threshold is set (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because it is a temporary policy for web standards compliance. It won't work in Microsoft Edge as soon as version 107.\r\nIf you enable this policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4ms, will not be clamped. This improves short horizon performance, but websites abusing the API will still eventually have their setTimeout usages clamped.\r\nIf you disable or don't configure policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4ms, will be clamped.\r\n\r\nThis is a web standards compliancy feature that may change task ordering on a web page, leading to unexpected behavior on sites that are dependent on a certain ordering.\r\nIt also may affect sites with a lot of usage of a timeout of 0ms for setTimeout. For example, increasing CPU load.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_unthrottlednestedtimeoutenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_unthrottlednestedtimeoutenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_internetexplorerintegrationalwaysuseoscapture","displayName":"Always use the OS capture engine to avoid issues with capturing Internet Explorer mode tabs (User)","description":"Configure this policy to control whether Microsoft Edge will use the \"OS capture engine\" or the \"Browser capture engine\" when capturing browser windows in the same process using the screen-share APIs.\r\n\r\nYou should configure this policy if you want to capture the contents of Internet Explorer mode tabs. However, enabling this policy may negatively impact performance when capturing browser windows in the same process.\r\n\r\nThis policy only affects window capture, not tab capture. The contents of Internet Explorer mode tabs will not be captured when you choose to capture only a single tab, even if you configure this policy.\r\n\r\nIf you enable this policy, Microsoft Edge will always use the OS capture engine for window capture. Internet Explorer mode tabs will have their contents captured.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use the Browser capture engine for browser windows in the same process. Internet Explorer mode tabs in these windows will not have their contents captured.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2174004","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_internetexplorerintegrationalwaysuseoscapture_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_internetexplorerintegrationalwaysuseoscapture_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeenabled_recommended","displayName":"Efficiency mode enabled (User)","description":"Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and disabled otherwise.\r\n\r\nIf you enable this policy, efficiency mode will become active according to the setting chosen by the user. You can configure the efficiency mode setting using the 'EfficiencyMode' (Configure when efficiency mode should become active) policy. If the device does not have a battery, efficiency mode will always be active.\r\n\r\nIf you disable this policy, efficiency mode will never become active. The 'EfficiencyMode' and 'EfficiencyModeOnPowerEnabled' (Enable efficiency mode when the device is connected to a power source) policies will have no effect.\r\n\r\nIf you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeonpowerenabled_recommended","displayName":"Enable efficiency mode when the device is connected to a power source (User)","description":"Allows efficiency mode to become active when the device is connected to a power source. On devices with no battery, this policy has no effect.\r\n\r\nIf you enable this policy, efficiency mode will become active when the device is connected to a power source.\r\n\r\nIf you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeonpowerenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeonpowerenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeenabled","displayName":"Efficiency mode enabled (User)","description":"Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and disabled otherwise.\r\n\r\nIf you enable this policy, efficiency mode will become active according to the setting chosen by the user. You can configure the efficiency mode setting using the 'EfficiencyMode' (Configure when efficiency mode should become active) policy. If the device does not have a battery, efficiency mode will always be active.\r\n\r\nIf you disable this policy, efficiency mode will never become active. The 'EfficiencyMode' and 'EfficiencyModeOnPowerEnabled' (Enable efficiency mode when the device is connected to a power source) policies will have no effect.\r\n\r\nIf you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeonpowerenabled","displayName":"Enable efficiency mode when the device is connected to a power source (User)","description":"Allows efficiency mode to become active when the device is connected to a power source. On devices with no battery, this policy has no effect.\r\n\r\nIf you enable this policy, efficiency mode will become active when the device is connected to a power source.\r\n\r\nIf you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeonpowerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeonpowerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~printing_printpdfasimagedefault","displayName":"Print PDF as Image Default (User)","description":"Controls if Microsoft Edge makes the Print as image option the default when printing PDFs.\r\n\r\nIf you enable this policy, Microsoft Edge will default to setting the Print as image option in the Print Preview when printing a PDF.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not default to setting the Print as image option in the Print Preview when printing a PDF.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~printing_printpdfasimagedefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~printing_printpdfasimagedefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_enhancesecuritymodebypassintranet","displayName":"Enhanced Security Mode configuration for Intranet zone sites (User)","description":"Microsoft Edge will apply Enhanced Security Mode on Intranet zone sites by default. This may lead to Intranet zone sites acting in an unexpected manner.\r\n\r\nIf you enable this policy, Microsoft Edge won't apply Enhanced Security Mode on Intranet zone sites.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will apply Enhanced Security Mode on Intranet zone sites.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_enhancesecuritymodebypassintranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_enhancesecuritymodebypassintranet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_eventpathenabled","displayName":"Re-enable the Event.path API until Microsoft Edge version 115 (User)","description":"Starting in Microsoft Edge version 109, the non-standard API Event.path will be removed to improve web compatibility. This policy re-enables the API until version 115.\r\n\r\nIf you enable this policy, the Event.path API will be available.\r\n\r\nIf you disable this policy, the Event.path API will be unavailable.\r\n\r\nIf this policy is not set, the Event.path API will be in the following default states: available before version 109, and unavailable in version 109 to version 114.\r\n\r\nThis policy will be made obsolete after Microsoft Edge version 115.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_eventpathenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_eventpathenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_internetexplorerintegrationlocalmhtfileallowed","displayName":"Allow local MHTML files to open automatically in Internet Explorer mode (User)","description":"This policy controls whether local mht or mhtml files launched from the command line can open automatically in Internet Explorer mode based on the file content without specifying the --ie-mode-file-url command line.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'\r\nand\r\n'InternetExplorerIntegrationLocalFileAllowed' (Allow launching of local files in Internet Explorer mode) is enabled or not configured.\r\n\r\nIf you enable or don't configure this policy, local mht or mhtml files can launch in Microsoft Edge or Internet Explorer mode to best view the file.\r\n\r\nIf you disable this policy, local mht or mhtml files will launch in Microsoft Edge.\r\n\r\nNote that if you use the --ie-mode-file-url command line argument for launching local mht or mhtml files, it takes precedence over how you configured this policy.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_internetexplorerintegrationlocalmhtfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_internetexplorerintegrationlocalmhtfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended","displayName":"Performance Detector Enabled (User)","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\r\n\r\nIf you enable or don't configure this policy, performance detector is turned on.\r\n\r\nIf you disable this policy, performance detector is turned off.\r\n\r\nThe user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled","displayName":"Web Select Enabled (User)","description":"Web select lets users select and copy web content while preserving its formatting when pasted in most cases. It also allows more targeted selection on some web elements, such as copying a single column in a table.\r\n\r\nIf you enable or don't configure this policy, Web select is available through the right click context menu and the CTRL+SHIFT+X keyboard shortcut.\r\n\r\nIf you disable this policy, Web select won't be available.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlaccess","displayName":"Force WebSQL to be enabled (User)","description":"WebSQL is on by default as of Microsoft Edge version 101, but can be disabled via a Microsoft Edge flag.\r\nIf you enable this policy, WebSQL cannot be disabled.\r\nIf you disable or don't configure this policy, WebSQL can be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled","displayName":"Force WebSQL in non-secure contexts to be enabled (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because it is a temporary policy to support WebSQL in non-secure contexts. It won't work in Microsoft Edge as soon as version 110.\r\nIf you enable this policy, WebSQL in non-secure contexts will be enabled.\r\nIf you disable or don't configure this policy, WebSQL in non-secure contexts will follow the default settings of the broser.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~edgeworkspaces_edgeworkspacesenabled","displayName":"Enable Workspaces (User)","description":"Microsoft Edge Workspaces helps improve productivity for users in your organization.\r\n\r\nIf you enable this policy, users will be able to access the Microsoft Edge Workspaces feature.\r\nIf you disable or don't configure this policy, users will not be able to access the Microsoft Edge Workspaces feature.\r\n\r\nTo learn more about the feature, see https://go.microsoft.com/fwlink/?linkid=2209950","helpText":"","infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~edgeworkspaces_edgeworkspacesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~edgeworkspaces_edgeworkspacesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~identity_linkedaccountenabled","displayName":"Enable the linked account feature (User)","description":"Microsoft Edge guides a user to the account management page where they can link a Microsoft Account (MSA) to an Azure Active Directory (Azure AD) account.\r\n\r\nIf you enable or don't configure this policy, linked account information will be shown on a flyout. When the Azure AD profile doesn't have a linked account it will show \"Add account\".\r\n\r\nIf you disable this policy, linked accounts will be turned off and no extra information will be shown.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~identity_linkedaccountenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~identity_linkedaccountenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~performance_performancedetectorenabled","displayName":"Performance Detector Enabled (User)","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\r\n\r\nIf you enable or don't configure this policy, performance detector is turned on.\r\n\r\nIf you disable this policy, performance detector is turned off.\r\n\r\nThe user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~performance_performancedetectorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~performance_performancedetectorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~startup_restoreonstartupuserurlsenabled","displayName":"Allow users to add and remove their own sites during startup when the RestoreOnStartupURLs policy is configured (User)","description":"If you enable this policy, users are allowed to add and remove their own URLs to open when starting Edge while maintaining the admin specified mandatory list of sites specified by setting 'RestoreOnStartup' (Action to take on startup) policy to open a list of URLS and providing the list of sites in the 'RestoreOnStartupURLs' (Sites to open when the browser starts) policy.\r\n\r\nIf you disable or don't configure this policy, there is no change to how the 'RestoreOnStartup' and 'RestoreOnStartupURLs' policies work.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~startup_restoreonstartupuserurlsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge~startup_restoreonstartupuserurlsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting","displayName":"Set the default \"share additional operating system region\" setting (User)","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\r\n\r\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting will be shared with the web through the default JavaScript locale. If shared, websites will be able to query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\r\n\r\nIf you set this policy to \"Limited\", the OS Regional format will only be shared if its language part matches the Microsoft Edge display language.\r\n\r\nIf you set this policy to \"Always\", the OS Regional format will always be shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months can be displayed in one language while the surrounding text is displayed in another language.\r\n\r\nIf you set this policy to \"Never\", the OS Regional format will never be shared.\r\n\r\nExample 1: In this example the OS Regional format is set to \"en-GB\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Limited\", or \"Always\".\r\n\r\nExample 2: In this example the OS Regional format is set to \"es-MX\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Always\" but will not if the policy is set to \"Limited\".\r\n\r\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282\r\n\r\nPolicy options mapping:\r\n\r\n* Limited (0) = Limited\r\n\r\n* Always (1) = Always share the OS Regional format\r\n\r\n* Never (2) = Never share the OS Regional format\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting_defaultshareadditionalosregionsetting","displayName":"'Set the default \"share additional operating system region\" setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting_defaultshareadditionalosregionsetting_0","displayName":"Limited","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting_defaultshareadditionalosregionsetting_1","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_defaultshareadditionalosregionsetting_defaultshareadditionalosregionsetting_2","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_encryptedclienthelloenabled","displayName":"TLS Encrypted ClientHello Enabled (User)","description":"Encrypted ClientHello (ECH) is an extension to TLS that encrypts the sensitive fields of ClientHello to improve privacy.\r\n\r\nIf ECH is enabled, Microsoft Edge might or might not use ECH depending on server support, the availability of the HTTPS DNS record, or the rollout status.\r\n\r\nIf you enable or do not configure this policy, Microsoft Edge will follow the default rollout process for ECH.\r\n\r\nIf this policy is disabled, Microsoft Edge will not enable ECH.\r\n\r\nBecause ECH is an evolving protocol, Microsoft Edge's implementation is subject to change.\r\n\r\nAs such, this policy is a temporary measure to control the initial experimental implementation. It will be replaced with final controls as the protocol finalizes.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_encryptedclienthelloenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_encryptedclienthelloenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended","displayName":"Set the default \"share additional operating system region\" setting (User)","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\r\n\r\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting will be shared with the web through the default JavaScript locale. If shared, websites will be able to query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\r\n\r\nIf you set this policy to \"Limited\", the OS Regional format will only be shared if its language part matches the Microsoft Edge display language.\r\n\r\nIf you set this policy to \"Always\", the OS Regional format will always be shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months can be displayed in one language while the surrounding text is displayed in another language.\r\n\r\nIf you set this policy to \"Never\", the OS Regional format will never be shared.\r\n\r\nExample 1: In this example the OS Regional format is set to \"en-GB\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Limited\", or \"Always\".\r\n\r\nExample 2: In this example the OS Regional format is set to \"es-MX\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Always\" but will not if the policy is set to \"Limited\".\r\n\r\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282\r\n\r\nPolicy options mapping:\r\n\r\n* Limited (0) = Limited\r\n\r\n* Always (1) = Always share the OS Regional format\r\n\r\n* Never (2) = Never share the OS Regional format\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting","displayName":"'Set the default \"share additional operating system region\" setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting_0","displayName":"Limited","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting_1","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting_2","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge~startup_newtabpageapplauncherenabled","displayName":"Hide App Launcher on Microsoft Edge new tab page (User)","description":"By default, the App Launcher is shown every time a user opens a new tab page.\r\n\r\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge new tab page and App Launcher is there for users.\r\n\r\nIf you disable this policy, App Launcher doesn't appear and users won't be able to launch M365 apps from Microsoft Edge new tab page via the App Launcher.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge~startup_newtabpageapplauncherenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge~startup_newtabpageapplauncherenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls","displayName":"Allow clipboard use on specific sites (User)","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\r\n\r\nSetting the policy lets you create a list of URL patterns that specify which sites can use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\r\n\r\nLeaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set. If it isn't set, the user's personal setting applies.\r\n\r\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls_clipboardallowedforurlsdesc","displayName":"Allow clipboard use on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls","displayName":"Block clipboard use on specific sites (User)","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\r\n\r\nSetting the policy lets you create a list of URL patterns that specify sites that can't use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\r\n\r\nLeaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set. If it isn't set, the user's personal setting applies.\r\n\r\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_clipboardblockedforurlsdesc","displayName":"Block clipboard use on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting","displayName":"Default clipboard site permission (User)","description":"This policy controls the default value for the clipboard site permission.\r\n\r\nSetting the policy to 2 blocks sites from using the clipboard site permission.\r\n\r\nSetting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use an API.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'ClipboardAllowedForUrls' (Allow clipboard use on specific sites) and 'ClipboardBlockedForUrls' (Block clipboard use on specific sites) policies.\r\n\r\nThis policy only affects clipboard operations controlled by the clipboard site permission and doesn't affect sanitized clipboard writes or trusted copy and paste operations.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockClipboard (2) = Do not allow any site to use the clipboard site permission\r\n\r\n* AskClipboard (3) = Allow sites to ask the user to grant the clipboard site permission\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_defaultclipboardsetting","displayName":"Default clipboard site permission (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_defaultclipboardsetting_2","displayName":"Do not allow any site to use the clipboard site permission","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_defaultclipboardsetting_3","displayName":"Allow sites to ask the user to grant the clipboard site permission","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled","displayName":"Determines whether the Microsoft Root Store and built-in certificate verifier will be used to verify server certificates (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 114.\r\n\r\nWhen this policy is set to enabled, Microsoft Edge will perform verification of server certificates using the built-in certificate verifier with the Microsoft Root Store as the source of public trust.\r\n\r\nWhen this policy is set to disabled, Microsoft Edge will use the system certificate verifier and system root certificates.\r\n\r\nWhen this policy is not set, the Microsoft Root Store or system provided roots may be used.\r\n\r\nThis policy is planned to be removed in Microsoft Edge version\r\n121 for Android devices when support for using the platform supplied roots is planned to be removed.\r\n\r\nThis policy was removed in Microsoft Edge version 115 for\r\nMicrosoft Windows and macOS,\r\nMicrosoft Edge version 120 for\r\nLinux, and\r\nMicrosoft Edge version 121 for\r\nAndroid\r\nwhen support for using the platform supplied certificate verifier and roots was removed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowalldevicesforurls","displayName":"Allow listed sites to connect to any HID device (User)","description":"This setting allows you to list sites which are automatically granted permission to access all available devices.\r\n\r\nThe URLs must be valid or the policy is ignored. Only the origin (scheme, host and port) of the URL is evaluated.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nThis policy overrides 'DefaultWebHidGuardSetting' (Control use of the WebHID API), 'WebHidAskForUrls' (Allow the WebHID API on these sites), 'WebHidBlockedForUrls' (Block the WebHID API on these sites) and the user's preferences.\r\n\r\nExample value:\r\n\r\nhttps://microsoft.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowalldevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowalldevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowalldevicesforurls_webhidallowalldevicesforurlsdesc","displayName":"Allow listed sites to connect to any HID device (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdevicesforurls","displayName":"Allow listed sites connect to specific HID devices (User)","description":"This setting lets you list the URLs that specify which sites are automatically granted permission to access a HID device with the given vendor and product IDs.\r\n\r\nSetting the policy Each item in the list requires both devices and urls fields for the item to be valid, otherwise the item is ignored.\r\n\r\n * Each item in the devices field must have a vendor_id and may have a product_id field.\r\n\r\n * Omitting the product_id field will create a policy matching any device with the specified vendor ID.\r\n\r\n * An item which has a product_id field without a vendor_id field is invalid and is ignored.\r\n\r\nIf you don't set this policy, that means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nURLs in this policy shouldn't conflict with those configured through 'WebHidBlockedForUrls' (Block the WebHID API on these sites). If they do, this policy takes precedence over 'WebHidBlockedForUrls'.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"product_id\": 5678,\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://microsoft.com\",\r\n \"https://chromium.org\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdevicesforurls_webhidallowdevicesforurls","displayName":"Allow listed sites connect to specific HID devices (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage (User)","description":"This setting allows you to list the URLs that specify which sites are automatically granted permission to access a HID device containing a top-level collection with the given HID usage.\r\n\r\nEach item in the list requires both usages and urls fields for the policy to be valid.\r\n\r\n * Each item in the usages field must have a usage_page and may have a usage field.\r\n\r\n * Omitting the usage field will create a policy matching any device containing a top-level collection with a usage from the specified usage page.\r\n\r\n * An item which has a usage field without a usage_page field is invalid and is ignored.\r\n\r\nIf you don't set this policy, that means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nURLs in this policy shouldn't conflict with those configured through 'WebHidBlockedForUrls' (Block the WebHID API on these sites). If they do, this policy takes precedence over 'WebHidBlockedForUrls'.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"urls\": [\r\n \"https://microsoft.com\",\r\n \"https://chromium.org\"\r\n ],\r\n \"usages\": [\r\n {\r\n \"usage\": 5678,\r\n \"usage_page\": 1234\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_autofillmembershipsenabled","displayName":"Save and fill memberships (User)","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\r\n\r\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\r\n\r\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\r\n\r\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_autofillmembershipsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_autofillmembershipsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended_autofillmembershipsenabled_recommended","displayName":"Save and fill memberships (User)","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\r\n\r\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\r\n\r\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\r\n\r\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended_autofillmembershipsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended_autofillmembershipsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended_searchfiltersenabled_recommended","displayName":"Search Filters Enabled (User)","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions will be shown.\r\n\r\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\r\n\r\nIf you disable this policy, the autosuggestion dropdown won't display the ribbon of available filters.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended_searchfiltersenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended_searchfiltersenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended~printing_recommended_printpreviewstickysettings_recommended","displayName":"Configure the sticky print preview settings (User)","description":"Configuring this policy sets the print preview settings as the most recent choice in Print Preview instead of the default print preview settings.\r\n\r\nEach item of this policy expects a boolean:\r\n\r\nLayout specifies if the webpage layout should be kept sticky or not in print preview settings. If we set this to True the webpage layout uses the recent choice otherwise it will set to default value.\r\n\r\nSize specifies if the page size should be kept sticky or not in print preview settings. If we set this to True the page size uses the recent choice otherwise it will set to default value.\r\n\r\nScale Type specifies if the scaling percentage and scale type should be kept sticky or not in print preview settings. If we set this to True the scale percentage and scale type both uses the recent choice oherwise it will set to default value.\r\n\r\nMargins specifies if the page margin should be kept sticky or not in print preview settings. If we set this to True the page margins uses the recent choice otherwise it will set to default value.\r\n\r\nIf you enable this policy, the selected values will use the most recent choice in Print Preview.\r\n\r\nIf you disable or don't configure this policy, print preview settings will not be impacted.\r\n\r\nExample value:\r\n\r\n{\r\n \"layout\": false,\r\n \"margins\": true,\r\n \"scaleType\": false,\r\n \"size\": true\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"layout\": false, \"margins\": true, \"scaleType\": false, \"size\": true}","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended~printing_recommended_printpreviewstickysettings_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended~printing_recommended_printpreviewstickysettings_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_recommended~printing_recommended_printpreviewstickysettings_recommended_printpreviewstickysettings","displayName":"Configure the sticky print preview settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchfiltersenabled","displayName":"Search Filters Enabled (User)","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions will be shown.\r\n\r\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\r\n\r\nIf you disable this policy, the autosuggestion dropdown won't display the ribbon of available filters.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchfiltersenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchfiltersenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled","displayName":"Search in Sidebar enabled (User)","description":"Search in Sidebar allows users to open search result in sidebar (including sidebar search for Progressive Web Apps).\r\n\r\nIf you configure this policy to 'EnableSearchInSidebar' or don't configure it, Search in sidebar will be enabled.\r\n\r\nIf you configure this policy to 'DisableSearchInSidebarForKidsMode', Search in sidebar will be disabled when in Kids mode. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\r\n\r\nIf you configure this policy to 'DisableSearchInSidebar', Search in sidebar will be disabled. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\r\n\r\nPolicy options mapping:\r\n\r\n* EnableSearchInSidebar (0) = Enable search in sidebar\r\n\r\n* DisableSearchInSidebarForKidsMode (1) = Disable search in sidebar for Kids Mode\r\n\r\n* DisableSearchInSidebar (2) = Disable search in sidebar\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled","displayName":"Search in Sidebar enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled_0","displayName":"Enable search in sidebar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled_1","displayName":"Disable search in sidebar for Kids Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled_2","displayName":"Disable search in sidebar","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsallowedforurls","displayName":"Allow multiple automatic downloads in quick succession on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are allowed to perform multiple successive automatic downloads.\r\nIf you don't configure this policy, 'DefaultAutomaticDownloadsSetting' (Default automatic downloads setting) applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\r\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsallowedforurls_automaticdownloadsallowedforurlsdesc","displayName":"Allow multiple automatic downloads in quick succession on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls","displayName":"Block multiple automatic downloads in quick succession on specific sites (User)","description":"Define a list of sites, based on URL patterns, where multiple successive automatic downloads aren't allowed.\r\nIf you don't configure this policy, 'DefaultAutomaticDownloadsSetting' (Default automatic downloads setting) applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\r\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com\r\n[*.]contoso.com","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls_automaticdownloadsblockedforurlsdesc","displayName":"Block multiple automatic downloads in quick succession on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting","displayName":"Default automatic downloads setting (User)","description":"Administrators can use this policy to control whether websites can perform multiple downloads successively. Individual site behavior can be managed using the AutomaticDownloadsAllowedForUrls and AutomaticDownloadsBlockedForUrls policies.\r\n\r\nDefault behavior:\r\n\r\n- A user gesture is required for each additional download.\r\n\r\n- Users can modify their browser settings to disable successive downloads.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowAutomaticDownloads (1) = Allow all websites to perform multiple downloads without requiring a user gesture between each download.\r\n\r\n* BlockAutomaticDownloads (2) = Prevent all websites from performing multiple downloads, even after a user gesture.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting","displayName":"Default automatic downloads setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting_1","displayName":"Allow all websites to perform automatic downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting_2","displayName":"Don't allow any website to perform automatic downloads","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings","displayName":"Configure navigation settings per groups of URLs in Microsoft Edge Workspaces (User)","description":"This setting lets you to define groups of URLs, and apply specific Microsoft Edge Workspaces navigation settings to each group.\r\n\r\nIf this policy is configured, Microsoft Edge Workspaces will use the configured settings when deciding whether and how to share navigations among collaborators in a Microsoft Edge Workspace.\r\n\r\nIf this policy is not configured, Microsoft Edge Workspaces will use only default and internally configured navigation settings.\r\n\r\nFor more information about configuration options, see https://go.microsoft.com/fwlink/?linkid=2218655\r\n\r\nNote, format url_patterns according to https://go.microsoft.com/fwlink/?linkid=2095322. You can configure the url_regex_patterns in this policy to match multiple URLs using a Perl style regular expression for the pattern. Note that pattern matches are case sensitive. For more information about the regular expression rules that are used, refer to https://go.microsoft.com/fwlink/p/?linkid=2133903.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"navigation_options\": {\r\n \"do_not_send_to\": true,\r\n \"remove_all_query_parameters\": true\r\n },\r\n \"url_patterns\": [\r\n \"https://contoso.com\",\r\n \"https://www.fabrikam.com\",\r\n \".exact.hostname.com\"\r\n ]\r\n },\r\n {\r\n \"navigation_options\": {\r\n \"query_parameters_to_remove\": [\r\n \"username\",\r\n \"login_hint\"\r\n ]\r\n },\r\n \"url_patterns\": [\r\n \"https://adatum.com\"\r\n ]\r\n },\r\n {\r\n \"navigation_options\": {\r\n \"do_not_send_from\": true,\r\n \"prefer_initial_url\": true\r\n },\r\n \"url_regex_patterns\": [\r\n \"\\\\Ahttps://.*?tafe\\\\..*?trs.*?\\\\.fabrikam.com/Sts\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings_workspacesnavigationsettings","displayName":"Configure navigation settings per groups of URLs in Microsoft Edge Workspaces (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereadergrammartoolsenabled","displayName":"Enable Grammar Tools feature within Immersive Reader in Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 125.\r\n\r\nThis policy is obsoleted because Grammar Tools is deprecated from Edge. This policy won't work in Microsoft Edge version 126. Enables the Grammar Tools feature within Immersive Reader in Microsoft Edge.\r\nThis helps improve reading comprehension by splitting words into syllables and highlighting nouns, verbs, adverbs, and adjectives.\r\n\r\nIf you enable this policy or don't configure it, the Grammar Tools option shows up within Immersive Reader.\r\nIf you disable this policy, users can't access the Grammar Tools feature within Immersive Reader.","helpText":"","infoUrls":[],"categoryId":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","categoryName":"Immersive Reader settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereadergrammartoolsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereadergrammartoolsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereaderpicturedictionaryenabled","displayName":"Enable Picture Dictionary feature within Immersive Reader in Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 126.\r\n\r\nThis Policy is obsoleted because Picture Dictionary is deprecated from Edge as of Sept, 2023. This policy won't work in Microsoft Edge Version 127. Enables the Picture Dictionary feature within Immersive Reader in Microsoft Edge.\r\nThis feature helps in reading comprehension by letting a user to click on any single word and see an illustration related to the meaning.\r\n\r\nIf you enable this policy or don't configure it, the Picture Dictionary option shows up within Immersive Reader.\r\nIf you disable this policy, users can't access the Picture Dictionary feature within Immersive Reader.","helpText":"","infoUrls":[],"categoryId":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","categoryName":"Immersive Reader settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereaderpicturedictionaryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereaderpicturedictionaryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~printing_printpreviewstickysettings","displayName":"Configure the sticky print preview settings (User)","description":"Configuring this policy sets the print preview settings as the most recent choice in Print Preview instead of the default print preview settings.\r\n\r\nEach item of this policy expects a boolean:\r\n\r\nLayout specifies if the webpage layout should be kept sticky or not in print preview settings. If we set this to True the webpage layout uses the recent choice otherwise it will set to default value.\r\n\r\nSize specifies if the page size should be kept sticky or not in print preview settings. If we set this to True the page size uses the recent choice otherwise it will set to default value.\r\n\r\nScale Type specifies if the scaling percentage and scale type should be kept sticky or not in print preview settings. If we set this to True the scale percentage and scale type both uses the recent choice oherwise it will set to default value.\r\n\r\nMargins specifies if the page margin should be kept sticky or not in print preview settings. If we set this to True the page margins uses the recent choice otherwise it will set to default value.\r\n\r\nIf you enable this policy, the selected values will use the most recent choice in Print Preview.\r\n\r\nIf you disable or don't configure this policy, print preview settings will not be impacted.\r\n\r\nExample value:\r\n\r\n{\r\n \"layout\": false,\r\n \"margins\": true,\r\n \"scaleType\": false,\r\n \"size\": true\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"layout\": false, \"margins\": true, \"scaleType\": false, \"size\": true}","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~printing_printpreviewstickysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~printing_printpreviewstickysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~printing_printpreviewstickysettings_printpreviewstickysettings","displayName":"Configure the sticky print preview settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_internetexplorermodecleardataonexitenabled","displayName":"Clear history for IE and IE mode every time you exit (User)","description":"This policy controls whether browsing history is deleted from Internet Explorer and Internet Explorer mode every time Microsoft Edge is closed.\r\n\r\nUsers can configure this setting in the 'Clear browsing data for Internet Explorer' option in the Privacy, search, and services menu of Settings.\r\n\r\nIf you enable this policy, on browser exit Internet Explorer browsing history will be cleared.\r\n\r\nIf you disable or do not configure this policy, Internet Explorer browsing history will not be cleared on browser exit.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_internetexplorermodecleardataonexitenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_internetexplorermodecleardataonexitenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_newpdfreaderenabled","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled (User)","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\r\n\r\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_newpdfreaderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_newpdfreaderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_recommended_newpdfreaderenabled_recommended","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled (User)","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\r\n\r\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_recommended_newpdfreaderenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_recommended_newpdfreaderenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed","displayName":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context (User)","description":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context. A SharedArrayBuffer is a binary data buffer that can be used to create views on shared memory. SharedArrayBuffers have a memory access vulnerability in several popular CPUs.\r\n\r\nIf you enable this policy, sites are allowed to use SharedArrayBuffers with no restrictions.\r\n\r\nIf you disable or don't configure this policy, sites are allowed to use SharedArrayBuffers only when cross-origin isolated.\r\n\r\nMicrosoft Edge will require cross-origin isolation when using SharedArrayBuffers from Microsoft Edge 91 onward for Web Compatibility reasons.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_showacrobatsubscriptionbutton","displayName":"Shows button on native PDF viewer in Microsoft Edge that allows users to sign up for Adobe Acrobat subscription (User)","description":"This policy lets the native PDF viewer in Microsoft Edge show a button that lets a user looking for advanced digital document features to discover and subscribe to premium offerings. This is done via the Acrobat extension.\r\n\r\nIf you enable or don't configure this policy, the button will show up on the native PDF viewer in Microsoft Edge. A user will be able to buy Adobe subscription to access their premium offerings.\r\n\r\nIf you disable this policy, the button won't be visible on the native PDF viewer in Microsoft Edge. A user won't be able to discover Adobe's advanced PDF tools or buy their subscriptions.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_showacrobatsubscriptionbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_showacrobatsubscriptionbutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_cryptowalletenabled","displayName":"Enable CryptoWallet feature (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 128.\r\n\r\nThis policy is obsoleted because this feature will no longer be supported, starting in Microsoft Edge 128. There is no replacement for this policy.\r\n Enables CryptoWallet feature in Microsoft Edge.\r\n\r\n If you enable this policy or don't configure it, users can use CryptoWallet feature which allows users to securely store, manage and transact digital assets such as Bitcoin, Ethereum and other cryptocurrencies. Therefore, Microsoft Edge may access Microsoft servers to communicate with the web3 world during the use of the CryptoWallet feature.\r\n\r\n If you disable this policy, users can't use CryptoWallet feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_cryptowalletenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_cryptowalletenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_mousegestureenabled","displayName":"Mouse Gesture Enabled (User)","description":"This policy lets you configure the Mouse Gesture feature in Microsoft Edge.\r\n\r\nThis feature provides an easy way for users to complete tasks like scroll forward or backward, open new tab, refresh page, etc. They can finish a task by pressing and holding the mouse right button to draw certain patterns on a webpage, instead of clicking the buttons or using keyboard shortcuts.\r\n\r\nIf you enable or don't configure this policy, you can use the Mouse Gesture feature on Microsoft Edge to start using this feature.\r\n\r\nIf you disable this policy, you can't use the Mouse Gesture feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_mousegestureenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_mousegestureenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_readaloudenabled","displayName":"Enable Read Aloud feature in Microsoft Edge (User)","description":"Enables the Read Aloud feature within Microsoft Edge.\r\nUsing this feature, users can listen to the content on the web page. This enables users to multi-task or improve their reading comprehension by hearing content at their own pace.\r\n\r\nIf you enable this policy or don't configure it, the Read Aloud option shows up in the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.\r\nIf you disable this policy, users can't access the Read Aloud feature from the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_readaloudenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_readaloudenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_restorepdfview","displayName":"Restore PDF view (User)","description":"Enables PDF View Recovery in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy Microsoft Edge will recover the last state of PDF view and land users to the section where they ended reading in the last session.\r\n\r\nIf you disable this policy Microsoft Edge will recover the last state of PDF view and land users at the start of the PDF file.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_restorepdfview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_restorepdfview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_tabservicesenabled","displayName":"Enable tab organization suggestions (User)","description":"This policy controls whether Microsoft Edge can use its tab organization service to help name or suggest tab groups to increase productivity.\r\n\r\nIf you enable or don't configure this policy, when a user creates a tab group or activates certain \"Group Similar Tabs\" features Microsoft Edge sends tab data to its tab organization service. This data includes URLs, page titles, and existing group information. The service uses this data to return suggestions for better groupings and group names.\r\n\r\nIf you disable this policy, no data will be sent to the tab organization service. Microsoft Edge won't suggest group names when a group is created and certain \"Group Similar Tabs\" features that rely on the service won't be available.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_tabservicesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_tabservicesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_defaultbrowsersettingscampaignenabled","displayName":"Enables default browser settings campaigns (User)","description":"This policy enables the default browser settings campaign. If a user clicks to accept the campaign, their default browser and/or default search engine will be changed to Microsoft Edge and Microsoft Bing, respectively. If the user dismisses the campaign, the user's browser settings will remain unchanged.\r\n\r\nIf you enable or don't configure this policy, users will be prompted to set Microsoft Edge as the default browser and Microsoft Bing as the default search engine, if they do not have those browser settings.\r\n\r\nIf you disable this policy, users will not be prompted to set Microsoft Edge as the default browser, or to set Microsoft Bing as the default search engine.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_defaultbrowsersettingscampaignenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_defaultbrowsersettingscampaignenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_discoverpagecontextenabled","displayName":"Enable Discover access to page contents for AAD profiles (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nThis policy has been obsoleted as of Edge 127. Two new Edge Policies have taken its place. Those policies are CopilotPageContext (Control Copilot access to page contents for AAD profiles), and CopilotCDPPageContext (Control Copilot with Commercial Data Protection access to page contents for AAD profiles).\r\n\r\nThis policy did not allow for separate control of Copilot and Copilot with Commercial Data Protection. The new policies allow separate control of these versions of Copilot. The new policies also allow admins to force-enable Copilot access to Edge page contents by enabling the policy, whereas DiscoverPageContextEnabled only allowed force-disabling of Copilot page access.\r\n\r\nThis policy controls Discover access to page contents for AAD profiles. Discover is an extension that hosts Bing Chat. In order to summarize pages and interact with text selections, it needs to be able to access the page contents. When enabled, page contents will be sent to Bing. This policy does not affect MSA profiles.\r\n\r\nIf you enable or don't configure this policy, Discover will have access to page contents.\r\n\r\nIf you disable this policy, Discover will not be able to access page contents.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_discoverpagecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_discoverpagecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_enforcelocalanchorconstraintsenabled","displayName":"Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nX.509 certificates may encode constraints, such as Name Constraints, in extensions in the certificate. RFC 5280 specifies that enforcing such constraints on trust anchor certificates is optional.\r\n\r\nStarting in Microsoft Edge 112, such constraints in certificates loaded from the platform certificate store will now be enforced.\r\n\r\nThis policy exists as a temporary opt-out in case an enterprise encounters issues with the constraints encoded in their private roots. In that case this policy may be used to temporarily disable enforcement of the constraints while correcting the certificate issues.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will enforce constraints encoded into trust anchors loaded from the platform trust store.\r\n\r\nIf you disable this policy, Microsoft Edge will not enforce constraints encoded into trust anchors loaded from the platform trust store.\r\n\r\nThis policy has no effect if the 'MicrosoftRootStoreEnabled' (Determines whether the Microsoft Root Store and built-in certificate verifier will be used to verify server certificates) policy is disabled.\r\n\r\nThis policy was removed in Microsoft Edge version 128. Starting with that version, constraints in trust anchors are always enforced.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_enforcelocalanchorconstraintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_enforcelocalanchorconstraintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_showdownloadstoolbarbutton","displayName":"Show Downloads button on the toolbar (User)","description":"Set this policy to always show the Downloads button on the toolbar.\r\n\r\nIf you enable this policy, the Downloads button is pinned to the toolbar.\r\n\r\nIf you disable or don't configure the policy, the Downloads button isn't shown on the toolbar by default. Users can toggle the Downloads button in edge://settings/appearance.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_showdownloadstoolbarbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_showdownloadstoolbarbutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_standalonehubssidebarenabled","displayName":"Standalone Sidebar Enabled (User)","description":"Standalone Sidebar is an optional mode for the Sidebar in Microsoft Edge. When this mode is activated by a user, the Sidebar appears in a fixed position on the Microsoft Windows desktop, and is hidden from the browser application frame.\r\n\r\nIf you enable or don't configure this policy, users will have the ability to activate the Standalone Sidebar.\r\nIf you disable this policy, options to activate Standalone Sidebar will be hidden or made unavailable. Note that blocking 'HubsSidebarEnabled' (Show Hubs Sidebar) will also prevent users from accessing Standalone Sidebar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_standalonehubssidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_standalonehubssidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_composeinlineenabled","displayName":"Compose is enabled for writing on the web (User)","description":"This policy lets you configure Compose in Microsoft Edge. Compose provides help for writing with AI-generated text, which lets the user get ideas for writing. This includes elaborating on text, re-writing, changing tone, formatting the text, and more.\r\n\r\nIf you enable or don't configure this policy, Compose can provide text generation for eligible fields, which are text editable and don't have an autocomplete attribute.\r\n\r\nIf you disable this policy, Compose will not be able to provide text generation for eligible fields. Compose will still be available for prompt-based text generation through the sidebar and must be managed with either 'EdgeDiscoverEnabled' (Discover feature In Microsoft Edge) policy or 'HubsSidebarEnabled' (Show Hubs Sidebar) policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_composeinlineenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_composeinlineenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeindicatoruienabled","displayName":"Manage the indicator UI of the Enhanced Security Mode (ESM) feature in Microsoft Edge (User)","description":"This policy lets you manage whether the indicator User Interface (UI) for enhanced security mode is shown or not when ESM is turned on.\r\n\r\nIf you enable or don't configure this policy, the indicator UI is on.\r\n\r\nIf you disable this policy, the indicator UI is off.\r\n\r\nNote: If this policy is used, only the indicator User Interface experience is supressed - ESM is still turned on. For more information, see the 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) policy.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeindicatoruienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeindicatoruienabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeoptoutuxenabled","displayName":"Manage opt-out user experience for Enhanced Security Mode (ESM) in Microsoft Edge (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy lets you manage whether the opt-out user experience for enhanced security mode is presented when ESM is turned on for Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, the UI for the opt-out user experience is on.\r\n\r\nIf you disable this policy, the UI for the opt-out user experience is off.\r\n\r\nNote: If this policy is used, only the User Interface for the opt-out experience is supressed - ESM is still turned on. For more information, see the 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) policy.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.\r\n\r\nAfter careful evaluation, we have determined that this experimental opt-out UX is not required. As a result, this policy will be deprecated and stop working after Edge version 130.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeoptoutuxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeoptoutuxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_recommended_walletdonationenabled_recommended","displayName":"Wallet Donation Enabled (User)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\r\n\r\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\r\n\r\nIf you disable this policy, users can't use the Wallet Donation feature.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_recommended_walletdonationenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_recommended_walletdonationenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_searchforimageenabled","displayName":"Search for image enabled (User)","description":"This policy lets you configure the Image Search feature in the right-click context menu.\r\n\r\nIf you enable or don't configure this policy, then the \"Search the web for image\" option will be visible in the context menu.\r\n\r\nIf you disable this policy, then the \"Search the web for image\" will not be visible in the context menu.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_searchforimageenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_searchforimageenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_walletdonationenabled","displayName":"Wallet Donation Enabled (User)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\r\n\r\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\r\n\r\nIf you disable this policy, users can't use the Wallet Donation feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_walletdonationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_walletdonationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenabled","displayName":"Microsoft Edge management enabled (User)","description":"Microsoft Edge management service in Microsoft 365 Admin Center lets you set policy and manage users through a Microsoft Edge focused cloud-based management experience. This policy lets you control whether Microsoft Edge management is enabled.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will attempt to connect to the Microsoft Edge management service to download and apply policy assigned to the Azure AD account of the user.\r\n\r\nIf you disable this policy, Microsoft Edge will not attempt to connect to the Microsoft Edge management service.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken","displayName":"Microsoft Edge management enrollment token (User)","description":"Microsoft Edge management service in Microsoft 365 Admin Center lets you set policy and manage users through a Microsoft Edge focused cloud-based management experience. This policy lets you specify an enrollment token that's used to register with Microsoft Edge management service and deploy the associated policies. The user must be signed into Microsoft Edge with a valid work or school account otherwise Microsoft Edge will not download the policy.\r\n\r\nIf you enable this policy, Microsoft Edge will attempt to use the specified enrollment token to register with the Microsoft Edge management service and download the published policy.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not attempt to connect to the Microsoft Edge management service.\r\n\r\nExample value: RgAAAACBbzoQDmUrRfq3WeKUoFeEBwBOqK2QPYsBT5V3lQFoKND-AAAAAAEVAAAOqK2QPYvBT5V4lQFoKMD-AAADTXvzAAAA0","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_edgemanagementenrollmenttoken","displayName":"Microsoft Edge management enrollment token (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementextensionsfeedbackenabled","displayName":"Microsoft Edge management extensions feedback enabled (User)","description":"This setting controls whether Microsoft Edge sends data about blocked extensions to the Microsoft Edge management service.\r\n\r\nThe 'EdgeManagementEnabled' policy must also be enabled for this setting to take effect.\r\n\r\nIf you enable this policy, Microsoft Edge will send data to the Microsoft Edge service when a user tries to install a blocked extension.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge won't send any data to the Microsoft Edge service about blocked extensions.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementextensionsfeedbackenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementextensionsfeedbackenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_recommended~performance_recommended_pinbrowseressentialstoolbarbutton_recommended","displayName":"Pin browser essentials toolbar button (User)","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\r\n\r\nWhen the button is pinned, it will always appear on the toolbar.\r\n\r\nWhen the button isn't pinned, it will only appear when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\r\n\r\nIf you enable or don't configure this policy, the Browser essentials button will be pinned on the toolbar.\r\n\r\nIf you disable this policy, the Browser essentials button won't be pinned on the toolbar.\r\n\r\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_recommended~performance_recommended_pinbrowseressentialstoolbarbutton_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_recommended~performance_recommended_pinbrowseressentialstoolbarbutton_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_throttlenonvisiblecrossoriginiframesallowed","displayName":"Allows enabling throttling of non-visible, cross-origin iframes (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 123.\r\n\r\nThrottling of cross-origin frames that are display:none and non-visible is a feature designed to make cross-process and same-process cross-origin iframes consistent in their rendering behavior. For more details on cross-process vs. same-process throttling, refer to https://go.microsoft.com/fwlink/?linkid=2239564.\r\n\r\nThis enterprise policy exists to allow administrators to control whether their users are able to turn the additional throttling on or not.\r\n\r\nIf you enable or don't configure this policy, users can opt-in to throttling.\r\n\r\nIf you disable this policy, users can't enable throttling.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_throttlenonvisiblecrossoriginiframesallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_throttlenonvisiblecrossoriginiframesallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting","displayName":"Default setting for third-party storage partitioning (User)","description":"This policy controls whether third-party storage partitioning is allowed by default.\r\n\r\nIf this policy is set to 1 - AllowPartitioning, or unset, third-party storage partitioning will be allowed by default. This default may be overridden for specific top-level origins by other means.\r\n\r\nIf this policy is set to 2 - BlockPartitioning, third-party storage partitioning will be disabled for all contexts.\r\n\r\nUse ThirdPartyStoragePartitioningBlockedForOrigins to disable third-party storage partitioning for specific top-level origins.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowPartitioning (1) = Allow third-party storage partitioning by default.\r\n\r\n* BlockPartitioning (2) = Disable third-party storage partitioning.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting","displayName":"Default setting for third-party storage partitioning (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting_1","displayName":"Let third-party storage partitioning to be enabled.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting_2","displayName":"Block third-party storage partitioning from being enabled.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_thirdpartystoragepartitioningblockedfororigins","displayName":"Disable third-party storage partitioning for specific top-level origins (User)","description":"This policy lets you set a list of URL patterns that specify top-level origins for which third-party storage partitioning (partitioning of cross-origin iframe storage) should be disabled.\r\n\r\nIf this policy isn't set or a top-level origin doesn't match one of the URL patterns, then the value from 'DefaultThirdPartyStoragePartitioningSetting' (Default setting for third-party storage partitioning) will be used.\r\n\r\nNote that the patterns you list are treated as origins, not URLs, so you shouldn't specify a path. For detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nwww.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_thirdpartystoragepartitioningblockedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_thirdpartystoragepartitioningblockedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_thirdpartystoragepartitioningblockedfororigins_thirdpartystoragepartitioningblockedfororiginsdesc","displayName":"Block third-party storage partitioning for these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton","displayName":"Pin browser essentials toolbar button (User)","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\r\n\r\nWhen the button is pinned, it will always appear on the toolbar.\r\n\r\nWhen the button isn't pinned, it will only appear when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\r\n\r\nIf you enable or don't configure this policy, the Browser essentials button will be pinned on the toolbar.\r\n\r\nIf you disable this policy, the Browser essentials button won't be pinned on the toolbar.\r\n\r\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_allowsystemnotifications","displayName":"Allows system notifications (User)","description":"Lets you use system notifications instead of Microsoft Edge's embedded Message Center on Windows and Linux.\r\n\r\nIf set to True or not set, Microsoft Edge is allowed to use system notifications.\r\n\r\nIf set to False, Microsoft Edge will not use system notifications. Microsoft Edge's embedded Message Center will be used as a fallback.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_allowsystemnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_allowsystemnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_edgewalletetreeenabled","displayName":"Edge Wallet E-Tree Enabled (User)","description":"The Edge Wallet E-Tree feature in Microsoft Edge allows users to plant a E-Tree for their own.\r\n\r\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\r\n\r\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_edgewalletetreeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_edgewalletetreeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_internetexplorerintegrationzoneidentifiermhtfileallowed","displayName":"Automatically open downloaded MHT or MHTML files from the web in Internet Explorer mode (User)","description":"This policy controls whether MHT or MHTML files that are downloaded from the web are automatically opened in Internet Explorer mode.\r\n\r\nIf you enable this policy, the MHT or MHTML files that are downloaded from the web can be opened in both Microsoft Edge and Internet Explorer mode to provide the best user experience.\r\n\r\nIf you disable or don't configure this policy, MHT or MHTML files that are downloaded from the web won't automatically open in Internet Explorer mode.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_internetexplorerintegrationzoneidentifiermhtfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_internetexplorerintegrationzoneidentifiermhtfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended_edgewalletetreeenabled_recommended","displayName":"Edge Wallet E-Tree Enabled (User)","description":"The Edge Wallet E-Tree feature in Microsoft Edge allows users to plant a E-Tree for their own.\r\n\r\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\r\n\r\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended_edgewalletetreeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended_edgewalletetreeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended~edgegames_recommended_gamermodeenabled_recommended","displayName":"Enable Gamer Mode (User)","description":"Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more.\r\n\r\nIf you enable or don't configure this policy, users can opt into Gamer Mode.\r\nIf you disable this policy, Gamer Mode will be disabled.","helpText":"","infoUrls":[],"categoryId":"48965ad9-3011-4722-855b-7179fef89954","categoryName":"Games settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended~edgegames_recommended_gamermodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended~edgegames_recommended_gamermodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_searchbarallowed","displayName":"Enable the Search bar (User)","description":"Enables the search bar. When enabled, users can use the search bar to search the web from their desktop or from an application. The search bar provides a search box, powered by Edge default search engine, that shows web suggestions and opens all web searches in Microsoft Edge. The search bar can be launched from the \"More tools\" menu or jump list in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy:\r\nThe search bar will be automatically enabled for all profiles.\r\nThe option to enable the search bar at startup will be toggled on if the 'SearchbarIsEnabledOnStartup' (Allow the Search bar at Windows startup) policy is enabled.\r\nIf the 'SearchbarIsEnabledOnStartup' is disabled or not configured, the option to enable the search bar at startup will be toggled off.\r\nUsers will see the menu item to launch the search bar from the Microsoft Edge \"More tools\" menu. Users can launch the search bar from \"More tools\".\r\nUsers will see the menu item to launch the search bar from the Microsoft Edge jump list menu. Users can launch the search bar from the Microsoft Edge jump list menu.\r\nThe search bar can be turned off by the \"Quit\" option in the System tray or by closing the search bar from the 3 dot menu. The search bar will be restarted on system reboot if auto-start is enabled.\r\n\r\n\r\nIf you disable this policy:\r\nThe search bar will be disabled for all profiles.\r\nThe option to launch the search bar from Microsoft Edge \"More tools\" menu will be disabled.\r\nThe option to launch the search bar from Microsoft Edge jump list menu will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_searchbarallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_searchbarallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_searchbarisenabledonstartup","displayName":"Allow the Search bar at Windows startup (User)","description":"Allows the Search bar to start running at Windows startup.\r\n\r\nIf you enable:\r\n The Search bar will start running at Windows startup by default.\r\n If the Search bar is disabled via 'SearchbarAllowed' (Enable the Search bar) policy, this policy will not start the Search bar on Windows startup.\r\n\r\nIf you disable this policy:\r\n The Search bar will not start at Windows startup for all profiles.\r\n The option to start the search bar at Windows startup will be disabled and toggled off in search bar settings.\r\n\r\nIf you don't configure the policy:\r\n The Search bar will not start at Windows startup for all profiles.\r\n The option to start the search bar at Windows startup will be toggled off in search bar settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_searchbarisenabledonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_searchbarisenabledonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_showhistorythumbnails","displayName":"Show thumbnail images for browsing history (User)","description":"This policy lets you configure whether the history thumbnail feature collects and saves images for the sites you visit. When enabled, this feature makes it easier to identify sites when you hover over your history results.\r\nIf you don't configure this policy, the thumbnail feature is turned on after a user visits the history hub twice in the past 7 days.\r\nIf you enable this policy, the history thumbnail collects and saves images for visited sites.\r\nIf you disable this policy, the history thumbnail doesn't collect and save images for visited sites.\r\nWhen the feature is disabled, existing images are deleted on a per user basis, and the feature no longer collects or saves images when a site is visited.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_showhistorythumbnails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_showhistorythumbnails_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_splitscreenenabled","displayName":"Enable split screen feature in Microsoft Edge (User)","description":"This policy lets you configure the split screen feature in Microsoft Edge. This feature lets a user open two web pages in one tab.\r\n\r\nIf you enable or don't configure this policy, users can use the split screen feature in Microsoft Edge.\r\n\r\nIf you disable this policy, users can't use the split screen feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_splitscreenenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_splitscreenenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_uploadfromphoneenabled","displayName":"Enable upload files from mobile in Microsoft Edge desktop (User)","description":"This policy lets you configure the \"Upload from mobile\" feature in Microsoft Edge.\r\n\r\nUpload from mobile lets users select file from mobile devices to desktop when user upload file in a webpage in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, you can use the Upload from mobile feature in Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Upload from mobile feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_uploadfromphoneenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_uploadfromphoneenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge~edgegames_gamermodeenabled","displayName":"Enable Gamer Mode (User)","description":"Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more.\r\n\r\nIf you enable or don't configure this policy, users can opt into Gamer Mode.\r\nIf you disable this policy, Gamer Mode will be disabled.","helpText":"","infoUrls":[],"categoryId":"81c518f1-522e-4957-b850-e8a66d2ab215","categoryName":"Games settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge~edgegames_gamermodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge~edgegames_gamermodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_beforeunloadeventcancelbypreventdefaultenabled","displayName":"Control the behavior for the cancel dialog produced by the beforeunload event (User)","description":"This policy provides a temporary opt-out for two related fixes to the behavior of the confirmation dialog that’s shown by the beforeunload event.\r\n\r\nWhen this policy is Enabled, the new (correct) behavior will be used.\r\nWhen this policy is Disabled, the old (legacy) behavior will be used.\r\nWhen this policy is left not set, the default behavior will be used.\r\nNote: This policy is a temporary workaround and will be removed in a future release.\r\n\r\nNew and correct behavior: In `beforeunload`, calling `event.preventDefault()` will trigger the confirmation dialog. Setting `event.returnValue` to the empty string won’t trigger the confirmation dialog.\r\n\r\nOld and legacy behavior: In `beforeunload`, calling `event.preventDefault()` won’t trigger the confirmation dialog. Setting `event.returnValue` to the empty string will trigger the confirmation dialog.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_beforeunloadeventcancelbypreventdefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_beforeunloadeventcancelbypreventdefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcebuiltinpushmessagingclient","displayName":"Forces Microsoft Edge to use its built-in WNS push client to connect to the Windows Push Notification Service. (User)","description":"In some environments, the Windows OS client can't connect to the Windows Push Notification Service (WNS). For these environments, you can use the Microsoft Edge built-in WNS push client, which may be able to connect successfully.\r\n\r\nIf enabled, Microsoft Edge will use its built-in WNS push client to connect to WNS.\r\n\r\nIf disabled or not configured, Microsoft Edge will use the Windows OS client to connect to the Windows Push Notification Service. This is the default setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcebuiltinpushmessagingclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcebuiltinpushmessagingclient_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled. (User)","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy.\r\nCurrently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers.\r\nThis enterprise policy can be used to opt out of this gradual deprecation by forcing the default to stay enabled.\r\n\r\nPages might depend on unload event handlers to save data or signal the end of a user session to the server.\r\nThis is not recommended because it's unreliable and impacts performance by blocking use of BackForwardCache.\r\nRecommended alternatives exist, but the unload event has been used for a long time. Some applications might still rely on them.\r\n\r\nIf you disable this policy or don't configure it, unload event handlers will gradually be deprecated in-line with the deprecation rollout and sites which don't set Permissions-Policy header will stop firing `unload` events.\r\n\r\nIf you enable this policy then unload event handlers will continue to work by default.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcepermissionpolicyunloaddefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcepermissionpolicyunloaddefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge (User)","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\r\n\r\nThe Picture in Picture floating overlay button lets user to watch videos in a floating window on top of other windows.\r\n\r\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_recommended~passwordmanager_recommended_passworddeleteonbrowsercloseenabled_recommended","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes (User)","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when:\r\n- The 'Passwords' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\r\n- The policy ClearBrowsingDataOnExit is enabled\r\n\r\nIf you enable this policy, passwords won't be cleared when the browser closes.\r\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":"","infoUrls":[],"categoryId":"a877a2ff-f144-421f-814c-593e972a8a20","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_recommended~passwordmanager_recommended_passworddeleteonbrowsercloseenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_recommended~passwordmanager_recommended_passworddeleteonbrowsercloseenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_sendmouseeventsdisabledformcontrolsenabled","displayName":"Control the new behavior for event dispatching on disabled form controls (User)","description":"Event dispatching on disabled form controls is being changed in Edge to improve compatibility with other browsers and to improve the developer experience.\r\n\r\nWith this change, MouseEvents get dispatched on disabled form control elements. Exceptions for this behavior are click, mouseup, and mousedown. Some examples of the new events are mousemove, mouseenter, and mouseleave.\r\n\r\nThis change also truncates the event path of click, mouseup, and mousedown when they’re dispatched on children of disabled form controls. These events aren’t dispatched on the disabled form control or any of its ancestors.\r\n\r\nNote: This new behavior might break some websites.\r\n\r\nIf this policy is enabled or left not set, the new behavior will be used.\r\n\r\nIf this policy is disabled, the old behavior will be used.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_sendmouseeventsdisabledformcontrolsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_sendmouseeventsdisabledformcontrolsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~contentsettings_dataurlinsvguseenabled","displayName":"Data URL support for SVGUseElement (User)","description":"This policy enables Data URL support for SVGUseElement, which will be disabled\r\nby default starting in Edge stable version 119.\r\nIf this policy is Enabled, Data URLs will keep working in SVGUseElement.\r\nIf this policy is Disabled or left not set, Data URLs won't work in SVGUseElement.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~contentsettings_dataurlinsvguseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~contentsettings_dataurlinsvguseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~network_compressiondictionarytransportenabled","displayName":"Enable compression dictionary transport support (User)","description":"This feature enables the use of dictionary-specific content encodings in the Accept-Encoding request header (\"sbr\" and \"zst-d\") when dictionaries are available for use.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will accept web contents using the compression dictionary transport feature.\r\n\r\nIf you disable this policy, Microsoft Edge will turn off the compression dictionary transport feature.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~network_compressiondictionarytransportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~network_compressiondictionarytransportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes (User)","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when:\r\n- The 'Passwords' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\r\n- The policy ClearBrowsingDataOnExit is enabled\r\n\r\nIf you enable this policy, passwords won't be cleared when the browser closes.\r\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~smartscreen_exemptsmartscreendownloadwarnings","displayName":"Disable SmartScreen AppRep based warnings for specified file types on specified domains (User)","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from SmartScreen AppRep warnings. For example, if the \"vbe\" extension is associated with \"website1.com\", users would not see a SmartScreen AppRep warning when downloading \"vbe\" files from \"website1.com\", but may see a download warning when downloading \"vbe\" files from \"website2.com\".\r\n\r\nFiles with file type extensions specified for domains identified by this policy will still be subject to file type extension-based security warnings and mixed-content download warnings.\r\n\r\nIf you disable this policy or don't configure it, files that trigger SmartScreen AppRep download warnings will show warnings to the user.\r\n\r\nIf you enable this policy:\r\n\r\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so \"vbe\" should be used instead of \".vbe\".\r\n\r\nExample:\r\n\r\nThe following example value would prevent SmartScreen AppRep warnings on msi, exe, and vbe extensions for *.contoso.com domains. It may show the user a SmartScreen AppRep warning on any other domain for exe and msi files, but not for vbe files.\r\n\r\n[\r\n { \"file_extension\": \"msi\", \"domains\": [\"contoso.com\"] },\r\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\r\n { \"file_extension\": \"vbe\", \"domains\": [\"*\"] }\r\n]\r\n\r\nNote that while the preceding example shows the suppression of SmartScreen AppRep download warnings for \"vbe\" files for all domains, applying suppression of such warnings for all domains is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"domains\": [\r\n \"https://contoso.com\",\r\n \"contoso2.com\"\r\n ],\r\n \"file_extension\": \"msi\"\r\n },\r\n {\r\n \"domains\": [\r\n \"*\"\r\n ],\r\n \"file_extension\": \"vbe\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~smartscreen_exemptsmartscreendownloadwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~smartscreen_exemptsmartscreendownloadwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~smartscreen_exemptsmartscreendownloadwarnings_exemptsmartscreendownloadwarnings","displayName":"Disable SmartScreen AppRep based warnings for specified file types on specified domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagebingchatenabled","displayName":"Disable Bing chat entry-points on Microsoft Edge Enterprise new tab page (User)","description":"By default, there are two Bing chat entry-points on new tab page. One is inside the new tab page search box, and one is in the Bing Autosuggest drawer on-click.\r\n\r\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge Enterprise new tab page and the Bing chat entry-points are there for users.\r\n\r\nIf you disable this policy, Bing chat entry-points don't appear on the new tab page.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagebingchatenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagebingchatenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagecompanylogoenabled","displayName":"Hide the company logo on the Microsoft Edge new tab page (User)","description":"By default, the company logo is shown on the new tab page if the company logo is configured in Admin Portal.\r\n\r\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge new tab page and the company logo is there for users.\r\n\r\nIf you disable this policy, the company logo doesn't appear on Microsoft Edge new tab page.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagecompanylogoenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagecompanylogoenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge_recommended_organizationalbrandingonworkprofileuienabled_recommended","displayName":"Allow the use of your organization's branding assets from Microsoft Entra on the profile-related UI of a work profile (User)","description":"Allow the use of your organization's branding assets from Entra, if any, on the profile-related UI of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect.\r\n\r\nIf you enable this policy, your organization's branding assets from Entra will be used.\r\n\r\nIf you disable or don't configure this policy, your organization's branding assets from Entra won't be used.\r\n\r\nFor more information about configuring your organization's branding assets on Entra, please visit https://go.microsoft.com/fwlink/?linkid=2254514.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge_recommended_organizationalbrandingonworkprofileuienabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge_recommended_organizationalbrandingonworkprofileuienabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile","displayName":"Switch intranet sites to a work profile (User)","description":"Allows Microsoft Edge to switch to the appropriate profile when Microsoft Edge detects that a URL is the intranet.\r\n\r\nIf you enable or don't configure this policy, navigations to intranet URLs will switch to the most recently used work profile if one exists.\r\n\r\nIf you disable this policy, navigations to intranet URLs will remain in the current browser profile.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchsitesoniemodesitelisttoworkprofile","displayName":"Switch sites on the IE mode site list to a work profile (User)","description":"Allows Microsoft Edge to switch to the appropriate profile when navigating to a site that matches an entry on the IE mode site list. Only sites that specify IE mode or Edge mode will be switched to the work profile.\r\n\r\nIf you enable or don't configure this policy, navigations to URLs matching a site on the IE mode site list will switch to the most recently used work profile if one exists.\r\n\r\nIf you disable this policy, navigations to URLs matching a site on the IE mode site list will remain in the current browser profile.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchsitesoniemodesitelisttoworkprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchsitesoniemodesitelisttoworkprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementpolicyoverridesplatformpolicy","displayName":"Microsoft Edge management service policy overrides platform policy. (User)","description":"If you enable this policy, the cloud-based Microsoft Edge management service policy takes precedence if it conflicts with platform policy.\r\n\r\nIf you disable or don't configure this policy, platform policy takes precedence if it conflicts with the cloud-based Microsoft Edge management service policy.\r\n\r\nThis mandatory policy affects machine scope cloud-based Microsoft Edge management policies.\r\n\r\nMachine policies apply to all edge browser instances regardless of the user who is logged in.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementpolicyoverridesplatformpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementpolicyoverridesplatformpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementuserpolicyoverridescloudmachinepolicy","displayName":"Allow cloud-based Microsoft Edge management service user policies to override local user policies. (User)","description":"If you enable this policy, cloud-based Microsoft Edge management service user policies takes precedence if it conflicts with local user policy.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge management service user policies will take precedence.\r\n\r\nThe policy can be combined with 'EdgeManagementPolicyOverridesPlatformPolicy' (Microsoft Edge management service policy overrides platform policy.). If both policies are enabled, all cloud-based Microsoft Edge management service policies will take precedence over conflicting local service policies.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementuserpolicyoverridescloudmachinepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementuserpolicyoverridescloudmachinepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_edge3pserptelemetryenabled","displayName":"Edge 3P SERP Telemetry Enabled (User)","description":"Edge3P Telemetry in Microsoft Edge captures the searches user does on third party search providers without identifying the person or the device and captures only if the user has consented to this collection of data. User can turn off the collection at any time in the browser settings.\r\n\r\nIf you enable or don't configure this policy, Edge 3P SERP Telemetry feature will be enabled.\r\n\r\nIf you disable this policy, Edge 3P SERP Telemetry feature will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_edge3pserptelemetryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_edge3pserptelemetryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_edge3pserptelemetryenabled_recommended","displayName":"Edge 3P SERP Telemetry Enabled (User)","description":"Edge3P Telemetry in Microsoft Edge captures the searches user does on third party search providers without identifying the person or the device and captures only if the user has consented to this collection of data. User can turn off the collection at any time in the browser settings.\r\n\r\nIf you enable or don't configure this policy, Edge 3P SERP Telemetry feature will be enabled.\r\n\r\nIf you disable this policy, Edge 3P SERP Telemetry feature will be disabled.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_edge3pserptelemetryenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_edge3pserptelemetryenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_organizationlogooverlayonappiconenabled_recommended","displayName":"Allow your organization's logo from Microsoft Entra to be overlaid on the Microsoft Edge app icon of a work profile (User)","description":"Allow your organization's logo from Entra, if any, to be overlaid on the Microsoft Edge app icon of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect.\r\n\r\nIf you enable this policy, your organization's logo from Entra will be used.\r\n\r\nIf you disable or don't configure this policy, your organization's logo from Entra won't be used.\r\n\r\nFor more information about configuring your organization's logo on Entra, please visit https://go.microsoft.com/fwlink/?linkid=2254514.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_organizationlogooverlayonappiconenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_organizationlogooverlayonappiconenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~identity_recommended_automaticprofileswitchingsitelist_recommended","displayName":"Configure the automatic profile switching site list (User)","description":"Set this policy to control which profiles Microsoft Edge will use to open sites in. Switching configurations for sites listed in this policy take precedence over other heuristics Microsoft Edge uses for switching sites but note that sites not listed on this policy are still subject to switching by those heuristics. If this policy is not configured, Microsoft Edge will continue using its heuristics to automatically switch sites.\r\n\r\nThis policy maps a URL hostname to a profile that it should be opened in.\r\n\r\nThe 'site' field should take the form of a URL hostname.\r\n\r\nThe 'profile' field can take one of the following values:\r\n- 'Work': The most recently used Microsoft Entra signed-in profile will be used to open 'site'.\r\n- 'Personal': The most recently used MSA signed-in profile will be used to open 'site'.\r\n- 'No preference': The currently used profile will be used to open 'site'.\r\n- Wildcard email address: This takes the form of '*@contoso.com'. A profile whose username ends with the contents following the '*' will be used to open 'site'.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"site\": \"work.com\",\r\n \"profile\": \"Work\"\r\n },\r\n {\r\n \"site\": \"personal.com\",\r\n \"profile\": \"Personal\"\r\n },\r\n {\r\n \"site\": \"nopreference.com\",\r\n \"profile\": \"No preference\"\r\n },\r\n {\r\n \"site\": \"contoso.com\",\r\n \"profile\": \"*@contoso.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"04b46099-4ee5-4def-8e04-569c988057a9","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~identity_recommended_automaticprofileswitchingsitelist_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~identity_recommended_automaticprofileswitchingsitelist_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~identity_recommended_automaticprofileswitchingsitelist_recommended_automaticprofileswitchingsitelist","displayName":"Configure the automatic profile switching site list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"04b46099-4ee5-4def-8e04-569c988057a9","categoryName":"Identity and sign-in","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~sleepingtabs_recommended_autodiscardsleepingtabsenabled_recommended","displayName":"Configure auto discard sleeping tabs (User)","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab will need to be reloaded.\r\n\r\nIf the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature will be enabled by default.\r\n\r\nIf the 'SleepingTabsEnabled' is disabled, then this feature will be disabled by default and cannot be enabled.\r\n\r\nIf enabled, idle background tabs will be discarded after 1.5 days.\r\n\r\nIf disabled, idle background tab will not be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~sleepingtabs_recommended_autodiscardsleepingtabsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~sleepingtabs_recommended_autodiscardsleepingtabsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_webappsettings","displayName":"Web App management settings (User)","description":"This policy allows an admin to specify settings for installed web apps. This policy maps a Web App ID to its specific setting. A default configuration can be set using the special ID *, which applies to all web apps without a custom configuration in this policy.\r\n\r\n- The manifest_id field is the Manifest ID for the Web App.\r\nSee https://developer.chrome.com/blog/pwa-manifest-id/\r\nfor instructions on how to determine the Manifest ID for an installed web app.\r\n- The run_on_os_login field specifies if a web app can be run during OS login.\r\nIf this field is set to blocked, the web app will not run during OS login and the user will not be able to enable this later.\r\nIf this field is set to run_windowed, the web app will run during OS login and the user won't be able to disable this later.\r\nIf this field is set to allowed, the user will be able to configure the web app to run at OS login.\r\nThe default policy configuration only allows the allowed and blocked values.\r\n- (Starting with Microsoft Edge version 120) The prevent_close_after_run_on_os_login field specifies if a web app can be prevented from closing in any way.\r\nFor example, by the user, by task manager, or by web APIs. This behavior can only be enabled if run_on_os_login is set to run_windowed.\r\nIf the app is already running, this setting will only take effect after the app is restarted.\r\nIf this field isn't defined, users can close the app.\r\n(This is currently not supported in Microsoft Edge.)\r\n- (Since version 118) The force_unregister_os_integration field specifies if all OS integration for a web app, that is, shortcuts, file handlers, protocol handlers and so on will be removed or not.\r\nIf an app is already running, this property will come into effect after the app restarts.\r\nThis should be used with caution, since it can override any OS integration that is set automatically during the startup of the web applications system. This currently only works on Windows, Mac and Linux platforms.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"manifest_id\": \"https://foo.example/index.html\",\r\n \"run_on_os_login\": \"allowed\"\r\n },\r\n {\r\n \"manifest_id\": \"https://bar.example/index.html\",\r\n \"run_on_os_login\": \"allowed\"\r\n },\r\n {\r\n \"manifest_id\": \"https://foobar.example/index.html\",\r\n \"run_on_os_login\": \"run_windowed\",\r\n \"prevent_close_after_run_on_os_login\": true\r\n },\r\n {\r\n \"manifest_id\": \"*\",\r\n \"run_on_os_login\": \"blocked\"\r\n },\r\n {\r\n \"manifest_id\": \"https://foo.example/index.html\",\r\n \"force_unregister_os_integration\": true\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_webappsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_webappsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_webappsettings_webappsettings","displayName":"Web App management settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist","displayName":"Configure the automatic profile switching site list (User)","description":"Set this policy to control which profiles Microsoft Edge will use to open sites in. Switching configurations for sites listed in this policy take precedence over other heuristics Microsoft Edge uses for switching sites but note that sites not listed on this policy are still subject to switching by those heuristics. If this policy is not configured, Microsoft Edge will continue using its heuristics to automatically switch sites.\r\n\r\nThis policy maps a URL hostname to a profile that it should be opened in.\r\n\r\nThe 'site' field should take the form of a URL hostname.\r\n\r\nThe 'profile' field can take one of the following values:\r\n- 'Work': The most recently used Microsoft Entra signed-in profile will be used to open 'site'.\r\n- 'Personal': The most recently used MSA signed-in profile will be used to open 'site'.\r\n- 'No preference': The currently used profile will be used to open 'site'.\r\n- Wildcard email address: This takes the form of '*@contoso.com'. A profile whose username ends with the contents following the '*' will be used to open 'site'.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"site\": \"work.com\",\r\n \"profile\": \"Work\"\r\n },\r\n {\r\n \"site\": \"personal.com\",\r\n \"profile\": \"Personal\"\r\n },\r\n {\r\n \"site\": \"nopreference.com\",\r\n \"profile\": \"No preference\"\r\n },\r\n {\r\n \"site\": \"contoso.com\",\r\n \"profile\": \"*@contoso.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist_automaticprofileswitchingsitelist","displayName":"Configure the automatic profile switching site list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled","displayName":"Configure auto discard sleeping tabs (User)","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab will need to be reloaded.\r\n\r\nIf the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature will be enabled by default.\r\n\r\nIf the 'SleepingTabsEnabled' is disabled, then this feature will be disabled by default and cannot be enabled.\r\n\r\nIf enabled, idle background tabs will be discarded after 1.5 days.\r\n\r\nIf disabled, idle background tab will not be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly","displayName":"Force Windows executable Native Messaging hosts to launch directly (User)","description":"This policy controls whether native host executables launch directly on Windows.\r\n\r\nIf you enable this policy, Microsoft Edge is forced to launch native messaging hosts implemented as executables directly.\r\n\r\nIf you disable this policy, Microsoft Edge will launch hosts using cmd.exe as an intermediary process.\r\n\r\nIf you don't configure this policy, Microsoft Edge will decide which approach to use based on a progressive rollout from the legacy behavior to the Launch Directly behavior, guided by ecosystem compatibility.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_postquantumkeyagreementenabled","displayName":"Enable post-quantum key agreement for TLS (User)","description":"This policy configures whether Microsoft Edge will offer a post-quantum key agreement algorithm in TLS. This lets supporting servers protect user traffic from being decrypted by quantum computers.\r\n\r\nIf you enable this policy, Microsoft Edge will offer a post-quantum key agreement in TLS connections. TLS connections will be protected from quantum computers when communicating with compatible servers.\r\n\r\nIf you disable this policy, Microsoft Edge will not offer a post-quantum key agreement in TLS connections. User traffic will be unprotected from decryption by quantum computers.\r\n\r\nIf you don't configure this policy, Microsoft Edge will follow the default rollout process for offering a post-quantum key agreement.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing TLS servers and networking middleware are expected to ignore the new option and continue selecting previous options.\r\n\r\nHowever, devices that don't implement TLS correctly may malfunction when offered the new option. For example, they might disconnect in response to unrecognized options or the resulting larger messages. These devices are not post-quantum-ready and will interfere with an enterprise's post-quantum transition. If this issue is encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Microsoft Edge. You can enable it to test for issues and you can disable it while you resolve issues.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_postquantumkeyagreementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_postquantumkeyagreementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~googlecast_edgedisabledialprotocolforcastdiscovery","displayName":"Disable DIAL protocol for cast device discovery (User)","description":"Enable this policy to disable the DIAL (Discovery And Launch) protocol for cast device discovery. (If EnableMediaRouter is disabled, this policy will have no effect).\r\n\r\nEnable this policy to disable DIAL protocol.\r\n\r\nBy default, Cast device discovery will use DIAL protocol.","helpText":"","infoUrls":[],"categoryId":"fddc444c-3591-4a50-865b-d8993b798e12","categoryName":"Cast","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~googlecast_edgedisabledialprotocolforcastdiscovery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~googlecast_edgedisabledialprotocolforcastdiscovery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsenabled","displayName":"Enable Related Website Sets (User)","description":"This policy lets you control the enablement of the Related Website Sets feature. Related Website Sets (RWS) is a way for an organisation to declare relationships among sites, so that Microsoft Edge allows limited third-party cookie access for specific purposes across those sites.\r\n\r\nIf this policy set to True or unset, the Related Website Sets feature is enabled.\r\n\r\nIf this policy is set to False, the Related Website Sets feature is disabled.","helpText":"","infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (User)","description":"This policy provides a way to override the list of sets Microsoft Edge uses for Related Website Sets\r\n\r\nEach set in the browser's list of Related Website Sets must meet the requirements of a Related Website Set. A Related Website Set must contain a primary site and one or more member sites.\r\nA set can also contain a list of service sites that it owns, as well as a map from a site to all its ccTLD variants. See https://github.com/WICG/first-party-sets for more information on how Microsoft Edge uses Related Website Sets.\r\n\r\n\r\nAll sites in a Related Website Set must be a registrable domain served over HTTPS. Each site in a Related Website Set must also be unique, which means a site can't be listed more than once in a Related Website Set.\r\n\r\nWhen this policy is given an empty dictionary, Microsoft Edge uses the public list of Related Website Sets.\r\n\r\nFor all sites in a Related Website Set from the replacements list, if a site is also present on a Related Website Set in the browser's list, then that site will be removed from the browser's Related Website Set. After this, the policy's Related Website Set will be added to the Microsoft Edge's list of Related Website Sets.\r\n\r\nFor all sites in a Related Website Set from the additions list, if a site is also present on a Related Website Set in Microsoft Edge's list, then the browser's Related Website Set will be updated so that the new Related Website Set can be added to the browser's list. After the browser's list has been updated, the policy's Related Website Set will be added to the browser's list of Related Website Sets.\r\n\r\nThe browser's list of Related Website Sets requires that for all sites in its list, no site is in\r\nmore than one set. This is also required for both the replacements list\r\nand the additions list. Similarly, a site can't be in both the\r\nreplacements list and the additions list.\r\n\r\nWildcards (*) aren't supported as a policy value, or as a value within any Related Website Set in these lists.\r\n\r\nExample value:\r\n\r\n{\r\n \"additions\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate2.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate2.test\": [\r\n \"https://associate2.com\"\r\n ]\r\n },\r\n \"primary\": \"https://primary2.test\",\r\n \"serviceSites\": [\r\n \"https://associate2-content.test\"\r\n ]\r\n }\r\n ],\r\n \"replacements\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate1.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate1.test\": [\r\n \"https://associate1.co.uk\"\r\n ]\r\n },\r\n \"primary\": \"https://primary1.test\",\r\n \"serviceSites\": [\r\n \"https://associate1-content.test\"\r\n ]\r\n }\r\n ]\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"additions\": [{\"associatedSites\": [\"https://associate2.test\"], \"ccTLDs\": {\"https://associate2.test\": [\"https://associate2.com\"]}, \"primary\": \"https://primary2.test\", \"serviceSites\": [\"https://associate2-content.test\"]}], \"replacements\": [{\"associatedSites\": [\"https://associate1.test\"], \"ccTLDs\": {\"https://associate1.test\": [\"https://associate1.co.uk\"]}, \"primary\": \"https://primary1.test\", \"serviceSites\": [\"https://associate1-content.test\"]}]}","helpText":"","infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_preventtyposquattingpromptoverride","displayName":"Prevent bypassing Edge Website Typo Protection prompts for sites (User)","description":"This policy setting lets you decide whether users can override the Edge Website Typo Protection warnings about potential typosquatting websites.\r\n\r\nIf you enable this setting, users can't ignore Edge Website Typo Protection warnings and they are blocked from continuing to the site.\r\n\r\nIf you disable or don't configure this setting, users can ignore Edge Website Typo Protection warnings and continue to the site.\r\n\r\nThis will only take effect when TyposquattingCheckerEnabled policy is not set or set to enabled.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_preventtyposquattingpromptoverride_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_preventtyposquattingpromptoverride_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains","displayName":"Configure the list of domains for which Edge Website Typo Protection won't trigger warnings (User)","description":"Configure the list of Edge Website Typo Protection trusted domains. This means:\r\nEdge Website Typo Protection won't check for potentially malicious typosquatting websites.\r\n\r\nIf you enable this policy, Edge Website Typo Protection trusts these domains.\r\nIf you disable or don't set this policy, default Edge Website Typo Protection protection is applied to all resources.\r\n\r\nThis will only take effect when TyposquattingCheckerEnabled policy is not set or set to enabled.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10/11 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.\r\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender for Endpoint. You must configure your allow and block lists in Microsoft 365 Defender portal using Indicators (Settings > Endpoints > Indicators).\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_typosquattingallowlistdomainsdesc","displayName":"Configure the list of domains for which Edge Website Typo Protection won't trigger warnings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled","displayName":"Enables DALL-E themes generation (User)","description":"This policy lets you generate browser themes using DALL-E and apply them to Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, the AI generated themes will be enabled.\r\n\r\nIf you disable this policy, the AI generated themes will be disabled for your organization.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_enhancesecuritymodeallowuserbypass","displayName":"Allow users to bypass Enhanced Security Mode (User)","description":"Microsoft Edge will let users bypass Enhanced Security Mode on a site via Settings page or PageInfo flyout. This policy lets you configure whether users can bypass Enhanced Security Mode.\r\n\r\nIf you disable this policy, Microsoft Edge won't allow users to bypass Enhanced Security Mode.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will allow users to bypass Enhanced Security Mode.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_enhancesecuritymodeallowuserbypass_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_enhancesecuritymodeallowuserbypass_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_superdragdropenabled","displayName":"Super Drag Drop Enabled (User)","description":"This policy lets you configure the Super Drag Drop feature in Microsoft Edge.\r\n\r\nWith this feature, users can drag a link or text from a webpage and drop it onto the same page. They can then either open the URL in a new tab or search the text using the default search engine.\r\n\r\nIf you enable or don't configure this policy, you can use the Super Drag Drop feature on Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Super Drag Drop feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_superdragdropenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_superdragdropenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_urldiagnosticdataenabled","displayName":"URL reporting in Edge diagnostic data enabled (User)","description":"Controls sending URLs of pages visited and per-page usage in the Microsoft Edge optional diagnostics data to Microsoft to help make browsing and search better. This also includes identifiers and usage diagnostics of other browser components that can modify or provide content, such as extensions.\r\n\r\nThis policy is applicable only if the 'DiagnosticData' (Send required and optional diagnostic data about browser usage) setting is set to 'OptionalData'. See the description of 'DiagnosticData' for more information on how Microsoft Edge diagnostic data levels are set.\r\n\r\nIf you enable or don't configure this setting, URLs are provided in optional diagnostic data.\r\n\r\nIf you disable this setting, URLs are not reported in optional diagnostic data.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_urldiagnosticdataenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_urldiagnosticdataenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_rsakeyusageforlocalanchorsenabled","displayName":"Check RSA key usage for server certificates issued by local trust anchors (User)","description":"The X.509 key usage extension declares how the key in a certificate can be\r\nused. These instructions ensure certificates aren't used in an unintended\r\ncontext, which protects against a class of cross-protocol attacks on HTTPS and\r\nother protocols. HTTPS clients must verify that server certificates match the\r\nconnection's TLS parameters.\r\n\r\nIf this policy is enabled,\r\nMicrosoft Edge will perform this key\r\ncheck. This helps prevent attacks where an attacker manipulates the browser into\r\ninterpreting a key in ways that the certificate owner did not intend.\r\n\r\nIf this policy is set to disabled or not configured,\r\nMicrosoft Edge will skip this key check in\r\nHTTPS connections that negotiate TLS 1.2 and use an RSA certificate that\r\nchains to a local trust anchor. Examples of local trust anchors include\r\npolicy-provided or user-installed root certificates. In all other cases, the\r\ncheck is performed independent of this policy's setting.\r\n\r\nThis policy is available for administrators to preview the behavior of a\r\nfuture release, which will enable this check by default. At that point, this\r\npolicy will remain temporarily available for administrators that need more\r\ntime to update their certificates to meet the new RSA key usage requirements.\r\n\r\nConnections that fail this check will fail with the error\r\nERR_SSL_KEY_USAGE_INCOMPATIBLE. Sites that fail with this error likely have a\r\nmisconfigured certificate. Modern ECDHE_RSA cipher suites use the\r\n\"digitalSignature\" key usage option, while legacy RSA decryption cipher suites\r\nuse the \"keyEncipherment\" key usage option. If uncertain, administrators should\r\ninclude both in RSA certificates meant for HTTPS.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_rsakeyusageforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_rsakeyusageforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_screencapturewithoutgestureallowedfororigins","displayName":"Allow screen capture without prior user gesture (User)","description":"For security reasons, the\r\ngetDisplayMedia() web API requires\r\na prior user gesture (\"transient activation\") to be called or the API will\r\nfail.\r\n\r\nWhen this policy is configured, admins can specify origins on which this API\r\ncan be called without prior user gesture.\r\n\r\nFor detailed information on valid url patterns, see\r\nhttps://go.microsoft.com/fwlink/?linkid=2095322. Note: * is not an accepted\r\nvalue for this policy.\r\n\r\nIf this policy is not configured, all origins require a prior user gesture to\r\ncall this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_screencapturewithoutgestureallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_screencapturewithoutgestureallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge_screencapturewithoutgestureallowedfororigins_screencapturewithoutgestureallowedfororiginsdesc","displayName":"Allow screen capture without prior user gesture (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting (User)","description":"Setting the policy to \"BlockWindowManagement\" (value 2) automatically denies the window management permission to sites by default. This limits the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nSetting the policy to \"AskWindowManagement\" (value 3) by default prompts the user when the window management permission is requested. If users allow the permission, it extends the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nNot configuring the policy means the \"AskWindowManagement\" policy applies, but users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockWindowManagement (2) = Denies the Window Management permission on all sites by default\r\n\r\n* AskWindowManagement (3) = Ask every time a site wants obtain the Window Management permission\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_defaultwindowmanagementsetting_2","displayName":"Denies the Window Management permission on all sites by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_defaultwindowmanagementsetting_3","displayName":"Ask every time a site wants obtain the Window Management permission","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementallowedforurls","displayName":"Allow Window Management permission on specified sites (User)","description":"Lets you configure a list of site url patterns that specify sites which will automatically grant the window management permission. This extends the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy isn't configured for a site, then the policy from 'DefaultWindowManagementSetting' (Default Window Management permission setting) applies to the site, if configured. Otherwise the permission will follow the browser's defaults and let users choose this permission per site.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementallowedforurls_windowmanagementallowedforurlsdesc","displayName":"Allow Window Management permission on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls","displayName":"Block Window Management permission on specified sites (User)","description":"Lets you configure a list of site url patterns that specify sites which will automatically deny the window management permission. This limits the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy isn't configured for a site, then the policy from 'DefaultWindowManagementSetting' (Default Window Management permission setting) applies to the site, if configured. Otherwise the permission will follow the browser's defaults and let users choose this permission per site.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls_windowmanagementblockedforurlsdesc","displayName":"Block Window Management permission on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensioninstalltypeblocklist","displayName":"Blocklist for extension install types (User)","description":"The blocklist controls which extension install types are disallowed.\r\n\r\nSetting the \"command_line\" will block an extension from being loaded from command line.\r\n\r\nPolicy options mapping:\r\n\r\n* command_line (command_line) = Blocks extensions from being loaded from command line\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\ncommand_line","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensioninstalltypeblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensioninstalltypeblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensioninstalltypeblocklist_extensioninstalltypeblocklistdesc","displayName":"Blocklist for extension install types (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability (User)","description":"Control if Manifest v2 extensions can be used by browser.\r\n\r\nManifest v2 extensions support will be deprecated and all extensions need to be migrated to v3 in the future. More information about, and the timeline of the migration has not been established.\r\n\r\nIf the policy is set to Default or not set, v2 extension loading is decided by browser. This will follow the preceding timeline when it's established.\r\n\r\nIf the policy is set to Disable, v2 extensions installation are blocked, and existing ones are disabled. This option is going to be treated the same as if the policy is unset after v2 support is turned off by default.\r\n\r\nIf the policy is set to Enable, v2 extensions are allowed. The option is going to be treated the same as if the policy isn't set before v2 support is turned off by default.\r\n\r\nIf the policy is set to EnableForForcedExtensions, force installed v2 extensions are allowed. This includes extensions that are listed by 'ExtensionInstallForcelist' (Control which extensions are installed silently) or 'ExtensionSettings' (Configure extension management settings) with installation_mode \"force_installed\" or \"normal_installed\". All other v2 extensions are disabled. The option is always available regardless of the manifest migration state.\r\n\r\nExtensions availabilities are still controlled by other policies.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default browser behavior\r\n\r\n* Disable (1) = Manifest v2 is disabled\r\n\r\n* Enable (2) = Manifest v2 is enabled\r\n\r\n* EnableForForcedExtensions (3) = Manifest v2 is enabled for forced extensions only\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_0","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_1","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_2","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_3","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotcdppagecontext","displayName":"Control Copilot with Commercial Data Protection access to page context for Microsoft Entra ID profiles (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 132.\r\n\r\nThis policy has been obsoleted as of Edge 133. Instead of this obsolete policy, we recommend using 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane).\r\n\r\nThis policy controls access to page contents for Copilot with Commercial Data Protection in the Edge sidebar. This policy applies only to Microsoft Entra ID profiles. To summarize pages and interact with text selections, it needs to be able to access the page contents. This policy does not apply to MSA profiles. This policy doesn't control access for Copilot without Commercial Data Protection. Access for Copilot without Commercial Data Protection is controlled by the policy CopilotPageContext.\r\n\r\nIf you enable this policy, Copilot with Commercial Data Protection will have access to page context.\r\n\r\nIf you don't configure this policy, a user can enable access to page context for Copilot with Commercial Data Protection using the setting toggle in Edge.\r\n\r\nIf you disable this policy, Copilot with Commercial Data Protection will not be able to access page context.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotcdppagecontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotcdppagecontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotpagecontext","displayName":"Control Copilot access to page context for Microsoft Entra ID profiles (User)","description":"This policy controls access to page contents for Copilot in the Microsoft Edge sidebar when users are logged into their MSA Copilot account. This policy applies only to Microsoft Entra ID Microsoft Edge profiles. To summarize pages and interact with text selections, it needs to be able to access the page contents. This policy does not apply to MSA Microsoft Edge profiles. This policy doesn't control access for Copilot with enterprise data protection (EDP). Access for Copilot with enterprise data protection (EDP) is controlled by the 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane) policy.\r\n\r\nIf you enable this policy, Copilot will have access to page content when logged in with Entra ID.\r\n\r\nIf this policy is not configured, the default behavior for non-EU countries is that access is initially enabled. For EU countries, the default behavior is that access is initially disabled. In both cases, if the policy is not configured, users can enable or disable Copilot's access to page content using the setting toggle in Microsoft Edge.\r\n\r\nIf you disable this policy, Copilot will not be able to access page context.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotpagecontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotpagecontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled","displayName":"Enable deprecated/removed Mutation Events (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy provides a temporary opt-in back to a deprecated and removed set of platform events named Mutation Events.\r\n\r\nIf you enable this policy, mutation events will continue to be fired, even if they've been disabled by default for normal web users.\r\n\r\nIf you disable or don't configure this policy, these events will not be fired.\r\n\r\nThis policy is a temporary workaround, and enterprises should still work to remove their dependencies on these mutation events.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_imageeditorserviceenabled","displayName":"Enable the Designer for Image Editor feature (User)","description":"Lets users access and use the Designer for Image Editor feature to edit an image they select.\r\n\r\nIf you enable or don't configure this policy, users can access and use the Designer for Image Editor feature in Microsoft Edge.\r\n\r\nIf you disable this policy, users can't access and use the Designer for Image Editor feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_imageeditorserviceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_imageeditorserviceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_qrcodegeneratorenabled","displayName":"Enable QR Code Generator (User)","description":"This policy enables the QR Code generator feature in Microsoft Edge.\r\n\r\nIf you enable this policy or don't configure it, the QR Code Generator feature is enabled.\r\n\r\nIf you disable this policy, the QR Code Generator feature is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_qrcodegeneratorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_qrcodegeneratorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge~network_zstdcontentencodingenabled","displayName":"Enable zstd content encoding support (User)","description":"This feature enables advertising \"zstd\" support in the Accept-Encoding request header and support for decompressing zstd web content.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will accept server responses compressed with zstd.\r\n\r\nIf you disable this policy, the zstd content encoding feature will not be advertised or supported when processing server responses.\r\n\r\nThis policy is temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge~network_zstdcontentencodingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge~network_zstdcontentencodingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge_internetexplorersetforegroundwhenactive","displayName":"Keep the active Microsoft Edge window with an Internet Explorer mode tab always in the foreground. (User)","description":"This policy controls whether to always keep the active Microsoft Edge window with an Internet Explorer mode tab in the foreground.\r\n\r\nIf you enable this policy, the active Microsoft Edge window with an Internet Explorer mode tab will always be in the foreground.\r\n\r\nIf you disable or don't configure this policy, the active Microsoft Edge window with an Internet Explorer mode tab will not be kept in the foreground.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge_internetexplorersetforegroundwhenactive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge_internetexplorersetforegroundwhenactive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge~identity_proactiveauthworkflowenabled","displayName":"Enable proactive authentication (User)","description":"This policy controls the proactive authentication in Microsoft Edge, that connects the signed-in user identity with Microsoft Bing, MSN and Copilot services for a smooth and consistent sign-in experience.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser.\r\n\r\nIf you disable this policy, Microsoft Edge does not send authentications requests to these services and users will need to manually sign-in.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge~identity_proactiveauthworkflowenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge~identity_proactiveauthworkflowenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_csscustomstatedeprecatedsyntaxenabled","displayName":"Controls whether the deprecated :--foo syntax for CSS custom state is enabled (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 132.\r\n\r\nThe :--foo syntax for the CSS custom state feature is being changed to :state(foo) in Microsoft Edge in order to comply with changes that have been made in Firefox and Safari. This policy lets the deprecated syntax to be used until Stable 132.\r\n\r\nThis deprecation might break some Microsoft Edge-only websites that use the deprecated :--foo syntax.\r\n\r\nIf you enable this policy, the deprecated syntax will be enabled.\r\n\r\nIf you disable this policy or don't set it, the deprecated syntax will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_csscustomstatedeprecatedsyntaxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_csscustomstatedeprecatedsyntaxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist","displayName":"Control which apps cannot be opened in Microsoft Edge sidebar (User)","description":"Define a list of sites, based on URL patterns, that cannot be opened in sidebar.\r\n\r\nIf you don't configure this policy, a user can open any app in sidebar.\r\n\r\nIf the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used and no sidebar can be opened.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nNote: A blocklist value of '*' means all apps are blocked unless they are explicitly listed in the 'EdgeSidebarAppUrlHostAllowList' (Allow specific apps to be opened in Microsoft Edge sidebar) policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_edgesidebarappurlhostblocklistdesc","displayName":"Control which apps cannot be opened in Microsoft Edge sidebar (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128.1~policy~microsoft_edge_applicationboundencryptionenabled","displayName":"Enable Application Bound Encryption (User)","description":"Enabling this policy or leaving it unset binds the encryption keys used for local data storage to Microsoft Edge whenever possible.\r\n\r\nDisabling this policy has a detrimental effect on Microsoft Edge's security because unknown and potentially hostile apps can retrieve the encryption keys used to secure data.\r\n\r\nOnly turn off this policy if there are compatibility issues, such as scenarios where other applications need legitimate access to Microsoft Edge's data. Encrypted user data is expected to be fully portable between different computers or the integrity and location of Microsoft Edge's executable files isn’t consistent.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128.1~policy~microsoft_edge_applicationboundencryptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128.1~policy~microsoft_edge_applicationboundencryptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings","displayName":"Dynamic Code Settings (User)","description":"This policy controls the dynamic code settings for Microsoft Edge.\r\n\r\nDisabling dynamic code improves the security of Microsoft Edge by preventing potentially hostile dynamic code and third-party code from making changes to Microsoft Edge's behavior. However this might cause compatibility issues with third-party software that must run in the browser process.\r\n\r\nIf you set this policy to 0 (the default) or leave unset, then Microsoft Edge will use the default settings.\r\n\r\nIf you set this policy to 1 – (EnabledForBrowser) then the Microsoft Edge browser process is prevented from creating dynamic code.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default dynamic code settings\r\n\r\n* EnabledForBrowser (1) = Prevent the browser process from creating dynamic code\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_dynamiccodesettings","displayName":"Dynamic Code Settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_dynamiccodesettings_0","displayName":"Default dynamic code settings","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_dynamiccodesettings_1","displayName":"Prevent the browser process from creating dynamic code","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgeopeninsidebarenabled","displayName":"Enable open in sidebar (User)","description":"Allow/Disallow user open a website or an app to the sidebar.\r\n\r\nIf you enable or don't configure this policy, users will be able to access the feature.\r\nIf you disable this policy, users will not be able to access the feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgeopeninsidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgeopeninsidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgesidebarcustomizeenabled","displayName":"Enable sidebar customize (User)","description":"Allow/Disallow to use sidebar customize.\r\n\r\nIf you enable or don't configure this policy, users will be able to access sidebar customize.\r\nIf you disable this policy, users will not be able to access the sidebar customize.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgesidebarcustomizeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgesidebarcustomizeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_keyboardfocusablescrollersenabled","displayName":"Enable keyboard focusable scrollers (User)","description":"This policy provides a temporary opt-out for the new keyboard focusable scrollers behavior.\r\n\r\nWhen this policy is Enabled or unset, scrollers without focusable children are keyboard focusable by default.\r\n\r\nWhen this policy is Disabled, scrollers are not keyboard focusable by default.\r\n\r\nThis policy is a temporary workaround and will be removed in Edge Stable 135.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_keyboardfocusablescrollersenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_keyboardfocusablescrollersenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_recommended~downloads_recommended_showdownloadsinsecurewarningsenabled_recommended","displayName":"Enable insecure download warnings (User)","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\r\n\r\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user will receive a UI warning, such as \"Insecure download blocked.\" The user will still have an option to proceed and download the item.\r\n\r\nIf you disable this policy, the warnings for insecure downloads will be suppressed.","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_recommended~downloads_recommended_showdownloadsinsecurewarningsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_recommended~downloads_recommended_showdownloadsinsecurewarningsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~downloads_showdownloadsinsecurewarningsenabled","displayName":"Enable insecure download warnings (User)","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\r\n\r\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user will receive a UI warning, such as \"Insecure download blocked.\" The user will still have an option to proceed and download the item.\r\n\r\nIf you disable this policy, the warnings for insecure downloads will be suppressed.","helpText":"","infoUrls":[],"categoryId":"5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","categoryName":"Downloads","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~downloads_showdownloadsinsecurewarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~downloads_showdownloadsinsecurewarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page (User)","description":"Control if users can turn on Developer Mode on edge://extensions.\r\n\r\nIf the policy isn't set, users can turn on developer mode on the extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\r\nIf the policy is set to Allow (0), users can turn on developer mode on the extensions page.\r\nIf the policy is set to Disallow (1), users cannot turn on developer mode on the extensions page.\r\n\r\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.\r\n\r\nPolicy options mapping:\r\n\r\n* Allow (0) = Allow the usage of developer mode on extensions page\r\n\r\n* Disallow (1) = Do not allow the usage of developer mode on extensions page\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensiondevelopermodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensiondevelopermodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings_0","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings_1","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant an extended background lifetime to connecting extensions. (User)","description":"Extensions that connect to one of these origins will keep running as long as the port is connected.\r\nIf unset, the policy's default values are used. These are the app origins that offer SDKs that are known to not offer the possibility to restart a closed connection to a previous state:\r\n- Smart Card Connector\r\n- Citrix Receiver (stable, beta, back-up)\r\n- VMware Horizon (stable, beta)\r\n\r\nIf set, the default value list is extended with the newly configured values. The defaults and policy-provided entries will grant the exception to the connecting extensions, as long as the port is connected.\r\n\r\nExample value:\r\n\r\nchrome-extension://abcdefghijklmnopabcdefghijklmnop/\r\nchrome-extension://bcdefghijklmnopabcdefghijklmnopa/","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_extensionextendedbackgroundlifetimeforportconnectionstourlsdesc","displayName":"Configure a list of origins that grant an extended background lifetime to connecting extensions. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled","displayName":"Enable Printing LPAC Sandbox (User)","description":"Setting this policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services when the system configuration supports it.\r\n\r\nSetting this policy to Disabled has a detrimental effect on Microsoft Edge's security because services used for printing might run in a weaker sandbox configuration.\r\n\r\nOnly turn this policy off if there are compatibility issues with third party software that prevent printing services from operating correctly inside the LPAC Sandbox.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge_edgeentracopilotpagecontext","displayName":"Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane (User)","description":"This policy controls whether Copilot in the Microsoft Edge sidepane can access Microsoft Edge page content. This includes page summarization and similar contextual queries sent to Copilot.\r\n\r\nThis policy only applies to users who are signed in to Microsoft Edge with their Entra account and are using Copilot in the sidepane. This policy applies to all Copilot products in the Microsoft Edge sidepane - namely, Microsoft 365 Copilot Business Chat and Microsoft Copilot with enterprise data protection (EDP).\r\n\r\nIf you enable this policy, Copilot will be able to access Microsoft Edge page content when users ask a contextual query to Copilot in the Microsoft Edge sidepane.\r\n\r\nIf you disable this policy, Copilot will not be able to access Microsoft Edge page content.\r\n\r\nIf you don't configure this policy, the default behavior is as follows:\r\n\r\n- For non-EU countries, access is enabled by default.\r\n\r\n- For EU countries, access is disabled by default.\r\n\r\n- In both cases, if the policy is not configured, users can enable or disable Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings.\r\n\r\nExceptions to the preceding behavior include when a page is protected using data loss prevention (DLP) measures. In that case, Copilot will not be able to access Microsoft Edge page content even when this policy is enabled. This behavior is to ensure the integrity of DLP.\r\n\r\nLearn more about Copilot's data usage and consent at https://go.microsoft.com/fwlink/?linkid=2288056","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge_edgeentracopilotpagecontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge_edgeentracopilotpagecontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge~performance_extensionsperformancedetectorenabled","displayName":"Extensions Performance Detector enabled (User)","description":"This policy controls if users can access the Extensions Performance Detector Recommended Action feature in Browser Essentials. This feature alerts extension users if their extensions are causing performance regressions in the browser and allows them to take action to resolve the issue.\r\n\r\nIf you enable or don't configure this policy, users will receive Extensions Performance Detector notifications from Browser Essentials. When there is an active alert, users will be able to view the impact of extensions on their browser's performance and make an informed decision to disable impacting extensions. The detector will exclude browser-managed extensions, such as Google Docs offline, component extensions, and organization-managed extensions (ie. extensions that cannot be disabled).\r\n\r\nIf you disable this policy, users will not receive notifications or be able to view the Extensions Performance Detector Recommended Action.","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge~performance_extensionsperformancedetectorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge~performance_extensionsperformancedetectorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist","displayName":"Allow specific apps to be opened in Microsoft Edge sidebar (User)","description":"Define a list of sites, based on URL patterns, that are not subject to the 'EdgeSidebarAppUrlHostBlockList' (Control which apps cannot be opened in Microsoft Edge sidebar).\r\n\r\nIf you don't configure this policy, a user can open any app in sidebar except the urls listed in 'EdgeSidebarAppUrlHostBlockList'.\r\n\r\nIf you configure this policy, the apps listed in the allow list could be opened in sidebar even if they are listed in the block list.\r\n\r\nBy default, all apps are allowed. However, if you prohibited apps by policy, you can use the list of allowed apps to change that policy.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist_edgesidebarappurlhostallowlistdesc","displayName":"Allow specific apps to be opened in Microsoft Edge sidebar (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_edgeautofillmlenabled","displayName":"Machine learning powered autofill suggestions (User)","description":"Allows ML technology to predict and fill in forms and text fields for better browsing. Your personal data is secure and will not be used elsewhere.\r\n\r\nIf you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data.\r\n\r\nIf you disable this policy, machine learning powered autofill suggestions will not be shown, and autofill will no longer use cloud-based machine learning models to enhance form filling with smarter, context aware suggestions. Instead, autofill will rely on basic form data without the benefits of machine learning.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_edgeautofillmlenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_edgeautofillmlenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_livetranslationallowed","displayName":"Live translation allowed (User)","description":"Allow users to turn the Realtime Video Translation feature on or off.\r\n\r\nThis feature allows videos being watched to be translated to the selected language in real time or live. Users need to click the translate icon that appears when they hover over a video to get started.\r\n\r\nThis is the on-device feature and none of the audio, data or even translated audio leave the device.\r\n\r\nIf you enable or don't configure this policy, users can turn this feature on or off in edge://settings/languages.\r\nIf you disable this policy, users will not be able to turn this feature on. If user has been using the feature already and policy gets disabled, the feature related files downloaded previously, will be deleted from the device after 30 days. We recommend not to disable the policy, unless it is needed in your environment.\r\n\r\nIf users enable this feature, the feature related files (approximately 200 megabytes) will be downloaded to the device on the first run and periodically thereafter to enhance performance and accuracy. These files will be deleted 30 days after their last use.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_livetranslationallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_livetranslationallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_personalizetopsitesincustomizesidebarenabled","displayName":"Personalize my top sites in Customize Sidebar enabled by default (User)","description":"This policy controls whether Microsoft Edge browser be allowed to use the browsing history to personalize the top sites in the customize sidebar page.\r\n\r\nIf you enable this policy, Microsoft Edge will use the browsing history to personalize the top sites in the customize sidebar page.\r\n\r\nIf you disable this policy, Microsoft Edge will not use the browsing history to personalize the top sites in the customize sidebar page.\r\n\r\nIf you don't configure this policy, the default behavior is to use the browsing history to personalize the top sites in the customize sidebar page.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_personalizetopsitesincustomizesidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_personalizetopsitesincustomizesidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_recommended_edgeautofillmlenabled_recommended","displayName":"Machine learning powered autofill suggestions (User)","description":"Allows ML technology to predict and fill in forms and text fields for better browsing. Your personal data is secure and will not be used elsewhere.\r\n\r\nIf you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data.\r\n\r\nIf you disable this policy, machine learning powered autofill suggestions will not be shown, and autofill will no longer use cloud-based machine learning models to enhance form filling with smarter, context aware suggestions. Instead, autofill will rely on basic form data without the benefits of machine learning.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_recommended_edgeautofillmlenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_recommended_edgeautofillmlenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_selectparserrelaxationenabled","displayName":"Controls whether the new HTML parser behavior for the element. This policy supports the old HTML parser behavior until M136.\r\n\r\nIf this policy is enabled or unset, the HTML parser will allow additional tags inside the element.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_selectparserrelaxationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_selectparserrelaxationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenallowedforurls","displayName":"Allow automatic full screen on specified sites (User)","description":"For security reasons, the\r\nrequestFullscreen() web API\r\nrequires a prior user gesture (\"transient activation\") to be called or it will\r\nfail. Users' personal settings may allow certain origins to call this API\r\nwithout a prior user gesture.\r\n\r\nThis policy supersedes users' personal settings and allows matching origins to\r\ncall the API without a prior user gesture.\r\n\r\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\nWildcards (*) are allowed.\r\n\r\nOrigins matching both blocked and allowed policy patterns will be blocked.\r\nOrigins not specified by policy or user settings will require a prior user\r\ngesture to call this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenallowedforurls_automaticfullscreenallowedforurlsdesc","displayName":"Allow automatic full screen on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls","displayName":"Block automatic full screen on specified sites (User)","description":"For security reasons, the\r\nrequestFullscreen() web API\r\nrequires a prior user gesture (\"transient activation\") to be called or it will\r\nfail. Users' personal settings may allow certain origins to call this API\r\nwithout a prior user gesture.\r\n\r\nThis policy supersedes users' personal settings and blocks matching origins\r\nfrom calling the API without a prior user gesture.\r\n\r\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\nWildcards (*) are allowed.\r\n\r\nOrigins matching both blocked and allowed policy patterns will be blocked.\r\nOrigins not specified by policy or user settings will require a prior user\r\ngesture to call this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls_automaticfullscreenblockedforurlsdesc","displayName":"Block automatic full screen on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~generativeai_genailocalfoundationalmodelsettings","displayName":"Settings for GenAI local foundational model (User)","description":"Configure how Microsoft Edge downloads the foundational GenAI model and uses it for inference locally.\r\n\r\nWhen the policy is set to Allowed (0) or not set, the model is downloaded automatically, and used for inference.\r\n\r\nWhen the policy is set to Disabled (1), the model will not be downloaded.\r\n\r\nModel downloading can also be disabled by ComponentUpdatesEnabled.\r\n\r\nPolicy options mapping:\r\n\r\n* Allowed (0) = Downloads model automatically\r\n\r\n* Disabled (1) = Do not download model\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"76e34834-6d47-4e06-b14c-aa2888cdce27","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~generativeai_genailocalfoundationalmodelsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~generativeai_genailocalfoundationalmodelsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings","displayName":"Settings for GenAI local foundational model (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76e34834-6d47-4e06-b14c-aa2888cdce27","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings_0","displayName":"Downloads model automatically","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings_1","displayName":"Do not download model","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled","displayName":"Enable IPv6 reachability check override (User)","description":"This policy enables an override of the IPv6 reachability check. When overridden, the\r\nsystem will always query AAAA records when resolving host names. It applies to\r\nall users and interfaces on the device.\r\n\r\nIf you enable this policy, the IPv6 reachability check will be overridden.\r\n\r\nIf you disable or don't configure this policy, the IPv6 reachability check will not be overridden.\r\nThe system only queries AAAA records when it is reachable to a global IPv6 host.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~passwordmanager_deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords (User)","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own.\r\n\r\nIf fixing them is possible, it usually requires complex user actions.\r\n\r\nEnabling this policy or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched.\r\n\r\nDisabling this policy means users will have their password manager data untouched, but will experience a broken password manager functionality.\r\n\r\nIf the policy is set, users can't override it in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~passwordmanager_deletingundecryptablepasswordsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~passwordmanager_deletingundecryptablepasswordsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedfilehash","displayName":"View XFA-based PDF files using IE Mode for allowed file hash. (User)","description":"XFA is a legacy technology that is deprecated by its original creators. It is not an ISO standard and as such, doesn't align with the modern web architecture. Continued use poses potential risks and vulnerabilities. For more information, see - 'ViewXFAPDFInIEModeAllowedOrigins' (View XFA-based PDF files using IE Mode for allowed file origin.).\r\n\r\nIf you enable this policy, you can configure the list of base64 encoded SHA256 file hashes for which XFA PDF files will automatically open in Microsoft Edge using IE Mode.\r\n\r\nIf you disable or don't configure this policy, XFA PDFs won't be considered for opening via IE mode except the files from file origin mentioned in Policy 'ViewXFAPDFInIEModeAllowedOrigins'\r\n\r\nFor more information, see - [Get-FileHash](https://go.microsoft.com/fwlink/?linkid=2294823), [Dot Net Convert API](https://go.microsoft.com/fwlink/?linkid=2294913).\r\n\r\nExample value:\r\n\r\npZGm1Av0IEBKARczz7exkNYsZb8LzaMrV7J32a2fFG4=\r\nnFeL0Q+9HX7WFI3RsmSDFTlUtrbclXH67MTdXDwWuu4=","helpText":"","infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedfilehash_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedfilehash_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedfilehash_viewxfapdfiniemodeallowedfilehashdesc","displayName":"View XFA-based PDF files using IE Mode for allowed file hash. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins","displayName":"View XFA-based PDF files using IE Mode for allowed file origin. (User)","description":"Internet Explorer (IE) mode uses the Adobe Acrobat Active-X PDF Plugin to open XFA-based PDF files. This policy will only work if the Active-X plugin is already on the user's device, it's not installed as part of this policy.\r\n\r\nIt's important to note that XFA is a legacy technology that is deprecated by its original creators. It is not an ISO standard and as such, doesn't align with the modern web architecture. Continued use poses potential risks and vulnerabilities.\r\n\r\nGiven the deprecated status of XFA technology and the lack of any investment by its creators, we strongly recommend that you start planning your transition to a more advanced HTML\\PDF form-based solutions.\r\n\r\nIn the interim, this policy provides a workaround for users to view XFA PDF in Microsoft Edge.\r\n\r\nIf you enable this policy, you can configure the list of origins from which XFA PDF files will be automatically opened in Microsoft Edge using IE Mode.\r\n\r\nIf you disable or don't configure the policy, XFA PDFs won't be considered for opening via Internet Explorer mode.\r\n\r\nFor detailed information on valid URL patterns, see - https://go.microsoft.com/fwlink/?linkid=2095322\r\n\r\nAlternatively, 'ViewXFAPDFInIEModeAllowedFileHash' (View XFA-based PDF files using IE Mode for allowed file hash.) can also be used to configure list of file hashes instead of URL origins, which will enable those files to be automatically opened in Microsoft Edge using IE Mode.\r\n\r\nExample value:\r\n\r\nhttps://contesso.sharepoint.com/accounts/\r\nhttps://contesso.sharepoint.com/transport/\r\nfile://account_forms/","helpText":"","infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins_viewxfapdfiniemodeallowedoriginsdesc","displayName":"View XFA-based PDF files using IE Mode for allowed file origin. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled","displayName":"Enable additional search box in browser (User)","description":"A search box is an additional text input field located next to the address bar in a web browser. It allows users to perform web searches directly from the browser interface.\r\n\r\nIf you enable or don't configure this policy, the search box will be visible and available for use.\r\nUsers can toggle the search box in Edge Settings page edge://settings/appearance#SearchBoxInToolbar.\r\n\r\nIf you disable this policy, search box will not be visible, and users will have to use the address bar or navigate to a search engine to perform web searches.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_allowwebauthnwithbrokentlscerts","displayName":"Allow Web Authentication requests on sites with broken TLS certificates. (User)","description":"If you enable this policy, Microsoft Edge will allow Web Authentication requests on websites that have TLS certificates with errors (i.e. websites considered not secure).\r\n\r\nIf you disable or don't configure this policy, the default behavior of blocking such requests will apply.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_allowwebauthnwithbrokentlscerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_allowwebauthnwithbrokentlscerts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar (User)","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\r\n\r\nIf you don't configure this policy, no app is forced to be shown in sidebar.\r\n\r\nIf the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used and no sidebar can be shown.\r\n\r\nFor detailed information about valid url, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nNote: URL patterns are not supported in this policy. You should provide the exact URL of the app.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_edgesidebarappurlhostforcelistdesc","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist","displayName":"HTTP Allowlist (User)","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that will not be upgraded to HTTPS and will not show an error interstitial if HTTPS-First Mode is enabled. Organizations can use this policy to maintain access to servers that do not support HTTPS, without needing to disable 'AutomaticHttpsDefault' (Configure Automatic HTTPS).\r\n\r\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase.\r\n\r\nBlanket host wildcards (i.e., \"*\" or \"[*]\") are not allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies.\r\n\r\nNote: This policy does not apply to HSTS upgrades.\r\n\r\nExample value:\r\n\r\ntestserver.example.com\r\n[*.]example.org","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist_httpallowlistdesc","displayName":"HTTP Allowlist (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_pdfvieweroutofprocessiframeenabled","displayName":"Use out-of-process iframe PDF Viewer (User)","description":"Determines whether the PDF viewer in Microsoft Edge uses an out-of-process iframe (OOPIF).\r\nThis will be the new PDF viewer architecture going forward, as it is simpler in design and makes adding new features easier. The current GuestView PDF viewer, which relies on an outdated and overly complex architecture, is being deprecated.\r\n\r\nWhen this policy is set to Enabled or not set, Microsoft Edge will use the OOPIF PDF viewer architecture. Once Enabled or not set, the default behavior will be decided by Microsoft Edge.\r\n\r\nWhen this policy is set to Disabled, Microsoft Edge will strictly use the existing GuestView PDF viewer. This approach embeds a web page with its own separate frame tree into another web page.\r\n\r\nThis policy will be removed in the future, after the OOPIF PDF viewer feature has fully rolled out.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_pdfvieweroutofprocessiframeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_pdfvieweroutofprocessiframeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates. (User)","description":"Setting the policy to All (0) or leaving it unset lets users edit trust settings for all CA certificates, remove user-imported certificates, and import certificates using Certificate Manager. Setting the policy to UserOnly (1) lets users manage only user-imported certificates, but not change trust settings of built-in certificates. Setting it to None (2) lets users view (not manage) CA certificates.\r\n\r\nPolicy options mapping:\r\n\r\n* All (0) = Allow users to manage all certificates\r\n\r\n* UserOnly (1) = Allow users to manage user certificates\r\n\r\n* None (2) = Disallow users from managing certificates\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed_0","displayName":"Allow users to manage all certificates","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed_1","displayName":"Allow users to manage user certificates","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_cacertificatemanagementallowed_2","displayName":"Disallow users from managing certificates","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates","displayName":"TLS server certificates that should be trusted by Microsoft Edge (User)","description":"This policy enables a list of TLS certificates that should be trusted by Microsoft Edge for server authentication.\r\nCertificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_cacertificatesdesc","displayName":"TLS server certificates that should be trusted by Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Microsoft Edge for server authentication with constraints (User)","description":"This policy enables a list of TLS certificates that should be trusted by Microsoft Edge for server authentication, with constraints added outside the certificate. If no constraint of a certain type is present, then any name of that type is allowed.\r\nCertificates should be base64-encoded. At least one constraint must be specified for each certificate.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"certificate\": \"MIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X\",\r\n \"constraints\": {\r\n \"permitted_dns_names\": [\r\n \"example.org\"\r\n ],\r\n \"permitted_cidrs\": [\r\n \"10.1.1.0/24\"\r\n ]\r\n }\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificateswithconstraints_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificateswithconstraints_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificateswithconstraints_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Microsoft Edge for server authentication with constraints (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cadistrustedcertificates","displayName":"TLS certificates that should be distrusted by Microsoft Edge for server authentication (User)","description":"This policy enables defining a list of certificate public keys that should be distrusted by Microsoft Edge for TLS server\r\nauthentication.\r\n\r\nThe policy value is a list of base64-encoded X.509 certificates. Any\r\ncertificate with a matching SPKI (SubjectPublicKeyInfo) will be distrusted.\r\n\r\nExample value:\r\n\r\nMIIB/TCCAaOgAwIBAgIUQthnWVsd1jWpUCNBf/uILjXC+t4wCgYIKoZIzj0EAwIwVDELMAkGA1UEBhMCVVMxETAPBgNVBAgMCFZpcmdpbmlhMQ8wDQYDVQQHDAZSZXN0b24xITAfBgNVBAoMGEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDAeFw0yMzEyMDcxNjE5NTVaFw0yMzEyMjExNjE5NTVaMFQxCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhWaXJnaW5pYTEPMA0GA1UEBwwGUmVzdG9uMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQ9Akav/KB0aVA9FM1QK4J1CEHn5rFOyY/nxcr5HG3+Fom0Kwu5zTR/kz9eOYgtG/1NmCzbiEKaULDfzA8V9aJ7o1MwUTAdBgNVHQ4EFgQUq37bLKiuw8Y/G+rurMf46hw7EekwHwYDVR0jBBgwFoAUq37bLKiuw8Y/G+rurMf46hw7EekwDwYDVR0TAQH/BAUwAwEB/zAKBggqhkjOPQQDAgNIADBFAiEA/JhtLSgtVOcXkgFJ9V5Vb6lhGdiKQFfzO9wTxPeCxCECIFePYPucys2n/r9MOBMHiX/8068ssv+uceqokzUg0mAb","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cadistrustedcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cadistrustedcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cadistrustedcertificates_cadistrustedcertificatesdesc","displayName":"TLS certificates that should be distrusted by Microsoft Edge for server authentication (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication (User)","description":"This policy enables defining a list of certificates that are not trusted or distrusted in Microsoft Edge\r\nbut can be used as hints for path-building. Certificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIIFljCCA36gAwIBAgINAgO8U1lrNMcY9QFQZjANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjEwHhcNMjAwODEzMDAwMDQyWhcNMjcwOTMwMDAwMDQyWjBGMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzETMBEGA1UEAxMKR1RTIENBIDFDMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPWI3+dijB43+DdCkH9sh9D7ZYIl/ejLa6T/belaI+KZ9hzpkgOZE3wJCor6QtZeViSqejOEH9Hpabu5dOxXTGZok3c3VVP+ORBNtzS7XyV3NzsXlOo85Z3VvMO0Q+sup0fvsEQRY9i0QYXdQTBIkxu/t/bgRQIh4JZCF8/ZK2VWNAcmBA2o/X3KLu/qSHw3TT8An4Pf73WELnlXXPxXbhqW//yMmqaZviXZf5YsBvcRKgKAgOtjGDxQSYflispfGStZloEAoPtR28p3CwvJlk/vcEnHXG0g/Zm0tOLKLnf9LdwLtmsTDIwZKxeWmLnwi/agJ7u2441Rj72ux5uxiZ0CAwEAAaOCAYAwggF8MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQUinR/r4XN7pXNPZzQ4kYU83E1HScwHwYDVR0jBBgwFoAU5K8rJnEaK0gnhS9SZizv8IkTcT4waAYIKwYBBQUHAQEEXDBaMCYGCCsGAQUFBzABhhpodHRwOi8vb2NzcC5wa2kuZ29vZy9ndHNyMTAwBggrBgEFBQcwAoYkaHR0cDovL3BraS5nb29nL3JlcG8vY2VydHMvZ3RzcjEuZGVyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6Ly9jcmwucGtpLmdvb2cvZ3RzcjEvZ3RzcjEuY3JsMFcGA1UdIARQME4wOAYKKwYBBAHWeQIFAzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3BraS5nb29nL3JlcG9zaXRvcnkvMAgGBmeBDAECATAIBgZngQwBAgIwDQYJKoZIhvcNAQELBQADggIBAIl9rCBcDDy+mqhXlRu0rvqrpXJxtDaV/d9AEQNMwkYUuxQkq/BQcSLbrcRuf8/xam/IgxvYzolfh2yHuKkMo5uhYpSTld9brmYZCwKWnvy15xBpPnrLRklfRuFBsdeYTWU0AIAaP0+fbH9JAIFTQaSSIYKCGvGjRFsqUBITTcFTNvNCCK9U+o53UxtkOCcXCb1YyRt8OS1b887U7ZfbFAO/CVMkH8IMBHmYJvJh8VNS/UKMG2YrPxWhu//2m+OBmgEGcYk1KCTd4b3rGS3hSMs9WYNRtHTGnXzGsYZbr8w0xNPM1IERlQCh9BIiAfq0g3GvjLeMcySsN1PCAJA/Ef5c7TaUEDu9Ka7ixzpiO2xj2YC/WXGsYye5TBeg2vZzFb8q3o/zpWwygTMD0IZRcZk0upONXbVRWPeyk+gB9lm+cZv9TSjOz23HFtz30dZGm6fKa+l3D/2gthsjgx0QGtkJAITgRNOidSOzNIb2ILCkXhAd4FJGAJ2xDx8hcFH1mt0G/FX0Kw4zd8NLQsLxdxP8c4CU6x+7Nz/OAipmsHMdMqUybDKwjuDEI/9bfU1lcKwrmz3O2+BtjjKAvpafkmO8l7tdufThcV4q5O8DIrGKZTqPwJNl1IXNDw9bg1kWRxYtnCQ6yICmJhSFm/Y3m6xv+cXDBlHz4n/FsRC6UfTd","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cahintcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cahintcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cahintcertificates_cahintcertificatesdesc","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_caplatformintegrationenabled","displayName":"Use user-added TLS certificates from platform trust stores for server authentication (User)","description":"If enabled (or unset), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.\r\n\r\nIf disabled, user-added TLS certificates from platform trust stores will not be used in path-building for TLS server authentication.","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_caplatformintegrationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_caplatformintegrationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_seamlesswebtobrowsersigninenabled","displayName":"Seamless Web To Browser Sign-in Enabled (User)","description":"This policy only takes effect when the 'WebToBrowserSignInEnabled' (Web To Browser Sign-in Enabled) is enabled.\r\nIf you enable this policy and set this policy to True, users cannot turn off Seamless Web to Browser Sign-in feature from \"Automatic sign in on Microsoft Edge\" setting on Microsoft Edge profile settings page and that toggle will be greyed out.\r\nIf you enable this policy and set this policy to False, users cannot turn on Seamless Web to Browser Sign-in feature from \"Automatic sign in on Microsoft Edge\" setting on Microsoft Edge profile settings page and that toggle will be greyed out.\r\nIf you enable this policy but not configured or disabled, users can turn on/off Seamless Web to Browser Sign-in feature from settings by themselves.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_seamlesswebtobrowsersigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_seamlesswebtobrowsersigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_webtobrowsersigninenabled","displayName":"Web To Browser Sign-in Enabled (User)","description":"Allow user to sign in to the same account in Microsoft Edge when a user signs in to a Microsoft website.\r\nIf this policy is enabled or not configured, user are able to get sign in CTA or seamless sign in experience(if 'SeamlessWebToBrowserSignInEnabled' (Seamless Web To Browser Sign-in Enabled) is enabled) when user sign in on Microsoft website.\r\nIf this policy is disabled, user will not get sign in CTA or seamless sign in experience when user sign in on Microsoft website.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_webtobrowsersigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_webtobrowsersigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~network_dataurlwhitespacepreservationenabled","displayName":"DataURL Whitespace Preservation for all media types (User)","description":"This policy provides a temporary opt-out for changes to how Edge handles whitepsace in data URLS.\r\nPreviously, whitespace would be kept only if the top level media type was text or contained the media type string xml.\r\nNow, whitespace will be preserved in all data URLs, regardless of media type.\r\n\r\nIf this policy is left unset or is set to True, the new behavior is enabled.\r\n\r\nWhen this policy is set to False, the old behavior is enabled.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~network_dataurlwhitespacepreservationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~network_dataurlwhitespacepreservationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_addressbarworksearchresultsenabled","displayName":"Enable Work Search suggestions in the address bar (User)","description":"Enables the display of relevant workplace suggestions in the address bar’s suggestion dropdown when users type a query in the address bar.\r\n\r\nIf this policy is enabled or not configured, users can view internal work-related suggestions, such as bookmarks, files, and people results powered by Microsoft 365, in the Microsoft Edge address bar suggestion dropdown. To access these results, users must be signed into Microsoft Edge with their Entra ID account associated with that organization.\r\n\r\nIf this policy is disabled, users will not see internal workplace results in the Microsoft Edge address bar suggestion dropdown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_addressbarworksearchresultsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_addressbarworksearchresultsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerprotectionenabled_recommended","displayName":"Configure Edge Scareware Blocker Protection (User)","description":"This policy setting allows administrators to control whether Microsoft Edge enables the Scareware Blocker, an AI-powered feature that provides warning messages to help protect users from potential tech scams.\r\n\r\nIf this policy is enabled, Edge Scareware Blocker will warn users of potential tech scams.\r\n\r\nIf this policy is disabled, Edge Scareware Blocker will not warn users of potential tech scams.\r\n\r\nIf this policy is not configured, Edge Scareware Blocker will not warn users of potential tech scams, but users can choose warnings in settings.\r\n\r\nBy configuring this policy, administrators determine whether users receive proactive scam warnings or must manually enable them.","helpText":"","infoUrls":[],"categoryId":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerprotectionenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerprotectionenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_serviceworkertocontrolsrcdociframeenabled","displayName":"Allow ServiceWorker to control srcdoc iframes (User)","description":"https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with the \"allow-same-origin\" sandbox attribute to be under ServiceWorker control.\r\n\r\nBy default (if left unset) or when set to Enabled, Microsoft Edge makes srcdoc iframes with \"allow-same-origin\" sandbox attributes to be under ServiceWorker control.\r\n\r\nSetting the policy to Disabled prevents ServiceWorker control over srcdoc iframes.\r\n\r\nThis policy is temporary and planned for deprecation in 2026.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_serviceworkertocontrolsrcdociframeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_serviceworkertocontrolsrcdociframeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_sharedworkerbloburlfixenabled","displayName":"Make SharedWorker blob URL behavior aligned with the specification (User)","description":"According to Service Worker specification\r\nhttps://w3c.github.io/ServiceWorker/#control-and-use-worker-client, workers\r\nshould inherit controllers for blob URLs. Currently, only DedicatedWorkers\r\ninherit the controller, while SharedWorkers do not.\r\n\r\nEnabled/Unset: Microsoft Edge inherits\r\nthe controller for SharedWorker blob URLs, aligning with the specification.\r\n\r\nDisabled: Behavior remains unchanged, not aligning with the specification.\r\n\r\nThis policy is temporary and will be removed in a future update.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_sharedworkerbloburlfixenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_sharedworkerbloburlfixenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_webaudiooutputbufferingenabled","displayName":"Enable adaptive buffering for Web Audio (User)","description":"This policy determines whether the browser enables adaptive buffering\r\nfor Web Audio. Adaptive buffering can reduce audio glitches but may\r\nincrease latency to varying degrees.\r\n\r\nEnabled: The browser will always use adaptive buffering.\r\nDisabled or Not Set: The browser will automatically decide during the\r\n feature launch process whether to use adaptive buffering.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_webaudiooutputbufferingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_webaudiooutputbufferingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout","displayName":"Delay before running idle actions (User)","description":"Triggers an action when the computer is idle.\r\n\r\nIf you set this policy, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy.\r\n\r\nIf you not set this policy, no action will be ran.\r\n\r\nThe minimum threshold is 1 minute.\r\n\r\n\"User input\" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_idletimeout","displayName":"Delay before running idle actions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeoutactions","displayName":"Actions to run when the computer is idle (User)","description":"List of actions to run when the timeout from the IdleTimeout policy is reached.\r\n\r\nIf the IdleTimeout policy is unset, this policy has no effect.\r\n\r\nWhen the timeout from the IdleTimeout policy is reached, the browser runs the actions configured in this policy.\r\n\r\nIf you do not set this policy or no actions are selected, the IdleTimeout policy has no effect.\r\n\r\nSupported actions are:\r\n\r\n'close_browsers': close all browser windows and PWAs for this profile.\r\n\r\n'reload_pages': reload all webpages. For some pages, the user may be prompted for confirmation first.\r\n\r\n'clear_browsing_history', 'clear_download_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', 'clear_autofill', 'clear_site_settings': clear the corresponding browsing data.\r\n\r\nSetting 'clear_browsing_history', 'clear_password_signing', 'clear_autofill', and 'clear_site_settings' will disable sync for the respective data types if neither `Chrome Sync` is disabled by setting the SyncDisabled policy nor BrowserSignin is disabled.\r\n\r\nPolicy options mapping:\r\n\r\n* close_browsers (close_browsers) = Close Browsers\r\n\r\n* clear_browsing_history (clear_browsing_history) = Clear Browsing History\r\n\r\n* clear_download_history (clear_download_history) = Clear Download History\r\n\r\n* clear_cookies_and_other_site_data (clear_cookies_and_other_site_data) = Clear Cookies and Other Site Data\r\n\r\n* clear_cached_images_and_files (clear_cached_images_and_files) = Clear Cached Images and Files\r\n\r\n* clear_password_signin (clear_password_signin) = Clear Password Signin\r\n\r\n* clear_autofill (clear_autofill) = Clear Autofill\r\n\r\n* clear_site_settings (clear_site_settings) = Clear Site Settings\r\n\r\n* reload_pages (reload_pages) = Reload Pages\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\nclose_browsers","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeoutactions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeoutactions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeoutactions_idletimeoutactionsdesc","displayName":"Actions to run when the computer is idle (User)","description":"","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers (User)","description":"Allows you to set whether Microsoft Edge will run the v8 JavaScript engine with more advanced JavaScript optimizations enabled.\r\n\r\nDisabling JavaScript optimizations (by setting this policy's value to 2) will mean that Microsoft Edge may render web content more slowly.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'JavaScriptOptimizerAllowedForSites' (Allow JavaScript optimization on these sites) and 'JavaScriptOptimizerBlockedForSites' (Block JavaScript optimizations on these sites) policies.\r\n\r\nIf you don't configure this policy, JavaScript optimizations are enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowJavaScriptOptimizer (1) = Enable advanced JavaScript optimizations on all sites\r\n\r\n* BlockJavaScriptOptimizer (2) = Disable advanced JavaScript optimizations on all sites\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting_1","displayName":"Enable advanced JavaScript optimizations on all sites","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting_2","displayName":"Disable advanced JavaScript optimizations on all sites","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the 'JavaScriptOptimizerAllowedForSites' (Allow JavaScript optimization on these sites) policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations enabled, but fabrikam.com will use the policy from 'DefaultJavaScriptOptimizerSetting' (Control use of JavaScript optimizers), if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set, otherwise Javascript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites_javascriptoptimizerallowedforsitesdesc","displayName":"Allow JavaScript optimization on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are disabled.\r\n\r\nDisabling JavaScript optimizations will mean that Microsoft Edge may render web content more slowly.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the 'JavaScriptOptimizerBlockedForSites' (Block JavaScript optimizations on these sites) policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations disabled, but fabrikam.com will use the policy from 'DefaultJavaScriptOptimizerSetting' (Control use of JavaScript optimizers), if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set, otherwise JavaScript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_javascriptoptimizerblockedforsitesdesc","displayName":"Block JavaScript optimizations on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~printing_oopprintdriversallowed","displayName":"Out-of-process print drivers allowed (User)","description":"This policy determines whether Microsoft Edge handles interactions with printer drivers through a separate service process.\r\n\r\nUsing a service process for tasks like querying available printers, retrieving print driver settings, and submitting documents to local printers improves browser stability and prevents UI freezing during Print Preview.\r\n\r\nEnabled or Not Set: Microsoft Edge will use a separate service process for these printing tasks.\r\n\r\nDisabled: Microsoft Edge will perform these printing tasks within the browser process.\r\n\r\nNote: This policy will be deprecated in the future once the transition to out-of-process print drivers is fully implemented.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~printing_oopprintdriversallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~printing_oopprintdriversallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~scarewareblocker_scarewareblockerprotectionenabled","displayName":"Configure Edge Scareware Blocker Protection (User)","description":"This policy setting allows administrators to control whether Microsoft Edge enables the Scareware Blocker, an AI-powered feature that provides warning messages to help protect users from potential tech scams.\r\n\r\nIf this policy is enabled, Edge Scareware Blocker will warn users of potential tech scams.\r\n\r\nIf this policy is disabled, Edge Scareware Blocker will not warn users of potential tech scams.\r\n\r\nIf this policy is not configured, Edge Scareware Blocker will not warn users of potential tech scams, but users can choose warnings in settings.\r\n\r\nBy configuring this policy, administrators determine whether users receive proactive scam warnings or must manually enable them.","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~scarewareblocker_scarewareblockerprotectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~scarewareblocker_scarewareblockerprotectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_addressbartrendingsuggestenabled","displayName":"Enable Microsoft Bing trending suggestions in the address bar (User)","description":"This policy controls whether Microsoft Bing trending suggestions appear in the address bar’s suggestion dropdown when users click the address bar while on a New Tab Page.\r\n\r\nIf this policy is enabled or not configured, Microsoft Bing trending suggestions will appear in the address bar suggestion dropdown.\r\n\r\nIf this policy is disabled, Microsoft Edge will not display Microsoft Bing trending suggestions when users click the address bar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_addressbartrendingsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_addressbartrendingsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_webcontentfilteringblockedcategories","displayName":"Configure Web Content Filtering (User)","description":"You can configure this policy to block certain categories of URLs. Blocking a category prevents users in specified device groups from accessing URLs associated with the category.\r\n\r\nThe list of possible categories, their Category String, and their description are detailed at https://go.microsoft.com/fwlink/?linkid=2249965\r\n\r\nTo block a category, add the Category String of the category to the following List of blocked categories If you leave this policy unset or disable the policy, no URLs will be blocked.\r\n\r\nIf you want to block a specific URL without blocking an entire category, add the URL to the list of blocked URLs using the 'URLBlocklist' (Block access to a list of URLs) policy.\r\n\r\nIf you want a specific URL in a blocked category to be accessible, add the URL to the list of allowed URLs using the 'URLAllowlist' (Define a list of allowed URLs) policy.\r\n\r\nThis Web Content Filtering policy only works on Microsoft Edge on Windows 10 devices or above.\r\n\r\nPolicy options mapping:\r\n\r\n* chat (chat) = Chat\r\n\r\n* child_abuse_images (child_abuse_images) = Child Abuse Images\r\n\r\n* criminal_activity (criminal_activity) = Criminal Activity\r\n\r\n* download_sites (download_sites) = Download Sites\r\n\r\n* gambling (gambling) = Gambling\r\n\r\n* games (games) = Games\r\n\r\n* hacking (hacking) = Hacking\r\n\r\n* hate_and_intolerance (hate_and_intolerance) = Hate and Intolerance\r\n\r\n* illegal_drug (illegal_drug) = Illegal Drug\r\n\r\n* illegal_software (illegal_software) = Illegal Software\r\n\r\n* image_sharing (image_sharing) = Image Sharing\r\n\r\n* instant_messaging (instant_messaging) = Instant Messaging\r\n\r\n* nudity (nudity) = Nudity\r\n\r\n* peer_to_peer (peer_to_peer) = Peer to Peer\r\n\r\n* pornography_or_sexually_explicit (pornography_or_sexually_explicit) = Pornography or Sexually Explicit\r\n\r\n* professional_networking (professional_networking) = Professional Networking\r\n\r\n* self_harm (self_harm) = Self Harm\r\n\r\n* sex_education (sex_education) = Sex Education\r\n\r\n* social_networking (social_networking) = Social Networking\r\n\r\n* streaming_and_downloads (streaming_and_downloads) = Streaming Media and Downloads\r\n\r\n* tasteless (tasteless) = Tasteless\r\n\r\n* violence (violence) = Violence\r\n\r\n* weapons (weapons) = Weapons\r\n\r\n* web_based_email (web_based_email) = Web Based Email\r\n\r\n* none (none) = None\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\ngambling\r\nstreaming_and_downloads\r\ngames","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_webcontentfilteringblockedcategories_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_webcontentfilteringblockedcategories_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_webcontentfilteringblockedcategories_webcontentfilteringblockedcategoriesdesc","displayName":"List of blocked categories (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~contentsettings_partitionedbloburlusage","displayName":"Manage Blob URL Partitioning During Fetching and Navigation (User)","description":"This policy controls whether Blob URLs are partitioned during fetching and navigation.\r\nIf this policy is set to Enabled or not set, Blob URLs will be partitioned.\r\nIf this policy is set to Disabled, Blob URLs won't be partitioned. This is the Blob URL behavior prior to\r\nMicrosoft Edge version 135.\r\n\r\nIf storage partitioning is disabled for a given top-level origin by either\r\nThirdPartyStoragePartitioningBlockedForOrigins\r\nor DefaultThirdPartyStoragePartitioningSetting,\r\nthen Blob URLs will also not be partitioned.\r\n\r\nThe policy is scheduled to be available through Microsoft Edge version 140. After this\r\nversion, the policy will be removed, and Microsoft Edge will no longer support unpartitioned\r\nblob storage.\r\n\r\nFor detailed information on third-party storage partitioning, please see https://github.com/privacycg/storage-partitioning.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~contentsettings_partitionedbloburlusage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~contentsettings_partitionedbloburlusage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor","displayName":"Set the company logo backplate color on the new tab page. (User)","description":"By default, the new tab page sets the company logo backplate color to the neutralStrokeActive (#cecece) constant.\r\n\r\nYou can configure this policy with a color hex code to change the company logo backplate color on the new tab page.\r\n\r\nIf this policy is not configured, the default neutralStrokeActive (#cecece) color will be used as the backplate color.\r\n\r\nExample value: #cecece","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor_newtabpagecompanylogobackplatecolor","displayName":"Set the company logo backplate color on the new tab page. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~webrtc_webrtciphandlingurl","displayName":"WebRTC IP Handling Policy for URL Patterns (User)","description":"Controls which IP addresses and network interfaces WebRTC can use\r\nwhen establishing connections for specific URL patterns.\r\n\r\nHow It Works:\r\nAccepts a list of URL patterns, each paired with a handling type.\r\nWebRTC evaluates patterns sequentially; the first match determines the handling type.\r\nIf no match is found, WebRTC defaults to the WebRtcLocalhostIpHandling WebRtcLocalhostIpHandling. policy.\r\nThis policy applies only to origins—URL path components are ignored.\r\nWildcards (*) are supported in URL patterns.\r\n\r\nSupported Handling Values:\r\ndefault – Uses all available network interfaces.\r\ndefault_public_and_private_interfaces – WebRTC uses all public and private interfaces.\r\ndefault_public_interface_only – WebRTC uses only public interfaces.\r\ndisable_non_proxied_udp – WebRTC uses UDP SOCKS proxying or falls back to TCP proxying.\r\n\r\nMore Information:\r\nValid input patterns: https://go.microsoft.com/fwlink/?linkid=2095322\r\nHandling types: https://tools.ietf.org/html/rfc8828.html#section-5.2\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.example.com\",\r\n \"handling\": \"default_public_and_private_interfaces\"\r\n },\r\n {\r\n \"url\": \"https://[*.]example.edu\",\r\n \"handling\": \"default_public_interface_only\"\r\n },\r\n {\r\n \"url\": \"*\",\r\n \"handling\": \"disable_non_proxied_udp\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~webrtc_webrtciphandlingurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~webrtc_webrtciphandlingurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~webrtc_webrtciphandlingurl_webrtciphandlingurl","displayName":"WebRTC IP Handling Policy for URL Patterns (User)","description":"","helpText":"","infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge_httpsupgradesenabled","displayName":"Enable automatic HTTPS upgrades (User)","description":"As of Microsoft Edge version 120, Microsoft Edge tries to upgrade HTTP navigations to HTTPS whenever possible to improve security. Navigations to captive portals, IP addresses, and non-unique hostnames are excluded from automatic upgrades.\r\n\r\nIf this policy is enabled or not configured, automatic HTTPS upgrades are turned on by default.\r\n\r\nIf this policy is disabled, Microsoft Edge won't attempt to upgrade HTTP connections to HTTPS.\r\n\r\nTo exempt specific hostnames or hostname patterns from being upgraded, use the HttpAllowlist policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge_httpsupgradesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge_httpsupgradesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~passwordmanager_passwordexportenabled","displayName":"Enable exporting saved passwords from Password Manager (User)","description":"This policy controls whether the Export Password button in edge://wallet/passwords is enabled.\r\n\r\nIf enabled or not configured, users can export saved passwords.\r\nIf disabled, the Export Password button is unavailable, preventing password exports.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~passwordmanager_passwordexportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~passwordmanager_passwordexportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~profile_profiletypeinprofilebuttonenabled","displayName":"Controls the display of the profile button label for the work or school profile (User)","description":"Controls whether the label for the work or school profile type is shown in the profile button.\r\n\r\nThis policy does not apply when the OrganizationalBrandingOnWorkProfileUIEnabled policy is enabled.\r\n\r\nIf you enable this policy, the label for the work or school profile type appears in the profile button.\r\n\r\nIf you disable this policy or leave it not configured, the label is not shown.","helpText":"","infoUrls":[],"categoryId":"1043e7ed-8651-44b2-b918-7230c0b75a6c","categoryName":"Profile settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~profile_profiletypeinprofilebuttonenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~profile_profiletypeinprofilebuttonenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onbulkdataentryenterpriseconnector","displayName":"Configuration policy for bulk data entry for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when data is entered in Microsoft Edge from the clipboard or by drag and dropping web content.\r\n\r\nConnector Fields\r\n\r\n1. url_list,\r\ntags,\r\nenable,\r\ndisable\r\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\r\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\r\nAnalysis is triggered if at least one tag is included in the request.\r\n\r\n2. service_provider\r\nIdentifies the analysis service provider the configuration applies to.\r\n\r\n3. block_until_verdict\r\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\r\nAny other integer value allows the page to access the data immediately.\r\n\r\n4. default_action\r\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\r\nAny other value permits the page to access the data.\r\n\r\n5. minimum_data_size\r\nSpecifies the minimum size (in bytes) that the entered data must meet or exceed to be scanned.\r\nDefault: 100 bytes if the field is not set.\r\n\r\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"block_until_verdict\": 0,\r\n \"default_action\": \"allow\",\r\n \"disable\": [\r\n {\r\n \"tags\": [\r\n \"malware\"\r\n ],\r\n \"url_list\": [\r\n \"*.us.com\"\r\n ]\r\n }\r\n ],\r\n \"enable\": [\r\n {\r\n \"tags\": [\r\n \"malware\"\r\n ],\r\n \"url_list\": [\r\n \"*\"\r\n ]\r\n },\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.them.com\",\r\n \"*.others.com\"\r\n ]\r\n }\r\n ],\r\n \"minimum_data_size\": 100,\r\n \"service_provider\": \"local_system_agent\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onbulkdataentryenterpriseconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onbulkdataentryenterpriseconnector_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onbulkdataentryenterpriseconnector_onbulkdataentryenterpriseconnector","displayName":"Configuration policy for bulk data entry for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector","displayName":"Configuration policy for files attached for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when a file is attached to Microsoft Edge.\r\n\r\nConnector Fields\r\n\r\n1. url_list,\r\ntags,\r\nenable,\r\ndisable\r\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\r\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\r\nAnalysis is triggered if at least one tag is included in the request.\r\n\r\n2. service_provider\r\nIdentifies the analysis service provider the configuration applies to.\r\n\r\n3. block_until_verdict\r\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\r\nAny other integer value allows the page to access the data immediately.\r\n\r\n4. default_action\r\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\r\nAny other value permits the page to access the data.\r\n\r\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"block_until_verdict\": 0,\r\n \"default_action\": \"allow\",\r\n \"disable\": [\r\n {\r\n \"tags\": [\r\n \"malware\"\r\n ],\r\n \"url_list\": [\r\n \"*.us.com\"\r\n ]\r\n }\r\n ],\r\n \"enable\": [\r\n {\r\n \"tags\": [\r\n \"malware\"\r\n ],\r\n \"url_list\": [\r\n \"*\"\r\n ]\r\n },\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.them.com\",\r\n \"*.others.com\"\r\n ]\r\n }\r\n ],\r\n \"service_provider\": \"local_system_agent\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector_onfileattachedenterpriseconnector","displayName":"Configuration policy for files attached for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector","displayName":"Configuration policy for print for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when a page or file is printed from Microsoft Edge.\r\n\r\nConnector Fields\r\n\r\n1. url_list,\r\ntags,\r\nenable,\r\ndisable\r\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\r\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\r\nAnalysis is triggered if at least one tag is included in the request.\r\n\r\n2. service_provider\r\nIdentifies the analysis service provider the configuration applies to.\r\n\r\n3. block_until_verdict\r\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\r\nAny other integer value allows the page to access the data immediately.\r\n\r\n4. default_action\r\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\r\nAny other value permits the page to access the data.\r\n\r\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"block_until_verdict\": 0,\r\n \"default_action\": \"allow\",\r\n \"disable\": [\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.us.com\"\r\n ]\r\n }\r\n ],\r\n \"enable\": [\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.them.com\",\r\n \"*.others.com\"\r\n ]\r\n }\r\n ],\r\n \"service_provider\": \"local_system_agent\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector_onprintenterpriseconnector","displayName":"Configuration policy for print for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_webauthenticationremotedesktopallowedorigins","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications. (User)","description":"This policy defines a list of allowed HTTPS origins for remote desktop client applications that initiate WebAuthn API requests from a browsing session on a remote host.\r\n\r\nOrigins specified in this policy can request WebAuthn authentication for Relying Party IDs (RP IDs) they would not typically be authorized to claim.\r\n\r\nOnly HTTPS origins are supported. Wildcards are not permitted. Entries that do not\r\nmeet these requirements will be ignored.\r\n\r\nFor more information about the WebAuthn Remote Desktop Support feature, please see https://github.com/w3c/webauthn/wiki/Explainer:-Remote-Desktop-Support/a4e158c569f456c759d0ddd294a9015bd4d4eb9a.\r\n\r\nExample value:\r\n\r\nhttps://server:8080/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_webauthenticationremotedesktopallowedorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_webauthenticationremotedesktopallowedorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_webauthenticationremotedesktopallowedorigins_webauthenticationremotedesktopallowedoriginsdesc","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge~network_happyeyeballsv3enabled","displayName":"Use the Happy Eyeballs V3 algorithm for connection attempts (User)","description":"Controls whether Microsoft Edge uses the Happy Eyeballs V3 algorithm to optimize connection attempts. This algorithm improves reliability and performance in dual-stack (IPv4/IPv6) networks by racing connection attempts across IP versions and HTTP protocols (e.g., HTTP/3 vs. others). For more details, see https://datatracker.ietf.org/doc/draft-pauly-happy-happyeyeballs-v3.\r\n\r\nEnabled or not configured: Uses the algorithm for connection attempts.\r\n\r\nDisabled: Disables the algorithm.\r\n\r\nNote: This policy supports dynamic refresh.\r\n\r\nImportant: This policy is temporary and will be removed in a future version.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge~network_happyeyeballsv3enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge~network_happyeyeballsv3enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_builtinaiapisenabled","displayName":"Allow pages to use the built-in AI APIs. (User)","description":"Use this policy to control whether websites can access the built-in AI APIs, including the LanguageModel API, Summarization API, Writer API, and Rewriter API.\r\n\r\nEnable this policy to allow pages to use the APIs. If you don’t configure this policy, the APIs are still allowed.\r\n\r\nDisable this policy to block access to the APIs. The APIs will return an error when used.\r\n\r\nFor more information, see https://github.com/webmachinelearning/writing-assistance-apis/blob/main/README.md.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_builtinaiapisenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_builtinaiapisenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_edgehistoryaisearchenabled","displayName":"Control access to AI-enhanced search in History (User)","description":"This policy controls whether users can use AI-enhanced search in their browsing history in Microsoft Edge.\r\n\r\nWhen enabled or not configured, users can search using synonyms, natural language phrases, and minor spelling errors to find previously visited pages.\r\n\r\nWhen disabled, users can only perform exact match (verbatim) searches in their history.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_edgehistoryaisearchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_edgehistoryaisearchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_prefetchwithserviceworkerenabled","displayName":"Allow SpeculationRules prefetch for ServiceWorker-controlled URLs (User)","description":"Controls whether SpeculationRules prefetch requests are allowed for\r\nServiceWorker-controlled URLs.\r\n\r\nStarting with Microsoft Edge version 138,\r\nprefetch requests to ServiceWorker-controlled URLs are allowed by default when\r\nthe PrefetchServiceWorker feature is enabled.\r\n\r\nIf this policy is enabled or not configured, that default behavior is used.\r\n\r\nTo restore the legacy behavior from versions prior to 138, where prefetch requests\r\nto ServiceWorker-controlled URLs were blocked, set this policy to disabled.\r\n\r\nThis policy is intended to be temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_prefetchwithserviceworkerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_prefetchwithserviceworkerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_recommended~identity_recommended_edgeopenexternallinkswithprimaryworkprofileenabled_recommended","displayName":"Use Primary Work Profile as default to open external links (User)","description":"This policy controls whether Microsoft Edge uses the Primary Work Profile as the default profile when opening external links.\r\n1. On Windows, the Primary Work Profile refers to the profile signed in with the Entra ID account used to enroll the device.\r\n2. On macOS and Linux, the Primary Work Profile is the only profile signed in with an Entra ID account. If multiple profiles are signed in with Entra ID accounts, the Primary Work Profile setting does not apply.\r\n\r\nPolicy behavior:\r\n1. If enabled or not configured, Microsoft Edge will use the Primary Work Profile as the default for opening external links.\r\n2. If disabled, the last used profile becomes the default for opening external links.\r\n\r\nNote: This policy does not override the following scenarios:\r\n1. If the EdgeDefaultProfileEnabled policy is set, it takes precedence over this policy.\r\n2. External links opened from Outlook or Microsoft Teams may be configured to launch in a specific profile, which can override the Primary Work Profile setting.\r\n3. If the user sets a preference for \"Default profile for external links\" in Profile preferences, that setting will take effect.","helpText":"","infoUrls":[],"categoryId":"04b46099-4ee5-4def-8e04-569c988057a9","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_recommended~identity_recommended_edgeopenexternallinkswithprimaryworkprofileenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_recommended~identity_recommended_edgeopenexternallinkswithprimaryworkprofileenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_tls13earlydataenabled","displayName":"Control whether TLS 1.3 Early Data is enabled in Microsoft Edge (User)","description":"This policy controls whether TLS 1.3 Early Data is enabled in Microsoft Edge.\r\n\r\nTLS 1.3 Early Data is an extension that allows an HTTP request to be sent in parallel with the TLS handshake. When enabled and supported by the server, this can improve page load performance.\r\n\r\nEnabled – Microsoft Edge enables TLS 1.3 Early Data.\r\n\r\nDisabled – Microsoft Edge disables TLS 1.3 Early Data.\r\n\r\nNot configured – Microsoft Edge follows the default rollout process for TLS 1.3 Early Data.\r\n\r\nNOTE: When this feature is enabled, whether TLS 1.3 Early Data is used depends on server support. Most modern TLS servers and middleware can handle or reject Early Data without interrupting the connection. However, improperly implemented TLS stacks may cause connection failures. If such issues occur, contact the device or software vendor for a resolution.\r\n\r\nThis policy is temporary and intended to help test for compatibility issues. It may be removed in a future release once the feature is fully rolled out.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_tls13earlydataenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_tls13earlydataenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to block requests from public websites to devices on a user's local network. (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nLocal Network Access restrictions prevent public websites from making\r\nrequests to devices on a user's local network without explicit user permission.\r\n\r\nIf you enable this policy, Microsoft Edge will\r\nblock any request that would otherwise trigger a DevTools warning\r\ndue to Local Network Access checks.\r\nThese requests will be denied without prompting the user.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will handle\r\nthese requests using the default behavior, which may include showing warnings in DevTools\r\nand allowing the request to proceed depending on the context.\r\n\r\nNote: This feature improves local network security by deprecating direct access to private IP addresses from public websites\r\nunless explicitly granted by the user.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_enableunsafeswiftshader","displayName":"Allow software WebGL fallback using SwiftShader (User)","description":"Controls whether SwiftShader is used as a fallback for WebGL when hardware GPU acceleration is not available.\r\n\r\nWhen enabled, Microsoft Edge will use SwiftShader to support WebGL on systems without GPU acceleration, such as headless environments or virtual machines.\r\n\r\nStarting in Microsoft Edge version 139, SwiftShader has been deprecated due to security concerns. As a result, WebGL context creation will fail in scenarios where SwiftShader would have been used. Enabling this policy allows organizations to temporarily defer the deprecation and continue using SwiftShader.\r\n\r\nIf you disable or do not configure this policy, WebGL context creation may fail on systems without hardware acceleration. This could cause web content relying on WebGL to function incorrectly if it does not handle context creation failures.\r\n\r\nNote: This is a temporary policy and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_enableunsafeswiftshader_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_enableunsafeswiftshader_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_microsoft365copilotchaticonenabled","displayName":"Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar (User)","description":"For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon will be shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users.\r\n\r\nThis policy only applies when users are accessing Copilot in the sidepane.\r\n\r\nIf the policy is enabled: Copilot will appear in the toolbar.\r\n\r\nIf the policy is disabled: Copilot will not appear in the toolbar.\r\n\r\nIf the policy is not configured: Otherwise, Copilot will show in the toolbar and users may enable or disable Copilot from showing by using the Show Copilot toggle in settings.\r\n\r\nWhen both this policy and 'HubsSidebarEnabled' (Show Hubs Sidebar) are configured, this policy takes precedence in determining whether Copilot appears in the toolbar. If this policy is not configured and 'HubsSidebarEnabled' is disabled, Copilot will remain hidden. In a future release, this policy will be the sole control for managing Copilot's visibility in the toolbar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_microsoft365copilotchaticonenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_microsoft365copilotchaticonenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_onsecurityevententerpriseconnector","displayName":"Configuration policy for Microsoft Edge for Business Reporting Connectors (User)","description":"Defines the Microsoft Edge for Business Reporting Connectors service settings that apply when a security event occurs in Microsoft Edge. These events include negative verdicts from Data Loss Prevention Connectors, password reuse, navigation to unsafe pages, and other security-sensitive actions.\r\n\r\nThe service_provider field specifies the reporting service provider. The enabled_event_names field lists the security events enabled for that provider.\r\n\r\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2325446.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"enabled_event_names\": [\r\n \"passwordChangedEvent\",\r\n \"sensitiveDataEvent\"\r\n ],\r\n \"enabled_opt_in_events\": [\r\n {\r\n \"name\": \"loginEvent\",\r\n \"url_patterns\": [\r\n \"*\"\r\n ]\r\n },\r\n {\r\n \"name\": \"passwordBreachEvent\",\r\n \"url_patterns\": [\r\n \"example.com\",\r\n \"other.example.com\"\r\n ]\r\n }\r\n ],\r\n \"service_provider\": \"microsoft\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_onsecurityevententerpriseconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_onsecurityevententerpriseconnector_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_onsecurityevententerpriseconnector_onsecurityevententerpriseconnector","displayName":"Configuration policy for Microsoft Edge for Business Reporting Connectors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_recommended_microsoft365copilotchaticonenabled_recommended","displayName":"Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar (User)","description":"For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon will be shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users.\r\n\r\nThis policy only applies when users are accessing Copilot in the sidepane.\r\n\r\nIf the policy is enabled: Copilot will appear in the toolbar.\r\n\r\nIf the policy is disabled: Copilot will not appear in the toolbar.\r\n\r\nIf the policy is not configured: Otherwise, Copilot will show in the toolbar and users may enable or disable Copilot from showing by using the Show Copilot toggle in settings.\r\n\r\nWhen both this policy and 'HubsSidebarEnabled' (Show Hubs Sidebar) are configured, this policy takes precedence in determining whether Copilot appears in the toolbar. If this policy is not configured and 'HubsSidebarEnabled' is disabled, Copilot will remain hidden. In a future release, this policy will be the sole control for managing Copilot's visibility in the toolbar.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_recommended_microsoft365copilotchaticonenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_recommended_microsoft365copilotchaticonenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~extensions_mandatoryextensionsforinprivatenavigation","displayName":"Specify extensions users must allow in order to navigate using InPrivate mode (User)","description":"This policy lets you specify a list of extension IDs that must be explicitly allowed by the user to run in InPrivate mode in order to enable InPrivate browsing.\r\n\r\nIf users do not allow all listed extensions to run in InPrivate mode, they will be unable to navigate using InPrivate.\r\n\r\nIf any extension in the list is not installed, InPrivate navigation is blocked.\r\n\r\nThis policy only applies when InPrivate mode is enabled. If InPrivate mode is disabled using the InPrivateModeAvailability policy, this policy has no effect.\r\n\r\nExample value:\r\n\r\nabcdefghijklmnopabcdefghijklmnop","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~extensions_mandatoryextensionsforinprivatenavigation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~extensions_mandatoryextensionsforinprivatenavigation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~extensions_mandatoryextensionsforinprivatenavigation_mandatoryextensionsforinprivatenavigationdesc","displayName":"Specify extensions users must allow in order to navigate using InPrivate mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~identity_edgeopenexternallinkswithappspecifiedprofile","displayName":"Prioritize App specified profile to open external links (User)","description":"This policy controls whether the profile specified by an app (such as Microsoft Teams or Outlook) is given priority when opening external links, instead of the profile selected in the Default profile for external links setting.\r\n\r\nPolicy behavior:\r\n1. Enabled or not configured: The app-specified profile is prioritized for opening external links. This behavior overrides the profile selected in settings, and the behavior defined by the EdgeDefaultProfileEnabled and EdgeOpenExternalLinksWithPrimaryWorkProfileEnabled policies. If the app doesn't specify a profile, this policy has no effect.\r\n2. Disabled: The profile selected in settings—along with the EdgeDefaultProfileEnabled and EdgeOpenExternalLinksWithPrimaryWorkProfileEnabled policies—will be used to determine which profile opens external links.\r\n\r\nNOTE:\r\nThis policy doesn't override user-defined preferences set through Automatic profile switching, including the Custom site switch setting located within it. If a user has configured specific sites to open in designated profiles, those preferences take precedence.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~identity_edgeopenexternallinkswithappspecifiedprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge~identity_edgeopenexternallinkswithappspecifiedprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_additionaldnsquerytypesenabled","displayName":"Allow DNS queries for more DNS record types (User)","description":"This policy controls whether Microsoft Edge can query more DNS record types when making insecure (non-Secure DNS) requests.\r\n\r\nIf this policy is unset or set to Enabled, more record types such as HTTPS (DNS type 65) may be queried in addition to A (DNS type 1) and AAAA (DNS type 28).\r\n\r\nIf this policy is set to Disabled, Microsoft Edge will only query A and AAAA record types for insecure DNS requests.\r\n\r\nThis setting doesn't affect DNS queries made via Secure DNS, which may always use more record types.\r\n\r\nNote: This is a temporary policy and is planned for removal in a future version of Microsoft Edge. After removal, Microsoft Edge will always be able to query more DNS types during insecure requests.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_additionaldnsquerytypesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_additionaldnsquerytypesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled (User)","description":"This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigations to HTTPS.\r\n\r\nIf this setting is not set or is set to allowed, users will be able to enable HTTPS-Only Mode.\r\nIf this setting is set to disallowed, users will not be able to enable HTTPS-Only Mode.\r\nIf this setting is set to force_enabled, HTTPS-Only Mode will be enabled in Strict mode and users will not be able to disable it.\r\nIf this setting is set to force_balanced_enabled, HTTPS-Only Mode will be enabled in Balanced mode and users will not be able to disable it.\r\n\r\nIf you set this policy to a value that is not supported by the version of Microsoft Edge that receives the policy, Microsoft Edge will default to the allowed setting.\r\n\r\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\r\n\r\nPolicy options mapping:\r\n\r\n* allowed (allowed) = Do not restrict users' HTTPS-Only Mode setting\r\n\r\n* disallowed (disallowed) = Do not allow users to enable any HTTPS-Only Mode\r\n\r\n* force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode\r\n\r\n* force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: disallowed","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_allowed","displayName":"Do not restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_disallowed","displayName":"Do not allow users to enable any HTTPS-Only Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_force_enabled","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_force_balanced_enabled","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_restrictcoresharingonrenderer","displayName":"Restrict CPU core sharing for renderer process (User)","description":"This policy helps mitigate side-channel cross-process memory attacks by isolating the renderer process to a dedicated CPU core, preventing other processes from being scheduled on the same core. This mitigation is supported on Microsoft® Windows® 11 24H2 and later. If the operating system does not support the necessary scheduling features, this policy has no effect. Enabling this policy may reduce performance in demanding workloads, similar to the impact of disabling hyperthreading. For more information refer https://learn.microsoft.com/windows/win32/api/winnt/ns-winnt-process_mitigation_side_channel_isolation_policy\r\nIf you enable this policy, other processes can not be scheduled on the same CPU core as a renderer process.\r\nIf you disable this policy, other processes can be scheduled on the same CPU core as a renderer process.\r\nIf you don't configure this policy, other processes may be scheduled on the same core as the renderer process. Behavior may vary depending on Microsoft Edge version and platform.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_restrictcoresharingonrenderer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_restrictcoresharingonrenderer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup (User)","description":"This policy controls whether Microsoft Edge enables the ServiceWorkerAutoPreload feature.\r\n\r\nWhen enabled or not configured, Microsoft Edge may initiate the main resource network request concurrently with the Service Worker bootstrap process. This can improve performance in scenarios where the Service Worker is not already running.\r\n\r\nIf you disable this policy, Microsoft Edge will wait to dispatch the navigation request until after the Service Worker has started.\r\n\r\nThis is a temporary policy and will be removed in version 144 of Microsoft Edge.\r\n\r\nFor more details on the feature, see https://github.com/WICG/service-worker-auto-preload.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_serviceworkerautopreloadenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_serviceworkerautopreloadenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls","displayName":"Allow sites to make requests to local network endpoints. (User)","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions.\r\n\r\nIf an origin is specified by both this policy and the 'LocalNetworkAccessBlockedForUrls' (Block sites from making requests to local network endpoints.) policy, the blocked list takes precedence.\r\n\r\nFor origins not covered by this policy, the user's personal settings and local network access restrictions will apply.\r\n\r\nFor guidance on valid URL pattern syntax, see:\r\nhttps://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns\r\n\r\nNote: This policy enables controlled exceptions to local network access restrictions. It allows specific public websites to access private IP addresses when necessary for trusted local communication scenarios. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls_localnetworkaccessallowedforurlsdesc","displayName":"Allow sites to make requests to local network endpoints. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls","displayName":"Block sites from making requests to local network endpoints. (User)","description":"List of URL patterns. Requests initiated from websites served by matching origins are blocked from issuing Local Network Access requests.\r\n\r\nIf an origin is covered by both this policy and by 'LocalNetworkAccessAllowedForUrls' (Allow sites to make requests to local network endpoints.), this policy takes precedence.\r\n\r\nDepending on the stage of the rollout of Local Network Access, LocalNetworkAccessRestrictionsEnabled may also need to be enabled for this policy to block Local Network Access requests.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\r\n\r\nNote: This policy improves local network security by blocking specified public websites from accessing private IP addresses. It helps prevent unauthorized external sites from reaching internal resources unless explicitly permitted. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls_localnetworkaccessblockedforurlsdesc","displayName":"Block sites from making requests to local network endpoints. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled","displayName":"Allows users to translate videos to different languages. (User)","description":"This policy configures the on-device real-time video translation feature in Microsoft Edge.\r\nWith this feature, users can watch videos translated into their selected language in real time.\r\n\r\nWhen a user selects the Translate icon and chooses a source (video language) and target language (translated language),\r\ntranslation components are downloaded on first use (approximately 200 MB per language pair).\r\n\r\nThese components may be updated periodically to improve performance and translation quality.\r\nTranslation is performed locally on the user’s device and no data is sent outside of the device.\r\nThe feature is available only for non-DRM videos, on supported high-end devices, with select language pairs, and in select regions.\r\nFor more details, see https://www.microsoft.com/en-us/edge/features/real-time-video-translation.\r\n\r\nIf you enable or don’t configure this policy, the on-device real-time video translation feature is enabled and\r\nusers will see the Translate button when hovering over videos.\r\n\r\nIf you disable this policy, the on-device real-time video translation feature is disabled and the Translate button won’t be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_originkeyedprocessesenabled_recommended","displayName":"Enable origin-keyed process isolation for improved security (User)","description":"This policy enables origin-keyed process isolation for most pages, which improves security by separating content from different origins into distinct processes. This may increase the number of processes created. Users can override this setting by using command-line flags or edge://flags to turn the feature on or off.\r\n\r\nIf you enable this policy, most origins will be isolated, even from other origins within the same site. For related configuration, see the IsolateOrigins and SitePerProcess policies.\r\n\r\nIf you disable this policy, origins will not be isolated from the rest of their site unless the origin explicitly requests isolation.\r\n\r\nIf you don’t configure this policy, the browser will decide which origins to isolate and when. By default, this feature is disabled. The default state may change in the future.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_originkeyedprocessesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_originkeyedprocessesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_showtabpreviewenabled_recommended","displayName":"Enable tab preview on hover (User)","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\r\n\r\nIf you disable this policy, tab previews will not be shown on hover.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_showtabpreviewenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_showtabpreviewenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_relaunchfastifoutdated","displayName":"Relaunch browser quickly when the current version is outdated (User)","description":"This policy specifies the minimum release age after which relaunch notifications become more aggressive. The release age is calculated from the time the currently running version was last served to clients.\r\n\r\nIf a browser relaunch is needed to finalize a pending update and the current version has been outdated for more than the number of days specified by this setting, the RelaunchNotificationPeriod policy is overridden to 2 hours. If the RelaunchNotification policy is set to 1 ('Required'), a browser relaunch will be forced at the end of the period.\r\n\r\nIf not set, or if the release age cannot be determined, the RelaunchNotificationPeriod policy will be used for all updates.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_relaunchfastifoutdated_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_relaunchfastifoutdated_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_relaunchfastifoutdated_relaunchfastifoutdated","displayName":"Time period (days): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_showtabpreviewenabled","displayName":"Enable tab preview on hover (User)","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\r\n\r\nIf you disable this policy, tab previews will not be shown on hover.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_showtabpreviewenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_showtabpreviewenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge~webrtc_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC (User)","description":"This policy controls the use of post-quantum key agreement for WebRTC in Microsoft Edge.\r\n\r\nIf you enable this policy, Microsoft Edge will offer post-quantum key agreement for WebRTC.\r\n\r\nIf you disable this policy, post-quantum key agreement will not be offered for WebRTC.\r\n\r\nIf you don't configure this policy, post-quantum key agreement will not be offered for WebRTC. A future version of Microsoft Edge may enable this feature by default.\r\n\r\nOffering a post-quantum key agreement is backwards compatible. Existing datagram transport layer security (DTLS) peers and networking middleware are expected to ignore the new option and continue using previous options.\r\n\r\nHowever, devices that don't correctly implement DTLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or larger message sizes. Such devices aren’t post-quantum-ready and may interfere with an organization's post-quantum transition. If this issue occurs, administrators should contact the device vendor for a fix.\r\n\r\nThis policy is temporary and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge~webrtc_webrtcpostquantumkeyagreement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge~webrtc_webrtcpostquantumkeyagreement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerblocksdetectedsitesenabled_recommended","displayName":"Configure Edge scareware blocker to block sites detected as potential tech scams (User)","description":"This policy controls whether Microsoft Edge blocks sites that are detected as potential tech scams.\r\n\r\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will block sites detected as potential tech scams.\r\n\r\nIf you disable this policy, Microsoft Edge will not block sites detected as potential tech scams.","helpText":"","infoUrls":[],"categoryId":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerblocksdetectedsitesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerblocksdetectedsitesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockersenddetectedsitestosmartscreenenabled_recommended","displayName":"Configure Edge scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen (User)","description":"This policy controls whether Microsoft Edge shares URLs of sites that are detected as potential tech scams with Microsoft Defender SmartScreen.\r\n\r\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\r\n\r\nIf you enable this policy, Microsoft Edge will share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.","helpText":"","infoUrls":[],"categoryId":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockersenddetectedsitestosmartscreenenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockersenddetectedsitestosmartscreenenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerallowlistdomains","displayName":"Configure the list of domains where Microsoft Edge scareware blocker won't run (User)","description":"This policy configures the list of trusted domains for Microsoft Edge scareware blocker. When a website's source URL matches any domain in this list, Edge scareware blocker won’t analyze that site.\r\n\r\nThis policy takes effect only if the ScarewareBlockerProtectionEnabled policy is enabled.\r\n\r\nIf you enable this policy, Microsoft Edge scareware blocker will trust the specified domains.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge scareware blocker will analyze all sites.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerallowlistdomains_scarewareblockerallowlistdomainsdesc","displayName":"Configure the list of domains where Microsoft Edge scareware blocker won't run (User)","description":"","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerblocksdetectedsitesenabled","displayName":"Configure Edge scareware blocker to block sites detected as potential tech scams (User)","description":"This policy controls whether Microsoft Edge blocks sites that are detected as potential tech scams.\r\n\r\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will block sites detected as potential tech scams.\r\n\r\nIf you disable this policy, Microsoft Edge will not block sites detected as potential tech scams.","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerblocksdetectedsitesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerblocksdetectedsitesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockersenddetectedsitestosmartscreenenabled","displayName":"Configure Edge scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen (User)","description":"This policy controls whether Microsoft Edge shares URLs of sites that are detected as potential tech scams with Microsoft Defender SmartScreen.\r\n\r\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\r\n\r\nIf you enable this policy, Microsoft Edge will share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockersenddetectedsitestosmartscreenenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockersenddetectedsitestosmartscreenenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge_sharebrowsinghistorywithcopilotsearchallowed","displayName":"Allow sharing tenant-approved browsing history with Microsoft 365 Copilot Search (User)","description":"This policy controls whether browsing history in Microsoft Edge is shared with Microsoft 365 Copilot Search to provide more relevant search results. Only tenant-approved, work-related sites are shared.\r\n\r\nThis feature is available only to users who are signed in to Microsoft Edge with an Entra ID account and have an eligible Microsoft 365 Copilot license.\r\n\r\nIf you enable or don't configure this policy, browsing history will be shared with Microsoft 365 Copilot Search by default, and users can turn off sharing using the toggle in Microsoft Edge settings.\r\n\r\nIf you disable this policy, browsing history won't be shared with Microsoft 365 Copilot Search.\r\n\r\nLearn more about how Copilot uses data and consent at https://go.microsoft.com/fwlink/?linkid=2333202","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge_sharebrowsinghistorywithcopilotsearchallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge_sharebrowsinghistorywithcopilotsearchallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge~network_localnetworkaccessrestrictionstemporaryoptout","displayName":"Specifies whether to opt out of Local Network Access restrictions (User)","description":"This policy allows for opting out of restrictions on requests to local network endpoints.\r\n\r\nIf you enable this policy, Local Network Access requests will only display warnings in Edge DevTools when Local Network Access checks fail.\r\n\r\nIf you disable or don't configure this policy, Local Network Access requests will follow the default handling behavior.\r\n\r\nFor more information about Local Network Access restrictions, see Local Network Access .\r\n\r\nThis enterprise policy is temporary and will be removed after Microsoft Edge version 146.\r\n\r\nTo allow specific URL patterns that should automatically be granted Local Network Access permission, use the LocalNetworkAccessAllowedForUrls policy.\r\n\r\nNote: If the LocalNetworkAccessRestrictionsEnabled policy is enabled, it takes precedence over this policy.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge~network_localnetworkaccessrestrictionstemporaryoptout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge~network_localnetworkaccessrestrictionstemporaryoptout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge~performance_ramresourcecontrolsenabled","displayName":"Enable RAM (memory) resource controls (User)","description":"This policy controls whether users can access the RAM (memory) resource control feature. This feature lets users set an individual limit on how much RAM (memory) the browser can use.\r\n\r\nTo set a specific memory limit, use the 'TotalMemoryLimitMb' (Set limit on megabytes of memory a single Microsoft Edge instance can use) policy.\r\n\r\nIf you enable or don't configure this policy, users can enable resource control and set the amount of RAM that Microsoft Edge can use. Browser performance may be affected by low limits.\r\n\r\nIf you disable this policy, users can't use resource control.","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge~performance_ramresourcecontrolsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev143~policy~microsoft_edge~performance_ramresourcecontrolsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled","displayName":"Enable Silent Printing (User)","description":"This policy controls whether Microsoft Edge uses silent printing.\r\n\r\nIf you enable this policy, Edge automatically closes the print preview window and prints to the default printer using its default settings. If the default printer is Save as PDF, the file is saved to the user's Downloads folder.\r\n\r\nIf you disable or don't configure this policy, silent printing is disabled. The print preview window stays open and the user must choose print settings as usual.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_whatsnewpageforentraprofilesenabled","displayName":"Control whether an informational webpage for Edge for Business is shown in the new tab after major browser updates (User)","description":"Starting in Microsoft Edge version 145, users with Microsoft Entra ID profiles will see an informational page about new Edge for Business features after major browser updates. This page highlights recent enhancements designed to promote secure and productive browsing.\r\n\r\nThis policy controls whether users with Microsoft Entra ID profiles see this informational page. This policy applies only to Microsoft Entra ID profiles and does not apply to Microsoft account (MSA) profiles.\r\n\r\nThis policy is available starting in Microsoft Edge version 144 to allow configuration ahead of the changes introduced in version 145.\r\n\r\nIf you enable this policy or do not configure it, Microsoft Edge shows the informational page by default.\r\nIf you disable this policy, Microsoft Edge does not show the informational page to users.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_whatsnewpageforentraprofilesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_whatsnewpageforentraprofilesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls","displayName":"Block geolocation on these sites (User)","description":"Use this policy to define a list of URL patterns for sites that are blocked from accessing the user's geolocation. These sites also can't prompt the user for location permissions.\r\n\r\nIf you enable this policy, the list you provide determines which sites are blocked from requesting or accessing geolocation.\r\n\r\nIf you disable or don't configure this policy, DefaultGeolocationSetting applies to all sites, if configured. If it's not configured, the user’s personal browser setting is used.\r\n\r\nFor detailed information on valid url patterns, see the documentation on pattern formats: https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls_geolocationblockedforurlsdesc","displayName":"Block geolocation on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_precisegeolocationallowedforurls","displayName":"Allow precise geolocation on these sites (User)","description":"This policy lets you specify a list of URL patterns for sites that are allowed to access the user's high-accuracy geolocation without prompting for permission.\r\n\r\nIf you leave this policy unset, DefaultGeolocationSetting applies to all sites (if configured). Otherwise, the user's personal setting is used.\r\n\r\nFor information about valid url patterns, see https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format. Wildcards (*) are supported.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_precisegeolocationallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_precisegeolocationallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_precisegeolocationallowedforurls_precisegeolocationallowedforurlsdesc","displayName":"Allow precise geolocation on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended","displayName":"Allow HTTPS-Only Mode to be enabled (User)","description":"This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigations to HTTPS.\r\n\r\nIf this setting isn't set or is set to `allowed`, users are able to enable HTTPS-Only Mode.\r\nIf this setting is set to `disallowed`, HTTPS-Only Mode will be disabled.\r\nIf this setting is set to `force_enabled`, HTTPS-Only Mode is enabled in Strict mode.\r\nIf this setting is set to `force_balanced_enabled`, HTTPS-Only Mode is enabled in Balanced mode.\r\n\r\nThe settings `force_enabled` and `force_balanced_enabled` can be recommended to users. HTTPS-Only Mode will be set to Strict or Balanced initially, but users are allowed to change it.\r\n\r\nIf you set this policy to a value that isn't supported by the version of Microsoft Edge that receives the policy, Microsoft Edge defaults to the `allowed` setting.\r\n\r\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\r\n\r\nPolicy options mapping:\r\n\r\n* allowed (allowed) = Don't restrict users' HTTPS-Only Mode setting\r\n\r\n* disallowed (disallowed) = Disable HTTPS-Only Mode\r\n\r\n* force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode\r\n\r\n* force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: disallowed","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_httpsonlymode_allowed","displayName":"Don't restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_httpsonlymode_disallowed","displayName":"Disable HTTPS-Only Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_httpsonlymode_force_enabled","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_recommended_httpsonlymode_recommended_httpsonlymode_force_balanced_enabled","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_staticstoragequotaenabled","displayName":"Control whether storage quota APIs will return static values (User)","description":"Controls how the Storage Quota APIs report the available quota to websites.\r\n\r\nWhen enabled, the Storage Quota APIs return a static quota value equal to the current usage plus the smaller of 10 GiB or the device's total storage rounded up to the nearest 1 GiB.\r\n\r\nWhen disabled, the Storage Quota APIs return a dynamic quota value that reflects the actual available device storage.\r\n\r\nWhen unset, the browser uses the default platform behavior.\r\n\r\nThis policy does not affect sites with unlimited storage permissions or enforced quota settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_staticstoragequotaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_staticstoragequotaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_webappinstallbyuserenabled","displayName":"Enable User Web App Install From Browser (User)","description":"This policy controls whether users can install web apps through Microsoft Edge.\r\nIf you enable or don’t configure this policy, users can install web apps through the browser.\r\nIf you disable this policy, users can’t install web apps through the browser, and the \"apps\" data type is excluded from synchronization.\r\nThis policy doesn't support dynamic refresh. Changes to this policy, whether enabled, disabled, or not configured, take effect only after the browser is restarted.\r\nThis policy doesn't affect the 'WebAppInstallForceList' policy. Web apps specified by that policy are installed regardless of this policy setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_webappinstallbyuserenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_webappinstallbyuserenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting","displayName":"Default idle detection setting (User)","description":"Setting this policy to 1 - AllowIdleDetection allows websites to use the Idle Detection API without requesting user permission.\r\n\r\nSetting this policy to 2 - BlockIdleDetection prevents websites from using the Idle Detection API.\r\n\r\nSetting this policy to 3 - AskIdleDetection requires websites to request user permission each time before using the Idle Detection API.\r\n\r\nIf you do not configure this policy, users can decide whether to allow the Idle Detection API and can change this setting themselves.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowIdleDetection (1) = Allow sites to detect idle state without asking the user\r\n\r\n* BlockIdleDetection (2) = Do not allow any site to detect the user's idle state\r\n\r\n* AskIdleDetection (3) = Ask every time a site wants to detect the user's idle state\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting","displayName":"Idle detection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting_1","displayName":"Allow sites to detect idle state without asking the user","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting_2","displayName":"Do not allow any site to detect the user's idle state","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting_3","displayName":"Ask every time a site wants to detect the user's idle state","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls","displayName":"Allow idle detection on these sites (User)","description":"Allows you to specify a list of URL patterns for sites that are allowed to use the Idle Detection API.\r\n\r\nIf you do not configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise.\r\n\r\nOnly the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported. For detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=209532.\r\n\r\nURL patterns specified in the blocklist take precedence over this allowlist. This allowlist takes precedence over the DefaultIdleDetectionSetting policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls_idledetectionallowedforurlsdesc","displayName":"Allowed sites for idle detection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls","displayName":"Block idle detection on these sites (User)","description":"Allows you to specify a list of URL patterns for sites that are not allowed to use the Idle Detection API.\r\n\r\nOnly the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported.\r\n\r\nFor detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nIf you do not configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls_idledetectionblockedforurlsdesc","displayName":"Blocked sites for idle detection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~extensions_edgesafehostingextensionenabled","displayName":"Control Microsoft Edge Safe Hosting Extension (User)","description":"This policy controls whether the Microsoft Edge Safe Hosting component extension is installed automatically when users visit supported Microsoft services, such as Microsoft 365 Copilot app.\r\n\r\nThe Microsoft Edge Safe Hosting extension provides additional security capabilities for these services. When a user accesses a supported service, the extension installs automatically to enable those protections.\r\n\r\nIf you enable or don't configure this policy, the extension installs automatically and remains installed for 90 days after the user's last visit, then is removed if no further activity occurs.\r\n\r\nIf you disable this policy, the extension won't install automatically. If it’s already installed, it will be removed.\r\n\r\nNote: This policy controls only automatic installation. It doesn’t prevent users from manually installing other extensions from the Microsoft Edge Add-ons website.","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~extensions_edgesafehostingextensionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~extensions_edgesafehostingextensionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled","displayName":"Enable editing profile in settings (User)","description":"This policy controls whether users can modify profile properties (such as profile avatar) from the profile settings page.\r\n\r\nIf you enable or don't configure this policy, users can edit profile properties. The edit button is available on the profile settings page.\r\n\r\nIf you disable this policy, users can't edit profile properties. The edit button is disabled on the profile settings page.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled","displayName":"Enable saving passkeys to the password manager (User)","description":"This policy controls whether users can save passkeys in the built-in password manager. It does not limit access to, or change the contents of, passkeys already saved in the password manager.\r\n\r\nIf the PasswordManagerEnabled policy is Disabled, saving to the built-in password manager is disabled in general, including passkeys. In this case, this policy has no effect.\r\n\r\nIf this policy is enabled or not configured, users can save passkeys in the built-in password manager when signed in to Microsoft Edge.\r\n\r\nIf this policy is disabled, users cannot save new passkeys to the built-in password manager. Previously saved passkeys continue to work.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge_standardizedbrowserzoomenabled","displayName":"Enable Standardized Browser Zoom Behavior (User)","description":"Configures whether the CSS \"zoom\" property follows the current CSS specification or legacy behavior.\r\n\r\nWhen this policy is enabled or not configured, the CSS \"zoom\" property follows the current specification defined by the CSS Working Group:\r\nhttps://drafts.csswg.org/css-viewport/#zoom-property\r\n\r\nWhen this policy is disabled, the CSS \"zoom\" property uses its legacy, pre-standardized behavior.\r\n\r\nThis policy is temporary and is intended to provide time for organizations to migrate web content to the updated behavior. In a future Microsoft Edge release, this policy will be removed and the standardized behavior will be enforced by default.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge_standardizedbrowserzoomenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge_standardizedbrowserzoomenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowciphers","displayName":"Prefer specific encryption cipher algorithms for TLS (User)","description":"This policy configures Microsoft Edge to order its preferred encryption ciphers in TLS 1.3 based on algorithms approved by a specific compliance regime.\r\n\r\nSetting this policy does not guarantee that any specific algorithms will be negotiated.\r\n\r\nThis policy allows server operators who support both compliant and non-compliant clients to differentiate between them, and use certain non-default algorithms with increased cryptographic strength only for clients explicitly configured to prefer them.\r\n\r\nSetting the policy to 'cnsa' configures Microsoft Edge to prefer ciphers required for compliance with the Commercial National Security Algorithm Suite versions 1.0 and 2.0 (CNSA 1.0 and 2.0).\r\n\r\nNot setting the policy, or setting it to 'default', configures Microsoft Edge to use its default ciphers.\r\n\r\nSetting this policy isn't required for security. The default cryptography used by Microsoft Edge is strong enough to withstand a brute-force attack using the entire power of the Sun.\r\n\r\nSetting this policy will cause Microsoft Edge to be slower when accessing websites.\r\n\r\nThis policy only affects TLS 1.3 and QUIC. It doesn't affect earlier versions of TLS.\r\n\r\nPolicy options mapping:\r\n\r\n* CNSA (cnsa) = Prefer ciphers satisfying the requirements of CNSA 1.0 and 2.0\r\n\r\n* Default (default) = Use Microsoft Edge's default cipher order\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: cnsa","helpText":"","infoUrls":[],"categoryId":"120b24dd-c04a-4291-8f24-9c48fcdc1434","categoryName":"Cryptography compliance policies","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowciphers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowciphers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowciphers_preferslowciphers","displayName":"Prefer specific encryption cipher algorithms for TLS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"120b24dd-c04a-4291-8f24-9c48fcdc1434","categoryName":"Cryptography compliance policies","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowciphers_preferslowciphers_cnsa","displayName":"Prefer ciphers satisfying the requirements of CNSA 1.0 and 2.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowciphers_preferslowciphers_default","displayName":"Use Microsoft Edge's default cipher order","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowkexalgorithms","displayName":"Prefer specific key exchange algorithms for TLS (User)","description":"This policy configures Microsoft Edge to prioritize certain key agreement algorithms (supported groups) in TLS 1.3 based on compliance requirements.\r\n\r\nIf you set this policy to 'cnsa2', Microsoft Edge prefers the algorithms required for the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0). If you leave this policy unset or set it to 'default', the browser uses its standard key exchange order.\r\n\r\nThis policy does not guarantee negotiation of a specific algorithm. It is designed to help server operators distinguish clients with compliance requirements and apply higher-strength, non-default algorithms only when appropriate.\r\n\r\nIf this policy would prefer a post-quantum key agreement algorithm but PostQuantumKeyAgreementEnabled is Disabled, the post-quantum setting takes precedence.\r\n\r\nThis policy applies only to TLS 1.3 and QUIC. The default cryptography used by Microsoft Edge already provides strong security, but enabling this policy may reduce performance when accessing websites.\r\n\r\nPolicy options mapping:\r\n\r\n* CNSA2.0 (cnsa2) = Prefer key exchange methods satisfying the requirements of CNSA 2.0\r\n\r\n* Default (default) = Use Microsoft Edge's default supported groups\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: cnsa2","helpText":"","infoUrls":[],"categoryId":"120b24dd-c04a-4291-8f24-9c48fcdc1434","categoryName":"Cryptography compliance policies","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowkexalgorithms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowkexalgorithms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowkexalgorithms_preferslowkexalgorithms","displayName":"Prefer specific key exchange algorithms for TLS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"120b24dd-c04a-4291-8f24-9c48fcdc1434","categoryName":"Cryptography compliance policies","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowkexalgorithms_preferslowkexalgorithms_cnsa2","displayName":"Prefer key exchange methods satisfying the requirements of CNSA 2.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~cryptographycompliance_preferslowkexalgorithms_preferslowkexalgorithms_default","displayName":"Use Microsoft Edge's default supported groups","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides","displayName":"Override IP address space mappings (User)","description":"Specifies IP address space overrides for Local Network Access restrictions. This policy allows administrators to treat specific IP address ranges as public (exempt from Local Network Access restrictions) or as local (subject to Local Network Access restrictions).\r\n\r\nIP address space overrides can be specified using one of the following formats:\r\n\r\n• [cidr]=[public|local|loopback]\r\nwhere [cidr] is an IP address range in CIDR notation. CIDR overrides apply to all ports.\r\n\r\n• [ip-address]:[port]=[public|local|loopback]\r\n\r\nIPv6 addresses must be specified in URL-safe (bracketed) format.\r\n\r\nFor more information about Local Network Access, see https://wicg.github.io/local-network-access/.\r\n\r\nExample value:\r\n\r\n100.64.0.0/10=public\r\n[2001:db8::]/32=local\r\n192.168.0.1:8000=public\r\n[2001:DB8::8:800:200C:417A]:8080=local","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides_localnetworkaccessipaddressspaceoverridesdesc","displayName":"Override IP address space mappings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccesspermissionspolicydefaultenabled","displayName":"Allow Local Network Access (LNA) requests in subframes without explicit delegation (User)","description":"Controls whether Local Network Access (LNA) permissions are inherited by cross-origin subframes.\r\n\r\nBy default, Local Network Access permissions can be requested in cross-origin subframes only if they are explicitly delegated.\r\n\r\nIf you enable this policy, subframes inherit all LNA Permissions Policy features by default and can make local network requests, which trigger the permission prompt.\r\n\r\nIf you disable or don't configure this policy, subframes must be explicitly delegated the Permissions Policy feature to make local network requests and trigger the permission prompt.\r\n\r\nThis policy applies to the Permissions Policy features \"local-network-access\", \"loopback-network\", and \"local-network\".\r\n\r\nFor more information about Local Network Access, see https://learn.microsoft.com/deployedge/ms-edge-local-network-access.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccesspermissionspolicydefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccesspermissionspolicydefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkallowedforurls","displayName":"Allow sites to make network requests to local network endpoints. (User)","description":"Controls which website origins are exempt from Local Network Access checks when accessing local network endpoints.\r\n\r\nNetwork requests initiated from websites that match the specified URL patterns are not subject to Local Network Access checks.\r\n\r\nFor origins not covered by the patterns specified in this policy, the user's personal configuration applies.\r\n\r\nFor detailed information about valid URL patterns, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\r\n\r\nFor more information about Local Network Access restrictions, see https://wicg.github.io/local-network-access/.\r\n\r\nMultiple policies can list origins that affect requests to local network endpoints. If an origin matches more than one of the following policies, they take precedence in the following order:\r\n- LocalNetworkBlockedForUrls\r\n- LocalNetworkAllowedForUrls\r\n- LoopbackNetworkBlockedForUrls\r\n- LoopbackNetworkAllowedForUrls\r\n- LocalNetworkAccessBlockedForUrls\r\n- LocalNetworkAccessAllowedForUrls\r\n\r\nThis policy controls access to local network endpoints (private IP addresses) and can be used to allow specific websites to access local network resources.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkallowedforurls_localnetworkallowedforurlsdesc","displayName":"Allow sites to make network requests to local network endpoints. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkblockedforurls","displayName":"Block sites from making network requests to local network endpoints. (User)","description":"Controls which website origins are blocked from making Local Network Access requests to local network endpoints.\r\n\r\nNetwork requests initiated from websites that match the specified URL patterns are blocked from issuing Local Network Access requests.\r\n\r\nFor origins not covered by the patterns specified in this policy, the user's personal configuration applies.\r\n\r\nFor detailed information about valid URL patterns, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\r\n\r\nFor more information about Local Network Access restrictions, see https://wicg.github.io/local-network-access/.\r\n\r\nMultiple policies can list origins that affect requests to local network endpoints. If an origin matches more than one of the following policies, they take precedence in the following order:\r\n- LocalNetworkBlockedForUrls\r\n- LocalNetworkAllowedForUrls\r\n- LoopbackNetworkBlockedForUrls\r\n- LoopbackNetworkAllowedForUrls\r\n- LocalNetworkAccessBlockedForUrls\r\n- LocalNetworkAccessAllowedForUrls\r\n\r\nThis policy controls access to local network endpoints (private IP addresses) and can be used to block specific websites from accessing local network resources.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkblockedforurls_localnetworkblockedforurlsdesc","displayName":"Block sites from making network requests to local network endpoints. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls","displayName":"Allow sites to make network requests to the local device. (User)","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions when accessing loopback addresses (127.0.0.1, ::1, localhost).\r\n\r\nIf a requesting origin matches a URL pattern specified in this policy, requests to loopback addresses are allowed and are not subject to Local Network Access restrictions.\r\n\r\nFor origins not covered by this policy, the user's personal settings and local network access restrictions apply.\r\n\r\nIf this policy is disabled or not configured, no additional exemptions are granted beyond the user's existing configuration.\r\n\r\nMultiple policies can specify origins that affect requests to the local device. If an origin matches more than one of the following policies, they are applied in the following order of precedence:\r\n- LoopbackNetworkBlockedForUrls\r\n- LoopbackNetworkAllowedForUrls\r\n- LocalNetworkAccessBlockedForUrls\r\n- LocalNetworkAccessAllowedForUrls\r\n\r\nFor guidance on valid URL pattern syntax, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns .\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls_loopbacknetworkallowedforurlsdesc","displayName":"Allow sites to make network requests to the local device. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkblockedforurls","displayName":"Block sites from making network requests to the local device. (User)","description":"Specifies a list of URL patterns for which requests initiated from matching origins to loopback addresses (127.0.0.1, ::1, localhost) are blocked from issuing Local Network Access requests.\r\n\r\nIf a requesting origin matches a URL pattern specified in this policy, requests to loopback addresses are blocked.\r\n\r\nFor origins not covered by this policy, the user's personal settings and local network access restrictions apply.\r\n\r\nMultiple policies can specify origins that affect requests to the local device. If an origin matches more than one of the following policies, they are applied in the following order of precedence:\r\n- LoopbackNetworkBlockedForUrls\r\n- LoopbackNetworkAllowedForUrls\r\n- LocalNetworkAccessBlockedForUrls\r\n- LocalNetworkAccessAllowedForUrls\r\n\r\nNote: This policy improves local network security by blocking specified public websites from accessing loopback addresses. It helps prevent unauthorized external sites from reaching local services running on the device unless explicitly permitted.\r\n\r\nFor more information about Local Network Access, see https://wicg.github.io/local-network-access/\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkblockedforurls_loopbacknetworkblockedforurlsdesc","displayName":"Block sites from making network requests to the local device. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_browserguestmodeenforced","displayName":"Enforce Edge guest mode (User)","description":"Controls whether Microsoft Edge enforces Guest-only browsing.\r\n\r\nIf you enable this policy, Microsoft Edge enforces Guest sessions and prevents profile sign-in. Guest sessions run in InPrivate mode.\r\n\r\nIf you disable or don't configure this policy, users can create and use profiles. Guest mode can also be controlled separately using the BrowserGuestModeEnabled policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_browserguestmodeenforced_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_browserguestmodeenforced_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_forceforegroundpriorityforalltabs","displayName":"Force foreground priority for all tabs (User)","description":"This policy controls whether background web content runs at foreground priority.\r\n\r\nBy default, the browser optimizes resource usage by lowering the scheduling\r\npriority of content in background tabs. This helps improve overall system\r\nresponsiveness and performance for the active tab.\r\n\r\nIf you enable this policy, background web content runs at the same foreground\r\npriority as the active tab, regardless of visibility state.\r\n\r\nIf you disable or don't configure this policy, the browser determines the\r\npriority of web content based on standard heuristics. For example, content\r\nthat is not visible, not playing audio, and not participating in video calls\r\nmay be deprioritized.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_forceforegroundpriorityforalltabs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_forceforegroundpriorityforalltabs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist","displayName":"Allow access to a list of URLs in InPrivate mode. (User)","description":"This policy allows administrators to specify a list of URL patterns that are permitted to open in InPrivate mode. It can be used to create exceptions for URL patterns defined in 'InPrivateModeUrlBlocklist' (Block access to a list of URLs in InPrivate mode.). See how to format a URL pattern (https://go.microsoft.com/fwlink/?linkid=2095322).\r\n\r\nIf both this policy and 'InPrivateModeUrlBlocklist' are configured, the allowlist takes precedence. URLs that match a pattern on this allowlist are allowed. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither list fall back to 'URLBlocklist' (Block access to a list of URLs) and 'URLAllowlist' (Define a list of allowed URLs).\r\n\r\nIf this policy is configured and 'InPrivateModeUrlBlocklist' is not configured, only the URLs specified in this allowlist can be opened in InPrivate mode. All other URLs are blocked.\r\n\r\nIf 'InPrivateModeAvailability' (Configure InPrivate mode availability) is set to disallow (value 1) but this policy is configured, InPrivate mode is available only for URLs that match the allowlist.\r\n\r\nIf this policy is not configured, no exceptions are applied to 'InPrivateModeUrlBlocklist' or 'InPrivateModeAvailability'.\r\n\r\nThis policy applies only to InPrivate mode. To allow URLs across all browsing modes and profiles, use the 'URLAllowlist' policy.\r\n\r\nThis policy supports up to 1000 entries.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist_inprivatemodeurlallowlistdesc","displayName":"Allow access to a list of URLs in InPrivate mode. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist","displayName":"Block access to a list of URLs in InPrivate mode. (User)","description":"This policy controls which URLs are blocked from loading in InPrivate mode in Microsoft Edge.\r\n\r\nAdministrators can specify a list of URL patterns that are blocked when users browse in InPrivate mode. For information about the supported URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nIf both 'InPrivateModeUrlBlocklist' (Block access to a list of URLs in InPrivate mode.) and 'InPrivateModeUrlAllowlist' (Allow access to a list of URLs in InPrivate mode.) are configured, the allowlist takes precedence.\r\n- URLs that match the allowlist are allowed.\r\n- URLs that match the blocklist but not the allowlist are blocked.\r\n- URLs that match neither list follow the behavior defined by the general 'URLBlocklist' (Block access to a list of URLs) and 'URLAllowlist' (Define a list of allowed URLs) policies.\r\n\r\nIf 'InPrivateModeUrlAllowlist' is configured and this policy is not configured, only URLs on the allowlist can be opened in InPrivate mode.\r\n\r\nIf 'InPrivateModeAvailability' (Configure InPrivate mode availability) is set to disallow (value 1) and 'InPrivateModeUrlAllowlist' is configured, InPrivate mode is available only for URLs that match the allowlist.\r\n\r\nThis policy applies only to InPrivate mode. To block URLs across all browsing modes, use 'URLBlocklist'.\r\n\r\nThis policy supports up to 1000 entries.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist_inprivatemodeurlblocklistdesc","displayName":"Block access to a list of URLs in InPrivate mode. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended","displayName":"Set default download directory (User)","description":"This policy sets the default directory that Microsoft Edge uses to download files. Users can change the directory through browser settings.\r\n\r\nIf you don't configure this policy, Microsoft Edge uses the platform-specific default download directory.\r\n\r\nThis policy has no effect if the DownloadDirectory policy is set.\r\n\r\nFor a list of supported variables, see https://learn.microsoft.com/en-us/deployedge/edge-learnmore-create-user-directory-vars .\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_defaultdownloaddirectory","displayName":"Set default download directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_xsltenabled","displayName":"Control the availability of the XSLT feature (User)","description":"Controls whether the XSLT feature (the XSLTProcessor JavaScript API and the XSL processing instruction) is available in Microsoft Edge.\r\n\r\nIf you enable this policy, XSLT is available regardless of the browser's default configuration.\r\n\r\nIf you disable this policy, XSLT is unavailable regardless of the browser's default configuration.\r\n\r\nIf you don't configure this policy, XSLT availability is determined by the browser's default configuration and any applicable field trials.\r\n\r\nThis policy is temporary and will be removed in a future version of Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_xsltenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_xsltenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains","displayName":"Allow specified sites to access file:// URLs in the PDF Viewer (User)","description":"Controls which sites can access file:// URLs in the PDF Viewer.\r\n\r\nIf you enable this policy, sites in the list can access file:// URLs in the PDF Viewer.\r\n\r\nIf you disable or don't configure this policy, sites cannot access file:// URLs in the PDF Viewer.\r\n\r\nExample value:\r\n\r\nexample.com\r\ncontoso.com","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains_pdflocalfileaccessallowedfordomainsdesc","displayName":"Allow specified sites to access file:// URLs in the PDF Viewer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~protectedcontent_protectedcontentidentifiersallowed","displayName":"Allows web pages to use identifiers for the purpose of protected content playback (User)","description":"This policy controls whether sites can use hardware-specific device identifiers to enable hardware-secure DRM (for example, Widevine L1 or PlayReady SL3000), which may be required for high-resolution protected content playback.\r\n\r\nIf you enable this policy or do not configure it, sites are allowed to use protected content identifiers.\r\n\r\nIf you disable this policy, sites are not allowed to use protected content identifiers.","helpText":"","infoUrls":[],"categoryId":"2af24920-f611-4f03-99a6-205773869ae6","categoryName":"Protected Content","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~protectedcontent_protectedcontentidentifiersallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~protectedcontent_protectedcontentidentifiersallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge. (User)","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\r\n\r\nBrowsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\r\n\r\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\r\n\r\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?LinkId=2341535.\r\n\r\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\r\n\r\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\r\n\r\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist","displayName":"Browsing with Copilot Allowed URLs (User)","description":"Allows you to define a list of URLs where browsing with Copilot is available. Users cannot modify this list.\r\n\r\nIf you enable this policy, browsing with Copilot is available only on the sites specified in the list. To allow a broader set of sites while blocking specific exceptions, configure this policy together with the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. For example, you can include '*' to allow all sites, and then use the block list to restrict access to specific URLs.\r\n\r\nYou can define exceptions based on schemes, subdomains, ports, or origins. When multiple filters apply, the most specific match determines whether a URL is allowed or blocked. The block list takes precedence over the allow list.\r\n\r\nIf you disable or do not configure this policy, browsing with Copilot is unavailable on all sites, even if the 'AllowBrowsingWithCopilot' (Controls the availability of browsing with Copilot in Microsoft Edge.) policy is enabled.\r\n\r\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. This policy applies only to the site origin; any path specified in the URL pattern is ignored. For guidance on formatting URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu\r\ncontoso.net\r\nlogin.contoso.us","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_browsingwithcopilotallowlistdesc","displayName":"Browsing with Copilot Allowed URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist","displayName":"Browsing with Copilot Blocked URLs (User)","description":"Controls the list of URLs where browsing with Copilot is blocked. Users can't modify this list.\r\n\r\nUse this policy to define exceptions to broader allowlists. For example, you can set 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) to '*' to allow all sites, and then use this policy to block access to specific URLs.\r\n\r\nThis policy supports blocking by scheme, subdomain, or port. When multiple URL patterns apply, the most specific match determines whether access is allowed or blocked. Blocklist entries take precedence over allowlist entries.\r\n\r\nIf you don't configure this policy, no exceptions are applied to 'BrowsingWithCopilotAllowList'.\r\n\r\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. URL matching is based on the site origin only; any path specified in the pattern is ignored.\r\n\r\nFor information about URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu\r\ncontoso.net\r\nlogin.contoso.us","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist_browsingwithcopilotblocklistdesc","displayName":"Browsing with Copilot Blocked URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_copilotnewtabpageenabled","displayName":"Enable the Copilot new tab page (User)","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\r\n\r\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\r\n\r\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\r\n\r\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\r\n\r\nIf you enable this policy, the Copilot new tab page is turned on.\r\n\r\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_copilotnewtabpageenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_copilotnewtabpageenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityallowlist","displayName":"List of URL patterns for which developer tools are allowed to be opened (User)","description":"This policy controls where developer tools can be used in Microsoft Edge by specifying an allowlist of URL patterns.\r\n\r\nURL patterns are matched against the URL of every frame on the page being inspected.\r\n\r\nIf you configure this policy and do not configure the 'DeveloperToolsAvailabilityBlocklist' (List of URL patterns for which developer tools are blocked) policy, developer tools are available only when every frame on the page matches a pattern in this allowlist. If any frame does not match, developer tools are blocked for the entire page. For information on the URL format, see https://go.microsoft.com/fwlink/?linkid=2095322 .\r\n\r\nIf you configure both this policy and the 'DeveloperToolsAvailabilityBlocklist' policy, this allowlist takes precedence. URLs that match this allowlist are allowed even if they also match the blocklist. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither are governed by the 'DeveloperToolsAvailability' (Control where developer tools can be used) policy.\r\n\r\nIf you disable or do not configure this policy, developer tools availability is determined by the 'DeveloperToolsAvailabilityBlocklist' and 'DeveloperToolsAvailability' policies.\r\n\r\nThis policy applies to developer tools opened for websites, extensions, and web applications.\r\n\r\nThis policy supports up to 1,000 entries.\r\n\r\nExample value:\r\n\r\ncontoso.com\r\nhttps://ssl.server.com\r\ncontoso.com/good_path\r\nhttps://server.contoso.com:8080/path\r\n.exact.hostname.com\r\nfile://*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityallowlist_developertoolsavailabilityallowlistdesc","displayName":"List of URL patterns for which developer tools are allowed to be opened (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityblocklist","displayName":"List of URL patterns for which developer tools are blocked (User)","description":"This policy specifies URL patterns where developer tools are blocked. For information on the URL format, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nURL patterns are evaluated against the URL of every frame on the page being inspected. If any frame matches a pattern in this policy, developer tools are blocked for the entire page.\r\n\r\nIf you configure this policy and do not configure the 'DeveloperToolsAvailabilityAllowlist' (List of URL patterns for which developer tools are allowed to be opened) policy, developer tools are blocked when any frame matches a pattern in this policy. If no frames match, availability is determined by the 'DeveloperToolsAvailability' (Control where developer tools can be used) policy.\r\n\r\nIf you configure both this policy and the 'DeveloperToolsAvailabilityAllowlist' policy, the allowlist takes precedence. URLs that match the allowlist are allowed, even if they also match this policy. URLs that match this policy (but not the allowlist) are blocked. If a URL matches neither, the 'DeveloperToolsAvailability' policy determines availability.\r\n\r\nIf you disable or do not configure this policy, developer tools availability is determined by the 'DeveloperToolsAvailabilityAllowlist' and 'DeveloperToolsAvailability' policies.\r\n\r\nThis policy supports up to 1,000 entries.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com\r\ncontoso.com\r\nhttps://ssl.server.com\r\ncontoso.com/bad_path\r\nhttps://server.contoso.com:8080/path\r\n.exact.hostname.com\r\n*\r\nfile://*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityblocklist_developertoolsavailabilityblocklistdesc","displayName":"List of URL patterns for which developer tools are blocked (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_m365linksautoopencopilotenabled","displayName":"Automatically open Copilot side pane with contextual insights for links opened from Outlook (User)","description":"This policy controls whether Microsoft Edge automatically opens the Microsoft Copilot side pane when users open web links from Outlook emails sent from the same tenant.\r\n\r\nStarting in Microsoft Edge version 148, when users open eligible links from Outlook emails sent from the same tenant, Microsoft Edge automatically opens the Copilot side pane with contextual insights. Copilot can use the originating Outlook email as context to surface relevant insights and suggested next steps alongside the web content.\r\n\r\nIf you enable this policy or don't configure it, the Copilot side pane opens automatically when users open links from Outlook emails sent from the same tenant.\r\n\r\nIf you disable this policy, the Copilot side pane doesn't open automatically when users open links from Outlook emails sent from the same tenant.\r\n\r\nThis feature applies only to links opened from Outlook emails sent from the same tenant and requires Microsoft Copilot to be available for the user in Microsoft Edge.\r\n\r\nThis feature is disabled if the 'CopilotPageContext' (Control Copilot access to page context for Microsoft Entra ID profiles) policy or the 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane) policy is disabled, regardless of this policy's configuration. Copilot requires access to page content to provide contextual insights.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_m365linksautoopencopilotenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_m365linksautoopencopilotenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket","displayName":"Maximum number of concurrent connections to the proxy server for WebSocket requests (User)","description":"Specifies the maximum number of simultaneous connections to a proxy server for WebSocket requests.\r\n\r\nTo configure limits for non-WebSocket requests, see the 'MaxConnectionsPerProxy' (Maximum number of concurrent connections to the proxy server) policy.\r\n\r\nIf you don't configure this policy, the default value of 32 is used.\r\n\r\nSome web applications maintain multiple concurrent connections (for example, long-lived or hanging requests). Setting a value lower than the default may cause networking delays when many such applications are open.\r\n\r\nSome proxy servers cannot handle a high number of concurrent connections per client. In these cases, reducing the value of this policy may improve reliability.\r\n\r\nThe supported range is 6 to 256:\r\n- Values less than 6 are treated as 6.\r\n- Values greater than 256 are treated as 256.\r\n\r\nWe recommend modifying this value only if required by your proxy server configuration or network environment.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket_maxconnectionsperproxyforwebsocket","displayName":"Maximum number of concurrent connections to the proxy server for WebSocket requests: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge. (User)","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\r\n\r\nBrowsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\r\n\r\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\r\n\r\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?LinkId=2341535.\r\n\r\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\r\n\r\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\r\n\r\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended","displayName":"Enable the Copilot new tab page (User)","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\r\n\r\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\r\n\r\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\r\n\r\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\r\n\r\nIf you enable this policy, the Copilot new tab page is turned on.\r\n\r\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended","displayName":"Set the default New Tab Page feed tab to Work or Discover (User)","description":"This policy sets the default feed tab on the New Tab Page to Work or Discover.\r\n\r\nIf you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work.\r\n\r\nIf you set this policy to 'Discover' (1), Microsoft Edge sets the default feed tab to Discover.\r\n\r\nThis policy only takes effect when 'ConfigureNTPFeedTabVisibility' (Configure whether the Discover or Work feed tabs are shown on the New Tab Page.) is set to 'EnableBothWorkDiscover' (0) or is not configured. If only one tab is visible, this policy has no effect.\r\n\r\nPolicy options mapping:\r\n\r\n* NTPDefaultFeedTabWork (0) = Work\r\n\r\n* NTPDefaultFeedTabDiscover (1) = Discover\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab_0","displayName":"Work","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab_1","displayName":"Discover","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_sharedworkerextendedlifetimeenabled","displayName":"Enable the extended lifetime option for SharedWorkers (User)","description":"Controls whether Microsoft Edge allows SharedWorkers to use the extendedLifetime option.\r\n\r\nIf you enable or don't configure this policy, SharedWorkers can use the extended lifetime option in the SharedWorker constructor.\r\n\r\nIf you disable this policy, the extended lifetime option is ignored, even if it is requested by the page.\r\n\r\nThis policy is temporary and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_sharedworkerextendedlifetimeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_sharedworkerextendedlifetimeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~identity_m365authpopupsinworkenabled","displayName":"Allow M365 authentication popups in work profiles (User)","description":"This policy controls whether Microsoft Edge allows Microsoft 365 authentication pop-ups to bypass the pop-up blocker in work profiles.\r\n\r\nWhen users are signed in with a work account, some Microsoft 365 sites (for example, microsoft.com, cloud.microsoft, and visualstudio.com) may open authentication pop-ups to login.microsoftonline.com, login.live.com, or login.microsoft.com. These pop-ups are required to complete sign-in.\r\n\r\nIf you enable this policy or don't configure it, Microsoft 365 authentication pop-ups are allowed in work profiles.\r\n\r\nIf you disable this policy, Microsoft 365 authentication pop-ups follow the default settings like other pop-ups.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~identity_m365authpopupsinworkenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~identity_m365authpopupsinworkenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~manageability_mamwithdevicedlpenabled","displayName":"Allow MAM enrollment when managed device has Purview DLP policy configured (User)","description":"Controls whether Microsoft Edge allows Mobile Application Management (MAM) enrollment on managed devices when Microsoft Purview Data Loss Prevention (DLP) is configured.\r\n\r\nIf you enable this policy, MAM enrollment is allowed even when Purview DLP is detected on the device.\r\n\r\nIf you disable or don't configure this policy, MAM enrollment is blocked when Purview DLP is detected on the device.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~manageability_mamwithdevicedlpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~manageability_mamwithdevicedlpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility","displayName":"Configure whether the Discover or Work feed tabs are shown on the New Tab Page. (User)","description":"This policy configures whether the Discover or Work feed tabs are shown on the New Tab Page. By default, both Work and Discover tabs are enabled.\r\n\r\nIf you set this policy to 'EnableBothWorkDiscover' (0) or do not configure this policy, Microsoft Edge shows both the Work and Discover feed tabs on the new tab page.\r\n\r\nIf you set this policy to 'EnableOnlyWork' (1), Microsoft Edge shows only the Work feed tab on the new tab page.\r\n\r\nIf you set this policy to 'EnableOnlyDiscover' (2), Microsoft Edge shows only the Discover feed tab on the new tab page.\r\n\r\nThis policy works with the SetNTPDefaultFeedTab policy, which controls which feed tab is selected by default when both tabs are available.\r\n\r\nPolicy options mapping:\r\n\r\n* EnableBothWorkDiscover (0) = Enable both Work and Discover tabs\r\n\r\n* EnableOnlyWork (1) = Enable only Work tab\r\n\r\n* EnableOnlyDiscover (2) = Enable only Discover tab\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility","displayName":"Configure whether the Discover or Work feed tabs are shown on the New Tab Page. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility_0","displayName":"Enable both Work and Discover tabs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility_1","displayName":"Enable only Work tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility_2","displayName":"Enable only Discover tab","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (User)","description":"This policy sets the default feed tab on the New Tab Page to Work or Discover.\r\n\r\nIf you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work.\r\n\r\nIf you set this policy to 'Discover' (1), Microsoft Edge sets the default feed tab to Discover.\r\n\r\nThis policy only takes effect when 'ConfigureNTPFeedTabVisibility' (Configure whether the Discover or Work feed tabs are shown on the New Tab Page.) is set to 'EnableBothWorkDiscover' (0) or is not configured. If only one tab is visible, this policy has no effect.\r\n\r\nPolicy options mapping:\r\n\r\n* NTPDefaultFeedTabWork (0) = Work\r\n\r\n* NTPDefaultFeedTabDiscover (1) = Discover\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab_0","displayName":"Work","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab_1","displayName":"Discover","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\r\n\r\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\r\n\r\nDisabling this setting is the same as leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\r\n\r\nPolicy options mapping:\r\n\r\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\r\n\r\n* RestoreOnStartupIsLastSession (1) = Restore the last session\r\n\r\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\r\n\r\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_6","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\r\n\r\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\r\n\r\nDisabling this setting is the same as leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\r\n\r\nPolicy options mapping:\r\n\r\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\r\n\r\n* RestoreOnStartupIsLastSession (1) = Restore the last session\r\n\r\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\r\n\r\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_6","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads (User)","description":"Controls whether ads are blocked on sites with intrusive ads. You can set this policy to one of the following options:\r\n\r\n* 1 = Allow ads on all sites.\r\n\r\n* 2 = Block ads on sites with intrusive ads (Default value).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_adssettingforintrusiveadssites_1","displayName":"Allow ads on all sites","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_adssettingforintrusiveadssites_2","displayName":"Block ads on sites with intrusive ads. (Default value)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowpopupsduringpageunload","displayName":"Allows a page to show popups during its unloading (User)","description":"This policy allows an admin to specify that a page can show popups during its unloading.\r\n\r\nWhen the policy is set to enabled, pages are allowed to show popups while they're being unloaded.\r\n\r\nWhen the policy is set to disabled or unset, pages aren't allowed to show popups while they're being unloaded. This is as per the spec: (https://html.spec.whatwg.org/#apis-for-creating-and-navigating-browsing-contexts-by-name).\r\n\r\nThis policy will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowpopupsduringpageunload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowpopupsduringpageunload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls","displayName":"Configure tracking prevention exceptions for specific sites (User)","description":"Configure the list of URL patterns that are excluded from tracking prevention.\r\n\r\nIf you configure this policy, the list of configured URL patterns is excluded from tracking prevention.\r\n\r\nIf you don't configure this policy, the global default value from the \"Block tracking of users' web-browsing activity\" policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_allowtrackingforurlsdesc","displayName":"Configure tracking prevention exceptions for specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_autoplayallowed","displayName":"Allow media autoplay for websites (User)","description":"This policy sets the media autoplay policy for websites.\r\n\r\nThe default setting, \"Not configured\" respects the current media autoplay settings and lets users configure their autoplay settings.\r\n\r\nSetting to \"Enabled\" sets media autoplay to \"Allow\". All websites are allowed to autoplay media. Users can’t override this policy.\r\n\r\nSetting to \"Disabled\" sets media autoplay to \"Block\". No websites are allowed to autoplay media. Users can’t override this policy.\r\n\r\nA tab will need to be closed and re-opened for this policy to take effect.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_autoplayallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_autoplayallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clearbrowsingdataonexit","displayName":"Clear browsing data when Microsoft Edge closes (User)","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\r\n\r\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured 'DefaultCookiesSetting' (Configure cookies)\r\n\r\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\r\n\r\nIf you enable this policy, don't configure the 'AllowDeletingBrowserHistory' (Enable deleting browser and download history) or the 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes) policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured 'AllowDeletingBrowserHistory' or 'ClearCachedImagesAndFilesOnExit'.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clearbrowsingdataonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clearbrowsingdataonexit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clickonceenabled","displayName":"Allow users to open files using the ClickOnce protocol (User)","description":"Allow users to open files using the ClickOnce protocol. The ClickOnce protocol allows websites to request that the browser open files from a specific URL using the ClickOnce file handler on the user's computer or device.\r\n\r\nIf you enable this policy, users can open files using the ClickOnce protocol. This policy overrides the user's ClickOnce setting in the edge://flags/ page.\r\n\r\nIf you disable this policy, users can't open files using the ClickOnce protocol. Instead, the file will be saved to the file system using the browser. This policy overrides the user's ClickOnce setting in the edge://flags/ page.\r\n\r\nIf you don't configure this policy, users can't open files using the ClickOnce protocol. Users have the option to enable the use of the ClickOnce protocol with the edge://flags/ page.\r\n\r\nDisabling ClickOnce may prevent ClickOnce applications (.application files) from launching properly.\r\n\r\nFor more information about ClickOnce, see https://go.microsoft.com/fwlink/?linkid=2103872 and https://go.microsoft.com/fwlink/?linkid=2099880.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clickonceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clickonceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_commandlineflagsecuritywarningsenabled","displayName":"Enable security warnings for command-line flags (User)","description":"If disabled, this policy prevents security warnings from appearing when Microsoft Edge is launched with potentially dangerous command-line flags.\r\n\r\nIf enabled or unset, security warnings are displayed when these command-line flags are used to launch Microsoft Edge.\r\n\r\nFor example, the --disable-gpu-sandbox flag generates this warning: You're using an unsupported command-line flag: --disable-gpu-sandbox. This poses stability and security risks.\r\n\r\nOn Windows, this policy is only available on instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro (or Enterprise) instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_commandlineflagsecuritywarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_commandlineflagsecuritywarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_directinvokeenabled","displayName":"Allow users to open files using the DirectInvoke protocol (User)","description":"Allow users to open files using the DirectInvoke protocol. The DirectInvoke protocol allows websites to request that the browser open files from a specific URL using a specific file handler on the user's computer or device.\r\n\r\nIf you enable or don't configure this policy, users can open files using the DirectInvoke protocol.\r\n\r\nIf you disable this policy, users can't open files using the DirectInvoke protocol. Instead, the file will be saved to the file system.\r\n\r\nNote: Disabling DirectInvoke may prevent certain Microsoft SharePoint Online features from working as expected.\r\n\r\nFor more information about DirectInvoke, see https://go.microsoft.com/fwlink/?linkid=2103872 and https://go.microsoft.com/fwlink/?linkid=2099871.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_directinvokeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_directinvokeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_edgecollectionsenabled","displayName":"Enable the Collections feature (User)","description":"Lets you allow users to access the Collections feature, where they can collect, organize, share, and export content more efficiently and with Office integration.\r\n\r\nIf you enable or don't configure this policy, users can access and use the Collections feature in Microsoft Edge.\r\n\r\nIf you disable this policy, users can't access and use Collections in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_edgecollectionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_edgecollectionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_enterprisehardwareplatformapienabled","displayName":"Allow managed extensions to use the Enterprise Hardware Platform API (User)","description":"When this policy is set to enabled, extensions installed by enterprise policy are allowed to use the Enterprise Hardware Platform API.\r\nWhen this policy is set to disabled or isn't set, no extensions are allowed to use the Enterprise Hardware Platform API.\r\nThis policy also applies to component extensions.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_enterprisehardwareplatformapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_enterprisehardwareplatformapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_forcenetworkinprocess","displayName":"Force networking code to run in the browser process (User)","description":"This policy forces networking code to run in the browser process.\r\n\r\nThis policy is disabled by default. If enabled, users are open to security issues when the networking process is sandboxed.\r\n\r\nThis policy is intended to give enterprises a chance to migrate to 3rd party software that doesn't depend on hooking networking APIs. Proxy servers are recommended over LSPs and Win32 API patching.\r\n\r\nIf this policy isn't set, networking code may run out of the browser process depending on field trials of the NetworkService experiment.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_forcenetworkinprocess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_forcenetworkinprocess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_gotointranetsiteforsinglewordentryinaddressbar","displayName":"Force direct intranet site navigation instead of searching on single word entries in the Address Bar (User)","description":"If you enable this policy, the top auto-suggest result in the address bar suggestion list will navigate to intranet sites if the text entered in the address bar is a single word without punctuation.\r\n\r\nDefault navigation when typing a single word without punctuation will conduct a navigation to an intranet site matching the entered text.\r\n\r\nIf you enable this policy, the second auto-suggest result in the address bar suggestion list will conduct a web search exactly as it was entered, provided that this text is a single word without punctuation. The default search provider will be used unless a policy to prevent web search is also enabled.\r\n\r\nTwo effects of enabling this policy are:\r\n\r\nNavigation to sites in response to single word queries that would typically resolve to a history item will no longer happen. Instead, the browser will attempt navigate to internal sites that may not exist in an organization’s intranet. This will result in a 404 error.\r\n\r\nPopular, single-word search terms will require manual selection of search suggestions to properly conduct a search.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_gotointranetsiteforsinglewordentryinaddressbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_gotointranetsiteforsinglewordentryinaddressbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_importbrowsersettings","displayName":"Allow importing of browser settings (User)","description":"Allows users to import browser settings from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browser settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_importbrowsersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_importbrowsersettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist","displayName":"Configure the Enterprise Mode Site List (User)","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210\r\n\r\nExample value: https://internal.contoso.com/sitelist.xml","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist_internetexplorerintegrationsitelist","displayName":"Configure the Enterprise Mode Site List (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled","displayName":"Configure whether a user always has a default profile automatically signed in with their work or school account (User)","description":"This policy determines if a user can remove the Microsoft Edge profile automatically signed in with a user's work or school account.\r\n\r\nIf you enable this policy, a non-removable profile will be created with the user's work or school account on Windows. This profile can't be signed out or removed.\r\n\r\nIf you disable or don't configure this policy, the profile automatically signed in with a user's work or school account on Windows can be signed out or removed by the user.\r\n\r\nIf you want to configure browser sign in, use the 'BrowserSignin' (Browser sign-in settings) policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_clearbrowsingdataonexit_recommended","displayName":"Clear browsing data when Microsoft Edge closes (User)","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\r\n\r\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured 'DefaultCookiesSetting' (Configure cookies)\r\n\r\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\r\n\r\nIf you enable this policy, don't configure the 'AllowDeletingBrowserHistory' (Enable deleting browser and download history) or the 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes) policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured 'AllowDeletingBrowserHistory' or 'ClearCachedImagesAndFilesOnExit'.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_clearbrowsingdataonexit_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_clearbrowsingdataonexit_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_importbrowsersettings_recommended","displayName":"Allow importing of browser settings (User)","description":"Allows users to import browser settings from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browser settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_importbrowsersettings_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_importbrowsersettings_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenfortrusteddownloadsenabled_recommended","displayName":"Force Microsoft Defender SmartScreen checks on downloads from trusted sources (User)","description":"This policy setting lets you configure whether Microsoft Defender SmartScreen checks download reputation from a trusted source.\r\n\r\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download’s reputation regardless of source.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen doesn’t check the download’s reputation when downloading from a trusted source.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenfortrusteddownloadsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenfortrusteddownloadsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_renderercodeintegrityenabled","displayName":"Enable renderer code integrity (deprecated) (User)","description":"If this policy is enabled or left unset, then Renderer Code Integrity is enabled. This policy should only be disabled if compatibility issues are encountered with third party software that must run inside Microsoft Edge's renderer processes.\r\n\r\nDisabling this policy has a detrimental effect on Microsoft Edge's security and stability because unknown and potentially hostile code will be allowed to load inside Microsoft Edge's renderer processes.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_renderercodeintegrityenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_renderercodeintegrityenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support (User)","description":"Enable support for Signed HTTP Exchange (SXG).\r\n\r\nIf this policy isn't set or enabled, Microsoft Edge will accept web contents served as Signed HTTP Exchanges.\r\n\r\nIf this policy is set to disabled, Signed HTTP Exchanges can't be loaded.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_spellchecklanguageblocklist","displayName":"Force disable spellcheck languages (User)","description":"Force-disables spellcheck languages. Unrecognized languages in that list will be ignored.\r\n\r\nIf you enable this policy, spellcheck will be disabled for the languages specified. The user can still enable or disable spellcheck for languages not in the list.\r\n\r\nIf you do not set this policy, or disable it, there will be no change to the user's spellcheck preferences.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy is set to disabled, this policy will have no effect.\r\n\r\nIf a language is included in both the 'SpellcheckLanguage' (Enable specific spellcheck languages) and the 'SpellcheckLanguageBlocklist' policy, the spellcheck language is enabled.\r\n\r\nThe currently supported languages are: af, bg, ca, cs, da, de, el, en-AU, en-CA, en-GB, en-US, es, es-419, es-AR, es-ES, es-MX, es-US, et, fa, fo, fr, he, hi, hr, hu, id, it, ko, lt, lv, nb, nl, pl, pt-BR, pt-PT, ro, ru, sh, sk, sl, sq, sr, sv, ta, tg, tr, uk, vi.\r\n\r\nExample value:\r\n\r\nfr\r\nes","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_spellchecklanguageblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_spellchecklanguageblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_spellchecklanguageblocklist_spellchecklanguageblocklistdesc","displayName":"Force disable spellcheck languages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention","displayName":"Block tracking of users' web-browsing activity (User)","description":"Lets you decide whether to block websites from tracking users' web-browsing activity.\r\n\r\nIf you enable this policy, you have the following options for setting the level of tracking prevention:\r\n\r\n* 0 = Off (no tracking prevention)\r\n\r\n* 1 = Basic (blocks harmful trackers, content and ads will be personalized)\r\n\r\n* 2 = Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)\r\n\r\n* 3 = Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)\r\n\r\nIf you disable this policy or don't configure it, users can set their own level of tracking prevention.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_trackingprevention","displayName":"Block tracking of users' web-browsing activity (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_trackingprevention_0","displayName":"Off (no tracking prevention)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_trackingprevention_1","displayName":"Basic (blocks harmful trackers, content and ads will be personalized)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_trackingprevention_2","displayName":"Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_trackingprevention_3","displayName":"Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge~smartscreen_smartscreenfortrusteddownloadsenabled","displayName":"Force Microsoft Defender SmartScreen checks on downloads from trusted sources (User)","description":"This policy setting lets you configure whether Microsoft Defender SmartScreen checks download reputation from a trusted source.\r\n\r\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download’s reputation regardless of source.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen doesn’t check the download’s reputation when downloading from a trusted source.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge~smartscreen_smartscreenfortrusteddownloadsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge~smartscreen_smartscreenfortrusteddownloadsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_allowsyncxhrinpagedismissal","displayName":"Allow pages to send synchronous XHR requests during page dismissal (User)","description":"This policy lets you specify that a page can send synchronous XHR requests during page dismissal.\r\n\r\nIf you enable this policy, pages can send synchronous XHR requests during page dismissal.\r\n\r\nIf you disable this policy or don't configure this policy, pages aren't allowed to send synchronous XHR requests during page dismissal.\r\n\r\nThis policy is temporary and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_allowsyncxhrinpagedismissal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_allowsyncxhrinpagedismissal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_backgroundtemplatelistupdatesenabled","displayName":"Enables background updates to the list of available templates for Collections and other features that use templates (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because we are moving to a new policy. It won't work in Microsoft Edge as soon as version 104. The new policy to use is 'EdgeAssetDeliveryServiceEnabled' (Allow features to download assets from the Asset Delivery Service).\r\n\r\nLets you enable or disable background updates to the list of available templates for Collections and other features that use templates. Templates are used to extract rich metadata from a webpage when the page is saved to a collection.\r\n\r\nIf you enable this setting or the setting is unconfigured, the list of available templates will be downloaded in the background from a Microsoft service every 24 hours.\r\n\r\nIf you disable this setting the list of available templates will be downloaded on demand. This type of download might result in small performance penalties for Collections and other features.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_backgroundtemplatelistupdatesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_backgroundtemplatelistupdatesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_customhelplink","displayName":"Specify custom help link (User)","description":"Specify a link for the Help menu or the F1 key.\r\n\r\nIf you enable this policy, an admin can specify a link for the Help menu or the F1 key.\r\n\r\nIf you disable or don't configure this policy, the default link for the Help menu or the F1 key is used.\r\n\r\nExample value: https://go.microsoft.com/fwlink/?linkid=2080734","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_customhelplink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_customhelplink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_customhelplink_customhelplink","displayName":"Specify custom help link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_externalprotocoldialogshowalwaysopencheckbox","displayName":"Show an \"Always open\" checkbox in external protocol dialog (User)","description":"This policy controls whether the \"Always allow this site to open links of this type\" checkbox is shown on external protocol launch confirmation prompts.\r\n\r\nIf you set this policy to True, when an external protocol confirmation prompt is shown, the user can select \"Always allow\" to skip all future confirmation prompts for the protocol on this site.\r\n\r\nIf you set this policy to False, the \"Always allow\" checkbox isn't displayed. The user will be prompted for confirmation every time an external protocol is invoked.\r\n\r\nIf this policy is unset, the checkbox visibility is controlled by the \"Enable remembering protocol launch prompting preferences\" flag in edge://flags","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_externalprotocoldialogshowalwaysopencheckbox_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_externalprotocoldialogshowalwaysopencheckbox_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist","displayName":"Configure the list of names that will bypass the HSTS policy check (User)","description":"Hostnames specified in this list will be exempt from the HSTS policy check that could potentially upgrade requests from \"http://\" to \"https://\". Only single-label hostnames are allowed in this policy. Hostnames must be canonicalized. Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific hostnames specified; it doesn't apply to subdomains of the names in the list.\r\n\r\nExample value:\r\n\r\nmeet","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist_hstspolicybypasslistdesc","displayName":"Configure the list of names that will bypass the HSTS policy check (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_importopentabs","displayName":"Allow importing of open tabs (User)","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_importopentabs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_importopentabs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended","displayName":"Allow importing of open tabs (User)","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagemanagedquicklinks_recommended","displayName":"Set new tab page quick links (User)","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\r\n\r\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\r\n\r\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' is not provided, the URL is used as the default title. If 'pinned' is not provided, the default value is false.\r\n\r\nMicrosoft Edge presents these in the order listed, from left to right, with all pinned tiles displayed ahead of non-pinned tiles.\r\n\r\nIf the policy is set as mandatory, the 'pinned' field will be ignored and all tiles will be pinned. The tiles can't be deleted by the user and will always appear at the front of the quick links list.\r\n\r\nIf the policy is set as recommended, pinned tiles will remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying non-pinned links via this policy to an existing browser profile, the links may not appear at all, depending on how they rank compared to the user's browsing history.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"pinned\": true,\r\n \"title\": \"Contoso Portal\",\r\n \"url\": \"https://contoso.com\"\r\n },\r\n {\r\n \"title\": \"Fabrikam\",\r\n \"url\": \"https://fabrikam.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagemanagedquicklinks_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagemanagedquicklinks_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagemanagedquicklinks_recommended_newtabpagemanagedquicklinks","displayName":"Set new tab page quick links (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagesetfeedtype_recommended","displayName":"Configure the Microsoft Edge new tab page experience (User)","description":"Lets you choose either the Microsoft News or Office 365 feed experience for the new tab page.\r\n\r\nWhen you set this policy to Microsoft News feed experience (0), users will see the Microsoft News feed experience on the new tab page.\r\n\r\nWhen you set this policy to Office 365 feed experience (1), users with an Azure Active Directory browser sign-in will see the Office 365 feed experience on the new tab page.\r\n\r\nIf you disable or don't configure this policy:\r\n\r\n- Users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, as well as the standard new tab page feed experience.\r\n\r\n- Users without an Azure Active Directory browser sign-in will see the standard new tab page experience.\r\n\r\nIf you configure this policy *and* the 'NewTabPageLocation' (Configure the new tab page URL) policy, 'NewTabPageLocation' has precedence.\r\n\r\nDefault setting: Disabled or not configured.\r\n\r\n* 0 = Microsoft News feed experience\r\n\r\n* 1 = Office 365 feed experience","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagesetfeedtype_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagesetfeedtype_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagesetfeedtype_recommended_newtabpagesetfeedtype","displayName":"New tab page experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagesetfeedtype_recommended_newtabpagesetfeedtype_0","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended~startup_recommended_newtabpagesetfeedtype_recommended_newtabpagesetfeedtype_1","displayName":"Office 365 feed experience","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_tabfreezingenabled","displayName":"Allow freezing of background tabs (User)","description":"Controls whether Microsoft Edge can freeze tabs that are in the background for at least 5 minutes.\r\n\r\nTab freezing reduces CPU, battery, and memory usage. Microsoft Edge uses heuristics to avoid freezing tabs that do useful work in the background, such as display notifications, play sound, and stream video.\r\n\r\nIf you enable or don't configure this policy, tabs that have been in the background for at least 5 minutes might be frozen.\r\n\r\nIf you disable this policy, no tabs will be frozen.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_tabfreezingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_tabfreezingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagecompanylogo","displayName":"Set new tab page company logo (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nWe are deprecating this policy because it doesn't work as expected and recommend that it not be used.\r\n\r\nSpecifies the company logo to use on the new tab page in Microsoft Edge.\r\n\r\nThe policy should be configured as a string that expresses the logo(s) in JSON format. For example: { \"default_logo\": { \"url\": \"https://www.contoso.com/logo.png\", \"hash\": \"cd0aa9856147b6c5b4ff2b7dfee5da20aa38253099ef1b4a64aced233c9afe29\" }, \"light_logo\": { \"url\": \"https://www.contoso.com/light_logo.png\", \"hash\": \"517d286edb416bb2625ccfcba9de78296e90da8e32330d4c9c8275c4c1c33737\" } }\r\n\r\nYou configure this policy by specifying the URL from which Microsoft Edge can download the logo and its cryptographic hash (SHA-256), which is used to verify the integrity of the download. The logo must be in PNG or SVG format, and its file size must not exceed 16 MB. The logo is downloaded and cached, and it will be redownloaded whenever the URL or the hash changes. The URL must be accessible without any authentication.\r\n\r\nThe 'default_logo' is required and will be used when there's no background image. If 'light_logo' is provided, it will be used when the user's new tab page has a background image. We recommend a horizontal logo with a transparent background that is left-aligned and vertically centered. The logo should have a minimum height of 32 pixels and an aspect ratio from 1:1 to 4:1. The 'default_logo' should have proper contrast against a white/black background while the 'light_logo' should have proper contrast against a background image.\r\n\r\nIf you enable this policy, Microsoft Edge downloads and shows the specified logo(s) on the new tab page. Users can't override or hide the logo(s).\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will show no company logo or a Microsoft logo on the new tab page.\r\n\r\nFor help with determining the SHA-256 hash, see https://docs.microsoft.com/powershell/module/microsoft.powershell.utility/get-filehash.\r\n\r\nExample value:\r\n\r\n{\r\n \"light_logo\": {\r\n \"url\": \"https://www.contoso.com/light_logo.png\", \r\n \"hash\": \"517d286edb416bb2625ccfcba9de78296e90da8e32330d4c9c8275c4c1c33737\"\r\n }, \r\n \"default_logo\": {\r\n \"url\": \"https://www.contoso.com/logo.png\", \r\n \"hash\": \"cd0aa9856147b6c5b4ff2b7dfee5da20aa38253099ef1b4a64aced233c9afe29\"\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagecompanylogo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagecompanylogo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagecompanylogo_newtabpagecompanylogo","displayName":"New tab page company logo (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks","displayName":"Set new tab page quick links (User)","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\r\n\r\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\r\n\r\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' is not provided, the URL is used as the default title. If 'pinned' is not provided, the default value is false.\r\n\r\nMicrosoft Edge presents these in the order listed, from left to right, with all pinned tiles displayed ahead of non-pinned tiles.\r\n\r\nIf the policy is set as mandatory, the 'pinned' field will be ignored and all tiles will be pinned. The tiles can't be deleted by the user and will always appear at the front of the quick links list.\r\n\r\nIf the policy is set as recommended, pinned tiles will remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying non-pinned links via this policy to an existing browser profile, the links may not appear at all, depending on how they rank compared to the user's browsing history.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"pinned\": true,\r\n \"title\": \"Contoso Portal\",\r\n \"url\": \"https://contoso.com\"\r\n },\r\n {\r\n \"title\": \"Fabrikam\",\r\n \"url\": \"https://fabrikam.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks_newtabpagemanagedquicklinks","displayName":"Set new tab page quick links (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype","displayName":"Configure the Microsoft Edge new tab page experience (User)","description":"Lets you choose either the Microsoft News or Office 365 feed experience for the new tab page.\r\n\r\nWhen you set this policy to Microsoft News feed experience (0), users will see the Microsoft News feed experience on the new tab page.\r\n\r\nWhen you set this policy to Office 365 feed experience (1), users with an Azure Active Directory browser sign-in will see the Office 365 feed experience on the new tab page.\r\n\r\nIf you disable or don't configure this policy:\r\n\r\n- Users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, as well as the standard new tab page feed experience.\r\n\r\n- Users without an Azure Active Directory browser sign-in will see the standard new tab page experience.\r\n\r\nIf you configure this policy *and* the 'NewTabPageLocation' (Configure the new tab page URL) policy, 'NewTabPageLocation' has precedence.\r\n\r\nDefault setting: Disabled or not configured.\r\n\r\n* 0 = Microsoft News feed experience\r\n\r\n* 1 = Office 365 feed experience","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype","displayName":"New tab page experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype_0","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype_1","displayName":"Office 365 feed experience","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_alternateerrorpagesenabled","displayName":"Suggest similar pages when a webpage can’t be found (User)","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\r\n\r\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\r\n\r\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Suggest similar pages when a webpage can’t be found** toggle, which the user can switch on or off. Note that if you have enable this policy (AlternateErrorPagesEnabled), the Suggest similar pages when a webpage can’t be found setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the Suggest similar pages when a webpage can’t be found setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_alternateerrorpagesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_alternateerrorpagesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_dnsinterceptionchecksenabled","displayName":"DNS interception checks enabled (User)","description":"This policy configures a local switch that can be used to disable DNS interception checks. These checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\r\n\r\nThis detection might not be necessary in an enterprise environment where the network configuration is known. It can be disabled to avoid additional DNS and HTTP traffic on start-up and each DNS configuration change.\r\n\r\nIf you enable or don’t set this policy, the DNS interception checks are performed.\r\n\r\nIf you disable this policy, DNS interception checks aren’t performed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_dnsinterceptionchecksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_dnsinterceptionchecksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_hidefirstrunexperience","displayName":"Hide the First-run experience and splash screen (User)","description":"If you enable this policy, the First-run experience and the splash screen will not be shown to users when they run Microsoft Edge for the first time.\r\n\r\nFor the configuration options shown in the First Run Experience, the browser will default to the following:\r\n\r\n-On the New Tab Page, the feed type will be set to MSN News and the layout to Inspirational.\r\n\r\n-The user will still be automatically signed into Microsoft Edge if the Windows account is of Azure AD or MSA type.\r\n\r\n-Sync will not be enabled by default and users will be able to turn on sync from the sync settings.\r\n\r\nIf you disable or don't configure this policy, the First-run experience and the Splash screen will be shown.\r\n\r\nNote: The specific configuration options shown to the user in the First Run Experience, can also be managed by using other specific policies. You can use the HideFirstRunExperience policy in combination with these policies to configure a specific browser experience on your managed devices. Some of these other policies are:\r\n\r\n-'AutoImportAtFirstRun' (Automatically import another browser's data and settings at first run)\r\n\r\n-'NewTabPageLocation' (Configure the new tab page URL)\r\n\r\n-'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience)\r\n\r\n-'SyncDisabled' (Disable synchronization of data using Microsoft sync services)\r\n\r\n-'BrowserSignin' (Browser sign-in settings)\r\n\r\n-'NonRemovableProfileEnabled' (Configure whether a user always has a default profile automatically signed in with their work or school account)","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_hidefirstrunexperience_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_hidefirstrunexperience_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_paymentmethodqueryenabled","displayName":"Allow websites to query for available payment methods (User)","description":"Allows you to set whether websites can check if the user has payment methods saved.\r\n\r\nIf you disable this policy, websites that use PaymentRequest.canMakePayment or PaymentRequest.hasEnrolledInstrument API will be informed that no payment methods are available.\r\n\r\nIf you enable this policy or don't set this policy, websites can check if the user has payment methods saved.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_paymentmethodqueryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_paymentmethodqueryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_personalizationreportingenabled","displayName":"Allow personalization of ads, search and news by sending browsing history to Microsoft (User)","description":"This policy prevents Microsoft from collecting a user's Microsoft Edge browsing history to be used for personalizing advertising, search, news and other Microsoft services.\r\n\r\nThis setting is only available for users with a Microsoft account. This setting is not available for child accounts or enterprise accounts.\r\n\r\nIf you disable this policy, users can't change or override the setting. If this policy is enabled or not configured, Microsoft Edge will default to the user’s preference.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_personalizationreportingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_personalizationreportingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_pinningwizardallowed","displayName":"Allow Pin to taskbar wizard (User)","description":"Microsoft Edge uses the Pin to taskbar wizard to help users pin suggested sites to the taskbar. The Pin to taskbar wizard feature is enabled by default and accessible to the user through the Settings and more menu.\r\n\r\nIf you enable this policy or don't configure it, users can call the Pin to taskbar wizard from the Settings and More menu. The wizard can also be called via a protocol launch.\r\n\r\nIf you disable this policy, the Pin to taskbar wizard is disabled in the menu and cannot be called via a protocol launch.\r\n\r\nUser settings to enable or disable the Pin to taskbar wizard aren't available.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_pinningwizardallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_pinningwizardallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended","displayName":"Suggest similar pages when a webpage can’t be found (User)","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\r\n\r\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\r\n\r\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Suggest similar pages when a webpage can’t be found** toggle, which the user can switch on or off. Note that if you have enable this policy (AlternateErrorPagesEnabled), the Suggest similar pages when a webpage can’t be found setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the Suggest similar pages when a webpage can’t be found setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenpuaenabled_recommended","displayName":"Configure Microsoft Defender SmartScreen to block potentially unwanted apps (User)","description":"This policy setting lets you configure whether to turn on blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default.\r\n\r\nIf you enable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenpuaenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenpuaenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb","displayName":"Set limit on megabytes of memory a single Microsoft Edge instance can use. (User)","description":"Configures the amount of memory that a single Microsoft Edge instance can use before tabs start getting discarded to save memory. The memory used by the tab will be freed and the tab will have to be reloaded when switched to.\r\n\r\nIf you enable this policy, the browser will start to discard tabs to save memory once the limitation is exceeded. However, there is no guarantee that the browser is always running under the limit. Any value under 1024 will be rounded up to 1024.\r\n\r\nIf you don't set this policy, the browser will only attempt to save memory when it has detected that the amount of physical memory on its machine is low.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb_totalmemorylimitmb","displayName":"Set memory limit for Microsoft Edge instances: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist","displayName":"Configure list of force-installed Web Apps (User)","description":"Specifies a list of websites that are installed silently, without user interaction, and which can't be uninstalled or disabled by the user.\r\n\r\nEach list item of the policy is an object with the following members:\r\n - \"url\", which is mandatory. \"url\" should be the URL of the web app to install.\r\n\r\nValues for the optional members are:\r\n - \"launch_container\" should be either \"window\" or \"tab\" to indicate how the Web App will be opened after it's installed.\r\n - \"create_desktop_shortcut\" should be true if a desktop shortcut should be created on Windows.\r\n\r\nIf \"default_launch_container\" is omitted, the app will open in a tab by default. Regardless of the value of \"default_launch_container\", users can change which container the app will open in. If \"create_desktop_shortcuts\" is omitted, no desktop shortcuts will be created.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.contoso.com/maps\", \r\n \"create_desktop_shortcut\": true, \r\n \"default_launch_container\": \"window\"\r\n }, \r\n {\r\n \"url\": \"https://app.contoso.edu\", \r\n \"default_launch_container\": \"tab\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist_webappinstallforcelist","displayName":"URLs for Web Apps to be silently installed. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84. (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThe Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and have been disabled by default starting in M80. This policy allows these features to be selectively re-enabled until M84.\r\n\r\n If you set this policy is set to True, the Web Components v0 features will be enabled for all sites.\r\n\r\n If you set this policy to False or don't set this policy, the Web Components v0 features will be disabled by default, starting in M80.\r\n\r\n This policy will be removed after Microsoft Edge 84.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webcomponentsv0enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webcomponentsv0enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webrtclocalipsallowedurls","displayName":"Manage exposure of local IP addressess by WebRTC (User)","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*contoso.com*\") for which local IP address should be exposed by WebRTC.\r\n\r\nIf you enable this policy and set a list of origins (URLs) or hostname patterns, when edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will expose the local IP address for cases that match patterns in the list.\r\n\r\nIf you disable or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will not expose local IP addresses. The local IP address is concealed with an mDNS hostname.\r\n\r\nIf you enable, disable, or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, WebRTC will expose local IP addresses.\r\n\r\nPlease note that this policy weakens the protection of local IP addresses that might be needed by administrators.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n*contoso.com*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webrtclocalipsallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webrtclocalipsallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webrtclocalipsallowedurls_webrtclocalipsallowedurlsdesc","displayName":"Manage exposure of local IP addressess by WebRTC (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (User)","description":"Allows you to set whether users can add exceptions to allow mixed content for specific sites.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'InsecureContentAllowedForUrls' (Allow insecure content on specified sites) and 'InsecureContentBlockedForUrls' (Block insecure content on specified sites) policies.\r\n\r\nIf this policy isn't set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.\r\n\r\n* 2 = Do not allow any site to load blockable mixed content\r\n\r\n* 3 = Allow users to add exceptions to allow blockable mixed content","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_2","displayName":"Do not allow any site to load blockable mixed content","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_3","displayName":"Allow users to add exceptions to allow blockable mixed content","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentallowedforurls","displayName":"Allow insecure content on specified sites (User)","description":"Create a list of URL patterns to specify sites that can display insecure mixed content (that is, HTTP content on HTTPS sites).\r\n\r\nIf you don't configure this policy, blockable mixed content will be blocked and optionally blockable mixed content will be upgraded. However, users will be allowed to set exceptions to allow insecure mixed content for specific sites.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentallowedforurls_insecurecontentallowedforurlsdesc","displayName":"Allow insecure content on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls","displayName":"Block insecure content on specified sites (User)","description":"Create a list of URL patterns to specify sites that aren't allowed to display blockable (i.e. active) mixed content (that is, HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled.\r\n\r\nIf you don't configure this policy, blockable mixed content will be blocked and optionally blockable mixed content will be upgraded. However, users will be allowed to set exceptions to allow insecure mixed content for specific sites.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls_insecurecontentblockedforurlsdesc","displayName":"Block insecure content on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled","displayName":"Enable default legacy SameSite cookie behavior setting (obsolete) (User)","description":"Lets you revert all cookies to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", and removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute.\r\n\r\nYou can set the following values for this policy:\r\n\r\n* 1 = Revert to legacy SameSite behavior for cookies on all sites\r\n\r\n* 2 = Use SameSite-by-default behavior for cookies on all sites\r\n\r\nIf you don't set this policy, the default behavior for cookies that don't specify a SameSite attribute will depend on other configuration sources for the SameSite-by-default feature. This feature might be set by a field trial or by enabling the same-site-by-default-cookies flag in edge://flags.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled","displayName":"Enable default legacy SameSite cookie behavior setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_1","displayName":"Revert to legacy SameSite behavior for cookies on all sites","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_2","displayName":"Use SameSite-by-default behavior for cookies on all sites","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist","displayName":"Revert to legacy SameSite behavior for cookies on specified sites (obsolete) (User)","description":"Cookies set for domains match specified patterns will revert to legacy SameSite behavior.\r\n\r\nReverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", and removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute.\r\n\r\nIf you don't set this policy, the global default value will be used. The global default will also be used for cookies on domains not covered by the patterns you specify.\r\n\r\nThe global default value can be configured using the 'LegacySameSiteCookieBehaviorEnabled' (Enable default legacy SameSite cookie behavior setting) policy. If 'LegacySameSiteCookieBehaviorEnabled' is unset, the global default value falls back to other configuration sources.\r\n\r\nNote that patterns you list in this policy are treated as domains, not URLs, so you should not specify a scheme or port.\r\n\r\nExample value:\r\n\r\nwww.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_legacysamesitecookiebehaviorenabledfordomainlistdesc","displayName":"Revert to legacy SameSite behavior for cookies on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled","displayName":"Configure Microsoft Defender SmartScreen to block potentially unwanted apps (User)","description":"This policy setting lets you configure whether to turn on blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default.\r\n\r\nIf you enable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_addressbarmicrosoftsearchinbingproviderenabled","displayName":"Enable Microsoft Search in Bing suggestions in the address bar (User)","description":"Enables the display of relevant Microsoft Search in Bing suggestions in the address bar's suggestion list when the user types a search string in the address bar. If you enable or don't configure this policy, users can see internal results powered by Microsoft Search in Bing in the Microsoft Edge address bar suggestion list. To see the Microsoft Search in Bing results, the user must be signed into Microsoft Edge with their Azure AD account for that organization.\r\nIf you disable this policy, users can't see internal results in the Microsoft Edge address bar suggestion list.\r\nIf you have enabled the set of policies which forces a default search provider ('DefaultSearchProviderEnabled' (Enable the default search provider), 'DefaultSearchProviderName' (Default search provider name) and 'DefaultSearchProviderSearchURL' (Default search provider search URL)), and the search provider specified is not Bing, then this policy is not applicable and there will be no Microsoft Search in Bing suggestions in the address bar's suggestion list.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_addressbarmicrosoftsearchinbingproviderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_addressbarmicrosoftsearchinbingproviderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for InPrivate and Guest profiles (User)","description":"Configure this policy to allow/disallow ambient authentication for InPrivate and Guest profiles in Microsoft Edge.\r\n\r\nAmbient Authentication is http authentication with default credentials when explicit credentials aren't provided via NTLM/Kerberos/Negotiate challenge/response schemes.\r\n\r\nIf you set the policy to RegularOnly (value 0), it allows ambient authentication for Regular sessions only. InPrivate and Guest sessions won't be allowed to ambiently authenticate.\r\n\r\nIf you set the policy to InPrivateAndRegular (value 1), it allows ambient authentication for InPrivate and Regular sessions. Guest sessions won't be allowed to ambiently authenticate.\r\n\r\nIf you set the policy to GuestAndRegular (value 2), it allows ambient authentication for Guest and Regular sessions. InPrivate sessions won't be allowed to ambiently authenticate\r\n\r\nIf you set the policy to All (value 3), it allows ambient authentication for all sessions.\r\n\r\nNote that ambient authentication is always allowed on regular profiles.\r\n\r\nIn Microsoft Edge version 81 and later, if the policy is left not set, ambient authentication will be enabled in regular sessions only.\r\n\r\n* 0 = Enable ambient authentication in regular sessions only\r\n\r\n* 1 = Enable ambient authentication in InPrivate and regular sessions\r\n\r\n* 2 = Enable ambient authentication in guest and regular sessions\r\n\r\n* 3 = Enable ambient authentication in regular, InPrivate and guest sessions","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for InPrivate and Guest profiles (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_0","displayName":"Enable ambient authentication in regular sessions only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_1","displayName":"Enable ambient authentication in InPrivate and regular sessions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_2","displayName":"Enable ambient authentication in guest and regular sessions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_3","displayName":"Enable ambient authentication in regular, InPrivate and guest sessions","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_audiosandboxenabled","displayName":"Allow the audio sandbox to run (User)","description":"This policy controls the audio process sandbox.\r\n\r\nIf you enable this policy, the audio process will run sandboxed.\r\n\r\nIf you disable this policy, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\r\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\r\n\r\nIf you don't configure this policy, the default configuration for the audio sandbox will be used, which might differ based on the platform.\r\n\r\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_audiosandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_audiosandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin","displayName":"Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account (User)","description":"Enable the use of Active Directory accounts for automatic sign in if your users' machines are Domain Joined and your environment is not hybrid joined. If you want users automatically signed in with their Azure Active Directory accounts instead, please Azure AD join (See https://go.microsoft.com/fwlink/?linkid=2118197 for more information) or hybrid join (See https://go.microsoft.com/fwlink/?linkid=2118365 for more information) your environment.\r\n\r\nIf you have configured the 'BrowserSignin' (Browser sign-in settings) policy to disabled, this policy will not take any effect.\r\n\r\nIf you enable this policy and set it to \"Sign in and make domain account non-removable\", Microsoft Edge will automatically sign in users that are on domain joined machines using their Active Directory accounts.\r\n\r\nIf you set this policy to \"Disabled\" or don't set it, Microsoft Edge will not automatically sign in users that are on domain joined machines with Active Directory accounts.\r\n\r\n* 0 = Disabled\r\n\r\n* 1 = Sign in and make domain account non-removable","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_configureonpremisesaccountautosignin","displayName":"Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_configureonpremisesaccountautosignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_configureonpremisesaccountautosignin_1","displayName":"Sign in and make domain account non-removable","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_forcelegacydefaultreferrerpolicy","displayName":"Use a default referrer policy of no-referrer-when-downgrade. (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis enterprise policy is for short-term adaptation and will be removed in M83.\r\n\r\nMicrosoft Edge’s default referrer policy is being strengthened from its current value of no-referrer-when-downgrade to the more secure strict-origin-when-cross-origin through a gradual rollout targeting M80 stable.\r\n\r\nBefore the rollout, this enterprise policy will have no effect. After the rollout, when this enterprise policy is enabled, Microsoft Edge’s default referrer policy will be set to its pre-M80 value of no-referrer-when-downgrade.\r\n\r\nThis enterprise policy is disabled by default","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_forcelegacydefaultreferrerpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_forcelegacydefaultreferrerpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache (User)","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\r\n\r\nIf you disable or don’t set this policy, the browser will use the default behavior of cross-site auth, which as of version 80, will be to scope HTTP server authentication credentials by top-level site. So, if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites.\r\n\r\nIf you enable this policy HTTP auth credentials entered in the context of one site will automatically be used in the context of another site.\r\n\r\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\r\n\r\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_globallyscopehttpauthcacheenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_globallyscopehttpauthcacheenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importcookies","displayName":"Allow importing of Cookies (User)","description":"Allows users to import Cookies from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Cookies aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Cookies are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importcookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importcookies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importextensions","displayName":"Allow importing of extensions (User)","description":"Allows users to import extensions from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts","displayName":"Allow importing of shortcuts (User)","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Shortcuts aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Shortcuts are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect","displayName":"Specify how \"in-page\" navigations to unconfigured sites behave when started from Internet Explorer mode pages (User)","description":"An \"in-page\" navigation is started from a link, a script, or a form on the current page. It can also be a server-side redirect of a previous \"in-page\" navigation attempt. Conversely, a user can start a navigation that isn't \"in-page\" that's independent of the current page in several ways by using the browser controls. For example, using the address bar, the back button, or a favorite link.\r\n\r\nThis setting lets you specify whether navigations from pages loaded in Internet Explorer mode to unconfigured sites (that are not configured in the Enterprise Mode Site List) switch back to Microsoft Edge or remain in Internet Explorer mode.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to \"Internet Explorer mode\" (1)\r\nand\r\n'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry.\r\n\r\nIf you disable or don’t configure this policy, only sites configured to open in Internet Explorer mode will open in that mode. Any site not configured to open in Internet Explorer mode will be redirected back to Microsoft Edge.\r\n\r\nIf you set this policy to Default (value 0), only sites configured to open in Internet Explorer mode will open in that mode. Any site not configured to open in Internet Explorer mode will be redirected back to Microsoft Edge.\r\n\r\nIf you set this policy to AutomaticNavigationsOnly (value 1), you get the default experience except that all automatic navigations (such as 302 redirects) to unconfigured sites will be kept in Internet Explorer mode.\r\n\r\nIf you set this policy to AllInPageNavigations (value 2), all navigations from pages loaded in IE mode to unconfigured sites are kept in Internet Explorer mode (Least Recommended).\r\n\r\nIf you enable this policy, you can choose one of the following navigation options:\r\n\r\n* 0 = Default\r\n\r\n* 1 = Keep only automatic navigations in Internet Explorer mode\r\n\r\n* 2 = Keep all in-page navigations in Internet Explorer mode\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2105106","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect","displayName":"Specify how \"in-page\" navigations to unconfigured sites behave when started from Internet Explorer mode pages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect_1","displayName":"Keep only automatic navigations in Internet Explorer mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect_2","displayName":"Keep all in-page navigations in Internet Explorer mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importcookies_recommended","displayName":"Allow importing of Cookies (User)","description":"Allows users to import Cookies from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Cookies aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Cookies are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importcookies_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importcookies_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importextensions_recommended","displayName":"Allow importing of extensions (User)","description":"Allows users to import extensions from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importextensions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importextensions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importshortcuts_recommended","displayName":"Allow importing of shortcuts (User)","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Shortcuts aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Shortcuts are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importshortcuts_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importshortcuts_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_strictermixedcontenttreatmentenabled","displayName":"Enable stricter treatment for mixed content (User)","description":"This policy controls the treatment for mixed content (HTTP content in HTTPS sites) in the browser.\r\n\r\nIf you set this policy to true or not set, audio and video mixed content will be automatically upgraded to HTTPS (that is, the URL will be rewritten as HTTPS, without a fallback if the resource isn’t available over HTTPS) and a 'Not Secure' warning will be shown in the URL bar for image mixed content.\r\n\r\nIf you set the policy to false, auto upgrades will be disabled for audio and video, and no warning will be shown for images.\r\n\r\nThis policy does not affect other types of mixed content other than audio, video, and images.\r\n\r\nThis policy will no longer take effect starting in Microsoft Edge 84.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_strictermixedcontenttreatmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_strictermixedcontenttreatmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors. (User)","description":"This policy controls a security feature in TLS 1.3 that protects connections against downgrade attacks. It is backwards-compatible and will not affect connections to compliant TLS 1.2 servers or proxies. However, older versions of some TLS-intercepting proxies have an implementation flaw which causes them to be incompatible.\r\n\r\nIf you enable this policy or don't set it, Microsoft Edge will enable these security protections for all connections.\r\n\r\nIf you disable this policy, Microsoft Edge will disable these security protections for connections authenticated with locally-installed CA certificates. These protections are always enabled for connections authenticated with publicly-trusted CA certificates.\r\n\r\nThis policy may be used to test for any affected proxies and upgrade them. Affected proxies are expected to fail connections with an error code of ERR_TLS13_DOWNGRADE_DETECTED. A later version of Microsoft Edge will enable this option by default.\r\n\r\nAfter it is enabled by default, administrators who need more time to upgrade affected proxies may use this policy to temporarily disable this security feature. This policy will be removed after version 85.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev81identitydiff~policy~microsoft_edge_forcecertificatepromptsonmultiplematches","displayName":"Configure whether Microsoft Edge should automatically select a certificate when there are multiple certificate matches for a site configured with \"AutoSelectCertificateForUrls\" (User)","description":"Toggles whether users are prompted to select a certificate if there are multiple certificates available and a site is configured with 'AutoSelectCertificateForUrls' (Automatically select client certificates for these sites). If you don't configure 'AutoSelectCertificateForUrls' for a site, the user will always be prompted to select a certificate.\r\n\r\nIf you set this policy to True, Microsoft Edge will prompt a user to select a certificate for sites on the list defined in 'AutoSelectCertificateForUrls' if and only if there is more than one certificate.\r\n\r\nIf you set this policy to False or don't configure it, Microsoft Edge will automatically select a certificate even if there are multiple matches for a certificate. The user will not be prompted to select a certificate for sites on the list defined in 'AutoSelectCertificateForUrls'.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81identitydiff~policy~microsoft_edge_forcecertificatepromptsonmultiplematches_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81identitydiff~policy~microsoft_edge_forcecertificatepromptsonmultiplematches_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowsurfgame","displayName":"Allow surf game (User)","description":"If you disable this policy, users won't be able to play the surf game when the device is offline or if the user navigates to edge://surf.\r\n\r\nIf you enable or don't configure this policy, users can play the surf game.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowsurfgame_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowsurfgame_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls","displayName":"Configure the list of sites for which Microsoft Edge will attempt to establish a Token Binding with. (User)","description":"Configure the list of URL patterns for sites that the browser will attempt to perform the Token Binding protocol with.\r\nFor the domains on this list, the browser will send the Token Binding ClientHello in the TLS handshake (See https://tools.ietf.org/html/rfc8472).\r\nIf the server responds with a valid ServerHello response, the browser will create and send Token Binding messages on subsequent https requests. See https://tools.ietf.org/html/rfc8471 for more info.\r\n\r\nIf this list is empty, Token Binding will be disabled.\r\n\r\nThis policy is only available on Windows 10 devices with Virtual Secure Mode capability.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\n[*.]mydomain2.com\r\n[*.].mydomain2.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_allowtokenbindingforurlsdesc","displayName":"Configure the list of sites for which Microsoft Edge will attempt to establish a Token Binding with. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_bingadssuppression","displayName":"Block all ads on Bing search results (User)","description":"Enables an ad-free search experience on Bing.com\r\n\r\nIf you enable this policy, then a user can search on bing.com and have an ad-free search experience. At the same time, the SafeSearch setting will be set to 'Strict' and can't be changed by the user.\r\n\r\nIf you don't configure this policy, then the default experience will have ads in the search results on bing.com. SafeSearch will be set to 'Moderate' by default and can be changed by the user.\r\n\r\nThis policy is only available for K-12 SKUs that are identified as EDU tenants by Microsoft.\r\n\r\nPlease refer to https://go.microsoft.com/fwlink/?linkid=2119711 to learn more about this policy or if the following scenarios apply to you:\r\n\r\n* You have an EDU tenant, but the policy doesn't work.\r\n\r\n* You had your IP whitelisted for having an ad free search experience.\r\n\r\n* You were experiencing an ad-free search experience on Microsoft Edge Legacy and want to upgrade to the new version of Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_bingadssuppression_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_bingadssuppression_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_clearcachedimagesandfilesonexit","displayName":"Clear cached images and files when Microsoft Edge closes (User)","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\r\n\r\nIf you enable this policy, cached images and files will be deleted each time Microsoft Edge closes.\r\n\r\nIf you disable this policy, users cannot configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\r\n\r\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\r\n\r\nIf you disable this policy, don't enable the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) policy, because they both deal with deleting data. If you configure both, the 'ClearBrowsingDataOnExit' policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_clearcachedimagesandfilesonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_clearcachedimagesandfilesonexit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare","displayName":"Configure the Share experience (User)","description":"If you set this policy to 'ShareAllowed' (0, the default), users will be able to access the Windows 10 Share experience from the Settings and More Menu in Microsoft Edge to share with other apps on the system.\r\n\r\nIf you set this policy to 'ShareDisallowed' (1), users won't be able to access the Windows 10 Share experience. If the Share button is on the toolbar, it will also be hidden.\r\n\r\n* 0 = Allow using the Share experience\r\n\r\n* 1 = Don't allow using the Share experience\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_configureshare","displayName":"Configure the Share experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_configureshare_0","displayName":"Allow using the Share experience","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_configureshare_1","displayName":"Don't allow using the Share experience","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_deletedataonmigration","displayName":"Delete old browser data on migration (User)","description":"This policy determines whether user browsing data from Microsoft Edge Legacy will be deleted after migrating to the Microsoft Edge version 81 or later.\r\n\r\nIf you set this policy to \"Enabled\", all browsing data from Microsoft Edge Legacy after migrating to the Microsoft Edge version 81 or later will be deleted. This policy must be set before migrating to the Microsoft Edge version 81 or later to have any effect on existing browsing data.\r\n\r\nIf you set this policy to \"Disabled\", or the policy is not configured, user browsing data isn't deleted after migrating to the Microsoft Edge version 83 or later.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_deletedataonmigration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_deletedataonmigration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode","displayName":"Control the mode of DNS-over-HTTPS (User)","description":"Control the mode of the DNS-over-HTTPS resolver. Note that this policy will only set the default mode for each query. The mode can be overridden for special types of queries such as requests to resolve a DNS-over-HTTPS server hostname.\r\n\r\nThe \"off\" mode will disable DNS-over-HTTPS.\r\n\r\nThe \"automatic\" mode will send DNS-over-HTTPS queries first if a DNS-over-HTTPS server is available and may fallback to sending insecure queries on error.\r\n\r\nThe \"secure\" mode will only send DNS-over-HTTPS queries and will fail to resolve on error.\r\n\r\nIf you don't configure this policy, the browser might send DNS-over-HTTPS requests to a resolver associated with the user's configured system resolver.\r\n\r\nExample value: off","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode","displayName":"Control the mode of DNS-over-HTTPS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_off","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_automatic","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_secure","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver (User)","description":"The URI template of the desired DNS-over-HTTPS resolver. To specify multiple DNS-over-HTTPS resolvers, separate the corresponding URI templates with spaces.\r\n\r\nIf you set 'DnsOverHttpsMode' (Control the mode of DNS-over-HTTPS) to \"secure\" then this policy must be set and cannot be empty.\r\n\r\nIf you set 'DnsOverHttpsMode' to \"automatic\" and this policy is set then the URI templates specified will be used. If you don't set this policy, then hardcoded mappings will be used to attempt to upgrade the user's current DNS resolver to a DoH resolver operated by the same provider.\r\n\r\nIf the URI template contains a dns variable, requests to the resolver will use GET; otherwise requests will use POST.\r\n\r\nIncorrectly formatted templates will be ignored.\r\n\r\nExample value: https://dns.example.net/dns-query{?dns}","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpstemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpstemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpstemplates_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_familysafetysettingsenabled","displayName":"Allow users to configure Family safety (User)","description":"This policy disables and completely hides the Family safety page in Settings. Navigation to edge://settings/familysafety will also be blocked. The Family safety page describes what features are available for family groups and how to join a family group. Learn more about family safety here: (https://go.microsoft.com/fwlink/?linkid=2098432).\r\n\r\nIf you enable this policy or don't configure it, the Family safety page will be shown.\r\n\r\nIf you disable this policy, the Family safety page will not be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_familysafetysettingsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_familysafetysettingsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_localprovidersenabled","displayName":"Allow suggestions from local providers (User)","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\r\n\r\nIf you enable this policy, suggestions from local providers are used.\r\n\r\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions will not appear.\r\n\r\nIf you do not configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\r\n\r\nNote that some features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the 'SavingBrowserHistoryDisabled' (Disable saving browser history) policy.\r\n\r\nThis policy requires a browser restart to finish applying.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_localprovidersenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_localprovidersenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_recommended_clearcachedimagesandfilesonexit_recommended","displayName":"Clear cached images and files when Microsoft Edge closes (User)","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\r\n\r\nIf you enable this policy, cached images and files will be deleted each time Microsoft Edge closes.\r\n\r\nIf you disable this policy, users cannot configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\r\n\r\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\r\n\r\nIf you disable this policy, don't enable the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) policy, because they both deal with deleting data. If you configure both, the 'ClearBrowsingDataOnExit' policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_recommended_clearcachedimagesandfilesonexit_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_recommended_clearcachedimagesandfilesonexit_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_recommended_localprovidersenabled_recommended","displayName":"Allow suggestions from local providers (User)","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\r\n\r\nIf you enable this policy, suggestions from local providers are used.\r\n\r\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions will not appear.\r\n\r\nIf you do not configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\r\n\r\nNote that some features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the 'SavingBrowserHistoryDisabled' (Disable saving browser history) policy.\r\n\r\nThis policy requires a browser restart to finish applying.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_recommended_localprovidersenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_recommended_localprovidersenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_screencaptureallowed","displayName":"Allow or deny screen capture (User)","description":"If you enable this policy, or don't configure this policy, a web page can use screen-share APIs (for example, getDisplayMedia() or the Desktop Capture extension API) for a screen capture.\r\nIf you disable this policy, calls to screen-share APIs will fail. For example, if you're using a web-based online meeting, video or screen sharing will not work. However, this policy is not considered\r\n(and a site will be allowed to use screen-share APIs) if the site matches an origin pattern in any of the following policies:\r\n'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins),\r\n'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins),\r\n'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins),\r\n'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_screencaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_screencaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments (User)","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\r\n​\r\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL will be enabled.​\r\n\r\nIf you disable this policy, web page scrolling to specific text fragments via a URL will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_synctypeslistdisabled","displayName":"Configure the list of types that are excluded from synchronization (User)","description":"If you enable this policy all the specified data types will be excluded from synchronization. This policy can be used to limit the type of data uploaded to the Microsoft Edge synchronization service.\r\n\r\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", and “collections”. Note that these data type names are case sensitive.\r\n\r\nUsers will not be able to override the disabled data types.\r\n\r\nExample value:\r\n\r\nfavorites","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_synctypeslistdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_synctypeslistdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_synctypeslistdisabled_synctypeslistdisableddesc","displayName":"Configure the list of types that are excluded from synchronization (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_appcacheforceenabled","displayName":"Allows the AppCache feature to be re-enabled, even if it's turned off by default (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 96.\r\n\r\nSupport for AppCache and this policy was removed from Microsoft Edge starting in version 97.\r\n\r\nIf you set this policy to true, the AppCache is enabled, even when AppCache in Microsoft Edge is not available by default.\r\n\r\nIf you set this policy to false, or don't set it, AppCache will follow Microsoft Edge's defaults.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_appcacheforceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_appcacheforceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload","displayName":"Require that the Enterprise Mode Site List is available before tab navigation (User)","description":"Lets you specify whether Microsoft Edge tabs wait to navigate until the browser has downloaded the initial Enterprise Mode Site List. This setting is intended for the scenario where the browser home page should load in Internet Explorer mode, and it is important that is does so on browser first run after IE mode is enabled. If this scenario does not exist, we recommend not enabling this setting because it can negatively impact the performance of loading the home page. The setting only applies when Microsoft Edge does not have a cached Enterprise Mode Site List, such as on browser first run after IE mode is enabled.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to \"Internet Explorer mode\" (1)\r\nand\r\n'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry.\r\n\r\nThe timeout behavior of this policy can be configured with the 'NavigationDelayForInitialSiteListDownloadTimeout' (Set a timeout for delay of tab navigation for the Enterprise Mode Site List) policy.\r\n\r\nIf you set this policy to 1, when Microsoft Edge does not have a cached version of the Enterprise Mode Site List, tabs delay navigating until the browser has downloaded the site list. Sites configured to open in Internet Explorer mode by the site list will load in Internet Explorer mode, even during the initial navigation of the browser. Sites that cannot possibly be configured to open in Internet Explorer, such as any site with a scheme other than http:, https:, file:, or ftp: do not delay navigating and load immediately in Edge mode.\r\n\r\nIf you set this policy to 0 or don't configure it, when Microsoft Edge does not have a cached version of the Enterprise Mode Site List, tabs will navigate immediately, and not wait for the browser to download the Enterprise Mode Site List. Sites configured to open in Internet Explorer mode by the site list will open in Microsoft Edge mode until the browser has finished downloading the Enterprise Mode Site List.\r\n\r\n* 0 = None\r\n\r\n* 1 = All eligible navigations","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload","displayName":"Require that the Enterprise Mode Site List is available before tab navigation (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload_0","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload_1","displayName":"All eligible navigations","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection","displayName":"Configure enhanced hang detection for Internet Explorer mode (User)","description":"Enhanced hang detection is a more granular approach to detecting hung webpages in Internet Explorer mode than what standalone Internet Explorer uses. When a hung webpage is detected, the browser will apply a mitigation to prevent the rest of the browser from hanging.\r\n\r\nThis setting allows you to configure the use of enhanced hang detection in case you run into incompatible issues with any of your websites. We recommend disabling this policy only if you see notifications such as \"(website) is not responding\" in Internet Explorer mode but not in standalone Internet Explorer.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to \"Internet Explorer mode\" (1)\r\nand\r\n'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry.\r\n\r\nIf you set this policy to 'Enabled' (1) or don’t configure it, websites running in Internet Explorer mode will use enhanced hang detection.\r\n\r\nIf you set this policy to 'Disabled' (0), enhanced hang detection is disabled, and users will get the basic Internet Explorer hang detection behavior.\r\n\r\n* 0 = Enhanced hang detection disabled\r\n\r\n* 1 = Enhanced hang detection enabled\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_internetexplorerintegrationenhancedhangdetection","displayName":"Configure enhanced hang detection for Internet Explorer mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_internetexplorerintegrationenhancedhangdetection_0","displayName":"Enhanced hang detection disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_internetexplorerintegrationenhancedhangdetection_1","displayName":"Enhanced hang detection enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_nativewindowocclusionenabled","displayName":"Enable Hiding of Native Windows (User)","description":"Enables hiding of native windows in Microsoft Edge.\r\n\r\nIf you enable this setting, to reduce CPU and power consumption Microsoft Edge will detect when a window is covered by other windows, and will suspend work painting pixels.\r\n\r\nIf you disable this setting Microsoft Edge will not detect when a window is covered by other windows.\r\n\r\nIf this policy is left not set, window hiding detection will be enabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_nativewindowocclusionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_nativewindowocclusionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_navigationdelayforinitialsitelistdownloadtimeout","displayName":"Set a timeout for delay of tab navigation for the Enterprise Mode Site List (User)","description":"Allows you to set a timeout, in seconds, for Microsoft Edge tabs waiting to navigate until the browser has downloaded the initial Enterprise Mode Site List.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to \"Internet Explorer mode\" (1)\r\nand\r\n'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry\r\nand\r\n'DelayNavigationsForInitialSiteListDownload' (Require that the Enterprise Mode Site List is available before tab navigation) is set to \"All eligible navigations\" (1).\r\n\r\nTabs will not wait longer than this timeout for the Enterprise Mode Site List to download. If the browser has not finished downloading the Enterprise Mode Site List when the timeout expires, Microsoft Edge tabs will continue navigating anyway. The value of the timeout should be no greater than 20 seconds and no fewer than 1 second.\r\n\r\nIf you set the timeout in this policy to a value greater than the default of 2 seconds, an information bar is shown to the user after 2 seconds. The information bar contains a button that allows the user to quit waiting for the Enterprise Mode Site List download to complete.\r\n\r\nIf you don't configure this policy, the default timeout of 2 seconds is used. This default is subject to change in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_navigationdelayforinitialsitelistdownloadtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_navigationdelayforinitialsitelistdownloadtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_navigationdelayforinitialsitelistdownloadtimeout_navigationdelayforinitialsitelistdownloadtimeout","displayName":"Set a timeout for delay of tab navigation for the Enterprise Mode Site List: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended","displayName":"Manage Search Engines (User)","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine.\r\nYou do not need to specify the encoding. Starting in Microsoft Edge 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge 80.\r\n\r\nStarting in Microsoft Edge 83, you can enable search engine discovery with the allow_search_engine_discovery optional parameter. This parameter must be the first item in the list. If allow_search_engine_discovery is not specified, search engine discovery will be disabled by default. Starting in Microsoft Edge 84, you can set this policy as a recommended policy to allow search provider discovery. You do not need to add the allow_search_engine_discovery optional parameter.\r\n\r\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\r\n\r\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\r\n\r\nIf the 'DefaultSearchProviderSearchURL' (Default search provider search URL) policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allow_search_engine_discovery\": true\r\n }, \r\n {\r\n \"is_default\": true, \r\n \"suggest_url\": \"https://www.example1.com/qbox?query={searchTerms}\", \r\n \"search_url\": \"https://www.example1.com/search?q={searchTerms}\", \r\n \"name\": \"Example1\", \r\n \"keyword\": \"example1.com\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example2.com/qbox?query={searchTerms}\", \r\n \"image_search_url\": \"https://www.example2.com/images/detail/search?iss=sbiupload\", \r\n \"name\": \"Example2\", \r\n \"keyword\": \"example2.com\", \r\n \"image_search_post_params\": \"content={imageThumbnail},url={imageURL},sbisrc={SearchSource}\", \r\n \"search_url\": \"https://www.example2.com/search?q={searchTerms}\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example3.com/qbox?query={searchTerms}\", \r\n \"search_url\": \"https://www.example3.com/search?q={searchTerms}\", \r\n \"name\": \"Example3\", \r\n \"keyword\": \"example3.com\", \r\n \"encoding\": \"UTF-8\", \r\n \"image_search_url\": \"https://www.example3.com/images/detail/search?iss=sbiupload\"\r\n }, \r\n {\r\n \"search_url\": \"https://www.example4.com/search?q={searchTerms}\", \r\n \"name\": \"Example4\", \r\n \"keyword\": \"example4.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended_managedsearchengines","displayName":"Manage Search Engines (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended","displayName":"Enable the default search provider (User)","description":"Enables the ability to use a default search provider.\r\n\r\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\r\n\r\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider.\r\n\r\nIf you disable this policy, the user can't search from the address bar.\r\n\r\nIf you enable or disable this policy, users can't change or override it.\r\n\r\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy.","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended","displayName":"Default search provider encodings (User)","description":"Specify the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They are tried in the order provided.\r\n\r\nThis policy is optional. If not configured, the default, UTF-8, is used.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value:\r\n\r\nUTF-8\r\nUTF-16\r\nGB2312\r\nISO-8859-1","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended","displayName":"Specifies the search-by-image feature for the default search provider (User)","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\r\n\r\nThis policy is optional. If you don't configure it, image search isn't available.\r\n\r\nSpecify Bing's Image Search URL as:\r\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\r\n\r\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\r\n\r\nSee 'DefaultSearchProviderImageURLPostParams' (Parameters for an image URL that uses POST) policy to finish configuring image search.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value: https://search.contoso.com/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended","displayName":"Parameters for an image URL that uses POST (User)","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it's replaced with real image thumbnail data. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nSpecify Bing's Image Search URL Post Params as:\r\n'imageBin={google:imageThumbnailBase64}'.\r\n\r\nSpecify Google's Image Search URL Post Params as:\r\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\r\n\r\nIf you don't set this policy, image search requests are sent using the GET method.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended","displayName":"Default search provider keyword (User)","description":"Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider.\r\n\r\nThis policy is optional. If you don't configure it, no keyword activates the search provider.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_defaultsearchproviderkeyword","displayName":"Default search provider keyword (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended","displayName":"Default search provider name (User)","description":"Specifies the name of the default search provider.\r\n\r\nIf you enable this policy, you set the name of the default search provider.\r\n\r\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\r\n\r\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended","displayName":"Default search provider search URL (User)","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\r\n\r\nSpecify Bing's search URL as:\r\n\r\n'{bing:baseURL}search?q={searchTerms}'.\r\n\r\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\r\n\r\nThis policy is required when you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) policy; if you don't enable the latter policy, this policy is ignored.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value: https://search.contoso.com/search?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended","displayName":"Default search provider URL for suggestions (User)","description":"Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user has entered so far.\r\n\r\nThis policy is optional. If you don't configure it, users won't see search suggestions; they will see suggestions from their browsing history and favorites.\r\n\r\nBing's suggest URL can be specified as:\r\n\r\n'{bing:baseURL}qbox?query={searchTerms}'.\r\n\r\nGoogle's suggest URL can be specified as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy will not be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy.\r\n\r\nExample value: https://search.contoso.com/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_winhttpproxyresolverenabled","displayName":"Use Windows proxy resolver (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nUse Windows to resolve proxies for all browser networking instead of the proxy resolver built into Microsoft Edge. The Windows proxy resolver enables Windows proxy features such as DirectAccess/NRPT.\r\n\r\nThis policy comes with the problems described by https://crbug.com/644030. It causes PAC files to be fetched and executed by Windows code, including PAC files set via the 'ProxyPacUrl' (Set the proxy .pac file URL) policy. Since Network Fetches for the PAC file happen via Windows instead of Microsoft Edge code, network policies such as 'DnsOverHttpsMode' (Control the mode of DNS-over-HTTPS) will not apply to network fetches for a PAC file.\r\n\r\nThis policy is deprecated. It will be superseded by a similar feature in a future release, see https://crbug.com/1032820.\r\n\r\nIf you enable this policy, the Windows proxy resolver will be used.\r\n\r\nIf you disable or don't configure this policy, the Microsoft Edge proxy resolver will be used.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_winhttpproxyresolverenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_winhttpproxyresolverenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge~applicationguard_applicationguardcontainerproxy","displayName":"Application Guard Container Proxy (User)","description":"Configures the proxy settings for Microsoft Edge Application Guard.\r\nIf you enable this policy, Microsoft Edge Application Guard ignores other sources of proxy configurations.\r\n\r\nIf you don't configure this policy, Microsoft Edge Application Guard uses the proxy configuration of the host.\r\n\r\nThis policy does not affect the proxy configuration of Microsoft Edge outside of Application Guard (on the host).\r\n\r\nThe ProxyMode field lets you specify the proxy server used by Microsoft Edge Application Guard.\r\n\r\nThe ProxyPacUrl field is a URL to a proxy .pac file.\r\n\r\nThe ProxyServer field is a URL for the proxy server.\r\n\r\nIf you choose the 'direct' value as 'ProxyMode', all other fields are ignored.\r\n\r\nIf you choose the 'auto_detect' value as 'ProxyMode', all other fields are ignored.\r\n\r\nIf you choose the 'fixed_servers' value as 'ProxyMode', the 'ProxyServer' field is used.\r\n\r\nIf you choose the 'pac_script' value as 'ProxyMode', the 'ProxyPacUrl' field is used.\r\n\r\nExample value:\r\n\r\n{\r\n \"ProxyMode\": \"direct\", \r\n \"ProxyPacUrl\": \"https://internal.site/example.pac\", \r\n \"ProxyServer\": \"123.123.123.123:8080\"\r\n}","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge~applicationguard_applicationguardcontainerproxy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge~applicationguard_applicationguardcontainerproxy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge~applicationguard_applicationguardcontainerproxy_applicationguardcontainerproxy","displayName":"Application Guard Container Proxy (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user (User)","description":"Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator should not be included when listing the protocol and the protocol should be all lower case. For example, list \"skype\" instead of \"skype:\", \"skype://\" or \"Skype\".\r\n\r\nIf you configure this policy, a protocol will only be permitted to launch an external application without prompting by policy if:\r\n\r\n- the protocol is listed\r\n\r\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\r\n\r\nIf either condition is false, the external protocol launch prompt will not be omitted by policy.\r\n\r\nIf you don't configure this policy, no protocols can launch without a prompt. Users can opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an \"Always open\" checkbox in external protocol dialog) policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' (Block access to a list of URLs) policy, which are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\n\r\nThis policy does not work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ],\r\n \"protocol\": \"spotify\"\r\n },\r\n {\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ],\r\n \"protocol\": \"msteams\"\r\n },\r\n {\r\n \"allowed_origins\": [\r\n \"*\"\r\n ],\r\n \"protocol\": \"msoutlook\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls","displayName":"URLs where AutoOpenFileTypes can apply (User)","description":"A list of URLs to which 'AutoOpenFileTypes' (List of file types that should be automatically opened on download) will apply to. This policy has no impact on automatically open values set by users via the download shelf ... > \"Always open files of this type\" menu entry.\r\n\r\nIf you set URLs in this policy, files will only automatically open by policy if the URL is part of this set and the file type is listed in 'AutoOpenFileTypes'. If either condition is false, the download won't automatically open by policy.\r\n\r\nIf you don't set this policy, all downloads where the file type is in 'AutoOpenFileTypes' will automatically open.\r\n\r\nA URL pattern has to be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nThis policy does not work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls_autoopenallowedforurlsdesc","displayName":"URLs where AutoOpenFileTypes can apply (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenfiletypes","displayName":"List of file types that should be automatically opened on download (User)","description":"This policy sets a list of file types that should be automatically opened on download. Note: The leading separator should not be included when listing the file type, so list \"txt\" instead of \".txt\".\r\n\r\nBy default, these file types will be automatically opened on all URLs. You can use the 'AutoOpenAllowedForURLs' (URLs where AutoOpenFileTypes can apply) policy to restrict the URLs for which these file types will be automatically opened on.\r\n\r\nFiles with types that should be automatically opened will still be subject to the enabled Microsoft Defender SmartScreen checks and won't be opened if they fail those checks.\r\n\r\nFile types that a user has already specified to automatically be opened will continue to do so when downloaded. The user will continue to be able to specify other file types to be automatically opened.\r\n\r\nIf you don't set this policy, only file types that a user has already specified to automatically be opened will do so when downloaded.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory or instances that enrolled for device management.\r\n\r\nExample value:\r\n\r\nexe\r\ntxt","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenfiletypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenfiletypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenfiletypes_autoopenfiletypesdesc","displayName":"List of file types that should be automatically opened on download (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_defaultsearchprovidercontextmenuaccessallowed","displayName":"Allow default search provider context menu search access (User)","description":"Enables the use of a default search provider on the context menu.\r\n\r\nIf you set this policy to disabled the search context menu item that relies on your default search provider and sidebar search will not be available.\r\n\r\nIf this policy is set to enabled or not set, the context menu item for your default search provider and sidebar search will be available.\r\n\r\nThe policy value is only applied when the 'DefaultSearchProviderEnabled' (Enable the default search provider) policy is enabled, and is not applicable otherwise.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_defaultsearchprovidercontextmenuaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_defaultsearchprovidercontextmenuaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_enablesha1forlocalanchors","displayName":"Allow certificates signed using SHA-1 when issued by local trust anchors (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nWhen this setting is enabled, Microsoft Edge allows connections secured by SHA-1 signed certificates so long as the the certificate chains to a locally-installed root certificate and is otherwise valid.\r\n\r\nNote that this policy depends on the operating system (OS) certificate verification stack allowing SHA-1 signatures. If an OS update changes the OS handling of SHA-1 certificates, this policy might no longer have effect. Further, this policy is intended as a temporary workaround to give enterprises more time to move away from SHA-1. This policy will be removed in Microsoft Edge 92 releasing in mid 2021.\r\n\r\nIf you don't set this policy or set it to false, or the SHA-1 certificate chains to a publicly trusted certificate root, then Microsoft Edge won't allow certificates signed by SHA-1.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_enablesha1forlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_enablesha1forlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109.\r\n\r\nThis policy has been obsoleted in favor of 'ExemptFileTypeDownloadWarnings' (Disable download file type extension-based warnings for specified file types on domains) because of a type mismatch that caused errors in Mac.\r\n\r\nYou can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users would not see a warning when downloading \"jnlp\" files from \"website1.com\", but see a download warning when downloading \"jnlp\" files from \"website2.com\".\r\n\r\nFiles with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\r\n\r\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.\r\n\r\nIf you enable this policy:\r\n\r\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list \"jnlp\" should be used instead of \".jnlp\".\r\n\r\nExample:\r\n\r\nThe following example value would prevent file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\r\n\r\n[\r\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\r\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\r\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\r\n]\r\n\r\nNote that while the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.\r\n\r\nExample value:\r\n\r\n{\"domains\": [\"https://contoso.com\", \"contoso2.com\"], \"file_extension\": \"jnlp\"}\r\n{\"domains\": [\"*\"], \"file_extension\": \"swf\"}","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_exemptdomainfiletypepairsfromfiletypedownloadwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_exemptdomainfiletypepairsfromfiletypedownloadwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_exemptdomainfiletypepairsfromfiletypedownloadwarnings_exemptdomainfiletypepairsfromfiletypedownloadwarningsdesc","displayName":"Disable download file type extension-based warnings for specified file types on domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_intensivewakeupthrottlingenabled","displayName":"Control the IntensiveWakeUpThrottling feature (User)","description":"When enabled the IntensiveWakeUpThrottling feature causes Javascript timers in background tabs to be aggressively throttled and coalesced, running no more than once per minute after a page has been backgrounded for 5 minutes or more.\r\n\r\nThis is a web standards compliant feature, but it may break functionality on some websites by causing certain actions to be delayed by up to a minute. However, it results in significant CPU and battery savings when enabled. See https://bit.ly/30b1XR4 for more details.\r\n\r\nIf you enable this policy, the feature will be force enabled, and users will not be able to override this setting.\r\nIf you disable this policy, the feature will be force disabled, and users will not be able to override this setting.\r\nIf you don't configure this policy, the feature will be controlled by its own internal logic. Users can manually configure this setting.\r\n\r\nNote that the policy is applied per renderer process, with the most recent value of the policy setting in force when a renderer process starts. A full restart is required to ensure that all the loaded tabs receive a consistent policy setting. It is harmless for processes to be running with different values of this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_intensivewakeupthrottlingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_intensivewakeupthrottlingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_newtabpagesearchbox_recommended","displayName":"Configure the new tab page search box experience (User)","description":"You can configure the new tab page search box to use \"Search box (Recommended)\" or \"Address bar\" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL).\r\n\r\n If you disable or don't configure this policy and:\r\n\r\n- If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.\r\n- If the address bar default search engine is not Bing, users are offered an additional choice (use \"Address bar\") when searching on new tabs.\r\n\r\n\r\nIf you enable this policy and set it to:\r\n\r\n- \"Search box (Recommended)\" ('bing'), the new tab page uses the search box to search on new tabs.\r\n- \"Address bar\" ('redirect'), the new tab page search box uses the address bar to search on new tabs.\r\n\r\nPolicy options mapping:\r\n\r\n* bing (bing) = Search box (Recommended)\r\n\r\n* redirect (redirect) = Address bar\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: bing","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_newtabpagesearchbox_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_newtabpagesearchbox_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_newtabpagesearchbox_recommended_newtabpagesearchbox","displayName":"New tab page search box experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_newtabpagesearchbox_recommended_newtabpagesearchbox_bing","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_newtabpagesearchbox_recommended_newtabpagesearchbox_redirect","displayName":"Address bar","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmonitorallowed_recommended","displayName":"Allow users to be alerted if their passwords are found to be unsafe (User)","description":"Allow Microsoft Edge to monitor user passwords.\r\n\r\nIf you enable this policy, the user will get alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\r\n\r\nIf you disable this policy, users will not be asked for permission to enable this feature. Their passwords will not be scanned and they will not be alerted either.\r\n\r\nIf you don't configure the policy, users can turn this feature on or off.\r\n\r\nTo learn more about how Microsoft Edge finds unsafe passwords see https://go.microsoft.com/fwlink/?linkid=2133833\r\n\r\nAdditional guidance:\r\n\r\nThis policy can be set as both Recommended as well as Mandatory, however with an important callout.\r\n\r\nMandatory enabled: If the policy is set to Mandatory enabled, the UI in Settings will be disabled but remain in 'On' state, and a briefcase icon will be made visible next to it with this description displayed on hover - \"This setting is managed by your organization.\"\r\n\r\nRecommended enabled: If the policy is set to Recommended enabled, the UI in Settings will remain in 'Off' state, but a briefcase icon will be made visible next to it with this description displayed on hover - \"Your organization recommends a specific value for this setting and you have chosen a different value\"\r\n\r\nMandatory and Recommended disabled: Both these states will work the normal way, with the usual captions being shown to users.","helpText":"","infoUrls":[],"categoryId":"a877a2ff-f144-421f-814c-593e972a8a20","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmonitorallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmonitorallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~startup_recommended_newtabpageprerenderenabled_recommended","displayName":"Enable preload of the new tab page for faster rendering (User)","description":"If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~startup_recommended_newtabpageprerenderenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~startup_recommended_newtabpageprerenderenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation","displayName":"Set the roaming profile directory (User)","description":"Configures the directory to use to store the roaming copy of profiles.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory to store a roaming copy of the profiles, as long as you've also enabled the 'RoamingProfileSupportEnabled' (Enable using roaming copies for Microsoft Edge profile data) policy. If you disable the 'RoamingProfileSupportEnabled' policy or don't configure it, the value stored in this policy isn't used.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables you can use.\r\n\r\nIf you don't configure this policy, the default roaming profile path is used.\r\n\r\nExample value: ${roaming_app_data}\\edge-profile","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation_roamingprofilelocation","displayName":"Set the roaming profile directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilesupportenabled","displayName":"Enable using roaming copies for Microsoft Edge profile data (User)","description":"Enable this policy to use roaming profiles on Windows. The settings stored in Microsoft Edge profiles (favorites and preferences) are also saved to a file stored in the Roaming user profile folder (or the location specified by the administrator through the 'RoamingProfileLocation' (Set the roaming profile directory) policy).\r\n\r\nIf you disable this policy or don't configure it, only the regular local profiles are used.\r\n\r\nThe 'SyncDisabled' (Disable synchronization of data using Microsoft sync services) policy disables all data synchronization, overriding policy.\r\n\r\nSee https://docs.microsoft.com/windows-server/storage/folder-redirection/deploy-roaming-user-profiles for more information on using roaming user profiles.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilesupportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilesupportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_tlsciphersuitedenylist","displayName":"Specify the TLS cipher suites to disable (User)","description":"Configure the list of cipher suites that are disabled for TLS connections.\r\n\r\nIf you configure this policy, the list of configured cipher suites will not be used when establishing TLS connections.\r\n\r\nIf you don't configure this policy, the browser will choose which TLS cipher suites to use.\r\n\r\nCipher suite values to be disabled are specified as 16-bit hexadecimal values. The values are assigned by the Internet Assigned Numbers Authority (IANA) registry.\r\n\r\nThe TLS 1.3 cipher suite TLS_AES_128_GCM_SHA256 (0x1301) is required for TLS 1.3 and can't be disabled by this policy.\r\n\r\nThis policy does not affect QUIC-based connections. QUIC can be turned off via the 'QuicAllowed' (Allow QUIC protocol) policy.\r\n\r\nExample value:\r\n\r\n0x1303\r\n0xcca8\r\n0xcca9","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_tlsciphersuitedenylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_tlsciphersuitedenylist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_tlsciphersuitedenylist_tlsciphersuitedenylistdesc","displayName":"Specify the TLS cipher suites to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox","displayName":"Configure the new tab page search box experience (User)","description":"You can configure the new tab page search box to use \"Search box (Recommended)\" or \"Address bar\" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL).\r\n\r\n If you disable or don't configure this policy and:\r\n\r\n- If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.\r\n- If the address bar default search engine is not Bing, users are offered an additional choice (use \"Address bar\") when searching on new tabs.\r\n\r\n\r\nIf you enable this policy and set it to:\r\n\r\n- \"Search box (Recommended)\" ('bing'), the new tab page uses the search box to search on new tabs.\r\n- \"Address bar\" ('redirect'), the new tab page search box uses the address bar to search on new tabs.\r\n\r\nPolicy options mapping:\r\n\r\n* bing (bing) = Search box (Recommended)\r\n\r\n* redirect (redirect) = Address bar\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: bing","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_newtabpagesearchbox","displayName":"New tab page search box experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_newtabpagesearchbox_bing","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_newtabpagesearchbox_redirect","displayName":"Address bar","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~passwordmanager_passwordmonitorallowed","displayName":"Allow users to be alerted if their passwords are found to be unsafe (User)","description":"Allow Microsoft Edge to monitor user passwords.\r\n\r\nIf you enable this policy, the user will get alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\r\n\r\nIf you disable this policy, users will not be asked for permission to enable this feature. Their passwords will not be scanned and they will not be alerted either.\r\n\r\nIf you don't configure the policy, users can turn this feature on or off.\r\n\r\nTo learn more about how Microsoft Edge finds unsafe passwords see https://go.microsoft.com/fwlink/?linkid=2133833\r\n\r\nAdditional guidance:\r\n\r\nThis policy can be set as both Recommended as well as Mandatory, however with an important callout.\r\n\r\nMandatory enabled: If the policy is set to Mandatory enabled, the UI in Settings will be disabled but remain in 'On' state, and a briefcase icon will be made visible next to it with this description displayed on hover - \"This setting is managed by your organization.\"\r\n\r\nRecommended enabled: If the policy is set to Recommended enabled, the UI in Settings will remain in 'Off' state, but a briefcase icon will be made visible next to it with this description displayed on hover - \"Your organization recommends a specific value for this setting and you have chosen a different value\"\r\n\r\nMandatory and Recommended disabled: Both these states will work the normal way, with the usual captions being shown to users.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~passwordmanager_passwordmonitorallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~passwordmanager_passwordmonitorallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~startup_newtabpageprerenderenabled","displayName":"Enable preload of the new tab page for faster rendering (User)","description":"If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~startup_newtabpageprerenderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~startup_newtabpageprerenderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage (User)","description":"This policy controls sending required and optional diagnostic data about browser usage to Microsoft.\r\n\r\nRequired diagnostic data is collected to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\nOptional diagnostic data includes data about how you use the browser, websites you visit and crash reports to Microsoft for product and service improvement.\r\n\r\nUp to version 121, this policy is not supported on Windows 10 devices. To control this data collection on Windows 10 for 121 and previous, IT admins must use the Windows diagnostic data group policy. This policy will either be 'Allow Telemetry' or 'Allow Diagnostic Data', depending on the version of Windows. Learn more about Windows 10 diagnostic data collection: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nFor version 122 and later, this policy is supported on Windows 10 devices to allow controlling Microsoft Edge data collection separately from Windows 10 diagnostics data collection.\r\n\r\nUse one of the following settings to configure this policy:\r\n\r\n'Off' turns off required and optional diagnostic data collection. This option is not recommended.\r\n\r\n'RequiredData' sends required diagnostic data but turns off optional diagnostic data collection. Microsoft Edge will send required diagnostic data to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\n'OptionalData' sends optional diagnostic data includes data about browser usage, websites that are visited, crash reports sent to Microsoft for product and service improvement.\r\n\r\nOn Windows 7/macOS, this policy controls sending required and optional data to Microsoft.\r\n\r\nIf you don't configure this policy or disable it, Microsoft Edge will default to the user's preference.\r\n\r\nPolicy options mapping:\r\n\r\n* Off (0) = Off (Not recommended)\r\n\r\n* RequiredData (1) = Required data\r\n\r\n* OptionalData (2) = Optional data\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_diagnosticdata_0","displayName":"Off (Not recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_diagnosticdata_1","displayName":"Required data","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_diagnosticdata_2","displayName":"Optional data","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist","displayName":"Block access to a specified list of services and export targets in Collections (User)","description":"List specific services and export targets that users can't access in the Collections feature in Microsoft Edge. This includes displaying additional data from Bing and exporting collections to Microsoft products or external partners.\r\n\r\nIf you enable this policy, services and export targets that match the given list are blocked.\r\n\r\nIf you don't configure this policy, no restrictions on the acceptable services and export targets are enforced.\r\n\r\nPolicy options mapping:\r\n\r\n* pinterest_suggestions (pinterest_suggestions) = Pinterest suggestions\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\npinterest_suggestions","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_collectionsservicesandexportsblocklistdesc","displayName":"Block access to a specified list of services and export targets in Collections (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting","displayName":"Default sensors setting (User)","description":"Set whether websites can access and use sensors such as motion and light sensors. You can completely block or allow websites to get access to sensors.\r\n\r\nSetting the policy to 1 lets websites access and use sensors. Setting the policy to 2 denies access to sensors.\r\n\r\nYou can override this policy for specific URL patterns by using the 'SensorsAllowedForUrls' (Allow access to sensors on specific sites) and 'SensorsBlockedForUrls' (Block access to sensors on specific sites) policies.\r\n\r\nIf you don't configure this policy, websites can access and use sensors, and users can change this setting. This is the global default for 'SensorsAllowedForUrls' and 'SensorsBlockedForUrls'.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowSensors (1) = Allow sites to access sensors\r\n\r\n* BlockSensors (2) = Do not allow any site to access sensors\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_defaultsensorssetting","displayName":"Default sensors setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_defaultsensorssetting_1","displayName":"Allow sites to access sensors","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_defaultsensorssetting_2","displayName":"Do not allow any site to access sensors","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting","displayName":"Control use of the Serial API (User)","description":"\r\nSet whether websites can access serial ports. You can completely block access or ask the user each time a website wants to get access to a serial port.\r\n\r\nSetting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\r\n\r\nYou can override this policy for specific URL patterns by using the 'SerialAskForUrls' (Allow the Serial API on specific sites) and 'SerialBlockedForUrls' (Block the Serial API on specific sites) policies.\r\n\r\nIf you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockSerial (2) = Do not allow any site to request access to serial ports via the Serial API\r\n\r\n* AskSerial (3) = Allow sites to ask for user permission to access a serial port\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_defaultserialguardsetting","displayName":"Control use of the Serial API (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_defaultserialguardsetting_2","displayName":"Do not allow any site to request access to serial ports via the Serial API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_defaultserialguardsetting_3","displayName":"Allow sites to ask for user permission to access a serial port","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage (User)","description":"This policy controls sending required and optional diagnostic data about browser usage to Microsoft.\r\n\r\nRequired diagnostic data is collected to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\nOptional diagnostic data includes data about how you use the browser, websites you visit and crash reports to Microsoft for product and service improvement.\r\n\r\nUp to version 121, this policy is not supported on Windows 10 devices. To control this data collection on Windows 10 for 121 and previous, IT admins must use the Windows diagnostic data group policy. This policy will either be 'Allow Telemetry' or 'Allow Diagnostic Data', depending on the version of Windows. Learn more about Windows 10 diagnostic data collection: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nFor version 122 and later, this policy is supported on Windows 10 devices to allow controlling Microsoft Edge data collection separately from Windows 10 diagnostics data collection.\r\n\r\nUse one of the following settings to configure this policy:\r\n\r\n'Off' turns off required and optional diagnostic data collection. This option is not recommended.\r\n\r\n'RequiredData' sends required diagnostic data but turns off optional diagnostic data collection. Microsoft Edge will send required diagnostic data to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\n'OptionalData' sends optional diagnostic data includes data about browser usage, websites that are visited, crash reports sent to Microsoft for product and service improvement.\r\n\r\nOn Windows 7/macOS, this policy controls sending required and optional data to Microsoft.\r\n\r\nIf you don't configure this policy or disable it, Microsoft Edge will default to the user's preference.\r\n\r\nPolicy options mapping:\r\n\r\n* Off (0) = Off (Not recommended)\r\n\r\n* RequiredData (1) = Required data\r\n\r\n* OptionalData (2) = Optional data\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata_0","displayName":"Off (Not recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata_1","displayName":"Required data","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata_2","displayName":"Optional data","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_enterprisemodesitelistmanagerallowed","displayName":"Allow access to the Enterprise Mode Site List Manager tool (User)","description":"Allows you to set whether Enterprise Mode Site List Manager is available to users.\r\n\r\nIf you enable this policy, users can see the Enterprise Mode Site List Manager nav button on edge://compat page, navigate to the tool and use it.\r\n\r\nIf you disable or don't configure this policy, users won't see the Enterprise Mode Site List Manager nav button and won't be able to use it.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_enterprisemodesitelistmanagerallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_enterprisemodesitelistmanagerallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_forcesync","displayName":"Force synchronization of browser data and do not show the sync consent prompt (User)","description":"Forces data synchronization in Microsoft Edge. This policy also prevents the user from turning sync off.\r\n\r\nIf you don't configure this policy, users will be able to turn sync on or off. If you enable this policy, users will not be able to turn sync off.\r\n\r\nFor this policy to work as intended,\r\n'BrowserSignin' (Browser sign-in settings) policy must not be configured, or must be set to enabled. If 'ForceSync' (Force synchronization of browser data and do not show the sync consent prompt) is set to disabled, then 'BrowserSignin' will not take affect.\r\n\r\n'SyncDisabled' (Disable synchronization of data using Microsoft sync services) must not be configured or must be set to False. If this is set to True, 'ForceSync' will not take affect.\r\n\r\n0 = Do not automatically start sync and show the sync consent (default)\r\n1 = Force sync to be turned on for Azure AD/Azure AD-Degraded user profile and do not show the sync consent prompt","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_forcesync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_forcesync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled","displayName":"Enable warnings for insecure forms (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy controls the handling of insecure forms (forms submitted over HTTP) embedded in secure (HTTPS) sites in the browser.\r\nIf you enable this policy or don't set it, a full page warning will be shown when an insecure form is submitted. Additionally, a warning bubble will be shown next to the form fields when they are focused, and autofill will be disabled for those forms.\r\nIf you disable this policy, warnings will not be shown for insecure forms, and autofill will work normally.\r\n\r\nThis policy may be removed as soon as Edge 132. The feature is enabled by default since Edge 131.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_internetexplorerintegrationtestingallowed","displayName":"Allow Internet Explorer mode testing (User)","description":"This policy is a replacement for the ie-mode-test flag policy. It lets users open an IE mode tab from the UI menu option.\r\n\r\n This setting works in conjunction with:\r\n 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'\r\n and\r\n 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry.\r\n\r\n If you enable this policy, users can open IE mode tab from the UI option and navigate current site to an IE mode site.\r\n\r\n If you disable this policy, users can't see the UI option in the menu directly.\r\n\r\n If you don't configure this policy, you can set up the ie-mode-test flag manually.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_internetexplorerintegrationtestingallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_internetexplorerintegrationtestingallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit","displayName":"Save cookies when Microsoft Edge closes (User)","description":"When this policy is enabled, the specified set of cookies is exempt from deletion when the browser closes. This policy is only effective when:\r\n- The 'Cookies and other site data' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\r\n- The policy 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) is enabled or\r\n- The policy 'DefaultCookiesSetting' (Configure cookies) is set to 'Keep cookies for the duration of the session'.\r\n\r\nYou can define a list of sites, based on URL patterns, that will have their cookies preserved across sessions.\r\n\r\nNote: Users can still edit the cookie site list to add or remove URLs. However, they can't remove URLs that have been added by an Admin.\r\n\r\nIf you enable this policy, the list of cookies won't be cleared when the browser closes.\r\n\r\nIf you disable or don't configure this policy, the user's personal configuration is used.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit_savecookiesonexitdesc","displayName":"Save cookies when Microsoft Edge closes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls","displayName":"Allow access to sensors on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can access and use sensors such as motion and light sensors.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultSensorsSetting' (Default sensors setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor URL patterns that don't match this policy, the following order of precedence is used: The 'SensorsBlockedForUrls' (Block access to sensors on specific sites) policy (if there is a match), the 'DefaultSensorsSetting' policy (if set), or the user's personal settings.\r\n\r\nThe URL patterns defined in this policy can't conflict with those configured in the 'SensorsBlockedForUrls' policy. You can't allow and block a URL.\r\n\r\nFor detailed information about valid URL patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_sensorsallowedforurlsdesc","displayName":"Allow access to sensors on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsblockedforurls","displayName":"Block access to sensors on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can't access sensors such as motion and light sensors.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultSensorsSetting' (Default sensors setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor URL patterns that don't match this policy, the following order of precedence is used: The 'SensorsAllowedForUrls' (Allow access to sensors on specific sites) policy (if there is a match), the 'DefaultSensorsSetting' policy (if set), or the user's personal settings.\r\n\r\nThe URL patterns defined in this policy can't conflict with those configured in the 'SensorsAllowedForUrls' policy. You can't allow and block a URL.\r\n\r\nFor detailed information about valid URL patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsblockedforurls_sensorsblockedforurlsdesc","displayName":"Block access to sensors on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialaskforurls","displayName":"Allow the Serial API on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can ask the user for access to a serial port.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultSerialGuardSetting' (Control use of the Serial API) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor URL patterns that don't match this policy, the following order of precedence is used: The 'SerialBlockedForUrls' (Block the Serial API on specific sites) policy (if there is a match), the 'DefaultSerialGuardSetting' policy (if set), or the user's personal settings.\r\n\r\nThe URL patterns defined in this policy can't conflict with those configured in the 'SerialBlockedForUrls' policy. You can't allow and block a URL.\r\n\r\nFor detailed information about valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialaskforurls_serialaskforurlsdesc","displayName":"Allow the Serial API on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialblockedforurls","displayName":"Block the Serial API on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can't ask the user to grant them access to a serial port.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultSerialGuardSetting' (Control use of the Serial API) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor URL patterns that don't match this policy, the following order of precedence is used: The 'SerialAskForUrls' (Allow the Serial API on specific sites) policy (if there is a match), the 'DefaultSerialGuardSetting' policy (if set), or the user's personal settings.\r\n\r\nThe URL patterns in this policy can't conflict with those configured in the 'SerialAskForUrls' policy. You can't allow and block a URL.\r\n\r\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialblockedforurls_serialblockedforurlsdesc","displayName":"Block the Serial API on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_useragentclienthintsenabled","displayName":"Enable the User-Agent Client Hints feature (obsolete) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because it's only intended to be a short-term mechanism to give enterprises more time to update their web content if and when it's found to be incompatible with the User-Agent Client Hints feature. It won't work in Microsoft Edge version 89.\r\n\r\nWhen enabled the User-Agent Client Hints feature sends granular request headers that provide information about the user browser (for example, the browser version) and environment (for example, the system architecture).\r\n\r\nThis is an additive feature, but the new headers may break some websites that restrict the characters that requests may contain.\r\n\r\nIf you enable or don't configure this policy, the User-Agent Client Hints feature is enabled. If you disable this policy, this feature is unavailable.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_useragentclienthintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_useragentclienthintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit","displayName":"Limits the number of user data snapshots retained for use in case of emergency rollback (User)","description":"Following each major version update, Microsoft Edge will create a snapshot of parts of the user's browsing data to use in case of a later emergency that requires a temporary version rollback. If a temporary rollback is performed to a version for which a user has a corresponding snapshot, the data in the snapshot is restored. This lets users keep settings such as bookmarks and autofill data.\r\n\r\nIf you don't set this policy, the default value of 3 snapshots is used.\r\n\r\nIf you set this policy, old snapshots are deleted as needed to respect the limit you set. If you set this policy to 0, no snapshots are taken.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit_userdatasnapshotretentionlimit","displayName":"Limits the number of user data snapshots retained for use in case of emergency rollback: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading (User)","description":"If you set this policy to 3, websites can ask for read access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\r\n\r\nIf you don't set this policy, websites can ask for access. Users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockFileSystemRead (2) = Don't allow any site to request read access to files and directories via the File System API\r\n\r\n* AskFileSystemRead (3) = Allow sites to ask the user to grant read access to files and directories via the File System API\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_2","displayName":"Don't allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_3","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing (User)","description":"If you set this policy to 3, websites can ask for write access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\r\n\r\nIf you don't set this policy, websites can ask for access. Users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockFileSystemWrite (2) = Don't allow any site to request write access to files and directories\r\n\r\n* AskFileSystemWrite (3) = Allow sites to ask the user to grant write access to files and directories\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting_2","displayName":"Don't allow any site to request write access to files and directories","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting_3","displayName":"Allow sites to ask the user to grant write access to files and directories","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls","displayName":"Allow read access via the File System API on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\r\n\r\nLeaving the policy unset means 'DefaultFileSystemReadGuardSetting' (Control use of the File System API for reading) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemReadBlockedForUrls' (Block read access via the File System API on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_filesystemreadaskforurlsdesc","displayName":"Allow read access via the File System API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadblockedforurls","displayName":"Block read access via the File System API on these sites (User)","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\r\n\r\nIf you don't set this policy, 'DefaultFileSystemReadGuardSetting' (Control use of the File System API for reading) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemReadAskForUrls' (Allow read access via the File System API on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadblockedforurls_filesystemreadblockedforurlsdesc","displayName":"Block read access via the File System API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls","displayName":"Allow write access to files and directories on these sites (User)","description":"If you set this policy, you can list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nIf you don't set this policy, 'DefaultFileSystemWriteGuardSetting' (Control use of the File System API for writing) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemWriteBlockedForUrls' (Block write access to files and directories on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls_filesystemwriteaskforurlsdesc","displayName":"Allow write access to files and directories on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls","displayName":"Block write access to files and directories on these sites (User)","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nIf you don't set this policy, 'DefaultFileSystemWriteGuardSetting' (Control use of the File System API for writing) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemWriteAskForUrls' (Allow write access to files and directories on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls_filesystemwriteblockedforurlsdesc","displayName":"Block write access to files and directories on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_spotlightexperiencesandrecommendationsenabled","displayName":"Choose whether users can receive customized background images and text, suggestions, notifications,\r\nand tips for Microsoft services (User)","description":"Choose whether users can receive customized background images and text, suggestions, notifications, and tips for Microsoft services.\r\n\r\nIf you enable or don't configure this setting, spotlight experiences and recommendations are turned on.\r\n\r\nIf you disable this setting, spotlight experiences and recommendations are turned off.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_spotlightexperiencesandrecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_spotlightexperiencesandrecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes","displayName":"Configure the background types allowed for the new tab page layout (User)","description":"You can configure which types of background image that are allowed on the new tab page layout in Microsoft Edge.\r\n\r\nIf you don't configure this policy, all background image types on the new tab page are enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* DisableImageOfTheDay (1) = Disable daily background image type\r\n\r\n* DisableCustomImage (2) = Disable custom background image type\r\n\r\n* DisableAll (3) = Disable all background image types\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes","displayName":"New tab page experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes_1","displayName":"Disable daily background image type","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes_2","displayName":"Disable custom background image type","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes_3","displayName":"Disable all background image types","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (User)","description":"If FriendlyURLs are enabled, Microsoft Edge will compute additional representations of the URL and place them on the clipboard.\r\n\r\nThis policy configures what format will be pasted when the user pastes in external applications, or inside Microsoft Edge without the 'Paste as' context menu item.\r\n\r\nIf configured, this policy makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu will not be available.\r\n\r\n* Not configured = The user will be able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\r\n\r\n* 1 = No additional formats will be stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature will be disabled.\r\n\r\n* 3 = The user will get a friendly URL whenever they paste into surfaces that accept rich text. The plain URL will still be available for non-rich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\r\n\r\n* 4 = (Not currently used)\r\n\r\nThe richer formats may not be well-supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy.\r\n\r\nThe recommended policy is available in Microsoft Edge 105 or later.\r\n\r\nPolicy options mapping:\r\n\r\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\r\n\r\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.\r\n\r\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat_1","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat_3","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat_4","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled","displayName":"Shopping in Microsoft Edge Enabled (User)","description":"This policy lets users compare the prices of a product they are looking at, get coupons from the website they're on, or auto-apply coupons during checkout.\r\n\r\nIf you enable or don't configure this policy, shopping features such as price comparison and coupons will be automatically applied for retail domains. Coupons for the current retailer and prices from other retailers will be fetched from a server.\r\n\r\nIf you disable this policy shopping features such as price comparison and coupons will not be automatically found for retail domains.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_hideinternetexplorerredirectuxforincompatiblesitesenabled","displayName":"Hide the one-time redirection dialog and the banner on Microsoft Edge (User)","description":"This policy gives an option to disable one-time redirection dialog and the banner. When this policy is enabled, users will not see both the one-time dialog and the banner.\r\nUsers will continue to be redirected to Microsoft Edge when they encounter an incompatible website on Internet Explorer, but their browsing data will not be imported.\r\n\r\n- If you enable this policy the one-time redirection dialog and banner will never be shown to users. Users' browsing data will not be imported when a redirection happens.\r\n\r\n- If you disable or don't set this policy, the redirection dialog will be shown on the first redirection and the persistent redirection banner will be shown to users on sessions that begin with a redirection. Users' browsing data will be imported every time user encounters such redirection (ONLY IF user consents to it on the one-time dialog).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_hideinternetexplorerredirectuxforincompatiblesitesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_hideinternetexplorerredirectuxforincompatiblesitesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_edgeshoppingassistantenabled_recommended","displayName":"Shopping in Microsoft Edge Enabled (User)","description":"This policy lets users compare the prices of a product they are looking at, get coupons from the website they're on, or auto-apply coupons during checkout.\r\n\r\nIf you enable or don't configure this policy, shopping features such as price comparison and coupons will be automatically applied for retail domains. Coupons for the current retailer and prices from other retailers will be fetched from a server.\r\n\r\nIf you disable this policy shopping features such as price comparison and coupons will not be automatically found for retail domains.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_edgeshoppingassistantenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_edgeshoppingassistantenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"This setting lets you specify whether Internet Explorer will redirect navigations to sites that require a modern browser to Microsoft Edge.\r\n\r\nIf you don't configure this policy or set it to 'Sitelist', beginning in M87, Internet Explorer will redirect sites that require a modern browser to Microsoft Edge.\r\n\r\nMicrosoft provides a list of public sites that require such redirection, such as https://mail.yahoo.com.\r\n\r\nWhen a site is redirected from Internet Explorer to Microsoft Edge, the Internet Explorer tab that began loading that site is closed if it had no prior content. Otherwise, it is navigated to a Microsoft help page explaining why the site was redirected to Microsoft Edge.\r\n\r\nWhen Microsoft Edge is launched to load a site from IE, an information bar is shown to the user explaining that the site works best in a modern browser.\r\n\r\nIf you set this policy to 'Disable', Internet Explorer will not redirect any traffic to Microsoft Edge.\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715\r\n\r\nPolicy options mapping:\r\n\r\n* Disable (0) = Disable\r\n\r\n* Sitelist (1) = Redirect sites based on the incompatible sites sitelist\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode_0","displayName":"Prevent redirection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode_1","displayName":"Redirect sites based on the incompatible sites sitelist","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordrevealenabled_recommended","displayName":"Enable Password reveal button (User)","description":"Lets you configure the default display of the browser password reveal button for password input fields on websites.\r\n\r\nIf you enable or don't configure this policy, the browser user setting defaults to displaying the password reveal button.\r\n\r\nIf you disable this policy, the browser user setting won't display the password reveal button.\r\n\r\nFor accessibility, users can change the browser setting from the default policy.\r\n\r\nThis policy only affects the browser password reveal button, it doesn't affect websites' custom reveal buttons.","helpText":"","infoUrls":[],"categoryId":"a877a2ff-f144-421f-814c-593e972a8a20","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordrevealenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordrevealenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall","displayName":"Prevent install of the BHO to redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"This setting lets you specify whether to block the install of the Browser Helper Object (BHO) that enables redirecting incompatible sites from Internet Explorer to Microsoft Edge for sites that require a modern browser.\r\n\r\nIf you enable this policy, the BHO will not be installed. If it is already installed it will be uninstalled on the next Microsoft Edge update.\r\n\r\nIf this policy is not configured or is disabled, the BHO will be installed.\r\n\r\nThe BHO is required for incompatible site redirection to occur, however whether redirection occurs or not is also controlled by 'RedirectSitesFromInternetExplorerRedirectMode' (Redirect incompatible sites from Internet Explorer to Microsoft Edge).\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"This setting lets you specify whether Internet Explorer will redirect navigations to sites that require a modern browser to Microsoft Edge.\r\n\r\nIf you don't configure this policy or set it to 'Sitelist', beginning in M87, Internet Explorer will redirect sites that require a modern browser to Microsoft Edge.\r\n\r\nMicrosoft provides a list of public sites that require such redirection, such as https://mail.yahoo.com.\r\n\r\nWhen a site is redirected from Internet Explorer to Microsoft Edge, the Internet Explorer tab that began loading that site is closed if it had no prior content. Otherwise, it is navigated to a Microsoft help page explaining why the site was redirected to Microsoft Edge.\r\n\r\nWhen Microsoft Edge is launched to load a site from IE, an information bar is shown to the user explaining that the site works best in a modern browser.\r\n\r\nIf you set this policy to 'Disable', Internet Explorer will not redirect any traffic to Microsoft Edge.\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715\r\n\r\nPolicy options mapping:\r\n\r\n* Disable (0) = Disable\r\n\r\n* Sitelist (1) = Redirect sites based on the incompatible sites sitelist\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_redirectsitesfrominternetexplorerredirectmode","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_redirectsitesfrominternetexplorerredirectmode_0","displayName":"Prevent redirection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_redirectsitesfrominternetexplorerredirectmode_1","displayName":"Redirect sites based on the incompatible sites sitelist","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_speechrecognitionenabled","displayName":"Configure Speech Recognition (User)","description":"Set whether websites can use the W3C Web Speech API to recognize speech from the user. The Microsoft Edge implementation of the Web Speech API uses Azure Cognitive Services, so voice data will leave the machine.\r\n\r\nIf you enable or don't configure this policy, web-based applications that use the Web Speech API can use Speech Recognition.\r\n\r\nIf you disable this policy, Speech Recognition is not available through the Web Speech API.\r\n\r\nRead more about this feature here:\r\nSpeechRecognition API: https://go.microsoft.com/fwlink/?linkid=2143388\r\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2143680","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_speechrecognitionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_speechrecognitionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_webcaptureenabled","displayName":"Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge (User)","description":"Note: The web capture feature is rebranded to \"Screenshot\".\r\n\r\nEnables the Screenshot feature in Microsoft Edge. This feature lets users capture web and PDF content, and annotate captures using inking tools. Users can also do a visual image search based on the captured content.\r\n\r\nIf you enable or don't configure this policy, the Screenshot option appears in the context menu, the Settings and more menu, and by using the keyboard shortcut, CTRL+SHIFT+S.\r\n\r\nIf you disable this policy, users can't access this feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_webcaptureenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_webcaptureenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskaddressbareditingenabled","displayName":"Configure address bar editing for kiosk mode public browsing experience (User)","description":"This policy only applies to Microsoft Edge kiosk mode while using the public browsing experience.\r\n\r\nIf you enable or don't configure this policy, users can change the URL in the address bar.\r\n\r\nIf you disable this policy, it prevents users from changing the URL in the address bar.\r\n\r\nFor detailed information on configuring kiosk Mode, see https://go.microsoft.com/fwlink/?linkid=2137578.","helpText":"","infoUrls":[],"categoryId":"d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","categoryName":"Kiosk Mode settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskaddressbareditingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskaddressbareditingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskdeletedownloadsonexit","displayName":"Delete files downloaded as part of kiosk session when Microsoft Edge closes (User)","description":"This policy only applies to Microsoft Edge kiosk mode.\r\n\r\nIf you enable this policy, files downloaded as part of the kiosk session are deleted each time Microsoft Edge closes.\r\n\r\nIf you disable this policy or don't configure it, files downloaded as part of the kiosk session are not deleted when Microsoft Edge closes.\r\n\r\nFor detailed information on configuring kiosk Mode, see https://go.microsoft.com/fwlink/?linkid=2137578.","helpText":"","infoUrls":[],"categoryId":"d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","categoryName":"Kiosk Mode settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskdeletedownloadsonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskdeletedownloadsonexit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~printing_printingpapersizedefault","displayName":"Default printing page size (User)","description":"Overrides default printing page size.\r\n\r\nname should contain one of the listed formats or 'custom' if required paper size is not in the list. If 'custom' value is provided custom_size property should be specified. It describes the desired height and width in micrometers. Otherwise custom_size property shouldn't be specified. Policy that violates these rules is ignored.\r\n\r\nIf the page size is unavailable on the printer chosen by the user this policy is ignored.\r\n\r\nExample value:\r\n\r\n{\r\n \"custom_size\": {\r\n \"height\": 297000,\r\n \"width\": 210000\r\n },\r\n \"name\": \"custom\"\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"custom_size\": {\"height\": 297000, \"width\": 210000}, \"name\": \"custom\"}","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~printing_printingpapersizedefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~printing_printingpapersizedefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~printing_printingpapersizedefault_printingpapersizedefault","displayName":"Default printing page size (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended","displayName":"Set the background tab inactivity timeout for sleeping tabs (User)","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure sleeping tabs) is enabled or is not configured and the user has enabled the sleeping tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 30Seconds (30) = 30 seconds of inactivity\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_30","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs (User)","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure sleeping tabs) is enabled or is not configured and the user has enabled the sleeping tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 30Seconds (30) = 30 seconds of inactivity\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_30","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed","displayName":"Allow launching of local files in Internet Explorer mode (User)","description":"This policy controls the availability of the --ie-mode-file-url command line argument which is used to launch Microsoft Edge with a local file specified on the command line into Internet Explorer mode.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nIf you set this policy to true, or don't configure it, the user is allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\r\n\r\nIf you set this policy to false, the user isn't allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist","displayName":"Open local files in Internet Explorer mode file extension allow list (User)","description":"This policy limits which file:// URLs are allowed to be launched into Internet Explorer mode based on file extension.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nWhen a file:// URL is requested to launch in Internet Explorer mode, the file extension of the URL must be present in this list in order for the URL to be allowed to launch in Internet Explorer mode. A URL which is blocked from opening in Internet Explorer mode will instead open in Edge mode.\r\n\r\nIf you set this policy to the special value \"*\" or don't configure it, all file extensions are allowed.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210\r\n\r\nExample value:\r\n\r\n.mht\r\n.pdf\r\n.vsdx","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist_internetexplorerintegrationlocalfileextensionallowlistdesc","displayName":"Open local files in Internet Explorer mode file extension allow list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileshowcontextmenu","displayName":"Show context menu to open a link in Internet Explorer mode (User)","description":"This policy controls the visibility of the 'Open link in new Internet Explorer mode tab' option on the context menu for file:// links.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nIf you set this policy to true, the 'Open link in new Internet Explorer mode tab' context menu item will be available for file:// links.\r\n\r\nIf you set this policy to false or don't configure it, the context menu item will not be added.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileshowcontextmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileshowcontextmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior","displayName":"Intranet Redirection Behavior (User)","description":"This policy configures behavior for intranet redirection via DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\r\n\r\nIf this policy isn't configured, the browser will use the default behavior of DNS interception checks and intranet redirect suggestions. In M88, they are enabled by default but will be disabled by default in the future release.\r\n\r\n'DNSInterceptionChecksEnabled' (DNS interception checks enabled) is a related policy that might also disable DNS interception checks. However, this policy is a more flexible version which might separately control intranet redirection infobars and might be expanded in the future.\r\nIf either 'DNSInterceptionChecksEnabled' or this policy make a request to disable interception checks, the checks will be disabled.\r\nIf DNS interception checks are disabled by this policy but 'GoToIntranetSiteForSingleWordEntryInAddressBar' (Force direct intranet site navigation instead of searching on single word entries in the Address Bar) is enabled, single word queries will still result in intranet navigations.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Use default browser behavior.\r\n\r\n* DisableInterceptionChecksDisableInfobar (1) = Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.\r\n\r\n* DisableInterceptionChecksEnableInfobar (2) = Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.\r\n\r\n* EnableInterceptionChecksEnableInfobar (3) = Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_intranetredirectbehavior","displayName":"Intranet Redirection Behavior (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_intranetredirectbehavior_0","displayName":"Use default browser behavior.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_intranetredirectbehavior_1","displayName":"Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_intranetredirectbehavior_2","displayName":"Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_intranetredirectbehavior_intranetredirectbehavior_3","displayName":"Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended_showmicrosoftrewards_recommended","displayName":"Show Microsoft Rewards experiences (User)","description":"Show Microsoft Rewards experience and notifications.\r\nIf you enable this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\r\n - The setting to enable Give mode will be enabled and respect the user's setting.\r\n\r\nIf you disable this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will not see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be disabled and toggled off.\r\n\r\nIf you don't configure this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\r\n - The setting to enable Give mode will be enabled and respect the user's setting.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended_showmicrosoftrewards_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended_showmicrosoftrewards_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~performance_recommended_startupboostenabled_recommended","displayName":"Enable startup boost (User)","description":"Allows Microsoft Edge processes to start at OS sign-in and restart in background after the last browser window is closed.\r\n\r\nIf Microsoft Edge is running in background mode, the browser might not close when the last window is closed and the browser won't be restarted in background when the window closes. See the 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about what happens after configuring Microsoft Edge background mode behavior.\r\n\r\nIf you enable this policy, startup boost is turned on.\r\n\r\nIf you disable this policy, startup boost is turned off.\r\n\r\nIf you don't configure this policy, startup boost may initially be off or on. The user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about startup boost: https://go.microsoft.com/fwlink/?linkid=2147018","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~performance_recommended_startupboostenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~performance_recommended_startupboostenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended","displayName":"Block Sleeping Tabs on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are not allowed to be put to sleep by Sleeping Tabs.\r\n\r\nIf the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is disabled, this list is not used and no sites will be put to sleep automatically.\r\n\r\nIf you don't configure this policy, all sites will be eligible to be put to sleep unless the user's personal configuration blocks them.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended_sleepingtabsblockedforurlsdesc","displayName":"Block Sleeping Tabs on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsenabled_recommended","displayName":"Configure Sleeping Tabs (User)","description":"This policy setting lets you configure whether to turn on Sleeping Tabs. Sleeping Tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, Sleeping Tabs is turned on.\r\n\r\nIndividual sites may be blocked from being put to sleep by configuring the policy 'SleepingTabsBlockedForUrls' (Block Sleeping Tabs on specific sites).\r\n\r\nIf you enable this setting, Sleeping Tabs is turned on.\r\n\r\nIf you disable this setting, Sleeping Tabs is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use Sleeping Tabs.","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended","displayName":"Set the background tab inactivity timeout for Sleeping Tabs (User)","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if Sleeping Tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is enabled or is not configured and the user has enabled the Sleeping Tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_showmicrosoftrewards","displayName":"Show Microsoft Rewards experiences (User)","description":"Show Microsoft Rewards experience and notifications.\r\nIf you enable this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\r\n - The setting to enable Give mode will be enabled and respect the user's setting.\r\n\r\nIf you disable this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will not see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be disabled and toggled off.\r\n\r\nIf you don't configure this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\r\n - The setting to enable Give mode will be enabled and respect the user's setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_showmicrosoftrewards_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_showmicrosoftrewards_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed","displayName":"Configures availability of a vertical layout for tabs on the side of the browser (User)","description":"Configures whether a user can access an alternative layout where tabs are vertically aligned on the side of the browser instead of at the top.\r\nWhen there are several tabs open, this layout provides better tab viewing and management. There's better visibility of the site titles,\r\nit's easier to scan aligned icons, and there's more space to manage and close tabs.\r\n\r\nIf you disable this policy, then the vertical tab layout will not be available as an option for users.\r\n\r\nIf you enable or don't configure this policy, the tab layout will still be at the top, but a user has the option to turn on vertical tabs on the side.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols","displayName":"Allow legacy TLS/DTLS downgrade in WebRTC (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 120.\r\n\r\nIf you enable this policy, WebRTC peer connections can downgrade to obsolete\r\nversions of the TLS/DTLS (DTLS 1.0, TLS 1.0 and TLS 1.1) protocols.\r\nIf you disable or don't set this policy, these TLS/DTLS versions are\r\ndisabled.\r\n\r\nThis policy was removed in Microsoft Edge 121 and is ignored if set.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetallowed","displayName":"Enable the Search bar (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nEnables the search bar. When enabled, users can use the search bar to search the web from their desktop or from an application. The search bar provides a search box that shows web suggestions and opens all web searches in Microsoft Edge. The search box provides search (powered by Bing) and URL suggestions. The search bar can be launched from the \"More tools\" menu or jump list in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy:\r\nThe search bar will be automatically enabled for all profiles.\r\nThe option to enable the search bar at startup will be toggled on if the 'WebWidgetIsEnabledOnStartup' (Allow the Search bar at Windows startup) policy is enabled.\r\nIf the 'WebWidgetIsEnabledOnStartup' is disabled or not configured, the option to enable the search bar at startup will be toggled off.\r\nUsers will see the menu item to launch the search bar from the Microsoft Edge \"More tools\" menu. Users can launch the search bar from \"More tools\".\r\nUsers will see the menu item to launch the search bar from the Microsoft Edge jump list menu. Users can launch the search bar from the Microsoft Edge jump list menu.\r\nThe search bar can be turned off by the \"Quit\" option in the System tray or by closing the search bar from the 3 dot menu. The search bar will be restarted on system reboot if auto-start is enabled.\r\n\r\n\r\nIf you disable this policy:\r\nThe search bar will be disabled for all profiles.\r\nThe option to launch the search bar from Microsoft Edge \"More tools\" menu will be disabled.\r\nThe option to launch the search bar from Microsoft Edge jump list menu will be disabled.\r\n\r\nThis policy is deprecated due to the deprecation of the Web widget's vertical layout. This policy will be made obsolete in 119 release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetisenabledonstartup","displayName":"Allow the Search bar at Windows startup (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 119.\r\n\r\nThis policy is obsolete due to the deprecation of the Web widget, which is now known as Edge search bar. Admins should use SearchbarIsEnabledOnStartup for Edge search bar instead. Allows the Search bar to start running at Windows startup.\r\n\r\nIf you enable this policy the Search bar will start running at Windows startup by default. If the Search bar is disabled via 'WebWidgetAllowed' (Enable the Search bar) policy, this policy will not start the Search bar on Windows startup.\r\n\r\nIf you disable this policy, the Search bar will not start at Windows startup for all profiles. The option to start the Edge search bar at Windows startup will be disabled and toggled off in Microsoft Edge settings.\r\n\r\nIf you don't configure this policy, the Search bar will not start at Windows startup for all profiles. The option to start the Edge search bar at Windows startup will be toggled off in Microsoft Edge settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetisenabledonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetisenabledonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~extensions_blockexternalextensions","displayName":"Blocks external extensions from being installed (User)","description":"Control the installation of external extensions.\r\n\r\nIf you enable this setting, external extensions are blocked from being installed.\r\n\r\nIf you disable this setting or leave it unset, external extensions are allowed to be installed.\r\n\r\nExternal extensions and their installation are documented at [Alternate extension distribution methods](/microsoft-edge/extensions-chromium/developer-guide/alternate-distribution-options).","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~extensions_blockexternalextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~extensions_blockexternalextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~performance_startupboostenabled","displayName":"Enable startup boost (User)","description":"Allows Microsoft Edge processes to start at OS sign-in and restart in background after the last browser window is closed.\r\n\r\nIf Microsoft Edge is running in background mode, the browser might not close when the last window is closed and the browser won't be restarted in background when the window closes. See the 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about what happens after configuring Microsoft Edge background mode behavior.\r\n\r\nIf you enable this policy, startup boost is turned on.\r\n\r\nIf you disable this policy, startup boost is turned off.\r\n\r\nIf you don't configure this policy, startup boost may initially be off or on. The user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about startup boost: https://go.microsoft.com/fwlink/?linkid=2147018","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~performance_startupboostenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~performance_startupboostenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist","displayName":"Disable printer types on the deny list (User)","description":"The printer types on the deny list won't be discovered or have their capabilities fetched.\r\n\r\nPlacing all printer types on the deny list effectively disables printing, because there's no print destination for documents.\r\n\r\nIf you don't configure this policy, or the printer list is empty, all printer types are discoverable.\r\n\r\nPrinter destinations include extension printers and local printers. Extension printers are also known as print provider destinations, and include any destination that belongs to a Microsoft Edge extension.\r\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\r\n\r\nIn Microsoft version 93 or later, if you set this policy to 'pdf' it also disables the 'save as Pdf' option from the right click context menu.\r\n\r\nIn Microsoft version 103 or later, if you set this policy to 'onedrive' it also disables the 'save as Pdf (OneDrive)' option from print preview.\r\n\r\nPolicy options mapping:\r\n\r\n* privet (privet) = Zeroconf-based (mDNS + DNS-SD) protocol destinations\r\n\r\n* extension (extension) = Extension-based destinations\r\n\r\n* pdf (pdf) = The 'Save as PDF' destination. (93 or later, also disables from context menu)\r\n\r\n* local (local) = Local printer destinations\r\n\r\n* onedrive (onedrive) = Save as PDF (OneDrive) printer destinations. (103 or later)\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\nlocal\r\nprivet","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist_printertypedenylistdesc","displayName":"Disable printer types on the deny list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsblockedforurls","displayName":"Block Sleeping Tabs on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are not allowed to be put to sleep by Sleeping Tabs.\r\n\r\nIf the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is disabled, this list is not used and no sites will be put to sleep automatically.\r\n\r\nIf you don't configure this policy, all sites will be eligible to be put to sleep unless the user's personal configuration blocks them.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsblockedforurls_sleepingtabsblockedforurlsdesc","displayName":"Block Sleeping Tabs on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsenabled","displayName":"Configure Sleeping Tabs (User)","description":"This policy setting lets you configure whether to turn on Sleeping Tabs. Sleeping Tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, Sleeping Tabs is turned on.\r\n\r\nIndividual sites may be blocked from being put to sleep by configuring the policy 'SleepingTabsBlockedForUrls' (Block Sleeping Tabs on specific sites).\r\n\r\nIf you enable this setting, Sleeping Tabs is turned on.\r\n\r\nIf you disable this setting, Sleeping Tabs is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use Sleeping Tabs.","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs (User)","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if Sleeping Tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is enabled or is not configured and the user has enabled the Sleeping Tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings (User)","description":"Configures browsing data lifetime settings for Microsoft Edge.\r\nThis policy controls the lifetime of selected browsing data. This policy has no effect if Sync is enabled.\r\nThe available data types are the 'browsing_history', 'download_history', 'cookies_and_other_site_data', 'cached_images_and_files', 'password_signin', 'autofill', 'site_settings' and 'hosted_app_data'.\r\nMicrosoft Edge will regularly remove data of selected types that is older than 'time_to_live_in_hours'. Because data deletion only happens at certain intervals, some data might be kept slightly longer but never more than twice its expected 'time_to_live_in_hours'.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"data_types\": [\r\n \"browsing_history\"\r\n ], \r\n \"time_to_live_in_hours\": 24\r\n }, \r\n {\r\n \"data_types\": [\r\n \"password_signin\", \r\n \"autofill\"\r\n ], \r\n \"time_to_live_in_hours\": 12\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages","displayName":"Define an ordered list of preferred languages that websites should display in if the site supports the language (User)","description":"Configures the language variants that Microsoft Edge sends to websites as part of the Accept-Language request HTTP header and prevents users from adding, removing, or changing the order of preferred languages in Microsoft Edge settings. Users who want to change the languages Microsoft Edge displays in or offers to translate pages to will be limited to the languages configured in this policy.\r\n\r\nIf you enable this policy, websites will appear in the first language in the list that they support unless other site-specific logic is used to determine the display language. The language variants defined in this policy override the languages configured as part of the 'SpellcheckLanguage' (Enable specific spellcheck languages) policy.\r\n\r\nIf you don't configure or disable this policy, Microsoft Edge sends websites the user-specified preferred languages as part of the Accept-Language request HTTP header.\r\n\r\nFor detailed information on valid language variants, see https://go.microsoft.com/fwlink/?linkid=2148854.\r\n\r\nExample value: en-US,fr,es","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages_definepreferredlanguages","displayName":"Define an ordered list of preferred languages that websites should display in if the site supports the language (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended","displayName":"Block smart actions for a list of services (User)","description":"List specific services, such as PDFs, that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\r\n\r\nIf you enable the policy: :\r\n - The smart action in the mini and full context menu will be disabled for all profiles for services that match the given list.\r\n - Users will not see the smart action in the mini and full context menu on text selection for services that match the given list.\r\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be disabled for services that match the given list.\r\n\r\nIf you disable or don't configure this policy:\r\n - The smart action in the mini and full context menu will be enabled for all profiles.\r\n - Users will see the smart action in the mini and full context menu on text selection.\r\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\nsmart_actions_pdf","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended_smartactionsblocklistdesc","displayName":"Block smart actions for a list of services (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_showrecommendationsenabled","displayName":"Allow feature recommendations and browser assistance notifications from Microsoft Edge (User)","description":"This setting controls the in-browser assistance notifications which are intended to help users get the most out of Microsoft Edge. This is done by recommending features and by helping them use browser features. These notifications take the form of dialog boxes, flyouts, coach marks and banners in the browser. An example of an assistance notification would be when a user has many tabs opened in the browser. In this instance Microsoft Edge may prompt the user to try out the vertical tabs feature which is designed to give better browser tab management.\r\n\r\nDisabling this policy will stop this message from appearing again even if the user has too many tabs open.\r\n Any features that have been disabled by a management policy are not suggested to users.\r\nIf you enable or don't configure this setting, users will receive recommendations or notifications from Microsoft Edge.\r\n If you disable this setting, users will not receive any recommendations or notifications from Microsoft Edge","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_showrecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_showrecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_smartactionsblocklist","displayName":"Block smart actions for a list of services (User)","description":"List specific services, such as PDFs, that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\r\n\r\nIf you enable the policy: :\r\n - The smart action in the mini and full context menu will be disabled for all profiles for services that match the given list.\r\n - Users will not see the smart action in the mini and full context menu on text selection for services that match the given list.\r\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be disabled for services that match the given list.\r\n\r\nIf you disable or don't configure this policy:\r\n - The smart action in the mini and full context menu will be enabled for all profiles.\r\n - Users will see the smart action in the mini and full context menu on text selection.\r\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\nsmart_actions_pdf","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_smartactionsblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_smartactionsblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_smartactionsblocklist_smartactionsblocklistdesc","displayName":"Block smart actions for a list of services (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~manageability_mamenabled","displayName":"Mobile App Management Enabled (User)","description":"Allows the Microsoft Edge browser to retrieve policies from the Intune application management services and apply them to users' profiles.\r\n\r\nIf you enable this policy or don't configure it, Mobile App Management (MAM) Policies can be applied.\r\n\r\nIf you disable this policy, Microsoft Edge will not communicate with Intune to request MAM Policies.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~manageability_mamenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~manageability_mamenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode (User)","description":"Restricts background graphics printing mode. If this policy isn't set there's no restriction on printing background graphics.\r\n\r\nPolicy options mapping:\r\n\r\n* any (any) = Allow printing with and without background graphics\r\n\r\n* enabled (enabled) = Allow printing only with background graphics\r\n\r\n* disabled (disabled) = Allow printing only without background graphics\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_any","displayName":"Allow printing with and without background graphics","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_enabled","displayName":"Allow printing only with background graphics","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_disabled","displayName":"Allow printing only without background graphics","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode (User)","description":"Overrides the last used setting for printing background graphics.\r\nIf you enable this setting, background graphics printing is enabled.\r\nIf you disable this setting, background graphics printing is disabled.\r\n\r\nPolicy options mapping:\r\n\r\n* enabled (enabled) = Enable background graphics printing mode by default\r\n\r\n* disabled (disabled) = Disable background graphics printing mode by default\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingbackgroundgraphicsdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingbackgroundgraphicsdefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_enabled","displayName":"Enable background graphics printing mode by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_disabled","displayName":"Disable background graphics printing mode by default","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on shutdown (User)","description":"Controls the duration (in seconds) that keepalive requests are allowed to prevent the browser from completing its shutdown.\r\n\r\nIf you configure this policy, the browser will block completing shutdown while it processes any outstanding keepalive requests (see https://fetch.spec.whatwg.org/#request-keepalive-flag) up to the maximum period of time specified by this policy.\r\n\r\nIf you disable or don't configure this policy, the default value of 0 seconds is used and outstanding keepalive requests will be immediately cancelled during browser shutdown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_fetchkeepalivedurationsecondsonshutdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_fetchkeepalivedurationsecondsonshutdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_fetchkeepalivedurationsecondsonshutdown_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on shutdown: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin","displayName":"Sets managed configuration values for websites to specific origins (User)","description":"Setting this policy defines the return value of Managed Configuration API for given origin.\r\n\r\nManaged Configuration API is a key-value configuration that can be accessed via navigator.device.getManagedConfiguration() javascript call. This API is only available to origins which correspond to force-installed web applications via 'WebAppInstallForceList' (Configure list of force-installed Web Apps).\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"managed_configuration_hash\": \"asd891jedasd12ue9h\",\r\n \"managed_configuration_url\": \"https://static.contoso.com/configuration.json\",\r\n \"origin\": \"https://www.contoso.com\"\r\n },\r\n {\r\n \"managed_configuration_hash\": \"djio12easd89u12aws\",\r\n \"managed_configuration_url\": \"https://static.contoso.com/configuration2.json\",\r\n \"origin\": \"https://www.example.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_managedconfigurationperorigin","displayName":"Sets managed configuration values for websites to specific origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_quickviewofficefilesenabled","displayName":"Manage QuickView Office files capability in Microsoft Edge (User)","description":"Allows you to set whether users can view publicly accessible Office files on the web that aren't on OneDrive or SharePoint. (For example: Word documents, PowerPoint presentations, and Excel spreadsheets)\r\n\r\nIf you enable or don't configure this policy, these files can be viewed in Microsoft Edge using Office Viewer instead of downloading the files.\r\n\r\nIf you disable this policy, these files will be downloaded to be viewed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_quickviewofficefilesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_quickviewofficefilesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_recommended~httpauthentication_recommended_windowshelloforhttpauthenabled_recommended","displayName":"Windows Hello For HTTP Auth Enabled (User)","description":"Indicates if Windows Credential UI should be used to respond to NTLM and Negotiate authentication challenges.\r\n\r\nIf you disable this policy, a basic username and password prompt will be used to respond to NTLM and Negotiate challenges. If you enable or don't configure this policy, Windows Credential UI will be used.","helpText":"","infoUrls":[],"categoryId":"6fafeb5c-65ce-4993-b421-46e60da69131","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_recommended~httpauthentication_recommended_windowshelloforhttpauthenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_recommended~httpauthentication_recommended_windowshelloforhttpauthenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_sslerroroverrideallowedfororigins","displayName":"Allow users to proceed from the HTTPS warning page for specific origins (User)","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\r\n\r\nIf you enable or don't configure the 'SSLErrorOverrideAllowed' (Allow users to proceed from the HTTPS warning page) policy, this policy does nothing.\r\n\r\nIf you disable the 'SSLErrorOverrideAllowed' policy, configuring this policy lets you configure a list of origin patterns for sites where users can continue to click through SSL error pages. Users can't click through SSL error pages on origins that are not on this list.\r\n\r\nIf you don't configure this policy, the 'SSLErrorOverrideAllowed' policy applies for all sites.\r\n\r\nFor detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy. This policy only matches based on origin, so any path or query in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_sslerroroverrideallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_sslerroroverrideallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_sslerroroverrideallowedfororigins_sslerroroverrideallowedfororiginsdesc","displayName":"Allow users to proceed from the HTTPS warning page for specific origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~applicationguard_applicationguardfavoritessyncenabled","displayName":"Application Guard Favorites Sync Enabled (User)","description":"This policy allows Microsoft Edge computers/devices that have application guard enabled to sync favorites from the host to the container so the favorites match.\r\n\r\nIf 'ManagedFavorites' (Configure favorites) are configured, those favorites will also be synced to the container.\r\n\r\nIf you enable this policy, editing favorites in the container is disabled. So, the add favorites and add favorites folder buttons will be blurred out in the UI of the container browser.\r\n\r\nIf you disable or don't configure this policy, favorites on the host will not be shared to the container.","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~applicationguard_applicationguardfavoritessyncenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~applicationguard_applicationguardfavoritessyncenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~httpauthentication_windowshelloforhttpauthenabled","displayName":"Windows Hello For HTTP Auth Enabled (User)","description":"Indicates if Windows Credential UI should be used to respond to NTLM and Negotiate authentication challenges.\r\n\r\nIf you disable this policy, a basic username and password prompt will be used to respond to NTLM and Negotiate challenges. If you enable or don't configure this policy, Windows Credential UI will be used.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~httpauthentication_windowshelloforhttpauthenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~httpauthentication_windowshelloforhttpauthenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode","displayName":"Print Rasterization Mode (User)","description":"Controls how Microsoft Edge prints on Windows.\r\n\r\nWhen printing to a non-PostScript printer on Windows, sometimes print jobs need to be rasterized to print correctly.\r\n\r\nIf you set this policy to 'Full' or don't configure it, Microsoft Edge will do full page rasterization if necessary.\r\n\r\nIf you set this policy to 'Fast', Microsoft Edge will reduce the amount of rasterization which can help reduce print job sizes and increase printing speed.\r\n\r\nPolicy options mapping:\r\n\r\n* Full (0) = Full page rasterization\r\n\r\n* Fast (1) = Avoid rasterization if possible\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_printrasterizationmode","displayName":"Print Rasterization Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_printrasterizationmode_0","displayName":"Full page rasterization","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_printrasterizationmode_1","displayName":"Avoid rasterization if possible","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports","displayName":"Explicitly allowed network ports (User)","description":"There is a list of restricted ports built into Microsoft Edge. Connections to these ports will fail. This policy allows bypassing that list. The set of ports is defined as a comma-separated list that outgoing connections should be permitted on.\r\n\r\nPorts are restricted to prevent Microsoft Edge from being used as a vector to exploit various network vulnerabilities. Setting this policy may expose your network to attacks. This policy is intended as a temporary workaround for error code \"ERR_UNSAFE_PORT\" while migrating a service running on a blocked port to a standard port (for example port 80 or 443).\r\n\r\nMalicious websites can easily detect that this policy is set, and for which ports, then use that information to target attacks.\r\n\r\nEach port listed in this policy is labeled with a date that it can be unblocked until. After that date the port will be restricted regardless of if it's specified by the value of this policy.\r\n\r\nLeaving the value empty or unset means that all restricted ports will be blocked. Invalid port values set through this policy will be ignored while valid ones will still be applied.\r\n\r\nThis policy overrides the \"--explicitly-allowed-ports\" command-line option.\r\n\r\nPolicy options mapping:\r\n\r\n* 554 (554) = port 554 (can be unblocked until 2021/10/15)\r\n\r\n* 10080 (10080) = port 10080 (can be unblocked until 2022/04/01)\r\n\r\n* 6566 (6566) = port 6566 (can be unblocked until 2021/10/15)\r\n\r\n* 989 (989) = port 989 (can be unblocked until 2022/02/01)\r\n\r\n* 990 (990) = port 990 (can be unblocked until 2022/02/01)\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\n10080","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports_explicitlyallowednetworkportsdesc","displayName":"Explicitly allowed network ports (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_importstartuppagesettings","displayName":"Allow importing of startup page settings (User)","description":"Allows users to import Startup settings from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the Startup settings are always imported.\r\n\r\nIf you disable this policy, startup settings are not imported at first run or at manual import.\r\n\r\nIf you don't configure this policy, startup settings are imported at first run, and users can choose whether to import this data manually by selecting browser settings option during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge will import startup settings on first run, but users can select or clear **browser settings** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Microsoft Edge Legacy and Google Chrome (on Windows 7, 8, and 10) browsers.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_importstartuppagesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_importstartuppagesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_mathsolverenabled","displayName":"Let users snip a Math problem and get the solution with a step-by-step explanation in Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 125.\r\n\r\nThis policy is obsoleted because Math Solver is deprecated from Edge. This policy won't work in Microsoft Edge version 126. This policy lets you manage whether users can use the Math Solver tool in Microsoft Edge or not.\r\n\r\nIf you enable or don't configure the policy, then a user can take a snip of the Math problem and get the solution including a step-by-step explanation of the solution in a Microsoft Edge side pane.\r\n\r\nIf you disable the policy, then the Math Solver tool will be disabled and users will not be able to use it.\r\n\r\nNote: Setting the 'ComponentUpdatesEnabled' (Enable component updates in Microsoft Edge) policy to disabled will also disable the Math Solver component.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_mathsolverenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_mathsolverenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_recommended_importstartuppagesettings_recommended","displayName":"Allow importing of startup page settings (User)","description":"Allows users to import Startup settings from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the Startup settings are always imported.\r\n\r\nIf you disable this policy, startup settings are not imported at first run or at manual import.\r\n\r\nIf you don't configure this policy, startup settings are imported at first run, and users can choose whether to import this data manually by selecting browser settings option during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge will import startup settings on first run, but users can select or clear **browser settings** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Microsoft Edge Legacy and Google Chrome (on Windows 7, 8, and 10) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_recommended_importstartuppagesettings_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_recommended_importstartuppagesettings_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~applicationguard_applicationguardtrafficidentificationenabled","displayName":"Application Guard Traffic Identification (User)","description":"If you enable or don't configure this policy, Application Guard will add an extra HTTP header (X-MS-ApplicationGuard-Initiated) to all outbound HTTP requests made from the Application Guard container.\r\n\r\nIf you disable this policy, the extra header is not added to the traffic.","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~applicationguard_applicationguardtrafficidentificationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~applicationguard_applicationguardtrafficidentificationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~startup_newtabpagecontentenabled","displayName":"Allow Microsoft content on the new tab page (User)","description":"This policy applies for Microsoft Edge to all profile types, namely unsigned local user profiles, profiles signed in using a Microsoft Account, profiles signed in using Active Directory and profiles signed in using Microsoft Entra ID. The Enterprise new tab page for profiles signed in using Microsoft Entra ID can be configured in the M365 admin portal, but this policy setting takes precedence, so any M365 admin portal configurations will be ignored.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge displays Microsoft content on the new tab page. The user can choose different display options for the content. These options include, but aren't limited to: Content off, Content visible on scroll, Headings only, and Content visible. Enabling this policy doesn't force content to be visible - the user can keep setting their own preferred content position.\r\n\r\nIf you disable this policy, Microsoft Edge doesn't display Microsoft content on the new tab page, the Content control in the NTP settings flyout is disabled and set to \"Content off\", and the Layout control in the NTP settings flyout is disabled and set to \"Custom\".\r\n\r\nRelated policies: 'NewTabPageAllowedBackgroundTypes' (Configure the background types allowed for the new tab page layout), 'NewTabPageQuickLinksEnabled' (Allow quick links on the new tab page)","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~startup_newtabpagecontentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~startup_newtabpagecontentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~startup_newtabpagequicklinksenabled","displayName":"Allow quick links on the new tab page (User)","description":"If you enable or don't configure this policy, Microsoft Edge displays quick links on the new tab page, and the user can interact with the control, turning quick links on and off. Enabling this policy does not force quick links to be visible - the user can continue to turn quick links on and off.\r\n\r\nIf you disable this policy, Microsoft Edge hides quick links on the new tab page and disables the quick links control in the NTP settings flyout.\r\n\r\nThis policy only applies for Microsoft Edge local user profiles, profiles signed in using a Microsoft Account, and profiles signed in using Active Directory. To configure the Enterprise new tab page for profiles signed in using Azure Active Directory, use the M365 admin portal.\r\n\r\nRelated policies: 'NewTabPageAllowedBackgroundTypes' (Configure the background types allowed for the new tab page layout), 'NewTabPageContentEnabled' (Allow Microsoft content on the new tab page)","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~startup_newtabpagequicklinksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge~startup_newtabpagequicklinksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled","displayName":"Single sign-on for work or school sites using this profile enabled (User)","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\r\n\r\nIf you disable this policy, non-AAD profiles will not be able to use SSO using other credentials present on the machine. This will also ensure that 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' is turned off.\r\n\r\nIf you enable this policy or don't configure it, non-AAD profiles will be able to use SSO using other credentials present on the machine and 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will continue working.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault","displayName":"Configure Automatic HTTPS (User)","description":"This policy lets you manage settings for 'AutomaticHttpsDefault' (Configure Automatic HTTPS), which switches connections from HTTP to HTTPS.\r\n\r\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\r\n\r\nNote: The 'UpgradeCapableDomains' configuration requires a component list, and will not upgrade these connections if 'ComponentUpdatesEnabled' (Enable component updates in Microsoft Edge) is set to 'Disabled'.\r\n\r\nIf you don't configure this policy, 'AutomaticHttpsDefault' will be enabled, and will only upgrade connections on domains likely to support HTTPS.\r\n\r\nPolicy options mapping:\r\n\r\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\r\n\r\n* UpgradeCapableDomains (1) = Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\r\n\r\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_automatichttpsdefault","displayName":"Configure Automatic HTTPS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_automatichttpsdefault_0","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_automatichttpsdefault_1","displayName":"Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_automatichttpsdefault_2","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_headlessmodeenabled","displayName":"Control use of the Headless Mode (User)","description":"This policy setting lets you decide whether users can launch Microsoft Edge in headless mode.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge allows use of the headless mode.\r\n\r\nIf you disable this policy, Microsoft Edge denies use of the headless mode.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_headlessmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_headlessmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationlocalsitelistexpirationdays","displayName":"Specify the number of days that a site remains on the local IE mode site list (User)","description":"If the 'InternetExplorerIntegrationReloadInIEModeAllowed' (Allow unconfigured sites to be reloaded in Internet Explorer mode) policy is enabled or not configured, users will be able to tell Microsoft Edge to load specific pages in Internet Explorer mode for a limited number of days.\r\n\r\nYou can use this setting to determine how many days that configuration is remembered in the browser. After this period has elapsed, the individual page will no longer automatically load in IE mode.\r\n\r\nIf you disable the 'InternetExplorerIntegrationReloadInIEModeAllowed' policy, this policy has no effect.\r\n\r\nIf you disable or don't configure this policy, the default value of 30 days is used.\r\n\r\nIf you enable this policy, you must enter the number of days for which the sites are retained on the user's local site list in Microsoft Edge. The value can be from 0 to 90 days.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationlocalsitelistexpirationdays_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationlocalsitelistexpirationdays_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationlocalsitelistexpirationdays_internetexplorerintegrationlocalsitelistexpirationdays","displayName":"Specify the number of days that a site remains on the local IE mode site list: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationreloadiniemodeallowed","displayName":"Allow unconfigured sites to be reloaded in Internet Explorer mode (User)","description":"This policy allows users to reload unconfigured sites (that are not configured in the Enterprise Mode Site List) in Internet Explorer mode when browsing in Microsoft Edge and a site requires Internet Explorer for compatibility.\r\n\r\nAfter a site has been reloaded in Internet Explorer mode, \"in-page\" navigations will stay in Internet Explorer mode (for example, a link, script, or form on the page, or a server-side redirect from another \"in-page\" navigation). Users can choose to exit from Internet Explorer mode, or Microsoft Edge will automatically exit from Internet Explorer mode when a navigation that isn't \"in-page\" occurs (for example, using the address bar, the back button, or a favorite link).\r\n\r\nUsers can also optionally tell Microsoft Edge to use Internet Explorer mode for the site in the future. This choice will be remembered for a length of time managed by the 'InternetExplorerIntegrationLocalSiteListExpirationDays' (Specify the number of days that a site remains on the local IE mode site list) policy.\r\n\r\nIf the 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) policy is set to 'IEMode', then sites explicitly configured by the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy's site list to use Microsoft Edge can't be reloaded in Internet Explorer mode, and sites configured by the site list or by the 'SendIntranetToInternetExplorer' (Send all intranet sites to Internet Explorer) policy to use Internet Explorer mode can't exit from Internet Explorer mode.\r\n\r\nIf you enable this policy, users are allowed to reload unconfigured sites in Internet Explorer mode.\r\n\r\nIf you disable this policy, users aren't allowed to reload unconfigured sites in Internet Explorer mode.\r\n\r\nNote that if you enable this policy, it takes precedence over how you configured the 'InternetExplorerIntegrationTestingAllowed' (Allow Internet Explorer mode testing) policy, and that policy will be disabled.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationreloadiniemodeallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationreloadiniemodeallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_aadwebsitessousingthisprofileenabled_recommended","displayName":"Single sign-on for work or school sites using this profile enabled (User)","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\r\n\r\nIf you disable this policy, non-AAD profiles will not be able to use SSO using other credentials present on the machine. This will also ensure that 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' is turned off.\r\n\r\nIf you enable this policy or don't configure it, non-AAD profiles will be able to use SSO using other credentials present on the machine and 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will continue working.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_aadwebsitessousingthisprofileenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_aadwebsitessousingthisprofileenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended","displayName":"Configure Automatic HTTPS (User)","description":"This policy lets you manage settings for 'AutomaticHttpsDefault' (Configure Automatic HTTPS), which switches connections from HTTP to HTTPS.\r\n\r\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\r\n\r\nNote: The 'UpgradeCapableDomains' configuration requires a component list, and will not upgrade these connections if 'ComponentUpdatesEnabled' (Enable component updates in Microsoft Edge) is set to 'Disabled'.\r\n\r\nIf you don't configure this policy, 'AutomaticHttpsDefault' will be enabled, and will only upgrade connections on domains likely to support HTTPS.\r\n\r\nPolicy options mapping:\r\n\r\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\r\n\r\n* UpgradeCapableDomains (1) = Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\r\n\r\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault","displayName":"Configure Automatic HTTPS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault_0","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault_1","displayName":"Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault_2","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_internetexplorerintegrationreloadiniemodeallowed_recommended","displayName":"Allow unconfigured sites to be reloaded in Internet Explorer mode (User)","description":"This policy allows users to reload unconfigured sites (that are not configured in the Enterprise Mode Site List) in Internet Explorer mode when browsing in Microsoft Edge and a site requires Internet Explorer for compatibility.\r\n\r\nAfter a site has been reloaded in Internet Explorer mode, \"in-page\" navigations will stay in Internet Explorer mode (for example, a link, script, or form on the page, or a server-side redirect from another \"in-page\" navigation). Users can choose to exit from Internet Explorer mode, or Microsoft Edge will automatically exit from Internet Explorer mode when a navigation that isn't \"in-page\" occurs (for example, using the address bar, the back button, or a favorite link).\r\n\r\nUsers can also optionally tell Microsoft Edge to use Internet Explorer mode for the site in the future. This choice will be remembered for a length of time managed by the 'InternetExplorerIntegrationLocalSiteListExpirationDays' (Specify the number of days that a site remains on the local IE mode site list) policy.\r\n\r\nIf the 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) policy is set to 'IEMode', then sites explicitly configured by the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy's site list to use Microsoft Edge can't be reloaded in Internet Explorer mode, and sites configured by the site list or by the 'SendIntranetToInternetExplorer' (Send all intranet sites to Internet Explorer) policy to use Internet Explorer mode can't exit from Internet Explorer mode.\r\n\r\nIf you enable this policy, users are allowed to reload unconfigured sites in Internet Explorer mode.\r\n\r\nIf you disable this policy, users aren't allowed to reload unconfigured sites in Internet Explorer mode.\r\n\r\nNote that if you enable this policy, it takes precedence over how you configured the 'InternetExplorerIntegrationTestingAllowed' (Allow Internet Explorer mode testing) policy, and that policy will be disabled.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_internetexplorerintegrationreloadiniemodeallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_internetexplorerintegrationreloadiniemodeallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowed","displayName":"Specifies whether to allow insecure websites to make requests to more-private network endpoints (User)","description":"Controls whether insecure websites are allowed to make requests to more-private network endpoints.\r\n\r\nThis policy relates to the CORS-RFC1918 specification. See https://wicg.github.io/cors-rfc1918 for more details.\r\n\r\nA network endpoint is more private than another if:\r\n1) Its IP address is localhost and the other is not.\r\n2) Its IP address is private and the other is public.\r\nIn the future, depending on spec evolution, this policy might apply to all cross-origin requests directed at private IPs or localhost.\r\n\r\nA website is deemed secure if it meets the definition of a secure context in https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts. Otherwise, it will be treated as an insecure context.\r\n\r\nWhen this policy is either not set or set to false, the default behavior for requests from insecure contexts to more-private network endpoints will depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests feature, which may be set by a field trial or on the command line.\r\n\r\nWhen this policy is set to true, insecure websites are allowed to make requests to any network endpoint, subject to other cross-origin checks.","helpText":"","infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts (User)","description":"List of URL patterns. Private network requests initiated from insecure websites served by matching origins are allowed.\r\n\r\nIf this policy is not set, this policy behaves as if set to the empty list.\r\n\r\nFor origins not covered by the patterns specified here, the global default value will be used either from the 'InsecurePrivateNetworkRequestsAllowed' (Specifies whether to allow insecure websites to make requests to more-private network endpoints) policy, if it is set, or the user's personal configuration otherwise.\r\n\r\nNote that this policy only affects insecure origins, so secure origins (e.g. https://example.com) included in this list will be ignored.\r\n\r\nFor detailed information on valid URL patterns, please see https://docs.microsoft.com/en-us/DeployEdge/edge-learnmmore-url-list-filter%20format.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_insecureprivatenetworkrequestsallowedforurlsdesc","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill (User)","description":"The feature helps users add an additional layer of privacy to their online accounts by requiring device authentication (as a way of confirming the user's identity) before the saved password is auto-filled into a web form. This ensures that non-authorized persons can't use saved passwords for autofill.\r\n\r\nThis group policy configures the radio button selector that enables this feature for users. It also has a frequency control where users can specify how often they would like to be prompted for authentication.\r\n\r\nIf you set this policy to 'Automatically', disable this policy, or don't configure this policy, autofill will not have any authentication flow.\r\n\r\nIf you set this policy to 'WithDevicePassword', users will have to enter their device password (or preferred mode of authentication under Windows) to prove their identity before their password is auto filled. Authentication modes include Windows Hello, PIN, face recognition, or fingerprint. The frequency for authentication prompt will be set to 'Always' by default. However, users can change it to the other option, which is 'Once every browsing session'.\r\n\r\nIf you set this policy to 'WithCustomPrimaryPassword', users will be asked to create their custom password and then to be redirected to Settings. After the custom password is set, users can authenticate themselves using the custom password and their passwords will get auto-filled after successful authentication. The frequency for authentication prompt will be set to 'Always' by default. However, users can change it to the other option, which is 'Once every browsing session'.\r\n\r\nIf you set this policy to 'AutofillOff', saved passwords will no longer be suggested for autofill.\r\n\r\nPolicy options mapping:\r\n\r\n* Automatically (0) = Automatically\r\n\r\n* WithDevicePassword (1) = With device password\r\n\r\n* WithCustomPrimaryPassword (2) = With custom primary password\r\n\r\n* AutofillOff (3) = Autofill off\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_0","displayName":"Automatically","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_1","displayName":"With device password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_2","displayName":"With custom primary password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_3","displayName":"Autofill off","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist","displayName":"Allow media autoplay on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are allowed to autoplay media.\r\n\r\nIf you don't configure this policy, the global default value from the 'AutoplayAllowed' (Allow media autoplay for websites) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nNote: * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist_autoplayallowlistdesc","displayName":"Allow media autoplay on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_cecpq2enabled","displayName":"CECPQ2 post-quantum key-agreement enabled for TLS (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 113.\r\n\r\nThis policy was removed in Microsoft Edge 114 and is ignored if set. It served to disable CECPQ2, but CECPQ2 has been disabled by default. A separate policy will be introduced to control the rollout of the replacement of CECPQ2. That replacement will be a combination of the standard key-agreement X25519 with NIST's chosen post-quantum KEM, called \"Kyber\".\r\n\r\nIf this policy is not configured, or is set to enabled, then Microsoft Edge will follow the default rollout process for CECPQ2, a post-quantum key-agreement algorithm in TLS.\r\n\r\nCECPQ2 results in larger TLS messages which, in very rare cases, can trigger bugs in some networking hardware. This policy can be set to False to disable CECPQ2 while networking issues are resolved.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_cecpq2enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_cecpq2enabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_configureviewinfileexplorer","displayName":"Configure the View in File Explorer feature for SharePoint pages in Microsoft Edge (User)","description":"This setting allows you to configure the View in File Explorer capability for file management in SharePoint Online while using Microsoft Edge.\r\n\r\nYou will need to list the specific domains where this is allowed and list cookies needed for SharePoint authentication (rtFa and FedAuth).\r\n\r\nBehind the scenes, the policy allows URLs with the viewinfileexplorer: scheme to open WebDAV URLs in Windows File Explorer on pages matching the list of domains and uses the cookies you specified for WebDAV authentication.\r\n\r\nIf you enable this policy, you can use the \"View in File Explorer\" feature on the SharePoint document libraries you list. You will need to specify the SharePoint domain and authentication cookies. See example value below.\r\n\r\nIf you disable or don't configure this policy, you cannot use the \"View in File Explorer\" feature on SharePoint document libraries.\r\n\r\nNote that while this is an available option through Microsoft Edge, rather than use the View in File Explorer option, the recommended approach to managing files and folders outside of SharePoint is to sync your SharePoint files or move or copy files in SharePoint.\r\nSync your SharePoint files: https://go.microsoft.com/fwlink/p/?linkid=2166983\r\nMove or copy files in SharePoint: https://go.microsoft.com/fwlink/p/?linkid=2167123\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"cookies\": [\r\n \"rtFa\",\r\n \"FedAuth\"\r\n ],\r\n \"domain\": \"contoso.sharepoint.com\"\r\n },\r\n {\r\n \"cookies\": [\r\n \"rtFa\",\r\n \"FedAuth\"\r\n ],\r\n \"domain\": \"contoso2.sharepoint.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_configureviewinfileexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_configureviewinfileexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_configureviewinfileexplorer_configureviewinfileexplorer","displayName":"Configure the View in File Explorer feature for SharePoint pages in Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationcloudsitelist","displayName":"Configure the Enterprise Mode Cloud Site List (User)","description":"The Microsoft Edge Site Lists setting in the M365 Admin Center allows you to host your site list(s) in a compliant cloud location and manage the contents of your site list(s) through the built-in experience. This setting allows you to specify which site list within the M365 Admin Center to deploy to your users. The user must be signed into Microsoft Edge with a valid work or school account. Otherwise, Microsoft Edge will not download the site list from the cloud location.\r\n\r\nThis setting is applicable only when the 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) setting is configured.\r\n\r\nIf you configure this policy, Microsoft Edge will use the specified site list. When enabled, you can enter the identifier of the site list that you created and published to the cloud in M365 Admin Center.\r\n\r\nThis setting takes precedence over Microsoft Edge's 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy as well as Internet Explorer's site list setting (Use the Enterprise mode IE website list). If you disable or don't configure this policy, Microsoft Edge will use the 'InternetExplorerIntegrationSiteList' policy instead.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707\r\n\r\nExample value: aba95e58-070f-4784-8dcd-e5fd46c2c6d6","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationcloudsitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationcloudsitelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationcloudsitelist_internetexplorerintegrationcloudsitelist","displayName":"Configure the Enterprise Mode Cloud Site List (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval","displayName":"Configure how frequently the Enterprise Mode Site List is refreshed (User)","description":"This setting lets you specify a custom refresh interval for the Enterprise Mode Site List. The refresh interval is specified in minutes. The minimum refresh interval is 30 minutes.\r\n\r\nThis setting is applicable only when the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) or 'InternetExplorerIntegrationCloudSiteList' (Configure the Enterprise Mode Cloud Site List) setting is configured.\r\n\r\nIf you configure this policy, Microsoft Edge will attempt to retrieve an updated version of the configured Enterprise Mode Site List using the specified refresh interval.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use a default refresh interval, it is 10080 minutes (7 days) starting from version 110 or later, 120 minutes from version 93 to 110, and 30 minutes before version 93.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval_internetexplorerintegrationsitelistrefreshinterval","displayName":"Configure how frequently the Enterprise Mode Site List is refreshed: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_localbrowserdatashareenabled","displayName":"Enable Windows to search local Microsoft Edge browsing data (User)","description":"Enables Windows to index Microsoft Edge browsing data stored locally on the user's device and allows users to find and launch previously stored browsing data directly from Windows features such as the search box on the taskbar in Windows.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will publish local browsing data to the Windows Indexer.\r\n\r\nIf you disable this policy, Microsoft Edge will not share data to the Windows Indexer.\r\n\r\nNote that if you disable this policy, Microsoft Edge will remove the data shared with Windows on the device and stop sharing any new browsing data.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_localbrowserdatashareenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_localbrowserdatashareenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_msawebsitessousingthisprofileallowed","displayName":"Allow single sign-on for Microsoft personal sites using this profile (User)","description":"'Allow single sign-on for Microsoft personal sites using this profile' option allows non-MSA profiles to be able to use single sign-on for Microsoft sites using MSA credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-MSA profiles only.\r\n\r\nIf you disable this policy, non-MSA profiles will not be able to use single sign-on for Microsoft sites using MSA credentials present on the machine.\r\n\r\nIf you enable this policy or don't configure it, users will be able to use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_msawebsitessousingthisprofileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_msawebsitessousingthisprofileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_localbrowserdatashareenabled_recommended","displayName":"Enable Windows to search local Microsoft Edge browsing data (User)","description":"Enables Windows to index Microsoft Edge browsing data stored locally on the user's device and allows users to find and launch previously stored browsing data directly from Windows features such as the search box on the taskbar in Windows.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will publish local browsing data to the Windows Indexer.\r\n\r\nIf you disable this policy, Microsoft Edge will not share data to the Windows Indexer.\r\n\r\nNote that if you disable this policy, Microsoft Edge will remove the data shared with Windows on the device and stop sharing any new browsing data.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_localbrowserdatashareenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_localbrowserdatashareenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_msawebsitessousingthisprofileallowed_recommended","displayName":"Allow single sign-on for Microsoft personal sites using this profile (User)","description":"'Allow single sign-on for Microsoft personal sites using this profile' option allows non-MSA profiles to be able to use single sign-on for Microsoft sites using MSA credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-MSA profiles only.\r\n\r\nIf you disable this policy, non-MSA profiles will not be able to use single sign-on for Microsoft sites using MSA credentials present on the machine.\r\n\r\nIf you enable this policy or don't configure it, users will be able to use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_msawebsitessousingthisprofileallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_msawebsitessousingthisprofileallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_travelassistanceenabled_recommended","displayName":"Enable travel assistance (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105.\r\n\r\nThis policy is obsolete as the feature is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy. It doesn't work in Microsoft Edge after version 105.\r\nConfigure this policy to allow/disallow travel assistance.\r\n\r\nThe travel assistance feature gives helpful and relevant information to a user who performs Travel related task within the browser. This feature provides trusted and validated suggestions / information to the users from across sources gathered by Microsoft.\r\n\r\nIf you enable or don't configure this setting, travel assistance will be enabled for the users when they are performing travel related tasks.\r\n\r\nIf you disable this setting, travel assistance will be disabled and users will not be able to see any travel related recommendations.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_travelassistanceenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_travelassistanceenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended","displayName":"Sets layout for printing (User)","description":"Configuring this policy sets the layout for printing webpages.\r\n\r\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\r\n\r\nIf you enable this policy, the selected option is set as the layout option.\r\n\r\nPolicy options mapping:\r\n\r\n* portrait (0) = Sets layout option as portrait\r\n\r\n* landscape (1) = Sets layout option as landscape\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_printingwebpagelayout","displayName":"Sets layout for printing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_printingwebpagelayout_0","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_printingwebpagelayout_1","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_relaunchwindow","displayName":"Set the time interval for relaunch (User)","description":"Specifies a target time window for the end of the relaunch notification period.\r\n\r\nUsers are notified of the need for a browser relaunch or device restart based on the 'RelaunchNotification' (Notify a user that a browser restart is recommended or required for pending updates) and 'RelaunchNotificationPeriod' (Set the time period for update notifications) policy settings. Browsers and devices are forcibly restarted at the end of the notification period when the 'RelaunchNotification' policy is set to 'Required'. This RelaunchWindow policy can be used to defer the end of the notification period so that it falls within a specific time window.\r\n\r\nIf you don't configure this policy, the default target time window is the whole day (i.e., the end of the notification period is never deferred).\r\n\r\nNote: Though the policy can accept multiple items in entries, all but the first item are ignored.\r\nWarning: Setting this policy may delay application of software updates.\r\n\r\nExample value:\r\n\r\n{\r\n \"entries\": [\r\n {\r\n \"duration_mins\": 240,\r\n \"start\": {\r\n \"hour\": 2,\r\n \"minute\": 15\r\n }\r\n }\r\n ]\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"entries\": [{\"duration_mins\": 240, \"start\": {\"hour\": 2, \"minute\": 15}}]}","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_relaunchwindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_relaunchwindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_relaunchwindow_relaunchwindow","displayName":"Relaunch time window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_remotedebuggingallowed","displayName":"Allow remote debugging (User)","description":"Controls whether users may use remote debugging.\r\n\r\nIf you enable or don't configure this policy, users may use remote debugging by specifying --remote-debug-port and --remote-debugging-pipe command line switches.\r\n\r\nIf you disable this policy, users are not allowed to use remote debugging.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_remotedebuggingallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_remotedebuggingallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_travelassistanceenabled","displayName":"Enable travel assistance (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105.\r\n\r\nThis policy is obsolete as the feature is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy. It doesn't work in Microsoft Edge after version 105.\r\nConfigure this policy to allow/disallow travel assistance.\r\n\r\nThe travel assistance feature gives helpful and relevant information to a user who performs Travel related task within the browser. This feature provides trusted and validated suggestions / information to the users from across sources gathered by Microsoft.\r\n\r\nIf you enable or don't configure this setting, travel assistance will be enabled for the users when they are performing travel related tasks.\r\n\r\nIf you disable this setting, travel assistance will be disabled and users will not be able to see any travel related recommendations.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_travelassistanceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_travelassistanceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_tripledesenabled","displayName":"Enable 3DES cipher suites in TLS (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 96.\r\n\r\n'This policy was removed in version 97 after 3DES was removed from Microsoft Edge.\r\n\r\nIf the policy is set to true, then 3DES cipher suites in TLS will be enabled. If it is set to false, they will be disabled. If the policy is unset, 3DES cipher suites are disabled by default. This policy may be used to temporarily retain compatibility with an outdated server. This is a stopgap measure and the server should be reconfigured.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_tripledesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_tripledesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (User)","description":"Allows you to set whether Microsoft Edge will run the v8 JavaScript engine with JIT (Just In Time) compiler enabled or not.\r\n\r\nDisabling the JavaScript JIT will mean that Microsoft Edge may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Microsoft Edge to render web content in a more secure configuration.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'JavaScriptJitAllowedForSites' (Allow JavaScript to use JIT on these sites) and 'JavaScriptJitBlockedForSites' (Block JavaScript from using JIT on these sites) policies.\r\n\r\nIf you don't configure this policy, JavaScript JIT is enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowJavaScriptJit (1) = Allow any site to run JavaScript JIT\r\n\r\n* BlockJavaScriptJit (2) = Do not allow any site to run JavaScript JIT\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_1","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_2","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitAllowedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT enabled, but fabrikam.com will use the policy from 'DefaultJavaScriptJitSetting' (Control use of JavaScript JIT), if set, or default to JavaScript JIT enabled.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set, otherwise Javascript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_javascriptjitallowedforsitesdesc","displayName":"Allow JavaScript to use JIT on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites","displayName":"Block JavaScript from using JIT on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites which are not allowed to run JavaScript JIT (Just In Time) compiler enabled.\r\n\r\nDisabling the JavaScript JIT will mean that Microsoft Edge may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Microsoft Edge to render web content in a more secure configuration.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitBlockedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT disabled, but fabrikam.com will use the policy from 'DefaultJavaScriptJitSetting' (Control use of JavaScript JIT), if set, or default to JavaScript JIT enabled.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set, otherwise JavaScript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites_javascriptjitblockedforsitesdesc","displayName":"Block JavaScript from using JIT on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_showpdfdefaultrecommendationsenabled","displayName":"Allow notifications to set Microsoft Edge as default PDF reader (User)","description":"This policy setting lets you decide whether employees should receive recommendations to set Microsoft Edge as PDF handler.\r\n\r\nIf you enable or don't configure this setting, employees receive recommendations from Microsoft Edge to set itself as the default PDF handler.\r\n\r\nIf you disable this setting, employees will not receive any notifications from Microsoft Edge to set itself as the default PDF handler.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_showpdfdefaultrecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_showpdfdefaultrecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol","displayName":"Configure users ability to override feature flags (User)","description":"Configures users ability to override state of feature flags.\r\nIf you set this policy to 'CommandLineOverridesEnabled', users can override state of feature flags using command line arguments but not edge://flags page.\r\n\r\nIf you set this policy to 'OverridesEnabled', users can override state of feature flags using command line arguments or edge://flags page.\r\n\r\nIf you set this policy to 'OverridesDisabled', users can't override state of feature flags using command line arguments or edge://flags page.\r\n\r\nIf you don't configure this policy, the behavior is the same as the 'OverridesEnabled'.\r\n\r\nPolicy options mapping:\r\n\r\n* CommandLineOverridesEnabled (2) = Allow users to override feature flags using command line arguments only\r\n\r\n* OverridesEnabled (1) = Allow users to override feature flags\r\n\r\n* OverridesDisabled (0) = Prevent users from overriding feature flags\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"eb6409fc-fb52-413d-ae4b-eff017b52b30","categoryName":"Experimentation","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol","displayName":"Configure users ability to override feature flags (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb6409fc-fb52-413d-ae4b-eff017b52b30","categoryName":"Experimentation","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol_2","displayName":"Allow users to override feature flags using command line arguments only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol_1","displayName":"Allow users to override feature flags","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol_0","displayName":"Prevent users from overriding feature flags","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_implicitsigninenabled","displayName":"Enable implicit sign-in (User)","description":"Configure this policy to allow/disallow implicit sign-in.\r\n\r\nIf you have configured the 'BrowserSignin' (Browser sign-in settings) policy to 'Disable browser sign-in', this policy will not take any effect.\r\n\r\nIf you enable or don't configure this setting, implicit sign-in will be enabled, Edge will attempt to sign the user into their profile based on what and how they sign in to their OS.\r\n\r\nIf you disable this setting, implicit sign-in will be disabled.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_implicitsigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_implicitsigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_oneauthauthenticationenforced","displayName":"OneAuth Authentication Flow Enforced for signin (User)","description":"This policy allows users to decide whether to use the OneAuth library for sign-in and token fetch in Microsoft Edge on Windows 10 RS3 and above.\r\n\r\nIf you disable or don't configure this policy, signin process will use Windows Account Manager. Microsoft Edge would be able to use accounts you logged in to Windows, Microsoft Office, or other Microsoft applications for login, without the needing of password. Or you can provide valid account and password to sign in, which will be stored in Windows Account Manager for future usage. You will be able to investigate all accounts stored in Windows Account Manager through Windows Settings -> Accounts -> Email and accounts page.\r\n\r\nIf you enable this policy, OneAuth authentication flow will be used for account signin. The OneAuth authentication flow has fewer dependencies and can work without Windows shell. The account you use would not be stored in the Email and accounts page.\r\n\r\nThis policy will only take effect on Windows 10 RS3 and above. On Windows 10 below RS3, OneAuth is used for authentication in Microsoft Edge by default.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_oneauthauthenticationenforced_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_oneauthauthenticationenforced_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_passwordgeneratorenabled","displayName":"Allow users to get a strong password suggestion whenever they are creating an account online (User)","description":"Configures the Password Generator Settings toggle that enables/disables the feature for users.\r\n\r\nIf you enable or don't configure this policy, then Password Generator will offer users a strong and unique password suggestion (via a dropdown) on Signup and Change Password pages.\r\n\r\nIf you disable this policy, users will no longer see strong password suggestions on Signup or Change Password pages.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_passwordgeneratorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_passwordgeneratorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill (User)","description":"The feature helps users add an additional layer of privacy to their online accounts by requiring device authentication (as a way of confirming the user's identity) before the saved password is auto-filled into a web form. This ensures that non-authorized persons can't use saved passwords for autofill. Note that this feature does not protect against locally-running malware.\r\n\r\nThis group policy configures the radio button selector that enables this feature for users. It also has a frequency control where users can specify how often they would like to be prompted for authentication.\r\n\r\nIf you set this policy to 'Automatically', disable this policy, or don't configure this policy, autofill will not have any authentication flow.\r\n\r\nIf you set this policy to 'WithDevicePassword', users will have to enter their device password (or preferred mode of authentication under Windows) to prove their identity before their password is auto filled. Authentication modes include Windows Hello, PIN, face recognition, or fingerprint. The frequency for authentication prompt will be set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\r\n\r\nIf you set this policy to 'WithCustomPrimaryPassword', users will be asked to create their custom password and then to be redirected to Settings. After the custom password is set, users can authenticate themselves using the custom password and their passwords will get auto-filled after successful authentication. The frequency for authentication prompt will be set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\r\n\r\nIf you set this policy to 'AutofillOff', saved passwords will no longer be suggested for autofill.\r\n\r\nPolicy options mapping:\r\n\r\n* Automatically (0) = Automatically\r\n\r\n* WithDevicePassword (1) = With device password\r\n\r\n* WithCustomPrimaryPassword (2) = With custom primary password\r\n\r\n* AutofillOff (3) = Autofill off\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_0","displayName":"Automatically","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_1","displayName":"With device password","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout","displayName":"Sets layout for printing (User)","description":"Configuring this policy sets the layout for printing webpages.\r\n\r\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\r\n\r\nIf you enable this policy, the selected option is set as the layout option.\r\n\r\nPolicy options mapping:\r\n\r\n* portrait (0) = Sets layout option as portrait\r\n\r\n* landscape (1) = Sets layout option as landscape\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_printingwebpagelayout","displayName":"Sets layout for printing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_printingwebpagelayout_0","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_printingwebpagelayout_1","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge_webrtcrespectosroutingtableenabled","displayName":"Enable support for Windows OS routing table rules when making peer to peer connections via WebRTC (User)","description":"Controls whether WebRTC will respect the Windows OS routing table rules when making peer to peer connections, thus enabling split tunnel VPNs.\r\n\r\nIf you disable this policy or don't configure it, WebRTC will not consider the routing table and may make peer to peer connections over any available network.\r\n\r\nIf you enable this policy, WebRTC will prefer to make peer to peer connections using the indicated network interface for the remote address as indicated in the routing table.\r\n\r\nThis policy is only available on Windows.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge_webrtcrespectosroutingtableenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge_webrtcrespectosroutingtableenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~applicationguard_applicationguardpassivemodeenabled","displayName":"Ignore Application Guard site list configuration and browse Edge normally (User)","description":"Set whether Edge should ignore the Application Guard site list configuration for trusted and untrusted sites.\r\n\r\nIf you enable this policy, all navigations from Edge, including navigations to untrusted sites, will be accessed normally within Edge without redirecting to the Application Guard container. Note: this policy ONLY impacts Edge, so navigations from other browsers might get redirected to the Application Guard Container if you have the corresponding extensions enabled.\r\n\r\nIf you disable or don't configure this policy, Edge does not ignore the Application Guard site list. If users try to navigate to an untrusted site in the host, the site will open in the container.","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~applicationguard_applicationguardpassivemodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~applicationguard_applicationguardpassivemodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~identity_onlyonpremisesimplicitsigninenabled","displayName":"Only on-premises account enabled for implicit sign-in (User)","description":"Configure this policy to decide whether only on-premises accounts are enabled for implicit sign-in.\r\n\r\nIf you enable this policy, only on-premises accounts will be enabled for implicit sign-in. Microsoft Edge won't attempt to implicitly sign in to MSA or AAD accounts. Upgrade from on-premises accounts to AAD accounts will be stopped as well.\r\n\r\nIf you disable or don't configure this policy, all accounts will be enabled for implicit sign-in.\r\n\r\nThis policy will only take effect when policy 'ConfigureOnPremisesAccountAutoSignIn' (Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account) is enabled and set to 'SignInAndMakeDomainAccountNonRemovable'.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~identity_onlyonpremisesimplicitsigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~identity_onlyonpremisesimplicitsigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_browserlegacyextensionpointsblockingenabled","displayName":"Enable browser legacy extension point blocking (User)","description":"Sets the ProcessExtensionPointDisablePolicy on Microsoft Edge's browser process to block code injection from legacy third party applications.\r\n\r\nIf you enable or don't configure this policy, the ProcessExtensionPointDisablePolicy is applied to block legacy extension points in the browser process.\r\n\r\nIf you disable this policy, the ProcessExtensionPointDisablePolicy is not applied to block legacy extension points in the browser process. This has a detrimental effect on Microsoft Edge's security and stability as unknown and potentially hostile code can load inside Microsoft Edge's browser process. Only turn off the policy if there are compatibility issues with third-party software that must run inside Microsoft Edge's browser process.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_browserlegacyextensionpointsblockingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_browserlegacyextensionpointsblockingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_crossoriginwebassemblymodulesharingenabled","displayName":"Specifies whether WebAssembly modules can be sent cross-origin (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 98.\r\n\r\nSpecifies whether WebAssembly modules can be sent to another window or worker cross-origin. Cross-origin WebAssembly module sharing was deprecated as part of the efforts to deprecate document.domain, see https://github.com/mikewest/deprecating-document-domain. This policy allowed re-enabling of cross-origin WebAssembly module sharing. This policy is obsolete because it was intended to offer a longer transition period in the deprecation process.\r\n\r\nIf you enable this policy, sites can send WebAssembly modules cross-origin\r\nwithout restrictions.\r\n\r\nIf you disable or don't configure this policy, sites can only send\r\nWebAssembly modules to windows and workers in the same origin.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_crossoriginwebassemblymodulesharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_crossoriginwebassemblymodulesharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_displaycapturepermissionspolicyenabled","displayName":"Specifies whether the display-capture permissions-policy is checked or skipped (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109.\r\n\r\nThis policy is obsolete. The policy was a temporary workaround for non-spec-compliant enterprise applications.\r\n\r\nThis policy stopped working in Microsoft Edge 107 and was obsoleted in Microsoft Edge 110.\r\n\r\nThe display-capture permissions-policy gates access to getDisplayMedia(),\r\nas per this spec:\r\nhttps://www.w3.org/TR/screen-capture/#feature-policy-integration\r\nHowever, if this policy is Disabled, this requirement is not enforced,\r\nand getDisplayMedia() is allowed from contexts that would otherwise be\r\nforbidden.\r\n\r\nIf you enable or don't configure this policy, sites can only call getDisplayMedia() from\r\ncontexts which are allowlisted by the display-capture permissions-policy.\r\n\r\nIf you disable this policy, sites can call getDisplayMedia() even from contexts\r\nwhich are not allowlisted by the display-capture permissions policy.\r\nNote that other restrictions may still apply.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_displaycapturepermissionspolicyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_displaycapturepermissionspolicyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenheightadjustment","displayName":"Configure the pixel adjustment between window.open heights sourced from IE mode pages vs. Edge mode pages (User)","description":"This setting lets you specify a custom adjustment to the height of popup windows generated via window.open from the Internet Explorer mode site.\r\n\r\nIf you configure this policy, Microsoft Edge will add the adjustment value to the height, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 5.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window height calculations.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenheightadjustment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenheightadjustment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenheightadjustment_internetexplorerintegrationwindowopenheightadjustment","displayName":"Configure the pixel adjustment between window.open heights sourced from IE mode pages vs. Edge mode pages: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment","displayName":"Configure the pixel adjustment between window.open widths sourced from IE mode pages vs. Edge mode pages (User)","description":"This setting lets you specify a custom adjustment to the width of popup windows generated via window.open from the Internet Explorer mode site.\r\n\r\nIf you configure this policy, Microsoft Edge will add the adjustment value to the width, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 4.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window width calculations.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_internetexplorerintegrationwindowopenwidthadjustment","displayName":"Configure the pixel adjustment between window.open widths sourced from IE mode pages vs. Edge mode pages: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended_visualsearchenabled_recommended","displayName":"Visual search enabled (User)","description":"Visual search lets you quickly explore more related content about entities in an image.\r\n\r\nIf you enable or don't configure this policy, visual search will be enabled via image hover, context menu, and search in sidebar.\r\n\r\nIf you disable this policy, visual search will be disabled and you won't be able to get more info about images via hover, context menu, and search in sidebar.\r\n\r\nNote: Visual Search in Web Capture is still managed by 'WebCaptureEnabled' (Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge) policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended_visualsearchenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended_visualsearchenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended~smartscreen_recommended_newsmartscreenlibraryenabled_recommended","displayName":"Enable new SmartScreen library (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 107.\r\n\r\nThis policy doesn't work because it was only intended to be a short-term mechanism to support the update to a new SmartScreen client.\r\n\r\nAllows the Microsoft Edge browser to load the new SmartScreen library (libSmartScreenN) for any SmartScreen checks on site URLs or application downloads.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will use the new SmartScreen library (libSmartScreenN).\r\n\r\nIf you disable this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nBefore Microsoft Edge version 103, if you don't configure this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.\r\nThis also includes macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended~smartscreen_recommended_newsmartscreenlibraryenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended~smartscreen_recommended_newsmartscreenlibraryenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior","displayName":"Configure ShadowStack crash rollback behavior (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109.\r\n\r\nThis policy is deprecated because it's intended to serve only as a short-term mechanism to give enterprises more time to update their environments and report issues if they are found to be incompatible with Hardware-enforced Stack Protection. It won't work in Microsoft Edge as soon as version 109.\r\n\r\nMicrosoft Edge includes a Hardware-enforced Stack Protection security feature. This feature may result in the browser crashing unexpectedly in cases that do not represent an attempt to compromise the browser's security.\r\n\r\nUsing this policy, you may control the behavior of the Hardware-enforced Stack Protection feature after a crash triggered by this feature is encountered.\r\n\r\nSet this policy to 'Disable' to disable the feature.\r\n\r\nSet this policy to 'DisableUntilUpdate' to disable the feature until Microsoft Edge updates next time.\r\n\r\nSet this policy to 'Enable' to keep the feature enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* Disable (0) = Disable Hardware-enforced Stack Protection\r\n\r\n* DisableUntilUpdate (1) = Disable Hardware-enforced Stack Protection until the next Microsoft Edge update\r\n\r\n* Enable (2) = Enable Hardware-enforced Stack Protection\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_shadowstackcrashrollbackbehavior","displayName":"Configure ShadowStack crash rollback behavior (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_shadowstackcrashrollbackbehavior_0","displayName":"Disable Hardware-enforced Stack Protection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_shadowstackcrashrollbackbehavior_1","displayName":"Disable Hardware-enforced Stack Protection until the next Microsoft Edge update","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_shadowstackcrashrollbackbehavior_2","displayName":"Enable Hardware-enforced Stack Protection","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_visualsearchenabled","displayName":"Visual search enabled (User)","description":"Visual search lets you quickly explore more related content about entities in an image.\r\n\r\nIf you enable or don't configure this policy, visual search will be enabled via image hover, context menu, and search in sidebar.\r\n\r\nIf you disable this policy, visual search will be disabled and you won't be able to get more info about images via hover, context menu, and search in sidebar.\r\n\r\nNote: Visual Search in Web Capture is still managed by 'WebCaptureEnabled' (Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge) policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_visualsearchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_visualsearchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled","displayName":"Allow intranet zone file URL links from Microsoft Edge to open in Windows File Explorer (User)","description":"This setting allows file URL links to intranet zone files from intranet zone HTTPS websites to open Windows File Explorer for that file or directory.\r\n\r\nIf you enable this policy, intranet zone file URL links originating from intranet zone HTTPS pages will open Windows File Explorer to the parent directory of the file and select the file. Intranet zone directory URL links originating from intranet zone HTTPS pages will open Windows File Explorer to the directory with no items in the directory selected.\r\n\r\nIf you disable or don't configure this policy, file URL links will not open.\r\n\r\nMicrosoft Edge uses the definition of intranet zone as configured for Internet Explorer. Note that https://localhost/ is specifically blocked as an exception of allowed intranet zone host, while loopback addresses (127.0.0.*, [::1]) are considered internet zone by default.\r\n\r\nUsers may opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an \"Always open\" checkbox in external protocol dialog) policy is disabled.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~smartscreen_newsmartscreenlibraryenabled","displayName":"Enable new SmartScreen library (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 107.\r\n\r\nThis policy doesn't work because it was only intended to be a short-term mechanism to support the update to a new SmartScreen client.\r\n\r\nAllows the Microsoft Edge browser to load the new SmartScreen library (libSmartScreenN) for any SmartScreen checks on site URLs or application downloads.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will use the new SmartScreen library (libSmartScreenN).\r\n\r\nIf you disable this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nBefore Microsoft Edge version 103, if you don't configure this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.\r\nThis also includes macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~smartscreen_newsmartscreenlibraryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~smartscreen_newsmartscreenlibraryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended","displayName":"Configure when efficiency mode should become active (User)","description":"This policy setting lets you configure when efficiency mode will become active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, the default is for efficiency mode to never become active.\r\n\r\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites).\r\n\r\nSet this policy to 'AlwaysActive' and efficiency mode will always be active.\r\n\r\nSet this policy to 'NeverActive' and efficiency mode will never become active.\r\n\r\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode will become active when the device is unplugged.\r\n\r\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode will become active when the device is unplugged and the battery is low.\r\n\r\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode will take moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode will take additional steps to save battery.\r\n\r\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nIf the device does not have a battery, efficiency mode will never become active in any mode other than 'AlwaysActive' unless the setting or 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is enabled.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\r\n\r\nPolicy options mapping:\r\n\r\n* AlwaysActive (0) = Efficiency mode is always active\r\n\r\n* NeverActive (1) = Efficiency mode is never active\r\n\r\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\r\n\r\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\r\n\r\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_4","displayName":"When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_5","displayName":"When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"This policy setting lets you configure when efficiency mode will become active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, the default is for efficiency mode to never become active.\r\n\r\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites).\r\n\r\nSet this policy to 'AlwaysActive' and efficiency mode will always be active.\r\n\r\nSet this policy to 'NeverActive' and efficiency mode will never become active.\r\n\r\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode will become active when the device is unplugged.\r\n\r\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode will become active when the device is unplugged and the battery is low.\r\n\r\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode will take moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode will take additional steps to save battery.\r\n\r\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nIf the device does not have a battery, efficiency mode will never become active in any mode other than 'AlwaysActive' unless the setting or 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is enabled.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\r\n\r\nPolicy options mapping:\r\n\r\n* AlwaysActive (0) = Efficiency mode is always active\r\n\r\n* NeverActive (1) = Efficiency mode is never active\r\n\r\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\r\n\r\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\r\n\r\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_4","displayName":"When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_5","displayName":"When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_audioprocesshighpriorityenabled","displayName":"Allow the audio process to run with priority above normal on Windows (User)","description":"This policy controls the priority of the audio process on Windows.\r\nIf this policy is enabled, the audio process will run with above normal priority.\r\nIf this policy is disabled, the audio process will run with normal priority.\r\nIf this policy is not configured, the default configuration for the audio process will be used.\r\nThis policy is intended as a temporary measure to give enterprises the ability to\r\nrun audio with higher priority to address certain performance issues with audio capture.\r\nThis policy will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_audioprocesshighpriorityenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_audioprocesshighpriorityenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_autolaunchprotocolscomponentenabled","displayName":"AutoLaunch Protocols Component Enabled (User)","description":"Specifies whether the AutoLaunch Protocols component should be enabled. This component allows Microsoft to provide a list similar to that of the 'AutoLaunchProtocolsFromOrigins' (Define a list of protocols that can launch an external application from listed origins without prompting the user) policy, allowing certain external protocols to launch without prompt or blocking certain protocols (on specified origins). By default, this component is enabled.\r\n\r\nIf you enable or don't configure this policy, the AutoLaunch Protocols component is enabled.\r\n\r\nIf you disable this policy, the AutoLaunch Protocols component is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_autolaunchprotocolscomponentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_autolaunchprotocolscomponentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_forcesynctypes","displayName":"Configure the list of types that are included for synchronization (User)","description":"If you enable this policy all the specified data types will be included for synchronization for Azure AD/Azure AD-Degraded user profiles. This policy can be used to ensure the type of data uploaded to the Microsoft Edge synchronization service.\r\n\r\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", \"history\", \"openTabs\", \"edgeWallet\", \"collections\", \"apps\", and \"edgeFeatureUsage\". The \"edgeFeatureUsage\" data type will be supported starting in Microsoft Edge version 134. Note that these data type names are case sensitive.\r\n\r\nUsers will not be able to override the enabled data types.\r\n\r\nExample value:\r\n\r\nfavorites","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_forcesynctypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_forcesynctypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_forcesynctypes_forcesynctypesdesc","displayName":"Configure the list of types that are included for synchronization (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes","displayName":"Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode (User)","description":"Starting with Microsoft Edge version 96, navigations that switch between Internet Explorer mode and Microsoft Edge will include form data.\r\n\r\nIf you enable this policy, you can specify which data types should be included in navigations between Microsoft Edge and Internet Explorer mode.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use the new behavior of including form data in navigations that change modes.\r\n\r\nTo learn more, see https://go.microsoft.com/fwlink/?linkid=2174004\r\n\r\nPolicy options mapping:\r\n\r\n* IncludeNone (0) = Do not send form data or headers\r\n\r\n* IncludeFormDataOnly (1) = Send form data only\r\n\r\n* IncludeHeadersOnly (2) = Send additional headers only\r\n\r\n* IncludeFormDataAndHeaders (3) = Send form data and additional headers\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes","displayName":"Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_0","displayName":"Do not send form data or headers","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_1","displayName":"Send form data only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_2","displayName":"Send additional headers only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_3","displayName":"Send form data and additional headers","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorermodetoolbarbuttonenabled","displayName":"Show the Reload in Internet Explorer mode button in the toolbar (User)","description":"Set this policy to show the Reload in Internet Explorer mode button in the toolbar. Users can hide the button in the toolbar through edge://settings/appearance. The button will only be shown on the toolbar when the 'InternetExplorerIntegrationReloadInIEModeAllowed' (Allow unconfigured sites to be reloaded in Internet Explorer mode) policy is enabled or if the user has chosen to enable \"Allow sites to be reloaded in Internet Explorer mode\".\r\n\r\nIf you enable this policy, the Reload in Internet mode button is pinned to the toolbar.\r\n\r\nIf you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default. Users can toggle the Show Internet Explorer mode button in edge://settings/appearance.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorermodetoolbarbuttonenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorermodetoolbarbuttonenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended_internetexplorermodetoolbarbuttonenabled_recommended","displayName":"Show the Reload in Internet Explorer mode button in the toolbar (User)","description":"Set this policy to show the Reload in Internet Explorer mode button in the toolbar. Users can hide the button in the toolbar through edge://settings/appearance. The button will only be shown on the toolbar when the 'InternetExplorerIntegrationReloadInIEModeAllowed' (Allow unconfigured sites to be reloaded in Internet Explorer mode) policy is enabled or if the user has chosen to enable \"Allow sites to be reloaded in Internet Explorer mode\".\r\n\r\nIf you enable this policy, the Reload in Internet mode button is pinned to the toolbar.\r\n\r\nIf you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default. Users can toggle the Show Internet Explorer mode button in edge://settings/appearance.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended_internetexplorermodetoolbarbuttonenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended_internetexplorermodetoolbarbuttonenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended","displayName":"Configure when efficiency mode should become active (User)","description":"This policy setting lets you configure when efficiency mode will become active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, the default is for efficiency mode to never become active.\r\n\r\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites).\r\n\r\nSet this policy to 'AlwaysActive' and efficiency mode will always be active.\r\n\r\nSet this policy to 'NeverActive' and efficiency mode will never become active.\r\n\r\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode will become active when the device is unplugged.\r\n\r\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode will become active when the device is unplugged and the battery is low.\r\n\r\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode will take moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode will take additional steps to save battery.\r\n\r\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nIf the device does not have a battery, efficiency mode will never become active in any mode other than 'AlwaysActive' unless the setting or 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is enabled.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\r\n\r\nPolicy options mapping:\r\n\r\n* AlwaysActive (0) = Efficiency mode is always active\r\n\r\n* NeverActive (1) = Efficiency mode is never active\r\n\r\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\r\n\r\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\r\n\r\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~performance_recommended_efficiencymode_recommended_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended","displayName":"Configure Edge Website Typo Protection (User)","description":"This policy setting lets you configure whether to turn on Edge Website Typo Protection. Edge Website Typo Protection provides warning messages to help protect your users from potential typosquatting sites. By default, Edge Website Typo Protection is turned on.\r\n\r\nIf you enable this policy, Edge Website Typo Protection is turned on.\r\n\r\nIf you disable this policy, Edge Website Typo Protection is turned off.\r\n\r\nIf you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.","helpText":"","infoUrls":[],"categoryId":"1ccd3115-55e7-464f-9bb9-d38a92191306","categoryName":"Edge Website Typo Protection settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_rendererappcontainerenabled","displayName":"Enable renderer in app container (User)","description":"Launches Renderer processes into an App Container for\r\nadditional security benefits.\r\n\r\nIf you don't configure this policy, Microsoft Edge will launch the renderer process in an app\r\ncontainer in a future update.\r\n\r\nIf you enable this policy, Microsoft Edge will launch the renderer process in an app container.\r\n\r\nIf you disable this policy, Microsoft Edge will not launch the renderer process in an app container.\r\n\r\nOnly turn off the policy if there are compatibility issues with\r\nthird-party software that must run inside Microsoft Edge's renderer processes.\r\n\r\nThis policy will only take effect on Windows 10 RS5 and above.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_rendererappcontainerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_rendererappcontainerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_sharedlinksenabled","displayName":"Show links shared from Microsoft 365 apps in History (User)","description":"Allows Microsoft Edge to display links recently shared by or shared with the user from Microsoft 365 apps in History.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge displays links recently shared by or shared with the user from Microsoft 365 apps in History.\r\n\r\nIf you disable this policy, Microsoft Edge does not display links recently shared by or shared with the user from Microsoft 365 apps in History. The control in Microsoft Edge settings is disabled and set to off.\r\n\r\nThis policy only applies for Microsoft Edge local user profiles and profiles signed in using Azure Active Directory.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_sharedlinksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_sharedlinksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~applicationguard_applicationguarduploadblockingenabled","displayName":"Prevents files from being uploaded while in Application Guard (User)","description":"Sets whether files can be uploaded while in Application Guard.\r\n\r\nIf you enable this policy, users will not be able to upload files in Application Guard.\r\n\r\nIf you disable or don't configure this policy, users will be able to upload files while in Application Guard.","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~applicationguard_applicationguarduploadblockingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~applicationguard_applicationguarduploadblockingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"This policy setting lets you configure when efficiency mode will become active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, the default is for efficiency mode to never become active.\r\n\r\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites).\r\n\r\nSet this policy to 'AlwaysActive' and efficiency mode will always be active.\r\n\r\nSet this policy to 'NeverActive' and efficiency mode will never become active.\r\n\r\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode will become active when the device is unplugged.\r\n\r\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode will become active when the device is unplugged and the battery is low.\r\n\r\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode will take moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode will take additional steps to save battery.\r\n\r\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nIf the device does not have a battery, efficiency mode will never become active in any mode other than 'AlwaysActive' unless the setting or 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is enabled.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\r\n\r\nPolicy options mapping:\r\n\r\n* AlwaysActive (0) = Efficiency mode is always active\r\n\r\n* NeverActive (1) = Efficiency mode is never active\r\n\r\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\r\n\r\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\r\n\r\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode","displayName":"Print PostScript Mode (User)","description":"Controls how Microsoft Edge prints on Microsoft Windows.\r\n\r\nPrinting to a PostScript printer on Microsoft Windows different PostScript generation methods can affect printing performance.\r\n\r\nIf you set this policy to Default, Microsoft Edge will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts.\r\n\r\nIf you set this policy to Type42, Microsoft Edge will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\r\n\r\nIf you don't configure this policy, Microsoft Edge will be in Default mode.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default\r\n\r\n* Type42 (1) = Type42\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_printpostscriptmode","displayName":"Print PostScript Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_printpostscriptmode_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_printpostscriptmode_1","displayName":"Type42","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI (User)","description":"Controls print image resolution when Microsoft Edge prints PDFs with rasterization.\r\n\r\nWhen printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution will significantly increase the processing and printing time while a low resolution can lead to poor imaging quality.\r\n\r\nIf you set this policy, it allows a particular resolution to be specified for use when rasterizing PDFs for printing.\r\n\r\nIf you set this policy to zero or don't configure it, the system default resolution will be used during rasterization of page images.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~typosquattingchecker_typosquattingcheckerenabled","displayName":"Configure Edge Website Typo Protection (User)","description":"This policy setting lets you configure whether to turn on Edge Website Typo Protection. Edge Website Typo Protection provides warning messages to help protect your users from potential typosquatting sites. By default, Edge Website Typo Protection is turned on.\r\n\r\nIf you enable this policy, Edge Website Typo Protection is turned on.\r\n\r\nIf you disable this policy, Edge Website Typo Protection is turned off.\r\n\r\nIf you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~typosquattingchecker_typosquattingcheckerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~typosquattingchecker_typosquattingcheckerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_accessibilityimagelabelsenabled","displayName":"Let screen reader users get image descriptions from Microsoft (User)","description":"Lets screen reader users get descriptions of unlabeled images on the web.\r\n\r\nIf you enable or don't configure this policy, users have the option of using an anonymous Microsoft service. This service provides automatic descriptions for unlabeled images users encounter on the web when they're using a screen reader.\r\n\r\nIf you disable this policy, users can't enable the Get Image Descriptions from Microsoft feature.\r\n\r\nWhen this feature is enabled, the content of images that need a generated description is sent to Microsoft servers to generate a description.\r\n\r\nNo cookies or other user data is sent to Microsoft, and Microsoft doesn't save or log any image content.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_accessibilityimagelabelsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_accessibilityimagelabelsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request header support enabled (User)","description":"This policy lets you configure support of CORS non-wildcard request headers.\r\n\r\nMicrosoft Edge version 97 introduces support for CORS non-wildcard request headers. When a script makes a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header must be explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. See https://go.microsoft.com/fwlink/?linkid=2180022 for more detail.\r\n\r\nIf you enable or don't configure the policy, Microsoft Edge will support the CORS non-wildcard request headers and behave as previously described.\r\n\r\nIf you disable this policy, Microsoft Edge will allow the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\r\n\r\nThis policy is a temporary workaround for the new CORS non-wildcard request header feature. It's intended to be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_corsnonwildcardrequestheaderssupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_corsnonwildcardrequestheaderssupport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgediscoverenabled","displayName":"Discover feature In Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105.\r\n\r\nThis policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy.\r\n\r\nThis policy lets you configure the Discover feature in Microsoft Edge.\r\n\r\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\r\n\r\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\r\n\r\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgediscoverenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgediscoverenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgeenhanceimagesenabled","displayName":"Enhance images enabled (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 121.\r\n\r\nThe enhance images feature is deprecated and starting in 122 this policy will be removed. Set whether Microsoft Edge can automatically enhance images to show you sharper images with better color, lighting, and contrast.\r\n\r\nIf you enable this policy or don't configure the policy, Microsoft Edge will automatically enhance images on specific web applications.\r\n\r\nIf you disable this policy, Microsoft Edge will not enhance images.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgeenhanceimagesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgeenhanceimagesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_internetexplorermodetabinedgemodeallowed","displayName":"Allow sites configured for Internet Explorer mode to open in Microsoft Edge (User)","description":"This policy lets sites configured to open in Internet Explorer mode to be opened by Microsoft Edge for testing on a modern browser without removing them from the site list.\r\n\r\nUsers can configure this setting in the \"More tools\" menu by selecting 'Open sites in Microsoft Edge'.\r\n\r\nIf you enable this policy, the option to 'Open sites in Microsoft Edge' will be visible under \"More tools\". Users use this option to test IE mode sites on a modern browser.\r\n\r\nIf you disable or don't configure this policy, users can't see the option 'Open in Microsoft Edge' under the \"More tools\" menu. However, users can access this menu option with the --ie-mode-test flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_internetexplorermodetabinedgemodeallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_internetexplorermodetabinedgemodeallowed_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_openmicrosoftlinksinedgeenabled","displayName":"Always open links from certain Microsoft apps in Microsoft Edge (User)","description":"Make Microsoft Edge open links from other supported Microsoft Apps, such as Microsoft Outlook and Microsoft Teams on Windows 10 and above, so that web links can be opened using the correct profile in Microsoft Edge. This does not change the browser set as the default in Windows settings.\r\n\r\nIf you do not configure this policy, the end user will see a prompt to manage this policy the first time Microsoft Edge opens a link from supported Microsoft apps. Users can manage this policy in Microsoft Edge settings at any time. The default browser setting in Windows will not be changed based on the Microsoft Edge setting.\r\n\r\nIf this policy is Enabled, Microsoft Edge will open web links from these apps, and will use the correct profile where possible, even when Microsoft Edge is not set as the default in Windows settings. This policy does not change the browser set as the default in Windows settings.\r\n\r\nIf this policy is disabled, the browser set as the default in Windows settings will be used to open web links from these apps.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_openmicrosoftlinksinedgeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_openmicrosoftlinksinedgeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended_edgediscoverenabled_recommended","displayName":"Discover feature In Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105.\r\n\r\nThis policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy.\r\n\r\nThis policy lets you configure the Discover feature in Microsoft Edge.\r\n\r\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\r\n\r\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\r\n\r\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended_edgediscoverenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended_edgediscoverenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreendnsrequestsenabled_recommended","displayName":"Enable Microsoft Defender SmartScreen DNS requests (User)","description":"This policy lets you configure whether to enable DNS requests made by Microsoft Defender SmartScreen. Note: Disabling DNS requests will prevent Microsoft Defender SmartScreen from getting IP addresses, and potentially impact the IP-based protections provided.\r\n\r\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen will make DNS requests.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen will not make any DNS requests.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreendnsrequestsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreendnsrequestsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_websqlinthirdpartycontextenabled","displayName":"Force WebSQL in third-party contexts to be re-enabled (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 100.\r\n\r\nThis policy is obsolete because it was intended to be a short-term mechanism to give enterprises more time to update their web content when it's found to be incompatible with the change to disable WebSQL in third-party contexts. It doesn't work in Microsoft Edge after version 100.\r\n\r\nWebSQL in third-party contexts (for example, cross-site iframes) is off by default as of Microsoft Edge version 97 and was fully removed in version 101.\r\n\r\nIf you enable this policy, WebSQL in third-party contexts will be re-enabled.\r\n\r\nIf you disable this policy or don't configure it, WebSQL in third-party contexts will stay off.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_websqlinthirdpartycontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_websqlinthirdpartycontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls","displayName":"Automatically grant sites permission to connect all serial ports (User)","description":"Setting the policy allows you to list sites which are automatically granted permission to access all available serial ports.\r\n\r\nThe URLs must be valid, or the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered.\r\n\r\nThis policy overrides 'DefaultSerialGuardSetting' (Control use of the Serial API), 'SerialAskForUrls' (Allow the Serial API on specific sites), 'SerialBlockedForUrls' (Block the Serial API on specific sites) and the user's preferences.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls_serialallowallportsforurlsdesc","displayName":"Automatically grant sites permission to connect all serial ports (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls","displayName":"Automatically grant sites permission to connect to USB serial devices (User)","description":"Setting the policy lets you list sites that are automatically granted permission to access USB serial devices with vendor and product IDs that match the vendor_id and product_id fields.\r\n\r\nOptionally you can omit the product_id field. This enables site access to all the vendor's devices. When you provide a product ID, then you give the site access to a specific device from the vendor but not all devices.\r\n\r\nThe URLs must be valid, or the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered.\r\n\r\nThis policy overrides 'DefaultSerialGuardSetting' (Control use of the Serial API), 'SerialAskForUrls' (Allow the Serial API on specific sites), 'SerialBlockedForUrls' (Block the Serial API on specific sites) and the user's preferences.\r\n\r\nThis policy only affects access to USB devices through the Web Serial API. To grant access to USB devices through the WebUSB API see the 'WebUsbAllowDevicesForUrls' (Grant access to specific sites to connect to specific USB devices) policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"product_id\": 5678,\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://specific-device.example.com\"\r\n ]\r\n },\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://all-vendor-devices.example.com\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_serialallowusbdevicesforurls","displayName":"Automatically grant sites permission to connect to USB serial devices (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins","displayName":"Allow Same Origin Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'ScreenCaptureAllowed' (Allow or deny screen capture).\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins_sameorigintabcaptureallowedbyoriginsdesc","displayName":"Allow Same Origin Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins","displayName":"Allow Desktop, Window, and Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of Capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in any of the following policies: 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins).\r\n\r\nIf a site matches a URL pattern in this policy, the 'ScreenCaptureAllowed' (Allow or deny screen capture) will not be considered.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins_screencaptureallowedbyoriginsdesc","displayName":"Allow Desktop, Window, and Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins","displayName":"Allow Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can use Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in the 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins) policy.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'ScreenCaptureAllowed' (Allow or deny screen capture).\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins_tabcaptureallowedbyoriginsdesc","displayName":"Allow Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_windowcaptureallowedbyorigins","displayName":"Allow Window and Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can use Window and Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of Capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in any of the following policies: 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins).\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'ScreenCaptureAllowed' (Allow or deny screen capture).\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_windowcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_windowcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_windowcaptureallowedbyorigins_windowcaptureallowedbyoriginsdesc","displayName":"Allow Window and Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~smartscreen_smartscreendnsrequestsenabled","displayName":"Enable Microsoft Defender SmartScreen DNS requests (User)","description":"This policy lets you configure whether to enable DNS requests made by Microsoft Defender SmartScreen. Note: Disabling DNS requests will prevent Microsoft Defender SmartScreen from getting IP addresses, and potentially impact the IP-based protections provided.\r\n\r\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen will make DNS requests.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen will not make any DNS requests.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~smartscreen_smartscreendnsrequestsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~smartscreen_smartscreendnsrequestsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge (User)","description":"This policy lets you enhance the security state in Microsoft Edge.\r\n\r\nIf you set this policy to 'StandardMode', the enhanced mode will be turned off and Microsoft Edge will fallback to its standard security mode.\r\n\r\nIf you set this policy to 'BalancedMode', the security state will be in balanced mode.\r\n\r\nIf you set this policy to 'StrictMode', the security state will be in strict mode.\r\n\r\nIf you set this policy to 'BasicMode', the security state will be in basic mode.\r\n\r\nNote: Sites that use WebAssembly (WASM) are not currently supported when 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2195852\r\n\r\nPolicy options mapping:\r\n\r\n* StandardMode (0) = Standard mode\r\n\r\n* BalancedMode (1) = Balanced mode\r\n\r\n* StrictMode (2) = Strict mode\r\n\r\n* BasicMode (2) = Basic mode\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_0","displayName":"Standard mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_1","displayName":"Balanced mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_2","displayName":"Strict mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_3","displayName":"Basic mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_edgefollowenabled","displayName":"Enable Follow service in Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 126.\r\n\r\nLets Microsoft Edge browser enable Follow service and apply it to users.\r\n\r\nUsers can use the Follow feature for an influencer, site, or topic in Microsoft Edge..\r\n\r\nIf you enable or don't configure this policy, Follow in Microsoft Edge can be applied.\r\n\r\nIf you disable this policy, Microsoft Edge will not communicate with Follow service to provide the follow feature.\r\n\r\nThis policy is obsolete after version 126.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_edgefollowenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_edgefollowenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge (User) (obsolete)","description":"This policy lets you enhance the security state in Microsoft Edge.\r\n\r\nIf you set this policy to 'StandardMode', the enhanced mode will be turned off and Microsoft Edge will fallback to its standard security mode.\r\n\r\nIf you set this policy to 'BalancedMode', the security state will be in balanced mode.\r\n\r\nIf you set this policy to 'StrictMode', the security state will be in strict mode.\r\n\r\nIf you set this policy to 'BasicMode', the security state will be in basic mode.\r\n\r\nNote: Sites that use WebAssembly (WASM) are not supported on 32-bit systems when 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\r\n\r\nStarting in Microsoft Edge 113, 'BasicMode' is deprecated and is treated the same as 'BalancedMode'. It won't work in Microsoft Edge version 116.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895\r\n\r\nPolicy options mapping:\r\n\r\n* StandardMode (0) = Standard mode\r\n\r\n* BalancedMode (1) = Balanced mode\r\n\r\n* StrictMode (2) = Strict mode\r\n\r\n* BasicMode (3) = (Deprecated) Basic mode\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge (User) (obsolete)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_0","displayName":"Standard mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_1","displayName":"Balanced mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_2","displayName":"Strict mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodebypasslistdomains","displayName":"Configure the list of domains for which enhance security mode will not be enforced (User)","description":"Configure the list of enhance security trusted domains. This means that\r\nenhance security mode will not be enforced when loading the sites in trusted domains.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodebypasslistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodebypasslistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodebypasslistdomains_enhancesecuritymodebypasslistdomainsdesc","displayName":"Configure the list of domains for which enhance security mode will not be enforced (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodeenforcelistdomains","displayName":"Configure the list of domains for which enhance security mode will always be enforced (User)","description":"Configure the list of enhance security untrusted domains. This means that\r\nenhance security mode will always be enforced when loading the sites in untrusted domains.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodeenforcelistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodeenforcelistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodeenforcelistdomains_enhancesecuritymodeenforcelistdomainsdesc","displayName":"Configure the list of domains for which enhance security mode will always be enforced (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_inappsupportenabled","displayName":"In-app support Enabled (User)","description":"Microsoft Edge uses the in-app support feature (enabled by default) to allow users to contact our support agents directly from the browser. Also, by default, users can't disable (turn off) the in-app support feature.\r\n\r\nIf you enable this policy or don't configure it, users can invoke in-app support.\r\n\r\nIf you disable this policy, users can't invoke in-app support.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_inappsupportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_inappsupportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_microsoftedgeinsiderpromotionenabled","displayName":"Microsoft Edge Insider Promotion Enabled (User)","description":"Shows content promoting the Microsoft Edge Insider channels on the About Microsoft Edge settings page.\r\n\r\nIf you enable or don't configure this policy, the Microsoft Edge Insider promotion content will be shown on the About Microsoft Edge page.\r\n\r\nIf you disable this policy, the Microsoft Edge Insider promotion content will not be shown on the About Microsoft Edge page.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_microsoftedgeinsiderpromotionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_microsoftedgeinsiderpromotionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_u2fsecuritykeyapienabled","displayName":"Allow using the deprecated U2F Security Key API (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 103.\r\n\r\nThis policy is obsolete because it was intended to be a short-term mechanism to give enterprises more time to update their web content when it's found to be incompatible with the change to remove the U2F Security Key API. It doesn't work in Microsoft Edge after version 103.\r\n\r\nIf you enable this policy, the deprecated U2F Security Key API can be used and the deprecation reminder prompt shown for U2F API requests is suppressed.\r\n\r\nIf you disable this policy or don't configure it, the U2F Security Key API is disabled by default and can only be used by sites that register for and use the U2FSecurityKeyAPI origin trial which ended after Microsoft Edge version 103.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_u2fsecuritykeyapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_u2fsecuritykeyapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings","displayName":"Print preview sticky settings (User)","description":"Specifies whether print preview should apply last used settings for Microsoft Edge PDF and webpages.\r\n\r\nIf you set this policy to 'EnableAll' or don't configure it, Microsoft Edge applies the last used print preview settings for both PDF and webpages.\r\n\r\nIf you set this policy to 'DisableAll', Microsoft Edge doesn't apply the last used print preview settings for both PDF and webpages.\r\n\r\nIf you set this policy to 'DisablePdf', Microsoft Edge doesn't apply the last used print preview settings for PDF printing and retains it for webpages.\r\n\r\nIf you set this policy to 'DisableWebpage', Microsoft Edge doesn't apply the last used print preview settings for webpage printing and retain it for PDF.\r\n\r\nThis policy is only available if you enable or don't configure the 'PrintingEnabled' (Enable printing) policy.\r\n\r\nPolicy options mapping:\r\n\r\n* EnableAll (0) = Enable sticky settings for PDF and Webpages\r\n\r\n* DisableAll (1) = Disable sticky settings for PDF and Webpages\r\n\r\n* DisablePdf (2) = Disable sticky settings for PDF\r\n\r\n* DisableWebpage (3) = Disable sticky settings for Webpages\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_printstickysettings","displayName":"Print preview sticky settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_printstickysettings_0","displayName":"Enable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_printstickysettings_1","displayName":"Disable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_printstickysettings_2","displayName":"Disable sticky settings for PDF","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge~printing_printstickysettings_printstickysettings_3","displayName":"Disable sticky settings for Webpages","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_addressbareditingenabled","displayName":"Configure address bar editing (User)","description":"If you enable or don't configure this policy, users can change the URL in the address bar.\r\n\r\nIf you disable this policy, it prevents users from changing the URL in the address bar.\r\n\r\nNote: This policy doesn't prevent the browser from navigating to any URL. Users can still navigate to any URL by using the search option in the default New Tab Page, or using any link that leads to a web search engine. To ensure that users can only go to sites you expect, consider configuring the following policies in addition to this policy:\r\n\r\n- 'NewTabPageLocation' (Configure the new tab page URL)\r\n\r\n- 'HomepageLocation' (Configure the home page URL)\r\n\r\n- 'HomepageIsNewTabPage' (Set the new tab page as the home page)\r\n\r\n- 'URLBlocklist' (Block access to a list of URLs) and 'URLAllowlist' (Define a list of allowed URLs) to scope the pages that browser can navigate to.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_addressbareditingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_addressbareditingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_allowgamesmenu","displayName":"Allow users to access the games menu (User)","description":"If you enable or don't configure this policy, users can access the games menu.\r\n\r\nIf you disable this policy, users won't be able to access the games menu.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_allowgamesmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_allowgamesmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins","displayName":"Define a list of protocols that can not be silently blocked by anti-flood protection (User)","description":"Allows you to create a list of protocols, and for each protocol an associated list of allowed origin patterns. These origins won't be silently blocked from launching an external application by anti-flood protection. The trailing separator shouldn't be included when listing the protocol. For example, list \"skype\" instead of \"skype:\" or \"skype://\".\r\n\r\nIf you configure this policy, a protocol will only be permitted to bypass being silently blocked by anti-flood protection if:\r\n\r\n- the protocol is listed\r\n\r\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\r\n\r\nIf either condition is false, the external protocol launch may be blocked by anti-flood protection.\r\n\r\nIf you don't configure this policy, no protocols can bypass being silently blocked.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' (Block access to a list of URLs) policy, that are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\n\r\nThis policy doesn't work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"protocol\": \"spotify\",\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"msteams\",\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"msoutlook\",\r\n \"allowed_origins\": [\r\n \"*\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_donotsilentlyblockprotocolsfromorigins","displayName":"Define a list of protocols that can not be silently blocked by anti-flood protection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_hubssidebarenabled","displayName":"Show Hubs Sidebar (User)","description":"Shows a launcher bar on the right side of Microsoft Edge's screen.\r\n\r\nEnable this policy to always show the Sidebar.\r\nDisable this policy to never show the Sidebar.\r\n\r\nIf you don't configure the policy, users can choose whether to show the Sidebar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_hubssidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_hubssidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting","displayName":"Configure reporting of potentially misconfigured neutral site URLs to the M365 Admin Center Site Lists app (User)","description":"This setting lets you enable reporting of sites that might need to be configured as a neutral site on the Enterprise Mode Site List. The user must be signed into Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant specified by the policy.\r\n\r\nIf you configure this policy, Microsoft Edge will send a report to the M365 Admin Center Site Lists app when a navigation appears stuck redirecting back and forth between the Microsoft Edge and Internet Explorer engines several times. This usually indicates that redirection to an authentication server is switching engines, which repeatedly fails in a loop. The report will show the URL of the site that is the redirect target, minus any query string or fragment. The user's identity isn't reported.\r\n\r\nFor this reporting to work correctly, you must have successfully visited the Microsoft Edge Site Lists app in the M365 Admin Center at least once. This activates a per-tenant storage account used to store these reports. Microsoft Edge will still attempt to send reports if this step hasn't been completed. However, the reports will not be stored in the Site Lists app.\r\n\r\nWhen enabling this policy, you must specify your O365 tenant ID. To learn more about finding your O365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will never send reports about potentially misconfigured neutral sites to the Site Lists app.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707\r\n\r\nExample value: aba95e58-070f-4784-8dcd-e5fd46c2c6d6","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting_internetexplorerintegrationcloudneutralsitesreporting","displayName":"Configure reporting of potentially misconfigured neutral site URLs to the M365 Admin Center Site Lists app (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting","displayName":"Configure reporting of IE Mode user list entries to the M365 Admin Center Site Lists app (User)","description":"This setting lets you enable reporting of sites that Microsoft Edge users add to their local IE Mode site list. The user must be signed into Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant specified by the policy.\r\n\r\nIf you configure this policy, Microsoft Edge will send a report to the M365 Admin Center Site Lists app when a user adds a site to their local IE mode site list. The report will show the URL of the site the user added, minus any query string or fragment. The user's identity isn't reported.\r\n\r\nFor this reporting to work correctly, you must have successfully visited the Microsoft Edge Site Lists app in the M365 Admin Center at least once. This activates a per-tenant storage account used to store these reports. Microsoft Edge will still attempt to send reports if this step hasn't been completed. However, the reports will not be stored in the Site Lists app.\r\n\r\nWhen enabling this policy, you must specify your O365 tenant ID. To learn more about finding your O365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will never send reports about URLs added to a user's local site list to the Site Lists app.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707\r\n\r\nExample value: aba95e58-070f-4784-8dcd-e5fd46c2c6d6","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting_internetexplorerintegrationcloudusersitesreporting","displayName":"Configure reporting of IE Mode user list entries to the M365 Admin Center Site Lists app (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended","displayName":"Show Hubs Sidebar (User)","description":"Shows a launcher bar on the right side of Microsoft Edge's screen.\r\n\r\nEnable this policy to always show the Sidebar.\r\nDisable this policy to never show the Sidebar.\r\n\r\nIf you don't configure the policy, users can choose whether to show the Sidebar.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended~identity_recommended_signinctaonntpenabled_recommended","displayName":"Enable sign in click to action dialog (User)","description":"Configure this policy to show sign in click to action dialog on New tab page.\r\n\r\nIf you enable or don't configure this policy, sign in click to action dialog is shown on New tab page.\r\n\r\nIf you disable this policy, sign in click to action dialog isn't shown on the New tab page.","helpText":"","infoUrls":[],"categoryId":"04b46099-4ee5-4def-8e04-569c988057a9","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended~identity_recommended_signinctaonntpenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended~identity_recommended_signinctaonntpenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_relatedmatchescloudserviceenabled","displayName":"Configure Related Matches in Find on Page (User)","description":"Specifies how the user receives related matches in Find on Page, which provides spellcheck, synonyms, and Q&A results in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, users can receive related matches in Find on Page on all sites. The results are processed in a cloud service.\r\n\r\nIf you disable this policy, users can receive related matches in Find on Page on limited sites. The results are processed on the user's device.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_relatedmatchescloudserviceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_relatedmatchescloudserviceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_sandboxexternalprotocolblocked","displayName":"Allow Microsoft Edge to block navigations to external protocols in a sandboxed iframe (User)","description":"Microsoft Edge will block navigations to external protocols inside a\r\nsandboxed iframe.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will block those navigations.\r\n\r\nIf you disable this policy, Microsoft Edge will not block those navigations.\r\n\r\nThis can be used by administrators who need more time to update their internal website affected by this new restriction. This Enterprise policy is temporary; it's intended to be removed after Microsoft Edge version 104.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_sandboxexternalprotocolblocked_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_sandboxexternalprotocolblocked_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction","displayName":"Enable or disable the User-Agent Reduction (User)","description":"The User-Agent HTTP request header is scheduled to be reduced. To facilitate testing and compatibility, this policy can enable the reduction feature for all websites, or disable the ability for origin trials, or field trials to enable the feature.\r\n\r\nIf you don't configure this policy or set it to Default, User-Agent will be controlled by experimentation.\r\n\r\nSet this policy to 'ForceEnabled' to force the reduced version of the User-Agent request header.\r\n\r\nSet this policy to 'ForceDisabled' to force the full version of the User-Agent request header.\r\n\r\nTo learn more about the User-Agent string, read here:\r\n\r\nhttps://docs.microsoft.com/en-us/microsoft-edge/web-platform/user-agent-guidance.\r\n\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = User-Agent reduction will be controllable via Experimentation\r\n\r\n* ForceDisabled (1) = User-Agent reduction diabled, and not enabled by Experimentation\r\n\r\n* ForceEnabled (2) = User-Agent reduction will be enabled for all origins\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_useragentreduction","displayName":"Enable or disable the User-Agent Reduction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_useragentreduction_0","displayName":"User-Agent reduction will be controllable via Experimentation","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_useragentreduction_1","displayName":"User-Agent reduction diabled, and not enabled by Experimentation","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_useragentreduction_2","displayName":"User-Agent reduction will be enabled for all origins","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist","displayName":"Configure the list of domains for which the password manager UI (Save and Fill) will be disabled (User)","description":"Configure the list of domains where Microsoft Edge should disable the password manager. This means that Save and Fill workflows will be disabled, ensuring that passwords for those websites can't be saved or auto filled into web forms.\r\n\r\nIf you enable this policy, the password manager will be disabled for the specified set of domains.\r\n\r\nIf you disable or don't configure this policy, password manager will work as usual for all domains.\r\n\r\nIf you configure this policy, that is, add domains for which password manager is blocked, users can't change or override the behavior in Microsoft Edge. In addition, users can't use password manager for those URLs.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com/\r\nhttps://login.contoso.com","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist_passwordmanagerblocklistdesc","displayName":"Configure the list of domains for which the password manager UI (Save and Fill) will be disabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":null},{"id":"user_vendor_msft_policy_config_notifications_disallownotificationmirroring","displayName":"Disallow Notification Mirroring (User)","description":"Boolean value that turns off notification mirroring. For each user logged into the device, if you enable this policy (set value to 1) the app and system notifications received by this user on this device will not get mirrored to other devices of the same logged in user. If you disable or do not configure this policy (set value to 0) the notifications received by this user on this device will be mirrored to other devices of the same logged in user. This feature can be turned off by apps that do not want to participate in Notification Mirroring. This feature can also be turned off by the user in the Cortana setting page. No reboot or service restart is required for this policy to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Notifications#disallownotificationmirroring"],"categoryId":"cb1e177e-8f06-4a69-8215-ec1e91c19e30","categoryName":"Notifications","options":[{"id":"user_vendor_msft_policy_config_notifications_disallownotificationmirroring_0","displayName":"Block","description":"Enable notification mirroring.","helpText":null},{"id":"user_vendor_msft_policy_config_notifications_disallownotificationmirroring_1","displayName":"Allow","description":"Disable notification mirroring.","helpText":null}]},{"id":"user_vendor_msft_policy_config_notifications_disallowtilenotification","displayName":"Disallow Tile Notification (User)","description":"This policy setting turns off tile notifications. If you enable this policy setting, applications and system features will not be able to update their tiles and tile badges in the Start screen. If you disable or do not configure this policy setting, tile and badge notifications are enabled and can be turned off by the administrator or user. No reboots or service restarts are required for this policy setting to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Notifications#disallowtilenotification"],"categoryId":"cb1e177e-8f06-4a69-8215-ec1e91c19e30","categoryName":"Notifications","options":[{"id":"user_vendor_msft_policy_config_notifications_disallowtilenotification_0","displayName":"Block","description":"Disabled.","helpText":null},{"id":"user_vendor_msft_policy_config_notifications_disallowtilenotification_1","displayName":"Allow","description":"Enabled.","helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicy","displayName":"Age out documents older than n days (User)","description":"This policy controls when locally cached Office documents are aged out of the Office Document Cache","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicy_l_ageoutpolicydecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_evictserverversionspolicy","displayName":"Age out the locally cached copies of server document versions that are more than n days old. (User)","description":"\r\n This policy controls when locally cached Office version documents from the server are aged out of the local cache.\r\n\r\n If you enable this policy setting, Office document versions from the server that have been locally cached for more than n days, will be deleted from the local cache.\r\n\r\n If you disable or do not configure this policy setting, Office document versions from the server that have been locally cached, will be deleted from the local cache if older than the default of one day.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_evictserverversionspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_evictserverversionspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_evictserverversionspolicy_l_evictserverversionspolicydecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_maximplicitcachesize","displayName":"Set the max size of the Office Document Cache (User)","description":"This policy controls how large the user's Office Document Cache can be. It does not apply to explicitly cached files on \"OneDrive for Business Client\" and \"OneDrive (consumer) Client\".","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_maximplicitcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_maximplicitcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_maximplicitcachesize_l_maximplicitcachesizedecimal","displayName":"Percent of disk space (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_opendirectlyinapp","displayName":"Open Directly in Office Client Application (User)","description":"This policy allows the admin to choose whether Office documents located on web servers open up directly in the App or go via the web browser","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_opendirectlyinapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_opendirectlyinapp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps","displayName":"Apps blocked by Writing Assistance admin policy (User)","description":"This policy setting allows administrators to specify a list of applications where Writing Assistance will be blocked.\nIf you enable this policy setting, enter one application executable name per line (e.g., notepad.exe). Writing Assistance will be disabled in those applications.\nIf you disable or do not configure this policy setting, Writing Assistance will not be blocked by this policy in any application.\n ","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps_l_writingassistantadminblockedappslistid","displayName":"Blocked application names (e.g., notepad.exe) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedurls","displayName":"Web pages blocked by Writing Assistance admin policy (User)","description":"This policy setting allows administrators to specify a list of web page URL patterns where Writing Assistance will be blocked.\nIf you enable this policy setting, enter one URL pattern per line (e.g., example.com). Writing Assistance will be disabled on pages matching those patterns.\nIf you disable or do not configure this policy setting, Writing Assistance will not be blocked by this policy on any web page.\n ","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedurls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedurls_l_writingassistantadminblockedurlslistid","displayName":"Blocked URL patterns (e.g., example.com) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblocklistlocked","displayName":"Lock Writing Assistance admin blocklist (User)","description":"This policy setting controls whether users can modify the admin-managed Writing Assistance blocklist.\nIf you enable this policy setting (or do not configure it), the admin blocklist is locked and users cannot remove entries from it.\nIf you disable this policy setting, users can remove individual entries from the admin-provided blocklist.\n ","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblocklistlocked_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblocklistlocked_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice","displayName":"Writing Assistance First Run Experience Mode (User)","description":"This policy setting controls the Writing Assistance first run experience (FRE).If you enable this policy setting, choose one of the following options:Skip FRE entirely - Writing Assistance marks the first run experience as completed without showing it.Informational only - Writing Assistance shows the first run experience once without requiring user approval or sign-in. The experience is marked completed immediately, uses Next on page 1 and Okay on page 2, removes No Thanks, and is still completed if the user dismisses it.Approval required - Writing Assistance keeps the existing approval-required first run experience behavior.If you disable or don’t configure this policy setting, Writing Assistance uses the existing default first run experience behavior.Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for Enterprise.","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice_l_writingassistantfirstrunexperienceadminchoicedropid","displayName":"Configure Writing Assistance First Run Experience Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice_l_writingassistantfirstrunexperienceadminchoicedropid_0","displayName":"Skip FRE entirely","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice_l_writingassistantfirstrunexperienceadminchoicedropid_1","displayName":"Informational only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantfirstrunexperienceadminchoice_l_writingassistantfirstrunexperienceadminchoicedropid_2","displayName":"Approval required","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice","displayName":"Configure Writing Assistance installation and startup (User)","description":"This policy setting controls whether Writing Assistance is not installed, installed without launching automatically at startup and locked off, installed without launching automatically at startup but still user-controllable, installed and allowed to launch automatically at startup and locked on, or installed with startup on by default but still user-controllable.\n\nIf you enable this policy setting, choose one of the following options:\n- Not installed: Writing Assistance is removed and should not appear in Start.\n- Installed, don't launch at startup: Writing Assistance remains installed, but automatic startup launches are blocked and users cannot turn startup back on.\n- Installed, don't launch at startup by default (users can enable): Writing Assistance remains installed, automatic startup launches are off by default, and users can turn startup on later.\n- Installed, launch at startup: Writing Assistance remains installed, automatic startup launches are allowed, and users cannot turn startup off.\n- Installed, launch at startup by default (users can disable): Writing Assistance remains installed, automatic startup launches are on by default, and users can turn startup off later.\n\nIf you disable or don't configure this policy setting, Writing Assistance follows its default install and startup behavior, and users can control startup themselves.\n\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for Enterprise.\n ","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_l_writingassistantinstallandstartupadminchoiceenum","displayName":"Configure Writing Assistance Install and Startup Behavior (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_l_writingassistantinstallandstartupadminchoiceenum_0","displayName":"Not installed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_l_writingassistantinstallandstartupadminchoiceenum_1","displayName":"Installed, don't launch at startup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_l_writingassistantinstallandstartupadminchoiceenum_3","displayName":"Installed, don't launch at startup by default (users can enable)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_l_writingassistantinstallandstartupadminchoiceenum_2","displayName":"Installed, launch at startup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_l_writingassistantinstallandstartupadminchoiceenum_4","displayName":"Installed, launch at startup by default (users can disable)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v10~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_allownonadminuserinstalllaps","displayName":"Allow users who aren’t admins to install language accessory packs (User)","description":"This policy setting controls whether users can install language accessory packs for Office even if they don’t have local administrator permissions on their devices. By default, users must have local administrator permissions on their devices to install language accessory packs.\r\n\r\nIf you enable this policy setting, users will be able to install language accessory packs for Office even if they don’t have local administrator permissions on their devices. They can install those language accessory packs by going to File > Options > Language in the app, such as Word.\r\n\r\nIf you disable or don’t configure this policy setting, users who don’t have local administrator permissions on their devices won’t be able to install language accessory packs. Someone with local administrator permissions on the device will need to install the language accessory packs for the user.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2161939.\r\n ","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v10~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_allownonadminuserinstalllaps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v10~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_allownonadminuserinstalllaps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_miscellaneous437_l_officerecommendeddocuments","displayName":"Show recommended files on the File tab or start page (User)","description":"This policy setting allows you to control whether users see a list of recommended files on the File tab or start page in Word, Excel, and PowerPoint, on devices running Windows.\r\n\r\nIf you enable this policy setting, users will see a list of recommended files on the File tab or start page.\r\n\r\nIf you disable this policy setting, users won't see a list of recommended files on the File tab or start page.\r\n\r\nIf you don't configure this policy setting, users will see a list of recommended files on the File tab or start page.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2146780.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_miscellaneous437_l_officerecommendeddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_miscellaneous437_l_officerecommendeddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_services_l_officeenableautoalttext","displayName":"Automatically generate alternative text (alt text) for pictures (User)","description":"This policy setting controls whether alternative text (alt text) is generated automatically for pictures in Word, PowerPoint, and Outlook.\r\n\r\nThis policy setting is related to the \"Automatically generate alt text for me\" check box under File > Options > Ease of Access > Automatic Alt Text.\r\n\r\nIf you enable this policy setting, alt text will be generated automatically for pictures. The \"Automatically generate alt text for me\" check box will be selected and users won't be able to clear the check box.\r\n\r\nIf you disable this policy setting, alt text won't be generated automatically for pictures. The \"Automatically generate alt text for me\" check box won't be selected and users won't be able to select the check box.\r\n\r\nIf you don't configure this policy setting, alt text will be generated automatically for pictures. But, users will be able to clear the \"Automatically generate alt text for me\" check box.\r\n ","helpText":"","infoUrls":[],"categoryId":"478ed057-8ee7-4dd2-8276-06dad8f85397","categoryName":"Services","options":[{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_services_l_officeenableautoalttext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_services_l_officeenableautoalttext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicylocalversioning","displayName":"Number of days to keep local document versions in the local cache (User)","description":"This policy controls how long local document versions are kept in the local cache. The default setting is 30 days and applies to Word, Excel, and PowerPoint. \r\n\r\nIf you enable this policy setting, local document versions will be kept for the number of days specified, after which they’ll be deleted from the local cache. You can configure the setting with a value from 1 to 30.\r\n\r\nIf you disable or don’t configure this policy setting, local document versions will be kept for 30 days, after which they’ll be deleted from the local cache.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicylocalversioning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicylocalversioning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicylocalversioning_l_ageoutpolicylocalversioningdecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains","displayName":"Turn off roaming of file names and metadata by server domain. (User)","description":"\r\nThis policy setting controls whether file names and metadata for Office files are roamed and appear in the list of recently opened files in an Office app, such as Word, on different devices.\r\n\r\nRoaming, which relies on a web-based Microsoft service, occurs when a user signs into Office with the same work or school account on different devices.\r\n\r\nNote: This policy is applied to any Office files stored on a specified list of server domains. The set of disallowed domains is a semicolon separated list: \"*.contoso.com;service.microsoft.com\".\r\n\r\nIf you enable this policy setting, file names and metadata won't roam and won’t appear in the list of recently opened files in Office apps on other devices, unless the file has been opened on that device.\r\n\r\nIf you disable or don't configure this policy setting, file names and metadata will roam and will appear in the list of recently opened files in Office apps on other devices, even if the file hasn’t been opened on that device.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains_l_disalloweddomainlist","displayName":"Disallowed Domains: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthpromptbehavior","displayName":"Allow specified hosts to show Basic Authentication prompts to Office apps (User)","description":"This policy setting allows you to specify which hosts can show Basic Authentication sign-in prompts to Office apps.\r\n\r\nBy default, all Basic Authentication sign-in prompts are blocked, and the user is shown a message that the sign-in method isn’t allowed.\r\n\r\nIf you enable this policy setting, you need to enter the hosts by name, separating the host names with a semi-colon. For example: server1.contoso.com; server2.fabrikam.com.\r\n\r\nWarning: Allowing Basic Authentication sign-in prompts isn’t recommended because it’s a security risk.\r\n\r\nBasic Authentication sign-in prompts from all other hosts will be blocked and the user will be shown a message that the sign-in method isn’t allowed.\r\n\r\nIf you disable or don’t configure this policy setting, all Basic Authentication sign-in prompts will be blocked, and the user will be shown a message that the sign-in method isn’t allowed.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2199001.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthpromptbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthpromptbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthpromptbehavior_l_authenticationbasicauthenabledhostsid","displayName":"Host names: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthproxybehavior","displayName":"Allow Basic Authentication prompts from network proxies (User)","description":"This policy setting controls whether network proxies are allowed to show Basic Authentication prompts.\r\n\r\nBy default, all Basic Authentication sign-in prompts are blocked, and the user is shown a message that the sign-in method isn’t allowed.\r\n\r\nIf you enable this policy setting, then network proxies will be allowed to show Basic Authentication prompts.\r\n\r\nWarning: Allowing Basic Authentication sign-in prompts isn’t recommended because it’s a security risk.\r\n\r\nIf you disable or don’t configure this policy setting, all Basic Authentication sign-in prompts from network proxes will be blocked, and the user will be shown a message that the sign-in method isn’t allowed.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2199001.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthproxybehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthproxybehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_pdfandxps_l_pdfprotectionfromoffice","displayName":"Use the Sensitivity feature in Office to apply sensitivity labels to PDFs (User)","description":"This policy setting controls whether sensitivity labels powered by Microsoft Purview Information Protection are applied to PDFs created in Word, Excel, and PowerPoint.​\r\n\r\nIf you enable this policy setting or don’t configure it, PDFs will inherit the sensitivity label and encryption from the source Word, Excel, and PowerPoint document.\r\n\r\nIf you disable this policy setting, PDFs created in Word, Excel, and PowerPoint do not inherit their source file’s sensitivity labels and encryption. When the source file is encrypted, users who do not have the rights to remove protection cannot export to PDF.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise. For more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2220953.","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_pdfandxps_l_pdfprotectionfromoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_pdfandxps_l_pdfprotectionfromoffice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_securitysettings_l_aipexception","displayName":"Use the Azure Information Protection add-in for sensitivity labeling (User)","description":"This policy setting controls whether the Microsoft Azure Information Protection add-in can be used rather than the default of built-in labeling to view and apply sensitivity labels in Office apps. It applies only to subscription versions of Office, such as Microsoft 365 Apps for enterprise.​\r\n\r\nIf you enable this policy setting and the Microsoft Azure Information Protection unified labeling client is installed, the add-in from that client replaces the default labeling built into Office apps.\r\n\r\nIf you disable this policy setting or don’t configure it, the default labeling experience that’s built-in for Office apps is used to view and apply sensitivity labels.​\r\n\r\nFor more information about this setting, see https://go.microsoft.com/fwlink/p/?linkid=2207430.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_securitysettings_l_aipexception_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_securitysettings_l_aipexception_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice","displayName":"Choose which browser opens web links (User)","description":"This policy controls which browser will open web links from within supported Microsoft 365 apps. By default, web links will open in Microsoft Edge.\r\n\r\nNote: This policy doesn’t override any user settings or policies that specify that document links should open in the desktop apps instead of their web app counterparts.\r\n\r\nIf you enable this policy, you can choose either “System default browser” or a specific browser, such as “Microsoft Edge.” “System default browser” refers to the browser setting specified on the user’s Windows device.\r\n\r\nIf you disable or don’t configure this policy, web links will open in Microsoft Edge. The user can set their preferred browser from the settings for the specific Microsoft 365 app.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2224834.","helpText":"","infoUrls":[],"categoryId":"94ce8206-be22-496c-aa72-f3560e2a5c8d","categoryName":"Links","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_l_browserchoiceenum","displayName":"Browser: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"94ce8206-be22-496c-aa72-f3560e2a5c8d","categoryName":"Links","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_l_browserchoiceenum_0","displayName":"System default browser","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_l_browserchoiceenum_1","displayName":"Microsoft Edge","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm","displayName":"Encryption mode for Information Rights Management (IRM) (User)","description":"If you enable this policy setting, you can choose from two options for controlling the encryption mode that Excel, PowerPoint, Word, Visio, and Outlook applications use to protect content with Information Rights Management (IRM):\r\n\r\n- Electronic Codebook (ECB) – ECB mode is always used when applying IRM encryption.\r\n- Cipher Block Chaining (CBC) – CBC mode is always used when applying IRM encryption.\r\n\r\nIf you disable or don't configure this policy setting:\r\n\r\n- For Microsoft 365 Apps (Version 2304 or later): Cipher Block Chaining (CBC) mode is used.\r\n- For earlier Microsoft 365 Apps and Office LTSC 2021, 2019, and 2016: Electronic Codebook (ECB) mode is used.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_l_encryptiontypeforirmcolon","displayName":"IRM Encryption Mode: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_l_encryptiontypeforirmcolon_1","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_l_encryptiontypeforirmcolon_2","displayName":"Electronic Codebook (ECB)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v15~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableresourceidnamemapping","displayName":"Disable caching when opening server-only files. (User)","description":"This policy setting controls disabling caching when opening server-only files.\r\n\r\nCaching files helps Office speed up server-only file opens but could cause conflicts for organizations that rename files or change file contents directly on SharePoint.\r\n\r\nThe cache is meant to improve performance so disabling it is expected to hurt performance.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v15~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableresourceidnamemapping_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v15~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableresourceidnamemapping_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatieuser","displayName":"Disable local training of the Adaptive Floatie feature for the user. (User)","description":"\r\nThis policy setting disables local training of the Adaptive Floatie feature for the user.\r\n\r\nFor local training policy, feature-specific settings are prioritized over general settings and computer settings are prioritized over user settings.\r\n\r\nIf a higher priority policy setting is not configured, then:\r\n- If this policy setting is enabled, local training of the Adaptive Floatie feature is disabled for the user.\r\n- If this policy setting is disabled, local training of the Adaptive Floatie feature is enabled for the user.\r\n- If this policy setting is not configured, local training of the Adaptive Floatie feature is determined by lower priority policy settings.\r\n- If this policy setting is not configured and lower priority policy settings are also not configured, local training of the Adaptive Floatie feature is enabled for the user.\r\n\r\nFor this policy setting, the order of priority is:\r\n1. Disable local training of the Adaptive Floatie feature for the computer.\r\n2. Disable local training of all features for the computer.\r\n3. Disable local training of the Adaptive Floatie feature for the user.\r\n4. Disable local training of all features for the user.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatieuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatieuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletraininguser","displayName":"Disable local training of all features for the user. (User)","description":"\r\nThis policy setting disables local training of all features for the user.\r\n\r\nFor local training policy, feature-specific settings are prioritized over general settings and computer settings are prioritized over user settings.\r\n\r\nIf a higher priority policy setting is not configured, then:\r\n- If this policy setting is enabled, local training of all features is disabled for the user.\r\n- If this policy setting is disabled, local training of all features is enabled for the user.\r\n- If this policy setting is not configured, local training of all features is enabled for the user.\r\n\r\nFor this policy setting, the order of priority is:\r\n1. Disable local training of [a specific feature] for the computer.\r\n2. Disable local training of all features for the computer.\r\n3. Disable local training of [a specific feature] for the user.\r\n4. Disable local training of all features for the user.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletraininguser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletraininguser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowuserdefinedfilesharecatalogs","displayName":"Allow users to control the Trusted Shared Folder Catalogs (User)","description":"\r\nThis policy setting allows users to control all the Trusted Shared Folder Catalogs when other policy settings in the Trusted Catalogs folder are set by policy. \r\n\r\nNote: This setting only applies to Version 2308 or later of Office.\r\n\r\nIf you enable this policy setting, users can set their own Trusted Shared Folder Catalogs including the Default Shared Folder location. Shared Folder Catalogs defined by policy will not be used.\r\n\r\nIf you disable this policy setting, then all Trusted Shared Folders Catalogs are policy controlled.\r\n\r\nIf you do not configure this policy setting but do configure other policy settings in the Trusted Catalogs folder, the Trusted Shared Folder Catalogs are policy controlled. If you do not configure this policy setting or any other policy setting in the Trusted Catalogs folder, users can set their own Trusted Shared Folder locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowuserdefinedfilesharecatalogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowuserdefinedfilesharecatalogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics","displayName":"Configure Get Diagnostics feature's visibility in the Help Ribbon in Office applications and control the feature's mode of operation. (User)","description":"This policy setting allows you to enable or disable Get Diagnostics in Office applications and specifies the mode in which the feature operates.\r\n\r\nIf you enable this policy setting, you must choose one of the following options:\r\nDisabled\r\nEnable upload of diagnostics logs to Microsoft\r\nEnable the collection of diagnostic logs in an archive\r\n\r\nIf you select \"Disabled\", Office applications will not display a visible Get Diagnostics button in the Help Ribbon.\r\n\r\nIf you select \"Enable upload of diagnostics logs to Microsoft\", Office applications will have a visible Get Diagnostics button in the Help Ribbon. Clicking this button will upload the application’s diagnostic logs to Microsoft for support purposes.\r\n\r\nIf you select \"Enable the collection of diagnostic logs in an archive\", Office applications will have a visible Get Diagnostics button in the Help Ribbon. Clicking this button will capture the application’s diagnostic logs in a file archive on the device where the application is currently running. These logs will not be uploaded to Microsoft.\r\n\r\nPlease note that the option “Enable the collection of diagnostic logs in an archive” may not be applicable in certain Office applications. When the application does not support local log collection, setting the policy to this option will completely disable the feature, removing the \"Get Diagnostics\" button.\r\n\r\nIf you don’t set this policy, the feature will operate in the default mode, which is “Enable upload of diagnostics logs to Microsoft.”\r\n ","helpText":"","infoUrls":[],"categoryId":"e86f24d3-8531-4298-b064-692ea795b1d9","categoryName":"Diagnostics","options":[{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum","displayName":"Configure Get Diagnostics: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e86f24d3-8531-4298-b064-692ea795b1d9","categoryName":"Diagnostics","options":[{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum_1","displayName":"Upload diagnostic logs to Microsoft","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum_2","displayName":"Capture diagnostic logs in a local archive, dont upload logs to Microsoft","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v18~policy~l_microsoftofficesystem~l_miscellaneous437_l_linksopenrightdefaultsettingisnative","displayName":"File links open preference default selection as Desktop App (User)","description":"This policy setting controls which file links open preference is set as the default for users’ who has not make their selection. For more information about file links handling and open preference in Office, see https://go.microsoft.com/fwlink/?linkid=2277074. User can manually change the default selection anytime.\r\n\r\nIf you enabled this policy setting, file open preference in Word, Excel, PowerPoint, and Outlook will be defaulted to open in Desktop App.\r\n\r\nIf you disable this policy setting, file open preference in Word, Excel, PowerPoint, and Outlook will be defaulted to open in web browser.\r\n\r\nNote: This policy setting only applies to subscription version of Office.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v18~policy~l_microsoftofficesystem~l_miscellaneous437_l_linksopenrightdefaultsettingisnative_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v18~policy~l_microsoftofficesystem~l_miscellaneous437_l_linksopenrightdefaultsettingisnative_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v19~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_acceptalleulas","displayName":"Accept all EULAs (User)","description":"By default, users are required to accept a EULA upon activating an Office license. By setting this policy, all EULAs will be automatically accepted machine-wide and no prompts will be shown.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v19~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_acceptalleulas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v19~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_acceptalleulas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter","displayName":"Hide Microsoft cloud-based file locations in the Backstage view (User)","description":"This policy setting allows you to hide Microsoft cloud-based file locations in the Backstage view in Office. This helps prevent users from opening, saving, or sharing cloud-based files to locations such as: OneDrive, SharePoint, or Third Party Services.\r\n\r\nThis policy setting only applies to Word, PowerPoint, and Excel.\r\n\r\nTo filter specific services, add the values for all services to be disabled:\r\n 1 - OneDrive Personal\r\n 4 - ThisPC\r\n 8 - SharePoint OnPrem\r\n 16 - Recent Places\r\n 32 - SharePoint\r\n 64 - OneDrive for Business\r\n 128 - Third Party Services\r\n\r\nSpecial Values:\r\n 0 - (Default) All services enabled.\r\n 2 - (Legacy Value) Disable SharePoint and OneDrive for Business.\r\n\t4294967295 - All optional services disabled.\r\n\r\nFor example, OneDrive Personal (1), This PC (4) and Third Party Services (128) can all be disabled with a value of 133.\r\n\r\nThis value is calculated as follows: 1 + 4 + 128 = 133\r\n\r\nCommon Setting Values:\r\n 1 - Disable OneDrive Personal\r\n 2 - Disable SharePoint Online and OneDrive for Business\r\n 3 - Disable SharePoint Online, OneDrive for Business, and OneDrive Personal\r\n\r\nIf you disable or don’t configure this policy setting, users can use any configured Microsoft cloud-based file location to open, save, and share files.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid","displayName":"Online Storage Filter Value: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences","displayName":"Allow the use of connected experiences in Office (User)","description":"This policy setting allows you to control whether connected experiences are available to your users when they're using Office.\r\n\r\nConnected experiences include experiences that analyze content, such as Editor in Word, experiences that download online content, such as PowerPoint QuickStarter, and other connected experiences, such as document co-authoring and online file storage. It also includes additional optional connected experiences, such as inserting an online video into a PowerPoint presentation or the 3D Maps feature in Excel, which uses Bing. See the Note at the end for more information about other policy settings that you can use to control these connected experiences.\r\n\r\nIf you enable this policy setting, these connected experiences will be available to your users.\r\n\r\nIf you disable this policy setting, these connected experiences won't be available to your users.\r\n\r\nNote: If you disable this policy setting, nearly all connected experiences will be turned off. However, limited Office functionality will remain available, such as synching a mailbox in Outlook. Essential services, such as the licensing service that confirms that you’re properly licensed to use Office, will also remain available.\r\n\r\nIf you don't configure this policy setting, these connected experiences will be available to your users.\r\n\r\nNote: You can use these other policy settings if you want to disable just a certain group of connected experiences: \"Allow the use of connected experiences in Office that analyze content\", \"Allow the use of connected experiences in Office that download online content\", and \"Allow the use of additional optional connected experiences in Office\".\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2085689","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent","displayName":"Allow the use of connected experiences in Office that analyze content (User)","description":"This policy setting allows you to control whether connected experiences that analyze content are available to your users when they're using Office.\r\n\r\nPowerPoint Designer and Editor in Word are examples of connected experiences that analyze content.\r\n\r\nIf you enable this policy setting, connected experiences that analyze content will be available to your users.\r\n\r\nIf you disable this policy setting, connected experiences that analyze content won't be available to your users.\r\n\r\nIf you don't configure this policy setting, connected experiences that analyze content will be available to your users.\r\n\r\nNote: If you disable the \"Allow the use of connected experiences in Office\" policy setting, connected experiences that analyze content won't be available to your users.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2085794\r\n\r\nNote: For information about how this policy setting affects Microsoft 365 Copilot, see https://go.microsoft.com/fwlink/p/?linkid=2248397.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent","displayName":"Allow the use of connected experiences in Office that download online content (User)","description":"This policy setting allows you to control whether connected experiences that download online content are available to your users when they’re using Office.\r\n\r\nOffice templates and PowerPoint QuickStarter are examples of connected experiences that download online content.\r\n\r\nIf you enable this policy setting, connected experiences that download online content will be available to your users.\r\n\r\nIf you disable this policy setting, connected experiences that download online content won’t be available to your users.\r\n\r\nIf you don’t configure this policy setting, connected experiences that download online content will be available to your users.\r\n\r\nNote: If you disable the “Allow the use of connected experiences in Office” policy setting, connected experiences that download online content won’t be available to your users.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2085688","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences","displayName":"Allow the use of additional optional connected experiences in Office (User)","description":"This policy setting allows you to control whether additional optional connected experiences are available to your users when they’re using Office.\r\n\r\nAdditional optional connected experiences are offered by Microsoft directly to your users and are governed by terms other than your organization’s commercial agreement with Microsoft.\r\n\r\nInserting an online video into a PowerPoint presentation or the 3D Maps feature in Excel, which uses Bing, are examples of additional optional connected experiences.\r\n\r\nNote: Even if you choose to make these additional optional connected experiences available to your users, your users will have the option to turn these additional optional connected experiences off as a group by going to File > Account > Account Privacy > Manage Settings.\r\n\r\nIf you enable this policy setting, additional optional connected experiences will be available to your users.\r\n\r\nIf you disable this policy setting, additional optional connected experiences won’t be available to your users.\r\n\r\nNote: Some additional optional connected experiences may be controlled by other policy settings instead of this policy setting. For more information, see the link below.\r\n\r\nIf you don’t configure this policy setting, additional optional connected experiences will be available to your users.\r\n\r\nNote: If you disable the “Allow the use of connected experiences in Office” policy setting, additional optional connected experiences won’t be available to your users.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2085690\r\n\r\nNote: For information about how this policy setting affects Microsoft 365 Copilot, see https://go.microsoft.com/fwlink/p/?linkid=2248196.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2.updates.3~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel","displayName":"Turn off AutoSave by default in Excel (User)","description":"This policy setting allows you to turn off AutoSave by default in Excel. AutoSave automatically saves all changes a user makes to files that are stored in OneDrive, OneDrive for Business, or SharePoint Online.\r\n\r\nIf you enable this policy setting, AutoSave is off by default in Excel. But, the user can enable AutoSave for Excel by going to File > Options > Save. Or, the user can enable AutoSave for a specific Excel file by using the AutoSave toggle in the title bar.\r\n\r\nIf you disable or don’t configure this policy setting, AutoSave is on by default, but the user can disable AutoSave by going to File > Options > Save or by using the AutoSave toggle.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum_0","displayName":"Use AutoSave Default Setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum_1","displayName":"AutoSave Is On By Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum_2","displayName":"AutoSave Is Off By Default","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint","displayName":"Turn off AutoSave by default in PowerPoint (User)","description":"This policy setting allows you to turn off AutoSave by default in PowerPoint. AutoSave automatically saves all changes a user makes to files that are stored in OneDrive, OneDrive for Business, or SharePoint Online.\r\n\r\nIf you enable this policy setting, AutoSave is off by default in PowerPoint. But, the user can enable AutoSave for PowerPoint by going to File > Options > Save. Or, the user can enable AutoSave for a specific PowerPoint file by using the AutoSave toggle in the title bar.\r\n \r\nIf you disable or don’t configure this policy setting, AutoSave is on by default, but the user can disable AutoSave by going to File > Options > Save or by using the AutoSave toggle.\r\n \r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum_0","displayName":"Use AutoSave Default Setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum_1","displayName":"AutoSave Is On By Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum_2","displayName":"AutoSave Is Off By Default","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword","displayName":"Turn off AutoSave by default in Word (User)","description":"This policy setting allows you to turn off AutoSave by default in PowerPoint. AutoSave automatically saves all changes a user makes to files that are stored in OneDrive, OneDrive for Business, or SharePoint Online.\r\n\r\nIf you enable this policy setting, AutoSave is off by default in PowerPoint. But, the user can enable AutoSave for PowerPoint by going to File > Options > Save. Or, the user can enable AutoSave for a specific PowerPoint file by using the AutoSave toggle in the title bar.\r\n \r\nIf you disable or don’t configure this policy setting, AutoSave is on by default, but the user can disable AutoSave by going to File > Options > Save or by using the AutoSave toggle.\r\n \r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum_0","displayName":"Use AutoSave Default Setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum_1","displayName":"AutoSave Is On By Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum_2","displayName":"AutoSave Is Off By Default","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationexcel","displayName":"[Deprecated] Don’t AutoSave files in Excel (User)","description":"Important: This policy setting will be removed in a future release and will no longer be supported. Please use the \"Turn off AutoSave by default in Excel\" policy setting instead.\r\n \r\nThis policy setting controls whether files can be AutoSaved in the desktop version of Excel after Excel has been updated with new features. By default, Auto Saving files is Enabled.\r\n\r\nIf you enable this policy setting files will not be able to be AutoSaved.\r\n\r\nIf you disable or don’t configure this policy setting files will be able to be AutoSaved.\r\n\r\nNote: There are separate policy settings for Word, Excel, and PowerPoint.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationpowerpoint","displayName":"[Deprecated] Don’t AutoSave files in PowerPoint (User)","description":"Important: This policy setting will be removed in a future release and will no longer be supported. Please use the \"Turn off AutoSave by default in PowerPoint\" policy setting instead.\r\n \r\nThis policy setting controls whether files can be AutoSaved in the desktop version of PowerPoint after PowerPoint has been updated with new features. By default, Auto Saving files is Enabled.\r\n\r\nIf you enable this policy setting files will not be able to be AutoSaved.\r\n\r\nIf you disable or don’t configure this policy setting files will be able to be AutoSaved.\r\n\r\nNote: There are separate policy settings for Word, Excel, and PowerPoint.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationword","displayName":"[Deprecated] Don’t AutoSave files in Word (User)","description":"Important: This policy setting will be removed in a future release and will no longer be supported. Please use the \"Turn off AutoSave by default in Word\" policy setting instead.\r\n \r\nThis policy setting controls whether files can be AutoSaved in the desktop version of Word after Word has been updated with new features. By default, Auto Saving files is Enabled.\r\n\r\nIf you enable this policy setting files will not be able to be AutoSaved.\r\n\r\nIf you disable or don’t configure this policy setting files will be able to be AutoSaved.\r\n\r\nNote: There are separate policy settings for Word, Excel, and PowerPoint.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_disabledefaultservice","displayName":"Remove Office Presentation Service from the list of online presentation services in PowerPoint and Word (User)","description":"This policy setting allows you to remove Office Presentation Service from the list of online presentation services in PowerPoint and Word. This list appears when a user selects Present Online from the Share tab in Backstage view and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, Office Presentation Service is not shown as an option for presenting online. \r\n\r\nIf you disable or do not configure this policy setting, users can select Office Presentation Service to present their PowerPoint or Word file to other users online.","helpText":"","infoUrls":[],"categoryId":"5bf4c2ba-be08-4cda-bf33-d10707580d78","categoryName":"Present Online","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_disabledefaultservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_disabledefaultservice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_disableprogrammaticaccess","displayName":"Restrict programmatic access for creating online presentations in PowerPoint and Word (User)","description":"This policy setting allows you to restrict the ability to create an online presentation programmatically in PowerPoint and Word.\r\n\r\nIf you enable this policy setting, an online presentation cannot be created programmatically.\r\n\r\nIf you disable or do not configure this policy setting, an online presentation can be created programmatically.","helpText":"","infoUrls":[],"categoryId":"5bf4c2ba-be08-4cda-bf33-d10707580d78","categoryName":"Present Online","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_disableprogrammaticaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_disableprogrammaticaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_preventaccesstouserspecifiedservices","displayName":"Prevent users from adding online presentation services in PowerPoint and Word (User)","description":"This policy setting allows you to prevent users from adding new or previously created presentation services to the list of online presentation services in PowerPoint and Word. These services appear when a user selects the More services link under Present Online on the Share tab in Backstage view.\r\n\r\nIf you enable or do not configure this policy setting, the More services link does not allow users to add a new presentation service. In addition, all services previously added by users are removed from the list.\r\n\r\nIf you disable this policy setting, the More Services link provides an option for users to add a new presentation service. In addition, the list of services previously added by users appears in the list of services.","helpText":"","infoUrls":[],"categoryId":"5bf4c2ba-be08-4cda-bf33-d10707580d78","categoryName":"Present Online","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_preventaccesstouserspecifiedservices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast_l_preventaccesstouserspecifiedservices_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00","displayName":"Configure presentation service in PowerPoint and Word 1 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicecreatesharednotes0","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicecreatesharednotes0_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicecreatesharednotes0_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicemajorversion0","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceminorversion0","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicenotesdefaulturl0","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceservercapabilities0","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceserverdescription0","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceserverinfo0","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceservername0","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceserverterms0","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastserviceserverurl0","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicesharednotescustomurl0","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01","displayName":"Configure presentation service in PowerPoint and Word 2 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicecreatesharednotes1","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicecreatesharednotes1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicecreatesharednotes1_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicemajorversion1","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceminorversion1","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicenotesdefaulturl1","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceservercapabilities1","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceserverdescription1","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceserverinfo1","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceservername1","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceserverterms1","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceserverurl1","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicesharednotescustomurl1","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02","displayName":"Configure presentation service in PowerPoint and Word 3 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicecreatesharednotes2","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicecreatesharednotes2_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicecreatesharednotes2_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicemajorversion2","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceminorversion2","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicenotesdefaulturl2","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceservercapabilities2","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceserverdescription2","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceserverinfo2","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceservername2","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceserverterms2","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceserverurl2","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicesharednotescustomurl2","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03","displayName":"Configure presentation service in PowerPoint and Word 4 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastservicecreatesharednotes3","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastservicecreatesharednotes3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastservicecreatesharednotes3_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastservicemajorversion3","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceminorversion3","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastservicenotesdefaulturl3","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceservercapabilities3","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverdescription3","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverinfo3","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceservername3","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverterms3","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverurl3","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastservicesharednotescustomurl3","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04","displayName":"Configure presentation service in PowerPoint and Word 5 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicecreatesharednotes4","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicecreatesharednotes4_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicecreatesharednotes4_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicemajorversion4","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceminorversion4","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicenotesdefaulturl4","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceservercapabilities4","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverdescription4","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverinfo4","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceservername4","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverterms4","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverurl4","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicesharednotescustomurl4","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05","displayName":"Configure presentation service in PowerPoint and Word 6 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicecreatesharednotes5","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicecreatesharednotes5_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicecreatesharednotes5_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicemajorversion5","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceminorversion5","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicenotesdefaulturl5","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceservercapabilities5","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceserverdescription5","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceserverinfo5","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceservername5","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceserverterms5","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceserverurl5","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicesharednotescustomurl5","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06","displayName":"Configure presentation service in PowerPoint and Word 7 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastservicecreatesharednotes6","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastservicecreatesharednotes6_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastservicecreatesharednotes6_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastservicemajorversion6","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceminorversion6","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastservicenotesdefaulturl6","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceservercapabilities6","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceserverdescription6","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceserverinfo6","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceservername6","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceserverterms6","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceserverurl6","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastservicesharednotescustomurl6","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07","displayName":"Configure presentation service in PowerPoint and Word 8 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicecreatesharednotes7","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicecreatesharednotes7_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicecreatesharednotes7_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicemajorversion7","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceminorversion7","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicenotesdefaulturl7","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceservercapabilities7","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceserverdescription7","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceserverinfo7","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceservername7","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceserverterms7","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastserviceserverurl7","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicesharednotescustomurl7","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08","displayName":"Configure presentation service in PowerPoint and Word 9 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicecreatesharednotes8","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicecreatesharednotes8_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicecreatesharednotes8_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicemajorversion8","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceminorversion8","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicenotesdefaulturl8","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceservercapabilities8","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceserverdescription8","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceserverinfo8","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceservername8","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceserverterms8","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceserverurl8","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicesharednotescustomurl8","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09","displayName":"Configure presentation service in PowerPoint and Word 10 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicecreatesharednotes9","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicecreatesharednotes9_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicecreatesharednotes9_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicemajorversion9","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceminorversion9","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicenotesdefaulturl9","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceservercapabilities9","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceserverdescription9","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceserverinfo9","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceservername9","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceserverterms9","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceserverurl9","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicesharednotescustomurl9","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaultinstanceslimit","displayName":"Set the database default instances limit (User)","description":"This policy setting allows you to specify the default limit of how many instances per page the database shim can return. The application is allowed to specify a larger timeout programmatically. This is a default value to be used by the database shim to restrict the number of results that can be returned per page. The application can specify a larger limit via execution context.\r\n\r\nIf you enable this policy setting, you may specify the default limit of how many instances the database shim can return.\r\n\r\nIf you disable or do not configure this policy setting, a default value of 200 instances per page will be used.","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaultinstanceslimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaultinstanceslimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaultinstanceslimit_l_databasedefaultinstanceslimitdecimal","displayName":"Default number of instances returned (User)","description":"","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaulttimeout","displayName":"Set the database default timeout (User)","description":"This policy setting allows you to specify the default timeout in milliseconds used by the database shim. The application can specify a larger limit via the execution context.\r\n \r\nIf you enable this policy setting, you may specify the default timeout in milliseconds used by the database shim.\r\n\r\nIf you disable or do not configure this policy setting, a default of 7000 milliseconds will be used.","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaulttimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaulttimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasedefaulttimeout_l_databasedefaulttimeoutdecimal","displayName":"Database default timeout (milliseconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit","displayName":"Set maximum database instances limit (User)","description":"This policy setting allows you to specify the maximum limit of how many instances per page the database shim can return. This policy setting enforces the allowed maximum for applications including those that do not respect the default.\r\n \r\nIf you enable this policy setting, you may specify the maximum limit of how many instances the database shim can return.\r\n\r\nIf you disable or do not configure this policy setting, there will be no limit of how many instances the database shim can return.","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit_l_databasemaxinstanceslimitdecimal","displayName":"Maximum number of instances returned (User)","description":"","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout","displayName":"Set maximum database timeout limit (User)","description":"This policy setting allows you to specify the maximum timeout in milliseconds used by the database shim. This maximum value is enforced for applications including those that do not respect the default.\r\n\r\nIf you enable this policy setting, you may specify the maximum timeout in milliseconds used by the database shim.\r\n\r\nIf you disable or do not configure this policy setting, no maximum timeout value will be enforced.","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout_l_databasemaxtimeoutdecimal","displayName":"Database maximum timeout (milliseconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_cleanupinterval","displayName":"Set the cleanup interval (User)","description":"This policy setting allows you to specify the interval (in minutes) for how long successfully completed operations and other data that is no longer needed will remain in the cache before they can be deleted. The synchronization process leads to data in the cache that will no longer be needed. However, the data may be useful for troubleshooting purposes. To prevent the cache from growing too large, the cache contents should periodically be deleted.\r\n\r\nIf you enable this policy setting, you may specify the interval (in minutes) for the times the contents in the cache are deleted.\r\n\r\nIf you disable or do not configure this policy setting, a default value of 1440 minutes (1 day) will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_cleanupinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_cleanupinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_cleanupinterval_l_cleanupintervaldecimal","displayName":"Cleanup interval (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval","displayName":"Set errors cleanup interval (User)","description":"This policy setting allows you to specify the interval for how long failed operations and other error data will remain in the cache before they can be deleted. Synchronization can fail for any reason. The failed operations and related instances are marked as \"in error,\" and this data will eventually need to be removed from the cache. It is recommended that this interval be larger than the regular cleanup interval to give the user opportunities to troubleshoot errors.\r\n\r\nIf you enable this policy setting, you may specify the interval (in minutes) for the times the failed operations and error data in the cache are deleted. \r\n\r\nIf you disable or do not configure this policy setting, a default value of 10080 minutes (1 week) will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval_l_errorscleanupintervaldecimal","displayName":"Errors cleanup interval (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries","displayName":"Set maximum number of retries when synchronization fails (User)","description":"This policy setting allows you to specify the maximum number of times a failed synchronization operation can be retried.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of times a failed synchronization operation can be retried.\r\n\r\nIf you disable or do not configure this policy setting, then a default value of 50 times will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries_l_maxretriesdecimal","displayName":"Maximum number of retries (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_queryinstanceslimit","displayName":"Set query items limit (User)","description":"This policy setting allows you to specify the maximum number of items that will be added to the client’s cache as the result of executing a query. Several bulk operations (especially queries) can return a large number of items to be added to the cache. This increases the size of the cache, potentially exceeding the 4GB limit imposed by Microsoft SQL Server CE. It also increases the amount of work required to keep the cache synchronized and increases the load on the LOB server. In order to protect the system, a limit is used – any results processed before reaching the limit are still committed, but the operation is marked as failed and will be retried later.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of items that will be added to the client’s cache as the result of executing a query.\r\n\r\nIf you disable or do not configure this policy setting, a default value of 2000 items will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_queryinstanceslimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_queryinstanceslimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_queryinstanceslimit_l_queryinstanceslimitdecimal","displayName":"Query instances limit (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_querytimeout","displayName":"Set query processing timeout limit (User)","description":"This policy setting allows you to specify the maximum number of minutes the system will spend processing an individual query. When the interval is exceeded, the processing is aborted and the query is marked as failed. The query will then be retried later. Several bulk operations (especially queries) can take a significant amount of time before all results are retrieved and processed. During this time no other operation can be processed.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of minutes the system will spend processing an individual query.\r\n\r\nIf you disable or do not configure this policy setting, a default value of 20 minutes will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_querytimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_querytimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_querytimeout_l_querytimeoutdecimal","displayName":"Time before query timeout (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_refreshfrequencylimit","displayName":"Set refresh frequency limit (User)","description":"This policy setting allows you to enforce a lower limit in minutes for the refresh interval. Refreshing subscriptions too frequently can overload the LOB systems or the network with too many requests.\r\n\r\nIf you enable this policy setting, you may specify the number of minutes for the refresh interval. This limit prevents cache subscriptions from being refreshed more frequently, reducing the number of requests issued against the line-of-business (LOB) system.\r\n\r\nIf you disable or do not configure this policy setting, a default limit of 10 minutes will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_refreshfrequencylimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_refreshfrequencylimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_refreshfrequencylimit_l_refreshfrequencylimitdecimal","displayName":"Refresh frequency limit (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_retryintervallimit","displayName":"Set subscription refresh retry interval (User)","description":"This policy setting allows you to specify the maximum number of minutes the system must wait before retrying the operation execution of a failed operation.\r\n\r\nIf you enable this policy setting, you may specify the maximum interval in minutes before a retrying the operation execution of a failed operation.\r\n\r\nIf you disable or do not configure this policy setting, then a default value of 360 minutes will be used.\r\n","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_retryintervallimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_retryintervallimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_retryintervallimit_l_retryintervallimitdecimal","displayName":"Maximum retry interval (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_sleepinterval","displayName":"Set maximum sleep interval (User)","description":"This policy setting allows you to set an upper limit on the sleep interval used by the cache. The sleep is automatically interrupted when any application made changes in the cache or if there is an action scheduled to be performed.\r\n \r\nIf you enable this policy setting, you may specify how long (in minutes) the synchronization should wait before resuming when there is no pending work to do.\r\n\r\nIf you disable or do not configure this policy setting, then a default value of 20 minutes will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_sleepinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_sleepinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_sleepinterval_l_sleepintervaldecimal","displayName":"Sleep interval upper limit (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaultsizelimit","displayName":"Set web service default return size limit (User)","description":"This policy setting allows you to specify the default limit of how much data in kilobytes (KB) the web service shim can return per call. The application is allowed to specify a larger limit programmatically.\r\n\r\nIf you enable this policy setting, you may specify the default limit of data in kilobytes the web service shim can return per call.\r\n\r\nIf you disable or do not configure this policy setting, a default limit of 3000 KB will be used.","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaultsizelimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaultsizelimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaultsizelimit_l_webservicedefaultsizelimitdecimal","displayName":"Web service default size limit (KB) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaulttimeout","displayName":"Set web service default timeout (User)","description":"This policy setting allows you to specify the default timeout in milliseconds for the web service shim. The application is allowed to specify a larger timeout programmatically.\r\n\r\nIf you enable this policy setting, you may specify the default timeout in milliseconds for the web service shim.\r\n\r\nIf you disable or do not configure this policy setting, a default of 7000 milliseconds will be used.","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaulttimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaulttimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaulttimeout_l_webservicedefaulttimeoutdecimal","displayName":"Web service default timeout limit (milliseconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxsizelimit","displayName":"Set maximum web service return size limit (User)","description":"This policy setting allows you to specify the maximum limit of how much data in kilobytes (KB) the web service shim can return per call. This maximum value is enforced for applications including those that do not respect the default. \r\n\r\nIf you enable this policy setting, you may specify the maximum limit of data in kilobytes the web service shim can return per call.\r\n\r\nIf you disable or do not configure this policy setting, no maximum limit will be enforced.","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxsizelimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxsizelimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxsizelimit_l_webservicemaxsizelimitdecimal","displayName":"Web service maximum size limit (KB) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxtimeout","displayName":"Set maximum web service default timeout (User)","description":"This policy setting allows you to specify the maximum timeout in milliseconds for the web service shim. This maximum value is enforced for applications that do not respect the default.\r\n\r\nIf you enable this policy setting, you may specify the maximum timeout in milliseconds for the web service shim.\r\n\r\nIf you disable or do not configure this policy setting, no maximum limit will be enforced.","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicemaxtimeout_l_webservicemaxtimeoutdecimal","displayName":"Web service maximum timeout limit (milliseconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest","displayName":"Default subject for a review request (User)","description":"Defines the default subject text for a review request.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest_l_defaultsubjectforareviewrequest393","displayName":"Default subject for a review request (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_donotpromptuserstoshareexcelworkbookswhensendingforreview","displayName":"Do not prompt users to share Excel workbooks when sending for review (User)","description":"Checked: Do not prompt the user to share Excel workbooks when sending them for review. | Unchecked: Prompt the user to share Excel workbooks when sending them for review.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_donotpromptuserstoshareexcelworkbookswhensendingforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_donotpromptuserstoshareexcelworkbookswhensendingforreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingadhocreview","displayName":"Max number of documents being reviewed using ad hoc review (User)","description":"Sets the total number of documents that can be sent for review by a user using ad-hoc review before reusing registry entries from previous review cycles.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingadhocreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingadhocreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingadhocreview_l_empty388","displayName":"\r\nMax number of documents being reviewed using ad hoc review\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview","displayName":"Max number of documents being reviewed using 'send for review' (User)","description":"Sets the total number of documents that can be sent for review by a user before reusing registry entries from previous review cycles.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview_l_empty385","displayName":"\r\nMax number of documents being reviewed using 'send for review'\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing","displayName":"Outlook: Ad hoc reviewing (User)","description":"\"Enable ad hoc reviewing\": Enables the ad-hoc review feature. | \"Exclude author's e-mail in documents\": Enables the ad-hoc review feature, but the authors e-mail is not recorded on the sent document. | \"Disable ad hoc reviewing\": Disables the ad-hoc review feature.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_l_empty400","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_l_empty400_0","displayName":"Enable ad hoc reviewing","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_l_empty400_2","displayName":"Exclude author's e-mail in documents","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_l_empty400_1","displayName":"Disable ad hoc reviewing","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview","displayName":"Outlook: 'send for review' (User)","description":"\"Enable 'send for review\"': Enables the Send For Review feature. | \"Exclude author's e-mail in documents\": Enables the Send For Review feature, but the authors e-mail is not recorded on the sent document. | \"Disable 'send for review\"': Disables the Send For Review feature.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399_0","displayName":"Enable 'send for review'","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399_2","displayName":"Exclude author's e-mail in documents","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399_1","displayName":"Disable 'send for review'","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor","displayName":"Prompt for sending reviewed document to author (User)","description":"\"Never ask user\": Do not ask users if they want to send back changes to the author. | \"Prompt for 'send for review\"': Ask users if they want to send back changes to the author only if the document was sent using Send For Review and not with ad-hoc review. | \"Always prompt\": Ask users if they want to send back changes to the author for documents sent using either Send For Review or ad-hoc review.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_l_empty395","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_l_empty395_2","displayName":"Never ask user","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_l_empty395_1","displayName":"Prompt for 'send for review'","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_l_empty395_0","displayName":"Always prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview","displayName":"When choosing 'Send for Review...' (User)","description":"\"Send link and attachment\": When choosing Send for Review for a document on a server, send both a link and an attachment. | \"Only send link\": When choosing Send for Review for a document on a server, send only a link. | \"Prompt user\": When choosing Send for Review for a document on a server, prompt the user for what to send.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_l_empty392","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_l_empty392_2","displayName":"Send link and attachment","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_l_empty392_1","displayName":"Only send link","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_l_empty392_0","displayName":"Prompt user","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_coauthoring_l_setdocumentsynchronizationtimeout","displayName":"Set document synchronization timeout (User)","description":"This policy setting specifies the server timeout value in milliseconds for document synchronization. This policy setting does not apply when synchronizing documents on SharePoint servers. \r\n\r\nIf you enable this policy setting, you may specify the server timeout value in milliseconds for document synchronization.\r\n\r\nIf you disable or do not configure this policy setting, the server timeout will default to the Windows timeout value.\r\n","helpText":"","infoUrls":[],"categoryId":"a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_coauthoring_l_setdocumentsynchronizationtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_coauthoring_l_setdocumentsynchronizationtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_coauthoring_l_setdocumentsynchronizationtimeout_l_setdocumentsynchronizationtimeoutspinid","displayName":"in milliseconds: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","categoryName":"Co-authoring","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withasimplewebdiscussionslink373","displayName":"With a simple Web discussions link (User)","description":"Defines the default message body text used in a reply to an email request for review when the reply contains a simple Web discussions link. ","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withasimplewebdiscussionslink373_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withasimplewebdiscussionslink373_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withasimplewebdiscussionslink373_l_withasimplewebdiscussionslink374","displayName":"With a simple Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withawebdiscussionslink380","displayName":"With a Web discussions link (User)","description":"Defines the default message body text used in a reply to an email request for review when the reply contains a simple Web discussions link. ","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withawebdiscussionslink380_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withawebdiscussionslink380_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withawebdiscussionslink380_l_withawebdiscussionslink381","displayName":"With a Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustanattachment","displayName":"With just an attachment (User)","description":"Defines the default message body text used in a reply to an email request for review when the reply contains a simple Web discussions link. ","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustanattachment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustanattachment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustanattachment_l_withjustanattachment379","displayName":"With just an attachment (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink","displayName":"With just a simple Web discussions link (User)","description":"Defines the default message body text used in a reply to an email request for review when the reply contains a simple Web discussions link. ","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink_l_withjustasimplewebdiscussionslink377","displayName":"With just a simple Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontainingalink","displayName":"Only containing a link (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontainingalink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontainingalink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontainingalink_l_onlycontainingalink357","displayName":"Only containing a link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontaininganattachment","displayName":"Only containing an attachment (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontaininganattachment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontaininganattachment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontaininganattachment_l_onlycontaininganattachment356","displayName":"Only containing an attachment (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withalinkandanattachment","displayName":"With a link and an attachment (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withalinkandanattachment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withalinkandanattachment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withalinkandanattachment_l_withalinkandanattachment359","displayName":"With a link and an attachment (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink","displayName":"With a simple Web discussions link (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink_l_withasimplewebdiscussionslink362","displayName":"With a simple Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment","displayName":"With a simple Web discussions link and an attachment (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment_l_withasimplewebdiscussionslinkandanattachment364","displayName":"With a simple Web discussions link and an attachment (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslink","displayName":"With a Web discussions link (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslink_l_withawebdiscussionslink367","displayName":"With a Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslinkandanattachment","displayName":"With a Web discussions link and an attachment (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslinkandanattachment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslinkandanattachment_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslinkandanattachment_l_withawebdiscussionslinkandanattachment370","displayName":"With a Web discussions link and an attachment (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons","displayName":"Configure presence icons (User)","description":"This policy setting allows you to specify whether Microsoft Office applications display presence icons in the user interface (UI).\r\n\r\nIf you enable this policy setting, you may specify when applications display presence icons:\r\n\r\n- Display all: Presence icons are displayed in the UI.\r\n- Display some: Presence icons are displayed only in the Contact Card, Quick Contacts and SharePoint.\r\n- Display none: Presence icons are not displayed in the UI.\r\n\r\nIf you disable or you do not configure this policy setting, presence icons are displayed in the UI.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid_0","displayName":"Display all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid_1","displayName":"Display some","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid_2","displayName":"Display none","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_displaylegacygaldialog","displayName":"Display legacy GAL dialog (User)","description":"This policy setting allows you to specify the way contact information is displayed.\r\n\r\nIf you enable this policy setting the global address list (GAL) dialog is displayed instead of the Contact Card when users double click a contact in Outlook. \r\n\r\nIf you disable or do not configure this policy setting the Contact Card is displayed when users double click a contact in Outlook.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_displaylegacygaldialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_displaylegacygaldialog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayhovermenu","displayName":"Do not display Hover Menu (User)","description":"This policy setting allows you to stop the Hover Menu from displaying when a user hovers over a contact’s presence icon or display name with the mouse cursor.\r\n\r\nIf you enable this policy setting, when a user hovers over a contact’s presence icon or display name with the mouse cursor, the Hover Menu will not be displayed.\r\n\r\nIf you disable or do not configure this policy setting, the Hover Menu appears when a user hovers over a contact’s presence icon or display name with the mouse cursor.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayhovermenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayhovermenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayphotograph","displayName":"Do not display photograph (User)","description":"This policy setting lets you specify if the photograph is shown on the contact card, e-mail header, reading pane, fast search results, global address list (GAL) dialog, Backstage, and quick contacts. \r\n\r\nIf you enable this policy setting, photographs are not displayed in the locations listed above.\r\n\r\nIf you disable or do not configure this policy setting, photographs appear in the locations listed above.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayphotograph_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayphotograph_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removememberoftab","displayName":"Remove Member Of tab (User)","description":"This policy setting allows you to remove the Member Of tab from the Contact Card.\r\n\r\nIf you enable this policy setting the Member Of tab is removed from the Contact Card.\r\n\r\nIf you disable or do not configure this policy setting the Member Of tab appears on the Contact Card.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removememberoftab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removememberoftab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removeorganizationtab","displayName":"Remove Organization tab (User)","description":"This policy setting allows you to remove the Organization tab from the Contact Card.\r\n\r\nIf you enable this policy setting, the Organization tab is removed from the Contact Card.\r\n\r\nIf you disable or do not configure this policy setting, the Organization tab appears on the Contact Card.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removeorganizationtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removeorganizationtab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffclicktoimoption","displayName":"Turn off click to IM option (User)","description":"This policy setting allows you to remove the Instant Messaging (IM) option from the Contact Card and Outlook Ribbon.\r\n\r\nIf you enable this policy setting the Instant Messaging icon does not appear on the Contact Card and Outlook Ribbon.\r\n\r\nIf you disable or do not configure this policy setting the Instant Messaging icon appears on the Contact Card and Outlook Ribbon.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffclicktoimoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffclicktoimoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffclicktotelephone","displayName":"Turn off click to telephone (User)","description":"This policy setting allows you to remove the telephone option from the Contact Card and Outlook Ribbon.\r\n\r\nIf you enable this policy setting, the telephone option does not appear in the Contact Card. Telephone links do not appear in the Contact Card. Telephone options do not appear in the Outlook Ribbon.\r\n\r\nIf you disable or do not configure this policy setting telephone options appear in the Contact Card and Outlook Ribbon.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffclicktotelephone_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffclicktotelephone_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffpresenceintegration","displayName":"Turn off presence integration (User)","description":"This policy setting allows you to turn off instant messaging (IM) presence integration for Microsoft Office applications. \r\n\r\nIf you enable this policy, setting IM presence icons will not be displayed and presence integration will be turned off for Office applications.\r\n\r\nIf you disable or do not configure this policy setting, IM presence icons will be displayed and presence integration will be turned on for Office applications.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffpresenceintegration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffpresenceintegration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttabcalendar","displayName":"Remove Calendar Line (User)","description":"\r\nThis policy setting enables you to remove the Calendar line on the Contact Tab, which is on the Contact Card.\r\n\r\nIf you enable this policy setting, you can remove the Calendar line.\r\n\r\nIf you disable or do not configure this policy setting, the Calendar line appears on the Contact Tab.\r\n","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttabcalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttabcalendar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttablocation","displayName":"Remove Location Line (User)","description":"\r\nThis policy setting enables you to remove the Location line on the Contact Tab, which is on the Contact Card.\r\n\r\nIf you enable this policy setting, you can remove the Location line.\r\n\r\nIf you disable or do not configure this policy setting, the Location line appears on the Contact Tab.\r\n","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttablocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttablocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacebirthday","displayName":"Replace AD - Birthday (User)","description":"This policy setting allows you to customize the 16th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"birthday\" of line 16.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 16 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacebirthday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacebirthday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacebirthday_l_birthdayadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacecompany","displayName":"Replace AD - Company (User)","description":"This policy setting allows you to customize the 12th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"company\" of line 12.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 12 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacecompany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacecompany_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacecompany_l_companyadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail","displayName":"Replace AD - E-mail (User)","description":"This policy setting allows you to customize the 1st value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"email address\" of line 1.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 1 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail_l_emailadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome","displayName":"Replace AD - Home (User)","description":"This policy setting allows you to customize the 6th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"home phone\" of line 6.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 6 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome_l_homeadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome2","displayName":"Replace AD - Home2 (User)","description":"This policy setting allows you to customize the 7th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"home phone 2\" of line 7.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 7 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome2_l_home2adreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehomeadd","displayName":"Replace AD - Home Address (User)","description":"This policy setting allows you to customize the 14th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"home address\" of line 14.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 14 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehomeadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehomeadd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehomeadd_l_homeaddadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceim","displayName":"Replace AD - IM (User)","description":"This policy setting allows you to customize the 9th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"IM address\" of line 9.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 9 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceim_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceim_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceim_l_imadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacemobile","displayName":"Replace AD - Mobile (User)","description":"This policy setting allows you to customize the 5th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"mobile phone\" of line 5.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 5 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacemobile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacemobile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacemobile_l_mobileadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceoffice","displayName":"Replace AD - Office (User)","description":"This policy setting allows you to customize the 11th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"office location\" of line 11.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 11 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceoffice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceoffice_l_officeadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceother","displayName":"Replace AD - Other (User)","description":"This policy setting allows you to customize the 8th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"other phone\" of line 8.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 8 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceother_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceother_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceother_l_otheradreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceotheradd","displayName":"Replace AD - Other Address (User)","description":"This policy setting allows you to customize the 15th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"other address\" of line 15.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 15 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceotheradd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceotheradd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceotheradd_l_otheraddadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceprofile","displayName":"Replace AD - Profile (User)","description":"This policy setting allows you to customize the 10th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"profile\" of line 10.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 10 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceprofile_l_profileadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework","displayName":"Replace AD - Work (User)","description":"This policy setting allows you to customize the 2nd value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"work phone\" of line 2.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 2 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework_l_workadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2","displayName":"Replace AD - Work2 (User)","description":"This policy setting allows you to customize the 3rd value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"work phone 2\" of line 3.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 3 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2_l_work2adreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkadd","displayName":"Replace AD - Work Address (User)","description":"This policy setting allows you to customize the 13th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"work address\" of line 13.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 13 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkadd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkadd_l_workaddadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkfax","displayName":"Replace AD - WorkFax (User)","description":"This policy setting allows you to customize the 4th value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"work fax\" of line 4.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 4 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkfax_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkfax_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkfax_l_workfaxadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacebirthday","displayName":"Replace Label - Birthday (User)","description":"This policy setting allows you to change or remove the 16th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacebirthday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacebirthday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacebirthday_l_birthdaylabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany","displayName":"Replace Label - Company (User)","description":"This policy setting allows you to change or remove the 12th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany_l_companylabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail","displayName":"Replace Label - E-mail (User)","description":"This policy setting allows you to change or remove the 1st label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail_l_emaillabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome","displayName":"Replace Label - Home (User)","description":"This policy setting allows you to change or remove the 6th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome_l_homelabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome2","displayName":"Replace Label - Home2 (User)","description":"This policy setting allows you to change or remove the 7th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome2_l_home2labelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehomeadd","displayName":"Replace Label - Home Address (User)","description":"This policy setting allows you to change or remove the 14th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehomeadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehomeadd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehomeadd_l_homeaddlabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceim","displayName":"Replace Label - IM (User)","description":"This policy setting allows you to change or remove the 9th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceim_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceim_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceim_l_imlabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile","displayName":"Replace Label - Mobile (User)","description":"This policy setting allows you to change or remove the 5th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile_l_mobilelabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceoffice","displayName":"Replace Label - Office (User)","description":"This policy setting allows you to change or remove the 11th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceoffice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceoffice_l_officelabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother","displayName":"Replace Label - Other (User)","description":"This policy setting allows you to change or remove the 8th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother_l_otherlabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceotheradd","displayName":"Replace Label - Other Address (User)","description":"This policy setting allows you to change or remove the 15th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceotheradd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceotheradd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceotheradd_l_otheraddlabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceprofile","displayName":"Replace Label - Profile (User)","description":"This policy setting allows you to change or remove the 10th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceprofile_l_profilelabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework","displayName":"Replace Label - Work (User)","description":"This policy setting allows you to change or remove the 2nd label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework_l_worklabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework2","displayName":"Replace Label - Work2 (User)","description":"This policy setting allows you to change or remove the 3rd label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework2_l_work2labelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd","displayName":"Replace Label - Work Address (User)","description":"This policy setting allows you to change or remove the 13th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd_l_workaddlabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkfax","displayName":"Replace Label - WorkFax (User)","description":"This policy setting allows you to change or remove the 4th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkfax_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkfax_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkfax_l_workfaxlabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacebirthday","displayName":"Replace MAPI - Birthday (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"birthday\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"birthday\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacebirthday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacebirthday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacebirthday_l_birthdaymapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany","displayName":"Replace MAPI - Company (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"company\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"company\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany_l_companymapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceemail","displayName":"Replace MAPI - E-mail (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"email address\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"email address\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceemail_l_emailmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome","displayName":"Replace MAPI - Home (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"home phone\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"home phone\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome_l_homemapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome2","displayName":"Replace MAPI - Home2 (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"home phone 2\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"home phone 2\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome2_l_home2mapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehomeadd","displayName":"Replace MAPI - Home Address (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"home address\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"home address\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehomeadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehomeadd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehomeadd_l_homeaddmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceim","displayName":"Replace MAPI - IM (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"IM address\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"IM address\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceim_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceim_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceim_l_immapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacemobile","displayName":"Replace MAPI - Mobile (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"mobile phone\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"mobile phone\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacemobile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacemobile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacemobile_l_mobilemapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceoffice","displayName":"Replace MAPI - Office (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"office location\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"office location\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceoffice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceoffice_l_officemapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceother","displayName":"Replace MAPI - Other (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"other phone\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"other phone\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceother_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceother_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceother_l_othermapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceotheradd","displayName":"Replace MAPI - Other Address (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"other address\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"other address\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceotheradd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceotheradd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceotheradd_l_otheraddmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceprofile","displayName":"Replace MAPI - Profile (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"profile\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"profile\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceprofile_l_profilemapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework","displayName":"Replace MAPI - Work (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"work phone\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"work phone\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework_l_workmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework2","displayName":"Replace MAPI - Work2 (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"work phone 2\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"work phone 2\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework2_l_work2mapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkadd","displayName":"Replace MAPI - Work Address (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"work address\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"work address\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkadd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkadd_l_workaddmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkfax","displayName":"Replace MAPI - WorkFax (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"work fax\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"work fax\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkfax_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkfax_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceworkfax_l_workfaxmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_baseurl","displayName":"Base URL (User)","description":"Sets the URL for the location of customized error messages.","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_baseurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_baseurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_baseurl_l_baseurl349","displayName":"Base URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext","displayName":"Default button text (User)","description":"Sets the custom button text that appears on the error dialog box.","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext_l_defaultbuttontext350","displayName":"Default button text (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext","displayName":"Default save prompt text (User)","description":"Sets the text displayed when the user saves a document in any format other than the default.","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext_l_defaultsaveprompttext352","displayName":"Default save prompt text (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize351","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize351_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize351_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_hidebuiltinshapepresetstyles","displayName":"Hide built-in shape style presets (User)","description":"This policy setting allows you to specify whether or not to show the the built-in shape preset styles.","helpText":"","infoUrls":[],"categoryId":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","categoryName":"Disable Items in User Interface","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_hidebuiltinshapepresetstyles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_hidebuiltinshapepresetstyles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_tooltipfordisabledtoolbarbuttonsandmenuitems","displayName":"Tooltip for disabled toolbar buttons and menu items (User)","description":"Defines the text to be used in tooltips for disabled toolbar buttons and menu items.","helpText":"","infoUrls":[],"categoryId":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","categoryName":"Disable Items in User Interface","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_tooltipfordisabledtoolbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_tooltipfordisabledtoolbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_tooltipfordisabledtoolbarbuttonsandmenuitems_l_tooltipfordisabledtoolbarbuttonsandmenuitems353","displayName":"Tooltip for disabled toolbar buttons and menu items (User)","description":"","helpText":"","infoUrls":[],"categoryId":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","categoryName":"Disable Items in User Interface","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_turnoffscreenclipping","displayName":"Turn off screen clipping (User)","description":"This policy setting allows you to turn off the Insert Screenshot feature.\r\n\r\nIf you enable this policy setting, you will turn off the Insert Screenshot feature found in Microsoft Excel, PowerPoint, Outlook, and Word. This setting does not affect the screen clipping feature found in Microsoft OneNote or the Print Screen key on your keyboard.\r\n\r\nIf you disable or do not configure this policy setting, the Insert Screenshot feature in Microsoft Excel, PowerPoint, Outlook, and Word will be available. This feature allows users to insert both screen clippings and the contents of an entire active window. ","helpText":"","infoUrls":[],"categoryId":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","categoryName":"Disable Items in User Interface","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_turnoffscreenclipping_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_turnoffscreenclipping_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_dlp_l_policytipsenabled","displayName":"Enable DLP on application boot (User)","description":"This policy setting determines whether DLP executes on application boot.\r\n\r\nIf you enable this policy setting, DLP runs on application boot.\r\n\r\nIf you disable or do not configure this policy setting, DLP does not run on application boot.","helpText":"","infoUrls":[],"categoryId":"b94cbc54-e565-44f2-a27a-a63b2514d8bf","categoryName":"DLP","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_dlp_l_policytipsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_dlp_l_policytipsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_disabledocumentinformationpanel","displayName":"Disable Document Information Panel (User)","description":"This policy setting controls whether Excel, PowerPoint, and Word users can view document information in the Document Information Panel.The Document Information Panel replaces the modal Properties dialog box in earlier versions of Excel, PowerPoint, and Word, and allows users to view and edit metadata that is associated with the document. Office 2016 developers can create custom Document Information Panels to record a variety of information relevant to the document or the organization. \r\n\r\nIf you enable this policy setting, forms and controls do not display in the Document Information Panel. The panel itself will display when users open it, but it will be blank. \r\n\r\nIf you disable or do not configure this policy setting, users can view the Document Information Panel.","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_disabledocumentinformationpanel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_disabledocumentinformationpanel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui","displayName":"Document Information Panel Beaconing UI (User)","description":"This policy setting controls whether users see a security warning when they open custom Document Information Panels that contain a Web beaconing threat. InfoPath can be used to create custom Document Information Panels that can be attached to Excel workbooks, PowerPoint presentations, and Word documents. \r\n\r\nIf you enable this policy setting, you can choose from three options for controlling when users are prompted about Web beaconing threats: \r\n\r\n- Never show UI \r\n\r\n- Always show UI \r\n\r\n- Show UI if XSN is in Internet Zone \r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled -- Never show UI.","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui_l_empty423","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui_l_empty423_0","displayName":"Never show UI","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui_l_empty423_1","displayName":"Always show UI","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_documentinformationpanelbeaconingui_l_empty423_2","displayName":"Show UI if XSN is in Internet Zone","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel","displayName":"Offline Mode for Document Information Panel (User)","description":"Specify if Offline Mode is disabled/enabled for custom Document Information Panel templates and if the Document Information Panel is currently in Offline Mode.","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel_l_empty422","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel_l_empty422_0","displayName":"Disable Offline Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel_l_empty422_1","displayName":"Enable Offline Mode, work offline now","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_offlinemodefordocumentinformationpanel_l_empty422_2","displayName":"Enable Offline Mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution","displayName":"Trust Local Solution (User)","description":"Suppresses prompt that asks to load a locally installed full-trust solution of a Document Information Panel in the background. This is normally shown if a full-trust solution is deployed and there are bound properties in the document (e.g. lookups) that must load the Document Information Panel in the background to retrieve the contents of the property. \r\n\r\nEnter pairs corresponding to the Document Information Panel solution path and a value of 1 to disable. If the value is set, the user will not be prompted when loading the full-trust solution in the background. The solution will load normally (and any non-related warnings that exist).","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_l_empty421","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_l_empty421_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_l_empty421_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_hidemissingcomponentdownloadhyperlinks","displayName":"Hide missing component download hyperlinks (User)","description":"Don't allow the download of missing components but not showing the download hyperlinks for the missing components. Possible missing components are the Microsoft .NET 2.0 framework and Workflow component.","helpText":"","infoUrls":[],"categoryId":"bc633a5a-c712-49a6-9f56-775ca9321df4","categoryName":"Downloading Framework Components","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_hidemissingcomponentdownloadhyperlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_hidemissingcomponentdownloadhyperlinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20framework","displayName":"Set download location for Microsoft .NET Framework 2.0 (User)","description":"Set a custom path to where users can access the missing component.","helpText":"","infoUrls":[],"categoryId":"bc633a5a-c712-49a6-9f56-775ca9321df4","categoryName":"Downloading Framework Components","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20framework_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20framework_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20framework_l_empty434","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"bc633a5a-c712-49a6-9f56-775ca9321df4","categoryName":"Downloading Framework Components","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20frameworklp","displayName":"Set download location for Microsoft .NET Framework 2.0 Language Pack (User)","description":"Set a custom path to where users can access the missing component.","helpText":"","infoUrls":[],"categoryId":"bc633a5a-c712-49a6-9f56-775ca9321df4","categoryName":"Downloading Framework Components","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20frameworklp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20frameworklp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20frameworklp_l_empty435","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"bc633a5a-c712-49a6-9f56-775ca9321df4","categoryName":"Downloading Framework Components","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy1","displayName":"Places Bar Location 1 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy1_l_placesbarname","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy1_l_placesbarpath","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy10","displayName":"Places Bar Location 10 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy10_l_placesbarname227","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy10_l_placesbarpath228","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy2","displayName":"Places Bar Location 2 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy2_l_placesbarname211","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy2_l_placesbarpath212","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy3","displayName":"Places Bar Location 3 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy3_l_placesbarname213","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy3_l_placesbarpath214","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy4","displayName":"Places Bar Location 4 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy4_l_placesbarname215","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy4_l_placesbarpath216","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5","displayName":"Places Bar Location 5 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_l_placesbarname217","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_l_placesbarpath218","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6","displayName":"Places Bar Location 6 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_l_placesbarname219","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_l_placesbarpath220","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7","displayName":"Places Bar Location 7 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_l_placesbarname221","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_l_placesbarpath222","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8","displayName":"Places Bar Location 8 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8_l_placesbarname223","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8_l_placesbarpath224","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy9","displayName":"Places Bar Location 9 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy9_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy9_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy9_l_placesbarname225","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy9_l_placesbarpath226","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing","displayName":"Activate Restricted Browsing (User)","description":"When Restricted Browsing is activated the save as dialog box will be restricted such that the user will only be able to navigate to those locations and the children of those locations specified in the \"Restricted Browsing\\Approve Locations\" policy setting. If you want to enable the \"Approve Locations\" policy setting, you must first enable the \"Approve Locations\" policy setting first.","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_access","displayName":"Microsoft Access (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_access_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_access_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_excel","displayName":"Microsoft Excel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_excel_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_excel_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_infopath","displayName":"Microsoft InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_infopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_infopath_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_onenote","displayName":"Microsoft OneNote (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_onenote_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_onenote_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_outlook","displayName":"Microsoft Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_outlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_outlook_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_powerpoint","displayName":"Microsoft PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_powerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_powerpoint_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_project","displayName":"Microsoft Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_project_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_project_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_publisher","displayName":"Microsoft Publisher (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_publisher_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_publisher_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_sharepoint","displayName":"Microsoft SharePoint Designer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_sharepoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_sharepoint_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_visio","displayName":"Microsoft Visio (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_visio_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_visio_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_word","displayName":"Microsoft Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_word_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_word_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy","displayName":"Approve Locations (User)","description":"Adds locations, such as c:\\Windows or \\\\server\\share, to the list of approved locations for use with Restricted Browsing. When Restricted Browsing is active, the Save As dialog box is restricted such that the user can navigate only to the locations and the children of the locations specified in this list. \r\n\r\nTo allow easier access to these approved locations, consider adding them to the Places bar by using the Places Bar Locations setting for the File Open/Save dialog box. If there are no approved locations in the Places bar, the dialog box may not be able to open.\r\n\r\nTo activate Restricted Browsing, use the Restricted Browsing/Activate Restricted Browsing setting. Note: You must set this policy setting first before the \"Activate Restricted Browsing.\"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_l_listofapprovedlocations","displayName":"List of Approved Locations: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_l_listofapprovedlocations_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_l_listofapprovedlocations_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_firstrun_l_disablemovie","displayName":"Disable First Run Movie (User)","description":"This policy setting determines whether a video about signing-in to Office is played when Office first runs.\r\n\r\nIf you enable this policy setting, the video does not run during Office First Run.\r\n\r\nIf you disable or do not configure this policy setting, a video about signing-in to Office plays when Office first runs.","helpText":"","infoUrls":[],"categoryId":"72a7524b-11c5-4695-9fcf-6cf30c8ba2b9","categoryName":"First Run","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_firstrun_l_disablemovie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_firstrun_l_disablemovie_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_firstrun_l_disableofficefirstrun","displayName":"Disable Office First Run on application boot (User)","description":"This policy setting determines whether the Office First Run comes up on first application boot if not previously viewed.\r\n\r\nIf you enable this policy setting, the Office First Run does not run on first application boot.\r\n\r\nIf you disable or do not configure this policy setting, the Office First Run about signing-in to Office comes up on first application boot if not previously viewed.","helpText":"","infoUrls":[],"categoryId":"72a7524b-11c5-4695-9fcf-6cf30c8ba2b9","categoryName":"First Run","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_firstrun_l_disableofficefirstrun_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_firstrun_l_disableofficefirstrun_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_allowroamingquickaccesstoolbarribboncustomizations","displayName":"Allow roaming of all user customizations (User)","description":"This policy setting allows roaming of both the Quick Access Toolbar and Ribbon customizations. \r\n\r\nIf you enable this policy setting, users' Quick Access Toolbar and Ribbon customizations will be available to them on any computer on their network when they log on. \r\n\r\nIf you disable or do not configure this policy setting, users' Quick Access Toolbar and Ribbon customizations will only be available to them on the computer on which they made the customizations.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_allowroamingquickaccesstoolbarribboncustomizations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_allowroamingquickaccesstoolbarribboncustomizations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy","displayName":"Turn off user customizations via UI (User)","description":"This policy setting can prevent users from customizing both the Quick Access Toolbar and Ribbon through the user interface (UI).\r\n\r\nIf you enable this policy setting, the following UI entry points are turned off: the Quick Access Toolbar and Ribbon tabs in the application's Office Center dialog box, and the Quick Access Toolbar and Ribbon customization options on the right-click menu on the Ribbon.\r\n\r\nIf you disable or do not configure this policy setting, users can customize the Quick Access Toolbar and Ribbon through both the application’s Office Center dialog box, and the right-click menu on the Ribbon.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiaccess","displayName":"Disallow in Access (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiaccess_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiaccess_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiexcel","displayName":"Disallow in Excel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiexcel_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiexcel_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiinfopath","displayName":"Disallow in InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiinfopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiinfopath_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuionenote","displayName":"Disallow in OneNote (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuionenote_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuionenote_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuioutlook","displayName":"Disallow in Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuioutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuioutlook_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipowerpoint","displayName":"Disallow in PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipowerpoint_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiproject","displayName":"Disallow in Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiproject_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipublisher","displayName":"Disallow in Publisher (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipublisher_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipublisher_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispd","displayName":"Disallow in SharePoint Designer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispw","displayName":"Disallow in SharePoint Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispw_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispw_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuivisio","displayName":"Disallow in Visio (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuivisio_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuivisio_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiword","displayName":"Disallow in Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiword_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_donotshowscreentipsontoolbars","displayName":"Do not show ScreenTips on toolbars (User)","description":"This policy setting allows you to configure the \"Show ScreenTips on Toolbars\" option.\r\n\r\nIf you enable this policy setting, ScreenTips will not be shown on toolbars.\r\n\r\nIf you disable or do not configure this policy setting, ScreenTips will be shown on toolbars.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_donotshowscreentipsontoolbars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_donotshowscreentipsontoolbars_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_largeicons","displayName":"Large icons (User)","description":"Checks/Unchecks the corresponding UI option. This option only applies to CommandBars UI.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_largeicons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_largeicons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_listfontnamesintheirfont","displayName":"List font names in their font (User)","description":"Checks/Unchecks the corresponding UI option. This option only applies to CommandBars UI.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_listfontnamesintheirfont_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_listfontnamesintheirfont_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations","displayName":"Menu animations (User)","description":"Checks/Unchecks the corresponding UI option. This option only applies to CommandBars UI.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_l_menuanimations209","displayName":"Menu animations (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_l_menuanimations209_0","displayName":"(System Default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_l_menuanimations209_1","displayName":"Random","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_l_menuanimations209_2","displayName":"Unfold","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_l_menuanimations209_3","displayName":"Slide","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_l_menuanimations209_4","displayName":"Fade","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy","displayName":"Disable UI extending from documents and templates (User)","description":"This policy setting controls whether Office 2016 applications load any custom user interface (UI) code included with a document or template. Office 2016 allows developers to extend the UI with customization code that is included in a document or template. \r\n\r\nIf you enable this policy setting, Office 2016 applications cannot load any UI customization code included with documents and templates. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 applications load any UI customization code included with a document or template when opening it.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyaccess","displayName":"Disallow in Access (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyaccess_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyaccess_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyexcel","displayName":"Disallow in Excel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyexcel_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyexcel_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyinfopath","displayName":"Disallow in InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyinfopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyinfopath_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyoutlook","displayName":"Disallow in Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyoutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyoutlook_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypowerpoint","displayName":"Disallow in PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypowerpoint_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyproject","displayName":"Disallow in Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyproject_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypublisher","displayName":"Disallow in Publisher (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypublisher_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypublisher_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyvisio","displayName":"Disallow in Visio (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyvisio_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyvisio_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyword","displayName":"Disallow in Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyword_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy","displayName":"Turn off all user customizations (User)","description":"This policy setting can prevent users from making any Quick Access Toolbar and the Ribbon customizations. This includes customizations made through user interface (UI) entry points, or loaded from documents or templates.\r\n\r\nIf you enable this policy setting, users will not be able to customize the Quick Access Toolbar and Ribbon through either the Quick Access Toolbar and Ribbon tabs in the application's Office Center dialog box, or the right-click menu on the Ribbon. In addition, Quick Access Toolbar and Ribbon customizations originating from documents or templates will not be loaded when these documents are opened.\r\n\r\nIf you disable or do not configure this policy setting, users can make Quick Access Toolbar and Ribbon customizations through the UI, as well as load them from documents and templates.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyaccess","displayName":"Disallow in Access (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyaccess_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyaccess_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyexcel","displayName":"Disallow in Excel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyexcel_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyexcel_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyinfopath","displayName":"Disallow in InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyinfopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyinfopath_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyonenote","displayName":"Disallow in OneNote (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyonenote_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyonenote_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyoutlook","displayName":"Disallow in Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyoutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyoutlook_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypowerpoint","displayName":"Disallow in PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypowerpoint_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyproject","displayName":"Disallow in Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyproject_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypublisher","displayName":"Disallow in Publisher (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypublisher_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypublisher_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspd","displayName":"Disallow in SharePoint Designer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspw","displayName":"Disallow in SharePoint Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspw_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspw_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyvisio","displayName":"Disallow in Visio (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyvisio_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyvisio_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyword","displayName":"Disallow in Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyword_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_showshortcutkeysinscreentips","displayName":"Show shortcut keys in ScreenTips (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_showshortcutkeysinscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_showshortcutkeysinscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_automaticdiscovery","displayName":"Automatic Discovery (User)","description":"Enables/Disables the Automatic Discovery feature.","helpText":"","infoUrls":[],"categoryId":"13123148-c522-437f-b316-d78f5cc0d28d","categoryName":"Shared Workspace","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_automaticdiscovery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_automaticdiscovery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_automaticdiscovery_l_automaticdiscovery210","displayName":"Automatic Discovery (User)","description":"","helpText":"","infoUrls":[],"categoryId":"13123148-c522-437f-b316-d78f5cc0d28d","categoryName":"Shared Workspace","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_automaticdiscovery_l_automaticdiscovery210_on","displayName":"On","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_automaticdiscovery_l_automaticdiscovery210_off","displayName":"Off","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_disableuserfromsettingpersonalsiteasdefaultlocation","displayName":"Disable user from setting personal site as default location (User)","description":"Checked: User is not able to define the default location to the personal site. | Unchecked: Default location is not restricted.","helpText":"","infoUrls":[],"categoryId":"13123148-c522-437f-b316-d78f5cc0d28d","categoryName":"Shared Workspace","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_disableuserfromsettingpersonalsiteasdefaultlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_disableuserfromsettingpersonalsiteasdefaultlocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace~l_definesharedworkspaceurls_l_site1","displayName":"Site 1: (User)","description":"Specifies the name and URL of a shared workspace. The name and URL appear in the Document Management pane.","helpText":"","infoUrls":[],"categoryId":"725adbdf-1eb8-45c4-8eb1-44747bd1615d","categoryName":"Define Shared Workspace URL's","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace~l_definesharedworkspaceurls_l_site1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace~l_definesharedworkspaceurls_l_site1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace~l_definesharedworkspaceurls_l_site1_l_name","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"725adbdf-1eb8-45c4-8eb1-44747bd1615d","categoryName":"Define Shared Workspace URL's","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace~l_definesharedworkspaceurls_l_site1_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"725adbdf-1eb8-45c4-8eb1-44747bd1615d","categoryName":"Define Shared Workspace URL's","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_charttemplatesserverlocation","displayName":"Chart Templates Server Location (User)","description":"Specifies the location [URL or UNC] for server-based chart templates.","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_charttemplatesserverlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_charttemplatesserverlocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_charttemplatesserverlocation_l_location","displayName":"Location: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_enablemsgraphasdefaultchart","displayName":"Enable MS Graph as Default Chart Tool in PowerPoint and Word (User)","description":"Enables administrators to set the default chart creation tool to MS Graph instead of the default Excel Chart in PowerPoint and Word. Also blocks conversion of Graph charts to Office charts.","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_enablemsgraphasdefaultchart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_enablemsgraphasdefaultchart_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_graphgallerypath","displayName":"Graph gallery path (User)","description":"Sets the path to store user-defined custom charts.","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_graphgallerypath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_graphgallerypath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_graphgallerypath_l_graphgallerypath354","displayName":"Graph gallery path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_help_l_federatedsearchforhelp","displayName":"Federated search for help (User)","description":"\r\n This policy setting allows you to determine the sources of content that Office users in your organization can access through Office Help (F1).\r\n\r\n If you enable or do not configure this policy setting, users who utilize Office Help see content from both Office and the Internet.\r\n\r\n If you disable this setting, Office users’ search results through Help are limited to Office content.\r\n ","helpText":"","infoUrls":[],"categoryId":"1942922a-cba9-44c8-871f-3d915c62bd06","categoryName":"Help","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_help_l_federatedsearchforhelp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_help_l_federatedsearchforhelp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltincolorvariations","displayName":"Disable built-in color variations (User)","description":"Specify whether or not to show the built-in color variations.","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltincolorvariations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltincolorvariations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltinigxgraphics","displayName":"Disable built-in graphics (User)","description":"Specify whether or not to show the built-in SmartArt Graphics.","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltinigxgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltinigxgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltinquickstyles","displayName":"Disable Built-in Quick Styles (User)","description":"Specify whether or not to show the built-in Quick Styles.","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltinquickstyles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltinquickstyles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel","displayName":"Error Severity Level (User)","description":"Specify the severity level of errors included in the log file created when loading layouts for SmartArt graphic layouts. Choosing Errors only will result in the smallest possible log file and choosing All will result in the largest log file.","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419","displayName":"Error Severity Level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_0","displayName":"Errors only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_1","displayName":"Level 1 warnings and below","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_2","displayName":"Level 2 warnings and below","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_3","displayName":"Level 3 warnings and below","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_4","displayName":"All","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber","displayName":"Log File Entries Number (User)","description":"Specify the number of log entries to be removed from the log file when the maximum size limit is exceeded. (1-1000)","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber_l_empty420","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfilemaximumsize","displayName":"Log File Maximum Size (User)","description":"Specify the maximum size in bytes for the log file created when loading custom layouts. (Maximum = 100000)","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfilemaximumsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfilemaximumsize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfilemaximumsize_l_logfilemaximumsizepart","displayName":"Bytes: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookcontactsdictionary","displayName":"Set comment fields for Outlook Contacts Dictionary (User)","description":"This policy setting allows you to specify the fields to display in the comments in the Outlook Contacts Dictionary. This policy setting applies to Japanese Microsoft IME only.\r\n\r\nIf you enable this policy setting, you can specify the fields to display by setting strings, which are represented by the following identification letter IDs. You must also use any IDs/strings in the following sequence.\r\n\r\nID for each field is as follows:\r\na = Full Name\r\nc = Phonetic Name\r\ne = Company Name\r\nf = Department Name\r\ng = Title\r\nh = Office Location\r\nj = Email Address\r\nk = Business Telephone Number\r\nl = Business Address\r\n\r\nFor example, if you want to display Full Name, Phonetic Name and Company Name, specify 'ace'.\r\n\r\nIf you do not configure this policy setting, Full Name, Phonetic Name, Company Name, Department Name, and Job Title are displayed in the comments in this order.","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookcontactsdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookcontactsdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookcontactsdictionary_l_setcommentfieldsforoutlookcontactsdictionaryid","displayName":"Field identification letters: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookglobaladdresslistdictionary","displayName":"Set comment fields for Outlook Global Address List Dictionary (User)","description":"This policy setting allows you to specify the fields to display in the comments in the Outlook Global Address List Dictionary. This policy setting applies to Japanese Microsoft IME only.\r\n\r\nIf you enable this policy setting, you can specify the fields to display by setting strings, which are represented by the following identification letter IDs. You must also use any IDs/strings in the following sequence.\r\n\r\nThe ID for each field is as follows:\r\na = Full Name\r\nc = Phonetic Name\r\ne = Company Name\r\nf = Department Name\r\ng = Title\r\nh = Office Location\r\nj = Email Address\r\nk = Business Telephone Number\r\nl = Business Address\r\n\r\nFor example, if you want to display Full Name, Phonetic Name and Company Name, specify 'ace'.\r\n\r\nIf you do not configure this policy setting, Full Name, Phonetic Name, Department Name, Job Title and Office Location are displayed in the comments, in this order.","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookglobaladdresslistdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookglobaladdresslistdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookglobaladdresslistdictionary_l_setcommentfieldsforoutlookglobaladdresslistdictionaryid","displayName":"Field identification letters: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookcontactsdictionary","displayName":"Set update interval for Outlook Contacts Dictionary (User)","description":"This policy setting allows you to specify the update interval for the Outlook Contacts Dictionary. This policy setting applies to Japanese Microsoft IME only.\r\n\r\nIf you enable this policy setting, you can specify the update interval. For example, if you specify \"720,\" the Outlook Contacts Dictionary is updated every 720 minutes.\r\n\r\nIf you do not configure this policy setting, the Outlook Contacts Dictionary is updated every 1440 minutes (24 hours).","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookcontactsdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookcontactsdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookcontactsdictionary_l_setupdateintervalforoutlookcontactsdictionaryspinid","displayName":"(in minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary","displayName":"Set update interval for Outlook Global Address List Dictionary (User)","description":"This policy setting allows you to specify the update interval for the Outlook Global Address List Dictionary. This policy setting applies to Japanese Microsoft IME only.\r\n\r\n\r\nIf you enable this policy setting, you can specify the update interval in minutes. For example, if you specify \"720,\" the Outlook Global Address List Dictionary is updated every 720 minutes.\r\n\r\nIf you do not configure this policy setting, the Outlook Global Address List Dictionary is updated every 1440 minutes (24 hours).","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary_l_setupdateintervalforoutlookglobaladdresslistdictionaryspinid","displayName":"(in minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffoutlooknamedictionaries","displayName":"Turn off Outlook name dictionaries update (User)","description":"This policy setting allows you to turn off updating for Outlook name dictionaries of Microsoft IME (Input Method Editor). This policy setting applies to Japanese Microsoft IME only.\r\n\r\nIf you enable this policy setting, all Outlook name dictionaries are not updated.\r\nOutlook name dictionaries that were added before enabling this policy setting are used for conversion.\r\n\r\nIf you disable or do not configure this policy setting, Outlook name dictionaries are generated, updated and used for conversion.","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffoutlooknamedictionaries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffoutlooknamedictionaries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffsharepointdictionary","displayName":"Turn off SharePoint dictionary update (User)","description":"This policy setting allows you to turn off updating for SharePoint dictionary of Microsoft IME (Input Method Editor). This policy setting applies to Japanese Microsoft IME only.\r\n\r\nIf you enable this policy setting, SharePoint dictionary is not updated, and you cannot add a new SharePoint dictionary.\r\nA SharePoint dictionary that was added before enabling this policy setting is used for conversion.\r\n\r\nIf you disable or do not configure this policy setting, SharePoint dictionary can be updated and added.","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffsharepointdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffsharepointdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingerrormessages","displayName":"Stop reporting error messages (User)","description":"This policy setting controls whether the application reports error messages.\r\n\r\nIf you enable this policy, error messages will not be reported.\r\n\r\nIf you disable or do not configure this policy setting, error messages will be reported.","helpText":"","infoUrls":[],"categoryId":"33fb4f49-5c7f-472c-a0f3-e05646a55902","categoryName":"Improved Error Reporting","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingerrormessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingerrormessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingnoncriticalerrors","displayName":"Stop reporting non-critical errors (User)","description":"This policy setting controls whether the application reports non-critical errors.\r\n\r\nIf you enable this policy, non-critical errors will not be reported.\r\n\r\nIf you disable or do not configure this policy setting, non-critical errors will be reported.","helpText":"","infoUrls":[],"categoryId":"33fb4f49-5c7f-472c-a0f3-e05646a55902","categoryName":"Improved Error Reporting","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingnoncriticalerrors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingnoncriticalerrors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings_l_disableproofingtoolsadvertisement","displayName":"Notify users if they do not have proofing tools for a language they use (User)","description":"This policy setting allows you to turn on or turn off notifications that are displayed to users when they use a language in their document but do not have proofing tools installed for that language.\r\n\r\nIf you enable this policy setting, users see a message bar when they use a language in their document but do not have proofing tools installed for that language. Users cannot disable this notification because the \"Never show again\" button is not shown, and the checkbox to disable proofing notifications is removed from the Options dialog box.\r\n\r\nIf you disable this policy setting, users do not see this message bar.\r\n\r\nIf you do not configure this policy setting, users see this message bar. They can disable the notification by clicking the \"Never show again\" button or by clearing a check box in the Options dialog box.","helpText":"","infoUrls":[],"categoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","categoryName":"Language Preferences","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings_l_disableproofingtoolsadvertisement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings_l_disableproofingtoolsadvertisement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktolanguagepackdownloadsite","displayName":"Change or delete link to language pack download site (User)","description":"This policy setting affects the language download link under the display and help language section.\r\n\r\nIf you enable this policy setting you, you may enter the URL to another location where language packs may be downloaded.\r\n\r\nIf you disable this policy setting the URL will be removed.\r\n\r\nIf you do not configure this policy setting, the URL will remain available and point to the language pack download site on Office.com.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktolanguagepackdownloadsite_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktolanguagepackdownloadsite_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktolanguagepackdownloadsite_l_changeordeletelinktolanguagepackdownloadsiteid","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite","displayName":"Change or delete link to the proofing tools download site (User)","description":"This policy setting affects the proofing tools link under the Editing language section.\r\n\r\nIf you enable this policy setting you, you may enter the URL to another location where proofing tools may be downloaded.\r\n\r\nIf you disable this policy setting the URL will be removed.\r\n\r\nIf you do not configure this policy setting, the URL will remain available and point to the proofing tools site on Office.com.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite_l_changeordeletelinktoproofingtoolsdownloadsiteid","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin","displayName":"Display help in (User)","description":"Sets the default language of online Help. In addition to configuring this setting, consider enabling the same language in the 'Enabled Editing Languages' policy node.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336","displayName":"Display help in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_0","displayName":"(same as menus and dialog boxes)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1078","displayName":"Afrikaans","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1052","displayName":"Albanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1118","displayName":"Amharic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1025","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1067","displayName":"Armenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1101","displayName":"Assamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1068","displayName":"Azerbaijani (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2117","displayName":"Bangla (Bangladesh)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1093","displayName":"Bangla (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1069","displayName":"Basque","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1059","displayName":"Belarusian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_5146","displayName":"Bosnian (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1026","displayName":"Bulgarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1027","displayName":"Catalan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1170","displayName":"Central Kurdish (Iraq)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1116","displayName":"Cherokee","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2052","displayName":"Chinese (Simplified)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1028","displayName":"Chinese (Traditional)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1050","displayName":"Croatian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1029","displayName":"Czech","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1030","displayName":"Danish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1164","displayName":"Dari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1043","displayName":"Dutch","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1033","displayName":"English","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1061","displayName":"Estonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1124","displayName":"Filipino","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1035","displayName":"Finnish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1036","displayName":"French","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1110","displayName":"Galician","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1079","displayName":"Georgian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1031","displayName":"German","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1032","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1095","displayName":"Gujarati","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1128","displayName":"Hausa (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1037","displayName":"Hebrew","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1081","displayName":"Hindi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1038","displayName":"Hungarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1039","displayName":"Icelandic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1136","displayName":"Igbo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1057","displayName":"Indonesian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2141","displayName":"Inuktitut (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2108","displayName":"Irish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1076","displayName":"isiXhosa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1077","displayName":"isiZulu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1040","displayName":"Italian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1041","displayName":"Japanese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1099","displayName":"Kannada","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1087","displayName":"Kazakh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1107","displayName":"Khmer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1158","displayName":"K'iche","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1159","displayName":"Kinyarwanda","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1089","displayName":"Swahili","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1111","displayName":"Konkani","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1042","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1088","displayName":"Kyrgyz","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1062","displayName":"Latvian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1063","displayName":"Lithuanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1134","displayName":"Luxembourgish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1086","displayName":"Malay (Malaysia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1100","displayName":"Malayalam","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1082","displayName":"Maltese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1153","displayName":"Maori","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1102","displayName":"Marathi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1104","displayName":"Mongolian (Cyrillic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1071","displayName":"Macedonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1121","displayName":"Nepali","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1044","displayName":"Norwegian (Bokmal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2068","displayName":"Norwegian (Nynorsk)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1096","displayName":"Odia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1065","displayName":"Persian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1045","displayName":"Polish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1046","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2070","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1094","displayName":"Punjabi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2118","displayName":"Punjabi (Pakistan)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_3179","displayName":"Quechua (Peru)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1048","displayName":"Romanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1049","displayName":"Russian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1169","displayName":"Scottish Gaelic (United Kingdom)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_3098","displayName":"Serbian (Cyrillic, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_7194","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2074","displayName":"Serbian (Latin, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1132","displayName":"Sesotho sa Leboa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1074","displayName":"Setswana","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2137","displayName":"Sindhi (Arabic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1115","displayName":"Sinhala","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1051","displayName":"Slovak","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1060","displayName":"Slovenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_3082","displayName":"Spanish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1053","displayName":"Swedish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1064","displayName":"Tajik","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1097","displayName":"Tamil","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1092","displayName":"Tatar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1098","displayName":"Telugu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1054","displayName":"Thai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1139","displayName":"Tigrinya (Ethiopia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1055","displayName":"Turkish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1090","displayName":"Turkmen","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1058","displayName":"Ukrainian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1056","displayName":"Urdu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1152","displayName":"Uyghur (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1091","displayName":"Uzbek (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_2051","displayName":"Valencian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1066","displayName":"Vietnamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1106","displayName":"Welsh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1160","displayName":"Wolof","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_l_displayhelpin336_1130","displayName":"Yoruba","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin","displayName":"Display menus and dialog boxes in (User)","description":"Sets the display language of the user interface for all Office 2016 programs. In addition to configuring this setting, consider enabling the same language in the 'Enabled Editing Languages' policy node.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334","displayName":"Display menus and dialog boxes in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_0","displayName":"(same as the system)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1078","displayName":"Afrikaans","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1052","displayName":"Albanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1118","displayName":"Amharic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1025","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1067","displayName":"Armenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1101","displayName":"Assamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1068","displayName":"Azerbaijani (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2117","displayName":"Bangla (Bangladesh)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1093","displayName":"Bangla (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1069","displayName":"Basque","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1059","displayName":"Belarusian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_5146","displayName":"Bosnian (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1026","displayName":"Bulgarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1027","displayName":"Catalan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1170","displayName":"Central Kurdish (Iraq)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1116","displayName":"Cherokee","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2052","displayName":"Chinese (Simplified)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1028","displayName":"Chinese (Traditional)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1050","displayName":"Croatian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1029","displayName":"Czech","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1030","displayName":"Danish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1164","displayName":"Dari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1043","displayName":"Dutch","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1033","displayName":"English","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1061","displayName":"Estonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1124","displayName":"Filipino","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1035","displayName":"Finnish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1036","displayName":"French","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1110","displayName":"Galician","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1079","displayName":"Georgian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1031","displayName":"German","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1032","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1095","displayName":"Gujarati","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1128","displayName":"Hausa (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1037","displayName":"Hebrew","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1081","displayName":"Hindi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1038","displayName":"Hungarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1039","displayName":"Icelandic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1136","displayName":"Igbo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1057","displayName":"Indonesian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2141","displayName":"Inuktitut (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2108","displayName":"Irish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1076","displayName":"isiXhosa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1077","displayName":"isiZulu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1040","displayName":"Italian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1041","displayName":"Japanese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1099","displayName":"Kannada","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1087","displayName":"Kazakh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1107","displayName":"Khmer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1158","displayName":"K'iche","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1159","displayName":"Kinyarwanda","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1088","displayName":"Kyrgyz","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1089","displayName":"Swahili","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1111","displayName":"Konkani","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1042","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1062","displayName":"Latvian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1063","displayName":"Lithuanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1134","displayName":"Luxembourgish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1086","displayName":"Malay (Malaysia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1100","displayName":"Malayalam","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1082","displayName":"Maltese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1153","displayName":"Maori","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1102","displayName":"Marathi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1071","displayName":"Macedonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1104","displayName":"Mongolian (Cyrillic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1121","displayName":"Nepali","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1044","displayName":"Norwegian (Bokmal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2068","displayName":"Norwegian (Nynorsk)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1096","displayName":"Odia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1065","displayName":"Persian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1045","displayName":"Polish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1046","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2070","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1094","displayName":"Punjabi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2118","displayName":"Punjabi (Pakistan)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_3179","displayName":"Quechua (Peru)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1048","displayName":"Romanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1049","displayName":"Russian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1169","displayName":"Scottish Gaelic (United Kingdom)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_3098","displayName":"Serbian (Cyrillic, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_7194","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2074","displayName":"Serbian (Latin, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1132","displayName":"Sesotho sa Leboa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1074","displayName":"Setswana","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2137","displayName":"Sindhi (Arabic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1115","displayName":"Sinhala","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1051","displayName":"Slovak","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1060","displayName":"Slovenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_3082","displayName":"Spanish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1053","displayName":"Swedish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1064","displayName":"Tajik","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1097","displayName":"Tamil","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1092","displayName":"Tatar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1098","displayName":"Telugu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1054","displayName":"Thai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1139","displayName":"Tigrinya (Ethiopia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1055","displayName":"Turkish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1090","displayName":"Turkmen","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1058","displayName":"Ukrainian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1056","displayName":"Urdu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1152","displayName":"Uyghur (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1091","displayName":"Uzbek (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2051","displayName":"Valencian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1066","displayName":"Vietnamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1106","displayName":"Welsh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1160","displayName":"Wolof","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1130","displayName":"Yoruba","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage","displayName":"Primary Editing Language (User)","description":"Defines the editing options for Office 2016 programs. In addition to configuring this setting, consider enabling the same language in the 'Enabled Editing Languages' policy node. Please refer to the Office Resource Kit documentation for important information on setting the installed version of Microsoft Office.","helpText":"","infoUrls":[],"categoryId":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","categoryName":"Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341","displayName":"Primary Editing Language (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","categoryName":"Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1078","displayName":"Afrikaans","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1052","displayName":"Albanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1156","displayName":"Alsatian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1118","displayName":"Amharic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5121","displayName":"Arabic (Algeria)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_15361","displayName":"Arabic (Bahrain)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3073","displayName":"Arabic (Egypt)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2049","displayName":"Arabic (Iraq)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_11265","displayName":"Arabic (Jordan)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_13313","displayName":"Arabic (Kuwait)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_12289","displayName":"Arabic (Lebanon)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4097","displayName":"Arabic (Libya)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_6145","displayName":"Arabic (Morocco)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_8193","displayName":"Arabic (Oman)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_16385","displayName":"Arabic (Qatar)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1025","displayName":"Arabic (Saudi Arabia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_10241","displayName":"Arabic (Syria)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_7169","displayName":"Arabic (Tunisia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_14337","displayName":"Arabic (U.A.E.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_9217","displayName":"Arabic (Yemen)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1067","displayName":"Armenian (Armenia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1101","displayName":"Assamese (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2092","displayName":"Azerbaijani (Cyrillic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1068","displayName":"Azerbaijani (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2117","displayName":"Bangla (Bangladesh)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1093","displayName":"Bangla (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1133","displayName":"Bashkir","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1069","displayName":"Basque","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1059","displayName":"Belarusian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_8218","displayName":"Bosnian (Cyrillic, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5146","displayName":"Bosnian (Latin, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1150","displayName":"Breton","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1026","displayName":"Bulgarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1109","displayName":"Burmese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1027","displayName":"Catalan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1170","displayName":"Central Kurdish (Iraq)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1116","displayName":"Cherokee","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2052","displayName":"Chinese (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3076","displayName":"Chinese (Hong Kong S.A.R.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5124","displayName":"Chinese (Macao S.A.R.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4100","displayName":"Chinese (Singapore)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1028","displayName":"Chinese (Taiwan)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1155","displayName":"Corsican","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4122","displayName":"Croatian (Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1050","displayName":"Croatian (Croatia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1029","displayName":"Czech","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1030","displayName":"Danish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1164","displayName":"Dari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1125","displayName":"Divehi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2067","displayName":"Dutch (Belgium)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1043","displayName":"Dutch (Netherlands)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1126","displayName":"Edo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3081","displayName":"English (Australia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_10249","displayName":"English (Belize)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4105","displayName":"English (Canada)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_9225","displayName":"English (Caribbean)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_15369","displayName":"English (Hong Kong S.A.R.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_16393","displayName":"English (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_14345","displayName":"English (Indonesia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_6153","displayName":"English (Ireland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_8201","displayName":"English (Jamaica)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_17417","displayName":"English (Malaysia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5129","displayName":"English (New Zealand)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_13321","displayName":"English (Philippines)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_18441","displayName":"English (Singapore)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_7177","displayName":"English (South Africa)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_11273","displayName":"English (Trinidad and Tobago)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2057","displayName":"English (U.K.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1033","displayName":"English (U.S.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_12297","displayName":"English (Zimbabwe)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1061","displayName":"Estonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1080","displayName":"Faeroese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1124","displayName":"Filipino","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1035","displayName":"Finnish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2060","displayName":"French (Belgium)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_11276","displayName":"French (Cameroon)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3084","displayName":"French (Canada)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_7180","displayName":"French (Caribbean)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_9228","displayName":"French (Congo (DRC))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_12300","displayName":"French (Côte d'Ivoire)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1036","displayName":"French (France)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_15372","displayName":"French (Haiti)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5132","displayName":"French (Luxembourg)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_13324","displayName":"French (Mali)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_6156","displayName":"French (Monaco)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_14348","displayName":"French (Morocco)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_8204","displayName":"French (Reunion)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_10252","displayName":"French (Senegal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4108","displayName":"French (Switzerland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1122","displayName":"Frisian (Netherlands)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1127","displayName":"Fulfulde","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1169","displayName":"Scottish Gaelic (United Kingdom)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1110","displayName":"Galician","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1079","displayName":"Georgian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3079","displayName":"German (Austria)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1031","displayName":"German (Germany)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5127","displayName":"German (Liechtenstein)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4103","displayName":"German (Luxembourg)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2055","displayName":"German (Switzerland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1032","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1135","displayName":"Greenlandic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1140","displayName":"Guarani","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1095","displayName":"Gujarati","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1128","displayName":"Hausa (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1141","displayName":"Hawaiian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1037","displayName":"Hebrew (Israel)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1081","displayName":"Hindi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1038","displayName":"Hungarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1129","displayName":"Ibibio","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1039","displayName":"Icelandic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1136","displayName":"Igbo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1057","displayName":"Indonesian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2141","displayName":"Inuktitut (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1117","displayName":"Inuktitut (Syllabics)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2108","displayName":"Irish (Ireland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1077","displayName":"isiZulu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1076","displayName":"isiXhosa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1040","displayName":"Italian (Italy)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2064","displayName":"Italian (Switzerland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1041","displayName":"Japanese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1099","displayName":"Kannada","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1137","displayName":"Kanuri","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1120","displayName":"Kashmiri (Arabic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2144","displayName":"Kashmiri (Devanagari)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1087","displayName":"Kazakh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1107","displayName":"Khmer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1158","displayName":"K'iche","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1159","displayName":"Kinyarwanda","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1111","displayName":"Konkani","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1042","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1088","displayName":"Kyrgyz","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1108","displayName":"Lao","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1142","displayName":"Latin","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1062","displayName":"Latvian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1063","displayName":"Lithuanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1134","displayName":"Luxembourgish (Luxembourg)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1071","displayName":"Macedonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2110","displayName":"Malay (Brunei)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1086","displayName":"Malay (Malaysia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1100","displayName":"Malayalam","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1082","displayName":"Maltese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1112","displayName":"Manipuri","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1153","displayName":"Maori","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1146","displayName":"Mapudungun","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1102","displayName":"Marathi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1148","displayName":"Mohawk","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1104","displayName":"Mongolian (Cyrillic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2128","displayName":"Mongolian (Traditional Mongolian)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2145","displayName":"Nepali (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1121","displayName":"Nepali (Nepal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1044","displayName":"Norwegian (Bokmål)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2068","displayName":"Norwegian (Nynorsk)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1154","displayName":"Occitan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1138","displayName":"Oromo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1096","displayName":"Odia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1145","displayName":"Papiamentu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1123","displayName":"Pashto","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1065","displayName":"Persian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1045","displayName":"Polish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1046","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2070","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1094","displayName":"Punjabi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2118","displayName":"Punjabi (Pakistan)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1131","displayName":"Quechua (Bolivia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2155","displayName":"Quechua (Ecuador)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3179","displayName":"Quechua (Peru)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1047","displayName":"Romansh (Switzerland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2072","displayName":"Romanian (Moldova)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1048","displayName":"Romanian (Romania)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2073","displayName":"Russian (Moldova)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1049","displayName":"Russian (Russia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_9275","displayName":"Sami, Inari (Finland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4155","displayName":"Sami, Lule (Norway)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5179","displayName":"Sami, Lule (Sweden)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3131","displayName":"Sami, Northern (Finland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1083","displayName":"Sami, Northern (Norway)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2107","displayName":"Sami, Northern (Sweden)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_8251","displayName":"Sami, Skolt (Finland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_6203","displayName":"Sami, Southern (Norway)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_7227","displayName":"Sami, Southern (Sweden)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1103","displayName":"Sanskrit","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_7194","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_6170","displayName":"Serbian (Latin, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3098","displayName":"Serbian (Cyrillic, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_10266","displayName":"Serbian (Cyrillic, Serbia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_12314","displayName":"Serbian (Cyrillic, Montenegro)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2074","displayName":"Serbian (Latin, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_11290","displayName":"Serbian (Latin, Montenegro)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_9242","displayName":"Serbian (Latin, Serbia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1072","displayName":"Sesotho","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1132","displayName":"Sesotho sa Leboa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1074","displayName":"Setswana","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1113","displayName":"Sindhi (Devanagari)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2137","displayName":"Sindhi (Arabic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1115","displayName":"Sinhala","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1051","displayName":"Slovak","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1060","displayName":"Slovenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1143","displayName":"Somali","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2094","displayName":"Lower Sorbian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1070","displayName":"Upper Sorbian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_11274","displayName":"Spanish (Argentina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_16394","displayName":"Spanish (Bolivia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_13322","displayName":"Spanish (Chile)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_9226","displayName":"Spanish (Colombia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_5130","displayName":"Spanish (Costa Rica)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_7178","displayName":"Spanish (Dominican Republic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_12298","displayName":"Spanish (Ecuador)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_17418","displayName":"Spanish (El Salvador)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_4106","displayName":"Spanish (Guatemala)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_18442","displayName":"Spanish (Honduras)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2058","displayName":"Spanish (Mexico)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_19466","displayName":"Spanish (Nicaragua)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_6154","displayName":"Spanish (Panama)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_15370","displayName":"Spanish (Paraguay)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_10250","displayName":"Spanish (Peru)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_20490","displayName":"Spanish (Puerto Rico)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_3082","displayName":"Spanish (Spain)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_21514","displayName":"Spanish (United States)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_14346","displayName":"Spanish (Uruguay)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_8202","displayName":"Spanish (Venezuela)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1089","displayName":"Swahili","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2077","displayName":"Swedish (Finland)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1053","displayName":"Swedish (Sweden)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1114","displayName":"Syriac","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2143","displayName":"Tamazight (Latin, Algeria)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1119","displayName":"Tamazight (Arabic, Morocco)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1097","displayName":"Tamil","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1092","displayName":"Tatar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1098","displayName":"Telugu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1064","displayName":"Tajik","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1054","displayName":"Thai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1105","displayName":"Tibetan (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2163","displayName":"Tigrinya (Eritrea)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1139","displayName":"Tigrinya (Ethiopia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1055","displayName":"Turkish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1090","displayName":"Turkmen","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1152","displayName":"Uyghur (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1058","displayName":"Ukrainian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1056","displayName":"Urdu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2115","displayName":"Uzbek (Cyrillic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1091","displayName":"Uzbek (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_2051","displayName":"Valencian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1075","displayName":"Venda","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1066","displayName":"Vietnamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1106","displayName":"Welsh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1160","displayName":"Wolof","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1073","displayName":"Xitsonga","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1157","displayName":"Sakha","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1144","displayName":"Yi (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1085","displayName":"Yiddish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_l_primaryeditinglanguage341_1130","displayName":"Yoruba","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_afrikaans","displayName":"Afrikaans (User)","description":"Enables the editing language Afrikaans","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_afrikaans_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_afrikaans_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_albanian","displayName":"Albanian (User)","description":"Enables the editing language Albanian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_albanian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_albanian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_alsatian","displayName":"Alsatian (User)","description":"Enables the editing language Alsatian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_alsatian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_alsatian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_amharic","displayName":"Amharic (User)","description":"Enables the editing language Amharic","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_amharic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_amharic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicalgeria","displayName":"Arabic (Algeria) (User)","description":"Enables the editing language Arabic (Algeria)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicalgeria_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicalgeria_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicbahrain","displayName":"Arabic (Bahrain) (User)","description":"Enables the editing language Arabic (Bahrain)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicbahrain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicbahrain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicegypt","displayName":"Arabic (Egypt) (User)","description":"Enables the editing language Arabic (Egypt)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicegypt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicegypt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiciraq","displayName":"Arabic (Iraq) (User)","description":"Enables the editing language Arabic (Iraq)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiciraq_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiciraq_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicjordan","displayName":"Arabic (Jordan) (User)","description":"Enables the editing language Arabic (Jordan)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicjordan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicjordan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabickuwait","displayName":"Arabic (Kuwait) (User)","description":"Enables the editing language Arabic (Kuwait)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabickuwait_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabickuwait_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclebanon","displayName":"Arabic (Lebanon) (User)","description":"Enables the editing language Arabic (Lebanon)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclebanon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclebanon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclibya","displayName":"Arabic (Libya) (User)","description":"Enables the editing language Arabic (Libya)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclibya_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclibya_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicmorocco","displayName":"Arabic (Morocco) (User)","description":"Enables the editing language Arabic (Morocco)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicmorocco_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicmorocco_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicoman","displayName":"Arabic (Oman) (User)","description":"Enables the editing language Arabic (Oman)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicoman_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicoman_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicqatar","displayName":"Arabic (Qatar) (User)","description":"Enables the editing language Arabic (Qatar)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicqatar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicqatar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicsaudiarabia","displayName":"Arabic (Saudi Arabia) (User)","description":"Enables the editing language Arabic (Saudi Arabia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicsaudiarabia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicsaudiarabia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicsyria","displayName":"Arabic (Syria) (User)","description":"Enables the editing language Arabic (Syria)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicsyria_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicsyria_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabictunisia","displayName":"Arabic (Tunisia) (User)","description":"Enables the editing language Arabic (Tunisia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabictunisia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabictunisia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicuae","displayName":"Arabic (U.A.E.) (User)","description":"Enables the editing language Arabic (U.A.E.)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicuae_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicuae_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicyemen","displayName":"Arabic (Yemen) (User)","description":"Enables the editing language Arabic (Yemen)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicyemen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicyemen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_armenianarmenia","displayName":"Armenian (Armenia) (User)","description":"Enables the editing language Armenian (Armenia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_armenianarmenia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_armenianarmenia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_assameseindia","displayName":"Assamese (India) (User)","description":"Enables the editing language Assamese (India)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_assameseindia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_assameseindia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_azerbaijanicyrillic","displayName":"Azerbaijani (Cyrillic) (User)","description":"Enables the editing language Azerbaijani (Cyrillic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_azerbaijanicyrillic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_azerbaijanicyrillic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_azerbaijanilatin","displayName":"Azerbaijani (Latin) (User)","description":"Enables the editing language Azerbaijani (Latin)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_azerbaijanilatin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_azerbaijanilatin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglabangladesh","displayName":"Bangla (Bangladesh) (User)","description":"Enables the editing language Bangla (Bangladesh)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglabangladesh_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglabangladesh_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglaindia","displayName":"Bangla (India) (User)","description":"Enables the editing language Bangla (India)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglaindia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglaindia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bashkir","displayName":"Bashkir (User)","description":"Enables the editing language Bashkir","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bashkir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bashkir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_basque","displayName":"Basque (User)","description":"Enables the editing language Basque","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_basque_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_basque_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_belarusian","displayName":"Belarusian (User)","description":"Enables the editing language Belarusian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_belarusian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_belarusian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosniancyrillicbosniaandherzegovina","displayName":"Bosnian (Cyrillic, Bosnia and Herzegovina) (User)","description":"Enables the editing language \"Bosnian (Cyrillic, Bosnia and Herzegovina)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosniancyrillicbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosniancyrillicbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosnianlatinbosniaandherzegovina","displayName":"Bosnian (Latin, Bosnia and Herzegovina) (User)","description":"Enables the editing language \"Bosnian (Latin, Bosnia and Herzegovina)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosnianlatinbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosnianlatinbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_breton","displayName":"Breton (User)","description":"Enables the editing language Breton","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_breton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_breton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bulgarian","displayName":"Bulgarian (User)","description":"Enables the editing language Bulgarian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bulgarian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bulgarian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_burmese","displayName":"Burmese (User)","description":"Enables the editing language Burmese","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_burmese_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_burmese_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_catalan","displayName":"Catalan (User)","description":"Enables the editing language Catalan","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_catalan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_catalan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_centralkurdishiraq","displayName":"Central Kurdish (Iraq) (User)","description":"Enables the editing language Central Kurdish (Iraq)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_centralkurdishiraq_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_centralkurdishiraq_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_cherokee","displayName":"Cherokee (User)","description":"Enables the editing language Cherokee","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_cherokee_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_cherokee_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesehongkongsar","displayName":"Chinese (Hong Kong S.A.R.) (User)","description":"Enables the editing language Chinese (Hong Kong S.A.R.)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesehongkongsar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesehongkongsar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesemacaosar","displayName":"Chinese (Macao S.A.R.) (User)","description":"Enables the editing language Chinese (Macao S.A.R.)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesemacaosar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesemacaosar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chineseprc","displayName":"Chinese (PRC) (User)","description":"Enables the editing language Chinese (PRC)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chineseprc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chineseprc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesesingapore","displayName":"Chinese (Singapore) (User)","description":"Enables the editing language Chinese (Singapore)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesesingapore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesesingapore_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesetaiwan","displayName":"Chinese (Taiwan) (User)","description":"Enables the editing language Chinese (Taiwan)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesetaiwan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_chinesetaiwan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_corsican","displayName":"Corsican (User)","description":"Enables the editing language Corsican","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_corsican_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_corsican_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatianbosniaandherzegovina","displayName":"Croatian (Bosnia and Herzegovina) (User)","description":"Enables the editing language Croatian (Bosnia and Herzegovina)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatianbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatianbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatiancroatia","displayName":"Croatian (Croatia) (User)","description":"Enables the editing language Croatian (Croatia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatiancroatia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatiancroatia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_czech","displayName":"Czech (User)","description":"Enables the editing language Czech","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_czech_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_czech_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_danish","displayName":"Danish (User)","description":"Enables the editing language Danish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_danish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_danish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dari","displayName":"Dari (User)","description":"Enables the editing language Dari","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dari_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dari_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_divehi","displayName":"Divehi (User)","description":"Enables the editing language Divehi","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_divehi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_divehi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dutchbelgium","displayName":"Dutch (Belgium) (User)","description":"Enables the editing language Dutch (Belgium)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dutchbelgium_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dutchbelgium_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dutchnetherlands","displayName":"Dutch (Netherlands) (User)","description":"Enables the editing language Dutch (Netherlands)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dutchnetherlands_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dutchnetherlands_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_edo","displayName":"Edo (User)","description":"Enables the editing language Edo","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_edo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_edo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishaustralia","displayName":"English (Australia) (User)","description":"Enables the editing language English (Australia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishaustralia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishaustralia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishbelize","displayName":"English (Belize) (User)","description":"Enables the editing language English (Belize)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishbelize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishbelize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcanada","displayName":"English (Canada) (User)","description":"Enables the editing language English (Canada)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcanada_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcanada_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcaribbean","displayName":"English (Caribbean) (User)","description":"Enables the editing language English (Caribbean)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcaribbean_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcaribbean_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishhongkongsar","displayName":"English (Hong Kong S.A.R.) (User)","description":"Enables the editing language English (Hong Kong S.A.R.)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishhongkongsar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishhongkongsar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishindia","displayName":"English (India) (User)","description":"Enables the editing language English (India)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishindia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishindia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishindonesia","displayName":"English (Indonesia) (User)","description":"Enables the editing language English (Indonesia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishindonesia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishindonesia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishireland","displayName":"English (Ireland) (User)","description":"Enables the editing language English (Ireland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishireland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishireland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishjamaica","displayName":"English (Jamaica) (User)","description":"Enables the editing language English (Jamaica)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishjamaica_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishjamaica_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishmalaysia","displayName":"English (Malaysia) (User)","description":"Enables the editing language English (Malaysia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishmalaysia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishmalaysia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishnewzealand","displayName":"English (New Zealand) (User)","description":"Enables the editing language English (New Zealand)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishnewzealand_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishnewzealand_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishphilippines","displayName":"English (Philippines) (User)","description":"Enables the editing language English (Philippines)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishphilippines_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishphilippines_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishsingapore","displayName":"English (Singapore) (User)","description":"Enables the editing language English (Singapore)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishsingapore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishsingapore_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishsouthafrica","displayName":"English (South Africa) (User)","description":"Enables the editing language English (South Africa)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishsouthafrica_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishsouthafrica_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishtrinidadandtobago","displayName":"English (Trinidad and Tobago) (User)","description":"Enables the editing language English (Trinidad and Tobago)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishtrinidadandtobago_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishtrinidadandtobago_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishuk","displayName":"English (U.K.) (User)","description":"Enables the editing language English (U.K.)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishuk_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishuk_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishus","displayName":"English (U.S.) (User)","description":"Enables the editing language English (U.S.)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishus_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishus_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishzimbabwe","displayName":"English (Zimbabwe) (User)","description":"Enables the editing language English (Zimbabwe)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishzimbabwe_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishzimbabwe_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_estonian","displayName":"Estonian (User)","description":"Enables the editing language Estonian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_estonian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_estonian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_faeroese","displayName":"Faeroese (User)","description":"Enables the editing language Faeroese","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_faeroese_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_faeroese_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_filipino","displayName":"Filipino (User)","description":"Enables the editing language Filipino","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_filipino_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_filipino_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_finnish","displayName":"Finnish (User)","description":"Enables the editing language Finnish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_finnish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_finnish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchbelgium","displayName":"French (Belgium) (User)","description":"Enables the editing language French (Belgium)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchbelgium_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchbelgium_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcameroon","displayName":"French (Cameroon) (User)","description":"Enables the editing language French (Cameroon)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcameroon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcameroon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcanada","displayName":"French (Canada) (User)","description":"Enables the editing language French (Canada)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcanada_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcanada_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcaribbean","displayName":"French (Caribbean) (User)","description":"Enables the editing language French (Caribbean)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcaribbean_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcaribbean_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcongodrc","displayName":"French (Congo (DRC)) (User)","description":"Enables the editing language French (Congo (DRC))","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcongodrc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcongodrc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcotedivoire","displayName":"French (Côte d'Ivoire) (User)","description":"Enables the editing language French (Côte d'Ivoire)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcotedivoire_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcotedivoire_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchfrance","displayName":"French (France) (User)","description":"Enables the editing language French (France)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchfrance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchfrance_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchhaiti","displayName":"French (Haiti) (User)","description":"Enables the editing language French (Haiti)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchhaiti_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchhaiti_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchluxembourg","displayName":"French (Luxembourg) (User)","description":"Enables the editing language French (Luxembourg)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchluxembourg_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchluxembourg_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmali","displayName":"French (Mali) (User)","description":"Enables the editing language French (Mali)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmali_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmali_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmonaco","displayName":"French (Monaco) (User)","description":"Enables the editing language French (Monaco)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmonaco_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmonaco_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmorocco","displayName":"French (Morocco) (User)","description":"Enables the editing language French (Morocco)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmorocco_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmorocco_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchreunion","displayName":"French (Reunion) (User)","description":"Enables the editing language French (Reunion)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchreunion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchreunion_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchsenegal","displayName":"French (Senegal) (User)","description":"Enables the editing language French (Senegal)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchsenegal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchsenegal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchswitzerland","displayName":"French (Switzerland) (User)","description":"Enables the editing language French (Switzerland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchswitzerland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchswitzerland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frisiannetherlands","displayName":"Frisian (Netherlands) (User)","description":"Enables the editing language Frisian (Netherlands)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frisiannetherlands_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frisiannetherlands_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_fulfulde","displayName":"Fulfulde (User)","description":"Enables the editing language Fulfulde","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_fulfulde_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_fulfulde_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_galician","displayName":"Galician (User)","description":"Enables the editing language Galician","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_galician_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_galician_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_georgian","displayName":"Georgian (User)","description":"Enables the editing language Georgian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_georgian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_georgian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanaustria","displayName":"German (Austria) (User)","description":"Enables the editing language German (Austria)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanaustria_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanaustria_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germangermany","displayName":"German (Germany) (User)","description":"Enables the editing language German (Germany)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germangermany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germangermany_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanliechtenstein","displayName":"German (Liechtenstein) (User)","description":"Enables the editing language German (Liechtenstein)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanliechtenstein_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanliechtenstein_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanluxembourg","displayName":"German (Luxembourg) (User)","description":"Enables the editing language German (Luxembourg)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanluxembourg_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanluxembourg_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanswitzerland","displayName":"German (Switzerland) (User)","description":"Enables the editing language German (Switzerland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanswitzerland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanswitzerland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greek","displayName":"Greek (User)","description":"Enables the editing language Greek","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greek_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greek_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greenlandic","displayName":"Greenlandic (User)","description":"Enables the editing language Greenlandic","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greenlandic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greenlandic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_guarani","displayName":"Guarani (User)","description":"Enables the editing language Guarani","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_guarani_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_guarani_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_gujarati","displayName":"Gujarati (User)","description":"Enables the editing language Gujarati","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_gujarati_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_gujarati_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hausa","displayName":"Hausa (Latin) (User)","description":"Enables the editing language Hausa (Latin)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hausa_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hausa_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hawaiian","displayName":"Hawaiian (User)","description":"Enables the editing language Hawaiian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hawaiian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hawaiian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hebrewisrael","displayName":"Hebrew (Israel) (User)","description":"Enables the editing language Hebrew (Israel)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hebrewisrael_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hebrewisrael_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hindi","displayName":"Hindi (User)","description":"Enables the editing language Hindi","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hindi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hindi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hungarian","displayName":"Hungarian (User)","description":"Enables the editing language Hungarian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hungarian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hungarian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_ibibio","displayName":"Ibibio (User)","description":"Enables the editing language Ibibio","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_ibibio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_ibibio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_icelandic","displayName":"Icelandic (User)","description":"Enables the editing language Icelandic","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_icelandic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_icelandic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_igbo","displayName":"Igbo (User)","description":"Enables the editing language Igbo","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_igbo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_igbo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_indonesian","displayName":"Indonesian (User)","description":"Enables the editing language Indonesian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_indonesian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_indonesian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutlatin","displayName":"Inuktitut (Latin) (User)","description":"Enables the editing language Inuktitut (Latin)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutlatin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutlatin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutsyllabics","displayName":"Inuktitut (Syllabics) (User)","description":"Enables the editing language Inuktitut (Syllabics)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutsyllabics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutsyllabics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_irishireland","displayName":"Irish (Ireland) (User)","description":"Enables the editing language Irish (Ireland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_irishireland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_irishireland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isixhosa","displayName":"isiXhosa (User)","description":"Enables the editing language isiXhosa","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isixhosa_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isixhosa_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isizulu","displayName":"isiZulu (User)","description":"Enables the editing language isiZulu","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isizulu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isizulu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianitaly","displayName":"Italian (Italy) (User)","description":"Enables the editing language Italian (Italy)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianitaly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianitaly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianswitzerland","displayName":"Italian (Switzerland) (User)","description":"Enables the editing language Italian (Switzerland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianswitzerland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianswitzerland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_japanese","displayName":"Japanese (User)","description":"Enables the editing language Japanese","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_japanese_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_japanese_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kannada","displayName":"Kannada (User)","description":"Enables the editing language Kannada","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kannada_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kannada_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kanuri","displayName":"Kanuri (User)","description":"Enables the editing language Kanuri","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kanuri_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kanuri_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiriarabic","displayName":"Kashmiri (Arabic) (User)","description":"Enables the editing language Kashmiri (Arabic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiriarabic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiriarabic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiridevanagari","displayName":"Kashmiri (Devanagari) (User)","description":"Enables the editing language Kashmiri (Devanagari)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiridevanagari_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiridevanagari_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kazakh","displayName":"Kazakh (User)","description":"Enables the editing language Kazakh","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kazakh_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kazakh_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_khmer","displayName":"Khmer (User)","description":"Enables the editing language Khmer","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_khmer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_khmer_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kiche","displayName":"K'iche (User)","description":"Enables the editing language K'iche","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kiche_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kiche_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kinyarwanda","displayName":"Kinyarwanda (User)","description":"Enables the editing language Kinyarwanda","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kinyarwanda_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kinyarwanda_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_konkani","displayName":"Konkani (User)","description":"Enables the editing language Konkani","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_konkani_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_konkani_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_korean","displayName":"Korean (User)","description":"Enables the editing language Korean","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_korean_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_korean_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kyrgyz","displayName":"Kyrgyz (User)","description":"Enables the editing language Kyrgyz","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kyrgyz_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kyrgyz_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lao","displayName":"Lao (User)","description":"Enables the editing language Lao","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lao_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lao_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latin","displayName":"Latin (User)","description":"Enables the editing language Latin","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latvian","displayName":"Latvian (User)","description":"Enables the editing language Latvian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latvian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latvian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lithuanian","displayName":"Lithuanian (User)","description":"Enables the editing language Lithuanian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lithuanian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lithuanian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lowersorbian","displayName":"Lower Sorbian (User)","description":"Enables the editing language Lower Sorbian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lowersorbian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lowersorbian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_luxembourgishluxembourg","displayName":"Luxembourgish (Luxembourg) (User)","description":"Enables the editing language Luxembourgish (Luxembourg)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_luxembourgishluxembourg_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_luxembourgishluxembourg_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_macedonian","displayName":"Macedonian (User)","description":"Enables the editing language Macedonian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_macedonian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_macedonian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malayalam","displayName":"Malayalam (User)","description":"Enables the editing language Malayalam","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malayalam_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malayalam_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malaybrunei","displayName":"Malay (Brunei) (User)","description":"Enables the editing language Malay (Brunei)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malaybrunei_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malaybrunei_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malaymalaysia","displayName":"Malay (Malaysia) (User)","description":"Enables the editing language Malay (Malaysia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malaymalaysia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_malaymalaysia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_maltese","displayName":"Maltese (User)","description":"Enables the editing language Maltese","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_maltese_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_maltese_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_manipuri","displayName":"Manipuri (User)","description":"Enables the editing language Manipuri","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_manipuri_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_manipuri_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_maori","displayName":"Maori (User)","description":"Enables the editing language Maori","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_maori_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_maori_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mapudungun","displayName":"Mapudungun (User)","description":"Enables the editing language Mapudungun","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mapudungun_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mapudungun_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_marathi","displayName":"Marathi (User)","description":"Enables the editing language Marathi","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_marathi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_marathi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mohawk","displayName":"Mohawk (User)","description":"Enables the editing language Mohawk","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mohawk_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mohawk_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliancyrillic","displayName":"Mongolian (Cyrillic) (User)","description":"Enables the editing language Mongolian (Cyrillic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliancyrillic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliancyrillic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliantraditionalmongolian","displayName":"Mongolian (Traditional Mongolian) (User)","description":"Enables the editing language Mongolian (Traditional Mongolian)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliantraditionalmongolian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliantraditionalmongolian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepaliindia","displayName":"Nepali (India) (User)","description":"Enables the editing language Nepali (India)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepaliindia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepaliindia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepalinepal","displayName":"Nepali (Nepal) (User)","description":"Enables the editing language Nepali (Nepal)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepalinepal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepalinepal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_norwegianbokml","displayName":"Norwegian (Bokmål) (User)","description":"Enables the editing language Norwegian (Bokm†l)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_norwegianbokml_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_norwegianbokml_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_norwegiannynorsk","displayName":"Norwegian (Nynorsk) (User)","description":"Enables the editing language Norwegian (Nynorsk)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_norwegiannynorsk_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_norwegiannynorsk_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_occitan","displayName":"Occitan (User)","description":"Enables the editing language Occitan","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_occitan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_occitan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_odia","displayName":"Odia (User)","description":"Enables the editing language Odia","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_odia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_odia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_oromo","displayName":"Oromo (User)","description":"Enables the editing language Oromo","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_oromo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_oromo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_papiamentu","displayName":"Papiamentu (User)","description":"Enables the editing language Papiamentu","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_papiamentu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_papiamentu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_pashto","displayName":"Pashto (User)","description":"Enables the editing language Pashto","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_pashto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_pashto_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_persian","displayName":"Persian (User)","description":"Enables the editing language Persian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_persian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_persian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_polish","displayName":"Polish (User)","description":"Enables the editing language Polish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_polish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_polish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portuguesebrazil","displayName":"Portuguese (Brazil) (User)","description":"Enables the editing language Portuguese (Brazil)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portuguesebrazil_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portuguesebrazil_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portugueseportugal","displayName":"Portuguese (Portugal) (User)","description":"Enables the editing language Portuguese (Portugal)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portugueseportugal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portugueseportugal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabi","displayName":"Punjabi (User)","description":"Enables the editing language Punjabi","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabipakistan","displayName":"Punjabi (Pakistan) (User)","description":"Enables the editing language Punjabi (Pakistan)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabipakistan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabipakistan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuabolivia","displayName":"Quechua (Bolivia) (User)","description":"Enables the editing language Quechua (Bolivia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuabolivia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuabolivia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaecuador","displayName":"Quechua (Ecuador) (User)","description":"Enables the editing language Quechua (Ecuador)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaecuador_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaecuador_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaperu","displayName":"Quechua (Peru) (User)","description":"Enables the editing language Quechua (Peru)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaperu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaperu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanianmoldova","displayName":"Romanian (Moldova) (User)","description":"Enables the editing language Romanian (Moldova)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanianmoldova_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanianmoldova_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanianromania","displayName":"Romanian (Romania) (User)","description":"Enables the editing language Romanian (Romania)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanianromania_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanianromania_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanshswitzerland","displayName":"Romansh (Switzerland) (User)","description":"Enables the editing language Romansh (Switzerland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanshswitzerland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_romanshswitzerland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_russianmoldova","displayName":"Russian (Moldova) (User)","description":"Enables the editing language Russian (Moldova)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_russianmoldova_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_russianmoldova_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_russianrussia","displayName":"Russian (Russia) (User)","description":"Enables the editing language Russian (Russia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_russianrussia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_russianrussia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sakha","displayName":"Sakha (User)","description":"Enables the editing language Sakha","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sakha_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sakha_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiinarifinland","displayName":"Sami, Inari (Finland) (User)","description":"Enables the editing language \"Sami, Inari (Finland)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiinarifinland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiinarifinland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samilulenorway","displayName":"Sami, Lule (Norway) (User)","description":"Enables the editing language \"Sami, Lule (Norway)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samilulenorway_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samilulenorway_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samilulesweden","displayName":"Sami, Lule (Sweden) (User)","description":"Enables the editing language \"Sami, Lule (Sweden)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samilulesweden_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samilulesweden_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernfinland","displayName":"Sami, Northern (Finland) (User)","description":"Enables the editing language \"Sami, Northern (Finland)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernfinland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernfinland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernnorway","displayName":"Sami, Northern (Norway) (User)","description":"Enables the editing language \"Sami, Northern (Norway)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernnorway_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernnorway_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernsweden","displayName":"Sami, Northern (Sweden) (User)","description":"Enables the editing language \"Sami, Northern (Sweden)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernsweden_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernsweden_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiskoltfinland","displayName":"Sami, Skolt (Finland) (User)","description":"Enables the editing language \"Sami, Skolt (Finland)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiskoltfinland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiskoltfinland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samisouthernnorway","displayName":"Sami, Southern (Norway) (User)","description":"Enables the editing language \"Sami, Southern (Norway)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samisouthernnorway_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samisouthernnorway_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samisouthernsweden","displayName":"Sami, Southern (Sweden) (User)","description":"Enables the editing language \"Sami, Southern (Sweden)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samisouthernsweden_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samisouthernsweden_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sanskrit","displayName":"Sanskrit (User)","description":"Enables the editing language Sanskrit","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sanskrit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sanskrit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_scottishgaelicunitedkingdom","displayName":"Scottish Gaelic (United Kingdom) (User)","description":"Enables the editing language Scottish Gaelic (United Kingdom)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_scottishgaelicunitedkingdom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_scottishgaelicunitedkingdom_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicbosniaandherzegovina","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina) (User)","description":"Enables the editing language \"Serbian (Cyrillic, Bosnia and Herzegovina)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicmontenegro","displayName":"Serbian (Cyrillic, Montenegro) (User)","description":"Enables the editing language \"Serbian (Cyrillic, Montenegro)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicmontenegro_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicmontenegro_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicserbia","displayName":"Serbian (Cyrillic, Serbia) (User)","description":"Enables the editing language \"Serbian (Cyrillic, Serbia)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicserbia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicserbia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicserbiaandmontenegro","displayName":"Serbian (Cyrillic, Serbia and Montenegro (Former)) (User)","description":"Enables the editing language \"Serbian (Cyrillic, Serbia and Montenegro (Former))\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicserbiaandmontenegro_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicserbiaandmontenegro_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinbosniaandherzegovina","displayName":"Serbian (Latin, Bosnia and Herzegovina) (User)","description":"Enables the editing language \"Serbian (Latin, Bosnia and Herzegovina)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinmontenegro","displayName":"Serbian (Latin, Montenegro) (User)","description":"Enables the editing language \"Serbian (Latin, Montenegro)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinmontenegro_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinmontenegro_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinserbia","displayName":"Serbian (Latin, Serbia) (User)","description":"Enables the editing language \"Serbian (Latin, Serbia)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinserbia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinserbia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinserbiaandmontenegro","displayName":"Serbian (Latin, Serbia and Montenegro (Former)) (User)","description":"Enables the editing language \"Serbian (Latin, Serbia and Montenegro (Former))\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinserbiaandmontenegro_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbianlatinserbiaandmontenegro_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sesotho","displayName":"Sesotho (User)","description":"Enables the editing language Sesotho","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sesotho_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sesotho_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sesothosaleboa","displayName":"Sesotho sa Leboa (User)","description":"Enables the editing language Sesotho sa Leboa","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sesothosaleboa_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sesothosaleboa_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_setswana","displayName":"Setswana (User)","description":"Enables the editing language Setswana","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_setswana_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_setswana_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhiarabic","displayName":"Sindhi (Arabic) (User)","description":"Enables the editing language Sindhi (Arabic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhiarabic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhiarabic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhidevanagari","displayName":"Sindhi (Devanagari) (User)","description":"Enables the editing language Sindhi (Devanagari)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhidevanagari_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhidevanagari_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sinhala","displayName":"Sinhala (User)","description":"Enables the editing language Sinhala","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sinhala_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sinhala_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_slovak","displayName":"Slovak (User)","description":"Enables the editing language Slovak","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_slovak_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_slovak_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_slovenian","displayName":"Slovenian (User)","description":"Enables the editing language Slovenian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_slovenian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_slovenian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_somali","displayName":"Somali (User)","description":"Enables the editing language Somali","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_somali_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_somali_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishargentina","displayName":"Spanish (Argentina) (User)","description":"Enables the editing language Spanish (Argentina)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishargentina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishargentina_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishbolivia","displayName":"Spanish (Bolivia) (User)","description":"Enables the editing language Spanish (Bolivia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishbolivia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishbolivia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishchile","displayName":"Spanish (Chile) (User)","description":"Enables the editing language Spanish (Chile)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishchile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishchile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishcolombia","displayName":"Spanish (Colombia) (User)","description":"Enables the editing language Spanish (Colombia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishcolombia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishcolombia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishcostarica","displayName":"Spanish (Costa Rica) (User)","description":"Enables the editing language Spanish (Costa Rica)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishcostarica_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishcostarica_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishdominicanrepublic","displayName":"Spanish (Dominican Republic) (User)","description":"Enables the editing language Spanish (Dominican Republic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishdominicanrepublic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishdominicanrepublic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishecuador","displayName":"Spanish (Ecuador) (User)","description":"Enables the editing language Spanish (Ecuador)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishecuador_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishecuador_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishelsalvador","displayName":"Spanish (El Salvador) (User)","description":"Enables the editing language Spanish (El Salvador)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishelsalvador_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishelsalvador_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishguatemala","displayName":"Spanish (Guatemala) (User)","description":"Enables the editing language Spanish (Guatemala)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishguatemala_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishguatemala_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishhonduras","displayName":"Spanish (Honduras) (User)","description":"Enables the editing language Spanish (Honduras)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishhonduras_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishhonduras_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishmexico","displayName":"Spanish (Mexico) (User)","description":"Enables the editing language Spanish (Mexico)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishmexico_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishmexico_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishnicaragua","displayName":"Spanish (Nicaragua) (User)","description":"Enables the editing language Spanish (Nicaragua)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishnicaragua_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishnicaragua_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpanama","displayName":"Spanish (Panama) (User)","description":"Enables the editing language Spanish (Panama)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpanama_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpanama_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishparaguay","displayName":"Spanish (Paraguay) (User)","description":"Enables the editing language Spanish (Paraguay)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishparaguay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishparaguay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishperu","displayName":"Spanish (Peru) (User)","description":"Enables the editing language Spanish (Peru)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishperu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishperu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpuertorico","displayName":"Spanish (Puerto Rico) (User)","description":"Enables the editing language Spanish (Puerto Rico)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpuertorico_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpuertorico_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishspain","displayName":"Spanish (Spain) (User)","description":"Enables the editing language Spanish (Spain)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishspain_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishspain_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishunitedstates","displayName":"Spanish (United States) (User)","description":"Enables the editing language Spanish (United States)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishunitedstates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishunitedstates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishuruguay","displayName":"Spanish (Uruguay) (User)","description":"Enables the editing language Spanish (Uruguay)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishuruguay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishuruguay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishvenezuela","displayName":"Spanish (Venezuela) (User)","description":"Enables the editing language Spanish (Venezuela)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishvenezuela_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishvenezuela_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swahili","displayName":"Swahili (User)","description":"Enables the editing language Swahili","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swahili_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swahili_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swedishfinland","displayName":"Swedish (Finland) (User)","description":"Enables the editing language Swedish (Finland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swedishfinland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swedishfinland_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swedishsweden","displayName":"Swedish (Sweden) (User)","description":"Enables the editing language Swedish (Sweden)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swedishsweden_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_swedishsweden_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_syriac","displayName":"Syriac (User)","description":"Enables the editing language Syriac","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_syriac_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_syriac_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tajik","displayName":"Tajik (User)","description":"Enables the editing language Tajik","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tajik_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tajik_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightarabicmorocco","displayName":"Tamazight (Arabic, Morocco) (User)","description":"Enables the editing language \"Tamazight (Arabic, Morocco)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightarabicmorocco_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightarabicmorocco_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightlatinalgeria","displayName":"Tamazight (Latin, Algeria) (User)","description":"Enables the editing language \"Tamazight (Latin, Algeria)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightlatinalgeria_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightlatinalgeria_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamil","displayName":"Tamil (User)","description":"Enables the editing language Tamil","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamil_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamil_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tatar","displayName":"Tatar (User)","description":"Enables the editing language Tatar","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tatar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tatar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_telugu","displayName":"Telugu (User)","description":"Enables the editing language Telugu","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_telugu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_telugu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_thai","displayName":"Thai (User)","description":"Enables the editing language Thai","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_thai_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_thai_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tibetanprc","displayName":"Tibetan (PRC) (User)","description":"Enables the editing language Tibetan (PRC)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tibetanprc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tibetanprc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaeritrea","displayName":"Tigrinya (Eritrea) (User)","description":"Enables the editing language Tigrinya (Eritrea)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaeritrea_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaeritrea_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaethiopia","displayName":"Tigrinya (Ethiopia) (User)","description":"Enables the editing language Tigrinya (Ethiopia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaethiopia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaethiopia_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkish","displayName":"Turkish (User)","description":"Enables the editing language Turkish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkmen","displayName":"Turkmen (User)","description":"Enables the editing language Turkmen","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkmen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkmen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_ukrainian","displayName":"Ukrainian (User)","description":"Enables the editing language Ukrainian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_ukrainian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_ukrainian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uppersorbian","displayName":"Upper Sorbian (User)","description":"Enables the editing language Upper Sorbian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uppersorbian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uppersorbian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_urdu","displayName":"Urdu (User)","description":"Enables the editing language Urdu","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_urdu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_urdu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uyghurprc","displayName":"Uyghur (PRC) (User)","description":"Enables the editing language Uyghur (PRC)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uyghurprc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uyghurprc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbekcyrillic","displayName":"Uzbek (Cyrillic) (User)","description":"Enables the editing language Uzbek (Cyrillic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbekcyrillic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbekcyrillic_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbeklatin","displayName":"Uzbek (Latin) (User)","description":"Enables the editing language Uzbek (Latin)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbeklatin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbeklatin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_valencian","displayName":"Valencian (User)","description":"Enables the editing language Valencian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_valencian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_valencian_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_venda","displayName":"Venda (User)","description":"Enables the editing language Venda","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_venda_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_venda_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_vietnamese","displayName":"Vietnamese (User)","description":"Enables the editing language Vietnamese","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_vietnamese_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_vietnamese_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_welsh","displayName":"Welsh (User)","description":"Enables the editing language Welsh","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_welsh_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_welsh_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_wolof","displayName":"Wolof (User)","description":"Enables the editing language Wolof","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_wolof_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_wolof_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_xitsonga","displayName":"Xitsonga (User)","description":"Enables the editing language Xitsonga","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_xitsonga_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_xitsonga_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yiddish","displayName":"Yiddish (User)","description":"Enables the editing language Yiddish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yiddish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yiddish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yiprc","displayName":"Yi (PRC) (User)","description":"Enables the editing language Yi (PRC)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yiprc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yiprc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yoruba","displayName":"Yoruba (User)","description":"Enables the editing language Yoruba","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yoruba_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_yoruba_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_other_l_disablecomingsoon","displayName":"Turn off Coming Soon (User)","description":"\r\n This policy setting controls whether Coming Soon is available to users. Coming Soon provides information in an Office app, such as Word or Excel, about upcoming feature changes to that app and lets users try out those changes ahead of time. By default, Coming Soon is available to users.\r\n\r\n If you enable this policy setting, Coming Soon is turned off and isn't available to users.\r\n\r\n If you disable or don't configure this policy setting, Coming Soon is available to users.\r\n ","helpText":"","infoUrls":[],"categoryId":"e0dfe97e-348d-4d30-a6a1-e0de1989236e","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_other_l_disablecomingsoon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_other_l_disablecomingsoon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion","displayName":"Active Directory timeout for querying one entry for group expansion (User)","description":"Specifies the timeout value for querying one Active Directory entry for group expansion.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion_l_entertimeoutinseconds","displayName":"Enter timeout in seconds: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl","displayName":"Additional permissions request URL (User)","description":"Specifies a location where a user can obtain more information about getting access to IRM content.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_l_checktospecifyacustomurloremailaddress","displayName":"Check to specify a custom URL or e-mail address (User)","description":"","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_l_checktospecifyacustomurloremailaddress_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_l_checktospecifyacustomurloremailaddress_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_l_specifyurlemailaddress","displayName":"Specify URL/Email address: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_allowuserswithearlierversionsofofficetoreadwithbrowsers","displayName":"Allow users with earlier versions of Office to read with browsers... (User)","description":"This policy setting will allow users with earlier versions of Office to read documents with browsers supporting Information Rights Management.\r\n\r\nIf you enable this policy setting, users with earlier versions of Office can read documents with browsers supporting Information Rights Management. Note that this will make all documents with restricted permissions larger.\r\n\r\nIf you disable or do not configure this policy setting, users with earlier versions of Office cannot read documents with browsers supporting Information Rights Management.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_allowuserswithearlierversionsofofficetoreadwithbrowsers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_allowuserswithearlierversionsofofficetoreadwithbrowsers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_alwaysexpandgroupsinofficewhenrestrictingpermissionfordocume","displayName":"Always expand groups in Office when restricting permission for documents (User)","description":"This policy setting controls whether group names automatically expand to display all the members of the group when selected in the Permissions dialog box. \r\n\r\nIf you enable this policy setting, when users select a group name while applying Information Rights Management (IRM) permissions to Excel workbooks, InfoPath templates, Outlook e-mail messages, PowerPoint presentations, or Word documents in the Permissions dialog box, it will automatically expand to display all the members of the group. \r\n\r\nIf you disable or do not configure this policy setting, when users select a group name in the Permissions dialog box, the members of the group are not displayed.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_alwaysexpandgroupsinofficewhenrestrictingpermissionfordocume_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_alwaysexpandgroupsinofficewhenrestrictingpermissionfordocume_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_alwaysrequireuserstoconnecttoverifypermission","displayName":"Always require users to connect to verify permission (User)","description":"This policy setting controls whether users are required to connect to the Internet or a local network to have their licenses confirmed every time they attempt to open Excel workbooks, InfoPath forms or templates, Outlook e-mail messages, PowerPoint presentations, or Word documents that are protected by Information Rights Management (IRM). This policy is useful if you want to log the usage of files with restricted permissions on the server.\r\n\r\nIf you enable this policy setting, users are required to connect to verify permissions. This policy setting will only affect protected files created on machines where the policy is enabled.\r\n\r\nIf you disable or do not configure this policy setting, users are not required to connect to the network to verify permissions.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_alwaysrequireuserstoconnecttoverifypermission_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_alwaysrequireuserstoconnecttoverifypermission_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_disableinformationrightsmanagementuserinterface","displayName":"Turn off Information Rights Management user interface (User)","description":"This policy setting controls Information Rights Management (IRM).\r\n\r\nIf you enable this policy setting, IRM will be turned off for users.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to use IRM.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_disableinformationrightsmanagementuserinterface_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_disableinformationrightsmanagementuserinterface_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_neverallowuserstospecifygroupswhenrestrictingpermissionfordo","displayName":"Never allow users to specify groups when restricting permission for documents (User)","description":"This policy setting controls whether Office 2016 users can assign permissions to distribution lists when using Information Rights Management. \r\n\r\nIf you enable this policy setting, Office 2016 users cannot specify a distribution list as an authorized party in the Permission dialog box. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 users can specify distribution lists when using Information Rights Management (IRM) to restrict access to Excel workbooks, InfoPath templates, Outlook e-mail messages, PowerPoint presentations, or Word documents.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_neverallowuserstospecifygroupswhenrestrictingpermissionfordo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_neverallowuserstospecifygroupswhenrestrictingpermissionfordo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_preventusersfromchangingpermissions","displayName":"Prevent users from changing permissions on rights managed content (User)","description":"This policy setting controls whether Office 2016 users can change permissions for content that is protected with Information Rights Management (IRM). \r\n\r\nThe Information Rights Management feature of Office 2016 allows individuals and administrators to specify access permissions to Word documents, Excel workbooks, PowerPoint presentations, InfoPath templates and forms, and Outlook e-mail messages. This functionality helps prevent sensitive information from being printed, forwarded, or copied by unauthorized people. \r\n\r\nIf you enable this policy setting, users can open and edit documents for which they have the appropriate permissions, but they cannot create new rights-managed content, add IRM to existing documents, change existing IRM permissions, or remove IRM from documents. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 users can add, remove, or change IRM permissions for documents if they are authorized to do so.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_preventusersfromchangingpermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_preventusersfromchangingpermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_specifydefaultpermissionserver","displayName":"Specify Permission Policy Default Server for Quick Access Toolbar (User)","description":"This policy setting specifies the RMS server Office uses by default.\r\n\r\nIf you enable this policy setting, Office uses the server you specify as the default RMS server.\r\n\r\nIf you disable or do not configure this policy setting, Office chooses the default RMS server.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_specifydefaultpermissionserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_specifydefaultpermissionserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_specifydefaultpermissionserver_l_empty407","displayName":"\r\nEnter Permission Policy Default Server for Quick Access Toolbar\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_urlforlocationofdocumenttemplatespolicy","displayName":"URL for location of document templates displayed when applications do not recognize rights-managed documents (User)","description":"Provide the path to a folder with document, spreadsheet, and presentation files to be used as templates for a unencrypted wrapper for files with rights-managed content received by users with older versions of Office. Office includes plain-text wrapper documents that notify users about a rights-managed document in certain circumstances. If the user's application cannot recognize a document that includes rights-management, the user receives the wrapper document with information such as instructions for downloading a Rights Management Add-on for Windows Internet Explorer. You can provide a folder with customized templates for Office to use for these plain-text wrappers by using this setting to specify a URL to a folder.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_urlforlocationofdocumenttemplatespolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_urlforlocationofdocumenttemplatespolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_urlforlocationofdocumenttemplatespolicy_l_enteraurl","displayName":"Enter a URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_checkouttolocaldisk","displayName":"Check-out to local disk (User)","description":"This policy turns on the check-out to local disk feature.\r\n\r\nIf you enable this policy setting, documents that are checked-out will be stored in the Local Drafts folder on the local disk.\r\n\r\nIf you disable or do not configure this policy setting, documents that are checked out will be checked-out on SharePoint and no local copy will be created.","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_checkouttolocaldisk_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_checkouttolocaldisk_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_deletefilesfromofficedocumentcache","displayName":"Delete files from Office Document Cache (User)","description":"This policy setting determines whether or not documents opened in Office are deleted from the Office Document Cache when they are closed.\r\n\r\nIf you enable this policy setting documents are deleted from the Office Document Cache when they are closed. \r\n\r\nIf you disable or do not configure this policy setting, documents are not deleted from the Office Document Cache when they are closed.\r\n\r\nNote: This policy setting does not apply to documents in SharePoint Workspace. Documents in SharePoint Workspace will not be deleted from the Office Document cache when they are closed. Sharepoint Workspace will not work correctly if this Group Policy is enabled.","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_deletefilesfromofficedocumentcache_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_deletefilesfromofficedocumentcache_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_enablecheckouttodrafts","displayName":"Save checked-out files to a local folder (User)","description":"This policy setting allows users to save files checked out from SharePoint, or other document management server products, to a local folder when editing the files. \r\n\r\nBy default, checked-out files are stored in the Office Document Cache. The Office Document Cache allows the same offline editing capabilities as a local folder, but automatically syncs the files when there is Internet connectivity.\r\n\r\nNote: It’s not recommended to enable this policy setting unless needed to support existing document management processes.\r\n\r\nIf you enable this policy setting, users can specify a local folder to save checked-out files to by going to File > Options > Save > Offline editing options.\r\n\r\nIf you disable or don’t configure this policy setting, checked-out files are stored in the Office Document Cache.\r\n ","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_enablecheckouttodrafts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_enablecheckouttodrafts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_officedocumentcachelocation","displayName":"Office document cache location (User)","description":"This policy setting determines the location where Office maintains the Office Document Cache.\r\n\r\nIf you enable this policy setting, you can specify the location where Office maintains the Office Document Cache.\r\n\r\nIf you disable or do not configure this policy setting, the Office Document Cache will be stored in the following location: %LocalAppData%\\Microsoft\\Office\\16.0\\OfficeFileCache","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_officedocumentcachelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_officedocumentcachelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_officedocumentcachelocation_l_officedocumentcachelocationid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_opendocumentsfromofficedocumentcachefirst","displayName":"Open documents from Office Document Cache first (User)","description":"This policy setting allows the client application to open a document directly from the Office Document Cache if it is aware that the server the document resides on is not reachable. It may be useful in situations where you would like to wait to contact the server every time, time out and then fallback to the cache. \r\n\r\nIf you enable or do not configure this policy setting, documents will be opened directly from the Office Document Cache when the server the document resides on is not reachable. \r\n\r\nIf you disable this policy setting, Office will always attempt to first reach the server the document resides on before opening it from the Office Document Cache.","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_opendocumentsfromofficedocumentcachefirst_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_opendocumentsfromofficedocumentcachefirst_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_allowlinkedinfeatures","displayName":"Show LinkedIn features in Office applications (User)","description":"This policy setting will prevent LinkedIn features from appearing in the Office applications.\r\n\r\nIf you enable or do not configure this policy, users will be able to leverage LinkedIn data and resources from a variety of locations within the Office applications.\r\n\r\nIf you disable this policy setting, LinkedIn features will not be available.\r\n\r\nImportant: This policy setting only applies to Office 365 clients that are installed by using Click-to-Run, including Office 365 ProPlus, Office 365 Business, Visio Pro for Office 365 and Project Pro for Office 365. It doesn't apply to Office products that use Windows Installer (MSI).\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_allowlinkedinfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_allowlinkedinfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_alwaysshowfilesharemoreoptions","displayName":"Show additional sharing choices under the File tab (User)","description":"This policy settings controls what is displayed when the user goes to File > Share in Word, Excel, or PowerPoint.\r\n\r\nBy default, choosing File > Share takes the user to the Share dialog, which provides various choices for sharing. These choices used to appear under File > Share, but no longer appear there by default. There are some additional choices that used to appear under File > Share, but don’t appear in the Share dialog.\r\n\r\nIf you enable this policy setting, the user isn’t taken to the Share dialog and the user sees all the sharing choices under File > Share. For example, several options to share by email or an option to share by instant message.\r\n\r\nIf you disable or don’t configure this policy setting, choosing File > Share takes the user to the Share dialog, which doesn’t have all the sharing choices.\r\n\r\nNote: The user can also add buttons for these additional sharing choices to the ribbon or to the quick access toolbar, regardless of how this policy setting is configured.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_alwaysshowfilesharemoreoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_alwaysshowfilesharemoreoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changedestinationurlforsharepointhyperlink","displayName":"Change destination URL for SharePoint hyperlink (User)","description":"This policy setting changes the destination URL of the Learn more about SharePoint hyperlink located on the Save to SharePoint form in the Backstage view for Word, PowerPoint, Excel, Visio, and Project.\r\n\r\nIf you enable this policy setting, the hyperlink destination you provide will be used.\r\n\r\nIf you disable or do not configure this policy setting, then the default destination URL to Learn more about SharePoint will be used.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changedestinationurlforsharepointhyperlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changedestinationurlforsharepointhyperlink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changedestinationurlforsharepointhyperlink_l_changedestinationurlforsharepointhyperlinkid","displayName":"Destination URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changelabelofsavetosharepoint","displayName":"SharePoint Product Name (User)","description":"This policy setting allows you to customize the label that is used for your company's SharePoint deployment. This will update the label that is used in the Open and Save As places in all Office applications.\r\n\r\nYou can use this option to make it more clear to users where they should be saving company documents.\r\n\r\nIf you enable this policy setting, the new string you provide will be used to refer to your company's SharePoint deployment. We recommend setting this to the name of your company.\r\n\r\nIf you disable or do not configure this policy setting then the default string, \"SharePoint,\" will be displayed in the Open and Save As UI in all Office applications.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changelabelofsavetosharepoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changelabelofsavetosharepoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changelabelofsavetosharepoint_l_changelabelofsavetosharepointid","displayName":"Custom string to be displayed: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging","displayName":"Control Blogging (User)","description":"This policy setting controls whether users can compose and post blog entries from Word.\r\n\r\nIf you enable this policy setting, you can choose from three options for controlling blogging: \r\n\r\n* Enabled - Users may compose and post blog entries from Word to any available blog provider. This is the default configuration in Word. \r\n\r\n* Only SharePoint blogs allowed - Users can only post blog entries to SharePoint sites. \r\n\r\n* Disabled - The blogging feature in Word is disabled entirely. \r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled-Enabled.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging_l_empty503","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging_l_empty503_0","displayName":"Enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging_l_empty503_1","displayName":"Only SharePoint blogs allowed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_controlblogging_l_empty503_2","displayName":"All blogging disabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableanimations","displayName":"Disable Office animations (User)","description":"This setting will disable all unnecessary Office animations. By default, animation effects, such as fading between views, are enabled.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableanimations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableanimations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablebackgrounds","displayName":"Disable Office Backgrounds (User)","description":"This policy setting turns on and off the ability of users to select an Office background.\r\n\r\nIf you enable this policy setting, users won’t see the Office Backgrounds setting in either the Account place or the Options dialog. They also won’t have an Office Background applied to the upper right of their Office applications.\r\n\r\nIf you disable or don’t configure this policy setting, users will see the Office Backgrounds setting in the Account place and in the Options dialog, and they will have an Office Background applied to the upper right of their Office applications.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablebackgrounds_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablebackgrounds_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableclipboardtoolbartriggers","displayName":"Disable Clipboard Toolbar triggers (User)","description":"Checked: Prevents the Office Clipboard from automatically appearing when multiple Copy commands are performed in any of the Office programs. | Unchecked: Permits the Office Clipboard to appear automatically when multiple Copy commands are performed in Office programs.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableclipboardtoolbartriggers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableclipboardtoolbartriggers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelinksopenright","displayName":"Open Office file links in Office Online (User)","description":"\r\n This policy setting controls which version of Office opens when a hyperlink to an Office file stored on OneDrive, OneDrive for Business, or a SharePoint Online team site is selected.\r\n\r\n By default, a hyperlink to a file stored in one of these locations opens the file in the Office client version of Word, Excel, or PowerPoint. This is the version of Office that is installed on the user’s computer. If Office isn’t installed on the user’s computer, the file is opened in the Office Online version of the program in the user’s web browser.\r\n\r\n If you enable this policy setting, a hyperlink to an Office file stored in one of these locations opens the file in the Office Online version of Word, Excel, or PowerPoint. This opens the file in the user’s web browser.\r\n\r\n If you disable or don’t configure this policy setting, a hyperlink to an Office file stored in one of these locations opens the file in the Office client version of Word, Excel, or PowerPoint, if Office is installed on the user’s computer.\r\n\r\n Note: This policy setting only applies to subscription versions of the Office client, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelinksopenright_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelinksopenright_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableofficestartglobal","displayName":"Disable the Office Start screen for all Office applications (User)","description":"This policy setting controls whether the Office Start screen appears on boot for all Office applications.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot any Office application.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot their Office applications.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableofficestartglobal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableofficestartglobal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablescreenshotautohyperlink","displayName":"Do not automatically hyperlink screenshots (User)","description":"This policy setting allows you to specify whether or not Word, PowerPoint, Excel or Outlook automatically binds hyperlink to a screenshot inserted through the Insert Screenshot tool, if the screenshot is of an Internet Explorer browser window.\r\n\r\nIf you enable this policy setting, Word, PowerPoint, Excel and Outlook does not automatically bind hyperlinks to screenshot of Internet Explorer browser windows.\r\n\r\nIf you disable or do not configure this policy setting, Word, PowerPoint, Excel and Outlook automatically binds a hyperlink to screenshots of Internet Explorer browser windows.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablescreenshotautohyperlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablescreenshotautohyperlink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablewebviewintheofficefiledialogs","displayName":"Disable web view in the Office file dialog boxes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablewebviewintheofficefiledialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablewebviewintheofficefiledialogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disalowconvertdocumentpolicy","displayName":"Disallow Convert Document (Excel, PowerPoint, Word) (User)","description":"Disallow users to convert files that are in compatibility mode via the \"Convert\" command for Excel, PowerPoint, and Word.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disalowconvertdocumentpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disalowconvertdocumentpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotdisplaypathsinalerts","displayName":"Do not display paths in alerts (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotdisplaypathsinalerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotdisplaypathsinalerts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotemulatetabswithspaceswhenexportinghtml","displayName":"Emulate tabs with spaces when exporting HTML (User)","description":"Enabled: Tabs are emulated by replacing them with spaces when exporting HTML. | Disabled: Tab characters are not replaced with spaces when exporting HTML format.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotemulatetabswithspaceswhenexportinghtml_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotemulatetabswithspaceswhenexportinghtml_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donottrackdocumenteditingtime","displayName":"Do not track document editing time (User)","description":"Checked: Do not calculate the total editing time while a document is open. | Unchecked: Track the editing time while a document is open.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donottrackdocumenteditingtime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donottrackdocumenteditingtime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotuploadmediafiles","displayName":"Do not upload media files (User)","description":"Disables/Enables uploading of media files.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotuploadmediafiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotuploadmediafiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotusehardwareacceleration","displayName":"Do not use hardware graphics acceleration (User)","description":"This policy setting allows you to not use hardware graphics acceleration.\r\n\r\nIf you enable this policy setting, hardware graphics acceleration will not be used.\r\n\r\nIf you disable or do not configure this policy setting hardware graphics acceleration may be used.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotusehardwareacceleration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotusehardwareacceleration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotvalidateprintersbeforeusingthem","displayName":"Do not validate printers before using them (User)","description":"This policy setting allows you to determine whether Word, PowerPoint, or Excel validates its connection with a printer before attempting to use it in the Print tab in Backstage View.\r\n\r\nIf you enable this policy setting, Word, PowerPoint, and Excel do not validate printers before using them. If invalid data is returned from the printer, then Word, PowerPoint, and Excel still attempt to use the data, which can result in the application failing.\r\n\r\nIf you disable or do not configure this policy setting, Word, PowerPoint, and Excel validate printers before using them in the Print tab in Backstage View. If validation fails, the printer is disabled.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotvalidateprintersbeforeusingthem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotvalidateprintersbeforeusingthem_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_enableworkflowsonmysite","displayName":"Enable Workflows on My Site (User)","description":"Allows workflows on My Site to be started from within the workflow enabled Office applications.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_enableworkflowsonmysite_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_enableworkflowsonmysite_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_freezedry","displayName":"Enable Smart Resume (User)","description":"If Outlook, Word, Excel, or PowerPoint shuts down unexpectedly and is restarted automatically (for example, by Document Recovery), the user is returned to a visual state similar to the state at shutdown. By default, this setting is enabled.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_freezedry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_freezedry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_graphicfilterlegacymode","displayName":"Graphic filter legacy mode (User)","description":"Controls code path used by legacy GIF/PNG/JPEG filters. The default is to use the GDI+ codecs for these image types. For a compatibility mode to previous versions of Office which will use the legacy filter code, enable this policy.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_graphicfilterlegacymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_graphicfilterlegacymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_hidethelearnmoreaboutsharepointhyperlink","displayName":"Hide the Learn more about SharePoint Hyperlink (User)","description":"This policy setting allows you to remove the Learn more about SharePoint hyperlink from the Save to SharePoint form in the Backstage view for Word, PowerPoint, Excel, Visio, and Project.\r\n\r\nIf you enable this policy setting, the hyperlink will not be displayed.\r\n\r\nIf you disable or do not configure this policy setting, the hyperlink will appear for the Save to SharePoint form in the Backstage view when there are no locations listed.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_hidethelearnmoreaboutsharepointhyperlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_hidethelearnmoreaboutsharepointhyperlink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_homeworkflowlibrary","displayName":"Home Workflow Library (User)","description":"Allows administrators to make workflows from a specified list or library available within the workflow enabled Office applications. The value of this key should be the URL to the list or library where the workflows have been made available.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_homeworkflowlibrary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_homeworkflowlibrary_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_homeworkflowlibrary_l_path2504","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations","displayName":"Increase the visibility of Accessibility Checker violations (User)","description":"This policy setting controls whether a document, workbook, or spreadsheet with accessibility errors will cause a loud warning or error slab in the user interface.\r\n\r\nIf you enable this policy setting, you may specify what happens when a document, workbook, or spreadsheet has accessibility errors:\r\n\r\n- Accessibility violations do not change Prepare for Distribution loudness (default)\r\n- Accessibility errors cause the Prepare for Distribution slab to be loud\r\n- Accessibility errors or warnings cause the Prepare for Distribution slab to be loud\r\n\r\nIf you disable or do not configure this policy setting, the Accessibility Checker UI will be presented in its normal state.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid_0","displayName":"Accessibility violations do not change loudness (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid_1","displayName":"Accessibility errors cause slab to be loud","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid_2","displayName":"Accessibility errors or warnings cause slab to be loud","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_iscustomaddintabdefaultbackstageplace","displayName":"Take users to a custom File menu tab (User)","description":"\r\nThis policy setting controls whether users are taken to a custom menu tab when they choose the File menu in an Office app, such as Word or PowerPoint. A custom menu tab can be provided by an installed add-in.\r\n\r\nBy default, when users choose the File menu, they are taken to one of the File menu tabs provided by Office, such as Home or Info.\r\n\r\nIf you enable this policy setting, and an installed add-in provides a custom File menu tab, users will be taken to that custom tab when they choose the File menu.\r\n\r\nIf you disable or don’t configure this policy setting, when users choose the File menu, users will be taken to one of the File menu tabs provided by Office, such as Home or Info.\r\n\r\nNote: This policy setting only applies to Office clients, such as Office 365 ProPlus, that come with an Office 365 plan.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_iscustomaddintabdefaultbackstageplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_iscustomaddintabdefaultbackstageplace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_iscustomtabdefaultinnewplace","displayName":"Show the Custom tab as the default tab when creating a new file (User)","description":"\r\nThis policy settings controls whether the Custom tab shows as the default tab under File > New in Word, Excel, and PowerPoint.\r\n\r\nThe Custom tab shows the custom templates that are available. If there aren’t any custom templates, the Custom tab can’t be shown.\r\n\r\nIf you enable this policy setting, users will see the Custom tab as the default tab when creating a new file by going to File > New.\r\n\r\nIf you disable or don’t configure this policy setting, users will see the Featured tab as the default tab when creating a new file by going to File > New, unless access to Office-provided templates has been disabled.\r\n\r\nNote: This policy setting only applies to Office clients, such as Office 365 ProPlus, that come with an Office 365 plan.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_iscustomtabdefaultinnewplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_iscustomtabdefaultinnewplace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcode","displayName":"Disable Microsoft Office shared drawing code for blip caching (User)","description":"Disables blip (an image representation) caching in the shared drawing code GEL. Caching can speed up certain operations. Disabling blip caching can be used to prevent caching during file open operations.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcodeformeta","displayName":"Disable Microsoft Office shared drawing code for metafile rendering (User)","description":"Disables nearly all EMF's and WMF's will no longer be converted at runtime to be anti-aliased. Examples of EMF/WMF's that would remain \"aliased\" are: clipart, OLE object placeholders, any user inserted EMF/WMF image, etc. Any EMF/WMF containing text would be an exception to this and would be still getting anti-aliased.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcodeformeta_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcodeformeta_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_mrutemplatelistlength","displayName":"Most Recently Used Template List Length (User)","description":"This setting determines the length of the recently used templates list in the New Document dialog box. The maximum value is 25 and the minimum value is 0. This setting applies to Word, Powerpoint, and Excel.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_mrutemplatelistlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_mrutemplatelistlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_mrutemplatelistlength_l_mrutemplatelistlength505","displayName":"Most Recently Used Template List Length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter","displayName":"Hide file locations when opening or saving files (User)","description":"\r\nThis policy setting allows you to hide specific file locations when the user opens or saves a file. This helps prevent users from using either the local PC, SharePointServer, or Microsoft Office 365 cloud-based file locations such as OneDrive or SharePoint Online, to open, save, or share files.\r\n\r\nNote: This policy setting only applies to Word, PowerPoint, and Excel.\r\n\r\nIf you enable this policy setting, you can specify which file locations are hidden when the user opens or saves a file.\r\n\r\nIf you disable or don’t configure this policy setting, users can use the local PC, SharePoint Server or any configured Microsoft cloud-based file location to open, save, and share files.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid_1","displayName":"Hide OneDrive Personal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid_2","displayName":"Hide SharePoint Online and OneDrive for Business","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid_3","displayName":"Hide OneDrive Personal, SharePoint Online and OneDrive for Business","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid_4","displayName":"Hide Local PC","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid_8","displayName":"Hide SharePoint Server","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_printticketsafemode","displayName":"Print ticket safe mode (User)","description":"This policy setting allows you to determine whether Word, PowerPoint, or Excel turns off print ticket features the next time it attempts to use print ticket features after the application fails. Print ticket features include duplexing and stapling.\r\n\r\nIf you enable or do not configure this policy setting, print ticket features are turned off if Word, PowerPoint, and Excel fail while attempting to use a printer's print ticket functionality. When the printer is next used, its print ticket features are turned off until the user requests to use them again.\r\n\r\nIf you disable this policy setting, Word, PowerPoint, or Excel does not turn off print ticket features due to a previous application failure. This might result in repeated instances of the printer not responding.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_printticketsafemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_printticketsafemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_providefeedbackwithsound","displayName":"Provide feedback with sound (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_providefeedbackwithsound_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_providefeedbackwithsound_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showpasteoptionsbuttons","displayName":"Show Paste Options button when content is pasted (User)","description":"This policy setting configures the Paste Options button.\r\n\r\nIf you enable this policy setting, the Paste Options button is displayed after content is pasted.\r\n\r\nIf you disable or do not configure this policy setting, the Paste Options button is not displayed.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showpasteoptionsbuttons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showpasteoptionsbuttons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips","displayName":"Show Screen Tips (User)","description":"This policy setting allows you to determine whether Office applications display screen tips when users hover on commands on the Office Ribbon, and whether the screen tips display feature names and descriptions, or just feature names. \r\n\r\nIf you enable this policy setting, you can select any of the following options:\r\n- Show feature descriptions: Both feature names and descriptions appear when users hover over commands on the Ribbon. \r\n- Don't show feature descriptions: Only feature names appear when users hover over commands on the Ribbon. \r\n- Don't show screen tips: Nothing appears when users hover over commands on the Ribbon.\r\n\r\nIf you disable this policy setting, nothing appears when users hover over commands on the Office Ribbon.\r\n\r\nIf you do not configure this policy setting, both feature names and descriptions appear when users hover over commands on the Office Ribbon.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_l_showscreentipsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_l_showscreentipsdropid_0","displayName":"Show feature descriptions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_l_showscreentipsdropid_1","displayName":"Don't show feature descriptions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_l_showscreentipsdropid_2","displayName":"Don't show screentips","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showskydrivesignin","displayName":"Show OneDrive Sign In (User)","description":"Prompt user to sign in to OneDrive while performing a file save operation.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showskydrivesignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showskydrivesignin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions","displayName":"Block signing into Office (User)","description":"This policy setting controls whether users can provide credentials to Office using either their Microsoft Account or the user ID assigned by your organization for accessing Office 365.\r\nIf you enable this policy setting, you can specify one of the following options:\r\n\r\n- If you select \"Both IDs allowed\", users can sign in and access Office content by using either ID\r\n- If you select \"Microsoft Account only\", users can sign in only by using their Microsoft Account.\r\n- If you select \"Organization only\", users can sign in only by using the user ID assigned by your organization for accessing Office 365.\r\n- If you select \"None allowed\", users cannot sign in by using either ID.\r\n\r\nIf you disable or do not configure this policy setting, users can sign in by using either ID.\r\n\r\nNote: This policy does not apply to licensing. A user can license their product using any applicable ID if they have a valid license associated with that account. Providing credentials for licensing purposes when that ID type has been disabled, however, will not affect the signed in state of Office.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5","displayName":"Block signing into Office (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_0","displayName":"Both IDs allowed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_1","displayName":"Microsoft Account only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_2","displayName":"Org ID only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_3","displayName":"None allowed","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_suppressrecommendedsettingsdialog","displayName":"Suppress recommended settings dialog (User)","description":"This policy setting controls the Recommended Settings dialog on first run of Office.\r\n\r\nIf you enable this policy setting, the recommended settings dialog will not be displayed on first run of Office.\r\n\r\nIf you disable or do not configure this policy setting, the recommended settings will provide choices to the user to opt into services such as such as Microsoft Update, new software notifications, Customer Experience Improvement Program, Office Diagnostics (Automatically receive small updates to improve reliability) Online Help (Online content options) and Online Search Relevancy that will help improve their Office experience.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_suppressrecommendedsettingsdialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_suppressrecommendedsettingsdialog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselegacytranslationfeatures","displayName":"Use legacy translation features (User)","description":"\r\nThis policy setting allows you to use legacy translation features in Office apps, such as Word, instead of the Translator feature, which uses the cloud-based Microsoft Translator service.\r\n\r\nLegacy translation features include the following:\r\n- Translation of the entire document, by using the browser-based Bilingual Viewer.\r\n- Translation of selected text, by using the Research pane.\r\n- Translation of an individual word when hovering over the word, by using the Mini Translator.\r\n\r\nYou may need to use legacy translation features in special cases that require extra configurability, such as when using customer translation providers.\r\n\r\nIf you enable this policy setting, translation commands, such as those on the ribbon or in shortcut menus, will use the legacy translation features instead of the Translator feature.\r\n\r\nIf you disable or don’t configure this policy setting, translation commands, such as those on the ribbon or in shortcut menus, will use the Translator feature instead of the legacy translation features.\r\n\r\nNote: This policy setting only applies to apps and subscription versions of Office, such as Office 365 ProPlus, that support the Translator feature.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselegacytranslationfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselegacytranslationfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselocaluserinfo","displayName":"Use local user name and initials values regardless of signed-in user (User)","description":"This policy setting controls whether Office uses the user name and initials of the user currently signed-in, or the user name and initials that are specified in the Options dialog box.\r\n\r\nIf you enable this policy setting, regardless of any user currently signed-in, Office uses the user name and initials specified in the Options dialog box.\r\n\r\nIf you disable or do not configure this policy setting, Office uses the user name and initials from the information provided by the user that is currently signed-in.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselocaluserinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselocaluserinfo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_usesystemfontinsteadoftahoma","displayName":"Use system font instead of the Office default UI font (User)","description":"Use the system font instead of the Office default UI font. | Unchecked: Use the Office default UI font.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_usesystemfontinsteadoftahoma_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_usesystemfontinsteadoftahoma_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders","displayName":"Web Folders: Managing pairs of Web pages and folders (User)","description":"Specifies how a Web page and folder pair is to be displayed and managed by Windows.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders_l_webfoldersmanagingpairsofwebpagesandfolders506","displayName":"Web Folders: Managing pairs of Web pages and folders (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders_l_webfoldersmanagingpairsofwebpagesandfolders506_0","displayName":"Show and manage the pair as a single file","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders_l_webfoldersmanagingpairsofwebpagesandfolders506_2","displayName":"Show both parts and manage them individually","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_webfoldersmanagingpairsofwebpagesandfolders_l_webfoldersmanagingpairsofwebpagesandfolders506_1","displayName":"Show both parts but manage as a single file","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1","displayName":"Workflow Cache 1 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowcachename","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowdescrip","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowfriendly","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowpath","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowsig","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowsig_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowsig_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10","displayName":"Workflow Cache 10 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowcachename473","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowdescrip475","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowfriendly476","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowpath474","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowsig477","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowsig477_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowsig477_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11","displayName":"Workflow Cache 11 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowcachename478","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowdescrip480","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowfriendly481","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowpath479","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowsig482","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowsig482_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowsig482_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12","displayName":"Workflow Cache 12 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowcachename483","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowdescrip485","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowfriendly486","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowpath484","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowsig487","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowsig487_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowsig487_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13","displayName":"Workflow Cache 13 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowcachename488","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowdescrip490","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowfriendly491","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowpath489","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowsig492","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowsig492_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowsig492_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14","displayName":"Workflow Cache 14 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowcachename493","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowdescrip495","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowfriendly496","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowpath494","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowsig497","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowsig497_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowsig497_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15","displayName":"Workflow Cache 15 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowcachename498","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowdescrip500","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowfriendly501","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowpath499","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowsig502","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowsig502_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowsig502_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2","displayName":"Workflow Cache 2 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowcachename433","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowdescrip435","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowfriendly436","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowpath434","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowsig437","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowsig437_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowsig437_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3","displayName":"Workflow Cache 3 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowcachename438","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowdescrip440","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowfriendly441","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowpath439","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowsig442","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowsig442_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowsig442_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4","displayName":"Workflow Cache 4 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowcachename443","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowdescrip445","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowfriendly446","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowpath444","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowsig447","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowsig447_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowsig447_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5","displayName":"Workflow Cache 5 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowcachename448","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowdescrip450","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowfriendly451","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowpath449","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowsig452","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowsig452_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache5_l_workflowsig452_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6","displayName":"Workflow Cache 6 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowcachename453","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowdescrip455","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowfriendly456","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowpath454","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowsig457","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowsig457_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowsig457_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7","displayName":"Workflow Cache 7 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowcachename458","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowdescrip460","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowfriendly461","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowpath459","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowsig462","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowsig462_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowsig462_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8","displayName":"Workflow Cache 8 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowcachename463","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowdescrip465","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowfriendly466","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowpath464","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowsig467","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowsig467_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowsig467_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9","displayName":"Workflow Cache 9 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowcachename468","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowdescrip470","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowfriendly471","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowpath469","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowsig472","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowsig472_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache9_l_workflowsig472_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseexcel","displayName":"Block opening of pre-release versions of file formats new to Excel 2016 through the Compatibility Pack for Office 2016 and Excel 2016 Converter (User)","description":"This policy setting controls whether users with the Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2016 File Formats installed can open Office Open XML files saved with pre-release versions of Excel 2016. Excel Open XML files usually have the following extensions: .xlsx, .xlsm, .xltx, .xltm, .xlam. \r\n\r\nIf you enable this policy setting, users of the Compatibility Pack will not be able to open Office Open XML files created in pre-release versions of Excel 2016.\r\n\r\nIf you disable this policy setting, users with the Compatibility Pack installed can open files saved by some pre-release versions of Excel, but not by others, which can lead to inconsistent file opening functionality.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled. ","helpText":"","infoUrls":[],"categoryId":"8b0e5a63-c309-430b-8521-7bd21e715b90","categoryName":"Office 2016 Converters","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseppt","displayName":"Block opening of pre-release versions of file formats new to PowerPoint 2016 through the Compatibility Pack for Office 2016 and PowerPoint 2016 Converter (User)","description":"This policy setting controls whether users with the Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2016 File Formats installed can open Office Open XML files saved with pre-release versions of PowerPoint 2016. PowerPoint Open XML files usually have the following extensions: .pptx, .pptm, .potx, .potm, .ppsx, .ppsm, .ppam, .thmx, .xml. \r\n\r\nIf you enable this policy setting, users of the Compatibility Pack will not be able to open Office Open XML files created in pre-release versions of PowerPoint 2016. \r\n\r\nIf you disable this policy setting, users with the Compatibility Pack installed can open files saved by some pre-release versions of PowerPoint, but not by others, which can lead to inconsistent file opening functionality.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled","helpText":"","infoUrls":[],"categoryId":"8b0e5a63-c309-430b-8521-7bd21e715b90","categoryName":"Office 2016 Converters","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseppt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseppt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_disableinclusionofdocumentpropertiesinpdfandxpsoutput","displayName":"Disable inclusion of document properties in PDF and XPS output (User)","description":"This policy setting controls whether document metadata can be saved in PDF and XPS documents. \r\n\r\nIf you enable this policy setting, document properties metadata is not exported to PDF and XPS files. \r\n\r\nIf you disable this policy setting, document properties metadata will always be saved with PDF and XPS files, and users will not be able to override this configuration. \r\n\r\nIf you do not configure this policy setting, if the Microsoft Save as PDF or XPS Add-in for Microsoft Office Programs add-in is installed, document properties are saved as metadata when users save files using the PDF or XPS or Publish as PDF or XPS commands in Access, Excel, InfoPath, PowerPoint, and Word, unless the \"Document properties\" option is unchecked in the Options dialog.","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_disableinclusionofdocumentpropertiesinpdfandxpsoutput_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_disableinclusionofdocumentpropertiesinpdfandxpsoutput_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa","displayName":"Enforce PDF compliance with ISO 19005-1 (PDF/A) (User)","description":"Allows enforcement of ISO 19005-1 compliance in PDF output. The values for his setting are as follows:\r\n \r\nDefault: Options UI defaults to not ISO compliant. User may override.\r\n\r\nEncourage: Options UI defaults to ISO compliance. User may override.\r\n\r\nPrevent: Not ISO compliant. No user override.\r\n\r\nEnforce: ISO compliant. No user override.\r\n\r\nSee Office Help for more details on the tradeoffs of choosing ISO 19005 compliance.","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_l_empty417","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_l_empty417_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_l_empty417_1","displayName":"Encourage","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_l_empty417_2","displayName":"Prevent","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_enforcepdfcompliancewithiso190051pdfa_l_empty417_3","displayName":"Enforce","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser","displayName":"Disable Microsoft Save As PDF and XPS add-ins (User)","description":"Allows the user or administrator to specify which of the installed Microsoft PDF and XPS add-ins are available. \r\n\r\nWhen this setting is not configured, installed Microsoft PDF and XPS add-ins are visible to users. \r\n\r\nDefault: same as not configured. \r\n\r\nDisable XPS: Hides and disables the Microsoft Save As XPS add-in. \r\n\r\nDisable PDF: Hides and disables the Microsoft Save As PDF add-in. \r\n\r\nDisable XPS and PDF: Hides and disables both the Microsoft Save As PDF and Save As XPS add-ins.","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_l_empty418","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_l_empty418_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_l_empty418_1","displayName":"Disable XPS","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_l_empty418_2","displayName":"Disable PDF","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_pdfandxps_l_specifytypesoffixedformatoptionsavailabletotheuser_l_empty418_3","displayName":"Disable XPS and PDF","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences","displayName":"[Deprecated] Allow the use of connected experiences in Office (User)","description":"\r\n This policy setting allows you to control whether connected experiences are available to your users when they're using Office.\r\n\r\n Connected experiences include experiences that analyze content, such as Editor in Word, experiences that download online content, such as PowerPoint QuickStarter, and other connected experiences, such as document co-authoring and online file storage. It also includes additional optional connected experiences, such as the LinkedIn features of the Resume Assistant in Word or the 3D Maps feature in Excel, which uses Bing. See the Note at the end for more information about other policy settings that you can use to control these connected experiences.\r\n\r\n If you enable this policy setting, these connected experiences will be available to your users.\r\n\r\n If you disable this policy setting, these connected experiences won't be available to your users.\r\n\r\n Note: If you disable this policy setting, nearly all connected experiences will be turned off. However, limited Office functionality will remain available, such as synching a mailbox in Outlook. Essential services, such as the licensing service that confirms that you’re properly licensed to use Office, will also remain available.\r\n\r\n If you don't configure this policy setting, these connected experiences will be available to your users.\r\n\r\n Note: You can use these other policy settings if you want to disable just a certain group of connected experiences:\"Allow the use of connected experiences in Office that analyze content,\" \"Allow the use of connected experiences in Office that download online content,\" and \"Allow the use of additional optional connected experiences in Office.\"\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2085689\r\n ","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_l_connectedofficeexperiencesdropid","displayName":"[Deprecated] Connected experiences in Office (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_l_connectedofficeexperiencesdropid_1","displayName":"Connected","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_l_connectedofficeexperiencesdropid_2","displayName":"Disconnected","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_disableoptinwizard","displayName":"Disable Opt-in Wizard on first run (User)","description":"This policy setting controls whether users see the Opt-in Wizard the first time they run a Microsoft Office 2016 application. \r\n\r\nIf you enable this policy setting, the Opt-in Wizard does not display the first time users run an Office 2016 application. \r\n\r\nIf you disable or do not configure this policy setting, the Opt-in Wizard displays the first time users run a Microsoft Office 2016 application, which allows them to opt into Internet--based services that will help improve their Office experience, such as Microsoft Update, the Customer Experience Improvement Program, Office Diagnostics, and Online Help.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_disableoptinwizard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_disableoptinwizard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_enablecustomerexperienceimprovementprogram","displayName":"Enable Customer Experience Improvement Program (User)","description":"This policy setting controls whether users can participate in the Microsoft Office Customer Experience Improvement Program to help improve Microsoft Office. When users choose to participate in the Customer Experience Improvement Program (CEIP), Office 2016 applications automatically send information to Microsoft about how the applications are used. This information is combined with other CEIP data to help Microsoft solve problems and to improve the products and features customers use most often. This feature does not collect users' names, addresses, or any other identifying information except the IP address that is used to send the data. \r\n\r\nIf you enable this policy setting, users have the opportunity to opt into participation in the CEIP the first time they run an Office application. If your organization has policies that govern the use of external resources such as the CEIP, allowing users to opt in to the program might cause them to violate these policies. \r\n\r\nIf you disable this policy setting, Office 2016 users cannot participate in the Customer Experience Improvement Program. \r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_enablecustomerexperienceimprovementprogram_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_enablecustomerexperienceimprovementprogram_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent","displayName":"[Deprecated] Allow the use of connected experiences in Office that analyze content (User)","description":"\r\n This policy setting allows you to control whether connected experiences that analyze content are available to your users when they're using Office.\r\n\r\n PowerPoint Designer and Editor in Word are examples of connected experiences that analyze content.\r\n\r\n If you enable this policy setting, connected experiences that analyze content will be available to your users.\r\n\r\n If you disable this policy setting, connected experiences that analyze content won't be available to your users.\r\n\r\n If you don't configure this policy setting, connected experiences that analyze content will be available to your users.\r\n\r\n Note: If you disable the \"Allow the use of connected experiences in Office\" policy setting, conected experiences that analyze content won't be available to your users.\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2085794\r\n ","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_l_officeexperiencesanlayzingcontentdropid","displayName":"[Deprecated] Connected experiences in Office that analyze content (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_l_officeexperiencesanlayzingcontentdropid_1","displayName":"Enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesanlayzingcontent_l_officeexperiencesanlayzingcontentdropid_2","displayName":"Disabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent","displayName":"[Deprecated] Allow the use of connected experiences in Office that download online content (User)","description":"\r\n This policy setting allows you to control whether connected experiences that download online content are available to your users when they’re using Office.\r\n\r\n Office templates and PowerPoint QuickStarter are examples of connected experiences that download online content.\r\n\r\n If you enable this policy setting, connected experiences that download online content will be available to your users.\r\n\r\n If you disable this policy setting, connected experiences that download online content won’t be available to your users.\r\n\r\n If you don’t configure this policy setting, connected experiences that download online content will be available to your users.\r\n\r\n Note: If you disable the “Allow the use of connected experiences in Office” policy setting, connected experiences that download online content won’t be available to your users.\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2085688\r\n ","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_l_officeexperiencesdownloadingcontentdropid","displayName":"[Deprecated] Connected experiences in Office that download online content (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_l_officeexperiencesdownloadingcontentdropid_1","displayName":"Enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_l_officeexperiencesdownloadingcontentdropid_2","displayName":"Disabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences","displayName":"[Deprecated] Allow the use of additional optional connected experiences in Office (User)","description":"\r\n This policy setting allows you to control whether additional optional connected experiences are available to your users when they’re using Office.\r\n\r\n Additional optional connected experiences are offered by Microsoft directly to your users and are governed by terms other than your organization’s commercial agreement with Microsoft.\r\n\r\n The LinkedIn features of the Resume Assistant in Word or the 3D Maps feature in Excel, which uses Bing, are examples of additional optional connected experiences.\r\n\r\n Note: Even if you choose to make these additional optional connected experiences available to your users, your users will have the option to turn these additional optional connected experiences off as a group by going to File > Account > Account Privacy > Manage Settings.\r\n\r\n If you enable this policy setting, additional optional connected experiences will be available to your users.\r\n\r\n If you disable this policy setting, additional optional connected experiences won’t be available to your users.\r\n\r\n Note: Some additional optional connected experiences may be controlled by other policy settings instead of this policy setting. For more information, see the link below.\r\n\r\n If you don’t configure this policy setting, additional optional connected experiences will be available to your users.\r\n\r\n Note: If you disable the “Allow the use of connected experiences in Office” policy setting, additional optional connected experiences won’t be available to your users.\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2085690\r\n ","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_l_optionalconnectedexperiencesdropid","displayName":"[Deprecated] Optional connected experiences in Office (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_l_optionalconnectedexperiencesdropid_1","displayName":"Enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_optionalconnectedexperiences_l_optionalconnectedexperiencesdropid_2","displayName":"Disabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_screenshot","displayName":"Allow including screenshot with Office Feedback (User)","description":"This policy setting manages whether the Office Feedback Tool (a.k.a. Send a Smile) allows the user to send a screenshot of their desktop with their feedback to Microsoft. The Office Feedback Tool allows users to provide Microsoft feedback regarding their positive and negative experiences when using Office.\r\n\r\nIf you enable this policy setting, the Office Feedback Tool will allow the user to send a screenshot of their desktop with their feedback to Microsoft.\r\n\r\nIf you disable this policy setting, the Office Feedback Tool will not allow the user to send a screenshot of their desktop with their feedback to Microsoft.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_screenshot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_screenshot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendcustomerdata","displayName":"Send personal information (User)","description":"This policy setting controls whether users can send personal information to Office. When users choose to send information Office 2016 applications automatically send information to Office.\r\n\r\nIf you enable this policy setting, users will opt into sending personal information to Office. If your organization has policies that govern the use of external resources, opting users into the program might cause them to violate these policies.\r\n\r\nIf you disable this policy setting, Office 2016 users cannot send personal information to Office.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendcustomerdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendcustomerdata_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendfeedback","displayName":"Send Office Feedback (User)","description":"This policy setting manages the Office Feedback Tool (a.k.a. Send a Smile). The Office Feedback Tool allows users to provide Microsoft feedback regarding their positive and negative experiences when using Office.\r\n\r\nIf you enable this policy setting, the Office Feedback Tool will be turned on in all Office applications in which the tool is available. They can access the tool through the Smile button located in the top right corner of the Office application.\r\n\r\nIf you disable this policy setting, the Office Feedback Tool will be turned off. Users will not see the Smile button in any of the Office applications in which the tool is available.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendfeedback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendfeedback_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry","displayName":"Configure the level of client software diagnostic data sent by Office to Microsoft (User)","description":"\r\n This policy setting allows you to configure the level of client software diagnostic data that is collected and sent to Microsoft about the Office client software running on the user's device.\r\n\r\n Client software diagnostic data is used to keep Office secure and up-to-date, detect, diagnose and remediate problems, and also make product improvements. This data does not include a user's name or email address, the content of the user's files, or information about apps unrelated to Office.\r\n\r\n If you enable this policy setting, you must choose which level of diagnostic data is sent to Microsoft. Your choices are Required, Optional, or Neither.\r\n\r\n If you choose Required, the minimum data needed to keep Office secure, up-to-date, and performing as expected on the device it's installed on is sent to Microsoft.\r\n\r\n If you choose Optional, additional data that helps make product improvements and provides enhanced information to help detect, diagnose, and remediate issues is sent to Microsoft. If you choose to send optional diagnostic data, required diagnostic data is also included.\r\n\r\n If you choose Neither, no diagnostic data about Office client software running on the user's device is sent to Microsoft. This option, however, significantly limits Microsoft's ability to detect, diagnose, and remediate problems that your users may encounter when using Office.\r\n\r\n If you disable or don't configure this policy setting, optional diagnostic data is sent to Microsoft.\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2085687 ","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid","displayName":"Type of diagnostic data: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid_3","displayName":"Neither","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid_2","displayName":"Optional","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid_1","displayName":"Required","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_updatereliabilitypolicy","displayName":"Automatically receive small updates to improve reliability (User)","description":"This policy setting controls whether Microsoft Office Diagnostics is enabled. Office Diagnostics enables Microsoft to diagnose system problems by periodically downloading a small file to the computer. \r\n\r\nIf you enable this policy setting, Office Diagnostics collects information about specific errors and the IP address of the computer. Office Diagnostics does not transmit any personally identifiable information to Microsoft other than the IP address of the computer requesting the update. \r\n\r\nIf you disable this policy setting, users will not receive updates from Office Diagnostics. \r\n\r\nIf you do not configure this policy setting, this policy setting is not enabled, but users have the opportunity to opt into receiving updates from Office Diagnostics the first time they run an Office 2016 application.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_updatereliabilitypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_updatereliabilitypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags","displayName":"Specify custom labels to use with the Readiness Toolkit (User)","description":"This policy setting allows you to specify up to four custom labels to categorize and filter data in reports created by the Readiness Toolkit for Office. Labels are available in reports that are based on scans of the most recently used Office documents and installed add-ins on the user’s computer.\r\n\r\nYou can specify any string for the custom labels. For example, you can use a label to indicate the user’s department, title, or geographic location. When the Readiness Toolkit runs on the user’s computer, the custom labels are collected and are made available in the reports that are created. For example, you can filter the report to show only data from the Finance Department. Assign labels in a consistent manner, such as always using Label 1 for department.\r\n\r\nIf you enable this policy setting, the custom labels that you specify will be available in reports created by the Readiness Toolkit.\r\n\r\nIf you disable or don’t configure this policy setting, custom labels won’t be available in reports created by the Readiness Toolkit.\r\n\r\nNote: If you're using the Office Telemetry Dashboard and have already configured tags (labels), the Readiness Toolkit automatically collects those labels during its scan of the user's computer and will make them available in its reports. You don't need to enable this policy setting unless you want to specify different labels. Labels you specify for the Readiness Toolkit won't appear in the Office Telemetry Dashboard.","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_l_officereadinesstoolkitcustomtagstag1","displayName":"Label 1: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_l_officereadinesstoolkitcustomtagstag2","displayName":"Label 2: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_l_officereadinesstoolkitcustomtagstag3","displayName":"Label 3: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_l_officereadinesstoolkitcustomtagstag4","displayName":"Label 4: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitenableusageagent","displayName":"Allow add-in usage data to be generated and collected by the Readiness Toolkit (User)","description":"This policy setting allows you to configure whether the Readiness Toolkit for Office generates and collects add-in usage data. The data generated and collected includes when the add-in is loaded and used, and if the add-in crashes. This information is available in reports provided by the Readiness Toolkit.\r\n\r\nIf you enable this policy setting, the Readiness Toolkit generates and collects add-in usage data.\r\n\r\nIf you disable or don't configure this policy setting, the Readiness Toolkit doesn't generate or collect add-in usage data.","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitenableusageagent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitenableusageagent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization","displayName":"ActiveX Control Initialization (User)","description":"This policy setting specifies the Microsoft ActiveX® initialization security level for all Microsoft Office applications. ActiveX controls can adversely affect a computer directly. In addition, malicious code can be used to compromise an ActiveX control and attack a computer. To indicate the safety of an ActiveX control, developers can denote them as Safe For Initialization (SFI). SFI indicates that a control is safe to open and run, and that it is not capable of causing a problem for any computer, regardless of whether it has persisted data values or not. If a control is not marked SFI, it is possible that the control could adversely affect a computer--or it could mean that the developers did not test the control in all situations and are not sure whether it might be compromised in the future. \r\n \r\n If you enable this policy setting, you can set the ActiveX security level to a number between 1 and 6. These security levels are as follows: \r\n \r\n 1 - Regardless of how the control is marked, load it and use the persisted values (if any). This setting does not prompt the user. \r\n \r\n 2 - If SFI, load the control in safe mode and use persisted values (if any). If not SFI, load in unsafe mode with persisted values (if any), or use the default (first-time initialization) settings. This level is similar to the default configuration, but does not prompt the user. \r\n \r\n 3 - If SFI, load the control in unsafe mode and use persisted values (if any). If not SFI, prompt the user and advise them that it is marked unsafe. If the user chooses No at the prompt, do not load the control. Otherwise, load it with default (first-time initialization) settings. \r\n \r\n 4 - If SFI, load the control in safe mode and use persisted values (if any). If not SFI, prompt the user and advise them that it is marked unsafe. If the user chooses No at the prompt, do not load the control. Otherwise, load it with default (first-time initialization) settings. \r\n \r\n 5 - If SFI, load the control in unsafe mode and use persisted values (if any). If not SFI, prompt the user and advise them that it is marked unsafe. If the user chooses No at the prompt, do not load the control. Otherwise, load it with persisted values. \r\n \r\n 6 - If SFI, load the control in safe mode and use persisted values (if any). If not SFI, prompt the user and advise them that it is marked unsafe. If the user chooses No at the prompt, do not load the control. Otherwise, load it with persisted values. \r\n \r\n If you disable or do not configure this policy setting, if a control is marked SFI, the application loads the control in safe mode and uses persisted values (if any). If the control is not marked SFI, the application loads the control in unsafe mode with persisted values (if any), or uses the default (first-time initialization) settings. In both situations, the Message Bar informs users that the controls have been disabled and prompts them to respond. \r\n \r\n Important - Some ActiveX controls do not respect the safe mode registry setting, and therefore might load persisted data even though you configure this setting to instruct the control to use safe mode. This setting only increases security for ActiveX controls that are accurately marked as SFI. In situations that involve malicious or poorly designed code, an ActiveX control might be inaccurately marked as SFI.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon","displayName":"ActiveX Control Initialization: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon_2","displayName":"2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon_3","displayName":"3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon_4","displayName":"4","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon_5","displayName":"5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_activexcontrolinitialization_l_activexcontrolinitializationcolon_6","displayName":"6","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions","displayName":"Allow file extensions for OLE embedding (User)","description":"This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus or Visio Pro for Office 365.\r\n\r\nThis policy setting allows you to specify which file extensions Office won’t block when they are embedded as an OLE package in an Office file by using the Object Packager control.\r\n\r\nBy default, Office blocks certain file extensions. For a list of those file extensions, go to https://go.microsoft.com/fwlink/?linkid=847759.\r\n\r\nImportant: Malicious scripts and executables can be embedded as an OLE package and can cause harm if clicked by the user.\r\n\r\nIf you enable this policy setting, enter the file extensions to allow, separated by semicolons. For example, exe;vbs;js.\r\n\r\nIf you disable or don’t configure this policy setting, the default set of file extensions will be blocked.\r\n\r\nIf you want to block additional file extensions, enable the \"Block additional file extensions for OLE embedding\" policy setting.\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions_l_allowedextensionsole","displayName":"File extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity","displayName":"Automation Security (User)","description":"This policy setting controls whether macros can run in an Office 2016 application that is opened programmatically by another application. \r\n\r\nIf you enable this policy setting, you can choose from three options for controlling macro behavior in Excel, PowerPoint, and Word when the application is opened programmatically: \r\n\r\n- Disable macros by default - All macros are disabled in the programmatically opened application. \r\n\r\n- Macros enabled (default) - Macros can run in the programmatically opened application. This option enforces the default configuration in Excel, PowerPoint, and Word. \r\n\r\n- User application macro security level - Macro functionality is determined by the setting in the \"Macro Settings\" section of the Trust Center. \r\n\r\nIf you disable or do not configure this policy setting, when a separate program is used to launch Microsoft Excel, PowerPoint, or Word programmatically, any macros can run in the programmatically opened application without being blocked.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel","displayName":"Set the Automation Security level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel_3","displayName":"Disable macros by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel_2","displayName":"Use application macro security level","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel_1","displayName":"Macros enabled (default)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions","displayName":"Block additional file extensions for OLE embedding (User)","description":"This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus or Visio Pro for Office 365.\r\n\r\nThis policy setting allows you to specify additional file extensions that Office will block when they are embedded as an OLE package in an Office file by using the Object Packager control.\r\n\r\nBy default, Office blocks certain file extensions. For a list of those file extensions, go to https://go.microsoft.com/fwlink/?linkid=847759.\r\n\r\nImportant: Malicious scripts and executables can be embedded as an OLE package and can cause harm if clicked by the user.\r\n\r\nIf you enable this policy setting, enter the additional file extensions to block, separated by semicolons. For example, py;rb.\r\n\r\nIf you disable or don’t configure this policy setting, the default set of file extensions will be blocked.\r\n\r\nIf you want to allow certain file extensions, enable the \"Allow file extensions for OLE embedding\" policy setting. Extensions added to this policy setting will take precedence over extensions in \"Allow file extensions for OLE embedding\"\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions_l_blockedextensionsole","displayName":"File extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects","displayName":"Check ActiveX objects (User)","description":"This policy setting determines whether Office checks that an ActiveX object is properly categorized before loading it. \r\n\r\nIf you enable this policy setting, you can select one of the following options:\r\n- Do not check: Office loads ActiveX objects without checking if they are properly categorized.\r\n- Override IE kill bit list: Office uses the category list to override IE kill bit checks. (This is also the default behavior for this policy setting). \r\n- Strict allow list: Office only loads properly categorized ActiveX objects.\r\n\r\nIf you disable or do not configure this policy setting, Office uses the category list to override IE kill bit checks.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects_l_checkactivexobjectsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects_l_checkactivexobjectsdropid_0","displayName":"Do not check","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects_l_checkactivexobjectsdropid_1","displayName":"Override IE kill bit list","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkactivexobjects_l_checkactivexobjectsdropid_2","displayName":"Strict allow list","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkexcelrtdservers","displayName":"Check Excel RTD servers (User)","description":"This policy setting determines whether Office checks that a RealTimeData (RTD) is properly categorized before loading it. \r\n\r\nIf you enable this policy setting Office only loads properly categorized RTD servers.\r\n\r\nIf you disable or do not configure this policy setting, Office does not check that an RTD server is properly categorized before loading it.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkexcelrtdservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkexcelrtdservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects","displayName":"Check OLE objects (User)","description":"This policy setting determines whether Office checks that an OLE object is properly categorized before loading it. \r\n\r\nIf you enable this policy setting, you can select one of the following options:\r\n- Do not check: Office loads OLE objects without checking if they are properly categorized.\r\n- Override IE kill bit list: Office uses the category list to override IE kill bit checks. (This is also the default behavior for this policy setting). \r\n- Strict allow list: Office only loads properly categorized OLE objects.\r\n\r\nIf you disable or do not configure this policy setting, Office uses the category list to override IE kill bit checks.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_l_checkoleobjectsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_l_checkoleobjectsdropid_0","displayName":"Do not check","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_l_checkoleobjectsdropid_1","displayName":"Override IE kill bit list","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_l_checkoleobjectsdropid_2","displayName":"Strict allow list","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkowcdatasourceproviders","displayName":"Check OWC data source providers (User)","description":"This policy setting determines whether Office checks that an Office Web Components (OWC) data source provider is properly categorized before loading it.\r\n\r\nIf you enable this policy setting, Office only loads properly categorized data source providers.\r\n\r\nIf you disable or do not configure this policy setting, Office does not check that an OWC data source provider is properly categorized before loading it.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkowcdatasourceproviders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkowcdatasourceproviders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disableallactivex","displayName":"Disable All ActiveX (User)","description":"This policy setting controls whether ActiveX controls are disabled. \r\n\r\nIf you enable this policy setting, Office 2016 applications do not initialize ActiveX controls from non-trusted locations, and do not notify the user that the ActiveX controls are disabled. \r\n\r\nIf you disable or do not configure this policy setting, users can set the trust level for ActiveX controls in the Trust Center in the 2016 versions of Microsoft Access, PowerPoint, Word, and Excel. The default configuration does not load untrusted ActiveX controls, but uses the Message Bar to prompt users about the control, and they can then choose whether to run the control.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disableallactivex_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disableallactivex_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablealltrustbarnotificationsfor","displayName":"Disable all Trust Bar notifications for security issues (User)","description":"This policy setting controls whether Office 2016 applications notify users when potentially unsafe features or content are detected, or whether such features or content are silently disabled without notification. \r\n\r\nThe Message Bar in Office 2016 applications is used to identify security issues, such as unsigned macros or potentially unsafe add-ins. When such issues are detected, the application disables the unsafe feature or content and displays the Message Bar at the top of the active window. The Message Bar informs the users about the nature of the security issue and, in some cases, provides the users with an option to enable the potentially unsafe feature or content, which could harm the user's computer. \r\n\r\nIf you enable this policy setting, Office 2016 applications do not display information in the Message Bar about potentially unsafe content that has been detected or has automatically been blocked. \r\n\r\nIf you disable this policy setting, Office 2016 applications display information in the Message Bar about content that has automatically been blocked. \r\n\r\nIf you do not configure this policy setting, if an Office 2016 application detects a security issue, the Message Bar is displayed. However, this configuration can be modified by users in the Trust Center.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablealltrustbarnotificationsfor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablealltrustbarnotificationsfor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablepasswordtoopenui","displayName":"Disable password to open UI (User)","description":"This policy setting controls whether Office 2016 users can add password encryption to documents. (Users would access this feature in Microsoft Office tab--click Info, click Protect Document, then click Encrypt with Password.)\r\n \r\n If you enable this policy setting, users cannot password protect their 2016 Office documents. \r\n \r\n\r\nIf you disable or do not configure this policy setting, users can encrypt their 2016 Office files with passwords.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablepasswordtoopenui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablepasswordtoopenui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablevbaforofficeapplications319","displayName":"Disable VBA for Office applications (User)","description":"This policy setting allows you to prevent Excel 2016, SharePoint Designer 2016, Outlook 2016, PowerPoint 2016, Publisher 2016, and Word 2016 from using Visual Basic for Applications (VBA), whether or not the VBA feature is installed on user computers. Changing this policy setting will not install or remove the VBA files from the user computers. For more information about configuring security settings, see the 2016 Office Resource Kit.\r\n\r\nIf you enable this policy setting, VBA is disabled on 2016 Office applications on user computers.\r\n\r\nIf you disable or do not configure this policy setting, VBA is enabled for 2016 Office applications on user computers.\r\n","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablevbaforofficeapplications319_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disablevbaforofficeapplications319_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_enableminimizevbaresigning","displayName":"Enable Minimizing VBA Project Digital Signature Invalidation (User)","description":"\r\nThis policy setting allows you to reduce the number of actions in Office that will result in a document's VBA digital signature becoming invalidated.\r\n\r\nThe VBA project may be modified in certain ways that change the project storage but that do not invalidate the source code digital signature. With this setting turned off, these actions will lead to the VBA digital signature being invalidated, and the signature dropped on save if the user does not have the private key available to resign.\r\n\r\nWith this setting on, we will only perform a resign of the project if the source code signature has changed, and will keep the existing signature in other cases. If the VBA project storage is changed and saved, but the old signature retained under this feature, this can lead to an invalidation of the saved compiled VBA project state. If this happens, the VBA project will be forced to recompile each time the document is loaded. This may have negative performance impacts for larger VBA projects. Once a document is in this state, the state will persist until the VBA project is resigned.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_enableminimizevbaresigning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_enableminimizevbaresigning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptdocumentproperties","displayName":"Encrypt document properties (User)","description":"This policy setting allows you configure if the document properties are encrypted. This applies to OLE documents (Office 97-2003 compatible) if the application is configured for CAPI RC4.\r\n\r\nIf you enable this policy setting, the document properties will be encrypted.\r\n\r\nIf you disable or do not configure this policy setting, the document properties will not be encrypted.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptdocumentproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptdocumentproperties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003","displayName":"Encryption type for password protected Office 97-2003 files (User)","description":"This policy setting enables you to specify an encryption type for password-protected Office 97-2003 files.\r\n \r\nIf you enable this policy setting, you can specify the type of encryption that Office applications will use to encrypt password-protected files in the older Office 97-2003 file formats. The chosen encryption type must have a corresponding cryptographic service provider (CSP) installed on the computer that encrypts the file. See the HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\ registry key for a list of CSPs installed on the local computer. Specify the encryption type to use by entering it in the provided text box in the following form:\r\n\r\n,,.\r\nFor example, Microsoft Enhanced Cryptographic Provider v1.0,RC4,128\r\n\r\nIf you do not configure this policy setting, Excel, PowerPoint, and Word use Office 97/2000 Compatible encryption, a proprietary encryption method, to encrypt password-protected Office 97-2003 files.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003_l_encryptiontypecolon318","displayName":"Encryption type: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedofficeopen","displayName":"Encryption type for password protected Office Open XML files (User)","description":"This policy setting allows you to specify an encryption type for Office Open XML files.\r\n \r\nIf you enable this policy setting, you can specify the type of encryption that Office applications use to encrypt password-protected files in the Office Open XML file formats used by Excel, PowerPoint, and Word. The chosen encryption type must have a corresponding cryptographic service provider (CSP) installed on the computer that encrypts the file. See the HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\ registry key for a list of CSPs installed on the local computer. Specify the encryption type to use by entering it in the provided text box in the following form:\r\n\r\n,,\r\n\r\nFor example: Microsoft Enhanced Cryptographic Provider v1.0,RC4,128\r\n\r\nIf you disable or do not configure this policy setting, the default CSP is used. The default cryptographic service provider (CSP) is Microsoft Enhanced RSA and AES Cryptographic Provider, AES-128, 128-bit.\r\n\r\nNote: This policy setting does not take effect unless the registry key \r\nHKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\\\Security\\Crypto\\CompatMode is set to 0. By default the CompatMode registry key is set to 1.\r\n","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedofficeopen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedofficeopen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedofficeopen_l_encryptiontypecolon","displayName":"Encryption type: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3","displayName":"Load Controls in Forms3 (User)","description":"This policy setting allows you to control how ActiveX controls in UserForms should be initialized based upon whether they are Safe For Initialization (SFI) or Unsafefor Initialization (UFI). \r\n \r\n ActiveX controls are Component Object Model (COM) objects and have unrestricted access to users' computers. ActiveX controls can access the local file system and change the registry settings of the operating system. If a malicious user repurposes an ActiveX control to take over a user's computer, the effect could be significant. To help improve security, ActiveX developers can mark controls as Safe For Initialization (SFI), which means that the developer states that the controls are safe to open and run and not capable of causing harm to any computers. If a control is not marked SFI, the control could adversely affect a computer--or it's possible the developers did not test the control in all situations and are not sure whether their control might be compromised at some future date.SFI controls run in safe mode, which limits their access to the computer. For example, a worksheet control can both read and write files when it is in unsafe mode, but perhaps only read from files when it is in safe mode. This functionality allows the control to be used in very powerful ways when safety wasn't important, but the control would still be safe for use in a Web page. If a control is not marked as SFI, it is marked Unsafe For Initialization (UFI), which means that it is capable of affecting a user's computer. If UFI ActiveX controls are loaded, they are always loaded in unsafe mode. \r\n \r\n If you enable this policy setting, you can choose from four options for loading controls in UserForms: \r\n \r\n 1- For a UFI or SFI signed control that supports safe and unsafe mode, load the control in unsafe mode. For an SFI signed control that only supports a safe mode configuration, load the control in safe mode. This option enforces the default configuration. \r\n \r\n 2 - Users are prompted to determine how UserForm forms will load. The prompt only displays once per session within an application. When users respond to the prompt, loading continues based on whether the control is UFI or SFI: \r\n \r\n - For a UFI signed control, if users respond Yes to the prompt, load the control in unsafe mode. If users respond No, load the control using the default properties. \r\n \r\n - For an SFI signed control that supports both safe and unsafe modes, if users respond Yes to the prompt, load the control in unsafe mode. If users respond No, load the control using safe mode. If the SFI control can only support safe mode, load the control in safe mode. This option is the default configuration in the Microsoft Office 2016 release. \r\n \r\n 3 - Users are prompted to determine how UserForm forms will load. The prompt only displays once per session within an application. When users respond to the prompt, loading continues based on whether the control is UFI or SFI: \r\n \r\n - For a UFI signed control, if users respond Yes to the prompt, load the control in unsafe mode. If users respond No, load the control with its default properties. \r\n \r\n - For an SFI signed control, load in safe mode. \r\n \r\n 4 - For a UFI signed control, load with the default properties of the control. For an SFI signed control, load in safe mode (considered to be the safest mode). \r\n \r\n If you disable or do not configure this policy setting, the behavior is as if you enable this policy setting and then select option 1. ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon","displayName":"Load Controls in Forms3: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_2","displayName":"2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_3","displayName":"3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_4","displayName":"4","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope","displayName":"Macro Runtime Scan Scope (User)","description":"This policy setting specifies for which documents the VBA Runtime Scan feature is enabled.\r\n\r\nIf the feature is disabled for all documents, no runtime scanning of enabled macros will be performed.\r\n\r\nIf the feature is enabled for low trust documents, the feature will be enabled for all documents for which macros are enabled except:\r\n\r\n - Documents opened while macro security settings are set to \"Enable All Macros\"\r\n\r\n - Documents opened from a Trusted Location\r\n\r\n - Documents that are Trusted Documents\r\n\r\n - Documents that contain VBA that is digitally signed by a Trusted Publisher\r\n\r\nIf the feature is enabled for all documents, then the above class of documents are not excluded from the behavior.\r\n\r\nThis protocol allows the VBA runtime to report to the Anti-Virus system certain high-risk code behaviors it is about to execute and allows the Anti-Virus to report back to the process if the sequence of observed behaviors indicates likely malicious activity so the Office application can take appropriate action.\r\n\r\nWhen this feature is enabled, affected VBA projects' runtime performance may be reduced.\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope_l_macroruntimescanscopeenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope_l_macroruntimescanscopeenum_0","displayName":"Disable for all documents","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope_l_macroruntimescanscopeenum_1","displayName":"Enable for low trust documents","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_macroruntimescanscope_l_macroruntimescanscopeenum_2","displayName":"Enable for all documents","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_preventwordandexcelfromloadingmanagedcodeextensions","displayName":"Prevent Word and Excel from loading managed code extensions (User)","description":"This policy setting allows you to prevent Word 2016 and Excel 2016 from loading managed code extensions.\r\n\r\nIf you enable this policy setting, Word 2016 and Excel 2016 will not load managed code extensions.\r\n\r\nIf you disable or do not configure this policy setting, Word 2016 and Excel 2016 will load managed code extensions automatically.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_preventwordandexcelfromloadingmanagedcodeextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_preventwordandexcelfromloadingmanagedcodeextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforpasswordprotected","displayName":"Protect document metadata for password protected files (User)","description":"This policy setting determines whether metadata is encrypted when an Office Open XML file is password protected.\r\n \r\n If you enable this policy setting, Excel 2016, PowerPoint 2016, and Word 2016 encrypt metadata stored in password-protected Office Open XML files and override any configuration changes on users' computers.\r\n \r\n If you disable this policy setting, Office 2016 applications cannot encrypt metadata in password-protected Office Open XML files, which can reduce security.\r\n \r\n If you do not configure this policy setting, when an Office Open XML document is protected with a password and saved, any metadata associated with the document is encrypted along with the rest of the document's contents. If this configuration is changed, potentially sensitive information such as the document author and hyperlink references could be exposed to unauthorized people.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforpasswordprotected_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforpasswordprotected_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforrightsmanaged","displayName":"Protect document metadata for rights managed Office Open XML Files (User)","description":"This policy setting determines whether metadata is encrypted in Office Open XML files that are protected by Information Rights Management (IRM). \r\n\r\nIf you enable this policy setting, Excel, PowerPoint, and Word encrypt metadata stored in rights-managed Office Open XML files and override any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Office 2016 applications cannot encrypt metadata in rights-managed Office Open XML files, which can reduce security. \r\n\r\nIf you do not configure this policy setting, when Information Rights Management (IRM) is used to restrict access to an Office Open XML document, any metadata associated with the document is not encrypted.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforrightsmanaged_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforrightsmanaged_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength","displayName":"Set minimum password length (User)","description":"This setting will define what the minimum length a password should be when the local policy is enforced.\r\n\r\nIf you enable this policy setting, you may specify the minimum password length. The valid range is between 0 and 255.\r\n\r\nIf you disable or do not configure this policy setting, the default minimum password length is 0 characters.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength_l_setminimumpasswordlengthspinid","displayName":"Minimum password length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordhashformatasisocompliant","displayName":"Set password hash format as ISO-compliant (User)","description":"This policy setting allows you create ISO-compliant modification password records.\r\n\r\nIf you enable this policy setting, then passwords created will be ISO-compliant.\r\n\r\nIf you disable or do not configure this policy setting, the default will be ECMA-style records.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordhashformatasisocompliant_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordhashformatasisocompliant_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordrulesdomaintimeout","displayName":"Set password rules domain timeout (User)","description":"This policy setting will define how long in milliseconds to wait when contacting a domain controller before timing out. This requires the \"Set password rules level\" to be enabled and set to \"Local length, local complexity, and domain policy checks.\"\r\n\r\nIf you enable this policy setting, you may set how long in milliseconds to wait when contacting a domain controller before timing out.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 4000 milliseconds is used.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordrulesdomaintimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordrulesdomaintimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordrulesdomaintimeout_l_setpasswordrulesdomaintimeoutspinid","displayName":"in milliseconds (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel","displayName":"Set password rules level (User)","description":"This policy setting allows you to set the password rules level.\r\n\r\nIf you enable this policy setting, you may specify a password rules level:\r\n\r\n- No password checks: There are no complexity checks\r\n- Local length check: Minimum length checks\r\n- Local length and complexity checks: Minimum length checks plus 3 of 4 character groups checks.\r\n- Local length, local complexity, and domain policy checks: All the previous checks plus Windows domain password rules enforced.\r\n\r\nIf you select \"Local length and complexity checks\" or \"Local length, local complexity, and domain policy checks,\" then the password must contain characters from at least three of four character sets: lowercase a-z, uppercase A-Z, digits 0-9, or non-alphabetic characters. When this complexity is enforced, the minimum password length needs to be at least 6, but can be more depending on the value set in the \"Set minimum password length\" policy setting.\r\n\r\nIf you select \"Local length, local complexity, and domain policy checks,\" then Microsoft Office will use the Windows domain policy as well as all the settings \"Local length and complexity checks.\" This allows a custom password filter that is installed for Windows passwords to be used. If you are offline or a domain controller cannot be contacted, then the Windows password settings are not used, and only the \"Local length and complexity checks\" settings are used. If you don’t have a custom password filter, then \"Local length and complexity checks\" saves a trip across the network and would be the best choice.\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the same as if this policy setting were enabled and \"No password checks\" selected.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_l_setpasswordrulesleveldropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_l_setpasswordrulesleveldropid_0","displayName":"No password checks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_l_setpasswordrulesleveldropid_1","displayName":"Local length check","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_l_setpasswordrulesleveldropid_2","displayName":"Local length and complexity checks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordruleslevel_l_setpasswordrulesleveldropid_3","displayName":"Local length, local complexity, and domain policy checks","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_suppresshyperlinkwarnings","displayName":"Suppress hyperlink warnings (User)","description":"This policy setting controls whether Office 2016 applications notify users about unsafe hyperlinks. Links that Office 2016 considers unsafe include links to executable files, TIFF files, and Microsoft Document Imaging (MDI) files. Other unsafe links are those that use protocols considered to be unsafe such as javascript. \r\n\r\nIf you enable this policy setting, unsafe hyperlink warnings are suppressed for all users. \r\n\r\nIf you disable or do not configure this policy setting, hyperlink warnings cannot be suppressed by any means. Office 2016 users will be notified that links are unsafe and must enable them manually to use them.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_suppresshyperlinkwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_suppresshyperlinkwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnofferrorreportingforfilesthatfailfilevalidation","displayName":"Turn off error reporting for files that fail file validation (User)","description":"This policy determines whether error reports and files that fail file validation should be sent using the Watson dialog.\r\n\r\nIf you enable this policy setting, users will not see the Watson dialog. Files that fail file validation will not be sent by the Watson dialog to Microsoft.\r\n\r\nIf you disable or do not configure this policy setting, the Watson dialog to send files that fail validation will show up once every two weeks.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnofferrorreportingforfilesthatfailfilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnofferrorreportingforfilesthatfailfilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnoffpdfencryptionsettingui","displayName":"Turn off PDF encryption setting UI (User)","description":"This policy setting allows you to turn off the PDF encryption setting UI.\r\n\r\nIf you enable this policy setting, the PDF encryption UI is hidden. If your organization has a higher requirement on encryption than what is supported, the recommendation is to enable this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the PDF encryption UI is shown, and users may choose to encrypt the PDF file or not.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnoffpdfencryptionsettingui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnoffpdfencryptionsettingui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_checkthexadesportionsofadigitalsignature","displayName":"Check the XAdES portions of a digital signature (User)","description":"This policy setting lets you specify whether or not Office 2016 checks the XAdES portions of a digital signature, if present, when validating a digital signature for a document. \r\n\r\nIf you enable this policy setting, Office 2016 checks the XAdES portions of a digital signature when validating it.\r\n\r\nIf you disable or do not configure this policy setting, Office 2016 only validates XML-DSig and XAdES-BES portions of a digital signature.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_checkthexadesportionsofadigitalsignature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_checkthexadesportionsofadigitalsignature_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm","displayName":"Configure time stamping hashing algorithm (User)","description":"This policy setting allows you to configure the time stamping hashing algorithm used by Office 2016 applications to validate a message or document.\r\n \r\nIf you enable this policy setting, you can specify any of the following standard hashing algorithm (SHA) functions:\r\n- SHA1\r\n- SHA256\r\n- SHA384\r\n- SHA512\r\n\r\nIf you disable or do not configure this policy setting, SHA1 will be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_l_configuretimestampinghashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_l_configuretimestampinghashingalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_l_configuretimestampinghashingalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_l_configuretimestampinghashingalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_configuretimestampinghashingalgorithm_l_configuretimestampinghashingalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_donotallowexpiredcertificateswhenvalidatingsignatures","displayName":"Do not allow expired certificates when validating signatures (User)","description":"This policy setting allows you to configure Office 2016 applications to accept expired digital certificates during verification of digital signatures.\r\n\r\nIf you enable or do not configure this policy setting, Office 2016 applications display digital signatures created with expired certificates as invalid.\r\n\r\nIf you disable this policy setting, Office 2016 applications treat expired certificates as valid.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_donotallowexpiredcertificateswhenvalidatingsignatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_donotallowexpiredcertificateswhenvalidatingsignatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration","displayName":"Requested XAdES level for signature generation (User)","description":"This policy setting allows you to specify a requested or desired XAdES level in creating a digital signature. \r\n\r\nIf you enable this policy setting, you may specify the XAdES level in creating a digital signature. If the desired XAdES level is not reached, the last highest XAdES level reached is used if the level is higher than the minimum XAdES level (XAdeES-BES).\r\n\r\n- No XAdES: XML-DSig - No XAdES\r\n- XAdES-BES: Minimal XAdES (Default)\r\n- XAdES-T: Will fall back to XAdES-BES if minimum XAdES level < XAdes-T\r\n- XAdES-C: Will fall back to XAdES-T if minimum XAdES level < XAdes-C\r\n- XAdES-X: Will fall back to XAdES-C if minimum XAdES level < XAdes-X\r\n- XAdES-X-L: Will fall back to XAdES-X if minimum XAdES level < XAdes-X-L\r\n\r\nIf you disable or do not configure this policy setting, XAdES-BES will be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_0","displayName":"No XAdES","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_1","displayName":"XAdES-BES","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_2","displayName":"XAdES-T","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_3","displayName":"XAdES-C","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_4","displayName":"XAdES-X","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_5","displayName":"XAdES-X-L","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requireocspatsignaturegenerationtime","displayName":"Require OCSP at signature generation time (User)","description":"This policy setting lets you determine whether Office 2016 requires OCSP (Online Certificate Status Protocol) revocation data for all digital certificates in a chain when digital signatures are generated.\r\n\r\nIf you enable this policy setting, Office 2016 requires OCSP revocation data for all certificates in a chain when digital signatures are generated.\r\n\r\nIf you disable or do not configure this policy setting, Office 2016 does not set any restrictions on what type of revocation data is to be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requireocspatsignaturegenerationtime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requireocspatsignaturegenerationtime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm","displayName":"Select digital signature hashing algorithm (User)","description":"This policy setting allows you to configure the hashing algorithm Office 2016 applications use to confirm digital signatures.\r\n\r\nIf you enable this policy setting, you can specify any of the following SHA standard functions:\r\n- SHA1\r\n- SHA256\r\n- SHA384\r\n- SHA512\r\n\r\nIf you disable or do not configure this policy setting, the default value of SHA1 is used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits","displayName":"Configure invalid DSA public key size (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as invalid because of the number of DSA public key bits used in the digital signature.\r\n\r\nIf you enable this policy setting, you can specify the number of bits that Office treats as invalid in a digital signature. For example: 512, 768, etc.\r\n\r\nIf you don’t configure this policy setting, Office won’t treat any digital signatures as invalid because of the number of bits in the public key.\r\n\r\nEnabling this policy causes the minimum DSA public key size to be the next largest option.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm","displayName":"Configure invalid hashing algorithm (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as invalid when it contains specific hash algorithms.\r\n\r\nIf you enable this policy setting, you can specify the weakest hash algorithm that Office treats as invalid. If you enable this policy setting, you can specify any of the following algorithms:\r\n- MD5\r\n- SHA1\r\n- SHA256\r\n- SHA384\r\n\r\nIf you don’t configure this policy setting, Office won’t treat digital signatures as invalid because of the hashing algorithm.\r\n\r\nFor example, if you set MD5 as the invalid hashing algorithm Office treats MD5 signatures as invalid.\r\n ","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_md5","displayName":"MD5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits","displayName":"Configure invalid RSA public key size (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as invalid because of the number of RSA public key bits used in the digital signature.\r\n\r\nIf you enable this policy setting, you can specify the number of bits that Office treats as invalid in a digital signature. For example: 512, 768, etc.\r\n\r\nIf you don’t configure this policy setting, Office won’t treat any digital signatures as invalid because of the number of bits in the public key.\r\n\r\nEnabling this policy causes the minimum RSA public key size to be the next largest option.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid_1536","displayName":"1536","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_l_selectdigitalsignaturehashingalgorithmdropid_2048","displayName":"2048","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits","displayName":"Configure legacy DSA public key size (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as legacy because of the number of DSA public key bits used in the digital signature.\r\n\r\nIf you enable this policy setting, you can specify the number of bits that Office treats as legacy in a digital signature. For example: 512, 768, etc.\r\n\r\nIf you don’t configure this policy setting, Office won’t treat any digital signatures as legacy because of the number of bits in the public key.\r\n\r\nEnabling this policy causes the minimum DSA public key size to be the next largest option.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm","displayName":"Configure legacy hashing algorithm (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as legacy when it contains specific hash algorithms.\r\n\r\nIf you enable this policy setting, you can specify the weakest hash algorithm that Office treats as legacy. You can specify any of the following algorithms:\r\n- MD5\r\n- SHA1\r\n- SHA256\r\n- SHA384\r\n\r\nIf you don’t configure this policy setting, Office treats digital signatures containing SHA1 or better as valid.\r\n\r\nFor example, if you set SHA256 as the legacy hashing algorithm, Office treats SHA384 signatures as valid.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_md5","displayName":"MD5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits","displayName":"Configure legacy RSA public key size (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as legacy because of the number of RSA public key bits used in the digital signature.\r\n\r\nIf you enable this policy setting, you can specify the number of bits that Office treats as legacy in a digital signature. For example: 512, 768, etc.\r\n\r\nIf you don’t configure this policy setting, Office won’t treat any digital signatures as legacy because of the number of bits in the public key.\r\n\r\nEnabling this policy causes the minimum RSA public key size to be the next largest option.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid_1536","displayName":"1536","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyrsabits_l_selectdigitalsignaturehashingalgorithmdropid_2048","displayName":"2048","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits","displayName":"Configure minimum DSA public key size (User)","description":"This policy setting allows you to configure the minimum number of DSA public key bits Office allows to create digital signatures.\r\n \r\nIf you enable this policy setting, you can specify the minimum number of bits that can be used to create a digital signature. For example: 1024, 2048, etc.\r\n \r\nIf you disable or don’t configure this policy setting, Office allows all DSA keys, unless the legacy or invalid DSA policy settings are configured.\r\n\r\n If the legacy or invalid DSA public key bits policy settings are configured, then the default for this setting will be the next larger value. For example, if the number of DSA public key bits is set to 768, then this setting would default to 1024.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturemindsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits","displayName":"Configure minimum RSA public key size (User)","description":"This policy setting allows you to configure the minimum number of RSA public key bits Office allows to create digital signatures.\r\n \r\nIf you enable this policy setting, you can specify the minimum number of bits that can be used to create a digital signature. For example: 1024, 2048, etc.\r\n \r\nIf you disable or don’t configure this policy setting, Office allows all RSA keys, unless the legacy or invalid RSA policy settings are configured.\r\n\r\n If the legacy or invalid RSA public key bits policy settings are configured, then the default for this setting will be the next larger value. For example, if the number of RSA public key bits is set to 768, then this setting would default to 1024.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_1536","displayName":"1536","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_2048","displayName":"2048","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureminrsabits_l_selectdigitalsignaturehashingalgorithmdropid_4096","displayName":"4096","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel","displayName":"Set signature verification level (User)","description":"This policy setting allows you to set the verification level used by Office 2016 applications when validating a digital signature.\r\n\r\nNote: Enabling this policy setting is not recommended for subscription versions of Office, such as Office 365 ProPlus, because it will use the legacy registry based rules settings (described below) instead of basing the verification level on the Office version that signed the file.\r\n\r\nIf you enable this policy setting, you can set the verification level to any of the following:\r\n\r\n- No rules: Office 2016 digital signature rules are disabled.\r\n\r\n- Office 2007 rules: Office 2016 uses the Office 2007 digital signature rules.\r\n\r\n- Office 2010 rules: Office 2016 uses the Office 2010 digital signature rules.\r\n\r\n- Office 2013 rules: Office 2016 uses the Office 2013 digital signature rules.\r\n\r\nIf you disable or do not configure this policy setting, subscription versions of Office 2016 use the rules of the Office version that was used to sign the document to validate the digital signature.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_l_setsignatureverificationleveldropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_l_setsignatureverificationleveldropid_0","displayName":"No rules","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_l_setsignatureverificationleveldropid_1","displayName":"Office 2007 rules","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_l_setsignatureverificationleveldropid_2","displayName":"Office 2010 rules","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_setsignatureverificationlevel_l_setsignatureverificationleveldropid_3","displayName":"Office 2013 rules","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_settimestampservertimeout","displayName":"Set timestamp server timeout (User)","description":"This policy setting allows you to configure the number of seconds Office 2016 applications wait for a response from the time stamping server before timing out. If timeout occurs, the Office 2016 application will not open the message or document.\r\n\r\nIf you enable this policy setting, the number of seconds you specify will be the length of time Office 2016 will wait for the time stamping server to return a result.\r\n\r\nIf you disable or do not configure this policy setting, the default of 5 seconds will be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_settimestampservertimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_settimestampservertimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_settimestampservertimeout_l_settimestampservertimeoutspinid","displayName":"In seconds (User)","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter","displayName":"Specify filtering for certificate issuers (User)","description":"This policy setting allows you to configure Office to only allow certificates from a specific issuer when creating a digital signature.\r\n \r\nIf you enable this policy setting, Office only displays certificates that contain the string you set in the policy. This setting is case-sensitive.\r\n\r\nFor example, a setting of \"MyCA\" would match an issuer of \"MyCA 1\"and \"MyCA 2\", but not \"MYCA 3\".\r\n\r\nIf you disable or don’t configure this setting, then signing certificates from any issuer can be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter_l_specifyissuerfilterid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration","displayName":"Specify minimum XAdES level for digital signature generation (User)","description":"This policy setting lets you specify a minimum XAdES level that Office 2016 applications must reach in order to create an XAdES digital signature. If unable to reach the minimum XAdESLevel, the Office application fails to create the signature. \r\n\r\nIf you enable this policy setting, you can set the following minimum XAdES levels that must be met by the Office application before creating the digital signature.\r\n\r\n- No minimum level\r\n- XAdES-BES: Must create at least XAdES-BES or fail\r\n- XAdES-T: Must create at least XAdES-T (timestamp) or fail. \r\n- XAdES-C: Must create at least XAdES-C (certificate and revocation references) or fail. \r\n- XAdES-X: Must create at least XAdES-X (timestamp -C) or fail. \r\n- XAdES-X-L: Must create at least XAdES-X-L (store certificate and revocation values) or fail.\r\n\r\nIf you disable or do not configure this policy setting, Office 2016 does not require a minimum XAdES level and creates the most advanced XAdES signature possible, up to the level specified in the policy setting","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_0","displayName":"No minimum level","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_1","displayName":"XAdES-BES","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_2","displayName":"XAdES-T","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_3","displayName":"XAdES-C","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_4","displayName":"XAdES-X","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_5","displayName":"XAdES-X-L","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifytimestampservername","displayName":"Specify timestamp server name (User)","description":"This policy setting allows you to set the HTTP URL for the timestamp server used by Office 2016 applications in the process of validating messages or documents.\r\n\r\nIf you enable this policy setting, you must provide a valid HTTP URL address for the timestamp server. \r\n\r\nIf you do disable or not configure this policy setting, a timestamp server will not be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifytimestampservername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifytimestampservername_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifytimestampservername_l_specifytimestampservernameid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_suppressnocertdialog","displayName":"Display alternative certificate providers (User)","description":"This policy setting allows you to configure whether Office displays a link to get a certificate from a Microsoft partner when there are no usable signing certificates.\r\n\r\nIf you enable this policy setting, the link won’t be displayed.\r\n\r\nIf you disable or don’t configure this policy setting, the link is displayed.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_suppressnocertdialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_suppressnocertdialog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey01","displayName":"Escrow Key #1 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey01_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey02","displayName":"Escrow Key #2 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey02_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey03","displayName":"Escrow Key #3 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey03_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey04","displayName":"Escrow Key #4 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey04_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey05","displayName":"Escrow Key #5 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey05_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06","displayName":"Escrow Key #6 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey07","displayName":"Escrow Key #7 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey07_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey08","displayName":"Escrow Key #8 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey08_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey09","displayName":"Escrow Key #9 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey09_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey10","displayName":"Escrow Key #10 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey10_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11","displayName":"Escrow Key #11 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12","displayName":"Escrow Key #12 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey13","displayName":"Escrow Key #13 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey13_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey14","displayName":"Escrow Key #14 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey14_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15","displayName":"Escrow Key #15 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16","displayName":"Escrow Key #16 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17","displayName":"Escrow Key #17 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey18","displayName":"Escrow Key #18 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey18_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey19","displayName":"Escrow Key #19 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey19_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey20","displayName":"Escrow Key #20 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey20_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_allowmixofpolicyanduserlocations","displayName":"Allow mix of policy and user locations (User)","description":"This policy setting controls whether trusted locations can be defined by users, the Office Customization Tool (OCT), and Group Policy, or if they must be defined by Group Policy alone.\r\n \r\nIf you enable this policy setting, users can specify any location as a trusted location, and a computer can have a combination of user-created, OCT-created, and Group Policy-created trusted locations.\r\n \r\nIf you disable this policy setting, all trusted locations that are not created by Group Policy are disabled and users cannot create new trusted locations in the Trust Center.\r\n \r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled.\r\n \r\nNote - InfoPath 2016 and Outlook 2016 do not recognize trusted locations, and therefore are unaffected by this policy setting.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_allowmixofpolicyanduserlocations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_allowmixofpolicyanduserlocations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos","displayName":"Set the minimum operating system for verifying agile VBA signatures (User)","description":"This policy setting allows you to set the minimum operating system (OS) on which agile VBA signatures produced by Office can be verified. This ensures the hashing algorithm used to sign is compatible with the specified OS and later versions. \r\n\r\nIf you enable this policy setting, Office uses the OS you specify as the minimum OS to verify agile VBA signatures.\r\n\r\nIf you disable or do not configure this policy setting, Office uses Windows 7 as the minimum OS to verify agile VBA signatures.\r\n\r\nIf you specify a minimum OS version that is higher than the highest OS supported by Office, Office uses the highest supported OS to verify agile VBA signatures.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_0","displayName":"Windows XP","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_1","displayName":"Windows Vista","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_2","displayName":"Windows 7","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_3","displayName":"Windows 8","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_l_allowsubfolders245","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_l_allowsubfolders245_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_l_allowsubfolders245_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_l_datecolon243","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_l_descriptioncolon244","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc02_l_pathcolon242","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_allowsubfolders249","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_allowsubfolders249_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_allowsubfolders249_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_datecolon247","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_descriptioncolon248","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_pathcolon246","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_allowsubfolders253","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_allowsubfolders253_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_allowsubfolders253_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_datecolon251","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_descriptioncolon252","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_pathcolon250","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_allowsubfolders257","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_allowsubfolders257_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_allowsubfolders257_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_datecolon255","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_descriptioncolon256","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_pathcolon254","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_allowsubfolders261","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_allowsubfolders261_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_allowsubfolders261_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_datecolon259","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_descriptioncolon260","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_pathcolon258","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_allowsubfolders265","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_allowsubfolders265_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_allowsubfolders265_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_datecolon263","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_descriptioncolon264","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_pathcolon262","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_l_allowsubfolders269","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_l_allowsubfolders269_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_l_allowsubfolders269_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_l_datecolon267","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_l_descriptioncolon268","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc08_l_pathcolon266","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_l_allowsubfolders273","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_l_allowsubfolders273_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_l_allowsubfolders273_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_l_datecolon271","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_l_descriptioncolon272","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc09_l_pathcolon270","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_allowsubfolders277","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_allowsubfolders277_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_allowsubfolders277_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_datecolon275","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_descriptioncolon276","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_pathcolon274","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11","displayName":"Trusted Location #11 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_l_allowsubfolders281","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_l_allowsubfolders281_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_l_allowsubfolders281_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_l_datecolon279","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_l_descriptioncolon280","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc11_l_pathcolon278","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_l_allowsubfolders285","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_l_allowsubfolders285_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_l_allowsubfolders285_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_l_datecolon283","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_l_descriptioncolon284","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_l_pathcolon282","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_l_allowsubfolders289","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_l_allowsubfolders289_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_l_allowsubfolders289_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_l_datecolon287","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_l_descriptioncolon288","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc13_l_pathcolon286","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_allowsubfolders293","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_allowsubfolders293_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_allowsubfolders293_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_datecolon291","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_descriptioncolon292","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_pathcolon290","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_allowsubfolders297","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_allowsubfolders297_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_allowsubfolders297_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_datecolon295","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_descriptioncolon296","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_pathcolon294","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_allowsubfolders301","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_allowsubfolders301_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_allowsubfolders301_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_datecolon299","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_descriptioncolon300","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_pathcolon298","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_allowsubfolders305","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_allowsubfolders305_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_allowsubfolders305_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_datecolon303","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_descriptioncolon304","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_pathcolon302","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_allowsubfolders309","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_allowsubfolders309_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_allowsubfolders309_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_datecolon307","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_descriptioncolon308","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_pathcolon306","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_allowsubfolders313","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_allowsubfolders313_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_allowsubfolders313_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_datecolon311","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_descriptioncolon312","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_pathcolon310","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_allowsubfolders317","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_allowsubfolders317_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_allowsubfolders317_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_datecolon315","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_descriptioncolon316","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_pathcolon314","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustlegacysignature","displayName":"Trust legacy VBA signatures (User)","description":"This policy setting allows you to control how Office loads and verifies legacy Visual Basic for Applications (VBA) signatures.\r\n\r\nIf you enable or do not configure this policy setting, Office applications can load and verify legacy VBA signatures.\r\n\r\nIf you disable this policy setting, Office applications can’t load or verify legacy VBA signatures. They can only load and verify agile VBA signatures.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustlegacysignature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustlegacysignature_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01","displayName":"Unsafe Location #1 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_l_allowsubfolders01","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_l_allowsubfolders01_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_l_allowsubfolders01_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_l_pathcolon01","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02","displayName":"Unsafe Location #2 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_allowsubfolders02","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_allowsubfolders02_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_allowsubfolders02_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_pathcolon02","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03","displayName":"Unsafe Location #3 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03_l_allowsubfolders03","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03_l_allowsubfolders03_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03_l_allowsubfolders03_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc03_l_pathcolon03","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04","displayName":"Unsafe Location #4 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_l_allowsubfolders04","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_l_allowsubfolders04_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_l_allowsubfolders04_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_l_pathcolon04","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05","displayName":"Unsafe Location #5 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_l_allowsubfolders05","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_l_allowsubfolders05_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_l_allowsubfolders05_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_l_pathcolon05","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06","displayName":"Unsafe Location #6 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_allowsubfolders06","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_allowsubfolders06_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_allowsubfolders06_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_pathcolon06","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07","displayName":"Unsafe Location #7 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07_l_allowsubfolders07","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07_l_allowsubfolders07_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07_l_allowsubfolders07_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc07_l_pathcolon07","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08","displayName":"Unsafe Location #8 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_l_allowsubfolders08","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_l_allowsubfolders08_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_l_allowsubfolders08_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_l_pathcolon08","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09","displayName":"Unsafe Location #9 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_l_allowsubfolders09","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_l_allowsubfolders09_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_l_allowsubfolders09_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_l_pathcolon09","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10","displayName":"Unsafe Location #10 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_allowsubfolders10","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_allowsubfolders10_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_allowsubfolders10_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_pathcolon10","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11","displayName":"Unsafe Location #11 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_l_allowsubfolders11","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_l_allowsubfolders11_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_l_allowsubfolders11_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_l_pathcolon11","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12","displayName":"Unsafe Location #12 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12_l_allowsubfolders12","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12_l_allowsubfolders12_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12_l_allowsubfolders12_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc12_l_pathcolon12","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13","displayName":"Unsafe Location #13 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_l_allowsubfolders13","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_l_allowsubfolders13_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_l_allowsubfolders13_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_l_pathcolon13","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14","displayName":"Unsafe Location #14 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_allowsubfolders14","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_allowsubfolders14_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_allowsubfolders14_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_pathcolon14","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15","displayName":"Unsafe Location #15 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_l_allowsubfolders15","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_l_allowsubfolders15_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_l_allowsubfolders15_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_l_pathcolon15","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16","displayName":"Unsafe Location #16 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_l_allowsubfolders16","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_l_allowsubfolders16_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_l_allowsubfolders16_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_l_pathcolon16","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17","displayName":"Unsafe Location #17 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_l_allowsubfolders17","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_l_allowsubfolders17_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_l_allowsubfolders17_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_l_pathcolon17","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18","displayName":"Unsafe Location #18 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_allowsubfolders18","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_allowsubfolders18_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_allowsubfolders18_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_pathcolon18","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19","displayName":"Unsafe Location #19 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19_l_allowsubfolders19","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19_l_allowsubfolders19_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19_l_allowsubfolders19_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc19_l_pathcolon19","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20","displayName":"Unsafe Location #20 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20_l_allowsubfolders20","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20_l_allowsubfolders20_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20_l_allowsubfolders20_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc20_l_pathcolon20","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowunsecureapps","displayName":"Allow Unsecure web add-ins and Catalogs (User)","description":"This policy setting allows users to run unsecure web add-in, which are add-ins that have web page or catalog locations that are not SSL-secured (https://), and are not in users' Internet zones.\r\n\r\nIf you enable this policy setting, users can run unsecure apps. To enable specific unsecure web add-ins, you must also configure the Trusted Web add-in Catalog policy settings to trust the catalogs that contains those Add-ins.\r\n\r\nIf you disable or do not configure this policy setting, unsecure web add-ins are not allowed.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowunsecureapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowunsecureapps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultfilesharecatalog","displayName":"Default Shared Folder Location (User)","description":"This policy setting sets allows you to set the location of the Shared Folder that is designated as Default.\r\n\r\nIf you enable this policy setting, you can set the URL for the Shared Folder from which users can insert web add-ins into their Office documents.\r\n\r\nIf you disable this policy setting, users cannot insert web add-ins from a Shared Folder.\r\n\r\nIf you do not configure this policy setting, or any other policy settings in the Trusted Catalogs folder, users can set their own Default Shared Folder location.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultfilesharecatalog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultfilesharecatalog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultfilesharecatalog_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultspcatalog","displayName":"Default SharePoint Catalog Location (User)","description":"This policy setting allows you to set the location of the SharePoint Catalog that is designated as Default. The web add-ins contained in the Default Catalog can be inserted into Office documents by users.\r\n\r\nIf you enable this policy setting, you can set the URL for the SharePoint Catalog from which users can insert apps into their Office documents.\r\n\r\nIf you disable this policy setting, users cannot insert web add-ins from a SharePoint catalog.\r\n\r\nIf you do not configure this policy setting or set any other policy settings in the Trusted Catalogs folder, users can set their own Default SharePoint Catalog location.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultspcatalog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultspcatalog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultspcatalog_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableallcatalogs","displayName":"Block Web Add-ins (User)","description":"This policy setting allows you to prevent users from using web add-ins.\r\n\r\nIf you enable this policy setting, web add-ins are blocked and all other policy settings in the Trusted Catalogs folder are ignored.\r\n\r\nIf you disable or do not configure this policy setting, apps are allowed. Other policy settings in the Trusted Catalogs folder determine which specific app sources are allowed.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableallcatalogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableallcatalogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableofficestore","displayName":"Block the Office Store (User)","description":"This policy setting allows you to prevent users from using or inserting web add-ins that come from the Office Store.\r\n\r\nIf you enable this policy setting, apps from the Office Store are blocked.\r\n\r\nIf you disable or do not configure this policy setting, apps from the Office Store are allowed, unless the \"Block Apps for Office\" policy setting is enabled.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableofficestore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableofficestore_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog01","displayName":"Trusted Catalog Location #1 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog01_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog02","displayName":"Trusted Catalog Location #2 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog02_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog03","displayName":"Trusted Catalog Location #3 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog03_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04","displayName":"Trusted Catalog Location #4 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05","displayName":"Trusted Catalog Location #5 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog06","displayName":"Trusted Catalog Location #6 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog06_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog07","displayName":"Trusted Catalog Location #7 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog07_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog08","displayName":"Trusted Catalog Location #8 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog08_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog09","displayName":"Trusted Catalog Location #9 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog09_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog10","displayName":"Trusted Catalog Location #10 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog10_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_adattributecontaingpersonalsiteurl","displayName":"AD attribute containing Personal Site URL (User)","description":"The Office client updates the User object in the Active Directory with the URL of the user's personal site. Please enter the attribute of the user object which Office should update. The default is \"wwwHomePage\".","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_adattributecontaingpersonalsiteurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_adattributecontaingpersonalsiteurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_adattributecontaingpersonalsiteurl_l_empty424","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_allowfilesynchronizationviasoaponlyondomainnetworks","displayName":"Allow file synchronization via SOAP over HTTP only on domain networks (User)","description":"This policy setting controls file synchronization via SOAP over HTTP.\r\n\r\nIf you enable this policy setting, file synchronization via SOAP over HTTP is allowed only on domain networks. \r\n\r\nIf you disable or do not configure this policy setting, file synchronization via SOAP over HTTP functions on all networks.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_allowfilesynchronizationviasoaponlyondomainnetworks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_allowfilesynchronizationviasoaponlyondomainnetworks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod","displayName":"Catalog Refresh Period (User)","description":"This policy setting sets the apps for Office catalog refresh period, which is the amount of time (hours) Office waits between refreshes of the app catalogs. Refreshing the catalogs detects whether entitlements to any apps have expired.\r\n\r\nIf you enable this policy setting, set the number of hours to determine the length of the refresh period. Choose a value between 0 (always refresh) and 10,000.\r\n\r\nIf you disable or do not configure this policy setting, the catalog refresh period is set to the default 72 hours.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod_l_empty601","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_disabletheofficeclientfrompolling","displayName":"Disable the Office client from polling the SharePoint Server for published links (User)","description":"This policy setting controls whether Office 2016 applications can poll Office servers to retrieve lists of published links. \r\n\r\nIf you enable this policy setting, Office 2016 applications cannot poll an Office server for published links. \r\n\r\nIf you disable or do not configure this policy setting, users of Office 2016 applications can see and use links to Microsoft SharePoint Server sites from those applications. You can configure published links to Office applications during initial deployment, and can add or change links as part of regular operations. These links appear on the My SharePoint Sites tab of the Open, Save, and Save As dialog boxes when opening and saving documents from these applications. Links can be targeted so that they only appear to users who are members of particular audiences. \r\n\r\nNote - This policy setting applies to Microsoft SharePoint Server specifically. It does not apply to Microsoft SharePoint Foundation.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_disabletheofficeclientfrompolling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_disabletheofficeclientfrompolling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_disabletheuserfromsettingthepersonalsiteurl","displayName":"Disable the user from setting the Personal Site URL (User)","description":"This setting will disable the Office client applications from setting the personal site URL in the Active Directory.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_disabletheuserfromsettingthepersonalsiteurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_disabletheuserfromsettingthepersonalsiteurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_foldernameforpublishedlinks","displayName":"Folder name for Published Links (User)","description":"The folder name used to store network folder shortcuts published from SharePoint Server. \"My SharePoints\" (localized) by default.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_foldernameforpublishedlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_foldernameforpublishedlinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_foldernameforpublishedlinks_l_empty427","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload","displayName":"Frequency for polling the server to download published links (User)","description":"Minimum time to wait (in seconds) before polling SharePoint Server to download published links.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload_l_empty426","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_lengthadattributecontainingpersonalsiteurl","displayName":"Length AD Attribute containing Personal Site URL (User)","description":"The Office client updates the User object in the Active Directory with the URL of the user's personal site. Please enter the length of URL that the attribute can accept. The default is 2048.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_lengthadattributecontainingpersonalsiteurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_lengthadattributecontainingpersonalsiteurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_lengthadattributecontainingpersonalsiteurl_l_empty425","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_turnonfilesynchronizationviasoapoverhttp","displayName":"Turn on file synchronization via SOAP over HTTP (User)","description":"This policy setting controls file synchronization via SOAP over HTTP.\r\n\r\nIf you enable or do not configure this policy setting, file synchronization via SOAP over HTTP is turned on. Turning file synchronization on here will still allow application-specific file synchronization to be turned off.\r\n\r\nIf you disable this policy setting this policy setting, file synchronization via SOAP over HTTP is turned off. You will turn off file synchronization via SOAP over HTTP for other applications even if the application-specific file synchronization is turned on.\r\n\r\nImportant: If you disable this policy setting, which will turn off file synchronization via SOAP over HTTP, you will also prevent co-authoring for Word and PowerPoint, and it will adversely affect the behavior of SharePoint Workspaces.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_turnonfilesynchronizationviasoapoverhttp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_turnonfilesynchronizationviasoapoverhttp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_enablecolleagueimportoutlookaddintowork","displayName":"Enable Colleague Import Outlook Add-in to work with Microsoft SharePoint Server (User)","description":"This setting will enable the Colleague Import Outlook Add-in.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_enablecolleagueimportoutlookaddintowork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_enablecolleagueimportoutlookaddintowork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofdaystoscanfromtodaytodetermine","displayName":"Maximum number of days to scan from today to determine the user's colleagues for recommendation (User)","description":"The maximum number of days to scan the Outlook mailbox to determine the colleagues the user has. The larger the number, the more accurate the recommendation. The smaller the number, the faster the recommendations are generated.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofdaystoscanfromtodaytodetermine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofdaystoscanfromtodaytodetermine_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofdaystoscanfromtodaytodetermine_l_empty429","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofitemstoscanfromtoday","displayName":"Maximum number of items to scan from today to determine the user's colleagues for recommendation (User)","description":"The maximum number of items to scan in the Outlook mailbox to determine the colleagues the user has. The larger the number, the more accurate the recommendation. The smaller the number, the faster the recommendations are generated.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofitemstoscanfromtoday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofitemstoscanfromtoday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofitemstoscanfromtoday_l_empty428","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofreceipientsinanoutlookitem","displayName":"Maximum number of recipients in an Outlook item to scan to determine the user's colleagues for recommendation (User)","description":"The maximum number of recipients in an Outlook item to scan to determine the colleagues the user has. The larger the number, the more accurate the recommendation. The smaller the number, the faster the recommendations are generated.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofreceipientsinanoutlookitem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofreceipientsinanoutlookitem_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofreceipientsinanoutlookitem_l_empty430","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows","displayName":"Maximum number of rows fetched per request while populating a lookup in the SharePoint list control (User)","description":"The maximum number of rows fetched per request while populating a lookup in the SharePoint list control. Based on a standalone server's recommended hardware configuration a good default would be about 5000. The limit helps improve the performance of the SharePoint list control and is a defense in depth measure to prevent loading the server.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_100","displayName":"100","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_450","displayName":"450","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_5000","displayName":"5000","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimebeforestartingcolleague","displayName":"Minimum time before starting Colleague recommendation scan (User)","description":"The minimum idle time (in milliseconds) to wait before the Colleague Import Outlook add-in begins to scan the mailbox.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimebeforestartingcolleague_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimebeforestartingcolleague_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimebeforestartingcolleague_l_empty431","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimetowaitbeforerescanning","displayName":"Minimum time to wait before rescanning the Outlook mailbox for new colleague recommendations (User)","description":"The minimum time (in hours) to wait before rescanning the Outlook mailbox for new colleague recommendations.","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimetowaitbeforerescanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimetowaitbeforerescanning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimetowaitbeforerescanning_l_empty432","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services_l_disableofficeuserroamingsettings","displayName":"Disable Roaming Office User Settings (User)","description":"Microsoft Office includes the ability to roam settings for specific Office features amongst devices by storing this data in the cloud. This data includes user activity such as the list of most recently used documents as well as user preferences such as the Office theme. This policy setting controls whether this data is allowed to be stored in the cloud. \r\n\r\nIf you enable this policy setting, roaming settings are only stored locally and not synchronized to the Microsoft Office roaming settings web service. \r\n\r\nIf you disable or do not configure this policy setting, roaming settings are synchronized with the Microsoft Office roaming settings web service and users can access their data from other devices. \r\n\r\nExisting data in the cloud is not affected by this policy.","helpText":"","infoUrls":[],"categoryId":"478ed057-8ee7-4dd2-8276-06dad8f85397","categoryName":"Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services_l_disableofficeuserroamingsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services_l_disableofficeuserroamingsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disablefaxoverinternetfeature","displayName":"Disable Internet Fax feature (User)","description":"This policy setting determines whether users can access the Internet Fax feature in Office 2016 applications. \r\n\r\nIf you enable this policy setting, Office 2016 users cannot send Internet faxes, and the Internet Fax menu item is removed from the Send sub-menu of the Microsoft Office menu. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 users can use the Internet Fax feature.","helpText":"","infoUrls":[],"categoryId":"a5607145-2bd3-4473-a8ee-d7fa5c2f2675","categoryName":"Fax","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disablefaxoverinternetfeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disablefaxoverinternetfeature_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disallowcustomcoversheet","displayName":"Disallow custom cover sheet (User)","description":"Disables the custom fax cover sheet by displaying the message, \"This option has been disabled by administrative policy\" when the user clicks the Custom button in the Fax Service pane of the email message.","helpText":"","infoUrls":[],"categoryId":"a5607145-2bd3-4473-a8ee-d7fa5c2f2675","categoryName":"Fax","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disallowcustomcoversheet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disallowcustomcoversheet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_enterprisetemplatespath","displayName":"Enterprise templates path (User)","description":"Specifies the location of enterprise templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_enterprisetemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_enterprisetemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_enterprisetemplatespath_l_enterprisetemplatespath329","displayName":"Enterprise templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles","displayName":"Set User path for the label page size update files (User)","description":"This policy setting allows you to override the User path for the label page size update files. \r\n\r\nIf you enable this policy setting, you may enter the path to the PSX update files and override the User path.\r\n\r\nIf you disable or do not configure this policy setting, the User path for the label page size update files remains valid.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles_l_setuserpathforthelabelpagesizeupdatefilesid","displayName":"User path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles","displayName":"Set Workgroup path for label page size update files (User)","description":"This policy setting allows you to specify the Workgroup path for the label page size update files. This is useful if the organization has a centralized template depot. \r\n\r\nIf you enable this policy setting, you may enter the path to the PSX update files.\r\n\r\nIf you disable or do not configure this policy setting, there is no Workgroup path for the shared label templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles_l_setworkgrouppathforlabelpagesizeupdatefilesid","displayName":"Workgroup path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_sharedthemespath","displayName":"Shared themes path (User)","description":"Specifies the location of workgroup themes.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_sharedthemespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_sharedthemespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_sharedthemespath_l_sharedthemespath330","displayName":"Shared themes path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_userqueriespath","displayName":"User queries path (User)","description":"Specifies the location of data sources for database queries.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_userqueriespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_userqueriespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_userqueriespath_l_userqueriespath331","displayName":"User queries path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath","displayName":"User templates path (User)","description":"Specifies the location of user templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath_l_usertemplatespath328","displayName":"User templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage","displayName":"Web Query dialog box home page (User)","description":"Specifies the default location of the home page for Web queries.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage_l_webquerydialoghomepage333","displayName":"Web Query dialog box home page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgroupbuildingblockspath","displayName":"Workgroup building blocks path (User)","description":"Specifies the location of workgroup building block templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgroupbuildingblockspath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgroupbuildingblockspath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgroupbuildingblockspath_l_path2","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgrouptemplatespath","displayName":"Workgroup templates path (User)","description":"Specifies the location of workgroup templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgrouptemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgrouptemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_workgrouptemplatespath_l_workgrouptemplatespath329","displayName":"Workgroup templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_ekufiltering","displayName":"EKU filtering (User)","description":"This policy setting allows you to specify enhanced key usage (EKU) values to be used in filtering a list of digital certificates for signing Excel, PowerPoint, and Word documents. An enhanced key usage (EKU) extension to a digital certificate is a collection of one or more values that indicate how a certificate should be used. Examples of EKU values include Smart Card Logon and Client Authentication. EKU filtering allows you to filter the list of installed certificates that can be used for digitally signing documents. The filtered list will appear when users attempt to select a certificate for digitally signing a document. \r\n\r\nIf you enable this policy setting, you can specify a list of object identifiers (OIDs) that represent acceptable EKUs for certificates used in conjunction with signed documents. For example, for a certificate with the Encrypting File System (1.3.6.1.4.1.311.10.3.4) identifier, the OID is 1.3.6.1.4.1.311.10.3.4. This list of appropriate OIDs will vary according to the specific certificates that the organization uses. For a list of object IDs associated with Microsoft cryptography, see Microsoft Knowledge Base article 287547, \"Object IDs associated with Microsoft cryptography\" at http://officeredir.microsoft.com/r/rlidGPOIDAndCrypt2O14?clid=1033. \r\n\r\nIf you disable or do not configure this policy setting, EKU filtering is not available.","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_ekufiltering_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_ekufiltering_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_ekufiltering_l_empty412","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_legacyformatsignatires","displayName":"Legacy format signatures (User)","description":"This policy setting controls whether users can apply binary format digital signatures to Office 97-2003 documents. \r\n\r\nIf you enable this policy setting, Office 2016 applications use the Office 2003 binary format to apply digital signatures to Office 97-2003 binary documents so that they will be recognized by the Office 2003 release and earlier applications. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 applications use the XML--based XMLDSIG format to attach digital signatures to documents, including Office 97-2003 binary documents. XMLDSIG signatures are not recognized by Office 2003 applications or previous versions. If an Office 2003 user opens an Excel, PowerPoint, or Word binary document with an XMLDSIG signature attached, the signature will be lost.","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_legacyformatsignatires_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_legacyformatsignatires_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_setdefaultimagedirctory","displayName":"Set default image directory (User)","description":"Sets the default directory for signing images (defaults to your pictures otherwise).","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_setdefaultimagedirctory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_setdefaultimagedirctory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_setdefaultimagedirctory_l_setdefaultimagedirctorypart","displayName":"Last-used signature image directory: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressexternalsigningservicesmenuitems","displayName":"Suppress external signature services menu item (User)","description":"This policy setting controls whether Outlook displays the \"Add Signature Services\" menu item. \r\n\r\nIf you enable this policy setting, Outlook does not display the \"Add Signature Services\" menu item on the Signature Line drop-down menu. \r\n\r\nIf you disable or do not configure this policy setting, users can select \"Add Signature Services\" (from the Signature Line drop-down menu on the Insert tab of the Ribbon in Excel, PowerPoint, and Word) to see a list of signature service providers on Office.com.","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressexternalsigningservicesmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressexternalsigningservicesmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders","displayName":"Suppress Office Signing Providers (User)","description":"This policy setting controls whether users can apply a default Microsoft Office signature line to Word documents and Excel workbooks. Digital signatures provide assurances of authenticity, integrity, and non-repudiation to electronic documents. In Excel and Word, users can add visible representations of their signatures to a document at the same time that they add digital signatures. The ability to capture digital signatures by using signature lines in Office 2016 documents makes it possible for organizations to use paperless signing processes for documents such as contracts or other agreements. \r\n\r\nIf you enable this policy setting, you can choose from four options for enabling the default Microsoft Office 2016 signature lines: \r\n\r\n- Enable Western and East Asian - Both Microsoft Office Signature Line and Stamp Signature Line are available from the Signature Line drop-down menu on the Insert tab of the Ribbon. \r\n\r\n- Suppress default Western - Users cannot add the Microsoft Office Signature Line to documents. \r\n\r\n- Suppress default East Asian - Users cannot add the Stamp Signature Line to documents. \r\n\r\n- Suppress both Western and East Asian. Neither of the default signature lines is available. This only takes affect if there is at least one other valid third party signature provider installed. \r\n\r\nIf you disable or do not configure this policy setting, Excel and Word include support for two kinds of signature lines, called Microsoft Office Signature Line and Stamp Signature Lines. The choice(s) available to the user vary according to the editing language(s) that are configured for the application at installation. \r\n\r\n- Microsoft Office Signature Line displays the letter \"X\" followed by a horizontal line, a familiar convention for handwritten signature lines. \r\n\r\n- Stamp Signature Line is only available to users of the Simplified Chinese, Traditional Chinese, Japanese, or Korean language versions of Office 2016, or to users who have installed Office 2016 Multi-Language Pack for one of these languages. This signature line displays a square, a convention in countries where rubber identity stamps (called hanko in Japan and South Korea) are used to sign documents. \r\n\r\nBoth kinds of signature lines allow signers to specify their name, title, and e-mail address. If neither kind of signature line is appropriate, third-party signature products can be added to Office applications to serve different needs. \r\n\r\nIf the correct signature line is not available for users to choose, they might be prevented from digitally signing documents. \r\n\r\nNote - This policy setting only applies to visible signature lines in Excel workbooks and Word documents. It does not affect the ability of users to add invisible digital signatures to Excel workbooks, PowerPoint presentations, and Word documents.","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_l_empty413","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_l_empty413_0","displayName":"Enable Western and East Asian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_l_empty413_1","displayName":"Suppress default Western","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_l_empty413_2","displayName":"Suppress default East Asian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressofficesigningproviders_l_empty413_3","displayName":"Suppress both Western and East Asian","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_smartdocumentswordexcel_l_completelydisablethesmartdocumentsfeatureinwordandexcel","displayName":"Completely disable the Smart Documents feature in Word and Excel (User)","description":"This policy setting allows you to configure the ability to run smart documents in Word or Excel. However, since XML expansion packs can include many types of solutions in addition to smart document solutions, this policy setting cannot be used to disable the ability to run XML expansion packs.\r\n\r\nIf you enable this policy setting, smart document solutions will not run. To fully manage the Smart Documents feature, this policy and the \"Disable Smart Document's use of manifests\" policy should both be configured.\r\n\r\nIf you disable or do not configure this policy setting, smart document solutions will run.","helpText":"","infoUrls":[],"categoryId":"449201b6-5002-42d1-85ed-d288fb6552da","categoryName":"Smart Documents (Word, Excel)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_smartdocumentswordexcel_l_completelydisablethesmartdocumentsfeatureinwordandexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_smartdocumentswordexcel_l_completelydisablethesmartdocumentsfeatureinwordandexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_smartdocumentswordexcel_l_disablesmartdocumentsuseofmanifests","displayName":"Disable Smart Document's use of manifests (User)","description":"This policy setting controls whether Office 2016 applications can load an XML expansion pack manifest file with a Smart Document. \r\n\r\nAn XML expansion pack is the group of files that constitutes a Smart Document in Excel and Word. You package one or more components that provide the logic needed for a Smart Document by using an XML expansion pack. These components can include any type of file, including XML schemas, Extensible Stylesheet Language Transforms (XSLTs), dynamic-link libraries (DLLs), and image files, as well as additional XML files, HTML files, Word files, Excel files, and text files. \r\n\r\nThe key component to building an XML expansion pack is creating an XML expansion pack manifest file. By creating this file, you specify the locations of all files that make up the XML expansion pack, as well as information that instructs Office 2016 how to set up the files for your Smart Document. The XML expansion pack can also contain information about how to set up some files, such as how to install and register a COM object required by the XML expansion pack. \r\n\r\nIf you enable this policy setting, Office 2016 applications cannot load XML expansion packs with Smart Documents. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 applications can load an XML expansion pack manifest file with a Smart Document.","helpText":"","infoUrls":[],"categoryId":"449201b6-5002-42d1-85ed-d288fb6552da","categoryName":"Smart Documents (Word, Excel)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_smartdocumentswordexcel_l_disablesmartdocumentsuseofmanifests_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_smartdocumentswordexcel_l_disablesmartdocumentsuseofmanifests_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_autoorgidgetkey","displayName":"Automatically activate Office with federated organization credentials (User)","description":"This policy setting activates Office on users’ computers without prompting them to sign in to their Office 365 accounts.\r\n\r\nIf you enable or do not configure this policy setting, and a user is already signed in with federated organization credentials, Office automatically activates when the user first starts an Office application. If either multiple or no organization credentials are found, the user is prompted to sign in.\r\n\r\nIf you disable this policy setting, Office might prompt the user to sign in with their organization's credentials if Office is not installed directly by the user from his or her Office 365 account homepage.\r\n","helpText":"","infoUrls":[],"categoryId":"760376f3-6b74-4992-89eb-aa41d6190e94","categoryName":"Subscription Activation","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_autoorgidgetkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_autoorgidgetkey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_hidemanageaccountlink","displayName":"Do not show \"Manage Account\" link for subscription licenses. (User)","description":"This policy setting controls whether a \"Manage Account\" link is exposed in Account tab of the File menu for subscription licenses.\r\n\r\nIf you enable this policy setting, Office does not expose a \"Manage Account\" link for subscription licenses.\r\n\r\nIf you disable or do not configure this policy setting, Office exposes a \"Manage Account\" link for subscription licenses.","helpText":"","infoUrls":[],"categoryId":"760376f3-6b74-4992-89eb-aa41d6190e94","categoryName":"Subscription Activation","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_hidemanageaccountlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_hidemanageaccountlink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_enablelogging","displayName":"Turn on telemetry data collection (User)","description":"This policy setting allows you to turn on the data collection features in Office that are used by Office Telemetry Dashboard and Office Telemetry Log.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent and Office applications will collect telemetry data, which includes Office application usage, most recently used Office documents (including file names) and solutions usage, compatibility issues, and critical errors that occur on the local computers. You can use Office Telemetry Dashboard to view this data remotely, and users can use Office Telemetry Log to view this data on their local computers.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent and Office applications do not generate or collect telemetry data.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_enablelogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_enablelogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentfilemetadataobfuscation","displayName":"Turn on privacy settings in Office Telemetry Agent (User)","description":"This policy setting configures Office Telemetry Agent to disguise, or obfuscate, certain file properties that are reported in telemetry data.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent obfuscates the file name, file path, and title of Office documents before uploading telemetry data to the shared folder.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent uploads telemetry data that shows the full file name, file path, and title of all Office documents.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentfilemetadataobfuscation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentfilemetadataobfuscation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentupload","displayName":"Turn on data uploading for Office Telemetry Agent (User)","description":"This policy setting turns on the data uploading feature in Office Telemetry Agent.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent periodically uploads telemetry data to a shared folder.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent does not upload any data. However, telemetry data is still collected on the local computer and can be viewed by using Office Telemetry Log.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentupload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentupload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcommonfileshare","displayName":"Specify the UNC path to store Office telemetry data (User)","description":"This policy setting allows you to specify the Uniform Naming Convention (UNC) path of a shared folder to which Office Telemetry Agent sends Office telemetry data.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent uploads Office telemetry data to the UNC path that you specify. Use the format \\\\Server_Name\\Share_Name.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent does not send the data, and you cannot see any data in Office Telemetry Dashboard.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcommonfileshare_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcommonfileshare_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcommonfileshare_l_officeosmcommonfilesharefileshare","displayName":"UNC path to store Office telemetry data: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags","displayName":"Specify custom tags for Office telemetry data (User)","description":"This policy setting allows you to add custom tags to the Office telemetry data that is sent by Office Telemetry Agent.\r\n\r\nIf you enable this policy setting, the specified custom tags are shown in Office Telemetry Dashboard, where you can filter the collected data by the tag name. You can specify any string that you want to categorize and filter the collected data (for example, department name, title of user, and so forth).\r\n\r\nIf you disable or do not configure this policy setting, no custom tags are shown in Office Telemetry Dashboard, and you cannot filter the data that is sent by Office Telemetry Agent.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_l_officeosmcustomtagstag1","displayName":"Tag 1: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_l_officeosmcustomtagstag2","displayName":"Tag 2: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_l_officeosmcustomtagstag3","displayName":"Tag 3: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_l_officeosmcustomtagstag4","displayName":"Tag 4: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications","displayName":"Office applications to exclude from Office Telemetry Agent reporting (User)","description":"This policy setting allows you to prevent telemetry data for Office applications from being reported to Office Telemetry Dashboard.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent does not upload telemetry data for the specified Office applications to Office Telemetry Dashboard.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent uploads telemetry data for all Office applications.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsaccess","displayName":"Access-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsaccess_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsaccess_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsexcel","displayName":"Excel-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsexcel_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsexcel_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsonenote","displayName":"OneNote-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsonenote_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsonenote_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsoutlook","displayName":"Outlook-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsoutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsoutlook_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationspowerpoint","displayName":"PowerPoint-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationspowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationspowerpoint_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsproject","displayName":"Project-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsproject_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationspublisher","displayName":"Publisher-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationspublisher_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationspublisher_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsvisio","displayName":"Visio-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsvisio_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsvisio_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsword","displayName":"Word-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsword_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes","displayName":"Office solutions to exclude from Office Telemetry Agent reporting (User)","description":"This policy setting allows you to prevent telemetry data for Office solutions from being reported to Office Telemetry Dashboard.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent does not upload telemetry data for the specified Office solutions to Office Telemetry Dashboard.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent uploads telemetry data for all available solution types.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesagave","displayName":"Web Add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesagave_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesagave_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesappaddins","displayName":"Application-specific add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesappaddins_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesappaddins_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypescomaddins","displayName":"COM add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypescomaddins_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypescomaddins_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesdocumentfiles","displayName":"Office document files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesdocumentfiles_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesdocumentfiles_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypestemplatefiles","displayName":"Office template files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypestemplatefiles_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypestemplatefiles_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_capitalizefirstletterofsentence","displayName":"Capitalize first letter of sentence (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_capitalizefirstletterofsentence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_capitalizefirstletterofsentence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_capitalizenamesofdays","displayName":"Capitalize names of days (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_capitalizenamesofdays_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_capitalizenamesofdays_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_correctaccidentaluseofcapslockkey","displayName":"Correct accidental use of cAPS LOCK key (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_correctaccidentaluseofcapslockkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_correctaccidentaluseofcapslockkey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_correcttwoinitialcapitals","displayName":"Correct TWo INitial CApitals (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_correcttwoinitialcapitals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_correcttwoinitialcapitals_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_replacetextasyoutype","displayName":"Replace text as you type (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_replacetextasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_replacetextasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_showautocorrectoptionsbuttons","displayName":"Show AutoCorrect Options buttons (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_showautocorrectoptionsbuttons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_showautocorrectoptionsbuttons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_checkfornewactionsurl","displayName":"Check for new actions URL (User)","description":"This policy setting allows you to configure the \"Check for New Actions\" menu option.\r\n\r\nIf you enable this policy setting, and when a URL is specified, a new \"Check for New Actions\" menu option will be added to the \"Additional Actions\" context menu.\r\n\r\nIf you disable or do not configure this policy setting, or when it is enabled and a URL is not specified, a \"Check for New Actions\" menu option will not be shown in the \"Additional Actions\" context menu.","helpText":"","infoUrls":[],"categoryId":"69931627-230d-4df9-bbef-e3eac64ea8ef","categoryName":"Additional Actions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_checkfornewactionsurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_checkfornewactionsurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_checkfornewactionsurl_l_checkfornewactionsurl231","displayName":"Check for new actions URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"69931627-230d-4df9-bbef-e3eac64ea8ef","categoryName":"Additional Actions","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_enableadditionalactionsinexcel","displayName":"Enable additional actions in Excel (User)","description":"This policy setting controls whether Excel can provide additional actions for certain words and phrases in a workbook through the right-click menu, and whether users can configure this behavior by checking or unchecking the \"Enable additional actions in the right-click menu\" option under the File tab | Options | Proofing | AutoCorrect Options | Actions tab. If additional actions functionality is turned on, Excel can recognize dates and financial symbols and provide additional actions for them.\r\n\r\nIf you enable or do not configure this policy setting, users can configure Excel to provide additional actions. Note: Excel does not provide additional actions until users check the \"Enable additional actions in the right-click menu\" option in the UI.\r\n\r\nIf you disable this policy setting, users cannot configure Excel to provide additional actions.","helpText":"","infoUrls":[],"categoryId":"69931627-230d-4df9-bbef-e3eac64ea8ef","categoryName":"Additional Actions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_enableadditionalactionsinexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_enableadditionalactionsinexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_moreactionsurl","displayName":"More actions URL (User)","description":"This policy setting allows you to specify what URL to send users to when the More Actions button is clicked. The More Actions button can be found under File tab | Options | Proofing | Autocorrect Options... | Actions | More Actions.\r\n\r\nIf you enable this policy setting and you specify a URL, the More Actions button will send the user to the specified URL. If you enable this policy setting and you do not specify a URL (you leave the field blank), the More Actions button is disabled.\r\n\r\nIf you disable or do not configure this policy setting, the More Actions button will send the user to the default URL.","helpText":"","infoUrls":[],"categoryId":"69931627-230d-4df9-bbef-e3eac64ea8ef","categoryName":"Additional Actions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_moreactionsurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_moreactionsurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_moreactionsurl_l_moreactionsurleditid","displayName":"More Actions URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"69931627-230d-4df9-bbef-e3eac64ea8ef","categoryName":"Additional Actions","options":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_conversionservices_l_conversionservicesoptions","displayName":"Conversion Service Options (User)","description":"This policy setting controls users' access to the online features of Office 2016.","helpText":"","infoUrls":[],"categoryId":"6c142a01-47fa-422d-8135-29e81bc970cc","categoryName":"Conversion Service","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_conversionservices_l_conversionservicesoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_conversionservices_l_conversionservicesoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_conversionservices_l_conversionservicesoptions_l_conversionservicesoptions236","displayName":"Conversion service options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6c142a01-47fa-422d-8135-29e81bc970cc","categoryName":"Conversion Service","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_conversionservices_l_conversionservicesoptions_l_conversionservicesoptions236_0","displayName":"Do not allow to use Microsoft Conversion Service","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_conversionservices_l_conversionservicesoptions_l_conversionservicesoptions236_2","displayName":"Allow to use Microsoft Conversion Service","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_onlinecontentoptions","displayName":"Online Content Options (User)","description":"This policy setting controls users' access to the online features of Office 2016.\r\n\r\nIf you enable this policy setting, you can choose one of two options for user access to online content and services:\r\n\r\n* Do not allow Office to connect to the Internet – Office applications do not connect to the Internet to access online services, or to download the latest online content from Office.com. Connected features of Office 2016 are disabled.\r\n\r\n* Allow Office to connect to the Internet – Office applications use online services and download the latest online content from Office.com when users’ computers are connected to the Internet. Connected features of Office 2016 are enabled. This option enforces the default configuration.\r\n\r\nIf you disable this policy setting or do not configure this policy setting, Office applications use online services and download the latest online content from Office.com when users’ computers are connected to the Internet. Users can change this behavior by deselecting the \"Allow Office to connect to the Internet\" checkbox in the Privacy Options section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","categoryName":"Online Content","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_onlinecontentoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_onlinecontentoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_onlinecontentoptions_l_onlinecontentoptions236","displayName":"Online content options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","categoryName":"Online Content","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_onlinecontentoptions_l_onlinecontentoptions236_0","displayName":"Do not allow Office to connect to the Internet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_onlinecontentoptions_l_onlinecontentoptions236_2","displayName":"Allow Office to connect to the Internet","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions","displayName":"Service Level Options (User)","description":"This policy setting controls the types of services that can be used by the online features of Office 2016.\r\n \r\nIf you enable this policy setting, you can choose one of three options for gating access to online services based on the owner of the service:\r\n\r\n* Office services only - Office 2016 applications on the computer communicate only with Office-owned services. All other Microsoft or third-party service integration in Office 2016 is disabled on the computer. This is the most restrictive option.\r\n\r\n* Microsoft services only - Office 2016 applications on the computer communicate only with Microsoft-owned services. All third-party service integration in Office 2016 is disabled on the computer.\r\n\r\n* All services - All service integration in Office 2016 is enabled on the computer. This is also the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, Office 2016 client applications allow all service integrations. Individual users can manage the set of services they use through the new My Office place in Office Backstage view.","helpText":"","infoUrls":[],"categoryId":"91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","categoryName":"Online Content","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions_l_serviceleveloptionsdropid","displayName":"Service Level Options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","categoryName":"Online Content","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions_l_serviceleveloptionsdropid_0","displayName":"Office services only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions_l_serviceleveloptionsdropid_1","displayName":"Microsoft services only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_onlinecontent_l_serviceleveloptions_l_serviceleveloptionsdropid_2","displayName":"All services","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_powerpointdesigner_l_powerpointdesigneroptions","displayName":"PowerPoint Designer Options (User)","description":"This policy setting allows an administrator to enable or disable PowerPoint Designer","helpText":"","infoUrls":[],"categoryId":"5838ed03-2902-4931-92cf-e349ab09c9b8","categoryName":"PowerPoint Designer","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_powerpointdesigner_l_powerpointdesigneroptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_powerpointdesigner_l_powerpointdesigneroptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_powerpointdesigner_l_powerpointdesigneroptions_l_powerpointdesigneroptionsid","displayName":"PowerPoint Designer options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5838ed03-2902-4931-92cf-e349ab09c9b8","categoryName":"PowerPoint Designer","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_powerpointdesigner_l_powerpointdesigneroptions_l_powerpointdesigneroptionsid_0","displayName":"Disable PowerPoint Designer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralserviceoptions~l_powerpointdesigner_l_powerpointdesigneroptions_l_powerpointdesigneroptionsid_73187","displayName":"Enable PowerPoint Designer","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disablehyperlinkstowebtemplatesinfilenewandtaskpanes","displayName":"Disable web templates in File | New and on the Office Start screen (User)","description":"This policy setting controls whether users can download templates from Office.com from within the Office applications.\r\n\r\nIf you enable this policy setting, users will not see featured templates from Office.com in File | New and on the Office Start screen and will not be able to download templates from within Office applications.\r\n\r\nIf you disable or do not configure this policy setting, users will see featured templates from Office.com in File | New and on the Office Start screen and will be able to download templates from within Office applications.\r\n\r\nNote - Enabling this policy setting does not prevent users from downloading templates from Office.com using their Web browsers.","helpText":"","infoUrls":[],"categoryId":"2d5a483f-b408-426d-9234-2883eae20afb","categoryName":"Tools | Options | General | Web Options...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disablehyperlinkstowebtemplatesinfilenewandtaskpanes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disablehyperlinkstowebtemplatesinfilenewandtaskpanes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disableofficetemplates","displayName":"Hide all Office-provided templates on the Office Start screen and in File | New (User)","description":"This policy setting controls whether Office-provided templates (from Office.com and shipped with the Office clients) are hidden on the Office Start screen and in File | New.\r\n\r\nIf you enable this policy setting, users will not see any Office provided templates on the Office Start screen nor in File | New.\r\n\r\nIf you disable or do not configure this policy setting, users will see Office provided templates on the Office Start screen nor in File | New.\r\n\r\nNote - enabling this policy setting does not prevent users from downloading templates from Office.com using their Web browsers and does not prevent users from using Office-provided templates installed on their hard drive using Windows Explorer to launch those templates.","helpText":"","infoUrls":[],"categoryId":"2d5a483f-b408-426d-9234-2883eae20afb","categoryName":"Tools | Options | General | Web Options...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disableofficetemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disableofficetemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disabletargetedmessaging","displayName":"Hide dynamic lifecycle messages (User)","description":"This policy setting controls whether dynamic lifecycle messages are displayed in Office applications.\r\n\r\nA dynamic lifecycle message appears as a notification in an Office application. This message is similar to a default lifecycle message, but provides additional information. For example, a message that reminds users to renew their subscription that also includes information to help them renew. Office periodically connects to the Internet and contacts Microsoft to determine if there are any relevant messages to display.\r\n\r\nIf you enable this policy setting, Office won’t check for these types of messages, but, default lifecycle messages still display in Office applications.\r\n\r\nIf you disable or don’t configure this policy setting, Office checks for these types of messages and displays them.","helpText":"","infoUrls":[],"categoryId":"2d5a483f-b408-426d-9234-2883eae20afb","categoryName":"Tools | Options | General | Web Options...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disabletargetedmessaging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disabletargetedmessaging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_allowpngasanoutputformat","displayName":"Allow PNG as an output format (User)","description":"This policy setting determines whether Office 2016 applications can output graphics in Portable Network Graphics (PNG) format when documents are saved as Web pages.\r\n\r\nIf you enable this policy setting, Office 2016 applications can save graphics in PNG format and users cannot change this configuration.\r\n\r\nIf you disable this policy setting, Office 2016 applications cannot save graphics in PNG format and users cannot change this configuration.\r\n\r\nIf you do not configure this policy setting, Office 2016 applications do not save graphics in the PNG format. Users can change this functionality by opening the application's Options dialog box, clicking Advanced, clicking Web Options, and selecting the Allow PNG as a graphics format check box.","helpText":"","infoUrls":[],"categoryId":"8ee1d8d2-582f-401b-927a-993016f4290d","categoryName":"Browsers","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_allowpngasanoutputformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_allowpngasanoutputformat_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_relyonvmlfordisplayinggraphicsinbrowsers","displayName":"Rely on VML for displaying graphics in browsers (User)","description":"This policy setting controls whether Office 2016 applications save standard raster file format (GIF or PNG) copies of Vector Markup Language (VML) graphics when documents are saved as Web pages.\r\n\r\nIf you enable this policy setting, Office 2016 applications will not generate alternate files for VML graphics when documents are saved as Web pages. In addition, the \"Rely on VML for displaying graphics in browsers\" check box is checked in the Web Options dialog in Excel, PowerPoint, and Word, and users cannot change it.\r\n\r\nIf you disable this policy setting, Office 2016 applications also save copies of the graphics in a standard raster file format (GIF or PNG) for use by browsers that cannot display VML. In addition, the \"Rely on VML for displaying graphics in browsers\" check box is cleared in the Web Options dialog in Excel, PowerPoint, and Word, and users cannot change it.\r\n\r\nIf you do not configure this policy setting, when saving VML graphics, Office 2016 applications also save copies of the graphics in a standard raster file format (GIF or PNG) for use by browsers that cannot display VML. If the \"Rely on VML for displaying graphics in browsers\" check box in the Web Options dialog is selected, applications will not save raster copies of VML graphics, which means those graphics will not display in non-Microsoft browsers.","helpText":"","infoUrls":[],"categoryId":"8ee1d8d2-582f-401b-927a-993016f4290d","categoryName":"Browsers","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_relyonvmlfordisplayinggraphicsinbrowsers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_relyonvmlfordisplayinggraphicsinbrowsers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor","displayName":"Target monitor (User)","description":"Sets the value in the UI.","helpText":"","infoUrls":[],"categoryId":"8ee1d8d2-582f-401b-927a-993016f4290d","categoryName":"Browsers","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_pixelsperinch","displayName":"Pixels per inch (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8ee1d8d2-582f-401b-927a-993016f4290d","categoryName":"Browsers","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_pixelsperinch_72","displayName":"72","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_pixelsperinch_96","displayName":"96","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_pixelsperinch_120","displayName":"120","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize","displayName":"Screen size (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8ee1d8d2-582f-401b-927a-993016f4290d","categoryName":"Browsers","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_544x376","displayName":"544 x 376","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_640x480","displayName":"640 x 480","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_720x512","displayName":"720 x 512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_800x600","displayName":"800 x 600","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1024x768","displayName":"1024 x 768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1152x882","displayName":"1152 x 882","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1152x900","displayName":"1152 x 900","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1280x1024","displayName":"1280 x 1024","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1600x1200","displayName":"1600 x 1200","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1800x1440","displayName":"1800 x 1440","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_targetmonitor_l_screensize_1920x1200","displayName":"1920 x 1200","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding","displayName":"Default or specific encoding (User)","description":"When enabled, either default encoding or a specified encoding will be used.","helpText":"","infoUrls":[],"categoryId":"025c640e-51e2-4f04-85e3-a13f30b5e08c","categoryName":"Encoding","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_alwayssavewebpagesinthedefaultencoding","displayName":"Always save Web pages in the default encoding. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"025c640e-51e2-4f04-85e3-a13f30b5e08c","categoryName":"Encoding","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_alwayssavewebpagesinthedefaultencoding_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_alwayssavewebpagesinthedefaultencoding_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas","displayName":"Save this document as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"025c640e-51e2-4f04-85e3-a13f30b5e08c","categoryName":"Encoding","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1256","displayName":"Arabic Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_28594","displayName":"Baltic Alphabet (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1257","displayName":"Baltic Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_852","displayName":"Central European (DOS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_28592","displayName":"Central European Alphabet (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1250","displayName":"Central European Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_936","displayName":"Chinese Simplified (GB2312)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_52936","displayName":"Chinese Simplified (HZ)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_950","displayName":"Chinese Traditional (Big 5)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_866","displayName":"Cyrillic Alphabet (DOS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_28595","displayName":"Cyrillic Alphabet (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_20866","displayName":"Cyrillic Alphabet (KOI8-R)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1251","displayName":"Cyrillic Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_28597","displayName":"Greek Alphabet (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1253","displayName":"Greek Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1255","displayName":"Hebrew Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_51932","displayName":"Japanese (EUC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_50220","displayName":"Japanese (JIS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_50222","displayName":"Japanese (JIS-Allow 1 byte Kana - SO/SI)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_50221","displayName":"Japanese (JIS-Allow 1 byte Kana)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_932","displayName":"Japanese (Shift-JIS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_949","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_28593","displayName":"Latin 3 Alphabet (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_874","displayName":"Thai (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1254","displayName":"Turkish Alphabet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_21866","displayName":"Ukrainian Alphabet (KOI8-RU)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1200","displayName":"Universal Alphabet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1201","displayName":"Universal Alphabet (Big-Endian)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_65001","displayName":"Universal Alphabet (UTF-8)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1258","displayName":"Vietnamese Alphabet (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_28598","displayName":"Visual Hebrew (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_l_savethisdocumentas_1252","displayName":"Western Alphabet (Windows)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_checkifofficeisthedefaulteditorforwebpagescreatedinoffice","displayName":"Check if Office is the default editor for Web pages created in Office (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_checkifofficeisthedefaulteditorforwebpagescreatedinoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_checkifofficeisthedefaulteditorforwebpagescreatedinoffice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentdirectlyinofficeapplication","displayName":"Open Office document directly in Office application (User)","description":"This policy setting allows you to choose whether Office documents located on web servers open directly in the registered application or through the web browser. \r\n\r\nIf you enable this policy setting, files will open directly in the associated Office application, bypassing the web browser.\r\n\r\nIf you disable this policy setting files will open through the web browser.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentdirectlyinofficeapplication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentdirectlyinofficeapplication_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentsasreadwritewhilebrowsing","displayName":"Open Office documents as read/write while browsing (User)","description":"This policy setting controls whether users can edit and save Office 2016 documents on Web servers that they have opened using Internet Explorer.\r\n \r\nIf enable this policy setting, when users browse to an Office 2016 document on a Web server using Internet Explorer the appropriate application opens the file in read/write mode.\r\n\r\nIf you disable or do not configure this policy setting, when users browse to an Office 2016 document on a Web server using Internet Explorer, the appropriate application opens the file in read-only mode.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentsasreadwritewhilebrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentsasreadwritewhilebrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_organizesupportingfilesinafolder","displayName":"Organize supporting files in a folder (User)","description":"This will be forced on if 'Use long file names' is forced off.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_organizesupportingfilesinafolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_organizesupportingfilesinafolder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_updatelinksonsave","displayName":"Update links on save (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_updatelinksonsave_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_updatelinksonsave_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_uselongfilenameswheneverpossible","displayName":"Use long file names whenever possible (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_uselongfilenameswheneverpossible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_uselongfilenameswheneverpossible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting","displayName":"Rely on CSS for font formatting (User)","description":"This policy setting allows you to rely on CSS for font formatting.\r\n\r\nIf you enable this policy setting, you may select configure these options:\r\n- Enforce CSS: If checked, enforce CSS is on. If not checked, enforce CSS is off.\r\n- CSS setting for Word: If checked, the CSS setting for Word as an email editor is used.\r\n\r\nIf you disable or do not configure this policy setting, the options will not be configured.","helpText":"","infoUrls":[],"categoryId":"eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_l_checktoenforcecssonunchecktoenforcecssoff","displayName":"Enforce CSS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_l_checktoenforcecssonunchecktoenforcecssoff_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_l_checktoenforcecssonunchecktoenforcecssoff_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_l_usethecsssettingforwordasanemaileditor","displayName":"CSS setting for Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_l_usethecsssettingforwordasanemaileditor_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_general_l_relyoncssforfontformatting_l_usethecsssettingforwordasanemaileditor_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_allowaccenteduppercaseinfrench","displayName":"Allow accented uppercase in French (User)","description":"Checks/Unchecks the option \"Enforce accented uppercase in French\".","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_allowaccenteduppercaseinfrench_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_allowaccenteduppercaseinfrench_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes","displayName":"Arabic modes (User)","description":"Specifies the spelling rules to use for checking spelling of Arabic text. This option is available only if you are using a right-to-left language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for the language, and have enabled support for the language through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_l_empty239","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_l_empty239_0","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_l_empty239_1","displayName":"Strict initial alef hamza","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_l_empty239_2","displayName":"Strict final yaa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_l_empty239_3","displayName":"Both strict","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_combineauxverbadj","displayName":"Combine aux verb/adj. (User)","description":"Checks/Unchecks the corresponding UI option. This option is available only if you are using the Korean language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for Korean, and have enabled support for Korean through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_combineauxverbadj_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_combineauxverbadj_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_flagrepeatedwords","displayName":"Flag Repeated Words (User)","description":"Allows users to flag or ignore repeated words.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_flagrepeatedwords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_flagrepeatedwords_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode","displayName":"Hebrew mode (User)","description":"Specifies the script to use for checking spelling of Hebrew text. This option is available only if you are using a right-to-left language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for that language, and have enabled support for the language through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_l_empty238","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_l_empty238_0","displayName":"Full","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_l_empty238_1","displayName":"Partial","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_l_empty238_2","displayName":"Mixed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_l_empty238_3","displayName":"Mixed authorized","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignoreinternetandfileaddresses","displayName":"Ignore Internet and file addresses (User)","description":"Allow users to ignore URLs and file paths.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignoreinternetandfileaddresses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignoreinternetandfileaddresses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignorewordsinuppercase","displayName":"Ignore words in UPPERCASE (User)","description":"Allow users to ignore words written in UPPERCASE.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignorewordsinuppercase_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignorewordsinuppercase_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignorewordswithnumbers","displayName":"Ignore words with numbers (User)","description":"Allows users to ignore words with numbers.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignorewordswithnumbers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_ignorewordswithnumbers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_processcompoundnouns","displayName":"Process compound nouns (User)","description":"Checks/Unchecks the corresponding UI option. This option is available only if you are using the Korean language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for Korean, and have enabled support for Korean through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_processcompoundnouns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_processcompoundnouns_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_suggestfrommaindictionaryonly","displayName":"Suggest from main dictionary only (User)","description":"Allows users to select words from main lexicon only.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_suggestfrommaindictionaryonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_suggestfrommaindictionaryonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_useautochangelist","displayName":"Use auto-change list (User)","description":"Checks/Unchecks the option \"Search misused word list\". This option is available only if you are using the Korean language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for Korean, and have enabled support for Korean through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_useautochangelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_useautochangelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_usegermanpostreformruleswhenrunningspellcheck","displayName":"German: Use post-reform rules (User)","description":"Allows users to choose a particular spellchecking style; Pre-reform or post reform.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_usegermanpostreformruleswhenrunningspellcheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_usegermanpostreformruleswhenrunningspellcheck_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling~l_proofingdatacollection_l_improveproofingtools","displayName":"Improve Proofing Tools (User)","description":"This policy setting controls whether the Help Improve Proofing Tools feature sends usage data to Microsoft. The Help Improve Proofing Tools feature collects data about use of the Proofing Tools, such as additions to the custom dictionary, and sends it to Microsoft. After about six months, the feature stops sending data to Microsoft and deletes the data collection file from the user's computer. \r\n\r\nIf you enable this policy setting, this feature is enabled if users choose to participate in the Customer Experience Improvement Program (CEIP). If your organization has policies that govern the use of external resources such as the CEIP, allowing the use of the Help Improve Proofing Tools feature might cause them to violate these policies. \r\n\r\nIf you disable this policy setting, the Help Improve Proofing Tools feature does not collect proofing tool usage information and transmit it to Microsoft. \r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"df357f0c-78fe-4aee-a465-f3da7499077e","categoryName":"Proofing Data Collection","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling~l_proofingdatacollection_l_improveproofingtools_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling~l_proofingdatacollection_l_improveproofingtools_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_allowwebarchivestobesavedinanyhtmlencoding","displayName":"Allow Web Archives to be saved in any HTML encoding (User)","description":"Enabled: Allow the user to save Web Archives in any HTML encoding.\r\n\r\nNot enabled: Always use US-ASCII for Web Archives.\r\n\r\nThis results in smaller files, but is not supported in Windows Internet Explorer 5.0 or earlier.","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_allowwebarchivestobesavedinanyhtmlencoding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_allowwebarchivestobesavedinanyhtmlencoding_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish","displayName":"Default format for 'Publish' (User)","description":"\"Web Archive (*.mht)\": The Publish command creates a Web Archive file. | \"Web Page (*.htm)\": The Publish command creates an HTML file. | \"Default\": The Publish command uses the default Web page format for publishing.","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish_l_defaultformatforpublish405","displayName":"Default format for 'Publish' (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish_l_defaultformatforpublish405_2","displayName":"Web Archive (*.mht)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish_l_defaultformatforpublish405_1","displayName":"Web Page (*.htm)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_defaultformatforpublish_l_defaultformatforpublish405_0","displayName":"Default","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointsaveanadditionalversionofthepresentationforolderbr","displayName":"PowerPoint: Save an additional version of the presentation for older browsers (User)","description":"Checked: PowerPoint publishes Web Archive presentations that contain a version of the presentation that is compatible with older browsers. | Unchecked: PowerPoint publishes Web Archive presentations that contain only the version of the presentation that is compatible with later browsers.","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointsaveanadditionalversionofthepresentationforolderbr_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointsaveanadditionalversionofthepresentationforolderbr_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility","displayName":"PowerPoint: web page format compatibility (User)","description":"\"All browsers\": Save new PowerPoint web pages in a format that is compatible with all browsers. | \"Windows Internet Explorer 4.0 or later\": Save new PowerPoint web pages in a format that requires Windows Internet Explorer 4.0 or later. | \"Based on installed browsers\": Examine the browsers installed on the user's computer and save new PowerPoint web pages in the smallest possible format that is compatible with all of the installed browsers.","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406","displayName":"PowerPoint: web page format compatibility (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406_2","displayName":"All browsers","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406_1","displayName":"Windows Internet Explorer 4.0 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406_0","displayName":"Based on installed browsers","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_savenewwebpagesaswebarchives","displayName":"Save new Web pages as Web archives (User)","description":"Checked: Use Web Archive (*.mht) as the default format for the Save as Web Page command (File menu). | Unchecked: Use Web page (*.htm) as the default format for the Save as Web Page command (File menu).","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_savenewwebpagesaswebarchives_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_savenewwebpagesaswebarchives_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding","displayName":"Web Archive encoding (User)","description":"\"Use 8 bit content-transfer-encoding\": Use a content-transfer-encoding of 8bit for all parts in a Web Archive file. | \"Use 8 bit only for encoding text parts\": Use a content-transfer-encoding of 8bit only for text parts. | \"Use RFC-approved encoding\": Always use RFC-approved encodings.","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding_l_webarchiveencoding402","displayName":"Web Archive encoding (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding_l_webarchiveencoding402_2","displayName":"Use 8 bit content-transfer-encoding","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding_l_webarchiveencoding402_1","displayName":"Use 8 bit only for encoding text parts","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_webarchiveencoding_l_webarchiveencoding402_0","displayName":"Use RFC-approved encoding","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationexcel","displayName":"Don’t show the What’s New information for Excel (User)","description":"This policy setting controls whether the What’s New information is shown when a user opens the desktop version of Excel for the first time after Excel has been updated with new features. By default, the What’s New information is shown.\r\n\r\nIf you enable this policy setting, the What’s New information isn’t shown. Also, the What’s New button in File > Account is disabled.\r\n\r\nIf you disable or don’t configure this policy setting, the What’s New information is shown.\r\n\r\nNote: There are separate policy settings for Word, Excel, PowerPoint, Outlook, OneNote, and Visio.\r\n ","helpText":"","infoUrls":[],"categoryId":"adf11731-7089-4e2e-8dde-4bd9ef86b067","categoryName":"What's New","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationonenote","displayName":"Don’t show the What’s New information for OneNote (User)","description":"This policy setting controls whether the What’s New information is shown when a user opens the desktop version of OneNote for the first time after OneNote has been updated with new features. By default, the What’s New information is shown.\r\n\r\nIf you enable this policy setting, the What’s New information isn’t shown. Also, the What’s New button in File > Account is disabled.\r\n\r\nIf you disable or don’t configure this policy setting, the What’s New information is shown.\r\n\r\nNote: There are separate policy settings for Word, Excel, PowerPoint, Outlook, OneNote, and Visio.\r\n ","helpText":"","infoUrls":[],"categoryId":"adf11731-7089-4e2e-8dde-4bd9ef86b067","categoryName":"What's New","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationonenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationonenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationoutlook","displayName":"Don’t show the What’s New information for Outlook (User)","description":"This policy setting controls whether the What’s New information is shown when a user opens the desktop version of Outlook for the first time after Outlook has been updated with new features. By default, the What’s New information is shown.\r\n\r\nIf you enable this policy setting, the What’s New information isn’t shown. Also, the What’s New button in File > Office Account is disabled.\r\n\r\nIf you disable or don’t configure this policy setting, the What’s New information is shown.\r\n\r\nNote: There are separate policy settings for Word, Excel, PowerPoint, Outlook, OneNote, and Visio.\r\n ","helpText":"","infoUrls":[],"categoryId":"adf11731-7089-4e2e-8dde-4bd9ef86b067","categoryName":"What's New","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationpowerpoint","displayName":"Don’t show the What’s New information for PowerPoint (User)","description":"This policy setting controls whether the What’s New information is shown when a user opens the desktop version of PowerPoint for the first time after PowerPoint has been updated with new features. By default, the What’s New information is shown.\r\n\r\nIf you enable this policy setting, the What’s New information isn’t shown. Also, the What’s New button in File > Account is disabled.\r\n\r\nIf you disable or don’t configure this policy setting, the What’s New information is shown.\r\n\r\nNote: There are separate policy settings for Word, Excel, PowerPoint, Outlook, OneNote, and Visio.\r\n ","helpText":"","infoUrls":[],"categoryId":"adf11731-7089-4e2e-8dde-4bd9ef86b067","categoryName":"What's New","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationvisio","displayName":"Don’t show the What’s New information for Visio (User)","description":"This policy setting controls whether the What’s New information is shown when a user opens the desktop version of Visio for the first time after Visio has been updated with new features. By default, the What’s New information is shown.\r\n\r\nIf you enable this policy setting, the What’s New information isn’t shown. Also, the What’s New button in File > Account is disabled.\r\n\r\nIf you disable or don’t configure this policy setting, the What’s New information is shown.\r\n\r\nNote: There are separate policy settings for Word, Excel, PowerPoint, Outlook, OneNote, and Visio.\r\n ","helpText":"","infoUrls":[],"categoryId":"adf11731-7089-4e2e-8dde-4bd9ef86b067","categoryName":"What's New","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationvisio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationvisio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationword","displayName":"Don’t show the What’s New information for Word (User)","description":"This policy setting controls whether the What’s New information is shown when a user opens the desktop version of Word for the first time after Word has been updated with new features. By default, the What’s New information is shown.\r\n\r\nIf you enable this policy setting, the What’s New information isn’t shown. Also, the What’s New button in File > Account is disabled.\r\n\r\nIf you disable or don’t configure this policy setting, the What’s New information is shown.\r\n\r\nNote: There are separate policy settings for Word, Excel, PowerPoint, Outlook, OneNote, and Visio.\r\n ","helpText":"","infoUrls":[],"categoryId":"adf11731-7089-4e2e-8dde-4bd9ef86b067","categoryName":"What's New","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_whatsnew_l_dontshowwhatsnewinformationword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_miscellaneous437_l_cloudonlysaving","displayName":"Restrict saving on non-Cloud locations (User)","description":"This policy setting controls whether Word, Excel, and PowerPoint users can use non-cloud locations (local and network) to create new files.\r\n\r\nIf you enable this policy setting, users will only have Cloud Locations available to perform SaveAs and Save new files.\r\n\r\nIf you disable or don’t configure this policy setting, users can use any location (Cloud, Local, and Network) to perform SaveAs and Save new files.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for Enterprise.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_miscellaneous437_l_cloudonlysaving_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_miscellaneous437_l_cloudonlysaving_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_shownfilefmtprompt","displayName":"Show the File Format dialog (User)","description":"This policy setting allows you to control whether the file format dialog has already been shown to the user. If you enable this policy setting, the dialog won't be shown again. If you disable this policy setting, the dialog prompts the user to select a default file format on each boot until one is selected. If you don't configure this policy setting, the dialog prompts the user to select a default file format on each boot until one is selected.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_shownfilefmtprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_shownfilefmtprompt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload","displayName":"Age out documents older than n days Including documents with pending uploads (User)","description":"\r\n This policy controls when locally cached Office documents are aged out of the Office Document Cache including if the file may have pending uploads. This acts as a maximum possible age (in days) for any file to remain in the Office Document Cache.\r\n\r\n If you enable this policy setting, files older than the policy \"Age out documents older than n days\" as well as this setting will get cleaned up regardless of file pending upload status.\r\n\r\n If you disable this policy setting or if you do not configure this policy setting, Office will clean out only files that do not have pending changes per the policy \"Age out documents older than n days\". Configuring this policy with a value of 0 is also considered disabling the policy.\r\n\r\n For more information https://support.microsoft.com/en-us/topic/managing-office-document-cache-size-ea64af72-b597-408e-8ecf-fd55daa02476\r\n\r\n Note: This policy setting only applies to Office builds 19328.20000 and newer\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload_l_ageoutpolicyincludingfilespendinguploaddecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_writingassistantadminchoiceadminchoice","displayName":"Enable Writing Assistant (User)","description":"This policy setting controls whether users can use the Writing Assistant feature.\r\n \r\nIf you enable or don’t configure this policy setting, users will be allowed to use Writing Assistant and it will be enabled by default (unless the users disabled it).\r\n\r\nIf you disable this policy setting, users won't see Writing Assistant by default.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for Enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_writingassistantadminchoiceadminchoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_writingassistantadminchoiceadminchoice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins","displayName":"List of allowed COM/VSTO add-ins registered in HKCU (User)","description":"This policy setting allows you to specify COM/VSTO add-ins registered in HKEY_CURRENT_USER (HKCU) that should be allowed to load, overriding the \"Block loading of COM/VSTO add-ins registered in HKCU\" policy.\r\n\r\nSome legitimate add-ins may be installed in HKCU even when deployed by administrators, due to how the independent software vendor (ISV) designed their installer. This policy provides an administrative override to allow specific add-ins to load despite being registered in HKCU.\r\n\r\nIf you enable this policy setting, you can specify a list of COM/VSTO add-ins that are allowed to load from HKCU. Enter each add-in using its ProgID as the name.\r\n\r\nIf you disable or don't configure this policy setting, the standard HKCU blocking behavior applies when that policy is enabled.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_l_allowedcomaddinslist","displayName":"Allowed COM/VSTO Add-ins: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_l_allowedcomaddinslist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_l_allowedcomaddinslist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockmotwmacrointrustedorsigned","displayName":"Block all internet macros (ignore trusted locations or publishers) (User)","description":"This policy setting removes the trusted location and trusted publisher exceptions for files downloaded from the internet with Mark of the Web (MOTW).\r\n\r\nBy default, Office blocks macros from the internet but allows exceptions for files that are either in trusted locations or signed by trusted publishers.\r\n\r\nIf you enable this policy setting, all macros in files downloaded from the internet will be blocked, including those in trusted locations or signed by trusted publishers. This provides maximum protection against internet-based macro threats.\r\n\r\nIf you disable or don't configure this policy setting, the default behavior applies where macros from the internet are blocked except when the file is in a trusted location or signed by a trusted publisher.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockmotwmacrointrustedorsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockmotwmacrointrustedorsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockvbamacrotrusteddocument","displayName":"Turn off Trusted Documents for VBA macros (User)","description":"This policy setting allows you to turn off the Trusted Documents feature for documents containing VBA macros.\r\n\r\nIf you enable this policy setting, users will always see security notifications for VBA macros in documents. When users click \"Enable Content\" for VBA macros, Office will not create a trust record for the document, ensuring that the user is prompted every time they open the document.\r\n\r\nIf you disable or don't configure this policy setting, the Trusted Documents feature allows users to always allow VBA macros in a document so that the user is not prompted the next time they open that document. Trusted documents are exempt from security notifications.\r\n\r\nNote: Enabling this policy setting does not clear existing trusted documents that were previously trusted.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockvbamacrotrusteddocument_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockvbamacrotrusteddocument_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_enablemacrotrustlevel","displayName":"Enable macro trust levels (User)","description":"This policy setting controls whether macro trust levels are enabled, which classifies VBA macros into four security levels based on file location and digital signature status.\r\n\r\nIf you enable this policy setting, VBA macros will be classified into the following trust levels with corresponding user experiences:\r\n\r\n- Lowest (Most Trusted): Files signed by a trusted publisher, saved to a trusted location, or unsaved files.\r\n - User Experience: No Message Bar displayed, macros load normally.\r\n\r\n- Lower: Files opened from a connected personal or business OneDrive account, connected SharePoint location, or local OneDrive folders.\r\n - User Experience: Yellow Message Bar with Enable Content option.\r\n\r\n- Moderate: Files opened from intranet locations, or signed with an extended validation (EV) certificate but not by a trusted publisher.\r\n - User Experience: Yellow Message Bar with a Learn More option. This encourages security awareness by requiring additional steps before enabling macros.\r\n\r\n- Highest (Least Trusted): All other files.\r\n - User Experience: Red Message Bar with macros blocked.\r\n\r\nWhen enabled, unsaved files containing macros will display a warning dialog when users attempt to save the file to local disk, informing them that saving locally may block macro execution when the file is reopened.\r\n\r\nIf you disable or don't configure this policy setting, macro trust levels are not enabled and the standard macro security behavior applies.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_enablemacrotrustlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_enablemacrotrustlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_requirealwaysonmacrosig","displayName":"Require trusted publisher signatures for macros that are always loaded (User)","description":"This policy setting controls signature requirements for macros that are automatically loaded when Office applications start.\r\n\r\nMacros that are always loaded include VBA add-ins and templates that load automatically: Excel add-ins (xla/xlam), PowerPoint add-ins (ppa/ppam), Access add-ins (accda/mda), and Word templates (dot/dotm).\r\n\r\nIf you enable this policy setting:\r\n- Unsigned macros that are always loaded are silently disabled and don't load.\r\n- Signed but untrusted macros that are always loaded display a red Message Bar with no option for users to enable them for the current session.\r\n- Macros signed by a trusted publisher are allowed to always load.\r\n\r\nIf you disable or don't configure this policy setting, macros that are always on can load without requiring trusted publisher signatures.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_requirealwaysonmacrosig_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_requirealwaysonmacrosig_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_restrictcucomaddin","displayName":"Block loading of COM/VSTO add-ins registered in HKCU (User)","description":"This policy setting controls whether COM/VSTO add-ins registered only in HKEY_CURRENT_USER (HKCU) are blocked from loading.\r\n\r\nStandard users can install add-ins through ClickOnce deployment or the Office Add-ins settings, which typically register add-ins in HKCU rather than HKEY_LOCAL_MACHINE (HKLM).\r\n\r\nIf you enable this policy setting, all COM/VSTO add-ins registered only in HKCU will be blocked from loading, preventing users from running add-ins they have installed without administrator privileges.\r\n\r\nIf you disable or don't configure this policy setting, COM/VSTO add-ins registered in HKCU are allowed to load normally.\r\n\r\nNote: Add-ins registered in HKLM (typically installed by administrators) are not affected by this policy setting.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_restrictcucomaddin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_restrictcucomaddin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_vbadigsigchaintrustedpublishers","displayName":"Allow root or intermediate certificates as VBA trusted publishers (User)","description":"This policy setting controls whether root and intermediate certificates can be added as trusted publishers for VBA macro validation when the VBA Macro Notification Settings policy is set to \"Disable all except digitally signed macros\".\r\n\r\nIf you enable this policy setting, administrators can add root or intermediate certificates to the trusted publishers store. VBA macros signed by any certificate that chains to these trusted root or intermediate certificates will be considered as signed by a trusted publisher and allowed to run.\r\n\r\nIf you disable or don't configure this policy setting, only end (leaf) certificates can be added as trusted publishers.\r\n\r\nNote: This policy setting only takes effect when the VBA Macro Notification Settings policy is set to \"Disable all except digitally signed macros\".","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_vbadigsigchaintrustedpublishers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_vbadigsigchaintrustedpublishers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v22~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelastmileinappmessaging","displayName":"Disable Last-Mile In-App Messages (User)","description":"This policy setting prevents Office from displaying bizbar messages to the user about last-mile (environmental) issues affecting their experience.\r\n\r\nIf you disable or don’t configure this policy setting, Office will display last-mile messages by default as they are encountered.\r\n\r\nIf you enable this policy setting, Office will not display the configured last-mile in-app messages when they are encountered.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v22~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelastmileinappmessaging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v22~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelastmileinappmessaging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockinsecureprotocols","displayName":"Block Insecure Protocols (User)","description":"\r\n\t\t\tThis policy setting allows you to control which protocols can be used when opening documents in Microsoft 365 apps.\r\n\r\n\t\t\tIf you enable this policy setting, non-HTTPS links will be blocked when opening documents in Microsoft 365 apps.\r\n\r\n\t\t\tIf you disable this policy setting, all protocols and links will be allowed when opening documents in Microsoft 365 apps.\r\n\r\n\t\t\tIf you don't configure this policy setting, all protocols and links will be allowed when opening documents in Microsoft 365 apps.\r\n\t\t","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockinsecureprotocols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockinsecureprotocols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockolegraph","displayName":"Block OLE Graph (User)","description":"This policy setting allows you to control whether Object Linking and Embedding (OLE) Graph functionality runs in Microsoft 365 apps.\r\n\r\nIf you enable this policy setting, OLE Graph, including MSGraph.Application and MSGraph.Chart, will not run in any Microsoft 365 app. Instead, a static image will render in its place.\r\n\r\nIf you disable this policy setting, OLE Graph will run in Microsoft 365 apps.\r\n\r\nIf you don't configure this policy setting, OLE Graph will run in Microsoft 365 apps.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockolegraph_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockolegraph_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockorgchart","displayName":"Block OrgChart (User)","description":"This policy setting allows you to control whether Organization Chart (OrgChart) Add-in for Microsoft Office programs runs in Microsoft 365 apps.\r\n\r\nIf you enable this policy setting, OrgChart will not run in any Microsoft 365 app. Instead, a static image will render in its place.\r\n\r\nIf you disable this policy setting, OrgChart will run in Microsoft 365 apps.\r\n\r\nIf you don't configure this policy setting, OrgChart will run in Microsoft 365 apps.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockorgchart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockorgchart_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockwecfallback","displayName":"Restrict Apps from FPRPC Fallback (User)","description":"\r\n\t\t\tThis policy setting allows you to control the fallback behavior of Microsoft 365 apps when using FrontPage Server Extensions Remote Procedure Call Protocol (FPRPC).\r\n\r\n\t\t\tIf you enable this policy setting, Microsoft 365 apps will not use FPRPC.\r\n\r\n\t\t\tIf you disable this policy setting, Microsoft 365 apps will continue to use FPRPC.\r\n\r\n\t\t\tIf you don't configure this policy setting, Microsoft 365 apps will continue to use FPRPC.\r\n\t\t","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockwecfallback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockwecfallback_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3.1~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableroamingmruforonpremservers","displayName":"Turn off roaming of on-premises file names and metadata (User)","description":"\r\nThis policy setting controls whether file names and metadata for Office files are roamed and appear in the list of recently opened files in an Office app, such as Word, on different devices.\r\n\r\nRoaming, which relies on a web-based Microsoft service, occurs when a user signs into Office with the same work or school account on different devices.\r\n\r\nNote: This policy setting only applies to Office files that are saved to on-premises instances of SharePoint Server or OneDrive for Business.\r\n\r\nIf you enable this policy setting, file names and metadata won't roam and won’t appear in the list of recently opened files in Office apps on other devices, unless the file has been opened on that device.\r\n\r\nIf you disable or don't configure this policy setting, file names and metadata will roam and will appear in the list of recently opened files in Office apps on other devices, even if the file hasn’t been opened on that device.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v3.1~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableroamingmruforonpremservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3.1~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableroamingmruforonpremservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_collaborationsettings_l_documentchat","displayName":"Allow co-authors to chat within a document (User)","description":"This policy setting controls whether co-authors can use the chat functionality within an Office application to collaborate with each other when editing a document.\r\n\r\nIf you enable or don’t configure this policy setting, users can chat with each other when co-authoring a document.\r\n\r\nIf you disable this policy setting, users can’t chat with each other when co-authoring a document.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_collaborationsettings_l_documentchat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_collaborationsettings_l_documentchat_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser","displayName":"Default Office theme (User)","description":"This policy setting allows you to select the user interface (UI) theme used by Office, if the user has not already selected an Office theme.\r\n\r\nNote: This setting only applies to Version 1903 or later of Office.\r\n\r\nIf you enable this policy setting, you may choose the Office theme used in cases where the user has not selected an Office theme themselves.\r\n\r\nIf you disable or do not configure this policy setting, Office will use the Colorful theme in cases where the user has not selected an Office theme themselves.\r\n\r\nRegardless of how you configure this policy setting, users can change their Office theme by going to File > Account > Office Theme (or, in Outlook, by going to File > Office Account > Office Theme).\r\n\r\nNote: The “Default Office theme” policy setting located under Computer Configuration takes precedence over this policy setting.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum","displayName":"Theme: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_0","displayName":"Colorful","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_3","displayName":"Dark Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_4","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_5","displayName":"White","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableroamingmruforonpremservers","displayName":"Turn off roaming of on-premises file names and metadata (User)","description":"\r\nThis policy setting controls whether file names and metadata for Office files are roamed and appear in the list of recently opened files in an Office app, such as Word, on different devices.\r\n\r\nRoaming, which relies on a web-based Microsoft service, occurs when a user signs into Office with the same work or school account on different devices.\r\n\r\nNote: This policy setting only applies to Office files that are saved to on-premises instances of SharePoint Server or OneDrive for Business.\r\n\r\nIf you enable this policy setting, file names and metadata won't roam and won’t appear in the list of recently opened files in Office apps on other devices, unless the file has been opened on that device.\r\n\r\nIf you disable or don't configure this policy setting, file names and metadata will roam and will appear in the list of recently opened files in Office apps on other devices, even if the file hasn’t been opened on that device.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableroamingmruforonpremservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableroamingmruforonpremservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_miscellaneous437_l_officeinsideruserexperience","displayName":"Show the option for Office Insider (User)","description":"This policy setting controls whether the option for Office Insider is shown under File > Account in an Office app, such as Word.\r\n\r\nBy showing this option, a user can choose to join or leave the Office Insider program. For more information about the Office Insider program, see https://insider.office.com.\r\n\r\nIf you enable this policy setting, the option for Office Insider is shown under File > Account.\r\n\r\nNote: if you enable this policy setting, you shouldn’t enable and configure the “Update Channel” or the “Update Path” policy setting under Computer Configuration\\Policies\\Administrative Templates\\Microsoft Office 2016 (Machine)\\Updates. If you do, those policy settings will take precedence, even though the option for Office Insider is shown.\r\n\r\nIf you disable this policy setting, the option for Office Insider is not shown under File > Account.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus, and to subscription versions of Project and Visio.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_miscellaneous437_l_officeinsideruserexperience_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_miscellaneous437_l_officeinsideruserexperience_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_forceruntimeavscan","displayName":"Force Runtime AV Scan (User)","description":"This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus or Visio Pro for Office 365. \r\n\r\nThis policy setting controls when Office files are scanned at runtime by an installed Anti-Virus software.\r\n\r\nNote, files will only be scanned if the Anti-Virus software registers as a provider for runtime scanning.\r\n\r\nIf you enable this policy setting, Office applications will submit all files for a runtime scan by Antivirus.\r\n\r\nIf you disable or do not configure this policy setting, Office will selectively submit certain files, for example encrypted files, for a runtime scan by Antivirus.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_forceruntimeavscan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_forceruntimeavscan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_useofficeforlabelling","displayName":"Use the Sensitivity feature in Office to apply and view sensitivity labels (User)","description":"This policy setting controls whether sensitivity labels configured by an admin can be applied and viewed by using the Sensitivity feature in an Office app, such as Word, or by using the Microsoft Azure Information Protection add-in, if the add-in is installed and enabled.\r\n\r\nIf you enable this policy setting, the Sensitivity feature in an Office app can be used to apply and view sensitivity labels. If the Microsoft Azure Information Protection add-in is installed, the add-in is prevented from loading, even if the add-in is enabled, and the add-in can’t be used to apply sensitivity labels.\r\n\r\nIf you disable this policy setting, the Sensitivity feature won’t be available in an Office app and can’t be used to apply or view sensitivity labels. If the Microsoft Azure Information Protection add-in is installed and enabled, the add-in will be allowed to load and can be used to apply sensitivity labels.\r\n\r\nIf you don’t configure this policy setting:\r\n\r\n- If the Microsoft Azure Information Protection add-in is installed and enabled, the add-in will be allowed to load and can be used to apply sensitivity labels. The Sensitivity feature won’t be available in an Office app and can’t be used to apply or view sensitivity labels.\r\n- If the Microsoft Azure Information Protection add-in is not installed, or is installed but is disabled, then the Sensitivity feature in an Office app can be used to apply and view sensitivity labels.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_useofficeforlabelling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_useofficeforlabelling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior","displayName":"Control how Office handles form-based sign-in prompts (User)","description":"This policy setting controls how Office applications handle form-based sign-in prompts.​\r\n\r\nIf you enable this policy setting, you must choose one of the following options:​\r\n\r\nBlock all prompts​\r\nAsk the user what to do for each new host​\r\nShow prompts only from allowed hosts​\r\n\r\nIf you select “Block all prompts” then no form-based sign-in prompts are shown to the user and the user is shown a message that the sign-in method isn’t allowed.​\r\n\r\nIf you select “Ask the user what do for each new host” then the user is asked for each new host whether the user wants to sign-in to the host. If the user has previously signed-in to a host, a form-based sign-in prompt is shown for that host. Also, form-based sign-in prompts are shown for any hosts specified by the “Specify hosts allowed to show form-based sign-in prompts to users” setting.\r\n\r\nIf you select “Show prompts only from allowed hosts” then form-based sign-in prompts are shown only from hosts that have been specified by the additional “Specify hosts allowed to show form-based sign-in prompts to users” setting. Form-based sign-in prompts from all other hosts are blocked and the user is shown a message that the sign-in method isn’t allowed.\r\n\r\nNote: If you don’t configure the “Specify hosts allowed to show form-based sign-in prompts to users” setting or don’t specify any hosts in that setting, then the behavior of the “Show prompts only from allowed hosts” option will be the same as if you selected the “Block all prompts” option.\r\n\r\nIf you disable or don’t configure this policy setting, all form-based sign-in prompts are blocked and the user is shown a message that the sign-in method isn’t allowed. But users are able to change the behavior for form-based sign-in prompts by going to File > Options > Trust Center > Trust Center Settings > Form-based sign-in.\r\n\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus, and to subscription versions of Project and Visio.​","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_l_authenticationfbabehaviorenum","displayName":"Behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_l_authenticationfbabehaviorenum_1","displayName":"Block all prompts","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_l_authenticationfbabehaviorenum_2","displayName":"Ask the user what to do for each new host","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_l_authenticationfbabehaviorenum_3","displayName":"Show prompts only from allowed hosts","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v5~policy~l_microsoftofficesystem~l_securitysettings_l_authenticationfbabehavior_l_authenticationfbaenabledhostsid","displayName":"Specify hosts allowed to show form-based sign-in prompts to users: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_allowvbaintranetrefs","displayName":"Allow VBA to load typelib references by path from untrusted intranet locations (User)","description":"This policy setting permits VBA to load typelib references by explicit path read from the project data if that path points to an intranet location that is not explicitly in the system trusted sites list.\r\n\r\nBy default, VBA will attempt to load typelibs referenced in a project by searching for the library GUID in the registry. If it is not found in the registry, VBA will attempt to load the typelib or project reference using the path stored in the project for the reference as long as the reference does not point to an internet or intranet location that is not in the trusted sites list.\r\n\r\nIf you enable this policy setting, VBA will treat intranet paths like local machine paths, and therefore VBA will attempt to search for unregistered references in intranet locations that are not local machine or in the system's trusted sites list.\r\n\r\nIf you disable or don’t configure this policy setting, VBA maintains its default behavior and will refuse to load typelibs on intranet paths if it does not find the typelib registered in HKEY_CLASSES_ROOT.\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_allowvbaintranetrefs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_allowvbaintranetrefs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_disablestrictvbarefssecuritypolicy","displayName":"Disable additional security checks on VBA library references that may refer to unsafe locations on the local machine (User)","description":"This policy setting restricts VBA to checking project library references only against the registry and trusted zones. By default VBA performs additional checks against library paths to prevent loading references from potentially unsafe locations on the local machine as well. It is recommended that this setting remain 0 or unset to allow for the more secure default behavior. Only enable this setting if the default behavior is causing compatibility issues with critical solutions, and then, only to provide time to migrate the solutions to address the less secure behavior, at which point the setting should be turned off again.\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_disablestrictvbarefssecuritypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_disablestrictvbarefssecuritypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7.updates~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey","displayName":"Allow users to receive and respond to in-product surveys from Microsoft (User)","description":"This policy setting allows you to control whether your users can receive and respond to in-product surveys in Microsoft 365 products. Microsoft will use this feedback to improve the product experience for users. The ability to receive and respond to in-product surveys is enabled by default.\r\n\r\nIf you enable this policy setting, your users will be able to receive and respond to in-product surveys about their experience using Microsoft 365 products.\r\n\r\nIf you disable this policy setting, Microsoft will not survey your users while they are using Microsoft 365 products.\r\n\r\nIf you don't configure this policy setting, your users will be able to receive and respond to in-product surveys about their experience using Microsoft 365 products.\r\n\r\nComing soon, you will be able to view and manage feedback from your org in the Microsoft 365 admin center.\r\n\r\nNote: This data will be considered \"Feedback\" under your Microsoft 365 agreement, including information that would otherwise be considered \"Customer Data\" or \"Personal Data\".\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2142253","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v7.updates~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7.updates~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_miscellaneous437_l_personalizationhomeuseprogram","displayName":"Show in-product notifications for the Microsoft Home Use Program (User)","description":"This policy setting controls whether notifications about the Microsoft Home Use Program (HUP) are displayed to end-users in Office applications.\r\n\r\nIf you enable this policy setting, Office will occasionally notify end-users if they are eligible to purchase an Office subscription for their personal use at a discount via the Microsoft Home Use Program. End-users can permanently opt-out of these notifications at any time using a button within the notification.\r\n\r\nIf you disable this policy setting, Office will not display any notifications related to the Microsoft Home Use Program.\r\n\r\nIf you don't configure this policy setting, Microsoft will control whether or not these notifications appear. Please check the Message Center in the Microsoft 365 admin center for updates on whether this feature has been enabled by Microsoft yet and the default setting for the notifications.\r\n\r\nFor more information, see https://aka.ms/huplearnmore.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_miscellaneous437_l_personalizationhomeuseprogram_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_miscellaneous437_l_personalizationhomeuseprogram_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_emailcollection","displayName":"Allow Microsoft to follow up on feedback submitted by users (User)","description":"This policy setting controls whether Microsoft can follow up on feedback submitted by users to help understand the feedback, troubleshoot an issue submitted through feedback, or share back how Microsoft used the feedback to improve the product.\r\n\r\nMicrosoft may send transactional emails or request follow-up conversations via email, voice, or other means related to the feedback or survey response. In some circumstances, Microsoft may ask for additional information to assist with troubleshooting.\r\n\r\nIf you enable this policy setting, Microsoft may follow up on feedback submitted. \r\n\r\nIf you disable or don’t configure this policy setting, Microsoft will not follow up on feedback submitted by your users.\r\n\r\nComing soon, you will be able to view and manage feedback from your org in the Microsoft 365 admin center.\r\n\r\nNote: This policy setting has no effect if the \"Allow users to submit feedback to Microsoft\" policy setting or the “Allow users to receive and respond to in-product surveys from Microsoft” policy setting is set to Disabled.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2142253","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_emailcollection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_emailcollection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey","displayName":"[Deprecated] Allow users to receive and respond to in-product surveys from Microsoft (User)","description":"This policy setting allows you to control whether your users can receive and respond to in-product surveys in Microsoft 365 products. Microsoft will use this feedback to improve the product experience for users. The ability to receive and respond to in-product surveys is enabled by default.\r\n\r\nIf you enable this policy setting, your users will be able to receive and respond to in-product surveys about their experience using Microsoft 365 products.\r\n\r\nIf you disable this policy setting, Microsoft will not survey your users while they are using Microsoft 365 products.\r\n\r\nIf you don't configure this policy setting, your users will be able to receive and respond to in-product surveys about their experience using Microsoft 365 products.\r\n\r\nComing soon, you will be able to view and manage feedback from your org in the Microsoft 365 admin center.\r\n\r\nNote: This data will be considered \"Feedback\" under your Microsoft 365 agreement, including information that would otherwise be considered \"Customer Data\" or \"Personal Data\".\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2142253","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions","displayName":"Disable 3D Model File Formats List (User)","description":"This policy setting allows you to specify a list of 3D model file formats that will be blocked from being loaded in Office applications.\r\n\r\nIf you enable this policy setting, you can specify a list of 3D Model file format that Office applications will block on insert or load. You should specify the list of 3D model file formats to block in a list of files extensions. For example, to block the FBX extension, enter the string “FBX”. To block the FBX and OBJ extensions, enter the string “FBX; OBJ”.\r\n\r\nIf you disable or do not configure this policy setting, Office applications do not restrict any 3D model file formats.\r\n","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions_l_model3dblocklist","displayName":"List of file extensions to block: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffcameraandmicrophoneinapplicationguard","displayName":"Turn off camera and microphone access for Office apps using Application Guard. (User)","description":"The policy allows you to control whether Office apps using Application Guard can access the user's camera and microphone if they're enabled on the user's device.\r\n\r\nImportant: A compromised Application Guard container could bypass camera and microphone permissions and access the camera and microphone without the user’s knowledge. To prevent unauthorized access, we recommend that the camera and microphone be turned off on the user’s device when they aren’t needed.\r\n\r\nIf you enable this policy setting, Office apps using Application Guard won't be able to access the camera and microphone on the user’s device. \r\n\r\nIf you disable or don't configure this policy setting, Office apps using Application Guard will be able to access the camera and microphone on the user’s device.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffcameraandmicrophoneinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffcameraandmicrophoneinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffclipboardaccessinapplicationguard","displayName":"Don't allow copy and paste from Office documents opened in Application Guard. (User)","description":"This policy setting allows you to control whether users can copy and paste content from Office to and from documents opened in Application Guard.\r\nNote: Application Guard only allows copying text and images and doesn’t allow copying of rich content.\r\n\r\nIf you enable this policy setting, users can't copy and paste content to and from documents opened in Application Guard to other locations outside Application Guard.\r\n\r\nIf you disable or don't configure this policy setting, users can copy and paste content to and from documents opened in Application Guard to other locations outside Application Guard.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffclipboardaccessinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffclipboardaccessinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffhardwareaccelerationinapplicationguard","displayName":"Disable hardware acceleration for Office in Application Guard. (User)","description":"This policy setting controls whether Office in Application Guard uses hardware or software acceleration to render graphics.\r\n\r\nIf you enable this setting, Application Guard uses software-based (CPU) rendering and won’t load any third-party graphics drivers or interact with any connected graphics hardware.\r\n\r\nImportant: Be aware that disabling or not configuring this policy setting with potentially compromised graphics devices or drivers might pose a risk to the user's device.\r\n\r\nIf you disable or don't configure this setting, Application Guard uses Hyper-V to access supported, high-security rendering graphics hardware (GPUs). These GPUs improve rendering performance and battery life while using Application Guard, particularly for video playback and other graphics-intensive operations. If you disable or don't configure this setting without connecting any high-security rendering graphics hardware, Application Guard will automatically revert to software-based (CPU) rendering.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise. ","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffhardwareaccelerationinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffhardwareaccelerationinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffofficeinapplicationguard","displayName":"Don't use Application Guard with Office. (User)","description":"This policy setting allows you to control whether Office apps use Application Guard to isolate untrusted documents.\r\n\r\nIf you enable this policy setting, Office apps won't use Application Guard to isolate untrusted documents even if the device is configured to use Application Guard. Instead, Office will use Protected View to isolate untrusted documents.\r\n\r\nNote: You should consider enabling this policy setting if you want to stop Office apps from using Application Guard without impacting the use of Application Guard with other applications.\r\n\r\nIf you disable or don't configure this policy settings, Office apps will use Application Guard to isolate untrusted documents. The device must be configured to use Application Guard and the user must be licensed to use Application Guard.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffofficeinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffofficeinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard","displayName":"Restrict printing from Office of documents opened in Application Guard. (User)","description":"This policy setting allows you to control how users can print from Office documents opened in Application Guard. \r\nIf you enable this policy setting, you can choose to selectively retrict one or more of the following printing options.\r\n- Don't allow printing to XPS, prevents users from printing as XPS and saving the resulting file on the host. \r\n- Don't allow printing to PDF, prevents users from printing as PDF and saving the resulting file on the host. \r\n- Don't allow printing to local printers, prevents users from printing to locally attached printers. \r\n- Don't allow printing to existing network printers, prevents users from printing to previously connected network printers. Also, users can't search for additional printers.\r\nNote: if you select all the choices or don’t select any of the choices, then printing isn’t allowed in Application Guard.\r\n\r\nIf you disable or don’t configure this policy setting, users can print to all printers configured on their device.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnofflocalprintinginapplicationguard","displayName":"Disable Local printing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnofflocalprintinginapplicationguard_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnofflocalprintinginapplicationguard_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffnetworkprintinginapplicationguard","displayName":"Disable Network printing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffnetworkprintinginapplicationguard_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffnetworkprintinginapplicationguard_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffpdfprintinginapplicationguard","displayName":"Disable PDF printing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffpdfprintinginapplicationguard_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffpdfprintinginapplicationguard_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffxpsprintinginapplicationguard","displayName":"Disable XPS printing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffxpsprintinginapplicationguard_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffprintsettingsinapplicationguard_l_turnoffxpsprintinginapplicationguard_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnofftrustpromotionfordocumentsinapplicationguard","displayName":"Prevent users from removing Application Guard protection on files. (User)","description":"This policy setting allows you to control whether users can remove Application Guard protection and open a document with full trust in Office.\r\n\r\nIf you enable this policy setting, users can continue to work with Office documents in Application Guard, however, they cannot remove protection and open a document outside Application Guard.\r\n\r\nIf you disable or do not configure this policy settings, Office will by default allow users to remove protection and open a document with full trust.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnofftrustpromotionfordocumentsinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnofftrustpromotionfordocumentsinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_logcollection","displayName":"Allow users to include log files and content samples when they submit feedback to Microsoft (User)","description":"This policy setting controls whether your users see an option to include log files and content samples when they submit feedback to Microsoft.\r\n\r\nLog files and content samples help Microsoft troubleshoot product issues and Microsoft will use this information to improve product experiences for users. The option to include log files and content samples when submitting feedback to Microsoft is disabled by default.\r\n\r\nIf you enable this policy setting, your users will see an option to include log files and content samples when they submit feedback to Microsoft.\r\n\r\nIf you disable or don’t configure this policy setting, your users will not see an option to include log files and content samples when they submit feedback to Microsoft.\r\n\r\nComing soon, you will be able to view and manage feedback from your org in the Microsoft 365 admin center.\r\n\r\nNote: This policy setting has no effect if the \"Allow users to submit feedback to Microsoft\" policy setting is set to Disabled.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2142253","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_logcollection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_logcollection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_onlytrustvbasignaturev3","displayName":"Only trust VBA macros that use V3 signatures (User)","description":"This policy setting controls whether only VBA macros that use V3 signatures can be trusted and run in the application.\r\n\r\nIf you enable this policy setting, only VBA macros that use V3 signatures can be trusted and run in the application.\r\n\r\nIf you enable this policy setting, we also recommend that you enable the “VBA Macro Notification Settings” policy setting for the application and then select the “Disable all except digitally signed macros” option.\r\n\r\nNote: Before enabling this policy setting, you should upgrade your existing VBA macros to use V3 signatures.\r\n\r\nIf you disable or don’t configure this policy setting, VBA macros signed with legacy signature schemes can be trusted and run in the application.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_onlytrustvbasignaturev3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_onlytrustvbasignaturev3_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_configureprecreateinapplicationguard","displayName":"Configure Application Guard container precreation. (User)","description":"This policy setting determines if the Application Guard container, for isolating untrusted files, is pre-created for improved run time performance.\r\n\r\nIf you enable this policy setting, you can specify the number of days to continue pre-creating an Application Guard container if the user has not opened a file with Application Guard. Pre-creating a container when the user logs in will decrease the wait time when opening an untrusted file.\r\n\r\n“65535” will configure Office to always create an Application Guard container when a user logs into Windows.\r\n\"20\" will configure Office to pre-create the container each time a user logs into Windows for up to 20 days after the last time the user opened an untrusted file using Application Guard.\r\n“0” will configure Office to never pre-create the container. Instead the container will only be created when a user opens their first untrusted file after logging into Windows.\r\n\r\nNote: if you configure Office to never pre-create a container then users will experience a longer wait when opening an untrusted file after logging into Windows.\r\n\r\nIf you disable or don’t configure this setting, Office will use a built-in heuristic to pre-create the container.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_configureprecreateinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_configureprecreateinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v8~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_configureprecreateinapplicationguard_l_setappguardprewarmwindowvalue","displayName":"Pre-Create Window (days): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser","displayName":"Show the option for the Office Update Channel experience (User)","description":"This policy setting controls whether the option for Update Channel experience is shown under File > Account on an Office app, such as Word.\r\n\r\nBy showing this option, a user can choose to receive Office updates from the Office update channels that the administrator chooses to expose to the users.\r\n\r\nIf you enable this policy setting, the option for Update Channel experience is shown under File > Account.\r\n\r\nNote: This policy supersedes the “Show the option for Office Insider” in cases where both policies are configured.\r\n\r\nNote: If you enable this policy setting, you shouldn’t enable and configure the “Target Version”, “Update Channel” or the “Update Path” policy setting under Computer Configuration\\Policies\\Administrative Templates\\Microsoft Office 2016 (Machine)\\Updates. If you do, those policy settings will take precedence, blocking user access to the Office Update Channel experience.\r\n\r\nIf you disable this policy setting, the option for Office Channel experience is not shown under File > Account.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderfast","displayName":"Beta Channel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderfast_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderfast_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderslow","displayName":"Current Channel (Preview) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderslow_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderslow_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_mec","displayName":"Monthly Enterprise Channel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_mec_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_mec_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_production","displayName":"Current Channel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_production_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_production_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_sae","displayName":"Semi-Annual Enterprise Channel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_sae_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_sae_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_saepreview","displayName":"Semi-Annual Enterprise Channel (Preview) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_saepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_saepreview_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffblockingofunsupportedfiletypesinapplicationguard","displayName":"Turn off protection of unsupported file types in Application Guard for Office. (User)","description":"This policy setting controls whether Application Guard for Office will block unsupported file types from being opened in Office apps or if it will enable the redirection to Protected View.\r\n\r\nIf you enable this setting, Application Guard for Office will redirect unsupported file types to Protected View in Office apps.\r\n\r\nImportant: Be aware that enabling this policy setting might pose a risk to the user's device.\r\n\r\nIf you disable or don't configure this setting, Application Guard for Office will block unsupported file types in Office apps.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffblockingofunsupportedfiletypesinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffblockingofunsupportedfiletypesinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites","displayName":"Configure team site libraries to sync automatically (User)","description":"This setting lets you specify SharePoint team site libraries to sync automatically the next time users sign in to the OneDrive sync app (OneDrive.exe). It may take up to 8 hours after a users signs in before the library begins to sync. To use the setting, you must enable OneDrive Files On-Demand, and the setting applies only for users on computers running Windows 10 (1709) Fall Creators Update or later. Do not enable this setting for the same library to more than 1,000 devices. To ensure a good sync experience, avoid enabling this feature on large libraries sets (For the most up to date guidance see https://docs.microsoft.com/en-us/onedrive/use-group-policy#AutoMountTeamSites). This feature is not enabled for on-premises SharePoint sites.\r\n \r\nIf you enable this setting, the OneDrive sync app will automatically download the contents of the libraries you specified as online-only files the next time the user signs in. The user won't be able to stop syncing the libraries.\r\n \r\nIf you disable this setting, team site libraries that you've specified won't be automatically synced for new users. Existing users can choose to stop syncing the libraries, but the libraries won't stop syncing automatically.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_automountteamsiteslistbox","displayName":"Libraries: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_automountteamsiteslistbox_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_automountteamsiteslistbox_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir","displayName":"Set the default location for the OneDrive folder (User)","description":"This setting lets you set a specific path as the default location of the OneDrive folder on users' computers. By default, the path is under %userprofile%.\r\n\r\nIf you enable this setting, the default location of the OneDrive - {organization name} folder will be the path that you specify in the OneDrive.admx file. To prevent users from changing the location you specify, enable the \"Prevent users from changing the location of their OneDrive folder\" setting.\r\n\r\nIf you disable or do not configure this setting, the default location of the OneDrive - {organization name} folder will be in %userprofile%.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_defaultrootdirlist","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_defaultrootdirlist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_defaultrootdirlist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot","displayName":"Prevent users from changing the location of their OneDrive folder (User)","description":"This setting lets you block users from changing the location of their OneDrive - {organization name} folder during setup of the OneDrive sync app.\r\n\r\nIf you enable this setting, the \"Change location\" link is hidden in OneDrive Setup. The OneDrive folder will be created in the default location, or in the custom location you specified if you enabled the \"Set the default location for the OneDrive folder\" setting.\r\n\r\nIf you disable or do not configure this setting, users can click the \"Change location\" link to change the location of their OneDrive folder in OneDrive Setup.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_disablecustomrootlist","displayName":"Change location setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_disablecustomrootlist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_disablecustomrootlist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablefretutorial","displayName":"Disable the tutorial that appears at the end of OneDrive Setup (User)","description":"This setting lets you prevent the tutorial from launching in a web browser at the end of OneDrive Setup.\r\n\r\nIf you enable this setting, users will not see the tutorial after they complete OneDrive Setup.\r\n\r\nIf you disable or do not configure this setting, the tutorial will appear at the end of OneDrive Setup.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablefretutorial_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablefretutorial_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonbatterysaver","displayName":"Continue syncing when devices have battery saver mode turned on (User)","description":"This setting lets you turn off the auto-pause feature for devices that have battery saver mode turned on.\r\n\r\nIf you enable this setting, syncing will continue when users turn on battery saver mode. OneDrive will not automatically pause syncing.\r\n\r\nIf you disable or do not configure this setting, syncing will pause automatically when battery saver mode is detected and a notification will be displayed. Users can choose not to pause syncing by clicking \"Sync Anyway\" in the notification. When syncing is paused, users can resume syncing by clicking the OneDrive cloud icon in the notification area of the taskbar and then clicking the alert at the top of the activity center.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonbatterysaver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonbatterysaver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonmeterednetwork","displayName":"Continue syncing on metered networks (User)","description":"This setting lets you turn off the auto-pause feature when devices connect to metered networks.\r\n\r\nIf you enable this setting, syncing will continue when devices are on a metered network. OneDrive will not automatically pause syncing.\r\n\r\nIf you disable or do not configure this setting, syncing will pause automatically when a metered network is detected and a notification will be displayed. Users can choose not to pause syncing by clicking \"Sync Anyway\" in the notification. When syncing is paused, uers can resume syncing by clicking the OneDrive cloud icon in the notification area of the taskbar and then clicking the alert at the top of the activity center.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonmeterednetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonmeterednetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepersonalsync","displayName":"Prevent users from syncing personal OneDrive accounts (User)","description":"This setting lets you block users from signing in with a Microsoft account to sync their personal OneDrive files.\r\n\r\nIf you enable this setting, users will be prevented from setting up a sync relationship for their personal OneDrive account. Users who are already syncing their personal OneDrive when you enable this setting won't be able to continue syncing (and will be shown a message that syncing has stopped), but any files synced to the computer will remain on the computer.\r\n\r\nIf you disable or do not configure this setting, users can sync their personal OneDrive accounts.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepersonalsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepersonalsync_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_downloadbandwidthlimit","displayName":"Limit the sync app download speed to a fixed rate (User)","description":"This setting lets you configure the maximum speed at which the OneDrive sync app (OneDrive.exe) can download files. This rate is a fixed value in kilobytes per second, and applies only to syncing, not to downloading updates. The lower the rate, the slower files will download. The minimum rate that can be set is 1 KB/s and the maximum rate is 100000 KB/s. Any input lower than 50 KB/s will set the limit to 50 KB/s, even if the UI shows the inputted rate.\r\nIf you enable this setting, computers will use the maximum download rate that you specify, and users will not be able to change it.\r\n\r\nIf you disable or do not configure this setting, users can choose to limit the download rate in OneDrive sync app settings.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_downloadbandwidthlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_downloadbandwidthlimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_downloadbandwidthlimit_downloadratevalue","displayName":"Bandwidth: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_enableallocsiclients","displayName":"Coauthor and share in Office desktop apps (User)","description":"This setting lets multiple users use the Office 365 ProPlus, Office 2019, or Office 2016 desktop apps to simultaneously edit an Office file stored in OneDrive. It also lets users share files from the Office desktop apps.\r\n\r\nIf you enable this setting, coauthoring and sharing in the Office desktop apps is enabled. Users can disable these features by opening the OneDrive sync app settings, clicking the Office tab, and clearing the \"Use Office applications to sync Office files that I open\" check box.\r\n\r\nIf you disable this setting, coauthoring and sharing in the Office desktop apps is disabled, and the Office tab is hidden in sync app. The \"Office file conflicts\" setting will also be disabled and when two versions of a file conflict, both copies will be kept.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_enableallocsiclients_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_enableallocsiclients_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_enableholdthefile","displayName":"Allow users to choose how to handle Office file sync conflicts (User)","description":"This setting specifies what happens when there's a conflict between Office file versions during sync. By default, users can decide if they want to merge changes or keep both copies. Users can also change settings in the OneDrive sync app to always keep both copies. (This option is available for Office 2016 or later only. With earlier versions of Office, both copies are always kept.)\r\n\r\nIf you enable this setting or do not configure this setting, users can decide if they want to merge changes or keep both copies. Users can also select in OneDrive sync app settings to keep both copies.\r\n\r\nIf you disable this setting, both copies of the file will be kept when versions of a file conflict. Users won't be able to change the setting and merge changes.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_enableholdthefile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_enableholdthefile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit","displayName":"Limit the sync app upload speed to a fixed rate (User)","description":"This setting lets you configure the maximum speed at which the OneDrive sync app (OneDrive.exe) can upload files. This rate is a fixed value in kilobytes per second. The lower the rate, the slower the computer will upload files. The minimum rate that can be set is 1 KB/s and the maximum rate is 100000 KB/s. Any input lower than 50 KB/s will set the limit to 50 KB/s, even if the UI shows the inputted rate.\r\n\r\nIf you enable this setting, computers will use the maximum upload rate that you specify, and users will not be able to change it in OneDrive settings.\r\n\r\nIf you disable or do not configure this setting, users can choose to limit the upload rate to a fixed value (in KB/second), or set it to \"Adjust automatically\" which will use 70% of upload throughput to respond to increases and decreases in throughput.\r\n\r\nInstead of using this setting to limit the upload rate, we recommend enabling \"Limit the sync app upload rate to a percentage of throughput\" to set a limit that adjusts to changing conditions. You should not enable both settings at the same time.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit_uploadratevalue","displayName":"Bandwidth: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},{"id":"user_vendor_msft_policy_config_onedrivengscv4~policy~onedrivengsc_kfmforcewindowsdisplaylanguage","displayName":"Always use the user's Windows display language when provisioning known folders in OneDrive (User)","description":"When you move Windows known folders to OneDrive, they will be provisioned in the user's Windows display language by default, unless the user sets a different preferred language. This setting lets you override the user's preferred language setting. It works with both Known Folder Move settings (\"Silently move Windows known folders to OneDrive\" and \"Prompt users to move Windows known folders to OneDrive\").\r\n\r\nIf you enable this setting, known folders will be provisioned using the user's Windows display language, even if the user sets a different preferred language.\r\n\r\nIf you disable or do not configure this setting, and the user set a preferred language, their known folders will be provisioned in OneDrive using that language. The known folders on their PC will appear in their preferred language.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv4~policy~onedrivengsc_kfmforcewindowsdisplaylanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv4~policy~onedrivengsc_kfmforcewindowsdisplaylanguage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_disablefreanimation","displayName":"Disable animation that appears during OneDrive Setup (User)","description":"This setting lets you prevent the animation from showing during OneDrive Setup.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_disablefreanimation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_disablefreanimation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_enableautostart","displayName":"Start OneDrive automatically when signing in to Windows (User)","description":"This setting overrides a user's choice, ensuring OneDrive will automatically start every time they sign in to Windows. \r\n \r\nIf you configure this setting, OneDrive will start automatically when a user signs in to Windows. The OneDrive sync app must be restarted after this setting is enabled for the setting to take effect.\r\n\r\nIf you do not configure this setting or set it to any value other than 1, the user can choose to automatically start OneDrive (default choice) or to disable OneDrive from starting in OneDrive sync app settings.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_enableautostart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_enableautostart_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_disableinstalledonenoteaddins","displayName":"Disable installed OneNote Add-ins (User)","description":"Turns off all of the installed OneNote Add-ins.","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_disableinstalledonenoteaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_disableinstalledonenoteaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_disableonenotecomapi","displayName":"Disable OneNote COM API (User)","description":"Disable OneNote COM API - this disables add-on applications that may use the COM API. Note that it also breaks other features that use this API such as sending information from Outlook to OneNote.","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_disableonenotecomapi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_disableonenotecomapi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\OneNote\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\OneNote\\Addins.\r\n\r\nYou can also obtain the ProgID of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_addins_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"1ae8c95a-5748-4647-80f8-b447e60601a2","categoryName":"Add-ins","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook","displayName":"Choose default codec to be used for Video notebook (User)","description":"This option will set the default codec used by OneNote for video recording that are created in OneNote.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec","displayName":"Choose the Windows Media Video 8 codec: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for color pocket pcs (150 kbps)","displayName":"Color Pocket PCs (150 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for dial-up modems or single-channel isdn (28.8 to 56 kbps)","displayName":"Dial-up Modems or Single-channel ISDN (28.8 to 56 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for lan, cable modem, or xdsl (100 to 768 kbps)","displayName":"LAN, Cable Modem, or xDSL (100 to 768 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for dial-up modems or lan (28.8 to 100 kbps)","displayName":"Dial-up Modems or LAN (28.8 to 100 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for dial-up modems (28.8 kbps)","displayName":"Dial-up Modems (28.8 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for dial-up modems (56 kbps)","displayName":"Dial-up Modems (56 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for local area network (100 kbps)","displayName":"Local Area Network (100 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for local area network (256 kbps)","displayName":"Local Area Network (256 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for local area network (384 kbps)","displayName":"Local Area Network (384 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for broadband (ntsc, 700 kbps)","displayName":"Broadband (NTSC, 700 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for broadband (ntsc, 1400 kbps)","displayName":"Broadband (NTSC, 1400 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for broadband (pal, 384 kbps)","displayName":"Broadband (PAL, 384 Kbps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_choosedefaultcodectobeusedforvideonotebook_l_choosethewindowsmediavideo8codec_windows media video 8 for broadband (pal, 700 kbps)","displayName":"Broadband (PAL, 700 Kbps)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_disableaudosearch","displayName":"Disable audio search (User)","description":"Disables OneNote audio search feature.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_disableaudosearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_disableaudosearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_disablelinkedaudiofeature","displayName":"Disable Linked Audio feature (User)","description":"This policy setting allows you to configure the Record Audio and the Record Video commands on the Insert tab.\r\n\r\nIf you enable this policy setting, the commands will be not be available.\r\n\r\nIf you disable or do not configure this policy, the commands will be available.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_disablelinkedaudiofeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_disablelinkedaudiofeature_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_rewindfromstartofparagraphbythefollowingnumberofseconds","displayName":"Rewind from start of paragraph by the following number of seconds (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_rewindfromstartofparagraphbythefollowingnumberofseconds_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_rewindfromstartofparagraphbythefollowingnumberofseconds_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_rewindfromstartofparagraphbythefollowingnumberofseconds_l_rewindfromstartofparagraphbysec","displayName":"Rewind from start of paragraph by: (sec) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofbitstosamplewhenrecording","displayName":"Specify number of bits to sample when recording (User)","description":"Specifies the default number of bits per sample (value is in kbps) used when recording audio. If the appropriate codec is found, then this is the default bit depth used in the Format setting for Linked Audio, found under File tab | Options | Audio & Video.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofbitstosamplewhenrecording_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofbitstosamplewhenrecording_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofbitstosamplewhenrecording_l_bits","displayName":"Bits: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofchannelstorecord","displayName":"Specify number of channels to record (User)","description":"Specifies whether 1 or 2 channels are used when recording audio. If the appropriate codec is found, then this is the default number of channels used in the Format setting for Linked Audio found under File tab | Options | Audio & Video.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofchannelstorecord_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofchannelstorecord_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofchannelstorecord_l_channels12","displayName":"Channels (1-2): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifyratetosampleaudiobitssecond","displayName":"Specify rate to sample audio (bits/second) (User)","description":"Specifies the default sample rate (value is in kHz) used when recording audio. If the appropriate codec is found, then this is the default sample rate used in the Format setting for Linked Audio found under File tab | Options | Audio & Video.","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifyratetosampleaudiobitssecond_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifyratetosampleaudiobitssecond_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifyratetosampleaudiobitssecond_l_bitssecond","displayName":"Bits/Second: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook","displayName":"Automatically back up my notebook... (User)","description":"Checks/Unchecks the option ''Automatically back up my notebook at the following time interval''.","helpText":"","infoUrls":[],"categoryId":"c02141e6-0725-4f6f-9138-83d10c6bc104","categoryName":"Backup","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin","displayName":"Automatically back up at this interval (min): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c02141e6-0725-4f6f-9138-83d10c6bc104","categoryName":"Backup","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_2","displayName":"2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_3","displayName":"3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_4","displayName":"4","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_5","displayName":"5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_10","displayName":"10","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_15","displayName":"15","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_30","displayName":"30","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_60","displayName":"60","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_120","displayName":"120","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_180","displayName":"180","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_240","displayName":"240","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_300","displayName":"300","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_360","displayName":"360","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_480","displayName":"480","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_720","displayName":"720","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_960","displayName":"960","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_1440","displayName":"1440","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_2880","displayName":"2880","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_4320","displayName":"4320","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_5760","displayName":"5760","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_7200","displayName":"7200","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_8640","displayName":"8640","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_10080","displayName":"10080","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_20160","displayName":"20160","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_30240","displayName":"30240","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_40320","displayName":"40320","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_50400","displayName":"50400","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_automaticallybackupatthisintervalmin_60480","displayName":"60480","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_checktoenableautomaticbackup","displayName":"Check to enable automatic backup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c02141e6-0725-4f6f-9138-83d10c6bc104","categoryName":"Backup","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_checktoenableautomaticbackup_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_checktoenableautomaticbackup_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_numberofbackupcopiestokeep","displayName":"Number of backup copies to keep (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"c02141e6-0725-4f6f-9138-83d10c6bc104","categoryName":"Backup","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_numberofbackupcopiestokeep_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_numberofbackupcopiestokeep_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_numberofbackupcopiestokeep_l_numberofbackupcopiestokeep2","displayName":"Number of backup copies to keep (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c02141e6-0725-4f6f-9138-83d10c6bc104","categoryName":"Backup","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_navigationbarappearsontheright","displayName":"Navigation bar appears on the right (User)","description":"This option is to specify where the navigation bar appears.","helpText":"","infoUrls":[],"categoryId":"44774d3d-387b-4fa7-8de4-d82b039c06d1","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_navigationbarappearsontheright_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_navigationbarappearsontheright_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_pagetabsappearontheleft","displayName":"Page tabs appear on the left (User)","description":"Right: Unchecks the option ''Page tabs appear on the left''. | Left: Checks the option ''Page tabs appear on the left''.","helpText":"","infoUrls":[],"categoryId":"44774d3d-387b-4fa7-8de4-d82b039c06d1","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_pagetabsappearontheleft_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_pagetabsappearontheleft_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_pagetabsappearontheleft_l_specifylocationofthepagetabcontrol","displayName":"Specify location of the page tab control: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44774d3d-387b-4fa7-8de4-d82b039c06d1","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_pagetabsappearontheleft_l_specifylocationofthepagetabcontrol_0","displayName":"Right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_pagetabsappearontheleft_l_specifylocationofthepagetabcontrol_1","displayName":"Left","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_shownotecontainers","displayName":"Show Note Containers (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"44774d3d-387b-4fa7-8de4-d82b039c06d1","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_shownotecontainers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_shownotecontainers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_verticalscrollbarappearsonleft","displayName":"Vertical scroll bar appears on left (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"44774d3d-387b-4fa7-8de4-d82b039c06d1","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_verticalscrollbarappearsonleft_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_verticalscrollbarappearsonleft_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autobulletrecognition","displayName":"Auto Bullet Recognition (User)","description":"Checks/Unchecks the option ''Apply bullets to lists automatically''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autobulletrecognition_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autobulletrecognition_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autokeyboardswitching","displayName":"Auto Keyboard Switching (User)","description":"Check/Unchecks the option ''Switch keyboards automatically''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autokeyboardswitching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autokeyboardswitching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autonumberingrecognition","displayName":"Auto Numbering Recognition (User)","description":"Checks/Unchecks the option ''Apply numbering to lists automatically''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autonumberingrecognition_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autonumberingrecognition_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontname","displayName":"Default Font Name (User)","description":"Specifies the value in the option ''Font''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontname_l_font","displayName":"Font: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize","displayName":"Default Font Size (User)","description":"Specifies the value in the option ''Size''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize_l_fontsize","displayName":"Font Size: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_includelinktosourcewhenpastingfromtheinternet","displayName":"Include link to source when pasting from the Internet (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_includelinktosourcewhenpastingfromtheinternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_includelinktosourcewhenpastingfromtheinternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_showpasteoptionsbuttons","displayName":"Show Paste Options buttons (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_showpasteoptionsbuttons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_showpasteoptionsbuttons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnoffautocalculator","displayName":"Turn off auto calculator (User)","description":"This option turns on/off the auto calculator functionality.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnoffautocalculator_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnoffautocalculator_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnofflinkcreationwith","displayName":"Turn off link creation with [[ ]] (User)","description":"This policy setting allows you to turn off link creation with [[ ]]. OneNote allows users to automatically create links by putting [[ ]] around a term. OneNote will then automatically create a new page in that section and create a link on that text.\r\n\r\nIf you enable this policy setting, users will not be able to use [[ ]] to create a link and a new page.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will automatically create links when users use [[ ]].","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnofflinkcreationwith_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnofflinkcreationwith_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_addsignaturetoonenoteemailmessages","displayName":"Add signature to OneNote email messages (User)","description":"Checks/Unchecks the option ''Add the following signature to e-mail messages and Web pages created in OneNote''.","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_addsignaturetoonenoteemailmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_addsignaturetoonenoteemailmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_allowonenoteemailattachments","displayName":"Allow OneNote e-mail attachments (User)","description":"Checks/Unchecks the option ''Attach a copy of the original notes as a OneNote file''.","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_allowonenoteemailattachments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_allowonenoteemailattachments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_attachembeddedfilestotheemail","displayName":"Attach embedded files to the email message as separate files (User)","description":"This policy setting allows you to configure the \"Attach embedded files to the email message as separate file\" option found under File tab | Options | Advanced | E-mail sent from OneNote.\r\n\r\nIf you enable or do not configure this policy setting, embedded files are attached to the email message as separate files.\r\n\r\nIf you disable this policy setting, embedded files are not attached to the email message as separate files.","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_attachembeddedfilestotheemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_attachembeddedfilestotheemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_usethissignatureforonenoteemail","displayName":"Use this signature for OneNote email (User)","description":"Sets the value in the option ''Add the following signature to e-mail messages and Web pages created in OneNote''.","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_usethissignatureforonenoteemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_usethissignatureforonenoteemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_usethissignatureforonenoteemail_l_entersignaturetouseforonenoteemail","displayName":"Enter signature to use for OneNote e-mail (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_noteflags_l_copyitemswhenmovingthem","displayName":"Copy items when moving them (User)","description":"This policy setting allows you to configure tagged notes.\r\n\r\nIf you enable or do not configure this policy setting, the option \"Leave original tagged notes unchanged\" will be checked.\r\n\r\nIf you disable this policy setting, the option \"Show original tagged notes as dimmed\" will be checked.","helpText":"","infoUrls":[],"categoryId":"4a7b0e92-ba43-46aa-96e8-c5839dbcb524","categoryName":"Note Flags","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_noteflags_l_copyitemswhenmovingthem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_noteflags_l_copyitemswhenmovingthem_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_noteflags_l_showdimmedtaggednotesinthetagssummarytaskpane","displayName":"Show dimmed tagged notes in the Tags Summary task pane (User)","description":"Checks/unchecks the option \"Show dimmed tagged notes in the Tags Summary task pane.\"","helpText":"","infoUrls":[],"categoryId":"4a7b0e92-ba43-46aa-96e8-c5839dbcb524","categoryName":"Note Flags","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_noteflags_l_showdimmedtaggednotesinthetagssummarytaskpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_noteflags_l_showdimmedtaggednotesinthetagssummarytaskpane_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_addonenoteicontonotificationarea","displayName":"Add OneNote icon to notification area (User)","description":"Checks/Unchecks the option ''Place OneNote icon in the notification area of the taskbar''.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_addonenoteicontonotificationarea_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_addonenoteicontonotificationarea_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote","displayName":"Default unit of measurement used in OneNote (User)","description":"Sets the value in the option ''Measurement units''.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_l_specifydefaultunitofmeasurement","displayName":"Specify default unit of measurement: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_l_specifydefaultunitofmeasurement_0","displayName":"Inch","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_l_specifydefaultunitofmeasurement_1","displayName":"Centimeter","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_l_specifydefaultunitofmeasurement_2","displayName":"Millimeter","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_l_specifydefaultunitofmeasurement_3","displayName":"Point","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_l_specifydefaultunitofmeasurement_4","displayName":"Pica","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableembeddedfiles","displayName":"Disable embedded files (User)","description":"To disable the ability to embed files on a OneNote page, so people cannot transmit files that might not be caught by anti-virus software, etc. Note: This policy will only limit embedded files in the OneNote UI, if a page has an embedded file OneNote will still sync and replicate the embedded files in the file system.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableembeddedfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableembeddedfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableocr","displayName":"Disable OCR (User)","description":"This policy turns off the OneNote image optical character recognition (OCR) feature. The OCR feature allows OneNote to automatically scan through images to find text that will appear in search results.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableocr_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableocr_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableonenotescreenclippingnotifications","displayName":"Disable OneNote screen clipping notifications (User)","description":"Turns off all of the OneNote screen clipping notifications.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableonenotescreenclippingnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableonenotescreenclippingnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableonenotescreenclippings","displayName":"Disable OneNote Screen Clippings (User)","description":"Disables the screen clipping feature in OneNote.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableonenotescreenclippings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disableonenotescreenclippings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_embeddedfilesblockedextensions","displayName":"Embedded Files Blocked Extensions (User)","description":"To disable the ability of the users in your organization from being able to open a file attachment of a specific file type from a Microsoft OneNote page, add the extensions you want to disable using this format: \".ext1;.ext2;\" If you want to disable the opening of any attachment from a OneNote page, see the Disable embedded files policy. You cannot block embedded audio and video recordings (WMA & WMV) with this policy instead refer to the Disable embedded files policy.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_embeddedfilesblockedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_embeddedfilesblockedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_embeddedfilesblockedextensions_l_empty12","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot","displayName":"Load a notebook on first boot (User)","description":"Points to a folder containing a notebook that should be loaded on first boot.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot_l_empty13","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_notebookpresence","displayName":"Notebook Presence (User)","description":"This policy setting enables or disables the Notebook Presence feature in OneNote, which broadcasts user presence within a notebook and enables real-time synchronization for users who are editing the same page. Note: Any change to this policy does not take effect until OneNote is restarted.\r\n\r\nIf you enable or do not configure this policy setting, users are notified when they are editing the same page in a notebook as another user. OneNote also enters real-time sync when it discovers multiple users editing the same page. \r\n\r\nIf you disable this policy setting, users are not notified when they are editing the same page in a notebook as another user. OneNote does not enter real-time sync when multiple users are editing the same page.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_notebookpresence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_notebookpresence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_numberofdaysbeforewarningthatserveris","displayName":"Number of days before warning that server is inaccessible (User)","description":"Set the number of days until OneNote warns that the server is inaccessible and prompts for a new location for the affected files.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_numberofdaysbeforewarningthatserveris_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_numberofdaysbeforewarningthatserveris_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_numberofdaysbeforewarningthatserveris_l_empty14","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_setuncintervaltopollforchangesonfileservers","displayName":"Set UNC interval to poll for changes on file servers (User)","description":"This policy setting allows you to change the synchronization interval at which OneNote will poll for changes on the server. When OneNote synchronizes a notebook on UNC, also known as SMB or Windows File shares, OneNote will receive notifications from the file server as well as poll the server looking for new updates on the server.\r\n\r\nBy making the interval faster it will make OneNote synchronize faster, but it also might cause performance issues on the server.\r\n\r\nIf you enable this policy setting, you may specify the number of seconds OneNote will poll.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will automatically poll every 30 seconds.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_setuncintervaltopollforchangesonfileservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_setuncintervaltopollforchangesonfileservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_setuncintervaltopollforchangesonfileservers_l_setuncintervaltopollforchangesonfileserversspinid","displayName":"Interval to poll the server (seconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointsyncinterval","displayName":"SharePoint sync interval for notebooks stored on SharePoint (User)","description":"Limits the number of times OneNote polls a SharePoint site for changes to a section. Enter the sync interval in seconds.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointsyncinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointsyncinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointsyncinterval_l_empty15","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_specifyembeddedfilesizelimit","displayName":"Embedded File Size Limit (User)","description":"This policy setting enables you to specify the maximum embedded file size that users can insert directly into a OneNote notebook on a SharePoint server.\r\n \r\nIf you enable this policy setting, you can increase or decrease the default maximum file size of 50 MB. \r\n\r\nIf you increase this value, users can insert larger files directly into the notebook, but this may reduce server performance. \r\n\r\nIf you decrease this value, users can only insert smaller files directly into the notebook, which may improve server performance if OneNote sync is generating a lot of traffic.\r\n\r\nIf you disable or do not configure this policy setting, users cannot insert a file larger than 50MB inserted into a OneNote notebook. Instead, the file is uploaded to a SharePoint folder and inserted as a hyperlink into the notebook.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_specifyembeddedfilesizelimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_specifyembeddedfilesizelimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_specifyembeddedfilesizelimit_l_embeddedfilesizelimit","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffonenoteautolinkednotetaking","displayName":"Turn off OneNote auto-linked note taking (User)","description":"This policy setting turns off the OneNote auto note taking feature which allows you to take notes on items such as webpages, Word documents, etc. OneNote will automatically record what pages or document you were viewing when you took this note.\r\n\r\nIf you enable this policy setting, OneNote will not automatically link notes when the user tries to turn on this feature.\r\n\r\nIf you disable or do not enable this policy, OneNote will automatically link notes when the user tries to turn on this feature.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffonenoteautolinkednotetaking_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffonenoteautolinkednotetaking_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disablepasswordprotectedsections","displayName":"Disable password protected sections (User)","description":"Disables the ability to create new password protected sections. You can however still unlock and edit existing sections which had a password set.","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disablepasswordprotectedsections_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disablepasswordprotectedsections_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disallowsaddonsaccesstopass","displayName":"Disallows add-ons access to password protected sections (User)","description":"This option disallows extensibility add-ons the ability to access password protected sections if they are unlocked.","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disallowsaddonsaccesstopass_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disallowsaddonsaccesstopass_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime","displayName":"Lock password protected sections after user hasn't worked on them for a time (User)","description":"OneNote supports password protecting sections and they are unlocked once a user types the password and can be locked again by either a timeout period or when you navigate away from the section. This option will lock the section after the user hasn't used the section for the selected amount of time.","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_checktolocksections","displayName":"Check to lock sections (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_checktolocksections_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_checktolocksections_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections","displayName":"Time interval (minutes) to lock password protected sections: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_5","displayName":"5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_10","displayName":"10","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_15","displayName":"15","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_30","displayName":"30","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_60","displayName":"60","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_120","displayName":"120","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_240","displayName":"240","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_480","displayName":"480","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_720","displayName":"720","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsafteruserhasntworkedonthemforatime_l_timeintervalminutestolockpasswordprotectedsections_1440","displayName":"1440","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsassoonasinavigateawayfromthem","displayName":"Lock password protected sections as soon as I navigate away from them (User)","description":"OneNote supports password protecting sections and they are unlocked once a user types the password and can be locked again by either a timeout period or when you navigate away from the section. This option will lock the section once you navigate away from the password protected section.","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsassoonasinavigateawayfromthem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsassoonasinavigateawayfromthem_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_automaticallyswitchbetweenpenandselectiontool","displayName":"Automatically switch between Pen and Selection Tool (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"84de2eed-843c-401b-a3fd-e21be88f2365","categoryName":"Pen","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_automaticallyswitchbetweenpenandselectiontool_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_automaticallyswitchbetweenpenandselectiontool_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_createallnewpageswithrulelines","displayName":"Create all new pages with rule lines (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"84de2eed-843c-401b-a3fd-e21be88f2365","categoryName":"Pen","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_createallnewpageswithrulelines_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_createallnewpageswithrulelines_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_disablescratchout","displayName":"Disable scratch out (User)","description":"Disables the scratch out gesture while inking.","helpText":"","infoUrls":[],"categoryId":"84de2eed-843c-401b-a3fd-e21be88f2365","categoryName":"Pen","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_disablescratchout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_disablescratchout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_showtabletpcinputpanelononenotepages","displayName":"Show Tablet PC Input Panel on OneNote pages (User)","description":"Enable this policy to display the Tablet PC Input Panel on OneNote pages.","helpText":"","infoUrls":[],"categoryId":"84de2eed-843c-401b-a3fd-e21be88f2365","categoryName":"Pen","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_showtabletpcinputpanelononenotepages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_showtabletpcinputpanelononenotepages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_usepenpressuresensitivity","displayName":"Use pen pressure sensitivity (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"84de2eed-843c-401b-a3fd-e21be88f2365","categoryName":"Pen","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_usepenpressuresensitivity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_pen_l_usepenpressuresensitivity_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles","displayName":"Enable ability to optimize OneNote files... (User)","description":"Checks/Unchecks the option ''Optimize sections after OneNote has been inactive for the following number of minutes''.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_l_checktoenableabilitytooptimizeonenotefiles","displayName":"Check to enable ability to optimize OneNote files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_l_checktoenableabilitytooptimizeonenotefiles_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_l_checktoenableabilitytooptimizeonenotefiles_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_l_optimizeonenotefilesatthisintervalmin","displayName":"Optimize OneNote files at this interval (min): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder","displayName":"Location of Backup Folder (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder_l_backupfolder","displayName":"Backup Folder: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofunfilednotessection","displayName":"Location of unfiled notes section (User)","description":"Location where OneNote stores the unfiled notes section.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofunfilednotessection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofunfilednotessection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofunfilednotessection_l_opensidenotesinthissection","displayName":"Open Side Notes in this section: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot","displayName":"Notebook Root (User)","description":"To change to where new notebooks are defaulted, enter a path to a folder relative to your documents.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot_l_empty1","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections","displayName":"Percentage of unused disk space to allow in sections (User)","description":"Sets the value in the option ''Percentage of unused space to allow in sections without optimizing''.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections_l_enterpercentage","displayName":"Enter Percentage: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setparametersforcngcontext","displayName":"Set parameters for CNG context (User)","description":"This policy setting allows you to specify the encryption parameters that should be used for the CNG context. \r\n\r\nIf you enable this policy setting, the parameters specified will be passed to the CNG context.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG values will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setparametersforcngcontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setparametersforcngcontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm","displayName":"Specify CNG random number generator algorithm (User)","description":"This policy setting allows you to configure the CNG random number generator to use.\r\n\r\nIf you enable this policy setting, the random number generator specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default random number generator will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_l_specifycngrandomnumbergeneratoralgorithmid","displayName":"Random number generator: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngsaltlength","displayName":"Specify CNG salt length (User)","description":"This policy setting allows you to specific the number of bytes of salt that should be used.\r\n\r\nIf you enable this policy setting, the bytes specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default length or 16 will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngsaltlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngsaltlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility","displayName":"Specify encryption compatibility (User)","description":"This policy setting allows you to specify the encrypted database compatibility.\r\n\r\nIf you enable this policy setting, the compatibility format specified will be applied during encryption for new files\r\n- Use legacy format\r\n- Use next generation format\r\n- All files save with next generation format\r\n\r\nIf you disable or do not configure this policy setting, the default setting, \"Use next generation format,\" will be applied.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_0","displayName":"Use legacy format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_1","displayName":"Use next generation format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_2","displayName":"All files save with next generation format","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_sendtoonenote_l_disableoutlooksendemailtoonenoteoption","displayName":"Disable Outlook send email to OneNote option (User)","description":"This policy disables the OneNote ''Send to OneNote'' add-in for Microsoft Outlook. By default OneNote installs an add-in on the Outlook toolbar which allows users to send emails to OneNote. The ''Send to OneNote'' button appears on the main mail module in Outlook as well as when viewing an email message. You may disable this feature with this policy.","helpText":"","infoUrls":[],"categoryId":"a87f9d6a-0c84-4cad-839f-e912c6006c12","categoryName":"Send to OneNote","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_sendtoonenote_l_disableoutlooksendemailtoonenoteoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_sendtoonenote_l_disableoutlooksendemailtoonenoteoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions","displayName":"OneNote Spelling Options (User)","description":"These options change the \"When correcting spelling in OneNote\" options that appear in the File tab | Option | Proofing dialog box.","helpText":"","infoUrls":[],"categoryId":"1bfef2c3-a561-4e7a-8f0f-0944bc79c20f","categoryName":"Spelling","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_l_empty11","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"1bfef2c3-a561-4e7a-8f0f-0944bc79c20f","categoryName":"Spelling","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_l_empty11_0","displayName":"no spell checking","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_l_empty11_1","displayName":"check spelling as you type","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_l_empty11_2","displayName":"hide spelling errors","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_spelling_l_onenotespellingoptions_l_empty11_3","displayName":"check spelling but hide errors","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepinversionhistory","displayName":"Days back to keep in version history (User)","description":"This policy setting allows you to set the number of days when all version history items created before this value will be deleted. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, you can set the number of days back to delete version history.\r\n\r\nIf you disable or do not configure this policy setting OneNote will default to keeping previous versions for all days in the past. This is the default value of -1.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepinversionhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepinversionhistory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepinversionhistory_l_daysbacktokeepinversionhistoryspinid","displayName":"Days back to keep versions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepitemsinrecyclebin","displayName":"Days back to keep items in recycle bin (User)","description":"This policy setting allows you to set the number of days before which all items added to the Recycle Bin before value will be deleted when the version history is pruned. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, you can set the number of days in the past to keep recycle bin items.\r\n\r\nIf you do not configure this policy setting OneNote will use the default value of 60 days in the past.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepitemsinrecyclebin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepitemsinrecyclebin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepitemsinrecyclebin_l_daysbacktokeepitemsinrecyclebinspinid","displayName":"Days back to keep items in recycle bin (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofallversions","displayName":"Days all Version History items are \"safe\" from pruning (User)","description":"This policy setting allows you to specify a period of time during which OneNote maintains comprehensive version history pages. After the time specified, OneNote maintains more basic version history pages, which uses less storage space.\r\n\r\nIf you enable this policy setting, OneNote maintains comprehensive version history pages for the length of time you specify, and then maintains basic version history pages once the time period expires.\r\n\r\nIf you disable or do not configure this policy setting, OneNote maintains comprehensive version history pages for 2 days, and then maintains basic version history pages once the time period expires.\r\n ","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofallversions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofallversions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofallversions_l_daysofallversionsspinid","displayName":"Days back (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofhourlyversionsnottopruneafterdaysback","displayName":"Days of hourly versions not to prune after Days Back (User)","description":"This policy setting allows you to set the number of hourly versions not to prune after Days Back. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, you may specify the number of days to keep hourly versions after the Days Back setting. This value specifies the number of days past \"DaysOfAllVersions\" to keep hourly version history information. Users will keep one version per hour for this number of days after \"DaysOfAllVersions\".\r\n\r\nIf you disable or do not configure this policy setting, OneNote will keep hourly versions for the past 5 days.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofhourlyversionsnottopruneafterdaysback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofhourlyversionsnottopruneafterdaysback_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysofhourlyversionsnottopruneafterdaysback_l_daysofhourlyversionsnottopruneafterdaysbackspinid","displayName":"Days back (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_donotpruneversionsovertime","displayName":"Do not prune versions over time (User)","description":"This policy setting allows you to turn off OneNote's automatic pruning. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, OneNote will not prune previous versions.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will prune previous versions. The default value is to prune versions over time. You should only enable this policy setting if OneNote should not prune previous versions.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_donotpruneversionsovertime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_donotpruneversionsovertime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_maximumnumberofonceperdayversionhistoryitemskept","displayName":"Maximum number of once-per-day version history items kept (User)","description":"This policy setting allows you to set the number of once-per-day history items to be kept for each page. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, you can set the number of versions per day to keep. If you set a value of -1 this will tell OneNote to keep all old once-per-day version history items.\r\n \r\nIf you disable or do not configure this policy setting OneNote will keep a page for the past 10 days every day in the past.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_maximumnumberofonceperdayversionhistoryitemskept_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_maximumnumberofonceperdayversionhistoryitemskept_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_maximumnumberofonceperdayversionhistoryitemskept_l_maximumnumberofonceperdayversionhistoryitemskeptspinid","displayName":"Max number of versions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_turnoffversionsandnotebookrecyclebininsharednotebooks","displayName":"Turn off Versions and Notebook Recycle Bin in shared notebooks (User)","description":"This policy setting allows you to turn off version history which includes versions and the notebook recycle bin. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, it will turn off version history.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will store previous versions by default.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_turnoffversionsandnotebookrecyclebininsharednotebooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_turnoffversionsandnotebookrecyclebininsharednotebooks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointbackgroundsyncintervalmultiplier","displayName":"Multiplier for background sync interval for notebooks stored on SharePoint (User)","description":"This policy setting allows you to increase the interval between background polls of a SharePoint site for changes to notebooks.\r\n\r\nIf you enable this policy setting, OneNote will poll SharePoint less frequently for changes to whole notebooks. Intervals are multiplied by the entered value, a positive integer value from 1 to 10. Larger intervals will slow notebook sync but reduce server load.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will sync notebooks at the default rate (multiplier value of 1).\r\n\r\nNote: This policy setting only applies to volume licensed versions of Office 2016 that use Windows Installer (MSI), such as Office Professional Plus 2016 and Office Standard 2016.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointbackgroundsyncintervalmultiplier_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointbackgroundsyncintervalmultiplier_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointbackgroundsyncintervalmultiplier_l_empty16","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier","displayName":"Multiplier for foreground sync interval for the currently viewed section stored on SharePoint (User)","description":"This policy setting allows you to increase the interval between foreground polls of a SharePoint site for changes to the currently viewed section.\r\n\r\nIf you enable this policy setting, OneNote will poll SharePoint less frequently for changes to the currently viewed section. Intervals are multiplied by the entered value, a positive integer value from 1 to 10. Larger intervals will slow section sync but reduce server load.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will sync the currently viewed section at the default rate (multiplier value of 1).\r\n\r\nNote: This policy setting only applies to volume licensed versions of Office 2016 that use Windows Installer (MSI), such as Office Professional Plus 2016 and Office Standard 2016.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier_l_empty17","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier","displayName":"Multiplier for Presence sync interval for notebooks stored on SharePoint (User)","description":"This policy setting allows you to increase the interval between polls to SharePoint to determine active users of notebooks. OneNote will sync notebooks at a faster rate when other users are interacting with a notebook.\r\n\r\nIf you enable this policy setting, OneNote will poll SharePoint less frequently to determine if there are other users currently interacting with notebooks. Intervals are multiplied by the entered value, a positive integer value from 1 to 10. Larger intervals will slow detection of concurrent users in notebooks but reduce server load.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will poll for active users of notebooks at the default rate (multiplier value of 1).\r\n\r\nNote: This policy setting only applies to volume licensed versions of Office 2016 that use Windows Installer (MSI), such as Office Professional Plus 2016 and Office Standard 2016.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier_l_empty18","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_onent16v4~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disablesupportdiagnostics","displayName":"Turn off support diagnostics in OneNote (User)","description":"This policy setting controls whether OneNote sends client information to support services on failure.\r\n\r\nSending client information to support services on failure can help diagnose the issue, provide resolution steps, or show contextual error messaging to the user.\r\n\r\nIf you enable this policy setting, OneNote won’t send client information to support services on failure.\r\n\r\nIf you disable or don’t configure this policy setting, OneNote will send client information to support services on failure.\r\n\r\nNote: This policy setting only applies to Version 2207 and later of OneNote.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v4~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disablesupportdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v4~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disablesupportdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v5~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_onenotetextprediction","displayName":"OneNote text prediction (User)","description":"\r\nThis policy setting controls whether users will see and be able to accept text predictions when writing notes in English in OneNote.\r\n\r\nIf you enable or don't configure this policy setting, users will see and be able to accept predicted text by using the Tab key or right arrow key while writing their notes. Or they can simply keep typing to ignore the predicted text.\r\n\r\nIf you disable this policy setting, users will not be able to see or accept text predictions while writing notes.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v5~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_onenotetextprediction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v5~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_onenotetextprediction_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v6.1~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffnewstickynotesinonenote","displayName":"Disable the new Sticky Notes experience (User)","description":"This policy controls the ability of users to access the new Sticky Notes experiences from OneNote.\r\n\r\nIf you enable this policy setting, users will be unable to access the new Sticky Notes experiences from OneNote.\r\n\r\nIf you disable this policy setting, users can access the new Sticky Notes experiences from OneNote.\r\n\r\nIf you do not set this policy setting, users can access the new Sticky Notes experiences from OneNote.\r\n\r\nNote: This policy does not affect the classic Microsoft Sticky Notes app available on the Microsoft Store. Additionally, disabling or not setting this policy does not guarantee access to the new Sticky Notes experiences from OneNote.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v6.1~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffnewstickynotesinonenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v6.1~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffnewstickynotesinonenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v6~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffnewstickynotesinonenote","displayName":"Disable the new Sticky Notes experience (User)","description":"This policy controls the ability of users to access the new Sticky Notes experiences from OneNote.\r\n\r\nIf you enable this policy setting, users will be unable to access the new Sticky Notes experiences from OneNote.\r\n\r\nIf you disable this policy setting, users can access the new Sticky Notes experiences from OneNote.\r\n\r\nIf you do not set this policy setting, users can access the new Sticky Notes experiences from OneNote.\r\n\r\nNote: This policy does not affect the classic Microsoft Sticky Notes app available on the Microsoft Store. Additionally, disabling or not setting this policy does not guarantee access to the new Sticky Notes experiences from OneNote.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v6~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffnewstickynotesinonenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v6~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_turnoffnewstickynotesinonenote_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v7~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_onenotesensitivitylabels","displayName":"Enable OneNote Sensitivity Labels (User)","description":"This policy setting controls whether Purview Sensitivity Label capabilities can be enabled for OneNote Sections.\r\n\r\nIf you enable this policy, users can use supported Purview features, such as manual labeling, label removal, or default labels, to apply sensitivity labels to OneNote sections and help protect sensitive information. At this time, mandatory labels, auto labeling, and dynamic watermarking are not supported.\r\n\r\nIf you disable this policy, users won't be able to apply, change or remove Sensitivity Labels in OneNote Sections.\r\n\r\nIf you do not configure this policy setting, users won't be able to apply, change or remove Sensitivity Labels in OneNote Sections.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v7~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_onenotesensitivitylabels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v7~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_onenotesensitivitylabels_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems290","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems290_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems290_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems290_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_outlk16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace","displayName":"Disable Preview Place. (User)","description":"\r\n This policy setting determines whether the Preview Place feature is allowed. Enabling this setting will block the Preview Place feature from being available.\r\n Users will no longer be able to preview and provide feedback on upcoming changes in Outlook.\r\n\tNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v10~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disablecalendarsearchagendaview","displayName":"Do not allow Calendar search agenda view (User)","description":"This policy setting allows you to prevent agenda view for Calendar search.\r\n\r\nIf you enable this policy setting, Calendar search will default to list view.\r\n\r\nIf you disable or do not configure this policy setting, it will default to agenda view.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v10~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disablecalendarsearchagendaview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v10~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disablecalendarsearchagendaview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifymaxcertlengthallowedtostamp","displayName":"Maximum Size Limit for certificate in Reply to Encrypted Emails cases. (User)","description":"When replying to a digitally signed email using Outlook, Win32 saves the certificate chain of the original sender in Exchange. This allows for encrypted replies without adding the original sender to the contact list. \r\nHowever, there are cases where a sent email may not be delivered or saved in the sent items if the size of the stored certificate on the Exchange server is too large.\r\nTo avoid this issue caused by large certificate sizes of the original email sender in Win32 Outlook, the default upper limit is set at 12921 bytes. However, administrators have the option to configure a higher limit, up to a maximum of 16384 bytes.\t\r\n ","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifymaxcertlengthallowedtostamp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifymaxcertlengthallowedtostamp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifymaxcertlengthallowedtostamp_l_specifymaxcertlengthallowedtostampspinid","displayName":"In bytes: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":null},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifywaitonsendtimeoutfordlpevaluation","displayName":"Specify wait time to evaluate sensitive content (User)","description":"This policy setting is used to define the waiting time for evaluating sensitive content in emails before a user can send them. Customize whether immediate email sending is allowed, sending is permitted after a specific wait time, or complete evaluation is required before sending. Regardless of the setting, the service will continue the evaluation in the background and take appropriate action based on the results, such as blocking delivery if necessary.\r\n\r\nIf you disable or do not configure this policy setting, emails will be sent right away without waiting for the final evaluation of the configured policies.\r\n\r\nIf you enable this policy setting, you can set a specific wait time, measured in seconds (in the range of 0-9999), before the \"Send Anyway\" button appears in the waiting dialog. This allows users to send the mail even before the policy evaluation is complete. \r\n\r\nPlease note that setting the wait time above 9999 indicates that users are not allowed to send the mail without evaluation. In such cases, the \"Send Anyway\" button will never be shown.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifywaitonsendtimeoutfordlpevaluation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifywaitonsendtimeoutfordlpevaluation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_specifywaitonsendtimeoutfordlpevaluation_l_specifywaitonsendtimeoutfordlpevaluationspinid","displayName":"In seconds: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":null},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hidenewoutlooktoggle","displayName":"Hide the “Try the new Outlook” toggle in Outlook (User)","description":"This policy setting controls whether the “Try the new Outlook” toggle is displayed in Outlook.\r\n\r\nIf you enable this policy setting, the toggle for “Try the new Outlook” will be hidden and users will not have the ability to switch between the existing and new Outlook experiences.\r\n\r\nIf you disable or do not configure this policy setting, the toggle for “Try the new Outlook” will be displayed.\r\n\r\nNote: This policy only applies to subscription-based Microsoft 365 Apps.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hidenewoutlooktoggle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v11~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hidenewoutlooktoggle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v12~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablesimplemapisendwithoutoutlook","displayName":"Running Outlook for Simple MAPI Mail Sending (User)","description":"This policy setting determines whether users can send mail through Simple MAPI when Outlook is not active.\r\n\r\nIf you enable this policy setting, users are required to have Outlook running to send mail through Simple MAPI. This will force users to open Outlook to send mail, ensuring that Outlook Add-ins run properly before the mail is sent. \r\n\r\nIf you disable this policy setting, users are allowed to send mail through Simple MAPI regardless of Outlook running.\r\n\r\nWhen this policy setting is not configured, it functions as if it has been disabled, allowing users to send mail through Simple MAPI without having Outlook running.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v12~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablesimplemapisendwithoutoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v12~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablesimplemapisendwithoutoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps","displayName":"Show Outlook Loop components for supported apps. (User)","description":"This policy controls whether Outlook displays Loop components that are supported by installed apps without requiring users to explicitly choose to load them.\r\n\r\nIf you enable this policy setting by selecting \"Always show automatically\" or \"Only show automatically within tenant,\" Outlook will automatically display Loop components in emails. This applies to all messages or specifically to messages that originate within the recipient's local tenant or organization. This might involve contacting servers used by the installed apps to retrieve Loop components.\r\n\r\nIf you do not set this policy setting, Outlook will default to the \"Only show automatically within tenant\" setting. This ensures Loop components are automatically displayed in emails originating from the recipient's local tenant or organization.\r\n\r\nNote: Loop components included in messages located in the Junk Mail folder will not load automatically, regardless of the policy setting specified. Loop components will only be shown for apps that are installed, ensuring security and a tailored experience in Outlook.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid","displayName":"Show Outlook Loop components for supported apps (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid_1","displayName":"Always show automatically.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid_2","displayName":"Only show automatically within tenant.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid_3","displayName":"Don’t show automatically.","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals","displayName":"Interval between new Outlook migration attempts (User)","description":"This policy setting controls the interval between new Outlook migration attempts.\r\n\r\nIf you don't set this or set this to 0 (default value), classic Outlook will stop executing \"New Outlook auto migration\" after the user toggles back to classic Outlook for Windows.\r\n\r\nIf you set this to 1, classic Outlook will show a blocking prompt on each app launch, which will attempt to switch the user to the new Outlook app.\r\n\r\nIf you set this to N (2 - 9900) value, \"New Outlook auto migration\" will be re-initiated N days after the user toggles back to classic Outlook.\r\n\r\nNote: This policy only applies to subscription-based Microsoft 365 Apps.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_l_newoutlookautomigrationretryintervalsid","displayName":"New Outlook Auto Migration Retry Interval: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablecomtowebaddinupgrade","displayName":"Disable web add-in installation on migration to new Outlook for Windows (User)","description":"This policy setting allows you to disable installation of web add-in equivalents of COM add-ins on the switch to new Outlook. The add-ins available for migration are listed in https://aka.ms/newoutlooksettings.\r\n\r\nLearn more about Outlook web add-ins at https://learn.microsoft.com/office/dev/add-ins/outlook/outlook-add-ins-overview.\r\n\r\nCOM add-ins do not work in new Outlook for Windows. By default, users in the organization will get the option to install available web add-ins, in place of COM add-ins, when they move from classic Outlook for Windows.\r\n\r\nIf you enable this policy setting, users will not get the option to install web add-ins in place of their COM add-ins. \r\n \r\nIf you disable or do not configure this policy setting, users will get an option to install web add-ins in place of their COM add-ins.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablecomtowebaddinupgrade_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablecomtowebaddinupgrade_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_donewoutlookautomigration","displayName":"Admin-Controlled Migration to New Outlook (User)","description":"\r\nThis policy controls the ability of IT admins to initiate the migration of users from classic Outlook to new Outlook.\r\n\r\nIf you enable this policy setting, IT admins will start the process to switch users from classic Outlook to new Outlook.\r\n\r\nIf you disable this policy setting, the migration process to new Outlook will be stopped, keeping users on their current version of Outlook without transitioning to new Outlook.\r\n\r\nIf you do not set this policy setting, the migration process to new Outlook will not start, and users that have not migrated will remain on classic Outlook.\r\n\r\nNote: IT admins can also define intervals for re-initiating the migration process for users who revert to classic Outlook from new Outlook. This is managed through the NewOutlookAutoMigrationRetryIntervals policy, offering a tailored strategy for transitioning users based on organizational requirements and user feedback.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_donewoutlookautomigration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_donewoutlookautomigration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals","displayName":"Interval between new Outlook migration attempts (User)","description":"This policy setting controls the interval between new Outlook migration attempts.\r\n\r\nIf you don't set this or set this to 0 (default value), classic Outlook will stop executing \"New Outlook auto migration\" after the user toggles back to classic Outlook for Windows.\r\n\r\nIf you set this to 1, classic Outlook will show a blocking prompt on each app launch, which will attempt to switch the user to the new Outlook app.\r\n\r\nIf you set this to N (2 - 9900) value, \"New Outlook auto migration\" will be re-initiated N days after the user toggles back to classic Outlook.\r\n\r\nNote: This policy only applies to subscription-based Microsoft 365 Apps.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_l_newoutlookautomigrationretryintervalsid","displayName":"New Outlook Auto Migration Retry Interval: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption","displayName":"MailTips bar display options (User)","description":"\r\n This policy setting controls MailTips bar display options. If the \"Disable MailTips\" policy is also enabled, this policy takes precedence.\r\n\r\n If you enable this policy setting, you can choose from three options for determining how the MailTips bar will display:\r\n\r\n - Display automatically when MailTips apply\r\n - Display at all times\r\n - Never Display MailTips\r\n\r\n If you disable or do not configure this policy setting, users can choose how the MailTips bar will display.\r\n ","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions_0","displayName":"Display automatically when MailTips apply","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions_1","displayName":"Display at all times","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions_2","displayName":"Never display MailTips","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_smimedisabledataupload","displayName":"Block processing of S/MIME encrypted messages by certain connected experiences (User)","description":"\r\nThis policy controls whether certain connected experiences that analyze your content can process email messages with S/MIME encryption.\r\n\r\nIf you enable this policy setting, certain connected experiences that analyze your content can’t process email messages with S/MIME encryption. This means connected experiences such as the following won’t be available:\r\n\r\n-\tSpelling and grammar check (Editor)\r\n-\tSuggested replies\r\n-\tAutomatically apply or recommend sensitivity labels\r\n-\tMicrosoft Purview Data Loss Prevention policy tips\r\n\r\nFor more information about which connected experiences are affected, see https://go.microsoft.com/fwlink/p/?linkid=2268773.\r\n\r\nIf you disable or don’t configure this policy setting, all connected experiences that analyze your content can process email messages with S/MIME encryption.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_smimedisabledataupload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_smimedisabledataupload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy","displayName":"Manage user setting for new Outlook automatic migration (User)","description":"\r\nThis policy allows you to manage the user setting for enabling or disabling automatic migration to the new Outlook app. Automatic migration could be admin-driven (enabled through 'Admin-Controlled migration to New Outlook' policy), or Microsoft-driven.\r\n\r\nWhen applied, this policy controls whether the user can be switched to the new Outlook app automatically or retains control over the setting.\r\n\r\nIf you set this policy to 1 (Set to 1), the user setting controlling automatic migration is enabled. Automatic migration to the new Outlook app is allowed, and the user cannot change this setting.\r\n\r\nIf you set this policy to 2 (Set to 2), the user setting controlling automatic migration is disabled. Automatic migration to the new Outlook app is not allowed, and the user cannot change this setting.\r\n\r\nIf you set this policy to 0 (Set to 0) or don't configure this policy (default), the user setting for automatic migration is not controlled by the policy, allowing the user to manage it themselves. This user setting for automatic migration is enabled by default.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy_l_newoutlookautomigrationusersettingpolicyid","displayName":"New Outlook Auto Migration User Setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_outlk16v17~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomaticsetupusersetting","displayName":"Manage automatic setup of classic Outlook accounts in new Outlook (User)","description":"\r\nThis policy setting allows you to manage whether classic Outlook automatically sets up user accounts and settings in new Outlook.\r\n\r\nIf you enable this policy setting, automatic setup of user accounts and settings in new Outlook is allowed and cannot be changed by the user.\r\n\r\nIf you disable this policy setting, automatic setup of user accounts and settings in new Outlook is not allowed and cannot be changed by the user.\r\n\r\nIf you don't configure this policy setting, users can manage the setting themselves. Automatic setup is enabled by default.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v17~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomaticsetupusersetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v17~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomaticsetupusersetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges","displayName":"Add properties to attachments to enable Reply with Changes (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_l_addpropertiestoattachmentstoenablereplywithchanges","displayName":"Add properties to attachments to enable Reply with Changes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_l_addpropertiestoattachmentstoenablereplywithchanges_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_l_addpropertiestoattachmentstoenablereplywithchanges_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator","displayName":"Allow commas as address separator (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_l_allowcommasasaddressseparator","displayName":"Allow commas as address separator (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_l_allowcommasasaddressseparator_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_l_allowcommasasaddressseparator_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_automaticnamechecking","displayName":"Automatic name checking (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_automaticnamechecking_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_automaticnamechecking_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_automaticnamechecking_l_automaticnamechecking","displayName":"Automatic name checking (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_automaticnamechecking_l_automaticnamechecking_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_automaticnamechecking_l_automaticnamechecking_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_deletemeetingrequestfrominboxwhenresponding","displayName":"Delete meeting request from Inbox when responding (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_deletemeetingrequestfrominboxwhenresponding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_deletemeetingrequestfrominboxwhenresponding_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_deletemeetingrequestfrominboxwhenresponding_l_deletemeetingrequestfrominboxwhenresponding","displayName":"Delete meeting request from Inbox when responding (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_deletemeetingrequestfrominboxwhenresponding_l_deletemeetingrequestfrominboxwhenresponding_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_deletemeetingrequestfrominboxwhenresponding_l_deletemeetingrequestfrominboxwhenresponding_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_messagesexpireafterdays","displayName":"Messages expire after (days) (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_messagesexpireafterdays_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_messagesexpireafterdays_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_messagesexpireafterdays_l_messagesexpireafterdays","displayName":"Messages expire after (days): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance","displayName":"Set importance (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance","displayName":"Set importance: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance_2","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance_1","displayName":"Normal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance_0","displayName":"Low","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity","displayName":"Set sensitivity (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_l_setsensitivity","displayName":"Set sensitivity: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_l_setsensitivity_0","displayName":"Normal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_l_setsensitivity_1","displayName":"Personal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_l_setsensitivity_2","displayName":"Private","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_l_setsensitivity_3","displayName":"Confidential","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_suggestnameswhilecompletingtoccandbccfields","displayName":"Suggest names while completing To, Cc, and Bcc fields (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_suggestnameswhilecompletingtoccandbccfields_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_suggestnameswhilecompletingtoccandbccfields_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_suggestnameswhilecompletingtoccandbccfields_l_suggestnameswhilecompletingtoccandbccfields","displayName":"Suggest names while completing To, Cc, and Bcc fields (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_suggestnameswhilecompletingtoccandbccfields_l_suggestnameswhilecompletingtoccandbccfields_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_suggestnameswhilecompletingtoccandbccfields_l_suggestnameswhilecompletingtoccandbccfields_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2.updates.4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts","displayName":"Prevent copying or moving items between accounts (User)","description":"This policy setting allows you to prevent items from being copied or moved to other accounts or PSTs.\r\n\r\nIf you enable this policy setting, items will be prevented from being moved or copied to other accounts or PSTs. Enter one of the following details:\r\n\r\n- \"Contoso.com\": prevents copying or moving from the account corresponding to the listed domain\r\n- \"*\": prevents copying from all accounts and PST's\r\n- \"SharePoint\": prevents copies or moves from the SharePoint PST\r\n\r\nIf you disable or do not configure this policy setting, copying or moving items between accounts or PSTs is allowed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2.updates.4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2.updates.4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2.updates.4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts_l_preventcopyingormovingitemsbetweenaccountsid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"ee62e9fc-14c8-4f24-aa7e-89524087a802","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize37","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ee62e9fc-14c8-4f24-aa7e-89524087a802","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize37_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"ee62e9fc-14c8-4f24-aa7e-89524087a802","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize37_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"ee62e9fc-14c8-4f24-aa7e-89524087a802","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disablecommandbar38","displayName":"Disable command bar buttons and menu items (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"8184df77-410e-41a6-b687-88de05769977","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disablecommandbar38_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disablecommandbar38_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disablecommandbar38_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8184df77-410e-41a6-b687-88de05769977","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys39","displayName":"Disable shortcut keys (User)","description":"Specify the virtual key code and modifier for the shortcut key to disable.","helpText":"","infoUrls":[],"categoryId":"8184df77-410e-41a6-b687-88de05769977","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys39_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys39_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys39_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8184df77-410e-41a6-b687-88de05769977","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_predefined_l_hidequickstepsgallery","displayName":"Disable Quick Steps Gallery (User)","description":"This policy setting allows you to hide the Quick Steps Gallery in the Ribbon. By default, the Quick Steps Gallery is included in the Home tab of the Outlook explorer Ribbon. \r\n\r\nIf you enable this policy setting, you will hide the Quick Steps Gallery in the Ribbon.\r\n\r\nIf you disable or do not configure this policy setting, the Quick Steps Gallery will be included in the Home tab of the Outlook explorer Ribbon.","helpText":"","infoUrls":[],"categoryId":"d59dfcc1-6c35-41de-bfb6-de94b8120ca5","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_predefined_l_hidequickstepsgallery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_predefined_l_hidequickstepsgallery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage","displayName":"Calendar Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Calendar Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_showassociatedwebpage42","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_showassociatedwebpage42_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_showassociatedwebpage42_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage44","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage44_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage44_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_urladdressofassociatedwebpage43","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage","displayName":"Contacts Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Contacts Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_showassociatedwebpage45","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_showassociatedwebpage45_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_showassociatedwebpage45_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage47","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage47_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_contactsfolderhomepage_l_urladdressofassociatedwebpage46","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage","displayName":"Deleted Items Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Deleted Items Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_showassociatedwebpage48","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_showassociatedwebpage48_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_showassociatedwebpage48_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage50","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage50_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage50_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_urladdressofassociatedwebpage49","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_disablefolderhomepages","displayName":"Do not allow Home Page URL to be set in folder Properties (User)","description":"By default, users can set a URL to be used as the Home Page for a folder by entering the URL on the Home Page tab on the folder's Properties dialog box. By enabling this setting, you can disallow setting Folder Home Pages for all folders.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_disablefolderhomepages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_disablefolderhomepages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage","displayName":"Drafts Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Drafts Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_showassociatedwebpage51","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_showassociatedwebpage51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_showassociatedwebpage51_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage53","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage53_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage53_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_draftsfolderhomepage_l_urladdressofassociatedwebpage52","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage","displayName":"Inbox Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Inbox Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_showassociatedwebpage40","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_showassociatedwebpage40_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_showassociatedwebpage40_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_urladdressofassociatedwebpage41","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage","displayName":"Journal Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Journal Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_showassociatedwebpage54","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_showassociatedwebpage54_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_showassociatedwebpage54_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage56","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage56_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage56_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_urladdressofassociatedwebpage55","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage","displayName":"Notes Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Notes Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_showassociatedwebpage57","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_showassociatedwebpage57_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_showassociatedwebpage57_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage59","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage59_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_urladdressofassociatedwebpage58","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage","displayName":"Outbox Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Outbox Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_showassociatedwebpage60","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_showassociatedwebpage60_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_showassociatedwebpage60_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage62","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage62_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage62_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_urladdressofassociatedwebpage61","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage","displayName":"RSS Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the RSS Feeds Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_showassociatedwebpage","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_showassociatedwebpage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_showassociatedwebpage_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_turnoffinternetexplorersecuritychecks","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_turnoffinternetexplorersecuritychecks_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_turnoffinternetexplorersecuritychecks_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_urladdressofassociatedwebpage","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage","displayName":"Sent Items Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Sent Items Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_showassociatedwebpage63","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_showassociatedwebpage63_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_showassociatedwebpage63_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage65","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage65_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage65_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_urladdressofassociatedwebpage64","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage","displayName":"Tasks Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Tasks Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_showassociatedwebpage66","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_showassociatedwebpage66_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_showassociatedwebpage66_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage68","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage68_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage68_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_urladdressofassociatedwebpage67","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions","displayName":"Configure form regions permissions (User)","description":"By default, all form region customizations are permitted to run in Outlook. By using this setting, you can disable all form region customizations, or specify that form regions must be registered on a per-computer basis, rather than a per-user basis.","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart","displayName":"Configure form regions permissions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart_0","displayName":"All form regions are allowed to run","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart_1","displayName":"Allow only those registered in HKLM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart_2","displayName":"No form regions are allowed to run","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions","displayName":"Locked form regions (User)","description":"This policy setting allows you to configure adjoining form regions to be always expanded.\r\n\r\nIf you enable this policy setting, you may enter the adjoining form region name as the Value name and the Value data as \"1\" (without quotes). This ensures that users see the whole adjoining form region and cannot collapse it. This works for both Explorer and Inspector.\r\n\r\nIf you disable or do not configure this policy setting, adjoining form regions are not expanded.","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions_l_empty76","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions_l_empty76_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions_l_empty76_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_infopathintegration_l_disableinfopathpropertiespromotioninoutlook","displayName":"Do not promote InfoPath forms properties into Outlook properties (User)","description":"By default, InfoPath property promotion is enabled. This setting allows you to disable the ability to promote InfoPath forms properties into Outlook properties. This feature allows InfoPath forms to promote properties from the underlying data into named properties in Outlook. These properties are displayed in views on folders, and users can group, filter, and sort by them.","helpText":"","infoUrls":[],"categoryId":"e1a2f289-40d8-4e7c-b0a6-cd36f0ee9111","categoryName":"InfoPath Integration","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_infopathintegration_l_disableinfopathpropertiespromotioninoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_infopathintegration_l_disableinfopathpropertiespromotioninoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces","displayName":"Default servers and data for Meeting Workspaces (User)","description":"Using this policy, you can define default servers and server data for Meeting Workspaces. It is recommended that you draft this policy in a text editor and paste it into the text box in the setting. You can add up to five servers by listing them in the \"Default server:\" text box. Each server is defined by a pipe-delimited list, with a total of six pipes per server record. The OrganizerName field is left blank. For example: http://server1 | Friendly name for server1 | templateLCID | templateID | TemplateName | OrganizerName | http://server2 | ... and so on. For more information, see the Office 2016 Resource Kit on TechNet.","helpText":"","infoUrls":[],"categoryId":"f77040df-7dd2-4916-b6a0-5ef962686d4e","categoryName":"Meeting Workspace","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces_l_defaultserver","displayName":"Default server: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f77040df-7dd2-4916-b6a0-5ef962686d4e","categoryName":"Meeting Workspace","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist","displayName":"Disable user entries to server list (User)","description":"This policy setting controls whether Outlook users can add entries to the list of SharePoint servers when establishing a meeting workspace. \r\n\r\nIf you enable this policy setting, you can choose between two options to determine whether Outlook users can add entries to the published server list: \r\n\r\n- Publish default, allow others. This option is the default configuration in Outlook. \r\n\r\n- Publish default, disallow others. This option prevents users from adding servers to the default published server list. \r\n\r\nIf you disable or do not configure this policy setting, when users create a meeting workspace, they can choose a server from a default list provided by administrators or manually enter the address of a server that is not listed. This is the equivalent of Enabled -- Publish default, allow others.","helpText":"","infoUrls":[],"categoryId":"f77040df-7dd2-4916-b6a0-5ef962686d4e","categoryName":"Meeting Workspace","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_l_checktodisableusersfromaddingentriestoserverlist","displayName":"Check to disable users from adding entries to server list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f77040df-7dd2-4916-b6a0-5ef962686d4e","categoryName":"Meeting Workspace","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_l_checktodisableusersfromaddingentriestoserverlist_1","displayName":"Publish default, allow others","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_l_checktodisableusersfromaddingentriestoserverlist_2","displayName":"Publish default, disallow others","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody","displayName":"Change the limit for the number of MIME body parts (User)","description":"By default, the limit is 250 for the number of MIME body parts when an e-mail message is converted from MIME to MAPI. The number can be set to any positive integer. This helps prevent scenarios in which Outlook hangs while attempting conversion.","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody_l_empty75","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitrecipients","displayName":"Change the limit for the number of recipients (User)","description":"By default, the limit is 12288 recipients included for an e-mail message when the message is converted from MIME to MAPI. The number can be set to any positive integer. This helps prevent scenarios in which Outlook hangs while attempting conversion.","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitrecipients_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitrecipients_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitrecipients_l_empty73","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitforthenumberof","displayName":"Change the limit for the number of nested embedded messages (User)","description":"By default, the limit is 50 embedded messages when an e-mail message is converted from MIME to MAPI. The number can be set to any positive integer. This helps prevent scenarios in which Outlook hangs while attempting conversion.","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitforthenumberof_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitforthenumberof_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitforthenumberof_l_empty71","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitfriendlyname","displayName":"Change the limit for the number of characters in Friendly Name (User)","description":"By default, the limit is 1000 characters for Friendly Name when an e-mail message is converted from MIME to MAPI. The number can be set to any positive integer. This helps prevent scenarios in which Outlook hangs while attempting conversion.","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitfriendlyname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitfriendlyname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitfriendlyname_l_empty72","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitmimeheaders","displayName":"Change the limit for the number of MIME headers (User)","description":"By default, the limit is 20000 for the number of MIME headers when an e-mail message is converted from MIME to MAPI. The number can be set to any positive integer. This helps prevent scenarios in which Outlook hangs while attempting conversion.","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitmimeheaders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitmimeheaders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changethelimitmimeheaders_l_empty74","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_addnewcategories","displayName":"Add new categories (User)","description":"This policy setting allows you to add (append) new categories to the user's current list of categories.\r\n\r\nIf you enable this policy setting, you may add (append) new categories to the user's current list of categories (the default list of categories or the list of categories the user has created). A category's length should not exceed 255 characters.\r\n\r\nIf you disable or do not configure this policy setting, the user's current list of categories is not modified.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_addnewcategories_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_addnewcategories_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_addnewcategories_l_enternewcategoriessemicolondelimited","displayName":"Enter new categories (comma or semicolon delimited) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_allowcryptoautosave","displayName":"Extend Outlook Autosave to include encrypted e-mail messages (User)","description":"By default, Outlook does not automatically save copies of unsent e-mail messages that are encrypted. You can enable this setting so that Outlook autosaves unsent encrypted e-mail messages to the user's Drafts folder.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_allowcryptoautosave_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_allowcryptoautosave_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disableaddinlogging","displayName":"Disable Windows event logging for Outlook add-ins (User)","description":"This policy setting governs logging of connected add-ins to the Windows event log.\r\n\r\nIf you enable this policy setting, an inventory of connected Outlook add-ins will not be written to the Windows event log.\r\n\r\nIf you disable or do not configure this policy setting, an inventory of connected Outlook add-ins will be written to the Windows event log.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disableaddinlogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disableaddinlogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disabledistributionlistexpansion","displayName":"Do not expand Contact Groups (User)","description":"This policy setting controls whether Outlook users can expand Contact Groups when addressing e-mail messages. \r\n\r\nIf you enable this policy setting, Outlook users cannot expand Contact Groups. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook users add a Contact Group to the To, CC, or BCC fields of an e-mail message or other item, they can expand the Contact Group to see the e-mail addresses of everyone in the group.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disabledistributionlistexpansion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disabledistributionlistexpansion_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablevlvbrowsingonldapservers","displayName":"Disable VLV Browsing on LDAP servers (User)","description":"When this policy is enabled, Outlook will not use the Virtual List Views (VLV) LDAP extension when querying an LDAP servier. When the policy is not configured or disabled, Outlook will use the Virtual Lst Views (VLV) LDAP extension when querying an LDAP server.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablevlvbrowsingonldapservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablevlvbrowsingonldapservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablewindowsfriendlylogonmailquery","displayName":"Do not show unread message count on Windows Welcome screen (User)","description":"By default, Windows queries Outlook for the unread message count for users and displays the result on the Windows Welcome screen. By enabling this setting, you can change this behavior so that Windows does not provide this feature on the Welcome screen.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablewindowsfriendlylogonmailquery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablewindowsfriendlylogonmailquery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_donotdownloadpermissionlicenseforirmemailduring","displayName":"Do not download rights permission license information for IRM e-mail during Exchange folder sync (User)","description":"By default, IRM license information for e-mail messages is downloaded to the user's local cache when Outlook synchronizes with Exchange. By enabling this setting, you can change this behavior so that licence information is not cached locally and users must connect to the network to retreive license information in order to open rights-managed e-mail messages.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_donotdownloadpermissionlicenseforirmemailduring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_donotdownloadpermissionlicenseforirmemailduring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\Outlook\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\Outlook\\Addins.\r\n\r\nYou can also obtain the ProgID of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.\r\n\r\nAdd-ins that are disabled by this policy will never be disabled by the Outlook add-in disabling feature, which disables add-ins for performance, resiliency, or reliability reasons.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges","displayName":"Managing Categories during e-mail exchanges (User)","description":"By default, categories on incoming e-mail are removed, and categories are removed when replying to or forwarding an e-mail. This setting allows you to control how categories are shared as users exchange e-mail messages. You can specify that categories are not removed for users' incoming e-mail. You can also specify that e-mail messages that users reply to or forward retain the categories on the original message.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_acceptcategoriesassignedtoincomingmailbythesender","displayName":"Accept Categories assigned to incoming mail by the sender (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_acceptcategoriesassignedtoincomingmailbythesender_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_acceptcategoriesassignedtoincomingmailbythesender_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_whenreplyingtoandforwardingmailincludepersonalcategories","displayName":"When replying to and forwarding mail, include personal categories (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_whenreplyingtoandforwardingmailincludepersonalcategories_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_whenreplyingtoandforwardingmailincludepersonalcategories_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventmapiservicesfrombeingadded","displayName":"Prevent MAPI services from being added (User)","description":"By default, any MAPI service can be added to a user profile as an Outlook account. This setting allows you to prevent users from adding a specific MAPI services on the list of services. To prevent adding a MAPI service, append the name of the service to the list of services stored in this setting, separated by from a previous name by a semi-colon (;). For example, if you wanted to prevent adding the Outlook Mobile Service and Live Meeting Transport, you would configure this setting \"MSOMS;LiveMeeting\".","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventmapiservicesfrombeingadded_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventmapiservicesfrombeingadded_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventmapiservicesfrombeingadded_l_preventmapiservicesfrombeingaddedpart","displayName":"Enter MAPI services to disable (semi-colon delimited) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes","displayName":"Prevent users from adding e-mail account types (User)","description":"Disables/Enables the option for adding e-mail account of the associated type in the Server Types page of the E-mail Accounts dialog box.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingeasemailaccounts","displayName":"Prevent users from adding Exchange ActiveSync e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingeasemailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingeasemailaccounts_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingexchangeemailaccounts","displayName":"Prevent users from adding Exchange e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingexchangeemailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingexchangeemailaccounts_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingimapemailaccounts","displayName":"Prevent users from adding IMAP e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingimapemailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingimapemailaccounts_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingothertypesofemailaccounts","displayName":"Prevent users from adding other types of e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingothertypesofemailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingothertypesofemailaccounts_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingpop3emailaccounts","displayName":"Prevent users from adding POP3 e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingpop3emailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingpop3emailaccounts_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfrommakingchangestooutlookprofiles","displayName":"Prevent users from making changes to Outlook profiles (User)","description":"This policy setting allows you to prevent users from accessing profile or account configuration tools through either Account Settings or through the Mail Control Panel Applet.\r\n\r\nIf you enable this policy setting, users will see the error, \"This feature has been disabled by your system administrator\" if they select the Account Settings button under Account Information found by clicking on the File tab. Users will also be unable to access profile configuration the Mail Control Panel Applet.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to access Account Settings and the Mail Control Panel Applet normally.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfrommakingchangestooutlookprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfrommakingchangestooutlookprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest","displayName":"Specify delay before sending people search request (User)","description":"This policy is used to set the delay for sending people search requests from the Find a Contact box in Outlook and the Related People section that appears in the Backstage view (Info tab) of Office applications.\r\n\r\nIf you enable this policy setting, you can specify the delay in milliseconds between when the user stops (or pauses) typing in the search box and when the application sends a search request.\r\n\r\nIf you disable or do not configure this policy setting, the default delay is 200 milliseconds (0.20 seconds).","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest_l_specifydelaybeforesendingpeoplesearchrequestspinid","displayName":"in milliseconds (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout","displayName":"Set the time-out interval for Outlook people search (User)","description":"This policy setting controls the time-out interval of Outlook people search. Outlook returns as many people search results as possible before the time-out interval lapses. If the search results are incomplete, Outlook displays a message at the bottom of the results list.\r\n\r\nIf you enable this policy setting, you can specify the time-out interval in milliseconds.\r\n\r\nIf you disable or do not configure this policy setting, the time-out interval is 60,000 milliseconds (60 seconds).","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout_l_specifyoutlookpeoplesearchtimeoutspinid","displayName":"in milliseconds (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_workflowtasksinoutlook","displayName":"Do not display \"Open this task\" button for workflow tasks (User)","description":"As part of E-mail notification of workflow tasks, users can edit a task by clicking the \"Open this task\" button to display the task dialog box for the workflow task. When this setting is enabled, the \"Open this task\" button is not displayed.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_workflowtasksinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_workflowtasksinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforostfiles","displayName":"Default location for OST files (User)","description":"This policy setting allows you to specify a different folder location for Outlook Data File (OST) files on user computers. \r\n\r\nIf you enable this policy setting, you can specify a location for OST files on user computers.\r\n\r\nIf you disable or do not configure this policy setting, OST files are located in: %LOCALAPPDATA%\\Microsoft\\Outlook on user computers.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforostfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforostfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforostfiles_l_defaultlocationforostfilespart","displayName":"Default location for OST files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforpstfiles","displayName":"Default location for PST files (User)","description":"This policy setting allows you to specify a different folder location for Outlook Data File (PST) files on user computers. \r\n\r\nIf you enable this policy setting, you can specify a location for PST files on user computers.\r\n\r\nIf you disable or do not configure this policy setting, PST files are located in: %USERPROFILE%\\Documents\\Outlook Files\\ on user computers.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforpstfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforpstfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_defaultlocationforpstfiles_l_defaultlocationforpstfiles79","displayName":"Default location for PST files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_donotsendmeetingforwardnotifications","displayName":"Do not send meeting forward notifications (User)","description":"This policy setting prevents Outlook from sending meeting forward notifications. This does not affect whether or not Exchange sends meeting forward notifications. \r\n\r\nIf you enable this policy setting, Outlook will not send meeting forward notifications.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will send meeting forward notifications.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_donotsendmeetingforwardnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_donotsendmeetingforwardnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstabsolutemaximumsize","displayName":"Large PST: Absolute maximum size (User)","description":"Specifies the maximum allowable size (in megabytes) for an Outlook Data File.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstabsolutemaximumsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstabsolutemaximumsize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstabsolutemaximumsize_l_enterabsolutemaximumsizeforpstinmegabytes2","displayName":"(0 - 4,294,967,295 MB) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstsizetodisableaddingnewcontent","displayName":"Large PST: Size to disable adding new content (User)","description":"Specifies the size at which Outlook will no longer accept new content into an Outlook Data File.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstsizetodisableaddingnewcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstsizetodisableaddingnewcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_largepstsizetodisableaddingnewcontent_l_entersizetodisableaddingnewcontenttopstinmegabytes2","displayName":"(0 - 4,294,967,295 MB) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize","displayName":"Legacy PST: Absolute maximum size (User)","description":"Specifies the maximum allowable size (in bytes) for an Outlook 97-2002 Data File.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize_l_enterabsolutemaximumsizeforpstinbytes2","displayName":"(0 - 2,075,149,312 bytes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstsizetodisableaddingnewcontent","displayName":"Legacy PST: Size to disable adding new content (User)","description":"Specifies the size at which Outlook will no longer accept new content into an Outlook Data File.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstsizetodisableaddingnewcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstsizetodisableaddingnewcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstsizetodisableaddingnewcontent_l_entersizetodisableaddingnewcontenttopstinbytes2","displayName":"(0 - 2,075,149,312 Bytes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_permanentlyremovealldeleteditems","displayName":"Permanently remove all deleted content from PST and OST files (User)","description":"By default, a small percentage of deleted data is not overwritten in Outlook PST and OST files. By enabling this setting, all deleted data in PST and OST files is overwritten when users exit Outlook.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_permanentlyremovealldeleteditems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_permanentlyremovealldeleteditems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi","displayName":"Preferred PST Mode (Unicode/ANSI) (User)","description":"Specifies whether new PST files created by the user are to be in Unicode or ANSI format, and whether the user is allowed to choose that format.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_l_chooseadefaultformatfornewpsts","displayName":"Choose a default format for new PSTs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_l_chooseadefaultformatfornewpsts_0","displayName":"Prefer Unicode PST","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_l_chooseadefaultformatfornewpsts_1","displayName":"Prefer ANSI PST","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_l_chooseadefaultformatfornewpsts_2","displayName":"Enforce Unicode PST","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preferredpstmodeunicodeansi_l_chooseadefaultformatfornewpsts_3","displayName":"Enforce ANSI PST","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingnewcontentto","displayName":"Prevent users from adding new content to existing PST files (User)","description":"This setting prevents users from adding any new content to PST files linked to their profiles.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingnewcontentto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingnewcontentto_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts","displayName":"Prevent users from adding PSTs to Outlook profiles and/or prevent using Sharing-Exclusive PSTs (User)","description":"By default, users can add PSTs to their Outlook profiles and can use Sharing-Exclusive PSTs for storing SharePoint Lists and Internet Calendars. You can use this setting to limit users' ability to store mail in a decentralized fashion. You can block the use of PSTs completely, but be aware that blocking all PSTs disables Outlook features such as SharePoint Lists and Internet Calendar. \r\n\r\nIf instead you allow only Sharing-Exclusive PSTs to be added to user profiles, PST usage is still limited but the Outlook features that rely on special PSTs are not disabled. The setting that allows Sharing-Exclusive PSTs to be added blocks users from creating new folders in the Sharing-Exclusive PST; copying existing mail folders from their default store to the PST; and copying individual mail items to the root of the PST.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts_l_empty78","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts_l_empty78_0","displayName":"(default) PSTs can be added","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts_l_empty78_1","displayName":"No PSTs can be added","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_preventusersfromaddingpsts_l_empty78_2","displayName":"Only Sharing-Exclusive PSTs can be added","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_pstnullfreeondelete","displayName":"PST Null Data on Delete (User)","description":"This policy setting allows you to force Outlook to fully nullify deleted data in users’ Personal Folder files (.pst) at the time that the data is deleted. \r\n \r\nIf you enable this policy setting, data is immediately nullified in PST files when deleted. \r\n \r\nIf you disable or do not configure this policy setting, data remains in PST files until it is purged or overwritten by the user.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_pstnullfreeondelete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_pstnullfreeondelete_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_upgradeonlythedefaultstore","displayName":"Upgrade only the default store (User)","description":"This policy setting allows you to specify that only the default data file is upgraded on the first boot of Outlook.\r\n\r\nIf you enable this policy setting, only the data file associated with your delivery mailbox is upgraded.\r\n\r\nIf you disable or do not configure this policy setting, all Outlook Data Files are upgraded.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_upgradeonlythedefaultstore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_upgradeonlythedefaultstore_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior","displayName":"Configure fast shutdown behavior (User)","description":"This policy setting controls Outlook's \"fast shutdown\" behavior. \r\n\r\nIf you enable this policy setting, you may select one of these options:\r\n\r\n- MAPI provider does not support: Outlook should always use Fast Shutdown unless a MAPI provider explicitly does not support it.\r\n- All MAPI providers support: Outlook only uses Fast Shutdown if all MAPI providers do support it.\r\n- Never: Outlook never uses Fast Shutdown\r\n\r\nIf you disable or do not configure this policy setting, the behavior will be the same as the \"MAPI provider does not support\" option.","helpText":"","infoUrls":[],"categoryId":"ffb0a109-2507-42b3-b26f-9f667f2d5029","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior_l_configurefastshutdownbehaviordropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ffb0a109-2507-42b3-b26f-9f667f2d5029","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior_l_configurefastshutdownbehaviordropid_0","displayName":"MAPI provider does not support","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior_l_configurefastshutdownbehaviordropid_1","displayName":"All MAPI providers support","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehavior_l_configurefastshutdownbehaviordropid_2","displayName":"Never","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehaviorforaddins","displayName":"Configure fast shutdown behavior for add-ins (User)","description":"This policy setting controls Outlook's \"fast shutdown\" behavior for add-ins.\r\n\r\nIf you enable this policy setting, the BeginShutdown and OnDisconnection events should always be called for all add-ins. \r\n\r\nIf you disable or do not configure this policy setting, all Outlook addins should always use the Addin Fast Shutdown behavior and not have the BeginShutdown and OnDisconnection events called.","helpText":"","infoUrls":[],"categoryId":"ffb0a109-2507-42b3-b26f-9f667f2d5029","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehaviorforaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_configurefastshutdownbehaviorforaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_preventshutdownifexternalreferencesexist","displayName":"Prevent shutdown if external references exist (User)","description":"This policy setting controls whether Outlook should ignore external references during shutdown.\r\n\r\nIf you enable this policy setting, shutdown will not occur if external references exist.\r\n\r\nIf you disable or do not configure this policy setting, external references will be ignored during shutdown.","helpText":"","infoUrls":[],"categoryId":"ffb0a109-2507-42b3-b26f-9f667f2d5029","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_preventshutdownifexternalreferencesexist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_shutdown_l_preventshutdownifexternalreferencesexist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions_l_internetandnetworkpathsintohyperlinks","displayName":"Internet and network paths into hyperlinks (User)","description":"This policy setting specifies whether Outlook automatically turns text that represents Internet and network paths into hyperlinks. This option can also be configured by selecting the “Internet and network paths with hyperlinks” check box that is available on the Outlook | File | Options | Mail | Editor Options.... | Proofing | AutoCorrect Options… | AutoFormat tab on the user interface (UI).\r\n\r\nIf you enable or do not configure this policy setting, text in Outlook that represents internet and network paths are automatically turned into hyperlinks. This is the default behavior of Outlook.\r\n\r\nIf you disable this policy setting, text in Outlook that represents internet and network paths are not automatically turned into hyperlinks.","helpText":"","infoUrls":[],"categoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","categoryName":"Outlook Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions_l_internetandnetworkpathsintohyperlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions_l_internetandnetworkpathsintohyperlinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_cacheothersmail","displayName":"Disable shared mail folder caching (User)","description":"This policy setting allows you to control the caching of shared mail folders.\r\n\r\nIf you enable this policy setting, Outlook will only cache shared non-mail folders.\r\n\r\nIf you disable or do not configure this policy setting, shared mail and non-mail folders you have access to are cached in your .ost file when you add another mailbox to your profile.","helpText":"","infoUrls":[],"categoryId":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","categoryName":"Delegates","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_cacheothersmail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_cacheothersmail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_locationofitemsdeletedbydelegates","displayName":"Store deleted items in owner's mailbox instead of delegate's mailbox (User)","description":"This policy setting allows you to store deleted items in the owner's mailbox instead of the delegate's mailbox.\r\n\r\nIf you enable this policy setting, deleted items are stored in the owner's Deleted Items folder. For this setting to work correctly, the owner must also give the delegate permission to write to the owner's Deleted Items folder.\r\n\r\nIf you disable or do not configure this policy setting, items deleted by a delegate are stored in the delegate's Deleted Items Folder instead of the owner's Deleted Items folder.","helpText":"","infoUrls":[],"categoryId":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","categoryName":"Delegates","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_locationofitemsdeletedbydelegates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_locationofitemsdeletedbydelegates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_disablereadingpanecompose","displayName":"Disable Reading Pane Compose (User)","description":"This policy setting allows you to control whether user’s responses to emails are composed inline on the reading pane or in a new window.\r\n\r\nIf you enable this policy setting, responses to emails are composed in new windows.\r\n\r\nIf you disable or do not configure this policy setting, responses to emails are composed inline in the reading pane.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_disablereadingpanecompose_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_disablereadingpanecompose_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_forceselectionofaccountbeforesending","displayName":"Force selection of account before sending (User)","description":"This policy setting enables you to force users to select an e-mail account from which to send outgoing e-mail.\r\n\r\nIf you enable this policy setting, users must choose an e-mail account before they can send an e-mail.\r\n\r\nIf you disable or do not configure this policy setting, e-mail is sent from the default e-mail account if users do not select a specific e-mail account.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_forceselectionofaccountbeforesending_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_forceselectionofaccountbeforesending_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_outlookprotectionrules","displayName":"Outlook Protection Rules (User)","description":"This policy setting controls whether the Outlook Protection Rules add-in is enabled.\r\n\r\nIf you enable or do not configure this policy setting the add-in automatically downloads Outlook Protection Rules from Exchange and processes them when each Exchange mailbox user composes a new e-mail. \r\n\r\nIf you disable this policy setting the add-in does not download or process Outlook Protection Rules.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_outlookprotectionrules_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_outlookprotectionrules_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat_l_disablesignatures","displayName":"Do not allow signatures for e-mail messages (User)","description":"This policy setting allows you to prevent Outlook users from adding signatures to e-mails they create, reply to, or forward. \r\n\r\nIf you enable this policy setting, Outlook users cannot manually add signatures to e-mails they create, reply to, or forward, nor will they be able to configure automatic signatures.\r\n\r\nIf you disable or do not configure this policy setting, Outlook 2016 users can add signatures to e-mail messages either manually or automatically.","helpText":"","infoUrls":[],"categoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","categoryName":"Mail Format","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat_l_disablesignatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat_l_disablesignatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_autoselectencodingforoutgoingmessages","displayName":"Auto-select encoding for outgoing messages (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_autoselectencodingforoutgoingmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_autoselectencodingforoutgoingmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_disableinternationalizeddomainnamesidninoutlook","displayName":"Disable Internationalized Domain Names (IDN) in Outlook (User)","description":"By default, Outlook supports Internationalized Domain Names (IDN) for SMTP addresses in Outlook if Windows provides the appropriate support for this feature. You can disable IDN support so that Punycode rather than native characters are used for rendering SMTP addresses. \r\n\r\nYou might choose to disable IDN support in Outlook if you do not typically expect non-ASCII characters in SMTP addresses. \r\n\r\nThis setting does not affect the support of IDN in URLs.","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_disableinternationalizeddomainnamesidninoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_disableinternationalizeddomainnamesidninoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages","displayName":"Encoding for outgoing messages (User)","description":"Sets the value in the option \"Preferred encoding for outgoing messages\".","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages","displayName":"Use this encoding for outgoing messages: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28596","displayName":"Arabic (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1256","displayName":"Arabic (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28594","displayName":"Baltic (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1257","displayName":"Baltic (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28592","displayName":"Central European (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1250","displayName":"Central European (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_54936","displayName":"Chinese Simplified (GB18030)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_936","displayName":"Chinese Simplified (GB2312)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_52936","displayName":"Chinese Simplified (HZ)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_950","displayName":"Chinese Traditional (Big5)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28595","displayName":"Cyrillic (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_20866","displayName":"Cyrillic (KOI8-R)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_21866","displayName":"Cyrillic (KOI8-U)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1251","displayName":"Cyrillic (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28597","displayName":"Greek (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1253","displayName":"Greek (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_38598","displayName":"Hebrew (ISO-Logical)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1255","displayName":"Hebrew (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_51932","displayName":"Japanese (EUC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_50220","displayName":"Japanese (JIS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_50221","displayName":"Japanese (JIS-Allow 1 byte Kana)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_932","displayName":"Japanese (Shift-JIS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_949","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_51949","displayName":"Korean (EUC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28593","displayName":"Latin 3 (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28605","displayName":"Latin 9(ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_874","displayName":"Thai (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28599","displayName":"Turkish (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1254","displayName":"Turkish (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_65000","displayName":"Unicode (UTF-7)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_65001","displayName":"Unicode (UTF-8)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_20127","displayName":"US-ASCII","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_50000","displayName":"User Defined","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1258","displayName":"Vietnamese (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28591","displayName":"Western European (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1252","displayName":"Western European (Windows)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags","displayName":"English message headers and flags (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_l_useenglishformessageflags","displayName":"Use English for message flags (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_l_useenglishformessageflags_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_l_useenglishformessageflags_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_l_useenglishformessageheadersonrepliesorforwards","displayName":"Use English for message headers on replies or forwards (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_l_useenglishformessageheadersonrepliesorforwards_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_englishmessageheadersandflags_l_useenglishformessageheadersonrepliesorforwards_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_euroencodingforoutgoingmessages","displayName":"Euro encoding for outgoing messages (User)","description":"This policy setting allows you to choose whether to ignore the euro character when auto-detecting the encoding of an outgoing message and the preferred encoding does not support euro.","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_euroencodingforoutgoingmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_euroencodingforoutgoingmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_euroencodingforoutgoingmessages_l_whenpreferredencodingdoesnotsupporteuro2","displayName":"Auto-select should: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_euroencodingforoutgoingmessages_l_whenpreferredencodingdoesnotsupporteuro2_0","displayName":"Send messages as UTF 8","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_euroencodingforoutgoingmessages_l_whenpreferredencodingdoesnotsupporteuro2_1","displayName":"ignore euro","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions","displayName":"Outlook Rich Text options (User)","description":"This policy setting controls how Outlook sends Rich Text Format (RTF) messages to Internet recipients.\r\n\r\nIf you enable this policy setting, you may choose from the following for handling RTF messages addressed to recipients on the Internet:\r\n* Convert to Plain Text format - Outlook converts the message to plain text format in the default character set. Any message formatting will be lost.\r\n\r\nIf you disable or do not configure this policy setting, Outlook automatically converts RTF formatted messages that are sent over the Internet to HTML format, so that the message formatting is maintained and attachments are received.","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions_l_whensendingoutlookrichtextmessagestointernetrecipients2","displayName":"Use this format: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions_l_whensendingoutlookrichtextmessagestointernetrecipients2_1","displayName":"Convert to Plain Text format","description":null,"helpText":null}},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions","displayName":"Plain text options (User)","description":"This policy setting allows you to control how plain text messages are formatted when they are sent from Outlook. \r\n\r\nIf you enable this policy setting, text is automatically wrapped in Internet e-mail messages and attachments are encoded in UUENCODE format. \r\n\r\nIf you disable this policy setting, Outlook uses the standard MIME format to encode attachments in plain text Outlook messages. Users will not be able to change this configuration. \r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Disabled, but users can modify plain text options in Outlook when required by clicking Tools, clicking Options, clicking the Mail Format tab, clicking Internet Format, and changing the values under \"Plain text options\".","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_automaticallywraptextatxcharacters","displayName":"Automatically wrap text at characters. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_encodeattachmentsinuuencodeformatwhensending1","displayName":"Encode attachments in UUENCODE format (User)","description":"","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_encodeattachmentsinuuencodeformatwhensending1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_encodeattachmentsinuuencodeformatwhensending1_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor","displayName":"Set message format (User)","description":"This policy setting controls the default message format in Outlook. \r\n\r\nIf you do not configure this policy setting, new e-mail messages in Outlook are formatted as HTML. \r\n\r\nIf you enable this policy setting, you can set the default e-mail format in Outlook to HTML, Rich Text, or plain text. Users can choose a format other than the default when composing messages. \r\n\r\nIf you disable this policy setting, Outlook uses HTML as the default e-mail format and users will not be able to change it. \r\n\r\nIf you do not configure this policy setting, Outlook uses HTML as the default e-mail format, but users can choose a format other than the default when composing messages.","helpText":"","infoUrls":[],"categoryId":"25df12bc-5ebd-4db2-8930-5d27690f3e60","categoryName":"Message Format","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor_l_usethefollowingformateditorforemailmessages","displayName":"Use the following format for e-mail messages: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25df12bc-5ebd-4db2-8930-5d27690f3e60","categoryName":"Message Format","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor_l_usethefollowingformateditorforemailmessages_131072","displayName":"HTML","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor_l_usethefollowingformateditorforemailmessages_196608","displayName":"Rich Text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting~l_messageformat_l_messageformateditor_l_usethefollowingformateditorforemailmessages_65536","displayName":"Plain Text","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts","displayName":"Stationery Fonts (User)","description":"This policy setting allows you to choose a Stationery font option.\r\n\r\nIf you enable this policy setting, a Stationery font option from the dropdown list will be enforced.\r\n\r\nIf you disable or do not configure this policy setting, the default setting (use theme's font) will be used.","helpText":"","infoUrls":[],"categoryId":"88b16683-81f2-450a-9bf2-42f582e0b748","categoryName":"Stationery and Fonts","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts_l_stationeryfontoptions","displayName":"Stationery font options: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"88b16683-81f2-450a-9bf2-42f582e0b748","categoryName":"Stationery and Fonts","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts_l_stationeryfontoptions_0","displayName":"Use theme's font","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts_l_stationeryfontoptions_1","displayName":"Use user's font on replies and forwards","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_stationeryandfonts_l_stationeryfonts_l_stationeryfontoptions_2","displayName":"Always use user's fonts","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailsetup_l_mailaccountoptions","displayName":"Mail account options (User)","description":"Send messages immediately when connected","helpText":"","infoUrls":[],"categoryId":"114356a4-dfc9-44e9-9a62-f1d601d48445","categoryName":"Mail Setup","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailsetup_l_mailaccountoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailsetup_l_mailaccountoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"fa6bfb01-34f6-4c54-89b9-f7e717e6d394","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_allowselectionfloaties","displayName":"Show Mini Toolbar on selection (User)","description":"Disabling this policy setting will result in Mini Toolbar not being displayed on text selection. By default, Mini Toolbar on selection is enabled and its visibility can be changed via a setting in the Editor Options dialog box.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_allowselectionfloaties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_allowselectionfloaties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableonlinemodeauthdiagnostics","displayName":"Disable online mode for Get Diagnostics. (User)","description":"\r\n This policy setting determines whether online mode for Get Diagnostics is allowed. Enabling this setting will block Get Diagnostics feature from sending authentication and diagnostics logs to our service.\r\n Users will now go through offline mode. We will collect all the logs and store them in the Downloads folder of the user. This user can contact support and decide if they want to send us the logs. \r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableonlinemodeauthdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableonlinemodeauthdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace","displayName":"Disable Preview Place. (User)","description":"\r\n This policy setting determines whether the Preview Place feature is allowed. Enabling this setting will block the Preview Place feature from being available.\r\n Users will no longer be able to preview and provide feedback on upcoming changes in Outlook.\r\n\tNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablereadingpane","displayName":"Do not display the reading pane (User)","description":"By default, the Reading Pane is enabled only in the mail module and located on the right hand side of the window. This setting allows you to disable the reading pane.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablereadingpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablereadingpane_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_donotdownloadphotosfromtheactivedirectory","displayName":"Do not download photos from the Active Directory (User)","description":"This policy setting controls whether user photos will be downloaded from the Active Directory (if available). \r\n\r\nIf you enable this policy setting, photos will not be downloaded.\r\n\r\nIf you disable or do not configure this policy setting, photos will be downloaded.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_donotdownloadphotosfromtheactivedirectory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_donotdownloadphotosfromtheactivedirectory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_emptydeleteditemsfolder","displayName":"Empty the Deleted Items folder when Outlook closes (User)","description":"By default, the Deleted Items folder is not emptied when users exit Outlook. By enabling this setting, you can change this behavior so that the Deleted Items folder is emptied when Outlook closes.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_emptydeleteditemsfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_emptydeleteditemsfolder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hideappsstorebuttoninhometabribbon","displayName":"Hide the Office Store button (User)","description":"The Office Store button allows users to get apps for Outlook from the Home tab in the ribbon.\r\n\r\nIf you enable this policy setting, the Office Store button doesn’t appear on the Home tab in the ribbon.\r\n\r\nIf you disable or don’t configure this policy setting, the Office Store button appears on the Home tab in the ribbon.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hideappsstorebuttoninhometabribbon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hideappsstorebuttoninhometabribbon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hidephotolink","displayName":"Hide photo link (User)","description":"This policy setting configures the link to the user's My Site (when detected) where the user's photo can be uploaded. This link is under the File tab. \r\n\r\nIf you enable this policy setting, the link is not visible.\r\n\r\nIf you disable or do not configure this policy setting, the link is visible.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hidephotolink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_hidephotolink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_makeoutlookthedefaultprogramforemailcontactsandcalendar","displayName":"Make Outlook the default program for E-mail, Contacts, and Calendar (User)","description":"This policy setting controls whether Outlook is the default program for e-mail, contacts, and calendar services.\r\n\r\nIf you enable this policy setting, the \"Make Outlook the default program for E-mail, Contacts, and Calendar\" check box on the General tab of the Office Center is selected and users cannot change it.\r\n\r\nIf you disable this policy setting, users cannot make Outlook the default program for these services.\r\n\r\nIf you do not configure this policy setting, Outlook is made the default program for e-mail, contacts, and calendar services when it is installed, although users can designate other programs as the default programs for these services.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_makeoutlookthedefaultprogramforemailcontactsandcalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_makeoutlookthedefaultprogramforemailcontactsandcalendar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane","displayName":"Reading Pane (User)","description":"Checks/Unchecks the option \"Mark items as read when viewed in the Reading Pane\" in the Reading Pane dialog box.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markitemasreadwhenselectionchanges","displayName":"Mark item as read when selection changes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markitemasreadwhenselectionchanges_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markitemasreadwhenselectionchanges_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markmessagesasreadinreadingwindow","displayName":"Mark messages as read in reading window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markmessagesasreadinreadingwindow_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markmessagesasreadinreadingwindow_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_singlekeyreadingusingspacebar","displayName":"Single key reading using spacebar (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_singlekeyreadingusingspacebar_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_singlekeyreadingusingspacebar_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_waitxxxsecondsbeforemarkingitemsasread","displayName":"Wait xxx seconds before marking items as read: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_sortfoldersalphabetically","displayName":"Sort folders alphabetically (User)","description":"This policy setting controls whether users can rearrange their folders in Outlook.\r\n\r\nIf you enable this policy setting, users cannot rearrange their folders. The folders are displayed alphabetically.\r\n\r\nIf you disable this policy setting, users can rearrange their folders, but are not able to turn automatic alphabetical sorting back on from the Ribbon. \r\n\r\nIf you do not configure this policy setting, users can rearrange their folders, and turn automatic alphabetical sorting back on from the Ribbon.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_sortfoldersalphabetically_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_sortfoldersalphabetically_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disablefolderhomepagesforfoldersinnondefaultstores","displayName":"Do not allow folders in non-default stores to be set as folder home pages (User)","description":"By default, creating folder home pages for folders in non-default stores is blocked; you cannot define a folder home page for a folder that is in a non-default store. This setting allows you to unblock folder home pages for folders in non-default stores. Note that other settings might still prevent folder home pages from functioning.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disablefolderhomepagesforfoldersinnondefaultstores_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disablefolderhomepagesforfoldersinnondefaultstores_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts","displayName":"Do not allow Outlook object model scripts to run for shared folders (User) (Deprecated)","description":"This policy setting controls whether Outlook executes scripts associated with custom forms or folder home pages for shared folders. \r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with shared folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for shared folders. \r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_v2","displayName":"Do not allow Outlook object model scripts to run for shared folders (User)","description":"This policy setting controls whether Outlook executes scripts associated with custom forms or folder home pages for shared folders. \r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with shared folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for shared folders. \r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders","displayName":"Do not allow Outlook object model scripts to run for public folders (User) (Deprecated)","description":"This policy setting controls whether Outlook executes scripts that are associated with custom forms or folder home pages for public folders.\r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you do not configure this policy setting, Outlook will not run any scripts associated with public folders by default. Users can configure the setting in the Trust Center by selecting the “Allow script in public folders” check box.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_v2","displayName":"Do not allow Outlook object model scripts to run for public folders (User)","description":"This policy setting controls whether Outlook executes scripts that are associated with custom forms or folder home pages for public folders.\r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you do not configure this policy setting, Outlook will not run any scripts associated with public folders by default. Users can configure the setting in the Trust Center by selecting the “Allow script in public folders” check box.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_enablemailloggingtroubleshooting","displayName":"Enable mail logging (troubleshooting) (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_enablemailloggingtroubleshooting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_enablemailloggingtroubleshooting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_minimizeoutlooktothesystemtray","displayName":"Minimize Outlook to the system tray (User)","description":"Checks/Unchecks the Outlook system tray icon option \"Hide When Minimized\".","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_minimizeoutlooktothesystemtray_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_minimizeoutlooktothesystemtray_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_moreoptions","displayName":"Warn before permanently deleting items (User)","description":"By default, a warning message is displayed before Outlook items are permanently deleted. By disabling this setting, you can change this behavior to not display the warning message.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_moreoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_moreoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_msgunicodeformatwhendraggingtofilesystem","displayName":"Use Unicode format when dragging e-mail message to file system (User) (Deprecated)","description":"This policy setting controls whether e-mail messages dragged from Outlook to the file system are saved in Unicode or ANSI format. \r\n\r\nIf you enable or do not configure this policy setting, when users drag an e-mail message from Outlook to the file system, Outlook uses the Unicode character encoding standard to create the message file, which preserves special characters in the message. \r\n\r\nIf you disable this policy setting, when users drag an e-mail message from Outlook to the file system, the message file created is in ANSI format.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_msgunicodeformatwhendraggingtofilesystem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_msgunicodeformatwhendraggingtofilesystem_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_msgunicodeformatwhendraggingtofilesystem_v2","displayName":"Use Unicode format when dragging e-mail message to file system (User)","description":"This policy setting controls whether e-mail messages dragged from Outlook to the file system are saved in Unicode or ANSI format. \r\n\r\nIf you enable or do not configure this policy setting, when users drag an e-mail message from Outlook to the file system, Outlook uses the Unicode character encoding standard to create the message file, which preserves special characters in the message. \r\n\r\nIf you disable this policy setting, when users drag an e-mail message from Outlook to the file system, the message file created is in ANSI format.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_msgunicodeformatwhendraggingtofilesystem_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_msgunicodeformatwhendraggingtofilesystem_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_preventsavingsyncconflicts","displayName":"Prevent saving sync conflicts (User)","description":"This policy setting allows you to prevent saving of sync conflicts.\r\n\r\nIf you enable this policy setting, Outlook will not save sync conflicts.\r\n\r\nIf you disable or do not configure this policy setting, all conflicts except those related to Calendar and RSS items are saved by default.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_preventsavingsyncconflicts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_preventsavingsyncconflicts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_savecalendarconflicts","displayName":"Save calendar sync conflicts (User)","description":"This policy setting allows you to save calendar sync conflicts.\r\n\r\nIf you enable this policy setting, Outlook will save calendar sync conflicts.\r\n\r\nIf you disable or do not configure this policy setting, calendar sync conflicts are not saved by default.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_savecalendarconflicts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_savecalendarconflicts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_saverssconflicts","displayName":"Save RSS conflicts (User)","description":"This policy setting allows you to save RSS conflicts.\r\n\r\nIf you enable this policy setting, RSS conflicts will be saved. This policy setting takes precedence over the \"Prevent saving sync conflicts\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, RSS conflicts are not saved.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_saverssconflicts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_saverssconflicts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts","displayName":"Turn on logging for all conflicts (User)","description":"This policy setting allows you to create Modification Resolution logs whenever the Outlook conflict resolver runs. \r\n\r\nIf you enable this policy setting, Outlook will create Modification Resolution logs whenever the Outlook conflict resolver runs. By default, Modification Resolution logs are written into the Sync Issues folder whenever Outlook's conflict resolver cannot resolve a conflict.\r\n\r\nYou may select one of these options:\r\n- No conflicts are logged: No Modification Resolution logs are written into the Sync Issues folder whenever Outlook's conflict resolver runs. \r\n- All conflicts logged: Modification Resolution logs are written into the Sync Issues folder whenever Outlook's conflict resolver runs.\r\n- Unresolved conflicts logged only: Modification Resolution logs are written into the Sync Issues folder in Outlook when the Outlook conflict resolver cannot resolve a conflict.\r\n\r\nThis applies to all item types.\r\n\r\nIf you disable or do not configure this policy setting, no Modification Resolution logs are written when the Outlook conflict resolver runs.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid_0","displayName":"No conflicts are logged (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid_1","displayName":"All conflicts logged","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid_2","displayName":"Unresolved conflicts logged only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders","displayName":"Reminders (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"13eb248a-4549-4d23-9ada-23b40edf36bf","categoryName":"Reminder Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_l_displaythereminder","displayName":"Display the reminder (User)","description":"","helpText":"","infoUrls":[],"categoryId":"13eb248a-4549-4d23-9ada-23b40edf36bf","categoryName":"Reminder Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_l_displaythereminder_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_l_displaythereminder_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_l_playremindersound","displayName":"Play reminder sound (User)","description":"","helpText":"","infoUrls":[],"categoryId":"13eb248a-4549-4d23-9ada-23b40edf36bf","categoryName":"Reminder Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_l_playremindersound_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_l_playremindersound_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_archiveignorelastmodifiedtime","displayName":"Change the criteria that Outlook uses to archive different item types (User)","description":"If you enable this policy setting, Outlook ignores the last modified date and archives items based on a date that is specific for the item type, as follows:\r\n\r\n-Email message: The received date.\r\n-Calendar item: The actual date that an appointment, event, or meeting is scheduled for.\r\n-Task: The completion date. Tasks that are not marked as completed are not archived. Tasks that are assigned to other users are archived only if the status is completed. \r\n-Note: The last modified date and time.\r\n-Journal entry: The date when the journal entry is created.\r\n-Contact: Not archived.\r\n\r\nIf you disable or do not configure this policy setting, Outlook archives different items based on the item type, as follows:\r\n\r\n-Email message: The received date or the last modified date and time, whichever is later. \r\n-Calendar item: The last modified date and time or the actual date that an appointment, event, or meeting is scheduled for, whichever is later. \r\n-Task: The completion date or the last modified date and time, whichever is later. Tasks that are not marked as completed are not archived. Tasks that are assigned to other users are archived only if the status is completed. \r\n-Note: The last modified date and time.\r\n-Journal entry: The date when the journal entry is created or the last modified date and time, whichever is later.\r\n-Contact: Not archived.","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_archiveignorelastmodifiedtime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_archiveignorelastmodifiedtime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings","displayName":"AutoArchive Settings (User)","description":"If you enable this policy setting, the options specified in the AutoArchive dialog box are disabled.","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_archiveordeleteolditems","displayName":"Archive or delete old items (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_archiveordeleteolditems_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_archiveordeleteolditems_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_cleanoutitemsolderthan","displayName":"Clean out items older than (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_deleteexpireditemsemailfoldersonly","displayName":"Delete expired items (e-mail folders only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_deleteexpireditemsemailfoldersonly_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_deleteexpireditemsemailfoldersonly_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_empty19","displayName":"\r\nDuring AutoArchive:\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_empty19_0","displayName":"Months","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_empty19_1","displayName":"Weeks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_empty19_2","displayName":"Days","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_permanentlydeleteolditems","displayName":"Permanently delete old items (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_permanentlydeleteolditems_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_permanentlydeleteolditems_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_promptbeforeautoarchiveruns","displayName":"Prompt before AutoArchive runs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_promptbeforeautoarchiveruns_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_promptbeforeautoarchiveruns_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_runautoarchiveeveryxdays","displayName":"Run AutoArchive every days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_showarchivefolderinfolderlist","displayName":"Show archive folder in folder list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_showarchivefolderinfolderlist_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_showarchivefolderinfolderlist_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_turnonautoarchive","displayName":"Turn on AutoArchive (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_turnonautoarchive_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_turnonautoarchive_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_disablefilearchive","displayName":"Disable File|Archive (User)","description":"This setting allows you to disable File|Archive and prevent users from manually archiving items in their mailbox. You might want to set this if you have deployed other messaging records management policies in order to avoid conflicts. You should also consider disabling AutoArchive in the setting named AutoArchive Settings.","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_disablefilearchive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_disablefilearchive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice","displayName":"Polling Out-of-office Web service (User)","description":"By default, the Out Of Office (OOF) Web service is polled every 15 minutes (900000 milliseconds). This setting allows you to set the maximum number of milliseconds that elapse before Outlook polls the OOF Web service for OOF status.","helpText":"","infoUrls":[],"categoryId":"93a20c17-1e34-4778-8c95-91a46980ea75","categoryName":"Out of Office Assistant","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"93a20c17-1e34-4778-8c95-91a46980ea75","categoryName":"Out of Office Assistant","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_300000","displayName":"5 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_600000","displayName":"10 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_900000","displayName":"15 minutes (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_1200000","displayName":"20 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_1500000","displayName":"25 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_1800000","displayName":"30 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_2100000","displayName":"35 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_2400000","displayName":"40 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_2700000","displayName":"45 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_3000000","displayName":"50 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_3600000","displayName":"1 hour","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_7200000","displayName":"2 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_14400000","displayName":"4 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_28800000","displayName":"8 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_outofofficeassistant_l_pollingoofwebsrvice_l_empty21_86400000","displayName":"24 hours","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_allowattendeestoproposenewtimesformeetingsyouorganize","displayName":"Allow attendees to propose new times for meetings you organize (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_allowattendeestoproposenewtimesformeetingsyouorganize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_allowattendeestoproposenewtimesformeetingsyouorganize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults","displayName":"Calendar item defaults (User)","description":"Sets the value in the option \"Default reminder\".","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults_l_showremindersxminutesbeforetheeventstarts","displayName":"Show reminders minutes before the event starts: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendarweeknumbers","displayName":"Calendar week numbers (User)","description":"By default, week numbers are not shown in the Date Navigator in the Calendar. You can change this behavior to show week numbers in the Date Navigator by enabling this setting.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendarweeknumbers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendarweeknumbers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing","displayName":"Control Calendar Sharing (User)","description":"By default, users can share an entire calendar by saving it in the iCalendar format, or share a snapshot of a calendar by using e-mail. This setting allows you to specify the detail level in the shared versions of calendars, or to disable sharing of calendars.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_l_controlcalendarsharing5","displayName":"Control Calendar Sharing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_l_controlcalendarsharing5_32768","displayName":"Prevent Calendar Sharing","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_l_controlcalendarsharing5_16384","displayName":"Allow calendar sharing with 'Availability Only' detail level","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_l_controlcalendarsharing5_8192","displayName":"Allow calendar sharing with 'Availability Only' and 'Limited Details' detail level","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disablemeetingregeneration","displayName":"Do not regenerate meetings (User)","description":"By default, when a user accepts or tentatively accepts a meeting, Outlook creates a duplicate copy of the meeting with the new response status and a new entry ID. Outlook then deletes the old version of the meeting from the calendar. This setting allows you to roll back to the legacy behavior and prevent meeting regeneration.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disablemeetingregeneration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disablemeetingregeneration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disableweather","displayName":"Disable Weather Bar (User)","description":"This policy setting allows you to turn on or turn off the Weather Bar.\r\n\r\nIf you enable this policy setting, the Weather Bar is turned off.\r\n\r\nIf you disable or do not configure this setting, the Weather Bar is turned on.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disableweather_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_disableweather_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enableendearly","displayName":"End appointments and meetings early (User)","description":"\r\n This policy setting allows you to control whether the end time of appointments and meetings are reduced by a specified number of minutes when a user creates an appointment or meeting.\r\n\r\n If you enable this policy setting, the end time of appointments and meetings are reduced by a specified number of minutes when a user creates an appointment or meeting.\r\n\r\n To specify how many minutes to reduce appointments and meetings by, you can use the “Reduce the end time of short appointments and meetings by a specified number of minutes” and “Reduce the end time of long appointments and meetings by a specified number of minutes” policy settings.\r\n\r\n If you don’t enable those policy settings to specify a time in minutes, users will be able to specify a time, in minutes, by going to File > Options > Calendar. If the user hasn’t specified a time, default values of 5 minutes, for short meetings, and 10 minutes, for long meetings, will be used.\r\n\r\n If you disable this policy setting, appointments and meetings can’t be configured to end early and the option will be disabled under File > Options > Calendar and can’t be enabled by the user.\r\n\r\n If you don’t configure this policy setting, appointments and meetings aren’t configured to end early, but the user can enable appointments and meetings to end early by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enableendearly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enableendearly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enablemeetingdownleveltext","displayName":"Enable down-level meeting text (User)","description":"This policy setting controls whether Outlook automatically displays the meeting time and location in the meeting request body.\r\n\r\nIf you enable this policy setting, Outlook automatically displays the meeting time and location in the meeting request body.\r\n\r\nIf you disable or do not configure this policy setting, Outlook does not automatically display the meeting time and location in the meeting request body.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enablemeetingdownleveltext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enablemeetingdownleveltext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong","displayName":"Reduce the end time of long appointments and meetings by a specified number of minutes (User)","description":"\r\n This policy setting allows you to specify how many minutes to reduce the end time of a long appointment or meeting by when a user creates an appointment or meeting. A long appointment or meeting is one that lasts for one hour or longer.\r\n\r\n If you enable this policy setting, you specify the number of minutes to reduce the end time of a long appointment or meeting by when a user creates an appointment or meeting. The user won’t be able to change this value by going to File > Options > Calendar.\r\n\r\n Note: You should also enable the “End appointments and meetings early” policy setting\r\n\r\n If you disable or don’t configure this policy setting, the default value of 10 minutes is used or whatever the user specifies by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong_l_endearlylongspinid","displayName":"Minutes to reduce meetings by: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort","displayName":"Reduce the end time of short appointments and meetings by a specified number of minutes (User)","description":"\r\n This policy setting allows you to specify how many minutes to reduce the end time of a short appointment or meeting by when a user creates an appointment or meeting. A short appointment or meeting is one that lasts for less than one hour.\r\n\r\n If you enable this policy setting, you specify the number of minutes to reduce the end time of a short appointment or meeting by when a user creates an appointment or meeting. The user can’t change this value by going to File > Options > Calendar.\r\n\r\n Note: You should also enable the “End appointments and meetings early” policy setting.\r\n\r\n If you disable or don’t configure this policy setting, the default value of 5 minutes is used or whatever the user specifies by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort_l_endearlyshortspinid","displayName":"Minutes to reduce meetings by: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek","displayName":"First day of the week (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek","displayName":"Choose the first day of the week: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_0","displayName":"Sunday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_1","displayName":"Monday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_4","displayName":"Thursday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_5","displayName":"Friday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_6","displayName":"Saturday","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear","displayName":"First week of year (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_l_choosethefirstweekoftheyear","displayName":"Choose the first week of the year: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_l_choosethefirstweekoftheyear_0","displayName":"Starts on Jan. 1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_l_choosethefirstweekoftheyear_2","displayName":"First full week","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_l_choosethefirstweekoftheyear_1","displayName":"First four-day week","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_hideluckydayswhenusingrokuyoujapanesecalendar","displayName":"Hide lucky days when using Rokuyou (Japanese) calendar (User)","description":"Checked: Does not display lucky days when using a Japanese Rokuyou calendar. | Unchecked: Displays lucky days when using a Japanese Rokuyou calendar.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_hideluckydayswhenusingrokuyoujapanesecalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_hideluckydayswhenusingrokuyoujapanesecalendar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_hidesendlatestversionbutton","displayName":"Hide Send Latest Version button (User)","description":"This policy setting hides the \"Send Latest Version\" button and prevents it from appearing on out-of-date meeting forward notifications and responses.\r\n\r\nIf you enable this policy setting, the \"Send Latest Version\" button be hidden on out-of-date meeting forward notifications and responses. \r\n\r\nIf you disable or do not configure this policy setting, the \"Send Latest Version\" button will be turned on.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_hidesendlatestversionbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_hidesendlatestversionbutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_includeappointmentsonlywithinworkinghours","displayName":"Include appointments only within working hours (User)","description":"By default, all appointments in a calendar are included when that calendar is shared through e-mail or by using the Office.com Sharing Service. This setting allows users to publish only appointments that are within users' working hours.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_includeappointmentsonlywithinworkinghours_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_includeappointmentsonlywithinworkinghours_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_meetingrequestsusingicalendar","displayName":"Send Internet meeting requests using iCalendar format (User)","description":"This policy setting determines whether users' meeting requests sent outside of your organization use the iCalendar format.\r\n\r\nIf you enable or do not configure this policy setting, meeting requests sent outside of your organization use the ICAL format.\r\n\r\nIf you disable this policy setting, meeting requests sent outside your organization use the TNEF format.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_meetingrequestsusingicalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_meetingrequestsusingicalendar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_remindersoncalendaritems","displayName":"Do not display reminders on Calendar items by default (User)","description":"By default, when users create Calendar items, the Reminder: check box in the item is set. By disabling this setting, you can change the default behavior so that the Reminder: check box is cleared by default .","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_remindersoncalendaritems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_remindersoncalendaritems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_restupdatesforcalendar","displayName":"REST updates for calendars (User)","description":"This policy determines if Outlook can use REST to update calendars.\r\n\r\n If you enable this policy, Outlook will use REST to update supported Office 365 and Outlook.com calendars.\r\n\r\n If you disable this policy, Outlook won't use REST to update any calendars.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_restupdatesforcalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_restupdatesforcalendar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes","displayName":"Use this response when you propose new meeting times (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_l_usethisresponsewhenyouproposenewmeetingtimes6","displayName":"Use this response when you propose new meeting times (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_l_usethisresponsewhenyouproposenewmeetingtimes6_2","displayName":"Tentative","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_l_usethisresponsewhenyouproposenewmeetingtimes6_3","displayName":"Accept","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_l_usethisresponsewhenyouproposenewmeetingtimes6_4","displayName":"Decline","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherserviceurl","displayName":"Weather Service URL (User)","description":"This policy setting allows you to configure the weather service URL for Outlook.\r\n\r\nIf you enable this policy setting, you must enter your desired weather service URL.\r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default weather service URL.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherserviceurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherserviceurl_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherserviceurl_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency","displayName":"Weather Bar Update Frequency (User)","description":"This policy setting allows you to set the update frequency (in minutes) for the Weather Bar. \r\n\r\nIf you enable this policy setting, Outlook sets the update frequency to the specified value. \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default value of 120 minutes.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency_l_weatherupdatefrequencyintervalspinid","displayName":"Update frequency (in minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours","displayName":"Working hours (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime","displayName":"End Time: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1020","displayName":"5:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_0","displayName":"12:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_30","displayName":"12:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_60","displayName":"1:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_90","displayName":"1:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_120","displayName":"2:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_150","displayName":"2:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_180","displayName":"3:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_210","displayName":"3:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_240","displayName":"4:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_270","displayName":"4:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_300","displayName":"5:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_330","displayName":"5:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_360","displayName":"6:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_390","displayName":"6:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_420","displayName":"7:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_450","displayName":"7:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_480","displayName":"8:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_510","displayName":"8:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_540","displayName":"9:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_570","displayName":"9:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_600","displayName":"10:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_630","displayName":"10:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_660","displayName":"11:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_690","displayName":"11:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_720","displayName":"12:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_750","displayName":"12:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_780","displayName":"1:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_810","displayName":"1:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_840","displayName":"2:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_870","displayName":"2:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_900","displayName":"3:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_930","displayName":"3:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_960","displayName":"4:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_990","displayName":"4:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1050","displayName":"5:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1080","displayName":"6:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1110","displayName":"6:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1140","displayName":"7:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1170","displayName":"7:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1200","displayName":"8:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1230","displayName":"8:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1260","displayName":"9:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1290","displayName":"9:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1320","displayName":"10:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1350","displayName":"10:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1380","displayName":"11:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_endtime_1410","displayName":"11:30 PM","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime","displayName":"Start time: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_480","displayName":"8:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_0","displayName":"12:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_30","displayName":"12:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_60","displayName":"1:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_90","displayName":"1:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_120","displayName":"2:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_150","displayName":"2:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_180","displayName":"3:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_210","displayName":"3:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_240","displayName":"4:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_270","displayName":"4:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_300","displayName":"5:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_330","displayName":"5:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_360","displayName":"6:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_390","displayName":"6:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_420","displayName":"7:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_450","displayName":"7:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_510","displayName":"8:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_540","displayName":"9:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_570","displayName":"9:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_600","displayName":"10:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_630","displayName":"10:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_660","displayName":"11:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_690","displayName":"11:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_720","displayName":"12:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_750","displayName":"12:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_780","displayName":"1:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_810","displayName":"1:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_840","displayName":"2:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_870","displayName":"2:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_900","displayName":"3:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_930","displayName":"3:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_960","displayName":"4:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_990","displayName":"4:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1020","displayName":"5:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1050","displayName":"5:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1080","displayName":"6:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1110","displayName":"6:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1140","displayName":"7:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1170","displayName":"7:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1200","displayName":"8:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1230","displayName":"8:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1260","displayName":"9:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1290","displayName":"9:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1320","displayName":"10:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1350","displayName":"10:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1380","displayName":"11:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1410","displayName":"11:30 PM","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek","displayName":"Work week (User)","description":"Sets the value in the option \"Calendar work week\".","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek","displayName":"Length of work week: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_124","displayName":"Monday to Friday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_120","displayName":"Monday to Thursday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_60","displayName":"Tuesday to Friday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_126","displayName":"Monday to Saturday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_30","displayName":"Wednesday to Saturday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_142","displayName":"Thursday to Sunday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_252","displayName":"Sunday to Friday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workweek_l_lengthofworkweek_254","displayName":"All seven days","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions","displayName":"Internet Free/Busy Options (User)","description":"Checks/Unchecks the option \"Publish at my location\".","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_l_publishatthisurl","displayName":"Publish at this URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_l_publishfreebusyinformation","displayName":"Publish free/busy information (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_l_publishfreebusyinformation_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_l_publishfreebusyinformation_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_l_searchatthisurl","displayName":"Search at this URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9","displayName":"Options (User)","description":"Sets the value in the option \"Publish [] month(s) of Calendar free/busy information on the server\".","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_freebusyupdatedontheservereveryxxxseconds","displayName":"Free/Busy updated on the server every xxx seconds: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_monthsoffreebusyinformationpublished","displayName":"Months of Free/Busy information published: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_preventusersfromchangingmonthsoffreebusyinformation1","displayName":"Prevent users from changing Months of Free/Busy information being published (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_preventusersfromchangingmonthsoffreebusyinformation1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_preventusersfromchangingmonthsoffreebusyinformation1_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_accesstopublishedcalendars","displayName":"Access to published calendars (User)","description":"This policy setting determines what restrictions apply to users who publish their calendars on Office.com or third-party World Wide Web Distributed Authoring and Versioning (WebDAV) servers. \r\n\r\nIf you enable or disable this policy setting, calendars that are published on Office.com must have restricted access (users other than the calendar owner/publisher who wish to view the calendar can only do so if they receive invitations from the calendar owner), and users cannot publish their calendars to third-party DAV servers. \r\n\r\nIf you do not configure this policy setting, users can share their calendars with others by publishing them to the Office.com Calendar Sharing Services and to a server that supports the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol. Office.com allows users to choose whether to restrict access to their calendars to people they invite, or allow unrestricted access to anyone who knows the URL to reach the calendar. DAV access restrictions can only be achieved through server and folder permissions, and might require the assistance of a server administrator to set up and maintain.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_accesstopublishedcalendars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_accesstopublishedcalendars_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver","displayName":"Path to DAV server (User)","description":"This setting allows you to define the path to a DAV server that should be used when users publish their calendars via DAV.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_preventpublishingtoadavserver","displayName":"Prevent publishing to a DAV server (User)","description":"This policy setting controls whether Outlook users can publish their calendars to a DAV server. \r\n\r\nIf you enable this policy setting, Outlook users cannot publish their calendars to a DAV server. \r\n\r\nIf you disable or do not configure this policy setting, Outlook users can share their calendars with others by publishing them to a server that supports the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_preventpublishingtoadavserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_preventpublishingtoadavserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_preventpublishingtoofficeonline","displayName":"Prevent publishing to Office.com (User)","description":"This policy setting controls whether Outlook users can publish their calendars to the Office.com Calendar Sharing Service. \r\n\r\nIf you enable this policy setting, Outlook users cannot publish their calendars to Office.com. \r\n\r\nIf you disable do not configure this policy setting, Outlook users can share their calendars with selected others by publishing them to the Microsoft Outlook Calendar Sharing Service. Users can control who can view their calendar and at what level of detail.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_preventpublishingtoofficeonline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_preventpublishingtoofficeonline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_publishinterval","displayName":"Publish interval (User)","description":"By default, Outlook does not publish calendars to Office.com more often then the publish interval set by Office.com. This setting allows users to publish calendars more often than the Office.com interval specifies.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_publishinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_publishinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails","displayName":"Restrict level of calendar details users can publish (User)","description":"This policy setting controls the level of calendar details that Outlook users can publish to the Microsoft Outlook Calendar Sharing Service. \r\n\r\nIf you enable this policy setting, you can choose from three levels of detail: \r\n\r\n* All options are available - This level of detail is the default configuration. \r\n* Disables 'Full details' \r\n* Disables 'Full details' and 'Limited details' \r\n\r\nIf you disable or do not configure this policy setting, Outlook users can share their calendars with selected others by publishing them to the Microsoft Outlook Calendar Sharing Service. Users can choose from three levels of detail: \r\n\r\n* Availability only - Authorized visitors will see the user's time marked as Free, Busy, Tentative, or Out of Office, but will not be able to see the subjects or details of calendar items. \r\n* Limited details - Authorized visitors can see the user's availability and the subjects of calendar items only. They will not be able to view the details of calendar items. Optionally, users can allow visitors to see the existence of private items. \r\n* Full details - Authorized visitors can see the full details of calendar items. Optionally, users can allow visitors to see the existence of private items.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails_l_empty4","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails_l_empty4_0","displayName":"All options are available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails_l_empty4_8192","displayName":"Disables 'Full details'","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictlevelofcalendardetails_l_empty4_16384","displayName":"Disables 'Full details' and 'Limited details'","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictuploadmethod","displayName":"Restrict upload method (User)","description":"This policy setting controls whether Outlook can automatically upload calendar updates to Office.com. \r\n\r\nIf you enable this policy setting, Outlook enforces the \"Single Upload: Updates will not be uploaded from the Published Calendar Settings dialog\" option, and calendar updates are not uploaded. Users will not be able to change this setting.\r\n\r\nIf you disable this policy setting Outlook automatically publishes calendar updates to Office.com at regular intervals and users will not be able to change this. \r\n\r\nIf you do not configure this policy setting, when users publish their calendar to Office.com using the Microsoft Outlook Calendar Sharing Service, Outlook updates the calendars online at regular intervals unless they click \"Advanced\" and select \"Single Upload: Updates will not be uploaded from the Published Calendar Settings dialog\".","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictuploadmethod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_restrictuploadmethod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner","displayName":"Meeting Planner (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"2592e8ea-5eb0-482b-b41e-eab92f33ac07","categoryName":"Planner Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_l_showcalendardetailsinthegrid","displayName":"Show calendar details in the grid (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2592e8ea-5eb0-482b-b41e-eab92f33ac07","categoryName":"Planner Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_l_showcalendardetailsinthegrid_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_l_showcalendardetailsinthegrid_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_l_showpopupcalendardetails","displayName":"Show popup calendar details (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2592e8ea-5eb0-482b-b41e-eab92f33ac07","categoryName":"Planner Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_l_showpopupcalendardetails_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_planneroptions_l_meetingplanner_l_showpopupcalendardetails_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_defaultrecurrenceduration","displayName":"Specify total number of days in a recurring meeting or appointment (User)","description":"This policy setting allows you to specify the default number of days after which a recurring meeting or appointment (but not a task) ends.\r\n\r\nIf you enable this policy setting, the “End by” setting is the default setting for recurring meetings and appointments, and the “End by” value is set to the specified number of days after today’s date. For example, if you specify a value of 180 and today's date is May 5, 2011, the “End by” value is November 1, 2011 (180 days after today’s date).\r\n\r\nIf you disable or do not configure this policy setting, the “No end date” option is the default setting for recurring meetings and appointments.","helpText":"","infoUrls":[],"categoryId":"826db7fb-889b-4a99-80a6-38347ba37f21","categoryName":"Recurring item configuration","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_defaultrecurrenceduration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_defaultrecurrenceduration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_defaultrecurrenceduration_l_defaultrecurrencedurationspinid","displayName":"End recurrence after x days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"826db7fb-889b-4a99-80a6-38347ba37f21","categoryName":"Recurring item configuration","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_disablenoenddate","displayName":"Disable the \"No end date\" option for recurring items (User)","description":"This policy setting allows you to disable the \"No end date\" option for the recurrence range in appointments, meetings, and tasks.\r\n\r\nIf you enable this policy setting, the “No end date” option is disabled, and the “End after” recurrence setting is selected and set to “10 occurrences” by default. You can change this default setting by configuring the “Specify total number of days in a recurring meeting or appointment” policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the “No end date” option is enabled and is the default setting for recurring meetings, appointments, and tasks.","helpText":"","infoUrls":[],"categoryId":"826db7fb-889b-4a99-80a6-38347ba37f21","categoryName":"Recurring item configuration","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_disablenoenddate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_recurrenceoptions_l_disablenoenddate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_donotallowhorizontalcalendarview","displayName":"Do not allow horizontal calendar view (User)","description":"This policy setting allows you to prevent horizontal calendar view.\r\n\r\nIf you enable this policy setting, horizontal calendar view is not allowed.\r\n\r\nIf you disable or do not configure this policy setting, horizontal calendar view is allowed.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_donotallowhorizontalcalendarview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_donotallowhorizontalcalendarview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventmydepartmentcalendarfromappearing","displayName":"Prevent My Department Calendar from appearing (User)","description":"This policy setting prevents My Department Calendar from appearing in the navigation pane.\r\n\r\nIf you enable this policy setting, My Department Calendar will not appear in the navigation pane.\r\n\r\nIf you disable or do not configure this policy setting, My Department Calendar will appear in the navigation pane.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventmydepartmentcalendarfromappearing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventmydepartmentcalendarfromappearing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventotherdepartmentcalendarfromappearing","displayName":"Prevent Other Department Calendar from appearing (User)","description":"This policy setting prevents Other Department Calendar from appearing in the navigation pane.\r\n\r\nIf you enable this policy setting, Other Department Calendar will not appear in the navigation pane.\r\n\r\nIf you disable or do not configure this policy setting, Other Department Calendar will appear in the navigation pane.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventotherdepartmentcalendarfromappearing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventotherdepartmentcalendarfromappearing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventreportinglinegroupcalendarfromappearing","displayName":"Prevent Reporting Line Group Calendar from appearing (User)","description":"This policy setting prevents Reporting Line Group Calendar from appearing in the navigation pane.\r\n\r\nIf you enable this policy setting, Reporting Line Group Calendar will not appear in the navigation pane.\r\n\r\nIf you disable or do not configure this policy setting, My Reporting Line Group Calendar will appear in the navigation pane.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventreportinglinegroupcalendarfromappearing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventreportinglinegroupcalendarfromappearing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffautoswitchingfromhorizontaltovertical","displayName":"Turn off auto-switching from horizontal to vertical layout (User)","description":"This policy setting controls auto switching of calendar layouts from horizontal to vertical. \r\n\r\nIf you enable this policy setting, auto-switching is turned off.\r\n\r\nIf you disable or do not configure this policy setting, auto-switching is turned on.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffautoswitchingfromhorizontaltovertical_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffautoswitchingfromhorizontaltovertical_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffautoswitchingfromverticaltohorizontallayout","displayName":"Turn off auto-switching from vertical to horizontal layout (User)","description":"This policy setting controls auto-switching of calendar layouts from vertical to horizontal.\r\n\r\nIf you enable this policy setting, auto-switching is turned off.\r\n\r\nIf you disable or do not configure this policy setting, auto-switching is turned on.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffautoswitchingfromverticaltohorizontallayout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffautoswitchingfromverticaltohorizontallayout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnofflegacygroupcalendarmigration","displayName":"Turn off Legacy Group Calendar migration (User)","description":"This policy setting controls the migration of legacy Group Calendar. \r\n\r\nIf you enable this policy setting, migration will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, migration will be turned on.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnofflegacygroupcalendarmigration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnofflegacygroupcalendarmigration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffsharingrecommendation","displayName":"Turn off sharing recommendation (User)","description":"This policy setting controls the sharing recommendation feature. \r\n\r\nIf you enable this policy setting, the recommendation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, the recommendation will be turned on.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffsharingrecommendation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnoffsharingrecommendation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_determineorderofsourcesforphotos","displayName":"Determine order of sources for photos (User)","description":"This policy setting controls the order of sources for photos displayed in Outlook. \r\n\r\nIf you enable this policy setting, Outlook will first look at the OAB/AD for the user photo. If this is not available, Outlook will show a Contact photo if the Contact photo is available.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will first look into the Contact Address Books for the user photo. If this is not available, Outlook will look to the OAB/AD if available.","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_determineorderofsourcesforphotos_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_determineorderofsourcesforphotos_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts","displayName":"Select the default setting for how to file new contacts (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex","displayName":"Additional Contacts Index: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_2","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_7","displayName":"Cyrillic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_15","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_16","displayName":"Hebrew","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_28","displayName":"Thai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_30","displayName":"Vietnamese","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_checkforduplicatecontacts","displayName":"Check for duplicate contacts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_checkforduplicatecontacts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_checkforduplicatecontacts_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfileasorder","displayName":"Default File As order: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfileasorder_32791","displayName":"Last First","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfileasorder_32823","displayName":"First Last","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfileasorder_14870","displayName":"Company","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfileasorder_32793","displayName":"Last, First (Company)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfileasorder_32792","displayName":"Company (Last, First)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfullnameorder","displayName":"Default Full Name order: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfullnameorder_e","displayName":"First (Middle) Last","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfullnameorder_h","displayName":"Last First","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_defaultfullnameorder_s","displayName":"First Last1 Last2","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_showanadditionalcontactsindex","displayName":"Show an additional Contacts Index (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_showanadditionalcontactsindex_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_showanadditionalcontactsindex_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_showcontactslinkingcontrolsonallforms","displayName":"Show Contacts linking controls on all Forms (User)","description":"By default, Tasks, Appointments, Journal Entries, and Contacts hide the controls in the Outlook user interface used for linking related contacts. When you enable this setting, the linking controls appear in Outlook. You might choose to enable this setting if your users rely on contact linking - for example, to track partners who attend appointments together or to track ways in which contacts are related to each other.","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_showcontactslinkingcontrolsonallforms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_showcontactslinkingcontrolsonallforms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior","displayName":"Change CTRL+ENTER shortcut behavior (User)","description":"This policy setting controls whether CTRL+ENTER can be used as a shortcut to send an email message. You can change this behavior so that CTRL+ENTER does not send an email message.\r\n\r\nIf you enable this policy setting, you may select one of these choices:\r\n- CTRL+Enter is not a shortcut for sending a message\r\n- CTRL+Enter is a shortcut for sending a message\r\n- CTRL+Enter displays a prompt\r\n\r\nIf you disable or do not configure this policy setting, users can use CTRL+ENTER to send an e-mail message. By default, users are prompted the first time they use the shortcut to confirm sending the message.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior_l_changectrlentershortcutbehaviorid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior_l_changectrlentershortcutbehaviorid_0","displayName":"CTRL+Enter is not a shortcut for sending a message","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior_l_changectrlentershortcutbehaviorid_1","displayName":"CTRL+Enter is a shortcut for sending a message","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_changectrlentershortcutbehavior_l_changectrlentershortcutbehaviorid_2","displayName":"CTRL+Enter displays a prompt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_checkforgottenattachments","displayName":"Attachment Reminder Options (User)","description":"This policy setting governs the enabling or disabling of the Attachment Reminder feature in Outlook.\r\n\r\nIf you enable or do not configure this policy setting, when a user sends an email, Outlook looks for any references to attachments in the email, and if no attachments are found, displays a dialog box to alert the user.\r\n\r\nIf you disable this policy setting, Outlook does not check for any references to attachments, and the Attachment Reminder dialog box does not pop up.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_checkforgottenattachments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_checkforgottenattachments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview","displayName":"Configure Cross Folder Content in conversation view (User)","description":"This policy setting controls how conversation view in Outlook is loaded and whether Cross Folder Content is turned on or off.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n- On and cross-store (default): Cross Folder Content is on and cross-store. Data will be pulled from all connected data files whether they are cached or online. \r\n- Off: Cross Folder Content is turned off.\r\n- On and current: Cross Folder Content is on, but data is only pulled from the current data file. \r\n- On and local: Cross Folder Content is on, but data is only pulled from the current data file and any other local data files.\r\n\r\nIf you disable or do not configure this policy setting, Cross Folder Content will be turned on and pulled from all connected data files.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_l_configurecrossfoldercontentinconversationviewdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_l_configurecrossfoldercontentinconversationviewdropid_0","displayName":"On and cross-store (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_l_configurecrossfoldercontentinconversationviewdropid_1","displayName":"Off","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_l_configurecrossfoldercontentinconversationviewdropid_2","displayName":"On and current","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_l_configurecrossfoldercontentinconversationviewdropid_3","displayName":"On and local","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_disableattachmentpreviewing","displayName":"Do not allow attachment previewing in Outlook (User)","description":"This policy setting controls whether Outlook users can preview attachments in e-mail messages. \r\n\r\nIf you enable this policy setting, users cannot preview attachments within Outlook. Users must instead use the appropriate application to view attachments, depending on security settings. This configuration can be used to guard against theoretical future zero-day attacks that target specific file types. \r\n\r\nIf you disable or do not configure this policy setting, Outlook users can preview certain types of e-mail attachments within the message window or Reading Pane by clicking the icon that represents the attachment. Users can preview Outlook items, Word documents, PowerPoint presentations, Excel worksheets, Microsoft Visio® drawings, image files, and text files. To help protect users from malicious code, active content embedded in attachments (including scripts, macros, and ActiveX controls) is disabled during a preview.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_disableattachmentpreviewing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_disableattachmentpreviewing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_disablemailtips","displayName":"Disable Mail Tips (User)","description":"This policy setting determines whether users can view Mail Tips.\r\n\t \r\nIf you enable this policy setting, Mail Tips do not appear in Outlook.\r\n\t\t\t\t\t\r\nIf you disable or do not configure this policy, Mail Tips appear in Outlook.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_disablemailtips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_disablemailtips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_displaysenderpicture","displayName":"Display Sender Picture (User)","description":"This policy setting controls whether Outlook displays pictures in email headers for senders of email messages and meeting requests. \r\n\t \r\nIf you enable or do not configure this policy setting Outlook displays pictures for senders if they are available. \r\n\r\nIf you disable this policy setting, pictures of senders will not be displayed.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_displaysenderpicture_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_displaysenderpicture_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_donotuseconversationalarrangementinviews","displayName":"Do not use Conversation arrangement in Views (User)","description":"This policy setting allows you to prevent the use of Conversation arrangement in Views.\r\n\r\nIf you enable this policy setting, you will prevent Conversational arrangement in Views.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to use Conversation arrangement in Views.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_donotuseconversationalarrangementinviews_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_donotuseconversationalarrangementinviews_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling","displayName":"Message handling (User)","description":"You can use this setting to specify various options for how e-mail messages are handled.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_aftermovingordeletinganopenitem0","displayName":"After moving or deleting an open item: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_aftermovingordeletinganopenitem0_0","displayName":"Open the next item","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_aftermovingordeletinganopenitem0_1","displayName":"Return to the current folder","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_aftermovingordeletinganopenitem0_2","displayName":"Open the previous item","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_automaticallycleanupplaintextmessages","displayName":"Automatically clean up plain text messages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_automaticallycleanupplaintextmessages_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_automaticallycleanupplaintextmessages_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_autosaveunsenteveryxxminutes0noautosave","displayName":"Autosave unsent every xx minutes (0=No AutoSave): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_closeoriginalmessagewhenreplyorforward","displayName":"Close original message when reply or forward (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_closeoriginalmessagewhenreplyorforward_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_closeoriginalmessagewhenreplyorforward_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_savecopiesofmessagesinsentitemsfolder","displayName":"Save copies of messages in Sent Items folder (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_savecopiesofmessagesinsentitemsfolder_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_messagehandling_l_savecopiesofmessagesinsentitemsfolder_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards","displayName":"On replies and forwards (User)","description":"Sets the values in the corresponding UI options.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_allowuserscommentstobemarked","displayName":"Allow user's comments to be marked (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_allowuserscommentstobemarked_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_allowuserscommentstobemarked_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_prefixeachlinewith","displayName":"Prefix each line with: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenforwardingamessage","displayName":"When forwarding a message: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenforwardingamessage_1","displayName":"Attach orginal message","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenforwardingamessage_2","displayName":"Include original message text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenforwardingamessage_3","displayName":"Include and indent org. message text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenforwardingamessage_1000","displayName":"Prefix each line of the org. message","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenreplyingtoamessage","displayName":"When replying to a message: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenreplyingtoamessage_0","displayName":"Do not include orginal message","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenreplyingtoamessage_1","displayName":"Attach orginal message","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenreplyingtoamessage_2","displayName":"Include original message text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenreplyingtoamessage_3","displayName":"Include and indent org. message text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_l_whenreplyingtoamessage_1000","displayName":"Prefix each line of the org. message","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_reademailasplaintext","displayName":"Read e-mail as plain text (User)","description":"This policy setting determines whether Outlook renders all e-mail messages in plain text format for reading.Outlook can display e-mail messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. \r\n\r\nIf you enable this policy setting, the \"Read all standard mail in plain text\" check box option is selected in the \"E-mail Security\" section of the Trust Center and users cannot change it. This option only changes the way e-mail messages are displayed; the original message is not converted to plain text format. \r\n\r\nIf you disable or do not configure this policy setting, Outlook displays e-mail messages in whatever format they were received in.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_reademailasplaintext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_reademailasplaintext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_readsignedemailasplaintext","displayName":"Read signed e-mail as plain text (User)","description":"This policy setting determines whether Outlook renders all digitally signed e-mail in plain text format for reading. Outlook can display e-mail messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. \r\n\r\nIf you enable this policy setting, the \"Read all standard mail in plain text\" check box option is selected in the \"E-mail Security\" section of the Trust Center and users cannot change it. This option only changes the way e-mail messages are displayed; the original message is not converted to plain text format. \r\n\r\nIf you disable or do not configure this policy setting, Outlook displays digitally signed e-mail messages in the format they were received in.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_readsignedemailasplaintext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_readsignedemailasplaintext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_disableautopreview","displayName":"Disable AutoPreview (User)","description":"Enabling this policy permanently disables the item preview. Users cannot turn it back on and the ribbon UI to change it is disabled.","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_disableautopreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_disableautopreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages","displayName":"More save messages (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_l_infoldersotherthantheinboxsavereplieswithoriginalmessage","displayName":"In folders other than the Inbox, save replies with original message (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_l_infoldersotherthantheinboxsavereplieswithoriginalmessage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_l_infoldersotherthantheinboxsavereplieswithoriginalmessage_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_l_saveforwardedmessages","displayName":"Save forwarded messages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_l_saveforwardedmessages_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_moresavemessages_l_saveforwardedmessages_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages","displayName":"Save Messages (User)","description":"Specifies the folder in which unsent messages are saved.","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_l_saveunsentitemsinthisfolder","displayName":"Save unsent items in this folder: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_l_saveunsentitemsinthisfolder_4","displayName":"Outbox","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_l_saveunsentitemsinthisfolder_5","displayName":"Sent Items","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_l_saveunsentitemsinthisfolder_6","displayName":"Inbox","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_savemessages_l_saveunsentitemsinthisfolder_16","displayName":"Drafts","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive","displayName":"When new items arrive (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_brieflychangethemousecursor","displayName":"Briefly change the mouse cursor (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_brieflychangethemousecursor_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_brieflychangethemousecursor_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_playasound","displayName":"Play a sound (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_playasound_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_playasound_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_showanenvelopeiconinthesystemtray","displayName":"Show an envelope icon in the system tray (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_showanenvelopeiconinthesystemtray_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_showanenvelopeiconinthesystemtray_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage","displayName":"When sending a message (User)","description":"Sets the values in the corresponding UI options.","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_addpropertiestoattachmentstoenablereplywithchanges","displayName":"Add properties to attachments to enable Reply with Changes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_addpropertiestoattachmentstoenablereplywithchanges_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_addpropertiestoattachmentstoenablereplywithchanges_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_allowcommasasaddressseparator","displayName":"Allow commas as address separator (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_allowcommasasaddressseparator_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_allowcommasasaddressseparator_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_automaticnamechecking","displayName":"Automatic name checking (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_automaticnamechecking_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_automaticnamechecking_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_deletemeetingrequestfrominboxwhenresponding","displayName":"Delete meeting request from Inbox when responding (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_deletemeetingrequestfrominboxwhenresponding_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_deletemeetingrequestfrominboxwhenresponding_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_messagesexpireafterdays","displayName":"Messages expire after (days): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setimportance","displayName":"Set importance: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setimportance_2","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setimportance_1","displayName":"Normal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setimportance_0","displayName":"Low","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setsensitivity","displayName":"Set sensitivity: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setsensitivity_0","displayName":"Normal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setsensitivity_1","displayName":"Personal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setsensitivity_2","displayName":"Private","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_setsensitivity_3","displayName":"Confidential","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_suggestnameswhilecompletingtoccandbccfields","displayName":"Suggest names while completing To, Cc, and Bcc fields (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_suggestnameswhilecompletingtoccandbccfields_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_suggestnameswhilecompletingtoccandbccfields_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_newmaildesktopalert","displayName":"Do not display New Mail alert for users (User)","description":"By default, users receive an alert message on their desktops when new mail arrives. By enabling this setting, the alert is not displayed for new mail.","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_newmaildesktopalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_newmaildesktopalert_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert","displayName":"Specify default location of Desktop Alert (User)","description":"You can change the default location of the Desktop Alert. In the Corner field, select a number corresponding to a quadrant of the user's screen: 0 = upper left, 1 = upper right, 2 = lower left, 3 = lower right (the default). In the XOffset field, enter a number representing the horizontal distance from the corner you've specified (the default is 44). In the YOffset field, enter a number representing the vertical distance from the corner you've specified (the default is 42).","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_l_corner03","displayName":"Corner (0-3) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_l_xoffsetdefault44","displayName":"XOffset (default 44): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_l_yoffsetdefault42","displayName":"YOffset (default 42): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertbeforefadeinmillisec","displayName":"Specify duration of Desktop Alert before fade (in milliseconds) (User)","description":"Specify duration of Desktop Alert before fade (in milliseconds)","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertbeforefadeinmillisec_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertbeforefadeinmillisec_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertbeforefadeinmillisec_l_millisecdefault4000","displayName":"Millisec (Default 4000): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec","displayName":"Specify duration of Desktop Alert on mouse over (in milliseconds) (User)","description":"Specify duration of Desktop Alert on mouse over (in milliseconds)","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec_l_millisec1","displayName":"Millisec: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeininmillisec","displayName":"Specify duration of fade in (in milliseconds) (User)","description":"Specify duration of fade in (in milliseconds)","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeininmillisec_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeininmillisec_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeininmillisec_l_millisec","displayName":"Millisec: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeoutinmillisec","displayName":"Specify duration of fade out (in milliseconds) (User)","description":"Specify duration of fade out (in milliseconds)","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeoutinmillisec_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeoutinmillisec_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationoffadeoutinmillisec_l_millisec2","displayName":"Millisec: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityatstartoffadein","displayName":"Specify opacity at start of fade in (User)","description":"Specify opacity at start of fade in","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityatstartoffadein_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityatstartoffadein_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityatstartoffadein_l_specifyopacityatstartoffadein3","displayName":"Specify opacity at start of fade in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityofdesktopalert","displayName":"Specify opacity of Desktop Alert (User)","description":"Specify opacity of Desktop Alert","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityofdesktopalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityofdesktopalert_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifyopacityofdesktopalert_l_opacityalphalevel","displayName":"Opacity (Alpha Level): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options","displayName":"Options (User)","description":"You can use these settings to specify how tracking options work for Outlook e-mail messages.","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_deleteblankvotingandmeetingresponsesafterprocessing","displayName":"Delete blank voting and meeting responses after processing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_deleteblankvotingandmeetingresponsesafterprocessing_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_deleteblankvotingandmeetingresponsesafterprocessing_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processreceiptsonarrival","displayName":"Process receipts on arrival (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processreceiptsonarrival_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processreceiptsonarrival_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processrequestsandresponsesonarrival","displayName":"Process requests and responses on arrival (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processrequestsandresponsesonarrival_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processrequestsandresponsesonarrival_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestareadreceiptforallmessagesausersends","displayName":"Request a read receipt for all messages a user sends (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestareadreceiptforallmessagesausersends_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestareadreceiptforallmessagesausersends_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestdeliveryrcptforallmsgsausersendsexchangeonly","displayName":"Request delivery rcpt for all msgs a user sends (Exchange only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestdeliveryrcptforallmsgsausersendsexchangeonly_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestdeliveryrcptforallmsgsausersendsexchangeonly_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_whenoutlookisaskedtorespondtoareadreceiptrequest","displayName":"When Outlook is asked to respond to a read receipt request: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_whenoutlookisaskedtorespondtoareadreceiptrequest_0","displayName":"Always send a response","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_whenoutlookisaskedtorespondtoareadreceiptrequest_1","displayName":"Never send a response","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_whenoutlookisaskedtorespondtoareadreceiptrequest_2","displayName":"Ask before sending a response","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_turnoffsendandtrack","displayName":"Turn off Send and Track feature (User)","description":"By default, users can flag an e-mail that they send to help them remember to follow up on it later. The flag is not sent to the recipient. By enabling this setting, this feature is turned off.","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_turnoffsendandtrack_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_turnoffsendandtrack_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_addpeopleiemailtothesafesenderslist","displayName":"Add e-mail recipients to users' Safe Senders Lists (User)","description":"This policy setting controls whether recipients' e-mail addresses are automatically added to the user's Safe Senders List in Microsoft Outlook. Sometimes users will send e-mail messages to request that they be taken off a mailing list. If the e-mail recipient is then automatically added to the Safe Senders List, future e-mail messages from that address will no longer be sent to the users Junk E-mail folder, even if it would otherwise be considered junk. \r\n\r\nIf you enable this policy setting, all recipients of outgoing messages are automatically added to users' Safe Senders Lists. If users respond to junk e-mail senders while this policy setting is Enabled, all future junk e-mail from the same address will be considered safe. \r\n\r\nIf you disable this policy setting, recipients of outgoing messages are not automatically added to the Safe Senders List. Users must explicitly add addresses to the list. \r\n\r\nIf you do not configure this policy setting, recipients of outgoing messages are not added automatically to individual users' Safe Senders Lists. However, users can change this configuration in the Outlook user interface.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_addpeopleiemailtothesafesenderslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_addpeopleiemailtothesafesenderslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_hidejunkmailui","displayName":"Hide Junk Mail UI (User)","description":"This policy setting controls whether the Junk E-mail Filter is enabled in Outlook. The Junk E-mail Filter in Outlook is designed to intercept the most obvious junk e-mail, or spam, and send it to users' Junk E-mail folders. The filter evaluates each incoming message based on several factors, including the time when the message was sent and the content of the message. The filter does not single out any particular sender or message type, but instead analyzes each message based on its content and structure to discover whether or not it is probably spam.\r\n \r\nIf you enable this policy setting, junk e-mail filtering in Outlook is turned off entirely, in addition to hiding the filtering controls from users. In addition, you can use the \"Junk E-mail Protection level\" policy setting to preset a filtering level and prevent users from changing it. Note - This policy setting does not affect the configuration of the Microsoft Exchange Server Intelligent Message Filter (IMF), which provides server-level junk e-mail filtering. \r\n\r\nIf you disable or do not configure this policy setting, the Junk E-mail Filter in Outlook is enabled.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_hidejunkmailui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_hidejunkmailui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkmailimportlist","displayName":"Trigger to apply junk email list settings (User)","description":"This policy setting allows you to trigger the activation of other junk e-mail policy settings.\r\n\r\nIf you enable this policy setting, you will trigger the activation of other junk e-mail policy settings. For example, if you configure the \"Specify path to Safe Senders list\" policy setting, the specified Safe Senders list is not imported by Outlook unless you also enable the \"Junk Mail Import List\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, you will not trigger the activation of other junk e-mail policies.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkmailimportlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkmailimportlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_overwriteorappendjunkmailimportlist","displayName":"Overwrite or Append Junk Mail Import List (User)","description":"By default, when a new Junk E-mail Filter list is deployed, Outlook appends the new Junk Mail Import List to the existing list. Enable this setting to replace the existing list with the new list, instead of appending to the current list.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_overwriteorappendjunkmailimportlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_overwriteorappendjunkmailimportlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_permanentlydeletejunkemail","displayName":"Permanently delete Junk E-mail (User)","description":"This policy setting determines whether suspected junk e-mail is permanently deleted instead of moved to the Junk E-mail folder.\r\n\r\nIf you enable this policy setting, suspected junk e-mail is immediately deleted and not moved into the Deleted Items folder.\r\n\r\nIf you disable or do not configure this policy setting, suspected junk e-mail is moved into the Junk E-mail folder.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_permanentlydeletejunkemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_permanentlydeletejunkemail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtoblockedsenderslist","displayName":"Specify path to Blocked Senders list (User)","description":"Specify a text file containing a list of e-mail addresses to append to or overwrite the Blocked Senders list (depending on the policy \"Overwrite or Append Junk Mail Import List\").","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtoblockedsenderslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtoblockedsenderslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtoblockedsenderslist_l_specifyfullpathandfilenametoblockedsenderslist","displayName":"Specify full path and filename to Blocked Senders list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist","displayName":"Specify path to Safe Recipients list (User)","description":"Specify a text file containing a list of e-mail addresses to append to or overwrite the Safe Recipients list (depending on the policy \"Overwrite or Append Junk Mail Import List\").","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist_l_specifyfullpathandfilenametosaferecipientslist","displayName":"Specify full path and filename to Safe Recipients list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist","displayName":"Specify path to Safe Senders list (User)","description":"Specify a text file containing a list of e-mail addresses to append to or overwrite the Safe Senders list (depending on the policy \"Overwrite or Append Junk Mail Import List\").","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist_l_specifyfullpathandfilenametosafesenderslist","displayName":"Specify full path and filename to Safe Senders list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_spoofyemails","displayName":"Hide warnings about suspicious domain names in e-mail addresses (User)","description":"By default, users are warned about suspicious domain names in the e-mail addresses. Use this setting to hide warnings about suspicious domain names in e-mail addreses.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_spoofyemails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_spoofyemails_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_trustemailfromcontacts","displayName":"Trust e-mail from contacts (User)","description":"This policy setting controls whether Outlook analyzes e-mail from users' Contacts when filtering junk e-mail.\r\n\r\nIf you enable this policy setting, the \"Also trust E-mail from my Contacts\" check box is selected in the Safe Senders tab of the Junk E-mail Options dialog and users cannot change it. E-mail addresses in users' Contacts list are treated as safe senders for purposes of filtering junk e-mail.\r\n\r\nIf you disable this policy setting, e-mail addresses in users' Contacts list are not treated as safe senders for purposes of filtering junk email, and users cannot change this configuration.\r\n\r\nIf you do not configure this policy setting, e-mail messages that are received from people who are listed in Contacts are considered safe by the Junk E-mail Filter, but users can change this configuration.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_trustemailfromcontacts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_trustemailfromcontacts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehithighlighting","displayName":"Do not display hit highlights in search results (User)","description":"By default, hit highlights are included in search results. Enable this setting to turn off search hit highlighting.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehithighlighting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehithighlighting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehybridsearch","displayName":"Disable Hybrid Searching (User)","description":"This policy setting controls whether searches in Cached Exchange Mode can also be run on the Exchange server. This policy does not affect either Online Mode or non-Exchange accounts. \r\n\r\nIf you enable this policy setting, Outlook runs searches locally in Cached Exchange Mode and “hybrid” (on the Exchange Server also) modes. It should be noted that if the sync slider is enabled and all mail is not locally cached, you may not see all available results.\r\n\r\nIf you disable or do not configure this policy setting, Outlook first runs searches locally, but then allows the user to search on the Exchange server by clicking “More” link at the bottom of searches, or uses the equivalent ribbon button.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehybridsearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehybridsearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disableinstallationprompts","displayName":"Prevent installation prompts when Windows Desktop Search component is not present (User)","description":"This policy setting allows you to prevent a dialog box from being shown when the Windows Desktop Search 4.0 or above system component is not present on the user's computer and removes the other links provided in Outlook to allow users to download the component. The new search functionality in Outlook requires Windows Desktop Search 4.0 or above.\r\n\r\nIf you enable this policy setting, the dialog box is not shown.\r\n\r\nIf you disable or do not configure this policy setting, the dialog box is shown when this system component is not present. Users are prompted with a dialog box when Outlook starts that explains how to download the system component to install on their computers. In addition, other links are provided by default in Outlook to allow users to download the system component. \r\n\r\nNote: If the required Windows system component is not available, the buttons in the Outlook Search ribbon tab will be disabled regardless of how this policy setting is configured.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disableinstallationprompts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disableinstallationprompts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_donotincludetheonlinearchiveinallmailitemsearch","displayName":"Do not include the Online Archive in All Mail Item search (User)","description":"This policy sets the default action in All Mail Item search to not include search results from the Online Archive.\r\n\r\nIf you enable this policy setting, search results from the Online Archive will not be included in an All Mail Item search in Outlook.\r\n\r\nIf you disable or do not configure this policy setting, search results from the Online Archive will be included in an All Mail Item search in Outlook.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_donotincludetheonlinearchiveinallmailitemsearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_donotincludetheonlinearchiveinallmailitemsearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor","displayName":"Change color used to highlight search matches (User)","description":"By default, search matches are highlighted in yellow. This setting allows you to change the color used for highlighting matches in search results.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon","displayName":"Background Color: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_000000","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_12632256","displayName":"Silver","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8421504","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16777215","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_65535","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16711808","displayName":"Fuchsia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8453888","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16776960","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8421376","displayName":"Olive","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8388736","displayName":"Purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_32768","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16711680","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8388608","displayName":"Maroon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_128","displayName":"Navy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_32896","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_255","displayName":"Blue","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_preventclearsignedmessageandattachmentindexing","displayName":"Prevent clear signed message and attachment indexing (User)","description":"This policy setting allows you to turn off the indexing of the body and attachments of clear-text signed messages. The sender, subject line, and date will continue to be indexed and searchable. \r\n\r\nIf you enable this policy setting, indexing of clear-text signed messages will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, clear-text signed messages will be indexed and searchable.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_preventclearsignedmessageandattachmentindexing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_preventclearsignedmessageandattachmentindexing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope","displayName":"Set default search scope (User)","description":"This policy allows you to specify the default search scope to be used. Users will not be able to change the default once this policy is set, but they can change the scope while running a search.\r\n \r\nIf you enable this policy, you can specify the folders that Outlook searches by default when the user begins a new search.\r\n \r\nIf you disable or do not configure this policy, Outlook searches all folders in the current mailbox when the search is initiated from the Inbox. If the search is initiated from another folder, the search only includes items from that folder. Users can still change the scope when searching.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_l_setdefaultsearchscopedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_l_setdefaultsearchscopedropid_0","displayName":"Default behavior (see explanation)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_l_setdefaultsearchscopedropid_1","displayName":"\"All Mailboxes\" on all folders","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_l_setdefaultsearchscopedropid_2","displayName":"\"Current Folder\" on all folders","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_setdefaultsearchscope_l_setdefaultsearchscopedropid_3","displayName":"\"Current Mailbox\" on all folders","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_turnoffautomaticsearchindexreconciliation","displayName":"Turn off automatic search index reconciliation (User)","description":"This policy setting configures the automatic verification of the integrity of Outlook's search index every 72 hours.\r\n\r\nIf you enable this policy setting, automatic reconciliation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will reconcile its index every 72 hours.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_turnoffautomaticsearchindexreconciliation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_turnoffautomaticsearchindexreconciliation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_turnoffwordwheel","displayName":"Do not display search results as the user types (User)","description":"By default, search results are displayed as the user types a search query. This functionality (known as WordWheeling) can be turned off by enabling this setting.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_turnoffwordwheel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_turnoffwordwheel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions","displayName":"Layout Options (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b9ab4d39-9e28-4897-aa34-0201a35ea989","categoryName":"Right-to-left","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setglobaltextdirection","displayName":"Set global text direction: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b9ab4d39-9e28-4897-aa34-0201a35ea989","categoryName":"Right-to-left","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setglobaltextdirection_0","displayName":"Context-based","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setglobaltextdirection_1","displayName":"Left to right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setglobaltextdirection_2","displayName":"Right-to-left","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setlayoutdirection","displayName":"Set layout direction: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b9ab4d39-9e28-4897-aa34-0201a35ea989","categoryName":"Right-to-left","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setlayoutdirection_0","displayName":"Left to Right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_l_setlayoutdirection_1","displayName":"Right to Left","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general","displayName":"General (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","categoryName":"Spelling","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_l_alwayscheckspellingbeforesending","displayName":"Always check spelling before sending (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","categoryName":"Spelling","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_l_alwayscheckspellingbeforesending_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_l_alwayscheckspellingbeforesending_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_l_ignoreoriginalmessagetextinreplyorforward","displayName":"Ignore original message text in reply or forward (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","categoryName":"Spelling","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_l_ignoreoriginalmessagetextinreplyorforward_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_spelling_l_general_l_ignoreoriginalmessagetextinreplyorforward_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockglobaladdresslistsynchronization","displayName":"Block Global Address List synchronization (User)","description":"This policy setting allows you to block the synchronization of contacts between Outlook and the Global Address List (GAL).\r\n\r\nIf you enable this policy setting, GAL contact synchronization is blocked.\r\n\r\nIf you disable or you do not configure this policy setting, GAL contact synchronization is allowed.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockglobaladdresslistsynchronization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockglobaladdresslistsynchronization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocknetworkactivitysynchronization","displayName":"Block network activity synchronization (User)","description":"This policy setting allows you to block synchronization of status updates between Outlook and social networks.\r\n\r\nIf you enable this policy setting, social network activity synchronization is blocked.\r\n\r\nIf you disable or you do not configure this policy setting, social network activity synchronization is allowed.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocknetworkactivitysynchronization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocknetworkactivitysynchronization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocksocialnetworkcontactsynchronization","displayName":"Block social network contact synchronization (User)","description":"This policy setting allows you to block synchronization of contacts between Outlook and social networks. \r\n\r\nIf you enable this policy setting, social network contact synchronization is blocked.\r\n\r\nIf you disable or you do not configure this policy setting, social network contact synchronization is allowed.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocksocialnetworkcontactsynchronization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocksocialnetworkcontactsynchronization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockspecificsocialnetworkproviders","displayName":"Block specific social network providers (User)","description":"This policy setting allows you to specify the list of social network providers that will never be loaded by the Outlook Social Connector. \r\n\r\nIf you enable this policy setting, social network providers added to the list will never be loaded by the Outlook Social Connector. This list needs to be semi-colon delimited. \r\n\r\nIf you disable or you do not configure this policy setting, the Outlook Social Connector can load any provider specified by the user.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockspecificsocialnetworkproviders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockspecificsocialnetworkproviders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blockspecificsocialnetworkproviders_l_blockspecificsocialnetworkprovidersid","displayName":"Separate ProgIDs with semi-colons (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotallowondemandactivitysynchronization","displayName":"Do not allow on-demand activity synchronization (User)","description":"This policy setting allows you to prevent on-demand synchronization of activity information between Outlook and social networks.\r\n\r\nIf you enable this policy setting, on-demand synchronization is blocked. \r\n\r\nIf you disable or you do not configure this policy setting, on-demand synchronization is allowed.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotallowondemandactivitysynchronization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotallowondemandactivitysynchronization_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotdownloadphotosfromactivedirectory","displayName":"Do not download photos from Active Directory (User)","description":"This policy setting controls whether contact photos are downloaded from the Active Directory.\r\n\r\nIf you enable this policy setting, contact photos are not downloaded. \r\n\r\nIf you disable or you do not configure this policy setting, contact photos are downloaded.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotdownloadphotosfromactivedirectory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotdownloadphotosfromactivedirectory_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotshowsocialnetworkinfobars","displayName":"Do not show social network info-bars (User)","description":"This policy setting controls whether certain info-bar messages that will prompt users to install social network providers are displayed in the social connector. \r\n\r\nIf you enable this policy setting, the info-bars are not shown.\r\n\r\nIf you disable or you do not configure this policy setting, the info-bars are shown.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotshowsocialnetworkinfobars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_donotshowsocialnetworkinfobars_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_preventsocialnetworkconnectivity","displayName":"Disable Office connections to social networks (User)","description":"This policy setting prevents users from connecting Office to social networks (including SharePoint), and prevents Office from displaying contacts and feeds from their social networks.\r\n\r\nIf you enable this policy setting, users cannot connect Office to social networks.\r\n\r\nIf you disable or you do not configure this policy setting, users can connect Office to social networks.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_preventsocialnetworkconnectivity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_preventsocialnetworkconnectivity_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval","displayName":"Set GAL contact synchronization interval (User)","description":"This policy setting controls how often contact information is synchronized between Outlook and connected social networks (in minutes). \r\n\r\nIf you enable this policy setting, you may specify the specified interval (in minutes) in which contact information is synchronized.\r\n\r\nIf you disable or you do not configure this policy setting, contact information is synchronized at the default interval (once every 4 days, or 5760 minutes).","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval_l_setgalcontactsynchronizationintervalspinid","displayName":"Synchronization interval (in minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifyactivityfeedsynchronizationinterval","displayName":"Specify activity feed synchronization interval (User)","description":"This policy setting specifies the minimum interval that Office waits before requesting activity feed information from social networks for a given contact.\r\n\r\nIf you enable this policy setting, Office waits for at least the specified interval before requesting a new activity feed for each contact.\r\n\r\nIf you disable or do not configure this policy setting, Office waits for at least the default interval (60 minutes) before requesting a new activity feed for each contact.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifyactivityfeedsynchronizationinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifyactivityfeedsynchronizationinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifyactivityfeedsynchronizationinterval_l_specifyactivityfeedsynchronizationintervalspinid","displayName":"Synchronization interval (in minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload","displayName":"Specify list of social network providers to load (User)","description":"This policy setting determines the list of social network providers that are loaded by the Outlook Social Connector.\r\n\r\nIf you enable this policy setting, you may enter a list of provider progIDs of social network providers that will be loaded by the Outlook Social Connector. This list needs to be semi-colon delimited. Note that if you enable this policy setting, only social network providers that are on this list will be loaded by the Outlook Social Connector. No other social network providers will be loaded.\r\n\r\nIf you disable or you do not configure this policy setting, the Outlook Social Connector can load any provider specified by the user.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload_l_specifylistofsocialnetworkproviderstoloadid","displayName":"Separate ProgIDs with semi-colons (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_turnoffoutlooksocialconnector","displayName":"Turn off Outlook Social Connector (User)","description":"This policy setting allows you to turn off the Outlook Social Connector.\r\n\r\nIf you enable this policy setting, the Outlook Social Connector is turned off.\r\n\r\nIf you disable or you do not configure this policy setting, the Outlook Social Connector is turned on.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_turnoffoutlooksocialconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_turnoffoutlooksocialconnector_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_outlooktodayavailability","displayName":"Outlook Today availability (User)","description":"Checked: Displays the customizable Outlook Today page. | Unchecked: Displays a standard folder view in place of Outlook Today.","helpText":"","infoUrls":[],"categoryId":"75ad885f-6118-4508-a2fd-bb26be931c3f","categoryName":"Outlook Today Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_outlooktodayavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_outlooktodayavailability_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_urlforcustomoutlooktoday","displayName":"URL for custom Outlook Today (User)","description":"Specifies the URL of a custom web page to be displayed in place of Outlook Today.","helpText":"","infoUrls":[],"categoryId":"75ad885f-6118-4508-a2fd-bb26be931c3f","categoryName":"Outlook Today Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_urlforcustomoutlooktoday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_urlforcustomoutlooktoday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_urlforcustomoutlooktoday_l_entertheurlofoutlooktodayswebpagemax129chars","displayName":"Enter the URL of Outlook Today's web page (max 129 chars): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75ad885f-6118-4508-a2fd-bb26be931c3f","categoryName":"Outlook Today Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersinexchangeonline","displayName":"Keep Search Folders in Exchange online (User)","description":"This policy setting allows you to specify the number of days to keep a Search Folder active when running in online mode. After a Search Folder has not been accessed for the specified number of days, it becomes dormant and no longer remains up-to-date with current contents of folders (viewing the Search Folder makes it active again and restarts the timer).\r\n\r\nIf you enable this policy setting, you may specify the number of days to keep a Search Folder active when running in online mode.\r\n\r\nIf you disable or do not configure this policy setting, then Search Folders always remain dormant.","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersinexchangeonline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersinexchangeonline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersinexchangeonline_l_specifydaystokeepfoldersaliveinexchangeonlinemode","displayName":"Specify days to keep folders alive in Exchange online mode: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersoffline","displayName":"Keep Search Folders offline (User)","description":"This policy setting allows you to specify the number of days to keep a Search Folder active when running in offline or cached mode. After a Search Folder has not been accessed for the specified number of days, it becomes dormant and no longer remains up-to-date with current contents of folders (viewing the Search Folder makes it active again and restarts the timer).\r\n\r\nIf you enable this policy setting, you may specify the number of days to keep a Search Folder active when running in offline mode.\r\n\r\nIf you disable or do not configure this policy setting, then Search Folders always remain dormant.","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersoffline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersoffline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_keepsearchfoldersoffline_l_specifydaystokeepfoldersaliveinofflineorcachedmode","displayName":"Specify days to keep folders alive in offline or cached mode: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox","displayName":"Maximum Number of Online Search Folders per mailbox (User)","description":"Specifies the maximum number of Search Folders that run on the Exchange server. The number of Search Folders running on the client computer is not affected.","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox_l_specifymaximumnumberofsearchfolders2","displayName":"Maximum number of Search Folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms","displayName":"Allow Active X One Off Forms (User) (Deprecated)","description":"By default, third-party ActiveX controls are not allowed to run in one-off forms in Outlook. You can change this behavior so that Safe Controls (Microsoft Forms 2.0 controls and the Outlook Recipient and Body controls) are allowed in one-off forms, or so that all ActiveX controls are allowed to run.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_l_empty29","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_l_empty29_0","displayName":"Load only Outlook Controls","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_l_empty29_1","displayName":"Allows only Safe Controls","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_l_empty29_2","displayName":"Allows all ActiveX Controls","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2","displayName":"Allow Active X One Off Forms (User)","description":"By default, third-party ActiveX controls are not allowed to run in one-off forms in Outlook. You can change this behavior so that Safe Controls (Microsoft Forms 2.0 controls and the Outlook Recipient and Body controls) are allowed in one-off forms, or so that all ActiveX controls are allowed to run.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29","displayName":"\r\nSets which ActiveX controls to allow.\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29_0","displayName":"Load only Outlook Controls","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29_1","displayName":"Allows only Safe Controls","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29_2","displayName":"Allows all ActiveX Controls","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel","displayName":"Configure Add-In Trust Level (User)","description":"All installed trusted COM addins can be trusted. Exchange Settings for the addins still override if present and this option is selected.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28","displayName":"\r\nSelect Add-In Trust Level:\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28_0","displayName":"Trust all, or use Exchange settings if present","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28_1","displayName":"Trust all loaded and installed COM addins","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28_2","displayName":"Do NOT trust loaded and installed COM addins","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_disablerememberpasswordcheckboxforinternetemailsettingsdialo","displayName":"Disable 'Remember password' for Internet e-mail accounts (User)","description":"Use this option to hide your user's ability to cache passwords locally in the computer's registry. When configured, this policy will hide the 'Remember Password' checkbox and not allow users to have Outlook remember their password. \r\n\r\nNote that POP3, IMAP, and HTTP e-mail accounts are all considered Internet e-mail accounts in Outlook. E-mail account options are listed on the Server Type dialog box when users choose 'New' under Tools | Account Settings.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_disablerememberpasswordcheckboxforinternetemailsettingsdialo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_disablerememberpasswordcheckboxforinternetemailsettingsdialo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_donotautomaticallysignreplies","displayName":"Do not automatically sign replies (User)","description":"This policy setting allows you to specify whether replies will be automatically signed.\r\n\r\nIf you enable this policy setting, the option to respond automatically to a signed message with a signed response will be overridden, and an unsigned response will be the default reply to a signed message.\r\n\r\nIf you disable or do not configure this policy setting, a signed response will be the default reply to a signed message.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_donotautomaticallysignreplies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_donotautomaticallysignreplies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_preventusersfromcustomizingattachmentsecuritysettings","displayName":"Prevent users from customizing attachment security settings (User) (Deprecated)","description":"This policy setting prevents users from overriding the set of attachments blocked by Outlook.\r\n\r\nIf you enable this policy setting users will be prevented from overriding the set of attachments blocked by Outlook. Outlook also checks the \"Level1Remove\" registry key when this setting is specified. \r\n\r\nIf you disable or do not configure this policy setting, users will be allowed to override the set of attachments blocked by Outlook.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_preventusersfromcustomizingattachmentsecuritysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_preventusersfromcustomizingattachmentsecuritysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_preventusersfromcustomizingattachmentsecuritysettings_v2","displayName":"Prevent users from customizing attachment security settings (User)","description":"This policy setting prevents users from overriding the set of attachments blocked by Outlook.\r\n\r\nIf you enable this policy setting users will be prevented from overriding the set of attachments blocked by Outlook. Outlook also checks the \"Level1Remove\" registry key when this setting is specified. \r\n\r\nIf you disable or do not configure this policy setting, users will be allowed to override the set of attachments blocked by Outlook.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_preventusersfromcustomizingattachmentsecuritysettings_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_preventusersfromcustomizingattachmentsecuritysettings_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_promptusertochoosesecuritysettingsifdefaultsettingsfail","displayName":"Prompt user to choose security settings if default settings fail (User)","description":"Check to prompt the user to choose security settings if default settings fail; uncheck to automatically select.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_promptusertochoosesecuritysettingsifdefaultsettingsfail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_promptusertochoosesecuritysettingsifdefaultsettingsfail_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_turnoffcontactexport","displayName":"Turn off contact export (User)","description":"This policy setting controls the ability of users to export contact information from the address book.\r\n\r\nIf you enable this policy setting, the \"Add to Contacts\" menu is not configurable in the address book.\r\n\r\nIf you disable or do not configure this policy setting, the \"Add to Contacts\" menu is configurable.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_turnoffcontactexport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_turnoffcontactexport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_useprotectedviewforattachmentsreceivedfrominternalsenders","displayName":"Use Protected View for attachments received from internal senders (User)","description":"This policy setting allows you to determine if attachments received from senders within your organization open in Protected View. This setting only applies to Outlook accounts setup to use an Exchange server.\r\n\r\nIf you enable this policy setting, attachments received from senders within your organization open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, attachments received from senders within your organization do not open in Protected View.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_useprotectedviewforattachmentsreceivedfrominternalsenders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_useprotectedviewforattachmentsreceivedfrominternalsenders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockexternalcontent","displayName":"Display pictures and external content in HTML e-mail (User)","description":"This policy setting setting controls whether Outlook downloads untrusted pictures and external content located in HTML e-mail messages without users explicitly choosing to download them. \r\n\r\nIf you enable this policy setting, Outlook will not automatically download content from external servers unless the sender is included in the Safe Senders list. Recipients can choose to download external content from untrusted senders on a message-by-message basis. \r\n\r\nIf you disable this policy setting, Outlook will display pictures and external content in HTML e-mail automatically.\r\n\r\nIf you do not configure this policy setting, Outlook does not download external content in HTML e-mail and RSS items unless the content is considered safe. Content that Outlook can be configured to consider safe includes: \r\n\r\n- Content in e-mail messages from senders and to recipients defined in the Safe Senders and Safe Recipients lists. \r\n- Content from Web sites in Internet Explorer's Trusted Sites security zone. \r\n- Content in RSS items. \r\n- Content from SharePoint Discussion Boards. Users can control what content is considered safe by changing the options in the \"Automatic Download\" section of the Trust Center. If Outlook's default blocking configuration is overridden, in the Trust Center or by some other method, Outlook will display external content in all HTML e-mail messages, including any that include Web beacons.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockexternalcontent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockexternalcontent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockinternet","displayName":"Include Internet in Safe Zones for Automatic Picture Download (User) (Deprecated)","description":"This policy setting controls whether pictures and external content in HTML e-mail messages from untrusted senders on the Internet are downloaded without Outlook users explicitly choosing to do so. \r\n\r\nIf you enable this policy setting, Outlook will automatically download external content in all e-mail messages sent over the Internet and users will not be able to change the setting. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not consider the Internet a safe zone, which means that Outlook will not automatically download content from external servers unless the sender is included in the Safe Senders list. Recipients can choose to download external content from untrusted senders on a message-by-message basis.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockinternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockinternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockinternet_v2","displayName":"Include Internet in Safe Zones for Automatic Picture Download (User)","description":"This policy setting controls whether pictures and external content in HTML e-mail messages from untrusted senders on the Internet are downloaded without Outlook users explicitly choosing to do so. \r\n\r\nIf you enable this policy setting, Outlook will automatically download external content in all e-mail messages sent over the Internet and users will not be able to change the setting. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not consider the Internet a safe zone, which means that Outlook will not automatically download content from external servers unless the sender is included in the Safe Senders list. Recipients can choose to download external content from untrusted senders on a message-by-message basis.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockinternet_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockinternet_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockintranet","displayName":"Include Intranet in Safe Zones for Automatic Picture Download (User)","description":"This policy setting controls whether pictures and external content in HTML e-mail messages from untrusted senders on the local intranet are downloaded without Outlook users explictly choosing to do so. \r\n\r\nIf you enable this policy setting, Outlook will automatically download external content in all e-mail messages sent over the local intranet and users will not be able to change the setting. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not consider the local intranet a safe zone, which means that Outlook will not automatically download content from other servers in the Local Intranet zone unless the sender is included in the Safe Senders list. Recipients can choose to download external content from untrusted senders on a message-by-message basis.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockintranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blockintranet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blocktrustedzones","displayName":"Block Trusted Zones (User)","description":"This policy setting controls whether pictures from sites in the Trusted Sites security zone are automatically downloaded in Outlook e-mail messages and other items. \r\n\r\nIf you enable this policy setting, Outlook does not automatically download content from Web sites in the Trusted sites zone in Internet Explorer. Recipients can choose to download external content on a message-by-message basis. \r\n\r\nIf you disable or do not configure this policy setting, Outlook automatically downloads content from Web sites in the Trusted sites zone in Internet Explorer.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blocktrustedzones_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blocktrustedzones_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafesenderandrecipientlists","displayName":"Automatically download content for e-mail from people in Safe Senders and Safe Recipients Lists (User)","description":"This policy setting controls whether Outlook automatically downloads external content in e-mail from senders in the Safe Senders List or Safe Recipients List. \r\n\r\nIf you enable this policy setting, Outlook automatically downloads content for e-mail from people in Safe Senders and Safe Recipients lists. \r\n\r\nIf you disable this policy setting, Outlook will not automatically download content from external servers for messages sent by people listed in users' Safe Senders Lists or Safe Recipients Lists. Recipients can choose to download external content on a message-by-message basis. \r\n\r\nIf you do not configure this policy setting, downloads are permitted when users receive e-mail from people listed in the user's Safe Senders List or Safe Recipients List.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafesenderandrecipientlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafesenderandrecipientlists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafezones","displayName":"Do not permit download of content from safe zones (User)","description":"This policy setting controls whether Outlook automatically downloads content from safe zones when displaying messages. \r\n\r\nIf you enable this policy setting content from safe zones will be downloaded automatically. \r\n\r\nIf you disable this policy Outlook will not automatically download content from safe zones. Recipients can choose to download external content from untrusted senders on a message-by-message basis. \r\n\r\nIf you do not configure this policy setting, Outlook automatically downloads content from sites that are considered \"safe,\" as defined in the Security tab of the Internet Options dialog box in Internet Explorer. \r\n\r\nImportant - Note that this policy setting is \"backward.\" Despite the name, disabling the policy setting prevents the download of content from safe zones and enabling the policy setting allows it.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafezones_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafezones_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablecontinuebuttononallencryptionwarningdialogs","displayName":"Do not provide Continue option on Encryption warning dialog boxes (User)","description":"This setting controls whether Outlook users are allowed to send e-mail messages after they see an encryption warning. \r\n\r\nIf you enable this policy setting, encryption warning dialog boxes do not contain a Continue button, which means that users must cancel the sending operation entirely. \r\n\r\nIf you disable or do not configure this policy setting, if Outlook users see an encryption-related dialog box when attempting to send a message, they can choose to dismiss the warning and send the message anyway.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablecontinuebuttononallencryptionwarningdialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablecontinuebuttononallencryptionwarningdialogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablepublishtogalbutton","displayName":"Do not display 'Publish to GAL' button (User)","description":"This policy setting controls whether Outlook users can publish e-mail certificates to the Global Address List (GAL). \r\n\r\nIf you enable this policy setting, the \"Publish to GAL\" button does not display in the \"E-mail Security\" section of the Trust Center. \r\n\r\nIf you disable or do not configure this policy setting, Outlook users can publish their e-mail certificates to the GAL through the \"E-mail Security\" section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablepublishtogalbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablepublishtogalbutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_donotcheckemailaddressagainstaddressofcertificatesbeingusing","displayName":"Do not check e-mail address against address of certificates being used (User)","description":"This policy setting controls whether Outlook verifies the user's e-mail address with the address associated with the certificate used for signing.\r\n\r\nIf you enable this policy setting, users can send messages signed with certificates that do not match their e-mail addresses.\r\n\r\nIf you disable or do not configure this policy setting, Outlook verifies that the user's e-mail address matches the certificate being used for signing.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_donotcheckemailaddressagainstaddressofcertificatesbeingusing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_donotcheckemailaddressagainstaddressofcertificatesbeingusing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_enableaiacertevaluation","displayName":"Enable Retrieval of Remote Certificate Authority Information (User)","description":"This policy setting controls whether Outlook will use remote certificate authority information in a secure email message to validate that its certificate is trusted. \r\n\r\nIf you enable this setting, you’ll allow the operating system to access remote network locations specified in a certificate for validation.\r\n\r\nIf you disable or don’t configure this setting, retrieval of remote Certificate Authority Information won’t be allowed, and only stored certificates will be used for authentication.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_enableaiacertevaluation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_enableaiacertevaluation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_enablecryptographyicons","displayName":"Enable Cryptography Icons (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_enablecryptographyicons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_enablecryptographyicons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_encryptallemailmessages","displayName":"Encrypt all e-mail messages (User)","description":"This policy setting allows you to require that all e-mail messages be encrypted when sent from Outlook.\r\n\r\nIf you enable this policy setting, the Encrypt button is automatically selected on all outgoing e-mail messages, meeting invitations, and other Outlook items. Users must select an appropriate certificate to encrypt the message for the intended recipient.\r\n\r\nIf you disable or do not configure this policy setting, outgoing e-mail messages are not encrypted. If you disable this policy setting, users will not be able to change the configuration.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_encryptallemailmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_encryptallemailmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_ensureallsmimesignedmessageshavealabel","displayName":"Ensure all S/MIME signed messages have a label (User)","description":"This policy setting controls whether Outlook requires labels on S/MIME signed messages.\r\n\r\nIf you enable this policy setting, labels must be attached to all Outlook S/MIME messages before they are sent. Users can attach labels to messages in the \"Message Options\" dialog box by clicking \"Security Settings,\" ensuring that the \"Add digital signature to this message\" check box is selected, and selecting a label under \"Security Label.\"\r\n\r\nIf you disable all S/MIME signed messages are not required to have a label, and users cannot change this functionality.\r\n\r\nIf you do not configure this policy setting, all S/MIME signed messages are not required to have a label, but users can change this functionality through the \"Message Options\" dialog box.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_ensureallsmimesignedmessageshavealabel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_ensureallsmimesignedmessageshavealabel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_fortezzacertificatepolicies","displayName":"Fortezza certificate policies (User)","description":"This policy setting specifies a list of policies allowed in the policies extension of a certificate that indicate the certificate is a Fortezza certificate. Fortezza is a hardware--based encryption standard created by the National Security Agency (NSA), a division of the United States Department of Defense. To be valid for use with Fortezza, a certificate must include an appropriate policy in the certificate's policies extension. \r\n\r\nIf you enable this policy setting, you can enter a list of policies in the supplied text box that can be used to indicate that a certificate is a Fortezza certificate. The list should be separated by semi-colons. For example: policy1;policy2;policy3. \r\n\r\nIf you disable or so nor configure this policy setting, a list of Fortezza certificate policies are not listed.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_fortezzacertificatepolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_fortezzacertificatepolicies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_fortezzacertificatepolicies_l_enterlistofpoliciesthatcanbeinthepoliciesextension2","displayName":"List of policies to indicate that a certificate is a Fortezza certificate (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats","displayName":"Message Formats (User)","description":"This policy setting controls which message encryption formats Outlook can use. Outlook supports three formats for encrypting and signing messages: S/MIME, Exchange, and Fortezza.\r\n\r\nIf you enable this policy setting, you can specify whether Outlook can use S/MIME (the default), Exchange, or Fortezza encryption, or any combination of any of these options. Users will not be able to change this configuration.\r\n\r\nIf you disable or do not configure this policy setting, Outlook only uses S/MIME to encrypt and sign messages. If you disable this policy setting, users will not be able to change this configuration.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats","displayName":"Support the following message formats: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_1","displayName":"S/MIME","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_2","displayName":"Exchange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_20","displayName":"Fortezza","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_3","displayName":"S/MIME and Exchange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_21","displayName":"S/MIME and Fortezza","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_22","displayName":"Exchange and Fortezza","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messageformats_l_supportthefollowingmessageformats_23","displayName":"S/MIME, Exchange, and Fortezza","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messagewhenoutlookcannotfindthedigitalidtodecodeamessage","displayName":"Message when Outlook cannot find the digital ID to decode a message (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messagewhenoutlookcannotfindthedigitalidtodecodeamessage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messagewhenoutlookcannotfindthedigitalidtodecodeamessage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_messagewhenoutlookcannotfindthedigitalidtodecodeamessage_l_entererrormessagetextmax255characters","displayName":"Enter error message text (max 255 characters): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings","displayName":"Minimum encryption settings (User) (Deprecated)","description":"This policy setting allows you to set the minimum key length for an encrypted e-mail message.\r\n\r\nIf you enable this policy setting, you may set the minimum key length for an encrypted e-mail message. Outlook will display a warning dialog if the user tries to send a message using an encryption key that is below the minimum encryption key value set. The user can still choose to ignore the warning and send using the encryption key originally chosen.\r\n\r\nIf you disable or do not configure this policy setting, a dialog warning will be shown to the user if the user attempts to send a message using encryption. The user can still choose to ignore the warning and send using the encryption key originally chosen.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_l_minimumkeysizeinbits","displayName":"Minimum key size (in bits): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_v2","displayName":"Minimum encryption settings (User)","description":"This policy setting allows you to set the minimum key length for an encrypted e-mail message.\r\n\r\nIf you enable this policy setting, you may set the minimum key length for an encrypted e-mail message. Outlook will display a warning dialog if the user tries to send a message using an encryption key that is below the minimum encryption key value set. The user can still choose to ignore the warning and send using the encryption key originally chosen.\r\n\r\nIf you disable or do not configure this policy setting, a dialog warning will be shown to the user if the user attempts to send a message using encryption. The user can still choose to ignore the warning and send using the encryption key originally chosen.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_v2_l_minimumkeysizeinbits","displayName":"Minimum key size (in bits): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_outlooktnefinsmimemessages","displayName":"Always use TNEF formatting in S/MIME messages (User)","description":"This policy setting allows you to specify the formatting when sending S/MIME messages.\r\n\r\nIf you enable this policy setting, Outlook always uses TNEF formatting when sending S/MIME messages.\r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the format specified by the user when sending e-mail messages, including when sending S/MIME messages.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_outlooktnefinsmimemessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_outlooktnefinsmimemessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_repliesorforwardstosignedencryptedmessagesaresignedencrypted","displayName":"Replies or forwards to signed/encrypted messages are signed/encrypted (User)","description":"This policy setting controls whether replies and forwards to signed/encrypted mail should also be signed/encrypted. \r\n\r\nIf you enable this policy setting, signing/encryption will be turned on when replying/forwarding a signed or encrypted message, even if the user is not configured for SMIME.\r\n\r\nIf you disable or do not configure this policy setting, signing/encryption is not enforced.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_repliesorforwardstosignedencryptedmessagesaresignedencrypted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_repliesorforwardstosignedencryptedmessagesaresignedencrypted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requestansmimereceiptforallsmimesignedmessages","displayName":"Request an S/MIME receipt for all S/MIME signed messages (User)","description":"This policy setting controls whether Outlook sends S/MIME receipt requests with S/MIME signed messages.\r\n\r\nIf you enable this policy setting, Outlook requests S/MIME receipts whenever it sends S/MIME signed messages and users cannot change this setting.\r\n\r\nIf you disable or do not configure this policy setting, Outlook does not send S/MIME receipt requests with signed messages, but users can still include receipt requests with individual messages. If you disable this policy setting, users cannot change this functionality, but if you do not configure this policy setting, users can enable the option in the \"E-mail Security\" section of the Trust Center or the \"Security Properties\" dialog for individual messages.\r\n\r\nImportant: When the \"Sign all e-mail messages\" policy setting is enabled, enabling this policy setting can place significant stress on the e-mail infrastructure. Consider your needs and capabilities before enabling both settings.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requestansmimereceiptforallsmimesignedmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requestansmimereceiptforallsmimesignedmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority","displayName":"Required Certificate Authority (User)","description":"This policy setting enables you to designate a required certificate authority for Outlook to use for encryption and digital signatures.\r\n\r\nIf you enable this policy setting, you can specify a required certificate authority by entering an X.509 distinguished name in the text field that is provided. The name must conform to the X.509 certificate format exactly. For example:\r\n\r\nCN=WoodgroveBankCA, DC=WoodgroveBank, DC=com\r\n\r\nIf you disable or do not configure this policy setting, Outlook trusts any certificate authorities that are represented by certificates in the Trusted Root Certification Authorities store on users' computers.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority_l_x509issuednthatrestrictschoiceofcertifyingauthorities","displayName":"X.509 issue DN that restricts choice of certifying authorities: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiresuitebalgorithmsforsmimeoperations","displayName":"Require SuiteB algorithms for S/MIME operations (User)","description":"This policy setting determines whether Outlook is required to use NSA Suite B algorithms for S/MIME operations. Outlook implements Suite B, a set of cryptographic algorithms for symmetric encryption, hashing, digital signatures, and key exchange announced in 2005 by the National Security Agency (NSA), a division of the United States Department of Defense. The Suite B protocols can be used to meet U.S. government standards for handling both classified and unclassified information. \r\n\r\nIf you enable this policy setting, Outlook uses only Suite B algorithms for S/MIME operations. The Suite B algorithms are as follows: \r\n\r\n- Symmetric encryption. Advanced Encryption Standard (AES) with key sizes of 128 and 256 bits. \r\n\r\n- Message digest. Secure Hash Algorithm (SHA-256 and SHA-384). \r\n\r\n- Key agreement. Elliptic-Curve Menezes-Qu-Vanstone (ECMQV); Elliptic Curve Diffie-Hellman (ECDH). \r\n\r\n- Digital Signatures. Elliptic-Curve Digital Signature Algorithm (ECDSA). \r\n\r\nIf you disable or do not configure this policy setting, Outlook can use any available algorithm for S/MIME operations, such as encryption, signing, and so on. \r\n\r\nNote - For more information about Suite B, see \"Fact Sheet NSA Suite B Cryptography\" http://www.nsa.gov/ia/industry/crypto_suite_b.cfm.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiresuitebalgorithmsforsmimeoperations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiresuitebalgorithmsforsmimeoperations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_runinfipscompliantmode","displayName":"Run in FIPS compliant mode (User)","description":"This policy setting controls whether Outlook is required to use FIPS-compliant algorithms when signing and encrypting messages. Outlook can run in a mode that complies with Federal Information Processing Standards (FIPS), a set of standards published by the National Institute of Standards and Technology (NIST) for use by non-military United States government agencies and by government contractors.\r\n\r\nIf you enable this policy setting, Outlook runs in a mode that complies with the FIPS 140-1 standard for cryptographic modules. This mode requires the use of the SHA-1 algorithm for signing and 3DES for encryption.\r\n\r\nIf you disable or do not configure this policy setting, Outlook does not run in FIPS-compliant mode. Organizations that do business with the United States government but do not run Outlook in FIPS-compliant mode risk violating the U.S. government's rules regarding the handling of sensitive information.\r\n\r\nFor more information about FIPS, see FIPS - General Information at http://www.itl.nist.gov/fipspubs/geninfo.htm","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_runinfipscompliantmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_runinfipscompliantmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_sendallsignedmessagesasclearsignedmessages","displayName":"Send all signed messages as clear signed messages (User)","description":"This policy setting controls whether Outlook sends signed messages as clear text signed messages.\r\n\r\nIf you enable this policy setting, the \"Send clear text signed message when sending signed messages\" option is selected in the E-mail Security section of the Trust Center.\r\n\r\nIf you disable or do not configure this policy setting, when users sign e-mail messages with their digital signature and send them, Outlook uses the signature's private key to encrypt the digital signature but sends the messages as clear text, unless they are encrypted separately.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_sendallsignedmessagesasclearsignedmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_sendallsignedmessagesasclearsignedmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signallemailmessages","displayName":"Sign all e-mail messages (User)","description":"This policy setting controls whether Outlook requires digital signatures on all outgoing e-mail messages.\r\n\r\nIf you enable this policy setting, Outlook requires all outgoing messages to be digitally signed before being sent.\r\n\r\nIf you disable or do not configure this policy setting, Outlook does not require outgoing messages to have digital signatures.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signallemailmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signallemailmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning","displayName":"Signature Warning (User) (Deprecated)","description":"This policy setting controls how Outlook warns users about messages with invalid digital signatures.\r\n\r\nIf you enable this policy setting, you can choose from three options for controlling how Outlook users are warned about invalid signatures:\r\n\r\n- Let user decide if they want to be warned. This option enforces the default configuration.\r\n- Always warn about invalid signatures.\r\n- Never warn about invalid signatures.\r\n\r\nIf you disable or do not configure this policy setting, if users open e-mail messages that include invalid digital signatures, Outlook displays a warning dialog. Users can decide whether they want to be warned about invalid signatures in the future.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30","displayName":"Signature Warning (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30_0","displayName":"Let user decide if they want to be warned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30_1","displayName":"Always warn about invalid signatures","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30_2","displayName":"Never warn about invalid signatures","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2","displayName":"Signature Warning (User)","description":"This policy setting controls how Outlook warns users about messages with invalid digital signatures.\r\n\r\nIf you enable this policy setting, you can choose from three options for controlling how Outlook users are warned about invalid signatures:\r\n\r\n- Let user decide if they want to be warned. This option enforces the default configuration.\r\n- Always warn about invalid signatures.\r\n- Never warn about invalid signatures.\r\n\r\nIf you disable or do not configure this policy setting, if users open e-mail messages that include invalid digital signatures, Outlook displays a warning dialog. Users can decide whether they want to be warned about invalid signatures in the future.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2_l_signaturewarning30","displayName":"Signature Warning (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2_l_signaturewarning30_0","displayName":"Let user decide if they want to be warned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2_l_signaturewarning30_1","displayName":"Always warn about invalid signatures","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_v2_l_signaturewarning30_2","displayName":"Never warn about invalid signatures","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients","displayName":"S/MIME interoperability with external clients: (User)","description":"This policy setting controls whether Outlook decodes encrypted messages itself or passes them to an external program for processing.\r\n\r\nIf you enable this policy setting, you can choose from three options for configuring external S/MIME clients:\r\n\r\n- Handle internally. Outlook decrypts all S/MIME messages itself.\r\n- Handle externally. Outlook hands all S/MIME messages off to the configured external program.\r\n- Handle if possible. Outlook attempts to decrypt all S/MIME messages itself. If it cannot decrypt a message, Outlook hands the message off to the configured external program. This option is the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of selecting Enabled – Handle if possible.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients_l_behaviorforhandlingsmimemessages","displayName":"Behavior for handling S/MIME messages: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients_l_behaviorforhandlingsmimemessages_0","displayName":"Handle internally","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients_l_behaviorforhandlingsmimemessages_1","displayName":"Handle externally","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeinteroperabilitywithexternalclients_l_behaviorforhandlingsmimemessages_2","displayName":"Handle if possible","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests","displayName":"S/MIME receipt requests behavior (User)","description":"This policy setting controls how Outlook handles S/MIME receipt requests.\r\n\r\nIf you enable this policy setting, you can choose from four options for handling S/MIME receipt requests in Outlook:\r\n\r\n- Open message if receipt can't be sent\r\n- Don't open message if receipt can't be sent\r\n- Always prompt before sending receipt\r\n- Never send S/MIME receipts\r\n\r\nIf you disable or do not configure this policy setting, when users open messages with attached receipt requests, Outlook prompts them to decide whether to send a receipt to the sender with information about the identity of the user who opened the message and the time it was opened. If Outlook cannot send the receipt, the user is still allowed to open the message.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_l_handlemessageswithsmimereceiptrequestsinthefollowingmanner","displayName":"Handle messages with S/MIME receipt requests in the following manner: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_l_handlemessageswithsmimereceiptrequestsinthefollowingmanner_0","displayName":"Open message if receipt can't be sent","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_l_handlemessageswithsmimereceiptrequestsinthefollowingmanner_3","displayName":"Don't open message if receipt can't be sent","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_l_handlemessageswithsmimereceiptrequestsinthefollowingmanner_1","displayName":"Always prompt before sending receipt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimereceiptrequests_l_handlemessageswithsmimereceiptrequestsinthefollowingmanner_2","displayName":"Never send S/MIME receipts","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeuseissuerserialnumber","displayName":"Use UserIssuerSerialNumber (User)","description":"This policy setting determines whether Outlook uses IssuerSerialNumber as the SignerIdentifier, which enables third-party email client software applications to read encrypted Outlook email messages. For more information about Cryptographic Message Syntax, refer to the RFC 5652 specification.\r\n\r\nIf you enable or do not configure this policy setting, Outlook uses the IssuerSerialNumber as the SignerIdentifier.\r\n\r\nIf you disable this policy setting, Outlook uses SubjectKeyIdentifier for the SignerIdentifier, which might prevent third-party email client software applications from reading encrypted Outlook email messages.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeuseissuerserialnumber_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeuseissuerserialnumber_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_urlforsmimecertificates","displayName":"URL for S/MIME certificates (User)","description":"This policy setting provides a URL at which Outlook users can obtain S/MIME certificates. \r\n\r\nIf you enable this policy setting, you can enter a URL from which users can obtain S/MIME certificates. The URL can contain three variables, %1, %2, and %3, which will be replaced by the user's name, e-mail address, and language, respectively. When users click \"Get a Digital ID\", they will be directed to the supplied URL. \r\n\r\nIf you disable or do not configure this policy setting, a URL for S/MIME certificates is not provided.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_urlforsmimecertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_urlforsmimecertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_urlforsmimecertificates_l_enterurl","displayName":"Enter URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_attachmentsecuretemporaryfolder","displayName":"Attachment Secure Temporary Folder (User)","description":"This policy setting allows you to specify a folder path for the Secure Temporary Files folder rather than using the one that is randomly generated by Outlook. \r\n\r\nIf you enable this policy setting, you can specify a folder path for the Security Temporary Files folder rather than using the one that is randomly generated by Outlook. \r\n\r\nIf you disable or do not configure this policy setting, Outlook will assign the Secure Temporary Files folder a different random name for each user. \r\n\r\nImportant - If you must use a specific folder for Outlook attachments, Microsoft recommends that you use a local directory (for best performance), that you place the folder under the Temporary Internet Files folder (to benefit from the enhanced security on that folder), and that the folder name is unique and difficult to guess.","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_attachmentsecuretemporaryfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_attachmentsecuretemporaryfolder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_attachmentsecuretemporaryfolder_l_enterthesecurefolderpath","displayName":"Enter the Secure Folder path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls","displayName":"Missing CRLs (User)","description":"This policy setting controls whether Outlook considers a missing certificate revocation list (CRL) a warning or an error. Digital certificates contain an attribute that shows where the corresponding CRL is located. CRLs contain lists of digital certificates that have been revoked by their controlling certification authorities (CAs), typically because the certificates were issued improperly or their associated private keys were compromised. If a CRL is missing or unavailable, Outlook cannot determine whether a certificate has been revoked. Therefore, an improperly issued certificate or one that has been compromised might be used to gain access to data. \r\n\r\nIf you enable this policy setting, you can choose between two options that determine how Outlook functions when a CRL is missing: \r\n\r\n- Warning. This option is the default configuration in Outlook and ensures that Outlook displays a warning message when a CRL is missing. \r\n\r\n- Error. This option ensures that Outlook displays an error message when a CRL is missing. \r\n\r\nIf you disable or do not configure this policy setting, Outlook displays a warning message when a CRL is not available.","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_l_indicateamissingcrlasan","displayName":"Indicate a missing CRL as a(n): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_l_indicateamissingcrlasan_0","displayName":"Warning","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_l_indicateamissingcrlasan_1","displayName":"Error","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates","displayName":"Missing root certificates (User)","description":"This policy setting controls how Outlook functions when a root certificate is missing. \r\n\r\nIf you enable this policy setting, you can choose from three options that determine how Outlook functions when a root certificate is missing. \r\n\r\n- Neither Error nor Warning. This option displays neither an error nor a warning, and enforces the default configuration in Outlook.\r\n- Warning. This option ensures that Outlook displays a warning message when a root certificate is missing. \r\n- Error. This option ensures that Outlook displays an error message when a root certificate is missing. \r\n\r\nIf you don't configure this policy setting, users will see an error when a root certificate is missing.","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan","displayName":"Indicate a missing root certificate as a(n): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan_0","displayName":"Neither error nor warning","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan_1","displayName":"Warning","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan_2","displayName":"Error","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_promotingerrorsaswarnings","displayName":"Promote Level 2 errors as errors, not warnings (User)","description":"This policy setting allows you to treat Level 2 errors as warnings instead of errors. Level 2 errors occur when the message signature appears to be valid, but there are other issues with the signature. \r\n\r\nIf you enable this policy setting, Level 2 errors will be treated as warnings.\r\n\r\nIf you disable or do not configure this policy setting, Level 2 errors will be treated as errors\r\n\r\nWhen you specify a value for PromoteErrorsAsWarnings, note that potential Level 2 error conditions include the following:\r\n\r\n- Unknown Signature Algorithm\r\n- No Signing Certification Found\r\n- Bad Attribute Sets\r\n- No Issuer Certificate found\r\n- No CRL Found\r\n- Out-of-date CRL\r\n- Root Trust Problem\r\n- Out-of-date CTL","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_promotingerrorsaswarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_promotingerrorsaswarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists","displayName":"Retrieving CRLs (Certificate Revocation Lists) (User) (Deprecated)","description":"This policy setting controls how Outlook retrieves Certificate Revocation Lists to verify the validity of certificates.Certificate revocation lists (CRLs) are lists of digital certificates that have been revoked by their controlling certificate authorities (CAs), typically because the certificates were issued improperly or their associated private keys were compromised. \r\n\r\nIf you enable this policy setting, you can choose from three options to govern how Outlook uses CRLs: \r\n\r\n- Use system Default. Outlook relies on the CRL download schedule that is configured for the operating system. \r\n- When online always retrieve the CRL. This option is the default configuration in Outlook. \r\n- Never retrieve the CRL. Outlook will not attempt to download the CRL for a certificate, even if it is online. This option can reduce security. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook handles a certificate that includes a URL from which a CRL can be downloaded, Outlook will retrieve the CRL from the provided URL if Outlook is online.","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_l_empty31","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_l_empty31_0","displayName":"Use system Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_l_empty31_1","displayName":"When online always retreive the CRL","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_l_empty31_2","displayName":"Never retreive the CRL","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2","displayName":"Retrieving CRLs (Certificate Revocation Lists) (User)","description":"This policy setting controls how Outlook retrieves Certificate Revocation Lists to verify the validity of certificates.Certificate revocation lists (CRLs) are lists of digital certificates that have been revoked by their controlling certificate authorities (CAs), typically because the certificates were issued improperly or their associated private keys were compromised. \r\n\r\nIf you enable this policy setting, you can choose from three options to govern how Outlook uses CRLs: \r\n\r\n- Use system Default. Outlook relies on the CRL download schedule that is configured for the operating system. \r\n- When online always retrieve the CRL. This option is the default configuration in Outlook. \r\n- Never retrieve the CRL. Outlook will not attempt to download the CRL for a certificate, even if it is online. This option can reduce security. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook handles a certificate that includes a URL from which a CRL can be downloaded, Outlook will retrieve the CRL from the provided URL if Outlook is online.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2_l_empty31","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2_l_empty31_0","displayName":"Use system Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2_l_empty31_1","displayName":"When online always retreive the CRL","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_retrievingcrlscertificaterevocationlists_v2_l_empty31_2","displayName":"Never retreive the CRL","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode","displayName":"Outlook Security Mode (User)","description":"This policy setting controls which set of security settings are enforced in Outlook. \r\n\r\nIf you enable this policy setting, you can choose from four options for enforcing Outlook security settings: \r\n\r\n* Outlook Default Security - This option is the default configuration in Outlook. Users can configure security themselves, and Outlook ignores any security-related settings configured in Group Policy. \r\n\r\n* Use Security Form from 'Outlook Security Settings' Public Folder - Outlook uses the settings from the security form published in the designated public folder. \r\n\r\n* Use Security Form from 'Outlook 10 Security Settings' Public Folder - Outlook uses the settings from the security form published in the designated public folder. \r\n\r\n* Use Outlook Security Group Policy - Outlook uses security settings from Group Policy. \r\n\r\nImportant - You must enable this policy setting if you want to apply the other Outlook security policy settings mentioned in this guide. \r\n\r\nIf you disable or do not configure this policy setting, Outlook users can configure security for themselves, and Outlook ignores any security-related settings that are configured in Group Policy. \r\n\r\nNote - In previous versions of Outlook, when security settings were published in a form in Exchange Server public folders, users who needed these settings required the HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Security\\CheckAdminSettings registry key to be set on their computers for the settings to apply. In Outlook, the CheckAdminSettings registry key is no longer used to determine users' security settings. Instead, the Outlook Security Mode setting can be used to determine whether Outlook security should be controlled directly by Group Policy, by the security form from the Outlook Security Settings Public Folder, or by the settings on users' own computers.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_l_outlooksecuritypolicy","displayName":"Outlook Security Policy: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_l_outlooksecuritypolicy_0","displayName":"Outlook Default Security","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_l_outlooksecuritypolicy_1","displayName":"Use Security Form from 'Outlook Security Settings' Public Folder","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_l_outlooksecuritypolicy_2","displayName":"Use Security Form from 'Outlook 10 Security Settings' Public Folder","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings_l_outlooksecuritymode_l_outlooksecuritypolicy_3","displayName":"Use Outlook Security Group Policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments","displayName":"Allow users to demote attachments to Level 2 (User) (Deprecated)","description":"This policy setting controls whether Outlook users can demote attachments to Level 2 by using a registry key, which will allow them to save files to disk and open them from that location. Outlook uses two levels of security to restrict access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, users can create a list of Level 1 file types to demote to Level 2 by adding the file types to the following registry key: HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Security\\Level1Remove. \r\n\r\nIf you disable or do not configure this policy setting, users cannot demote level 1 attachments to level 2, and the HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Security\\Level1Remove registry key has no effect.\r\n","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_v2","displayName":"Allow users to demote attachments to Level 2 (User)","description":"This policy setting controls whether Outlook users can demote attachments to Level 2 by using a registry key, which will allow them to save files to disk and open them from that location. Outlook uses two levels of security to restrict access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, users can create a list of Level 1 file types to demote to Level 2 by adding the file types to the following registry key: HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Security\\Level1Remove. \r\n\r\nIf you disable or do not configure this policy setting, users cannot demote level 1 attachments to level 2, and the HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Security\\Level1Remove registry key has no effect.\r\n","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1addfilepolicy","displayName":"Add file extensions to block as Level 1 (User)","description":"This policy setting controls which types of attachments (determined by file extension) Outlook prevents from being delivered. \r\n\r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify additional file type extensions as Level 1--that is, to be blocked from delivery--by entering them in the text field provided separated by semicolons. \r\n\r\nIf you disable or do not configure this policy setting, Outlook classifies a number of potentially harmful file types (such as those with .exe, .reg, and .vbs extensions) as Level 1 and blocks files with those extensions from being delivered. Important: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1addfilepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1addfilepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1addfilepolicy_l_additionalextensions","displayName":"Additional Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments","displayName":"Display Level 1 attachments (User) (Deprecated)","description":"This policy setting controls whether Outlook blocks potentially dangerous attachments designated Level 1. \r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n \r\nIf you enable this policy setting, Outlook users can gain access to Level 1 file type attachments by first saving the attachments to disk and then opening them, as with Level 2 attachments. \r\n\r\nIf you disable this policy setting, Level 1 attachments do not display under any circumstances. \r\n\r\nIf you do not configure this policy setting, Outlook completely blocks access to Level 1 files, and requires users to save Level 2 files to disk before opening them.","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_v2","displayName":"Display Level 1 attachments (User)","description":"This policy setting controls whether Outlook blocks potentially dangerous attachments designated Level 1. \r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n \r\nIf you enable this policy setting, Outlook users can gain access to Level 1 file type attachments by first saving the attachments to disk and then opening them, as with Level 2 attachments. \r\n\r\nIf you disable this policy setting, Level 1 attachments do not display under any circumstances. \r\n\r\nIf you do not configure this policy setting, Outlook completely blocks access to Level 1 files, and requires users to save Level 2 files to disk before opening them.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy","displayName":"Remove file extensions blocked as Level 1 (User) (Deprecated)","description":"This policy setting controls which types of attachments (determined by file extension) Outlook prevents from being delivered. \r\n\r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify the removal of file type extensions as that Outlook classifies as Level 1--that is, to be blocked from delivery--by entering them in the text field provided separated by semicolons. \r\n\r\nIf you disable or do not configure this policy setting, Outlook classifies a number of potentially harmful file types (such as those with .exe, .reg, and .vbs extensions) as Level 1 and blocks files with those extensions from being delivered. \r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_l_removedextensions","displayName":"Removed Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_v2","displayName":"Remove file extensions blocked as Level 1 (User)","description":"This policy setting controls which types of attachments (determined by file extension) Outlook prevents from being delivered. \r\n\r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify the removal of file type extensions as that Outlook classifies as Level 1--that is, to be blocked from delivery--by entering them in the text field provided separated by semicolons. \r\n\r\nIf you disable or do not configure this policy setting, Outlook classifies a number of potentially harmful file types (such as those with .exe, .reg, and .vbs extensions) as Level 1 and blocks files with those extensions from being delivered. \r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_v2_l_removedextensions","displayName":"Removed Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2addfilepolicy","displayName":"Add file extensions to block as Level 2 (User)","description":"This policy setting controls which types of attachments (determined by file extension) must be saved to disk before users can open them. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify a list of attachment file types to classify as Level 2, which forces users to actively decide to download the attachment to view it. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not classify any file type extensions as Level 2. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2addfilepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2addfilepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2addfilepolicy_l_additionalextensions23","displayName":"Additional Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy","displayName":"Remove file extensions blocked as Level 2 (User) (Deprecated)","description":"This policy setting controls which types of attachments (determined by file extension) must be saved to disk before users can open them. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify a list of attachment file types to classify as Level 2, which forces users to actively decide to download the attachment to view it. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not classify any file type extensions as Level 2. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_l_removedextensions25","displayName":"Removed Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_v2","displayName":"Remove file extensions blocked as Level 2 (User)","description":"This policy setting controls which types of attachments (determined by file extension) must be saved to disk before users can open them. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify a list of attachment file types to classify as Level 2, which forces users to actively decide to download the attachment to view it. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not classify any file type extensions as Level 2. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_v2_l_removedextensions25","displayName":"Removed Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_nopromptlevel1close","displayName":"Do not prompt about Level 1 attachments when closing an item (User)","description":"This policy setting controls whether Outlook displays a warning before closing an item that contains an unsafe attachment that will be blocked when the item is re-opened.To protect users from viruses and other harmful files, Outlook uses two levels of security, designated Level 1 and Level 2, to restrict users' access to files attached to e-mail messages or other items. Outlook completely blocks access to Level 1 files by default, and requires users to save Level 2 files to disk before opening them. Potentially harmful files can be classified into these two levels by file type extension, with all other file types considered safe. \r\n\r\nIf you enable this policy setting, Outlook will not display a warning when users close items with Level 1 attachments, which could cause data loss. \r\n\r\nIf you disable or do not configure this policy setting, when a user closes an item to which a level 1 file has been attached, Outlook warns the user that the message contains a potentially unsafe attachment and that the user might not be able to access the attachment when opening the item later. (Such a sequence of events might occur when a user closes a draft message that they intend to resume editing at some future time.) \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_nopromptlevel1close_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_nopromptlevel1close_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_nopromptlevel1send","displayName":"Do not prompt about Level 1 attachments when sending an item (User)","description":"This policy setting controls whether Outlook displays a warning before sending an item that contains an unsafe attachment that will be blocked when the item is opened by a recipient. To protect users from viruses and other harmful files, Outlook uses two levels of security, designated Level 1 and Level 2, to restrict access to files attached to e-mail messages or other items. Outlook completely blocks access to Level 1 files by default, and requires users to save Level 2 files to disk before opening them. Potentially harmful files can be classified into these two levels by file type extension, with all other file types considered safe. \r\n\r\nIf you enable this policy setting, Outlook will not display a warning when a user sends an item with a Level 1 attachment, which can cause users' data to be at risk.\r\n\r\nIf you disable or do not configure this policy setting, when users attempt to send an item to which a level 1 file has been attached, Outlook warns them that the message contains a potentially unsafe attachment and that the recipient might not be able to access it. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_nopromptlevel1send_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_nopromptlevel1send_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_showolepackageobj","displayName":"Display OLE package objects (User)","description":"By default, OLE package objects are not displayed in e-mail messages. You can change this behavior so that the package appears in the body of the e-mail message as an icon that represents an embedded or linked OLE object. When users double-click the icon representing the package, the program used to create the object either plays the object or opens and displays it. Be aware that the icon for OLE package objects can be easily changed and used to disguise malicious files.\r\n\r\nTo set Exchange Security Form settings by using Group Policy, note that this policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_showolepackageobj_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_showolepackageobj_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms","displayName":"Allow scripts in one-off Outlook forms (User) (Deprecated)","description":"This policy setting controls whether scripts can run in Outlook forms in which the script and layout are contained within the message. \r\n\r\nIf you enable this policy setting, scripts can run in one-off Outlook forms. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not run scripts in forms in which the script and the layout are contained within the message. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"e11f4bd4-9041-49c9-9b8c-163827d606ce","categoryName":"Custom Form Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_v2","displayName":"Allow scripts in one-off Outlook forms (User)","description":"This policy setting controls whether scripts can run in Outlook forms in which the script and layout are contained within the message. \r\n\r\nIf you enable this policy setting, scripts can run in one-off Outlook forms. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not run scripts in forms in which the script and the layout are contained within the message. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom","displayName":"Set Outlook object model custom actions execution prompt (User) (Deprecated)","description":"This policy setting controls whether Outlook prompts users before executing a custom action. Custom actions add functionality to Outlook that can be triggered as part of a rule. Among other possible features, custom actions can be created that reply to messages in ways that circumvent the Outlook model's programmatic send protections. \r\n\r\nIf you enable this policy setting, you can choose from four options to control how Outlook functions when a custom action is executed that uses the Outlook object model: \r\n\r\n* Prompt User \r\n* Automatically Approve \r\n* Automatically Deny \r\n* Prompt user based on computer security. This option enforces the default configuration in Outlook. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook or another program initiates a custom action using the Outlook object model, users are prompted to allow or reject the action. If this configuration is changed, malicious code can use the Outlook object model to compromise sensitive information or otherwise cause data and computing resources to be at risk. This is the equivalent of choosing Enabled -- Prompt user based on computer security.","helpText":"","infoUrls":[],"categoryId":"e11f4bd4-9041-49c9-9b8c-163827d606ce","categoryName":"Custom Form Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_l_onexecutecustomactionoom_setting","displayName":"When executing a custom action: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e11f4bd4-9041-49c9-9b8c-163827d606ce","categoryName":"Custom Form Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_l_onexecutecustomactionoom_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_l_onexecutecustomactionoom_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_l_onexecutecustomactionoom_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_l_onexecutecustomactionoom_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2","displayName":"Set Outlook object model custom actions execution prompt (User)","description":"This policy setting controls whether Outlook prompts users before executing a custom action. Custom actions add functionality to Outlook that can be triggered as part of a rule. Among other possible features, custom actions can be created that reply to messages in ways that circumvent the Outlook model's programmatic send protections. \r\n\r\nIf you enable this policy setting, you can choose from four options to control how Outlook functions when a custom action is executed that uses the Outlook object model: \r\n\r\n* Prompt User \r\n* Automatically Approve \r\n* Automatically Deny \r\n* Prompt user based on computer security. This option enforces the default configuration in Outlook. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook or another program initiates a custom action using the Outlook object model, users are prompted to allow or reject the action. If this configuration is changed, malicious code can use the Outlook object model to compromise sensitive information or otherwise cause data and computing resources to be at risk. This is the equivalent of choosing Enabled -- Prompt user based on computer security.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_l_onexecutecustomactionoom_setting","displayName":"When executing a custom action: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_l_onexecutecustomactionoom_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_l_onexecutecustomactionoom_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_l_onexecutecustomactionoom_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_l_onexecutecustomactionoom_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess","displayName":"Configure Outlook object model prompt when reading address information (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to gain access to a recipient field, such as the ''To:'' field, using the Outlook object model.\r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to access a recipient field using the Outlook object model:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt.\r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended.\r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. This is the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to access recipient fields, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_l_oomaddressaccess_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_l_oomaddressaccess_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_l_oomaddressaccess_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_l_oomaddressaccess_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_l_oomaddressaccess_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2","displayName":"Configure Outlook object model prompt when reading address information (User)","description":"This policy setting controls what happens when an untrusted program attempts to gain access to a recipient field, such as the ''To:'' field, using the Outlook object model.\r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to access a recipient field using the Outlook object model:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt.\r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended.\r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. This is the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to access recipient fields, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook","displayName":"Configure Outlook object model prompt when accessing an address book (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to gain access to an Address Book using the Outlook object model. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to programmatically access an Address Book using the Outlook object model:\r\n\r\n- Prompt user - Users are prompted to approve every access attempt. \r\n- Automatically approve - Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny - Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security - Outlook will rely on the setting in the ''Programmatic Access'' section of the Trust Center. This is the default behavior.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to access the address book programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_l_oomaddressbook_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_l_oomaddressbook_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_l_oomaddressbook_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_l_oomaddressbook_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_l_oomaddressbook_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2","displayName":"Configure Outlook object model prompt when accessing an address book (User)","description":"This policy setting controls what happens when an untrusted program attempts to gain access to an Address Book using the Outlook object model. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to programmatically access an Address Book using the Outlook object model:\r\n\r\n- Prompt user - Users are prompted to approve every access attempt. \r\n- Automatically approve - Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny - Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security - Outlook will rely on the setting in the ''Programmatic Access'' section of the Trust Center. This is the default behavior.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to access the address book programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula","displayName":"Configure Outlook object model prompt When accessing the Formula property of a UserProperty object (User) (Deprecated)","description":"This policy setting controls what happens when a user designs a custom form in Outlook and attempts to bind an Address Information field to a combination or formula custom field.\r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to access address information using the UserProperties. Find method of the Outlook object model: \r\n\r\n- Prompt user. The user will be prompted to approve every access attempt. \r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. \r\n\r\nIf you disable or do not configure this policy setting, when a user tries to bind an address information field to a combination or formula custom field in a custom form, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_l_oomformula_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_l_oomformula_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_l_oomformula_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_l_oomformula_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_l_oomformula_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2","displayName":"Configure Outlook object model prompt When accessing the Formula property of a UserProperty object (User)","description":"This policy setting controls what happens when a user designs a custom form in Outlook and attempts to bind an Address Information field to a combination or formula custom field.\r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to access address information using the UserProperties. Find method of the Outlook object model: \r\n\r\n- Prompt user. The user will be prompted to approve every access attempt. \r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. \r\n\r\nIf you disable or do not configure this policy setting, when a user tries to bind an address information field to a combination or formula custom field in a custom form, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_l_oomformula_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_l_oomformula_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_l_oomformula_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_l_oomformula_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_l_oomformula_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest","displayName":"Configure Outlook object model prompt when responding to meeting and task requests (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to programmatically send e-mail in Outlook using the Response method of a task or meeting request. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to programmatically send e-mail using the Response method of a task or meeting request:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt.\r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended.\r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook only prompts users when antivirus software is out of date or not running. This is the default configuration. \r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to respond to tasks or meeting requests programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_l_oommeetingtaskrequest_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_l_oommeetingtaskrequest_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_l_oommeetingtaskrequest_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_l_oommeetingtaskrequest_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_l_oommeetingtaskrequest_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2","displayName":"Configure Outlook object model prompt when responding to meeting and task requests (User)","description":"This policy setting controls what happens when an untrusted program attempts to programmatically send e-mail in Outlook using the Response method of a task or meeting request. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to programmatically send e-mail using the Response method of a task or meeting request:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt.\r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended.\r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook only prompts users when antivirus software is out of date or not running. This is the default configuration. \r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to respond to tasks or meeting requests programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas","displayName":"Configure Outlook object model prompt when executing Save As (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to use the Save As command to programmatically save an item. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to use the Save As command to programmatically save an item:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt. \r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. This is the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to use the Save As command, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_l_oomsaveas_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_l_oomsaveas_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_l_oomsaveas_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_l_oomsaveas_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_l_oomsaveas_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2","displayName":"Configure Outlook object model prompt when executing Save As (User)","description":"This policy setting controls what happens when an untrusted program attempts to use the Save As command to programmatically save an item. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to use the Save As command to programmatically save an item:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt. \r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. This is the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to use the Save As command, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend","displayName":"Configure Outlook object model prompt when sending mail (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to send e-mail programmatically using the Outlook object model. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to send e-mail programmatically using the Outlook object model: \r\n\r\n- Prompt user - The user will be prompted to approve every access attempt.\r\n- Automatically approve - Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny - Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. \r\n\r\nImportant: This policy setting only applies if the ''Outlook Security Mode'' policy setting under ''Microsoft Outlook 2016\\Security\\Security Form Settings'' is configured to ''Use Outlook Security Group Policy.''\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to send mail programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_l_oomsend_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_l_oomsend_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_l_oomsend_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_l_oomsend_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_l_oomsend_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2","displayName":"Configure Outlook object model prompt when sending mail (User)","description":"This policy setting controls what happens when an untrusted program attempts to send e-mail programmatically using the Outlook object model. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to send e-mail programmatically using the Outlook object model: \r\n\r\n- Prompt user - The user will be prompted to approve every access attempt.\r\n- Automatically approve - Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny - Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. \r\n\r\nImportant: This policy setting only applies if the ''Outlook Security Mode'' policy setting under ''Microsoft Outlook 2016\\Security\\Security Form Settings'' is configured to ''Use Outlook Security Group Policy.''\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to send mail programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_l_oomsend_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_l_oomsend_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_l_oomsend_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_l_oomsend_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_v2_l_oomsend_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve","displayName":"Configure Simple MAPI name resolution prompt (User)","description":"This policy setting allows you to specify what occurs when a program attempts to gain access to an Address Book, using Simple MAPI.\r\n\r\nIf you enable this policy setting, you can choose whether Outlook always allows access to the Address Book, always disallows access to the Address Book, or prompts the user to specify whether to allow or disallow access to the Address Book.\r\n\r\nIf you disable or do not configure this policy setting, Outlook prompts the user to specify whether to allow or disallow access to the Address Book.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_l_simplemapi_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_l_simplemapi_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_l_simplemapi_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_l_simplemapi_setting_0","displayName":"Automatically Deny","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage","displayName":"Configure Simple MAPI message opening prompt (User)","description":"This policy setting allows you to specify what occurs when a program attempts to gain access to a recipient field, such as the “To” field, using Simple MAPI.\r\n\r\nIf you enable this policy setting, you can choose whether Outlook always allows access to the recipient field, always disallows access to the recipient field, or prompt users to specify whether to allow or disallow access to the recipient field.\r\n\r\nIf you disable or do not configure this policy setting, Outlook prompts users to specify whether to allow or disallow access to the Address Book.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting_0","displayName":"Automatically Deny","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend","displayName":"Configure Simple MAPI sending prompt (User)","description":"This policy setting allows you to specify what occurs when a program attempts to send mail programmatically, using Simple MAPI.\r\n\r\nIf you enable this policy setting, you can choose whether Outlook always allows sending mail, always disables sending mail, or prompts users to specify whether to allow or disallow sending mail.\r\n\r\nIf you disable or do not configure this policy setting, Outlook prompts users to specify whether to allow or disallow sending the mail.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend_l_simplemapi_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend_l_simplemapi_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend_l_simplemapi_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapisend_l_simplemapi_setting_0","displayName":"Automatically Deny","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins","displayName":"Configure trusted add-ins (User)","description":"This policy setting can be used to specify a list of trusted add-ins that can be run without being restricted by the security measures in Outlook.\r\n\r\nIf you enable this policy setting, a list of trusted add-ins and hashes is made available that you can modify by adding and removing entries. The list is empty by default. To create a new entry, enter a DLL file name in the ''Value Name'' column and the hash result in the ''Value'' column. \r\n\r\nIf you disable or do not configure this policy setting, the list of trusted add-ins is empty and unused, so the recommended EC and SSLF settings do not create any usability issues. However, users who rely on add-ins that access the Outlook object model might be repeatedly prompted unless administrators enable this setting and add the add-ins to the list.\r\n\r\nNote - You can also configure Exchange Security Form settings by enabling the ''Outlook Security Mode'' setting in User Configuration\\Administrative Templates\\Microsoft Outlook 2016\\Security\\Security Form Settings\\Microsoft Outlook 2016 Security and selecting ''Use Outlook Security Group Policy'' from the drop-down list.","helpText":"","infoUrls":[],"categoryId":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","categoryName":"Trusted Add-ins","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins_l_listoftrustedaddins","displayName":"List of trusted add-ins and hashes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","categoryName":"Trusted Add-ins","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins_l_listoftrustedaddins_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","categoryName":"Trusted Add-ins","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins_l_listoftrustedaddins_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","categoryName":"Trusted Add-ins","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_applymacrosecuritysettings","displayName":"Apply macro security settings to macros, add-ins and additional actions (User)","description":"This policy setting controls whether Outlook also applies the macro security settings to installed COM add-ins and additional actions. \r\n\r\nIf you enable this policy setting, the macro security settings will also be applied to add-ins and additional actions. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not use the macro security settings to determine whether to run macros, installed COM add-ins, and additional actions.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_applymacrosecuritysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_applymacrosecuritysettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_enablelinksinemailmessages","displayName":"Allow hyperlinks in suspected phishing e-mail messages (User) (Deprecated)","description":"This policy setting controls whether hyperlinks in suspected phishing e-mail messages in Outlook are allowed. \r\n\r\nIf you enable this policy setting, Outlook will allow hyperlinks in suspected phishing messages that are not also classified as junk e-mail. \r\n\r\nIf you disable or do not configure this policy setting, Outlook will not allow hyperlinks in suspected phishing messages, even if they are not classified as junk e-mail.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_enablelinksinemailmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_enablelinksinemailmessages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_enablelinksinemailmessages_v2","displayName":"Allow hyperlinks in suspected phishing e-mail messages (User)","description":"This policy setting controls whether hyperlinks in suspected phishing e-mail messages in Outlook are allowed. \r\n\r\nIf you enable this policy setting, Outlook will allow hyperlinks in suspected phishing messages that are not also classified as junk e-mail. \r\n\r\nIf you disable or do not configure this policy setting, Outlook will not allow hyperlinks in suspected phishing messages, even if they are not classified as junk e-mail.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_enablelinksinemailmessages_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_enablelinksinemailmessages_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_onsendaddinsenabled","displayName":"Disable send when web extensions can’t load. (User)","description":"If you enable this policy setting, Outlook won’t allow email and meeting requests to be sent until web add-ins are loaded from Exchange.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_onsendaddinsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_onsendaddinsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationalertthreshold","displayName":"Specify activation disabling threshold for web extensions (User)","description":"This policy setting allows you to specify the threshold that Outlook refers to before disabling a web extension during activation. \r\n\r\nIf you enable this policy setting, you can specify a threshold (in milliseconds) for the activation manager retry limit during an Outlook session. If the web extension requires more than the specified threshold for the number of occurrences specified by the activation manager retry limit during an Outlook session, Outlook disables the web extension. \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default activation alert threshold of 1000 milliseconds. The maximum activation alert threshold is 10000 milliseconds, and the minimum activation alert threshold is 100 milliseconds.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationalertthreshold_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationalertthreshold_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationalertthreshold_l_outlookactivationalertthresholdspinid","displayName":"(100 - 10000 milliseconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationmanagerretrylimit","displayName":"Specify activation manager retry limit for web extensions (User)","description":"This policy setting allows you to specify the retry limit Outlook uses before disabling a web extension during activation.\r\n\r\nIf you enable this policy setting, you can specify the activation manager retry limit. If the web extension requires more than the specified activation alert threshold for the number of occurrences specified by the activation manager retry limit during an Outlook session, Outlook automatically disables the web extension. \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default activation manager retry limit of 3 occurrences. The maximum activation manager retry limit is 5 occurrences, and the minimum activation manager retry limit is 1 occurrence.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationmanagerretrylimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationmanagerretrylimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookactivationmanagerretrylimit_l_outlookactivationmanagerretrylimitspinid","displayName":"(1 - 5 occurrences) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval","displayName":"Specify alert interval for web extensions (User)","description":"This policy setting allows you to specify the alert interval Outlook uses before disabling a web extension during initialization. The alert interval controls how often Office checks on memory and CPU usage for a running web extension. \r\n\r\nIf you enable this policy setting, you can specify the alert interval for web extensions. If the web extension requires more than the specified memory alert threshold when the memory or CPU check occurs, Outlook disables the web extension. \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default alert interval of 5 seconds. This alert interval overrides the WEF alert interval. The maximum alert interval is 600 seconds, and the minimum alert interval is 5 seconds.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval_l_outlookalertintervalspinid","displayName":"(5 - 600 seconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookmemoryalertthreshold","displayName":"Specify Outlook memory alert threshold for web extensions (User)","description":"This policy setting allows you to specify the memory usage limit Outlook uses before disabling a web extension during initialization. The memory alert threshold controls the maximum amount of virtual memory that can be used by a running web extension.\r\n\r\nIf you enable this policy setting, you can specify the memory alert threshold for web extensions. If the web extension requires more than the specified memory alert threshold when a memory or CPU check occurs, Outlook disables the web extension.\r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default memory usage limit of 1500 MB. This memory alert threshold overrides the WEF memory alert threshold. The maximum memory alert threshold is 1500 MB, and the minimum memory alert threshold is 1 MB.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookmemoryalertthreshold_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookmemoryalertthreshold_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookmemoryalertthreshold_l_outlookmemoryalertthresholdspinid","displayName":"(1 - 1500 MB) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookrestartmanagerretrylimit","displayName":"Specify the number of restarts attempted for a running web extension (User)","description":"This policy setting allows you to specify the number of restarts Outlook attempts for a running web extension.\r\n\r\nIf you enable this policy setting, you can specify the number of restarts Outlook attempts for a running web extension. If the web extension requires more than the specified number of restarts during an Outlook session, Outlook disables the web extension.\r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default restart limit of 3 occurrences. The maximum restart limit is 10 occurrences, and the minimum restart limit is 1 occurrence.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookrestartmanagerretrylimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookrestartmanagerretrylimit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookrestartmanagerretrylimit_l_outlookrestartmanagerretrylimitspinid","displayName":"(1 - 10 occurrences) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook","displayName":"Security setting for macros (User) (Deprecated)","description":"This policy setting controls the security level for macros in Outlook. \r\n\r\nIf you enable this policy setting, you can choose from four options for handling macros in Outlook: \r\n\r\n- Always warn. This option corresponds to the \"Warnings for all macros\" option in the \"Macro Security\" section of the Outlook Trust Center. Outlook disables all macros that are not opened from a trusted location, even if the macros are signed by a trusted publisher. For each disabled macro, Outlook displays a security alert dialog box with information about the macro and its digital signature (if present), and allows users to enable the macro or leave it disabled. \r\n\r\n- Never warn, disable all. This option corresponds to the \"No warnings and disable all macros\" option in the Trust Center. Outlook disables all macros that are not opened from trusted locations, and does not notify users. \r\n\r\n- Warning for signed, disable unsigned. This option corresponds to the \"Warnings for signed macros; all unsigned macros are disabled\" option in the Trust Center. Outlook handles macros as follows: \r\n\r\n--If a macro is digitally signed by a trusted publisher, the macro can run if the user has already trusted the publisher. \r\n\r\n--If a macro has a valid signature from a publisher that the user has not trusted, the security alert dialog box for the macro lets the user choose whether to enable the macro for the current session, disable the macro for the current session, or to add the publisher to the Trusted Publishers list so that it will run without prompting the user in the future. \r\n\r\n--If a macro does not have a valid signature, Outlook disables it without prompting the user, unless it is opened from a trusted location. \r\n\r\nThis option is the default configuration in Outlook. \r\n\r\n- No security check. This option corresponds to the \"No security check for macros (Not recommended)\" option in the Trust Center. Outlook runs all macros without prompting users. This configuration makes users' computers vulnerable to potentially malicious code and is not recommended. \r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of Enabled -- Warning for signed, disable unsigned.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel","displayName":"Security Level (User) (Deprecated)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_2","displayName":"Always warn","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_4","displayName":"Never warn, disable all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_3","displayName":"Warn for signed, disable unsigned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_1","displayName":"No security check","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2","displayName":"Security setting for macros (User)","description":"This policy setting controls the security level for macros in Outlook. \r\n\r\nIf you enable this policy setting, you can choose from four options for handling macros in Outlook: \r\n\r\n- Always warn. This option corresponds to the \"Warnings for all macros\" option in the \"Macro Security\" section of the Outlook Trust Center. Outlook disables all macros that are not opened from a trusted location, even if the macros are signed by a trusted publisher. For each disabled macro, Outlook displays a security alert dialog box with information about the macro and its digital signature (if present), and allows users to enable the macro or leave it disabled. \r\n\r\n- Never warn, disable all. This option corresponds to the \"No warnings and disable all macros\" option in the Trust Center. Outlook disables all macros that are not opened from trusted locations, and does not notify users. \r\n\r\n- Warning for signed, disable unsigned. This option corresponds to the \"Warnings for signed macros; all unsigned macros are disabled\" option in the Trust Center. Outlook handles macros as follows: \r\n\r\n--If a macro is digitally signed by a trusted publisher, the macro can run if the user has already trusted the publisher. \r\n\r\n--If a macro has a valid signature from a publisher that the user has not trusted, the security alert dialog box for the macro lets the user choose whether to enable the macro for the current session, disable the macro for the current session, or to add the publisher to the Trusted Publishers list so that it will run without prompting the user in the future. \r\n\r\n--If a macro does not have a valid signature, Outlook disables it without prompting the user, unless it is opened from a trusted location. \r\n\r\nThis option is the default configuration in Outlook. \r\n\r\n- No security check. This option corresponds to the \"No security check for macros (Not recommended)\" option in the Trust Center. Outlook runs all macros without prompting users. This configuration makes users' computers vulnerable to potentially malicious code and is not recommended. \r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of Enabled -- Warning for signed, disable unsigned.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel","displayName":"Security Level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_2","displayName":"Always warn","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_4","displayName":"Never warn, disable all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_3","displayName":"Warn for signed, disable unsigned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_1","displayName":"No security check","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_preventsavingcredentialsforbasicauthenticationpolicy","displayName":"Prevent saving credentials for Basic Authentication policy (User)","description":"This policy setting allows you to prevent Outlook from saving user credentials using Basic Authentication.\r\n\r\nIf you enable this policy setting, Outlook will not save user credentials using Basic Authentication.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will allow the user to save credentials when using Basic Authentication against a server. These credentials are stored as generic and retrievable by any process running with that user's rights on the machine.","helpText":"","infoUrls":[],"categoryId":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_preventsavingcredentialsforbasicauthenticationpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_preventsavingcredentialsforbasicauthenticationpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_specifyofflineaddressbookpath","displayName":"Specify Offline Address Book path (User)","description":"This policy setting allows you to specify a path to save the Offline Address Book. This policy setting will apply to all Microsoft Exchange accounts.\r\n\r\nIf you enable this policy setting, you may specify a path to save the Offline Address Book.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will save the Offline Address Book in %LOCALAPPDATA%\\Microsoft\\Outlook.","helpText":"","infoUrls":[],"categoryId":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_specifyofflineaddressbookpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_specifyofflineaddressbookpath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_specifyofflineaddressbookpath_l_specifyofflineaddressbookpathid","displayName":"Offline Address Book path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","categoryName":"E-mail","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency","displayName":"EAS Sync Frequency (User)","description":"This policy setting allows you to specify the number of minutes that Outlook automatically syncs the users' Exchange ActiveSync (EAS) accounts.\r\n\r\nIf you enable this policy setting, you can specify the number of minutes.\r\n\r\nIf you disable or do not configure this policy setting, Outlook automatically syncs the users’ EAS accounts every 59 minutes.","helpText":"","infoUrls":[],"categoryId":"b161cf66-abfa-4a36-a9ac-c20ca60594e0","categoryName":"Exchange ActiveSync","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency_l_eassyncfrequencyintervalspinid","displayName":"Synchronization interval (in minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b161cf66-abfa-4a36-a9ac-c20ca60594e0","categoryName":"Exchange ActiveSync","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_automaticallyconfigureprofilebasedonactive","displayName":"Automatically configure profile based on Active Directory Primary SMTP address (User)","description":"Automatically configure only the first profile based on Active Directory primary SMTP address\r\n\r\nThis policy setting controls whether users who are joined to a domain in an Active Directory environment can change the primary SMTP address that is used when they set up an account in Outlook.\r\n\r\nIf this policy setting is enabled, users can enter a profile name to create a new profile without using the new account wizard. A user interface does not appear as the profile is created.\r\n\r\nThis key will be ignored after the first profile has been successfully created.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_automaticallyconfigureprofilebasedonactive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_automaticallyconfigureprofilebasedonactive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_automaticallyconfigureprofilebasedonactiveonce","displayName":"Automatically configure only the first profile based on Active Directory primary SMTP address (User)","description":"Automatically configure profile based on Active Directory Primary SMTP address once\r\n\r\nThis policy setting controls whether users who are joined to a domain in an Active Directory environment can change the primary SMTP address that is used when they set up accounts in Outlook.\r\n\r\nIf this policy setting is enabled, users can create a new profile by entering a profile name. The profile is created without using the New Account wizard. No user interface appears as the profile is created. \r\n\r\nThis key will be ignored after the first profile has been successfully created.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_automaticallyconfigureprofilebasedonactiveonce_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_automaticallyconfigureprofilebasedonactiveonce_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold","displayName":"Cached Exchange low bandwidth threshold (User)","description":"Specifies the bit rate threshold value. If the bit rate of the active network connection is below this value, Outlook identifies the network connection as a \"slow\" connection and operates accordingly (for example, downloading headers instead of full messages).","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold_l_enterthebitratekbps128k128thresholdtodetectlowbandwidth2","displayName":"(0 - 1,000,000 kbps) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablechangingfolderpermissions","displayName":"Do not allow users to change permissions on folders (User)","description":"This policy setting prevents users from changing their mail folder permissions. \r\n\r\nIf you enable this policy setting, Outlook users cannot change permissions on folders; the settings on the Permissions tab are disabled. Enabling this policy setting does not affect existing permissions, and users can still change permissions by sending a sharing message.\r\n\r\nIf you disable or do not configure this policy setting, Outlook users can change the permissions for folders under their control by using the Permissions tab of the Properties dialog box for the folder.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablechangingfolderpermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablechangingfolderpermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disableexchangeconsumeraccounts","displayName":"Prevent personal Microsoft accounts from using MAPI (User)","description":"This policy setting governs whether personal Microsoft accounts can be configured to use MAPI in Outlook.\r\n\r\nA personal Microsoft account is an account hosted on Outlook.com, Hotmail.com, Live.com, Msn.com or any variation on those domains.\r\n\r\nIf you enable this policy, users won’t be able to configure a personal Microsoft account to use MAPI in Outlook.\r\n\r\nThis means that in the Add Account dialog box in Outlook, users must choose “Manual setup or additional server types,” then choose Next, and then choose “POP or IMAP.”\r\n\r\nIf you disable or don’t configure this policy setting, users can configure a personal Microsoft account to use MAPI in Outlook. They can do this by choosing “E-mail” account in the Add Account dialog box.\r\n\r\nNote that personal Microsoft accounts that are configured to use MAPI will be automatically configured to use Cached Exchange Mode, and this can’t be changed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disableexchangeconsumeraccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disableexchangeconsumeraccounts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablerpctransportfallback","displayName":"Disable connection fallback between protocols (User)","description":"This policy setting allows you to control the connection transport fallback behavior in Outlook when it attempts to connect to a Microsoft Exchange Server.\r\n \r\nThis policy setting applies if you are using Outlook Anywhere (RPC over HTTP) to connect to a Microsoft Exchange Server. There are two Outlook profile settings on the Microsoft Exchange Proxy Settings dialog box (accessed through the Control Panel or Account Settings), that configure the default connection transport fallback behavior.\r\n \r\n- On fast networks, connect using HTTP first, then connect using TCP/IP\r\n- On slow networks, connect using HTTP first, then connect using TCP/IP\r\n \r\nFor example, if you are on a fast network and you enable the “On fast networks, connect using HTTP first, then connect using TCP/IP” setting in the Microsoft Exchange Proxy Settings dialog box, Outlook first attempts to connect to the Exchange Server using HTTP. If Outlook is unable to connect using HTTP, then it attempts to connect using TCP/IP.\r\n \r\nIf you enable this policy setting, if Outlook connection attempts with Microsoft Exchange Server fail, Outlook does not fallback to the TCP/IP protocol, regardless of what is specified in the Microsoft Exchange Proxy Settings dialog box. \r\n\r\nIf you disable or do not configure this policy setting, Outlook connection attempts with Microsoft Exchange Server can fallback from either TCP/IP to HTTP, or HTTP to TCP/IP, depending on the settings specified in the Microsoft Exchange Proxy Settings dialog box.\r\n","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablerpctransportfallback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablerpctransportfallback_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_donotcreatenewostonupgrade","displayName":"Do not create new OST file on upgrade (User)","description":"This policy setting controls whether Outlook creates a new OST file when you upgrade to Outlook 2016. The new OST file uses less space on the disk. When a new OST file is created, the contents from the previous version of Outlook are downloaded from the Exchange Server.\r\n\r\nIf you enable this policy setting, Outlook continues to use the existing OST file created by the installed earlier version of Outlook. \r\n\r\nIf you disable or do not configure this policy setting, when you upgrade to Outlook 2016, a new OST file is created, and the contents from the installed earlier version of Outlook are downloaded from the Exchange server.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_donotcreatenewostonupgrade_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_donotcreatenewostonupgrade_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface","displayName":"Configure Outlook Anywhere user interface options (User)","description":"This policy setting allows you to determine whether users can view and change user interface (UI) options for Outlook Anywhere.\r\n\r\nIf you enable this policy setting, users can view and change UI options for Outlook Anywhere.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to use the Outlook Anywhere feature, but they will not be able to view or change UI options for it.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_l_chooseuistatewhenoscansupportfeature","displayName":"Choose UI State when OS can support feature: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_l_chooseuistatewhenoscansupportfeature_0","displayName":"Hidden","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_l_chooseuistatewhenoscansupportfeature_1","displayName":"All config UI enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_l_chooseuistatewhenoscansupportfeature_2","displayName":"Enable only On/Off control but not config UI","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_l_chooseuistatewhenoscansupportfeature_3","displayName":"Enable config UI when settings are pre-deployed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_l_chooseuistatewhenoscansupportfeature_4","displayName":"Disable but show all config UI","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption","displayName":"Enable RPC encryption (User) (Deprecated)","description":"This policy setting controls whether Outlook uses remote procedure call (RPC) encryption to communicate with Microsoft Exchange servers. \r\n\r\nIf you enable this policy setting, Outlook uses RPC encryption when communicating with an Exchange server. Note - RPC encryption only encrypts the data from the Outlook client computer to the Exchange server. It does not encrypt the messages themselves as they traverse the Internet. \r\n\r\nIf you disable or do not configure this policy setting, RPC encryption is still used by default. This setting allows you to override the corresponding per-profile setting.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_v2","displayName":"Enable RPC encryption (User)","description":"This policy setting controls whether Outlook uses remote procedure call (RPC) encryption to communicate with Microsoft Exchange servers. \r\n\r\nIf you enable this policy setting, Outlook uses RPC encryption when communicating with an Exchange server. Note - RPC encryption only encrypts the data from the Outlook client computer to the Exchange server. It does not encrypt the messages themselves as they traverse the Internet. \r\n\r\nIf you disable or do not configure this policy setting, RPC encryption is still used by default. This setting allows you to override the corresponding per-profile setting.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat","displayName":"Exchange Unicode Mode - Ignore OST Format (User)","description":"This policy setting allows you to specify whether existing OST format determines the mailbox mode.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n* OST Format determines mode: the format of the user's OST file will be used to determine whether to run in Unicode or ANSI mode.\r\n* Create new OST if format doesn't match mode: create a new OST file if needed.\r\n* Prompt to create new OST if format doesn't match mode\r\n\r\nIf you disable or do not configure this policy setting, you will not be able to specify whether existing OST format determines the mailbox mode.\r\n\r\nThis policy is ignored if PreferANSI is not set and the OST is enabled but either does not exist or is a Unicode OST, because it would be impossible for the user to create an ANSI OST.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_l_choosewhetherexistingostformatdeterminesmailboxmode","displayName":"Choose whether existing OST format determines mailbox mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_l_choosewhetherexistingostformatdeterminesmailboxmode_0","displayName":"OST Format determines mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_l_choosewhetherexistingostformatdeterminesmailboxmode_1","displayName":"Create new OST if format doesn't match mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_l_choosewhetherexistingostformatdeterminesmailboxmode_2","displayName":"Prompt to create new OST if format doesn't match mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodesilentostformatchange","displayName":"Exchange Unicode Mode - Silent OST format change (User)","description":"This policy setting allows .OST files to silently update to Unicode format from ANSI.\r\n\r\nIf you enable this policy setting, it will only have meaning if the related policy setting \"Exchange Unicode Mode - Ignore OST format\" is enabled and set to the options listed below.\r\n\r\nThe behavior is as follows -\r\n\r\n\"Ignore OST Format\" policy setting is enabled and set to \"Create new OST if format doesn't match mode\"; \"Silent OST Format Change\" policy setting is enabled:\r\nIf Outlook detects a mode that is different than the current .OST mode, then a new .OST is created without prompting the user.\r\n\r\n\"Ignore OST Format\" policy setting is enabled and set to \"Prompt to create new OST if format doesn't match mode\"; \"Silent OST Format Change\" policy setting is enabled:\r\nIf Outlook detects a mode that is different than the current .OST mode, the user is prompted to allow a delay in the conversion to the mode set by policy. By clicking Ok, a new OST is created without a prompt for a new .OST name.\r\n\r\nIf you disable or do not configure this policy setting, users will be prompted to enter a new name for the updated .OST file.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodesilentostformatchange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodesilentostformatchange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeturnoffansi","displayName":"Exchange Unicode Mode - Turn off ANSI mode (User)","description":"This policy setting controls the creation of ANSI OST files.\r\n\r\nIf you enable or do not configure this policy setting, new ANSI OST files cannot be created.\r\n\r\nIf you disable this policy setting, all new OST files for an Outlook profile are created in ANSI format.\r\n\r\nProfiles with multiple Exchange accounts will always create Unicode OST files, regardless of this policy setting.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeturnoffansi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeturnoffansi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_foldersizedisplay","displayName":"Do not display Folder Size button on folder properties dialog box (User)","description":"Retains/Removes the \"Folder Size\" button in the General tab of the Properties dialog box.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_foldersizedisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_foldersizedisplay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_ostcreation","displayName":"Do not allow an OST file to be created (User)","description":"Prevents offline folder use at startup. This is equivalent to clicking the Disable Offline Use button in the Offline Folder Settings dialog box.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_ostcreation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_ostcreation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover","displayName":"Disable AutoDiscover (User)","description":"This policy setting allows you to disable AutoDiscover.\r\n\r\nIf you enable this policy setting, you can select one or more of the following options to disable in the AutoDiscover feature.\r\n\r\n\"Exclude the last known good URL” – Outlook does not use the last known good Autodiscover URL.\r\n\r\n\"Exclude the SCP object lookup\" – Outlook does not perform Active Directory queries for Service Connection Point (SCP) objects with Autodiscover information.\r\n\r\n\"Exclude the root domain query based on your primary SMTP address\" - Outlook does not use the root domain of your primary SMTP address to locate the AutoDiscover service. For example, you select this optionOutlook does not use the following URL: https:///autodiscover/autodiscover.xml.\r\n\r\n\"Exclude the query for the AutoDiscover domain\" - Outlook does not use the Autodiscover domain to locate the Autodiscover service. For example, Outlook does not use the following URL: https://autodiscover./autodiscover/autodiscover.xml\r\n\r\n\"Exclude the HTTP redirect method\" - Outlook does not use the HTTP redirect method in the event it is unable to reach the AutoDiscover service via either of the HTTPS URLs: https:///autodiscover/autodiscover.xml or https://autodiscover./autodiscover/autodiscover.xml.\r\n\r\n\"Exclude the SRV record query in DNS\" - Outlook does not use an SRV record lookup in DNS to locate the AutoDiscover service.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverautodiscoversubdomain","displayName":"Exclude the query for the AutoDiscover domain (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverautodiscoversubdomain_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverautodiscoversubdomain_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverhttpredirect","displayName":"Exclude the HTTP redirect method (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverhttpredirect_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverhttpredirect_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverlkgurl","displayName":"Exclude the last known goode URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverlkgurl_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverlkgurl_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverrootdomain","displayName":"Exclude the root domain query based on your primary SMTP address (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverrootdomain_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverrootdomain_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverscplookup","displayName":"Exclude the SCP object lookup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverscplookup_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverscplookup_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoversrvrecord","displayName":"Exclude the SRV record query in DNS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoversrvrecord_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoversrvrecord_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_personaldistributionlistsexchangeonly","displayName":"Do not validate personal Contact Groups when sending e-mail messages (User)","description":"Use only the local cache to obtain current user information when expanding a Personal Contact Group while sending e-mail","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_personaldistributionlistsexchangeonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_personaldistributionlistsexchangeonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts","displayName":"Prevent copying or moving items between accounts (User)","description":"This policy setting allows you to prevent items from being copied or moved to other accounts or PSTs.\r\n\r\nIf you enable this policy setting, items will be prevented from being moved or copied to other accounts or PSTs. Enter one of the following details:\r\n\r\n- \"Contoso.com\": prevents copying or moving from the account corresponding to the listed domain\r\n- \"*\": prevents copying from all accounts and PST's\r\n- \"SharePoint\": prevents copies or moves from the SharePoint PST\r\n\r\nIf you disable or do not configure this policy setting, copying or moving items between accounts or PSTs is allowed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventcopyingormovingitemsbetweenaccounts_l_preventcopyingormovingitemsbetweenaccountsid","displayName":"SMTP address domain (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventnondefaultexchangeaccounts","displayName":"Prevent adding non-default Exchange accounts (User)","description":"This policy allows you to prevent users from adding non-default Exchange accounts to existing Outlook profiles.\r\n\r\nIf you enable this policy setting, you will prevent users from adding non-default Exchange accounts via the Add New E-mail Account wizard.\r\n\r\nIf you disable or do not configure this policy setting, users can add non-default Exchange accounts to existing Outlook profiles.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventnondefaultexchangeaccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventnondefaultexchangeaccounts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags","displayName":"RPC/HTTP Connection Flags (User)","description":"This policy setting configures connection options for Outlook Anywhere. \r\n\r\nIf you enable this policy setting, you can configure multiple connection options by selecting the flag in the drop down menu that contains the combination of settings you need. The following flags are available: \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the settings specified in Autodiscover.\r\n\r\nFlag 1: Enables the 'Connect to Microsoft Exchange using HTTP checkbox' on the Connection tab. \r\n\r\nThe following flags configure options in the Microsoft Exchange Proxy Settings dialog box: \r\n\r\nFlag 2: Enables the 'Connect using SSL only' checkbox \r\nFlag 3: Enables the 'Only connect to proxy servers that have this principal name in their certificate' checkbox \r\nFlag 4: Enables the 'On fast networks, connect using HTTP first, then connect using TCP/IP' checkbox \r\nFlag 5: Enables the 'On slow networks, connect using HTTP first, then connect using TCP/IP' checkbox \r\n","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags","displayName":"Select a combination of RPC/HTTP connection flags (see Explain tab for details): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_0","displayName":"No Flags","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_47","displayName":"Flags: 1 + 2 + 3 + 4 + 5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_39","displayName":"Flags: 1 + 2 + 3 + 5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_43","displayName":"Flags: 1 + 2 + 4 + 5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_35","displayName":"Flags: 1 + 2 + 5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_41","displayName":"Flags: 1 + 4 + 5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpchttpconnectionflags_l_selectrpchttpconnectionflags_33","displayName":"Flags: 1 + 5","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting","displayName":"RPC Proxy Authentication Setting (User)","description":"This policy setting determines the RPC proxy authentication setting for Outlook Anywhere.\r\n \r\nIf you enable this policy setting, you can specify the proxy authentication setting that Outlook uses, and this overrides any proxy authentication setting specified in Autodiscover.\r\n\r\nIf you do not configure this policy setting Outlook uses the proxy server authentication specified in Autodiscover.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_l_selectrpcproxyauthentication","displayName":"Authentication used to connect with the proxy server: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_l_selectrpcproxyauthentication_1","displayName":"Basic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_l_selectrpcproxyauthentication_2","displayName":"NTLM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_l_selectrpcproxyauthentication_16","displayName":"Negotiate","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyauthenticationsetting_l_selectrpcproxyauthentication_65536","displayName":"Certificate","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyservername","displayName":"RPC Proxy Server Name (User)","description":"This policy setting determines the RPC proxy server that Outlook Anywhere uses when connecting to Exchange.\r\n \r\nIf you enable this policy setting, Outlook uses only the RPC proxy server that you specify when connecting to Exchange. It ignores the proxy server specified in Autodiscover.\r\n\r\nIf you disable or do not configure this policy setting Outlook uses the RPC proxy server that is specified in Autodiscover.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyservername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyservername_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyservername_l_rpcproxyservernametextid","displayName":"Specify the proxy server name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyserverprincipalname","displayName":"Only connect if Proxy Server certificate has this principal name (User)","description":"This policy setting specifies the required certificate principal name for the RPC proxy server for Outlook Anywhere. \r\n\r\nIf you enable this policy setting, you must enter a server principal name. You must precede the server name with \"msstd:\" for this configuration to work. For example, you would enter the following text if the server principal name is mail.fourthcoffee.com: \r\n\r\nmsstd:mail.fourthcoffee.com \r\n\r\nIf you disable or do not configure this setting, Outlook uses the certificate principal name that is specified in Autodiscover.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyserverprincipalname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyserverprincipalname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyserverprincipalname_l_rpcproxyserverprincipalnametextid","displayName":"Specify the proxy server principal name (see Explain tab for details): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_setmaximumnumberofexchangeaccounts","displayName":"Set maximum number of Exchange accounts per profile (User)","description":"This policy setting allows you to set the maximum number of Exchange accounts allowed per Outlook profile.\r\n\r\nIf you enable this policy setting, you will be able to set the maximum number of Exchange accounts allowed per Outlook profile.\r\n\r\nIf you disable or do not configure this policy setting, the default maximum number of Exchange accounts allowed per Outlook profile is 10.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_setmaximumnumberofexchangeaccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_setmaximumnumberofexchangeaccounts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_setmaximumnumberofexchangeaccounts_l_setmaximumnumberofexchangeaccountsspinid","displayName":"Number of Accounts: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders","displayName":"Synchronizing data in shared folders (User)","description":"This setting controls the number of days that elapses without a user accessing an Outlook folder before Outlook stops synchronizing the folder with Exchange. For example, say this option is set to 45. User A opens User B's calendar in Outlook, and then does not click on it again for 45 days. Outlook stops synchronizing the data with Exchange and the calendar is no longer up-to-date. The local copy of the data is removed from the OST file. If User A then clicks on the User B calendar 90 days later, Outlook synchronizes the calendar data and starts the clock again for 45 days.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders_l_numberofdays","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbook","displayName":"Turn off Hierarchical Address Book (User)","description":"This policy setting turns off the Hierarchical Address Book (HAB).\r\n\r\nIf you enable this policy setting, the HAB will be turned off. \r\n\r\nIf you disable or do not configure this policy setting, the HAB will be displayed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbookdepartmentselection","displayName":"Turn off Hierarchical Address Book department selection (User)","description":"This policy setting controls whether departments can be picked as recipients in the Hierarchical Address Book (HAB).\r\n\r\nIf you enable this policy setting, the tree control to pick departments as recipients is turned off in the HAB.\r\n\r\nIf you disable or do not configure this policy setting, the tree control to pick departments as recipients is turned on in the HAB.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbookdepartmentselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbookdepartmentselection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbooksearch","displayName":"Turn off Hierarchical Address Book search (User)","description":"This policy setting controls entry points to search in the Hierarchical Address Book (HAB).\r\n\r\nIf you enable this policy setting, all entry points to search features in the HAB will be turned off. \r\n\r\nIf you disable or do not configure this policy setting, all entry points to search features in the HAB will be enabled.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbooksearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbooksearch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_uselegacyoutlookauthenticationdialogs","displayName":"Use legacy Change Password authentication dialog boxes (User)","description":"By default, Outlook displays the Windows authentication dialog box when users are prompted to change their passwords. By enabling this setting, you can change this behavior so that older-style Outlook dialog boxes that include the Change Password button are displayed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_uselegacyoutlookauthenticationdialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_uselegacyoutlookauthenticationdialogs_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode","displayName":"Cached Exchange Mode (File | Cached Exchange Mode) (User)","description":"Specifies the default Cached Exchange Mode for new profiles and disables the download options in the Cached Exchange Mode command submenu in the File menu.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles","displayName":"Select Cached Exchange Mode for new profiles (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles_1","displayName":"Download Headers","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles_2","displayName":"Download Full Items","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles_3","displayName":"Download Headers and then Full Items","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_configurecachedexchangemode","displayName":"Use Cached Exchange Mode for new and existing Outlook profiles (User)","description":"By default, users can choose to configure Cached Exchange Mode or use Online mode. By enabling this setting, new and existing Outlook profiles are configured to use Cached Exchange Mode. Disabling this setting configures new and existing Outlook profiles to use Online mode.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_configurecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_configurecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadfullitemsfilecachedexchangemode","displayName":"Disallow Download Full Items (User)","description":"This policy setting allows you to turn off the \"Download Full Items\" option.\r\n\r\nIf you enable this policy setting, you will turn off the \"Download Full Items\" option in the Download Preferences menu in the Send/Receive tab.\r\n\r\nIf you disable or do not configure this policy setting, you will allow the \"Download Full Items\" option in the Download Preferences menu in the Send/Receive tab.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadfullitemsfilecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadfullitemsfilecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadheadersfilecachedexchangemode","displayName":"Disallow Download Headers (User)","description":"Disables/Enables the option \"Download Headers\" in the Server group of the Send/Receive tab.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadheadersfilecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadheadersfilecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadheadersthenfullitemsfilecachedexchangemode","displayName":"Disallow Download Headers then Full Items (User)","description":"This policy setting allows you to turn off the \"Download Headers and then Full Items\" option. Microsoft Exchange Server 2003 or later is required.\r\n\r\nIf you enable this policy setting, you will turn off the \"Download Headers and then Full Items\" option in the Download Preferences menu in the Send/Receive tab.\r\n\r\nIf you disable or do not configure this policy setting, you will allow the \"Download Headers and then Full Items\" option in the Download Preferences menu in the Send/Receive tab.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadheadersthenfullitemsfilecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadheadersthenfullitemsfilecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowonslowconnectionsonlydownloadheadersfilecachedexchan","displayName":"Disallow On Slow Connections Only Download Headers (User)","description":"This policy setting allows you to turn off the \"On Slow Connections Download Only Headers\" option.\r\n\r\nIf you enable this policy setting, you will turn off the \"On Slow Connections Download Only Headers\" option in the Download Preferences menu in the Send/Receive tab.\r\n\r\nIf you disable or do not configure this policy setting, you will allow the \"On Slow Connections Download Only Headers\" option in the Download Preferences menu in the Send/Receive tab.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowonslowconnectionsonlydownloadheadersfilecachedexchan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowonslowconnectionsonlydownloadheadersfilecachedexchan_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_downloadpublicfolderfavorites","displayName":"Download Public Folder Favorites (User)","description":"Checked: Checks the \"Download Public Folder Favorites\" option in the Advanced tab of the Microsoft Exchange Server dialog box (More Settings button in the E-mail Accounts dialog box) and enables the option. This enables Public Folder Favorites synchronization in Cached Exchange mode. | Unchecked: Unchecks the \"Download Public Folder Favorites\" option in the Advanced tab of the Microsoft Exchange Server dialog box (More Settings button in the E-mail Accounts dialog box) and disables the option. This disables Public Folder Favorites synchronization in Cached Exchange mode.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_downloadpublicfolderfavorites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_downloadpublicfolderfavorites_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_downloadshardnonmailfolders","displayName":"Download shared non-mail folders (User)","description":"By default, most shared folders that users access in other mailboxes are automatically downloaded and cached in the users' local OST files when Cached Exchange Mode is enabled. Only shared Mail folders are not cached. You can use this setting to change this behavior so that non-mail folders are not downloaded automatically.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_downloadshardnonmailfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_downloadshardnonmailfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entermaximumsecondstowaittosyncchanges","displayName":"Enter maximum seconds to wait to sync changes (User)","description":"Specifies maximum number of seconds to wait before synchronizing changes with the Exchange server.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entermaximumsecondstowaittosyncchanges_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entermaximumsecondstowaittosyncchanges_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entermaximumsecondstowaittosyncchanges_l_entersecondstowaitbeforesyncdefault60sec","displayName":"Enter seconds to wait before sync(Default 60 sec.) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver","displayName":"Enter seconds to wait to download changes from server (User)","description":"Specifies number of seconds to wait before downloading changes from the Exchange server.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver_l_entersecondstowaitbeforedownloaddefault30sec","displayName":"Enter seconds to wait before download(Default 30 sec.) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittouploadchangestoserver","displayName":"Enter seconds to wait to upload changes to server (User)","description":"Specifies number of seconds to wait before uploading changes to the Exchange server.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittouploadchangestoserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittouploadchangestoserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittouploadchangestoserver_l_entersecondstowaitbeforeuploaddefault15sec","displayName":"Enter seconds to wait before upload(Default 15 sec.) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_hybridmode","displayName":"Disable Exchange Fast Access (User)","description":"This policy setting allows you to disable Exchange Fast Access, which forces user accounts to access data from a local cache.\r\n\r\nIf you enable this policy setting, Exchange Fast Access is not available to any Exchange Accounts on a computer.\r\n\r\nIf you disable or do not configure this policy setting, Exchange Fast Access is turned on by default for Exchange Accounts in Cached Exchange Mode.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_hybridmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_hybridmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_incachedexchangemakesendreceivef9nulloperation","displayName":"Do not sync in Cached Exchange mode when users click Send/Receive or F9 (User)","description":"By default, when users click Send/Receive or press F9 for Cached Exchange Mode accounts, Outlook synchronizes with the Exchange server. When this setting is enabled, clicking Send/Receive and pressing F9 do not synchronize with Exchange unless only one folder is being synchronized. Users can continue to use shift-F9 to synchronize the current folder.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_incachedexchangemakesendreceivef9nulloperation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_incachedexchangemakesendreceivef9nulloperation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_includeonlinemodegalinanr","displayName":"Use the Online Global Address List for Nickname Resolution (User)","description":"This policy setting allows you to force Outlook to use the Online Global Address List for ambiguous name resolution when composing messages in Outlook, instead of using the Offline Address Book when it is available.\r\n\r\nIf you enable this policy setting, addresses are resolved using the Online Global Address List, which may contain additional information (that the Offline Address Book would not have) that allows an address to be resolved.\r\n\r\nIf you disable or do not configure this policy setting, Outlook resolves addresses using the Offline Address Book when it is available.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_includeonlinemodegalinanr_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_includeonlinemodegalinanr_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbookexactaliasmatching","displayName":"Return e-mail alias if it exactly matches the provided e-mail address when searching OAB (User)","description":"By default, when searching the Offline Address Book, Outlook resolves e-mail addresses using Ambiguous Name Resolution. With Ambiguous Name Resolution, Outlook suggests additional possible matches (if they exist) even if there is a name that matches exactly the e-mail alias entered. By enabling this setting, you can change the behavior so that Outlook returns a single e-mail address if it exactly matches an e-mail alias.","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbookexactaliasmatching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbookexactaliasmatching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads","displayName":"Offline Address Book: Limit manual OAB downloads (User)","description":"This policy setting allows you to specify the number of manual downloads of the offline address book (OAB) allowed in a 13 hour period.\r\n\r\nIf you enable this policy setting, you may specify the number of manual downloads of the offline address book (OAB) allowed in a 13 hour period. If you set the value to 0, then no manual OAB downloads are allowed. If you set the value to the maximum of 65535, then that will allow an unlimited number of manual downloads of the OAB.\r\n\r\nIf you disable or do not configure this policy setting, an unlimited number of manual downloads of the OAB will be allowed.","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads_l_allowxxmanualoabdownloadsper13hrperiod","displayName":"Upper limit of number of manual OAB downloads per 13 hour period (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitnumberofincrementaloabdownloads","displayName":"Offline Address Book: Limit number of incremental OAB downloads (User)","description":"This policy setting allows you to specify the number of incremental download attempts of the offline address book (OAB) allowed in a 13 hour period.\r\n\r\nIf you enable this policy setting, you may specify the number of incremental download attempts of the offline address book (OAB) allowed in a 13 hour period. If you set the value to 0, then no incremental download attempts are allowed. If you set the value to the maximum of 65535, then that will allow an unlimited number of incremental OAB download attempts.\r\n\r\nIf you disable or do not configure this policy setting, an unlimited number of incremental OAB download attempts of the OAB will be allowed.","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitnumberofincrementaloabdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitnumberofincrementaloabdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitnumberofincrementaloabdownloads_l_allowxxincrementaloabdownloadsper13hrperiod","displayName":"Allow xx incremental OAB downloads per 13hr period (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbookpromptbeforedownloadingfulloab","displayName":"Offline Address Book: Prompt before Downloading Full OAB (User)","description":"Specifies that the user is asked for permission before initiating a full download of the offline address book.","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbookpromptbeforedownloadingfulloab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbookpromptbeforedownloadingfulloab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_imap_l_turnonpurgewhenswitchingfolders","displayName":"Turn on purge when switching folders (User)","description":"When \"purge on switch\" is enabled, IMAP e-mail messages marked for deletion in the current folder will be permanently removed from the server when the user switches to another folder. This setting will allow you to enable the IMAP \"purge on switch\" feature.","helpText":"","infoUrls":[],"categoryId":"63ca5d8b-829d-42c5-92e8-35f9ca47fb0e","categoryName":"IMAP","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_imap_l_turnonpurgewhenswitchingfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_imap_l_turnonpurgewhenswitchingfolders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_automaticallydownloadenclosures","displayName":"Automatically download enclosures (User)","description":"This policy setting allows you to control whether Outlook automatically downloads enclosures on RSS items.\r\n\r\nIf you enable this policy setting, Outlook will automatically download enclosures on RSS items.\r\n\r\nIf you disable or do not configure this policy setting, enclosures on RSS items are not downloaded by default.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_automaticallydownloadenclosures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_automaticallydownloadenclosures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_defaultrssfeeds","displayName":"Default RSS Feeds (User)","description":"This policy setting allows you to deploy default RSS Feeds by providing a list of URLs that point to content that is syndicated through RSS. Outlook reads the list when it starts, and the corresponding RSS Feeds are added to each of the user's profiles. By default, users are not subscribed to any RSS Feeds.\r\n\r\nIf you enable this policy setting, you may specify the URLs in the format: feed://, where \"feed://\" replaces \"http://\". This ensures that the URL is parsed as an RSS XML file in Outlook.\r\n\r\nIf you disable or do not configure this policy setting, users are not subscribed to any RSS Feeds.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_defaultrssfeeds_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_defaultrssfeeds_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_defaultrssfeeds_l_defaultrsssubscriptionspart","displayName":"List of default RSS Feeds (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_defaultrssfeeds_l_defaultrsssubscriptionspart_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_defaultrssfeeds_l_defaultrsssubscriptionspart_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_disableroamingofrsssubscriptions","displayName":"Do not roam users' RSS Feeds (User)","description":"This policy setting allows you to change the default delivery location of RSS Feeds to a local PST.\r\n\r\nIf you enable this setting, the default delivery location will be changed to a local PST. When RSS Feeds are delivered to a local PST, they will not roam from client to client and will only be available on the computer where the user originally subscribed to the RSS Feed.\r\n\r\nIf you disable or do not configure this policy setting, subscriptions to RSS Feeds are delivered to the user's mailbox and roam from client to client via Exchange. This setting does not affect RSS Feeds that were subscribed before the policy setting was enabled. This setting also does not prevent the user from manually directing an RSS Feed to deliver to the user's mailbox, which allows the RSS Feed to roam from client to client.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_disableroamingofrsssubscriptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_disableroamingofrsssubscriptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_downloadfulltextofarticles","displayName":"Download full text of articles as HTML attachments (User)","description":"This policy setting controls whether Outlook automatically makes an offline copy of the RSS items as HTML attachments.\r\n\r\nIf you enable this policy setting, Outlook automatically makes an offline copy of RSS items as HTML attachments. \r\n\r\nIf you disable or do not configure this policy setting, Outlook will not automatically make an offline copy of RSS items as HTML attachments.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_downloadfulltextofarticles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_downloadfulltextofarticles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_overridepublishedsyncinterval","displayName":"Override published sync interval (User)","description":"This policy setting allows you to ignore the synchronization interval specified by the RSS publisher. By default, Outlook follows the synchronization interval specified by the RSS publisher and RSS Feeds will not be synchronized more often than allowed by the RSS publisher. If Outlook does not follow the RSS publisher's synchronization interval, the RSS publisher may suspend Outlook from synchronizing the RSS Feed.\r\n\r\nIf you enable this policy setting, Outlook will always ignore the synchronization interval specified by the RSS publisher.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will always follow the synchronization interval specified by the RSS publisher.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_overridepublishedsyncinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_overridepublishedsyncinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_runrulesonrssitems","displayName":"Run rules on RSS items (User)","description":"By default, rules are not run on RSS items. Use this setting to make rules run on RSS items.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_runrulesonrssitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_runrulesonrssitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_synchronizeoutlookrssfeedswithcommonfeedlist","displayName":"Synchronize Outlook RSS Feeds with Common Feed List (User)","description":"This policy setting controls whether Outlook subscribes to the Common Feed List, which is made available to multiple RSS clients. The Common Feed List is a hierarchical set of RSS Feeds to which clients such as Outlook, the Feeds list in Internet Explorer 7, and the Feed Headlines Sidebar gadget in Windows Vista can subscribe. \r\n\r\nIf you enable this policy setting, Outlook automatically subscribes to RSS Feeds added in Internet Explorer, and Outlook RSS Feeds are synchronized with the Common Feed List so they are available in Internet Explorer. Be aware that third-party applications besides Internet Explorer can add RSS Feeds to the Common Feed List, and if you enable this setting Outlook automatically subscribes to those RSS Feeds as well. \r\n\r\nIf you disable or do not configure this policy setting, Outlook maintains its own list of RSS Feeds and does not automatically subscribe to RSS Feeds that are added to the Common Feed List.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_synchronizeoutlookrssfeedswithcommonfeedlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_synchronizeoutlookrssfeedswithcommonfeedlist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_turnoffrssfeature","displayName":"Turn off RSS feature (User)","description":"This policy setting controls whether the RSS aggregation feature in Outlook is enabled. \r\n\r\nIf you enable this policy setting, the RSS aggregation feature in Outlook is disabled. \r\n\r\nIf you disable or do not configure this policy setting, users can subscribe to RSS Feeds from within Outlook and read RSS items like e-mail messages.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_turnoffrssfeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_turnoffrssfeature_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists","displayName":"Default SharePoint lists (User)","description":"This policy setting allows you to deploy SharePoint lists.\r\n\r\nIf you enable this policy setting, you can provide a list of SharePoint list URLs in the following format:\r\n\r\nValue name: SPsite1\r\nValue: SPsite1 stssync:// URL. See MS-STSSYN for documentation.\r\n\r\nValue name: SPSite2\r\nValue: SPsite2 stssync:// URL. See MS-STSSYN for documentation.\r\n\r\nThe list of URLs provided is read when Outlook starts up, and the corresponding SharePoint lists are added to each of the user's profiles.\r\n\r\nIf you disable or do not configure this policy setting, users will not have any default SharePoint lists.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists_l_empty35","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists_l_empty35_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists_l_empty35_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_definecustomlabelforsharepointstore","displayName":"Define custom label for SharePoint store (User)","description":"You can use this setting to define a custom label for the SharePoint Lists PST and most other places where the term \"SharePoint\" is used in Outlook. (Setting this value replaces the word \"SharePoint\" in Outlook strings with the value you specify.) A custom label might be particularly useful when deploying a third-party server that supports the same Microsoft SharePoint Foundation Web services Outlook uses for synchronization.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_definecustomlabelforsharepointstore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_definecustomlabelforsharepointstore_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_definecustomlabelforsharepointstore_l_definecustomlabelforsharepointstorepart","displayName":"Enter custom label for SharePoint store: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disableroamingofsharepointlists","displayName":"Do not roam users' SharePoint lists (User)","description":"By default, links to SharePoint lists are available on each client that the users use to connect to their Microsoft Exchange Server mailboxes. This setting allows you to disable roaming links to SharePoint lists. When roaming is disabled, SharePoint lists are available only on the client that originally linked them.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disableroamingofsharepointlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disableroamingofsharepointlists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disablesharepointintegrationinoutlook","displayName":"Do not allow Sharepoint-Outlook integration (User)","description":"This policy setting allows you to prevent access to Microsoft SharePoint Foundation with Outlook.\r\n\r\nIf you enable this policy setting, user profiles will not be able to upload new items or sync changes to the SharePoint list from the server; however, user profiles that have pre-existing SharePoint lists will retain their local data. In addition, new SharePoint lists cannot be connected when this policy setting is enabled. This can be toggled on and off to restore synchronization to existing lists. Note that users will not receive a message if synchronization has been prevented.\r\n\r\nIf you disable or do not configure this policy setting, Microsoft SharePoint Foundation access will be allowed with Outlook.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disablesharepointintegrationinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disablesharepointintegrationinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_logsharepointsyncrequestsandresponses","displayName":"Log SharePoint sync requests and responses (User)","description":"This policy setting allows you to control whether sync requests and responses between Outlook and SharePoint are logged. Log files can help diagnose problems with Outlook and SharePoint interactions. Each log file links to one or more XML files (also in the TEMP directory) containing detailed server response and error information. The XML filename is based on the corresponding log file; you can obtain all related diagnostic files by copying all *-wss-*.* files from the TEMP directory.\r\n\r\nIf you enable this policy setting, Outlook logs most sync requests and responses to a log file stored in the user's TEMP directory. One log file is created per session (up to seven total), using the naming convention: 0-wss-sync-log.HTM, 1-wss-sync-log.HTM, etc. \r\n\r\nIf you disable or do not configure this policy setting, sync requests and responses between Outlook and SharePoint are not logged.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_logsharepointsyncrequestsandresponses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_logsharepointsyncrequestsandresponses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_modifynumberofchangeditemsincluded","displayName":"Modify number of changed items included in SharePoint client page download (User)","description":"By default, the number of changes an Outlook client downloads from a SharePoint server in a single web service request or \"page\" is 250 changed items. If SharePoint servers have reduced capacity or are overwhelmed by the size of requests coming from Outlook clients, you can change this setting to specify a different number of items to download for a SharePoint page. \r\n\r\nYou should test changes in this setting to determine the impact in your specific environment. A page size below 15 or above 1000 is not recommended.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_modifynumberofchangeditemsincluded_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_modifynumberofchangeditemsincluded_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_modifynumberofchangeditemsincluded_l_empty34","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_overridepublishedsyncinteral36","displayName":"Override published sync interval (User)","description":"This policy setting allows you to prevent users from overriding the sync interval published by managed SharePoint lists.\r\n\r\nIf you enable this policy setting, the \"Update Limit\" checkbox found under File tab | Info | Account Settings | SharePoint List | Change… is disabled, and the user's connected SharePoint lists will only sync as defined by the list's administrator.\r\n\r\nIf you disable this policy setting, then individual users will be able to override the sync interval by unchecking the \"Update Limit\" checkbox in the SharePoint List's Options dialog. Defined sync intervals can range from 1 minute to 1440 minutes (a full day).\r\n\r\nIf you do not configure this policy setting, the user's profile will sync the SharePoint list at a default of 20 minutes or as specified by the administrator of the SharePoint list.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_overridepublishedsyncinteral36_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_overridepublishedsyncinteral36_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_automaticallydownloadenclosureswebcal","displayName":"Automatically download attachments (User)","description":"This policy setting controls whether Outlook downloads files attached to Internet Calendar appointments. \r\n\r\nIf you enable this policy setting, Outlook automatically downloads all Internet Calendar appointment attachments \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not download attachments when retrieving Internet Calendar appointments.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_automaticallydownloadenclosureswebcal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_automaticallydownloadenclosureswebcal_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions","displayName":"Default Internet Calendar subscriptions (User)","description":"This policy setting allows you to deploy Internet Calendar subscriptions.\r\n\r\nIf you enable this policy setting, the URLs listed here will be read and the corresponding Internet Calendar subscriptions will be added to each of the user's profiles. The name you specify here will not be used as the name of the Internet Calendar subscription.\r\n\r\nIf you disable or do not configure this policy setting users will not have any default Internet Calendar subscriptions.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_l_empty32","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_l_empty32_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_l_empty32_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_disableroamingofinternetcalendars","displayName":"Disable roaming of Internet Calendars (User)","description":"By default, Internet Calendars are available on each client that the users use to connect to their Microsoft Exchange Server mailboxes. This setting allows you to disable roaming Internet Calendars. When roaming is disabled, Internet Calendars are available only on the client that originally linked them.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_disableroamingofinternetcalendars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_disableroamingofinternetcalendars_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_disablewebcalintegration","displayName":"Do not include Internet Calendar integration in Outlook (User)","description":"This policy setting allows you to determine whether or not you want to include Internet Calendar integration in Outlook. The Internet Calendar feature in Outlook enables users to publish calendars online (using the webcal:// protocol) and subscribe to calendars that others have published. When users subscribe to an Internet calendar, Outlook queries the calendar at regular intervals and downloads any changes as they are posted. \r\n\r\nIf you enable this policy setting, all Internet calendar functionality in Outlook is disabled. \r\n\r\nIf you disable or do not configure this policy setting, Outlook allows users to subscribe to Internet calendars.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_disablewebcalintegration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_disablewebcalintegration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_overridepublishedsyncinteral","displayName":"Override published sync interval (User)","description":"By default, Outlook follows the sync interval specified by the Internet Calendar publisher and Internet Calendar subscriptions will not be sync'd more often than allowed by the Internet Calendar publisher. This setting allows you to prevent users from overriding the sync interval published by Internet Calendar publishers.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_overridepublishedsyncinteral_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_overridepublishedsyncinteral_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v3~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preferprovidedemailinautodiscoverauthprompts","displayName":"Prefer the provided account email in AutoDiscover auth prompts. (User)","description":"If set, this policy setting governs the displayed email in auth prompts related to AutoDiscover.\r\n\r\n Default (0): Prefers the account UPN, when available.\r\n\r\n If you enable this setting, then AutoDiscover auth prompts will prefer the provided account email (can be either SMTP or UPN depending on which was configured).","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v3~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preferprovidedemailinautodiscoverauthprompts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v3~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preferprovidedemailinautodiscoverauthprompts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions_l_disableguesssmart","displayName":"Disable GuessSmart in Outlook. (User)","description":"This policy setting determines whether GuessSmart will be used to configure an account.\r\n\r\nIf you enable this policy setting, GuessSmart will not be used to configure an account.","helpText":"","infoUrls":[],"categoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","categoryName":"Outlook Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions_l_disableguesssmart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions_l_disableguesssmart_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions_l_disableroamingsettings","displayName":"Disable roaming settings in Outlook. (User)","description":"This policy setting determines whether roaming settings will be used to store accounts and their settings.\r\n\r\nIf you enable this policy setting, roaming settings will not store Outlook accounts or their settings in the cloud.","helpText":"","infoUrls":[],"categoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","categoryName":"Outlook Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions_l_disableroamingsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions_l_disableroamingsettings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookfeedbackfeatures","displayName":"Disable Outlook features in the Feedback tab under the File menu in Outlook (User)","description":"This policy setting determines whether Outlook features will be displayed in the Feedback tab under the File menu in Outlook.\r\n\r\nIf you enable this policy setting, then Outlook features will not be displayed in the Feedback tab under the File menu in Outlook.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookfeedbackfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookfeedbackfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookmobilehyperlink","displayName":"Disable Outlook Mobile Hyperlink (User)","description":"This policy setting determines if the Outlook Mobile Hyperlink is shown in Account Settings.\r\n\r\nIf you enable this policy setting, users will be unable to view the Outlook Mobile Hyperlink in Account Settings.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookmobilehyperlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookmobilehyperlink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportbackstage","displayName":"Disable the Support tab under the File menu in Outlook (User)","description":"This policy setting determines whether the Support tab will be displayed under the File menu in Outlook.\r\n\r\nIf you enable this policy setting, then the Support tab will not be displayed under the File menu in Outlook.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportbackstage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportbackstage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportdiagnostics","displayName":"Disable support diagnostics in Outlook (User)","description":"This policy setting determines if Outlook can communicate client information on failure to support services with the intent of diagnosing the issue or making the information available to support to help with the diagnosis/resolution of the issue and/or provide contextual error messaging to the user.\r\n\r\nIf you enable this policy setting, then Outlook will not communicate client information on failure to support services.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportticketcreationinoutlook","displayName":"Disable support ticket creation in Outlook (User)","description":"This policy setting determines if an Outlook support ticket can be created in Outlook.\r\n\r\nIf you enable this policy setting, users will be unable to create a support ticket in Outlook.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportticketcreationinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportticketcreationinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_disableaccountsettingsdetectionservice","displayName":"Prevent Outlook from interacting with the account settings detection service (User)","description":"This policy setting determines whether Outlook can interact with the account settings detection service to gather information about a user's account settings.\r\n\r\nIf you enable this policy setting, users will need to manually configure their account settings.","helpText":"","infoUrls":[],"categoryId":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_disableaccountsettingsdetectionservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_disableaccountsettingsdetectionservice_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_disableoffice365simplifiedaccountcreation","displayName":"Prevent Office 365 E-mail accounts from being configured within a simplified Interface (User)","description":"This policy setting determines whether an Office 365 E-mail account when being configured in Outlook, can use a simplified dialog that can greatly accelerate the initial account creation.\r\n\r\nIf you enable this policy setting, users will configure their Office 365 accounts using the Account Wizard, as they do, for all other account types.","helpText":"","infoUrls":[],"categoryId":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_disableoffice365simplifiedaccountcreation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_l_disableoffice365simplifiedaccountcreation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_enableeasaccountcreation","displayName":"Enable Exchange ActiveSync account creation in the Outlook account setup UI (User)","description":"This policy setting determines whether the Exchange ActiveSync button will be displayed in the account setup UI.\r\n\r\nIf you enable this policy setting, the Exchange ActiveSync button will be displayed in Outlook account setup UI.","helpText":"","infoUrls":[],"categoryId":"b161cf66-abfa-4a36-a9ac-c20ca60594e0","categoryName":"Exchange ActiveSync","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_enableeasaccountcreation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_enableeasaccountcreation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookenableofficeconfigserviceinautodiscover","displayName":"Allow Outlook Autodiscover to interact with Office Config Service (User)","description":"This policy setting determines whether Outlook can interact with the Office Config Service to get Autodiscover V2 service endpoint URL for different sovereigns.\r\n\r\nif you enable this policy setting, Outlook will get the URL for the sovereign Autodiscover v2 service endpoint by default.\r\n\r\nIf you disable this policy setting, Outlook will get the URL for the WW Autodiscover v2 service endpoint by default.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookenableofficeconfigserviceinautodiscover_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookenableofficeconfigserviceinautodiscover_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableadminnotifications","displayName":"Disable Outlook tenant admin notifications (User)","description":"This policy setting determines if tenant admins can receive support notifications in Outlook.\r\n\r\nDefault (0): Tenant admins who are signed in will receive status updates about potential issues and fixes that are impacting their tenant.\r\n\r\nIf you enable this setting, tenant admins who are signed in won't receive status updates about potential issues and fixes that are impacting their tenant.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableadminnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableadminnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablecrashnotificationonrestart","displayName":"Disable the Outlook crash notification when Outlook restarts. (User)","description":"This policy setting determines if the Outlook crash notification on restart is allowed. Enabling this setting will block Outlook crash notification on restart.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablecrashnotificationonrestart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablecrashnotificationonrestart_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_allowprivatekeycheck","displayName":"Check for the user's private key when the user sends an encrypted email that includes the user as a recipient (User)","description":"This policy setting controls whether Outlook checks for the user's private key when the user sends an encrypted email and the user is included as a recipient of the email. The user can be included as recipient either directly or as a member of a distribution list.\r\n\r\nIf you enable this policy setting, Outlook checks for the user's private key.\r\n\r\nIf you disable this policy setting, Outlook doesn't check for the user's private key.\r\n\r\nIf you don't configure this policy setting, Outlook checks for the user's private key.\r\n ","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_allowprivatekeycheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_allowprivatekeycheck_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel","displayName":"Junk E-mail protection level (User) (Deprecated)","description":"This policy setting controls your Junk E-mail protection level. The Junk E-mail Filter in Outlook helps to prevent junk e-mail messages, also known as spam, from cluttering user's Inbox. The filter evaluates each incoming message based on several factors, including the time when the message was sent and the content of the message. The filter does not single out any particular sender or message type, but instead analyzes each message based on its content and structure to discover whether or not it is probably spam.\r\n\r\nIf you enable this policy setting, you can select one of the four listed options available. After you select an option, users will not be able to change it.\r\n\r\nIf you disable this policy setting, Outlook reverts to the user-defined protection level.\r\n\r\nIf you do not configure this policy setting, users can change their junk e-mail filtering options.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_l_selectlevel","displayName":"Select level: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_l_selectlevel_4294967295","displayName":"No Protection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_l_selectlevel_6","displayName":"Low (Default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_l_selectlevel_3","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_l_selectlevel_2147483648","displayName":"Trusted Lists Only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2","displayName":"Junk E-mail protection level (User)","description":"This policy setting controls your Junk E-mail protection level. The Junk E-mail Filter in Outlook helps to prevent junk e-mail messages, also known as spam, from cluttering user's Inbox. The filter evaluates each incoming message based on several factors, including the time when the message was sent and the content of the message. The filter does not single out any particular sender or message type, but instead analyzes each message based on its content and structure to discover whether or not it is probably spam.\r\n\r\nIf you enable this policy setting, you can select one of the four listed options available. After you select an option, users will not be able to change it.\r\n\r\nIf you disable this policy setting, Outlook reverts to the user-defined protection level.\r\n\r\nIf you do not configure this policy setting, users can change their junk e-mail filtering options.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel","displayName":"Select level: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_4294967295","displayName":"No Protection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_6","displayName":"Low (Default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_3","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_2147483648","displayName":"Trusted Lists Only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver","displayName":"Authentication with Exchange Server (User) (Deprecated)","description":"This policy setting controls which authentication method Outlook uses to authenticate with Microsoft Exchange Server. Note - Exchange Server supports the Kerberos authentication protocol and NTLM for authentication. The Kerberos protocol is the more secure authentication method and is supported on Windows 2000 Server and later versions. NTLM authentication is supported in pre-Windows 2000 environments.\r\n \r\nIf you enable this policy setting, you can choose from three different options for controlling how Outlook authenticates with Microsoft Exchange Server:\r\n\r\n- Kerberos/NTLM password authentication. Outlook attempts to authenticate using the Kerberos authentication protocol. If this attempt fails, Outlook attempts to authenticate using NTLM. This option is the default configuration.\r\n\r\n- Kerberos password authentication. Outlook attempts to authenticate using the Kerberos protocol only.\r\n\r\n- NTLM password authentication. Outlook attempts to authenticate using NTLM only.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will attempt to authenticate using the Kerberos authentication protocol. If it cannot (because no Windows 2000 or later domain controllers are available), it will authenticate using NTLM.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver","displayName":"Select the authentication with Exchange server. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_9","displayName":"Kerberos/NTLM Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_16","displayName":"Kerberos Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_10","displayName":"NTLM Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_2147545088","displayName":"Insert a smart card","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2","displayName":"Authentication with Exchange Server (User)","description":"This policy setting controls which authentication method Outlook uses to authenticate with Microsoft Exchange Server. Note - Exchange Server supports the Kerberos authentication protocol and NTLM for authentication. The Kerberos protocol is the more secure authentication method and is supported on Windows 2000 Server and later versions. NTLM authentication is supported in pre-Windows 2000 environments.\r\n \r\nIf you enable this policy setting, you can choose from three different options for controlling how Outlook authenticates with Microsoft Exchange Server:\r\n\r\n- Kerberos/NTLM password authentication. Outlook attempts to authenticate using the Kerberos authentication protocol. If this attempt fails, Outlook attempts to authenticate using NTLM. This option is the default configuration.\r\n\r\n- Kerberos password authentication. Outlook attempts to authenticate using the Kerberos protocol only.\r\n\r\n- NTLM password authentication. Outlook attempts to authenticate using NTLM only.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will attempt to authenticate using the Kerberos authentication protocol. If it cannot (because no Windows 2000 or later domain controllers are available), it will authenticate using NTLM.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_l_selecttheauthenticationwithexchangeserver","displayName":"Select the authentication with Exchange server. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_l_selecttheauthenticationwithexchangeserver_9","displayName":"Kerberos/NTLM Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_l_selecttheauthenticationwithexchangeserver_16","displayName":"Kerberos Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_l_selecttheauthenticationwithexchangeserver_10","displayName":"NTLM Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_v2_l_selecttheauthenticationwithexchangeserver_2147545088","displayName":"Insert a smart card","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_predefined_l_disableeditdefaultuserpermissions","displayName":"Limit which permissions can be assigned to Default, Anonymous, or My Organization on mail folders and calendars (User)","description":"This policy setting allows you to limit which permissions can be assigned to Default, Anonymous, or My Organization on mail folders and calendars.\r\n\r\nIf you enable this policy setting, users can assign only the following permissions to Default, Anonymous, or My Organization.\r\n\r\n- None on mail folders\r\n- None or basic Free/Busy information on calendars\r\n\r\nUsers won't be able to assign any other permissions to Default, Anonymous, or My Organization. All permissions will still be available to assign to other users on mail folders and calendars.\r\n\r\nIf you disable or don't configure this policy setting, users can assign any permissions to Default, Anonymous, or My Organization on mail folders and calendars.","helpText":"","infoUrls":[],"categoryId":"d59dfcc1-6c35-41de-bfb6-de94b8120ca5","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_predefined_l_disableeditdefaultuserpermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_predefined_l_disableeditdefaultuserpermissions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_delegatesentitemsstyle","displayName":"Saving messages sent from a shared mailbox to the Sent Items folder (User)","description":"This policy setting controls whether messages sent from a shared mailbox are saved to the Sent Items folder of the shared mailbox.\r\n\r\nBy default, messages sent from a shared mailbox aren't saved to the Sent Items folder of the shared mailbox.\r\n\r\nIf you enable this policy setting, messages sent from a shared mailbox will be saved to the Sent Items folder of the shared mailbox.\r\n\r\nIf you disable or don’t configure this policy setting, messages sent from a shared mailbox won’t be saved to the Sent Items folder of the shared mailbox.","helpText":"","infoUrls":[],"categoryId":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","categoryName":"Delegates","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_delegatesentitemsstyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_delegatesentitemsstyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype","displayName":"Shorten appointments and meetings (User)","description":"\r\n This policy setting allows you to shorten the default duration of appointments and meetings by a specified number of minutes. If you enable this policy setting, you can choose between the following options: End Early, Start Late, None.\r\n If you select End Early, meetings and appointments will end early by the specified number of minutes. \r\n If you select Start Late, meetings and appointments will start late by the specified number of minutes. \r\n If you select None, the default meeting duration will not be shortened. \r\n In all cases, the settings for this feature will be disabled in the Outlook Options dialog. \r\n If you don’t configure this policy setting, users can modify these settings by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype","displayName":"Select the Shorten Events Type (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype_none","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype_end_early","displayName":"End Early","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype_start_late","displayName":"Start Late","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_alwaysusemsoauthforautodiscover","displayName":"Autodiscover is always capable of using modern authentication (User)","description":"This policy setting controls whether Autodiscover is always capable of using modern authentication, regardless of the authentication methods supported by the primary mailbox connection type.\r\n\r\nBy default, Autodiscover only uses authentication methods that are supported by the primary mailbox connection type. Modern authentication won't always be one of the supported authentication methods for some connection types.\r\n\r\nIf you enable this policy setting, Autodiscover is always capable of using modern authentication, regardless of the authentication methods supported by the primary mailbox connection type. Enabling this policy setting may result in additional prompts for users to provide their password, when modern authentication is used, but not supported for the connection type.\r\n\r\nIf you disable or don’t configure this policy setting, Autodiscover will only use authentication methods supported by the primary mailbox connection type.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_alwaysusemsoauthforautodiscover_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_alwaysusemsoauthforautodiscover_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers","displayName":"Don’t show redirect warnings for Autodiscover for the specified HTTPS server names (User)","description":"This policy setting allows you to specify HTTPS server names for which Autodiscover won’t show a warning message when redirecting from HTTP to HTTPS.\r\n\r\nBy default, when an Autodiscover operation redirects from HTTP to HTTPS, you may be shown a warning message about the redirection.\r\n\r\nIf you enable this policy setting, you need to specify HTTPS server names, and for those server names, you won’t be shown a warning message. For example, if you enter contoso.com, you won’t be shown a warning message when Autodiscover redirects to https://contoso.com.\r\n\r\nIf you disable or don’t configure this policy setting, you may be shown a warning message when an Autodiscover operation redirects from HTTP to HTTPS.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers_l_autodiscoverredirectserverslist","displayName":"HTTPS server names: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},{"id":"user_vendor_msft_policy_config_outlk16v8~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_recommendoutlookextension","displayName":"Recommend the Microsoft Outlook Extension (User)","description":"This policy setting controls whether Windows 10 users of the Outlook app and the Outlook web app will see a recommendation to install the new Microsoft Outlook extension for Microsoft Edge. If a user chooses to click the recommendation, they will be taken to the Microsoft Outlook extension page where they can choose to install this web-based, productivity add on. Your users can dismiss the recommendation and will only see the recommendation twice. If your users choose to install the extension, they will be able to access their mail, calendar, contacts, and tasks from an icon in Microsoft Edge without requiring that they open another browser tab. The extension is a “mini” version of Outlook on the web which operates as a one-click flyout from the browser header.\r\n\r\nIn the future, Microsoft may release a version of this extension for the Chrome browser. Microsoft will respect this policy for future promotions of a Chrome extension, as well.\r\n\r\nIf you enable or do not configure this policy setting, the recommendation will be presented to the user.\r\n\r\nIf you disable this policy setting, the recommendation will not be presented to the user.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise and Outlook web app.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2165458","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v8~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_recommendoutlookextension_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v8~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_recommendoutlookextension_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin","displayName":"Deactivate Outlook web add-ins whose equivalent COM or VSTO add-in is installed (User)","description":"This policy setting allows you to deactivate Outlook web add-ins if the associated COM or VSTO add-in is installed.\r\n\r\nIf you enable this policy setting, users will not be able to use Outlook web add-ins where the corresponding COM or VSTO add-in is installed and you have provided the following information for each add-in.\r\n \"Value name\": Specify the Id of the Outlook web add-in, as noted in its manifest. Note: Do not add {} around the Id.\r\n \"Value\": Specify the programmatic ID (ProgID) for the Outlook COM or VSTO add-in.\r\n\r\nIf you disable or don't configure this policy setting, users will continue to be able to use any versions of the add-in that are installed.\r\n\r\nFor more information about when to use this setting, see https://go.microsoft.com/fwlink/p/?linkid=2156690","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_l_equivalentcomaddin2","displayName":"Outlook web add-ins to deactivate (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_l_equivalentcomaddin2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_l_equivalentcomaddin2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported","displayName":"Maximum Groups Supported (User)","description":"This policy setting controls the maximum number of groups that are accessible through the Navigation Pane in Outlook for Windows.\r\n\r\nIf you enable this policy setting, only the number of groups set in the Groups Count will be shown in the Navigation Pane. \r\n\r\nIf you don’t enable this policy setting, the maximum number of groups displayed defaults to 1000.\r\n ","helpText":"","infoUrls":[],"categoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","categoryName":"Outlook Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported_l_specifymaxgroupssupportedid","displayName":"Groups Count: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","categoryName":"Outlook Options","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_disableautosavewhencoauthoring","displayName":"Don’t automatically save changes when working in the same PowerPoint presentation as others (User)","description":"This policy setting controls whether changes are saved automatically when users are working together in the same presentation.\r\n\r\nBy default, when users are working together in the same presentation, changes are automatically saved. This allows users to see the edits made by others in real time. But, some add-ins or solutions might not be compatible with PowerPoint saving so frequently.\r\n\r\nIf you enable this policy setting, changes aren’t saved automatically and users won’t see real-time edits.\r\n\r\nIf you disable or don't configure this policy setting, changes are saved automatically and users will see real-time edits.\r\n\r\nNote: this policy setting doesn’t affect the AutoRecover settings configured under File > Options > Save.\r\n ","helpText":"","infoUrls":[],"categoryId":"ceacf7fa-fa6e-434d-a381-e20e5245d180","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_disableautosavewhencoauthoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_disableautosavewhencoauthoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_preventcoauthoring","displayName":"Prevent co-authoring (User)","description":"This policy setting controls how PowerPoint opens a file for editing on document management servers that support co-authoring.\r\n\r\nIf you enable this policy setting, PowerPoint will prevent co-authoring by taking an exclusive file lock. \r\n\r\nIf you disable or do not configure this policy setting, PowerPoint will allow co-authoring by taking short-term shared locks. \r\n\r\nNote: When file synchronization via SOAP over HTTP is turned off it will prevent co-authoring.","helpText":"","infoUrls":[],"categoryId":"ceacf7fa-fa6e-434d-a381-e20e5245d180","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_preventcoauthoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_preventcoauthoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_turnoffrevisiontracking","displayName":"Turn off revision tracking (User)","description":"This policy setting allows you to turn off revision tracking in PowerPoint.\r\n\r\nBy default, revision tracking is on in presentations where revision tracking is supported.\r\n\r\nIf you enable this policy setting, revisions made to a presentation aren’t tracked or shown.\r\n\r\nIf you disable or don’t configure this policy setting, revisions made to a presentation are tracked and shown.","helpText":"","infoUrls":[],"categoryId":"ceacf7fa-fa6e-434d-a381-e20e5245d180","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_turnoffrevisiontracking_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_collaborationsettings~l_coauthoring_l_turnoffrevisiontracking_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Specifies the list of error messages to customize.","helpText":"","infoUrls":[],"categoryId":"28ab8eed-623a-4e9b-813e-13256472dbaf","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize80","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"28ab8eed-623a-4e9b-813e-13256472dbaf","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize80_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"28ab8eed-623a-4e9b-813e-13256472dbaf","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize80_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"28ab8eed-623a-4e9b-813e-13256472dbaf","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys158","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys158_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys158_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys158_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinrecordingpresenterview","displayName":"Turn off microphone recording by default when recording a slide show (User)","description":"This policy setting allows you to set microphone recording off by default when recording a slide show.\r\n\r\nBy default, microphone recording is on the first time a user records a slide show. If the user turns off microphone recording, then microphone recording will be off the next time the slide show recording window is launched, even if PowerPoint is closed and reopened.\r\n\r\nIf you enable this policy setting, microphone recording is turned off by default. A user can turn on microphone recording when recording a slide show. But, the next time the slide show recording window is launched, microphone recording will be off by default.\r\n\r\nIf you disable or don’t configure this policy setting, the default state of microphone recording is determined by the user.\r\n\r\nNote: Enabling this policy setting also turns off camera recording by default when recording a slide show. There is a separate policy setting if you just want to turn off camera recording by default when recording a slide show.\r\n ","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinrecordingpresenterview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinrecordingpresenterview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinscreenrecorder","displayName":"Turn off audio recording for screen recording (User)","description":"This policy setting allows you to control the initial audio recording setting for a screen recording in PowerPoint. By default, audio is recorded during a screen recording.\r\n \r\nIf you enable this policy setting, audio isn’t recorded during a screen recording. But, the user can choose to turn on audio recording manually in the UI.\r\n \r\nIf you disable or don’t configure this policy setting, audio is recorded during a screen recording. The user can choose to turn off audio recording manually in the UI.","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinscreenrecorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinscreenrecorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultvideooffinrecordingpresenterview","displayName":"Turn off camera recording by default when recording a slide show (User)","description":"This policy setting allows you to set camera recording off by default when recording a slide show.\r\n\r\nBy default, camera recording is on the first time a user records a slide show. If the user turns off camera recording, then camera recording will be off the next time the slide show recording window is launched, even if PowerPoint is closed and reopened.\r\n\r\nIf you enable this policy setting, camera recording is turned off by default. A user can turn on camera recording when recording a slide show. But, the next time the slide show recording window is launched, camera recording will be off by default.\r\n\r\nIf you disable or don’t configure this policy setting, the default state of camera recording is determined by the user, unless the “Turn off microphone recording by default when recording a slide show” policy setting is enabled. Enabling that policy setting also turns off camera recording by default.\r\n ","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultvideooffinrecordingpresenterview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultvideooffinrecordingpresenterview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable specific command bar buttons and menu items in the specified applications. \r\n\r\nIf you enable this policy setting you can disable specific command bar buttons and menu items in the user interface for the selected application. The predefined list of command bar buttons and menu items you can disable becomes available to you when you enable this policy setting. \r\n\r\nIf you disable or do not configure this policy setting, the predefined list of command bar buttons and menu items are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_broadcastslideshow","displayName":"Slide Show tab | Start Slide Show | Broadcast Slide Show (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_broadcastslideshow_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_broadcastslideshow_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient","displayName":"File tab | Share | Send Using E-mail (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview","displayName":"File tab | Options | Customize Ribbon | All Commands | Web Page Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlinkppt","displayName":"Insert tab | Links | Hyperlink (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlinkppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlinkppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolslanguage","displayName":"Review tab | Language | Language (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolslanguage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolslanguage_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacrosppt","displayName":"Developer tab | Code | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacrosppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacrosppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity","displayName":"Developer tab | Code | Macro Security (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorppt","displayName":"Developer tab | Code | Visual Basic (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddressppt","displayName":"File tab | Options | Customize Ribbon | All Commands | Address (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddressppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddressppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable specific shortcut key combinations in the specified applications. \r\n\r\nIf you enable this policy setting you can disable specific shortcut keys for the selected application. The predefined list of shortcut keys you can disable becomes available to you when you enable this policy setting. \r\n\r\nIf you disable or do not configure this policy setting, the predefined list of shortcut keys are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditorppt","displayName":"Alt+F11 (Developer | Code | Visual Basic) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditorppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditorppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros","displayName":"Alt+F8 (Developer | Code | Macros) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlf5broadcastslideshow","displayName":"Ctrl+F5 (Slide Show | Start Slide Show | Broadcast Slide Show) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlf5broadcastslideshow_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlf5broadcastslideshow_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindppt","displayName":"Ctrl+F (Home | Editing | Find) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkppt","displayName":"Ctrl+K (Insert | Links | Hyperlink) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkppt_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_enablerecordingribbontab","displayName":"Turn on recording ribbon tab (User)","description":"This policy setting allows you to control the initial recording ribbon tab in PowerPoint. By default, the tab is not visible.\r\n\r\nIf you enable this policy setting, recording ribbon tab is visible. But, the user can choose to turn off the feature manually in the UI.\r\n\r\nIf you disable or don’t configure this policy setting, recording ribbon tab is not visible. The user can choose to turn on the feature manually in the UI.\r\n ","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_enablerecordingribbontab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_enablerecordingribbontab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_hidebuiltintablestyles","displayName":"Hide built in table styles (User)","description":"Hides the built in table styles for PowerPoint. By default, built-in styles are shown.","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_hidebuiltintablestyles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_hidebuiltintablestyles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation","displayName":"Check for accessibility issues while editing (User)","description":"This policy setting controls whether accessibility issues are checked for automatically while the user is editing a presentation. By default, accessibility issues aren’t checked for automatically.\r\n\r\nIf you enable this policy setting, accessibility issues are checked for automatically and users won’t be able to turn it off. The status bar will indicate if accessibility recommendations are available to make the presentation more usable by people with disabilities.\r\n\r\nIf you disable or don’t configure this policy setting, accessibility issues won’t be checked for automatically while editing a presentation. Users can turn on automatic checking by going to File > Options > Ease of Access.\r\n","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation","displayName":"Stop checking for alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that objects such as images and shapes contain alt text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that objects such as images and shapes contain alt text.\r\n\r\nIf you disable or do not configure this policy setting, objects will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsandcolumns","displayName":"Stop checking for blank table rows and columns (User)","description":"This policy setting prevents the Accessibility Checker from verifying that blank rows and columns have not been inserted into tables.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that blank rows and columns have not been inserted into tables.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for blank rows and columns and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsandcolumns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsandcolumns_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformediafilescaptions","displayName":"Stop checking for media files which might need captions (User)","description":"This policy setting prevents the Accessibility Checker from flagging media files that might need caption information.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging media files that might need caption information.\r\n\r\nIf you disable or do not configure this policy setting, presentations will be scanned for media files and the results will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformediafilescaptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformediafilescaptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformergedandsplitcells","displayName":"Stop checking for merged and split cells (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables do not have merged or split cells.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables do not have merged or split cells.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for merged and split cells and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformergedandsplitcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformergedandsplitcells_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingmeaningfulorderofobjectsonslides","displayName":"Stop checking to ensure a meaningful order of objects on slides (User)","description":"This policy setting prevents the Accessibility Checker from checking if a slide has non-placeholder objects which might be read back out of order.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking if a slide has non-placeholder objects which might be read back out of order.\r\n\r\nIf you disable or do not configure this policy setting, slides will be checked for objects which might be read back out of order and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingmeaningfulorderofobjectsonslides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingmeaningfulorderofobjectsonslides_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingpresentationsallowprogrammaticaccess","displayName":"Stop checking to ensure presentations allow programmatic access (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that presentations have not blocked programmatic access through DRM.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that presentations have not blocked programmatic access through DRM.\r\n\r\nIf you disable or do not configure this policy setting, presentations will be checked for programmatic access and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingpresentationsallowprogrammaticaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingpresentationsallowprogrammaticaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation","displayName":"Stop checking for table alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables contain alt text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables contain alt text.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation","displayName":"Stop checking for table header accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables have a header row specified.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables have a header row specified.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for header rows and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtextcontrast","displayName":"Stop checking for text color contrast (User)","description":"This policy setting prevents the Accessibility Checker from flagging text with low contrast and readability.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging text with low contrast and readability.\r\n\r\nIf you disable or do not configure this policy setting, text will be scanned for color contrast and the results will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtextcontrast_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtextcontrast_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingthatslidetitlesexist","displayName":"Stop checking that slide titles exist (User)","description":"This policy setting prevents the Accessibility Checker from verifying that every slide has a title placeholder.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that every slide has a title placeholder.\r\n\r\nIf you disable or do not configure this policy setting, slides will be checked for titles and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingthatslidetitlesexist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingthatslidetitlesexist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensureeachslidehasauniquetitle","displayName":"Stop checking to ensure each slide has a unique title (User)","description":"This policy setting prevents the Accessibility Checker from verifying that every slide has a unique title.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that every slide has a unique title.\r\n\r\nIf you disable or do not configure this policy setting, slide titles will be checked for uniqueness and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensureeachslidehasauniquetitle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensureeachslidehasauniquetitle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful","displayName":"Stop checking to ensure hyperlink text is meaningful (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_defaultcustomtab","displayName":"Show custom templates tab by default in PowerPoint on the Office Start screen and in File | New (User)","description":"This policy setting controls whether custom templates (when they exist) show as the default tab in PowerPoint on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, users will the see custom templates tab as the default tab in PowerPoint on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in PowerPoint on the Office Start screen and in File | New, unless all Office-provided templates have been disabled.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_defaultcustomtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_defaultcustomtab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_disableofficestartpowerpoint","displayName":"Disable the Office Start screen for PowerPoint (User)","description":"This policy setting controls whether the Office Start screen appears on boot for PowerPoint.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot PowerPoint.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot PowerPoint.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_disableofficestartpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_disableofficestartpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_disableslideupdate","displayName":"Disable Slide Update (User)","description":"This policy setting controls whether users can link slides in a presentation with their counterparts in a PowerPoint Slide Library.\r\n\r\nIf you enable this policy setting, PowerPoint cannot check the status of a slide in a Slide Library when a presentation with Slide Update data is opened.\r\n\r\nIf you disable or do not configure this policy setting, each time users open a presentation that contains a shared slide, PowerPoint notifies them if the slide has been updated and provides them with the opportunity to ignore the update, append a new slide to the outdated slide, or replace the outdated slide with the updated one.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_disableslideupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_disableslideupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins, or specify the file name of PowerPoint add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\PowerPoint\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\PowerPoint\\Addins.\r\n\r\nTo obtain the file name of an add-in, click the File menu in the application where the add-in is installed. Click Options, click Add-ins, and then use the Location column to determine the file name of the add-in.\r\n\r\nYou can also obtain the ProgID or the file name of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_personaltemplatespath","displayName":"Personal templates path for PowerPoint (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp","displayName":"Turn off file synchronization via SOAP over HTTP (User)","description":"This policy setting controls file synchronization via SOAP over HTTP for PowerPoint.\r\n\r\nIf you enable this policy setting, file synchronization via SOAP over HTTP is turned off for PowerPoint.\r\n\r\nIf you disable or do not configure this policy setting this policy setting, file synchronization via SOAP over HTTP is turned on for PowerPoint.\r\n\r\nNote: Turning off file synchronization via SOAP over HTTP will also prevent co-authoring and adversely affect the behavior of SharePoint Workspaces.","helpText":"","infoUrls":[],"categoryId":"7aeaf6f8-5511-4216-9483-28f432a5a08f","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_allowautoextendfordesktop","displayName":"Allow PowerPoint to also automatically extend the display when presenting on a desktop (User)","description":"This policy setting specifies whether PowerPoint can also automatically extend the display when users present on a desktop computer.\r\n\r\nIf you enable this policy setting, PowerPoint will automatically extend the display when users present on a desktop computer, if the \"Automatically extend display when presenting on a laptop or tablet\" checkbox on the UI under File | Options | Advanced | Display is checked.\r\n\r\nIf you disable or do not configure this policy setting, PowerPoint does not automatically extend the display when users present on a desktop computer, even if the \"Automatically extend display when presenting on a laptop or tablet\" checkbox on the UI under File | Options | Advanced | Display is checked.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_allowautoextendfordesktop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_allowautoextendfordesktop_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_backgroundprinting","displayName":"Print in background (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_backgroundprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_backgroundprinting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_chartreftrackingenabled","displayName":"Allow formatting and labels to track data points (User)","description":"This policy setting governs how custom formatting and data labels react to data changes in a chart.\r\n\r\nIf you enable or do not configure this policy setting, when the user creates a new presentation, custom formatting and data labels follow data points as they move or change in any chart in the workbook.\r\n\r\nIf you disable this policy setting, custom formatting and data labels do not follow data points, but instead follow data point indices.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_chartreftrackingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_chartreftrackingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_disablesettopology","displayName":"Do not allow PowerPoint to automatically extend the display when presenting on a laptop or tablet (User)","description":"This policy setting specifies whether PowerPoint automatically extends the display when users present on a laptop or tablet computer.\r\n\r\nIf you enable this policy setting, PowerPoint does not automatically extend the display when users present on a laptop or tablet computer. In addition, the \"Automatically extend display when presenting on a laptop or tablet\" checkbox on the user interface (UI) under File | Options | Advanced | Display is unchecked.\r\n\r\nIf you disable or do not configure this policy setting, PowerPoint automatically extends the display when users present on a laptop or tablet computer. Users can change this behavior by unchecking the \"Automatically extend display when presenting on a laptop or tablet\" checkbox on the UI under File | Options | Advanced | Display","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_disablesettopology_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_disablesettopology_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes","displayName":"Display enterprise themes (User)","description":"This policy allows you to display enterprise themes in the ribbon galleries. You can also name the category for the themes, and you can hide all the Office in-box and connected gallery themes.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesdontshowothers","displayName":"Only show enterprise themes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesdontshowothers_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesdontshowothers_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesgallerytitle","displayName":"Enterprise themes category title (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_donotdisturb","displayName":"Set user availablity to Do not Disturb during Slide Show (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_donotdisturb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_donotdisturb_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_draganddroptextediting","displayName":"Allow text to be dragged and dropped (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_draganddroptextediting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_draganddroptextediting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_endwithblackslide","displayName":"End with black slide (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_endwithblackslide_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_endwithblackslide_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_maximumnumberofundos","displayName":"Maximum number of undos (User)","description":"Specifies the maximum number of undo levels.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_maximumnumberofundos_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_maximumnumberofundos_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_maximumnumberofundos_l_maximumnumberofundos2","displayName":"Maximum number of undos (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_popupmenuonrightmouseclick","displayName":"Show menu on right mouse click (User)","description":"Checked: Checks the option ''Show menu on right mouse click''. | Unchecked: Unchecks the option ''Show menu on right mouse click''.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_popupmenuonrightmouseclick_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_popupmenuonrightmouseclick_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printinsertedobjectsatprinterresolution","displayName":"Print inserted objects at printer resolution (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printinsertedobjectsatprinterresolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printinsertedobjectsatprinterresolution_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printtruetypefontsasgraphics","displayName":"Print TrueType fonts as graphics (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printtruetypefontsasgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printtruetypefontsasgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist","displayName":"Number of presentations in the Recent Presentations list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Presentations list that appears when users click Open on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Presentations list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Presentations list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist_l_sizeofrecentlyusedfilelist","displayName":"Size of recently used file list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_showpopupmenubutton","displayName":"Show popup toolbar (User)","description":"Checked: Checks the option ''Show popup toolbar''. | Unchecked: Unchecks the option ''Show popup toolbar''.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_showpopupmenubutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_showpopupmenubutton_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_usesmartcutandpaste","displayName":"Use smart cut and paste (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_usesmartcutandpaste_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_usesmartcutandpaste_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_verticalruler","displayName":"Show vertical ruler (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_verticalruler_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_verticalruler_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_whenselectingautomaticallyselectentireword","displayName":"When selecting, automatically select entire word (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_whenselectingautomaticallyselectentireword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_whenselectingautomaticallyselectentireword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_windowsintaskbar","displayName":"Show all windows in the Taskbar (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_windowsintaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_windowsintaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_resizegraphicstofitbrowserwindow","displayName":"Resize graphics to fit browser window (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_resizegraphicstofitbrowserwindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_resizegraphicstofitbrowserwindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_showslideanimationwhilebrowsing","displayName":"Show slide animation while browsing (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_showslideanimationwhilebrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_showslideanimationwhilebrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation","displayName":"Slide navigation (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_addslidenavigationcontrols","displayName":"Add slide navigation controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_addslidenavigationcontrols_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_addslidenavigationcontrols_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors","displayName":"Colors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_browsercolors","displayName":"Browser colors","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_presentationschemetextcolor","displayName":"Presentation colors (text color)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_presentationschemeaccentcolor","displayName":"Presentation colors (accent color)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_whitetextonblack","displayName":"White text on black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_blacktextonwhite","displayName":"Black text on white","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"f66fb7e4-a968-4969-b627-f99aaad0dfc3","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_allowselectionfloaties","displayName":"Show Mini Toolbar on selection (User)","description":"Disabling this policy setting will result in Mini Toolbar not being displayed on text selection. By default, Mini Toolbar on selection is enabled and its visibility can be changed via a setting in the PowerPoint Options dialog box.","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_allowselectionfloaties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_allowselectionfloaties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablegallerypreviews","displayName":"Enable Live Preview (User)","description":"Shows or hides the Live Preview that appear when using Galleries that support previews. Live Preview shows how a command would be applied without actually applying it to the document.","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablegallerypreviews_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablegallerypreviews_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disableincrementaldownload","displayName":"Wait to show users a cloud-based presentation until all content is downloaded (User)","description":"\r\nThis policy setting allows you to control whether PowerPoint waits until all content is downloaded before showing a presentation to the user. This policy setting applies to presentations that are opened from a cloud-based location, such as OneDrive Personal, OneDrive for Business, or SharePoint Online.\r\n\r\nBy default, when the user opens a cloud-based presentation in PowerPoint, the user can view the presentation while other content, such as images or video, continues to download. But, some functionality, such as editing and presenting, is limited or not available until the entire contents of the presentation are downloaded.\r\n\r\nIf you enable this policy setting, PowerPoint will wait, when opening a cloud-based presentation, until the entire contents of the presentation are downloaded before showing the presentation to the user.\r\n\r\nYou may want to enable this policy setting if you have add-ins or automated processes that rely on the entire contents of the presentation being available and fully editable as soon as the presentation is shown.\r\n\r\nIf you disable or don't configure this setting, PowerPoint opens cloud-based files more quickly, so the user can start viewing the presentation while the other content downloads.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disableincrementaldownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disableincrementaldownload_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablelivesubtitles","displayName":"Don’t allow the use of Live Subtitles (User)","description":"\r\nThis policy setting controls whether users can turn on Live Subtitles during a presentation. By default, Live Subtitles are off but can be turned on by users.\r\n\r\nIf you enable this policy setting, users can't turn on Live Subtitles during a presentation.\r\n\r\nIf you disable or don't configure this policy setting, users can turn on Live Subtitles.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablelivesubtitles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablelivesubtitles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablequickstarter","displayName":"Turn off QuickStarter (User)","description":"This policy setting controls whether QuickStarter is available to users. By default, QuickStarter is available to users if they meet the language and region requirements for the feature.\r\n\r\nIf you enable this policy setting, QuickStarter won’t be available to users.\r\n\r\nIf you disable or don’t configure this policy setting, QuickStarter will be available to users if they meet the language and region requirements for the feature.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablequickstarter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablequickstarter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablesummaryslidesectionzoom","displayName":"Don’t allow Summary Zoom, Slide Zoom, and Section Zoom in a PowerPoint presentation (User)","description":"This policy setting controls whether users can insert and playback a Summary Zoom, a Slide Zoom, or a Section Zoom in a PowerPoint presentation. By default, users can use these types of Zoom in a presentation.\r\n\r\nIf you enable this policy setting, users can’t use these types of Zoom in a presentation.\r\n\r\nIf you disable or don’t configure this policy setting, users can use these types of Zoom in a presentation.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablesummaryslidesectionzoom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablesummaryslidesectionzoom_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_promptifpowerpointisnotdefault","displayName":"Prompt the user if PowerPoint is not the default application for its file extensions (User)","description":"This policy setting specifies whether PowerPoint prompts users to change their file extension associations for any file types that are no longer associated with PowerPoint.\r\n\r\nIf you enable this policy setting, when users start PowerPoint, they are not prompted to change file extensions for any files that are no longer associated with PowerPoint. In addition, the checkbox on the user interface (UI) under File |Options | General | Start up options | Tell me is unchecked.\r\n\r\nIf you disable or do not configure this policy setting, when users start PowerPoint, they are prompted to change file extensions for any files that are no longer associated with PowerPoint. Users can change this behavior either by selecting the checkbox displayed in the prompt, or by selecting the UI checkbox under File |Options | General | Start up options | Tell me (which is selected by default).\r\n","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_promptifpowerpointisnotdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_promptifpowerpointisnotdefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions","displayName":"[Deprecated] PowerPoint Designer Options (User)","description":"Important: This policy setting is no longer supported and will be removed in a future release. Please use the \"PowerPoint Designer Options\" policy setting from the PowerPoint policy set instead.\r\n\r\nThis policy setting allows an administrator to enable or disable PowerPoint Designer","helpText":"","infoUrls":[],"categoryId":"77ca5e78-a1fe-456e-9814-034b1ea2658d","categoryName":"PowerPoint Designer","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_l_powerpointdesigneroptions","displayName":"PowerPoint Designer options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"77ca5e78-a1fe-456e-9814-034b1ea2658d","categoryName":"PowerPoint Designer","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_l_powerpointdesigneroptions_0","displayName":"Disable PowerPoint Designer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_l_powerpointdesigneroptions_73187","displayName":"Enable PowerPoint Designer","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_checkspellingasyoutype","displayName":"Check spelling as you type (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_checkspellingasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_checkspellingasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_enablecontextualspellingpolicy","displayName":"Check grammar with spelling (User)","description":"Enabling this policy to turn contextual spelling on by default.","helpText":"","infoUrls":[],"categoryId":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_enablecontextualspellingpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_enablecontextualspellingpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofitbodytexttoplaceholder","displayName":"AutoFit body text to placeholder (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b792508d-da03-4174-bcf1-666d128ee8ad","categoryName":"AutoFormat as you type","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofitbodytexttoplaceholder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofitbodytexttoplaceholder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofittitletexttoplaceholder","displayName":"AutoFit title text to placeholder (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b792508d-da03-4174-bcf1-666d128ee8ad","categoryName":"AutoFormat as you type","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofittitletexttoplaceholder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofittitletexttoplaceholder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_replacestraightquoteswithsmartquotes","displayName":"Replace straight quotes with smart quotes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b792508d-da03-4174-bcf1-666d128ee8ad","categoryName":"AutoFormat as you type","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_replacestraightquoteswithsmartquotes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_replacestraightquoteswithsmartquotes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_defaultfilelocation","displayName":"Default file location (User)","description":"Specifies the default location for presentation files.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_defaultfilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_defaultfilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_defaultfilelocation_l_defaultfilelocation0","displayName":"Default file location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_disablepackageforcd","displayName":"Disable Package For CD (User)","description":"Check to Disable Package for CD; Uncheck to Enable Package for CD. Shows or hides the File tab | Save & Send | Package Presentation for CD command. Package for CD allows the user to package and burn presentations onto CD for portable viewing even when PowerPoint is not installed.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_disablepackageforcd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_disablepackageforcd_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_keeplastautosavedversions","displayName":"Keep the last AutoSaved versions of files for the next session (User)","description":"This policy setting determines whether PowerPoint keeps the last AutoSaved version of a file if a user closes a file without saving it. (Note: AutoSave applies only when AutoRecover is enabled.)\r\n\r\nIf you enable or do not configure this policy setting, PowerPoint keeps the last AutoSaved version of the file and makes it available to the user the next time the file is opened if the user closes a file without saving it.\r\n\r\nIf you disable this policy setting, PowerPoint does not keep the last AutoSaved version of the file if the user closes a file without saving it.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_keeplastautosavedversions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_keeplastautosavedversions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo","displayName":"Save AutoRecover info (User)","description":"Checked: Checks the option ''Save AutoRecover info''. | Unchecked: Unchecks the option ''Save AutoRecover info''.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_l_autorecoversavefrequencyminutes","displayName":"AutoRecover save frequency (minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_l_autorecoversavelocation","displayName":"AutoRecover save location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_l_enablesaveautorecoverinfo","displayName":"Enable save AutoRecover info (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_l_enablesaveautorecoverinfo_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_l_enablesaveautorecoverinfo_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas","displayName":"Default file format (User)","description":"This policy setting governs the default format for new presentation files that users create.\r\n \r\nIf you enable this policy setting, when a user creates a new blank presentation, it is in the specified default format. Users may still override the default and specify a specific format when they create a presentation.\r\n\r\nIf you disable or do not configure this policy setting, PowerPoint Presentation is the default option.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_l_savepowerpointfilesas1","displayName":"Save PowerPoint files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_l_savepowerpointfilesas1_27","displayName":"PowerPoint Presentation (*.pptx)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_l_savepowerpointfilesas1_28","displayName":"PowerPoint Macro-Enabled Presentation (*.pptm)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_l_savepowerpointfilesas1_0","displayName":"PowerPoint 97-2003 Presentation (*.ppt)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_savepowerpointfilesas_l_savepowerpointfilesas1_52","displayName":"OpenDocument Presentation (*.odp)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_turnofffileformatcompatiblitydialogforodp","displayName":"Suppress file format compatibility dialog box for OpenDocument Presentation format (User)","description":"This policy setting allows you to enable or disable the file format compatibility dialog box when saving a file as an OpenDocument presentation file in Microsoft PowerPoint.\r\n\r\nIf you enable this policy, the file format compatibility dialog is displayed whenever you save as an OpenDocument presentation file in PowerPoint.\r\n\r\nIf you disable this policy, the file format compatibility dialog is not displayed when you save as an OpenDocument presentation file in PowerPoint.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_turnofffileformatcompatiblitydialogforodp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_turnofffileformatcompatiblitydialogforodp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt","displayName":"Scan encrypted macros in PowerPoint Open XML presentations (User)","description":"This policy setting controls whether encrypted macros in Open XML presentations are required to be scanned with anti-virus software before being opened.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n- Scan encrypted macros: encrypted macros are disabled unless anti-virus software is installed. Encrypted macros are scanned by your anti-virus software when you attempt to open an encrypted presentation that contains macros.\r\n- Scan if anti-virus software available: if anti-virus software is installed, scan the encrypted macros first before allowing them to load. If anti-virus software is not available, allow encrypted macros to load.\r\n- Load macros without scanning: do not check for anti-virus software and allow macros to be loaded in an encrypted file.\r\n\r\nIf you disable or do not configure this policy setting, the behavior will be similar to the \"Scan encrypted macros\" option.","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt_l_determinewhethertoforceencryptedpptdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt_l_determinewhethertoforceencryptedpptdropid_0","displayName":"Scan encrypted macros (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt_l_determinewhethertoforceencryptedpptdropid_1","displayName":"Scan if anti-virus software available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_determinewhethertoforceencryptedppt_l_determinewhethertoforceencryptedpptdropid_2","displayName":"Load macros without scanning","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_downloadimages","displayName":"Unblock automatic download of linked images (User)","description":"This policy setting determines whether PowerPoint automatically downloads links from external sources.\r\n\r\nIf you enable this policy setting, PowerPoint will load images saved in remote locations.\r\n\r\nIf you disable or do not configure this policy setting, when PowerPoint opens a presentation it does not display any linked images saved on a different computer unless the presentation itself is saved in a trusted location (as configured in the Trust Center).","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_downloadimages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_downloadimages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_makehiddenmarkupvisible","displayName":"Make hidden markup visible (User)","description":"This policy setting controls whether hidden markup is visible when users open PowerPoint files in standard or HTML format.\r\n\r\nIf you enable this policy setting, PowerPoint ignores this flag when opening a file, and always displays any markup present in the file. In addition, when saving a file, PowerPoint sets the flag to display markup when the presentation is next opened.\r\n\r\nIf you disable this policy setting, PowerPoint sets the flag according to the state of the \"Show Markup\" option on the Review tab of the Ribbon when it saves presentations in standard or HTML format. In addition, PowerPoint enables or disables the \"Show Markup\" option according to the way the flag is set when it opens files, which means that a presentation saved with hidden markup is opened with the markup still hidden.\r\n\r\nIf you disable this policy setting, the behavior is the equivalent of Enabled.","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_makehiddenmarkupvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_makehiddenmarkupvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms","displayName":"Run Programs (User)","description":"This policy setting controls the prompting and activation behavior for the \"Run Programs\" option for action buttons in PowerPoint.\r\n\r\nIf you enable this policy setting, you can choose from three options to control how the \"Run Programs\" option functions:\r\n\r\n- Disable (don't run any programs). If users click an action button with the \"Run Programs\" action assigned to it, nothing will happen. This option enforces the default configuration in PowerPoint.\r\n\r\n- Enable (prompt user before running). If users click an action button with the \"Run Programs\" action assigned to it, PowerPoint will prompt them to continue before running the program.\r\n\r\n- Enable all (run without prompting). If users click an action button with the \"Run Programs\" action assigned to it. PowerPoint will run the program automatically, without prompting.\r\n\r\nIf you disable or do not configure this policy setting, if users click an action with the \"Run Programs\" action assigned to it, nothing will happen. This behavior is the same as Enabled -- Disable (don't run any programs).","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty_0","displayName":"disable (don't run any programs)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty_1","displayName":"enable (prompt user before running)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty_2","displayName":"enable all (run without prompting)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_turnofffilevalidation","displayName":"Turn off file validation (User)","description":"This policy setting allows you turn off the file validation feature.\r\n\r\nIf you enable this policy setting, file validation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, file validation will be turned on. Office Binary Documents (97-2003) are checked to see if they conform against the file format schema before they are opened.","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_turnofffilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_turnofffilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setparametersforcngcontext","displayName":"Set parameters for CNG context (User)","description":"This policy setting allows you to specify the encryption parameters that should be used for the CNG context. \r\n\r\nIf you enable this policy setting, the parameters specified will be passed to the CNG context.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG values will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setparametersforcngcontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setparametersforcngcontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm","displayName":"Specify CNG random number generator algorithm (User)","description":"This policy setting allows you to configure the CNG random number generator to use.\r\n\r\nIf you enable this policy setting, the random number generator specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default random number generator will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_l_specifycngrandomnumbergeneratoralgorithmid","displayName":"Random number generator: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngsaltlength","displayName":"Specify CNG salt length (User)","description":"This policy setting allows you to specific the number of bytes of salt that should be used.\r\n\r\nIf you enable this policy setting, the bytes specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default length or 16 will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngsaltlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngsaltlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility","displayName":"Specify encryption compatibility (User)","description":"This policy setting allows you to specify the encrypted database compatibility.\r\n\r\nIf you enable this policy setting, the compatibility format specified will be applied during encryption for new files\r\n- Use legacy format\r\n- Use next generation format\r\n- All files save with next generation: All files save with the next generation format\r\n\r\nIf you disable or do not configure this policy setting, the default setting, \"Use next generation format,\" will be applied.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_0","displayName":"Use legacy format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_1","displayName":"Use next generation format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_2","displayName":"All files save with next generation","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_usenewkeyonpasswordchange","displayName":"Use new key on password change (User)","description":"This policy setting allows you to specify if a new encryption key is used when the password is changed.\r\n\r\nIf you enable or do not configure this policy setting, a new intermediate key is generated when the password is changed. This causes any extra key encryptors to be removed when the file is saved.\r\n\r\nIf you disable this policy setting, a new intermediate key is not generated when the password is changed.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_usenewkeyonpasswordchange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_usenewkeyonpasswordchange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User) (Deprecated)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve","displayName":"Set maximum number of trust records to preserve (User)","description":"This policy setting allows you to specify the maximum number of trust records to preserve when the purge task detects that this application has trusted more than the number of trusted documents set by the \"Set maximum number of trusted documents\" policy setting.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of trust records to preserve, with an upper limit of 20000. Due to performance reasons, it is not recommended to set it to the upper limit.\r\n\r\nIf you disable or you do not configure this policy setting, the default value for of 400 is used.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_l_setmaximumnumberoftrustrecordstopreservespinid","displayName":"Maximum to preserve: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject","displayName":"Trust access to Visual Basic Project (User)","description":"This policy setting controls whether automation clients such as Microsoft Visual Studio 2005 Tools for Microsoft Office (VSTO) can access the Visual Basic for Applications project system in the specified applications. VSTO projects require access to the Visual Basic for Applications project system in Excel, PowerPoint, and Word, even though the projects do not use Visual Basic for Applications. Design-time support of controls in both Visual Basic and C# projects depends on the Visual Basic for Applications project system in Word and Excel.\r\n\r\nIf you enable this policy setting, VSTO and other automation clients can access the Visual Basic for Applications project system in the specified applications. Users will not be able to change this behavior through the \"Trust access to the VBA project object model\" user interface option under the Macro Settings section of the Trust Center.\r\n\r\nIf you disable this policy setting, VSTO does not have programmatic access to VBA projects. In addition, the \"Trust access to the VBA project object model\" check box is cleared and users cannot change it. Note: Disabling this policy setting prevents VSTO projects from interacting properly with the VBA project system in the selected application.\r\n\r\nIf you do not configure this policy setting, automation clients do not have programmatic access to VBA projects. Users can enable this by selecting the \"Trust access to the VBA project object model\" in the \"Macro Settings\" section of the Trust Center. However, doing so allows macros in any documents the user opens to access the core Visual Basic objects, methods, and properties, which represents a potential security hazard.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocuments","displayName":"Turn off trusted documents (User)","description":"This policy setting allows you to turn off the trusted documents feature. The trusted documents feature allows users to always enable active content in documents such as macros, ActiveX controls, data connections, etc. so that they are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.\r\n\r\nIf you enable this policy setting, you will turn off the trusted documents feature. Users will receive a security prompt every time a document containing active content is opened.\r\n\r\nIf you disable or do not configure this policy setting, documents will be trusted when users enable content for a document, and users will not receive a security prompt.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork","displayName":"Turn off Trusted Documents on the network (User)","description":"This policy setting allows you to turn off the trusted documents feature for documents opened from the network.\r\n\r\nIf you enable this policy setting, users will always see security notifications for active content such as macros, ActiveX controls, data connections, etc. for documents opened from the network.\r\n\r\nIf you disable or do not configure this policy setting, the trusted documents feature allows users to always allow active content in documents such as macros, ActiveX controls, data connections, etc. so that users are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty3","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty3_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty3_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty3_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty3_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters","displayName":"Graphic Filters (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_l_graphicfiltersdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_l_graphicfiltersdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_l_graphicfiltersdropid_1","displayName":"Save blocked","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint","displayName":"Legacy converters for PowerPoint (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_l_legacyconvertersforpowerpointdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint","displayName":"Microsoft Office Open XML converters for PowerPoint (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles","displayName":"OpenDocument Presentation files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentpresentationfiles_l_opendocumentpresentationfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles","displayName":"Outline files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles_l_outlinefilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles_l_outlinefilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles_l_outlinefilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_outlinefiles_l_outlinefilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters","displayName":"PowerPoint beta converters (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetaconverters_l_powerpointbetaconvertersdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles","displayName":"PowerPoint beta files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpointbetafiles_l_powerpointbetafilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior","displayName":"Set default file block behavior (User)","description":"This policy setting allows you to determine if users can open, view, or edit Word files.\r\n\r\nIf you enable this policy setting, you can set one of these options:\r\n- Blocked files are not opened\r\n- Blocked files open in Protected View and can not be edited\r\n- Blocked files open in Protected View and can be edited\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the same as the \"Blocked files are not opened\" setting. Users will not be able to open blocked files.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_0","displayName":"Blocked files are not opened","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_1","displayName":"Blocked files open in Protected View and can not be edited","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_2","displayName":"Blocked files open in Protected View and can be edited","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages","displayName":"Web Pages (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview","displayName":"Do not open files from the Internet zone in Protected View (User)","description":"This policy setting allows you to determine if files downloaded from the Internet zone open in Protected View.\r\n\r\nIf you enable this policy setting, files downloaded from the Internet zone do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files downloaded from the Internet zone open in Protected View.","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview","displayName":"Do not open files in unsafe locations in Protected View (User)","description":"This policy setting lets you determine if files located in unsafe locations will open in Protected View. If you have not specified unsafe locations, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders are considered unsafe locations.\r\n\r\nIf you enable this policy setting, files located in unsafe locations do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files located in unsafe locations open in Protected View.","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview","displayName":"Open files on local Intranet UNC in Protected View (User)","description":"This policy setting lets you determine if files on local Intranet UNC file shares open in Protected View.\r\n\r\nIf you enable this policy setting, files on local Intranet UNC file shares open in Protected View if their UNC paths appear to be within the Internet zone.\r\n\r\nIf you disable or do not configure this policy setting, files on Intranet UNC file shares do not open in Protected View if their UNC paths appear to be within the Internet zone.","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails","displayName":"Set document behavior if file validation fails (User)","description":"This policy setting controls how Office handles documents when they fail file validation. \r\n\r\nIf you enable this policy setting, you can configure the following options for files that fail file validation:\r\n\r\n- Block files completely. Users cannot open the files.\r\n- Open files in Protected View and disallow edit. Users cannot edit the files. This is also how Office handles the files if you disable this policy setting.\r\n- Open files in Protected View and allow edit. Users can edit the files. This is also how Office handles the files if you do not configure this policy setting.\r\n\r\nIf you disable this policy setting, Office follows the \"Open files in Protected View and disallow edit\" behavior.\r\n\r\nIf you do not configure this policy setting, Office follows the \"Open files in Protected View and allow edit\" behavior.","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_0","displayName":"Block files","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_1","displayName":"Open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3","displayName":"Checked: Allow edit. Unchecked: Do not allow edit. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook","displayName":"Turn off Protected View for attachments opened from Outlook (User)","description":"This policy setting allows you to determine if PowerPoint files in Outlook attachments open in Protected View.\r\n\r\nIf you enable this policy setting, Outlook attachments do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, Outlook attachments open in Protected View.","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork","displayName":"Allow Trusted Locations on the network (User)","description":"This policy setting controls whether trusted locations on the network can be used.\r\n\r\nIf you enable this policy setting, users can specify trusted locations on network shares or in other remote locations that are not under their direct control by clicking the \"Add new location\" button in the Trusted Locations section of the Trust Center. Content, code, and add-ins are allowed to load from trusted locations with minimal security and without prompting the user for permission.\r\n\r\nIf you disable this policy setting, the selected application ignores any network locations listed in the Trusted Locations section of the Trust Center. \r\n\r\nIf you also deploy Trusted Locations via Group Policy, you should verify whether any of them are remote locations. If any of them are remote locations and you do not allow remote locations via this policy setting, those policy keys that point to remote locations will be ignored on client computers.\r\n\r\nDisabling this policy setting does not delete any network locations from the Trusted Locations list, but causes disruption for users who add network locations to the Trusted Locations list. Users are also prevented from adding new network locations to the Trusted Locations list in the Trust Center. We recommended that you do not enable this policy setting (as the \"Allow Trusted Locations on my network (not recommended)\" check box also states). Therefore, in practice, it should be possible to disable this policy setting in most situations without causing significant usability issues for most users.\r\n\r\nIf you do not enable this policy setting, users can select the \"Allow Trusted Locations on my network (not recommended)\" check box if desired and then specify trusted locations by clicking the \"Add new location\" button.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders7","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders7_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders7_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_datecolon5","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_descriptioncolon6","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_pathcolon4","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders11","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders11_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders11_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_datecolon9","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_descriptioncolon10","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_pathcolon8","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders15","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders15_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders15_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_datecolon13","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_descriptioncolon14","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_pathcolon12","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders19","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders19_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders19_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_datecolon17","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_descriptioncolon18","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_pathcolon16","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders23","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders23_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders23_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon21","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_descriptioncolon22","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_pathcolon20","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_datecolon25","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_descriptioncolon26","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_pathcolon24","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders31","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders31_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders31_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_datecolon29","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_descriptioncolon30","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_pathcolon28","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders35","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders35_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders35_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_datecolon33","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders39","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders39_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders39_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_descriptioncolon38","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_pathcolon36","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11","displayName":"Trusted Location #11 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders43","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders43_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders43_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_descriptioncolon42","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_pathcolon40","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders47","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders47_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_datecolon45","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_descriptioncolon46","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_pathcolon44","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders51","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders51_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_datecolon49","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_descriptioncolon50","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_pathcolon48","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders55","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders55_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders55_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_descriptioncolon54","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders59","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders59_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_datecolon57","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_descriptioncolon58","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_pathcolon56","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders63","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders63_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders63_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_datecolon61","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_pathcolon60","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders67","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders67_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders67_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_pathcolon64","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders71","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders71_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders71_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_datecolon69","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_descriptioncolon70","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_pathcolon68","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders75","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders75_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders75_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_datecolon73","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_descriptioncolon74","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_pathcolon72","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders79","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders79_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders79_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_datecolon77","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_descriptioncolon78","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_pathcolon76","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles","displayName":"PowerPoint 2007 and later presentations, shows, templates, themes and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles","displayName":"PowerPoint 97-2003 presentations, shows, templates and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v3~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingsectionname","displayName":"Stop checking for Section with valid name (User)","description":"This policy setting prevents the Accessibility Checker from flagging section with default/untitled name.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging section with default/untitled name.\r\n\r\nIf you disable or do not configure this policy setting, section will be scanned for valid name and the results will appear in the Accessibility Checker.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v3~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingsectionname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v3~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingsectionname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v3~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckinguniquesectionname","displayName":"Stop checking for section with unique name (User)","description":"This policy setting prevents the Accessibility Checker from verifying that every section has a unique name.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that every section has a unique name.\r\n\r\nIf you disable or do not configure this policy setting, sections will be checked for unique names and any issues will appear in the Accessibility Checker.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v3~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckinguniquesectionname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v3~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckinguniquesectionname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v4~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_enablemoderncommentscreatenew","displayName":"Use modern comments in PowerPoint (User)","description":"\r\nThis policy setting controls whether modern comments are used in PowerPoint. For more information about modern comments and when to enable this setting, see https://go.microsoft.com/fwlink/p/?linkid=2116065.\r\n\r\nIf you enable this policy setting, when a user adds comments to a new file or a file without comments, the new comments that are added will be modern comments. If users have a version of PowerPoint that doesn’t support modern comments, a notification appears directing them to use PowerPoint for the web to view modern comments in files that have them.\r\n\r\nIf you disable this policy setting, users will continue to see the previous commenting experience for new files and existing files that do not have any modern comments. Users will still be able to read files that already have modern comments in them if they have a version of PowerPoint that supports modern comments.\r\n\r\nFor information about what happens when you don't configure this policy setting, see https://go.microsoft.com/fwlink/p/?linkid=2116065.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v4~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_enablemoderncommentscreatenew_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v4~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_enablemoderncommentscreatenew_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions","displayName":"OLE Active Content (User)","description":"This policy setting controls the prompting and activation behavior for the \"OLE Active Content\" option in PowerPoint.\r\n\r\nIf you enable this policy setting, you can choose from three options to control how the \"OLE Active Content\" option functions:\r\n\r\n- Disable (don't activate any OLE Active Content). If users click an action button with the \"Object action\" action assigned to it, nothing will happen.\r\n\r\n- Enable (prompt user before activating OLE Active Content). If users click an action button with the \"Object action\" action assigned to it, PowerPoint will prompt them to continue before activating the action. This option enforces the default configuration in PowerPoint.\r\n\r\n- Enable all (allow activating OLE Active Content without prompting). If users click an action button with the \"Object action\" action assigned to it. PowerPoint will activate the action automatically, without prompting.\r\n\r\nIf you do not configure this policy setting, PowerPoint follows the Enable (prompt user before activating OLE Active Content) option.","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions_l_empty_0","displayName":"disable (don't allow activating OLE Active Content)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions_l_empty_1","displayName":"enable (prompt user before activating OLE Active Content)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v5~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_oleactions_l_empty_2","displayName":"enable all (allow activating OLE Active Content without prompting)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser","displayName":"List of Approved USB-connected print devices (User)","description":"\r\n\r\n This setting is a component of the Device Control Printing Restrictions. To use this setting, enable Device Control Printing by enabling the \"Enable Device Control Printing Restrictions\" setting.\r\n\r\n When Device Control Printing is enabled, the system uses the specified list of vid/pid values to determine if the current USB connected printer is approved for local printing.\r\n\r\n Type all the approved vid/pid combinations (separated by commas) that correspond to approved USB printer models. When a user tries to print to a USB printer queue the device vid/pid will be compared to the approved list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-approvedusbprintdevicesuser"],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser_approvedusbprintdevices_list","displayName":"vid/pid (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":null},{"id":"user_vendor_msft_policy_config_printers_enabledevicecontroluser","displayName":"Enable Device Control Printing Restrictions (User)","description":"\r\n Determines whether Device Control Printing Restrictions are enforced for printing on this computer.\r\n\r\n By default, there are no restrictions to printing based on connection type or printer Make/Model.\r\n\r\n If you enable this setting, the computer will restrict printing to printer connections on the corporate network or approved USB-connected printers.\r\n\r\n If you disable this setting or do not configure it, there are no restrictions to printing based on connection type or printer Make/Model.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-enabledevicecontroluser"],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_enabledevicecontroluser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_enabledevicecontroluser_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user","displayName":"Point and Print Restrictions (User)","description":"This policy setting controls the client Point and Print behavior, including the security prompts for Windows Vista computers. The policy setting applies only to non-Print Administrator clients, and only to computers that are members of a domain.\n\n If you enable this policy setting:\n -Windows XP and later clients will only download print driver components from a list of explicitly named servers. If a compatible print driver is available on the client, a printer connection will be made. If a compatible print driver is not available on the client, no connection will be made.\n -You can configure Windows Vista clients so that security warnings and elevated command prompts do not appear when users Point and Print, or when printer connection drivers need to be updated.\n\n If you do not configure this policy setting:\n -Windows Vista client computers can point and print to any server.\n -Windows Vista computers will show a warning and an elevated command prompt when users create a printer connection to any server using Point and Print.\n -Windows Vista computers will show a warning and an elevated command prompt when an existing printer connection driver needs to be updated.\n -Windows Server 2003 and Windows XP client computers can create a printer connection to any server in their forest using Point and Print.\n\n If you disable this policy setting:\n -Windows Vista client computers can create a printer connection to any server using Point and Print.\n -Windows Vista computers will not show a warning or an elevated command prompt when users create a printer connection to any server using Point and Print.\n -Windows Vista computers will not show a warning or an elevated command prompt when an existing printer connection driver needs to be updated.\n -Windows Server 2003 and Windows XP client computers can create a printer connection to any server using Point and Print.\n -The \"Users can only point and print to computers in their forest\" setting applies only to Windows Server 2003 and Windows XP SP1 (and later service packs).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-pointandprintrestrictions-user"],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationoninstall_enum","displayName":"When installing drivers for a new connection: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationoninstall_enum_0","displayName":"Show warning and elevation prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationoninstall_enum_1","displayName":"Show warning only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationonupdate_enum","displayName":"When updating drivers for an existing connection: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationonupdate_enum_0","displayName":"Show warning and elevation prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationonupdate_enum_1","displayName":"Show warning only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedforest_chk","displayName":"Users can only point and print to machines in their forest (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedforest_chk_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedforest_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedservers_chk","displayName":"Users can only point and print to these servers: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedservers_chk_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedservers_chk_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedservers_edit","displayName":"Enter fully qualified server names separated by semicolons (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":null},{"id":"user_vendor_msft_policy_config_privacy_disableprivacyexperience","displayName":"Disable Privacy Experience (User)","description":"Enabling this policy prevents the privacy experience from launching during user logon for new and upgraded users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#disableprivacyexperience"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"user_vendor_msft_policy_config_privacy_disableprivacyexperience_0","displayName":"Disabled","description":"Allow the 'choose privacy settings for your device' screen for a new user during their first logon or when an existing user logs in for the first time after an upgrade.","helpText":null},{"id":"user_vendor_msft_policy_config_privacy_disableprivacyexperience_1","displayName":"Enabled","description":"Do not allow the 'choose privacy settings for your device' screen when a new user logs in or an existing user logs in for the first time after an upgrade.","helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_defaultcustomtab","displayName":"Show custom templates tab by default in Project on the Office Start screen and in File | New (User)","description":"This policy setting controls whether custom templates (when they exist) show as the default tab in Project on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, users will the see custom templates tab as the default tab in Project on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Project on the Office Start screen and in File | New, unless all Office-provided templates have been disabled.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_defaultcustomtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_defaultcustomtab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_disableofficestartproject","displayName":"Disable the Office Start screen for Project (User)","description":"This policy setting controls whether the Office Start screen appears on boot for Project.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot Project.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot Project.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_disableofficestartproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_disableofficestartproject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\MS Project\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\MS Project\\Addins.\r\n\r\nYou can also obtain the ProgID of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength","displayName":"Most Recently Used Template List Length (User)","description":"This setting determines the length of the recently used templates list in the New Document task pane (File New...). The maximum value is 9 and the minimum value is 0. This setting applies only applies to Project.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength_l_mrutemplatelistlength39","displayName":"Most Recently Used Template List Length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath","displayName":"Personal templates path for Project (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"8e48532a-ff0e-4422-82e2-6956b6786005","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjautocalc","displayName":"Automatic Calculation (User)","description":"Specifies that calculations should be done automatically as soon as a change is made.\r\n\r\nIf you enable this setting, calculations will be made after every change to the project.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"ed137c3d-d7bc-48f3-ad86-ff194fc6820d","categoryName":"Calculation options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjautocalc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjautocalc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjcalcall","displayName":"Calculate all open projects (User)","description":"Specifies that Project should recalculate all open projects.\r\n\r\nIf you enable this setting, all open projects will be recalculated anytime Project does a calculation.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"ed137c3d-d7bc-48f3-ad86-ff194fc6820d","categoryName":"Calculation options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjcalcall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjcalcall_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjactualcostscalc","displayName":"Actual costs are always calculated by Microsoft Project (User)","description":"Specifies that Project calculates actual costs automatically, based upon resource rates, per-use resource costs, and fixed task costs.\r\n\r\nIf you enable this setting, Project will automatically calculate actual costs.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjactualcostscalc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjactualcostscalc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmovecompleted","displayName":"And move end of completed parts forward to status date (User)","description":"Moves the completed portion of a task forward to finish at the status date.\r\n\r\nIf you enable this setting, the completed portion of the task moves forward to finish at the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmovecompleted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmovecompleted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmoveremaining","displayName":"And move start of remaining parts back to status date (User)","description":"Moves the remaining portion of a task back to start at the status date.\r\n\r\nIf you enable this setting, the remaining portion of the task moves back to start at the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmoveremaining_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmoveremaining_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcalcmultiplecriticalpaths","displayName":"Calculate multiple critical paths (User)","description":"Specifies that Project should calculate and display a critical path for each independent network of tasks within the project.\r\n\r\nIf you enable this setting, Project will calculate multiple critical paths.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcalcmultiplecriticalpaths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcalcmultiplecriticalpaths_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcritifless","displayName":"Tasks are critical if slack is less than or equal to (User)","description":"Specifies the number of days of slack Project uses to determine critical tasks.\r\n\r\nIf you enable this setting, tasks are marked as critical if the slack is less than or equal to the value you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcritifless_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcritifless_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjcritifless_l_pjcritifless29","displayName":"Tasks are critical if slack is less than or equal to (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual","displayName":"Default fixed costs accrual (User)","description":"Specifies how Project sets the fixed cost accrual for new tasks.\r\n\r\nIf you enable this setting, new tasks will accrue fixed cost according to the specification you made.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_l_pjdefaultfixedaccrual28","displayName":"Default fixed costs accrual (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_l_pjdefaultfixedaccrual28_1","displayName":"Start","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_l_pjdefaultfixedaccrual28_3","displayName":"Prorated","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_l_pjdefaultfixedaccrual28_2","displayName":"End","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjeditstototaltask","displayName":"Edits to total task % complete will be spread to the status date (User)","description":"Distributes the changes to total percent complete evenly across the schedule to the project status date (or to the current date if you haven't specified a project status date).\r\n\r\nIf you enable this setting, edits to total task percent complete are evenly distributed across the schedule up to the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjeditstototaltask_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjeditstototaltask_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjedittototalspread","displayName":"Edits to total actual cost will be spread to the status date (User)","description":"Distributes the changes to total actual cost evenly across the schedule to the status date (or to the current date if you have not specified a project status date).\r\n\r\nIf you enable this setting, Project will distribute edits to actual cost evenly across a task up to the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjedittototalspread_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjedittototalspread_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjinsertedprojects","displayName":"Inserted projects are calculated like summary tasks (User)","description":"Specifies that a single critical path is calculated throughout the master project, by treating inserted projects as summary tasks in the master project.\r\n\r\nIf you enable this setting, the critical path is calculated by treating inserted projects as summary tasks.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjinsertedprojects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjinsertedprojects_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjmovecompleted","displayName":"Move end of completed parts after status date back to status date (User)","description":"Moves the completed portion of a task back to finish at the status date.\r\n\r\nIf you enable this setting, the completed portion of the task moves back to finish at the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjmovecompleted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjmovecompleted_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjmoveremaining","displayName":"Move start of remaining parts before status date forward to status date (User)","description":"Moves remaining portions of a task forward to start at the status date.\r\n\r\nIf you enable this setting, the remaining portion of the task moves forward to start at the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjmoveremaining_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjmoveremaining_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjupdatingtask","displayName":"Updating task status updates resource status (User)","description":"Automatically updates resource status, such as actual and remaining work and cost, whenever you update task status, such as percent complete, actual duration, or remaining duration.\r\n\r\nIf you enable this setting, task status updates are automatically applied to resources.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjupdatingtask_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjupdatingtask_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline","displayName":"Baseline for Earned Value calculations (User)","description":"Specifies the baseline that is used to measure project performance using earned value analysis.\r\n\r\nIf you enable this setting, Project will calculate earned value using the baseline you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"acbc106b-796a-4ba3-ab5f-c130530ad455","categoryName":"Earned Value options for Project1","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27","displayName":"Baseline for Earned Value calculations (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acbc106b-796a-4ba3-ab5f-c130530ad455","categoryName":"Earned Value options for Project1","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_1","displayName":"Baseline","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_12","displayName":"Baseline 1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_13","displayName":"Baseline 2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_14","displayName":"Baseline 3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_15","displayName":"Baseline 4","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_16","displayName":"Baseline 5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_17","displayName":"Baseline 6","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_18","displayName":"Baseline 7","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_19","displayName":"Baseline 8","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_20","displayName":"Baseline 9","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_l_pjevbaseline27_21","displayName":"Baseline 10","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod","displayName":"Default task Earned Value method (User)","description":"Specifies the method used for earned value analysis.\r\n\r\nIf you enable this setting, Project will calculate earned value using the method you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"acbc106b-796a-4ba3-ab5f-c130530ad455","categoryName":"Earned Value options for Project1","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_l_pjevmethod26","displayName":"Default task Earned Value method (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acbc106b-796a-4ba3-ab5f-c130530ad455","categoryName":"Earned Value options for Project1","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_l_pjevmethod26_0","displayName":"% Complete","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_l_pjevmethod26_1","displayName":"Physical % Complete","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdayspermonth","displayName":"Days per month (User)","description":"Defines the number of days that you want Project to assign to a task when you enter a duration of a month.\r\n\r\nIf you enable this setting, month-long tasks will be assigned the number of days that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdayspermonth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdayspermonth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdayspermonth_l_pjdayspermonth20","displayName":"Days per month (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultendtime","displayName":"Default end time (User)","description":"Specifies the finish time that Project assigns to tasks by default when you enter a finish date without specifying a time.\r\n\r\nIf you enable this setting, new tasks where the user does not enter an end time will have the end time that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultendtime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultendtime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultendtime_l_pjdefaultendtime2","displayName":"Default end time (Minutes after 12am * 10) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultstarttime","displayName":"Default start time (User)","description":"Specifies the start time that Project assigns to tasks by default when you enter a start date without specifying a time.\r\n\r\nIf you enable this setting, new tasks where the user does not enter a start time will use the start time that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultstarttime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultstarttime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultstarttime_l_pjdefaultstarttime2","displayName":"Default start time (Minutes after 12am * 10) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear","displayName":"Fiscal year starts in (User)","description":"Specifies the month that begins the fiscal year.\r\n\r\nIf you enable this setting, the fiscal year will start on the month you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17","displayName":"Fiscal year starts in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_1","displayName":"January","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_2","displayName":"February","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_3","displayName":"March","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_4","displayName":"April","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_5","displayName":"May","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_6","displayName":"June","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_7","displayName":"July","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_8","displayName":"August","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_9","displayName":"September","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_10","displayName":"October","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_11","displayName":"November","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_12","displayName":"December","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday","displayName":"Hours per day (User)","description":"Defines the number of hours that you want Project to assign to a task when the user enters a duration of one day.\r\n\r\nIf you enable this setting, day-long tasks will be assigned the number of hours that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday_l_pjhoursperday18","displayName":"Hours per day (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperweek","displayName":"Hours per week (User)","description":"Specifies the number of hours that you want Project to assign to a task when the user enters a duration of one week.\r\n\r\nIf you enable this setting, week-long tasks will be assigned the number of hours that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperweek_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperweek_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperweek_l_pjhoursperweek19","displayName":"Hours per week (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjstartingyear","displayName":"Use starting year for FY numbering (User)","description":"Labels the fiscal year using the calendar year in which the fiscal year begins.\r\n\r\nIf you enable this setting, the label for the fiscal year is the calendar year in which the fiscal year begins.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjstartingyear_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjstartingyear_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts","displayName":"Week starts on (User)","description":"Specifies the day of the week on which you want the scheduling week to begin.\r\n\r\nIf you enable this setting, weeks will start on the day you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16","displayName":"Week starts on (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_6","displayName":"Saturday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_0","displayName":"Sunday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_1","displayName":"Monday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_4","displayName":"Thursday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_5","displayName":"Friday","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjallowcelldragdrop","displayName":"Allow cell drag and drop (User)","description":"Allow fields in sheets to be moved using the mouse.\r\nIf you enable this setting, users can move rows and fields to new locations using the mouse.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"d33133b4-77df-429a-9580-ed70f7da676d","categoryName":"Edit options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjallowcelldragdrop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjallowcelldragdrop_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjasktoupdate","displayName":"Ask to update automatic links (User)","description":"Prompts the user to update linked objects whenever they open a file containing OLE links, if the source has changed.\r\n \r\nIf you enable this setting, users are prompted to update linked objects whose source has changed whenever they open a file containing OLE links.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"d33133b4-77df-429a-9580-ed70f7da676d","categoryName":"Edit options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjasktoupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjasktoupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjeditdirectlycell","displayName":"Edit directly in cell (User)","description":"Allows editing directly in the selected cell.\r\n \r\nIf you enable this setting, users can directly edit a cell's value.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"d33133b4-77df-429a-9580-ed70f7da676d","categoryName":"Edit options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjeditdirectlycell_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjeditdirectlycell_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjmoveafterenter","displayName":"Move selection after enter (User)","description":"Automatically selects the field below the current field after the user presses the ENTER key.\r\n \r\nIf you enable this setting, the field below the current field is selected after the user presses the ENTER key.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"d33133b4-77df-429a-9580-ed70f7da676d","categoryName":"Edit options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjmoveafterenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjmoveafterenter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour","displayName":"Followed hyperlink color (User)","description":"Specifies the color of hyperlinks that have already been followed.\r\n\r\nIf you enable this setting, hyperlinks that have been followed are displayed in the color you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15","displayName":"Followed hyperlink color (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_16","displayName":"Automatic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_0","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_1","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_2","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_3","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_4","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_5","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_6","displayName":"Fuchsia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_7","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_8","displayName":"Maroon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_9","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_10","displayName":"Olive","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_11","displayName":"Navy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_12","displayName":"Purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_13","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_14","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_15","displayName":"Silver","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour","displayName":"Hyperlink color (User)","description":"Specifies the color of hyperlinks that have not yet been followed.\r\n \r\nIf you enable this setting, hyperlinks that have not been followed are displayed in the color you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14","displayName":"Hyperlink color (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_16","displayName":"Automatic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_0","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_1","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_2","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_3","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_4","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_5","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_6","displayName":"Fuchsia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_7","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_8","displayName":"Maroon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_9","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_10","displayName":"Olive","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_11","displayName":"Navy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_12","displayName":"Purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_13","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_14","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_l_pjhyperlinkcolour14_15","displayName":"Silver","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjunderlinelinks","displayName":"Underline hyperlinks (User)","description":"Shows hyperlinks with underlined text.\r\n\r\nIf you enable this setting, hyperlinks are underlined.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjunderlinelinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjunderlinelinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjaddspace","displayName":"Add space before label (User)","description":"Adds a space between numbers and time unit labels.\r\n \r\nIf you enable this setting, a space is displayed between numbers and the time unit label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjaddspace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjaddspace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays","displayName":"Days (User)","description":"Sets the label for days.\r\n \r\nIf you enable this setting, days are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10","displayName":"Days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_0","displayName":"d","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_1","displayName":"dy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_2","displayName":"day","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_4","displayName":"\r\n ","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours","displayName":"Hours (User)","description":"Sets the label for hours.\r\n \r\nIf you enable this setting, hours are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9","displayName":"Hours (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_0","displayName":"h","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_1","displayName":"hr","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_2","displayName":"hour","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_4","displayName":"\r\n ","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes","displayName":"Minutes (User)","description":"Sets the label for minutes.\r\n\r\nIf you enable this setting, minutes are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_l_pjminutes8","displayName":"Minutes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_l_pjminutes8_0","displayName":"m","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_l_pjminutes8_1","displayName":"min","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_l_pjminutes8_2","displayName":"minute","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_l_pjminutes8_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_l_pjminutes8_4","displayName":"\r\n ","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths","displayName":"Months (User)","description":"Sets the label for months.\r\n \r\nIf you enable this setting, months are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_l_pjmonths12","displayName":"Months (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_l_pjmonths12_0","displayName":"mo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_l_pjmonths12_1","displayName":"mon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_l_pjmonths12_2","displayName":"month","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_l_pjmonths12_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjmonths_l_pjmonths12_4","displayName":"\r\n ","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks","displayName":"Weeks (User)","description":"Sets the label for weeks.\r\n\r\nIf you enable this setting, weeks are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11","displayName":"Weeks (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_0","displayName":"w","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_1","displayName":"wk","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_2","displayName":"week","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_4","displayName":"\r\n ","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears","displayName":"Years (User)","description":"Sets the label for years.\r\n \r\nIf you enable this setting, years are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_l_pjyears13","displayName":"Years (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_l_pjyears13_0","displayName":"y","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_l_pjyears13_1","displayName":"yr","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_l_pjyears13_2","displayName":"year","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_l_pjyears13_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjyears_l_pjyears13_4","displayName":"\r\n ","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels","displayName":"Undo Levels (User)","description":"Limits the number of actions (1-99) that a user can undo. If you enable this setting, you can set a limit on the number of actions (1-99) a user is can undo. If you disable this setting or do not configure it, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels_l_undolevels5","displayName":"Undo Levels (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","categoryName":"General","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjautoaddnew","displayName":"Automatically add new resources and tasks (User)","description":"Automatically adds new resources to the resource pool and assigns them default values whenever a new resource name or new resource's initials are added.\r\n \r\nIf you enable this setting, new resources and tasks are automatically inserted into the project.\r\n\r\nIf you disable this setting, users are alerted whenever a new resource or task is created when making a new assignment.\r\n\r\nIf you do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","categoryName":"General options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjautoaddnew_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjautoaddnew_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultotime","displayName":"Default overtime rate (User)","description":"Specifies the overtime pay rate for new resources.\r\n \r\nIf you enable this setting, all new resources will use the specified overtime pay rate\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","categoryName":"General options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultotime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultotime_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultotime_l_pjdefaultotime7","displayName":"Default overtime rate (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","categoryName":"General options for 'Project1'","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultstdrate","displayName":"Default standard rate (User)","description":"Specifies the standard pay rate for new resources.\r\n \r\nIf you enable this setting, all new resources will use the specified standard pay rate.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","categoryName":"General options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultstdrate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultstdrate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjdefaultstdrate_l_pjdefaultstdrate6","displayName":"Default standard rate (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","categoryName":"General options for 'Project1'","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjopenlast","displayName":"Open last file on startup (User)","description":"Upon starting Project, automatically opens the last used project file.\r\n \r\nIf you enable this setting, the last file that the user had open automatically re-opens when they start Project.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjopenlast_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjopenlast_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjpromptforinfo","displayName":"Prompt for project info for new projects (User)","description":"Opens the Project Information dialog box whenever the user creates a new project.\r\n\r\nIf you enable this setting, the Project Information dialog box is displayed whenever you create a new project.\r\n\r\nIf you disable or do not configure this setting, the users default setting is followed.","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjpromptforinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjpromptforinfo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjrecentlyused","displayName":"Number of projects in the Recent Projects list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Projects list that appears when users click Open on the File tab in Backstage view. \r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Projects list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Projects list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjrecentlyused_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjrecentlyused_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjrecentlyused_l_pjmrut","displayName":"Number of entries: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjsetautofilter","displayName":"Set AutoFilter on for new projects (User)","description":"This policy setting turns on AutoFilter automatically when the user creates a new project.\r\n\r\nIf you enable or do not configure this policy setting, AutoFilter is automatically turned on when users create a new project.\r\n\r\nIf you disable this policy setting, AutoFilter is not automatically turned on when users create a new project.","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjsetautofilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_pjsetautofilter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"Number of folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface_l_disableinternalidmatching","displayName":"Disable Internal ID Matching (User)","description":"Prevent internal id matching. If you enable this setting, Project will not use internal identifiers to match different-language or renamed Organizer items between projects. If this setting is disabled or not configured, internal identifiers will be used to match different-language or renamed Organizer items between projects.","helpText":"","infoUrls":[],"categoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","categoryName":"Interface","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface_l_disableinternalidmatching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface_l_disableinternalidmatching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettings_l_pjgbuidisplaytoggle","displayName":"Display Project Guide (User)","description":"Displays the side pane containing the Project Guide.\r\n\r\nIf you enable this setting, the Project Guide will be displayed.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"343eb575-3ac8-4da9-b66d-ce84b84be7c3","categoryName":"Project Guide settings","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettings_l_pjgbuidisplaytoggle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettings_l_pjgbuidisplaytoggle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage","displayName":"Project Guide Functionality and Layout page (User)","description":"Choose whether the side pane displays the default Project Guide or a custom Project Guide your organization has developed.\r\n\r\nIf you enable this setting, the Project Guide you specified will be displayed when the Project Guide is opened.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjgbuidefaultpageurl","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjusedefaultstartpage34","displayName":"Project Guide Functionality and Layout page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjusedefaultstartpage34_1","displayName":"Use Microsoft Project's Default page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjusedefaultstartpage34_0","displayName":"Use a custom page","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema","displayName":"Project Guide Content (User)","description":"Specifies whether the side pane displays the Project Guide content that comes with Project or custom content that your organization has developed.\r\n\r\nIf you enable this setting, content for the Project Guide is loaded from the specified location.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema_l_pjgbuixmlschemapath","displayName":"XML file for custom content: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema_l_pjusedefaultxmlschema35","displayName":"Project Guide Content (User)","description":"","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema_l_pjusedefaultxmlschema35_1","displayName":"Use Microsoft Project's default content","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultxmlschema_l_pjusedefaultxmlschema35_0","displayName":"Use custom content","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjchangedurationooui","displayName":"Edits to work, units or duration (User)","description":"Specifies that the feedback triangle should appear in a corner of a Task Name field if you change the task's start date or finish date.\r\n\r\nIf you enable this setting, a feedback triangle is displayed in the corner of the Task Name field if the user changes the task's start or finish date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"fe7c8652-17d4-40a7-869c-f7cfc3454402","categoryName":"Show indicators and Option butons for","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjchangedurationooui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjchangedurationooui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjdeletenameooui","displayName":"Deletions in the Name column (User)","description":"Specifies that the delete indicator should appear in the Indicators field if you delete text in the Task Name or Resource Names field.\r\n\r\nIf you enable this setting, the delete indicator will appear if the user deletes a Task Name or Resource Names.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"fe7c8652-17d4-40a7-869c-f7cfc3454402","categoryName":"Show indicators and Option butons for","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjdeletenameooui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjdeletenameooui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjenterdateooui","displayName":"Edits to start and finish dates (User)","description":"Specifies that the feedback triangle should appear in a corner of the Duration field or the Task Name field if you change a task's work, units, or duration.\r\n\r\nIf you enable this setting, a feedback triangle is displayed in the corner of the Duration or Task Name field if the user changes the task's work, units, or duration.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"fe7c8652-17d4-40a7-869c-f7cfc3454402","categoryName":"Show indicators and Option butons for","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjenterdateooui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjenterdateooui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjresourceassignooui","displayName":"Resource Assigments (User)","description":"Specifies that the feedback triangle should appear in a corner of a field if the user assigns additional resources to a task that already has resources assigned.\r\n\r\nIf you enable this setting, a feedback triangle is displayed in the corner of a field if users assign additional resources to a task that already has resources assigned.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"fe7c8652-17d4-40a7-869c-f7cfc3454402","categoryName":"Show indicators and Option butons for","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjresourceassignooui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjresourceassignooui_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype","displayName":"Save Microsoft Project files as (User)","description":"Specifies the default file format that should be applied when any Project file is saved.\r\n\r\nIf you enable this setting, project files will be saved with the format you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30","displayName":"Save Microsoft Project files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30_msproject.mpp.12","displayName":"Project (*.mpp)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30_msproject.mpt.12","displayName":"Template (*.mpt)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30_msproject.mpp.9","displayName":"Project 2000-2003 (*.mpp)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveoption","displayName":"Save Active Project only (User)","description":"Saves only the active project at the interval you specify. This setting is only used by Project if Auto Save is turned on.\r\n\r\nIf you enable this setting, Project will only save the active project at specified intervals.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveprompt","displayName":"Prompt before saving (User)","description":"Specifies whether Project should prompt the user before saving their project as a result of the Auto Save function.\r\n\r\nIf you enable this setting, users will be prompted before their project is automatically saved.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveprompt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveevery","displayName":"Auto Save every (User)","description":"Specifies that you want Project to automatically save your projects periodically.\r\n\r\nIf you enable this setting, Project will save users projects at the specified interval.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveevery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveevery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval","displayName":"Save Interval (User)","description":"Specifies how often Project should automatically save your projects. This setting is only used by Project if Auto Save has been turned on.\r\n\r\nIf you enable this setting, Project will save users projects at the specified interval.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval_l_pjsaveinterval33","displayName":"Save Interval (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation","displayName":"Local Project Cache Location (User)","description":"Sets the location path of the local project cache on the user's computer.","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation_l_cachelocation37","displayName":"Local Project Cache Location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachesizeperprofile","displayName":"Local Project Cache Size Limit in MB (User)","description":"Sets the size limit in MB of the local project cache. This is applied per user profile. If this setting is enabled, the size of the cache will be set to the number specified. If this setting is disabled or not configured, users are able to set the cache size limit.","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachesizeperprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachesizeperprofile_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachesizeperprofile_l_cachesizeperprofile38","displayName":"Local Project Cache Size Limit in MB (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocprojects","displayName":"Projects (User)","description":"Specifies the default location in the computer system for saving and opening projects.\r\n\r\nIf you enable this policy setting, the location first appears in the Open and Save As dialog box.\r\n\r\nIf you disable or do not configure this policy setting, the users default for this setting is followed.","helpText":"","infoUrls":[],"categoryId":"d679b407-a753-40aa-bc9f-175f363b0eff","categoryName":"File locations","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocprojects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocprojects_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocprojects_l_pjfilelocprojects31","displayName":"Projects (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d679b407-a753-40aa-bc9f-175f363b0eff","categoryName":"File locations","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocusertemplates","displayName":"User Templates (User)","description":"Specifies the default location in the computer system for saving and opening workgroup templates.\r\n\r\nIf you enable this policy setting, the location first appears in the Open and Save As dialog box.\r\n\r\nIf you disable or do not configure this policy setting, the users default for this setting is followed.","helpText":"","infoUrls":[],"categoryId":"d679b407-a753-40aa-bc9f-175f363b0eff","categoryName":"File locations","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocusertemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocusertemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocusertemplates_l_pjfilelocusertemplates32","displayName":"User Templates (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d679b407-a753-40aa-bc9f-175f363b0eff","categoryName":"File locations","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_keeptasksonnearestworkingday","displayName":"Keep tasks on nearest working day (User)","description":"This policy setting will enable a constraint to be applied to tasks when they are toggled from Manually Scheduled Mode to Automatically Scheduled Mode, allowing the task date to be as close to the user-entered date as possible.\r\n\r\nIf you enable this policy setting, the task date will be as close to the user-entered date as possible when tasks are toggled from Manually Scheduled Mode to Automatically Scheduled Mode.\r\n\r\nIf you disable or do not configure this policy setting, the task date will not to be as close to the user-entered date when tasks are toggled from Manually Scheduled Mode to Automatically Scheduled Mode.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_keeptasksonnearestworkingday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_keeptasksonnearestworkingday_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjautolinktasks","displayName":"Autolink inserted or moved tasks (User)","description":"This policy setting automatically links tasks when you cut, move, or insert them.\r\n\r\nIf you enable this policy setting, tasks will automatically be linked when you cut, move, or insert them.\r\n\r\nIf you disable or do not configure this policy setting, tasks will not automatically be linked when you cut, move, or insert them.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjautolinktasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjautolinktasks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes","displayName":"Default task type (User)","description":"Specifies the default task type for new tasks.\r\n\r\nIf you enable this setting, new tasks will be set to the type that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes_l_pjdefaulttasktypes25","displayName":"Default task type (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes_l_pjdefaulttasktypes25_1","displayName":"Fixed Duration","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes_l_pjdefaulttasktypes25_0","displayName":"Fixed Units","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdefaulttasktypes_l_pjdefaulttasktypes25_2","displayName":"Fixed Work","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits","displayName":"Duration is entered in (User)","description":"Specifies the unit of time (minutes, hours, days, weeks, or months) used by default in the Duration field.\r\n\r\nIf you enable this setting, the unit you specify will be used if the user does not specify a unit of time when entering a duration.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23","displayName":"Duration is entered in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_3","displayName":"Minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_5","displayName":"Hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_7","displayName":"Days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_9","displayName":"Weeks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_11","displayName":"Months","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks","displayName":"New tasks (User)","description":"Specifies the default start date for new tasks as they are entered in the current project. For projects scheduled from the start date, the options are \"Start on Project Start Date\" and \"Start on Current Date.\" For projects scheduled from the finish date, the options are \"Finish on Project Finish Date\" and \"Start on Current Date.\"\r\n\r\nIf you enable this setting, new tasks will start on the date you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_l_pjnewtasks22","displayName":"New tasks (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_l_pjnewtasks22_0","displayName":"Start on Project Start Date","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_l_pjnewtasks22_1","displayName":"Start on Current Date","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtaskseffort","displayName":"New tasks are effort driven (User)","description":"This policy setting specifies that new tasks are scheduled such that the work on the task remains constant as you add or remove assignments.\r\n\r\nIf you enable this policy setting, new tasks will be effort-driven.\r\n\r\nIf you disable or do not configure this policy setting, new tasks will not be effort-driven.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtaskseffort_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtaskseffort_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasksestdurations","displayName":"New tasks have estimated durations (User)","description":"Specifies that all new tasks have estimated durations.\r\n\r\nIf you enable this setting, all new tasks will require estimated durations.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasksestdurations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasksestdurations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjshowestimateddurations","displayName":"Show that tasks have estimated durations (User)","description":"Displays a question mark (?) after the duration unit of any task with an estimated duration.\r\n\r\nIf you enable this setting, tasks with estimated durations have a question mark after their duration unit.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjshowestimateddurations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjshowestimateddurations_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjsplitinprogresstasks","displayName":"Split in-progress tasks (User)","description":"Allows rescheduling of remaining duration and work when a task slips or reports progress ahead of schedule.\r\n\r\nIf you enable this setting, the remaining duration and work will be rescheduled if a task slips or reports progress ahead of schedule.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjsplitinprogresstasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjsplitinprogresstasks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjtaskshonorconstraints","displayName":"Tasks will always honor their constraint dates (User)","description":"Specifies that Project schedules tasks according to their constraint dates.\r\n\r\nIf you enable this setting, task constraints will always be honored when tasks are scheduled.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjtaskshonorconstraints_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjtaskshonorconstraints_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits","displayName":"Work is entered in (User)","description":"Specifies the default unit of time (minutes, hours, days, weeks, or months) used in the Work field in the current project.\r\n\r\nIf you enable this setting, whenever Project displays work values, the unit you specified will be used.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_l_pjworkunits24","displayName":"Work is entered in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_l_pjworkunits24_3","displayName":"Minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_l_pjworkunits24_5","displayName":"Hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_l_pjworkunits24_7","displayName":"Days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_l_pjworkunits24_9","displayName":"Weeks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_l_pjworkunits24_11","displayName":"Months","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_setdefaultstartdatefornewtasks","displayName":"Set default start date for new tasks (User)","description":"This policy setting specifies the default start date for new tasks as they are entered in the current project. For projects scheduled from the start date, the options are \"Start on Project Start Date\" and \"Start on Current Date.\" For projects scheduled from the finish date, the options are \"Finish on Project Finish Date\" and \"Start on Current Date.\"\r\n\r\nIf you enable or do not configure this policy setting, new tasks will start on the project start date.\r\n\r\nIf you disable this policy setting, new tasks will not start on the project start date.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_setdefaultstartdatefornewtasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_setdefaultstartdatefornewtasks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_setnewtaskstobeautomaticallyscheduled","displayName":"Set new tasks to be automatically scheduled (User)","description":"This policy setting will set new tasks to be automatically scheduled.\r\n\r\nIf you enable this policy setting, new tasks will be automatically scheduled.\r\n\r\nIf you disable or do not configure this policy setting, new tasks will be manually scheduled.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_setnewtaskstobeautomaticallyscheduled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_setnewtaskstobeautomaticallyscheduled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_showtasksschedulesuggestions","displayName":"Show tasks schedule suggestions (User)","description":"This policy setting will allow the display of green task suggestions to indicate potential optimization.\r\n\r\nIf you enable this policy setting, a green task suggestion will be displayed to indicate potential problems.\r\n\r\nIf you disable or do not configure this policy setting, a green task suggestion will not be displayed to indicate potential problems.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_showtasksschedulesuggestions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_showtasksschedulesuggestions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_showtasksschedulewarnings","displayName":"Show tasks schedule warnings (User)","description":"This policy setting will allow the display of red task warnings to indicate potential problems.\r\n\r\nIf you enable or do not configure this policy setting, a red task warning will be displayed to indicate potential problems.\r\n\r\nIf you disable this policy setting, a red task warning will not be displayed to indicate potential problems.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_showtasksschedulewarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_showtasksschedulewarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_taskscanbemadeinactive","displayName":"Tasks can be made inactive (User)","description":"This policy setting will allow tasks to be inactivated.\r\n\r\nIf you enable or do not configure this policy setting, users will be able to use the Inactive tasks feature, and tasks are allowed to be inactivated.\r\n\r\nIf you disable this policy setting, tasks cannot be inactivated.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_taskscanbemadeinactive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_taskscanbemadeinactive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_updatemanuallyscheduledtaskswheneditinglinks","displayName":"Update manually scheduled tasks when editing links (User)","description":"This policy setting will allow the update of manually scheduled task dates when predecessor links are created or updated.\r\n\r\nIf you enable or do not configure this policy setting, manually scheduled task dates will be updated when predecessor links are created or updated.\r\n\r\nIf you disable this policy setting, manually scheduled task dates will not be updated when predecessor links are created or updated.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_updatemanuallyscheduledtaskswheneditinglinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_updatemanuallyscheduledtaskswheneditinglinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits","displayName":"Show assignment units as (User)","description":"Shows resource assignments units as a decimal or percentage.\r\n\r\nIf you enable this setting, resource assignment units will be set to the option you choose from the list.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"304a579b-ff3b-4897-8bb8-5a1dda45356f","categoryName":"Schedule options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_l_pjassignmentunits21","displayName":"Show assignment units as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"304a579b-ff3b-4897-8bb8-5a1dda45356f","categoryName":"Schedule options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_l_pjassignmentunits21_0","displayName":"Percentage","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_l_pjassignmentunits21_1","displayName":"Decimal","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjshowschedmessage","displayName":"Show scheduling messages (User)","description":"Displays messages about schedule inconsistencies, such as a successor task starting before the finish of the predecessor task.\r\n\r\nIf you enable this setting, users will be alerted about scheduling inconsistencies.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"304a579b-ff3b-4897-8bb8-5a1dda45356f","categoryName":"Schedule options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjshowschedmessage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjshowschedmessage_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency","displayName":"Default Project Currency (User)","description":"Allows you to manage whether users can set the default currency type for their new project plans. If you enable this setting, the default currency type is enforced for all new project plans. If this setting is disabled or not configured, users can set the default currency type for new project plans.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4","displayName":"Default Project Currency (User)","description":"","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_aed","displayName":"United Arab Emirates, Dirhams","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_afa","displayName":"Afghanistan, Afghanis","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_all","displayName":"Albania, Leke","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_amd","displayName":"Armenia, Drams","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_aoa","displayName":"Angola, Kwanza","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ars","displayName":"Argentina, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_aud","displayName":"Australia, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_awg","displayName":"Aruba, Guilders (also called Florins)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_azm","displayName":"Azerbaijan, Manats","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bam","displayName":"Bosnia and Herzegovina, Convertible Marka","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bbd","displayName":"Barbados, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bdt","displayName":"Bangladesh, Taka","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bgn","displayName":"Bulgaria, Leva","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bhd","displayName":"Bahrain, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bif","displayName":"Burundi, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bmd","displayName":"Bermuda, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bnd","displayName":"Brunei Darussalam, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bob","displayName":"Bolivia, Bolivianos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_brl","displayName":"Brazil, Brazil Real","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bsd","displayName":"Bahamas, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_btn","displayName":"Bhutan, Ngultrum","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bwp","displayName":"Botswana, Pulas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_byr","displayName":"Belarus, Rubles","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_bzd","displayName":"Belize, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_cad","displayName":"Canada, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_cdf","displayName":"Congo (DRC)//Kinshasa, Congolese Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_chf","displayName":"Switzerland, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_clp","displayName":"Chile, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_cny","displayName":"China, Yuan Renminbi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_cop","displayName":"Colombia, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_crc","displayName":"Costa Rica, Colones","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_csd","displayName":"Serbia, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_cup","displayName":"Cuba, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_cve","displayName":"Cabo Verde, Escudos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_czk","displayName":"Czech Republic, Koruny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_djf","displayName":"Djibouti, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_dkk","displayName":"Denmark, Kroner","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_dop","displayName":"Dominican Republic, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_dzd","displayName":"Algeria, Algeria Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_egp","displayName":"Egypt, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ern","displayName":"Eritrea, Nakfa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_etb","displayName":"Ethiopia, Birr","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_eur","displayName":"Euro Member Countries, Euro","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_fjd","displayName":"Fiji, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_fkp","displayName":"Falkland (Malvinas) Islands, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gbp","displayName":"United Kingdom, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gel","displayName":"Georgia, Lari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ggp","displayName":"Guernsey, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ghc","displayName":"Ghana, Cedis","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gip","displayName":"Gibraltar, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gmd","displayName":"Gambia, Dalasi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gnf","displayName":"Guinea, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gtq","displayName":"Guatemala, Quetzales","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_gyd","displayName":"Guyana, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_hkd","displayName":"Hong Kong, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_hnl","displayName":"Honduras, Lempiras","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_hrk","displayName":"Croatia, Kuna","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_htg","displayName":"Haiti, Gourdes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_huf","displayName":"Hungary, Forint","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_idr","displayName":"Indonesia, Rupiahs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ils","displayName":"Israel, New Shekels","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_imp","displayName":"Isle of Man, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_inr","displayName":"India, Rupees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_iqd","displayName":"Iraq, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_irr","displayName":"Iran, Rials","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_isk","displayName":"Iceland, Kronur","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_jep","displayName":"Jersey, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_jmd","displayName":"Jamaica, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_jod","displayName":"Jordan, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_jpy","displayName":"Japan, Yen","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kes","displayName":"Kenya, Shillings","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kgs","displayName":"Kyrgyzstan, Soms","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_khr","displayName":"Cambodia, Riels","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kmf","displayName":"Comoros, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kpw","displayName":"North Korea, Won","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_krw","displayName":"Korea, Won","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kwd","displayName":"Kuwait, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kyd","displayName":"Cayman Islands, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_kzt","displayName":"Kazakhstan, Tenge","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_lak","displayName":"Laos, Kips","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_lbp","displayName":"Lebanon, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_lkr","displayName":"Sri Lanka, Rupees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_lrd","displayName":"Liberia, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_lsl","displayName":"Lesotho, Maloti","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ltl","displayName":"Lithuania, Litai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_lyd","displayName":"Libya, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mad","displayName":"Morocco, Dirhams","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mdl","displayName":"Moldova, Lei","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mga","displayName":"Madagascar, Ariary","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mkd","displayName":"Macedonia FYRO, Denars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mmk","displayName":"Myanmar (Burma), Kyats","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mnt","displayName":"Mongolia, Tugriks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mop","displayName":"Macao, Patacas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mro","displayName":"Mauritania, Ouguiyas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mur","displayName":"Mauritius, Rupees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mvr","displayName":"Maldives (Maldive Islands), Rufiyaa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mwk","displayName":"Malawi, Kwachas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mxn","displayName":"Mexico, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_myr","displayName":"Malaysia, Ringgits","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_mzm","displayName":"Mozambique, Meticais","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_nad","displayName":"Namibia, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ngn","displayName":"Nigeria, Nairas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_nio","displayName":"Nicaragua, Cordobas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_nok","displayName":"Norway, Krone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_npr","displayName":"Nepal, Nepal Rupees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_nzd","displayName":"New Zealand, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_omr","displayName":"Oman, Rials","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_pab","displayName":"Panama, Balboa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_pen","displayName":"Peru, Nuevos Soles","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_pgk","displayName":"Papua New Guinea, Kina","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_php","displayName":"Philippines, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_pkr","displayName":"Pakistan, Rupees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_pln","displayName":"Poland, Zlotych","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_pyg","displayName":"Paraguay, Guarani","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_qar","displayName":"Qatar, Rials","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ron","displayName":"Romania, New Lei","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_rub","displayName":"Russia, Rubles","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_rwf","displayName":"Rwanda, Rwanda Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sar","displayName":"Saudi Arabia, Riyals","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sbd","displayName":"Solomon Islands, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_scr","displayName":"Seychelles, Rupees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sdd","displayName":"Sudan, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sek","displayName":"Sweden, Kronor","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sgd","displayName":"Singapore, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_shp","displayName":"Saint Helena, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sll","displayName":"Sierra Leone, Leones","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_sos","displayName":"Somalia, Shillings","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_spl","displayName":"Seborga, Luigini","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_srd","displayName":"Suriname, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_std","displayName":"São Tome and Principe, Dobras","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_svc","displayName":"El Salvador, Colones","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_syp","displayName":"Syria, Pounds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_szl","displayName":"Swaziland, Emalangeni","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_thb","displayName":"Thailand, Baht","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_tjs","displayName":"Tajikistan, Somoni","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_tmm","displayName":"Turkmenistan, Manats","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_tnd","displayName":"Tunisia, Dinars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_top","displayName":"Tonga, Pa'anga","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_try","displayName":"Turkey, Lira","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ttd","displayName":"Trinidad and Tobago, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_tvd","displayName":"Tuvalu, Tuvalu Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_twd","displayName":"Taiwan, New Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_tzs","displayName":"Tanzania, Shillings","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_uah","displayName":"Ukraine, Hryvnia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ugx","displayName":"Uganda, Shillings","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_usd","displayName":"United States of America, Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_uyu","displayName":"Uruguay, Pesos","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_uzs","displayName":"Uzbekistan, Sums","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_ves","displayName":"Venezuela, Bolívar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_vnd","displayName":"Vietnam, Dong","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_vuv","displayName":"Vanuatu, Vatu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_wst","displayName":"Samoa, Tala","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xaf","displayName":"Communauté Financière Africaine BEAC, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xag","displayName":"Silver, Ounces","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xau","displayName":"Gold, Ounces","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xcd","displayName":"East Caribbean Dollars","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xdr","displayName":"International Monetary Fund (IMF) Special Drawing Rights","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xof","displayName":"Communauté Financière Africaine BCEAO, Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xpd","displayName":"Palladium Ounces","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xpf","displayName":"Comptoirs Français du Pacifique Francs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_xpt","displayName":"Platinum, Ounces","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_yer","displayName":"Yemen, Rials","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_zar","displayName":"South Africa, Rand","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_zmk","displayName":"Zambia, Kwacha","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_l_defaultprojectcurrency4_zwd","displayName":"Zimbabwe, Zimbabwe Dollars","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat","displayName":"Date Format (User)","description":"Specifies the format for displaying dates. Some information, such as time formats and the date separator, is set through the Control Panel.\r\n \r\nIf you enable this setting, dates are displayed in the format you set.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3","displayName":"Date Format (User)","description":"","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_0","displayName":"1/31/00 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_1","displayName":"1/31/00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_20","displayName":"1/31/2000","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_2","displayName":"January 31, 2000 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_3","displayName":"January 31, 2000","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_4","displayName":"Jan 31 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_5","displayName":"Jan 31 '00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_6","displayName":"January 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_7","displayName":"Jan 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_8","displayName":"Mon 1/31/00 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_9","displayName":"Mon 1/31/00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_10","displayName":"Mon Jan 31, '00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_11","displayName":"Mon 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_15","displayName":"Mon Jan 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_16","displayName":"Mon 1/31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_17","displayName":"Mon 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_12","displayName":"1/31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_13","displayName":"31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_14","displayName":"12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_18","displayName":"W1/1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_19","displayName":"W1/1/00 12:33 PM","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview","displayName":"Default View (User)","description":"Specifies the view that Project displays at startup.\r\n \r\nIf you enable this setting, you can set the default view that is displayed at startup.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2","displayName":"Default View (User)","description":"","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_bar rollup","displayName":"Bar Rollup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_calendar","displayName":"Calendar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_descriptive network diagram","displayName":"Descriptive Network Diagram","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_detail gantt","displayName":"Detail Gantt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_gantt chart","displayName":"Gantt Chart","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_leveling gantt","displayName":"Leveling Gantt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_milestone date rollup","displayName":"Milestone Date Rollup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_milestone rollup","displayName":"Milestone Rollup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_network diagram","displayName":"Network Diagram","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_relationship diagram","displayName":"Relationship Diagram","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource allocation","displayName":"Resource Allocation","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource form","displayName":"Resource Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource graph","displayName":"Resource Graph","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource name form","displayName":"Resource Names Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource sheet","displayName":"Resource Sheet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource usage","displayName":"Resource Usage","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task details form","displayName":"Task Details Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task entry","displayName":"Task Entry","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task form","displayName":"Task Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task name form","displayName":"Task Name Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task sheet","displayName":"Task Sheet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task usage","displayName":"Task Usage","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_tracking gantt","displayName":"Tracking Gantt","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_projectsummarytask","displayName":"Project Summary Task (User)","description":"Allows you to manage whether the project summary task is displayed. If you enable this setting, the project summary task is displayed. If this setting is disabled or not configured, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_projectsummarytask_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_projectsummarytask_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0","displayName":"Calendar Type (User)","description":"Allows you to set the default calendar type. You need to have the Complex Script and East Asian language packs installed on the operating system in order for this setting to be available. If you enable this setting, you can set the default calendar type. If you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"70b0e7ef-ceac-4c25-8f9f-5a6bf07163b6","categoryName":"Calendar Type","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0_l_calendartype1","displayName":"Calendar Type (User)","description":"","helpText":"","infoUrls":[],"categoryId":"70b0e7ef-ceac-4c25-8f9f-5a6bf07163b6","categoryName":"Calendar Type","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0_l_calendartype1_1","displayName":"Gregorian Calendar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0_l_calendartype1_6","displayName":"Hijri Calendar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_calendartype_l_calendartype0_l_calendartype1_7","displayName":"Thai Buddhist","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_automaticallyaddnewitemstotheglobalproject","displayName":"Automatically add new items to the global project (User)","description":"This policy setting specifies whether new items (views, tables, filters, and groups) are automatically added to the global project so they are available in all of the projects.\r\n\r\nIf you enable or do not configure this policy setting, new items will be automatically added to the global project.\r\n\r\nIf you disable this policy setting, new items will not be automatically added to the global project.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_automaticallyaddnewitemstotheglobalproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_automaticallyaddnewitemstotheglobalproject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjentrybar","displayName":"Entry Bar (User)","description":"Displays the entry bar, in which you can enter or edit field information.\r\nIf you enable this setting, the entry bar is displayed.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjentrybar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjentrybar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjolelinks","displayName":"OLE Link Indicators (User)","description":"Displays the indicator for OLE linked objects in the lower-right corner of the cell that contains the link.\r\nIf you enable this setting, the indicator is displayed for OLE linked objects.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjolelinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjolelinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjprojectscreentips","displayName":"Project Screentips (User)","description":"Displays tips for Gantt bars and field headings, including dates for timescale units, and the full cell contents if a cell is too narrow to completely display the text in sheet and Network Diagram views.\r\n\r\nIf you enable this setting, tips are displayed fro Gantt bars and field headings.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjprojectscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjprojectscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjscrollbar","displayName":"Scroll Bars (User)","description":"Displays scrollbars for views.\r\n \r\nIf you enable this setting, scrollbars are displayed in the views.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjstatusbar","displayName":"Status Bar (User)","description":"Displays the status bar, which shows information about the progress of certain operations in Project.\r\n \r\nIf you enable this setting, the option to display the status bar is selected.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjstatusbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjstatusbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjwindowsinstatusbar","displayName":"Windows in Taskbar (User)","description":"Specifies whether separate windows are opened and displayed as separate buttons on the Windows taskbar for every open project.\r\n \r\nIf you enable this setting, a new window is displayed in the taskbar for each open project.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjwindowsinstatusbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjwindowsinstatusbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_enableuntrustedintranetzoneaccesstoprojectserver","displayName":"Enable untrusted intranet zone access to Project server (User)","description":"Allows users to access Project Server Web sites and Workspaces that have not been added to their trusted internet zones. If you enable this setting, users can access Project Server and Microsoft SharePoint Foundation sites that are not in their trusted internet zones. If this setting is disabled or not configured, users are required to add the Project Server and Microsoft SharePoint Foundation sites to their trusted internet site zones.","helpText":"","infoUrls":[],"categoryId":"623d41fb-000e-41d8-b955-373f8c700def","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_enableuntrustedintranetzoneaccesstoprojectserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_enableuntrustedintranetzoneaccesstoprojectserver_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats","displayName":"Previous-version file formats (User)","description":"Allows you manage whether users can open or save files in Project with file formats from previous versions or file formats that are not default. By default, users can not open or save files with formats from previous versions.","helpText":"","infoUrls":[],"categoryId":"623d41fb-000e-41d8-b955-373f8c700def","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"623d41fb-000e-41d8-b955-373f8c700def","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats_l_empty_0","displayName":"Do not open or save","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats_l_empty_1","displayName":"Prompt when opening and saving","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security_l_legacyfileformats_l_empty_2","displayName":"Allow opening and saving","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setparametersforcngcontext","displayName":"Set parameters for CNG context (User)","description":"This policy setting allows you to specify the encryption parameters that should be used for the CNG context. \r\n\r\nIf you enable this policy setting, the parameters specified will be passed to the CNG context.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG values will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setparametersforcngcontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setparametersforcngcontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm","displayName":"Specify CNG random number generator algorithm (User)","description":"This policy setting allows you to configure the CNG random number generator to use.\r\n\r\nIf you enable this policy setting, the random number generator specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default random number generator will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_l_specifycngrandomnumbergeneratoralgorithmid","displayName":"Random number generator: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngsaltlength","displayName":"Specify CNG salt length (User)","description":"This policy setting allows you to specific the number of bytes of salt that should be used.\r\n\r\nIf you enable this policy setting, the bytes specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default length or 16 will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngsaltlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngsaltlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel","displayName":"Security Level (User)","description":"Specifies the level of security used when opening documents.\r\n\r\nIf you enable this policy setting, the security level you specified will be used when user open documents.\r\n\r\nIf you disable or do not configure this policy setting, the users default for this setting is followed.","helpText":"","infoUrls":[],"categoryId":"26dfd0a7-546b-4583-b0c7-85b98ac5a40c","categoryName":"Tools | Macro","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_l_pjsecuritylevel36","displayName":"Security Level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"26dfd0a7-546b-4583-b0c7-85b98ac5a40c","categoryName":"Tools | Macro","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_l_pjsecuritylevel36_1","displayName":"Low (not recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_l_pjsecuritylevel36_2","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_l_pjsecuritylevel36_3","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_pjmacro_l_pjsecuritylevel_l_pjsecuritylevel36_4","displayName":"Very High","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_allowtrustedlocationsonthenetwork","displayName":"Allow Trusted Locations on the network (User)","description":"This policy setting controls whether trusted locations on the network can be used.\r\n\r\nIf you enable this policy setting, users can specify trusted locations on network shares or in other remote locations that are not under their direct control by clicking the \"Add new location\" button in the Trusted Locations section of the Trust Center. Content, code, and add-ins are allowed to load from trusted locations with minimal security and without prompting the user for permission.\r\n\r\nIf you disable this policy setting, the selected application ignores any network locations listed in the Trusted Locations section of the Trust Center. \r\n\r\nIf you also deploy Trusted Locations via Group Policy, you should verify whether any of them are remote locations. If any of them are remote locations and you do not allow remote locations via this policy setting, those policy keys that point to remote locations will be ignored on client computers.\r\n\r\nDisabling this policy setting does not delete any network locations from the Trusted Locations list, but causes disruption for users who add network locations to the Trusted Locations list. Users are also prevented from adding new network locations to the Trusted Locations list in the Trust Center. We recommended that you do not enable this policy setting (as the \"Allow Trusted Locations on my network (not recommended)\" check box also states). Therefore, in practice, it should be possible to disable this policy setting in most situations without causing significant usability issues for most users.\r\n\r\nIf you do not enable this policy setting, users can select the \"Allow Trusted Locations on my network (not recommended)\" check box if desired and then specify trusted locations by clicking the \"Add new location\" button.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_allowtrustedlocationsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_allowtrustedlocationsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users, except if application add-ins are required to be signed by Trusted Publishers.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User) (Deprecated)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n\r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_allowsubfolders15","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_allowsubfolders15_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_allowsubfolders15_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_datecolon13","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_descriptioncolon14","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_pathcolon12","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_datecolon17","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_descriptioncolon18","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_pathcolon16","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_datecolon21","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_descriptioncolon22","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_pathcolon20","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_datecolon25","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_descriptioncolon26","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_pathcolon24","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_l_allowsubfolders31","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_l_allowsubfolders31_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_l_allowsubfolders31_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_l_datecolon29","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_l_descriptioncolon30","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_l_pathcolon28","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_allowsubfolders35","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_allowsubfolders35_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_allowsubfolders35_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_datecolon33","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_allowsubfolders39","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_allowsubfolders39_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_allowsubfolders39_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_descriptioncolon38","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_pathcolon36","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_descriptioncolon42","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_pathcolon40","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_datecolon45","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_descriptioncolon46","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_pathcolon44","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11","displayName":"Trusted Location #11 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_l_allowsubfolders51","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_l_allowsubfolders51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_l_allowsubfolders51_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_l_datecolon49","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_l_descriptioncolon50","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc11_l_pathcolon48","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_allowsubfolders55","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_allowsubfolders55_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_allowsubfolders55_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_descriptioncolon54","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_l_allowsubfolders59","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_l_allowsubfolders59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_l_allowsubfolders59_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_l_datecolon57","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_l_descriptioncolon58","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc13_l_pathcolon56","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_l_allowsubfolders63","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_l_allowsubfolders63_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_l_allowsubfolders63_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_l_datecolon61","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc14_l_pathcolon60","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_pathcolon64","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_datecolon69","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_descriptioncolon70","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_pathcolon68","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_datecolon73","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_descriptioncolon74","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_pathcolon72","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_l_datecolon77","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_l_descriptioncolon78","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc18_l_pathcolon76","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_datecolon81","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_descriptioncolon82","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_pathcolon80","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_datecolon85","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_descriptioncolon86","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_pathcolon84","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_proj16v3~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the internet (User)","description":"\r\nThis policy setting allows you to block macros from running in Office files that come from the internet.\r\n\r\nIf you enable this policy setting, macros are blocked from running, even if \"Enable all macros\" is selected in the Macro Settings section of the Trust Center. Users will receive a notification that macros are blocked from running.\r\n\r\nThe exceptions when macros will be allowed to run are:\r\n- The Office file is saved to a Trusted Location.\r\n- The Office file was previously trusted by the user.\r\n- Macros are digitally signed and the matching Trusted Publisher certificate is installed on the device.\r\n\r\nIf you disable this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the internet.\r\n\r\nIf you don’t configure this policy setting, macros will be blocked from running. Users will receive a notification telling them of the security risks of macros from the internet along with a link to learn more.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2185771.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v3~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v3~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. \r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"907fd656-2a80-4f34-8615-a3acb11a2b95","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"907fd656-2a80-4f34-8615-a3acb11a2b95","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable specific command bar buttons and menu items for Publisher.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, the predefined list of command bar buttons and menu items are enabled for Publisher.","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filepublishtoweb","displayName":"File tab | Export | Publish HTML (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filepublishtoweb_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filepublishtoweb_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailemailpreview","displayName":"File tab | Share | E-mail Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailemailpreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailemailpreview_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailsendthispage","displayName":"File tab | Share | Email (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailsendthispage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailsendthispage_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview","displayName":"Web tab | View | Web Page Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_puboptions1","displayName":"File tab | Options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_puboptions1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_puboptions1_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsaddins","displayName":"Developer tab | Add-Ins | COM Add-Ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsaddins_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsaddins_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacro","displayName":"Developer tab (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacro_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacro_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacros","displayName":"Developer tab | Code | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity","displayName":"Developer tab | Code | Macro Security (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditor","displayName":"Developer tab | Code | Visual Basic (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditor_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditor_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_adddoublequotesinhebrewalphabetnumbering","displayName":"Add double quotes in Hebrew alphabet numbering (User)","description":"Checked: Adds double quotation marks ('') to Hebrew numbering. | Unchecked: Does not add double quotation marks ('') to Hebrew numbering.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_adddoublequotesinhebrewalphabetnumbering_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_adddoublequotesinhebrewalphabetnumbering_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab","displayName":"Default tab to show in Publisher on the Office Start screen and in File | New (User)","description":"This policy setting controls what displays as the default tab in Publisher on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, you can choose one of two options to become the default tab on the Office Start screen and in File | New:\r\n\r\n* Built-in – Users will the see built-in templates tab as the default tab in Publisher on the Office Start screen and in File | New.\r\n\r\n* Custom – Users will the see custom templates tab as the default tab in Publisher on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Publisher on the Office Start screen and in File | New","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab","displayName":"Default tab (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab_0","displayName":"Featured","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab_2","displayName":"Built-in","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab_1","displayName":"Custom","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_disableofficestartpublisher","displayName":"Disable the Office Start screen for Publisher (User)","description":"This policy setting controls whether the Office Start screen appears on boot for Publisher.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot Publisher.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot Publisher.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_disableofficestartpublisher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_disableofficestartpublisher_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\Publisher\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\Publisher\\Addins.\r\n\r\nYou can also obtain the ProgID of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath","displayName":"Personal templates path for Publisher (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_promptusertosetupprinter","displayName":"Prompt user to setup printer (User)","description":"When set, Publisher will show a prompt to the user to start the Printer Setup Wizard when a new printer is found.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_promptusertosetupprinter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_promptusertosetupprinter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_allowtexttobedraggedanddropped","displayName":"Allow text to be dragged and dropped (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_allowtexttobedraggedanddropped_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_allowtexttobedraggedanddropped_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallyhyphenateinnewtextboxes","displayName":"Automatically hyphenate in new text boxes (User)","description":"Checks/Unchecks the option ''Automatically hyphenate in new text boxes''.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallyhyphenateinnewtextboxes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallyhyphenateinnewtextboxes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallysubstitutefontformissingeachars","displayName":"Automatically substitute font for missing East Asian characters (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallysubstitutefontformissingeachars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallysubstitutefontformissingeachars_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallyswitchkeyboard","displayName":"Automatically switch keyboard to match the language of surrounding text (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallyswitchkeyboard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_automaticallyswitchkeyboard_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_enableincrementalpublishtoweb","displayName":"Enable incremental publish to Web (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_enableincrementalpublishtoweb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_enableincrementalpublishtoweb_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_promptuserwhenreapplyingastyle","displayName":"Prompt user when reapplying a style (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_promptuserwhenreapplyingastyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_promptuserwhenreapplyingastyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_sendentirepublicationasasingle","displayName":"Send entire publication as a single JPEG image (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_sendentirepublicationasasingle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_sendentirepublicationasasingle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setmaximumnumberofmruitemstodisplay","displayName":"Number of publications in the Recent Publications list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Publications list that appears when users click Open on the File tab in Backstage view. \r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Publications list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Publications list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setmaximumnumberofmruitemstodisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setmaximumnumberofmruitemstodisplay_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setmaximumnumberofmruitemstodisplay_l_setmaximumnumberofmruitemstodisplayspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_showscreentipsonobjects","displayName":"Show ScreenTips on objects (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_showscreentipsonobjects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_showscreentipsonobjects_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_turnoffdragpreview","displayName":"Turn off drag preview (User)","description":"This policy setting allows you to determine whether Publisher shows a semi-transparent drag preview or a simple outline of the object when the object is dragged.\r\n\r\nIf you enable this policy setting, only the outline of the object is shown while being dragged. This is the recommended setting for older machines because of the resource requirements of this feature.\r\n\r\nIf you disable or do not configure this policy setting, a semi-transparent drag preview of the object is shown while being dragged.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_turnoffdragpreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_turnoffdragpreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usechinesefontsizes","displayName":"Use Chinese font sizes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usechinesefontsizes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usechinesefontsizes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usexpsenhancedprintpath","displayName":"Use XPS-enhanced print path (User)","description":"This policy setting allows you to use XPS-enhanced print path when available. \r\n\r\nIf you enable or do not configure this policy setting, the XPS print path will be used.\r\n\r\nIf you disable this policy setting, the XPS print path is not used.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usexpsenhancedprintpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usexpsenhancedprintpath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenformattingautomaticallyformatentireword","displayName":"When formatting, automatically format entire word (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenformattingautomaticallyformatentireword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenformattingautomaticallyformatentireword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenselectingautomaticallyselectentireword","displayName":"When selecting, automatically select entire word (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenselectingautomaticallyselectentireword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenselectingautomaticallyselectentireword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection","displayName":"Default Publisher direction (User)","description":"Specifies the default layout orientation.","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_l_defaultpublisherdirection3","displayName":"Default Publisher direction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_l_defaultpublisherdirection3_0","displayName":"Left to right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_l_defaultpublisherdirection3_1","displayName":"Right to left","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_setdefaulttextflowdirection","displayName":"Set default text flow direction (User)","description":"This policy setting allows you to set the default text flow between Right-to-Left (RTL) and Left-to-Right (LTR). \r\n\r\nIf you enable this policy setting, you may choose whether text will flow RTL or LTR.\r\n\r\nIf you disable or not configure this policy setting, the default text flow setting is used.","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_setdefaulttextflowdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_setdefaulttextflowdirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_setdefaulttextflowdirection_l_setdefaulttextflowdirectiondropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_setdefaulttextflowdirection_l_setdefaulttextflowdirectiondropid_1","displayName":"Left-to-Right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_setdefaulttextflowdirection_l_setdefaulttextflowdirectiondropid_256","displayName":"Right-to-Left","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_usesequencechecking","displayName":"Use sequence checking (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_usesequencechecking_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_usesequencechecking_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_usetypeandreplace","displayName":"Use type and replace (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_usetypeandreplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_usetypeandreplace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_general_l_showthenewtemplategallerywhenstartingpublisher","displayName":"Show the New template gallery when starting Publisher (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"1a0386fd-354b-441e-a0d6-1523c209dae7","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_general_l_showthenewtemplategallerywhenstartingpublisher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_general_l_showthenewtemplategallerywhenstartingpublisher_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"6d1e32eb-61f7-4907-b9fe-b83fda8ad67d","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype","displayName":"Check spelling as you type (User)","description":"This policy setting allows you to configure options for spelling errors.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n- Check spelling as you type: This option is checked.\r\n- Hide spelling errors: This option is checked, but \"Check spelling as you type\" is unchecked.\r\n- Both: \"Check spelling as you type\" and \"Hide spelling errors\" are both checked.\r\n\r\nIf you disable or do not configure this policy setting, the \"Check spelling as you type\" option is checked.","helpText":"","infoUrls":[],"categoryId":"51e0cebb-cac4-4905-9b31-539295e4b85b","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype_l_checkspellingasyoutypedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"51e0cebb-cac4-4905-9b31-539295e4b85b","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype_l_checkspellingasyoutypedropid_1","displayName":"Check spelling as you type","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype_l_checkspellingasyoutypedropid_2","displayName":"Hide spelling errors","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_proofing_l_checkspellingasyoutype_l_checkspellingasyoutypedropid_3","displayName":"Both","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_allowbackgroundsaves","displayName":"Allow background saves (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"038b49c9-4f13-4ace-be8d-bd076bffa23e","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_allowbackgroundsaves_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_allowbackgroundsaves_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery","displayName":"Save AutoRecover info every (minutes) (User)","description":"This policy setting allows you to specify the Save Autorecover interval in minutes.\r\n\r\nIf you enable this policy setting, you may specify the Save Autorecover interval in minutes (valid range: 1-120).\r\n\r\nIf you disable or do not configure this policy setting, the interval specified in the UI will be used.\r\n","helpText":"","infoUrls":[],"categoryId":"038b49c9-4f13-4ace-be8d-bd076bffa23e","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery_l_saveautorecoverinfoeveryid","displayName":"Minutes (range 1-120): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"038b49c9-4f13-4ace-be8d-bd076bffa23e","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_preventfatallycorruptfilesfromopening","displayName":"Prompt to allow fatally corrupt files to open instead of blocking them (User)","description":"When disabled, fatally corrupt files are prevented from opening. When enabled, the user is warned but may choose to open the file.By default, fatally corrupt files are prevented from opening.","helpText":"","infoUrls":[],"categoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_preventfatallycorruptfilesfromopening_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_preventfatallycorruptfilesfromopening_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel","displayName":"Publisher Automation Security Level (User)","description":"This policy setting controls whether macros opened programmatically by another application can run in Publisher.\r\n\r\nIf you enable this policy setting, you may choose an option for controlling macro behavior in Publisher when the application is opened programmatically:\r\n\r\n- Low (enabled): Macros can run in the programmatically opened application.\r\n- By UI (prompted): Macro functionality is determined by the setting in the \"Macro Settings\" section of the Trust Center.\r\n- High (disabled): All macros are disabled in the programmatically opened application.\r\n\r\nIf you disable or do not configure this policy setting, Publisher will use the default Macro setting in Trust Center.","helpText":"","infoUrls":[],"categoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty_1","displayName":"Low (enabled)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty_2","displayName":"By UI (prompted)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty_3","displayName":"High (disabled)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Block application add-ins loading (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users, except if application add-ins are required to be signed by Trusted Publishers.","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins (User) (Deprecated)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2","displayName":"Disable Trust Bar Notification for unsigned application add-ins (User)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_pub16v3~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if \"Enable all macros\" is selected in the Macro Settings section of the Trust Center. Users will receive a notification that macros are blocked from running.\r\n\r\n The exceptions when macros will be allowed to run are:\r\n - The Office file is saved to a Trusted Location.\r\n - The Office file was previously trusted by the user.\r\n - Macros are digitally signed and the matching Trusted Publisher certificate is installed on the device.\r\n\r\n If you disable this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the internet.\r\n\r\n If you don’t configure this policy setting, macros will be blocked from running. Users will receive a notification telling them of the security risks of macros from the internet along with a link to learn more.\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2185771.\r\n ","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v3~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v3~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_remotedesktop_autosubscription","displayName":"Auto-subscription (User)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-configuration-service-provider"],"categoryId":"c14c2e8b-0081-46e0-89ac-48ade3b83408","categoryName":"Remote Desktop","options":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection","displayName":"Restrict clipboard transfer from client to server (User)","description":"This policy setting allows you to restrict clipboard data transfers from client to server.\r\n\r\nIf you enable this policy setting, you must choose from the following behaviors:\r\n\r\n- Disable clipboard transfers from client to server.\r\n\r\n- Allow plain text copying from client to server.\r\n\r\n- Allow plain text and images copying from client to server.\r\n\r\n- Allow plain text, images and Rich Text Format copying from client to server.\r\n\r\n- Allow plain text, images, Rich Text Format and HTML copying from client to server.\r\n\r\nIf you disable or do not configure this policy setting, users can copy arbitrary contents from client to server if clipboard redirection is enabled.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the stricter restriction will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-limitclienttoserverclipboardredirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_ts_cs_clipboard_restriction_text","displayName":"Restrict clipboard transfer from client to server: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_ts_cs_clipboard_restriction_text_0","displayName":"Disable clipboard transfers from client to server","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_ts_cs_clipboard_restriction_text_1","displayName":"Allow plain text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_ts_cs_clipboard_restriction_text_2","displayName":"Allow plain text and images","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_ts_cs_clipboard_restriction_text_3","displayName":"Allow plain text, images and Rich Text Format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_ts_cs_clipboard_restriction_text_4","displayName":"Allow plain text, images, Rich Text Format and HTML","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection","displayName":"Restrict clipboard transfer from server to client (User)","description":"This policy setting allows you to restrict clipboard data transfers from server to client.\r\n\r\nIf you enable this policy setting, you must choose from the following behaviors:\r\n\r\n- Disable clipboard transfers from server to client.\r\n\r\n- Allow plain text copying from server to client.\r\n\r\n- Allow plain text and images copying from server to client.\r\n\r\n- Allow plain text, images and Rich Text Format copying from server to client.\r\n\r\n- Allow plain text, images, Rich Text Format and HTML copying from server to client.\r\n\r\nIf you disable or do not configure this policy setting, users can copy arbitrary contents from server to client if clipboard redirection is enabled.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the stricter restriction will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-limitservertoclientclipboardredirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_ts_sc_clipboard_restriction_text","displayName":"Restrict clipboard transfer from server to client: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_ts_sc_clipboard_restriction_text_0","displayName":"Disable clipboard transfers from server to client","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_ts_sc_clipboard_restriction_text_1","displayName":"Allow plain text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_ts_sc_clipboard_restriction_text_2","displayName":"Allow plain text and images","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_ts_sc_clipboard_restriction_text_3","displayName":"Allow plain text, images and Rich Text Format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_ts_sc_clipboard_restriction_text_4","displayName":"Allow plain text, images, Rich Text Format and HTML","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_security_recoveryenvironmentauthentication","displayName":"Recovery Environment Authentication (User)","description":"This policy controls the requirement of Admin Authentication in RecoveryEnvironment.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Security#recoveryenvironmentauthentication"],"categoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_security_recoveryenvironmentauthentication_0","displayName":"current) behavior","description":"current) behavior","helpText":null},{"id":"user_vendor_msft_policy_config_security_recoveryenvironmentauthentication_1","displayName":"RequireAuthentication: Admin Authentication is always required for components in RecoveryEnvironment","description":"RequireAuthentication: Admin Authentication is always required for components in RecoveryEnvironment","helpText":null},{"id":"user_vendor_msft_policy_config_security_recoveryenvironmentauthentication_2","displayName":"NoRequireAuthentication: Admin Authentication is not required for components in RecoveryEnvironment","description":"NoRequireAuthentication: Admin Authentication is not required for components in RecoveryEnvironment","helpText":null}]},{"id":"user_vendor_msft_policy_config_settings_configuretaskbarcalendar","displayName":"Configure Taskbar Calendar (User)","description":"Allows IT Admins to configure the default setting for showing additional calendars (besides the default calendar for the locale) in the taskbar clock and calendar flyout. In this version of Windows 10, supported additional calendars are: Simplified or Traditional Chinese lunar calendar. Turning on one of these calendars will display Chinese lunar dates below the default calendar for the locale. Select Don't show additional calendars to prevent showing other calendars besides the default calendar for the locale.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Settings#configuretaskbarcalendar"],"categoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","categoryName":"Settings","options":[{"id":"user_vendor_msft_policy_config_settings_configuretaskbarcalendar_0","displayName":"User will be allowed to configure the setting.","description":"User will be allowed to configure the setting.","helpText":null},{"id":"user_vendor_msft_policy_config_settings_configuretaskbarcalendar_1","displayName":"Don't show additional calendars.","description":"Don't show additional calendars.","helpText":null},{"id":"user_vendor_msft_policy_config_settings_configuretaskbarcalendar_2","displayName":"Simplified Chinese (Lunar).","description":"Simplified Chinese (Lunar).","helpText":null},{"id":"user_vendor_msft_policy_config_settings_configuretaskbarcalendar_3","displayName":"Traditional Chinese (Lunar).","description":"Traditional Chinese (Lunar).","helpText":null}]},{"id":"user_vendor_msft_policy_config_settings_pagevisibilitylist","displayName":"Page Visibility List (User)","description":"Allows IT Admins to either prevent specific pages in the System Settings app from being visible or accessible, or to do so for all pages except those specified. The mode will be specified by the policy string beginning with either the string showonly: or hide:.  Pages are identified by a shortened version of their already published URIs, which is the URI minus the ms-settings: prefix. For example, if the URI for a settings page is ms-settings:bluetooth, the page identifier used in the policy will be just bluetooth. Multiple page identifiers are separated by semicolons. The following example illustrates a policy that would allow access only to the about and bluetooth pages, which have URI ms-settings:about and ms-settings:bluetooth respectively:showonly:about;bluetooth. If the policy is not specified, the behavior will be that no pages are affected. If the policy string is formatted incorrectly, it will be ignored entirely (i. e. treated as not set) to prevent the machine from becoming unserviceable if data corruption occurs. Note that if a page is already hidden for another reason, then it will remain hidden even if it is in a showonly: list. The format of the PageVisibilityList value is as follows: The value is a unicode string up to 10,000 characters long, which will be used without case sensitivity. There are two variants: one that shows only the given pages and one which hides the given pages. The first variant starts with the string showonly: and the second with the string hide:. Following the variant identifier is a semicolon-delimited list of page identifiers, which must not have any extra whitespace. Each page identifier is the ms-settings:xyz URI for the page, minus the ms-settings: prefix, so the identifier for the page with URI ms-settings:network-wifi would be just network-wifi. The default value for this setting is an empty string, which is interpreted as show everything. Example 1, specifies that only the wifi and bluetooth pages should be shown (they have URIs ms-settings:network-wifi and ms-settings:bluetooth). All other pages (and the categories they're in) will be hidden:showonly:network-wifi;bluetooth. Example 2, specifies that the wifi page should not be shown:hide:network-wifi","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Settings#pagevisibilitylist"],"categoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","categoryName":"Settings","options":null},{"id":"user_vendor_msft_policy_config_start_alwaysshownotificationicon","displayName":"Always Show Notification Icon (User)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#alwaysshownotificationicon"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_alwaysshownotificationicon_0","displayName":"Auto-hide notification bell icon","description":"Auto-hide notification bell icon","helpText":null},{"id":"user_vendor_msft_policy_config_start_alwaysshownotificationicon_1","displayName":"Show notification bell icon","description":"Show notification bell icon","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_configurestartpins","displayName":"Configure Start Pins (User)","description":"Allows admin to override the default items pinned to Start.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#configurestartpins"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":null},{"id":"user_vendor_msft_policy_config_start_disablecontextmenus","displayName":"Disable Context Menus (User)","description":"Enabling this policy prevents context menus from being invoked in the Start Menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#disablecontextmenus"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_disablecontextmenus_0","displayName":"Disabled","description":"Do not disable.","helpText":null},{"id":"user_vendor_msft_policy_config_start_disablecontextmenus_1","displayName":"Enabled","description":"Disable.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_forcestartsize","displayName":"Force Start Size (User)","description":"Forces the start screen size. If there is policy configuration conflict, the latest configuration request is applied to the device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#forcestartsize"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_forcestartsize_0","displayName":"Do not force size of Start.","description":"Do not force size of Start.","helpText":null},{"id":"user_vendor_msft_policy_config_start_forcestartsize_1","displayName":"Force non-fullscreen size of Start.","description":"Force non-fullscreen size of Start.","helpText":null},{"id":"user_vendor_msft_policy_config_start_forcestartsize_2","displayName":"Force a fullscreen size of Start.","description":"Force a fullscreen size of Start.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_hideapplist","displayName":"Hide App List (User)","description":"Setting the value of this policy to 1 or 2 collapses the app list. Setting the value of this policy to 3 removes the app list entirely. Setting the value of this policy to 2 or 3 disables the corresponding toggle in the Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hideapplist"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hideapplist_0","displayName":"None.","description":"None.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hideapplist_1","displayName":"Hide all apps list.","description":"Hide all apps list.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hideapplist_2","displayName":"Hide all apps list, and Disable \"Show app list in Start menu\" in Settings app.","description":"Hide all apps list, and Disable \"Show app list in Start menu\" in Settings app.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hideapplist_3","displayName":"Hide all apps list, remove all apps button, and Disable \"Show app list in Start menu\" in Settings app.","description":"Hide all apps list, remove all apps button, and Disable \"Show app list in Start menu\" in Settings app.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_hidecategoryview","displayName":"Hide Category View (User)","description":"This policy setting allows you to hide the category view in the Start Menu. If you enable this policy setting, the Start Menu will no longer show the category view as an option and will default to grid view.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidecategoryview"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hidecategoryview_0","displayName":"Category view shown.","description":"Category view shown.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hidecategoryview_1","displayName":"Category view hidden.","description":"Category view hidden.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_hidefrequentlyusedapps","displayName":"Hide Frequently Used Apps (User)","description":"Enabling this policy hides the most used apps from appearing on the start menu and disables the corresponding toggle in the Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidefrequentlyusedapps"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hidefrequentlyusedapps_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hidefrequentlyusedapps_1","displayName":"Enabled","description":"Hide.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_hidepeoplebar","displayName":"Hide People Bar (User)","description":"Enabling this policy removes the people icon from the taskbar as well as the corresponding settings toggle. It also prevents users from pinning people to the taskbar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidepeoplebar"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hidepeoplebar_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hidepeoplebar_1","displayName":"Enabled","description":"Hide.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_hiderecentjumplists","displayName":"Hide Recent Jumplists (User)","description":"Enabling this policy hides recent jumplists from appearing on the start menu/taskbar and disables the corresponding toggle in the Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hiderecentjumplists"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hiderecentjumplists_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hiderecentjumplists_1","displayName":"Enabled","description":"Hide.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_hiderecentlyaddedapps","displayName":"Hide Recently Added Apps (User)","description":"Enabling this policy hides recently added apps from appearing on the start menu and disables the corresponding toggle in the Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hiderecentlyaddedapps"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hiderecentlyaddedapps_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hiderecentlyaddedapps_1","displayName":"Enabled","description":"Hide.","helpText":null}]},{"id":"user_vendor_msft_policy_config_start_startlayout","displayName":"Start Layout (User)","description":"Important For more information, see Policy scope. Allows you to override the default Start layout and prevents the user from changing it. If both user and device policies are set, the user policy will be used. Apps pinned to the taskbar can also be changed with this policyFor further details on how to customize the Start layout, please see Customize and export Start layout and Configure Windows 10 taskbar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#startlayout"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":null},{"id":"user_vendor_msft_policy_config_start_turnoffabbreviateddatetimeformat","displayName":"Turn Off Abbreviated Date Time Format (User)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#turnoffabbreviateddatetimeformat"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_turnoffabbreviateddatetimeformat_0","displayName":"Show abbreviated time and date format","description":"Show abbreviated time and date format","helpText":null},{"id":"user_vendor_msft_policy_config_start_turnoffabbreviateddatetimeformat_1","displayName":"Show classic time and date format","description":"Show classic time and date format","helpText":null}]},{"id":"user_vendor_msft_policy_config_system_allowtelemetry","displayName":"Allow Telemetry (User)","description":"Allow the device to send diagnostic and usage telemetry data, such as Watson. For more information about diagnostic data for Windows, including what is and what is not collected by Windows, see Configure Windows diagnostic data in your organization. Note: This value is only applicable to Windows Enterprise, Windows Education, Windows Mobile Enterprise, Windows IoT Core (IoT Core), Windows Server 2016, and Windows CPC OS. The following tables describe the supported values:Windows 8. 1 Values:0 - Not allowed. 1 - Allowed, except for Secondary Data Requests. 2 (default) - Allowed. Windows 10 Values:0 - Security. Information that is required to help keep Windows or Windows CPC OS more secure, including data about the Connected User Experience and Telemetry component settings, the Malicious Software Removal Tool, and Windows Defender. Note: This value is only applicable to Windows 10 Enterprise, Windows 10 Education, Windows 10 Mobile Enterprise, Windows IoT Core (IoT Core), Windows Server 2016, and Windows CPC OS. Using this setting on other devices is equivalent to setting the value of 1. 1 - Basic. Basic device info, including: quality-related data, app compatibility, app usage data, and data from the Security level. 2 - Enhanced. Additional insights, including: how Windows, Windows Server, System Center, Windows CPC OS, and apps are used, how they perform, advanced reliability data, and data from both the Basic and the Security levels. 3 - Full. All data necessary to identify and help to fix problems, plus data from the Security, Basic, and Enhanced levels. Important lf you are using Windows 8. 1 MDM server and set a value of 0 using the legacy AllowTelemetry policy on a Windows 10 Mobile device, then the value is not respected and the telemetry level is silently set to level 1. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#allowtelemetry"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"user_vendor_msft_policy_config_system_allowtelemetry_0","displayName":"Security","description":"Security. Information that is required to help keep Windows more secure, including data about the Connected User Experience and Telemetry component settings, the Malicious Software Removal Tool, and Windows Defender.\nNote: This value is only applicable to Windows 10 Enterprise, Windows 10 Education, Windows 10 Mobile Enterprise, Windows 10 IoT Core (IoT Core), and Windows Server 2016. Using this setting on other devices is equivalent to setting the value of 1.","helpText":null},{"id":"user_vendor_msft_policy_config_system_allowtelemetry_1","displayName":"Basic","description":"Basic. Basic device info, including: quality-related data, app compatibility, app usage data, and data from the Security level.","helpText":null},{"id":"user_vendor_msft_policy_config_system_allowtelemetry_3","displayName":"Full","description":"Full. All data necessary to identify and help to fix problems, plus data from the Security, Basic, and Enhanced levels.","helpText":null}]},{"id":"user_vendor_msft_policy_config_teamsv2~policy~l_teams_teams_preventfirstlaunchafterinstall_policy","displayName":"Prevent Microsoft Teams from starting automatically after installation (User)","description":"This policy setting controls whether Microsoft Teams starts automatically when the user logs into a device after Teams is installed.\r\n\r\nIf you enable this policy setting, Teams does not start automatically when the user logs in to the device and the user has not started Teams previously.\r\n\r\nNote: If you enable this policy setting, you must do so before Teams is installed.\r\n\r\nOnce a user starts Teams for the first time, Teams is configured to start automatically the next time the user logs into the device.\r\n\r\nIf you disable or don’t configure this policy setting, Teams automatically starts when a user logs in to the device after Teams is installed.\r\n\r\nNote: The user can configure Teams not to start automatically by configuring user settings within Teams.","helpText":"","infoUrls":[],"categoryId":"501b5a30-253c-48b7-ab40-de1d100e4358","categoryName":"Microsoft Teams","options":[{"id":"user_vendor_msft_policy_config_teamsv2~policy~l_teams_teams_preventfirstlaunchafterinstall_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_teamsv2~policy~l_teams_teams_preventfirstlaunchafterinstall_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy","displayName":"Restrict sign in to Teams to accounts in specific tenants (User)","description":"This policy setting allows you to control the accounts that can be used in Teams on managed devices running Windows. \r\n\r\nIf you enable this policy setting, users will only be allowed to sign in with accounts from Azure Active Directory (Azure AD) tenants that you specify. You can enter a comma separated list of tenant IDs. \r\n \r\nThe policy setting applies to all ways that the user signs in, including first and additional accounts on versions of Teams that support multiple accounts side by side. \r\n\r\nThe policy setting is also enforced when users sign out and sign back in. \r\n\r\nIf you disable or don't configure this policy setting, Teams will continue to allow users to sign in with work or school accounts, or personal Microsoft accounts. \r\n\r\nImportant: This policy setting only restricts which users can sign in. It does not restrict the ability for users to be invited as a guest in other Azure AD tenants, or switch to tenants they were invited to.\r\n\r\nNote: This policy does not apply to Teams web app.","helpText":"","infoUrls":[],"categoryId":"501b5a30-253c-48b7-ab40-de1d100e4358","categoryName":"Microsoft Teams","options":[{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy_restrictteamssignintoaccountsfromtenantlist","displayName":"Tenant IDs: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"501b5a30-253c-48b7-ab40-de1d100e4358","categoryName":"Microsoft Teams","options":null},{"id":"user_vendor_msft_policy_config_timelanguagesettings_restrictlanguagepacksandfeaturesinstall","displayName":"Restrict Language Packs And Features Install (User)","description":"This policy setting restricts the install of language packs and language features, such as spell checkers, on a device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TimeLanguageSettings#restrictlanguagepacksandfeaturesinstall"],"categoryId":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","categoryName":"Time Language Settings","options":[{"id":"user_vendor_msft_policy_config_timelanguagesettings_restrictlanguagepacksandfeaturesinstall_0","displayName":"Disabled","description":"Not restricted.","helpText":null},{"id":"user_vendor_msft_policy_config_timelanguagesettings_restrictlanguagepacksandfeaturesinstall_1","displayName":"Enabled","description":"Restricted.","helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"d5b3cab7-d486-4f74-8525-6bd740b950bc","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize98","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d5b3cab7-d486-4f74-8525-6bd740b950bc","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize98_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"d5b3cab7-d486-4f74-8525-6bd740b950bc","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize98_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"d5b3cab7-d486-4f74-8525-6bd740b950bc","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys100","displayName":"Disable shortcut keys (User)","description":"Specify the virtual key code and modifier for the shortcut key to disable.","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys100_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys100_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys100_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"Specify command bar buttons and menu items to disable.","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient","displayName":"File Tab | Share | Email (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlink","displayName":"Insert tab | Hyperlink (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlink_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlink_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosmacros","displayName":"Developer tab | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosmacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosmacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosvisualbasiceditor","displayName":"Developer tab | Visual Basic (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosvisualbasiceditor_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosvisualbasiceditor_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_visiooptions99","displayName":"File tab | Options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_visiooptions99_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_visiooptions99_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab","displayName":"Default tab to show in Visio on the Office Start screen and in File | New (User)","description":"This policy setting controls what displays as the default tab in Visio on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, you can choose one of two options to become the default tab on the Office Start screen and in File | New:\r\n\r\n* Built-in – Users will the see built-in templates tab as the default tab in Visio on the Office Start screen and in File | New.\r\n\r\n* Custom – Users will the see custom templates tab as the default tab in Visio on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Visio on the Office Start screen and in File | New","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab","displayName":"Default tab (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab_0","displayName":"Featured","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab_2","displayName":"Built-in","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_defaultbuiltintab_l_defaultbuiltintab_1","displayName":"Custom","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_disableofficestartvisio","displayName":"Disable the Office Start screen for Visio (User)","description":"This policy setting controls whether the Office Start screen appears on boot for Visio.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot Visio.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot Visio.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_disableofficestartvisio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_disableofficestartvisio_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_emailmessageforsendtocommands","displayName":"Email message for 'Send To' commands (User)","description":"Command in the Send To submenu of the File menu.","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_emailmessageforsendtocommands_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_emailmessageforsendtocommands_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_emailmessageforsendtocommands_l_emailmessageforsendtocommands101","displayName":"Email message for 'Send To' commands (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Visio\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Visio\\Addins.\r\n\r\nYou can also obtain the ProgID of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_personaltemplatespath","displayName":"Personal templates path for Visio (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_alwaysoffermetricandusunitsfornewblankdrawings","displayName":"Always offer 'Metric' and 'US units' for new blank drawings and stencils (User)","description":"This policy setting will allow the showing of both US Units and Metric Units when you create a new blank drawing or stencil.\r\n\r\nIf you enable this policy setting, both US Units and Metric Units are shown as a choice before you create a new blank drawing or stencil. These drawings open with the appropriate rulers and page setup and use the appropriate units for the drawing tools. This does not install the templates and stencils in both unit types. This policy setting is always enabled whenever the Developer Tab is turned on.\r\n\r\nIf you disable or do not configure this policy setting, you are not shown a choice between units when creating a blank drawing or stencil if templates and stencils of only one type of unit are installed.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_alwaysoffermetricandusunitsfornewblankdrawings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_alwaysoffermetricandusunitsfornewblankdrawings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle","displayName":"Angle (User)","description":"Specifies the unit of measure for the angle of rotation.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_l_angle8","displayName":"Angle (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_l_angle8_81","displayName":"Degrees","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_l_angle8_82","displayName":"Deg-Min-Sec","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_l_angle8_84","displayName":"Min-Sec","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_l_angle8_85","displayName":"Seconds","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_angle_l_angle8_83","displayName":"Radians","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration","displayName":"Duration (User)","description":"Specifies the unit of measure for duration, which is elapsed time as compared to a specific date or a given hour.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_l_duration9","displayName":"Duration (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_l_duration9_43","displayName":"Weeks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_l_duration9_44","displayName":"Days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_l_duration9_45","displayName":"Hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_l_duration9_46","displayName":"Minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_l_duration9_47","displayName":"Seconds","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_preventshowingnewscreenonlaunch","displayName":"Prevent showing New screen on launch (User)","description":"This policy setting allows you to prevent the New screen to be shown on launch of Visio.\r\n\r\nIf you enable this policy setting, the New screen will not be shown on launch.\r\n\r\nIf you disable or do not configure this policy setting, the New screen, including a catalog of templates, is shown when you open Visio.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_preventshowingnewscreenonlaunch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_preventshowingnewscreenonlaunch_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist","displayName":"Number of entries in the Recent Drawings list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Drawings list that appears when users click Open on the File tab in Backstage view. \r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Drawings list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Drawings list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist_l_numberofentries","displayName":"Number of entries: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"Number of folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_smarttags","displayName":"Actions (User)","description":"Shows additional actions if you hover over them in the drawing.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_smarttags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_smarttags_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear","displayName":"Specify ScreenTips to appear (User)","description":"This policy setting allows you to specify what ScreenTips appear in Visio to help you identify and use various features, including drawing window rulers, control handles, and ShapeSheet cells.\r\n\r\nIf you enable this policy setting, you may specify one or more other ScreenTips that will appear for:\r\n- Drawing\r\n- Dialogs\r\n- Rulers\r\n- ShapeSheet\r\n\r\nIf you disable or do not configure this policy setting, no ScreenTips will appear for the options listed above.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid1","displayName":"Drawing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid1_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid2","displayName":"Dialogs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid2_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid2_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid3","displayName":"Rulers (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid3_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid4","displayName":"Shapesheet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid4_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid4_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_stencilwindowscreentips","displayName":"Stencil window ScreenTips (User)","description":"Specifies whether ScreenTips (ScreenTips: Tips that appear when you pause the pointer over certain elements in the Visio program, including: masters on stencils, toolbar buttons, and the ruler) appear in Visio to help you identify shapes in the stencil window.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_stencilwindowscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_stencilwindowscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text","displayName":"Text (User)","description":"Specifies the unit of measure for indents, line spacing and other text measurements. The default unit for type size is points (1 point = 1/72 in.). You can enter type size in another unit of measure (for example, 1ft or 12 in) but you can't change the default.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_l_text7","displayName":"Text (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_l_text7_51","displayName":"Picas","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_l_text7_50","displayName":"Points","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_l_text7_54","displayName":"Ciceros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_l_text7_53","displayName":"Didots","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_centerselectiononzoom","displayName":"Center selection on zoom (User)","description":"Specifies that when you zoom in, whatever shape was selected appears in the center of the window.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_centerselectiononzoom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_centerselectiononzoom_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enableautoconnect","displayName":"Enable AutoConnect (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enableautoconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enableautoconnect_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enablelivedynamics","displayName":"Enable live dynamics (User)","description":"When you resize or rotate a shape, you can see the shape as it is being transformed, instead of just seeing the bounding box until the action is complete","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enablelivedynamics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enablelivedynamics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enalbeconnectorsplitting","displayName":"Enable connector splitting (User)","description":"When you place a shape on the line of a connector, it splits and each piece becomes a separate connector glued to the shape. Not all drawing types support connector splitting.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enalbeconnectorsplitting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enalbeconnectorsplitting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_selectshapespartiallywithinarea","displayName":"Select shapes partially within area (User)","description":"If you select shapes by using a selection net(dragging a box around shapes on the drawing page), you can change the selection settings to also include shapes that are partially within the selection net.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_selectshapespartiallywithinarea_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_selectshapespartiallywithinarea_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_showmorehandles","displayName":"Show more handles on hover (User)","description":"This policy setting allows you to show more shape handles when hovering over a selected shape.\r\n\r\nIf you enable this policy setting, more shape handles will be shown after a brief delay.\r\n\r\nIf you disable or do not configure this policy setting, more shape handles will not be shown.\r\n","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_showmorehandles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_showmorehandles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnoffshapesheetformulaautocomplete","displayName":"Turn off ShapeSheet Formula AutoComplete (User)","description":"This policy setting allows you to configure ShapeSheet Formula AutoComplete.\r\n\r\nIf you enable this policy setting, ShapeSheet Formula AutoComplete is turned off.\r\n\r\nIf you disable or do not configure this policy setting, ShapeSheet Formula AutoComplete is turned on.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnoffshapesheetformulaautocomplete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnoffshapesheetformulaautocomplete_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnoffsmartdeletebehaviorofconnectorswhendeletingshapes","displayName":"Turn off smart delete behavior of connectors when deleting shapes (User)","description":"This policy setting turns off smart delete behavior of connectors when deleting shapes.\r\n\r\nIf you enable this policy setting, connectors are not deleted when shapes are deleted.\r\n\r\nIf you disable or do not configure this policy setting, connectors are deleted when shapes are deleted.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnoffsmartdeletebehaviorofconnectorswhendeletingshapes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnoffsmartdeletebehaviorofconnectorswhendeletingshapes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnofftransitions","displayName":"Turn off transitions (User)","description":"This policy setting allows you to configure transitions, which are smooth animation effects.\r\n\r\nIf you enable this policy setting, transitions are turned off.\r\n\r\nIf you disable or do not configure this policy setting, transitions are turned on.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnofftransitions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_turnofftransitions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_zoomonrollwithintellimouse","displayName":"Zoom on roll with IntelliMouse (User)","description":"If selected, lets you zoom in or out from a drawing by rolling the wheel of the Microsoft Intellimouse","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_zoomonrollwithintellimouse_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_zoomonrollwithintellimouse_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_addons","displayName":"Add-ons (User)","description":"Displays the additional location of macros and add-ons.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_addons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_addons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_addons_l_addonscolon","displayName":"Add-ons: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings","displayName":"Drawings (User)","description":"Displays the additional location of drawings. When you add a location here, it becomes the default save location.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings_l_drawingscolon","displayName":"Drawings: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_favoritesstencilname","displayName":"Favorites Stencil Name (User)","description":"Displays the name of the stencil created in the My Shapes folder that contains a user's favorite shapes.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_favoritesstencilname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_favoritesstencilname_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_favoritesstencilname_l_favoritesstencilnamecolon","displayName":"Favorites Stencil Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_help","displayName":"Help (User)","description":"Displays the additional location of Help files.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_help_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_help_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_help_l_helpcolon","displayName":"Help: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes","displayName":"My Shapes (User)","description":"Displays the path of the My Shapes folder.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes_l_myshapescolon","displayName":"My Shapes: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup","displayName":"Start-up (User)","description":"Displays the additional location for macros and add-ons opened when you start Visio.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup_l_startupcolon","displayName":"Start-up: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_stencils","displayName":"Stencils (User)","description":"Displays the additional location of stencils. When a location is added here, stencils in this location are listed on the Shapes submenu from the file menu.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_stencils_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_stencils_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_stencils_l_stencilscolon","displayName":"Stencils: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates","displayName":"Templates (User)","description":"This policy setting allows you to specify the additional location of templates.\r\n\r\nIf you enable this policy setting, you may specify the additional location of templates. These locations are listed on the New screen of the File tab.\r\n\r\nIf you disable or do not configure this policy setting, no additional location of templates is shown.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates_l_templatescolon","displayName":"Templates: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_enableautomationevents","displayName":"Enable Automation events (User)","description":"Enables Visio events to be sent to Visio add-ons and VBA macros. If cleared, disables all Visio events. If you clear this option, some drawing types in Visio that rely on Automation events may not have full functionality.","helpText":"","infoUrls":[],"categoryId":"4e62ada2-f091-49e1-99dd-ffdf5cf558cd","categoryName":"General Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_enableautomationevents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_enableautomationevents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_openeachshapesheetinthesamewindow","displayName":"Open each ShapeSheet in the same window (User)","description":"Opens multiple ShapeSheets in the same window rather than displaying each ShapeSheet in its own window.","helpText":"","infoUrls":[],"categoryId":"4e62ada2-f091-49e1-99dd-ffdf5cf558cd","categoryName":"General Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_openeachshapesheetinthesamewindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_openeachshapesheetinthesamewindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_putallsettingsinwindowsregistry","displayName":"Put all settings in Windows registry (User)","description":"Adds all possible application settings into the Windows registry. By default, only certain settings are added (non-default settings and very few others, such as file paths, import and export filters, and last files) to keep the registry settings simple.","helpText":"","infoUrls":[],"categoryId":"4e62ada2-f091-49e1-99dd-ffdf5cf558cd","categoryName":"General Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_putallsettingsinwindowsregistry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_putallsettingsinwindowsregistry_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4","displayName":"Language for file conversion (User)","description":"This policy setting specifies how Visio determines what language to use when converting to or from an earlier version of Visio. \r\n\r\nIf you enable this policy setting, you may select from one of these options:\r\n\r\n- Let Visio decide language\r\n- Prompt for language\r\n- Use the following language: You must specify the numeric Microsoft Locale ID (LCID) for that language.\r\n\r\nIf you disable or do not configure this policy setting, Visio decides what language to use.","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_l_languageforfileconversion5","displayName":"Language for file conversion (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_l_languageforfileconversion5_0","displayName":"Let Visio decide language","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_l_languageforfileconversion5_1","displayName":"Prompt for language","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_l_languageforfileconversion5_2","displayName":"Use the following language","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_l_uselanguage","displayName":"Use language: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfileopenwarnings","displayName":"Show file open warnings (User)","description":"Indicates whether a warning message is displayed when you open files that contain errors such as invalid XML code.","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfileopenwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfileopenwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfilesavewarnings","displayName":"Show file save warnings (User)","description":"Indicates whether a warning message is displayed when you save files that contain errors such as invalid XML code.","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfilesavewarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfilesavewarnings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_openresultsnewwindow","displayName":"Open results new window (User)","description":"Indicates whether a new search results stencil is created for every search. If cleared, the results of a search replace the results of any previous search.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_openresultsnewwindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_openresultsnewwindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor","displayName":"Search for: (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_l_searchfor10","displayName":"Search for: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_l_searchfor10_1","displayName":"All of the words (AND)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_l_searchfor10_0","displayName":"Any of the words (OR)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults","displayName":"Search results (User)","description":"Specifies whether results are returned in alphabetical order by shape name or by stencil name (group). Click By Group to help distinguish between shapes that have the same name but appear on different stencils. Selecting this option is also useful if you want to locate the stencil containing the shape.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_l_searchresults11","displayName":"Search results (User)","description":"","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_l_searchresults11_0","displayName":"Alphabetically","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_l_searchresults11_1","displayName":"By Group","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_showshapesearchpane","displayName":"Show Shape Search pane (User)","description":"Displays the shape search user interface elements of the stencil window.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_showshapesearchpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_showshapesearchpane_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_donotshowminitoolbaronselectionoftext","displayName":"Do not show Mini Toolbar on selection of text (User)","description":"This policy setting allows you to configure the Mini Toolbar on selection of text.\r\n\r\nIf you enable this policy setting, the Mini Toolbar is not shown on selection.\r\n\r\nIf you disable or do not configure this policy setting, the Mini Toolbar is shown on selection.","helpText":"","infoUrls":[],"categoryId":"a7d55d90-e1d1-4577-8bfd-fe2641bce461","categoryName":"User Interface Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_donotshowminitoolbaronselectionoftext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_donotshowminitoolbaronselectionoftext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_turnofflivepreview","displayName":"Turn off Live Preview (User)","description":"This policy setting allows you to configure Live Preview, which shows a preview of how a feature affects the document as you hover over different choices.\r\n\r\nIf you enable this policy setting, Live Preview is turned off.\r\n\r\nIf you disable or do not configure this policy setting, Live Preview is turned on.","helpText":"","infoUrls":[],"categoryId":"a7d55d90-e1d1-4577-8bfd-fe2641bce461","categoryName":"User Interface Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_turnofflivepreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_turnofflivepreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_turnofflivepreviewintheshapeswindow","displayName":"Turn off Live Preview in the Shapes window (User)","description":"This policy setting turns off the Live Preview in the Shapes window feature, which shows shapes in the Shapes window with the detail and color depth they will have in a drawing, including theme colors and effects.\r\n\r\nIf you enable this policy setting, Live Preview in the Shapes Window is turned off.\r\n\r\nIf you disable or do not configure this policy setting, Live Preview in the Shapes Window is turned on.","helpText":"","infoUrls":[],"categoryId":"a7d55d90-e1d1-4577-8bfd-fe2641bce461","categoryName":"User Interface Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_turnofflivepreviewintheshapeswindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_turnofflivepreviewintheshapeswindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"2764869c-54a3-462b-bc72-c580621ab6bb","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_fractionswithfractioncharacter","displayName":"Fractions with fraction character (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"af9b2941-29f9-4ee5-ae09-215f4e242943","categoryName":"AutoCorrect Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_fractionswithfractioncharacter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_fractionswithfractioncharacter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_hyphenswithdash","displayName":"Hyphens with dash (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"af9b2941-29f9-4ee5-ae09-215f4e242943","categoryName":"AutoCorrect Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_hyphenswithdash_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_hyphenswithdash_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_ordinalswithsuperscript","displayName":"Ordinals with superscript (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"af9b2941-29f9-4ee5-ae09-215f4e242943","categoryName":"AutoCorrect Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_ordinalswithsuperscript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_ordinalswithsuperscript_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_smileyfacesandarrowswithspecialsymbols","displayName":"Smiley faces and arrows with special symbols (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"af9b2941-29f9-4ee5-ae09-215f4e242943","categoryName":"AutoCorrect Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_smileyfacesandarrowswithspecialsymbols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_smileyfacesandarrowswithspecialsymbols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_straightquoteswithsmartquotes","displayName":"Straight quotes with smart quotes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"af9b2941-29f9-4ee5-ae09-215f4e242943","categoryName":"AutoCorrect Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_straightquoteswithsmartquotes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_straightquoteswithsmartquotes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save_l_turnoffcaddwgfunctionality","displayName":"Turn off CAD/DWG functionality (User)","description":"This policy setting allows you to turn off all entry points related to CAD/DWG files.\r\n\r\nIf you enable this policy setting, CAD/DWG functionality will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, CAD/DWG functionality will be turned on.","helpText":"","infoUrls":[],"categoryId":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save_l_turnoffcaddwgfunctionality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save_l_turnoffcaddwgfunctionality_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto","displayName":"Save checked-out files to (User)","description":"This policy setting allows you to choose if checked-out files are saved to the server drafts location or the web server. \r\n\r\nIf you enable this policy setting, you can choose where checked-out files are saved:\r\n- Server drafts location: The server drafts location on this computer\r\n- Web server: The web server\r\n\r\nIf you disable or do not configure this policy setting, checked-out files are stored in the server drafts location.","helpText":"","infoUrls":[],"categoryId":"2eed22da-106f-4c93-9a45-5ce803b50233","categoryName":"Offline Editing","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_l_savecheckedoutfilestodropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2eed22da-106f-4c93-9a45-5ce803b50233","categoryName":"Offline Editing","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_l_savecheckedoutfilestodropid_1","displayName":"Server drafts location","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_l_savecheckedoutfilestodropid_0","displayName":"Web server","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_promptfordocumentpropertiesonfirstsave","displayName":"Prompt for document properties on first save (User)","description":"Indicates whether the properties dialog box opens when a file is saved for the first time. File properties include author name and information such as the status of the file, preview settings and other properties.","helpText":"","infoUrls":[],"categoryId":"73415dea-0103-4427-83c5-6c97bf81af1d","categoryName":"Save Documents","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_promptfordocumentpropertiesonfirstsave_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_promptfordocumentpropertiesonfirstsave_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas","displayName":"Save Visio files as (User)","description":"Identifies the default file format in which Visio files are saved.","helpText":"","infoUrls":[],"categoryId":"73415dea-0103-4427-83c5-6c97bf81af1d","categoryName":"Save Documents","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas_l_savevisiofilesas6","displayName":"Save Visio files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"73415dea-0103-4427-83c5-6c97bf81af1d","categoryName":"Save Documents","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas_l_savevisiofilesas6_0","displayName":"Visio Document","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas_l_savevisiofilesas6_3","displayName":"Visio Macro-Enabled Document","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_savevisiofilesas_l_savevisiofilesas6_1","displayName":"Visio 2003-2016 Document","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_enablemicrosoftvisualbasicforapplicationsproject","displayName":"Enable Microsoft Visual Basic for Applications project creation (User)","description":"Enables creations of VBA projects when you open (or create) a document that does not already contain a project. If you clear this check box, you will not be able to create a macro in a document that does not already contain a project.","helpText":"","infoUrls":[],"categoryId":"253fda23-118b-48c7-b24a-27b8c93df41a","categoryName":"Macro Security","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_enablemicrosoftvisualbasicforapplicationsproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_enablemicrosoftvisualbasicforapplicationsproject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_loadmicrosoftvisualbasicforapplicationsprojectsf","displayName":"Load Microsoft Visual Basic for Applications projects from text (User)","description":"If you want to be able to have your VBA project work in drawings created in other versions of Visio, select this option so that your VBA project is compiled when the file is loaded, but the compiled project is never saved.","helpText":"","infoUrls":[],"categoryId":"253fda23-118b-48c7-b24a-27b8c93df41a","categoryName":"Macro Security","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_loadmicrosoftvisualbasicforapplicationsprojectsf_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_loadmicrosoftvisualbasicforapplicationsprojectsf_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_allowtrustedlocationsonthenetwork","displayName":"Allow Trusted Locations on the network (User)","description":"This policy setting controls whether trusted locations on the network can be used.\r\n\r\nIf you enable this policy setting, users can specify trusted locations on network shares or in other remote locations that are not under their direct control by clicking the \"Add new location\" button in the Trusted Locations section of the Trust Center. Content, code, and add-ins are allowed to load from trusted locations with minimal security and without prompting the user for permission.\r\n\r\nIf you disable this policy setting, the selected application ignores any network locations listed in the Trusted Locations section of the Trust Center. \r\n\r\nIf you also deploy Trusted Locations via Group Policy, you should verify whether any of them are remote locations. If any of them are remote locations and you do not allow remote locations via this policy setting, those policy keys that point to remote locations will be ignored on client computers.\r\n\r\nDisabling this policy setting does not delete any network locations from the Trusted Locations list, but causes disruption for users who add network locations to the Trusted Locations list. Users are also prevented from adding new network locations to the Trusted Locations list in the Trust Center. We recommended that you do not enable this policy setting (as the \"Allow Trusted Locations on my network (not recommended)\" check box also states). Therefore, in practice, it should be possible to disable this policy setting in most situations without causing significant usability issues for most users.\r\n\r\nIf you do not enable this policy setting, users can select the \"Allow Trusted Locations on my network (not recommended)\" check box if desired and then specify trusted locations by clicking the \"Add new location\" button.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_allowtrustedlocationsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_allowtrustedlocationsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users, except if application add-ins are required to be signed by Trusted Publishers.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User) (Deprecated)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the 2016 versions of the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the 2016 versions of the specified applications are ignored, including any trusted locations established by Office during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the 2016 versions of the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve","displayName":"Set maximum number of trust records to preserve (User)","description":"This policy setting allows you to specify the maximum number of trust records to preserve when the purge task detects that this application has trusted more than the number of trusted documents set by the \"Set maximum number of trusted documents\" policy setting.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of trust records to preserve, with an upper limit of 20000. Due to performance reasons, it is not recommended to set it to the upper limit.\r\n\r\nIf you disable or you do not configure this policy setting, the default value for of 400 is used.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_l_setmaximumnumberoftrustrecordstopreservespinid","displayName":"Maximum to preserve: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_allowsubfolders15","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_allowsubfolders15_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_allowsubfolders15_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_datecolon13","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_descriptioncolon14","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_pathcolon12","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_datecolon17","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_descriptioncolon18","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_pathcolon16","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_datecolon21","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_descriptioncolon22","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_pathcolon20","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_datecolon25","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_descriptioncolon26","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_pathcolon24","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_allowsubfolders31","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_allowsubfolders31_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_allowsubfolders31_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_datecolon29","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_descriptioncolon30","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_pathcolon28","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_allowsubfolders35","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_allowsubfolders35_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_allowsubfolders35_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_datecolon33","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_allowsubfolders39","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_allowsubfolders39_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_allowsubfolders39_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_descriptioncolon38","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_pathcolon36","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_descriptioncolon42","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_pathcolon40","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_datecolon45","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_descriptioncolon46","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_pathcolon44","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11","displayName":"Trusted Location #11 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_allowsubfolders51","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_allowsubfolders51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_allowsubfolders51_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_datecolon49","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_descriptioncolon50","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_pathcolon48","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_allowsubfolders55","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_allowsubfolders55_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_allowsubfolders55_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_descriptioncolon54","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_allowsubfolders59","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_allowsubfolders59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_allowsubfolders59_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_datecolon57","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_descriptioncolon58","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_pathcolon56","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_allowsubfolders63","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_allowsubfolders63_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_allowsubfolders63_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_datecolon61","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_pathcolon60","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_pathcolon64","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_datecolon69","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_descriptioncolon70","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_pathcolon68","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_datecolon73","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_descriptioncolon74","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_pathcolon72","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_datecolon77","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_descriptioncolon78","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_pathcolon76","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_datecolon81","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_descriptioncolon82","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_pathcolon80","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_datecolon85","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_descriptioncolon86","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_pathcolon84","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocuments","displayName":"Turn off trusted documents (User)","description":"This policy setting allows you to turn off the trusted documents feature. The trusted documents feature allows users to always enable active content in documents such as macros, ActiveX controls, data connections, etc. so that they are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.\r\n\r\nIf you enable this policy setting, you will turn off the trusted documents feature. Users will receive a security prompt every time a document containing active content is opened.\r\n\r\nIf you disable or do not configure this policy setting, documents will be trusted when users enable content for a document, and users will not receive a security prompt.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork","displayName":"Turn off Trusted Documents on the network (User)","description":"This policy setting allows you to turn off the trusted documents feature for documents opened from the network.\r\n\r\nIf you enable this policy setting, users will always see security notifications for active content such as macros, ActiveX controls, data connections, etc. for documents opened from the network.\r\n\r\nIf you disable or do not configure this policy setting, the trusted documents feature allows users to always allow active content in documents such as macros, ActiveX controls, data connections, etc. so that users are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files","displayName":"Visio 2000-2002 Binary Drawings, Templates and Stencils (User)","description":"This policy setting allows you to determine whether users can open or save Visio files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked: Both opening and saving of the file type will be blocked.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_l_visio2000filesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_l_visio2000filesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_l_visio2000filesdropid_2","displayName":"Open/Save blocked","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files","displayName":"Visio 2003-2010 Binary Drawings, Templates and Stencils (User)","description":"This policy setting allows you to determine whether users can open or save Visio files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked: Both opening and saving of the file type will be blocked.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid_2","displayName":"Open/Save blocked","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio50andearlierfiles","displayName":"Visio 5.0 or earlier Binary Drawings, Templates and Stencils (User)","description":"This policy setting allows you to determine whether users can open or save Visio files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked: Both opening and saving of the file type will be blocked.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio50andearlierfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio50andearlierfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio50andearlierfiles_l_visio50andearlierfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio50andearlierfiles_l_visio50andearlierfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio50andearlierfiles_l_visio50andearlierfilesdropid_2","displayName":"Open/Save blocked","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visio16v3~policy~l_microsoftvisio~l_visiooptions~l_proofing_l_disablevisiornrpane","displayName":"Turn off Research and Translation features in Visio (User)","description":"\r\n This policy setting controls whether the Research and Translation features appear in Visio.\r\n\r\n If you enable this policy setting, users won’t see the Research and Translation features in Visio.\r\n\r\n If you disable or don't configure this policy setting, users will see the Research and Translation features in Visio.\r\n\r\n Note: This policy setting only applies to subscription versions of Visio and Visio LTSC 2021.\r\n ","helpText":"","infoUrls":[],"categoryId":"8495c82c-f273-4bcc-8886-6751103a9c7b","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_visio16v3~policy~l_microsoftvisio~l_visiooptions~l_proofing_l_disablevisiornrpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v3~policy~l_microsoftvisio~l_visiooptions~l_proofing_l_disablevisiornrpane_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablefeedbackdialog","displayName":"Disable the send-a-smile feature (User)","description":"This policy disables the Visual Studio send-a-smile feature.","helpText":"","infoUrls":[],"categoryId":"802f3065-0bf1-4578-9d6d-ab1ef02db3ec","categoryName":"Feedback Settings","options":[{"id":"user_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablefeedbackdialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablefeedbackdialog_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablescreenshotcapture","displayName":"Disables send-a-smile's screenshot capability (User)","description":"This policy disables the screenshot capability in the send-a-smile feature.","helpText":"","infoUrls":[],"categoryId":"802f3065-0bf1-4578-9d6d-ab1ef02db3ec","categoryName":"Feedback Settings","options":[{"id":"user_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablescreenshotcapture_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablescreenshotcapture_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_allowrecallexport","displayName":"Allow Recall Export (User) (Windows Insiders only)","description":"This policy allows you to determine whether Recall and snapshot information can be exported. Recall and snapshot information may be sensitive, and the files that are exported are unencrypted. Users can export from Settings > Privacy & Security > Recall & Snapshots > Advanced Settings > Export your Recall and snapshot info. Users are warned that the files are unencrypted before exporting. When you set this policy to enabled, users will be able to export Recall and snapshot information. If the policy is set to disabled or not configured, users will not be able to export their Recall and snapshot information.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#allowrecallexport"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_allowrecallexport_0","displayName":"Deny export of Recall and snapshots information","description":"Deny export of Recall and snapshots information","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_allowrecallexport_1","displayName":"Allow export of Recall and snapshot information","description":"Allow export of Recall and snapshot information","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_disableaidataanalysis","displayName":"Disable AI Data Analysis (User)","description":"This policy setting allows you to determine whether end users have the option to allow snapshots to be saved on their PCs. If disabled, end users will have a choice to save snapshots of their screen on their PC and then use Recall to find things they've seen. If the policy is enabled, end users will not be able to save snapshots on their PC. If the policy is not configured, end users will not be able to save snapshots on their PC.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disableaidataanalysis"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_disableaidataanalysis_0","displayName":"Enable Saving Snapshots for Windows.","description":"Enable Saving Snapshots for Windows.","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_disableaidataanalysis_1","displayName":"Disable Saving Snapshots for Windows.","description":"Disable Saving Snapshots for Windows.","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_disableclicktodo","displayName":"Disable Click To Do (User)","description":"Click to Do lets people take action on content on their screens. When activated, it takes a screenshot of their screen and analyzes it to present actions. Click to Do ends when they exit it, and it can't take screenshots while closed. Screenshot analysis is always performed locally on their device. By default, Click to Do is enabled for users. This policy setting allows you to determine whether Click to Do is available for users on their device. When the policy is enabled, the Click to Do component and entry points will not be available to users. When the policy is disabled, users will have Click to Do available on their device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disableclicktodo"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_disableclicktodo_0","displayName":"Click to Do is enabled","description":"Click to Do is enabled","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_disableclicktodo_1","displayName":"Click to Do is disabled.","description":"Click to Do is disabled.","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_removemicrosoftcopilotapp","displayName":"Remove Microsoft Copilot App (User)","description":"This policy setting allows you to uninstall Microsoft Copilot from devices in a targeted way. It will apply to devices/users that meet the below conditions: Microsoft 365 Copilot and Microsoft Copilot are both installed; the Microsoft Copilot app was not installed by the user; the Microsoft Copilot app was not launched in the last 14 days. If this policy is enabled, the Microsoft Copilot app will be uninstalled. Users can still re-install if they choose to. This setting applies to Enterprise, Professional and Education client SKUs only.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#removemicrosoftcopilotapp"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_removemicrosoftcopilotapp_0","displayName":"Removal Disabled.","description":"Removal Disabled.","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_removemicrosoftcopilotapp_1","displayName":"Removal Enabled.","description":"Removal Enabled.","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_setcopilothardwarekey","displayName":"Set Copilot Hardware Key (User)","description":"This policy setting determines which app opens when the user presses the Copilot key on their keyboard. If the policy is enabled, the specified app will open when the user presses the Copilot key. Users can change the key assignment in Settings. If the policy is not configured, Copilot will open if it's available in that country or region.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setcopilothardwarekey"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":null},{"id":"user_vendor_msft_policy_config_windowsai_setdenyapplistforrecall","displayName":"Set Deny App List For Recall (User)","description":"This policy allows you to set a semicolon-separated list of app names which should not be collected in Recall Snapshots\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setdenyapplistforrecall"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":null},{"id":"user_vendor_msft_policy_config_windowsai_setdenyurilistforrecall","displayName":"Set Deny Uri List For Recall (User)","description":"This policy allows you to set a semicolon-separated list of uris which should not be collected in Recall Snapshots\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setdenyurilistforrecall"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots","displayName":"Set Maximum Storage Duration For Recall Snapshots (User)","description":"This policy setting allows you to control the maximum amount of time (in days) that Windows saves snapshots for Recall. The default value for this setting is '0' which doesn't set a time frame to delete snapshots. When the default is used, snapshots aren't deleted until the maximum storage allocation for Recall is reached and the oldest snapshots are deleted first. You can configure the maximum storage duration to be 30, 60, 90, or 180 days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setmaximumstoragedurationforrecallsnapshots"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_0","displayName":"Let the OS define the maximum amount of time the snapshots will be saved","description":"Let the OS define the maximum amount of time the snapshots will be saved","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_30","displayName":"30 days","description":"30 days","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_60","displayName":"60 days","description":"60 days","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_90","displayName":"90 days","description":"90 days","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_180","displayName":"180 days","description":"180 days","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots","displayName":"[Deprecated] Set Maximum Storage Space For Recall Snapshots (User) (Windows Insiders only)","description":"This policy setting allows you to control the maximum amount of disk space that can be used by Windows to save snapshots for Recall. The default value of '0' will let the OS configure the amount of storage allocated to snapshots. When the default value of '0' is used, the OS configures the storage allocation for snapshots based on the device storage capacity. 25 GB is allocated when the device storage capacity is 256 GB. 75 GB is allocated when the device storage capacity is 512 GB. 150 GB is allocated when the device storage capacity is 1 TB or higher.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setmaximumstoragespaceforrecallsnapshots"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_0","displayName":"Let the OS define the maximum storage amount based on hard drive storage size","description":"Let the OS define the maximum storage amount based on hard drive storage size","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_10000","displayName":"10GB","description":"10GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_25000","displayName":"25GB","description":"25GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_50000","displayName":"50GB","description":"50GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_75000","displayName":"75GB","description":"75GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_100000","displayName":"100GB","description":"100GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_150000","displayName":"150GB","description":"150GB","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_v2","displayName":"Set Maximum Storage Space For Recall Snapshots (User)","description":"This policy setting allows you to control the maximum amount of disk space that can be used by Windows to save snapshots for Recall. The default value of '0' will let the OS configure the amount of storage allocated to snapshots. When the default value of '0' is used, the OS configures the storage allocation for snapshots based on the device storage capacity. 25 GB is allocated when the device storage capacity is 256 GB. 75 GB is allocated when the device storage capacity is 512 GB. 150 GB is allocated when the device storage capacity is 1 TB or higher.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setmaximumstoragespaceforrecallsnapshots"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_0","displayName":"Let the OS define the maximum storage amount based on hard drive storage size","description":"Let the OS define the maximum storage amount based on hard drive storage size","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_10240","displayName":"10GB","description":"10GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_25600","displayName":"25GB","description":"25GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_51200","displayName":"50GB","description":"50GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_76800","displayName":"75GB","description":"75GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_102400","displayName":"100GB","description":"100GB","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragespaceforrecallsnapshots_153600","displayName":"150GB","description":"150GB","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowsai_turnoffwindowscopilot","displayName":"Turn Off Copilot in Windows (User)","description":"This policy setting allows you to turn off Windows Copilot. If you enable this policy setting, users will not be able to use Copilot. The Copilot icon will not appear on the taskbar either. If you disable or do not configure this policy setting, users will be able to use Copilot when it's available to them.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#turnoffwindowscopilot"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_turnoffwindowscopilot_0","displayName":"Enable Copilot","description":"Enable Copilot","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_turnoffwindowscopilot_1","displayName":"Disable Copilot","description":"Disable Copilot","helpText":null}]},{"id":"user_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging","displayName":"Turn on PowerShell Script Block Logging (User)","description":"\n This policy setting enables logging of all PowerShell script input to the Microsoft-Windows-PowerShell/Operational event log. If you enable this policy setting,\n Windows PowerShell will log the processing of commands, script blocks, functions, and scripts - whether invoked interactively, or through automation.\n \n If you disable this policy setting, logging of PowerShell script input is disabled.\n \n If you enable the Script Block Invocation Logging, PowerShell additionally logs events when invocation of a command, script block, function, or script\n starts or stops. Enabling Invocation Logging generates a high volume of event logs.\n \n Note: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-windowspowershell#windowspowershell-turnonpowershellscriptblocklogging"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"user_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_enablescriptblockinvocationlogging","displayName":"Log script block invocation start / stop events: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"user_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_enablescriptblockinvocationlogging_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_enablescriptblockinvocationlogging_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablewpm","displayName":"Disable lock‑free coauthoring (User)","description":"This policy controls whether Word can use lock‑free coauthoring in collaboration sessions.\n\nLock‑free coauthoring allows multiple collaborators to edit the same paragraph at the same time when supported for a collaboration session.\n\nIf you enable this policy, Word will not use lock‑free coauthoring and will instead use the existing coauthoring behavior to support collaboration across the session.\n\nIf you disable or do not configure this policy, Word will automatically use lock‑free coauthoring when it is supported for a collaboration session.","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablewpm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablewpm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_skipopenduetolonglocalpath","displayName":"Skip Opening Local Files with Long Paths (User)","description":"This policy controls whether Word should skip opening local files with very long paths.\n\nIf you enable this policy, Word will not open local files that have very long paths. Only enable if local files with long paths are causing issues in your environment.\n\nIf you disable or do not configure this policy, Word will open local files with long paths.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_skipopenduetolonglocalpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_skipopenduetolonglocalpath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v10~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_disablemoderncommentsoptoutoption","displayName":"Hide the modern comments opt-out (User)","description":"This policy setting allows you to hide the modern comments opt-out toggle in Word from your users.\r\n\r\nNote: This opt-out toggle is only temporary and will eventually be removed from Word.\r\n\r\nIf you enable this policy setting, the toggle to turn off modern comments will be hidden from your users.\r\n\r\nIf you disable or don't configure this policy setting, your users will be able to temporarily turn off the new modern comments experience from the Options menu in Word. \r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v10~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_disablemoderncommentsoptoutoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v10~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_disablemoderncommentsoptoutoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v11~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_alternateclplabelcontentmarkanchoringoption","displayName":"Use an alternate method of anchoring content marks from CLP labels (User)","description":"This policy setting switches Word to use a alternate method of anchoring content marks associated with CLP labels, which can improve layout for some content marks.\r\n\r\nIf you enable this policy setting, Word will use the alternate content mark anchoring method.\r\n\r\nIf you disable or don't configure this policy setting, Word will use the original content mark anchoring method.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v11~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_alternateclplabelcontentmarkanchoringoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v11~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_alternateclplabelcontentmarkanchoringoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v12~policy~l_microsoftofficeword_l_stopreadaloudeyesoffexperience","displayName":"Stop Read Aloud when app goes in background (User)","description":"This policy prevents Read Aloud from reading text when app goes in background.\r\n\r\nIf you enable this policy setting, Read Aloud will be disabled and will stop reading the text when app is sent to background.\r\n\r\nIf you disable or do not configure this policy setting, Read Aloud will continue reading the text when app moves to background and user will be able to control Read Aloud via notification.","helpText":"","infoUrls":[],"categoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","categoryName":"Microsoft Word 2016","options":[{"id":"user_vendor_msft_policy_config_word16v12~policy~l_microsoftofficeword_l_stopreadaloudeyesoffexperience_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v12~policy~l_microsoftofficeword_l_stopreadaloudeyesoffexperience_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword_l_showesignribbon","displayName":"Allow the use of SharePoint eSignature for Microsoft Word (User)","description":"This policy setting allows you to control whether users can request eSignatures directly from Word in tenants that have enabled Microsoft's native eSignature service.\r\n\r\nIf you enable this policy setting, users can request eSignatures from within Word. This policy setting applies only to subscription versions of Word.\r\n\r\nIf you disable this policy setting, users cannot request eSignatures from within Word.\r\n\r\nIf you don't configure this policy setting, users cannot request eSignatures from within Word.","helpText":"","infoUrls":[],"categoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","categoryName":"Microsoft Word 2016","options":[{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword_l_showesignribbon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword_l_showesignribbon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_startupboostoption","displayName":"Allow Startup Boost feature (User)","description":"This policy setting configures the \"Startup Boost\" checkbox found under File tab | Options | General. Startup Boost improves Word's boot time by prewarming the app on user login.\r\n\r\nIf you enable or do not configure this policy, users will be able to use the Startup Boost feature. The Startup Boost checkbox will be enabled and checked by default.\r\n\r\nIf you disable this policy setting, the Startup Boost feature will not be available. The Startup Boost checkbox will be disabled and unchecked.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_startupboostoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_startupboostoption_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v14~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_advancedtypographyoutlook","displayName":"Allow Advanced Typography features for Outlook (User)","description":"This policy setting sets the “Advanced Typography” options found under Outlook’s File tab | Outlook Options | Mail | Editor Options | Advanced | Advanced Typography.\r\n\r\nIf you enable or do not configure this policy setting, Advanced Typography features will be applied. This is the default behavior.\r\n\r\nIf you disable this policy setting, Advanced Typography features will not be applied.\r\n ","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v14~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_advancedtypographyoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v14~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_advancedtypographyoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablecoauthoringondocmfiles","displayName":"Prevent co-authoring on files with macros for Word (User)","description":"This policy controls whether users will be able to co-author Word documents with macros.\r\n\r\nEnabling this policy setting will turn off the ability to co-author Word documents with macros.\r\n\r\nIf you disable or don't configure this policy setting, the user will be able to co-author Word documents with macros.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablecoauthoringondocmfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablecoauthoringondocmfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablertc","displayName":"Disable Real Time Coauthoring for Word (User)","description":"This policy lets admins disable Real Time Coauthoring. They may want to do so if they have solutions that are not compatible with some elements of real time coauthoring, such as add-ins that would trigger too often due to Real Time Coauthoring causing the frequent saving of user content. \r\n\r\nIf you enable this policy setting, it will prevent Real Time Coauthoring. \r\n\r\nIf you disable or do not configure this policy setting, users will be able to experience Real Time Coauthoring feature.","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablertc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablertc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_donotautomaticallymergeserverandlocaldocument","displayName":"Do not automatically merge server and local document (User)","description":"This policy setting determines if changes made to a server document should be automatically merged with the locally-cached copy of the document on the next save. This policy pertains to the co-authoring experience in Word.\r\n\r\nIf you enable this policy setting, then changes made to a server document will not be automatically merged with the locally-cached copy of the document on the next save. \r\n\r\nIf you disable or do not configure this policy setting, then changes made to a server document will be automatically merged with the locally-cached copy of the document on the next save.","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_donotautomaticallymergeserverandlocaldocument_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_donotautomaticallymergeserverandlocaldocument_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_preventcoauthoring","displayName":"Prevent co-authoring (User)","description":"This policy setting controls how Word opens a file for editing on document management servers that support co-authoring.\r\n\r\nIf you enable this policy setting, Word will prevent co-authoring by taking an exclusive file lock. \r\n\r\nIf you disable or do not configure this policy setting, Word will allow co-authoring by taking short-term shared locks. \r\n\r\nNote: When file synchronization via SOAP over HTTP is turned off it will prevent co-authoring.","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_preventcoauthoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_preventcoauthoring_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize97","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize97_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize97_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","categoryName":"Customizable Error Messages","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable some specific commands in Microsoft Word. Commands are buttons, menus, or other items that can be added to the Quick Access Toolbar or to the Ribbon under File tab | Options | Quick Access Toolbar or via File | Options | Customize Ribbon, respectively.\r\n\r\nIf you enable this policy setting then you can specify what commands in the user interface for Word are disabled.\r\n\r\nIf you disable or do not configure this policy setting, the commands in the predefined list are all enabled in Word.","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient","displayName":"File tab | Share | Email (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview","displayName":"File tab | Options | (\"Customize Ribbon\" or \"Quick Access Toolbar\") | All Commands | Web Page Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlinkwd","displayName":"Insert tab | Links | Hyperlink (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlinkwd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_inserthyperlinkwd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacroswd","displayName":"Developer tab | Code | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacroswd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacromacroswd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrorecordnewmacro","displayName":"Developer tab | Code | Record Macro (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrorecordnewmacro_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrorecordnewmacro_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity","displayName":"Developer tab | Code | Macro Security (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorwd","displayName":"Developer tab | Code | Visual Basic (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorwd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorwd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrowd","displayName":"View tab | Macros | Macros (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrowd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrowd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsprotectdocument","displayName":"File tab | Info | Protect Document (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsprotectdocument_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsprotectdocument_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolstemplatesandaddins","displayName":"Developer tab | Templates | Document Template (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolstemplatesandaddins_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolstemplatesandaddins_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddresswd","displayName":"File tab | Options | (\"Customize Ribbon\" or \"Quick Access Toolbar\") | All Commands | Document Location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddresswd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddresswd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable specific shortcut key combinations in the specified applications. \r\n\r\nIf you enable this policy setting you can disable specific shortcut keys for the selected application. The predefined list of shortcut keys you can disable becomes available to you when you enable this policy setting. \r\n\r\nIf you disable or do not configure this policy setting, the predefined list of shortcut keys are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditorwd","displayName":"Alt+F11 (Developer | Code | Visual Basic) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditorwd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditorwd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros","displayName":"Alt+F8 (Developer | Code | Macros) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf8toolsmacromacros_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindwd","displayName":"Ctrl+F (Home | Editing | Find) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindwd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindwd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkwd","displayName":"Ctrl+K (Insert | Links | Hyperlink) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkwd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkwd_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation","displayName":"Check for accessibility issues while editing (User)","description":"This policy setting controls whether accessibility issues are checked for automatically while the user is editing a document. By default, accessibility issues aren’t checked for automatically.\r\n\r\nIf you enable this policy setting, accessibility issues are checked for automatically and users won’t be able to turn it off. The status bar will indicate if accessibility recommendations are available to make the document more usable by people with disabilities.\r\n\r\nIf you disable or don’t configure this policy setting, accessibility issues won’t be checked for automatically while editing a document. Users can turn on automatic checking by going to File > Options > Ease of Access.\r\n","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation","displayName":"Stop checking for alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that objects such as images and shapes contain alt text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that objects such as images and shapes contain alt text.\r\n\r\nIf you disable or do not configure this policy setting, objects will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingblankcharactersusedforformatting","displayName":"Stop checking whether blank characters are used for formatting (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that multiple consecutive whitespace characters have not been used for formatting.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that multiple consecutive whitespace characters have not been used for formatting.\r\n\r\nIf you disable or do not configure this policy setting, documents will be checked for consecutive whitespace usage and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingblankcharactersusedforformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingblankcharactersusedforformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingdocumentsallowprogrammaticaccess","displayName":"Stop checking to ensure documents allow programmatic access (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that documents have not blocked programmatic access through DRM.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that documents have not blocked programmatic access through DRM.\r\n\r\nIf you disable or do not configure this policy setting, documents will be checked for programmatic access and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingdocumentsallowprogrammaticaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingdocumentsallowprogrammaticaccess_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsandcolumns","displayName":"Stop checking for blank table rows and columns (User)","description":"This policy setting prevents the Accessibility Checker from verifying that blank rows and columns have not been inserted into tables.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that blank rows and columns have not been inserted into tables.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for blank rows and columns and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsandcolumns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforblanktablerowsandcolumns_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforimagewatermarks","displayName":"Stop checking for image watermarks (User)","description":"This policy setting prevents the Accessibility Checker from checking if a document has image watermarks.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking if a document has image watermarks.\r\n\r\nIf you disable or do not configure this policy setting, documents will be checked for watermarks and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforimagewatermarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforimagewatermarks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingformergedandsplitcells","displayName":"Stop checking for merged and split cells (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables do not have merged or split cells.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables do not have merged or split cells.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for merged and split cells and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingformergedandsplitcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingformergedandsplitcells_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingfortablesusedforlayout","displayName":"Stop checking for tables used for layout (User)","description":"This policy setting prevents the Accessibility Checker from flagging layout tables (i.e. tables with no style applied).\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging layout tables (i.e. tables with no style applied).\r\n\r\nIf you disable or do not configure this policy setting, tables with no style will be flagged and the violations will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingfortablesusedforlayout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingfortablesusedforlayout_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingheadingstylesdonotskipstylelevel","displayName":"Stop checking to ensure heading styles do not skip style level (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that headings in a document are used in order.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that headings in a document are used in order.\r\n\r\nIf you disable or do not configure this policy setting, the ordering of headings in a document will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingheadingstylesdonotskipstylelevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingheadingstylesdonotskipstylelevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckinglongdocumentsusestylesforstructure","displayName":"Stop checking to ensure long documents use styles for structure (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that long documents have used styles to define content structure.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that long documents have used styles to define content structure.\r\n\r\nIf you disable or do not configure this policy setting, documents will be checked for style usage and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckinglongdocumentsusestylesforstructure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckinglongdocumentsusestylesforstructure_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingstylesusedfrequently","displayName":"Stop checking to ensure styles have been used frequently (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that documents using styles have used them frequently enough to accurately represent the document's content structure.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that documents using styles have used them frequently enough to accurately represent the document's content structure.\r\n\r\nIf you disable or do not configure this policy setting, the frequency of style usage will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingstylesusedfrequently_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingstylesusedfrequently_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation","displayName":"Stop checking for table header accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables have a header row specified.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables have a header row specified.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for header rows and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtableheaderaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensureheadingsaresuccinct","displayName":"Stop checking to ensure headings are succinct (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that headings in a document are succinct.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that headings in a document are succinct.\r\n\r\nIf you disable or do not configure this policy setting, document headings will be checked for length and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensureheadingsaresuccinct_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensureheadingsaresuccinct_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful","displayName":"Stop checking to ensure hyperlink text is meaningful (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingwhetherobjectsarefloating","displayName":"Stop checking whether objects are floating (User)","description":"This policy setting prevents the Accessibility Checker from checking if a document has objects that are floating instead of inline.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking if a document has objects that are floating instead of inline.\r\n\r\nIf you disable or do not configure this policy setting, objects will be checked for floating text wrapping properties and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingwhetherobjectsarefloating_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingwhetherobjectsarefloating_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorepunctuationcharacters","displayName":"Ignore punctuation characters (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorepunctuationcharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorepunctuationcharacters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorewhitespacecharacters","displayName":"Ignore whitespace characters (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorewhitespacecharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorewhitespacecharacters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchbavahafa","displayName":"Match ba/va, ha/fa (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchbavahafa_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchbavahafa_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchcase","displayName":"Match case (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchcase_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchcase_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchchoonusedforvowels","displayName":"Match cho-on used for vowels (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchchoonusedforvowels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchchoonusedforvowels_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchcontractionsyoonsokuon","displayName":"Match contractions (yo-on, sokuon) (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchcontractionsyoonsokuon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchcontractionsyoonsokuon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchdiziduzu","displayName":"Match di/zi, du/zu (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchdiziduzu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchdiziduzu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchfullhalfwidthform","displayName":"Match full/half width form (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchfullhalfwidthform_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchfullhalfwidthform_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhiraganakatakana","displayName":"Match hiragana/katakana (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhiraganakatakana_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhiraganakatakana_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhyuiyubyuvyu","displayName":"Match hyu/iyu, byu/vyu (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhyuiyubyuvyu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhyuiyubyuvyu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchiaiyapianopiyano","displayName":"Match ia/iya (piano/piyano) (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchiaiyapianopiyano_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchiaiyapianopiyano_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchkikutekisutotekusuto","displayName":"Match ki/ku (tekisuto/tekusuto) (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchkikutekisutotekusuto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchkikutekisutotekusuto_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchminusdashchoon","displayName":"Match minus/dash/cho-on (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchminusdashchoon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchminusdashchoon_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matcholdkanaforms","displayName":"Match old kana forms (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matcholdkanaforms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matcholdkanaforms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchrepeatcharactermarks","displayName":"Match 'repeat character' marks (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchrepeatcharactermarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchrepeatcharactermarks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchseshezeje","displayName":"Match se/she, ze/je (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchseshezeje_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchseshezeje_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchtsithichidhizi","displayName":"Match tsi/thi/chi, dhi/zi (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchtsithichidhizi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchtsithichidhizi_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchvariantformkanjiitaiji","displayName":"Match variant-form kanji (itaiji) (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchvariantformkanjiitaiji_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchvariantformkanjiitaiji_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_alternaterevisionbarpositioninprinteddocument","displayName":"Alternate revision bar position in printed document (User)","description":"Checked: For a multi-column page, revision bars are printed to the side of the column in which the revision appears. | Unchecked: For a multi-column page, revision bars are printed to the side of the page in which the revision appears.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_alternaterevisionbarpositioninprinteddocument_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_alternaterevisionbarpositioninprinteddocument_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_defaultcustomtab","displayName":"Show custom templates tab by default in Word on the Office Start screen and in File | New (User)","description":"This policy setting controls whether custom templates (when they exist) show as the default tab in Word on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, users will the see custom templates tab as the default tab in Word on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Word on the Office Start screen and in File | New, unless all Office-provided templates have been disabled.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_defaultcustomtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_defaultcustomtab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_disablemrulistinfontdropdown","displayName":"Disable MRU list in font dropdown (User)","description":"This policy allows you to hide the list of recently used fonts found under Home tab | Font.\r\n\r\nIf you enable this policy setting, the list of recently used fonts will not be shown.\r\n\r\nIf you disable or do not configure this policy setting, the list of recently used fonts will be shown.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_disablemrulistinfontdropdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_disablemrulistinfontdropdown_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_disableofficestartword","displayName":"Disable the Office Start screen for Word (User)","description":"This policy setting controls whether the Office Start screen appears on boot for Word.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot Word.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot Word.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_disableofficestartword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_disableofficestartword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinemachinetranslation","displayName":"Do not use online machine translation (User)","description":"This policy setting allows you to prevent online machine translation services from being used for the translation of documents and text through the Research pane.\r\n\r\nIf you enable this policy setting, online machine translation services cannot be used to translate documents and text through the Research pane.\r\n\r\nIf you disable or do not configure this policy setting, online machine translation services can be used to translate text through the Research pane.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinemachinetranslation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinemachinetranslation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinetranslationdictionaries","displayName":"Use online translation dictionaries (User)","description":"This policy setting allows you to prevent online dictionaries from being used for the translation of text through the Research pane.\r\n\r\nIf you enable or do not configure this policy setting, the online dictionaries can be used to translate text through the Research pane.\r\n\r\nIf you disable this policy setting, the online dictionaries cannot be used to translate text through the Research pane.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinetranslationdictionaries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinetranslationdictionaries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins, or specify the file name of Word add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\Word\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\Word\\Addins.\r\n\r\nTo obtain the file name of an add-in, click the File menu in the application where the add-in is installed. Click Options, click Add-ins, and then use the Location column to determine the file name of the add-in.\r\n\r\nYou can also obtain the ProgID or the file name of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.\r\n\r\nTo specify that a Word add-in is always enabled, in addition to configuring this policy setting, you must also specify a location that is used as a trusted source for open files in Word. To do this, configure the \"Trusted Locations\" policy setting at User Configuration\\Administrative Templates\\Microsoft Word 2016\\Word Options\\Security\\Trust Center, and then move the add-in file into the trusted location.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_personaltemplatespath","displayName":"Personal templates path for Word (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_showpeople","displayName":"Show pictures in comments (User)","description":"This policy setting determines whether or not comments show pictures.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_showpeople_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_showpeople_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_toolscompareandmergedocumentslegalblackline","displayName":"Tools | Compare and Merge Documents, Legal blackline (User)","description":"If you enable this policy setting, a comparison between two documents automatically generates a new Legal Blackline document, leaving the original documents unchanged.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_toolscompareandmergedocumentslegalblackline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_toolscompareandmergedocumentslegalblackline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference","displayName":"Volume preference (User)","description":"This policy setting allows you to configure Microsoft Word to retain file path information when you work with files on a network server, either as a mapped drive (Z:\\Folder_Name\\File_Name) or as Universal Naming Convention (UNC) (\\\\Share_Name\\File_Name).\r\n\r\nIf you enable this policy setting, you may select one of these options:\r\n- Use Drive letter or UNC as entered\r\n- Convert Drive letter to UNC\r\n- Convert UNC to Drive letter\r\n\r\nIf you disable or do not configure this policy setting, the default option is \"Use Drive letter or UNC as entered.\"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference_l_volumepreference179","displayName":"Volume preference (User)","description":"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference_l_volumepreference179_0","displayName":"Use Drive letter or UNC as entered","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference_l_volumepreference179_2","displayName":"Convert Drive letter to UNC","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_volumepreference_l_volumepreference179_1","displayName":"Convert UNC to Drive letter","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp","displayName":"Turn off file synchronization via SOAP over HTTP (User)","description":"This policy setting controls file synchronization via SOAP over HTTP for Word.\r\n\r\nIf you enable this policy setting, file synchronization via SOAP over HTTP is turned off for Word.\r\n\r\nIf you disable or do not configure this policy setting this policy setting, file synchronization via SOAP over HTTP is turned on for Word.\r\n\r\nNote: Turning off file synchronization via SOAP over HTTP will also prevent co-authoring and adversely affect the behavior of SharePoint Workspaces.","helpText":"","infoUrls":[],"categoryId":"b206e4ef-a288-4fb7-a7ee-4a30b4df3b98","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178~l_serversettings_l_turnofffilesynchronizationviasoapoverhttp_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_convertcommonterms","displayName":"Convert common terms (User)","description":"Checks/unchecks the corresponding UI option in the \"Chinese Conversion\" dialog, which found under Review tab | Convert with Options button. This may only be visible when Chinese is enabled as an editing language.","helpText":"","infoUrls":[],"categoryId":"7bee4dea-82a4-4a03-b903-654b374819b1","categoryName":"Chinese Conversion | Convert with Options","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_convertcommonterms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_convertcommonterms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_translationdirection","displayName":"Translation direction (User)","description":"This policy setting allows you to set the default translation direction for Chinese text.\r\n\r\nIf you enable this policy setting, the selected option will check the corresponding checkbox in the \"Chinese Conversion\" dialog. This dialog is found in the Review tab | \"Convert with Options\" button. This may only be visible when Chinese is enabled as an editing language. \r\n\r\nIf you disable or do not configure this policy setting, either translation direction may be set.","helpText":"","infoUrls":[],"categoryId":"7bee4dea-82a4-4a03-b903-654b374819b1","categoryName":"Chinese Conversion | Convert with Options","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_translationdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_translationdirection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_translationdirection_l_translationdirection96","displayName":"Translation direction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7bee4dea-82a4-4a03-b903-654b374819b1","categoryName":"Chinese Conversion | Convert with Options","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_translationdirection_l_translationdirection96_2052","displayName":"Traditional Chinese to Simplified Chinese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_translationdirection_l_translationdirection96_1028","displayName":"Simplified Chinese to Traditional Chinese","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_usetaiwanhongkongsarandmacaosarcharactervariants","displayName":"Use Taiwan, Hong Kong SAR and Macao SAR character variants (User)","description":"This policy setting allows you to configure the \"Chinese Conversion\" dialog, which is accessed by the \"Convert with Options\" button in the Review tab. This may only be visible when Chinese is enabled as an editing language.\r\n\r\nIf you enable this policy setting, the option is selected.\r\n\r\nIf you disable or do not configure this policy setting, the option is not selected.","helpText":"","infoUrls":[],"categoryId":"7bee4dea-82a4-4a03-b903-654b374819b1","categoryName":"Chinese Conversion | Convert with Options","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_usetaiwanhongkongsarandmacaosarcharactervariants_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewchinesetranslation_l_usetaiwanhongkongsarandmacaosarcharactervariants_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewsetlanguage_l_detectlanguageautomatically","displayName":"Detect language automatically (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"d79c9f9a-f469-4f39-a66a-6f7d5ee77e81","categoryName":"Language | Set Proofing Language...","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewsetlanguage_l_detectlanguageautomatically_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_reviewtab~l_reviewsetlanguage_l_detectlanguageautomatically_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addbidirectionalmarkswhensavingtextfiles","displayName":"Add Bi-Directional Marks when saving Text files (User)","description":"Checked: Add Bi-Directional Marks when saving Text files. | Unchecked: Do not add Bi-Directional Marks when saving Text files.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addbidirectionalmarkswhensavingtextfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addbidirectionalmarkswhensavingtextfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addcontrolcharactersincutandcopy","displayName":"Add control characters in Cut and Copy (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addcontrolcharactersincutandcopy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addcontrolcharactersincutandcopy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_adddoublequoteforhebrewalphabetnumbering","displayName":"Add double quote for Hebrew alphabet numbering (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_adddoublequoteforhebrewalphabetnumbering_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_adddoublequoteforhebrewalphabetnumbering_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowa4letterpaperresizing","displayName":"Scale content for A4 or 8.5'' x 11'' paper sizes (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowa4letterpaperresizing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowa4letterpaperresizing_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowaccenteduppercaseinfrench","displayName":"Allow accented uppercase in French (User)","description":"Checks/unchecks the option ''Enforce accented uppercase in French''.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowaccenteduppercaseinfrench_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowaccenteduppercaseinfrench_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowbackgroundsaves","displayName":"Allow background saves (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowbackgroundsaves_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_allowbackgroundsaves_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_alwayscreatebackupcopy","displayName":"Always create backup copy (User)","description":"Checks/unchecks the corresponding UI option found under File tab | Options | Advanced | Save.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_alwayscreatebackupcopy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_alwayscreatebackupcopy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_asianfontsalsoapplytolatintext","displayName":"Asian fonts also apply to Latin text (User)","description":"Checks/unchecks the corresponding UI option. This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_asianfontsalsoapplytolatintext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_asianfontsalsoapplytolatintext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_autokeyboardswitching","displayName":"Auto-Keyboard switching (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_autokeyboardswitching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_autokeyboardswitching_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_automaticallycreatedrawingcanvaswheninsertingautoshapes","displayName":"Automatically create drawing canvas when inserting AutoShapes (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_automaticallycreatedrawingcanvaswheninsertingautoshapes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_automaticallycreatedrawingcanvaswheninsertingautoshapes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backgroundprinting","displayName":"Print in background (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backgroundprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backgroundprinting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backofthesheet","displayName":"Print on back of the sheet for duplex printing (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backofthesheet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backofthesheet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_bookmarks","displayName":"Show bookmarks (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_bookmarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_bookmarks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_chartreftrackingenabled","displayName":"Allow formatting and labels to track data points (User)","description":"This policy setting governs how custom formatting and data labels react to data changes in a chart.\r\n\r\nIf you enable or do not configure this policy setting, when the user creates a new presentation, custom formatting and data labels follow data points as they move or change in any chart in the workbook.\r\n\r\nIf you disable this policy setting, custom formatting and data labels do not follow data points, but instead follow data point indices.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_chartreftrackingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_chartreftrackingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_confirmconversionatopen","displayName":"Confirm file format conversion on open (User)","description":"This policy setting allows you to set the \"Confirm file format conversion on open\" option in Word Options | Advanced | General.\r\n\r\nIf you enable this policy setting, \"Confirm file format conversion on open\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Confirm file format conversion on open\" will not be set.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_confirmconversionatopen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_confirmconversionatopen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_controlcharacters","displayName":"Show control characters (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_controlcharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_controlcharacters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_copyremotelystoredfiles","displayName":"Copy remotely stored files onto your computer, and update the remote file when saving (User)","description":"This policy setting allows you to set the \"Copy remotely stored files onto your computer, and update the remote file when saving\" option in Word Options | Advanced | Save.\r\n\r\nIf you enable this policy setting, \"Copy remotely stored files onto your computer, and update the remote file when saving\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Copy remotely stored files onto your computer, and update the remote file when saving\" will not be set.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_copyremotelystoredfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_copyremotelystoredfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning","displayName":"Custom markup warning (User)","description":"This policy setting specifies how Word behaves when opening a document that contains custom XML markup.\r\n\r\nIf you enable this policy setting, you can set the behavior to one of the following: \r\n\r\n- 0: Do not prompt the user and silently remove the custom XML markup. \r\n\r\n- 1: Prompt the user regarding the loss of custom XML markup. This is the default option. \r\n\r\n- 2: Prompt the user regarding the loss of custom XML markup, and do not allow them to suppress this prompt. \r\n\r\n- 3: Prompt the user regarding the loss of custom XML markup, and open the file read-only. \r\n\r\n- 4: Prompt the user regarding the loss of custom XML markup, do not allow them to suppress this prompt, and open the file read-only. \r\n\r\n- 5: Do not prompt the user and silently remove the custom XML markup, but open the file read-only.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid","displayName":"Custom markup warning: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid_0","displayName":"Do not prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid_1","displayName":"Prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid_2","displayName":"Always prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid_3","displayName":"Prompt and open the file read-only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid_4","displayName":"Always prompt and open the file read-only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_custommarkupwarning_l_custommarkupwarningdropid_5","displayName":"Do not prompt and open the file read-only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_diacritics","displayName":"Diacritics (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_diacritics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_diacritics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_differentcolorfordiacritics","displayName":"Use this color for diacritics (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_differentcolorfordiacritics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_differentcolorfordiacritics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_documentview","displayName":"Document view (User)","description":"Used for complex scripts. Specifies if documents shall be displayed Right-to-left or Left-to-right.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_documentview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_documentview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_documentview_l_documentview7","displayName":"Document view (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_documentview_l_documentview7_1","displayName":"Right-to-left","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_documentview_l_documentview7_0","displayName":"Left-to-Right","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draftfont","displayName":"Use draft font in Draft and Outline views (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draftfont_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draftfont_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draftoutput","displayName":"Use draft quality (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draftoutput_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draftoutput_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draganddroptextediting","displayName":"Allow text to be dragged and dropped (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draganddroptextediting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draganddroptextediting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_drawings","displayName":"Show drawings and text boxes on screen (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_drawings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_drawings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_enableclickandtype","displayName":"Enable click and type (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_enableclickandtype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_enableclickandtype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents","displayName":"English Word 6.0/95 documents (User)","description":"Sets the option to convert the file correctly.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents_l_englishword6095documents11","displayName":"English Word 6.0/95 documents (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents_l_englishword6095documents11_0","displayName":"Contain Asian text","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents_l_englishword6095documents11_1","displayName":"Open normally","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_englishword6095documents_l_englishword6095documents11_2","displayName":"Automatically detect Asian text","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuimaximumzoomlevel","displayName":"Set the maximum zoom level for expand / collapse on-object UI (User)","description":"This policy setting allows you to specify the maximum zoom level percentage at which point the expand/collapse on-object UI stops rendering. Regardless of the value specified for this policy setting, the expand / collapse feature is still available from the context menu for headings.\r\n\r\nIf you enable this policy setting, you can specify a maximum zoom level percentage from 0-500. If you specify a value of 0, the on-object UI never renders.\r\n\r\nIf you disable or do not configure this policy setting, there will be no maximum.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuimaximumzoomlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuimaximumzoomlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuimaximumzoomlevel_l_setexpandcollapseuimaximumzoomlevelspinid","displayName":"Set the maximum zoom level for expand / collapse on-object UI (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuiminimumzoomlevel","displayName":"Set the minimum zoom level for expand / collapse on-object UI (User)","description":"This policy setting allows you to specify the minimum zoom level percentage at which point the expand/collapse on-object UI stops rendering. Regardless of the value specified for this policy setting, the expand / collapse feature is still available from the context menu for headings.\r\n\r\nIf you enable this policy setting, you can specify a minimum zoom level percentage from 0-500.\r\n\r\nIf you disable or do not configure this policy setting, the minimum zoom level is set to 50%.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuiminimumzoomlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuiminimumzoomlevel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_expandcollapseuiminimumzoomlevel_l_setexpandcollapseuiminimumzoomlevelspinid","displayName":"Set the minimum zoom level for expand / collapse on-object UI (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldcodes","displayName":"Show field codes instead of their values (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldcodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldcodes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading","displayName":"Field shading (User)","description":"Specifies when field shading is displayed.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading_l_fieldshading6","displayName":"Field shading (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading_l_fieldshading6_0","displayName":"Never","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading_l_fieldshading6_1","displayName":"Always","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_fieldshading_l_fieldshading6_2","displayName":"When selected","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_frontofsheet","displayName":"Print on front of the sheet for duplex printing (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_frontofsheet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_frontofsheet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_horizontalscrollbar","displayName":"Show horizontal scroll bar (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_horizontalscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_horizontalscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_imecontrolactive","displayName":"IME Control Active (User)","description":"Checks/unchecks the corresponding UI option. This option only appears if you configure Word to use an IME.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_imecontrolactive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_imecontrolactive_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_imetrueinline","displayName":"IME TrueInLine (User)","description":"Checks/unchecks the corresponding UI option. This option only appears if you configure Word to use an IME.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_imetrueinline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_imetrueinline_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_keeptrackofformatting","displayName":"Keep track of formatting (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_keeptrackofformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_keeptrackofformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_leftscrollbar","displayName":"Left scroll bar (User)","description":"Checks/unchecks the corresponding UI option. This option is only available if support for right-to-left languages is enabled through Microsoft Office Language Preferences. This setting also sets Right ruler (Print view only).","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_leftscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_leftscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies","displayName":"Mark formatting inconsistencies (User)","description":"Defines color to use for marking formatting inconsistencies.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_checktoenforcesettingonunchecktoenforcesettingoff18","displayName":"Check to enforce setting on; uncheck to enforce setting off (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_checktoenforcesettingonunchecktoenforcesettingoff18_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_checktoenforcesettingonunchecktoenforcesettingoff18_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies","displayName":"Color for marking formatting inconsistencies (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_0","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_255","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_128","displayName":"Dark Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_3368703","displayName":"Light Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_52479","displayName":"Sky Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_10079487","displayName":"Pale Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_6710937","displayName":"Blue Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_65280","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_32768","displayName":"Dark Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_13056","displayName":"Darker Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_13434828","displayName":"Light Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_3355392","displayName":"Olive Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_3381606","displayName":"Sea Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16711680","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_8388608","displayName":"Dark Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16776960","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_8421376","displayName":"Dark Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16777113","displayName":"Light Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16777215","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_10040064","displayName":"Brown","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16737792","displayName":"Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16750848","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_65535","displayName":"Cyan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_32896","displayName":"Dark Cyan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_13434879","displayName":"Light Cyan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16711935","displayName":"Magenta","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_8388736","displayName":"Dark Magenta","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_13158","displayName":"Dark Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_3355545","displayName":"Indigo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_10079232","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_3394764","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16763904","displayName":"Gold","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_10040166","displayName":"Plum","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16751052","displayName":"Rose","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_16764057","displayName":"Tan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_13408767","displayName":"Lavender","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_8421504","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_l_colorformarkingformattinginconsistencies_12632256","displayName":"Gray 25%","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits","displayName":"Show measurements in units of (User)","description":"Selects the default measurement unit for the horizontal ruler and for measurements in dialog boxes.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_l_selectunits","displayName":"Select units: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_l_selectunits_0","displayName":"Inches","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_l_selectunits_2","displayName":"Centimeters","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_l_selectunits_4","displayName":"Millimeters","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_l_selectunits_1","displayName":"Points","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_l_selectunits_3","displayName":"Picas","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames","displayName":"Month names (User)","description":"Used for complex scripts. Specifies if month names shall be of calendar type Gregorian Arabic, Gregorian transliterated English, or Gregorian transliterated French.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_l_monthnames17","displayName":"Month names (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_l_monthnames17_0","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_l_monthnames17_1","displayName":"English transliterated","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_l_monthnames17_2","displayName":"French transliterated","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_movement","displayName":"Cursor movement (User)","description":"Used for complex scripts. Specifies if logical or visual cursor control shall be used.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_movement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_movement_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_movement_l_movement4","displayName":"Cursor movement (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_movement_l_movement4_0","displayName":"Logical","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_movement_l_movement4_1","displayName":"Visual","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral","displayName":"Numeral (User)","description":"Used for complex scripts. Specifies if numerals shall be displayed as Arabic, Hindi, Context, or System numerals. ","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_l_numeral16","displayName":"Numeral (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_l_numeral16_0","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_l_numeral16_1","displayName":"Hindi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_l_numeral16_2","displayName":"Context","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_numeral_l_numeral16_3","displayName":"System","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_pictureplaceholders","displayName":"Show picture placeholders (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_pictureplaceholders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_pictureplaceholders_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_promptbeforesavingnormaltemplate","displayName":"Prompt before saving Normal template (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_promptbeforesavingnormaltemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_promptbeforesavingnormaltemplate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_prompttoupdatestyle","displayName":"Prompt to update style (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_prompttoupdatestyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_prompttoupdatestyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_providefeedbackwithanimation","displayName":"Provide feedback with animation (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_providefeedbackwithanimation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_providefeedbackwithanimation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_recentlyusedfilelist","displayName":"Number of documents in the Recent Documents list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Documents list that appears when users click Open on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Documents list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Documents list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_recentlyusedfilelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_recentlyusedfilelist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_recentlyusedfilelist_l_numberofentries","displayName":"Number of entries: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_reverseprintorder","displayName":"Print pages in reverse order (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_reverseprintorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_reverseprintorder_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_showpixelsforhtmlfeatures","displayName":"Show pixels for HTML features (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_showpixelsforhtmlfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_showpixelsforhtmlfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth","displayName":"Style area pane width in Draft and Outline views (User)","description":"This policy setting allows you to set the width of the style area that shows the names of applied styles to the side of document text.\r\n\r\nIf you enable this policy setting, you may specify the width of the style area.\r\n\r\nIf you disable or do not configure this policy setting, the default width is used.\r\n","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8","displayName":"Style area pane width in Draft and Outline views (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_0","displayName":"0''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_24","displayName":"0.25''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_48","displayName":"0.5''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_72","displayName":"0.75''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_96","displayName":"1''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_120","displayName":"1.25''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_144","displayName":"1.5''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_168","displayName":"1.75''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_192","displayName":"2''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_216","displayName":"2.25''","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_styleareawidth_l_styleareawidth8_240","displayName":"2.5''","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_textboundaries","displayName":"Show text boundaries (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_textboundaries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_textboundaries_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_typeandreplace","displayName":"Type and replace (User)","description":"This policy setting allows you to check or uncheck the \"Type and Replace\" checkbox found under File tab | Options | Advanced. This checkbox may only be shown when certain South East Asian languages, such as Thai or Vietnamese, are enabled.\r\n\r\nSouth Asian languages follow stringent grammatical rules that dictate which textual character elements are allowed next to one another in the composition of words. To compound the complexity of correctly entering South Asian characters, text includes both simple characters and characters that include one or more markings such as diacritics, tone marks, vowels, and accents— for example, in Thai, leading vowels are normally followed by a consonant that does or does not include vowel markings, but diacritics are located below it.\r\n\r\nTo assist you in correctly entering characters in your document that prescribe to the grammar rules for the enabled South Asian language, Word can automatically check the text for you. Word can also make logical substitutions for you by using Type and Replace, a complementary feature.\r\n\r\nSequence checking can be used by itself or in combination with Type and Replace. When sequence checking only is selected, Word will not allow an invalid character to be typed at the insertion point. If Type and Replace is also selected, Word will insert or replace an existing character to make a valid sequence.\r\n\r\nIf you enable or do not configure this policy setting, the \"Type and Replace\" checkbox is checked.\r\n\r\nIf you disable this policy setting, the \"Type and Replace\" checkbox is unchecked.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_typeandreplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_typeandreplace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_typingreplacesselection","displayName":"Typing replaces selected text (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_typingreplacesselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_typingreplacesselection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_updateautomaticlinksatopen","displayName":"Update automatic links at Open (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_updateautomaticlinksatopen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_updateautomaticlinksatopen_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usecharacterunits","displayName":"Show measurements in width of characters (User)","description":"Checks/unchecks the corresponding UI option. This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usecharacterunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usecharacterunits_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usectrlclicktofollowhyperlink","displayName":"Use CTRL + Click to follow hyperlink (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usectrlclicktofollowhyperlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usectrlclicktofollowhyperlink_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesequencechecking","displayName":"Use sequence checking (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesequencechecking_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesequencechecking_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesmartparagraphselection","displayName":"Use smart paragraph selection (User)","description":"This policy setting controls the \"Use smart paragraph selection\" option found under File tab | Options | Advanced | Editing options.\r\n\r\nIf you enable or do not configure this policy setting, Word will automatically select the paragraph mark at the end of a selected range of text.\r\n\r\nIf you disable this policy setting, Word will not automatically select the paragraph mark at the end of a selected range of text. However, a user can still select the paragraph mark manually.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesmartparagraphselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesmartparagraphselection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usetheinskeyforpaste","displayName":"Use the Insert key for paste (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usetheinskeyforpaste_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usetheinskeyforpaste_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalrulerprintviewonly","displayName":"Show vertical ruler in Print Layout view (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalrulerprintviewonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalrulerprintviewonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalscrollbar","displayName":"Show vertical scroll bar (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection","displayName":"Cursor visual selection (User)","description":"Specifies if Block or Continuous selection shall be used. Block selection parodies the selection behavior within the Windows explorer when files in a folder. You draw a rectangle with the curson, and everything inside the rectangle is selected.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_l_visualselection5","displayName":"Cursor visual selection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_l_visualselection5_0","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_l_visualselection5_1","displayName":"Continuous","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_whenselectingautomaticallyselectentireword","displayName":"When selecting, automatically select entire word (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_whenselectingautomaticallyselectentireword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_whenselectingautomaticallyselectentireword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_wraptowindow","displayName":"Show text wrapped within the document window (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_wraptowindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_wraptowindow_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_relyoncssforfontformatting","displayName":"Rely on CSS for font formatting (User)","description":"This policy setting allows you to configure the \"Use Cascading Style Sheets (CSS) for appearance of messages\" option found under Microsoft Outlook's File tab | Outlook Options | Mail | Message format.\r\n\r\nIf you enable this policy setting, the option is checked.\r\n\r\nIf you disable or do not configure this policy setting, the option is not checked.\r\n","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_relyoncssforfontformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_relyoncssforfontformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_autorecoverfiles","displayName":"AutoRecover files (User)","description":"Defines the default path for storing AutoRecover files.","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_autorecoverfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_autorecoverfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_autorecoverfiles_l_autorecoverfiles13","displayName":"AutoRecover files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_clipartpictures","displayName":"Clipart pictures (User)","description":"This policy setting allows you to define the default path to Clipart pictures that is set in Word Options | Advanced | General | \"File Locations...\"\r\n\r\nIf you enable this policy setting, you may specify the default path to Clipart pictures.\r\n\r\nIf you disable or do not configure this policy setting, no path is specified.","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_clipartpictures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_clipartpictures_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_clipartpictures_l_clipartpictures12","displayName":"Clipart pictures (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_defaultfilelocation","displayName":"Default File Location (User)","description":"Defines the default path to documents.","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_defaultfilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_defaultfilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_defaultfilelocation_l_documents","displayName":"Documents (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_startup","displayName":"Startup (User)","description":"Defines the default path to Word's Startup folder.","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_startup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_startup_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_startup_l_startup15","displayName":"Startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_tools","displayName":"Tools (User)","description":"Defines the default path to tools.","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_tools_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_tools_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_tools_l_tools14","displayName":"Tools (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustformattingwhenpastingfrommicrosoftexcel","displayName":"Adjust formatting when pasting from Microsoft Excel (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustformattingwhenpastingfrommicrosoftexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustformattingwhenpastingfrommicrosoftexcel_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustparagraphspacingonpaste","displayName":"Adjust paragraph spacing on paste (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustparagraphspacingonpaste_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustparagraphspacingonpaste_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustsentenceandwordspacingautomatically","displayName":"Adjust sentence and word spacing automatically (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustsentenceandwordspacingautomatically_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjustsentenceandwordspacingautomatically_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjusttableformattingandalignmentonpaste","displayName":"Adjust table formatting and alignment on paste (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjusttableformattingandalignmentonpaste_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjusttableformattingandalignmentonpaste_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_mergeformattingwhenpastingfrompowerpoint","displayName":"Merge formatting when pasting from PowerPoint (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_mergeformattingwhenpastingfrompowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_mergeformattingwhenpastingfrompowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_mergepastedlistswithsurroundinglists","displayName":"Merge pasted lists with surrounding lists (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_mergepastedlistswithsurroundinglists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_mergepastedlistswithsurroundinglists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_smartstylebehavior","displayName":"Smart style behavior (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_smartstylebehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_smartstylebehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_browser_l_disablefeaturesnotsupportedbyspecifiedbrowsers","displayName":"Disable features not supported by specified browsers (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"56e510be-ca39-46a2-9eb2-6f1af6d4b16a","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_browser_l_disablefeaturesnotsupportedbyspecifiedbrowsers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_browser_l_disablefeaturesnotsupportedbyspecifiedbrowsers_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_files_l_checkifwordisthedefaulteditorforallotherwebpages","displayName":"Check if Word is the default editor for all other Web pages (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"d804205d-6c12-4f40-86a0-aa5a5355370f","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_files_l_checkifwordisthedefaulteditorforallotherwebpages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_files_l_checkifwordisthedefaulteditorforallotherwebpages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_documentproperties","displayName":"Print document properties (User)","description":"This policy setting allows you to control the \"Print document properties\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will print an additional page with the printed document's properties, including the document's author, filename, creation date, etc., for every document that is printed.\r\n\r\nIf you disable or do not configure this policy setting, no additional page will be printed.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_documentproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_documentproperties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_drawingobjects","displayName":"Print drawings created in Word (User)","description":"This policy setting allows you to configure the \"Print drawings created in Word\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will print graphics and floating text boxes. \r\n\r\nIf you disable or do not configure this policy setting, Word will not print graphics or floating text boxes. Instead, Word will print a blank box in the place of each graphic and floating text box.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_drawingobjects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_drawingobjects_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_hiddentext","displayName":"Hidden text (User)","description":"This policy setting controls whether text that is formatted as hidden displays on Word users' monitor screens.\r\n\r\nIf you enable this policy setting, Word displays hidden text at all times. Hidden text on monitor screens displays as underlined with a dotted line.\r\n\r\nIf you disable or do not configure this policy setting, Word does not display text formatted as hidden unless \"Show/Hide ¶\" is selected or Word is configured to show hidden text in the \"Display\" section of the \"Word Options\" dialog.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_hiddentext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_hiddentext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_highlight","displayName":"Show highlighter marks (User)","description":"This policy setting controls highlighter marks.\r\n\r\nIf you enable this policy setting, highlighter marks, both on screen and when printing, will be shown.\r\n\r\nIf you disable or do not configure this policy setting, highlighter marks, both on screen and when printing, will be hidden.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_highlight_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_highlight_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_objectanchors","displayName":"Object anchors (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_objectanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_objectanchors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalbreaks","displayName":"Optional breaks (User)","description":"Determines whether the symbol used to represent optional breaks is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalbreaks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalbreaks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalhyphens","displayName":"Optional hyphens (User)","description":"Determines whether the symbol used to represent optional hyphens is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalhyphens_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalhyphens_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_paragraphmarks","displayName":"Paragraph marks (User)","description":"Determines whether the symbol used to represent the end of paragraphs is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_paragraphmarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_paragraphmarks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_screentips","displayName":"Show document tooltips on hover (User)","description":"Determines whether the symbol used to represent Screen Tips are shown in the document.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_screentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_screentips_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_spaces","displayName":"Spaces (User)","description":"Determines whether the symbol used to represent spaces is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_spaces_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_spaces_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_tabcharacters","displayName":"Tab characters (User)","description":"Determines whether the symbol used to represent tabs is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_tabcharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_tabcharacters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatefields","displayName":"Update fields before printing (User)","description":"This policy setting allows you to configure the \"Update fields before printing\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will update fields in the document before the document is printed.\r\n\r\nIf you disable or do not configure this policy setting, Word will not update fields in the document before the document is printed.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatefields_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatefields_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatelinks","displayName":"Update linked data before printing (User)","description":"This policy setting controls the \"Update linked data before printing\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will update linked data in the document before the document is printed. One example of linked data in Word is an embedded Excel chart that is linked to an Excel spreadsheet.\r\n\r\nIf you disable or do not configure this policy setting, Word will not update linked data in the document before the document is printed.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatelinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatelinks_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_whitespacebetweenpagesprintviewonly","displayName":"Show white space between pages in Print Layout view (User)","description":"Determines whether the symbol used to represent white space between pages in Print view only is shown in the document.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_whitespacebetweenpagesprintviewonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_whitespacebetweenpagesprintviewonly_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"f9e53433-d8d9-4eaf-bdf3-d32de60d686e","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_alertifnotdefault","displayName":"Prompt the user if Word is not the default application for its file extensions (User)","description":"\r\n This policy setting specifies whether to prompt users to change their file extensions association if any of the file type extensions that were associated with Word, are no longer associated with Word.\r\n\r\n If you enable this policy setting, users will never be prompted on program start whenever any of these file types are associated with other applications. If the policy is Enabled, the checkbox under “File->Options-> General -> Start up options-> Tell me …” is Disabled and Unchecked.\r\n\r\n If you disable or do not configure this policy setting users will be prompted on program start whenever any of these file types are associated with other applications. Users can change the behavior of the feature either by checking the checkbox presented in the prompt or by checking the checkbox under “File->Options-> General -> Start up options-> Tell me …”\r\n If the policy is Not Configured or disabled the checkbox is Enabled and Checked by default.","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_alertifnotdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_alertifnotdefault_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_allowselectionfloaties","displayName":"Show Mini Toolbar on selection (User)","description":"Disabling this policy setting will result in Mini Toolbar not being displayed on text selection. By default, Mini Toolbar on selection is enabled and its visibility can be changed via a setting in the Word Options dialog box.","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_allowselectionfloaties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_allowselectionfloaties_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_digitalprint","displayName":"Don't show the option to transform a document to a Sway web page (User)","description":"This policy setting controls whether the File menu option to transform a Word document to a Sway web page is shown to the user. By default, this option is shown to the user.\r\n\r\nIf you enable this policy setting, the File menu option to transform a Word document to a Sway web page is hidden from the user. \r\n\r\nIf you disable or don't configure this policy setting, the File menu option to transform a Word document to a Sway web page is shown to the user.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_digitalprint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_digitalprint_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_enablelivepreview","displayName":"Enable Live Preview (User)","description":"This policy setting configures the \"Enable Live Preview\" checkbox found under File tab | Options | General. Live Preview shows how a command would be applied without actually applying it to the document.\r\n\r\nIf you enable this policy setting, the option is checked, and Live Preview will be shown when using Galleries that support previews\r\n\r\nIf you disable or do not configure this policy setting, the option is unchecked, and Live Preview will be hidden when using Galleries that support previews.","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_enablelivepreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_enablelivepreview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_linkedinresumeassistant","displayName":"Allow LinkedIn Resume Assistant feature (User)","description":"This policy setting controls whether the LinkedIn Resume Assistant appears in Word.\r\n\r\nIf you enable or do not configure this policy, users will be able to use the LinkedIn Resume Assistant.\r\n\r\nIf you disable this policy setting, the LinkedIn Resume Assistant will not be available.\r\n\r\nImportant: This policy setting only applies to Office 365 clients that are installed by using Click-to-Run, including Office 365 ProPlus, Office 365 Business, Visio Pro for Office 365 and Project Pro for Office 365. It doesn't apply to Office products that use Windows Installer (MSI).\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_linkedinresumeassistant_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_linkedinresumeassistant_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_onlinevideos","displayName":"Allow Online Videos to play within Word (User)","description":"This policy setting controls whether online videos can be played within Word.\r\n\r\nIf you enable or do not configure this policy, users will be able to play online videos within Word.\r\n\r\nIf you disable this policy setting, you will not be able to play online videos within Word.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_onlinevideos_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_onlinevideos_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading","displayName":"Open e-mail attachments in Reading View (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_l_checktoallowstartinginreadinglayout","displayName":"Check to allow starting in Reading Layout (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_l_checktoallowstartinginreadinglayout_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_l_checktoallowstartinginreadinglayout_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype","displayName":"Mark grammar errors as you type (User)","description":"Defines color to use for marking grammatical errors.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_checktoenforcesettingonunchecktoenforcesettingoff0","displayName":"Check to enforce setting on; uncheck to enforce setting off (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_checktoenforcesettingonunchecktoenforcesettingoff0_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_checktoenforcesettingonunchecktoenforcesettingoff0_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors","displayName":"Color for marking grammatical errors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_0","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_255","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_128","displayName":"Dark Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_3368703","displayName":"Light Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_52479","displayName":"Sky Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_10079487","displayName":"Pale Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_6710937","displayName":"Blue Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_65280","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_32768","displayName":"Dark Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_13056","displayName":"Darker Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_13434828","displayName":"Light Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_3355392","displayName":"Olive Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_3381606","displayName":"Sea Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16711680","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_8388608","displayName":"Dark Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16776960","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_8421376","displayName":"Dark Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16777113","displayName":"Light Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16777215","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_10040064","displayName":"Brown","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16737792","displayName":"Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16750848","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_65535","displayName":"Cyan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_32896","displayName":"Dark Cyan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_13434879","displayName":"Light Cyan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16711935","displayName":"Magenta","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_8388736","displayName":"Dark Magenta","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_13158","displayName":"Dark Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_3355545","displayName":"Indigo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_10079232","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_3394764","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16763904","displayName":"Gold","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_10040166","displayName":"Plum","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16751052","displayName":"Rose","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_16764057","displayName":"Tan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_13408767","displayName":"Lavender","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_8421504","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_colorformarkinggrammaticalerrors_12632256","displayName":"Gray 25%","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarwithspelling","displayName":"Check grammar with spelling (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarwithspelling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarwithspelling_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingbackgroundspellingchecker","displayName":"Delay before starting background spelling checker (User)","description":"This policy setting allows you to configure when the background spell check is started.\r\n\r\nIf you enable this policy setting, you may specify the delay, in milliseconds, before the background spell check is started. This setting only applies when Word is running in a terminal server session.\r\n\r\nIf you disable or do not configure this policy setting, Word will behave normally when in a terminal server session.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingbackgroundspellingchecker_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingbackgroundspellingchecker_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingbackgroundspellingchecker_l_delaybeforestartingbackgroundspellingchecker3","displayName":"Milliseconds (e.g. 5000 milliseconds = 5 seconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingotherproofingtools","displayName":"Delay before starting other proofing tools (User)","description":"This policy setting allows you to configure when the background grammar check is started.\r\n\r\nIf you enable this policy setting, you may specify the delay, in milliseconds, before the background grammar check is started. This setting only applies when Word is running in a terminal server session.\r\n\r\nIf you disable or do not configure this policy setting, Word will behave normally when in a terminal server session.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingotherproofingtools_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingotherproofingtools_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingotherproofingtools_l_delaybeforestartingbackgroundgrammarchecker3","displayName":"Milliseconds (e.g. 5000 milliseconds = 5 seconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_donotenableadditionalactionsintherightclickmenu","displayName":"Do not enable additional actions in the right-click menu (User)","description":"This policy setting allows you to configure the \"Enable additional actions in the right-click menu\" button found under File tab | Options | Proofing | Autocorrect Options... | Actions.\r\n\r\nIf you enable this policy setting, the checkbox will not be checked, and Additional Actions recognition will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, the checkbox will be checked, and Additional Actions recognition will be turned on.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_donotenableadditionalactionsintherightclickmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_donotenableadditionalactionsintherightclickmenu_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_showreadabilitystatistics","displayName":"Show readability statistics (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_showreadabilitystatistics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_showreadabilitystatistics_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_writingstyle","displayName":"Writing style (User)","description":"Specifies the writing style Word uses when checking the active document.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_writingstyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_writingstyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_writingstyle_l_writingstyle1","displayName":"Writing style (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_writingstyle_l_writingstyle1_0","displayName":"Grammar & Style","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_writingstyle_l_writingstyle1_1","displayName":"Grammar Only","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_capitalizefirstletterofsentence","displayName":"Capitalize first letter of sentence (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_capitalizefirstletterofsentence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_capitalizefirstletterofsentence_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_capitalizenamesofdays","displayName":"Capitalize names of days (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_capitalizenamesofdays_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_capitalizenamesofdays_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctaccidentalusageofcapslockkey","displayName":"Correct accidental usage of cAPS LOCK key (User)","description":"This policy setting allows you to set the \"Correct accidental usage of cAPS LOCK key\" option in Word Options | Proofing | \"AutoCorrect Options...\" | AutoCorrect.\r\n\r\nIf you enable this policy setting, \"Correct accidental usage of cAPS LOCK key\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Correct accidental usage of cAPS LOCK key\" will not be set.y","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctaccidentalusageofcapslockkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctaccidentalusageofcapslockkey_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctkeyboardsetting","displayName":"Correct keyboard setting (User)","description":"This policy setting allows you to set the \"Correct keyboard setting\" option in Word Options | Proofing | \"AutoCorrect Options...\" | AutoCorrect.\r\n\r\nIf you enable this policy setting, \"Correct keyboard setting\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Correct keyboard setting\" will not be set.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctkeyboardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctkeyboardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correcttwoinitialcapitals","displayName":"Correct TWo INitial CApitals (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correcttwoinitialcapitals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correcttwoinitialcapitals_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_replacetextasyoutype","displayName":"Replace text as you type (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_replacetextasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_replacetextasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticbulletedlists","displayName":"Automatic bulleted lists (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticbulletedlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticbulletedlists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticnumberedlists","displayName":"Automatic numbered lists (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticnumberedlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticnumberedlists_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_borderlines","displayName":"Border lines (User)","description":"Checks/unchecks the option \"Border Lines.\"","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_borderlines_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_borderlines_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_closingstyletoletterclosings","displayName":"Closing style to letter closings (User)","description":"This policy setting allows you to set the \"Closing style to letter closings\" option found in Word Options | Proofing | AutoCorrect Options... | AutoFormat As You Type.\r\n\r\nIf you enable this policy setting, \"Closing style to letter closings\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Closing style to letter closings\" will not be set.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_closingstyletoletterclosings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_closingstyletoletterclosings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_datestyle","displayName":"Date style (User)","description":"Checks/unchecks the option \"Date style.\" This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_datestyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_datestyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_headings","displayName":"Headings (User)","description":"Checks/unchecks the option ''Built in Heading styles''.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_headings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_headings_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_tables","displayName":"Tables (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_tables_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_tables_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_autospace","displayName":"Auto space (User)","description":"This policy setting allows you to set the option \"Delete needless spaces between Asian and Western text\" in the group \"Automatically as you type.\" This option may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, \"Delete needless spaces between Asian and Western text\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Delete needless spaces between Asian and Western text\" will not be set.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_autospace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_autospace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_definestylesbasedonyourformatting","displayName":"Define styles based on your formatting (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_definestylesbasedonyourformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_definestylesbasedonyourformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_formatbeginningoflistitemliketheonebeforeit","displayName":"Format beginning of list item like the one before it (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_formatbeginningoflistitemliketheonebeforeit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_formatbeginningoflistitemliketheonebeforeit_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_insertclosingphrasetomatchjapanesesalutation","displayName":"Insert closing phrase to match Japanese salutation (User)","description":"Checks/unchecks the option \"Insert closing phrase to match Japanese salutation.\" This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_insertclosingphrasetomatchjapanesesalutation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_insertclosingphrasetomatchjapanesesalutation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_insertclosingphrasetomatchmemostyle","displayName":"Insert closing phrase to match memo style (User)","description":"Checks/unchecks the option \"Insert closing phrase to match memo style.\" This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_insertclosingphrasetomatchmemostyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_insertclosingphrasetomatchmemostyle_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_matchparentheses","displayName":"Match parentheses (User)","description":"This policy setting allows you to set the option \"Match opening and closing parentheses\" in Word Options | Proofing | AutoCorrect Options... | AutoFormat As You Type | Automatically as you type. This option may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, \"Match opening and closing parentheses\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Match opening and closing parentheses\" will not be set.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_matchparentheses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_matchparentheses_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_setleftindentontabsandbackspace","displayName":"Set left indent on tabs and backspace (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_setleftindentontabsandbackspace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_setleftindentontabsandbackspace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_boldand_italic_withrealformatting","displayName":"*Bold* and _italic_ with real formatting (User)","description":"This policy setting allows you to set the \"*Bold* and _italic_ with real formatting\" option.\r\n\r\nIf you enable this policy setting, you will set the the \"*Bold* and _italic_ with real formatting\" option in File | Options | Proofing | AutoCorrect Options... | AutoFormat.\r\n\r\nIf you disable or do not configure this policy setting, the option is not set.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_boldand_italic_withrealformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_boldand_italic_withrealformatting_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_dashlikecharacters","displayName":"Dash-like characters (User)","description":"Checks/unchecks the option \"Long vowel sounds with dash.\" This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_dashlikecharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_dashlikecharacters_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_firstlineindent","displayName":"First line indent (User)","description":"Checks/unchecks the option \"Spaces at beginning of paragraph with first-line indent\" in the group \"Replace as you type.\" This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_firstlineindent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_firstlineindent_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_fractions12withfractioncharacter","displayName":"Fractions (1/2) with fraction character (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_fractions12withfractioncharacter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_fractions12withfractioncharacter_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_ordinals1stwithsuperscript","displayName":"Ordinals (1st) with superscript (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_ordinals1stwithsuperscript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_ordinals1stwithsuperscript_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_straightquoteswithsmartquotes","displayName":"Straight quotes with smart quotes (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_straightquoteswithsmartquotes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_straightquoteswithsmartquotes_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_symbolcharacterswithsymbols","displayName":"Symbol characters (--) with symbols (User)","description":"Checks/unchecks the option ''Hyphens (--) with dash (-)''.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_symbolcharacterswithsymbols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_symbolcharacterswithsymbols_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_compatmodeonsaveas","displayName":"Save As Open XML in Compatibility Mode (User)","description":"This policy setting allows you to hide the \"Maintain compatibility with previous versions of Word\" checkbox. For any file format that is in Compatibility Mode, there will be a \"Maintain compatibility with previous versions of Word\" checkbox in the Save As dialog when saving to any of the Open XML file formats. This checkbox allows users to preserve the fidelity of documents that open in compatibility mode when saving those documents to any of the Open XML file formats. Checking this box will prevent conversion to the version of Word that is saving the file.\r\n\r\nConversion maximizes fidelity with the version of Word that is saving the file, and it is recommended for users who want their Word documents to be compatible with this version of Word. However, conversion may impact the fidelity and compatibility of some features when the file is opened by a previous version of Word.\r\n\r\nIf you enable this policy setting, the \"Maintain compatibility with previous versions of Word\" checkbox will be hidden. The Save As behavior for any of the Open XML file formats will always maintain compatibility with previous versions of Word. The file that is in compatibility mode will be prevented from being converted to the version of Word saving this file. \r\n\r\nIf you disable or do not configure this policy setting, the \"Maintain compatibility with previous versions of Word\" checkbox in the Save As dialog will be shown. Unless checked by the user, an Open XML file will be converted when the document is saved. Users will still, by default, be shown a final dialog when saving to confirm that the user wants to save the file without \"Maintain compatibility with previous versions of Word\" checked.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_compatmodeonsaveas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_compatmodeonsaveas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_donotdisplayfileformatcompatiblitydialogforodt","displayName":"Do not display file format compatibility dialog box for OpenDocument text format (User)","description":"This policy setting allows you to configure the file format compatibility dialog box when saving a file as an OpenDocument text file in Word.\r\n \r\nIf you enable this policy setting, the file format compatibility dialog is not displayed whenever you save as an OpenDocument text file in Word.\r\n \r\nIf you disable or do not configure this policy setting, the file format compatibility dialog is displayed when you save as an OpenDocument text file in Word.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_donotdisplayfileformatcompatiblitydialogforodt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_donotdisplayfileformatcompatiblitydialogforodt_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_keeplastautosavedversions","displayName":"Keep the last AutoSaved versions of files for the next session (User)","description":"This policy setting determines whether Word keeps the last AutoSaved version of a file if a user closes a file without saving it. (Note: AutoSave applies only when AutoRecover is enabled.)\r\n\r\nIf you enable or do not configure this policy setting, Word keeps the last AutoSaved version of the file and makes it available to the user the next time the file is opened if the user closes a file without saving it.\r\n\r\nIf you disable this policy setting, Word does not keep the last AutoSaved version of the file if the user closes a file without saving it.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_keeplastautosavedversions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_keeplastautosavedversions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo","displayName":"Save AutoRecover info (User)","description":"If you enable this policy setting, you can specify the number of minutes that Word will wait between saving AutoRecover information for the file. To prevent Word from ever saving AutoRecover information for the file, enable this policy and set the value to '0'.\r\n\r\nIf you disable or do not configure this policy setting, this policy will have no effect on the number of minutes that Word will wait between saving AutoRecover information for the file. By default, Word saves AutoRecover information for the file every 10 minutes.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo_l_saveautorecoverinfoeveryminutes","displayName":"Save AutoRecover info every (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas","displayName":"Default file format (User)","description":"This policy setting determines the default file format for saving files in Word.\r\n\r\nIf you enable this policy setting, you can set the default file format from among the following options: \r\n\r\n- Word Document (*.docx): This option is the default configuration in Word.\r\n- Single Files Web Page (*.mht)\r\n- Web Page (*.htm; *.html)\r\n- Web Page, Filtered (*.htm, *.html)\r\n- Rich Text Format (*.rtf)\r\n- Plain Text (*.txt)\r\n- Word 6.0/95 (*.doc)\r\n- Word 6.0/95 - Chinese (Simplified) (*.doc)\r\n- Word 6.0/95 - Chinese (Traditional) (*.doc)\r\n- Word 6.0/95 - Japanese (*.doc)\r\n- Word 6.0/95 - Korean (*.doc)\r\n- Word 97-2002 and 6.0/95 - RTF\r\n- Word 5.1 for Macintosh (*.mcw)\r\n- Word 5.0 for Macintosh (*.mcw)\r\n- Word 2.x for Windows (*.doc)\r\n- Works 4.0 for Windows (*.wps)\r\n- WordPerfect 5.x for Windows (*.doc)\r\n- WordPerfect 5.1 for DOS (*.doc)\r\n- Word Macro-Enabled Document (*.docm)\r\n- Word Template (*.dotx)\r\n- Word Macro-Enabled Template (*.dotm)\r\n- Word 97 - 2003 Document (*.doc)\r\n- Word 97 - 2003 Template (*.dot)\r\n- Word XML Document (*.xml)\r\n- Strict Open XML Document (*.docx)\r\n- OpenDocument Text (*.odt)\r\n\r\nUsers can choose to save presentations or documents in a different file format than the default.\r\n\r\nIf you disable or do not configure this policy setting, Word saves new files in the Office Open XML format: Word files have a .docx extension. For users who run recent versions of Word, Microsoft offers the Microsoft Office Compatibility Pack, which enables them to open and save Office Open XML files. If some users in your organization cannot install the Compatibility Pack, or are running versions of Word older than Microsoft Office 2000 with Service Pack 3, they might not be able to access Office Open XML files.\r\n\r\nThis policy setting is often set in combination with the \"Save As Open XML in Compatibility Mode\" policy setting.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3","displayName":"Save Word files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_","displayName":"Word Document (*.docx)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_webarchive","displayName":"Single Files Web Page (*.mht)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_html","displayName":"Web Page (*.htm; *.html)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_reducedhtml","displayName":"Web Page, Filtered (*.htm, *.html)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_rtf","displayName":"Rich Text Format (*.rtf)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_text","displayName":"Plain Text (*.txt)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msword6exp","displayName":"Word 6.0/95 (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msword6scexp","displayName":"Word 6.0/95 - Chinese (Simplified) (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msword6tcexp","displayName":"Word 6.0/95 - Chinese (Traditional) (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msword6jexp","displayName":"Word 6.0/95 - Japanese (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msword95kexp","displayName":"Word 6.0/95 - Korean (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msword6rtfexp","displayName":"Word 97-2002 & 6.0/95 - RTF","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_mswordmac51","displayName":"Word 5.1 for Macintosh (*.mcw)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_mswordmac5","displayName":"Word 5.0 for Macintosh (*.mcw)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_mswordwin2","displayName":"Word 2.x for Windows (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_msworkswin4","displayName":"Works 4.0 for Windows (*.wps)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_wrdprfctwin","displayName":"WordPerfect 5.x for Windows (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_wrdprfctdos51","displayName":"WordPerfect 5.1 for DOS (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_macroenableddocument","displayName":"Word Macro-Enabled Document (*.docm)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_template","displayName":"Word Template (*.dotx)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_macroenabledtemplate","displayName":"Word Macro-Enabled Template (*.dotm)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_doc","displayName":"Word 97 - 2003 Document (*.doc)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_dot","displayName":"Word 97 - 2003 Template (*.dot)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_flatxml","displayName":"Word XML Document (*.xml)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_docxstrict","displayName":"Strict Open XML Document (*.docx)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_l_savewordfilesas3_odt","displayName":"OpenDocument Text (*.odt)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation","displayName":"Set default compatibility mode on file creation (User)","description":"This policy setting allows you to specify the default compatibility mode when creating new files in Word. There are four modes:\r\n\r\n1. Word 2003: This mode disables features in Word that are not compatible with Word 2003.\r\n2. Word 2007: This mode disables features in Word that are not compatible with Word 2007.\r\n3. Word 2010: This mode disables features in Word that are not compatible with Word 2010.\r\n4. Full functionality mode: This mode ensures that all new features remain enabled. This is the default setting for Word. \r\n\r\nNote: Not all file formats support all four Compatibility Modes. Open XML file formats such as .docx and .dotx, support all four modes.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_l_setdefaultcompatibilitymodeonfilecreationdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_l_setdefaultcompatibilitymodeonfilecreationdropid_11","displayName":"Word 2003","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_l_setdefaultcompatibilitymodeonfilecreationdropid_12","displayName":"Word 2007","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_l_setdefaultcompatibilitymodeonfilecreationdropid_14","displayName":"Word 2010","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_setdefaultcompatibilitymodeonfilecreation_l_setdefaultcompatibilitymodeonfilecreationdropid_15","displayName":"Full functionality mode","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_disableirmonxpsexport","displayName":"Turn off IRM protection on XPS Export for Word (User)","description":"This policy controls the default IRM protection setting when exporting Word documents to XPS files.\r\n\r\nEnabling this policy setting will turn off IRM protection when exporting to XPS, if not explicitly set by users through the Export Options dialog.\r\n\r\nIf you disable or don't configure this policy setting, the default IRM protection setting for XPS export is based on previous IRM export selection. \r\n ","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_disableirmonxpsexport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_disableirmonxpsexport_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_disablewarningonincludefieldsupdate","displayName":"Don’t ask permission before updating IncludePicture and IncludeText fields in Word (User)","description":"This policy setting allows you to control whether Word prompts the user with a security message before updating IncludePicture and IncludeText fields in the document.\r\n\r\nBy default, the user is prompted with a security message before those fields are updated. But, the prompt might effect automated workflows that merge Word documents.\r\n\r\nImportant: Fields that contain IncludePicture and IncludeText references can be used for data exfiltration or phishing exploits. A field containing these references can be modified to point to external websites for content. If credentials are required for accessing the picture or text, the process of updating the field will request a sign-in from the user. While this is a legitimate scenario for trusted sources, it is vulnerable to phishing if the document is not from a trusted source.\r\n\r\nIf you enable this policy setting, the user won’t be prompted with a security message before those fields are updated. Enabling this policy setting is not recommended because of the possible security implications.\r\n\r\nIf you disable or don’t configure this policy setting, the user will be prompted with a security message before those fields are updated.\r\n ","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_disablewarningonincludefieldsupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_disablewarningonincludefieldsupdate_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_makehiddenmarkupvisible","displayName":"Make hidden markup visible (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_makehiddenmarkupvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_makehiddenmarkupvisible_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_storerandomnumbertoimprovemergeaccuracy","displayName":"Store random number to improve merge accuracy (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_storerandomnumbertoimprovemergeaccuracy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_storerandomnumbertoimprovemergeaccuracy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_turnofffilevalidation","displayName":"Turn off file validation (User)","description":"This policy setting allows you turn off the file validation feature.\r\n\r\nIf you enable this policy setting, file validation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, file validation will be turned on. Office Binary Documents (97-2003) are checked to see if they conform against the file format schema before they are opened.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_turnofffilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_turnofffilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_warnbeforeprintingsavingorsendingafilethatcontainstrackedcha","displayName":"Warn before printing, saving or sending a file that contains tracked changes or comments (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_warnbeforeprintingsavingorsendingafilethatcontainstrackedcha_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_warnbeforeprintingsavingorsendingafilethatcontainstrackedcha_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setparametersforcngcontext","displayName":"Set parameters for CNG context (User)","description":"This policy setting allows you to specify the encryption parameters that should be used for the CNG context. \r\n\r\nIf you enable this policy setting, the parameters specified will be passed to the CNG context.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG values will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setparametersforcngcontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setparametersforcngcontext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm","displayName":"Specify CNG random number generator algorithm (User)","description":"This policy setting allows you to configure the CNG random number generator to use.\r\n\r\nIf you enable this policy setting, the random number generator specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default random number generator will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_l_specifycngrandomnumbergeneratoralgorithmid","displayName":"Random number generator: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngsaltlength","displayName":"Specify CNG salt length (User)","description":"This policy setting allows you to specify the number of bytes of salt that should be used.\r\n\r\nIf you enable this policy setting, the bytes specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default length of 16 will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngsaltlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngsaltlength_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility","displayName":"Specify encryption compatibility (User)","description":"This policy setting allows you to specify the encrypted database compatibility.\r\n\r\nIf you enable this policy setting, the compatibility format specified will be applied during encryption for new files\r\n- Use legacy format\r\n- Use next generation format\r\n- All files save with next generation format\r\n\r\nIf you disable or do not configure this policy setting, the default setting, \"Use next generation format,\" will be applied.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_0","displayName":"Use legacy format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_1","displayName":"Use next generation format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_2","displayName":"All files save with next generation format","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_usenewkeyonpasswordchange","displayName":"Use new key on password change (User)","description":"This policy setting allows you to specify if a new encryption key is used when the password is changed.\r\n\r\nIf you enable or do not configure this policy setting, a new intermediate key is generated when the password is changed. This causes any extra key encryptors to be removed when the file is saved.\r\n\r\nIf you disable this policy setting, a new intermediate key is not generated when the password is changed.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_usenewkeyonpasswordchange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_usenewkeyonpasswordchange_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde","displayName":"Dynamic Data Exchange (User)","description":"This policy setting controls the ability to use Dynamic Data Exchange (DDE) in Word. By default, DDE isn’t allowed in Word. Allowing DDE isn’t recommended because of security concerns.\r\n \r\nIf you enable this policy setting, you can select either of the following options:\r\n \r\n-Limit Dynamic Data Exchange\r\n-Allow Dynamic Data Exchange\r\n \r\nIf you choose “Limit Dynamic Data Exchange,” DDE requests made to an already running program are allowed.  But, DDE requests that require another executable program to be launched aren’t allowed.\r\n \r\nIf you disable or don’t configure this policy setting, DDE isn’t allowed.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_l_allowddedropid","displayName":"Dynamic Data Exchange setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_l_allowddedropid_1","displayName":"Limited Dynamic Data Exchange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_l_allowddedropid_2","displayName":"Allow Dynamic Data Exchange","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowwordmailloadembeddedfonts","displayName":"Allow embedded TrueType fonts to be sent in messages (User)","description":"\r\n This policy setting controls whether embedded TrueType fonts can be sent in messages.\r\n\r\n By default, embedded TrueType fonts aren't allowed in messages. Allowing embedded TrueType fonts Isn't recommended because of security concerns.\r\n\r\n If you enable this policy setting, embedded TrueType fonts can be sent in messages.\r\n\r\n If you disable or don’t configure this policy setting, embedded TrueType fonts can't be sent in messages.\r\n ","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowwordmailloadembeddedfonts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowwordmailloadembeddedfonts_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword","displayName":"Scan encrypted macros in Word Open XML documents (User)","description":"This policy setting controls whether encrypted macros in Open XML documents be are required to be scanned with anti-virus software before being opened.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n- Scan encrypted macros: encrypted macros are disabled unless anti-virus software is installed. Encrypted macros are scanned by your anti-virus software when you attempt to open an encrypted workbook that contains macros.\r\n- Scan if anti-virus software available: if anti-virus software is installed, scan the encrypted macros first before allowing them to load. If anti-virus software is not available, allow encrypted macros to load.\r\n- Load macros without scanning: do not check for anti-virus software and allow macros to be loaded in an encrypted file.\r\n\r\nIf you disable or do not configure this policy setting, the behavior will be similar to the \"Scan encrypted macros\" option.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword_l_determinewhethertoforceencryptedworddropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword_l_determinewhethertoforceencryptedworddropid_0","displayName":"Scan encrypted macros (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword_l_determinewhethertoforceencryptedworddropid_1","displayName":"Scan if anti-virus software available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_determinewhethertoforceencryptedword_l_determinewhethertoforceencryptedworddropid_2","displayName":"Load macros without scanning","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users, except if application add-ins are required to be signed by Trusted Publishers.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User) (Deprecated)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2","displayName":"Disable Trust Bar Notification for unsigned application add-ins and block them (User)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_v2_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve","displayName":"Set maximum number of trust records to preserve (User)","description":"This policy setting allows you to specify the maximum number of trust records to preserve when the purge task detects that this application has trusted more than the number of trusted documents set by the \"Set maximum number of trusted documents\" policy setting.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of trust records to preserve, with an upper limit of 20000. Due to performance reasons, it is not recommended to set it to the upper limit.\r\n\r\nIf you disable or you do not configure this policy setting, the default value for of 400 is used.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_l_setmaximumnumberoftrustrecordstopreservespinid","displayName":"Maximum to preserve: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject","displayName":"Trust access to Visual Basic Project (User)","description":"This policy setting controls whether automation clients such as Microsoft Visual Studio 2005 Tools for Microsoft Office (VSTO) can access the Visual Basic for Applications project system in the specified applications. VSTO projects require access to the Visual Basic for Applications project system in Excel, PowerPoint, and Word, even though the projects do not use Visual Basic for Applications. Design-time support of controls in both Visual Basic and C# projects depends on the Visual Basic for Applications project system in Word and Excel.\r\n\r\nIf you enable this policy setting, VSTO and other automation clients can access the Visual Basic for Applications project system in the specified applications. Users will not be able to change this behavior through the \"Trust access to the VBA project object model\" user interface option under the Macro Settings section of the Trust Center.\r\n\r\nIf you disable this policy setting, VSTO does not have programmatic access to VBA projects. In addition, the \"Trust access to the VBA project object model\" check box is cleared and users cannot change it. Note: Disabling this policy setting prevents VSTO projects from interacting properly with the VBA project system in the selected application.\r\n\r\nIf you do not configure this policy setting, automation clients do not have programmatic access to VBA projects. Users can enable this by selecting the \"Trust access to the VBA project object model\" in the \"Macro Settings\" section of the Trust Center. However, doing so allows macros in any documents the user opens to access the core Visual Basic objects, methods, and properties, which represents a potential security hazard.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_trustaccesstovisualbasicproject_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocuments","displayName":"Turn off trusted documents (User)","description":"This policy setting allows you to turn off the trusted documents feature. The trusted documents feature allows users to always enable active content in documents such as macros, ActiveX controls, data connections, etc. so that they are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.\r\n\r\nIf you enable this policy setting, you will turn off the trusted documents feature. Users will receive a security prompt every time a document containing active content is opened.\r\n\r\nIf you disable or do not configure this policy setting, documents will be trusted when users enable content for a document, and users will not receive a security prompt.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork","displayName":"Turn off Trusted Documents on the network (User)","description":"This policy setting allows you to turn off the trusted documents feature for documents opened from the network.\r\n\r\nIf you enable this policy setting, users will always see security notifications for active content such as macros, ActiveX controls, data connections, etc. for documents opened from the network.\r\n\r\nIf you disable or do not configure this policy setting, the trusted documents feature allows users to always allow active content in documents such as macros, ActiveX controls, data connections, etc. so that users are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty19","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty19_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty19_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty19_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_vbawarningspolicy_l_empty19_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword","displayName":"Legacy converters for Word (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_l_legacyconvertersforworddropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword","displayName":"Office Open XML converters for Word (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_officeopenxmlconvertersforword_l_officeopenxmlconvertersforworddropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles","displayName":"OpenDocument Text files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles","displayName":"Plain text files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles","displayName":"RTF files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior","displayName":"Set default file block behavior (User)","description":"This policy setting allows you to determine if users can open, view, or edit Word files.\r\n\r\nIf you enable this policy setting, you can set one of these options:\r\n- Blocked files are not opened\r\n- Blocked files open in Protected View and can not be edited\r\n- Blocked files open in Protected View and can be edited\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the same as the \"Blocked files are not opened\" setting. Users will not be able to open blocked files.","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_0","displayName":"Blocked files are not opened","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_1","displayName":"Blocked files open in Protected View and can not be edited","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_l_setdefaultfileblockbehaviordropid_2","displayName":"Blocked files open in Protected View and can be edited","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages","displayName":"Web pages (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates","displayName":"Word 2000 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_l_word2000binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_l_word2000binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_l_word2000binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_l_word2000binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_l_word2000binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2000binarydocumentsandtemplates_l_word2000binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments","displayName":"Word 2003 and plain XML documents (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_l_word2003andplainxmldocumentsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates","displayName":"Word 2003 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates","displayName":"Word 2007 and later binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterbinarydocumentsandtemplates_l_word2007andlaterbinarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates","displayName":"Word 2007 and later documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2007andlaterdocsandtemplates_l_word2007andlaterdocsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates","displayName":"Word 2 and earlier binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates","displayName":"Word 6.0 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates","displayName":"Word 95 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_l_word95binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_l_word95binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_l_word95binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_l_word95binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_l_word95binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word95binarydocumentsandtemplates_l_word95binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates","displayName":"Word 97 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_l_word97binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_l_word97binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_l_word97binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_l_word97binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_l_word97binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_l_word97binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates","displayName":"Word XP binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_l_wordxpbinarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_l_wordxpbinarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_l_wordxpbinarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_l_wordxpbinarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_l_wordxpbinarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_wordxpbinarydocumentsandtemplates_l_wordxpbinarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview","displayName":"Do not open files from the Internet zone in Protected View (User)","description":"This policy setting allows you to determine if files downloaded from the Internet zone open in Protected View.\r\n\r\nIf you enable this policy setting, files downloaded from the Internet zone do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files downloaded from the Internet zone open in Protected View.","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview","displayName":"Do not open files in unsafe locations in Protected View (User)","description":"This policy setting lets you determine if files located in unsafe locations will open in Protected View. If you have not specified unsafe locations, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders are considered unsafe locations.\r\n\r\nIf you enable this policy setting, files located in unsafe locations do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files located in unsafe locations open in Protected View.","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesinunsafelocationsinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview","displayName":"Open files on local Intranet UNC in Protected View (User)","description":"This policy setting lets you determine if files on local Intranet UNC file shares open in Protected View.\r\n\r\nIf you enable this policy setting, files on local Intranet UNC file shares open in Protected View if their UNC paths appear to be within the Internet zone.\r\n\r\nIf you disable or do not configure this policy setting, files on Intranet UNC file shares do not open in Protected View if their UNC paths appear to be within the Internet zone.","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails","displayName":"Set document behavior if file validation fails (User)","description":"This policy setting controls how Office handles documents when they fail file validation. \r\n\r\nIf you enable this policy setting, you can configure the following options for files that fail file validation:\r\n\r\n- Block files completely. Users cannot open the files.\r\n- Open files in Protected View and disallow edit. Users cannot edit the files. This is also how Office handles the files if you disable this policy setting.\r\n- Open files in Protected View and allow edit. Users can edit the files. This is also how Office handles the files if you do not configure this policy setting.\r\n\r\nIf you disable this policy setting, Office follows the \"Open files in Protected View and disallow edit\" behavior.\r\n\r\nIf you do not configure this policy setting, Office follows the \"Open files in Protected View and allow edit\" behavior.","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_0","displayName":"Block files","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_1","displayName":"Open in Protected View","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3","displayName":"Checked: Allow edit. Unchecked: Do not allow edit. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook","displayName":"Turn off Protected View for attachments opened from Outlook (User)","description":"This policy setting allows you to determine if Word files in Outlook attachments open in Protected View.\r\n\r\nIf you enable this policy setting, Outlook attachments do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, Outlook attachments open in Protected View.","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_turnoffprotectedviewforattachmentsopenedfromoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork","displayName":"Allow Trusted Locations on the network (User)","description":"This policy setting controls whether trusted locations on the network can be used.\r\n\r\nIf you enable this policy setting, users can specify trusted locations on network shares or in other remote locations that are not under their direct control by clicking the \"Add new location\" button in the Trusted Locations section of the Trust Center. Content, code, and add-ins are allowed to load from trusted locations with minimal security and without prompting the user for permission.\r\n\r\nIf you disable this policy setting, the selected application ignores any network locations listed in the Trusted Locations section of the Trust Center. \r\n\r\nIf you also deploy Trusted Locations via Group Policy, you should verify whether any of them are remote locations. If any of them are remote locations and you do not allow remote locations via this policy setting, those policy keys that point to remote locations will be ignored on client computers.\r\n\r\nDisabling this policy setting does not delete any network locations from the Trusted Locations list, but causes disruption for users who add network locations to the Trusted Locations list. Users are also prevented from adding new network locations to the Trusted Locations list in the Trust Center. We recommended that you do not enable this policy setting (as the \"Allow Trusted Locations on my network (not recommended)\" check box also states). Therefore, in practice, it should be possible to disable this policy setting in most situations without causing significant usability issues for most users.\r\n\r\nIf you do not enable this policy setting, users can select the \"Allow Trusted Locations on my network (not recommended)\" check box if desired and then specify trusted locations by clicking the \"Add new location\" button.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_allowtrustedlocationsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders23","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders23_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders23_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_datecolon21","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_descriptioncolon22","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_pathcolon20","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_datecolon25","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_descriptioncolon26","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_pathcolon24","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders31","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders31_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders31_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_datecolon29","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_descriptioncolon30","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_pathcolon28","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders35","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders35_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders35_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_datecolon33","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders39","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders39_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders39_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_descriptioncolon38","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_pathcolon36","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders43","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders43_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders43_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_descriptioncolon42","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_pathcolon40","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders47","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_allowsubfolders47_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_datecolon45","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_descriptioncolon46","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_pathcolon44","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders51","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders51_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_datecolon49","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_descriptioncolon50","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_pathcolon48","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders55","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders55_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders55_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_descriptioncolon54","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11","displayName":"Trusted Location #11 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders59","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders59_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_datecolon57","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_descriptioncolon58","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_pathcolon56","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders63","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders63_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders63_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_datecolon61","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_pathcolon60","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders67","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders67_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders67_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_pathcolon64","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders71","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders71_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders71_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_datecolon69","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_descriptioncolon70","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_pathcolon68","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders75","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders75_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders75_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_datecolon73","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_descriptioncolon74","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_pathcolon72","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders79","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders79_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders79_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_datecolon77","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_descriptioncolon78","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_pathcolon76","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders83","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders83_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders83_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_datecolon81","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_descriptioncolon82","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_pathcolon80","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders87","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders87_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders87_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_datecolon85","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_descriptioncolon86","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_pathcolon84","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders91","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders91_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders91_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_datecolon89","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_descriptioncolon90","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_pathcolon88","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders95","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders95_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders95_1","displayName":"True","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_datecolon93","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_descriptioncolon94","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_pathcolon92","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons","displayName":"Balloons (User)","description":"Turning balloons off will show revisions inline. This corresponds to the choices in the Review ribbon.","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty_0","displayName":"Balloons on","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty_2","displayName":"Comments and formatting only in balloons","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty_1","displayName":"Balloons off (revisions inline)","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument","displayName":"Compare resulting document (User)","description":"This option determines whether the results of a document compare or combine will appear in a new document or one of the source documents. This corresponds to the option in the Compare dialog box ( Review ribbon | Compare | more options).","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart","displayName":"Document used for result of compare: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart_0","displayName":"Original Document","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart_1","displayName":"Revised Document","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart_2","displayName":"New document","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor","displayName":"Deletions color (User)","description":"Selects the color for tracked deletions. This corresponds to the choices in the Review ribbon | Track changes | Change tracking options dialog box.","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart","displayName":"Color for tracking deletions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_2","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_3","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_4","displayName":"Turquoise","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_5","displayName":"Bright Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_6","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_7","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_8","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_9","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_10","displayName":"Dark Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_11","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_12","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_13","displayName":"Violet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_14","displayName":"Dark Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_15","displayName":"Dark Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_16","displayName":"Gray 50%","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_17","displayName":"Gray 25%","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_ignorewhitespace","displayName":"Ignore White Space (User)","description":"This option determines if white space is compared in document compare. This corresponds to the option in the Compare dialog box ( Review ribbon | Compare | more options).","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_ignorewhitespace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_ignorewhitespace_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor","displayName":"Insertions color (User)","description":"Selects the default color for tracked insertions. This corresponds to the choices in the Review ribbon | Track changes | Change tracking options dialog box.","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart","displayName":"Color for tracking insertions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_2","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_3","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_4","displayName":"Turquoise","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_5","displayName":"Bright Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_6","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_7","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_8","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_9","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_10","displayName":"Dark Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_11","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_12","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_13","displayName":"Violet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_14","displayName":"Dark Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_15","displayName":"Dark Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_16","displayName":"Gray 50%","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_17","displayName":"Gray 25%","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors","displayName":"Table compare colors (User)","description":"This option determines the colors used for displaying the results of compared tables. Selecting ''none'' will track the changes, but they will not be colored in the resulting document (they will be listed in the reviewing pane).","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1","displayName":"Color for inserted cells: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_2","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_3","displayName":"Light blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_4","displayName":"Light yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_5","displayName":"Light purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_6","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_7","displayName":"Light green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_8","displayName":"Gray","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2","displayName":"Color for deleted cells: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_2","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_3","displayName":"Light blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_4","displayName":"Light yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_5","displayName":"Light purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_6","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_7","displayName":"Light green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart2_8","displayName":"Gray","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3","displayName":"Color for merged cells: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_2","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_3","displayName":"Light blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_4","displayName":"Light yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_5","displayName":"Light purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_6","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_7","displayName":"Light green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart3_8","displayName":"Gray","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4","displayName":"Color for split cells: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_2","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_3","displayName":"Light blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_4","displayName":"Light yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_5","displayName":"Light purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_6","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_7","displayName":"Light green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart4_8","displayName":"Gray","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v3~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_acronyms","displayName":"Remove the Acronyms command from the ribbon (User)","description":"This policy setting allows you to remove the Acronyms command from the ribbon. The Acronyms command appears on the References tab.\r\n\r\nIf you enable this policy setting, the Acronyms command is removed from the ribbon. Users won't be able to add the Acronyms command to the ribbon manually. Therefore users won't be able to use the Acronyms feature.\r\n\r\nIf you disable or don't configure this policy setting, the Acronyms command appears on the ribbon.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v3~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_acronyms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v3~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_acronyms_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook","displayName":"Specify default quality of compression done on inlined images inserted in Outlook (User)","description":"This policy setting allows you to specify default quality of compression done on inlined images in Outlook.\r\n\r\nIf you enable this policy setting, Outlook would compress the inlined images in the message as per the specified quality.\r\n\r\nIf you disable or don't configure this policy setting, inlined images would be compressed at the default quality (220 dpi).\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_l_defaultcompressionqualityforinlinedimagesinoutlookpart","displayName":"Default inline image compression quality for Outlook: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_l_defaultcompressionqualityforinlinedimagesinoutlookpart_0","displayName":"High Fidelity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_l_defaultcompressionqualityforinlinedimagesinoutlookpart_1","displayName":"330 ppi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_l_defaultcompressionqualityforinlinedimagesinoutlookpart_2","displayName":"220 ppi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_l_defaultcompressionqualityforinlinedimagesinoutlookpart_3","displayName":"150 ppi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_defaultcompressionqualityforinlinedimagesinoutlook_l_defaultcompressionqualityforinlinedimagesinoutlookpart_4","displayName":"96 ppi","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_donotcompressinlinedimagesinoutlook","displayName":"Do not compress the inlined images inserted in Outlook (User)","description":"This policy setting allows you to disable compression on inlined images in Outlook.\r\n\r\nIf you enable this policy setting, Outlook won't compress inlined images in the message.\r\n\r\nIf you disable or don't configure this policy setting, inlined images would be compressed.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_donotcompressinlinedimagesinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v4~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_donotcompressinlinedimagesinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation","displayName":"Stop checking for table alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables contain alt text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables contain alt text.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningfultext","displayName":"Stop checking to ensure hyperlink text is meaningful (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningfultext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningfultext_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningfultextextension","displayName":"Stop checking to ensure hyperlink text extension is meaningful if they include extensions (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text if they include extensions.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text if they include extensions.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text that include extensions will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningfultextextension_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningfultextextension_1","displayName":"Enabled","description":null,"helpText":null}]},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}","displayName":"Printer Shared ID (User)","description":"Identifies the Universal Print printer, by its Share ID, you wish to install on the targeted user account. The printer's Share ID can be found in the printer's properties via the Universal Print portal. Note: the targeted user account must have access rights to both the printer and to the Universal Print service.","helpText":"","infoUrls":[],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_clouddeviceid","displayName":"Cloud Device ID (User)","description":"Identifies the Universal Print printer, by its Printer ID, you wish to install on the targeted user account. The printer's Printer ID can be found in the printer's properties via the Universal Print portal. Note: the targeted user account must have access rights to both the printer and to the Universal Print service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PrinterProvisioning-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_errorcode","displayName":"Error code (User)","description":"Univeral Print printer installation error code.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PrinterProvisioning-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_install","displayName":"Install (User)","description":"Install Univeral Print printer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PrinterProvisioning-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_install_true","displayName":"Install","description":"Install this printer","helpText":null}},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_printersharedid","displayName":"Shared ID (User)","description":"Universal Print printer shared id","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/UPPrinterInstalls-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_printersharedname","displayName":"Printer Shared Name (User)","description":"Identifies the Universal Print printer, by its Share Name, you wish to install on the targeted user account. The printer's Share Name can be found in the printer's properties via the Universal Print portal. Note: the targeted user account must have access rights to both the printer and to the Universal Print service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PrinterProvisioning-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_status","displayName":"Status (User)","description":"Univeral Print printer status.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PrinterProvisioning-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},{"id":"vendor_msft_controlledconfiguration_blob","displayName":"Controlled Configuration Blob","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/defender-csp#:~:text=Configuration/TamperProtection"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"vendor_msft_defender_configuration_tamperprotection","displayName":"TamperProtection","description":"Enable tamper protection to prevent Microsoft Defender being disabled.\r\nNot Configured state is default and will have no impact.\r\nEnabled will enable the Tamper Protection restrictions.\r\nDisabled will disable the Tamper Protection restrictions.\r\nWhen the Enabled or Disabled state exists on a client, deploying Not configured will have no impact on the setting. To change the state from currently Enabled/Disabled, you must deploy the opposite setting to have effect.","helpText":null,"infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"vendor_msft_defender_configuration_tamperprotection_0","displayName":"Not configured","description":null,"helpText":null},{"id":"vendor_msft_defender_configuration_tamperprotection_1","displayName":"Enabled","description":null,"helpText":null},{"id":"vendor_msft_defender_configuration_tamperprotection_2","displayName":"Disabled","description":null,"helpText":null}]},{"id":"vendor_msft_defender_configuration_tamperprotection_blob","displayName":"Tamper Protection Blob","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/defender-csp#:~:text=Configuration/TamperProtection"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},{"id":"vendor_msft_defender_configuration_tamperprotection_options","displayName":"Configuration Protection (Device) (Preview)","description":"This setting can be used to turn on controlled configuration or tamper protection to help protect important security features from unwanted changes and interference.\r\n\r\nIf the setting is configured to Tamper Protection (On), this turns on tamper protection to enforce tamper protected settings to their secure defaults. This includes real-time protection, behavior monitoring, and more. Settings are configured with an MDM solution, such as Intune and is available in Windows 10 Enterprise E5 or equivalent subscriptions.\r\n\r\nIf the setting is configured to Controlled Configuration (On), this turns on controlled configuration, which enforces the configuration coming from Intune exclusively and any non-configured settings to their secure defaults. Controlled configuration is applicable to Antivirus and Endpoint detection and response settings.\r\n\r\nIf the setting is configured to OFF, this turns off Controlled Configuration and Tamper Protection.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/defender-csp#:~:text=Configuration/TamperProtection"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"vendor_msft_defender_configuration_tamperprotection_options_1","displayName":"Off","description":null,"helpText":null},{"id":"vendor_msft_defender_configuration_tamperprotection_options_0","displayName":"Tamper Protection (On)","description":null,"helpText":null},{"id":"vendor_msft_defender_configuration_tamperprotection_options_2","displayName":"Configuration Protection (On)","description":null,"helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_allowlocalipsecpolicymerge","displayName":"Allow Local Ipsec Policy Merge","description":"This value is an on/off switch. If this value is false, connection security rules from the local store are ignored and not enforced, regardless of the schema version and connection security rule version. The merge law for this option is to always use the value of the GroupPolicyRSoPStore.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_allowlocalipsecpolicymerge_false","displayName":"False","description":"AllowLocalIpsecPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_allowlocalipsecpolicymerge_true","displayName":"True","description":"AllowLocalIpsecPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, firewall rules from the local store are ignored and not enforced. The merge law for this option is to always use the value of the GroupPolicyRSoPStore. This value is valid for all schema versions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_allowlocalpolicymerge_false","displayName":"False","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_allowlocalpolicymerge_true","displayName":"True","description":"AllowLocalPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_authappsallowuserprefmerge","displayName":"Auth Apps Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, authorized application firewall rules in the local store are ignored and not enforced. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_authappsallowuserprefmerge_false","displayName":"False","description":"AuthAppsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_authappsallowuserprefmerge_true","displayName":"True","description":"AuthAppsAllowUserPrefMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_defaultinboundaction","displayName":"Default Inbound Action for Domain Profile","description":"This value is the action that the firewall does by default (and evaluates at the very end) on inbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 1 [Block]. The merge law for this option is to let the value of the GroupPolicyRSoPStore.win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_defaultinboundaction_0","displayName":"Allow","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_defaultinboundaction_1","displayName":"Block","description":"Block Inbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow]. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_defaultoutboundaction_0","displayName":"Allow","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_defaultoutboundaction_1","displayName":"Block","description":"Block Outbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disableinboundnotifications","displayName":"Disable Inbound Notifications","description":"This value is an on/off switch. If this value is false, the firewall MAY display a notification to the user when an application is blocked from listening on a port. If this value is on, the firewall MUST NOT display such a notification. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_disableinboundnotifications_false","displayName":"False","description":"Firewall May Display Notification","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disableinboundnotifications_true","displayName":"True","description":"Firewall Must Not Display Notification","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disablestealthmode","displayName":"Disable Stealth Mode","description":"This value is an on/off switch. When this option is false, the server operates in stealth mode. The firewall rules used to enforce stealth mode are implementation-specific. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_disablestealthmode_false","displayName":"False","description":"Use Stealth Mode","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disablestealthmode_true","displayName":"True","description":"Disable Stealth Mode","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disablestealthmodeipsecsecuredpacketexemption","displayName":"Disable Stealth Mode Ipsec Secured Packet Exemption","description":"This value is an on/off switch. This option is ignored if DisableStealthMode is on. Otherwise, when this option is true, the firewall's stealth mode rules MUST NOT prevent the host computer from responding to unsolicited network traffic if that traffic is secured by IPsec. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used. For schema versions 0x0200, 0x0201, and 0x020A, this value is invalid and MUST NOT be used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_disablestealthmodeipsecsecuredpacketexemption_false","displayName":"False","description":"FALSE","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disablestealthmodeipsecsecuredpacketexemption_true","displayName":"True","description":"TRUE","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disableunicastresponsestomulticastbroadcast","displayName":"Disable Unicast Responses To Multicast Broadcast","description":"This value is used as an on/off switch. If it is true, unicast responses to multicast broadcast traffic is blocked. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_disableunicastresponsestomulticastbroadcast_false","displayName":"False","description":"Unicast Responses Not Blocked","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_disableunicastresponsestomulticastbroadcast_true","displayName":"True","description":"Unicast Responses Blocked","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablefirewall","displayName":"Enable Domain Network Firewall","description":"This value is an on/off switch for the firewall and advanced security enforcement. If this value is false, the server MUST NOT block any network traffic, regardless of other policy settings. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":" ","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogdroppedpackets","displayName":"Enable Log Dropped Packets","description":"This value is used as an on/off switch. If this value is on, the firewall logs all the dropped packets. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogdroppedpackets_false","displayName":"Disable Logging Of Dropped Packets","description":"Disable Logging Of Dropped Packets","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogdroppedpackets_true","displayName":"Enable Logging Of Dropped Packets","description":"Enable Logging Of Dropped Packets","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogignoredrules","displayName":"Enable Log Ignored Rules","description":"This value is used as an on/off switch. The server MAY use this value in an implementation-specific way to control logging of events if a rule is not enforced for any reason. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogignoredrules_false","displayName":"Disable Logging Of Ignored Rules","description":"Disable Logging Of Ignored Rules","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogignoredrules_true","displayName":"Enable Logging Of Ignored Rules","description":"Enable Logging Of Ignored Rules","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogsuccessconnections","displayName":"Enable Log Success Connections","description":"This value is used as an on/off switch. If this value is on, the firewall logs all successful inbound connections. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogsuccessconnections_false","displayName":"Disable Logging Of Successful Connections","description":"Disable Logging Of Successful Connections","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_enablelogsuccessconnections_true","displayName":"Enable Logging Of Successful Connections","description":"Enable Logging Of Successful Connections","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_globalportsallowuserprefmerge","displayName":"Global Ports Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, global port firewall rules in the local store are ignored and not enforced. The setting only has meaning if it is set or enumerated in the Group Policy store or if it is enumerated from the GroupPolicyRSoPStore. The merge law for this option is to let the value GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_globalportsallowuserprefmerge_false","displayName":"False","description":"GlobalPortsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_globalportsallowuserprefmerge_true","displayName":"True","description":"GlobalPortsAllowUserPrefMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_domainprofile_logfilepath","displayName":"Log File Path","description":"This value is a string that represents a file path to the log where the firewall logs dropped packets and successful connections. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_logmaxfilesize","displayName":"Log Max File Size","description":"This value specifies the size, in kilobytes, of the log file where dropped packets and successful connections are logged. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_shielded","displayName":"Shielded","description":"This value is used as an on/off switch. If this value is on and EnableFirewall is on, the server MUST block all incoming traffic regardless of other policy settings. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_shielded_false","displayName":"False","description":"Shielding Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_shielded_true","displayName":"True","description":"Shielding On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}","displayName":" Firewall Rule Name","description":"Unique alpha numeric identifier for the rule. The rule name must not include a forward slash (/).","helpText":"","infoUrls":[],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_action_type","displayName":"Action","description":"Specifies the action the rule enforces to block or allow network traffic.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_action_type_0","displayName":"Block","description":"Block","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_action_type_1","displayName":"Allow","description":"Allow","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_app_filepath","displayName":"File Path","description":"The file path of an app is simply its location on the client device. For example, C:\\Windows\\System\\Notepad.exe or %WINDIR%\\Notepad.exe. You can define one application to be used in each Firewall rule. If you specify multiple conditions in a single rule, these will be treated as an AND operation. i.e program=svchost.exe AND service=mpssvc, etc. All of the app related conditions in a single rule work to scope the traffic even further, so they must all correspond to the specific app/service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_app_packagefamilyname","displayName":"Package Family Name","description":"Package family names can be retrieved by running the Get-AppxPackage command from PowerShell. You can define one application to be used in each Firewall rule. If you specify multiple conditions in a single rule, these will be treated as an AND operation. i.e program=svchost.exe AND service=mpssvc, etc. All of the app related conditions in a single rule work to scope the traffic even further, so they must all correspond to the specific app/service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_app_servicename","displayName":"Service Name","description":"Windows service short names are used in cases when a service, not an application, is sending or receiving traffic. Service short names can be retrieved by running the Get-Service command from PowerShell. You can define one application to be used in each Firewall rule. If you specify multiple conditions in a single rule, these will be treated as an AND operation. i.e program=svchost.exe AND service=mpssvc, etc. All of the app related conditions in a single rule work to scope the traffic even further, so they must all correspond to the specific app/service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_description","displayName":"Description","description":"Specifies the description of the rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_direction","displayName":"Direction","description":"Comma separated list. The rule is enabled based on the traffic direction as following.\n\nIN - the rule applies to inbound traffic.\nOUT - the rule applies to outbound traffic.\n\nIf not specified the detault is OUT.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_direction_in","displayName":"The rule applies to inbound traffic.","description":"The rule applies to inbound traffic.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_direction_out","displayName":"The rule applies to outbound traffic.","description":"The rule applies to outbound traffic.","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_edgetraversal","displayName":"Edge Traversal","description":"Indicates whether edge traversal is enabled or disabled for this rule.\n\nThe EdgeTraversal property indicates that specific inbound traffic is allowed to tunnel through NATs and other edge devices using the Teredo tunneling technology. In order for this setting to work correctly, the application or service with the inbound firewall rule needs to support IPv6. The primary application of this setting allows listeners on the host to be globally addressable through a Teredo IPv6 address.\n\nNew rules have the EdgeTraversal property disabled by default.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_edgetraversal_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_edgetraversal_1","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_enabled","displayName":"Enabled","description":"Indicates whether the rule is enabled or disabled. If not specified - a new rule is enabled by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_enabled_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_enabled_1","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_firewallrulename","displayName":null,"description":null,"helpText":null,"infoUrls":[],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_icmptypesandcodes","displayName":"ICMP Types And Codes","description":"\n String value. Multiple ICMP type+code pairs can be included in the string by separating each value with a \",\". If more than one ICMP type+code pair is specified, the strings must be separated by a comma.\n To specify all ICMP types and codes, use the \"*\" character. For specific ICMP types and codes, use the \":\" to separate the type and code.\n The following are valid examples: 3:4 or 1:*. The \"*\" character can be used to represent any code. The \"*\" character can't be used to specify any type, examples such as \"*:4\" or \"*:*\" are invalid.\n When setting this field in a firewall rule, the protocol field must also be set, to either 1 (ICMP) or 58 (IPv6-ICMP).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes","displayName":"Interface Types","description":"String value. Multiple interface types can be included in the string by separating each value with a \",\". Acceptable values are \"RemoteAccess\", \"Wireless\", \"Lan\", and \"All\".\n If more than one interface type is specified, the strings must be separated by a comma.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_remoteaccess","displayName":"Remote Access","description":"RemoteAccess","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_wireless","displayName":"Wireless","description":"Wireless","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_lan","displayName":"Lan","description":"Lan","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_mobilebroadband","displayName":"[Not Supported] Mobile Broadband","description":"MobileBroadband","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_mbb","displayName":"Mobile Broadband","description":"MobileBroadband","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_all","displayName":"All","description":"All","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_localaddressranges","displayName":"Local Address Ranges","description":"List of local addresses covered by the rule. Valid tokens include:​\r\n\r\n\"*\" indicates any local address. If present, this must be the only token included.\r\nA subnet can be specified using either the subnet mask or network prefix notation. If neither a subnet mask nor a network prefix is specified, the subnet mask defaults to 255.255.255.255.​​\r\nA valid IPv6 address.​​\r\nAn IPv4 address range in the format of \"start address - end address\" with no spaces included, where the start address is less than the end address.​​\r\nAn IPv6 address range in the format of \"start address - end address\" with no spaces included, where the start address is less than the end address.\r\n\r\nIf not specified, the default is \"Any address.\"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_localportranges","displayName":"Local Port Ranges","description":"List of local port ranges. Valid values include:​\r\n\r\nA valid port number between 0 and 65535. For example, 200\r\nA port range in the format of \"start port – end port\" with no spaces included, where the start port is less than the end port. For example, 300-320\r\n\r\nIf not specified, the default is \"All ports.\" When defining multiple local and remote port ranges, the Firewall rule will be evaluated as OR operations within an individual field, and AND operations across rule fields. i.e. (local port A OR local port B) AND (remote port A OR remote port B). When setting this field in a firewall rule, the protocol field must also be set, to either 6 (TCP) or 17 (UDP).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_localuserauthorizedlist","displayName":"Local User Authorized List","description":"Specifies the list of authorized local users for this rule. A list of authorized users cannot be specified if the rule being authored is targeting a Windows service. If not specified, the default is all users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_name","displayName":"Name","description":"Specifies the friendly name of the firewall rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_policyappid","displayName":"Policy App Id","description":" Specifies one WDAC tag. This is a string that can contain any alphanumeric character and any of the characters \":\", \"/\", \".\", and \"_\". \r\n A PolicyAppId and ServiceName cannot be specified in the same rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_profiles","displayName":"Network Types","description":"Specifies the profiles to which the rule belongs: Domain, Private, Public. See FW_PROFILE_TYPE for the bitmasks that are used to identify profile types. If not specified, the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_profiles_1","displayName":"FW_PROFILE_TYPE_DOMAIN: This value represents the profile for networks that are connected to domains.","description":"FW_PROFILE_TYPE_DOMAIN: This value represents the profile for networks that are connected to domains.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_profiles_2","displayName":"FW_PROFILE_TYPE_PRIVATE: This value represents the standard profile for networks. These networks are classified as private by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are behind Network Address Translation (NAT) devices, routers, and other edge devices, and they are in a private location, such as a home or an office. AND FW_PROFILE_TYPE_PRIVATE: This value represents the profile for private networks, which is represented by the same value as that used for FW_PROFILE_TYPE_STANDARD.","description":"FW_PROFILE_TYPE_STANDARD: This value represents the standard profile for networks. These networks are classified as private by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are behind Network Address Translation (NAT) devices, routers, and other edge devices, and they are in a private location, such as a home or an office. AND FW_PROFILE_TYPE_PRIVATE: This value represents the profile for private networks, which is represented by the same value as that used for FW_PROFILE_TYPE_STANDARD.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_profiles_4","displayName":"FWPROFILETYPEPUBLIC: This value represents the profile for public networks. These networks are classified as public by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are those at airports, coffee shops, and other public places where the peers in the network or the network administrator are not trusted.","description":"FW_PROFILE_TYPE_PUBLIC: This value represents the profile for public networks. These networks are classified as public by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are those at airports, coffee shops, and other public places where the peers in the network or the network administrator are not trusted.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_profiles_2147483647","displayName":"FW_PROFILE_TYPE_ALL: This value represents all these network sets and any future network sets.","description":"FW_PROFILE_TYPE_ALL: This value represents all these network sets and any future network sets.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_profiles_-2147483648","displayName":"FW_PROFILE_TYPE_CURRENT: This value represents the current profiles to which the firewall and advanced security components determine the host is connected at the moment of the call. This value can be specified only in method calls, and it cannot be combined with other flags.","description":"FW_PROFILE_TYPE_CURRENT: This value represents the current profiles to which the firewall and advanced security components determine the host is connected at the moment of the call. This value can be specified only in method calls, and it cannot be combined with other flags.","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_protocol","displayName":"Protocol","description":"Select the protocol for this port rule. Transport layer protocols, TCP(6) and UDP(17), allow you to specify ports or port ranges. For custom protocols, enter a number between 0 and 255 representing the IP protocol. If not specified, the default is \"Any.\"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_remoteaddressdynamickeywords","displayName":"Reusable groups","description":"Comma separated list of Dynamic Keyword Address Ids (GUID strings) specifying the remote addresses covered by the rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_remoteaddressranges","displayName":"Remote Address Ranges","description":"List of remote addresses covered by the rule. Tokens are case insensitive. Valid tokens include:​​​\r\n\r\n\"*\" indicates any remote address. If present, this must be the only token included.\r\n\r\n\"Defaultgateway\"\r\n\"DHCP\"\r\n\"DNS\"\r\n\"WINS\"\r\n\"Intranet\" (supported on Windows versions 1809+)\r\n\"RmtIntranet\" (supported on Windows versions 1809+)\r\n\"Internet\" (supported on Windows versions 1809+)\r\n\"Ply2Renders\" ​(supported on Windows versions 1809+)\r\n\"LocalSubnet\" indicates any local address on the local subnet.\r\nA subnet can be specified using either the subnet mask or network prefix notation. If neither a subnet mask nor a network prefix is specified, the subnet mask defaults to 255.255.255.255.\r\nA valid IPv6 address.\r\nAn IPv4 address range in the format of \"start address - end address\" with no spaces included, where the start address is less than the end address.\r\nAn IPv6 address range in the format of \"start address - end address\" with no spaces included, where the start address is less than the end address.​\r\n\r\nIf not specified, the default is \"Any address.\"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_remoteportranges","displayName":"Remote Port Ranges","description":"List of remote port ranges. Valid values include:​\r\n\r\nA valid port number between 0 and 65535. For example, 200\r\nA port range in the format of \"start port – end port\" with no spaces included, where the start port is less than the end port. For example, 300-320\r\n\r\nIf not specified, the default is \"All ports.\" When defining multiple local and remote port ranges, the Firewall rule will be evaluated as OR operations within an individual field, and AND operations across rule fields. i.e. (local port A OR local port B) AND (remote port A OR remote port B). When setting this field in a firewall rule, the protocol field must also be set, to either 6 (TCP) or 17 (UDP).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_global_crlcheck","displayName":"Certificate revocation list verification","description":"This value specifies how certificate revocation list (CRL) verification is enforced. The value MUST be 0, 1, or 2. A value of 0 disables CRL checking. A value of 1 specifies that CRL checking is attempted and that certificate validation fails only if the certificate is revoked. Other failures that are encountered during CRL checking (such as the revocation URL being unreachable) do not cause certificate validation to fail. A value of 2 means that checking is required and that certificate validation fails if any error is encountered during CRL processing. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, use the local store value.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_crlcheck_0","displayName":"None","description":"Disables CRL checking","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_crlcheck_1","displayName":"Attempt","description":"Specifies that CRL checking is attempted and that certificate validation fails only if the certificate is revoked. Other failures that are encountered during CRL checking (such as the revocation URL being unreachable) do not cause certificate validation to fail.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_crlcheck_2","displayName":"Require","description":"Means that checking is required and that certificate validation fails if any error is encountered during CRL processing","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_disablestatefulftp","displayName":"Disable Stateful Ftp","description":"This value is an on/off switch. If off, the firewall performs stateful File Transfer Protocol (FTP) filtering to allow secondary connections. FALSE means off; TRUE means on, so the stateful FTP is disabled. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_disablestatefulftp_false","displayName":"False","description":"Stateful FTP enabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_disablestatefulftp_true","displayName":"True","description":"Stateful FTP disabled","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_enableauditmode","displayName":"Enable Audit Mode","description":"This value specifies if the target machine is in Firewall Audit Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_enableauditmode_false","displayName":"Indicates that Audit mode is disabled","description":"Indicates that Audit mode is disabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_enableauditmode_true","displayName":"Indicates that Audit mode is enabled","description":"Indicates that Audit mode is enabled","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_enablepacketqueue","displayName":"Enable Packet Queue","description":"This value specifies how scaling for the software on the receive side is enabled for both the encrypted receive and clear text forward path for the IPsec tunnel gateway scenario. Use of this option also ensures that the packet order is preserved. The data type for this option value is a integer and is a combination of flags. A value of 0x00 indicates that all queuing is to be disabled. A value of 0x01 specifies that inbound encrypted packets are to be queued. A value of 0x02 specifies that packets are to be queued after decryption is performed for forwarding.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_enablepacketqueue_0","displayName":"Disabled","description":"Indicates that all queuing is to be disabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_enablepacketqueue_1","displayName":"Queue Inbound","description":"Specifies that inbound encrypted packets are to be queued","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_enablepacketqueue_2","displayName":"Queue Outbound","description":"Specifies that packets are to be queued after decryption is performed for forwarding","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt","displayName":"IPsec Exceptions","description":"This value configures IPsec exceptions and MUST be a combination of the valid flags that are defined in IPSEC_EXEMPT_VALUES; therefore, the maximum value MUST always be IPSEC_EXEMPT_MAX-1 for servers supporting a schema version of 0x0201 and IPSEC_EXEMPT_MAX_V2_0-1 for servers supporting a schema version of 0x0200. If the maximum value is exceeded when the method RRPC_FWSetGlobalConfig (Opnum 4) is called, the method returns ERROR_INVALID_PARAMETER. This error code is returned if no other preceding error is discovered. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, use the local store value.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_0","displayName":"FWGLOBALCONFIGIPSECEXEMPTNONE: No IPsec exemptions.","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_NONE: No IPsec exemptions.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_1","displayName":"Exempt neighbor discover IPv6 ICMP type-codes from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_NEIGHBOR_DISC: Exempt neighbor discover IPv6 ICMP type-codes from IPsec.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_2","displayName":"Exempt ICMP from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_ICMP: Exempt ICMP from IPsec.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_4","displayName":"Exempt router discover IPv6 ICMP type-codes from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_ROUTER_DISC: Exempt router discover IPv6 ICMP type-codes from IPsec.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_8","displayName":"Exempt both IPv4 and IPv6 DHCP traffic from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_DHCP: Exempt both IPv4 and IPv6 DHCP traffic from IPsec.","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_opportunisticallymatchauthsetperkm","displayName":"Opportunistically Match Auth Set Per KM","description":"This value is used as an on/off switch. When this option is false, keying modules MUST ignore the entire authentication set if they do not support all of the authentication suites specified in the set. When this option is true, keying modules MUST ignore only the authentication suites that they don’t support. For schema versions 0x0200, 0x0201, and 0x020A, this value is invalid and MUST NOT be used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_opportunisticallymatchauthsetperkm_false","displayName":"False","description":"FALSE","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_opportunisticallymatchauthsetperkm_true","displayName":"True","description":"TRUE","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_presharedkeyencoding","displayName":"Preshared Key Encoding","description":"Specifies the preshared key encoding that is used. MUST be a valid value from the PRESHARED_KEY_ENCODING_VALUES enumeration. Default is 1 [UTF-8]. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, use the local store value.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_presharedkeyencoding_0","displayName":"None","description":"FW_GLOBAL_CONFIG_PRESHARED_KEY_ENCODING_NONE: Preshared key is not encoded. Instead, it is kept in its wide-character format. This symbolic constant has a value of 0.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_presharedkeyencoding_1","displayName":"UTF8","description":"FW_GLOBAL_CONFIG_PRESHARED_KEY_ENCODING_UTF_8: Encode the preshared key using UTF-8. This symbolic constant has a value of 1.","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_global_saidletime","displayName":"Security association idle time","description":"This value configures the security association idle time, in seconds. Security associations are deleted after network traffic is not seen for this specified period of time. The value MUST be in the range of 300 to 3,600 inclusive. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, use the local store value.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}","displayName":" Firewall Rule Name","description":"Unique alpha numeric identifier for the rule. The rule name must not include a forward slash (/).","helpText":"","infoUrls":[],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_action","displayName":"Action","description":"Specifies the action the rule enforces:\n0 - Block\n1 - Allow","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_action_0","displayName":"Block","description":"Block","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_action_1","displayName":"Allow","description":"Allow","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_direction","displayName":"Direction","description":"The rule is enabled based on the traffic direction as following.\n\nIN - the rule applies to inbound traffic.\nOUT - the rule applies to outbound traffic.\n\nIf not specified the detault is OUT.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_direction_in","displayName":"The rule applies to inbound traffic.","description":"The rule applies to inbound traffic.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_direction_out","displayName":"The rule applies to outbound traffic.","description":"The rule applies to outbound traffic.","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_enabled","displayName":"Enabled","description":"Indicates whether the rule is enabled or disabled. If not specified - a new rule is enabled by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_enabled_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_enabled_1","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_firewallrulename","displayName":null,"description":null,"helpText":null,"infoUrls":[],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_localaddressranges","displayName":"Local Address Ranges","description":"Consists of one or more comma-delimited tokens specifying the local addresses covered by the rule. \"*\" is the default value.\nValid tokens include:\n\"*\" indicates any local address. If present, this must be the only token included.\n\nA subnet can be specified using either the subnet mask or network prefix notation. If neither a subnet mask not a network prefix is specified, the subnet mask defaults to 255.255.255.255.\nA valid IPv6 address.\nAn IPv4 address range in the format of \"start address - end address\" with no spaces included.\nAn IPv6 address range in the format of \"start address - end address\" with no spaces included. If not specified the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_localportranges","displayName":"Local Port Ranges","description":"Comma Separated list of ranges for eg. 100-120,200,300-320. If not specified the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_name","displayName":"Name","description":"Specifies the friendly name of the Hyper-V Firewall rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_priority","displayName":"Priority","description":"This value represents the order of rule enforcement. A lower priority rule is evaluated first. If not specified, block rules are evaluated before allow rules. If priority is configured, it is highly recommended to configure the value for ALL rules to ensure expected evaluation of rules.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_profiles","displayName":"Profiles","description":"Specifies the profiles to which the rule belongs: Domain, Private, Public. See FW_PROFILE_TYPE for the bitmasks that are used to identify profile types. If not specified, the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_profiles_1","displayName":"FWPROFILETYPEDOMAIN: This value represents the profile for networks that are connected to domains.","description":"FW_PROFILE_TYPE_DOMAIN: This value represents the profile for networks that are connected to domains.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_profiles_2","displayName":"FWPROFILETYPESTANDARD: This value represents the standard profile for networks. These networks are classified as private by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are behind Network Address Translation (NAT) devices, routers, and other edge devices, and they are in a private location, such as a home or an office. AND FWPROFILETYPEPRIVATE: This value represents the profile for private networks, which is represented by the same value as that used for FWPROFILETYPESTANDARD.","description":"FW_PROFILE_TYPE_STANDARD: This value represents the standard profile for networks. These networks are classified as private by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are behind Network Address Translation (NAT) devices, routers, and other edge devices, and they are in a private location, such as a home or an office. AND FW_PROFILE_TYPE_PRIVATE: This value represents the profile for private networks, which is represented by the same value as that used for FW_PROFILE_TYPE_STANDARD.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_profiles_4","displayName":"FWPROFILETYPEPUBLIC: This value represents the profile for public networks. These networks are classified as public by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are those at airports, coffee shops, and other public places where the peers in the network or the network administrator are not trusted.","description":"FW_PROFILE_TYPE_PUBLIC: This value represents the profile for public networks. These networks are classified as public by the administrators in the server host. The classification happens the first time the host connects to the network. Usually these networks are those at airports, coffee shops, and other public places where the peers in the network or the network administrator are not trusted.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_profiles_2147483647","displayName":"FWPROFILETYPEALL: This value represents all these network sets and any future network sets.","description":"FW_PROFILE_TYPE_ALL: This value represents all these network sets and any future network sets.","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_protocol","displayName":"Protocol","description":"0-255 number representing the ip protocol (TCP = 6, UDP = 17). If not specified the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_remoteaddressranges","displayName":"Remote Address Ranges","description":"Consists of one or more comma-delimited tokens specifying the remote addresses covered by the rule. The default value is \"*\". Valid tokens include:\n\"*\" indicates any remote address. If present, this must be the only token included.\nA subnet can be specified using either the subnet mask or network prefix notation. If neither a subnet mask not a network prefix is specified, the subnet mask defaults to 255.255.255.255.\nA valid IPv6 address.\nAn IPv4 address range in the format of \"start address - end address\" with no spaces included.\nAn IPv6 address range in the format of \"start address - end address\" with no spaces included. If not specified the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_remoteportranges","displayName":"Remote Port Ranges","description":" Comma Separated list of ranges for eg. 100-120,200,300-320. If not specified the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_vmcreatorid","displayName":"Target","description":"This field specifies the VM Creator ID that this rule is applicable to. Not configuring this setting will result in this rule applying to all VM creators.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_vmcreatorid_wsl","displayName":"Windows Subsystem for Linux","description":"Windows Subsystem for Linux","helpText":null}},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}","displayName":"VM Creator Id","description":"VM Creator ID that these settings apply to. Valid format is a GUID","helpText":"","infoUrls":[],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_allowhostpolicymerge","displayName":"Allow Host Policy Merge","description":"This value is used as an on/off switch. If this value is true, applicable host firewall rules and settings will be applied to Hyper-V Firewall.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_allowhostpolicymerge_false","displayName":"AllowHostPolicyMerge Off","description":"AllowHostPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_allowhostpolicymerge_true","displayName":"AllowHostPolicyMerge On","description":"AllowHostPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, Hyper-V Firewall rules from the local store are ignored and not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_allowlocalpolicymerge_false","displayName":"AllowLocalPolicyMerge Off","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_allowlocalpolicymerge_true","displayName":"AllowLocalPolicyMerge On","description":"AllowLocalPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_defaultinboundaction","displayName":"Default Inbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on inbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 1 [Block].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_defaultinboundaction_0","displayName":"Allow Inbound By Default","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_defaultinboundaction_1","displayName":"Block Inbound By Default","description":"Block Inbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_defaultoutboundaction_0","displayName":"Allow Outbound By Default","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_defaultoutboundaction_1","displayName":"Block Outbound By Default","description":"Block Outbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_enablefirewall","displayName":"Enable Domain Network Firewall","description":"This value is an on/off switch for the Hyper-V Firewall enforcement.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_enableloopback","displayName":"Enable Loopback","description":"This value is an on/off switch for loopback traffic. This determines if this VM is able to send/receive loopback traffic to other VMs or the host.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_enableloopback_false","displayName":"Disable loopback","description":"Disable loopback","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_enableloopback_true","displayName":"Enable loopback","description":"Enable loopback","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, Hyper-V Firewall rules from the local store are ignored and not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_allowlocalpolicymerge_false","displayName":"AllowLocalPolicyMerge Off","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_allowlocalpolicymerge_true","displayName":"AllowLocalPolicyMerge On","description":"AllowLocalPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultinboundaction","displayName":"Default Inbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on inbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 1 [Block].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultinboundaction_0","displayName":"Allow Inbound By Default","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultinboundaction_1","displayName":"Block Inbound By Default","description":"Block Inbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultoutboundaction_0","displayName":"Allow Outbound By Default","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultoutboundaction_1","displayName":"Block Outbound By Default","description":"Block Outbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_enablefirewall","displayName":"Enable Private Network Firewall","description":"This value is an on/off switch for the Hyper-V Firewall enforcement.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, Hyper-V Firewall rules from the local store are ignored and not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_allowlocalpolicymerge_false","displayName":"AllowLocalPolicyMerge Off","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_allowlocalpolicymerge_true","displayName":"AllowLocalPolicyMerge On","description":"AllowLocalPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultinboundaction","displayName":"Default Inbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on inbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 1 [Block].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultinboundaction_0","displayName":"Allow Inbound By Default","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultinboundaction_1","displayName":"Block Inbound By Default","description":"Block Inbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultoutboundaction_0","displayName":"Allow Outbound By Default","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultoutboundaction_1","displayName":"Block Outbound By Default","description":"Block Outbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_enablefirewall","displayName":"Enable Public Network Firewall","description":"This value is an on/off switch for the Hyper-V Firewall enforcement.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_enablefirewall_false","displayName":"False","description":"Disable Hyper-V Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_enablefirewall_true","displayName":"True","description":"Enable Hyper-V Firewall","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_target","displayName":"Target","description":"Settings for the Windows Firewall for Hyper-V containers. Each setting applies on a per-VM Creator basis","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_target_wsl","displayName":"Windows Subsystem for Linux","description":"Windows Subsystem for Linux","helpText":null}},{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalipsecpolicymerge","displayName":"Allow Local Ipsec Policy Merge","description":"This value is an on/off switch. If this value is false, connection security rules from the local store are ignored and not enforced, regardless of the schema version and connection security rule version. The merge law for this option is to always use the value of the GroupPolicyRSoPStore.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalipsecpolicymerge_false","displayName":"False","description":"AllowLocalIpsecPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalipsecpolicymerge_true","displayName":"True","description":"AllowLocalIpsecPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, firewall rules from the local store are ignored and not enforced. The merge law for this option is to always use the value of the GroupPolicyRSoPStore. This value is valid for all schema versions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalpolicymerge_false","displayName":"False","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalpolicymerge_true","displayName":"True","description":"AllowLocalPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_authappsallowuserprefmerge","displayName":"Auth Apps Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, authorized application firewall rules in the local store are ignored and not enforced. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_authappsallowuserprefmerge_false","displayName":"False","description":"AuthAppsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_authappsallowuserprefmerge_true","displayName":"True","description":"AuthAppsAllowUserPrefMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultinboundaction","displayName":"Default Inbound Action for Private Profile","description":"Specifies how to filter inbound traffic. The acceptable values for this parameter are: NotConfigured, Allow, or Block.","helpText":" ","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultinboundaction_0","displayName":"Allow","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultinboundaction_1","displayName":"Block","description":"Block Inbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow]. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultoutboundaction_0","displayName":"Allow","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultoutboundaction_1","displayName":"Block","description":"Block Outbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableinboundnotifications","displayName":"Disable Inbound Notifications","description":"This value is an on/off switch. If this value is false, the firewall MAY display a notification to the user when an application is blocked from listening on a port. If this value is on, the firewall MUST NOT display such a notification. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableinboundnotifications_false","displayName":"False","description":"Firewall May Display Notification","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableinboundnotifications_true","displayName":"True","description":"Firewall Must Not Display Notification","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmode","displayName":"Disable Stealth Mode","description":"This value is an on/off switch. When this option is false, the server operates in stealth mode. The firewall rules used to enforce stealth mode are implementation-specific. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmode_false","displayName":"False","description":"Use Stealth Mode","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmode_true","displayName":"True","description":"Disable Stealth Mode","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmodeipsecsecuredpacketexemption","displayName":"Disable Stealth Mode Ipsec Secured Packet Exemption","description":"This value is an on/off switch. This option is ignored if DisableStealthMode is on. Otherwise, when this option is true, the firewall's stealth mode rules MUST NOT prevent the host computer from responding to unsolicited network traffic if that traffic is secured by IPsec. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used. For schema versions 0x0200, 0x0201, and 0x020A, this value is invalid and MUST NOT be used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmodeipsecsecuredpacketexemption_false","displayName":"False","description":"FALSE","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmodeipsecsecuredpacketexemption_true","displayName":"True","description":"TRUE","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableunicastresponsestomulticastbroadcast","displayName":"Disable Unicast Responses To Multicast Broadcast","description":"This value is used as an on/off switch. If it is true, unicast responses to multicast broadcast traffic is blocked. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableunicastresponsestomulticastbroadcast_false","displayName":"False","description":"Unicast Responses Not Blocked","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableunicastresponsestomulticastbroadcast_true","displayName":"True","description":"Unicast Responses Blocked","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablefirewall","displayName":"Enable Private Network Firewall","description":"This value is an on/off switch for the firewall and advanced security enforcement. If this value is false, the server MUST NOT block any network traffic, regardless of other policy settings. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":" ","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogdroppedpackets","displayName":"Enable Log Dropped Packets","description":"This value is used as an on/off switch. If this value is on, the firewall logs all the dropped packets. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogdroppedpackets_false","displayName":"Disable Logging Of Dropped Packets","description":"Disable Logging Of Dropped Packets","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogdroppedpackets_true","displayName":"Enable Logging Of Dropped Packets","description":"Enable Logging Of Dropped Packets","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogignoredrules","displayName":"Enable Log Ignored Rules","description":"This value is used as an on/off switch. The server MAY use this value in an implementation-specific way to control logging of events if a rule is not enforced for any reason. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogignoredrules_false","displayName":"Disable Logging Of Ignored Rules","description":"Disable Logging Of Ignored Rules","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogignoredrules_true","displayName":"Enable Logging Of Ignored Rules","description":"Enable Logging Of Ignored Rules","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogsuccessconnections","displayName":"Enable Log Success Connections","description":"This value is used as an on/off switch. If this value is on, the firewall logs all successful inbound connections. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogsuccessconnections_false","displayName":"Disable Logging Of Successful Connections","description":"Disable Logging Of Successful Connections","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogsuccessconnections_true","displayName":"Enable Logging Of Successful Connections","description":"Enable Logging Of Successful Connections","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_globalportsallowuserprefmerge","displayName":"Global Ports Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, global port firewall rules in the local store are ignored and not enforced. The setting only has meaning if it is set or enumerated in the Group Policy store or if it is enumerated from the GroupPolicyRSoPStore. The merge law for this option is to let the value GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_globalportsallowuserprefmerge_false","displayName":"False","description":"GlobalPortsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_globalportsallowuserprefmerge_true","displayName":"True","description":"GlobalPortsAllowUserPrefMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_privateprofile_logfilepath","displayName":"Log File Path","description":"This value is a string that represents a file path to the log where the firewall logs dropped packets and successful connections. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_logmaxfilesize","displayName":"Log Max File Size","description":"This value specifies the size, in kilobytes, of the log file where dropped packets and successful connections are logged. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_shielded","displayName":"Shielded","description":"This value is used as an on/off switch. If this value is on and EnableFirewall is on, the server MUST block all incoming traffic regardless of other policy settings. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_shielded_false","displayName":"False","description":"Shielding Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_shielded_true","displayName":"True","description":"Shielding On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalipsecpolicymerge","displayName":"Allow Local Ipsec Policy Merge","description":"This value is an on/off switch. If this value is false, connection security rules from the local store are ignored and not enforced, regardless of the schema version and connection security rule version. The merge law for this option is to always use the value of the GroupPolicyRSoPStore.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalipsecpolicymerge_false","displayName":"False","description":"AllowLocalIpsecPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalipsecpolicymerge_true","displayName":"True","description":"AllowLocalIpsecPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, firewall rules from the local store are ignored and not enforced. The merge law for this option is to always use the value of the GroupPolicyRSoPStore. This value is valid for all schema versions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalpolicymerge_false","displayName":"False","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalpolicymerge_true","displayName":"True","description":"AllowLocalPolicyMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_authappsallowuserprefmerge","displayName":"Auth Apps Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, authorized application firewall rules in the local store are ignored and not enforced. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_authappsallowuserprefmerge_false","displayName":"False","description":"AuthAppsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_authappsallowuserprefmerge_true","displayName":"True","description":"AuthAppsAllowUserPrefMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultinboundaction","displayName":"Default Inbound Action for Public Profile","description":"Specifies how to filter inbound traffic. The acceptable values for this parameter are: NotConfigured, Allow, or Block.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultinboundaction_0","displayName":"Allow","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultinboundaction_1","displayName":"Block","description":"Block Inbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow]. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultoutboundaction_0","displayName":"Allow","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultoutboundaction_1","displayName":"Block","description":"Block Outbound By Default","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disableinboundnotifications","displayName":"Disable Inbound Notifications","description":"This value is an on/off switch. If this value is false, the firewall MAY display a notification to the user when an application is blocked from listening on a port. If this value is on, the firewall MUST NOT display such a notification. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_disableinboundnotifications_false","displayName":"False","description":"Firewall May Display Notification","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disableinboundnotifications_true","displayName":"True","description":"Firewall Must Not Display Notification","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmode","displayName":"Disable Stealth Mode","description":"This value is an on/off switch. When this option is false, the server operates in stealth mode. The firewall rules used to enforce stealth mode are implementation-specific. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmode_false","displayName":"False","description":"Use Stealth Mode","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmode_true","displayName":"True","description":"Disable Stealth Mode","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmodeipsecsecuredpacketexemption","displayName":"Disable Stealth Mode Ipsec Secured Packet Exemption","description":"This value is an on/off switch. This option is ignored if DisableStealthMode is on. Otherwise, when this option is true, the firewall's stealth mode rules MUST NOT prevent the host computer from responding to unsolicited network traffic if that traffic is secured by IPsec. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used. For schema versions 0x0200, 0x0201, and 0x020A, this value is invalid and MUST NOT be used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmodeipsecsecuredpacketexemption_false","displayName":"False","description":"FALSE","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmodeipsecsecuredpacketexemption_true","displayName":"True","description":"TRUE","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disableunicastresponsestomulticastbroadcast","displayName":"Disable Unicast Responses To Multicast Broadcast","description":"This value is used as an on/off switch. If it is true, unicast responses to multicast broadcast traffic is blocked. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_disableunicastresponsestomulticastbroadcast_false","displayName":"False","description":"Unicast Responses Not Blocked","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disableunicastresponsestomulticastbroadcast_true","displayName":"True","description":"Unicast Responses Blocked","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablefirewall","displayName":"Enable Public Network Firewall","description":"This value is an on/off switch for the firewall and advanced security enforcement. If this value is false, the server MUST NOT block any network traffic, regardless of other policy settings. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":" ","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogdroppedpackets","displayName":"Enable Log Dropped Packets","description":"This value is used as an on/off switch. If this value is on, the firewall logs all the dropped packets. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogdroppedpackets_false","displayName":"Disable Logging Of Dropped Packets","description":"Disable Logging Of Dropped Packets","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogdroppedpackets_true","displayName":"Enable Logging Of Dropped Packets","description":"Enable Logging Of Dropped Packets","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogignoredrules","displayName":"Enable Log Ignored Rules","description":"This value is used as an on/off switch. The server MAY use this value in an implementation-specific way to control logging of events if a rule is not enforced for any reason. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogignoredrules_false","displayName":"Disable Logging Of Ignored Rules","description":"Disable Logging Of Ignored Rules","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogignoredrules_true","displayName":"Enable Logging Of Ignored Rules","description":"Enable Logging Of Ignored Rules","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogsuccessconnections","displayName":"Enable Log Success Connections","description":"This value is used as an on/off switch. If this value is on, the firewall logs all successful inbound connections. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogsuccessconnections_false","displayName":"Disable Logging Of Successful Connections","description":"Disable Logging Of Successful Connections","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogsuccessconnections_true","displayName":"Enable Logging Of Successful Connections","description":"Enable Logging Of Successful Connections","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_globalportsallowuserprefmerge","displayName":"Global Ports Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, global port firewall rules in the local store are ignored and not enforced. The setting only has meaning if it is set or enumerated in the Group Policy store or if it is enumerated from the GroupPolicyRSoPStore. The merge law for this option is to let the value GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_globalportsallowuserprefmerge_false","displayName":"False","description":"GlobalPortsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_globalportsallowuserprefmerge_true","displayName":"True","description":"GlobalPortsAllowUserPrefMerge On","helpText":null}]},{"id":"vendor_msft_firewall_mdmstore_publicprofile_logfilepath","displayName":"Log File Path","description":"This value is a string that represents a file path to the log where the firewall logs dropped packets and successful connections. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_logmaxfilesize","displayName":"Log Max File Size","description":"This value specifies the size, in kilobytes, of the log file where dropped packets and successful connections are logged. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_shielded","displayName":"Shielded","description":"This value is used as an on/off switch. If this value is on and EnableFirewall is on, the server MUST block all incoming traffic regardless of other policy settings. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_shielded_false","displayName":"False","description":"Shielding Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_shielded_true","displayName":"True","description":"Shielding On","helpText":null}]},{"id":"vendor_msft_personalization_companylogourl","displayName":"Company Logo Url","description":"A http or https Url to a jpg, jpeg or png image that neeeds to be downloaded and used as the Company Logo or a file Url to a local image on the file system that needs to be used as the Company Logo. This setting is currently available for boot to cloud shared pc mode only.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Personalization-csp/"],"categoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","categoryName":"Personalization","options":null},{"id":"vendor_msft_personalization_companyname","displayName":"Company Name","description":"The name of the company to be displayed on the sign-in screen. This setting is currently available for boot to cloud shared pc mode only.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Personalization-csp/"],"categoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","categoryName":"Personalization","options":null},{"id":"vendor_msft_personalization_desktopimageurl","displayName":"Desktop Image Url","description":"A http or https Url to a jpg, jpeg or png image that needs to be downloaded and used as the Desktop Image or a file Url to a local image on the file system that needs to be used as the Desktop Image.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Personalization-csp/"],"categoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","categoryName":"Personalization","options":null},{"id":"vendor_msft_personalization_lockscreenimageurl","displayName":"Lock Screen Image Url","description":"A http or https Url to a jpg, jpeg or png image that neeeds to be downloaded and used as the Lock Screen Image or a file Url to a local image on the file system that needs to be used as the Lock Screen Image.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Personalization-csp/"],"categoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","categoryName":"Personalization","options":null},{"id":"vendor_msft_sharedpc_accountmodel","displayName":"Account Model","description":"Configures which type of accounts are allowed to use the PC. Allowed values: 0 (only guest), 1 (domain-joined only), 2 (domain-joined and guest). If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_accountmodel_0","displayName":"Guest","description":"Only guest accounts are allowed.","helpText":null},{"id":"vendor_msft_sharedpc_accountmodel_1","displayName":"Domain","description":"Only domain-joined accounts are allowed.","helpText":null},{"id":"vendor_msft_sharedpc_accountmodel_2","displayName":"Guest and Domain","description":"Domain-joined and guest accounts are allowed.","helpText":null}]},{"id":"vendor_msft_sharedpc_deletionpolicy","displayName":"Deletion Policy","description":"Configures when accounts will be deleted. Allowed values: 0 (delete immediately), 1 (delete at disk space threshold), 2 (Delete at disk space threshold and inactive threshold). If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_deletionpolicy_0","displayName":"Delete immediately","description":"Delete immediately.","helpText":null},{"id":"vendor_msft_sharedpc_deletionpolicy_1","displayName":"Delete at disk space threshold","description":"Delete at disk space threshold","helpText":null},{"id":"vendor_msft_sharedpc_deletionpolicy_2","displayName":"Delete at disk space threshold and inactive threshold","description":"Delete at disk space threshold and inactive threshold","helpText":null}]},{"id":"vendor_msft_sharedpc_disklevelcaching","displayName":"Disk Level Caching","description":"Stop deleting accounts when available disk space reaches this threshold, given as percent of total disk capacity. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_diskleveldeletion","displayName":"Disk Level Deletion","description":"Accounts will start being deleted when available disk space falls below this threshold, given as percent of total disk capacity. Accounts that have been inactive the longest will be deleted first. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_enableaccountmanager","displayName":"Enable Account Manager","description":"Enable the account manager for shared PC mode. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_enableaccountmanager_false","displayName":"false","description":"False","helpText":null},{"id":"vendor_msft_sharedpc_enableaccountmanager_true","displayName":"true","description":"True","helpText":null}]},{"id":"vendor_msft_sharedpc_enablesharedpcmode","displayName":"Enable Shared PC Mode","description":"Setting this node to \"true\" triggers the action to configure a device to Shared PC mode.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_enablesharedpcmode_false","displayName":"false","description":"Not configured","helpText":null},{"id":"vendor_msft_sharedpc_enablesharedpcmode_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"vendor_msft_sharedpc_enablesharedpcmodewithonedrivesync","displayName":"Enable Shared PC Mode With One Drive Sync","description":"Setting this node to “1” triggers the action to configure a device to Shared PC mode with OneDrive sync turned on","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/SharedPC-csp/"],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_enablesharedpcmodewithonedrivesync_false","displayName":"Not configured","description":"Not configured","helpText":null},{"id":"vendor_msft_sharedpc_enablesharedpcmodewithonedrivesync_true","displayName":"Enabled","description":"Enabled","helpText":null}]},{"id":"vendor_msft_sharedpc_inactivethreshold","displayName":"Inactive Threshold","description":"Accounts will start being deleted when they have not been logged on during the specified period, given as number of days.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_kioskmodeaumid","displayName":"Kiosk Mode AUMID","description":"Specifies the AUMID of the app to use with assigned access. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_kioskmodeusertiledisplaytext","displayName":"Kiosk Mode User Tile Display Text","description":"Specifies the display text for the account shown on the sign-in screen which launches the app specified by KioskModeAUMID. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_maintenancestarttime","displayName":"Maintenance Start Time","description":"Daily start time of maintenance hour. Given in minutes from midnight. Default is 0 (12am). If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_maxpagefilesizemb","displayName":"Max Page File Size MB","description":"Maximum size of the paging file in MB. Applies only to systems with less than 32 GB storage and at least 3 GB of RAM. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/SharedPC-csp/"],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_sharedpc_restrictlocalstorage","displayName":"Restrict Local Storage","description":"Restricts the user from using local storage. This node is optional. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_restrictlocalstorage_false","displayName":"false","description":"False","helpText":null},{"id":"vendor_msft_sharedpc_restrictlocalstorage_true","displayName":"true","description":"True","helpText":null}]},{"id":"vendor_msft_sharedpc_setedupolicies","displayName":"Set Edu Policies","description":"Set a list of EDU policies.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_setedupolicies_false","displayName":"false","description":"Not configured","helpText":null},{"id":"vendor_msft_sharedpc_setedupolicies_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"vendor_msft_sharedpc_setpowerpolicies","displayName":"Set Power Policies","description":"Set a list of power policies. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_setpowerpolicies_false","displayName":"false","description":"Not configured","helpText":null},{"id":"vendor_msft_sharedpc_setpowerpolicies_true","displayName":"true","description":"Enabled","helpText":null}]},{"id":"vendor_msft_sharedpc_signinonresume","displayName":"Sign In On Resume","description":"Require signing in on waking up from sleep. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_signinonresume_false","displayName":"false","description":"False","helpText":null},{"id":"vendor_msft_sharedpc_signinonresume_true","displayName":"true","description":"True","helpText":null}]},{"id":"vendor_msft_sharedpc_sleeptimeout","displayName":"Sleep Timeout","description":"The amount of time before the PC sleeps, giving in seconds. 0 means the PC never sleeps. Default is 5 minutes. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/SharedPC-csp/"],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null},{"id":"vendor_msft_tenantlockdown_requirenetworkinoobe","displayName":"Require Network In OOBE (Device)","description":"true - Require network in OOBE, false - no network connection requirement in OOBE","helpText":null,"infoUrls":[],"categoryId":"c4ce54b8-e555-4447-9791-dd8e9dbb86b0","categoryName":"Tenant Lockdown","options":[{"id":"vendor_msft_tenantlockdown_requirenetworkinoobe_true","displayName":"true","description":null,"helpText":null},{"id":"vendor_msft_tenantlockdown_requirenetworkinoobe_false","displayName":"false","description":null,"helpText":null}]},{"id":"vendor_msft_windowslicensing_devicelicensingservice_licensetype","displayName":"License Type","description":"Get/Replace License Type: User Based License = 0, Device Based License = 1\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WindowsLicensing-csp/"],"categoryId":"f8a973d8-b5d6-4d3e-9e82-63f61107fd0c","categoryName":"Windows Licensing","options":[{"id":"vendor_msft_windowslicensing_devicelicensingservice_licensetype_0","displayName":"User Based License","description":"User Based License","helpText":null},{"id":"vendor_msft_windowslicensing_devicelicensingservice_licensetype_1","displayName":"Device Based License","description":"Device Based License","helpText":null}]},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}","displayName":" Connection Profile ID (Windows Insiders only)","description":"Unique identifier of a network preference policy. Unique ID is auto-generated.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":[],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_cellular_plmnid","displayName":"PLMNID (Windows Insiders only)","description":"5- or 6-digit string identifying a cellular network. It consists of the combination of Mobile Country Code (MCC) and Mobile Network Code (MNC). \r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_connectionprofileid","displayName":null,"description":null,"helpText":null,"infoUrls":[],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_priority","displayName":"Priority (Windows Insiders only)","description":"Priority of a policy compared to the others where 1 represents the highest priority. Thus, the smaller this value is, the higher preference this specific network will receive in establishing a data connection. \r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_stayconnected","displayName":"Stay Connected (Windows Insiders only)","description":"When set to 0: Default network discovery behavior is applied. When set to 1: Once connected, the device will always stay connected to this network. This means the device will not attempt to discover or switch to other higher priority networks until it first loses connectivity to this network.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":[{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_stayconnected_0","displayName":"Default network discovery behavior.","description":"Default network discovery behavior.","helpText":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_stayconnected_1","displayName":"Once connected to this network, try to stay connected.","description":"Once connected to this network, try to stay connected.","helpText":null}]},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_wirelesstype","displayName":"Wireless Type (Windows Insiders only)","description":"Type of wireless network (either Cellular or Wi-Fi). 0 represents Cellular, and 1 represents Wi-Fi. Currently only cellular is supported.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":[{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_wirelesstype_0","displayName":"Cellular","description":"Cellular","helpText":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_wirelesstype_1","displayName":"Wi- Fi","description":"Wi-Fi","helpText":null}]},{"id":"vendor_msft_wirelessnetworkpreference_isenabled","displayName":"Is Enabled (Windows Insiders only)","description":"It determines whether the wireless connectivity management policy is enabled or not.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":[{"id":"vendor_msft_wirelessnetworkpreference_isenabled_false","displayName":"Disable the wireless management policy.","description":"Disable the wireless management policy.","helpText":null},{"id":"vendor_msft_wirelessnetworkpreference_isenabled_true","displayName":"Enable the wireless management policy.","description":"Enable the wireless management policy.","helpText":null}]},{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_maxrescanintervalinseconds","displayName":"Max Rescan Interval In Seconds (Windows Insiders only)","description":"Maximum time (in seconds) from the point that no connection could be established using the permissible eSIM profiles on the device to the start of the next round of network discovery attempts. A smaller interval increases network discovery frequency and can decrease battery life significantly. A value of 0 means that the device is to pick a reasonable interval per its own discretion.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_networkdiscoveryoption","displayName":"Network Discovery Option (Windows Insiders only)","description":"Configures which approach should be used in the network discovery process. There are two possible values: (0) no network scan will be performed – rather, registration and connection will be attempted with each eSIM profile in descending order of preference; or (1) Network scan will be performed using the current active eSIM profile. This option works for modems that when performing a network scan show the complete list of available networks independently of which eSIM profile is active.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":[{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_networkdiscoveryoption_0","displayName":"No network scan will be performed -- rather, registration and connection will be attempted with each eSIM profile in descending order of preference.","description":"No network scan will be performed -- rather, registration and connection will be attempted with each eSIM profile in descending order of preference.","helpText":null},{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_networkdiscoveryoption_1","displayName":"Network scan will be performed using the current active eSIM profile.","description":"Network scan will be performed using the current active eSIM profile.","helpText":null}]},{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_preferredprofilewakeconnectiontimerinseconds","displayName":"Preferred Profile Wake Connection Timer In Seconds (Windows Insiders only)","description":"When the device is woken from sleep with the most-preferred profile already enabled, this value configures the amount of time (in seconds) before the agent will give up on waiting for connection re-establishment with the most-preferred profile and start network discovery.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_profileregistrationtimerinseconds","displayName":"Profile Registration Timer In Seconds (Windows Insiders only)","description":"When evaluating eSIM profiles for connectivity, this value configures the amount of time (in seconds) that the agent will wait for network registration before considering this profile unsatisfactory and moving on to the next one.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_screenoffdurationtotriggernetworkdiscoveryinminutes","displayName":"Screen Off Duration To Trigger Network Discovery In Minutes (Windows Insiders only)","description":"When the device experiences screen off and back on, this value configures the minimum duration (in minutes) of the screen off period that will trigger network discovery.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},{"id":"vendor_msft_wirelessnetworkpreference_prefercellularoverwifi","displayName":"Prefer Cellular Over Wi Fi (Windows Insiders only)","description":"It determines the order of preference between Wi-Fi and cellular networks. When the value is set to “False”, Wi-Fi is preferred over cellular. When the value is set to “True”, cellular is preferred over Wi-Fi. \r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":[{"id":"vendor_msft_wirelessnetworkpreference_prefercellularoverwifi_false","displayName":"Prefer Wi-Fi over Cellular.","description":"Prefer Wi-Fi over Cellular.","helpText":null},{"id":"vendor_msft_wirelessnetworkpreference_prefercellularoverwifi_true","displayName":"Prefer Cellular over Wi-Fi.","description":"Prefer Cellular over Wi-Fi.","helpText":null}]}] diff --git a/Config/openapi.json b/Config/openapi.json index e019e964185ff..6d83f1cc86524 100644 --- a/Config/openapi.json +++ b/Config/openapi.json @@ -7261,7 +7261,8 @@ "type": "string" }, "tenantFilter": { - "type": "string" + "type": "string", + "description": "User creation is single-tenant only. Without this guard an 'AllTenants' (or otherwise unresolvable) tenantFilter fails Get-AuthorisedRequest, the Graph write helpers return $null non-terminating, and the endpoint reports success while creating nothing." }, "usageLocation": { "$ref": "#/components/schemas/LabelValue" @@ -7400,6 +7401,9 @@ } } }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, "401": { "description": "Unauthorized - invalid or missing bearer token" }, @@ -11437,8 +11441,17 @@ "schema": { "type": "object", "properties": { + "SkipCache": { + "type": "string", + "description": "Re-run the check instead of serving the cached result." + }, "TenantId": { - "type": "string" + "type": "string", + "description": "The tenant to (re)check for the 'Tenants' type. Query or body, for the same reason as Type." + }, + "Type": { + "type": "string", + "description": "Which self-diagnostic to run: Permissions, Tenants or GDAP. Read from either the query string or the body: the UI calls this as a GET with ?Type=, while a POST dispatcher (the MCP gateway documents it as POST because it also reads a body field) delivers it in the body - reading only the query left both empty and returned an empty result for every Type." } } } @@ -11452,12 +11465,22 @@ "description": "Re-run the check instead of serving the cached result.", "required": false, "schema": { - "type": "boolean" + "type": "string" + } + }, + { + "name": "TenantId", + "in": "query", + "description": "The tenant to (re)check for the 'Tenants' type. Query or body, for the same reason as Type.", + "required": false, + "schema": { + "type": "string" } }, { "name": "Type", "in": "query", + "description": "Which self-diagnostic to run: Permissions, Tenants or GDAP. Read from either the query string or the body: the UI calls this as a GET with ?Type=, while a POST dispatcher (the MCP gateway documents it as POST because it also reads a body field) delivers it in the body - reading only the query left both empty and returned an empty result for every Type.", "required": false, "schema": { "type": "string", @@ -40583,6 +40606,9 @@ "type": "string", "x-cipp-field-source": "graph" }, + "lastSyncDateTime": { + "x-cipp-field-source": "backend" + }, "numberOfHoursFromLastSync": { "x-cipp-field-source": "backend" }, @@ -41383,6 +41409,67 @@ "x-cipp-role": "Exchange.Mailbox.Read" } }, + "/api/ListCAPolicyCoverage": { + "get": { + "summary": "ListCAPolicyCoverage", + "operationId": "ListCAPolicyCoverage", + "tags": [ + "Tenant > Conditional" + ], + "description": "Resolves identity assignment coverage for a single Conditional Access policy: which users\nare touched by includes or exclusions, their net status (covered or excluded), and why\n(users, transitive groups, roles, guests, special tokens). Does not evaluate apps,\nlocations, or sign-in what-if conditions.", + "parameters": [ + { + "name": "GUID", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + }, + { + "name": "id", + "in": "query", + "required": false, + "schema": { + "type": "string" + } + }, + { + "$ref": "#/components/parameters/tenantFilter" + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "$ref": "#/components/schemas/StandardResults" + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "Tenant.ConditionalAccess.Read" + } + }, "/api/ListCAtemplates": { "get": { "summary": "ListCAtemplates", @@ -45988,7 +46075,8 @@ "type": "string" }, "cmdParams": { - "type": "string" + "type": "object", + "description": "Parameters to splat onto the Exchange cmdlet, as an object of name/value pairs (e.g. { \"Identity\": \"user@contoso.com\" }). Cast to an object so the generated schema types cmdParams as an object rather than a string - a string-typed schema made the client reject an object body, leaving no way to pass parameters." }, "Compliance": { "type": "boolean" @@ -48955,6 +49043,168 @@ "x-cipp-role": "Tenant.Directory.Read" } }, + "/api/ListInstanceDiagnostics": { + "get": { + "summary": "ListInstanceDiagnostics", + "operationId": "ListInstanceDiagnostics", + "tags": [ + "CIPP > Settings" + ], + "description": "Self diagnostics for this instance. Checks turns the recorded InstanceHealth samples\ninto a pass/warn/fail list with a suggested fix per finding; Timeline returns the raw\nbuckets plus the restart and out-of-memory events, with the API clients that were\nbusiest in the hour leading up to each event. Requires SuperAdmin access.", + "parameters": [ + { + "name": "Action", + "in": "query", + "required": false, + "schema": { + "type": "string", + "enum": [ + "Checks", + "Timeline" + ] + } + }, + { + "name": "Hours", + "in": "query", + "required": false, + "schema": { + "type": "integer" + } + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Derived from the fields written into the storage table it reads. Fields taken from the storage writers may be omitted by this endpoint, and the response may carry computed fields not listed here.", + "properties": { + "BootTime": { + "x-cipp-field-source": "storage" + }, + "Bucket": { + "x-cipp-field-source": "storage" + }, + "EgressBytes": { + "x-cipp-field-source": "storage" + }, + "EgressBytesToday": { + "type": "integer", + "x-cipp-field-source": "storage" + }, + "EgressCapBytes": { + "x-cipp-field-source": "storage" + }, + "EgressRejectClients": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "EgressRejectCount": { + "type": "integer", + "x-cipp-field-source": "storage" + }, + "ErrCount": { + "type": "integer", + "x-cipp-field-source": "storage" + }, + "ETag": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "GapMinutes": { + "type": "integer", + "x-cipp-field-source": "storage" + }, + "GcHeapLimitMb": { + "type": "integer", + "x-cipp-field-source": "storage" + }, + "HeapMb": { + "type": "integer", + "x-cipp-field-source": "storage" + }, + "HeapMbLive": { + "type": "integer", + "x-cipp-field-source": "storage" + }, + "Kind": { + "x-cipp-field-source": "storage" + }, + "MaxLimiterWaitMs": { + "type": "integer", + "x-cipp-field-source": "storage" + }, + "OomCount": { + "type": "integer", + "x-cipp-field-source": "storage" + }, + "PartitionKey": { + "x-cipp-field-source": "storage" + }, + "PoolExhaustedCount": { + "type": "integer", + "x-cipp-field-source": "storage" + }, + "PreviousSample": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "RowKey": { + "x-cipp-field-source": "storage" + }, + "StalledRunCount": { + "type": "integer", + "x-cipp-field-source": "storage" + }, + "Timestamp": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "TopEndpointsMs": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "Version": { + "type": "string", + "x-cipp-field-source": "storage" + }, + "WatchdogCount": { + "type": "integer", + "x-cipp-field-source": "storage" + } + } + } + } + } + } + }, + "400": { + "description": "Bad request - missing required field or invalid input" + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "CIPP.SuperAdmin.Read", + "x-cipp-any-tenant": true + } + }, "/api/ListIntuneApprovalRequests": { "get": { "summary": "List Intune multi-admin approval requests", @@ -56853,7 +57103,7 @@ "tags": [ "Identity > Reports" ], - "description": "Lists recent sign-in log entries for a tenant, filterable by various criteria. Supports AllTenants queries.", + "description": "Lists recent sign-in log entries for a tenant, filterable by various criteria. Supports AllTenants queries.\n\nDeprecated: use ListGraphRequest with Endpoint=auditLogs/signIns instead, which supports $filter, $top,\n$orderby, and manualPagination with nextLink continuation. This endpoint returns at most one page of\nresults and will be removed in a future release.", "parameters": [ { "name": "Days", @@ -60511,6 +60761,7 @@ { "name": "category", "in": "query", + "description": "Restrict to a single category (the framework/area name a test belongs to).", "required": false, "schema": { "type": "string" @@ -60519,6 +60770,7 @@ { "name": "countsOnly", "in": "query", + "description": "'true' to return only the aggregate counts with no rows. Implies includeCounts.", "required": false, "schema": { "type": "string" @@ -60527,6 +60779,7 @@ { "name": "includeCounts", "in": "query", + "description": "'true' to also return aggregate counts (per status, high-risk failures, distinct tenants).", "required": false, "schema": { "type": "string" @@ -60535,6 +60788,7 @@ { "name": "risk", "in": "query", + "description": "Restrict to a single risk level: High, Medium or Low.", "required": false, "schema": { "type": "string" @@ -60543,6 +60797,7 @@ { "name": "rowStatus", "in": "query", + "description": "Return rows only for these statuses, while still counting every status the filters match.", "required": false, "schema": { "type": "string" @@ -60551,6 +60806,7 @@ { "name": "status", "in": "query", + "description": "Narrow the scan to these statuses: Passed, Failed, Investigate, Skipped, Informational.", "required": false, "schema": { "type": "string" @@ -60559,6 +60815,7 @@ { "name": "summaryOnly", "in": "query", + "description": "'true' to project away the large ResultMarkdown/ResultDataJson blobs for a lighter read.", "required": false, "schema": { "type": "string" @@ -60567,6 +60824,7 @@ { "name": "tenantFilter", "in": "query", + "description": "One or more tenant domains to report on. Omit, or pass 'AllTenants', to query every tenant the caller may see. Accepts a string, a comma-delimited string, or an array.", "required": false, "schema": { "type": "string" @@ -60575,6 +60833,7 @@ { "name": "testId", "in": "query", + "description": "One or more test IDs (the result row's RowKey), e.g. 'CustomScript-'.", "required": false, "schema": { "type": "string" @@ -60583,6 +60842,7 @@ { "name": "testType", "in": "query", + "description": "Restrict to a single test type: Identity, Devices or Custom.", "required": false, "schema": { "type": "string" diff --git a/Config/standards.json b/Config/standards.json index c645548e7d22a..4653ad33f0aaa 100644 --- a/Config/standards.json +++ b/Config/standards.json @@ -1741,7 +1741,7 @@ "cat": "Entra (AAD) Standards", "tag": ["CIS M365 7.0.0 (1.3.4)", "SMB1001 (2.8)"], "appliesToTest": ["CIS_1_3_4", "EIDSCAAP05", "SMB1001_2_8"], - "helpText": "**Requires 'Billing Administrator' GDAP role.** This standard disables all self service licenses and enables all exclusions", + "helpText": "This standard disables all self service licenses and enables all exclusions", "executiveText": "Prevents employees from purchasing Microsoft 365 licenses independently, ensuring all software acquisitions go through proper procurement channels. This maintains budget control, prevents unauthorized spending, and ensures compliance with corporate licensing agreements.", "addedComponent": [ { @@ -1760,7 +1760,7 @@ "impact": "Medium Impact", "impactColour": "warning", "addedDate": "2021-11-16", - "powershellEquivalent": "Set-MsolCompanySettings -AllowAdHocSubscriptions $false", + "powershellEquivalent": "Update-MSCommerceProductPolicy -PolicyId AllowSelfServicePurchase -Value Disabled", "recommendedBy": [] }, { @@ -1768,8 +1768,9 @@ "cat": "Entra (AAD) Standards", "tag": ["SMB1001 (2.8)"], "appliesToTest": ["SMB1001_2_8", "ZTNA21858"], - "helpText": "Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone.", - "executiveText": "Automatically disables external guest accounts that haven't been used for a number of days, reducing security risks from dormant accounts while maintaining access for active external collaborators. This helps maintain a clean user directory and reduces potential attack vectors.", + "helpText": "Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Optionally soft-deletes already-disabled guests after a configurable grace period past that threshold (0 = never delete). Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone. Deleted guests remain recoverable from Deleted Items for about 30 days.", + "docsDescription": "Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Remediation first disables stale enabled guests, and later soft-deletes guests that are already disabled once they have been inactive for the disable threshold plus the configured grace delta (deletion age = days + deleteGraceDays). The disable-before-delete grace is further guaranteed by never deleting a guest in the same pass it was disabled. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone. Graph user DELETE is a soft-delete (recoverable from Deleted Items for about 30 days), which lets a later re-invite create a clean guest object instead of colliding with a disabled account.", + "executiveText": "Automatically disables external guest accounts that haven't been used for a number of days, and can optionally remove already-disabled dormant guests after an additional grace period. This reduces security risks from abandoned external access, keeps the directory clean, and avoids errors when previously disabled guests need to be invited back.", "addedComponent": [ { "type": "number", @@ -1778,6 +1779,15 @@ "defaultValue": 90, "label": "Days of inactivity" }, + { + "type": "number", + "name": "standards.DisableGuests.deleteGraceDays", + "label": "Grace days after disable before deletion (0 = never delete). Guests are deleted once inactive for the disable threshold plus this many additional days.", + "defaultValue": 0, + "validators": { + "min": { "value": 0, "message": "Minimum value is 0" } + } + }, { "type": "switch", "name": "standards.DisableGuests.IncludeNeverSignedIn", @@ -1786,8 +1796,8 @@ } ], "label": "Disable Guest accounts that have not logged on for a number of days", - "impact": "Medium Impact", - "impactColour": "warning", + "impact": "High Impact", + "impactColour": "danger", "addedDate": "2022-10-20", "powershellEquivalent": "Graph API", "recommendedBy": ["CIS", "CIPP"], diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecScheduledCommand.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecScheduledCommand.ps1 index 76642ac56c520..6c37665b867de 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecScheduledCommand.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Push-ExecScheduledCommand.ps1 @@ -4,6 +4,22 @@ function Push-ExecScheduledCommand { Entrypoint #> param($Item) + + function Write-CippResultLog { + param([string]$Prefix, $Value, [int]$MaxItems = 25, [int]$MaxChars = 4096) + $Items = @($Value) + $ToLog = $Value + $Suffix = '' + if ($Items.Count -gt $MaxItems) { + $ToLog = $Items[0..($MaxItems - 1)] + $Suffix = " ...[$($Items.Count) items total, first $MaxItems logged]" + } + try { $Json = $ToLog | ConvertTo-Json -Depth 10 -Compress } catch { $Json = "$ToLog" } + if (-not $Json) { $Json = '' } + if ($Json.Length -gt $MaxChars) { $Json = $Json.Substring(0, $MaxChars) + '...[truncated]' } + Write-Information "${Prefix}: $Json$Suffix" + } + $item = $Item | ConvertTo-Json -Depth 100 | ConvertFrom-Json Write-Information "We are going to be running a scheduled task: $($Item.TaskInfo | ConvertTo-Json -Depth 10)" @@ -293,7 +309,7 @@ function Push-ExecScheduledCommand { try { Write-Information "Executing command $($Item.Command) for individual matched data item with parameters: $($individualCommandParameters | ConvertTo-Json -Depth 10)" & $Item.Command @individualCommandParameters - Write-Information "Results for individual execution: $($results | ConvertTo-Json -Depth 10)" + Write-CippResultLog -Prefix 'Results for individual execution' -Value $results } catch { Write-Information "Failed to execute command for individual matched data item: $($_.Exception.Message)" } @@ -328,7 +344,7 @@ function Push-ExecScheduledCommand { $results = $results.Results } - Write-Information "Results: $($results | ConvertTo-Json -Depth 10)" + Write-CippResultLog -Prefix 'Results' -Value $results if ($item.command -like 'Get-CIPPAlert*') { Write-Information 'This is an alert task. Processing results as alerts.' $results = @($results) @@ -350,7 +366,7 @@ function Push-ExecScheduledCommand { @{ Results = $Message } } } - Write-Information "Results after processing: $($results | ConvertTo-Json -Depth 10)" + Write-CippResultLog -Prefix 'Results after processing' -Value $results Write-Information 'Moving onto storing results' if ($results -is [string]) { $StoredResults = $results @@ -359,7 +375,7 @@ function Push-ExecScheduledCommand { $StoredResults = $results | ConvertTo-Json -Compress -Depth 20 | Out-String } } - Write-Information "Results: $($results | ConvertTo-Json -Depth 10)" + Write-CippResultLog -Prefix 'Results' -Value $results if ($StoredResults.Length -gt 64000 -or $IsMultiTenantTask) { $TaskResultsTable = Get-CippTable -tablename 'ScheduledTaskResults' $TaskResults = @{ diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/SharePoint Permissions/Push-StoreSharePointPermissions.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/SharePoint Permissions/Push-StoreSharePointPermissions.ps1 index 8b00f6c888832..c50052e0c7bc0 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/SharePoint Permissions/Push-StoreSharePointPermissions.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/SharePoint Permissions/Push-StoreSharePointPermissions.ps1 @@ -8,15 +8,27 @@ function Push-StoreSharePointPermissions { flattens their Site and Assignment rows into a single row set, and writes SharePointPermissions once via Add-CIPPDbItem. - Completeness guard: if the number of site results does not match ExpectedSiteCount the - function throws without writing. The cache is written in replace mode, so writing a partial - set would silently discard every site the failed batches were responsible for. - - Merge-on-Skip: when a site returns Skipped, its rows are restored from the existing cache - (matched on siteId) so a transient SPO failure does not erase permission data that was - collected successfully on an earlier run. A Skipped site with no prior rows keeps just its - Site row, which carries collectionStatus and the error - the report can then say the site - could not be scanned rather than implying it has no permissions. + Partial-run tolerance: on a large tenant a whole batch can fail to return (throttling, + timeout, worker reclaim), dropping its ~20 sites from the fan-in. Rather than discard the + entire run, the sites that WERE collected are written fresh and every expected site that did + not come back is carried over from the prior cache and flagged Skipped - the same treatment a + per-site Skip already gets. This keeps the report (and its -Count row's timestamp) alive + across the common case of one flaky batch instead of letting the whole cache expire under the + 30-day reporting retention. ExpectedSiteIds - passed by Set-CIPPDBCacheSharePointPermissions - + is what lets a site whose batch failed (carry it over) be told apart from a site that no + longer exists (let it fall out). An older in-flight orchestration queued before that parameter + existed falls back to the previous all-or-nothing behaviour, because without the id set a + short result set cannot be reconciled safely. + + No-progress guard: the write only happens when at least one site was actually collected this + run. A run where nothing came back leaves the prior cache untouched - it is NOT rewritten with + fresh timestamps (which would launder stale data past the retention window) and its -Count row + is not restamped - so genuinely stale data still ages out and expires honestly. + + Memory: rows are streamed into a single Add-CIPPDbItem invocation (one invocation keeps its + RunId-based orphan cleanup authoritative) and each site's collected rows are released as they + are written, and the prior cache is read one site at a time (by RowKey prefix) only for the + sites being restored - a 100k-assignment tenant OOMs the worker here otherwise. Row types written (see Push-DBCacheSharePointPermissionsBatch for the full schema): - rowType 'Site' one per site, always present, carries collectionStatus and library counts @@ -30,6 +42,11 @@ function Push-StoreSharePointPermissions { $TenantFilter = $Item.Parameters.TenantFilter $ExpectedSiteCount = [int]$Item.Parameters.ExpectedSiteCount + # The full expected site-id set, when the collector passed it. Present -> a site that is expected + # but absent from the results is a failed batch (carry it over); one not in the set no longer + # exists (drop it). Older orchestrations predate this parameter; see the fallback below. + $ExpectedSiteIds = @($Item.Parameters.ExpectedSiteIds | Where-Object { $_ }) + $HaveExpectedIds = $ExpectedSiteIds.Count -gt 0 try { $SiteResults = [System.Collections.Generic.List[object]]::new() @@ -40,53 +57,137 @@ function Push-StoreSharePointPermissions { } $ActualCount = $SiteResults.Count - if ($ActualCount -ne $ExpectedSiteCount) { - throw "SharePoint permissions completeness check failed for $TenantFilter : expected $ExpectedSiteCount site results, got $ActualCount" - } - - # Restore rows for sites that could not be collected this run. - $SkippedResults = @($SiteResults | Where-Object { $_.CollectionStatus -eq 'Skipped' }) - $MergedCount = 0 - $PriorRowsBySiteId = @{} - if ($SkippedResults.Count -gt 0) { - foreach ($Existing in @(New-CIPPDbRequest -TenantFilter $TenantFilter -Type 'SharePointPermissions')) { - if ($Existing.rowType -ne 'Assignment') { continue } - $Key = [string]$Existing.siteId - if (-not $Key) { continue } - if (-not $PriorRowsBySiteId.ContainsKey($Key)) { - $PriorRowsBySiteId[$Key] = [System.Collections.Generic.List[object]]::new() - } - $PriorRowsBySiteId[$Key].Add($Existing) + $ReturnedIds = [System.Collections.Generic.HashSet[string]]::new([System.StringComparer]::OrdinalIgnoreCase) + $SkippedIds = [System.Collections.Generic.List[string]]::new() + $CollectedCount = 0 + foreach ($SiteResult in $SiteResults) { + $null = $ReturnedIds.Add([string]$SiteResult.SiteId) + if ($SiteResult.CollectionStatus -eq 'Skipped') { + $SkippedIds.Add([string]$SiteResult.SiteId) + } else { + $CollectedCount++ } } - $AllRows = [System.Collections.Generic.List[object]]::new() - foreach ($SiteResult in $SiteResults) { - if ($SiteResult.SiteRow) { $AllRows.Add($SiteResult.SiteRow) } + # Nothing collected this run. Leave the prior cache untouched rather than restamp it with + # fresh timestamps (which would hide stale data from the retention window) or write a fresh + # -Count row over data we did not refresh. + if ($CollectedCount -eq 0) { + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "SharePoint permissions: no sites collected this run for $TenantFilter (expected $ExpectedSiteCount, returned $ActualCount); prior cache left untouched" -sev Error + return + } - if ($SiteResult.CollectionStatus -eq 'Skipped') { - $Key = [string]$SiteResult.SiteId - if ($Key -and $PriorRowsBySiteId.ContainsKey($Key)) { - foreach ($Row in $PriorRowsBySiteId[$Key]) { $AllRows.Add($Row) } - $MergedCount++ - } - continue + # Expected sites that no batch returned a result for (the batch failed/was reclaimed). + $MissingIds = [System.Collections.Generic.List[string]]::new() + if ($HaveExpectedIds) { + foreach ($Id in $ExpectedSiteIds) { + if (-not $ReturnedIds.Contains([string]$Id)) { $MissingIds.Add([string]$Id) } } + } elseif ($ActualCount -ne $ExpectedSiteCount) { + # No expected-id set to reconcile against (pre-upgrade orchestration): a partial set can't + # be told from deletions, and writing it would let replace-mode orphan cleanup delete the + # missing sites' rows. Preserve the prior cache and wait for a complete run, as before. + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "SharePoint permissions: incomplete result set for $TenantFilter (expected $ExpectedSiteCount, got $ActualCount) with no expected-site list to reconcile; prior cache left untouched" -sev Warning + return + } - foreach ($Row in @($SiteResult.Rows)) { - if ($Row) { $AllRows.Add($Row) } + # Sites whose assignment rows must be restored from the prior cache: those that came back + # Skipped, plus those that did not come back at all. Read each one on its own by RowKey prefix + # so peak memory tracks the restore set, not the whole tenant. + $RestoreIds = [System.Collections.Generic.List[string]]::new() + foreach ($Id in $SkippedIds) { $RestoreIds.Add([string]$Id) } + foreach ($Id in $MissingIds) { $RestoreIds.Add([string]$Id) } + + $PriorAssignmentsBySiteId = @{} + $PriorSiteRowBySiteId = @{} + if ($RestoreIds.Count -gt 0) { + # Resolve the partition key exactly as Add-CIPPDbItem does so the read and the write agree. + $DbTenant = $TenantFilter + if ($TenantFilter -match '^[0-9a-f]{8}-([0-9a-f]{4}-){3}[0-9a-f]{12}$') { + try { + $Lookup = @(Get-Tenants -TenantFilter $TenantFilter -IncludeErrors) + if ($Lookup.Count -gt 0) { $DbTenant = $Lookup[0].defaultDomainName } + } catch {} + } + $PartEsc = $DbTenant -replace "'", "''" + $Table = Get-CippTable -tablename 'CippReportingDB' + foreach ($Id in $RestoreIds) { + $Key = [string]$Id + # Match Add-CIPPDbItem's path-character RowKey sanitisation so the prefix lines up with + # stored keys (site ids are otherwise clean ASCII). Every row for a site is keyed + # 'SharePointPermissions-_...', so that prefix returns exactly this site's Site + # and Assignment rows and nothing else. + $SafeId = $Key -replace '[/\\#?]', '_' + $Prefix = "SharePointPermissions-${SafeId}_" + $PrefixEsc = $Prefix -replace "'", "''" + $Filter = "PartitionKey eq '$PartEsc' and RowKey ge '$PrefixEsc' and RowKey lt '${PrefixEsc}~'" + $PriorRows = try { @(Get-CIPPAzDataTableEntity @Table -Filter $Filter) } catch { @() } + foreach ($Row in $PriorRows) { + if ([string]::IsNullOrWhiteSpace($Row.Data)) { continue } + $Parsed = try { $Row.Data | ConvertFrom-Json -ErrorAction Stop } catch { $null } + if (-not $Parsed) { continue } + if ($Parsed.rowType -eq 'Assignment') { + if (-not $PriorAssignmentsBySiteId.ContainsKey($Key)) { + $PriorAssignmentsBySiteId[$Key] = [System.Collections.Generic.List[object]]::new() + } + $PriorAssignmentsBySiteId[$Key].Add($Parsed) + } elseif ($Parsed.rowType -eq 'Site' -and -not $PriorSiteRowBySiteId.ContainsKey($Key)) { + $PriorSiteRowBySiteId[$Key] = $Parsed + } + } } } - if ($SkippedResults.Count -gt 0) { - $RemainingSkipped = $SkippedResults.Count - $MergedCount - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "SharePoint permissions: $($SkippedResults.Count) of $ActualCount sites returned Skipped from collection; restored $MergedCount from prior cache; $RemainingSkipped have no permission rows" -sev Warning - } + # Stream rows into one Add-CIPPDbItem invocation and release each site's collected rows as + # they are written, so the freshly-collected set is not held in memory beside the write. + $Stats = @{ Assignments = 0 } + & { + foreach ($SiteResult in $SiteResults) { + if ($SiteResult.SiteRow) { $SiteResult.SiteRow } + + if ($SiteResult.CollectionStatus -eq 'Skipped') { + $Key = [string]$SiteResult.SiteId + if ($PriorAssignmentsBySiteId.ContainsKey($Key)) { + foreach ($Row in $PriorAssignmentsBySiteId[$Key]) { $Stats.Assignments++; $Row } + } + } else { + foreach ($Row in @($SiteResult.Rows)) { + if ($Row) { + if ($Row.rowType -eq 'Assignment') { $Stats.Assignments++ } + $Row + } + } + } + # Release this site's rows now the writer has them (best effort). + try { $SiteResult.Rows = $null; $SiteResult.SiteRow = $null } catch {} + } - Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointPermissions' -Data @($AllRows) -AddCount + # Carry over every expected site no batch returned. A synthetic Skipped site row keeps the + # site visible and flagged in the report; its prior assignment rows are restored. + foreach ($Id in $MissingIds) { + $Key = [string]$Id + $Prior = $PriorSiteRowBySiteId[$Key] + [PSCustomObject]@{ + rowType = 'Site' + id = "${Key}_site" + siteId = $Key + siteName = $Prior.siteName + siteUrl = $Prior.siteUrl + collectionStatus = 'Skipped' + collectionError = 'Site was not returned by its collection batch this run; prior permission data retained.' + librariesScanned = [int]($Prior.librariesScanned ?? 0) + librariesWithUniquePermissions = [int]($Prior.librariesWithUniquePermissions ?? 0) + collectedAt = $Prior.collectedAt + } + if ($PriorAssignmentsBySiteId.ContainsKey($Key)) { + foreach ($Row in $PriorAssignmentsBySiteId[$Key]) { $Stats.Assignments++; $Row } + } + } + } | Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'SharePointPermissions' -AddCount - $AssignmentCount = @($AllRows | Where-Object { $_.rowType -eq 'Assignment' }).Count - Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $AssignmentCount SharePoint permission assignments across $ActualCount sites ($MergedCount merge-on-Skip) from $(@($Item.Results).Count) batches" -sev Info + $RestoredSites = $PriorAssignmentsBySiteId.Keys.Count + $Sev = if ($MissingIds.Count -gt 0 -or $SkippedIds.Count -gt 0) { 'Warning' } else { 'Info' } + Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message "Cached $($Stats.Assignments) SharePoint permission assignments for $TenantFilter : $CollectedCount of $ExpectedSiteCount sites collected, $($SkippedIds.Count) skipped, $($MissingIds.Count) missing (carried over), $RestoredSites restored from prior cache, from $(@($Item.Results).Count) batches" -sev $Sev return } catch { diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertUserReportedPhishing.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertUserReportedPhishing.ps1 index 60138097fc7b9..8a9a680f8401b 100644 --- a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertUserReportedPhishing.ps1 +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertUserReportedPhishing.ps1 @@ -18,7 +18,6 @@ function Get-CIPPAlertUserReportedPhishing { $Submissions = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/security/threatSubmission/emailThreats?`$filter=createdDateTime ge $Since" -tenantid $TenantFilter -AsApp $true $AlertData = foreach ($Submission in $Submissions) { - # Only include user-reported submissions if ($Submission.source -ne 'user') { continue } [PSCustomObject]@{ @@ -42,6 +41,11 @@ function Get-CIPPAlertUserReportedPhishing { } } catch { $ErrorMessage = Get-CippException -Exception $_ - Write-AlertMessage -message "User-reported phishing alert failed for $($TenantFilter): $($ErrorMessage.NormalizedError)" -tenant $TenantFilter -LogData $ErrorMessage + if ($ErrorMessage.NormalizedError -match 'dataservice\.protection\.outlook\.com' -or $ErrorMessage.NormalizedError -match 'No HTTP resource was found') { + $Message = "User-reported phishing alert skipped for $($TenantFilter): Exchange Online API unavailable in this tenant's region. Check tenant and EXO health." + } else { + $Message = "User-reported phishing alert failed for $($TenantFilter): $($ErrorMessage.NormalizedError)" + } + Write-AlertMessage -message $Message -tenant $TenantFilter -LogData $ErrorMessage } } diff --git a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertVulnerabilities.ps1 b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertVulnerabilities.ps1 index 598e84844b343..83dd5cce9310b 100644 --- a/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertVulnerabilities.ps1 +++ b/Modules/CIPPAlerts/Public/Alerts/Get-CIPPAlertVulnerabilities.ps1 @@ -43,14 +43,14 @@ function Get-CIPPAlertVulnerabilities { } try { - $VulnerabilityRequest = New-GraphGetRequest -tenantid $TenantFilter -uri 'https://api.securitycenter.microsoft.com/api/machines/SoftwareVulnerabilitiesByMachine' -scope 'https://api.securitycenter.microsoft.com/.default' + $VulnerabilityGroups = New-GraphGetRequest -tenantid $TenantFilter -uri 'https://api.securitycenter.microsoft.com/api/machines/SoftwareVulnerabilitiesByMachine' -scope 'https://api.securitycenter.microsoft.com/.default' | + Where-Object { $_.cveId } | + Select-Object cveId, vulnerabilitySeverityLevel, firstSeenTimestamp, lastSeenTimestamp, cvssScore, exploitabilityLevel, softwareName, softwareVendor, softwareVersion, recommendedSecurityUpdate, recommendedSecurityUpdateId, recommendedSecurityUpdateUrl, deviceName, deviceId, osPlatform, osVersion, osArchitecture | + Group-Object cveId - if ($VulnerabilityRequest) { + if ($VulnerabilityGroups) { $AlertData = [System.Collections.Generic.List[PSCustomObject]]::new() - # Group by CVE ID and create objects for each vulnerability - $VulnerabilityGroups = $VulnerabilityRequest | Where-Object { $_.cveId } | Group-Object cveId - foreach ($Group in $VulnerabilityGroups) { $FirstVuln = $Group.Group | Sort-Object firstSeenTimestamp | Select-Object -First 1 $HoursOld = [math]::Round(((Get-Date) - [datetime]$FirstVuln.firstSeenTimestamp).TotalHours) diff --git a/Modules/CIPPCore/CIPPCore.psm1 b/Modules/CIPPCore/CIPPCore.psm1 index 63d4384cb032c..615ea62d781be 100644 --- a/Modules/CIPPCore/CIPPCore.psm1 +++ b/Modules/CIPPCore/CIPPCore.psm1 @@ -1,14 +1,15 @@ # ModuleBuilder will concatenate all function files into this module # This block is only used when running from source (not built) -if (Test-Path (Join-Path $PSScriptRoot 'Public')) { - $Public = @(Get-ChildItem -Path (Join-Path $PSScriptRoot 'Public\*.ps1') -Recurse -ErrorAction SilentlyContinue) - foreach ($import in @($Public)) { - try { - . $import.FullName - } catch { - Write-Error -Message "Failed to import function $($import.FullName): $_" - } +$Public = @(Get-ChildItem -Path (Join-Path $PSScriptRoot "Public\*.ps1") -Recurse -ErrorAction SilentlyContinue) +$Private = @(Get-ChildItem -Path (Join-Path $PSScriptRoot "Private\*.ps1") -Recurse -ErrorAction SilentlyContinue) +$Functions = $Public + $Private +foreach ($import in @($Functions)) { + try { + . $import.FullName + } catch { + Write-Error -Message "Failed to import function $($import.FullName): $_" } - - Export-ModuleMember -Function $Public.BaseName } + +# Private functions are dot-sourced into module scope but never exported. +Export-ModuleMember -Function $Public.BaseName diff --git a/Modules/CIPPCore/Private/Authentication/Find-CippBaseRole.ps1 b/Modules/CIPPCore/Private/Authentication/Find-CippBaseRole.ps1 new file mode 100644 index 0000000000000..6b0ba74987ec8 --- /dev/null +++ b/Modules/CIPPCore/Private/Authentication/Find-CippBaseRole.ps1 @@ -0,0 +1,22 @@ +function Find-CippBaseRole { + <# + .SYNOPSIS + The base-role property matching any of the given role names. + .DESCRIPTION + Preserves the original loop semantics: base-role properties are walked in + definition order and a later match overwrites an earlier one. + .FUNCTIONALITY + Internal + #> + param($Roles, $BaseRoles) + $BaseRole = $null + foreach ($Role in $BaseRoles.PSObject.Properties) { + foreach ($CandidateRole in $Roles) { + if ($Role.Name -eq $CandidateRole) { + $BaseRole = $Role + break + } + } + } + return $BaseRole +} diff --git a/Modules/CIPPCore/Private/Authentication/Get-CippRequestIPAddress.ps1 b/Modules/CIPPCore/Private/Authentication/Get-CippRequestIPAddress.ps1 new file mode 100644 index 0000000000000..b1b83f7acd275 --- /dev/null +++ b/Modules/CIPPCore/Private/Authentication/Get-CippRequestIPAddress.ps1 @@ -0,0 +1,12 @@ +function Get-CippRequestIPAddress { + <# + .SYNOPSIS + First x-forwarded-for hop with any port suffix and IPv6 brackets stripped. + .FUNCTIONALITY + Internal + #> + param($Request) + $ForwardedFor = $Request.Headers.'x-forwarded-for' -split ',' | Select-Object -First 1 + $IPRegex = '^(?(?:\d{1,3}(?:\.\d{1,3}){3}|\[[0-9a-fA-F:]+\]|[0-9a-fA-F:]+))(?::\d+)?$' + return $ForwardedFor -replace $IPRegex, '$1' -replace '[\[\]]', '' +} diff --git a/Modules/CIPPCore/Private/Authentication/New-CippMeResponse.ps1 b/Modules/CIPPCore/Private/Authentication/New-CippMeResponse.ps1 new file mode 100644 index 0000000000000..78527507a07c3 --- /dev/null +++ b/Modules/CIPPCore/Private/Authentication/New-CippMeResponse.ps1 @@ -0,0 +1,160 @@ +function New-CippMeResponse { + <# + .SYNOPSIS + Builds the /me HTTP response for the user branch of Test-CIPPAccess. + + .DESCRIPTION + Extracted verbatim from Test-CIPPAccess. All request-scoped state arrives as + parameters — including the impersonation marker — so nothing here depends on + script scope crossing function boundaries. + + .PARAMETER User + Resolved (possibly impersonated) client principal. + + .PARAMETER IPAllowed + Result of the caller's IP-range check. /me is exempt from the IP throw but + reports the denial in its body instead. + + .PARAMETER IPAddress + Parsed request IP; only referenced in the IP-denial message. + + .PARAMETER Impersonation + The active impersonation object ($null when not impersonating). + + .PARAMETER AccessTimings + The caller's profiling hashtable; mutated by reference to record timings. + + .FUNCTIONALITY + Internal + #> + param( + $User, + $IPAllowed, + $IPAddress, + $Impersonation, + $AccessTimings + ) + + if (!$User.userRoles) { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = ( + @{ + 'clientPrincipal' = $null + 'permissions' = @() + } | ConvertTo-Json -Depth 5) + }) + } + + if (!$IPAllowed) { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = ( + @{ + 'clientPrincipal' = $null + 'permissions' = @() + 'message' = "Your IP address ($IPAddress) is not in the allowed range for your role(s)" + } | ConvertTo-Json -Depth 5) + }) + } + + $swPermsMe = [System.Diagnostics.Stopwatch]::StartNew() + $Permissions = Get-CippAllowedPermissions -UserRoles $User.userRoles + $swPermsMe.Stop() + $AccessTimings['GetPermissions(me)'] = $swPermsMe.Elapsed.TotalMilliseconds + + # Include SSO migration status for admins with AppSettings permissions + $MeResponse = @{ + 'clientPrincipal' = $User + 'permissions' = @($Permissions) + } + if ($Impersonation) { + # The frontend banner needs these to render the exit affordance even when + # the impersonated role has almost no permissions. + $MeResponse['impersonating'] = $Impersonation.Impersonating + $MeResponse['realUserRoles'] = @($Impersonation.RealRoles) + } + + # Hosted payment status checks — shown to all users (no permission gating) + if ($env:cipp_hosted_subscription_ended) { + $MeResponse['hostedSubscriptionEnded'] = $true + } + if ($env:cipp_hosted_failed_payments) { + $MeResponse['hostedFailedPayments'] = $true + } + # CyberDrain-hosted instance (CIPP_HOSTED is set by the hosted deployment templates). + # Lets the frontend point at the management portal for anything the instance's own + # identity cannot do, such as custom domains on the shared App Service plan. + $MeResponse['hosted'] = $env:CIPP_HOSTED -eq 'true' + # CIPP-NG (container web app on an App Service plan) versus a legacy function app plus + # static web app - the backend page shows different resources for each. + $MeResponse['ng'] = $env:CIPPNG -eq 'true' + + $CanManageAppSettings = $Permissions -contains 'CIPP.AppSettings.ReadWrite' + $HasAnyPermission = ($Permissions | Measure-Object).Count -gt 0 + + # Initial setup state: real (non-placeholder) SAM credentials loaded in this + # worker. Placeholder set matches Get-CIPPAuthentication/Initialize-CIPPAuth. + # The frontend blocks the whole UI behind the setup wizard until complete; + # samAppPresent distinguishes "no app registration at all" from "app exists + # but the refresh token is missing" so the wizard can offer a token reset. + $PlaceholderPattern = '^(LongApplicationId|AppSecret|RefreshToken|tenantId)$' + $TestSamCredentials = { + $HasAppId = [bool]($env:ApplicationID -and $env:ApplicationID -notmatch $PlaceholderPattern -and + $env:TenantID -and $env:TenantID -notmatch $PlaceholderPattern) + $HasRefreshToken = [bool]($env:RefreshToken -and $env:RefreshToken -notmatch $PlaceholderPattern) + @{ HasAppId = $HasAppId; Complete = ($HasAppId -and $HasRefreshToken) } + } + $SamState = & $TestSamCredentials + if (-not $SamState.Complete) { + # Env vars are per-worker and loaded at warmup, so setup completed on + # another worker leaves this one stale. Reload at most once per 30s per + # worker, tracked in an env var because runspaces don't share script + # scope, so an unconfigured instance doesn't hit storage on every poll. + $NowUnix = [DateTimeOffset]::UtcNow.ToUnixTimeSeconds() + $LastAttempt = [int64]0 + $null = [int64]::TryParse($env:CippMeAuthReloadAt, [ref]$LastAttempt) + if (($NowUnix - $LastAttempt) -ge 30) { + $env:CippMeAuthReloadAt = [string]$NowUnix + $null = Get-CIPPAuthentication + $SamState = & $TestSamCredentials + } + } + $MeResponse['initialSetupComplete'] = $SamState.Complete + $MeResponse['samAppPresent'] = $SamState.HasAppId + + # Forced SSO migration: non-dismissible prompt when migration env var is set. + # Suppressed until initial setup (SAM app) is complete — the setup wizard has + # to run first, and ExecSSOSetup needs the SAM app to create the CIPP-SSO + # registration. + $InitialSetupComplete = $SamState.Complete + if ($env:CIPP_SSO_MIGRATION_APPID -and $CanManageAppSettings -and $InitialSetupComplete) { + $MeResponse['forceSsoMigration'] = @{ + appId = $env:CIPP_SSO_MIGRATION_APPID + status = 'pending' + } + } + + if ($env:CIPPNG -ne 'true' -and $HasAnyPermission) { + try { + $SSOTable = Get-CIPPTable -tablename 'SSOMigration' + $SSOMigration = Get-CIPPAzDataTableEntity @SSOTable -Filter "PartitionKey eq 'SSO' and RowKey eq 'MigrationConfig'" -ErrorAction SilentlyContinue + if ($SSOMigration) { + $MeResponse['ssoMigration'] = @{ + status = $SSOMigration.Status + appId = $SSOMigration.AppId + multiTenant = [bool]($SSOMigration.MultiTenant -eq 'true' -or $SSOMigration.MultiTenant -eq 'True') + } + } else { + $MeResponse['ssoMigration'] = @{ status = 'none' } + } + } catch { + $MeResponse['ssoMigration'] = @{ status = 'none' } + } + } + + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = ($MeResponse | ConvertTo-Json -Depth 5) + }) +} diff --git a/Modules/CIPPCore/Public/Authentication/New-CIPPSSOApp.ps1 b/Modules/CIPPCore/Public/Authentication/New-CIPPSSOApp.ps1 index b2ba18288d3b6..04baa58f1430d 100644 --- a/Modules/CIPPCore/Public/Authentication/New-CIPPSSOApp.ps1 +++ b/Modules/CIPPCore/Public/Authentication/New-CIPPSSOApp.ps1 @@ -4,7 +4,7 @@ function New-CIPPSSOApp { Creates or updates the CIPP-SSO app registration for EasyAuth SSO migration. .DESCRIPTION Creates a new or updates an existing Entra ID app registration for CIPP-SSO with - openid, profile, and email delegated permissions. If ExistingAppId is provided, + openid, profile, email, and offline_access delegated permissions. If ExistingAppId is provided, looks up that specific app by clientId. If the app no longer exists in the tenant, creates a new one. Does NOT create a client secret — call Add-CIPPSSOAppSecret for that as a separate step so the AppId can be persisted before the (sometimes @@ -42,6 +42,7 @@ function New-CIPPSSOApp { @{ id = '37f7f235-527c-4136-accd-4a02d197296e'; type = 'Scope' } # openid @{ id = '14dad69e-099b-42c9-810b-d002981feec1'; type = 'Scope' } # profile @{ id = '64a6cdd6-aab1-4aaf-94b8-3cc8405e90d0'; type = 'Scope' } # email + @{ id = '7427e0e9-2fba-42fe-b0c0-848c9e6a8182'; type = 'Scope' } # offline_access ) # Look up existing app by stored AppId (not by name — supports multiple CIPP instances) diff --git a/Modules/CIPPCore/Public/Authentication/Test-CIPPAccess.ps1 b/Modules/CIPPCore/Public/Authentication/Test-CIPPAccess.ps1 index 876542e4f229c..2f0bd6d4083f1 100644 --- a/Modules/CIPPCore/Public/Authentication/Test-CIPPAccess.ps1 +++ b/Modules/CIPPCore/Public/Authentication/Test-CIPPAccess.ps1 @@ -75,9 +75,7 @@ function Test-CIPPAccess { $Type = 'APIClient' $swApiClient = [System.Diagnostics.Stopwatch]::StartNew() # Direct API Access - $ForwardedFor = $Request.Headers.'x-forwarded-for' -split ',' | Select-Object -First 1 - $IPRegex = '^(?(?:\d{1,3}(?:\.\d{1,3}){3}|\[[0-9a-fA-F:]+\]|[0-9a-fA-F:]+))(?::\d+)?$' - $IPAddress = $ForwardedFor -replace $IPRegex, '$1' -replace '[\[\]]', '' + $IPAddress = Get-CippRequestIPAddress -Request $Request $Client = Get-CippApiClient -AppId $Request.Headers.'x-ms-client-principal-name' if ($Client) { @@ -106,15 +104,7 @@ function Test-CIPPAccess { $_ } } - $BaseRole = $null - foreach ($Role in $script:CIPPBaseRoles.PSObject.Properties) { - foreach ($ClientRole in $Client.Role) { - if ($Role.Name -eq $ClientRole) { - $BaseRole = $Role - break - } - } - } + $BaseRole = Find-CippBaseRole -Roles $Client.Role -BaseRoles $script:CIPPBaseRoles } else { $CustomRoles = @('cipp-api') } @@ -184,9 +174,7 @@ function Test-CIPPAccess { $AllowedIPRanges = Get-CIPPRoleIPRanges -Roles $User.userRoles if ($AllowedIPRanges -notcontains 'Any') { - $ForwardedFor = $Request.Headers.'x-forwarded-for' -split ',' | Select-Object -First 1 - $IPRegex = '^(?(?:\d{1,3}(?:\.\d{1,3}){3}|\[[0-9a-fA-F:]+\]|[0-9a-fA-F:]+))(?::\d+)?$' - $IPAddress = $ForwardedFor -replace $IPRegex, '$1' -replace '[\[\]]', '' + $IPAddress = Get-CippRequestIPAddress -Request $Request if ($IPAddress) { $IPAllowed = $false foreach ($Range in $AllowedIPRanges) { @@ -224,129 +212,8 @@ function Test-CIPPAccess { } if ($Request.Params.CIPPEndpoint -eq 'me') { - - if (!$User.userRoles) { - return ([HttpResponseContext]@{ - StatusCode = [HttpStatusCode]::OK - Body = ( - @{ - 'clientPrincipal' = $null - 'permissions' = @() - } | ConvertTo-Json -Depth 5) - }) - } - - if (!$IPAllowed) { - return ([HttpResponseContext]@{ - StatusCode = [HttpStatusCode]::OK - Body = ( - @{ - 'clientPrincipal' = $null - 'permissions' = @() - 'message' = "Your IP address ($IPAddress) is not in the allowed range for your role(s)" - } | ConvertTo-Json -Depth 5) - }) - } - - $swPermsMe = [System.Diagnostics.Stopwatch]::StartNew() - $Permissions = Get-CippAllowedPermissions -UserRoles $User.userRoles - $swPermsMe.Stop() - $AccessTimings['GetPermissions(me)'] = $swPermsMe.Elapsed.TotalMilliseconds - - # Include SSO migration status for admins with AppSettings permissions - $MeResponse = @{ - 'clientPrincipal' = $User - 'permissions' = @($Permissions) - } - if ($script:CippImpersonation) { - # The frontend banner needs these to render the exit affordance even when - # the impersonated role has almost no permissions. - $MeResponse['impersonating'] = $script:CippImpersonation.Impersonating - $MeResponse['realUserRoles'] = @($script:CippImpersonation.RealRoles) - } - - # Hosted payment status checks — shown to all users (no permission gating) - if ($env:cipp_hosted_subscription_ended) { - $MeResponse['hostedSubscriptionEnded'] = $true - } - if ($env:cipp_hosted_failed_payments) { - $MeResponse['hostedFailedPayments'] = $true - } - # CyberDrain-hosted instance (CIPP_HOSTED is set by the hosted deployment templates). - # Lets the frontend point at the management portal for anything the instance's own - # identity cannot do, such as custom domains on the shared App Service plan. - $MeResponse['hosted'] = $env:CIPP_HOSTED -eq 'true' - # CIPP-NG (container web app on an App Service plan) versus a legacy function app plus - # static web app - the backend page shows different resources for each. - $MeResponse['ng'] = $env:CIPPNG -eq 'true' - - $CanManageAppSettings = $Permissions -contains 'CIPP.AppSettings.ReadWrite' - $HasAnyPermission = ($Permissions | Measure-Object).Count -gt 0 - - # Initial setup state: real (non-placeholder) SAM credentials loaded in this - # worker. Placeholder set matches Get-CIPPAuthentication/Initialize-CIPPAuth. - # The frontend blocks the whole UI behind the setup wizard until complete; - # samAppPresent distinguishes "no app registration at all" from "app exists - # but the refresh token is missing" so the wizard can offer a token reset. - $PlaceholderPattern = '^(LongApplicationId|AppSecret|RefreshToken|tenantId)$' - $TestSamCredentials = { - $HasAppId = [bool]($env:ApplicationID -and $env:ApplicationID -notmatch $PlaceholderPattern -and - $env:TenantID -and $env:TenantID -notmatch $PlaceholderPattern) - $HasRefreshToken = [bool]($env:RefreshToken -and $env:RefreshToken -notmatch $PlaceholderPattern) - @{ HasAppId = $HasAppId; Complete = ($HasAppId -and $HasRefreshToken) } - } - $SamState = & $TestSamCredentials - if (-not $SamState.Complete) { - # Env vars are per-worker and loaded at warmup, so setup completed on - # another worker leaves this one stale. Reload at most once per 30s per - # worker, tracked in an env var because runspaces don't share script - # scope, so an unconfigured instance doesn't hit storage on every poll. - $NowUnix = [DateTimeOffset]::UtcNow.ToUnixTimeSeconds() - $LastAttempt = [int64]0 - $null = [int64]::TryParse($env:CippMeAuthReloadAt, [ref]$LastAttempt) - if (($NowUnix - $LastAttempt) -ge 30) { - $env:CippMeAuthReloadAt = [string]$NowUnix - $null = Get-CIPPAuthentication - $SamState = & $TestSamCredentials - } - } - $MeResponse['initialSetupComplete'] = $SamState.Complete - $MeResponse['samAppPresent'] = $SamState.HasAppId - - # Forced SSO migration: non-dismissible prompt when migration env var is set. - # Suppressed until initial setup (SAM app) is complete — the setup wizard has - # to run first, and ExecSSOSetup needs the SAM app to create the CIPP-SSO - # registration. - $InitialSetupComplete = $SamState.Complete - if ($env:CIPP_SSO_MIGRATION_APPID -and $CanManageAppSettings -and $InitialSetupComplete) { - $MeResponse['forceSsoMigration'] = @{ - appId = $env:CIPP_SSO_MIGRATION_APPID - status = 'pending' - } - } - - if ($env:CIPPNG -ne 'true' -and $HasAnyPermission) { - try { - $SSOTable = Get-CIPPTable -tablename 'SSOMigration' - $SSOMigration = Get-CIPPAzDataTableEntity @SSOTable -Filter "PartitionKey eq 'SSO' and RowKey eq 'MigrationConfig'" -ErrorAction SilentlyContinue - if ($SSOMigration) { - $MeResponse['ssoMigration'] = @{ - status = $SSOMigration.Status - appId = $SSOMigration.AppId - multiTenant = [bool]($SSOMigration.MultiTenant -eq 'true' -or $SSOMigration.MultiTenant -eq 'True') - } - } else { - $MeResponse['ssoMigration'] = @{ status = 'none' } - } - } catch { - $MeResponse['ssoMigration'] = @{ status = 'none' } - } - } - - return ([HttpResponseContext]@{ - StatusCode = [HttpStatusCode]::OK - Body = ($MeResponse | ConvertTo-Json -Depth 5) - }) + # Impersonation marker passed explicitly rather than read from script scope inside the helper. + return (New-CippMeResponse -User $User -IPAllowed $IPAllowed -IPAddress $IPAddress -Impersonation $script:CippImpersonation -AccessTimings $AccessTimings) } if ($User.userRoles -contains 'admin' -or $User.userRoles -contains 'superadmin') { @@ -368,14 +235,7 @@ function Test-CIPPAccess { } elseif ($User.userRoles -contains 'admin') { $User.userRoles = @('admin') } - foreach ($Role in $script:CIPPBaseRoles.PSObject.Properties) { - foreach ($UserRole in $User.userRoles) { - if ($Role.Name -eq $UserRole) { - $BaseRole = $Role - break - } - } - } + $BaseRole = Find-CippBaseRole -Roles $User.userRoles -BaseRoles $script:CIPPBaseRoles } @@ -401,7 +261,6 @@ function Test-CIPPAccess { # Check custom role permissions for limitations on api calls or tenants if ($null -eq $BaseRole.Name -and $Type -eq 'User' -and ($CustomRoles | Measure-Object).Count -eq 0) { - Write-Information $BaseRole.Name throw 'Access to this CIPP API endpoint is not allowed, the user does not have the required permission' } elseif (($CustomRoles | Measure-Object).Count -gt 0) { if (@('admin', 'superadmin') -contains $BaseRole.Name) { @@ -477,16 +336,17 @@ function Test-CIPPAccess { # Tenant list and group list requests have already returned above, from the # cached scope rules. Everything from here is the per-endpoint access decision. # Resolve the target from the request only. Do not fall back to $env:TenantID — - # that is the partner/home tenant, not a customer. Missing/unmapped filters are - # unresolved: Test-CippRoleTenantScope returns $true (block fail-closed / allow quirk). + # that is the partner/home tenant, not a customer. A missing filter means the + # endpoint is not tenant-scoped; a filter that resolves to no known tenant is + # denied on the allow pass and stays in scope for the block pass. $TenantFilter = $Request.Query.tenantFilter ?? $Request.Body.tenantFilter.value ?? $Request.Body.tenantFilter ?? $Request.Query.tenantId ?? $Request.Body.tenantId.value ?? $Request.Body.tenantId $TenantAllowed = $false $APIAllowed = $false $swPermissionEval = [System.Diagnostics.Stopwatch]::StartNew() # Block pass: deny wins, but only when the blocking role also grants the - # permission and its tenant scope covers the target. Test-CippRoleTenantScope - # returns $true for missing/unmapped tenants — here that means fail closed (apply block). + # permission and its tenant scope covers the target. -TreatUnresolvedAsInScope + # keeps unresolved targets in scope so the deny still applies (fail closed). foreach ($Role in $PermissionSet) { $RoleGrantsPermission = $false foreach ($Perm in $Role.Permissions) { @@ -498,7 +358,7 @@ function Test-CIPPAccess { if (-not $RoleGrantsPermission) { continue } if ($Role.BlockedEndpoints -notcontains $Request.Params.CIPPEndpoint) { continue } - $BlockInScope = Test-CippRoleTenantScope -Role $Role -TenantFilter $TenantFilter -Tenants $Tenants -Request $Request -ApiRole $APIRole + $BlockInScope = Test-CippRoleTenantScope -Role $Role -TenantFilter $TenantFilter -Tenants $Tenants -Request $Request -ApiRole $APIRole -TreatUnresolvedAsInScope if ($BlockInScope) { throw "Access to this CIPP API endpoint is not allowed, the custom role '$($Role.Role)' has blocked this endpoint: $($Request.Params.CIPPEndpoint)" } @@ -538,19 +398,6 @@ function Test-CIPPAccess { } throw 'Access to this CIPP API endpoint is not allowed, the user does not have the required permission' } - - if (!$TenantAllowed -and $Functionality -notmatch 'AnyTenant') { - if (!$APIAllowed) { - throw "Access to this CIPP API endpoint is not allowed, you do not have the required permission: $APIRole" - } - if (!$TenantAllowed -and $Functionality -notmatch 'AnyTenant') { - Write-Information "Tenant not allowed: $TenantFilter" - - throw 'Access to this tenant is not allowed' - } else { - return $true - } - } } else { # No permissions found for any roles if ($TenantList.IsPresent) { @@ -558,8 +405,6 @@ function Test-CIPPAccess { } throw 'Access to this CIPP API endpoint is not allowed, the user does not have the required permission' } - $swUserBranch.Stop() - $AccessTimings['UserBranch'] = $swUserBranch.Elapsed.TotalMilliseconds } if ($TenantList.IsPresent) { diff --git a/Modules/CIPPCore/Public/Authentication/Test-CippRoleTenantScope.ps1 b/Modules/CIPPCore/Public/Authentication/Test-CippRoleTenantScope.ps1 index c72d3abe1ca41..a13843c8b3580 100644 --- a/Modules/CIPPCore/Public/Authentication/Test-CippRoleTenantScope.ps1 +++ b/Modules/CIPPCore/Public/Authentication/Test-CippRoleTenantScope.ps1 @@ -9,12 +9,12 @@ function Test-CippRoleTenantScope { group-shaped body authorized by group identity (no member expand), then allowed-minus-blocked after expanding tenant groups. - Unknown / missing / unmapped tenant filters return $true. Callers interpret that - differently: the allow path treats it as allow (legacy quirk); the - BlockedEndpoints pass treats it as in-scope so the deny still applies - (fail closed). Do not fall back to $env:TenantID — that is the partner - home tenant, not a customer. Do not "align" those call sites without an - explicit decision. + An empty tenant filter means the endpoint is not tenant-scoped, so every role + is in scope. A filter that is present but resolves to no known tenant is + denied, unless the caller passes -TreatUnresolvedAsInScope — the + BlockedEndpoints pass does, so its deny still applies to unresolved targets + (fail closed). Do not fall back to $env:TenantID — that is the partner home + tenant, not a customer. .PARAMETER Role Role permission object from Get-CIPPRolePermissions (AllowedTenants, BlockedTenants, ...). @@ -31,6 +31,11 @@ function Test-CippRoleTenantScope { .PARAMETER ApiRole Endpoint permission string; used for AllTenants Write$ / Read$ branches. + .PARAMETER TreatUnresolvedAsInScope + Keep a present-but-unresolvable tenant filter in scope instead of denying it. + Only the BlockedEndpoints pass sets this, so a block still applies when the + target cannot be resolved. + .OUTPUTS [bool] $true if the role's scope covers the target. @@ -57,7 +62,10 @@ function Test-CippRoleTenantScope { $Request, [Parameter(Mandatory = $true)] - [string]$ApiRole + [string]$ApiRole, + + [Parameter()] + [switch]$TreatUnresolvedAsInScope ) $Tenants = @($Tenants) @@ -127,6 +135,13 @@ function Test-CippRoleTenantScope { return ($AllowedTenants -contains $Tenant -and $ExpandedBlockedTenants -notcontains $Tenant) } - # Unmapped tenant filter: true for both call sites (allow quirk / block fail-closed). - return $true + # No filter (or an AllTenants request the ApiRole branches above did not handle): + # the request is not scoped to a resolvable single tenant, so the role is in scope. + if ([string]::IsNullOrWhiteSpace($TenantFilter) -or $TenantFilter -eq 'AllTenants') { + return $true + } + + # Filter present but resolves to no known tenant: denied, unless the caller opted + # into fail-closed block semantics. + return $TreatUnresolvedAsInScope.IsPresent } diff --git a/Modules/CIPPCore/Public/Authentication/Update-CIPPSSOPreconsent.ps1 b/Modules/CIPPCore/Public/Authentication/Update-CIPPSSOPreconsent.ps1 index bbbd94e609550..7977a85e65478 100644 --- a/Modules/CIPPCore/Public/Authentication/Update-CIPPSSOPreconsent.ps1 +++ b/Modules/CIPPCore/Public/Authentication/Update-CIPPSSOPreconsent.ps1 @@ -7,7 +7,7 @@ function Update-CIPPSSOPreconsent { .DESCRIPTION Reads the stored SSO AppId from Key Vault (or the DevSecrets table in dev mode) and ensures an AllPrincipals oauth2PermissionGrant exists for it against Microsoft Graph - covering the delegated scopes New-CIPPSSOApp requests (openid, profile, email). + covering the delegated scopes New-CIPPSSOApp requests (openid, profile, email, offline_access). Runs from warmup rather than at app-creation time: the service principal is not always queryable immediately after the app registration is created, so a create-time grant is @@ -25,7 +25,7 @@ function Update-CIPPSSOPreconsent { $GraphAppId = '00000003-0000-0000-c000-000000000000' # Keep in sync with the delegated permissions New-CIPPSSOApp requests. - $RequiredScopes = @('openid', 'profile', 'email') + $RequiredScopes = @('openid', 'profile', 'email', 'offline_access') $MigrationTable = Get-CIPPTable -TableName 'SSOMigration' $Existing = $null diff --git a/Modules/CIPPCore/Public/Authentication/Update-CIPPSSORedirectUri.ps1 b/Modules/CIPPCore/Public/Authentication/Update-CIPPSSORedirectUri.ps1 index 73fe4d0284856..363e32b57f68e 100644 --- a/Modules/CIPPCore/Public/Authentication/Update-CIPPSSORedirectUri.ps1 +++ b/Modules/CIPPCore/Public/Authentication/Update-CIPPSSORedirectUri.ps1 @@ -1,8 +1,9 @@ function Update-CIPPSSORedirectUri { <# .SYNOPSIS - Ensures the CIPP-SSO app registration includes redirect URIs for all bound hostnames - and that signInAudience matches the stored multi-tenant flag. + Ensures the CIPP-SSO app registration includes redirect URIs for all bound hostnames, + that signInAudience matches the stored multi-tenant flag, and that its delegated Graph + permissions include every scope CIPP-SSO requires. .DESCRIPTION Reads the stored SSO AppId and MultiTenant flag from Key Vault (or DevSecrets table @@ -11,8 +12,12 @@ function Update-CIPPSSORedirectUri { 2. Ensures the SSO app's web.redirectUris includes a callback URI for each hostname. 3. Verifies and patches signInAudience on the app reg if it doesn't match the stored multi-tenant flag (AzureADMyOrg for single-tenant, AzureADMultipleOrgs for multi). + 4. Ensures requiredResourceAccess declares the delegated Graph scopes New-CIPPSSOApp + requests (openid, profile, email, offline_access), backfilling any missing on an app + created before a scope was added to the default set. - Additive only — it never removes a URI, so a domain bound out-of-band keeps working. + Additive only — it never removes a URI or a permission, so a domain bound out-of-band + keeps working. .PARAMETER PassThru Emit a result object describing what happened. Off by default so warmup callers @@ -83,7 +88,7 @@ function Update-CIPPSSORedirectUri { } try { - $AppResponse = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/applications(appId='$SSOAppId')?`$select=id,web,signInAudience" -NoAuthCheck $true -AsApp $true + $AppResponse = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/applications(appId='$SSOAppId')?`$select=id,web,signInAudience,requiredResourceAccess" -NoAuthCheck $true -AsApp $true $ExistingUris = @($AppResponse.web.redirectUris) # Determine which URIs are missing @@ -93,8 +98,23 @@ function Update-CIPPSSORedirectUri { $ExpectedAudience = if ($SSOMultiTenant) { 'AzureADMultipleOrgs' } else { 'AzureADMyOrg' } $AudienceMismatch = $AppResponse.signInAudience -ne $ExpectedAudience - if ($MissingUris.Count -eq 0 -and -not $AudienceMismatch) { - Write-Information '[SSO-Redirect] All redirect URIs present and signInAudience correct' + # Determine which delegated Graph scopes the app registration is missing. Kept in sync + # with New-CIPPSSOApp's $Permissions - an app created before offline_access was added to + # the default set gets it backfilled here at warmup, so the Entra "API permissions" view + # and the admin-consent grant (Update-CIPPSSOPreconsent) stay consistent. Additive only. + $GraphResourceId = '00000003-0000-0000-c000-000000000000' + $DesiredScopeIds = @( + '37f7f235-527c-4136-accd-4a02d197296e' # openid + '14dad69e-099b-42c9-810b-d002981feec1' # profile + '64a6cdd6-aab1-4aaf-94b8-3cc8405e90d0' # email + '7427e0e9-2fba-42fe-b0c0-848c9e6a8182' # offline_access + ) + $GraphEntry = @($AppResponse.requiredResourceAccess) | Where-Object { $_.resourceAppId -eq $GraphResourceId } | Select-Object -First 1 + $GrantedScopeIds = @($GraphEntry.resourceAccess | Where-Object { $_.type -eq 'Scope' } | ForEach-Object { $_.id }) + $MissingScopeIds = @($DesiredScopeIds | Where-Object { $_ -notin $GrantedScopeIds }) + + if ($MissingUris.Count -eq 0 -and -not $AudienceMismatch -and $MissingScopeIds.Count -eq 0) { + Write-Information '[SSO-Redirect] All redirect URIs present, signInAudience correct, and required scopes declared' if ($HostnameState.Discovered) { & $Result 'nochange' $ExistingUris @() 'All sign-in URLs are already registered.' } else { @@ -132,6 +152,35 @@ function Update-CIPPSSORedirectUri { } } + # Backfill any missing delegated Graph scopes on the app registration. Patched separately + # from URIs/audience so a policy rejection here can't drop those additions. + if ($MissingScopeIds.Count -gt 0) { + try { + # Rebuild the Graph resourceAccess as the union of what's already declared and the + # missing scopes, so nothing already consented is dropped. + $MergedGraphAccess = [System.Collections.Generic.List[object]]::new() + foreach ($Access in @($GraphEntry.resourceAccess)) { $MergedGraphAccess.Add(@{ id = $Access.id; type = $Access.type }) } + foreach ($ScopeId in $MissingScopeIds) { $MergedGraphAccess.Add(@{ id = $ScopeId; type = 'Scope' }) } + + # Preserve any non-Graph resource entries untouched. + $NewResourceAccess = @( + @($AppResponse.requiredResourceAccess) | Where-Object { $_.resourceAppId -ne $GraphResourceId } | ForEach-Object { + @{ resourceAppId = $_.resourceAppId; resourceAccess = @($_.resourceAccess | ForEach-Object { @{ id = $_.id; type = $_.type } }) } + } + @{ resourceAppId = $GraphResourceId; resourceAccess = @($MergedGraphAccess) } + ) + + $PermsBody = @{ requiredResourceAccess = $NewResourceAccess } | ConvertTo-Json -Depth 6 + $null = New-GraphPOSTRequest -uri "https://graph.microsoft.com/v1.0/applications/$($AppResponse.id)" -body $PermsBody -type PATCH -NoAuthCheck $true -AsApp $true + Write-Information "[SSO-Redirect] Added missing delegated Graph scopes to app registration: $($MissingScopeIds -join ', ')" + Write-LogMessage -API 'SSO-Redirect' -message "Added missing delegated Graph scopes to CIPP-SSO app registration: $($MissingScopeIds -join ', ')" -sev Info + } catch { + # Non-fatal: sign-in and existing consent are unaffected. The admin-consent grant + # written by Update-CIPPSSOPreconsent is the load-bearing path for offline_access. + Write-Information "[SSO-Redirect] Could not update app registration permissions (non-fatal): $($_.Exception.Message)" + } + } + $Summary = if ($MissingUris.Count -gt 0) { "Registered $($MissingUris.Count) new sign-in URL(s)." } else { 'Sign-in URLs were already up to date.' } if ($HostnameState.Discovered) { & $Result 'updated' $UpdatedUris $MissingUris $Summary diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableGuestsState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableGuestsState.ps1 index 2408a4bc0cc53..6c89e8783ffbf 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableGuestsState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableGuestsState.ps1 @@ -1,17 +1,24 @@ function Get-CIPPBaselineDisableGuestsState { <# .SYNOPSIS - Prepare hook for DisableGuests: enabled guests with no sign-in attempt inside the window. + Prepare hook for DisableGuests: stale guests to disable and (optionally) already-disabled guests to delete. .DESCRIPTION Read live rather than from the Guests cache: that collector expands sponsors but does not select signInActivity, which decides the verdict here. Extending it would let this move to cache like the other user sweeps. + Produces TWO write sets, because the lifecycle is two-phase and deliberately so: + guestsToDisable - stale and still enabled. + guestsToDelete - already disabled AND past disable+grace days (only when deleteGraceDays > 0). + A guest is therefore never deleted in the same pass that disabled it; the disable is + the warning shot, and an admin has the delete delta to notice and re-enable. + A guest counts when the newest of its interactive, non-interactive and successful sign-in timestamps is older than the window - the same view the Entra portal and the inactive-guest alert give. Guests with no sign-in on record (typically invitations nobody redeemed) only count when IncludeNeverSignedIn is on; it is off by default and off when the template - predates it. Accounts an admin re-enabled in the last 7 days are left alone. + predates it. Accounts an admin re-enabled in the last 7 days are left alone on the disable set. + Missing/blank/0 deleteGraceDays leaves guestsToDelete empty so existing templates stay disable-only. .FUNCTIONALITY Internal #> @@ -23,17 +30,27 @@ function Get-CIPPBaselineDisableGuestsState { $CheckDays = if ([string]::IsNullOrWhiteSpace("$($Item.Variables.days)")) { 90 } else { [int]$Item.Variables.days } $IncludeNeverSignedIn = $Item.Variables.IncludeNeverSignedIn -eq $true + $DeleteDelta = if ([string]::IsNullOrWhiteSpace("$($Item.Variables.deleteGraceDays)")) { 0 } else { [int]$Item.Variables.deleteGraceDays } + if ($DeleteDelta -lt 0) { $DeleteDelta = 0 } + $DeleteEnabled = $DeleteDelta -gt 0 + $DeleteAge = $CheckDays + $DeleteDelta + $Cutoff = (Get-Date).AddDays(-$CheckDays).ToUniversalTime() $Lookup = $Cutoff.ToString('o') + $DeleteCutoff = (Get-Date).AddDays(-$DeleteAge).ToUniversalTime() + $DeleteLookup = $DeleteCutoff.ToString('o') + $GuestSelect = 'id,userPrincipalName,signInActivity,mail,userType,accountEnabled,createdDateTime' - $Guests = @(New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users?`$filter=createdDateTime le $Lookup and userType eq 'Guest' and accountEnabled eq true&`$select=id,userPrincipalName,signInActivity,mail,userType,accountEnabled,createdDateTime" -scope 'https://graph.microsoft.com/.default' -tenantid $TenantFilter) + $TestStale = { + param($Guest, $Window) + $LastSignIn = Get-CIPPLastSignInDateTime -SignInActivity $Guest.signInActivity + if ($LastSignIn) { $LastSignIn -le $Window } else { $IncludeNeverSignedIn } + } - $Stale = @($Guests | Where-Object { - $LastSignIn = Get-CIPPLastSignInDateTime -SignInActivity $_.signInActivity - if ($LastSignIn) { $LastSignIn -le $Cutoff } else { $IncludeNeverSignedIn } - }) + $EnabledGuests = @(New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users?`$filter=createdDateTime le $Lookup and userType eq 'Guest' and accountEnabled eq true&`$select=$GuestSelect" -scope 'https://graph.microsoft.com/.default' -tenantid $TenantFilter) + $ToDisable = @($EnabledGuests | Where-Object { & $TestStale $_ $Cutoff }) - if ($Stale.Count -gt 0) { + if ($ToDisable.Count -gt 0) { $AuditLookup = (Get-Date).AddDays(-7).ToUniversalTime().ToString('o') $Reactivated = @(try { $Audits = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/auditLogs/directoryAudits?`$filter=activityDisplayName eq 'Enable account' and activityDateTime ge $AuditLookup&`$select=targetResources" -scope 'https://graph.microsoft.com/.default' -tenantid $TenantFilter @@ -42,13 +59,19 @@ function Get-CIPPBaselineDisableGuestsState { Write-Information "Baselines: reactivation audit lookup on $TenantFilter failed: $($_.Exception.Message)" @() }) - $Stale = @($Stale | Where-Object { $Reactivated -notcontains $_.id }) + $ToDisable = @($ToDisable | Where-Object { $Reactivated -notcontains $_.id }) } + $ToDelete = @(if ($DeleteEnabled) { + $DisabledGuests = @(New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users?`$filter=createdDateTime le $DeleteLookup and userType eq 'Guest' and accountEnabled eq false&`$select=$GuestSelect" -scope 'https://graph.microsoft.com/.default' -tenantid $TenantFilter) + $DisabledGuests | Where-Object { & $TestStale $_ $DeleteCutoff } + }) + @{ Current = [PSCustomObject]@{ - offenders = @($Stale | ForEach-Object { "$($_.userPrincipalName ?? $_.mail)" } | Sort-Object) - targets = @($Stale | ForEach-Object { [PSCustomObject]@{ id = "$($_.id)" } }) + offenders = @(@($ToDisable | ForEach-Object { "Disable: $($_.userPrincipalName ?? $_.mail)" }) + @($ToDelete | ForEach-Object { "Delete: $($_.userPrincipalName ?? $_.mail)" }) | Sort-Object) + guestsToDisable = @($ToDisable | ForEach-Object { [PSCustomObject]@{ id = "$($_.id)" } }) + guestsToDelete = @($ToDelete | ForEach-Object { [PSCustomObject]@{ id = "$($_.id)" } }) } } } diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableSelfServiceLicensesState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableSelfServiceLicensesState.ps1 index 438257f6c0edd..6d80ac3420683 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableSelfServiceLicensesState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineDisableSelfServiceLicensesState.ps1 @@ -11,8 +11,8 @@ function Get-CIPPBaselineDisableSelfServiceLicensesState { The products and autoclaim live OUTSIDE Graph (licensing.m365.microsoft.com and admin.microsoft.com, each with its own token scope); the cache collector already - speaks both, and the products list requires the Billing Administrator GDAP role - - a 403 there parks the row at No Data rather than inventing a verdict. + speaks both - a failed product collection parks the row at No Data rather than + inventing a verdict. .FUNCTIONALITY Internal #> diff --git a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineDisableSelfServiceLicenses.ps1 b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineDisableSelfServiceLicenses.ps1 index 514d3709ba4f0..3156ee588f2e1 100644 --- a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineDisableSelfServiceLicenses.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineDisableSelfServiceLicenses.ps1 @@ -32,7 +32,7 @@ function Invoke-CIPPBaselineDisableSelfServiceLicenses { $null = New-GraphPostRequest -tenantid $TenantFilter -uri 'https://graph.microsoft.com/v1.0/policies/authorizationPolicy' -type PATCH -body '{"allowedToSignUpEmailBasedSubscriptions":false}' } else { $Body = @{ policyValue = "$($Item.policyValue)" } | ConvertTo-Json -Compress - $null = New-GraphPostRequest -scope 'aeb86249-8ea3-49e2-900b-54cc8e308f85/.default' -tenantid $TenantFilter -uri "https://licensing.m365.microsoft.com/v1.0/policies/AllowSelfServicePurchase/products/$Id" -type PUT -body $Body + $null = New-GraphPostRequest -scope 'aeb86249-8ea3-49e2-900b-54cc8e308f85/.default' -tenantid $TenantFilter -uri "https://licensing.m365.microsoft.com/v1.0/policies/AllowSelfServicePurchase/products/$Id" -type PUT -body $Body -AsApp $true } } catch { $Failures++ diff --git a/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-DomainOrchestrator.ps1 b/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-DomainOrchestrator.ps1 index db26487381b70..1257c7f5b74f4 100644 --- a/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-DomainOrchestrator.ps1 +++ b/Modules/CIPPCore/Public/Entrypoints/Orchestrator Functions/Start-DomainOrchestrator.ps1 @@ -8,35 +8,59 @@ function Start-DomainOrchestrator { Entrypoint #> [CmdletBinding(SupportsShouldProcess = $true)] - param($TenantFilter) + param( + $TenantFilter, + [switch]$SkipExchangeFilter + ) try { if ($TenantFilter -and $TenantFilter -ne 'allTenants') { - $TenantList = @($TenantFilter) - $TenantParams = @{ - TenantFilter = $TenantFilter + $Queue = New-CippQueueEntry -Name 'Domain Analyser' -TotalTasks 1 + $InputObject = [PSCustomObject]@{ + QueueFunction = [PSCustomObject]@{ + FunctionName = 'GetTenants' + DurableName = 'DomainAnalyserTenant' + QueueId = $Queue.RowKey + TenantParams = @{ + TenantFilter = $TenantFilter + } + } + OrchestratorName = 'DomainAnalyser_Tenants' + SkipLog = $true } } else { - $TenantList = Get-Tenants -IncludeAll - if (($TenantList | Measure-Object).Count -eq 0) { - Write-Information 'No tenants found' - return 0 + $TenantList = @(Get-Tenants) + if (-not $SkipExchangeFilter) { + $ExchangeCapabilities = @( + 'EXCHANGE_S_STANDARD', 'EXCHANGE_S_ENTERPRISE' + 'EXCHANGE_S_STANDARD_GOV', 'EXCHANGE_S_ENTERPRISE_GOV' + 'EXCHANGE_LITE' + 'EXCHANGE_S_DESKLESS', 'EXCHANGE_S_DESKLESS_GOV' + 'EXCHANGE_S_ESSENTIALS' + ) + $TenantList = @($TenantList | Where-Object { + Test-CIPPStandardLicense -StandardName 'DomainAnalyser' -TenantFilter $_.defaultDomainName -RequiredCapabilities $ExchangeCapabilities -SkipLog + }) } - $TenantParams = @{ - IncludeAll = $true + if ($TenantList.Count -eq 0) { + Write-Information 'No tenants to analyse' + return 0 } - } - $Queue = New-CippQueueEntry -Name 'Domain Analyser' -TotalTasks ($TenantList | Measure-Object).Count - $InputObject = [PSCustomObject]@{ - QueueFunction = [PSCustomObject]@{ - FunctionName = 'GetTenants' - DurableName = 'DomainAnalyserTenant' - QueueId = $Queue.RowKey - TenantParams = $TenantParams + $Queue = New-CippQueueEntry -Name 'Domain Analyser' -TotalTasks $TenantList.Count + $Batch = foreach ($Tenant in $TenantList) { + [PSCustomObject]@{ + customerId = $Tenant.customerId + FunctionName = 'DomainAnalyserTenant' + QueueId = $Queue.RowKey + QueueName = $Tenant.defaultDomainName + } + } + $InputObject = [PSCustomObject]@{ + Batch = @($Batch) + OrchestratorName = 'DomainAnalyser_Tenants' + SkipLog = $true } - OrchestratorName = 'DomainAnalyser_Tenants' - SkipLog = $true } if ($PSCmdlet.ShouldProcess('Domain Analyser', 'Starting Orchestrator')) { Write-LogMessage -API 'DomainAnalyser' -message 'Starting Domain Analyser' -sev Info diff --git a/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-InstanceHealthSample.ps1 b/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-InstanceHealthSample.ps1 new file mode 100644 index 0000000000000..faa86b4f47da5 --- /dev/null +++ b/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-InstanceHealthSample.ps1 @@ -0,0 +1,123 @@ +function Start-InstanceHealthSample { + <# + .SYNOPSIS + Timer function that records a 5 minute instance-health sample + .DESCRIPTION + Reduces the last five minutes of container log lines into one bucket row in the + InstanceHealth table, plus one row per API client seen in that window. The diagnostics + endpoint reads these rows instead of rescanning the log, so a self-diagnostics run stays + cheap and can look further back than the retained log files. + + The log bridge only exists inside the container host, so a missing bridge is logged and + skipped rather than failing the timer. + #> + [CmdletBinding(SupportsShouldProcess = $true)] + param() + + if (-not $PSCmdlet.ShouldProcess('Start-InstanceHealthSample', 'Record instance health sample')) { return } + + $Now = [DateTime]::UtcNow + # Bucket on the 5 minute floor so samples line up across restarts and nodes. + $Bucket = $Now.AddMinutes(-($Now.Minute % 5)).ToString('yyyy-MM-ddTHH:mm') + + try { + $Lines = [Craft.Services.LogBridge]::GetLogsSince($Now.AddMinutes(-5), $null, $null, $null) + } catch { + Write-Information "[InstanceHealth] Log bridge unavailable, skipping sample: $($_.Exception.Message)" + return + } + + try { + $Sample = Get-CIPPInstanceHealthSample -Lines @($Lines) + + # Live memory reading from the stats history, used as a floor when the log carried no + # heap sample. The reported GC limit is the real ceiling for the headroom check. + $HeapMbLive = $null + $GcHeapLimitMb = $null + try { + $Point = @([Craft.Services.StatsHistoryBridge]::GetHistory(5, 1)) | Select-Object -Last 1 + if ($Point) { + $HeapMbLive = [int][math]::Round([double]$Point.HeapMB) + if ([double]$Point.GCHeapLimitMB -gt 0) { $GcHeapLimitMb = [int][math]::Round([double]$Point.GCHeapLimitMB) } + } + } catch { + Write-Information "[InstanceHealth] Stats history unavailable: $($_.Exception.Message)" + } + + $Table = Get-CIPPTable -TableName 'InstanceHealth' + + # Egress ledger is instance-wide, Craft-owned, and only exists when accounting is on - + # a missing bridge or ledger means "no egress data", never a fake zero. + $Ledger = $null + try { + $Ledger = Get-CIPPEgressLedger -LogDirectory ([Craft.Services.LogBridge]::GetLogDirectory()) -Now $Now + } catch { + Write-Information "[InstanceHealth] Log bridge unavailable for egress ledger: $($_.Exception.Message)" + } + + # One fixed partition for the whole table so a window read is a single partition-scoped + # RowKey range instead of a cross-partition scan; the bucket lives in RowKey and Bucket. + $Entity = @{ + PartitionKey = 'InstanceHealth' + RowKey = "${Bucket}_sample" + Bucket = $Bucket + Kind = 'sample' + OomCount = [int]$Sample.OomCount + WatchdogCount = [int]$Sample.WatchdogCount + PoolExhaustedCount = [int]$Sample.PoolExhaustedCount + ErrCount = [int]$Sample.ErrCount + MaxLimiterWaitMs = [int]$Sample.MaxLimiterWaitMs + StalledRunCount = [int]$Sample.StalledRunCount + TopEndpointsMs = [string]($Sample.TopEndpointsMs | ConvertTo-Json -Compress) + } + # Nullable readings are omitted rather than stored as a sentinel, so "no reading" and + # "read zero" stay distinguishable. + if ($null -ne $Sample.HeapMb) { $Entity.HeapMb = [int]$Sample.HeapMb } + if ($null -ne $HeapMbLive) { $Entity.HeapMbLive = [int]$HeapMbLive } + if ($null -ne $GcHeapLimitMb) { $Entity.GcHeapLimitMb = [int]$GcHeapLimitMb } + if ($Sample.EgressRejectCount -gt 0) { $Entity.EgressRejectCount = [int]$Sample.EgressRejectCount } + if (@($Sample.EgressRejectClients).Count -gt 0) { $Entity.EgressRejectClients = [string]($Sample.EgressRejectClients | ConvertTo-Json -Compress) } + + if ($Ledger) { + $Entity.EgressBytesToday = [long]$Ledger.Bytes + + $Today = $Now.ToString('yyyy-MM-dd') + $PreviousSamples = @(Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'InstanceHealth' and RowKey ge '${Today}T00:00' and Kind eq 'sample'") + $PreviousWithEgress = $PreviousSamples | Where-Object { $null -ne $_.EgressBytesToday } | Sort-Object -Property Bucket -Descending | Select-Object -First 1 + + if ($PreviousWithEgress) { + $Delta = [long]$Ledger.Bytes - [long]$PreviousWithEgress.EgressBytesToday + if ($Delta -lt 0) { $Delta = 0 } + $Entity.EgressBytes = $Delta + } else { + # No earlier reading today: the ledger total is everything since the day (or accounting) began. + $Entity.EgressBytes = [long]$Ledger.Bytes + } + } + + if ($env:CRAFT_API_EGRESS_LIMIT_BYTES) { + $CapBytes = 0 + if ([long]::TryParse($env:CRAFT_API_EGRESS_LIMIT_BYTES, [ref]$CapBytes) -and $CapBytes -gt 0) { + $Entity.EgressCapBytes = $CapBytes + } + } + + Add-CIPPAzDataTableEntity @Table -Entity $Entity -Force | Out-Null + + foreach ($Client in $Sample.Clients) { + Add-CIPPAzDataTableEntity @Table -Entity @{ + PartitionKey = 'InstanceHealth' + RowKey = "${Bucket}_client_$($Client.AppId)" + Bucket = $Bucket + Kind = 'client' + AppId = [string]$Client.AppId + AppName = [string]$Client.AppName + IP = [string]$Client.IP + Count = [int]$Client.Count + } -Force | Out-Null + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API 'InstanceHealthSample' -message "Failed to record instance health sample: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + } +} diff --git a/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-TableCleanup.ps1 b/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-TableCleanup.ps1 index a91a6dc0a1464..30a7909022a9c 100644 --- a/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-TableCleanup.ps1 +++ b/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-TableCleanup.ps1 @@ -140,6 +140,18 @@ function Start-TableCleanup { Property = @('PartitionKey', 'RowKey', 'ETag') } } + @{ + # 5-minute instance health samples and boot markers. Two weeks covers the + # diagnostics window (max 14 days) with nothing left over. + FunctionName = 'TableCleanupTask' + Type = 'CleanupRule' + TableName = 'InstanceHealth' + DataTableProps = @{ + Filter = "PartitionKey eq 'InstanceHealth' and Timestamp lt datetime'$((Get-Date).AddDays(-14).ToUniversalTime().ToString('yyyy-MM-ddTHH:mm:ssZ'))'" + First = 10000 + Property = @('PartitionKey', 'RowKey', 'ETag') + } + } @{ FunctionName = 'TableCleanupTask' Type = 'DeleteTable' diff --git a/Modules/CIPPCore/Public/Functions/Get-CIPPEgressLedger.ps1 b/Modules/CIPPCore/Public/Functions/Get-CIPPEgressLedger.ps1 new file mode 100644 index 0000000000000..4abf5a963faa4 --- /dev/null +++ b/Modules/CIPPCore/Public/Functions/Get-CIPPEgressLedger.ps1 @@ -0,0 +1,44 @@ +function Get-CIPPEgressLedger { + <# + .SYNOPSIS + Reads today's API egress ledger written by Craft. + .DESCRIPTION + Craft flushes egress-ledger.json ({"DateUtc":"yyyy-MM-dd","Bytes":}) to its log + directory every 60s, only when egress accounting is enabled and at least one API-client + response has been served today. A missing file, a different UTC day, or unparsable JSON + all mean "no data for today" rather than an error, so this never throws. + .FUNCTIONALITY + Internal + .EXAMPLE + Get-CIPPEgressLedger -LogDirectory ([Craft.Services.LogBridge]::GetLogDirectory()) + #> + [CmdletBinding()] + param( + [Parameter(Mandatory = $true)] + [string]$LogDirectory, + + [DateTime]$Now = [DateTime]::UtcNow + ) + + $Path = Join-Path -Path $LogDirectory -ChildPath 'egress-ledger.json' + if (-not (Test-Path -Path $Path -PathType Leaf)) { return $null } + + try { + $Ledger = Get-Content -Path $Path -Raw -ErrorAction Stop | ConvertFrom-Json -ErrorAction Stop + } catch { + return $null + } + + if (-not $Ledger.DateUtc -or $Ledger.DateUtc -ne $Now.ToString('yyyy-MM-dd')) { return $null } + + try { + $Bytes = [long]$Ledger.Bytes + } catch { + return $null + } + + return [pscustomobject]@{ + DateUtc = [string]$Ledger.DateUtc + Bytes = $Bytes + } +} diff --git a/Modules/CIPPCore/Public/Functions/Get-CIPPInstanceHealthSample.ps1 b/Modules/CIPPCore/Public/Functions/Get-CIPPInstanceHealthSample.ps1 new file mode 100644 index 0000000000000..b950ba0d4446b --- /dev/null +++ b/Modules/CIPPCore/Public/Functions/Get-CIPPInstanceHealthSample.ps1 @@ -0,0 +1,119 @@ +function Get-CIPPInstanceHealthSample { + <# + .SYNOPSIS + Reduces a window of container log lines into a single instance-health sample. + .DESCRIPTION + Counts the failure signatures that matter for self diagnostics (out-of-memory kills, + watchdog restarts, HTTP pool exhaustion, stalled orchestrator runs) and extracts the + peak heap sample, the worst limiter wait, the slowest endpoints and the API clients + seen in the window. + + Pure text reduction with no I/O, so the timer that calls it can never fail on this + step and the thresholds stay unit-testable. + .FUNCTIONALITY + Internal + .EXAMPLE + Get-CIPPInstanceHealthSample -Lines ([Craft.Services.LogBridge]::GetLogsSince($From, $null, $null, $null)) + #> + [CmdletBinding()] + param( + [Parameter(Position = 0, ValueFromPipeline = $false)] + [AllowNull()] + [AllowEmptyCollection()] + [string[]]$Lines + ) + + $OomCount = 0 + $WatchdogCount = 0 + $PoolExhaustedCount = 0 + $ErrCount = 0 + $StalledRunCount = 0 + $MaxLimiterWaitMs = 0 + $HeapMb = $null + $EgressRejectCount = 0 + # Ordered HashSet-backed dedup - same client can be rejected many times per window. + $EgressRejectClients = [System.Collections.Generic.List[string]]::new() + $EgressRejectClientsSeen = [System.Collections.Generic.HashSet[string]]::new() + + $Endpoints = @{} + # Keyed on AppId - the same client can appear under several IPs, the last one wins. + $Clients = [ordered]@{} + + foreach ($Line in $Lines) { + if ([string]::IsNullOrWhiteSpace($Line)) { continue } + + if ($Line -match 'OutOfMemoryException') { $OomCount++ } + if ($Line -match 'Container startup attempt|Restart counter') { $WatchdogCount++ } + if ($Line -match 'HTTP pool exhausted') { $PoolExhaustedCount++ } + if ($Line -match '\[ERR\]') { $ErrCount++ } + if ($Line -match 'T\+([0-9]{2,})\.[0-9]+min: .* 0 running ([1-9][0-9]*) pending') { $StalledRunCount++ } + + if ($Line -match 'Egress cap reached') { + $EgressRejectCount++ + if ($Line -match '429 for (\S+) on' -and $EgressRejectClientsSeen.Add($Matches[1])) { + $EgressRejectClients.Add($Matches[1]) + } + } + + if ($Line -match 'Limiter slot acquired after (\d+)ms') { + $Wait = [int]$Matches[1] + if ($Wait -gt $MaxLimiterWaitMs) { $MaxLimiterWaitMs = $Wait } + } + + if ($Line -match 'heap=([0-9]+)MB') { + $Heap = [int]$Matches[1] + if ($null -eq $HeapMb -or $Heap -gt $HeapMb) { $HeapMb = $Heap } + } + + if ($Line -match '\[HTTP\]\s+\S+\s+(\S+)\s+\d{3}\s+(\d+)ms') { + $Function = $Matches[1] + $Ms = [int]$Matches[2] + $Endpoints[$Function] = [int]($Endpoints[$Function]) + $Ms + } + + # Access checks run more than once per request, so count unique request ids per + # client rather than lines. Lines without an id fall back to one count each. + if ($Line -match 'API Access: AppName=([^,]+), AppId=(\S+), IP=([0-9a-fA-F.:]*)') { + $AppName = $Matches[1] + $AppId = $Matches[2] + $IP = $Matches[3] + $RequestId = if ($Line -match '\[API\]\s+(\S+)\s+PS\b') { $Matches[1] } else { [guid]::NewGuid().ToString() } + if (-not $Clients.Contains($AppId)) { + $Clients[$AppId] = @{ + AppId = $AppId + AppName = $AppName + IP = $IP + Count = 0 + Requests = [System.Collections.Generic.HashSet[string]]::new() + } + } + if ($Clients[$AppId].Requests.Add($RequestId)) { $Clients[$AppId].Count++ } + $Clients[$AppId].IP = $IP + $Clients[$AppId].AppName = $AppName + } + } + + $TopEndpoints = @{} + foreach ($Entry in ($Endpoints.GetEnumerator() | Sort-Object -Property Value -Descending | Select-Object -First 3)) { + $TopEndpoints[$Entry.Key] = $Entry.Value + } + + $ClientList = [System.Collections.Generic.List[hashtable]]::new() + foreach ($Client in $Clients.Values) { + $ClientList.Add(@{ AppId = $Client.AppId; AppName = $Client.AppName; IP = $Client.IP; Count = $Client.Count }) + } + + return [PSCustomObject]@{ + OomCount = $OomCount + WatchdogCount = $WatchdogCount + PoolExhaustedCount = $PoolExhaustedCount + ErrCount = $ErrCount + MaxLimiterWaitMs = $MaxLimiterWaitMs + HeapMb = $HeapMb + StalledRunCount = $StalledRunCount + TopEndpointsMs = $TopEndpoints + Clients = $ClientList + EgressRejectCount = $EgressRejectCount + EgressRejectClients = $EgressRejectClients + } +} diff --git a/Modules/CIPPCore/Public/Functions/Test-CIPPStalledRun.ps1 b/Modules/CIPPCore/Public/Functions/Test-CIPPStalledRun.ps1 new file mode 100644 index 0000000000000..4a94a7571aa7a --- /dev/null +++ b/Modules/CIPPCore/Public/Functions/Test-CIPPStalledRun.ps1 @@ -0,0 +1,32 @@ +function Test-CIPPStalledRun { + <# + .SYNOPSIS + Decides whether a worker run summary is stalled. + .DESCRIPTION + A run summary has no status field, so "active" means CompletedUtc is unset. An active + run with queued work but nothing running, started more than two hours ago, is stalled. + + Pure predicate with no I/O so the threshold stays unit-testable. + .FUNCTIONALITY + Internal + .EXAMPLE + Test-CIPPStalledRun -Run $Summary -Now ([DateTime]::UtcNow) + #> + [CmdletBinding()] + [OutputType([bool])] + param( + [Parameter(Mandatory = $true)] + [AllowNull()] + $Run, + [Parameter(Mandatory = $true)] + [DateTime]$Now + ) + + if (-not $Run) { return $false } + if ($null -ne $Run.CompletedUtc) { return $false } + if ([int]$Run.Running -ne 0) { return $false } + if ([int]$Run.Queued -le 0) { return $false } + if ($null -eq $Run.StartedUtc) { return $false } + + return ([DateTime]$Run.StartedUtc).ToUniversalTime() -lt $Now.ToUniversalTime().AddHours(-2) +} diff --git a/Modules/CIPPCore/Public/Functions/Write-CIPPInstanceBootMarker.ps1 b/Modules/CIPPCore/Public/Functions/Write-CIPPInstanceBootMarker.ps1 new file mode 100644 index 0000000000000..1847c8a0c48f7 --- /dev/null +++ b/Modules/CIPPCore/Public/Functions/Write-CIPPInstanceBootMarker.ps1 @@ -0,0 +1,55 @@ +function Write-CIPPInstanceBootMarker { + <# + .SYNOPSIS + Records that this instance started, next to the health samples it interrupts. + .DESCRIPTION + The health timer stops writing while a container is down, so the gap between the last + sample and this boot is the outage the instance cannot otherwise observe. Storing the + marker in the same table and bucket layout lets the diagnostics timeline line restarts + up against the samples on either side. + + Warmup runs on every node, so the row is keyed on the boot's 5 minute bucket and + upserted - racing nodes write the same marker instead of duplicating it. + + Never throws; warmup steps are soft-fail by design. + .FUNCTIONALITY + Internal + .EXAMPLE + Write-CIPPInstanceBootMarker + #> + [CmdletBinding()] + param() + + try { + $Now = [DateTime]::UtcNow + $Bucket = $Now.AddMinutes(-($Now.Minute % 5)).ToString('yyyy-MM-ddTHH:mm') + + $Table = Get-CIPPTable -TableName 'InstanceHealth' + + # All rows share one partition now, so this is a single partition-scoped RowKey range + # instead of a cross-partition scan. Bucket keys sort lexically because they are ISO. + $Since = $Now.AddHours(-24).ToString('yyyy-MM-ddTHH:mm') + $Previous = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'InstanceHealth' and RowKey ge '$Since' and Kind eq 'sample'" | + Sort-Object -Property Bucket | Select-Object -Last 1 + + $Entity = @{ + PartitionKey = 'InstanceHealth' + RowKey = "${Bucket}_boot" + Bucket = $Bucket + Kind = 'boot' + BootTime = $Now.ToString('yyyy-MM-ddTHH:mm:ssZ') + Version = [string]($env:APP_VERSION ?? '') + } + + if ($Previous.Bucket) { + $LastSample = [DateTime]::ParseExact($Previous.Bucket, 'yyyy-MM-ddTHH:mm', [cultureinfo]::InvariantCulture, [System.Globalization.DateTimeStyles]::AssumeUniversal -bor [System.Globalization.DateTimeStyles]::AdjustToUniversal) + $Entity.PreviousSample = [string]$Previous.Bucket + $Entity.GapMinutes = [int][math]::Round(($Now - $LastSample).TotalMinutes) + } + + Add-CIPPAzDataTableEntity @Table -Entity $Entity -Force | Out-Null + Write-Information "[InstanceHealth] Boot marker recorded for bucket $Bucket" + } catch { + Write-Information "[InstanceHealth] Boot marker failed (non-fatal): $($_.Exception.Message)" + } +} diff --git a/Modules/CIPPCore/Public/Get-CIPPCAPolicyIdentityCoverage.ps1 b/Modules/CIPPCore/Public/Get-CIPPCAPolicyIdentityCoverage.ps1 new file mode 100644 index 0000000000000..9127068616aae --- /dev/null +++ b/Modules/CIPPCore/Public/Get-CIPPCAPolicyIdentityCoverage.ps1 @@ -0,0 +1,604 @@ +function Get-CIPPCAPolicyIdentityCoverage { + <# + .SYNOPSIS + Resolves who a Conditional Access policy's identity assignment touches, and why. + .DESCRIPTION + Returns touched users only (concrete include or exclude expansions). The All users token + sets includesAllUsers and is not expanded into one row per directory user. Exclude wins + for status; include+exclude rows stay in the result with both reason arrays. + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param ( + [Parameter(Mandatory = $true)] + [string]$TenantFilter, + + [Parameter(Mandatory = $true)] + [string]$PolicyId + ) + + $GuidPattern = '^[0-9a-fA-F]{8}-([0-9a-fA-F]{4}-){3}[0-9a-fA-F]{12}$' + $IncludeMap = @{} + $ExcludeMap = @{} + $Unresolved = [System.Collections.Generic.List[object]]::new() + $IncludesAllUsers = $false + $GroupNameLookup = @{} + $RoleNameLookup = @{} + + function Add-CoverageReason { + param ( + [hashtable]$Map, + [string]$UserId, + [hashtable]$Reason + ) + if ([string]::IsNullOrWhiteSpace($UserId) -or $null -eq $Reason) { return } + if (-not $Map.ContainsKey($UserId)) { + $Map[$UserId] = [System.Collections.Generic.List[object]]::new() + } + $Existing = $Map[$UserId] | Where-Object { $_.value -eq $Reason.value } + if ($Existing) { return } + $Map[$UserId].Add([pscustomobject]$Reason) | Out-Null + } + + function New-CoverageReason { + param ( + [string]$Type, + [string]$Id, + [string]$Token, + [string]$Label, + [bool]$Transitive = $false, + [string]$ViaGroupId, + [string]$ViaGroupLabel + ) + $ValueKey = if ($Id -and $ViaGroupId) { + "$Type`:$Id`:group:$ViaGroupId" + } elseif ($Id) { + "$Type`:$Id" + } elseif ($Token) { + "$Type`:$Token" + } else { + $Type + } + $Reason = @{ + type = $Type + value = $ValueKey + label = $Label + } + if ($Id) { $Reason.id = $Id } + if ($Transitive) { $Reason.transitive = $true } + if ($ViaGroupId) { + $Reason.viaGroupId = $ViaGroupId + if ($ViaGroupLabel) { $Reason.viaGroupLabel = $ViaGroupLabel } + } + return $Reason + } + + function Test-IsGuid { + param ([string]$Value) + return $Value -match $GuidPattern + } + + # Load policy + $Policy = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/identity/conditionalAccess/policies/$PolicyId" -tenantid $TenantFilter -AsApp $true + if (-not $Policy) { + throw "Conditional Access policy $PolicyId was not found." + } + + $Users = $Policy.conditions.users + if ($null -eq $Users) { + $Users = [pscustomobject]@{} + } + + # --- Include / exclude users (GUIDs + tokens) --- + foreach ($UserRef in @($Users.includeUsers)) { + if ([string]::IsNullOrWhiteSpace($UserRef)) { continue } + if ($UserRef -eq 'All') { + $IncludesAllUsers = $true + continue + } + if ($UserRef -eq 'None') { continue } + if ($UserRef -eq 'GuestsOrExternalUsers') { + try { + $GuestUsers = @(New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/users?`$filter=userType eq 'Guest'&`$select=id,displayName,userPrincipalName,userType&`$top=999" -tenantid $TenantFilter -AsApp $true) + foreach ($Guest in $GuestUsers) { + Add-CoverageReason -Map $IncludeMap -UserId $Guest.id -Reason (New-CoverageReason -Type 'includeUsers' -Token 'GuestsOrExternalUsers' -Label 'Guests or external users') + } + } catch { + $Unresolved.Add([pscustomobject]@{ field = 'includeUsers'; id = 'GuestsOrExternalUsers'; error = $_.Exception.Message }) | Out-Null + } + continue + } + if (Test-IsGuid $UserRef) { + Add-CoverageReason -Map $IncludeMap -UserId $UserRef -Reason (New-CoverageReason -Type 'includeUsers' -Id $UserRef -Label 'User inclusion') + } + } + + foreach ($UserRef in @($Users.excludeUsers)) { + if ([string]::IsNullOrWhiteSpace($UserRef)) { continue } + if ($UserRef -eq 'GuestsOrExternalUsers') { + try { + $GuestUsers = @(New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/users?`$filter=userType eq 'Guest'&`$select=id,displayName,userPrincipalName,userType&`$top=999" -tenantid $TenantFilter -AsApp $true) + foreach ($Guest in $GuestUsers) { + Add-CoverageReason -Map $ExcludeMap -UserId $Guest.id -Reason (New-CoverageReason -Type 'excludeUsers' -Token 'GuestsOrExternalUsers' -Label 'Guests or external users') + } + } catch { + $Unresolved.Add([pscustomobject]@{ field = 'excludeUsers'; id = 'GuestsOrExternalUsers'; error = $_.Exception.Message }) | Out-Null + } + continue + } + if (Test-IsGuid $UserRef) { + Add-CoverageReason -Map $ExcludeMap -UserId $UserRef -Reason (New-CoverageReason -Type 'excludeUsers' -Id $UserRef -Label 'User exclusion') + } + } + + # --- Groups (transitive + direct, so nested can be labelled accurately) --- + $IncludeGroups = @($Users.includeGroups | Where-Object { Test-IsGuid $_ }) + $ExcludeGroups = @($Users.excludeGroups | Where-Object { Test-IsGuid $_ }) + $AllGroupIds = @($IncludeGroups + $ExcludeGroups | Select-Object -Unique) + + if ($AllGroupIds.Count -gt 0) { + $GroupDetailRequests = [System.Collections.Generic.List[object]]::new() + $GroupMemberRequests = [System.Collections.Generic.List[object]]::new() + foreach ($GroupId in $AllGroupIds) { + $GroupDetailRequests.Add(@{ + id = "details-$GroupId" + method = 'GET' + url = "groups/$GroupId`?`$select=id,displayName" + }) + $GroupMemberRequests.Add(@{ + id = "transitive-$GroupId" + method = 'GET' + url = "groups/$GroupId/transitiveMembers/microsoft.graph.user?`$select=id&`$top=999" + }) + $GroupMemberRequests.Add(@{ + id = "direct-$GroupId" + method = 'GET' + url = "groups/$GroupId/members/microsoft.graph.user?`$select=id&`$top=999" + }) + } + + try { + $GroupDetailsResults = New-GraphBulkRequest -Requests @($GroupDetailRequests) -tenantid $TenantFilter -asapp $true + foreach ($Result in @($GroupDetailsResults)) { + $GroupId = $Result.id -replace '^details-', '' + if ($Result.status -eq 200 -and $Result.body) { + $GroupNameLookup[$GroupId] = $Result.body.displayName + } else { + $Field = if ($IncludeGroups -contains $GroupId) { 'includeGroups' } else { 'excludeGroups' } + $Unresolved.Add([pscustomobject]@{ + field = $Field + id = $GroupId + error = if ($Result.body.error.message) { $Result.body.error.message } else { "HTTP $($Result.status)" } + }) | Out-Null + } + } + } catch { + foreach ($GroupId in $AllGroupIds) { + $Field = if ($IncludeGroups -contains $GroupId) { 'includeGroups' } else { 'excludeGroups' } + $Unresolved.Add([pscustomobject]@{ field = $Field; id = $GroupId; error = $_.Exception.Message }) | Out-Null + } + } + + try { + # New-GraphBulkRequest follows @odata.nextLink and merges pages into body.value + $GroupMembersResults = New-GraphBulkRequest -Requests @($GroupMemberRequests) -tenantid $TenantFilter -asapp $true + $DirectMembersByGroup = @{} + $TransitiveMembersByGroup = @{} + foreach ($Result in @($GroupMembersResults)) { + if ($Result.status -ne 200) { + $FailedGroupId = if ($Result.id -like 'transitive-*') { + $Result.id -replace '^transitive-', '' + } elseif ($Result.id -like 'direct-*') { + $Result.id -replace '^direct-', '' + } else { + $null + } + # Transitive expansion is required for coverage; record once per group. + if ($Result.id -like 'transitive-*' -and $FailedGroupId) { + $Already = $Unresolved | Where-Object { $_.id -eq $FailedGroupId -and $_.field -like '*Groups' } + if (-not $Already) { + $Field = if ($IncludeGroups -contains $FailedGroupId) { 'includeGroups' } else { 'excludeGroups' } + $Unresolved.Add([pscustomobject]@{ + field = $Field + id = $FailedGroupId + error = if ($Result.body.error.message) { $Result.body.error.message } else { "HTTP $($Result.status)" } + }) | Out-Null + } + } + continue + } + $MemberIds = [System.Collections.Generic.HashSet[string]]::new() + foreach ($Member in @($Result.body.value)) { + if ($Member.id) { [void]$MemberIds.Add([string]$Member.id) } + } + if ($Result.id -like 'direct-*') { + $DirectMembersByGroup[($Result.id -replace '^direct-', '')] = $MemberIds + } elseif ($Result.id -like 'transitive-*') { + $TransitiveMembersByGroup[($Result.id -replace '^transitive-', '')] = $MemberIds + } + } + + foreach ($GroupId in $AllGroupIds) { + if (-not $TransitiveMembersByGroup.ContainsKey($GroupId)) { + $Already = $Unresolved | Where-Object { $_.id -eq $GroupId -and $_.field -like '*Groups' } + if (-not $Already) { + $Field = if ($IncludeGroups -contains $GroupId) { 'includeGroups' } else { 'excludeGroups' } + $Unresolved.Add([pscustomobject]@{ + field = $Field + id = $GroupId + error = 'Group member expansion returned no result' + }) | Out-Null + } + continue + } + $Members = $TransitiveMembersByGroup[$GroupId] + if (-not $Members) { continue } + $DirectMembers = $DirectMembersByGroup[$GroupId] + if (-not $DirectMembers) { + $DirectMembers = [System.Collections.Generic.HashSet[string]]::new() + } + + $GroupLabel = if ($GroupNameLookup.ContainsKey($GroupId) -and $GroupNameLookup[$GroupId]) { + $GroupNameLookup[$GroupId] + } else { + $GroupId + } + + $IsInclude = $IncludeGroups -contains $GroupId + $IsExclude = $ExcludeGroups -contains $GroupId + foreach ($MemberId in $Members) { + $IsNested = -not $DirectMembers.Contains($MemberId) + $ReasonLabel = if ($IsNested) { "Group: $GroupLabel (nested)" } else { "Group: $GroupLabel" } + if ($IsInclude) { + Add-CoverageReason -Map $IncludeMap -UserId $MemberId -Reason (New-CoverageReason -Type 'includeGroups' -Id $GroupId -Label $ReasonLabel -Transitive $IsNested) + } + if ($IsExclude) { + Add-CoverageReason -Map $ExcludeMap -UserId $MemberId -Reason (New-CoverageReason -Type 'excludeGroups' -Id $GroupId -Label $ReasonLabel -Transitive $IsNested) + } + } + } + } catch { + foreach ($GroupId in $AllGroupIds) { + $Already = $Unresolved | Where-Object { $_.id -eq $GroupId -and $_.field -like '*Groups' } + if ($Already) { continue } + $Field = if ($IncludeGroups -contains $GroupId) { 'includeGroups' } else { 'excludeGroups' } + $Unresolved.Add([pscustomobject]@{ + field = $Field + id = $GroupId + error = "Group member expansion failed: $($_.Exception.Message)" + }) | Out-Null + } + } + } + + # --- Roles (active assignments only) --- + $IncludeRoles = @($Users.includeRoles | Where-Object { Test-IsGuid $_ }) + $ExcludeRoles = @($Users.excludeRoles | Where-Object { Test-IsGuid $_ }) + $AllRoleTemplateIds = @($IncludeRoles + $ExcludeRoles | Select-Object -Unique) + + if ($AllRoleTemplateIds.Count -gt 0) { + $RoleDefinitions = @(New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/roleManagement/directory/roleDefinitions?`$select=id,templateId,displayName" -tenantid $TenantFilter -AsApp $true -ErrorAction SilentlyContinue) + $TemplateToDefinitionId = @{} + foreach ($Rd in $RoleDefinitions) { + if ($null -ne $Rd.templateId) { + $TemplateToDefinitionId[$Rd.templateId] = $Rd.id + $RoleNameLookup[$Rd.templateId] = $Rd.displayName + $RoleNameLookup[$Rd.id] = $Rd.displayName + } + } + + foreach ($RoleId in $AllRoleTemplateIds) { + if (-not $RoleNameLookup.ContainsKey($RoleId) -and -not $TemplateToDefinitionId.ContainsKey($RoleId)) { + $Field = if ($IncludeRoles -contains $RoleId) { 'includeRoles' } else { 'excludeRoles' } + $Unresolved.Add([pscustomobject]@{ field = $Field; id = $RoleId; error = 'Role definition not found' }) | Out-Null + } + } + + $Assignments = @(New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/roleManagement/directory/roleAssignments?`$expand=principal(`$select=id,displayName)" -tenantid $TenantFilter -AsApp $true -ErrorAction SilentlyContinue) + + # Group-held role assignments: expand transitive user members so CA role targeting matches Entra. + $RoleGroupJobs = [System.Collections.Generic.List[object]]::new() + foreach ($Assignment in $Assignments) { + $PrincipalType = [string]$Assignment.principal.'@odata.type' + if ($PrincipalType -ne '#microsoft.graph.group') { continue } + $PrincipalId = $Assignment.principalId + if (-not $PrincipalId) { continue } + $DefId = $Assignment.roleDefinitionId + + foreach ($TemplateId in $AllRoleTemplateIds) { + $MatchedDefId = $TemplateToDefinitionId[$TemplateId] + if ($DefId -ne $MatchedDefId -and $DefId -ne $TemplateId) { continue } + + $RoleLabel = if ($RoleNameLookup.ContainsKey($TemplateId) -and $RoleNameLookup[$TemplateId]) { + $RoleNameLookup[$TemplateId] + } else { + $TemplateId + } + $GroupLabel = if ($Assignment.principal.displayName) { + $Assignment.principal.displayName + } else { + $PrincipalId + } + + $RoleGroupJobs.Add([pscustomobject]@{ + GroupId = $PrincipalId + GroupLabel = $GroupLabel + TemplateId = $TemplateId + RoleLabel = $RoleLabel + IsInclude = ($IncludeRoles -contains $TemplateId) + IsExclude = ($ExcludeRoles -contains $TemplateId) + }) | Out-Null + } + } + + $RoleGroupMemberLookup = @{} + $UniqueRoleGroupIds = @($RoleGroupJobs.GroupId | Select-Object -Unique) + if ($UniqueRoleGroupIds.Count -gt 0) { + $RoleGroupMemberRequests = [System.Collections.Generic.List[object]]::new() + foreach ($GroupId in $UniqueRoleGroupIds) { + $RoleGroupMemberRequests.Add(@{ + id = "roleGroup-$GroupId" + method = 'GET' + url = "groups/$GroupId/transitiveMembers/microsoft.graph.user?`$select=id&`$top=999" + }) + } + try { + $RoleGroupMemberResults = New-GraphBulkRequest -Requests @($RoleGroupMemberRequests) -tenantid $TenantFilter -asapp $true + foreach ($Result in @($RoleGroupMemberResults)) { + if ($Result.status -ne 200) { continue } + $GroupId = $Result.id -replace '^roleGroup-', '' + $MemberIds = [System.Collections.Generic.HashSet[string]]::new() + foreach ($Member in @($Result.body.value)) { + if ($Member.id) { [void]$MemberIds.Add([string]$Member.id) } + } + $RoleGroupMemberLookup[$GroupId] = $MemberIds + } + } catch { + Write-Information "Get-CIPPCAPolicyIdentityCoverage: role-group member expansion failed: $($_.Exception.Message)" + } + } + + foreach ($Job in $RoleGroupJobs) { + $Members = $RoleGroupMemberLookup[$Job.GroupId] + if (-not $Members -or $Members.Count -eq 0) { continue } + $ReasonLabel = "Role: $($Job.RoleLabel) via group $($Job.GroupLabel)" + foreach ($MemberId in $Members) { + if ($Job.IsInclude) { + Add-CoverageReason -Map $IncludeMap -UserId $MemberId -Reason (New-CoverageReason -Type 'includeRoles' -Id $Job.TemplateId -Label $ReasonLabel -ViaGroupId $Job.GroupId -ViaGroupLabel $Job.GroupLabel) + } + if ($Job.IsExclude) { + Add-CoverageReason -Map $ExcludeMap -UserId $MemberId -Reason (New-CoverageReason -Type 'excludeRoles' -Id $Job.TemplateId -Label $ReasonLabel -ViaGroupId $Job.GroupId -ViaGroupLabel $Job.GroupLabel) + } + } + } + + foreach ($Assignment in $Assignments) { + $PrincipalType = [string]$Assignment.principal.'@odata.type' + if ($PrincipalType -and $PrincipalType -ne '#microsoft.graph.user') { continue } + $PrincipalId = $Assignment.principalId + if (-not $PrincipalId) { continue } + $DefId = $Assignment.roleDefinitionId + + foreach ($TemplateId in $AllRoleTemplateIds) { + $MatchedDefId = $TemplateToDefinitionId[$TemplateId] + if ($DefId -ne $MatchedDefId -and $DefId -ne $TemplateId) { continue } + + $RoleLabel = if ($RoleNameLookup.ContainsKey($TemplateId) -and $RoleNameLookup[$TemplateId]) { + $RoleNameLookup[$TemplateId] + } else { + $TemplateId + } + + if ($IncludeRoles -contains $TemplateId) { + Add-CoverageReason -Map $IncludeMap -UserId $PrincipalId -Reason (New-CoverageReason -Type 'includeRoles' -Id $TemplateId -Label "Role: $RoleLabel") + } + if ($ExcludeRoles -contains $TemplateId) { + Add-CoverageReason -Map $ExcludeMap -UserId $PrincipalId -Reason (New-CoverageReason -Type 'excludeRoles' -Id $TemplateId -Label "Role: $RoleLabel") + } + } + } + } + + # --- Guests / external user blocks --- + function Get-CoverageGuestHomeTenantId { + param ($User) + foreach ($Identity in @($User.identities)) { + $Issuer = [string]$Identity.issuer + if ($Issuer -match $GuidPattern) { return $Issuer } + } + return $null + } + + function Get-CoverageGuestCategory { + param ($User) + $Upn = [string]$User.userPrincipalName + $IsExt = $Upn -like '*#EXT#*' + $UserType = [string]$User.userType + if ($UserType -eq 'Guest' -and $IsExt) { return 'b2bCollaborationGuest' } + if ($UserType -eq 'Member' -and $IsExt) { return 'b2bCollaborationMember' } + if ($UserType -eq 'Guest' -and -not $IsExt) { return 'internalGuest' } + return $null + } + + function Test-CoverageExternalTenantMatch { + param ( + $User, + $ExternalTenants + ) + if ($null -eq $ExternalTenants) { return $true } + $Kind = [string]$ExternalTenants.membershipKind + if ([string]::IsNullOrWhiteSpace($Kind) -or $Kind -eq 'all') { return $true } + if ($Kind -ne 'enumerated') { return $true } + + $Allowed = @($ExternalTenants.members | Where-Object { -not [string]::IsNullOrWhiteSpace($_) }) + if ($Allowed.Count -eq 0) { return $false } + + $HomeTenantId = Get-CoverageGuestHomeTenantId -User $User + if (-not $HomeTenantId) { return $false } + return ($Allowed -contains $HomeTenantId) + } + + function Expand-GuestBlock { + param ( + $GuestConfig, + [hashtable]$Map, + [string]$Type, + [string]$Field + ) + if ($null -eq $GuestConfig) { return } + $TypesRaw = $GuestConfig.guestOrExternalUserTypes + if ([string]::IsNullOrWhiteSpace($TypesRaw) -or $TypesRaw -eq 'none') { return } + + $SelectedTypes = @( + $TypesRaw -split ',' | + ForEach-Object { $_.Trim() } | + Where-Object { $_ -and $_ -ne 'none' -and $_ -ne 'unknownFutureValue' } | + Select-Object -Unique + ) + if ($SelectedTypes.Count -eq 0) { return } + + # These CA categories are not reliably enumerable from directory user objects. + $NonEnumerableTypes = @( + 'b2bDirectConnectUser' + 'otherExternalUser' + 'serviceProvider' + ) + foreach ($GuestType in $SelectedTypes) { + if ($NonEnumerableTypes -contains $GuestType) { + $Unresolved.Add([pscustomobject]@{ + field = $Field + id = $GuestType + error = 'This guest or external user type cannot be expanded from directory users' + }) | Out-Null + } + } + + $EnumerableTypes = @( + $SelectedTypes | Where-Object { + $_ -in @('b2bCollaborationGuest', 'b2bCollaborationMember', 'internalGuest') + } + ) + if ($EnumerableTypes.Count -eq 0) { return } + + $Candidates = [System.Collections.Generic.List[object]]::new() + try { + if ($EnumerableTypes -contains 'b2bCollaborationGuest' -or $EnumerableTypes -contains 'internalGuest') { + $GuestUsers = @(New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/users?`$filter=userType eq 'Guest'&`$select=id,displayName,userPrincipalName,userType,identities&`$top=999" -tenantid $TenantFilter -AsApp $true) + foreach ($Guest in $GuestUsers) { $Candidates.Add($Guest) | Out-Null } + } + if ($EnumerableTypes -contains 'b2bCollaborationMember') { + # B2B collaboration members keep the #EXT# UPN pattern with userType Member. + $MemberExtUsers = @(New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/users?`$count=true&`$filter=userType eq 'Member' and contains(userPrincipalName,'#EXT#')&`$select=id,displayName,userPrincipalName,userType,identities&`$top=999" -tenantid $TenantFilter -AsApp $true -ComplexFilter) + foreach ($Member in $MemberExtUsers) { $Candidates.Add($Member) | Out-Null } + } + } catch { + $Unresolved.Add([pscustomobject]@{ field = $Field; id = $TypesRaw; error = $_.Exception.Message }) | Out-Null + return + } + + $Seen = [System.Collections.Generic.HashSet[string]]::new() + $Label = "Guest types: $TypesRaw" + foreach ($Candidate in $Candidates) { + if (-not $Candidate.id) { continue } + if (-not $Seen.Add([string]$Candidate.id)) { continue } + + $Category = Get-CoverageGuestCategory -User $Candidate + if (-not $Category -or ($EnumerableTypes -notcontains $Category)) { continue } + if (-not (Test-CoverageExternalTenantMatch -User $Candidate -ExternalTenants $GuestConfig.externalTenants)) { + continue + } + + Add-CoverageReason -Map $Map -UserId $Candidate.id -Reason (New-CoverageReason -Type $Type -Token $TypesRaw -Label $Label) + } + } + + Expand-GuestBlock -GuestConfig $Users.includeGuestsOrExternalUsers -Map $IncludeMap -Type 'includeGuestsOrExternalUsers' -Field 'includeGuestsOrExternalUsers' + Expand-GuestBlock -GuestConfig $Users.excludeGuestsOrExternalUsers -Map $ExcludeMap -Type 'excludeGuestsOrExternalUsers' -Field 'excludeGuestsOrExternalUsers' + + # --- All token: annotate touched users only --- + $AllReason = New-CoverageReason -Type 'includeUsers' -Token 'All' -Label 'All users' + if ($IncludesAllUsers) { + foreach ($UserId in @($IncludeMap.Keys + $ExcludeMap.Keys | Select-Object -Unique)) { + Add-CoverageReason -Map $IncludeMap -UserId $UserId -Reason $AllReason + } + } + + # --- Union touched users and resolve directory labels --- + $TouchedIds = @($IncludeMap.Keys + $ExcludeMap.Keys | Select-Object -Unique) + $DirectoryLookup = @{} + + if ($TouchedIds.Count -gt 0) { + for ($i = 0; $i -lt $TouchedIds.Count; $i += 1000) { + $Batch = @($TouchedIds[$i..([Math]::Min($i + 999, $TouchedIds.Count - 1))]) + try { + $Body = @{ ids = $Batch; types = @('user') } + $Resolved = New-GraphPOSTRequest -uri 'https://graph.microsoft.com/v1.0/directoryObjects/getByIds?$select=id,displayName,userPrincipalName,userType' -tenantid $TenantFilter -body $Body -AsApp $true + foreach ($Obj in @($Resolved.value)) { + if ($Obj.id) { + $DirectoryLookup[$Obj.id] = $Obj + } + } + } catch { + Write-Information "Get-CIPPCAPolicyIdentityCoverage: getByIds failed: $($_.Exception.Message)" + } + } + } + + # Mark assignment user GUIDs that never resolved + foreach ($UserRef in @($Users.includeUsers + $Users.excludeUsers)) { + if ((Test-IsGuid $UserRef) -and -not $DirectoryLookup.ContainsKey($UserRef)) { + $Field = if (@($Users.includeUsers) -contains $UserRef) { 'includeUsers' } else { 'excludeUsers' } + $Already = $Unresolved | Where-Object { $_.id -eq $UserRef -and $_.field -eq $Field } + if (-not $Already) { + $Unresolved.Add([pscustomobject]@{ field = $Field; id = $UserRef; error = 'User not found' }) | Out-Null + } + } + } + + $Identities = [System.Collections.Generic.List[object]]::new() + foreach ($UserId in ($TouchedIds | Sort-Object)) { + $IncludeReasons = if ($IncludeMap.ContainsKey($UserId)) { @($IncludeMap[$UserId]) } else { @() } + $ExcludeReasons = if ($ExcludeMap.ContainsKey($UserId)) { @($ExcludeMap[$UserId]) } else { @() } + + $Status = if ($ExcludeReasons.Count -gt 0) { 'excluded' } else { 'covered' } + $Dir = $DirectoryLookup[$UserId] + + $Identities.Add([pscustomobject]@{ + id = $UserId + displayName = if ($Dir.displayName) { $Dir.displayName } else { $UserId } + userPrincipalName = if ($Dir.userPrincipalName) { $Dir.userPrincipalName } else { $null } + userType = if ($Dir.userType) { $Dir.userType } else { $null } + status = $Status + includeReasons = @($IncludeReasons) + excludeReasons = @($ExcludeReasons) + }) | Out-Null + } + + $CoveredCount = @($Identities | Where-Object { $_.status -eq 'covered' }).Count + $ExcludedCount = @($Identities | Where-Object { $_.status -eq 'excluded' }).Count + + $HasExcludeUsers = @($Users.excludeUsers | Where-Object { -not [string]::IsNullOrWhiteSpace($_) }).Count -gt 0 + $HasExcludeGroups = @($Users.excludeGroups | Where-Object { Test-IsGuid $_ }).Count -gt 0 + $HasExcludeRoles = @($Users.excludeRoles | Where-Object { Test-IsGuid $_ }).Count -gt 0 + $HasExcludeGuests = $null -ne $Users.excludeGuestsOrExternalUsers -and + -not [string]::IsNullOrWhiteSpace($Users.excludeGuestsOrExternalUsers.guestOrExternalUserTypes) -and + $Users.excludeGuestsOrExternalUsers.guestOrExternalUserTypes -ne 'none' + $HasExclusions = $HasExcludeUsers -or $HasExcludeGroups -or $HasExcludeRoles -or $HasExcludeGuests + + return [pscustomobject]@{ + policyId = $Policy.id + displayName = $Policy.displayName + state = $Policy.state + includesAllUsers = [bool]$IncludesAllUsers + hasExclusions = [bool]$HasExclusions + summary = [pscustomobject]@{ + coveredCount = $CoveredCount + excludedCount = $ExcludedCount + unresolvedCount = $Unresolved.Count + touchedCount = $Identities.Count + } + unresolved = @($Unresolved) + identities = @($Identities) + } +} diff --git a/Modules/CIPPCore/Public/Get-CIPPIntuneCompareExclusions.ps1 b/Modules/CIPPCore/Public/Get-CIPPIntuneCompareExclusions.ps1 index 81fa4355a4bd3..117773d7e0949 100644 --- a/Modules/CIPPCore/Public/Get-CIPPIntuneCompareExclusions.ps1 +++ b/Modules/CIPPCore/Public/Get-CIPPIntuneCompareExclusions.ps1 @@ -38,6 +38,7 @@ function Get-CIPPIntuneCompareExclusions { 'featureUpdatesPauseStartDate' 'wslDistributions', 'lastSuccessfulSyncDateTime', + 'inventorySyncStatus', 'tenantFilter', 'agents', 'isSynced' diff --git a/Modules/CIPPCore/Public/GraphHelper/New-GraphGetRequest.ps1 b/Modules/CIPPCore/Public/GraphHelper/New-GraphGetRequest.ps1 index dbdaaf7b424d2..a9c11118f8c19 100644 --- a/Modules/CIPPCore/Public/GraphHelper/New-GraphGetRequest.ps1 +++ b/Modules/CIPPCore/Public/GraphHelper/New-GraphGetRequest.ps1 @@ -172,8 +172,9 @@ function New-GraphGetRequest { $ShouldRetry = $true } } - # Check for "Resource temporarily unavailable" - elseif ($Message -like '*Resource temporarily unavailable*' -or $Message -like '*Too many requests*') { + # Check for "Resource temporarily unavailable" / SharePoint CSOM throttling + # ("Server busy, please retry" is transient and safe to retry). + elseif ($Message -like '*Resource temporarily unavailable*' -or $Message -like '*Too many requests*' -or $Message -like '*Server busy*') { if ($RetryCount -lt $MaxRetries) { $WaitTime = Get-Random -Minimum 1.1 -Maximum 3.1 # Random sleep between 1-2 seconds Write-Warning "Resource temporarily unavailable. Waiting $WaitTime seconds before retry. Attempt $($RetryCount + 1) of $MaxRetries" diff --git a/Modules/CIPPCore/Public/GraphHelper/New-GraphPOSTRequest.ps1 b/Modules/CIPPCore/Public/GraphHelper/New-GraphPOSTRequest.ps1 index 28c9c85797605..0d1f091ad2cca 100644 --- a/Modules/CIPPCore/Public/GraphHelper/New-GraphPOSTRequest.ps1 +++ b/Modules/CIPPCore/Public/GraphHelper/New-GraphPOSTRequest.ps1 @@ -78,8 +78,9 @@ function New-GraphPOSTRequest { } $ShouldRetry = $true } - # Check for "Resource temporarily unavailable" - elseif ($Message -like '*Resource temporarily unavailable*' -or $Message -like '*Too many requests*') { + # Check for "Resource temporarily unavailable" / SharePoint CSOM throttling + # ("Server busy, please retry" is transient and safe to retry, e.g. ListSiteProperties). + elseif ($Message -like '*Resource temporarily unavailable*' -or $Message -like '*Too many requests*' -or $Message -like '*Server busy*') { $WaitTime = Get-Random -Minimum 1.1 -Maximum 3.1 $RetryReason = 'Resource temporarily unavailable.' $ShouldRetry = $true diff --git a/Modules/CIPPCore/Public/GraphRequests/Get-GraphRequestList.ps1 b/Modules/CIPPCore/Public/GraphRequests/Get-GraphRequestList.ps1 index 22a56bae7464b..c7e0a9188d03f 100644 --- a/Modules/CIPPCore/Public/GraphRequests/Get-GraphRequestList.ps1 +++ b/Modules/CIPPCore/Public/GraphRequests/Get-GraphRequestList.ps1 @@ -92,6 +92,13 @@ function Get-GraphRequestList { $Endpoint = $Endpoint -replace '^/', '' $DisplayName = ($Endpoint -split '/')[0] + # @odata.count is only returned when the request carries $count=true, so a CountOnly caller + # that did not also pass $count got a response with no count and CountOnly returned $null. + # Add it here (ConsistencyLevel:eventual is set via ComplexFilter on the count request below). + if ($CountOnly.IsPresent -and -not $Parameters.ContainsKey('$count')) { + $Parameters['$count'] = 'true' + } + if ($QueueNameOverride) { $QueueName = $QueueNameOverride } else { diff --git a/Modules/CIPPCore/Public/MCP/ConvertTo-CippMcpArgumentShape.ps1 b/Modules/CIPPCore/Public/MCP/ConvertTo-CippMcpArgumentShape.ps1 new file mode 100644 index 0000000000000..5c5cbe416a75d --- /dev/null +++ b/Modules/CIPPCore/Public/MCP/ConvertTo-CippMcpArgumentShape.ps1 @@ -0,0 +1,73 @@ +function ConvertTo-CippMcpArgumentShape { + <# + .SYNOPSIS + Coerces MCP tool arguments to match the tool's input schema, wrapping a bare scalar into + the { value } object shape a CIPP endpoint actually reads. + .DESCRIPTION + CIPP autocomplete/select fields are read as $Request.Body..value, so the generated + spec documents them as LabelValue objects ({ "value": "..." }). Nothing on the dispatch + path validated arguments against that schema, so an MCP caller that sent a bare string for + such a field made .value resolve to $null at the endpoint. For a field that scopes a query + (a user or tenant selector, say) that silently dropped the scope and returned an UNSCOPED + 200 rather than erroring. + + This walks the top-level schema properties and, where a property is a LabelValue-shaped + object (an object schema carrying a 'value' property) or an array of them, wraps a bare + scalar the caller sent into @{ value = } (or an array of those). $ref is already + inlined in the catalog's inputSchema, so the LabelValue component arrives here as a plain + object schema. Anything already the right shape, and any field the schema does not + describe, is returned exactly as received. + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [hashtable]$Arguments, + $InputSchema + ) + + if (-not $Arguments -or $Arguments.Count -eq 0) { return $Arguments } + if ($InputSchema -isnot [System.Collections.IDictionary]) { return $Arguments } + $Properties = $InputSchema['properties'] + if ($Properties -isnot [System.Collections.IDictionary]) { return $Arguments } + + # An object schema is CIPP's autocomplete/select shape when it carries a 'value' property - + # the field the backend reads as $Field.value. + $IsLabelValue = { + param($Schema) + if ($Schema -isnot [System.Collections.IDictionary]) { return $false } + $Props = $Schema['properties'] + if ($Props -isnot [System.Collections.IDictionary]) { return $false } + return [bool](@($Props.Keys) | Where-Object { "$_".ToLowerInvariant() -eq 'value' }) + } + + # A JSON scalar: string, number or boolean. Objects (hashtable / PSCustomObject) and arrays + # are already structured and are left untouched. + $IsScalar = { param($Value) $null -ne $Value -and ($Value -is [string] -or $Value -is [valuetype]) } + + foreach ($Name in @($Arguments.Keys)) { + if (-not $Properties.Contains($Name)) { continue } + $Schema = $Properties[$Name] + if ($Schema -isnot [System.Collections.IDictionary]) { continue } + $Value = $Arguments[$Name] + + if (& $IsLabelValue $Schema) { + # Object-shaped LabelValue: wrap a bare scalar so $Field.value resolves. + if (& $IsScalar $Value) { + $Arguments[$Name] = @{ value = $Value } + } + } elseif ($Schema['type'] -eq 'array' -and (& $IsLabelValue $Schema['items'])) { + # Array of LabelValue: wrap each bare scalar element, and a bare scalar into a + # single-element array, leaving elements the caller already shaped as objects. + if (& $IsScalar $Value) { + $Arguments[$Name] = @(@{ value = $Value }) + } elseif ($Value -is [System.Collections.IEnumerable] -and $Value -isnot [string]) { + $Arguments[$Name] = @(foreach ($Item in $Value) { + if (& $IsScalar $Item) { @{ value = $Item } } else { $Item } + }) + } + } + } + + return $Arguments +} diff --git a/Modules/CIPPCore/Public/MCP/Get-CippMcpToolResult.ps1 b/Modules/CIPPCore/Public/MCP/Get-CippMcpToolResult.ps1 index e52e26ef01c76..47a0618c3b0a5 100644 --- a/Modules/CIPPCore/Public/MCP/Get-CippMcpToolResult.ps1 +++ b/Modules/CIPPCore/Public/MCP/Get-CippMcpToolResult.ps1 @@ -121,7 +121,7 @@ function Get-CippMcpToolResult { isError = $true } } - return Invoke-CippMcpApiRequest -Request $Request -TriggerMetadata $TriggerMetadata -ToolName $TargetName -Arguments $ArgHash['arguments'] -Method $Entry._method -ParamAlias $Entry._paramAlias + return Invoke-CippMcpApiRequest -Request $Request -TriggerMetadata $TriggerMetadata -ToolName $TargetName -Arguments $ArgHash['arguments'] -Method $Entry._method -ParamAlias $Entry._paramAlias -InputSchema $Entry.inputSchema } default { # Core passthroughs (always available) and legacy direct catalog calls (respect connector scoping). @@ -135,7 +135,7 @@ function Get-CippMcpToolResult { if (-not $Entry) { throw [pscustomobject]@{ code = -32602; message = "Unknown or unavailable tool: $ToolName. Use SearchTools to discover valid tool names." } } - return Invoke-CippMcpApiRequest -Request $Request -TriggerMetadata $TriggerMetadata -ToolName $ToolName -Arguments $Arguments -Method $Entry._method -ParamAlias $Entry._paramAlias + return Invoke-CippMcpApiRequest -Request $Request -TriggerMetadata $TriggerMetadata -ToolName $ToolName -Arguments $Arguments -Method $Entry._method -ParamAlias $Entry._paramAlias -InputSchema $Entry.inputSchema } } } diff --git a/Modules/CIPPCore/Public/MCP/Invoke-CippMcpApiRequest.ps1 b/Modules/CIPPCore/Public/MCP/Invoke-CippMcpApiRequest.ps1 index 194b65e3569db..4a6eb0024c048 100644 --- a/Modules/CIPPCore/Public/MCP/Invoke-CippMcpApiRequest.ps1 +++ b/Modules/CIPPCore/Public/MCP/Invoke-CippMcpApiRequest.ps1 @@ -25,11 +25,24 @@ function Invoke-CippMcpApiRequest { [string]$Method = 'GET', # Wire-name -> real-name map from the catalog entry (_paramAlias), for parameters that # had to be renamed to satisfy the MCP property-name rules. - [hashtable]$ParamAlias + [hashtable]$ParamAlias, + # The tool's inputSchema from the catalog entry, used to coerce argument shapes (a bare + # string sent for a { value } LabelValue field is wrapped so the endpoint's .value read + # resolves instead of silently dropping the scope). + $InputSchema ) $ArgHash = ConvertTo-CippMcpHashtable -InputObject $Arguments + # Reshape arguments to the tool's schema before dispatch: a caller that sends a bare string + # for an autocomplete/select (LabelValue) field would otherwise make the endpoint's + # $Field.value read resolve to $null, silently dropping a query scope and returning an + # unscoped 200. Done on the wire-named args, before the OData alias reversal below, because + # the schema is keyed by the same wire names. + if ($InputSchema) { + $ArgHash = ConvertTo-CippMcpArgumentShape -Arguments $ArgHash -InputSchema $InputSchema + } + # Restore any parameter renamed for the wire. OData options ('$filter', '$top', ...) are # advertised as odata_filter / odata_top because MCP property names cannot contain '$'; # the endpoint still reads the original name, so translate back before dispatching. diff --git a/Modules/CIPPCore/Public/New-CIPPIntuneTemplate.ps1 b/Modules/CIPPCore/Public/New-CIPPIntuneTemplate.ps1 index c38d5d39f0540..2f50b17a2ffc4 100644 --- a/Modules/CIPPCore/Public/New-CIPPIntuneTemplate.ps1 +++ b/Modules/CIPPCore/Public/New-CIPPIntuneTemplate.ps1 @@ -90,6 +90,13 @@ function New-CIPPIntuneTemplate { 'configurationPolicies' { $Type = 'Catalog' $Template = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/deviceManagement/$($urlname)('$($ID)')?`$expand=settings" -tenantid $TenantFilter | Select-Object name, description, settings, platforms, technologies, templateReference + # Apple enrollment (ADE) policies deploy only with a creationSource binding them to the + # target tenant's ADE token ("DepTokenId_{tokenId}"). That id is per tenant, so strip the + # source tenant's token and store a %ADETokenId% placeholder the deploy resolves from the + # target tenant's custom variable (see Get-CIPPTextReplacement / Set-CIPPIntunePolicy). + if ($Template.templateReference.templateFamily -like 'enrollment*' -or $Template.technologies -match 'enrollment') { + $Template | Add-Member -NotePropertyName 'creationSource' -NotePropertyValue 'DepTokenId_%ADETokenId%' -Force + } $TemplateJson = $Template | ConvertTo-Json -Depth 100 -Compress $DisplayName = $Template.name diff --git a/Modules/CIPPCore/Public/PIM/Get-CIPPPIMRoleAssignments.ps1 b/Modules/CIPPCore/Public/PIM/Get-CIPPPIMRoleAssignments.ps1 index aa2c4de378ff1..4ba9c650a11c3 100644 --- a/Modules/CIPPCore/Public/PIM/Get-CIPPPIMRoleAssignments.ps1 +++ b/Modules/CIPPCore/Public/PIM/Get-CIPPPIMRoleAssignments.ps1 @@ -124,6 +124,8 @@ function Get-CIPPPIMRoleAssignments { PIMCapable = $PIMCapable PolicySummary = $null PolicyBelowFloor = $null + PolicySettings = $null + FloorIssues = @() } } @@ -290,6 +292,8 @@ function Get-CIPPPIMRoleAssignments { if ($Policy) { $Row.PolicySummary = $Policy.Summary.SummaryText $Row.PolicyBelowFloor = $Policy.Summary.BelowFloor + $Row.PolicySettings = $Policy.Settings + $Row.FloorIssues = @($Policy.Summary.FloorIssues) } } } catch { diff --git a/Modules/CIPPCore/Public/Select-CIPPIntuneAvailableSetting.ps1 b/Modules/CIPPCore/Public/Select-CIPPIntuneAvailableSetting.ps1 index 9fa9d9a222fb3..330f2d6440952 100644 --- a/Modules/CIPPCore/Public/Select-CIPPIntuneAvailableSetting.ps1 +++ b/Modules/CIPPCore/Public/Select-CIPPIntuneAvailableSetting.ps1 @@ -19,6 +19,14 @@ function Select-CIPPIntuneAvailableSetting { The parsed Catalog policy payload. .PARAMETER TenantFilter The tenant to resolve setting availability against. + .PARAMETER ThrowOnMissingRequired + Deploy-only guard. Apple enrollment (ADE) policies mark every Setup Assistant option required + and Graph rejects a create/update when any is absent, with an opaque "A required Setting in + the template is not present in the policy" error. Microsoft keeps adding new required options + (e.g. accessibility appearance, Liquid Glass), so a template captured before they existed can + never deploy. When set, this throws an actionable error naming the missing settings instead. + Scoped to the enrollment family only - Endpoint Security and generic Catalog policies deploy + fine with a subset, so they are never validated. The comparison and drift paths never set it. .EXAMPLE $Template = Select-CIPPIntuneAvailableSetting -Policy $Template -TenantFilter $TenantFilter #> @@ -27,7 +35,8 @@ function Select-CIPPIntuneAvailableSetting { [Parameter(Mandatory = $true)] $Policy, [Parameter(Mandatory = $true)] - [string]$TenantFilter + [string]$TenantFilter, + [switch]$ThrowOnMissingRequired ) $TemplateId = $Policy.templateReference.templateId @@ -82,6 +91,29 @@ function Select-CIPPIntuneAvailableSetting { } } + if ($ThrowOnMissingRequired) { + # Only the enrollment family (Apple ADE) marks every setting required and refuses a create + # when one is missing. Endpoint Security and generic Catalog policies deploy fine as a subset, + # so validating them here would block working deployments. Both the family and the technology + # are read straight off the captured policy, so no extra Graph call is needed. + $TemplateFamily = $Policy.templateReference.templateFamily + if ($TemplateFamily -like 'enrollment*' -or $Policy.technologies -match 'enrollment') { + $PresentIds = @($Policy.settings.settingInstance.settingInstanceTemplateReference.settingInstanceTemplateId | Where-Object { $_ }) + $MissingTemplates = @($AvailableSettings | Where-Object { + $_.settingInstanceTemplate.isRequired -eq $true -and + $_.settingInstanceTemplate.settingInstanceTemplateId -notin $PresentIds + }) + if ($MissingTemplates.Count -gt 0) { + $MissingNames = @($MissingTemplates | ForEach-Object { + $DefId = $_.settingInstanceTemplate.settingDefinitionId + $Friendly = ($_.settingDefinitions | Where-Object { $_.id -eq $DefId } | Select-Object -First 1).displayName + if ($Friendly) { $Friendly } else { $DefId } + }) + throw "This enrollment policy template is missing $($MissingTemplates.Count) setting(s) that Microsoft now requires: $($MissingNames -join ', '). Microsoft periodically adds new required Setup Assistant options to Apple enrollment policies, and a template captured before they existed can no longer be deployed. Re-create this template from a tenant where the policy is fully configured (open and save it in Intune so the new options are added), then deploy again." + } + } + } + $Policy.settings = $FilteredSettings return $Policy } diff --git a/Modules/CIPPCore/Public/Set-CIPPIntunePolicy.ps1 b/Modules/CIPPCore/Public/Set-CIPPIntunePolicy.ps1 index 22b7abd94fd20..445ed7be1aaf9 100644 --- a/Modules/CIPPCore/Public/Set-CIPPIntunePolicy.ps1 +++ b/Modules/CIPPCore/Public/Set-CIPPIntunePolicy.ps1 @@ -211,10 +211,31 @@ function Set-CIPPIntunePolicy { } $Template = $RawJSON | ConvertFrom-Json + + # Apple enrollment (ADE) policies must carry a creationSource that binds them to this + # tenant's ADE token ("DepTokenId_{tokenId}"). The token id is per tenant, so templates + # store a %ADETokenId% placeholder that Get-CIPPTextReplacement (run above) resolves + # from the tenant's custom variable. Missing it, the DCV2 create fails with an opaque + # generic error - so fail early with the tenant's real token id(s) to set instead. + $IsEnrollmentPolicy = $Template.templateReference.templateFamily -like 'enrollment*' -or $Template.technologies -match 'enrollment' + if ($IsEnrollmentPolicy -and (-not $Template.creationSource -or $Template.creationSource -match '%')) { + try { $DepTokens = @(New-GraphGETRequest -uri 'https://graph.microsoft.com/beta/deviceManagement/depOnboardingSettings' -tenantid $TenantFilter) } catch { $DepTokens = @() } + $TokenHint = if ($DepTokens.Count -eq 0) { + 'This tenant has no Apple ADE/DEP token - connect one under Apple enrollment first.' + } elseif ($DepTokens.Count -eq 1) { + "Create a tenant custom variable named 'ADETokenId' set to '$($DepTokens[0].id)', then redeploy." + } else { + "Create a tenant custom variable named 'ADETokenId' set to one of this tenant's ADE token ids ($(@($DepTokens.id) -join ', ')), then redeploy." + } + throw "Apple enrollment policy '$DisplayName' has no ADE token binding. $TokenHint" + } + if ($Template.templateReference.templateId) { # Remove settings this tenant does not offer. The comparison paths run the # baseline through the same helper so they diff against what actually lands. - $Template = Select-CIPPIntuneAvailableSetting -Policy $Template -TenantFilter $TenantFilter + # ThrowOnMissingRequired turns Graph's opaque "required Setting not present" + # rejection into a named, actionable error for stale Apple enrollment templates. + $Template = Select-CIPPIntuneAvailableSetting -Policy $Template -TenantFilter $TenantFilter -ThrowOnMissingRequired $RawJSON = ConvertTo-Json -InputObject $Template -Depth 100 -Compress } @@ -222,7 +243,10 @@ function Set-CIPPIntunePolicy { $CatalogTemplateId = $Template.templateReference.templateId $FuzzyResult = Find-CIPPFuzzyPolicyMatch -DisplayName $DisplayName -ExistingPolicies $CheckExististing -MaxDistance $LevenshteinDistance -NameProperty 'name' -TemplateId $CatalogTemplateId if ($FuzzyResult) { - $PolicyFile = $RawJSON | ConvertFrom-Json | Select-Object * -ExcludeProperty Platform, PolicyType, CreationSource + # CreationSource is a read-only echo on ordinary Catalog policies, but on an + # enrollment policy it is the token binding and must survive the edit (PUT). + $ExcludeOnEdit = if ($IsEnrollmentPolicy) { @('Platform', 'PolicyType') } else { @('Platform', 'PolicyType', 'CreationSource') } + $PolicyFile = $RawJSON | ConvertFrom-Json | Select-Object * -ExcludeProperty $ExcludeOnEdit $RawJSON = ConvertTo-Json -InputObject $PolicyFile -Depth 100 -Compress $ExistingID = $FuzzyResult.Policy if ($FuzzyResult.MatchType -eq 'fuzzy') { diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSelfServicePurchaseProducts.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSelfServicePurchaseProducts.ps1 index a96cef3be7938..646d2ca8abd59 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSelfServicePurchaseProducts.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSelfServicePurchaseProducts.ps1 @@ -5,11 +5,10 @@ function Set-CIPPDBCacheSelfServicePurchaseProducts { .DESCRIPTION Reads the AllowSelfServicePurchase product policy list from the M365 licensing service - (licensing.m365.microsoft.com, scope aeb86249-8ea3-49e2-900b-54cc8e308f85/.default) and - the trial autoclaim policy from admin.microsoft.com, the same calls - Invoke-CIPPStandardDisableSelfServiceLicenses makes. Requires the tenant GDAP - relationship to include the 'Billing Administrator' role. The autoclaim policy is - cached as an extra row (productId 'autoclaim') and is non-fatal if unreachable. + (licensing.m365.microsoft.com, scope aeb86249-8ea3-49e2-900b-54cc8e308f85/.default, + app-only) and the trial autoclaim policy from admin.microsoft.com, the same calls + Invoke-CIPPStandardDisableSelfServiceLicenses makes. The autoclaim policy is cached + as an extra row (productId 'autoclaim') and is non-fatal if unreachable. .PARAMETER TenantFilter The tenant to cache self-service purchase products for @@ -27,7 +26,7 @@ function Set-CIPPDBCacheSelfServicePurchaseProducts { try { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Caching self-service purchase products' -sev Debug - $SelfServiceItems = (New-GraphGetRequest -scope 'aeb86249-8ea3-49e2-900b-54cc8e308f85/.default' -uri 'https://licensing.m365.microsoft.com/v1.0/policies/AllowSelfServicePurchase/products' -tenantid $TenantFilter).items + $SelfServiceItems = (New-GraphGetRequest -scope 'aeb86249-8ea3-49e2-900b-54cc8e308f85/.default' -uri 'https://licensing.m365.microsoft.com/v1.0/policies/AllowSelfServicePurchase/products' -tenantid $TenantFilter -AsApp $true).items $Results = [System.Collections.Generic.List[object]]::new() foreach ($Item in $SelfServiceItems) { diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSharePointPermissions.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSharePointPermissions.ps1 index 85f50a6609b7e..ec4bc6f671f88 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSharePointPermissions.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheSharePointPermissions.ps1 @@ -111,6 +111,11 @@ function Set-CIPPDBCacheSharePointPermissions { Parameters = @{ TenantFilter = $TenantFilter ExpectedSiteCount = $ExpectedSiteCount + # The full expected site-id set lets Push-StoreSharePointPermissions tell a site + # whose batch failed this run (carry its prior rows over, flagged Skipped) from + # one that no longer exists (let it fall out), so a single flaky batch no longer + # discards the whole run and empties the report. + ExpectedSiteIds = @($Sites.id) } } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecAccessChecks.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecAccessChecks.ps1 index 185cc32f322ba..559fb26481ee0 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecAccessChecks.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecAccessChecks.ps1 @@ -16,10 +16,19 @@ function Invoke-ExecAccessChecks { $4HoursAgo = (Get-Date).AddHours(-1).ToUniversalTime() $TimestampFilter = $4HoursAgo.ToString('yyyy-MM-ddTHH:mm:ss.fffK') + # Which self-diagnostic to run: Permissions, Tenants or GDAP. Read from either the query + # string or the body: the UI calls this as a GET with ?Type=, while a POST dispatcher (the + # MCP gateway documents it as POST because it also reads a body field) delivers it in the + # body - reading only the query left both empty and returned an empty result for every Type. + $Type = $Request.Query.Type ?? $Request.Body.Type + # Re-run the check instead of serving the cached result. - $SkipCache = $Request.Query.SkipCache -eq $true + $SkipCache = ($Request.Query.SkipCache ?? $Request.Body.SkipCache) -eq $true + + # The tenant to (re)check for the 'Tenants' type. Query or body, for the same reason as Type. + $TenantId = $Request.Body.TenantId ?? $Request.Query.TenantId - switch ($Request.Query.Type) { + switch ($Type) { 'Permissions' { if (-not $SkipCache) { try { @@ -43,7 +52,7 @@ function Invoke-ExecAccessChecks { } 'Tenants' { $AccessChecks = Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'TenantAccessChecks'" - if (!$Request.Body.TenantId) { + if (!$TenantId) { try { $Tenants = Get-Tenants -IncludeErrors | Where-Object { $_.customerId -ne $env:TenantID } $Results = foreach ($Tenant in $Tenants) { @@ -109,8 +118,8 @@ function Invoke-ExecAccessChecks { $Message = Test-CIPPAccessTenant -Headers $Request.Headers } - if ($Request.Body.TenantId) { - $Tenant = Get-Tenants -TenantFilter $Request.Body.TenantId + if ($TenantId) { + $Tenant = Get-Tenants -TenantFilter $TenantId $null = Test-CIPPAccessTenant -Tenant $Tenant.customerId -Headers $Request.Headers $Results = "Refreshing tenant $($Tenant.displayName)" } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListInstanceDiagnostics.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListInstanceDiagnostics.ps1 new file mode 100644 index 0000000000000..4feef89816f89 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListInstanceDiagnostics.ps1 @@ -0,0 +1,393 @@ +function Invoke-ListInstanceDiagnostics { + <# + .FUNCTIONALITY + Entrypoint,AnyTenant + .ROLE + CIPP.SuperAdmin.Read + .DESCRIPTION + Self diagnostics for this instance. Checks turns the recorded InstanceHealth samples + into a pass/warn/fail list with a suggested fix per finding; Timeline returns the raw + buckets plus the restart and out-of-memory events, with the API clients that were + busiest in the hour leading up to each event. Requires SuperAdmin access. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Action = $Request.Query.Action ?? 'Checks' + + $Hours = 24 + if ($Request.Query.Hours) { $Hours = [int]$Request.Query.Hours } + if ($Hours -lt 1) { $Hours = 1 } + if ($Hours -gt 336) { $Hours = 336 } + + $BucketFormat = 'yyyy-MM-ddTHH:mm' + $BucketStyles = [System.Globalization.DateTimeStyles]::AssumeUniversal -bor [System.Globalization.DateTimeStyles]::AdjustToUniversal + + function ConvertFrom-HealthBucket { + param([string]$Bucket) + return [DateTime]::ParseExact($Bucket, $BucketFormat, [cultureinfo]::InvariantCulture, $BucketStyles) + } + + # Heap ceiling comes from the limit the runtime reported on the newest sample, then the GC + # hard limit the host set (hex bytes), then the default budget. Shared by Checks and Timeline + # so both report the same cap. + function Get-DiagnosticsHeapCapMb { + param($Samples) + $HeapCapMb = 2398 + if ($env:DOTNET_GCHeapHardLimit) { + try { $HeapCapMb = [int]([Convert]::ToInt64(($env:DOTNET_GCHeapHardLimit -replace '^0x', ''), 16) / 1MB) } catch { $HeapCapMb = 2398 } + } + $ReportedCap = @($Samples | Where-Object { [int]$_.GcHeapLimitMb -gt 0 }) | Select-Object -Last 1 + if ($ReportedCap) { $HeapCapMb = [int]$ReportedCap.GcHeapLimitMb } + return $HeapCapMb + } + + function Format-DiagnosticsBytes { + param([long]$Bytes) + if ($Bytes -ge 1GB) { return '{0:N1} GB' -f ($Bytes / 1GB) } + return '{0:N1} MB' -f ($Bytes / 1MB) + } + + try { + $Now = [DateTime]::UtcNow + $WindowStart = $Now.AddHours(-$Hours) + $StartBucket = $WindowStart.AddMinutes(-($WindowStart.Minute % 5)).ToString($BucketFormat) + + # One fixed partition, so this is a single partition-scoped RowKey range instead of a + # cross-partition scan. + $Table = Get-CIPPTable -TableName 'InstanceHealth' + $Rows = @(Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'InstanceHealth' and RowKey ge '$StartBucket'") + + $Samples = @($Rows | Where-Object { $_.Kind -eq 'sample' } | Sort-Object -Property Bucket) + $Boots = @($Rows | Where-Object { $_.Kind -eq 'boot' } | Sort-Object -Property Bucket) + $ClientRows = @($Rows | Where-Object { $_.Kind -eq 'client' }) + + # AppId -> totals over the whole window, used for both the client check and the + # per-event baselines. + $ClientTotals = @{} + foreach ($Row in $ClientRows) { + $AppId = [string]$Row.AppId + if (-not $ClientTotals.ContainsKey($AppId)) { + $ClientTotals[$AppId] = @{ AppId = $AppId; AppName = [string]$Row.AppName; IP = [string]$Row.IP; Count = 0 } + } + $ClientTotals[$AppId].Count += [int]$Row.Count + if ($Row.AppName) { $ClientTotals[$AppId].AppName = [string]$Row.AppName } + if ($Row.IP) { $ClientTotals[$AppId].IP = [string]$Row.IP } + } + + switch ($Action) { + 'Checks' { + $Results = [System.Collections.Generic.List[hashtable]]::new() + + $OomTotal = ($Samples | Measure-Object -Property OomCount -Sum).Sum ?? 0 + $Results.Add(@{ + Check = 'oom' + Status = if ($OomTotal -gt 0) { 'FAIL' } else { 'PASS' } + Detail = if ($OomTotal -gt 0) { "$OomTotal OutOfMemoryException(s) in the last ${Hours}h" } else { "No out-of-memory errors in the last ${Hours}h" } + Fix = if ($OomTotal -gt 0) { 'Move to a larger plan or reduce concurrent background work - the process is hitting its heap limit.' } else { $null } + }) + + $HeapCapMb = Get-DiagnosticsHeapCapMb -Samples $Samples + + # A window can hold live-only samples, so fall back to the live reading rather + # than reporting no data at all. + $PeakHeap = ($Samples | ForEach-Object { if ($null -ne $_.HeapMb) { [int]$_.HeapMb } elseif ($null -ne $_.HeapMbLive) { [int]$_.HeapMbLive } } | Measure-Object -Maximum).Maximum + if ($null -eq $PeakHeap -or $HeapCapMb -le 0) { + $Results.Add(@{ Check = 'heap-headroom'; Status = 'INFO'; Detail = 'No heap samples recorded in this window'; Fix = $null }) + } else { + $Percent = [math]::Round(($PeakHeap / $HeapCapMb) * 100, 1) + $HeapDetail = "Peak heap ${PeakHeap}MB of ${HeapCapMb}MB ($Percent%)" + if ($Percent -gt 100) { + # A single log window can straddle two containers, so a peak above the + # cap is a swap artefact rather than a real over-allocation. + $Results.Add(@{ Check = 'heap-headroom'; Status = 'WARN'; Detail = "$HeapDetail - log spans two containers (image swap)"; Fix = 'Re-check after the next full window on a single container.' }) + } elseif ($Percent -ge 90) { + $Results.Add(@{ Check = 'heap-headroom'; Status = 'FAIL'; Detail = $HeapDetail; Fix = 'Move to a larger plan - the instance is one burst away from an out-of-memory restart.' }) + } elseif ($Percent -ge 75) { + $Results.Add(@{ Check = 'heap-headroom'; Status = 'WARN'; Detail = $HeapDetail; Fix = 'Watch this - consider a larger plan or fewer concurrent scheduled tasks.' }) + } else { + $Results.Add(@{ Check = 'heap-headroom'; Status = 'PASS'; Detail = $HeapDetail; Fix = $null }) + } + } + + $WatchdogTotal = ($Samples | Measure-Object -Property WatchdogCount -Sum).Sum ?? 0 + $Results.Add(@{ + Check = 'watchdog' + Status = if ($WatchdogTotal -gt 0) { 'WARN' } else { 'PASS' } + Detail = if ($WatchdogTotal -gt 0) { "$WatchdogTotal watchdog restart line(s) in the last ${Hours}h" } else { "No watchdog restarts in the last ${Hours}h" } + Fix = if ($WatchdogTotal -gt 0) { 'Check the container log around each restart - the process is failing to stay up.' } else { $null } + }) + + $PoolTotal = ($Samples | Measure-Object -Property PoolExhaustedCount -Sum).Sum ?? 0 + $Results.Add(@{ + Check = 'pool-exhausted' + Status = if ($PoolTotal -gt 0) { 'WARN' } else { 'PASS' } + Detail = if ($PoolTotal -gt 0) { "HTTP pool exhausted $PoolTotal time(s) in the last ${Hours}h" } else { "HTTP pool never exhausted in the last ${Hours}h" } + Fix = if ($PoolTotal -gt 0) { 'Requests are queuing for a runspace - reduce parallel API clients or move to a larger plan.' } else { $null } + }) + + $StalledTotal = ($Samples | Measure-Object -Property StalledRunCount -Sum).Sum ?? 0 + $Results.Add(@{ + Check = 'stalled-runs' + Status = if ($StalledTotal -gt 0) { 'WARN' } else { 'PASS' } + Detail = if ($StalledTotal -gt 0) { "$StalledTotal stalled orchestrator run report(s) in the last ${Hours}h" } else { "No stalled orchestrator runs in the last ${Hours}h" } + Fix = if ($StalledTotal -gt 0) { 'Runs have pending work but nothing running - cancel the stuck run from Worker Health and let it re-queue.' } else { $null } + }) + + $EgressSamples = @($Samples | Where-Object { $null -ne $_.EgressBytesToday }) + if ($EgressSamples.Count -eq 0) { + $Results.Add(@{ Check = 'egress'; Status = 'INFO'; Detail = 'No API egress recorded in this window - egress accounting is off or no API client traffic was served'; Fix = $null }) + } else { + $NewestEgress = $EgressSamples | Sort-Object -Property Bucket | Select-Object -Last 1 + $TodayBytes = [long]$NewestEgress.EgressBytesToday + $CapSample = @($Samples | Where-Object { [long]$_.EgressCapBytes -gt 0 }) | Select-Object -Last 1 + $CapBytes = if ($CapSample) { [long]$CapSample.EgressCapBytes } else { $null } + $EgressRejectTotal = ($Samples | Measure-Object -Property EgressRejectCount -Sum).Sum ?? 0 + + if ($EgressRejectTotal -gt 0) { + # Distinct client names across the window's reject lists, in first-seen order. + $RejectClients = [System.Collections.Generic.List[string]]::new() + $Seen = [System.Collections.Generic.HashSet[string]]::new() + foreach ($RejectSample in ($Samples | Where-Object { $_.EgressRejectClients })) { + try { + foreach ($ClientName in @($RejectSample.EgressRejectClients | ConvertFrom-Json)) { + if ($Seen.Add($ClientName)) { $RejectClients.Add($ClientName) } + } + } catch {} + } + $CapDisplay = if ($CapBytes) { Format-DiagnosticsBytes -Bytes $CapBytes } else { 'unknown' } + $Results.Add(@{ + Check = 'egress' + Status = 'FAIL' + Detail = "API egress cap reached: $EgressRejectTotal request(s) rejected with 429, clients: $($RejectClients -join ', '); served $(Format-DiagnosticsBytes -Bytes $TodayBytes) of $CapDisplay" + Fix = 'Identify which integration is pulling the most data and throttle it, or raise the daily egress budget.' + }) + } elseif ($CapBytes) { + $Percent = [math]::Round(($TodayBytes / $CapBytes) * 100, 1) + $EgressDetail = "Served $(Format-DiagnosticsBytes -Bytes $TodayBytes) of $(Format-DiagnosticsBytes -Bytes $CapBytes) today ($Percent%)" + if ($Percent -ge 75) { + $Results.Add(@{ Check = 'egress'; Status = 'WARN'; Detail = $EgressDetail; Fix = $null }) + } else { + $Results.Add(@{ Check = 'egress'; Status = 'PASS'; Detail = $EgressDetail; Fix = $null }) + } + } else { + $Results.Add(@{ Check = 'egress'; Status = 'INFO'; Detail = "Served $(Format-DiagnosticsBytes -Bytes $TodayBytes) today (no daily budget set)"; Fix = $null }) + } + } + + $TotalAccess = 0 + foreach ($Client in $ClientTotals.Values) { $TotalAccess += $Client.Count } + $TopClient = $ClientTotals.Values | Sort-Object -Property Count -Descending | Select-Object -First 1 + if ($TopClient -and $TotalAccess -gt 0 -and $TopClient.Count -ge 10000 -and ($TopClient.Count / $TotalAccess) -ge 0.5) { + $Share = [math]::Round(($TopClient.Count / $TotalAccess) * 100) + $Results.Add(@{ + Check = 'api-clients' + Status = 'WARN' + Detail = "API client $($TopClient.AppName) ($($TopClient.IP)) made $($TopClient.Count) of $TotalAccess authenticated API accesses ($Share%)" + Fix = 'A single integration dominates this instance - throttle it or give it its own instance.' + }) + } else { + $TopDetail = if ($TopClient) { "busiest: $($TopClient.AppName) ($($TopClient.Count))" } else { 'no API clients seen' } + $Results.Add(@{ + Check = 'api-clients' + Status = 'INFO' + Detail = "$TotalAccess authenticated API accesses from $($ClientTotals.Count) client(s) in the last ${Hours}h, $TopDetail" + Fix = $null + }) + } + + $RestartCount = $Boots.Count + $Results.Add(@{ + Check = 'restarts' + Status = if ($RestartCount -gt 2) { 'WARN' } elseif ($RestartCount -ge 1) { 'INFO' } else { 'PASS' } + Detail = if ($RestartCount -gt 2) { "Container restarted $RestartCount times in the last ${Hours}h" } elseif ($RestartCount -ge 1) { "Container restarted $RestartCount time(s) in the last ${Hours}h" } else { "No restarts in the last ${Hours}h" } + Fix = if ($RestartCount -gt 2) { 'Repeated restarts usually follow an out-of-memory kill or an auto-update loop - check the timeline.' } else { $null } + }) + + try { + $Runs = @([Craft.Services.WorkerMetricsBridge]::GetRunSummaries()) + $Stalled = [System.Collections.Generic.List[string]]::new() + foreach ($Run in $Runs) { + if (Test-CIPPStalledRun -Run $Run -Now $Now) { + $Name = [string]$Run.Name + $Stalled.Add($(if ($Name) { $Name } else { 'unnamed run' })) + } + } + $Results.Add(@{ + Check = 'orchestrator' + Status = if ($Stalled.Count -gt 0) { 'FAIL' } else { 'PASS' } + Detail = if ($Stalled.Count -gt 0) { "Stalled for over 2h with pending work: $($Stalled -join ', ')" } else { 'No stalled orchestrator runs' } + Fix = if ($Stalled.Count -gt 0) { 'Cancel the run from Worker Health so its work re-queues on the next timer.' } else { $null } + }) + } catch { + $Results.Add(@{ Check = 'orchestrator'; Status = 'INFO'; Detail = 'Worker metrics not available'; Fix = $null }) + } + + # ARM-only, so it exists on hosted instances and is skipped everywhere else. + if ($env:WEBSITE_SITE_NAME) { + $SiteName = $env:WEBSITE_SITE_NAME + $Subscription = $null + $RGName = $null + try { + $Subscription = Get-CIPPAzFunctionAppSubId + $RGName = Get-CIPPFunctionAppResourceGroup -SiteName $SiteName + } catch { + Write-Information "Could not resolve ARM site details: $($_.Exception.Message)" + } + + if ($Subscription -and $RGName) { + try { + $Uri = "https://management.azure.com/subscriptions/$Subscription/resourceGroups/$RGName/providers/Microsoft.Web/sites/$SiteName/containerlogs?api-version=2023-12-01" + $ContainerLog = New-CIPPAzRestRequest -Uri $Uri -Method POST + if ($ContainerLog -isnot [string]) { $ContainerLog = [string]$ContainerLog } + $Cutoff = $Now.AddHours(-24) + $Stopping = 0 + foreach ($Line in ($ContainerLog -split "`n")) { + if ($Line -notmatch 'State:\s*Stopping') { continue } + # Undated lines are counted; the endpoint only returns recent log. + if ($Line -match '^(\d{4}-\d{2}-\d{2}T[\d:.]+)') { + try { if ([DateTime]::Parse($Matches[1]).ToUniversalTime() -lt $Cutoff) { continue } } catch {} + } + $Stopping++ + } + $Results.Add(@{ + Check = 'container-log' + Status = if ($Stopping -gt 2) { 'WARN' } else { 'PASS' } + Detail = "$Stopping container stop event(s) in the platform log in the last 24h" + Fix = if ($Stopping -gt 2) { 'The platform is cycling the container - check the restart and out-of-memory checks above.' } else { $null } + }) + } catch { + $Results.Add(@{ Check = 'container-log'; Status = 'INFO'; Detail = 'Platform container log not available'; Fix = $null }) + } + } else { + $Results.Add(@{ Check = 'container-log'; Status = 'INFO'; Detail = 'Platform container log not available'; Fix = $null }) + } + } + + $Body = @{ Results = @($Results) } + } + 'Timeline' { + # Bucket -> AppId -> count, so an event can look back over the preceding hour + # without re-scanning every row. + $ClientsByBucket = @{} + foreach ($Row in $ClientRows) { + $Bucket = [string]$Row.Bucket + if (-not $ClientsByBucket.ContainsKey($Bucket)) { $ClientsByBucket[$Bucket] = @{} } + $AppId = [string]$Row.AppId + $ClientsByBucket[$Bucket][$AppId] = [int]$ClientsByBucket[$Bucket][$AppId] + [int]$Row.Count + } + + $Buckets = [System.Collections.Generic.List[hashtable]]::new() + foreach ($Sample in $Samples) { + $Bucket = [string]$Sample.Bucket + $BucketClients = [System.Collections.Generic.List[hashtable]]::new() + if ($ClientsByBucket.ContainsKey($Bucket)) { + foreach ($Entry in $ClientsByBucket[$Bucket].GetEnumerator()) { + $BucketClients.Add(@{ + AppId = $Entry.Key + AppName = [string]$ClientTotals[$Entry.Key].AppName + IP = [string]$ClientTotals[$Entry.Key].IP + Count = $Entry.Value + }) + } + } + $TopEndpoints = @{} + if ($Sample.TopEndpointsMs) { + try { $TopEndpoints = $Sample.TopEndpointsMs | ConvertFrom-Json -AsHashtable } catch {} + } + $Buckets.Add(@{ + Bucket = $Bucket + OomCount = [int]$Sample.OomCount + WatchdogCount = [int]$Sample.WatchdogCount + PoolExhaustedCount = [int]$Sample.PoolExhaustedCount + ErrCount = [int]$Sample.ErrCount + MaxLimiterWaitMs = [int]$Sample.MaxLimiterWaitMs + StalledRunCount = [int]$Sample.StalledRunCount + HeapMb = if ($null -ne $Sample.HeapMb) { [int]$Sample.HeapMb } else { $null } + HeapMbLive = if ($null -ne $Sample.HeapMbLive) { [int]$Sample.HeapMbLive } else { $null } + EgressBytes = if ($null -ne $Sample.EgressBytes) { [long]$Sample.EgressBytes } else { $null } + EgressBytesToday = if ($null -ne $Sample.EgressBytesToday) { [long]$Sample.EgressBytesToday } else { $null } + TopEndpointsMs = $TopEndpoints + Clients = @($BucketClients) + }) + } + + # Baseline is per-hour, so an event's 60 minute lead-in compares like for like. + $WindowHours = [math]::Max($Hours, 1) + + $Events = [System.Collections.Generic.List[hashtable]]::new() + $EventSources = [System.Collections.Generic.List[hashtable]]::new() + foreach ($Boot in $Boots) { + $EventSources.Add(@{ Bucket = [string]$Boot.Bucket; Type = 'boot'; GapMinutes = if ($null -ne $Boot.GapMinutes) { [int]$Boot.GapMinutes } else { $null } }) + } + foreach ($Sample in ($Samples | Where-Object { [int]$_.OomCount -gt 0 })) { + $EventSources.Add(@{ Bucket = [string]$Sample.Bucket; Type = 'oom'; GapMinutes = $null }) + } + + foreach ($Source in ($EventSources | Sort-Object -Property { $_.Bucket })) { + $EventTime = ConvertFrom-HealthBucket -Bucket $Source.Bucket + $LeadIn = @{} + for ($Offset = 5; $Offset -le 60; $Offset += 5) { + $Key = $EventTime.AddMinutes(-$Offset).ToString($BucketFormat) + if (-not $ClientsByBucket.ContainsKey($Key)) { continue } + foreach ($Entry in $ClientsByBucket[$Key].GetEnumerator()) { + $LeadIn[$Entry.Key] = [int]$LeadIn[$Entry.Key] + $Entry.Value + } + } + + $TopClients = [System.Collections.Generic.List[hashtable]]::new() + foreach ($Entry in ($LeadIn.GetEnumerator() | Sort-Object -Property Value -Descending | Select-Object -First 3)) { + $Baseline = [math]::Round($ClientTotals[$Entry.Key].Count / $WindowHours, 2) + $TopClients.Add(@{ + AppId = $Entry.Key + AppName = [string]$ClientTotals[$Entry.Key].AppName + IP = [string]$ClientTotals[$Entry.Key].IP + Count = $Entry.Value + Baseline = $Baseline + Ratio = if ($Baseline -gt 0) { [math]::Round($Entry.Value / $Baseline, 2) } else { $null } + }) + } + + $Events.Add(@{ + Bucket = $Source.Bucket + Type = $Source.Type + GapMinutes = $Source.GapMinutes + TopClients = @($TopClients) + }) + } + + $EgressCapSample = @($Samples | Where-Object { [long]$_.EgressCapBytes -gt 0 }) | Select-Object -Last 1 + $EgressAvailable = @($Samples | Where-Object { $null -ne $_.EgressBytesToday }).Count -gt 0 + + $Body = @{ + Results = @{ + Buckets = @($Buckets) + Events = @($Events) + HeapCapMb = Get-DiagnosticsHeapCapMb -Samples $Samples + EgressCapBytes = if ($EgressCapSample) { [long]$EgressCapSample.EgressCapBytes } else { $null } + EgressAvailable = $EgressAvailable + } + } + } + default { + return [HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @{ Results = "Unknown action: $Action" } + } + } + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API $APIName -message "Instance diagnostics error: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + return [HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::InternalServerError + Body = @{ Results = "Failed: $($ErrorMessage.NormalizedError)" } + } + } + + return [HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = $Body + } +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecTokenExchange.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecTokenExchange.ps1 index 0d986f51f3f49..69f952ecf09f9 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecTokenExchange.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Setup/Invoke-ExecTokenExchange.ps1 @@ -77,10 +77,9 @@ function Invoke-ExecTokenExchange { if (-not $SAMCert) { throw 'Certificate authentication is required but no SAM certificate is available. Complete the application step first, then retry.' } - # Assertion audience = the tenant the sign-in targets ($env:TenantID). The body's tenantId is - # actually the app id, so it is not a valid audience; fall back to the multi-tenant authority. - $GuidPattern = '^[0-9a-f]{8}-([0-9a-f]{4}-){3}[0-9a-f]{12}$' - $AssertionTenant = if ($env:TenantID -match $GuidPattern) { $env:TenantID } else { 'organizations' } + # aud must equal the token endpoint we POST to (validated above). Do not use + # $env:TenantID: the frontend posts to /organizations, and a partner-GUID aud + # produces AADSTS700023. Body tenantId is the app id, not a realm. $FormData.Remove('client_secret') $FormData['client_assertion_type'] = 'urn:ietf:params:oauth:client-assertion-type:jwt-bearer' Write-LogMessage -API $APIName -message 'Using the SAM certificate assertion for the token exchange' -Sev 'Debug' @@ -93,7 +92,7 @@ function Invoke-ExecTokenExchange { $MaxAttempts = if ($UseCertAssertion) { 3 } else { 1 } for ($Attempt = 1; $Attempt -le $MaxAttempts; $Attempt++) { if ($UseCertAssertion) { - $FormData['client_assertion'] = New-CIPPCertificateAssertion -TenantId $AssertionTenant -AppId $AppId -Certificate $SAMCert.Certificate + $FormData['client_assertion'] = New-CIPPCertificateAssertion -TenantId 'organizations' -AppId $AppId -Certificate $SAMCert.Certificate -Audience $TokenUrl } $Results = Invoke-RestMethod -Uri $TokenUrl -Method Post -Body $FormData -ContentType 'application/x-www-form-urlencoded' -ErrorAction Stop -SkipHttpErrorCheck if ($UseCertAssertion -and $Attempt -lt $MaxAttempts -and $Results.error_description -match 'AADSTS700027') { diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ListExoRequest.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ListExoRequest.ps1 index b2a160cd135b7..d2ea8c0143149 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ListExoRequest.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Email-Exchange/Tools/Invoke-ListExoRequest.ps1 @@ -15,7 +15,11 @@ function Invoke-ListExoRequest { ) $Cmdlet = $Request.Body.Cmdlet - $cmdParams = if ($Request.Body.cmdParams) { $Request.Body.cmdParams } else { [PSCustomObject]@{} } + # Parameters to splat onto the Exchange cmdlet, as an object of name/value pairs + # (e.g. { "Identity": "user@contoso.com" }). Cast to an object so the generated schema + # types cmdParams as an object rather than a string - a string-typed schema made the + # client reject an object body, leaving no way to pass parameters. + $cmdParams = if ($Request.Body.cmdParams) { [pscustomobject]$Request.Body.cmdParams } else { [PSCustomObject]@{} } $Verb = ($Cmdlet -split '-')[0] $TenantFilter = $Request.Body.TenantFilter diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListPIMRoles.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListPIMRoles.ps1 index 42303dfda204a..735e0e56e1928 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListPIMRoles.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Roles/Invoke-ListPIMRoles.ps1 @@ -76,6 +76,8 @@ function Invoke-ListPIMRoles { PIMCapable = $Meta.PIMCapable PolicySummary = $Meta.PolicySummary PolicyBelowFloor = $Meta.PolicyBelowFloor + PolicySettings = $Meta.PolicySettings + FloorIssues = @($Meta.FloorIssues) MemberCount = $Assignments.Count PermanentCount = $PermanentCount EligibleCount = $EligibleCount diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUser.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUser.ps1 index 5f36856d9bce8..80c3d4ea9d757 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUser.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUser.ps1 @@ -26,6 +26,21 @@ function Invoke-AddUser { }) } + # User creation is single-tenant only. Without this guard an 'AllTenants' (or otherwise + # unresolvable) tenantFilter fails Get-AuthorisedRequest, the Graph write helpers return + # $null non-terminating, and the endpoint reports success while creating nothing. + if ($UserObj.tenantFilter -eq 'AllTenants' -or -not (Get-Tenants -TenantFilter $UserObj.tenantFilter)) { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = [pscustomobject]@{ + 'Results' = @{ + resultText = 'User creation is single-tenant only. Select a specific tenant before creating a user.' + state = 'error' + } + } + }) + } + if ($UserObj.Scheduled.Enabled) { try { $Username = $UserObj.username ?? $UserObj.mailNickname diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUserBulk.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUserBulk.ps1 index 67ddccdaddea4..d7066114fecea 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUserBulk.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Administration/Users/Invoke-AddUserBulk.ps1 @@ -12,6 +12,21 @@ function Invoke-AddUserBulk { # Interact with body parameters or the body of the request. $TenantFilter = $Request.Body.tenantFilter + # Bulk user creation is single-tenant only. Without this guard an 'AllTenants' (or otherwise + # unresolvable) tenantFilter makes New-GraphBulkRequest return $null non-terminating, so the + # results loop runs zero times and the endpoint reports success while creating nothing. + if (-not $TenantFilter -or $TenantFilter -eq 'AllTenants' -or -not (Get-Tenants -TenantFilter $TenantFilter)) { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @{ + Results = @{ + resultText = 'Bulk user creation is single-tenant only. Select a specific tenant before creating users.' + state = 'error' + } + } + }) + } + $BulkUsers = $Request.Body.BulkUser $AssignedLicenses = $Request.Body.licenses $UsageLocation = $Request.Body.usageLocation diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListAzureADConnectStatus.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListAzureADConnectStatus.ps1 index 9dda69a4c3be8..a892e9884d5a8 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListAzureADConnectStatus.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListAzureADConnectStatus.ps1 @@ -15,9 +15,19 @@ Function Invoke-ListAzureADConnectStatus { if (($DataToReturn -eq 'AzureADConnectSettings') -or ([string]::IsNullOrEmpty($DataToReturn)) ) { $ADConnectStatusGraph = New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/organization' -tenantid $TenantFilter + $LastSyncDateTime = $ADConnectStatusGraph.onPremisesLastSyncDateTime + # The field name promises hours since the last on-prem sync, but it was returning the raw + # timestamp. Compute the actual elapsed hours ($null when the tenant has never synced); the + # timestamp itself is still available under lastSyncDateTime and raw. + $HoursFromLastSync = if ($LastSyncDateTime) { + [math]::Round(((Get-Date).ToUniversalTime() - ([datetime]$LastSyncDateTime).ToUniversalTime()).TotalHours, 2) + } else { + $null + } $AzureADConnectSettings = [PSCustomObject]@{ dirSyncEnabled = [boolean]$ADConnectStatusGraph.onPremisesSyncEnabled - numberOfHoursFromLastSync = $ADConnectStatusGraph.onPremisesLastSyncDateTime + numberOfHoursFromLastSync = $HoursFromLastSync + lastSyncDateTime = $LastSyncDateTime raw = $ADConnectStatusGraph } } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListSignIns.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListSignIns.ps1 index 6bb5e6ceec6f6..9fe2afde0a1cf 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListSignIns.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Identity/Reports/Invoke-ListSignIns.ps1 @@ -6,6 +6,10 @@ Function Invoke-ListSignIns { Identity.AuditLog.Read .DESCRIPTION Lists recent sign-in log entries for a tenant, filterable by various criteria. Supports AllTenants queries. + + Deprecated: use ListGraphRequest with Endpoint=auditLogs/signIns instead, which supports $filter, $top, + $orderby, and manualPagination with nextLink continuation. This endpoint returns at most one page of + results and will be removed in a future release. #> [CmdletBinding()] param($Request, $TriggerMetadata) @@ -36,7 +40,8 @@ Function Invoke-ListSignIns { Write-Host $Filters Write-LogMessage -headers $Headers -API $APINAME -message 'Retrieved sign in report' -Sev 'Debug' -tenant $TenantFilter - $GraphRequest = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/auditLogs/signIns?api-version=beta&`$filter=$($Filters)" -tenantid $TenantFilter -ErrorAction Stop + # Single page only: full-range paging belongs to ListGraphRequest with manualPagination. + $GraphRequest = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/auditLogs/signIns?api-version=beta&`$filter=$($Filters)" -tenantid $TenantFilter -noPagination $true -ErrorAction Stop $response = $GraphRequest | Select-Object *, @{l = 'additionalDetails'; e = { $_.status.additionalDetails } } , @{l = 'errorCode'; e = { $_.status.errorCode } }, @@ -49,6 +54,7 @@ Function Invoke-ListSignIns { return ([HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK Body = @($response) + Headers = @{ 'Deprecation' = 'true' } }) } catch { Write-LogMessage -headers $Request.Headers -API $APINAME -message "Failed to retrieve Sign In report: $($_.Exception.message) " -Sev 'Error' -tenant $TenantFilter diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSharepointQuota.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSharepointQuota.ps1 index 01ca13eb14bd0..e4f6226c48a47 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSharepointQuota.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Teams-Sharepoint/Invoke-ListSharepointQuota.ps1 @@ -29,8 +29,12 @@ Function Invoke-ListSharepointQuota { # tenants where the service account lacks SharePoint admin rights, which made this # endpoint silently return 'Not available'. $SharePointQuota = New-GraphGetRequest -extraHeaders $extraHeaders -scope "$($SharePointInfo.AdminUrl)/.default" -tenantid $TenantFilter -uri "$($SharePointInfo.AdminUrl)/_api/StorageQuotas()?api-version=1.3.2" -asapp $true -UseCertificate - $GeoUsedStorageMB = ($SharePointQuota.GeoUsedStorageMB | Measure-Object -Sum).Sum - $TenantStorageMB = $SharePointQuota.TenantStorageMB | Select-Object -First 1 + # The API types every figure as a string. Cast each geo's used storage before summing + # (Measure-Object -Sum does not add strings, so this returned $null), and cast the + # tenant pool, so both surface as numbers instead of a null and a string. + $GeoUsedStorageMB = (@($SharePointQuota) | ForEach-Object { [double]($_.GeoUsedStorageMB ?? 0) } | Measure-Object -Sum).Sum + $TenantStorageRaw = @($SharePointQuota.TenantStorageMB | Where-Object { $_ }) | Select-Object -First 1 + $TenantStorageMB = if ($null -ne $TenantStorageRaw) { [double]$TenantStorageRaw } else { 0 } # Per-geo detail so a Multi-Geo tenant can see where the used storage actually sits # rather than only a tenant-wide total. The API types every figure as a string, so diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ListCAPolicyCoverage.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ListCAPolicyCoverage.ps1 new file mode 100644 index 0000000000000..810f1b31db3bf --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Conditional/Invoke-ListCAPolicyCoverage.ps1 @@ -0,0 +1,44 @@ +function Invoke-ListCAPolicyCoverage { + <# + .FUNCTIONALITY + Entrypoint + .ROLE + Tenant.ConditionalAccess.Read + .DESCRIPTION + Resolves identity assignment coverage for a single Conditional Access policy: which users + are touched by includes or exclusions, their net status (covered or excluded), and why + (users, transitive groups, roles, guests, special tokens). Does not evaluate apps, + locations, or sign-in what-if conditions. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Headers = $Request.Headers + + $TenantFilter = $Request.Query.tenantFilter ?? $Request.Body.tenantFilter + $PolicyId = $Request.Query.GUID ?? $Request.Body.GUID ?? $Request.Query.id ?? $Request.Body.id + + if ([string]::IsNullOrWhiteSpace($TenantFilter) -or [string]::IsNullOrWhiteSpace($PolicyId)) { + return ([HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::BadRequest + Body = @{ Results = 'tenantFilter and GUID (policy id) are required.' } + }) + } + + try { + $Results = Get-CIPPCAPolicyIdentityCoverage -TenantFilter $TenantFilter -PolicyId $PolicyId + Write-LogMessage -Headers $Headers -API $APIName -tenant $TenantFilter -message "Resolved identity coverage for CA policy $($Results.displayName)" -Sev Info + $StatusCode = [HttpStatusCode]::OK + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $Results = "Failed to resolve CA policy coverage: $($ErrorMessage.NormalizedError)" + Write-LogMessage -Headers $Headers -API $APIName -tenant $TenantFilter -message $Results -Sev Error -LogData $ErrorMessage + $StatusCode = [HttpStatusCode]::InternalServerError + } + + return ([HttpResponseContext]@{ + StatusCode = $StatusCode + Body = @{ Results = $Results } + }) +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecDomainAnalyser.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecDomainAnalyser.ps1 index 34fc4be7f5045..70a29d07ae921 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecDomainAnalyser.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Standards/Invoke-ExecDomainAnalyser.ps1 @@ -9,7 +9,9 @@ function Invoke-ExecDomainAnalyser { param($Request, $TriggerMetadata) # Call the wrapper - it handles queuing internally via Start-CIPPOrchestrator - $Params = @{} + $Params = @{ + SkipExchangeFilter = $true + } if ($Request.Body.tenantFilter) { $Params.TenantFilter = $Request.Body.tenantFilter.value ?? $Request.Body.tenantFilter } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-ListTestResultsTenants.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-ListTestResultsTenants.ps1 index 0c6523350c252..6c6c78700dd2c 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-ListTestResultsTenants.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/Tenant/Tests/Invoke-ListTestResultsTenants.ps1 @@ -21,15 +21,26 @@ function Invoke-ListTestResultsTenants { $APIName = $TriggerMetadata.FunctionName try { + # One or more tenant domains to report on. Omit, or pass 'AllTenants', to query every + # tenant the caller may see. Accepts a string, a comma-delimited string, or an array. $TenantFilterRaw = $Request.Query.tenantFilter ?? $Request.Body.tenantFilter + # One or more test IDs (the result row's RowKey), e.g. 'CustomScript-'. $TestIdRaw = $Request.Query.testId ?? $Request.Body.testId + # Narrow the scan to these statuses: Passed, Failed, Investigate, Skipped, Informational. $StatusRaw = $Request.Query.status ?? $Request.Body.status + # Restrict to a single test type: Identity, Devices or Custom. $TestType = $Request.Query.testType ?? $Request.Body.testType + # Restrict to a single risk level: High, Medium or Low. $Risk = $Request.Query.risk ?? $Request.Body.risk + # Restrict to a single category (the framework/area name a test belongs to). $Category = $Request.Query.category ?? $Request.Body.category + # 'true' to project away the large ResultMarkdown/ResultDataJson blobs for a lighter read. $SummaryOnly = $Request.Query.summaryOnly ?? $Request.Body.summaryOnly + # Return rows only for these statuses, while still counting every status the filters match. $RowStatusRaw = $Request.Query.rowStatus ?? $Request.Body.rowStatus + # 'true' to also return aggregate counts (per status, high-risk failures, distinct tenants). $IncludeCounts = $Request.Query.includeCounts ?? $Request.Body.includeCounts + # 'true' to return only the aggregate counts with no rows. Implies includeCounts. $CountsOnly = $Request.Query.countsOnly ?? $Request.Body.countsOnly # Normalise inputs that may arrive as a single string, a comma-delimited string, or an diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableGuests.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableGuests.ps1 index 3f7068abcda74..7236c0c4df80a 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableGuests.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableGuests.ps1 @@ -7,20 +7,21 @@ function Invoke-CIPPStandardDisableGuests { .SYNOPSIS (Label) Disable Guest accounts that have not logged on for a number of days .DESCRIPTION - (Helptext) Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone. - (DocsDescription) Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone. + (Helptext) Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Optionally soft-deletes already-disabled guests after a configurable grace period past that threshold (0 = never delete). Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone. Deleted guests remain recoverable from Deleted Items for about 30 days. + (DocsDescription) Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Remediation first disables stale enabled guests, and later soft-deletes guests that are already disabled once they have been inactive for the disable threshold plus the configured grace delta (deletion age = days + deleteGraceDays). The disable-before-delete grace is further guaranteed by never deleting a guest in the same pass it was disabled. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone. Graph user DELETE is a soft-delete (recoverable from Deleted Items for about 30 days), which lets a later re-invite create a clean guest object instead of colliding with a disabled account. .NOTES CAT Entra (AAD) Standards TAG "ZTNA21858" EXECUTIVETEXT - Automatically disables external guest accounts that haven't been used for a number of days, reducing security risks from dormant accounts while maintaining access for active external collaborators. This helps maintain a clean user directory and reduces potential attack vectors. + Automatically disables external guest accounts that haven't been used for a number of days, and can optionally remove already-disabled dormant guests after an additional grace period. This reduces security risks from abandoned external access, keeps the directory clean, and avoids errors when previously disabled guests need to be invited back. ADDEDCOMPONENT {"type":"number","name":"standards.DisableGuests.days","required":true,"defaultValue":90,"label":"Days of inactivity"} + {"type":"number","name":"standards.DisableGuests.deleteGraceDays","label":"Grace days after disable before deletion (0 = never delete). Guests are deleted once inactive for the disable threshold plus this many additional days.","defaultValue":0,"validators":{"min":{"value":0,"message":"Minimum value is 0"}}} {"type":"switch","name":"standards.DisableGuests.IncludeNeverSignedIn","label":"Disable accounts that have not yet signed in","defaultValue":false} IMPACT - Medium Impact + High Impact ADDEDDATE 2022-10-20 POWERSHELLEQUIVALENT @@ -48,54 +49,99 @@ function Invoke-CIPPStandardDisableGuests { return $true } #we're done. - $checkDays = if ($Settings.days) { $Settings.days } else { 90 } # Default to 90 days if not set. Pre v8.5.0 compatibility + $checkDays = if ($Settings.days) { [int]$Settings.days } else { 90 } # Default to 90 days if not set. Pre v8.5.0 compatibility # Off unless the template turns it on, so templates that predate the switch keep skipping guests with no sign-in on record. $IncludeNeverSignedIn = $Settings.IncludeNeverSignedIn -eq $true + # deleteGraceDays is a delta on top of days; missing/blank/0 preserves disable-only behaviour for existing templates. + $DeleteDelta = if ([string]::IsNullOrWhiteSpace([string]$Settings.deleteGraceDays)) { 0 } else { [int]$Settings.deleteGraceDays } + if ($DeleteDelta -lt 0) { $DeleteDelta = 0 } + $DeleteEnabled = $DeleteDelta -gt 0 + $DeleteAge = $checkDays + $DeleteDelta + $Days = (Get-Date).AddDays(-$checkDays).ToUniversalTime() $Lookup = $Days.ToString('o') - $AuditLookup = (Get-Date).AddDays(-7).ToUniversalTime().ToString('o') + $DeleteDate = (Get-Date).AddDays(-$DeleteAge).ToUniversalTime() + $DeleteLookup = $DeleteDate.ToString('o') + $GuestSelect = 'id,UserPrincipalName,signInActivity,mail,userType,accountEnabled,createdDateTime,externalUserState' + + # Annotates a guest with LastSignInDateTime / NeverSignedIn and returns $true when it is stale + # relative to $Cutoff. Newest of interactive, non-interactive and successful sign-in timestamps - + # the view the Entra portal and the inactive-guest alert give - rather than successful sign-ins + # alone, which stay old while a blocked or disabled guest keeps trying. + $TestStale = { + param($Guest, $Cutoff, [bool]$IncludeNeverSignedIn) + $LastSignIn = Get-CIPPLastSignInDateTime -SignInActivity $Guest.signInActivity + if ($LastSignIn) { + if ($LastSignIn -le $Cutoff) { + $Guest | Add-Member -NotePropertyMembers ([ordered]@{ + LastSignInDateTime = $LastSignIn + NeverSignedIn = $false + }) -Force + return $true + } + return $false + } + if ($IncludeNeverSignedIn) { + # No sign-in attempt on record; createdDateTime is already <= cutoff due to the server-side filter + $Guest | Add-Member -NotePropertyMembers ([ordered]@{ + LastSignInDateTime = $null + NeverSignedIn = $true + }) -Force + return $true + } + return $false + } try { - $GraphRequest = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users?`$filter=createdDateTime le $Lookup and userType eq 'Guest' and accountEnabled eq true &`$select=id,UserPrincipalName,signInActivity,mail,userType,accountEnabled,createdDateTime,externalUserState" -scope 'https://graph.microsoft.com/.default' -tenantid $Tenant - - $StaleGuests = foreach ($guest in $GraphRequest) { - # Newest of the interactive, non-interactive and successful sign-in timestamps - the view the - # Entra portal and the inactive-guest alert give - rather than successful sign-ins alone, which - # stay old while a blocked or disabled guest keeps trying. - $LastSignIn = Get-CIPPLastSignInDateTime -SignInActivity $guest.signInActivity - if ($LastSignIn) { - if ($LastSignIn -le $Days) { - $guest | Add-Member -NotePropertyMembers ([ordered]@{ - LastSignInDateTime = $LastSignIn - NeverSignedIn = $false - }) -Force + $EnabledGuests = @(New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users?`$filter=createdDateTime le $Lookup and userType eq 'Guest' and accountEnabled eq true&`$select=$GuestSelect" -scope 'https://graph.microsoft.com/.default' -tenantid $Tenant) + $GuestsToDisable = @(foreach ($guest in $EnabledGuests) { + if (& $TestStale $guest $Days $IncludeNeverSignedIn) { $guest } - } elseif ($IncludeNeverSignedIn) { - # No sign-in attempt on record; createdDateTime is already <= $Days due to the server-side filter - $guest | Add-Member -NotePropertyMembers ([ordered]@{ - LastSignInDateTime = $null - NeverSignedIn = $true - }) -Force - $guest - } + }) + + $GuestsToDelete = @() + $GuestsMeetingDeleteThreshold = @() + if ($DeleteEnabled) { + $DisabledGuests = @(New-GraphGetRequest -uri "https://graph.microsoft.com/beta/users?`$filter=createdDateTime le $DeleteLookup and userType eq 'Guest' and accountEnabled eq false&`$select=$GuestSelect" -scope 'https://graph.microsoft.com/.default' -tenantid $Tenant) + $GuestsMeetingDeleteThreshold = @(foreach ($guest in $DisabledGuests) { + if (& $TestStale $guest $DeleteDate $IncludeNeverSignedIn) { + $guest + } + }) + # Only already-disabled guests are deleted this run; guests disabled in this same pass are left for a later run. + $GuestsToDelete = @($GuestsMeetingDeleteThreshold) } - $GraphRequest = @($StaleGuests) } catch { $ErrorMessage = Get-NormalizedError -Message $_.Exception.Message Write-LogMessage -API 'Standards' -Tenant $Tenant -Message "Could not get the DisableGuests state for $Tenant. Error: $ErrorMessage" -Sev Error return } - $AuditResults = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/auditLogs/directoryAudits?`$filter=activityDisplayName eq 'Enable account' and activityDateTime ge $AuditLookup&`$select=targetResources" -scope 'https://graph.microsoft.com/.default' -tenantid $Tenant - $RecentlyReactivatedUsers = @(foreach ($AuditEntry in $AuditResults) { $AuditEntry.targetResources[0].id }) | Select-Object -Unique - - $GraphRequest = @($GraphRequest | Where-Object { -not ($RecentlyReactivatedUsers -contains $_.id) }) + # Same as baseline: audit only matters for the disable set. Skip it when empty so delete-only + # runs are not blocked by an audit failure, and swallow audit errors so a lookup outage cannot + # abort remediation (fail open on the 7-day re-enable skip). + if ($GuestsToDisable.Count -gt 0) { + $AuditLookup = (Get-Date).AddDays(-7).ToUniversalTime().ToString('o') + $RecentlyReactivatedUsers = @(try { + $AuditResults = New-GraphGetRequest -uri "https://graph.microsoft.com/beta/auditLogs/directoryAudits?`$filter=activityDisplayName eq 'Enable account' and activityDateTime ge $AuditLookup&`$select=targetResources" -scope 'https://graph.microsoft.com/.default' -tenantid $Tenant + @(foreach ($AuditEntry in $AuditResults) { $AuditEntry.targetResources[0].id }) | Select-Object -Unique + } catch { + Write-LogMessage -API 'Standards' -Tenant $Tenant -Message "DisableGuests: reactivation audit lookup failed: $($_.Exception.Message)" -Sev Warning + @() + }) + $GuestsToDisable = @($GuestsToDisable | Where-Object { $RecentlyReactivatedUsers -notcontains $_.id }) + } if ($Settings.remediate -eq $true) { - if ($GraphRequest.Count -gt 0) { + $DisabledCount = 0 + $DeletedCount = 0 + $FailedCount = 0 + $DeletedGuestIds = [System.Collections.Generic.List[string]]::new() + + if ($GuestsToDisable.Count -gt 0) { $int = 0 - $BulkRequests = foreach ($guest in $GraphRequest) { + $BulkRequests = foreach ($guest in $GuestsToDisable) { @{ id = $int++ method = 'PATCH' @@ -112,9 +158,10 @@ function Invoke-CIPPStandardDisableGuests { for ($i = 0; $i -lt $BulkResults.Count; $i++) { $result = $BulkResults[$i] - $guest = $GraphRequest[$i] + $guest = $GuestsToDisable[$i] if ($result.status -eq 200 -or $result.status -eq 204) { + $DisabledCount++ $guest.accountEnabled = $false $reason = if ($guest.NeverSignedIn) { "never signed in, created $($guest.createdDateTime)" @@ -123,54 +170,128 @@ function Invoke-CIPPStandardDisableGuests { } Write-LogMessage -API 'Standards' -tenant $tenant -message "Disabled guest $($guest.UserPrincipalName) ($($guest.id)). Reason: $reason" -sev Info } else { + $FailedCount++ $errorMsg = if ($result.body.error.message) { $result.body.error.message } else { "Unknown error (Status: $($result.status))" } Write-LogMessage -API 'Standards' -tenant $tenant -message "Failed to disable guest $($guest.UserPrincipalName) ($($guest.id)): $errorMsg" -sev Error } } } catch { $ErrorMessage = Get-CippException -Exception $_ + $FailedCount += $GuestsToDisable.Count Write-LogMessage -API 'Standards' -tenant $tenant -message "Failed to process bulk disable guests request: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage } - } else { + } + + if ($GuestsToDelete.Count -gt 0) { + $int = 0 + $DeleteMap = @{} + $DeleteRequests = foreach ($guest in $GuestsToDelete) { + $CurrentId = $int++ + $DeleteMap[$CurrentId] = $guest + @{ + id = $CurrentId + method = 'DELETE' + url = "users/$($guest.id)" + } + } + + try { + $DeleteResults = New-GraphBulkRequest -tenantid $tenant -Requests @($DeleteRequests) + foreach ($result in $DeleteResults) { + $guest = $DeleteMap[[int]$result.id] + if ($null -eq $guest) { continue } + + if ($result.status -eq 200 -or $result.status -eq 204) { + $DeletedCount++ + $null = $DeletedGuestIds.Add([string]$guest.id) + $reason = if ($guest.NeverSignedIn) { + "never signed in, created $($guest.createdDateTime)" + } else { + "last sign-in: $($guest.LastSignInDateTime.ToString('o'))" + } + Write-LogMessage -API 'Standards' -tenant $tenant -message "Deleted guest $($guest.UserPrincipalName) ($($guest.id)). Reason: $reason" -sev Info + } else { + $FailedCount++ + $errorMsg = if ($result.body.error.message) { $result.body.error.message } else { "Unknown error (Status: $($result.status))" } + Write-LogMessage -API 'Standards' -tenant $tenant -message "Failed to delete guest $($guest.UserPrincipalName) ($($guest.id)): $errorMsg" -sev Error + } + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + $FailedCount += $GuestsToDelete.Count + Write-LogMessage -API 'Standards' -tenant $tenant -message "Failed to process bulk delete guests request: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + } + } + + if ($DeletedGuestIds.Count -gt 0) { + $GuestsToDelete = @($GuestsToDelete | Where-Object { $_.id -notin $DeletedGuestIds }) + $GuestsMeetingDeleteThreshold = @($GuestsMeetingDeleteThreshold | Where-Object { $_.id -notin $DeletedGuestIds }) + } + + if ($DisabledCount -gt 0 -or $DeletedCount -gt 0 -or $FailedCount -gt 0) { + Write-LogMessage -API 'Standards' -tenant $tenant -message "DisableGuests remediation completed. Disabled: $DisabledCount. Deleted: $DeletedCount. Failed: $FailedCount." -sev Info + } elseif ($GuestsToDisable.Count -eq 0 -and $GuestsToDelete.Count -eq 0) { Write-LogMessage -API 'Standards' -tenant $tenant -message "No guest accounts without a sign-in in the last $checkDays days - all guest accounts are already compliant." -sev Info } } + if ($Settings.alert -eq $true) { + $AlertGuests = @($GuestsToDisable) + if ($DeleteEnabled) { + $AlertGuests = @($GuestsToDisable + $GuestsMeetingDeleteThreshold) + } - if ($GraphRequest.Count -gt 0) { - $Filtered = @($GraphRequest | Select-Object -Property UserPrincipalName, id, signInActivity, LastSignInDateTime, NeverSignedIn, mail, userType, accountEnabled, externalUserState, createdDateTime) - $NeverSignedInCount = @($Filtered | Where-Object { $_.NeverSignedIn }).Count - $StaleCount = $Filtered.Count - $NeverSignedInCount - $AlertMessage = "Stale guest accounts found: $($GraphRequest.Count) total ($StaleCount with no sign-in attempt in $checkDays days, $NeverSignedInCount never signed in and created more than $checkDays days ago)" + if ($AlertGuests.Count -gt 0) { + $Filtered = @($AlertGuests | Select-Object -Property UserPrincipalName, id, signInActivity, LastSignInDateTime, NeverSignedIn, mail, userType, accountEnabled, externalUserState, createdDateTime) + $NeverSignedInCount = @($GuestsToDisable | Where-Object { $_.NeverSignedIn }).Count + $StaleCount = $GuestsToDisable.Count - $NeverSignedInCount + $AlertMessage = "Stale guest accounts found: $($GuestsToDisable.Count) total ($StaleCount with no sign-in attempt in $checkDays days, $NeverSignedInCount never signed in and created more than $checkDays days ago)" + if ($DeleteEnabled) { + $AlertMessage += ", $($GuestsMeetingDeleteThreshold.Count) meeting delete threshold (inactive $DeleteAge days, already disabled)" + } Write-StandardsAlert -message $AlertMessage -object $Filtered -tenant $tenant -standardName 'DisableGuests' -standardId $Settings.standardId Write-LogMessage -API 'Standards' -tenant $tenant -message $AlertMessage -sev Info } else { Write-LogMessage -API 'Standards' -tenant $tenant -message "No stale guest accounts found (threshold: $checkDays days)." -sev Info } } + if ($Settings.report -eq $true) { - $Filtered = @($GraphRequest | Where-Object { $_.accountEnabled } | Select-Object -Property UserPrincipalName, id, signInActivity, LastSignInDateTime, NeverSignedIn, mail, userType, accountEnabled, externalUserState, createdDateTime) + # After a remediate pass, successfully disabled guests have accountEnabled flipped off so + # the compare field reflects remaining work - same as the pre-delete-grace behaviour. + $Filtered = @($GuestsToDisable | Where-Object { $_.accountEnabled } | Select-Object -Property UserPrincipalName, id, signInActivity, LastSignInDateTime, NeverSignedIn, mail, userType, accountEnabled, externalUserState, createdDateTime) $NeverSignedIn = @($Filtered | Where-Object { $_.NeverSignedIn }) $StaleSignIns = @($Filtered | Where-Object { -not $_.NeverSignedIn }) + $DeleteDetails = if ($DeleteEnabled) { + @($GuestsMeetingDeleteThreshold | Select-Object -Property UserPrincipalName, id, signInActivity, LastSignInDateTime, NeverSignedIn, mail, userType, accountEnabled, externalUserState, createdDateTime) + } else { + @() + } $CurrentValue = [PSCustomObject]@{ GuestsDisabledAfterDays = $checkDays + GuestsDeleteGraceDays = $DeleteDelta GuestsIncludeNeverSignedIn = $IncludeNeverSignedIn GuestsDisabledAccountCount = $Filtered.Count GuestsStaleSignInCount = $StaleSignIns.Count GuestsNeverSignedInCount = $NeverSignedIn.Count GuestsDisabledAccountDetails = $Filtered GuestsNeverSignedInDetails = $NeverSignedIn + GuestsMeetingDeleteThreshold = if ($DeleteEnabled) { $DeleteDetails } else { 'Deletion disabled' } + GuestsMeetingDeleteCount = if ($DeleteEnabled) { $DeleteDetails.Count } else { 0 } } $ExpectedValue = [PSCustomObject]@{ GuestsDisabledAfterDays = $checkDays + GuestsDeleteGraceDays = $DeleteDelta GuestsIncludeNeverSignedIn = $IncludeNeverSignedIn GuestsDisabledAccountCount = 0 GuestsStaleSignInCount = 0 GuestsNeverSignedInCount = 0 GuestsDisabledAccountDetails = @() GuestsNeverSignedInDetails = @() + GuestsMeetingDeleteThreshold = if ($DeleteEnabled) { @() } else { 'Deletion disabled' } + GuestsMeetingDeleteCount = 0 } Set-CIPPStandardsCompareField -FieldName 'standards.DisableGuests' -CurrentValue $CurrentValue -ExpectedValue $ExpectedValue -TenantFilter $Tenant diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableSelfServiceLicenses.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableSelfServiceLicenses.ps1 index 08781f6a7140d..ceab1d61e41fa 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableSelfServiceLicenses.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardDisableSelfServiceLicenses.ps1 @@ -7,8 +7,8 @@ function Invoke-CIPPStandardDisableSelfServiceLicenses { .SYNOPSIS (Label) Disable Self Service Licensing .DESCRIPTION - (Helptext) **Requires 'Billing Administrator' GDAP role.** This standard disables all self service licenses and enables all exclusions - (DocsDescription) \*\*Requires 'Billing Administrator' GDAP role.\*\* This standard disables all self service licenses and enables all exclusions + (Helptext) This standard disables all self service licenses and enables all exclusions + (DocsDescription) This standard disables all self service licenses and enables all exclusions .NOTES CAT Entra (AAD) Standards @@ -23,7 +23,7 @@ function Invoke-CIPPStandardDisableSelfServiceLicenses { ADDEDDATE 2021-11-16 POWERSHELLEQUIVALENT - Set-MsolCompanySettings -AllowAdHocSubscriptions \$false + Update-MSCommerceProductPolicy -PolicyId AllowSelfServicePurchase -Value Disabled RECOMMENDEDBY UPDATECOMMENTBLOCK Run the Tools\Update-StandardsComments.ps1 script to update this comment block @@ -34,10 +34,10 @@ function Invoke-CIPPStandardDisableSelfServiceLicenses { param($Tenant, $Settings) try { - $selfServiceItems = (New-GraphGETRequest -scope 'aeb86249-8ea3-49e2-900b-54cc8e308f85/.default' -uri 'https://licensing.m365.microsoft.com/v1.0/policies/AllowSelfServicePurchase/products' -tenantid $Tenant).items + $selfServiceItems = (New-GraphGETRequest -scope 'aeb86249-8ea3-49e2-900b-54cc8e308f85/.default' -uri 'https://licensing.m365.microsoft.com/v1.0/policies/AllowSelfServicePurchase/products' -tenantid $Tenant -AsApp $true).items } catch { if ($_.Exception.Message -like '*403*') { - $Message = "Failed to retrieve self service products: Insufficient permissions. Please ensure the tenant GDAP relationship includes the 'Billing Administrator' role: $($_.Exception.Message)" + $Message = "Failed to retrieve self service products: Insufficient permissions: $($_.Exception.Message)" } else { $Message = "Failed to retrieve self service products: $($_.Exception.Message)" } @@ -45,11 +45,7 @@ function Invoke-CIPPStandardDisableSelfServiceLicenses { throw $Message } - if ($settings.exclusions -like '*;*') { - $exclusions = $settings.Exclusions -split (';') - } else { - $exclusions = $settings.Exclusions -split (',') - } + $exclusions = @("$($Settings.Exclusions)" -split '[,;]' | ForEach-Object { $_.Trim() } | Where-Object { $_ }) $CurrentValues = [System.Collections.Generic.List[PSCustomObject]]::new() foreach ($Item in $selfServiceItems) { @@ -146,7 +142,7 @@ function Invoke-CIPPStandardDisableSelfServiceLicenses { $authBody = @{ allowedToSignUpEmailBasedSubscriptions = $false } | ConvertTo-Json -Compress New-GraphPostRequest -uri 'https://graph.microsoft.com/v1.0/policies/authorizationPolicy' -tenantid $Tenant -body $authBody -type PATCH } else { - New-GraphPOSTRequest -scope 'aeb86249-8ea3-49e2-900b-54cc8e308f85/.default' -uri "https://licensing.m365.microsoft.com/v1.0/policies/AllowSelfServicePurchase/products/$($Item.productId)" -tenantid $Tenant -body $body -type PUT + New-GraphPOSTRequest -scope 'aeb86249-8ea3-49e2-900b-54cc8e308f85/.default' -uri "https://licensing.m365.microsoft.com/v1.0/policies/AllowSelfServicePurchase/products/$($Item.productId)" -tenantid $Tenant -body $body -type PUT -AsApp $true } Write-LogMessage -API 'Standards' -tenant $tenant -message "Changed Self Service status for product '$($Item.productName) - $($Item.productId)' from '$currentValue' to '$($Item.policyValue)'" -sev Info @@ -157,7 +153,7 @@ function Invoke-CIPPStandardDisableSelfServiceLicenses { } $CurrentValues = [System.Collections.Generic.List[PSCustomObject]]::new() - $refreshedItems = (New-GraphGETRequest -scope 'aeb86249-8ea3-49e2-900b-54cc8e308f85/.default' -uri 'https://licensing.m365.microsoft.com/v1.0/policies/AllowSelfServicePurchase/products' -tenantid $Tenant).items + $refreshedItems = (New-GraphGETRequest -scope 'aeb86249-8ea3-49e2-900b-54cc8e308f85/.default' -uri 'https://licensing.m365.microsoft.com/v1.0/policies/AllowSelfServicePurchase/products' -tenantid $Tenant -AsApp $true).items foreach ($Item in $refreshedItems) { $CurrentValues.Add([PSCustomObject]@{ productName = $Item.productName @@ -197,12 +193,14 @@ function Invoke-CIPPStandardDisableSelfServiceLicenses { } if ($Settings.alert) { - $selfServiceItemsToAlert = $CurrentValues | Where-Object { $_.policyValue -eq 'Enabled' } - if (!$selfServiceItemsToAlert) { - Write-LogMessage -API 'Standards' -tenant $tenant -message 'All self-service licenses are disabled' -sev Info + # Alert on current rows that differ from expected (exclusions stay Enabled; OnlyTrialsWithoutPaymentMethod is also drift) + $selfServiceItemsToAlert = @(Compare-Object -ReferenceObject $ExpectedValues -DifferenceObject $CurrentValues -Property productName, productId, policyValue | + Where-Object { $_.SideIndicator -eq '=>' }) + if ($selfServiceItemsToAlert.Count -eq 0) { + Write-LogMessage -API 'Standards' -tenant $tenant -message 'All self-service licenses are set correctly' -sev Info } else { - Write-StandardsAlert -message 'One or more self-service licenses are enabled' -object $selfServiceItemsToAlert -tenant $tenant -standardName 'DisableSelfServiceLicenses' -standardId $Settings.standardId - Write-LogMessage -API 'Standards' -tenant $tenant -message 'One or more self-service licenses are enabled' -sev Info + Write-StandardsAlert -message 'One or more self-service license settings are out of policy' -object $selfServiceItemsToAlert -tenant $tenant -standardName 'DisableSelfServiceLicenses' -standardId $Settings.standardId + Write-LogMessage -API 'Standards' -tenant $tenant -message 'One or more self-service license settings are out of policy' -sev Info } } diff --git a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_7.ps1 b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_7.ps1 index 5c4fe03bf239f..0516d89bcff9f 100644 --- a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_7.ps1 +++ b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_7.ps1 @@ -6,6 +6,11 @@ function Invoke-CippTestCIS_2_1_7 { param($Tenant) try { + if (-not (Test-CIPPStandardLicense -StandardName 'CIS_2_1_7' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'CIS_2_1_7' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'High' -Name 'An anti-phishing policy has been created' -UserImpact 'Low' -ImplementationEffort 'Medium' -Category 'Email Protection' + return + } + $AntiPhish = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoAntiPhishPolicies' if (-not $AntiPhish) { diff --git a/Modules/CIPPTests/Public/Tests/CISA/Identity/Invoke-CippTestCISAMSEXO102.md b/Modules/CIPPTests/Public/Tests/CISA/Identity/Invoke-CippTestCISAMSEXO102.md index 6e7965ddee11f..5a014fa73df85 100644 --- a/Modules/CIPPTests/Public/Tests/CISA/Identity/Invoke-CippTestCISAMSEXO102.md +++ b/Modules/CIPPTests/Public/Tests/CISA/Identity/Invoke-CippTestCISAMSEXO102.md @@ -6,13 +6,12 @@ Ensuring that emails containing malware are immediately quarantined or deleted p 1. Navigate to Microsoft 365 Defender portal > Email & collaboration > Policies & rules > Threat policies > Anti-malware 2. Select each malware filter policy -3. Under "Protection settings": - - Set "Malware detection response" to either "Delete entire message" or "Quarantine message" -4. Or use PowerShell: +3. Under "Protection settings" enable the common attachments filter and set its action so matching mail is either quarantined or rejected (dropped) +4. Or use PowerShell (FileTypeAction accepts `Quarantine` or `Reject`): ```powershell -Set-MalwareFilterPolicy -Identity "Default" -Action Quarantine -# Or -Set-MalwareFilterPolicy -Identity "Default" -Action DeleteMessage +Set-MalwareFilterPolicy -Identity "Default" -EnableFileFilter $true -FileTypeAction Quarantine +# Or reject (drop) matching mail instead +Set-MalwareFilterPolicy -Identity "Default" -EnableFileFilter $true -FileTypeAction Reject ``` **Links:** diff --git a/Modules/CIPPTests/Public/Tests/CISA/Identity/Invoke-CippTestCISAMSEXO102.ps1 b/Modules/CIPPTests/Public/Tests/CISA/Identity/Invoke-CippTestCISAMSEXO102.ps1 index e1ab88df20d4d..5f1756313c6ad 100644 --- a/Modules/CIPPTests/Public/Tests/CISA/Identity/Invoke-CippTestCISAMSEXO102.ps1 +++ b/Modules/CIPPTests/Public/Tests/CISA/Identity/Invoke-CippTestCISAMSEXO102.ps1 @@ -23,15 +23,15 @@ function Invoke-CippTestCISAMSEXO102 { return } - $AcceptableActions = @('DeleteMessage', 'Quarantine') + $AcceptableActions = @('Quarantine', 'Reject') $FailedPolicies = [System.Collections.Generic.List[object]]::new() foreach ($Policy in $MalwarePolicies) { - if ($Policy.Action -notin $AcceptableActions) { + if ($Policy.FileTypeAction -notin $AcceptableActions) { $FailedPolicies.Add([PSCustomObject]@{ 'Policy Name' = $Policy.Name - 'Current Action' = $Policy.Action - 'Expected' = 'DeleteMessage or Quarantine' + 'Current Action' = $Policy.FileTypeAction + 'Expected' = 'Quarantine or Reject' }) } } diff --git a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA105.ps1 b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA105.ps1 index 4a89546a6022f..1ae71817edf32 100644 --- a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA105.ps1 +++ b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA105.ps1 @@ -9,7 +9,11 @@ function Invoke-CippTestORCA105 { $Policies = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoSafeLinksPolicies' if (-not $Policies) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA105' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in database. This may be due to missing required licenses or data collection not yet completed.' -Risk 'High' -Name 'Safe Links Synchronous URL detonation is enabled' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + if (-not (Test-CIPPStandardLicense -StandardName 'ORCA105' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA105' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'High' -Name 'Safe Links Synchronous URL detonation is enabled' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA105' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in the database. Data collection for this tenant may not have completed yet - refresh the cache and try again.' -Risk 'High' -Name 'Safe Links Synchronous URL detonation is enabled' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } return } diff --git a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA113.ps1 b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA113.ps1 index 9a455e4b56612..25303a4b3b761 100644 --- a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA113.ps1 +++ b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA113.ps1 @@ -9,7 +9,11 @@ function Invoke-CippTestORCA113 { $SafeLinksPolicies = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoSafeLinksPolicies' if (-not $SafeLinksPolicies) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA113' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in database. This may be due to missing required licenses or data collection not yet completed.' -Risk 'High' -Name 'AllowClickThrough is disabled in Safe Links policies' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + if (-not (Test-CIPPStandardLicense -StandardName 'ORCA113' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA113' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'High' -Name 'AllowClickThrough is disabled in Safe Links policies' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA113' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in the database. Data collection for this tenant may not have completed yet - refresh the cache and try again.' -Risk 'High' -Name 'AllowClickThrough is disabled in Safe Links policies' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } return } diff --git a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA124.ps1 b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA124.ps1 index a09a297734ba8..f8c30e7e06163 100644 --- a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA124.ps1 +++ b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA124.ps1 @@ -9,7 +9,11 @@ function Invoke-CippTestORCA124 { $Policies = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoSafeAttachmentPolicies' if (-not $Policies) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA124' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in database. This may be due to missing required licenses or data collection not yet completed.' -Risk 'High' -Name 'Safe attachments unknown malware response set to block messages' -UserImpact 'Medium' -ImplementationEffort 'Low' -Category 'Safe Attachments' + if (-not (Test-CIPPStandardLicense -StandardName 'ORCA124' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA124' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'High' -Name 'Safe attachments unknown malware response set to block messages' -UserImpact 'Medium' -ImplementationEffort 'Low' -Category 'Safe Attachments' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA124' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in the database. Data collection for this tenant may not have completed yet - refresh the cache and try again.' -Risk 'High' -Name 'Safe attachments unknown malware response set to block messages' -UserImpact 'Medium' -ImplementationEffort 'Low' -Category 'Safe Attachments' + } return } diff --git a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA156.ps1 b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA156.ps1 index 54e346fb3116c..b88562b60eb62 100644 --- a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA156.ps1 +++ b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA156.ps1 @@ -9,7 +9,11 @@ function Invoke-CippTestORCA156 { $Policies = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoSafeLinksPolicies' if (-not $Policies) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA156' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in database. This may be due to missing required licenses or data collection not yet completed.' -Risk 'Low' -Name 'Safe Links Policies are tracking user clicks' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + if (-not (Test-CIPPStandardLicense -StandardName 'ORCA156' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA156' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'Low' -Name 'Safe Links Policies are tracking user clicks' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA156' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in the database. Data collection for this tenant may not have completed yet - refresh the cache and try again.' -Risk 'Low' -Name 'Safe Links Policies are tracking user clicks' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } return } diff --git a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA158.ps1 b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA158.ps1 index 0bf527155b7a5..1d964e942fd78 100644 --- a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA158.ps1 +++ b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA158.ps1 @@ -9,7 +9,11 @@ function Invoke-CippTestORCA158 { $AtpPolicy = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoAtpPolicyForO365' if (-not $AtpPolicy) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA158' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in database. This may be due to missing required licenses or data collection not yet completed.' -Risk 'High' -Name 'Safe Attachments enabled for SharePoint and Teams' -UserImpact 'High' -ImplementationEffort 'Low' -Category 'Safe Attachments' + if (-not (Test-CIPPStandardLicense -StandardName 'ORCA158' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA158' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'High' -Name 'Safe Attachments enabled for SharePoint and Teams' -UserImpact 'High' -ImplementationEffort 'Low' -Category 'Safe Attachments' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA158' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in the database. Data collection for this tenant may not have completed yet - refresh the cache and try again.' -Risk 'High' -Name 'Safe Attachments enabled for SharePoint and Teams' -UserImpact 'High' -ImplementationEffort 'Low' -Category 'Safe Attachments' + } return } diff --git a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA179.ps1 b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA179.ps1 index 9013546daa21e..0723fe2049731 100644 --- a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA179.ps1 +++ b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA179.ps1 @@ -9,7 +9,11 @@ function Invoke-CippTestORCA179 { $Policies = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoSafeLinksPolicies' if (-not $Policies) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA179' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in database. This may be due to missing required licenses or data collection not yet completed.' -Risk 'Medium' -Name 'Safe Links is enabled intra-organization' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + if (-not (Test-CIPPStandardLicense -StandardName 'ORCA179' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA179' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'Medium' -Name 'Safe Links is enabled intra-organization' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA179' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in the database. Data collection for this tenant may not have completed yet - refresh the cache and try again.' -Risk 'Medium' -Name 'Safe Links is enabled intra-organization' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } return } diff --git a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA225.ps1 b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA225.ps1 index 487b3af7820e2..3ecb08aac9ef0 100644 --- a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA225.ps1 +++ b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA225.ps1 @@ -9,7 +9,11 @@ function Invoke-CippTestORCA225 { $AtpPolicy = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoAtpPolicyForO365' if (-not $AtpPolicy) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA225' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in database. This may be due to missing required licenses or data collection not yet completed.' -Risk 'Medium' -Name 'Safe Documents is enabled for Office clients' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Attachments' + if (-not (Test-CIPPStandardLicense -StandardName 'ORCA225' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA225' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'Medium' -Name 'Safe Documents is enabled for Office clients' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Attachments' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA225' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in the database. Data collection for this tenant may not have completed yet - refresh the cache and try again.' -Risk 'Medium' -Name 'Safe Documents is enabled for Office clients' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Attachments' + } return } diff --git a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA226.ps1 b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA226.ps1 index a25c716e83bfe..252899ddfb8d3 100644 --- a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA226.ps1 +++ b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA226.ps1 @@ -15,7 +15,11 @@ function Invoke-CippTestORCA226 { } if (-not $SafeLinksPolicies) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA226' -TestType 'Identity' -Status 'Failed' -ResultMarkdown 'No Safe Links policies found. Each domain should have a Safe Links policy.' -Risk 'High' -Name 'Each domain has a Safe Links policy' -UserImpact 'High' -ImplementationEffort 'Medium' -Category 'Safe Links' + if (-not (Test-CIPPStandardLicense -StandardName 'ORCA226' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA226' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'High' -Name 'Each domain has a Safe Links policy' -UserImpact 'High' -ImplementationEffort 'Medium' -Category 'Safe Links' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA226' -TestType 'Identity' -Status 'Failed' -ResultMarkdown 'No Safe Links policies found. Each domain should have a Safe Links policy.' -Risk 'High' -Name 'Each domain has a Safe Links policy' -UserImpact 'High' -ImplementationEffort 'Medium' -Category 'Safe Links' + } return } diff --git a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA227.ps1 b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA227.ps1 index 519d060dbf1cb..82df15ac5abba 100644 --- a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA227.ps1 +++ b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA227.ps1 @@ -15,7 +15,11 @@ function Invoke-CippTestORCA227 { } if (-not $SafeAttachmentPolicies) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA227' -TestType 'Identity' -Status 'Failed' -ResultMarkdown 'No Safe Attachments policies found. Each domain should have a Safe Attachments policy.' -Risk 'High' -Name 'Each domain has a Safe Attachments policy' -UserImpact 'High' -ImplementationEffort 'Medium' -Category 'Safe Attachments' + if (-not (Test-CIPPStandardLicense -StandardName 'ORCA227' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA227' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'High' -Name 'Each domain has a Safe Attachments policy' -UserImpact 'High' -ImplementationEffort 'Medium' -Category 'Safe Attachments' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA227' -TestType 'Identity' -Status 'Failed' -ResultMarkdown 'No Safe Attachments policies found. Each domain should have a Safe Attachments policy.' -Risk 'High' -Name 'Each domain has a Safe Attachments policy' -UserImpact 'High' -ImplementationEffort 'Medium' -Category 'Safe Attachments' + } return } diff --git a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA234.ps1 b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA234.ps1 index a5ec895303419..94700fab55d24 100644 --- a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA234.ps1 +++ b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA234.ps1 @@ -9,7 +9,11 @@ function Invoke-CippTestORCA234 { $AtpPolicy = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoAtpPolicyForO365' if (-not $AtpPolicy) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA234' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in database. This may be due to missing required licenses or data collection not yet completed.' -Risk 'Medium' -Name 'Click through is disabled for Safe Documents' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Attachments' + if (-not (Test-CIPPStandardLicense -StandardName 'ORCA234' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA234' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'Medium' -Name 'Click through is disabled for Safe Documents' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Attachments' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA234' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in the database. Data collection for this tenant may not have completed yet - refresh the cache and try again.' -Risk 'Medium' -Name 'Click through is disabled for Safe Documents' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Attachments' + } return } diff --git a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA236.ps1 b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA236.ps1 index 290b843d81afa..cb65cf06292d2 100644 --- a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA236.ps1 +++ b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA236.ps1 @@ -9,7 +9,11 @@ function Invoke-CippTestORCA236 { $Policies = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoSafeLinksPolicies' if (-not $Policies) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA236' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in database. This may be due to missing required licenses or data collection not yet completed.' -Risk 'High' -Name 'Safe Links is enabled for emails' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + if (-not (Test-CIPPStandardLicense -StandardName 'ORCA236' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA236' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'High' -Name 'Safe Links is enabled for emails' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA236' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in the database. Data collection for this tenant may not have completed yet - refresh the cache and try again.' -Risk 'High' -Name 'Safe Links is enabled for emails' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } return } diff --git a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA237.ps1 b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA237.ps1 index 03d259bde938f..8c95400a35f6d 100644 --- a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA237.ps1 +++ b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA237.ps1 @@ -9,7 +9,11 @@ function Invoke-CippTestORCA237 { $Policies = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoSafeLinksPolicies' if (-not $Policies) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA237' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in database. This may be due to missing required licenses or data collection not yet completed.' -Risk 'High' -Name 'Safe Links is enabled for Teams' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + if (-not (Test-CIPPStandardLicense -StandardName 'ORCA237' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA237' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'High' -Name 'Safe Links is enabled for Teams' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA237' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in the database. Data collection for this tenant may not have completed yet - refresh the cache and try again.' -Risk 'High' -Name 'Safe Links is enabled for Teams' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } return } diff --git a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA238.ps1 b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA238.ps1 index c93892a42786c..03747a162fcfd 100644 --- a/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA238.ps1 +++ b/Modules/CIPPTests/Public/Tests/ORCA/Identity/Invoke-CippTestORCA238.ps1 @@ -9,7 +9,11 @@ function Invoke-CippTestORCA238 { $Policies = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoSafeLinksPolicies' if (-not $Policies) { - Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA238' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in database. This may be due to missing required licenses or data collection not yet completed.' -Risk 'High' -Name 'Safe Links is enabled for Office documents' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + if (-not (Test-CIPPStandardLicense -StandardName 'ORCA238' -TenantFilter $Tenant -Preset DefenderForOffice365 -SkipLog)) { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA238' -TestType 'Identity' -Status 'Unlicensed' -ResultMarkdown 'This tenant is not licensed for Microsoft Defender for Office 365 (ATP). Required capabilities: ATP_ENTERPRISE, ATP_ENTERPRISE_GOV, THREAT_INTELLIGENCE, THREAT_INTELLIGENCE_GOV.' -Risk 'High' -Name 'Safe Links is enabled for Office documents' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } else { + Add-CippTestResult -TenantFilter $Tenant -TestId 'ORCA238' -TestType 'Identity' -Status 'Skipped' -ResultMarkdown 'No data found in the database. Data collection for this tenant may not have completed yet - refresh the cache and try again.' -Risk 'High' -Name 'Safe Links is enabled for Office documents' -UserImpact 'Low' -ImplementationEffort 'Low' -Category 'Safe Links' + } return } diff --git a/Modules/CippExtensions/Public/Halo/Get-HaloTicketType.ps1 b/Modules/CippExtensions/Public/Halo/Get-HaloTicketType.ps1 index 60b7bbd7a6d74..9bb26de08d644 100644 --- a/Modules/CippExtensions/Public/Halo/Get-HaloTicketType.ps1 +++ b/Modules/CippExtensions/Public/Halo/Get-HaloTicketType.ps1 @@ -16,7 +16,11 @@ function Get-HaloTicketType { $Token = Get-HaloToken -configuration $Configuration $UserAgent = Get-CippUserAgent - Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/TicketType?showall=true" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($Token.access_token)" } + # Invoke-RestMethod emits a top-level JSON array as one Object[] without enumerating it, + # so returning it directly makes @(Get-HaloTicketType) a nested array. Writing the + # variable enumerates the rows. + $TicketTypes = Invoke-RestMethod -UserAgent $UserAgent -Uri "$($Configuration.ResourceURL)/TicketType?showall=true" -ContentType 'application/json' -Method GET -Headers @{Authorization = "Bearer $($Token.access_token)" } + $TicketTypes } catch { $Message = if ($_.ErrorDetails.Message) { Get-NormalizedError -Message $_.ErrorDetails.Message diff --git a/Tests/Alerts/Get-CIPPAlertUserReportedPhishing.Tests.ps1 b/Tests/Alerts/Get-CIPPAlertUserReportedPhishing.Tests.ps1 new file mode 100644 index 0000000000000..545f51b8cfff8 --- /dev/null +++ b/Tests/Alerts/Get-CIPPAlertUserReportedPhishing.Tests.ps1 @@ -0,0 +1,91 @@ +# Pester tests for Get-CIPPAlertUserReportedPhishing +# Verifies user-report filtering, that pagination never chases the regional EXO backend cursor, +# and that a regional route-miss degrades quietly instead of flooding alerts. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + # Resolve by name under Modules/ so the test survives the function moving between modules. + $AlertPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Get-CIPPAlertUserReportedPhishing.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $AlertPath) { throw 'Could not locate Get-CIPPAlertUserReportedPhishing.ps1 under Modules/' } + + # Provide minimal stubs so Mock has commands to replace during tests + function New-GraphGetRequest { param($uri, $tenantid, $AsApp) } + function Write-AlertTrace { param($cmdletName, $tenantFilter, $data) } + function Write-AlertMessage { param($tenant, $message, $LogData) } + function Get-CippException { param($Exception) @{ NormalizedError = $Exception.Exception.Message } } + + . $AlertPath +} + +Describe 'Get-CIPPAlertUserReportedPhishing' { + BeforeEach { + $script:CapturedData = $null + $script:CapturedTenant = $null + $script:CapturedAlertMessage = $null + + Mock -CommandName New-GraphGetRequest -MockWith { + @( + [pscustomobject]@{ + id = 'sub-user' + source = 'user' + sender = 'attacker@evil.example' + emailSubject = 'Reset your password now' + category = 'phishing' + createdBy = [pscustomobject]@{ user = [pscustomobject]@{ displayName = 'Reporter One'; email = 'reporter@contoso.com' } } + }, + [pscustomobject]@{ + id = 'sub-admin' + source = 'administrator' + sender = 'noreply@contoso.com' + emailSubject = 'Admin submitted sample' + category = 'phishing' + createdBy = [pscustomobject]@{ user = [pscustomobject]@{ displayName = 'Some Admin'; email = 'admin@contoso.com' } } + } + ) + } + + Mock -CommandName Write-AlertTrace -MockWith { + param($cmdletName, $tenantFilter, $data) + $script:CapturedData = $data + $script:CapturedTenant = $tenantFilter + } + + Mock -CommandName Write-AlertMessage -MockWith { + param($tenant, $message, $LogData) + $script:CapturedAlertMessage = $message + } + } + + It 'reports only user-sourced submissions' { + Get-CIPPAlertUserReportedPhishing -TenantFilter 'contoso.onmicrosoft.com' + + $CapturedData | Should -Not -BeNullOrEmpty + @($CapturedData).Count | Should -Be 1 + $CapturedData.SubmissionId | Should -Contain 'sub-user' + $CapturedData.SubmissionId | Should -Not -Contain 'sub-admin' + $CapturedTenant | Should -Be 'contoso.onmicrosoft.com' + } + + It 'alerts with a stable EXO-unavailable message when the region does not serve the API' { + Mock -CommandName New-GraphGetRequest -MockWith { + throw "No HTTP resource was found that matches the request URI 'https://deu01b.dataservice.protection.outlook.com/ReportSubmission/security/threatSubmission/emailThreats?`$filter=createdDateTime ge 2026-09-07T09:30:27Z&tenantid=abc'." + } + + Get-CIPPAlertUserReportedPhishing -TenantFilter 'mobiler-home-service.de' + + Should -Invoke Write-AlertMessage -Times 1 -Exactly + $CapturedAlertMessage | Should -Match 'Exchange Online API unavailable' + $CapturedAlertMessage | Should -Match 'Check tenant and EXO health' + $CapturedAlertMessage | Should -Not -Match '2026-09-07' + } + + It 'still raises an alert for genuine (non-regional) failures' { + Mock -CommandName New-GraphGetRequest -MockWith { throw 'Insufficient privileges to complete the operation.' } + + Get-CIPPAlertUserReportedPhishing -TenantFilter 'contoso.onmicrosoft.com' + + Should -Invoke Write-AlertMessage -Times 1 -Exactly + $CapturedAlertMessage | Should -Match 'Insufficient privileges' + } +} diff --git a/Tests/Baselines/BaselineDisableGuests.Tests.ps1 b/Tests/Baselines/BaselineDisableGuests.Tests.ps1 index c1dd46cc61f56..9ab9a23b1b270 100644 --- a/Tests/Baselines/BaselineDisableGuests.Tests.ps1 +++ b/Tests/Baselines/BaselineDisableGuests.Tests.ps1 @@ -1,8 +1,9 @@ # Get-CIPPBaselineDisableGuestsState mirrors the DisableGuests standard: the same newest-attempt # rule, the same IncludeNeverSignedIn switch (off by default and off for templates that predate -# it) and the same 7-day grace after an admin re-enables an account. Each test pins one of those, -# because drift between the standard and the baseline shows up as a guest one path disables and -# the other reports compliant. +# it), the same 7-day grace after an admin re-enables an account, and the same deleteGraceDays +# gate (missing/0 = never delete; only already-disabled guests past days+grace). Each test pins +# one of those, because drift between the standard and the baseline shows up as a guest one path +# remediates and the other reports compliant. BeforeAll { $script:RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) @@ -24,6 +25,7 @@ BeforeAll { param( [string]$Id, [string]$Upn, + [bool]$AccountEnabled = $true, [int]$CreatedDaysAgo = 400, [Nullable[int]]$InteractiveDaysAgo, [Nullable[int]]$NonInteractiveDaysAgo, @@ -35,7 +37,7 @@ BeforeAll { userPrincipalName = $Upn mail = $Upn userType = 'Guest' - accountEnabled = $true + accountEnabled = $AccountEnabled createdDateTime = $script:Now.AddDays(-$CreatedDaysAgo).ToString('o') } if ($null -ne $InteractiveDaysAgo -or $null -ne $NonInteractiveDaysAgo -or $null -ne $SuccessfulDaysAgo) { @@ -48,42 +50,50 @@ BeforeAll { $Guest | ConvertTo-Json -Depth 5 | ConvertFrom-Json } - # A rendered template item. Omit -IncludeNeverSignedIn to model a template saved before the - # switch existed. + # A rendered template item. Omit -IncludeNeverSignedIn / -DeleteGraceDays to model a template + # saved before those settings existed. function script:New-DisableGuestsItem { - param([Nullable[int]]$Days, [Nullable[bool]]$IncludeNeverSignedIn) + param( + [Nullable[int]]$Days, + [Nullable[bool]]$IncludeNeverSignedIn, + [Nullable[int]]$DeleteGraceDays + ) $Variables = [PSCustomObject]@{} if ($null -ne $Days) { $Variables | Add-Member -NotePropertyName days -NotePropertyValue $Days } if ($null -ne $IncludeNeverSignedIn) { $Variables | Add-Member -NotePropertyName IncludeNeverSignedIn -NotePropertyValue $IncludeNeverSignedIn } + if ($null -ne $DeleteGraceDays) { $Variables | Add-Member -NotePropertyName deleteGraceDays -NotePropertyValue $DeleteGraceDays } [PSCustomObject]@{ Variables = $Variables } } } Describe 'Get-CIPPBaselineDisableGuestsState' { BeforeEach { - $script:guests = @() + $script:enabledGuests = @() + $script:disabledGuests = @() $script:audits = @() Mock New-GraphGetRequest { param($uri) if ($uri -like '*directoryAudits*') { return $script:audits } - return $script:guests + if ($uri -like '*accountEnabled eq false*') { return $script:disabledGuests } + return $script:enabledGuests } } It 'judges inactivity on the newest sign-in attempt, not the last successful sign-in' { - $script:guests = @( + $script:enabledGuests = @( New-Guest -Id 'g1' -Upn 'bas_example.com#EXT#@contoso.onmicrosoft.com' -SuccessfulDaysAgo 300 -InteractiveDaysAgo 154 -NonInteractiveDaysAgo 3 New-Guest -Id 'stale' -Upn 'stale@example.com' -SuccessfulDaysAgo 250 -InteractiveDaysAgo 200 -NonInteractiveDaysAgo 190 ) $Prepared = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem -Days 180) -TenantFilter $script:Tenant - @($Prepared.Current.offenders) | Should -Be @('stale@example.com') - @($Prepared.Current.targets).id | Should -Be @('stale') + @($Prepared.Current.offenders) | Should -Be @('Disable: stale@example.com') + @($Prepared.Current.guestsToDisable).id | Should -Be @('stale') + @($Prepared.Current.guestsToDelete) | Should -BeNullOrEmpty } It 'skips guests with no sign-in on record unless IncludeNeverSignedIn is on' { - $script:guests = @(New-Guest -Id 'pending' -Upn 'pending@example.com') + $script:enabledGuests = @(New-Guest -Id 'pending' -Upn 'pending@example.com') $Legacy = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem -Days 90) -TenantFilter $script:Tenant @($Legacy.Current.offenders) | Should -BeNullOrEmpty @@ -92,28 +102,54 @@ Describe 'Get-CIPPBaselineDisableGuestsState' { @($Off.Current.offenders) | Should -BeNullOrEmpty $On = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem -Days 90 -IncludeNeverSignedIn $true) -TenantFilter $script:Tenant - @($On.Current.offenders) | Should -Be @('pending@example.com') - @($On.Current.targets).id | Should -Be @('pending') + @($On.Current.offenders) | Should -Be @('Disable: pending@example.com') + @($On.Current.guestsToDisable).id | Should -Be @('pending') } It 'leaves a guest an admin re-enabled in the last 7 days alone' { - $script:guests = @(New-Guest -Id 'stale' -Upn 'stale@example.com' -InteractiveDaysAgo 200) + $script:enabledGuests = @(New-Guest -Id 'stale' -Upn 'stale@example.com' -InteractiveDaysAgo 200) $script:audits = @([pscustomobject]@{ targetResources = @([pscustomobject]@{ id = 'stale' }) }) $Prepared = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem -Days 90) -TenantFilter $script:Tenant @($Prepared.Current.offenders) | Should -BeNullOrEmpty - @($Prepared.Current.targets) | Should -BeNullOrEmpty + @($Prepared.Current.guestsToDisable) | Should -BeNullOrEmpty } It 'falls back to 90 days when the template carries no value' { - $script:guests = @( + $script:enabledGuests = @( New-Guest -Id 'over' -Upn 'over@example.com' -InteractiveDaysAgo 100 New-Guest -Id 'under' -Upn 'under@example.com' -InteractiveDaysAgo 80 ) $Prepared = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem) -TenantFilter $script:Tenant - @($Prepared.Current.offenders) | Should -Be @('over@example.com') + @($Prepared.Current.offenders) | Should -Be @('Disable: over@example.com') + } + + It 'leaves guestsToDelete empty when deleteGraceDays is missing or 0' { + $script:enabledGuests = @(New-Guest -Id 'stale' -Upn 'stale@example.com' -InteractiveDaysAgo 200) + $script:disabledGuests = @(New-Guest -Id 'old' -Upn 'old@example.com' -AccountEnabled $false -InteractiveDaysAgo 400) + + $Missing = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem -Days 90) -TenantFilter $script:Tenant + @($Missing.Current.guestsToDelete) | Should -BeNullOrEmpty + @($Missing.Current.guestsToDisable).id | Should -Be @('stale') + + $Zero = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem -Days 90 -DeleteGraceDays 0) -TenantFilter $script:Tenant + @($Zero.Current.guestsToDelete) | Should -BeNullOrEmpty + } + + It 'puts already-disabled guests past days plus grace into guestsToDelete only' { + $script:enabledGuests = @(New-Guest -Id 'toDisable' -Upn 'todisable@example.com' -InteractiveDaysAgo 200) + $script:disabledGuests = @( + New-Guest -Id 'toDelete' -Upn 'todelete@example.com' -AccountEnabled $false -InteractiveDaysAgo 200 + New-Guest -Id 'tooRecent' -Upn 'toorecent@example.com' -AccountEnabled $false -InteractiveDaysAgo 100 + ) + + $Prepared = Get-CIPPBaselineDisableGuestsState -Item (New-DisableGuestsItem -Days 90 -DeleteGraceDays 30) -TenantFilter $script:Tenant + + @($Prepared.Current.guestsToDisable).id | Should -Be @('toDisable') + @($Prepared.Current.guestsToDelete).id | Should -Be @('toDelete') + @($Prepared.Current.offenders) | Should -Be @('Delete: todelete@example.com', 'Disable: todisable@example.com') } } diff --git a/Tests/Baselines/BaselineEntraHeavies.Tests.ps1 b/Tests/Baselines/BaselineEntraHeavies.Tests.ps1 index 08fa17b073f0c..a77e93e3afa12 100644 --- a/Tests/Baselines/BaselineEntraHeavies.Tests.ps1 +++ b/Tests/Baselines/BaselineEntraHeavies.Tests.ps1 @@ -280,7 +280,7 @@ Describe 'Get-CIPPBaselineDisableSelfServiceLicensesState' { Invoke-CIPPBaselineDisableSelfServiceLicenses -Remediate $null -TenantFilter $script:Tenant -Current $Prepared.Current Should -Invoke New-GraphPostRequest -ParameterFilter { $uri -match 'autoclaim' } Should -Invoke New-GraphPostRequest -ParameterFilter { $uri -match 'authorizationPolicy' -and $type -eq 'PATCH' } - Should -Invoke New-GraphPostRequest -ParameterFilter { $uri -match 'licensing.m365.microsoft.com' -and $type -eq 'PUT' } + Should -Invoke New-GraphPostRequest -ParameterFilter { $uri -match 'licensing.m365.microsoft.com' -and $type -eq 'PUT' -and $AsApp } } } diff --git a/Tests/DBCache/Push-StoreSharePointPermissions.Tests.ps1 b/Tests/DBCache/Push-StoreSharePointPermissions.Tests.ps1 new file mode 100644 index 0000000000000..8fe05b7c0297a --- /dev/null +++ b/Tests/DBCache/Push-StoreSharePointPermissions.Tests.ps1 @@ -0,0 +1,187 @@ +# Pester tests for Push-StoreSharePointPermissions +# +# The store step for the SharePoint permissions scan. These lock the behaviour that keeps a large +# tenant's report alive instead of letting it expire under the 30-day reporting retention: +# - a run where a whole batch failed (sites missing from the fan-in) still writes the sites that +# came back and carries the missing ones over from the prior cache, flagged Skipped; +# - a run that collected nothing writes nothing, so stale data is not re-stamped as fresh; +# - rows are streamed into one Add-CIPPDbItem invocation (memory) and the prior cache is read only +# for the sites being restored, by RowKey prefix. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Push-StoreSharePointPermissions.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $FunctionPath) { throw 'Could not locate Push-StoreSharePointPermissions.ps1 under Modules/' } + + # Minimal stubs so Mock has commands to replace. + function Write-LogMessage { param($API, $tenant, $message, $sev, $LogData) } + function Add-CIPPDbItem { + [CmdletBinding()] + param( + [Parameter(Mandatory)][string]$TenantFilter, + [Parameter(Mandatory)][string]$Type, + [Parameter(Mandatory, ValueFromPipeline)][AllowNull()][AllowEmptyCollection()]$InputObject, + [switch]$Count, + [switch]$AddCount, + [switch]$Append, + [switch]$ClearOnEmpty, + [string]$RunId + ) + } + function Get-CippTable { param($tablename) @{} } + function Get-CIPPAzDataTableEntity { param([string]$Filter) @() } + function Get-Tenants { param($TenantFilter, [switch]$IncludeErrors) } + function Get-CippException { param($Exception) } + + . $FunctionPath + + function New-SiteRow { + param($Id, $Status = 'Full') + [PSCustomObject]@{ rowType = 'Site'; id = "${Id}_site"; siteId = $Id; siteName = "site-$Id"; collectionStatus = $Status } + } + function New-Assignment { + param($Id, $SiteId) + [PSCustomObject]@{ rowType = 'Assignment'; id = $Id; siteId = $SiteId; principalId = 'p1'; permissionLevel = 'Read' } + } + function New-SiteResult { + param($Id, $Status = 'Full', $Assignments = 0) + $Rows = @(for ($i = 1; $i -le $Assignments; $i++) { New-Assignment -Id "${Id}_a$i" -SiteId $Id }) + [PSCustomObject]@{ + SiteId = $Id + CollectionStatus = $Status + SiteRow = (New-SiteRow -Id $Id -Status $Status) + Rows = @($Rows) + } + } + function New-WorkItem { + param($SiteResults, [int]$ExpectedSiteCount, $ExpectedSiteIds) + @{ + Parameters = @{ TenantFilter = 'contoso.onmicrosoft.com'; ExpectedSiteCount = $ExpectedSiteCount; ExpectedSiteIds = $ExpectedSiteIds } + Results = @(@{ Sites = @($SiteResults) }) + } + } + # Prior-cache entity rows (as stored: one Site row + N Assignment rows, Data is compressed JSON). + function New-PriorEntities { + param($SiteId, [int]$Assignments, [int]$Libraries = 3) + $Entities = [System.Collections.Generic.List[object]]::new() + $Entities.Add([PSCustomObject]@{ Data = ([PSCustomObject]@{ rowType = 'Site'; id = "${SiteId}_site"; siteId = $SiteId; siteName = "prior-$SiteId"; siteUrl = "https://x/$SiteId"; collectionStatus = 'Full'; librariesScanned = $Libraries; librariesWithUniquePermissions = 1 } | ConvertTo-Json -Compress) }) + for ($i = 1; $i -le $Assignments; $i++) { + $Entities.Add([PSCustomObject]@{ Data = ([PSCustomObject]@{ rowType = 'Assignment'; id = "${SiteId}_prior_a$i"; siteId = $SiteId; principalId = "pp$i"; permissionLevel = 'Read' } | ConvertTo-Json -Compress) }) + } + @($Entities) + } +} + +Describe 'Push-StoreSharePointPermissions' { + BeforeEach { + $script:Rows = [System.Collections.Generic.List[object]]::new() + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Get-CippException -MockWith { @{} } + Mock -CommandName Get-CippTable -MockWith { @{} } + Mock -CommandName Add-CIPPDbItem -MockWith { + $script:Rows.Add([PSCustomObject]@{ Type = $Type; AddCount = $AddCount.IsPresent; Tenant = $TenantFilter; Row = $InputObject }) + } + } + + It 'writes every site and assignment row on a complete run, with no prior-cache read' { + $Item = New-WorkItem -ExpectedSiteCount 2 -ExpectedSiteIds @('s1', 's2') -SiteResults @( + (New-SiteResult -Id 's1' -Assignments 2), + (New-SiteResult -Id 's2' -Assignments 1) + ) + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { @() } + + Push-StoreSharePointPermissions -Item $Item + + # 2 site rows + 3 assignment rows, streamed one per invocation. + Should -Invoke Add-CIPPDbItem -Times 5 -Exactly -ParameterFilter { + $AddCount.IsPresent -and $Type -eq 'SharePointPermissions' -and $TenantFilter -eq 'contoso.onmicrosoft.com' + } + @($script:Rows | Where-Object { $_.Row.rowType -eq 'Assignment' }).Count | Should -Be 3 + Should -Invoke Get-CIPPAzDataTableEntity -Times 0 -Exactly + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { $sev -eq 'Info' -and $message -like 'Cached 3 SharePoint permission assignments*' } + } + + It 'carries a missing batch over from the prior cache instead of discarding the run' { + # s1, s2 came back; s3 was expected but its batch did not return. + $Item = New-WorkItem -ExpectedSiteCount 3 -ExpectedSiteIds @('s1', 's2', 's3') -SiteResults @( + (New-SiteResult -Id 's1' -Assignments 1), + (New-SiteResult -Id 's2' -Assignments 1) + ) + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + if ($Filter -match 'SharePointPermissions-s3_') { return (New-PriorEntities -SiteId 's3' -Assignments 2 -Libraries 5) } + @() + } + + Push-StoreSharePointPermissions -Item $Item + + # s1 site+1, s2 site+1, s3 synthetic site + 2 restored = 3 site rows + 4 assignment rows. + @($script:Rows | Where-Object { $_.Row.rowType -eq 'Site' }).Count | Should -Be 3 + @($script:Rows | Where-Object { $_.Row.rowType -eq 'Assignment' }).Count | Should -Be 4 + + $Synth = @($script:Rows | Where-Object { $_.Row.rowType -eq 'Site' -and $_.Row.siteId -eq 's3' }) + $Synth.Count | Should -Be 1 + $Synth[0].Row.collectionStatus | Should -Be 'Skipped' + $Synth[0].Row.librariesScanned | Should -Be 5 + $Synth[0].Row.collectionError | Should -BeLike '*not returned by its collection batch*' + + # Only the missing site is read from the prior cache, by its own RowKey prefix. + Should -Invoke Get-CIPPAzDataTableEntity -Times 1 -Exactly + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { $sev -eq 'Warning' -and $message -like '*1 missing (carried over)*' } + } + + It 'restores a returned-Skipped site''s assignments from the prior cache' { + $Item = New-WorkItem -ExpectedSiteCount 2 -ExpectedSiteIds @('s1', 's2') -SiteResults @( + (New-SiteResult -Id 's1' -Assignments 1), + (New-SiteResult -Id 's2' -Status 'Skipped' -Assignments 0) + ) + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { + if ($Filter -match 'SharePointPermissions-s2_') { return (New-PriorEntities -SiteId 's2' -Assignments 2) } + @() + } + + Push-StoreSharePointPermissions -Item $Item + + # s1 site + 1 asg, s2 (skipped) site + 2 restored asg = 2 site rows + 3 assignment rows. + @($script:Rows | Where-Object { $_.Row.rowType -eq 'Site' }).Count | Should -Be 2 + @($script:Rows | Where-Object { $_.Row.rowType -eq 'Assignment' }).Count | Should -Be 3 + Should -Invoke Get-CIPPAzDataTableEntity -Times 1 -Exactly + } + + It 'writes nothing when no site was collected, so a stale cache is not re-stamped' { + $Item = New-WorkItem -ExpectedSiteCount 2 -ExpectedSiteIds @('s1', 's2') -SiteResults @( + (New-SiteResult -Id 's1' -Status 'Skipped'), + (New-SiteResult -Id 's2' -Status 'Skipped') + ) + + Push-StoreSharePointPermissions -Item $Item + + Should -Invoke Add-CIPPDbItem -Times 0 -Exactly + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { $sev -eq 'Error' -and $message -like '*no sites collected this run*' } + } + + It 'without an expected-site list, an incomplete run preserves the prior cache (no partial write)' { + $Item = New-WorkItem -ExpectedSiteCount 3 -ExpectedSiteIds $null -SiteResults @( + (New-SiteResult -Id 's1' -Assignments 1), + (New-SiteResult -Id 's2' -Assignments 1) + ) + + Push-StoreSharePointPermissions -Item $Item + + Should -Invoke Add-CIPPDbItem -Times 0 -Exactly + Should -Invoke Write-LogMessage -Times 1 -Exactly -ParameterFilter { $sev -eq 'Warning' -and $message -like '*no expected-site list to reconcile*' } + } + + It 'without an expected-site list, a complete run still writes (back-compat path)' { + $Item = New-WorkItem -ExpectedSiteCount 2 -ExpectedSiteIds $null -SiteResults @( + (New-SiteResult -Id 's1' -Assignments 1), + (New-SiteResult -Id 's2' -Assignments 1) + ) + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { @() } + + Push-StoreSharePointPermissions -Item $Item + + Should -Invoke Add-CIPPDbItem -Times 4 -Exactly -ParameterFilter { $Type -eq 'SharePointPermissions' } + Should -Invoke Get-CIPPAzDataTableEntity -Times 0 -Exactly + } +} diff --git a/Tests/Endpoint/Invoke-ExecTokenExchange.Tests.ps1 b/Tests/Endpoint/Invoke-ExecTokenExchange.Tests.ps1 new file mode 100644 index 0000000000000..ee25ab7d821f4 --- /dev/null +++ b/Tests/Endpoint/Invoke-ExecTokenExchange.Tests.ps1 @@ -0,0 +1,107 @@ +# Pester tests for Invoke-ExecTokenExchange certificate assertions. +# The Direct Add / SAM OAuth popup posts to the /organizations token endpoint. When certificate +# auth is on, the client assertion aud claim must equal that tokenUrl - using $env:TenantID +# (partner GUID) produces AADSTS700023. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Get-ChildItem -Path (Join-Path $RepoRoot 'Modules') -Recurse -Filter 'Invoke-ExecTokenExchange.ps1' -File -ErrorAction SilentlyContinue | + Select-Object -First 1 -ExpandProperty FullName + if (-not $FunctionPath) { throw 'Could not locate Invoke-ExecTokenExchange.ps1 under Modules/' } + + class HttpResponseContext { + [object]$StatusCode + [object]$Body + [object]$Headers + } + + $Accelerators = [psobject].Assembly.GetType('System.Management.Automation.TypeAccelerators') + if (-not $Accelerators::Get.ContainsKey('HttpStatusCode')) { + $Accelerators::Add('HttpStatusCode', [System.Net.HttpStatusCode]) + } + + function Get-CippKeyVaultName { 'test-kv' } + function Write-LogMessage { param($API, $message, $Sev) } + function Get-CIPPAuthentication { $true } + function Get-CIPPTable { param($tablename) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter) } + function Get-CippKeyVaultSecret { param($VaultName, $Name, [switch]$AsPlainText) } + function Get-CIPPSAMCertificate { param([switch]$SkipCache) } + function New-CIPPCertificateAssertion { param($TenantId, $AppId, $Certificate, $Audience) } + function Invoke-RestMethod { + param($Uri, $Method, $Body, $ContentType, [switch]$SkipHttpErrorCheck) + } + + . $FunctionPath + + function New-TokenExchangeRequest { + param( + [string]$TokenUrl = 'https://login.microsoftonline.com/organizations/oauth2/v2.0/token', + [string]$AppId = 'sam-app-id' + ) + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ExecTokenExchange' } + Body = [pscustomobject]@{ + tokenUrl = $TokenUrl + tenantId = $AppId + tokenRequest = [pscustomobject]@{ + grant_type = 'authorization_code' + client_id = $AppId + code = 'auth-code' + redirect_uri = 'https://cipp.example.com/authredirect' + } + } + } + } +} + +Describe 'Invoke-ExecTokenExchange certificate assertion audience' { + BeforeEach { + $script:SavedEnv = @{} + foreach ($Name in 'CertificateAuthMode', 'ApplicationSecret', 'TenantID', 'AzureWebJobsStorage', 'NonLocalHostAzurite') { + $script:SavedEnv[$Name] = [Environment]::GetEnvironmentVariable($Name) + } + # Partner tenant GUID - the regression was using this as aud instead of tokenUrl. + $env:TenantID = '11111111-2222-3333-4444-555555555555' + $env:CertificateAuthMode = $true + $env:ApplicationSecret = 'AppSecret' + Remove-Item env:AzureWebJobsStorage -ErrorAction SilentlyContinue + Remove-Item env:NonLocalHostAzurite -ErrorAction SilentlyContinue + + Mock Write-LogMessage {} + Mock Get-CippKeyVaultName { 'test-kv' } + Mock Get-CIPPAuthentication { $true } + Mock Get-CIPPSAMCertificate { [pscustomobject]@{ Certificate = 'CERT-OBJECT'; Thumbprint = 'ABC' } } + Mock New-CIPPCertificateAssertion { 'signed.jwt.assertion' } + Mock Invoke-RestMethod { @{ access_token = 'token'; refresh_token = 'refresh'; expires_in = 3600 } } + Mock Start-Sleep {} + } + + AfterEach { + foreach ($Name in $script:SavedEnv.Keys) { + if ($null -eq $script:SavedEnv[$Name]) { + Remove-Item "env:$Name" -ErrorAction SilentlyContinue + } else { + Set-Item "env:$Name" -Value $script:SavedEnv[$Name] + } + } + } + + It 'builds the certificate assertion aud from the organizations tokenUrl, not env:TenantID' { + $TokenUrl = 'https://login.microsoftonline.com/organizations/oauth2/v2.0/token' + $Response = Invoke-ExecTokenExchange -Request (New-TokenExchangeRequest -TokenUrl $TokenUrl) -TriggerMetadata $null + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + Should -Invoke New-CIPPCertificateAssertion -Times 1 -Exactly -ParameterFilter { + $Audience -eq $TokenUrl -and + $TenantId -eq 'organizations' -and + $AppId -eq 'sam-app-id' + } + Should -Invoke Invoke-RestMethod -Times 1 -Exactly -ParameterFilter { + $Uri -eq $TokenUrl -and + $Body.ContainsKey('client_assertion') -and + $Body['client_assertion_type'] -eq 'urn:ietf:params:oauth:client-assertion-type:jwt-bearer' -and + -not $Body.ContainsKey('client_secret') + } + } +} diff --git a/Tests/Endpoint/Invoke-ListInstanceDiagnostics.Timeline.Tests.ps1 b/Tests/Endpoint/Invoke-ListInstanceDiagnostics.Timeline.Tests.ps1 new file mode 100644 index 0000000000000..8c1b2569938d0 --- /dev/null +++ b/Tests/Endpoint/Invoke-ListInstanceDiagnostics.Timeline.Tests.ps1 @@ -0,0 +1,81 @@ +# Pester tests for Invoke-ListInstanceDiagnostics (Timeline action) +# InstanceHealth rows now share one PartitionKey with the bucket in RowKey/Bucket and the row +# type in Kind, so the endpoint splits rows by Kind instead of parsing RowKey. This pins that +# a mocked mixed-Kind row set still groups clients under the right bucket and emits a boot event. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListInstanceDiagnostics.ps1' + + class HttpResponseContext { + [int]$StatusCode + [object]$Body + } + $Accelerators = [psobject].Assembly.GetType('System.Management.Automation.TypeAccelerators') + if (-not $Accelerators::Get.ContainsKey('HttpStatusCode')) { + $Accelerators::Add('HttpStatusCode', [System.Net.HttpStatusCode]) + } + + function Get-CIPPTable { param($TableName) @{ Context = 'stub' } } + function Get-CIPPAzDataTableEntity { param($Context, $Filter) } + function Get-CippException { param($Exception) @{ NormalizedError = "$Exception" } } + function Write-LogMessage { param($API, $message, $sev, $LogData) } + + . $FunctionPath + + function New-DiagRequest { + param([string]$Action = 'Timeline', [int]$Hours = 24) + [pscustomobject]@{ + Params = @{ CIPPEndpoint = 'ListInstanceDiagnostics' } + Query = [pscustomobject]@{ Action = $Action; Hours = $Hours } + } + } +} + +Describe 'Invoke-ListInstanceDiagnostics Timeline row splitting' { + It 'groups clients under their sample bucket and emits a boot event from mixed Kind rows' { + $Rows = @( + [pscustomobject]@{ PartitionKey = 'InstanceHealth'; RowKey = '2026-09-10T10:00_sample'; Bucket = '2026-09-10T10:00'; Kind = 'sample'; OomCount = 0; WatchdogCount = 0; PoolExhaustedCount = 0; ErrCount = 0; MaxLimiterWaitMs = 0; StalledRunCount = 0; HeapMb = 500; HeapMbLive = $null; GcHeapLimitMb = 3072; TopEndpointsMs = $null; EgressBytesToday = 1048576; EgressBytes = 204800; EgressCapBytes = 10485760 } + [pscustomobject]@{ PartitionKey = 'InstanceHealth'; RowKey = '2026-09-10T10:00_client_11111111-1111-1111-1111-111111111111'; Bucket = '2026-09-10T10:00'; Kind = 'client'; AppId = '11111111-1111-1111-1111-111111111111'; AppName = 'Acme RMM'; IP = '203.0.113.9'; Count = 5 } + [pscustomobject]@{ PartitionKey = 'InstanceHealth'; RowKey = '2026-09-10T10:05_boot'; Bucket = '2026-09-10T10:05'; Kind = 'boot'; BootTime = '2026-09-10T10:05:00Z'; GapMinutes = 3 } + ) + + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $Rows } -ParameterFilter { $Filter -match "PartitionKey eq 'InstanceHealth'" } + + $Response = Invoke-ListInstanceDiagnostics -Request (New-DiagRequest -Action 'Timeline') -TriggerMetadata $null + + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $Response.Body.Results.Buckets | Should -HaveCount 1 + $Response.Body.Results.Buckets[0].Bucket | Should -Be '2026-09-10T10:00' + $Response.Body.Results.Buckets[0].Clients | Should -HaveCount 1 + $Response.Body.Results.Buckets[0].Clients[0].AppId | Should -Be '11111111-1111-1111-1111-111111111111' + $Response.Body.Results.Buckets[0].Clients[0].Count | Should -Be 5 + + $Response.Body.Results.Buckets[0].EgressBytesToday | Should -Be 1048576 + $Response.Body.Results.Buckets[0].EgressBytes | Should -Be 204800 + $Response.Body.Results.EgressCapBytes | Should -Be 10485760 + $Response.Body.Results.EgressAvailable | Should -BeTrue + + $Response.Body.Results.HeapCapMb | Should -Be 3072 + + $Response.Body.Results.Events | Should -HaveCount 1 + $Response.Body.Results.Events[0].Type | Should -Be 'boot' + $Response.Body.Results.Events[0].Bucket | Should -Be '2026-09-10T10:05' + $Response.Body.Results.Events[0].GapMinutes | Should -Be 3 + } + + It 'reports egress unavailable when no sample in the window carries a reading' { + $Rows = @( + [pscustomobject]@{ PartitionKey = 'InstanceHealth'; RowKey = '2026-09-10T10:00_sample'; Bucket = '2026-09-10T10:00'; Kind = 'sample'; OomCount = 0; WatchdogCount = 0; PoolExhaustedCount = 0; ErrCount = 0; MaxLimiterWaitMs = 0; StalledRunCount = 0; HeapMb = 500; HeapMbLive = $null; GcHeapLimitMb = 3072; TopEndpointsMs = $null } + ) + + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $Rows } -ParameterFilter { $Filter -match "PartitionKey eq 'InstanceHealth'" } + + $Response = Invoke-ListInstanceDiagnostics -Request (New-DiagRequest -Action 'Timeline') -TriggerMetadata $null + + $Response.Body.Results.EgressAvailable | Should -BeFalse + $Response.Body.Results.Buckets[0].EgressBytes | Should -BeNullOrEmpty + $Response.Body.Results.Buckets[0].EgressBytesToday | Should -BeNullOrEmpty + $Response.Body.Results.EgressCapBytes | Should -BeNullOrEmpty + } +} diff --git a/Tests/Extensions/Get-HaloTicketType.Tests.ps1 b/Tests/Extensions/Get-HaloTicketType.Tests.ps1 new file mode 100644 index 0000000000000..6a850690979f8 --- /dev/null +++ b/Tests/Extensions/Get-HaloTicketType.Tests.ps1 @@ -0,0 +1,26 @@ +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function Get-CIPPTable { param($TableName) @{} } + function Get-CIPPAzDataTableEntity { + [pscustomobject]@{ config = (@{ HaloPSA = @{ ResourceURL = 'https://halo.example.com/api'; ClientID = 'x' } } | ConvertTo-Json -Compress) } + } + function Get-HaloToken { param($configuration) @{ access_token = 'token' } } + function Get-CippUserAgent { 'CIPP/test' } + function Get-NormalizedError { param($Message) $Message } + + . (Join-Path $RepoRoot 'Modules/CippExtensions/Public/Halo/Get-HaloTicketType.ps1') +} + +Describe 'Get-HaloTicketType' { + It 'emits one row per ticket type when Halo answers with a JSON array' { + # Invoke-RestMethod hands a top-level JSON array back as a single Object[], matching Halo's /TicketType response. + Mock Invoke-RestMethod { , @([pscustomobject]@{ id = 21; name = 'Alert' }, [pscustomobject]@{ id = 1; name = 'Incident' }) } + + $Result = @(Get-HaloTicketType) + + $Result.Count | Should -Be 2 + $Result[0].id | Should -Be 21 + $Result[1].name | Should -Be 'Incident' + } +} diff --git a/Tests/Mcp/Invoke-CippMcpApiRequest.Tests.ps1 b/Tests/Mcp/Invoke-CippMcpApiRequest.Tests.ps1 index 157e8d880877c..f61b9899580a4 100644 --- a/Tests/Mcp/Invoke-CippMcpApiRequest.Tests.ps1 +++ b/Tests/Mcp/Invoke-CippMcpApiRequest.Tests.ps1 @@ -9,19 +9,34 @@ BeforeAll { $BackendRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) $McpRoot = Join-Path $BackendRoot 'Modules/CIPPCore/Public/MCP' - foreach ($Leaf in 'ConvertTo-CippMcpHashtable.ps1', 'Invoke-CippMcpApiRequest.ps1') { + foreach ($Leaf in 'ConvertTo-CippMcpHashtable.ps1', 'ConvertTo-CippMcpArgumentShape.ps1', 'Invoke-CippMcpApiRequest.ps1') { . (Join-Path $McpRoot $Leaf) } # The router is stubbed: these tests are about how a response is shaped for the model, - # not about routing, RBAC or the endpoint behind it. - function New-CippCoreRequest { return $script:StubResponse } + # not about routing, RBAC or the endpoint behind it. The request it receives is captured so + # the argument-shaping tests can assert what the endpoint would have seen. + function New-CippCoreRequest { + param($Request, $TriggerMetadata) + $script:CapturedRequest = $Request + return $script:StubResponse + } function Invoke-ToolResult { param($Body, $StatusCode = 200) $script:StubResponse = [pscustomobject]@{ Body = $Body; StatusCode = $StatusCode } return Invoke-CippMcpApiRequest -Request ([pscustomobject]@{ Headers = @{} }) -ToolName 'ListThings' -Arguments @{} } + + # Dispatches with a schema and returns the request the router would have received, so a test + # can inspect the coerced Query/Body the endpoint sees. + function Get-DispatchedRequest { + param($Arguments, $InputSchema, $Method = 'GET') + $script:StubResponse = [pscustomobject]@{ Body = @(); StatusCode = 200 } + $script:CapturedRequest = $null + $null = Invoke-CippMcpApiRequest -Request ([pscustomobject]@{ Headers = @{} }) -ToolName 'ListThings' -Arguments $Arguments -Method $Method -InputSchema $InputSchema + return $script:CapturedRequest + } } Describe 'MCP tool result normalisation' { @@ -138,3 +153,66 @@ Describe 'MCP tool result normalisation' { } } } + +Describe 'MCP argument shaping (LabelValue coercion)' { + # An autocomplete/select field is read by the endpoint as $Field.value, so the spec documents + # it as a LabelValue object. A caller that sends a bare string used to reach the endpoint + # unchanged, .value resolved to $null, and a field that scopes the query silently dropped the + # scope - an unscoped 200 instead of an error. The dispatch path now reshapes it to { value }. + BeforeAll { + $script:UserSchema = @{ + type = 'object' + properties = @{ + user = @{ type = 'object'; properties = @{ value = @{ type = 'string' }; label = @{ type = 'string' } }; required = @('value') } + } + } + $script:UsersArraySchema = @{ + type = 'object' + properties = @{ + users = @{ type = 'array'; items = @{ type = 'object'; properties = @{ value = @{ type = 'string' } }; required = @('value') } } + } + } + } + + It 'wraps a bare string for a LabelValue field into { value }, on a POST body' { + $Request = Get-DispatchedRequest -Arguments @{ user = 'user@contoso.com' } -InputSchema $script:UserSchema -Method 'POST' + $Request.Body.user | Should -BeOfType [hashtable] + $Request.Body.user.value | Should -Be 'user@contoso.com' + } + + It 'wraps a bare string for a LabelValue field into { value }, on a GET query' { + $Request = Get-DispatchedRequest -Arguments @{ user = 'user@contoso.com' } -InputSchema $script:UserSchema -Method 'GET' + $Request.Query.user.value | Should -Be 'user@contoso.com' + } + + It 'leaves an already-correct { value } object untouched' { + $Request = Get-DispatchedRequest -Arguments @{ user = @{ value = 'user@contoso.com'; label = 'User' } } -InputSchema $script:UserSchema -Method 'POST' + $Request.Body.user.value | Should -Be 'user@contoso.com' + $Request.Body.user.label | Should -Be 'User' + } + + It 'wraps each bare string in an array-of-LabelValue field' { + $Request = Get-DispatchedRequest -Arguments @{ users = @('a@contoso.com', 'b@contoso.com') } -InputSchema $script:UsersArraySchema -Method 'POST' + @($Request.Body.users).Count | Should -Be 2 + $Request.Body.users[0].value | Should -Be 'a@contoso.com' + $Request.Body.users[1].value | Should -Be 'b@contoso.com' + } + + It 'wraps a single bare string into a one-element array for an array-of-LabelValue field' { + $Request = Get-DispatchedRequest -Arguments @{ users = 'only@contoso.com' } -InputSchema $script:UsersArraySchema -Method 'POST' + @($Request.Body.users).Count | Should -Be 1 + $Request.Body.users[0].value | Should -Be 'only@contoso.com' + } + + It 'leaves a field the schema does not describe exactly as sent' { + $Request = Get-DispatchedRequest -Arguments @{ tenantFilter = 'contoso.com' } -InputSchema $script:UserSchema -Method 'POST' + $Request.Body.tenantFilter | Should -Be 'contoso.com' + } + + It 'passes a bare string through when no schema is supplied (back-compat)' { + $script:StubResponse = [pscustomobject]@{ Body = @(); StatusCode = 200 } + $script:CapturedRequest = $null + $null = Invoke-CippMcpApiRequest -Request ([pscustomobject]@{ Headers = @{} }) -ToolName 'ListThings' -Arguments @{ user = 'user@contoso.com' } -Method 'POST' + $script:CapturedRequest.Body.user | Should -Be 'user@contoso.com' + } +} diff --git a/Tests/Private/Get-CIPPCAPolicyIdentityCoverage.Tests.ps1 b/Tests/Private/Get-CIPPCAPolicyIdentityCoverage.Tests.ps1 new file mode 100644 index 0000000000000..f26f289f1cefd --- /dev/null +++ b/Tests/Private/Get-CIPPCAPolicyIdentityCoverage.Tests.ps1 @@ -0,0 +1,565 @@ +# Pester tests for Get-CIPPCAPolicyIdentityCoverage — identity assignment who/why resolution. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Get-CIPPCAPolicyIdentityCoverage.ps1') + + function New-GraphGetRequest { param($uri, $tenantid, $AsApp, $ErrorAction, $noPagination, $ComplexFilter) } + function New-GraphBulkRequest { param($Requests, $tenantid, $asapp, $Version) } + function New-GraphPOSTRequest { param($uri, $tenantid, $body, $AsApp, $type) } + + $script:UserA = 'aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa' + $script:UserB = 'bbbbbbbb-bbbb-bbbb-bbbb-bbbbbbbbbbbb' + $script:UserC = 'cccccccc-cccc-cccc-cccc-cccccccccccc' + $script:UserX = 'xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx' + $script:GroupStaff = '11111111-1111-1111-1111-111111111111' + $script:GroupBreak = '22222222-2222-2222-2222-222222222222' + $script:GroupAdmins = '33333333-3333-3333-3333-333333333333' + $script:RoleGa = '62e90394-69f5-4237-9190-012177145e10' + $script:RoleGaDef = '62e90394-69f5-4237-9190-012177145e10' +} + +Describe 'Get-CIPPCAPolicyIdentityCoverage' { + BeforeEach { + Mock -CommandName New-GraphPOSTRequest -MockWith { + [pscustomobject]@{ + value = @( + [pscustomobject]@{ id = $script:UserA; displayName = 'Alice'; userPrincipalName = 'alice@contoso.com'; userType = 'Member' } + [pscustomobject]@{ id = $script:UserB; displayName = 'Bob'; userPrincipalName = 'bob@contoso.com'; userType = 'Member' } + [pscustomobject]@{ id = $script:UserC; displayName = 'Carol'; userPrincipalName = 'carol@contoso.com'; userType = 'Member' } + ) + } + } + Mock -CommandName New-GraphBulkRequest -MockWith { @() } + Mock -CommandName New-GraphGetRequest -MockWith { @() } + } + + It 'returns only touched users (untouched directory user absent)' { + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ + id = 'policy-1' + displayName = 'Include Alice' + state = 'enabled' + conditions = [pscustomobject]@{ + users = [pscustomobject]@{ + includeUsers = @($script:UserA) + excludeUsers = @() + includeGroups = @() + excludeGroups = @() + includeRoles = @() + excludeRoles = @() + } + } + } + } -ParameterFilter { $uri -like '*/conditionalAccess/policies/*' } + + $Result = Get-CIPPCAPolicyIdentityCoverage -TenantFilter 'contoso.com' -PolicyId 'policy-1' + + $Result.identities.id | Should -Contain $script:UserA + $Result.identities.id | Should -Not -Contain $script:UserX + $Result.summary.touchedCount | Should -Be 1 + $Result.identities[0].status | Should -Be 'covered' + $Result.identities[0].includeReasons[0].value | Should -Be "includeUsers:$($script:UserA)" + } + + It 'keeps exclude-only users with status excluded' { + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ + id = 'policy-2' + displayName = 'Exclude only Bob' + state = 'enabled' + conditions = [pscustomobject]@{ + users = [pscustomobject]@{ + includeUsers = @('None') + excludeUsers = @($script:UserB) + includeGroups = @() + excludeGroups = @() + includeRoles = @() + excludeRoles = @() + } + } + } + } -ParameterFilter { $uri -like '*/conditionalAccess/policies/*' } + + $Result = Get-CIPPCAPolicyIdentityCoverage -TenantFilter 'contoso.com' -PolicyId 'policy-2' + + $Result.identities.Count | Should -Be 1 + $Result.identities[0].id | Should -Be $script:UserB + $Result.identities[0].status | Should -Be 'excluded' + $Result.identities[0].includeReasons.Count | Should -Be 0 + $Result.identities[0].excludeReasons[0].type | Should -Be 'excludeUsers' + } + + It 'sets includesAllUsers without emitting every directory user' { + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ + id = 'policy-3' + displayName = 'All users' + state = 'enabled' + conditions = [pscustomobject]@{ + users = [pscustomobject]@{ + includeUsers = @('All') + excludeUsers = @() + includeGroups = @() + excludeGroups = @() + includeRoles = @() + excludeRoles = @() + } + } + } + } -ParameterFilter { $uri -like '*/conditionalAccess/policies/*' } + + $Result = Get-CIPPCAPolicyIdentityCoverage -TenantFilter 'contoso.com' -PolicyId 'policy-3' + + $Result.includesAllUsers | Should -BeTrue + $Result.hasExclusions | Should -BeFalse + $Result.identities.Count | Should -Be 0 + $Result.summary.touchedCount | Should -Be 0 + } + + It 'All + exclude user yields excluded row with All include reason' { + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ + id = 'policy-4' + displayName = 'All minus Alice' + state = 'enabledForReportingButNotEnforced' + conditions = [pscustomobject]@{ + users = [pscustomobject]@{ + includeUsers = @('All') + excludeUsers = @($script:UserA) + includeGroups = @() + excludeGroups = @() + includeRoles = @() + excludeRoles = @() + } + } + } + } -ParameterFilter { $uri -like '*/conditionalAccess/policies/*' } + + $Result = Get-CIPPCAPolicyIdentityCoverage -TenantFilter 'contoso.com' -PolicyId 'policy-4' + + $Result.includesAllUsers | Should -BeTrue + $Result.hasExclusions | Should -BeTrue + $Result.identities.Count | Should -Be 1 + $Result.identities[0].status | Should -Be 'excluded' + $Result.identities[0].includeReasons.value | Should -Contain 'includeUsers:All' + $Result.identities[0].excludeReasons.type | Should -Contain 'excludeUsers' + $Result.state | Should -Be 'enabledForReportingButNotEnforced' + } + + It 'include+exclude yields status excluded with both reason arrays' { + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ + id = 'policy-5' + displayName = 'Alice included and excluded' + state = 'enabled' + conditions = [pscustomobject]@{ + users = [pscustomobject]@{ + includeUsers = @($script:UserA) + excludeUsers = @($script:UserA) + includeGroups = @() + excludeGroups = @() + includeRoles = @() + excludeRoles = @() + } + } + } + } -ParameterFilter { $uri -like '*/conditionalAccess/policies/*' } + + $Result = Get-CIPPCAPolicyIdentityCoverage -TenantFilter 'contoso.com' -PolicyId 'policy-5' + $Row = $Result.identities | Where-Object { $_.id -eq $script:UserA } + + $Row.status | Should -Be 'excluded' + $Row.includeReasons.Count | Should -BeGreaterThan 0 + $Row.excludeReasons.Count | Should -BeGreaterThan 0 + } + + It 'expands include groups transitively and attributes multi-path reasons' { + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ + id = 'policy-6' + displayName = 'Group and role' + state = 'enabled' + conditions = [pscustomobject]@{ + users = [pscustomobject]@{ + includeUsers = @($script:UserA) + excludeUsers = @() + includeGroups = @($script:GroupStaff) + excludeGroups = @() + includeRoles = @($script:RoleGa) + excludeRoles = @() + } + } + } + } -ParameterFilter { $uri -like '*/conditionalAccess/policies/*' } + + Mock -CommandName New-GraphGetRequest -MockWith { + @( + [pscustomobject]@{ id = $script:RoleGaDef; templateId = $script:RoleGa; displayName = 'Global Administrator' } + ) + } -ParameterFilter { $uri -like '*/roleDefinitions*' } + + Mock -CommandName New-GraphGetRequest -MockWith { + @( + [pscustomobject]@{ + principalId = $script:UserA + roleDefinitionId = $script:RoleGaDef + principal = [pscustomobject]@{ '@odata.type' = '#microsoft.graph.user'; id = $script:UserA } + } + ) + } -ParameterFilter { $uri -like '*/roleAssignments*' } + + Mock -CommandName New-GraphBulkRequest -MockWith { + param($Requests, $tenantid, $asapp, $Version) + $Out = [System.Collections.Generic.List[object]]::new() + foreach ($Req in $Requests) { + if ($Req.id -like 'details-*') { + $Out.Add([pscustomobject]@{ + id = $Req.id + status = 200 + body = [pscustomobject]@{ id = $script:GroupStaff; displayName = 'All Staff' } + }) + } elseif ($Req.id -like 'transitive-*') { + $Out.Add([pscustomobject]@{ + id = $Req.id + status = 200 + body = [pscustomobject]@{ + value = @( + [pscustomobject]@{ id = $script:UserA } + [pscustomobject]@{ id = $script:UserB } + ) + } + }) + } elseif ($Req.id -like 'direct-*') { + # Alice is a direct member; Bob is only nested. + $Out.Add([pscustomobject]@{ + id = $Req.id + status = 200 + body = [pscustomobject]@{ + value = @( + [pscustomobject]@{ id = $script:UserA } + ) + } + }) + } + } + return @($Out) + } + + $Result = Get-CIPPCAPolicyIdentityCoverage -TenantFilter 'contoso.com' -PolicyId 'policy-6' + $Alice = $Result.identities | Where-Object { $_.id -eq $script:UserA } + $Bob = $Result.identities | Where-Object { $_.id -eq $script:UserB } + + $Alice | Should -Not -BeNullOrEmpty + $Alice.status | Should -Be 'covered' + $Alice.includeReasons.Count | Should -BeGreaterOrEqual 3 + ($Alice.includeReasons | Where-Object { $_.type -eq 'includeUsers' }).Count | Should -Be 1 + ($Alice.includeReasons | Where-Object { $_.type -eq 'includeGroups' }).Count | Should -Be 1 + ($Alice.includeReasons | Where-Object { $_.type -eq 'includeRoles' }).Count | Should -Be 1 + $AliceGroup = $Alice.includeReasons | Where-Object { $_.type -eq 'includeGroups' } | Select-Object -First 1 + $AliceGroup.label | Should -Be 'Group: All Staff' + $AliceGroup.transitive | Should -BeFalse + + $Bob.status | Should -Be 'covered' + $BobGroup = $Bob.includeReasons | Where-Object { $_.type -eq 'includeGroups' } | Select-Object -First 1 + $BobGroup.label | Should -Be 'Group: All Staff (nested)' + $BobGroup.transitive | Should -BeTrue + $Result.identities.id | Should -Not -Contain $script:UserC + } + + It 'records unresolved deleted group GUIDs' { + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ + id = 'policy-7' + displayName = 'Missing group' + state = 'disabled' + conditions = [pscustomobject]@{ + users = [pscustomobject]@{ + includeUsers = @() + excludeUsers = @() + includeGroups = @($script:GroupBreak) + excludeGroups = @() + includeRoles = @() + excludeRoles = @() + } + } + } + } -ParameterFilter { $uri -like '*/conditionalAccess/policies/*' } + + Mock -CommandName New-GraphBulkRequest -MockWith { + @( + [pscustomobject]@{ + id = "details-$($script:GroupBreak)" + status = 404 + body = [pscustomobject]@{ error = [pscustomobject]@{ message = 'Not Found' } } + } + [pscustomobject]@{ + id = "transitive-$($script:GroupBreak)" + status = 404 + body = $null + } + [pscustomobject]@{ + id = "direct-$($script:GroupBreak)" + status = 404 + body = $null + } + ) + } + + $Result = Get-CIPPCAPolicyIdentityCoverage -TenantFilter 'contoso.com' -PolicyId 'policy-7' + + $Result.unresolved.Count | Should -BeGreaterThan 0 + $Result.unresolved[0].field | Should -Be 'includeGroups' + $Result.unresolved[0].id | Should -Be $script:GroupBreak + $Result.state | Should -Be 'disabled' + } + + It 'expands GuestsOrExternalUsers token to guest users only' { + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ + id = 'policy-8' + displayName = 'Guests' + state = 'enabled' + conditions = [pscustomobject]@{ + users = [pscustomobject]@{ + includeUsers = @('GuestsOrExternalUsers') + excludeUsers = @() + includeGroups = @() + excludeGroups = @() + includeRoles = @() + excludeRoles = @() + } + } + } + } -ParameterFilter { $uri -like '*/conditionalAccess/policies/*' } + + Mock -CommandName New-GraphGetRequest -MockWith { + @( + [pscustomobject]@{ id = $script:UserC; displayName = 'Guest Carol'; userPrincipalName = 'carol_ext#EXT#@contoso.com'; userType = 'Guest' } + ) + } -ParameterFilter { $uri -like "*/users?*userType eq 'Guest'*" -or $uri -like '*userType%20eq%20%27Guest%27*' } + + # Fallback: match any users query for guests + Mock -CommandName New-GraphGetRequest -MockWith { + @( + [pscustomobject]@{ id = $script:UserC; displayName = 'Guest Carol'; userPrincipalName = 'carol_ext#EXT#@contoso.com'; userType = 'Guest' } + ) + } -ParameterFilter { $uri -like '*/users?*' } + + $Result = Get-CIPPCAPolicyIdentityCoverage -TenantFilter 'contoso.com' -PolicyId 'policy-8' + + $Result.identities.id | Should -Contain $script:UserC + $Result.identities[0].includeReasons.value | Should -Contain 'includeUsers:GuestsOrExternalUsers' + $Result.identities.id | Should -Not -Contain $script:UserA + } + + It 'expands group-held role assignments to transitive user members' { + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ + id = 'policy-9' + displayName = 'Admin MFA' + state = 'enabled' + conditions = [pscustomobject]@{ + users = [pscustomobject]@{ + includeUsers = @() + excludeUsers = @() + includeGroups = @() + excludeGroups = @() + includeRoles = @($script:RoleGa) + excludeRoles = @() + } + } + } + } -ParameterFilter { $uri -like '*/conditionalAccess/policies/*' } + + Mock -CommandName New-GraphGetRequest -MockWith { + @( + [pscustomobject]@{ id = $script:RoleGaDef; templateId = $script:RoleGa; displayName = 'Global Administrator' } + ) + } -ParameterFilter { $uri -like '*/roleDefinitions*' } + + Mock -CommandName New-GraphGetRequest -MockWith { + @( + [pscustomobject]@{ + principalId = $script:GroupAdmins + roleDefinitionId = $script:RoleGaDef + principal = [pscustomobject]@{ + '@odata.type' = '#microsoft.graph.group' + id = $script:GroupAdmins + displayName = 'Role Admins' + } + } + ) + } -ParameterFilter { $uri -like '*/roleAssignments*' } + + Mock -CommandName New-GraphBulkRequest -MockWith { + param($Requests, $tenantid, $asapp, $Version) + @( + [pscustomobject]@{ + id = "roleGroup-$($script:GroupAdmins)" + status = 200 + body = [pscustomobject]@{ + value = @( + [pscustomobject]@{ id = $script:UserB } + [pscustomobject]@{ id = $script:UserC } + ) + } + } + ) + } + + $Result = Get-CIPPCAPolicyIdentityCoverage -TenantFilter 'contoso.com' -PolicyId 'policy-9' + $Bob = $Result.identities | Where-Object { $_.id -eq $script:UserB } + $Carol = $Result.identities | Where-Object { $_.id -eq $script:UserC } + + $Result.identities.id | Should -Not -Contain $script:UserA + $Bob.status | Should -Be 'covered' + $Bob.includeReasons[0].label | Should -Be 'Role: Global Administrator via group Role Admins' + $Bob.includeReasons[0].viaGroupId | Should -Be $script:GroupAdmins + $Carol.status | Should -Be 'covered' + $Carol.includeReasons[0].type | Should -Be 'includeRoles' + } + + It 'filters guest blocks by guestOrExternalUserTypes and externalTenants' { + $ExternalTenant = 'dddddddd-dddd-dddd-dddd-dddddddddddd' + $OtherTenant = 'eeeeeeee-eeee-eeee-eeee-eeeeeeeeeeee' + + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ + id = 'policy-10' + displayName = 'B2B guests from one tenant' + state = 'enabled' + conditions = [pscustomobject]@{ + users = [pscustomobject]@{ + includeUsers = @() + excludeUsers = @() + includeGroups = @() + excludeGroups = @() + includeRoles = @() + excludeRoles = @() + includeGuestsOrExternalUsers = [pscustomobject]@{ + guestOrExternalUserTypes = 'b2bCollaborationGuest' + externalTenants = [pscustomobject]@{ + membershipKind = 'enumerated' + members = @($ExternalTenant) + } + } + } + } + } + } -ParameterFilter { $uri -like '*/conditionalAccess/policies/*' } + + Mock -CommandName New-GraphGetRequest -MockWith { + @( + [pscustomobject]@{ + id = $script:UserA + displayName = 'Matching B2B guest' + userPrincipalName = 'a_fabrikam.com#EXT#@contoso.com' + userType = 'Guest' + identities = @( + [pscustomobject]@{ signInType = 'federated'; issuer = $ExternalTenant } + ) + } + [pscustomobject]@{ + id = $script:UserB + displayName = 'Wrong-tenant B2B guest' + userPrincipalName = 'b_other.com#EXT#@contoso.com' + userType = 'Guest' + identities = @( + [pscustomobject]@{ signInType = 'federated'; issuer = $OtherTenant } + ) + } + [pscustomobject]@{ + id = $script:UserC + displayName = 'Internal guest' + userPrincipalName = 'carol@contoso.com' + userType = 'Guest' + identities = @() + } + ) + } -ParameterFilter { $uri -like "*/users?*userType eq 'Guest'*" -or $uri -like '*userType%20eq%20%27Guest%27*' -or ($uri -like '*/users?*' -and $uri -like '*Guest*') } + + $Result = Get-CIPPCAPolicyIdentityCoverage -TenantFilter 'contoso.com' -PolicyId 'policy-10' + + $Result.identities.id | Should -Contain $script:UserA + $Result.identities.id | Should -Not -Contain $script:UserB + $Result.identities.id | Should -Not -Contain $script:UserC + $Result.identities[0].includeReasons[0].type | Should -Be 'includeGuestsOrExternalUsers' + } + + It 'records unresolved when group member expansion throws' { + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ + id = 'policy-11' + displayName = 'Group expand fail' + state = 'enabled' + conditions = [pscustomobject]@{ + users = [pscustomobject]@{ + includeUsers = @() + excludeUsers = @() + includeGroups = @($script:GroupStaff) + excludeGroups = @() + includeRoles = @() + excludeRoles = @() + } + } + } + } -ParameterFilter { $uri -like '*/conditionalAccess/policies/*' } + + Mock -CommandName New-GraphBulkRequest -MockWith { + param($Requests, $tenantid, $asapp, $Version) + $HasMembers = @($Requests | Where-Object { $_.id -like 'transitive-*' -or $_.id -like 'direct-*' }).Count -gt 0 + if ($HasMembers) { + throw 'Graph bulk failure' + } + @( + [pscustomobject]@{ + id = "details-$($script:GroupStaff)" + status = 200 + body = [pscustomobject]@{ id = $script:GroupStaff; displayName = 'All Staff' } + } + ) + } + + $Result = Get-CIPPCAPolicyIdentityCoverage -TenantFilter 'contoso.com' -PolicyId 'policy-11' + + $Result.identities.Count | Should -Be 0 + $Result.unresolved.Count | Should -BeGreaterThan 0 + $Result.unresolved[0].field | Should -Be 'includeGroups' + $Result.unresolved[0].id | Should -Be $script:GroupStaff + $Result.unresolved[0].error | Should -Match 'Group member expansion failed' + } + + It 'does not dump all guests for non-enumerable guest types' { + Mock -CommandName New-GraphGetRequest -MockWith { + [pscustomobject]@{ + id = 'policy-12' + displayName = 'Service provider only' + state = 'enabled' + conditions = [pscustomobject]@{ + users = [pscustomobject]@{ + includeUsers = @() + excludeUsers = @() + includeGroups = @() + excludeGroups = @() + includeRoles = @() + excludeRoles = @() + includeGuestsOrExternalUsers = [pscustomobject]@{ + guestOrExternalUserTypes = 'serviceProvider' + externalTenants = [pscustomobject]@{ membershipKind = 'all' } + } + } + } + } + } -ParameterFilter { $uri -like '*/conditionalAccess/policies/*' } + + Mock -CommandName New-GraphGetRequest -MockWith { + throw 'Should not enumerate directory guests for serviceProvider-only policies' + } -ParameterFilter { $uri -like '*/users?*' } + + $Result = Get-CIPPCAPolicyIdentityCoverage -TenantFilter 'contoso.com' -PolicyId 'policy-12' + + $Result.identities.Count | Should -Be 0 + $Result.unresolved | Where-Object { $_.id -eq 'serviceProvider' } | Should -Not -BeNullOrEmpty + } +} diff --git a/Tests/Private/Get-CIPPEgressLedger.Tests.ps1 b/Tests/Private/Get-CIPPEgressLedger.Tests.ps1 new file mode 100644 index 0000000000000..df0978b9514b4 --- /dev/null +++ b/Tests/Private/Get-CIPPEgressLedger.Tests.ps1 @@ -0,0 +1,34 @@ +# Pester tests for Get-CIPPEgressLedger +# The ledger is written by Craft outside this repo, so "no data yet" (missing file, stale +# day, garbage JSON) must be indistinguishable from a real zero-byte day: both return $null, +# never a fake 0 that looks like a reading. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Functions/Get-CIPPEgressLedger.ps1') +} + +Describe 'Get-CIPPEgressLedger' { + It 'returns the bytes when the ledger is for today' { + $Now = [DateTime]::Parse('2026-09-11T12:00:00Z').ToUniversalTime() + Set-Content -Path (Join-Path $TestDrive 'egress-ledger.json') -Value '{"DateUtc":"2026-09-11","Bytes":123456}' + $Result = Get-CIPPEgressLedger -LogDirectory $TestDrive -Now $Now + $Result.Bytes | Should -Be 123456 + $Result.DateUtc | Should -Be '2026-09-11' + } + + It 'returns null when the ledger is for a previous UTC day' { + $Now = [DateTime]::Parse('2026-09-11T12:00:00Z').ToUniversalTime() + Set-Content -Path (Join-Path $TestDrive 'egress-ledger.json') -Value '{"DateUtc":"2026-09-10","Bytes":123456}' + Get-CIPPEgressLedger -LogDirectory $TestDrive -Now $Now | Should -BeNullOrEmpty + } + + It 'returns null when the file is missing' { + Get-CIPPEgressLedger -LogDirectory (Join-Path $TestDrive 'does-not-exist') | Should -BeNullOrEmpty + } + + It 'returns null for unparsable JSON' { + Set-Content -Path (Join-Path $TestDrive 'egress-ledger.json') -Value 'not json {{' + Get-CIPPEgressLedger -LogDirectory $TestDrive | Should -BeNullOrEmpty + } +} diff --git a/Tests/Private/Get-CIPPInstanceHealthSample.Tests.ps1 b/Tests/Private/Get-CIPPInstanceHealthSample.Tests.ps1 new file mode 100644 index 0000000000000..7f844769f3820 --- /dev/null +++ b/Tests/Private/Get-CIPPInstanceHealthSample.Tests.ps1 @@ -0,0 +1,151 @@ +# Pester tests for Get-CIPPInstanceHealthSample +# The self-diagnostics checks are only as good as this reduction: a signature that stops +# matching turns a FAIL into a silent PASS, which is worse than no diagnostics at all. These +# tests pin each log signature to the counter it feeds, and pin the two shapes that must not +# throw - an empty window and a window of ordinary chatter. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Functions/Get-CIPPInstanceHealthSample.ps1') +} + +Describe 'Get-CIPPInstanceHealthSample' { + BeforeEach { + $script:MixedLines = @( + '2026-09-10T10:00:00.000Z [ERR] Unhandled: System.OutOfMemoryException: Exception of type was thrown.' + '2026-09-10T10:00:01.000Z [WRN] Container startup attempt 3 of 5' + '2026-09-10T10:00:02.000Z [WRN] Restart counter = 2' + '2026-09-10T10:00:03.000Z [WRN] HTTP pool exhausted for Invoke-ListTenants' + '2026-09-10T10:00:04.000Z [INF] Limiter slot acquired after 1200ms' + '2026-09-10T10:00:05.000Z [INF] Limiter slot acquired after 300ms' + '2026-09-10T10:00:06.000Z [INF] stats heap=1834MB threads=42' + '2026-09-10T10:00:07.000Z [INF] stats heap=902MB threads=40' + '2026-09-10T10:00:08.000Z [WRN] T+125.4min: StandardsOrchestrator 0 running 12 pending' + '2026-09-10T10:00:09.000Z [INF] [HTTP] GET Invoke-ListTenants 200 1500ms' + '2026-09-10T10:00:10.000Z [INF] [HTTP] GET Invoke-ListTenants 200 500ms' + '2026-09-10T10:00:11.000Z [INF] [HTTP] POST Invoke-ExecStandards 200 900ms' + '2026-09-10T10:00:12.000Z [INF] [HTTP] GET Invoke-ListUsers 200 100ms' + '2026-09-10T10:00:13.000Z [INF] [HTTP] GET Invoke-ListDomains 500 50ms' + '2026-09-10T10:00:14.000Z [ERR] Graph request failed with 503' + '2026-09-10T10:00:15.000Z [INF] API Access: AppName=Acme RMM, AppId=11111111-1111-1111-1111-111111111111, IP=203.0.113.9' + '2026-09-10T10:00:16.000Z [INF] API Access: AppName=Acme RMM, AppId=11111111-1111-1111-1111-111111111111, IP=203.0.113.10' + '2026-09-10T10:00:17.000Z [INF] API Access: AppName=Other PSA, AppId=22222222-2222-2222-2222-222222222222, IP=198.51.100.4' + ) + } + + Context 'a window containing every signature' { + It 'counts one request when the access line repeats under the same request id' { + $Lines = @( + '2026-09-10T10:00:15.000Z [INF] [API] aaaa1111 PS Invoke-GetVersion: API Access: AppName=Local, AppId=33333333-3333-3333-3333-333333333333, IP=203.0.113.1' + '2026-09-10T10:00:15.010Z [INF] [API] aaaa1111 PS Invoke-GetVersion: API Access: AppName=Local, AppId=33333333-3333-3333-3333-333333333333, IP=203.0.113.1' + '2026-09-10T10:00:15.020Z [INF] [API] bbbb2222 PS Invoke-GetVersion: API Access: AppName=Local, AppId=33333333-3333-3333-3333-333333333333, IP=203.0.113.1' + ) + @((Get-CIPPInstanceHealthSample -Lines $Lines).Clients)[0].Count | Should -Be 2 + } + + It 'counts an access line whose forwarded IP is empty' { + $Lines = @('2026-09-10T10:00:15.000Z [INF] API Access: AppName=Local, AppId=33333333-3333-3333-3333-333333333333, IP=') + $Result = Get-CIPPInstanceHealthSample -Lines $Lines + @($Result.Clients).Count | Should -Be 1 + @($Result.Clients)[0].Count | Should -Be 1 + } + + It 'counts out-of-memory exceptions' { + (Get-CIPPInstanceHealthSample -Lines $script:MixedLines).OomCount | Should -Be 1 + } + + It 'counts both watchdog restart signatures' { + (Get-CIPPInstanceHealthSample -Lines $script:MixedLines).WatchdogCount | Should -Be 2 + } + + It 'counts pool exhaustion' { + (Get-CIPPInstanceHealthSample -Lines $script:MixedLines).PoolExhaustedCount | Should -Be 1 + } + + It 'counts error-level lines' { + (Get-CIPPInstanceHealthSample -Lines $script:MixedLines).ErrCount | Should -Be 2 + } + + It 'keeps the worst limiter wait, not the last' { + (Get-CIPPInstanceHealthSample -Lines $script:MixedLines).MaxLimiterWaitMs | Should -Be 1200 + } + + It 'keeps the peak heap sample, not the last' { + (Get-CIPPInstanceHealthSample -Lines $script:MixedLines).HeapMb | Should -Be 1834 + } + + It 'counts stalled runs' { + (Get-CIPPInstanceHealthSample -Lines $script:MixedLines).StalledRunCount | Should -Be 1 + } + + It 'sums endpoint time per function and keeps only the top three' { + $Top = (Get-CIPPInstanceHealthSample -Lines $script:MixedLines).TopEndpointsMs + $Top.Count | Should -Be 3 + $Top['Invoke-ListTenants'] | Should -Be 2000 + $Top['Invoke-ExecStandards'] | Should -Be 900 + $Top['Invoke-ListUsers'] | Should -Be 100 + $Top.ContainsKey('Invoke-ListDomains') | Should -BeFalse + } + + It 'counts egress rejections and captures distinct client names' { + $Lines = @( + '2026-09-10T10:00:00.000Z [WRN] Egress cap reached — 429 for AcmeRMM on GET /api/ListTenants; served 1000000000/1000000000 bytes today, Retry-After 30s' + '2026-09-10T10:00:01.000Z [WRN] Egress cap reached — 429 for AcmeRMM on GET /api/ListUsers; served 1000000000/1000000000 bytes today, Retry-After 30s' + '2026-09-10T10:00:02.000Z [WRN] Egress cap reached — 429 for OtherPSA on GET /api/ListDomains; served 1000000000/1000000000 bytes today, Retry-After 30s' + ) + $Sample = Get-CIPPInstanceHealthSample -Lines $Lines + $Sample.EgressRejectCount | Should -Be 3 + @($Sample.EgressRejectClients) | Should -Be @('AcmeRMM', 'OtherPSA') + } + + It 'groups API access by AppId and counts repeats' { + $Clients = (Get-CIPPInstanceHealthSample -Lines $script:MixedLines).Clients + $Clients.Count | Should -Be 2 + $Acme = $Clients | Where-Object { $_.AppName -eq 'Acme RMM' } + $Acme.Count | Should -Be 2 + $Acme.AppId | Should -Be '11111111-1111-1111-1111-111111111111' + $Acme.IP | Should -Be '203.0.113.10' + } + } + + Context 'a window with nothing to report' { + It 'returns zeroed counters for an empty window' { + $Sample = Get-CIPPInstanceHealthSample -Lines @() + $Sample.OomCount | Should -Be 0 + $Sample.WatchdogCount | Should -Be 0 + $Sample.PoolExhaustedCount | Should -Be 0 + $Sample.ErrCount | Should -Be 0 + $Sample.MaxLimiterWaitMs | Should -Be 0 + $Sample.StalledRunCount | Should -Be 0 + $Sample.TopEndpointsMs.Count | Should -Be 0 + $Sample.Clients.Count | Should -Be 0 + $Sample.EgressRejectCount | Should -Be 0 + @($Sample.EgressRejectClients).Count | Should -Be 0 + } + + It 'reports no heap reading rather than zero when no sample was logged' { + (Get-CIPPInstanceHealthSample -Lines @()).HeapMb | Should -BeNullOrEmpty + } + + It 'ignores ordinary log chatter that matches nothing' { + $Sample = Get-CIPPInstanceHealthSample -Lines @( + '2026-09-10T10:00:00.000Z [INF] Tenant cache refreshed for 214 tenants' + '2026-09-10T10:00:01.000Z [DBG] Token cache hit' + '' + ' ' + 'a line with no timestamp at all' + ) + $Sample.OomCount | Should -Be 0 + $Sample.ErrCount | Should -Be 0 + $Sample.HeapMb | Should -BeNullOrEmpty + $Sample.Clients.Count | Should -Be 0 + $Sample.TopEndpointsMs.Count | Should -Be 0 + } + + It 'does not count a completed run as stalled' { + # 0 pending is the healthy shape and must stay below the signature. + $Sample = Get-CIPPInstanceHealthSample -Lines @('2026-09-10T10:00:00.000Z [INF] T+125.4min: StandardsOrchestrator 0 running 0 pending') + $Sample.StalledRunCount | Should -Be 0 + } + } +} diff --git a/Tests/Private/Get-CippRequestIPAddress.Tests.ps1 b/Tests/Private/Get-CippRequestIPAddress.Tests.ps1 new file mode 100644 index 0000000000000..cf51004b3845a --- /dev/null +++ b/Tests/Private/Get-CippRequestIPAddress.Tests.ps1 @@ -0,0 +1,40 @@ +# Unit tests for Get-CippRequestIPAddress: first x-forwarded-for hop with any port +# suffix and IPv6 brackets stripped; missing header yields an empty string. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + . (Join-Path $RepoRoot 'Modules/CIPPCore/Private/Authentication/Get-CippRequestIPAddress.ps1') + + function New-IPRequest { + param($ForwardedFor) + $Headers = @{} + if ($null -ne $ForwardedFor) { $Headers['x-forwarded-for'] = $ForwardedFor } + [pscustomobject]@{ Headers = $Headers } + } +} + +Describe 'Get-CippRequestIPAddress' { + It 'returns a plain IPv4 unchanged' { + Get-CippRequestIPAddress -Request (New-IPRequest '1.2.3.4') | Should -Be '1.2.3.4' + } + + It 'strips a port from IPv4' { + Get-CippRequestIPAddress -Request (New-IPRequest '1.2.3.4:8080') | Should -Be '1.2.3.4' + } + + It 'strips brackets and port from bracketed IPv6' { + Get-CippRequestIPAddress -Request (New-IPRequest '[::1]:443') | Should -Be '::1' + } + + It 'returns bare IPv6 unchanged' { + Get-CippRequestIPAddress -Request (New-IPRequest '2001:db8::1') | Should -Be '2001:db8::1' + } + + It 'takes only the first hop of a multi-hop header' { + Get-CippRequestIPAddress -Request (New-IPRequest '9.9.9.9, 8.8.8.8, 7.7.7.7') | Should -Be '9.9.9.9' + } + + It 'returns an empty string when the header is missing' { + Get-CippRequestIPAddress -Request (New-IPRequest $null) | Should -Be '' + } +} diff --git a/Tests/Private/Select-CIPPIntuneAvailableSetting.Tests.ps1 b/Tests/Private/Select-CIPPIntuneAvailableSetting.Tests.ps1 new file mode 100644 index 0000000000000..4f50890d54fb4 --- /dev/null +++ b/Tests/Private/Select-CIPPIntuneAvailableSetting.Tests.ps1 @@ -0,0 +1,125 @@ +# Pester tests for Select-CIPPIntuneAvailableSetting. +# +# The helper reduces a Catalog policy to the settings a tenant offers. ThrowOnMissingRequired adds a +# deploy-only guard for Apple enrollment (ADE) policies: Microsoft marks every Setup Assistant option +# required and keeps adding new ones, so a template captured before an option existed can no longer +# deploy and Graph returns an opaque "required Setting not present" error. The guard must fire only +# for the enrollment family, only when asked, and only when a required setting is genuinely absent. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + # Stub mirrors the real signature so drift fails loudly here. + function New-GraphGETRequest { [CmdletBinding()] param($uri, $tenantid, $AsApp, $ComplexFilter) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Select-CIPPIntuneAvailableSetting.ps1') + + $script:Tenant = 'contoso.onmicrosoft.com' + + # Builds one settingTemplates entry as Graph returns it (settingInstanceTemplate + expanded + # settingDefinitions), matching what the helper reads. + function New-SettingTemplate { + param($InstanceId, $DefinitionId, [bool]$Required, $DisplayName) + [PSCustomObject]@{ + settingInstanceTemplate = [PSCustomObject]@{ + settingInstanceTemplateId = $InstanceId + settingDefinitionId = $DefinitionId + isRequired = $Required + choiceSettingValueTemplate = [PSCustomObject]@{ settingValueTemplateId = "$InstanceId-val" } + } + settingDefinitions = @([PSCustomObject]@{ id = $DefinitionId; displayName = $DisplayName }) + } + } + + # Builds one policy setting instance referencing a setting instance template. + function New-PolicySetting { + param($InstanceId, $DefinitionId) + [PSCustomObject]@{ + settingInstance = [PSCustomObject]@{ + settingDefinitionId = $DefinitionId + settingInstanceTemplateReference = [PSCustomObject]@{ settingInstanceTemplateId = $InstanceId } + choiceSettingValue = [PSCustomObject]@{ + value = "$DefinitionId`_1" + settingValueTemplateReference = [PSCustomObject]@{ settingValueTemplateId = "$InstanceId-val" } + } + } + } + } + + # An ADE-style template: two required settings, one optional. + $script:AdeSettingTemplates = @( + New-SettingTemplate -InstanceId 'inst-affinity' -DefinitionId 'ade_useraffinity' -Required $true -DisplayName 'User affinity' + New-SettingTemplate -InstanceId 'inst-a11y' -DefinitionId 'ade_setupassistant_accessibilityappearance' -Required $true -DisplayName 'Accessibility appearance' + New-SettingTemplate -InstanceId 'inst-certs' -DefinitionId 'ade_appleconfiguratorcertificates' -Required $false -DisplayName 'Certificates' + ) + + function New-AdePolicy { + param([string[]]$IncludeInstanceIds) + $map = @{ + 'inst-affinity' = 'ade_useraffinity' + 'inst-a11y' = 'ade_setupassistant_accessibilityappearance' + 'inst-certs' = 'ade_appleconfiguratorcertificates' + } + $settings = @(foreach ($id in $IncludeInstanceIds) { New-PolicySetting -InstanceId $id -DefinitionId $map[$id] }) + [PSCustomObject]@{ + name = 'iOS Enrollment' + technologies = 'enrollment' + templateReference = [PSCustomObject]@{ templateId = 'ade-template_1'; templateFamily = 'enrollmentConfiguration' } + settings = $settings + } + } +} + +Describe 'Select-CIPPIntuneAvailableSetting -ThrowOnMissingRequired' { + BeforeEach { + # Isolate the per-tenant/template lookup cache between tests. + $script:CIPPIntuneSettingTemplateCache = @{} + Mock -CommandName New-GraphGETRequest -MockWith { $script:AdeSettingTemplates } + } + + Context 'an Apple enrollment policy missing a required setting' { + It 'throws an actionable error naming the missing setting by its friendly name' { + $Policy = New-AdePolicy -IncludeInstanceIds @('inst-affinity', 'inst-certs') + + { Select-CIPPIntuneAvailableSetting -Policy $Policy -TenantFilter $script:Tenant -ThrowOnMissingRequired } | + Should -Throw -ExpectedMessage '*Accessibility appearance*' + } + + It 'does not throw when the guard is not requested (comparison and drift paths)' { + $Policy = New-AdePolicy -IncludeInstanceIds @('inst-affinity', 'inst-certs') + + { Select-CIPPIntuneAvailableSetting -Policy $Policy -TenantFilter $script:Tenant } | + Should -Not -Throw + } + } + + Context 'an Apple enrollment policy with every required setting present' { + It 'returns the policy without throwing' { + $Policy = New-AdePolicy -IncludeInstanceIds @('inst-affinity', 'inst-a11y', 'inst-certs') + + $Result = Select-CIPPIntuneAvailableSetting -Policy $Policy -TenantFilter $script:Tenant -ThrowOnMissingRequired + $Result.name | Should -Be 'iOS Enrollment' + } + } + + Context 'a non-enrollment (Endpoint Security) policy missing a required setting' { + It 'is never validated - those deploy fine as a subset' { + $Policy = New-AdePolicy -IncludeInstanceIds @('inst-affinity', 'inst-certs') + $Policy.technologies = 'mdm,microsoftSense' + $Policy.templateReference.templateFamily = 'endpointSecurityAntivirus' + + { Select-CIPPIntuneAvailableSetting -Policy $Policy -TenantFilter $script:Tenant -ThrowOnMissingRequired } | + Should -Not -Throw + } + } + + Context 'the setting template lookup returns nothing' { + It 'returns the policy untouched rather than throwing' { + Mock -CommandName New-GraphGETRequest -MockWith { @() } + $Policy = New-AdePolicy -IncludeInstanceIds @('inst-affinity', 'inst-certs') + + { Select-CIPPIntuneAvailableSetting -Policy $Policy -TenantFilter $script:Tenant -ThrowOnMissingRequired } | + Should -Not -Throw + } + } +} diff --git a/Tests/Private/Set-CIPPIntunePolicy.Enrollment.Tests.ps1 b/Tests/Private/Set-CIPPIntunePolicy.Enrollment.Tests.ps1 new file mode 100644 index 0000000000000..bfa2e233e14d9 --- /dev/null +++ b/Tests/Private/Set-CIPPIntunePolicy.Enrollment.Tests.ps1 @@ -0,0 +1,126 @@ +# Pester tests for the Apple enrollment (ADE) token binding in the Catalog branch of +# Set-CIPPIntunePolicy. +# +# ADE enrollment policies are Settings Catalog policies that must POST a creationSource binding them +# to the tenant's ADE token ("DepTokenId_{tokenId}"). The token id is per tenant, so templates carry +# a %ADETokenId% placeholder resolved from the tenant's custom variable at deploy time. Without a +# resolved token the DCV2 create fails with an opaque generic error, so deployment fails early with +# the tenant's real token id(s) instead. Ordinary (non-enrollment) Catalog policies are untouched. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + # Stubs mirror the real signatures so signature drift fails loudly here. + function New-GraphGETRequest { [CmdletBinding()] param($uri, $tenantid, $AsApp, $ComplexFilter) } + function New-GraphPOSTRequest { [CmdletBinding()] param($uri, $tenantid, $type, $body, $AddedHeaders) } + function Write-LogMessage { [CmdletBinding()] param($message, $tenant, $API, $tenantId, $headers, $user, $sev, $Sev2, $LogData) } + function Get-CippException { [CmdletBinding()] param($Exception) } + function Get-CIPPTextReplacement { [CmdletBinding()] param([string]$TenantFilter, $Text, [switch]$EscapeForJson) } + function Get-CIPPIntunePolicyName { [CmdletBinding()] param($TemplateType, $RawJSON, $DisplayName) } + function Select-CIPPIntuneAvailableSetting { [CmdletBinding()] param($Policy, [string]$TenantFilter, [switch]$ThrowOnMissingRequired) } + function Find-CIPPFuzzyPolicyMatch { [CmdletBinding()] param($DisplayName, $ExistingPolicies, $MaxDistance, $ODataType, $NameProperty, $TemplateId) } + function Set-CIPPAssignedPolicy { [CmdletBinding()] param($GroupName, $PolicyId, $PlatformType, $Type, $TenantFilter, $ExcludeGroup, $AssignmentMode, $AssignmentFilterName, $AssignmentFilterType) } + function Sync-CIPPReusablePolicySettings { [CmdletBinding()] param($TemplateInfo, $Tenant) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Set-CIPPIntunePolicy.ps1') + + $script:Tenant = 'contoso.onmicrosoft.com' + + function New-EnrollmentPolicy { + param($CreationSource) + $Policy = [ordered]@{ + name = 'iOS_enroll' + technologies = 'enrollment' + templateReference = [ordered]@{ templateId = '27d20e9c_1'; templateFamily = 'enrollmentConfiguration' } + settings = @() + } + if ($PSBoundParameters.ContainsKey('CreationSource')) { $Policy.creationSource = $CreationSource } + return ($Policy | ConvertTo-Json -Depth 10) + } +} + +Describe 'Set-CIPPIntunePolicy -TemplateType Catalog (Apple enrollment token binding)' { + BeforeEach { + Mock -CommandName Write-LogMessage -MockWith { } + # The replacement pass leaves the text as-is here, so an unset %ADETokenId% survives to the gate. + Mock -CommandName Get-CIPPTextReplacement -MockWith { $Text } + Mock -CommandName Get-CIPPIntunePolicyName -MockWith { 'iOS_enroll' } + Mock -CommandName Select-CIPPIntuneAvailableSetting -MockWith { $Policy } + Mock -CommandName Find-CIPPFuzzyPolicyMatch -MockWith { $null } + Mock -CommandName Set-CIPPAssignedPolicy -MockWith { } + # A plain throw normalises to its own message, which is how the reason reaches the caller. + Mock -CommandName Get-CippException -MockWith { [PSCustomObject]@{ NormalizedError = $Exception.Exception.Message } } + # depOnboardingSettings returns the tenant's ADE token(s); everything else (existing policy + # list) returns nothing so the add path is taken. + Mock -CommandName New-GraphGETRequest -MockWith { + if ($uri -match 'depOnboardingSettings') { @([pscustomobject]@{ id = 'TOKEN-ABC' }) } else { @() } + } + Mock -CommandName New-GraphPOSTRequest -MockWith { [PSCustomObject]@{ id = 'new-policy-id' } } + } + + Context 'an enrollment policy whose token placeholder was not resolved' { + It 'throws a clear error naming the ADETokenId variable and the tenant token id, without posting' { + $RawJSON = New-EnrollmentPolicy -CreationSource 'DepTokenId_%ADETokenId%' + + { Set-CIPPIntunePolicy -TemplateType 'Catalog' -DisplayName 'iOS_enroll' ` + -RawJSON $RawJSON -TenantFilter $script:Tenant } | + Should -Throw -ExpectedMessage '*ADETokenId*TOKEN-ABC*' + + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly + } + } + + Context 'an enrollment policy with no creationSource at all (captured before this change)' { + It 'throws rather than letting Graph fail generically' { + $RawJSON = New-EnrollmentPolicy + + { Set-CIPPIntunePolicy -TemplateType 'Catalog' -DisplayName 'iOS_enroll' ` + -RawJSON $RawJSON -TenantFilter $script:Tenant } | + Should -Throw -ExpectedMessage '*ADE token binding*' + + Should -Invoke New-GraphPOSTRequest -Times 0 -Exactly + } + } + + Context 'the tenant has no ADE token at all' { + It 'says so instead of naming a token id' { + Mock -CommandName New-GraphGETRequest -MockWith { @() } + $RawJSON = New-EnrollmentPolicy -CreationSource 'DepTokenId_%ADETokenId%' + + { Set-CIPPIntunePolicy -TemplateType 'Catalog' -DisplayName 'iOS_enroll' ` + -RawJSON $RawJSON -TenantFilter $script:Tenant } | + Should -Throw -ExpectedMessage '*no Apple ADE/DEP token*' + } + } + + Context 'an enrollment policy whose token was resolved to a real id' { + It 'posts the policy with creationSource intact' { + $RawJSON = New-EnrollmentPolicy -CreationSource 'DepTokenId_REAL-TOKEN-ID' + + $Result = Set-CIPPIntunePolicy -TemplateType 'Catalog' -DisplayName 'iOS_enroll' ` + -RawJSON $RawJSON -TenantFilter $script:Tenant + + $Result | Should -BeLike '*Successfully added*' + Should -Invoke New-GraphPOSTRequest -Times 1 -Exactly -ParameterFilter { + $type -eq 'POST' -and ($body | ConvertFrom-Json).creationSource -eq 'DepTokenId_REAL-TOKEN-ID' + } + } + } + + Context 'an ordinary (non-enrollment) Catalog policy with no creationSource' { + It 'is never gated and deploys normally' { + $RawJSON = [ordered]@{ + name = 'Settings Catalog Policy' + technologies = 'mdm' + templateReference = [ordered]@{ templateId = ''; templateFamily = 'none' } + settings = @() + } | ConvertTo-Json -Depth 10 + + $Result = Set-CIPPIntunePolicy -TemplateType 'Catalog' -DisplayName 'Settings Catalog Policy' ` + -RawJSON $RawJSON -TenantFilter $script:Tenant + + $Result | Should -BeLike '*Successfully added*' + Should -Invoke New-GraphPOSTRequest -Times 1 -Exactly + } + } +} diff --git a/Tests/Private/Test-CIPPAccess.BlockedEndpoints.Tests.ps1 b/Tests/Private/Test-CIPPAccess.BlockedEndpoints.Tests.ps1 index 56feb718ecd9a..e230185b406da 100644 --- a/Tests/Private/Test-CIPPAccess.BlockedEndpoints.Tests.ps1 +++ b/Tests/Private/Test-CIPPAccess.BlockedEndpoints.Tests.ps1 @@ -21,6 +21,9 @@ BeforeAll { . $ScopeHelperPath . $FunctionPath + $PrivateAuthDir = Join-Path $RepoRoot 'Modules/CIPPCore/Private/Authentication' + . (Join-Path $PrivateAuthDir 'Get-CippRequestIPAddress.ps1') + . (Join-Path $PrivateAuthDir 'Find-CippBaseRole.ps1') $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } diff --git a/Tests/Private/Test-CIPPAccess.Core.Tests.ps1 b/Tests/Private/Test-CIPPAccess.Core.Tests.ps1 new file mode 100644 index 0000000000000..e2f5e8457d559 --- /dev/null +++ b/Tests/Private/Test-CIPPAccess.Core.Tests.ps1 @@ -0,0 +1,654 @@ +# Characterization tests for Test-CIPPAccess. These encode CURRENT behavior exactly, +# including quirks, so a later simplification pass is protected. The function is not changed. +# +# Harness mirrors the sibling Test-CIPPAccess.*.Tests.ps1 files: dot-source the function, +# stub the external surface, pre-seed the runspace caches ($script:CIPPFunctionPermissions, +# $script:CIPPBaseRoles) so no config/storage/network is touched. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $AuthDir = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Authentication' + $FunctionPath = Join-Path $AuthDir 'Test-CIPPAccess.ps1' + $ScopeHelperPath = Join-Path $AuthDir 'Test-CippRoleTenantScope.ps1' + + # /me returns build [HttpResponseContext]@{...} with [HttpStatusCode]::OK; neither short + # name resolves when the function is dot-sourced without `using namespace System.Net`, + # so shim both. Only the /me IP-exemption test needs them. + class HttpResponseContext { + [int]$StatusCode + [object]$Body + [object]$ContentType + } + enum HttpStatusCode { + OK = 200 + } + + # Stub the full external surface every exercised path touches. + function Get-CippApiClient { param($AppId) } + function Test-IpInRange { param($IPAddress, $Range) $false } + function Get-CIPPRolePermissions { param($Role) } + function Get-Tenants { param([switch]$IncludeErrors) @() } + function Get-CippAccessScopeRule { param($Role) } + function Get-CIPPRoleIPRanges { param($Roles) @('Any') } + function Test-CIPPAccessUserRole { param($User) $User } + function Resolve-CippImpersonation { param($User, $Request) [pscustomobject]@{ User = $User; Impersonating = $null; RealRoles = $User.userRoles } } + function Get-CippAllowedPermissions { param($UserRoles) @() } + function Expand-CIPPTenantGroups { param($TenantFilter) @() } + function Write-LogMessage { param($message, $API, $tenant, $sev, $user, $LogData) } + + $PrivateAuthDir = Join-Path $RepoRoot 'Modules/CIPPCore/Private/Authentication' + + . $ScopeHelperPath + . $FunctionPath + . (Join-Path $PrivateAuthDir 'New-CippMeResponse.ps1') + . (Join-Path $PrivateAuthDir 'Get-CippRequestIPAddress.ps1') + . (Join-Path $PrivateAuthDir 'Find-CippBaseRole.ps1') + + # Base roles shaped like Config/cipp-roles.json (include/exclude wildcard arrays). + $script:SeedBaseRoles = [pscustomobject]@{ + readonly = [pscustomobject]@{ include = @('*.Read'); exclude = @('CIPP.SuperAdmin.*', 'CIPP.Admin.*', 'CIPP.AppSettings.*') } + editor = [pscustomobject]@{ include = @('*.Read', '*.ReadWrite'); exclude = @('CIPP.SuperAdmin.*', 'CIPP.Admin.*', 'CIPP.AppSettings.*', 'Tenant.Standards.ReadWrite') } + admin = [pscustomobject]@{ include = @('*'); exclude = @('CIPP.SuperAdmin.*') } + superadmin = [pscustomobject]@{ include = @('*'); exclude = @() } + } + + # Encode a user principal the way Azure SWA delivers it: base64(JSON) in x-ms-client-principal. + function ConvertTo-PrincipalHeader { + param($Principal) + [System.Convert]::ToBase64String([System.Text.Encoding]::UTF8.GetBytes(($Principal | ConvertTo-Json -Depth 6 -Compress))) + } + + # A user request. Pass an explicit principal object, or roles to build a standard one. + function New-UserRequest { + param( + [string]$CIPPEndpoint = 'ExecResetPass', + [string[]]$UserRoles = @('editor'), + [object]$Principal, + [hashtable]$Query = @{}, + [hashtable]$Body = @{}, + [string]$ForwardedFor = '1.2.3.4', + [switch]$OmitForwardedFor + ) + if (-not $PSBoundParameters.ContainsKey('Principal')) { + $Principal = [pscustomobject]@{ + identityProvider = 'aad' + userId = '00000000-0000-0000-0000-000000000001' + userDetails = 'user@contoso.com' + userRoles = $UserRoles + } + } + $Headers = @{ + 'x-ms-client-principal' = (ConvertTo-PrincipalHeader -Principal $Principal) + 'x-ms-client-principal-name' = 'user@contoso.com' + } + if (-not $OmitForwardedFor) { $Headers['x-forwarded-for'] = $ForwardedFor } + [pscustomobject]@{ + Params = @{ CIPPEndpoint = $CIPPEndpoint } + Headers = $Headers + Query = $Query + Body = $Body + } + } + + # An API-client request (aad idp + GUID principal name) -> APIClient branch. + function New-ApiClientRequest { + param( + [string]$CIPPEndpoint = 'ExecResetPass', + [hashtable]$Query = @{}, + [hashtable]$Body = @{}, + [string]$ForwardedFor = '1.2.3.4' + ) + [pscustomobject]@{ + Params = @{ CIPPEndpoint = $CIPPEndpoint } + Headers = @{ + 'x-ms-client-principal-idp' = 'aad' + 'x-ms-client-principal-name' = '11111111-1111-1111-1111-111111111111' + 'x-forwarded-for' = $ForwardedFor + } + Query = $Query + Body = $Body + } + } +} + +Describe 'Test-CIPPAccess Public role' { + BeforeAll { + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecPublicThing' = @{ Role = 'Public'; Functionality = 'Entrypoint' } } + $script:CIPPBaseRoles = $script:SeedBaseRoles + } + + It 'returns $true immediately for a Public endpoint without touching identity' { + # No principal header at all; Public must short-circuit before any identity processing. + $Request = [pscustomobject]@{ Params = @{ CIPPEndpoint = 'ExecPublicThing' }; Headers = @{}; Query = @{}; Body = @{} } + Mock -CommandName Get-CippApiClient -MockWith { throw 'identity must not be processed for Public' } + Test-CIPPAccess -Request $Request | Should -BeTrue + Should -Invoke -CommandName Get-CippApiClient -Times 0 + } +} + +Describe 'Test-CIPPAccess APIClient branch' { + BeforeAll { + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } } + $script:CIPPBaseRoles = $script:SeedBaseRoles + } + + It 'unknown client (Get-CippApiClient returns null) gets the cipp-api custom role' { + # Unknown client -> CustomRoles = @('cipp-api'); no base role; no scope rules -> required-permission throw. + Mock -CommandName Get-CippApiClient -MockWith { $null } + Mock -CommandName Get-Tenants -MockWith { @() } + Mock -CommandName Get-CIPPRolePermissions -MockWith { throw 'no perms' } + # cipp-api is not admin/superadmin, has no permissions found -> required-permission throw. + { Test-CIPPAccess -Request (New-ApiClientRequest) } | + Should -Throw -ExpectedMessage '*does not have the required permission*' + } + + It 'known client with IPRange Any is allowed through the IP gate' { + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'App'; Role = @('somerole'); IPRange = @('Any') } + } + Mock -CommandName Get-Tenants -MockWith { @() } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'somerole'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('AllTenants'); BlockedTenants = @(); BlockedEndpoints = @() } + } + Test-CIPPAccess -Request (New-ApiClientRequest) | Should -BeTrue + } + + It 'known client with a restrictive IPRange and an out-of-range IP throws the IP-permission error' { + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'App'; Role = @('somerole'); IPRange = @('10.0.0.0/24') } + } + Mock -CommandName Test-IpInRange -MockWith { $false } + { Test-CIPPAccess -Request (New-ApiClientRequest -ForwardedFor '1.2.3.4') } | + Should -Throw -ExpectedMessage '*the API Client does not have the required permission*' + } + + It 'known client whose Role is a base role (admin) hits base include/exclude and falls through to $true' { + # admin base role: include '*' matches APIRole, exclude 'CIPP.SuperAdmin.*' does not. + # admin has no CustomRoles (admin is a default role) so base-role allow -> end-of-function $true. + Mock -CommandName Get-CippApiClient -MockWith { + [pscustomobject]@{ AppName = 'App'; Role = @('admin'); IPRange = @('Any') } + } + Test-CIPPAccess -Request (New-ApiClientRequest) | Should -BeTrue + } +} + +Describe 'Test-CIPPAccess User branch - identity and roles' { + BeforeAll { + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } } + $script:CIPPBaseRoles = $script:SeedBaseRoles + } + + It 'rebuilds identity from claims when userDetails is blank and selects preferred_username + oid' { + $Principal = [pscustomobject]@{ + userDetails = '' + claims = @( + [pscustomobject]@{ typ = 'preferred_username'; val = 'claimed@contoso.com' } + [pscustomobject]@{ typ = 'oid'; val = 'oid-from-claim' } + ) + } + # Rebuilt user gets userRoles @('authenticated','anonymous') -> Test-CIPPAccessUserRole is consulted. + Mock -CommandName Test-CIPPAccessUserRole -MockWith { + param($User) + $User.userDetails | Should -Be 'claimed@contoso.com' + $User.userId | Should -Be 'oid-from-claim' + $User.userRoles = @('editor') + $User + } + Test-CIPPAccess -Request (New-UserRequest -Principal $Principal) | Should -BeTrue + Should -Invoke -CommandName Test-CIPPAccessUserRole -Times 1 + } + + It 'falls back to x-ms-client-principal-name when no UPN-type claim is present' { + $Principal = [pscustomobject]@{ + userDetails = '' + claims = @([pscustomobject]@{ typ = 'oid'; val = 'oid-only' }) + } + Mock -CommandName Test-CIPPAccessUserRole -MockWith { + param($User) + # No upn/preferred_username/email claim -> UPN falls back to the header name. + $User.userDetails | Should -Be 'user@contoso.com' + $User.userRoles = @('editor') + $User + } + Test-CIPPAccess -Request (New-UserRequest -Principal $Principal) | Should -BeTrue + Should -Invoke -CommandName Test-CIPPAccessUserRole -Times 1 + } + + It 'resolves roles via Test-CIPPAccessUserRole ONLY when userRoles is exactly authenticated+anonymous' { + Mock -CommandName Test-CIPPAccessUserRole -MockWith { param($User) $User.userRoles = @('editor'); $User } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('authenticated', 'anonymous')) | Should -BeTrue + Should -Invoke -CommandName Test-CIPPAccessUserRole -Times 1 + } + + It 'does NOT call Test-CIPPAccessUserRole when a concrete role is already present' { + Mock -CommandName Test-CIPPAccessUserRole -MockWith { param($User) $User } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('editor')) | Should -BeTrue + Should -Invoke -CommandName Test-CIPPAccessUserRole -Times 0 + } + + It 'throws unable-to-resolve-roles when no roles remain after resolution' { + # authenticated+anonymous triggers resolution; resolver clears userRoles -> throw. + Mock -CommandName Test-CIPPAccessUserRole -MockWith { param($User) $User.userRoles = @(); $User } + { Test-CIPPAccess -Request (New-UserRequest -UserRoles @('authenticated', 'anonymous')) } | + Should -Throw -ExpectedMessage '*unable to resolve roles*' + } +} + +Describe 'Test-CIPPAccess User branch - IP enforcement' { + BeforeAll { + $script:CIPPFunctionPermissions = @{ + 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } + 'Invoke-me' = @{ Role = 'Public'; Functionality = 'Entrypoint' } + } + $script:CIPPBaseRoles = $script:SeedBaseRoles + } + + It 'throws when the IP is outside the role allowed range' { + Mock -CommandName Get-CIPPRoleIPRanges -MockWith { @('10.0.0.0/24') } + Mock -CommandName Test-IpInRange -MockWith { $false } + { Test-CIPPAccess -Request (New-UserRequest -UserRoles @('editor') -ForwardedFor '1.2.3.4') } | + Should -Throw -ExpectedMessage '*your IP address (1.2.3.4) is not in the allowed range*' + } + + It 'does NOT throw on out-of-range IP for the /me endpoint (the /me exemption)' { + # /me is exempt from the IP throw; it continues into the me-response build. + # Env controls keep the me build off storage (CIPPNG=true skips the SSO table read). + Mock -CommandName Get-CIPPRoleIPRanges -MockWith { @('10.0.0.0/24') } + Mock -CommandName Test-IpInRange -MockWith { $false } + Mock -CommandName Get-CippAllowedPermissions -MockWith { @() } + $script:SavedNG = $env:CIPPNG + $env:CIPPNG = 'true' + try { + $Result = Test-CIPPAccess -Request (New-UserRequest -CIPPEndpoint 'me' -UserRoles @('editor') -ForwardedFor '1.2.3.4') + $Result.StatusCode | Should -Be ([int][System.Net.HttpStatusCode]::OK) + } finally { + if ($null -eq $script:SavedNG) { Remove-Item Env:\CIPPNG -ErrorAction SilentlyContinue } else { $env:CIPPNG = $script:SavedNG } + } + } + + It 'allows when role IP ranges are Any' { + Mock -CommandName Get-CIPPRoleIPRanges -MockWith { @('Any') } + Mock -CommandName Test-IpInRange -MockWith { throw 'Test-IpInRange must not be called when range is Any' } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('editor')) | Should -BeTrue + Should -Invoke -CommandName Test-IpInRange -Times 0 + } +} + +Describe 'Test-CIPPAccess User branch - impersonation and AllTenants' { + BeforeAll { + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } } + $script:CIPPBaseRoles = $script:SeedBaseRoles + } + + It 'downstream evaluation uses the impersonated users roles' { + # Real user is superadmin; impersonation swaps to a restricted custom role with no permission -> throw. + Mock -CommandName Resolve-CippImpersonation -MockWith { + param($User, $Request) + $Impersonated = [pscustomobject]@{ identityProvider = 'aad'; userId = 'x'; userDetails = 'target@contoso.com'; userRoles = @('restrictedrole') } + [pscustomobject]@{ User = $Impersonated; Impersonating = 'target@contoso.com'; RealRoles = @('superadmin') } + } + Mock -CommandName Get-Tenants -MockWith { @() } + Mock -CommandName Get-CIPPRolePermissions -MockWith { throw 'no perms for restrictedrole' } + # If it had used the real superadmin role, admin/superadmin returns true early; instead restrictedrole + # has no permissions -> required-permission throw, proving the impersonated role drove the decision. + { Test-CIPPAccess -Request (New-UserRequest -UserRoles @('superadmin')) } | + Should -Throw -ExpectedMessage '*does not have the required permission*' + } + + It 'admin + -TenantList returns @(AllTenants)' { + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('admin')) -TenantList | Should -Be @('AllTenants') + } + + It 'superadmin + -TenantList returns @(AllTenants)' { + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('superadmin')) -TenantList | Should -Be @('AllTenants') + } +} + +Describe 'Test-CIPPAccess base role include/exclude' { + BeforeAll { + $script:CIPPBaseRoles = $script:SeedBaseRoles + } + + It 'allows when the base role include matches the APIRole' { + # readonly.include '*.Read' matches 'Identity.User.Read'; readonly has no custom roles -> $true. + $script:CIPPFunctionPermissions = @{ 'Invoke-ListUsers' = @{ Role = 'Identity.User.Read'; Functionality = 'Entrypoint' } } + Test-CIPPAccess -Request (New-UserRequest -CIPPEndpoint 'ListUsers' -UserRoles @('readonly')) | Should -BeTrue + } + + It 'throws the base-role error when an exclude matches even though an include also matched' { + # readonly.include '*.Read' matches 'CIPP.AppSettings.Read', but exclude 'CIPP.AppSettings.*' wins. + $script:CIPPFunctionPermissions = @{ 'Invoke-ListAppSettings' = @{ Role = 'CIPP.AppSettings.Read'; Functionality = 'Entrypoint' } } + { Test-CIPPAccess -Request (New-UserRequest -CIPPEndpoint 'ListAppSettings' -UserRoles @('readonly')) } | + Should -Throw -ExpectedMessage "*the 'readonly' base role does not have the required permission: CIPP.AppSettings.Read*" + } + + It 'throws required-permission when there is no base role and zero custom roles' { + # A role name that is neither a default nor a base role, but strip happens: user keeps the single + # unknown role as a custom role. To hit the zero-custom-role path we need a default-only role set. + # 'authenticated' alone (not the exact auth+anon pair) -> no resolution, no base role, no custom roles. + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } } + { Test-CIPPAccess -Request (New-UserRequest -UserRoles @('authenticated')) } | + Should -Throw -ExpectedMessage '*the user does not have the required permission*' + } +} + +Describe 'Test-CIPPAccess -TenantList / -GroupList scope rules' { + BeforeAll { + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } } + $script:CIPPBaseRoles = $script:SeedBaseRoles + } + + It 'returns @() when there are no scope rules at all' { + Mock -CommandName Get-CippAccessScopeRule -MockWith { throw 'no rule' } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('customrole')) -TenantList | Should -Be @() + } + + It 'Unrestricted rule returns @(AllTenants) for -TenantList' { + Mock -CommandName Get-CippAccessScopeRule -MockWith { [pscustomobject]@{ Unrestricted = $true } } + Mock -CommandName Get-Tenants -MockWith { throw 'Get-Tenants must not be called for Unrestricted' } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('customrole')) -TenantList | Should -Be @('AllTenants') + Should -Invoke -CommandName Get-Tenants -Times 0 + } + + It 'Unrestricted rule returns @(AllGroups) for -GroupList' { + Mock -CommandName Get-CippAccessScopeRule -MockWith { [pscustomobject]@{ Unrestricted = $true } } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('customrole')) -GroupList | Should -Be @('AllGroups') + } + + It 'AllowAllTenants (not unrestricted) calls Get-Tenants and excludes BlockedTenants' { + Mock -CommandName Get-CippAccessScopeRule -MockWith { + [pscustomobject]@{ Unrestricted = $false; AllowAllTenants = $true; BlockedTenants = @('tenant-b'); AllowedTenants = @() } + } + Mock -CommandName Get-Tenants -MockWith { + @([pscustomobject]@{ customerId = 'tenant-a' }, [pscustomobject]@{ customerId = 'tenant-b' }) + } + $Result = Test-CIPPAccess -Request (New-UserRequest -UserRoles @('customrole')) -TenantList + $Result | Should -Be @('tenant-a') + Should -Invoke -CommandName Get-Tenants -Times 1 + } + + It 'explicit AllowedTenants does NOT call Get-Tenants, excludes blocked, sorts unique' { + Mock -CommandName Get-CippAccessScopeRule -MockWith { + [pscustomobject]@{ Unrestricted = $false; AllowAllTenants = $false; AllowedTenants = @('tenant-c', 'tenant-a', 'tenant-a'); BlockedTenants = @('tenant-b') } + } + Mock -CommandName Get-Tenants -MockWith { throw 'Get-Tenants must not be called for explicit AllowedTenants' } + $Result = Test-CIPPAccess -Request (New-UserRequest -UserRoles @('customrole')) -TenantList + $Result | Should -Be @('tenant-a', 'tenant-c') + Should -Invoke -CommandName Get-Tenants -Times 0 + } +} + +Describe 'Test-CIPPAccess per-endpoint custom-role evaluation' { + BeforeAll { + $script:CIPPBaseRoles = $script:SeedBaseRoles + $script:Tenant1 = [pscustomobject]@{ customerId = 'tenant-1'; defaultDomainName = 't1.example.com' } + $script:Tenant2 = [pscustomobject]@{ customerId = 'tenant-2'; defaultDomainName = 't2.example.com' } + } + + It 'sticky APIAllowed: role A grants permission but fails tenant scope, role B passes scope -> $true' { + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } } + Mock -CommandName Get-Tenants -MockWith { @($script:Tenant1, $script:Tenant2) } + Mock -CommandName Expand-CIPPTenantGroups -MockWith { @() } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + param($Role) + switch ($Role) { + 'roleA' { [pscustomobject]@{ Role = 'roleA'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('tenant-1'); BlockedTenants = @(); BlockedEndpoints = @() } } + 'roleB' { [pscustomobject]@{ Role = 'roleB'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('tenant-2'); BlockedTenants = @(); BlockedEndpoints = @() } } + default { throw "unexpected $Role" } + } + } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('roleA', 'roleB') -Query @{ tenantFilter = 'tenant-2' }) | Should -BeTrue + } + + It 'throws required-permission naming the APIRole when no role grants the permission' { + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } } + Mock -CommandName Get-Tenants -MockWith { @($script:Tenant1) } + Mock -CommandName Expand-CIPPTenantGroups -MockWith { @() } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'roleX'; Permissions = @('Identity.User.Read'); AllowedTenants = @('AllTenants'); BlockedTenants = @(); BlockedEndpoints = @() } + } + { Test-CIPPAccess -Request (New-UserRequest -UserRoles @('roleX') -Query @{ tenantFilter = 'tenant-1' }) } | + Should -Throw -ExpectedMessage '*required permission: Identity.User.ReadWrite*' + } + + It 'permission granted, tenant not allowed, Functionality AnyTenant -> $true' { + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'AnyTenant' } } + Mock -CommandName Get-Tenants -MockWith { @($script:Tenant1, $script:Tenant2) } + Mock -CommandName Expand-CIPPTenantGroups -MockWith { @() } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'roleT1'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('tenant-1'); BlockedTenants = @(); BlockedEndpoints = @() } + } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('roleT1') -Query @{ tenantFilter = 'tenant-2' }) | Should -BeTrue + } + + It 'UNRESOLVED tenantFilter, Functionality AnyTenant -> $true' { + # Constraint: the unresolved-filter deny must never reach AnyTenant endpoints — + # the AnyTenant exemption is evaluated after the tenant-scope result, so a + # filter that maps to no known tenant still passes here (and only here). + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'AnyTenant' } } + Mock -CommandName Get-Tenants -MockWith { @($script:Tenant1, $script:Tenant2) } + Mock -CommandName Expand-CIPPTenantGroups -MockWith { @() } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'roleT1'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('tenant-1'); BlockedTenants = @(); BlockedEndpoints = @() } + } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('roleT1') -Query @{ tenantFilter = 'ffffffff-ffff-ffff-ffff-ffffffffffff' }) | Should -BeTrue + } + + It 'permission granted, tenant not allowed, no AnyTenant -> tenant error' { + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } } + Mock -CommandName Get-Tenants -MockWith { @($script:Tenant1, $script:Tenant2) } + Mock -CommandName Expand-CIPPTenantGroups -MockWith { @() } + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'roleT1'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('tenant-1'); BlockedTenants = @(); BlockedEndpoints = @() } + } + { Test-CIPPAccess -Request (New-UserRequest -UserRoles @('roleT1') -Query @{ tenantFilter = 'tenant-2' }) } | + Should -Throw -ExpectedMessage '*Access to this tenant is not allowed*' + } + + It 'Get-CIPPRolePermissions throws for every role: with -TenantList -> @()' { + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } } + Mock -CommandName Get-CippAccessScopeRule -MockWith { throw 'no rule' } + Mock -CommandName Get-CIPPRolePermissions -MockWith { throw 'no perms' } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('customrole')) -TenantList | Should -Be @() + } + + It 'Get-CIPPRolePermissions throws for every role: without -TenantList -> required-permission throw' { + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } } + Mock -CommandName Get-Tenants -MockWith { @($script:Tenant1) } + Mock -CommandName Get-CIPPRolePermissions -MockWith { throw 'no perms' } + { Test-CIPPAccess -Request (New-UserRequest -UserRoles @('customrole')) } | + Should -Throw -ExpectedMessage '*does not have the required permission*' + } +} + +Describe 'Test-CIPPAccess tenant-filter permutations' { + BeforeAll { + $script:CIPPFunctionPermissions = @{ + 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } + 'Invoke-ListUsers' = @{ Role = 'Identity.User.Read'; Functionality = 'Entrypoint' } + } + $script:CIPPBaseRoles = $script:SeedBaseRoles + $script:Tenant1 = [pscustomobject]@{ customerId = 'tenant-1'; defaultDomainName = 't1.example.com' } + $script:Tenant2 = [pscustomobject]@{ customerId = 'tenant-2'; defaultDomainName = 't2.example.com' } + } + BeforeEach { + Mock -CommandName Get-Tenants -MockWith { @($script:Tenant1, $script:Tenant2) } + Mock -CommandName Expand-CIPPTenantGroups -MockWith { @() } + } + + Context 'unmapped tenant filter' { + It 'DENIES a tenantFilter GUID that maps to no known tenant (unresolved filters fail closed on the allow path)' { + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'roleT1'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('tenant-1'); BlockedTenants = @(); BlockedEndpoints = @() } + } + { Test-CIPPAccess -Request (New-UserRequest -UserRoles @('roleT1') -Query @{ tenantFilter = 'ffffffff-ffff-ffff-ffff-ffffffffffff' }) } | + Should -Throw -ExpectedMessage '*Access to this tenant is not allowed*' + } + + It 'still ALLOWS an absent tenantFilter for a tenant-restricted role (endpoint is not tenant-scoped)' { + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'roleT1'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('tenant-1'); BlockedTenants = @(); BlockedEndpoints = @() } + } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('roleT1')) | Should -BeTrue + } + } + + Context 'AllTenants filter vs Read/Write APIRole' { + It 'AllTenants + APIRole ending in Read -> allowed even for a tenant-restricted role' { + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'roleT1'; Permissions = @('Identity.User.Read'); AllowedTenants = @('tenant-1'); BlockedTenants = @(); BlockedEndpoints = @() } + } + Test-CIPPAccess -Request (New-UserRequest -CIPPEndpoint 'ListUsers' -UserRoles @('roleT1') -Query @{ tenantFilter = 'AllTenants' }) | + Should -BeTrue + } + + It 'AllTenants + APIRole ending in Write -> tenant denied for a tenant-restricted role' { + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'roleT1'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('tenant-1'); BlockedTenants = @(); BlockedEndpoints = @() } + } + { Test-CIPPAccess -Request (New-UserRequest -UserRoles @('roleT1') -Query @{ tenantFilter = 'AllTenants' }) } | + Should -Throw -ExpectedMessage '*Access to this tenant is not allowed*' + } + } + + Context 'filter precedence' { + It 'Body.tenantFilter.value (object form) resolves the target when Query has no filter' { + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'roleT1'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('tenant-1'); BlockedTenants = @(); BlockedEndpoints = @() } + } + $Body = @{ tenantFilter = [pscustomobject]@{ type = 'Tenant'; value = 'tenant-2'; label = 'T2' } } + # Body value tenant-2 is outside the role's scope; if the object form did not resolve, + # the unmapped-filter quirk would allow this instead. + { Test-CIPPAccess -Request (New-UserRequest -UserRoles @('roleT1') -Body $Body) } | + Should -Throw -ExpectedMessage '*Access to this tenant is not allowed*' + } + + It 'Query.tenantFilter wins over Body.tenantFilter when both are present' { + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'roleT1'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('tenant-1'); BlockedTenants = @(); BlockedEndpoints = @() } + } + $Body = @{ tenantFilter = [pscustomobject]@{ type = 'Tenant'; value = 'tenant-2'; label = 'T2' } } + # Query names the allowed tenant, Body the denied one; allow proves Query precedence. + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('roleT1') -Query @{ tenantFilter = 'tenant-1' } -Body $Body) | + Should -BeTrue + } + } +} + +Describe 'Test-CIPPAccess base and custom role interplay' { + BeforeAll { + $script:CIPPFunctionPermissions = @{ + 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } + 'Invoke-ListUsers' = @{ Role = 'Identity.User.Read'; Functionality = 'Entrypoint' } + 'Invoke-ListSharepointSites' = @{ Role = 'Sharepoint.Site.Read'; Functionality = 'Entrypoint' } + } + $script:CIPPBaseRoles = $script:SeedBaseRoles + $script:Tenant1 = [pscustomobject]@{ customerId = 'tenant-1'; defaultDomainName = 't1.example.com' } + $script:Tenant2 = [pscustomobject]@{ customerId = 'tenant-2'; defaultDomainName = 't2.example.com' } + } + BeforeEach { + Mock -CommandName Get-Tenants -MockWith { @($script:Tenant1, $script:Tenant2) } + Mock -CommandName Expand-CIPPTenantGroups -MockWith { @() } + } + + Context 'custom roles narrow base roles' { + It 'editor + custom role: endpoint the base allows but the custom role does not grant -> required-permission throw' { + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'customrole'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('AllTenants'); BlockedTenants = @(); BlockedEndpoints = @() } + } + { Test-CIPPAccess -Request (New-UserRequest -CIPPEndpoint 'ListSharepointSites' -UserRoles @('editor', 'customrole') -Query @{ tenantFilter = 'tenant-1' }) } | + Should -Throw -ExpectedMessage '*required permission: Sharepoint.Site.Read*' + } + + It 'editor + custom role: granted endpoint but tenant outside the custom scope -> tenant error' { + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'customrole'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('tenant-1'); BlockedTenants = @(); BlockedEndpoints = @() } + } + { Test-CIPPAccess -Request (New-UserRequest -UserRoles @('editor', 'customrole') -Query @{ tenantFilter = 'tenant-2' }) } | + Should -Throw -ExpectedMessage '*Access to this tenant is not allowed*' + } + + It 'control: editor alone has NO tenant restriction and never consults custom-role permissions' { + Mock -CommandName Get-CIPPRolePermissions -MockWith { throw 'must not be consulted for a base-only user' } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('editor') -Query @{ tenantFilter = 'tenant-2' }) | Should -BeTrue + Should -Invoke -CommandName Get-CIPPRolePermissions -Times 0 + } + } + + Context 'permission regex semantics' { + It 'a role granting only Identity.User.ReadWrite satisfies APIRole Identity.User.Read (substring regex match; load-bearing)' { + # $Perm -match $APIRole: 'Identity.User.ReadWrite' contains 'Identity.User.Read', so ReadWrite implies Read. + Mock -CommandName Get-CIPPRolePermissions -MockWith { + [pscustomobject]@{ Role = 'customrole'; Permissions = @('Identity.User.ReadWrite'); AllowedTenants = @('AllTenants'); BlockedTenants = @(); BlockedEndpoints = @() } + } + Test-CIPPAccess -Request (New-UserRequest -CIPPEndpoint 'ListUsers' -UserRoles @('customrole') -Query @{ tenantFilter = 'tenant-1' }) | + Should -BeTrue + } + } + + Context 'role collapse shortcuts' { + It 'superadmin who also has custom roles returns $true via the shortcut; custom-role scoping never evaluated' { + Mock -CommandName Get-CIPPRolePermissions -MockWith { throw 'must not be consulted for superadmin' } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('superadmin', 'customrole') -Query @{ tenantFilter = 'tenant-1' }) | + Should -BeTrue + Should -Invoke -CommandName Get-CIPPRolePermissions -Times 0 + } + } + + Context 'unknown endpoint (APIRole resolves to $null)' { + # Not in $script:CIPPFunctionPermissions and Get-Help fails -> $APIRole stays $null. + It 'admin base role allows an unknown endpoint ($null -like ''*'' is true)' { + Test-CIPPAccess -Request (New-UserRequest -CIPPEndpoint 'NoSuchEndpoint' -UserRoles @('admin')) 3>$null | + Should -BeTrue + } + + It 'readonly base role denies an unknown endpoint ($null -like ''*.Read'' is false)' { + { Test-CIPPAccess -Request (New-UserRequest -CIPPEndpoint 'NoSuchEndpoint' -UserRoles @('readonly')) 3>$null } | + Should -Throw -ExpectedMessage '*base role does not have the required permission*' + } + } +} + +Describe 'Test-CIPPAccess scope-rule permutations' { + BeforeAll { + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } } + $script:CIPPBaseRoles = $script:SeedBaseRoles + } + + It 'mixed rules: Unrestricted + explicit AllowedTenants -> union contains AllTenants AND the explicit IDs' { + Mock -CommandName Get-CippAccessScopeRule -MockWith { + param($Role) + switch ($Role) { + 'openrole' { [pscustomobject]@{ Unrestricted = $true } } + 'scopedrole' { [pscustomobject]@{ Unrestricted = $false; AllowAllTenants = $false; AllowedTenants = @('tenant-y', 'tenant-x'); BlockedTenants = @() } } + default { throw "unexpected $Role" } + } + } + Mock -CommandName Get-Tenants -MockWith { throw 'Get-Tenants must not be called (no AllowAllTenants rule)' } + $Result = Test-CIPPAccess -Request (New-UserRequest -UserRoles @('openrole', 'scopedrole')) -TenantList + $Result | Should -Be @('AllTenants', 'tenant-x', 'tenant-y') + Should -Invoke -CommandName Get-Tenants -Times 0 + } + + It '-GroupList with a non-unrestricted rule returns its AllowedGroups sorted unique' { + Mock -CommandName Get-CippAccessScopeRule -MockWith { + [pscustomobject]@{ Unrestricted = $false; AllowedGroups = @('group-b', 'group-a', 'group-a') } + } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('customrole')) -GroupList | Should -Be @('group-a', 'group-b') + } +} + +Describe 'Test-CIPPAccess IP quirks' { + BeforeAll { + $script:CIPPFunctionPermissions = @{ 'Invoke-ExecResetPass' = @{ Role = 'Identity.User.ReadWrite'; Functionality = 'Entrypoint' } } + $script:CIPPBaseRoles = $script:SeedBaseRoles + } + + It 'restrictive role IP range with NO x-forwarded-for header -> allowed (empty IP fail-open quirk)' { + # No header -> parsed IP is '' -> the if($IPAddress) guard skips matching and sets IPAllowed = $true. + Mock -CommandName Get-CIPPRoleIPRanges -MockWith { @('10.0.0.0/24') } + Mock -CommandName Test-IpInRange -MockWith { throw 'must not be called with an empty IP' } + Test-CIPPAccess -Request (New-UserRequest -UserRoles @('editor') -OmitForwardedFor) | Should -BeTrue + Should -Invoke -CommandName Test-IpInRange -Times 0 + } +} diff --git a/Tests/Private/Test-CIPPAccess.TenantGroupAuth.Tests.ps1 b/Tests/Private/Test-CIPPAccess.TenantGroupAuth.Tests.ps1 index 4b817dee8e107..631312038942a 100644 --- a/Tests/Private/Test-CIPPAccess.TenantGroupAuth.Tests.ps1 +++ b/Tests/Private/Test-CIPPAccess.TenantGroupAuth.Tests.ps1 @@ -24,6 +24,9 @@ BeforeAll { . $ScopeHelperPath . $FunctionPath + $PrivateAuthDir = Join-Path $RepoRoot 'Modules/CIPPCore/Private/Authentication' + . (Join-Path $PrivateAuthDir 'Get-CippRequestIPAddress.ps1') + . (Join-Path $PrivateAuthDir 'Find-CippBaseRole.ps1') # Bypass the config-file reads by pre-seeding the runspace caches the function guards on. $script:CIPPFunctionPermissions = @{ diff --git a/Tests/Private/Test-CIPPStalledRun.Tests.ps1 b/Tests/Private/Test-CIPPStalledRun.Tests.ps1 new file mode 100644 index 0000000000000..c7d7359c732c9 --- /dev/null +++ b/Tests/Private/Test-CIPPStalledRun.Tests.ps1 @@ -0,0 +1,52 @@ +# Pester tests for Test-CIPPStalledRun +# The run summary carries no status field, so the stall predicate is the only thing standing +# between a wedged orchestrator run and a silent PASS. These tests pin each clause. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Functions/Test-CIPPStalledRun.ps1') + + $script:Now = [DateTime]::Parse('2026-09-10T12:00:00Z').ToUniversalTime() + function New-Run { + param($Running, $Queued, $StartedUtc, $CompletedUtc) + [PSCustomObject]@{ + Name = 'StandardsOrchestrator' + Running = $Running + Queued = $Queued + StartedUtc = $StartedUtc + CompletedUtc = $CompletedUtc + } + } +} + +Describe 'Test-CIPPStalledRun' { + It 'flags an active run with queued work, nothing running and a start over 2h old' { + $Run = New-Run -Running 0 -Queued 12 -StartedUtc $script:Now.AddHours(-3) -CompletedUtc $null + Test-CIPPStalledRun -Run $Run -Now $script:Now | Should -BeTrue + } + + It 'does not flag a run that is still doing work' { + $Run = New-Run -Running 2 -Queued 12 -StartedUtc $script:Now.AddHours(-3) -CompletedUtc $null + Test-CIPPStalledRun -Run $Run -Now $script:Now | Should -BeFalse + } + + It 'does not flag a run with nothing left queued' { + $Run = New-Run -Running 0 -Queued 0 -StartedUtc $script:Now.AddHours(-3) -CompletedUtc $null + Test-CIPPStalledRun -Run $Run -Now $script:Now | Should -BeFalse + } + + It 'does not flag a completed run' { + $Run = New-Run -Running 0 -Queued 12 -StartedUtc $script:Now.AddHours(-3) -CompletedUtc $script:Now.AddHours(-1) + Test-CIPPStalledRun -Run $Run -Now $script:Now | Should -BeFalse + } + + It 'does not flag a run that started an hour ago' { + $Run = New-Run -Running 0 -Queued 12 -StartedUtc $script:Now.AddHours(-1) -CompletedUtc $null + Test-CIPPStalledRun -Run $Run -Now $script:Now | Should -BeFalse + } + + It 'does not flag a run that has not started' { + $Run = New-Run -Running 0 -Queued 12 -StartedUtc $null -CompletedUtc $null + Test-CIPPStalledRun -Run $Run -Now $script:Now | Should -BeFalse + } +} diff --git a/Tests/Private/Update-CIPPSSOPreconsent.Tests.ps1 b/Tests/Private/Update-CIPPSSOPreconsent.Tests.ps1 index 0ac0f4fe9c5c4..f4f41afe9cdc7 100644 --- a/Tests/Private/Update-CIPPSSOPreconsent.Tests.ps1 +++ b/Tests/Private/Update-CIPPSSOPreconsent.Tests.ps1 @@ -105,7 +105,7 @@ Describe 'Update-CIPPSSOPreconsent' { ($body | ConvertFrom-Json).consentType -eq 'AllPrincipals' -and ($body | ConvertFrom-Json).clientId -eq $script:SsoSpId -and ($body | ConvertFrom-Json).resourceId -eq $script:GraphSpId -and - ($body | ConvertFrom-Json).scope -eq 'openid profile email' + ($body | ConvertFrom-Json).scope -eq 'openid profile email offline_access' } } @@ -145,7 +145,7 @@ Describe 'Update-CIPPSSOPreconsent' { id = 'grant-1' resourceId = $script:GraphSpId consentType = 'AllPrincipals' - scope = 'email openid profile User.Read' + scope = 'email offline_access openid profile User.Read' }) } @@ -172,7 +172,7 @@ Describe 'Update-CIPPSSOPreconsent' { Should -Invoke -CommandName New-GraphPOSTRequest -Times 1 -Exactly -ParameterFilter { $type -eq 'PATCH' -and $uri -eq 'https://graph.microsoft.com/v1.0/oauth2PermissionGrants/grant-1' -and - ($body | ConvertFrom-Json).scope -eq 'email openid profile User.Read' + ($body | ConvertFrom-Json).scope -eq 'email offline_access openid profile User.Read' } } diff --git a/Tests/Private/Update-CIPPSSORedirectUri.Tests.ps1 b/Tests/Private/Update-CIPPSSORedirectUri.Tests.ps1 new file mode 100644 index 0000000000000..97dee45388e9c --- /dev/null +++ b/Tests/Private/Update-CIPPSSORedirectUri.Tests.ps1 @@ -0,0 +1,135 @@ +# Pester tests for Update-CIPPSSORedirectUri +# Focused on the delegated-scope backfill added alongside offline_access: an app registration +# created before a scope joined the default set must have it added at warmup, additively, without +# dropping anything already declared - while an app that already has every scope costs no write. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Authentication/Update-CIPPSSORedirectUri.ps1' + + # Minimal stubs so Mock has commands to replace during tests + function Get-CIPPTable { param($TableName) } + function Get-CIPPAzDataTableEntity { param($Context, $Filter) } + function Get-CippKeyVaultName { } + function Get-CippKeyVaultSecret { param($VaultName, $Name, [switch]$AsPlainText) } + function Get-CIPPSiteHostname { param([switch]$AsRedirectUri, [switch]$IncludeStatus, [switch]$NoFallback) } + function New-GraphGetRequest { param($uri, $NoAuthCheck, $AsApp) } + function New-GraphPOSTRequest { param($uri, $body, $type, $NoAuthCheck, $AsApp) } + function Write-LogMessage { param($API, $message, $LogData, $sev) } + function Get-CippException { param($Exception) } + + . $FunctionPath + + $script:GraphResourceId = '00000003-0000-0000-c000-000000000000' + $script:OpenId = '37f7f235-527c-4136-accd-4a02d197296e' + $script:ProfileScope = '14dad69e-099b-42c9-810b-d002981feec1' + $script:Email = '64a6cdd6-aab1-4aaf-94b8-3cc8405e90d0' + $script:OfflineAccess = '7427e0e9-2fba-42fe-b0c0-848c9e6a8182' +} + +Describe 'Update-CIPPSSORedirectUri scope backfill' { + BeforeEach { + $script:SsoAppId = '33333333-3333-3333-3333-333333333333' + $script:AppObjectId = 'app-object-id' + $script:Callback = 'https://cipp.example.com/.auth/login/aad/callback' + + $script:OriginalStorage = $env:AzureWebJobsStorage + $script:OriginalNonLocal = $env:NonLocalHostAzurite + $script:OriginalHostname = $env:WEBSITE_HOSTNAME + + # Hosted (Key Vault) path, single tenant, URIs already correct so only scopes vary. + $env:AzureWebJobsStorage = 'DefaultEndpointsProtocol=https;AccountName=stub' + $env:NonLocalHostAzurite = $null + $env:WEBSITE_HOSTNAME = 'cipp.example.com' + + # Graph resourceAccess declared on the app - each test overrides this before calling. + $script:AppScopeIds = @($script:OpenId, $script:ProfileScope, $script:Email) + # Any extra (non-Graph) requiredResourceAccess entries the app carries. + $script:ExtraResources = @() + + Mock -CommandName Get-CippKeyVaultName -MockWith { 'stub-vault' } + Mock -CommandName Get-CippKeyVaultSecret -MockWith { + if ($Name -eq 'SSOAppId') { return $script:SsoAppId } + if ($Name -eq 'SSOMultiTenant') { return 'False' } + return $null + } + Mock -CommandName Get-CIPPSiteHostname -MockWith { + [PSCustomObject]@{ RedirectUris = @($script:Callback); Discovered = $true; Error = $null } + } + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Get-CippException -MockWith { @{ NormalizedError = 'stub' } } + Mock -CommandName New-GraphPOSTRequest -MockWith { } + + Mock -CommandName New-GraphGetRequest -MockWith { + [PSCustomObject]@{ + id = $script:AppObjectId + signInAudience = 'AzureADMyOrg' + web = [PSCustomObject]@{ redirectUris = @($script:Callback) } + requiredResourceAccess = @( + @($script:ExtraResources) + [PSCustomObject]@{ + resourceAppId = $script:GraphResourceId + resourceAccess = @($script:AppScopeIds | ForEach-Object { [PSCustomObject]@{ id = $_; type = 'Scope' } }) + } + ) + } + } + } + + AfterEach { + $env:AzureWebJobsStorage = $script:OriginalStorage + $env:NonLocalHostAzurite = $script:OriginalNonLocal + $env:WEBSITE_HOSTNAME = $script:OriginalHostname + } + + It 'backfills offline_access when the app registration is missing it' { + # App has only the original three scopes + $script:AppScopeIds = @($script:OpenId, $script:ProfileScope, $script:Email) + + Update-CIPPSSORedirectUri + + Should -Invoke -CommandName New-GraphPOSTRequest -Times 1 -Exactly -ParameterFilter { + $type -eq 'PATCH' -and + $uri -eq "https://graph.microsoft.com/v1.0/applications/$script:AppObjectId" -and + (($body | ConvertFrom-Json).requiredResourceAccess | Where-Object { $_.resourceAppId -eq $script:GraphResourceId }).resourceAccess.id -contains $script:OfflineAccess + } + } + + It 'keeps the scopes already declared when backfilling' { + $script:AppScopeIds = @($script:OpenId, $script:ProfileScope, $script:Email) + + Update-CIPPSSORedirectUri + + Should -Invoke -CommandName New-GraphPOSTRequest -Times 1 -Exactly -ParameterFilter { + $GraphAccess = (($body | ConvertFrom-Json).requiredResourceAccess | Where-Object { $_.resourceAppId -eq $script:GraphResourceId }).resourceAccess.id + @($script:OpenId, $script:ProfileScope, $script:Email, $script:OfflineAccess) | ForEach-Object { $_ -in $GraphAccess } | Should -Not -Contain $false + $true + } + } + + It 'writes nothing when every required scope is already declared' { + $script:AppScopeIds = @($script:OpenId, $script:ProfileScope, $script:Email, $script:OfflineAccess) + + Update-CIPPSSORedirectUri + + Should -Invoke -CommandName New-GraphPOSTRequest -Times 0 -Exactly + } + + It 'preserves a non-Graph resource entry while backfilling the Graph scopes' { + $script:AppScopeIds = @($script:OpenId, $script:ProfileScope, $script:Email) + $script:ExtraResources = @( + [PSCustomObject]@{ + resourceAppId = '00000002-0000-0000-c000-000000000000' + resourceAccess = @([PSCustomObject]@{ id = 'some-other-scope-id'; type = 'Scope' }) + } + ) + + Update-CIPPSSORedirectUri + + Should -Invoke -CommandName New-GraphPOSTRequest -Times 1 -Exactly -ParameterFilter { + $Resources = ($body | ConvertFrom-Json).requiredResourceAccess + ($Resources | Where-Object { $_.resourceAppId -eq '00000002-0000-0000-c000-000000000000' }) -and + (($Resources | Where-Object { $_.resourceAppId -eq $script:GraphResourceId }).resourceAccess.id -contains $script:OfflineAccess) + } + } +} diff --git a/Tests/Standards/Invoke-CIPPStandardDisableGuests.Tests.ps1 b/Tests/Standards/Invoke-CIPPStandardDisableGuests.Tests.ps1 index 06b4ff7946737..a9370e70bf926 100644 --- a/Tests/Standards/Invoke-CIPPStandardDisableGuests.Tests.ps1 +++ b/Tests/Standards/Invoke-CIPPStandardDisableGuests.Tests.ps1 @@ -6,7 +6,9 @@ # sign-in alone, which stays old while a blocked or disabled guest keeps trying; # - guests with no sign-in on record are skipped unless IncludeNeverSignedIn is on, and a # template that predates the switch behaves as off; -# - a guest an admin re-enabled in the last 7 days is left alone. +# - a guest an admin re-enabled in the last 7 days is left alone; +# - deleteGraceDays missing/0 never issues DELETE; grace > 0 deletes only already-disabled +# guests past days+grace, never guests disabled in the same pass. BeforeAll { $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) @@ -48,6 +50,7 @@ BeforeAll { [string]$Id, [string]$Upn, [string]$State = 'Accepted', + [bool]$AccountEnabled = $true, [int]$CreatedDaysAgo = 400, [Nullable[int]]$InteractiveDaysAgo, [Nullable[int]]$NonInteractiveDaysAgo, @@ -59,7 +62,7 @@ BeforeAll { userPrincipalName = $Upn mail = $Upn userType = 'Guest' - accountEnabled = $true + accountEnabled = $AccountEnabled createdDateTime = $script:Now.AddDays(-$CreatedDaysAgo).ToString('o') externalUserState = $State } @@ -80,7 +83,10 @@ Describe 'Invoke-CIPPStandardDisableGuests' { $script:alerts = [System.Collections.Generic.List[object]]::new() $script:compare = [System.Collections.Generic.List[object]]::new() $script:disabled = [System.Collections.Generic.List[string]]::new() - $script:guests = @() + $script:deleted = [System.Collections.Generic.List[string]]::new() + $script:bulkMethods = [System.Collections.Generic.List[string]]::new() + $script:enabledGuests = @() + $script:disabledGuests = @() $script:audits = @() Mock -CommandName Test-CIPPStandardLicense -MockWith { $true } @@ -100,12 +106,19 @@ Describe 'Invoke-CIPPStandardDisableGuests' { Mock -CommandName New-GraphGetRequest -MockWith { param($uri, $tenantid, $scope) if ($uri -like '*directoryAudits*') { return $script:audits } - return $script:guests + if ($uri -like '*accountEnabled eq false*') { return $script:disabledGuests } + return $script:enabledGuests } Mock -CommandName New-GraphBulkRequest -MockWith { param($tenantid, $Requests) @(foreach ($Request in $Requests) { - $script:disabled.Add(($Request.url -replace '^users/', '')) + $script:bulkMethods.Add([string]$Request.method) + $Id = ($Request.url -replace '^users/', '') + if ($Request.method -eq 'DELETE') { + $script:deleted.Add($Id) + } else { + $script:disabled.Add($Id) + } [pscustomobject]@{ id = $Request.id; status = 204; body = $null } }) } @@ -115,7 +128,7 @@ Describe 'Invoke-CIPPStandardDisableGuests' { It 'keeps a guest whose last successful sign-in is old but who attempted a sign-in inside the window' { # The reported shape: a successful sign-in 300 days back, an interactive attempt 154 days # back and a non-interactive attempt 3 days back, against a 180-day threshold. - $script:guests = @(New-Guest -Id 'g1' -Upn 'bas_example.com#EXT#@contoso.onmicrosoft.com' -SuccessfulDaysAgo 300 -InteractiveDaysAgo 154 -NonInteractiveDaysAgo 3) + $script:enabledGuests = @(New-Guest -Id 'g1' -Upn 'bas_example.com#EXT#@contoso.onmicrosoft.com' -SuccessfulDaysAgo 300 -InteractiveDaysAgo 154 -NonInteractiveDaysAgo 3) Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 180 } @@ -125,7 +138,7 @@ Describe 'Invoke-CIPPStandardDisableGuests' { } It 'disables a guest whose newest attempt of any kind is outside the window, and logs that date' { - $script:guests = @( + $script:enabledGuests = @( New-Guest -Id 'stale' -Upn 'stale@example.com' -SuccessfulDaysAgo 250 -InteractiveDaysAgo 200 -NonInteractiveDaysAgo 190 New-Guest -Id 'active' -Upn 'active@example.com' -SuccessfulDaysAgo 250 -InteractiveDaysAgo 200 -NonInteractiveDaysAgo 100 ) @@ -141,7 +154,7 @@ Describe 'Invoke-CIPPStandardDisableGuests' { } It 'counts a lastSuccessfulSignInDateTime that runs ahead of both attempt timestamps as activity' { - $script:guests = @(New-Guest -Id 'ahead' -Upn 'ahead@example.com' -InteractiveDaysAgo 200 -SuccessfulDaysAgo 10) + $script:enabledGuests = @(New-Guest -Id 'ahead' -Upn 'ahead@example.com' -InteractiveDaysAgo 200 -SuccessfulDaysAgo 10) Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 180 } @@ -151,7 +164,7 @@ Describe 'Invoke-CIPPStandardDisableGuests' { Context 'guests with no sign-in on record' { It 'are skipped when the template predates the switch or has it off' { - $script:guests = @(New-Guest -Id 'pending' -Upn 'pending@example.com' -State 'PendingAcceptance') + $script:enabledGuests = @(New-Guest -Id 'pending' -Upn 'pending@example.com' -State 'PendingAcceptance') Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 90 } Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 90; IncludeNeverSignedIn = $false } @@ -161,7 +174,7 @@ Describe 'Invoke-CIPPStandardDisableGuests' { } It 'are disabled only when IncludeNeverSignedIn is on, with the invitation age as the reason' { - $script:guests = @( + $script:enabledGuests = @( New-Guest -Id 'pending' -Upn 'pending@example.com' -State 'PendingAcceptance' New-Guest -Id 'fresh' -Upn 'fresh@example.com' -InteractiveDaysAgo 5 ) @@ -175,7 +188,7 @@ Describe 'Invoke-CIPPStandardDisableGuests' { Context 'recently re-enabled guests' { It 'are left alone for 7 days after an admin re-enables them' { - $script:guests = @(New-Guest -Id 'stale' -Upn 'stale@example.com' -InteractiveDaysAgo 200) + $script:enabledGuests = @(New-Guest -Id 'stale' -Upn 'stale@example.com' -InteractiveDaysAgo 200) $script:audits = @([pscustomobject]@{ targetResources = @([pscustomobject]@{ id = 'stale' }) }) Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 90 } @@ -185,9 +198,78 @@ Describe 'Invoke-CIPPStandardDisableGuests' { } } + Context 'delete grace' { + It 'never deletes when deleteGraceDays is missing or 0' { + $script:enabledGuests = @(New-Guest -Id 'stale' -Upn 'stale@example.com' -InteractiveDaysAgo 200) + $script:disabledGuests = @(New-Guest -Id 'old' -Upn 'old@example.com' -AccountEnabled $false -InteractiveDaysAgo 400) + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 90 } + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 90; deleteGraceDays = 0 } + + @($script:disabled) | Should -Be @('stale', 'stale') + @($script:deleted) | Should -BeNullOrEmpty + @($script:bulkMethods) | Should -Not -Contain 'DELETE' + } + + It 'deletes only already-disabled guests past days plus grace, not guests disabled in the same pass' { + $script:enabledGuests = @(New-Guest -Id 'toDisable' -Upn 'todisable@example.com' -InteractiveDaysAgo 200) + $script:disabledGuests = @( + New-Guest -Id 'toDelete' -Upn 'todelete@example.com' -AccountEnabled $false -InteractiveDaysAgo 200 + New-Guest -Id 'tooRecent' -Upn 'toorecent@example.com' -AccountEnabled $false -InteractiveDaysAgo 100 + ) + + # days=90, grace=30 => delete age 120. toDelete (200) qualifies; tooRecent (100) does not; + # toDisable is enabled so it is PATCHed this run and must not be DELETE'd in the same pass. + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 90; deleteGraceDays = 30 } + + @($script:disabled) | Should -Be @('toDisable') + @($script:deleted) | Should -Be @('toDelete') + @($script:bulkMethods) | Should -Contain 'PATCH' + @($script:bulkMethods) | Should -Contain 'DELETE' + @($script:logs | Where-Object { $_.Message -like 'Deleted guest todelete@example.com (toDelete). Reason: last sign-in: *' }).Count | Should -Be 1 + } + + It 'respects IncludeNeverSignedIn for the delete set' { + $script:enabledGuests = @() + $script:disabledGuests = @(New-Guest -Id 'pending' -Upn 'pending@example.com' -AccountEnabled $false -State 'PendingAcceptance') + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 90; deleteGraceDays = 30 } + @($script:deleted) | Should -BeNullOrEmpty + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 90; deleteGraceDays = 30; IncludeNeverSignedIn = $true } + @($script:deleted) | Should -Be @('pending') + } + + It 'still deletes when the disable set is empty even if audit would fail' { + $script:enabledGuests = @() + $script:disabledGuests = @(New-Guest -Id 'old' -Upn 'old@example.com' -AccountEnabled $false -InteractiveDaysAgo 200) + Mock -CommandName New-GraphGetRequest -MockWith { + param($uri, $tenantid, $scope) + if ($uri -like '*directoryAudits*') { throw 'audit unavailable' } + if ($uri -like '*accountEnabled eq false*') { return $script:disabledGuests } + return $script:enabledGuests + } + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = 90; deleteGraceDays = 30 } + + Should -Invoke New-GraphGetRequest -ParameterFilter { $uri -like '*directoryAudits*' } -Times 0 -Exactly + @($script:deleted) | Should -Be @('old') + } + + It 'treats string days as an int so delete age is days plus grace, not concatenation' { + $script:enabledGuests = @() + # 200 days inactive: qualifies for delete at 90+30=120, would not if age were wrongly 9030 + $script:disabledGuests = @(New-Guest -Id 'old' -Upn 'old@example.com' -AccountEnabled $false -InteractiveDaysAgo 200) + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ remediate = $true; days = '90'; deleteGraceDays = '30' } + + @($script:deleted) | Should -Be @('old') + } + } + Context 'alert and report' { It 'splits stale sign-ins from never-signed-in guests and records the switch' { - $script:guests = @( + $script:enabledGuests = @( New-Guest -Id 'stale' -Upn 'stale@example.com' -InteractiveDaysAgo 200 New-Guest -Id 'pending' -Upn 'pending@example.com' -State 'PendingAcceptance' New-Guest -Id 'active' -Upn 'active@example.com' -NonInteractiveDaysAgo 2 @@ -202,10 +284,12 @@ Describe 'Invoke-CIPPStandardDisableGuests' { $script:compare.Count | Should -Be 1 $Current = $script:compare[0].Current $Current.GuestsDisabledAfterDays | Should -Be 90 + $Current.GuestsDeleteGraceDays | Should -Be 0 $Current.GuestsIncludeNeverSignedIn | Should -BeTrue $Current.GuestsDisabledAccountCount | Should -Be 2 $Current.GuestsStaleSignInCount | Should -Be 1 $Current.GuestsNeverSignedInCount | Should -Be 1 + $Current.GuestsMeetingDeleteThreshold | Should -Be 'Deletion disabled' @($Current.GuestsNeverSignedInDetails).id | Should -Be 'pending' @($Current.GuestsDisabledAccountDetails | Where-Object { -not $_.NeverSignedIn }).LastSignInDateTime | Should -Not -BeNullOrEmpty @@ -214,10 +298,11 @@ Describe 'Invoke-CIPPStandardDisableGuests' { $Expected.GuestsStaleSignInCount | Should -Be 0 $Expected.GuestsNeverSignedInCount | Should -Be 0 $Expected.GuestsIncludeNeverSignedIn | Should -BeTrue + $Expected.GuestsMeetingDeleteThreshold | Should -Be 'Deletion disabled' } It 'reports the switch off and no never-signed-in guests when the template omits it' { - $script:guests = @(New-Guest -Id 'pending' -Upn 'pending@example.com' -State 'PendingAcceptance') + $script:enabledGuests = @(New-Guest -Id 'pending' -Upn 'pending@example.com' -State 'PendingAcceptance') Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ report = $true; days = 90 } @@ -226,5 +311,19 @@ Describe 'Invoke-CIPPStandardDisableGuests' { $Current.GuestsDisabledAccountCount | Should -Be 0 $Current.GuestsNeverSignedInCount | Should -Be 0 } + + It 'includes delete candidates in alert and report when grace is set' { + $script:enabledGuests = @(New-Guest -Id 'stale' -Upn 'stale@example.com' -InteractiveDaysAgo 200) + $script:disabledGuests = @(New-Guest -Id 'old' -Upn 'old@example.com' -AccountEnabled $false -InteractiveDaysAgo 200) + + Invoke-CIPPStandardDisableGuests -Tenant $script:Tenant -Settings @{ alert = $true; report = $true; days = 90; deleteGraceDays = 30 } + + $script:alerts[0].Message | Should -Match '1 meeting delete threshold \(inactive 120 days, already disabled\)' + $Current = $script:compare[0].Current + $Current.GuestsDeleteGraceDays | Should -Be 30 + $Current.GuestsMeetingDeleteCount | Should -Be 1 + @($Current.GuestsMeetingDeleteThreshold).id | Should -Be 'old' + $script:compare[0].Expected.GuestsMeetingDeleteThreshold | Should -Be @() + } } } diff --git a/version_latest.txt b/version_latest.txt index b4ebbcb7157d2..f65d9ca04026c 100644 --- a/version_latest.txt +++ b/version_latest.txt @@ -1 +1 @@ -10.10.1 \ No newline at end of file +10.10.2 \ No newline at end of file From c04bde0f4b53280c1ed21d838ba2c4bbcfc8a600 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Mon, 14 Sep 2026 19:32:55 +0000 Subject: [PATCH 4/4] Merge pull request #607 from CyberDrain/dev fix: Dev to hotfix Synced from CyberDrain/CIPP@75dd35aec0e195537b6161778cb6d758a53ce954 --- Config/PermissionsTranslator.json | 4025 +++++++++-------- Config/openapi.json | 70 +- .../Push-DomainAnalyserDomain.ps1 | 12 + .../Grant-CippAppGraphConsent.ps1 | 81 + .../Authentication/Initialize-CIPPAuth.ps1 | 53 + .../Authentication/Set-CIPPMCPClientApp.ps1 | 38 + .../Get-CIPPBaselineGroupTemplateState.ps1 | 20 +- .../Invoke-CIPPBaselineGroupTemplate.ps1 | 8 + .../Start-InstanceHealthSample.ps1 | 35 - .../Functions/Get-CIPPEgressAccounting.ps1 | 125 + .../Public/Functions/Get-CIPPEgressLedger.ps1 | 44 - .../Get-CIPPInstanceHealthSample.ps1 | 13 - .../MCP/Get-CippMcpScopeAppSettings.ps1 | 71 + .../Public/DBCache/Set-CIPPDBCacheDevices.ps1 | 2 +- .../CIPP/Settings/Invoke-ExecApiClient.ps1 | 48 +- .../CIPP/Settings/Invoke-ListApiEgress.ps1 | 135 + .../Invoke-ListInstanceDiagnostics.ps1 | 84 +- .../Invoke-CIPPStandardGroupTemplate.ps1 | 18 + .../CIS/Identity/Invoke-CippTestCIS_2_1_7.ps1 | 33 +- .../BaselineTemplateFamilies2.Tests.ps1 | 14 +- Tests/Endpoint/Invoke-AddUser.Tests.ps1 | 23 + ...ListInstanceDiagnostics.Timeline.Tests.ps1 | 127 +- .../Get-CIPPEgressAccounting.Tests.ps1 | 96 + Tests/Private/Get-CIPPEgressLedger.Tests.ps1 | 34 - .../Get-CIPPInstanceHealthSample.Tests.ps1 | 13 - .../Get-CippMcpScopeAppSettings.Tests.ps1 | 53 + .../Grant-CippAppGraphConsent.Tests.ps1 | 102 + Tests/Private/Set-CIPPMCPClientApp.Tests.ps1 | 96 + ...Invoke-CIPPStandardGroupTemplate.Tests.ps1 | 46 +- version_latest.txt | 2 +- 30 files changed, 3216 insertions(+), 2305 deletions(-) create mode 100644 Modules/CIPPCore/Public/Authentication/Grant-CippAppGraphConsent.ps1 create mode 100644 Modules/CIPPCore/Public/Functions/Get-CIPPEgressAccounting.ps1 delete mode 100644 Modules/CIPPCore/Public/Functions/Get-CIPPEgressLedger.ps1 create mode 100644 Modules/CIPPCore/Public/MCP/Get-CippMcpScopeAppSettings.ps1 create mode 100644 Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListApiEgress.ps1 create mode 100644 Tests/Private/Get-CIPPEgressAccounting.Tests.ps1 delete mode 100644 Tests/Private/Get-CIPPEgressLedger.Tests.ps1 create mode 100644 Tests/Private/Get-CippMcpScopeAppSettings.Tests.ps1 create mode 100644 Tests/Private/Grant-CippAppGraphConsent.Tests.ps1 create mode 100644 Tests/Private/Set-CIPPMCPClientApp.Tests.ps1 diff --git a/Config/PermissionsTranslator.json b/Config/PermissionsTranslator.json index 74cc01fc96763..9e140b5ded6ab 100644 --- a/Config/PermissionsTranslator.json +++ b/Config/PermissionsTranslator.json @@ -6,6 +6,20 @@ "origin": "Delegated (1ES Resource Management PPE)", "value": "manage_ado_pools" }, + { + "description": "Allows the application to create or delete document libraries and lists in all site collections on behalf of the signed-in user.", + "displayName": "Create, edit, and delete items and lists in all site collections", + "id": "65e50fdc-43b7-4915-933e-e8138f11f40a", + "origin": "Delegated (Microsoft Graph)", + "value": "Sites.Manage.All" + }, + { + "description": "Allows the application to read documents and list items in all site collections on behalf of the signed-in user", + "displayName": "Read items in all site collections", + "id": "205e70e5-aba6-4c52-a976-6d2d46c48043", + "origin": "Delegated (Microsoft Graph)", + "value": "Sites.Read.All" + }, { "description": "Allows the application to edit or delete documents and list items in all site collections on behalf of the signed-in user.", "displayName": "Edit or delete items in all site collections", @@ -111,6 +125,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "Tasks.Read.Shared" }, + { + "description": "Allows the application to have full control of all site collections on behalf of the signed-in user.", + "displayName": "Have full control of all site collections", + "id": "5a54b8b3-347c-476d-8f8e-42d5c7424d29", + "origin": "Delegated (Microsoft Graph)", + "value": "Sites.FullControl.All" + }, { "description": "Allows the app to create, read, update, and delete the signed-in user's tasks and task lists, including any shared with the user.", "displayName": "Create, read, update, and delete user’s tasks and task lists", @@ -119,39 +140,32 @@ "value": "Tasks.ReadWrite" }, { - "description": "Allows the app to create, read, update, and delete tasks a user has permissions to, including their own and shared tasks.", - "displayName": "Read and write user and shared tasks", - "id": "c5ddf11b-c114-4886-8558-8a4e557cd52b", - "origin": "Delegated (Microsoft Graph)", - "value": "Tasks.ReadWrite.Shared" - }, - { - "description": "Allows the application to read documents and list items in all site collections on behalf of the signed-in user", - "displayName": "Read items in all site collections", - "id": "205e70e5-aba6-4c52-a976-6d2d46c48043", + "description": "Allow the application to create site collections on behalf of the signed in user. Upon creation the application will be granted Sites.Selected(delegated) + FullControl to the newly created site.", + "displayName": "Create Site Collections, on behalf of the signed-in user", + "id": "0e2e68e1-3f32-4e10-9281-f749e097fcbe", "origin": "Delegated (Microsoft Graph)", - "value": "Sites.Read.All" + "value": "Sites.Create.All" }, { - "description": "Allows the app to create teams on behalf of the signed-in user.", - "displayName": "Create teams", - "id": "7825d5d6-6049-4ce7-bdf6-3b8d53f4bcd0", + "description": "Allows the app to read your organization's sign-in identifiers, on behalf of the signed-in user.", + "displayName": "Read SignInIdentifiers", + "id": "458e1edc-1e75-438c-8c7b-c32115c9d373", "origin": "Delegated (Microsoft Graph)", - "value": "Team.Create" + "value": "SignInIdentifier.Read.All" }, { - "description": "Allows the application to create or delete document libraries and lists in all site collections on behalf of the signed-in user.", - "displayName": "Create, edit, and delete items and lists in all site collections", - "id": "65e50fdc-43b7-4915-933e-e8138f11f40a", + "description": "Allows the app to get sensitivity labels.", + "displayName": "Get labels app scope.", + "id": "8b377c27-ea19-4863-a948-8a8588c8f2c3", "origin": "Delegated (Microsoft Graph)", - "value": "Sites.Manage.All" + "value": "SensitivityLabels.Read.All" }, { - "description": "Allow the application to create site collections on behalf of the signed in user. Upon creation the application will be granted Sites.Selected(delegated) + FullControl to the newly created site.", - "displayName": "Create Site Collections, on behalf of the signed-in user", - "id": "0e2e68e1-3f32-4e10-9281-f749e097fcbe", + "description": "Allows the app to export all Sentiment Survey, on behalf of the signed-in user.", + "displayName": "Export all Sentiment Survey", + "id": "df9fd94d-51ff-443d-8f31-ae4dc1b5b8d8", "origin": "Delegated (Microsoft Graph)", - "value": "Sites.Create.All" + "value": "SentimentSurvey.Export.All" }, { "description": "Allows the app to read all Exchange service activity, on behalf of the signed-in user.", @@ -258,13 +272,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "ShortNotes.ReadWrite" }, - { - "description": "Allows the app to read your organization's sign-in identifiers, on behalf of the signed-in user.", - "displayName": "Read SignInIdentifiers", - "id": "458e1edc-1e75-438c-8c7b-c32115c9d373", - "origin": "Delegated (Microsoft Graph)", - "value": "SignInIdentifier.Read.All" - }, { "description": "Allows the app to read and write your organization's sign-in identifiers, on behalf of the signed-in user.", "displayName": "Read and write all sign-in identifiers", @@ -273,11 +280,18 @@ "value": "SignInIdentifier.ReadWrite.All" }, { - "description": "Allows the application to have full control of all site collections on behalf of the signed-in user.", - "displayName": "Have full control of all site collections", - "id": "5a54b8b3-347c-476d-8f8e-42d5c7424d29", + "description": "Allows the app to create, read, update, and delete tasks a user has permissions to, including their own and shared tasks.", + "displayName": "Read and write user and shared tasks", + "id": "c5ddf11b-c114-4886-8558-8a4e557cd52b", "origin": "Delegated (Microsoft Graph)", - "value": "Sites.FullControl.All" + "value": "Tasks.ReadWrite.Shared" + }, + { + "description": "Allows the app to create teams on behalf of the signed-in user.", + "displayName": "Create teams", + "id": "7825d5d6-6049-4ce7-bdf6-3b8d53f4bcd0", + "origin": "Delegated (Microsoft Graph)", + "value": "Team.Create" }, { "description": "Read the names and descriptions of teams, on behalf of the signed-in user.", @@ -287,18 +301,18 @@ "value": "Team.ReadBasic.All" }, { - "description": "Read the members of teams, on behalf of the signed-in user.", - "displayName": "Read the members of teams", - "id": "2497278c-d82d-46a2-b1ce-39d4cdde5570", + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps installed for the signed-in user. Does not give the ability to read application-specific settings.", + "displayName": "Manage user's installed Teams apps", + "id": "093f8818-d05f-49b8-95bc-9d2a73e9a43c", "origin": "Delegated (Microsoft Graph)", - "value": "TeamMember.Read.All" + "value": "TeamsAppInstallation.ReadWriteForUser" }, { - "description": "Add and remove members from teams, on behalf of the signed-in user. Also allows changing a member's role, for example from owner to non-owner.", - "displayName": "Add and remove members from teams", - "id": "4a06efd2-f825-4e34-813e-82a57b03d1ee", + "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in chats the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Manage selected Teams apps installed in chats", + "id": "690aa3b6-4b71-41c2-a990-77a8c4768d2b", "origin": "Delegated (Microsoft Graph)", - "value": "TeamMember.ReadWrite.All" + "value": "TeamsAppInstallation.ReadWriteSelectedForChat" }, { "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in teams the signed-in user can access. Does not give the ability to read application-specific settings.", @@ -406,46 +420,46 @@ "value": "TeamsTab.ReadWriteForUser" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs in chats the signed-in user can access.", - "displayName": "Allow the Teams app to manage only its own tabs in chats", - "id": "0c219d04-3abf-47f7-912d-5cca239e90e6", + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in teams the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Manage installed Teams apps in teams", + "id": "2e25a044-2580-450d-8859-42eeb6e996c0", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsTab.ReadWriteSelfForChat" + "value": "TeamsAppInstallation.ReadWriteForTeam" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs to teams the signed-in user can access.", - "displayName": "Allow the Teams app to manage only its own tabs in teams", - "id": "f266662f-120a-4314-b26a-99b08617c7ef", + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in chats the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Manage installed Teams apps in chats", + "id": "aa85bf13-d771-4d5d-a9e6-bca04ce44edf", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsTab.ReadWriteSelfForTeam" + "value": "TeamsAppInstallation.ReadWriteForChat" }, { - "description": "Allows the app to read, install, upgrade, and uninstall selected Teams apps in chats the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Manage selected Teams apps installed in chats", - "id": "690aa3b6-4b71-41c2-a990-77a8c4768d2b", + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in user accounts, and manage its permission grants for accessing those specific users' data, on behalf of the signed-in user.", + "displayName": "Allow the Teams app to manage itself and its permission grants in user accounts", + "id": "7a349935-c54d-44ab-ab66-1b460d315be7", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteSelectedForChat" + "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForUser" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps installed for the signed-in user. Does not give the ability to read application-specific settings.", - "displayName": "Manage user's installed Teams apps", - "id": "093f8818-d05f-49b8-95bc-9d2a73e9a43c", + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in teams the signed-in user can access, and manage its permission grants for accessing those specific teams' data.", + "displayName": "Allow the Teams app to manage itself and its permission grants in teams", + "id": "4a6bbf29-a0e1-4a4d-a7d1-cef17f772975", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteForUser" + "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForTeam" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in teams the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Manage installed Teams apps in teams", - "id": "2e25a044-2580-450d-8859-42eeb6e996c0", + "description": "Read the members of teams, on behalf of the signed-in user.", + "displayName": "Read the members of teams", + "id": "2497278c-d82d-46a2-b1ce-39d4cdde5570", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteForTeam" + "value": "TeamMember.Read.All" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in chats the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Manage installed Teams apps in chats", - "id": "aa85bf13-d771-4d5d-a9e6-bca04ce44edf", + "description": "Add and remove members from teams, on behalf of the signed-in user. Also allows changing a member's role, for example from owner to non-owner.", + "displayName": "Add and remove members from teams", + "id": "4a06efd2-f825-4e34-813e-82a57b03d1ee", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteForChat" + "value": "TeamMember.ReadWrite.All" }, { "description": "Add and remove members from all teams, on behalf of the signed-in user. Does not allow adding or removing a member with the owner role. Additionally, does not allow the app to elevate an existing member to the owner role.", @@ -489,6 +503,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "TeamsAppInstallation.ManageSelectedForUser" }, + { + "description": "Allows the app to get sensitivity labels.", + "displayName": "Get labels user scope.", + "id": "1aeb73ce-68d7-49b7-913a-eedc80844551", + "origin": "Delegated (Microsoft Graph)", + "value": "SensitivityLabel.Read" + }, { "description": "Allows the app to read the Teams apps that are installed in chats the signed-in user can access. Does not give the ability to read application-specific settings.", "displayName": "Read installed Teams apps in chats", @@ -496,20 +517,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "TeamsAppInstallation.ReadForChat" }, - { - "description": "Allows the app to read the Teams apps that are installed in teams the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Read installed Teams apps in teams", - "id": "5248dcb1-f83b-4ec3-9f4d-a4428a961a72", - "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadForTeam" - }, - { - "description": "Allows the app to export all Sentiment Survey, on behalf of the signed-in user.", - "displayName": "Export all Sentiment Survey", - "id": "df9fd94d-51ff-443d-8f31-ae4dc1b5b8d8", - "origin": "Delegated (Microsoft Graph)", - "value": "SentimentSurvey.Export.All" - }, { "description": "Allows the app to read the Teams apps that are installed for the signed-in user. Does not give the ability to read application-specific settings.", "displayName": "Read user's installed Teams apps", @@ -517,6 +524,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "TeamsAppInstallation.ReadForUser" }, + { + "description": "Allows the app to read the selected Teams apps that are installed in chats the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Read selected installed Teams apps in chats", + "id": "0f3420c2-c6ec-46de-ab72-fd51267087d5", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadSelectedForChat" + }, { "description": "Allows the app to read the selected Teams apps that are installed in teams the signed-in user can access. Does not give the ability to read application-specific settings.", "displayName": "Read selected installed Teams apps in teams", @@ -560,46 +574,46 @@ "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForChat" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in teams the signed-in user can access, and manage its permission grants for accessing those specific teams' data.", - "displayName": "Allow the Teams app to manage itself and its permission grants in teams", - "id": "4a6bbf29-a0e1-4a4d-a7d1-cef17f772975", + "description": "Allows the app to read the Teams apps that are installed in teams the signed-in user can access. Does not give the ability to read application-specific settings.", + "displayName": "Read installed Teams apps in teams", + "id": "5248dcb1-f83b-4ec3-9f4d-a4428a961a72", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForTeam" + "value": "TeamsAppInstallation.ReadForTeam" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in user accounts, and manage its permission grants for accessing those specific users' data, on behalf of the signed-in user.", - "displayName": "Allow the Teams app to manage itself and its permission grants in user accounts", - "id": "7a349935-c54d-44ab-ab66-1b460d315be7", + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs in chats the signed-in user can access.", + "displayName": "Allow the Teams app to manage only its own tabs in chats", + "id": "0c219d04-3abf-47f7-912d-5cca239e90e6", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForUser" + "value": "TeamsTab.ReadWriteSelfForChat" }, { - "description": "Allows the app to read the selected Teams apps that are installed in chats the signed-in user can access. Does not give the ability to read application-specific settings.", - "displayName": "Read selected installed Teams apps in chats", - "id": "0f3420c2-c6ec-46de-ab72-fd51267087d5", + "description": "Allows the app to evaluate all sensitivity label.", + "displayName": "Evaluate labels tenant scope.", + "id": "a42e3c42-b31e-4919-b699-696dca5dc9e7", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadSelectedForChat" + "value": "SensitivityLabel.Evaluate.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for the signed-in user.", - "displayName": "Allow the Teams app to manage only its own tabs for a user", - "id": "395dfec1-a0b9-465f-a783-8250a430cb8c", + "description": "Allows the app to read and write security incidents, on behalf of the signed-in user.", + "displayName": "Read and write to incidents", + "id": "128ca929-1a19-45e6-a3b8-435ec44a36ba", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsTab.ReadWriteSelfForUser" + "value": "SecurityIncident.ReadWrite.All" }, { - "description": "Allows the app to get sensitivity labels.", - "displayName": "Get labels app scope.", - "id": "8b377c27-ea19-4863-a948-8a8588c8f2c3", + "description": "Allows an app to read all service usage reports on behalf of the signed-in user. Services that provide usage reports include Office 365 and Azure Active Directory.", + "displayName": "Read all usage reports", + "id": "02e97553-ed7b-43d0-ab3c-f8bace0d040c", "origin": "Delegated (Microsoft Graph)", - "value": "SensitivityLabels.Read.All" + "value": "Reports.Read.All" }, { - "description": "Allows the app to evaluate all sensitivity label.", - "displayName": "Evaluate labels tenant scope.", - "id": "a42e3c42-b31e-4919-b699-696dca5dc9e7", + "description": "Allows the app to read admin report settings, such as whether to display concealed information in reports, on behalf of the signed-in user", + "displayName": "Read admin report settings", + "id": "84fac5f4-33a9-4100-aa38-a20c6d29e5e7", "origin": "Delegated (Microsoft Graph)", - "value": "SensitivityLabel.Evaluate.All" + "value": "ReportSettings.Read.All" }, { "description": "Allows the app to read and update admin report settings, such as whether to display concealed information in reports, on behalf of the signed-in user.", @@ -706,6 +720,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "RoleManagement.Read.Defender" }, + { + "description": "Allows the app to read available properties of remoteTenantGroups, on behalf of the signed-in user.", + "displayName": "Read RemoteTenantGroups information", + "id": "d207fff0-6e36-4360-a23b-495e23b60385", + "origin": "Delegated (Microsoft Graph)", + "value": "RemoteTenantGroups.Read.All" + }, { "description": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes reading directory role templates, directory roles and memberships.", "displayName": "Read directory RBAC settings", @@ -714,39 +735,32 @@ "value": "RoleManagement.Read.Directory" }, { - "description": "Allows the app to read the role-based access control (RBAC) settings for your organization's Exchange Online service, on behalf of the signed-in user. This includes reading Exchange management role definitions, role groups, role group membership, role assignments, management scopes, and role assignment policies.", - "displayName": "Read Exchange Online RBAC configuration", - "id": "3bc15058-7858-4141-b24f-ae43b4e80b52", + "description": "Allow the application to create, update and delete any data from Records Management, such as configuration, labels, and policies on behalf of the signed-in user.", + "displayName": "Read and write Records Management configuration, labels, and policies", + "id": "f2833d75-a4e6-40ab-86d4-6dfe73c97605", "origin": "Delegated (Microsoft Graph)", - "value": "RoleManagement.Read.Exchange" + "value": "RecordsManagement.ReadWrite.All" }, { - "description": "Allows the app to read admin report settings, such as whether to display concealed information in reports, on behalf of the signed-in user", - "displayName": "Read admin report settings", - "id": "84fac5f4-33a9-4100-aa38-a20c6d29e5e7", + "description": "Allows the app to get direct access to real-time enriched data in a meeting, on behalf of the signed-in user.", + "displayName": "Access real-time enriched data in a meeting", + "id": "db5d5bae-0c9e-444e-9390-8a5fea98c253", "origin": "Delegated (Microsoft Graph)", - "value": "ReportSettings.Read.All" + "value": "RealTimeActivityFeed.Read.All" }, { - "description": "Allows the app to read and manage the Cloud PC role-based access control (RBAC) settings, on behalf of the signed-in user. This includes reading and managing Cloud PC role definitions and role assignments.", - "displayName": "Read and write Cloud PC RBAC settings", - "id": "501d06f8-07b8-4f18-b5c6-c191a4af7a82", + "description": "Allows the app to read, create, and delete time-based eligibility schedules for access to Azure AD groups, on behalf of the signed-in user.", + "displayName": "Read, create, and delete eligibility schedules for access to Azure AD groups", + "id": "ba974594-d163-484e-ba39-c330d5897667", "origin": "Delegated (Microsoft Graph)", - "value": "RoleManagement.ReadWrite.CloudPC" + "value": "PrivilegedEligibilitySchedule.ReadWrite.AzureADGroup" }, { - "description": "Allows an app to read all service usage reports on behalf of the signed-in user. Services that provide usage reports include Office 365 and Azure Active Directory.", - "displayName": "Read all usage reports", - "id": "02e97553-ed7b-43d0-ab3c-f8bace0d040c", - "origin": "Delegated (Microsoft Graph)", - "value": "Reports.Read.All" - }, - { - "description": "Allow the application to create, update and delete any data from Records Management, such as configuration, labels, and policies on behalf of the signed-in user.", - "displayName": "Read and write Records Management configuration, labels, and policies", - "id": "f2833d75-a4e6-40ab-86d4-6dfe73c97605", + "description": "Allows the app to read, create, and delete time-based eligibility schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", + "displayName": "Read, create, and delete eligibility schedules for app permission grants and app role assignments", + "id": "f7ff1cb0-e255-4bb3-b24a-6708c60c5418", "origin": "Delegated (Microsoft Graph)", - "value": "RecordsManagement.ReadWrite.All" + "value": "PrivilegedEligibilitySchedule.ReadWrite.EntraAppRole" }, { "description": "Allows the app to delete time-based eligibility schedules for access to Azure AD groups, on behalf of the signed-in user.", @@ -853,13 +867,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "QnA.Read.All" }, - { - "description": "Allows the app to get direct access to real-time enriched data in a meeting, on behalf of the signed-in user.", - "displayName": "Access real-time enriched data in a meeting", - "id": "db5d5bae-0c9e-444e-9390-8a5fea98c253", - "origin": "Delegated (Microsoft Graph)", - "value": "RealTimeActivityFeed.Read.All" - }, { "description": "Allows the application to read any data from Records Management, such as configuration, labels, and policies on behalf of the signed-in user.", "displayName": "Read Records Management configuration, labels, and policies", @@ -868,11 +875,18 @@ "value": "RecordsManagement.Read.All" }, { - "description": "Allows the app to read available properties of remoteTenantGroups, on behalf of the signed-in user.", - "displayName": "Read RemoteTenantGroups information", - "id": "d207fff0-6e36-4360-a23b-495e23b60385", + "description": "Allows the app to read the role-based access control (RBAC) settings for your organization's Exchange Online service, on behalf of the signed-in user. This includes reading Exchange management role definitions, role groups, role group membership, role assignments, management scopes, and role assignment policies.", + "displayName": "Read Exchange Online RBAC configuration", + "id": "3bc15058-7858-4141-b24f-ae43b4e80b52", "origin": "Delegated (Microsoft Graph)", - "value": "RemoteTenantGroups.Read.All" + "value": "RoleManagement.Read.Exchange" + }, + { + "description": "Allows the app to read and manage the Cloud PC role-based access control (RBAC) settings, on behalf of the signed-in user. This includes reading and managing Cloud PC role definitions and role assignments.", + "displayName": "Read and write Cloud PC RBAC settings", + "id": "501d06f8-07b8-4f18-b5c6-c191a4af7a82", + "origin": "Delegated (Microsoft Graph)", + "value": "RoleManagement.ReadWrite.CloudPC" }, { "description": "Allows the app to read the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes reading M365 Defender role definitions and role assignments.", @@ -882,18 +896,18 @@ "value": "RoleManagement.ReadWrite.Defender" }, { - "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes instantiating directory roles and managing directory role membership, and reading directory role templates, directory roles and memberships.", - "displayName": "Read and write directory RBAC settings", - "id": "d01b97e9-cbc0-49fe-810a-750afd5527a3", + "description": "Allows the app to read all Security Copilot signed-in user's resources on behalf of the signed-in user", + "displayName": "Read all Security Copilot resources for the signed-in user", + "id": "84499c31-ac2e-44d3-a0cf-a6c386d4dfe8", "origin": "Delegated (Microsoft Graph)", - "value": "RoleManagement.ReadWrite.Directory" + "value": "SecurityCopilotWorkspaces.Read.All" }, { - "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your organization's Exchange Online service, on behalf of the signed-in user. This includes reading, creating, updating, and deleting Exchange management role definitions, role groups, role group membership, role assignments, management scopes, and role assignment policies.", - "displayName": "Read and write Exchange Online RBAC configuration", - "id": "c1499fe0-52b1-4b22-bed2-7a244e0e879f", + "description": "Allows the app to read and write Security Copilot resources owned by the signed-in user on their behalf.", + "displayName": "Read and write individually owned Security Copilot resources of the signed-in user", + "id": "206291b0-2167-47a7-a640-6cdc1df710ba", "origin": "Delegated (Microsoft Graph)", - "value": "RoleManagement.ReadWrite.Exchange" + "value": "SecurityCopilotWorkspaces.ReadWrite.All" }, { "description": "Allows the app to read your organization’s security events on behalf of the signed-in user.", @@ -1001,46 +1015,46 @@ "value": "SecurityIncident.Read.All" }, { - "description": "Allows the app to read and write security incidents, on behalf of the signed-in user.", - "displayName": "Read and write to incidents", - "id": "128ca929-1a19-45e6-a3b8-435ec44a36ba", + "description": "Read email metadata, security detection details, and execute remediation actions like deleting an email, on behalf of the signed in user.", + "displayName": "Read metadata, detection details, and execute remediation actions on emails in your organization", + "id": "48eb8c83-6e58-46e7-a6d3-8805822f5940", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityIncident.ReadWrite.All" + "value": "SecurityAnalyzedMessage.ReadWrite.All" }, { - "description": "Allow the app to determine if there is any sensitivity label to be applied automatically to the content or recommended to the user for manual application, on behalf of the signed-in user.", - "displayName": "Evaluate sensitivity labels", - "id": "a4633e44-d355-4474-99df-8c2de6b0e39e", + "description": "Read email metadata and security detection details on behalf of the signed in user.", + "displayName": "Read metadata and detection details for emails in your organization", + "id": "53e6783e-b127-4a35-ab3a-6a52d80a9077", "origin": "Delegated (Microsoft Graph)", - "value": "SensitivityLabel.Evaluate" + "value": "SecurityAnalyzedMessage.Read.All" }, { - "description": "Allows the app to read and write Security Copilot resources owned by the signed-in user on their behalf.", - "displayName": "Read and write individually owned Security Copilot resources of the signed-in user", - "id": "206291b0-2167-47a7-a640-6cdc1df710ba", + "description": "Allows the app to read and write to all security alerts, on behalf of the signed-in user.", + "displayName": "Read and write to all security alerts", + "id": "471f2a7f-2a42-4d45-a2bf-594d0838070d", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityCopilotWorkspaces.ReadWrite.All" + "value": "SecurityAlert.ReadWrite.All" }, { - "description": "Allows the app to read all Security Copilot signed-in user's resources on behalf of the signed-in user", - "displayName": "Read all Security Copilot resources for the signed-in user", - "id": "84499c31-ac2e-44d3-a0cf-a6c386d4dfe8", + "description": "Allows the app to read all security alerts, on behalf of the signed-in user.", + "displayName": "Read all security alerts", + "id": "bc257fb8-46b4-4b15-8713-01e91bfbe4ea", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityCopilotWorkspaces.Read.All" + "value": "SecurityAlert.Read.All" }, { - "description": "Read email metadata, security detection details, and execute remediation actions like deleting an email, on behalf of the signed in user.", - "displayName": "Read metadata, detection details, and execute remediation actions on emails in your organization", - "id": "48eb8c83-6e58-46e7-a6d3-8805822f5940", + "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your company's directory, on behalf of the signed-in user. This includes instantiating directory roles and managing directory role membership, and reading directory role templates, directory roles and memberships.", + "displayName": "Read and write directory RBAC settings", + "id": "d01b97e9-cbc0-49fe-810a-750afd5527a3", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityAnalyzedMessage.ReadWrite.All" + "value": "RoleManagement.ReadWrite.Directory" }, { - "description": "Read email metadata and security detection details on behalf of the signed in user.", - "displayName": "Read metadata and detection details for emails in your organization", - "id": "53e6783e-b127-4a35-ab3a-6a52d80a9077", + "description": "Allows the app to read and manage the role-based access control (RBAC) settings for your organization's Exchange Online service, on behalf of the signed-in user. This includes reading, creating, updating, and deleting Exchange management role definitions, role groups, role group membership, role assignments, management scopes, and role assignment policies.", + "displayName": "Read and write Exchange Online RBAC configuration", + "id": "c1499fe0-52b1-4b22-bed2-7a244e0e879f", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityAnalyzedMessage.Read.All" + "value": "RoleManagement.ReadWrite.Exchange" }, { "description": "Allows the app to read the role-based access control (RBAC) alerts for your company's directory, on behalf of the signed-in user. This includes reading alert statuses, alert definitions, alert configurations and incidents that lead to an alert.", @@ -1084,6 +1098,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "RoleManagementPolicy.ReadWrite.AzureADGroup" }, + { + "description": "Allow the app to determine if there is any sensitivity label to be applied automatically to the content or recommended to the user for manual application, on behalf of the signed-in user.", + "displayName": "Evaluate sensitivity labels", + "id": "a4633e44-d355-4474-99df-8c2de6b0e39e", + "origin": "Delegated (Microsoft Graph)", + "value": "SensitivityLabel.Evaluate" + }, { "description": "Allows the app to read, update, and delete policies for privileged role-based access control (RBAC) assignments of your company's directory, on behalf of the signed-in user.", "displayName": "Read, update, and delete all policies for privileged role assignments of your company's directory", @@ -1091,20 +1112,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "RoleManagementPolicy.ReadWrite.Directory" }, - { - "description": "Allows the app to manage policies in Privileged Identity Management for App Roles, on behalf of the signed-in user.", - "displayName": "Manage all policies in PIM for App Roles", - "id": "652ec839-e4ac-4eb5-b545-ecc90eeceb2d", - "origin": "Delegated (Microsoft Graph)", - "value": "RoleManagementPolicy.ReadWrite.EntraAppRole" - }, - { - "description": "Allows the app to get sensitivity labels.", - "displayName": "Get labels user scope.", - "id": "1aeb73ce-68d7-49b7-913a-eedc80844551", - "origin": "Delegated (Microsoft Graph)", - "value": "SensitivityLabel.Read" - }, { "description": "Allows the app to read schedule, schedule groups, shifts and associated entities in the Teams or Shifts application on behalf of the signed-in user.", "displayName": "Read user schedule items", @@ -1112,6 +1119,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "Schedule.Read.All" }, + { + "description": "Allows the app to manage schedule, schedule groups, shifts and associated entities in the Teams or Shifts application on behalf of the signed-in user.", + "displayName": "Read and write user schedule items", + "id": "63f27281-c9d9-4f29-94dd-6942f7f1feb0", + "origin": "Delegated (Microsoft Graph)", + "value": "Schedule.ReadWrite.All" + }, { "description": "Allows the app to read/write schedule permissions for a specific role in Shifts application on behalf of the signed-in user.", "displayName": "Read/Write schedule permissions for a role.", @@ -1155,25 +1169,25 @@ "value": "SecurityAlert.Create.All" }, { - "description": "Allows the app to read all security alerts, on behalf of the signed-in user.", - "displayName": "Read all security alerts", - "id": "bc257fb8-46b4-4b15-8713-01e91bfbe4ea", + "description": "Allows the app to manage policies in Privileged Identity Management for App Roles, on behalf of the signed-in user.", + "displayName": "Manage all policies in PIM for App Roles", + "id": "652ec839-e4ac-4eb5-b545-ecc90eeceb2d", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityAlert.Read.All" + "value": "RoleManagementPolicy.ReadWrite.EntraAppRole" }, { - "description": "Allows the app to read and write to all security alerts, on behalf of the signed-in user.", - "displayName": "Read and write to all security alerts", - "id": "471f2a7f-2a42-4d45-a2bf-594d0838070d", + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs to teams the signed-in user can access.", + "displayName": "Allow the Teams app to manage only its own tabs in teams", + "id": "f266662f-120a-4314-b26a-99b08617c7ef", "origin": "Delegated (Microsoft Graph)", - "value": "SecurityAlert.ReadWrite.All" + "value": "TeamsTab.ReadWriteSelfForTeam" }, { - "description": "Allows the app to manage schedule, schedule groups, shifts and associated entities in the Teams or Shifts application on behalf of the signed-in user.", - "displayName": "Read and write user schedule items", - "id": "63f27281-c9d9-4f29-94dd-6942f7f1feb0", + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for the signed-in user.", + "displayName": "Allow the Teams app to manage only its own tabs for a user", + "id": "395dfec1-a0b9-465f-a783-8250a430cb8c", "origin": "Delegated (Microsoft Graph)", - "value": "Schedule.ReadWrite.All" + "value": "TeamsTab.ReadWriteSelfForUser" }, { "description": "Allows the app to read your tenant's acquired telephone number details on behalf of the signed-in admin user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", @@ -1183,18 +1197,18 @@ "value": "TeamsTelephoneNumber.Read.All" }, { - "description": "Allows the app to read and modify your tenant's acquired telephone number details on behalf of the signed-in admin user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", - "displayName": "Read and Modify Tenant-Acquired Telephone Number Details", - "id": "424b07a8-1209-4d17-9fe4-9018a93a1024", + "description": "Allows the app to read and write Temporary Access Pass authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' Temporary Access Pass methods.", + "id": "05de4a66-e51a-4312-842a-30c8094698d2", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsTelephoneNumber.ReadWrite.All" + "value": "UserAuthMethod-TAP.ReadWrite.All" }, { - "description": "Allows the app to read your tenant's user configurations on behalf of the signed-in admin user. User configuration may include attributes related to user, such as telephone number, assigned policies, etc.", - "displayName": "Read Teams user configurations", - "id": "5c469ce4-dab5-4afd-b9de-14f1ba4004a7", + "description": "Allows the app to read the signed-in user's Windows Hello authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's Windows Hello methods", + "id": "efe2b5aa-3a8e-486c-b0be-cc4d185c1b40", "origin": "Delegated (Microsoft Graph)", - "value": "TeamsUserConfiguration.Read.All" + "value": "UserAuthMethod-WindowsHello.Read" }, { "description": "Allows the app to read Windows Hello authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", @@ -1301,6 +1315,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "UserWindowsSettings.Read.All" }, + { + "description": "Allows the app to read and write the signed-in user's Temporary Access Pass authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's Temporary Access Pass authentication methods", + "id": "2424436d-902f-4651-a1c7-b3b93147c960", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-TAP.ReadWrite" + }, { "description": "Allows the app to read and write a user's windows settings which are stored in cloud and their values on behalf of the signed-in user.", "displayName": "Read and write windows settings for all devices", @@ -1309,39 +1330,32 @@ "value": "UserWindowsSettings.ReadWrite.All" }, { - "description": "This role can read Verified Id profiles in a tenant.", - "displayName": "Read Verified Id profiles", - "id": "604b2056-41ed-4c56-aad5-1241d4ef7333", - "origin": "Delegated (Microsoft Graph)", - "value": "VerifiedId-Profile.Read.All" - }, - { - "description": "Allows the app to read the signed-in user's Windows Hello authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read the signed-in user's Windows Hello methods", - "id": "efe2b5aa-3a8e-486c-b0be-cc4d185c1b40", + "description": "Allows the app to read Temporary Access Pass authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' Temporary Access Pass methods", + "id": "6976c635-c9c2-41e6-a21d-e6913a155273", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-WindowsHello.Read" + "value": "UserAuthMethod-TAP.Read.All" }, { - "description": "This role can read and write Verified Id profiles in a tenant.", - "displayName": "Read and write Verified Id profiles", - "id": "e4a9cb5e-4767-48f8-9029-decf26a54456", + "description": "Allows the app to read and write SoftwareOATH authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' SoftwareOATH methods.", + "id": "5b34c8b5-2396-4b35-b284-83fb6a3e73ce", "origin": "Delegated (Microsoft Graph)", - "value": "VerifiedId-Profile.ReadWrite.All" + "value": "UserAuthMethod-SoftwareOATH.ReadWrite.All" }, { - "description": "Allows the app to read and write Temporary Access Pass authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' Temporary Access Pass methods.", - "id": "05de4a66-e51a-4312-842a-30c8094698d2", + "description": "Allows the app to read the signed-in user's phone authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's phone authentication methods", + "id": "43dab3b9-e8b4-424d-8e13-6a2ad2a625fa", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-TAP.ReadWrite.All" + "value": "UserAuthMethod-Phone.Read" }, { - "description": "Allows the app to read Temporary Access Pass authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' Temporary Access Pass methods", - "id": "6976c635-c9c2-41e6-a21d-e6913a155273", + "description": "Allows the app to read phone authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' phone authentication methods", + "id": "20cf4ae1-09b9-4d29-a6f8-43e1820ce60c", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-TAP.Read.All" + "value": "UserAuthMethod-Phone.Read.All" }, { "description": "Allows the app to read and write the signed-in user's phone authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", @@ -1448,13 +1462,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "UserAuthMethod-SoftwareOATH.ReadWrite" }, - { - "description": "Allows the app to read and write SoftwareOATH authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' SoftwareOATH methods.", - "id": "5b34c8b5-2396-4b35-b284-83fb6a3e73ce", - "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-SoftwareOATH.ReadWrite.All" - }, { "description": "Allows the app to read the signed-in user's Temporary Access Pass authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", "displayName": "Read the signed-in user's Temporary Access Pass authentication methods", @@ -1463,11 +1470,18 @@ "value": "UserAuthMethod-TAP.Read" }, { - "description": "Allows the app to read and write the signed-in user's Temporary Access Pass authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write the signed-in user's Temporary Access Pass authentication methods", - "id": "2424436d-902f-4651-a1c7-b3b93147c960", + "description": "This role can read Verified Id profiles in a tenant.", + "displayName": "Read Verified Id profiles", + "id": "604b2056-41ed-4c56-aad5-1241d4ef7333", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-TAP.ReadWrite" + "value": "VerifiedId-Profile.Read.All" + }, + { + "description": "This role can read and write Verified Id profiles in a tenant.", + "displayName": "Read and write Verified Id profiles", + "id": "e4a9cb5e-4767-48f8-9029-decf26a54456", + "origin": "Delegated (Microsoft Graph)", + "value": "VerifiedId-Profile.ReadWrite.All" }, { "description": "Allows an application to read virtual appointments for the signed-in user. Only an organizer or participant user can read their virtual appointments. ", @@ -1477,18 +1491,18 @@ "value": "VirtualAppointment.Read" }, { - "description": "Allows an application to read and write virtual appointments for the signed-in user. Only an organizer or participant user can read and write their virtual appointments. ", - "displayName": "Read and write a user's virtual appointments ", - "id": "2ccc2926-a528-4b17-b8bb-860eed29d64c", - "origin": "Delegated (Microsoft Graph)", - "value": "VirtualAppointment.ReadWrite" + "description": "Allow this app to receive information about devices (such as compliance and enrollment state) that are managed by Intune.", + "displayName": "Get device state and compliance information from Microsoft Intune", + "id": "7ec88bad-30c7-4928-a005-4455362cfd98", + "origin": "Application (Microsoft Intune API)", + "value": "get_device_compliance" }, { - "description": "Allows an application to send notifications for virtual appointments for the signed-in user.", - "displayName": "Send notification regarding virtual appointments for the signed-in user", - "id": "20d02fff-a0ef-49e7-a46e-019d4a6523b7", - "origin": "Delegated (Microsoft Graph)", - "value": "VirtualAppointmentNotification.Send" + "description": "Allows the app to send partner compliance policies and its Azure AD Group assignment to Microsoft Intune without a signed-in user.", + "displayName": "Manage partner compliance policies with Microsoft Intune.", + "id": "3857e233-c379-404e-85e9-bdbf3a62b28f", + "origin": "Application (Microsoft Intune API)", + "value": "manage_partner_compliance_policy" }, { "description": "Read PFX certificate requests and send certificates to Microsoft Intune.", @@ -1595,27 +1609,6 @@ "origin": "Application (Microsoft Mixed Reality)", "value": "arrtest.signin" }, - { - "description": "Sign In to Mixed Reality Services", - "displayName": "Signin", - "id": "b24fe742-e2a6-4995-adbf-aba1516932c5", - "origin": "Application (Microsoft Mixed Reality)", - "value": "mixedreality.signin" - }, - { - "description": "Allows the app to send partner compliance policies and its Azure AD Group assignment to Microsoft Intune without a signed-in user.", - "displayName": "Manage partner compliance policies with Microsoft Intune.", - "id": "3857e233-c379-404e-85e9-bdbf3a62b28f", - "origin": "Application (Microsoft Intune API)", - "value": "manage_partner_compliance_policy" - }, - { - "description": "Allow this app to receive information about devices (such as compliance and enrollment state) that are managed by Intune.", - "displayName": "Get device state and compliance information from Microsoft Intune", - "id": "7ec88bad-30c7-4928-a005-4455362cfd98", - "origin": "Application (Microsoft Intune API)", - "value": "get_device_compliance" - }, { "description": "Grants access to the Intune data warehouse API", "displayName": "Get data warehouse information from Microsoft Intune", @@ -1630,6 +1623,34 @@ "origin": "Delegated (Microsoft Intune AAD BitLocker Recovery Key Integration)", "value": "IntuneAADBitLockerRecoveryKey.Read" }, + { + "description": "Allows Intune Admins to enroll a Microsoft Tunnel Gateway Agent", + "displayName": "MicrosoftTunnelGatewayEnrollment", + "id": "e323f13a-1fcc-49cc-883f-c6da13ae0542", + "origin": "Delegated (Microsoft Intune)", + "value": "MicrosoftTunnelGatewayEnrollment" + }, + { + "description": "Read all unified policies a user has access to.", + "displayName": "Read all unified policies a user has access to.", + "id": "34f7024b-1bed-402f-9664-f5316a1e1b4a", + "origin": "Delegated (Microsoft Information Protection Sync Service)", + "value": "UnifiedPolicy.User.Read" + }, + { + "description": "Allows an application to read and write virtual appointments for the signed-in user. Only an organizer or participant user can read and write their virtual appointments. ", + "displayName": "Read and write a user's virtual appointments ", + "id": "2ccc2926-a528-4b17-b8bb-860eed29d64c", + "origin": "Delegated (Microsoft Graph)", + "value": "VirtualAppointment.ReadWrite" + }, + { + "description": "Allows an application to send notifications for virtual appointments for the signed-in user.", + "displayName": "Send notification regarding virtual appointments for the signed-in user", + "id": "20d02fff-a0ef-49e7-a46e-019d4a6523b7", + "origin": "Delegated (Microsoft Graph)", + "value": "VirtualAppointmentNotification.Send" + }, { "description": "Allows the app to read virtual events created by you", "displayName": "Read your virtual events", @@ -1672,6 +1693,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "WorkforceIntegration.ReadWrite.All" }, + { + "description": "Allows the app to read and write password authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' password methods.", + "id": "7f5b683d-df96-4690-a88d-6e336ed6dc7c", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Password.ReadWrite.All" + }, { "description": "Allows the current signed-in user to read Content Domain information.", "displayName": "ContentDomain.Read.All", @@ -1679,20 +1707,6 @@ "origin": "Application (Microsoft Graph Connectors Core)", "value": "ContentDomain.Read.All" }, - { - "description": "Allows the current signed in user to update the Content Domain information", - "displayName": "ContentDomain.ReadWrite", - "id": "6662245d-d5f3-42cb-b401-b08c2f424d5f", - "origin": "Application (Microsoft Graph Connectors Core)", - "value": "ContentDomain.ReadWrite" - }, - { - "description": "Allows the app to read phone authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' phone authentication methods", - "id": "20cf4ae1-09b9-4d29-a6f8-43e1820ce60c", - "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Phone.Read.All" - }, { "description": "Read and Write permission of Content Domain Items into all content domain shards. ", "displayName": "ContentDomainItem.ReadWrite.All", @@ -1700,6 +1714,20 @@ "origin": "Application (Microsoft Graph Connectors Core)", "value": "ContentDomainItem.ReadWrite.All" }, + { + "description": "Read and Write permission of Content Domain Items into the content domain shard owned by the application. ", + "displayName": "ContentDomainItem.ReadWrite.OwnedBy", + "id": "83447e6a-d68b-4373-bd75-efab237f20ba", + "origin": "Application (Microsoft Graph Connectors Core)", + "value": "ContentDomainItem.ReadWrite.OwnedBy" + }, + { + "description": "Allows the current signed in user to update the Content Domain information", + "displayName": "ContentDomain.ReadWrite", + "id": "6662245d-d5f3-42cb-b401-b08c2f424d5f", + "origin": "Delegated (Microsoft Graph Connectors Core)", + "value": "ContentDomain.ReadWrite" + }, { "description": "Read all published labels and label policies for an organization.", "displayName": "InformationProtectionPolicy.Read.All", @@ -1729,46 +1757,39 @@ "value": "UnifiedPolicy.Tenant.Read" }, { - "description": "Read all unified policies a user has access to.", - "displayName": "Read all unified policies a user has access to.", - "id": "34f7024b-1bed-402f-9664-f5316a1e1b4a", - "origin": "Delegated (Microsoft Information Protection Sync Service)", - "value": "UnifiedPolicy.User.Read" - }, - { - "description": "Allows Intune Admins to enroll a Microsoft Tunnel Gateway Agent", - "displayName": "MicrosoftTunnelGatewayEnrollment", - "id": "e323f13a-1fcc-49cc-883f-c6da13ae0542", - "origin": "Delegated (Microsoft Intune)", - "value": "MicrosoftTunnelGatewayEnrollment" + "description": "Allows the app to read and write the signed-in user's password authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's password authentication methods", + "id": "60cce20d-d41e-4594-b391-84bbf8cc31f3", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Password.ReadWrite" }, { - "description": "Read and Write permission of Content Domain Items into the content domain shard owned by the application. ", - "displayName": "ContentDomainItem.ReadWrite.OwnedBy", - "id": "83447e6a-d68b-4373-bd75-efab237f20ba", - "origin": "Application (Microsoft Graph Connectors Core)", - "value": "ContentDomainItem.ReadWrite.OwnedBy" + "description": "Allows the app to read password authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' password authentication methods", + "id": "4f69a4e2-2aa0-43a7-ad6b-98b4cda1f23f", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-Password.Read.All" }, { - "description": "Allows the app to read the signed-in user's phone authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read the signed-in user's phone authentication methods", - "id": "43dab3b9-e8b4-424d-8e13-6a2ad2a625fa", + "description": "Allows the app to read the signed-in user's password authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's password authentication methods", + "id": "7f0f82c3-de19-4ddc-810d-a2206d7637fd", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Phone.Read" + "value": "UserAuthMethod-Password.Read" }, { - "description": "Allows the app to read and write password authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' password methods.", - "id": "7f5b683d-df96-4690-a88d-6e336ed6dc7c", + "description": "Allows the application to list and read all Tenant Governance relationships on behalf of the signed-in user.", + "displayName": "Read Tenant Governance relationships", + "id": "0b1c2458-4845-477b-a704-3cce8b06bf28", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Password.ReadWrite.All" + "value": "TenantGovernance-Relationship.Read.All" }, { - "description": "Allows the app to read and write the signed-in user's password authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write the signed-in user's password authentication methods", - "id": "60cce20d-d41e-4594-b391-84bbf8cc31f3", + "description": "Allows the application to list, read, and update Tenant Governance relationships on behalf of the signed-in user.", + "displayName": "Read and write Tenant Governance relationships", + "id": "3fbcd6a3-a9a5-4d69-8a78-acc7d7195180", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Password.ReadWrite" + "value": "TenantGovernance-Relationship.ReadWrite.All" }, { "description": "Allows the application to list and read all Tenant Governance requests on behalf of the signed-in user.", @@ -1876,46 +1897,46 @@ "value": "ThreatSubmission.ReadWrite.All" }, { - "description": "Allows the app to read your organization's threat submission policies on behalf of the signed-in user. Also allows the app to create new threat submission policies on behalf of the signed-in user.", - "displayName": "Read and write all threat submission policies", - "id": "059e5840-5353-4c68-b1da-666a033fc5e8", + "description": "Allows the application to list, read, and refresh related tenants information on behalf of the signed-in user.", + "displayName": "Read and write related tenants", + "id": "e61db2de-de55-461e-942d-52a028ed1076", "origin": "Delegated (Microsoft Graph)", - "value": "ThreatSubmissionPolicy.ReadWrite.All" + "value": "TenantGovernance-RelatedTenant.ReadWrite.All" }, { - "description": "Allows the app to read topics data on behalf of the signed-in user.", - "displayName": "Read topic items", - "id": "79c4c76f-409a-4f98-884d-e2c09291ec26", + "description": "Allows the application to list and read related tenants information on behalf of the signed-in user.", + "displayName": "Read related tenants", + "id": "9caaca93-f090-4b9a-b4bb-17de251354d4", "origin": "Delegated (Microsoft Graph)", - "value": "Topic.Read.All" + "value": "TenantGovernance-RelatedTenant.Read.All" }, { - "description": "Allows the application to list, read, and update Tenant Governance relationships on behalf of the signed-in user.", - "displayName": "Read and write Tenant Governance relationships", - "id": "3fbcd6a3-a9a5-4d69-8a78-acc7d7195180", + "description": "Allows the application to list, read, create, update, and delete Tenant Governance policy templates on behalf of the signed-in user.", + "displayName": "Read and write Tenant Governance policy templates", + "id": "7cd0bd21-45fe-4c8e-a549-3c95bd27d185", "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-Relationship.ReadWrite.All" + "value": "TenantGovernance-PolicyTemplate.ReadWrite.All" }, { - "description": "Allows the application to list and read all Tenant Governance relationships on behalf of the signed-in user.", - "displayName": "Read Tenant Governance relationships", - "id": "0b1c2458-4845-477b-a704-3cce8b06bf28", + "description": "Allows the application to list and read all Tenant Governance policy templates on behalf of the signed-in user.", + "displayName": "Read Tenant Governance policy templates", + "id": "ad222a15-813d-46b8-8f8d-1976a69a74f3", "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-Relationship.Read.All" + "value": "TenantGovernance-PolicyTemplate.Read.All" }, { - "description": "Allows the application to list, read, and refresh related tenants information on behalf of the signed-in user.", - "displayName": "Read and write related tenants", - "id": "e61db2de-de55-461e-942d-52a028ed1076", + "description": "Allows the app to read and modify your tenant's acquired telephone number details on behalf of the signed-in admin user. Acquired telephone numbers may include attributes related to assigned object, emergency location, network site, etc.", + "displayName": "Read and Modify Tenant-Acquired Telephone Number Details", + "id": "424b07a8-1209-4d17-9fe4-9018a93a1024", "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-RelatedTenant.ReadWrite.All" + "value": "TeamsTelephoneNumber.ReadWrite.All" }, { - "description": "Allows the application to list and read related tenants information on behalf of the signed-in user.", - "displayName": "Read related tenants", - "id": "9caaca93-f090-4b9a-b4bb-17de251354d4", + "description": "Allows the app to read your tenant's user configurations on behalf of the signed-in admin user. User configuration may include attributes related to user, such as telephone number, assigned policies, etc.", + "displayName": "Read Teams user configurations", + "id": "5c469ce4-dab5-4afd-b9de-14f1ba4004a7", "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-RelatedTenant.Read.All" + "value": "TeamsUserConfiguration.Read.All" }, { "description": "Allows the app to read the available Teams templates, on behalf of the signed-in user.", @@ -1959,6 +1980,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "TeamworkCustomEmoji.Read" }, + { + "description": "Allows the app to read your organization's threat submission policies on behalf of the signed-in user. Also allows the app to create new threat submission policies on behalf of the signed-in user.", + "displayName": "Read and write all threat submission policies", + "id": "059e5840-5353-4c68-b1da-666a033fc5e8", + "origin": "Delegated (Microsoft Graph)", + "value": "ThreatSubmissionPolicy.ReadWrite.All" + }, { "description": "Allow the app to read the management data for Teams devices on behalf of the signed-in user.", "displayName": "Read Teams devices", @@ -1966,20 +1994,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "TeamworkDevice.Read.All" }, - { - "description": "Allow the app to read and write the management data for Teams devices on behalf of the signed-in user.", - "displayName": "Read and write Teams devices", - "id": "ddd97ecb-5c31-43db-a235-0ee20e635c40", - "origin": "Delegated (Microsoft Graph)", - "value": "TeamworkDevice.ReadWrite.All" - }, - { - "description": "Allows the app to read trust framework key set properties on behalf of the signed-in user.", - "displayName": "Read trust framework key sets", - "id": "7ad34336-f5b1-44ce-8682-31d7dfcd9ab9", - "origin": "Delegated (Microsoft Graph)", - "value": "TrustFrameworkKeySet.Read.All" - }, { "description": "Allows the app to read the signed-in user's sections (folders) for organizing chats and channels in Teams.", "displayName": "Read your sections", @@ -1987,6 +2001,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "TeamworkSection.Read" }, + { + "description": "Allows the app to read and write the signed-in user's sections (folders) for organizing chats and channels in Teams.", + "displayName": "Read and write your sections", + "id": "70dbe5e8-39b9-40f3-8c65-3ec7b00ad804", + "origin": "Delegated (Microsoft Graph)", + "value": "TeamworkSection.ReadWrite" + }, { "description": "Allows the app to read tags in Teams, on behalf of the signed-in user.", "displayName": "Read tags in Teams", @@ -2030,32 +2051,25 @@ "value": "TenantGovernance-Invitation.ReadWrite.All" }, { - "description": "Allows the application to list and read all Tenant Governance policy templates on behalf of the signed-in user.", - "displayName": "Read Tenant Governance policy templates", - "id": "ad222a15-813d-46b8-8f8d-1976a69a74f3", - "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-PolicyTemplate.Read.All" - }, - { - "description": "Allows the application to list, read, create, update, and delete Tenant Governance policy templates on behalf of the signed-in user.", - "displayName": "Read and write Tenant Governance policy templates", - "id": "7cd0bd21-45fe-4c8e-a549-3c95bd27d185", + "description": "Allow the app to read and write the management data for Teams devices on behalf of the signed-in user.", + "displayName": "Read and write Teams devices", + "id": "ddd97ecb-5c31-43db-a235-0ee20e635c40", "origin": "Delegated (Microsoft Graph)", - "value": "TenantGovernance-PolicyTemplate.ReadWrite.All" + "value": "TeamworkDevice.ReadWrite.All" }, { - "description": "Allows the app to read and write the signed-in user's sections (folders) for organizing chats and channels in Teams.", - "displayName": "Read and write your sections", - "id": "70dbe5e8-39b9-40f3-8c65-3ec7b00ad804", + "description": "Allows the app to read time-based eligibility schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", + "displayName": "Read eligibility schedules for app permission grants and app role assignments", + "id": "9b9eb231-5483-4f3c-89e9-9d5048dafe9d", "origin": "Delegated (Microsoft Graph)", - "value": "TeamworkSection.ReadWrite" + "value": "PrivilegedEligibilitySchedule.Read.EntraAppRole" }, { - "description": "Allows the app to read, create, and delete time-based eligibility schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", - "displayName": "Read, create, and delete eligibility schedules for app permission grants and app role assignments", - "id": "f7ff1cb0-e255-4bb3-b24a-6708c60c5418", + "description": "Allows the app to read topics data on behalf of the signed-in user.", + "displayName": "Read topic items", + "id": "79c4c76f-409a-4f98-884d-e2c09291ec26", "origin": "Delegated (Microsoft Graph)", - "value": "PrivilegedEligibilitySchedule.ReadWrite.EntraAppRole" + "value": "Topic.Read.All" }, { "description": "Allows the app to read and write trust framework key set properties on behalf of the signed-in user.", @@ -2065,11 +2079,18 @@ "value": "TrustFrameworkKeySet.ReadWrite.All" }, { - "description": "Allows the app to create users, on behalf of the signed-in user.", - "displayName": "Create users", - "id": "d8ce6a2a-46ff-438e-96bc-020f23870a55", + "description": "Allows the app to read and write email methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' email methods.", + "id": "074f680f-c89e-45be-880e-5d0642860a1c", "origin": "Delegated (Microsoft Graph)", - "value": "User.Create" + "value": "UserAuthMethod-Email.ReadWrite.All" + }, + { + "description": "Allows the app to read the signed-in user's external authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's external authentication methods", + "id": "d1739827-146b-4f7f-b52c-1c509253aa57", + "origin": "Delegated (Microsoft Graph)", + "value": "UserAuthMethod-External.Read" }, { "description": "Allows the app to read external authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", @@ -2177,46 +2198,46 @@ "value": "UserAuthMethod-Passkey.ReadWrite.All" }, { - "description": "Allows the app to read the signed-in user's password authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read the signed-in user's password authentication methods", - "id": "7f0f82c3-de19-4ddc-810d-a2206d7637fd", + "description": "Allows the app to read and write the signed-in user's email authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write the signed-in user's email authentication methods", + "id": "696aa421-62dc-4c99-be16-015b23444089", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Password.Read" + "value": "UserAuthMethod-Email.ReadWrite" }, { - "description": "Allows the app to read password authentication methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' password authentication methods", - "id": "4f69a4e2-2aa0-43a7-ad6b-98b4cda1f23f", + "description": "Allows the app to read email methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' email methods", + "id": "76caaf3a-ebdb-40a3-9299-4196e636f290", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Password.Read.All" + "value": "UserAuthMethod-Email.Read.All" }, { - "description": "Allows the app to read the signed-in user's external authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read the signed-in user's external authentication methods", - "id": "d1739827-146b-4f7f-b52c-1c509253aa57", + "description": "Allows the app to read the signed-in user's email authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read the signed-in user's email authentication methods", + "id": "12b23cea-90c1-4873-9094-f45c5f290f86", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-External.Read" + "value": "UserAuthMethod-Email.Read" }, { - "description": "Allows the app to read and write email methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' email methods.", - "id": "074f680f-c89e-45be-880e-5d0642860a1c", + "description": " Allows the app to read and write authentication methods of all users in your organization that the signed-in user has access to. Authentication methods include things like a user's phone numbers and Authenticator app settings. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' authentication methods", + "id": "b7887744-6746-4312-813d-72daeaee7e2d", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Email.ReadWrite.All" + "value": "UserAuthenticationMethod.ReadWrite.All" }, { - "description": "Allows the app to read and write the signed-in user's email authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write the signed-in user's email authentication methods", - "id": "696aa421-62dc-4c99-be16-015b23444089", + "description": "Allows the app to read basic unified group properties, memberships and owners of the group the signed-in guest is a member of.", + "displayName": "Read unified group memberships as guest", + "id": "73e75199-7c3e-41bb-9357-167164dbb415", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Email.ReadWrite" + "value": "UnifiedGroupMember.Read.AsGuest" }, { - "description": "Allows the app to read email methods of all users in your organization that the signed-in user has access to. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' email methods", - "id": "76caaf3a-ebdb-40a3-9299-4196e636f290", + "description": "Allows the app to create users, on behalf of the signed-in user.", + "displayName": "Create users", + "id": "d8ce6a2a-46ff-438e-96bc-020f23870a55", "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Email.Read.All" + "value": "User.Create" }, { "description": "Allows the app to delete and restore all users, on behalf of the signed-in user.", @@ -2260,6 +2281,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "User.Read" }, + { + "description": "Allows the app to read trust framework key set properties on behalf of the signed-in user.", + "displayName": "Read trust framework key sets", + "id": "7ad34336-f5b1-44ce-8682-31d7dfcd9ab9", + "origin": "Delegated (Microsoft Graph)", + "value": "TrustFrameworkKeySet.Read.All" + }, { "description": "Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user.", "displayName": "Read all users' full profiles", @@ -2267,20 +2295,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "User.Read.All" }, - { - "description": "Allows the app to read a basic set of profile properties of other users in your organization on behalf of the signed-in user. This includes display name, first and last name, email address and photo.", - "displayName": "Read all users' basic profiles", - "id": "b340eb25-3456-403f-be2f-af7a0d370277", - "origin": "Delegated (Microsoft Graph)", - "value": "User.ReadBasic.All" - }, - { - "description": "Allows the app to read basic unified group properties, memberships and owners of the group the signed-in guest is a member of.", - "displayName": "Read unified group memberships as guest", - "id": "73e75199-7c3e-41bb-9357-167164dbb415", - "origin": "Delegated (Microsoft Graph)", - "value": "UnifiedGroupMember.Read.AsGuest" - }, { "description": "Allows the app to read and update users, on behalf of the signed-in user.", "displayName": "Read and update users", @@ -2288,6 +2302,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "User.ReadUpdate.All" }, + { + "description": "Allows the app to read your profile. It also allows the app to update your profile information on your behalf.", + "displayName": "Read and write access to user profile", + "id": "b4e74841-8e56-480b-be8b-910348b18b4c", + "origin": "Delegated (Microsoft Graph)", + "value": "User.ReadWrite" + }, { "description": "Allows the app to read and write the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user.", "displayName": "Read and write all users' full profiles", @@ -2331,32 +2352,11 @@ "value": "UserAuthenticationMethod.ReadWrite" }, { - "description": " Allows the app to read and write authentication methods of all users in your organization that the signed-in user has access to. Authentication methods include things like a user's phone numbers and Authenticator app settings. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' authentication methods", - "id": "b7887744-6746-4312-813d-72daeaee7e2d", - "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthenticationMethod.ReadWrite.All" - }, - { - "description": "Allows the app to read the signed-in user's email authentication methods. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read the signed-in user's email authentication methods", - "id": "12b23cea-90c1-4873-9094-f45c5f290f86", - "origin": "Delegated (Microsoft Graph)", - "value": "UserAuthMethod-Email.Read" - }, - { - "description": "Allows the app to read your profile. It also allows the app to update your profile information on your behalf.", - "displayName": "Read and write access to user profile", - "id": "b4e74841-8e56-480b-be8b-910348b18b4c", - "origin": "Delegated (Microsoft Graph)", - "value": "User.ReadWrite" - }, - { - "description": "Allows the app to read, create, and delete time-based eligibility schedules for access to Azure AD groups, on behalf of the signed-in user.", - "displayName": "Read, create, and delete eligibility schedules for access to Azure AD groups", - "id": "ba974594-d163-484e-ba39-c330d5897667", + "description": "Allows the app to read a basic set of profile properties of other users in your organization on behalf of the signed-in user. This includes display name, first and last name, email address and photo.", + "displayName": "Read all users' basic profiles", + "id": "b340eb25-3456-403f-be2f-af7a0d370277", "origin": "Delegated (Microsoft Graph)", - "value": "PrivilegedEligibilitySchedule.ReadWrite.AzureADGroup" + "value": "User.ReadBasic.All" }, { "description": "Allows the app to read time-based eligibility schedules for access to Azure AD groups, on behalf of the signed-in user.", @@ -2366,18 +2366,18 @@ "value": "PrivilegedEligibilitySchedule.Read.AzureADGroup" }, { - "description": "Allows the application to manage file storage container type registrations on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", - "displayName": "Manage file storage container type registrations on behalf of the signed in user", - "id": "c319a7df-930e-44c0-a43b-7e5e9c7f4f24", + "description": "Allows the app to delete time-based assignment schedules for access to Azure AD groups, on behalf of the signed-in user.", + "displayName": "Delete assignment schedules for access to Azure AD groups", + "id": "ca5fe595-68ff-4dfd-907d-4509501a0e49", "origin": "Delegated (Microsoft Graph)", - "value": "FileStorageContainerTypeReg.Manage.All" + "value": "PrivilegedAssignmentSchedule.Remove.AzureADGroup" }, { - "description": "Allows the application to manage selected file storage container type registrations on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", - "displayName": "Access selected file storage container type registrations.", - "id": "d1e4f63a-1569-475c-b9b2-bdc140405e38", + "description": "Allows the app to read, create, and delete time-based assignment schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", + "displayName": "Read, create, and delete assignment schedules for app permission grants and app role assignments", + "id": "e07122a7-d275-4a27-a2f5-eb62349edae0", "origin": "Delegated (Microsoft Graph)", - "value": "FileStorageContainerTypeReg.Selected" + "value": "PrivilegedAssignmentSchedule.ReadWrite.EntraAppRole" }, { "description": "Allows the app to read and write financials data on behalf of the signed-in user.", @@ -2484,13 +2484,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "Group-XTenantIdentitySync.Read.All" }, - { - "description": "Allows the application to manage file storage container types on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", - "displayName": "Manage file storage container types on behalf of the signed in user", - "id": "8e6ec84c-5fcd-4cc7-ac8a-2296efc0ed9b", - "origin": "Delegated (Microsoft Graph)", - "value": "FileStorageContainerType.Manage.All" - }, { "description": "Allows the app to read all scenario health monitoring alerts", "displayName": "Read all scenario health monitoring alerts", @@ -2499,32 +2492,39 @@ "value": "HealthMonitoringAlert.Read.All" }, { - "description": "Allows the application to utilize the file storage container platform to manage containers on behalf of the signed in user. The specific file storage containers and the permissions granted to them will be configured in Microsoft 365 by the developer of each container type.", - "displayName": "Access selected file storage containers", - "id": "085ca537-6565-41c2-aca7-db852babc212", + "description": "Allows the app to read and write all scenario monitoring alerts, on behalf of the signed-in user.", + "displayName": "Read and write all scenario monitoring alerts", + "id": "b7c60f27-2195-4d5f-96a7-6b98bdfd9664", "origin": "Delegated (Microsoft Graph)", - "value": "FileStorageContainer.Selected" + "value": "HealthMonitoringAlert.ReadWrite.All" }, { - "description": "Allow the application to access files explicitly permissioned to the application on behalf of the signed in user. The specific files and the permissions granted will be configured in SharePoint Online or OneDrive.", - "displayName": "Access selected Files, on behalf of the signed-in user", - "id": "ef2779dc-ef1b-4211-8310-8a0ac2450081", + "description": "Allows the application to manage selected file storage container type registrations on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", + "displayName": "Access selected file storage container type registrations.", + "id": "d1e4f63a-1569-475c-b9b2-bdc140405e38", "origin": "Delegated (Microsoft Graph)", - "value": "Files.SelectedOperations.Selected" + "value": "FileStorageContainerTypeReg.Selected" }, { - "description": "Allows the app to search the email message trace on behalf of the signed-in user.", - "displayName": "Search the email message trace", - "id": "b2e7d27e-14e7-41ad-bb15-a88ceb9c3e90", + "description": "Allows the app to read all scenario health monitoring alert configurations", + "displayName": "Read all scenario health monitoring alert configurations", + "id": "fb873030-8626-47e6-96ff-8a5bff3b725f", "origin": "Delegated (Microsoft Graph)", - "value": "ExchangeMessageTrace.Read.All" + "value": "HealthMonitoringAlertConfig.Read.All" }, { - "description": "Allows the app to read all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", - "displayName": "Read all external connections", - "id": "a38267a5-26b6-4d76-9493-935b7599116b", + "description": "Allows the application to manage file storage container type registrations on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", + "displayName": "Manage file storage container type registrations on behalf of the signed in user", + "id": "c319a7df-930e-44c0-a43b-7e5e9c7f4f24", + "origin": "Delegated (Microsoft Graph)", + "value": "FileStorageContainerTypeReg.Manage.All" + }, + { + "description": "Allows the application to utilize the file storage container platform to manage containers on behalf of the signed in user. The specific file storage containers and the permissions granted to them will be configured in Microsoft 365 by the developer of each container type.", + "displayName": "Access selected file storage containers", + "id": "085ca537-6565-41c2-aca7-db852babc212", "origin": "Delegated (Microsoft Graph)", - "value": "ExternalConnection.Read.All" + "value": "FileStorageContainer.Selected" }, { "description": "Allows the app to read and write all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", @@ -2631,6 +2631,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "Files.ReadWrite.Selected" }, + { + "description": "Allow the application to access files explicitly permissioned to the application on behalf of the signed in user. The specific files and the permissions granted will be configured in SharePoint Online or OneDrive.", + "displayName": "Access selected Files, on behalf of the signed-in user", + "id": "ef2779dc-ef1b-4211-8310-8a0ac2450081", + "origin": "Delegated (Microsoft Graph)", + "value": "Files.SelectedOperations.Selected" + }, { "description": "Allows the application to utilize the file storage container administration capabilities on behalf of an administrator user.", "displayName": "Manage all file storage containers", @@ -2639,18 +2646,11 @@ "value": "FileStorageContainer.Manage.All" }, { - "description": "Allows the app to read and write all scenario monitoring alerts, on behalf of the signed-in user.", - "displayName": "Read and write all scenario monitoring alerts", - "id": "b7c60f27-2195-4d5f-96a7-6b98bdfd9664", - "origin": "Delegated (Microsoft Graph)", - "value": "HealthMonitoringAlert.ReadWrite.All" - }, - { - "description": "Allows the app to read all scenario health monitoring alert configurations", - "displayName": "Read all scenario health monitoring alert configurations", - "id": "fb873030-8626-47e6-96ff-8a5bff3b725f", + "description": "Allows the application to manage file storage container types on behalf of the signed in user. The user must be a SharePoint Embedded Admin or Global Admin.", + "displayName": "Manage file storage container types on behalf of the signed in user", + "id": "8e6ec84c-5fcd-4cc7-ac8a-2296efc0ed9b", "origin": "Delegated (Microsoft Graph)", - "value": "HealthMonitoringAlertConfig.Read.All" + "value": "FileStorageContainerType.Manage.All" }, { "description": "Allows the app to read and write all scenario monitoring alert configurations, on behalf of the signed-in user.", @@ -2660,18 +2660,18 @@ "value": "HealthMonitoringAlertConfig.ReadWrite.All" }, { - "description": "Allows the app to upload data files to a data connector on behalf of the signed-in user.", - "displayName": "Upload files to a data connector", - "id": "fc47391d-ab2c-410f-9059-5600f7af660d", + "description": "Allows the app to read own identity diagnostics information, including symptoms, runs, statuses, and results for the signed-in user", + "displayName": "Read your identity diagnostics", + "id": "3839e465-e636-4c8e-b959-340182fb0567", "origin": "Delegated (Microsoft Graph)", - "value": "IndustryData-DataConnector.Upload" + "value": "IdentityDiagnostic.Read" }, { - "description": "Allows the app to read inbound data flows on behalf of the signed-in user.", - "displayName": "View inbound flow definitions", - "id": "cb0774da-a605-42af-959c-32f438fb38f4", + "description": "Allows the app to read all identity diagnostics information, including symptoms, runs, statuses, and results for all users in the organization, on behalf of the signed-in user.", + "displayName": "Read all identity diagnostics", + "id": "9181fb3f-4b8e-45ef-98ae-41774b813b80", "origin": "Delegated (Microsoft Graph)", - "value": "IndustryData-InboundFlow.Read.All" + "value": "IdentityDiagnostic.Read.All" }, { "description": "Allows the app to read and write inbound data flows on behalf of the signed-in user.", @@ -2779,46 +2779,46 @@ "value": "LearningAssignedCourse.Read" }, { - "description": "Allows the app to read and write data connectors on behalf of the signed-in user.", - "displayName": "Manage data connector definitions", - "id": "5ce933ac-3997-4280-aed0-cc072e5c062a", + "description": "Allows the app to read learning content in the organization's directory, on behalf of the signed-in user.", + "displayName": "Read learning content", + "id": "ea4c1fd9-6a9f-4432-8e5d-86e06cc0da77", "origin": "Delegated (Microsoft Graph)", - "value": "IndustryData-DataConnector.ReadWrite.All" + "value": "LearningContent.Read.All" }, { - "description": "Allows the app to read data connectors on behalf of the signed-in user.", - "displayName": "View data connector definitions", - "id": "d19c0de5-7ecb-4aba-b090-da35ebcd5425", + "description": "Allows the app to manage learning content in the organization's directory, on behalf of the signed-in user.", + "displayName": "Manage learning content", + "id": "53cec1c4-a65f-4981-9dc1-ad75dbf1c077", "origin": "Delegated (Microsoft Graph)", - "value": "IndustryData-DataConnector.Read.All" + "value": "LearningContent.ReadWrite.All" }, { - "description": "Allows the app to read basic Industry Data service and resource information on behalf of the signed-in user.", - "displayName": "Read basic Industry Data service and resource definitions", - "id": "60382b96-1f5e-46ea-a544-0407e489e588", + "description": "Allows the app to read inbound data flows on behalf of the signed-in user.", + "displayName": "View inbound flow definitions", + "id": "cb0774da-a605-42af-959c-32f438fb38f4", "origin": "Delegated (Microsoft Graph)", - "value": "IndustryData.ReadBasic.All" + "value": "IndustryData-InboundFlow.Read.All" }, { - "description": "Allows the app to have the same access to mailboxes as the signed-in user via IMAP protocol.", - "displayName": "Read and write access to mailboxes via IMAP.", - "id": "652390e4-393a-48de-9484-05f9b1212954", + "description": "Allows the app to upload data files to a data connector on behalf of the signed-in user.", + "displayName": "Upload files to a data connector", + "id": "fc47391d-ab2c-410f-9059-5600f7af660d", "origin": "Delegated (Microsoft Graph)", - "value": "IMAP.AccessAsUser.All" + "value": "IndustryData-DataConnector.Upload" }, { - "description": "Allows the app to read own identity diagnostics information, including symptoms, runs, statuses, and results for the signed-in user", - "displayName": "Read your identity diagnostics", - "id": "3839e465-e636-4c8e-b959-340182fb0567", + "description": "Allows the app to read and write data connectors on behalf of the signed-in user.", + "displayName": "Manage data connector definitions", + "id": "5ce933ac-3997-4280-aed0-cc072e5c062a", "origin": "Delegated (Microsoft Graph)", - "value": "IdentityDiagnostic.Read" + "value": "IndustryData-DataConnector.ReadWrite.All" }, { - "description": "Allows the app to read all identity diagnostics information, including symptoms, runs, statuses, and results for all users in the organization, on behalf of the signed-in user.", - "displayName": "Read all identity diagnostics", - "id": "9181fb3f-4b8e-45ef-98ae-41774b813b80", + "description": "Allows the app to read data connectors on behalf of the signed-in user.", + "displayName": "View data connector definitions", + "id": "d19c0de5-7ecb-4aba-b090-da35ebcd5425", "origin": "Delegated (Microsoft Graph)", - "value": "IdentityDiagnostic.Read.All" + "value": "IndustryData-DataConnector.Read.All" }, { "description": "Allows the app to start identity diagnostic processes for the signed-in user.", @@ -2862,13 +2862,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "IdentityProvider.ReadWrite.All" }, - { - "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange Web Services.", - "displayName": "Access mailboxes as the signed-in user via Exchange Web Services", - "id": "9769c687-087d-48ac-9cb3-c37dde652038", - "origin": "Delegated (Microsoft Graph)", - "value": "EWS.AccessAsUser.All" - }, { "description": "Allows the app to read identity risk event information for all users in your organization on behalf of the signed-in user.", "displayName": "Read identity risk event information", @@ -2876,6 +2869,20 @@ "origin": "Delegated (Microsoft Graph)", "value": "IdentityRiskEvent.Read.All" }, + { + "description": "Allows the app to read and update identity risk event information for all users in your organization on behalf of the signed-in user. Update operations include confirming risk event detections. ", + "displayName": "Read and write risk event information", + "id": "9e4862a5-b68f-479e-848a-4e07e25c9916", + "origin": "Delegated (Microsoft Graph)", + "value": "IdentityRiskEvent.ReadWrite.All" + }, + { + "description": "Allows the app to read all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", + "displayName": "Read all external connections", + "id": "a38267a5-26b6-4d76-9493-935b7599116b", + "origin": "Delegated (Microsoft Graph)", + "value": "ExternalConnection.Read.All" + }, { "description": "Allows the app to read risky agents information in your organization, on behalf of the signed-in user.", "displayName": "Read risky agents information", @@ -2883,13 +2890,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "IdentityRiskyAgent.Read.All" }, - { - "description": "Allows the app to read and update identity risky agents information for all agents in your organization on behalf of the signed-in user. Update operations include dismissing risky agents.", - "displayName": "Read and write risky agents information", - "id": "d343bdeb-db6a-4e06-97da-9dafc2d61c60", - "origin": "Delegated (Microsoft Graph)", - "value": "IdentityRiskyAgent.ReadWrite.All" - }, { "description": "Allows the app to read all identity risky service principal information for your organization, on behalf of the signed-in user.", "displayName": "Read all identity risky service principal information", @@ -2933,46 +2933,46 @@ "value": "IdentityUserFlow.ReadWrite.All" }, { - "description": "Allows the app to read and update identity risk event information for all users in your organization on behalf of the signed-in user. Update operations include confirming risk event detections. ", - "displayName": "Read and write risk event information", - "id": "9e4862a5-b68f-479e-848a-4e07e25c9916", + "description": "Allows the app to have the same access to mailboxes as the signed-in user via IMAP protocol.", + "displayName": "Read and write access to mailboxes via IMAP.", + "id": "652390e4-393a-48de-9484-05f9b1212954", "origin": "Delegated (Microsoft Graph)", - "value": "IdentityRiskEvent.ReadWrite.All" + "value": "IMAP.AccessAsUser.All" }, { - "description": "Allows the app to read learning content in the organization's directory, on behalf of the signed-in user.", - "displayName": "Read learning content", - "id": "ea4c1fd9-6a9f-4432-8e5d-86e06cc0da77", + "description": "Allows the app to read basic Industry Data service and resource information on behalf of the signed-in user.", + "displayName": "Read basic Industry Data service and resource definitions", + "id": "60382b96-1f5e-46ea-a544-0407e489e588", "origin": "Delegated (Microsoft Graph)", - "value": "LearningContent.Read.All" + "value": "IndustryData.ReadBasic.All" }, { - "description": "Allows the app to read or write your organization's authentication event listeners on behalf of the signed-in user.", - "displayName": "Read and write your organization's authentication event listeners", - "id": "d11625a6-fe21-4fc6-8d3d-063eba5525ad", + "description": "Allows the app to read and update identity risky agents information for all agents in your organization on behalf of the signed-in user. Update operations include dismissing risky agents.", + "displayName": "Read and write risky agents information", + "id": "d343bdeb-db6a-4e06-97da-9dafc2d61c60", "origin": "Delegated (Microsoft Graph)", - "value": "EventListener.ReadWrite.All" + "value": "IdentityRiskyAgent.ReadWrite.All" }, { - "description": "Allows the app to list the all the snapshots, create a recovery job and enumerate the changes of a specific recovery job, on behalf of the signed-in user.", - "displayName": "Create preview and recovery job, read recovery job and snapshots", - "id": "8269c6ff-41d7-4172-a783-b2ce38322e42", + "description": "Allows the app to search the email message trace on behalf of the signed-in user.", + "displayName": "Search the email message trace", + "id": "b2e7d27e-14e7-41ad-bb15-a88ceb9c3e90", "origin": "Delegated (Microsoft Graph)", - "value": "EntraBackup.ReadWrite.Recovery" + "value": "ExchangeMessageTrace.Read.All" }, { - "description": "Allows the app to create device objects based on device templates owned by the signed-in user, on behalf of the signed in user.", - "displayName": "Create devices based on owned device templates", - "id": "edc92e89-a987-48a9-911a-a7b1967dd7b1", + "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange Web Services.", + "displayName": "Access mailboxes as the signed-in user via Exchange Web Services", + "id": "9769c687-087d-48ac-9cb3-c37dde652038", "origin": "Delegated (Microsoft Graph)", - "value": "Device.CreateFromOwnedTemplate" + "value": "EWS.AccessAsUser.All" }, { - "description": "Allows the app to read a user's list of devices on behalf of the signed-in user.", - "displayName": "Read user devices", - "id": "11d4cd79-5ba5-460f-803f-e22c8ab85ccd", + "description": "Allows the app to read or write your organization's authentication event listeners on behalf of the signed-in user.", + "displayName": "Read and write your organization's authentication event listeners", + "id": "d11625a6-fe21-4fc6-8d3d-063eba5525ad", "origin": "Delegated (Microsoft Graph)", - "value": "Device.Read" + "value": "EventListener.ReadWrite.All" }, { "description": "Allows the app to read your organization's devices' configuration information on behalf of the signed-in user.", @@ -3079,13 +3079,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "DeviceManagementRBAC.Read.All" }, - { - "description": "Allows the app to launch another app or communicate with another app on a user's device on behalf of the signed-in user.", - "displayName": "Communicate with user devices", - "id": "bac3b9c2-b516-4ef4-bd3b-c2ef73d8d804", - "origin": "Delegated (Microsoft Graph)", - "value": "Device.Command" - }, { "description": "Allows the app to read and write the properties relating to the Microsoft Intune Role-Based Access Control (RBAC) settings.", "displayName": "Read and write Microsoft Intune RBAC settings", @@ -3094,25 +3087,39 @@ "value": "DeviceManagementRBAC.ReadWrite.All" }, { - "description": "Allows the app to manage permission grants for delegated permissions exposed by any API (including Microsoft Graph), on behalf of the signed in user.", - "displayName": "Manage all delegated permission grants", - "id": "41ce6ca6-6826-4807-84f1-1c82854f7ee5", + "description": "Allows the app to read Microsoft Intune device compliance scripts, device management scripts, device shell scripts, device custom attribute shell scripts and device health scripts on behalf of the signed in user.", + "displayName": "Read Microsoft Intune Scripts", + "id": "d32381d8-ee89-4220-9c83-b672aa68d404", "origin": "Delegated (Microsoft Graph)", - "value": "DelegatedPermissionGrant.ReadWrite.All" + "value": "DeviceManagementScripts.Read.All" }, { - "description": "Allows the app to manage (create-update-terminate) Delegated Admin relationships with customers as well as role assignments to security groups for active Delegated Admin relationships on behalf of the signed-in user.", - "displayName": "Manage Delegated Admin relationships with customers", - "id": "885f682f-a990-4bad-a642-36736a74b0c7", + "description": "Allows the app to read a user's list of devices on behalf of the signed-in user.", + "displayName": "Read user devices", + "id": "11d4cd79-5ba5-460f-803f-e22c8ab85ccd", "origin": "Delegated (Microsoft Graph)", - "value": "DelegatedAdminRelationship.ReadWrite.All" + "value": "Device.Read" }, { - "description": "Allows the application to list and query any shared user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant on behalf of the signed-in user.", - "displayName": "Read all shared cross-tenant user profiles and export their data", - "id": "759dcd16-3c90-463c-937e-abf89f991c18", + "description": "Allows the app to create device objects based on device templates owned by the signed-in user, on behalf of the signed in user.", + "displayName": "Create devices based on owned device templates", + "id": "edc92e89-a987-48a9-911a-a7b1967dd7b1", "origin": "Delegated (Microsoft Graph)", - "value": "CrossTenantUserProfileSharing.Read.All" + "value": "Device.CreateFromOwnedTemplate" + }, + { + "description": "Allows the app to launch another app or communicate with another app on a user's device on behalf of the signed-in user.", + "displayName": "Communicate with user devices", + "id": "bac3b9c2-b516-4ef4-bd3b-c2ef73d8d804", + "origin": "Delegated (Microsoft Graph)", + "value": "Device.Command" + }, + { + "description": "Allows the app to manage permission grants for delegated permissions exposed by any API (including Microsoft Graph), on behalf of the signed in user.", + "displayName": "Manage all delegated permission grants", + "id": "41ce6ca6-6826-4807-84f1-1c82854f7ee5", + "origin": "Delegated (Microsoft Graph)", + "value": "DelegatedPermissionGrant.ReadWrite.All" }, { "description": "Allows the application to list and query user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export and remove external user data (e.g. customer content or system-generated logs), associated with the current tenant on behalf of the signed-in user.", @@ -3170,6 +3177,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "CustomSecAttributeAssignment.ReadWrite.All" }, + { + "description": "Allows the app to read and write Microsoft Intune device compliance scripts, device management scripts, device shell scripts, device custom attribute shell scripts and device health scripts on behalf of the signed in user.", + "displayName": "Read and write Microsoft Intune Scripts", + "id": "8b9d79d0-ad75-4566-8619-f7500ecfcebe", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementScripts.ReadWrite.All" + }, { "description": "Allows the app to read audit logs for events that contain information about custom security attributes, on behalf of the signed-in user.", "displayName": "Read custom security attribute audit logs", @@ -3177,13 +3191,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "CustomSecAttributeAuditLogs.Read.All" }, - { - "description": "Allows the app to read custom security attribute definitions for the tenant on behalf of a signed in user.", - "displayName": "Read custom security attribute definitions", - "id": "ce026878-a0ff-4745-a728-d4fedd086c07", - "origin": "Delegated (Microsoft Graph)", - "value": "CustomSecAttributeDefinition.Read.All" - }, { "description": "Allows the app to read and write custom security attribute definitions for the tenant on behalf of a signed in user.", "displayName": "Read and write custom security attribute definitions", @@ -3226,6 +3233,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "DelegatedAdminRelationship.Read.All" }, + { + "description": "Allows the app to manage (create-update-terminate) Delegated Admin relationships with customers as well as role assignments to security groups for active Delegated Admin relationships on behalf of the signed-in user.", + "displayName": "Manage Delegated Admin relationships with customers", + "id": "885f682f-a990-4bad-a642-36736a74b0c7", + "origin": "Delegated (Microsoft Graph)", + "value": "DelegatedAdminRelationship.ReadWrite.All" + }, { "description": "Allows the app to read delegated permission grants, on behalf of the signed in user.", "displayName": "Read delegated permission grants", @@ -3234,39 +3248,32 @@ "value": "DelegatedPermissionGrant.Read.All" }, { - "description": "Allows the app to read Microsoft Intune device compliance scripts, device management scripts, device shell scripts, device custom attribute shell scripts and device health scripts on behalf of the signed in user.", - "displayName": "Read Microsoft Intune Scripts", - "id": "d32381d8-ee89-4220-9c83-b672aa68d404", - "origin": "Delegated (Microsoft Graph)", - "value": "DeviceManagementScripts.Read.All" - }, - { - "description": "Allows the app to read and write Microsoft Intune device compliance scripts, device management scripts, device shell scripts, device custom attribute shell scripts and device health scripts on behalf of the signed in user.", - "displayName": "Read and write Microsoft Intune Scripts", - "id": "8b9d79d0-ad75-4566-8619-f7500ecfcebe", + "description": "Allows the app to read custom security attribute definitions for the tenant on behalf of a signed in user.", + "displayName": "Read custom security attribute definitions", + "id": "ce026878-a0ff-4745-a728-d4fedd086c07", "origin": "Delegated (Microsoft Graph)", - "value": "DeviceManagementScripts.ReadWrite.All" + "value": "CustomSecAttributeDefinition.Read.All" }, { - "description": "Allows the app to read Microsoft Intune service properties including device enrollment and third party service connection configuration.", - "displayName": "Read Microsoft Intune configuration", - "id": "8696daa5-bce5-4b2e-83f9-51b6defc4e1e", + "description": "Allows the app to read data for the learning provider in the organization's directory, on behalf of the signed-in user.", + "displayName": "Read learning provider", + "id": "dd8ce36f-9245-45ea-a99e-8ac398c22861", "origin": "Delegated (Microsoft Graph)", - "value": "DeviceManagementServiceConfig.Read.All" + "value": "LearningProvider.Read" }, { - "description": "Allows the app to read the user's modules and resources on behalf of the signed-in user.", - "displayName": "Read the user's class modules and resources", - "id": "484859e8-b9e2-4e92-b910-84db35dadd29", + "description": "Allows the app to read Microsoft Intune service properties including device enrollment and third party service connection configuration.", + "displayName": "Read Microsoft Intune configuration", + "id": "8696daa5-bce5-4b2e-83f9-51b6defc4e1e", "origin": "Delegated (Microsoft Graph)", - "value": "EduCurricula.Read" + "value": "DeviceManagementServiceConfig.Read.All" }, { - "description": "Allows the app to read and write user's modules and resources on behalf of the signed-in user.", - "displayName": "Read and write the user's class modules and resources", - "id": "4793c53b-df34-44fd-8d26-d15c517732f5", + "description": "Allows the app to create device templates on behalf of the signed in user. The user is marked as owners of the created device template. As a member of owners, the user will be allowed to manage devices created from the template.", + "displayName": "Create device templates", + "id": "0b1717ff-3e42-4a73-8c29-e6b2e1093960", "origin": "Delegated (Microsoft Graph)", - "value": "EduCurricula.ReadWrite" + "value": "DeviceTemplate.Create" }, { "description": "Allows the app to read the structure of schools and classes in an organization's roster and education-specific information about users to be read on behalf of the user.", @@ -3374,46 +3381,46 @@ "value": "EntraBackup.ReadWrite.Preview" }, { - "description": "Allows the app to read and write assignments without grades on behalf of the user.", - "displayName": "Read and write users' class assignments without grades", - "id": "2ef770a1-622a-47c4-93ee-28d6adbed3a0", + "description": "Allows the app to list the all the snapshots, create a recovery job and enumerate the changes of a specific recovery job, on behalf of the signed-in user.", + "displayName": "Create preview and recovery job, read recovery job and snapshots", + "id": "8269c6ff-41d7-4172-a783-b2ce38322e42", "origin": "Delegated (Microsoft Graph)", - "value": "EduAssignments.ReadWriteBasic" + "value": "EntraBackup.ReadWrite.Recovery" }, { - "description": "Allows the app to read and write assignments and their grades on behalf of the user.", - "displayName": "Read and write users' class assignments and their grades", - "id": "2f233e90-164b-4501-8bce-31af2559a2d3", + "description": "Allows the app to read your organization's authentication event listeners on behalf of the signed-in user.", + "displayName": "Read your organization's authentication event listeners", + "id": "f7dd3bed-5eec-48da-bc73-1c0ef50bc9a1", "origin": "Delegated (Microsoft Graph)", - "value": "EduAssignments.ReadWrite" + "value": "EventListener.Read.All" }, { - "description": "Allows the app to read assignments without grades on behalf of the user.", - "displayName": "Read users' class assignments without grades", - "id": "c0b0103b-c053-4b2e-9973-9f3a544ec9b8", + "description": "Allows the app to read and write user's modules and resources on behalf of the signed-in user.", + "displayName": "Read and write the user's class modules and resources", + "id": "4793c53b-df34-44fd-8d26-d15c517732f5", "origin": "Delegated (Microsoft Graph)", - "value": "EduAssignments.ReadBasic" + "value": "EduCurricula.ReadWrite" }, { - "description": "Allows the app to read assignments and their grades on behalf of the user.", - "displayName": "Read users' class assignments and their grades", - "id": "091460c9-9c4a-49b2-81ef-1f3d852acce2", + "description": "Allows the app to read the user's modules and resources on behalf of the signed-in user.", + "displayName": "Read the user's class modules and resources", + "id": "484859e8-b9e2-4e92-b910-84db35dadd29", "origin": "Delegated (Microsoft Graph)", - "value": "EduAssignments.Read" + "value": "EduCurricula.Read" }, { - "description": "Allows the app to read and write Microsoft Intune service properties including device enrollment and third party service connection configuration.", - "displayName": "Read and write Microsoft Intune configuration", - "id": "662ed50a-ac44-4eef-ad86-62eed9be2a29", + "description": "Allows the app to read and write assignments without grades on behalf of the user.", + "displayName": "Read and write users' class assignments without grades", + "id": "2ef770a1-622a-47c4-93ee-28d6adbed3a0", "origin": "Delegated (Microsoft Graph)", - "value": "DeviceManagementServiceConfig.ReadWrite.All" + "value": "EduAssignments.ReadWriteBasic" }, { - "description": "Allows the app to create device templates on behalf of the signed in user. The user is marked as owners of the created device template. As a member of owners, the user will be allowed to manage devices created from the template.", - "displayName": "Create device templates", - "id": "0b1717ff-3e42-4a73-8c29-e6b2e1093960", + "description": "Allows the app to read and write assignments and their grades on behalf of the user.", + "displayName": "Read and write users' class assignments and their grades", + "id": "2f233e90-164b-4501-8bce-31af2559a2d3", "origin": "Delegated (Microsoft Graph)", - "value": "DeviceTemplate.Create" + "value": "EduAssignments.ReadWrite" }, { "description": "Allows the app to read all device templates, on behalf of the signed in user.", @@ -3457,13 +3464,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "DirectoryRecommendations.Read.All" }, - { - "description": "Allows the app to read your organization's authentication event listeners on behalf of the signed-in user.", - "displayName": "Read your organization's authentication event listeners", - "id": "f7dd3bed-5eec-48da-bc73-1c0ef50bc9a1", - "origin": "Delegated (Microsoft Graph)", - "value": "EventListener.Read.All" - }, { "description": "Allows the app to read and update Azure AD recommendations, on behalf of the signed-in user.", "displayName": "Read and update Azure AD recommendations", @@ -3471,6 +3471,20 @@ "origin": "Delegated (Microsoft Graph)", "value": "DirectoryRecommendations.ReadWrite.All" }, + { + "description": "Allows the app to read all domain properties on behalf of the signed-in user.", + "displayName": "Read domains.", + "id": "2f9ee017-59c1-4f1d-9472-bd5529a7b311", + "origin": "Delegated (Microsoft Graph)", + "value": "Domain.Read.All" + }, + { + "description": "Allows the app to read and write Microsoft Intune service properties including device enrollment and third party service connection configuration.", + "displayName": "Read and write Microsoft Intune configuration", + "id": "662ed50a-ac44-4eef-ad86-62eed9be2a29", + "origin": "Delegated (Microsoft Graph)", + "value": "DeviceManagementServiceConfig.ReadWrite.All" + }, { "description": "Allows the app to read and write all domain properties on behalf of the signed-in user. Also allows the app to add, verify and remove domains.", "displayName": "Read and write domains", @@ -3478,13 +3492,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "Domain.ReadWrite.All" }, - { - "description": "Allows the app to read internal federation configuration for a domain.", - "displayName": "Read internal federation configuration for a domain.", - "id": "33203a2a-a761-40f0-8a7c-a7e74a9f8ac6", - "origin": "Delegated (Microsoft Graph)", - "value": "Domain-InternalFederation.Read.All" - }, { "description": "Allows the app to create, read, update and delete internal federation configuration for a domain.", "displayName": "Create, read, update and delete internal federation configuration for a domain.", @@ -3528,25 +3535,32 @@ "value": "EduAdministration.ReadWrite" }, { - "description": "Allows the app to read all domain properties on behalf of the signed-in user.", - "displayName": "Read domains.", - "id": "2f9ee017-59c1-4f1d-9472-bd5529a7b311", + "description": "Allows the app to read assignments and their grades on behalf of the user.", + "displayName": "Read users' class assignments and their grades", + "id": "091460c9-9c4a-49b2-81ef-1f3d852acce2", "origin": "Delegated (Microsoft Graph)", - "value": "Domain.Read.All" + "value": "EduAssignments.Read" }, { - "description": "Allows the app to manage learning content in the organization's directory, on behalf of the signed-in user.", - "displayName": "Manage learning content", - "id": "53cec1c4-a65f-4981-9dc1-ad75dbf1c077", + "description": "Allows the app to read assignments without grades on behalf of the user.", + "displayName": "Read users' class assignments without grades", + "id": "c0b0103b-c053-4b2e-9973-9f3a544ec9b8", "origin": "Delegated (Microsoft Graph)", - "value": "LearningContent.ReadWrite.All" + "value": "EduAssignments.ReadBasic" }, { - "description": "Allows the app to read data for the learning provider in the organization's directory, on behalf of the signed-in user.", - "displayName": "Read learning provider", - "id": "dd8ce36f-9245-45ea-a99e-8ac398c22861", + "description": "Allows the app to read internal federation configuration for a domain.", + "displayName": "Read internal federation configuration for a domain.", + "id": "33203a2a-a761-40f0-8a7c-a7e74a9f8ac6", "origin": "Delegated (Microsoft Graph)", - "value": "LearningProvider.Read" + "value": "Domain-InternalFederation.Read.All" + }, + { + "description": "Sign In to Mixed Reality Services", + "displayName": "Signin", + "id": "b24fe742-e2a6-4995-adbf-aba1516932c5", + "origin": "Application (Microsoft Mixed Reality)", + "value": "mixedreality.signin" }, { "description": "Allows the app to create, update, read, and delete data for the learning provider in the organization's directory, on behalf of the signed-in user.", @@ -3555,6 +3569,27 @@ "origin": "Delegated (Microsoft Graph)", "value": "LearningProvider.ReadWrite" }, + { + "description": "Allows an app to read license assignments for users and groups, on behalf of the signed-in user.", + "displayName": "Read all license assignments.", + "id": "f395577a-0960-456b-979f-7228de0c5996", + "origin": "Delegated (Microsoft Graph)", + "value": "LicenseAssignment.Read.All" + }, + { + "description": "Allows the app to read your organization's device configuration policies on behalf of the signed-in user. For example, device registration policy can limit initial provisioning controls using quota restrictions, additional authentication and authorization checks.", + "displayName": "Read your organization's device configuration policies", + "id": "3616a4b0-6746-49c4-a678-4c237599074d", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.DeviceConfiguration" + }, + { + "description": "Allows the app to read your organization’s identity protection policy on behalf of the signed-in user.", + "displayName": "Read your organization’s identity protection policy", + "id": "d146432f-b803-4ed4-8d42-ba74193a6ede", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.IdentityProtection" + }, { "description": "Allows the app to read policies related to consent and permission grants for applications, on behalf of the signed-in user.", "displayName": "Read consent and permission grant policies", @@ -3660,6 +3695,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "Policy.ReadWrite.FeatureRollout" }, + { + "description": "Allows the app to read your organization's cross tenant access policies on behalf of the signed-in user.", + "displayName": "Read your organization's cross tenant access policies", + "id": "b337372a-8b4d-428d-9cd8-3d7363865736", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.Read.CrossTenantAccess" + }, { "description": "Allows the application to read and update the organization's federated token validation policy on behalf of the signed-in user.", "displayName": "Read and write your organization's federated token validation policy", @@ -3668,39 +3710,32 @@ "value": "Policy.ReadWrite.FedTokenValidation" }, { - "description": "Allows the app to read and write your organization’s identity protection policy on behalf of the signed-in user.", - "displayName": "Read and write your organization’s identity protection policy ", - "id": "7256e131-3efb-4323-9854-cf41c6021770", - "origin": "Delegated (Microsoft Graph)", - "value": "Policy.ReadWrite.IdentityProtection" - }, - { - "description": "Allows the app to read your organization’s identity protection policy on behalf of the signed-in user.", - "displayName": "Read your organization’s identity protection policy", - "id": "d146432f-b803-4ed4-8d42-ba74193a6ede", + "description": "Allows the app to read your organization's conditional access policies on behalf of the signed-in user.", + "displayName": "Read your organization's conditional access policies", + "id": "633e0fce-8c58-4cfb-9495-12bbd5a24f7c", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.Read.IdentityProtection" + "value": "Policy.Read.ConditionalAccess" }, { - "description": "Allows the app to read and write your organization's mobility management policies on behalf of the signed-in user. For example, a mobility management policy can set the enrollment scope for a given mobility management application.", - "displayName": "Read and write your organization's mobility management policies", - "id": "a8ead177-1889-4546-9387-f25e658e2a79", + "description": "Allows the app to read the authentication method policies, on behalf of the signed-in user. ", + "displayName": "Read authentication method policies", + "id": "a6ff13ac-1851-4993-8ca9-a671d70de2d5", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.ReadWrite.MobilityManagement" + "value": "Policy.Read.AuthenticationMethod" }, { - "description": "Allows the app to read your organization's device configuration policies on behalf of the signed-in user. For example, device registration policy can limit initial provisioning controls using quota restrictions, additional authentication and authorization checks.", - "displayName": "Read your organization's device configuration policies", - "id": "3616a4b0-6746-49c4-a678-4c237599074d", + "description": "Allows the app to read and write organization-wide Microsoft 365 apps installation settings on behalf of the signed-in user.", + "displayName": "Read and write organization-wide Microsoft 365 apps installation settings", + "id": "1ff35e91-19eb-42d8-aa2d-cc9891127ae5", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.Read.DeviceConfiguration" + "value": "OrgSettings-Microsoft365Install.ReadWrite.All" }, { - "description": "Allows the app to read your organization's conditional access policies on behalf of the signed-in user.", - "displayName": "Read your organization's conditional access policies", - "id": "633e0fce-8c58-4cfb-9495-12bbd5a24f7c", + "description": "Allows the app to read organization-wide Microsoft To Do settings on behalf of the signed-in user.", + "displayName": "Read organization-wide Microsoft To Do settings", + "id": "7ff96f41-f022-45ba-acd8-ef3f03063d6b", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.Read.ConditionalAccess" + "value": "OrgSettings-Todo.Read.All" }, { "description": "Allows the app to read and write organization-wide Microsoft To Do settings on behalf of the signed-in user.", @@ -3807,13 +3842,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "Policy.Read.All" }, - { - "description": "Allows the app to read the authentication method policies, on behalf of the signed-in user. ", - "displayName": "Read authentication method policies", - "id": "a6ff13ac-1851-4993-8ca9-a671d70de2d5", - "origin": "Delegated (Microsoft Graph)", - "value": "Policy.Read.AuthenticationMethod" - }, { "description": "Allows the app to read your organization's B2BManagement policies on behalf of the signed-in user.", "displayName": "Read your organization's B2BManagement policies", @@ -3822,11 +3850,18 @@ "value": "Policy.Read.B2BManagementPolicy" }, { - "description": "Allows the app to read your organization's cross tenant access policies on behalf of the signed-in user.", - "displayName": "Read your organization's cross tenant access policies", - "id": "b337372a-8b4d-428d-9cd8-3d7363865736", + "description": "Allows the app to read and write your organization’s identity protection policy on behalf of the signed-in user.", + "displayName": "Read and write your organization’s identity protection policy ", + "id": "7256e131-3efb-4323-9854-cf41c6021770", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.Read.CrossTenantAccess" + "value": "Policy.ReadWrite.IdentityProtection" + }, + { + "description": "Allows the app to read and write your organization's mobility management policies on behalf of the signed-in user. For example, a mobility management policy can set the enrollment scope for a given mobility management application.", + "displayName": "Read and write your organization's mobility management policies", + "id": "a8ead177-1889-4546-9387-f25e658e2a79", + "origin": "Delegated (Microsoft Graph)", + "value": "Policy.ReadWrite.MobilityManagement" }, { "description": "Allows the app to manage policies related to consent and permission grants for applications, on behalf of the signed-in user.", @@ -3836,18 +3871,18 @@ "value": "Policy.ReadWrite.PermissionGrant" }, { - "description": "Allows the application to read and update the organization's recovery policy on behalf of the signed-in user.", - "displayName": "Read and write your organization's recovery policy", - "id": "1e7a2f4c-e602-4b1b-9547-304dd65c4cc2", + "description": "Allows the application to read and update the metadata and document content of print jobs that the signed-in user created.", + "displayName": "Read and write user's print jobs", + "id": "b81dd597-8abb-4b3f-a07a-820b0316ed04", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.ReadWrite.Recovery" + "value": "PrintJob.ReadWrite" }, { - "description": "Allows the app to read and write your organization's security defaults policy on behalf of the signed-in user.", - "displayName": "Read and write your organization's security defaults policy", - "id": "0b2a744c-2abf-4f1e-ad7e-17a087e2be99", + "description": "Allows the application to read and update the metadata and document content of print jobs on behalf of the signed-in user. ", + "displayName": "Read and write print jobs", + "id": "036b9544-e8c5-46ef-900a-0646cc42b271", "origin": "Delegated (Microsoft Graph)", - "value": "Policy.ReadWrite.SecurityDefaults" + "value": "PrintJob.ReadWrite.All" }, { "description": "Allows the application to read and update the metadata of print jobs that the signed-in user created. Does not allow access to print job document content.", @@ -3955,46 +3990,46 @@ "value": "PrivilegedAssignmentSchedule.ReadWrite.AzureADGroup" }, { - "description": "Allows the app to read, create, and delete time-based assignment schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", - "displayName": "Read, create, and delete assignment schedules for app permission grants and app role assignments", - "id": "e07122a7-d275-4a27-a2f5-eb62349edae0", + "description": "Allows the application to read the metadata of print jobs on behalf of the signed-in user. Does not allow access to print job document content.", + "displayName": "Read basic information of print jobs", + "id": "04ce8d60-72ce-4867-85cf-6d82f36922f3", "origin": "Delegated (Microsoft Graph)", - "value": "PrivilegedAssignmentSchedule.ReadWrite.EntraAppRole" + "value": "PrintJob.ReadBasic.All" }, { - "description": "Allows the app to delete time-based assignment schedules for access to Azure AD groups, on behalf of the signed-in user.", - "displayName": "Delete assignment schedules for access to Azure AD groups", - "id": "ca5fe595-68ff-4dfd-907d-4509501a0e49", + "description": "Allows the application to read the metadata of print jobs that the signed-in user created. Does not allow access to print job document content.", + "displayName": "Read basic information of user's print jobs", + "id": "6a71a747-280f-4670-9ca0-a9cbf882b274", "origin": "Delegated (Microsoft Graph)", - "value": "PrivilegedAssignmentSchedule.Remove.AzureADGroup" + "value": "PrintJob.ReadBasic" }, { - "description": "Allows the application to read and update the metadata and document content of print jobs on behalf of the signed-in user. ", - "displayName": "Read and write print jobs", - "id": "036b9544-e8c5-46ef-900a-0646cc42b271", + "description": "Allows the application to read the metadata and document content of print jobs on behalf of the signed-in user. ", + "displayName": "Read print jobs", + "id": "afdd6933-a0d8-40f7-bd1a-b5d778e8624b", "origin": "Delegated (Microsoft Graph)", - "value": "PrintJob.ReadWrite.All" + "value": "PrintJob.Read.All" }, { - "description": "Allows the application to read and update the metadata and document content of print jobs that the signed-in user created.", - "displayName": "Read and write user's print jobs", - "id": "b81dd597-8abb-4b3f-a07a-820b0316ed04", + "description": "Allows the application to read the metadata and document content of print jobs that the signed-in user created.", + "displayName": "Read user's print jobs", + "id": "248f5528-65c0-4c88-8326-876c7236df5e", "origin": "Delegated (Microsoft Graph)", - "value": "PrintJob.ReadWrite" + "value": "PrintJob.Read" }, { - "description": "Allows the application to read the metadata of print jobs on behalf of the signed-in user. Does not allow access to print job document content.", - "displayName": "Read basic information of print jobs", - "id": "04ce8d60-72ce-4867-85cf-6d82f36922f3", + "description": "Allows the application to read and update the organization's recovery policy on behalf of the signed-in user.", + "displayName": "Read and write your organization's recovery policy", + "id": "1e7a2f4c-e602-4b1b-9547-304dd65c4cc2", "origin": "Delegated (Microsoft Graph)", - "value": "PrintJob.ReadBasic.All" + "value": "Policy.ReadWrite.Recovery" }, { - "description": "Allows the application to read the metadata of print jobs that the signed-in user created. Does not allow access to print job document content.", - "displayName": "Read basic information of user's print jobs", - "id": "6a71a747-280f-4670-9ca0-a9cbf882b274", + "description": "Allows the app to read and write your organization's security defaults policy on behalf of the signed-in user.", + "displayName": "Read and write your organization's security defaults policy", + "id": "0b2a744c-2abf-4f1e-ad7e-17a087e2be99", "origin": "Delegated (Microsoft Graph)", - "value": "PrintJob.ReadBasic" + "value": "Policy.ReadWrite.SecurityDefaults" }, { "description": "Allows the app to read and write your organization's trust framework policies on behalf of the signed-in user.", @@ -4038,6 +4073,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "Presence.ReadWrite" }, + { + "description": "Allows the app to read organization-wide Microsoft 365 apps installation settings on behalf of the signed-in user.", + "displayName": "Read organization-wide Microsoft 365 apps installation settings", + "id": "8cbdb9f6-9c2e-451a-814d-ec606e5d0212", + "origin": "Delegated (Microsoft Graph)", + "value": "OrgSettings-Microsoft365Install.Read.All" + }, { "description": "Allows the application to read print connectors on behalf of the signed-in user.", "displayName": "Read print connectors", @@ -4045,20 +4087,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "PrintConnector.Read.All" }, - { - "description": "Allows the application to read and write print connectors on behalf of the signed-in user.", - "displayName": "Read and write print connectors", - "id": "79ef9967-7d59-4213-9c64-4b10687637d8", - "origin": "Delegated (Microsoft Graph)", - "value": "PrintConnector.ReadWrite.All" - }, - { - "description": "Allows the app to read organization-wide Microsoft To Do settings on behalf of the signed-in user.", - "displayName": "Read organization-wide Microsoft To Do settings", - "id": "7ff96f41-f022-45ba-acd8-ef3f03063d6b", - "origin": "Delegated (Microsoft Graph)", - "value": "OrgSettings-Todo.Read.All" - }, { "description": "Allows the application to create (register) printers on behalf of the signed-in user. ", "displayName": "Register printers ", @@ -4066,6 +4094,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "Printer.Create" }, + { + "description": "Allows the application to create (register), read, update, and delete (unregister) printers on behalf of the signed-in user. ", + "displayName": "Register, read, update, and unregister printers", + "id": "93dae4bd-43a1-4a23-9a1a-92957e1d9121", + "origin": "Delegated (Microsoft Graph)", + "value": "Printer.FullControl.All" + }, { "description": "Allows the application to read printers on behalf of the signed-in user. ", "displayName": "Read printers", @@ -4109,46 +4144,46 @@ "value": "PrintJob.Create" }, { - "description": "Allows the application to read the metadata and document content of print jobs that the signed-in user created.", - "displayName": "Read user's print jobs", - "id": "248f5528-65c0-4c88-8326-876c7236df5e", + "description": "Allows the application to read and write print connectors on behalf of the signed-in user.", + "displayName": "Read and write print connectors", + "id": "79ef9967-7d59-4213-9c64-4b10687637d8", "origin": "Delegated (Microsoft Graph)", - "value": "PrintJob.Read" + "value": "PrintConnector.ReadWrite.All" }, { - "description": "Allows the application to read the metadata and document content of print jobs on behalf of the signed-in user. ", - "displayName": "Read print jobs", - "id": "afdd6933-a0d8-40f7-bd1a-b5d778e8624b", + "description": "Allows the app to read and write organization-wide Microsoft Forms settings on behalf of the signed-in user.", + "displayName": "Read and write organization-wide Microsoft Forms settings", + "id": "346c19ff-3fb2-4e81-87a0-bac9e33990c1", "origin": "Delegated (Microsoft Graph)", - "value": "PrintJob.Read.All" + "value": "OrgSettings-Forms.ReadWrite.All" }, { - "description": "Allows the application to create (register), read, update, and delete (unregister) printers on behalf of the signed-in user. ", - "displayName": "Register, read, update, and unregister printers", - "id": "93dae4bd-43a1-4a23-9a1a-92957e1d9121", + "description": "Allows the app to read organization-wide Microsoft Forms settings on behalf of the signed-in user.", + "displayName": "Read organization-wide Microsoft Forms settings", + "id": "210051a0-1ffc-435c-ae76-02d226d05752", "origin": "Delegated (Microsoft Graph)", - "value": "Printer.FullControl.All" + "value": "OrgSettings-Forms.Read.All" }, { - "description": "Allows the app to read and write organization-wide Microsoft 365 apps installation settings on behalf of the signed-in user.", - "displayName": "Read and write organization-wide Microsoft 365 apps installation settings", - "id": "1ff35e91-19eb-42d8-aa2d-cc9891127ae5", + "description": "Allows the app to read and write organization-wide Dynamics customer voice settings on behalf of the signed-in user.", + "displayName": "Read and write organization-wide Dynamics customer voice settings", + "id": "4cea26fb-6967-4234-82c4-c044414743f8", "origin": "Delegated (Microsoft Graph)", - "value": "OrgSettings-Microsoft365Install.ReadWrite.All" + "value": "OrgSettings-DynamicsVoice.ReadWrite.All" }, { - "description": "Allows the app to read organization-wide Microsoft 365 apps installation settings on behalf of the signed-in user.", - "displayName": "Read organization-wide Microsoft 365 apps installation settings", - "id": "8cbdb9f6-9c2e-451a-814d-ec606e5d0212", + "description": "Allows the app to read email in the signed-in user's mailbox except body, previewBody, attachments and any extended properties.", + "displayName": "Read user basic mail", + "id": "a4b8392a-d8d1-4954-a029-8e668a39a170", "origin": "Delegated (Microsoft Graph)", - "value": "OrgSettings-Microsoft365Install.Read.All" + "value": "Mail.ReadBasic" }, { - "description": "Allows the app to read and write organization-wide Microsoft Forms settings on behalf of the signed-in user.", - "displayName": "Read and write organization-wide Microsoft Forms settings", - "id": "346c19ff-3fb2-4e81-87a0-bac9e33990c1", + "description": "Allows the app to read mail the signed-in user can access, including their own and shared mail, except for body, bodyPreview, uniqueBody, attachments, extensions, and any extended properties.", + "displayName": "Read user and shared basic mail", + "id": "b11fa0e7-fdb7-4dc9-b1f1-59facd463480", "origin": "Delegated (Microsoft Graph)", - "value": "OrgSettings-Forms.ReadWrite.All" + "value": "Mail.ReadBasic.Shared" }, { "description": "Allows the app to create, read, update, and delete email in user mailboxes. Does not include permission to send mail.", @@ -4255,34 +4290,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "MailboxSettings.Read" }, - { - "description": "Allows the app to create, read, update, and delete user's mailbox settings. Does not include permission to send mail.", - "displayName": "Read and write user mailbox settings", - "id": "818c620a-27a9-40bd-a6a5-d96f7d610b4b", - "origin": "Delegated (Microsoft Graph)", - "value": "MailboxSettings.ReadWrite" - }, - { - "description": "Allows the app to read mail tips on behalf of the signed-in user for mailboxes they have access to. Mail tips include automatic replies, mailbox status, custom tips, and delivery information.", - "displayName": "Read mail tips for mailboxes you can access", - "id": "4776cae1-54bd-4dfd-823c-e5861ed49a98", - "origin": "Delegated (Microsoft Graph)", - "value": "MailTips.ReadBasic.Shared" - }, - { - "description": "Allows the app to read mail the signed-in user can access, including their own and shared mail, except for body, bodyPreview, uniqueBody, attachments, extensions, and any extended properties.", - "displayName": "Read user and shared basic mail", - "id": "b11fa0e7-fdb7-4dc9-b1f1-59facd463480", - "origin": "Delegated (Microsoft Graph)", - "value": "Mail.ReadBasic.Shared" - }, - { - "description": "Allows the app to read email in the signed-in user's mailbox except body, previewBody, attachments and any extended properties.", - "displayName": "Read user basic mail", - "id": "a4b8392a-d8d1-4954-a029-8e668a39a170", - "origin": "Delegated (Microsoft Graph)", - "value": "Mail.ReadBasic" - }, { "description": "Allows the app to read mail a user can access, including their own and shared mail.", "displayName": "Read user and shared mail", @@ -4298,18 +4305,18 @@ "value": "Mail.Read" }, { - "description": "Allows the app to read data for the learner's self-initiated courses in the organization's directory, on behalf of the signed-in user.", - "displayName": "Read user's self-initiated courses", - "id": "f6403ef7-4a96-47be-a190-69ba274c3f11", + "description": "Allows the app to read and modify lockbox configuration settings on behalf of the signed-in user", + "displayName": "Read and write lockbox settings", + "id": "bdc52289-9ed7-4339-83ab-772ae618713c", "origin": "Delegated (Microsoft Graph)", - "value": "LearningSelfInitiatedCourse.Read" + "value": "LockboxSettings.ReadWrite.All" }, { - "description": "Allows an app to read license assignments for users and groups, on behalf of the signed-in user.", - "displayName": "Read all license assignments.", - "id": "f395577a-0960-456b-979f-7228de0c5996", + "description": "Allows the app to read lockbox configuration settings on behalf of the signed-in user", + "displayName": "Read lockbox settings", + "id": "2ea429a7-d1fa-4f96-b451-e91ecc5e5fe2", "origin": "Delegated (Microsoft Graph)", - "value": "LicenseAssignment.Read.All" + "value": "LockboxSettings.Read.All" }, { "description": "Allows an app to manage license assignments for users and groups, on behalf of the signed-in user.", @@ -4353,13 +4360,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "LifecycleWorkflows.Read.All" }, - { - "description": "Allows the app to read all managed tenant information on behalf of the signed-in user.", - "displayName": "Read all managed tenant information", - "id": "dc34164e-6c4a-41a0-be89-3ae2fbad7cd3", - "origin": "Delegated (Microsoft Graph)", - "value": "ManagedTenants.Read.All" - }, { "description": "Allows the app to create, update, list, read and delete all workflows, tasks and related lifecycle workflows resources on behalf of the signed-in user.", "displayName": "Read and write all lifecycle workflows resources", @@ -4367,6 +4367,20 @@ "origin": "Delegated (Microsoft Graph)", "value": "LifecycleWorkflows.ReadWrite.All" }, + { + "description": "Allows the app to read all Lifecycle workflows custom task extensions on behalf of a signed-in user.", + "displayName": "Read all Lifecycle workflows custom task extensions", + "id": "2973a298-1d69-4f87-8d30-7025f0ec19d7", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecycleWorkflows-CustomExt.Read.All" + }, + { + "description": "Allows the app to create, read, update, and delete user's mailbox settings. Does not include permission to send mail.", + "displayName": "Read and write user mailbox settings", + "id": "818c620a-27a9-40bd-a6a5-d96f7d610b4b", + "origin": "Delegated (Microsoft Graph)", + "value": "MailboxSettings.ReadWrite" + }, { "description": "Allows the app to create, update, list, read and delete all Lifecycle workflows custom task extensions on behalf of a signed-in user.", "displayName": "Read and write all Lifecycle workflows custom task extensions", @@ -4374,13 +4388,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "LifecycleWorkflows-CustomExt.ReadWrite.All" }, - { - "description": "Allows the app to read all Lifecycle workflows reports on behalf of a signed-in user.", - "displayName": "Read all Lifecycle workflows reports", - "id": "4d3d7f81-163f-426a-8432-5638d2e82083", - "origin": "Delegated (Microsoft Graph)", - "value": "LifecycleWorkflows-Reports.Read.All" - }, { "description": "Allows the app to run workflows on-demand on behalf of a signed-in user.", "displayName": "Run workflows on-demand in Lifecycle workflows", @@ -4424,18 +4431,39 @@ "value": "Lists.SelectedOperations.Selected" }, { - "description": "Allows the app to read all Lifecycle workflows custom task extensions on behalf of a signed-in user.", - "displayName": "Read all Lifecycle workflows custom task extensions", - "id": "2973a298-1d69-4f87-8d30-7025f0ec19d7", + "description": "Allows the app to read lockbox requests on behalf of the signed-in user", + "displayName": "Read lockbox requests", + "id": "a368a3ce-713b-46d9-9c93-bb559acf38ca", "origin": "Delegated (Microsoft Graph)", - "value": "LifecycleWorkflows-CustomExt.Read.All" + "value": "LockboxRequest.Read.All" }, { - "description": "Allows the app to read time-based eligibility schedules for permission grants for application permissions to any API (including Microsoft Graph) and application assignments for any app, on behalf of the signed-in user.", - "displayName": "Read eligibility schedules for app permission grants and app role assignments", - "id": "9b9eb231-5483-4f3c-89e9-9d5048dafe9d", + "description": "Allows the app to read and manage lockbox requests on behalf of the signed-in user", + "displayName": "Read and manage lockbox requests", + "id": "524d6259-f823-43c4-964a-97e3b8ddb56c", "origin": "Delegated (Microsoft Graph)", - "value": "PrivilegedEligibilitySchedule.Read.EntraAppRole" + "value": "LockboxRequest.ReadWrite.All" + }, + { + "description": "Allows the app to read all Lifecycle workflows reports on behalf of a signed-in user.", + "displayName": "Read all Lifecycle workflows reports", + "id": "4d3d7f81-163f-426a-8432-5638d2e82083", + "origin": "Delegated (Microsoft Graph)", + "value": "LifecycleWorkflows-Reports.Read.All" + }, + { + "description": "Allows the app to read data for the learner's self-initiated courses in the organization's directory, on behalf of the signed-in user.", + "displayName": "Read user's self-initiated courses", + "id": "f6403ef7-4a96-47be-a190-69ba274c3f11", + "origin": "Delegated (Microsoft Graph)", + "value": "LearningSelfInitiatedCourse.Read" + }, + { + "description": "Allows the app to read mail tips on behalf of the signed-in user for mailboxes they have access to. Mail tips include automatic replies, mailbox status, custom tips, and delivery information.", + "displayName": "Read mail tips for mailboxes you can access", + "id": "4776cae1-54bd-4dfd-823c-e5861ed49a98", + "origin": "Delegated (Microsoft Graph)", + "value": "MailTips.ReadBasic.Shared" }, { "description": "Allows the app to read and write all managed tenant information on behalf of the signed-in user.", @@ -4445,11 +4473,18 @@ "value": "ManagedTenants.ReadWrite.All" }, { - "description": "Allows the app to read multi-tenant organization details and tenants on behalf of the signed-in user.", - "displayName": "Read multi-tenant organization details and tenants", - "id": "526aa72a-5878-49fe-bf4e-357973af9b06", + "description": "Allows the app to read online meeting artifacts on behalf of the signed-in user.", + "displayName": "Read user's online meeting artifacts", + "id": "110e5abb-a10c-4b59-8b55-9b4daa4ef743", "origin": "Delegated (Microsoft Graph)", - "value": "MultiTenantOrganization.Read.All" + "value": "OnlineMeetingArtifact.Read.All" + }, + { + "description": "Allows the app to read all recordings of online meetings, on behalf of the signed-in user.", + "displayName": "Read all recordings of online meetings.", + "id": "190c2bb6-1fdd-4fec-9aa2-7d571b5e1fe3", + "origin": "Delegated (Microsoft Graph)", + "value": "OnlineMeetingRecording.Read.All" }, { "description": "Allows the app to read online meeting details on behalf of the signed-in user.", @@ -4557,46 +4592,46 @@ "value": "OrgSettings-DynamicsVoice.Read.All" }, { - "description": "Allows the app to read and write organization-wide Dynamics customer voice settings on behalf of the signed-in user.", - "displayName": "Read and write organization-wide Dynamics customer voice settings", - "id": "4cea26fb-6967-4234-82c4-c044414743f8", + "description": "Allows the app to read all AI Insights for online meetings, on behalf of the signed-in user.", + "displayName": "Read all AI Insights for online meetings.", + "id": "166741d6-eeb8-46fe-91f4-817d2af7bc88", "origin": "Delegated (Microsoft Graph)", - "value": "OrgSettings-DynamicsVoice.ReadWrite.All" + "value": "OnlineMeetingAiInsight.Read.All" }, { - "description": "Allows the app to read organization-wide Microsoft Forms settings on behalf of the signed-in user.", - "displayName": "Read organization-wide Microsoft Forms settings", - "id": "210051a0-1ffc-435c-ae76-02d226d05752", + "description": "Allows the app to see and update the data you gave it access to, even when users are not currently using the app. This does not give the app any additional permissions.", + "displayName": "Maintain access to data you have given it access to", + "id": "7427e0e9-2fba-42fe-b0c0-848c9e6a8182", "origin": "Delegated (Microsoft Graph)", - "value": "OrgSettings-Forms.Read.All" + "value": "offline_access" }, { - "description": "Allows the app to read all recordings of online meetings, on behalf of the signed-in user.", - "displayName": "Read all recordings of online meetings.", - "id": "190c2bb6-1fdd-4fec-9aa2-7d571b5e1fe3", + "description": "Allows the app to deliver its notifications on behalf of signed-in users. Also allows the app to read, update, and delete the user's notification items for this app.", + "displayName": "Deliver and manage user notifications for this app", + "id": "89497502-6e42-46a2-8cb2-427fd3df970a", "origin": "Delegated (Microsoft Graph)", - "value": "OnlineMeetingRecording.Read.All" + "value": "Notifications.ReadWrite.CreatedByApp" }, { - "description": "Allows the app to read online meeting artifacts on behalf of the signed-in user.", - "displayName": "Read user's online meeting artifacts", - "id": "110e5abb-a10c-4b59-8b55-9b4daa4ef743", + "description": "This is deprecated! Do not use! This permission no longer has any effect. You can safely consent to it. No additional privileges will be granted to the app.", + "displayName": "Limited notebook access (deprecated)", + "id": "ed68249d-017c-4df5-9113-e684c7f8760b", "origin": "Delegated (Microsoft Graph)", - "value": "OnlineMeetingArtifact.Read.All" + "value": "Notes.ReadWrite.CreatedByApp" }, { - "description": "Allows the app to read all AI Insights for online meetings, on behalf of the signed-in user.", - "displayName": "Read all AI Insights for online meetings.", - "id": "166741d6-eeb8-46fe-91f4-817d2af7bc88", + "description": "Allows the app to read the memberships of hidden groups and administrative units on behalf of the signed-in user, for those hidden groups and administrative units that the signed-in user has access to.", + "displayName": "Read hidden memberships", + "id": "f6a3db3e-f7e8-4ed2-a414-557c8c9830be", "origin": "Delegated (Microsoft Graph)", - "value": "OnlineMeetingAiInsight.Read.All" + "value": "Member.Read.Hidden" }, { - "description": "Allows the app to see and update the data you gave it access to, even when users are not currently using the app. This does not give the app any additional permissions.", - "displayName": "Maintain access to data you have given it access to", - "id": "7427e0e9-2fba-42fe-b0c0-848c9e6a8182", + "description": "Allows the app to read multi-tenant organization details and tenants on behalf of the signed-in user.", + "displayName": "Read multi-tenant organization details and tenants", + "id": "526aa72a-5878-49fe-bf4e-357973af9b06", "origin": "Delegated (Microsoft Graph)", - "value": "offline_access" + "value": "MultiTenantOrganization.Read.All" }, { "description": "Allows the app to read multi-tenant organization basic details and active tenants on behalf of the signed-in user.", @@ -4638,7 +4673,14 @@ "displayName": "Read and write all network access information", "id": "ae2df9c5-f18d-4ec4-a51b-bdeb807f177b", "origin": "Delegated (Microsoft Graph)", - "value": "NetworkAccess.ReadWrite.All" + "value": "NetworkAccess.ReadWrite.All" + }, + { + "description": "Allows the app to read all managed tenant information on behalf of the signed-in user.", + "displayName": "Read all managed tenant information", + "id": "dc34164e-6c4a-41a0-be89-3ae2fbad7cd3", + "origin": "Delegated (Microsoft Graph)", + "value": "ManagedTenants.Read.All" }, { "description": "Allows the app to read your organization's branches for network access on behalf of the signed-in user.", @@ -4647,20 +4689,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "NetworkAccessBranch.Read.All" }, - { - "description": "Allows the app to read and write your organization's branches for network access on behalf of the signed-in user.", - "displayName": "Read and write properties of branches for network access", - "id": "b8a36cc2-b810-461a-baa4-a7281e50bd5c", - "origin": "Delegated (Microsoft Graph)", - "value": "NetworkAccessBranch.ReadWrite.All" - }, - { - "description": "Allows the app to read the memberships of hidden groups and administrative units on behalf of the signed-in user, for those hidden groups and administrative units that the signed-in user has access to.", - "displayName": "Read hidden memberships", - "id": "f6a3db3e-f7e8-4ed2-a414-557c8c9830be", - "origin": "Delegated (Microsoft Graph)", - "value": "Member.Read.Hidden" - }, { "description": "Allows the app to read your organization's security and routing network access policies on behalf of the signed-in user.", "displayName": "Read security and routing policies for network access", @@ -4668,6 +4696,13 @@ "origin": "Delegated (Microsoft Graph)", "value": "NetworkAccessPolicy.Read.All" }, + { + "description": "Allows the app to read and write your organization's security and routing network access policies on behalf of the signed-in user.", + "displayName": "Read and write security and routing policies for network access", + "id": "b1fbad0f-ef6e-42ed-8676-bca7fa3e7291", + "origin": "Delegated (Microsoft Graph)", + "value": "NetworkAccessPolicy.ReadWrite.All" + }, { "description": "Allows the app to read all network access reports on behalf of the signed-in user.", "displayName": "Read all network access reports", @@ -4711,32 +4746,11 @@ "value": "Notes.ReadWrite.All" }, { - "description": "This is deprecated! Do not use! This permission no longer has any effect. You can safely consent to it. No additional privileges will be granted to the app.", - "displayName": "Limited notebook access (deprecated)", - "id": "ed68249d-017c-4df5-9113-e684c7f8760b", - "origin": "Delegated (Microsoft Graph)", - "value": "Notes.ReadWrite.CreatedByApp" - }, - { - "description": "Allows the app to deliver its notifications on behalf of signed-in users. Also allows the app to read, update, and delete the user's notification items for this app.", - "displayName": "Deliver and manage user notifications for this app", - "id": "89497502-6e42-46a2-8cb2-427fd3df970a", - "origin": "Delegated (Microsoft Graph)", - "value": "Notifications.ReadWrite.CreatedByApp" - }, - { - "description": "Allows the app to read and write your organization's security and routing network access policies on behalf of the signed-in user.", - "displayName": "Read and write security and routing policies for network access", - "id": "b1fbad0f-ef6e-42ed-8676-bca7fa3e7291", - "origin": "Delegated (Microsoft Graph)", - "value": "NetworkAccessPolicy.ReadWrite.All" - }, - { - "description": "Allows the application to list and query user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export external user data (e.g. customer content or system-generated logs), associated with the current tenant on behalf of the signed-in user.", - "displayName": "Read shared cross-tenant user profile and export data", - "id": "cb1ba48f-d22b-4325-a07f-74135a62ee41", + "description": "Allows the app to read and write your organization's branches for network access on behalf of the signed-in user.", + "displayName": "Read and write properties of branches for network access", + "id": "b8a36cc2-b810-461a-baa4-a7281e50bd5c", "origin": "Delegated (Microsoft Graph)", - "value": "CrossTenantUserProfileSharing.Read" + "value": "NetworkAccessBranch.ReadWrite.All" }, { "description": "Sign in to synthetics service", @@ -4745,13 +4759,6 @@ "origin": "Delegated (Microsoft Mixed Reality)", "value": "syntest.signin" }, - { - "description": "Allows the app to uninstall Microsoft Entra Connect Sync Agent and offboard SSPR for the tenant", - "displayName": "Read, write and manage Microsoft Entra Connect Sync Agent", - "id": "69201c67-737b-4a20-8f16-e0c8c64e0b0e", - "origin": "Application (Microsoft password reset service)", - "value": "PasswordWriteback.OffboardClient.All" - }, { "description": " ", "displayName": "OrgApp.Reshare (retired)", @@ -5326,13 +5333,6 @@ "origin": "Delegated (Power BI Service)", "value": "SparkJobDefinition.Execute.All" }, - { - "description": "Allows the app to make API calls that require restore permissions on all Warehouses, on behalf of the signed-in user.", - "displayName": "Make API calls that require restore permissions on all Warehouses", - "id": "7da32ee4-ec68-43a4-b13a-b5385ad9770e", - "origin": "Delegated (Power BI Service)", - "value": "Warehouse.Restore.All" - }, { "description": "Allows reading mirrored databases on the user’s behalf.", "displayName": "Read mirrored databases", @@ -5340,6 +5340,13 @@ "origin": "Delegated (Power BI Service)", "value": "MirroredDatabase.Read.All" }, + { + "description": "Allows the app to create and manage external data shares for all mirrored Databases, on behalf of the signed-in user.", + "displayName": "Allows the app to create and manage external data shares for all mirrored Databases", + "id": "eb433b13-ec6d-487b-8411-b5fadda75072", + "origin": "Delegated (Power BI Service)", + "value": "MirroredDatabase.ExternalDataShare.All" + }, { "description": " ", "displayName": "MirroredDatabase.Execute (retired)", @@ -5473,13 +5480,6 @@ "origin": "Delegated (Power BI Service)", "value": "Eventhouse.Execute.All" }, - { - "description": "Allows the app to make API calls that executes requests on all API for GraphQL items, on behalf of the signed-in user.", - "displayName": "Make API calls that executes requests on all API for GraphQL items", - "id": "fc011432-d782-46d3-8143-f0328911e0a3", - "origin": "Delegated (Power BI Service)", - "value": "GraphQL.Execute.All" - }, { "description": " ", "displayName": "Environment.Reshare (retired)", @@ -5487,6 +5487,13 @@ "origin": "Delegated (Power BI Service)", "value": "Environment.Reshare.All" }, + { + "description": "Allows modifying environment items on the user’s behalf.", + "displayName": "Read and write environment items", + "id": "995d4201-6a2d-45c6-bad2-9f2aba89298d", + "origin": "Delegated (Power BI Service)", + "value": "Environment.ReadWrite.All" + }, { "description": "Allows reading environment items on the user’s behalf.", "displayName": "Read environment items", @@ -5494,6 +5501,13 @@ "origin": "Delegated (Power BI Service)", "value": "Environment.Read.All" }, + { + "description": " ", + "displayName": "DataAgent.Reshare (retired)", + "id": "82b1d51c-42df-4ba9-9aee-bbba1e3f2ab7", + "origin": "Delegated (Power BI Service)", + "value": "DataAgent.Reshare.All" + }, { "description": "Allows reading Databricks workspaces catalog metadata on the user’s behalf.", "displayName": "Read Databricks workspaces catalog metadata.", @@ -5543,6 +5557,13 @@ "origin": "Delegated (Power BI Service)", "value": "Datamart.Read.All" }, + { + "description": "Allows the app to make API calls that executes requests on all API for GraphQL items, on behalf of the signed-in user.", + "displayName": "Make API calls that executes requests on all API for GraphQL items", + "id": "fc011432-d782-46d3-8143-f0328911e0a3", + "origin": "Delegated (Power BI Service)", + "value": "GraphQL.Execute.All" + }, { "description": "Allows modifying datamarts on the user’s behalf.", "displayName": "Read and write datamarts", @@ -5550,13 +5571,6 @@ "origin": "Delegated (Power BI Service)", "value": "Datamart.ReadWrite.All" }, - { - "description": " ", - "displayName": "Datamart.Reshare (retired)", - "id": "44abf802-73c1-42f4-a26f-915b4c27fa8f", - "origin": "Delegated (Power BI Service)", - "value": "Datamart.Reshare.All" - }, { "description": "Allows the app to make API calls that require execute permissions on all data pipelines, on behalf of the signed-in user.", "displayName": "Make API calls that require execute permissions all data pipelines", @@ -5614,11 +5628,18 @@ "value": "Environment.Execute.All" }, { - "description": "Allows modifying environment items on the user’s behalf.", - "displayName": "Read and write environment items", - "id": "995d4201-6a2d-45c6-bad2-9f2aba89298d", + "description": " ", + "displayName": "Datamart.Reshare (retired)", + "id": "44abf802-73c1-42f4-a26f-915b4c27fa8f", "origin": "Delegated (Power BI Service)", - "value": "Environment.ReadWrite.All" + "value": "Datamart.Reshare.All" + }, + { + "description": "Allows the app to make API calls that require restore permissions on all Warehouses, on behalf of the signed-in user.", + "displayName": "Make API calls that require restore permissions on all Warehouses", + "id": "7da32ee4-ec68-43a4-b13a-b5385ad9770e", + "origin": "Delegated (Power BI Service)", + "value": "Warehouse.Restore.All" }, { "description": "Allows executing GraphQLApis on the user’s behalf.", @@ -5627,13 +5648,6 @@ "origin": "Delegated (Power BI Service)", "value": "GraphQLApi.Execute.All" }, - { - "description": "Allows reading GraphQLApis on the user’s behalf.", - "displayName": "Read GraphQLApis", - "id": "deae611f-920b-422f-805e-f635080c4cfb", - "origin": "Delegated (Power BI Service)", - "value": "GraphQLApi.Read.All" - }, { "description": "Allows modifying GraphQLApis on the user’s behalf.", "displayName": "Read and write GraphQLApis", @@ -5845,11 +5859,11 @@ "value": "ItemMetadata.Read.All" }, { - "description": "Allows the app to create and manage external data shares for all mirrored Databases, on behalf of the signed-in user.", - "displayName": "Allows the app to create and manage external data shares for all mirrored Databases", - "id": "eb433b13-ec6d-487b-8411-b5fadda75072", + "description": "Allows reading GraphQLApis on the user’s behalf.", + "displayName": "Read GraphQLApis", + "id": "deae611f-920b-422f-805e-f635080c4cfb", "origin": "Delegated (Power BI Service)", - "value": "MirroredDatabase.ExternalDataShare.All" + "value": "GraphQLApi.Read.All" }, { "description": "Allows the app to make API calls that can read and write the item metadata of all Fabric items, on behalf of the signed-in user.", @@ -5921,6 +5935,13 @@ "origin": "Delegated (Power BI Service)", "value": "KQLDashboard.Execute.All" }, + { + "description": "Allows modifying data agents on the user’s behalf.", + "displayName": "Read and write data agents", + "id": "c23fda5c-561f-4890-ad72-5f57bb7496fd", + "origin": "Delegated (Power BI Service)", + "value": "DataAgent.ReadWrite.All" + }, { "description": " ", "displayName": "WarehouseSnapshot.Execute (retired)", @@ -5928,13 +5949,6 @@ "origin": "Delegated (Power BI Service)", "value": "WarehouseSnapshot.Execute.All" }, - { - "description": "Allows reading warehouse snapshots on the user’s behalf.", - "displayName": "Read warehouse snapshots", - "id": "fe27a477-ed49-4762-9157-5a22eec929a7", - "origin": "Delegated (Power BI Service)", - "value": "WarehouseSnapshot.Read.All" - }, { "description": "Allows modifying warehouse snapshots on the user’s behalf.", "displayName": "Read and write warehouse snapshots", @@ -6811,11 +6825,11 @@ "value": "Purview.Assets.Delete" }, { - "description": " ", - "displayName": "DataAgent.Reshare (retired)", - "id": "82b1d51c-42df-4ba9-9aee-bbba1e3f2ab7", + "description": "Allows reading warehouse snapshots on the user’s behalf.", + "displayName": "Read warehouse snapshots", + "id": "fe27a477-ed49-4762-9157-5a22eec929a7", "origin": "Delegated (Power BI Service)", - "value": "DataAgent.Reshare.All" + "value": "WarehouseSnapshot.Read.All" }, { "description": "Allows the app create an on-demand Skype meeting and join guest users into Skype for Business services", @@ -7084,25 +7098,32 @@ "value": "PhysicalRP.ReadWrite" }, { - "description": "Allows the Application to read and write the user's data pertaining to itself in the Intune Mobile Application Management service", - "displayName": "Read and Write the User's App Management data", - "id": "3c7192af-9629-4473-9276-d35e4e4b36c5", - "origin": "Delegated (Microsoft Mobile Application Management)", - "value": "DeviceManagementManagedApps.ReadWrite" + "description": "Allows the application to list and query any shared user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export external user data (e.g. customer content or system-generated logs), for any user associated with the current tenant on behalf of the signed-in user.", + "displayName": "Read all shared cross-tenant user profiles and export their data", + "id": "759dcd16-3c90-463c-937e-abf89f991c18", + "origin": "Delegated (Microsoft Graph)", + "value": "CrossTenantUserProfileSharing.Read.All" }, { - "description": "Allows modifying data agents on the user’s behalf.", - "displayName": "Read and write data agents", - "id": "c23fda5c-561f-4890-ad72-5f57bb7496fd", + "description": "Allows reading data agents on the user’s behalf.", + "displayName": "Read data agents", + "id": "40fa91d5-73ef-412c-a8c8-c8658670d0eb", "origin": "Delegated (Power BI Service)", - "value": "DataAgent.ReadWrite.All" + "value": "DataAgent.Read.All" }, { - "description": "Allows executing data agents on the user’s behalf.", - "displayName": "Execute data agents", - "id": "c6756612-6853-4145-a661-90c1d045b2dc", + "description": " ", + "displayName": "Dashboard.Reshare (retired)", + "id": "c67b16d3-b5b8-4c87-8ca0-a8e00c6d6ff3", "origin": "Delegated (Power BI Service)", - "value": "DataAgent.Execute.All" + "value": "Dashboard.Reshare.All" + }, + { + "description": "Allows the app to read company places (conference rooms and room lists) for calendar events and other applications, without a signed-in user.", + "displayName": "Read all company places", + "id": "4830e04b-48ac-4de5-bbd9-8aceb58e506b", + "origin": "Application (Office 365 Exchange Online)", + "value": "Place.Read.All" }, { "description": "Allow application to access user’s mailbox via POP protocol", @@ -7216,6 +7237,13 @@ "origin": "Delegated (Office 365 Exchange Online)", "value": "Contacts.Read.Shared" }, + { + "description": "Allows the application to read and write tenant-wide people settings without a signed-in user.", + "displayName": "Read and write all tenant-wide people settings", + "id": "98ed40ef-611a-4479-bd35-eaa7863e946a", + "origin": "Application (Office 365 Exchange Online)", + "value": "PeopleSettings.ReadWrite.All" + }, { "description": "Allows the app to create, read, update, and delete user contacts.", "displayName": "Read and write user contacts", @@ -7224,32 +7252,25 @@ "value": "Contacts.ReadWrite" }, { - "description": "Allows the app to read company places (conference rooms and room lists) for calendar events and other applications, without a signed-in user.", - "displayName": "Read all company places", - "id": "4830e04b-48ac-4de5-bbd9-8aceb58e506b", + "description": "Allows the application to read tenant-wide people settings without a signed-in user.", + "displayName": "Read all tenant-wide people settings", + "id": "789ef6b5-4ecc-4f61-b6b3-66ef3109173c", "origin": "Application (Office 365 Exchange Online)", - "value": "Place.Read.All" - }, - { - "description": "Allows the app to create, read, update, and delete contacts a user has permissions to, including their own and shared contacts.", - "displayName": "Read and write user and shared contacts ", - "id": "44882612-f346-430a-b938-4f00ee1c77a7", - "origin": "Delegated (Office 365 Exchange Online)", - "value": "Contacts.ReadWrite.All" + "value": "PeopleSettings.Read.All" }, { - "description": "Allows the application to read and write tenant-wide people settings without a signed-in user.", - "displayName": "Read and write all tenant-wide people settings", - "id": "98ed40ef-611a-4479-bd35-eaa7863e946a", + "description": "Allows the app to read the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed SKUs and tenant branding information.", + "displayName": "Organization.Read.All", + "id": "15f260d6-f874-4366-8672-6b3658c5a09b", "origin": "Application (Office 365 Exchange Online)", - "value": "PeopleSettings.ReadWrite.All" + "value": "Organization.Read.All" }, { - "description": "Allows the app to read and write the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed SKUs and tenant branding information.", - "displayName": "Organization.ReadWrite.All", - "id": "c976971c-a54d-4835-a240-2479e3dac74a", - "origin": "Application (Office 365 Exchange Online)", - "value": "Organization.ReadWrite.All" + "description": "Allow the application full access to the OCM service on behalf of the signed-in user", + "displayName": "Have full access to the OCM Service ", + "id": "9454efbe-3f0a-4074-9ec5-a25adefb6f87", + "origin": "Delegated (O365SBRM Service)", + "value": "user_impersonation" }, { "description": "Allows the app to read events of all calendars without a signed-in user.", @@ -7364,18 +7385,18 @@ "value": "MailboxSettings.ReadWrite" }, { - "description": "Allows the app to read the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed SKUs and tenant branding information.", - "displayName": "Organization.Read.All", - "id": "15f260d6-f874-4366-8672-6b3658c5a09b", + "description": "Allows the app to read and write the organization and related resources, on behalf of the signed-in user. Related resources include things like subscribed SKUs and tenant branding information.", + "displayName": "Organization.ReadWrite.All", + "id": "c976971c-a54d-4835-a240-2479e3dac74a", "origin": "Application (Office 365 Exchange Online)", - "value": "Organization.Read.All" + "value": "Organization.ReadWrite.All" }, { - "description": "Allows the application to read tenant-wide people settings without a signed-in user.", - "displayName": "Read all tenant-wide people settings", - "id": "789ef6b5-4ecc-4f61-b6b3-66ef3109173c", - "origin": "Application (Office 365 Exchange Online)", - "value": "PeopleSettings.Read.All" + "description": "Allows the app to create, read, update, and delete contacts a user has permissions to, including their own and shared contacts.", + "displayName": "Read and write user and shared contacts ", + "id": "44882612-f346-430a-b938-4f00ee1c77a7", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "Contacts.ReadWrite.All" }, { "description": "Allows the app to create, read, update, and delete contacts a user has permissions to, including their own and shared contacts.", @@ -7390,13 +7411,13 @@ "id": "266d2589-20b5-4f91-9a03-89247d1be8da", "origin": "Delegated (Office 365 Exchange Online)", "value": "EAS.AccessAsUser.All" - }, - { - "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange Web Services.", - "displayName": "Access mailboxes as the signed-in user via Exchange Web Services", - "id": "3b5f3d61-589b-4a3c-a359-5dd4b5ee5bd5", + }, + { + "description": "This allows application to host MyDay Owa powered experience for both user and shared mailbox and calendar", + "displayName": "OPX.MyDay.All", + "id": "d056cee4-aed2-4aa4-b2a9-292fe18b06d2", "origin": "Delegated (Office 365 Exchange Online)", - "value": "EWS.AccessAsUser.All" + "value": "OPX.MyDay.All" }, { "description": "This allows application to host MyDay Owa powered experience for shared mailbox and calendar", @@ -7510,20 +7531,6 @@ "origin": "Delegated (Office 365 Exchange Online)", "value": "User.Read" }, - { - "description": "Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user.", - "displayName": "Read all users' full profiles", - "id": "eb665d05-7f76-4d1b-b176-1cfc814e668d", - "origin": "Delegated (Office 365 Exchange Online)", - "value": "User.Read.All" - }, - { - "description": "This allows application to host MyDay Owa powered experience for both user and shared mailbox and calendar", - "displayName": "OPX.MyDay.All", - "id": "d056cee4-aed2-4aa4-b2a9-292fe18b06d2", - "origin": "Delegated (Office 365 Exchange Online)", - "value": "OPX.MyDay.All" - }, { "description": "This allows the application to host MyDay Owa powered experience", "displayName": "OPX.MyDay", @@ -7545,6 +7552,20 @@ "origin": "Delegated (Office 365 Exchange Online)", "value": "Notes.Read" }, + { + "description": "Allows the app to create, read, update, and delete user's mailbox settings. Does not include permission to send mail.", + "displayName": "Read and write user mailbox settings", + "id": "2e83d72d-8895-4b66-9eea-abb43449ab8b", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "MailboxSettings.ReadWrite" + }, + { + "description": "Allows the app to have the same access to mailboxes as the signed-in user via Exchange Web Services.", + "displayName": "Access mailboxes as the signed-in user via Exchange Web Services", + "id": "3b5f3d61-589b-4a3c-a359-5dd4b5ee5bd5", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "EWS.AccessAsUser.All" + }, { "description": "Allows the app to manage a limited set of Exchange Online configuration objects via the adminapi/v2.0 endpoint. This permission is intended for specific scenarios and requires appropriate Exchange RBAC role assignments. This permission replaces the previous Exchange.ManageV2 permission.", "displayName": "Manage Exchange Online Admin API", @@ -7594,6 +7615,13 @@ "origin": "Delegated (Office 365 Exchange Online)", "value": "Mail.Read" }, + { + "description": "A placeholder scope for preauth", + "displayName": "PreAuthPlaceholder", + "id": "25b4ea33-257e-47f5-b778-8df9c7e10548", + "origin": "Delegated (o365.servicecommunications.microsoft.com)", + "value": "PreAuthPlaceholder" + }, { "description": "Allows the app to read mail a user can access, including their own and shared mail.", "displayName": "Read user and shared mail ", @@ -7602,18 +7630,11 @@ "value": "Mail.Read.All" }, { - "description": "Allow the application full access to the OCM service on behalf of the signed-in user", - "displayName": "Have full access to the OCM Service ", - "id": "9454efbe-3f0a-4074-9ec5-a25adefb6f87", - "origin": "Delegated (O365SBRM Service)", - "value": "user_impersonation" - }, - { - "description": "Allows the app to read mail a user can access, including their own and shared mail.", - "displayName": "Read user and shared mail ", - "id": "1d894596-c906-42b1-8422-9360440c1c0c", + "description": "Allows the app to read the signed-in user's mailbox except body, previewBody, attachments and any extended properties.", + "displayName": "Read user basic mail", + "id": "dab085de-3e14-432f-a47f-84b6457059c4", "origin": "Delegated (Office 365 Exchange Online)", - "value": "Mail.Read.Shared" + "value": "Mail.ReadBasic" }, { "description": "Allows the app to create, read, update, and delete email in user mailboxes. Does not include permission to send mail.", @@ -7665,32 +7686,11 @@ "value": "MailboxSettings.Read" }, { - "description": "Allows the app to create, read, update, and delete user's mailbox settings. Does not include permission to send mail.", - "displayName": "Read and write user mailbox settings", - "id": "2e83d72d-8895-4b66-9eea-abb43449ab8b", - "origin": "Delegated (Office 365 Exchange Online)", - "value": "MailboxSettings.ReadWrite" - }, - { - "description": "Allows the app to read the signed-in user's mailbox except body, previewBody, attachments and any extended properties.", - "displayName": "Read user basic mail", - "id": "dab085de-3e14-432f-a47f-84b6457059c4", - "origin": "Delegated (Office 365 Exchange Online)", - "value": "Mail.ReadBasic" - }, - { - "description": "Allows the app to read a basic set of profile properties of users in your company or school on behalf of the signed-in user. Includes display name, photo, and email address.", - "displayName": "Read all users' basic profiles", - "id": "6222dbab-a24c-4210-9d91-2f47cf565614", + "description": "Allows the app to read mail a user can access, including their own and shared mail.", + "displayName": "Read user and shared mail ", + "id": "1d894596-c906-42b1-8422-9360440c1c0c", "origin": "Delegated (Office 365 Exchange Online)", - "value": "User.ReadBasic.All" - }, - { - "description": "A placeholder scope for preauth", - "displayName": "PreAuthPlaceholder", - "id": "25b4ea33-257e-47f5-b778-8df9c7e10548", - "origin": "Delegated (o365.servicecommunications.microsoft.com)", - "value": "PreAuthPlaceholder" + "value": "Mail.Read.Shared" }, { "description": "This allows teams users to access HAPI", @@ -7699,6 +7699,20 @@ "origin": "Delegated (O365 Demeter)", "value": "teams" }, + { + "description": "Allows callers to read subscriptions", + "displayName": "subscriptions.read", + "id": "b24afad3-a979-4f67-8e97-6da6301b3c2e", + "origin": "Delegated (O365 Demeter)", + "value": "subscriptions.read" + }, + { + "description": "Allows reading library resources", + "displayName": "Visitor", + "id": "91fb9a45-6b1c-4d38-b915-4f1987a64c1c", + "origin": "Application (Microsoft Premonition)", + "value": "Library.Read" + }, { "description": "Allows for all operations of library resources", "displayName": "Librarian", @@ -7811,20 +7825,6 @@ "origin": "Delegated (Microsoft Service Trust)", "value": "ComplianceManager.ReadWrite.All" }, - { - "description": "Allows users to read documents.", - "displayName": "Read all documents", - "id": "e808ab43-7555-447f-8b87-1d6a5c5038ef", - "origin": "Delegated (Microsoft Service Trust)", - "value": "Documents.Read.All" - }, - { - "description": "Allows reading library resources", - "displayName": "Visitor", - "id": "91fb9a45-6b1c-4d38-b915-4f1987a64c1c", - "origin": "Application (Microsoft Premonition)", - "value": "Library.Read" - }, { "description": "Allows control plane operations of VNETs owned by the user", "displayName": "VNET.ReadWrite", @@ -7832,6 +7832,13 @@ "origin": "Delegated (Microsoft Power Platform Service - PROD)", "value": "VNET.ReadWrite" }, + { + "description": "Allows data plane access to all VNETs on the system", + "displayName": "VNET.Read.All", + "id": "e2159836-d709-4343-a518-8bb0e5744afa", + "origin": "Application (Microsoft Power Platform Service - PROD)", + "value": "VNET.Read.All" + }, { "description": "Allow access the Office People API", "displayName": "Access the Office People API", @@ -7839,6 +7846,27 @@ "origin": "Delegated (Microsoft People Cards Service)", "value": "User.ReadWrite" }, + { + "description": "Access the Office People API", + "displayName": "Access to log on", + "id": "07c496ee-38d1-46df-b73d-45e1ff46d11e", + "origin": "Delegated (Microsoft People Cards Service)", + "value": "User.Read.All" + }, + { + "description": "Allows the Application to read and write the user's data pertaining to itself in the Intune Mobile Application Management service", + "displayName": "Read and Write the User's App Management data", + "id": "3c7192af-9629-4473-9276-d35e4e4b36c5", + "origin": "Delegated (Microsoft Mobile Application Management)", + "value": "DeviceManagementManagedApps.ReadWrite" + }, + { + "description": "Allows the app to uninstall Microsoft Entra Connect Sync Agent and offboard SSPR for the tenant", + "displayName": "Read, write and manage Microsoft Entra Connect Sync Agent", + "id": "69201c67-737b-4a20-8f16-e0c8c64e0b0e", + "origin": "Application (Microsoft password reset service)", + "value": "PasswordWriteback.OffboardClient.All" + }, { "description": "Allows the app to refresh and recreate on-premises configuration for Microsoft self-service password reset.", "displayName": "Read, write and manage self-service password reset writeback configuration", @@ -7882,18 +7910,18 @@ "value": "Chat.ReadWrite" }, { - "description": "Allow access the Office People API", - "displayName": "Access the Office People API", - "id": "1c95d935-5ae8-4181-944c-746c8b105528", - "origin": "Delegated (Microsoft People Cards Service)", - "value": "Files.Read" + "description": "Allows users to read documents.", + "displayName": "Read all documents", + "id": "e808ab43-7555-447f-8b87-1d6a5c5038ef", + "origin": "Delegated (Microsoft Service Trust)", + "value": "Documents.Read.All" }, { "description": "Allow access the Office People API", "displayName": "Access the Office People API", - "id": "9beac4c9-e7ab-4507-9600-1f78e7d6097e", + "id": "1c95d935-5ae8-4181-944c-746c8b105528", "origin": "Delegated (Microsoft People Cards Service)", - "value": "Files.ReadWrite" + "value": "Files.Read" }, { "description": "Allow access the Office People API", @@ -7952,25 +7980,18 @@ "value": "User.Read" }, { - "description": "Access the Office People API", - "displayName": "Access to log on", - "id": "07c496ee-38d1-46df-b73d-45e1ff46d11e", + "description": "Allow access the Office People API", + "displayName": "Access the Office People API", + "id": "9beac4c9-e7ab-4507-9600-1f78e7d6097e", "origin": "Delegated (Microsoft People Cards Service)", - "value": "User.Read.All" - }, - { - "description": "Allows data plane access to all VNETs on the system", - "displayName": "VNET.Read.All", - "id": "e2159836-d709-4343-a518-8bb0e5744afa", - "origin": "Application (Microsoft Power Platform Service - PROD)", - "value": "VNET.Read.All" + "value": "Files.ReadWrite" }, { - "description": "Our app will be a one stop shop for current and prospective customers who need Security, Privacy, and Compliance information around Microsoft Cloud (Azure, Dynamics CRM Online and Office 365). It should be open any tenant who has AAD record – trial tenants as well as paid tenant across Microsoft Cloud.", - "displayName": "Microsoft Service Trust", - "id": "b55dae21-0932-4324-a1cd-45a046d7a6e1", - "origin": "Delegated (Microsoft Service Trust)", - "value": "Trust.Content.All" + "description": "Allows the app to read the full set of profile properties, reports, and managers of other users in your organization, on behalf of the signed-in user.", + "displayName": "Read all users' full profiles", + "id": "eb665d05-7f76-4d1b-b176-1cfc814e668d", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "User.Read.All" }, { "description": "Allows the app to run advanced hunting queries", @@ -7980,11 +8001,11 @@ "value": "AdvancedHunting.Read.All" }, { - "description": "Allows the app to create or update any custom detection rule", - "displayName": "Read and write all custom detection rules", - "id": "a7deff90-e2f5-4e4e-83a3-2c74e7002e28", - "origin": "Application (Microsoft Threat Protection)", - "value": "CustomDetections.ReadWrite.All" + "description": "Read Access To MDLRest APIs", + "displayName": "MDLRest.Read", + "id": "9b5904c8-49e7-4d21-81c0-118a2a9c7d81", + "origin": "Delegated (Microsoft.MileIQ.RESTService)", + "value": "MDLRest.Read" }, { "description": "Read Write Access To MDLRest APIs", @@ -8098,20 +8119,6 @@ "origin": "Delegated (O365 Demeter)", "value": "proposal.read" }, - { - "description": "Allows callers to read subscriptions", - "displayName": "subscriptions.read", - "id": "b24afad3-a979-4f67-8e97-6da6301b3c2e", - "origin": "Delegated (O365 Demeter)", - "value": "subscriptions.read" - }, - { - "description": "Read Access To MDLRest APIs", - "displayName": "MDLRest.Read", - "id": "9b5904c8-49e7-4d21-81c0-118a2a9c7d81", - "origin": "Delegated (Microsoft.MileIQ.RESTService)", - "value": "MDLRest.Read" - }, { "description": "MileIQ.All", "displayName": "MileIQ.All", @@ -8119,6 +8126,20 @@ "origin": "Delegated (Microsoft.MileIQ.Dashboard)", "value": "MileIQ.All" }, + { + "description": "Allow the application full access to the Azure Event Hubs service on behalf of the signed-in user", + "displayName": "Have full access to the Azure Event Hub service", + "id": "7d388411-3845-4cfc-aa69-33192f4b9735", + "origin": "Delegated (Microsoft.EventHubs)", + "value": "user_impersonation" + }, + { + "description": "Allows the app to create or update any custom detection rule", + "displayName": "Read and write all custom detection rules", + "id": "a7deff90-e2f5-4e4e-83a3-2c74e7002e28", + "origin": "Application (Microsoft Threat Protection)", + "value": "CustomDetections.ReadWrite.All" + }, { "description": "Allows the app to read any incident", "displayName": "Read all incidents", @@ -8168,6 +8189,13 @@ "origin": "Delegated (Microsoft Visual Studio Services API)", "value": "all" }, + { + "description": "Our app will be a one stop shop for current and prospective customers who need Security, Privacy, and Compliance information around Microsoft Cloud (Azure, Dynamics CRM Online and Office 365). It should be open any tenant who has AAD record – trial tenants as well as paid tenant across Microsoft Cloud.", + "displayName": "Microsoft Service Trust", + "id": "b55dae21-0932-4324-a1cd-45a046d7a6e1", + "origin": "Delegated (Microsoft Service Trust)", + "value": "Trust.Content.All" + }, { "description": "Allow the application to delete feature flags on behalf of the signed-in user.", "displayName": "Delete Feature Flags", @@ -8176,11 +8204,11 @@ "value": "FeatureFlag.Delete" }, { - "description": "Allow the application to read feature flags on behalf of the signed-in user.", - "displayName": "Read Feature Flags", - "id": "dd4449fe-4788-4656-b3f2-4f066e14478a", + "description": "Allow the application to write feature flags on behalf of the signed-in user.", + "displayName": "Write Feature Flags", + "id": "f3cb665c-6320-4ae2-996d-b58707ade4c3", "origin": "Delegated (Microsoft.Azconfig)", - "value": "FeatureFlag.Read" + "value": "FeatureFlag.Write" }, { "description": "Allow the application to delete key-values on behalf of the signed-in user.", @@ -8232,23 +8260,23 @@ "value": "Notifications.Write" }, { - "description": "Allow the application full access to the Azure Event Hubs service on behalf of the signed-in user", - "displayName": "Have full access to the Azure Event Hub service", - "id": "7d388411-3845-4cfc-aa69-33192f4b9735", - "origin": "Delegated (Microsoft.EventHubs)", - "value": "user_impersonation" + "description": "Allow the application to read feature flags on behalf of the signed-in user.", + "displayName": "Read Feature Flags", + "id": "dd4449fe-4788-4656-b3f2-4f066e14478a", + "origin": "Delegated (Microsoft.Azconfig)", + "value": "FeatureFlag.Read" }, { - "description": "Allow the application to write feature flags on behalf of the signed-in user.", - "displayName": "Write Feature Flags", - "id": "f3cb665c-6320-4ae2-996d-b58707ade4c3", - "origin": "Delegated (Microsoft.Azconfig)", - "value": "FeatureFlag.Write" + "description": "Allows executing data agents on the user’s behalf.", + "displayName": "Execute data agents", + "id": "c6756612-6853-4145-a661-90c1d045b2dc", + "origin": "Delegated (Power BI Service)", + "value": "DataAgent.Execute.All" }, { - "description": "Allows the app to read a basic set of profile properties of other users in your organization on behalf of the signed-in user. This includes display name, first and last name, email address and photo.", + "description": "Allows the app to read a basic set of profile properties of users in your company or school on behalf of the signed-in user. Includes display name, photo, and email address.", "displayName": "Read all users' basic profiles", - "id": "9b005f11-86f0-45f7-8c27-4fff5d849916", + "id": "6222dbab-a24c-4210-9d91-2f47cf565614", "origin": "Delegated (Office 365 Exchange Online)", "value": "User.ReadBasic.All" }, @@ -8260,11 +8288,11 @@ "value": "User.ReadWrite" }, { - "description": "c", - "displayName": "activitydata.tenant.read", - "id": "ba4ca83c-e834-4e66-bfe1-df738f63b557", - "origin": "Application (Office 365 Information Protection)", - "value": "activitydata.tenant.read" + "description": "Allows the app to read documents and list items in all site collections on behalf of the signed-in user.", + "displayName": "Read items in all site collections", + "id": "4e0d77b0-96ba-4398-af14-3baa780278f4", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "AllSites.Read" }, { "description": "Allows the app to create, read, update, and delete documents and list items in all site collections on behalf of the signed-in user.", @@ -8378,6 +8406,13 @@ "origin": "Delegated (Office 365 SharePoint Online)", "value": "Sites.Search.All" }, + { + "description": "Allows the app to read, create, update, and delete document libraries and lists in all site collections on behalf of the signed-in user.", + "displayName": "Read and write items and lists in all site collections", + "id": "b3f70a70-8a4b-4f95-9573-d71c496a53f4", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "AllSites.Manage" + }, { "description": "Allows the app to access a subset of site collections with a signed-in user. The specific site collections and the permissions granted will be configured in SharePoint Online.", "displayName": "Access selected site collections", @@ -8386,32 +8421,25 @@ "value": "Sites.Selected" }, { - "description": "Allows the app to read documents and list items in all site collections on behalf of the signed-in user.", - "displayName": "Read items in all site collections", - "id": "4e0d77b0-96ba-4398-af14-3baa780278f4", - "origin": "Delegated (Office 365 SharePoint Online)", - "value": "AllSites.Read" - }, - { - "description": "Allows the app to read site collection metadata using the SharePoint admin site, on behalf of the signed-in user.", - "displayName": "Can view site collection metadata from the admin site", - "id": "ee5c91f0-be0b-463e-85c9-57f0514c3d29", + "description": "Allows the app to have full control of all site collections on behalf of the signed-in user.", + "displayName": "Have full control of all site collections", + "id": "56680e0d-d2a3-4ae1-80d8-3c4f2100e3d0", "origin": "Delegated (Office 365 SharePoint Online)", - "value": "SitesMetadataAdmin.Read.All" + "value": "AllSites.FullControl" }, { - "description": "Allows the app to read, create, update, and delete document libraries and lists in all site collections on behalf of the signed-in user.", - "displayName": "Read and write items and lists in all site collections", - "id": "b3f70a70-8a4b-4f95-9573-d71c496a53f4", - "origin": "Delegated (Office 365 SharePoint Online)", - "value": "AllSites.Manage" + "description": "Allows the app to read user profiles without a signed in user.", + "displayName": "Read user profiles", + "id": "df021288-bdef-4463-88db-98f22de89214", + "origin": "Application (Office 365 SharePoint Online)", + "value": "User.Read.All" }, { - "description": "Allows the app to read and update user profiles and to read basic site info without a signed in user.", - "displayName": "Read and write user profiles", - "id": "741f803b-c850-494e-b5df-cde7c675a1ca", + "description": "Allows the app to read and write migration data via the SharePoint admin site without a signed-in user.", + "displayName": "Read and write access to migration data on the SharePoint admin site", + "id": "dfe5a59c-77fe-436b-9a47-375a284cf302", "origin": "Application (Office 365 SharePoint Online)", - "value": "User.ReadWrite.All" + "value": "Migration.ReadWrite.All" }, { "description": "Allow the application to provision OneDrive for Business drives for users in the tenant, without a signed-in user.", @@ -8526,18 +8554,18 @@ "value": "TermStore.ReadWrite.All" }, { - "description": "Allows the app to read user profiles without a signed in user.", - "displayName": "Read user profiles", - "id": "df021288-bdef-4463-88db-98f22de89214", + "description": "Allows the app to read and update user profiles and to read basic site info without a signed in user.", + "displayName": "Read and write user profiles", + "id": "741f803b-c850-494e-b5df-cde7c675a1ca", "origin": "Application (Office 365 SharePoint Online)", - "value": "User.Read.All" + "value": "User.ReadWrite.All" }, { - "description": "Allows the app to have full control of all site collections on behalf of the signed-in user.", - "displayName": "Have full control of all site collections", - "id": "56680e0d-d2a3-4ae1-80d8-3c4f2100e3d0", + "description": "Allows the app to read site collection metadata using the SharePoint admin site, on behalf of the signed-in user.", + "displayName": "Can view site collection metadata from the admin site", + "id": "ee5c91f0-be0b-463e-85c9-57f0514c3d29", "origin": "Delegated (Office 365 SharePoint Online)", - "value": "AllSites.FullControl" + "value": "SitesMetadataAdmin.Read.All" }, { "description": "Allows the app to read and write site collection metadata using the SharePoint admin site, on behalf of the signed-in user.", @@ -8554,11 +8582,11 @@ "value": "TaskStatus.Submit" }, { - "description": "Allows the app to read tenant reports via the SharePoint admin site, on behalf of the signed-in user.", - "displayName": "Can view tenant reports from the admin site", - "id": "97533022-c395-42ce-bcf7-7d554ac912fc", - "origin": "Delegated (Office 365 SharePoint Online)", - "value": "TenantReports.Read.All" + "description": "Allow the application to access Azure Data Explorer on behalf of the signed-in user.", + "displayName": "Access Azure Data Explorer", + "id": "eaf7943f-ddfe-4442-96af-9419cf9522f3", + "origin": "Delegated (Power BI Service)", + "value": "Code.AccessAzureDataExplorer.All" }, { "description": "Allow the application full access to the Azure Data Lake service on behalf of the signed-in user.", @@ -8672,20 +8700,6 @@ "origin": "Delegated (Power BI Service)", "value": "Dashboard.ReadWrite.All" }, - { - "description": " ", - "displayName": "Dashboard.Reshare (retired)", - "id": "c67b16d3-b5b8-4c87-8ca0-a8e00c6d6ff3", - "origin": "Delegated (Power BI Service)", - "value": "Dashboard.Reshare.All" - }, - { - "description": "Allow the application to access Azure Data Explorer on behalf of the signed-in user.", - "displayName": "Access Azure Data Explorer", - "id": "eaf7943f-ddfe-4442-96af-9419cf9522f3", - "origin": "Delegated (Power BI Service)", - "value": "Code.AccessAzureDataExplorer.All" - }, { "description": "Allows reading Iceberg and Delta table catalog metadata from the external provider on the users behalf.", "displayName": "Read Iceberg and Delta table catalog metadata from the provider", @@ -8707,6 +8721,20 @@ "origin": "Delegated (Power BI Service)", "value": "Capacity.ReadWrite.All" }, + { + "description": "The app can view all Power BI Premium and Power BI Embedded capacities that the signed in user has access to.", + "displayName": "View all capacities", + "id": "76e2ebd5-0dfb-4a5b-93c7-ed89e0362834", + "origin": "Delegated (Power BI Service)", + "value": "Capacity.Read.All" + }, + { + "description": "Allows the app to read tenant reports via the SharePoint admin site, on behalf of the signed-in user.", + "displayName": "Can view tenant reports from the admin site", + "id": "97533022-c395-42ce-bcf7-7d554ac912fc", + "origin": "Delegated (Office 365 SharePoint Online)", + "value": "TenantReports.Read.All" + }, { "description": "Allows the app to read and write tenant reports via the SharePoint admin site, on behalf of the signed-in user.", "displayName": "Can view and edit tenant reports from the admin site", @@ -8756,6 +8784,13 @@ "origin": "Application (Office365 Zoom)", "value": "eDiscovery.Jobs.Write" }, + { + "description": "Allows the app to read migration data via the SharePoint admin site without a signed-in user.", + "displayName": "Read access to migration data on the SharePoint admin site", + "id": "b7155856-e8b7-4ba1-bf43-8c9912353676", + "origin": "Application (Office 365 SharePoint Online)", + "value": "Migration.Read.All" + }, { "description": "Allow app to access compliance connector", "displayName": "Connector.Read", @@ -8763,20 +8798,6 @@ "origin": "Delegated (Office365 Zoom)", "value": "Connector.Read" }, - { - "description": "Allows the app to read and write migration data via the SharePoint admin site without a signed-in user.", - "displayName": "Read and write access to migration data on the SharePoint admin site", - "id": "dfe5a59c-77fe-436b-9a47-375a284cf302", - "origin": "Application (Office 365 SharePoint Online)", - "value": "Migration.ReadWrite.All" - }, - { - "description": "Allow app to download the ediscovery exported data", - "displayName": "eDiscovery.Export.Download", - "id": "df0d2e21-1705-4006-b158-1114609fdfbd", - "origin": "Delegated (Office365 Zoom)", - "value": "eDiscovery.Export.Download" - }, { "description": "Legacy scope used by Office Client", "displayName": "user_impersonation", @@ -8820,18 +8841,11 @@ "value": "App.Read.All" }, { - "description": "The app can view all Power BI Premium and Power BI Embedded capacities that the signed in user has access to.", - "displayName": "View all capacities", - "id": "76e2ebd5-0dfb-4a5b-93c7-ed89e0362834", - "origin": "Delegated (Power BI Service)", - "value": "Capacity.Read.All" - }, - { - "description": "Allows the app to read migration data via the SharePoint admin site without a signed-in user.", - "displayName": "Read access to migration data on the SharePoint admin site", - "id": "b7155856-e8b7-4ba1-bf43-8c9912353676", - "origin": "Application (Office 365 SharePoint Online)", - "value": "Migration.Read.All" + "description": "Allow app to download the ediscovery exported data", + "displayName": "eDiscovery.Export.Download", + "id": "df0d2e21-1705-4006-b158-1114609fdfbd", + "origin": "Delegated (Office365 Zoom)", + "value": "eDiscovery.Export.Download" }, { "description": "Allows the app to search across sharepoint content. This is used for 3S unfurl route.", @@ -8847,6 +8861,20 @@ "origin": "Delegated (Office 365 Search Service)", "value": "SubstrateSearch-Internal.ReadWrite" }, + { + "description": "Allows the app to list QnA and to read their properties on behalf of the signed-in user. ", + "displayName": "Read all QnA", + "id": "537ceb4f-32cd-4b8e-bab3-8303e950ccf0", + "origin": "Delegated (Office 365 Search Service)", + "value": "QnA.Read.All" + }, + { + "description": "c", + "displayName": "MessageTrace.Read.All", + "id": "06ab0d31-7112-476e-a479-66394bec63d6", + "origin": "Application (Office 365 Information Protection)", + "value": "MessageTrace.Read.All" + }, { "description": "c", "displayName": "MessageTraceDetail.tenant.read", @@ -8959,20 +8987,6 @@ "origin": "Application (Office 365 Information Protection)", "value": "reducedrecipient.read.all" }, - { - "description": "c", - "displayName": "Relocation.ReadWrite.All", - "id": "092afc53-fa1b-44c3-9fdf-46fcd25a5d99", - "origin": "Application (Office 365 Information Protection)", - "value": "Relocation.ReadWrite.All" - }, - { - "description": "c", - "displayName": "MessageTrace.Read.All", - "id": "06ab0d31-7112-476e-a479-66394bec63d6", - "origin": "Application (Office 365 Information Protection)", - "value": "MessageTrace.Read.All" - }, { "description": "This scope allows Apps to read tenant's MessageEventSummary data", "displayName": "messageeventsummary.tenant.read", @@ -8994,6 +9008,20 @@ "origin": "Application (Office 365 Information Protection)", "value": "InsiderRiskData.Read.All" }, + { + "description": "c", + "displayName": "EopDataInsights.AccessAsApp", + "id": "cfbd1345-3cf0-408c-8c99-1491bde7ce52", + "origin": "Application (Office 365 Information Protection)", + "value": "EopDataInsights.AccessAsApp" + }, + { + "description": "c", + "displayName": "activitydata.tenant.read", + "id": "ba4ca83c-e834-4e66-bfe1-df738f63b557", + "origin": "Application (Office 365 Information Protection)", + "value": "activitydata.tenant.read" + }, { "description": "c", "displayName": "AggConsumptionBillingReport.Read.All", @@ -9045,24 +9073,24 @@ }, { "description": "c", - "displayName": "AuditProvisioningData.Tenant.Read", - "id": "9760b448-d4d4-478b-bebc-0ebe62c935c9", + "displayName": "Relocation.ReadWrite.All", + "id": "092afc53-fa1b-44c3-9fdf-46fcd25a5d99", "origin": "Application (Office 365 Information Protection)", - "value": "AuditProvisioningData.Tenant.Read" + "value": "Relocation.ReadWrite.All" }, { "description": "c", - "displayName": "RemediationEmailResult.Read.All", - "id": "cae0e51f-af85-4f35-870d-9f024147648d", + "displayName": "AuditProvisioningData.Tenant.Read", + "id": "9760b448-d4d4-478b-bebc-0ebe62c935c9", "origin": "Application (Office 365 Information Protection)", - "value": "RemediationEmailResult.Read.All" + "value": "AuditProvisioningData.Tenant.Read" }, { "description": "c", - "displayName": "AzureActivityData.Read.All", - "id": "926c05c5-5941-491b-973a-509c2a4a2542", + "displayName": "compliancestatus.tenant.read", + "id": "59c90462-e42e-4698-8a51-196ebd407166", "origin": "Application (Office 365 Information Protection)", - "value": "AzureActivityData.Read.All" + "value": "compliancestatus.tenant.read" }, { "description": "c", @@ -9115,38 +9143,38 @@ }, { "description": "c", - "displayName": "EopDataInsights.AccessAsApp", - "id": "cfbd1345-3cf0-408c-8c99-1491bde7ce52", - "origin": "Application (Office 365 Information Protection)", - "value": "EopDataInsights.AccessAsApp" - }, - { - "description": "c", - "displayName": "compliancestatus.tenant.read", - "id": "59c90462-e42e-4698-8a51-196ebd407166", + "displayName": "AzureActivityData.Read.All", + "id": "926c05c5-5941-491b-973a-509c2a4a2542", "origin": "Application (Office 365 Information Protection)", - "value": "compliancestatus.tenant.read" + "value": "AzureActivityData.Read.All" }, { - "description": "Allows reading data agents on the user’s behalf.", - "displayName": "Read data agents", - "id": "40fa91d5-73ef-412c-a8c8-c8658670d0eb", - "origin": "Delegated (Power BI Service)", - "value": "DataAgent.Read.All" + "description": "Allows the app to read a basic set of profile properties of other users in your organization on behalf of the signed-in user. This includes display name, first and last name, email address and photo.", + "displayName": "Read all users' basic profiles", + "id": "9b005f11-86f0-45f7-8c27-4fff5d849916", + "origin": "Delegated (Office 365 Exchange Online)", + "value": "User.ReadBasic.All" }, { "description": "c", - "displayName": "RemediationEmailResult.ReadWrite.All", - "id": "dac43cb8-9b13-43b1-bc17-e7eb8fe26717", + "displayName": "RemediationEmailResult.Read.All", + "id": "cae0e51f-af85-4f35-870d-9f024147648d", "origin": "Application (Office 365 Information Protection)", - "value": "RemediationEmailResult.ReadWrite.All" + "value": "RemediationEmailResult.Read.All" }, { - "description": "c", - "displayName": "TenantLicenseStatus.Read.All", - "id": "27787a44-0423-4f0d-a417-1276c93397fb", + "description": "This allows to change RoleGroupMember to the tenant", + "displayName": "RoleGroupMember.tenant.write", + "id": "abe60d99-0a67-4250-afc0-290614d84b41", "origin": "Application (Office 365 Information Protection)", - "value": "TenantLicenseStatus.Read.All" + "value": "RoleGroupMember.tenant.write" + }, + { + "description": "Allows the application to read DLP policy events, including detected sensitive data, for your organization.", + "displayName": "Read DLP policy events including detected sensitive data", + "id": "4807a72c-ad38-4250-94c9-4eabfe26cd55", + "origin": "Application (Office 365 Management APIs)", + "value": "ActivityFeed.ReadDlp" }, { "description": "Allows the application to read service health information for your organization.", @@ -9186,16 +9214,9 @@ { "description": "Allows the application to read activity data for your organization.", "displayName": "Read activity data for your organization", - "id": "594c1fb6-4f81-4475-ae41-0c394909246c", - "origin": "Delegated (Office 365 Management APIs)", - "value": "ActivityFeed.Read" - }, - { - "description": "Allows the application to read DLP policy events, including detected sensitive data, for your organization.", - "displayName": "Read DLP policy events including detected sensitive data", - "id": "4807a72c-ad38-4250-94c9-4eabfe26cd55", + "id": "594c1fb6-4f81-4475-ae41-0c394909246c", "origin": "Delegated (Office 365 Management APIs)", - "value": "ActivityFeed.ReadDlp" + "value": "ActivityFeed.Read" }, { "description": "Allows the application to read all the AppCatalog", @@ -9226,11 +9247,11 @@ "value": "People.Read" }, { - "description": "Allows the app to list QnA and to read their properties on behalf of the signed-in user. ", - "displayName": "Read all QnA", - "id": "537ceb4f-32cd-4b8e-bab3-8303e950ccf0", - "origin": "Delegated (Office 365 Search Service)", - "value": "QnA.Read.All" + "description": "TenantLicenseStatus.Read.All", + "displayName": "TenantLicenseStatus.Read.All", + "id": "27787a44-0423-4f0d-a417-1276c93397fb", + "origin": "Delegated (Office 365 Information Protection)", + "value": "TenantLicenseStatus.Read.All" }, { "description": "RbacTenantStatus.Write", @@ -9239,6 +9260,13 @@ "origin": "Delegated (Office 365 Information Protection)", "value": "RbacTenantStatus.Write" }, + { + "description": "RbacTenantStatus.Read", + "displayName": "RbacTenantStatus.Read", + "id": "edfd2d1c-b4b5-4b83-b5e8-c38594e49c26", + "origin": "Delegated (Office 365 Information Protection)", + "value": "RbacTenantStatus.Read" + }, { "description": "c", "displayName": "ThreatSubmission.ReadWrite.All", @@ -9274,6 +9302,13 @@ "origin": "Delegated (Office 365 Information Protection)", "value": "alert.read" }, + { + "description": "c", + "displayName": "RemediationEmailResult.ReadWrite.All", + "id": "dac43cb8-9b13-43b1-bc17-e7eb8fe26717", + "origin": "Application (Office 365 Information Protection)", + "value": "RemediationEmailResult.ReadWrite.All" + }, { "description": "This allows user to change Office 365 alerts.", "displayName": "alert.write", @@ -9282,18 +9317,11 @@ "value": "alert.write" }, { - "description": "This allows to change RoleGroupMember to the tenant", - "displayName": "RoleGroupMember.tenant.write", - "id": "abe60d99-0a67-4250-afc0-290614d84b41", - "origin": "Application (Office 365 Information Protection)", - "value": "RoleGroupMember.tenant.write" - }, - { - "description": "AtpStandardPolicy.Tenant.Read", - "displayName": "AtpStandardPolicy.Tenant.Read", - "id": "b87cb2cc-0570-4e76-9606-3528d5fb44e7", + "description": "AtpStandardPolicy.Tenant.Write", + "displayName": "AtpStandardPolicy.Tenant.Write", + "id": "9945d5be-d9cb-45d0-b347-3f827c0d374d", "origin": "Delegated (Office 365 Information Protection)", - "value": "AtpStandardPolicy.Tenant.Read" + "value": "AtpStandardPolicy.Tenant.Write" }, { "description": "LabelAnalyticsActivityData.Read.All", @@ -9331,25 +9359,25 @@ "value": "RbacAccessCheck.read" }, { - "description": "RbacTenantStatus.Read", - "displayName": "RbacTenantStatus.Read", - "id": "edfd2d1c-b4b5-4b83-b5e8-c38594e49c26", + "description": "AtpStandardPolicy.Tenant.Read", + "displayName": "AtpStandardPolicy.Tenant.Read", + "id": "b87cb2cc-0570-4e76-9606-3528d5fb44e7", "origin": "Delegated (Office 365 Information Protection)", - "value": "RbacTenantStatus.Read" + "value": "AtpStandardPolicy.Tenant.Read" }, { - "description": "AtpStandardPolicy.Tenant.Write", - "displayName": "AtpStandardPolicy.Tenant.Write", - "id": "9945d5be-d9cb-45d0-b347-3f827c0d374d", - "origin": "Delegated (Office 365 Information Protection)", - "value": "AtpStandardPolicy.Tenant.Write" + "description": "Allows the app to manage restricted resources based on the other permissions granted to the app, on behalf of the signed-in user.", + "displayName": "Manage restricted resources in the directory", + "id": "cba5390f-ed6a-4b7f-b657-0efc2210ed20", + "origin": "Delegated", + "value": "Directory.Write.Restricted" }, { - "description": "Allows the application to obtain basic tenant information about another target tenant within the Azure AD ecosystem on behalf of the signed-in user.", - "displayName": "Read cross-tenant basic information", - "id": "81594d25-e88e-49cf-ac8c-fecbff49f994", + "description": "Allows the application to list and query user profile information associated with the current tenant on behalf of the signed-in user. It also permits the application to export external user data (e.g. customer content or system-generated logs), associated with the current tenant on behalf of the signed-in user.", + "displayName": "Read shared cross-tenant user profile and export data", + "id": "cb1ba48f-d22b-4325-a07f-74135a62ee41", "origin": "Delegated (Microsoft Graph)", - "value": "CrossTenantInformation.ReadBasic.All" + "value": "CrossTenantUserProfileSharing.Read" }, { "description": "Allows the app to read and write organization-wide copilot limited mode setting on behalf of the signed-in user.", @@ -9358,13 +9386,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "CopilotSettings-LimitedMode.ReadWrite" }, - { - "description": "Allows the app to read organization-wide copilot limited mode setting on behalf of the signed-in user.", - "displayName": "Read organization-wide copilot limited mode setting", - "id": "aeb2982d-632d-4155-b533-18756ab6fdd8", - "origin": "Delegated (Microsoft Graph)", - "value": "CopilotSettings-LimitedMode.Read" - }, { "description": "View discovery alerts, reports, apps, and other related information", "displayName": "discovery.read", @@ -9911,13 +9932,6 @@ "origin": "Delegated (M365DataAtRestEncryption)", "value": "CustomerKeyTenant-Internal.ReadWrite.All" }, - { - "description": "Allows the user to read DiscoveryGroup, on behalf of the signed-in user.", - "displayName": "Read DiscoveryGroup information", - "id": "034f2362-c46e-4e6b-9905-c23d1b928bce", - "origin": "Delegated (EASM API)", - "value": "DiscoveryGroup.Read.All" - }, { "description": "Allows the uesr to Read and Write DiscoveryGroup, on behalf of the signed-in user.", "displayName": "Read and Write DiscoveryGroup", @@ -10030,13 +10044,6 @@ "origin": "Delegated (Fidalgo Dataplane Public)", "value": "access_as_user" }, - { - "description": "Allows the uesr to Read and Write Asset Resource, on behalf of the signed-in user.", - "displayName": "Read and Write Asset Resource", - "id": "3e2a4aea-4efd-4851-9af9-de64ccbb354f", - "origin": "Delegated (EASM API)", - "value": "AssetResource.ReadWrite.All" - }, { "description": "Allow the application to access Fiji Storage on behalf of the signed-in user.", "displayName": "Access Fiji Storage", @@ -10045,25 +10052,32 @@ "value": "user_impersonation" }, { - "description": "Allows the user to read Asset Resource, including asset resource, asset audit trails, asset summary and asset snapshot, on behalf of the signed-in user.", - "displayName": "Read Asset Resource information", - "id": "2288f070-b471-48c3-b16b-113c05a3cfbb", + "description": "Allows the user to read DiscoveryGroup, on behalf of the signed-in user.", + "displayName": "Read DiscoveryGroup information", + "id": "034f2362-c46e-4e6b-9905-c23d1b928bce", "origin": "Delegated (EASM API)", - "value": "AssetResource.Read.All" + "value": "DiscoveryGroup.Read.All" }, { - "description": "Dynamics 365 is a business management solution that’s connecting people and processes like never before. From day one, it makes ordering, selling, invoicing, and reporting easier and faster.", - "displayName": "Access Dynamics 365 Business Central as the signed-in user", - "id": "2fb13c28-9d89-417f-9af2-ec3065bc16e6", - "origin": "Delegated (Dynamics 365 Business Central)", - "value": "Financials.ReadWrite.All" + "description": "Allow applications to access Genome RP API on behalf of the signed-in user", + "displayName": "Access Genome RP API as the signed-in user", + "id": "6fc8a23e-a3f1-4b36-9b21-8df0b525bd83", + "origin": "Delegated (Genome RP API)", + "value": "access_as_user" }, { - "description": "This allows app to run ppe tenant userscope in DLS", - "displayName": "UserScope-PPE.ReadWrite.All", - "id": "60f89623-e4c0-4fbd-84c6-a7f1e4108959", - "origin": "Application (DirectoryLookupService)", - "value": "UserScope-PPE.ReadWrite.All" + "description": "Allows the uesr to Read and Write Asset Resource, on behalf of the signed-in user.", + "displayName": "Read and Write Asset Resource", + "id": "3e2a4aea-4efd-4851-9af9-de64ccbb354f", + "origin": "Delegated (EASM API)", + "value": "AssetResource.ReadWrite.All" + }, + { + "description": "Dynamics 365 is a business management solution that’s connecting people and processes like never before. From day one, it makes ordering, selling, invoicing, and reporting easier and faster.", + "displayName": "Access as the signed-in user", + "id": "bce0976a-cb0b-473b-8800-84eda9f8e447", + "origin": "Delegated (Dynamics 365 Business Central)", + "value": "user_impersonation" }, { "description": "This allows app to access test tenant data", @@ -10179,17 +10193,17 @@ }, { "description": "Dynamics 365 is a business management solution that’s connecting people and processes like never before. From day one, it makes ordering, selling, invoicing, and reporting easier and faster.", - "displayName": "Access as the signed-in user", - "id": "bce0976a-cb0b-473b-8800-84eda9f8e447", + "displayName": "Access Dynamics 365 Business Central as the signed-in user", + "id": "2fb13c28-9d89-417f-9af2-ec3065bc16e6", "origin": "Delegated (Dynamics 365 Business Central)", - "value": "user_impersonation" + "value": "Financials.ReadWrite.All" }, { - "description": "Allow applications to access Genome RP API on behalf of the signed-in user", - "displayName": "Access Genome RP API as the signed-in user", - "id": "6fc8a23e-a3f1-4b36-9b21-8df0b525bd83", - "origin": "Delegated (Genome RP API)", - "value": "access_as_user" + "description": "Allows the user to read Asset Resource, including asset resource, asset audit trails, asset summary and asset snapshot, on behalf of the signed-in user.", + "displayName": "Read Asset Resource information", + "id": "2288f070-b471-48c3-b16b-113c05a3cfbb", + "origin": "Delegated (EASM API)", + "value": "AssetResource.Read.All" }, { "description": "Allows the app to read all external connections without a signed-in user.", @@ -10205,6 +10219,13 @@ "origin": "Application (Graph Connector Service)", "value": "ExternalConnection.Read.OwnedBy" }, + { + "description": "Allows the app to read and write all external connections without a signed-in user.", + "displayName": "ExternalConnection.ReadWrite.All", + "id": "296c3066-18b3-4977-9e2b-9d2ca1fda62c", + "origin": "Application (Graph Connector Service)", + "value": "ExternalConnection.ReadWrite.All" + }, { "description": "Invoke Diagnostics", "displayName": "Invoke Diagnostics", @@ -10346,18 +10367,11 @@ "value": "WebhookData.Read.All" }, { - "description": "Allows the app to read and write external items on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read external items of the connection that it is authorized to.", - "displayName": "ExternalItem.ReadWrite.OwnedBy", - "id": "13d477ed-f4cf-4cc0-9678-80517234742e", + "description": "Allows the app to discover and execute Copilot connector MCP tools on behalf of the signed-in user.", + "displayName": "Execute Copilot connector MCP tools as the signed-in user", + "id": "4f1e0c5f-7d24-4c8e-9a7b-3c2d1e0f5a61", "origin": "Delegated (Graph Connector Service)", - "value": "ExternalItem.ReadWrite.OwnedBy" - }, - { - "description": "Allows the app to read and write all external connections without a signed-in user.", - "displayName": "ExternalConnection.ReadWrite.All", - "id": "296c3066-18b3-4977-9e2b-9d2ca1fda62c", - "origin": "Application (Graph Connector Service)", - "value": "ExternalConnection.ReadWrite.All" + "value": "McpTools.Execute" }, { "description": "Allows the app to read and write external connections without a signed-in user. The app can only read and write external connections that it is authorized to, or it can create new external connections. ", @@ -10408,13 +10422,6 @@ "origin": "Application (Graph Connector Service)", "value": "ExternalItem.ReadWrite.OwnedBy" }, - { - "description": "Allows an application to read or write Microsoft Managed Key Data", - "displayName": "Read or Write Microsoft Managed Key Data", - "id": "ac23b270-1dc3-4ee4-bd56-d7eb945c2332", - "origin": "Application (M365DataAtRestEncryption)", - "value": "MicrosoftManagedKey-Internal.ReadWrite.All" - }, { "description": "Allows the app to read all webhook connection details without a signed-in user.", "displayName": "WebhookData.Read.All", @@ -10423,11 +10430,18 @@ "value": "WebhookData.Read.All" }, { - "description": "Allows the app to read external connections on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read external connections that it is authorized to. ", - "displayName": "ExternalConnection.Read.OwnedBy", - "id": "039455a3-0a80-4713-841a-f87a5d43bee9", + "description": "Allows an application to read or write Microsoft Managed Key Data", + "displayName": "Read or Write Microsoft Managed Key Data", + "id": "ac23b270-1dc3-4ee4-bd56-d7eb945c2332", + "origin": "Application (M365DataAtRestEncryption)", + "value": "MicrosoftManagedKey-Internal.ReadWrite.All" + }, + { + "description": "Allows the app to read all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", + "displayName": "ExternalConnection.Read.All", + "id": "feac6de7-1991-4608-8905-0bed2fd3f86f", "origin": "Delegated (Graph Connector Service)", - "value": "ExternalConnection.Read.OwnedBy" + "value": "ExternalConnection.Read.All" }, { "description": "Allows the app to read and write all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", @@ -10472,11 +10486,18 @@ "value": "ExternalItem.ReadWrite.All" }, { - "description": "Allows the app to read all external connections on behalf of a signed-in user. The signed-in user must be an administrator.", - "displayName": "ExternalConnection.Read.All", - "id": "feac6de7-1991-4608-8905-0bed2fd3f86f", + "description": "Allows the app to read and write external items on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read external items of the connection that it is authorized to.", + "displayName": "ExternalItem.ReadWrite.OwnedBy", + "id": "13d477ed-f4cf-4cc0-9678-80517234742e", "origin": "Delegated (Graph Connector Service)", - "value": "ExternalConnection.Read.All" + "value": "ExternalItem.ReadWrite.OwnedBy" + }, + { + "description": "Allows the app to read external connections on behalf of a signed-in user. The signed-in user must be an administrator. The app can only read external connections that it is authorized to. ", + "displayName": "ExternalConnection.Read.OwnedBy", + "id": "039455a3-0a80-4713-841a-f87a5d43bee9", + "origin": "Delegated (Graph Connector Service)", + "value": "ExternalConnection.Read.OwnedBy" }, { "description": "Allows the app to read agent registration information without a signed-in user.", @@ -11354,11 +11375,11 @@ "value": "Application.ReadWrite.All" }, { - "description": "Allows calling debugging APIs", - "displayName": "UserScope-PPE.Debug.All", - "id": "f6c5fb21-2e2e-42f4-a961-ffb661669441", + "description": "This allows app to run ppe tenant userscope in DLS", + "displayName": "UserScope-PPE.ReadWrite.All", + "id": "60f89623-e4c0-4fbd-84c6-a7f1e4108959", "origin": "Application (DirectoryLookupService)", - "value": "UserScope-PPE.Debug.All" + "value": "UserScope-PPE.ReadWrite.All" }, { "description": "Allows an app to read, write and manage bookings appointments, businesses, customers, services, and staff on behalf of the signed-in user.", @@ -11641,11 +11662,11 @@ "value": "Calendars.Read.All" }, { - "description": "Allows the app to read all domain properties without a signed-in user.", - "displayName": "Read domains", - "id": "dbb9058a-0e50-45d7-ae91-66909b5d4664", - "origin": "Application (Microsoft Graph)", - "value": "Domain.Read.All" + "description": "Allows calling debugging APIs", + "displayName": "UserScope-PPE.Debug.All", + "id": "f6c5fb21-2e2e-42f4-a961-ffb661669441", + "origin": "Application (DirectoryLookupService)", + "value": "UserScope-PPE.Debug.All" }, { "description": "This allows app to run test tenant userscope in DLS", @@ -11655,18 +11676,11 @@ "value": "UserScope-Dev.ReadWrite.All" }, { - "description": "This allows app to run prod tenant userscope in DLS", - "displayName": "UserScope.ReadWrite.All", - "id": "6f6965e3-3c5a-47e2-81a6-9c40ddacc7f6", + "description": "Allows calling debugging APIs", + "displayName": "UserScope-Dev.Debug.All", + "id": "d3aaaaff-f3e8-4b2f-8285-12478a43eb7d", "origin": "Application (DirectoryLookupService)", - "value": "UserScope.ReadWrite.All" - }, - { - "description": "Grants the ability to read, write, and manage symbols.", - "displayName": "Symbols (read, write and manage)", - "id": "6314624e-fd22-4945-a279-2bab145fe26e", - "origin": "Delegated (Azure DevOps)", - "value": "vso.symbols_manage" + "value": "UserScope-Dev.Debug.All" }, { "description": "Grants the ability to read and write symbols.", @@ -11780,13 +11794,6 @@ "origin": "Delegated (Azure DevOps)", "value": "vso.work_write" }, - { - "description": "Grants the ability to read symbols.", - "displayName": "Symbols (read)", - "id": "c424c3d9-15df-4837-9fa3-b9ed83b3687a", - "origin": "Delegated (Azure DevOps)", - "value": "vso.symbols" - }, { "description": "Read/Write access for all objects in the space topology", "displayName": "Read/Write Access", @@ -11795,25 +11802,32 @@ "value": "Read.Write" }, { - "description": "Grants the ability to read and query service endpoints.", - "displayName": "Service Endpoints (read and query)", - "id": "81928d24-d278-4dc9-baf9-6756e5ea62e2", + "description": "Grants the ability to read, write, and manage symbols.", + "displayName": "Symbols (read, write and manage)", + "id": "6314624e-fd22-4945-a279-2bab145fe26e", "origin": "Delegated (Azure DevOps)", - "value": "vso.serviceendpoint_query" + "value": "vso.symbols_manage" }, { - "description": "Grants the ability to read service endpoints.", - "displayName": "Service Endpoints (read)", - "id": "503568bd-aea0-4478-a536-a8325f5f0830", + "description": "Read, write access for all objects in the space topology", + "displayName": "Read, write Access", + "id": "6f0a461a-c02f-4f98-994a-b116efecc7b2", + "origin": "Delegated (Azure Digital Twins Authorization PDP)", + "value": "Read.Write" + }, + { + "description": "Grants the ability to read symbols.", + "displayName": "Symbols (read)", + "id": "c424c3d9-15df-4837-9fa3-b9ed83b3687a", "origin": "Delegated (Azure DevOps)", - "value": "vso.serviceendpoint" + "value": "vso.symbols" }, { - "description": "Grants the ability to create and read feeds and packages.", - "displayName": "Packaging (read and write)", - "id": "fb6a8425-8933-4b7f-9c4a-154568e06e5c", + "description": "Grants the ability to read, query, and manage service endpoints.", + "displayName": "Service Endpoints (read, query and manage)", + "id": "6f9f984c-a956-40b7-a6ac-4f7e3f091f96", "origin": "Delegated (Azure DevOps)", - "value": "vso.packaging_write" + "value": "vso.serviceendpoint_manage" }, { "description": "Grants the ability to read Pats for a user", @@ -11928,18 +11942,18 @@ "value": "vso.security_manage" }, { - "description": "Grants the ability to read, query, and manage service endpoints.", - "displayName": "Service Endpoints (read, query and manage)", - "id": "6f9f984c-a956-40b7-a6ac-4f7e3f091f96", + "description": "Grants the ability to read service endpoints.", + "displayName": "Service Endpoints (read)", + "id": "503568bd-aea0-4478-a536-a8325f5f0830", "origin": "Delegated (Azure DevOps)", - "value": "vso.serviceendpoint_manage" + "value": "vso.serviceendpoint" }, { - "description": "Read, write access for all objects in the space topology", - "displayName": "Read, write Access", - "id": "6f0a461a-c02f-4f98-994a-b116efecc7b2", - "origin": "Delegated (Azure Digital Twins Authorization PDP)", - "value": "Read.Write" + "description": "Grants the ability to read and query service endpoints.", + "displayName": "Service Endpoints (read and query)", + "id": "81928d24-d278-4dc9-baf9-6756e5ea62e2", + "origin": "Delegated (Azure DevOps)", + "value": "vso.serviceendpoint_query" }, { "description": "Allows the user to access consumption APIs on Microsoft Enterprise Graph", @@ -11956,11 +11970,11 @@ "value": "az-exp-backend" }, { - "description": "Allows user to read DocumentReference resources in a patient's compartment.", - "displayName": "patient.DocumentReference.read", - "id": "e2a5290a-59c6-4847-af7f-c5b16c692f24", - "origin": "Delegated (Azure Healthcare APIs)", - "value": "patient.DocumentReference.read" + "description": "Role representing Azure ExP frontend services.", + "displayName": "Azure ExP Frontend", + "id": "7f9e080a-e4af-4ac9-bc98-8b8cf39c0e40", + "origin": "Application (Azure ExP)", + "value": "az-exp-frontend" }, { "description": "Allows user to read Encounter resources in a patient's compartment.", @@ -12074,6 +12088,20 @@ "origin": "Delegated (Azure Healthcare APIs)", "value": "user.CarePlan.read" }, + { + "description": "Allows user to read CareTeam resources in their own compartment.", + "displayName": "user.CareTeam.read", + "id": "3cb5f829-1e8d-4224-9e87-678b02c8f9b1", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.CareTeam.read" + }, + { + "description": "Allows user to read DocumentReference resources in a patient's compartment.", + "displayName": "patient.DocumentReference.read", + "id": "e2a5290a-59c6-4847-af7f-c5b16c692f24", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "patient.DocumentReference.read" + }, { "description": "Allows user to read DiagnosticReport resources in a patient's compartment.", "displayName": "patient.DiagnosticReport.read", @@ -12095,20 +12123,6 @@ "origin": "Delegated (Azure Healthcare APIs)", "value": "patient.Condition.read" }, - { - "description": "Allows user to read CareTeam resources in a patient's compartment.", - "displayName": "patient.CareTeam.read", - "id": "4860ad86-f40e-4e2b-8661-ba03ee154b19", - "origin": "Delegated (Azure Healthcare APIs)", - "value": "patient.CareTeam.read" - }, - { - "description": "Role representing Azure ExP frontend services.", - "displayName": "Azure ExP Frontend", - "id": "7f9e080a-e4af-4ac9-bc98-8b8cf39c0e40", - "origin": "Application (Azure ExP)", - "value": "az-exp-frontend" - }, { "description": "Role representing Azure ExP Reader Security Group.", "displayName": "Azure ExP Reader", @@ -12151,13 +12165,6 @@ "origin": "Application (Azure Healthcare APIs)", "value": "system.all.all" }, - { - "description": "Grants the ability to create, read, update, and delete feeds and packages.", - "displayName": "Packaging (read, write, and manage)", - "id": "1c2a30a3-4b4c-42b1-bb10-6f24faf344d7", - "origin": "Delegated (Azure DevOps)", - "value": "vso.packaging_manage" - }, { "description": "Allows a user to read all resources in the system.", "displayName": "system.all.read", @@ -12166,11 +12173,18 @@ "value": "system.all.read" }, { - "description": "Grants permission to obtain launch context.", - "displayName": "launch", - "id": "fa5f9b76-5f20-4466-8b3d-6718de9744e2", + "description": "Grants the ability to create and read feeds and packages.", + "displayName": "Packaging (read and write)", + "id": "fb6a8425-8933-4b7f-9c4a-154568e06e5c", + "origin": "Delegated (Azure DevOps)", + "value": "vso.packaging_write" + }, + { + "description": "Grants permission to read information about the current logged-in user.", + "displayName": "fhirUser", + "id": "a86144c7-3e19-4b56-9675-15803eb1e617", "origin": "Delegated (Azure Healthcare APIs)", - "value": "launch" + "value": "fhirUser" }, { "description": "Asks for a patient to be selected at launch time.", @@ -12215,18 +12229,25 @@ "value": "patient.CarePlan.read" }, { - "description": "Grants permission to read information about the current logged-in user.", - "displayName": "fhirUser", - "id": "a86144c7-3e19-4b56-9675-15803eb1e617", + "description": "Allows user to read CareTeam resources in a patient's compartment.", + "displayName": "patient.CareTeam.read", + "id": "4860ad86-f40e-4e2b-8661-ba03ee154b19", "origin": "Delegated (Azure Healthcare APIs)", - "value": "fhirUser" + "value": "patient.CareTeam.read" }, { - "description": "Allows user to read CareTeam resources in their own compartment.", - "displayName": "user.CareTeam.read", - "id": "3cb5f829-1e8d-4224-9e87-678b02c8f9b1", + "description": "Grants permission to obtain launch context.", + "displayName": "launch", + "id": "fa5f9b76-5f20-4466-8b3d-6718de9744e2", "origin": "Delegated (Azure Healthcare APIs)", - "value": "user.CareTeam.read" + "value": "launch" + }, + { + "description": "Grants the ability to create, read, update, and delete feeds and packages.", + "displayName": "Packaging (read, write, and manage)", + "id": "1c2a30a3-4b4c-42b1-bb10-6f24faf344d7", + "origin": "Delegated (Azure DevOps)", + "value": "vso.packaging_manage" }, { "description": "Grants the ability to read feeds and packages.", @@ -12236,18 +12257,11 @@ "value": "vso.packaging" }, { - "description": "Provides read, write, and management access to subscriptions and read access to event metadata, including filterable field values.", - "displayName": "Notifications (manage)", - "id": "90f74b44-f4ec-4f41-9003-cb9cb64cdd32", + "description": "Provides read and write access to subscriptions and read access to event metadata, including filterable field values.", + "displayName": "Notifications (write)", + "id": "10e32108-6193-4cd9-b405-ab95c87509b0", "origin": "Delegated (Azure DevOps)", - "value": "vso.notification_manage" - }, - { - "description": "The app can view and write to all models for the signed in user and models that the user has access to.", - "displayName": "Read and Write all Models", - "id": "59ef67ea-d35f-4c6d-b1ce-95468f134ccb", - "origin": "Delegated (Azure Analysis Services)", - "value": "Model.ReadWrite.All" + "value": "vso.notification_write" }, { "description": "Allows access to the Azure API Center Data API service on behalf of the signed-in user.", @@ -12354,13 +12368,6 @@ "origin": "Delegated (Azure Data Lake)", "value": "user_impersonation" }, - { - "description": "Allows the app to send which accounts are managed by the PAM solution for all AD and Entra identities for MDI customers.", - "displayName": "Send which accounts are managed by the PAM solution", - "id": "9bba0ae2-fc9b-4c22-b607-b6afdf6601cb", - "origin": "Delegated (Azure Advanced Threat Protection)", - "value": "Identity.PrivilegeAccountTagging" - }, { "description": "Allows an application to call ADME apis without a signed in user.", "displayName": "ADME Application API access", @@ -12368,6 +12375,20 @@ "origin": "Application (Azure Data Manager for Energy)", "value": "ADME.ApplicationAccess" }, + { + "description": "The app can view and write to all models for the signed in user and models that the user has access to.", + "displayName": "Read and Write all Models", + "id": "59ef67ea-d35f-4c6d-b1ce-95468f134ccb", + "origin": "Delegated (Azure Analysis Services)", + "value": "Model.ReadWrite.All" + }, + { + "description": "Allows the app to send which accounts are managed by the PAM solution for all AD and Entra identities for MDI customers.", + "displayName": "Send which accounts are managed by the PAM solution", + "id": "9bba0ae2-fc9b-4c22-b607-b6afdf6601cb", + "origin": "Delegated (Azure Advanced Threat Protection)", + "value": "Identity.PrivilegeAccountTagging" + }, { "description": "Allows the app to get a list of actions required on AD and Entra identities and update on the status of said actions for MDI customers.", "displayName": "get a list of actions and update on the status of said actions", @@ -12376,11 +12397,11 @@ "value": "Identity.PrivilegeAccountActions" }, { - "description": "Allows the app to get a list of actions required on AD and Entra identities and update on the status of said actions for MDI customers.", - "displayName": "get a list of actions and update on the status of said actions", - "id": "c613cf81-75fb-4201-a32b-7a58d1fe4dff", + "description": "Allows the app to send which accounts are managed by the PAM solution for all AD and Entra identities for MDI customers.", + "displayName": "Send which accounts are managed by the PAM solution", + "id": "850e8a94-5d16-40ff-9167-cfda8c7f9ea8", "origin": "Application (Azure Advanced Threat Protection)", - "value": "Identity.PrivilegeAccountActions" + "value": "Identity.PrivilegeAccountTagging" }, { "description": "Access to IoT DPS", @@ -12431,6 +12452,13 @@ "origin": "Application (Attestation Service)", "value": "user_impersonation" }, + { + "description": "Allow the app to access resources on behalf of the signed-in user.", + "displayName": "Access ADME", + "id": "b51d4d2d-b434-4627-8f1d-6684a79793e7", + "origin": "Delegated (Azure Data Manager for Energy)", + "value": "user_impersonation" + }, { "description": "Allow the application to access Azure Autonomous Development Platform on behalf of the signed-in user.", "displayName": "Access Azure Autonomous Development Platform", @@ -12438,13 +12466,6 @@ "origin": "Delegated (Autonomous Development Platform)", "value": "user_impersonation" }, - { - "description": "Allows a service or application to register Global Secure Access Private Network Connectors.", - "displayName": "Register connectors", - "id": "46314cfe-5021-44c3-a00c-e5e4fdc9b5ac", - "origin": "Application (Azure AD Application Proxy)", - "value": "Connector.Register" - }, { "description": "Allows an application to read access recommendation insights", "displayName": "Read access recommendation insights", @@ -12495,18 +12516,25 @@ "value": "Application.ReadWrite" }, { - "description": "Allows the app to send which accounts are managed by the PAM solution for all AD and Entra identities for MDI customers.", - "displayName": "Send which accounts are managed by the PAM solution", - "id": "850e8a94-5d16-40ff-9167-cfda8c7f9ea8", + "description": "Allows the app to get a list of actions required on AD and Entra identities and update on the status of said actions for MDI customers.", + "displayName": "get a list of actions and update on the status of said actions", + "id": "c613cf81-75fb-4201-a32b-7a58d1fe4dff", "origin": "Application (Azure Advanced Threat Protection)", - "value": "Identity.PrivilegeAccountTagging" + "value": "Identity.PrivilegeAccountActions" }, { - "description": "Allow the app to access resources on behalf of the signed-in user.", - "displayName": "Access ADME", - "id": "b51d4d2d-b434-4627-8f1d-6684a79793e7", - "origin": "Delegated (Azure Data Manager for Energy)", - "value": "user_impersonation" + "description": "Allows a service or application to register Global Secure Access Private Network Connectors.", + "displayName": "Register connectors", + "id": "46314cfe-5021-44c3-a00c-e5e4fdc9b5ac", + "origin": "Application (Azure AD Application Proxy)", + "value": "Connector.Register" + }, + { + "description": "Allows user to read Condition resources in their own compartment.", + "displayName": "user.Condition.read", + "id": "dd554abf-e473-4190-8382-9b096fe49efa", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.Condition.read" }, { "description": "Allow the application to access Azure Device Update on behalf of the signed-in user.", @@ -12516,18 +12544,11 @@ "value": "user_impersonation" }, { - "description": "Grants the ability to read your load test runs, test results, and APM artifacts.", - "displayName": "Load test (read)", - "id": "e000c422-1bec-45ec-9d30-083f21df9d04", + "description": "Grants the ability to create and update load test runs, and read metadata including test results and APM artifacts.", + "displayName": "Load test (read and write)", + "id": "28d646b8-7efa-4ff7-9e39-dfb3a53b7fa6", "origin": "Application (Azure DevOps)", - "value": "vso.loadtest" - }, - { - "description": "Grants the ability to read installed extensions.", - "displayName": "Extensions (read)", - "id": "8fd343dd-9d94-4128-b3a3-f0ba1b869463", - "origin": "Delegated (Azure DevOps)", - "value": "vso.extension" + "value": "vso.loadtest_write" }, { "description": "Grants the ability to read data (settings and documents) stored by installed extensions.", @@ -12641,6 +12662,20 @@ "origin": "Delegated (Azure DevOps)", "value": "vso.notification_diagnostics" }, + { + "description": "Provides read, write, and management access to subscriptions and read access to event metadata, including filterable field values.", + "displayName": "Notifications (manage)", + "id": "90f74b44-f4ec-4f41-9003-cb9cb64cdd32", + "origin": "Delegated (Azure DevOps)", + "value": "vso.notification_manage" + }, + { + "description": "Grants the ability to read installed extensions.", + "displayName": "Extensions (read)", + "id": "8fd343dd-9d94-4128-b3a3-f0ba1b869463", + "origin": "Delegated (Azure DevOps)", + "value": "vso.extension" + }, { "description": "Provides ability to manage environment", "displayName": "Environment (read, manage)", @@ -12662,20 +12697,6 @@ "origin": "Delegated (Azure DevOps)", "value": "vso.dashboards_manage" }, - { - "description": "Grants the ability to read team dashboard information.", - "displayName": "Team dashboards (read)", - "id": "e9e366b1-b116-44b7-bd65-575d6bc13fc8", - "origin": "Delegated (Azure DevOps)", - "value": "vso.dashboards" - }, - { - "description": "Grants the ability to create and update load test runs, and read metadata including test results and APM artifacts.", - "displayName": "Load test (read and write)", - "id": "28d646b8-7efa-4ff7-9e39-dfb3a53b7fa6", - "origin": "Application (Azure DevOps)", - "value": "vso.loadtest_write" - }, { "description": "Allow the application full access to the REST APIs provided by Visual Studio Team Services on behalf of the signed-in user", "displayName": "Have full access to Visual Studio Team Services REST APIs", @@ -12725,13 +12746,6 @@ "origin": "Delegated (Azure DevOps)", "value": "vso.analytics" }, - { - "description": "Provides read and write access to subscriptions and read access to event metadata, including filterable field values.", - "displayName": "Notifications (write)", - "id": "10e32108-6193-4cd9-b405-ab95c87509b0", - "origin": "Delegated (Azure DevOps)", - "value": "vso.notification_write" - }, { "description": "Grants the ability to read the auditing log and audit streams to users", "displayName": "Audit Read Log", @@ -12740,11 +12754,18 @@ "value": "vso.auditlog" }, { - "description": "Grants the ability to access build artifacts, including build results, definitions, and requests, and the ability to receive notifications about build events via service hooks.", - "displayName": "Build (read)", - "id": "0d85fdcb-8267-4af0-857e-7f76b110fbdc", + "description": "Grants the ability to read your load test runs, test results, and APM artifacts.", + "displayName": "Load test (read)", + "id": "e000c422-1bec-45ec-9d30-083f21df9d04", + "origin": "Application (Azure DevOps)", + "value": "vso.loadtest" + }, + { + "description": "Grants the ability to manage auditing streams to users", + "displayName": "Audit Streams (manage)", + "id": "ba2781d8-d6df-4b58-ac73-d80e7cdd25cd", "origin": "Delegated (Azure DevOps)", - "value": "vso.build" + "value": "vso.auditstreams_manage" }, { "description": "Grants the ability to access build artifacts, including build results, definitions, and requests, and the ability to queue a build, update build properties, and the ability to receive notifications about build events via service hooks.", @@ -12796,18 +12817,25 @@ "value": "vso.connected_server" }, { - "description": "Grants the ability to manage auditing streams to users", - "displayName": "Audit Streams (manage)", - "id": "ba2781d8-d6df-4b58-ac73-d80e7cdd25cd", + "description": "Grants the ability to read team dashboard information.", + "displayName": "Team dashboards (read)", + "id": "e9e366b1-b116-44b7-bd65-575d6bc13fc8", "origin": "Delegated (Azure DevOps)", - "value": "vso.auditstreams_manage" + "value": "vso.dashboards" }, { - "description": "Allows user to read Condition resources in their own compartment.", - "displayName": "user.Condition.read", - "id": "dd554abf-e473-4190-8382-9b096fe49efa", - "origin": "Delegated (Azure Healthcare APIs)", - "value": "user.Condition.read" + "description": "Grants the ability to access build artifacts, including build results, definitions, and requests, and the ability to receive notifications about build events via service hooks.", + "displayName": "Build (read)", + "id": "0d85fdcb-8267-4af0-857e-7f76b110fbdc", + "origin": "Delegated (Azure DevOps)", + "value": "vso.build" + }, + { + "description": "Allows the app to read all domain properties without a signed-in user.", + "displayName": "Read domains", + "id": "dbb9058a-0e50-45d7-ae91-66909b5d4664", + "origin": "Application (Microsoft Graph)", + "value": "Domain.Read.All" }, { "description": "Allows user to read Device resources in their own compartment.", @@ -12817,18 +12845,11 @@ "value": "user.Device.read" }, { - "description": "Allows user to read DiagnosticReport resources in their own compartment.", - "displayName": "user.DiagnosticReport.read", - "id": "588567a0-59db-4598-8bd7-0cbea9ff1811", + "description": "Allows user to read DocumentReference resources in their own compartment.", + "displayName": "user.DocumentReference.read", + "id": "23b15307-5f89-4954-b86c-00e2c4279a8f", "origin": "Delegated (Azure Healthcare APIs)", - "value": "user.DiagnosticReport.read" - }, - { - "description": "Read-only access to Bcos resources", - "displayName": "Bcos.ReadOnly", - "id": "c6a7f3e3-dea5-4df4-a094-59ceca797083", - "origin": "Application (Branch Connect Web Service)", - "value": "Bcos.ReadOnly" + "value": "user.DocumentReference.read" }, { "description": "Read-write access to Bcos resources", @@ -12935,13 +12956,6 @@ "origin": "Application (Configuration Manager Microservice)", "value": "Collection.Read.All" }, - { - "description": "c", - "displayName": "Skype Bot Reviewer", - "id": "ae068e81-caaf-43a2-8081-717c1fb700d0", - "origin": "Application (Bot Framework Dev Portal)", - "value": "SkypeReviewer" - }, { "description": "Allows to call service API to query device data", "displayName": "Read device data", @@ -12950,25 +12964,32 @@ "value": "Device.Read.All" }, { - "description": "c", - "displayName": "RBAC Test Role Prod", - "id": "b6c09b98-4044-4869-976f-625da4f561c3", - "origin": "Application (Bot Framework Dev Portal)", - "value": "RBACTestRoleProd" + "description": "Read-only access to Bcos resources", + "displayName": "Bcos.ReadOnly", + "id": "c6a7f3e3-dea5-4df4-a094-59ceca797083", + "origin": "Application (Branch Connect Web Service)", + "value": "Bcos.ReadOnly" }, { - "description": "Admins for prod devportal", - "displayName": "Prod Devportal Admin", - "id": "9160be5e-b0e2-4961-9419-21dc535897ca", + "description": "Allows to call service API to query or modify device data", + "displayName": "Read or write device data", + "id": "4b03fb80-ef9e-4391-86c9-152c41bf0693", + "origin": "Application (Configuration Manager Microservice)", + "value": "Device.ReadWrite.All" + }, + { + "description": "c", + "displayName": "Skype Bot Reviewer", + "id": "ae068e81-caaf-43a2-8081-717c1fb700d0", "origin": "Application (Bot Framework Dev Portal)", - "value": "ProdAdmin" + "value": "SkypeReviewer" }, { - "description": "Allows the app to search all calendars and to read their properties for default on behalf of the signed-in user. ", - "displayName": "Read all calendars for default", - "id": "46089125-31ba-451a-96a1-278c9490b608", - "origin": "Delegated (Bing)", - "value": "Calendars.Read" + "description": "Support engineers for prod devportal", + "displayName": "Prod Devportal Support", + "id": "b1de6b77-7554-4b4d-9db5-dc90af4bbe89", + "origin": "Application (Bot Framework Dev Portal)", + "value": "ProdSupport" }, { "description": "Allows the app to read Copilot product eligibility information, on behalf of the signed-in user.", @@ -13083,18 +13104,18 @@ "value": "IntUser" }, { - "description": "Support engineers for prod devportal", - "displayName": "Prod Devportal Support", - "id": "b1de6b77-7554-4b4d-9db5-dc90af4bbe89", + "description": "Admins for prod devportal", + "displayName": "Prod Devportal Admin", + "id": "9160be5e-b0e2-4961-9419-21dc535897ca", "origin": "Application (Bot Framework Dev Portal)", - "value": "ProdSupport" + "value": "ProdAdmin" }, { - "description": "Allows to call service API to query or modify device data", - "displayName": "Read or write device data", - "id": "4b03fb80-ef9e-4391-86c9-152c41bf0693", - "origin": "Application (Configuration Manager Microservice)", - "value": "Device.ReadWrite.All" + "description": "c", + "displayName": "RBAC Test Role Prod", + "id": "b6c09b98-4044-4869-976f-625da4f561c3", + "origin": "Application (Bot Framework Dev Portal)", + "value": "RBACTestRoleProd" }, { "description": "Allows to call service API to query inventory class", @@ -13111,11 +13132,11 @@ "value": "Notification.Read.All" }, { - "description": "Read Permission for seeding offers", - "displayName": "READ Seeding offers for a tenant", - "id": "f3f3f5b3-6e2e-4f6b-8f3c-6e2e2b1e4f4a", - "origin": "Application (Consumption Billing)", - "value": "Purview.Offer.Seeding.Read" + "description": "Allows to call service API to query or modify notification and notification result", + "displayName": "Read or write notification and notification result", + "id": "0db7d603-2368-4c9a-8f47-adc9ac73e5e1", + "origin": "Application (Configuration Manager Microservice)", + "value": "Notification.ReadWrite.All" }, { "description": "Allows the app to create, read, update and delete applications and service principals on behalf of the signed-in user. Does not allow management of consent grants.", @@ -13208,6 +13229,20 @@ "origin": "Application (DirectoryLookupService)", "value": "UserScope.Debug.All" }, + { + "description": "This allows app to run prod tenant userscope in DLS", + "displayName": "UserScope.ReadWrite.All", + "id": "6f6965e3-3c5a-47e2-81a6-9c40ddacc7f6", + "origin": "Application (DirectoryLookupService)", + "value": "UserScope.ReadWrite.All" + }, + { + "description": "Read Permission for seeding offers", + "displayName": "READ Seeding offers for a tenant", + "id": "f3f3f5b3-6e2e-4f6b-8f3c-6e2e2b1e4f4a", + "origin": "Application (Consumption Billing)", + "value": "Purview.Offer.Seeding.Read" + }, { "description": "Permission to create seeding offer", "displayName": "CREATE/START Seeding offer for a tenant", @@ -13229,27 +13264,6 @@ "origin": "Application (Consumption Billing)", "value": "Purview.Offer.FreeTrial.Read" }, - { - "description": "Permission to create/start free trials", - "displayName": "CREATE/START Free Trials for a tenant", - "id": "6061d6f3-95e7-4aef-b53f-81967905b679", - "origin": "Application (Consumption Billing)", - "value": "Purview.Offer.FreeTrial.Create" - }, - { - "description": "Allows to call service API to query or modify notification and notification result", - "displayName": "Read or write notification and notification result", - "id": "0db7d603-2368-4c9a-8f47-adc9ac73e5e1", - "origin": "Application (Configuration Manager Microservice)", - "value": "Notification.ReadWrite.All" - }, - { - "description": "Allows the app to search all calendars and to read their properties on behalf of the signed-in user. ", - "displayName": "Read all calendars", - "id": "73c5d1d0-1ba7-4978-ad4c-32f0a8a1a9ed", - "origin": "Delegated (Bing)", - "value": "Calendar.Read.All" - }, { "description": "Access Connections Service Api", "displayName": "Access Connections Service Api", @@ -13258,11 +13272,18 @@ "value": "user_impersonation" }, { - "description": "Authorized to call the Consumption Billing reporting API for a single tenant id", - "displayName": "GET Consumption Bill Report for a tenant", - "id": "866040a7-8984-4760-8e56-363aefb78d69", - "origin": "Application (Consumption Billing)", - "value": "CBS.Reporting.Read" + "description": "Allows the app to search all calendars and to read their properties for default on behalf of the signed-in user. ", + "displayName": "Read all calendars for default", + "id": "46089125-31ba-451a-96a1-278c9490b608", + "origin": "Delegated (Bing)", + "value": "Calendars.Read" + }, + { + "description": "Allows the app to create and manage connector configurations. The app would use the connector configuration to send actionable messages to your inbox or a group of your choice.", + "displayName": "Read and write connector configurations", + "id": "ba9c6a98-63fd-487c-b835-c1f895764e25", + "origin": "Delegated (Connectors)", + "value": "webhook.readwrite.all" }, { "description": "Authorized to call the Consumption Billing reporting API for a single tenant id", @@ -13314,11 +13335,25 @@ "value": "Purview.Offer.FreeTrial.ConsumedUnits.Write" }, { - "description": "Allows the app to create and manage connector configurations. The app would use the connector configuration to send actionable messages to your inbox or a group of your choice.", - "displayName": "Read and write connector configurations", - "id": "ba9c6a98-63fd-487c-b835-c1f895764e25", - "origin": "Delegated (Connectors)", - "value": "webhook.readwrite.all" + "description": "Permission to create/start free trials", + "displayName": "CREATE/START Free Trials for a tenant", + "id": "6061d6f3-95e7-4aef-b53f-81967905b679", + "origin": "Application (Consumption Billing)", + "value": "Purview.Offer.FreeTrial.Create" + }, + { + "description": "Authorized to call the Consumption Billing reporting API for a single tenant id", + "displayName": "GET Consumption Bill Report for a tenant", + "id": "866040a7-8984-4760-8e56-363aefb78d69", + "origin": "Application (Consumption Billing)", + "value": "CBS.Reporting.Read" + }, + { + "description": "Allows the app to search all calendars and to read their properties on behalf of the signed-in user. ", + "displayName": "Read all calendars", + "id": "73c5d1d0-1ba7-4978-ad4c-32f0a8a1a9ed", + "origin": "Delegated (Bing)", + "value": "Calendar.Read.All" }, { "description": "Allows the app to list buildings and to read their properties on behalf of the signed-in user. ", @@ -13334,20 +13369,6 @@ "origin": "Delegated (Bing)", "value": "Bookmark.Read.All" }, - { - "description": "Allows the app to list Acronym and to read their properties on behalf of the signed-in user. ", - "displayName": "Read all Acronyms", - "id": "92bacdd9-8c69-46f7-a004-387210ecd2eb", - "origin": "Delegated (Bing)", - "value": "Acronym.Read.All" - }, - { - "description": "this allows to read user profile", - "displayName": "user.read", - "id": "34a47c2f-cd0d-47b4-a93c-2c41130c671c", - "origin": "Delegated (Azure Kubernetes Service AAD Server)", - "value": "user.read" - }, { "description": "Consent for Azure Machine Learning Service", "displayName": "user_impersonation", @@ -13460,6 +13481,20 @@ "origin": "Application (Azure Signup Api)", "value": "Qualification_DOD" }, + { + "description": "Allow user to add gcc high qualification.", + "displayName": "Qualification_GCCHigh", + "id": "ab0c514c-6a2b-4a77-81bc-74019dff79d3", + "origin": "Application (Azure Signup Api)", + "value": "Qualification_GCCHigh" + }, + { + "description": "this allows to read user profile", + "displayName": "user.read", + "id": "34a47c2f-cd0d-47b4-a93c-2c41130c671c", + "origin": "Delegated (Azure Kubernetes Service AAD Server)", + "value": "user.read" + }, { "description": "Allow the application full access to the Azure Key Vault service on behalf of the signed-in user", "displayName": "Have full access to the Azure Key Vault service", @@ -13481,20 +13516,6 @@ "origin": "Application (Azure Inference Service)", "value": "Azure.Inference.MLReader" }, - { - "description": "Have the permissions to create and modify models, deployments and environments; update traffic of deployments and perform; and scale up deployments.", - "displayName": "Inference ML administrator", - "id": "90d1b19a-1849-4c47-9d91-ed1842c92f52", - "origin": "Application (Azure Inference Service)", - "value": "Azure.Inference.MLAdministrator" - }, - { - "description": "Allows user to read DocumentReference resources in their own compartment.", - "displayName": "user.DocumentReference.read", - "id": "23b15307-5f89-4954-b86c-00e2c4279a8f", - "origin": "Delegated (Azure Healthcare APIs)", - "value": "user.DocumentReference.read" - }, { "description": "Allows user to read Encounter resources in their own compartment.", "displayName": "user.Encounter.read", @@ -13544,13 +13565,6 @@ "origin": "Delegated (Azure Healthcare APIs)", "value": "user.Observation.read" }, - { - "description": "Allow user to add gcc high qualification.", - "displayName": "Qualification_GCCHigh", - "id": "ab0c514c-6a2b-4a77-81bc-74019dff79d3", - "origin": "Application (Azure Signup Api)", - "value": "Qualification_GCCHigh" - }, { "description": "Allows user to read Organization resources in their own compartment.", "displayName": "user.Organization.read", @@ -13559,11 +13573,18 @@ "value": "user.Organization.read" }, { - "description": "Allows user to read Practitioner resources in their own compartment.", - "displayName": "user.Practitioner.read", - "id": "079186df-3044-4484-a785-d9750101f8f3", + "description": "Allow user to add government qualification.", + "displayName": "Qualification_Government", + "id": "3e74b245-2d1f-4ffb-a5e8-9a05aceca540", + "origin": "Application (Azure Signup Api)", + "value": "Qualification_Government" + }, + { + "description": "Allows user to read Patient resources in their own compartment.", + "displayName": "user.Patient.read", + "id": "56998e01-1f00-4832-a130-c358e252acf2", "origin": "Delegated (Azure Healthcare APIs)", - "value": "user.Practitioner.read" + "value": "user.Patient.read" }, { "description": "Allows user to read PractitionerRole resources in their own compartment.", @@ -13612,42 +13633,42 @@ "displayName": "Inference executor", "id": "92ad2108-b071-46c2-8ac0-1dcf9a2c4fd6", "origin": "Application (Azure Inference Service)", - "value": "Azure.Inference.Executor" + "value": "Azure.Inference.Executor" + }, + { + "description": "Have the permissions to create and modify models, deployments and environments; update traffic of deployments and perform; and scale up deployments.", + "displayName": "Inference ML administrator", + "id": "90d1b19a-1849-4c47-9d91-ed1842c92f52", + "origin": "Application (Azure Inference Service)", + "value": "Azure.Inference.MLAdministrator" }, { - "description": "Allows user to read Patient resources in their own compartment.", - "displayName": "user.Patient.read", - "id": "56998e01-1f00-4832-a130-c358e252acf2", + "description": "Allows user to read Practitioner resources in their own compartment.", + "displayName": "user.Practitioner.read", + "id": "079186df-3044-4484-a785-d9750101f8f3", "origin": "Delegated (Azure Healthcare APIs)", - "value": "user.Patient.read" + "value": "user.Practitioner.read" }, { - "description": "Allows calling debugging APIs", - "displayName": "UserScope-Dev.Debug.All", - "id": "d3aaaaff-f3e8-4b2f-8285-12478a43eb7d", - "origin": "Application (DirectoryLookupService)", - "value": "UserScope-Dev.Debug.All" + "description": "Allows user to read DiagnosticReport resources in their own compartment.", + "displayName": "user.DiagnosticReport.read", + "id": "588567a0-59db-4598-8bd7-0cbea9ff1811", + "origin": "Delegated (Azure Healthcare APIs)", + "value": "user.DiagnosticReport.read" }, { - "description": "Allow user to add government qualification.", - "displayName": "Qualification_Government", - "id": "3e74b245-2d1f-4ffb-a5e8-9a05aceca540", + "description": "Provides delegated role to the caller.", + "displayName": "SignupPlatformDelegatedRole", + "id": "8de2faed-dae7-4e94-8d5d-a49be218c680", "origin": "Application (Azure Signup Api)", - "value": "Qualification_Government" + "value": "SignupPlatformDelegatedRole" }, { - "description": "Allows partners to add tags with charity namespace.", - "displayName": "Tag_charity", - "id": "eb6f173a-fd78-41c4-9208-e2df4e4e0475", + "description": "Allows partners to add tags with ea namespace.", + "displayName": "Tag_ea", + "id": "d59f33c1-1406-4028-a0f7-8f00ae1dbf10", "origin": "Application (Azure Signup Api)", - "value": "Tag_charity" - }, - { - "description": "Address Customer Master Reader", - "displayName": "AddressCustomerMasterReader", - "id": "1cbc9fa5-af3f-44ad-9455-35ef4dd212aa", - "origin": "Application (Billing)", - "value": "AddressCustomerMasterReader" + "value": "Tag_ea" }, { "description": "Billing Period Reader", @@ -13761,6 +13782,20 @@ "origin": "Application (Bing)", "value": "bawuser" }, + { + "description": "Allows the app to list Acronym and to read their properties on behalf of the signed-in user. ", + "displayName": "Read all Acronyms", + "id": "92bacdd9-8c69-46f7-a004-387210ecd2eb", + "origin": "Delegated (Bing)", + "value": "Acronym.Read.All" + }, + { + "description": "Address Customer Master Reader", + "displayName": "AddressCustomerMasterReader", + "id": "1cbc9fa5-af3f-44ad-9455-35ef4dd212aa", + "origin": "Application (Billing)", + "value": "AddressCustomerMasterReader" + }, { "description": "Allows the app to make API calls that require read and write permissions on ContextualSupport Service, on behalf of the signed-in user.", "displayName": "Make API calls that require read and write permissions on ContextualSupport Service", @@ -13782,20 +13817,6 @@ "origin": "Delegated (AzureDatabricks)", "value": "user_impersonation" }, - { - "description": "Allows a user to invoke any write (POST, PUT) operation across the provisioning API.", - "displayName": "ProvisioningAPI.WriteUser", - "id": "c175fb63-786b-45cc-b884-9372c7f12120", - "origin": "Application (AzureCommunicationsGateway)", - "value": "ProvisioningAPI.WriteUser" - }, - { - "description": "Allows partners to add tags with ea namespace.", - "displayName": "Tag_ea", - "id": "d59f33c1-1406-4028-a0f7-8f00ae1dbf10", - "origin": "Application (Azure Signup Api)", - "value": "Tag_ea" - }, { "description": "Allows partners to add tags with edu namespace.", "displayName": "Tag_edu", @@ -13845,13 +13866,6 @@ "origin": "Delegated (Azure SQL Database)", "value": "user_impersonation" }, - { - "description": "Provides delegated role to the caller.", - "displayName": "SignupPlatformDelegatedRole", - "id": "8de2faed-dae7-4e94-8d5d-a49be218c680", - "origin": "Application (Azure Signup Api)", - "value": "SignupPlatformDelegatedRole" - }, { "description": "Allows the application to create conversation threads and reply on existing threads for the SRE agents that user has access to", "displayName": "Create conversation threads with SRE agents and reply on existing conversation threads", @@ -13860,10 +13874,17 @@ "value": "Threads.ReadWrite.All" }, { - "description": "Allow the application full access to the Azure Time Series Insights service on behalf of the signed-in user.", - "displayName": "Access Azure Time Series Insights service", - "id": "a3a77dfe-67a4-4373-b02a-dfe8485e2248", - "origin": "Delegated (Azure Time Series Insights)", + "description": "Allows partners to add tags with charity namespace.", + "displayName": "Tag_charity", + "id": "eb6f173a-fd78-41c4-9208-e2df4e4e0475", + "origin": "Application (Azure Signup Api)", + "value": "Tag_charity" + }, + { + "description": "Allow the application to access Azure Storage on behalf of the signed-in user.", + "displayName": "Access Azure Storage", + "id": "03e0da56-190b-40ad-a80c-ea378c433f7f", + "origin": "Delegated (Azure Storage)", "value": "user_impersonation" }, { @@ -13916,10 +13937,17 @@ "value": "ProvisioningAPI.Write" }, { - "description": "Allow the application to access Azure Storage on behalf of the signed-in user.", - "displayName": "Access Azure Storage", - "id": "03e0da56-190b-40ad-a80c-ea378c433f7f", - "origin": "Delegated (Azure Storage)", + "description": "Allows a user to invoke any write (POST, PUT) operation across the provisioning API.", + "displayName": "ProvisioningAPI.WriteUser", + "id": "c175fb63-786b-45cc-b884-9372c7f12120", + "origin": "Application (AzureCommunicationsGateway)", + "value": "ProvisioningAPI.WriteUser" + }, + { + "description": "Allow the application full access to the Azure Time Series Insights service on behalf of the signed-in user.", + "displayName": "Access Azure Time Series Insights service", + "id": "a3a77dfe-67a4-4373-b02a-dfe8485e2248", + "origin": "Delegated (Azure Time Series Insights)", "value": "user_impersonation" }, { @@ -13943,13 +13971,6 @@ "origin": "Application (Microsoft Graph)", "value": "Domain-InternalFederation.ReadWrite.All" }, - { - "description": "Allows the app to read, update and delete identities that are associated with a user's account, without a signed in user. This controls the identities users can sign-in with.", - "displayName": "Manage all users' identities", - "id": "c529cfca-c91b-489c-af2b-d92990b66ce6", - "origin": "Application (Microsoft Graph)", - "value": "User.ManageIdentities.All" - }, { "description": "Allows the app to read a basic set of profile properties of other users in your organization without a signed-in user. Includes display name, first and last name, email address, open extensions, and photo.", "displayName": "Read all users' basic profiles", @@ -14048,13 +14069,6 @@ "origin": "Application (Microsoft Graph)", "value": "UserAuthMethod-HardwareOATH.Delete.All" }, - { - "description": "Allows the app to invite guest users to the organization, without a signed-in user.", - "displayName": "Invite guest users to the organization", - "id": "09850681-111b-4a89-9bed-3f2cae46d706", - "origin": "Application (Microsoft Graph)", - "value": "User.Invite.All" - }, { "description": "Allows the app to read HardwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", "displayName": "Read all users' HardwareOATH authentication methods", @@ -14063,18 +14077,32 @@ "value": "UserAuthMethod-HardwareOATH.Read.All" }, { - "description": "Allows the app to delete and restore all users, without a signed-in user.", - "displayName": "Delete and restore all users", - "id": "eccc023d-eccf-4e7b-9683-8813ab36cecc", + "description": "Allows the app to read, update and delete identities that are associated with a user's account, without a signed in user. This controls the identities users can sign-in with.", + "displayName": "Manage all users' identities", + "id": "c529cfca-c91b-489c-af2b-d92990b66ce6", "origin": "Application (Microsoft Graph)", - "value": "User.DeleteRestore.All" + "value": "User.ManageIdentities.All" }, { - "description": "Allows the application to list and read related tenants information without a signed-in user.", - "displayName": "Read related tenants", - "id": "7ced9a83-8e7c-46df-b3e0-6b45a6ecedcd", + "description": "Allows the application to read and write HardwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' HardwareOATH authentication methods", + "id": "7e9ebcc1-90aa-4471-8051-e68d6b4e9c89", "origin": "Application (Microsoft Graph)", - "value": "TenantGovernance-RelatedTenant.Read.All" + "value": "UserAuthMethod-HardwareOATH.ReadWrite.All" + }, + { + "description": "Allows the app to invite guest users to the organization, without a signed-in user.", + "displayName": "Invite guest users to the organization", + "id": "09850681-111b-4a89-9bed-3f2cae46d706", + "origin": "Application (Microsoft Graph)", + "value": "User.Invite.All" + }, + { + "description": "Allows the app to enable and disable users' accounts, without a signed-in user.", + "displayName": "Enable and disable user accounts", + "id": "3011c876-62b7-4ada-afa2-506cbbecc68c", + "origin": "Application (Microsoft Graph)", + "value": "User.EnableDisableAccount.All" }, { "description": "Allows the application to list and read all Tenant Governance relationships without a signed-in user.", @@ -14189,18 +14217,11 @@ "value": "User.Create" }, { - "description": "Allows the app to enable and disable users' accounts, without a signed-in user.", - "displayName": "Enable and disable user accounts", - "id": "3011c876-62b7-4ada-afa2-506cbbecc68c", - "origin": "Application (Microsoft Graph)", - "value": "User.EnableDisableAccount.All" - }, - { - "description": "Allows the application to read and write HardwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' HardwareOATH authentication methods", - "id": "7e9ebcc1-90aa-4471-8051-e68d6b4e9c89", + "description": "Allows the app to delete and restore all users, without a signed-in user.", + "displayName": "Delete and restore all users", + "id": "eccc023d-eccf-4e7b-9683-8813ab36cecc", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-HardwareOATH.ReadWrite.All" + "value": "User.DeleteRestore.All" }, { "description": "Allows the application to delete Microsoft Authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify Microsoft Authentication methods.", @@ -14217,11 +14238,11 @@ "value": "UserAuthMethod-MicrosoftAuthApp.Read.All" }, { - "description": "Allows the app to read Temporary Access Pass authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' Temporary Access Pass methods", - "id": "bf82209c-b22b-4747-ac88-a68be99032cf", + "description": "Allows the application to read and write Microsoft Authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read and write all users' Microsoft Authentication methods", + "id": "c833c349-a1ab-4b6d-94a2-fa9a8674420c", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-TAP.Read.All" + "value": "UserAuthMethod-MicrosoftAuthApp.ReadWrite.All" }, { "description": "Allows the application to read and write Temporary Access Pass authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", @@ -14335,6 +14356,20 @@ "origin": "Application (Microsoft Graph)", "value": "VerifiedId-Profile.Read.All" }, + { + "description": "Allows the application to read virtual appointments for all users, without a signed-in user. The app must also be authorized to access an individual user’s data by the online meetings application access policy.", + "displayName": "Read all virtual appointments for users, as authorized by online meetings application access policy", + "id": "d4f67ec2-59b5-4bdc-b4af-d78f6f9c1954", + "origin": "Application (Microsoft Graph)", + "value": "VirtualAppointment.Read.All" + }, + { + "description": "Allows the app to read Temporary Access Pass authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' Temporary Access Pass methods", + "id": "bf82209c-b22b-4747-ac88-a68be99032cf", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-TAP.Read.All" + }, { "description": "Allows the application to delete Temporary Access Pass authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify Temporary Access Pass authentication methods.", "displayName": "Delete all users' Temporary Access Pass authentication methods", @@ -14356,20 +14391,6 @@ "origin": "Application (Microsoft Graph)", "value": "UserAuthMethod-SoftwareOATH.Read.All" }, - { - "description": "Allows the application to delete SoftwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify SoftwareOATH authentication methods.", - "displayName": "Delete all users' SoftwareOATH authentication methods", - "id": "e5676e10-1a16-452b-ad10-71f54b755852", - "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-SoftwareOATH.Delete.All" - }, - { - "description": "Allows the application to read and write Microsoft Authentication methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read and write all users' Microsoft Authentication methods", - "id": "c833c349-a1ab-4b6d-94a2-fa9a8674420c", - "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-MicrosoftAuthApp.ReadWrite.All" - }, { "description": "Allows the application to delete passkey authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify passkey authentication methods.", "displayName": "Delete all users' passkey authentication methods", @@ -14419,13 +14440,6 @@ "origin": "Application (Microsoft Graph)", "value": "UserAuthMethod-Phone.Read.All" }, - { - "description": "Allows the application to list and read all Tenant Governance policy templates without a signed-in user.", - "displayName": "Read Tenant Governance policy templates", - "id": "eb9465d8-e7c0-4301-8e51-927f34ee3134", - "origin": "Application (Microsoft Graph)", - "value": "TenantGovernance-PolicyTemplate.Read.All" - }, { "description": "Allows the application to read and write phone methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", "displayName": "Read and write all users' phone methods", @@ -14434,11 +14448,18 @@ "value": "UserAuthMethod-Phone.ReadWrite.All" }, { - "description": "Allows the app to read platform credentials methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", - "displayName": "Read all users' platform credentials methods", - "id": "07c0b1e4-15bd-442f-834b-30f8291388d1", + "description": "Allows the application to list and read related tenants information without a signed-in user.", + "displayName": "Read related tenants", + "id": "7ced9a83-8e7c-46df-b3e0-6b45a6ecedcd", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-PlatformCred.Read.All" + "value": "TenantGovernance-RelatedTenant.Read.All" + }, + { + "description": "Allows the application to delete platform credentials methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify platform credentials methods.", + "displayName": "Delete all users' platform credentials methods", + "id": "bd760918-651f-4e67-b66f-8f614384dec2", + "origin": "Application (Microsoft Graph)", + "value": "UserAuthMethod-PlatformCred.Delete.All" }, { "description": "Allows the application to read and write platform credentials methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", @@ -14490,39 +14511,39 @@ "value": "UserAuthMethod-ResourceKey.ReadWrite.All" }, { - "description": "Allows the application to delete platform credentials methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify platform credentials methods.", - "displayName": "Delete all users' platform credentials methods", - "id": "bd760918-651f-4e67-b66f-8f614384dec2", + "description": "Allows the application to delete SoftwareOATH authentication methods of all users in your organization, without a signed-in user. This does not allow the app to read, create, or modify SoftwareOATH authentication methods.", + "displayName": "Delete all users' SoftwareOATH authentication methods", + "id": "e5676e10-1a16-452b-ad10-71f54b755852", "origin": "Application (Microsoft Graph)", - "value": "UserAuthMethod-PlatformCred.Delete.All" + "value": "UserAuthMethod-SoftwareOATH.Delete.All" }, { - "description": "Allows the application to read virtual appointments for all users, without a signed-in user. The app must also be authorized to access an individual user’s data by the online meetings application access policy.", - "displayName": "Read all virtual appointments for users, as authorized by online meetings application access policy", - "id": "d4f67ec2-59b5-4bdc-b4af-d78f6f9c1954", + "description": "Allows the app to read platform credentials methods of all users in your organization, without a signed-in user. This does not allow the app to see secret information like passwords, or to sign-in or otherwise use the authentication methods.", + "displayName": "Read all users' platform credentials methods", + "id": "07c0b1e4-15bd-442f-834b-30f8291388d1", "origin": "Application (Microsoft Graph)", - "value": "VirtualAppointment.Read.All" + "value": "UserAuthMethod-PlatformCred.Read.All" }, { - "description": "Allows the application to list and read all Tenant Governance invitations without a signed-in user.", - "displayName": "Read Tenant Governance invitations", - "id": "3f4f98e9-6faf-4e5f-814b-ed2ed8a4ec9e", + "description": "Allows the application to list and read all Tenant Governance policy templates without a signed-in user.", + "displayName": "Read Tenant Governance policy templates", + "id": "eb9465d8-e7c0-4301-8e51-927f34ee3134", "origin": "Application (Microsoft Graph)", - "value": "TenantGovernance-Invitation.Read.All" + "value": "TenantGovernance-PolicyTemplate.Read.All" }, { - "description": "Allows the app to read and write tags in Teams without a signed-in user.", - "displayName": "Read and write tags in Teams", - "id": "a3371ca5-911d-46d6-901c-42c8c7a937d8", + "description": "Allows the application to list and read all Tenant Governance invitations without a signed-in user.", + "displayName": "Read Tenant Governance invitations", + "id": "3f4f98e9-6faf-4e5f-814b-ed2ed8a4ec9e", "origin": "Application (Microsoft Graph)", - "value": "TeamworkTag.ReadWrite.All" + "value": "TenantGovernance-Invitation.Read.All" }, { - "description": "Allows the app to create teams without a signed-in user. ", - "displayName": "Create teams", - "id": "23fc2474-f741-46ce-8465-674744c5c361", + "description": "Allows the app to read all group chat or channel targeted messages in Microsoft Teams.", + "displayName": "Read all targeted messages of group chat or channel", + "id": "b0cfd829-be18-4b31-bb0e-ec1df8197ba3", "origin": "Application (Microsoft Graph)", - "value": "Team.Create" + "value": "TeamworkTargetedMessage.Read.All" }, { "description": "Get a list of all teams, without a signed-in user.", @@ -14636,13 +14657,6 @@ "origin": "Application (Microsoft Graph)", "value": "TeamsAppInstallation.ReadSelectedForUser.All" }, - { - "description": "Allows the app to create, read, update and delete all users’ tasks and task lists in your organization, without a signed-in user", - "displayName": "Read and write all users’ tasks and tasklists", - "id": "44e666d1-d276-445b-a5fc-8815eeb81d55", - "origin": "Application (Microsoft Graph)", - "value": "Tasks.ReadWrite.All" - }, { "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any chat, without a signed-in user. Gives the ability to manage permission grants for accessing those specific chats' data.", "displayName": "Manage installation and permission grants of Teams apps for all chats", @@ -14650,6 +14664,20 @@ "origin": "Application (Microsoft Graph)", "value": "TeamsAppInstallation.ReadWriteAndConsentForChat.All" }, + { + "description": "Allows the app to create teams without a signed-in user. ", + "displayName": "Create teams", + "id": "23fc2474-f741-46ce-8465-674744c5c361", + "origin": "Application (Microsoft Graph)", + "value": "Team.Create" + }, + { + "description": "Allows the app to create, read, update and delete all users’ tasks and task lists in your organization, without a signed-in user", + "displayName": "Read and write all users’ tasks and tasklists", + "id": "44e666d1-d276-445b-a5fc-8815eeb81d55", + "origin": "Application (Microsoft Graph)", + "value": "Tasks.ReadWrite.All" + }, { "description": "Allows the app to read all users’ tasks and task lists in your organization, without a signed-in user.", "displayName": "Read all users’ tasks and tasklist", @@ -14658,11 +14686,11 @@ "value": "Tasks.Read.All" }, { - "description": "Allows the application to upload bulk user data to the identity synchronization service, without a signed-in user.", - "displayName": "Upload user data to the identity synchronization service", - "id": "db31e92a-b9ea-4d87-bf6a-75a37a9ca35a", + "description": "Allows the application to upload bulk user data to the identity synchronization service for apps that this application creates or owns, without a signed-in user.", + "displayName": "Upload user data to the identity sync service for apps that this application creates or owns", + "id": "25c32ff3-849a-494b-b94f-20a8ac4e6774", "origin": "Application (Microsoft Graph)", - "value": "SynchronizationData-User.Upload" + "value": "SynchronizationData-User.Upload.OwnedBy" }, { "description": "Allows the app to read, create, edit, and delete all the short notes without a signed-in user.", @@ -14720,6 +14748,13 @@ "origin": "Application (Microsoft Graph)", "value": "Sites.Read.All" }, + { + "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any team, without a signed-in user. Gives the ability to manage permission grants for accessing those specific teams' data.", + "displayName": "Manage installation and permission grants of Teams apps for all teams", + "id": "b0c13be0-8e20-4bc5-8c55-963c23a39ce9", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteAndConsentForTeam.All" + }, { "description": "Allows the app to create, read, update, and delete documents and list items in all site collections without a signed in user.", "displayName": "Read and write items in all site collections", @@ -14727,13 +14762,6 @@ "origin": "Application (Microsoft Graph)", "value": "Sites.ReadWrite.All" }, - { - "description": "Allow the application to access a subset of site collections without a signed in user. The specific site collections and the permissions granted will be configured in SharePoint Online.", - "displayName": "Access selected site collections", - "id": "883ea226-0bf2-4a8f-9f9d-92c9162a727d", - "origin": "Application (Microsoft Graph)", - "value": "Sites.Selected" - }, { "description": "Allows the app to read your organization's SPIFFE trust domains and child resources without a signed in user.", "displayName": "Read SPIFFE trust domains and child resources", @@ -14784,18 +14812,25 @@ "value": "Synchronization.ReadWrite.All" }, { - "description": "Allows the application to upload bulk user data to the identity synchronization service for apps that this application creates or owns, without a signed-in user.", - "displayName": "Upload user data to the identity sync service for apps that this application creates or owns", - "id": "25c32ff3-849a-494b-b94f-20a8ac4e6774", + "description": "Allows the application to upload bulk user data to the identity synchronization service, without a signed-in user.", + "displayName": "Upload user data to the identity synchronization service", + "id": "db31e92a-b9ea-4d87-bf6a-75a37a9ca35a", "origin": "Application (Microsoft Graph)", - "value": "SynchronizationData-User.Upload.OwnedBy" + "value": "SynchronizationData-User.Upload" }, { - "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any team, without a signed-in user. Gives the ability to manage permission grants for accessing those specific teams' data.", - "displayName": "Manage installation and permission grants of Teams apps for all teams", - "id": "b0c13be0-8e20-4bc5-8c55-963c23a39ce9", + "description": "Allow the application to access a subset of site collections without a signed in user. The specific site collections and the permissions granted will be configured in SharePoint Online.", + "displayName": "Access selected site collections", + "id": "883ea226-0bf2-4a8f-9f9d-92c9162a727d", "origin": "Application (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteAndConsentForTeam.All" + "value": "Sites.Selected" + }, + { + "description": "Allows the application to read and write virtual appointments for all users, without a signed-in user. The app must also be authorized to access an individual user’s data by the online meetings application access policy.", + "displayName": "Read-write all virtual appointments for users, as authorized by online meetings app access policy", + "id": "bf46a256-f47d-448f-ab78-f226fff08d40", + "origin": "Application (Microsoft Graph)", + "value": "VirtualAppointment.ReadWrite.All" }, { "description": "Allows the app to read, install, upgrade, and uninstall Teams apps in any user account, without a signed-in user. Gives the ability to manage permission grants for accessing those specific users' data.", @@ -14805,18 +14840,11 @@ "value": "TeamsAppInstallation.ReadWriteAndConsentForUser.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any chat, without a signed-in user, and manage its permission grants for accessing those specific chats' data.", - "displayName": "Allow the Teams app to manage itself and its permission grants for all chats", - "id": "ba1ba90b-2d8f-487e-9f16-80728d85bb5c", - "origin": "Application (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForChat.All" - }, - { - "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs in any team, without a signed-in user.", - "displayName": "Allow the Teams app to manage only its own tabs for all teams", - "id": "91c32b81-0ef0-453f-a5c7-4ce2e562f449", + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any team, without a signed-in user, and manage its permission grants for accessing those specific teams' data.", + "displayName": "Allow the Teams app to manage itself and its permission grants for all teams", + "id": "1e4be56c-312e-42b8-a2c9-009600d732c0", "origin": "Application (Microsoft Graph)", - "value": "TeamsTab.ReadWriteSelfForTeam.All" + "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForTeam.All" }, { "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for any user, without a signed-in user.", @@ -14930,6 +14958,20 @@ "origin": "Application (Microsoft Graph)", "value": "TeamworkTag.Read.All" }, + { + "description": "Allows the app to read and write tags in Teams without a signed-in user.", + "displayName": "Read and write tags in Teams", + "id": "a3371ca5-911d-46d6-901c-42c8c7a937d8", + "origin": "Application (Microsoft Graph)", + "value": "TeamworkTag.ReadWrite.All" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs in any team, without a signed-in user.", + "displayName": "Allow the Teams app to manage only its own tabs for all teams", + "id": "91c32b81-0ef0-453f-a5c7-4ce2e562f449", + "origin": "Application (Microsoft Graph)", + "value": "TeamsTab.ReadWriteSelfForTeam.All" + }, { "description": "Allows a Teams app to read, install, upgrade, and uninstall its own tabs for any chat, without a signed-in user.", "displayName": "Allow the Teams app to manage only its own tabs for all chats", @@ -14951,20 +14993,6 @@ "origin": "Application (Microsoft Graph)", "value": "TeamsTab.ReadWriteForTeam.All" }, - { - "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs for any chat, without a signed-in user.", - "displayName": "Allow the Teams app to manage all tabs for all chats", - "id": "fd9ce730-a250-40dc-bd44-8dc8d20f39ea", - "origin": "Application (Microsoft Graph)", - "value": "TeamsTab.ReadWriteForChat.All" - }, - { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any team, without a signed-in user, and manage its permission grants for accessing those specific teams' data.", - "displayName": "Allow the Teams app to manage itself and its permission grants for all teams", - "id": "1e4be56c-312e-42b8-a2c9-009600d732c0", - "origin": "Application (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForTeam.All" - }, { "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any user account, without a signed-in user, and manage its permission grants for accessing those specific users' data.", "displayName": "Allow the Teams app to manage itself and its permission grants in all user accounts", @@ -15014,13 +15042,6 @@ "origin": "Application (Microsoft Graph)", "value": "TeamsAppInstallation.ReadWriteSelectedForUser.All" }, - { - "description": "Allows the app to read all group chat or channel targeted messages in Microsoft Teams.", - "displayName": "Read all targeted messages of group chat or channel", - "id": "b0cfd829-be18-4b31-bb0e-ec1df8197ba3", - "origin": "Application (Microsoft Graph)", - "value": "TeamworkTargetedMessage.Read.All" - }, { "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any chat, without a signed-in user.", "displayName": "Allow the Teams app to manage itself for all chats", @@ -15029,11 +15050,18 @@ "value": "TeamsAppInstallation.ReadWriteSelfForChat.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself to any user, without a signed-in user.", - "displayName": "Allow the app to manage itself for all users", - "id": "908de74d-f8b2-4d6b-a9ed-2a17b3b78179", + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself for any chat, without a signed-in user, and manage its permission grants for accessing those specific chats' data.", + "displayName": "Allow the Teams app to manage itself and its permission grants for all chats", + "id": "ba1ba90b-2d8f-487e-9f16-80728d85bb5c", "origin": "Application (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteSelfForUser.All" + "value": "TeamsAppInstallation.ReadWriteAndConsentSelfForChat.All" + }, + { + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in any team, without a signed-in user.", + "displayName": "Allow the Teams app to manage itself for all teams", + "id": "9f67436c-5415-4e7f-8ac1-3014a7132630", + "origin": "Application (Microsoft Graph)", + "value": "TeamsAppInstallation.ReadWriteSelfForTeam.All" }, { "description": "Read all team's settings, without a signed-in user.", @@ -15085,18 +15113,25 @@ "value": "TeamsTab.ReadWrite.All" }, { - "description": "Allows a Teams app to read, install, upgrade, and uninstall itself in any team, without a signed-in user.", - "displayName": "Allow the Teams app to manage itself for all teams", - "id": "9f67436c-5415-4e7f-8ac1-3014a7132630", + "description": "Allows a Teams app to read, install, upgrade, and uninstall all tabs for any chat, without a signed-in user.", + "displayName": "Allow the Teams app to manage all tabs for all chats", + "id": "fd9ce730-a250-40dc-bd44-8dc8d20f39ea", "origin": "Application (Microsoft Graph)", - "value": "TeamsAppInstallation.ReadWriteSelfForTeam.All" + "value": "TeamsTab.ReadWriteForChat.All" }, { - "description": "Allows the application to read and write virtual appointments for all users, without a signed-in user. The app must also be authorized to access an individual user’s data by the online meetings application access policy.", - "displayName": "Read-write all virtual appointments for users, as authorized by online meetings app access policy", - "id": "bf46a256-f47d-448f-ab78-f226fff08d40", + "description": "Allows a Teams app to read, install, upgrade, and uninstall itself to any user, without a signed-in user.", + "displayName": "Allow the app to manage itself for all users", + "id": "908de74d-f8b2-4d6b-a9ed-2a17b3b78179", "origin": "Application (Microsoft Graph)", - "value": "VirtualAppointment.ReadWrite.All" + "value": "TeamsAppInstallation.ReadWriteSelfForUser.All" + }, + { + "description": "Allows the app to read all the short notes without a signed-in user.", + "displayName": "Read all users' short notes", + "id": "0c7d31ec-31ca-4f58-b6ec-9950b6b0de69", + "origin": "Application (Microsoft Graph)", + "value": "ShortNotes.Read.All" }, { "description": "Allows the application to send notification regarding virtual appointments as any user, without a signed-in user. The app must also be authorized to access an individual user's data by the online meetings application access policy.", @@ -15106,18 +15141,11 @@ "value": "VirtualAppointmentNotification.Send" }, { - "description": "Allows the app to read all virtual events without a signed-in user.", - "displayName": "Read all users' virtual events", - "id": "1dccb351-c4e4-4e09-a8d1-7a9ecbf027cc", + "description": "Allows the app to read and write anonymous users' virtual event registrations, without a signed-in user", + "displayName": "Read and write anonymous users' virtual event registrations", + "id": "23211fc1-f9d1-4e8e-8e9e-08a5d0a109bb", "origin": "Application (Microsoft Graph)", - "value": "VirtualEvent.Read.All" - }, - { - "description": "Allows the app to read events in user calendars, except for properties such as body, attachments, and extensions.", - "displayName": "Read basic details of user calendars", - "id": "662d75ba-a364-42ad-adee-f5f880ea4878", - "origin": "Delegated (Microsoft Graph)", - "value": "Calendars.ReadBasic" + "value": "VirtualEventRegistration-Anon.ReadWrite.All" }, { "description": "Allows the app to create, read, update, and delete events in user calendars.", @@ -15231,13 +15259,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "ChannelMember.ReadWrite.All" }, - { - "description": "Allows the app to read events in all calendars that the user can access, including delegate and shared calendars.", - "displayName": "Read user and shared calendars", - "id": "2b9c4092-424d-4249-948d-b43879977640", - "origin": "Delegated (Microsoft Graph)", - "value": "Calendars.Read.Shared" - }, { "description": "Allows an app to edit channel messages in Microsoft Teams, on behalf of the signed-in user.", "displayName": "Edit user's channel messages", @@ -15246,25 +15267,32 @@ "value": "ChannelMessage.Edit" }, { - "description": "Allows the app to read events in user calendars.", - "displayName": "Read user calendars ", - "id": "465a38f9-76ea-45b9-9f34-9e8b0d4b0b42", + "description": "Allows the app to read events in user calendars, except for properties such as body, attachments, and extensions.", + "displayName": "Read basic details of user calendars", + "id": "662d75ba-a364-42ad-adee-f5f880ea4878", "origin": "Delegated (Microsoft Graph)", - "value": "Calendars.Read" + "value": "Calendars.ReadBasic" }, { - "description": "Allows the app to read all data associated with the business scenarios it owns. Data access will be attributed to the signed-in user.", - "displayName": "Read all data for business scenarios this app creates or owns", - "id": "25b265c4-5d34-4e44-952d-b567f6d3b96d", + "description": "Allows an app to read a channel's messages in Microsoft Teams, on behalf of the signed-in user.", + "displayName": "Read user channel messages", + "id": "767156cb-16ae-4d10-8f8b-41b657c8c8c8", "origin": "Delegated (Microsoft Graph)", - "value": "BusinessScenarioData.Read.OwnedBy" + "value": "ChannelMessage.Read.All" }, { - "description": "Allows the app to read restore sessions, on behalf of the signed in user.", - "displayName": "Read restore sessions", - "id": "94b36f78-434f-4904-8c08-421d9a9c1dc2", + "description": "Allows the app to read events in all calendars that the user can access, including delegate and shared calendars.", + "displayName": "Read user and shared calendars", + "id": "2b9c4092-424d-4249-948d-b43879977640", "origin": "Delegated (Microsoft Graph)", - "value": "BackupRestore-Restore.Read.All" + "value": "Calendars.Read.Shared" + }, + { + "description": "Allows the app to fully manage all data associated with the business scenarios it owns. Data access and changes will be attributed to the signed-in user.", + "displayName": "Read and write all data for business scenarios this app creates or owns", + "id": "19932d57-2952-4c60-8634-3655c79fc527", + "origin": "Delegated (Microsoft Graph)", + "value": "BusinessScenarioData.ReadWrite.OwnedBy" }, { "description": "Allows the app to search the backup snapshots for Microsoft 365 resources, and restore Microsoft 365 resources from a backed-up snapshot, on behalf of the signed in user.", @@ -15379,18 +15407,18 @@ "value": "BusinessScenarioConfig.ReadWrite.OwnedBy" }, { - "description": "Allows the app to fully manage all data associated with the business scenarios it owns. Data access and changes will be attributed to the signed-in user.", - "displayName": "Read and write all data for business scenarios this app creates or owns", - "id": "19932d57-2952-4c60-8634-3655c79fc527", + "description": "Allows the app to read all data associated with the business scenarios it owns. Data access will be attributed to the signed-in user.", + "displayName": "Read all data for business scenarios this app creates or owns", + "id": "25b265c4-5d34-4e44-952d-b567f6d3b96d", "origin": "Delegated (Microsoft Graph)", - "value": "BusinessScenarioData.ReadWrite.OwnedBy" + "value": "BusinessScenarioData.Read.OwnedBy" }, { - "description": "Allows an app to read a channel's messages in Microsoft Teams, on behalf of the signed-in user.", - "displayName": "Read user channel messages", - "id": "767156cb-16ae-4d10-8f8b-41b657c8c8c8", + "description": "Allows the app to read events in user calendars.", + "displayName": "Read user calendars ", + "id": "465a38f9-76ea-45b9-9f34-9e8b0d4b0b42", "origin": "Delegated (Microsoft Graph)", - "value": "ChannelMessage.Read.All" + "value": "Calendars.Read" }, { "description": "Allows the app to read and write channel messages, on behalf of the signed-in user. This doesn't allow the app to edit the policyViolation of a channel message.", @@ -15407,11 +15435,11 @@ "value": "ChannelMessage.Send" }, { - "description": "Allows the app to read and approve consent requests on behalf of the signed in user.", - "displayName": "Read and approve consent requests", - "id": "e694a3a1-7878-46d8-8c29-3d195f6589f4", + "description": "Read all channel names, channel descriptions, and channel settings, on behalf of the signed-in user.", + "displayName": "Read the names, descriptions, and settings of channels", + "id": "233e0cf1-dd62-48bc-b65b-b38fe87fcf8e", "origin": "Delegated (Microsoft Graph)", - "value": "ConsentRequest.ReadApprove.All" + "value": "ChannelSettings.Read.All" }, { "description": "Allows the app to read app consent requests and approvals, and deny or approve those requests on behalf of the signed-in user.", @@ -15525,6 +15553,20 @@ "origin": "Delegated (Microsoft Graph)", "value": "CopilotPolicySettings.ReadWrite" }, + { + "description": "Allows the app to read organization-wide copilot limited mode setting on behalf of the signed-in user.", + "displayName": "Read organization-wide copilot limited mode setting", + "id": "aeb2982d-632d-4155-b533-18756ab6fdd8", + "origin": "Delegated (Microsoft Graph)", + "value": "CopilotSettings-LimitedMode.Read" + }, + { + "description": "Allows the app to read and approve consent requests on behalf of the signed in user.", + "displayName": "Read and approve consent requests", + "id": "e694a3a1-7878-46d8-8c29-3d195f6589f4", + "origin": "Delegated (Microsoft Graph)", + "value": "ConsentRequest.ReadApprove.All" + }, { "description": "Allows the app to read consent requests and approvals on behalf of the signed-in user.", "displayName": "Read consent requests", @@ -15546,20 +15588,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "ConsentRequest.Create" }, - { - "description": "Allows the app to read and write all Configuration Monitoring entities on behalf of the signed-in user.", - "displayName": "Read and write all Configuration Monitoring entities", - "id": "54505ce9-e719-41f7-a7cc-dbe114e1d811", - "origin": "Delegated (Microsoft Graph)", - "value": "ConfigurationMonitoring.ReadWrite.All" - }, - { - "description": "Read all channel names, channel descriptions, and channel settings, on behalf of the signed-in user.", - "displayName": "Read the names, descriptions, and settings of channels", - "id": "233e0cf1-dd62-48bc-b65b-b38fe87fcf8e", - "origin": "Delegated (Microsoft Graph)", - "value": "ChannelSettings.Read.All" - }, { "description": "Read and write the names, descriptions, and settings of all channels, on behalf of the signed-in user.", "displayName": "Read and write the names, descriptions, and settings of channels", @@ -15609,13 +15637,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "Chat.ReadWrite.All" }, - { - "description": "Allows the app to monitor backup and restore jobs, view quota usage and billing details, on behalf of the signed in user.", - "displayName": "Read monitoring, quota and billing information for the tenant", - "id": "b4e98de1-4600-4e90-b5e1-7c1dfef04e5c", - "origin": "Delegated (Microsoft Graph)", - "value": "BackupRestore-Monitor.Read.All" - }, { "description": "Read the members of chats, on behalf of the signed-in user.", "displayName": "Read the members of chats", @@ -15624,11 +15645,18 @@ "value": "ChatMember.Read" }, { - "description": "Allows an app to read one-to-one and group chat messages, on behalf of the signed-in user.", - "displayName": "Read user chat messages", - "id": "cdcdac3a-fd45-410d-83ef-554db620e5c7", + "description": "Allows the app to read restore sessions, on behalf of the signed in user.", + "displayName": "Read restore sessions", + "id": "94b36f78-434f-4904-8c08-421d9a9c1dc2", "origin": "Delegated (Microsoft Graph)", - "value": "ChatMessage.Read" + "value": "BackupRestore-Restore.Read.All" + }, + { + "description": "Add and remove members from chats, on behalf of the signed-in user.", + "displayName": "Add and remove members from chats", + "id": "dea13482-7ea6-488f-8b98-eb5bbecf033d", + "origin": "Delegated (Microsoft Graph)", + "value": "ChatMember.ReadWrite" }, { "description": "Allows an app to send one-to-one and group chat messages in Microsoft Teams, on behalf of the signed-in user.", @@ -15680,11 +15708,25 @@ "value": "ConfigurationMonitoring.Read.All" }, { - "description": "Add and remove members from chats, on behalf of the signed-in user.", - "displayName": "Add and remove members from chats", - "id": "dea13482-7ea6-488f-8b98-eb5bbecf033d", + "description": "Allows the app to read and write all Configuration Monitoring entities on behalf of the signed-in user.", + "displayName": "Read and write all Configuration Monitoring entities", + "id": "54505ce9-e719-41f7-a7cc-dbe114e1d811", "origin": "Delegated (Microsoft Graph)", - "value": "ChatMember.ReadWrite" + "value": "ConfigurationMonitoring.ReadWrite.All" + }, + { + "description": "Allows an app to read one-to-one and group chat messages, on behalf of the signed-in user.", + "displayName": "Read user chat messages", + "id": "cdcdac3a-fd45-410d-83ef-554db620e5c7", + "origin": "Delegated (Microsoft Graph)", + "value": "ChatMessage.Read" + }, + { + "description": "Allows the app to monitor backup and restore jobs, view quota usage and billing details, on behalf of the signed in user.", + "displayName": "Read monitoring, quota and billing information for the tenant", + "id": "b4e98de1-4600-4e90-b5e1-7c1dfef04e5c", + "origin": "Delegated (Microsoft Graph)", + "value": "BackupRestore-Monitor.Read.All" }, { "description": "Allows the app to update or read the status of M365 backup service (enable/disable), on behalf of the signed in user.", @@ -15700,20 +15742,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "BackupRestore-Control.Read.All" }, - { - "description": "Allows the app to read and update the backup configuration, and list of Microsoft 365 service resources to be backed-up, on behalf of the signed in user.", - "displayName": "Read and edit backup configuration policies", - "id": "a0244d16-171c-4496-8ffb-7b9b6954d339", - "origin": "Delegated (Microsoft Graph)", - "value": "BackupRestore-Configuration.ReadWrite.All" - }, - { - "description": "Allows the app to read and update the communication configuration of agent blueprints on behalf of the signed-in user.", - "displayName": "Read and write agent communication configuration", - "id": "15e0db35-0641-4175-b014-c2cb39286338", - "origin": "Delegated (Microsoft Graph)", - "value": "AgentCommunicationConfiguration.ReadWrite" - }, { "description": "Allows the client to create agent identities on behalf of the signed-in user, even if the client is not the parent agent identity blueprint.", "displayName": "Create agent identities without an agent blueprint parent", @@ -15826,6 +15854,20 @@ "origin": "Delegated (Microsoft Graph)", "value": "AgentIdentityBlueprintPrincipal.Read.All" }, + { + "description": "Allows the app to read, update, create, and delete agent identity blueprint principals on behalf of the signed-in user.", + "displayName": "Read and write all agent identity blueprint principals.", + "id": "bf2cad6a-9082-438a-9a63-95fa2687af65", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentIdentityBlueprintPrincipal.ReadWrite.All" + }, + { + "description": "Allows the app to read and update the communication configuration of agent blueprints on behalf of the signed-in user.", + "displayName": "Read and write agent communication configuration", + "id": "15e0db35-0641-4175-b014-c2cb39286338", + "origin": "Delegated (Microsoft Graph)", + "value": "AgentCommunicationConfiguration.ReadWrite" + }, { "description": "Allows the app to read the communication configuration of agent blueprints on behalf of the signed-in user.", "displayName": "Read agent communication configuration", @@ -15847,20 +15889,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "AgentCollection.ReadWrite.Global" }, - { - "description": "Allows the app to create, read, update, and delete collections and manage their membership in your organization's Agent Registry on behalf of the signed-in user.", - "displayName": "Read and write collections in Agent Registry, except quarantined and global", - "id": "6d8a7002-a05e-4b95-a768-0e6f0badc6c8", - "origin": "Delegated (Microsoft Graph)", - "value": "AgentCollection.ReadWrite.All" - }, - { - "description": "Allows the app to read and write anonymous users' virtual event registrations, without a signed-in user", - "displayName": "Read and write anonymous users' virtual event registrations", - "id": "23211fc1-f9d1-4e8e-8e9e-08a5d0a109bb", - "origin": "Application (Microsoft Graph)", - "value": "VirtualEventRegistration-Anon.ReadWrite.All" - }, { "description": "Allows the app to read all Windows update deployment settings for the organization without a signed-in user.", "displayName": "Read all Windows update deployment settings", @@ -15910,13 +15938,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "AccessReview.ReadWrite.Membership" }, - { - "description": "Allows the app to read, update, create, and delete agent identity blueprint principals on behalf of the signed-in user.", - "displayName": "Read and write all agent identity blueprint principals.", - "id": "bf2cad6a-9082-438a-9a63-95fa2687af65", - "origin": "Delegated (Microsoft Graph)", - "value": "AgentIdentityBlueprintPrincipal.ReadWrite.All" - }, { "description": "Allows an app to read all acronyms that the signed-in user can access.", "displayName": "Read all acronyms that the user can access", @@ -15925,11 +15946,18 @@ "value": "Acronym.Read.All" }, { - "description": "Allows the app to create, read, update, and delete administrative units and manage administrative unit membership on behalf of the signed-in user.", - "displayName": "Read and write administrative units", - "id": "7b8a2d34-6b3f-4542-a343-54651608ad81", + "description": "Allows the app to create agent users, read and write the full set of profile properties, reports, and managers of agent ID users, delete and restore agent users in your organization, and read basic company properties, on behalf of the signed-in user.", + "displayName": "Read and write all agent ID users' full profiles", + "id": "ad57fb88-4658-4fd6-ab7d-e43184b08e4e", "origin": "Delegated (Microsoft Graph)", - "value": "AdministrativeUnit.ReadWrite.All" + "value": "AgentIdUser.ReadWrite.All" + }, + { + "description": "Allows the app to read administrative units and administrative unit membership on behalf of the signed-in user.", + "displayName": "Read administrative units", + "id": "3361d15d-be43-4de6-b441-3c746d05163d", + "origin": "Delegated (Microsoft Graph)", + "value": "AdministrativeUnit.Read.All" }, { "description": "Allows the app to read agent cards and their skills in your organization's Agent Registry on behalf of the signed-in user.", @@ -15981,39 +16009,39 @@ "value": "AgentCollection.Read.Quarantined" }, { - "description": "Allows the app to read administrative units and administrative unit membership on behalf of the signed-in user.", - "displayName": "Read administrative units", - "id": "3361d15d-be43-4de6-b441-3c746d05163d", + "description": "Allows the app to create, read, update, and delete collections and manage their membership in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read and write collections in Agent Registry, except quarantined and global", + "id": "6d8a7002-a05e-4b95-a768-0e6f0badc6c8", "origin": "Delegated (Microsoft Graph)", - "value": "AdministrativeUnit.Read.All" + "value": "AgentCollection.ReadWrite.All" }, { - "description": "Allows the app to read all the short notes without a signed-in user.", - "displayName": "Read all users' short notes", - "id": "0c7d31ec-31ca-4f58-b6ec-9950b6b0de69", - "origin": "Application (Microsoft Graph)", - "value": "ShortNotes.Read.All" + "description": "Allows the app to create, read, update, and delete administrative units and manage administrative unit membership on behalf of the signed-in user.", + "displayName": "Read and write administrative units", + "id": "7b8a2d34-6b3f-4542-a343-54651608ad81", + "origin": "Delegated (Microsoft Graph)", + "value": "AdministrativeUnit.ReadWrite.All" }, { - "description": "Allows the app to create agent users, read and write the full set of profile properties, reports, and managers of agent ID users, delete and restore agent users in your organization, and read basic company properties, on behalf of the signed-in user.", - "displayName": "Read and write all agent ID users' full profiles", - "id": "ad57fb88-4658-4fd6-ab7d-e43184b08e4e", - "origin": "Delegated (Microsoft Graph)", - "value": "AgentIdUser.ReadWrite.All" + "description": "Allows the app to read all virtual events without a signed-in user.", + "displayName": "Read all users' virtual events", + "id": "1dccb351-c4e4-4e09-a8d1-7a9ecbf027cc", + "origin": "Application (Microsoft Graph)", + "value": "VirtualEvent.Read.All" }, { - "description": "Allows the app to read agent instances and their related collections in your organization's Agent Registry on behalf of the signed-in user.", - "displayName": "Read all agent instances in Agent Registry", - "id": "4c3c738a-2df0-4877-bf4a-f796950ff34c", + "description": "Allows the app to create agent users, read and write the full set of profile properties, reports, and managers of agent ID users in your organization, delete and restore agent users under an agent blueprint, and read basic company properties, on behalf of the signed-in user.", + "displayName": "Read and write full profiles of agent ID users under an agent blueprint", + "id": "52a417d9-0b3c-4466-9a3b-66960de73d74", "origin": "Delegated (Microsoft Graph)", - "value": "AgentInstance.Read.All" + "value": "AgentIdUser.ReadWrite.IdentityParentedBy" }, { - "description": "Allows the app to provision, read, create, and respond to approvals on behalf of the signed-in user.", - "displayName": "Read, create, and respond to approvals", - "id": "6768d3af-4562-48ff-82d2-c5e19eb21b9c", + "description": "Allows the app to create, read, update, and delete agent instances in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read and write agent instances in Agent Registry", + "id": "fc79e324-da24-497a-b5ec-e7de08320375", "origin": "Delegated (Microsoft Graph)", - "value": "ApprovalSolution.ReadWrite" + "value": "AgentInstance.ReadWrite.All" }, { "description": "Allows the app to read and respond to approvals on behalf of the signed-in user.", @@ -16127,6 +16155,20 @@ "origin": "Delegated (Microsoft Graph)", "value": "BackupRestore-Configuration.Read.All" }, + { + "description": "Allows the app to read and update the backup configuration, and list of Microsoft 365 service resources to be backed-up, on behalf of the signed in user.", + "displayName": "Read and edit backup configuration policies", + "id": "a0244d16-171c-4496-8ffb-7b9b6954d339", + "origin": "Delegated (Microsoft Graph)", + "value": "BackupRestore-Configuration.ReadWrite.All" + }, + { + "description": "Allows the app to provision, read, create, and respond to approvals on behalf of the signed-in user.", + "displayName": "Read, create, and respond to approvals", + "id": "6768d3af-4562-48ff-82d2-c5e19eb21b9c", + "origin": "Delegated (Microsoft Graph)", + "value": "ApprovalSolution.ReadWrite" + }, { "description": "Allows the app to read approvals on behalf of the signed-in user.", "displayName": "Read approvals", @@ -16148,20 +16190,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "Application-RemoteDesktopConfig.ReadWrite.All" }, - { - "description": "Allows the app to create, read, update and delete applications and service principals on behalf of the signed-in user. Allows management of app role assignments, except those exposed by Microsoft Graph. Does not allow management of delegated permission grants.", - "displayName": "Read and write applications", - "id": "bdfbf15f-ee85-4955-8675-146e8e5296b5", - "origin": "Delegated (Microsoft Graph)", - "value": "Application.ReadWrite.All" - }, - { - "description": "Allows the app to create, read, update, and delete agent instances in your organization's Agent Registry on behalf of the signed-in user.", - "displayName": "Read and write agent instances in Agent Registry", - "id": "fc79e324-da24-497a-b5ec-e7de08320375", - "origin": "Delegated (Microsoft Graph)", - "value": "AgentInstance.ReadWrite.All" - }, { "description": "Allows the user to read all agent registration information", "displayName": "Read all agent registrations", @@ -16211,13 +16239,6 @@ "origin": "Delegated (Microsoft Graph)", "value": "AiEnterpriseInteraction.Read" }, - { - "description": "Allows the app to create agent users, read and write the full set of profile properties, reports, and managers of agent ID users in your organization, delete and restore agent users under an agent blueprint, and read basic company properties, on behalf of the signed-in user.", - "displayName": "Read and write full profiles of agent ID users under an agent blueprint", - "id": "52a417d9-0b3c-4466-9a3b-66960de73d74", - "origin": "Delegated (Microsoft Graph)", - "value": "AgentIdUser.ReadWrite.IdentityParentedBy" - }, { "description": "Allows the app to read the signed-in user's activity statistics, such as how much time the user has spent on emails, in meetings, or in chat sessions.", "displayName": "Read user activity statistics", @@ -16226,11 +16247,18 @@ "value": "Analytics.Read" }, { - "description": "Allows the app to read, create and manage the API connectors used in user authentication flows, on behalf of the signed-in user.", - "displayName": "Read and write API connectors for authentication flows", - "id": "c67b52c5-7c69-48b6-9d48-7b3af3ded914", + "description": "Allows the app to read agent instances and their related collections in your organization's Agent Registry on behalf of the signed-in user.", + "displayName": "Read all agent instances in Agent Registry", + "id": "4c3c738a-2df0-4877-bf4a-f796950ff34c", "origin": "Delegated (Microsoft Graph)", - "value": "APIConnectors.ReadWrite.All" + "value": "AgentInstance.Read.All" + }, + { + "description": "Allows the app to read the API connectors used in user authentication flows, on behalf of the signed-in user.", + "displayName": "Read API connectors for authentication flows", + "id": "1b6ff35f-31df-4332-8571-d31ea5a4893f", + "origin": "Delegated (Microsoft Graph)", + "value": "APIConnectors.Read.All" }, { "description": "Allows the app to read the apps in the app catalogs.", @@ -16282,11 +16310,25 @@ "value": "Application.ReadUpdate.All" }, { - "description": "Allows the app to read the API connectors used in user authentication flows, on behalf of the signed-in user.", - "displayName": "Read API connectors for authentication flows", - "id": "1b6ff35f-31df-4332-8571-d31ea5a4893f", + "description": "Allows the app to create, read, update and delete applications and service principals on behalf of the signed-in user. Allows management of app role assignments, except those exposed by Microsoft Graph. Does not allow management of delegated permission grants.", + "displayName": "Read and write applications", + "id": "bdfbf15f-ee85-4955-8675-146e8e5296b5", "origin": "Delegated (Microsoft Graph)", - "value": "APIConnectors.Read.All" + "value": "Application.ReadWrite.All" + }, + { + "description": "Allows the app to read, create and manage the API connectors used in user authentication flows, on behalf of the signed-in user.", + "displayName": "Read and write API connectors for authentication flows", + "id": "c67b52c5-7c69-48b6-9d48-7b3af3ded914", + "origin": "Delegated (Microsoft Graph)", + "value": "APIConnectors.ReadWrite.All" + }, + { + "description": "Allows the application to obtain basic tenant information about another target tenant within the Azure AD ecosystem on behalf of the signed-in user.", + "displayName": "Read cross-tenant basic information", + "id": "81594d25-e88e-49cf-ac8c-fecbff49f994", + "origin": "Delegated (Microsoft Graph)", + "value": "CrossTenantInformation.ReadBasic.All" }, { "description": "Allows the application to read and change the tenant-level settings of SharePoint and OneDrive, without a signed-in user.", @@ -16295,13 +16337,6 @@ "origin": "Application (Microsoft Graph)", "value": "SharePointTenantSettings.ReadWrite.All" }, - { - "description": "Allows the application to read the tenant-level settings of SharePoint and OneDrive, without a signed-in user.", - "displayName": "Read SharePoint and OneDrive tenant settings", - "id": "83d4163d-a2d8-4d3b-9695-4ae3ca98f888", - "origin": "Application (Microsoft Graph)", - "value": "SharePointTenantSettings.Read.All" - }, { "description": "Allows the app to read your tenant's SharePoint Cross-Tenant migration settings and tasks, without a signed-in user.", "displayName": "Read SharePoint Cross-Tenant migration settings and tasks", @@ -17458,11 +17493,11 @@ "value": "GroupMember.Read.All" }, { - "description": "Allows the app to manage restricted resources based on the other permissions granted to the app, on behalf of the signed-in user.", - "displayName": "Manage restricted resources in the directory", - "id": "cba5390f-ed6a-4b7f-b657-0efc2210ed20", - "origin": "Delegated", - "value": "Directory.Write.Restricted" + "description": "Allows the application to read the tenant-level settings of SharePoint and OneDrive, without a signed-in user.", + "displayName": "Read SharePoint and OneDrive tenant settings", + "id": "83d4163d-a2d8-4d3b-9695-4ae3ca98f888", + "origin": "Application (Microsoft Graph)", + "value": "SharePointTenantSettings.Read.All" }, { "description": "Allows the app to read organization-wide apps and services settings, without a signed-in user.", diff --git a/Config/openapi.json b/Config/openapi.json index 6d83f1cc86524..7a37660c66dad 100644 --- a/Config/openapi.json +++ b/Config/openapi.json @@ -38886,6 +38886,58 @@ "x-cipp-role": "Endpoint.Autopilot.Read" } }, + "/api/ListApiEgress": { + "get": { + "summary": "ListApiEgress", + "operationId": "ListApiEgress", + "tags": [ + "CIPP > Settings" + ], + "description": "Per-API-client egress usage for this instance against the daily cap. Reads the\nCraftEgressAccounting table that the Craft runtime mirrors its egress accounting into (the same\nstorage account, so this reads it directly): a per-day audit row per client plus an instance\ntotal, and 15-minute buckets for the trend. Returns today's instance summary (used-of-cap,\nenforcing, when the cap was first hit, how many requests were shed), the per-client breakdown,\nand the last-24h instance trend. When the table has no data for today - accounting off, a\nnon-hosted instance, or simply no app-only traffic yet - Enabled is false and the UI hides the\ncard. SuperAdmin only.", + "parameters": [ + { + "name": "Hours", + "in": "query", + "required": false, + "schema": { + "type": "integer" + } + } + ], + "responses": { + "200": { + "description": "Success", + "content": { + "application/json": { + "schema": { + "type": "array", + "items": { + "type": "object", + "description": "Not described statically: this endpoint returns the upstream response as-is, so its fields are determined by the upstream API rather than by CIPP. Call the endpoint to see the actual shape, or add a response schema in backend/Config/openapi-overrides." + } + } + } + } + }, + "401": { + "description": "Unauthorized - invalid or missing bearer token" + }, + "403": { + "description": "Forbidden - caller lacks the required RBAC role" + }, + "500": { + "description": "Internal server error" + } + }, + "security": [ + { + "bearerAuth": [] + } + ], + "x-cipp-role": "CIPP.SuperAdmin.Read", + "x-cipp-any-tenant": true + } + }, "/api/ListApiTest": { "get": { "summary": "ListApiTest", @@ -49090,24 +49142,6 @@ "Bucket": { "x-cipp-field-source": "storage" }, - "EgressBytes": { - "x-cipp-field-source": "storage" - }, - "EgressBytesToday": { - "type": "integer", - "x-cipp-field-source": "storage" - }, - "EgressCapBytes": { - "x-cipp-field-source": "storage" - }, - "EgressRejectClients": { - "type": "string", - "x-cipp-field-source": "storage" - }, - "EgressRejectCount": { - "type": "integer", - "x-cipp-field-source": "storage" - }, "ErrCount": { "type": "integer", "x-cipp-field-source": "storage" diff --git a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Domain Analyser/Push-DomainAnalyserDomain.ps1 b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Domain Analyser/Push-DomainAnalyserDomain.ps1 index 508da7a7e02e6..cfb5d02467384 100644 --- a/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Domain Analyser/Push-DomainAnalyserDomain.ps1 +++ b/Modules/CIPPActivityTriggers/Public/Entrypoints/Activity Triggers/Domain Analyser/Push-DomainAnalyserDomain.ps1 @@ -242,6 +242,18 @@ function Push-DomainAnalyserDomain { $Result.DKIMEnabled = $false $ScoreExplanation.Add('DKIM Not Configured') | Out-Null } + + # Persist the selectors the analyser just discovered so GetDkimSelectors reads them from the + # Domains table instead of returning nothing (mirrors how Invoke-ListDomainHealth/ExecDnsConfig store them). + $DiscoveredSelectors = @($DkimRecord.Selectors | Where-Object { -not [string]::IsNullOrWhiteSpace($_) }) | Sort-Object -Unique + if ($DiscoveredSelectors.Count -gt 0) { + $DkimSelectorsJson = [string]($DiscoveredSelectors | ConvertTo-Json -Compress) + if ($DomainObject.PSObject.Properties.Name -notcontains 'DkimSelectors') { + $DomainObject | Add-Member -MemberType NoteProperty -Name DkimSelectors -Value $DkimSelectorsJson -Force + } else { + $DomainObject.DkimSelectors = $DkimSelectorsJson + } + } } catch { $Message = 'DKIM Exception' Write-LogMessage -API 'DomainAnalyser' -tenant $DomainObject.TenantId -message $Message -LogData (Get-CippException -Exception $_) -sev Error diff --git a/Modules/CIPPCore/Public/Authentication/Grant-CippAppGraphConsent.ps1 b/Modules/CIPPCore/Public/Authentication/Grant-CippAppGraphConsent.ps1 new file mode 100644 index 0000000000000..fb9198a70d561 --- /dev/null +++ b/Modules/CIPPCore/Public/Authentication/Grant-CippAppGraphConsent.ps1 @@ -0,0 +1,81 @@ +function Grant-CippAppGraphConsent { + <# + .SYNOPSIS + Ensures a tenant-wide (AllPrincipals) oauth2PermissionGrant exists from an app's service + principal to Microsoft Graph, covering the given delegated scopes. + .DESCRIPTION + Admin-consents delegated Microsoft Graph scopes for an app registration in the partner + tenant, so users signing in through it are not prompted to consent. Used to pre-consent + the OIDC + offline_access scopes an MCP client (Copilot Studio, Claude, ChatGPT, VS Code) + requests: without offline_access consent, Entra will not issue a refresh token and the + client re-authenticates every time the access token expires (~hourly). + + This matters most in tenants that disable user consent to applications (which CIPP's own + OauthConsentLowSec standard recommends): there, an un-consented offline_access request + silently yields no refresh token. Admin consent is the only reliable path. + + Additive — existing consented scopes are preserved and only the missing ones are added. + The service principal of a freshly created app is not always queryable immediately, so + the client SP lookup retries briefly before giving up. + .PARAMETER AppId + Application (client) ID of the app whose service principal should receive the grant. + .PARAMETER Scopes + Delegated Microsoft Graph scope names to ensure are consented (e.g. openid, profile, + offline_access). + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory)] + [string]$AppId, + + [Parameter(Mandatory)] + [string[]]$Scopes + ) + + $GraphAppId = '00000003-0000-0000-c000-000000000000' + + # The app's own service principal may still be replicating right after creation. + $ClientSp = $null + for ($Attempt = 1; $Attempt -le 3 -and -not $ClientSp.id; $Attempt++) { + try { + $ClientSp = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/servicePrincipals(appId='$AppId')?`$select=id" -NoAuthCheck $true -asapp $true + } catch { + Write-Information "[App-Consent] Service principal for $AppId not queryable yet (attempt $Attempt): $($_.Exception.Message)" + } + if (-not $ClientSp.id -and $Attempt -lt 3) { Start-Sleep -Seconds 2 } + } + if (-not $ClientSp.id) { + throw "Service principal for app '$AppId' was not found; cannot write consent grant yet." + } + + $GraphSp = New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/servicePrincipals(appId='$GraphAppId')?`$select=id" -NoAuthCheck $true -asapp $true + if (-not $GraphSp.id) { + throw 'Microsoft Graph service principal was not found in this tenant.' + } + + $Grants = @(New-GraphGetRequest -uri "https://graph.microsoft.com/v1.0/servicePrincipals/$($ClientSp.id)/oauth2PermissionGrants" -NoAuthCheck $true -asapp $true) + $TenantGrant = $Grants | Where-Object { $_.resourceId -eq $GraphSp.id -and $_.consentType -eq 'AllPrincipals' } | Select-Object -First 1 + + if ($TenantGrant) { + $CurrentScopes = @($TenantGrant.scope -split ' ' | Where-Object { $_ }) + $MissingScopes = @($Scopes | Where-Object { $_ -notin $CurrentScopes }) + if ($MissingScopes.Count -eq 0) { + return [PSCustomObject]@{ AppId = $AppId; Action = 'nochange'; Scopes = $CurrentScopes } + } + $MergedScopes = (@($CurrentScopes + $MissingScopes) | Sort-Object -Unique) -join ' ' + $PatchBody = @{ scope = $MergedScopes } | ConvertTo-Json -Compress + $null = New-GraphPOSTRequest -uri "https://graph.microsoft.com/v1.0/oauth2PermissionGrants/$($TenantGrant.id)" -body $PatchBody -type PATCH -NoAuthCheck $true -asapp $true + return [PSCustomObject]@{ AppId = $AppId; Action = 'updated'; Scopes = @($MergedScopes -split ' ') } + } + + $CreateBody = @{ + clientId = $ClientSp.id + consentType = 'AllPrincipals' + resourceId = $GraphSp.id + scope = ($Scopes -join ' ') + } | ConvertTo-Json -Compress + $null = New-GraphPOSTRequest -uri 'https://graph.microsoft.com/v1.0/oauth2PermissionGrants' -body $CreateBody -type POST -NoAuthCheck $true -asapp $true + return [PSCustomObject]@{ AppId = $AppId; Action = 'created'; Scopes = @($Scopes) } +} diff --git a/Modules/CIPPCore/Public/Authentication/Initialize-CIPPAuth.ps1 b/Modules/CIPPCore/Public/Authentication/Initialize-CIPPAuth.ps1 index 48666e1bbfb26..56aef6d4aab95 100644 --- a/Modules/CIPPCore/Public/Authentication/Initialize-CIPPAuth.ps1 +++ b/Modules/CIPPCore/Public/Authentication/Initialize-CIPPAuth.ps1 @@ -243,6 +243,59 @@ function Initialize-CIPPAuth { } else { Write-Information "[Auth-Init] EasyAuth already matches $($EnabledClients.Count) enabled API client(s) — no update needed" } + + # Ensure offline_access is admin-consented on every MCP-enabled client so Entra + # issues a refresh token — without it, MCP clients (Copilot Studio especially) + # re-authenticate roughly every hour when the access token expires. Set at + # client-creation time by Set-CIPPMCPClientApp, but re-checked here so a client + # created before this existed, or whose service principal had not replicated at + # creation, self-heals on the next warmup. Idempotent and cheap: the grant helper + # no-ops once the scopes are present. Best-effort per client. + foreach ($McpId in $McpClientIds) { + if ([string]::IsNullOrEmpty($McpId)) { continue } + try { + $McpConsent = Grant-CippAppGraphConsent -AppId $McpId -Scopes @('openid', 'profile', 'offline_access') + if ($McpConsent.Action -ne 'nochange') { + Write-Information "[Auth-Init] MCP client $McpId offline_access consent: $($McpConsent.Action)" + } + } catch { + Write-Information "[Auth-Init] MCP client $McpId offline_access consent reconcile failed (non-fatal): $_" + } + } + + # Ensure the MCP OAuth scope advertisement (challenge header + discovery docs) + # includes offline_access. These app settings are written by "Save to Azure", + # but a code deploy does NOT regenerate them — an instance that never re-saved + # after offline_access was added would still hand strict discovery clients + # (e.g. Copilot CLI) a scope with no offline_access, so they re-authenticate + # ~hourly. Reconcile on drift only: once offline_access is present this never + # writes (or restarts) again. Values come from the same helper Save to Azure + # uses, so a write here is byte-identical and self-terminating. + if ($McpClientIds.Count -gt 0 -and $env:WEBSITE_HOSTNAME) { + try { + $McpScope = "https://$($env:WEBSITE_HOSTNAME)/user_impersonation" + $HeaderTokens = @("$($env:WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES)" -split ' ' | Where-Object { $_ }) + $ScopeDrift = ('offline_access' -notin $HeaderTokens) -or ($McpScope -notin $HeaderTokens) + if (-not $ScopeDrift -and $env:CIPPNG) { + foreach ($DocJson in @($env:CRAFT_PRM, $env:CRAFT_PRM_AS)) { + $Supported = $null + try { $Supported = @(($DocJson | ConvertFrom-Json -ErrorAction Stop).scopes_supported) } catch { $ScopeDrift = $true; break } + if ('offline_access' -notin $Supported -or $McpScope -notin $Supported) { $ScopeDrift = $true; break } + } + } + if ($ScopeDrift) { + $McpRg = Get-CIPPFunctionAppResourceGroup -SiteName $env:WEBSITE_SITE_NAME + $McpAppSettings = Get-CippMcpScopeAppSettings -Hostname $env:WEBSITE_HOSTNAME -TenantId $env:TenantID -IsCippNg:([bool]$env:CIPPNG) + $null = Update-CIPPAzFunctionAppSetting -Name $env:WEBSITE_SITE_NAME -ResourceGroupName $McpRg -AppSetting $McpAppSettings + Write-Information '[Auth-Init] MCP OAuth scope advertisement was missing offline_access — reconciled app settings and requesting restart' + Request-CIPPRestart -Reason 'MCP OAuth scope settings reconciled (offline_access) during warmup' + } else { + Write-Information '[Auth-Init] MCP OAuth scope advertisement already includes offline_access — no update needed' + } + } catch { + Write-Information "[Auth-Init] MCP OAuth scope reconcile failed (non-fatal): $_" + } + } } } catch { Write-Information "[Auth-Init] API client reconcile failed (non-fatal): $_" diff --git a/Modules/CIPPCore/Public/Authentication/Set-CIPPMCPClientApp.ps1 b/Modules/CIPPCore/Public/Authentication/Set-CIPPMCPClientApp.ps1 index 8aadb98fdf12e..098ccf81bcdd6 100644 --- a/Modules/CIPPCore/Public/Authentication/Set-CIPPMCPClientApp.ps1 +++ b/Modules/CIPPCore/Public/Authentication/Set-CIPPMCPClientApp.ps1 @@ -125,12 +125,36 @@ function Set-CIPPMCPClientApp { $SpaRedirectUris.Add($Uri) } + # Declare offline_access (Microsoft Graph, delegated) so Entra will issue a refresh token to + # MCP clients. Without it, Copilot Studio (Manual OAuth) and stricter discovery clients + # re-prompt for sign-in roughly every hour when the access token expires. Additive — every + # permission already on the app is preserved; only offline_access is added if missing. + $GraphResourceId = '00000003-0000-0000-c000-000000000000' + $OfflineAccessId = '7427e0e9-2fba-42fe-b0c0-848c9e6a8182' + $RequiredResourceAccess = [System.Collections.Generic.List[object]]::new() + $GraphEntrySeen = $false + foreach ($Resource in @($App.requiredResourceAccess)) { + $ResourceAccess = [System.Collections.Generic.List[object]]::new() + foreach ($Access in @($Resource.resourceAccess)) { $ResourceAccess.Add(@{ id = $Access.id; type = $Access.type }) } + if ($Resource.resourceAppId -eq $GraphResourceId) { + $GraphEntrySeen = $true + if (-not ($ResourceAccess | Where-Object { $_.id -eq $OfflineAccessId })) { + $ResourceAccess.Add(@{ id = $OfflineAccessId; type = 'Scope' }) + } + } + $RequiredResourceAccess.Add(@{ resourceAppId = $Resource.resourceAppId; resourceAccess = @($ResourceAccess) }) + } + if (-not $GraphEntrySeen) { + $RequiredResourceAccess.Add(@{ resourceAppId = $GraphResourceId; resourceAccess = @(@{ id = $OfflineAccessId; type = 'Scope' }) }) + } + $PatchBody = @{ identifierUris = @($IdentifierUris) api = $Api web = @{ redirectUris = @($WebRedirectUris) } spa = @{ redirectUris = @($SpaRedirectUris) } publicClient = @{ redirectUris = @($PublicRedirectUris) } + requiredResourceAccess = @($RequiredResourceAccess) # "Allow public client flows" — required for the secret-less PKCE redemption every MCP # client above performs. isFallbackPublicClient = $true @@ -140,6 +164,20 @@ function Set-CIPPMCPClientApp { try { $null = New-GraphPOSTRequest -uri "https://graph.microsoft.com/v1.0/applications/$($App.id)" -type PATCH -body $PatchBody -NoAuthCheck $true -asapp $true Write-LogMessage -headers $Headers -API 'ExecApiClient' -message "Configured app registration $AppId as MCP resource (identifier URIs, v2 tokens, known MCP client callbacks + pre-authorization)." -Sev 'Info' + + # Admin-consent the OIDC + offline_access delegated scopes for this app so Entra + # issues the refresh token without a per-user consent prompt. Copilot Studio uses + # Manual OAuth and never reads the challenge/discovery scope, so this app-registration + # consent — not WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES — is what makes its refresh work. + # Best-effort: the app still works without it (users may see a one-time prompt, or the + # grant is retried the next time the client is saved), so a failure here is non-fatal. + try { + $ConsentResult = Grant-CippAppGraphConsent -AppId $AppId -Scopes @('openid', 'profile', 'offline_access') + Write-Information "[MCP-Client] offline_access admin-consent for $AppId : $($ConsentResult.Action)" + } catch { + Write-LogMessage -headers $Headers -API 'ExecApiClient' -message "MCP client $AppId configured, but admin-consent for offline_access could not be written (refresh tokens may prompt on first use): $($_.Exception.Message)" -Sev 'Warning' + } + return @{ Success = $true; IdentifierUris = @($IdentifierUris); RedirectUris = @($PublicRedirectUris) } } catch { $ErrMsg = $_.Exception.Message diff --git a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineGroupTemplateState.ps1 b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineGroupTemplateState.ps1 index 29745474a919b..a7c3124832f8e 100644 --- a/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineGroupTemplateState.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Get-CIPPBaselineGroupTemplateState.ps1 @@ -35,19 +35,17 @@ function Get-CIPPBaselineGroupTemplateState { if (-not $Template -or [string]::IsNullOrWhiteSpace($GroupName)) { return @{ Current = $null } } if ("$($Template.groupType)" -eq 'dynamicDistribution') { - $Distros = @(Get-CIPPBaselineCacheRows -TenantFilter $TenantFilter -Type 'ExoDynamicDistributionGroup') - if ($Distros.Count -eq 0 -and -not (Test-CIPPBaselineCacheCollected -TenantFilter $TenantFilter -Type 'ExoDynamicDistributionGroup')) { - return @{ Current = $null } - } - $Existing = $Distros | Where-Object { "$($_.Name)" -eq $GroupName } | Select-Object -First 1 - } else { - $Groups = @(Get-CIPPBaselineCacheRows -TenantFilter $TenantFilter -Type 'Groups') - if ($Groups.Count -eq 0 -and -not (Test-CIPPBaselineCacheCollected -TenantFilter $TenantFilter -Type 'Groups')) { - return @{ Current = $null } - } - $Existing = $Groups | Where-Object { "$($_.displayName)" -eq $GroupName } | Select-Object -First 1 + # Dynamic Distribution Groups are not supported by CIPP: do not grade them (a graded DDL reads as + # permanent drift and its executor write throws). Return not-applicable, consistent with the executor skip. + return @{ Current = $null } } + $Groups = @(Get-CIPPBaselineCacheRows -TenantFilter $TenantFilter -Type 'Groups') + if ($Groups.Count -eq 0 -and -not (Test-CIPPBaselineCacheCollected -TenantFilter $TenantFilter -Type 'Groups')) { + return @{ Current = $null } + } + $Existing = $Groups | Where-Object { "$($_.displayName)" -eq $GroupName } | Select-Object -First 1 + $Current = [PSCustomObject]@{ deployed = [bool]$Existing } # Carried for the executor, not graded. $Current | Add-Member -NotePropertyName 'templateBody' -NotePropertyValue $Template diff --git a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineGroupTemplate.ps1 b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineGroupTemplate.ps1 index f415b4d5307e1..8f1e8e4f8bccc 100644 --- a/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineGroupTemplate.ps1 +++ b/Modules/CIPPCore/Public/Baselines/Invoke-CIPPBaselineGroupTemplate.ps1 @@ -44,6 +44,14 @@ function Invoke-CIPPBaselineGroupTemplate { default { "$($Template.groupType)" } } + if ($NormalizedGroupType -eq 'DynamicDistribution') { + # Dynamic Distribution Groups are no longer supported by CIPP: EXO canonicalises the recipient + # filter (permanent drift) and Set-DynamicDistributionGroup -RecipientFilter throws. Skip the write + # and surface the skip in the run log instead of failing every remediation. + Write-LogMessage -API 'Baselines' -tenant $TenantFilter -message "Group Template '$($Template.displayName)': skipped - Dynamic Distribution Groups are not supported by CIPP." -Sev 'Warn' + return + } + if (-not $Existing) { if ($NormalizedGroupType -in @('Distribution', 'DynamicDistribution')) { $LicenseCheck = Test-CIPPStandardLicense -StandardName 'GroupTemplate' -TenantFilter $TenantFilter -Preset Exchange -SkipLog diff --git a/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-InstanceHealthSample.ps1 b/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-InstanceHealthSample.ps1 index faa86b4f47da5..5f9a6d83f5d5b 100644 --- a/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-InstanceHealthSample.ps1 +++ b/Modules/CIPPCore/Public/Entrypoints/Timer Functions/Start-InstanceHealthSample.ps1 @@ -46,15 +46,6 @@ function Start-InstanceHealthSample { $Table = Get-CIPPTable -TableName 'InstanceHealth' - # Egress ledger is instance-wide, Craft-owned, and only exists when accounting is on - - # a missing bridge or ledger means "no egress data", never a fake zero. - $Ledger = $null - try { - $Ledger = Get-CIPPEgressLedger -LogDirectory ([Craft.Services.LogBridge]::GetLogDirectory()) -Now $Now - } catch { - Write-Information "[InstanceHealth] Log bridge unavailable for egress ledger: $($_.Exception.Message)" - } - # One fixed partition for the whole table so a window read is a single partition-scoped # RowKey range instead of a cross-partition scan; the bucket lives in RowKey and Bucket. $Entity = @{ @@ -75,32 +66,6 @@ function Start-InstanceHealthSample { if ($null -ne $Sample.HeapMb) { $Entity.HeapMb = [int]$Sample.HeapMb } if ($null -ne $HeapMbLive) { $Entity.HeapMbLive = [int]$HeapMbLive } if ($null -ne $GcHeapLimitMb) { $Entity.GcHeapLimitMb = [int]$GcHeapLimitMb } - if ($Sample.EgressRejectCount -gt 0) { $Entity.EgressRejectCount = [int]$Sample.EgressRejectCount } - if (@($Sample.EgressRejectClients).Count -gt 0) { $Entity.EgressRejectClients = [string]($Sample.EgressRejectClients | ConvertTo-Json -Compress) } - - if ($Ledger) { - $Entity.EgressBytesToday = [long]$Ledger.Bytes - - $Today = $Now.ToString('yyyy-MM-dd') - $PreviousSamples = @(Get-CIPPAzDataTableEntity @Table -Filter "PartitionKey eq 'InstanceHealth' and RowKey ge '${Today}T00:00' and Kind eq 'sample'") - $PreviousWithEgress = $PreviousSamples | Where-Object { $null -ne $_.EgressBytesToday } | Sort-Object -Property Bucket -Descending | Select-Object -First 1 - - if ($PreviousWithEgress) { - $Delta = [long]$Ledger.Bytes - [long]$PreviousWithEgress.EgressBytesToday - if ($Delta -lt 0) { $Delta = 0 } - $Entity.EgressBytes = $Delta - } else { - # No earlier reading today: the ledger total is everything since the day (or accounting) began. - $Entity.EgressBytes = [long]$Ledger.Bytes - } - } - - if ($env:CRAFT_API_EGRESS_LIMIT_BYTES) { - $CapBytes = 0 - if ([long]::TryParse($env:CRAFT_API_EGRESS_LIMIT_BYTES, [ref]$CapBytes) -and $CapBytes -gt 0) { - $Entity.EgressCapBytes = $CapBytes - } - } Add-CIPPAzDataTableEntity @Table -Entity $Entity -Force | Out-Null diff --git a/Modules/CIPPCore/Public/Functions/Get-CIPPEgressAccounting.ps1 b/Modules/CIPPCore/Public/Functions/Get-CIPPEgressAccounting.ps1 new file mode 100644 index 0000000000000..079965f243e32 --- /dev/null +++ b/Modules/CIPPCore/Public/Functions/Get-CIPPEgressAccounting.ps1 @@ -0,0 +1,125 @@ +function Get-CIPPEgressAccounting { + <# + .SYNOPSIS + Reads Craft's per-API-client egress accounting table. + .DESCRIPTION + Craft writes 15 minute bucket rows and daily rollups, partitioned per API client plus an + 'instance-total' partition. Requests are counted at the wire, so they include responses + Craft served from its cache, and only API-client traffic is counted - never the UI. + + The table only exists when egress accounting is enabled, so a missing table or an empty + result is "no data" ($null), never an error. Never throws. + .FUNCTIONALITY + Internal + .EXAMPLE + Get-CIPPEgressAccounting -Hours 24 + #> + [CmdletBinding()] + param( + [int]$Hours = 24, + [DateTime]$Now = [DateTime]::UtcNow + ) + + try { + $TableName = if ($env:CRAFT_API_EGRESS_TABLE) { $env:CRAFT_API_EGRESS_TABLE } else { 'CraftEgressAccounting' } + $Table = Get-CIPPTable -TableName $TableName + + $WindowStart = $Now.AddHours(-$Hours) + $WindowStart = $WindowStart.AddMinutes(-($WindowStart.Minute % 15)).AddSeconds(-$WindowStart.Second).AddMilliseconds(-$WindowStart.Millisecond) + $StartKey = 'bkt_{0}' -f $WindowStart.ToString('yyyyMMdd\THHmmss\Z') + + # 'bku_' sorts immediately after every 'bkt_' row, so the window stays a RowKey range scan + # across the handful of client partitions. + $BucketRows = @(Get-CIPPAzDataTableEntity @Table -Filter "RowKey ge '$StartKey' and RowKey lt 'bku_'") + $DayRows = @(Get-CIPPAzDataTableEntity @Table -Filter "RowKey eq 'day_$($Now.ToString('yyyyMMdd'))'") + + if ($BucketRows.Count -eq 0 -and $DayRows.Count -eq 0) { return $null } + + # One lookup for every AppId in the table - the accounting rows only carry the GUID. + $AppNames = @{} + try { + foreach ($Client in @(Get-CippApiClient)) { + $ClientId = if ($Client.ClientId) { [string]$Client.ClientId } else { [string]$Client.RowKey } + if ($ClientId -and $Client.AppName) { $AppNames[$ClientId] = [string]$Client.AppName } + } + } catch { + Write-Information "[InstanceHealth] Could not resolve API client names: $($_.Exception.Message)" + } + + $InstanceDay = $DayRows | Where-Object { $_.PartitionKey -eq 'instance-total' } | Select-Object -First 1 + + $Clients = [System.Collections.Generic.List[hashtable]]::new() + foreach ($Row in ($DayRows | Where-Object { $_.PartitionKey -ne 'instance-total' } | Sort-Object -Property { [long]$_.Bytes } -Descending)) { + $AppId = [string]$Row.PartitionKey + $Clients.Add(@{ + AppId = $AppId + AppName = if ($AppNames[$AppId]) { $AppNames[$AppId] } else { $AppId } + Bytes = [long]$Row.Bytes + Requests = [long]$Row.Requests + Shed = [long]$Row.Shed + }) + } + + $ByBucket = [ordered]@{} + foreach ($Row in ($BucketRows | Sort-Object -Property RowKey)) { + $Key = [string]$Row.RowKey + if (-not $ByBucket.Contains($Key)) { $ByBucket[$Key] = [System.Collections.Generic.List[object]]::new() } + $ByBucket[$Key].Add($Row) + } + + $Buckets = [System.Collections.Generic.List[hashtable]]::new() + foreach ($Key in $ByBucket.Keys) { + $Rows = $ByBucket[$Key] + $Total = $Rows | Where-Object { $_.PartitionKey -eq 'instance-total' } | Select-Object -First 1 + + $BucketClients = [System.Collections.Generic.List[hashtable]]::new() + $SumBytes = [long]0 + $SumRequests = [long]0 + $SumShed = [long]0 + foreach ($Row in ($Rows | Where-Object { $_.PartitionKey -ne 'instance-total' })) { + $AppId = [string]$Row.PartitionKey + $SumBytes += [long]$Row.Bytes + $SumRequests += [long]$Row.Requests + $SumShed += [long]$Row.Shed + $BucketClients.Add(@{ + AppId = $AppId + AppName = if ($AppNames[$AppId]) { $AppNames[$AppId] } else { $AppId } + Bytes = [long]$Row.Bytes + Requests = [long]$Row.Requests + Shed = [long]$Row.Shed + }) + } + + $Reference = if ($Total) { $Total } else { $Rows[0] } + $BucketStart = if ($Reference.BucketStartUtc) { + ([DateTimeOffset]$Reference.BucketStartUtc).UtcDateTime.ToString('yyyy-MM-dd\THH:mm:ss\Z') + } else { + # RowKey is the bucket start, so it stands in when the property is absent. + $Key -replace '^bkt_', '' + } + + $Buckets.Add(@{ + BucketStart = $BucketStart + Bytes = if ($Total) { [long]$Total.Bytes } else { $SumBytes } + Requests = if ($Total) { [long]$Total.Requests } else { $SumRequests } + Shed = if ($Total) { [long]$Total.Shed } else { $SumShed } + Clients = @($BucketClients) + }) + } + + return [pscustomobject]@{ + BucketMinutes = 15 + CapBytes = if ($InstanceDay) { [long]$InstanceDay.CapBytes } else { [long]0 } + Enforcing = if ($InstanceDay) { [bool]$InstanceDay.Enforcing } else { $false } + TodayBytes = if ($InstanceDay) { [long]$InstanceDay.Bytes } else { [long]0 } + TodayRequests = if ($InstanceDay) { [long]$InstanceDay.Requests } else { [long]0 } + TodayShed = if ($InstanceDay) { [long]$InstanceDay.Shed } else { [long]0 } + CapReachedUtc = if ($InstanceDay -and $InstanceDay.CapReachedUtc) { ([DateTimeOffset]$InstanceDay.CapReachedUtc).UtcDateTime.ToString('yyyy-MM-dd\THH:mm:ss\Z') } else { $null } + Buckets = @($Buckets) + Clients = @($Clients) + } + } catch { + Write-Information "[InstanceHealth] Egress accounting unavailable: $($_.Exception.Message)" + return $null + } +} diff --git a/Modules/CIPPCore/Public/Functions/Get-CIPPEgressLedger.ps1 b/Modules/CIPPCore/Public/Functions/Get-CIPPEgressLedger.ps1 deleted file mode 100644 index 4abf5a963faa4..0000000000000 --- a/Modules/CIPPCore/Public/Functions/Get-CIPPEgressLedger.ps1 +++ /dev/null @@ -1,44 +0,0 @@ -function Get-CIPPEgressLedger { - <# - .SYNOPSIS - Reads today's API egress ledger written by Craft. - .DESCRIPTION - Craft flushes egress-ledger.json ({"DateUtc":"yyyy-MM-dd","Bytes":}) to its log - directory every 60s, only when egress accounting is enabled and at least one API-client - response has been served today. A missing file, a different UTC day, or unparsable JSON - all mean "no data for today" rather than an error, so this never throws. - .FUNCTIONALITY - Internal - .EXAMPLE - Get-CIPPEgressLedger -LogDirectory ([Craft.Services.LogBridge]::GetLogDirectory()) - #> - [CmdletBinding()] - param( - [Parameter(Mandatory = $true)] - [string]$LogDirectory, - - [DateTime]$Now = [DateTime]::UtcNow - ) - - $Path = Join-Path -Path $LogDirectory -ChildPath 'egress-ledger.json' - if (-not (Test-Path -Path $Path -PathType Leaf)) { return $null } - - try { - $Ledger = Get-Content -Path $Path -Raw -ErrorAction Stop | ConvertFrom-Json -ErrorAction Stop - } catch { - return $null - } - - if (-not $Ledger.DateUtc -or $Ledger.DateUtc -ne $Now.ToString('yyyy-MM-dd')) { return $null } - - try { - $Bytes = [long]$Ledger.Bytes - } catch { - return $null - } - - return [pscustomobject]@{ - DateUtc = [string]$Ledger.DateUtc - Bytes = $Bytes - } -} diff --git a/Modules/CIPPCore/Public/Functions/Get-CIPPInstanceHealthSample.ps1 b/Modules/CIPPCore/Public/Functions/Get-CIPPInstanceHealthSample.ps1 index b950ba0d4446b..c70b0652f4baa 100644 --- a/Modules/CIPPCore/Public/Functions/Get-CIPPInstanceHealthSample.ps1 +++ b/Modules/CIPPCore/Public/Functions/Get-CIPPInstanceHealthSample.ps1 @@ -30,10 +30,6 @@ function Get-CIPPInstanceHealthSample { $StalledRunCount = 0 $MaxLimiterWaitMs = 0 $HeapMb = $null - $EgressRejectCount = 0 - # Ordered HashSet-backed dedup - same client can be rejected many times per window. - $EgressRejectClients = [System.Collections.Generic.List[string]]::new() - $EgressRejectClientsSeen = [System.Collections.Generic.HashSet[string]]::new() $Endpoints = @{} # Keyed on AppId - the same client can appear under several IPs, the last one wins. @@ -48,13 +44,6 @@ function Get-CIPPInstanceHealthSample { if ($Line -match '\[ERR\]') { $ErrCount++ } if ($Line -match 'T\+([0-9]{2,})\.[0-9]+min: .* 0 running ([1-9][0-9]*) pending') { $StalledRunCount++ } - if ($Line -match 'Egress cap reached') { - $EgressRejectCount++ - if ($Line -match '429 for (\S+) on' -and $EgressRejectClientsSeen.Add($Matches[1])) { - $EgressRejectClients.Add($Matches[1]) - } - } - if ($Line -match 'Limiter slot acquired after (\d+)ms') { $Wait = [int]$Matches[1] if ($Wait -gt $MaxLimiterWaitMs) { $MaxLimiterWaitMs = $Wait } @@ -113,7 +102,5 @@ function Get-CIPPInstanceHealthSample { StalledRunCount = $StalledRunCount TopEndpointsMs = $TopEndpoints Clients = $ClientList - EgressRejectCount = $EgressRejectCount - EgressRejectClients = $EgressRejectClients } } diff --git a/Modules/CIPPCore/Public/MCP/Get-CippMcpScopeAppSettings.ps1 b/Modules/CIPPCore/Public/MCP/Get-CippMcpScopeAppSettings.ps1 new file mode 100644 index 0000000000000..6f0ea5e5db790 --- /dev/null +++ b/Modules/CIPPCore/Public/MCP/Get-CippMcpScopeAppSettings.ps1 @@ -0,0 +1,71 @@ +function Get-CippMcpScopeAppSettings { + <# + .SYNOPSIS + Builds the App Service settings that advertise the MCP OAuth scopes - the EasyAuth + challenge header plus the protected-resource / authorization-server discovery documents - + so a client requests offline_access and Entra issues a refresh token. + .DESCRIPTION + Single source of truth for WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES and, on CIPPNG/Craft, the + CRAFT_PRM and CRAFT_PRM_AS documents. Both Invoke-ExecApiClient (Save to Azure) and the + Initialize-CIPPAuth warmup reconcile write these; defining the values here means the two + callers cannot drift apart and fight each other with a restart on every warmup. + + offline_access is the load-bearing scope. Without it in the advertised scope set, strict + discovery clients - e.g. GitHub Copilot CLI, which reads the scope only from the challenge + header and never falls back to the discovery docs - never request it, so Entra never issues + a refresh token and the client re-authenticates roughly every hour. (Copilot Studio uses + Manual OAuth and ignores all of this; its refresh depends on app-registration consent.) + .PARAMETER Hostname + The App Service hostname (WEBSITE_HOSTNAME) - the *.azurewebsites.net host that matches the + MCP client app registration's identifier URIs, not the vanity domain. + .PARAMETER TenantId + Partner tenant ID, used to build the tenanted authorization-server endpoints. + .PARAMETER IsCippNg + When set, also emits the CRAFT_PRM / CRAFT_PRM_AS discovery documents (CIPPNG/Craft only). + .FUNCTIONALITY + Internal + #> + [CmdletBinding()] + param( + [Parameter(Mandatory)] + [string]$Hostname, + + [Parameter()] + [string]$TenantId, + + [Parameter()] + [switch]$IsCippNg + ) + + $McpScope = "https://$Hostname/user_impersonation" + $McpScopesSupported = @('openid', 'profile', 'offline_access', $McpScope) + + $Settings = @{ + 'WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES' = 'openid profile offline_access {0}' -f $McpScope + } + + if ($IsCippNg) { + $TenantedLogin = "https://login.microsoftonline.com/$TenantId" + $Settings['CRAFT_PRM'] = [ordered]@{ + resource = '{origin}/api/ExecMcp' + authorization_servers = @('{origin}') + scopes_supported = $McpScopesSupported + bearer_methods_supported = @('header') + } | ConvertTo-Json -Compress + $Settings['CRAFT_PRM_AS'] = [ordered]@{ + issuer = '{origin}' + authorization_endpoint = "$TenantedLogin/oauth2/v2.0/authorize" + token_endpoint = "$TenantedLogin/oauth2/v2.0/token" + jwks_uri = "$TenantedLogin/discovery/v2.0/keys" + registration_endpoint = '{origin}/api/PublicMcpRegister' + response_types_supported = @('code') + response_modes_supported = @('query', 'form_post') + grant_types_supported = @('authorization_code', 'refresh_token') + code_challenge_methods_supported = @('S256') + token_endpoint_auth_methods_supported = @('none', 'client_secret_post', 'client_secret_basic') + scopes_supported = $McpScopesSupported + } | ConvertTo-Json -Compress + } + + return $Settings +} diff --git a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDevices.ps1 b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDevices.ps1 index 62e7fbe041ad3..24242b0bbbc64 100644 --- a/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDevices.ps1 +++ b/Modules/CIPPDB/Public/DBCache/Set-CIPPDBCacheDevices.ps1 @@ -19,7 +19,7 @@ function Set-CIPPDBCacheDevices { try { Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Caching Azure AD devices' -sev Debug - New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/devices?$top=999&$select=id,displayName,operatingSystem,operatingSystemVersion,trustType,accountEnabled,approximateLastSignInDateTime,onPremisesSyncEnabled,isManaged,isCompliant,physicalIds,enrollmentProfileName,managementType,profileType' -tenantid $TenantFilter -Stream | + New-GraphGetRequest -uri 'https://graph.microsoft.com/beta/devices?$top=999&$select=id,deviceId,displayName,operatingSystem,operatingSystemVersion,trustType,accountEnabled,approximateLastSignInDateTime,onPremisesSyncEnabled,isManaged,isCompliant,physicalIds,enrollmentProfileName,managementType,profileType' -tenantid $TenantFilter -Stream | Add-CIPPDbItem -TenantFilter $TenantFilter -Type 'Devices' -AddCount Write-LogMessage -API 'CIPPDBCache' -tenant $TenantFilter -message 'Cached Azure AD devices successfully' -sev Debug diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecApiClient.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecApiClient.ps1 index 4a346e1389765..006a0ac161f94 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecApiClient.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ExecApiClient.ps1 @@ -221,40 +221,20 @@ function Invoke-ExecApiClient { Set-CippApiAuth -RGName $RGName -FunctionAppName $FunctionAppName -TenantId $TenantId -ClientIds $ClientIds -McpClientIds $McpClientIds if ($McpClientIds.Count -gt 0 -and $env:WEBSITE_HOSTNAME) { - # Advertise the OIDC scopes alongside the resource scope so discovery-based MCP - # clients (Copilot Studio, ChatGPT) request a refresh token. offline_access is - # what makes Entra issue one; without it the client re-consents every ~hour. - # Claude appends offline_access itself, but stricter clients only request what the - # metadata advertises, so it has to be in the protected-resource document and the - # EasyAuth challenge scope too - not just the authorization-server document. - $McpScope = "https://$($env:WEBSITE_HOSTNAME)/user_impersonation" - $McpScopesSupported = @('openid', 'profile', 'offline_access', $McpScope) - $McpDefaultScopeString = 'openid profile offline_access {0}' -f $McpScope - if ($env:CIPPNG) { - $TenantedLogin = "https://login.microsoftonline.com/$($env:TenantID)" - $PrmDocument = [ordered]@{ - resource = '{origin}/api/ExecMcp' - authorization_servers = @('{origin}') - scopes_supported = $McpScopesSupported - bearer_methods_supported = @('header') - } | ConvertTo-Json -Compress - $AsDocument = [ordered]@{ - issuer = '{origin}' - authorization_endpoint = "$TenantedLogin/oauth2/v2.0/authorize" - token_endpoint = "$TenantedLogin/oauth2/v2.0/token" - jwks_uri = "$TenantedLogin/discovery/v2.0/keys" - registration_endpoint = '{origin}/api/PublicMcpRegister' - response_types_supported = @('code') - response_modes_supported = @('query', 'form_post') - grant_types_supported = @('authorization_code', 'refresh_token') - code_challenge_methods_supported = @('S256') - token_endpoint_auth_methods_supported = @('none', 'client_secret_post', 'client_secret_basic') - scopes_supported = $McpScopesSupported - } | ConvertTo-Json -Compress - $null = Update-CIPPAzFunctionAppSetting -Name $FunctionAppName -ResourceGroupName $RGName -AppSetting @{ 'CRAFT_PRM' = "$PrmDocument"; 'CRAFT_PRM_AS' = "$AsDocument"; 'WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES' = $McpDefaultScopeString } - } else { - $null = Update-CIPPAzFunctionAppSetting -Name $FunctionAppName -ResourceGroupName $RGName -AppSetting @{ 'WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES' = $McpDefaultScopeString } - } + # Advertise the OIDC + offline_access scopes alongside the resource scope so + # discovery-based MCP clients (ChatGPT, VS Code, Copilot CLI) request a refresh + # token. offline_access is what makes Entra issue one; without it the client + # re-consents every ~hour. Claude appends offline_access itself, but stricter + # clients only request what the metadata advertises, so it has to be in the + # challenge header and the discovery docs, not just one of them. The values come + # from Get-CippMcpScopeAppSettings so the Initialize-CIPPAuth warmup reconcile + # writes byte-identical settings and the two paths never fight each other. + # NOTE: Copilot Studio does NOT read any of this. Entra has no RFC 7591 DCR, so + # Copilot Studio uses Manual OAuth with a maker-typed scope; its refresh token + # depends on offline_access being consented on the MCP client app registration + # (Set-CIPPMCPClientApp / Grant-CippAppGraphConsent), not on these documents. + $McpAppSettings = Get-CippMcpScopeAppSettings -Hostname $env:WEBSITE_HOSTNAME -TenantId $env:TenantID -IsCippNg:([bool]$env:CIPPNG) + $null = Update-CIPPAzFunctionAppSetting -Name $FunctionAppName -ResourceGroupName $RGName -AppSetting $McpAppSettings } else { $null = Update-CIPPAzFunctionAppSetting -Name $FunctionAppName -ResourceGroupName $RGName -AppSetting @{} -RemoveKeys @('WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES', 'CRAFT_PRM', 'CRAFT_PRM_AS') } diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListApiEgress.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListApiEgress.ps1 new file mode 100644 index 0000000000000..0b012a91fad20 --- /dev/null +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListApiEgress.ps1 @@ -0,0 +1,135 @@ +function Invoke-ListApiEgress { + <# + .FUNCTIONALITY + Entrypoint,AnyTenant + .ROLE + CIPP.SuperAdmin.Read + .DESCRIPTION + Per-API-client egress usage for this instance against the daily cap. Reads the + CraftEgressAccounting table that the Craft runtime mirrors its egress accounting into (the same + storage account, so this reads it directly): a per-day audit row per client plus an instance + total, and 15-minute buckets for the trend. Returns today's instance summary (used-of-cap, + enforcing, when the cap was first hit, how many requests were shed), the per-client breakdown, + and the last-24h instance trend. When the table has no data for today - accounting off, a + non-hosted instance, or simply no app-only traffic yet - Enabled is false and the UI hides the + card. SuperAdmin only. + #> + [CmdletBinding()] + param($Request, $TriggerMetadata) + + $APIName = $Request.Params.CIPPEndpoint + $Now = [DateTime]::UtcNow + $Today = $Now.ToString('yyyyMMdd') + $DailyKey = "day_$Today" + + # Trend window in hours (default 24). Clamped to the table's 7-day retention. + $Hours = 24 + if ($Request.Query.Hours) { $Hours = [int]$Request.Query.Hours } + if ($Hours -lt 1) { $Hours = 1 } + if ($Hours -gt 168) { $Hours = 168 } + + # 15-minute buckets over the window; the bkt_ prefix range excludes the day_ rows. + $SinceBucket = 'bkt_{0}' -f $Now.AddHours(-$Hours).ToString('yyyyMMddTHHmmssZ') + $SystemPartition = 'instance-total' + + try { + $Table = Get-CIPPTable -TableName 'CraftEgressAccounting' + + # Today's daily audit rows (per client + the instance total) - a small cross-partition read. + $DailyRows = @(Get-CIPPAzDataTableEntity @Table -Filter "RowKey eq '$DailyKey'") + $Instance = $DailyRows | Where-Object { $_.PartitionKey -eq $SystemPartition } | Select-Object -First 1 + + if (-not $Instance) { + # No accounting data for today: not enabled here (or nothing served yet). + $Body = @{ + Results = @{ + Enabled = $false + Hosted = ($env:CIPP_HOSTED -eq 'true') + DateUtc = $Now.ToString('yyyy-MM-dd') + } + } + return [HttpResponseContext]@{ StatusCode = [HttpStatusCode]::OK; Body = $Body } + } + + $CapBytes = [long]($Instance.CapBytes ?? 0) + $BytesToday = [long]($Instance.Bytes ?? 0) + $PctOfCap = if ($CapBytes -gt 0) { [math]::Round(($BytesToday / $CapBytes) * 100, 1) } else { $null } + + # Friendly names from the API client registry (fall back to the AppId when unregistered). + $NameByAppId = @{} + try { + $ClientTable = Get-CIPPTable -TableName 'ApiClients' + foreach ($ClientRow in @(Get-CIPPAzDataTableEntity @ClientTable)) { + if (-not [string]::IsNullOrEmpty($ClientRow.RowKey)) { + $NameByAppId[[string]$ClientRow.RowKey] = [string]$ClientRow.AppName + } + } + } catch { + # Registry read is best-effort; the chart falls back to AppIds. + Write-Information "ListApiEgress: ApiClients name lookup failed, using AppIds ($($_.Exception.Message))" + } + + $Clients = @( + $DailyRows | Where-Object { $_.PartitionKey -ne $SystemPartition } | ForEach-Object { + $AppId = [string]$_.PartitionKey + [PSCustomObject]@{ + AppId = $AppId + Name = if ($NameByAppId[$AppId]) { $NameByAppId[$AppId] } else { $AppId } + Bytes = [long]($_.Bytes ?? 0) + Requests = [long]($_.Requests ?? 0) + Shed = [long]($_.Shed ?? 0) + } + } | Sort-Object -Property Bytes -Descending + ) + + # Per-client 15-minute buckets over the last 24h, shaped for a stacked chart: one row per + # bucket with a byte column per client (0 when that client had no traffic that bucket). + $BucketRows = @(Get-CIPPAzDataTableEntity @Table -Filter "RowKey ge '$SinceBucket' and RowKey lt 'bku_'") + $ClientBuckets = @($BucketRows | Where-Object { $_.PartitionKey -ne $SystemPartition }) + # Series = clients seen today or anywhere in the 24h window, biggest-first for a stable stack. + $ClientIds = @(@($Clients.AppId) + @($ClientBuckets.PartitionKey) | Select-Object -Unique) + $ClientNames = @{} + foreach ($AppId in $ClientIds) { $ClientNames[$AppId] = if ($NameByAppId[$AppId]) { $NameByAppId[$AppId] } else { $AppId } } + + $Trend = @( + $ClientBuckets | Group-Object -Property RowKey | Sort-Object -Property Name | ForEach-Object { + $Row = [ordered]@{ BucketStartUtc = $_.Group[0].BucketStartUtc } + foreach ($AppId in $ClientIds) { + $Bucket = $_.Group | Where-Object { $_.PartitionKey -eq $AppId } | Select-Object -First 1 + $Row[$AppId] = if ($Bucket) { [long]($Bucket.Bytes ?? 0) } else { 0 } + } + [PSCustomObject]$Row + } + ) + + $Body = @{ + Results = @{ + Enabled = $true + Hosted = ($env:CIPP_HOSTED -eq 'true') + DateUtc = [string]($Instance.DateUtc ?? $Now.ToString('yyyy-MM-dd')) + CapBytes = $CapBytes + Enforcing = [bool]($Instance.Enforcing ?? ($CapBytes -gt 0)) + BytesToday = $BytesToday + PctOfCap = $PctOfCap + CapReachedUtc = $Instance.CapReachedUtc + ShedRequests = [long]($Instance.Shed ?? 0) + Clients = $Clients + ClientIds = $ClientIds + ClientNames = $ClientNames + Trend = $Trend + } + } + + return [HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::OK + Body = $Body + } + } catch { + $ErrorMessage = Get-CippException -Exception $_ + Write-LogMessage -API $APIName -message "API egress list error: $($ErrorMessage.NormalizedError)" -sev Error -LogData $ErrorMessage + return [HttpResponseContext]@{ + StatusCode = [HttpStatusCode]::InternalServerError + Body = @{ Results = "Failed: $($ErrorMessage.NormalizedError)" } + } + } +} diff --git a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListInstanceDiagnostics.ps1 b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListInstanceDiagnostics.ps1 index 4feef89816f89..1d61de574b127 100644 --- a/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListInstanceDiagnostics.ps1 +++ b/Modules/CIPPHTTP/Public/Entrypoints/HTTP Functions/CIPP/Settings/Invoke-ListInstanceDiagnostics.ps1 @@ -76,6 +76,10 @@ function Invoke-ListInstanceDiagnostics { if ($Row.IP) { $ClientTotals[$AppId].IP = [string]$Row.IP } } + # Craft owns this table and only writes it when egress accounting is on, so $null here + # means "no egress data" for both actions. + $Egress = Get-CIPPEgressAccounting -Hours $Hours -Now $Now + switch ($Action) { 'Checks' { $Results = [System.Collections.Generic.List[hashtable]]::new() @@ -135,44 +139,41 @@ function Invoke-ListInstanceDiagnostics { Fix = if ($StalledTotal -gt 0) { 'Runs have pending work but nothing running - cancel the stuck run from Worker Health and let it re-queue.' } else { $null } }) - $EgressSamples = @($Samples | Where-Object { $null -ne $_.EgressBytesToday }) - if ($EgressSamples.Count -eq 0) { - $Results.Add(@{ Check = 'egress'; Status = 'INFO'; Detail = 'No API egress recorded in this window - egress accounting is off or no API client traffic was served'; Fix = $null }) + # Craft stamps the daily instance-total row on the first API response it serves, + # so no row means no API-client traffic today rather than a zero reading. + $EgressHasDay = $Egress -and ($Egress.TodayBytes -gt 0 -or $Egress.TodayRequests -gt 0 -or $Egress.CapBytes -gt 0) + if (-not $EgressHasDay) { + $Results.Add(@{ Check = 'egress'; Status = 'INFO'; Detail = 'No API egress recorded today - egress accounting is off or no API client traffic was served'; Fix = $null }) } else { - $NewestEgress = $EgressSamples | Sort-Object -Property Bucket | Select-Object -Last 1 - $TodayBytes = [long]$NewestEgress.EgressBytesToday - $CapSample = @($Samples | Where-Object { [long]$_.EgressCapBytes -gt 0 }) | Select-Object -Last 1 - $CapBytes = if ($CapSample) { [long]$CapSample.EgressCapBytes } else { $null } - $EgressRejectTotal = ($Samples | Measure-Object -Property EgressRejectCount -Sum).Sum ?? 0 - - if ($EgressRejectTotal -gt 0) { - # Distinct client names across the window's reject lists, in first-seen order. - $RejectClients = [System.Collections.Generic.List[string]]::new() - $Seen = [System.Collections.Generic.HashSet[string]]::new() - foreach ($RejectSample in ($Samples | Where-Object { $_.EgressRejectClients })) { - try { - foreach ($ClientName in @($RejectSample.EgressRejectClients | ConvertFrom-Json)) { - if ($Seen.Add($ClientName)) { $RejectClients.Add($ClientName) } - } - } catch {} - } - $CapDisplay = if ($CapBytes) { Format-DiagnosticsBytes -Bytes $CapBytes } else { 'unknown' } + $TodayDisplay = Format-DiagnosticsBytes -Bytes $Egress.TodayBytes + $CapDisplay = if ($Egress.CapBytes -gt 0) { Format-DiagnosticsBytes -Bytes $Egress.CapBytes } else { 'unknown' } + $Percent = if ($Egress.CapBytes -gt 0) { [math]::Round(($Egress.TodayBytes / $Egress.CapBytes) * 100, 1) } else { $null } + + $Busiest = [System.Collections.Generic.List[string]]::new() + foreach ($Client in (@($Egress.Clients) | Select-Object -First 2)) { + $Busiest.Add("$($Client.AppName) ($(Format-DiagnosticsBytes -Bytes $Client.Bytes))") + } + $TopClientText = if ($Busiest.Count -gt 0) { $Busiest[0] } else { 'no API clients' } + + if ($Egress.TodayShed -gt 0 -or $Egress.CapReachedUtc) { + $BusiestText = if ($Busiest.Count -gt 0) { $Busiest -join ', ' } else { 'no API clients' } $Results.Add(@{ Check = 'egress' Status = 'FAIL' - Detail = "API egress cap reached: $EgressRejectTotal request(s) rejected with 429, clients: $($RejectClients -join ', '); served $(Format-DiagnosticsBytes -Bytes $TodayBytes) of $CapDisplay" - Fix = 'Identify which integration is pulling the most data and throttle it, or raise the daily egress budget.' + Detail = "API egress cap reached at $($Egress.CapReachedUtc): $($Egress.TodayShed) request(s) refused with 429; served $TodayDisplay of $CapDisplay; busiest: $BusiestText" + Fix = 'Throttle the named integration or raise the daily egress budget.' }) - } elseif ($CapBytes) { - $Percent = [math]::Round(($TodayBytes / $CapBytes) * 100, 1) - $EgressDetail = "Served $(Format-DiagnosticsBytes -Bytes $TodayBytes) of $(Format-DiagnosticsBytes -Bytes $CapBytes) today ($Percent%)" - if ($Percent -ge 75) { - $Results.Add(@{ Check = 'egress'; Status = 'WARN'; Detail = $EgressDetail; Fix = $null }) - } else { - $Results.Add(@{ Check = 'egress'; Status = 'PASS'; Detail = $EgressDetail; Fix = $null }) - } + } elseif ($Egress.Enforcing -and $null -ne $Percent -and $Percent -ge 75) { + $Results.Add(@{ + Check = 'egress' + Status = 'WARN' + Detail = "$TodayDisplay of $CapDisplay daily API egress budget ($Percent%) - on course to hit the cap; busiest: $TopClientText" + Fix = 'Throttle the named integration or raise the daily egress budget.' + }) + } elseif ($Egress.Enforcing) { + $Results.Add(@{ Check = 'egress'; Status = 'PASS'; Detail = "$TodayDisplay of $CapDisplay ($Percent%)"; Fix = $null }) } else { - $Results.Add(@{ Check = 'egress'; Status = 'INFO'; Detail = "Served $(Format-DiagnosticsBytes -Bytes $TodayBytes) today (no daily budget set)"; Fix = $null }) + $Results.Add(@{ Check = 'egress'; Status = 'INFO'; Detail = "$TodayDisplay served to API clients today (no daily budget set); busiest: $TopClientText"; Fix = $null }) } } @@ -306,8 +307,6 @@ function Invoke-ListInstanceDiagnostics { StalledRunCount = [int]$Sample.StalledRunCount HeapMb = if ($null -ne $Sample.HeapMb) { [int]$Sample.HeapMb } else { $null } HeapMbLive = if ($null -ne $Sample.HeapMbLive) { [int]$Sample.HeapMbLive } else { $null } - EgressBytes = if ($null -ne $Sample.EgressBytes) { [long]$Sample.EgressBytes } else { $null } - EgressBytesToday = if ($null -ne $Sample.EgressBytesToday) { [long]$Sample.EgressBytesToday } else { $null } TopEndpointsMs = $TopEndpoints Clients = @($BucketClients) }) @@ -357,16 +356,19 @@ function Invoke-ListInstanceDiagnostics { }) } - $EgressCapSample = @($Samples | Where-Object { [long]$_.EgressCapBytes -gt 0 }) | Select-Object -Last 1 - $EgressAvailable = @($Samples | Where-Object { $null -ne $_.EgressBytesToday }).Count -gt 0 + if ($Egress) { + $Egress | Add-Member -NotePropertyName 'Available' -NotePropertyValue $true -Force + $EgressBody = $Egress + } else { + $EgressBody = @{ Available = $false } + } $Body = @{ Results = @{ - Buckets = @($Buckets) - Events = @($Events) - HeapCapMb = Get-DiagnosticsHeapCapMb -Samples $Samples - EgressCapBytes = if ($EgressCapSample) { [long]$EgressCapSample.EgressCapBytes } else { $null } - EgressAvailable = $EgressAvailable + Buckets = @($Buckets) + Events = @($Events) + HeapCapMb = Get-DiagnosticsHeapCapMb -Samples $Samples + Egress = $EgressBody } } } diff --git a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardGroupTemplate.ps1 b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardGroupTemplate.ps1 index 9d8be26df013d..447e249335013 100644 --- a/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardGroupTemplate.ps1 +++ b/Modules/CIPPStandards/Public/Standards/Invoke-CIPPStandardGroupTemplate.ps1 @@ -66,6 +66,17 @@ function Invoke-CIPPStandardGroupTemplate { $ResolvedIds = @(@($TemplateRows.RowKey) + @($GroupTemplates.GUID) | Where-Object { $_ } | Select-Object -Unique) $MissingIds = @($RequestedIds | Where-Object { $_ -notin $ResolvedIds }) + # Dynamic Distribution Groups are no longer supported by CIPP: EXO canonicalises RecipientFilter + # so it never matches the template's raw filter (permanent drift), and Set-DynamicDistributionGroup + # -RecipientFilter throws. Drop them from normal processing but keep the skip visible - a Warn in the + # logs and a matching note on both sides of the report (identical, so it shows without reading as drift). + $SkippedDynamicGroups = @($GroupTemplates | Where-Object { "$($_.groupType)" -eq 'dynamicDistribution' }) + $GroupTemplates = @($GroupTemplates | Where-Object { "$($_.groupType)" -ne 'dynamicDistribution' }) + if ($SkippedDynamicGroups.Count -gt 0) { + $SkippedNames = @($SkippedDynamicGroups.displayName) -join ', ' + Write-LogMessage -API 'Standards' -tenant $tenant -message "Group Template: skipped $($SkippedDynamicGroups.Count) Dynamic Distribution Group template(s) ($SkippedNames) - Dynamic Distribution Groups are not supported by CIPP." -sev 'Warn' + } + if ('dynamicDistribution' -in $GroupTemplates.groupType) { try { $DynamicDistros = New-ExoRequest -cmdlet 'Get-DynamicDistributionGroup' -tenantid $tenant -Select 'Identity,Name,Alias,RecipientFilter,PrimarySmtpAddress' -ErrorAction Stop @@ -288,6 +299,13 @@ function Invoke-CIPPStandardGroupTemplate { MissingTemplates = @() } + if ($SkippedDynamicGroups.Count -gt 0) { + # Identical on both sides: visible to the user as "skipped / not supported", never graded as drift. + $SkippedNote = "Dynamic Distribution Groups are not supported by CIPP and were skipped: $(@($SkippedDynamicGroups.displayName) -join ', ')" + $CurrentValue.SkippedDynamicDistributionGroups = $SkippedNote + $ExpectedValue.SkippedDynamicDistributionGroups = $SkippedNote + } + Set-CIPPStandardsCompareField -FieldName 'standards.GroupTemplate' -CurrentValue $CurrentValue -ExpectedValue $ExpectedValue -TenantFilter $Tenant } } diff --git a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_7.ps1 b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_7.ps1 index 0516d89bcff9f..f8f25397a4eac 100644 --- a/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_7.ps1 +++ b/Modules/CIPPTests/Public/Tests/CIS/Identity/Invoke-CippTestCIS_2_1_7.ps1 @@ -18,20 +18,27 @@ function Invoke-CippTestCIS_2_1_7 { return } + $AntiPhishRules = Get-CIPPTestData -TenantFilter $Tenant -Type 'ExoAntiPhishRules' + + # Get-AntiPhishPolicy only populates Enabled for the built-in default policy; a custom policy's + # active state lives on its anti-phish rule's State, joined by AntiPhishPolicy name (mirrors + # Invoke-CIPPStandardAntiPhishPolicy / Invoke-ListAntiPhishingFilters). $Compliant = $AntiPhish | Where-Object { - $_.Enabled -eq $true -and - $_.PhishThresholdLevel -ge 2 -and - $_.EnableMailboxIntelligenceProtection -eq $true -and - $_.EnableMailboxIntelligence -eq $true -and - $_.EnableSpoofIntelligence -eq $true -and - $_.TargetedUserProtectionAction -in @('Quarantine', 'MoveToJmf') -and - $_.MailboxIntelligenceProtectionAction -in @('Quarantine', 'MoveToJmf') -and - $_.TargetedDomainProtectionAction -in @('Quarantine', 'MoveToJmf') -and - $_.AuthenticationFailAction -in @('Quarantine', 'MoveToJmf') -and - $_.EnableFirstContactSafetyTips -eq $true -and - $_.EnableSimilarUsersSafetyTips -eq $true -and - $_.EnableSimilarDomainsSafetyTips -eq $true -and - $_.EnableUnusualCharactersSafetyTips -eq $true + $Policy = $_ + $RuleEnabled = [bool]($AntiPhishRules | Where-Object { $_.AntiPhishPolicy -eq $Policy.Name -and $_.State -eq 'Enabled' }) + ($Policy.Enabled -eq $true -or $RuleEnabled) -and + $Policy.PhishThresholdLevel -ge 2 -and + $Policy.EnableMailboxIntelligenceProtection -eq $true -and + $Policy.EnableMailboxIntelligence -eq $true -and + $Policy.EnableSpoofIntelligence -eq $true -and + $Policy.TargetedUserProtectionAction -in @('Quarantine', 'MoveToJmf') -and + $Policy.MailboxIntelligenceProtectionAction -in @('Quarantine', 'MoveToJmf') -and + $Policy.TargetedDomainProtectionAction -in @('Quarantine', 'MoveToJmf') -and + $Policy.AuthenticationFailAction -in @('Quarantine', 'MoveToJmf') -and + $Policy.EnableFirstContactSafetyTips -eq $true -and + $Policy.EnableSimilarUsersSafetyTips -eq $true -and + $Policy.EnableSimilarDomainsSafetyTips -eq $true -and + $Policy.EnableUnusualCharactersSafetyTips -eq $true } if ($Compliant) { diff --git a/Tests/Baselines/BaselineTemplateFamilies2.Tests.ps1 b/Tests/Baselines/BaselineTemplateFamilies2.Tests.ps1 index 7bc5aa9def8b8..f3ed06eee9670 100644 --- a/Tests/Baselines/BaselineTemplateFamilies2.Tests.ps1 +++ b/Tests/Baselines/BaselineTemplateFamilies2.Tests.ps1 @@ -142,16 +142,14 @@ Describe 'Get-CIPPBaselineGroupTemplateState' { Mock Get-CIPPDbItem { [PSCustomObject]@{ RowKey = 'Groups-Count'; DataCount = 1 } } } - It 'checks a dynamic distribution template against Exchange, never against Graph groups' { - # A DDG lives in Exchange only. Checked against the Groups cache it would read - # missing forever and be re-created on every remediation run. + It 'does not grade a dynamic distribution template: DDLs are not supported by CIPP' { + # A DDG lives in Exchange only and CIPP no longer supports it - EXO canonicalises the + # recipient filter (permanent drift) and the executor write throws. The state must return + # not-applicable (Current = $null) instead of grading it against any cache. Mock Get-CIPPAzDataTableEntity { [PSCustomObject]@{ RowKey = 'tpl-g'; JSON = '{"displayName":"All Sales","groupType":"dynamicDistribution","membershipRules":"Department -eq ''Sales''"}' } } - Mock New-CIPPDbRequest { - if ($Type -eq 'ExoDynamicDistributionGroup') { @(@{ Name = 'All Sales'; Identity = 'All Sales'; RecipientFilter = "Department -eq 'Sales'" } | ConvertTo-Cached) } - else { @() } - } + Mock New-CIPPDbRequest { @() } $Item = [PSCustomObject]@{ Variables = [PSCustomObject]@{ groupTemplate = 'tpl-g' } } - (Get-CIPPBaselineGroupTemplateState -Item $Item -TenantFilter $script:Tenant).Current.deployed | Should -BeTrue + (Get-CIPPBaselineGroupTemplateState -Item $Item -TenantFilter $script:Tenant).Current | Should -BeNullOrEmpty } It 'checks every other group type against the Groups cache' { diff --git a/Tests/Endpoint/Invoke-AddUser.Tests.ps1 b/Tests/Endpoint/Invoke-AddUser.Tests.ps1 index bc6a54901f980..9d04186a9485a 100644 --- a/Tests/Endpoint/Invoke-AddUser.Tests.ps1 +++ b/Tests/Endpoint/Invoke-AddUser.Tests.ps1 @@ -26,6 +26,7 @@ BeforeAll { function New-CIPPUserTask { param($UserObj, $APIName, $Headers) } function Add-CIPPScheduledTask { param($Task, $hidden, $Headers, $DisallowDuplicateName) } function Write-LogMessage { param($headers, $API, $tenant, $message, $Sev, $LogData) } + function Get-Tenants { param($TenantFilter, $IncludeErrors, $IncludeAll) } . $FunctionPath @@ -65,6 +66,8 @@ Describe 'Invoke-AddUser' { Mock -CommandName Write-LogMessage -MockWith { } Mock -CommandName Add-CIPPScheduledTask -MockWith { } Mock -CommandName New-CIPPUserTask -MockWith { New-CreationResult } + # The endpoint refuses any tenantFilter it cannot resolve to a single tenant. + Mock -CommandName Get-Tenants -MockWith { [pscustomobject]@{ defaultDomainName = $TenantFilter; customerId = 'tenant-guid' } } } Context 'Creating the user now' { @@ -213,5 +216,25 @@ Describe 'Invoke-AddUser' { Should -Invoke New-CIPPUserTask -Times 0 -Exactly Should -Invoke Add-CIPPScheduledTask -Times 0 -Exactly } + + It 'refuses AllTenants because user creation is single-tenant only' { + $Response = Invoke-AddUser -Request (New-AddUserRequest -Body @{ tenantFilter = 'AllTenants' }) + + $Response.StatusCode | Should -Be ([HttpStatusCode]::BadRequest) + $Response.Body.Results.resultText | Should -BeLike 'User creation is single-tenant only*' + $Response.Body.Results.state | Should -Be 'error' + Should -Invoke New-CIPPUserTask -Times 0 -Exactly + } + + It 'refuses a tenantFilter that does not resolve to a known tenant' { + Mock -CommandName Get-Tenants -MockWith { $null } + + $Response = Invoke-AddUser -Request (New-AddUserRequest -Body @{ tenantFilter = 'nobody.example' }) + + $Response.StatusCode | Should -Be ([HttpStatusCode]::BadRequest) + $Response.Body.Results.resultText | Should -BeLike 'User creation is single-tenant only*' + Should -Invoke Get-Tenants -Times 1 -Exactly -ParameterFilter { $TenantFilter -eq 'nobody.example' } + Should -Invoke New-CIPPUserTask -Times 0 -Exactly + } } } diff --git a/Tests/Endpoint/Invoke-ListInstanceDiagnostics.Timeline.Tests.ps1 b/Tests/Endpoint/Invoke-ListInstanceDiagnostics.Timeline.Tests.ps1 index 8c1b2569938d0..b2f18f96a5e14 100644 --- a/Tests/Endpoint/Invoke-ListInstanceDiagnostics.Timeline.Tests.ps1 +++ b/Tests/Endpoint/Invoke-ListInstanceDiagnostics.Timeline.Tests.ps1 @@ -20,8 +20,10 @@ BeforeAll { function Get-CIPPAzDataTableEntity { param($Context, $Filter) } function Get-CippException { param($Exception) @{ NormalizedError = "$Exception" } } function Write-LogMessage { param($API, $message, $sev, $LogData) } + function Get-CippApiClient { param($AppId) } . $FunctionPath + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Functions/Get-CIPPEgressAccounting.ps1') function New-DiagRequest { param([string]$Action = 'Timeline', [int]$Hours = 24) @@ -30,52 +32,107 @@ BeforeAll { Query = [pscustomobject]@{ Action = $Action; Hours = $Hours } } } + + $script:HealthRows = @( + [pscustomobject]@{ PartitionKey = 'InstanceHealth'; RowKey = '2026-09-10T10:00_sample'; Bucket = '2026-09-10T10:00'; Kind = 'sample'; OomCount = 0; WatchdogCount = 0; PoolExhaustedCount = 0; ErrCount = 0; MaxLimiterWaitMs = 0; StalledRunCount = 0; HeapMb = 500; HeapMbLive = $null; GcHeapLimitMb = 3072; TopEndpointsMs = $null } + [pscustomobject]@{ PartitionKey = 'InstanceHealth'; RowKey = '2026-09-10T10:00_client_11111111-1111-1111-1111-111111111111'; Bucket = '2026-09-10T10:00'; Kind = 'client'; AppId = '11111111-1111-1111-1111-111111111111'; AppName = 'Acme RMM'; IP = '203.0.113.9'; Count = 5 } + [pscustomobject]@{ PartitionKey = 'InstanceHealth'; RowKey = '2026-09-10T10:05_boot'; Bucket = '2026-09-10T10:05'; Kind = 'boot'; BootTime = '2026-09-10T10:05:00Z'; GapMinutes = 3 } + ) + + $script:AppA = '11111111-1111-1111-1111-111111111111' + $script:AppB = '22222222-2222-2222-2222-222222222222' + + # Craft's egress table: 15 minute bucket rows per API client plus an instance-total + # partition, and the same split for today's daily rollup. + $script:EgressBucketRows = @( + [pscustomobject]@{ PartitionKey = $script:AppA; RowKey = 'bkt_20260910T100000Z'; Bytes = 700000; Requests = 7; Shed = 2; CapBytes = 1000000; BucketStartUtc = [DateTimeOffset]::Parse('2026-09-10T10:00:00Z'); AppId = $script:AppA } + [pscustomobject]@{ PartitionKey = $script:AppB; RowKey = 'bkt_20260910T100000Z'; Bytes = 200000; Requests = 2; Shed = 1; CapBytes = 1000000; BucketStartUtc = [DateTimeOffset]::Parse('2026-09-10T10:00:00Z'); AppId = $script:AppB } + [pscustomobject]@{ PartitionKey = 'instance-total'; RowKey = 'bkt_20260910T100000Z'; Bytes = 900000; Requests = 9; Shed = 3; CapBytes = 1000000; BucketStartUtc = [DateTimeOffset]::Parse('2026-09-10T10:00:00Z') } + ) + $script:EgressDayRows = @( + [pscustomobject]@{ PartitionKey = $script:AppA; RowKey = 'day_20260910'; Bytes = 700000; Requests = 7; Shed = 2; CapBytes = 1000000; DateUtc = '2026-09-10' } + [pscustomobject]@{ PartitionKey = $script:AppB; RowKey = 'day_20260910'; Bytes = 200000; Requests = 2; Shed = 1; CapBytes = 1000000; DateUtc = '2026-09-10' } + [pscustomobject]@{ PartitionKey = 'instance-total'; RowKey = 'day_20260910'; Bytes = 900000; Requests = 9; Shed = 3; CapBytes = 1000000; DateUtc = '2026-09-10'; Enforcing = $true; CapReachedUtc = [DateTimeOffset]::Parse('2026-09-10T10:07:00Z') } + ) } -Describe 'Invoke-ListInstanceDiagnostics Timeline row splitting' { - It 'groups clients under their sample bucket and emits a boot event from mixed Kind rows' { - $Rows = @( - [pscustomobject]@{ PartitionKey = 'InstanceHealth'; RowKey = '2026-09-10T10:00_sample'; Bucket = '2026-09-10T10:00'; Kind = 'sample'; OomCount = 0; WatchdogCount = 0; PoolExhaustedCount = 0; ErrCount = 0; MaxLimiterWaitMs = 0; StalledRunCount = 0; HeapMb = 500; HeapMbLive = $null; GcHeapLimitMb = 3072; TopEndpointsMs = $null; EgressBytesToday = 1048576; EgressBytes = 204800; EgressCapBytes = 10485760 } - [pscustomobject]@{ PartitionKey = 'InstanceHealth'; RowKey = '2026-09-10T10:00_client_11111111-1111-1111-1111-111111111111'; Bucket = '2026-09-10T10:00'; Kind = 'client'; AppId = '11111111-1111-1111-1111-111111111111'; AppName = 'Acme RMM'; IP = '203.0.113.9'; Count = 5 } - [pscustomobject]@{ PartitionKey = 'InstanceHealth'; RowKey = '2026-09-10T10:05_boot'; Bucket = '2026-09-10T10:05'; Kind = 'boot'; BootTime = '2026-09-10T10:05:00Z'; GapMinutes = 3 } - ) +Describe 'Invoke-ListInstanceDiagnostics egress and row splitting' { + BeforeEach { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $script:HealthRows } -ParameterFilter { $Filter -match "PartitionKey eq 'InstanceHealth'" } + Mock -CommandName Get-CippApiClient -MockWith { + @( + [pscustomobject]@{ ClientId = $script:AppA; AppName = 'Acme RMM' } + [pscustomobject]@{ ClientId = $script:AppB; AppName = 'Other PSA' } + ) + } + } - Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $Rows } -ParameterFilter { $Filter -match "PartitionKey eq 'InstanceHealth'" } + Context 'with egress accounting rows in the table' { + BeforeEach { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $script:EgressBucketRows } -ParameterFilter { $Filter -like 'RowKey ge*' } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $script:EgressDayRows } -ParameterFilter { $Filter -like "RowKey eq 'day_*" } + } - $Response = Invoke-ListInstanceDiagnostics -Request (New-DiagRequest -Action 'Timeline') -TriggerMetadata $null + It 'groups clients under their sample bucket and emits a boot event from mixed Kind rows' { + $Response = Invoke-ListInstanceDiagnostics -Request (New-DiagRequest -Action 'Timeline') -TriggerMetadata $null - $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) - $Response.Body.Results.Buckets | Should -HaveCount 1 - $Response.Body.Results.Buckets[0].Bucket | Should -Be '2026-09-10T10:00' - $Response.Body.Results.Buckets[0].Clients | Should -HaveCount 1 - $Response.Body.Results.Buckets[0].Clients[0].AppId | Should -Be '11111111-1111-1111-1111-111111111111' - $Response.Body.Results.Buckets[0].Clients[0].Count | Should -Be 5 + $Response.StatusCode | Should -Be ([System.Net.HttpStatusCode]::OK) + $Response.Body.Results.Buckets | Should -HaveCount 1 + $Response.Body.Results.Buckets[0].Bucket | Should -Be '2026-09-10T10:00' + $Response.Body.Results.Buckets[0].Clients | Should -HaveCount 1 + $Response.Body.Results.Buckets[0].Clients[0].AppId | Should -Be $script:AppA + $Response.Body.Results.Buckets[0].Clients[0].Count | Should -Be 5 - $Response.Body.Results.Buckets[0].EgressBytesToday | Should -Be 1048576 - $Response.Body.Results.Buckets[0].EgressBytes | Should -Be 204800 - $Response.Body.Results.EgressCapBytes | Should -Be 10485760 - $Response.Body.Results.EgressAvailable | Should -BeTrue + $Response.Body.Results.HeapCapMb | Should -Be 3072 - $Response.Body.Results.HeapCapMb | Should -Be 3072 + $Response.Body.Results.Events | Should -HaveCount 1 + $Response.Body.Results.Events[0].Type | Should -Be 'boot' + $Response.Body.Results.Events[0].Bucket | Should -Be '2026-09-10T10:05' + $Response.Body.Results.Events[0].GapMinutes | Should -Be 3 + } - $Response.Body.Results.Events | Should -HaveCount 1 - $Response.Body.Results.Events[0].Type | Should -Be 'boot' - $Response.Body.Results.Events[0].Bucket | Should -Be '2026-09-10T10:05' - $Response.Body.Results.Events[0].GapMinutes | Should -Be 3 - } + It 'returns the egress accounting block with bucket totals and resolved client names' { + $Response = Invoke-ListInstanceDiagnostics -Request (New-DiagRequest -Action 'Timeline') -TriggerMetadata $null + $Egress = $Response.Body.Results.Egress + + $Egress.Available | Should -BeTrue + $Egress.BucketMinutes | Should -Be 15 + $Egress.Buckets | Should -HaveCount 1 + $Egress.Buckets[0].BucketStart | Should -Be '2026-09-10T10:00:00Z' + $Egress.Buckets[0].Bytes | Should -Be 900000 + $Egress.Buckets[0].Requests | Should -Be 9 + $Egress.Buckets[0].Clients | Should -HaveCount 2 + ($Egress.Buckets[0].Clients | Where-Object { $_.AppId -eq $script:AppB }).AppName | Should -Be 'Other PSA' + + $Egress.TodayBytes | Should -Be 900000 + $Egress.TodayShed | Should -Be 3 + $Egress.Enforcing | Should -BeTrue + $Egress.Clients[0].AppName | Should -Be 'Acme RMM' + } - It 'reports egress unavailable when no sample in the window carries a reading' { - $Rows = @( - [pscustomobject]@{ PartitionKey = 'InstanceHealth'; RowKey = '2026-09-10T10:00_sample'; Bucket = '2026-09-10T10:00'; Kind = 'sample'; OomCount = 0; WatchdogCount = 0; PoolExhaustedCount = 0; ErrCount = 0; MaxLimiterWaitMs = 0; StalledRunCount = 0; HeapMb = 500; HeapMbLive = $null; GcHeapLimitMb = 3072; TopEndpointsMs = $null } - ) + It 'fails the egress check and names the busiest client when the cap was reached' { + $Response = Invoke-ListInstanceDiagnostics -Request (New-DiagRequest -Action 'Checks') -TriggerMetadata $null + $Check = $Response.Body.Results | Where-Object { $_.Check -eq 'egress' } - Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $Rows } -ParameterFilter { $Filter -match "PartitionKey eq 'InstanceHealth'" } + $Check.Status | Should -Be 'FAIL' + $Check.Detail | Should -BeLike '*cap reached at 2026-09-10T10:07:00Z*' + $Check.Detail | Should -BeLike '*3 request(s) refused with 429*' + $Check.Detail | Should -BeLike '*busiest: Acme RMM*' + $Check.Fix | Should -Not -BeNullOrEmpty + } + } - $Response = Invoke-ListInstanceDiagnostics -Request (New-DiagRequest -Action 'Timeline') -TriggerMetadata $null + Context 'with no egress accounting rows' { + It 'reports egress unavailable on the timeline' { + $Response = Invoke-ListInstanceDiagnostics -Request (New-DiagRequest -Action 'Timeline') -TriggerMetadata $null + $Response.Body.Results.Egress.Available | Should -BeFalse + } - $Response.Body.Results.EgressAvailable | Should -BeFalse - $Response.Body.Results.Buckets[0].EgressBytes | Should -BeNullOrEmpty - $Response.Body.Results.Buckets[0].EgressBytesToday | Should -BeNullOrEmpty - $Response.Body.Results.EgressCapBytes | Should -BeNullOrEmpty + It 'reports the egress check as INFO' { + $Response = Invoke-ListInstanceDiagnostics -Request (New-DiagRequest -Action 'Checks') -TriggerMetadata $null + $Check = $Response.Body.Results | Where-Object { $_.Check -eq 'egress' } + $Check.Status | Should -Be 'INFO' + $Check.Detail | Should -BeLike 'No API egress recorded today*' + } } } diff --git a/Tests/Private/Get-CIPPEgressAccounting.Tests.ps1 b/Tests/Private/Get-CIPPEgressAccounting.Tests.ps1 new file mode 100644 index 0000000000000..f4879e86f1630 --- /dev/null +++ b/Tests/Private/Get-CIPPEgressAccounting.Tests.ps1 @@ -0,0 +1,96 @@ +# Pester tests for Get-CIPPEgressAccounting +# Craft owns the accounting table, so "table absent or empty" must stay indistinguishable from a +# quiet day: both return $null rather than a fake zero reading. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + + function Get-CIPPTable { param($TableName) @{ Context = 'stub' } } + function Get-CIPPAzDataTableEntity { param($Context, $Filter) } + function Get-CippApiClient { param($AppId) } + + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Functions/Get-CIPPEgressAccounting.ps1') + + $script:Now = [DateTime]::Parse('2026-09-12T10:20:00Z').ToUniversalTime() + $script:AppA = '11111111-1111-1111-1111-111111111111' + $script:AppB = '22222222-2222-2222-2222-222222222222' + + $script:BucketRows = @( + [pscustomobject]@{ PartitionKey = $script:AppA; RowKey = 'bkt_20260912T100000Z'; Bytes = 600; Requests = 6; Shed = 0; CapBytes = 1000000; BucketStartUtc = [DateTimeOffset]::Parse('2026-09-12T10:00:00Z'); AppId = $script:AppA } + [pscustomobject]@{ PartitionKey = $script:AppB; RowKey = 'bkt_20260912T100000Z'; Bytes = 300; Requests = 3; Shed = 1; CapBytes = 1000000; BucketStartUtc = [DateTimeOffset]::Parse('2026-09-12T10:00:00Z'); AppId = $script:AppB } + [pscustomobject]@{ PartitionKey = 'instance-total'; RowKey = 'bkt_20260912T100000Z'; Bytes = 1000; Requests = 10; Shed = 1; CapBytes = 1000000; BucketStartUtc = [DateTimeOffset]::Parse('2026-09-12T10:00:00Z') } + [pscustomobject]@{ PartitionKey = $script:AppA; RowKey = 'bkt_20260912T101500Z'; Bytes = 250; Requests = 2; Shed = 0; CapBytes = 1000000; BucketStartUtc = [DateTimeOffset]::Parse('2026-09-12T10:15:00Z'); AppId = $script:AppA } + ) + + $script:DayRows = @( + [pscustomobject]@{ PartitionKey = $script:AppA; RowKey = 'day_20260912'; Bytes = 850; Requests = 8; Shed = 0; CapBytes = 1000000; DateUtc = '2026-09-12' } + [pscustomobject]@{ PartitionKey = $script:AppB; RowKey = 'day_20260912'; Bytes = 400; Requests = 4; Shed = 1; CapBytes = 1000000; DateUtc = '2026-09-12' } + [pscustomobject]@{ PartitionKey = 'instance-total'; RowKey = 'day_20260912'; Bytes = 1250; Requests = 12; Shed = 1; CapBytes = 1000000; DateUtc = '2026-09-12'; Enforcing = $true; CapReachedUtc = [DateTimeOffset]::Parse('2026-09-12T10:05:00Z') } + ) +} + +Describe 'Get-CIPPEgressAccounting' { + BeforeEach { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $script:BucketRows } -ParameterFilter { $Filter -like 'RowKey ge*' } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { $script:DayRows } -ParameterFilter { $Filter -like "RowKey eq 'day_*" } + Mock -CommandName Get-CippApiClient -MockWith { + @( + [pscustomobject]@{ ClientId = $script:AppA; AppName = 'Acme RMM' } + [pscustomobject]@{ ClientId = $script:AppB; AppName = 'Other PSA' } + ) + } + } + + It 'aggregates buckets and resolves client names' { + $Result = Get-CIPPEgressAccounting -Hours 6 -Now $script:Now + + $Result.BucketMinutes | Should -Be 15 + $Result.Buckets | Should -HaveCount 2 + $Result.Buckets[0].BucketStart | Should -Be '2026-09-12T10:00:00Z' + $Result.Buckets[0].Bytes | Should -Be 1000 + $Result.Buckets[0].Requests | Should -Be 10 + $Result.Buckets[0].Clients | Should -HaveCount 2 + ($Result.Buckets[0].Clients | Where-Object { $_.AppId -eq $script:AppB }).Bytes | Should -Be 300 + ($Result.Buckets[0].Clients | Where-Object { $_.AppId -eq $script:AppA }).AppName | Should -Be 'Acme RMM' + ($Result.Buckets[0].Clients | Where-Object { $_.AppId -eq $script:AppA }).Bytes | Should -Be 600 + } + + It 'falls back to the sum of clients when the bucket has no instance-total row' { + # Second bucket only has the one client row. + $Result = Get-CIPPEgressAccounting -Hours 6 -Now $script:Now + $Result.Buckets[1].BucketStart | Should -Be '2026-09-12T10:15:00Z' + $Result.Buckets[1].Bytes | Should -Be 250 + $Result.Buckets[1].Requests | Should -Be 2 + } + + It 'reads the daily totals from the instance-total row and sorts clients by bytes' { + $Result = Get-CIPPEgressAccounting -Hours 6 -Now $script:Now + + $Result.TodayBytes | Should -Be 1250 + $Result.TodayRequests | Should -Be 12 + $Result.TodayShed | Should -Be 1 + $Result.CapBytes | Should -Be 1000000 + $Result.Enforcing | Should -BeTrue + $Result.CapReachedUtc | Should -Be '2026-09-12T10:05:00Z' + $Result.Clients | Should -HaveCount 2 + $Result.Clients[0].AppName | Should -Be 'Acme RMM' + $Result.Clients[0].Bytes | Should -Be 850 + } + + It 'returns null when the table has no rows' { + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { @() } -ParameterFilter { $Filter -like 'RowKey ge*' } + Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { @() } -ParameterFilter { $Filter -like "RowKey eq 'day_*" } + Get-CIPPEgressAccounting -Hours 6 -Now $script:Now | Should -BeNullOrEmpty + } + + It 'returns null when the table cannot be read' { + Mock -CommandName Get-CIPPTable -MockWith { throw 'TableNotFound' } + Get-CIPPEgressAccounting -Hours 6 -Now $script:Now | Should -BeNullOrEmpty + } + + It 'falls back to the AppId when no API client record matches' { + Mock -CommandName Get-CippApiClient -MockWith { @() } + $Result = Get-CIPPEgressAccounting -Hours 6 -Now $script:Now + $Result.Clients[0].AppName | Should -Be $script:AppA + } +} diff --git a/Tests/Private/Get-CIPPEgressLedger.Tests.ps1 b/Tests/Private/Get-CIPPEgressLedger.Tests.ps1 deleted file mode 100644 index df0978b9514b4..0000000000000 --- a/Tests/Private/Get-CIPPEgressLedger.Tests.ps1 +++ /dev/null @@ -1,34 +0,0 @@ -# Pester tests for Get-CIPPEgressLedger -# The ledger is written by Craft outside this repo, so "no data yet" (missing file, stale -# day, garbage JSON) must be indistinguishable from a real zero-byte day: both return $null, -# never a fake 0 that looks like a reading. - -BeforeAll { - $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) - . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/Functions/Get-CIPPEgressLedger.ps1') -} - -Describe 'Get-CIPPEgressLedger' { - It 'returns the bytes when the ledger is for today' { - $Now = [DateTime]::Parse('2026-09-11T12:00:00Z').ToUniversalTime() - Set-Content -Path (Join-Path $TestDrive 'egress-ledger.json') -Value '{"DateUtc":"2026-09-11","Bytes":123456}' - $Result = Get-CIPPEgressLedger -LogDirectory $TestDrive -Now $Now - $Result.Bytes | Should -Be 123456 - $Result.DateUtc | Should -Be '2026-09-11' - } - - It 'returns null when the ledger is for a previous UTC day' { - $Now = [DateTime]::Parse('2026-09-11T12:00:00Z').ToUniversalTime() - Set-Content -Path (Join-Path $TestDrive 'egress-ledger.json') -Value '{"DateUtc":"2026-09-10","Bytes":123456}' - Get-CIPPEgressLedger -LogDirectory $TestDrive -Now $Now | Should -BeNullOrEmpty - } - - It 'returns null when the file is missing' { - Get-CIPPEgressLedger -LogDirectory (Join-Path $TestDrive 'does-not-exist') | Should -BeNullOrEmpty - } - - It 'returns null for unparsable JSON' { - Set-Content -Path (Join-Path $TestDrive 'egress-ledger.json') -Value 'not json {{' - Get-CIPPEgressLedger -LogDirectory $TestDrive | Should -BeNullOrEmpty - } -} diff --git a/Tests/Private/Get-CIPPInstanceHealthSample.Tests.ps1 b/Tests/Private/Get-CIPPInstanceHealthSample.Tests.ps1 index 7f844769f3820..ac1b10a8e9e1d 100644 --- a/Tests/Private/Get-CIPPInstanceHealthSample.Tests.ps1 +++ b/Tests/Private/Get-CIPPInstanceHealthSample.Tests.ps1 @@ -87,17 +87,6 @@ Describe 'Get-CIPPInstanceHealthSample' { $Top.ContainsKey('Invoke-ListDomains') | Should -BeFalse } - It 'counts egress rejections and captures distinct client names' { - $Lines = @( - '2026-09-10T10:00:00.000Z [WRN] Egress cap reached — 429 for AcmeRMM on GET /api/ListTenants; served 1000000000/1000000000 bytes today, Retry-After 30s' - '2026-09-10T10:00:01.000Z [WRN] Egress cap reached — 429 for AcmeRMM on GET /api/ListUsers; served 1000000000/1000000000 bytes today, Retry-After 30s' - '2026-09-10T10:00:02.000Z [WRN] Egress cap reached — 429 for OtherPSA on GET /api/ListDomains; served 1000000000/1000000000 bytes today, Retry-After 30s' - ) - $Sample = Get-CIPPInstanceHealthSample -Lines $Lines - $Sample.EgressRejectCount | Should -Be 3 - @($Sample.EgressRejectClients) | Should -Be @('AcmeRMM', 'OtherPSA') - } - It 'groups API access by AppId and counts repeats' { $Clients = (Get-CIPPInstanceHealthSample -Lines $script:MixedLines).Clients $Clients.Count | Should -Be 2 @@ -119,8 +108,6 @@ Describe 'Get-CIPPInstanceHealthSample' { $Sample.StalledRunCount | Should -Be 0 $Sample.TopEndpointsMs.Count | Should -Be 0 $Sample.Clients.Count | Should -Be 0 - $Sample.EgressRejectCount | Should -Be 0 - @($Sample.EgressRejectClients).Count | Should -Be 0 } It 'reports no heap reading rather than zero when no sample was logged' { diff --git a/Tests/Private/Get-CippMcpScopeAppSettings.Tests.ps1 b/Tests/Private/Get-CippMcpScopeAppSettings.Tests.ps1 new file mode 100644 index 0000000000000..29a79b6daef93 --- /dev/null +++ b/Tests/Private/Get-CippMcpScopeAppSettings.Tests.ps1 @@ -0,0 +1,53 @@ +# Pester tests for Get-CippMcpScopeAppSettings +# The single source of truth for the MCP OAuth scope app settings written by both +# Invoke-ExecApiClient (Save to Azure) and the Initialize-CIPPAuth warmup reconcile. The whole +# point of the helper is that both callers emit identical values, so these tests pin the exact +# shape: offline_access + the resource scope must appear in every advertised scope set, and the +# CRAFT_PRM / CRAFT_PRM_AS discovery docs appear only on CIPPNG. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + . (Join-Path $RepoRoot 'Modules/CIPPCore/Public/MCP/Get-CippMcpScopeAppSettings.ps1') + + $script:Hostname = 'cipp-backend.azurewebsites.net' + $script:McpScope = "https://$script:Hostname/user_impersonation" +} + +Describe 'Get-CippMcpScopeAppSettings' { + It 'puts offline_access and the resource scope in the challenge-header scope string' { + $Settings = Get-CippMcpScopeAppSettings -Hostname $script:Hostname -TenantId 'tenant-guid' + $Tokens = $Settings['WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES'] -split ' ' + $Tokens | Should -Contain 'openid' + $Tokens | Should -Contain 'profile' + $Tokens | Should -Contain 'offline_access' + $Tokens | Should -Contain $script:McpScope + } + + It 'omits the CRAFT discovery docs when not CIPPNG' { + $Settings = Get-CippMcpScopeAppSettings -Hostname $script:Hostname -TenantId 'tenant-guid' + $Settings.ContainsKey('CRAFT_PRM') | Should -BeFalse + $Settings.ContainsKey('CRAFT_PRM_AS') | Should -BeFalse + } + + It 'emits CRAFT_PRM and CRAFT_PRM_AS with offline_access in scopes_supported on CIPPNG' { + $Settings = Get-CippMcpScopeAppSettings -Hostname $script:Hostname -TenantId 'tenant-guid' -IsCippNg + + $Prm = $Settings['CRAFT_PRM'] | ConvertFrom-Json + $Prm.scopes_supported | Should -Contain 'offline_access' + $Prm.scopes_supported | Should -Contain $script:McpScope + $Prm.resource | Should -Be '{origin}/api/ExecMcp' + + $As = $Settings['CRAFT_PRM_AS'] | ConvertFrom-Json + $As.scopes_supported | Should -Contain 'offline_access' + $As.grant_types_supported | Should -Contain 'refresh_token' + $As.token_endpoint | Should -Be 'https://login.microsoftonline.com/tenant-guid/oauth2/v2.0/token' + } + + It 'is deterministic — repeated calls produce byte-identical values (no restart loop)' { + $A = Get-CippMcpScopeAppSettings -Hostname $script:Hostname -TenantId 'tenant-guid' -IsCippNg + $B = Get-CippMcpScopeAppSettings -Hostname $script:Hostname -TenantId 'tenant-guid' -IsCippNg + $A['WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES'] | Should -BeExactly $B['WEBSITE_AUTH_PRM_DEFAULT_WITH_SCOPES'] + $A['CRAFT_PRM'] | Should -BeExactly $B['CRAFT_PRM'] + $A['CRAFT_PRM_AS'] | Should -BeExactly $B['CRAFT_PRM_AS'] + } +} diff --git a/Tests/Private/Grant-CippAppGraphConsent.Tests.ps1 b/Tests/Private/Grant-CippAppGraphConsent.Tests.ps1 new file mode 100644 index 0000000000000..732e05c5ceb8e --- /dev/null +++ b/Tests/Private/Grant-CippAppGraphConsent.Tests.ps1 @@ -0,0 +1,102 @@ +# Pester tests for Grant-CippAppGraphConsent +# The tenant-wide (AllPrincipals) Graph consent primitive that makes Entra issue a refresh token +# for an MCP client app. Verifies it creates a grant when none exists, adds only the missing +# scopes to an existing one, is a no-op when everything is already consented, ignores per-user +# grants, and throws (rather than silently succeeding) when the app service principal is missing. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Authentication/Grant-CippAppGraphConsent.ps1' + + function New-GraphGetRequest { param($uri, $NoAuthCheck, $asapp) } + function New-GraphPOSTRequest { param($uri, $body, $type, $NoAuthCheck, $asapp) } + + . $FunctionPath + + $script:GraphAppId = '00000003-0000-0000-c000-000000000000' +} + +Describe 'Grant-CippAppGraphConsent' { + BeforeEach { + $script:AppId = '44444444-4444-4444-4444-444444444444' + $script:ClientSpId = 'client-sp-id' + $script:GraphSpId = 'graph-sp-id' + $script:ExistingGrants = @() + + Mock -CommandName Start-Sleep -MockWith { } + Mock -CommandName New-GraphPOSTRequest -MockWith { } + Mock -CommandName New-GraphGetRequest -MockWith { + if ($uri -match [regex]::Escape("appId='$script:AppId'")) { return [PSCustomObject]@{ id = $script:ClientSpId } } + if ($uri -match [regex]::Escape("appId='$script:GraphAppId'")) { return [PSCustomObject]@{ id = $script:GraphSpId } } + if ($uri -match 'oauth2PermissionGrants') { return $script:ExistingGrants } + return @() + } + } + + It 'creates an AllPrincipals grant for the requested scopes when none exists' { + Grant-CippAppGraphConsent -AppId $script:AppId -Scopes @('openid', 'profile', 'offline_access') + + Should -Invoke -CommandName New-GraphPOSTRequest -Times 1 -Exactly -ParameterFilter { + $type -eq 'POST' -and + $uri -eq 'https://graph.microsoft.com/v1.0/oauth2PermissionGrants' -and + ($body | ConvertFrom-Json).consentType -eq 'AllPrincipals' -and + ($body | ConvertFrom-Json).clientId -eq $script:ClientSpId -and + ($body | ConvertFrom-Json).resourceId -eq $script:GraphSpId -and + ($body | ConvertFrom-Json).scope -eq 'openid profile offline_access' + } + } + + It 'adds only the missing scopes to an existing grant' { + $script:ExistingGrants = @([PSCustomObject]@{ + id = 'grant-1' + resourceId = $script:GraphSpId + consentType = 'AllPrincipals' + scope = 'openid User.Read' + }) + + Grant-CippAppGraphConsent -AppId $script:AppId -Scopes @('openid', 'profile', 'offline_access') + + Should -Invoke -CommandName New-GraphPOSTRequest -Times 1 -Exactly -ParameterFilter { + $type -eq 'PATCH' -and + $uri -eq 'https://graph.microsoft.com/v1.0/oauth2PermissionGrants/grant-1' -and + ($body | ConvertFrom-Json).scope -eq 'offline_access openid profile User.Read' + } + } + + It 'does nothing when every requested scope is already consented' { + $script:ExistingGrants = @([PSCustomObject]@{ + id = 'grant-1' + resourceId = $script:GraphSpId + consentType = 'AllPrincipals' + scope = 'openid profile offline_access User.Read' + }) + + $Result = Grant-CippAppGraphConsent -AppId $script:AppId -Scopes @('openid', 'profile', 'offline_access') + + Should -Invoke -CommandName New-GraphPOSTRequest -Times 0 -Exactly + $Result.Action | Should -Be 'nochange' + } + + It 'ignores a per-user grant and creates the tenant-wide one' { + $script:ExistingGrants = @([PSCustomObject]@{ + id = 'grant-user' + resourceId = $script:GraphSpId + consentType = 'Principal' + scope = 'openid profile offline_access' + }) + + Grant-CippAppGraphConsent -AppId $script:AppId -Scopes @('openid', 'profile', 'offline_access') + + Should -Invoke -CommandName New-GraphPOSTRequest -Times 1 -Exactly -ParameterFilter { $type -eq 'POST' } + } + + It 'throws when the app service principal cannot be found' { + Mock -CommandName New-GraphGetRequest -MockWith { + if ($uri -match [regex]::Escape("appId='$script:GraphAppId'")) { return [PSCustomObject]@{ id = $script:GraphSpId } } + return @() + } + + { Grant-CippAppGraphConsent -AppId $script:AppId -Scopes @('offline_access') } | Should -Throw + Should -Invoke -CommandName New-GraphPOSTRequest -Times 0 -Exactly + } +} diff --git a/Tests/Private/Set-CIPPMCPClientApp.Tests.ps1 b/Tests/Private/Set-CIPPMCPClientApp.Tests.ps1 new file mode 100644 index 0000000000000..b72aa20b4044e --- /dev/null +++ b/Tests/Private/Set-CIPPMCPClientApp.Tests.ps1 @@ -0,0 +1,96 @@ +# Pester tests for Set-CIPPMCPClientApp +# Focused on the offline_access change: the MCP client app registration must declare +# offline_access (Microsoft Graph, delegated) additively - preserving existing permissions - and +# admin-consent it via Grant-CippAppGraphConsent, so Entra issues a refresh token and clients stop +# re-authenticating every hour. + +BeforeAll { + $RepoRoot = Split-Path -Parent (Split-Path -Parent (Split-Path -Parent $PSCommandPath)) + $FunctionPath = Join-Path $RepoRoot 'Modules/CIPPCore/Public/Authentication/Set-CIPPMCPClientApp.ps1' + + function New-GraphGetRequest { param($uri, $NoAuthCheck, $AsApp) } + function New-GraphPOSTRequest { param($uri, $body, $type, $NoAuthCheck, $AsApp) } + function Get-CippMcpKnownClients { } + function Grant-CippAppGraphConsent { param($AppId, $Scopes) } + function Write-LogMessage { param($headers, $API, $message, $Sev) } + + . $FunctionPath + + $script:GraphResourceId = '00000003-0000-0000-c000-000000000000' + $script:UserRead = 'e1fe6dd8-ba31-4d61-89e7-88639da4683d' + $script:OfflineAccess = '7427e0e9-2fba-42fe-b0c0-848c9e6a8182' +} + +Describe 'Set-CIPPMCPClientApp offline_access' { + BeforeEach { + $script:AppId = '55555555-5555-5555-5555-555555555555' + $script:AppObjectId = 'mcp-app-object-id' + + $script:OriginalHostname = $env:WEBSITE_HOSTNAME + $env:WEBSITE_HOSTNAME = 'cipp-backend.azurewebsites.net' + + # App starts with only the Graph User.Read delegated permission (what New-CIPPAPIConfig creates). + $script:AppRequiredResourceAccess = @( + [PSCustomObject]@{ + resourceAppId = $script:GraphResourceId + resourceAccess = @([PSCustomObject]@{ id = $script:UserRead; type = 'Scope' }) + } + ) + + Mock -CommandName Get-CippMcpKnownClients -MockWith { + [PSCustomObject]@{ + PublicClientRedirectUris = @('https://claude.ai/api/mcp/auth_callback') + ConfidentialRedirectUris = @('https://global.consent.azure-apim.net/redirect') + PreAuthorizedClientIds = @('aebc6443-996d-45c2-90f0-388ff96faa56') + } + } + Mock -CommandName Write-LogMessage -MockWith { } + Mock -CommandName Grant-CippAppGraphConsent -MockWith { [PSCustomObject]@{ AppId = $AppId; Action = 'created'; Scopes = $Scopes } } + Mock -CommandName New-GraphPOSTRequest -MockWith { } + Mock -CommandName New-GraphGetRequest -MockWith { + [PSCustomObject]@{ + id = $script:AppObjectId + appId = $script:AppId + identifierUris = @("api://$script:AppId") + api = [PSCustomObject]@{ oauth2PermissionScopes = @(); preAuthorizedApplications = @() } + web = [PSCustomObject]@{ redirectUris = @("https://$($env:WEBSITE_HOSTNAME)/.auth/login/aad/callback") } + spa = [PSCustomObject]@{ redirectUris = @() } + publicClient = [PSCustomObject]@{ redirectUris = @() } + requiredResourceAccess = $script:AppRequiredResourceAccess + } + } + } + + AfterEach { + $env:WEBSITE_HOSTNAME = $script:OriginalHostname + } + + It 'adds offline_access to the Graph requiredResourceAccess entry, preserving existing scopes' { + Set-CIPPMCPClientApp -AppId $script:AppId -Headers @{} + + Should -Invoke -CommandName New-GraphPOSTRequest -Times 1 -Exactly -ParameterFilter { + $type -eq 'PATCH' -and + $uri -eq "https://graph.microsoft.com/v1.0/applications/$script:AppObjectId" -and + $( + $GraphAccess = (($body | ConvertFrom-Json).requiredResourceAccess | Where-Object { $_.resourceAppId -eq $script:GraphResourceId }).resourceAccess.id + ($GraphAccess -contains $script:OfflineAccess) -and ($GraphAccess -contains $script:UserRead) + ) + } + } + + It 'admin-consents offline_access for the app' { + Set-CIPPMCPClientApp -AppId $script:AppId -Headers @{} + + Should -Invoke -CommandName Grant-CippAppGraphConsent -Times 1 -Exactly -ParameterFilter { + $AppId -eq $script:AppId -and ($Scopes -contains 'offline_access') + } + } + + It 'does not fail the configuration when the consent grant throws' { + Mock -CommandName Grant-CippAppGraphConsent -MockWith { throw 'Insufficient privileges' } + + $Result = Set-CIPPMCPClientApp -AppId $script:AppId -Headers @{} + + $Result.Success | Should -BeTrue + } +} diff --git a/Tests/Standards/Invoke-CIPPStandardGroupTemplate.Tests.ps1 b/Tests/Standards/Invoke-CIPPStandardGroupTemplate.Tests.ps1 index e21a988a8dbcc..53b231683f1c9 100644 --- a/Tests/Standards/Invoke-CIPPStandardGroupTemplate.Tests.ps1 +++ b/Tests/Standards/Invoke-CIPPStandardGroupTemplate.Tests.ps1 @@ -182,20 +182,48 @@ Describe 'Invoke-CIPPStandardGroupTemplate' { Should -Invoke -CommandName Set-CIPPStandardsCompareField -Times 0 -Exactly -Because 'reporting every group as missing on a failed read produces false drift' } - It 'creates no dynamic distribution groups when the Exchange read fails' { + } + + Context 'dynamic distribution group templates are not supported' { + # DDLs were removed from CIPP: EXO canonicalises RecipientFilter (permanent drift) and + # Set-DynamicDistributionGroup -RecipientFilter throws. They must be skipped - never created, + # never remediated - but the skip must be visible in the logs and in the report. + BeforeEach { Mock -CommandName Get-CIPPAzDataTableEntity -MockWith { script:New-DynamicDistroTemplateEntity } - # The Graph read succeeds (empty) but the Exchange read for dynamic distros fails. Mock -CommandName New-GraphGetRequest -MockWith { @() } - Mock -CommandName New-ExoRequest -MockWith { throw 'Exchange is unavailable' } + Mock -CommandName New-ExoRequest -MockWith { } + } - { Invoke-CIPPStandardGroupTemplate -Tenant $script:Tenant -Settings (script:New-Settings -Remediate) } | - Should -Not -Throw + It 'skips a dynamic distribution template in remediate mode and logs a Warn' { + $Settings = [pscustomobject]@{ + remediate = $true + report = $false + groupTemplate = [pscustomobject]@{ value = '22222222-2222-2222-2222-222222222222' } + } + Invoke-CIPPStandardGroupTemplate -Tenant $script:Tenant -Settings $Settings - Should -Invoke -CommandName New-CIPPGroup -Times 0 -Exactly -Because 'a failed Exchange read must not be treated as "no dynamic distribution groups exist"' + Should -Invoke -CommandName New-CIPPGroup -Times 0 -Exactly -Because 'DDLs are not supported and must not be created' + Should -Invoke -CommandName New-ExoRequest -Times 0 -Exactly -Because 'Set-DynamicDistributionGroup must never run for a skipped DDL' - $Errors = @($script:logs | Where-Object { $_.Sev -eq 'Error' }) - $Errors.Count | Should -BeGreaterThan 0 - $Errors[0].Message | Should -Match 'skipping this run to avoid creating duplicate groups' + $Warns = @($script:logs | Where-Object { $_.Sev -eq 'Warn' }) + $Warns.Count | Should -BeGreaterThan 0 + $Warns[0].Message | Should -Match 'Dynamic Distribution Group.*not supported by CIPP' + } + + It 'surfaces a skipped dynamic distribution template in the report, not as drift' { + $Settings = [pscustomobject]@{ + remediate = $false + report = $true + groupTemplate = [pscustomobject]@{ value = '22222222-2222-2222-2222-222222222222' } + } + Invoke-CIPPStandardGroupTemplate -Tenant $script:Tenant -Settings $Settings + + Should -Invoke -CommandName Set-CIPPStandardsCompareField -Times 1 -Exactly -ParameterFilter { + $null -ne $CurrentValue.SkippedDynamicDistributionGroups -and + $CurrentValue.SkippedDynamicDistributionGroups -eq $ExpectedValue.SkippedDynamicDistributionGroups -and + @($CurrentValue.MissingGroups).Count -eq 0 -and + @($CurrentValue.MissingTemplates).Count -eq 0 + } -Because 'the DDL is reported as skipped/not-supported, identical on both sides so it shows without reading as drift' } } } diff --git a/version_latest.txt b/version_latest.txt index f65d9ca04026c..bb891e92e87d5 100644 --- a/version_latest.txt +++ b/version_latest.txt @@ -1 +1 @@ -10.10.2 \ No newline at end of file +10.10.3 \ No newline at end of file